set sd_model for API later, inside the lock, to prevent multiple requests with different models ending up with incorrect results #5877 #6012