Payment Terminal Boundary
Each button uses PaymentTerminalAdapter first, then sends the explicit provider outcome to governed reconciliation.
No local terminal request yet.
- Load baseline and confirm payment starts unresolved.
- Simulate failed outcome; it must not become confirmed.
- Simulate requires_reconciliation; it must remain explicit.
- Force-close/reopen and confirm durable terminal request survives.
- Simulate confirmed outcome; only governed reconciliation may mark payment confirmed.
- Retry latest reconciliation; payment stays confirmed and replay becomes true.