Buyer-mandate journey adapter 0.4.0

Admits the current neomorphic.io service and instrument records in
src/data/site.ts. Those records stay the contract. This folder does not
copy them onto a page and does not edit them.

No-spend planning reuses agent-payment-policy
e466c954dba62c2a43e1cf2a5fa0a49f25de8533 (PR #3 head, package version
0.15.1). Main 2a215fe01a4627a1c82e200c2cc68b7584076c4e carries the same
plan and intent functions; this adapter pins the PR #3 commit named by
the job. It calls createIntent, createPlan, normalizeRequest, and
validateOutput. It does not call authorizePlan or authorizeExecution
and it does not generate a key.

Unpaid challenge parsing reuses agent-payment-integrity
731ac9b0ff22615a3d22e4897c39f3f14b55087f parseX402Challenge.

PAYMENT-RESPONSE decoding reuses @x402/core@2.16.0
decodePaymentResponseHeader. That is the existing receipt parser.

Useful results come from the maintained record-lab adapter
scripts/record-lab/adapter.mjs projectLocalRecords. Journey v2 reads a
caller-supplied local extraction artifact, mapping, and buyer record
schema from a client directory and binds those bytes into the scoped
mandate. A named-remote-extraction producer is an input label. This
adapter does not fetch that producer's URLs and does not pay for
extraction. Unknown and partial producer rows stay explicit. The v1
sealed product sample, including its url list, remains a regression
fixture. The capability-market fixture-echo adapter is not called.
The journey does not fetch, sign, settle, or record a balance.

The receive command is a pinned consumer of packages/route-lock decide
and packages/release-gate evaluateRelease. It does not copy those
packages and it does not rewrite public/downloads. Route-lock's
authority pair cannot lock. The held release descriptor is not
acceptance. A revoked descriptor blocks the next step.

Caller authority is an explicit file. A missing requester, task,
audience, method, path, expiry, recipient, amount, network, asset,
projection digest, or record revision is not permission. The task
record is read over local TLS. This adapter does not open the task
journal. Record correction and revocation are visible on a later
request. A valid projection from another task or principal, or a stale
projection digest, does not confer authority. An unobserved decision
receipt stays unknown and is not retried.

The receiving decision clock is the process clock at two boundaries:
the consumer, before it posts a new receipt, and the task API, before
it stores one. journey.now, --now, and BUYER_MANDATE_NOW are not
production authority. A test may pass an explicit millisecond clock
only while NODE_TEST_CONTEXT=child-v8. The peer clocks must agree
within 5000 ms. That bound does not extend expiresAt. Replay of a
stored receipt is a historical outcome and does not authorize a new
action, including after expiry. The ordinary consumer is `consume`.
It runs the local no-spend journey only when the current decision
authorizes a new action. The retained inputs for a later authenticated
host are examples/receive/hosting-contract.json. This adapter adds no
signer and does not broaden the scoped authority. The bind stays
127.0.0.1 while the host has no authentication.

Prior seal of this journey: eaca035ffcf55135f1cae5447823301354a6c599.
Collected retrieval terminal: 6048aaae93e456668844f41753c7337143eb10ad.
General-caller base: b1416ce08ede00809b64172c4f66357e7d1ee977.
