Related: #136257
Projection owner: #144762
## What Problem This Solves
Quick Chat could keep stale model choices after a catalog update and did not expose the published Fast setting. Its picker must preserve the Gateway's availability and thinking decisions, including refusal guidance and selectable rows whose availability is unknown.
## Why This Change Was Made
Quick Chat consumes the shared OpenClawKit catalog projection introduced in #144762. Both chat surfaces now use one Fast-state projection. Model and speed changes use the existing session-settings route lease and target queue, then reload canonical catalog/session state. This removes the partial patch-response model/thinking derivation.
Catalog publications refresh the open picker without losing its draft; late reads cannot replace a reopened presentation. The nonactivating panel preserves Attach text and Paste reply targeting. Native tests exercise the registered shortcut callback and require the panel/editor to present even while the application does not own foreground.
## User Impact
- Refused model rows are disabled with the published guidance; unknown availability remains selectable.
- Effort labels come from the catalog, and speed offers Session default, Fast, and Normal when applicable.
- Settings changes settle before sending. Rejected speed changes preserve the retry key for an unchanged draft.
- Reopening Quick Chat retains the correct catalog and presentation state.
## Evidence
- [Connected native candidate](https://github.com/openclaw/openclaw/actions/runs/34584437164) passes at this exact PR head using the real Gateway fixture from #144762/run 34571594676. A real catalog publication refreshes the same Quick Chat presentation without losing its draft. Clearing a saved speed override and choosing the unknown-availability model both reload canonical session state. No inference server or transport mock was added.
- [Connected baseline](https://github.com/openclaw/openclaw/actions/runs/34585094303) reproduces the missing refresh on main `68b7893b`: the Gateway publishes the new model name, but Quick Chat retains the old name. Build, connection, and publication pass before the stale-name assertion fails. The baseline's existing test guard suppresses its panel, so this is publication-state red, not a visual baseline.
- [Exact-head CI](https://github.com/openclaw/openclaw/actions/runs/34583201846) passed.
- [Final targeted macOS run](https://github.com/openclaw/openclaw/actions/runs/34581841571): app/native builds, 2 XCTest UI cases, 83 Swift Testing cases, and 11 shared projection tests passed. Includes rendered model selection, effort, Fast/default, refused/unknown rows, publication, stale reads, and send retry behavior.
- [Earlier resumed run](https://github.com/openclaw/openclaw/actions/runs/34581142507): the same picker and lifecycle proof passed; its first attempt failed before compilation on an HTTP 500 while downloading SwiftLint.
- [Baseline picker red](https://github.com/openclaw/openclaw/actions/runs/34566007763): refused row enabled, guidance missing, and inferred effort options. The candidate's native menu records show the corrected states.
- The final rebase was followed by 67 passing config/state/recovery tests and real Gateway startup/list/create/command transport checks for all 17 sanitized config fixtures, with fake credentials and external networking disabled. Legacy roster used Doctor repair before startup.
- Focused catalog/auth protocol tests passed. Retained Telegram Test Server `/models` proof returned the provider selector with zero inference requests.
Original and connected native captures were inspected locally and by an independent validator. Artifacts retain native menu JSON, real Gateway/session records, and panel images. Panel captures have clipping/transition limits; they do not establish expanded-menu visual quality. The shortcut proof invokes the registered callback and observes a visible editor with application-active/key-window state false; it does not claim a physical key event, foreground ownership, signing, or permission grants.
The corpus also exposed an unchanged base issue: the generic-token `/models` command advertises an OpenAI fallback while the published catalog is empty. Startup and command transport succeed; complete command/catalog semantic parity is not claimed. This PR changes only native app code and its tests.
No protocol version or schema change. The temporary proof workflow is removed from this PR; its task staging branch is retired and artifacts are retained. No shipped test behavior is deleted; existing fixtures are adapted to the typed settings provider, and the new speed tests cover accepted and rejected writes.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>