Route Lock adapter 0.1.0

The six readiness dimensions and the GET/POST preflight boundary come from
the private settlement-reliability benchmark at
bb854096b5760d0882de876d6e86ab611e0bef44. That repository stays private.
This package is not a republish of it.

Intentional adapter differences, both executed by the test suite:

- Challenge acceptance does not assume a buyer network. The caller may supply
  one. A null profile does not mean Base.
- POST bindingDigest covers the query string and, when a JSON body is
  supplied, the body digest. The original benchmark hashed the public route
  only. Raw query values and bodies are not retained in the decision.
- evidenceDigest is computed from bindingDigest, not from publicRoute plus
  query keys.
- The purchase decision requires runtime.observedAt inside the validity
  window. evaluatedAt is the decision clock and is not an observation time.

Offer comparison and request binding reuse agent-payment-policy 0.14.0.
Challenge parsing reuses agent-payment-integrity 731ac9b0ff22615a3d22e4897c39f3f14b55087f.
This package has no wallet, signature, payment, or settlement code.
