3e5d742ac7
main/resources/logback.xml routes the `audit` logger to a RollingFileAppender at logs/audit.log — the CB-505 security trail. AuditLogTest and BridgedAppAuthTest exercise that same logger, so every `mvn test` appended fabricated records to the production file. They are byte-identical to genuine ones: runs of denied/forbidden SPAWN/STOP/SEND from worker:term_a, which read exactly like an intrusion attempt. logs/audit.2026-07-29.0.log is 38 fabricated records out of 76 — half that day's security log is test fixtures, and nothing distinguishes them. Fix is one new file, src/test/resources/logback-test.xml: logback prefers it on the test classpath, so tests get a console-only config with no file appender and main/resources/logback.xml is untouched. The `audit` logger stays ENABLED (INFO, additivity=false) because AuditLogTest attaches its own ListAppender and asserts on emitted records — setting it OFF would have silently gutted those assertions. Verified: 311 tests green, and logs/audit.log line count is identical before and after a full `mvn clean install` (zero new records). Implemented by an opencode-free worker over the bridge in an isolated worktree (branch worker/cb-506-audit-test-isolation-e4aa9c-2); it correctly reported it could not run mvn rather than fabricating a result, so the build gate and the before/after audit-count check were run primary-side. Header comment added on integration.