Optional ReadonlyisErrors to treat as neither retriable nor a real failure — the command still rejects, but
the runner does not burn a retry on it. Used for a pw-link "already linked" result,
which the caller reads as an idempotent success.
Optional Readonlymaxstdout cap in bytes. Default 64 MiB (a big/dirty pw-dump cannot overflow it).
Optional ReadonlyonCalled before each backoff+retry (diagnostics / tests).
Optional ReadonlyretriesHow many extra attempts after the first on a transient failure. Default 2.
Optional ReadonlyretryBackoff between attempts, in ms. Default 100.
Optional ReadonlytimeoutKill the child (SIGKILL) and reject if it has not exited within this many ms. Default 10000.
Tuning for createExecRunner (all optional; the defaults are production-safe).