Filing gate ①, class (b), with reach: measured at a public door: a published runtime contract and its reader disagree, and the user reads the wrong cause.
Reader: the objectstack-wide triage seat's first touch. It grades the card and routes the fix to one of two repos: the consumer's reading in objectui, or the producer's payload in objectstack. Then the execution seat that claims it acts.
Dedupe: mcp__github__search_issues, closed included:
What happens
On the 2026-10-06 console dogfood sweep's CLI showcase runtime (objectui#11672), Browse Marketplace showed this hint under a load error:
This runtime serves the marketplace catalog itself. Check that the runtime is online.
The same request had been forwarded to cloud.objectos.ai: the error named that host, 403 Host not in allowlist: cloud.objectos.ai. The runtime does not serve the catalog itself. It proxies a control plane.
- The producer, objectstack
main at f0022c46: packages/cli/src/commands/serve.ts. Serve.RUNTIME_CONFIG_OPTIONS is one frozen object (about :1712–:1720) with controlPlaneUrl: ''. Both arms mount it, the cloud-connected one included (new RuntimeConfigPlugin({ ...Serve.RUNTIME_CONFIG_OPTIONS }), about :3845 and :3901). On the cloud-connected arm, MarketplaceProxyPlugin is mounted with the resolved marketplaceUrl (about :3829). With no explicit URL, resolveCloudUrl resolves to DEFAULT_CLOUD_URL = 'https://cloud.objectos.ai' (packages/cloud-connection/src/cloud-url.ts about :12, :39–:44). The block's own docblock says '' is the deliberate "stay on this origin" spelling for RuntimeConfigPlugin.
- The reader, objectui:
packages/app-shell/src/console/marketplace/MarketplacePage.tsx draws marketplace.load.failedHintSameOrigin when cloudUrl is ''. objectui's runtime-config.ts documents '' as "same-origin (i.e. the runtime we're attached to is the cloud)". That reading is stronger than the producer's ("stay on this origin" describes where requests go, not who serves the catalog).
- After PR objectui#11724 (in flight), the hint no longer shows under an answered refusal such as the 403. It still shows on such a runtime for a network failure or a 502 / 503 / 504, and there it still names the wrong server.
Done when
- On a runtime whose marketplace proxy forwards to a control plane, the load-error hint names that plane (or names none), and never says the runtime serves the catalog itself. On a runtime that really is the control plane, or an air-gapped one, it is unchanged.
- The runtime-config contract's
cloudUrl (or whatever key triage picks) means one thing on both sides, written in both repos' docs.
- Pins: the cloud-connected CLI arm, with the default plane, gets a hint that names
cloud.objectos.ai (or no same-origin claim). The air-gapped arm and a configured plane keep their current hints.
Not this card: the proxy forwarding a foreign hop's text/plain refusal verbatim instead of in its own error envelope. That is recorded in PR objectui#11724's Acceptance notes.
Dedupe words: failedHintSameOrigin · cloudUrl empty same origin · serves the marketplace catalog itself · RUNTIME_CONFIG_OPTIONS controlPlaneUrl · MarketplaceProxyPlugin default cloud
Filed by the domain:ui execution seat 2 (session_01FngvPpdrnhHMdHHq6vwwju), from the out-of-scope findings of objectui#11688's dev report. ⛔ Not graded or routed here; ⛔ not a claim.
Generated by Claude Code
Filing gate ①, class (b), with
reach:measured at a public door: a published runtime contract and its reader disagree, and the user reads the wrong cause.Reader: the objectstack-wide triage seat's first touch. It grades the card and routes the fix to one of two repos: the consumer's reading in objectui, or the producer's payload in objectstack. Then the execution seat that claims it acts.
Dedupe:
mcp__github__search_issues, closed included:groupBy#8356 (features.marketplaceasserted unconditionally), docs-gates: bring docs/adr/** and docs/audits/** into the doc-snippet walk, ledger-first (objectui#7856 card 2) #8357, refactor(app-shell): drop the redundant unknown[] assertion in useReconcileOnError #8389, finding(plugin-calendar): theObjectCalendarrenderer carries a lenient alias ladder (dateField/startField) that no published declaration spells — decide whether the aliases stay, are declared, or are refused #8355, #14514 and #15353. Those are the positive control for the query.cloudUrl: ''means.What happens
On the 2026-10-06 console dogfood sweep's CLI showcase runtime (objectui#11672), Browse Marketplace showed this hint under a load error:
The same request had been forwarded to
cloud.objectos.ai: the error named that host,403 Host not in allowlist: cloud.objectos.ai. The runtime does not serve the catalog itself. It proxies a control plane.mainatf0022c46:packages/cli/src/commands/serve.ts.Serve.RUNTIME_CONFIG_OPTIONSis one frozen object (about:1712–:1720) withcontrolPlaneUrl: ''. Both arms mount it, the cloud-connected one included (new RuntimeConfigPlugin({ ...Serve.RUNTIME_CONFIG_OPTIONS }), about:3845and:3901). On the cloud-connected arm,MarketplaceProxyPluginis mounted with the resolvedmarketplaceUrl(about:3829). With no explicit URL,resolveCloudUrlresolves toDEFAULT_CLOUD_URL = 'https://cloud.objectos.ai'(packages/cloud-connection/src/cloud-url.tsabout:12,:39–:44). The block's own docblock says''is the deliberate "stay on this origin" spelling forRuntimeConfigPlugin.packages/app-shell/src/console/marketplace/MarketplacePage.tsxdrawsmarketplace.load.failedHintSameOriginwhencloudUrlis''. objectui'sruntime-config.tsdocuments''as "same-origin (i.e. the runtime we're attached to is the cloud)". That reading is stronger than the producer's ("stay on this origin" describes where requests go, not who serves the catalog).Done when
cloudUrl(or whatever key triage picks) means one thing on both sides, written in both repos' docs.cloud.objectos.ai(or no same-origin claim). The air-gapped arm and a configured plane keep their current hints.Not this card: the proxy forwarding a foreign hop's
text/plainrefusal verbatim instead of in its own error envelope. That is recorded in PR objectui#11724's Acceptance notes.Dedupe words:
failedHintSameOrigin·cloudUrl empty same origin·serves the marketplace catalog itself·RUNTIME_CONFIG_OPTIONS controlPlaneUrl·MarketplaceProxyPlugin default cloudFiled by the
domain:uiexecution seat 2 (session_01FngvPpdrnhHMdHHq6vwwju), from the out-of-scope findings of objectui#11688's dev report. ⛔ Not graded or routed here; ⛔ not a claim.Generated by Claude Code