Skip to content

diu-stop: the marker gate reads prose, so a mention is not a use - #785

Merged
mergify[bot] merged 1 commit into
mainfrom
stack/EdbertChan/reflect/subagent-decisions-slot-20260922/diu-stop-marker-gate-reads-prose-mention-use--8d19b383
Sep 24, 2026
Merged

mergify[bot] merged 1 commit into
mainfrom
stack/EdbertChan/reflect/subagent-decisions-slot-20260922/diu-stop-marker-gate-reads-prose-mention-use--8d19b383

Conversation

@EdbertChan

@EdbertChan EdbertChan commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Summary

The gate that checks escape-hatch tags reads the raw reply, with no allowance for quoting.

So explaining the tag to someone trips it, and quoting the rule that defines it trips the very gate that enforces that rule.

It now skips fenced and inline code the way its sibling check already does, so naming the tag is not the same as using one.

Review Claim

A tag inside code formatting is a mention and does not trip the gate; a real malformed tag still does.

Review Lane

behavior

Review Unit

engine-runtime

Safety Invariant

A genuine tag with no blocker named still blocks, which is the gate's whole purpose. Only quoted and fenced spans are exempt, and the stripping reuses the function already used by the neighbouring check rather than a second copy.

Slice Rationale

One scanner's input, plus fixtures. Separate from the citation change in the same file because either can be reverted alone.

Non-goals

Does not change the tag format, and does not touch where a tag may appear in a reply.

Test Plan

Test Plan

Run at this commit:

python3 engine/hooks/diu-stop/tests/test_hooks.py
Ran 94 tests in 1.280s
OK

Must stay silent: a quoted mention, a mention in a fenced block, a verbatim quote of the rule. Must still fire: a real tag naming no blocker.

Revert Plan

Revert Plan

Revert this commit. Explaining or quoting the tag trips the gate again, as on main.


Note

Low Risk
Narrows marker enforcement to prose only; genuine malformed tags in prose still block, with broad unit test coverage.

Overview
The diu-stop malformed-tag and legacy UNVERIFIED: checks used to scan the full assistant message, so explaining {{CAT-UNVERIFIED}}, quoting the prove-it rule, or pasting the gate’s own refusal text could block the turn even though those tokens were not being used as escape hatches.

find_marker_problems now runs on prose only via new prose_only, which strips fenced blocks and inline backticks (same regexes as the unverified-claim path) and treats everything after an unclosed fence as non-prose. Malformed tags and bare legacy markers in running prose still block.

The README documents this distinction (mention vs use). Tests cover backticks, fences, verbatim rule quotes, relayed gate messages, unclosed fences, and regressions that real misuse in prose still fires.

Reviewed by Cursor Bugbot for commit 51ed95a. Bugbot is set up for automated code reviews on this repo. Configure here.

@EdbertChan

EdbertChan commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner Author

This pull request is part of a Mergify stack:

# Pull Request Link
1 wrong-check-reflect: one shot per reply, and scope the reflect scan to the turn #796
2 reflect: catch an evidence-order correction from the ledger transition, not from wording #782
3 unverified-tag-ledger: gate the next-prompt reminder, default to stale only #783
4 diu-stop: a file citation buys silence only when it is backed #784
5 diu-stop: the marker gate reads prose, so a mention is not a use #785 👈
6 cat-mode: show the escape-hatch tag in the form the gate accepts #786
7 principle-subagent-inherits-scope: a brief carries decisions, not just facts and a question #788
8 llm-judge: claude is the only default runner #793

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit a993989. Configure here.

Comment thread engine/hooks/diu-stop/claude_stop_check.py
Comment thread engine/hooks/diu-stop/claude_stop_check.py
@EdbertChan
EdbertChan force-pushed the stack/EdbertChan/reflect/subagent-decisions-slot-20260922/diu-stop-file-citation-buys-silence-only-backed--9ece412c branch from e409545 to d01a1ea Compare September 22, 2026 18:38
@EdbertChan
EdbertChan force-pushed the stack/EdbertChan/reflect/subagent-decisions-slot-20260922/diu-stop-marker-gate-reads-prose-mention-use--8d19b383 branch from a993989 to a0e5d05 Compare September 22, 2026 18:38
@EdbertChan

EdbertChan commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner Author

Revision history

# Type Changes Reason Date
1 initial a993989 2026-09-22 18:38 UTC
2 rebase a993989 → a0e5d05 (rebase only) 2026-09-22 18:38 UTC
3 rebase a0e5d05 → 950a355 (rebase only) 2026-09-23 14:06 UTC

@EdbertChan
EdbertChan force-pushed the stack/EdbertChan/reflect/subagent-decisions-slot-20260922/diu-stop-marker-gate-reads-prose-mention-use--8d19b383 branch from a0e5d05 to 950a355 Compare September 23, 2026 14:06
@EdbertChan
EdbertChan force-pushed the stack/EdbertChan/reflect/subagent-decisions-slot-20260922/diu-stop-file-citation-buys-silence-only-backed--9ece412c branch from d01a1ea to 2166b85 Compare September 23, 2026 14:06
@EdbertChan
EdbertChan force-pushed the stack/EdbertChan/reflect/subagent-decisions-slot-20260922/diu-stop-marker-gate-reads-prose-mention-use--8d19b383 branch from 950a355 to b0e1eea Compare September 24, 2026 08:29
@EdbertChan
EdbertChan force-pushed the stack/EdbertChan/reflect/subagent-decisions-slot-20260922/diu-stop-file-citation-buys-silence-only-backed--9ece412c branch from 2166b85 to 717a1f8 Compare September 24, 2026 08:29
@cursor

cursor Bot commented Sep 24, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_213db62d-5218-49d4-a646-5736c5d7ac68)

@EdbertChan
EdbertChan changed the base branch from stack/EdbertChan/reflect/subagent-decisions-slot-20260922/diu-stop-file-citation-buys-silence-only-backed--9ece412c to main September 24, 2026 09:40
@mergify

mergify Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Queued — the merge queue status continues in this comment ↓.

@EdbertChan

Copy link
Copy Markdown
Owner Author

Mergify repair stopped: GitHub reports merge conflict. The retry cap was reached for current head b0e1eea.

find_marker_problems ran markers.TAG_RE and the legacy-marker check over the
raw message. find_unverified_claims, ten lines below it, already stripped
fenced blocks and inline code and never shared that with the marker check.

The result: explaining the tag tripped the gate, and so did quoting
cat-mode's own rule, and so did relaying this gate's refusal word for word --
which cat-mode/SKILL.md:55 asks for.

  $ printf '%s' '{"last_assistant_message":"The escape hatch is
    `{{CAT-UNVERIFIED}}` and it has to name a blocker."}' \
      | python3 engine/hooks/diu-stop/claude_stop_check.py
  exit=2
  A `{{CAT-UNVERIFIED}}` tag here names no blocker. ...

After: exit=0, no output. A tag in running prose with no blocker named still
exits 2.

An unterminated fence drops everything after the marker it left behind,
rather than letting the unclosed block read as prose.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Change-Id: I8d19b3831299b0b18d5b31288017b1b0fff9cd21
@EdbertChan
EdbertChan force-pushed the stack/EdbertChan/reflect/subagent-decisions-slot-20260922/diu-stop-marker-gate-reads-prose-mention-use--8d19b383 branch from b0e1eea to 51ed95a Compare September 24, 2026 10:05
@EdbertChan

Copy link
Copy Markdown
Owner Author

@Mergifyio queue

@cursor

cursor Bot commented Sep 24, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_c8f5f4af-02bc-4d3a-8c79-30d6051e5898)

@mergify

mergify Bot commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

queue

🛑 The pull request has been removed from the queue admin-bypass

Details

The pull request #785 has been manually updated.

You can take a look at Mergify Merge Queue check runs for more details about the failure.

@EdbertChan

Copy link
Copy Markdown
Owner Author

@Mergifyio queue

@mergify

mergify Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Merge Queue Status

This pull request spent 19 minutes 22 seconds in the queue, including 18 minutes 55 seconds running CI.

Required conditions to merge
  • check-success = lint
  • check-success = test
  • check-success = validate

@mergify mergify Bot added the queued label Sep 24, 2026
@mergify mergify Bot mentioned this pull request Sep 24, 2026
6 tasks done
@mergify
mergify Bot merged commit e945c42 into main Sep 24, 2026
6 checks passed
@mergify mergify Bot removed the queued label Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant