9772e3b189
The remaining /model picker stall after the Copilot backoff fix: whenever the 1h provider-models disk cache TTL (or the remote model-catalog manifest TTL) lapsed mid-session, the next picker open blocked on 8-9 serial /v1/models round-trips (~2-3s measured) plus the catalog manifest fetch before rendering anything. Model catalogs change on release timescales, not hourly — so both caches now use stale-while-revalidate: - cached_provider_model_ids(): an expired entry whose credential fingerprint still matches is served immediately; a deduped daemon thread re-fetches the live catalog and rewrites the disk cache for the next open. Entries older than 7 days still block on a live fetch, credential rotation still busts the entry, and force_refresh still bypasses SWR. - model_catalog.get_catalog(): an expired disk manifest is served immediately with an off-thread refresh; only a truly cold cache (no disk copy) blocks on the network. Measured picker payload build with deliberately-expired caches: 2.9s -> 0.93s (first open in process) / 0.06s (subsequent opens). Combined with the Copilot fix (#76386): 7.3s -> ~0.06s for the common case.