## ADDED Requirements ### Requirement: Hard result limit is separate from baseline reservation The system SHALL retain the configured hard result-bundle byte limit while charging each new remote assignment a separately configured 2 MiB baseline bundle reservation and 2 MiB baseline projection reservation. #### Scenario: Remote assignment is issued - **WHEN** an eligible worker claims an assignment with available global and user quota - **THEN** the assignment advertises the unchanged hard bundle limit and pipeline accounting charges only the configured baseline bundle and projection reservations #### Scenario: Local assignment is issued - **WHEN** the server admits a local scan - **THEN** its existing worst-case capacity reservation behavior remains unchanged ### Requirement: Actual bundle size expands accounting safely The system SHALL atomically grow a remote reservation's charged bundle bytes to the validated actual bundle size before issuing an acceptance receipt. #### Scenario: Bundle exceeds baseline with capacity available - **WHEN** a valid bundle is larger than 2 MiB but does not exceed the hard result limit and aggregate bundle capacity is available - **THEN** the system increases the persisted reservation and pipeline capacity charge exactly once and accepts the bundle #### Scenario: Bundle exceeds baseline without capacity available - **WHEN** a valid bundle requires additional bundle capacity that is temporarily unavailable - **THEN** the system does not issue an acceptance receipt and permits the worker to retry the identical durable upload later ### Requirement: Actual projection size expands accounting safely The system SHALL grow a leased projection job's capacity to its serialized aggregate byte size before appending output. #### Scenario: Projection exceeds baseline with headroom available - **WHEN** serialization exceeds the baseline projection reservation and configured projection capacity is available - **THEN** the system atomically increases the job and pipeline charge before appending output #### Scenario: Projection exceeds baseline without headroom available - **WHEN** the additional projection capacity is temporarily unavailable - **THEN** the system returns the untouched job to pending without quarantine and retries it later ### Requirement: Global remote assignment limit The system SHALL enforce a configured global maximum of 50 unresolved remote assignments atomically in addition to each user's assignment cap. #### Scenario: Fiftieth assignment is admitted - **WHEN** 49 unresolved remote assignments exist and all other admission constraints are open - **THEN** one additional assignment is admitted #### Scenario: Fifty-first assignment is refused - **WHEN** 50 unresolved remote assignments exist - **THEN** another claim receives normal no-work backpressure without creating a reservation #### Scenario: Assignment resolves - **WHEN** an unresolved assignment receives a terminal resolution or expires - **THEN** its global slot becomes available for a subsequent claim ### Requirement: Capacity survives migration and reconciliation The system MUST preserve exact capacity accounting for reservations created before and after deployment. #### Scenario: Existing reservation is migrated - **WHEN** the additive schema migration encounters a reservation without a distinct bundle reservation value - **THEN** it backfills the value from the existing declared bundle bytes #### Scenario: Capacity is reconciled - **WHEN** pipeline capacity is rebuilt from durable state - **THEN** it sums each reservation's persisted bundle, projection, candidate, job, and quarantine charges exactly once