libtss2-tctildr0-2.4.5-1.11 >  A `CdMp9|}G*h'`M^]l=4b>S&F.ѱ|hbkC=8~yC޲CۆaoaT脃\w_ºj\ؓ#ܽTvHMom:#uYlH?I68zxC"U?duRYH݆g+P JlܴGI oab03b3011d07b10b84e46268ab58ffcbec885f8e7e819cf608f49226ad5ec378d9959be92ca62bb1e91182b506b84f8a85cc7ab5cX`CdMp9|Ɗ'D}ؒm{*^:?nJZ7Fģ$P籋YF;Džo ;y:'2U%t RBJhC#uwD$=] BH}Π3 {\ݸ1;<]Ga'颋MB[*t{WآvNP\O@.9`̥yS)k3? >扃~>k^a YaRx}uWJKåZ`{(#g%섟k>p@[t?[dd  = 5Fpv     08(68@9:B>Xk@XzFXGXHXIXXXYX\X]X^Y bYcYdZeZ fZ#lZ%uZ8vZ@wZxZyZ z[[[[[`Clibtss2-tctildr02.4.51.11TCTI interface loading libraryThis is a helper library that simplifies loading other tcti libraries. It is recommended over custom tcti loading code in applications.`Ccsheep58iSUSE Linux Enterprise 15SUSE LLC BSD-2-Clausehttps://www.suse.com/System/Librarieshttps://github.com/tpm2-software/tpm2-tsslinuxx86_64i`Cc`Cc8a926691aa17469b9f5d6786d0cfab4062b80382fe3f0076cd93603590e8b4aflibtss2-tctildr.so.0.0.0rootrootrootroottpm2-0-tss-2.4.5-1.11.src.rpmlibtss2-tctildr.so.0()(64bit)libtss2-tctildr0libtss2-tctildr0(x86-64)@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1`@^ P@]@]_@\\@[t[[>@[;e@[6@Z@ZYKYp@YoIYoIY)j@YR@YX@X@X@WW@W,@W@V͛@matthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commvetter@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.combwiedemann@suse.commatthias.gerstner@suse.commgerstner@suse.commeissner@suse.comjengelh@inai.demeissner@suse.commeissner@suse.commeissner@suse.comjengelh@inai.dedimstar@opensuse.orgmeissner@suse.com- drop 0001-esys-Fix-HMAC-generation-for-policy-sessions.patch: now contained in upstream tarball - update to upstream version 2.4.5 (jsc#SLE-17366): - changes in version 2.3.2: * Fix unit tests on S390 architectures * Fixed HMAC generation for policy sessions - changes in version 2.3.3: * Fixed mixing salted and unsalted sessions in the same ESAPI context * Removed use of VLAs from TPML marshal code * Added check for object node before calling compute_session_value function * Fixed auth calculation in Esys_StartAuthSession called with optional parameters * Fixed compute_encrypted_salt error handling in Esys_StartAuthSession * Fixed exported symbols map for libtss2-mu - changes in version 2.4.0: * Added a new Feature API (FAPI) implementation * Added Esys_TRSess_GetAuthRequired() ESAPI function * Added Esys_TR_GetTpmHandle() SAPI function * Added Esys_GetSysContext() SAPI function * Added the with-sanitizer configure option * Added CI for FreeBSD * Changed MSSIM TCTI to be async capable * Removed TCTI loaders from ESYS dependencies in pkg-config * Changed getPollHandles to allow num_handles query * Improved CI builds * Converted builds to docker builds * Number of fixes and improvements in the test code * Changed tcti-device in non-async mode to allways block * Fixed hmac calculation for tpm2_clear command in ESAPI * Fixed mixing salted and unsalted sessions in the same ESAPI context * Removed use of VLAs from TPML marshal code * Fixed setting C++ compiler for non-fuzzing builds at configure * Fixed setting the name of session objects * Fixed page alignment errors in Sys_Get/SetAuths functions * Fixed potential buffer overflow in tcti_mssim_receive * Fixed invalid memory alloc failure in Tss2_TctiLdr_Initialize * Fixed list of exported symbols map for libtss2-mu * Fixed resource name calculation in Esys_CreateLoaded * Fixed keysize of ECC curve TPM2_ECC_NISTP224 * Fixed segmentation fault in tctildr if name_conf was too big * Fixed memory leak in tctildr-tcti tests * Fixed HMAC generation for policy sessions * Added check for object node before calling compute_session_value function * Fixed auth calculation in Esys_StartAuthSession called with optional parameters * Fixed compute_encrypted_salt error handling in Esys_StartAuthSession * Fixed exported symbols map for libtss2-mu * Remove duplicate ESYS entries from map file * Removed the private implementation of strndup from tctildr - changes in version 2.4.1: * Fixed systemd-sysusers/-tmpfiles creation without systemd * Removed expired coverity token from travis.yaml * Fixed uninitialized context of FAPI command Fapi_ChangeAuth issue * Fixed handling of tcti pointer in Esys_Initialize * Fixed usages of EC routines deprecated in OSSL 1.2 and greater * Fixed FAPI handling of TPMs without stored certificates - changes in version 2.4.2: * Fixed duoble json_object_put call in event log processing. * Fixed memory leaks on error paths in FAPI * Fixed setting of FAPI app data. * Fixed size check for Fapi_Encrypt. * Fixed computation of PCR logs and PCR digest of PCR logs. * Improved comments for FAPI authentication. * Fixed segfault and leaks in FAPI * Fixed Fapi_GetCertificate for objects which are not of type key * Fixed hierarchy usage in Fapi_Provision * Fixed ESYS Shared secret calculation * Fixed doxygen warnings for FAPI docs * Fixed copying of primary template during key loading. * Fixed some wrong format directives in debug statements. * Fixed usage of hierarchy and authentication in Fapi_GetCertificate und Fapi_Delete * Fixed unallocated return buffers which may have lead to segfaults in tooling * Fixed usage of persistent handles. * Fixed computation of the size of a PCR selection (Fixes #1737). * Fixed missing hierarchy authentication for Fapi_Delete. * Fixed uninitialized context of FAPI command Fapi_ChangeAuth. * Fixed computation of random value for objects used for sealing. * Fixed return code for event parsing errors. * Fixed NV index and path handling in NV creation. * Fixed path checking for keys. * Fixed Fapi_GetInfo function. * Fixed path usage in Fapi_Import. * Fixed invalid settings of default flags for keys creation. * Fixed handle usage in Fapi_ChangeAuth * Enabled all PCR registers for SHA256 bank in the distribution profiles. * Added some checks to Fapi_Provisioning to avoid nasty failure states * Added a check to prevent overwrite or delete FAPI storage objects and directories * Remove obsolete test fapi-key-create-policy-password-sign.int.c * Checked hierarchy needed for EvictControl for deleting objects in FAPI. * Checked event log file before calling the TPM in Fapi_PcrExtend. * Adapted integration tests to SRK delete checking. * Improved presentation of Fapi_GetInfo. * Silenced expected errors from Esys_TestParams * Added man pages for FAPI json config files * Added a check that prevents deleting default directories * Added a check if primary keys already exist for Fapi_Provision * Added tests for derived persistent keys. * Added test policy PCR with PCR register 8. * Added check for deleting of the SRK. * Added test for sealing a random value. * Added content of the config file to FAPI Info. * Added a check for valid pathnames in keystore module. * Removed unecassary code from Fapi_ExportKey * Removed obsolete LIBDL_LDFLAGS and replace it with LIBADD_DL * Removed superfluous policies/pol_password.json file - changes in version 2.4.3: * Fix CVE-2020-24455 FAPI PolicyPCR not instatiating correctly Note that all TPM object created with a PolicyPCR with the currentPcrs and currentPcrsAndBank options have been created with an incorrect policy that ommits PCR checks. All these objects have to be recreated! * Fix bug in FAPI NV creation with custom index values * Cleanup of leftover sessions in error cases in FAPI * Better error messages in several FAPI errors * Add checks to FAPI policy paths * Add checks if FAPI is correctly provisioned * Fix execution of FAPI policies in some cases * Allow 0x prefixes for TPMU_HA in JSON encoding - changes in version 2.4.4: * FAPI: Fix policy searching, when a policyRef was provided * FAPI: Accept EK-Certs without CRL dist point * FAPI: Fix memleak in policy execution * FAPI: Fix setting of the system flag of NV objects This will let NV object metadata be created system-wide always instead of locally in the user. Existing metadata will remain in the user directory. It can be moved to the corresponding systemstore manually if needed. * FAPI: Set the written flag of NV objects in FAPI PolicyNV commands * FAPI: Fix deleting of policy files. * FAPI: Fix wrong file loading during object search. * Fapi: Fix memory leak * Fapi: Fix potential NULL-Dereference * Fapi: Remove superfluous NULL check - changes in version 2.4.5: * Fix Regression in Fapi_List * Fix memory leak in policy calculation- 0001-esys-Fix-HMAC-generation-for-policy-sessions.patch: fix problems with policy sessions that don't include an TPM2_PolicyAuthValue (bsc#1160736). This bug was fixed upstream in a minor release 2.3.2.- update to upstream version 2.3.0 (dependency for jsc#SLE-9515): - changes in version 2.3.0: - tss2-tctildr: A new library that helps with tcti initialization Recommend to use this in place of custom tcti loading code now ! - tss2-rc: A new library that provides textual representations for return codes - Option to disable NIST-deprecated crypto (--disable-weak-crypto) - Support Esys_TR_FromTPMPublic on sessions (for use in Esys_FlushContext) - map-files with correct symbol lists for tss2-sys and tss2-esys This may lead to unresolved symbols in linked applications - Support to call Tss2_Sys_Execute repeatedly on certain errors - Reduced RAM consumption in Esys due to Tss2_Sys_Execute change - Automated session attribution clearing for esys (decrypt and encrypt) per cmd - Removed libtss2-mu from "Requires" field of libtss2-esys.pc Needs to be added explicitely now - All fixes from 2.2.1, 2.2.2 and 2.2.3 - Fixed SPDX License Identifiers - Fixed Null-pointer problems in tcti-tbs - Fixed Default locality for tcti-mssim set to LOC_0 - Fixed coverity and valgrind leaks detected in test programs (not library code)- update to upstream version 2.2.3: - changes in version 2.2.3: * Fix computation of session name * Fixed PolicyPassword handling of session Attributes * Fixed windows build from dist ball * Fixed default tcti configure option * Fixed nonce size calculation in ESYS sessions - changes in version 2.2.2: * Fixed wrong encryption flag in EncryptDecrypt * Fixing openssl engine invocation- bsc#1130588: Require shadow instead of old pwdutils- update to upstream version 2.2.1: - changes from version 2.2.0: - Fixed leak of hkey on success in iesys_cryptossl_hmac_start - Fixed NULL ptr issues in Esys_HMAC_Start, Esys_HierarchyChangeAuth and Esys_NV_ChangeAuth - Fixed NULL ptr issue in sequenceHandleNode - Fixed NULL ptr auth handling in Esys_TR_SetAuth - Fixed NULL auth handling in iesys_compute_session_value - Fixed marshaling of TPM2Bs with sub types. - Fixed NULL ptr session handling in Esys_TRSess_SetAttributes - Fixed the way size of the hmac value of a session without authorization - Added missing MU functions for TPM2_NT type - Added missing MU functions for TPMA_ID_OBJECT type - Added missing type TPM2_NT into tss2_tpm2_types.h - Fixed wrong typename _ID_OBJECT in tss2_tpm2_types.h - Fixed build breakage when --with-maxloglevel is not 'trace' - Fixed build breakage in generated configure script when CFLAGS is set - Fixed configure scritp ERROR_IF_NO_PROG macro - Changed TPM2B type unmarshal to use sizeof of the dest buffer instead of dest - Fixed unmarshaling of the TPM2B type with invalid size - Removed dead code defect detected by coverity from Esys_TRSess_GetNonceTPM - Added support for QNX build - Added support for partial reads in device TCTI - changes from version 2.1.1: - Fixed leak of hkey on success in iesys_cryptossl_hmac_start - Fixed NULL ptr issues in Esys_HMAC_Start, Esys_HierarchyChangeAuth and Esys_NV_ChangeAuth - Fixed NULL ptr issue in sequenceHandleNode - Fixed NULL ptr auth handling in Esys_TR_SetAuth - Fixed NULL auth handling in iesys_compute_session_value - Fixed marshaling of TPM2Bs with sub types. - Fixed NULL ptr session handling in Esys_TRSess_SetAttributes - Fixed the way size of the hmac value of a session without authorization - Added missing MU functions for TPM2_NT type - Added missing MU functions for TPMA_ID_OBJECT type - Added missing type TPM2_NT into tss2_tpm2_types.h - Fixed wrong typename _ID_OBJECT in tss2_tpm2_types.h - Fixed build breakage when --with-maxloglevel is not 'trace' - Fixed build breakage in generated configure script when CFLAGS is set - Fixed configure scritp ERROR_IF_NO_PROG macro - Changed TPM2B type unmarshal to use sizeof of the dest buffer instead of dest - Fixed unmarshaling of the TPM2B type with invalid size - Removed dead code defect detected by coverity from Esys_TRSess_GetNonceTPM - changes from version 2.1.0: - Fixed handling of the default TCTI - Changed logging to be ISO-C99 compatible - Fixed leak of dlopen handle - Fixed logging of a response header tag in Tss2_Sys_Execute - Fixed marshaling of TPM2B parameters in SAPI commands - Fixed unnecessary warning in Esys_Startup - Fixed warnings in doxygen documentation - Added Esys_Free wrapper function for systems using different C runtime libraries - Added Windows TBS TCTI - Added non-blocking mode of operation in tcti-device - Added tests for Esys_HMAC and Esys_Hash - Enabled integration tests on physical TPM device - Added openssl libcrypto backend - Added Doxygen documentation to integration tests - Refactored SetDecryptParam - Enabled OpenSSL crypto backend by default - changes from 2.0.2: - Fixed NULL ptr issues in Esys_HMAC_Start, Esys_HierarchyChangeAuth and Esys_NV_ChangeAuth - Fixed NULL ptr issue in sequenceHandleNode - Fixed NULL ptr auth handling in Esys_TR_SetAuth - Fixed NULL auth handling in iesys_compute_session_value - Fixed marshaling of TPM2Bs with sub types. - Fixed NULL ptr session handling in Esys_TRSess_SetAttributes - Fixed the way size of the hmac value of a session without authorization - Added missing MU functions for TPM2_NT type - Added missing MU functions for TPMA_ID_OBJECT type - Added missing type TPM2_NT into tss2_tpm2_types.h - Fixed wrong typename _ID_OBJECT in tss2_tpm2_types.h - Fixed build breakage when --with-maxloglevel is not 'trace' - Fixed build breakage in generated configure script when CFLAGS is set - Fixed configure scritp ERROR_IF_NO_PROG macro - Changed TPM2B type unmarshal to use sizeof of the dest buffer instead of dest - Fixed unmarshaling of the TPM2B type with invalid size - Removed dead code defect detected by coverity from Esys_TRSess_GetNonceTPM - introduce _service file for syncing with upstream tags- update to upstream version 2.0.1 (FATE#324477): - Fixed problems with doxygan failing make distcheck - Fixed conversion of gcrypt mpi numbers to binary data - Fixed an error in parsing socket address in MSSIM TCTI - Fixed compilation error with --disable-tcti-mssim - Added initialization function for gcrypt to suppress warning - Fixed invalid type base type while marshaling TPMI_ECC_CURVE in Tss2_Sys_ECC_Parameters - Fixed invalid RSA encryption with exponent equal to 0 - Fixed checking of return codes in ESAPI commands - Added checks for programs required by the test harness @ configure time - Fixed warning on TPM2_RC_INITIALIZE rc after a Startup in Esys_Startup - Checked for 1.2 TPM type response - Changed constants values in esys header file to unsigned- also process udev triggers for tpmrm subsystem, otherwise /dev/tpmrm0 isn't properly updated (at least on SLES-12-SP4)- added all librares to baselibs.conf to satisfy 32-bit dependencies of esys0 and sys0- Explicitly require udev to fix missing ownership for /usr/lib/udev.- update to new major version 2.0.0: - version_fix.patch: removed, we're now using the distribution tarballs where this problem shouldn't happen - this update introduces an incompatible ABI to the previous version. all libraries have been renamed so there is not really a relation to the old version any more. - upstream changelog: [#]# [2.0.0] - 2018-06-20 [#]## Added - Implementation of the Marshal/Unmarshal library (libtss2-mu) - Implementation of the Enhanced System API (libtss2-esys aka ESAPI) - New implemetation of the TPM Command Transmission Interface (TCTI) for: - communication with Linux TPM2 device driver: libtss2-tcti-device - communication with Microsoft software simulator: libtss2-tcti-mssim - New directory layout (API break) - Updated documentation with new doxygen and updated man pages - Support for Windows build with Visual Studio and clang, currently limited to libtss2-mu and libtss2-sys - Implementation of the new Attached Component (AC) commands - Implementation of the new TPM2_PolicyAuthorizeNV command - Implementation of the new TPM2_CreateLoaded command - Implementation of the new TPM2_PolicyTemplate command - Addition of _Complete functions to all TPM commands - New logging framework - Added const qualifiers to API input pointers (API break) - Cleaned up headers and remove implementation.h and tpm2.h (API break) [#]## Changed - Converted all cpp files to c, removed dependency on C++ compiler. - Cleaned out a number of marshaling functions from the SAPI code. - Update Linux / Unix OS detection to use non-obsolete macros. - Changed TCTI macros to CamelCase (API break) - Changed TPMA_types to unsigned int with defines instead of bitfield structs (API/ABI break) - Changed Get/SetCmd/RspAuths to new parameter types (API/ABI break) - Fixed order of parameters in AC commands: Input command authorizations now come after the input handles, but still before the command parameters. [#]## Removed - Removed all sysapi/sysapi_utils/*arshal_TPM*.c files [#]## Fixed - Updated invalid number of handles in TPM2_PolicyNvWritten and TPM2_TestParms - Updated PlatformCommand function from libtss2-tcti-mssim to no longer send CANCEL_OFF before every command. - Expanded TPM2B macros and removed TPM2B_TYPE1 and TPM2B_TYPE2 macros - Fixed wrong return type for Tss2_Sys_Finalize (API break). [#]# [1.4.0] - 2018-03-02 [#]## Added - Attached Component commands from the last public review spec. [#]## Fixed - Essential files missing from release tarballs are now included. - Version string generation has been moved from configure.ac to the bootstrap script. It is now stored in a file named `VERSION` that is shipped in the release tarball. - We've stopped shipping the built man page for InitSocketTcti.3 and now ship the source.- removed leftover comment from dropped reproducable.patch- update to upstream version 1.3.0: - support for reproducable builds - improved documentation / manual pages - various stability bugfixes - EncryptDecrypt2 command is now implemented - removed reproducible.patch. This is now included upstream. - added version_fix.patch to fix package config version numbers.- fix the "fix", turns out only the unversioned symlink's supposed to go into - devel.- no longer install the udev rule, it's now part of the new tpm2.0-abrmd package. - fixed a warning regarding a missing dependency of the devel package to the main package - correctly package library symlinks only in the devel package, the library itself only in the library package. Was mixed up before.- removed tpm2-0-tss-configure.patch, it was just a hack, fixed by requiring autoconf-archive, see https://github.com/01org/TPM2.0-TSS/issues/227.- Updated to upstream version 1.1.0 - With this version the resourcemgr daemon is dropped from this package. It is replaced by a completely new implementation found in a new package tpm2.0-abrmd. this package will only consist of the libraries any more. - Changed - tpmclient, disabled all tests that rely on the old resourcemgr. - Fixed - Fixed definition of PCR_LAST AND TRANSIENT_LAST macros. - Removed - tpmtest - resourcemgr, replacement is in new repo: https://github.com/01org/tpm2-abrmd- Add reproducible.patch to sort input files to make build reproducible (boo#1041090)- create tss user account and install udev rule to fix startup of resourcemgr (bnc#1038586)- remove unnecessary dependency of libsapi0 to trousers. trousers has nothing to do with tpm2-tss.- fixed typo in resourcemgr.service (bsc#1031004)- Remove --with-pic which is only for static libs. - Fix an improper Requires line. - Split libtcti* from libsapi0; these are independentlty developable units.- Updated to 1.0 (FATE#321508) - Added - Travis-CI integration with GitHub - Unit tests for primitive (un)?marshal functions. - Example systemd unit for resourcemgr. - Allow for unit tests to be enabled selectively. - added pkg-config files for libraries - Changed - move simulator initialization code to socket TCTI init function. - socket TCTI finalize no longer frees context - rename libtss2 to libsapi - rename libtcti_device to libtcti-device - rename libtcti_socket to libtcti-socket - move $(includedir)/tss to $(includedir)/sapi - Move default compiler flags to config.site file. - Fixed - Fix run away resourcemgr threads by closing client sockets when resourcemgr recv() call returns 0. - Set MSG_NOSIGNAL for client connections to avoid SIGPIPE killing resourcemgr. - Fixes to handling of persistent objects by resourcemgr. - Removed - Semicolon from TPMA_* macros definitions. - Windows build files. - SAPI_CLIENT macro tests. - Security - Fix buffer overflow in resourcemgr. - use sample resourcemanager.service - tpm2-0-tss-configure.patch: fix weird error.- Remove type=forking from service file (bsc#995554)- added a systemd unit service file (FATE#315631)- Correct package naming to be in line with shared library guideline - Remove unused systemd build and runtime dependencies (FATE#315631)- Fix rpm group of library package: libs belong, per definition, to the group "System/Libraries". (FATE#315631)- initial import of the tpm 2.0 tss stack (FATE#315631)/sbin/ldconfig/sbin/ldconfigsheep58 16150292332.4.5-1.112.4.5-1.11libtss2-tctildr.so.0libtss2-tctildr.so.0.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:SLE-15-SP3:GA/standard/d6e961f3e176ac3ff46bdd7f76f067f7-tpm2-0-tsscpioxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=df829bcbc881d2d094e149daf5f7275e3a85843d, stripped PR RRRRRRRL1f#*&utf-8129e1d9edc2600115fdddd1d187aeb85e653ec8258988561115a651be0c037c2?7zXZ !t/k(y] cr$x#Dd8k+뿚%W$4Gy?Gq1Vt]gW~sDOԞ<alrdmZ3I 4u6J".S&Z4x_ؖFzy_ď9͉@m*NN1 . &0fJr=sVo3 _ڋ3p+zP"jcs&?MZHx@dc(5pE1{=QV}0\1d%[h7,@WeModdAKٴG##WӵdlCZ妸ִjYԸۓ<]I-V^ ͏=sJHMLWvy#fH82"#JB)Ycь'B#N7+ Vr x®w=z[ ;O`ǵS-^,`)yZkRJ4 1v?0AW0cRL,>PaY=%qAFz], Cmiϧܝ;ԤĂ'<;b5J6˧=գ@&/SӔ3CYUwxZ NUJd= & _ L$!߶9`e#W1ŀ/wזQas.BH_~@~&*zdw#W+O:&I y}lh,$tT!W&͍^SHNlB1,š`gT4Ev:b'$#m +5lqG2R `S'!{QḌilyÑ$Qp?o<g$B5q9 ()b{ۙ$4elV8\&d_7t*yp0T1pyN X IŸؤ}H ˏ 3i2n]zа$[j49/ k)MsRuTΒd@Q,,l[u.ͼǗiC4*8FF]CtYI:4c)3$(YC@LHY# lu!IX΃/ͣYvܗQT"G?tU=p]#IݍHsn*~L4Y.eH xIUs}_W C[ D6RRq"?~"/;~2)5I)`'M-[{{_t4"`m*t{?7o]6|Tޜl ٗl5:/xT2ŬCVD&ؕB6O͞f~'0ry_"5\EL׫c4o T5n(h_p2d$̲ -5$>mPcp#;#ZKu'^16j[1]JuLZ>2Ș?'Sޓ_NP+Dwqz5'H3ߥm`\kb,wq~KP =Rt$.;#.2%r+vԶEh"7 |(; ̌KMޏ|Y+wS֨p?[\"F(1x]!vMrK*z" _uvNꑐR+u(?)a (e\.o'k ^|GG9^&hf ^yHSP`|+#.1d@v׀&#ZR"Fgⶰ>v afS،d¸NP1߿w2kQX%YL]ce~s/9iQА{ cKD>k|6ZI=~,g' ý ̷ƿPoܫfG8˱Җ J%@[?72KV;&L| )lgp}Ljh&NYp`O_e4)z&K)! ]kș(g#|Gm)Ρ_#C &hA:-)ػqm̒`R4qOmϤ0+C;)/3v 3lzyǨqS[I(7QXCM0cg4jx :-?&ru,9-k}b…A`M9QnT>Qa5 ҖWx,P3#tO&Z9Nyya0M\-1?8n,ek[b~J[Ns97tg%UG21{,͊(ۏ uu2.o]81c }@&DI@nB70d60aIo)C{x,C(Akioq{ )sF}zB;/5'ߜnkNAdnĪbmekyx( Bg7X3 .2=%-Q=!\([Mj$%: &鈵 0BsrSP{n#tM̵q ̾Qnaⓡ[G-=5n+^`1ZVଽA`w&FTe\)DU 6;ZP!ݹ]!EBƖf8rUfaa, 􀲚ݱyT͗)*XmW:Xa({CbTqi!H5pj+>\|8X|Dˎ'hW+"H\F%G=P?ȍUi߈bknCTOVTP/PP لJύvĊtĒIRKF =iyg[>e|7s,݊;,TZ8NJ6 ,"\z~ÌEo }k;vej)5,R8\t \l^V=TyL+RisI!:SΞ po&fTHvC3B`GT 敏gS${AyHw뾛bfY7=x'ID?]q%Z a{,ݹ7z܎)=nPTBvMøQ7ѿo 2B ^M$ g0$k5[~F]ԵMM)+V LB?nΔ|@Y1RB 3:"信cǢU3Vx؝N;P߷ltw"!8,UF"ZqNմܺchF9Krߝ ]g;Gf]|L}"d ?mΝ K%J#%]VQ79ԣ 6א&:$qu}@aWB*&+YK +4h/ҍ~ԔEw`]3҅{|ZXڇqs2لA|{ !7 {6-l< FhSߕ>2Yc)vԎ+} ?DfV(krϬ q @vH^B'QWaגL"j#+;+6"ّFd>z:5/rD&&+#>.DUȒ`+~آyjz# ȗE{czY b,E=Vs#\0Y$|Zp(]X&CpW9zFIJ\|Hj0]WAAW]+cjߡ[l o6Nx6ϗ~Kb+ҋjb4Ni#)@J,>V-so^\(DD`L[1,7䟞5GM֤:ʃP2EKlSKpVnDp%Є>&[=kua#~+9l^xl꬚ G2P5ɞF#zHN ;Gĕ-qU 2 L~u >x qd)|ASҲ1+#N#^PzaWܮǮfUz1Wcz5:P|,P,`3&t/Ο}xt0jTQ078h {eTg:`=ahvE`5J _dEsq' [ewƬ=KYt8!|ʆ-'ڥ--yZH %wcgV|Dm50k6)/35o=X:Q*ZǰT얟2ʫRSwr9V|GQb][-F5rhS.XC]YS}qg$.FѱN#lj/lz`5XJϪOpJ\ncz% qrF/a4 ^a QQ],mJ f4.>5J, )!M@N.94: O݄飮S#-O.MsOy}2ҧA Y@!qܓ/_×VsMeT^XNP;cmꚌ_$$cGv lh4UZ{B0RTMԵeo2QɿB1 k[4'쬆0Q *Bm?پI`fO|s[R[{.Se)d]aIBJ Rh5Ρ* WUvO.FWxG[g\NJt)䁞E6KC񌵚Z>zfuO!܂dX*6E5pG,nCvZSz3DbӍz:JgY {v uKa&-+TpD\ KǺwӟ5 XǫȂq?s*P3mx>;d/ȒCwvb*1ENqu\GUyd<8ݰ\$F;V~Ȥz 8. X@HA^G QNp+  ]q q=0Pe۴L34bF&DxKU/+](YŰD_P"&(f r˸tnᨣ0:|(6=Q=a&1\i-y G*T%vL"qFHy.~hdahppOFڊo0VRv+@QɄfOyC .yO̷xw0R!"aU7h}pa_}݅qy~ 0 aEpm >}  To bM z`-U  pS}s k ,d݊Ն^5簙/D۴raqZρ^D^G; -~,_;1K+6bC-JX~G>V) fD4{}|Ӑ)x>*bh"Ts\vӨ ,3e1 ѿ5_ހ =A9N@- : 0;mW,FINs[P(Xrf!65rA䲸yCzpxJcP0ԜˆW\ cઆM9 e>+ˊk8"Y hßCuWjģcqBPpq>_u[Ƃ]26%BI>u"_c2!qdu2ϫ^*#W8"Ǹ GEtv VH3˟+x lXtv/bjUor J[墬^ ѽJwɲcrD&ܻ43.UFL G|R(N{*hB^E8Q=`Zzt }U$ra,PlϤ% 맨hY¥+ 'Q.--'7Wiє{butG KZ9 vRSq][ug30~F =c)cE:f] ˔>wh^.SÆdD\yL9BTl*k > 4'fa2Z!eh[.RqM͢tvw>b1h&iy>#Q,pq[~RUs¬M8˓)r -p fx칟/Frtn^nT M;>KaIs}bm5$~^i53\fb6ӬLF_W7pWhI6.w~TA+S@'M.D:=ކm}$rgB]GZT4?:xqs Q>XARWu5 0۱iOw\=ޯ ZՐD &* wɰ+#AZPNefeR;dxod;i `l8ԣv{9+$W,jMo>E~nR oSlEoJ0'ȱ<#RZE6cM" iEi0ua ,2.Icqu5x>Yђۃluŕ\*PҠF/ |ۋUSKqvOq[/?q4VH#Ѽ#

;fM-Ԁ8l{J8{}^{#*Z#'o|iYtK6:"n~zp}5;?Fv;¼İc66E&Z0$,J $k)1_nr< f'~S򃏃JA F@{&O!U[ Ɓ=S!h}e! 2BE>QCWN\ojV?1t//x44u2CܠKB48[ȁ?rF5f6Iuژ<ܰ {BtEqD&ڈv ǬB4Kh ߨ7?:ר|SfwJ(ـ<Bzq$E"to۾eȼM 9閦ժ#!3aof`$ˌxS=@AG b|Wx rSR[#̂ɹ!uf$4SSԵ Į{N;pPsLeK͓aBWd_Q<ͰIUxBr`4S~ 1w4ܚuba @&Z;aoAf/fACrCj1`[H]}sKa,\$~hvg~`U}iFVn쭛7u(YH;"b1ܹ?SpiNV;Cb8_nȟ@ ʭ.a4te|[Z 2G^ tF d; sTPjõ̧Y4) H~|܉&aHe `+9fF% JHգ+? D(5԰QUо@_sU}Dj}}[^̷ys(cBx\;}#vˢRrm,SLU3{K.d=7J538ʤE.kIb͍ p_Xcs}q,V Q٣|d0 aMmƝsb|p1]b|M.>q+#>YLxjY"^^&v-yydqj %~jSkT"G3wgUQLQlAh{@$sxa?PˉGPǭzy<~K{%h?wh+G}pI͹RpܞxVE?^-'5uh8.{a2̾gC?]&=>lgܙTE6)Z4+Ssk<5nED@q[?D 9kl:p0rmnCTʛE#B sA9`DoKdK=*-0)8'=VF$bk`=[jC&^_a{u;m's