Evidence record / flue
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-09-21-flue-2-1-0-per-tool-timeoutms-mcp-tool-annotations-preserved-configurable-trace-budgets
2.1.0: per-tool timeoutMs, MCP tool annotations preserved, configurable trace budgets. A tool can declare timeoutMs; on expiry the harness aborts
the tool’s signal and settles a ToolTimeoutError the model sees, so one hung
call no longer eats the submission’s durability budget. Tools from
createMcpConnection() now carry server-sent annotations (for example
destructiveHint); the release notes state Flue does not change behavior based
on them and the docs call them not a security boundary. Trace content budget
per span is settable.
Channel: tagged-release (preceded by 2.1.0-next.0 and next.1 preview-or-beta). Half: capability. Date: 2026-09-18.
Operator consequence: Try timeoutMs on every network-bound tool; it
removes a hand-rolled AbortController wrapper. MCP annotations let your own
approval gate read destructiveHint, but they are server-asserted: gate on them
only for servers you trust. If you run Workers AI dynamic models, 2.0.8’s warning
is the first signal that your cost dashboards showed $0 for unknown, not free.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-flue-2-1-0-per-tool-timeoutms-mcp-tool-annotations-preserved-configurable-trace-budgets
Profile citations
- Flue / claim / tool-timeout-and-mcp-annotations-2-1-0
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact