a1e60c3450
Final review found `pendingRetryFallbackModel` unreachable. `servingModel` returns `undefined` only when the session has no model at all, and the pending getter required one, so the badge term guarding on it could never fire. Its case — a fallback armed before anything has served — is already answered by `servingModel`'s bootstrap, which names the current model and flags it as fallback-routed. Removed, the same duplicate-surface cleanup that removed `retryFallbackModel`. Attribution now anchors on the session id rather than the session file. An unpersisted session has no file, so two `undefined`s compared equal and stale attribution survived `/new` and branch switches there; every real switch mints a new id, persisted or not. The cooldown-expiry restore keeps `#fallbackRouted` when the stored primary selector cannot be parsed. Nothing is restored on that path, so the session is still running on the fallback and its remaining turns are still fallback work; clearing the flag reported them as the configured primary. `executor-prewalk`'s fake session predates this work and never set `servingModel`, so the prewalk hand-off stopped advancing the reported model once the executor began reading attribution from the session. It now mirrors the hand-off the way the other executor fixtures do.