trousers-0.3.15-150400.3.3.19<>,Tfp9|pOv3U?o@F֐ Õq´0)xk&9z6#!LҰaLԨ`u*1K*(,<ֻj?ѱwh&Kߓ<< p/R|v+.ssY|Y8^ Mmv ڮ iŅ ET=y5o0M%As#]GI.pC@e-{ܚ,9=1z7 &n q.ea?-j砯y^a>H3?3d   V %FS i & #d   l   xQxL(8 9( : ='>'?'@'F'G'H(,I(X(Y(\(])@^*P b+!c+d,Me,Rf,Ul,Wu,lv,w.Xx.y/z/ /03Q3\3`3f3Ctrousers0.3.15150400.3.3.19TSS (TCG Software Stack) access daemon for a TPM chipThe trousers package provides a TSS implementation through the help of a user-space daemon, the tcsd, and a library Trousers aims to be compliant to the 1.1b and 1.2 TSS specifications as available from the Trusted Computing website http://www.trustedcomputinggroup.org/. The package needs the /dev/tpm device file to be present on your system. It is a character device file major 10 minor 224, 0600 tss:tss.fibs-power9-18)SUSE Linux Enterprise 15SUSE LLC BSD-3-Clausehttps://www.suse.com/Productivity/Securityhttp://trousers.sourceforge.net/linuxppc64le/usr/bin/getent group tss >/dev/null || /usr/sbin/groupadd -g 98 tss || : /usr/bin/getent passwd tss >/dev/null || \ /usr/sbin/useradd -u 98 -o -g tss -s /bin/false -c "TSS daemon" \ -d /var/lib/tpm tss || : if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : for service in tcsd.service ; do sysv_service=${service%.*} if [ ! -e /usr/lib/systemd/system/$service ] && [ ! -e /etc/init.d/$sysv_service ]; then mkdir -p /run/systemd/rpm/needs-preset touch /run/systemd/rpm/needs-preset/$service elif [ -e /etc/init.d/$sysv_service ] && [ ! -e /var/lib/systemd/migrated/$sysv_service ]; then /usr/sbin/systemd-sysv-convert --save $sysv_service || : mkdir -p /run/systemd/rpm/needs-sysv-convert touch /run/systemd/rpm/needs-sysv-convert/$service fi done fi if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : if [ "$YAST_IS_RUNNING" != "instsys" ]; then /usr/bin/systemctl daemon-reload || : fi for service in tcsd.service ; do sysv_service=${service%.*} if [ -e /run/systemd/rpm/needs-preset/$service ]; then /usr/bin/systemctl preset $service || : rm "/run/systemd/rpm/needs-preset/$service" || : elif [ -e /run/systemd/rpm/needs-sysv-convert/$service ]; then /usr/sbin/systemd-sysv-convert --apply $sysv_service || : rm "/run/systemd/rpm/needs-sysv-convert/$service" || : touch /var/lib/systemd/migrated/$sysv_service || : fi done fi /usr/bin/udevadm trigger -s tpm || : # bsc#1164472: adjust potential root ownership to allow tcsd to open the file # as unprivileged user. Be careful not to follow a symlink target. system_data=/var/lib/tpm/system.data if [ -e "${system_data}" ]; then chown --no-dereference tss:tss /var/lib/tpm/system.data fi test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ "$FIRST_ARG" -eq 0 -a -x /usr/bin/systemctl ]; then # Package removal, not upgrade /usr/bin/systemctl --no-reload disable tcsd.service || : ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_STOP_ON_REMOVAL" && . /etc/sysconfig/services test "$DISABLE_STOP_ON_REMOVAL" = yes -o \ "$DISABLE_STOP_ON_REMOVAL" = 1 && exit 0 /usr/bin/systemctl stop tcsd.service ) || : fi test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ $1 -eq 0 ]; then # Package removal for service in tcsd.service ; do sysv_service="${service%.*}" rm -f "/var/lib/systemd/migrated/$sysv_service" || : done fi if [ -x /usr/bin/systemctl ]; then /usr/bin/systemctl daemon-reload || : fi if [ "$FIRST_ARG" -ge 1 ]; then # Package upgrade, not uninstall if [ -x /usr/bin/systemctl ]; then ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_RESTART_ON_UPDATE" && . /etc/sysconfig/services test "$DISABLE_RESTART_ON_UPDATE" = yes -o \ "$DISABLE_RESTART_ON_UPDATE" = 1 && exit 0 /usr/bin/systemctl try-restart tcsd.service ) || : fi fi.\W"#]~^^A큤A큤Affffff^S_L^S^S^S^S^S^S^S^Sfۿfۿf^S^Sfeb009b7d1132ac33411e8f838c7e272606c8dd1d8944bc8b82ee28f9114e82fcc56f762ff401646eae0b25769c79234e22cabea3e3b4f4c7bc581a23787b36f44b635e9ae00264cd370fc62921814265679e2a15fa6d6ebbd468e40f00af48f4a98151c3a0e3a8859cc7cb647b1381d8d51d5e0adcee4d29ba44fbb56306d918fa066fc32ac644d28c5ae56f62feae0e3b8639565dccad1cc4345dc71577970ffccf2c7a906ae571849fc1bacd98f3e070e4da85b2ec6e937aa45ca1323b55ef1ad596d12e7471549663c03e280b5b5d084a2e853fb86e4d766109818f9d7dae4a6bf595610b97b05728f4615d54faf290fac3f8bef836a5d919de070f3cecc4842cff0de213dbcbe03bdcc03c3dcfaa48e03bf45eea9d18e970cef4411f4458686e9d62dea2df5433d4a435602c3e0522b3bb68a2e75c39c80552d6bdddd948e10fd3096b3fca327b01803d91959817028371fe8d9e1970256bc56aeb1bdc1138547b7d669844a1d7d5b9075872b6f5117996c0a21d78e383e79ce7eaedb8c07ef598700d70a9cd14ba28950c7b048cf21ec2ac2297013e5789830b58ffe8baf09355ad0bc2e91d802c18654c2b9219ac1a26cab805879a784eb8a030e02c437cef9d8224b158378505c02b77fcdaa05a2f9ecc1552e95ad6d71b5ea96b690219a3b32565147e2a9d085f67d3c83fd4b93dad037fb966cb0cc5499d8fa6a568d7c26f86aeb0e601cd2358475047161b619bb46872f84569448031f3649619e35e3194d734c81d99d6cb679ed5c24ac97652b068ff12eed215e1ce382a4fb7dcservicerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootroottsstssrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootroottsstrousers-0.3.15-150400.3.3.19.src.rpmconfig(trousers)trouserstrousers(ppc-64) @@@@@@    /bin/sh/bin/sh/bin/sh/bin/sh/bin/shconfig(trousers)coreutilscoreutilslibc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcrypto.so.1.1()(64bit)libcrypto.so.1.1(OPENSSL_1_1_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)pwdutilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)udev0.3.15-150400.3.3.193.0.4-14.6.0-14.0-15.2-14.14.3f @a\>@^˳@][GXh@W,@U@U/@Smatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commailaender@opensuse.orgjengelh@inai.decrrodriguez@opensuse.orgmpluskal@suse.commeissner@suse.com- fix runtime requirements for stat and udevadm (bsc#1221770). On minimal systems this can cause the %pretrans or %post scriptlets to fail because of missing tools.- update to new upstream version 0.3.15 (jira#SLE-18269): - Corrected mutliple security issues that existed if the tcsd is started by root instead of the tss user. CVE-2020-24332, CVE-2020-24330, CVE-2020-24331 - Replaced use of _no_optimize with asm memory barrier - Fixed multiple potential instances of use after free memory handling - Removed unused global variables which caused build issue on some distros - drop bsc1164472.patch: now contained in upstream tarball - adjusted %setup macro invocation which seemed to be wrong- fix a potential tss user to root privilege escalation when running tcsd (bsc#1164472). To do this run tcsd as the 'tss' user right away to prevent badly designed privilege drop and initialization code to run. - add bsc1164472.patch: additionally harden operation of tcsd when running as root. No longer follow symlinks in /var/lib/tpm. Drop gid to tss main group. require /etc/tcsd.conf to be owned by root:tss mode 0640.- Fix a local symlink attack problem with the %posttrans scriptlet (bsc#1157651, CVE-2019-18898). A rogue tss user could have used this attack to gain ownership of arbitrary files in the system during installation/update of the trousers package.- fix wrong installation of system.data.{auth,noauth} into /var/lib/tpm. These files are only sample files that *can* be used to fake that ownership was already taken by trousers, when other TPM stacks did that already. These files should not be there by default. Therefore install them into /usr/share/trousers instead, to allow the user to use them at his own discretion (fixes bsc#1111381). - implement a backup and restore logic for /var/lib/tpm/system.data.* to prevent removal of validly stored trousers state during update.- Update to version 0.3.14 (see ChangeLog) (FATE#321450)- Check for user/group existence before attempting to add them, and remove error suppression from these calls. - Avoid runtime dependency on systemd, the macros can all deal with its absence.- Force GNU inline semantics, fixes build with GCC5- Cleanup spec-file with spec-cleaner - Update prerequires - Use systemd unit file * replace tcsd.init with tcsd.service- updated to trousers 0.3.13 (bnc#881095 LTC#111124) - Changed exported functions which had a name too common, to avoid collision - Assessed daemon security using manual techniques and coverity - Fixed major security bugs and memory leaks - Added debug support to run tcsd with a different user/group - Daemon now properly closes sockets before shutting down * TROUSERS_0_3_12 - Added new network code for RPC, which supports IPv6 - Users of client applications can configure the hostname of the tcsd server they want to connect through the TSS_TCSD_HOSTNAME env var (only works if application didn't set a hostname in the context) - Added disable_ipv4 and disable_ipv6 config options for server - removed trousers-wrap_large_key_overflow.patch: upstream - removed trousers-0.3.11.2.diff: solved upstream now/bin/sh/bin/sh/bin/sh/bin/shibs-power9-18 1721031619 0.3.15-150400.3.3.190.3.15-150400.3.3.190.3.15-150400.3.3.19 tcsd.conftcsd.service91-trousers.rulesrctcsdtcsdtrousersAUTHORSChangeLogLICENSELTC-TSS_LLD_08_r2.pdfLTC-TSS_LLD_08_r2.sxwNICETOHAVESREADMEREADME.selinuxTODOTSS_programming_SNAFUs.txttcsd.conf.5.gztcsd.8.gztrouserssystem.data.authsystem.data.noauthtpm/etc//usr/lib/systemd/system//usr/lib/udev/rules.d//usr/sbin//usr/share/doc/packages//usr/share/doc/packages/trousers//usr/share/man/man5//usr/share/man/man8//usr/share//usr/share/trousers//var/lib/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:33188/SUSE_SLE-15-SP4_Update/159c6189c2888e1f144b776f98e388d1-trousers.SUSE_SLE-15-SP4_Updatedrpmxz5ppc64le-suse-linuxASCII textELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, BuildID[sha1]=de7e051e7eb7a13d2175471e35c3721bb3b65057, for GNU/Linux 3.10.0, strippeddirectoryASCII text, with no line terminators (OpenOffice.org 1.x Writer document)troff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)R R R R R R&I&Rf`}s# this scriplet and the counterpart in %posttrans work around a packaging bug # that was present in all trousers packages since around 2008 until 2018. # /var/lib/tpm/system.data.* was wrongly packaged as runtime state data # instead of package resource data in /usr/share. After removal of these files # from packaging, during updating they will be deleted. Since users could have # created their own versions of the files already (by taking ownership of a # TPM) we want to keep those files in place. # # to achieve this we use the ownership of /var/lib/tpm as an indicator. # Versions that still wrongly package those files also had the ownership of # the directory wrong. Therefore if the directory is not owned by the tss user # we apply a backup and restore logic. [ ! -d "/var/lib/tpm" ] && exit 0 OWNER=`/usr/bin/stat -c "%U" "/var/lib/tpm"` [ "$OWNER" = "tss" ] && exit 0 for data in system.data.auth system.data.noauth; do file="/var/lib/tpm/${data}" [ ! -e "$file" ] && continue cp -p $file ${file}.rpmsave echo "saving backup of $file" done/bin/shutf-82f3a6193a4d8a4e058f55ebb0406e214e921982174f0ff9152f335e3d9f3b6a2?7zXZ !t/?r]"k%b460c>ͱ8eUlN3GnlUqd\*^#|uH8;]?b ̮C"ҧ"g)x;TryZUΪ:zH(O:P V:.LBν>))pkhMS&eN1?n |0Ҵ9S_ئ~Xp((k2,b'o&&rlͭl]!|xkvQo[PfDtڱʩ\H=#>'&"GkgKuO.p1u ,7S(T\%6 `u MhSXv:b#+hA߳Z;͏ϫ.o5'8ۼwEWzt@wR7[Xh lLB?/,+ugX6:GDmM᷊n@U;ٝ96wx$." ùt=o%^,t ZVyD%Cବ}+Xbx{VT}$)? *iF 5|X<4"o䞏@hjwTU-Cesj7)L(9cXXxl_;f Mj䵷92H *8Ғdu֢ؐ EnؒOrYCl #3lG4R/^nṞM3&B94fGlA]n6^>@pzN(A| K:2x_XQ;&wm֛. ~SX]'*WrO]5XީmZ6 kO5N i,j~ ~:[sF[.$U;HT;-\*%;MY6tj0+N'~4)vg$ Qc[ה;SIތ;@fءsB;HkT>EIw/2,8Н|Ld|!73N"HJL.x7$_I4c'IpYcu/mPl]C"OeA'"G NMÏ"l-/7G noS5,)iBZCU7 jo e DF#m<'-r[E.#L׭Pj}<A˕sr+ZNy|6=FtINJo+U C; ҏoػ?[9K3H 1ŵ NØAGFt", 38{ѳ?ф )hTGQ/~ eh+PѭM6c FQfױ ~֡)l'8~W24 h;sC ]  Mlڲr _n2'X6ά$v{o(|{;.LG]oJhdD|FiPp<8r 5nGŬEskv8rg,{ xy$*<~<=)i'h >s,.wJvJMg\ XqzwC7'EiOk e7;8-1ԃZ`vV8^C}=3rCM7G7j?yb_mb&$jBI`POs¡3l ҰYfӈtY<2ׇV:V`=)L#{+?4;?5ϱ0쇡:5F}jPr St%+ dtW9Y}|NʌƓhV8`XRO(fvO+`-KDCWvmka[_ĝҭZ5^ ;4o7f;Z}R|7rr7w謝޵TE|H^gSWBixZ;Rzsle[] go3^C>\ څٕS<lq?nCeͲ!#^F˥rP6!އ7$QM읗^[oj~g@xϕLq_0@Z~@anU2C$4S>B ]}ؖ)UK4,BO+r &} ҫxs䙬iۨokyC*\I:6 jdN73?E)ewtɷ@q"o.YzahJ;ՔNQ8o߫Otub?Sy &VI6Е.#ˇZS/c wXkOخ]8.Do 6pBk \2K3ܪJbSnx>f*!0JfUm64^շv<{cD+My" cJeup׆J9$x hSU*3qhZ;ckכe2û\R`jo_BPB?N~qeS<7wT >D;0״ =K "^ƵPAu/*w-)2']%_$_IoKWdMGB &u^\u_h 6Uͳ 6Fx2*=ɍF<j +Ϣp65w[foTƛVs9)ķI?hI`Z'l@K1J.02DC Q^{CZƾt2OsEZE "Ys9V}њ'fb611&&q]Dd!8я']M7"ú|&hWL4@_^~MiXxTvYt Ϋ;ŷ{ϋ9@ |Xy'BQe]RzSQkZnA6eVV]E'7ԑN +HorsBp.F"Au*^.i۩36Ȏr g{@wl}L}IWI$wǃS[↑J{g*[[lm:)SrQ`qX4)"ngÒkaޫ:Ӡ LpJ_&o=4+N5iWԉqbQSev*^ȬG:e_h >:HϚjjZx5`,/! BR[YE/@HٴVr0uϬf|>kiEpf:\&zZٳG6h#ۋ洈{%< T.r01@.$/:FāE6!dU.BskWǝL9uaOb^^ddnFnH'ƪ R.aFDKޱDZa>mEQFc7=Cq>`3nnr}u _ >)6c'yjE3NӁa (܊0ETAHMQﰉgUv"Ѕ~ f)A.M˽ ({b#um(Sހ+E~l7sFsFq"P;oZHT֜& 2P3nЫ=KvPȒ$Iɳ;nOFيDkR :)5 ։B|*CsD=a dȢXH_Qwz&E_uzz@ijM1 ,l'Yic?t?3q -e C.srkirdΰyhm禝b̥C}V/x퓘 SdLie48?q@WCo*.QH> )u8cHfVd䎉HԮѶI1x*y5  ;,wq)|iM%A; M| O"V4r蠷#`Ht]=+=tY~xQwL`:[ԢYxWL@7 fj)c-Vи0DjP\6)biG&[AHVDޞ[Bg[k~"{ eq<}lt^=\@Mp.<TYHzmx3 7;k߿-Ѭuxwvჰ(WY<IGJD(B^;DW'OXPr4C2 `lI&8:X p!gI̡Ke2m@t1њWo,^]6Gfr;ڬCu.!-.щ t3} P2r#{&:r 9 hŇ7ߐmtC<]&Fe%Yw ֞*&$wsΣ2w&xD2`rDKBI&*lwj<8w 9qCK]c-misg },)Nv)u!wTTYABJoX&U6[wO{D;h]B-8:85a"D{~:b_YQO}j-$ɻr&OӖP0V~+(Ӳ.p$ V)C LjQINf*-N!E,~-gUxRL9 kǸ:Za>9l*Vr7=ZF%Ado R|Q+JD7$.*r1T/51z]KIw| #>e1BA`m;՜i1Ѱ?'uDD&`ږ27 %mDl~~-#4y1~v3: Ͳ!mbAN0|Ď3dqь˩Ē*0.ȽrD -petK /lFtn<糳?Њ-yUVFE{ d8UIœU+Јؚ.kw=L`V(dR4璂Gʢ ly"rIPIUKBPR̫{)k֪y)a˛QRgi l>e"Kyĝ:9xX)z(yDU\q= ͮSkm}4M8x*8PW IFC.!b)aœ_i;ƅ.| R N[%y!Ώ0~IM[E liŸ_9ҽԿ|xAl&oYE. oKōд?k|5),ĥeV,* ǣ)b^\O>MJ E+j#iN 6|{n-?l/e>e-m\N<[ (oO914չ"+4Ѐre1'[pbkwNӲV)uUmNdԭ |[]1;sPt֞Q/_f.a;B&V:Z,CN;'}QϖiQ NNS-tLQX_Ìvw5d5t!_wͫ}EJ뗞z EH`ix>`vLBNbnfՋHBWfc+Dڟvi]0?P1;hCDXL- ނiȝ_?X]e N7oO>Y d=C4>;{Uzj5`ۿu|GiژW))]؍__vFCT\`$L)Nh/bUBz,4s;ϯqG4yc%q/}QNxKaL_4,z΂/Ѿȍ iR7٦tD;!Njەh /^BH[3F#_+O-Z3?9KhK&# C(L!➠6=(IoiMDzgzgtVdw'Ijwʝ!CB ,ӡx:&}=5rr:Y]=y$t5]l9Wxmo/eP~^1UaX yjb\~='JWe[StJGVoV٦3CeG1֠B9{5a5=<49Exx+;փ+IV ax +\n b[i{u6,/m6kVOmGdl#ms,vA`ڍ!SG(C!CezpɧjMK7:`\ց*T( bZrBj7p * YZ