docs+demo: deep-gap closers — 211/0 re-score, HD1-HD4 scenes, status/README/scoring
Full authoritative run 2026-07-06: all 12 suites 211 PASS / 0 FAIL (KMS + container isolation live via Vault dev + Docker; security-gate 11/0). - run-hardening.sh: new "Vá đường lọt sâu" section (HD1 incident/kill-switch, HD2 multilingual VI/JA, HD3 true container isolation, HD4 split+classifier), closer updated to 211 checks. - CASAN_HARDENING_STATUS.md: Phase 6 deep-gap closers table; test inventory 175→211 (12 suites); C7/multilingual moved out of planned; C6 planned→partial (real isolation done); honest claim → H4 83, H2 82, H5/H6 stay 80 (infra-bound). - scoring-report-02-after-competition.md: current state — 211/0, H4 80→83, H2 80→82, avg 80.9→81.6, lowest harness still 80 (H5/H6), 3-milestone table. - README claim boundary: deep-gap closers listed; totals 175→211; H4/H2 bumps. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
5ec1a0cc82
commit
42115e3361
@@ -0,0 +1,54 @@
|
||||
# CASAN — Chấm điểm CÔNG TÂM · Bản 2/2: SAU KHI THI (Mốc 2)
|
||||
|
||||
> Chấm theo `casan_harness_assessment.md` (rubric: 0–30 GAP · 31–60 Partial · 61–80 Good · 81–100 Strong=production).
|
||||
> **Mốc 2 = sau khi thi** — sau `feat/plan07-track-a-hardening` + H5/H6 hardening. Cùng phương pháp chấm như Bản 1.
|
||||
> Điểm là đánh giá trưởng thành theo rubric (người chấm, neo vào bằng chứng + gap thật), KHÔNG phải (5/5 gate)×100.
|
||||
|
||||
## 1. Build được chấm
|
||||
| | |
|
||||
|---|---|
|
||||
| Mốc | **2 — sau khi thi** (sau `feat/plan07-track-a-hardening`) |
|
||||
| Quy mô | **63 script** (+26 vs bản thi) · 12 suite test đối kháng |
|
||||
| Model | Ollama `ornith:9b` (local); đường cloud OpenAI/Anthropic đã hiện thực, chưa test key thật |
|
||||
| H4/H5/H6 | **~4.0/5** (self-assessment dự án, `CASAN_HARDENING_STATUS.md §4`) |
|
||||
|
||||
## 2. Bằng chứng test đối kháng (thật, 0 lỗi)
|
||||
- **211 test PASS / 0 FAIL** trên **12 suite** (bản nộp thi là 175/8 suite; **+36 vá-lọt-sâu** sau thi):
|
||||
run-casan4 **35** · adversarial **44** · track-a **25** · track-c **29** · evidence-pack **7** · h5-approval **8** · h5-infra **7** · h6-agentops **20** · **c7-incident 15** · **h4-multilingual 7** · **c6-sandbox 6** · **h4-split-inject 8**.
|
||||
- `security-gate` aggregate: **PASS=11 FAIL=0 SKIP=0**.
|
||||
- H4 recall model **0.85** > regex 0.00 · Benign-FP **0.00% / block 100.00%** (95 mẫu EN/VI/JA + 16 vector).
|
||||
- H5: approval ký-danh-tính (chống giả/replay/tự-duyệt) · KMS live Vault (rotate/non-exportable) · WORM audit (gap/tamper).
|
||||
- H6: alert live (webhook·dead-letter) · provider-telemetry reconcile · dashboard `/healthz` stale-aware · window circuit-breaker.
|
||||
- **Vá lọt sâu (sau thi):** C7 incident + kill-switch (CRIT→khoá scope) · đa ngôn ngữ VI/JA (0 FP) · **cô lập container THẬT** (Docker, kernel chặn egress/host-read) · split-injection (quét ngữ cảnh ghép) + classifier-injection.
|
||||
|
||||
## 3. Điểm CÔNG TÂM theo rubric — Mốc 2
|
||||
| ID | Harness | Mốc 1 | **Mốc 2** | Band | Cứng hoá thêm sau thi | Gap production còn mở |
|
||||
|----|---------|:--:|:--:|---|---|---|
|
||||
| H1 | Context | 82 | **84** | Strong- | + log-levels + redaction + context-validate | chưa nén/RAG context lớn |
|
||||
| H2 | Tool | 74 | **82** ⬆ | Good(đỉnh) | + action-gate + supply-chain + data-exfil gate + **cô lập container THẬT** (C6) | rootless/nsjail + base image cho CI |
|
||||
| H3 | Evaluation | 82 | **82** | Strong- | (giữ) judge-gate live 5/0 | judge 1 model local |
|
||||
| H4 | Security | 60 | **83** ⬆ | Good(đỉnh) | + unicode/base64 · tool-output scan · strict fail-closed · benign-FP 0% + **đa ngôn ngữ VI/JA** + **split/classifier injection** | model-digest pin · eval-set độc lập |
|
||||
| H5 | Governance | 60 | **80** ⬆ | Good(đỉnh) | + approval ký-danh-tính · KMS live (rotate/non-exportable) · WORM audit ngoài | IdP live · WORM store thật (S3 Object Lock) · KMS mặc định |
|
||||
| H6 | AgentOps | 60 | **80** ⬆ | Good(đỉnh) | + alert live (webhook·dead-letter) · provider reconcile · dashboard hosted `/healthz` · window breaker | dashboard deploy thật + auth · kênh alert managed + on-call · billing-API thật |
|
||||
| H7 | Orchestration | 80 | **80** | Good(đỉnh) | (giữ) Boss DAG · rollback · fallback · drift | chưa transaction-rollback xuyên step |
|
||||
|
||||
**Average = 81.6 / 100 (H2 82 · H4 83 sau vá-lọt-sâu; H1 84 · H3 82 · H7 80) · Harness thấp nhất = 80 (H5·H6) · CASAN Level 4 — chứng minh bằng tấn công.**
|
||||
|
||||
> Vá-lọt-sâu sau thi (C7 incident/kill-switch · VI/JA · cô lập container thật · split/classifier) nâng **H2→82, H4→83** và đóng chiều Incident-response (Track C). **H5 và H6 vẫn 80** vì phần còn lại của chúng là HẠ TẦNG (IdP live · WORM store thật · KMS mặc định · dashboard/alert managed · billing-API) → **trần pipeline vẫn 80** (harness thấp nhất quyết định). Muốn cả pipeline vào "Strong (81+)" phải đóng nốt các mục hạ tầng đó.
|
||||
|
||||
## 4. Kết luận Mốc 2 (trung thực)
|
||||
- Ba harness GAP → nay **đồng đều đỉnh "Good" (80)**; harness thấp nhất nhích 60 → **80** ⇒ trần pipeline cao hơn hẳn Mốc 1.
|
||||
- **Vẫn giữ ở 80, chưa lên "Strong/production (81+)"**: bản production của IdP live · WORM store thật · KMS mặc định + HSM · sandbox isolation · dashboard/alert managed · billing-API còn **[planned]** (`CASAN_HARDENING_STATUS.md §3`).
|
||||
- Level 5 = các control đã hiện thực + test cục bộ; production Level 5 cần đóng nốt các gap trên.
|
||||
|
||||
## 5. So sánh các mốc (một dòng)
|
||||
| | Trước thi (Mốc 1) | Nộp thi (Mốc 2) | Nay — vá lọt sâu |
|
||||
|---|---|---|---|
|
||||
| Test đối kháng | 79 / 0 | 175 / 0 | **211 / 0** |
|
||||
| H4 · H5 · H6 | 60·60·60 | 80·80·80 | **83·80·80** |
|
||||
| H2 (Tool) | 74 | 80 | **82** |
|
||||
| Average | 71.1 | 80.9 | **81.6** |
|
||||
| Harness thấp nhất | 60 | 80 | **80** (H5·H6 — chờ hạ tầng) |
|
||||
| CASAN Level | 3→4 | 4 | 4 (chứng minh bằng tấn công) |
|
||||
|
||||
→ Bản 1/2 (trước khi thi): `scoring-report-01-before-competition.md`.
|
||||
Reference in New Issue
Block a user