diu-stop: the marker gate reads prose, so a mention is not a use - #785
Conversation
|
This pull request is part of a Mergify stack:
|
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit a993989. Configure here.
e409545 to
d01a1ea
Compare
a993989 to
a0e5d05
Compare
Revision history
|
a0e5d05 to
950a355
Compare
d01a1ea to
2166b85
Compare
950a355 to
b0e1eea
Compare
2166b85 to
717a1f8
Compare
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_213db62d-5218-49d4-a646-5736c5d7ac68) |
|
Queued — the merge queue status continues in this comment ↓. |
|
Mergify repair stopped: GitHub reports merge conflict. The retry cap was reached for current head b0e1eea. |
find_marker_problems ran markers.TAG_RE and the legacy-marker check over the
raw message. find_unverified_claims, ten lines below it, already stripped
fenced blocks and inline code and never shared that with the marker check.
The result: explaining the tag tripped the gate, and so did quoting
cat-mode's own rule, and so did relaying this gate's refusal word for word --
which cat-mode/SKILL.md:55 asks for.
$ printf '%s' '{"last_assistant_message":"The escape hatch is
`{{CAT-UNVERIFIED}}` and it has to name a blocker."}' \
| python3 engine/hooks/diu-stop/claude_stop_check.py
exit=2
A `{{CAT-UNVERIFIED}}` tag here names no blocker. ...
After: exit=0, no output. A tag in running prose with no blocker named still
exits 2.
An unterminated fence drops everything after the marker it left behind,
rather than letting the unclosed block read as prose.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Change-Id: I8d19b3831299b0b18d5b31288017b1b0fff9cd21
b0e1eea to
51ed95a
Compare
|
@Mergifyio queue |
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_c8f5f4af-02bc-4d3a-8c79-30d6051e5898) |
🛑 The pull request has been removed from the queue
|
|
@Mergifyio queue |
Merge Queue Status
This pull request spent 19 minutes 22 seconds in the queue, including 18 minutes 55 seconds running CI. Required conditions to merge
|

Summary
The gate that checks escape-hatch tags reads the raw reply, with no allowance for quoting.
So explaining the tag to someone trips it, and quoting the rule that defines it trips the very gate that enforces that rule.
It now skips fenced and inline code the way its sibling check already does, so naming the tag is not the same as using one.
Review Claim
A tag inside code formatting is a mention and does not trip the gate; a real malformed tag still does.
Review Lane
behavior
Review Unit
engine-runtime
Safety Invariant
A genuine tag with no blocker named still blocks, which is the gate's whole purpose. Only quoted and fenced spans are exempt, and the stripping reuses the function already used by the neighbouring check rather than a second copy.
Slice Rationale
One scanner's input, plus fixtures. Separate from the citation change in the same file because either can be reverted alone.
Non-goals
Does not change the tag format, and does not touch where a tag may appear in a reply.
Test Plan
Test Plan
Run at this commit:
Must stay silent: a quoted mention, a mention in a fenced block, a verbatim quote of the rule. Must still fire: a real tag naming no blocker.
Revert Plan
Revert Plan
Revert this commit. Explaining or quoting the tag trips the gate again, as on main.
Note
Low Risk
Narrows marker enforcement to prose only; genuine malformed tags in prose still block, with broad unit test coverage.
Overview
The diu-stop malformed-tag and legacy
UNVERIFIED:checks used to scan the full assistant message, so explaining{{CAT-UNVERIFIED}}, quoting the prove-it rule, or pasting the gate’s own refusal text could block the turn even though those tokens were not being used as escape hatches.find_marker_problemsnow runs on prose only via newprose_only, which strips fenced blocks and inline backticks (same regexes as the unverified-claim path) and treats everything after an unclosed fence as non-prose. Malformed tags and bare legacy markers in running prose still block.The README documents this distinction (mention vs use). Tests cover backticks, fences, verbatim rule quotes, relayed gate messages, unclosed fences, and regressions that real misuse in prose still fires.
Reviewed by Cursor Bugbot for commit 51ed95a. Bugbot is set up for automated code reviews on this repo. Configure here.