apparmor-profiles-3.1.7-150600.5.6.1<>,/Xhp9|z2?.BT7`FЯlDȾt]GK-S*+H]j$ʖǸo4u7|j*dSơovE Zd|X J vUlNa`3b 5vO}iKuJ\7}Z.9yY#[*0lvn #H0 |"LfAk\?,2|-,j.ڽw>SHZ6i-\-Q-) (>@???d ' i  #9X^h     PC QLUhZ__cd0dPe(e>8eH9g:sBFGHIX Y Z H[ L\ P]$l^7kb84c8d9`e9ef9hl9ju9|v=z=>?F?P?T?Z?Capparmor-profiles3.1.7150600.5.6.1AppArmor profiles that are loaded into the apparmor kernel moduleBase profiles. AppArmor is a file and network mandatory access control mechanism. AppArmor confines processes to the resources allowed by the systems administrator and can constrain the scope of potential security vulnerabilities. This package is part of a suite of tools that used to be named SubDomain.hh04-ch1b!6SUSE Linux Enterprise 15SUSE LLC GPL-2.0-only AND LGPL-2.1-or-laterhttps://www.suse.com/Productivity/Securityhttps://launchpad.net/apparmorlinuxnoarch%^V7:>69<9AA9=;:BDCEFCGMKJCICBJPCIIKID?D??>=<<<<ZGB@4cb  qc|WVA 4$$RV  $ 2rIqY A7LQy2N yYPU3UYLU9XIUYRMCiY1 ,a(F`' 9; . \ [ V<<]{1$E&2m{ 2 ~T(T"e PmZ1 mB A큤AAA큤A큤h h h hhhhhhhhhhh hhhhhh hhhhhh hhhh hhhh h hh hhhhhh hhhhhhhh hhhh hh hh h hhh h h h h h h h hh h h h h h h h h h hh h h h hh hhh h h h hh h hh hh hhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhhh68cbc7e271bed8160fb1dd96370f817f3ab61a65d405a542655a52223174de99643fa79788045b100be192345ef6c378ff97cfab0303593bf27e829bdc0e22b4a9459f44b42bed989146a7785a3e7a9a9beb5a4319d91007ff7938ebec6f6fdaab7f52de2a49c322ca22deaff676af8ebb909a0efd83b6d5e27579897a4c1c5d2f579e0bd229638c353f722be5d569088f55b297ee02cf32fae8226c1865aa04b845a39f39b6dd89fd194798b6e256f06cf57246796ecd525322851748748c1f064a9ff9902223b85a08a9030d4868215f93b1aed0262d81ae378c0887e7c2d733b4b1aeeb0e6f34197add8e90d04a7b51b3f800e146e1001b5a79ad37b9f2b52bdae8b831a46f381f541f563215ad6e1cc571daca13ba16aa597806e0225249796b6e6410e773021be2c82ad6fff7243e2e6f0d3c5c11adff61da073cb14d21dcc1af994578aa541041dc4f1a5a5e902f5bacddf783f1e08c0fb22fe622f8737823281bc7c0cc0f8c1181ba00768822bee344a885561e0fa17eb85ede3454ff81107f79fbb30188f8cef12435b9e584a686c26415c874b634f6fbbb5dac1a8c9713a9701599cf6cf610dc6fbaa85e6ccc7fdfa7261a25d3d213996aeae2757ba7d679d783bcaa5363764c16869f9ba995b36f0986db0b9d064025916e79ae86769b3370612194c0443dcaeb4483503e9f67e76d76fe7b28c6d9dab055fabeaec1ab19fa9edb110815e8afb1c90319ca5b468739300300adc013a121ee29da1811a5461ef85490aae0379a3723288539c21a200072453e1230511b0fc1a518a593dab4a141a620b249b52bea5ac8eebd27408df7ca56e67a1b5716adbc1d90ba7706b520236a3653e795b5b1762ff2c633719ec920734063fbb64ddff9c9e57cb514c5e90ef1727523ef832079ec02c8817f3b852ac8953ea05fa6b2601f2e3b676067207d5f4d60777308fd7e88ddc912b9d1e9562077c6438a23d925a31a0715390d8c5973b1ccdb15950066e099424d301af3e534cda973228af2ecb7326460be1c1b75ec6ba04e4ccf3e8deb5dc58b97b8ea38310a34838214f829d9d97d5a7fb8cbefda399fb3fd255417615c3fa1c026cfa7eed06fd7ba58c3b5cb0bc6478e6e27f75774172214494235ca00fc058966387c2824f9eaff8ea60ed7888be8ac96d5ed6d93eb94ca995979b604dd8813bc6b8d0a01d031fc4162766b75079cb034a0cb660a8448e7cbfaa59ceb8fd72a6a50167edcac82906a9f01e62d67347db7d402c98e4471548a029b8d424fc31cfc4083f0ed342b72eab2accc2c655c95272813199f06a2f7db93a231375902860e4306e561ee09896fcf381c76cd4af8b2f08bb90dc0f5ee2b1aee758841a2496c7c0055416cc85ea95377d139965eac9fc58403f411d821c6a95456bad8fe07226de1edb128f5a85fe7a7774a193e97afe6d695bee2568226c3b19d7e103a201cc9f29a52c6e2a2cdcb7ce6a6a2c640cce70ae04999ed60b0a976026a416e2856961882e06bc68abc16d4037ceb28faa7473a66ebd60ee2d7616321bcdda5d0274a710ebedddeae2237a8056924f7e02d233b9c252fe3ac767418bc35c95495954e2b36360b6de78ad77b7087ea38bb71ce0001c53644edcdc9afa09bf30260e4f7138525b1b8f65346e4b08c563b54759c0de72e4d112d07d3c65d36bb7bcd4ea9e8dedc811ac6e210efaeaf8c60eed8037dd30e6f6369ef74ba934438af33bb871e90584b9414f96f40e2b256b44710f72406f551fd9d86871d8f1c1b5c233b8356803b1768faae8e283a1c13698e8fdda52b1010a543290090131c2bf4ea878c446001285f5e53b98b355fcf78948c03e657e5d7334a929a1f3446fe1e3bf8dbf56e3b9e9ecab57c19a61ad31c12c8281a0fc2ecf3d49ef6dd542dc59849b5516988e7cac473dcbcbc4628940aff93a667d8e2fc0450279e04715f9977ddf0e4e0c53328159da9746a43ae08c12d6436bcafa4ab95794a993d0d8ca24cf1d334d4c9fce0a84854e0474de26c7cfa3a1e67cff4bf1034b7503fb8df38e5ace76607c853cb8dfc4d9d129bb262946919381c08d32151ce4a403c73ad22dcd5f9bca21be455587383e756a0343384c88f267a8aed928ddac0a62daa61229a0ec7b8e3fd91c5abf6e20c7c2093172b061126a386642e3e87a53366807829b3fbcca0df3efc6a70b6fe61c398e31e7df09c62a842da2aca7ab3049602aa4bbab8e95d7fdf25fccc3850f632b1cd0e4dd334507ac60d2e082c748d020a3c74dcc8f3f59da612eb93f1a811525eb2a9d8b58ab063a16077d5287f1ab8991cf18cae17ec149579e45f958c0724a1fb4a488bf1224ba412138927a02ba056b1d92445bf519394709b24cc23a11ac20c931e61fb5ea8a11531e0fe43c103819e2740802bab3af2079c1db2ea9af9c5cb6f1151dd374e97fc6d3903a9ad0227756b248e10f15bc94beb3e21f946f89185ab623884212ad299d00c7e82a75d1d9ac0914e6555cdfcdd80d3bc383bf01a81cf5404b1a9d9612a51a6ff5608a6b41f9aa39c87822763d955eaf53131dd924df8afcb1bbd6d604c56f08fb652ebd0bbed98f65d047b9c4aa2452bc3ebe8bdf0e9fee71e217ba04df1b5468ab8582e4dfec1ed71c07d69bc78c651238fd2a25a3c5835e3dca756e4e0a3923c729d257593a0f5a054eae0a0a041d5c31e67c03711e6e9481f08764a265f2d19baf11398cb3837d21da86d4f2b4464a867943ba617a9ecd96a261485d1635cd7475181d451e01d1a52c5d970c37c22dc79c87562659dc13d05f730dd2eb910799208ae49250f9012899454b44e9dd7cb104d2ab2bea2d0bfb898e2c112b6e9d80d6130153f7b3bba84c1b7dcad4c87193ae0263073d32f4fb40f9362f136a196af953db7a48b2b2a728650d7c41e453540a2e1ae38eaab57d929d9a000ffaab9b4cb6f9bee94658e6884c80a7f4f1db9d9b8eba884dc1fb0142f1756ea4499f2e7eaf9288757dd2a7eb7d6f44971cd0cee93bdcf203a5f41909a9a974d1fec6f7b2a17b0f811239cbd1af5bc3988aeda9faee5707c6ffae60bf937521b7ee71f3d8585a59ccbfca22f33c6c4f77b756f7f7d97d1fa51efaffbee2fd6c366fb80ca2b1c6795153098a8dc42062b6b4ef6754b30956c20aaad706cafdd144518d63c4af6bd13583957c01171c082f8a9fe11ea263f1836ce7a63c46e38674045f5d877167cd1877c59f4ec7e28401369f0a7775836e5bfaccbbe6e11758a50d1d8af40dde539d178d5509949308a30a7d6ec3f3ffe2a1c708482a66be047ae55963bb863fb63ffa415aa59e0fadb9ff3eb9c8ca611663d83bdb4787fc967605e67ca8d15e900150abd9350778f8312dfeed64384e23fa6648d4b5c6a6fc46e29e0a4bd4cf4f60f1cfe0dacd554bd6895f2c08cb6826eb8bb5fe332c5d3696efb039d4ec63129bc26c77449f111c5816b28998c06592bf540fa45b1301f20e720b107f959d99cba31966e122ca74650096839639f2efd858518f0f52fdf638e2db1df79720834071e48280c4ace5cdc4bd9c226b7580819e626e81ede4cd1b285f8c0fe5b5847391d7fc96ac431117c8ab9219bc9313e1a4e2595c1ee610fa1b4875c1000477b99c3a47a6dc33ee29bfad1da17ef591bbdae27e56617104ecc276f72c8702804fa399a282b71a639009f7679e56958f0afd0513e7372e579b3d1de789b43c180d3336c525584c1e3e302349abbe92c3900ffc5c8729f51828636695812e69766a3dbaceb2ffdd9da38b9e77122c0719567aac0e215e71f8cceef0bdfabb18b1bc8d4ece4a3a04b1673414563aba24c9d1cb9c75c66849b0b8768fb24ef37f6a1c5560fdcc5262df8d9f419c8f56a623622fef1408ffa98e0090fa40920bb7939264ee656a10af06035d98305bae7290c69282433394c92f94fc8df46263a990a019ca25e8c3fa34565f63fd4b53f70bc39c6991710b3f6b83782f038aa9c7c6854f98b92b76fb3549c8021975c441d0ee6b0923c0fef36724e106ab0bb6599472ef0717cbd18e962a903c064092d8b75501d2541ef0143550c5035cbc55b4c238dfc2611a829e8cd2e662280fa8fa5657b1a8c6c9c45572c7eae2cc2f379ddce887cbdabba8a506ac3db9708af24255285ae855101dd7056c52d0747bb53c582d487cb2ef1cdd3e84d57d8646a2190b296ec88d0841b6cd505076f75a88d7aa9f187921111cff5c1be0811253704f44181c6c00e69ac05abec0f539ad014c81c0f28380c8d89dba7153909ba735d0c2c3109665bb6b192534d0155e9a831b2a1e3d7e85b04120c5e7a933332e89de7eb75c98b8014d6dac1bfbf07756a31cd136671e062294c9cbd3e24c9ec3314c609a073ef177dd293d5789aed24f6022723253412be87eb28dfc5db7f039a3da535a665ad2f08cb3629ee3f0d3e7e17a12a6eb323ee0e123033925bd5d57a345e0fa80c8a4cd1fafb6516e3b4cd836a2366ac8be7fe81cb5fb71f1981d862133576388f01f9487038f6bb201a96339aff9b4298571bd09dd59654d5d51f845e165e1098ebd76fab193ff161badb910dd318d5d5ec3d6d61b435d308e5586b48f505fd7ba66bb3463eb1dbb40f3c0051cb31c09d7acea6211b2617566f5b89c2fa647becec96b7fe514879de2187a63755e93c33e805cac46d0348f942b0ea886cb28bd7a7ff7cbce79f53ca994d7637453788c6203308d0a358c3835af42d12129fcdf887cf1880dd7a691d0c99f5bdc9bc0cd5b079247430685c60493d527fa34edf886bef0538cb27dfdfbea98919bb02cc9287485e9c7bfb24e6f0c844ba3ac891f8f72177a919736dfde95ce368ed970c431a9922e52fae3084a89e6783321acc51728c030c9f8f492d258bafdc7d1c9d89d32f877f94307086856ac01a6a20f99fe273e577362fc985f3fee472dcb3d6e9748b95dd5cbae7c85473c7a85079451d44351350f727d3467af8e73c4fa0659e2ceaa475b026e13d52d96ec6f9ef3e34e9d92cf341915f9d3ccb655aa6b7738aa439a8f97042e51319c757c7e3da935a8bdfd86121e6efd8f249c704935ef94e7c497f11ac821cd4c4fcee9067206a65a4108d69b9bc12b015740947039f01c18049aaa04508c95f59e5d8f1238014edb67b44ca52880ac3610cea7bd4fab48b7255344a6be9c92a06956907e16f484475520a4cf9b221c264bd4395e29696e22764bf5d8a093460b3cf110cc3d5cd44f304feb76b281f24348b53aa0e4c48ab66c0272400932898aeb7f726216fa5db341d08d6473fda8627946866179efac869aac0d78eac02e24e6548a89d188d757cbe0937fddd1353c3a12cc5ba1a22d8cd8ae8da1cf777283c79a5a0a9cda1b168a79091467ccc556e02c5723e760d8effdac1703d6a03eddde3607d5d8aae54ba7f8eb628f3c8db37f6bee4c036e2529da2a0bc8ceff84fc14c73742c1cbfea5db2e36d4db2606551f1fe7470f2c32ffed65ff33534b05289d8c8331b406ee2a906575a412ec9c3cd483cbfab9339e19610323123bd281bd576a139975506bb118af57fb16571d63e1d1f0784d73aa47543d401bdb5c66dc2f35a079b73db118fb35f78e35aba2d558436dfdc63921910437150959a60bb88f1ef27840c25847f5d8c9525d27cc96974784a51de969faedb3bb34342549b781bb9996e33538b2cb203563bd1da49fb77f0bea32019e03ffb03016ca5338716c76854bc8e562ebcb939d0d3b8a88a6969179926c411a9ea6265a07bed5b89ede96a4b16d57a91cdf8c6f76d415ba3c7ff8d3f4335dbf340e0e381946ceb90fb5cd466cf936ae4f0535389a7000ccbdac0c12989e3e31500376a7110921335037f909f34da4604ffce7ecd6bafe2de42f2860f4a4343315cca7b42eb3d3da3b3d42e1fb24862bb750b5e52f02a9307db9817df3368c900e2b9da4b16a3b1dbec69cd3377da15b1882468b3a420b10135c682fcfcf2668e28828875422207ba4522bb62b13f51aca0a88e6f3977f49d73d2445068b3db8b922c366e2fa7b747c5b50e89d543d401a65661fe9e98e7b66f6da8121bf59cfaa6c8139d494b30a90aef132a70c563f035472d2e2c6c793f320f4c22a328136b359c4531c64e0c3bd048372d5c771ce763528b8b9203c86fd00a86e09f8ac3b3aa6815707728c8d44a292b21f09a57f3a4ac6d8883feb74f70b483a849ae53cbb6bd851886f75aba00abe15bd2252e046053040c6dc0f150441b1bfadb4e0491bf8b7105c286da664ad1b1d90cb26312355c6fb46bbedefc4ecb83aa7e0106f974efac67c1ebe6e5eb4764c7a6ae5243419644565dfd0d5313ff73ab726f050bdb606fd05a91cd2c5d1e810b44672e6246837d65c3721044e4ac9867c54a81143e8ea62f107a6c982e3955726bbc07c672e83ccfddfaba444855bdb8aecb16c6a26aa6e1a72d4982ddfa711d5059e5aca0deb4ff45276607143a6f000bd532bff6262f7e3d736dcc6057e8157f1f84f962e66b5f479881b0a5f7ec1b0425e1221b5f9ac59ca7bcbe5daa5c56a4768efa89dda073caaa19ba913b7820a7aff2907bf684dae4b6ba1a60adc4e0ae13cdc116631293a2afdee44f601313a2849ab95fa4b4d25cc176f1dce100a9ba52f5cece02c561b341fa8babdc3cc09486ca58e9b1e04816f2e461afccf8904f068775bfcc3ecb6d3d7911d6b66a02b533b48a26928c8ac6a34dbc0a72bfe095788dec4fc2bbcaddae96749d53d454080db698e60d10cd52a67eddf4b6564337bfd51a78980de5194f8d834207da21a135f43f7efd8a3e1c2e0202e0ec4e0c3d534fe5017b356227ddc57ddcb489e75e6437c6e2d2972c0a8545af437734124c83736c62fe5905dbe81088f97d6707884b7bce053197eb2d568a784e330e3f638c451695c0ca9a423e0df23d97a5c5762dd520fdc0ffd191e45917b525ab7b2926dda77a601028f651a3b90889aa863dd3a21c8d9c9dff01415b2ac44ee8b37b75c034118dccaf345f9a676da867657119c69d7a937db037baded19cdbf4638df5ad825a0fb7f70b674581d0d2415effec9a2e51eb0ebe5588d5df7bd7d55489afc7f0495b9aa756662531859361f03dec17935e00aeb624795be2eb93c0a670788f778af621db1a61e236a2c42b30fd9081f9400d8de0bcc553abc62a4a4cb5c6bfa4fd13f218aad7b15239ca9d197564a4a5cb5773250e326c3e33b4ce76b261491541c9d899bb7e60598384d137ac14efb0edc9f856ab6a3908fd6c1e54110a76ffa56104c0455572143c1dfd7002b854a98ce758821265c7f74756d46ceced6aa3b775901c86a23c853d7ee67f40161372e7631f3d6621255f4a76cf46c58484fee0341261f799ec4fcedf1cc01a42e05d05cff80dab1dd3db8af19981eb0c570d19d96c1f7896ae3eaebec27cc49de8182fdfd7f3fc733374f0f41c29e81ca274af8a4049b6f4dfb12119c50225bf2617d98078f3c207c6e12ac835a719524dcecee9c14647450a3ab85f8908ad5eb804430b39eb80e9b912f440eaa04e9d321bbf2ff9854003b49cdc96fed7efd5adbcf7be95511332b9238404e0494d7b3f51054f5c8eb12c98f5673c63039347e7b6546fa53ef8a6497b60ff42ec63f3d9b34e135cbd4b7a9d2d70ed73035d2371e0cff5ed8b663ff1a1b15b9c4d13a2fde4331779559474113286722f480b8fde246dbc562da219c67326ec5dc73ba7905dc755d9c00b5606f5cf67f298950a9ae96cae0f1b973ea57ddb5b547ff9b235db8deec538ce4fc4bb0d01c27c93abb9236818f253bbad1349cc2df8069cd5d7568927b74c2410116a13a9ef8b5126fcdd639db529f9ca5797cdc940f36465474cad9d4c15e2c4865df7d26368920c2f1e3ee1625508570612e9c5406bc534b3560631cd775de41aed6dffd2cc723dada17e07d935259b69ce5f0db67e71f244c450ec4b013bc406dd2dde0f7c9e8a8482811c553dd3c5f3f7d46aa9ef02468838ea16870457540bdb9b114ab84c8093c8f13c014ad6a7e3d69fb4f86497f470ad4394f596a4c3180c8355ee0f49271b0df3fbad0d82e935bd2ea6c29077e07a3a6e5dc9127629d6aeb9c17556fc43feae3ef94470d5ac2906482ff33532a0d7a9d7d654f5a8b184e9914973afc62faa7b95d2e36ab60253aa311a63b31948d0e9d3792ee3c87c8d2dd07ee758925c7978b9f4206c4e328009290254dd9306d169ee94f5252da87a6969d1e0fc5f8251bf3436388c73b21cb32d1ff25f2693b6b69a64a1e035b6dac158faba23eee7251f1663ca345872fd9ddc61812799fa04c5d69678d62b8f6236cea6811f4a69355f40e5243535580f75e2b6a85a4339ed312ceda3a45a3e18e12497b2fb3d0cdd9216a17d19b4c5ba2eb367021cc68c031b169f7df83afc5f6a2e964c24a0d5b4d608f701f35eef8ce5ece499eb4da12e358106826f3768364ffe83bec8901e7e28a754fd31ad1ebd850b96b810fdd8371209389f4839cb91b5c0a537f2e2fe63c09745d7bf4285359d99fc5cf08a89f24310112a9467f08d82d525597bfcc6df0a4503f477f3a3ca78d79725a1977fa4152e15671a01862f07827fce5c00e82ba72933d055768d5766dca628187e3bdffe48a34950b9f8a82a05a06cf1ea6c33710330384d01ee41f22f036eeec351cd1da38c88d92e171d1f9b8d63f1e8e9cc32f0e566576d104ba318ae127618024c4d78d2db58a7b86f5d0bc41292ba60902ab3edac6c6454e797ba4e2035a98289e8fc28d23005a2e038b2cc58e03e0c56fa7db673ed61d603647f9e5ac2312f480e89d22381196c25199c9f367152fdbb3f739c0694afaad4b1be7a193e9384026369fd6ba3af115f61a038ad1aa8dfb5242f72da20009ff13cc3430ea937386a66ab32cd4095e9f35f2ab44d47153d05a642b3536c1c92ed738fad6651845078dd5f6c9b943cfe9dcdbb7692c58e539b5117dfdfe7971b026e959b871665c7712cc0e677fb3f8889cca6eec3eb7af42b448d942b5121e6579074a0561d1f270ff26f9ff4a2b7065acd2513569907474c40f81777111a816330da51b983cc22808fa8c74193bb6e17a6efc05433a7f0f73758847a0419aaeddd704f16a62bf5d4655bedeb712c1d6b7c27981664f710a9b046e24e5d34e3f8abbb2723d341e5c5e1294e374da5996b1533a9194e9de7060ffdfb98ebe6e1fafd0805661839f9b380376e0c69069dee0d4ae1bd9f5c2180d2e6bcf0cc6cffa23464b945a9dfd8444dfd4f5da1df6e005559a2524409f4c8f0a2e130a9552e8c04a1a682a5bf7cd15db00cfed531fc9ed07e675c71db9bd714ab46e2f884ad7aa15047d5047f88c82f28427dd3106812d4a00840eea180990b6a446921e6fd1459b0a76e7fdc5e2ee301627b38eb4bbdde57ade8034d1a73d6fea2eb6d541d376e5482a656cc3957d43d3a90e92c93780b82eecb195443ecf9dbea96f8fc0892f43cfa22f4d6b995f28f4938a7a865dc1ee7c4c096b349baf80263e99ff346b1e1215248cdd38cda55cc9faa852f8603b1bcad5dabb1c39b7ae9af731f59e0039072f7bcc40ae6a32efbfa57b660dfd6fae0e357cd5da1b2028c5a3d4d805583eafb8ccf3b4ac0962279586735e69f8d450b241c4de617b18b5d4d22f9bdee02414543a5bbb70601ce1fe9dffc2d241d883a0b15c39593717556f73a80184b9302054e7148641a0ca9fa0478e4eac4348b065a909b2b705ac68b4217a90023b5069c0c28ee5e528fb11d9047ed887f09ca2c9a71f76e445b6e2ec18014ea6d2a4b3c7368476ebc8ec285b80adfc73793778a38f03f64544c1e50b392bd6064f885990782350e3ac8ae0844401fedff7ddc34d5e9e6e17b7b6207d4ab50cd99430109886b03df139466cfbc1b28315c90d4d4b3cd46449305127f2e84ff3bfa5153aca6ff47b07388dab31e5984b152f64af4109664bbcd03cb48ee941e1c5f3182e60cfde3184447c03755b12326c9665a792b131921bb26176c2f10f143ebeaae13102ef46d8398d1894332c4a49e9183c811d4a1a954a1b66aeb35f1e752f57b68629b5869ec75104025843e0ea50ff686c84b5fcac65d2355765c2106585783e412c1b41a246e60d1435d295ff0f667af1cf79ffa0079e06da4f92bae5cc2a4b9224e6c2dbfee61f195f058d7cc87ad088b552dcd8cde96019b99ae7062d6f5a8a2a68a9559313a66572239bb3d27187374d3c2f135669d71d9cffd204ba035fe153b9348b65f5b8f6646960b3731bad8fba1128f4ba21d199e8dce411ee0388cd517bfdb9e1f2bb6a6e97bef5ca1c61b25fd06adee82e43431ecd788ba8ce6a34979eba9e793716a15bad0bb452c235ff7639cedad6ff06464e7c50941c2a1d01ad14839f74c12f4aead8bf6b2e8f8c353325b7d71166431bab390a62cbe5d0e740e310a4da81ecf01a63d9c72e7336a6b7f40751a354fa8ba575c5a16e9933a31e6d6e3617b6068ac208b8b1da09f61f8b472a2e459ddf8b8a4557383983feff742f71e0a3e88730210ec4dab89c33e445b475452a07ed4d121852894c064efc347e09e88e6aaad36a31c5184d525981d8d131e3ccc737fee5d18486486e6398be3ac5957aa127651ee2885461ebab88571f795cd2cd6217f535d201971880d75ed3e2c2df3ad99deec82d53bf877803a8b18e120196ddf62ad26549517604d0aacce8a4168982dbd1b995008c3cb13bce4be7598f50c6f869e7be8eaf755c2dce8327c90d3bab61451a76ef03e0bce59ef4b7784a1e73ae6a5e4cf70dcbfacef158a5f40471749898860f5280e90a88ada115005fb59596b3c0cd9a032d304ceaf428ca2f101d11e81138f5cecbe163093c9212c3c517656ad8e6fb9c082a9dca28de166b562d22651aa20669345f2a6c196e4899a1a6e58570b8476f9f9a90d011b7f92f4fb8a3386ff614b7ec5ca1a231cab36d509dfadf3a50254a4aebcf9bc433aee5fe1c88bc0a4d0713bef2af865441cce055446e155fef3e5984abdc3a6219f19b638a4e79c23bf2a93b2cc4cd40589489199edcce8952711250989839bb02ee1319bdb009bb25bc79a6dda2411a8bb89ff8e89713db025c828797a9150e1d8cfa98f548a446d285dcaf9835f8c761a7aac4c534509e2dbb903b590a9e5ff8cc2861486e08eb589c66be379f11f3f96cc12299787a16644fff6bb872d7707b10f16db27144eb52f6242a727d4c7d4b756f779c919ba49c8fe360de00cb534991d03fbf3561b4a787586351f26aaf3d2361bb4e7a180cb130f62b72ac98d8c02f784d8f11f88a17a730fd147325ecf46adba38b0a13f340f96d2962b80fb563da83b62be48a9f0cd6d14b1a050e1db7c659c8a853bd16af77a3227fae4f4cf4050112bda93560b8b82e3bff62d97fdfc838aed43e53be9b3e39705c1cd341e51edbb685c466cdf722344ce50cde43d4d1e11a9a2f09ec2e87003eacc956af9cf9a50d0737dbcffefc98086d60832662b67687f9d84dce6aaf146528e14b4d59f1732f566f8bad6baed461a7e2125d000978f43afcdd2e91d14212db2c7fbc5f233d12ffdaffbdda1ab2c70f7553278f45641040e07bea8f8f630581af4bb22dec34456331abfa3ac65edc174a981f7579c044bd7d580571b21f93b9198893329d1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootapparmor-3.1.7-150600.5.6.1.src.rpmapparmor-profilesconfig(apparmor-profiles)subdomain-profiles     /bin/shapparmor-abstractionsapparmor-parser(CAP_SYSLOG)config(apparmor-profiles)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.1.73.1.7-150600.5.6.13.0.4-14.6.0-14.0-15.2-14.14.3hg@e@ee}@eԔ@eԔ@e@ee@eKx@eKx@ev@d@d7d@ddtdS@cccױ@c@c@c|c@c Xcb{@bb@bޅbVb@b@b{@bwbk@bi0@bZbV@bT@bRbBb<]@b@a7aZ@ap@aabaim@aEaaua $@`#@` @````_@`%@`!'`>` @__ǁ_ǁ_Q_h__@_~@_[f_P_-B@_@^m@^@^<@^j$@^,-]҇]o](]K@]]@\\@\ \\v{\I\ include in apache extra profile optional to avoid problems with empty profile directory (boo#1178527)- prepare usrmerge (boo#1029961) * use %_pamdir- update to AppArmor 3.0.1 - minor additions to profiles and abstractions - some bugfixes in libapparmor, apparmor_parser and the aa-* utils - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0.1 for the detailed upstream changelog - removed upstream(ed) patches: - changes-since-3.0.0.diff - extra-profiles-fix-Pux.diff - utils-fix-hotkey-conflict.diff- Use apache provided variables for the module_directry: + Use %apache_libexecdir + Add apache-rpm-macros BuildRequires- add utils-fix-hotkey-conflict.diff to fix a hotkey conflict in de, id and sv translations (and fix the test) (MR 675) - add extra-profiles-fix-Pux.diff to fix an inactive profile - prevents a crash in aa-logprof and aa-genprof when creating a new profile (MR 676)- update to AppArmor 3.0.0 - introduce feature abi declaration in profiles to enable use of new rule types (for openSUSE: dbus and unix rules) - support xattr attachment conditionals - experimental support for kill and unconfined profile modes - rewritten aa-status (in C), including support for new profile modes - rewritten aa-notify (in python), finally dropping the perl requirement at runtime - new tool aa-features-abi for extracting feature abis from the kernel - update profiles to have profile names and to use 3.0 feature abi - introduce @{etc_ro} and @{etc_rw} profile variables - new profile for php-fpm - several updates to profiles and abstractions (including boo#1166007) - fully support 'include if exists' in the aa-* tools - rewrite handling of alias, include, link and variable rules in the aa-* tools - rewrite and simplify log handling in the aa-logprof and aa-genprof - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0 for the detailed upstream changelog - patches: - add changes-since-3.0.0.diff with upstream fixes since the 3.0.0 release up to 3e18c0785abc03ee42a022a67a27a085516a7921 - drop upstreamed usr-etc-abstractions-base-nameservice.diff - drop 2.13-only libapparmor-so-number.diff - refresh apparmor-enable-profile-cache.diff - partially upstreamed - update apparmor-samba-include-permissions-for-shares.diff and apparmor-lessopen-profile.patch - switch to "include if exists" - apparmor-lessopen-profile.patch: add abi rule to lessopen profile - refresh apparmor-lessopen-nfs-workaround.diff - move away very loose apache profile that doesn't even match the apache2 binary path in openSUSE to avoid confusion (boo#872984) - move rewritten aa-status from utils to parser subpackage - add aa-features-abi to parser subpackage - replace perl and libnotify-tools requires with requiring python3-notify2 and python3-psutil (needed by the rewritten aa-notify) - drop ancient cleanup for /etc/init.d/subdomain from parser %pre - drop (never enabled) conditionals to build with python2 and to build the python-apparmor subpackage (upstream dropped python2 support) - drop setting PYTHON and PYTHON_VERSIONS env variable, no longer needed - set PYFLAKES path for utils check - add precompiled_cache build conditional to allow faster local builds without using kvm - remove duplicated BuildRequires: swig- update to AppArmor 2.13.5 - add missing permissions to several profiles and abstractions - bugfixes in parser and tools - fix two potential build failures in libapparmor - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5 for the detailed upstream changelog - remove upstream(ed) patches - changes-since-2.13.4.diff - abstractions-X-xauth-mr582.diff - sevdb-caps-mr589.diff - libvirt-leaseshelper.patch - cap_checkpoint_restore.diff - add libapparmor-so-number.diff to fix libapparmor so version (!658)- add CAP_CHECKPOINT_RESTORE to severity.db (MR 656, cap_checkpoint_restore.diff)- %service_del_postun_without_restart only works for Tumbleweed, keep using DISABLE_RESTART_ON_UPDATE for Leap 15.x- Make use of %service_del_postun_without_restart And stop using DISABLE_RESTART_ON_UPDATE as this interface is obsolete.- libvirt-leaseshelper.patch: add /usr/libexec as a path to the libvirt leaseshelper script (jsc#SLE-14253)- sevdb-caps-mr589.diff: add new capabilities CAP_BPF and CAP_PERFMON to severity.db (lp#1890547)- add abstractions-X-xauth-mr582.diff to allow reading the xauth file from its new sddm location (boo#1174290, boo#1174293)- add changes-since-2.13.4.diff with upstream changes and fixes since 2.13.4 up to 5f61bd4c: - add several abstractions related to xdg-open: dbus-network-manager-strict, exo-open, gio-open, gvfs-open, kde-open5, xdg-open - introduce @{run} variable - update dnsmasq and winbindd profile - update mdns, mesa and nameservice abstraction - some bugfixes in the aa-* tools, including a remote bugfix in the YaST AppArmor module (boo#1171315) - drop upstream(ed) patches (now part of changes-since-2.13.4.diff): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-fix-utils-network-test.diff - make-4.3-network.diff - abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch - apply usr-etc-abstractions-base-nameservice.diff only for Tumbleweed, but not for Leap 15.x where it's not needed - refresh usr-etc-abstractions-base-nameservice.diff- Add abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch (bsc#1168306)- fix build with make 4.3 by backporting some commits from upstream master (boo#1167953): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-network.diff - make-4.3-fix-utils-network-test.diff- update to AppArmor 2.13.4 - several abstraction updates (including boo#1153162) - disallow writing to fontconfig cache in abstractions/fonts - some bugfixes in the aa-* tools - fix log parsing for logs with an embedded newline - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4 for the detailed upstream changelog - drop upstreamed patches: - abstractions-ssl-certbot-paths.diff - apparmor-krb5-conf-d.diff - libapparmor-python3.8.diff - usr-etc-abstractions-authentification.diff - refresh usr-etc-abstractions-base-nameservice.diff- add usr-etc-abstractions-base-nameservice.diff to adjust abstractions/base and nameservice for /usr/etc/ (boo#1161756)- Properly pull in full python3 interpreter- add libapparmor-python3.8.diff to fix building the libapparmor python bindings (deb#943657)- add usr-etc-abstractions-authentification.diff to allow reading /usr/etc/pam.d/* and some other authentification-related files (boo#1153162)- add abstractions-ssl-certbot-paths.diff - add certbot paths to abstractions/ssl_certs and abstractions/ssl_keys- add apparmor-krb5-conf-d.diff for kerberos client- update to 2.13.3 - profile updates for dnsmasq, dovecot, identd, syslog-ng - new "lsb_release" profile (only used when using "Px -> lsb_release") - fix buggy syntax in tunables/share - several abstraction updates - parser: fix "Px -> foo-bar" (the "-" was rejected before) - several bugfixes in aa-genprof and aa-logprof - some fixes in cache handling - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3 for the detailed upstream changelog - drop upstream(ed) patches: - apparmor-nameservice-resolv-conf-link.patch - profile_filename_cornercase.diff - dnsmasq-libvirtd.diff - dnsmasq-revert-alternation.diff - usrmerge-fixes.diff - libapparmor-swig-4.diff - re-number remaining patches- add upstream libapparmor-swig-4.diff: fix libapparmor tests with swig 4.0 (boo#1135751)- Disable LTO (boo#1133091).- update lessopen.sh profile for usrMerge (bash and tar) (boo#1132350)- add usrmerge-fixes.diff: fix test failures when /bin/sh is handled by update-alternatives (boo#1127877)- add dnsmasq-revert-alternation.diff: revert path alternation in dnsmasq profile and re-add peer=/usr/sbin/libvirtd rules to avoid breaking libvirtd (boo#1127073)- add dnsmasq-libvirtd.diff: allow peer=libvirtd in the dnsmasq profile to match the newly added libvirtd profile name (boo#1118952#c3)- Use %license instead of %doc [bsc#1082318]- add apparmor-lessopen-nfs-workaround.diff: allow network access in lessopen.sh for reading files on NFS (workaround for boo#1119937 / lp#1784499)- add profile_filename_cornercase.diff: drop check that lets aa-logprof error out in a corner-case (log event for a non-existing profile while a profile file with the default filename for that non-existing profile exists) (boo#1120472)- netconfig: write resolv.conf to /run with link to /etc (fate#325872, boo#1097370) [patch apparmor-nameservice-resolv-conf-link.patch]- update to AppArmor 2.13.2 - add profile names to most profiles - update dnsmasq profile (pid file and logfile path) (boo#1111342) - add vulkan abstraction - add letsencrypt certificate path to abstractions/ssl_* - ignore *.orig and *.rej files when loading profiles - fix aa-complain etc. to handle named profiles - several bugfixes and small profile improvements - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.2 for the detailed upstream changelog - remove upstreamed fix-syntax-error-in-rc.apparmor.functions.patch- update to 2.13.1 - add qt5 and qt5-compose-cache-write abstractions - add @{uid} and @{uids} kernel var placeholders - several profile and abstraction updates - ignore "abi" rules in parser and tools (instead of erroring out) - utils: fix overwriting of child profile flags if they differ from the main profile - several bugfixes (including boo#1100779) - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.1 for the detailed upstream changelog - remove upstream(ed) patches: - aa-teardown-path.diff - fix-apparmor-systemd-perms.diff - logprof-skip-cache-d.diff - fix-samba-profiles.patch - make-pyflakes-happy.diff - dnsmasq-Add-permission-to-open-log-files.patch - refresh apparmor-samba-include-permissions-for-shares.diff - add fix-syntax-error-in-rc.apparmor.functions.patch- update rpmlintrc: - whitelist .features file which is part of the pre-compiled cache - comment out filters for the disabled tomcat_apparmor subpackage- Backport dnsmasq fix: 025c7dc6 - dnsmasq-Add-permission-to-open-log-files.patch (boo#1111342)- add make-pyflakes-happy.diff to fix an unused variable (SR 629206)- add fix-samba-profiles.patch - smbd loads new shared libraries. Allow winbindd to access new kerberos credential cache location (boo#1092099)- exclude the /etc/apparmor.d/cache.d/ directory from aa-logprof parsing (logprof-skip-cache-d.diff)- add fix-apparmor-systemd-perms.diff - fix permissions of /lib/apparmor/apparmor.systemd (boo#1090545)- create and package precompiled cache (/usr/share/apparmor/cache, read-only) (boo#1069906, boo#1074429) - change (writeable) cache directory to /var/cache/apparmor/ - with the new btrfs layout, the only reason for using /var/lib/apparmor/cache/ (which was "it's part of the / subvolume") is gone, and /var/cache makes more sense for the cache - adjust parser.conf (via apparmor-enable-profile-cache.diff) to use both cache locations - clear cache also in %post of abstractions package- update to AppArmor 2.13 - add support for multiple cache directories and cache overlays (boo#1069906, boo#1074429) - add support for conditional includes in policy - remove group restrictions from aa-notify (boo#1058787) - aa-complain etc.: set flags for profiles represented by a glob - aa-status: split profile from exec name - several profile and abstraction updates - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13 for the detailed upstream changelog - drop upstreamed patches and files: - aa-teardown - apparmor.service - apparmor.systemd - 32-bit-no-uid.diff - disable-cache-on-ro-fs.diff - dovecot-stats.diff - parser-write-cache-warn-only.diff - set-flags-for-profiles-represented-by-glob.patch - fix-regression-in-set-flags.patch - drop spec code that handled installing aa-teardown, apparmor.service and apparmor.systemd (now part of upstream Makefile) - simplify "make -C profiles parser-check" call (upstream Makefile bug that required to call "cd" was fixed) - add aa-teardown-path.diff - install aa-teardown in /usr/sbin/ - move 'exec' symlink to parser package (belongs to aa-exec)- Set flags for profiles represented by glob (bsc#1086154) set-flags-for-profiles-represented-by-glob.patch fix-regression-in-set-flags.patch- add dovecot-stats.diff: - add dovecot/stats profile and allow dovecot to run it (boo#1088161) - allow dovecot/auth to write /run/dovecot/old-stats-user (part of boo#1087753) - update 32-bit-no-uid.diff with upstream fix- Change of path of rpm in lessopen.sh (boo#1082956)- add disable-cache-on-ro-fs.diff - disable write cache if filesystem is read-only and don't bail out (bsc#1069906, bsc#1074429)- add parser-write-cache-warn-only.diff to make cache write failures a warning instead of an error (boo#1069906, boo#1074429) - reduce dependeny on libnotify-tools (used by aa-notify -p) to "Suggests" to avoid pulling in several Gnome packages on servers (boo#1067477)- update to AppArmor 2.12 - add support for 'owner' rules in aa-logprof and aa-genprof - add support for includes with absolute path in aa-logprof etc. (lp#1733700) - update aa-decode to also decode PROCTITLE (lp#1736841) - several profile and abstraction updates, including boo#1069470 - preserve errno across aa_*_unref() functions - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.12 for the detailed upstream changelog - drop upstreamed patches: - read_inactive_profile-exactly-once.patch - utils-fix-sorted-save_profiles-regression.diff - lessopen profile: change all 'rix' rules to 'mrix' - add 32-bit-no-uid.diff to fix handling of log events without ouid on 32 bit systems - no longer package static libapparmor.a- update to AppArmor 2.11.95 aka 2.12 beta1 - add JSON interface to aa-logprof and aa-genprof (used by YaST) - drop old YaST interface code - update audio, base and nameservice abstractions - allow @{pid} to match 7-digit pids - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_95 for the detailed upstream changelog - drop upstreamed patches - apparmor-yast-cleanup.patch - apparmor-json-support.patch - nameservice-libtirpc.diff - drop obsolete perl modules (YaST no longer needs them) - drop patches that were only needed by the obsolete perl modules: - apparmor-utils-string-split - apparmor-abstractions-no-multiline.diff - drop profiles-sockets-temporary-fix.patch - obsoleted by a fix in apparmor_parser - refresh utils-fix-sorted-save_profiles-regression.diff - add aa-teardown (new script to unload all profiles) - make ExecStop in apparmor.service a no-op (workaround for a systemd restriction, see boo#996520 and boo#853019 for details) - lessopen profile: allow capability dac_read_search and dac_override, allow groff to execute several helpers (boo#1065388)- read_inactive_profile-exactly-once.patch (bsc#1069346) Perform reading of inactive profiles exactly once.- update to AppArmor 2.11.1 - add permissions to several profiles and abstractions (including lp#1650827 and boo#1057900) - several fixes in the aa-* tools (including lp#1689667, lp#1628286, lp#1661766 and boo#1062667) - fix downgrading/converting of 'unix' rules (will be supported in kernel 4.15) to 'network unix' rules in apparmor_parser (boo#1061195) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_1 for upstream changelog - remove upstream(ed) patches - upstream-changes-r3616..3628.diff - upstream-changes-r3629..3648.diff - parser-tests-dbus-duplicated-conditionals.diff - apparmor-fix-podsyntax.patch - sshd-profile-drop-local-include-r3615.diff - refresh apparmor-yast-cleanup.patch - add utils-fix-sorted-save_profiles-regression.diff to fix a regression in displaying the "changed profiles" list in aa-logprof- add nameservice-libtirpc.diff to fix NIS/YP logins (boo#1062244)- profiles-sockets-temporary-fix.patch to cater to nameservices with the new sockets mediation, until unix rules are upstreamed (boo#1061195)- add apparmor-fix-podsyntax.patch from mailing list to fix compilation with perl 5.26- do not require exact X.Y version of "python3" - require also matching python(abi) which is arguably more important- don't rely on implementation details for reload in %post- add JSON support. Required for FATE#323380. (apparmor-yast-cleanup.patch, apparmor-json-support.patch)- add upstream-changes-r3629..3648.diff: - preserve unknown profiles when reloading apparmor.service (CVE-2017-6507, lp#1668892, boo#1029696) - add aa-remove-unknown utility to unload unknown profiles (lp#1668892) - update nvidia abstraction for newer nvidia drivers - don't enforce ordering of dbus rule attributes in utils (lp#1628286) - add --parser, --base and --Include option to aa-easyprof to allow non-standard paths (useful for tests) (lp#1521031) - move initialization code in apparmor.aa to init_aa(). This allows to run all utils tests even if /etc/apparmor.d/ or /sbin/apparmor_parser don't exist. - several improvements in the utils tests - drop upstreamed python3-drop-re-locale.patch - no longer delete/skip some of the utils tests (to allow this, add parser-tests-dbus-duplicated-conditionals.diff) - add var.mount dependeny to apparmor.service (boo#1016259#c34)- Cleanup spec file: - don't use insserv if we afterwards call systemd, this can have bad side effects - remove dead code - remove now obsolete 'distro' checks - Replace init.d script with new wrapper working with systemd- add python3-drop-re-locale.patch: remove deprecated re.LOCALE flag in Python UI as it was dropped from Python 3.6 (lp#1661766)- Fix RPM groups- add upstream-changes-r3616..3628.diff: - update abstractions/base, abstractions/apache2-common and dovecot profiles - merge ask_the_questions() of aa-logprof and aa-mergeprof - pass LDFLAGS when building parser, libapparmor perl bindings and pam_apparmor - adjust deleting the cache in profiles %post to the new cache location - silence errors when deleting the cache (boo#976914)- split libapparmor into separate spec to get rid of build loop involving mariadb, systemd, apparmor, libapr and mariadb again (see the discussion in SR 448871 for details) - libapparmor.spec is based on the AppArmor 2.11 apparmor.spec, but with minimum BuildRequires- update to AppArmor 2.11.0 - apparmor_parser now supports parallel compiles and loads - add full support for dbus, ptrace and signal rules and events to the utils - full rewrite of the file rule handling in the utils - lots of improvements and fixes - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11 for the detailed changelog - patches: - add sshd-profile-drop-local-include-r3615.diff to fix 'make check' - drop aa-unconfined-fix-netstat-call-2.10r3380.diff, no longer needed - refresh apparmor-abstractions-no-multiline.diff - refresh apparmor-samba-include-permissions-for-shares.diff - spec changes: - aa-unconfined switched to using ss (from iproute2), adjust Recommends: - move libapparmor to /usr/lib*/ - drop %if %suse_version checks for 12.x - change several Obsoletes from %version to < 2.9. Those package names weren't used since years, and 2.9 is still a careful choice - include apparmor.service independent of %suse_version - techdoc.pdf is now shipped in upstream tarball to reduce BuildRequires - drop latex2html, texlive-* and w3m BuildRequires - techdoc.txt and techdoc.html not included, drop them from the package - run most of utils/ make check (some tests expect /etc/apparmor.d/ and /sbin/apparmor_parser to exist, skip them) - BuildRequires python3-pyflakes (utils tests) and dejagnu (libapparmor tests) - drop sed'ing python3 into aa-* shebang (upstreamed) - build binutils - aa-exec is now written in C and lives in /usr/bin/, move it to the apparmor_parser package and create a compability symlink in /usr/sbin/ - aa-exec manpage moved to section 1 - aa-enabled is a small new tool to find out if AppArmor is enabled - package new aa_stack_profile(2) manpage- change /etc/apparmor.d/cache symlink to /var/lib/apparmor/cache/. This is part of the root partition (at least with default partitioning) and should be available earlier than /var/cache/apparmor/ (boo#1015249, boo#980081, bsc#1016259) - add dependency on var-lib.mount to apparmor.service as safety net- update to AppArmor 2.10.2 maintenance release - lots of bugfixes and profile updates (including boo#1000201, boo#1009964, boo#1014463) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_2 for details - add aa-unconfined-fix-netstat-call-2.10r3380.diff to fix a regression in aa-unconfined - drop upstream(ed) patches: - changes-since-2.10.1--r3326..3346.diff - changes-since-2.10.1--r3347..3353.diff - libapparmor-fix-import-path.diff (upstream fix is slightly different) - nscd-var-lib.diff - refresh apparmor-abstractions-no-multiline.diff- add nscd-var-lib.diff to allow /var/lib/nscd/ in the nscd profile and abstractions/nameservice (path changed in latest nscd in Tumbleweed)- add changes-since-2.10.1--r3347..3353.diff with upstream changes and fixes in the 2.10 branch, including - allow writing *.qf files (for disk-based buffering) in syslog-ng profile - add several permissions to the dovecot profiles (deb#835826) - add a missing path in the traceroute profile- add changes-since-2.10.1--r3326..3346.diff with upstream changes and fixes since the 2.10.1 release, including - allow dac_override in winbindd profile (boo#990006#c5) - allow mr for /usr/lib*/ldb/*.so in samba abstractions (needed since Samba 4.4.x, boo#990006) - abstractions/nameservice: also support ConnMan-managed resolv.conf - let aa-genprof ask about profiles in extra dir (again) - fix aa-logprof "add hat" endless loop (lp#1538306) - honor 'chown' file events in logparser.py - ignore log file events with a request mask of 'send' or 'receive' because they are actually network events (lp#1577051, lp#1582374) - accept hostname with dots when parsing logs (lp#1453300 comments #1 and #2) - fix python LibAppArmor import failures with swig > 3.0.8 (boo#987607) (libapparmor-fix-import-path.diff) - refresh apparmor-abstractions-no-multiline.diff - drop upstreamed profiles-ping-inet6-r3449.diff - add %check section - runs libapparmor (including swig bindings), parser and profiles tests - add BuildRequires: perl(Locale::gettext) - needed for parser tests- add profiles-ping-inet6-r3449.diff - latest ping also does IPv6 (boo#980596)- update to AppArmor 2.10.1 (2.10 branch r3326): - fix incorrect output of child profile names (apparmor_parser -N) which caused 'rcapparmor reload' to remove child profiles and hats (lp#1551950) - fix a crash in aa-logprof / logparser.py for change_hat log events (lp#1523297) and log events that look like file events, but aren't (lp#1540562, lp#1525119, lp#1466812) - write unix rules when saving a profile (lp#1522938, boo#954104#c3) - several fixes for variable handling in aa-logprof - map c (create) log events to w instead of a - add python to the "no Px rule" list in logprof.conf - let aa-logprof check for duplicate profiles - let aa-status work without the apparmor.fail python module (boo#971917, lp#1480492) - add permissions in several profiles (including boo#948584, boo#948753, boo#954959, boo#954958, boo#971790, boo#964971, boo#921098, boo#923201 and boo#921098#c15). - and many more fixes, see the full changelog at http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_1 - drop upstream(ed) patches: - fix-initscript-aa_log_end_msg.diff - syslog-ng-profile-boo948584.diff - upstream-profile-updates-r3205-3241.diff - refresh patches: - apparmor-abstractions-no-multiline.diff - apparmor-samba-include-permissions-for-shares.diff - drop libapparmor autogen.sh call (broke the build) and remove libtool BR- add syslog-ng-profile-boo948584.diff - add several permissions needed by latest syslog-ng (boo#948584, boo#948753) - add upstream-profile-updates-r3205-3241.diff with several profile updates: - add /usr/share/locale-bundle/** to abstractions/base - allow dnsmask to use /bin/sh (boo#940749) and /bin/dash - allow dovecot imap to read /run/dovecot/mounts - allow avahi-daemon to write to /run/systemd/notify - allow ntpd to read $PATH directory listings (boo#945592, boo#948752) - update dhclient profile - allow skype to read @{PROC}/@{pid}/net/dev (boo#939568) - and some other small updates - drop upstreamed apparmor-winbindd-r3213.diff (included in the upstream-profile-updates patch)- netstat moved to net-tools-deprecated in Tumbleweed (boo#944904)- add apparmor-winbindd-r3213.diff - add missing k permissions for /etc/samba/smbd.tmp/msg/* in winbindd profile (boo#921098 #c15..19)- add fix-initscript-aa_log_end_msg.diff - fixes ugly initscript output (boo#862170)- update to AppArmor 2.10 (trunk r3205) - profile names can now contain variables - improved profile compile time in apparmor_parser - lots of improvements, refactoring and bugfixes in the aa-* tools - new apis for managing and loading profile caches into the kernel in libapparmor - lots of profile updates - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10 for the complete changelog with more details - add new apparmor_private.h and the aa_query_label(2), aa_features(3), aa_kernel_interface(3), aa_policy_cache(3), aa_splitcon(3) manpages to libapparmor-devel - drop apparmor-2.5.1-edirectory-profile patch - it's most probably no longer needed (see boo#621394 for details) - drop upstreamed samba-4.2-profiles.diff - refresh apparmor-samba-include-permissions-for-shares.diff- systemd-rpm-macros and %systemd_requires were at the wrong place, move them to the parser package (boo#931792)- update to AppArmor 2.9.2 (2.9 branch r2911) - lots of bugfixes in the parser and the aa-* tools (including boo#918787) - update dovecot and dnsmasq profiles and several abstractions (including boo#911001) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_2 for the full changelog - remove upstream(ed) patches apparmor-changes-since-2.9.1.diff and apparmor-fix-stl-ostream.diff - replace GPG key with new AppArmor GPG signing key, see https://launchpad.net/apparmor/+announcement/13404- make sure %service_del_postun doesn't call systemctl try-restart (boo#853019, bare systemd edition) - add samba-4.2-profiles.diff: update samba (winbindd and nmb) profiles for samba 4.2 (boo#921098, boo#923201)- only install apparmor.service for openSUSE > 13.2- Add a native systemd unit which *at the moment* only wraps/masks the early boot script.- add apparmor-fix-stl-ostream.diff which fixes odd uses of std::ostream which are not valid. Fixes build with GCC 5- allow lessopen.sh to run /usr/bin/unzip-plain (boo#906858)- add Requires: python3 to python3-apparmor package - readline isn't part of python3-base (boo#917577)- add apparmor-changes-since-2.9.1.diff with upstream fixes since the 2.9.1 release - update logparser.py to support changed syslog format (lp#1399027) - update usr.sbin.dovecot and usr.lib.dovecot.imap{, -login} profiles (lp#1296667) - update the mysqld profile - fix network rule description in apparmor.d(5) manpage - drop upstreamed dnsmasq-profile-fixes.patch - update expired GPG key- update to AppArmor 2.9.1 (2.9 branch r2831) - fix log parsing for 3.16 kernels and syslog-style logs (boo#905368) - several fixes and performance improvements in the aa-* utils - profile updates for dnsmasq (boo#907870), nscd (boo#904620#c14 and bnc#908856), useradd, sendmail, man and passwd - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_1 for full release notes - refresh dnsmasq-profile-fixes.patch- Fix dnsmasq profile to allow executing bash to run the --dhcp-script argument. Also fixed /usr/lib -> /usr/{lib,lib64} to get libvirt leasehealper script to run even on x86_64. dnsmasq-profile-fixes.patch. boo#911001- rename lessopen.sh profile file to usr.bin.lessopen.sh to match the script filename- add apparmor-lessopen-profile.patch: /usr/bin/lessopen.sh needs confinement. bnc#906858- delete cache in apparmor-profiles %post (workaround for bnc#904620#c8 / lp#1392042)- No longer perform gpg validation; osc source_validator does it implicit: + Drop gpg-offline BuildRequires. + No longer execute gpg_verify.- fix bashism in post script- update to AppArmor 2.9.0 (r2759) - change aa-mergeprof to the final commandline syntax - lots of bugfixes in the aa-* tools (bnc#900163, lp#1328707 and several bugs without a formal bugreport) - small additions to gnome, freedesktop.org, ubuntu-browsers.d/java and user-mail abstractions - fix mod_apparmor to not break basic auth - update perl modules to support signal, unix and ptrace rules (bnc#900013) - don't warn about rules not supported by the kernel - fix logging of "audit capability" (lp#1378091) - add support for the "hat" keyword in apparmor.vim - build html version of apparmor.vim manpage again (lp#1366572) - see also http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_0 - update apparmor-abstractions-no-multiline.diff - remove upstreamed apparmor-profiles-ntpd-pid-location.diffsubdomain-profilesh04-ch1b 1745392364  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~3.1.7-150600.5.6.13.1.7-150600.5.6.13.1.72.9apache2.dphpsysinfobin.pingREADMEbin.pinglsb_releasenvidia_modprobephp-fpmsamba-bgqdsamba-dcerpcdsamba-rpcdsamba-rpcd-classicsamba-rpcd-spoolsssbin.klogdsbin.syslog-ngsbin.syslogdunix-chkpwdusr.bin.lessopen.shusr.lib.dovecot.anvilusr.lib.dovecot.authusr.lib.dovecot.configusr.lib.dovecot.deliverusr.lib.dovecot.dictusr.lib.dovecot.directorusr.lib.dovecot.doveadm-serverusr.lib.dovecot.dovecot-authusr.lib.dovecot.dovecot-ldausr.lib.dovecot.imapusr.lib.dovecot.imap-loginusr.lib.dovecot.lmtpusr.lib.dovecot.logusr.lib.dovecot.managesieveusr.lib.dovecot.managesieve-loginusr.lib.dovecot.pop3usr.lib.dovecot.pop3-loginusr.lib.dovecot.replicatorusr.lib.dovecot.script-loginusr.lib.dovecot.ssl-paramsusr.lib.dovecot.statsusr.sbin.apache2usr.sbin.avahi-daemonusr.sbin.dnsmasqusr.sbin.dovecotusr.sbin.identdusr.sbin.mdnsdusr.sbin.nmbdusr.sbin.nscdusr.sbin.ntpdusr.sbin.smbdusr.sbin.smbd-sharesusr.sbin.smbldap-useraddusr.sbin.tracerouteusr.sbin.winbinddzgreplsb_releasenvidia_modprobephp-fpmsamba-bgqdsamba-dcerpcdsamba-rpcdsamba-rpcd-classicsamba-rpcd-spoolsssbin.klogdsbin.syslog-ngsbin.syslogdunix-chkpwdusr.bin.lessopen.shusr.lib.dovecot.anvilusr.lib.dovecot.authusr.lib.dovecot.configusr.lib.dovecot.deliverusr.lib.dovecot.dictusr.lib.dovecot.directorusr.lib.dovecot.doveadm-serverusr.lib.dovecot.dovecot-authusr.lib.dovecot.dovecot-ldausr.lib.dovecot.imapusr.lib.dovecot.imap-loginusr.lib.dovecot.lmtpusr.lib.dovecot.logusr.lib.dovecot.managesieveusr.lib.dovecot.managesieve-loginusr.lib.dovecot.pop3usr.lib.dovecot.pop3-loginusr.lib.dovecot.replicatorusr.lib.dovecot.script-loginusr.lib.dovecot.ssl-paramsusr.lib.dovecot.statsusr.sbin.apache2usr.sbin.avahi-daemonusr.sbin.dnsmasqusr.sbin.dovecotusr.sbin.identdusr.sbin.mdnsdusr.sbin.nmbdusr.sbin.nscdusr.sbin.ntpdusr.sbin.smbdusr.sbin.smbldap-useraddusr.sbin.tracerouteusr.sbin.winbinddzgrepapparmorcache201d1af9.0.featuresbin.pinglsb_releasenvidia_modprobephp-fpmsamba-bgqdsamba-dcerpcdsamba-rpcdsamba-rpcd-classicsamba-rpcd-spoolsssbin.klogdsbin.syslog-ngsbin.syslogdunix-chkpwdusr.bin.lessopen.shusr.lib.dovecot.anvilusr.lib.dovecot.authusr.lib.dovecot.configusr.lib.dovecot.deliverusr.lib.dovecot.dictusr.lib.dovecot.directorusr.lib.dovecot.doveadm-serverusr.lib.dovecot.dovecot-authusr.lib.dovecot.dovecot-ldausr.lib.dovecot.imapusr.lib.dovecot.imap-loginusr.lib.dovecot.lmtpusr.lib.dovecot.logusr.lib.dovecot.managesieveusr.lib.dovecot.managesieve-loginusr.lib.dovecot.pop3usr.lib.dovecot.pop3-loginusr.lib.dovecot.replicatorusr.lib.dovecot.script-loginusr.lib.dovecot.ssl-paramsusr.lib.dovecot.statsusr.sbin.apache2usr.sbin.avahi-daemonusr.sbin.dnsmasqusr.sbin.dovecotusr.sbin.identdusr.sbin.mdnsdusr.sbin.nmbdusr.sbin.nscdusr.sbin.ntpdusr.sbin.smbdusr.sbin.smbldap-useraddusr.sbin.tracerouteusr.sbin.winbinddzgrepextra-profilesREADMEbin.netstatchromium_browseretc.cron.daily.logrotateetc.cron.daily.slocate.cronetc.cron.daily.tmpwatchfirefoxfirefox.shpostfix-anvilpostfix-bouncepostfix-cleanuppostfix-discardpostfix-dnsblogpostfix-errorpostfix-flushpostfix-lmtppostfix-localpostfix-masterpostfix-nqmgrpostfix-oqmgrpostfix-pickuppostfix-pipepostfix-postscreenpostfix-proxymappostfix-qmgrpostfix-qmqpdpostfix-scachepostfix-showqpostfix-smtppostfix-smtpdpostfix-spawnpostfix-tlsmgrpostfix-trivial-rewritepostfix-verifypostfix-virtualsbin.dhclientsbin.dhclient-scriptsbin.dhcpcdsbin.portmapsbin.resmgrdsbin.rpc.lockdsbin.rpc.statdusr.NX.bin.nxclientusr.bin.acroreadusr.bin.aproposusr.bin.dumpcapusr.bin.evolution-2.10usr.bin.famusr.bin.freshclamusr.bin.gaimusr.bin.manusr.bin.mlmmj-bounceusr.bin.mlmmj-maintdusr.bin.mlmmj-make-ml.shusr.bin.mlmmj-processusr.bin.mlmmj-receiveusr.bin.mlmmj-recieveusr.bin.mlmmj-sendusr.bin.mlmmj-subusr.bin.mlmmj-unsubusr.bin.operausr.bin.passwdusr.bin.procmailusr.bin.pyzorsocketusr.bin.razorsocketusr.bin.skypeusr.bin.spamcusr.bin.svnserveusr.bin.wiresharkusr.bin.xfsusr.lib.GConf.2.gconfd-2usr.lib.RealPlayer10.realplayusr.lib.apache2.mpm-prefork.apache2usr.lib.bonobo.bonobo-activation-serverusr.lib.evolution-data-server.evolution-data-server-1.10usr.lib.firefox.mozilla-xremote-clientusr.lib.man-db.manusr.lib64.GConf.2.gconfd-2usr.sbin.clamdusr.sbin.cupsdusr.sbin.dhcpdusr.sbin.haproxyusr.sbin.httpd2-preforkusr.sbin.imapdusr.sbin.in.fingerdusr.sbin.in.ftpdusr.sbin.in.ntalkdusr.sbin.ipop2dusr.sbin.ipop3dusr.sbin.lighttpdusr.sbin.mysqldusr.sbin.oidentdusr.sbin.popperusr.sbin.postaliasusr.sbin.postdropusr.sbin.postmapusr.sbin.postqueueusr.sbin.sendmailusr.sbin.sendmail.postfixusr.sbin.sendmail.sendmailusr.sbin.spamdusr.sbin.squidusr.sbin.sshdusr.sbin.useraddusr.sbin.userdelusr.sbin.vsftpdusr.sbin.xinetd/etc/apparmor.d//etc/apparmor.d/apache2.d//etc/apparmor.d/local//usr/share//usr/share/apparmor//usr/share/apparmor/cache//usr/share/apparmor/cache/201d1af9.0//usr/share/apparmor/extra-profiles/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:38382/SUSE_SLE-15-SP6_Update/108ff988527a5e410ebf430fd63f6431-apparmor.SUSE_SLE-15-SP6_Updatedrpmxz5x86_64-suse-linuxdirectoryASCII textC source, ASCII textASCII text, with very long linesUTF-8 Unicode text*"sO˻P# workaround for bnc#904620#c8 / lp#1392042 # old cache location up to 2.12 rm -f /var/lib/apparmor/cache/* 2>/dev/null # cache location starting with 2.13 rm -f /var/cache/apparmor/* 2>/dev/null #restart_on_update apparmor - but non-broken (bnc#853019) systemctl is-active -q apparmor && systemctl reload apparmor ||:/bin/shutf-8898438ab857b9d83114799039a3c1a6674badb31621a872245dc85e1bed12867?7zXZ !t/ >]"k%R~S4)JJZNKnz0`{Rڳ-$wXM, ;2Lg|"j9s G6`x0P=\lٽEKb;m؄38mUZnd"55كks88ۄyPw % '! }ÁZ+S g8u@<؊/(>P,np4@=#6z&2p&s8q?=nK:<&$xn/XlYv2zP1sUk(^8d+DC u SN<>C6&ʝ@c8U୽U/w%V{zb[;}3!2PCH)W;)mh F*$aXO{f?n>`9m:M,wkV"|>WUqTN&iC+]> wQdžDH4ă<RMh,^Is(2 4$ZsowL 5`1Zz៟jYm+B``ey58dxnK_6a <$Xar+*)]'#jarDSw'?иޥI<)q|Э``fQÜ"ٟ*T$%K-%P3dtL=)%2\H۱沬Q:‹ɧw}݋{z"` 대C[K? Լl( neKOrNq[+^1Y:#4 ==#ZR-m9gGъ7-+}Rc+ 4rLWVUI= 2r<ER҅kO̠¤,DZL~i5}iڒ laϫ@tNX0TQ[`3,'W^~|!xXV:> Vye!(<)Yn4)$3˜I@+/9!UՍ{ǚ&,Dc"~"?7pxqS;7-gB~FF/Zݨ}ŴZ^K=-fl%ul!qqse `± >$OK&HevVX#=5c.x3| cڤR|/=+m'Uexg Qxnܘ9nޱ!ГNR>wP,\{1m ~^bOw2Mlm3xtw@3뚮Wޭ|嘇fVv HE&!.9(}$-m}ڃ+#9zjWi Y({E5BT@sK$p3?ӯ%%>ԙ';QsB)c>dda`bѻpK ,'ޚ@~dɆQ6bъ'x- KXihP"{ɜZd7*s=jǞF] %-ِU+A␦mEjSM)(M(D.Qe-dj]W͛Rf́~wM٩?I ]v^BMsb.6~͝&Qղ$6͠,KU$❱hC{z3/߭ʶOM%oKwKY qo]MoQ 6ܵnM.3y?;pE8Vq?/&RoUD7hey"0Jc,fxK)m 4ƪ,$\Nd"}mO!v< ^C`Z_Njcp0tyo[a{:3Un9K+zwD濶 1cLzs-Bk\Vʄ8\'t'P}xfFx^&~H1zlc<YӾ!5HbtJ7o`+Nh*WGW9gsrxG^mLKĮ +YAzN&: ٙbm5Ht7r7e}8 2 Vp <2B{3ȩ#?rw4ؙ1K*r)jmp[J>#;t{ ̤&RF1(1f2zj[M#Wof!eEtY8 ^FymbTlA`TJFڂs-+DC\8Nj 0mgrUF-K.'T,6>ӵ7\~H͏i&'Ng6( $Q#ӗ\5 Ix\`n+n8fH(kb$ΊdK 9ק~Xɾ܎CҊf36TǒɤNWpktTK>w 9[>2L#W\np -SA4'h V/ ((lP{:EಫT  ,}'"v=;1p<,aOTI~uNt򳅵PjRe?s%D}+8}|,|T2a>ףJ>PhцwɌ!e=+ )¯O _xWA0ݚj="Z.ֻva=5`yK1u[}g$K'}1ͨxkGU7`4a6?G+ZN)l3GDC0ޟ@ 4Fy;?zfcc&tHfJtʃ):s? E~;ԋ4DznYqWE ZK6!hʑ[8c =ПKv0+Q б?s@ӢY!,691 BcOmAz/E ~s&$p_+Ԝt{ss䈂!jQYgVUD[AH`dP}F>x5ѦA3-I'ev@!E iC{!n % b|oysT7~Oi!*qO_(\.>,*N-ҀڬmFx(_Mj6ccz!iORIJz_a=w=;gFhosN/AUՊb1 g qz3T;N3_nvkH5@ (lX $P{] 7eZU\vkͪEFOGc1}gOXYPo[{:_go $iݙwR3\\5[LygV#1~cᶴMZMg.R{\BV17rw;vecgVqdFD6-b3e sb@Y){I8Cp$R= f" Im p(jL!@E1u[w=㐣! ' w7@u:4u6=e bNon'%ABh# º&8/St\ګO-Ð ,]˭]Y["zPl|蹃%[m0us'II.aޥ?~uZ4eP&4qRa8gWOH4rfܫ:@HwG.@Cڦ~?H >PdB'Eb*r̂KpQ 7P\*Z+n3GJ) idX|#KU'լkB=.T0uD#`xc9hŸmp.Uh'&~NbjN"ǡkI]K0]SD|]HP*F9Ns~!#,fL;wbh(;bC`8F̌8M"}z([vaFJqQ 씱=kB'C*MVIJ/LCmVtCE!Nh9k߱c-tW(\ Ky5*K0SZkBGUe2!":-Ԁ +"p:Px܂)Q*=Dt}z#F.BSi$Ch wZ;(S:ldٖWX׎ <ʋc06C}wd~@~r  )0d=QL\%?Ǟ&@:ϒOE*ش}6C fU۬4V0UH#Jit8in@ar?B/O;Q4xd˫x̎=80fm}Fb/ETA6y9@D<抉^'#1_ vLtl '̷V"\hTOѣWgpGʓslq[U"XC\ax|׶ Hw0T>G#<_HwKt~~\$5H-2ڑ+M/_NbQ'U͊x.>Ղ _/L`=h& e#:&ȥzoi2^[vBN`B=m(Il{M&&xk'-c{CO,M'zb4z]_bÛx`b{>Wh~v(>wv_G59%-EԇEsKXbmMh 5 "]X.͛Hi/d>Hˏ{ %j =Wp&B+JnM?Fi b|hvD>W1{,gv}+q=U9j!}1{NPT×RleP+6-lqQlWrFPOwg&1 8!K>1T`9P'MNm{MV-Y`u= q oň>=8.XKdm-cTE T{YOhJbޓmi}-lz*UpEs7!6KT9Xc`C9MTB2p"b۾VpN0iNÀr7DZJ;-kw} ,C)dgJU[,ղ̾88umv] {KHWJJa2tlC! _](j<Źl^lN*ΆBqiԸ iȜ.tAK6-QLjwr*&Zp1B=_ 7F]}lp0줋M)^m6@!Dr- ]uI°mlu= _Rϐ3]rmB(q@yMV:(ۅ䇍uf;k^ǣ;ZU__\L}&yS丂Iư) M 3+u5K6QbmЖE.߼ :tMÂw7yǃst\;;-Wpww,9Zba- t{9NS6 r!A%gٿrښqL蠕5y82sI֣CT<0ţ1FD-/곃<ۥ%t?2>g@Q=[6)2ES +/ M6ﻱnt. OഠX$ona4}hRV#dJs8D)>;eTzUH읏 (uy VݸL{xAݒW9$G${ %u׃5ߥaQA"%x1OJFI"rYp@G&X9AdFZ*̃]v)#$̣ ^Ȣ!PX Cw-6:$sEYQr[*߃D)+N¢G,kk>_^UfクoHcinQUPlvP5ú'^5pzn;t= 1@0x'CӤyuAWT\ m/!I>6O5>YsǡDëC׾X  im!g6\Ey!%TS5^|y1HN=/(3 #r6vr_oR7On-?1}leuY`Idž"`_Cf<2Z/TA*;9b\]t[͘*J>ImKj8EǍIɕyߌ1\rFUuCaXV h [j蒵PmE$i Iyo.W>{jEHht~|0&U5!Ƅ<|/l:okvP--ha6 8o_c:MHg2;LDd6)7Z;%ˌ$/)^mğ4K3NoTE•2'e_G֊ױoAo.+0J4INz'.J1/" T)+48rB/uGNYtXq39i1.´4ӗWSH:G3{.DFLב9n!M lEiBYUCȣ2K' 4g{̃gၝbˣ:'*r%@e/d.,wso&.~5̿\SrE.zE*f9r͛N`NK̃)z\ĥ4d2:I? W&JD)O#-O֙HȔQR52.[n aqCqo%#C6 5NDWU(JKD'JТ!:\NNn qaō`#fKA'Ti\h@a ]F/@#fD0cAEI,x۷ |we#9Wu1)f@+}9/3FAWMh}( JD`"}.fQa^U5O2Yč. ԥqQNIΉju(E:zZbUGslXij'oʾj8M˫H~{䅚k4(`X!PA ת)yEukʖ1%p&d=ѩfqW檍*2@u5(89 D#7:c~Uh[ ÂrY0Y S& Ѐ|t1m:g.  Sg ĊƊ0в|,Q|l2ٰ dh{.x\6€2#U ?28h<<Z !dD۽i9s> >0ʨ7*|$wcxR΃˖`rIjH9Ič):P@Y cνUTдrd?K}Wkg Gbᓃ8}{8N.Q78K,&>-W<^Oύ^rn2'q<z S_R$-JR|0. мb%ss/Kt?ԓ?RCoo)7sYR^Xu%xM 3rd۰.^ۇ!g"vyrYek2vÈ`&?UJ(,yhkZlIoX<& eSo,Q&[U.mրk1U<}.06YDЮ|+GP>ejUBt2$t]Ew J5vBUV\Q3Ly J% e2{&ZlԚRX=!$y? VӢ[h0jvp.4oTKݐ w33P˺qpΔzÔƷw #Hw2N[)GΖ[AJ"=>$l,8C;%F-)_ &*8D+$^@H@"g2y[%0<8kS y239u>k;H5m,~){0u$ EOyUJl+&08}s5ZZ{seJMGy TF| 4|ƕ'D? +aD@{InuR|=#wYa;ڻ8~NR$E3 ߝK"{q"*&nzÔPE>}O9]iJTܷic5 рM8R<%!qqbgwP=UI1ԇHQDn$՘[{$¶\0XW 2ebAosV8{\>r /`Mk1D4$1&ɈW(mH[>:+1nBd"&k|&پ A*aq0A1?Nʃ:e xaT%c%5|@t;08^P42w "6 |׈ja_fwP+-esp+a1 -Dn\).Qt O~F,ꁍ;=6l]~Ę5L>y6El="̆?.+jcz,q?GuU"r lYP:x0wĸ-KsIy^Yc4|Fܖo>!eƱbQ~#(]$oE |};8S<#,b͈Vv~%T1.83/3 $a|/uNgBmZ~WGʑ$4Ol>CD,rdwq#*Nxϩ:}Մ>{;jH(x6yHQRt-eAnXa2U)L@ jf>Ue#bg fah91nfl3mѡHnOv+&bJTz9f- KEr2 b59 {KpΌw,*h%^t l[w KiAis%Rd#M-ȋJknʯ 6}+fk0!HHrӲfiykى-PP6y+",&@9FK^ӻsMlD[{j| ;+n$d]=@!> PPu]iHaɤWʑ{'tcl߳5DEq9黜-}8[nwv>ɥmG'bT*ix|n88Tfo (nf ~$h}t"SR*WI0MlȇXG>2@#Baќ W4݂܅1\"P s!̀~W3~IԱPx/\ݐ^Ԭ$6&iX L#rj(_vOD#SWT|[d< c X-WYFkӢxVzbr\fofaܟg-e8/Xlf:%N;fRJDG4JUPʁ`A`wjzȓ&5P{B $+&NhrUh=N,.hc%K)_v5,dJB<T}*=hx@ ys+(Na5ձ5œ͍>*j'sRm9hg|n"`Vn2ס+6n_p?WфSYY{: ݸtl*f,͈'XmsS#EBm[P~xp.YrOƭaaP3v7`%)KsxD Dm:a :^Ÿ},'Tjw2u;P&M9eAj(q9X]%z*:!;rptdTL-8ʝ}*E452u[/vf uvM7cWj ʬ|†-Bwpҿx'p1<죃}K}ludkdHWxR6 Z#~)dv9.u |^eѪS9ަf 2hGq%:79 q{\.dDyt } ~dP~1w8g|M%qO3TYhTŸEIh\jl+%9@цpx]U3oO! 03Y$Uc ;m~/V0^$}PR;=zuPZ0D;\-.⦀j3ojOxx}P$O\Tg3(@_njDzR 6ׇ ՃTr$&v}=e'~e>6>S/=1 8/ȳ'%$"? b|#M^׀!$aX@GW/ 5T4￷àm/sƥ(~?Z4$p(vl |.yĨp_,}HdlY#\~r;uO,L.HrM#Fj\]w],;wXa/Na)2ڠ{Vڂ-LAk{ mSrй*(Oql.BMl D?}٬b6;[|ckZ*vhHfE| :=KĻIS?ВeQkUݨ}Hd!R·fERܰ>p0!TSqšE̳ JgrUįBL[ݒ rV5`M/ (LT#oQjὅ\`:gan4e1ᵩHB-ZXXҳ䉽<1xu3JZݤRv™ ,.=U ](E LL՞ҋci'p7ET(XOsÆA75QÕYq5AL]Ž4=E(Z'FxVob`:WNH;+ xv |"ծ_(,&v6FoYӢAw*iA)/}(9J3\{ ;X!tolhn-a ݢ9 `?umkb@L 2Pn%mHKrm:Iu ňMnK&8E HKsZB]0)('Gn op8I /79voK! (_ /qb-r:SP@pJBta>ŀ";֤ɝK}ЗdydSHs4owE}5-)g>^<u 3]TT̀Ň|Pc6fkSm=UL6$*NҊ?.H[vQoة v̿FG}i;DjM7k7ٓ<lc ^ZMx^X)+^T$Y\7.j%<ɱ%j$^Y$퍩 ):uEv) lZI?K+|e b^b|dŚJO,ciYE/ǷW4?,հy2KbKy>87=y+$م_r$jRA0ώ CWVZb(|%)D,O%,u$=ᕩ7]!I*?a=eH;wwŷ_u|2 5-kFP$bU4K|T̸H婸sRݽ߯r~ɓZ`%AK +T zmm2^ٛ(<`0ȩKĸS!2I t^_< TV]I_jQ:,dq¾ML}HQ&k`23G4 /CEHpc3g^@=b!*-t7$8gsL2Æ'~E C/e~&P- T[4΀БyZoi"*wlL0ౣqaɾWܜp|-Zz~aVCCN8E[&j1gN{\կvW_4OF]n]gkG-ekeyn`{[ BvD #, M12[;=)'5ԟ6r!]R_B&SlD߶h :S0R6<%6mPiWhac?`@/QY|Pg {fv/gr m;[!BK!I䨾3LMlw5٨-u|$Xe0eT~ I;X0z @e09Oi@B#2s7B{Tj@rnN9RHtiOL7K _5m-xTk^LBc)PɑƲnw1P冎ZAh(yӦWC])ƛ{3aaztBoƅzQ(Di{S<#j"9#b]O.By&]Ib*ƦIE֘%8tӨim厢!IWo'j_JcM^ĵ 7)5V]g#4^ $aёkU.g}٦!Yp 2X'YNt6y~Sn|>5Zi: Фo nF,~j;0F؎,'$S_?)5Op2)YKp<^D=hds71eڌCqK`qP="XMiM'O&H<!^7{`UWj}s<ߑƎ:t @ܖJbt|u[.Uaxke ++Ql+N&2㇡O.Z__q#2 [%F6ni?ODh,mZ7i ][2MdF0'\mBf쉄t/(]bѻB智︐ʓ`UYZx{:ќ 'j7?sKwgPdbOVF5;A"Osj)EP1@~K>R;jI(UxAX= CZYv77Z9a|3Y Dv}i+3Nܠ. YhwjfYA'\-w]l^#V@e(a+_oi}B4cZkص#j F{0h=L/Ѥh 0˰4{W E=<tD:2>*=N RMdv9ޠ9 2Sjyb%';*z1PTWA3YΣ{P# 1346 ~!n|s~cݷpWw~ILK,;F0),U}|)5^ꏐ4\*7)pğ\=kYZ2 h! ٵy<F 蠆> BTZ4DXXuf4B dgK1`C}m7 8zDicyЙGфx&Ytǂ wꟅU/̥fJN ASA'~\IkM(-}]ZCh.^}sBQ}x,*FBh24kد?aoV= PY(KL7>ps/j{'SybW TԡBr 0Ч1+r/F̪úUqeB" }xy/ +GXHrR*jT?O0?'~? ZQ碌PD%Oݥ(ས[wnEiئ@k:XҤbm"n#skώd2,=\qcC ^h[&bLKxxXdpcU{%N;=SPP sad*/֐QH9&'z- djF ~}IF#9zB(J -=dfJkxϫ̝jցO6&GF~py܎C(rfii yJXFa+H n1qGVFP;ډ.G`?Dacivט&Fh 8 mk49c^XQ l|oqshED ,8A=< ;UnR-,QeUz~b*gjkA'Zy1>4ځà`4}PWٍ )ciJX*OPik^,7ZJK:Ry%XWg."k@E& ot@U4m(zy\y$I5>~,L*8wX3iaks[h/ V;'UeqBqۊVQ=*jp{󭮠*_H!L .)7UN [`G(_K|80nj@H`"жy<¼dMGɭUvlǺp"~jTWAZ%stl Mp ny8vs} R:NsP'Q Њq Dѵ߰K3pu*δ-p&2Wi3WNA$6ŏ@n^ .7ލ?jQ2l:|$FF40 5/*\a+{w?֞r?l9HC[_)c tYgY+ !pK髼sCUČxK<ԠY.9|@K?p\Lw#Hf+׃6b3ؖ|fM^_&9? s8(\Nl#n]m?Ws?'J.2,)Vއ5x7{Gӓƺ@-QY2&|4s,ԥ|q9L4@tә=NUWECoq!Q f |r_}M[7: O;$0{0csjyvɟp^Dn44woO7+g+g8Ui-A; *3sr&8"Gf*bRu""|NbSti/r\ z9Xϵ@cKΐqIS>1[IJm3xF8퇟g wcLPZ_aΏ<GD{-z:EKwi2PhL*.͇ZHsBDrDi5o^sH4y5+~#?i#_8TNre< ÍZ;)SgϭgL!}C&O)b,ܣޅ+ku* i$5"- 3$a-چ6K}:JfRpV{Vq8Y?h#6 کJm3϶YA'5fBѩKep3Ոsl 3'y@ŊLT'KGnL-v ڞ,~UW~0rÖ]-OSVHrGV{XhRBD&gt9TO|gfBwߩMUk$"8+%ؤZP9 U<H&R@ 8O*tݷS$ZMIwZ:ilon?5]Lj Ue)NĘ&GFR}XlXzOOQ,vJF^fFX =i;}~3|*Kym;X =mT^a}77n0߉VœAHPյchEdXş Vbgc@p9XKUrZZ` +3dS*g!0p#80qҞZC "#(qV?z\5^ b9N>EfTs i@nA C^0ϟG^s+Ox[PD} )ݢ|8ޅa1Y&36/Ӈ N=fFwjb1\cS,$u]2r=B=ΣeLdIF?4>xͬXd٧?Y+*Jh.W3Ǯbš1f&r?o"|JteqE!qw*frζFv40RhCK]dn檽]?㋄uk(@ ws@v 2R"}nwb/N '^|-gn3%>׬ 6 q9o1"[ց3<kgU&O<(8L򂒵>$G'jx+Jiʳ[O8}j'O>kvԊ7&rI#)RVg 8=|nCH1'{+& ʓ}H01M7!`mX1@tqp[ I/jx(T*HZr(/gj~6=5sT9͇j/O ȯ/5G: 6TT w Z={S'GW\삊F4ID1P0g W `X.?zQ$Y=ԁ 1$&3s7SJjK\1dLΌ,Etόy J7 e',6aZi Heoq=NyCˇOd׃܈M {>"P3K,@ipH-|' {b/8/~TTBxSxӡRM/3Baµ\I}r1[\)uQ|trS=RiU$AYrJqS&윴KJeɡY1u;LO]K#K&mLeQ$.ja/n_&~*D@|jV[1V$<f||XtH^#5#3r֡0S'S) /.^_Mc9.;Ќ~do--3OӞa/+|S%WӨ3VMhkZP_h/&U=;L)jOƵsiC| *n,(n^ 6V{Pm %j hbE4l0z% msNB*Yo{Z4ou{lmnwy%2kj]2wyQGFc^Kx˗/C`?Vyb8W0}s}H:QjXr$a mJIu#8 @tfxo(?\z3 ]珲I)y" M/iBp! N[ 㑿1Xh(Vn`,$ۥZm?PUU^ܧ=0VZ;Aiv7Ϧy:hsocJz5C&i!VQwy"{ GO~~5!0q 7}XgJD ^bpgZJW3 `j+O"wZ`X_6imŵDbkHuMၳGBgh 9S$;z=mYn¢6r7.TU9] Un`(y+,IִW_{? lۿDmC.V`.JyceK"Fw-lA7OasV>I t=Ǖ׊~L`mM  pA{QbպyV 6 b1r^=Ǣ5$-ձ/P A=i5R):D8<+r¤EG')Y{7% pr#tMjP,[NNh6GXӁbxSn*h zy=YT6+*:jh]Ǽ k$Hg_oJevYYAi(-lr u|WgLcO@6X䩄E;KE?/_G:F(axOAi9uonPg;K6ie&;وQ6bxP]/W91P>mGPB@71dPbkI}?%i-٦4< k螮@rbL*u ^|K5ncpp.iJI~!)6P*"t%K\ӦC/ h g9G&^ ح,n|]lЧx1]I~2z%G{kJf_ŸM;\Sa&e,4AnYMqCb<rdU:˫'4-f=&v@I_Ukg4+HޥNmk%aGk5zoȝCe[zӈ?7E73L;޵^O43f?E2sࡋIC $!!âQ).yˆۤvaM7$>Hu@Z&4^vcSimSe}a@&? e퀄)Tg=JR.u.%#뀿/(25.itKAS ~hp 4if{^q'@u$aLI*l~}7Zmhf ![{)USṹY gW5?k.t4ݲF8|,b<%|e[^7d58Tz p IW"!6__Wjslm<Cw^-fF<\[omƬq @aƥg_ >oǺ :5Hԃ}U\&9+gJC*>X]#dP#r!Eh]yrBo`$@xIN6]觟y}AѾcݤD.>.Z0q2?#F9'pR!4+38ˆOj7*Yq3Ao2- iH5a$:Kv;@$pW7H&UG$y<{eWknosYx ʧjM#jI|:wM:Gt9BtLrv.[;uZs&r:اc̞)1@8h"= f.C:s^* g9d~Cް7joPz{ jxLYߐqӐfO[bHW[~sRt.ۥJVQ. !W~WI'%[*aUFGٿ&_*(ٛ~+g-`x܋bk U7Xh-a ivغGvMܨXN9)#A"1\GcJ q6B{Kqr5RMBϔ@7AvBfLYJTJ ?dp!/əbҗ@b+DjJ{= uS"(b4ػ%rh7ׄ wƞա))Ir/c!@6_yR MG(AÑa*T%!3rV[v@}"e"{᫻& !t;5e"(j+_}w W(&@t >U8e`q 2*֘ϰkg7X W^Ʌ*42E !v0qs& v'~fvϏ$%4dBgL 6*^'N{Aϛ6gҠ˕rwr5Nq¾4{=2/jԱ(Yw>R=#Vm9Яw^J,@A/^=B|CFFwy< -TY_6WJd[L(h糼zN;Jӕ1؍c;Jl`gQqZF}O*I ӷ*TAtV|+-^Ex"2j s"~El"qSe ;o?qQ$eYP{,\}%/z#1 @cu!k3 ܷ֛qMNI1 SY kU&6k[ͥ)۷Kg=+3Jw=B;4a{fHz)2ґ09 g1w8ڞEV |K=}u"q)$-X(DG״HKX+uq#ww:jz_Ǧtfם(H/Z_*w#j֑-]Y%+xk0udC˾E`a$0Ur[ FOq&:Wf(KV"҄P_;*]b:8'iF]ViL4a@- w2ϊlK+OR]:rb 3"ʥxY#=]t0EGOf}G;]A/)u*g?@%ۄ#q\&@f#;Εmq}l* 6MufŹPV}kS #b]r -1CҲ\ZCUΒ e k7)1ܩ`Ǒcm**9k^TAa'2rqMFൕ5(Q@:ى'Z@'eѻ:ITG7F9a3Zr*?4=z1Ïex%#2lEa{/\A+(Gu1IXڸ jc;8[O -Wgof} 8TEC9SaxDt^#j9FGjk -K]K765!FA7(i10JJ{(1p ܘ+g c% pAJQGQaU3c0-;m*9BH~mZyY1H؉-LiUi5" U/O2ңQhhL %N5އ[hs8IX(Uj(39Ie]?KR,G aO!X쑓Pwtggr˙Y-i쩟.,ALSu)L<*~T\ nQ2ؗUZ W4aɔ gE5tc5NM [9Z3@ԭ=ND*j|W HO5Dt8hij$<,|&VZ>IT~, A5b+7:Sxo;@+QI[SQ9<(`LB<18?8u]ܲ)Mr']WHK<{)2aWAGĈ pzӯѴ,ꂷ@꬚\L,0v \RTM̺L~WS֩Հ+q$l N7 dA*nxRס jޖ]JpD d}"&D`:Gh@fnh@g>C̽V)TilIqgSqM vmhx8wS%0M,":Ó.vt^^q!J89Ϟw2MoãՙbP0&B<2vFBJűb0~vjKOS%́$%*&5_- 6- )" QHo2.J.P{D`Z~ SGV5M?Y0S֦O(u$ LvgVW"\gzBv)9Gy9\0y;9}pɒ)eݏ'uLU)tI` SWXfU54^V#Xԉo[84 iڋLFB㍕˽ŊA&w}kz&LHܑa^8P#78g-|z#ݛ_pjQwI7ཽ' +TvJOGmw_̡T_Q9hU dk :3Xھ}oG5(XkrDpëfq;n;-B4 ~x S,'1'4d#Ƙ/O׈pՠUGL||a~[" >L(:ew'[XIȸPڙ)GEe^A?XuMIϲ 3}\[cJ3+'}/Yٵu][rcwh˪c2(@DT/LVL] UF{l&A*QVqnFZ$w ,߶.oh!ί,sv^bTOZE7ԏrܦucu\_Buz 91"SZ2:3ud&2Nw UܗhCVuU1[2Vh?Rͮ/uN0^}2yPT@M.~f!^S8lM|`_.jl<ॣ;3:l5&bK'tjK/!= PS!έ KOy/)ELy)! =on u/ʆ'~78co//3W!^ t 8B\Csw2Nu"@V0;11OHM)w1@%\oC# s!]o,xVSFᣱ:ȣܕYWˆOKԱ.σ=.%J}&@ n,ǁje?E$)l2:F^e <%ҋW"W'sħP)E $*&&طWO=w拶|]û2`4-7B}`a25CW#yh[vkL|jvfSs_uc)8;5ٸv6UZT;d/̟y,2(%s( .Mx\,/g;\KHLAFL mҦ9*+Z0{qaKH426-Ǹ15ƿzTK}MZsT Gg Div cc+Lh'N>` vwt'}Ep(L0ďO*AIpV~O'1o'Jߝi~^RnKLnl|.fN#&F?| vgJk2)`x|)rK! Fpڔr 쯻T _БbW S@i8v*ݐnnxVr#93 t4 r1fVx8>gc'zl9h`AWNw(=ˊSd nJL Ev^ VkJfM*Q% Pc&S!镁Sm4 hxǰ"Zs m{؀$LrCl&zFsMJkpVT9!M"ž{J+|Bк,W`*Ɠlov'?M "<IY A֘͠+_{,Ssvon&"Rg)-91K%BB" -pZK58LZ$#>ޗ2K}@ bUZJ ?_~H>Bʌ_Ofx_`Ї>Eʔ`>\oYknIi;TvRTfW qt])-;hs_)4~v<.^,(P gԄ&=Q/77w$PW_H܄dhd!軛-:PcCuyd3z =mr&Cim0IY`¯ٟP/3?2Xrkk?궣F/zO|Y?>霡;M "B. ^?HY7%n}qj:~5U<+?b_{ML/>g{kT/˦ryRbL]\L?>X<Ȫhۂ21=ף+@hf`f_ !ك7|ܖbb!XR\`ү9T"WD~'(BG˧ռ@+W蠤 ȵ$%1?4=XO5~^q@4 Xe:GlR0 ?4OAԺyԇ7] 0oڅ.T}5CЈL;%颿_wܺ]N3&u)J{/;^BSip!թFLn y>/B5xK#Yu(8i["0EBXKE>TCc[RTJf .`m8QbN+fu)uh{)?f3rjꖵmc:Z_.azi[)ǝ*@& Qh 0/b:i s=|&$ dUN,0UQo_l76Z&+&11's )S Ȣ[UžaJW~ 3P&:Q(cy63(UK$y,*OI 1zL"7 1VbǡaBqه8/ DZ/tI3S҃'A7w)H~@}h#8==cvJ\ ] WE+{e.%d]@q)Ni@nCDžG5|]O ]yR6i3uZ/oU0=>W*V7T&ȮN$ܠ[բ+kw(ۅcz`˃4J0Tb#$M=\ײN3"Ts饗mqٯ7i=c#lgŬq&3!*X\3B Y.AaamiS_GwjwxRFl\D,[x|"C[D:ˬcbMIdF.bs/ 67x3]5+d ; KmWހ2H|q,e"0mL^(y04<[PW}Н8 8vM$`{QHP43h_aT+p2bN<}|'܊?@szv&9}͹֘Gli+0> bBIY: K}6{kF)uJq.-n%1UTLfS7Y ro'9퍙ƀEwPV!9cr9-iyEIEni?f^ǯvrh^14daO JTƺ0?5}rURbFe(N"r|1-7F&CFVANèLfNhNx33k''&B&jlT`"@&i!CT-}"Μu[O5cOCL++ۤ3mנ;Tz w mDž=$qjs#ͽߛg u$@bvC J;JeRFiR}bqzQe;9U?SJl;J]j'dž90N_5;/7DR14]J*Ɲ#)_Rb=yM+CS1#ҧ~nuxdʲks@5E3Ê݉ }v%;b;0hYA 8xϳQi!7oVY7;z1ꪱΡpd׏HPa$CvcdHn-k:I CbxCBfZ"kx`;+6y1_{qr`"`nV~~_yB 2O3B /Or p9˙X4OiB1b}$ UOD^|At$c-XAls m$rVG]v B3Ȧвϴ=R`;ÉtV$2p M\ ˮ*6bF5FG9$NC3V+6M+ )7gTy#e^(]yS M Ӓ(|\r3ڹ*g J" VD'VaG53kF,w&UҤ`P=[NFNR6gOh"lڰ`Shuܰ[m[PM"9_>ZTofrխP+PU^ĕj=(ddTQN5L E_AZ8e`Mnj%0D̙̎2(k`]!/AA)X\8V[At&̑gʍPkQp%zM@76 SњmMƢDgOr{޽5_tQ}I>HLp0Na% rI Vy#R _j!n~Rsx9'@O9RP4[THmbm$M"Ty: 2na;^+NEҔKgv$7q֍T3AFҧ%A pX޶&#;|Qe= Aj5;Jg]7kgrE丼Bno Jw Bs4!'eÛDQ,K&aƣ"=b,I3? \и=|xG R\u<9ʵ7n`fكΙ1|ɢ=\B/v'#R mJXHA*[zGiDm%W6=TwS*mc7moqhX*.7ϯq<~?8Tnט%ٓQ̣7b\e`Z00j !LD}@ aOwAlU:g+?I^Q >6_]bAa2;# A.z>曢F)yjxs{%Xs{_9{ zkϲʙ1ݔ^`q'|d?#^ϯчF#LKi^m.ޜ!T!i As<xw_~0p.]еtF{rݔS:g~_V+J+9G3 oE:Z#槅h#lie~+^56EGwU a6T5l) 430Ne}4`+ˏ*zj8ofE2]v n r~HSʚ#_V*G&%-/BKE&r v%cV4"M mm9 7{^NA6ws?~^/0IN;Tu=)Q`*&c.wz{24G98AJ ŕT?RlI2,yU+1+zz M+jy(B)HhLD{O3[n|T1ҌKsBˮ N˗2)*o>8wEώ|9"t|-n?$?)y 3ї>*Ѿ eޏU _x:Br'y9{bPpKH/aW-ȀYlK2[F:kzZTx@m2Q0neF5M!UDՔ#8H`fZKSX-i9]Eyd2rh+sz6hP/[jey1܍#;sY8qp 5[r-jeUy޳OޔfHmBCC2$31qh,q'9]VUyiVemLʋEY5?Ú|´esocm pqN?{~|.x qsIJxQ.L_Cr\O~#Ch{Lo_F9 iw\_^ ȤN/_QΦOP8Güх{v>XA6EBqn;r4Jyk-z5MPZ(lXW~'k9wɬQP>DZ4x-'%t^+5H@.vp,mMGDfRKSqs}"e''F2]\=^z@# B kf84c}S²,V5XlQ82/ld_?tNL=gE}~wܠ,2S|j r#!"dik][g'[ 1)qk¿8ߟ/DlAA)ѡs0syהm|7Ǖ ,$V.*eJkUkӯB:̘桰>}@(r,є(bb70v2N!0\IeX̋=KWXylEt죕7@Qmn>H>؟+NgiG! TrT?ݥdeU)A5|6v(bԍ5)Nu0jc6)bZYV٣AT#DH '(Pbel?dޡ~&)'yq%t;Y, }ZQmOoW|uPL,@F09iQ!-h\ٝ/؟W(Q˷<)Bg5Q %O. L3(̆b1ӻ', V#8R4V1)/$o'XKÊ#N/^M.D8Fѷ-+OBG*^9Q b[1b:})gmY9{@ފ"%2A2n׼5|(39'&S{U!AvTJc1tw F_A:Lt֦FO|1"+M6ٴHHz,4$! Nz5쾖蒺1x4.>xt&m#&zEZa֎xWIMRwFꢜ`Z ^ ̸UޏhU!I}} l,D.,oIno?Z5^/4o|b~db"2d <|pA;xAhݣ/9 Uw'B`w f*,U`<9Am )8 7brSy@2P-za 5i+[_(eigpް3NʭS_lW7iw#'_hxSѵ1TɊ$ O 3'"m ეZAP:F$_yf(ýPГ} %ҟ7`noy0{t(26pc5;6;OJ 1UT#މhXI];+83%>p!.Lz67N'9"& Ver3Yؼ囔!IVϸ͎wn2S|$dwn_Eۇ 1E "ƤQ=Gr{.cD7-8){0#@Xiy*靅l e Ip7ˊ47RS@')t@z옢50ͷHpƌ$m`dN>tb&ij֪[0oMؒðޱ>bCcX k ,rN%̓eq|qӄ7WM85KU2ujcQ)&7/[xV źM TSH{y8&uo_`v@λDIXJ1FeuBsZ=TY1ڒ9RSiB;p@i͎4"MS$3Nr19[S"KjD_!-%Ֆ4L?`l[(2#e *(Wu $|J\Xƕ.]hxrKḦ́磷 (# 9En+Ŗ? Z'_2sceoZ@@khP__0rRne8I BNT̙;fc$am0ޭ^&,v'%cҾn^+"awR/AwxCҲL>z0nfJ|EDzmV=/+쌒'D*zuBmǤ]  6LH[D6;U+(}X,c]-xԑ$2Ӡ ULZC xb[@aQ1U%̑۔y5[k2oӂQ0[ۤooy 0́t XJzE hzw+<.̔?ƫFXN9VYw;"|1ȸUu.@kHoQ&`d|$4:'%g? k' cPdAdY|@ lOd $rb+)p%qNV=4P+o`0rm] ]XequQkhHS/sSX}3U>%bTZM p/z hq R#{Vick_è5~9uHh{0Ŕi9g.obVͶ[`ts>8ucNF^hĿmPPC@ߧne+ҵmAv!gLz k\ i"eLu,ɯ.;b5=A'_b J!V"pH2á_nY;}aSuIJ=pWEĘ) iCѣ50%-~(ިq0iǩB6\gNj@ ]I${ eɒ>ziH#5PFV r4.3~í|SB\tof lдCu#I"1dV> gݎ&5)4RL2GAUމz-W~;bC'vyH*>jxޡr':CSROJK; HÛʹAq^lVZ3Jlj]VAhۋ6vE-R ]EcqJ!)yFpL>]X2De zhH'^^"NnQP #ޑz^ۏCӦK`6:yh/= F)Lv EREej-#(qn>`gg?Ws+vCyhr'T+=4H aSAs ̅cq<\mg`kНntVFbo^&vt` tʥ9>sls +)h(e&yʋw1BO`k@)pb܎눾8 1n\߁"!#*&~80{t /\T&v0ɔɶGi HcpSZ)K؈|{E{_ɎFywQ7bEAqqw=0͇~FׄAm''b *8>^gpSg ) fke*vHxW!@Kܹ\dkQb|?Wnv8}S5|ϿܧX yݘ`3hDNG廋-&ˇm:o_r|QUpR+q~n*TV7T׈-% YFĸG|?lL="6XyG=J2;H $K ĕba!뱉ˉƼ`p`^?c|;DrWܡۓw4Ucm< ?d|WnY,J YBBN~,%7=@<G{"N_@i=aai5gO4_E4FتJȽ 7Й_ )Z9_&1pb(?Nv)uwh%W(mů :87`㎇iq̈́zuyMpN}cEIL]bkP(e/lLDfPEjqWu`HCJPH}N!5x;1 zŧ{s-~')?,b~eFʀjᓜߊƁPIw`Q"(3'L-0oce$+l|e,|\S@wvhWQSuYKO;R?G-5WfŦcHZQ6gvPc4]$\2@CGVXFݟ ;;w˝A|L9뻧-|! hhф7f KKQXtGLBmXrWA;.l6ME:,B+ĕNlR%ىYh7^mN_m_NMOax17pl^5lBT48~9w?qJDhҳzN 뛗GA_J oZܓ /6e<#Eϛ5m9hptuI0}⟍tĐys274yi"qo}9k2p[Hg7Qs 99M=/+LB>^%L2qtQ693&Vuy|&jK *45T聰W%UsH!amQ~9~L ACP&ٸh<{Nj(_0IEHgU" &Yl`=U.Y؜Zʵg~Jp82r*mOR2c &KJ#)8z]\ Ca#ǫІIQb<zkQAHDQ41[x;YR@cjҜruo+m^rG]uڎavgs<@}Er0SPPذ r᜺ڗ4u=!!펴b9(ZZ@Bj 虣~ѱ9fR 8 o=JZ$Iſjš\μr̬Y3ȞF _;U&˫urՑUu#'c<4dΤ,&PJKUPM^a Xjуrh% {GziۛT]i-.ff;v7t˩gI !4$ zbԴux.vsI15:9%9k|n_zqPܴN!Ѝ~həo4utauDRNY~P8Lc'iȈ=_0, 7. AZ;q?f/"B ݅7۟siy$FmQEz p"Z PRtOCƛ9d-;Jl 6 P׀7`_ty !89c 4蝁I\_etkGūjbp X#Pe|cHЇ0'M P?5_:0\`b/k |9=DEoo-Ś rWBN8>i+fX),܍5kA30u(1:-Գ-zB7M tMEoOU㊑E 1 O@`5jL- EHO`na(4N *`Ƙyo! wXLN{1f@qmP0c=l D2T5h3ҲceEl۠TH~Ks%gZ#}w@B&D^awFj b3ghY{xxZܰ $h^"UlJ…o.bLAUKJD;ƞE̔hW-q1e/<Ù0 DXZ#9H3e}&!TXޅx9rH䟢-ȯ^v>!#Mqca_70~2}ʏǼ +ù!>Lrj;j2=xgk]:d\*ة!^,[fp_uL uK=&^0Og.)rE*RL[>~cmf:f芪]T AD*Ѱo"`r avq ƺJB0ZRT{IICxFc+u>> 9-2?zLáJ8_13Ь/LwaXοL9a?J}Ķ=HH*i-;%8F׀C~vGM uϳwq,úIIʺ5?NגJ;b6.C),~LJY``Gϣ(pDybmplE%YaxW@o0_PXaEfkf>J.s1,m2QJRN$r(^1]cz8rzf c ȭӿY@EٺP$C؋Z+H@0#;eL1JBM[7_J{CA+=+O`HONl눛I텼C aF],vazQ6:R 8"dT} ~;МMwE^8aez.!PgT;&tn(M23;R|XC.@ZkDЖZVϫA3l"sFrD\=.VOܟN3`*֨Al<^s"L|(DG--9@ÎCVk8=|g=&w$ŞǪ7ĹY CzpO=zE`se>6QL|#Rhٓ.꘱xYi#j@;6=[fC. 3rǓIMe̝@ wUk/wQl}x}ƣ X %4yGiU zﶇR"/9IyBczF\qm(kR@jA*ݧٶ Ag҉.񾉦:F.AJV-LHIIe V<) [ .W ̴v1,-ocI*E F8qI0})0,̨ ~zc-B`cn_(+(IR6mMe]_7-ukAA=V!ztsߜtvrbsj┧*lH,M2r[^`z>2O(4LoNm2 _4U( :u>;u#M&+Yf Ρ>R–.?O'n~xV!_Z7=U'9Xt,%q4쀪I[9雅P=vHJii+&AUrW ZcHaR  Bqphn[tmhOCo3 %iBxOrV;2XsQn+\[Q0NZtNɏGSJ3 -vTJ/w*VՆ o6)pJ &e[Qy& =Z$ Lڀ+F|.8(/|*-jd/Qdf`DnɩEYR$d ;X>lփ$iImC83]OA{H'Kn7⾬p\'ZϢj\gy /GlSGڠN a൫a a"qls\gel!$eocY&94-q592|5zjiHr%ƇBUG%cuX'Q#Dhľکnvo\s?L57 %eq q%Doz0>0!'`p=CwϫG|cygˤjxE3jmO?$4gK~I96qp0C< uՈ?SIcB@NM[4k[N-.Ѹ=ðabm6үktZSOwr i߱i:hg.*Wi(L+$ Ta7'Wjxف'X}@- ftp/ЬOEVtCh<8a85,ZIW[9 Kvz _c&doNԣWm?O,a&%Lv2<'R`Z:x%&oUro,բFݮiw[MӄܐYc R['NMC;J>P$=SnHi*X]R8=[&lY&]T7W/> !7.ueٙA䱚edmOuSg oF Ad^a"' Nxoz^{yi,ܲ\7_Mky%B-3$K%_g"{<܈pFխ.)wμ"?Ѩ)*#zٔcXA瓝,krkι4@ie|_ГS (JDy4ʇBX#ט`.r 4{Dh<`]_r=Hrzѻo6WɃgAlĦ)3NZ,")8gRM&Yz;ROrYe&[̾r?x@ѱQ0.q޷Ɇ|#^!}0;:Cʵ b[pxA1`, 7B+u VnuaMoΩ͍;̠dc.Drε!`JMgQ5͎`->zRFgĻz8#-H'Z4{QU9?cqBVΊWMV 8\r*,n|K8Q3&Ƶ9%&L<%,DG!'rՇ,Ke }Wh4-_R;W͔T,QT՜AB6Ec(e-NjxLTPkd( B}K p7=@vsLznv|1@dFͳ{Z,dD1-ֵ8=W ̪0oXeHƭC 95' < ){.Z㙯kU&kδyjC=3nlqBO5s: ~Abu Y#؈ƯڅMD> r azk1[Vq&BUP7̡֒!គƁ) -#FD{e.f%nk};9ksLP"$odSTMjЀgںi%~kx.mv7j~6)H@g+3iR:9p E4R8^_67)K&k2v& L/2&o9a}H*4X}h4I5T4uQ?pr1; AJ;=qe fo$Ma6Baq>c{ꜷ7YrKk7 gOBbVsl9$S(yFPۮ,ui D۴Ȋڳ(!a#LFSr8{y:5l^Crli(ɦMYDSZKMYuaǿqO gGdF6-v>c!J^dқ*gꂪC.*`;uf/x`m@~< 6BUWȇt\1 ST HzUL~"1ğ>Emw\ S;aO(6 Žt-ޤ!O̅4vx*x{Ij4QvcZ4̕J}(Rߨ$GC!f)(b4Zs e#"Pq 洓9 __*?ۚ_L%cC.8ƅmP'e"[iL_xoL8M0 P.l4v#,n@]M5ZH§Uѿ45#M6H%*7ΟƖF0K͒Y ܌vČ$6†7>}qht޾ (-Η }AY<0Ʋth>S~df} 'F!Y1FQ˿a-PusQ1fƫ, 57u^nq`ceCG(PKkg[Euθ :.- -\kE0 YMDBȼ1QxNZ9Pé 8"l!'{aue>JsDT1/9 ^~i y7J䲓Wvp|gSew5O`z߽l6 Z̪gvah> 把LjᮅMO[t[P6ìGl5S$6m\RUWVKFi`W+b\yR2ɛ1*!ĔPpA)JB9g̦F)@Lh U+g1"jd^WErАCK<,%Q$AAcV :sMr~oPTy rxOcO2(B?8ȀC (oB`P;D̯uƎ̭c]I̳KNf^dmI h(!UJqEZCG_RG,5ŌjexƢ 惡 Hsg ۍT&,"xާKIŔDGb:P!IqٓI9QC?'#v x{ _</a%+a2]>۝f:Y1fsN0COgJAVB !K^KhspSsj#3-puX3ee/9tGC}bjg|QN&L"/WQ̜=W :i@xDA ;z|Tn\Jp\)苘eۓ>KYY[<,4 c9x'GvH˦JI9C,/_bWs X#[?EX5?:2^Ol_C~kYpØy%`'M ܝ3+={Kw#p azPNha}qq:pᥑ m1b7Ƒ>90e\K-w%ıL8\JmMLNg`ɀH)*g*QתMrF3Kv(dn -wF8(̿,Dx1#I t!4!`o-#atb(ޤrd剻ٴ5hQxk5F59Jњ9q+`  mkWIǒ BLzM-;HoW#ԝ 8Բ/I59R+X~Mξ F>τImB8Sp5~ifvr\^Qu6XDB{!G2R*{:L371~dH#нjՓ*p$l}SZS'BJ^On SJg cp5&ڋA߫%_ *~: OIM&FX=;Ƒ{F~ kş)LQVIzOc[vzx !׫oxNCA|eͶMpg{ aOQ.Bߪ4}pVgM m^py֞S0:.ͷ,d  @G3eL[$9P%6֚?~cBy(L`b[۫?*0n[JpPw֒絗mq6X z=X6!_({!I5T> fIgEa%lU :-}ԑ]~6=x:ɆÄńWp4(\.d(!e )g\Ιk3e{^r@@p`w/^}!Ȏn:"_v&h݋e-gVV/i2I1a'͢T+,$ܙ ,?ʢd|e+]Mg Y#?𵂈_kYK3K )/Ztx8.R+z?e`SUrekL;N$"Ucbc +ba}k5 xxlw)N[Gt]7RIš!?GjuME JBD~3g%ʄQ;8JMO^T)OAuUg:[6p[+\MB 99wq|q2}gJGAF{7,zk'Ar_&)1VRO 3 .xCnQ |a95ɰ(R7A /4cQ %kҍg'ݗ#lrL1G#toE?cFu{Ж]1ƌ2~?x;4U$"͎F@1f.$h瞄E:C~{ #3L2ZK} i5;P ZHR_ Gܤ.5,+)?_W#bāJ懦.C=_yPɟV1FTI4*ԫM ~mam B| G>l˜ Y9MXR9볡ߥyX("K-J?G3(;VgsiUP?КhAwgf*( .n,v9ؚM,Lk_aªetL,/M al#I29:<&bZԖA/16%h C NTylـ@v #\ Lz``@Cg(f\CaRf"CByy&8aWvӳ(9B:ʴ&<{Ph$Ԩq{A[M ʛ|daz}%\ӯ9Ju𸛿 $V^6R[R/#4 nQzc\%D HB=Y v6E' *+*BJ$1OoBΐ?`:G:uͼ2}r.t M3!7m..x \V[>b@`=JJOn+P5O3]g@28r"`D!HpӮA Iq2EHMbD_ڀ!~oӉ׍<+/Z0МeÖ㟎߽ GM0Kʼ4a~tif_3F0Qa埡n`J|KW.}e!Vh D?QV7{htU̕Ys}jT!簧ϱ1l/)#vf/ |[4pU}]q* nlr?:ZA 7#Aпo. E1&!Ԭ9Vw 0Pm H4VM}.pʊ1!w Էoc.xUx4%!~QBBݟboYmd Tg:ˇ6Ԥ^奿*_ 惛/y 6j+mUjX+K*'oNz6iob NT:c[M_ dB(;u}d:͋(W>sM 8決,*3ҽqOZ\gl, /aH= drwZZ&w:B~=UOXl,OSINo,i<<%2XbC/e9 }HqFw,7\Ш2"D7sGT.E& hʑ[+Z5Ak|ul1lbÊڈOKBI<$fŻP;4F.8FͨYhS7,XٺTlx y99EӉؾ~v_ RKTma|@{T~ȨNg ϖYڎw@Y0Wխ%Auy+ 1ޤ|^3FIP45cY+ϬRd#qj56k[/ThI-9+u`ȳ@yť'hL 5ѷWj{NiqCl2q ii[nW3uX"ȹ>^Ea?t㸡UguL'aJ̄eg; @:yq/2`YȷzpM -t?0^O)$ɝisĝ<{ᰘ:Np d1-|8skk`Ee,v`;Kq•(Y33nVz%ǡZ2 U_:H@ldGdE QIw%Zy 6WKwt7ւ ^dn#iɸQ;s B6u݈n"H.*)N$ӐdAZ>ԥu9:B+4z'-Ty. u/?r(%uoӫBW߆P~sRD˚K5 xeVe(URuJ i!'#Y* ]lJcIa9!!n<$fX ;~&8Q4&ޟoG- YZ