DEFAULT_MAX_RESULT_LENGTH

How many characters in total one evaluation may produce.

Charged against a running total held by the evaluation, not against each string separately. Per-string was the same number and a much weaker bound: an expression can hold any number of sibling arguments, each producing its own string up to the limit and all of them retained at once while the call is assembled, so a budget of one megabyte admitted thousands of them.

It counts characters built, not characters returned, so a string that passes through N nested calls is charged N times — it was genuinely allocated N times, and both buffers of each level are live at once. That makes this a bound on what an expression costs rather than on how long its answer is, which is the quantity worth bounding when the expression comes from an agent.

Charged before each piece is built rather than after, so that a formatString interpolating a megabyte-long value a thousand times fails while allocating the first megabyte instead of the thousandth — the same ordering dev.ynagai.a2ui.core.surface.walk needs for its instance budget.