v3.0.0: request hedging and deadline propagation
Idempotent requests that run longer than the route's observed p95 (or a fixed hedge.after_ms) now get a second attempt on another replica; the first successful answer is relayed and the loser is cancelled without recording anything on its breaker. Requests can carry an end-to-end budget through X-Request-Timeout or X-Request-Deadline, and routes can set a default deadline_seconds: the budget clamps every attempt timeout, is forwarded to upstreams with the remaining time, and stops a retry whose backoff would end past the deadline, answering 504 instead. Four new metrics cover hedges fired and won, the live hedge delay and deadline failures, and the chaos summary prints them. 88 tests.