pub fn check_sequence_integrity(journal: &Journal) -> CheckResultExpand description
sequence-integrity — the recording itself is trustworthy: seq is dense
from 1, there is one session, timestamps are in the protocol profile
(SPEC.md §F4), turn markers balance, and nothing follows session_end.
Every other oracle leans on this one: density is what makes “the journal
is complete” checkable, and the turn discipline (a turn does not survive a
crash — a resume implicitly closes it) is what lets the loop oracles
distinguish a crash from a bug.