libopenscap_sce25-1.3.2-lp152.1.2 >  A ^ O/=„``sr^d;rcRv^ֆUM3H'N]8 1lQ$ {h"GوO R&V;ze hNāko_y.0bebP M2 _r*2oԽ86'UlT{D J5gO=o=!3h;kf IR6lǞv ?R 4 ]&B5Iv]qRNm8j221376fc6dee87cd3c95aa96b872de2719c14f7daa38064037d4c94c64a1251c40dac956c96196183ebdb45a9640083e364e5444^ O/=„QwQnrHXE- X#MO2xg] ݁ ճq ,3I֠wgۂ݋iڤq֞*Ii5 ɽH4F,Tw 5{BB=Ż7LRASf>KvHAVx VT-` vegt+a0Fb6 `<bL#KOHQrh(IV4lbte";N[2ӽyFLq1=w")_>p@d4?d$d $ P  $*4< @ D L  @(B8L&9&:&>a@a!Fa0GaDHaLIaTXaXYad\a]a^abacbudbebfblbubvbwcxcyc zccccd Clibopenscap_sce251.3.2lp152.1.2Script Checking Engine Library for OpenSCAPThis package contains the Script Checking Engine Library (SCE) for OpenSCAP.^ 6goat01HopenSUSE Leap 15.2openSUSELGPL-2.1-or-laterhttps://bugs.opensuse.orgSystem/Librarieshttps://www.open-scap.org/linuxx86_64H^^13c0939c765afa57b2db3f04d55cc1ddc03366a21773a4dd5041a7fdbe739bb9libopenscap_sce.so.25.1.0rootrootrootrootopenscap-1.3.2-lp152.1.2.src.rpmlibopenscap_sce.so.25()(64bit)libopenscap_sce25libopenscap_sce25(x86-64)@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.11)(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libopenscap.so.25()(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1^{G^@^^]:\@\[@[[@[ @Z@Z1@Z1@ZZ@Z Z Y@X@XXoX2XW@V@V%@V`.V@Vf@UmUUF U#T@T}T|X@Ty@Christophe Giboudeaux Marcus Meissner Marcus Meissner Marcus Meissner Robert Frohl Robert Frohl Bjørn Lie Robert Frohl meissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comjengelh@inai.demeissner@suse.commeissner@suse.comrbrown@suse.commeissner@suse.commeissner@suse.commeissner@suse.comjengelh@inai.demeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comLed - Add upstream patch to fix the scap-workbench build: * 0001-Do-not-use-C-keyword-operator-as-a-function-paramete.patch- switch back to official release - openscap 1.3.2 - the test suite and build scripts were improved to support Debian 10 - offline mode has received some love with a set of dedicated tests and various fixes in OVAL probes; - the oscap-docker wrapper is no longer dependent on Atomic - Python binding are now more robust - HTML reports and guides, generated by the scanner, are now more accessible for non-visual rendering agents - Support of multi-check rules has been improved across the whole workflow There are other changes as well, here is the list: * New features - Offline mode support for environmentvariable58 probe - The oscap-docker wrapper is available without Atomic + Maintenance, bug fixes - Improved support of multi-check rules (report, remediations, console output) - Improved HTML report look and feel, including printed version - Less clutter in verbose mode output; some warnings and errors demoted to verbose mode levels - Probe rpmverifyfile uses and returns canonical paths - Improved a11y of HTML reports and guides - Fixes and improvements for SWIG Python bindings - #1403 fixed: Scanner would not apply remediation for multicheck rules (verbosity) - Fixed URL link mechanism for Red Hat Errata - New STIG Viewer URI: public.cyber.mil - Probe selinuxsecuritycontext would not check if SELinux is enabled - Scanner would provide information about unsupported OVAL objects - Added more tests for offline mode (probes, remediation) - #528 fixed: Eval SCE script when /tmp is in mode noexec - #1173, RHBZ#1603347 fixed: Double chdir/chroot in probe rpmverifypackage- temporary openscap 1.3.1 git snapshot - make it build with new RPM (bsc#1160720)- use distribution-release instead of dummy-release- openscap 1.3.1 - New features - Support for SCAP 1.3 Source Datastreams (evaluating, XML schemas, validation) - Introduced `oscap-podman` -- a tool for SCAP evaluation of Podman images and containers - Tailoring files are included in ARF result files - OVAL details are always shown in HTML report, users do not have to provide `--oval-results` on command line - HTML report displays OVAL test details also for OVAL tests included from other OVAL definitions using `extend_definition` - OVAL test IDs are shown in HTML report - Rule IDs are shown in HTML guide - Added `block_size` in Linux `partition_state` defined in OVAL 5.11.2 - Added `oscap_wrapper` that can be used to comfortably execute custom compiled oscap tool - Maintenance and bug fixes for a complete list please see https://github.com/OpenSCAP/openscap/releases/tag/1.3.1 - removed patches accepted upstream: rpmverifyfile_unittest.patch rpmverify_unittest.patch sysctl_unittest.patch test_probes_rpmverifypackage-disable-epoch-test.patch xinetd_probe.patch- obsolete removed packages: openscap-engine-sce and openscap-extra-probes- Drop gconf2-devel BuildRequires: It is not mandatory, so lets build without this obsolete package. - Add pkgconfig(glib-2.0) and pkgconfig(gobject-2.0) BuildRequires: They are also optional, but not obsolete, and previously pulled in via gconf2-devel dependency, so lets build support for them.- openscap-1.3.0 - New features - Introduced a virtual '(all)' profile selecting all rules - Verbose mode is a global option in all modules - Added Microsoft Windows CPEs - oscap-ssh can supply SSH options into an environment variable - Maintenance - Removed SEXP parser - Added Fedora 30 CPE - Fixed many Coverity defects (memory leaks etc.) - SCE builds are enabled by default - Moved many low-level functions out of public API - Removed unused and dead code - Updated manual pages - Numerous small fixes - xinetd_probe.patch: fix trailing whitespace in config - test_probes_rpmverifypackage-disable-epoch-test.patch: fix rpmverifypackage unit test - sysctl_unittest.patch: fix sysctl unit test - rpmverifyfile_unittest.patch: fix rpmverifyfile unit test - rpmverify_unittest.patch: fix rpmverify unit test - openscap-xattr.patch: removed, included by upstream- openscap-xattr.patch: build against new libattr- scap-yast2sec-xccdf.xml: remove platform cpe match, as it is impossible to match both opensuse and sles or official suse_linux_enterprise_server names at once. (bsc#1091040)- openscap-1.2.17 - New features - HTML Guide user experience improvements - New options in HTML report "Group By" menu - oscap-ssh supports --oval-results (issue #863) - Maintenance - Support comparing state record elements with item - Updated Bash completion - Make Bash role headers consistent with --help output - Fixed problems reported by Coverity (issue #909) - Fixed CVE schema to support 4 to 7 digits CVEs - Fix output of generated bash role missing fix message - Fix oscap-docker to clean up temporary image (RHBZ #1454637) - Fix Ansible remediations generation - Add a newline between ids in xccdf info (issue #968) - Fix unknown subtype handling in oval_subtype_parse (issue #986) - Outsourced the pthreads feature check and setup - Speed up in debug mode - Refactored the Python handling in build scripts - Prevent reading from host in offline mode (issue #1001) - Many probes use OWN offline mode - Improve offline mode logic in OVAL probes - Do not use chroot in system_info probe - Prevent a segfault in oscap_seterr on Solaris - Out of tree build is possible - Use chroot for RPM probes in offline mode - PEP8 accepts lines up to 99 characters - New configure parameter --with-oscap-temp-dir (issue #1016) - Fixed OVAL record elements namespace and SEXP conversion - Removed '\r' characters from help output (issue #1023) - Full Python 3 compatibility - Removed basic Python implementation of oval_probes.c - Added support for Travis CI and Sonar Cloud - Minor fixes inspired by Sonar Cloud - Added Fedora 29 CPE - New tests in upstream test suite (offline mode, Ansible, etc.)- openscap-new-suse.patch: handle SLE15 and openSUSE Leap 42.3 and 15.0 (bsc#1091040)- Replace old $RPM_* shell vars.- replace oscap-scan.init by oscap-scan.service, add a /usr/bin/oscap-scan helper tool for this. (bsc#1083115)- disable scap-as-rpm binary to avoid python2 dependency. (bsc#1082135)- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- openscap-productid-cvrf.patch: add a --productid selector for "oscap cvrf" as upstream does not detect the system yet. (might go away)- openscap-1.2.16 - New features - oscap can generate output that is compatible with STIG Viewer. - CVRF parsing and export has been implemented. - oscap info command has been expanded. - The AIX platform is supported. - Many documentation improvements. - Numerous other improvements of existing features. - Maintenance - Huge cross-platform improvements. - Memory leaks fixed (RHBZ#1485876). - SELinux fixes. - Many coverity fixes. - Numerous other bugfixes. - buildrequire procps-devel- openscap-1.2.15 / 25-08-2017 - New features - short profile names can be used instead of long IDs - new option --rule allows to evaluate only a single rule - new option --fix-type in "oscap xccdf generate fix" allows choosing remediation script type without typing long URL - "oscap info" shows profile titles - OVAL details in HTML report are easier to read - HTML report is smaller because unselected rules are removed - HTML report supports NIST 800-171 and CJIS - remediation scripts contain headers with useful information - remediation scripts report progress when they run - basic support for Oracle Linux (CPEs, runlevels) - remediation scripts can be generated from datastreams that contain multiple XCCDF benchmarks (issue #772) - basic support for OVAL 5.11.2 (only schemas, no features) - enabled offline RPM database in rpminfo probe (issue #778) - added Fedora 28 CPE - Maintenance - fixed oscap-docker with Docker >= 2.0 (issue #794) - fixed behavior of sysctl probe to be consistent with sysctl tool - fixed generating remediation scripts (issue #723, #773) - severity of tailored rules is not discarded (issue #739) - fixed errors in RPM probes initialization - oscap-docker shows all warnings reported by oscap (issue #713) - small improvements in verbose mode - standard C operations are used instead of custom OpenSCAP operations - fixed compiler warnings - fixed missing header files - fixed resource leaks (issue #715) - fixed pkgconfig file (RHBZ #1414777) - refactoring - documentation fixes and improvements- Remove line-trailing whitespace from last changelog entry. - Rename %soname to %sover to better reflect its use. - Replace unnecessary %__-type macro indirections.- openscap-1.2.14 / 21-03-2017 - New features - Detailed information about ARF files in 'oscap info' (issue #664) - XSLT template creating XCCDF files from OVAL files - Generating remediation scripts from ARF - Significant improvements of User Manual (issue #249, #513) - HTML report UX improvements (issue #601, #620, #622, #655) - Warnings are shown by default - Verbose mode is available in 'xccdf remediate' module (issue #520) - Added Fedora 26, Fedora 27 and OpenSUSE 42.2 CPEs (issue #698) - Support for Anaconda remediation in HTML report - Maintenance - Fixed CPE dictionary to identify RHEVH as RHEL7 (RHBZ #1420038) - Fixed systemd probes crashes inside containers (RHBZ #1431186, issue #700) - Added a warning on non-existing XCCDF Benchmarks (issue #614) - Fixed output on terminals with white background (RHBZ #1365911, issue #512) - Error handling in oscap-vm (RHBZ #1391754) - Fixed SCE stderr stalling (RHBZ #1420811) - Fixed Android OVAL schema (issue #279) - Fixed absolute filepath parsing in OVAL (RHBZ #1312831, #1312824) - Fixes based on Coverity scan report (issue #581, #634, #681) - Fixed duplicated error messages (issue #707) - Fixed XCCDF score calculation (issue #617) - Fixed segmentation faults in RPM probes (RHBZ #1414303, #1414312) - Fixed failing DataStream build if "@" is in filepath - Fixed missing header in result-oriented Ansible remediations - Memory leak and resource leak fixes (issue #635, #636) - New upstream tests - Many minor fixes and improvements- openscap-1.2.13 / 05-01-2017 - Maintenance - we always build system_info OVAL probe, fixed configure output accordingly - warn when the user requests to generate an ARF from XCCDF 1.1 - fixed a segfault when loading an OVAL file with invalid family attribute - added --thin-results CLI override to oscap xccdf eval - added --without-syschar CLI override to oscap xccdf eval - fixed a segfault when freeing xccdf_policy of the default profile - removed ARF schematron workaround when there are no applicable checks - fixed verbose output in oscap xccdf generate fix - do not filter fix by applicability when generating remediations from results - fixed memory leaks, resource leaks and other minor issues- openscap-1.2.12 / 21-11-2016 - New features - separated stdout and stderr in SCE results and HTML report - HTML reports contain [ref] links for rules and groups - Maintenance - fixed ARF errors reported by the SCAPval tool - fixed CVE parsing (issue #550) - fixed namespace of ARF vocabulary according to NIST SP800-126 errata - fixed exporting OVAL Windows namespaces - fixed injecting xccdf:check-content-ref references in ARF results - fixed oscap-docker incompliance reporting (issue #475, RHBZ #1387248) - fixed oscap-docker man page (RHBZ #1387166) - fixed memory leaks and resource leaks - small fixes and refactoring, test suite fixes- openscap-1.2.11 / 14-10-2016 - New features - huge speed-up of generating HTML reports and guides - support remote datastream components (issue #526) - support tailoring of external datastreams - various attributes of remediation scripts are now shown in HTML report (issue #541) - new option generating OVAL results without system characteristics - remediation scripts in HTML report are now collapsed - support for extracting Ansible playbooks - enabled fetching remote resources in OVAL module - added Wind River Linux CPE - Maintenance - updated jQuery and bootstrap libraries in HTML reports - extended, improved and updated user manual - fixed issues with proxy in oscap-docker (RHBZ #1351952) - fixed a bug in OVAL arithmetic function - fixed a segmentation fault (issue #529) - fixed results of XCCDF rules with @role="unscored" (issue #525) - fixed invalid characters in OVAL results (issue #468) - fixed a segmentation fault in tailoring (RHBZ #1367896) - updated SUSE 11 CPE - fixed many memory issues - large refactoring of datastream module - new tests in upstream test suite - various small fixes and improvements - openscap-1.2.10 / 29-06-2016 - New features - support --benchmark-id when running `oscap xccdf generate guide` - added CPE support for OpenSUSE 42.1 - Maintenance - oscap-docker fixed to be source compatible with both Python 2 and 3 - fixed offline mode in rpmverifypackage probe - fixed scanning of non-RHEL containers in oscap-docker (issue #427) - fixed regression in loading a datastream session (RHBZ #1250072) - fixed missing SCE results in XCCDF reports (issue #394) - fixed a segmentation fault (issue #370) - fix error message when OVAL generator element is missing (issue #345) - fixed failing rpminfo probe - fixed compilation on RHEL5 (issue #393) - new tests in upstream test suite - test suite is able to run on Fedora 24 - fixed remediation scripts appearance in HTML guides (issue #460) - fixed autoconf build - small fixes, refactoring, small documentation improvements- openscap 1.2.9 release - New features - oscap-chroot - a tool for offline scanning of filesystems mounted at arbitrary paths - enabled offline scanning in many probes - support for SCE in data streams - many improvements of verbose mode - verbose messages can be written on stderr - runlevel probe supports SUSE systems - new upstream tests - Maintenance - a lot of refactoring - fixes in various tests - OCILs are correctly placed in datastreams (issue #364) - oscap-vm can work with fusermount when guestunmount is not available - fixed oscap-docker HTTP communication issues (issue #304) - fixed oscap-docker tracebacks (issue #303, #317) - fixed container mounting in oscap-docker (issue #329) - added Fedora 25 CPE - only non-empty profiles are built (rhbz#1256879, rhbz#1302230) - fixed compiler errors on RHEL5 and SLES11 - fixed sorting of groups in HTML report (issue #342) - fixed version/@time and version/@update in XCCDF Benchmark - fixed CPE definitions to work also in offline mode - fixed sysctl probe (issue #258) - fixed manual page for oscap-ssh (rhbz#1299969) - updated user manuals and manual pages - updated .gitignore - dropped fix-missing-include.dif, not needed anymore- enable the SCE (script checking engine) packaged in "openscap-engine-sce" subpackage. - enable the CCE (Common Configuration Enumeration)- openscap 1.2.8 release - Maintenance - textfilecontent54_probe does not produce false positives on non-UTF files (rhbz #1285757) - fixed oscap-docker - small improvements in verbose mode - oscap info module shows information about tailoring files - fixed build with CCE (issue #264) - fixed XCCDF score computation (issue #272) - fixed segmentation fault in variable probe (issue #277) - fixed broken support for OVAL directives - fixed bash completion - plugged memory leaks - fixed fresh static analysis (coverity) findings - fixed shellcheck warnings - new tests - refactoring in datastream module - many small bugfixes and typo fixes- openscap 1.2.7 release - New features - OVAL 5.11.1 fully supported - oscap-vm - tool for offline scanning of virtual machines - verbose mode - added SLED, SLES and OpenSUSE CPE names - show profile description in HTML report and guide - group rules by PCI DSS identifier in HTML report - preliminary support for Ansible Playbooks within xccdf:fix - added "How to contribute" and "Versioning" documents - Maintenance - using bziped RHSA documents in oscap-docker - fixed errors of sysctl probe - fixed skip-valid option (issue #203) - fixed segmentation faults in SCE content reporting (issue #231) - fixed tracebacks of scap-as-rpm - fixed invalid memory reads in rpmverifyfile probe (issue #212) - updated README and user manual - many small bugfixes and new tests - openscap-new-inventory.patch: upstreamed - fix-missing-include.dif: refreshed, 1 hunk upstream- openscap-new-inventory.patch: find out the CPE ids of SUSE Linux Enterprise and openSUSE versions.- openscap 1.2.6 release - New features - introduced OpenSCAP user manual - improved OVAL 5.11.1 support - added OVAL 5.11.1 XSD schemas and schematrons - support for core/platform schema versions - support for check_existence attribute in state entities - support for CIM datetime format - amended behavior of mask attribute - added support for remote .xml.bz2 files (use with --fetch-remote-resources) - rewrote oscap-docker to python, deeper integration with Atomic Host - introduced CPE name for Fedora 24 to the internal dictionary - HTML report & guide - results can be grouped by according to various aspects - printing supported (interactive elements are now hidden when printing) - table of content now shows only selected items (rule & groups) - references to RHSA are presented as links to website (rhbz#1243808) - Maintenance - scap-as-rpm can now build source rpm packages (srpms) (trac#469) - scap-as-rpm now supports python3 - refactored oval processing into oval_session structure - many smaller bugfixes and new tests - new openscap-docker subpackage- openscap-1.2.5 update - maintenance - smaller bugfixes - plugged memory leaks - fixed fresh static analysis (coverity) findings - fixed shellcheck warnings - fixes for Solaris platform- openscap-1.2.4 update - new features - OVAL 5.11 support 99.8% completed! - new symlink probe introduced - new process58 test capabilities - added possible_value support for external variables - added possible_restriction support for external variables - improved IP address comparisons - Added Scientific Linux CPEs - Added oscap-docker tool - Created man-page for oscap-ssh - HTML changes - improved visibility of selected XCCDF profile in guides and reports - render rule-result/message contents in reports - maintenance - Tests now pass on ppc64 little endian arch (rhbz#1215220) - partition probe now supports remount, bind and move mount options - Patched NIST OVAL-5.11 schemas to be backward compatible with OVAL-5.10 (rhbz#1220262) - fixed scap-as-rpm to work with vintage python (2.6) - better error reporting when a probe dies (i.e. due to OOM killer) - dropped selinux policy from upstream (rhbz#1209969) - fix segfault on invalid selectors (rhbz#1220944) - solaris support patches: file-system zones, systeminfo improvements - many smaller fixes and new tests- openscap-1.2.3 update - new features - oscap-ssh -- handy utility to run remote scan over ssh - glob_to_regexp OVAL function added - HTML changes - show rationale elements - show fixtext elements - show Benchmark's front-matter, description and notices - show warnings for Groups and Rules - improved handling of multiple fixes within a single Rule - scroll evaluation characteristic if they overflow - maintenance - OVAL 5.11 schema fixes - Coverity and memory leak fixes - skip transient files when traversing /proc (trac#457)- openscap-1.2.2 update - new features - OVAL 5.11 support turned on by default - included OVAL 5.11 schematron rules - DataStream can now contain OVAL 5.11 - `oscap ds sds-compose` now supports --skip-valid parameter - HTML report changes - Notably increased level of OVAL details - Table of contents is now generated for HTML guides - maitenance - rhbz#1182242, rhbz#1159289 - @var_check & @var_ref exporting - solaris build fixes - xccdf:fix/instance processing fixes - improved (none) epoch processing in rpm probe - environmentvariable58 now emits warning messages when appropriate - offline mode improvements - other bugfixes- openscap-1.2.1 update - API changes - 5.11 schemas updated (from RC1 to gold) - oscap_source_new_from_memory can take bzip2ed content - HTML report changes - severity bar is now reversed (left-to-right) - maintenance - rhbz#1165139 - fix probe cancelation - dozen of bugfixes- openscap-1.2.0 update - new features - native support of bzip2ed SCAP files (file extension needs to be '.xml.bz2') - improved performance on huge XML documents, especially DataStreams - minimized use of temp files to absolute minimum - added OVAL-5.11 release candidate schemas - API changes - overall 50 new symbols added to public API - introduced oscap_source abstraction for input files - further info: http://isimluk.livejournal.com/4859.html - all the parsers converted to use oscap_source abstraction - introduced ds_sds_session, high level API for playing with Source DataStreams - introduced cpe_session, abstraction to approach multiple CPE resources - introduced ds_rds_session, high level API for playing with Result DataStreams (ARF files) - deprecated dozens of API calls dependent on filepath - introduced API for waivers (xccdf:override) and modification of ARF - initial support for waivers in HTML Report - dozens of small improvements - maintenance - dozens of small fixes - dozens of memory leaks (whole test suite is now leak free) - updated gnulib - openscap-1.1.0-fix-bashisms.patch: upstreamed- openscap-1.1.1 update - Hint towards `oscap info` when profile is not found in oscap tool - HTML report changes: - Source OVAL results from ARF if available - Highlight notchecked rules, treat them as rules that need attention - HTML guide changes: - Variable Substitution improvements - Show benchmark title - Show info about selected profile - Avoid cdf12:notice, show only its contents - bugfixes: - improved handling of fqdn in XCCDF - memory leaks - static analysis fixes- fix bashism in oscap-scan.cron script - add patches: * openscap-1.1.0-fix-bashisms.patch/sbin/ldconfig/sbin/ldconfiggoat01 15896494621.3.2-lp152.1.21.3.2-lp152.1.2libopenscap_sce.so.25libopenscap_sce.so.25.1.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Leap:15.2/standard/4799b3c9be76d993cc1778e6f68d1549-openscapcpioxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=63130ee1443398bd4cf1528de2e362304a9f1542, stripped PR RRRRRRR R RNĒVj} [utf-862227678a88f48158ebd79d31d13596c18fda4cfb777388d642e5d0a96b4ea42?7zXZ !t/;l] cr$x#+c!y5s=[ہ~G_ɡoFi^N *-@Wp(XQVJJJ+ Ź*w,h3 w/5;h;{#SqPH2ǜ9IS>]^@R~?qp'`z &Y*02{i{KM~w*u0 kA%bc6Yٙo_59m@L"Lހ]obi%88J?k"o=ےAaqhXse]$uQ(᳣2:lW?T /O>o׳ qɴVM zG #RP o]3o^zl&l}cWhB3H ꗂBΙ3qʣ "3%,p)?td+z~&WVPo|֜HGDnrTa:JJy Lg/ؽ˜ɤR_ $g:.52?l)1fj/Jjh'>=3ѧE(.jʍkipM%1(`FII/H [ r/LZ`C!#۪Q#n)$fBPR!¬D !t)I"eKLa1pk/ޔM=͋5+i+> xdct26,5cp n}6Ź?[i 8 vn6wO$rSlؐ d~IU<̈́. 3 -Ɍ!{2&b# )'v }:f< v=ƂZ=a_Gbc[!93 oĢ+Jle6jPt1G KX7e}ʁ SXY ӓ-H|`p7n"I|NY=Tkң"g)g(Oq?5ߟ;8M%)L) rDB10ajdj&ݨXG<z\1A40UH o2#,gƢ-PcF)8YQ*;\b4mIfƵE[W㮔@FJ5|8ts̩Ɗ;xj ΔPeF[ԿbGg7ӎ󒵋>-JܱѷdzyVz#FH0+A%H=$ȷϘc!^8ԲϢW_!'MaO>gAdYaR('d@?{L Bs!xRpӮnqLVr%? ~?e_)$tR4 x/rl* IF8= 'T~'`|!30\l<7aOxA{wՄM6RdH/c}<#~љr@n3m"|IKV@C0= mcn;.c|q(3{yM_s1Q"OYIy—lq,{bh`>d3Y0}"#rvga8ɗ~-ګOk&@[g. "#5+M uX!: L0q)UA\`'pr"bīU@^K=b;44[{!bp0%IJ%) o#&QVTp8z(#YDv^#G,חOai tX.2FIm/Fc`}h C&NrZ __+qVϻH򷘻n>kNc0R| NJ{zu_{ a}H!O*MWmdVH\IjiTp^ pXwlެ| !!87s}m;+]ah TnVBl$@$*c Qݯ+-p;^H]p 1 Op2!^ɟqV<P!|PI,fJso >VJ@Mm G]50 2u*Ot n c .x7Z%CȦv"_[{|ߝۈ2;tX])ՖGv+кT;LZ<;a#XoHWq)&Yz)]<5WKw4+4$H*q] gȒ#4tBIMK$x#MF *L棴-KF}adܺyo]18^|xU;NEsMMA#4D둈U [z 8V?rkJ 5[({1QzB!=`[m-X&.Wbt֧:lrg6$ y}IV(|26 ؕLe95(HKH2̬o͌ǩZ81rOs@\5w" 5P!^e6͑zr?j˛Jb*#K+6ثfؤdQ&h GܲB$Mkټ=kgGc m6"OsƸoK 0WL".C?`r##3V_Np| F&~G1t00ct៭zcg)) :φJҋ(8X=VJ /Zo(ռ7ܯjz2=9H`|Kǭ,%pmɴPzwNh]ɇ53_dtNH>R7p{mԔM:#`1D62|sҢLfOegD_a\aYݬmaU2YwY u0bW#1hXNl,-\ Kv(T"ծ@Zb(X #GG57p2?Y5#-$|t7kI\gAba@jq&ici]9@Pn%<> ,=Iq&TY,V H:I(X O_|tS&g~otCKOn6ѐ{m䰚ƪbda`jfEH־SW=gz`"r ou 9Zr/_["I0>ftNaN<nkEdb _3R Ab&Y}OeiGd<#O.sg/c &d6u~;sT^:qX̜|;3\0\xfS+\8`xLmh鴼I2$"\jԚqVAǕ 0m0)˰T"/Ҍ'/ں5cNUdmHbmwy8F!?Jz+)b(E Ԥẗ1[miN:;̀C6 I&Μ5^DzYۦმR ;+#HW:1x4߈lW~dХt8xSHOp:8Sn `˜ _DZ]6e1q+xFJPrbDZ0GE^ێ=;Y-%5*vz{lUKJiƾ018fu# Rl'4@ _9(Rlv Yjd ӶKjs>ϊ 'foBW6_ܚ}ቸկ:0k>,5 /%ɾizwд#YST΅-^jx㸆oOɉ9D)E2E yGZ4S2s$9EI'%Nf,& yKpYsHV;$at@2s0^* ?T6ġ2c dEcZC`S"T 3}_0`AUO6&G(1GMb>$$*@6Tb賁fvg#~/]찹)Bb(HˢJ2cCߖkY] aŬb9E'_obv)Z(/v Q0xEad>?)iP.fjlT;p޳WP -3FB{B.D== 2WH-)Pmƫ܁ԱH&X%⸀I4E"Ѳt>6/ ;f8Se،>.u=ᬑ+닼Ag~r6QQ "0y4`x?P{b^m-^L7cBg⅁R<Ub- }6K,jM6= \ZyϜhě״@ӷ<]c[.$nn.kPSXb̧,>JBr"HW#%͎"lQVWP|:&2놮2lXhQ*_l}>;ankv(#9+^=Wv]xI*5Yf:jE]6<CɰUpfԽ>X l*>J?I5t_DQ/ybz}! 3r_Pc55!6ݥ%O:OE}& q0>AZG FPb'?7].;BBLNrH5 0#WxƇv7.4ѶL fKMRiep!*(=a7j_[RP~/X\-' 0pؔX*y"4 :Xs\ 2,&ڈQEٛKy@i?0kLL223mT<ܕE \ބF3i8E;|Q`qLSzL~ñ"di'2%dGL;Ē]Ԝ nu2VS`{}/93ʀUA;FHpHŒߗJKI SC0?!RbG ?+hBJP^Xԯd$xOy_<\f83}׋z'nb~&d(v&  euwV鰔חJ:(jiu;Plq}GAFk3чL6Ed[T MѴK׏ jļ$HWGW39Ǔj1|okźP+NQk5:<:_M{B\]wjaX)$2 LA;Ld_xqi[Z"dGex|au7iv3j,?ҕWϻn EO2!ؘK+ŕ@JIFkJz}%La b)ZUKo$.fOoxE!pm -ձ%ۖq.Cy{R.3U+"zxvo oL/{?KxR.MdK`P4J׀;{p ~%v(s=1. ͬSxz`J%Q1xl0B0* aA C+vgyڮPU]l!M]9kg^eVeceČ74gߔD$JQU 4C /-7? 9_L;J-C\ց哵V#Gp&dnYyKN \ٝx`%H6 ]26ҀMݴd$ؖd"wW:jd"r38mu:]',U34Pq xj:]yZNХ<~Y68tJ c>vF~:m}mK~p)0Py(ؖ S c'Dp:p,򍔠fzv)y Ǟ z:${MOEwF] Kǟ(Os|3cxH_27a0>/G!oOʤ7(HSpY!]vrݳ|'KPUP{*@S $ ,V|SzU`jp߁ဓ,Э89J'_G{ixe$a-.yߝ~,, dDVO!t_6tMaw}̲60 a#væXB`rnEД?ٯ!0? ;C4mˠdI*L2 `ɗCp/<1g&9tKlÛJ<[cPgq'20lJE.juر Py6* HG`QQ̏'~_uO]}$z7MKa]8B0YhVȨJFw}Im=G+3$M99Z΢Gc",֕eGnN(X6|l0a.cb7꣯WO}hW6DMɤQZp* mDtG$Ob}c,YkoϮ]Vb~"f)Ӹ;1oR*jAUqm :00q}>u۵!Fl嵆f!C>j?R//ULƋf"Ztngrѝk 欼E!k"?| geǐtװYʇpUp(#S ky:S ϕ}:}vb ;Ҧ k1؃B+ $ ӗ~V]F"Ƿ r[nr~f%q=Jd׍|ePٷc'MdQnt6⡜V)Ʌ|&=9*E&cwg7&H/&?BXWR,=^mN1Ǟ}SKYR|] j̘ЩOa쯤عpY5&Rו L:7JiYOJCSF.) ה~"ܭr7m7r%0ucC!2\^qHBHl D9 nSyfE*'^#QbL+pÿo>zW-`10 *9PuZ9AUI?5Z5t1[24J   {qegb@7c]Q(k΄D'#[ĹCK1(zf߲/oy0q<9\`\H(1Т:I)(j2J7o:cɄў@/bO=̛4R %/3&aqr/%lwI TN5 s&~[F _Qlf)3|Ps1ȋIXa[:ZeǎpcGIZݢ3^> YP{^FtCT+={;I~ }xxlҨpbv)=s~0 sU[2*[vغQBN/U#dv * /# iMv& "}3*d3|ڗRQ`"V Bqɂ$e8 *8ixS[t^,R*j4<;N~`[:fLHx=_+L?G cvDq5^+.Lⵔp ϼS[ u/ɞ L}{#/f+ښ^F^oV=Z;.o|E}›:=*&>r}ōyhVd^g kq^5U^IfHZV?4a56M>ֆ?n#f\RXBK_(*w(p8˴:A;-ۙw@X0k!\$;(&0> ifM=BNTT2 :? ׬fee>2%[Qq,*9)?WBg slU|z^ L$&[ #:tⰛ~|$A1Ex{ۊt-A&,]4N#g*Tg>Г?tƺ gmM\agFXVzEϲpP)@7|M+tGǂ+]GKk)\8^`]c2 +:▇̜,U(O,%M8MovjpL!5ŴYQQ7fi5lcvT'(3'v }/&^.P$eoֈ_d߹~{DɿӗI/kLR^G;# )_exAlc&}]|/^)!ot!/V,=S񞂐iux$v{LE?XeЧ%\_]j[BS0 PaYɳ+:B0HDiA[Q)SY0S%~ۀ!̊xV>8rʖ`p@Z.Ɖ@#\Fa{ Y UEsgV0g*#_ndc̴n>e )/>F=5[Lf1qU}ec|!D_k

w-o&x&n 7铥$ɸW2:r ])۪PE;?B nCaFlZKkrgj98}=F@h"Q:^և[Bk顈"NHG =GG^sUV5xY/x[L%Wpێ4(Q-|KWYD~lulF }akW)5TE-~;a#PJemK-7eű"Dnn4 a + f ##Td=CDpHlB5Ia# )b=C9Pɠ,vf문x_Uϓ~Z!e8eyg1R@3'b.d_OJOE;eGW&Z_l<K-g-_e>w ϣ&AAK3L˅bkg}҇jo}\{s+6%ڊޫͥ?ByVo2X)|ʕ;UZ Xٚđ&!G':鵳LOgRa6r!Ď䐥i8Lā ׋)h$YUӒT`[fJbKVۋjS+Y%^]Rq4B<$fj3uFg+hb}~ʜ&,:rrU I 历2sYdR3 x3Pj(7^Xfmi] xi Ր0 >^ =G[Oryz]uUϩE^OUД 8lJ7}dF;Dkwt9\bVCΜJچ/P1DӚ vmp?CYt%V8)!n 9[6ZAb6Sϒb֗mYi `mwf]x";K=L~Erܼ ik 8i2 qEž(vf՝:zHoYCfW*cHܒ M@&VirXzC!)H3@$ &d_#]vR7ÕUء75x`  #t0QKʤ9R^gޜ rHեG/xucHR#6{gKݳLzqd4$z}?Xp-=="fMҔK2&n<9X ϙA R.s̭Y}"J2SzPYD@셼9]_%D&<'!—fEmd{f$?T}&yEh2JS"5ʡ)#}_afjG hXY^`5hKLѷjlऍ7No`rɽ3$tCKnPǢ1g_gO @E䷾E;NPY#yk:tsd]5ܝFc_l 3KK<,j*I׏1{[9*ƪ'a;x?Uk'DqQ ELŜSìzweAV ݲLհ/<6{ ߣ}a&=|] 1@l|\zyI B,̩MBMy/MӏF6u!@JԱs8ۋ^c{Q/q0 g4'ӫQlXF'x753/V8mŒ֛YeQŅKGK򊝭Ώy>ig]=v]:*m`\8<(~bg/Tem_/Έ."[L͞⨆9v ~aTTS`GjgޓzoR`EHWBO{jR*vXmo34t/nN"zR#r]$}@W+bɷBg <=j@!IGy77 t{Ȝ8 4'̛t6(W| 6FEwqտLKJ'̵֭#) 05!FYަeeFYrrQ BkR,UB*?׷ꙖIkAɻT%E A3=+`_ܮrvRA,Mj?L> (tYeÑz"P܊ Ч}K V,#rw~SsW[Bs]=%jea.4_h1pL-N6N ?r]- ,ng;xY㎋6F!e/G& [y pc@E&hPJűXXqSsvD&w>h><(ԛA'XvMOhjx\ŇPZɪ<+nGILE  Awnl26 BeS8nIk6?r` #lO^a<`-sػD ij[:8Ts H['@uMYm_Fwtܟ}8xȊ2z8SHO"2:)cBIf|̛0Ɯ5!.J3%q[}}˟L0S] b(% d!] T?߄bVlO|n3^ũzh" E-g UrJOj3@n0+.5qU+Z:oE6W"G+aTzV5kzxisehHu?׸#R4q#ɮ @ͫ `բ2,k+Če2-{ T.L>pmcpO罓뇤MVf9Bw%{Db7`paG{4O0d-7;5w0h} YZ