c2e7f55651
Separate `cycle` (a pipeline-graph round) from `milestone` (a Gitea tracker container that closes only when complete AND functional). `audit` proves drift-clean, never functional, so no audit signal — and no `/boss` done-state — may close a milestone. Introduces a milestone-close gate (complete ∧ functional) defined once in docs/pipeline.md, and a milestone-wide fieldtest as a carrier-scope variant of the existing fieldtest skill. The milestone fieldtest runs curated end-to-end scenarios derived top-down from the milestone's promise — proving the shipped implementation delivers what the milestone as a whole promised, not a mechanical union of per-cycle axes. The actual tracker close stays a manual act; this spec only defines when a milestone is closeable. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>