d5ceff958d
`/model <x>` onto copilot-acp validates through `models_validate._static_catalog`, which reads `provider_model_ids` with no disk cache. After the session probe landed, every such switch spawned `copilot --acp`, ran the handshake, and killed it (1-3 s; up to the 15 s probe timeout when the CLI is installed but the session stalls). The GitHub-API tier that path used before sat behind a 5-minute in-memory memo; the ACP tier now has the same memo, and it remembers failures too so a broken CLI is not re-spawned per switch. The probe itself moves to `CopilotACPProfile.fetch_models` — the slot that already said "model listing is handled by the ACP subprocess" and returned None — so hermes_cli/models.py no longer hand-builds `CopilotACPClient` kwargs that `profile.create_client` owns. Discovery failures are logged at debug instead of swallowed. Tests: the two picker wiring tests collapse into one parametrized contract; a new test proves three consecutive switch validations pay one probe and a failed probe is not retried (fails when the memo read is removed).