Two availability gaps listed in Architecture/10-Known-Gaps (not filed):
- Pushes have no concurrency limit.
max_pack_bytesbounds each receive-pack, not how many run at once, so a few accounts pushing large packs together can take every core and the disk on bay1 (4 cores). Uploads are bounded since #262 (internal/packlimit). repo download(SSH, API) runsgit archiveoutside the pack limit; only its two-minute deadline and 512 MiB cap bound it. The web archive route already takes a slot.
Put receive-pack under a limit with the same shape as #262 (global cap, per-principal cap, bounded queue with a wait, busy refusals per transport), either the same limiter or a separate budget for pushes so a clone storm cannot starve pushes and the reverse; and take a pack slot for repo download. Config under [limits], Admin/Performance/Threat-Model, Known-Gaps rows removed. Also drop the Known-Gaps row for grants and deploy keys of deleted rows, fixed by #306.
closed by cmc in commit db01bf4fad: wiki, changelog: push limit and repo download under the pack limit
2026-09-29 17:11 UTC