URL to fetch.
Optional timeoutMsOverride (e.g. for cache-validation
probes that want shorter windows than data fetches) and a
caller signal for cancellation propagation. The caller signal is
merged with the per-attempt timeout signal so either abort source
wins immediately. lane selects the bounded data or metadata pool.
onExhausted receives the final retryable error. A caller-aborted call
exits without consuming retry budget.
Runs inside the global fetch-gate lease. Call readBody()
to consume a response with a no-progress watchdog; returning without
reading cancels the body before the lease is released.
The consumer result, or undefined after abort or retry exhaustion.
Fetch with retries for transient failures.
4xx responses are returned immediately because retrying cannot fix a missing zarr key. Network errors, timeouts, 429, and 5xx responses are retried using the configured retry budget. The configured timeout is split across attempts and applied separately to time-to-headers and aggregate body-progress stalls. A quiet HTTP/2 stream remains valid while any live fetch is receiving bytes. Once body reading begins, an absolute deadline — the longer of eight stall windows or
Content-Lengthdivided by a 16 KiB/s aggregate floor, scaled by at most eight concurrent leases — bounds both a zero-byte response and a true trickle.