Function audit_coverage
pub fn audit_coverage(
regions: &[CertifiedRegion],
root_pair_count: u32,
) -> Result<(), CoverageFault>Expand description
Verify that the regions tile the root parameter box exactly.
§The invariant
Subdivision bisects all four parameter axes, so a leaf at depth d
covers exactly 16^-d of its root box – a dyadic rational, never a
rounded quantity. Summing 16^(MAX_AUDIT_DEPTH - d) over the leaves
gives exactly 16^MAX_AUDIT_DEPTH per root box if and only if the
leaves tile every root with no gap and no overlap.
The arithmetic is integer u128 throughout: no tolerance, no
accumulated float error, no judgement call. A dropped leaf makes the
sum too small, a duplicated one makes it too large, and either way
this returns a fault.
§Why this check outlives the code it checks
It constrains only completeness, never content. Future work may add refusal kinds, sharpen bounds, or change how tangency is handled; none of that is allowed to stop accounting for the domain. So this keeps catching the invisible bug class without needing a rewrite.