Session Integrity
integrity.json is optional, versioned, and contains relative paths, byte counts, and SHA-256 hashes for regular files in a finalized session package. Generation first validates the package and excludes the integrity file itself. Verification checks every listed path, file size, and digest.
Integrity generation changes a finalized package, so callers must record that operation in catalog provenance or package history. OrganicVision never silently changes a finalized package. A mismatch produces a typed, user-readable error and should mark the record for attention or quarantine.