limits: bound concurrent pushes; put repo download under the pack limit #308

closed cmc opened this on 2026-09-29 16:25 UTC · security

Discussion

cmc 2026-09-29 16:25 UTC

Two availability gaps listed in Architecture/10-Known-Gaps (not filed):

  • Pushes have no concurrency limit. max_pack_bytes bounds each receive-pack, not how many run at once, so a few accounts pushing large packs together can take every core and the disk on bay1 (4 cores). Uploads are bounded since #262 (internal/packlimit).
  • repo download (SSH, API) runs git archive outside the pack limit; only its two-minute deadline and 512 MiB cap bound it. The web archive route already takes a slot.

Put receive-pack under a limit with the same shape as #262 (global cap, per-principal cap, bounded queue with a wait, busy refusals per transport), either the same limiter or a separate budget for pushes so a clone storm cannot starve pushes and the reverse; and take a pack slot for repo download. Config under [limits], Admin/Performance/Threat-Model, Known-Gaps rows removed. Also drop the Known-Gaps row for grants and deploy keys of deleted rows, fixed by #306.

closed by cmc in commit db01bf4fad: wiki, changelog: push limit and repo download under the pack limit

2026-09-29 17:11 UTC

referenced in commit d4ea40c36c by cmc: httpd: a command a limiter turned away is 503 with Retry-After on the API

2026-09-29 17:11 UTC

referenced in commit 03e34fb24d by cmc: sshd: cut a push idle for push_idle or not at pre-receive by push_receive_timeout

2026-09-29 17:11 UTC

referenced in commit 1ac5d04bdb by cmc: control: repo download takes a pack slot

2026-09-29 17:11 UTC

referenced in commit 568b879143 by cmc: sshd: receive-pack takes a slot from its own push limit

2026-09-29 17:11 UTC

referenced in commit 973797757f by cmc: config: push_concurrency, push_per_principal, push_queue, push_queue_wait

2026-09-29 17:11 UTC