apparmor-docs-3.1.7-150600.5.6.1<>,hp9|OD[Cў?y |v.c}R>MC|-TܛYECyAX=Gݰ+A7fvSB+_$s'`BcdY;8yO&K[ꖭ?CC)Qc ̓ 6m2b.dDZ6X^rr.=D8{]w;\Ƚ"c5`Xb"UvNf\8q;t̡/r6NZ wUzzif_壯?a[F½ >;?xd # B 5Ihnx         G  T    @P`(89h:^FGG\ H I XY\ ] ^bcdEeJfMlOud vz(,2tCapparmor-docs3.1.7150600.5.6.1AppArmor Documentation packageThis package contains documentation for AppArmor. This package is part of a suite of tools that used to be named SubDomain.hh04-ch1bSUSE Linux Enterprise 15SUSE LLC GPL-2.0-or-laterhttps://www.suse.com/Documentation/Otherhttps://launchpad.net/apparmorlinuxnoarche0-KIvʷA큤A큤hh heWeWeheWheWeWeWe18b7ab1776823a1e62a2d6db1bbbe51819f5732e89ca63a6dd3d540e629a42030a0adfab04b7755e093632fab7b8ab2adea32fc2eb640ec9586faa0cd2ebbd4ebeac1b7aa8497a59a81c4fc342ec5666f42e2dccea0104e188935ddd2137815d383e3f1c2fd71198fe319a325fbb9a2068dd73b2609e27db150d3aeddd9ed06afaf9108909890bb258f3dadbbd113fb35878c5f106a107850d33d62c851288d5e33ae4afd85d4e8a3a0f579068ca74e1686ba4651958a25e6792c6e1226f58dbe26924e382467ea63dd33229f07de8c3503ef5eac61cad007103e59e545bfb065b734a62259324cfd147c49382f1f4d2b4389cfaffbb1052eea742c669224001e91ac861de966cac00dd5711c9742ff2bfa9793a2848b5ae04c406fa888fbc6rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootapparmor-3.1.7-150600.5.6.1.src.rpmapparmor-docs    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3hg@e@ee}@eԔ@eԔ@e@ee@eKx@eKx@ev@d@d7d@ddtdS@cccױ@c@c@c|c@c Xcb{@bb@bޅbVb@b@b{@bwbk@bi0@bZbV@bT@bRbBb<]@b@a7aZ@ap@aabaim@aEaaua $@`#@` @````_@`%@`!'`>` @__ǁ_ǁ_Q_h__@_~@_[f_P_-B@_@^m@^@^<@^j$@^,-]҇]o](]K@]]@\\@\ \\v{\I\ include in apache extra profile optional to avoid problems with empty profile directory (boo#1178527)- prepare usrmerge (boo#1029961) * use %_pamdir- update to AppArmor 3.0.1 - minor additions to profiles and abstractions - some bugfixes in libapparmor, apparmor_parser and the aa-* utils - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0.1 for the detailed upstream changelog - removed upstream(ed) patches: - changes-since-3.0.0.diff - extra-profiles-fix-Pux.diff - utils-fix-hotkey-conflict.diff- Use apache provided variables for the module_directry: + Use %apache_libexecdir + Add apache-rpm-macros BuildRequires- add utils-fix-hotkey-conflict.diff to fix a hotkey conflict in de, id and sv translations (and fix the test) (MR 675) - add extra-profiles-fix-Pux.diff to fix an inactive profile - prevents a crash in aa-logprof and aa-genprof when creating a new profile (MR 676)- update to AppArmor 3.0.0 - introduce feature abi declaration in profiles to enable use of new rule types (for openSUSE: dbus and unix rules) - support xattr attachment conditionals - experimental support for kill and unconfined profile modes - rewritten aa-status (in C), including support for new profile modes - rewritten aa-notify (in python), finally dropping the perl requirement at runtime - new tool aa-features-abi for extracting feature abis from the kernel - update profiles to have profile names and to use 3.0 feature abi - introduce @{etc_ro} and @{etc_rw} profile variables - new profile for php-fpm - several updates to profiles and abstractions (including boo#1166007) - fully support 'include if exists' in the aa-* tools - rewrite handling of alias, include, link and variable rules in the aa-* tools - rewrite and simplify log handling in the aa-logprof and aa-genprof - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0 for the detailed upstream changelog - patches: - add changes-since-3.0.0.diff with upstream fixes since the 3.0.0 release up to 3e18c0785abc03ee42a022a67a27a085516a7921 - drop upstreamed usr-etc-abstractions-base-nameservice.diff - drop 2.13-only libapparmor-so-number.diff - refresh apparmor-enable-profile-cache.diff - partially upstreamed - update apparmor-samba-include-permissions-for-shares.diff and apparmor-lessopen-profile.patch - switch to "include if exists" - apparmor-lessopen-profile.patch: add abi rule to lessopen profile - refresh apparmor-lessopen-nfs-workaround.diff - move away very loose apache profile that doesn't even match the apache2 binary path in openSUSE to avoid confusion (boo#872984) - move rewritten aa-status from utils to parser subpackage - add aa-features-abi to parser subpackage - replace perl and libnotify-tools requires with requiring python3-notify2 and python3-psutil (needed by the rewritten aa-notify) - drop ancient cleanup for /etc/init.d/subdomain from parser %pre - drop (never enabled) conditionals to build with python2 and to build the python-apparmor subpackage (upstream dropped python2 support) - drop setting PYTHON and PYTHON_VERSIONS env variable, no longer needed - set PYFLAKES path for utils check - add precompiled_cache build conditional to allow faster local builds without using kvm - remove duplicated BuildRequires: swig- update to AppArmor 2.13.5 - add missing permissions to several profiles and abstractions - bugfixes in parser and tools - fix two potential build failures in libapparmor - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5 for the detailed upstream changelog - remove upstream(ed) patches - changes-since-2.13.4.diff - abstractions-X-xauth-mr582.diff - sevdb-caps-mr589.diff - libvirt-leaseshelper.patch - cap_checkpoint_restore.diff - add libapparmor-so-number.diff to fix libapparmor so version (!658)- add CAP_CHECKPOINT_RESTORE to severity.db (MR 656, cap_checkpoint_restore.diff)- %service_del_postun_without_restart only works for Tumbleweed, keep using DISABLE_RESTART_ON_UPDATE for Leap 15.x- Make use of %service_del_postun_without_restart And stop using DISABLE_RESTART_ON_UPDATE as this interface is obsolete.- libvirt-leaseshelper.patch: add /usr/libexec as a path to the libvirt leaseshelper script (jsc#SLE-14253)- sevdb-caps-mr589.diff: add new capabilities CAP_BPF and CAP_PERFMON to severity.db (lp#1890547)- add abstractions-X-xauth-mr582.diff to allow reading the xauth file from its new sddm location (boo#1174290, boo#1174293)- add changes-since-2.13.4.diff with upstream changes and fixes since 2.13.4 up to 5f61bd4c: - add several abstractions related to xdg-open: dbus-network-manager-strict, exo-open, gio-open, gvfs-open, kde-open5, xdg-open - introduce @{run} variable - update dnsmasq and winbindd profile - update mdns, mesa and nameservice abstraction - some bugfixes in the aa-* tools, including a remote bugfix in the YaST AppArmor module (boo#1171315) - drop upstream(ed) patches (now part of changes-since-2.13.4.diff): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-fix-utils-network-test.diff - make-4.3-network.diff - abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch - apply usr-etc-abstractions-base-nameservice.diff only for Tumbleweed, but not for Leap 15.x where it's not needed - refresh usr-etc-abstractions-base-nameservice.diff- Add abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch (bsc#1168306)- fix build with make 4.3 by backporting some commits from upstream master (boo#1167953): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-network.diff - make-4.3-fix-utils-network-test.diff- update to AppArmor 2.13.4 - several abstraction updates (including boo#1153162) - disallow writing to fontconfig cache in abstractions/fonts - some bugfixes in the aa-* tools - fix log parsing for logs with an embedded newline - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4 for the detailed upstream changelog - drop upstreamed patches: - abstractions-ssl-certbot-paths.diff - apparmor-krb5-conf-d.diff - libapparmor-python3.8.diff - usr-etc-abstractions-authentification.diff - refresh usr-etc-abstractions-base-nameservice.diff- add usr-etc-abstractions-base-nameservice.diff to adjust abstractions/base and nameservice for /usr/etc/ (boo#1161756)- Properly pull in full python3 interpreter- add libapparmor-python3.8.diff to fix building the libapparmor python bindings (deb#943657)- add usr-etc-abstractions-authentification.diff to allow reading /usr/etc/pam.d/* and some other authentification-related files (boo#1153162)- add abstractions-ssl-certbot-paths.diff - add certbot paths to abstractions/ssl_certs and abstractions/ssl_keys- add apparmor-krb5-conf-d.diff for kerberos client- update to 2.13.3 - profile updates for dnsmasq, dovecot, identd, syslog-ng - new "lsb_release" profile (only used when using "Px -> lsb_release") - fix buggy syntax in tunables/share - several abstraction updates - parser: fix "Px -> foo-bar" (the "-" was rejected before) - several bugfixes in aa-genprof and aa-logprof - some fixes in cache handling - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3 for the detailed upstream changelog - drop upstream(ed) patches: - apparmor-nameservice-resolv-conf-link.patch - profile_filename_cornercase.diff - dnsmasq-libvirtd.diff - dnsmasq-revert-alternation.diff - usrmerge-fixes.diff - libapparmor-swig-4.diff - re-number remaining patches- add upstream libapparmor-swig-4.diff: fix libapparmor tests with swig 4.0 (boo#1135751)- Disable LTO (boo#1133091).- update lessopen.sh profile for usrMerge (bash and tar) (boo#1132350)- add usrmerge-fixes.diff: fix test failures when /bin/sh is handled by update-alternatives (boo#1127877)- add dnsmasq-revert-alternation.diff: revert path alternation in dnsmasq profile and re-add peer=/usr/sbin/libvirtd rules to avoid breaking libvirtd (boo#1127073)- add dnsmasq-libvirtd.diff: allow peer=libvirtd in the dnsmasq profile to match the newly added libvirtd profile name (boo#1118952#c3)- Use %license instead of %doc [bsc#1082318]- add apparmor-lessopen-nfs-workaround.diff: allow network access in lessopen.sh for reading files on NFS (workaround for boo#1119937 / lp#1784499)- add profile_filename_cornercase.diff: drop check that lets aa-logprof error out in a corner-case (log event for a non-existing profile while a profile file with the default filename for that non-existing profile exists) (boo#1120472)- netconfig: write resolv.conf to /run with link to /etc (fate#325872, boo#1097370) [patch apparmor-nameservice-resolv-conf-link.patch]- update to AppArmor 2.13.2 - add profile names to most profiles - update dnsmasq profile (pid file and logfile path) (boo#1111342) - add vulkan abstraction - add letsencrypt certificate path to abstractions/ssl_* - ignore *.orig and *.rej files when loading profiles - fix aa-complain etc. to handle named profiles - several bugfixes and small profile improvements - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.2 for the detailed upstream changelog - remove upstreamed fix-syntax-error-in-rc.apparmor.functions.patch- update to 2.13.1 - add qt5 and qt5-compose-cache-write abstractions - add @{uid} and @{uids} kernel var placeholders - several profile and abstraction updates - ignore "abi" rules in parser and tools (instead of erroring out) - utils: fix overwriting of child profile flags if they differ from the main profile - several bugfixes (including boo#1100779) - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.1 for the detailed upstream changelog - remove upstream(ed) patches: - aa-teardown-path.diff - fix-apparmor-systemd-perms.diff - logprof-skip-cache-d.diff - fix-samba-profiles.patch - make-pyflakes-happy.diff - dnsmasq-Add-permission-to-open-log-files.patch - refresh apparmor-samba-include-permissions-for-shares.diff - add fix-syntax-error-in-rc.apparmor.functions.patch- update rpmlintrc: - whitelist .features file which is part of the pre-compiled cache - comment out filters for the disabled tomcat_apparmor subpackage- Backport dnsmasq fix: 025c7dc6 - dnsmasq-Add-permission-to-open-log-files.patch (boo#1111342)- add make-pyflakes-happy.diff to fix an unused variable (SR 629206)- add fix-samba-profiles.patch - smbd loads new shared libraries. Allow winbindd to access new kerberos credential cache location (boo#1092099)- exclude the /etc/apparmor.d/cache.d/ directory from aa-logprof parsing (logprof-skip-cache-d.diff)- add fix-apparmor-systemd-perms.diff - fix permissions of /lib/apparmor/apparmor.systemd (boo#1090545)- create and package precompiled cache (/usr/share/apparmor/cache, read-only) (boo#1069906, boo#1074429) - change (writeable) cache directory to /var/cache/apparmor/ - with the new btrfs layout, the only reason for using /var/lib/apparmor/cache/ (which was "it's part of the / subvolume") is gone, and /var/cache makes more sense for the cache - adjust parser.conf (via apparmor-enable-profile-cache.diff) to use both cache locations - clear cache also in %post of abstractions package- update to AppArmor 2.13 - add support for multiple cache directories and cache overlays (boo#1069906, boo#1074429) - add support for conditional includes in policy - remove group restrictions from aa-notify (boo#1058787) - aa-complain etc.: set flags for profiles represented by a glob - aa-status: split profile from exec name - several profile and abstraction updates - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13 for the detailed upstream changelog - drop upstreamed patches and files: - aa-teardown - apparmor.service - apparmor.systemd - 32-bit-no-uid.diff - disable-cache-on-ro-fs.diff - dovecot-stats.diff - parser-write-cache-warn-only.diff - set-flags-for-profiles-represented-by-glob.patch - fix-regression-in-set-flags.patch - drop spec code that handled installing aa-teardown, apparmor.service and apparmor.systemd (now part of upstream Makefile) - simplify "make -C profiles parser-check" call (upstream Makefile bug that required to call "cd" was fixed) - add aa-teardown-path.diff - install aa-teardown in /usr/sbin/ - move 'exec' symlink to parser package (belongs to aa-exec)- Set flags for profiles represented by glob (bsc#1086154) set-flags-for-profiles-represented-by-glob.patch fix-regression-in-set-flags.patch- add dovecot-stats.diff: - add dovecot/stats profile and allow dovecot to run it (boo#1088161) - allow dovecot/auth to write /run/dovecot/old-stats-user (part of boo#1087753) - update 32-bit-no-uid.diff with upstream fix- Change of path of rpm in lessopen.sh (boo#1082956)- add disable-cache-on-ro-fs.diff - disable write cache if filesystem is read-only and don't bail out (bsc#1069906, bsc#1074429)- add parser-write-cache-warn-only.diff to make cache write failures a warning instead of an error (boo#1069906, boo#1074429) - reduce dependeny on libnotify-tools (used by aa-notify -p) to "Suggests" to avoid pulling in several Gnome packages on servers (boo#1067477)- update to AppArmor 2.12 - add support for 'owner' rules in aa-logprof and aa-genprof - add support for includes with absolute path in aa-logprof etc. (lp#1733700) - update aa-decode to also decode PROCTITLE (lp#1736841) - several profile and abstraction updates, including boo#1069470 - preserve errno across aa_*_unref() functions - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.12 for the detailed upstream changelog - drop upstreamed patches: - read_inactive_profile-exactly-once.patch - utils-fix-sorted-save_profiles-regression.diff - lessopen profile: change all 'rix' rules to 'mrix' - add 32-bit-no-uid.diff to fix handling of log events without ouid on 32 bit systems - no longer package static libapparmor.a- update to AppArmor 2.11.95 aka 2.12 beta1 - add JSON interface to aa-logprof and aa-genprof (used by YaST) - drop old YaST interface code - update audio, base and nameservice abstractions - allow @{pid} to match 7-digit pids - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_95 for the detailed upstream changelog - drop upstreamed patches - apparmor-yast-cleanup.patch - apparmor-json-support.patch - nameservice-libtirpc.diff - drop obsolete perl modules (YaST no longer needs them) - drop patches that were only needed by the obsolete perl modules: - apparmor-utils-string-split - apparmor-abstractions-no-multiline.diff - drop profiles-sockets-temporary-fix.patch - obsoleted by a fix in apparmor_parser - refresh utils-fix-sorted-save_profiles-regression.diff - add aa-teardown (new script to unload all profiles) - make ExecStop in apparmor.service a no-op (workaround for a systemd restriction, see boo#996520 and boo#853019 for details) - lessopen profile: allow capability dac_read_search and dac_override, allow groff to execute several helpers (boo#1065388)- read_inactive_profile-exactly-once.patch (bsc#1069346) Perform reading of inactive profiles exactly once.- update to AppArmor 2.11.1 - add permissions to several profiles and abstractions (including lp#1650827 and boo#1057900) - several fixes in the aa-* tools (including lp#1689667, lp#1628286, lp#1661766 and boo#1062667) - fix downgrading/converting of 'unix' rules (will be supported in kernel 4.15) to 'network unix' rules in apparmor_parser (boo#1061195) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_1 for upstream changelog - remove upstream(ed) patches - upstream-changes-r3616..3628.diff - upstream-changes-r3629..3648.diff - parser-tests-dbus-duplicated-conditionals.diff - apparmor-fix-podsyntax.patch - sshd-profile-drop-local-include-r3615.diff - refresh apparmor-yast-cleanup.patch - add utils-fix-sorted-save_profiles-regression.diff to fix a regression in displaying the "changed profiles" list in aa-logprof- add nameservice-libtirpc.diff to fix NIS/YP logins (boo#1062244)- profiles-sockets-temporary-fix.patch to cater to nameservices with the new sockets mediation, until unix rules are upstreamed (boo#1061195)- add apparmor-fix-podsyntax.patch from mailing list to fix compilation with perl 5.26- do not require exact X.Y version of "python3" - require also matching python(abi) which is arguably more important- don't rely on implementation details for reload in %post- add JSON support. Required for FATE#323380. (apparmor-yast-cleanup.patch, apparmor-json-support.patch)- add upstream-changes-r3629..3648.diff: - preserve unknown profiles when reloading apparmor.service (CVE-2017-6507, lp#1668892, boo#1029696) - add aa-remove-unknown utility to unload unknown profiles (lp#1668892) - update nvidia abstraction for newer nvidia drivers - don't enforce ordering of dbus rule attributes in utils (lp#1628286) - add --parser, --base and --Include option to aa-easyprof to allow non-standard paths (useful for tests) (lp#1521031) - move initialization code in apparmor.aa to init_aa(). This allows to run all utils tests even if /etc/apparmor.d/ or /sbin/apparmor_parser don't exist. - several improvements in the utils tests - drop upstreamed python3-drop-re-locale.patch - no longer delete/skip some of the utils tests (to allow this, add parser-tests-dbus-duplicated-conditionals.diff) - add var.mount dependeny to apparmor.service (boo#1016259#c34)- Cleanup spec file: - don't use insserv if we afterwards call systemd, this can have bad side effects - remove dead code - remove now obsolete 'distro' checks - Replace init.d script with new wrapper working with systemd- add python3-drop-re-locale.patch: remove deprecated re.LOCALE flag in Python UI as it was dropped from Python 3.6 (lp#1661766)- Fix RPM groups- add upstream-changes-r3616..3628.diff: - update abstractions/base, abstractions/apache2-common and dovecot profiles - merge ask_the_questions() of aa-logprof and aa-mergeprof - pass LDFLAGS when building parser, libapparmor perl bindings and pam_apparmor - adjust deleting the cache in profiles %post to the new cache location - silence errors when deleting the cache (boo#976914)- split libapparmor into separate spec to get rid of build loop involving mariadb, systemd, apparmor, libapr and mariadb again (see the discussion in SR 448871 for details) - libapparmor.spec is based on the AppArmor 2.11 apparmor.spec, but with minimum BuildRequires- update to AppArmor 2.11.0 - apparmor_parser now supports parallel compiles and loads - add full support for dbus, ptrace and signal rules and events to the utils - full rewrite of the file rule handling in the utils - lots of improvements and fixes - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11 for the detailed changelog - patches: - add sshd-profile-drop-local-include-r3615.diff to fix 'make check' - drop aa-unconfined-fix-netstat-call-2.10r3380.diff, no longer needed - refresh apparmor-abstractions-no-multiline.diff - refresh apparmor-samba-include-permissions-for-shares.diff - spec changes: - aa-unconfined switched to using ss (from iproute2), adjust Recommends: - move libapparmor to /usr/lib*/ - drop %if %suse_version checks for 12.x - change several Obsoletes from %version to < 2.9. Those package names weren't used since years, and 2.9 is still a careful choice - include apparmor.service independent of %suse_version - techdoc.pdf is now shipped in upstream tarball to reduce BuildRequires - drop latex2html, texlive-* and w3m BuildRequires - techdoc.txt and techdoc.html not included, drop them from the package - run most of utils/ make check (some tests expect /etc/apparmor.d/ and /sbin/apparmor_parser to exist, skip them) - BuildRequires python3-pyflakes (utils tests) and dejagnu (libapparmor tests) - drop sed'ing python3 into aa-* shebang (upstreamed) - build binutils - aa-exec is now written in C and lives in /usr/bin/, move it to the apparmor_parser package and create a compability symlink in /usr/sbin/ - aa-exec manpage moved to section 1 - aa-enabled is a small new tool to find out if AppArmor is enabled - package new aa_stack_profile(2) manpage- change /etc/apparmor.d/cache symlink to /var/lib/apparmor/cache/. This is part of the root partition (at least with default partitioning) and should be available earlier than /var/cache/apparmor/ (boo#1015249, boo#980081, bsc#1016259) - add dependency on var-lib.mount to apparmor.service as safety net- update to AppArmor 2.10.2 maintenance release - lots of bugfixes and profile updates (including boo#1000201, boo#1009964, boo#1014463) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_2 for details - add aa-unconfined-fix-netstat-call-2.10r3380.diff to fix a regression in aa-unconfined - drop upstream(ed) patches: - changes-since-2.10.1--r3326..3346.diff - changes-since-2.10.1--r3347..3353.diff - libapparmor-fix-import-path.diff (upstream fix is slightly different) - nscd-var-lib.diff - refresh apparmor-abstractions-no-multiline.diff- add nscd-var-lib.diff to allow /var/lib/nscd/ in the nscd profile and abstractions/nameservice (path changed in latest nscd in Tumbleweed)- add changes-since-2.10.1--r3347..3353.diff with upstream changes and fixes in the 2.10 branch, including - allow writing *.qf files (for disk-based buffering) in syslog-ng profile - add several permissions to the dovecot profiles (deb#835826) - add a missing path in the traceroute profile- add changes-since-2.10.1--r3326..3346.diff with upstream changes and fixes since the 2.10.1 release, including - allow dac_override in winbindd profile (boo#990006#c5) - allow mr for /usr/lib*/ldb/*.so in samba abstractions (needed since Samba 4.4.x, boo#990006) - abstractions/nameservice: also support ConnMan-managed resolv.conf - let aa-genprof ask about profiles in extra dir (again) - fix aa-logprof "add hat" endless loop (lp#1538306) - honor 'chown' file events in logparser.py - ignore log file events with a request mask of 'send' or 'receive' because they are actually network events (lp#1577051, lp#1582374) - accept hostname with dots when parsing logs (lp#1453300 comments #1 and #2) - fix python LibAppArmor import failures with swig > 3.0.8 (boo#987607) (libapparmor-fix-import-path.diff) - refresh apparmor-abstractions-no-multiline.diff - drop upstreamed profiles-ping-inet6-r3449.diff - add %check section - runs libapparmor (including swig bindings), parser and profiles tests - add BuildRequires: perl(Locale::gettext) - needed for parser tests- add profiles-ping-inet6-r3449.diff - latest ping also does IPv6 (boo#980596)- update to AppArmor 2.10.1 (2.10 branch r3326): - fix incorrect output of child profile names (apparmor_parser -N) which caused 'rcapparmor reload' to remove child profiles and hats (lp#1551950) - fix a crash in aa-logprof / logparser.py for change_hat log events (lp#1523297) and log events that look like file events, but aren't (lp#1540562, lp#1525119, lp#1466812) - write unix rules when saving a profile (lp#1522938, boo#954104#c3) - several fixes for variable handling in aa-logprof - map c (create) log events to w instead of a - add python to the "no Px rule" list in logprof.conf - let aa-logprof check for duplicate profiles - let aa-status work without the apparmor.fail python module (boo#971917, lp#1480492) - add permissions in several profiles (including boo#948584, boo#948753, boo#954959, boo#954958, boo#971790, boo#964971, boo#921098, boo#923201 and boo#921098#c15). - and many more fixes, see the full changelog at http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_1 - drop upstream(ed) patches: - fix-initscript-aa_log_end_msg.diff - syslog-ng-profile-boo948584.diff - upstream-profile-updates-r3205-3241.diff - refresh patches: - apparmor-abstractions-no-multiline.diff - apparmor-samba-include-permissions-for-shares.diff - drop libapparmor autogen.sh call (broke the build) and remove libtool BR- add syslog-ng-profile-boo948584.diff - add several permissions needed by latest syslog-ng (boo#948584, boo#948753) - add upstream-profile-updates-r3205-3241.diff with several profile updates: - add /usr/share/locale-bundle/** to abstractions/base - allow dnsmask to use /bin/sh (boo#940749) and /bin/dash - allow dovecot imap to read /run/dovecot/mounts - allow avahi-daemon to write to /run/systemd/notify - allow ntpd to read $PATH directory listings (boo#945592, boo#948752) - update dhclient profile - allow skype to read @{PROC}/@{pid}/net/dev (boo#939568) - and some other small updates - drop upstreamed apparmor-winbindd-r3213.diff (included in the upstream-profile-updates patch)- netstat moved to net-tools-deprecated in Tumbleweed (boo#944904)- add apparmor-winbindd-r3213.diff - add missing k permissions for /etc/samba/smbd.tmp/msg/* in winbindd profile (boo#921098 #c15..19)- add fix-initscript-aa_log_end_msg.diff - fixes ugly initscript output (boo#862170)- update to AppArmor 2.10 (trunk r3205) - profile names can now contain variables - improved profile compile time in apparmor_parser - lots of improvements, refactoring and bugfixes in the aa-* tools - new apis for managing and loading profile caches into the kernel in libapparmor - lots of profile updates - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10 for the complete changelog with more details - add new apparmor_private.h and the aa_query_label(2), aa_features(3), aa_kernel_interface(3), aa_policy_cache(3), aa_splitcon(3) manpages to libapparmor-devel - drop apparmor-2.5.1-edirectory-profile patch - it's most probably no longer needed (see boo#621394 for details) - drop upstreamed samba-4.2-profiles.diff - refresh apparmor-samba-include-permissions-for-shares.diff- systemd-rpm-macros and %systemd_requires were at the wrong place, move them to the parser package (boo#931792)- update to AppArmor 2.9.2 (2.9 branch r2911) - lots of bugfixes in the parser and the aa-* tools (including boo#918787) - update dovecot and dnsmasq profiles and several abstractions (including boo#911001) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_2 for the full changelog - remove upstream(ed) patches apparmor-changes-since-2.9.1.diff and apparmor-fix-stl-ostream.diff - replace GPG key with new AppArmor GPG signing key, see https://launchpad.net/apparmor/+announcement/13404- make sure %service_del_postun doesn't call systemctl try-restart (boo#853019, bare systemd edition) - add samba-4.2-profiles.diff: update samba (winbindd and nmb) profiles for samba 4.2 (boo#921098, boo#923201)- only install apparmor.service for openSUSE > 13.2- Add a native systemd unit which *at the moment* only wraps/masks the early boot script.- add apparmor-fix-stl-ostream.diff which fixes odd uses of std::ostream which are not valid. Fixes build with GCC 5- allow lessopen.sh to run /usr/bin/unzip-plain (boo#906858)- add Requires: python3 to python3-apparmor package - readline isn't part of python3-base (boo#917577)- add apparmor-changes-since-2.9.1.diff with upstream fixes since the 2.9.1 release - update logparser.py to support changed syslog format (lp#1399027) - update usr.sbin.dovecot and usr.lib.dovecot.imap{, -login} profiles (lp#1296667) - update the mysqld profile - fix network rule description in apparmor.d(5) manpage - drop upstreamed dnsmasq-profile-fixes.patch - update expired GPG key- update to AppArmor 2.9.1 (2.9 branch r2831) - fix log parsing for 3.16 kernels and syslog-style logs (boo#905368) - several fixes and performance improvements in the aa-* utils - profile updates for dnsmasq (boo#907870), nscd (boo#904620#c14 and bnc#908856), useradd, sendmail, man and passwd - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_1 for full release notes - refresh dnsmasq-profile-fixes.patch- Fix dnsmasq profile to allow executing bash to run the --dhcp-script argument. Also fixed /usr/lib -> /usr/{lib,lib64} to get libvirt leasehealper script to run even on x86_64. dnsmasq-profile-fixes.patch. boo#911001- rename lessopen.sh profile file to usr.bin.lessopen.sh to match the script filename- add apparmor-lessopen-profile.patch: /usr/bin/lessopen.sh needs confinement. bnc#906858- delete cache in apparmor-profiles %post (workaround for bnc#904620#c8 / lp#1392042)- No longer perform gpg validation; osc source_validator does it implicit: + Drop gpg-offline BuildRequires. + No longer execute gpg_verify.- fix bashism in post script- update to AppArmor 2.9.0 (r2759) - change aa-mergeprof to the final commandline syntax - lots of bugfixes in the aa-* tools (bnc#900163, lp#1328707 and several bugs without a formal bugreport) - small additions to gnome, freedesktop.org, ubuntu-browsers.d/java and user-mail abstractions - fix mod_apparmor to not break basic auth - update perl modules to support signal, unix and ptrace rules (bnc#900013) - don't warn about rules not supported by the kernel - fix logging of "audit capability" (lp#1378091) - add support for the "hat" keyword in apparmor.vim - build html version of apparmor.vim manpage again (lp#1366572) - see also http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_0 - update apparmor-abstractions-no-multiline.diff - remove upstreamed apparmor-profiles-ntpd-pid-location.diffh04-ch1b 1745392364 3.1.7-150600.5.6.1apparmorapparmor.vimapparmor-docsaa-teardown.8.htmlapparmor.7.htmlapparmor.cssapparmor.d.5.htmlapparmor.vim.5.htmlapparmor_parser.8.htmlapparmor_xattrs.7.htmltechdoc.pdf/usr/share//usr/share/apparmor//usr/share/doc/packages//usr/share/doc/packages/apparmor-docs/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:38382/SUSE_SLE-15-SP6_Update/108ff988527a5e410ebf430fd63f6431-apparmor.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linuxdirectoryASCII text, with very long linesXML 1.0 document, ASCII textXML 1.0 document, ASCII text, with very long linesASCII text*"sO˻Putf-8938bdf407102b7ef40452fadc9b567f46eabc24fb1849fb036ac59b1988d6e82?P7zXZ !t/^]"k%fnCQZuǡjע|sjdBC0Dj'D_fR I*/}{tCZ%L.elRA~Xp QNRJ\ X}dAxbMqkY3^s_-^Ar|ZlDDd7J\v*U;|)0D+:{W ޝ.O+2 =^ӯH/ƅ}3>qk/ qgӤdjI sK[̀( OInϴ GR-_=q,! ;x0>4jKa Nmuɸ SܶT0K*J[I~U wÎ}V b0ugC\U|j_x͏{ZbsΟl BFgrT@ڧӽ$,xDpCIOtmmgh~:sd'=#GujQ5t:5Xu1rUV y&De~vp+ ɎH4 ߄kZ*Vb୎/b?)jԕȬRB)B(Pt\^ew+Od'_CEka=ZUaQf53&%keJ{ ϛ̛4pXlP%mb;S|s)+L#C^9;g3%ȩ&E2F&GEsf^aB8 XSa#]]v.3@ –_Ic&AREMdp cd_gWX$9vuh1*V^ 6qxu:+*֢ wa!"ʝfwa6|n\vdc*|Yg*(J . Q'+[˅~UŲ$~hXgs*j$kFtr%32,hj59E9[OWע,(ܷ+.ic\xV)b !?UV9٪2¸]x/& i@8v6mvR4F4/}ɘ~V 4Z%3q>dgh$_G #|lGzљO, DWDQ 01p^ }#i۶;E-9)m =bg0z}n.z K|yYa/Ll}L!Ċy=A:˯ߙghjHÔQE^[V2!4eDmo>(4`|ÔC˱ z%Ble;Nƫhwqަ?T.QExMnCBK^OLr$ !-)85JSr,^y ws?xX>~ن0SzGUi3EfWhrD64SQaQ}u5t{E㮁0wZ)Xz;"{M*aѪ77P{2X#;oޢ+N KCR}7nE[TbwX{ ?\Gd}2\PVfرVWh}/YX8\Q9m2h]YϥPʪHT|"d:Y8(#BןU O3QYUKӢ$]ϔnNU0}a[*Ds)R&1 c"Uaf'd~w+Zx-@0pg I8 Z5UW-YS6XxN~ l` O *p%C^%[ OM/~Uɩk1E GQ ) PBi>yW*uMM&!?ʣgCcʯͷ),K4cU/U%:>NNr:sU 4n2HPj-ЙhTnBN0ԙĊdF2[^F0nj#u¹vϲ-B=X9b'vg;~`VU^Df'uw*{HUR0}ΦVIk1& hDܘ=hȺ+o[A۵` FڦvBCh,R@EQM~!Dt+Y2 luc妪/P;fճ@9ulv8xDjgBhM PK< 7M[I!XjFrU,5A [ZiBo5%5 )@HpL~rEo[?_S!OWxMByN jg'TbHgYs#xyuRϼnTPY\>dcD&$Ouml_qs]sC;0Ֆ G^B\xQp7L9A[ro9.bO:dB#E&u&?Ɨ.hc'*r@E.֙ Vv w+޻YgPJIys…kp9 ÏHLGNy137Q1~>` FZII 4Z飻"ϥn<4JO}|:'(vzW;iO> q iwT.Y4p`f/# XorV@CLύML|(wNfyɕj5zTlʠ d}b/dJ(Bߝm9-Y!WR;x_L6$@gzG?̌* 69Z"}"yl{W\ga;tqdL{GOBQx IpvHoa o 7ZĶ[bjY89ۍY{hyXҦeuiWe̟mO峅У_=Γ!b)\]2M\ 7;Hc)sdh޷.1j sLl<< ~@ somh~DՐ=4rnҭR'䬴V6tiμTcGIA'Ƹ%2#YzpYx?/\jpq-RIaJr^8%cIUtRm>",@YjCAcdƽHL3YEd[F}Q>7_R(t-])/륭4qFlM uYB9%i'PiI_0 X-"w1c|,D+|H }AJNoqbౙ  ؖXTPն֜ ? uSyǑycgZ*,VuGlqG9ffu֚\|V}g@*, A|)- `g3uTR2؊.Xi :Qqe(Q#Ac'cʬb(Zf*bt/4VdҾx| ς]F`SjdQu^ojFd?D ~r_,(a=r>Vt]R2`b2b*7w=+ :B@LG (& ҲgL8vJn?`+3L`tuFnf.yCZk Л{.65ˌt9XJ:PmI>ږ ) y>*8k)FԀ&AsXculѨ|JyN //]ꪾykda﹨z+'<Dz6J:r\űszHaZqǹikY-nkk[7N }W%&9y7̓y\RѨi  )-^jp]c DBn:?$plV-9za={Vk 8:`JO"6 Ї&'[)śN73J\,@y*LQLl"M)IX5B[K; GviFjTD6Rp]DX}Ù&* |6Dj2h].yp R _W@+nzq>=*a7¨~ŝ+6Qn&G\8bؐ"fKf\=/Mɣwp:'OD`^,TIvGhٞ&]q"Oҡ0"~K,H?V>)54{k*~_D*i[wn{]Y=IҸO$C]EퟪiQ |IzmS=/e{GeZw]6;)Goi?Q;ŘvMhq9 L\؀M <]$u3jA+J#.˧9,pU]E:V|wh=-؄zt-}7IDi˪gysZf><2A A32PqNHI]L| s>J G5o\l\Ye2}*&~]Ny m:VzL㝌 ?lh4 v(oD4+L*|ҹqTQN`\fl\[CL0BGÚ=dR#W˜ r4WšJhՓ?uBfWyٱѾoZݿ=}:dNކ|b9:| ~)#> *vzf|;([z Fu rdw(}ûnJqD*`lZnb^01!3 Sj ADj4\W7輀OFFF\#aH!;JCAZsaeM!0&rnFtHoN\q(1c1fZ RږdFÆWe6cS,hEz!?!^!J+Ws\xC+a <4EqYZ-KH $c8̾ЗD7E)1of!{,Q9IK/sOڂw> O_*>Sߛ\]K%.Dpokq}RBֻ<1ffj۽t hW&Jcg FIh8H y;!!X=e1A㶽c$ijWwX_+}Fݻ w<Ĺ0Ė9 xJY7FN]z\[pe`wShx8*`b}[pвV^":\v:{6Ag՜u m]u(ҹB<.#ޏܽ5=r(Z!U" XrܲG FDO~8f|[6>BHėl.r.0q漑6a M dd(8>q pdܾ]e҂vL.۴__R6}qȍq2;ɧz;繘p$ZLoÞ;("D(*WF))# !xվ{"bk2G[ ̯:յ/P0a}Vc JXS?<ԡu{Q$d@0]fw%Z- cP!lΣt8ܠzuV%Pwl,w[-LF@g]% 46 sI/pg/wXpcmc5H@iWHUsb+(o 52Ū,pVTzXz΄KJTxqˑd7BOfƧ #6yHحĂ4љ $R;'6IzHY.;sCJ KCPBaHeV~]qӇk LV?[;ˤ(k銼H {28Dp;4Y&xT{c a$50-1͑yjso[Ltb]$oL?ϡ7.LI` +{Zͫ 4HEj F $N)lgW an3@~ܹdwcY_N~Hz8tyk4{[% PQڣcJXg?^7;j`a[Zebgx~C>MWjn7F{؎vAaܝu phxHQ yL~-Sc#%9Bv .s*̤δo$62 k@9~pƩCvd,(rpgGtQjYyHh([790YV tDz= '됯hj7-}_90L54@fxAH+mP'50ݜpDzy.< 4cCX\wM0-{j6TΨ=PdV=K# y~|AౌwW쇤 G٧C=E|9#<͠VgZ;;ؖEGwA &q={Yyٜ^_hzejQ{IDB3YZAlp0?S}fPQ0'Jkut=,)D|qXzt6wB}Y9 uQ?" AtΊ=EG 4oL$mlyH|Bc]ƌ[˰u_b2rƓVdsJw}`3Al?:vđc3o@ri''Fi/< e'ARc 'D!(qٶg/w_u& C:F3S,L?)6K_y=VM9cFykoG49pF",>eY@@N[0?S$jF>Qc.ZYk}} 1 fVBQ  MKU4## 9.؂aIP AV=ۋ =?{ؘ37F?* (v=SϑLyBbM=ZP(=-44їwo1ȘHk[{x(Z9׶t 6Ùi&$q(lUTB8v/|`rHP4ggkndo)~u3^hja-xORY\YC ,Riq'}?x0ŕ}LkS-#mpm<ƥWюF$LK0}% Yس<yW1ΰ%-0c~2XiK OBo iAH\ 3g(Ʊ'KwcOȄe7Ivcc#Fʸݴur.bw-,:0Τ)Jx]`3voR8ͭ>L*(͆.sZ3|!c- R"/TВ}DBH!f-^Gl]K$c^YRD}{"x ݤT ?e**hS@w@}뽍nOzH Rd!DȚDZ[fx;/y5 Mji^w eT`sęCQ?:$X+.D5;2R7쮏fuDtSĉ3݊2OԒhv#ZYI В6? N u< -+H+晓qo Qz:%IU\w=wQO̓$@S鍮ISڦrߡfw!ZdRI6+TWb\LkVmK?#`}<Ꙛ(PS_q[?JΤՆѢj@q 8ǃL0hR;aѬVP窭 oqS\O;3wgIQt{ddG"kqGjd LRdQ.On@7?52:7N3"} @D~ySd:V7Y+bc\dkL0xnϭ@ܶY-KmFڷ>?$GkTJCURx}_Դ8\q*#3+maOIL4kKl𴿽G>Kԧ;Lf2hDhRAa{i$ i=uozUrv3StU6gT|xaz;, ׿ؽvRcsCe߁ƻ@Ykxzn?;S.9 跞mD_H ΒĚlR|ӁwK b#XGׁ=}~9«eyUVxnmˎ=eʾy1iEЈ<ɥMg͸oqtҜkE>03xeI^$d ׈zK>nϧmtz/8N ,TEH҅;M$cw2=$[ u: K4ZCq_7rp#9 Ū9!%ZϷSPݯq~k#x]@W ݷoo~dQ6[ I\ցVA|D'4~^ hamI Ec8"ywҔT}4Ac(̘EZ|bb:Q W} t,hGEUK#¥Y;@{^hHIV"2Q mZg;-UȞPH##rPC$ T<º|ߴL4IJ!|zIIVtq`asT-Heo9KiPeO?%M uz~zg'Bx m %VNpd]%G ƭT6_-ۣ^m JƮ]{ uD5 22cmB"~n*1 w OG*恽ƹ \X-2ʛ償ùErԱ|Qct X')ԍJuV4h8j#t%Y`$l3>č^!TLe~genġN5CvS \87 [~ x3T&䨗y \0EIJi}:OP̹7$B?cX44 %#wO 7 %KlRV8T<[c|˂@tk*Q({ᶕKK=L@#lFcn$42CY6⮢ Q,qu#,rZX]S>=k|t pnMTۤRGC[sKJ2*D^|}Znϓe%d%5teh D%@bOrШPv*&.1Vk.;zA;g;|wAޒ(oL'ecw WT›XtZbDCU |̈́BIMuLh\ڍ \ PU"ڪ"pjx9Qzh4k_Jx4#tԌ[~["wKqHcy@y:\Cg&SCX_`zWt3< uf .P/ʃ/=`TvH?4MdR}2 <"HsV@P;E$( #,R7Z3VJv+wH#ڮ縲3L|ZN k PՀ`PAIRK*pN&Qż~DMtd!4^(8gj+5D*bFۙݲt >^1_8.e٢gCQv\HX(m~dzkx.bdя_ yufO5!NP^Xq΀|R[b27Urf wUG7Ш[ `EuLdm<~Y@ l*k } 07i]|< -^fcrJ)-캹j+h/|_J\=f5뚠O12nmFvS r@'1#wTI3w_gP vo}f+ rns Bp(rfV14,gJbNtvRY9J"S7R TyjpBTLAPEvZd_Vzk#y 7ub=雝-^=6W>mSN!vɁKf)iE;+]b%`42 fl6@団WC1ZEd-{تi5C#A 6167'0ո@N+ݦi8*<ɚ065-Z̿T@iF*HFȍOjѶ=[7diCEBEox:=c-6>IgBw'#gdVzΤ~;A]L(_ΆAS׾#֠,G}11fsG9x>@t%f vp\~|CMmH"@zz[ [Gt$g!4Y"k[KSn&ҁӨMj  ;Y`ėcbv 8=M'jQx'S/U=peNZ%Fǟ[ ot/rXBD1ױ[hȚ9ā:v[q7>VICT|dk_%9I"^K!5x#E`Qb/TޗdR2 .S. VTO;D]w ;$Xm:uO=΢ל@hA3V%}z5`]aB5 A :eI]B[ y#QB+y QXS_fu>M47,f diKLg lj!>:!fH7'RY^fQqنY]:gڪ;y:-i4{k3aEZ%k* 53=*=<夗vw +n{9o97twRXvW3ۜ9:y7TqVR|Ii+5\t|-Û}kwq۞CZ2 Y Lv\:i&7Q#˹>j9Pok?wŔG ?W5y$|+t{NV߭i_d5Hl}<O&lN]{S0* 9;<"VytMsyPM)\,I "ohPSZx׿ bM-PUrR]UH\M' |-' iV( /^pdH))BI4QwFĖYK3ClM؆QŰO%*bUT7_aDC_t5X?)eX|s~.w8W[=׏ w֪j%7_[z@K@TXPY${rs6zu: Iř<黖mI%L~MzE7xv$8Hsoai˶Q%hb mFtӼ\m~DGYN68 ǂcWx2Hn\m2i*.tsODaʊ%@P X:UҪQ7󫉴krίe ^fk8j3pۉ-r\Z]hzZ JC1ڑſs 屈pgX,+~~(i㑗(@V(-X^hޝki(EY,%YI8%?RsPSnkOŏH1Ca ^ ur@-Rwn"+W6`I %9;cYp';l$\.)!gU>d[N'_5a.q۔u:fs;s[NObѼpfoCݰZI}9Z۶Ry\X8okWOx{,5X[0RGhiu&H%Ň8ui|ONjO7ͅ ,Z/=(bҝpl?|>OZ 6N)jj]) _Th OqSu8&pH9·u5LC|F+ jHV0_SNմw )>N#C(/bI4,uu|@i^$rw=cьfػ0@_"XgϿ/i@Մe^8sŕY@+W\ʪ,SudP5AI6'4c֡$Gh,?'%ļ] ene^\c a:[iYZ,VN$Mx7zW{I@dȣLYu@V47MQi㒑 dR4b^+ܟqMw79@W_,, d  nZ;_-aNS G6v+zE lE][Y[.0Y$fGHHZX4>`AĵjOy4F1Qcw "".i>neW ZP:\aѤ0!b-8EEuA{!IKSB1Be fR`6~&BeWc"aDk'$YgsPAjLdKPqA8> m>kȞƲ_? fӞTh<`9{)^w۱XjʵRew|d}(]nG#Oע&rC޳~κ*8rv@^sHb=负&o"9+K\u#$16""b)Ej|`*j6xD@Q@ܖ7\Wu_rZI+fd] KDs81[fFawDVQujʐƑc9lcbbegT,5m\aOqS3]VL2uxT\߷ Dn#>+!bz@E4(Z$,68c6R/j%HOU ^.@o&Ă Nw |7K7w" XInoBY?ʘ\u1>u/|M_j:4G?kIAJ,(7cBK /KzUm`t9:;W,7NP8z[ UG?x8:ZdWV">B ]n [&s :O#?V2&Wd^l ̌>-cT0.gonëGg|#7٦)8Fm:C 昅kG̭cpNRAb-8b|"f>1N\7ך?POqrFuVh>mO.0aD¯gחޓ@_gccfhldƈ5¡-r'݆T.f#B:G0>wUbî#^h(A9S^vy4]ZVETƲ7=u2E+qMž8mxKK\F#  ҩI'JČ_?f6Ta SGgo#W"xI&X@eT3btuoJ碈$mŰ(BXyC5;U|vKd gI`Ot?BٞЂ= ޵hw8=KqpY]6tTw$}*Y0w3)q> f$us(j!QOmI:X/XB0٫ bck4}3b˘5TN:M$ĄRMcc4 ;$ ڠ>g.ldYBp h=(twvI}&ʿ\I9㼀t0`E}C:EJͶf"FR(Jc5x(M*>ɞu&gRU .jURo5C&5fVI-ήu?8+hj ĢC!Ц6›uk!S迶 OpPh>_ם7%Ũsb}+RbsTH!`6+e?aK1T)zC܌/k[ UI>.v2ROB'Bݴ{2鶻SOfSQe=>\V1HD/JZ,vހ'F5ԍ/-6; I1=/OXu;4 8]@Z*jhYa`7{-WV+wĭ({-xP<`szKxRAS{U]a{-댓d3ч!yUj7%uzbLXu6T0dpsy5\K;vzEr\kۈ:v>sHFz}35@NdE36Se:dف}omw@ۀ4 hM+)_IR>)2nn (oE>q%۸ mVl7;(EFe\Ƃ 𭭡ȵ.TO+$@lx!E)+C$\.Tzb[^Ҵ_,2]B{8!cPM` cq8^\Ghg;:MQk,Lk cI}/ ݕYJfᔭO[&^}6܈f Er&<&fѴ2,ܹW:aE'qɥziun7A#sL wgL_~X&ûTb\ f*vg4)ޞcKY0L7CMy=KtrvAk'O68[UOe@llђmb$`R,`j,e!,%P٘gaRogLC0K *P1,T0{H՝:Ԓ|4??M{z@5`JnFI> `\툛ݔt'Df9 U= IӤyRs@:lltm Eo+%EYnUH^K0X/0[÷w+[MU_SbT&?Ucm bړCB=rw-'DsIHk ߯q wbiUciݠzZҪL <-4y{5b<9F.ZeU!)N d@7nЯU38Ra/ٮ];HqZlWЃ$6 5kRH.ﱫF; }[IeL OcgU@kNc&E) \)VzuS9BPoI' J$ЌrÇltSSEKnY!@(=SgexIE7y&Ͼvp;?|އ[{tw;&Ift@hwc:]-{vXcƞf7O2E͞XItj$ʖE<6:>^yfh|u \(hɊk2szģe'U,ǒ P]NՋƦ٥%'7.j3Bv30aE2:=8iآC]tC=9[goVԒBr 5?- W=wyEi8R[0#2bť=#paD(Co=Cįػ2ڠ au#q>=cèPnv<0_޻r _)NKkn^%0Vej)|'t @Z{$Q Qh\c'ڢJ yaV~P<:LWspGgE~!lS|zEHdN| |4X}E  qFgeau7$h]^E &#Gob?p7)"W[~(|vBU 'B47鏑zL|BQM0l7cl9[amۺBv1ggNRL$19#o}*0|zͪ> :U[#_&"Ji~lijX qCPL.{1m93ǻxh:$["*yrM.2>;J5WNlϖ"h<\MHcoV6n遚_Oq|j&V%*N-h8"BR>7Zۏi~vATA`Ac{h;Ѓ,ET`tf5A8gVFJ{CY^ޮeA Xr8s9Ǣ2[~4l<-(uP@%X8DsZVdy *H#~P1vmh`6l-PwYNj"eLsI5 T@,lojїS$G!)hbRFʭ\U:h+WTaJFzh" cu2l^]}P3'ZϱyK#^t^sxX(V'R(1mH8 /:C^*q }ݗ/tS#6kjvImҋ{4s}֫SI#rrֿˇI\秩}Bk69?~ K)͵#Mɫej6Z`?2\ ԕ_2#R @ "J4!N߂D/W$1}~khYAJFM6?܅ZpVx ثmJ"G_E_46YJcE4}y3}uyT~رS:p^ܢx WOcU󀫃NPA5dt.%g3қ^41lL2 qa) 9_SJL.L5sފ]jU Kꉟ!;H=ÿ|g9iG޻ߴ}M U /Ӑ"-_ӓȱGie?j5T hdn,@rNQW{ngDmw!y"NDc+~w4\Y;q!l EJK%kĔJEiEV#QT <&61G*Zk _iP)ZlBFQ.6ᏑAB\a:6uI@{Q7MtY**vvuΉWJK5/FB|ub寎b m`z?` _[4b#0s$IU>gt-k&Bo2"fF+bKOPi޵(ٕxb晹Dpa.+ niᵁ.CF\%؜p l4 Wѳ{Sv35iq6רgѝNLiJɒj|xX.~N˾76-!rTźhm5a}$=ޞJ4LƬyt`LPcL. iMX.&q >MY(>z4[59irq>Og&񄂪D-w^mE G%$zv)AgziS,: z 0gJT ݪos~L?<r#q%}'{96VHh>:=Oʌj(=24ͬ:$.ds@:JJ8 Шi2[K`e_yÿ}`m)ڎq3bL##ŖRiG퍔0UţWj0Lw-@mtwQkj-BgWZt@D}helԲ| vN5i\͢BM=kq8p۶uv3-5TF쥎(N1ڕ\;B0ђL]@8;s…ՃtXfOb3mU p.ηUܑ=g>J.%Y̝.oNq6٭p0{Fr;e^^fmԙ1jꌺ]ܰ+ۃ,浱4)`/ik"{f< PvcSA"_+l+6 g|%Ԫ‘OJ= x'j34bVQ#,xtN*$i!jL7K$̟^'a9*eՔywEu.+vYT;ZDc;@Hm?bR"?VCz.rX{=''h2v!6~yEgD܃dEhCm fC #t״:kJuƇ ?C&$[Tײ}#{d,_&f :)V=eDxNgUVPcq*vs|ʦ"7*he'>o)}߻ʫa:;^R12 T'gH }O XJRE9/뾥+>sX[j:qfc@9G$`j̑R220]xݧj^Nd |ίЃKpW8ՉjEtCSϿe`O`1S@iއϾܫzHD7ȸq31`g({Y[} p*%] zrj~1r$نim5'5]=^$lJ*Vp- )X~`5%"ߔ:|K5w75P_HѰ'G,_ZOlg9v)2`Nm|˵lC?Me=a۞ڷyN鐈u~f㳃3 [˯&.|blE^ eЂk4}Y&hQia/lJ#2Ui3O`p0ѸvZn{LB#@ ֽ2EH7 da 巢DGD)x$}_qiBlׂ(=fbdo!5Dn IO<=EIl8?R;V2MLh.z`hu 㳹i|nkD-VYnVEb_Ӽw}^W':x$xA0g\3hڦ3 .rRH5b(֓zV$T'cٔቀ oٹeel{b"E X-X.YX E|o$D$VrB>ifߘ:剧.".,LJݗLn>Zԍ'G$^,~~ .v)k @hS4ٶ;p+Ox $'Cf[1 V7Ñab֠ε %$Cق`t0"b0H (#BK^/ʀydVG^a31nTҴ.sJR}5S0֟ :o\bGU04'=%LxĹ~:Ǒz{z&FO|uRvU{6V{Z5;r a(BiMjޟY / bfڱs=inR?]UEڹEBneti-|qǣ<.3qdybVC5օqVHwћ?Ң'&ӨKpXR X#}Sʀ(Rlx fюx2 Q6QO},T>sꟁJ̘&Ԭ ×mTcs :Ͼ`an4SzCwy?"Ae޻RtH[QI&|StoߊQU!CH1_ #xl,"\Ƙ :Go:O<8eۅ86#7-XebkK $O;˿x"joW]Zu>HG\acT=k.gZ0f꩷@pDDVJ6w'k6LlǬ0wTc5ZdD>ԊX͇- R{j""PɞQJ봈90+]cm,bMXγmZqHfP3d0T]\F3\<ڝZCs1 ۄAؼ*4ӕԹbt ~喟uJ<,ĉ&{jߝ M2(Gʫ# 6@chDDECk >3 ve-=ݚ5K^kJ bJ$f WC @p2.OT`Pw'lm Nk^ wxwVẽ)$ \YpV˶MnƛSP$ύ:|VEnUra4'{@Hw.~MC <_8>twyl+9=~.П3IؤpB%]Y+?暕6 #?Vij4's 7c~7D 6tY*ٗ]3=C~",uYGdo`B 4m[80X?j ksNb!|R²t{9x~,^UN0-3jט -|AI *ǀ6{]8ЋOA]ctgh _סoߏfhD6ho9sމ-f0[Vۜ8B{'ߪ7Jv{) z|L7pid-^2aAhǎ7m1\`_:5m-Z"eziW[U4EG:주|x$rEzY%V.vv[iBi>`ė)<tt@\%zc7_oj6 SWxL4IxaC;p4U1GwR~e=tG–Mb-`0O,4DɔȐd:2d;$^4x_j8\=`'c3%f+LtHzƈ5b]1 *^/GaYDɹeˮmvmy3F6*q4`rK%s8B4MC"evѯDNXfؽ= 5̖tBRxsc!gt(DmL{EcXfU(9@'wQ8\0|!}yۘ&:d9&lt8M-NDծ{irƢ_zg3r4 Llǀ/e۠G68zDT?f.g^SY4h@4DjݒmZL"@&ƚj]'; , {7M^[gae;>9tyQlf?d::PDjͬS.;VtL7KpY z}50tރ#EPQq!X^,⠾ Vr5E0qNHfj@Hhhh2dC^>SCp* 3Nͱxk\"Abn/2l=hD\5暖ޫܟUwe5uAb5lc]u\V׻%; 1[ٝm Cnǜ~ׄOl S iQ1V,\|Pz$ 2:%ͳh&EYtDJjVQ8ԫ+oZh%Y.DJYgYk D݌K.[48m{شyv[Ҧ{ Bn+<sq nZBs,y z8Y? g"tþZpEO ڑ ,=TI rЏȚ y*Vq-BaXJ_H'PbBWNr"">v68 KOdog-?`4\ࠊ?fMxmG |!}K>*Y~݃;bV M^ 0qDy s+LW'~[I†ۘQ3r(}ˬ†FgɢE&aeDاnx 1e꜌Gqj& `0v6[:%)\7w O-}U-c6ު\(y}r8a6xpL*ž"~' & | 3u86t_[Mh0C]}*K +@4JPgVj~_N8bfuk\{Rî/F 8 2ә(0%|W#kڒ_ـ\R1D m xs%^F\̰V%g+V%$_ZOt--g;ׄYwa/8f*d2/c1~6 Re1DzIMenRɰ'Ņs^YUfFQ]p ?($>J8 Bk2wT-˱5?&m e%V'A ®d/{q`/cAOy Jtot%|_#hbUbD_ߕa4tUP5SLݐ e54P*XӸ\G$$)z\W詴kzxLO X/lO-ivs+#2u(D؉V1^&gOͲwv8U^aɟ;EC %vyט"٣ˇ8 )Z:UѲuUA@{,ͺ>#W'[Eu.N EV +޷_?%_V:?,IsoA-8K"bGߊ8Pr4׶"BwWzkQ5n b$HpsKf"6h!1[Yؚ'L `hi3<+J:bՅvOi p$+N~"?ua%4fs⌅r߼l_ FJ(+a`Ƴ4=&XkW*UF>ևoM:"ҔYCg6 7 {s@׊ y`4lJ*1 eQ@E] 5}ԝB&pXИlq>*_b9NBR־w;QLYK^V[M#苡 d3\㻼jf{ Rmv6wYV蜝rFS_,yԲ9g8q[ow0"n}Pb=g}η*%ݖC_V[_GMM[^ںr$2u `m_aO&&rqLxޓ :ZG<2$T$hWU^[Ng:_SC`ÝFH2X6h%wxz!$fvrHt&s͕#@2lCYLH߹+T||k]K*#ZH6f++~@M0O0PNӝ@ ^x,96ꠒvP! QBkFC`}Q@ol0k:9Vb T#DrŷF)C"k1\]e% 1#d#T2ET_q#o_1#4I |.~ut! P~NT+>L ljt!c]>DER~`,._J.`P["2/l>^C@1'3F7vҪE3@!I0j! ="볮2\j~K" U1sg^K嫱q܂ѵ:gS7O?Ft p^ogs 29VXG2%yr0vguo[x7Fj&Sh[)qK7oy VA͝E-! Ek!G9pf"w79g /.a |V0t5BȉCür*Unfulؗδ{)T*b Pl$g?G]3o-| ]l} gvh"@{z`rP^oߟVt&e8sL&_zês}\Z1MҒLe3ɹZ8xE7uF 8W᾽L|1.|y$ű]hl`0:R J ,n* w邐,i\}lQ="fl@:^ƿu0 tad&P}i9}`9ֺ*@IPh .?dYsMZtޡ5/"mځ‘xʰ!Wnz' S-qcʫtW$4z_WcS'< {t<|#M5)0cT#"UG[s;]~^*֦>_ zv5W׵b 2t8] r3U;Fz:L|Ud߹#5D؛+/C=809h׭m 9˃d$6HS+Q(&:}d=d:ꗸʧF9tͺ^QYm *K nNpT vK'f- b)$W8osZ}[@K@gC)WS;?nuծcvwnG֥Qk}bE2G@-g;T:2͜o KAܐPl*=GXH n k3)ǟBDw#7ÈeYjȯ* ; )3Z3 jMr4\].Am2fAnf"fivCjG˺ضV>J/g7P܁8NOxG a65ҙCySo1$BYR(Qjy/gw)eΡSE}/l>+ч XfK;k{~f*U涼03~rˮc{Yߍekqo+F(zן9.^'曗Qڗ '-.];m: %:|ٹ8qEP(8V)8s{Kf#x=}v/ϥ  M>Xw.+4 ,!,VuC;+su* I2 䓇ѳ"6 S:oZ] hN+e7+]cDfPmj+[&PB~~}зq SB3[=a!A4!=d7Zt^|xBd `捰籱Qj~4Y~!VG8h Gks#PY9[-2L^cb~EJDI`I:_%D0:tb[9ʗ5DŽm -/(d,Q2*DV+"Hpz^VTQh@4W9O>^m [m,Ig.FfmwcEC.@ F͒|$:+=3#hqte XD/&ꈶWa[cxJgL'%*mie9/,t̗(6)y83e)g+TO1H k^axu\~`4MgIS #uo@[~ b("GR嬶4_ZT .CM?]H,Ir{'46x}f dwTEEWxƳxȧU7s2zI|2gMZ;6AWR3VY'S`bͧڗ79+IdhY\]CT)kxov^%h`tt;uR@#cHs $}nZ<3*m^B̩`u!;?|֟Q`)RgK t*١" v= wtwaL[a%Ll糁`>JlXQ&ԝ=Vo0jY"$<au;F?ȓ,E5+ 1XP!3M$ᾇ/}W^ w?H]*EgyuR 7 Q)h{JQSm\o62s8l @p-kn`ds8֌XV?#΅TA *9- Rjg+b$j^Z;;Zoa#71VD!#yC.iy-75gg@ krú< y6eOl6F3dxGZ+مV^Vv)(9Z; v䪌Gq; Vj$ %4PTGʷ&7y~Ͼ@\Bg=tx`"6y n[j |*D1;VmE3sd_So9V HMWsjKMqvrx%al?MJwq go#֖2~"pff^d<կnÿ {inW.@oՏlW(3GUJ^Z3d@8{IiF<>}T4Uc]-yme$fgfI~'ޝ,:'sOjV)@If !Jai[kg?f;Y9/+bhFt UN0HdO4@.=Ķj͆TR~_I/Trg4aa[ƨK{=&enmlJ}Gt3\Lyw3kk"vlN/mD 4(Lqv}+߇@N8k՘=rv@F+='Qivy Q,\'T 8!Y os=ˏ g"XřT=1^KD.n~Ξ ӯ7xpWLs2B)aX? i=р7kv܅nG\;ybb<^.DG zܵePn)Գu^eFRf)<C J y{|tiy?VT~Ia*zA:A?N'6#2h"=ٮDc VW}HXIѧ?i7lZfбLa2^+`jdP'nMUJ"/`VY⚟Ap=4 Gcu o1p^XzT2 RX݆*тx ˣ4mpp.1@O'ޙa*dOoUrf*UߐBB3򝋅Q0KNN EȟR9tf-I+'hOɝ>65Ta-hDBV\d&eE+BEx^$+ C5#^3Р(p&#hM~q2ڒx8{?UV8A 6ho)_ .U)=R*nLs<^'TxkjԤȃBuh8-!V;p*/\dpPɇPK\h`$'0:#%Q|E=1U綐x:_c4znvحW\WH}QK[|<$29?DC,eؘЊl-~/9n{N\ D f&i/E|)Δ@Wpߴ%Øq!U ~X]-s1z 5'=P. ,m[ϖӻ eT*T"4Ӹ"RşL _zglMg6q:NjNw!t\c"$Z[hJv2N?jzJK8h 43d^ N7yG@OC"{zp9Rk(b?)bPA4c&uJWt2= (!{%I&=gfi4CxP9Ьb%J5³' &[fa|')qT"*98Fݴbt㘬Z"n,PYe<~xw.7؆w!P/C?d߶S/HS0PQIx%Tg|ߑ&3~_#%M< ~8w+_eڵUlj@< :j*@3ʆQN5 s-a}3FDKK*9^KV/?6E-Bv! v@kBܥ>cy-o~ݭSEvr?J1??J͹큣1].VH`L*6,c$wH庣 6f,OUfԬkTn3lH!p燣rJ+ 3[|V(0BCj&X8}<->M9; )?ˊq=PT>.Wj)pA@Eޢmҷ*Lh #"b;qZ})۟g&(N)c ,E_毁 p.5c];=pL"Ƞ8(CFoD+rͭOhA9 ppɃ>N3ݎa7sk0\;inCek@'<(ko͂J!x^*`"F$V?x㉼೸0hr;NFJ]$oW ?Ч>y9H&+DdFVrjRoExЕQN`~ף-ؙJsm>CYV@ەzusi_ ȓ/jDd1$jȧ6|);4p$Ry`X~*ψN'Wk:Rh71H*WV ]KPOyj6j"&/w_i;{w󯦺,_,'ShWߘ<=,x2϶P, ]a,(p^4l&3?l2g^Z JE1./%(H1ˆDd߱Y_GYYyv`=[c7|_FW_n񌕕eÚK 4mۜ *-jY)֮@rg&n( 'H8 אn]uئޕ9AӋ]{E+vH$Ofݬ1ROx Rg$#6Eӗ+q[!?N@$xIKs 0qmzyw }BQõ3#a/ju֙X,xpեlFϸؘefAġ5E!%ZN_h cg"[2IO{JsDGeH6 K6p|2, rm{BRIL=ϡgFݺ v{NnV\{|4r7. >xbx]maJq=&d?;u,s3mC&Y!W<||B_xNb v`fjwqxf᝾Y'r,Àϻ[z)C rTf93QX V9@ i?au'-( }KLL3Ŗߓl`՝|@ 4Oђ@jH '" 8Kmlb˨"S"O ! 3ik0|Gt{ w:6H NsmEtۭJw0 ?˴by-d#x,=Њ3^bހP5K$y.:2C2P`!BFϤPui;<:l| ]5m t>k0wBAQ%؆I#\Ls^>nNହȾ޿t39aV:R m花} U,^%~a@O-|T`3Ys%hAlrr)mRS\+2_MxpʄTx|4I Jq!q:i ˄+k<~oU78qvPfO-^ cA_Tcf|(q ۿXMc퀵Dɼkop; b`5tms5gj áHLnc`@jL:ͯʳg,+kzqI|h)dS>RV%kgח͡kܚ^ު"/PuwREp¢ۧ׹Jm:QvMo2zDc/L7ssq+f,)Ƣp.肄qf4QYvtրEZ2_%b SfZBYA@ذ>>᱊!0McHw\7zKdr3PbrGBg#F5uf ș X5cerv%[6@:j;,2Xhq~7ڡ&AZFb(KJ *d&{{A!OTjJb#H'D~_\z%:~‚xd$1 }h\=3ϯJt}]<=5YK=$76NyW#oTsнf+(IxG+QSj'mm:?^&2IՌSyHCGǓK#^@,f3njtQ {ܧhln9i 2ױagRvdı)R5:>Hrm T1y`rt=.asS JA/ 7*Ba zgԜwDaj ln%jKӯֻz\.8C(q,l%jLs92Xv%&l(KF6?8Zye9]ژ #? ô8F,![pZ}6$2nkh,FA?[h,l#ESԺ'{ u]h.\xDKARD?%~T|T vt~Py6꼬3C/_ywS-Z'mvG}mȋlg q؏$@$W6,lnSLSViF I: P)m6WTjC߾h=܏D%h{(bKd'* |@^ŘL4Ѱfkpޔז1ϳQӖw|GG9TD(w;En5l{*?U /xb?NMh&eSeJ0~#WuquqtVMq1^`ྠ%z `nUVzfӊ؜qZ %S/ ](k t c;!VUD7U̱k>3J:? k_5bT̮ԓ̝`GOCu_3-n,-\u߄4Qހ=m҂yA֫93Mk-Si7}|/Ɍ`s`ѕB NS.OGinji*|yzuEwwȁq)UqSnkPHXN{0>AdFT6,du J3|G@:bMHC59#K]?3RadOt?ZlQ~CusX {68[)jb@K;16jF!S. S3>|ʯ{=F3|R>>Lg`Y<p0ҧ*6r}uc&tp@X2ɱKg^G  K7 VFYj#A3YKnQyq9δ,EW%/&9b3)EcQ&( .I7NԳAw ɱł>ñ Ix5z|gZ߻jW"o*1QηqI'5N "8/Brbs] n?]<{PoOZ3]Tsi|``c8i$2YzRz`w:aQןw*y,˸*8_O81zV[0Ej^_Fݹ0I_aU܁Rs#` HAgۙ'`Z`S \'l:8^m?`<7z38vW('1ewZQ@1;NAƖ2i 9_z-:M6VNl -ۺ%>Q2 /% !. fTO$RX{oUO~vMu 2i+cvGk3 i$ [vmEƒUwDQӜw`Eknհ!FT}8<⴪-@6cH*39@S":6K~.0hޕ586;|k_GfT ;LG4(3b[^;o yD&L$lyF@Ѿ+Yo홎&&BoՋg}ȳZeJOO9AxQwwR+67K0lfvg*uem*Q1iv`(3}Rik7B^[2E%Bƙ~|3V}ݻR[ /% [ r|Ԋqȍ 85">.trCAGEYD+h _|@r%Q+I]DYhKABfb@7#]^lvyW?%A5[1CIVyt s. ;y`6}?8Wi۴N7}4{nW!IժӜM(Ee悃C0҄L1?)~vN#\/o|8VE=I7-nd4+^j햋8 9L\̙]Jx1^сyuh,fy32.~>E$a݇|j߀ Tog"i-'K +TDq zg]LbyH"ts #ùoO:uXA=zfZYq$CY֤ 0<D4*a9嚹?^öńL矓e|Z5n^ʈ".g 7=@Y+2-^wyM?!@۶gdhKϭ{r?lsr[] qVO/mU!Hy[c-YT@a¡i\Mă+`aB3ckG 0gm]{ZO-z *]p YehB4|&,5[n%[MYpɩB軔fQɌ?lsˊ=%N"^얫l6G_.Q&x(@L%c؈o:#LPeU>‰/վR(${j'mӏ!R$CfI~,.s< ]5)ǵv\ ([gк`jP147X8.JTD.Qb+{ .n0 E iK|g7Wp]c4)y>sHJƎ&(ous|2f$aM ~Z:NG,{:DdTfϘ#}[(+lK"?2|m[6ǀ&s[ذ1joڜqz+$ܻq_ǝ kWw'2/FɲU+:Xl=z}4aPLQ{$ec cq6KFȦiq0|ѼU^$iLe%6X9y=l<Njn?OfW5BEuڍ:΃nm@6%d$$J' U`EϞz(P0QrYC(vm|g _r>@Ucukn<PANmqmreDg$z|2\:dke1H9VSp'1٨9] ]䑜ySV6GZ7*'187Q)/R4U^fv>eHї51Sc%@ !H8ZjXߖE+#.]Y:;p!0A0T ?_)noiP#J@Nm?dx2pS|e/A mnIwC%"0n>Hu+$Mٔ 7p+M J]$LN搚uV5 Xh2LA4A#{##,6VUL_BJ<aBi aۗ\࿹/CU]Y{t6S^ѧwYbmp,zY2C%5_v,jfԕ!KnHY ~5ZGC$L.8v]BT҈6F›ik)JHY.:?B3rx}w__¯kքv8bԟ:.t.~MM:4)<ti1D-ue\#hp$qW޲rL=/TKxOӑp֗+1{VWY®7Ow"X/G ɰ0|xNw A[H^P4U *oPfYx8Y߾XSʱc-9 dq|rK7$5SZv{+IM)"b弋`db5fu}n{|TZlA<XiU_(h'6.aˈ1;~k}sa%)l.L 6uܦfK^)g=?fIT+>nqNQgLi:\@D0AԹ2RVؚt)/] VA# ([l>34ݐqfs+xpB>~V;M2|a>4wM{2R,D@):jvBf#3@9it} >~i- v@PRTTZj&vyIR(WluXdǼv6jSk~lȬm="g<= @vNb%PQ}(δD/9ڊ(Bu7ە8abg 3eHBI{=ZH%_]z3|BH} emhoȈ5[dC^DRG0aۀ})GkdqYOoSY уrNT^ut buy֣M?nԯ%ba3 r8 \]^/Uu,}.lv5Jθȥ*+jQ׆bZ2`:qxnWrOOA۫qx jD p|'^q{Lj0ZAy]N}DIZoG c04ijL ͙Ac6kIUfVw9a`MYp)`= }m~W1Phc̟ݑZ(9#@bΈaly9uƐs|Ԉ :/E)ʘ P8&L;|}~Ÿc.Q#DIŊʻI8=<]~\\DAԕ%F}6$u2,ߝksWyݼkPFcq}\AOLK`z܂ðW.CDV/ .BB v1~:?] EH!zkçd}QWlg Z J" l4JU#U'# $Zhx{.FW>}@]4'Cl:--zt Ѣmk Y@EWw{7gȌ+f7N cڕNy3Ic:z@+jYդBKH`UNИ(W*='_qcPu$җp'lR5cq]"q AIkqn\+&3볢MHOLq%u 1̬鲝;y$~[>30 9O*/Ό;չJ`f,ަcL쇽O+ $=v,|ѼڻDxЗ'bpq@Y[{dQh B[ ͊MX΀P"y'')j\?e7 e9e{ѯ7_/)y^Q&W :r) Wpna}_|x%30:wQ"CL"-S:Ej.;Ȣ'ښ&3R췂5ҹb E,o)Q`:=V~"%' +~h['y'"G&1j5f^2Xׅ?j/[U/wXAR0m5=ŭ3ȅ]9L0bXr@Ѳ!Z(nz䏶u0`),v:e)4]L8ݧ~V*r3drAgf⳼MT5&A"LՔ]J'm9PL+k'T:fJ"ibV R4rbn%Ihυ-z`D@-6M&w#M4}՘zh)!PҤǀۿ>I|z3ҽ4v_ hLgD&̑5WPob_E40T^NFms\W5l 6A+D iq~ֽp>r->j"r?Y 3  v$|"G,KR[i]k"*.Ż#УUeVꨴGӊ]^!)YT5\9X!q,KxYK6M1%^1;qO5*~fN$ߡLԄq>1=idw-Mc}ʒ:VMX/-nT׳X'ၻxYzmd*i#>$6 3_ggͥݳ+y׬wL.1R=e/RB@;[in/YP|p\&r#ԻQ6[X∗\`@ 4)ekdua"z*m aЖ[:|qrJȾ_ ^AlӔ<춮0Qn%!@lm cfXn cIdiK~D_K'τƏ'xoiQW/eOm9^$%NL9p2^Vͭ=f=mb>&6>:^@;4cZ](4eE{!`?s~]Z*Å4`AK8Ũak; EǷ v{ jWZbFɢ:1I̘[_Mlq%"ESC^&o$PG觹#a`x6OcQln()R2n`vu÷3Ⱦ~GƢ.(%iܰ@ckF̀] #cys -#cf+i.G»LiAkv%Q5'͛w#4"z`8^Ҙ\i);,[{\с. kg (`R÷kY$Nė(2˘$.#8HtwFيPWda6oqEDq'b;CI]]F{Cڼ~BPDKR\GXy)@= CSUUfR*,ɱ&.9?DC/KwJ 6/% 1Q:r&A"4͖x YH*Jaj:!:x%#`<ÙlTJ3D[Um -d,y+]rV^ T1a" |BmxPI7Y<(v۸bҊ9$MlKn%3;+EJ|¥ 46+c qlyQ. ne?#WE [4WCG5?)kİ+kn/98dT6G[ ?2֜u YK4C/Qɦ}y#4@gPM@PgvWw9e+QX8~ h-9|SZ*WN1U'@nJc$oSˍ< '>HOZ=ȯS)DW5/C85 8,`fIG`8ǎD@9'OE'v#P8:ΘQ¦i),*f~גeo&]6nДN݊[bs zAL"QszLdtKEg}UQ ֏l{;1 Rֈ`\YfZ^%jJvnJ֜m廓52\PF3MU.j`ia*C^9q~Wjoʌ,+i?j+kdzsd(,q1 2?})N5w#9=a"r9|'D+%}>吙APR՟F5jBpL~ݨ@pye8+c5{%kyu.Oʊ5<8Pr Eca7zGmw;zJDy=ٌ"G 6Ga#c\׍aE76 qy~_叴-A߿Z"Mބwdmz Є2lPӇRJ痆H;ؠT U;ɫgM.\S"o@bkS%3BӴ fwblhyLFB8,!J=b@H Lhlߞ׹$8hY/3ˡM{nyd=zv!d` ~+E`=kvn3''T 1GhH&thpҥ؆1'A3@5j ?@;iĂH O ! L|YhEQ]'"dRjc3[L HݤD2HgG:)(a!hfSu6@DCjJ=u-9jJ,e/a:=}*X:NXOQ+.ֽX=r#~~M%)vhEFhېI" T\*KQia pM49[C}̺7R싴.*CF0keοNq> 1OI,e,c{1d2}yg<7cḩô\X^4V8+J1۪)s@#5<_̂ؼ&| uIQEQ) (vdѬk7[Lxn&ߠ枔akcgQ . JGǷm ~i*"mbA?/[%-n_Xyӑv Y P@=hd7_Q33lGzsTSƑL΢g¾~hXsG_ ; #j 5:4RvHzuN FD j&pݩ3#ɑAΩLx{|LT} a ;uj &W.,:߾sVMhX=9ڡrL_X2I3?,J -z[,I@g@UXCꤷ 1nQp퇂LpkC~ iU"-]YyE0al2QSV 0r$<={{sɝ] {3,QЌҷS̝ǹ vvu{ߪԐ.{R?HpW@i4y=^Giؑ_?lWXu2W֘n̿Wq3 KAdyQ9#pO>]W].Fxd_LWQ6mq5% yc}*=8 CW0@Bkh%7/Jcu|E"\$n]rN?v2OYkit>!8^D,4@g>z%k4KI !0#BK>+ہV4g*Uw'3UU~e j#B3+6~>[z|Gr3˗=^-b,&΅a$E{,C-Lڙ$nR]t,Ӱ9-P?Gf,!8D|g$l͘>%6nRf'K/pFp$+_mDxHWЊo1$H5$-X ij,1 7 +ìWj@;Hhfs Х7o.[eQ^K,漬w.}*#3Dl si(cNFzp+u}LLY+*~~Zh^F\XbOhފ.Ruk=I I" zTj ?">V2F?|e:xW'0[6-m.g 4Uzq>m/ze :ȶJRHpSݢU-!ZUMun6kq5w꨷liﷹ94;BӫT2 2ט06j֬\PQ/DdmsjJE[xW4#֣#t—nQf;zΥ8'#)xW!>1٧fi%& xh uq 3}wDOǟc+>kS8 +g+07/&i'* _t?6cpa{[ţ}nX^X۽X̩ٔiҁݒ5`~>E]"\H`M=A;t0iWcG&S@$œf[lr0obzh@-V0Cxx9d$ކxxqA7m}S[nȬ&H 0|ȳpOCy*]ͣhO H=Ux)v=7 wf@/2!!! K@G%5A~j[Z蟪Q_Is2*Qz_?J+~yDc5"GMz[40)A^g3u4Sc/;DK'F=8 q*h7(죎pB~k.r@ RQYgQ`ͻb:&>G VXhϑ-2<:/<; q0;"B|SfJ e{yL = WAiW Da<{ wQ4& :17eqS ]B]je2 J:)yԱQ: 1|jG1_5*ٮ[kʕZ-}Gr~9픳2Z&()ī2{',M)b$e-y+0rcL=ʤb)+YAa 4Z̞r!@^Twgr1IΗ ao41oރm]pK ?rH~͚Z\*M/FhgT;XyzYIQtcfO{_ipN*xG#ޡ%r^MњzU*raPt Z_B'Oc2sb5J3䦌?9"{PUl9T[<4ٸќX/CY!3qA "ߧnwQ5%6@G8Sg&IM3ʘ J)6{|g|9~L>4;tmt3ԅ8e n; ʴ2HIT~a'ݙ!I"DcItﱲέ >ۏ*9z {b(aM6icےISw4u#D.֝LtǮ#PhRsƹv槟7t )6dhچs.:\W (T0l24 ;O2/裂}zplx @wCH vowzʓU%'1 fp܅MKNS/l^:+ܵiRm /z%U #>(ZH>Epn銵%AjRUd)f;o2Qj/Ż42qB‘Hgx{B3b0qe/Vʺ%!g7% rҺ!EpnM*u-= ,qk B7n͛Jtm~m{r邁ܶ`T:| &KMlxG#E7!tO-f v([7$x0B5A q?c. RˉUYI`eܶHe)׳%~#ˢY2\+sF0@oᓪ̆fU)Y8ޑ\BQڸQ&L$S*H/M^gs#"GΫ((LS"j"ٱcRT8nZ_[ز$ۚ"sWN0+5|'GT Zs8]j`9HRJpX> #c~AFdJ;Ts>'7LFahHg&Zc5i EQB%WvZ?_I2/. 2h"{ȥ6YqUӏH9U7ys3Z{oMU<4TN)spE~çfn0/_@8>`K %AuO#XX\6Vj}ȯn 1~$U$3l*lvc!]36,oOK0YX5~4&=z̩ ܱsID7YvVXKaZ['xDSg7BS& c1Xy98t9Ҵq+ ,9 A\>k 8DqFdo+V8 -8?G+I`U+L!-у|MoIdn7oQR % X8!J]wV ]V'[J[؂]/13Te (!:m d:E|\%0( ]]YfڭMbnY0121<+ž ٌ_MP "r}ͿAm5:Dc.i|H{():@SZ¼``+fcK^9o}Ǹla8jL1/uolk苁jE=qȝB/ gOFRW_odO{J\Jͤ'r}AWT>oʼnxLLf ơJrz0Gp9sKp{E[Y/(Xd &Qx~T{RE}M<)z4Z:_6'tPCt4>@uEp:͠ syj\C(\d`*ecP}zhJnW{yVJOZIF\ ;Os; E;&a'fIY"g]{2vߒ{R>`.JXdyZI;n b1x]"XTGL^<2,>;h{2hQ>]Ja"4BWq< 2Ă)Pf C\4SBWf%,x 79~4:4ĜUU]J+TWG3 Zir.*WRÝ -5 3:ppK0GygFf8P2?@pM' 44T[z=4HZ-ci!6\,IU=to笽LRtrC9ʢ=./HąuZ L^kxA +nf̳-_\CCF;kmD ,rO*Hv)%)H:=QBTa{CIut5ҧ]hBtWƇKzu&l<^ѻWoOG4Gb1I?Mh6ud6J<}:`$n'/gڃe`P)>IX/Xà)p|㎀$\ΩgFe:d{$H~ﮙ+9[qqn::v9,@Pb/7>6 +9AfnC#rHd>1 *do'tEEs t}fTqָYDג4oCbt>/n*h@Ih!l9X|:6PlѶbpO%m>#~vƝ p KL#YYSW~?^؈Jm5jQ41_f/7(mCȃhHѺYWEM,H&"7uf9hkmj2Om08*c'dՑQH*_m(nJg툑>*1(}nU0q" %d(=PzTKքIԉieoJו|_([& y6Z@|1i(#0ºҹ0!ϓ8 H=QQ{h`@r!mU iŜRԋAFM0 1+Kr*"i5&=ÄY}tYIl.:"(dbS`evUfHUF-K*E&oVTRr\fXIK^'Gm#`p6Oz ܥcZп[| 3iZy휀El;57QP~1mZ:]zr4ͳEncl"Rٽ,]Iqb ^SEkQ] (MN&/JgФ{;8Ioωi3=t ̟˶ YZ