fn mark_identity_rejection_coverage_limits( coverage: &mut [CoverageRecord], dropped_paths: &BTreeSet<String>, ) -> Result<(), CliError>
Mark graph-scoped coverage when publication evicted a typed identity row.