The transit, without a law for the star.
Every published planet radius is a statement about a star's atmosphere as much as about a planet. The depth of a transit is the light blocked, and how much light sits where the planet passes is decided by a limb-darkening law nobody measured for that star. This asks what the photometry forces on its own: the star is any nonnegative brightness profile at all, the measurement is a circle crossing a disc, and the answer is the set of radius ratios that survive. A quadratic law is fitted here too — but only to answer two questions about the harness, and never inside the enclosure.
a grazing transit: the planet never comes near the middle of the star
19 published values of Rp/R* span 0.12385 to 0.12780 — a spread of 3.2% — while a typical one quotes ±0.00008. Granting the orbit exactly and assuming only that the star is nowhere negative and does not brighten outward, this light curve forces Rp/R* into [0.1095, 0.3260].
the planet whose published radius ratio moves 3.7% between papers
10 published values of Rp/R* span 0.07990 to 0.08294 — a spread of 3.8% — while a typical one quotes ±0.00005. Granting the orbit exactly and assuming only that the star is nowhere negative and does not brighten outward, this light curve forces Rp/R* into [0.0719, 0.2424].
Nothing here trusts the optimiser.
The star is a nonnegative measure μ on [0,1] with ∫dμ = 1 — the normalisation is the statement that the curve is 1 out of transit. A planet of radius k at sky-plane distance z covers a fraction w(r; z, k) = arccos(clamp g)/π of the circle of radius r, so every datum is a two-sided linear constraint on μ. Because μ is a probability measure, the reachable depths are exactly the convex hull of the kernel's moment curve, and the whole question is whether a curve in Rm meets a box.
When it meets it, the meeting point is a finite convex combination — an atomic measure, exhibited, and re-checked bin by bin from scratch. When it misses it, the separating direction is a Farkas certificate: multipliers α, β ≥ 0 with minr h(r) > Σ αjuj − Σ βjlj, which refutes k for every μ at once. That minimum is over a continuum, so it is closed by interval arithmetic over an adaptive partition — of r and of the geometry, because the kernel's closed form mentions z five times and a naive enclosure over a z-box 0.01 wide once returned [0.16, 1.00] where the true value was 0.997, which had let a planet the size of its star pass as admissible.
The optimiser only proposes. Whatever it hands over is checked against the definition, and a value is reported only when the check passes; everything else is left undecided and shown as the gap between the inner and outer bars.