Ceiling for a single ingest request's IDLE-socket timeout. The retry runner
only checks its budget BETWEEN attempts, so one attempt that hangs forever
(a peer that accepts the connection and then goes silent — a black-holed
route, a wedged agent) never rejects and the delivery budget never applies.
Every ingest request therefore arms req.setTimeout, which fires only after
this long with NO bytes moving in either direction — an active transfer keeps
resetting it, so a slow-but-progressing upload is never killed.
Ceiling for a single ingest request's IDLE-socket timeout. The retry runner only checks its budget BETWEEN attempts, so one attempt that hangs forever (a peer that accepts the connection and then goes silent — a black-holed route, a wedged agent) never rejects and the delivery budget never applies. Every ingest request therefore arms
req.setTimeout, which fires only after this long with NO bytes moving in either direction — an active transfer keeps resetting it, so a slow-but-progressing upload is never killed.