cryptsetup-2.0.6-lp152.4.3.1<>,}_a-ɸ/=„ % 5$Hʎmvy) tLi)6iy}y]\¢|C5QHVuDŽxYRN% 3Jĸlh:zӓՈb;0FCgT_b9xK75NQK+,#uL#5vO1J⺻a";NVe#fZnf;ޒVEv91ݍӪ^bU/]3i|/%+&Jt` J kȯǂ?6%>D?d   M =CJ&lGG G G G G dGGGFlG$!:(!q8!x9!:">v@vFvGw GHx(GIyDGXyYy\yG]zG^b?cd|efluGv wGx4GyPNz=HLRCcryptsetup2.0.6lp152.4.3.1Set Up dm-crypt Based Encrypted Block Devicescryptsetup is used to conveniently set up dm-crypt based device-mapper targets. It allows to set up targets to read cryptoloop compatible volumes as well as LUKS formatted ones. The package additionally includes support for automatically setting up encrypted volumes at boot time via the config file /etc/crypttab._a-goat13MopenSUSE Leap 15.2openSUSESUSE-GPL-2.0-with-openssl-exception AND LGPL-2.0-or-laterhttp://bugs.opensuse.orgSystem/Basehttps://gitlab.com/cryptsetup/cryptsetup/linuxx86_64 mkdir -p /run/regenerate-initrd/ touch /run/regenerate-initrd/all [ -z "${TRANSACTIONAL_UPDATE}" -a -x /usr/bin/systemd-tmpfiles ] && /usr/bin/systemd-tmpfiles --create /usr/lib/tmpfiles.d/cryptsetup.conf || : mkdir -p /run/regenerate-initrd/ touch /run/regenerate-initrd/all#yxfIrjodgN i:y^ 7!%9C E  [+AhG729#:EBlB8GH-G17XmGMJ @A큤_a-_a-_a-_a-_a-_a-_a-_a-S}O1d`PȈZt{[TV̋VZt{O1d`O1d`O1d`O1d`O1d`O1d`Zt{O1d`Zt{O1d`OSO&O [P}Pa)QNS$S$S$SS UCVN)WʈW,W,YYYZt{Zt{[T[T[U[A\_a-_a-_a-_a-_a-_a-_a-_a-_a-_a-_a-_a-_a-_a-_a-_a-_a-_a-_a-_a-d6bb4b689200c2348945700a6b0dad5df92bc2015860d15f36a25590814d77b03b99aa930fe4d68810fe2a589a846b301bd9d527cc1b8d943a7c36db6a9d1d0607e4493d29be70499d763d2d6adaf71bb79497bd0111ab9fc63174b56c096e81a5f18e563f2dbb38d94744e1fe5d7ee7ca05960589b469c0bab38504c8129b6c6404f08cadad99a13c0480f17ee36f318576401850b64fc9a43bad27906e52b8a7837aee5b822c01c64b81517b071218874aec603ad6624f3f559c2dd6a8ca1245670cce8b6a0ddd66c8016cd8ccef6cd71f35717cbacc7f1e895b3855207b338c33cc37871654ec7ed87e6fbb896c8cf33ef5ef05b1611a5aed857596ffafa5c0c35222dd8552610cb4f1d1559e6b09c8ea04b1888d25202787772f1332dfab88139e083bd0d541f2d25a13da34c797a57e3ab3dc8cdc29783f611dc5a7ec7f3fe9c1111453360d298c1a4afda5f84aebde925fa164cc30e14c8d31e4686ba7325800b1569fc977bde2337bffdd20077a5b5dd98f172c944e32b75a19556e3504505ff6feb42cb3fc27cd79c52b0a8dd446ebac636db57e47b466f2fb6f870e0b3b98db51402d5c6b54a76f049fe834f385bb0a81a195148c217776c29abb2885f985ae4dd6fa76e34b4abff697d973821ac6bb255e00ec8844fbf9fd7d936c0db4517a88ecd842a1ea48360c45563ef051ba71d51d6e5d40e240516536d8b7972e5fc2fc53522a41cf685cde1ed92ab42df50f608dad44b533a20d1468ba2ae01c5c98071c7c98d4d62b7af278c2c3c38a89a9f2aea7811e8078f34a6eaa99f921b65038a98a6281769a64e90528394c11e9f58978945cfbf058bd72d251bbd9f325cc7b69e35a3235b851f6e3d8db5d01d717afac72ba452ddca753be93df085ea8c727c1487e11b032c9357a5187ec8ef86d16f0bbb3d8f357ad4cf780c425b2628be5d85dad2656f925cee0b464f53c3a669223fb6a43dc581a27fbbbc5f6e280116a8aa26191a7f768e9dab9d82735c4b48a4aad0824763d081418a034a40f6b268b8cfbabdfe510845bf2de9d20af02dc914a3eebfc7bab6697989cc85e43b39da1f941f335b5137c8b33216f3665f2df5b74a2186760d518babfcddf758112ba6c3946c2b6fa183d6a3662b3b34c09ebb40140613400e779506f22b7e005ddf07eb9e34df8ddfb5a6b053e7f1a57b4e44ebebf4c14ad2725bc3c40790fdac009890d44f3383abd33132f3f6e5e2114b5cc22df9a8b90cff57b061562ae48b74ffa53d0870533233fd1052e3f707216cf5f4f5941b0a67a5fc4a061e9d198ff7ffb01319f58779842a605461416c316bdf058e6e9091be4a69251bfe3556c7156ea0bfcd002f24822c0ba3cdd2cebfa9dc6b2463fe259b455c858bd7ebe5988a8fa6a4715c6bd4115489dbbc697f5a5b34058fc475b7c0db7f5faa108eefef8259641d4e435288c77eaa861163c2ce048a82cac90d17ddaa9adefe6a0b0f5fd155f4a31e4b4c3b3a31833d66f425462368041359d6a3165839ba3d51ee8b791da4adbf42e9b8aecd710112cf0a60bc6f9dcfa2f9caf91dcd6559d630eff407694c22b8a7f3217e5987a59b232ca2c7ea4cd3014c1c5fd4c941b0b767fd8d3246cbf48031d37564c8e6b56394dfbce815f6977954291049b53e440d880b42705939d9a513836df7abf4ffa7155ff9a1d2b1cf4c132390aaaa81594537ebee834ef41dd79e3430310491ccd9afd39971af54a580151557aaa9b9b822912260109b314fec98a14b4e525681877a2205703f005ca6aa56ae54a692356508326d024e1af8779187808b94aac22d36fd2b16c1be1f9bd7062999e28638cf4bd50f9c18e06632bc8660889bf0f45d52f09d6491d5291fe8619b329f6495be879093e92fb88c7c771bc0ba7da4f99386c80e0da2637249fe7fd99a57966d1d1e20dfae75a4967bd4676a882e6c13c121806f093d7e9426ce22275f598942b4fb7509951305b214b8b8f847e4ba4b26a3d9654105680cc2e7fdadd4c5c2260b6e19016a7ba548ea78bb8c562a4a1c68753bcab7104110d3df6fa239d54bdd8edc6c165c348ead91ad0e6ceea6aaeea0f71128d8187b4583eef22f3f3eba95a642bb9587909ff0eca1c2951afba46b0197f4b7c5428eb5a85bf730e9f756aa2859346bfac37373701233a0d60fc6055f3d94da49c03a7882fd3d498632d70fbd6c0db57c57bc6bb35165258f3094e6227ebd11ab04a423070437690cd7a10bd4beb2dadd3e165c2ccd25cf91e8ce7e784371b2bde24e653d327836fb9ae76a570c4edb3a5f064177cde8ff10f6821c0ab1a898ef8ae884a02b0187ff705b250d4fa28d6b0210e7f4be1b259e383b56c44d6804f1221f61ed9afbefa1260671ee6e5493d8817804337c65cbb008a0583c1e56c4fdf52e00df2cb7141d9f14da19fdc7cfb80aed1ddd3710b56a6fa11e3d75c1fe793607d2e1d40c3447841d2a38070b848577f15beda8f85f109797aaa84ed5598f689b8f2c5655476ea40fcbe39543dac3c60327202ef6c8e1c0cd266ffe5f0d8dd8f659acfd959007dea7523e2ce949e969070e9328a07a1f6782a2372d61617293bc2b63d030508feef745d3bb439dfa257ec847dcd8843f8ed9610d6554b0eecc710f1cf25157cf1e2f519edcee21f668b783ba516abab22b0260ca4d967ca0485c93b1fed3018ab6c198e35d26734441749d39cc683b0dcacc7ba8ec731db802a527e44fe8eebe0071e84381a2f531298c3ce3d62bb94cf1d6a958de66ad89229aef7bcc80bf1fea19948cf76f617380006fe6fc0c934f96dfd6042ab8347838391dbfc41b755166bfac7b0d587c829da4ce51f1987586e43e06e627557c0cfed351c4ee114657e50063eda1d826a24f6a134a822bd0091b1c21e728006b98f564d00d1248ab1032d211023d85b05feda20fd3decee4c2332e01ce5cc25c553a23ab055b2e7fa8cc2e61ef772b4589415b4d58d00dff388770227c8fa8793ba38680516d9a67bd4dbd20b90335d5af10a92dd5123351dea5fb070ab6bbe0f6b613355eb8356b5cc5bf8316ce6/usr/sbin/cryptsetup@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcryptsetup-2.0.6-lp152.4.3.1.src.rpmcryptsetupcryptsetup(x86-64) @@@@@@@@@@@@@@@@@@@@@@    /bin/sh/bin/sh/bin/shcoreutilscoreutilslibblkid.so.1()(64bit)libblkid.so.1(BLKID_2.15)(64bit)libblkid.so.1(BLKID_2.17)(64bit)libblkid.so.1(BLKID_2.21)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.15)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.25)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcryptsetup.so.12()(64bit)libcryptsetup.so.12(CRYPTSETUP_2.0)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpwquality.so.1()(64bit)libpwquality.so.1(LIBPWQUALITY_1.0)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1]@[G[G[{Zp^@Zlnussel@suse.delnussel@suse.delnussel@suse.deastieger@suse.comarchie.cobbs@gmail.commpluskal@suse.commpluskal@suse.comalexander_naumov@opensuse.orgbenoit.monin@gmx.frtiwai@suse.deasterios.dramis@gmail.comcrrodriguez@opensuse.orgcrrodriguez@opensuse.orgmpluskal@suse.com- New version 2.0.6 (jsc#SLE-5911, bsc#1165580): Changes since version 2.0.5 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Fix support of larger metadata areas in LUKS2 header. This release properly supports all specified metadata areas, as documented in LUKS2 format description (see docs/on-disk-format-luks2.pdf in archive). Currently, only default metadata area size is used (in format or convert). Later cryptsetup versions will allow increasing this metadata area size. * If AEAD (authenticated encryption) is used, cryptsetup now tries to check if the requested AEAD algorithm with specified key size is available in kernel crypto API. This change avoids formatting a device that cannot be later activated. For this function, the kernel must be compiled with the CONFIG_CRYPTO_USER_API_AEAD option enabled. Note that kernel user crypto API options (CONFIG_CRYPTO_USER_API and CONFIG_CRYPTO_USER_API_SKCIPHER) are already mandatory for LUKS2. * Fix setting of integrity no-journal flag. Now you can store this flag to metadata using --persistent option. * Fix cryptsetup-reencrypt to not keep temporary reencryption headers if interrupted during initial password prompt. * Adds early check to plain and LUKS2 formats to disallow device format if device size is not aligned to requested sector size. Previously it was possible, and the device was rejected to activate by kernel later. * Fix checking of hash algorithms availability for PBKDF early. Previously LUKS2 format allowed non-existent hash algorithm with invalid keyslot preventing the device from activation. * Allow Adiantum cipher construction (a non-authenticated length-preserving fast encryption scheme), so it can be used both for data encryption and keyslot encryption in LUKS1/2 devices. For benchmark, use: [#] cryptsetup benchmark -c xchacha12,aes-adiantum [#] cryptsetup benchmark -c xchacha20,aes-adiantum For LUKS format: [#] cryptsetup luksFormat -c xchacha20,aes-adiantum-plain64 -s 256 The support for Adiantum will be merged in Linux kernel 4.21. For more info see the paper https://eprint.iacr.org/2018/720.- Suggest hmac package (boo#1090768) - remove old upgrade hack for upgrades from 12.1 - New version 2.0.5 Changes since version 2.0.4 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Wipe full header areas (including unused) during LUKS format. Since this version, the whole area up to the data offset is zeroed, and subsequently, all keyslots areas are wiped with random data. This ensures that no remaining old data remains in the LUKS header areas, but it could slow down format operation on some devices. Previously only first 4k (or 32k for LUKS2) and the used keyslot was overwritten in the format operation. * Several fixes to error messages that were unintentionally replaced in previous versions with a silent exit code. More descriptive error messages were added, including error messages if - a device is unusable (not a block device, no access, etc.), - a LUKS device is not detected, - LUKS header load code detects unsupported version, - a keyslot decryption fails (also happens in the cipher check), - converting an inactive keyslot. * Device activation fails if data area overlaps with LUKS header. * Code now uses explicit_bzero to wipe memory if available (instead of own implementation). * Additional VeraCrypt modes are now supported, including Camellia and Kuznyechik symmetric ciphers (and cipher chains) and Streebog hash function. These were introduced in a recent VeraCrypt upstream. Note that Kuznyechik requires out-of-tree kernel module and Streebog hash function is available only with the gcrypt cryptographic backend for now. * Fixes static build for integritysetup if the pwquality library is used. * Allows passphrase change for unbound keyslots. * Fixes removed keyslot number in verbose message for luksKillSlot, luksRemoveKey and erase command. * Adds blkid scan when attempting to open a plain device and warn the user about existing device signatures in a ciphertext device. * Remove LUKS header signature if luksFormat fails to add the first keyslot. * Remove O_SYNC from device open and use fsync() to speed up wipe operation considerably. * Create --master-key-file in luksDump and fail if the file already exists. * Fixes a bug when LUKS2 authenticated encryption with a detached header wiped the header device instead of dm-integrity data device area (causing unnecessary LUKS2 header auto recovery).- make parallell installable version for SLE12- New version 2.0.4 Changes since version 2.0.3 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Use the libblkid (blockid) library to detect foreign signatures on a device before LUKS format and LUKS2 auto-recovery. This change fixes an unexpected recovery using the secondary LUKS2 header after a device was already overwritten with another format (filesystem or LVM physical volume). LUKS2 will not recreate a primary header if it detects a valid foreign signature. In this situation, a user must always use cryptsetup repair command for the recovery. Note that libcryptsetup and utilities are now linked to libblkid as a new dependence. To compile code without blockid support (strongly discouraged), use --disable-blkid configure switch. * Add prompt for format and repair actions in cryptsetup and integritysetup if foreign signatures are detected on the device through the blockid library. After the confirmation, all known signatures are then wiped as part of the format or repair procedure. * Print consistent verbose message about keyslot and token numbers. For keyslot actions: Key slot unlocked/created/removed. For token actions: Token created/removed. * Print error, if a non-existent token is tried to be removed. * Add support for LUKS2 token definition export and import. The token command now can export/import customized token JSON file directly from command line. See the man page for more details. * Add support for new dm-integrity superblock version 2. * Add an error message when nothing was read from a key file. * Update cryptsetup man pages, including --type option usage. * Add a snapshot of LUKS2 format specification to documentation and accordingly fix supported secondary header offsets. * Add bundled optimized Argon2 SSE (X86_64 platform) code. If the bundled Argon2 code is used and the new configure switch - -enable-internal-sse-argon2 option is present, and compiler flags support required optimization, the code will try to use optimized and faster variant. Always use the shared library (--enable-libargon2) if possible. This option was added because an enterprise distribution rejected to support the shared Argon2 library and native support in generic cryptographic libraries is not ready yet. * Fix compilation with crypto backend for LibreSSL >= 2.7.0. LibreSSL introduced OpenSSL 1.1.x API functions, so compatibility wrapper must be commented out. * Fix on-disk header size calculation for LUKS2 format if a specific data alignment is requested. Until now, the code used default size that could be wrong for converted devices. Changes since version 2.0.2 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Expose interface to unbound LUKS2 keyslots. Unbound LUKS2 keyslot allows storing a key material that is independent of master volume key (it is not bound to encrypted data segment). * New API extensions for unbound keyslots (LUKS2 only) crypt_keyslot_get_key_size() and crypt_volume_key_get() These functions allow to get key and key size for unbound keyslots. * New enum value CRYPT_SLOT_UNBOUND for keyslot status (LUKS2 only). * Add --unbound keyslot option to the cryptsetup luksAddKey command. * Add crypt_get_active_integrity_failures() call to get integrity failure count for dm-integrity devices. * Add crypt_get_pbkdf_default() function to get per-type PBKDF default setting. * Add new flag to crypt_keyslot_add_by_key() to force update device volume key. This call is mainly intended for a wrapped key change. * Allow volume key store in a file with cryptsetup. The --dump-master-key together with --master-key-file allows cryptsetup to store the binary volume key to a file instead of standard output. * Add support detached header for cryptsetup-reencrypt command. * Fix VeraCrypt PIM handling - use proper iterations count formula for PBKDF2-SHA512 and PBKDF2-Whirlpool used in system volumes. * Fix cryptsetup tcryptDump for VeraCrypt PIM (support --veracrypt-pim). * Add --with-default-luks-format configure time option. (Option to override default LUKS format version.) * Fix LUKS version conversion for detached (and trimmed) LUKS headers. * Add luksConvertKey cryptsetup command that converts specific keyslot from one PBKDF to another. * Do not allow conversion to LUKS2 if LUKSMETA (external tool metadata) header is detected. * More cleanup and hardening of LUKS2 keyslot specific validation options. Add more checks for cipher validity before writing metadata on-disk. * Do not allow LUKS1 version downconversion if the header contains tokens. * Add "paes" family ciphers (AES wrapped key scheme for mainframes) to allowed ciphers. Specific wrapped ley configuration logic must be done by 3rd party tool, LUKS2 stores only keyslot material and allow activation of the device. * Add support for --check-at-most-once option (kernel 4.17) to veritysetup. This flag can be dangerous; if you can control underlying device (you can change its content after it was verified) it will no longer prevent reading tampered data and also it does not prevent silent data corruptions that appear after the block was once read. * Fix return code (EPERM instead of EINVAL) and retry count for bad passphrase on non-tty input. * Enable support for FEC decoding in veritysetup to check dm-verity devices with additional Reed-Solomon code in userspace (verify command). Changes since version 2.0.1 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Fix a regression in early detection of inactive keyslot for luksKillSlot. It tried to ask for passphrase even for already erased keyslot. * Fix a regression in loopaesOpen processing for keyfile on standard input. Use of "-" argument was not working properly. * Add LUKS2 specific options for cryptsetup-reencrypt. Tokens and persistent flags are now transferred during reencryption; change of PBKDF keyslot parameters is now supported and allows to set precalculated values (no benchmarks). * Do not allow LUKS2 --persistent and --test-passphrase cryptsetup flags combination. Persistent flags are now stored only if the device was successfully activated with the specified flags. * Fix integritysetup format after recent Linux kernel changes that requires to setup key for HMAC in all cases. Previously integritysetup allowed HMAC with zero key that behaves like a plain hash. * Fix VeraCrypt PIM handling that modified internal iteration counts even for subsequent activations. The PIM count is no longer printed in debug log as it is sensitive information. Also, the code now skips legacy TrueCrypt algorithms if a PIM is specified (they cannot be used with PIM anyway). * PBKDF values cannot be set (even with force parameters) below hardcoded minimums. For PBKDF2 is it 1000 iterations, for Argon2 it is 4 iterations and 32 KiB of memory cost. * Introduce new crypt_token_is_assigned() API function for reporting the binding between token and keyslots. * Allow crypt_token_json_set() API function to create internal token types. Do not allow unknown fields in internal token objects. * Print message in cryptsetup that about was aborted if a user did not answer YES in a query.- update to 2.0.1: * To store volume key into kernel keyring, kernel 4.15 with dm-crypt 1.18.1 is required * Increase maximum allowed PBKDF memory-cost limit to 4 GiB * Use /run/cryptsetup as default for cryptsetup locking dir * Introduce new 64-bit byte-offset *keyfile_device_offset functions. * New set of fucntions that allows 64-bit offsets even on 32bit systems are now availeble: - crypt_resume_by_keyfile_device_offset - crypt_keyslot_add_by_keyfile_device_offset - crypt_activate_by_keyfile_device_offset - crypt_keyfile_device_read The new functions have added the _device_ in name. Old functions are just internal wrappers around these. * Also cryptsetup --keyfile-offset and --new-keyfile-offset now allows 64-bit offsets as parameters. * Add error hint for wrongly formatted cipher strings in LUKS1 and properly fail in luksFormat if cipher format is missing required IV.- Update to version 2.0.0: * Add support for new on-disk LUKS2 format * Enable to use system libargon2 instead of bundled version * Install tmpfiles.d configuration for LUKS2 locking directory * New command integritysetup: support for the new dm-integrity kernel target * Support for larger sector sizes for crypt devices * Miscellaneous fixes and improvements- Update to version 1.7.5: * Fixes to luksFormat to properly support recent kernel running in FIPS mode (bsc#1031998). * Fixes accesses to unaligned hidden legacy TrueCrypt header. * Fixes to optional dracut ramdisk scripts for offline re-encryption on initial boot.- Update to version 1.7.4: * Allow to specify LUKS1 hash algorithm in Python luksFormat wrapper. * Use LUKS1 compiled-in defaults also in Python wrapper. * OpenSSL backend: Fix OpenSSL 1.1.0 support without backward compatible API. * OpenSSL backend: Fix LibreSSL compatibility. * Check for data device and hash device area overlap in veritysetup. * Fix a possible race while allocating a free loop device. * Fix possible file descriptor leaks if libcryptsetup is run from a forked process. * Fix missing same_cpu_crypt flag in status command. * Various updates to FAQ and man pages. - Changes for version 1.7.3: * Fix device access to hash offsets located beyond the 2GB device boundary in veritysetup. * Set configured (compile-time) default iteration time for devices created directly through libcryptsetup * Fix PBKDF2 benchmark to not double iteration count for specific corner case. * Verify passphrase in cryptsetup-reencrypt when encrypting a new drive. * OpenSSL backend: fix memory leak if hash context was repeatedly reused. * OpenSSL backend: add support for OpenSSL 1.1.0. * Fix several minor spelling errors. * Properly check maximal buffer size when parsing UUID from /dev/disk/.- Update to version 1.7.2: * Update LUKS documentation format. Clarify fixed sector size and keyslots alignment. * Support activation options for error handling modes in Linux kernel dm-verity module: - -ignore-corruption - dm-verity just logs detected corruption - -restart-on-corruption - dm-verity restarts the kernel if corruption is detected If the options above are not specified, default behavior for dm-verity remains. Default is that I/O operation fails with I/O error if corrupted block is detected. - -ignore-zero-blocks - Instructs dm-verity to not verify blocks that are expected to contain zeroes and always return zeroes directly instead. NOTE that these options could have security or functional impacts, do not use them without assessing the risks! * Fix help text for cipher benchmark specification (mention --cipher option). * Fix off-by-one error in maximum keyfile size. Allow keyfiles up to compiled-in default and not that value minus one. * Support resume of interrupted decryption in cryptsetup-reencrypt utility. To resume decryption, LUKS device UUID (--uuid option) option must be used. * Do not use direct-io for LUKS header with unaligned keyslots. Such headers were used only by the first cryptsetup-luks-1.0.0 release (2005). * Fix device block size detection to properly work on particular file-based containers over underlying devices with 4k sectors. - Update to version 1.7.1: * Code now uses kernel crypto API backend according to new changes introduced in mainline kernel While mainline kernel should contain backward compatible changes, some stable series kernels do not contain fully backported compatibility patches. Without these patches most of cryptsetup operations (like unlocking device) fail. This change in cryptsetup ensures that all operations using kernel crypto API works even on these kernels. * The cryptsetup-reencrypt utility now properly detects removal of underlying link to block device and does not remove ongoing re-encryption log. This allows proper recovery (resume) of reencrypt operation later. NOTE: Never use /dev/disk/by-uuid/ path for reencryption utility, this link disappears once the device metadata is temporarily removed from device. * Cryptsetup now allows special "-" (standard input) keyfile handling even for TCRYPT (TrueCrypt and VeraCrypt compatible) devices. * Cryptsetup now fails if there are more keyfiles specified for non-TCRYPT device. * The luksKillSlot command now does not suppress provided password in batch mode (if password is wrong slot is not destroyed). Note that not providing password in batch mode means that keyslot is destroyed unconditionally.- update to 1.7.0: * The cryptsetup 1.7 release changes defaults for LUKS, there are no API changes. * Default hash function is now SHA256 (used in key derivation function and anti-forensic splitter). * Default iteration time for PBKDF2 is now 2 seconds. * Fix PBKDF2 iteration benchmark for longer key sizes. * Remove experimental warning for reencrypt tool. * Add optional libpasswdqc support for new LUKS passwords. * Update FAQ document.- Fix missing dependency on coreutils for initrd macros (boo#958562) - Call missing initrd macro at postun (boo#958562)- Update to 1.6.8 * If the null cipher (no encryption) is used, allow only empty password for LUKS. (Previously cryptsetup accepted any password in this case.) The null cipher can be used only for testing and it is used temporarily during offline encrypting not yet encrypted device (cryptsetup-reencrypt tool). Accepting only empty password prevents situation when someone adds another LUKS device using the same UUID (UUID of existing LUKS device) with faked header containing null cipher. This could force user to use different LUKS device (with no encryption) without noticing. (IOW it prevents situation when attacker intentionally forces user to boot into different system just by LUKS header manipulation.) Properly configured systems should have an additional integrity protection in place here (LUKS here provides only confidentiality) but it is better to not allow this situation in the first place. (For more info see QubesOS Security Bulletin QSB-019-2015.) * Properly support stdin "-" handling for luksAddKey for both new and old keyfile parameters. * If encrypted device is file-backed (it uses underlying loop device), cryptsetup resize will try to resize underlying loop device as well. (It can be used to grow up file-backed device in one step.) * Cryptsetup now allows to use empty password through stdin pipe. (Intended only for testing in scripts.)- Enable verbose build log.- regenerate the initrd if cryptsetup tool changes (wanted by 90crypt dracut module)- Update to 1.6.7 * Cryptsetup TCRYPT mode now supports VeraCrypt devices (TrueCrypt extension) * Support keyfile-offset and keyfile-size options even for plain volumes. * Support keyfile option for luksAddKey if the master key is specified. * For historic reasons, hashing in the plain mode is not used if keyfile is specified (with exception of --key-file=-). Print a warning if these parameters are ignored. * Support permanent device decryption for cryptsetup-reencrypt. To remove LUKS encryption from a device, you can now use - -decrypt option. * Allow to use --header option in all LUKS commands. The - -header always takes precedence over positional device argument. * Allow luksSuspend without need to specify a detached header. * Detect if O_DIRECT is usable on a device allocation. There are some strange storage stack configurations which wrongly allows to open devices with direct-io but fails on all IO operations later. * Add low-level performance options tuning for dmcrypt (for Linux 4.0 and later). * Get rid of libfipscheck library. (Note that this option was used only for Red Hat and derived distributions.) With recent FIPS changes we do not need to link to this FIPS monster anymore. Also drop some no longer needed FIPS mode checks. * Many fixes and clarifications to man pages. * Prevent compiler to optimize-out zeroing of buffers for on-stack variables. * Fix a crash if non-GNU strerror_r is used./bin/sh/bin/shgoat13 1600204233  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGcsdadeesfifriditnlplptsrsvukvizh2.0.6-lp152.4.3.12.0.6-lp152.4.3.1 cryptsetupcryptsetupcryptsetup.confcryptsetupcryptsetup-reencryptintegritysetupveritysetupcryptsetupAUTHORSCOPYINGCOPYING.LGPLChangeLog.oldFAQREADMETODOv1.0.7-ReleaseNotesv1.1.0-ReleaseNotesv1.1.1-ReleaseNotesv1.1.2-ReleaseNotesv1.1.3-ReleaseNotesv1.2.0-ReleaseNotesv1.3.0-ReleaseNotesv1.3.1-ReleaseNotesv1.4.0-ReleaseNotesv1.4.1-ReleaseNotesv1.4.2-ReleaseNotesv1.4.3-ReleaseNotesv1.5.0-ReleaseNotesv1.5.1-ReleaseNotesv1.6.0-ReleaseNotesv1.6.1-ReleaseNotesv1.6.2-ReleaseNotesv1.6.3-ReleaseNotesv1.6.4-ReleaseNotesv1.6.5-ReleaseNotesv1.6.6-ReleaseNotesv1.6.7-ReleaseNotesv1.6.8-ReleaseNotesv1.7.0-ReleaseNotesv1.7.1-ReleaseNotesv1.7.2-ReleaseNotesv1.7.3-ReleaseNotesv1.7.4-ReleaseNotesv1.7.5-ReleaseNotesv2.0.0-ReleaseNotesv2.0.1-ReleaseNotesv2.0.2-ReleaseNotesv2.0.3-ReleaseNotesv2.0.4-ReleaseNotesv2.0.5-ReleaseNotesv2.0.6-ReleaseNotescryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup-reencrypt.8.gzcryptsetup.8.gzintegritysetup.8.gzveritysetup.8.gz/run//sbin//usr/lib/tmpfiles.d//usr/sbin//usr/share/doc/packages//usr/share/doc/packages/cryptsetup//usr/share/locale/cs/LC_MESSAGES//usr/share/locale/da/LC_MESSAGES//usr/share/locale/de/LC_MESSAGES//usr/share/locale/es/LC_MESSAGES//usr/share/locale/fi/LC_MESSAGES//usr/share/locale/fr/LC_MESSAGES//usr/share/locale/id/LC_MESSAGES//usr/share/locale/it/LC_MESSAGES//usr/share/locale/nl/LC_MESSAGES//usr/share/locale/pl/LC_MESSAGES//usr/share/locale/pt_BR/LC_MESSAGES//usr/share/locale/sr/LC_MESSAGES//usr/share/locale/sv/LC_MESSAGES//usr/share/locale/uk/LC_MESSAGES//usr/share/locale/vi/LC_MESSAGES//usr/share/locale/zh_CN/LC_MESSAGES//usr/share/man/man8/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:14041/openSUSE_Leap_15.2_Update/e2e0104882693f52cbf2d9700907fb01-cryptsetup.openSUSE_Leap_15.2_Updatedrpmxz5x86_64-suse-linuxdirectoryASCII textELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, BuildID[sha1]=d77175ee1f1a08c761cdffaa50d4439acc5741e0, for GNU/Linux 3.2.0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, BuildID[sha1]=5354d3e3c892b1e39c636a980c1d5782de7eadcb, for GNU/Linux 3.2.0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, BuildID[sha1]=e24d7743c13269aa8e009e6b6559375cb848048a, for GNU/Linux 3.2.0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, BuildID[sha1]=a21d1a1ed28dd6c0a58e0f4452a90105d9c90606, for GNU/Linux 3.2.0, strippedUTF-8 Unicode texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)+>RRRRR RR RR RRRR RRRRRRRRR RRRRRRRR RR RR RRR RRRRRR RRRRR RR RRRR RRRRRRRR RRRR RR RRR RRRRRRR U2> VF if test -x /usr/lib/module-init-tools/regenerate-initrd-posttrans; then /bin/bash -c 'set +e; /usr/lib/module-init-tools/regenerate-initrd-posttrans' fi #/bin/shutf-80e7d1d825106b16bbd70db41fb957ada488859d7712a2a7489ba2e8b112240df?7zXZ !t/I]"k%{Aٙz |25YǒUdq=ޚO}?%c5S S@quuxcȲB+FGD$}A]}W- <^rw!cfݐ8!~G76$%\,G dˤ[uXvr/XwUw ,%&'yNͿEЙd݁k+MY0V|.ϙvR|ĮmZ] -{rgmguХWN])6k'ni: +MfZ .&nrHrm\'5҃3QŘ,S"L~3<<}{n¢vKf$7yHNOK3do{!i2pJz{K  RdTs΂(_0fF%`?|>&w$NHnw?;H@B ]3l r%AlCtD]bKy't??8۞Ffnn×h^O2?I)cr#ThR]U}U{URU>zqFuubE)!:l/V7+v`rA[tPk6SjLO΅*aCYDr 3>S<v- 95 5TE܉,pӂy^l+a fLJ U!HOvɭ/b8R{jVpPaRٿԥPr5D5r[A7a ˥h^7fKۤl(ވ:eG r;[;@doB䙿mY߄T:}͓1(}o_s/ vZd#oa%k+-FXF|*.pMhq<̎>> 7^$e JXC:H2ٗ5S:X,kq inq(0:g9|q_r|85f|ʻbEmi-<xaHEB /tϫY,Z+_)QA{p( 縷zW cSA>;NƩԶH`܆s[بuWb55OD=gfN=n M *MbpE?}i8[e{(C藒+M Kuy6{:!NXѾRv&OCzD|ВBԐ&{&\3=+J-߄0ֺ)a1(?Dn€kwdٝ^~!oG4Cg:G Ըy ׇ(ON[2:o "¯7 H P̴ͩA{$YErPf"Fѕox Ix^TSم8ilw5cwMFe]_ztEʴ`wfV: 8n{^9+E갶sZSQ4VX -Gl!6,L|?ȕk؝L&F"> zz)%Ռ (0XᬒM7n2rzV ?B3ad8QokR~~zݝt̜&r..ǭI^4yL%Y҅O^!%LhJzt`'0ܠ[/8<+ MrSeG%PC.FbL Ћ]`d9:'u+YAܻj9/ 0Xd:K qop27j.Ƀ6^nnն /(xfD)ey,zŐ:&HR(WueuG 8YNP$.Dƒ~RMgJr`nKʹ2?z3/^MC2ϔӎvs~2QO,ǎ|Iqk/r_MQ/ Q0wTsJq 8X m _Ɛ9I=k' v{Hpi MX-<O{9"oDVdp:=hפBSvU}gF"&Gz iޗ"o4@uEGo17 F>0E3UhhI͹TC!jkܑc#5cl K*q/hnK+}WC} @^Ph;IϣEnkrЏ@ِ>^oB렏myvBsWb4IR'ݡ[pu@ P>(H9,')Ao(?z\*L(PlO3Wٚz,1ӽe7 Q!CvNkMcB_Ϲmj; h`w0OiÌ]{SVa{2mm`bP̕~O}nJQs^((ys/3DV67a#T htg.1M& Ha 5JϜXHs՝ujU: rHtѱ}٭u{n bl-DdTK71T& DZd[]Q}ˑ-bb-ݏ;F̲:͢ϜK&+E{.z1%]UI٭op2xV΁Nu 璺i> K4 u8@()/,JHz}9/Wdߨh"UP #$XI6hTlD㾔[K s)PwHqaH%ތT^O_Th9,@$;r"4'c+ #6JEfMUQ,`F`ӕ8"wQƍֽӣHC?zTCK Ϊl\瀧z-t&vA:Ą*~+Ib9!W p=r3AJ[KN; //1:aDb{`%#" @D$[-е." WC,A?'^9iv_B`RɤvUlKq-딇yڧkDӃ-L@G|d&r{_2}'!fl'*`t=9}7*7RtC{6ל׹v_"^rRdz  nt-T]}~R,8U}9؁W8/Iݜa]]ps,](;4q#&[`U= vfBk&NީJ;؆msb/)-57hPՂGsr:;~<0rK"wXQGZL@{Ɠ&F_5v"~ЏԱ!-K#Hrb^W 1߱TswՉ R#p`;)+j@u:WGyհ-?iYwnZ6ͥ6E#?>ּꘪ]̝؎Şg>/bnDP5L^B^qfT` >T}aC/dّ+h1JV}i~\A<2]^#<|ʵT>:s8!Vk ?(8D{2W)2ab<P\ȂDݳ qCnyʜPac+:aa7KR95d fr#xPm:r,/ϻ!`)"e~8|P]c:.#v_,Q]B\PD?<\ˎŐ X/dd*FYV:9|#XiiX+"iy^bCK7]| wʎyGreW/,̰ l]5?V}pb& I4g)Ney3*~%X.ۓj[w%nq*~mh+:۫cp["1먠. 'F˾l "PïA$iydiw* 6?8)q?)1%\AϡJ@ #8t.-sto+窩Ra{"WXo6ygP៬C:0i3nʊ;#`CyIX^ J5{XP(:8ظH=#|aFsh]DOM1$ٟLqZ{9C{G2s.VO%۩o5q}3+aAh.DVFz>5vr <,~L7fn'`| <[4q@ZnjA|M*`%ZUB׵דT8 :;CC 2ǻ`쫑w"֥dd$R5)$A1!I*nA\Nt8z(XT1$['M<ιUsBԉПŽ-ٔ~Aj/R1|{W Ԧk@Lz*&FNw ܤ&`;SnJ;:S*9Ѡ3;N[*sՋWvCkwts3ʹׁyL|D7~3r\0N Zk&J$2byءW<膿Z6p5`> (\=],!cVdV7Iep O9 Oe·)~MՂ!#X%KC!q^y2kOVQ%51I2 L׌Bx[Ql ʂdeu YXē>]IeL F`AVPop {m0sx̲,v)֞5Ǝ) )%>\[n=16M#褬)4;mL:p r=v6w[8g˭ [{ҠCoͱ?Fr!6>v@$YAic>O3.KW~_S \f.-|g?1e"EV֜2;"'O$Fڧq!wA&*'[TV65T$Ś+!PW,-4٧qiTS!ǬhNsk(9tAM>ʗ6?{iln$`gV tLHk(5~P5qy$hA qr)_ +&![c="(k&T*V'q ;} nٕ as}a; q;\n9w+B}e|pd8;&&(ne7iD J:5>ڈ9d 9v.s,?+2ZxOQfp2c6!@?NRלҖvnj@8|/ʡ4T(W_?$gڻ(qȩCP@ 5=ܣ l@MSZ뵕jwB_X8U;qq ,$4Rt[ĉnlq FcegPu3tL@ZKfj{U e{#2 "VۘVy10~JzGzR"pabw/`5rP̯%ѯBgwP\g]Wy 7O?jV Hyǝ_aNǠcjdA @"Y~EL|+]!啅죡X@@c"AN#l$5hU|@ݫi'!%13H6A@ʍG 8n㸦Lp:\rSE<<-*#=6`NMQ_lm/5&RXҤ4 IYaS>crPj$*G*p$Y:Q.(9WlM&ǵ%SO#ك%x4p weNl$.z7q4N쟭K]h,"̹}jo8uXJ`i{J"GT{GXp kMg*ZF)0*mvX\pjK Nz"\)H ۯL̃=$i yuR]s1Ag(KJ!`d]`:x)xEepΩaX< ˆA*kEeF ׈Hc6ST` OTf5LqI}=@j-AĐ&:9p"t{1D/β{CS]%}G{{1; #oM1-5BO)LzesqnBB0e7`⟛"8wZ{4?iH1hY5Pl_ n|FLpq5I`BCd=Z[bJ+3(yT'ml'E;kY37#r/%f軫:B$_7U?`Pe`M\X0սtK}51&!uUCȠ6ɒZ"gPaٵ:/+uǙ,f/+OF -D-9-?yZމc"RQ*5ArBar\3sT\^T&k`pvXO:ϭuKO62ʖ?]~ܬfHO[fWQ0s4s`D(vʝgHW\yo/wSl«&ëMsحDb)tt r@I\"=*|<\$K\۽O 4J9Z/ wكVrNB YqB&Q F$5<<i)Nucv%"oK$XM!xGěɖ}5§sôjHy׿R,\MѬ|ȶuFXH\WY3{,u ]Zy?&"4\1 5R%W94A/;G(/_=3 +mɓEDXLGkފ²91\$p/(wp9:5S+]eKdB? Fܱݱ*QlV~XKӆF@9o&A9W*d&ZdhK#[6#kޤ ^R \v+gYx'~BCyȹD7ajd4̜V!YUDўҢs5(=!iz46zb}ՆIYM E?W!RiC ]y] Ğ:i^s`yv;~k=LCT K8X1G4ټ1GO3m[)M/ad`T sgoT }} GrC(Z&\|8UN<ɞտ+]㫩 )]7ýO9q pS`)NT^:B9Rb)=CԐOz2 ^ORUm[zx`S PuPof"F]_FUW_< >GFpsuFEc< FCvL||[#o1}izFƜA:(߰c [`3 (3\|{CK"+ue +mB$OSy-;=8,mZAr=G$`S ;+lJc;gXTa(ϮR -WEN;>&o:djNMl-vMcyhPg`"ztK'߫yi@J )_~ha`>;&ίa`#=%yF}.m'*܆!gP0:ur"r?5+f8csN[ڗ\RL[?^Q% Լ LJŖTZ7Q\Jߠ+KFYIa zhe!MKOf8LQy=8$ n*^#̸*]QAeP8!θ@&kqKRBzХBse9^|];+ {#QY?J81RK Z,9z]ٶ6NaSǹUilí"DeJǭMi^VHNgvͬT?{N)mvȬ>FW>6C ` Q?lѣsOZ H0/AsK㭬R}F5ΌWQȐ9=w3mϏb.&*8dPeS4b]l _e@r+A+ns6-+vdͻD6A.6K}RRlj"+(>28KF֫a8Ŏe5.3H,c%,{-]|7ԓfjקQ44X{>䠈ì·,NCD5ƶ ꅀ] @#W+Ʒ#Ӟ[wρPǩF1D 3m4:Z{zWnpUWGf> ^)5Yµd.Ղ{x~/T_"O)ZhM^''jTBM]66T]:1:%9K<6 h?cǙ4b"X12ͥ ޺CvݖyG0&ιoǨM3KAEoޔL/WQ-n2!PEҕJ2=ٻ`WR )ٮe`ǟe_^v-K$R¡?nh{)Sƞ!NA]i'#ʳ B|d'6~8qmf ?9զQ'4{\ JX\Oi 5SSIG=Y>xr5H¥s$qTD)4P5ɌA䚃#ޮHǽI9gQ*Mۙ=_yk!~V)B{XpA 3d_i=*D`&0RRSk5E '4 i?˰lWԆU%)f"Nٞ|QvcKon՟qxNhnlS z򓭇@_v{5GjTGqO׊ŖOO3haap%ݭS>%Pl VJ`&6}_qdt~~MXF؛saeR/ R;#JI4wPƏ Zbr>&TQ˙]aI;FtܗFR,S%2N}$I@.'jvxu"2 fYpj$M١2dtI+"yƭ!bNF;.r['@[4Z0p]q[3SFd殜u;cdZ1WA#Yv]W?)M:7Rpǥc 9:“zUk\ӪY/:-kI$iJr=~Q$VNqJwD)EM9kdŋfY'ҤN L2^ %.d Mq>(FqKȅ}|{ɲ(B݇y̧\kEeOx b&w (bT]-] c Vȳ*@m$7.*+ͷZ"no<"(QDmY<~*jfVS4B 0s8ǫK^,f̏'InZ8>þEG(gi[(-}(UCu䉻|06x?wLƊlRoDž]ZkeQow~svn$RdEPdG `GA5t,)-h2wgEmX|7_Dѕ3}I13As<.³Ê2"%FunMg$oS5ٱ|[23Xmċ!j,߫%ڋDQM.XQ2d9a~HD~˩^MƐ2?ΐwg+6G MC WҼۆ\8I #>ͨ:W֒^VKmR M :O1{=-s֨ )7842TP Nx׽Ĥ%ƟJd N+/vS>+p.^ Γ,|=Wg#|SˢZa4I9?BmieyQOu1f"P24p0 IouE>Ǣ]9^Ksb P68ɿL}㡒\Y:d <Ϯn>D9~nSS!G;a";;Ώ eO0;btC֗y1+$L[.pᶉ5x31rBƺ />s@mLd7X{/\>8_1-ƠBbيIvcbBd LgL%ڊ(҆ԘdCONGxF԰Ng bZ;ZD!w0 `ӵx2G1 mDv( fA31y21|H> 3l=X>3 `,48i%<re3VK(P6I$I_TkT֜Wc†e<ߟL!7n/iHE|G{U:(Ә29:,}"Y pZ|6a|\u]dΜ#ߑW$ܧTIF_1#>s ~' cמ afrL ?f=D`kh@|wV>N]EX{ƍaƯͧu͖C,'в2 %8% :q?LK6a/v_Ş-wW7J2:IWwB S:TmH(WjRUhHI>5*>gp`Km0I0nr S OoI='\ '+`BJ1@9Ͷ$i*Z'a]քZ r> I?֬\T:PGt MP".#"gl pxD(Y؏vЛ\Eb3YˬF+}&q}ȰǶheSgノ*Y#r 5oa2GlNGR? zo]LvپQhu܀yQyGȰ8 븶aamȹu%n8sY=:ޒ p-`nX©\Y$2s[2KY5 3ιK\n\*'~kv#SFd|PY.!n(]EAjO&ezv[0NPۍ=ܠad/ kdR4ҩD8^znc]"sVC=秡_mrQ7BSLEOؘ5G1]*2.8ֱFސ$ϩh~c[xMx,r V<,V rѱ(G05C-Rѿ5s+ Ϭp[IOh0CoԂ,/EHoCF+@Gr$^,㻶me P-pM^s;z 7q?<րD☬S2(ӕ:pjvU["Ք3;P)3fp<]b ;g}{nx'gٍ ooń]bF}jt˵FmOKդMj/6,+ʏ{@ }Vm'H,ʴiI]/r;ZkٲT/x0^e{ͣЁR F3IW#C,d]%Wۿ%}Ff/=S@ܓ `eҝI5JãZbeH>Iǯ@NI踳Z&4gC|Vωv2(odmj͗j0ahz;7k/X+5q0l.^DNO7;%^W-\BA?Mn{װ)!3Kڎb_&1_|d[K_D;ːC(2`/F dCJ.Eh@/ +I'ێUL|z"dt SަG5{p!D<1Fx8ދL /&~1%|vű2sPa4-ن1Rn;~oKrL^pF6:=ayv(WBRQ{!˭s2J^: z?wDcř`uYm!Z7ƹF<  zc*8{ G1z-#Ǩ)pIQ`=-{=$Yܗ&$v ^PG" }f 4TAnD'e[Zlm/6Wg,st3[*\/3ܷB8L!ͼ@ڛ([-(\2S(Z8@[8gMyr礓 5ykP 8fl_s-$W8@-,դ/K\/usZ=ioѤ Wps~7fc{;v[c~:g2NZIYv^K=&>oآPv!4*آZ~qv[ C'C8tyI2 [U2wE8L/`t%rj8 d  sU=نq0ȍx rx8LMYnW|?j>vmt, 46*,QDAiòs蜡DsU |LgOSܼ'>d;*DA߀5IΒ,(rV̟"98_8b%g~~V?jG[;/ࢫ"L+ NojJ Z,Ӕp<{_j+Ųᷠ#qpyu} {Zn( Lh.ûM r1X )J_ 9Z "q;F#.+iu/-w[Q!f"D`zҠ)!Xsal2A3p ূσi{ӝ*V$}6օy c֒?A63 t %\Q.nLbYfA{w) ,<檿Sɰ䄺[A&=r&C P J I%P'_tآH33)LK`@/+Rv'Yl^XW;Q5$5<\aw7W? _`W$|8f2f4:B|U+12I@(\$9cUsU(:s ;z}'`ySAJ6E.~ՖV)&*KEH? LFsCh֠q 1NIӾdQ"ݙ1%:ٱwUBֱl}JI/.0]L`J? fp*S)bd{~#Eb,X^tc-ޢ_2DPa85]#{ xBztIut@I;c'mb oH[P=t  TX\p0}k-GzIeI{"EXr%3Ժ%eT7ZV4#ұ4>#sUM=G#wn F%K3D}')4P"w,sypMDv4k9;IZ ,NK\;w4wQSaV`zϾB@.HQ"+MR m#' _DQAR7%xp.yS/1cm{\hU|߂x*K0NJ}7'fL+b(`Wt&؊1j+Je MU$(wuP)OOzG۩=aߍb8ė"Tً2lJҩsQD?֞*] 5+ ȸ<0Ur w `63/80+wW}fpF1j5T_ r}w3}؋f_ ַ'!橮Kǝ<\ѓk1&t7nP>P4X3L(ϗ T6jԳ+?!7@fG*V1Bgra}', ŠlZs~Ka.]3McHCWkZ| rvD$ZZ֬0,u"v9iZ iXH .&k 84k`qMutdXΣN.]aiL1p:4F?m)HK/[KJ!<)o\Ll!rCa٢F`*:_JRtb1fUHKNEn`gyw1`'-n.!Q@2(&,v-;j8F_uPO Θ `HCɿ (Rv CyPv3USh~}`y |[N-rBC<&`o<;u0NѬtH&*sD!,  +(n EG7b( QALWd33rQbsxaD􊰗 M;~Mn =`lVK`Q9M;% c9ֶk\XC3h*FOn2|RlO!.eϴFҞA uӁ״ Dp3͠rsTX:{9;sY<3x3JPJ\\a3k4RoGpY u!_/`礃'un}nA 9\j@ۂ HʰZ_v0ӍӀ{aoXQ:V =T΄rlҡ=ƳM)uS+Vnq!@etjLny+2eFر~l95`5&,{gZhJ+$w$=,:,? n;b%m-GAf|hwghoh-lt6X(o #X-TEM`}+5#mƬv=:"9`rnB.`!ox?#UоԼDIn'{skYb!^ueqi :^LX& Hz. !(3VGWa7C$nYz5d6w e.aI'RrkUR8:7:0Q7c@Um_wxv۹<>)/{Q%q;<,D7ֽ O##R-6$B5ATwMVzKq= @!?HF!˨~WEeibE,'46QjZjhYC~|Hfq[H"38(aǏ2Bb ^Ou3>T-\>N\RyHÇ>#e<03_3mIG2+ym7+5dJvhlqӲu",Aŝ},A%_4eD3C#d}A"->1AN PNٗ( 6섨ډ[ p':K[-oATD{Moծ Zq6?Ț %ɂ4, IJ @ӊ)0孧S6jG%慫U;P0 =u4oآL%?$v9\6=5xE=|I :XZ>O-R"듐 D@Im`tkDGB\S+QOzyA3[Q.*H[Σh?g4W/q?}Ӂ0F.,fqJ uj00`)D4CVb4<9PHlu~ϼ*v6{}_z4VA:{_=ބ<ӝ<8h 01E<|"{?숈 +!A v6z L|[Z)ݮ=jo: cGUbE@)vjw6.%Jvb<&oplD \8}x $#k쑼;4VRcm^[u܀4(9NPpuyYbl_5'Z@׊1v?ao5/0d;~ fK>CCϠ)z2;jlSfCD hd ;K_lO.u=C{o*ٿ?fa >Xi6X80W VgIrf-d席sQ }0V]M ewZC̓6]1A"iG? d'𿱞ce֗a\:ZJ̥&,ϥGi?D>lCvT?ja!,;BL٠:@Ї3 E3'fO0xt$q K;S3m_Ҵǖt5, v@G)qyv?f u avꮑ>:E֌>ɫ.nip ~ CV\e.,x|C>bƼS4`q΃$׹*UMCo ̨jFs,x25J_KN}9Pf Om 2MZ~LC@fv1cG`MܪV%/929zѡٯj: {,"*M xk19@@lcD|!dOoqvv ZGj5Fb8b$ NC%dui/S21RA4߾#EdO+&SOh/!{A%6M| B>أo| 4,B/{f*^xo BUC1Q0ȧk{㈱oy!agc:r_Ÿ*>WϞQ _RkK7{5fb&]Ts}]/O#wtyUOQ_0T쑲2h'W\i˸iDԍA85>)w0x@%ɒ\3]q;e|ޙn ,M+COQȿU-pL@ b9 8E2__7 ?=f/}c[iGk~PaLKÌ~i[ǩ&cE?Jcݴoa-oMlFE Mdɞ5?]<~uU]QqjҞ8(CAԛ/:&,"c١)aL"B3 `V(lAQu%mB ͗.UCpeJ\bkU 1xvwobLـe.gi;nR2_VlôZ& h Mdk}0I>8ڳ8&i,o ֓l8/ͩS {},x=WCx<,ֻ\=*>+pO"XD|4.ݿ7 _wGF\hjMQ$_ }.m6jL lqu% Q5lr 29M]@Zf GeNU΀Q|'S0DT* <{]@U7RUC҈;4(GȰ΅Mb‡u"8$[%딳[}bڦ(XS*(|cG鋕O.xvo@1aT /(wE9<:|i3uMQ'z˷stCpg=/ o4dRPTkx3pa2)ʗidЦ$D\A@/ĝV4OX+-+zI3kO*. ښN BQG秺A6$WjFG28)Z๭·G U?e],9~v~SiEB`Wu4Bn'G;*2jH00f߇̵"\;=ű皁T`,o We2\Ir,G̭} MvJ`& \twvEq S"yde̓)%#^HԴ/ojZ+QgUVylipᠵN/+@hҏEQ/PhZut2u6{/>\1\_9rah*μlKdWYQ1_v17׃|-,.?9 #61a\2YtDQ'.핤2`Va/ųKt84u߼!4 9 jWVuoN#e+Lzl_6|֖"~.$Dd))AōJRolUa"D6+RMLD 9S/p;T}# D5Q˗QD` 3P9tcH\Kp M ZLN~A,T\A#¦O %J$X5R:io㈜ ĸҨgf$JɫW;=-cڑS&D709?d+D*JLр|{u FcBw;iԥ]m2t$;E˵~R\J_WQAO| Ӿ7_ԁU\43I"I}]. orѭDzz8IUֈǰ.D5 `,'zgTp8}CO/+:hw­Io Ke ?\{ yIZo[ 1$emy,ٞ0D?,9R\9O1SoKi10mhZڻaWDw'6zivlXyC#%?%7z"]Gg&Tiv NYU"Wvp2<$ehmщJў^bbF+}bMN\3W|<@MَJQ|9^5 Ns=eʰ!_ޱK ŌZoԑ2; "xm/Lރj@5 Ef+`S@4B u ݾ%YzgYw* hfY+ BpQ+KILDW%Yp]qϴPO@`|to,Zʦ_@S]1"B2G9'1FEO"Ҵ2U#nT 7t7yV U6^1/maG|~|%bt 4i] o|ԧ1ݍ^ɰ7.8@EJca"3FT0B86eDqwewsDxu;cZ>VdK:ҤHjw 23z|˭sS~"ຘYz)qxdpdF2~%։sO.@P?M: _#nniBNl $Z*Q,r K ѳ d*no|{ ͈ M`á_X8ZCV@S Уj 8QeӾcgZōfZ"@=mt,\HQ?JՑ6;b@c̀5_p: m^.i5R-մ R]+N&HT<́nDfy8֢K6f?I&h򌱨R32i߱*cү0Fyiѿ6!4@-uI;m̹輋~zx bz%({vRڭ[җ).mh?0=[h ~6O9"k|]"3[%`M,ݜƾN  .bl< Ujx1%bo&YycD;e w y'[Y_)=;q2AJu Y,x*ۑvq [uftgn,.HbP(ú ݳag{ohҕ~EvADE8siY~ \Da^-o۾~K)!F T `*\Dʏt $'g߭35Tẅ vm1Lrk6@03Ʌ=Ǝ$M<^qp>QEcڊܭG6Ux&<)J>5`n6Lj.]QBTQWi#VawPC:'Y-zf2t9REbۈGr1#<8 OVo>pӿCrrs[SRa;gLQP!rڂ&F-ˆKm ΤzBo FT 6SkYD/"j<lAc d'{bDXcUu 34LJb(>!#%N9RF4ӌqN Jkeum[{rΞ{ad}l36ifehGDrYe{db@$ b՗xcQ}ϖ'm^kzbF HC$rR4};Oz[b_efއw5,nGV4^(,_4Jv}yxMKh!rlbvwJ9#(ou &姷#yedQEeoR"xXzS0EDSTP}m53[Is1jrAaᩯ']G)#ALK;a$\ 71) mRcfqE_XJ:ͶcuR47w>@ <ō6kl\U^pvi 'Lj4rj0UvUg:P?V"UR~<xN(c|=<e[;Sfc2Ƌ Kįw'i<bw~\HhkGݬ)RP%,qGBeg:!$MޤwP vǿ䵉6;fz_|ƙwG^7(cd*>,J.r~U1 oaYu+Lw3'>eTqc-&/yUjjTqhɢ^mZģ9$Bi\rʙ?Q (I?T$ц OI/J A*9-Ο2_SΪ-{N3N}7$dr_Pvc^7jsߙ4>A8:x}a}=@1w=yA&XY3bg pǍc6S:G[!`[h\=a:~ ȃp,4|n|RMt rQq|.~Ch9}֏(id.A lh\eHK'*CI-b%)bu !kJ0_!uŋ0,\#lW)C)i|.(kBgzuLv,as^' >+= U /R .ez̝7~1oRl3_SRV ЭAL5bq0NjN C‹9 HWj*asSbzԣY눊@Լ"ߑӧ-iTS/>MT=6QzMUŰUlݓ*K;cЅL2(|@?$3Z"Sb/hL\4VDX$hWj]o(J,9㚫n*2|+j )'=ZYP.N2Ӕ,#QblQA&<ĪuPJMօli \qI2YCl(/9 G;[16Ҙ-%/!1ӇOKC R<\yId gpB ₍O"?_Cfm3^Ln &Uة@mcGW$e㘺#/_J4n~̠'Ƨ7zKN@zOV L/ǠN6AGK L)mfَޔxQ: =JьVQiQ)_za}G;6c,pø)-ϸ!&Xft? * @JWʍ@| yqt}.[i{Ή7O1;-y8 -ylKW&c$tǽI+镒@}=!_+UjeM? Ӂ{ְ_N*sHԩhwh?7'6ug`b { w1z rXR܂m8To<; rm EI^3Cdx<7*l5tYUpe4Z(-R&Ȃ9ŕnnŭH_RHwL7VF|[e{8"2Ib9d`|M myF_U8c'-D9֜j<$zҿ)QJ,#c D461Vd*ouezWY(0\eqP#AUۄN3*ͭs hNC"c0Xċzη K#9i6` \-ϚAGÚ1TC0o`ZۛWB*B8R8V&_'q`}H*ۗ/OgSւ(񅽈Uv H\2̜p0?`JB[;^n֡LdBI{IH!XFDpYy:s=aɵa\m.S{}.]D?hc-N(5RmFt:țbl8WַƤk{mg$,OòHhcrUTnn.o˂g;]ߑ{i=2٠ mW)c`WF5w\>wL_GtPC\QKyjRBZ%@BvYl-}*]5UxwRw{KS>AUE~dP`'(cIf}rĆ;YX/1f[VBF:.-,oQ74&S_=㍝x89,pLAI'@L˒4rg?P!<0inO>jD.?.9Z**`K0 @R/"k4+u/l.k%F }0g KSPcR5W!EiB љ;hi-x]ߟKA?P)ٙr#X~+J)4,_om'qotq>1nEџ>,׉)"7l%"?tT4.sVd^{8F; ]cO*2098^̢8$(<#?J=o8#*rvdƭ뇅2.ڗkv ;ӎ`S訷}G`D}go9Yi煱.c8T*1Ha,Rg`*W  mCB>bC\d o01kKa(݆аtVAg0IoLLզ6'Gu paoB논#A~|},=Z2c@|U^A ]MvpN+;MK{ęy?L\^7Ł25һN AD.(ww))\_ӯaSI8Y %qڤ>7G2]+>TѺ!+%5}noN{P 7Y04AqoqN<͇V;4A8V'4h $as3n*-j] _ǦzSN(6e#)[T ;,n(5}V.:* !GvLM)bчpky|T|~VS$n^g`[Fg \t:&FHVz<"'&u1|$!䂃~K P!a2*$˙I/Ȕ 8wC&523XSfON~mZ]ύHS}I2fcFC(,r >[Be,WCpG9}4:A)3nVBl(KWόe)DefԊ}~"'XN)wEyz'^Lvw >Pfŕ&`\_Э׏aT=Ҭ)<\"iA "a̅L>:u>ØKwpp^Fl ͣ&h1:%hP_;42F;蔾6S`'Bu 5h) RhWOAØz}zL2bЊM^IX&-ۧ,4ޮV^}:(15B:>F1\`݁d̗_ Ţrt}*[Yߛ@}M@4SD%$]|u,^'*2e0-C,y*3,<߆RjTlkVծ/{!q*<벷=f7zmOIouu&~# 4UkdNh-[N)] G*N)FX)]mN%QH[A"`US$)vE;tp:v%fu=#Gk]|ĤJͳ%t1Y ?+lpkݗcI" 1h1W^s-uyr`4b<L>g2\SϤbGNH\pFu]@u2{xの Xx% PVrVCtxJgJrUnC\T3쏒6ganuTW>FxMɋGṃ2N7>R@~&X7 չA~Iw%} C0:TrZX~@Z'`3AȤ`Kp4Zc>պ8 3˘^ 1\u.Rh40 HmQ ;6y6X.-v1;w7|(J`ŝYvgsOs\:F#^uE@PJ-o@-QXYwZ A{f|ZbwۄE:H|`YÔR l7 ƀ9W>L*ϫwNg~WNvU/BTZ$L$\2PzWyl s=Ɔe kS5a[[uӆO~BXRL@ۦp:8pć>fOB UQi+yP c"no0ͨ?>=PZ_C (#lŸ8BfsiP Ȉ݊Z[6h<0Ok'zx;(AŐl½x*/`(t{43v"l7Qn.&ۯ<I0 #텄 Ðp3:,s5'wi3Ģȁفwv:(hPfNv-͌,]]HU ҘmR@NI6 #JmXQOxa43|#gC♡LP|Sb[^b .ۅa:jy""I(fS"<$cv%{Ӭ_W FzD֡ {ߓѯY_j L")a$@n.ʁD _?#_&* (,܅nAFz>&)\T) e`TGF/Sxt\@95E'Մ,=XCKN-qFT-[-c[x>]^BQV 3qi!7”VKI?fV>U]/I0|2.>gtэI.mC<͖irH0Y f>g. TR}!-\`"ۅWDp#A[IGEߠž8>VXkXC {`Y֌Ԑb+vr*>m`h<}~­qPfoBt۰CNR)D.f=OTvB%e" O>K{7!t(ʙ|>K?܄ONlB;D蕴mf羻CZ9$){x'TW%Qawe!Z?9FZp=7 Mc$ky'r?"`L6"?=!Ma.$x]W JnG' YgrΪwk.[.@i` ?E2Ioџ9ū1gi9@G)vPء4VjԗBZta_8H8T"Iy6jCZ=^ñ\a|. PHuy@*}u*]r .5zY$㏇x,"s\})F~>9.%_^FV$3Mt|Oru ր&tWђ`]C=SR$$(̼R/&56rd5illϼox7D9i#@}aEyF~HF[敚O B`rf~BvV`X fّY#bKK O2¡=J_B^<]X"g\ɦn;&~d0Ř& ~ ]5[ !el")6"e&I*/f.u; yl[jD]ю4p I|OG`^1lh(sQWSmEK@NG+ *!Ğ$DzH"I9N-rrN;hB|u8kB\X. CDPE}@^T]Q`NƲa2 B3b?<4 r`+F@Hv~ W_[9:/8C<,چ)O@vn2fBxr}}mB [3+&EŲo&&WdDn5-gS#u ;<6]pI2SS]I+m݂WW5ٙzK(r"%() \}*.!uăXQ Zpjȑ"GcCz\zhkƞfp3;A4NS:si aw%vyS1ڻL0ʋ-U^a[a#0p{nT]r{'q+BLi/|Rr-#mG{ 'hpdb׾m@jK+4 Wyы*[-,jFR~}MC Kf kR'U eL`fD Kj"aǒy#CYYri32g@,,xW,+Q$P􉧽зTHS_e#oc.01,^}A\Zr~[c疘zb*Z(_ T=saDkI@e⮥яoxNVތ2"<:xhajϼAOJߣPqiޮ[ܞvsMߝFbHZ$pLH*r0*nY`cb欴:D!Zfof\('AY'*(D]q/8ɓ%qTWBB.'H!සZWbx2gxk1qM,,̄ F[ts Ybe*tڂg:Ic RLefFNűŏ5Ju~l:'Հ!CZHZZydg-.ƽ(LzXu!"!|! P$ZV $:i \ )xT6wgwT@(6bVRAZ<*=%m ?1f(U~Nus%d^1}f-%Ne Ra}L"6Re؆cq3fS=ǐ?hcTɛq ߢ7SV5$BnS @ߵ]?Z_NVo $c*PfKϚ:Z%wA, -9`B3қbh U@Y ?%.|Td :$ca`K үSa}-1ꖯăD-V%! 1j;}C-a )5(P1\q>y!7CBo~Yu{+L͈Z%71aN[˯ A/lCʯN%;/ʻ-?R;6-bmK6W'߯'\ OSMxzml_ȻKFYIwYcR)ʉZxY q~PZZyN!L8< 8 /@Yu䉵br19H:Y]g*9+(=T <@~A ?*vJ1Zn4>#)d/L `Zy; t}l$XG(Y~յ%I:Z旓 dN/T'D.d^«bLpj? ;-ihH;`, Ȧ$v7/Fy73/k!+=3\>ol/ۑ <B0{WPJvPl0~33R#?;`>53_} z0; A&nB MZ sbtm h&Yi' dxNca'vaPC7''D>tcRCŭ؄ꇑlme BvMJ}UWM nOtm2@MZƹ%W5hlYˆ,5! pYyJ, ۜAl4m%Gݭyړj 2JzWqsĆ'Fp[h|=1^frD“<\ӚB&l~\SqHh hpHξonyMkc͉{c2uv6m@BN֘AȘ HޘQ) xyvwyyA8PlDHw\7\qBy#\#(p7)īWBW_ (C=z'I#<0+ :>ƾi O[$كj< ˗خenS5>dwEgdD'k@RTUƥ³qh5pN{w!KVKEqhJ1rD0LTHp|3~,^|âΐ.kę9Dq.K͆z1o,7Ǖ+5aٖ W™E?>J oYFt"liBRziѫ+v+[6Wѷx qfŏ:!\4611 F*}x5ZߎI8hpXB ty- k:=`*f>O ؐAZ{AkZx=2j̠/"Xw^ϩD_P<F*ӈ3PR:I4 qiV2HMR}${}m.`q"g)PTy~m!fHY<$AF&mǶ' tgg']$Mk;/jmJ`+%1! N)^, ;a~_x_ B⧁FOܐ"[* `5W*ɸ:jEsC T~\ZN e5f9ȡ[P6= &x]J^H=bA 5[A{P{ ^TL"?+V}Tm#rD僭C8@-| 1;D>i?.@"#qsE쾛wb;Sy/x^CRNޓ[l ѠDzuaq@d*3(BBBN-7I8}{99Lt}zh'j+KaCViYxU9q\we %>=S=nC\18GaVOu]Ȇg@PםeH`u- 8yy$HbBVU3`w^͢:bP <."C@`ҠBdv7Djt(gSH'ͳG&5|S ՠFԇIq5|9~^02EF p˾4$b[2]=AbƴI9}mc)]Xu&$>VAVᐥL3:=¤b~DlWd+>E׎\RHtZZp&` #{.Dtk{fޒ7aĹӆݱEXP`ͽ3VU D0]nN̆"Eewm|rM˩ˮxц7u&0e\:pkFd4DnHZ:BTœ7ny$G%:(#wR'Gcx~khxԃQWuh OF9#*c'# =Ȥ!c[[bqNb ) hCqP-\nC[5߻.7:w@x7>67n%3.D,Ne=-@tM;Pt(2-cx\SّMY Ql &UaI7Rf5F-ų0x^Ϙ@fQl(۸!֛{P[ҳҚNMlowZ39BsݟHiwtZ90)8o F0u5*{ΔQxc%i#z‘!>O^5"z<ڕD-Gq}5:Q'cGyɈym n SJg< Nv O3ju#LV~y{07O+od`y=]㲺 `#Pr';&T/S , )}w(-)޲s|Oi rZ ݁`xX9gC Uk7i31ʔ+!ogN0Ik#:X8q8$؋eig]uj^POp*~c X? &ݨ(|R8*xgA H&8vLP1s=M+{4rR"?4aJyUm/;%Vx]4:?U{GQ4cYB8AHk#?l~S+W T9WNrXTț=_e{2)>S2hE_*潗/,-(>M}2ȕwJ[/z|5sߐ #Nzs|!ř/5t{/[C|繈l*Ie wg{ =;vN͗opi'U j F+]K[bqT8bPv'ȊM)ہgtكc0fJbރm',Hj?/~L#_Ě>{-@^91Qiz3k?k i%ŸDΎI?c6tcTw-[I\fu k^qJ`.`;xzQnh\R% M:+î(%0wC1Q}w薌o(/KVDfe&498XTf1' @4z&Y D@h V˗פwVKzQf[@I_y!)F 21EIf;֦p]&okn2}EE6rIZ@ jד} j ˥{<`=^$/ Ӱweӯ#Vom'F06}]׋CZE"(WO<ʽ('HȊ]j0 =556:Wo//<8:p:60QQً0%4fupZ J\VhNC^?y|ʼn&i P_'k "s8M dz%.Vw$cw<)L#c_ <-pz 0mn b7T@SiPkR񛾃 pIu:yKcʋ[rz5W{#݊ssЇP/Τk 7ȡ@HTCp z=:&obsP(!ޙx~x;%T X=xU; a5a |j3uv1{84TcGIȰ2MN$mۭW@܄KvʽƾY |z#>GyBYFո780>rMVINTcn,,Nx)t&X-@\WJJiخ^|a *Ұ=XA.AKO c1L_O#ٽPD_TF x%ڼ5p);k՚9^B8hn"C/K$b3UBsZ{r%l젋F/9Yq.9m$s~cIB"`4uUҥ=I㽏:(AD</P.#Ֆk{7{ 2ϊ9$"h2Drk#7Lu4"L$~nS̆+ȱ?Xe(!/z6Č k(,֖Cߊw,v#BNBºz®Ό8H~/K4Cwpo+5 ,$-4VO9 Z@pU TB;m,ea`P$ *ƻSP/q!X"O"=9t  I)YeCS. bЂ U7r{}> O>] IK Jwj61ݒ.+,Y?NWULB'oέ!rF ]y@|H j69;P~J=Klq.(+[+d.Zckiõv1ZQ̶t"C'ÑJ2qK]Xt>벖m[O8H(O)^L/B9dqnn^Ö,|2` 23VIEh099y9(k2B3oJAc[^-",UI"[혮ww4yEoV9HHoSC>"zqo Hy9AlG㯜xjX"GToHk)']&(9ƴfpzKuﲩDO[p3& ѣtk ;!#n%F2LИ͇LdHY)5Lws*lF>JͨeMI3J69}n,eXBĕ58_5`iB\ih% bes}M H$5ըZvh ?D:c%bireHe6\4T}N>S\F&j2(/=toKR>[%wۭRZh^0&YW)S5SbGp|Z4}6q ˲> \VNBxQiGIb^Isc4ޥOD&s6 2F[ /3/?Յ pa Y\m>P'܄^g'Y_ׂ@+4zZPV{ԎT y a ODoVϑޑQ2!U+?Bvбm{3}ͶϫZ[,:eitͫfmX-:2.-& g^id1?({<9g&EU2fO7R.ޒRaῦiYBrf07l2̝؆s$s7^tOd03Q}<dm7VíEbK8؜W֊YR$tHy4٤r_nMϢlAP6GGDĿLew3Մ,ۑdlv:wXld\+<2 mi֐۩f} ͩk x¼(k$r 40 BxLL2e|h^[N :b@c0N " R(*(ժt) [kpoDB]ޫ4HU:msV&2 _hH`eu?~g<;vBЯpojotiVZ@X#=uD='#0C̾g3qSŁ;~'+PZ &;^$䤦R߮4iI3M59u)Ry+rLN2x\-2!_A :yY@޻[rKV5hOY܁ )/=P<Ҥp dYms0,2Bd=Oi*C 1ƒ =jD<5Π;| LPsB#Vs6?Qč!4a ypPQ)C !$7 ٙ㯘EѢ9#i4s !չ>$LaͰy"O1sPWP:@5&/eP=3SRbǁ RNp|E}9IbYKa$/\9BFQ(⋩vJ &RjB{#Y Idld1bܯ;hԩoFұe/O:ⰘAOְx_{WrPU9 &]&+ŻRwË*V86H-Z IN?zz 9#gQvϹTi_3j )_9*~F)% ]`{+-D{t qXR12Xukk" 9}w,g(nc@4ˇ#L|cHBgI'{9U}J.ďJKkZ|<怿.SLbxjW鴙o"e2uy@Rתdym u ڤsBa;bjU?b,wie@BwΊ{дL[ꕻQHzv@F,-ޭj~wȺKY$o<m9?{i lA u җ3+Q` +y>zoCtPBe`z.&⾶)R&M`4IrBJ d5~J՘XKA+Gr {8!(+A&f 191R:pHu8ܪiR ~ *ߔK+`׬P{.X<]uD̔gtg)=s4"Gbsué ;fk VЁQRs"u +Nǔ>YFNZcfnްE:Hm_p{R-LFsJSRu<׾h~X bv-pall'QI* .vi(%]@YaCYw|vJ!"fMoʚ@ףi譫1-/xTB큍p$iA]ϏXku|k6 q'4 z!Aw`JzֵSDsDĶы=I+]LoAΟLʫ9a#IVu[fY T̻,4z2U{֛jZW:0Ё[5^=3TϏ_z]uSuf} olոQ MoI뜲ݾ"b| yk"I 2R8;c9=-HXӓ:V=',CiOet}W~Z<:<``(g0N0E eX^<‹Pl|ܕ`lr[9 T E'w<:UWp_39x[(O5{Jnyuv(d@b&-hzߧ~s'xdQ.y4{%)vĖJ8U&bEoWpV*Y.~8ޙ,g *=e8Ԋs/׈UJyh^~Ү "Z\i7(QEmMsAdpǙ){̳ԪP؏,&nkft|mqIkDs0Qh=,Q!H*I͂ݡCi%gW] ڏ<1 @ԣ/P>^216+n)ph j&O>E٫OJ6IC{˒4 oJ$9ԌyVSo~Y qaYGB+qEɏ .%^۷UgS_#$HxExKn)[.BG."du`/gE:~D+@avWRL{ytdBNN1RxaPs2>^-h$\X]o<,+?Շ7k1,1ϗYҁ5ۥoG`k08k|ۥ5uZoXZXfq7+#T~勁HZ{!ih^D|KAlvmsfc#BWO ~dl5e8p V 5]l@b]7qf~9_=?mAƞ>H'^eUޢ>*%,G-(~s-J4̾pinͺ[т7(HɞwCpH1.W6fG &.& AtUՈIR.4,6mL"lWĎ ]ݝ1:\9;GPj@-ĈO42 eh3 ͕«^쁚XJۑ/ޣF.,3Ab>D30;"f:5,ʛw>ӈdf_- a^yV$՛$Iz"+yN7<}ϑy–^D!B@S' VUD䥰 `cZt-9Iޡ_*c dRܰ?"KIz0x X$&A.+DDS9'B~wY oq1(sޜJM\у($.,EY xkI=Xρ[K%i>^ihEz1m9Btp : #D0DӳI|pwv'.n`7l,e| ґͮ{ķmߦ pB`^v? ǯ%{ 6)TR:UEIt)x|]lYz~,8 L$5b]^_UN%Tss@5EDh#~NaNKL -NqݿFe"{~>0r#0@0(G==CTx#B?z߾M9L`EXp<6xjhijPUɛ7bgs)Y5MP43<\8.Ʉ5B|ObxXm*M;,#3MLkyICPƷj8jn|{,9|.p3|R ožRt&W@e{YE/܇p9,2m$(bb-6=iZSS3y@sƅ[&uQa{ X3LyI7{|[C:_)S,}v]ⵁDjAm?dRi$|*MºOBZd 18z;ޟ4ԕzIERWz4Lׄۓ|q,ǩU\9*Z7ٮF6:t{ ElTK-)c}s25~9v{gqI%3;>q]X>6RȾ?xw'8^.ea}\nn](MC=1ի , HyYV!nYPk7OoX:EZ>%d CWz2wͮhg$L]~4=H&,XςC2{ <51 +`q xTЯ΃W&>8@ngň=N 1#k3^JZgl%8eǷUsY"?8P0'{Y=RWO}3/^AvA֭ b&+ɬG1=-~uKg / OŒY' yN'~oF6pi')d7#?x+ۑ#:8/w"I[sPѤ̌ ?ZqH@HbLM"Lm3/vNʐ'kGSi. haF;6#KEfi˪HGUL3 @xUR:Dv >\og۹*U5tQ{$Br Buo(BӏI rxa&mږ? uB2ٜPc0J o]U"pHV¯Xj7" e͝3RON.rxD^LuYwEQ06Q2d_,"_R[ ˿ié0 F дbm=P>Yk'3">gj$ Q)i(j|"Vc&@3hJk9W4I/) [SU90.;#8pΦb=lG_t!5iI6ǻ0mUVK3#lbKowbFqqa$ۢGV`h#:eNU?j1En"AMYS pMM#Q^Y\چ+`AaRQCִ.ټlNaR85s{ YZ