fix(link): honor the caller's PL request timeout master
PlHttpSession.post() and .get() accepted a timeout but discarded it. Private-link requests were instead bounded by a constant named for session establishment, and that bound also covered the request-body send. Rename the timeout constant and TunnelClient constructor keyword to describe what they bound: _REQUEST_TIMEOUT_SECONDS and request_timeout=. Move the default from 30s to 180s so a worst-case segment body fits on a slow link while a wedged tunnel remains bounded. All three public entry points, request, stream_request, and proxy_stream_request, now accept a per-request timeout. Precedence is per-request argument, then constructor keyword, then module constant, resolved in one helper. The bound remains; it is now the caller's bound. Response-tail streaming stays outside it. Co-Authored-By: GPT-5 Codex <noreply@openai.com>