leaveIsIdempotentEvenWhenTeardownFails
Idempotent even when the first call FAILED — the half leaveIsIdempotent cannot reach.
A room that marks itself closed only after a successful teardown is idempotent on the happy path and not idempotent at all where it matters: the caller retries, the whole teardown runs again, and it throws again. That is the shape of a leave whose closed-flag sits at the bottom of the method instead of the top, and it is invisible to every test whose teardown succeeds.
What is asserted, and what deliberately is not. The obligation is "a second leave() must not throw", so that is the assertion. Whether the first one propagates the transport's failure is not asserted: a room may legitimately swallow a close failure it can do nothing about, and demanding a throw would fail a conforming room. Nor is "the second call must not re-run the teardown" — a room that retried and succeeded is not obviously non-conforming, and inventing that demand here would be over-specification. The first call's outcome is carried into the failure message instead, where it is diagnosis rather than contract.
The rig-fired count is what stops the remaining assertion from being vacuous: without it, a harness whose injected fault never reached the room's seam passes by absence — an unexercised rig is green, and green by absence is the failure mode this suite's own KDoc warns about.