permissions-20181116-lp151.3.1 >  A \̛/=„|Gд"grڽ֥~mJj|̙J셆È~ȧ o3 D`Q1PFb*ah`/_I`)e[(װ5/㽑I=\Cc.xEiAIɉ:zU8l6A4 1Ј C/3h!Og @5'fO+c\9sgae EJz m^z >v[%FϡT 倏̳k38\ f2c9*_6v" xJ,o|W1xvM媓 MH؅ >AIF3ct3 z3>;3Q_V>p@&l?&\d ! @ (1 Ka, P  b  t        = j   H v( 8 #9 D#: #>!lF!tG! H! I! X!Y!\"( ]"L ^"b#3c#d$>e$Cf$Fl$Hu$\ v$w% x% y%z%& &&&XCpermissions20181116lp151.3.1SUSE Linux Default PermissionsPermission settings of files and directories depending on the local security settings. The local security setting (easy, secure, or paranoid) can be configured in /etc/sysconfig/security.\̚sheep84OopenSUSE Leap 15.1openSUSEGPL-2.0+https://bugs.opensuse.orgProductivity/Securityhttp://github.com/openSUSE/permissionslinuxx86_64 PNAME=security SUBPNAME= SYSC_TEMPLATE=/usr/share/fillup-templates/sysconfig.$PNAME$SUBPNAME # If template not in new /usr/share/fillup-templates, fallback to old TEMPLATE_DIR if [ ! -f $SYSC_TEMPLATE ] ; then TEMPLATE_DIR=/var/adm/fillup-templates SYSC_TEMPLATE=$TEMPLATE_DIR/sysconfig.$PNAME$SUBPNAME fi SD_NAME="" if [ -x /bin/fillup ] ; then if [ -f $SYSC_TEMPLATE ] ; then echo "Updating /etc/sysconfig/$SD_NAME$PNAME ..." mkdir -p /etc/sysconfig/$SD_NAME touch /etc/sysconfig/$SD_NAME$PNAME /bin/fillup -q /etc/sysconfig/$SD_NAME$PNAME $SYSC_TEMPLATE fi else echo "ERROR: fillup not found. This should not happen. Please compare" echo "/etc/sysconfig/$PNAME and $TEMPLATE_DIR/sysconfig.$PNAME and" echo "update by hand." fi # apply all potentially changed permissions /usr/bin/chkstat --system0R1U \j9;@큤\̚\̚\̚\̚\̚\̚\̚\̚\̚695fe6b30c6f66604218b2ebf6101892df83b7d9d43f77e36962e21814c56c6596a6ed18a31f930ba9871fe2feb288740fd97a2cdadd750e1d90d2b889da1136254ecad52808937c3153a81d50810ee7e689d78dfc2cf8aac67cf179a2fdbf3b1bf6f81a057facaa31540b0e9aa7ed7eaf88b3649e936a84bcba7c1f28f65104c500f3032bdb314d3ab57bb60d80953120c22755dc83c62e7654c7d934feb2a6c1db3c18eaf18d5d5be92cca9f26453be974dd685e451337989c2f55918768bf35eca1eb5762d2b602f4b5114a54eb6e6815d26f10b5dab00cda67f2860ca4a32dcb772c1e9949198bc7695bd25c20cd21aea565905b0975de2edeafb31d8202acbebeb00ef9fccc619e66ad50b5c31ac346b2e06ec7d429ec8d2181bc5bd2f1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpermissions-20181116-lp151.3.1.src.rpmaaa_base:/etc/permissionsconfig(permissions)permissionspermissions(x86-64)@@@@@    /bin/shconfig(permissions)coreutilsdiffutilsfillupgrepgroup(trusted)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcap.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)20181116-lp151.3.13.0.4-14.6.0-14.0-15.2-14.14.1\8\b@[@[z@ZiZ\Z%8ZZ@Z@Z@ZNY|Y@Y˒Y@YY@Y7Y2Y1S@W"W@W@WBWBVV@VV2 @V +V +UuT~@TZ@jsegitz@suse.comjsegitz@suse.comopensuse-packaging@opensuse.orgmatthias.gerstner@suse.commeissner@suse.comkrahmer@suse.comkukuk@suse.commpluskal@suse.comastieger@suse.comrbrown@suse.comkrahmer@suse.comeeich@suse.comjsegitz@suse.comastieger@suse.compgajdos@suse.comastieger@suse.comastieger@suse.comopensuse-packaging@opensuse.orgdimstar@opensuse.orgmeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comkrahmer@suse.comdimstar@opensuse.orgmeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comkrahmer@suse.commeissner@suse.com- Added 0004-var-cache-man.patch. Removed entry for /var/cache/man. Conflicts with packaging and man:man is the better setting anyway (bsc#1133678)- Added 0001-whitelisting-update-virtualbox.patch (bsc#1120650) New whitelisting for /usr/lib/virtualbox/VirtualBoxVM and removed stale entries for VirtualBox - Added 0002-consistency-between-profiles.patch Ensure consistency of entries, otherwise switching between settings becomes problematic - Added 0003-var-run-postgresql.patch (bsc#1123886) Whitelist for postgresql. Currently the checker doesn't complain because the directories aren't packaged, but that might change and/or our checkers might improve- Update to version 20181116: * zypper-plugin: new plugin to fix bsc#1114383 * singularity: remove dropped -suid binaries (bsc#1028304) * capability whitelisting: allow cap_net_bind_service for ns-slapd from 389-ds * setuid whitelisting: add fusermount3 (bsc#1111230) * setuid whitelisting: add authbind binary (bsc#1111251) * setuid whitelisting: add firejail binary (bsc#1059013) * setuid whitelisting: add lxc-user-nic (bsc#988348) * whitelisting: add smc-tools LD_PRELOAD library (bsc#1102956) * whitelisting: add spice-gtk usb helper setuid binary (bnc#1101420) * Fix wrong file path in help string * Capabilities for usage of Wireshark for non-root - remove 0001-whitelisting-add-spice-gtk-usb-helper-setuid-binary-.patch: is now contained in tarball.- 0001-whitelisting-add-spice-gtk-usb-helper-setuid-binary-.patch: add whitelisting for the spice-gtk setuid binary (bsc#1101420) for improved usability.- Update to version 20180125: * the eror should be reported for permfiles[i], not argv[i], as these are not the same files. (bsc#1047247) * make btmp root:utmp (bsc#1050467)- Update to version 20180115: * - polkit-default-privs: usbauth (bsc#1066877)- fillup is required for post, not pre installation- Cleanup spec file with spec-cleaner - Drop conditions/definitions related to old distros- Update to version 20171129: * permissions: adding gvfs (bsc#1065864) * Allow setgid incingacmd on directory /run/icinga2/cmd bsc#1069410 * Allow fping cap_net_raw (bsc#1047921)- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- Update to version 20171121: * - permissions: adding kwayland (bsc#1062182)- Update to version 20171106: * Allow setuid root for singularity (group only) bsc#1028304- Update to version 20171025: * Stricter permissions on cron directories (paranoid) and stricter permissions on sshd_config (secure/paranoid)- Update to version 20170928: * Fix invalid syntax bsc#1048645 bsc#1060738- Update to version 20170927: * fix typos in manpages- Update to version 20170922: * Allow setuid root for singularity (group only) bsc#1028304- Update to version 20170913: * Allow setuid for shadow newuidmap, newgidmap bsc#979282, bsc#1048645)- Update to version 20170906: * permissions - copy dbus-daemon-launch-helper from / to /usr - bsc#1056764 * permissions: Adding suid bit for VBoxNetNAT (bsc#1033425)- BuildIgnore group(trusted): we don't really care for this group in the buildroot and do not want to get system-users into the bootstrap cycle as we can avoid it.- Require: group(trusted), as we are handing it out to some unsuspecting binaries and it is no longer default. (bsc#1041159 for fuse, also cronie, etc)- Update to version 20170602: * make /etc/ppp owned by root:root. The group dialout usage is no longer used- Update to version 20160807: * suexec2 is a symlink, no need for permissions handling- Update to version 20160802: * list the newuidmap and newgidmap, currently 0755 until review is done (bsc#979282) * root:shadow 0755 for newuidmap/newgidmap- adding qemu-bridge-helper mode 04750 (bsc#988279)- Introduce _service to easier update the package. For simplicity, change the version from yyyy.mm.dd to yyyymmdd (which is eactly %cd in the _service defintion). Upgrading is no problem.- chage only needs read rights to /etc/shadow, so setgid shadow is sufficient (bsc#975352)- permissions: adding gstreamer ptp file caps (bsc#960173)- the apache folks renamed suexec2 to suexec with symlink. adjust both (bsc#962060)- pinger needs to be squid:root, not root:squid (there is no squid group) bsc#961363- add suexec with 0755 to all standard profiles. this can and should be overridden in permissions.local if you need it setuid root. bsc#951765 bsc#263789 - added missing / to the squid specific directories (bsc#950557)- adjusted radosgw to root:www mode 0750 (bsc#943471)- radosgw can get capability cap_bind_net_service (bsc#943471)- remove /usr/bin/get_printing_ticket; (bnc#906336)- Added iouyap capabilities (bnc#904060)- %{_bindir}/get_printing_ticket turned to mode 700, setuid root no longer needed (bnc#685093) - permissions: incorporating squid changes from bnc#891268 - hint that chkstat --system --set needs to be run after editing bnc#895647/bin/shsheep84 1556912892 20181116-lp151.3.120181116-lp151.3.120181116-lp151.3.1permissionspermissions.easypermissions.localpermissions.paranoidpermissions.securechkstatsysconfig.securitypermissions.5.gzchkstat.8.gz/etc//usr/bin//usr/share/fillup-templates//usr/share/man/man5//usr/share/man/man8/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Leap:15.1/standard/bfbf26e270d73e9d55ca27acd2cfe381-permissionscpioxz5x86_64-suse-linuxASCII textELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.2.0, BuildID[sha1]=3d54e38e4f29c442c16e633f53d1458e36cbeb35, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)R R RR R3ي5W!Mutf-8be374cf3461c8aa1fb36417a150f28633092f08f1b192b3c0ee95fd33bb7b785?7zXZ !t/Rh] crv(vX0~oݑaFߖp؏tؖ)?޶;M,J97RPspU?k +J •X `5AL ס7KGɬѴJoBX'nkY9;{Hch0/gJ\3f: c)_xGjM&[^ Aqc\t@>Zg[PV3\q/@Qx>P5\ųR|thcF!í, R 3gB:|x= &ODc!QHۗ@58GwM eFaҖ3[i_';IefAw~ZKS_jb |{⬲hSwi~]ߜ4蠔+ h$w)p8 sHt<~vZPqp@̓agV =kT7c+V5mO?l6Gr0qҐCG)Quq:;G\H;K!ӓCP~hQ*+m91JOg-eKW m\I YL hvg ҩeϰΕ3@Uc#ẻhuyzV{qC_r4h"Ji V>glO q\]ПLN+ y7VLҁM6) .4Dh rBxbŵV٥sfx;5ETX=;63M]2Pȡ`zJ(CVŞ o1:ױj\ǯ 8Pf [rjD pz-9W= ِpJvBݨ̶)"e|5'= I[\tKKZҰGtS\zbYeKh0_x[X9 HaOӵ|4N~'RUs13NıҏBpW3ih hfnZWjJ#X=ͮ/Qڞ vq9 fn}FD*9bY2!]<*hyɜ4!.…3f"AZ![X+~̒;0([PD|CLCA ˦DgRTG--h`UREöSi>8@9=7vTv#&s.P[Sz @!8= 幠,JKz7{fO/\kjaqxrLə@t^`üK $Es_):&@SчFG(&a:Hɔ^Luq%Nx Ӎ-t +FGտĹ/=%YۡCACf^P|>1sÉ+kW^0}Gs+qåes7Q"xZ E=1+qͷ>39,^hw'sU %>7Lj<, /]˷&v@-d3h"Y5h 8YTk%c*:[]x7%g{.l~oI9jH\4lq27XZHݽ̵}ƣ@F= R/(~?ЗJ4F&2p4kI!FuڀW*S6!kOX3M|G(qq5@x_tTG ?g'_hT|4VuJ?s tV_5 c$OL.)Ti'F܄+{,z6*ǁ6?W%#Vi~U)L3*#. +l>âxj<7s -G9P'cYbw Q)zaOSZUwP{,TF<9APnwT-](TϵIҸL%WL\"* ]2&Հ`E {ج~Կz~)7t-{wȮl+3r ~e?q.O[+aXN\aoh^*Q*mcj[~"oVdž 鑔⯑$B]Y(kR˹'VW YKHd 5ltJ)-`~d@ͅjR؍\n ,'/CO5 = Bň޷H&7s)EwOw+Hd{ЧAa7У2z~7\ֿ^31qEo%fv.C+ A`3x? ը#z Ap/ ^ء0齘_`1/\.@Ǘ(3ӿ<*Gq'0|ɩKFjtLc@vCq϶{6j DJ D2@VUSkT i\HEX }ّԤ5%5oIgִ$^1M7xxf:++]Nz(:swnM9*U?EFy[[bw)89}X ̚ zxJIԵTXnR,TsK Xx΃w#'q+ x~@*H.hޓX?Ѫ ,)Ȼ WWi0:.8cF\1cfowDA甤\cKD6\I5|^j\(h0]QOB,@9[^Xbb0'ڣ-QRo^Vmk:ԧ[Qp@2XT?pTvz둞zTWB D:|s1ō,ARe|r ׆MzO'i(;'t4^SN0]E !*@!D$BO3 SA7ZgӇ)<֗$!ϳ،wyMSIm|S|KsK|ˀA!%q W"[[!4oǢ[6]\TeC2" QR'd,C7yn[^2.r'= W΀QvJGԨ!/+~Ly׮~8! @n ƑH$+ ,q V0*nW4 kyIljn+;Z**O|c5ms+7xZ9=-ˤL_Iπcu<+Vҍof|L!5̋!SiؙhמZ|%x3%dxmSTF[R+Mor($N!a]O?]V'8̪{۰c$O *c~VyVwMGiX7qM4{VbfBWUX"no0rZbŴo@ķG0_)V3q2jS!3fDƯ ?,l:f35hm| H]!i'|y`_t"d WA@P=^TٱEE`pd9/XtbwN> ǩ~ 4rͯNv <~SjTj]1M{N&7E G턈kXWn!$D97hz wfK7}]Dے>I(- /IG߆oRE3ZqH(ONSProѤ/1u+#9H*ںxt qHɝ E%';;*;g-*UU]OxUKg2.PSnf)0d5}P`6| {>Jrkn['*&8¦C4x7ި؝Em| KǂהHe}H+4o݉[^I\.9H ^2LI>y9E !u{c$]6-:,Yr=a9wgP%"' o7YAo_bE'~Q͖ WQE'~>)gz60nLk2STMÂ(FQO4/a^!L6<ćWUO %9"X VtjT;gK 3's{H-MXZlhO@V@&%7Tt>AӝcK6q;NjHIzNÃH@v3]ȡU&L {wKs&3Rz> )k )mԖaC%\ "yg*a~v֋?-To0UV-m z؆>3Jr$f<}ݭU~*vcܴubJ[Lm2P60AvLJY]{?r 7O& ; \ODtރ5,a$~V蕖FT9 8.JECL:ىdW_ӡ``y%J/N.36W)KE0lzNŨ$5fT&KHAX]isP+VO&_u/}# 4H7݋!Tb$_bg ]^x}+=w97t~~TU*Fd~'"/7 e#@e4wKLE{R\/b D0~Tuiא wm` ,Q(Yz$?h&PP]'ֱ23nT8; 70j K0śzxx i*Isl@(ev$TFYas. B{;na]q Fgq1W? #` =WdtHr[ܪwa>n$88ћ;pSHq48KƦ݈ -[ dH\2lҍ N87#>?«q6:]ԇ~/H>-{r bɻP,"*o&X "ŷ&̀o#mݑ3g2Y:dLAޕmAA}M.Ŋ f Qr\6 8h{Wѫ;zf8+Ո3a2ٝ"@ȼp&{#?mOP5`&=a#{d-LJO~( 5ԌPTp@3aѤE-οF k9roKKs ?s-3r,% >1ߍsVcCun~ ;w/UC.blB^\J`퇏2aU@^^НgP$ @(D32hYM*"l\Ȳc[РYJ6<X`>ђjK0񱋟`w6ݑtjHcnL^{fYջ$8وV% ]/rͶʥke02\Ԇ>iK:&]fr+ GLƠX0*M7J҇Z5#OtL NAEEP~sj;i&M.pMN)WJi<Z[]ehI\ Wvv"/ak)b.Y*d+4 떈mMu^Gۧ5?wMvgDKb/ ̵qVu., J:/vZq@$IbgHqqHJ"#G#I<h[)+]~BF?c&~8ִlw#Zǫ;*TӸՇts%)$$_1?,yk45`n+mN7r;W.YzC+YڵQկE{}#r_$p^^hMQ㤻x= /aȉ "]ڴ595v:I O9sRJ-lE2 e:$h?<^zHCXB(ING@7d>5:iC:ͯإ6*"Z9}c*Br֋hK:!Nw]g !jfFꨵmhLސKV}ĥ޷IECUvah?ZOM,DiDZ /jfd{W8g[΁F-<rd+I׋cr%%ǝ#ئ+AH KN 2򈼚qt5lnÖW;axVɣh S=53dhN'lH vqc%uk[P`]ND' %FX V-\ +=5S 11gp!1'{'% pZ^=Մ1lKV![PL۰=mOy lG;%zOԝ>CmX _hcbO_ï2|9 +C H &LDFu-B95v/Lhec=1=UQWQYܜ࠰kw/nǕ5 d?loevM`ף(K3؝U+´T\Yozxuv%`30hY׶$L{S(+NiX'E8"~Kp5lG`&@bO{^B5̉X 1kr!jFG3&3g@҉;SQ_eض\G |RC"TjöAjQ > O4h| '3 jSbL,Aaw޺E;}bCڟ6s6+/FrXmQFP1]bD@7ȳ*?֎3Ʈ :x"%;8ǃzsfIkMul{#A;Dmݎ`7l iPP!v]:Ԍ&r#j  \7hwR4js@e$47nbE5=z-l {+O PEL5L ⣭"S3%SE ^5ru)WH-=b"0,/D̀BKuUU^ GX>[ʐ$ͤ{`Q:P~j)/<砘S< :,y86 Y#E]!C=],t̋]MVps$ڞRP}Yh |!T~[fhZ\25e.׌ppAN1;s܁!D~xKe>r[̳"tNl3[[]+x@9wB=N|叹DYK"pkmU@ЗIz68KyԘm ҍ}S^oꚩ+vw)n5^^zL((%muDYRk)8 \8MQ`3B/{tlM/ynF]'+'ֱ=٧taQ6Rfco7יlkyFO[y*Yt(,>HqQfjF)ʌ^}V>@9rv+ѰW93bN=vMי E3zI,X9m5R); Dh &)E ."澽gG24'KsMѪj3t'$Y227ζla<Z1n; /m^~#amgEM-+p<7W0t+DX9c~6Bd”,J'W5 M:qiAHv~r?fITE Ov쳎. [ˣ(&mq?a6"$쎝h'DeϖS -l$Xf凸dHkgo|y㽺_ta*xjK gZ9%m ;YV^75^|[=y0B>ih.tik!tgq}5&ԭ]b-VBF.Ot!u]raPQW>.مhbxτ+Jp4 ;Gc_N1+ ۫yW(iē&*aP$C&(b49p!X %oU|w t&o:@Lz`{YWBsKbA\æQ9Y?f#KfRd\Z[18{!n6WF>eHI`(q_x$?c2SYqe= ^dVM]S3 *0 qdl;n 9SWPw]0c]:ٷ8%2NI3sɅht}>LTڔ'+"t UuIH,Dd<3X%_; |H3Ԓ?tS!wߐtėLyˣX<酿k@I94ƣed)eq]œhYK'H4q]b'tȼrJH7:R7;ϬySWH+ܦ<-&Cy$ZA\|b?6?g |-L ,[R#EfqsL0{&ZJy ScӶyU p`'~zT|.vXh[q6hϷLۡf|ps-dZ!_M7/Ƙ\P$g6JiwsI6E6BHoQ^_4J-GIQ` dY|zy>9 ԱdP^i\lwNhL^n!# O1OIaubojK>3A[Nڠ$;9NWݻ^JRSLHg2H!<%ίg)t:W'{0j}Zt"ҷzS$k- );u MOjp.w͉еdLR]<&wa$ʁOP k "+Z/H0_ Yuv15*G,\KI;L*˗X p}\_t6!gaWOVaygTt—ogs,Նq~p&&8; 뿂Dd*ەtq[Q6ϯ #h-YF(ϡ޸ÚJAK6U1^P[5:iK$Ð9Wو_0ْQg9gDڤpǴVAC#ewǏ ޿g0ʡH#?(Z+mj$NO e,#80P!҈5J$8;0!9) RŸ0,p1~6EGV++.bn#l9/w:Yz5׭Bk|y>4f u V{c3Ѥ!u,A-1ExLB_$F;v'l"Kx|W?~y*kXo*98r@nnPabAg+jpNBymD% -W\ 2CU3eEk(;Yzr 7B/5 ^lAC*{Y;WM-k,kxS_drS_G)0mz4f\TyҡoA Lvjf^t|]ߩ {(Pw0)UghN:H9i"rJ~~ª= _QA^g@Eh8dukt)ѪLz%cJPg3׳EⰭC~7jrbI6bt&垿^$L m^ Gy+'r%ݢlɾxĘ:~b&0zȒ7n!ލġYG*0l7ci PNe`S> Y5Isq#XD1񄰬Kb#qY?YwnGOKC7G璋96΢˂iVG{ËƝg! sn%D7&Ǻ+fc`8/6[jO\11Tܖp[z`X<[m\7r]-Y@q&bLTq?~kMJɍd;/B](x3(?NB>X6pHU:ā[J=³Q7ASe ĭk~ذkϏFlDy*݈1F;(#xAGWR2YXDPL,5r$`OYeNڷ6J!Md'Y[^)Hu\㈗Xm8Ak6jx=@q~`cIX%swRYCg%yS=UʂFHj4" OD ,{-NM 6W^T-,$+hE8$E&(x< W6n6ƯWlX&Yوmt[S ۸_#SOmrA" `'oKaiYVs*lDLqUrfPL`@^%\*)sEXjdUB00ncxj?xvCaSX8+>2B*bwV<޽˿4k'zw*B+E*>DF&2W-5g[MwHFfIB7vR~N#,Op)t]ZqF]AӤb`wҘ -Xžv{rl ST3}6}kѷ?f xZP:XJE YžSLJ?`8M$n>A*KćG?)wԆGe9~3y:i Q hZp~ - -[[@k_2h;`4tmn UԷi Eo̼uOz{B #ea|*<'697jy3>KJڵ8bx/ QaOYVь̤e6tX˄߰/c\=v i&zUFXMrG6Ś!(PB˸Q: ͒޹njDS),X]02m%,]ta)y^Zw">ˣۂds;08iDI@a0G,I4@[!'VUzbD]T/ƥ>l۵4W/9Lw৖)➏EVfnwZ7s)2Tе ?zJ6| R|W&Bt+'tG`ɋw(Ӂ#K@b_Kʇne _\l'~l?v[NR7?3~Ǹ }>" hf+kܞ'ʼn=Rm7Ht$-Fh²Bwݞqvژ&S$ZX<+5e(=}f'V#ܚef9Zf8!?}kP7(?͹wEDx=&>9fT^J3EC'6>N/:02t"C/:k~Ϣ@l?nl=܋wnL:tWvUX([|:dV㈬Meڔqi<[bX]ƊOMNDv~MiZMh/UIZIt xP.   '7kS^#7&AX)?jN$]#/zRu~Ɔ~l4_B\b@MqLCń֞5hThX9D)Nre;Ԉp fœ{ź_u[Rg~ZI-5rhV/f>JEQߍhevu/uњ|ؘ?8YaEP9%hؓck?zEX"To)X#ߖYCQw<>]V`34C<~ac l H+]#I!thмII%iRxx?>>}wWh8O.[A% N$I#[y: ֫]\ģD ư)4^RUdR=?(SHkF;ƵtVTʅ2ʉvX.;)!4guB5/A]5yDcիsY > Vz=6=J‹9HWՇkgOmɆD$%VrdW9bԲ s7nK 4Z~xo]ݪ7鯻2ZOZE$/*R^~ڑ_x^'ৢwvJUMFe $Ϻ28$OLMȥ2 ˄r@*lԉ/cm;|5lSO@9{)s|2n'Y&Xs#\喙 |]0:>Lpu'8\wtͽa|Va }I FL<-F NtFj$}^'WY a")`ߤ#v;=r;O  py 6zҊ!8mo(&3=h%gUyU VC {D0Yy[*G\`DK* 7͕۠ʓ2ʄqnjw jT[<甠xer ;v&iJo۠ә Gğ*/ۋO{d'QdY-҅:668v5r$~ݩ2j)x|E7R{^[ip7*GLY͏EЁAPaLhYE̺͡ =5L tUj >`_kSNmL,gL*pbZ%N q*qpQԎ (hVh MicL6<शcrh҇8- E'pkkdwN= LLeۜEw 8)y/V(&)AHB-D]`#Lmhgx YDjmB఻eY| ߼ 2y#:I83E9am_5BU.ߞkdvwe`MQO$Ndfx1r![h^G=ED {1 {zn1y:0f܋[ ^m{ܹj(̲0i Q49IA;Elۤ~CM Kh U#Wiw;^1=f!VU':"צQ\WS"n>̣.:qTRռk{*r'MfBh`S^QnW)6)O[L}[MP'UdhEvFe\0 m~O& (?{^aޝ~kh{嶜#9O`sܛ$|BCH"c,rL O'Op6zF#lKǘ(6| 5jR,9bKoЄl4"!ɧ+?J4^g+M@F/m N/H5h%׹>jly#H-zmmaܑ~7~^fy줘tdT lzàhF*9byYx^ӱ\ї A <-JD &[.]U|2B;A<˛r^]W.nMUX m1 r"{kb1xL%i@<]4e{@+:RDSv#s)4 Kd{knƎ9(9øJ6{T~(7&c#9dO1FF ?"YJb7 s0dV]ڼg^@^p~MHcsҮ=lQ|QM}s>|l}s] W]B2\Q-"r"%Ěwh!^#alϩՕI9_RRGnTwd?|R=[g,#vu"g+ U?"Vpf/Llm?ʜEmAXD0*۬2&(Em dS(0g?"?Ql\ ^ز8Q6OC&9?}[rn\ʹ*5u0=R mK^Q2kp)7+V2qVxuypB N֌M~=a ~2ޭ ر>ɃDҙOO W]@y5p2`}iY$ Y*nJ1&iӥf.u"<[>LQ칊Oyiڱ\]G7?4OJ7fz0iBsW*A9WKrl::T"Y)eiueY82oXMIlL]!he46 InfcLnnndA.KZ Áq%^/UijX嵅Gʀb_ g$mM.xE[~ %L6xFJ#Wcl ЅEfW{w;u6եs-1o/CnP͜6w0\xd5/}Lm&Pd,lڕcݯwbn:#m'aZr:M9cYφGݕ~ Uh*3ŭJȬxf+,< ކ4WIuPhG\3?4lj,*#pef9~ذ$%J5_!?墭bg1Q`oeG1ӯf-(j1sĚk 'd&ج;I@l0R[f) 1[@kLY 9H Y6c j_nܠERbVj0(bkqj znRw’Œh.J2\wK̎ YARߍ0 0D:|U6[A0b~LcتR Yh -#š( #;(K_ev[qsrrZE?ЩqJFvDYD*$n‚VN54d>X-"ER=䋓8*@]ÛaT4\hQ_xfyN_˩6/\?:w/[n)b_ߛst V#dTF]]@$=>{{Ms/ǕɉK c¨K7,hܰbo3y}V[2='g7̔qRGXRspǶ YZ