1# Native protected attachment boundaries
2
3Synthetic OneNote 2010 section with an exact known password in
4[manifest.json](manifest.json), including a supplementary Unicode character and a
5combining mark. All pages and attachments were generated by native OneNote.
6[The generator](../../tools/native/external-assets.ps1) accepts the recorded lengths.
7
8The notebook is the native protected image. `read/` contains an independent
9fresh-clone, empty-cache unlock oracle. Its `environment.json` says `cold: false`
10because the read reused the cache that the preceding isolated cold-open and
11unlock step established; that step is recorded separately in the manifest.
12
13Attachment plaintext is reproducible: repeat the 1024-byte block whose byte at
14index `i` is `i % 251`, truncated to the recorded length. Native exported hashes
15are in `read/payloads.json`; no second copy of those generated bytes is retained.
16The zero-length attachment has a zero-length stored payload even when protected.
17
18The initially rejected UI attempt is excluded. Source notebooks and personal
19profiles were never edited. This fixture establishes native 2010 behavior for
20these inputs; its password and contents are deliberately public.