| 382 | const TOOLS_SYNC_TTL_DISABLE_TOKENS = new Set(["off", "null", "false"]); |
| 383 | |
| 384 | const resolveToolsSyncTtlMs = (): number | null | undefined => { |
| 385 | const raw = process.env.EXECUTOR_TOOLS_SYNC_TTL_MS?.trim(); |
| 386 | if (!raw) return undefined; |
| 387 | if (TOOLS_SYNC_TTL_DISABLE_TOKENS.has(raw.toLowerCase())) return null; |
| 388 | const parsed = Number(raw); |
| 389 | // `isSafeInteger`, not `isInteger`: past 2^53 a decimal literal silently |
| 390 | // rounds to a nearby representable value, so an operator's typo'd digit |
| 391 | // would boot as a TTL they never wrote. Refuse it instead. |
| 392 | if (!Number.isSafeInteger(parsed)) { |
| 393 | // oxlint-disable-next-line executor/no-try-catch-or-throw, executor/no-error-constructor -- boundary: refuse to boot on a malformed operator knob |
| 394 | throw new Error( |
| 395 | `EXECUTOR_TOOLS_SYNC_TTL_MS ${JSON.stringify(raw)} is not an exactly representable whole number of milliseconds ("off", "null" or "false" disable time-based re-sync)`, |
| 396 | ); |
| 397 | } |
| 398 | if (parsed < 0) { |
| 399 | // oxlint-disable-next-line executor/no-try-catch-or-throw, executor/no-error-constructor -- boundary: refuse to boot on a malformed operator knob |
| 400 | throw new Error( |
| 401 | `EXECUTOR_TOOLS_SYNC_TTL_MS ${JSON.stringify(raw)} must not be negative (use "off" to disable time-based re-sync)`, |
| 402 | ); |
| 403 | } |
| 404 | return parsed; |
| 405 | }; |