TODO.md L4: with a dead model endpoint the sync discovered it only
mid-import, after slow clones — and a tooltip on the button is not a
readable error.
- app/rag/llm.py: ModelUnavailableError + check_models(llm) — a tiny
pre-sync probe (one short embedding + one 1-token-scale completion)
that fails naming the unavailable model (embed first, then the
summary model); the sync sanitizer still masks credentials.
- app/api/sync.py: the probe is step 1 of _run_sync — before source
resolution and before any clone_or_pull; a model failure is just
another 'failed' state (no new endpoint, A10/A12 untouched).
- frontend/assets/header.js: applySyncFailure now also opens the
module-owned error modal (every page carrying #sync-btn, zero
page-markup changes): lazily built backdrop + role=alertdialog
panel, error text via textContent, close via button / Esc /
backdrop, focus in-and-out to #sync-btn (with a body→#sync-btn
fallback — the run's disabled button drops focus to <body>).
- frontend/assets/styles.css: the modal on the phase-08 error palette
(z-index above the header, .is-open open/close, reduced-motion
stilling, 44px close target).
- Tests: probe unit tests (both up / embed down / summary down /
custom model names), sync integration (fail-fast before any clone,
probe-before-effective_sources ordering, credential masking,
healthy regression), the phase-41 source pins, and the story E2E
(two module apps on distinct ports — dead endpoint on a closed
loopback port vs session mock: ≤10 s fail-fast + modal contract,
all three dismissal paths with focus out to #sync-btn, button
title/.is-error + Sources banner untouched, healthy phase-32
lifecycle regression to 'Synced HH:MM').
E2E (isolation): test_sync_model_down.py 4/4, test_sync_button.py
3/3, test_git_sources_admin.py 6/6, test_local_directory_sources.py
3/3; unit+integration 721 passed, app/ coverage 99%; ruff + pyright
clean.