§
    ¥”jÄE  ã                   ó@  — d Z ddlZddlZddlZddlmZ ddlmZmZm	Z	m
Z
mZmZ ddlmZmZmZmZ ddlmZ ddlmZmZ ddlmZ dd	lmZ dd
lmZmZmZmZm Z  ddl!m"Z" ddl#m$Z$ ddl%m&Z& g d¢Z' ej(        e)¦  «        Z* G d„ de+¦  «        Z, G d„ de,¦  «        Z- G d„ de,¦  «        Z.d„ Z/ G d„ de0¦  «        Z1 G d„ de+¦  «        Z2de
eej3                          de4fd„Z5de
eej3                          de4fd„Z6de
eej3                          de4fd„Z7dej8        d ej9        fd!„Z:	 d>dej8        d ej;        fd#„Z<dej8        d$eej=        ej>        f         fd%„Z?d&eej@        ejA        f         dej8        d eBfd'„ZC G d(„ d)e$¦  «        ZD G d*„ d+eD¦  «        ZEd,ed e4fd-„ZFdej8        d.e4d ejG        fd/„ZH ed0¬1¦  «         G d2„ d3¦  «        ¦   «         ZId4ejJ        fd5„ZKd6„ ZLd7ejM        d ejN        fd8„ZOd7ejM        d eIfd9„ZPe"jQ        fd:ed;eeR         d<e4d eeReSf         fd=„ZTdS )?a  
General tools related to Cryptographic Message Syntax (CMS) signatures,
not necessarily to the extent implemented in the PDF specification.

CMS is defined in :rfc:`5652`. To parse CMS messages, pyHanko relies heavily on
`asn1crypto <https://github.com/wbond/asn1crypto>`_.
é    N)Ú	dataclass)ÚIOÚIterableÚListÚOptionalÚTupleÚUnion)ÚalgosÚcmsÚtspÚx509)ÚSignedDigestAlgorithm)ÚhashesÚserialization)Úpadding)ÚRSAPublicKey)Úload_cert_from_pemderÚload_certs_from_pemderÚload_certs_from_pemder_dataÚload_private_key_from_pemderÚ!load_private_key_from_pemder_data)Úmisc)ÚFormFillingError)Úget_pyca_cryptography_hash)ÚCMSExtractionErrorÚCMSStructuralErrorÚMultivaluedAttributeErrorÚNonexistentAttributeErrorÚSignedDataCertsÚSigningErrorÚUnacceptableSignerErrorÚValueErrorWithMessageÚas_signing_certificateÚas_signing_certificate_v2Úbyte_range_digestÚcheck_ess_certidÚextract_certificate_infoÚextract_signer_infoÚfind_cms_attributeÚfind_cms_attribute_iterÚfind_unique_cms_attributeÚget_cms_hash_algo_for_mechanismr   r   r   r   r   Úmatch_issuer_serialÚoptimal_pss_paramsÚsimple_cms_attributec                   ó"   ‡ — e Zd ZdZˆ fd„Zˆ xZS )r"   z¦
    Value error with a failure message attribute that can be conveniently
    extracted, instead of having to rely on extracting exception args
    generically.
    c                 ór   •— t          |¦  «        | _        t          ¦   «                              |¦  «         d S ©N)ÚstrÚfailure_messageÚsuperÚ__init__)Úselfr4   Ú	__class__s     €úc/var/www/finuniver-perm.ru/html/portfolio/venv/lib/python3.11/site-packages/pyhanko/sign/general.pyr6   zValueErrorWithMessage.__init__G   s1   ø€ Ý" ?Ñ3Ô3ˆÔÝ‰Œ×Ò˜Ñ)Ô)Ð)Ð)Ð)ó    )Ú__name__Ú
__module__Ú__qualname__Ú__doc__r6   Ú__classcell__)r8   s   @r9   r"   r"   @   sB   ø€ € € € € ðð ð*ð *ð *ð *ð *ð *ð *ð *ð *r:   r"   c                   ó   — e Zd ZdZdS )r   z!Structural error in a CMS object.N©r;   r<   r=   r>   © r:   r9   r   r   L   s   € € € € € Ø+Ð+Ð+Ð+r:   r   c                   ó   — e Zd ZdS )r   N©r;   r<   r=   rB   r:   r9   r   r   P   ó   € € € € € Ø€Dr:   r   c                 óV   — t          j        t          j        | ¦  «        |fdœ¦  «        S )a  
    Convenience method to quickly construct a CMS attribute object with
    one value.

    :param attr_type:
        The attribute type, as a string or OID.
    :param value:
        The value.
    :return:
        A :class:`.cms.CMSAttribute` object.
    )ÚtypeÚvalues)r   ÚCMSAttributeÚCMSAttributeType)Ú	attr_typeÚvalues     r9   r/   r/   T   s1   € õ ÔÝÔ% iÑ0Ô0¸U¸HÐEÐEñô ð r:   c                   ó   — e Zd ZdS )r   NrD   rB   r:   r9   r   r   e   rE   r:   r   c                   ó   — e Zd ZdS )r   NrD   rB   r:   r9   r   r   i   rE   r:   r   ÚattrsÚnamec                 óž   — t          j        dt          ¦  «         t          t	          | |¦  «        ¦  «        }|r|S t          d|› d�¦  «        ‚)aÕ  
    .. deprecated:: 0.35.0

    Find and return CMS attribute values of a given type.

    :param attrs:
        The :class:`.cms.CMSAttributes` object.
    :param name:
        The attribute type as a string (as defined in ``asn1crypto``).
    :return:
        The values associated with the requested type, if present.
    :raise NonexistentAttributeError:
        Raised when no such type entry could be found in the
        :class:`.cms.CMSAttributes` object.
    z/Deprecated in favour of find_cms_attribute_iterúUnable to locate attribute ú.)ÚwarningsÚwarnÚDeprecationWarningÚlistr*   r   )rO   rP   Úfound_valuess      r9   r)   r)   m   sa   € õ" „MØ9Ýñô ð õ
 Õ/°°tÑ<Ô<Ñ=Ô=€LØð OØÐå'Ð(MÀdÐ(MÐ(MÐ(MÑNÔNÐNr:   c              #   óZ   K  — | r$| D ]#}|d         j         |k    r|d         E d{V —† Œ"dS dS )aÝ  
    .. versionadded:: 0.35.0

    Find and return CMS attribute values of a given type in a generator.

    .. note::
        This function will return an empty generator rather than throwing
        :class:`.NonexistentAttributeError`.

    :param attrs:
        The :class:`.cms.CMSAttributes` object.
    :param name:
        The attribute type as a string (as defined in ``asn1crypto``).
    :return:
        The values associated with the requested type, if present.
    rG   rH   N)Únative)rO   rP   Úattrs      r9   r*   r*   Š   sb   è è € ð& ð *Øð 	*ð 	*ˆDØ�FŒ|Ô" dÒ*Ð*Ø œ>Ð)Ð)Ð)Ð)Ð)Ð)Ð)øð*ð *ð	*ð 	*r:   c                 óð   — t          | |¦  «        }	 t          |¦  «        }n!# t          $ r t          d|› d�¦  «        ‚w xY w	 t          |¦  «         t	          d|› d�¦  «        ‚# t          $ r |cY S w xY w)a   
    Find and return a unique CMS attribute value of a given type.

    :param attrs:
        The :class:`.cms.CMSAttributes` object.
    :param name:
        The attribute type as a string (as defined in ``asn1crypto``).
    :return:
        The value associated with the requested type, if present.
    :raise NonexistentAttributeError:
        Raised when no such type entry could be found in the
        :class:`.cms.CMSAttributes` object.
    :raise MultivaluedAttributeError:
        Raised when the attribute's cardinality is not 1.
    rR   rS   zExpected single-valued z attribute, but found multiple)r*   ÚnextÚStopIterationr   r   )rO   rP   ÚgenÚresults       r9   r+   r+   £   sµ   € õ& " %¨Ñ
.Ô
.€CðOÝ�c‘”ˆˆøÝð Oð Oð OÝ'Ð(MÀdÐ(MÐ(MÐ(MÑNÔNÐNðOøøøðÝˆS‰	Œ	ˆ	Ý'ØJ dÐJÐJÐJñ
ô 
ð 	
øõ ð ð ð Øˆˆˆðøøøs   ’" ¢A Á"A& Á&A5Á4A5ÚcertÚreturnc           
      ó  — t          j        dt          j        t          j        |                      ¦   «         ¦  «                             ¦   «         t          j        d| j	        i¦  «        g| d         d         dœdœ¦  «        gi¦  «        S )a  
    Format an ASN.1 ``SigningCertificate`` object, where the certificate
    is identified by its SHA-1 digest.

    :param cert:
        An X.509 certificate.
    :return:
        A :class:`tsp.SigningCertificate` object referring to the original
        certificate.
    ÚcertsÚdirectory_nameÚtbs_certificateÚserial_number©Úissuerrg   )Ú	cert_hashÚissuer_serial)
r   ÚSigningCertificateÚ	ESSCertIDÚhashlibÚsha1ÚdumpÚdigestr   ÚGeneralNameri   )ra   s    r9   r#   r#   Å   sž   € õ Ô!àÝ”å%,¤\°$·)²)±+´+Ñ%>Ô%>×%EÒ%EÑ%GÔ%Gõ !%Ô 0Ø%5°t´{Ð$Cñ!"ô !"ð'ð
 .2Ð2CÔ-DØ /ô.ð	*ð 	*ðð ñô ðð	
ñô ð r:   Úsha256c                 ón  — t          |¦  «        }t          j        |¦  «        }|                     |                      ¦   «         ¦  «         |                     ¦   «         }t          j        dt          j        d|i|t          j
        d| j        i¦  «        g| d         d         dœdœ¦  «        gi¦  «        S )aŒ  
    Format an ASN.1 ``SigningCertificateV2`` value, where the certificate
    is identified by the hash algorithm specified.

    :param cert:
        An X.509 certificate.
    :param hash_algo:
        Hash algorithm to use to digest the certificate.
        Default is SHA-256.
    :return:
        A :class:`tsp.SigningCertificateV2` object referring to the original
        certificate.
    rd   Ú	algorithmre   rf   rg   rh   )Úhash_algorithmrj   rk   )r   r   ÚHashÚupdaterp   Úfinalizer   ÚSigningCertificateV2ÚESSCertIDv2r   rr   ri   )ra   Ú	hash_algoÚ	hash_specÚmdÚdigest_values        r9   r$   r$   è   sË   € õ$ +¨9Ñ5Ô5€IÝ	Œ�YÑ	Ô	€BØ‡I‚Iˆd�iŠi‰kŒkÑÔÐØ—;’;‘=”=€LÝÔ#àÝ”à+6¸	Ð*BØ%1õ !%Ô 0Ø%5°t´{Ð$Cñ!"ô !"ð'ð
 .2Ð2CÔ-DØ /ô.ð	*ð 	*ðð ñô ðð	
ñô ð r:   Úcertidc                 ó~  — t          |t          j        ¦  «        rd}n|d         d         j        }t	          |¦  «        }t          j        |¦  «        }|                     |                      ¦   «         ¦  «         | 	                    ¦   «         }|d         j        }||k    rdS |d         }| pt          || ¦  «        S )a  
    Match an ``ESSCertID`` value against a certificate.

    :param cert:
        The certificate to match against.
    :param certid:
        The ``ESSCertID`` value.
    :return:
        ``True`` if the ``ESSCertID`` matches the certificate,
        ``False`` otherwise.
    ro   rv   ru   rj   Frk   )Ú
isinstancer   rm   rZ   r   r   rw   rx   rp   ry   r-   )ra   r€   r|   r}   r~   r   Úexpected_digest_valueÚexpected_issuer_serials           r9   r&   r&     sÂ   € õ �&�#œ-Ñ(Ô(ð AØˆ	ˆ	àÐ+Ô,¨[Ô9Ô@ˆ	å*¨9Ñ5Ô5€IÝ	Œ�YÑ	Ô	€BØ‡I‚Iˆd�iŠi‰kŒkÑÔÐØ—;’;‘=”=€LØ" ;Ô/Ô6ÐØÐ,Ò,Ð,ØˆuØ/5°oÔ/FÐØ%Ð%ð Õ)<Ø ñ*ô *ð r:   r„   c                 ó€  — |d         d         }| d         }t          |t          j        ¦  «        r3t          |¦  «        dk    s|d         j        dk    rdS |d         j        }	 |                     ¦   «         |j                             ¦   «         k    p
||j        k    }n# t          $ r d}Y nw xY w|o| d         |k    S )a~  
    Match the issuer and serial number of an X.509 certificate against some
    expected identifier.

    :param expected_issuer_serial:
        A certificate identifier, either :class:`cms.IssuerAndSerialNumber`
        or :class:`tsp.IssuerSerial`.
    :param cert:
        An :class:`x509.Certificate`.
    :return:
        ``True`` if there's a match, ``False`` otherwise.
    rf   rg   ri   é   r   re   F)	r‚   r   ÚGeneralNamesÚlenrP   Úchosenrp   ri   Ú
ValueError)r„   ra   Úserial_asn1Úexpected_issuerÚissuer_matchs        r9   r-   r-   6  së   € ð& Ð(Ô)¨/Ô:€KØ,¨XÔ6€Oõ �/¥4Ô#4Ñ5Ô5ð 4å�Ñ Ô  AÒ%Ð%Ø˜qÔ!Ô&Ð*:Ò:Ð:à�5Ø)¨!Ô,Ô3ˆðà× Ò Ñ"Ô" d¤k×&6Ò&6Ñ&8Ô&8Ò8ð .Ø $¤+Ò-ð 	ˆøõ ð ð ð Øˆˆˆðøøøð 	ÐOÐ/°Ô@ÀKÒOðs   Á%:B  Â B/Â.B/c                   ó   — e Zd ZdZdS )r    z1
    Error encountered while signing a file.
    NrA   rB   r:   r9   r    r    j  s   € € € € € ðð ð ð r:   r    c                   ó   — e Zd ZdZdS )r!   z=
    Error raised when a signer was judged unacceptable.
    NrA   rB   r:   r9   r!   r!   p  s   € € € € € ðð ð 	€Dr:   r!   Úmechc                 ó>   — | j         }|dk    rdS |dk    rdS | j        S )a%  
    Internal function that takes a :class:`.SignedDigestAlgorithm` instance
    and returns the name of the digest algorithm that has to be used to compute
    the ``messageDigest`` attribute.

    :param mech:
        A signature mechanism.
    :return:
        A digest algorithm name.
    Úed25519Úsha512Úed448Úshake256)Úsignature_algor|   )r�   Úsig_algos     r9   r,   r,   x  s4   € ð Ô"€HØ�9ÒÐØˆxØ	�WÒ	Ð	ØˆzàŒ~Ðr:   Údigest_algorithmc           
      óÚ  — |                      ¦   «         }t          j        | j                             ¦   «         ¦  «        }t          |t          ¦  «        st          dt          |¦  «        › �¦  «        ‚t          |¦  «        }t          j        ||¦  «        }t          j        t          j        d|i¦  «        t          j        dt          j        d|i¦  «        dœ¦  «        |dœ¦  «        S )a"  
    Figure out the optimal RSASSA-PSS parameters for a given certificate.
    The subject's public key must be an RSA key.

    :param cert:
        An RSA X.509 certificate.
    :param digest_algorithm:
        The digest algorithm to use.
    :return:
        RSASSA-PSS parameters.
    z&Expected RSA key, but got key of type ru   Úmgf1)ru   Ú
parameters)rv   Úmask_gen_algorithmÚsalt_length)Úlowerr   Úload_der_public_keyÚ
public_keyrp   r‚   r   r    rG   r   r   Úcalculate_max_pss_salt_lengthr
   ÚRSASSAPSSParamsÚDigestAlgorithmÚMaskGenAlgorithm)ra   r˜   Úkeyr~   Úoptimal_salt_lens        r9   r.   r.   �  sú   € ð (×-Ò-Ñ/Ô/Ðå
Ô
+¨D¬O×,@Ò,@Ñ,BÔ,BÑ
CÔ
C€CÝ�c�<Ñ(Ô(ð QÝÐOÅDÈÁIÄIÐOÐOÑPÔPÐPÝ	#Ð$4Ñ	5Ô	5€BåÔ<¸SÀ"ÑEÔEÐÝÔ å#Ô3ØÐ.Ð/ñô õ #(Ô"8à!'Ý"'Ô"7Ø$Ð&6Ð7ñ#ô #ðð ñ#ô #ð ,ð	
ð 	
ñô ð r:   T)Úfrozenc                   ól   — e Zd ZU dZej        ed<   	 eej                 ed<   	 eej	                 ed<   dS )r   zT
    Value type to describe certificates included in a CMS signed data payload.
    Úsigner_certÚother_certsÚattribute_certsN)
r;   r<   r=   r>   r   ÚCertificateÚ__annotations__r   r   ÚAttributeCertificateV2rB   r:   r9   r   r   ¸  sg   € € € € € € ðð ð Ô!Ð!Ð!Ñ!ðð �dÔ&Ô'Ð'Ð'Ñ'ðð ˜#Ô4Ô5Ð5Ð5Ñ5ðð r:   r   Úsidc                 ó    ‡ ‡— ‰ j         dk    rˆ fd„S ‰ j         dk    r+‰ j        j        Št                               d¦  «         ˆfd„S t
          ‚)NÚissuer_and_serial_numberc                 ó.   •— t          ‰j        | ¦  «        S r2   )r-   r‰   )Úcr¯   s    €r9   ú<lambda>z'_get_signer_predicate.<locals>.<lambda>Ð  s   ø€ Õ,¨S¬Z¸Ñ;Ô;€ r:   Úsubject_key_identifierz®The signature in this SignedData value seems to be identified by a subject key identifier --- this is legal in CMS, but many PDF viewers and SDKs do not support this feature.c                 ó   •— | j         ‰k    S r2   )Úkey_identifier)r³   Úskis    €r9   r´   z'_get_signer_predicate.<locals>.<lambda>Ú  s   ø€ ˜Ô)¨SÒ0€ r:   )rP   r‰   rZ   ÚloggerÚwarningÚNotImplementedError)r¯   r¸   s   `@r9   Ú_get_signer_predicater¼   Î  sm   øø€ Ø
„xÐ-Ò-Ð-Ø;Ð;Ð;Ð;Ð;Ø	ŒÐ-Ò	-Ð	-ð ŒjÔˆÝ�Šð<ñ	
ô 	
ð 	
ð
 1Ð0Ð0Ð0Ð0Ý
Ðr:   c                 ó®   — t          |d         ¦  «        }d }g }| D ]%} ||¦  «        r|}Œ|                     |¦  «         Œ&|€t          d¦  «        ‚||fS )Nr¯   z,signer certificate not included in signature)r¼   Úappendr   )rd   Úsigner_infoÚ	predicatera   rª   r³   s         r9   Ú_partition_certsrÁ   Þ  s|   € õ
 & k°%Ô&8Ñ9Ô9€IØ€DØ€KØð "ð "ˆØˆ9�Q‰<Œ<ð 	"ØˆDˆDà×Ò˜qÑ!Ô!Ð!Ð!Ø€|Ý Ð!OÑPÔPÐPØ�ÐÐr:   Úsigned_datac                 óV   — 	 | d         \  }|S # t           $ r t          d¦  «        ‚w xY w)a5  
    Extract the unique ``SignerInfo`` entry of a CMS signed data value, or
    throw a ``ValueError``.

    :param signed_data:
        A CMS ``SignedData`` value.
    :return:
        A CMS ``SignerInfo`` value.
    :raises ValueError:
        If the number of ``SignerInfo`` values is not exactly one.
    Úsigner_infosz-signer_infos should contain exactly one entry)rŠ   r   )rÂ   r¿   s     r9   r(   r(   ð  sI   € ð
Ø$ ^Ô4‰ˆØÐøÝð 
ð 
ð 
Ý Ø;ñ
ô 
ð 	
ð
øøøs   ‚ Ž(c                 ó@  — g }g }| d         D ]\}|j                              ¦   «         }|j        dk    r|                     |¦  «         Œ<|j        dk    r|                     |¦  «         Œ]t	          | ¦  «        }t          ||¦  «        \  }}t          |||¬¦  «        }|S )a  
    Extract and classify embedded certificates found in the ``certificates``
    field of the signed data value.

    :param signed_data:
        A CMS ``SignedData`` value.
    :return:
        A :class:`SignedDataCerts` object containing the embedded certificates.
    ÚcertificatesÚcertificateÚv2_attr_cert)r©   rª   r«   )r‰   ÚuntagrP   r¾   r(   rÁ   r   )	rÂ   rd   Ú
attr_certsr³   ra   r¿   r©   rª   Ú	cert_infos	            r9   r'   r'     s½   € ð €EØ€JØ˜Ô(ð $ð $ˆØŒx�~Š~ÑÔˆØŒ6�]Ò"Ð"Ø�LŠL˜ÑÔÐÐØŒV�~Ò%Ð%Ø×Ò˜dÑ#Ô#Ð#øÝ% kÑ2Ô2€KÝ/°°{ÑCÔCÑ€K�åØØØ"ðñ ô €Ið
 Ðr:   ÚstreamÚ
byte_rangeÚmd_algorithmc                 ó.  — t          |¦  «        }t          j        |¦  «        }d}t          |¦  «        }t	          j        |¦  «        D ]7\  }}	|                      |¦  «         t	          j        || ||	¬¦  «         ||	z  }Œ8||                     ¦   «         fS )a  
    Internal API to compute byte range digests. Potentially dangerous if used
    without due caution.

    :param stream:
        Stream over which to compute the digest. Must support seeking and
        reading.
    :param byte_range:
        The byte range, as a list of (offset, length) pairs, flattened.
    :param md_algorithm:
        The message digest algorithm to use.
    :param chunk_size:
        The I/O chunk size to use.
    :return:
        A tuple of the total digested length, and the actual digest.
    r   )Úmax_read)	r   r   rw   Ú	bytearrayr   Ú	pair_iterÚseekÚchunked_digestry   )
rÌ   rÍ   rÎ   Ú
chunk_sizeÚmd_specr~   Ú	total_lenÚ	chunk_bufÚloÚ	chunk_lens
             r9   r%   r%   "  s™   € õ, )¨Ñ6Ô6€GÝ	Œ�WÑ	Ô	€Bð
 €IÝ˜*Ñ%Ô%€IÝœ¨
Ñ3Ô3ð ð ‰ˆˆIØ�Š�B‰ŒˆÝÔ˜I v¨r¸IÐFÑFÔFÐFØ�YÑˆ	ˆ	à�b—k’k‘m”mÐ#Ð#r:   )rs   )Ur>   rn   ÚloggingrT   Údataclassesr   Útypingr   r   r   r   r   r	   Ú
asn1cryptor
   r   r   r   Úasn1crypto.algosr   Úcryptography.hazmat.primitivesr   r   Ú)cryptography.hazmat.primitives.asymmetricr   Ú-cryptography.hazmat.primitives.asymmetric.rsar   Úpyhanko.keysr   r   r   r   r   Úpyhanko.pdf_utilsr   Úpyhanko.pdf_utils.miscr   Úpyhanko_certvalidator.utilr   Ú__all__Ú	getLoggerr;   r¹   rŠ   r"   r   r   r/   ÚKeyErrorr   r   rI   r3   r)   r*   r+   r¬   rl   r#   rz   r$   rm   r{   r&   ÚIssuerAndSerialNumberÚIssuerSerialÚboolr-   r    r!   r,   r¢   r.   r   ÚSignerIdentifierr¼   rÁ   Ú
SignedDataÚ
SignerInfor(   r'   ÚDEFAULT_CHUNK_SIZEÚintÚbytesr%   rB   r:   r9   ú<module>ró      s•  ððð ð €€€Ø €€€Ø €€€Ø !Ð !Ð !Ð !Ð !Ð !Ø =Ð =Ð =Ð =Ð =Ð =Ð =Ð =Ð =Ð =Ð =Ð =Ð =Ð =Ð =Ð =à ,Ð ,Ð ,Ð ,Ð ,Ð ,Ð ,Ð ,Ð ,Ð ,Ð ,Ð ,Ø 2Ð 2Ð 2Ð 2Ð 2Ð 2Ø @Ð @Ð @Ð @Ð @Ð @Ð @Ð @Ø =Ð =Ð =Ð =Ð =Ð =Ø FÐ FÐ FÐ FÐ FÐ Fðð ð ð ð ð ð ð ð ð ð ð ð ð ð #Ð "Ð "Ð "Ð "Ð "Ø 3Ð 3Ð 3Ð 3Ð 3Ð 3Ø AÐ AÐ AÐ AÐ AÐ Aðð ð €ð< 
ˆÔ	˜8Ñ	$Ô	$€ð	*ð 	*ð 	*ð 	*ð 	*˜Jñ 	*ô 	*ð 	*ð,ð ,ð ,ð ,ð ,Ð.ñ ,ô ,ð ,ð	ð 	ð 	ð 	ð 	Ð.ñ 	ô 	ð 	ðð ð ð"	ð 	ð 	ð 	ð 	 ñ 	ô 	ð 	ð	ð 	ð 	ð 	ð 	 
ñ 	ô 	ð 	ðO˜h x°Ô0@Ô'AÔBð OÈ#ð Oð Oð Oð Oð:*Ø�H˜SÔ-Ô.Ô/ð*Ø7:ð*ð *ð *ð *ð2Ø�H˜SÔ-Ô.Ô/ðØ7:ðð ð ð ðD  Ô!1ð  °cÔ6Lð  ð  ð  ð  ðH '/ð+ð +Ø
Ô
ð+àÔð+ð +ð +ð +ð\Ø
Ô
ðØ$)¨#¬-¸¼Ð*HÔ$Iðð ð ð ð@1Ø! #Ô";¸SÔ=MÐ"MÔNð1à
Ô
ð1ð 
ð1ð 1ð 1ð 1ðhð ð ð ð Ð#ñ ô ð ð	ð 	ð 	ð 	ð 	˜lñ 	ô 	ð 	ðÐ*?ð ÀCð ð ð ð ð.&Ø
Ô
ð&Ø.1ð&à
Ôð&ð &ð &ð &ðR €�$ÐÑÔðð ð ð ð ñ ô ñ Ôðð*˜sÔ3ð ð ð ð ð ð ð ð$
 S¤^ð 
¸¼ð 
ð 
ð 
ð 
ð*¨#¬.ð ¸_ð ð ð ð ðB Ô&ð	#$ð #$Øð#$à˜”ð#$ð ð#$ð
 ˆ3�ˆ:Ôð#$ð #$ð #$ð #$ð #$ð #$r:   