| 270 | // sets the knob and typos it should find out at boot, not by watching a |
| 271 | // runaway execution use the 5-minute default. |
| 272 | const resolveSandboxTimeoutMs = (): number | undefined => { |
| 273 | const raw = process.env.EXECUTOR_SANDBOX_TIMEOUT_MS; |
| 274 | if (!raw) return undefined; |
| 275 | const parsed = Number(raw); |
| 276 | if (!Number.isFinite(parsed) || parsed <= 0) { |
| 277 | // oxlint-disable-next-line executor/no-try-catch-or-throw, executor/no-error-constructor -- boundary: refuse to boot on a malformed operator knob |
| 278 | throw new Error( |
| 279 | `EXECUTOR_SANDBOX_TIMEOUT_MS ${JSON.stringify(raw)} is not a positive number of milliseconds`, |
| 280 | ); |
| 281 | } |
| 282 | return Math.floor(parsed); |
| 283 | }; |
| 284 | |
| 285 | // How long an MCP session may sit idle before the store evicts it. 0 disables |
| 286 | // eviction, which restores the old behaviour of holding every session for the |