permissions-20181116-lp151.4.6.1 4>$  Ap]XG/=„"-Bu70ӈ@pMژ[6 qun3p݅[Dm2^',9#-;]K.Ãކ|eڛ e1أj1*G7/D*Y{^g)ԇb4zbWϠ/%cE& ^4#6-F>K0X}fS-^Z=B{OWCM6ϭE.QIP<̏~\tZm]ıA(JZ46,506815fbc7710ca50414fa29b7973a6c6a536e732dc7d1e22706ef00c96760507a537c3582d9d2fd25315aca3a3bf33cb80aa876~ȉ]XG/=„\B:\D$)jmć… QwSB-JO,˪][vP?*)`8_'Z_jyKE\zwY&~t ihP4 Y5?SsoϯTo()0{uQorG@IBJCxhuvpiN=}rHl?%8pn *p@'?'d # B #,5 Nd0 T  f  x        A n   L z( 8 %9 T%:+%>"F"G" H" I" X#Y#\#P ]#t ^$b$[c%d%e%f%l%u% v%w& x' y'Dz'X'h'l'r'Cpermissions20181116lp151.4.6.1SUSE Linux Default PermissionsPermission settings of files and directories depending on the local security settings. The local security setting (easy, secure, or paranoid) can be configured in /etc/sysconfig/security.]XBbuild80openSUSE Leap 15.1openSUSEGPL-2.0+http://bugs.opensuse.orgProductivity/Securityhttp://github.com/openSUSE/permissionslinuxx86_64 PNAME=security SUBPNAME= SYSC_TEMPLATE=/usr/share/fillup-templates/sysconfig.$PNAME$SUBPNAME # If template not in new /usr/share/fillup-templates, fallback to old TEMPLATE_DIR if [ ! -f $SYSC_TEMPLATE ] ; then TEMPLATE_DIR=/var/adm/fillup-templates SYSC_TEMPLATE=$TEMPLATE_DIR/sysconfig.$PNAME$SUBPNAME fi SD_NAME="" if [ -x /bin/fillup ] ; then if [ -f $SYSC_TEMPLATE ] ; then echo "Updating /etc/sysconfig/$SD_NAME$PNAME ..." mkdir -p /etc/sysconfig/$SD_NAME touch /etc/sysconfig/$SD_NAME$PNAME /bin/fillup -q /etc/sysconfig/$SD_NAME$PNAME $SYSC_TEMPLATE fi else echo "ERROR: fillup not found. This should not happen. Please compare" echo "/etc/sysconfig/$PNAME and $TEMPLATE_DIR/sysconfig.$PNAME and" echo "update by hand." fi # apply all potentially changed permissions /usr/bin/chkstat --system0R1U]j9;@큤]XA]XA]XA]XA]XA]XA]XA]XA]XA695fe6b30c6f66604218b2ebf6101892df83b7d9d43f77e36962e21814c56c6567fdd1987fddd0ca710a62521aac340450dcf8cad52af79b32e8c64f30c85e89254ecad52808937c3153a81d50810ee7e689d78dfc2cf8aac67cf179a2fdbf3be0786280d9eafd47119f5293e2a206e5a39e8ada9ced344c4b8bb9248c83439df13ac7c99f217883ec3f4bc1daa6c1e4c9b05a0172418f33192da49a9c50cb9219af6b7c395f549c396bfeebae012e8d29eba261f7d5cbed552850ce230e438435eca1eb5762d2b602f4b5114a54eb6e6815d26f10b5dab00cda67f2860ca4a32dcb772c1e9949198bc7695bd25c20cd21aea565905b0975de2edeafb31d8202acbebeb00ef9fccc619e66ad50b5c31ac346b2e06ec7d429ec8d2181bc5bd2f1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpermissions-20181116-lp151.4.6.1.src.rpmaaa_base:/etc/permissionsconfig(permissions)permissionspermissions(x86-64)@@@@@    /bin/shconfig(permissions)coreutilsdiffutilsfillupgrepgroup(trusted)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcap.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)20181116-lp151.4.6.13.0.4-14.6.0-14.0-15.2-14.14.1]@]:\8\b@[@[z@ZiZ\Z%8ZZ@Z@Z@ZNY|Y@Y˒Y@YY@Y7Y2Y1S@W"W@W@WBWBVV@VV2 @V +V +UuT~@TZ@Johannes Segitz Malte Kraus jsegitz@suse.comjsegitz@suse.comopensuse-packaging@opensuse.orgmatthias.gerstner@suse.commeissner@suse.comkrahmer@suse.comkukuk@suse.commpluskal@suse.comastieger@suse.comrbrown@suse.comkrahmer@suse.comeeich@suse.comjsegitz@suse.comastieger@suse.compgajdos@suse.comastieger@suse.comastieger@suse.comopensuse-packaging@opensuse.orgdimstar@opensuse.orgmeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comkrahmer@suse.comdimstar@opensuse.orgmeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comkrahmer@suse.commeissner@suse.com- Updated permissons for amanda, added 0006-bsc1110797_amanda.patch (bsc#1110797)- Added ./0005-singularity-starter-suid.patch (bsc#1128598) New whitelisting for /usr/lib/singularity/bin/starter-suid- Added 0004-var-cache-man.patch. Removed entry for /var/cache/man. Conflicts with packaging and man:man is the better setting anyway (bsc#1133678)- Added 0001-whitelisting-update-virtualbox.patch (bsc#1120650) New whitelisting for /usr/lib/virtualbox/VirtualBoxVM and removed stale entries for VirtualBox - Added 0002-consistency-between-profiles.patch Ensure consistency of entries, otherwise switching between settings becomes problematic - Added 0003-var-run-postgresql.patch (bsc#1123886) Whitelist for postgresql. Currently the checker doesn't complain because the directories aren't packaged, but that might change and/or our checkers might improve- Update to version 20181116: * zypper-plugin: new plugin to fix bsc#1114383 * singularity: remove dropped -suid binaries (bsc#1028304) * capability whitelisting: allow cap_net_bind_service for ns-slapd from 389-ds * setuid whitelisting: add fusermount3 (bsc#1111230) * setuid whitelisting: add authbind binary (bsc#1111251) * setuid whitelisting: add firejail binary (bsc#1059013) * setuid whitelisting: add lxc-user-nic (bsc#988348) * whitelisting: add smc-tools LD_PRELOAD library (bsc#1102956) * whitelisting: add spice-gtk usb helper setuid binary (bnc#1101420) * Fix wrong file path in help string * Capabilities for usage of Wireshark for non-root - remove 0001-whitelisting-add-spice-gtk-usb-helper-setuid-binary-.patch: is now contained in tarball.- 0001-whitelisting-add-spice-gtk-usb-helper-setuid-binary-.patch: add whitelisting for the spice-gtk setuid binary (bsc#1101420) for improved usability.- Update to version 20180125: * the eror should be reported for permfiles[i], not argv[i], as these are not the same files. (bsc#1047247) * make btmp root:utmp (bsc#1050467)- Update to version 20180115: * - polkit-default-privs: usbauth (bsc#1066877)- fillup is required for post, not pre installation- Cleanup spec file with spec-cleaner - Drop conditions/definitions related to old distros- Update to version 20171129: * permissions: adding gvfs (bsc#1065864) * Allow setgid incingacmd on directory /run/icinga2/cmd bsc#1069410 * Allow fping cap_net_raw (bsc#1047921)- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- Update to version 20171121: * - permissions: adding kwayland (bsc#1062182)- Update to version 20171106: * Allow setuid root for singularity (group only) bsc#1028304- Update to version 20171025: * Stricter permissions on cron directories (paranoid) and stricter permissions on sshd_config (secure/paranoid)- Update to version 20170928: * Fix invalid syntax bsc#1048645 bsc#1060738- Update to version 20170927: * fix typos in manpages- Update to version 20170922: * Allow setuid root for singularity (group only) bsc#1028304- Update to version 20170913: * Allow setuid for shadow newuidmap, newgidmap bsc#979282, bsc#1048645)- Update to version 20170906: * permissions - copy dbus-daemon-launch-helper from / to /usr - bsc#1056764 * permissions: Adding suid bit for VBoxNetNAT (bsc#1033425)- BuildIgnore group(trusted): we don't really care for this group in the buildroot and do not want to get system-users into the bootstrap cycle as we can avoid it.- Require: group(trusted), as we are handing it out to some unsuspecting binaries and it is no longer default. (bsc#1041159 for fuse, also cronie, etc)- Update to version 20170602: * make /etc/ppp owned by root:root. The group dialout usage is no longer used- Update to version 20160807: * suexec2 is a symlink, no need for permissions handling- Update to version 20160802: * list the newuidmap and newgidmap, currently 0755 until review is done (bsc#979282) * root:shadow 0755 for newuidmap/newgidmap- adding qemu-bridge-helper mode 04750 (bsc#988279)- Introduce _service to easier update the package. For simplicity, change the version from yyyy.mm.dd to yyyymmdd (which is eactly %cd in the _service defintion). Upgrading is no problem.- chage only needs read rights to /etc/shadow, so setgid shadow is sufficient (bsc#975352)- permissions: adding gstreamer ptp file caps (bsc#960173)- the apache folks renamed suexec2 to suexec with symlink. adjust both (bsc#962060)- pinger needs to be squid:root, not root:squid (there is no squid group) bsc#961363- add suexec with 0755 to all standard profiles. this can and should be overridden in permissions.local if you need it setuid root. bsc#951765 bsc#263789 - added missing / to the squid specific directories (bsc#950557)- adjusted radosgw to root:www mode 0750 (bsc#943471)- radosgw can get capability cap_bind_net_service (bsc#943471)- remove /usr/bin/get_printing_ticket; (bnc#906336)- Added iouyap capabilities (bnc#904060)- %{_bindir}/get_printing_ticket turned to mode 700, setuid root no longer needed (bnc#685093) - permissions: incorporating squid changes from bnc#891268 - hint that chkstat --system --set needs to be run after editing bnc#895647/bin/shbuild80 1570723906 20181116-lp151.4.6.120181116-lp151.4.6.120181116-lp151.4.6.1permissionspermissions.easypermissions.localpermissions.paranoidpermissions.securechkstatsysconfig.securitypermissions.5.gzchkstat.8.gz/etc//usr/bin//usr/share/fillup-templates//usr/share/man/man5//usr/share/man/man8/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:11244/openSUSE_Leap_15.1_Update/2d0af010771502e4e6a98c9788d7df6b-permissions.openSUSE_Leap_15.1_Updatecpioxz5x86_64-suse-linuxASCII textELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/l, for GNU/Linux 3.2.0, BuildID[sha1]=8e79cda1a39ea75467ff85e3807ac272a2fc72ea, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)R R RR RH=PpH{3S+:utf-8bbe87a405951d8e725f4e38449e448701e60efa4031a9c3d431ed2441d74ec3e?7zXZ !t/R] crv(vX0~ފ=Nɩ-uf )@uw ␍{zibĥ\CGԚ<"0y|ca~rǓ2ս'ʾ~K$D 0\|n'__dB@>1̊L| VCy=OY̓KÍU@"aͩ FpX8? wH(JcUE2vz\ HZ2yݐacgYYu yZVhYC9y攸YȏuG?n;.mս|B64P7tGckԒG|C.cZZ&pol_*#",\6Թ~عAkǜ{-qהbc[E)pC j{}-ǟ1pvu1h\aLRP9 "A o&>wRߣ4|bQnckBGVK$k _aRы}}\+uj͍6V*3vh@w&Eb!tFRz8 K ̰_h͛|!ۑҫ>m2سTԣ/rX7xxK*T\7]̒{1m IR{|{fW98t$q?j|.2CYb,,E9s KyF̢b &wd6$5Grϕ;esޙBCA>@|vo wm]'+mphu&,>R+F:7q bGwoq}c` OڂBNpѯ{mĽ;FR&ܦ}4,dυx{ 8VQT%3ݹ̕PU8FJO~g[#\6?>5HۜU"?tJ H.m+y2]K{ >idSSTp/̭#7ЦPCoVMƮL!* us-gZV[3 Km3vŀ\z`xT3DrbNZ̸?;IVڵ71>,49Z^Cfh' %wmxь R׹;b"Jq:W}[3pg!GSx{Ж-^NCcbGHL)V\ 3B_qɀ"f/ ц?xu FgЬ랛. qcIZ :RC[΅^0(Q崪Xώ#idmm_8j#e=ؑ)hZPr]mHg41v'ҹ>#znr񊈁TMޫ')2EK|XDuԗ}e#`uK yFԚ7idT&aVW9}KT#ox0&ҏ OW<-ˎ%@6[a WB;kԉr^|%K BŵUTpy4[^3nm:˹Ƿ&1_r%tuCR6bHT>b2pQ$-׹߶GRli6WHIHR;EINyr&w] ^S}׎ūLKΈMB b#pbϙw -r>)d EZ\tߛ.I84 ,_1fs2srK1380Nሊ_ii\ }ش$z࢞B56$^)`YP_2WhP ¦@7a)K|fQ/W 5"6)XTlNM2؆ATM?jKe:HN0F{FfE(V~}Q:K}H1a;K\zF>y2&~=:`ً pJ+g{u]HdK VFb%lu,qQiWy'V1ЁE*&1SYN) )[cFHPE ʳ*'^f-]!D) ~)d~T)%<{}h)H%LM\jhʙbFgZf76&_qj$˗:dǿϷpHEwЄђ%{tk+LtS6'=I}Tocryd4)Ko] t90%v#vsNَ 3@388!Sk7HͫD0{fqOWV &ep@Q'٬68Q9 n u^s)cL3JK|31|vtŃsW! 8e3[΄fäKЉ=icaeBsa7W89}od[1v_Ϡ_MpPGu"p ~X"T4 mlU5,4;=( O;L enՎeK d0DpgF_7He{ u9]-_IIӺcT֞_LKdBE@AS d00%{$h-Zƾo7uEjN6({ͨxA ҍaQ9]G2TS=#tppx pB2aƇo&XB#O4a_ %ވЉ'}:IOŌ qSfT$YE7_ ~m %[NݏJq0XcliߙT ^М.~C=s\ȯ4h p!i>IA<]jW|RxyI?61$Ү -Ԕ^5\Tׂvtʜ%3 F5sԇIXV.F>S8-kamCkDy {65KRQX|V~` KgH/ũT"#k^\N,LUl) WV?3I^a Ŭ8G5sxVAM$1٧r8|*Ѻj@EtYoNH mXWu?˘P=?hg4MQ !7w _@YN1p/[ =$"~ ŒÝ_!X%5" ~{ .=5̱YEaho4]lj'G=dҰPׇHN(Wo@2{:]jEܝ-I {[th.%'i3~@EOc"``1 .$DH.RMt*޳ܛ`Z >XE m)@X0RC\@sp"uqj'*6YTLu`?v 4/A &9XR5PJ0:La Ni%"!0v Or&4(Wq0Ez$QᶍBU;}+J`:㠾m{$[v,RU{Oc:fm7ݫ](Ah3udQ3&TL>dnhkSQʗ7:F+Q^ \l> T m _C RW­uSBcsKӪR]@IcUCܙzQI$S>2+O{Xfsk&- |f Rcԡ16ֳ%3&S:QD%)"Ig%,_%dr%xD˶91O\NFS(nxW -9=uWn'!QH:-H˯ohoaLnXzZ*Zp67v4KuEsMlNzI/?'ؐz_p{NdEb V?< +ngF}ї0&M,vaM-0~d+88!52ujƪ GS~ QO;%s$%0| SSaRbvk4N ~FZྖS)(jL!Ri>i(n8atLǝZ| [ʒ~SR5i8j琑_z>zlZ$9jTe5B6/!J6X1K'&%BV>MA+w[ )U2#$WwB3t: q̌ h5PJh%샐~X`g"]v MR' J~. Tg+b*/{EŔK0V \[suIE~?'ZDzkCRjIU[AK*̓HΛc Yn#!7m #ߍOѯK*px]ӷޡ-b03o};Sz|&W&Fwivg FsAv?l :<V#[M|]P|?~4Y^BWdm{_;@,FE8HNȒGx(}fynv 1Ƣ%qlǡ܏Гt֧)%/;l`AXFr;wN&u-v4hxM%)fEA_j5*bi ̖gbMӔ߃g'FF"|"0Ux1Ṣ"6Rf֥Xf/-b)k1,>W-5 pDw߀R- ېv2nb៉i/g+6F\i_֤^qnnIuX Y ;-Ў`HFɖ?&(,!`W =/ty23ZN`CŦ[jOX$WTb,f9$;T֩ Ǘf#eHL‡K縟> qܫ</_@}YnЭhk5 z@_2v,`+@chI 7h]0g MMd=r Ne& > 2V݇Z!X{9Kwh:rN +PMwlp< >|XПG8GC\s!˜m'Rmcy%$W4U =@TF8JxUJtYv)izfLpGQxƚdqX QetS`ԗт>ISbŻ8ZuhO^Q`#XR)F ,|ך'S89c&51DO~ݡ\EwjNc0_ 36dPJ>hժM5) ?DeRO:Y %%cȧuDcȍ#sݫ7<dCu;Ǣk7NBآ<@Wami^6hcJҌNu{vBWf:0봀K;X`#J3Eaʠc(n\j,fM-N{OCW53uyHm4A}C|ӑ?[yN6: &<\T;K%s7:H[_I%|!IuXlv'=; MZK:~ڨ?y6zGu0~Q&ԡ6 x'"„DŽerרU{7ipN<³iVԟp-̡#|L|7Zs'4ZąV Yk jOݵ244@*FVs<7muZ{hS"SzuҟL8qszu1 7b԰d{.@5ݟz+Ky"AbQΟ`ApLVu^^;jhc?ڙ[ݠkWKk+|Ig$n":,0D+cs&EBwV 9UI Y̘{~hE ly.L \Z;$ Q5'5zl1~H\YiXyѭҋzkbioj=1PXF>K):fU>q2 _zuvxGտ9Mlfi{8{NۙX>Q"4il"kT\b87rAKzpw Oo9 NʁHeM/9S'rh8 299$RQ$$7r ]7̢-'ǃIjd^wȳIzFT"UZNO~zekeP)uiȸ# 4oMOE{3y BDq`,!9^0=2~BQ nn!n85hĿ cRaW(?lʴbMLjL,YRS%+]OMA,Y?b/b$#WpQkl;{n8Ki&DZ#HG5M=Af>O3M-a4&pjBk+/}:*Wb]HL˝f8ه lo|POf2D;ǐcj];eTcgR-لJ=[:eyQa ]AE[ܑ>/jdxⷵ=n7G/ih<$CLX}N\‰QF3XVF[͇i{PW~1Nn3/WZ^m62 hg 7 HoanVoС~IUpTF)~{ niNm>Mk{M!ijFzcjT|O}aLjx1N\X PZam'/_c[QN5RO |TYSKB;yD&PIµ/w>hcC°E0ΫpTaH3J'*ԘsU5$QVyˌKJ:ljt`G+W5=8 ;)\в[p0\Am/d2ZF-pR'΁]t]ӌ)4U=Aɦ]\K!7Nn #ci*4y3t(I%Aɒ tfCa]/*j\g[HS\,9X?Ifƶ+gWjy|P&7̼nM3E%[؅;0GM254d_%G/87Zٕpމ"j-{UH2O8=Q~B D/eFWaS_݉J7*dnkrFj|\9\ }]j| n uJO94s/KFBj '9΍݅d Y<JGp}h9zJƪ>;Pdj\cnc&OFjڰ :eo5zmsy?n @g>RxmYbhL6l#\?k񦤫P@D5E ܐ ziw3DfFª ;cF2xU㽂0Upk*蜽i䪰$#hbZZ;|-4̱V`_SsKSUPq׊E+>l$XDK7BU-Oscynkٟn섣j!nR'I0pa d9ӱjPfY8\$|7)Flw8VPF"=G/TԢ[i"y1 Fq>4"2,bmB><7@9EWqFJQ:ÒV^I4GahHʩ@2A)z=,aMy$3$R9$ XC=@wxi}YD#p?!À@ ֲ>2ߙ*2eࡂmrq4"+!kPBvb4$vy%Jy_t0SYƵx@g}/CW+tQ*|UFqjc8ŏsnp ۸>FT<qQ!ۚ !:O5G s%(s_& v;#/T5|Y 86|; @JBتǾ{wcp4?]*)ҿ"U-ş*Ҙ0CFoiꭱ1|NcXJ9PԼPhQup)}u"u,k2ͤ&'jo%CΌq;-4kUZm}V 17L]Me% ($эզWlI YL<-x1}_R+Ђ]γ+XPeP^1*GD3v 75i}c|:tѓoJ\kHC''](J [yk8sd4UJ8x di$ 3T4qRa= Sm`j Xh/j mr_VӸy $>,Tچe U> Ӄpu1nb']ޕ 36CQ!kO('eet< tD祻2qS=bMc&v7zU_`e)V4jVFxPnj7hvW!\kc)n!FTȔo(݃M,剿$\\BU+ip9F(+|PRӒY[yfsŸc#_$HIIx/х4˵ΘJ 6"(2Ẍ́HdH R=n_[Z~Ay" q`\%AyJđA+Y}Cַ?MK>ȝYoN!4,s2=⪚[DA#ؗ`m-rQ&  y@Eax5J~,Z'(Ytdxh6OfEsFIɵuITpws~vrs*D Q!A'prA˛c_9'Ww믋Z*@U6M zm(8 RA/FTNh"^ƢQ0;n1Q\Fs-$C[ѡe[R[Sd5 xUmduӶ3QL ;ZKşHyrip|9d0m C0rÚc?G ih=m2>Rڷ[FY)Q 8ئbg XQ `5Q^h87Fg-g F0{v'Q"!`\x a) ^C;5q[ܘ7]5(v7z,rYk ?.>ǾfPhq<ʏO-I Og*O2Wբ'RT;&1?Į]X2pf6?rl~U K2&Nn?Ntm.akgZe )%:ج슸stj~P0NF hLzL#Xp`) *Q79A**o#bҨ>N&v` v_.ZҪр'%)+o1GR >ɩE4cc3KB}NP[R˾*MJ)|Rc%-P_FsbN(R q0DVڷ! ;`m_=ߞS XX4C<" 26+(m0kk pmggύ<$4<}V=DP:Hi2E1W˦.6}$We+:MV Qk]e7as?u-/8!ۍ4`PMԍ-e9)4*=$4fLj({-Э,aBHf_S9$~bZq$O+^c S(zܿ4e'Q-`"SiFUw_<8# fyyLVgRT p9w8D14ih8 4;t";ޞxH^u =,e>׋M @DgFe<޿`h!c!'!VTa,Du7-P1]]D`O17OrFf>F 2UfWZdagH=kmFlLoo蕏? g?]6RF$ib%*2% q)Lݎ?2/~$]xZ)(D^\Ca:;+Rh-`%ٳB mJad)^1 (/ JP1{=2.aku:\akM V.Dfߚ#-QZ`I?bb2ܒTAi]1Y\䂣MQ^ZjSOg<| c*?qt+-gw^ EMGhovd7cOBmf ўiK3!Lc NAh&VokhTd,ӸqGKZX6Klb0NJ6Yr&[*\ZU2szEG Y܈XT-I&WfeSʄI'B=G#iA'wfMVη7}D))2m?}SfL/;kZ^;ru#mʟbvp151XW"j J?3S:-?LX}=Nq-zBaud[qګ^%pac*J9!mw|"?qͬXNBUV;k:x!vg?# M>[İbJ0 l&on0u^X%w"p̷),u]iDUp#^kUi}uطeE)~fVm"7 C)S+0ߵb̎\l:Yf"; <2}l4uϱXqA.Fd3]ԱKr 40edvңSDF{JS)pӯ) m|K Hw;gص/pqe2N% 29̊qT{:πY'%2ji7{Ku7)wEfZ7(.Uh g0m՛]Y7|@@`_apҁL~iBZ)Tяb?m''1wT7P ?»eI" bSV%m _6u51f흔|Sd#Iuy@^kNҾTl|@"vRAk[f$B5w׬S))i6v JPU\6 Szz|ˬ&Y`@bnt{<87.i bbJج I[st7Ok|Ds/y4x vbd>R "}]6ɜ"58A5-I~RA =̉s[y.oA41ġpՖFzUŬv>')w _5hV# 꺛[󃾻 4'Bq1xJ^{ ϟc<˅=Db]<,}Ҁ `C>  3Rt%XGƘҚ.( %S<;Hp,#v_Ǽϵ9}+꾗y7>fǫ`۽U_WYqT?׉uɤ&b{G$6x݆dGOO'm~#Mɳ;zb<{yB;i!C50ї3> 젘 ,{GW%_^ qZ6šn@_qq.Qm&P^ÀVoS7IL>C֊W [|='ɋA'ߨ'Ɉ \#Mڭ vd̤p:yQpP5ja6meL^I<9 V.dDn>nLʫEH .~_nF u;sPO%EY1-UU#7 YNB nk flpr֢I_@]P48]1tWT"WV(D t0\ s0 ) y`>sJG!zؾY{H[4<`}"5k`qXwp+E֏`b;QjBRÇ^0]Po$0F^S)>2tO5ՈCfGkQY&T~ZҘQ//aRn 7 B%;)ŏJ @Oƽݲf`I_n5 zWB,SϾ,i(11Ӡʏ+-dgM)np_Lƕs9:?j[$1{ߔB~ @4N{;g2KUQN.59#xxY穫ңSRFs4[YUl3kkY^AVY@f!XUy;|i5[ӨF; :2ׂP]Ԫv#9zh S %"o&De@_{= L6`KRF .MM$͙v^}6-~EWs5f9*aҖnx0>_"{AKߛ/z+A94JƉ]ZQwؙg(5i JVi( BW`2~w;m>}-T8NWcfe5+C *LG6g|dO%: 銊'3Y}Mg,籹+ 6M*~r$_pHc^L:AFDz9>Ί3;DW4-?y q9%8KJԬ)IgaheY&U&ZpwXtXe]2M6q;9w^l iN/aF>R/HqG<͉}ˮ,"t`ѸqEdf>%4;erLp?%)xSR@"uݭ)Sg{ү쵗i$8x2`DDwwt2uFx䃥f$i_l s3v:/~f?Z(;QD)@)i#чiCH7}OQUYOH̉JĿs(PPS} qaC8 'o~e[`&+Glk"^[ES-P3EXB"J}L;,b+ 6KѣH}WHD@k7fZPP^ 1Ƣtц!Ǿ\(@ ܽ$Vv5{^2 7R*2Axk &rNa!g;EQ.\ 7EAI/:5!z!Srt}~vRf?څqF7OB\4fj}{8M?q ćF~)"2˜0)`6h@\EU~]T^aRP D$& µ1O΍e efQ(,X0*q)4 pT!"Q{kݥj?ʜBoMO {ult$n]Q-{P5=; hДɥ T8릠Dn*LD 76+N ;'Nz~ ^ ,ot"r@H2.A+ubt>b}|v=XA"l+0$Cof/O\ZkEb˸>: M