docs: clear the remaining error-level vale lints

Per #4128 (mara: allow-everywhere false positives go in a central
list, otherwise fix in source). Testing surfaced better fixes than
the plan posted on the issue:

- 5x Microsoft.Contractions 'that is' idiom false positives: adding
  the missing comma ("that is, ...") both reads better and satisfies
  the rule's own negative-lookahead, so no suppression is needed at
  all. Fixed in docs/integrations/forge.md, docs/tools/forge.md,
  docs/tools/hivectl.md, docs/web-ui/dashboard.md, and
  swarmctl-cli.md's generated source (swarmctl/src/main.rs, doc
  comment regenerated via markdown-docs).
- persistence.md's 'is not' matching inside 'is nothing': reworded to
  'there'\''s nothing' rather than add any exception -- dodges the trap
  and is a genuine contraction besides.
- ca.md's 'it is' matching inside the already-correct 'it isn'\''t':
  tried a central .vale.ini TokenIgnores entry first per the
  allow-everywhere framing, but testing against the real file (not
  just a synthetic snippet) found it silently fails to suppress
  whenever markdown emphasis syntax appears earlier in the same
  file -- an offset-drift bug in how Vale applies TokenIgnores, not
  a config mistake. Reworded to "it'\''s not" instead, same fix
  shape as persistence.md.
- config.md's 3 genuine Microsoft.Avoid 'backend' exceptions (already
  flagged and accepted on #4139 -- an actually-pluggable LLM API
  provider, matching the nix option's own name, not one internal
  system to name): scoped inline vale suppression around just that
  section, since this one really is context-specific rather than a
  rule bug.

Verified: fresh 'vale docs/ --minAlertLevel=error' is 0 errors AND
0 warnings (was 10 errors). nix fmt 0 changed beyond the edits
themselves. pre-push lints (tracker-tag/comment-block/doc-pointer)
clean. cargo clippy -p swarmctl -- -D warnings clean. Diffed the
regenerated swarmctl-cli.md against the old copy to confirm only
the intended line moved.
This commit is contained in:
iris 2026-09-09 20:30:15 +02:00 committed by mara
commit f22791b7a4
9 changed files with 18 additions and 10 deletions

View file

@ -479,7 +479,7 @@ so it survives restarts and redeploys.
with. **Keep it.** It's handed to Forgejo when swarm-controller registers a hook,
so replacing the file means every subsequent delivery fails
verification until the hook is re-registered with the new value. It's
generated automatically on first start; there is nothing to configure.
generated automatically on first start; there's nothing to configure.
If the file is unreadable at startup the daemon still starts and logs
`webhook secret unavailable`; the webhook endpoint then answers 503

View file

@ -279,7 +279,7 @@ to `closed_at` that `state_change_is_current` returns `true` — so it takes
the state-change path, dropping its body. Best of both worlds:
on the merge/close path `forge_notify` fetches the `latest_comment_url` comment and, when
its `created_at` is strictly **after** the subject's `closed_at`
(`comment_is_after_close`) — that is it raced the merge rather than being the
(`comment_is_after_close`) — that is, it raced the merge rather than being the
pre-merge last comment the subject keeps — append it as a
`comment by <author>: <excerpt>` block before the meta suffix
(`fresh_post_close_comment_tail`). The wake carries **both** `[PR merged]`

View file

@ -179,7 +179,7 @@ Two consumers, and only one of them is fine:
The consumption differs per runtime and is the part worth knowing.
tuwunel links no openssl, which makes `SSL_CERT_FILE` look inapplicable
— it isn't: its rustls-based TLS stack still resolves trust through the
— it's not: its rustls-based TLS stack still resolves trust through the
platform certificate store on Linux, and that store honors
`SSL_CERT_FILE`, so the env var takes effect the same way it would for
an OpenSSL-linked binary.

View file

@ -257,8 +257,8 @@ to discover valid label names before triaging or to audit the label set.
## Notes
- **Read-before-comment guard:** `comment` refuses to post when forge still
has an unread notification for the thread (that is someone commented since you
last read it). This prevents accidentally replying to old activity without
has an unread notification for the thread (that is, someone commented since
you last read it). This prevents accidentally replying to old activity without
seeing the new context. Read the thread with `hive-forge view <n>` or
`hive-forge comments <n>` (which mark the notification read and clear the
block), or pass `--force` to skip the guard.

View file

@ -240,7 +240,7 @@ Bare `choom` starts a fresh blank session. `--resume <value>` passes
through as `claude --resume <value>` to rejoin a prior session by its
session id — the flag name deliberately matches the claude flag it maps
to. (choom never uses claude's `--continue`: that's a bare flag that
takes no argument and resumes the cwd's _latest_ session, that is the
takes no argument and resumes the cwd's _latest_ session, that is, the
harness's; a value after it would be consumed as the first prompt,
silently poking the live harness session.) A value is required when the
flag is given. Either way choom never collides with the harness's live

View file

@ -25,7 +25,7 @@ swarm-level operator CLI
###### **Options:**
* `--authelia-bin <PATH>` — authelia binary used to hash passwords. The argon2 parameters must match the verifier's, so this has to be the *configured* package rather than whatever is on `PATH`
* `--users-file <PATH>` — Host-side path of authelia's users database — that is the path inside the container, prefixed with the container's root.
* `--users-file <PATH>` — Host-side path of authelia's users database — that is, the path inside the container, prefixed with the container's root.
This is the only user store: it's read before every change and written in place, and `swarm-authelia-bridge` writes the same file.

View file

@ -240,6 +240,12 @@ It leaves non-compile subcommands (`new`, `add`, third-party
Set to `false` for agents that parse cargo's JSON output
programmatically and don't pass `--message-format json` themselves.
<!-- vale Microsoft.Avoid = NO -->
<!-- "backend" here means "which LLM API provider" (a genuinely pluggable
choice, matching the nix option's own name `backendEnvironmentFile`) --
not one internal system to name instead, so mara's #4041 ruling doesn't
apply to this section. -->
## API-key backend (`useApiKey` / `backendEnvironmentFile`)
```nix
@ -300,3 +306,5 @@ Switching an already-provisioned OAuth agent to `useApiKey` leaves
cleaned up automatically. Cost shape also changes: subscription pricing
→ per-request billing with no built-in monthly cap, worth knowing before
pointing a busy agent at a metered backend.
<!-- vale Microsoft.Avoid = YES -->

View file

@ -454,7 +454,7 @@ named buckets of MCP tools; each agent starts with a role default
`ToolGroup::AGENT_DEFAULT`; hive-c0re seeds the root agent to
`ToolGroup::MANAGER_DEFAULT``messaging`, `meta`, `inbox`,
`lifecycle`, `approvals`, `scheduling`, `diagnostics`, `execution`,
that is every group except `forge` and `web_tools`). Checking /
that is, every group except `forge` and `web_tools`). Checking /
unchecking stages which groups are active for the agent; the
page-level **save all** button (below) commits it. Columns come from
`GET /api/tool-groups`. hive-c0re queues a rebuild so `HIVE_TOOL_GROUPS`