The enforcer now reads ctx.tools.get(exec.name).timeoutMs instead of a free-text tool-name config map, so a mistyped name is impossible and the tools/change warn-once apparatus is gone. exec.name always resolves in the registry during dispatch, so there is no unknown-name path to warn about.
timeout/ — tool-call timeout policy
The tool-call timeout policy plugin. A single product package: it is a deployment-policy consumer of the tools/execute around-dispatch seam (owned by dsh-tools) and the pure dsh-timeout library — not a swappable capability with an interface/implementation split, so it needs no seam trio.
| Package | Role | ctx key |
|---|---|---|
timeout-policy/ |
A tools/execute wrapper: for each configured tool it arms a per-call deadline on exec.signal and returns a structured TOOL_TIMEOUT result when that deadline wins |
(registers a tools/execute listener; injects nothing) |
Timeout is split across three layers: dsh-timeout owns the pure timing/classification primitive (deadline/timeoutOf), each capability owns termination (bash kills its process group, the fetch provider tears down its socket), and this package owns the model-facing tool-call budget as deployment policy — no model-facing timeout argument, no global default. It is the middleware the timeout-library RFC foresaw. bash and hook command execution keep their own BASH_TIMEOUT backend timeout and do not route through this policy.