cryptsetup-2.0.6-lp151.2.3.1<>,~X_`ɦ/=„+`TNi'PO@4Y^֬unYlX 벍_5t!; $zZn 85$x1X{˷V=x v'GVģ߯Tu__C #ᓵrM8lZ ,R(+eS gNSc՜ p|g}CY_l<*iGۼ"FB.# 6201'_Ksַ}AO + X>D?d   M =CJ&lGG G G G G dGGGFlG$!:(!q8!x9!:">v@vFvGw GHx(GIyDGXyYy\yG]zG^b?cd|efluGv wGx4GyPNz9DHNCcryptsetup2.0.6lp151.2.3.1Set Up dm-crypt Based Encrypted Block Devicescryptsetup is used to conveniently set up dm-crypt based device-mapper targets. It allows to set up targets to read cryptoloop compatible volumes as well as LUKS formatted ones. The package additionally includes support for automatically setting up encrypted volumes at boot time via the config file /etc/crypttab._`ɦbuild84MopenSUSE Leap 15.1openSUSESUSE-GPL-2.0-with-openssl-exception AND LGPL-2.0-or-laterhttp://bugs.opensuse.orgSystem/Basehttps://gitlab.com/cryptsetup/cryptsetup/linuxx86_64 mkdir -p /run/regenerate-initrd/ touch /run/regenerate-initrd/all [ -z "${TRANSACTIONAL_UPDATE}" -a -x /usr/bin/systemd-tmpfiles ] && /usr/bin/systemd-tmpfiles --create /usr/lib/tmpfiles.d/cryptsetup.conf || : mkdir -p /run/regenerate-initrd/ touch /run/regenerate-initrd/all#yxfIrjodgN i:y^ 7!%9C E  [+AhG729#:EBlB8GH-G17XmGMJ @A큤_`ɥ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɥS}O1d`PȈZt{[TV̋VZt{O1d`O1d`O1d`O1d`O1d`O1d`Zt{O1d`Zt{O1d`OSO&O [P}Pa)QNS$S$S$SS UCVN)WʈW,W,YYYZt{Zt{[T[T[U[A\_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤ_`ɤd6bb4b689200c2348945700a6b0dad5df92bc2015860d15f36a25590814d77b0f00761cfd11fd6d69a1125b064e9fec6fc5034e72d93b2ffe72259be11a813c097c1aeafbf70ae56f2f17138b4c7ba51518bab6e619587cba781d2e2d91b7848286faf2ff81231f8b39cdcbaac91a8bf6787dd7d7f57e51ba66ac3885785b918423d440f7e9d0b14b41c5da47460a7fd84a73abaf9ce996538246bbe5f9b0659a7837aee5b822c01c64b81517b071218874aec603ad6624f3f559c2dd6a8ca1245670cce8b6a0ddd66c8016cd8ccef6cd71f35717cbacc7f1e895b3855207b338c33cc37871654ec7ed87e6fbb896c8cf33ef5ef05b1611a5aed857596ffafa5c0c35222dd8552610cb4f1d1559e6b09c8ea04b1888d25202787772f1332dfab88139e083bd0d541f2d25a13da34c797a57e3ab3dc8cdc29783f611dc5a7ec7f3fe9c1111453360d298c1a4afda5f84aebde925fa164cc30e14c8d31e4686ba7325800b1569fc977bde2337bffdd20077a5b5dd98f172c944e32b75a19556e3504505ff6feb42cb3fc27cd79c52b0a8dd446ebac636db57e47b466f2fb6f870e0b3b98db51402d5c6b54a76f049fe834f385bb0a81a195148c217776c29abb2885f985ae4dd6fa76e34b4abff697d973821ac6bb255e00ec8844fbf9fd7d936c0db4517a88ecd842a1ea48360c45563ef051ba71d51d6e5d40e240516536d8b7972e5fc2fc53522a41cf685cde1ed92ab42df50f608dad44b533a20d1468ba2ae01c5c98071c7c98d4d62b7af278c2c3c38a89a9f2aea7811e8078f34a6eaa99f921b65038a98a6281769a64e90528394c11e9f58978945cfbf058bd72d251bbd9f325cc7b69e35a3235b851f6e3d8db5d01d717afac72ba452ddca753be93df085ea8c727c1487e11b032c9357a5187ec8ef86d16f0bbb3d8f357ad4cf780c425b2628be5d85dad2656f925cee0b464f53c3a669223fb6a43dc581a27fbbbc5f6e280116a8aa26191a7f768e9dab9d82735c4b48a4aad0824763d081418a034a40f6b268b8cfbabdfe510845bf2de9d20af02dc914a3eebfc7bab6697989cc85e43b39da1f941f335b5137c8b33216f3665f2df5b74a2186760d518babfcddf758112ba6c3946c2b6fa183d6a3662b3b34c09ebb40140613400e779506f22b7e005ddf07eb9e34df8ddfb5a6b053e7f1a57b4e44ebebf4c14ad2725bc3c40790fdac009890d44f3383abd33132f3f6e5e2114b5cc22df9a8b90cff57b061562ae48b74ffa53d0870533233fd1052e3f707216cf5f4f5941b0a67a5fc4a061e9d198ff7ffb01319f58779842a605461416c316bdf058e6e9091be4a69251bfe3556c7156ea0bfcd002f24822c0ba3cdd2cebfa9dc6b2463fe259b455c858bd7ebe5988a8fa6a4715c6bd4115489dbbc697f5a5b34058fc475b7c0db7f5faa108eefef8259641d4e435288c77eaa861163c2ce048a82cac90d17ddaa9adefe6a0b0f5fd155f4a31e4b4c3b3a31833d66f425462368041359d6a3165839ba3d51ee8b791da4adbf42e9b8aecd710112cf0a60bc6f9dcfa2f9caf91dcd6559d630eff407694c22b8a7f3217e5987a59b232ca2c7ea4cd3014c1c5fd4c941b0b767fd8d3246cbf48031d37564c8e6b56394dfbce815f6977954291049b53e440d880b42705939d9a513836df7abf4ffa7155ff9a1d2b1cf4c132390aaaa81594537ebee834ef41dd79e3430310491ccd9afd39971af54a580151557aaa9b9b822912260109b314fec98a14b4e525681877a2205703f005ca6aa56ae54a692356508326d024e1af8779187808b94aac22d36fd2b16c1be1f9bd7062999e28638cf4bd50f9c18e06632bc8660889bf0f45d52f09d6491d5291fe8619b329f6495be879093e92fb88c7c771bc0ba7da4f99386c80e0da2637249fe7fd99a57966d1d1e20dfae75a4967bd4676a882e6c13c121806f093d7e9426ce22275f598942b4fb7509951305b214b8b8f847e4ba4b26a3d9654105680cc2e7fdadd4c5c2260b6e19016a7ba548ea78bb8c562a4a1c68753bcab7104110d3df6fa239d54bdd8edc6c165c348ead91ad0e6ceea6aaeea0f71128d8187b4583eef22f3f3eba95a642bb9587909ff0eca1c2951afba46b0197f4b7c5428eb5a85bf730e9f756aa2859346bfac37373701233a0d60fc6055f3d94da49c03a7882fd3d498632d70fbd6c0db57c57bc6bb35165258f3094e6227ebd11ab04a423070437690cd7a10bd4beb2dadd3e165c2ccd25cf91e8ce7e784371b2bde24e653d327836fb9ae76a570c4edb3a5f064177cde8ff10f6821c0ab1a898ef8ae884a02b0187ff705b250d4fa28d6b0210e7f4be1b259e383b56c44d6804f1221f61ed9afbefa1260671ee6e5493d8817804337c65cbb008a0583c1e56c4fdf52e00df2cb7141d9f14da19fdc7cfb80aed1ddd3710b56a6fa11e3d75c1fe793607d2e1d40c3447841d2a38070b848577f15beda8f85f109797aaa84ed5598f689b8f2c5655476ea40fcbe39543dac3c60327202ef6c8e1c0cd266ffe5f0d8dd8f659acfd959007dea7523e2ce949e969070e9328a07a1f6782a2372d61617293bc2b63d030508feef745d3bb439dfa257ec847dcd8843f8ed9610d6554b0eecc710f1cf25157cf1e2f519edcee21f668b783ba516abab22b0260ca4d967ca0485c93b1fed3018ab6c198e35d26734441749d39cc683b0dcacc7ba8ec731db802a527e44fe8eebe0071e84381a2f531298c3ce3d62bb94cf1d6a958de66ad89229aef7bcc80bf1fea19948cf76f617380006fe6fc0c934f96dfd6042ab8347838391dbfc41b755166bfac7b0d587c829da4ce51f1987586e43e06e627557c0cfed351c4ee114657e50063eda1d826a24f6a134a822bd0091b1c21e728006b98f564d00d1248ab1032d211023d85b05feda20fd3decee4c2332e01ce5cc25c553a23ab055b2e7fa8cc2e61ef772b4589415b4d58d00dff388770227c8fa8793ba38680516d9a67bd4dbd20b90335d5af10a92dd5123351dea5fb070ab6bbe0f6b613355eb8356b5cc5bf8316ce6/usr/sbin/cryptsetup@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcryptsetup-2.0.6-lp151.2.3.1.src.rpmcryptsetupcryptsetup(x86-64) @@@@@@@@@@@@@@@@@@@@@@    /bin/sh/bin/sh/bin/shcoreutilscoreutilslibblkid.so.1()(64bit)libblkid.so.1(BLKID_2.15)(64bit)libblkid.so.1(BLKID_2.17)(64bit)libblkid.so.1(BLKID_2.21)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.15)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.25)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcryptsetup.so.12()(64bit)libcryptsetup.so.12(CRYPTSETUP_2.0)(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpwquality.so.1()(64bit)libpwquality.so.1(LIBPWQUALITY_1.0)(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1]@[G[G[{Zp^@Zlnussel@suse.delnussel@suse.delnussel@suse.deastieger@suse.comarchie.cobbs@gmail.commpluskal@suse.commpluskal@suse.comalexander_naumov@opensuse.orgbenoit.monin@gmx.frtiwai@suse.deasterios.dramis@gmail.comcrrodriguez@opensuse.orgcrrodriguez@opensuse.orgmpluskal@suse.com- New version 2.0.6 (jsc#SLE-5911, bsc#1165580): Changes since version 2.0.5 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Fix support of larger metadata areas in LUKS2 header. This release properly supports all specified metadata areas, as documented in LUKS2 format description (see docs/on-disk-format-luks2.pdf in archive). Currently, only default metadata area size is used (in format or convert). Later cryptsetup versions will allow increasing this metadata area size. * If AEAD (authenticated encryption) is used, cryptsetup now tries to check if the requested AEAD algorithm with specified key size is available in kernel crypto API. This change avoids formatting a device that cannot be later activated. For this function, the kernel must be compiled with the CONFIG_CRYPTO_USER_API_AEAD option enabled. Note that kernel user crypto API options (CONFIG_CRYPTO_USER_API and CONFIG_CRYPTO_USER_API_SKCIPHER) are already mandatory for LUKS2. * Fix setting of integrity no-journal flag. Now you can store this flag to metadata using --persistent option. * Fix cryptsetup-reencrypt to not keep temporary reencryption headers if interrupted during initial password prompt. * Adds early check to plain and LUKS2 formats to disallow device format if device size is not aligned to requested sector size. Previously it was possible, and the device was rejected to activate by kernel later. * Fix checking of hash algorithms availability for PBKDF early. Previously LUKS2 format allowed non-existent hash algorithm with invalid keyslot preventing the device from activation. * Allow Adiantum cipher construction (a non-authenticated length-preserving fast encryption scheme), so it can be used both for data encryption and keyslot encryption in LUKS1/2 devices. For benchmark, use: [#] cryptsetup benchmark -c xchacha12,aes-adiantum [#] cryptsetup benchmark -c xchacha20,aes-adiantum For LUKS format: [#] cryptsetup luksFormat -c xchacha20,aes-adiantum-plain64 -s 256 The support for Adiantum will be merged in Linux kernel 4.21. For more info see the paper https://eprint.iacr.org/2018/720.- Suggest hmac package (boo#1090768) - remove old upgrade hack for upgrades from 12.1 - New version 2.0.5 Changes since version 2.0.4 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Wipe full header areas (including unused) during LUKS format. Since this version, the whole area up to the data offset is zeroed, and subsequently, all keyslots areas are wiped with random data. This ensures that no remaining old data remains in the LUKS header areas, but it could slow down format operation on some devices. Previously only first 4k (or 32k for LUKS2) and the used keyslot was overwritten in the format operation. * Several fixes to error messages that were unintentionally replaced in previous versions with a silent exit code. More descriptive error messages were added, including error messages if - a device is unusable (not a block device, no access, etc.), - a LUKS device is not detected, - LUKS header load code detects unsupported version, - a keyslot decryption fails (also happens in the cipher check), - converting an inactive keyslot. * Device activation fails if data area overlaps with LUKS header. * Code now uses explicit_bzero to wipe memory if available (instead of own implementation). * Additional VeraCrypt modes are now supported, including Camellia and Kuznyechik symmetric ciphers (and cipher chains) and Streebog hash function. These were introduced in a recent VeraCrypt upstream. Note that Kuznyechik requires out-of-tree kernel module and Streebog hash function is available only with the gcrypt cryptographic backend for now. * Fixes static build for integritysetup if the pwquality library is used. * Allows passphrase change for unbound keyslots. * Fixes removed keyslot number in verbose message for luksKillSlot, luksRemoveKey and erase command. * Adds blkid scan when attempting to open a plain device and warn the user about existing device signatures in a ciphertext device. * Remove LUKS header signature if luksFormat fails to add the first keyslot. * Remove O_SYNC from device open and use fsync() to speed up wipe operation considerably. * Create --master-key-file in luksDump and fail if the file already exists. * Fixes a bug when LUKS2 authenticated encryption with a detached header wiped the header device instead of dm-integrity data device area (causing unnecessary LUKS2 header auto recovery).- make parallell installable version for SLE12- New version 2.0.4 Changes since version 2.0.3 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Use the libblkid (blockid) library to detect foreign signatures on a device before LUKS format and LUKS2 auto-recovery. This change fixes an unexpected recovery using the secondary LUKS2 header after a device was already overwritten with another format (filesystem or LVM physical volume). LUKS2 will not recreate a primary header if it detects a valid foreign signature. In this situation, a user must always use cryptsetup repair command for the recovery. Note that libcryptsetup and utilities are now linked to libblkid as a new dependence. To compile code without blockid support (strongly discouraged), use --disable-blkid configure switch. * Add prompt for format and repair actions in cryptsetup and integritysetup if foreign signatures are detected on the device through the blockid library. After the confirmation, all known signatures are then wiped as part of the format or repair procedure. * Print consistent verbose message about keyslot and token numbers. For keyslot actions: Key slot unlocked/created/removed. For token actions: Token created/removed. * Print error, if a non-existent token is tried to be removed. * Add support for LUKS2 token definition export and import. The token command now can export/import customized token JSON file directly from command line. See the man page for more details. * Add support for new dm-integrity superblock version 2. * Add an error message when nothing was read from a key file. * Update cryptsetup man pages, including --type option usage. * Add a snapshot of LUKS2 format specification to documentation and accordingly fix supported secondary header offsets. * Add bundled optimized Argon2 SSE (X86_64 platform) code. If the bundled Argon2 code is used and the new configure switch - -enable-internal-sse-argon2 option is present, and compiler flags support required optimization, the code will try to use optimized and faster variant. Always use the shared library (--enable-libargon2) if possible. This option was added because an enterprise distribution rejected to support the shared Argon2 library and native support in generic cryptographic libraries is not ready yet. * Fix compilation with crypto backend for LibreSSL >= 2.7.0. LibreSSL introduced OpenSSL 1.1.x API functions, so compatibility wrapper must be commented out. * Fix on-disk header size calculation for LUKS2 format if a specific data alignment is requested. Until now, the code used default size that could be wrong for converted devices. Changes since version 2.0.2 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Expose interface to unbound LUKS2 keyslots. Unbound LUKS2 keyslot allows storing a key material that is independent of master volume key (it is not bound to encrypted data segment). * New API extensions for unbound keyslots (LUKS2 only) crypt_keyslot_get_key_size() and crypt_volume_key_get() These functions allow to get key and key size for unbound keyslots. * New enum value CRYPT_SLOT_UNBOUND for keyslot status (LUKS2 only). * Add --unbound keyslot option to the cryptsetup luksAddKey command. * Add crypt_get_active_integrity_failures() call to get integrity failure count for dm-integrity devices. * Add crypt_get_pbkdf_default() function to get per-type PBKDF default setting. * Add new flag to crypt_keyslot_add_by_key() to force update device volume key. This call is mainly intended for a wrapped key change. * Allow volume key store in a file with cryptsetup. The --dump-master-key together with --master-key-file allows cryptsetup to store the binary volume key to a file instead of standard output. * Add support detached header for cryptsetup-reencrypt command. * Fix VeraCrypt PIM handling - use proper iterations count formula for PBKDF2-SHA512 and PBKDF2-Whirlpool used in system volumes. * Fix cryptsetup tcryptDump for VeraCrypt PIM (support --veracrypt-pim). * Add --with-default-luks-format configure time option. (Option to override default LUKS format version.) * Fix LUKS version conversion for detached (and trimmed) LUKS headers. * Add luksConvertKey cryptsetup command that converts specific keyslot from one PBKDF to another. * Do not allow conversion to LUKS2 if LUKSMETA (external tool metadata) header is detected. * More cleanup and hardening of LUKS2 keyslot specific validation options. Add more checks for cipher validity before writing metadata on-disk. * Do not allow LUKS1 version downconversion if the header contains tokens. * Add "paes" family ciphers (AES wrapped key scheme for mainframes) to allowed ciphers. Specific wrapped ley configuration logic must be done by 3rd party tool, LUKS2 stores only keyslot material and allow activation of the device. * Add support for --check-at-most-once option (kernel 4.17) to veritysetup. This flag can be dangerous; if you can control underlying device (you can change its content after it was verified) it will no longer prevent reading tampered data and also it does not prevent silent data corruptions that appear after the block was once read. * Fix return code (EPERM instead of EINVAL) and retry count for bad passphrase on non-tty input. * Enable support for FEC decoding in veritysetup to check dm-verity devices with additional Reed-Solomon code in userspace (verify command). Changes since version 2.0.1 ~~~~~~~~~~~~~~~~~~~~~~~~~~~ * Fix a regression in early detection of inactive keyslot for luksKillSlot. It tried to ask for passphrase even for already erased keyslot. * Fix a regression in loopaesOpen processing for keyfile on standard input. Use of "-" argument was not working properly. * Add LUKS2 specific options for cryptsetup-reencrypt. Tokens and persistent flags are now transferred during reencryption; change of PBKDF keyslot parameters is now supported and allows to set precalculated values (no benchmarks). * Do not allow LUKS2 --persistent and --test-passphrase cryptsetup flags combination. Persistent flags are now stored only if the device was successfully activated with the specified flags. * Fix integritysetup format after recent Linux kernel changes that requires to setup key for HMAC in all cases. Previously integritysetup allowed HMAC with zero key that behaves like a plain hash. * Fix VeraCrypt PIM handling that modified internal iteration counts even for subsequent activations. The PIM count is no longer printed in debug log as it is sensitive information. Also, the code now skips legacy TrueCrypt algorithms if a PIM is specified (they cannot be used with PIM anyway). * PBKDF values cannot be set (even with force parameters) below hardcoded minimums. For PBKDF2 is it 1000 iterations, for Argon2 it is 4 iterations and 32 KiB of memory cost. * Introduce new crypt_token_is_assigned() API function for reporting the binding between token and keyslots. * Allow crypt_token_json_set() API function to create internal token types. Do not allow unknown fields in internal token objects. * Print message in cryptsetup that about was aborted if a user did not answer YES in a query.- update to 2.0.1: * To store volume key into kernel keyring, kernel 4.15 with dm-crypt 1.18.1 is required * Increase maximum allowed PBKDF memory-cost limit to 4 GiB * Use /run/cryptsetup as default for cryptsetup locking dir * Introduce new 64-bit byte-offset *keyfile_device_offset functions. * New set of fucntions that allows 64-bit offsets even on 32bit systems are now availeble: - crypt_resume_by_keyfile_device_offset - crypt_keyslot_add_by_keyfile_device_offset - crypt_activate_by_keyfile_device_offset - crypt_keyfile_device_read The new functions have added the _device_ in name. Old functions are just internal wrappers around these. * Also cryptsetup --keyfile-offset and --new-keyfile-offset now allows 64-bit offsets as parameters. * Add error hint for wrongly formatted cipher strings in LUKS1 and properly fail in luksFormat if cipher format is missing required IV.- Update to version 2.0.0: * Add support for new on-disk LUKS2 format * Enable to use system libargon2 instead of bundled version * Install tmpfiles.d configuration for LUKS2 locking directory * New command integritysetup: support for the new dm-integrity kernel target * Support for larger sector sizes for crypt devices * Miscellaneous fixes and improvements- Update to version 1.7.5: * Fixes to luksFormat to properly support recent kernel running in FIPS mode (bsc#1031998). * Fixes accesses to unaligned hidden legacy TrueCrypt header. * Fixes to optional dracut ramdisk scripts for offline re-encryption on initial boot.- Update to version 1.7.4: * Allow to specify LUKS1 hash algorithm in Python luksFormat wrapper. * Use LUKS1 compiled-in defaults also in Python wrapper. * OpenSSL backend: Fix OpenSSL 1.1.0 support without backward compatible API. * OpenSSL backend: Fix LibreSSL compatibility. * Check for data device and hash device area overlap in veritysetup. * Fix a possible race while allocating a free loop device. * Fix possible file descriptor leaks if libcryptsetup is run from a forked process. * Fix missing same_cpu_crypt flag in status command. * Various updates to FAQ and man pages. - Changes for version 1.7.3: * Fix device access to hash offsets located beyond the 2GB device boundary in veritysetup. * Set configured (compile-time) default iteration time for devices created directly through libcryptsetup * Fix PBKDF2 benchmark to not double iteration count for specific corner case. * Verify passphrase in cryptsetup-reencrypt when encrypting a new drive. * OpenSSL backend: fix memory leak if hash context was repeatedly reused. * OpenSSL backend: add support for OpenSSL 1.1.0. * Fix several minor spelling errors. * Properly check maximal buffer size when parsing UUID from /dev/disk/.- Update to version 1.7.2: * Update LUKS documentation format. Clarify fixed sector size and keyslots alignment. * Support activation options for error handling modes in Linux kernel dm-verity module: - -ignore-corruption - dm-verity just logs detected corruption - -restart-on-corruption - dm-verity restarts the kernel if corruption is detected If the options above are not specified, default behavior for dm-verity remains. Default is that I/O operation fails with I/O error if corrupted block is detected. - -ignore-zero-blocks - Instructs dm-verity to not verify blocks that are expected to contain zeroes and always return zeroes directly instead. NOTE that these options could have security or functional impacts, do not use them without assessing the risks! * Fix help text for cipher benchmark specification (mention --cipher option). * Fix off-by-one error in maximum keyfile size. Allow keyfiles up to compiled-in default and not that value minus one. * Support resume of interrupted decryption in cryptsetup-reencrypt utility. To resume decryption, LUKS device UUID (--uuid option) option must be used. * Do not use direct-io for LUKS header with unaligned keyslots. Such headers were used only by the first cryptsetup-luks-1.0.0 release (2005). * Fix device block size detection to properly work on particular file-based containers over underlying devices with 4k sectors. - Update to version 1.7.1: * Code now uses kernel crypto API backend according to new changes introduced in mainline kernel While mainline kernel should contain backward compatible changes, some stable series kernels do not contain fully backported compatibility patches. Without these patches most of cryptsetup operations (like unlocking device) fail. This change in cryptsetup ensures that all operations using kernel crypto API works even on these kernels. * The cryptsetup-reencrypt utility now properly detects removal of underlying link to block device and does not remove ongoing re-encryption log. This allows proper recovery (resume) of reencrypt operation later. NOTE: Never use /dev/disk/by-uuid/ path for reencryption utility, this link disappears once the device metadata is temporarily removed from device. * Cryptsetup now allows special "-" (standard input) keyfile handling even for TCRYPT (TrueCrypt and VeraCrypt compatible) devices. * Cryptsetup now fails if there are more keyfiles specified for non-TCRYPT device. * The luksKillSlot command now does not suppress provided password in batch mode (if password is wrong slot is not destroyed). Note that not providing password in batch mode means that keyslot is destroyed unconditionally.- update to 1.7.0: * The cryptsetup 1.7 release changes defaults for LUKS, there are no API changes. * Default hash function is now SHA256 (used in key derivation function and anti-forensic splitter). * Default iteration time for PBKDF2 is now 2 seconds. * Fix PBKDF2 iteration benchmark for longer key sizes. * Remove experimental warning for reencrypt tool. * Add optional libpasswdqc support for new LUKS passwords. * Update FAQ document.- Fix missing dependency on coreutils for initrd macros (boo#958562) - Call missing initrd macro at postun (boo#958562)- Update to 1.6.8 * If the null cipher (no encryption) is used, allow only empty password for LUKS. (Previously cryptsetup accepted any password in this case.) The null cipher can be used only for testing and it is used temporarily during offline encrypting not yet encrypted device (cryptsetup-reencrypt tool). Accepting only empty password prevents situation when someone adds another LUKS device using the same UUID (UUID of existing LUKS device) with faked header containing null cipher. This could force user to use different LUKS device (with no encryption) without noticing. (IOW it prevents situation when attacker intentionally forces user to boot into different system just by LUKS header manipulation.) Properly configured systems should have an additional integrity protection in place here (LUKS here provides only confidentiality) but it is better to not allow this situation in the first place. (For more info see QubesOS Security Bulletin QSB-019-2015.) * Properly support stdin "-" handling for luksAddKey for both new and old keyfile parameters. * If encrypted device is file-backed (it uses underlying loop device), cryptsetup resize will try to resize underlying loop device as well. (It can be used to grow up file-backed device in one step.) * Cryptsetup now allows to use empty password through stdin pipe. (Intended only for testing in scripts.)- Enable verbose build log.- regenerate the initrd if cryptsetup tool changes (wanted by 90crypt dracut module)- Update to 1.6.7 * Cryptsetup TCRYPT mode now supports VeraCrypt devices (TrueCrypt extension) * Support keyfile-offset and keyfile-size options even for plain volumes. * Support keyfile option for luksAddKey if the master key is specified. * For historic reasons, hashing in the plain mode is not used if keyfile is specified (with exception of --key-file=-). Print a warning if these parameters are ignored. * Support permanent device decryption for cryptsetup-reencrypt. To remove LUKS encryption from a device, you can now use - -decrypt option. * Allow to use --header option in all LUKS commands. The - -header always takes precedence over positional device argument. * Allow luksSuspend without need to specify a detached header. * Detect if O_DIRECT is usable on a device allocation. There are some strange storage stack configurations which wrongly allows to open devices with direct-io but fails on all IO operations later. * Add low-level performance options tuning for dmcrypt (for Linux 4.0 and later). * Get rid of libfipscheck library. (Note that this option was used only for Red Hat and derived distributions.) With recent FIPS changes we do not need to link to this FIPS monster anymore. Also drop some no longer needed FIPS mode checks. * Many fixes and clarifications to man pages. * Prevent compiler to optimize-out zeroing of buffers for on-stack variables. * Fix a crash if non-GNU strerror_r is used./bin/sh/bin/shbuild84 1600178598  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGcsdadeesfifriditnlplptsrsvukvizh2.0.6-lp151.2.3.12.0.6-lp151.2.3.1 cryptsetupcryptsetupcryptsetup.confcryptsetupcryptsetup-reencryptintegritysetupveritysetupcryptsetupAUTHORSCOPYINGCOPYING.LGPLChangeLog.oldFAQREADMETODOv1.0.7-ReleaseNotesv1.1.0-ReleaseNotesv1.1.1-ReleaseNotesv1.1.2-ReleaseNotesv1.1.3-ReleaseNotesv1.2.0-ReleaseNotesv1.3.0-ReleaseNotesv1.3.1-ReleaseNotesv1.4.0-ReleaseNotesv1.4.1-ReleaseNotesv1.4.2-ReleaseNotesv1.4.3-ReleaseNotesv1.5.0-ReleaseNotesv1.5.1-ReleaseNotesv1.6.0-ReleaseNotesv1.6.1-ReleaseNotesv1.6.2-ReleaseNotesv1.6.3-ReleaseNotesv1.6.4-ReleaseNotesv1.6.5-ReleaseNotesv1.6.6-ReleaseNotesv1.6.7-ReleaseNotesv1.6.8-ReleaseNotesv1.7.0-ReleaseNotesv1.7.1-ReleaseNotesv1.7.2-ReleaseNotesv1.7.3-ReleaseNotesv1.7.4-ReleaseNotesv1.7.5-ReleaseNotesv2.0.0-ReleaseNotesv2.0.1-ReleaseNotesv2.0.2-ReleaseNotesv2.0.3-ReleaseNotesv2.0.4-ReleaseNotesv2.0.5-ReleaseNotesv2.0.6-ReleaseNotescryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup.mocryptsetup-reencrypt.8.gzcryptsetup.8.gzintegritysetup.8.gzveritysetup.8.gz/run//sbin//usr/lib/tmpfiles.d//usr/sbin//usr/share/doc/packages//usr/share/doc/packages/cryptsetup//usr/share/locale/cs/LC_MESSAGES//usr/share/locale/da/LC_MESSAGES//usr/share/locale/de/LC_MESSAGES//usr/share/locale/es/LC_MESSAGES//usr/share/locale/fi/LC_MESSAGES//usr/share/locale/fr/LC_MESSAGES//usr/share/locale/id/LC_MESSAGES//usr/share/locale/it/LC_MESSAGES//usr/share/locale/nl/LC_MESSAGES//usr/share/locale/pl/LC_MESSAGES//usr/share/locale/pt_BR/LC_MESSAGES//usr/share/locale/sr/LC_MESSAGES//usr/share/locale/sv/LC_MESSAGES//usr/share/locale/uk/LC_MESSAGES//usr/share/locale/vi/LC_MESSAGES//usr/share/locale/zh_CN/LC_MESSAGES//usr/share/man/man8/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:14036/openSUSE_Leap_15.1_Update/8245005994a8e0e5519df3a35f039318-cryptsetup.openSUSE_Leap_15.1_Updatedrpmxz5x86_64-suse-linuxdirectoryASCII textELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, BuildID[sha1]=1c6e271d2d43be34dfefe740cc8f6e885fd0ed8a, for GNU/Linux 3.2.0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, BuildID[sha1]=c78c00fb83d7e59e6bb53d840dfdc0f5427e67ba, for GNU/Linux 3.2.0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, BuildID[sha1]=e0d1a51d3c6f87a84003b77dc7e0ed3579e0d73c, for GNU/Linux 3.2.0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, BuildID[sha1]=e50ab7e50c23bd6f21d98c0630711eb1fcbc5448, for GNU/Linux 3.2.0, strippedUTF-8 Unicode texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)+>RRRRR RR RR RRRR RRRRRRRRR RRRRRRRR RR RR RRR RRRRRR RRRRR RR RRRR RRRRRRRR RRRR RR RRR RRRRRRR TvRys\Y if test -x /usr/lib/module-init-tools/regenerate-initrd-posttrans; then /bin/bash -${-/e/} /usr/lib/module-init-tools/regenerate-initrd-posttrans fi #/bin/shutf-82214cdb8b2e960724cea18b8fd63d3fcf93618e57f6ac5c39cfaf7683fe16e31?7zXZ !t/ ]"k%{Aٙz |25Yǒ{\V,VJ}C_om"$pkJ1$̺_5S!=N&f3Y2!?Rk d˿],ODk)-C~xA2h!ZLz2{C1&O.F5_Ey|D 97Hc@: vjz ʈJM~ǻ')P؁<#%C؆6Ka^3>s`UA%[Mg4 ~"' õ8b-47/{J-]coR#Ml,u&jeo'moqVC[pۥۘ[ 1{?s²SҸRWb@Uh[0W踁Μz9u8=ȶË6 釛9 f\VDλkUlp'm4g&F@١:`>K[R7顜|L-%s).hV"3L.E5iGma,& ~/٬2cS SBr\瓧양ۇvH|g8 XMz6^|0sTO>S:9M]w Xɩ%FCS tU}WQK"%/C ~wz5g7?E^!{#-@ G\2A}h?4f[fc%ނ2'Sl =<<:nn#7̲_A]sE< ȁ&ToZFJ_>벉RvM^cX ) Wx̢҄` !,t[,๳ɫq!̭Y}ȱ-Gp|zvO76ڗqu4"tǸyBS7oiGV2Jīl" iR(R}!'W^HLvde۠ zF (Lٷ/"\g;p N)rS7ط}>M,咁 ~RF\p@FOQ9D-LBP` e^S2w/?;!*y4ZG8zMiݗ}w I@PAntEFWfk*wH4rOYE?6fW8c'PW1K&Y]{Ov&=ELI' w)81x] (VE%@ZC[s$'4lqI$" B ]Yظ4rF]bߪDA rH6~6|#U,,$s;PJd"v:=37z0꾻L'0ܕOUi`He_>TXn>bCjiNH3,uVѹ*EtcLV2Ө}r z5EjAMrHpcXrJx&CIQ0Rg>|7؝jcYdWhbbN]@SXfczǧB:(i 9UNg;0ŰK6Щ #To 'gP0Ә||۞#pAGfhɐYvMi춋;`&ZnbE79p8Ahg<;t @)^=WaF?5V.:7ON왯l&}GzW2Ygf=W& q"QcJ &&Nj;;:T2=&k7AE8'bN0q ^.QH ;~?4MyxqZ5u$J5MY=Nˋ?3@Vy7x/YYo dJW f7(WY5.H?z!%CP &z ҤHLʬo: ~u`㿰@#O/plYO߈–;}# Q"sxD Dm&`N o N'PLZ65l8Gn۰yzV n=u~:#`/u4DN1e*<]pwRXԬrϾ5EV*hnp J-BuBf99a.rpRd8pdX~tVˬ=hO+jat30)R Q9DpP(Q˅3bҧG~n@DZr'VRr|-;?~Wnv;H02\8e\QF;&G  ]8 k,[T&碷ǫe^ߐNa)R23EcȠ@AL {?sswlrsYpѸ0Bc UIQsE܎9uHχQD֔}k5)\}%?4LlDU|u﷒ɏh¥|ٺxzjNFY2X5KgӹI3"Mc'%S5FƼӇ>Icm(lInV}yuh7Us1jf\b1 }Pz|ex S~ RE G[S !6[eͶA? gTdnWR!fߔշUݽx$?)N2͔{#Kqi^9WdG1#1v|}gcfPOB2In;!)zX J.`##\Kdc`ZBMxtx|Щǜ 1g;cea,ި["[267iZbѢq'ISjbۭ¹3W!brr]hz^ۉr/^IR')B>[ذL`T@Pkt:$pͨe\`#oGE9Wn&abs/S$Q roIrDxHp2-|N{>YX0-spм >6Zy1Ju4&+ӮHkw5% PSeht:C_YS`7nLΨ!!2ߏF\Jj^,( ofYqE'`N^Zߕi7 ( 6\Jhpxn1"/ 42ގ4Yl#ök׻٭NfpX(ޓCoz((1410j0/U; "mxCI1ŝI hSKv`VMK2=pTj@oV$JZ,D_{'쇧8d~,+8yUUaZ1|h~bP|J-!|o,841am?tήǼ`?Ō |PRa.E4o8? F%'vw ̕ƐuJ_7 o;TN-GlM"c꒭:+V">%f&Z!Rtg?ߌIBb!{3 .+Mus'tY\:4!6n !61sy'ۗ@uvZ }`}BfQ]sQ+!B|*$c)Ş5C <ǣ:h|s+KՔEN&S$M$ނ{t Z 8YΙSpnLKkeU 3uq0pi[]î W ;oDGDޥu=uXTԱLjp WB9<a^ ׸?$Q n%#"1"멪6iʂMv)> }w;ƕA`XJaovF6ńj|,O hȔ,nXHo|N *mNً߉U106I-m"=!ؿ#RZ8Vq4V:ELfA8{-4\۹6:U5U7DG@kdbM-}44 o¨1tu}&t -7Vy2k@&Iw9ȩH w Zc#i|`yE+Hͨ.qioB*`gg8(G|2l{ADxƭ ybRjKVWhX4ׄD\3qGJ</#' YP!jI'#|yq*f~B]xUdB9}l%H:vd? M" zƫQoQdv$`+,7(CAb-߀lSlT]q˹'kQ~gg^ЍW"P}&ذaYjr L+.k>GJ7ڂRh'@z)&vJԲhj-߃Kp)b\ѳ9=B"hV)W"]{첺)熔|C}p,3C]vTk& Bv6. 6چO/>Uo1jtp'jS#Yju #4Zڔ7v4E;.sp}8\sfdQL(bNlph@`lh;**ngsIO|b-ۛST-kU^c$/dd8MS*ZDدk+`HPDn2Agʭmۜth*m6\30y]y\e)/L 0BnWxc똱Q?.CG5C]Sst {6Tr钶 |sZL>KݔF<+E,Sadh]WŕNeol{*"oRn%ovj\ ~{R0!0fkPzŕ 3-NKlVS4s %MU SqOPUrX2+j@>C~I"3W1/#>Xr[b,e{KYg<>b}oL|Evc8c[28pF*3iަ 鰒ZpbQ˵Y9&>#H/<Ùu˹,lӿsw]1ѽӉ\D3):hs:v/Tc >dS^@fO7v\ɋ5VvB`5f6x:CT|R1h|<31HxMX-nGžbFBQV_L$3~É/E.9(G% [XZYDi6c\Y+@ :x'vRcZR홝kAąuBG"klw4߮ /}L;VN|08gRkTX{yřlv'uҟ22o3B.^LS}rv?>( 8-MV$9_ Vb8Ou3ݶtXo)G˚Sk?t .!re㊝U6PpxDw58sd'I@" Qj|UcXl=lpKz^WE,u]/@#IB ٪)H ЭeFN".b嫟6/uC=q3c2~ɜ^|N:15RKfYM9{.Ѯ?w P6ePеaEקJa,i\+(sYeqc(U:%޳BS:MLn+xk_ .ѰBry*sZgA've(,1JAFx043\ m0۸}B!#h p1-~aA}VDP?֯fyW]3C_G¬'f,bK]&5k2ͳKK+Aϱ d鞈tQ_ =\ؾ-TXDAVy ? 48{\N1"<@ú#%| &kA};m~cgU%aS X(*5ڊGe/,jxUsdboשL 61~BL<1S5 }.R%P5vnA=rhBs># l$* )9ے"pD4CRT\Ģ)]n+| W}: Jkm.[]l+(:=7.av{Gr+Z$xBu?}޿w-GO *Y\&kݷ5w!a!]?0IApH?^-z~|܆X]IvBǺH^Zυ$e^Y]TGYE, ~Oy^6 C*('[xBo`E bɬ62C?^* qJ>k^"+>&U@ ~ Y` A^d-7׽HlX{xa-ԑ<7Hˡ17)"sJdt2EĴ "\!ϟ3\q-ZLZB{uJcETjElqg:ΐ{,cCF49Ă)"pA+h@5u %yJ?DE^Jbdg77&c|~?p嘗2 m]DcJyu7/M2GKDҀJ#<x\< sK|UppMBDN㼤d:·WMڜ7Ԛ;ZtL/ëiC\t9>0QZ/+W㾩;5EY!Ws92'qZaoܥ**xTqT6H^w7j Fa0 2c}DpF7$,vL! QJJWx/z["&dy2oH#tkI?G d5Si 4i7ĝ)Bk 9T;4/_u|P?EJf$y|dTdo|5 w~{d'T豻5 lI#Yt0eQff"$nuH u P2Fҭdbh>󛟜\2l"ś݄` *%|SJe K1+k ~jNX]8%dd 0mƚp,\aj-wH2: SӼaUJs5 Fňl3:Ӎ}Cpx:`H]?`тAUٷ mHaF`t> -7G^,ڭ*pO4q[Uفbm=Qt(IuKq =ثH @!O<AKh  `"Lf#CNiQv$m2Fg34_rP'4a;?/|:g&D&AG#*+L&aCd5tV6g,I(9moKq 8A:d/fͽ)!Cr AܓA@Nml<_dP8#"j$%UɸBCՅ6DGe=j%#vHz= .$/i:[5 <,Xeۮ"$3{Ҏ>,50$tk+O/k37NxŮI)gY'Ve5$8H:tÞ+ˊѥEtsw&q Tk^pЙI(Wo.eu .u$* ,J9MyعM:@ǰ!JyZ09l{JoƧT 41j\cNClA.|͗Q&ڈG3X;)!4QOCր>@RBV<>ks 1<]{@'wms' .m"q5ϞGÆ)o.Q|'m%-E%|~{U{5_(I^ xk=RnsRaB%(8B G\l@FS7 Qmb\Bgs~L=9ߴ&:@l~(`AUJ[>1 udgVg9pܳ9#= 䛻ZEt?̶iT 9]e2O::%駻#&:mݐ:ܩA|Ww7qKu ״Gܓ9h1.?btUB5xIi_XQfKk?Lr=p`G6k%  ?V]Cx+9%;NH[c[AP=|`W!k=d͙O~ [e`Cη# dUnչs쇹"m ek iooF4!~?'- et^n{]?1% ;6hu\iI2'Ӳ1ISڿKZ1c=ԥjغ_a'WאEl7`h\-mG c{3.\&: MEȸϿ_don2sGpSJVj |j|CzGfp$5 1vi.Q ZoWDJ&\^o^vuk?LGpt/E ۚ˸]6V%DMojoj22Q :,A6. qC J促᪱os3bݱB="CO;sB3 yb]a$ڞ I=[J5)%N wq*csRRj20o͏de$k`ToHU.TD*; @LN_to9ȍi]F.q}q Fgd?1nxta5:ζk G ~s9>Db ka4ܪ.1}:Vg^{cA9Bw7r9915?N|]U]$L9Wlإh ^s#KYǝ2 5ao(O ԦO8yd7!_Le:`"+*Y<k6:)-f\gmiler-syHǩ'V9vt=4drdјDLs5!\Dߊ vC+` H)P8p- ^.ia1Tpv;]&,:6›?up>t? tm/?&/4)n.tywԨ+N9V M\MɏBA|$DLW4 ![sctWBQE- _d&``jXvz<qOtKBdh|* ؅i;P4i#EȨVxFR`Qy𚀘zt8-ȑcَG[ѐ9<&5* UzJ:JCY8`<8 L9k|1ԋz}9PafohLAhOƊ  l(%+*uLj|qlNqkwf v ԂjC")4R~փve]8$ 6 3ڣ4ziRs pPsIJQ_\A k܁Z DF2\jA]UMaN ^eˤK>Hu4*gGR@dn 8.pV8d,7q:l]gGdDn2X-Qgw%$jJc)tI ',+U% cqnCy!a |+ <"tjofsyg _qo+$\vҡ!%w~#"AsfB5^CyвvO.lOSۮ&tSnrK8i =q$ p^̦&Bo[􍏲YڝLW*_}lN >iL@C]`<DmI1ߪWl*쑀O1?n~+'lfaDS&Nӹ}۽8HfW#󳭘D0#[kD9g؁E` x&Ӓxd Fp'V%l^ܶ'#c\hZ' O|ʢ>\Wf1hI h $I _D:/OU[Zh9*&!,i_.*\Qۺ1mib=K/΄Yf33v fQfFN+rXč0g7N&{mvT{ƐЛ&sU#EVzCB.9h("Ⱦ$@Up; <@bR_Rc -fnaKہM$粐%Xc}wrlaK7.7tSnt(ҨV-g`.U"?;:%z-y@N*'|+Yrv~1ZR_C!"$$#qѱd!ŻQæJM]Sl 4{4JT Bd/$S8*g)j_YJ8Ry:#.w L%XXo;cA  >6CϹĜ"'h+!k _FR`; ,9Y ,Tķ˔^q(B1~@ޓB^2pՆo =7NSad +R *9;`es=4 3&@Ċ(_{To/SU}p=dle+ob T(ȐlA+K%[17ǻ\n=-9v5Cl>z 64Sm,cE7K ݼsiteO6_H3헓}PP4_ElI؋) zڌTL`Ԣ{z`Øb3B ig:E`*ʕ܉hr-[6O;)iVb,M^1>#6s 5/9~ͪx}ѩ%DŽla,#APAjwYcY V’u5h3/d,#qSSleO z.wageBZcC9:F>5٦ZTI^)qH6.ȇ}c Ṏ1z74s)'6cA GђQϏoz[Xa; skhn&χ2AL6J!a(Lr>Vv;@+[j0XBYl,hQzޡБ6Ӧ3,fvɐ4X=乫L2eògHKNuMRyi|dG^ r/?ve6w^Ĺ첨#bɲ/e5_H{935U yѹ滍cLԺ^" ! (wFUڵ$cRmTGpn͂<1nAg谯K/G^3IzJ6ngB[!_%a]˗YjkH1E|ƙ ڙi Sn¼ƐXl0]BU]tWKfI L^ gͪ=9:g^h_GGnK]%[%8Rƭ^;8/Q>hKtN*C#읗~;#"@cjC; I]Ey|Ѻ!aFOIJ>f?H~Cʑe!kc-d)oNߚu?F)YCe:l0m`A,SuΏvyZJpR=E^}`~EB#%גV ʕoiI b2oj,G69L)n<8r}n%o6" dܶO 8.A6T|2?}1ZP;Tnk - 2Cv4=S_h^D[7Ft"wY-9Q,JQ'c,Dn@g۳kkWΏvdiz0hW|e [=;X( ~Uч@[\)c2XıнbZi30Z,Vv'n2M74d$_ᵲ/ mDm)hpTIu,+S6{ɿm3sU BB]>a TQ ޚ }]TMfEr M^.V$/&G`wݭ:(c sG#YPZ^w0Љ\щ~XЭ yqqˆT]9H00,صU44&Wr_0-T#ʄ`io[Sғ2cH~}-Qg'# Jo^3tC.N+-]Tf&hAȔ !LIJ-wuJH[r8fلBXj҉K4āp͕{vAйNױ :hC僘t2}M~`%aXl]ftS8` pRřm ;=k*fb/ Hci>zaɓV7X5 BLnv BUG?89)_٧ 3a,fǡUtƀIpwi|i.Mֈ=.Ž,Ku^eW*$(n-9^v){g,Vɞ Y"0@Ŵ-&4)m3١07Ҽ菐)Iv&:IB9B$+@ PAƼb^b,`OQыX1dDz )eݱ Wi>,aȰ=ݰ\=D &/#^EoI|H\srfV/sEF2K[ڏ*1<\]DAAl?(5;?(:N/}>l^= ܾn42#mIf( _w;!"Խꆉ;3"id38=4&_ê٩zޟ[qD7M &* }7wK%K|B=hT|g$e"ܳc6C|ePO'ruZ(>mGkI|\i]e#Wo,&6RQ g{ԩ}&Ȕ =@0Yx/$@9Bw..[ f+keb51퐭;]Q" w"R#Q8+Ӝ{{ܰX%?0ey(ꔐfŬK޲w|[R֔&Z3iSC`dqs}yhui%>S[ռ.Uśe|B5xדYHCZbR~Ɵ_^6 Qr)HQ8'9te>S+z;I8YԘ#[ll>iuOA>FM}[ú0tl,&|Yo<$GOԮ[H0i@Ժt)%qrCRrLI澰?\%/ƈtfWf#A1 qvW|L$iP&HtGM{" e:Iҳmxw9]Ctx/?zf7<VIsMXh5r3ktakG+M<髏eQ%2S,}d`ɯLwlÚ\ NUqJ9y5d(Vw\w\ng>eG_ՌTV@B*̿{p0c- 3͚E_W w_xSDv*;}.. |C퐎Ԭ@KtA';MQk of$;+-pMсt_:f9%ZrwmL4$AG|&.ٗ1)h|ej4_u}, xcFJ9-9?gLV^9m)p/{"\(r/Y:Ż|[McaxYZ0^+<ۇ"4-e^B=Hmdhv qqhWk{y k ˆ0ujL^!uFYQi_9_$9`(v8 dpO' p3&>C<}8DoUAŃ"MC막NNğq O*X'qC׸Q3I}b"SM> fDe'#=Q_~ۦ|gpJ;6O)_`{&m7jj-5'WmF=ngbsuW: c T!QGh!?*D7u\A@rW~qw{͉y\G(5LNJ@&恑(AFNS_h.2ުgTCyLSURX(#3",]Opft͸ *Pp?~:n'dNvA6L3r@$); Df|:Kȥ!r SWn6 oش[unyk3<  XyXi #7/┾^v ׼AiD-#rgm PʰDV7]TorI`~j ;u8mՎژtEAV:v9X"G@ 49Y|kBN`^1uұsᴆ0JyoigTN Fy1@K}q˿Kk-2f<+5j Y=C|YFH§y,n8P(d$;DYdQ/-*(-֊)gR~ '5ڂGCIJ m>էmI.q`wYJ v$֥6wC?*`91@ݧTŦ( ,eGEȕ>'_:eY\oOݩ+_uluVS+qmK$n!ٝV!F{UnKtn~?ow7-#/k͑ bgC:Rj1O8[c2KPDшF5TM c[;fr*9C.j݀fUPtm5+ےCp^ՙnp2`BanߙѦ'Z`'Z!)^J-JrCƀ3x͉ c>7ɥ c}_4vbjeG3ݘU6zQ[OafxZnW 0~SOM 2"pvOx>0U Ȧ=ïKwe9;[˴d r x'[ꁐv,GZ&J2$S,y4ՐMEg; y6{FNʌE{'x G'PAe#@cV'Fs;7Y[lxXj^$ud\שׁ, 9`Q3@NݎV5 Ʃq*`v;O9tx/z[f \J6|*Hh20!?Ƚ>G^c#haiT-l[$wơy_u_Pc8aT^p $yZ5AsJ֢^<{0y%K'u*@JBt@UC/{,vޛHq ˺)^PTo$qlЗ"QM[B.<9_6&OBR] s\d2p RV G.r֥~ubQ%ȔjL׼īaq9u~F!p(AuNebyзs` t2`}L&ߊ\J8Gcf{UåN9(O\?QgkY J^a1ehϛ(55md_ELeCf^ZFQɺ sS3P|MvN W'gm~h :\OѯG.R*DR|B^m vR] 0[F0?P,ƴ+f\.ll~+W`?L9 >5-Ƕ:REuYG|o;Mı~f/K_Hw~\7OAԭ|j A_;÷~ w%,F)vukCpVmbE#|!۲~ UrvsG 2 oH8fxP՛aqUht6~)]FYˊ^ză(EA n4ΖJq#&fxe8v-R^]~D֣ff9H+$`|;5#G&qQkD&/Hl^A9N #IE>/v@HiWrz;ϞUЪSzO~;f0}*5<`r|v/LNQGv>ge"VB:IeY=(0۬hTJɽjHdsU@Ε1y-q/E/X垂D;ݾSΖxLG-v/#=* R?qc_.# |$[z-90 siIa2{+PX fsJeUFT|U;i+æ?[YFؚPtBUBB״rBq%Vϙե94O/R[2Tה{5C`L9׈06v{YTb{zmڶƚ$7rMqC-.~i'7gV^'? +I,M5ɗS{,HM&³vZ֔*O38B+f> 6cmXb#R yFPKi~3ȧ'boKEG,bKkd_wmfQ9fP,Zw՘tN4Vg^ZInçϠ ஸ.Mq%aSyHEUV"H0+=5O6 ǻyMwnZy.} 7r 'Kw?zRkfk^a;碚`Ps9e?!BFz+`|󥋩 rz8NgSb}vA =sKX#c _/8UˏE&}7}iaR&%E; [hDA3Clqð8:A6ba:#a< m?sԲg'g\]7;b"p;tk<{sMј )VK%q CM޺ág9CHmMA'䨏DMŵcS%TRP+qpN-]yG5ۥ sۏ+zz؊HZ^$#2ym_&ePy[o Ÿ^F)l.b0A'.T˙B΢RxrD"Ə@OMљV!-$~Hlލqy!K MkFQ7j3ģ\!=HS&S+R= &{L+8l#H&="kU}R4RNV@B~إk(F\?ZV,'P,,6?Ut؍#"q`!E:r*w!rɖ]GB̠a=%2hO udDshǠwiO*]cF"21 $Ds~ڿ1yh-c7@J"g˥v=;- a6@],TNQɌG2NMAVQ)|C146Ww+_Q ^WZIOL9Fv J8S9=x.,E^ Z5vH bb EQD.^ 2h>9wY?M@)y[8O( @]<_񿭴f7Opa%%I\Bi(`Tc+k5Tjy1tʝrdDFڼv+ƾ <,AlKFB@:&fةk 7x&*an23 0&i@G*`.Mn E&-4gWĢ7f Nh ۺ~w34G"}#nČb)/YJVd==Q?w®A ՄE'7dXֽ) 3IUuMfPp=0Y-CHoa7bspxC-‹ªLY[ k18"hx1lVKYueo[aJ8B *: XQN!oe![{K ϸ macsX:93SdN?u/j 4*uIƫ7|OPxBEe)3" Aqi-i%dz#+mD(hǨ[iw'35k2u S({"P#g΂-P^f.a8Ah58§tio;k;F~}96:s4RF hcrgXuv%"&IWS5Bbj FWGs4O7QO9]Ǯ,* ;j\+ϛ t.'rGo%hJ^Nn_0cNszyt`bA(M=o?[,e}!|L'0L9 O9Hcl3IVAqγ)< u %JƪpavYa|E͓*;r'D„_.${jk)iɑc#s]-%1 {#Czo)_Tz@%#@[_buf.i˝7+ZXxğRe(+/Ґh}b˭ׁy^~VXd*kZ|V}/6Nq$wQlg5R/LE#čP] pvtyL7"X+x "&$aK24rpG31®O7eu:^=|r #_ED[gL%MoNQ= ]#id2'Bl͇|s1A{?*Ue@GDVLk!SMF kXy6ދ|W φ p 3M+nD9?@2ѐh':u%OsTP #W=xvɪ/f.L`6pN {ƍXdhʮT nr a.cms[vjpFc #w3~ͮ9*^mr*ϦdeKk]%J)Dw(@V !*gFP^Xّv|i!&Kzy/]rBnރ@qF Ku#Їn!Kacf|[тM[4 j=t&q=ΘBMË2Ğ%ȇ9Gdst/|e`cyh̟Ag#5]19su:*b^ v+昄s > 1 "4f2,jGmDyOj(WψSVa9"sL(w gtYbS@.VVozAEz7}cH;z!ѭ,:5/Ӎ#ۋ["iy,i2E? U>}' NCYA u>A]el̈ԙ|!C 2B^f3if>; Uv痝=jtB7 82tAn3we("պ+4I.W)߳o߲#?>xD!?\EP"kLIs(${uig?. yaЀԷ;/lA&"AږBIW  o\f%7jDk-b_/j'C.6OZpk62w SEcPDZU|< 8BDnG~dwν3ᆟs'*kvN@vUo%5(pp2m&~)9vB,#I2g'F:iyʀ瑁*ױ`7Tʂ; P)H@vGjJ%1I! cvB@Y21ުy2tR>RsPd#AU uމ9jk9:}tY]/-u]/Hd?Qz 4;VbNFf\63 }dLi39ŸL|Q( Zq&E_d?^,-$ҵ >2W>R :1Ϊ{˼fyaub&.JښpUq3 >SGYШQύJ*綏SPE=.O~߃9K$"%VFm݈8] m+Z0qܭ _)=9bFP#d` דy-G4x"8Z_TD~{kN1gNm Ӈ 9o "MKJrXF1&e_"ڿW|JDeS;d,pEovQ4ʇؼ-M:6C.4qI $Gm.ia*X lN|O 4G]tME\14[~+ǺQĖ9|u?\_@C+LG6+>W¡ٔ<3Yג /s]@^D<-Ȣu.֨Q@ ݣ!v'9CAX)UtP%c]zL4Xά<,T,GV8wPؓBʅsH 0rI#-ê]-qh0|(i/ dil `YؽMWmW DTP ,[>l͎Xs$F^AʌcBdMR Sɵ0u;5bxf `5 Gv*/lGZLcZ( ve֞R!šd>I "EVv+vu7ߟ"Sftw{QAtIel0OO퐁ս,K8,bd2>9U5 1,#__ZB4eBFBV vT* ~v!y$#jXJU!ˍwkyZN ~0Ykձ mcn_yx+{6<Xg'߷Ҙw)2uq~]&p-ǛU)Ve.P8̴iLěGfS:,tϗ's̢mt :OP ̚:= 6ϝ,M픐fMڞV ~*RWDnW՞:z>چœ(ҏ_zMJrfOg ;7] ԡQxÅg鶁tc)ӽФu!7Ec Mo %;(dYsH kPC7^(G*O5V &U"wȥ򩔎쩉 |򊩅]=~֮q˰[ь1~lDa⸷snHr72$v3 5`$k*q&mj1-=G>Km `(M5IV]gyc`wA pt-)R)$?5qUgӓ~mv`MD!j#=tY~OC3۹D0f/1{u=l:P 2v0X4U\ b`,Sۛc/@Ha ݶec ګt&B5PƏU]*ykN{-HVHҀ}0"q~nJͅF6 |!k\G\ U2Qݐ'>.Fl(4ĶjTiъ/:5 iXdf܈%kz䅔5ΈWRR<թ4^ةOpQ6ȦmZ4=prIP1 *! `ҿ";2(Jp3IB˩˛HRu{PQ+!֝dCKEC_ EPq)ܜNr:=JbD\V> B2VOzHrESR`bLIZ)1@sN Ko=~+vvƓ˪l~ݍ3o^u3MÍg4y(}Ib D_C&acȬz30nSBr8.ne>uuiiϓreY[= BP4h@œuFrLcA$w\pPqmV-!!d[7_9+BoIJByOт 6qrI;Kƺ_2ݒd_GWЖh+T6rV8ΐґGbAh~[VCn:jh-bba2xe}W4è}$:od. )C_+;:Ĭ4]W,.L-| ۏݏ(>y6YJ+q(nvF4>n҇2/eh`z L& TzC_ҾX@f {㐻-BT~tLsZ ^*KHZGNZW%ש1^]1x'9`?>9)=: Bhhf[IouS-h3/Ż[s(ɢO4KUT!a%ZnN =~ٮ=wfw7sNLaFr8`,mt }ej2ϗ!Cy70S ^I׶P07]EZŒsγu71]Miq#xqibsX-A̯H(eDE/д\-˲(# Gwۧ4z%f3}H1e̽w8v ^bۆ:Q9zs\i/f!j9LH7NanzrQ%^Q*g!c{bmXpʭl!0h7I^<k2`!Z Qy1 d@ %?9?+ЍXޓg+iK$˲V=L.z)S0.PJ!]&dH4V<9y,Am!ڊxaNRony=;UD} h}5lx L(m'z%6ZFJRVߞҝSo܉tN"p|Z IEkaEsQאy31|R!FC}sH>0Gz&%OXVg' ҜsL>=K-)0PKv7 #M6t\uA uN[EUkZ52xI:pc~Ypm\e琉ZzÑDHyyaeoc`O2U "JIs4 W?z(JT`o[ix]7 ىS&SWEln[Wgd7P,4mpX|Kѱȑ]W$D$& /"2X k%o{k= xH>EmT[eqB K~ܲFwEЅ:Nd22=v$ARVL$}Dzʮq(nD!qiAaxJ(̉YF[7ik~ORRnO3y\!ohI N m-IG?*E_Y*Mڹ ^$p+񃩅fH\a=mR E/9@(8 ?4Vr&G"V\>T&|6[0X{'ͻKm)Y!3jlfB LQLvI檘]:AMI}H(\oJqE31.L e|eYU/_Kfk fxxA_4uB>jTu#V]w{aO` e K%*;TҴ2Sg{Mh3A$baM-?W.`hT,] =!@>?69/Xeb.:3n@́+/(D$]PE!=*/9 2ik)VFy|-QHb6#4 `4f0V'f#ԆeGEUjȨPg$u뙟-ŊpM{MĽ8>2ʘoAob{^N˃0l=z?_ߟ r\=t5"l8doxŒ@d[ñv6&Wn\!0Ҡ_tkA4Ǽ\_v藜c>EƩ{*Ϫ#މ8uhG%J0.5xMȳH0Q;̚sx򄯨p]!\p{yY hwėCFcZr#M0s^>Bc^~Θj4K:5Z]~Ҹqtuk~3;W?6z\!|B:xmNt {FKus﷕D  ]hhN۠{[\ϣ6G5W ~VgjdgfNϷr$p6N\K({Z?j9|9Yt䒋M>:)y)Y#ћQԽR@v(lܚXä$M9*w 攦z6`QT- ?Č))e"m/? e+Tc!ՑgBTϥ -g!{.-MwӦDi>DE1֪5H ϞufS0 nvyDv`W@]45pIaQ2; T*tDM3`FYZBt-]9p6) <)%gjɋB)h:X:8*p q)kǗZ)hv_6:j*rNRyMXum \8$gyB̺e:}5* ;eSʤ}ro mnz2Sk7g5i/mgN'*=BLS {\+4>Cגb| 4(,%p*)bܶ25dz@>GU[N$عBxK΍cq9G WmcC@Cz>@Oșc+ yq隺W q]5n9!@|T C(H k$chT`(3u)/[Ps-]~%$o^4z4"T_01֡F  7E"]5"v6v&)&W@ Vy @yG)+@3vd3 6kOܜFr!*Ũ .|➫(#m Ȥ|h'6f:,[ U~!L0I 8C8zVwMgkMvV"%#XGF9@=E%I@S ż&PYƛxɻaIa/|a5Qs)7\#|v!;\ЁlBݯis7}韶9| '0Anl]K}Cdr/]V ,x?2㥈vߡNbyQ ' FXXN?&34Ӥ21%nKB|AnY1$묱.`(͝F.yW mxKNz }E;||>c,7f'adtWE>C5N5dߟ*3?8ESR%ow|{8o}[fL#k4F31Aiv\ii{d^L҉ܴ& Ռ|, W&pBD7F&A{՘YG:xY`zX'\ut|#}.Ȧ:TZ ]n|7A2jy*)2ǀ4̾8[ki0hHfq4+Ks׮<(~'z 搙B# ɅސVuVFsTc)YK'+A MBOty)O< M:?bf@<90LvPLr6M"ìE`!Ex#(F4Zdܓ_C^@C @p೛94ژ)؜z^dNKRU彟7T/OtI@dFuΤ9\x@ÐomdHb$%u̅XALM/$䴚iM%7B<9A%yK4>_>koQ1:S-g%j[p[fy莚k?٪d`8] $JdxЩ\cAuK~ǫ9bV#ײr{(oDF _Wm{j'p-y(I&+;O2_! /V1k#*V1dlTL "v׷1F5Rۡ69JQeUL[O>w߂fJ,oB=`mH3<>* ^9 Ӕ4Q97M#.j⺙1ڂ!SGNjQs&egO, W߭Ŕ5xo9}mwq[{1d .b"aAkVpmcBNOx˯fF%)` K̫~ˎyYZyH7ٞtMXݡ6]Chk>t̆3XQNI^?X8O~r]ˈ,|Fw#4,?ĖйWS״vV—g::Ya4EYkC`ߘ ́!CGqvƝEl5\4^i O-c }=V᠜5Q4%Ҕ/ȣ2[iп]z/ w!ai 'L;'֗";YJ_LKjKܲ[bSYvU~0nVW4Ox Y9rSb~&2qk=t <#NspRg2R$PVMDUtMn(*B+Bذ׷4_F t\.3 a2 e'J1H* eNRᰭhPMSkAp^/L+i)oAS9~C]" wY .dܿ;_';NLR 7/D;HuT5}p=PZO4Mͥ46OL YN|$kIZx쥕BY6qKG s*yDӊ"Ŋ**{MZl4 YG&]YDj>M=rh:jPRoGmdĦ} UR|-{:tzm>b iG?StS㗈_Kx<4#Y{?W,oy^WxD< 4NSvaQcQdJzffAҼTCcXÈ[Zl N/1ߢs4T孠W;fե(IbKFp‹s]wAcHU7;,1;>E {s~|A(p=P|"b !yZ=UGgAw3ؠDcd[roŤt$ ?2a8~v$t*%AT%5;ϰA0F s9ƿ"#|U9L`\d[Q"3,!Ao *QxvYlr A)rlZFitFa }5e )wYåtA&a$p_ r^ʗk4JMӏQ(ˏmW7?h MFlUYte$$';\J`&>{WnȪ<7 ]d-:že`b0'/J¿0/V12:Ӱ~Αu@˹!Bowl͵Er3:&{a3_ ps1o Wk-Yk;C2h6Ť4];6] >=A/ .K?ϵb!T5C3Rh/W"uvpckg^Zf6$))G7TKtrx9g/_j'sCռP7+ޯ1s&VMR;-<@Šex ߔ1Y2 nIܣouĽ<@2ZXSO.>{zz&h4 J&sP|hYEΞV]VzdAr@*/j)<ЃQ@m'֗)WOxb(X حn 5g!4ti8 ϯGksOT>l$"#4FḡN]D5`AdnZɒ[sl Y~2sf4vȷ9[ȶlx` T'Xtm'-"ܪx_bz95'QNsen5SB >* ;]"ta"((wmHk {S2%8N0U. |-B"tVOECwşnt.{GpM*1a1NeW[-[@&A۴}+|&mQ&O4֛77oYo/6qw cde1ƘG]#FnvC:"ֲ y]Yy +wO q?AϪ_naCl D0$u-`PXF*l2OM< 9zP͐Z+5Fۿ 58ؠcqY}Bȧ5tC Cu~=0`CDZI$ ^mL-^(C^*?xbSguvH:}3%=&CraEmxӰڶ鳯TYQ*Ev·@nN4?6me9n'? rBdePu\9`URyR#s;օԭڰօu㊻oт?.U+AR]D7T2)͍T:mxw2,VFIyr_ȱU@ZϦ,@l+A9s-}5ҐaNBToH/͘3NF^ћ.)_܎yM> < B'[p**pI\ 㨽H:GQQDRű]`AɹpRL{'usTp G 8NدwҪ,g%H뙨yE+6L&@=2ްWB-7SP!%@Lއ>*ک/K+rvf],|&9jK̳T67TTIyؠ +;kf3U`m7`̽oڀT NnX _uOEI/ XDdH]_/|nL".4f>CЖq{LGtIw>agw5K']10`:gQqgXlC/xhzpA8(~Wr2>G9fyDf_E^<(XIәiD'|~9C[N Aᮽ6v|`.͎y/b v%$SqmylR6\fQ8))$s n[_RU},[Ml7ʡ?!}D 5cy dnLT\Q<3zyD mCo>AdzA ,F4`~+ ShíCMKJĒD9Jϵ/6旊imvO<,0T@̌r#){jKnd9Na6) 0t~SRB7X7o㈿np@qoRgBQ3C3`=ؗ_іw;?h-q\j*C\ ș,80+Uci!-6N@¼݉40>s{ Ĉ7 7n|r֯8n6HL#nvf:19HF^4N 9\.iBGd!u u3R/V/lKIE&,6)Pvܵ~<摝@vj,=$* O]7Մ$qp*|3 *| ;' $vL+Ucz(xD:}v"T8@O)zû;VKfͻ2))!W1 m؎A{ 6fYZ5Ԝ"Pkv/Iy2:Ċ/kˢuifBR~ꖅl˽zma/oI p nX!Ws)'|*r ? czp|-kS*lMxu Ŏ0V֫Uy1PMN&jQ_46_Y\hN{͸*'.z 8ߵu,C!c.o␐9?eZK198FłM/Fg3m}<|%( #u1L][mHj ffVyH/,yt:jk!Ƃ"|zbUT, a{v_lC>=u׸h,NU"s֠aBBM# UuqlN[b͎,(inT OP!x**|yж}WX'an~|,%Ib1Qh9}ty +BieTV Ƽ&GӁͽ |(b7~rZz2'!cn`E( ee9hEH0V8)CP#U#>{.aٻPԸGC;49 $kW#E cNIᡒĽpq:1}Ѻ _1bno{NzR:ex\j%dfIK䩠FH~ V%9G̈~|/_ gfm}g)Ng}%ɉW6`0`zьsq-:ޤ9a kwl`ܼRW~;Oǽ) | Ak:kD4k0__c' *ڳ}Ƅ#\9O&9WBt0 3{JM6aL/$hr(p-0 AkMݧMH8y-%7Kʒ= <¶.Z=I|eF-OK:{3ĆH ZP n5܅!ţ5b|v/,3a+].z!oĊKoڳ,՞X5M N|ӯ|It4LJxñx :X/0^_OV;Ff]R;nFA)P,Gyf.6IO Fভ &%j$k'kfm'w\~;T#jH$!6Jy.0]cG4O+]'?Hmk2J@98s Tg^sJVŮ]F%a37C!04}j $hay+̓\wYu; M|>Shr$7\:&;#~LY0ahUfWlͺ:128؞l*X ,Ws~"fsyW #r~4X ~-*%W"кYvd;{H= ߭~ G.>iS!U_\&z90sKpVCt@>tbqo,GӷfGmrY"aK^+W!oKT(J7ߘbcRCZILh1Oo}I OVFw{E-`~N:q `3scgPm%dE%P-VI&qB޹Esg~*Zbk}%/ G0bч1*Dqڻ~dc\6NpH(]Kz]XC^{MNwcf/9sH(iLq_[؎\S8C-1jV37 &șhѿp~vD5CPؓ%.j^; R#6yH/ =m9MWc^ 43%˘t3Sg|ISOrc_s˄!w[?72Ҁ6 7#/܈1|LʋBopPBXfٚ-UE_0ÃIVý۞_S#W`Y`>sG^GucoWnЅ?-=#GW塚*f; Q-^@4PeՎ d1wb&Pubso ZJ|^XCg;ZU__NjbGcebܕF,VXN,=_]/Ah,Eռ3I dʇ5id]`%P?ƐDhɦXZNeԋU rmVG#zuBd[ɚ91Qs丘q=߾H珒o}8!K8ge7)0[>W$}cCPo*R[\Ş0X7^!urg (=8sS]!6rCV%ȂTL͞jc0}af 5kZL0R4/Ae_s|WOHlvkCcg`a0衇D~p U>edp2&P׉9 nb**1i#8#Oix<5 C/@( ڛm낲SWxL [k!pIghTM#_ߤԫvcr?(cczi#[}ڙ:[MHi^֏@"s$M g&2eex/Ol%>Fxii ?sWsE{,5t깉uP"P%[(oi2zБ,٫\h)] O(53%4p&xA2UIe 1w)5\8`2 (Z] =X B&dzO2i%ɑ=UxEsWy=Z!R> ]IG-bGǝ1o K9-,qBm)J^X"QvspNW]ݘH\-\Q͠{q)X[A_D?gݯ{)#YWW3&9_ӯCe7Rq3w^?MH2WD?zt9lV %xF;P6:p{@q7&G+2s}&1XGl$!BeXb֢|m}uq91[nH;)Lb3|xVVd'8%3|9ߍx`OW{w."xd{E`Lb({dZ/tZ-"ETK4CPĄAaf"v IyB -i^6T<"v2^fw5gpVHk^p{#١o0tw=hV??hhӨy$, 8kX1݅[-,3l4 0UQWM{3 Hwf0F'DB eW>k;|];&=IcwbLYJX ߫&Ul<N1zْ]xqAN<:BUA3s(Z}BCZ7+Bd?QØUra#Uctfvl_&R_K7KX1[݅=ͳ#S$|̓˲ N- Bg.é5&] gfPzHv\luS@8-S_`si _$ DZSqeк( |Ch+ؓ^U"pM7%FQo0̳, AX{>ѝEk[T:C:jU-2.{u<V#֣L 0YSZH`Q*ѯ?>]x{wgP-^Y9sQwh*",LG?yF.; /j1"8y@հl,>E!-)G3ŭ&-eu' рڊWj!7:CJ*>`(2EV)c#5/ϭ#TP ^w5Oǹ{&?njlU7t冀D Vt&y`k^ ii^ 6MAnw$ \y}B A[G9Y('R$%n %~)}_xgfƒh̥`CIk9\ $3\͆7:ܝ6©=Jr.IƕJ= QmC③*Md zިzi$;aab&^zPѿ4a^=06tוl \&D  CDw8/A׾/% @<9-.J,tn18_KƖg6,iJ-V*bnۯOf1`] oJ': a{I! /_mĊC31xDJrfq7"JjP/EM?˺#'O#NP|:N(L :^Á\ n:& Z+|ہ =`yi a^Fy^ ̏ھw 'DR@W?$iѽg,dn=߷)@~N 1S<' l vY' 4[Vٱ3;L!'v8cǞK _d*ğٶI&m$ݑ:[,լ:Umd[WciWe^i+LuӋKFxPzّs9s_ER9ş-u1 ygxVeC.nd7Vΰ-&KBe,} nHrWgk VDO86>_oM{kd50$U6ǰ爳k4wƋ:K-.;N+mH(g&##YKGSDARJ =QN ;MIx4I]TT3NffiT00f/4,nN/jY]-'<0ܞ,)Fv(C|lpJnX5Yno^טkC(0aK9.iiK fFFdb.B%؞"^b7jlr.WQen k$,_$.?{?Pֻ2AFlGc (|jNՔnqR|;c+5ˎRJ'l.j!Hv90 Tu[c5,;n|J^ @G HԷdַ3 <=< '2"rߡi_ `A':X &\i.V2_U4 \RW #vܻGhE9tJfLѮ+g`u`'ǼH]^gL+¼WUo!G~m9PA2C#aBoP9>rE4Q~]5gOfj{ntYpeEQafʉk~F_&˩q҈.'ԏҽU*)'a}kX;鷷rz %̘8<$)۾=xu5J0ty8|g!{:/ׂrŴqKw18u3 e&Hgu[YӂlV ne5:Zu6>kZD P>wwuFȼqn4Ŧ8!`8 |CDpG7_?jI+Gv,4NQ3SK ua FBU11r}7E>RGOhXEWS!^wC@*Fuj >Ow$ɟq9WE+?Gյ@@7Qa(}h,8DVSGȥ<#Sn1FK[qg7GgՇŦ <լؕ@&˂b[TCj] <8 Tv_a{Mc8wn\Xr$#Z-dfHWn2|{*}Ãq=.`U]44R"ϓB##W`0Ui{0fDx53ZBlU0L'/CQܯT|\bfVEM.w0qMml(6 i97ec&*0?\> c1{Bge/ R3M_ۑOMgtEMvǃJY9!1 s7D;jkxd΁gj>Ԁ^D>1F[š>&uvA`t뉡-} E<X_W0@&X洁E{!(moyܟV283"TFwlY+O@H|7+ݲy}>iOE'\P˅Smw݀$`s.B}V;N|*bpp,`N؞݊t5 5!I򲢩o_~z վ"5'.&3#OdE.t,% Nh=yGIvc[ Db 'Ɂ]K ZҜƠ Ɛ1UjGs!-,0FD=|.ysL#@JΠS`{^S!C0?бڭe>^-bش!k<ЗNBsH i tfOrf,3;ND__kY-?!(e:PkkJԥ+yYX@7-'0"G߆' E$#J\ޡڷg3.rxNbFF=?(0ڒfׄ=1EϥDK8j8Pr.aƞ{j6ATz g y<a; `3g :?|).Avt1Ur?rq_NȕRفQ<)Y?M;?Fp0T?B5Ia 9@0a Vm9}Okn;xmVS|~> 8/JI_1oS(Tx| ܳl95"/ 6Xb"چz_D٤^ܕdf皻}b臮F[5|NK>xU_1icX,$)Kgk12X77ehJ 5!(p ֊M>mH $kW6 vhܓM"J]knٕDi2Id]{xFoK\wvh O87充?`pk`_ӝTr٤ωŠW TQZ3`}%]ddV=*s5YU5coVQ>d}xA5:sޒ4x]2?DGo42>st,N\Sq7KӋ9NScٷˊ@C )NҩԇËSFECnJJe+Ĺjo "> Tzf/\#Bi> dBi(0ml os.I )qYU^JeN;`5֒f=~JM_ rҘ`f`Ϯu5 S}pn ٽ{ޅwRve6 iYd;˜%%훙ُS[ZT6W iפBGJux Dt >fȓP^x#oŢ-W儁k?o> Z .iC ,5/';7 v7z% "*͔pC';s_9.Ƞ Bk-fFgo)-ȍ$׋#$ލi*IthXp RlT O;(ReRoV. O ¬ Ƽ W@N+mkx4&IS ZݷЕ5eG@sf5/ e 6e2c-ݘjsJԝͯPKyIٔA W}>q NËZZ7O#9Z3iu_=оM),rt$4QI%$-$Cfֵjkֿ<<onʿ/4LWfu0q_r0@ S6y|8q}}l A ~lahzE.Y" yFx!~xkE=B{uWY9I4Vy g,T0ܾO=\޶ YZ