model-failure.txt
Add proper failure handling around this model call: <paste>

Handle each distinctly — they need different responses:
- Rate limited (429). Back off and retry, respecting Retry-After.
- Timeout or network error. Retry with backoff, with a hard ceiling.
- Server error from the provider. Retry.
- Bad request (400). Do NOT retry — that's my bug. Log it loudly.
- Output that fails schema validation. Retry once with the error fed
  back, then give up.
- The model refusing or returning something unusable.

For each: what the user sees, and what gets logged. Never a raw
provider error shown to the user.

Then: is there a degraded mode where the feature still partly works
without the model?

Retrying a 400 forever is the classic mistake. It converts your bug into a rate-limit ban and a bill.