receive-pack takes a slot from its own limiter ([limits] push_concurrency 2, push_per_principal 1, push_queue 16, push_queue_wait 60s; a deploy key is its own principal), held through post-receive. A push is cut when nothing moves either way for push_idle (60s) once its pack starts or pre-receive begins, with receive.keepAlive set so hooks keep it alive, or when it has not reached pre-receive by push_receive_timeout (15m). repo download takes a pack slot; a limiter refusal is 503 with Retry-After on the API. Admin/Performance/Threat-Model/Controls/Known-Gaps (the #306 access row removed)/CHANGELOG.
Closes #308