7e4d02fef5
A global model/provider change must never stop a cron job. The #44585 guard raised [drift_skip] for every unpinned job whose provider_snapshot / model_snapshot no longer matched the live global default, so one `hermes model` switch silently killed whole fleets (reported by fastfinge, nitinthewiz, Dr-ilies; 13 of 60 jobs on the project lead's box after claude-fable-5 -> claude-fable-5.1). The snapshot is now the job's effective pin: _load_cron_job_config prefers job['model_snapshot'] over the global default and _resolve_job_runtime passes job['provider_snapshot'] as `requested` when neither a per-job pin nor a cron.model / cron.model_provider fleet default covers the axis. One INFO line per differing axis tells the operator what the job is running on and how to move it. Jobs without a snapshot (legacy records) still follow the global default; the existing fallback chain still handles a snapshot provider that fails to resolve. Both goals of #44585 hold: no silent inherit of a paid default (the job runs on what it was created under) and no outage. Owner decision (Teknium): "main agent model changing should not stop crons from executing, ever". Removed as unreachable: _check_model_drift, DRIFT_SKIP markers, the drift_alerted alert-once bit (mark_drift_alerted + the _record_run_outcome pop), the drift special-cases in _compose_run_delivery and _summarize_cron_failure_for_delivery, cron_model_drift_guard_enabled and the cron.model_drift_guard config key (v42 migration drops it from existing configs). The PLUGIN-COMPAT clear_drift_alerted block is untouched (scheduled revert). The `hermes config set model.default` notice and the Desktop model-change toast are reworded from "will fail closed / will be skipped" to "keep running on the model they were created under"; the impact payload drops guard_enabled (all six desktop locales updated).