INNER CODE UNIT · Python
_env
tiliondev/fortress · mcp/server.py:32
def _env(name: str, default: str | None = None) -> str | None:
"""Read a config var tolerant of BOTH brand prefixes during the migration:
the new one-L `TILION_*` first, then the legacy two-L `TILLION_*` the server
core still uses — so an operator isn't silently unconfigured across the
facade/server boundary. (The arham->tilion rename unifies these.)"""
return os.environ.get(f"TILION_{name}", os.environ.get(f"TILLION_{name}", default))
# Per-tool wall-clock cap: a hung nav/crawl must NOT wedge the shared browser (it
# holds a per-origin lock). On timeout the coroutine is cancelled (unwinding the
# lock) and a structured error is returned. Tune via env.
_TOOL_TIMEOUT = float(_env("MCP_TOOL_TIMEOUT", "120"))
def _safe(fn):
"""Error boundary for a tool: enforce a wall-clock timeout AND on any failure
return a STRUCTURED error the agent can reason about ({status:'error', error})
instead of an opaque protocol error, so a bad/slow call never crashes or wedges