apparmor-docs-3.1.7-150600.5.6.1<>,hp9|R]q6m2ۇPQ[OF4ᙢ_\-p7;oS|qFv_M+=D,*3\f*)U#unp7R% <!7\m86ȏ;nն7Ii.cZ8V,NJFé-01HŢnSB|M0|5ucB6yKHY1Y!SBWa«!뚔=Wz@) ~ͭ\>;?xd # B 5Ihnx         G  T    @P`(89h:^FGG\ H I XY\ ] ^bcdEeJfMlOud vz(,2tCapparmor-docs3.1.7150600.5.6.1AppArmor Documentation packageThis package contains documentation for AppArmor. This package is part of a suite of tools that used to be named SubDomain.hh04-ch1bSUSE Linux Enterprise 15SUSE LLC GPL-2.0-or-laterhttps://www.suse.com/Documentation/Otherhttps://launchpad.net/apparmorlinuxnoarche0-KIvʷA큤A큤hh heWeWeheWheWeWeWe18b7ab1776823a1e62a2d6db1bbbe51819f5732e89ca63a6dd3d540e629a42030a0adfab04b7755e093632fab7b8ab2adea32fc2eb640ec9586faa0cd2ebbd4ebeac1b7aa8497a59a81c4fc342ec5666f42e2dccea0104e188935ddd2137815d383e3f1c2fd71198fe319a325fbb9a2068dd73b2609e27db150d3aeddd9ed06afaf9108909890bb258f3dadbbd113fb35878c5f106a107850d33d62c851288d5e33ae4afd85d4e8a3a0f579068ca74e1686ba4651958a25e6792c6e1226f58dbe26924e382467ea63dd33229f07de8c3503ef5eac61cad007103e59e545bfb065b734a62259324cfd147c49382f1f4d2b4389cfaffbb1052eea742c669224001e91ac861de966cac00dd5711c9742ff2bfa9793a2848b5ae04c406fa888fbc6rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootapparmor-3.1.7-150600.5.6.1.src.rpmapparmor-docs    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3hg@e@ee}@eԔ@eԔ@e@ee@eKx@eKx@ev@d@d7d@ddtdS@cccױ@c@c@c|c@c Xcb{@bb@bޅbVb@b@b{@bwbk@bi0@bZbV@bT@bRbBb<]@b@a7aZ@ap@aabaim@aEaaua $@`#@` @````_@`%@`!'`>` @__ǁ_ǁ_Q_h__@_~@_[f_P_-B@_@^m@^@^<@^j$@^,-]҇]o](]K@]]@\\@\ \\v{\I\ include in apache extra profile optional to avoid problems with empty profile directory (boo#1178527)- prepare usrmerge (boo#1029961) * use %_pamdir- update to AppArmor 3.0.1 - minor additions to profiles and abstractions - some bugfixes in libapparmor, apparmor_parser and the aa-* utils - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0.1 for the detailed upstream changelog - removed upstream(ed) patches: - changes-since-3.0.0.diff - extra-profiles-fix-Pux.diff - utils-fix-hotkey-conflict.diff- Use apache provided variables for the module_directry: + Use %apache_libexecdir + Add apache-rpm-macros BuildRequires- add utils-fix-hotkey-conflict.diff to fix a hotkey conflict in de, id and sv translations (and fix the test) (MR 675) - add extra-profiles-fix-Pux.diff to fix an inactive profile - prevents a crash in aa-logprof and aa-genprof when creating a new profile (MR 676)- update to AppArmor 3.0.0 - introduce feature abi declaration in profiles to enable use of new rule types (for openSUSE: dbus and unix rules) - support xattr attachment conditionals - experimental support for kill and unconfined profile modes - rewritten aa-status (in C), including support for new profile modes - rewritten aa-notify (in python), finally dropping the perl requirement at runtime - new tool aa-features-abi for extracting feature abis from the kernel - update profiles to have profile names and to use 3.0 feature abi - introduce @{etc_ro} and @{etc_rw} profile variables - new profile for php-fpm - several updates to profiles and abstractions (including boo#1166007) - fully support 'include if exists' in the aa-* tools - rewrite handling of alias, include, link and variable rules in the aa-* tools - rewrite and simplify log handling in the aa-logprof and aa-genprof - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0 for the detailed upstream changelog - patches: - add changes-since-3.0.0.diff with upstream fixes since the 3.0.0 release up to 3e18c0785abc03ee42a022a67a27a085516a7921 - drop upstreamed usr-etc-abstractions-base-nameservice.diff - drop 2.13-only libapparmor-so-number.diff - refresh apparmor-enable-profile-cache.diff - partially upstreamed - update apparmor-samba-include-permissions-for-shares.diff and apparmor-lessopen-profile.patch - switch to "include if exists" - apparmor-lessopen-profile.patch: add abi rule to lessopen profile - refresh apparmor-lessopen-nfs-workaround.diff - move away very loose apache profile that doesn't even match the apache2 binary path in openSUSE to avoid confusion (boo#872984) - move rewritten aa-status from utils to parser subpackage - add aa-features-abi to parser subpackage - replace perl and libnotify-tools requires with requiring python3-notify2 and python3-psutil (needed by the rewritten aa-notify) - drop ancient cleanup for /etc/init.d/subdomain from parser %pre - drop (never enabled) conditionals to build with python2 and to build the python-apparmor subpackage (upstream dropped python2 support) - drop setting PYTHON and PYTHON_VERSIONS env variable, no longer needed - set PYFLAKES path for utils check - add precompiled_cache build conditional to allow faster local builds without using kvm - remove duplicated BuildRequires: swig- update to AppArmor 2.13.5 - add missing permissions to several profiles and abstractions - bugfixes in parser and tools - fix two potential build failures in libapparmor - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5 for the detailed upstream changelog - remove upstream(ed) patches - changes-since-2.13.4.diff - abstractions-X-xauth-mr582.diff - sevdb-caps-mr589.diff - libvirt-leaseshelper.patch - cap_checkpoint_restore.diff - add libapparmor-so-number.diff to fix libapparmor so version (!658)- add CAP_CHECKPOINT_RESTORE to severity.db (MR 656, cap_checkpoint_restore.diff)- %service_del_postun_without_restart only works for Tumbleweed, keep using DISABLE_RESTART_ON_UPDATE for Leap 15.x- Make use of %service_del_postun_without_restart And stop using DISABLE_RESTART_ON_UPDATE as this interface is obsolete.- libvirt-leaseshelper.patch: add /usr/libexec as a path to the libvirt leaseshelper script (jsc#SLE-14253)- sevdb-caps-mr589.diff: add new capabilities CAP_BPF and CAP_PERFMON to severity.db (lp#1890547)- add abstractions-X-xauth-mr582.diff to allow reading the xauth file from its new sddm location (boo#1174290, boo#1174293)- add changes-since-2.13.4.diff with upstream changes and fixes since 2.13.4 up to 5f61bd4c: - add several abstractions related to xdg-open: dbus-network-manager-strict, exo-open, gio-open, gvfs-open, kde-open5, xdg-open - introduce @{run} variable - update dnsmasq and winbindd profile - update mdns, mesa and nameservice abstraction - some bugfixes in the aa-* tools, including a remote bugfix in the YaST AppArmor module (boo#1171315) - drop upstream(ed) patches (now part of changes-since-2.13.4.diff): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-fix-utils-network-test.diff - make-4.3-network.diff - abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch - apply usr-etc-abstractions-base-nameservice.diff only for Tumbleweed, but not for Leap 15.x where it's not needed - refresh usr-etc-abstractions-base-nameservice.diff- Add abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch (bsc#1168306)- fix build with make 4.3 by backporting some commits from upstream master (boo#1167953): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-network.diff - make-4.3-fix-utils-network-test.diff- update to AppArmor 2.13.4 - several abstraction updates (including boo#1153162) - disallow writing to fontconfig cache in abstractions/fonts - some bugfixes in the aa-* tools - fix log parsing for logs with an embedded newline - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4 for the detailed upstream changelog - drop upstreamed patches: - abstractions-ssl-certbot-paths.diff - apparmor-krb5-conf-d.diff - libapparmor-python3.8.diff - usr-etc-abstractions-authentification.diff - refresh usr-etc-abstractions-base-nameservice.diff- add usr-etc-abstractions-base-nameservice.diff to adjust abstractions/base and nameservice for /usr/etc/ (boo#1161756)- Properly pull in full python3 interpreter- add libapparmor-python3.8.diff to fix building the libapparmor python bindings (deb#943657)- add usr-etc-abstractions-authentification.diff to allow reading /usr/etc/pam.d/* and some other authentification-related files (boo#1153162)- add abstractions-ssl-certbot-paths.diff - add certbot paths to abstractions/ssl_certs and abstractions/ssl_keys- add apparmor-krb5-conf-d.diff for kerberos client- update to 2.13.3 - profile updates for dnsmasq, dovecot, identd, syslog-ng - new "lsb_release" profile (only used when using "Px -> lsb_release") - fix buggy syntax in tunables/share - several abstraction updates - parser: fix "Px -> foo-bar" (the "-" was rejected before) - several bugfixes in aa-genprof and aa-logprof - some fixes in cache handling - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3 for the detailed upstream changelog - drop upstream(ed) patches: - apparmor-nameservice-resolv-conf-link.patch - profile_filename_cornercase.diff - dnsmasq-libvirtd.diff - dnsmasq-revert-alternation.diff - usrmerge-fixes.diff - libapparmor-swig-4.diff - re-number remaining patches- add upstream libapparmor-swig-4.diff: fix libapparmor tests with swig 4.0 (boo#1135751)- Disable LTO (boo#1133091).- update lessopen.sh profile for usrMerge (bash and tar) (boo#1132350)- add usrmerge-fixes.diff: fix test failures when /bin/sh is handled by update-alternatives (boo#1127877)- add dnsmasq-revert-alternation.diff: revert path alternation in dnsmasq profile and re-add peer=/usr/sbin/libvirtd rules to avoid breaking libvirtd (boo#1127073)- add dnsmasq-libvirtd.diff: allow peer=libvirtd in the dnsmasq profile to match the newly added libvirtd profile name (boo#1118952#c3)- Use %license instead of %doc [bsc#1082318]- add apparmor-lessopen-nfs-workaround.diff: allow network access in lessopen.sh for reading files on NFS (workaround for boo#1119937 / lp#1784499)- add profile_filename_cornercase.diff: drop check that lets aa-logprof error out in a corner-case (log event for a non-existing profile while a profile file with the default filename for that non-existing profile exists) (boo#1120472)- netconfig: write resolv.conf to /run with link to /etc (fate#325872, boo#1097370) [patch apparmor-nameservice-resolv-conf-link.patch]- update to AppArmor 2.13.2 - add profile names to most profiles - update dnsmasq profile (pid file and logfile path) (boo#1111342) - add vulkan abstraction - add letsencrypt certificate path to abstractions/ssl_* - ignore *.orig and *.rej files when loading profiles - fix aa-complain etc. to handle named profiles - several bugfixes and small profile improvements - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.2 for the detailed upstream changelog - remove upstreamed fix-syntax-error-in-rc.apparmor.functions.patch- update to 2.13.1 - add qt5 and qt5-compose-cache-write abstractions - add @{uid} and @{uids} kernel var placeholders - several profile and abstraction updates - ignore "abi" rules in parser and tools (instead of erroring out) - utils: fix overwriting of child profile flags if they differ from the main profile - several bugfixes (including boo#1100779) - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.1 for the detailed upstream changelog - remove upstream(ed) patches: - aa-teardown-path.diff - fix-apparmor-systemd-perms.diff - logprof-skip-cache-d.diff - fix-samba-profiles.patch - make-pyflakes-happy.diff - dnsmasq-Add-permission-to-open-log-files.patch - refresh apparmor-samba-include-permissions-for-shares.diff - add fix-syntax-error-in-rc.apparmor.functions.patch- update rpmlintrc: - whitelist .features file which is part of the pre-compiled cache - comment out filters for the disabled tomcat_apparmor subpackage- Backport dnsmasq fix: 025c7dc6 - dnsmasq-Add-permission-to-open-log-files.patch (boo#1111342)- add make-pyflakes-happy.diff to fix an unused variable (SR 629206)- add fix-samba-profiles.patch - smbd loads new shared libraries. Allow winbindd to access new kerberos credential cache location (boo#1092099)- exclude the /etc/apparmor.d/cache.d/ directory from aa-logprof parsing (logprof-skip-cache-d.diff)- add fix-apparmor-systemd-perms.diff - fix permissions of /lib/apparmor/apparmor.systemd (boo#1090545)- create and package precompiled cache (/usr/share/apparmor/cache, read-only) (boo#1069906, boo#1074429) - change (writeable) cache directory to /var/cache/apparmor/ - with the new btrfs layout, the only reason for using /var/lib/apparmor/cache/ (which was "it's part of the / subvolume") is gone, and /var/cache makes more sense for the cache - adjust parser.conf (via apparmor-enable-profile-cache.diff) to use both cache locations - clear cache also in %post of abstractions package- update to AppArmor 2.13 - add support for multiple cache directories and cache overlays (boo#1069906, boo#1074429) - add support for conditional includes in policy - remove group restrictions from aa-notify (boo#1058787) - aa-complain etc.: set flags for profiles represented by a glob - aa-status: split profile from exec name - several profile and abstraction updates - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13 for the detailed upstream changelog - drop upstreamed patches and files: - aa-teardown - apparmor.service - apparmor.systemd - 32-bit-no-uid.diff - disable-cache-on-ro-fs.diff - dovecot-stats.diff - parser-write-cache-warn-only.diff - set-flags-for-profiles-represented-by-glob.patch - fix-regression-in-set-flags.patch - drop spec code that handled installing aa-teardown, apparmor.service and apparmor.systemd (now part of upstream Makefile) - simplify "make -C profiles parser-check" call (upstream Makefile bug that required to call "cd" was fixed) - add aa-teardown-path.diff - install aa-teardown in /usr/sbin/ - move 'exec' symlink to parser package (belongs to aa-exec)- Set flags for profiles represented by glob (bsc#1086154) set-flags-for-profiles-represented-by-glob.patch fix-regression-in-set-flags.patch- add dovecot-stats.diff: - add dovecot/stats profile and allow dovecot to run it (boo#1088161) - allow dovecot/auth to write /run/dovecot/old-stats-user (part of boo#1087753) - update 32-bit-no-uid.diff with upstream fix- Change of path of rpm in lessopen.sh (boo#1082956)- add disable-cache-on-ro-fs.diff - disable write cache if filesystem is read-only and don't bail out (bsc#1069906, bsc#1074429)- add parser-write-cache-warn-only.diff to make cache write failures a warning instead of an error (boo#1069906, boo#1074429) - reduce dependeny on libnotify-tools (used by aa-notify -p) to "Suggests" to avoid pulling in several Gnome packages on servers (boo#1067477)- update to AppArmor 2.12 - add support for 'owner' rules in aa-logprof and aa-genprof - add support for includes with absolute path in aa-logprof etc. (lp#1733700) - update aa-decode to also decode PROCTITLE (lp#1736841) - several profile and abstraction updates, including boo#1069470 - preserve errno across aa_*_unref() functions - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.12 for the detailed upstream changelog - drop upstreamed patches: - read_inactive_profile-exactly-once.patch - utils-fix-sorted-save_profiles-regression.diff - lessopen profile: change all 'rix' rules to 'mrix' - add 32-bit-no-uid.diff to fix handling of log events without ouid on 32 bit systems - no longer package static libapparmor.a- update to AppArmor 2.11.95 aka 2.12 beta1 - add JSON interface to aa-logprof and aa-genprof (used by YaST) - drop old YaST interface code - update audio, base and nameservice abstractions - allow @{pid} to match 7-digit pids - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_95 for the detailed upstream changelog - drop upstreamed patches - apparmor-yast-cleanup.patch - apparmor-json-support.patch - nameservice-libtirpc.diff - drop obsolete perl modules (YaST no longer needs them) - drop patches that were only needed by the obsolete perl modules: - apparmor-utils-string-split - apparmor-abstractions-no-multiline.diff - drop profiles-sockets-temporary-fix.patch - obsoleted by a fix in apparmor_parser - refresh utils-fix-sorted-save_profiles-regression.diff - add aa-teardown (new script to unload all profiles) - make ExecStop in apparmor.service a no-op (workaround for a systemd restriction, see boo#996520 and boo#853019 for details) - lessopen profile: allow capability dac_read_search and dac_override, allow groff to execute several helpers (boo#1065388)- read_inactive_profile-exactly-once.patch (bsc#1069346) Perform reading of inactive profiles exactly once.- update to AppArmor 2.11.1 - add permissions to several profiles and abstractions (including lp#1650827 and boo#1057900) - several fixes in the aa-* tools (including lp#1689667, lp#1628286, lp#1661766 and boo#1062667) - fix downgrading/converting of 'unix' rules (will be supported in kernel 4.15) to 'network unix' rules in apparmor_parser (boo#1061195) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_1 for upstream changelog - remove upstream(ed) patches - upstream-changes-r3616..3628.diff - upstream-changes-r3629..3648.diff - parser-tests-dbus-duplicated-conditionals.diff - apparmor-fix-podsyntax.patch - sshd-profile-drop-local-include-r3615.diff - refresh apparmor-yast-cleanup.patch - add utils-fix-sorted-save_profiles-regression.diff to fix a regression in displaying the "changed profiles" list in aa-logprof- add nameservice-libtirpc.diff to fix NIS/YP logins (boo#1062244)- profiles-sockets-temporary-fix.patch to cater to nameservices with the new sockets mediation, until unix rules are upstreamed (boo#1061195)- add apparmor-fix-podsyntax.patch from mailing list to fix compilation with perl 5.26- do not require exact X.Y version of "python3" - require also matching python(abi) which is arguably more important- don't rely on implementation details for reload in %post- add JSON support. Required for FATE#323380. (apparmor-yast-cleanup.patch, apparmor-json-support.patch)- add upstream-changes-r3629..3648.diff: - preserve unknown profiles when reloading apparmor.service (CVE-2017-6507, lp#1668892, boo#1029696) - add aa-remove-unknown utility to unload unknown profiles (lp#1668892) - update nvidia abstraction for newer nvidia drivers - don't enforce ordering of dbus rule attributes in utils (lp#1628286) - add --parser, --base and --Include option to aa-easyprof to allow non-standard paths (useful for tests) (lp#1521031) - move initialization code in apparmor.aa to init_aa(). This allows to run all utils tests even if /etc/apparmor.d/ or /sbin/apparmor_parser don't exist. - several improvements in the utils tests - drop upstreamed python3-drop-re-locale.patch - no longer delete/skip some of the utils tests (to allow this, add parser-tests-dbus-duplicated-conditionals.diff) - add var.mount dependeny to apparmor.service (boo#1016259#c34)- Cleanup spec file: - don't use insserv if we afterwards call systemd, this can have bad side effects - remove dead code - remove now obsolete 'distro' checks - Replace init.d script with new wrapper working with systemd- add python3-drop-re-locale.patch: remove deprecated re.LOCALE flag in Python UI as it was dropped from Python 3.6 (lp#1661766)- Fix RPM groups- add upstream-changes-r3616..3628.diff: - update abstractions/base, abstractions/apache2-common and dovecot profiles - merge ask_the_questions() of aa-logprof and aa-mergeprof - pass LDFLAGS when building parser, libapparmor perl bindings and pam_apparmor - adjust deleting the cache in profiles %post to the new cache location - silence errors when deleting the cache (boo#976914)- split libapparmor into separate spec to get rid of build loop involving mariadb, systemd, apparmor, libapr and mariadb again (see the discussion in SR 448871 for details) - libapparmor.spec is based on the AppArmor 2.11 apparmor.spec, but with minimum BuildRequires- update to AppArmor 2.11.0 - apparmor_parser now supports parallel compiles and loads - add full support for dbus, ptrace and signal rules and events to the utils - full rewrite of the file rule handling in the utils - lots of improvements and fixes - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11 for the detailed changelog - patches: - add sshd-profile-drop-local-include-r3615.diff to fix 'make check' - drop aa-unconfined-fix-netstat-call-2.10r3380.diff, no longer needed - refresh apparmor-abstractions-no-multiline.diff - refresh apparmor-samba-include-permissions-for-shares.diff - spec changes: - aa-unconfined switched to using ss (from iproute2), adjust Recommends: - move libapparmor to /usr/lib*/ - drop %if %suse_version checks for 12.x - change several Obsoletes from %version to < 2.9. Those package names weren't used since years, and 2.9 is still a careful choice - include apparmor.service independent of %suse_version - techdoc.pdf is now shipped in upstream tarball to reduce BuildRequires - drop latex2html, texlive-* and w3m BuildRequires - techdoc.txt and techdoc.html not included, drop them from the package - run most of utils/ make check (some tests expect /etc/apparmor.d/ and /sbin/apparmor_parser to exist, skip them) - BuildRequires python3-pyflakes (utils tests) and dejagnu (libapparmor tests) - drop sed'ing python3 into aa-* shebang (upstreamed) - build binutils - aa-exec is now written in C and lives in /usr/bin/, move it to the apparmor_parser package and create a compability symlink in /usr/sbin/ - aa-exec manpage moved to section 1 - aa-enabled is a small new tool to find out if AppArmor is enabled - package new aa_stack_profile(2) manpage- change /etc/apparmor.d/cache symlink to /var/lib/apparmor/cache/. This is part of the root partition (at least with default partitioning) and should be available earlier than /var/cache/apparmor/ (boo#1015249, boo#980081, bsc#1016259) - add dependency on var-lib.mount to apparmor.service as safety net- update to AppArmor 2.10.2 maintenance release - lots of bugfixes and profile updates (including boo#1000201, boo#1009964, boo#1014463) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_2 for details - add aa-unconfined-fix-netstat-call-2.10r3380.diff to fix a regression in aa-unconfined - drop upstream(ed) patches: - changes-since-2.10.1--r3326..3346.diff - changes-since-2.10.1--r3347..3353.diff - libapparmor-fix-import-path.diff (upstream fix is slightly different) - nscd-var-lib.diff - refresh apparmor-abstractions-no-multiline.diff- add nscd-var-lib.diff to allow /var/lib/nscd/ in the nscd profile and abstractions/nameservice (path changed in latest nscd in Tumbleweed)- add changes-since-2.10.1--r3347..3353.diff with upstream changes and fixes in the 2.10 branch, including - allow writing *.qf files (for disk-based buffering) in syslog-ng profile - add several permissions to the dovecot profiles (deb#835826) - add a missing path in the traceroute profile- add changes-since-2.10.1--r3326..3346.diff with upstream changes and fixes since the 2.10.1 release, including - allow dac_override in winbindd profile (boo#990006#c5) - allow mr for /usr/lib*/ldb/*.so in samba abstractions (needed since Samba 4.4.x, boo#990006) - abstractions/nameservice: also support ConnMan-managed resolv.conf - let aa-genprof ask about profiles in extra dir (again) - fix aa-logprof "add hat" endless loop (lp#1538306) - honor 'chown' file events in logparser.py - ignore log file events with a request mask of 'send' or 'receive' because they are actually network events (lp#1577051, lp#1582374) - accept hostname with dots when parsing logs (lp#1453300 comments #1 and #2) - fix python LibAppArmor import failures with swig > 3.0.8 (boo#987607) (libapparmor-fix-import-path.diff) - refresh apparmor-abstractions-no-multiline.diff - drop upstreamed profiles-ping-inet6-r3449.diff - add %check section - runs libapparmor (including swig bindings), parser and profiles tests - add BuildRequires: perl(Locale::gettext) - needed for parser tests- add profiles-ping-inet6-r3449.diff - latest ping also does IPv6 (boo#980596)- update to AppArmor 2.10.1 (2.10 branch r3326): - fix incorrect output of child profile names (apparmor_parser -N) which caused 'rcapparmor reload' to remove child profiles and hats (lp#1551950) - fix a crash in aa-logprof / logparser.py for change_hat log events (lp#1523297) and log events that look like file events, but aren't (lp#1540562, lp#1525119, lp#1466812) - write unix rules when saving a profile (lp#1522938, boo#954104#c3) - several fixes for variable handling in aa-logprof - map c (create) log events to w instead of a - add python to the "no Px rule" list in logprof.conf - let aa-logprof check for duplicate profiles - let aa-status work without the apparmor.fail python module (boo#971917, lp#1480492) - add permissions in several profiles (including boo#948584, boo#948753, boo#954959, boo#954958, boo#971790, boo#964971, boo#921098, boo#923201 and boo#921098#c15). - and many more fixes, see the full changelog at http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_1 - drop upstream(ed) patches: - fix-initscript-aa_log_end_msg.diff - syslog-ng-profile-boo948584.diff - upstream-profile-updates-r3205-3241.diff - refresh patches: - apparmor-abstractions-no-multiline.diff - apparmor-samba-include-permissions-for-shares.diff - drop libapparmor autogen.sh call (broke the build) and remove libtool BR- add syslog-ng-profile-boo948584.diff - add several permissions needed by latest syslog-ng (boo#948584, boo#948753) - add upstream-profile-updates-r3205-3241.diff with several profile updates: - add /usr/share/locale-bundle/** to abstractions/base - allow dnsmask to use /bin/sh (boo#940749) and /bin/dash - allow dovecot imap to read /run/dovecot/mounts - allow avahi-daemon to write to /run/systemd/notify - allow ntpd to read $PATH directory listings (boo#945592, boo#948752) - update dhclient profile - allow skype to read @{PROC}/@{pid}/net/dev (boo#939568) - and some other small updates - drop upstreamed apparmor-winbindd-r3213.diff (included in the upstream-profile-updates patch)- netstat moved to net-tools-deprecated in Tumbleweed (boo#944904)- add apparmor-winbindd-r3213.diff - add missing k permissions for /etc/samba/smbd.tmp/msg/* in winbindd profile (boo#921098 #c15..19)- add fix-initscript-aa_log_end_msg.diff - fixes ugly initscript output (boo#862170)- update to AppArmor 2.10 (trunk r3205) - profile names can now contain variables - improved profile compile time in apparmor_parser - lots of improvements, refactoring and bugfixes in the aa-* tools - new apis for managing and loading profile caches into the kernel in libapparmor - lots of profile updates - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10 for the complete changelog with more details - add new apparmor_private.h and the aa_query_label(2), aa_features(3), aa_kernel_interface(3), aa_policy_cache(3), aa_splitcon(3) manpages to libapparmor-devel - drop apparmor-2.5.1-edirectory-profile patch - it's most probably no longer needed (see boo#621394 for details) - drop upstreamed samba-4.2-profiles.diff - refresh apparmor-samba-include-permissions-for-shares.diff- systemd-rpm-macros and %systemd_requires were at the wrong place, move them to the parser package (boo#931792)- update to AppArmor 2.9.2 (2.9 branch r2911) - lots of bugfixes in the parser and the aa-* tools (including boo#918787) - update dovecot and dnsmasq profiles and several abstractions (including boo#911001) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_2 for the full changelog - remove upstream(ed) patches apparmor-changes-since-2.9.1.diff and apparmor-fix-stl-ostream.diff - replace GPG key with new AppArmor GPG signing key, see https://launchpad.net/apparmor/+announcement/13404- make sure %service_del_postun doesn't call systemctl try-restart (boo#853019, bare systemd edition) - add samba-4.2-profiles.diff: update samba (winbindd and nmb) profiles for samba 4.2 (boo#921098, boo#923201)- only install apparmor.service for openSUSE > 13.2- Add a native systemd unit which *at the moment* only wraps/masks the early boot script.- add apparmor-fix-stl-ostream.diff which fixes odd uses of std::ostream which are not valid. Fixes build with GCC 5- allow lessopen.sh to run /usr/bin/unzip-plain (boo#906858)- add Requires: python3 to python3-apparmor package - readline isn't part of python3-base (boo#917577)- add apparmor-changes-since-2.9.1.diff with upstream fixes since the 2.9.1 release - update logparser.py to support changed syslog format (lp#1399027) - update usr.sbin.dovecot and usr.lib.dovecot.imap{, -login} profiles (lp#1296667) - update the mysqld profile - fix network rule description in apparmor.d(5) manpage - drop upstreamed dnsmasq-profile-fixes.patch - update expired GPG key- update to AppArmor 2.9.1 (2.9 branch r2831) - fix log parsing for 3.16 kernels and syslog-style logs (boo#905368) - several fixes and performance improvements in the aa-* utils - profile updates for dnsmasq (boo#907870), nscd (boo#904620#c14 and bnc#908856), useradd, sendmail, man and passwd - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_1 for full release notes - refresh dnsmasq-profile-fixes.patch- Fix dnsmasq profile to allow executing bash to run the --dhcp-script argument. Also fixed /usr/lib -> /usr/{lib,lib64} to get libvirt leasehealper script to run even on x86_64. dnsmasq-profile-fixes.patch. boo#911001- rename lessopen.sh profile file to usr.bin.lessopen.sh to match the script filename- add apparmor-lessopen-profile.patch: /usr/bin/lessopen.sh needs confinement. bnc#906858- delete cache in apparmor-profiles %post (workaround for bnc#904620#c8 / lp#1392042)- No longer perform gpg validation; osc source_validator does it implicit: + Drop gpg-offline BuildRequires. + No longer execute gpg_verify.- fix bashism in post script- update to AppArmor 2.9.0 (r2759) - change aa-mergeprof to the final commandline syntax - lots of bugfixes in the aa-* tools (bnc#900163, lp#1328707 and several bugs without a formal bugreport) - small additions to gnome, freedesktop.org, ubuntu-browsers.d/java and user-mail abstractions - fix mod_apparmor to not break basic auth - update perl modules to support signal, unix and ptrace rules (bnc#900013) - don't warn about rules not supported by the kernel - fix logging of "audit capability" (lp#1378091) - add support for the "hat" keyword in apparmor.vim - build html version of apparmor.vim manpage again (lp#1366572) - see also http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_0 - update apparmor-abstractions-no-multiline.diff - remove upstreamed apparmor-profiles-ntpd-pid-location.diffh04-ch1b 1745392364 3.1.7-150600.5.6.1apparmorapparmor.vimapparmor-docsaa-teardown.8.htmlapparmor.7.htmlapparmor.cssapparmor.d.5.htmlapparmor.vim.5.htmlapparmor_parser.8.htmlapparmor_xattrs.7.htmltechdoc.pdf/usr/share//usr/share/apparmor//usr/share/doc/packages//usr/share/doc/packages/apparmor-docs/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:38382/SUSE_SLE-15-SP6_Update/108ff988527a5e410ebf430fd63f6431-apparmor.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linuxdirectoryASCII text, with very long linesXML 1.0 document, ASCII textXML 1.0 document, ASCII text, with very long linesASCII text*"sO˻Putf-8938bdf407102b7ef40452fadc9b567f46eabc24fb1849fb036ac59b1988d6e82?P7zXZ !t/&]"k%nCQZuǡjע4dGb` sH;4 H wpcd6рLIJբDwC)Pj_gsD]*I hܐ!H ?\7!F* kNM5RDXCKR(<GԣpqG@* -J># :k_y"tC*O$D@T^%]`<.G;PyXj :0b;Æ/Q;sIoOyL!;k:͝CuOye*bH0K7c}a ,QywYeX@;&<ҊXljߕɟc,"A'fk)wŃ".-3:据ut ye_zK6 5>'I{{ rA[ o2L3D?X)C;Ou$_\`SX-^vNtz׳!ޠ{#mds.ml:;rTׇEn~㈍=Ieމ0R)$HWdm5I֢zgKo)Pjc+];c کJԅ ɥFx?l:叭KFlzTb2)syzBl&&g^5Be'3o־i49PJ@)@R*xqNZ,m%=/R9D[b| voBv[CSp ܙ"|jS¤>mIB]1-O*X~ -MTGt$\L= _80_6sɊPBӰI$IGBpQ" jV"!˅ (!'{F6oH匹 AN'8@K1 Qj,at7BY*55}שiɟq Սr_'OTq.Vq[bʹ$Ho'4]-GU.q\#%ԯOڈKĊE1R5*.#(Zpc,8Kf+L*Hǵ鉗a|bݓO>W*G ,kcXS"j[*urj"D*Ɲ7Du6t[Bb=Hdxֆ8X.%9\S(/ >>L.<+U,iMJѱy Y[~U茺 jnXI"+=9{}DŻ他TVBe /)b(E5SShݙjjv884^wwމpǽT[pq!s6y6lO\'p/əH&>@"jdŊQ^jHnk{5wƈ; CY֞n#~MOLadwa.yyl(]̓,&FU|y]{8Qv-=ס$КyY=mn' 63r+~{wTLnה9ϟj_a.ek >F @z3 ޥT &%yQxl0EKQ,icȡГ3Kqvo1O6W>'hun5. Oq 2tՖ޽(,Ѓ ΀n$v\OjH|Iwe`(Md e"ű$镇I AvMr1.܋!kG (Z5 J)b:Q*a囚E(% Gf\5Asɪt l7+g? wb]z5fXw}ů#>EǪ,!N߳ x73Brdi)H2uXP0Q&)=,߾j )]n-I1eQ^!6&@g$(rɋb˓=5F,*Z(Sknߓ~yz%23 󂻪wmq6IE(Rڹ&lg\?^5%zpo5#X1ʺ;Zh,LpE;DfBN}R9{s&s6L_Ƈ@KR:"|nM4# XAFĔ\[Y`B]Gi bUzʊKDƢ%PeHF _BTL0`~μ-vw~ )y;t0+K;]*6ml&2z6k_dS@D, K^0*ST?:c ߋC<s Go*vxNGM{(R )tgߚMw h* n /KV!;+XXRwtF :zC\u(w'8,X^7DE'@~ݗ(yAUM Y _v7k, UmamctgwjPlHa:8M/ F pfl5 'ly$|-}z=vVДǭaoE 5)l{E%ibHv"O+0M/=!r}]"M.dYhf;L6a~˶\{ѡ2}^-DGэPp!?Me? -U3'hh =(7JIU_%`Z-襶ǥØ[n~''ǵ 'EJ1N6> QX^)+UzxMuЄʛoUqUm3~gO*܆|ơ̡YER9kR~7ֹb~b|C.?]WGJTa/:lTsL(d4 *gn5WƋ=4s Mڀ}41cmq2Y5J3y´G9jvε5~qAogr&Tmm3 ~31-]U=ݝ.ƲnXCxNb۲ >L1JZ{g~x(8FAx,]!a癆fB=AKA ?C0.U4GUK7~ĝ:(#Ao)3r Y2W$U#'m }:BbI<کg&A9+7(#'lͳI5En^h )l7S]&~O;6O;)?~W|N|`ɧ ^(qĦWH."m#,aHK2AE$TgI`ܙZ `…|b?@R3G)GHLϦ;:&oM+_R@e/ҨiG|ϙePC5o? vG-n=[kHL"!z3r%uQxcI3)]Z!H.SZH(Rm xƑK8zakAs> A0Ҭ?83(jAaETJqgc:VhH4}~+~ȫ!>es ܁>}2K `_Sak׵ |\1oCy1J^|Q_#3Yz o`̹Ȅ60$53R"ן%|ҥ5J ҩZƈz.d0S^ŎDq7ln `̲B1}Ak%gh=yx[ifMBgV1dzMDb::F .N,*E6qj{!\x@9%$3(Wбu1* q}|RM5=G,~g_BgZ619d3GaEԠkHөv 2;vk݈@U)"\j =[O2! Fi0? _b B`a`j S&N)>'*߼as*oe:*Q9P\lƷZE0beiJ妤]r8܏&[gj4/BB>]Ҵ_1!g@aAU\ q5kCND-tAvg==cWq'\CGE iWNƛ(23چQtvï69ZK\ۼ-SgZYrZ/v)Fppbٻ8 h?1ADK EOxFB>@mEI*_ 8C@ ,2S@fMԸ0W|z/Ĉ#Rj]4y’>t  1qgPesȖs2ΰMrڻIH)J΂weSwq4n5*el6! MM.TE7LMTiCFdW"-į'Tj@-5*f^;[摽BuAs-u!B}u{? Y DΟy@7KBn9ijL͂uލM6DkhK7-TO :bɦB\1$ »'5,2 d|jAܩ* -dBNAM rPXY%{q.&y:k1.g^>y2l󢟋~yw\ ÕU:Ak,<.̑bMuʳmT=J2elDۉ")] 3: %a6:I_ 1 (J.P)CEz/x@nMQILcp[KN-6eQ,6Yׯ؂1.6vٮtd^ 2uxqƛ^  A[5IēEu!džlUֳYA[ n+ʠuU&o%Lh>\#Maƙu8_ao3/Nb6غ]+Nn|!2sj1!͸OD^n*--{r6'a1ht'1fC!0}5\]`V  QR`g_VKn ^3769ix!O_| gC|Q@[Bh=b ̏qKhƊĹVqK{N> M B%"EhJ j|gzpL_2("ۥ<1Z@&5A t$dm*,7Z gPآ85sGל]- Qze;1y:Bq6Xk?E'竩,w:>{N(9(omlZ8oZ'bݙc~γƛ][ѣB Y>6nf, ׬EK b1)ab'V/+5Zr.ۥ8pʏ BVGHx+e ٟ.byE.!:滵a}GLZ`~B0π:Iڂ 4zn/ FmO={~wA(oKj/YyNmv0ij{g}FnMs(PWRH8@PYpn)ăXK%̈ΐq˃-&cE |; H au{?_ʈMi4яF ': VؒS`Ǐ`6(Ʋ !`yaRN R8t F0LmwDadfɻf =?yvj_UH/ɞ>/k0VCjX6Oe'+*'Y;c%w ĭEn"U{XaՋH> HG'ߙj Wp]34hXNgD! )8ŧmK^ċh⢟eXi.Rø(ʹA{[dL6$ّY7+krHWT]: ŮNn't.Sd !#1F@zn#'O(Yl̐T_ڏN"]P)egLqT1y*.ٛ=mR[& w&AkX'ST/ե@T&1K 2dPti߲G&i5>j%HI|,|c*w5uXUc??E(f*֚ɇ4Zt&Gr%<9L+) -tc]2Ssv*2#٭c@kǒ> %\H4J }b ^Wy|je_?m|7d?&am͎j Ӌ3|<_zut0{jYB?n>o=VEܷh$S="Y,A %xNwּc3"GdQ\L3Օx sCRvÒS_DKLL*Q?za'(D5:GN5ol xgN:}_5^zoj .+{P #Hq=ˆQ eIh4',gp۷NfLŵ~*ѷp]$֓vS.SΎ|ы4sݣsʡUx*L}I"=GnM!oSw[trf%tiOyA;9:n :lf DANŻfGhEm;Tam3 lXأtDO5]$ _zJ[dpQD% vD:׈$bq-.\_:I>Ő&D[ C\gJݪ``>SwAkz j"TKhn7 t7$mnG@U`sQ~mG[Xr<,صVso?hz۱0MIX,H?t-yvls 4 j5B@C~JVNW,|>|SXS߽WӃвS񔹝=7Ue˂Ld P7UcUIڕ84?b?]Yww(}qzrt_KP0 fk05mB|n7P R<$SFDž5" LNiJ Bf/2jF`iC4b!ohQѧ;!na8`tGrU0m5pҵ7ƪ-usj#vsUJzX@ʚfJ|0A7hFH%OYF1mn#aXt3 #zy`7*(1T5R>V!WGؔ$ TYsiC %MIGcO W0{E)_DAlsғAMySuּ}@κNdkw˟#p$-1xz Ð-.#6b;5%1gQ~'FʞB*坃J̑l@TV B5_=?s I1dbEPQW$̎Ǜ{eQNxXfC_[mGߢ5yӐ d' (Cl!`)zzF|sЫODR;@mNpQVǔ DowT LHtAD{VJB $ǹI{;yM27ޢh6pS"wfUFjWe` |)C-wa[v:^Vt^bx%MJRkJm*m%l'Ҷt8| z$4lNc),>@=7ѫ5Q7ƀ/4X"2ZBl٨&AE_7YJ\%C4Az<$Q"А BS0-q7vm0Uf͉TJq$-h12EO@[[krȒd筚@,VhVRBasbغ !S'q&oEFeԫ;%*>F/J %&e3k}ELJb_r]/|+`zM\F]Kl)/Ho~K'!ӨU 8YXӼtb!ߍλ-Zb`='N#QPFڳ(TW!*AnL yG1yXd"xA-HQ7R@Q:P}% g7PsȾ"Q6~0S3v>=Kc!Fl w~}aV Ö,Xm%]x}1-0ޫKvu"iIY7Mº T7!dz"۟~* 'ɍ +|nҟ 鎤,p[+Vz kO [Yk<‘ zETN __F Tgz0!äQNDȊwʜv3 BG3\V;͖ے{8YגQWo cN95`dIWn⍐uhw Xyey)D:ܦJ۪t$y]ٸ N|f:+KA'M0ZNz2s3> H`{E]ְG ԷGdeGD?Xvt /X6GC0y:Ƴ5RGغ)$0h ._,ߖyB/\IwyއM$b\-fmҗsYXT` 8*n ے踳&~$p ڃ(ޕoCIϫ4=׏+]Jդ 5u,*i@˨[K35'XPҬ鐧X|NhpY)!X@m622j{KT94׍ÀȉsYKm{glS"{Ǖ4Xh'&'Ҵ%)\j7ʝ3c&Z$_-o0b},x🿁;Ʊx" -(YDZ_A~GjB:}+8SGΩ{la^EKNFq86f 砫tViJTeq9YXzҠ ǐQYR˓* $Wjc0ozm~xwY S[Yk61k*ܾZm!Sj'ĚBg.๤l|Aܥ!TӒ^ :r44d//m\4W1ۋֶ}VI2_M|΅NEس]XqP#l>Td;PͪUL"!\!%)8omPviA2@Ufm8&{_=|Ox]R3}!ĽCeu"*Ťu9R8N¥H4U0ŪK @,rc9&{x+&^gWZu&qc{ bE;"ܠL+/UmU__2EN>%࿰g1a[y4I,0gw8mj~ G7}6-{G>+J6P YFvNAZh7HMnm>2y b9C% >Mc;!-itɝ`~Ѯ3$HCEUؤ6J`_vV@*Z氭`{2T 5#bؔU]&wfVFU ֛w:̹;π_U(wub`_HJt88DGWH/%1Ii3myiMC4WQ  6j=Y˜E]-51F^tN1;W\-5"y.RdG9Ы\xDCCFB"QCX:QI )lv2yj"Ujj~wRϛ=,sd1O$TUb3R_]4h)eê/[0ʼŕ"?fS0 3OP`eBr[ѼҺGФݪ_94V|~ { pYD<j/У[yW6 4TL@]Ή& rb2.A8ibو;7HZXZ`'5/ᇂ7HؿWL5QPM\J/A$C؏{|:Y(V|l!{p `˪^u]W*Kd, 2&xG]Dt.İaYB[<6;p9][ܝƀ{J-+o$"@'Rطpx?h E\ު'VE%$oVC2]~u@fR͞'Y2Qa@ V'Vsđ@}ۀnb i@q˼ʒ* RFA &.>!n[tgѰ3t[oP1Z^ h RhĄ&GʊZѮF^/zj$$lLd{eBr (m u_I)²Dzѽ;.gFIIԺV-E6\c{eipMr/^{7Zs\^{>B-M4f$gl.ى|4Oait*x>$Hwy_AbF@RTV`rt54/UR1zlVaYRM@kY"TARM"&Y'؈9Gq t1I|Eb,\]m8X";VkwvA7\`?95= .k<b.9: ό^L}؅Uߓ0 W%d28l7JN p_ ;g$TWCvUs;!_g•V3kˡ>9?cQg8mwۛTrBb?mwOOV5c GҹǢv(Z`Z?)0'q C=(K./޿Z`?c Ć.Y=V<](S #;+icQ|e$U$>pn/GsWɋ0v#I8]hLh°M~ ߚi_d""ÇZZv(5_?þ-zZϣdW"Bk 14ne:- 5Q-ML}] !WǤ6so@sBC}E:9q>a&~zǁdZD9:ُ``X(*nE Uȅg)ZF bQPRI$+xu_(̐gyvQPv %BP/k]E%rXߝR)rN{ħ`w_0f`^#!R*f:,Ybn4u-·;fܶEᅕ|/ vMJ*PUe~/lo7 e]#FGnqKPl{*臎_̽ӳµ4 v[79 6N-a4΂~+R y >HXNz8~33џBm}t[FL;yGsu*ZgTfଦb&qE:<5&'@j@7WXK|z X$ yfO[9O!Dpso>Dq0{-]'&IWpy tg5ﶿn]?&oKg,Id}: U>{nf SZw͐Ѥ=~|lP |~ O)Ygt/6w, U2X}JmÍ?4U:.$|KM9@xDɁq:|=§=Q)4I,K{Wqt9aif۶hkBC4,0\>f~V!HXTq΢6U $0݃IP%wMcƵITϻ&]&Cv]LUsvG1(8,NvՅ$ͯ t襠+A@ 6hg[B7!oTEX!B?taRfiR8A1 .b9@.2XYO@l3σ[{;xۼSKU:QPgrhk9I@#5JS!,-R—ԍIfa*&Wb^ ,ޘhK5ao{!]\T8Xt:v-;3^+[?q?f/MUIĄאB3okzbbBQZjW:RxǤfN\IJJP4C*' tSLmpO[S+yS>z-jt:U`_TM^.ᓾ%I8ϧ6&M!QP-RQߕK$]:J-69RޏnAG)߶+:UˉwM2 ef)9>HYotS|/^xGtoQr}9q&tk ֭@W蛅hTZ#l!r^ʍ0ưJ;@tT\0P^+aȊ`$̈́$p Ã(f!N!Aj'=aijT8 Te Ps a|S4y$QC N2uR mbk~r ~lyi+LCN"LLLؕЙYnpT*۴ WOKMLB?yfVM*ak<U 1gXG^¦{nv!o6ܐ3-ILdʍǔ~EdWNugd]RŨO&i9{<,=_|=^G !j_$?8AAc+߈xPAp9*? ӸuD pM k`3oiβzO\ eA,L@ӲHs^.rv };LvTrW_5& JoM>k7puôZ\c=g褎Ҟx`WƑ!Y2"I'6]VH}T !f9N6s4-/1*-RMNJnDcGl_`ά;zEz›.T":ʯ 0К\ G Uzd<(a_)TcyWp8&+L(s8F} }hPڶʳ@9U_aT!&)QW2( MopNNq_9ƨHZvxp(g7{;)=/LqAlsFemWS(bHΘTnp3(h}2 w {ۓDė ֻ}۽bHćB!qJgBG+<}QiDOܞeIbJޙ dFJ:`Ym-اF.۲䛪#wI3ɝ–Uel}N`b;X#f1ʬr d}C ohNnꐨņ7U3d,R]2r(:^2@H#؁B3Ol8]5"tgu4=7$7_DF\(@jEl$Gpɗ=bw;C sVvց*hN[^6=a|MHD'3P/d38AB}ޟ^-]t5)d#M}nY]*e, F+8ZBӂr_`Q@0ANⅾhY9j$J>̾ vC u & {ؖ;ggoctO%%z, n;#. {Jsts2r>Cocfy ]26@Fֆ&gxcqzD"2JMjUkmE4})Yg.SxGNmi({x%3WNyz/«m,FIgE'JabVN4KJ!9 #+!ѸݻXUf?\)n Xfm}{=At#0눱!#$hN6ZWOrRG]dfݰ-:\61U;Y}XzgԷ_;V+xb K,~,>lIXȸ1>0Bu&ʢ R뽫誅lm۴ P8[};=OqMˌOd&G`XIUݽi_!nr' AVnn  F:]masIcLjWOug{sѲ?S|&C)F99x_"ؘ߈a)sEH.u+'#YA p`r1^d)i6\6Ԑ!+/a'|:KsXgWO '$&<9`nz~߾d˛ӿL%ro2"ܢE"n^h3ѧxy:t hB^]#C\>;(8IL 98j >(`ڐJ")fVsV ID O1j*4eQ\|mтrߥ$ɔ*ZS69'\HVx gE6 ] mQU\!{}?zʣɂGGnގVUX\z,~ ٶ~k-^5h:h(E,`Ce#+G~6D[@1iF8q >l48*L'ДYBFT_1P#Îij!h1# "\,ǻ]\ cԄNp|9- uB)se a%y1YL\3վ>bi.sWzLҵ cSQߪ{mxKr˼Tp;*(68;b@= Ԥ"p6 +4Wty]KSqn_"!=īҖY#<+@o q;`/Y N@p@ͻKQFĘǯ^X!~Ug^ipN9Ѓm,/O YZG#M!}[7$;`v Z[AxO8 G6 1H>^H]Io&GhmDkSVˋ]`/yupbǎ;c{x_]*EY6XL`@r:@ӭ\D9m1OБ)*]u)V COn~G_s57qV1`J0Zp#8Ffkf[G h9wvzߞ嗕8TEER7h2;-^EWV˵]@\lg呞\ԛ![ۚ #GF:1LťoìrnV %cOy{NkdXkL$LHimA %H5JCIJE1v?ΰav]c;eϳP ͎V0թbő' 5;~k] ssV4M{|RI4=Z71p`;^oq-- 9ߩèyP=yS1[ZY>DO;O űS'FpǮ!<ϰQ?$ jDsʄv4<96a<ޢLm +@eʣ1VEvn9o j2ǻעFNmt%URHt#p]@t:'6~$c>ǒ U~etc +yF0~C8iX* z9{UCvzPWL)uKΖ3ه;ĒzCfH~h`qà, gROɂf) 31Cnܘc".\4 7 n0p&4ҭbMe| $W*~Br8NmVuYXrlzIc=&( zGe*'}Oj!\ވϩE_brjPGtֱ=^tSy\s<g;^o Irqq3T؞[Ѣ3e#^ TטF &;le ~z. j$!FUoɓgqi,/B:l(`ݜؓUGphnw7-Q=CTF|A+ۉX8!p塋GVHC#SE/<&jK/ #[C+<r'tCge2wJ#EaU R12/Cafn݄.5/*r &<%p_O @&ŽnQ` ].E!#o%Z *5YN'w8oq(CW҆q3bidaɾVZq9߻,Xi;_ toK?9.ywoݔC#;URۢv,_cr &&~#rΰJhY.`-iZ`Қ?Csq\j(J1ϲ:pzm~GbVmQOȉ,M[?y Liޔ j}mwo​;^MW֎VKϥΏ8fMELU&>nYNa@VɩKՕ\WL20ɄV)D,zgx.v-jPlH$5rc=Y3Q#5щefXLlLһJmU޳ǽ^܁[' /ppyhג -R/ى_>51p0w9@OUa<*76F+p]C>g?_ṳȺ+5$Kh( DwQ?Pw+ŋXe/9jg3|I6A%~%D!DIE=ҡ>t1Rn$VELsD2).-Gc&9t.խ^Ihu`mК29TVRe9+(/&{3h8<~l@&^ȦYg!UMjM) 7Wubk Es=1\RD~-P=VtUD:VN w 3a7yx=Z..vU\'̇2ܐuV Pi%)^+v θ3~hæwhH/ L`#M9ٿ꘶D޷cr*yq]I+I3R fLF{Cfwkf^o[OLm q3M,~teN)Wm i?A΅A.:k2 q"Lga"?ϽysVl|ʊZxJreweC0CXuC &{D'd4C;rw3CA('X&S1SуŲSԺ҄ÅPGl{0@ЍR ^]윑[Mdo UƯoЕbeXETmohίJbh<[$\k ՠ̴+W ?ʳV Ym6X kX~0#:J .ʇȦQaㄚwa鬎>;*ׁfؔ=1BYKS@i'Z/AyA^)QL t"HJ&|uCD1/ja 'nQ-ZU)F?wopQ9^G4{Mʩu9[w ^_"1{ʄZ19~ YJ4>0<'aX^ATʘ/սGW/(-A/G^{C.3>s#g0 =͓!;gmDz=Z('r]w|դ q Bl[jЮfDFoj60ؗ 1v,u颮JA5hnsEo {s@w.B)ecuI6b5 H]\GR©qⳚ~:NrFP]"V&3:sԵjDtZ¯F,ʆ>֎hZ^(ZN(YtIƋ2 <4k-@Guw!+ν?Ou㚅;\[;KoJZU=+~<ėobc|"֜!⫶C+d 2+Biba M$*PֺߌI HD磍 پvg"}hhR9:팥/ _Eu^B]ωP2%`лfMM a8HS de-j~%-QUO]B"4M*w<hVT !D512ẂTC$M$ߵ0~9 <Nt1`:79 hLi;b,&.R|< 1߮(vi:zhz{] 2fV')ʝV #JǙGG:!+  ]8De\i2wԷ39Һ&N6uBP0K4sOu=x`3/Rb U F $#~( $Ywv Pkɼ2hᅠh{[z;ZP|;P+֢0jl44CE O;gwj7SaAglg$lD%tr=FhlWޘD.N{GIC0O%࠷bl}>ngW&%Ho[~pJu6e}utsV꾽>t X~pR+z}A*&HkJJ W_&Rώa,8Mrh|"\tg ?Pcv{Q:`O۾/Aķ1njS"@ZU#nnLdƓr$.ewoPPd3c}'I˴cx)uL%q~ҺPa ;kfľ,]s tk[RLfƔ[Nzcu$S'1trD{Xgd`%"+U]V^* B{tA$eot5y.ȗM@ ɎADC}Dp#+H'uM_|=@:0󘱌"\ C#dയj:TT1 W{AV8`f//il匧&e/z1WpI1bw T[#&\%[QjThkķMč ;bܞL}ziQ8Q/?nf5 ty+TC-/`xpiZ7F'}Hg=8LuFjp(ҘM0rkc("[,, CNtlu|슱ML/ kՔq\rlGKg 5uۏ2uڟf 7b˞ e"rHl!|V8߰4k`^$:U!LQ}&>mJYgEW(D^e*khžL+"/oNAs4'"p)\&*+G8Bc9hZ`iBM,no/痮Yn- M<O'rAH{ЌOqOU6 "}}6 Z*TjzaP~a(q*MwM R* n"u?oC7t57*w:)1},`N::g$KU@W@,i "3܋T:>uFux$pfJ.ׁ@EgPqF3xW5 ef М>wBB 2n{!me |m^4( @Gސ%$TH7U-jڗ A0+]fR={XҎPQi5"Ķm8p@uJX̹"[+]9s;DiTr3scs~ŦrfL}rΔ鳏w1JYCݞ8|^^قe1PR sbM`.Z}Ei/":;"?\ Xr%I튖=d?\G Jﻃq˷/0= XPWZ 08'Z'S+|M ٠1u5DT- ZYG#LZ/H]>2T:%SOiy=,nDrJ\CDk:]ߢ:Ro{w:R*t8Oi^ʶ7^YuRxdf S+=965Z8Yϒ]"[܏uOӎy:?!r(wG{ i=xG䒝_VXyQ꼏wQg{%n=&Gت_rREPQYH+&=sU,IXP5U^E'?(?^z< ߓ=򐺱5nj8-L./ GRyB2rsza| X/¹H]T|Y}ULK P<;OPk\4ͮ"FpE!<->rO? Ap22{0~[ +k& ک(AjͺsPcy_jGl@SpbaAao)= S I9&o+*Jƌr̨S [u:¶1 % V q!zƋP1<7 Z[E)נ-1!2֧ϫO'V?+ g}^)lRg^}\̘[\xᓞ]> '̄HmXS٘NQ;R~ y \{\bңrB C뫘kP˖T5j3dpw_L@6pl!v4 hE bxu8N.A&+5U 6#ptI<بP38.0'& bBNIrZQVREg+͉#e5QJ"v7WNߩk+`5I(Rz)%4VdPZ~%!b/g&m7Qn*\!o5{x=2@lE {T%r,cW8P u|:t;qp~<,8ɔtVؐ5.ڻI̗ffhL݌!>ï }TSCEhDX5;>p$l_j06d/j2|0'N;!oWR4 =# ^zV@YKx5C#W{ J fu7q_qR/"^b-x(a^V3=4[6qDؿS.[ŭ ғ n;D$?n[|K;)H2wu"H" P!YWҙPKr7_U+oqQM)I rPQy^Z-u A ?Ȩ|Sr8trRR*C+OwYy]4ê짌{gCWό/]"*@n[vw^f=OPq>EMщ6R{ SLtі TNї7Ѫ>ԾSy饝n:F4 tR -[9) V6LYq%;WX@AO[b>ݬ}5'9'ˎDi r`Io8nҝh í֩"^sB!LTJ4J񳗐eoG#m r{Z}݌}gƽ~+(Хϲg5䱕S0u$#m_+@]x7Ա&*;tγyMֵcY x稝dO۱f*"`35YeFkMvPR|Pη1<&K_AUps<,"iY}5ځރLDd:(Lu B^T*|M}J0$3{8QB5UŽGR|6K_ctrxȺy#dtV6hmcsy˧KL?k.X_&aBQw CNyq{M:(_Yi2R6O>{*e#/?aO\z,&/W]^{6(cq%V,u5. p]fe1޽\fMS.!Xlb]e(<sjK G)/0k~/j^\doJZw &KGAҸ$0vmYri-wZ N~Ik,;"8![p#|Z4#jFuHDC /dedqGZbF1Z~ݸN v0˕8Y! ps]C +T -8tWE;owZL}QHKaFIpYI>VO^έjA^ےmnU~F$:,^PEɓ4{KmjBwYC;0lD߹;lv ]NX 'eXLt`4U$\x߽a>8lmB->ΙzY Ƀu|:suWGxZs{;$b,8Hfl0%y^lX2ܱz ʌ_[.\DQĭ HJt:;B$rYMo־lr6jd%HCvۮ(Bu d}!gpL ' ?XjHdw eE\*v%شdwj .V/I΢ӗt%Bi-?˂̄8~4j˞ŋ4 6bn8svn J^3j:BMRX}N&@$ ۈ@N?dYk$f$X-&5;D֚E-?iIYrEO#0Jhrak OFMN ՚" S-i9T`"=@L2=z.I,&>Op m9Z{jlIVhCtHf$@#l󹖫g ?f-H(4].o=}|_l>xn5s93~:FdAsd}HQ4eW;S{$컈+TX".)"Y(Tu$P߭FXm"3gި"6CR>2!sق渦bz.$8 ¨s=)#t#UgXy`ai@k:#%':] th3d P[2}Qo*bDfISY0aYUDgiVV%O,{cE9J$ lVn vpaoW)Aռ?rmh;o!M{n͠a 󚩼Xti%\gD!ڧu==-C#}H~E &bv{B؇HJ̰7sYo=V@sS@U- >K {Èԍ|Ć׻< HR@`=Ux+,6myyž(\`TGq挅U ~ cJMlNSwaa3%&oW+` h®x`uߓŭ7f{ 7Zjɨlp76s0.On̮o~(A5)C`@Hp6pX_pkEDdDePsT obDz`LBOO" D.pZkAaÜ%ag7'l-' 5ǒa•eLOC{ lMҍ1"X:aЧ6ò# pO- 孡yrϗD_:T+g_]@}+q/n7[ x v?gE.ؒ 3-&}4="T7NR#qyx }0,״G_:Պ.Z3 m6sBs8)*z1 m;'@T;USyKBc&SvA8fڻSkwkoxVIT`ztyBwr/uHPDQdzyPnTp-Ycc`|wΜ("EF=!BK=r |Tx LQ+| vfB LCTqXJ~#>SҼeZY*'_.V;ƛOys>HMT= S s%ZJ5:i%M侪QgQm]+.2IF'K#/|׍!2/y1,KnjSXh5loR,FN^k#ހC;3=$Z6?>7Pc`岖kuY Fk/#5gT蹧-j?Qz-~1^dthWMV `o [Pj[NG\ne6LrHYD5iK:{ {!-hξ-{Cm&7:.~ɀv¼ 8;ogF.Y\MVf,vlϛgӄ#g͝Ij̊JY{g0Oc9h]# d 'GsI-=LG+8{,|ӄFI; B7}ف*n Uj#.:,[W3 >wڴ6'/v(/}w\0Eė ,Z1Ro!Xyi6Ay3Uy 쳉 /ՐZ HheYUB"ʜ31TcE4VC ɣ kȇr,E#dvSK+fZBuqUng9tޔAԧiĚG$I.:7nBDӀ7V+yG-w(\HwS6eF`S)aJNk:Oa+_6s1=8Y S5ٷ8 B?/xMHD8wѨ[Јc*:][â>1 &ɶ>[ -M *&8;3!fnr4N,gݛC k)oDO$v"O E@ AX=TOF{ @ĭIܚ0Fjڤ [)#pl^~u[ }(@0@9@D<̘xl~P }+vP'0m6M̧C]9To4xWsN1,$*2 W(RfX m< c|a |X#.x72;23ep6 9IFωKMm~i{rF1!E;DmuC],nDwRvIjtS~nD4ylJJ|E c6 9EJkv &EWXOœo+ڻ Ѹ'E񉗝@ 9j-OVp ΞpBCKS̃78Pˎ!hl=+p:„XHl&"[ј6`hqHH TX@ڦGHPr+5%`ڃ: 1[Yho_k-ǯK_C \sڶ =Tt QH*~% =7Z? >IiFXNrɑ*oNƴ܅DչX ` <KYCP#FKq)4_DLW`Jg9ե5m{N,T0z (u"K1 pDb`Νiڜ"eSA\泓ȰDk}q.ͥ?(7 +}Ơ"~gr.D#S4|RrJ ,Ʌx宼/#SRbGtMA9]P> S~X-}qi>8}ѹ"KY:_b C@EkH]6Fn,=4*{g|Il;Dwvkz!V\%SK; MNSKf6Tȹv>.:p?qV OQfI$9.Dp[eb"s|IxFJ&QFɩt#-E~p""49[>m˵ֶj$lKk ;l(AjDJd=lϝﴤ\~n$׸C>R3Bm>9>X*|K-ݽ/Voȱb{~\3t/IVP@ 0v˼*?R+XOBJ Rmm$LJDk#JL=VfwքHI׹TI]R֭=}")KJw>UP0(J}C6t IQwflltd&dgi"SփI*׋(e^u/짪jI~ru!h=̷l}L-X &ɛp}}0 &7VO=i[;!64?71jԌ1x֏#1][9Þod e(ie}%rmfeŅ.ARϮۖ8K)A))2VNRUBB҆&rxr>h;vm9wu>6~oIMؼ>(.Zkˡ$+{+4rWwۑZ\3yA9"&J]b^^ʭGm!n`;*r$/P<;2lP'ip]U3)rHRj6^W6q&M򭺛b `6 kupSPKBV|Va+v`hM-d07Qbxlid޴ϣXo0Ut;6yR%/F~m(VYTA:w%~'F=%.n`E: %a.7u޴2ZZˏboN֍B t.E,0gYD;ftp^G%]u0_$PX!exGӀ1)K;v.hs*:eetDLJQW5L@CWߏe94h-9QfEĨD*E3kvpÓHYhHQ [*g5MRtLhac&S%`gmRSL'Ip!b{y"B^gESά[c>Ls>R@WyhV6B2\;x[ Q~ީҥx;=+)y Aƫ L^לFA-'ĘQcYY{r+Ѣ}qvh9'{;-n76 #c>k\Q˓vp8f1(KNH~f:fx3(tkߩWՊnsrc $Z8 r^rPkDXR:A%'1s$ck+!=ntI*^^Wji$bdsaf{T68Z8@QL ;##+ H$J2ՖX!qSij%&x|Z >?Va9ӆE1DjvD[ݹɔAW X cp1h%};DU6XHlZZ h9@0sITmh4baˆ7HL <"$/xV?x /·,0i_! |nC#Np>eB+6z3iL3h~e3lz1?/1 jRNNFpvޥ~ԯDp&U|ZqM}XxCod$=}&/6n= +|"-3m:JMЀ@ t׿6;T;;z`-iC&3׃ Ǜ.QwVj!l} ɷ^ 5j-e͉4r&;P7{ ?eumQx?;,\`cv]eKܬ/J+T#5"3z48[q}h{lZKfT9dI,n*Βv/, IkgRY)i0c_K8UX쐛 #$ H~o)]!xzLBO&BvW am_Fuj2 >(_ <(WoB0Aғ|gVT@+\w RC}ve?YD.O•TC6ylRzizx'm0"󎴧r=:T`JK7t<^>x)afoPUlݜEiy&VѨ# =I蒡j2m[#}A +&wd/ w$ZN|#THJ? x k$Kl!5IxW ! 7{ӸabDQm%']Q j^R"1 S bRj!oNLJ?1o&.{+"@cLG9\@`)&.*&p-Sϯk4y VIMSЇhR+@> NSv\+ ,YL1f.zwbc1_ύ5g~AGB"LFhsA.%lԠݰ_VPxr L]#C`s"IV Eskɩ2;[Hpaze%`BfN ڴE:۸2(5h5Z[B6#Z A"'5Oe577".BKxj8ql_Yb  2lqߕ8 Kg!2[la }bU5dr{J#HÍ?kKKEݭ!yɼ=K?$*_2RT- ɔ ɚJw?%5Z; Ͽi{5bȰS Y=Ł<3=^ `y~8v>B&;k&]tgogQitvf튏/H%ojȇ;$/CS̀[y`b CAl%%UwY:i >/^7܉We&g^YW1Rlޝ&p>򢴔þhIW@M;m\j*Fzqg\R>AmФ>vi:ԯ3Ŗ?G6'X,p :c* yШRԛR?/Y *Zu#M14Q3 x}CҺI`VKl]xPsSYWJ*Ӛcg|]E EO'SD_sGزI'K6}PZHuUNͲ`}9og?/G0**yi /iu h5&ČK-ZgҲ#x$hl0EB;V'+,=6t oUF U]c"< ꣭`$?O_V~KJS{5g;$G$ 9xk"2@-nIuPl!Ƹ[x7W_k, 'G,`waEf D2$`GjVEps2i+ìJ-?+G$gkz$dj4oE, ~K_j*6NM~Yt{T.oUiUep ?S';z5EȷCaY,DQJf"c(qh'"L<#8q/d+e;>bɤވ}ՂLTLZ\@vdeW92^N(O<D?`tHFGVvyQgGä,/1;~UpZku(at~X1icC0pIR& 濟gaŒq,n, m!K}6K/ g}AŜzM?{[eA_6ḥoQO6EgCUZ!֙ Itv"h/o]8#S#Y<7#u\^6kzw>x~#08>K䚗#j XowFȁgO[+]hmԨOv Y92/.z߸CL/}%oj=v9j2D, jo15 ѥDž @p""K#;QO޹k&F _<]TUbM7[,NFVuѽaRh]k9IAjWw-]ڶ-%୲ ]Y;_ҌSFW*E:좩%X&l8 RNfJtrL>VM/ iY)+zZ;-&W)qQЮ `jti7$>ƣ q=T0Dqv`>jamp9CGCbJڠ֏2f{=p0R4Ǒ/2`*Q(aCIp8Afh=YS ~4WS%"tRF:W:8ۚ[镖n5JU}X7O#j<.7"& Uv 1F{ە|ĻfAiS 4OrS@j~ *N_W+- (B\L<(ut3}b^y*HZnq.酏 9tbn ˖ƧRC.E, 1wiom5SE[00"FqP a>#^|pRHKKhS)tP=-rƂhl,#ȶUiLӘ3;,Z'y7Mih\yZ&e[PCFr741G_eA\GF̒# ѱ8W8Jn> VłmD^w.ͽdF#\DYej=A6X1rk15S$ܔ~s)6e'2#4Xs<~)pH8Ds*u<ʃ[J4þEZF3"6 ;%wjҔV$JB3ۚ3Ы A~:.꭭0 O_LFRC)wB-^ӹްZD\~/28sf`5w\>^Z1]$(sR T.]?Q٪5S|j9,xZӭ֛Ѫ}^(C<tcRqt|hHsa8 ]*72 ČF >tg&g( =!LҸMپXψr ̸0O{SYPY;<Ǹ۵'""}\p裿(mgRG#TT 3%or񲌧TِlM.Ҫ>dA?Osi hO/ wZ\捃Ko-]&2]4OFʝU 3m$<q/T_MfYzf{yڔNd 2GKϦSm>c1Wqz+gdE؟w1 L*Ϭ}wﵾYT)=>f=6uWe[(c@Yw32x;C&Vm.P_N5 U:NOXULfMMqsIUS:6j"1P)Ðyj0g+i 7t ]!&A%YMk10KRk_\[MۘpR ̑SHrX1h} իÊwtOy*>7V}?ѦN&Mkx#CpB+D;I 1ԏBΟ+ HR{(VwNdIW^O'[/\D+ -8|*J6wWZPgzKhhe # |1~j_QSfxk,z yYc7Xdb5(T(ј$Wcfֽkg;1vbDJirotVhp亖g|Ǔ`9YW5ԁ%+ACNu>Lm&|Qwq{I}d'G-mϓ>`g-l~cD'!Π~G/2;S9H\-%z#HnOV .wOFP^2TRkDYUV21 MqDC1:3!1i?j } _FevZ *elaǹ /ic9gο٧{wOƵIOm{濔pYb܅AVci7-|ü{.uȏjh>,͹OyY]Vû3t&MN:֐\]Z1w ޺5dM11߫GK(x~LdwaF&:!鏦Vy\ 䜷DS'voQHsߝ)~H^>s?!?Ad%jEQ&ơMR<Z;\ySsԣ~T7@+>s Ǒ&K|ȩg,xoptWQj=U PY~jfnQ Il_F <5Xj-^>aD F&fu~|ID|yfP(6Y(CFĎ H{g9D>狟چO%rO:=AĄnwi#m|_{(! >5$ TjrI[`P'یHنWrg҈%κVmA-|3eF3e`089vD1W5+qa4 PIrv`R\bi}T't va '8B"yMium\ :4k$,:Pإ,lc(USGA6T6FSNt 40Rd )--=g75;1ŀjʷ^IBj9ܒ'{{*9gC%lSfp=4DvӠ?˚N7])EZCnAP̈ 7TL 1f=6^X Z unKr-&gcURnFfvbT.P~lW%as7Lh)r qfcط0AGVj'EX3*g9lHVe i uc~H:PܠeZ+D&hwxߔ_{L: iīyt*[ŢiHtXD;#f-ĠfC̄06vǒ :;|aӒnj;7>Ǟy[z5$TT׳I"؊aP L+#%:ZA"nH"ċ3?*Q3{|6)Efc8:Q%Zol~:X` }1lV 3]8S -l`~RSҹ|8QN9>_Bwu?5w3̄=[\::^0IͳQw*Myp qKPl-cnF';!#)ĺ qV}שpJƬIo-| sl6? egHeAzgþџtPXm6hڙc6 -dWxU ={2 j$ɪaeCC'$B>JuSU N^Yށav}@2Ƶz(S%jP+e.>ڱt6YIwY}K{gz+=XrOϭ]K,+)H#ڬBL%u^j޺A0-!&a^n4hɅCh="- ps{C_xyɈXΊ2]Ǽ^Njͽb8MĚ]C_3zwgj1R¹ԗ)IFCaJ,S#9(8}69""4Qrnj=fT;0} O%e*__̕D"RzwմM*=ohobFف8E5.QB,kcM9k ][µcH.$0T"b\!=\rUfY^ /+㣼B9,Mȉ3֨ ^p 14yڣcibI^^F&Q9w ;}#I `8lu-9w(Sn 4I[iЁ }I0HT2}δm@dE6ژw\F`TqAdL)>[& B\r-EXan69DC]mϻOvMts/n $u bk3`Bz (:6lεp0PrR+NWosVxfޯ @ɸW{`WG4K>!͇ yW gfW=MyDv"g7q\f*Dya#$T&ڟOYkdVJxFɦ -'yywlV  jd8]|n6z9}s7i*1cm*:0k\޷|v :N+TJ SؕƩ ,eLJo,gF .WGIpL<S}'*)FJZQvQ aÓ~eĈ= J1ĺs) ;tWHuzg {͠nK<-֫S\Cۢ1Eb/Js u(@IOb`N1jь"DcǶB 2Z\/_g+?+<,ߌ/. HE"MU2?E}0WP'ۍnLvޱ`T*B]?]/g lQvV94@[tNHI{TG#lSUa[Lh'0'3p& d-wި,ZvCiK۷T9/pXŽL-bsgpa)]91p^HF/+deĸEA/ۦXp Cw fb#Y"L>ZWh6F#I~Z\3|S ̍XN"j[=7Gё#Ty/ KpX2g!n3R2*Gt kQUB( O~O^[W(m0 5>(U[t^GT~)LAk!gѠb}K#1ďaco)XزP"msjMȦ*sbi}q啁rpRȶQ#iۊVsdJ~vVp/W ē՝ZUM}h}v,mг%5I`|?]zGK3b#d豺+,8+ˏCJ)Llίc?hs/ ~ ʖ?vGF2va iP@~zZIP.[uN4LMj.Rקb p+x_8 v ϼr\SE:bo0Yx,{J2d!$f z &/H:29tkPcrX-1XHVmJw7pU6[‡Pu;"$kM5PEwCVaFZSKy}4.% dp X0?;L7(`H:,h uJvX:/At5XmBN4YB'̆N6l\h OQ(5YK-p] +Ň6Mq M *c+7e*zŜ0;#o G !h<=RE50$E/lcKMtq5 >B'!y:eJ"#IUefjCۧ@,Zͬn ghrP'd%zczT|>ݛ2=tMzo=H~FT~S1gG |wItdOy=S6ڼnAs 3g&k-ye"5Uh50q XO&#4Xϩ8K5yMؘ? ,=#Yق@% 'כ%ݽ)'_ mş0Zm|W D /{EtXGh$ݠ9$Ct##ʕgqXm)$"i\]uj E G,Qwp`bk qEj|y_G^/Kf[')7@0SzDN@{O+ ^֙OW" ?gy/pu;,Ju:WF`o3{%w+VнT#?;<˙WbEu/R?" b.FVfsn6 CI)w-qgxϦ/w([-{e5]hlaTuSf֦VgEoB])F;s0a_p^3+QQ'9w(DwR,oߛGb:jt :g>Z1'%.Ͽd֙#A!sZ;Q$5t?㎑5(R'e(T+| wAMt*>7S9Pӥu91ťbBi+ᾡ7Bo~3 !R}Xj:Ѹ ?L>>Fz >:.]!n۠뮰!0]̻<?ŖyP{|sKgF?`>?{CD⨞Ž@9YoVm oo;Y)` Ji}]wbQD܇_c#[F߹Hأ7^vYWC7%}~8wV{[T5H!O?4Sj- v($)wY/k Q4v&5ßrQɔQp6," "d)Dr410#&`B۳M.Ck5$N :P@F vQJ7yqäQQ|g489Y!EQ}3 XLJ.-ZI/anVg@S5m܇>ރJ45Ƣt'lRfgmQE /LMRK 3kuMj` ƍdxMAS7,)(V=!^\dM R>[ܽHmhTODH@nO/t&%EN`moeqg)#OjKz$ `/QDƱy>b'/\#p=,:zA)g.\xJ03Vi"njCtjR͝r>L׋xIJs*4:51@ﯗMEE| !bAJ ][ ·GYl/ܳ6x' _6P:O&ف9]ɿͷu ޴Ǐ8ӂj֣3Z8-_WBX\!#FUh1#&'ij "Q\cDžME B-*csAbt'PKUoI([zR)2 I5k1PYC"ہdh^EhX=KwZ`ꑎ_NQnM{(u^u-7B)WC01)(+ _z%*9nIuᭌ_\k 2z_od"9ag*,Jnabd7Z~SY/H"צּh/3zF Enbuذ|DF*zj%ǻe{* NʛAIzwmʂ+kyl?H>zgA<,">߉I$-[8@f4lњ mdt8@e+N3}GF&i[UM^.cC@11?|q[pH HaF0,8fԩ>`Ik;\9ɦX*t[EOuGW&mysM9a (8jFW3b,Ϩ%!Lӆ~7n7GAkayd^s?lU/VuDj!}Gʧim;`BH=X~/⁶Uf8@F"(Uffy˾T^GDv??r_"s%75o+:">ӽԆߌb!}mNJ_Ƞ(a4\%BNUL@QQ'گ<ѵ} jK )N{o Hlٺ޴ӝ9g4ٳn.򬕍KVj;(\Bqoзm445kk9_J~[E ۙm=!5EK͓$H&,4:{QrgDP%VXW:rX0,|9e%*SNV h}8䟑#wȈ72+[r :u,LHWk>moRQx N\1J@.Ta6Y;S&PhkV*}oZUxW\h@.l{w5G붚 =%UG4B, KlLЦyO "6g} o(Ki޽|__G`ְ^.#q¬vG0z*˕vi*fhL= Z/[uu: W%Y' OcL(A~vha۠}Tw[7w 6c k)'7e#p)dQ"LUM  ?L ?\0h95"`_b$w匧ڲw᭻f8yZ9 Мd #N5bU(^wmдqh>">,1$ 7-f[jm;7^l#UeMQJ6yΛv _ 䇄@pԟcUG>P )ae+6ZvHn7&&/B sXҦee]OOJ) w^0d-P@T?y(?ŻFgH:MٺbygϕI*b;.ާ+ղ:Lӗۈ3hޝٯz/_'lTTL=Vh$HE\!iO UQJE?šYqڅ꒟%g5.kl; 'w"f9. NrXz{m0rK!=y]lW5Y@d;L1 'ǨE8k;cEgQ? a+6<;z ` "κަH"lԯr妌Z|dc.稝IqMMI,BL'Wz[rOW}t/6 U(_~s{K֯3 U@MA171LN_?|˔(ǫĘP#) <9FYF-jK]4B.F0̚WHB8V$}` V~𺁐F 2^ao.K=G\$HzFBk WH'((瀴ı0b:%W5wƶ[dp񲐌O.MC, h=p š,z|OРs6T<&ۍ&sړO y`s7l5Ȉ{1"/<Nޙ7t tGvg^ಽaKsқn*OQKs .# 0|$lߡ%= W|KKǁ̕2ш)RZ&5v46"_c(w @DH EV#}5H;,EuĤZg[VhGyMD2k.YaJ.RYl[Ȥ(g::!샭av{^HL iW\ w2ڨAD"dze^o6 E Z|^<,X>u*?r[4.75'i2Vk i*FoCWNQTu&ɚVxa> ݋DzMGXiŎABT9}:=tgOaLKCȤr(j0洛nˠ){rsҮt IVaPzheDT7jՌW.H )Z{AjG%ւHQ#sQs1͛y{zꦡ͂(^?sZp^ZR5驝 N,N_YL>AuRh8!Ȅ'ϑ8$RE,X Bv%5b31x VuAޮ:}i330F2/I &jܓp2;BUKPto( &h=Hg<6$ZN1~G rL0?PKjwݜLb%q 9J1JiJO*hA-lMmBAx^r^E}&a Ռʭ@OȺ;_'3XX0<_ua<6?9Ɲ1fngG'7I=p5MCa(ڣR'PDxM#9ۯ%/^Kv[CQjam6!m?UZMA::~ uD8aPcꓰ߅Gܡ>Rxd|n[Z $b*|-iyRmo#hLC#Bu[(/ M1M8õs eálޠʅ!92k+K\zjB+՞Gz.e+_X C OحɜjK[υ#Vrbc?rx~@RPJZ怦u8:&:.\,qVOrQ뼖:{^Kz<9)?Jj`nPt!&0q}ZMm^sͺSYI젩@g9l~rc`l0-p5nW;eo#<#w&J7B]%>jsh]þD=Z,{\G!~zz%˺*=W&p@^7a{>J1YJkĘJ8҄e](z}N>{]ze(J[ d!\4{Vfuؤ.Z_TUސ,m!چ '\UM^0ferՋ fǙlEpN&rV}^! s4!#wmHiыA468A+^Qa^27e]?VcGjN'i"Y/Jd`%~VݦA&ݍHno .Jr2b%-xPJmz߬O|.p"7_-R7QXx7v6ވS h^n +x|`Ăo-BaGZSspeXtl>`!`xKkO.ߚA;ްC"{1ˌ!#k~绣L 5DqGiOK?iq+lB43r"ۍp-]WSh%$ duQw[nDۃUҚ1XS_v>8[8 L?ܣh [ jye8\zvllE1Fh3J7|C^R6rƂUPyk4f˃BekaCД,T"%:{>0#4¡شA`Y+5e#e=+65kS&"ʲ%WTlXna*"L0!9#@ 'B~N7t}l 2Mݞ!4~?<,lPXcdK켘N>[hЮ&9êdꃸ^w:chiڬ4{6830XVmAuE_w޵KcCh hvupq벩Q=1qHl#D27H5,8J'TY8r=G''Ǐݳ%S'8~{RfF·9Je kcܞ}v+d C|d4 ܆?MryҀNd'mĒ`3|cl-z8]y \y3ߛ(>42MOg-^^z$z}۰|XǰQ%U?cD闖Ѭ !+YLNօ_WC` 6HS6*Dɐf_c<=k JV߳xΨ@0z@T*9N#4PFBW-=&Sc"VZ9v}AKy'f }J`o}]CEK,"y`8J%gHk|T-^|[]e?Ld ŹO}Si k {O2oNņb:.Q@_VMQxsyE HT`MWqѼu|#*:txoxݯ" _~v2Fc+]=Oq 3a7l)#I.劀 Qg?+ZYjeu?@? SV W'^ `y۽jgm*M]Ygce~yxAKUgt$)͕@ۖŹB>[3K(a6&dw!s MgmVÉNcNy+D $!ћkT/|;AĈ ]TPO\-Il| Sf\2xOFE^ Vvi