Release Gate public checklist 0.1.1

Decision rules follow the private release-gate candidate at
142d0c15647d5992d339a21d4071159679f686fd (branch release-gate-v1) and the
related publication check at 9fa796b56643db8123bcce74d7451ff7f28e60c2
(branch release-check-v1). Those repositories stay private. Their seller
parsers, live catalog clients, and fixtures are not copied into this package.

What is kept:

- A descriptor is authority. A purchase decision is a different domain.
- Owned origin evidence can hold a release.
- External index drift is a gate with action wait_index_do_not_owner_pay.
- A cache of that index, including Agentic Market after Bazaar, is wait.
- ownerPayment is false. Publish, pay, and settle verbs are refused.
- Historical seller rows are regression fixtures. They do not qualify the
  Route Lock package and they are not a launch.

The primary subject is packages/route-lock 0.1.0. The descriptor names
https://neomorphic.io/downloads/route-lock/0.1.0/route-lock-0.1.0.tgz.
That names the distributed 0.1.0 archive; it does not replace those bytes.
An offline check stays held. check --live accepts only when the GET body
matches artifact.packSha256. ownerPayment and paidServiceLaunch stay false.
See src/origin-proof.mjs.
