libapparmor1-3.0.4-150500.9.1 >  A cHp9|8PGS 8OM!4dOcSFp%61%+[yV an1\(EJitA\G2vRSeIPqA+kyG;f$CFN[Go`_ANz.x1wkѺ .dKZ%c)5g@|V0.t`=2FM Q!&UC[cdԎVbedf4fa4e8e3e2a5f14b5dc49fcb24d7abea16ffec41f200e7bbf0d7f8cc7e4dbdc59a8ea5ac97ed61657e995e9091b0a2df4b024cHp9|/M]wsƟ2F"ٽ6JӤo/?_#:$9X<w8hI䔤7N[Kć"{Ҳz|v `>8׫(ۋȞ)aQ% }0\.w=Ӆorp2NHӾu`oOeȢ-UOj3/ knۦU١bL&DK6"lCz#k5<+#^sxЭGna5䜁Yre& ڄ|zImd2}\L>pCp?`d  = %FX n     $.8`h0xI(s8|}9p}:}>@BFGHIXY@Zt[x\|]^bc_defluvwtx|yz\Clibapparmor13.0.4150500.9.1Utility library for AppArmorThis package provides the libapparmor library, which contains the change_hat(2) symbol, used for sub-process confinement by AppArmor, as well as functions to parse AppArmor log messages.c-s390zl36ZSUSE Linux Enterprise 15SUSE LLC LGPL-2.1-or-laterhttps://www.suse.com/System/Librarieshttps://launchpad.net/apparmorlinuxs390xZc(c(386dd42744dc214c872fe5aa2e62139c59fdfd6f9c5e12c9f57a7d8e097a9fa8libapparmor.so.1.8.2rootrootrootrootlibapparmor-3.0.4-150500.9.1.src.rpmlibapparmorlibapparmor.so.1()(64bit)libapparmor.so.1(APPARMOR_1.0)(64bit)libapparmor.so.1(APPARMOR_1.1)(64bit)libapparmor.so.1(APPARMOR_2.10)(64bit)libapparmor.so.1(APPARMOR_2.11)(64bit)libapparmor.so.1(APPARMOR_2.13)(64bit)libapparmor.so.1(APPARMOR_2.13.1)(64bit)libapparmor.so.1(APPARMOR_2.9)(64bit)libapparmor.so.1(APPARMOR_3.0)(64bit)libapparmor.so.1(IMMUNIX_1.0)(64bit)libapparmor.so.1(PRIVATE)(64bit)libapparmor1libapparmor1(s390-64)@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.2.3)(64bit)libc.so.6(GLIBC_2.26)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3c@cbk@bi0@bZbV@bT@bRbBb<]@b@a7aZ@ap@aabaim@aEaaua $@`#@` @````_@`%@`!'`>` @__ǁ_ǁ_Q_h__@_~@_[f_P_-B@_@^m@^@^<@^j$@^,-]҇]o](]K@]]@\\@\ \\v{\I\ include in apache extra profile optional to avoid problems with empty profile directory (boo#1178527)- prepare usrmerge (boo#1029961) * use %_pamdir- update to AppArmor 3.0.1 - minor additions to profiles and abstractions - some bugfixes in libapparmor, apparmor_parser and the aa-* utils - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0.1 for the detailed upstream changelog - removed upstream(ed) patches: - changes-since-3.0.0.diff - extra-profiles-fix-Pux.diff - utils-fix-hotkey-conflict.diff- Use apache provided variables for the module_directry: + Use %apache_libexecdir + Add apache-rpm-macros BuildRequires- add utils-fix-hotkey-conflict.diff to fix a hotkey conflict in de, id and sv translations (and fix the test) (MR 675) - add extra-profiles-fix-Pux.diff to fix an inactive profile - prevents a crash in aa-logprof and aa-genprof when creating a new profile (MR 676)- update to AppArmor 3.0.0 - introduce feature abi declaration in profiles to enable use of new rule types (for openSUSE: dbus and unix rules) - support xattr attachment conditionals - experimental support for kill and unconfined profile modes - rewritten aa-status (in C), including support for new profile modes - rewritten aa-notify (in python), finally dropping the perl requirement at runtime - new tool aa-features-abi for extracting feature abis from the kernel - update profiles to have profile names and to use 3.0 feature abi - introduce @{etc_ro} and @{etc_rw} profile variables - new profile for php-fpm - several updates to profiles and abstractions (including boo#1166007) - fully support 'include if exists' in the aa-* tools - rewrite handling of alias, include, link and variable rules in the aa-* tools - rewrite and simplify log handling in the aa-logprof and aa-genprof - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0 for the detailed upstream changelog - patches: - add changes-since-3.0.0.diff with upstream fixes since the 3.0.0 release up to 3e18c0785abc03ee42a022a67a27a085516a7921 - drop upstreamed usr-etc-abstractions-base-nameservice.diff - drop 2.13-only libapparmor-so-number.diff - refresh apparmor-enable-profile-cache.diff - partially upstreamed - update apparmor-samba-include-permissions-for-shares.diff and apparmor-lessopen-profile.patch - switch to "include if exists" - apparmor-lessopen-profile.patch: add abi rule to lessopen profile - refresh apparmor-lessopen-nfs-workaround.diff - move away very loose apache profile that doesn't even match the apache2 binary path in openSUSE to avoid confusion (boo#872984) - move rewritten aa-status from utils to parser subpackage - add aa-features-abi to parser subpackage - replace perl and libnotify-tools requires with requiring python3-notify2 and python3-psutil (needed by the rewritten aa-notify) - drop ancient cleanup for /etc/init.d/subdomain from parser %pre - drop (never enabled) conditionals to build with python2 and to build the python-apparmor subpackage (upstream dropped python2 support) - drop setting PYTHON and PYTHON_VERSIONS env variable, no longer needed - set PYFLAKES path for utils check - add precompiled_cache build conditional to allow faster local builds without using kvm - remove duplicated BuildRequires: swig- update to AppArmor 2.13.5 - add missing permissions to several profiles and abstractions - bugfixes in parser and tools - fix two potential build failures in libapparmor - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5 for the detailed upstream changelog - remove upstream(ed) patches - changes-since-2.13.4.diff - abstractions-X-xauth-mr582.diff - sevdb-caps-mr589.diff - libvirt-leaseshelper.patch - cap_checkpoint_restore.diff - add libapparmor-so-number.diff to fix libapparmor so version (!658)- add CAP_CHECKPOINT_RESTORE to severity.db (MR 656, cap_checkpoint_restore.diff)- %service_del_postun_without_restart only works for Tumbleweed, keep using DISABLE_RESTART_ON_UPDATE for Leap 15.x- Make use of %service_del_postun_without_restart And stop using DISABLE_RESTART_ON_UPDATE as this interface is obsolete.- libvirt-leaseshelper.patch: add /usr/libexec as a path to the libvirt leaseshelper script (jsc#SLE-14253)- sevdb-caps-mr589.diff: add new capabilities CAP_BPF and CAP_PERFMON to severity.db (lp#1890547)- add abstractions-X-xauth-mr582.diff to allow reading the xauth file from its new sddm location (boo#1174290, boo#1174293)- add changes-since-2.13.4.diff with upstream changes and fixes since 2.13.4 up to 5f61bd4c: - add several abstractions related to xdg-open: dbus-network-manager-strict, exo-open, gio-open, gvfs-open, kde-open5, xdg-open - introduce @{run} variable - update dnsmasq and winbindd profile - update mdns, mesa and nameservice abstraction - some bugfixes in the aa-* tools, including a remote bugfix in the YaST AppArmor module (boo#1171315) - drop upstream(ed) patches (now part of changes-since-2.13.4.diff): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-fix-utils-network-test.diff - make-4.3-network.diff - abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch - apply usr-etc-abstractions-base-nameservice.diff only for Tumbleweed, but not for Leap 15.x where it's not needed - refresh usr-etc-abstractions-base-nameservice.diff- Add abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch (bsc#1168306)- fix build with make 4.3 by backporting some commits from upstream master (boo#1167953): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-network.diff - make-4.3-fix-utils-network-test.diff- update to AppArmor 2.13.4 - several abstraction updates (including boo#1153162) - disallow writing to fontconfig cache in abstractions/fonts - some bugfixes in the aa-* tools - fix log parsing for logs with an embedded newline - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4 for the detailed upstream changelog - drop upstreamed patches: - abstractions-ssl-certbot-paths.diff - apparmor-krb5-conf-d.diff - libapparmor-python3.8.diff - usr-etc-abstractions-authentification.diff - refresh usr-etc-abstractions-base-nameservice.diff- add usr-etc-abstractions-base-nameservice.diff to adjust abstractions/base and nameservice for /usr/etc/ (boo#1161756)- Properly pull in full python3 interpreter- add libapparmor-python3.8.diff to fix building the libapparmor python bindings (deb#943657)- add usr-etc-abstractions-authentification.diff to allow reading /usr/etc/pam.d/* and some other authentification-related files (boo#1153162)- add abstractions-ssl-certbot-paths.diff - add certbot paths to abstractions/ssl_certs and abstractions/ssl_keys- add apparmor-krb5-conf-d.diff for kerberos client- update to 2.13.3 - profile updates for dnsmasq, dovecot, identd, syslog-ng - new "lsb_release" profile (only used when using "Px -> lsb_release") - fix buggy syntax in tunables/share - several abstraction updates - parser: fix "Px -> foo-bar" (the "-" was rejected before) - several bugfixes in aa-genprof and aa-logprof - some fixes in cache handling - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3 for the detailed upstream changelog - drop upstream(ed) patches: - apparmor-nameservice-resolv-conf-link.patch - profile_filename_cornercase.diff - dnsmasq-libvirtd.diff - dnsmasq-revert-alternation.diff - usrmerge-fixes.diff - libapparmor-swig-4.diff - re-number remaining patches- add upstream libapparmor-swig-4.diff: fix libapparmor tests with swig 4.0 (boo#1135751)- Disable LTO (boo#1133091).- update lessopen.sh profile for usrMerge (bash and tar) (boo#1132350)- add usrmerge-fixes.diff: fix test failures when /bin/sh is handled by update-alternatives (boo#1127877)- add dnsmasq-revert-alternation.diff: revert path alternation in dnsmasq profile and re-add peer=/usr/sbin/libvirtd rules to avoid breaking libvirtd (boo#1127073)- add dnsmasq-libvirtd.diff: allow peer=libvirtd in the dnsmasq profile to match the newly added libvirtd profile name (boo#1118952#c3)- Use %license instead of %doc [bsc#1082318]- add apparmor-lessopen-nfs-workaround.diff: allow network access in lessopen.sh for reading files on NFS (workaround for boo#1119937 / lp#1784499)- add profile_filename_cornercase.diff: drop check that lets aa-logprof error out in a corner-case (log event for a non-existing profile while a profile file with the default filename for that non-existing profile exists) (boo#1120472)- netconfig: write resolv.conf to /run with link to /etc (fate#325872, boo#1097370) [patch apparmor-nameservice-resolv-conf-link.patch]- update to AppArmor 2.13.2 - add profile names to most profiles - update dnsmasq profile (pid file and logfile path) (boo#1111342) - add vulkan abstraction - add letsencrypt certificate path to abstractions/ssl_* - ignore *.orig and *.rej files when loading profiles - fix aa-complain etc. to handle named profiles - several bugfixes and small profile improvements - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.2 for the detailed upstream changelog - remove upstreamed fix-syntax-error-in-rc.apparmor.functions.patch- update to 2.13.1 - add qt5 and qt5-compose-cache-write abstractions - add @{uid} and @{uids} kernel var placeholders - several profile and abstraction updates - ignore "abi" rules in parser and tools (instead of erroring out) - utils: fix overwriting of child profile flags if they differ from the main profile - several bugfixes (including boo#1100779) - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.1 for the detailed upstream changelog - remove upstream(ed) patches: - aa-teardown-path.diff - fix-apparmor-systemd-perms.diff - logprof-skip-cache-d.diff - fix-samba-profiles.patch - make-pyflakes-happy.diff - dnsmasq-Add-permission-to-open-log-files.patch - refresh apparmor-samba-include-permissions-for-shares.diff - add fix-syntax-error-in-rc.apparmor.functions.patch- update rpmlintrc: - whitelist .features file which is part of the pre-compiled cache - comment out filters for the disabled tomcat_apparmor subpackage- Backport dnsmasq fix: 025c7dc6 - dnsmasq-Add-permission-to-open-log-files.patch (boo#1111342)- add make-pyflakes-happy.diff to fix an unused variable (SR 629206)- add fix-samba-profiles.patch - smbd loads new shared libraries. Allow winbindd to access new kerberos credential cache location (boo#1092099)- exclude the /etc/apparmor.d/cache.d/ directory from aa-logprof parsing (logprof-skip-cache-d.diff)- add fix-apparmor-systemd-perms.diff - fix permissions of /lib/apparmor/apparmor.systemd (boo#1090545)- create and package precompiled cache (/usr/share/apparmor/cache, read-only) (boo#1069906, boo#1074429) - change (writeable) cache directory to /var/cache/apparmor/ - with the new btrfs layout, the only reason for using /var/lib/apparmor/cache/ (which was "it's part of the / subvolume") is gone, and /var/cache makes more sense for the cache - adjust parser.conf (via apparmor-enable-profile-cache.diff) to use both cache locations - clear cache also in %post of abstractions package- update to AppArmor 2.13 - add support for multiple cache directories and cache overlays (boo#1069906, boo#1074429) - add support for conditional includes in policy - remove group restrictions from aa-notify (boo#1058787) - aa-complain etc.: set flags for profiles represented by a glob - aa-status: split profile from exec name - several profile and abstraction updates - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13 for the detailed upstream changelog - drop upstreamed patches and files: - aa-teardown - apparmor.service - apparmor.systemd - 32-bit-no-uid.diff - disable-cache-on-ro-fs.diff - dovecot-stats.diff - parser-write-cache-warn-only.diff - set-flags-for-profiles-represented-by-glob.patch - fix-regression-in-set-flags.patch - drop spec code that handled installing aa-teardown, apparmor.service and apparmor.systemd (now part of upstream Makefile) - simplify "make -C profiles parser-check" call (upstream Makefile bug that required to call "cd" was fixed) - add aa-teardown-path.diff - install aa-teardown in /usr/sbin/ - move 'exec' symlink to parser package (belongs to aa-exec)- Set flags for profiles represented by glob (bsc#1086154) set-flags-for-profiles-represented-by-glob.patch fix-regression-in-set-flags.patch- add dovecot-stats.diff: - add dovecot/stats profile and allow dovecot to run it (boo#1088161) - allow dovecot/auth to write /run/dovecot/old-stats-user (part of boo#1087753) - update 32-bit-no-uid.diff with upstream fix- Change of path of rpm in lessopen.sh (boo#1082956)- add disable-cache-on-ro-fs.diff - disable write cache if filesystem is read-only and don't bail out (bsc#1069906, bsc#1074429)- add parser-write-cache-warn-only.diff to make cache write failures a warning instead of an error (boo#1069906, boo#1074429) - reduce dependeny on libnotify-tools (used by aa-notify -p) to "Suggests" to avoid pulling in several Gnome packages on servers (boo#1067477)- update to AppArmor 2.12 - add support for 'owner' rules in aa-logprof and aa-genprof - add support for includes with absolute path in aa-logprof etc. (lp#1733700) - update aa-decode to also decode PROCTITLE (lp#1736841) - several profile and abstraction updates, including boo#1069470 - preserve errno across aa_*_unref() functions - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.12 for the detailed upstream changelog - drop upstreamed patches: - read_inactive_profile-exactly-once.patch - utils-fix-sorted-save_profiles-regression.diff - lessopen profile: change all 'rix' rules to 'mrix' - add 32-bit-no-uid.diff to fix handling of log events without ouid on 32 bit systems - no longer package static libapparmor.a- update to AppArmor 2.11.95 aka 2.12 beta1 - add JSON interface to aa-logprof and aa-genprof (used by YaST) - drop old YaST interface code - update audio, base and nameservice abstractions - allow @{pid} to match 7-digit pids - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_95 for the detailed upstream changelog - drop upstreamed patches - apparmor-yast-cleanup.patch - apparmor-json-support.patch - nameservice-libtirpc.diff - drop obsolete perl modules (YaST no longer needs them) - drop patches that were only needed by the obsolete perl modules: - apparmor-utils-string-split - apparmor-abstractions-no-multiline.diff - drop profiles-sockets-temporary-fix.patch - obsoleted by a fix in apparmor_parser - refresh utils-fix-sorted-save_profiles-regression.diff - add aa-teardown (new script to unload all profiles) - make ExecStop in apparmor.service a no-op (workaround for a systemd restriction, see boo#996520 and boo#853019 for details) - lessopen profile: allow capability dac_read_search and dac_override, allow groff to execute several helpers (boo#1065388)- read_inactive_profile-exactly-once.patch (bsc#1069346) Perform reading of inactive profiles exactly once.- update to AppArmor 2.11.1 - add permissions to several profiles and abstractions (including lp#1650827 and boo#1057900) - several fixes in the aa-* tools (including lp#1689667, lp#1628286, lp#1661766 and boo#1062667) - fix downgrading/converting of 'unix' rules (will be supported in kernel 4.15) to 'network unix' rules in apparmor_parser (boo#1061195) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_1 for upstream changelog - remove upstream(ed) patches - upstream-changes-r3616..3628.diff - upstream-changes-r3629..3648.diff - parser-tests-dbus-duplicated-conditionals.diff - apparmor-fix-podsyntax.patch - sshd-profile-drop-local-include-r3615.diff - refresh apparmor-yast-cleanup.patch - add utils-fix-sorted-save_profiles-regression.diff to fix a regression in displaying the "changed profiles" list in aa-logprof- add nameservice-libtirpc.diff to fix NIS/YP logins (boo#1062244)- profiles-sockets-temporary-fix.patch to cater to nameservices with the new sockets mediation, until unix rules are upstreamed (boo#1061195)- add apparmor-fix-podsyntax.patch from mailing list to fix compilation with perl 5.26- do not require exact X.Y version of "python3" - require also matching python(abi) which is arguably more important- don't rely on implementation details for reload in %post- add JSON support. Required for FATE#323380. (apparmor-yast-cleanup.patch, apparmor-json-support.patch)- add upstream-changes-r3629..3648.diff: - preserve unknown profiles when reloading apparmor.service (CVE-2017-6507, lp#1668892, boo#1029696) - add aa-remove-unknown utility to unload unknown profiles (lp#1668892) - update nvidia abstraction for newer nvidia drivers - don't enforce ordering of dbus rule attributes in utils (lp#1628286) - add --parser, --base and --Include option to aa-easyprof to allow non-standard paths (useful for tests) (lp#1521031) - move initialization code in apparmor.aa to init_aa(). This allows to run all utils tests even if /etc/apparmor.d/ or /sbin/apparmor_parser don't exist. - several improvements in the utils tests - drop upstreamed python3-drop-re-locale.patch - no longer delete/skip some of the utils tests (to allow this, add parser-tests-dbus-duplicated-conditionals.diff) - add var.mount dependeny to apparmor.service (boo#1016259#c34)- Cleanup spec file: - don't use insserv if we afterwards call systemd, this can have bad side effects - remove dead code - remove now obsolete 'distro' checks - Replace init.d script with new wrapper working with systemd- add python3-drop-re-locale.patch: remove deprecated re.LOCALE flag in Python UI as it was dropped from Python 3.6 (lp#1661766)- Fix RPM groups- add upstream-changes-r3616..3628.diff: - update abstractions/base, abstractions/apache2-common and dovecot profiles - merge ask_the_questions() of aa-logprof and aa-mergeprof - pass LDFLAGS when building parser, libapparmor perl bindings and pam_apparmor - adjust deleting the cache in profiles %post to the new cache location - silence errors when deleting the cache (boo#976914)- split libapparmor into separate spec to get rid of build loop involving mariadb, systemd, apparmor, libapr and mariadb again (see the discussion in SR 448871 for details) - libapparmor.spec is based on the AppArmor 2.11 apparmor.spec, but with minimum BuildRequires- update to AppArmor 2.11.0 - apparmor_parser now supports parallel compiles and loads - add full support for dbus, ptrace and signal rules and events to the utils - full rewrite of the file rule handling in the utils - lots of improvements and fixes - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11 for the detailed changelog - patches: - add sshd-profile-drop-local-include-r3615.diff to fix 'make check' - drop aa-unconfined-fix-netstat-call-2.10r3380.diff, no longer needed - refresh apparmor-abstractions-no-multiline.diff - refresh apparmor-samba-include-permissions-for-shares.diff - spec changes: - aa-unconfined switched to using ss (from iproute2), adjust Recommends: - move libapparmor to /usr/lib*/ - drop %if %suse_version checks for 12.x - change several Obsoletes from %version to < 2.9. Those package names weren't used since years, and 2.9 is still a careful choice - include apparmor.service independent of %suse_version - techdoc.pdf is now shipped in upstream tarball to reduce BuildRequires - drop latex2html, texlive-* and w3m BuildRequires - techdoc.txt and techdoc.html not included, drop them from the package - run most of utils/ make check (some tests expect /etc/apparmor.d/ and /sbin/apparmor_parser to exist, skip them) - BuildRequires python3-pyflakes (utils tests) and dejagnu (libapparmor tests) - drop sed'ing python3 into aa-* shebang (upstreamed) - build binutils - aa-exec is now written in C and lives in /usr/bin/, move it to the apparmor_parser package and create a compability symlink in /usr/sbin/ - aa-exec manpage moved to section 1 - aa-enabled is a small new tool to find out if AppArmor is enabled - package new aa_stack_profile(2) manpage- change /etc/apparmor.d/cache symlink to /var/lib/apparmor/cache/. This is part of the root partition (at least with default partitioning) and should be available earlier than /var/cache/apparmor/ (boo#1015249, boo#980081, bsc#1016259) - add dependency on var-lib.mount to apparmor.service as safety net- update to AppArmor 2.10.2 maintenance release - lots of bugfixes and profile updates (including boo#1000201, boo#1009964, boo#1014463) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_2 for details - add aa-unconfined-fix-netstat-call-2.10r3380.diff to fix a regression in aa-unconfined - drop upstream(ed) patches: - changes-since-2.10.1--r3326..3346.diff - changes-since-2.10.1--r3347..3353.diff - libapparmor-fix-import-path.diff (upstream fix is slightly different) - nscd-var-lib.diff - refresh apparmor-abstractions-no-multiline.diff- add nscd-var-lib.diff to allow /var/lib/nscd/ in the nscd profile and abstractions/nameservice (path changed in latest nscd in Tumbleweed)- add changes-since-2.10.1--r3347..3353.diff with upstream changes and fixes in the 2.10 branch, including - allow writing *.qf files (for disk-based buffering) in syslog-ng profile - add several permissions to the dovecot profiles (deb#835826) - add a missing path in the traceroute profile- add changes-since-2.10.1--r3326..3346.diff with upstream changes and fixes since the 2.10.1 release, including - allow dac_override in winbindd profile (boo#990006#c5) - allow mr for /usr/lib*/ldb/*.so in samba abstractions (needed since Samba 4.4.x, boo#990006) - abstractions/nameservice: also support ConnMan-managed resolv.conf - let aa-genprof ask about profiles in extra dir (again) - fix aa-logprof "add hat" endless loop (lp#1538306) - honor 'chown' file events in logparser.py - ignore log file events with a request mask of 'send' or 'receive' because they are actually network events (lp#1577051, lp#1582374) - accept hostname with dots when parsing logs (lp#1453300 comments #1 and #2) - fix python LibAppArmor import failures with swig > 3.0.8 (boo#987607) (libapparmor-fix-import-path.diff) - refresh apparmor-abstractions-no-multiline.diff - drop upstreamed profiles-ping-inet6-r3449.diff - add %check section - runs libapparmor (including swig bindings), parser and profiles tests - add BuildRequires: perl(Locale::gettext) - needed for parser tests- add profiles-ping-inet6-r3449.diff - latest ping also does IPv6 (boo#980596)- update to AppArmor 2.10.1 (2.10 branch r3326): - fix incorrect output of child profile names (apparmor_parser -N) which caused 'rcapparmor reload' to remove child profiles and hats (lp#1551950) - fix a crash in aa-logprof / logparser.py for change_hat log events (lp#1523297) and log events that look like file events, but aren't (lp#1540562, lp#1525119, lp#1466812) - write unix rules when saving a profile (lp#1522938, boo#954104#c3) - several fixes for variable handling in aa-logprof - map c (create) log events to w instead of a - add python to the "no Px rule" list in logprof.conf - let aa-logprof check for duplicate profiles - let aa-status work without the apparmor.fail python module (boo#971917, lp#1480492) - add permissions in several profiles (including boo#948584, boo#948753, boo#954959, boo#954958, boo#971790, boo#964971, boo#921098, boo#923201 and boo#921098#c15). - and many more fixes, see the full changelog at http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_1 - drop upstream(ed) patches: - fix-initscript-aa_log_end_msg.diff - syslog-ng-profile-boo948584.diff - upstream-profile-updates-r3205-3241.diff - refresh patches: - apparmor-abstractions-no-multiline.diff - apparmor-samba-include-permissions-for-shares.diff - drop libapparmor autogen.sh call (broke the build) and remove libtool BR- add syslog-ng-profile-boo948584.diff - add several permissions needed by latest syslog-ng (boo#948584, boo#948753) - add upstream-profile-updates-r3205-3241.diff with several profile updates: - add /usr/share/locale-bundle/** to abstractions/base - allow dnsmask to use /bin/sh (boo#940749) and /bin/dash - allow dovecot imap to read /run/dovecot/mounts - allow avahi-daemon to write to /run/systemd/notify - allow ntpd to read $PATH directory listings (boo#945592, boo#948752) - update dhclient profile - allow skype to read @{PROC}/@{pid}/net/dev (boo#939568) - and some other small updates - drop upstreamed apparmor-winbindd-r3213.diff (included in the upstream-profile-updates patch)- netstat moved to net-tools-deprecated in Tumbleweed (boo#944904)- add apparmor-winbindd-r3213.diff - add missing k permissions for /etc/samba/smbd.tmp/msg/* in winbindd profile (boo#921098 #c15..19)- add fix-initscript-aa_log_end_msg.diff - fixes ugly initscript output (boo#862170)- update to AppArmor 2.10 (trunk r3205) - profile names can now contain variables - improved profile compile time in apparmor_parser - lots of improvements, refactoring and bugfixes in the aa-* tools - new apis for managing and loading profile caches into the kernel in libapparmor - lots of profile updates - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10 for the complete changelog with more details - add new apparmor_private.h and the aa_query_label(2), aa_features(3), aa_kernel_interface(3), aa_policy_cache(3), aa_splitcon(3) manpages to libapparmor-devel - drop apparmor-2.5.1-edirectory-profile patch - it's most probably no longer needed (see boo#621394 for details) - drop upstreamed samba-4.2-profiles.diff - refresh apparmor-samba-include-permissions-for-shares.diff- systemd-rpm-macros and %systemd_requires were at the wrong place, move them to the parser package (boo#931792)- update to AppArmor 2.9.2 (2.9 branch r2911) - lots of bugfixes in the parser and the aa-* tools (including boo#918787) - update dovecot and dnsmasq profiles and several abstractions (including boo#911001) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_2 for the full changelog - remove upstream(ed) patches apparmor-changes-since-2.9.1.diff and apparmor-fix-stl-ostream.diff - replace GPG key with new AppArmor GPG signing key, see https://launchpad.net/apparmor/+announcement/13404- make sure %service_del_postun doesn't call systemctl try-restart (boo#853019, bare systemd edition) - add samba-4.2-profiles.diff: update samba (winbindd and nmb) profiles for samba 4.2 (boo#921098, boo#923201)- only install apparmor.service for openSUSE > 13.2- Add a native systemd unit which *at the moment* only wraps/masks the early boot script.- add apparmor-fix-stl-ostream.diff which fixes odd uses of std::ostream which are not valid. Fixes build with GCC 5- allow lessopen.sh to run /usr/bin/unzip-plain (boo#906858)- add Requires: python3 to python3-apparmor package - readline isn't part of python3-base (boo#917577)- add apparmor-changes-since-2.9.1.diff with upstream fixes since the 2.9.1 release - update logparser.py to support changed syslog format (lp#1399027) - update usr.sbin.dovecot and usr.lib.dovecot.imap{, -login} profiles (lp#1296667) - update the mysqld profile - fix network rule description in apparmor.d(5) manpage - drop upstreamed dnsmasq-profile-fixes.patch - update expired GPG key- update to AppArmor 2.9.1 (2.9 branch r2831) - fix log parsing for 3.16 kernels and syslog-style logs (boo#905368) - several fixes and performance improvements in the aa-* utils - profile updates for dnsmasq (boo#907870), nscd (boo#904620#c14 and bnc#908856), useradd, sendmail, man and passwd - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_1 for full release notes - refresh dnsmasq-profile-fixes.patch- Fix dnsmasq profile to allow executing bash to run the --dhcp-script argument. Also fixed /usr/lib -> /usr/{lib,lib64} to get libvirt leasehealper script to run even on x86_64. dnsmasq-profile-fixes.patch. boo#911001- rename lessopen.sh profile file to usr.bin.lessopen.sh to match the script filename- add apparmor-lessopen-profile.patch: /usr/bin/lessopen.sh needs confinement. bnc#906858- delete cache in apparmor-profiles %post (workaround for bnc#904620#c8 / lp#1392042)- No longer perform gpg validation; osc source_validator does it implicit: + Drop gpg-offline BuildRequires. + No longer execute gpg_verify.- fix bashism in post script- update to AppArmor 2.9.0 (r2759) - change aa-mergeprof to the final commandline syntax - lots of bugfixes in the aa-* tools (bnc#900163, lp#1328707 and several bugs without a formal bugreport) - small additions to gnome, freedesktop.org, ubuntu-browsers.d/java and user-mail abstractions - fix mod_apparmor to not break basic auth - update perl modules to support signal, unix and ptrace rules (bnc#900013) - don't warn about rules not supported by the kernel - fix logging of "audit capability" (lp#1378091) - add support for the "hat" keyword in apparmor.vim - build html version of apparmor.vim manpage again (lp#1366572) - see also http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_0 - update apparmor-abstractions-no-multiline.diff - remove upstreamed apparmor-profiles-ntpd-pid-location.diff/sbin/ldconfig/sbin/ldconfiglibapparmors390zl36 16741184453.0.43.0.4-150500.9.13.0.4-150500.9.12.9libapparmor.so.1libapparmor.so.1.8.2/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:SLE-15-SP5:GA/standard/5fe6c53300f77e4434023ba0c87090f2-libapparmorcpioxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=c3809cc7e325fef90593cd470aa567bf3d24ac32, strippedP PPPPPPPPPPPPPPP P P PR RRR RR RR RRR RPsgKI βutf-8a0ec095cdb31bc5fd776c055247b4bd7b652857447b414418b8b60cd8e16888f?7zXZ !t/\Ko+] cr$x#GUɦ#`=HgѿƞVbߓ)P^Ҋes)d\$Q6LlUy&oj}mo{X :O?5L_3h,XdF;u` ,?:׿_ٮ0HځYChkhI3L@j F%~_ C|R&iAÓW9_`Ȱڻ"A]N;Mu(Hl{hG<fqN(/6@)VPQ2K4'5A⌠听 x_6Ō5-soFvfHROH Sc[;Uל+Vajx샰~%‘it+M*wRUk 3-ɩڴ/3r-)W6wYS~=8E ВXdDdM"Bi]Y _楪/ǵgН~&pGܥgXcQ] *qĐ׾P2.o߯u I.'کՉH|QlvcJLfwq$}a~ m)A?c}6@ N^"i?h$torrcF(88%xP],,+jH!Xs=sqcP TuRfMHϛ`bׂi~a~ؔaڟVLU._StHi5E{l< ڴ)҂8݆i!`IW~s",%ߺ7䉶1~Shc2cx."b,ޣgDQdS>9sJ8ps adk꒥-hOzt]7Bfxn!h@e5Y3/pS9H#~ެʅ`|O!kL6b]lhc@w?{\`MT{Fg)oQu;HCjڔJٵt?L]@=ŕm&.i &4?<7R8tnR=U-\S)|ԡ^™8BMw&{ ýZeMe2 TBVjFoY[ t!Ywy/EрU3%F~ffG/) BRpm ']^o#o09e_J\BA&;*rMZJu7-~D X/$.R?G84_׳2y)9XlcdjRĥHUAIoi[Ʒ7/Te[ ulf!Vf;}zb ɬ1$6HS09ruvESDc M]kT.:+6b|>ϿQw%- | cM(㠱?|}4WB@G_sءA-Āee++Rj% Q0dYHv+Iݻ`N>GUX8\a:to lD4>,wVGB0@MڛOXDC1|Uz )'"(f|rC1R#"SwD#婏e}IJt6%2˔p~ģ *TPA@GGܟeR^3a/8YAwƔ'Qw%ݚoƜj'%@apvy躱# o&>tt;39kJ8qF9$ՙ,103iK֕ ֒AG Td/::ڛMh_|f}L*%%{ *Cԙ\VIX`r/GFopyzwsX?tr@Fcme(Ѕ'e35ٜ؜Fha{VyRz9 i}ԉ`)[y_M^xL= |6FrYg?簙Ul>L]1#4.UC}iS 9^ܾ\$y>a~w!_BϡjHS;=M&/ wϸ?&0ǽ{i(ώ[#ʿ!Mz˱$G;ͫ@䥌dܢ["~"p(ng7kB@R\ k?|$h:ҷs?2%M͹O@گWXW4$1$کi$'m:D)/cw, B֙,0(XUױZ]彚Wbi 3RlskWYJdix~:&@!>cafP[DRu8#wcJw(Fp#=]OXx&/TSZ@]a*N}w3㇙4}3^=~̖TF oS= u 0 q%uA~apdNۡ@EII#ӝ>d'ѡTy:@R%KZ=soX+>fHH#v[vԀ m'Ze2gK^Bx7<6V Gq\~Cq[_:%u *?mR9A[O/#*+8K]tWpm%T&_/Qei*L)! Ǘ,<_螖__Cpnpb1y/ "`ɰ0Wlڎ-RC@ ,_ѥd4uT9#naƬ!pOѩ>Wَ+@(G}$FN& .bA fc @ߜ?ᱷ %Ă"q բ^Z {daIP8ҌPdɎM_:ݮ=h=[[ j\ʏ\8To0 (b0uT;QLMyp} lnvw  @gyRDZ‘z c:{ω7ݮ쏪ȥgKCj8Z, L˓zD88qnbwfr Z˷IteUăʨG1>_6{<JRϪD8 )pRu_4dB0eRݑ;Yn+EbVD5>Ѩ;^qR/F'63/B д| p-6 _Ki AW?*8.nϮxv@@}IgqM5e$AN( էh-Nntۙbwibn3mzo#4QOylC2"||0Kw}{Vʀ D>-)'7 f6Ͳ?gzJˤ: !r}f4ЕdPV<>֓]sbq#JXU sdٛ׮y}yR(hً@_"75%bJvHGt)'n*YQ#:Xo"vcpMH Y\tjde;)vDsu~ם]!dNm_WPk1 3V†ּ,X7yvAck6d]r~;C %=!:?6$&'6 Rp"(}zoR; s׃**%'>Ÿi] &M.׈[l@9`ï @5R^p[;`Un1=b^y$b=Ԡ򞽩۲{<͵18F,i[՜1L, mÉM=YR9\QY%Fs^XA||B`#pkV&;{((+ n~z xu/ G m$\Ʃp ΐe?md pA> ( F+ы[-FyaT 6[Ĵ)4Mk[E&aCquG;T94vjT.|" EOZԛviW Ȍ⧩Rn}la2X8c9!!C x[Z4[ rTU^4. hI隈OlMPm7yu;Lr5x5Xku|sTn27Ay) lN՜Y.}@)9ɘ}lIRG[ZnutߠK֛#w/ᛪMw F`~c m!ruUx3j W|9^F#nȏg=фgU09Vk VwOkt˓4•xLYt$3B&T@U;glI6%r.|ZBh2J!NP똂O4wC K}(\8VK klC}Jːz1W!oqb@oV,fYDA_a;~|@Rĝ2 ;ۺ2Qbִ]Z%zS뻁i)EPQw \7H'e諘IЙ&Ϙd>zwӭ1 o>R^v/BOP8~  @SE[KcY YЙ<toz~[% eu i÷<^L\*E}6$w#sz3vnca9FVh {d~SqZ4k7 :1 8M<RpV] e(Y,?ϝ?T0dN#܈+Ǿ)Ϳ2),`LA+k^aaGtGf_t!`]ăŤqT!ْDW(SDv8Lg,e X:iJO g}[Pv`3qzǍz;#^Rb}|s$@fBhTzu\O= j~: HB ߯/Fu(L؏5Z~4&jU$[3acN9~^{~ [$QI?U9J!6C,&d:nhU29˒ҷmEq%7{\׌M~,v`ޜQbi0ɷ+sK|  B_= Xơ9c[@CU"!ԯ5HN]Ƶo!vVzF^'S 3f6QD -: Կ^w.voFnmM|tzi);c.x,>VϘސL2{ Ǥ:޻ֹEdϢPg5< [rx8RiΙ Ku.pKHTBs %]]~ٰ+ ϡOQ e_A (F?)/%w(5 [.Q0b "߭8=$g6&hr Īɣ{y՚v~pRz:d̃}Ƭ)cAΖ\I̿Lɓi7IFEYI8zBI~T,dE]~=ZA ,2U?e&Sѿs**lW)bPf`bnT\G)܊i@rNڪ}@y7FE*pf~tM %-<+Φe+ВظZJv -Z&Rd[ެo/;R*myKC#DQUX[F]{zq Gk)P3|~^wc0B{46>W!٧O5r}gO}pPsq. zo*Fb.0!p @1NٍTλ*,KF`r݅O&:#_zRc/b5~֣VQI"彿(_1qfmaxⴌ.}X8֍ h5~݂QrRK?~9$%EN-d 5}Gu~>W>drڮ"<FuxzXϐh Wַ[j|j u@ m`<T+k]cu#C*֘~T)rdrXy+Zl͠:ѰD#<}1OAgmsk0/Ы#cC?dZE4 cc' d$ڕh}aA{NxSj<ৡ9 L[6Fys͛? f忯iVF xuNd855zGf`'ihu(ů]kJ+ }*M)#A k`Q-UǥQ qOiw0r[i\>SQάgLS|G$K_koT v~Up@>]/)/,]TWKsm0vFOÂ7r19 OO;`7̎:;t!9)w@-EwQ].els'A&N=.V+8iK- 69: աs$8Ϥ47a,`R:vNX*Keզ (޶:ݚ@:V﷪\_QKoJT5{ 6g7!Qr#aa,k̔L%lm~2ϠBOTG2vBa BM&[h& 1wGS_{PH_Ñ!v:?;lh ȐV ~uv( ?F" >m&QƊWPkoS뽝ᶆ(h>k#v"( @h[**^`C13aciA';Ed d^ϲ5 tMȟ&av &TV`1vt8[rKQ,VA7Μ|w9Ű=7AnwIqT< 9pn@bkyn@tN L ":og2iOt3xuqSeƴ6/] GZccm@dyO6*C E^S~ɥd̟ŨEmQc^˝қ% L?A7V!3t@k q\hn_qnYn ɐ1.El k6ƓsNͯSC.@*2i%KdnH b u2-Jb~3?CORΧ'99XSdM97dŮɪNsz&IRB"~ToN"Lƒ~.<_dsRSge /HO}ε7/@U>Y|Kq9;ψNjG,4ť ;p h7${Suw3s$J"iQYVUEщ=x)4$qZ'Ow9 寨ԁ׎밖Ċ[㡳ua<;(q=\ViPpnR5R3&EszkEw6[tD"4x~T0CYPCm,-Ό4u,{Ⱦ=UO.th^Gq'ooA \ļHsBj${9!G;"6mx=z+niB5՘:i\YGaЏAzR3'"ܿP޵Z{M$Od[!%!1<v ! sl!ZK/o^(U^#˒AeX" 4% ,*^ ɁgX=>C@O^*TQ10*{b=ԭj$4z/(o^ []Z aDҭzEY{lXd7};8DZ(-rX9A ]<9b-$%u-lXXgMrn{:+\bA;1tΰF> _xp Dz%]83yl;5,kt0IkB; TvT{wKӥz^EOOfP嶬Ԥ'xҬ¸{Ɛ:fU2Dx#!q!Fbꕵ1Xzpӟ7{ÄyszQ:xHW'/)T@A핤\iC( NڌO͊BH+Ȭ/OsRPHSVxsWq`ԭ+}S*G'277{VbI_Eq6㠧 [m@vwIa;T؇W豶W!IQÁ~l,R#Z kbS6n|uDgB~H<|3biW=!|ȜZiNbf"X/y?qAWW 3m; ߘ4x Sm;C[]սV[yՆžłdnGnXɗfu3c@cH~`c!iC=Ne:Ip4 n/EN  ۦr@wǃprwUTWzO5TiHjeО\RD1zAaҠ|OuitP\gDֶ";נ;X:NhO}"@i7델+VuQ Es8A3h! Fl0o6'Ɔ3ݒ͡ZOs7%,>&Elιd< B 7}<0h*X'60Δ F_wo)fMF[`SVLUGv4$fIg\GrXEu:> |#YX9.4"m-G2]xOx'kb0׏P0&9x` KH cH,؛< 516bv>DCqYCu=zX^DŽJ@Xf^S;1tSP~à'|5~QᗚaO@4g/C/ p8WvOp7w$2"YPD;?*bSH5N4pƔA]7 p-D:dv](Fu]: X MZsKTn#C0jϥl~Pn4H>9WRC%[p959?ĥuc]j0?^ QyO]|;$dm+l))S+OBb7R$; gݹ:T;MO5t>qPr9o0 <[Ey 2=5ri5p.E{;֮&4xb{Y=avV?'D_?G֢)OT@Șխj0V;55tC"B;Ja`HAB{, %@΍]YWj? 0`k#D,(~Bp卿wpReNvGQϖnKIEQޚ=o!?ia:C?58A;&`=}6:_14 "vȰhZnSGܸ*^r郺xPPP|Joͺ3_S2QT| >GLY&׳I@l\ T,L*O/P]r : \ݟ"MQ-3i( Kfk3dLfͶ䴳uر4M65ȸt(^`4pY%;n5i`CREГAx/zO:/A[Jx+7nnwm]/1[h7ć~Lm}q±t d:%5@(!*?7N4]ueV; Y5WmYm~Bͬ'X $HzE4c%ҽw D3lܴ`[%s2||沕Q> o' ӟ`ъIF^&l^_Y0NQy(A@ŕ@7riԡT={ʧW(+C4]v~oJG?X@3߰0ׯzrܔ[8vtJN"x 6^&) m'y_XH/V! s SI ۖ}Bw*R¶Zlč$ٍ3gAvIu|֍);si#ҙF$R'p_L7EL#d*>}ז&`.8>LMwG;{ΐp (7@@C#|CP&`GnQެg*M~?Wor\m@%÷=_Ђ`2K }e~ NZ 9k)y9TtC$fP@|YŭXu7pMw_RL|9y}72+&2$yx!p Br`섗%qh-XŸ'ԲqߡZW`nnNO³>ݔJ :# W TD:kGw[pWӮyec9dq2)oi-ǃ:\3JU Hˠ9DH[Fk tzp3^7TQt9J >f93^hnb7j5cso`€KHEvUտ i ޞ'Nﱒ>7u0 '_ Iw"tLRiOQ\H 07B.cdd( N?,S vpk!0{ |q P<*?c){&tRП(Kۙ'(ƨό1-<Л;t1||=%kjNѧG {tk 0U!Rf5E!Ծ4RY6wx!,Q?LCDB'UFun"PE  1NJK sܒpҤn>Fstw^AG;}fâF坹m"6Cyr0-NAU9*PluAh7> moI [ }5NS;.#b;$.MA%]h(ϡ xә/+1@Rx+MnҺ㧢n*|8zEI {aEv|ӌL g֥ty;D؉8mh9"@+:2@DPG#.-Zz`px"^D[ ck51qcP\Tbϛvutu#|;/4ۦ~ )}Bu/uW^ʋp)}N9ڷʶ 0zصJ\oQA^t&96tIN(9%fOPϝ@"^Ӭ._dNt3{]ǢWהko1>U?o*V{\UK&m@B6zb;o:Vxp(M!: ؄1y\mn:[J(H毼~7"1Pѯ;_Kߚy )nᲱ*xٱ*O~{bz ]\3gu[~]̠/-C$*$ IɦL./4T3؍t 9.m+5%|X}O!$P2X7015ioU'lLflf;hHo%U9MCh5~7ŧ(LlTEڷb}\~ ͅ8sQQ4;"rD;c֨`CO2\?oUn,!#s߬72|(@{Jo^a>6pm>2$>/NnqAAmf |Z`4\QW*R78~_FuNUoIVZ#.wߌ@H(GKW=]T@۷t<cEq6K"!-}Q=Ld蚂mz2ab!_FIA3F@Vn~eE4Ͽy5_ˣC8mR)iN |?X@} d,⣽B|kYw[Fk&6U+(}'Ν%e1'|3ɭ/!bS/B L@vy|$I{WR XP>UvGv YZe,w9ZTџ7ޒ8 jH-ʤP`ea3jnl2i  R֑g06;b`if]LOԧ;B'Z%\E$ i;R,^O0|z.Qsv9͞AzRs_נpX }K}y>oxjh !g5XI1k0u ys&[1*7 s e?>;:gΚ3LQ{cn8{ t0KY8x 5\!vxٿe>JWW1W:!aB8(e[5͕k\?ޝјG OGMT gEj8VrŠ\^Y뒇!>|&0@!Yj8M 7oUT: O}c X3O2X Brd>Z f.k]l{^~F{Rho6bavf'V8: ēH>k:}JtGH5LqVk0M*w|lé XEX,"z8׈.@@MS&{-3^vu@ ֏e@Y$xcbUBNP.Dj]! U|7FB!.PgFQ*PIZ+$bL#sxixViحrnXu1.g])Dun|I|˓f/Z,ʥfNeA'b$׋52U=$pQ/il46Zh"gz0\YNJ2fP5C2tp] %\ ^O YCX9et;suE{*bdCfu|ԩ2TRq7lIp6Yqzto_IWP`Rba"Ap2”CmXN#[]!$QbqUZx"]*kLYZ49 ď~~HJq#nB8R v΄=aG_ v[ALTn0&e(L8X\ WRBGj=5Wl'5#Q`!QHA!Nrc\2NRr%"^h. "e}Nmٰ1*XɞP.;B?+vF1 HȾt~ĉ,E,h)`d;1:cgJbhҡ!F2s @]vɕ2\ئƃwoϸ]m]wҲ(S5n&v۷e[tXDϧhBib2e﹍Rh=@[hjoX }T,X>@eZNF O3>.ᩥ1tM/FnH>pP-i4kCݶRz0AO2ԑ6~"rK);W2ǽҦOKS,) vW>[Wg2 \Iwwf A쁽uښ^#4YA~w'*hɓ6e&oHYx+f%ƙi^ykba) MQ9eBWA%&/ 3AUl$1ΖZH ekaczOzki%@1qi*9.Uy0tX\jz2~;4_ XK]UvlyEG]SݲR=IھZ=!BSY"IN7REºm'KÏ #~fV6 8r(l1Wj%Zޱ]ZEZ5 b%uE^ pn31| d/t@ĈpPMWF٬ˍ|7o80VYa2qSVj?{J^B,!7Q5sljSd|? lqӻVGo7h(>ĕI˷ߏ'6qg Fl7fm m?& \җЧ0/Zg4_<0Xd\ࠣbnZ;S..V'[@Gsvk`K{ˬg0,p sm *xZ{R TФ#K:Pv;TBjtڡSjV&8)4_K7h-53W[y)̂&(}z,bx*ˣ|}ac¸Hj.nh akۛYj?*Qj[LlН* ݾ<4/-_z'2j*?%¿,nD Ý&3k%dfnt}F!~IQa.WqUizI7hPmY%ѡU$E e١P<P{)NDnnO@π힃}Aav?9;!E^quG=AJܰ/r['Q[T~ƣZ\{u#-.C7Ȃ$Hʄ!: }:Jg!YI$18|$I^QIjHڷhg8tv)7iM*h(}:P҆0q1# hǤ#A su]Yɋbв'< {oyڬw_dog68idSP.-ocyQ2&Z2JG z't#.C~ Yau\)buI^m%J| 7SjU`<:Q}ٵ #]x8Q8ٕ+*'k "Ø/ x۠\V+<כ#F1ȾAI3|x)A_sH6G fg%B7H;kuVGKb\\.e2Ť~2_J60'9Nk&<#s-%'c̉\j?Eܚi!ć= 5%6q^`퀢gVV#>z@A)5,-ȉ`T=C(޾֋d(|H-AzV?dJ[sI \43*j}jTWiV86zWN$O06u\`z!dl~q!(Oڹ(ns֌x"B램u[ JTU)yuޟpѪ|)2C4240l&b1\ug.w%Q{_x׵q"#*tYOa3LE8Pb$@!PGPP˪*w# %N4ad hJVᤄ6PvC8l&BfoL }9#x)/:׾!F/LZ.a=0&8Y@=) umʰIEX7KEV?rzqƓOSjNvb5J2*DKr8JQ=Oe? -s@|jX[x_7~YYbDKTJN齓! *]u<}*m`{4"nbLxkIMB;rzʮSRKQtATG& I.d" ZHѰȊMŠAlFB/?Z7NHu!}c>ܹމd˺ւlQ;7Vڳ%CӰs 7TP hTV6I!eo1~Q3;>jp ȺD1`%M,NmM=bob kXXlƂL\gΎz͗.vZqW}_Nl`6KuL/?Lr>tg%l{`07_i,l@-;K! .j4M[A]CpGX3;ת#JO ]MG qň o2گ4rl"y7h]g P.i)w<-UU5_kVȄXernl6G꡾Bѥq" XlЌʀ= 6>:MB6sRȤBpq1u}82>.w_>^Nsh>WtgghS$-_~&~Ĥpg4CnqQ 3U M{u >$iwϮBFN`Q0%HYoj ȿi/~ zKgfgha5.!IF1R^/tpAL: A p2K9C9k5ռI92Y&:i>V%yb*L6μ.L%˭Vw`<,u0%-эUb 9=d@HPנ lm簰vuD e(GCs<qÜ-5{i $[ ~5/>0@ʣJbNl a~F{J8l). w)aJIJKϤϽ;.㕱Q»9pqOrIOMf}+bc +=:CT~ݔquѽS#lmXY]Ӈ1QhGZR<|ۢ(uo0HUԯ}Mg& ̂x+$ѥCv/L,fY ]?w_ Odh#^Ň<.HR@yV3L҂ead&lG3{3!:z14 R&(K!g/?] I#Cdhu AJ݄{;(5` f:4βz{'92hVkQƇlL]`;-OԊ hKWlhRyȞ!q/&aqn_OU7Ν*Ⱦvne.5ЅD$:+b+ p2c%K&eRIn וֹ3+1s@]C7:52 s*KI9pixlS=ZY#qX!M|sw>·cl$ij+,t)Dl¾_Yh˗8;"Hd?5jʚ[ϪQ῵fvZd;41D.ʵI G:⃘[b >ˤbQ