apparmor-docs-3.1.7-150600.5.6.1<>,hp9|{YHoHh`%_+Nvˉ3ܼ1'9$sE195<oT0﭅a6Cuʆyp\sZ8a{0aYl>lÂ@@TJek*N}e5/Cw{QO]8y[s̟-{fsn 7SV{DQE8F+ٶyd@ ^ [mk b眳1Jkj {/?UAQ;nX@'}\>;?xd # B 5Ihnx         G  T    @P`(89h:^FGG\ H I XY\ ] ^bcdEeJfMlOud vz(,2tCapparmor-docs3.1.7150600.5.6.1AppArmor Documentation packageThis package contains documentation for AppArmor. This package is part of a suite of tools that used to be named SubDomain.hh04-ch1bSUSE Linux Enterprise 15SUSE LLC GPL-2.0-or-laterhttps://www.suse.com/Documentation/Otherhttps://launchpad.net/apparmorlinuxnoarche0-KIvʷA큤A큤hh heWeWeheWheWeWeWe18b7ab1776823a1e62a2d6db1bbbe51819f5732e89ca63a6dd3d540e629a42030a0adfab04b7755e093632fab7b8ab2adea32fc2eb640ec9586faa0cd2ebbd4ebeac1b7aa8497a59a81c4fc342ec5666f42e2dccea0104e188935ddd2137815d383e3f1c2fd71198fe319a325fbb9a2068dd73b2609e27db150d3aeddd9ed06afaf9108909890bb258f3dadbbd113fb35878c5f106a107850d33d62c851288d5e33ae4afd85d4e8a3a0f579068ca74e1686ba4651958a25e6792c6e1226f58dbe26924e382467ea63dd33229f07de8c3503ef5eac61cad007103e59e545bfb065b734a62259324cfd147c49382f1f4d2b4389cfaffbb1052eea742c669224001e91ac861de966cac00dd5711c9742ff2bfa9793a2848b5ae04c406fa888fbc6rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootapparmor-3.1.7-150600.5.6.1.src.rpmapparmor-docs    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3hg@e@ee}@eԔ@eԔ@e@ee@eKx@eKx@ev@d@d7d@ddtdS@cccױ@c@c@c|c@c Xcb{@bb@bޅbVb@b@b{@bwbk@bi0@bZbV@bT@bRbBb<]@b@a7aZ@ap@aabaim@aEaaua $@`#@` @````_@`%@`!'`>` @__ǁ_ǁ_Q_h__@_~@_[f_P_-B@_@^m@^@^<@^j$@^,-]҇]o](]K@]]@\\@\ \\v{\I\ include in apache extra profile optional to avoid problems with empty profile directory (boo#1178527)- prepare usrmerge (boo#1029961) * use %_pamdir- update to AppArmor 3.0.1 - minor additions to profiles and abstractions - some bugfixes in libapparmor, apparmor_parser and the aa-* utils - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0.1 for the detailed upstream changelog - removed upstream(ed) patches: - changes-since-3.0.0.diff - extra-profiles-fix-Pux.diff - utils-fix-hotkey-conflict.diff- Use apache provided variables for the module_directry: + Use %apache_libexecdir + Add apache-rpm-macros BuildRequires- add utils-fix-hotkey-conflict.diff to fix a hotkey conflict in de, id and sv translations (and fix the test) (MR 675) - add extra-profiles-fix-Pux.diff to fix an inactive profile - prevents a crash in aa-logprof and aa-genprof when creating a new profile (MR 676)- update to AppArmor 3.0.0 - introduce feature abi declaration in profiles to enable use of new rule types (for openSUSE: dbus and unix rules) - support xattr attachment conditionals - experimental support for kill and unconfined profile modes - rewritten aa-status (in C), including support for new profile modes - rewritten aa-notify (in python), finally dropping the perl requirement at runtime - new tool aa-features-abi for extracting feature abis from the kernel - update profiles to have profile names and to use 3.0 feature abi - introduce @{etc_ro} and @{etc_rw} profile variables - new profile for php-fpm - several updates to profiles and abstractions (including boo#1166007) - fully support 'include if exists' in the aa-* tools - rewrite handling of alias, include, link and variable rules in the aa-* tools - rewrite and simplify log handling in the aa-logprof and aa-genprof - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0 for the detailed upstream changelog - patches: - add changes-since-3.0.0.diff with upstream fixes since the 3.0.0 release up to 3e18c0785abc03ee42a022a67a27a085516a7921 - drop upstreamed usr-etc-abstractions-base-nameservice.diff - drop 2.13-only libapparmor-so-number.diff - refresh apparmor-enable-profile-cache.diff - partially upstreamed - update apparmor-samba-include-permissions-for-shares.diff and apparmor-lessopen-profile.patch - switch to "include if exists" - apparmor-lessopen-profile.patch: add abi rule to lessopen profile - refresh apparmor-lessopen-nfs-workaround.diff - move away very loose apache profile that doesn't even match the apache2 binary path in openSUSE to avoid confusion (boo#872984) - move rewritten aa-status from utils to parser subpackage - add aa-features-abi to parser subpackage - replace perl and libnotify-tools requires with requiring python3-notify2 and python3-psutil (needed by the rewritten aa-notify) - drop ancient cleanup for /etc/init.d/subdomain from parser %pre - drop (never enabled) conditionals to build with python2 and to build the python-apparmor subpackage (upstream dropped python2 support) - drop setting PYTHON and PYTHON_VERSIONS env variable, no longer needed - set PYFLAKES path for utils check - add precompiled_cache build conditional to allow faster local builds without using kvm - remove duplicated BuildRequires: swig- update to AppArmor 2.13.5 - add missing permissions to several profiles and abstractions - bugfixes in parser and tools - fix two potential build failures in libapparmor - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5 for the detailed upstream changelog - remove upstream(ed) patches - changes-since-2.13.4.diff - abstractions-X-xauth-mr582.diff - sevdb-caps-mr589.diff - libvirt-leaseshelper.patch - cap_checkpoint_restore.diff - add libapparmor-so-number.diff to fix libapparmor so version (!658)- add CAP_CHECKPOINT_RESTORE to severity.db (MR 656, cap_checkpoint_restore.diff)- %service_del_postun_without_restart only works for Tumbleweed, keep using DISABLE_RESTART_ON_UPDATE for Leap 15.x- Make use of %service_del_postun_without_restart And stop using DISABLE_RESTART_ON_UPDATE as this interface is obsolete.- libvirt-leaseshelper.patch: add /usr/libexec as a path to the libvirt leaseshelper script (jsc#SLE-14253)- sevdb-caps-mr589.diff: add new capabilities CAP_BPF and CAP_PERFMON to severity.db (lp#1890547)- add abstractions-X-xauth-mr582.diff to allow reading the xauth file from its new sddm location (boo#1174290, boo#1174293)- add changes-since-2.13.4.diff with upstream changes and fixes since 2.13.4 up to 5f61bd4c: - add several abstractions related to xdg-open: dbus-network-manager-strict, exo-open, gio-open, gvfs-open, kde-open5, xdg-open - introduce @{run} variable - update dnsmasq and winbindd profile - update mdns, mesa and nameservice abstraction - some bugfixes in the aa-* tools, including a remote bugfix in the YaST AppArmor module (boo#1171315) - drop upstream(ed) patches (now part of changes-since-2.13.4.diff): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-fix-utils-network-test.diff - make-4.3-network.diff - abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch - apply usr-etc-abstractions-base-nameservice.diff only for Tumbleweed, but not for Leap 15.x where it's not needed - refresh usr-etc-abstractions-base-nameservice.diff- Add abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch (bsc#1168306)- fix build with make 4.3 by backporting some commits from upstream master (boo#1167953): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-network.diff - make-4.3-fix-utils-network-test.diff- update to AppArmor 2.13.4 - several abstraction updates (including boo#1153162) - disallow writing to fontconfig cache in abstractions/fonts - some bugfixes in the aa-* tools - fix log parsing for logs with an embedded newline - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4 for the detailed upstream changelog - drop upstreamed patches: - abstractions-ssl-certbot-paths.diff - apparmor-krb5-conf-d.diff - libapparmor-python3.8.diff - usr-etc-abstractions-authentification.diff - refresh usr-etc-abstractions-base-nameservice.diff- add usr-etc-abstractions-base-nameservice.diff to adjust abstractions/base and nameservice for /usr/etc/ (boo#1161756)- Properly pull in full python3 interpreter- add libapparmor-python3.8.diff to fix building the libapparmor python bindings (deb#943657)- add usr-etc-abstractions-authentification.diff to allow reading /usr/etc/pam.d/* and some other authentification-related files (boo#1153162)- add abstractions-ssl-certbot-paths.diff - add certbot paths to abstractions/ssl_certs and abstractions/ssl_keys- add apparmor-krb5-conf-d.diff for kerberos client- update to 2.13.3 - profile updates for dnsmasq, dovecot, identd, syslog-ng - new "lsb_release" profile (only used when using "Px -> lsb_release") - fix buggy syntax in tunables/share - several abstraction updates - parser: fix "Px -> foo-bar" (the "-" was rejected before) - several bugfixes in aa-genprof and aa-logprof - some fixes in cache handling - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3 for the detailed upstream changelog - drop upstream(ed) patches: - apparmor-nameservice-resolv-conf-link.patch - profile_filename_cornercase.diff - dnsmasq-libvirtd.diff - dnsmasq-revert-alternation.diff - usrmerge-fixes.diff - libapparmor-swig-4.diff - re-number remaining patches- add upstream libapparmor-swig-4.diff: fix libapparmor tests with swig 4.0 (boo#1135751)- Disable LTO (boo#1133091).- update lessopen.sh profile for usrMerge (bash and tar) (boo#1132350)- add usrmerge-fixes.diff: fix test failures when /bin/sh is handled by update-alternatives (boo#1127877)- add dnsmasq-revert-alternation.diff: revert path alternation in dnsmasq profile and re-add peer=/usr/sbin/libvirtd rules to avoid breaking libvirtd (boo#1127073)- add dnsmasq-libvirtd.diff: allow peer=libvirtd in the dnsmasq profile to match the newly added libvirtd profile name (boo#1118952#c3)- Use %license instead of %doc [bsc#1082318]- add apparmor-lessopen-nfs-workaround.diff: allow network access in lessopen.sh for reading files on NFS (workaround for boo#1119937 / lp#1784499)- add profile_filename_cornercase.diff: drop check that lets aa-logprof error out in a corner-case (log event for a non-existing profile while a profile file with the default filename for that non-existing profile exists) (boo#1120472)- netconfig: write resolv.conf to /run with link to /etc (fate#325872, boo#1097370) [patch apparmor-nameservice-resolv-conf-link.patch]- update to AppArmor 2.13.2 - add profile names to most profiles - update dnsmasq profile (pid file and logfile path) (boo#1111342) - add vulkan abstraction - add letsencrypt certificate path to abstractions/ssl_* - ignore *.orig and *.rej files when loading profiles - fix aa-complain etc. to handle named profiles - several bugfixes and small profile improvements - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.2 for the detailed upstream changelog - remove upstreamed fix-syntax-error-in-rc.apparmor.functions.patch- update to 2.13.1 - add qt5 and qt5-compose-cache-write abstractions - add @{uid} and @{uids} kernel var placeholders - several profile and abstraction updates - ignore "abi" rules in parser and tools (instead of erroring out) - utils: fix overwriting of child profile flags if they differ from the main profile - several bugfixes (including boo#1100779) - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.1 for the detailed upstream changelog - remove upstream(ed) patches: - aa-teardown-path.diff - fix-apparmor-systemd-perms.diff - logprof-skip-cache-d.diff - fix-samba-profiles.patch - make-pyflakes-happy.diff - dnsmasq-Add-permission-to-open-log-files.patch - refresh apparmor-samba-include-permissions-for-shares.diff - add fix-syntax-error-in-rc.apparmor.functions.patch- update rpmlintrc: - whitelist .features file which is part of the pre-compiled cache - comment out filters for the disabled tomcat_apparmor subpackage- Backport dnsmasq fix: 025c7dc6 - dnsmasq-Add-permission-to-open-log-files.patch (boo#1111342)- add make-pyflakes-happy.diff to fix an unused variable (SR 629206)- add fix-samba-profiles.patch - smbd loads new shared libraries. Allow winbindd to access new kerberos credential cache location (boo#1092099)- exclude the /etc/apparmor.d/cache.d/ directory from aa-logprof parsing (logprof-skip-cache-d.diff)- add fix-apparmor-systemd-perms.diff - fix permissions of /lib/apparmor/apparmor.systemd (boo#1090545)- create and package precompiled cache (/usr/share/apparmor/cache, read-only) (boo#1069906, boo#1074429) - change (writeable) cache directory to /var/cache/apparmor/ - with the new btrfs layout, the only reason for using /var/lib/apparmor/cache/ (which was "it's part of the / subvolume") is gone, and /var/cache makes more sense for the cache - adjust parser.conf (via apparmor-enable-profile-cache.diff) to use both cache locations - clear cache also in %post of abstractions package- update to AppArmor 2.13 - add support for multiple cache directories and cache overlays (boo#1069906, boo#1074429) - add support for conditional includes in policy - remove group restrictions from aa-notify (boo#1058787) - aa-complain etc.: set flags for profiles represented by a glob - aa-status: split profile from exec name - several profile and abstraction updates - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13 for the detailed upstream changelog - drop upstreamed patches and files: - aa-teardown - apparmor.service - apparmor.systemd - 32-bit-no-uid.diff - disable-cache-on-ro-fs.diff - dovecot-stats.diff - parser-write-cache-warn-only.diff - set-flags-for-profiles-represented-by-glob.patch - fix-regression-in-set-flags.patch - drop spec code that handled installing aa-teardown, apparmor.service and apparmor.systemd (now part of upstream Makefile) - simplify "make -C profiles parser-check" call (upstream Makefile bug that required to call "cd" was fixed) - add aa-teardown-path.diff - install aa-teardown in /usr/sbin/ - move 'exec' symlink to parser package (belongs to aa-exec)- Set flags for profiles represented by glob (bsc#1086154) set-flags-for-profiles-represented-by-glob.patch fix-regression-in-set-flags.patch- add dovecot-stats.diff: - add dovecot/stats profile and allow dovecot to run it (boo#1088161) - allow dovecot/auth to write /run/dovecot/old-stats-user (part of boo#1087753) - update 32-bit-no-uid.diff with upstream fix- Change of path of rpm in lessopen.sh (boo#1082956)- add disable-cache-on-ro-fs.diff - disable write cache if filesystem is read-only and don't bail out (bsc#1069906, bsc#1074429)- add parser-write-cache-warn-only.diff to make cache write failures a warning instead of an error (boo#1069906, boo#1074429) - reduce dependeny on libnotify-tools (used by aa-notify -p) to "Suggests" to avoid pulling in several Gnome packages on servers (boo#1067477)- update to AppArmor 2.12 - add support for 'owner' rules in aa-logprof and aa-genprof - add support for includes with absolute path in aa-logprof etc. (lp#1733700) - update aa-decode to also decode PROCTITLE (lp#1736841) - several profile and abstraction updates, including boo#1069470 - preserve errno across aa_*_unref() functions - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.12 for the detailed upstream changelog - drop upstreamed patches: - read_inactive_profile-exactly-once.patch - utils-fix-sorted-save_profiles-regression.diff - lessopen profile: change all 'rix' rules to 'mrix' - add 32-bit-no-uid.diff to fix handling of log events without ouid on 32 bit systems - no longer package static libapparmor.a- update to AppArmor 2.11.95 aka 2.12 beta1 - add JSON interface to aa-logprof and aa-genprof (used by YaST) - drop old YaST interface code - update audio, base and nameservice abstractions - allow @{pid} to match 7-digit pids - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_95 for the detailed upstream changelog - drop upstreamed patches - apparmor-yast-cleanup.patch - apparmor-json-support.patch - nameservice-libtirpc.diff - drop obsolete perl modules (YaST no longer needs them) - drop patches that were only needed by the obsolete perl modules: - apparmor-utils-string-split - apparmor-abstractions-no-multiline.diff - drop profiles-sockets-temporary-fix.patch - obsoleted by a fix in apparmor_parser - refresh utils-fix-sorted-save_profiles-regression.diff - add aa-teardown (new script to unload all profiles) - make ExecStop in apparmor.service a no-op (workaround for a systemd restriction, see boo#996520 and boo#853019 for details) - lessopen profile: allow capability dac_read_search and dac_override, allow groff to execute several helpers (boo#1065388)- read_inactive_profile-exactly-once.patch (bsc#1069346) Perform reading of inactive profiles exactly once.- update to AppArmor 2.11.1 - add permissions to several profiles and abstractions (including lp#1650827 and boo#1057900) - several fixes in the aa-* tools (including lp#1689667, lp#1628286, lp#1661766 and boo#1062667) - fix downgrading/converting of 'unix' rules (will be supported in kernel 4.15) to 'network unix' rules in apparmor_parser (boo#1061195) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_1 for upstream changelog - remove upstream(ed) patches - upstream-changes-r3616..3628.diff - upstream-changes-r3629..3648.diff - parser-tests-dbus-duplicated-conditionals.diff - apparmor-fix-podsyntax.patch - sshd-profile-drop-local-include-r3615.diff - refresh apparmor-yast-cleanup.patch - add utils-fix-sorted-save_profiles-regression.diff to fix a regression in displaying the "changed profiles" list in aa-logprof- add nameservice-libtirpc.diff to fix NIS/YP logins (boo#1062244)- profiles-sockets-temporary-fix.patch to cater to nameservices with the new sockets mediation, until unix rules are upstreamed (boo#1061195)- add apparmor-fix-podsyntax.patch from mailing list to fix compilation with perl 5.26- do not require exact X.Y version of "python3" - require also matching python(abi) which is arguably more important- don't rely on implementation details for reload in %post- add JSON support. Required for FATE#323380. (apparmor-yast-cleanup.patch, apparmor-json-support.patch)- add upstream-changes-r3629..3648.diff: - preserve unknown profiles when reloading apparmor.service (CVE-2017-6507, lp#1668892, boo#1029696) - add aa-remove-unknown utility to unload unknown profiles (lp#1668892) - update nvidia abstraction for newer nvidia drivers - don't enforce ordering of dbus rule attributes in utils (lp#1628286) - add --parser, --base and --Include option to aa-easyprof to allow non-standard paths (useful for tests) (lp#1521031) - move initialization code in apparmor.aa to init_aa(). This allows to run all utils tests even if /etc/apparmor.d/ or /sbin/apparmor_parser don't exist. - several improvements in the utils tests - drop upstreamed python3-drop-re-locale.patch - no longer delete/skip some of the utils tests (to allow this, add parser-tests-dbus-duplicated-conditionals.diff) - add var.mount dependeny to apparmor.service (boo#1016259#c34)- Cleanup spec file: - don't use insserv if we afterwards call systemd, this can have bad side effects - remove dead code - remove now obsolete 'distro' checks - Replace init.d script with new wrapper working with systemd- add python3-drop-re-locale.patch: remove deprecated re.LOCALE flag in Python UI as it was dropped from Python 3.6 (lp#1661766)- Fix RPM groups- add upstream-changes-r3616..3628.diff: - update abstractions/base, abstractions/apache2-common and dovecot profiles - merge ask_the_questions() of aa-logprof and aa-mergeprof - pass LDFLAGS when building parser, libapparmor perl bindings and pam_apparmor - adjust deleting the cache in profiles %post to the new cache location - silence errors when deleting the cache (boo#976914)- split libapparmor into separate spec to get rid of build loop involving mariadb, systemd, apparmor, libapr and mariadb again (see the discussion in SR 448871 for details) - libapparmor.spec is based on the AppArmor 2.11 apparmor.spec, but with minimum BuildRequires- update to AppArmor 2.11.0 - apparmor_parser now supports parallel compiles and loads - add full support for dbus, ptrace and signal rules and events to the utils - full rewrite of the file rule handling in the utils - lots of improvements and fixes - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11 for the detailed changelog - patches: - add sshd-profile-drop-local-include-r3615.diff to fix 'make check' - drop aa-unconfined-fix-netstat-call-2.10r3380.diff, no longer needed - refresh apparmor-abstractions-no-multiline.diff - refresh apparmor-samba-include-permissions-for-shares.diff - spec changes: - aa-unconfined switched to using ss (from iproute2), adjust Recommends: - move libapparmor to /usr/lib*/ - drop %if %suse_version checks for 12.x - change several Obsoletes from %version to < 2.9. Those package names weren't used since years, and 2.9 is still a careful choice - include apparmor.service independent of %suse_version - techdoc.pdf is now shipped in upstream tarball to reduce BuildRequires - drop latex2html, texlive-* and w3m BuildRequires - techdoc.txt and techdoc.html not included, drop them from the package - run most of utils/ make check (some tests expect /etc/apparmor.d/ and /sbin/apparmor_parser to exist, skip them) - BuildRequires python3-pyflakes (utils tests) and dejagnu (libapparmor tests) - drop sed'ing python3 into aa-* shebang (upstreamed) - build binutils - aa-exec is now written in C and lives in /usr/bin/, move it to the apparmor_parser package and create a compability symlink in /usr/sbin/ - aa-exec manpage moved to section 1 - aa-enabled is a small new tool to find out if AppArmor is enabled - package new aa_stack_profile(2) manpage- change /etc/apparmor.d/cache symlink to /var/lib/apparmor/cache/. This is part of the root partition (at least with default partitioning) and should be available earlier than /var/cache/apparmor/ (boo#1015249, boo#980081, bsc#1016259) - add dependency on var-lib.mount to apparmor.service as safety net- update to AppArmor 2.10.2 maintenance release - lots of bugfixes and profile updates (including boo#1000201, boo#1009964, boo#1014463) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_2 for details - add aa-unconfined-fix-netstat-call-2.10r3380.diff to fix a regression in aa-unconfined - drop upstream(ed) patches: - changes-since-2.10.1--r3326..3346.diff - changes-since-2.10.1--r3347..3353.diff - libapparmor-fix-import-path.diff (upstream fix is slightly different) - nscd-var-lib.diff - refresh apparmor-abstractions-no-multiline.diff- add nscd-var-lib.diff to allow /var/lib/nscd/ in the nscd profile and abstractions/nameservice (path changed in latest nscd in Tumbleweed)- add changes-since-2.10.1--r3347..3353.diff with upstream changes and fixes in the 2.10 branch, including - allow writing *.qf files (for disk-based buffering) in syslog-ng profile - add several permissions to the dovecot profiles (deb#835826) - add a missing path in the traceroute profile- add changes-since-2.10.1--r3326..3346.diff with upstream changes and fixes since the 2.10.1 release, including - allow dac_override in winbindd profile (boo#990006#c5) - allow mr for /usr/lib*/ldb/*.so in samba abstractions (needed since Samba 4.4.x, boo#990006) - abstractions/nameservice: also support ConnMan-managed resolv.conf - let aa-genprof ask about profiles in extra dir (again) - fix aa-logprof "add hat" endless loop (lp#1538306) - honor 'chown' file events in logparser.py - ignore log file events with a request mask of 'send' or 'receive' because they are actually network events (lp#1577051, lp#1582374) - accept hostname with dots when parsing logs (lp#1453300 comments #1 and #2) - fix python LibAppArmor import failures with swig > 3.0.8 (boo#987607) (libapparmor-fix-import-path.diff) - refresh apparmor-abstractions-no-multiline.diff - drop upstreamed profiles-ping-inet6-r3449.diff - add %check section - runs libapparmor (including swig bindings), parser and profiles tests - add BuildRequires: perl(Locale::gettext) - needed for parser tests- add profiles-ping-inet6-r3449.diff - latest ping also does IPv6 (boo#980596)- update to AppArmor 2.10.1 (2.10 branch r3326): - fix incorrect output of child profile names (apparmor_parser -N) which caused 'rcapparmor reload' to remove child profiles and hats (lp#1551950) - fix a crash in aa-logprof / logparser.py for change_hat log events (lp#1523297) and log events that look like file events, but aren't (lp#1540562, lp#1525119, lp#1466812) - write unix rules when saving a profile (lp#1522938, boo#954104#c3) - several fixes for variable handling in aa-logprof - map c (create) log events to w instead of a - add python to the "no Px rule" list in logprof.conf - let aa-logprof check for duplicate profiles - let aa-status work without the apparmor.fail python module (boo#971917, lp#1480492) - add permissions in several profiles (including boo#948584, boo#948753, boo#954959, boo#954958, boo#971790, boo#964971, boo#921098, boo#923201 and boo#921098#c15). - and many more fixes, see the full changelog at http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_1 - drop upstream(ed) patches: - fix-initscript-aa_log_end_msg.diff - syslog-ng-profile-boo948584.diff - upstream-profile-updates-r3205-3241.diff - refresh patches: - apparmor-abstractions-no-multiline.diff - apparmor-samba-include-permissions-for-shares.diff - drop libapparmor autogen.sh call (broke the build) and remove libtool BR- add syslog-ng-profile-boo948584.diff - add several permissions needed by latest syslog-ng (boo#948584, boo#948753) - add upstream-profile-updates-r3205-3241.diff with several profile updates: - add /usr/share/locale-bundle/** to abstractions/base - allow dnsmask to use /bin/sh (boo#940749) and /bin/dash - allow dovecot imap to read /run/dovecot/mounts - allow avahi-daemon to write to /run/systemd/notify - allow ntpd to read $PATH directory listings (boo#945592, boo#948752) - update dhclient profile - allow skype to read @{PROC}/@{pid}/net/dev (boo#939568) - and some other small updates - drop upstreamed apparmor-winbindd-r3213.diff (included in the upstream-profile-updates patch)- netstat moved to net-tools-deprecated in Tumbleweed (boo#944904)- add apparmor-winbindd-r3213.diff - add missing k permissions for /etc/samba/smbd.tmp/msg/* in winbindd profile (boo#921098 #c15..19)- add fix-initscript-aa_log_end_msg.diff - fixes ugly initscript output (boo#862170)- update to AppArmor 2.10 (trunk r3205) - profile names can now contain variables - improved profile compile time in apparmor_parser - lots of improvements, refactoring and bugfixes in the aa-* tools - new apis for managing and loading profile caches into the kernel in libapparmor - lots of profile updates - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10 for the complete changelog with more details - add new apparmor_private.h and the aa_query_label(2), aa_features(3), aa_kernel_interface(3), aa_policy_cache(3), aa_splitcon(3) manpages to libapparmor-devel - drop apparmor-2.5.1-edirectory-profile patch - it's most probably no longer needed (see boo#621394 for details) - drop upstreamed samba-4.2-profiles.diff - refresh apparmor-samba-include-permissions-for-shares.diff- systemd-rpm-macros and %systemd_requires were at the wrong place, move them to the parser package (boo#931792)- update to AppArmor 2.9.2 (2.9 branch r2911) - lots of bugfixes in the parser and the aa-* tools (including boo#918787) - update dovecot and dnsmasq profiles and several abstractions (including boo#911001) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_2 for the full changelog - remove upstream(ed) patches apparmor-changes-since-2.9.1.diff and apparmor-fix-stl-ostream.diff - replace GPG key with new AppArmor GPG signing key, see https://launchpad.net/apparmor/+announcement/13404- make sure %service_del_postun doesn't call systemctl try-restart (boo#853019, bare systemd edition) - add samba-4.2-profiles.diff: update samba (winbindd and nmb) profiles for samba 4.2 (boo#921098, boo#923201)- only install apparmor.service for openSUSE > 13.2- Add a native systemd unit which *at the moment* only wraps/masks the early boot script.- add apparmor-fix-stl-ostream.diff which fixes odd uses of std::ostream which are not valid. Fixes build with GCC 5- allow lessopen.sh to run /usr/bin/unzip-plain (boo#906858)- add Requires: python3 to python3-apparmor package - readline isn't part of python3-base (boo#917577)- add apparmor-changes-since-2.9.1.diff with upstream fixes since the 2.9.1 release - update logparser.py to support changed syslog format (lp#1399027) - update usr.sbin.dovecot and usr.lib.dovecot.imap{, -login} profiles (lp#1296667) - update the mysqld profile - fix network rule description in apparmor.d(5) manpage - drop upstreamed dnsmasq-profile-fixes.patch - update expired GPG key- update to AppArmor 2.9.1 (2.9 branch r2831) - fix log parsing for 3.16 kernels and syslog-style logs (boo#905368) - several fixes and performance improvements in the aa-* utils - profile updates for dnsmasq (boo#907870), nscd (boo#904620#c14 and bnc#908856), useradd, sendmail, man and passwd - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_1 for full release notes - refresh dnsmasq-profile-fixes.patch- Fix dnsmasq profile to allow executing bash to run the --dhcp-script argument. Also fixed /usr/lib -> /usr/{lib,lib64} to get libvirt leasehealper script to run even on x86_64. dnsmasq-profile-fixes.patch. boo#911001- rename lessopen.sh profile file to usr.bin.lessopen.sh to match the script filename- add apparmor-lessopen-profile.patch: /usr/bin/lessopen.sh needs confinement. bnc#906858- delete cache in apparmor-profiles %post (workaround for bnc#904620#c8 / lp#1392042)- No longer perform gpg validation; osc source_validator does it implicit: + Drop gpg-offline BuildRequires. + No longer execute gpg_verify.- fix bashism in post script- update to AppArmor 2.9.0 (r2759) - change aa-mergeprof to the final commandline syntax - lots of bugfixes in the aa-* tools (bnc#900163, lp#1328707 and several bugs without a formal bugreport) - small additions to gnome, freedesktop.org, ubuntu-browsers.d/java and user-mail abstractions - fix mod_apparmor to not break basic auth - update perl modules to support signal, unix and ptrace rules (bnc#900013) - don't warn about rules not supported by the kernel - fix logging of "audit capability" (lp#1378091) - add support for the "hat" keyword in apparmor.vim - build html version of apparmor.vim manpage again (lp#1366572) - see also http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_0 - update apparmor-abstractions-no-multiline.diff - remove upstreamed apparmor-profiles-ntpd-pid-location.diffh04-ch1b 1745392364 3.1.7-150600.5.6.1apparmorapparmor.vimapparmor-docsaa-teardown.8.htmlapparmor.7.htmlapparmor.cssapparmor.d.5.htmlapparmor.vim.5.htmlapparmor_parser.8.htmlapparmor_xattrs.7.htmltechdoc.pdf/usr/share//usr/share/apparmor//usr/share/doc/packages//usr/share/doc/packages/apparmor-docs/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:38382/SUSE_SLE-15-SP6_Update/108ff988527a5e410ebf430fd63f6431-apparmor.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linuxdirectoryASCII text, with very long linesXML 1.0 document, ASCII textXML 1.0 document, ASCII text, with very long linesASCII text*"sO˻Putf-8938bdf407102b7ef40452fadc9b567f46eabc24fb1849fb036ac59b1988d6e82?P7zXZ !t/R]"k%nCQZuǡjע|{9[Wp G’1 NKQmH-č(-f̪|qR @Tas,QKFGz2_)?S'XObBe4JY\Ijbds( B*s3LM'^xȿo1vW˅ŭd\SX< oQY1V`at 1ဤX H^4t먽"5˫^1{}$5-8^x(l}yZeX S?_ڔHh_]4_w*W%X8g?f fTfa:6m/G{otrٳ Xච?y,#:e*?)0=S:F(ˠ!?Z`ڶo*UcS%I \]Hs@aZ6$(u!Aks?Ưp/+)zB)Cz&*kgYIrgXiX%uTCj[ο3J_2|fM4]ϸ ?T$Xf1,Y"cPAڔ; !&dTGF'A6цAAE%mq x}ΌA$jcQYhN`|f⠲Rb<>h$,Sw9-1fwW%w;vsKC3yk`s*fǟ_37TtsEV$9:rELj% pA4$@p֩qmq<0}(k]~8<x-0\ԋV#OԚQfb }E ޡ?7;66뉔:Y], ,3MpWKAb< Gt  Iz,/3_?*4Ddr6/AXD` $oTKݤ ڒT6[rAs9o7BXC Xȯ l`G*1'i<,,P{lVXǁ҈s|U[QDt *}je+ȦJԁ6Db2nf_ ~UHyz:6M`)xjꥊ(ǧw:r⹿Fu^v3s8/J΍Rzŭat.JZ»7q߰2_ړA3Câ ;"_# \vL7[ׂ\_}ǖ]Jh%FGЬB y"R>cE,IįLj86➜fIlɓK:t$XU+h!2oh<=h1 ;-|o( /~U&X02"3N'h2(O/z}&Z\ju,}SuRhʧ@rNԤ?)XɞS3p o.@J(ŠT*IZeBE^&zU hE-O" z\BB)҈`AM">I'*K >p5Y+;+ LpLԈDeVTM/hUVf~BYWBR yQy (gT8rƸ= GrϗfxXRD}>1@)"5gYl)qfJz+jꉪ;m uDG*"-),F:^,T*cJú/'6lیaZJtL<~^Z5Eu2i7 0IM(i>o 0ys^\\ފ?\1wʝv!Q=]$m+}lw\ moRg9 !$OJ|cf\Q{_$YY1Y7)9NWtgǟ6%dedJO-u!!cWu`؈V'5}Ko8su>L4ux &Z*̢yjqn:t#X˭骚`:ˍ:w(?[&w,-5='}]#Q}&А7+F MI; V%> RlsL2(I6[XxYKқpM :=jۉ+'?`@勥Pm0C6g1gR'eaTsyQa?ІHF40˅ W8VF/X`X{7ګ ZD. gs39 h%oUߩWU8-֔x|ٝ 8Ljj :7Oz0X.qqƫ9+1w13&PN( -as@%7s )6Ϫ,hgh E΢H\ykuhp噆0JGJ'!2t)5Cm&-P݊>Pw}H?Ӈ@Ψ2ZoW}e“9{WA\.X2HPkVII8X',,2ZRɃHR Z R9 6/l=9^-7M˵Pj?*y|(ibPʤ>ujÉBCo 77y6L:|3'Q<\0z-ps& W%"tU6K%Z9Q*V,t cׅRgTI'#&u?Ƕeh+u(O&NSRk4H(L0fLzw9_(o= ?Zا|\<*'ׂMQrtn=79-,y%"i_7 p =@:x C2'W{QNH N_A9 DRֆ1cSIHqA#0lqI\NU|ܞ9FNA{T4:*|u +[E+zfʋGgpu櫈W_LT O#(WYYK9vIC3ZlWN0ՑS2),J LLBCpEYMݿ \,,P( ű6=X;Ֆl5*!u9]Ўal*qڱo&cLFq\ҫԌcyLJOe)CPOl7O=*).g76XɵFY i-431C$Ɯ1wep2i9G%)o1V\>!^"/9 J<А}VE)R`c*юQ2Lf Au; $ Ǚd IXE؁>^"@+>aO~ʡzof7H‚x_lgfނgXa!H=yႅ.agİׇr䋎u"Jr p}45tugÍ~N^ߓimBIIטz,~= Ӹg_&c;ڽo1#ބ :+7UJ-9g}:SIyO#F /j۾b -aLl/z9p#*? Rԛ"ByVt%ʇ[/on|\JwdGѓeZHY's'K1g T$ͪZΓ,(Uʉlgj u+HC@FҁD`VckU!teE\E//B+| 1.%kThw+x{x\6 Mat$}ط*d]"}9s,8(HY\x\[,-Byþ*ڏfahЬO$/4˧ܝK'eXgi% TыH4KMm7S`Ot29p1y^=CgT.ɶ\:<85[?g23+[]leswWd@(f;g j/`X[ @eڹWǰ.=EN=eЉPI zL6 $|2 m$BNAXqNRX/2gJ ]ۡN-:_XJi2&gxP'KI˼4$h|z=_rkzXt{Q#f79 "fC 28yjk I@[Us dкFP䠃htlɐ#zFy[7_T sݸouY6%bϓ/ Ű1ݚl'?/(#RXHwm.'"~ʌ!}lʈMCZiAIY(_ɝ*BX&W|+#<* KnV.L} zl&m&BҒQtض*$3=БF&H i8s!MѼѐTRj_NOE}tEhW߼qrngѳsxR6ѥ00?A OU44pM8[JM tq`5` UZ4jכ瞐1֛[h"EMM$zX?,+3oPBh!p&P`1 45"9iS̊  x%BD{"*PG jW &e74XnG ?_dU&K,NKd%4g0\I%`}AC,&W|? vl9d(fp*u0{šᷮ7ҲH3j5h9 ^ =,u6xI0;M~$SN3o_R%>K[ Ăõ> Hej ڑ~*s!YȺ_C`|SaOē++DofzbGEov98ށ{ bF(% i>2@pHt f]|FZG aS:"L7-L[r߂ubA^瑜&3t )GC,钷 >E^s"3r%@=:5r-T1 =X˸aed:.bdɑ d5U3/@bII؀ꎵ2}}0ą/s ;{@zn@8ڇmWX3Kf8F'Eޠ !V(C*tpsHoItNn +?4wIϠTۭ7fG6ț>BuV7&ZڡOTd&pYD}LvBBvA$,ZaX N.Oå3~m#]nPa) d#\ިQ#ʿNp·S}`$E{xE]Nh龺H vZ'~^RO҆b}/we({K=xsl:*NC,dNxӟc4|IYm.D˳SOC`Zϻ F: v֚'^B>bW ;T,IF**h6²gf|"d{&lIYtGsY(@jp 5iaEne]I :[Ζʍ"bF&&<@s*2u'h^vbIOB,pR=||fnŀw7ȃo>Q$YjH@Nxu0#@X ; W1{י!J'%Isѱ#"Aky~7ߑAG@$?=9xRKvuZ&F R/ȤA.k6gG+RKk;OSuR$W. 5%nX{ wm?H !AmҳkV腜IC.̧p_*ϋK6:х4IP-Iun/ @XiIq)@ET;Ghȶ K >{x g'd 0X͑2${9{"Zq$|eQ=$+"~,Ip ڼ:s*X2yQ %瘛-]Ѱ42#Y*SX%졊O >x;&EZ iYuh%u_${=ŀ'LjF Ka:#f/NŇn|vVlғaxWA=8rZ_$S>)|C!Js(``Rn  v;Iy \o6g zI#,c)aߊ4Jj}X-ۖk%^w\n^܇ẙBDdq2O `ޗ {=I=[ C R!}ni^azޚn/ZmMz;+'~7y.¨*ثL7R.-8|M,֗)^bSM)>o,|6<+U5<@҆DԇWzn%JILh|XH`!1n0P/{f) /įŕpdŐRƴjhSgV#)'؛ʣ4JAyH/@Kp*ۓ"M(bTئεkܢ2iw^z櫁[y ? a19",^n֪A2i5H5@#`d/(e/|_ɶCY 39uЖOv~He( 2?] lA8$4z.DΠ{ ObV)r[kBD=Ybb-+蝜.H2F1 4Wh/ہh}~A%2gX)SFCnt_[ixmF脆2{]Q9_J-b(K+;u{*]VgZ'&Z/ B $ kHiS}O C=?e7TM϶3EԴ?/c`*9[Ux2c'M]}uxo~feV+_vȪV'DH6NQIҥW_Rh^ |_el9m@If&QJgD)'^JB'F;>X jLE4kԤDpWҽ#'Ωźt0zV~Ԩn1kpwtP-PyrdJVn .\{bx8׉`=[LF%K |x?zORJ0bŸ P1ߎ$Am*sBz gI"wi"VJP>X&qnIV 5MBTxTW\P/Ԭu]Wßێ$XSs 44R[Q̸4zCw7A.c;rjG.3,ѐk^(YS؛I=(A HMD9j~:ԄRaMҹ@ˊS fQw1W-G~x3ٿ`VW/#,J򩑫hw\6餑oVm5>$J%qԮym1^I#ACIFjr$füvd0=ѢBz /ib h:MxcVFK Z ?U/淞DŽ4n;~)zC3Mo#+=aeHuaȐsEU /Qfd2lSe(/=Xa-2V7sJ,PG6^BU׌3Gh?i(>* Nhh ys hmZ[_#EAmo'zRUm+U} o/RLNwaZT>i&#i Xqt~ Ju@y+5eMco#8zӝ yO^SH4cNK&a^XI޾`1@tg[Nl*QMX*e6c] fW]q<1e~ gH'qfW1BG9EW-tqRJubV3*KSl9q[Pn'{JLI&k}d3f" N{d./JtDDe;8 zUV αo~5qcm.rzau$3eB*3Eydm6(/Ӫ :GvurU;Z"e|Rd^ڳI+•Kbۡ`w [fuȪ0 I[ I{|T蚳]Wl #Ujږ (i{Mr?Lk)Zd'tOXN Їl&^kԽٸ0m}1MLo@>0PetJo 8Nj.PhFX3j 6ή Ci?,9<ʣ6HŽIQyN5I;6Tx|%mM{^/0 K; xUo OΑ+(G/jrQW~D\mZj@F{u,ɏf`psrV,-@ʰikbLXrB bK[[2ےm7Fr~Eɹx"/693y6Wnlйz^@exqc"z?&!<$#g.WTv)/C2`ܺn by-[wr[.}oK5w:ט. }'Y^dU7 !N7D ,Cfp("snL*+굾I#RZtmpfq }"v]9gI/uҋkt\0'mz=)V%6@xʞ*:.oy*i\ln#4^2uJ~/vP†/@kXD:BI]9{JgA^f_KK^&QNQJI$+2[!:h"P{by>58q^]}5w?fa 0Ss!wUu i]% )=UtcUg1)5X~t*ǖ MT, H2p}ղ㕶drChoJYOZ\z؎?> SM3{ I1@֙b J)ZoOɈ-u>~ir`I"%Jj8)ziV˷E+nM 6%-)Y ɵF :`(rTU\쎴KΧqV:iW',ʴ_`!fϑïnBc\]kӎ;faLuOԟ%:]3u4 |<]v:o@erVoaSp֮YMHw|Mz.e{Oa^a{V{ӥGi+r9 ٣P~K|rgRR!;\%hp[c6ɩ,},~9?µO>( h8AH _ERk$Qmnqʿ5̊լ>R.Kj>H&iO='H:CJXT`}wcJW|gk2Pj =lgeDJS3b>RpO1J(:aS1Wlbe%TkЦ֔*UAj W:m8 kyPr'7,j T5RA@uDQ+Wfq9`F)LNH8vTVTYl\&Mjj4?[.3lWtH A#9ǾzrhABG7< Tfu .uPAl +Epxb[kmlvkJ:CoKF5:N?4݇yTOo\Qf4>|0~,X5c:{&w_5 ([cbL~$ FT~|hb([Cd_|tv(U? _Ss` 5/K1wְu@:ᚒdX -GW{T}n(bpI @벡+BN+-K݂t&~冕 ~cCca"|{m~Y,=-IPD::WUCCRK@ʆ^D^qسjHr6RptC ֟RJ `Y?M5y=<0V;Og& H*B+ >;<,5x~%9ixPYK Czro殝:ω7&;_ =hcX(L߇>ݹwm@ZD$鮀܄E+ztpo<kU!z3l hkQ0h??de&gZt2C[>-'@4yL_>Ojpxv^0y:1ƌۥem;"'pxTӴBYl=PX6~I o,.$\WWأGk!'oG/F *c1wK1zLN];@gC|V|FSf)LQ "AA-2/: ҷs7LD  U9eh%>F|"rr^:xP6HGn4ɻ,!asdpoPॾ+rZT845]Yſ/WxRR?W"QNT:y0vWwaT_i3l 4L=V 童)qyMGBq=h8i{WXͭ tO/v5KFf+y" 炅tem =UQKc_-%ߔ.?^r ~@d533鲮T;d6$)g\{u``0 }lmQmui}vi/g6!rΐ}lVK9ˉbHRϽ(+p2w6N䬄:Iǻad @C!`кV]aKv1Ggsusڟc+>O.u+R ,RN^̩*o,,9#D7F3ӜLf07 9-I۴ۮC$##󳽢;^'b5 8,P"6uLd' zZv CYormگY I2mw4ܐK}bUa|T.2[zC9+pF\H3g\&Qۅҍޫ-t#<4P@8yX Ԭ%ZWF-aTĸh3_!SA'!+!=M%F 6;/'C A^2wP /\zϼy2#AlSevhyJ8gsR%[#/z]nsK*^/9BB9zR ,ț-&w6(M89lt#lνDyZE"=l/EҰ΢ghި;׆ޏ25ǹR݇1JLv']? G# H\M3uJ0!B'jd ؖ^{ͻNnT#Aro(ʳَ~C&8di>[,1`7w R dCW7Z"%`c]2\Ҿ ϝp-@.#tMh' p0n~ñTCpa3AzEQrF}%O-D0Tr^OѤr)ԥ`GyZ5l`DT*΄+4$x V@ {;>! *'ޠ:͏F@\4Bʉ^TO,д?DŽR{W 椏tw'G~j BQ4!%MPľPXͼ[&ZJM"t!KHQV 8?EGnkGFIӀ a%!ж|ZoلSGzc gcK:yVgP]{MOM$y^̜We 7b氵@\ѡAYK?ACo'L)fjR@`^mBB!jґpHU mp;0 sGOimr4Z1+)u;D] L9^q"VQ0Q@[[XG0&>.V{;+\я{Ɯ(}6ާ& ʠG@{P'; ?ES|@E( bW) ßBY#HMZ"0tgMHA:M +b;\=Di.8j`X/dY"5o6V99$wcoAq;:n*;ҎCkk6_,Ф 0uL{t"ڿ> !FA 奫ׄ!8<τJ%UvTDR<{ D2SV^$ʢ|8C81r2A  uǜ5U9Yk6Wf#Met8- <߭NJUؤ G٩񃏈tAlMWJT[THY,/3ֿ`T+]9~ l߂6TLψgU[g&<"=B:rAn.5ܸbBn|H^ȦaD7MtQG7V"LfdR]yEL#2#E*[7஠h,e]%HcJ'x$v$}u>bxا=Yr:(|$@-i!9Ʊ9υ.jKqǎٌ0N"GI=ܤSpONbFl#`"-K "cb`ifAnJ\<}7=yRb6 6VE {F13tcV+!Ϣȁf^ze3%gHO,egՔbvL)p=?߻{ iGPhd[j`8 z]Xpے{zOH QJ 鲂) {zJk\(8RM*:FNDe6.ޜ*<4`'8O+a?uS.W3\#i|XX ϷWB`%ȗ h#iU.!O#H ژع =A?uwlCƗI upC5/5N.NvkS/m Z D[TNFɯ%fR_ͦ®h|S"(yzͱ&(~]7C,~4(rVl}ݿ K?KD(K8tc o!Zo83Fܘ$Hm ca"|Ֆ';Fd-Ș }ׯIU^ܧPD4qǔ0yRshk+kw$'dCtz1A@kM$o4zG NmG4Rxqz* W[ nrR5uW|,>ƛfeD<ᆠԹZҢDz-5l{iCmL?(ZW# Qo PM! t:0l[eIbf2HP.纎tDcKxiy SC4 yr{Q['H(KU_n,߷ ={,je;pq4~?+ree9EԒ<95?2+XyEU"~TtPA`Hi&Q*U>A$1RZ~0±a>\ݎGAn*&U]9y XS|а,X>WGÓ[hsUO HhLT /8Yb Ffc ⳯J&]n0fʊdN'փ9e!s?Scgq[,ah6~:搷sr_ᝇFȢ.}@[ 7-^cJO=g,(0BE'׵9۴3gdl/^SC"ge +_Ă0_Tm:S"B > r3pahHLsb ?~.,3;+f>h9 탣52BWF;J"IܥGx O[3<̒9)nyZvYυ0X.ku({kȵ8T)˼_!x踏eeL@99]`p|e.DŽA`"#SDtS7kYIr֢(0;+kUV[3צ8#!s=3'$>iMĹE#!L_9Pyۭ-f!`Bqکj1M)`H\#{p DޡNcE0@,X⼒Hluy!= eh\,8 o1ok_!ӑ ok`'"ܿɇHZ8;W.s#A4١(֩Ye| O~N^siL]Ȼj"mPth|։G#Q 5 y;~YXM bLT@AA΍VJz8ʿ5 =6(c}<@Dpb[EЦtEixIɻS"ȕWFCFii0VOѹ3U$וmI1_DJKJ:d$mbcU_l @s>,a`K E?@p$ ,_§Բr8S3okp0ũU !lHsqolSxƒ}{rx>PnbUc'VL` {,u,c#9Tv%FE\Y~h !AF?/GB&y U+|MČ$)|Q!Ab'҆'@֚ vgs T־'qY q~r,Yyzx5]+$ῆYFhZPP!+A,an1=DE& gq9Ք" iw؁ eh$?9Q[wJ߿p.QsXg#% cA}:"ѓ MTҘ^Z$7n _BVZ0^jR) v#2)nǩ=^p/:ꃨn{iJXp`F߽@u$Ps8IBsHV ŔVSaZ|0(&܉&.BAղ[K#VyK0҆Mpq5BfU`xx( _w{ޣc;[2h )G"mwJ \xp4ԙ/ʮeY}[Qy+G[n~Bd!"k?ۤk&t43[w FZSam5hn~2UI1z2pMf:.| A``esk ,&U38 OMMI1tw#H^Qmp?k(Ȃ̟W$ICcDh;,܉=gQۘ4Þs.[S, ` S3Q',E\ʋ&u21lCCRv#5´Ke۔ڞ/@:`"D-‹ csD',kl:w=5f 2$4dos(xZ(svQY}C<o|xu4`N_`gXtF {x6%pkO4/E;Q7$[/q8Qa!Qv Uo هx-1UX9D/=|(2#8Fh|/:q^k NKP9}3ʅ}3B-ZNf}23ϤygY+'c= l=9 rcڡK~MQV+zH SDaiLW^z+ 3#PʡI;k2Ǩ95o/[f!{-Ji# xaXUYnU'iPѮ”dH]xO+I 1] դsqDIG/jT9$ᄈqsRM,!)W<CeyYu D'5; қ7c\{s )cx停5^xkz׌!; K"v2B^*(> l7$L¡802NzUɮ|;R&t4T!GXto*ہ8@UvhB3:r=UFɵЊ ?ijKOMpH_jYVX-zU KuhK͕o59j-_w^[{fu~,#88#^jo@˙&PoPhzĥϦط,ln)Z\ [5 <4N9KvZA<.r!XZ5Lʑ@Q1T~CdvS## ,$U QۧGB%pPAIXAMeǸnO3 J0U=+H_W{lb(oxJZH}tLXk|Q!kRZ;Xn&[,&ÂiJ@ δԭQPDPy1,"EO,0P}aK(Գ*cs,?lVǬzm@I1sK||_,:+ /8v@WB]Cay}bG%b?} A=Ae{}S1dgnӤUsTVa:ޮ!= L+#0䖑3aU5lx Fxx2T@{cIԓI0^kV8{ڒ<đhSUoVn~oC!ڛ W $'Dz 6* aS*xs4)yoZHj°M?;+}=_4ڋOaBJʕ*K4Գ*`.kpCe6r+4P4􄁤YH&|x{qYQ\\Η{agZ#w_x"'O452w;+@,MV~s4LTA=́xO㠨u1"FW}}H+U`HSm{EOC_~ߵ*aI@ $03 %ĪWYs%r ;a;B. g*GL Gx>Ppn=I܀Lgis2N-dڵF- $-2XӚ( _845硜LJ&J,Lx+ .)Ⱛ,@6ٺ]* ɬ(( (>ûLȆ 3LV^ _=W0yY wj iOgZ(` n#X+,vc`e} ٢mMyyB)n9[]ȗk,Sȋ7ABvv4TpURܓ,u ->98ʳ4zn':1B¬Jkt3(.zҲ#uISAVrкgJ/h𒈔zTٶE:&p]5MxPɐj%R| xFֹ9h^whtyA_զB//9!8zQ/v̥zLDDFN2ԝՍB!$3C * !ZKf_cxQ6RWP|uvi2H fh7=eO]2y+c(J45b~|@֛ 8Y/RPDp_`Ri0l|Jeտɇ7(¡:T"։?Jɤ%ReXC֬m|kJ&hykm]8oKZdsB=llb4-_%zA y|a܅c)G勓hp%b=mTrt.8AX1Ha}هblX -+i/#( !\cQ&UNT^*+=QgVClW V8 !Mp8'X5+DMGG0ch҅ e) ׯ˥LRk:IzKuݟŋGc%_!v!֠ЃJΤzJ>drp^8EF]}S#yIwe'6&%1c`EwR@U_\n8\c!+g@#:'uS*= E[F1PЉJC*JLoagj"6:fIWMY{ L`& rasrc<FXk >x<5;1Do?l4MqїA({ol NqT8) E'鏊xL k&mR -rYp뒑,U}BH_ k}\%'`Oޒ` |o]$*IrɜhN(7ƨ}cx7 -9=iyZxb;\G6]a&hVa-`Z)[d]j?8Eu39?:.ߟsĒoxR#n3z'y:7hhwǢBBG'nm{ ^EMf^s.J oeK?+uBAG7"Ye\aÚP-F Fg_uLWpG%6N=QBmVƇq9޹RdF}~FGc}c'&cħud&e5Д3w;})7UB|#o2DjW =pٳkDez fa3'M`r66]T:sgoƤb!vׂUNOJ}PԳ:^epCإZquxMA< 3y*c@8ۙ)S,|!b2y:&`wz_G}F}l7Ӧ?yPh;5mqm9ދr lA2`(VC#lg nJ7_"z $E<܆+nQ+SXK4G<[oTČ\PS3Wnmw?KQy/I5 Y^zMΑ;3Ӿed$&~d?tFl%)>qiHXpcNƈV x`-8Itv :|GR-X.1&.m8#3^_ɗƟhE\9"+̯o]2`M /aESX"/%cLsHqiV2&̃ygbUJ. VvJHK 68ߍ6Vy GaR-xOWyQ 2cL;_S˱&Ӵ۴^vJM^ 7L>^y=F]#ⶃrbSPZnfJJcaz±O*0Mt$&F۟J401P զϚ=gRH \?y#.TE?? CqyvHE.%FG"Xf6hf=|zke`_! s}$d: s}eI: d9k:2{T}rޞFzPO_7OPՋ"sg)D^!=QG;E^e{c⪤44Z}Zݎ2XwhTF\H۔}]4p1MʈMk~-uFGkH_ޏsK9y=9ꟳl1Dž顏I1 hH쐚5"AjX}Ib*_'@巟s6ttɚ!QhVHe br lq`!+U81);wu0=Xǻ{HV} ̓~1w/0͔Te%<1m#|=Q2Blk8e8·ͣeУe^ uWˎ{Gzq??Ѓ~"@G8ecP֤\A "5Gd_/Q&MD1IdJW߷jhhXrś|؆lA1Hlwa½yG&0QId ѝ_Ia4'9# &npVVDSubp@MYk6 S+XaTN9; bC]kq+2~J~^(k '.Rqf@6L0&uL>: r%`B[m!o>)h(]g:;W)7p] t5/S&;jڜDީc&/dxn5pI'N|@A5pw`R[~*K[GREI$E&k |AD92%Ěo~^{^y[0s¤UX{̄/k&!xe_W|y߂6*,1RNOO=p(JsY /p͘=-NC-V[SX 76G/&>~{ ;D n_1ӌjР*mީKPEHvszoE:KazlG#a8E}g}-m@=F=&RNh%j*ݥ1?2zqUv Ϩ{rb-SKc%]ܣ7 +&=ߖWa,1d:fK/r7&Cf ,BZST.F'-fr#xt|r ;NcZhoܶ~h}`FJ H$ @ztn÷*QG`MTGN:Dzj*e] 'o47f"mm .5RO`t[rpފL'c$;ˇlL9J3@0K(<\{ A :kI?_10:2'#A `m Pfivin$ mx蔢@mS#h[ 06{G{#ͥx᱐t%0Kl:zا )_?cHdI(T 0A1j!:=4]ϏDj%j'0|U=+1! :"XH$UA7yϓo,~G3F[~@X;T1.g3w\Z ݳ ~'b9{' Ƭ#~7 ^<}#Ƙ'tw~HenLwADcܭޔprKݲP kҁ^?썍Ǻ~l#Gk=u"1d[JKuˏ%0f9/Wu - p ͙䥠`;@@N~QJ\j핻QR ] 3hYeP{\n/W[=J{pCm)k`Bc.ԥanpMb_L--H,nb\$!?#{W -GNk<CKeM,OC(#>ߩpzW?8[?DRe|[zP0%4p,? 7!ۺbF5ކ|Bqd(}s}0en{-"9minҁ Lpam!NnSÖ𗇳EuwMz}0徴xF*8^ksZB_[+hSP!oХpLF-Z`/"?i w_x؞/oz&ņ}O R&s;@6 NM"jԶ$dN>7]ZV֊e!F6].cWL4U3(#l'T$3<J|05@ D9`elױ@ckg;ȨWTy)x_Yita]-iUOFn{!_`=_qeQj>+䈢1k⨐$N}uQcfHB ٚkݲ e*O`Vk0y/ ^7| 0^ }7BCX h#푄lC=&~첬ְO] ۩ړBۉȒE)=DeӞ[$"傍EgD&a0@d"6|kXG.ÿ]^ SI/'f[N #fL-mF~@9h?wO0y[p3 r-tA38=`Bh$ZFd 渖>|T)yMcbm){vṾ!V5@+#fwGA4Ο=|'sGs&m!_o^{iW = S5O۪ cMx޽Z32PF(gC)ELBZ!~3e|] ad!(쿼>\4W2 r`ё)P^QL(yžeS 9w2ny%_.|X7UBkPGcpeQC$@kz$z 9W(H)BujU$XJ'%M?46C.ķGlMX ?  f=`CN-݀ 4 3SS&b>2Ŋ^ z"ҮqNzÔ{PJvE7AæVN:W 6Mon!Ի&0ݟ|94ZGuRr{+V\EÏ *T3U{k;7s7R ֹo[~St*FlE%p,8ik|Р,UȠEh6=~y"nab˃B!s1CGLvӝyKAq'c)8؅(궳'#! {Ix@Eh<: ]Uo]$h[sێe4ĝ#)6G)v} 0v/3Bi8H*lVm˹'Y@>]xr T,wE_16bZ>,Q![ a難j2+9 _׻@ujc[C!rɁ%HlŠ #]L ==!G"7ţ?n邺'HYhJ[J"ULU'JFhg`Z h o'd!,]IG2qû-գA9ƞ /9(]\ S*(S2O;j;»M-y:ʊh)NM\҅o-V0?1{' K?bK#1G#Z)0t;W׃'Fȶv.&4qxS)?{f J4l`+}?|*׳霗AY>;~7\ WOK Dk_*e5ޣZ Tg= *XYD#asЌ^O@l6dXm)6[[.8P>;g3+2flxad2§ϋn%sU41 VGˀLzyX=0-\,0<ГZJm,OF b-Eנ&p Ao`q~g6Sٰg褪kG={n[m\j"NpciwDOfB D)>t샑?m3t9$ ѣ GF! 5 R6ػ_XIoy0O ldn '1NKJqu=?;TBxT(L~;Yx4.,_C2 7DUH.+ -ZiP[Dbd\Q-xz⽡JBJ mqͿz<+5Xʫmɂьmqs|s)ϾwgMigvGH2hMH`*F&;'nVLt#B8 R\*F]Np"l6P$Dh>p氕أEq5U <_X x鎲]3$S:I,uGÿ C^ ?ZFnprTEsI ^f6aU6,d)#kwɈ#SyhOGs9JG~!NE$8M(eYjA`aQpTߊ*j\&.,aj N9 ~0:+h .UEB'(]8JNjpy:BVkӃԹ^nAI.lʌ7Աt,niC;pBв[ 0U^3!aT3/r?j272pM2 -k M31#X5ibEd)؊e P6LAY@m}GN> @Bs$|_KTȂ-}P܍NinS vO&SxK.ghҠRە~aG;[N@N;!=v" D.j}T7np8@MC'C Im/7ݠ ,缟 *u&%T_I pIڅ)l!"6sz}X  +U *\~gl Vs&U^(#axs"0 70BfT͆E}ؒ2^>y&֧ڻ]n9z ރC*Lk CD^kRF'?c94++RDc) PF8) %"炭Zy]J#^禾BOBhM62w |>\(B2Ӕ/b!Y Uٽ|W3ԝ)n- `yXt$cxW"[Q[Ua +V-- !{`+7[{v)T(8% [AjŤ) |b`TE>D,nuO_ ^̌r)jg^lw3C6 $JӋyNqI6Yas;\הYq+*mk A5w1qLT9y36kRܘ mR9֭[}'R:}8)+©N\.x'NL9zYj{}y9Ty&VS ;C CFC:||3VR`ݮKjv6ޘB\SgHJQϟ o('̸KeƥI"Rq64qdWP^"2ɥ3IzFsvLV' |iw#!yZ1[ 8e!Sm8ir?|m+d/eVX'TO--sefHx^52X66rEe҇;b&L\\ #^:dT e;b{iy_QY3tL<ՇcYLe};wV?"M1B( 2oZP]; li{]{u58Fvq_v:N~(_~euB#8ўkc,MhL3Wyh41Ԥ+cwj"nSrԈøhn7U>gYZOw DFy_|Lm񭶅ۙ-b O? } Ⱥt'{Bڛ"d>[F~J]\+ x^ 1kě M=ח˓STWz'n cA/ ʇcxmlu@nB |,{֯ȳtav/vvi?y xk&x2sa o g [r;Wꠛq]*];& ʕ.q06F 24N ] (34XY62iڼr)Ŋ7hn Sy=0Fj )YfKqèS3DF@ qef2EZD<;q$,?hX▧AC|Hq6ƥCGN-sYe "Pǭ} 6j.<%1 ?-0Zd7SKGN5Cz;9,"IIHk2A6`#0m:zLY= sp]6ŐT}w6'$(zXv>]jM#L L +'x{ $|A#((VwOv.*yf ў}M{M^|{L&~3_Z(2HVҏl~_ӹ¾͘Va[DF d,||LSVIZ]:.NxΜbyre~+ms@]a%p4-I& ~";#gv  xf"ZˮJʑmnm7*; 6 ـUEoFʹ'f]g)i7FF ,Tb2d_|AA{&?ݿE @WW%Gۏ;hBݢ]OyBD+_ "-*S&]u5@RSryƵeCBz f[3kpq4kȥ]3Bě'=?eRD c6ֽ[̃(7QFLdw`#*ud3r’˞RiV ha\x6Xb"|pe)wz_2>@7U_ySJii'"ӚRؕ'ѡJ$p54Vo>j˾50e7b}7bWN˾f\5Z j=}]< w2ku[Xۛ]ѻ EN&,=9n␶pP\<"Ԓ,8G#'//Mդ+9\A!]3i7e%ׂU Kctg{L_$whFd,`8oI|#,y<WLuhs#e Bc[}W_H] 2A!WrmOr?y:uB\/Ӿ@2ٖ-j[ l>j1YQ՘,J,zqXq(fKP;e+C,^XĊT5I;/Пj K[ Lktch6 )]j{g!q> ;&$D.ӎfsU𗰹0ruE.]kF_?yPb<#4t y$ ۮ q @Qr>H4*[ m,k[_†$Ԛ"I[`VLjxE$ 7ȀCo3T2`/-w8vBkB"{<7g}6I2 Ak53vАg:R3!l,ax } Yfm_΋ÄޮA2Z+IfS:65FsҪގIEm{ |n |X @gTgۼpB&dƯYHGوK||x Lk񉎵  t3,֑3Cت 6'P wJ_fα>Eӵs#p ?KIksկ2D-pktVO(sSBTZ>ѨASJms$'C׵^@X^9*gKfbֆ} +=} Lvx~'β!TZhh ~h]zĨȎ0!9PXǓr@TuY>]xf=:m& ɋ'2+ [a.ݽQr L򉜗M'_x߱ oRIv2:Z\8`_p؋c $Lzplk ĊVU9ьw$,j=ċ; |Tf^Q;P?ҐS 9d `80v҂];wM؛)0%9>KʐvpVePp1d̳[Qۑzw{}D IѮ- }gKv|lkzE6tu?WqQو3S00Pn'Oy&oH=a?Q3{;K\6`vhK Z_FrcM?SW~{EGB &l᰾76O-,s}45B8MԨ)0C36NzÐsq"^H2J>9gxQ5z%GxhI*6SRFƣC!/EG8e'%_t]Z=ĜR\֔agKBy]G; vwR+[_"?=6{]CN1Bl%Ãȗo ]:b?y9K!IO=Cfݔ`*DEWyXyO3\Dž8$ Y!|$$!Ѷ=5/2kqy7S_$>{I㴞< X[ī׀HK\vsxvZmWxߪH^|O}-zί/dpAtI~+0f$(ėwgٝHw# Hg׬ 8MiEb7=I@S՗n7O[gA 7wnUR7}9(nkKRC`mU,Q3}S&&\M7PNaQMm\.ˡ%E'M>׶S(~1Ch6:`B%sh,|)Q9 )K+CWz8f1No2*Mf 6~+u:^ӆ2M Me@8Q{78v9n*)wɇG6O롈JRUլ '[aG ܧP? $%iM*^kl٠, 4|d53~ۚ 8EfZK "@A%_ᙄ)tJoZh[f@yig y S- xm4+nC8 ;cV<%uc( 9 7ۘMdiwbv\Q^!ta{ԓD 5.n0iNNa La/zuz<7ls3{=`̴4+o2et~8R:GH2FZ|:].k/ry/D}w(潰vr ˱IQ:^,^k/^ 7 Xnیɉd_t1߂XMGJ,g! ᑢGL`L.͛OͅGƒ)ao 2 FE Z<0qЁo On.(OZIJcUh0 oX~!s)C0&1 <_RYBtJ 8VkdAw{"TԷ8jJr3Ǚ.|#Evs*,]xW)*a@P빍 !zsc}KCN`TQ_mزwY f} a-znM!'ୋJ.2aAIwwf-(zl3Rcf5X{wE*a$(Lesau@ԤM]\ J!c#zO Yjqܧsnh7, #wH B>Wʆasy}Qa ktԠzunI{%A;jAb5s!2F%RSnܳMC:j#bN {Vu[Ŝ&(R^n}rf/;\G}\%c4& ^3Fc@L<Q}~dEk/B4|6UhᔣpJkNM 8E#TtU{U\⃾lp !QSj}SMK#L_5$r[s ݐ^?'5"Mu2z6VtTg_ajB"PbGK$jbn㼥͎#>P_xB\ +a1)^4%?z,GY!x+OjPFe|SufZ a PGT!SSS<9U.r(8j(*n= (#|6 <ɂfk3zRpJǐA`SumЖ`_N`J He3$zpfUKͩxr>􎥒oqF4b5&#m~N^w@Yquᒠ"IȖj:dCfv^@oJZ猓qߌϻyzuWVY5Y%sTw^ώZĀɪp%xw.tT (T+ QSU"31~MZ((=@,⪒31O59ϸ>J\+ uQ-><? ,5Vp>do$7/w^@Jç?UDrpgCeԲ~\>tAZq`b˯)wS#)k32*թXYMx10{aIK~c=}9'I;NQԹ]ߔ-n'aKFB=sQ>iYUՒnCb|_NmVį_8"u%nj}_fkTժq9y_X lЉ%noC[CyQ# ɐV㼫K9Ex~h=x,xTmtg?W+{Ѐnc7a?y|˶WtA*SD#`/^o'#Zq-Ro8{=g*ޤE#t;D޳eZ,ZBvM2y'X\h*Um=UvXV_+^O&q8Ղuqrfz,0"}c9mH(`aŁ6sCo3 k)Fw*pX]U~ c >3%ésA[Q1y_=ͯ?0  @TK߅CMˇhѨ :t$_M*!~ pRᑖ a#r14d(D&ϒYQĊ1h*D=2\鶕[Xr':C*q[t86rK:pqoK*&Gf8L9/Fwl-+Wj$W,5Z%O7rzM*&j|SG 45 |Hs "vqTM͔ U,0\R5k>u2Y[:TȒ.V4II{{#`xo\t򳓽fr*nw=@wI`J4Fd4JvPAKXDHG^3y=s$^7-e-$>P:Fi;|4geX{w:8}!RrMм ;iy)7fNz^/^X!)~pI|E.ІKV5"QG}aj7cTS|7d(̑ QׂJ6FѭOP-aKb50vM Ѥ+6B/X@fp)z{y{z+:C}V>(\dSwߗIa1yևo2vv H2RP2$0=W;BBpRDN2F2QQW .!@@ T ugFcYW%)i._[jʽO<;nInW08JaCg7o`~L4p8M^M$y*87f?p\?E撱~|TWwt\>Vdm|T~pܧ5=Z}ՁrS%)G0HBOςOGp2MӪH:g6Cݡ$,8],7N0LotN Y_d 2oG3 |fc5kVs-ʶ; M?HƠUax֧?QFbczaoyQNc QC=|K/K-µ`ܨ:V.46Mn@}6 TDP|ߜXKq8 tAŜ V'aԭ"t|Cl}\r_S$\@Ztv'J ooZ|N`:z+f)?S 47AmZ3^_U0訛/.m[Vdijͷf5w䒿Pa;o(Nfnd _KCœv@w](bLR")l  DӅSΕSڞi"#^Vw&!*ٿ1HqWC _|$qB%ZA(;`3]p9cA%gvzgȨ~YSIr}j p]!}^^ua9֔W[YL ð5 $cC2 yA' #~.߼D(4٢858f*66`_B]sDD%^*lED7VvBW=تp.J!Jf 2(ЅYv^'UPaliR;t:Qv<(~+(מQzk`~lܯ㭥Go̪$Aʷe -N=>89Oa̲X%˯`cjי2CLIjZ 9 *^=dJ)6߂c,*v}m Y)B4Ab NT@k7ŎC7)hY}'Dmᛮ1IMƩ3E*WcTq`t( k]b}P@{w(h]tl,RדATߦ#.lzi-LOSS8!O=WOȀߨWaЧ͕(=zjm #R+I&nș&UL#tp e͜kP:̷9^ŖSU`ǡ}N@>V6;cUV&K ;'/rN$ |z z":ù$ֹ/8wgV=I͸wҞekf]IZ"If/m`׎FKxüC;ٹ7(MV N)A@-}AShREWyxQk_xB2'V{'G=_E+%s|” Ndm[4?3N%ؘ$|jo䥟hسCQ9 zc͓?_NTBx>U٩ثw|LRuq۲iz]#2sD&w`=wѰj &-BjC.yw5?+l4י Ek/NA%Yi `ڴު7Qg\eدC9'@؆UK$O:Z@ ` Cxi&E‚zD"gnыv˂ok0#wt lOh'KFkA;޻ ]YxZ_}UʄbgNyB\rKvk[#>Z -D1bFE -kW7x\̳  .7 v2'ej3f+3W}}@dVp1HDzd( Sa}|wE?3z AU4ۘlLjY&'7dU{&qQt_;xEtCK-O$fxl$6NUɗXr%#,d~W%~(LI+Af0O2Ph3QdZm//`B@z{8~ӏ0a-jV p3Yf) t5_Fqv1QitBQai!,EHmL?QQުOݒRd%1^=P&ZvEW=PLKc c}p]{ł޵>d&䳦EXdO/dkBi]Z|R"t œ}xg0R^>Ju&]h݋$G;t 2_n+@7s U2sHV|Z lB0+ ǢFr#il1ydxi@ut8y7b&/x$] UhR Rҕ0:Q 9ԃtq65Q?KYݼggb4dэO~wrl 'M!cB!ւ~ WoLݬۀ wd%6E[S8CWEڡTIDjJEbU=/`%u_ 'w%s7YZz.8@U~>#n;$TY @Ry̵;!26*B#i81)${ A4m4adin ჿH/!_{tل?*Dxա|T$Y=Ӻn{Uqcɵ;8T,).(B)<^|}ubu2&|B Uo9[t:u9Dđ'S?ta޽f1b@2f/pI$bgd(@'LVqa/r>xڄyfyF=i+7-m>}}No7-nk3NߴMBOi##M@h#{J}&@]5[f@2Tmh-v4MD!ܘ4`~pG}s b[ײַ(Wdlu=[CL lԭ/WdðGˆY0Y@G#ҺzucN?>drSCCbT ~1~BY ]ipۮ7^d ɣ8 $p&MOBձIZZU[`Wϖ+ZǮ[CǠt i(=3bBc5D&9"UӲWTE~\fj/`?,+yu*EDPQOȅlB^NYyDP]mu"FԊp'$O逖S/ xAQ÷$RRkUZ Lt>fd6P(hl4c/GA9b 嶑S2E>˔ބ1dA0U` .f|,D 'qOy8[!}4/ (0hc-~jze2[V˥wX{gS :] utKkejƘv a>8IvlÅrYP^9IKaa}i~"Cy3|$ɸ)-DlSQZfu=,ӭ8Df;U9C.Q~kDþ%%NNyv8R~bZqݾU6=s-%Fx7ҲʆgJ4>]Ve2abOSz°|XDwy]C7;XD:OʗPS2_^u˯>YC)IHQ{E\yTf&߭#LːjQ4.?sX/H#̈́,P:T 7iѐ# t(x*󴰍YƯڔ{)V'좎[c L "]w{O|F\ENr}yɍ=_pK%n8;9)8mo0Rs_7u喀;h*$$;ρ?aFXm4],UhzV}/+NoXڞtyA+]_失@y36 _4aHMUb zluY] Ӂav']Xr8|Xx¼R/o$oJDop>X[&pqLOX% 2򖝺FÜR"Aۋ#B'>8(,kUSk^n]w~9-<58"vc ~;Ƀ?/Ǿ6뢫xw#&*08@/h4NW2%8_aY'dhSSi1JڅIFY54$y>jJs+ `(+/˿g iꝖBp7NǣW 8J͇9Ɣe44:DƈM_ dqckO:^l;'SmŴ2YQD'qWrLҹ)_}cRˍF ܋ǿx TQcjKb'b0HN&*,D0dյߧ;{tyODT>pKeZ`D̨:8^W׋{^x=4pM7*5E"3VJILwŀy'5<٭SQ8ɿsG ^ٱOBO2IaT^Ȅ8cO)lFȇf`̯"˳* :ݕOr P ݵ:[4={"m|T'0paA[|oQ VЬbV~$fMJ6(MU(\eѢNq7#o7-ٟzTN6*|o$HmE&6`1¤K=/ݩppL7э4/ڑ4;qI._ E^N=C0s=8Ӛ n# [w<-mS0XjSl1hZD5>Dۅ lr<{gor$ c:Ly0}7ZEXYOL|\8\*3Ls$Y&Ngf^ѱNט7׉ )x/NooVGVSmJ,66_ mc 87RSujW!=BbL\]`v~Pϫ%43]y"Q*=derQDR%F+ZА8ꒀ )scjߊ:jXy)yNg15~8Զx[w4OV,N(.-i %A]Bqtw_L fb*hn/rf$iŴhA;ܦc)q~?b߶(*$,we vfz'LۓNu0B/b=7kǧHrڸ0TCa7X`:XJ@ʄvFح Q"< S ښ7ьzMlwN~_5VxjH +b9>&q5s"UZG\桑0ةRFg290ŷ9YGʔQc3ţG;3*- 1l# 4*"ߢcw26O .-W+%vB / ʓ=@ƤB.@ a=x%OVޖsd$K,bu;8?ZχpsQ3:2'%Ub:TX_l(!LXUͦ0퀚&eYzka0՞UW/NKsa@4㸯/!qTSLhh Pqs>_}&lyNVa\mRHJtVYB/O|7X萻ۢX2kԲΨī]Wҷ^$R\,eUVUp7GB` ZJ>vIMqV.u{jjBXEI<7[Ǐ#O.iK:n+r 0`ӖF(Sh rim޿& sɫ Ii%QCpL1!Ь Uh2z1i*"`(*CBOw$31Ph{p@15c>xML8XI}VTUTm^8ko7ϙnCd" }:Cpu\h/Gc!9kuJt{bTŸ 57VpᨑއG4FՐmw_ƾI:FV%AM{!eȔ^.i oL!WK6H351-jBÀ "@8̀ܫ{I\Qx3I0mW+`sm*y9W$Q(5!RDen?e+@4{p}#dKG MvYἁs "asfVl1òP^6H |;) "aMXТ|))!d-I&ϋ2 4\*Id2 8v]Ƨ& R5q %gbW9$2z/;1VwM y>j /]=~ 9 h5:^byֈENt͹7T%CQXh+) K- ͮס i`7ގly0Oߎ ]ڃpET)c" f۪Gjc~S\dby#='0cg7V2! AIE'(S*``V<6UZT&쭒Q s}i"͢?3&d BB% l][4_}70a8,<~9>R$+B1M|͈8STzpskk\-׍żI>7-+2r6(psX8p#C}RZͼr'on,R{ @({rm"$fZ8a'KڑK;<01tS:" u#Y5A K:{B x-!ma%AiNzBO3#KHW:✈Bķ.; dRT]Cg7'Ćg3v8a2yc2YڔCZ.捕n 'JePj/lajw쀗WDs謉}ݝUw& ?Lİ)MUe={Q*zՁV\޵Nv|^?)֑ *g-4֒$ u]Jjmb2% k|\ =հ%ӭs8Hn4~SI^<~r5/ƒ8r v%0#QQ,ǃnV:TpYd?HMj\Z7qcI>;lV?$նֈn2f#;!`Y\t>qܣ{# h$td' [4@ISSHߩnJfӁ 1ewP,ӏ(Hɟ[Lhqle% |k%XzQUIֽ Sq_T'%hbeϤҙviWe竏d_߻X !,GBpL(-,-`rR}qߚN 8 A״(5p/_U>=v1ʫJ>G<0 %kA1wt>YwIeh[Ӵld_FSH?w폳r[!hJ.r> CӾpX։6n߶۪͵%])q?ZooBCisOM㮙qŮ$8] ovklբ9Rk} X*շ]$]aVd3s&0\dGm:'ϟЀ~΢7ؠ61& 3 6ry."U4 j ƦQ$ruэz.Yֆ棴Xn PU8u%Ш4XBޟ@߁,QStN P<Ѥ|7-6a4nFPJ>r瓭&"n3owvd(5|2=*dD%m6w~k7^sod)FEɱ7| 1\)~1++~+Zof yD)HFk-cCsbO9&:ҫM &+O ů<߽-Q2i_glS^4кM,etg reEuL[u8.OGBr_ʭa *CCl`3kEW϶8u^5q Ϟo7iN1}}0[R9BQn*/{i00>@uosHIfCMY w(\;1ԀiECY/3&ia ؋BCVѣS.NBf'X>*rܖC1<*L/f]-p=($w>r%Ts@BɊTT᥸tLat,c hű ?SC{)һ8m笎fkViByW)vjSb3rWaLL9>"(L!;Bc2C0 L:`ȡ,N!xZ$)Gy\e\C4HSoa -^eYa9Z\$5\NYfIω&cSZUv89(% ;kt/-jWo%-dsFg% iY1sKjYը/J='=uNFK^xYLO]~H. `7!8Y|nu>~qhXV7کā(L& "M6xDpi΄3ֆյN,,!.j[C?U[sn, epten̊Ny=El{y I{\I aXۇ-^G̉|>9AZ;^(f@ ! ѕucN6M-=mlYO<!̚$`wx}#nVI[۟k/"j0ba@-nM%[] '9ȬC"~λ1\$su/1.+G{TDcWd2:.Ч]\J riunu-M,ea,#>:G} k=3OV X) xZ=\|/4DxC.Yt)j@pL㴅yH*Iƴ ?7Ŵ3s`<"K@ssq"O^ Cea ѳ*njnOսLo/,G.1vG`\'$:Fk{o&hm"0/w~N2]dfjc,8Ӕ) ,@NE.Ud*uϾ,zs7&эx39Ջ"&~n~T*2&{.T}SCT6x C~i2hVAKi\etn+NdY#E[eU&9yىOoQ.*do]CƍjaS?k҅.I,!a&v8 D3 I&C67 b6\U9[a61j5 CcKǃAYP֗ ^?? _3C5#55ߠD#fC]FJL^>?KN 5`H 51mbspndj7*8|UE%ѿN*<:W ŃR\H2B}75gm~ÒsuHIRhA 'ޏ{ġF.j>~&BmB薤5fGXݎBb.I OH|~>mz3#' H@}7S׼:klgubZ&9r T+o#ozmWJJHs.(\|*)} ^&u X@}'!dgDA`ZM>k[O _S#m~p֌y>R1&eGP7>8ŷṔ~TO/O|ZB.@|4M7l!O«르dc^w̵K6Pɇg#mBُ#_{AȬ ܟ+2gs*iM{P!! ~"*S) nEaڈ 9~Sֆ_@΃Hv%"ـk6Hp-*R(2,65xܷHӽ]h>;7|۵@ZLa}\ ZjOqf,4o})kx!v͛PT4 "ڶ ̐7`.{V oU:ubxyzimAH٤xqw BZCm +Zt2dRryKM%JfۓCnc6SC(XV0"i L As} ss)pگǓ~U Szђ'g9b0o5t,jݠV)saȗwv7ip@(FeCW0IM+7=(" G<^?f",@UdS.B =Wvf?@@ܸ+>$a*__۟jB#~\Ϗ7(*Mq[q ' 3N2; d!baH*f:?we}_Y;.$5l)*82X>>WCBx`]"R[z`@nElߦ!Fiƫ8抖m4%^8NOAm` !k_N繊%+9 PDZYVjϠ \O$yK 쭞%}/bpK+UߔkxyU)ZHKA-sc݌s%B咷ĶNgm]$(v }+)? $.5\LuJ&Jr>r ΗaL#EZ}}?*$>Q"Y i9"PWAt #M%G^ZQ%)J]vfxIZTt{c?ct~0\(-}9B 6o i4{:LG$ܜOK%~bQ++.9:.}ՅW=/mpnW<{|I"&RR^$\,fۆ9A _hRsfCۀ%'&A J\h`DW^r=a /zfK^4,;cvL|RdKޑxhJ[DȥXE>Эo{&Dԛkh)ͫ V|Z38y/=ʲUW&qjp csT.r\4:Avu5QceL8XHUB:j\J u\e \Ug$;sq}O,preT{w=˥ 9P:> BRPB-;$#AjyS< I$>?3ܣL~o0Ƒ͸rs3Dfo?dIѾg?^j|ܐЀyއ J=T}mW\ç ?`f>@:D, =gGN`!-ӋP&1N冄Ǽ$u/n"`%c`XkT,?|=p *۟ȗ&{ ?h]h|l]|T%_żxCB ό \]%|}{k-LkN|{ifNf1Y?N&h'NE$c -!/Lw!~8$ƌCe[(Rw9J=89|]CmО6dmw<eЬvϝVP I<ؾkBf,]JY8d $u}9V3WWASlZf{՛ثmL5CPDktOsOy*`Lj^蓫7$G$m p /e2W](}  BPLNF3V7 bs qy.a(e&j|HD UJ/aqk3,;GmˏՑɷZtlvcì6Pwxz 8V$6%aށ8@zu)ͫ(Bd(| 1r^xbW|#3x5!fBiwBoi1aƵĄ.a,m8~cP/ Dj( =jnEA:[7[TKA,ҠR9ޛ&]tăm8ZgDޣܭ W,]Ȩ-{:2e jQLz;{[ =BrO5Lw [NYEur= ->.͞ Q ۳wgD5*z4g~a] =( F:;(:!K};H͸B"f]^7#օ޼K1R¢2΋նzQ%^c?0ԞG? ոO.{:..薑Y)5Ù;Raa}b񹴖Ί֯J,~ɬuj *d=GXM[)?-%2%26+g̓F;a:RvfHG[+GT$qlz Z\n D(n]R⪺t( Y )_LO4=Rڗꒃsi&L=pY,CZs/N0`30|ezJ }5`V^oksb )bm״p؅&f-ooO*}Ү ~'2ó+?X+h!ұK hd'2ٴe?T*ЍRLsdVys(fїTtk'7N: %T= isCie1yaܗbhOmZTE)+y  qdHJ0淃DKbhl+ xp"\S JC+ή{ @@x̑r} $5|]ye!u[ MBҶ% _m+8>,[}p 5b잪^K^mh'u²*1ćR5^Ҽ@~bQs@9f , lJW1qiII(Yi8$PJ^?"Λ rb6v^`< ѓ,uHRo3H+dd \p`-%FE. ]c9x|䖃!@X\z5b)gN?C&h^~J1;./c9iOޏEj%_,v+5V YZ