permissions-20181116-lp151.4.9.1 4>$  Ap]3/=„bޥ8.֎/Gpū`+VQ T͑@օHK"N}41.o`2m}<_ !Yq-jmZ>]Y-0uZ|#Ҽ!X:[O%wN{a0/o4xɲ;`ueC~οrZ{ǟӇ݃A,qeN;WP{njKtuy vgiw`" D38c283084bd68f39ea36bbe8a35443e5cad1796e5c798afa35902efab70fefd397c1494d9aac4bf1f97141a02847d189b6ea1d89]3/=„]MEUD2Z}3ؿ D"=ﭚ `sZg_=FpwBNc#OF(lN}h P8=b-۱ş&HАgx7ZGP i?[l yk&.5t}ˌ)hp@)?)d # B'09 Rh4 X  j  |        E r   X ( 8 (9 p(:(>$F$G$ H$ I$ X%Y%\%P ]%t ^&b&[c'd'e'f'l'u' v'w) x)0 y)Tz)p))))Cpermissions20181116lp151.4.9.1SUSE Linux Default PermissionsPermission settings of files and directories depending on the local security settings. The local security setting (easy, secure, or paranoid) can be configured in /etc/sysconfig/security.]&cloud124openSUSE Leap 15.1openSUSEGPL-2.0+http://bugs.opensuse.orgProductivity/Securityhttp://github.com/openSUSE/permissionslinuxi586 PNAME=security SUBPNAME= SYSC_TEMPLATE=/usr/share/fillup-templates/sysconfig.$PNAME$SUBPNAME # If template not in new /usr/share/fillup-templates, fallback to old TEMPLATE_DIR if [ ! -f $SYSC_TEMPLATE ] ; then TEMPLATE_DIR=/var/adm/fillup-templates SYSC_TEMPLATE=$TEMPLATE_DIR/sysconfig.$PNAME$SUBPNAME fi SD_NAME="" if [ -x /bin/fillup ] ; then if [ -f $SYSC_TEMPLATE ] ; then echo "Updating /etc/sysconfig/$SD_NAME$PNAME ..." mkdir -p /etc/sysconfig/$SD_NAME touch /etc/sysconfig/$SD_NAME$PNAME /bin/fillup -q /etc/sysconfig/$SD_NAME$PNAME $SYSC_TEMPLATE fi else echo "ERROR: fillup not found. This should not happen. Please compare" echo "/etc/sysconfig/$PNAME and $TEMPLATE_DIR/sysconfig.$PNAME and" echo "update by hand." fi # apply all potentially changed permissions /usr/bin/chkstat --system0R1U]f9;@큤]%]%]%]%]%]%]%]%]%695fe6b30c6f66604218b2ebf6101892df83b7d9d43f77e36962e21814c56c65af6a8269519e48272326fcdc7f829c49836d58e066facfe22aab025b20ba55d8254ecad52808937c3153a81d50810ee7e689d78dfc2cf8aac67cf179a2fdbf3beff080a463452041f639770628f22e01db9462ebce7cd0f8c66289cc304babd997db9c5608bb3938eea88fc81f56ab3fc380553a5e98864227fc4a59123ceff3a63013296157348e3cb21293a0e745dd1e3fb54299c61e64bedf3dbc1451b3d635eca1eb5762d2b602f4b5114a54eb6e6815d26f10b5dab00cda67f2860ca4a32dcb772c1e9949198bc7695bd25c20cd21aea565905b0975de2edeafb31d8202acbebeb00ef9fccc619e66ad50b5c31ac346b2e06ec7d429ec8d2181bc5bd2f1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpermissions-20181116-lp151.4.9.1.src.rpmaaa_base:/etc/permissionsconfig(permissions)permissionspermissions(x86-32)@@@@@@@    /bin/shconfig(permissions)coreutilsdiffutilsfillupgrepgroup(trusted)libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libcap.so.2rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)20181116-lp151.4.9.13.0.4-14.6.0-14.0-15.2-14.14.1]@]@]@]@]:\8\b@[@[z@ZiZ\Z%8ZZ@Z@Z@ZNY|Y@Y˒Y@YY@Y7Y2Y1S@W"W@W@WBWBVV@VV2 @V +V +UuT~@TZ@Malte Kraus Malte Kraus Malte Kraus Johannes Segitz Malte Kraus jsegitz@suse.comjsegitz@suse.comopensuse-packaging@opensuse.orgmatthias.gerstner@suse.commeissner@suse.comkrahmer@suse.comkukuk@suse.commpluskal@suse.comastieger@suse.comrbrown@suse.comkrahmer@suse.comeeich@suse.comjsegitz@suse.comastieger@suse.compgajdos@suse.comastieger@suse.comastieger@suse.comopensuse-packaging@opensuse.orgdimstar@opensuse.orgmeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comkrahmer@suse.comdimstar@opensuse.orgmeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comkrahmer@suse.commeissner@suse.com- fix invalid free() when permfiles points to argv (bsc#1157198, changed 0007-chkstat-fix-privesc-CVE-2019-3690.patch)- fix /usr/sbin/pinger ownership to root:squid (bsc#1093414, CVE-2019-3688, 0008-squid-pinger-owner-fix-CVE-2019-3688.patch)- fix privilege escalation through untrusted symlinks (bsc#1150734, CVE-2019-3690, 0007-chkstat-fix-privesc-CVE-2019-3690.patch)- Updated permissons for amanda, added 0006-bsc1110797_amanda.patch (bsc#1110797)- Added ./0005-singularity-starter-suid.patch (bsc#1128598) New whitelisting for /usr/lib/singularity/bin/starter-suid- Added 0004-var-cache-man.patch. Removed entry for /var/cache/man. Conflicts with packaging and man:man is the better setting anyway (bsc#1133678)- Added 0001-whitelisting-update-virtualbox.patch (bsc#1120650) New whitelisting for /usr/lib/virtualbox/VirtualBoxVM and removed stale entries for VirtualBox - Added 0002-consistency-between-profiles.patch Ensure consistency of entries, otherwise switching between settings becomes problematic - Added 0003-var-run-postgresql.patch (bsc#1123886) Whitelist for postgresql. Currently the checker doesn't complain because the directories aren't packaged, but that might change and/or our checkers might improve- Update to version 20181116: * zypper-plugin: new plugin to fix bsc#1114383 * singularity: remove dropped -suid binaries (bsc#1028304) * capability whitelisting: allow cap_net_bind_service for ns-slapd from 389-ds * setuid whitelisting: add fusermount3 (bsc#1111230) * setuid whitelisting: add authbind binary (bsc#1111251) * setuid whitelisting: add firejail binary (bsc#1059013) * setuid whitelisting: add lxc-user-nic (bsc#988348) * whitelisting: add smc-tools LD_PRELOAD library (bsc#1102956) * whitelisting: add spice-gtk usb helper setuid binary (bnc#1101420) * Fix wrong file path in help string * Capabilities for usage of Wireshark for non-root - remove 0001-whitelisting-add-spice-gtk-usb-helper-setuid-binary-.patch: is now contained in tarball.- 0001-whitelisting-add-spice-gtk-usb-helper-setuid-binary-.patch: add whitelisting for the spice-gtk setuid binary (bsc#1101420) for improved usability.- Update to version 20180125: * the eror should be reported for permfiles[i], not argv[i], as these are not the same files. (bsc#1047247) * make btmp root:utmp (bsc#1050467)- Update to version 20180115: * - polkit-default-privs: usbauth (bsc#1066877)- fillup is required for post, not pre installation- Cleanup spec file with spec-cleaner - Drop conditions/definitions related to old distros- Update to version 20171129: * permissions: adding gvfs (bsc#1065864) * Allow setgid incingacmd on directory /run/icinga2/cmd bsc#1069410 * Allow fping cap_net_raw (bsc#1047921)- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- Update to version 20171121: * - permissions: adding kwayland (bsc#1062182)- Update to version 20171106: * Allow setuid root for singularity (group only) bsc#1028304- Update to version 20171025: * Stricter permissions on cron directories (paranoid) and stricter permissions on sshd_config (secure/paranoid)- Update to version 20170928: * Fix invalid syntax bsc#1048645 bsc#1060738- Update to version 20170927: * fix typos in manpages- Update to version 20170922: * Allow setuid root for singularity (group only) bsc#1028304- Update to version 20170913: * Allow setuid for shadow newuidmap, newgidmap bsc#979282, bsc#1048645)- Update to version 20170906: * permissions - copy dbus-daemon-launch-helper from / to /usr - bsc#1056764 * permissions: Adding suid bit for VBoxNetNAT (bsc#1033425)- BuildIgnore group(trusted): we don't really care for this group in the buildroot and do not want to get system-users into the bootstrap cycle as we can avoid it.- Require: group(trusted), as we are handing it out to some unsuspecting binaries and it is no longer default. (bsc#1041159 for fuse, also cronie, etc)- Update to version 20170602: * make /etc/ppp owned by root:root. The group dialout usage is no longer used- Update to version 20160807: * suexec2 is a symlink, no need for permissions handling- Update to version 20160802: * list the newuidmap and newgidmap, currently 0755 until review is done (bsc#979282) * root:shadow 0755 for newuidmap/newgidmap- adding qemu-bridge-helper mode 04750 (bsc#988279)- Introduce _service to easier update the package. For simplicity, change the version from yyyy.mm.dd to yyyymmdd (which is eactly %cd in the _service defintion). Upgrading is no problem.- chage only needs read rights to /etc/shadow, so setgid shadow is sufficient (bsc#975352)- permissions: adding gstreamer ptp file caps (bsc#960173)- the apache folks renamed suexec2 to suexec with symlink. adjust both (bsc#962060)- pinger needs to be squid:root, not root:squid (there is no squid group) bsc#961363- add suexec with 0755 to all standard profiles. this can and should be overridden in permissions.local if you need it setuid root. bsc#951765 bsc#263789 - added missing / to the squid specific directories (bsc#950557)- adjusted radosgw to root:www mode 0750 (bsc#943471)- radosgw can get capability cap_bind_net_service (bsc#943471)- remove /usr/bin/get_printing_ticket; (bnc#906336)- Added iouyap capabilities (bnc#904060)- %{_bindir}/get_printing_ticket turned to mode 700, setuid root no longer needed (bnc#685093) - permissions: incorporating squid changes from bnc#891268 - hint that chkstat --system --set needs to be run after editing bnc#895647/bin/shcloud124 1575544358 20181116-lp151.4.9.120181116-lp151.4.9.120181116-lp151.4.9.1permissionspermissions.easypermissions.localpermissions.paranoidpermissions.securechkstatsysconfig.securitypermissions.5.gzchkstat.8.gz/etc//usr/bin//usr/share/fillup-templates//usr/share/man/man5//usr/share/man/man8/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:11660/openSUSE_Leap_15.1_Update/4063abbacdb5366d88bdd46c05dc6db5-permissions.openSUSE_Leap_15.1_Updatecpioxz5i586-suse-linuxASCII textELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, interpreter /lib, BuildID[sha1]=c1c62663c86059e30f445f76c4b35b0d76ea1a53, for GNU/Linux 3.2.0, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)R R R R RR R$G) <ޚutf-8ac4066074b441be4e16c5336c198e4e1391306bff669e94c9c9e3a1f2f8739bd?7zXZ !t/;U:] crv(vX0~гfwIJܶsB20om0%Q}hNQO#` Ǵە6\P|> & ToOa#er|H~jL@O4 # c6Ve f,j) kМ_i088M0E]!  ~&dVH \\xUIf0PSו vc[>n\n>ܖ"јEm_z=D 裱oH`sM:~#,6VM$8Tgts?C 9g18P釕 IuZf6(mpЙT?9~Vx&3h'׎2sy3sZ!E$]Cńj1F X/Ƌ V8말ƧC\dbஒnN8m+SV3T3VL!c!00鞊3ڀ{ܲ$`շݟ4Q̵rMRb Rf;#Z?;״:9Fo@lZ<C 9h6ѫ&H㦰Gxk C8'Ԙ$%Ec̬"Gм~d#񗱝̱傣MPQzn;(n0סdO/5 ԾI**{M3zPg ;gi:sʭ tm1-e A@/oN7ʾܡtCBbo_9aԍwQ?OQdU?Gq|C)T&yelQ#eXqF:z0U ?x)c৸@%6wU}1QE&vtG s@2 ƫ2S^wa\X-{ >b)s% _xjvO\]FY2̴-PGd,p@E$BoGV Un#?j*!W04֍SZ7;Ӻrc{Z#+QQ#swVYN>`6ǡBO $Rѩfl*vU]y^8΃!d>=uZ.KNdC|}S2b-i 8V[#!5\' ת@|;T?"gAƛ1kXQ}64Vs7q/:RRŏKC%dU('HY?iA .'fv˞P)Eȵ12\ "!FK$[ ێB,m&XBÜdf ^&.vs9p8%\Ɖ  >>o+qu8}C :?@BsOvqmr:d鍏s8&ު!'Rs3֠lh\FX 䱃Kv: ثf6~/y\3XmStHŗ YƒkSF4&Zc!"ZBo=Z3Ѐbd"`ne!sUBƪ% eaHa!y)Kiە@P&e.ưCi~Q.oچ9w%IPr.t3!B5w~:Sp~k~^h jI|og8X86[vxDb@%"lz&UZW5?BV;|M`e:s Wl=U|>w!~6닳.k)kI00~md.%O>OtG,Q *ƑR?R"i)VC$P(`Fl[;1Q*ET>b on R#>2)o+#= ~`79CͅAFuHڹ㯎:27Fd}d/Q$Ia>%=:ٹ`l{ʋ4 8 Zøsk,Mr9CI" 3.- ﰡ_)spJo}Uz}qeE"`p}ΘasRh4( )Q EdF89 Hs}}HWvm9 K gBZE ^c'B`֌BڜQrLF M{FMA5$Aď2ࢆshG #FԹ* Ayy O|0QSܸlDdT'CS~\'Ū2fXy7S*Cm9(w<Bׄ3e*KY^yVy$a؄2Mq{|lмH[B&e~i*PIǹԚv*?Wu/DV% in|Cf9\t`Ј[-U68~-,~FȚRUP St>k|gːFb`GҮ7TT*=W$4(G)\e9K#?̌m2fIU97<ك<e*#Hts+ )C!9 @nR{axg *O7/@5}Hqxyk]nD<0~_R 47ilۛY=ӔQ(svvUL!kY&7헺R0f«u b*<m+" J'tZ [AX:iJ) L"hfԏ*o "Oͭm9_#*H&2~,ŀB4\x4J uG8}EiS:;b:1|M3˓-+&_V*\Z"w4inOFMEAK.|WW#jtc />UJQʽJxx|cju HTnny~` ]crFHps ;/_1o*i X(S ZRY#]CRÞߙ:@4{W#O]VVigKx4زW]IrA׃]?b7'v$55TVeArC wJ92o|!U/&}먡Y?xh;ue $QSIx6LbT0 K;+hqkb"/EjJU$k+AEw4Ӛ:ko>IV`̓&RPTԢe>fG6v4#?";"r HpM}kD[dV ~\}fb;@B"ٗq|>1 GN,jC)V }Fg:WaxC9c뵂9`F\-5`6}s0p߿$+pbuݽdkd`|9!.3ɱ9Si [\5hG;JQ3p[2?#R6jMVDbt_1sy6dOw=92y[ԫUM^5~U.M p7~K xa4~^:@KI2a#l#/c(:V5n= GdNd"+&/ a<D,q K(Bʦ<7U=~ѽ^ٸ]{F!Hc{[2,~٥VĊ’:~ɬD݄QiCߖnHXt̽I Mcu%Xk )0Mu[iLoPJW [.I^kבhM.6-afj'zºEhT}qx ֣xWwÒ=9g~;UR (5@F5E[zF۠lnfr4$8tKkX5Pñ3F~, %u떙|D<UZ5qJl*V.9):3],Aћ3Gk |ִNp:E.̈K|uwj*0ә=h2I9`yh4 [C:M^m(yheD='+ȫʦJ`  Z![0}2Ye"$bV$̘XHε\lwq&?dno9׹FѠ {ᮜ4BwnYzZxLBӖτ!..Z9hU IPP!PN˳[3_" M= m=%m. XMG_ `O,0%@P?ALiۚU}O‰AX`6%L08&/pg.q՘8Bweָo@=b:wνu3*i31tQHr0^uP޻ kc [56\LP}'xkvV0GI<_K`x;0,#rIÛÕbnͻcYRGc0U% jbZvl]Kc-`ԜཾF ԻmBDqdNI31fY]l`Xo\8^ﵟ).wc,/n(Ѿ2ء>\LTw>|4!e1F#fĤ8 锏QA+\H(k8i \' %й 9NC8v83ѵlu\@{2֊ ۽^w&_Bjz +1߻c_!V-FgYF vG;%y7Yv':fH0өi^0g1$UUE7~=F=3Z'rHT P[uy)\|No遰4 3 9>*0 }򪃹4T|ZO!H1#x Z l%lB&N[8Rzэۚ:!"1@ 3G%a4(B;12M=fF*yΆ.t9bjQh/ˉf$QH%v7WbΕ.> Fh=h/- ^#xZ(F&b7@@v$~tL>ċ@:>0CDUrOݸCQs#}LC^6_hVLw-ƪĮD8 Oܦ?]9= NBDL|N_3;F)X< $ӊ8B/6'p::)fIs-S؃)#&d;t]Clx'ݺcXw[<0%bhetk{Ր>tX͘Xٮ_ю$J4RLwYj}$ Vx `{h%rM&e*:?򲹚IPz8g6RK*"cb()^T%y]޾m|f+Yޕ-&gz "GX _ѕĿ_wlrN}Ab=~<0nĻh]@.f~`<PdaɆD׵Lkc|jkJ,.e[šgsI vh'e#< 0dsyд#p _MUϾ'N:GᝐۄzX"91j{6IOo,ﭩkX·Zef}vwsP|m!Ny\Ώ p晹1{ `u6NlË_(ci)W6hA3r^fCmӚ jJtL)?9s$:L5e "HڇyŤۊ7:e=^LAFi7/*<о4(jpY=dūvdg](pRd׈EI\(2  R"3B1m٫]pHQ ʛo?H#wtӣ9q%YC3|ϳ=)PTJJtP+^kb Рak!RE m M&…g2ȖWH(/:F–f9fNxJ 3}<0Bl%0 bcPX *ײ0+ǖ c*f=U$iE֜𤀆vBݙ?8 ^|"ZkVH3(Ta8z_d+![}4?=<ܛ?h@֭,&䷞ţ{l;d[WHÝ2^M4FO,W#·ڇ_0_@߷GXAS)Wn ,qARK U="r^HhHc!d];tZ,0@rڴK `V7T& 1uĸ_O[R[ՅluţKܤvs?C~^EP1AԖg,9EfEx>SdžO;K|Ju\ا'.1gQZCteyμ@zUy>A'5 c>5٥ځ>q xtWD P``EJ]q=QKwlʛ16g3*D֎9%o)OٱD{5[Pta}"x%$X=0w̓ms:0mw ֤b|~.t@GZ !%oU0ou[S6Sxm+"0ϒFJ |.7:ZHqpUøMKғ2_@M{f$[g+XnhaQY%J&'a)5 /@dH^)02:48AkEI$%] |yZ`*jI]Nk\bw+xMCy:|y] Gk,M<7QBL]}rhb{`gFgRo;R"Y&ԙwe~T >`o?vN_u*l %"P' b0/A:a%{RXujް)Elw"E $+L%ejdf]f C6L^\;ILyjeyrFגgX<<,C-[i?!V_Y)]r5%aA7YϦԴ=H#VQo++f\by)FT;_1҄:>: @u*b^VP"ECqS;'L?:m7DhN&80#ӥnJ\o6ƤU`7d9vyR\AMkBHr/ʹGjdl?=ql wL%xֵc:1 =UlvfwR嚦?ʵѪƒ;w)*wOYK5lU 1a/H j>T7Ksĸunu*L2mY7dDtӲXAi1ƑK{3r GRmo bv&GCF-Q.LLHdܒ dd,J_~ )4n9 V1DH[hQbtpVjk[p |LZߺW)jn6?ޯDV^Q Y*L@`+dh"&}w?=d> %V~ i\mԂ fjg/r*Tq5;03r(Vz63<&æ~= TlVqy.i.ii ř`m4_''_n24^PRX6D!f9-!XBuMv "\KL8!%=F(fzn`{Fm)Nge0QX-O@txC&ݟr 7{lnV k"06O&wouʒB[=RUnKX (R{n +~Th93O^6 S5fPHվbK*lұsR4G -'tXP o! )߳2F1~Y T{AAS7#jW}Pf 4PL|SmJQ\Malv7̑k"i#nTQ}E0:-ǘt.P8‘#A{7eH;O.\l8XYd~oIc,^ =FlYo3Mjn /M&D1]4~dO9W'@^6L|zNӳYf=2@y'Q(v~Hl) &'& (_=zH*C$fL % '(WhHО$eELߑyQ6/0.e >$UN.׈fZZ2,tX+~Ə!6dyj3d,Im-,zai%/IZ4+1T/f "Oim W`Fז3xXg*t^@*R} <#"{>˝-Mx#vӖo\u"-8@@g@ M#Մ'˒䊿R2=B&F/@,5rbt?o؂­-Sn'xUn< <2/N [ӏ!_XsWZ$X%*D m+1gp<-:X؏TAZLCgpQ#`޻MHMv&Z:n2G2t4m?|ۿd`u {T^ D= L}}/q#Mq1&r<4_r?I>O뫶ӜXfֈ=L8Uzp5BB PB2ek5"=.$oZajY6x\ [y!5y)e/RJidJvNm7yDpLփPրlt֖2; Xy1~!5z4 I*m'*w\ΩF+"ۇ?=m+T*?n(Z2`_ao_ GuJi,-CS+Oc!g&7\ZdEM o:6Cj \EG5سrJiPij)tXN kd=Cj`- Gc h2ɗIږT jc.32u4he( Qˊ`)*y4+<<%aո$;(~bᕐ FIdUAgz4[IVfĖ r+o&qEI3] x 9)K,I_1|ю~; qOXsDu1y5yVξ&pMӺJIM- =*nHt}PM.z3v6f #^u?MaS)d3Xad dxo'5cƾz ,׈_I"MO5I,;J۲CJ#I8+3i'L} a2ZdIsUi`09nR20wk@X-H eaܠ98T*2vG5DS`ـOo '{L$܀鯭f "L2e^Nuq}|, 6䓹W8(Sƕ]Rtyp sVoA `\o&q3ɛbVOd@J)A2yVX: #ō*l@ ,.nTLjkH+r?շh)X8M5͉B1fc}Cw߭YMn+?j$'Tp3͕X@:|3h sC+fV\4~k۵̓GP=:A޲ESL)y­Z" C)[v!G^tc?$3<0fe$KpX yp F==5DӦӵ{cr;-J!X:.J(pSq6!r)r1)zр?c~7j:)S%#_JN`a>g"L !ppU(&Sؒ}< /F'(vG"tMe0MC|ӡ/ XA>/)IՐ7𜦕ptc\8'R};χ MQxGd}ZJ,A8F^쀤t(HƅbA8?/zz̶(H$+<9cicA]R$ ;Ei=yV[j-)p9F {n{Z?m`{G0)fQ\g%uå >CxeCSt<qW{51>)Iȣ%X*t&k:kjm'%Iө5<`.7lD_] ;!xuzg'QF[/Lrͽ7m߶2l6\֢¬$KU<}/1k٪jLXL0`d&C2,`OG5qkLQc^cxWfiWu-ek>dyF3ZH O#|f}^_*r!FLz)_T}=5Հqa5r1)@@T:*{Å .{ҳO2Eq&6D3=NLk'KmN rW==¥ۚ2( {`Vzj a ْ:X1*xM˜ai5QK7'Xd|hsQ {<+=e-~JWPer:FPo39}fx<ͮAs %Ge''dI>C9b'\܏%Eٳ~PKߜA IRKdUfFȈzb5(6tbWEg$r}@[jϣwBA$"oc. MP($S )|el5*<;q() .cΏ[s`ѬٗܜD,>0 joQ¥-d3{ WuCxQїR"yO[>rg36Tc$|#(y۔2.о=1q.{X&$Ǥg0"=j92Ҵi$(,T ]btW$޶: ΄9ѷ ,t lX}b)_E^^|2}Vn6[p 1'`@Uڻ  ܅rИhfBԮPx ^m1L_Hsڤ!2C'b $p㔠]&ˢJ/>jBAERWVu6XpSrⳓlSy+)"aN=1G'F!˷❽b>]KrvImWoToM;_.TRM/tMuQ]Raҝ4r4A2\{z5r_ӝNtMޱ?^55.3zlC,^yջP# }1:.Hu7י҈Uwh 6>@H|1<@W{) InqV?J& _زfj:YRѩ6qb%:['pYa$}ɧL4=;*^;7B!0QwA S=BQMe(0_ȼg漦NhbG8z˃;ωKkNF!Ig1h &\B:uviTy_ Xe+IwIg/deY4(D,t+ҏpo5Fi4rND)tycUK׎rLJd/1[oa8 ɇ **ORxb>*w!s9e5YAt#nF^[5ϙH^E>ܿB8%襯\[85 ]a>NB$iF 죙)&ZG NJRكjMܴlZ^۶\ҁ@ebSqy}_/7Q0qJdmh`XyNVl;,OLj: U}W("U\w%Pp^$%a~X/ k {Ibqq8ǩ(xD^N6QRD B*F :6G%WO@-Gb:c~›k $;?0bˆpŪ=)1RBToTD+P-027ts4''Ri܋ JoĴa)@GrqxF/}|06921[f'u x(j մ3g*檅HUjhW1kN)9,bn[ $)3KW|}TH.}B h@Iߓ,ɽc07REwri+뫆vD5./H󇸏V+e+6VxiFtК[>z .{R!z"=+G&Mfu5@z]Nu4_q6 2 ~-ŞeVǥ Pf1XtyV!JHPy8cK⧌+n>6n+yҒ,B"ZnsVƟReM=#6pAHa&_z!¾I9%`Fϕ:i hȺKUIpPHWepZw|O~7ᜅF 40E{Ț?e*Ǖ y*[}<qpÐ}j!#G5řŒY2_ ׳{J],_GǨVU~|;☂"Kq[ُ}B){\d#\,7i QPf#F2pQ{`׋TS/[I[o3/|GI3 ^$7FLTG'i]; zړӞ;Mۜ7k%o~li\"oj-S½vC u NkDhΩ3s]f&Hap?} I(QT!E=,?ɹ|tZ.LTkQyg\3H鳽im'p`ܯ)hr2݄Z~lu 9!`wF:]&  <3Ol+2f2oP^ry*U&  ]=6P),ͩ*E Hc~$:S1p$|N|ا`BSgݱE-GVgf(-"ݟp΀9Σp&If5 ުDTQjZQ[ݗ0E@bN:8` 9eǟP06WQث 'v34S;;51H6i]T8:º4/Nnip[9p7j~ZajO?%c\mSL~Z= 0fTjB2L#|߸xxͱ0^#Qrr3MJL]W:[ حEa?&޽+GP,v=*"oC2o\M\?e?4ޥH G+ǎC@ǟ(-j,_k>?t!C q-0FQ4Ih/U#\Fҿ S|'cFy~+0IJZaa ɞZcҚY4'Σ9,m |#krz$Io c]vWn>AȬuܦ".vbEx1?9k ۺlG~I[(Y"iG;/yՑR)y$2 ipwc7SUIa0!p0O ݤ\&:~6wKܿ3~Q(^(pHo:Eh}/6S% yfU꣮jRr%(̋ =F=# =yDS2^CoK!APtRgeoZWγz<}EUAtQH?3q<ϒzj~x`2< )LGύk BԊS_]Nk߶}f&0aɫJ=őPE_pW3|ܟSfk5UgÇ?w#SNfwm'6u}Iov q赉 OJ'>^ ^Uʟe7ח(Qs8jZ9o9&$송&(Oۛ0g<1 vI2+VKC룫,$bmU3boQn2<_!^*AS6| &:GMp= *qPwJ]q$ŞGoGϳ3 +i-)%{՚PbU9i܅7HO KAj%r+ުD#0j#[wӥW^ϓ3)BֱCZMn%hōP'ϡ f ZA2Lf3orɇF)w"\wq_ߝ58\]ϩ@Cpp*``*cfѓ?S?v kn e#T,rAn;EY3T9x.9q8Va&Y4Fp 㿬bѵ%_I HuIs(VE u(.728iɄ{q/ljK&c<Ǝ_},@DuTpfqZQ)30,ZA/ O֧{NKQ4e)T+Ine=(ﳛGd2) 0r"P ܴ˄kN )-hAZ,]lJx0r|)9 /1ePh DU(OMG/L1pT$),Н;zF$sD[ k3oѦWPC)TWh8wO\TJ斢,(1No˨-w g9[ VaDjC>Cwcka}P+ѶTPۮ 8EuV$Xa2|!:*pm_Z4 #({Wޢ(ӅdnˑA9G %7jyj!eXg"٫7aNnxagx9G*8uI c ue}<`n>;ugd3[ux^wOUS(W̽U#77}3xl9rq'xeeNfϝmUzX;`e4P?}m%F蹷+u\O\*iQ!oz:=K)=D)[P LǭnyE¤TpgvSA0H4<XdEB섍}Q&9cSI /q|U|n-XqHbR;7=$i@gX /q`6["#gyQ\VO1~'cTA$