MediaPipeModelManager
Manages the on-demand MediaPipe Gemma model file in app-private storage. The model binary is NEVER committed to the repo — download is user-triggered (surfaced on the settings screen via ModelManager) and lands in filesDir/models/, resuming from a .tmp if a prior attempt was cut off.
The URL is manifest-derived (ModelManifestEntry, gallery A5) and the fetch is a real resumable transfer (ResumableModelDownloader, gallery A4). download itself refuses to start when ModelManifestEntry.requiresLicenseAck is set and the caller didn't pass licenseAcknowledged = true, or when the active network is metered — a caller SHOULD still schedule this inside a wifi-only WorkManager foreground job (for the FGS notification and to survive process death mid-transfer), but a caller that skips that no longer burns 555MB of cellular data or a gated model's license by omission; this class is the last line of defense, not the only one.