permissions-20200127-lp153.24.6.1 4>$  ApaX/=„}6m'95% ao/zXR7lq\`jԞN*J.&H,Q #1ř Zg )9=fi3NWU,/_ԁl]Ym<Q[b,8oO6]\c$񫣋DsAZ/ rŮcAw8W)`GcBEX=p*KjQSD= n2]kB7`a_O*TxQG<1J!߲yD1jje$4g(ޯ #RŇsWJ3hGkiB>p@z?zd $ C+4= Vl8 \  n          I v   L ?( z8 79 `7: 7>u@FuHGud Hu Iu XuYu\v ]v0 ^vbwcwdxUexZfx]lx_uxt vxwy xy yz zz,z<z@zFzCpermissions20200127lp153.24.6.1SUSE Linux Default PermissionsPermission settings of files and directories depending on the local security settings. The local security setting (easy, secure, or paranoid) can be configured in /etc/sysconfig/security.aOobs-power9-06=XopenSUSE Leap 15.3openSUSEGPL-2.0+http://bugs.opensuse.orgProductivity/Securityhttp://github.com/openSUSE/permissionslinuxppc64le PNAME=security SUBPNAME= SYSC_TEMPLATE=/usr/share/fillup-templates/sysconfig.$PNAME$SUBPNAME # If template not in new /usr/share/fillup-templates, fallback to old TEMPLATE_DIR if [ ! -f $SYSC_TEMPLATE ] ; then TEMPLATE_DIR=/var/adm/fillup-templates SYSC_TEMPLATE=$TEMPLATE_DIR/sysconfig.$PNAME$SUBPNAME fi SD_NAME="" if [ -x /bin/fillup ] ; then if [ -f $SYSC_TEMPLATE ] ; then echo "Updating /etc/sysconfig/$SD_NAME$PNAME ..." mkdir -p /etc/sysconfig/$SD_NAME touch /etc/sysconfig/$SD_NAME$PNAME /bin/fillup -q /etc/sysconfig/$SD_NAME$PNAME $SYSC_TEMPLATE fi else echo "ERROR: fillup not found. This should not happen. Please compare" echo "/etc/sysconfig/$PNAME and $TEMPLATE_DIR/sysconfig.$PNAME and" echo "update by hand." fi # apply all potentially changed permissions /usr/bin/chkstat --system;Tk1W6^ 9;@큤aMaMaMaMaMaNaMaMaM08f79ea016f1288ae1033733838b5d3c1b0c760511a3c00dd8792272c20e18a561c722ee39b8cbf07c24b99c9a866362671c5a984607616229b6fab62f7ec8be254ecad52808937c3153a81d50810ee7e689d78dfc2cf8aac67cf179a2fdbf3be186e053c2d66276c577c08ccdc467d5b4150a19c0bfeccd7eed528e80e61d42c0b8419b68f4b7b2ec821478798185bc1fca31a07a1a0d447ffc04046566659c191cc05cecc1ebaaa4620c2f4e072c53db14238ee765444ca9c6ba146324933135eca1eb5762d2b602f4b5114a54eb6e6815d26f10b5dab00cda67f2860ca4a32dcb772c1e9949198bc7695bd25c20cd21aea565905b0975de2edeafb31d8202acbebeb00ef9fccc619e66ad50b5c31ac346b2e06ec7d429ec8d2181bc5bd2f1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpermissions-20200127-lp153.24.6.1.src.rpmaaa_base:/etc/permissionsconfig(permissions)permissionspermissions(ppc-64)@@@    /bin/shconfig(permissions)coreutilsdiffutilsfillupgrepgroup(trusted)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcap.so.2()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)20200127-lp153.24.6.13.0.4-14.6.0-14.0-15.2-14.14.3aaa@`@` l^?@^ϧ^>@^^y@^\@^Y^;^:@^4]@]@]@]@]:\8\b@[@[z@ZiZ\Z%8ZZ@Z@Z@ZNY|Y@Y˒Y@YY@Y7Y2Y1S@W"W@W@WBWBVV@VV2 @V +V +UuT~@TZ@matthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.commalte.kraus@suse.comjsegitz@suse.comjsegitz@suse.comjsegitz@suse.commalte.kraus@suse.commalte.kraus@suse.commatthias.gerstner@suse.commatthias.gerstner@suse.comMalte Kraus Malte Kraus Malte Kraus Malte Kraus Johannes Segitz Malte Kraus jsegitz@suse.comjsegitz@suse.comopensuse-packaging@opensuse.orgmatthias.gerstner@suse.commeissner@suse.comkrahmer@suse.comkukuk@suse.commpluskal@suse.comastieger@suse.comrbrown@suse.comkrahmer@suse.comeeich@suse.comjsegitz@suse.comastieger@suse.compgajdos@suse.comastieger@suse.comastieger@suse.comopensuse-packaging@opensuse.orgdimstar@opensuse.orgmeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comkrahmer@suse.comdimstar@opensuse.orgmeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.commeissner@suse.comkrahmer@suse.commeissner@suse.com- Update to version 20200127: * base this fork on a SLE-15-SP3 branch instead of on the Factory branch. The Factory branch contains too many unknowns for the far-off Leap 15.3 codebase. * add a couple of cleanup changes that we can on Leap 15.3: - etc/permissions: remove unnecessary static dirs and devices - etc/permissions: remove legacy RPM directory entries - etc/permissions: remove outdated sudo directories- Update to version 20200127: * Makefile: Leap 15.3 still uses /etc, so adjust the installation setup- Update to version 20181225: * mgetty: faxq-helper now finally reside in /usr/libexec * libksysguard5: Updated path for ksgrd_network_helper * kdesu: Updated path for kdesud * sbin_dirs cleanup: these binaries have already been moved to /usr/sbin * mariadb: revert auth_pam_tool to /usr/lib{,64} again * cleanup: revert virtualbox back to plain /usr/lib * cleanup: remove deprecated /etc/ssh/sshd_config * hawk_invoke is not part of newer hawk2 packages anymore * cleanup: texlive-filesystem: public now resides in libexec * cleanup: authbind: helper now resides in libexec * cleanup: polkit: the agent now also resides in libexec * libexec cleanup: 'inn' news binaries now reside in libexec * whitelist please (bsc#1183669) * Fix enlightenment paths * usbauth: drop compatibility variable for libexec * usbauth: Updated path for usbauth-npriv * profiles: finish usage of variable for polkit-agent-helper-1 * Makefile: fix custom flags support when using make command line variables * added information about know limitations of this approach * Makefile: compile with LFO support to fix 32-bit emulation on 64-bit hosts (bsc#1178476) * Makefile: support CXXFLAGS and LDFLAGS override / extension via make/env variables (bsc#1178475) * profiles: prepare /usr/sbin versions of profile entries (bsc#1029961) * profiles: use new variables feature to remove redundant entries * profiles: remove now superfluous squid pinger paths (bsc#1171569) * tests: implement basic tests for new the new variable feature * tests: avoid redundant specification of test names by using class names * regtests: split up base types and actual test implementation * man pages: add documentation about variables, update copyrights * chkstat: implement support for variables in profile paths * chkstat: prepare reuse of config file locations * chkstat: fix some typos and whitespace * etc/permissions: remove unnecessary, duplicate, outdated entries * etc/permissions: remove trailing whitespace * ksgrd_network_helper: remove obviously wrong path * adjust squid pinger path (bsc#1171569) * mgetty: remove long dead (or never existing) locks directory (bsc#1171882) * squid: remove basic_pam_auth which doesn't need special perms (bsc#1171569) * cleanup now useless /usr/lib entries after move to /usr/libexec (bsc#1171164) * drop (f)ping capabilities in favor of ICMP_PROTO sockets (bsc#1174504) * whitelist Xorg setuid-root wrapper (bsc#1175867) * screen: remove /run/uscreens covered by systemd-tmpfiles (bsc#1171879) * Add /usr/libexec for cockpit-session as new path * physlock: whitelist with tight restrictions (bsc#1175720) * mtr-packet: stop requiring dialout group * etc/permissions: fix mtr permission * list_permissions: improve output format * list_permissions: support globbing in --path argument * list_permissions: implement simplifications suggested in PR#92 * list_permissions: new tool for better path configuration overview * regtest: support new getcap output format in libcap-2.42 * regtest: print individual test case errors to stderr * etc/permissions: remove static /var/spool/* dirs * etc/permissions: remove outdated entries * etc/permissions: remove unnecessary static dirs and devices * screen: remove now unused /var/run/uscreens * Revert "etc/permissions: remove entries for bind-chrootenv" * rework permissions.local text (boo#1173221) * dbus-1: adjust to new libexec dir location (bsc#1171164) * permission profiles: reinstate kdesud for kde5 * etc/permissions: remove entries for bind-chrootenv * etc/permissions: remove traceroute entry * VirtualBox: remove outdated entry which is only a symlink any more * /bin/su: remove path refering to symlink * etc/permissions: remove legacy RPM directory entries * /etc/permissions: remove outdated sudo directories * singularity: remove outdated setuid-binary entries * chromium: remove now unneeded chrome_sandbox entry (bsc#1163588) * dbus-1: remove deprecated alternative paths * PolicyKit: remove outdated entries last used in SLE-11 * pcp: remove no longer needed / conflicting entries * gnats: remove entries for package removed from Factory * kdelibs4: remove entries for package removed from Factory * v4l-base: remove entries for package removed from Factory * mailman: remove entries for package deleted from Factory * gnome-pty-helper: remove dead entry no longer part of the vte package * gnokii: remove entries for package no longer in Factory * xawtv (v4l-conf): correct group ownership in easy profile * systemd-journal: remove unnecessary profile entries * thttp: make makeweb entry usable in the secure profile (bsc#1171580) * profiles: add entries for enlightenment (bsc#1171686) * permissions fixed profile: utempter: reinstate libexec compatibility entry * chkstat: fix sign conversion warnings on non 32-bit architectures * chkstat: allow simultaneous use of `--set` and `--system` * regtest: adjust TestUnkownOwnership test to new warning output behaviour * whitelist texlive public binary (bsc#1171686) * fixed permissions: adjust to new libexec dir location (bsc#1171164) * chkstat: don't print warning about unknown user/group by default * Makefile: link with --as-needed, move libs to the end of the command line * setuid bit for cockpit (bsc#1169614) * Fix paranoid mode for newgidmap and newuidmap (boo#1171173) * chkstat: collectProfilePaths(): use directory_iterator to simplify code * chkstat: collectProfilePaths(): prefer /usr over /etc * regtest: add relative symlink corner case to TestSymlinkBehaviour * Chkstat::parseProfile(): avoid use of raw pointer * parseSysconfig(): only emmit warning if value is non-empty * incorporate a bunch of PR #56 review comments * regtest: add test for correct ownership change * chkstat: final pass over refactored code * chkstat: finish refactoring of safeOpen() * chkstat: improve/fix output of mismatches * chkstat: support numerical owner/group specification in profiles * chkstat: safeOpen: simplify path handling by using a std::string * chkstat regtest: support debug build * chkstat: start refactoring of safe_open() -> safeOpen() * chkstat: processEntries: pull out change logic into applyChanges() * chkstat: processEntries: pull out safety check logic * chkstat: processEntries: separate printing code and simplify ownership flags * chkstat: processEntries: also add file_status and *_ok flags to EntryContext * chkstat: processEntries: also add caps to EntryContext * chkstat: also move fd_path into EntryContext * chkstat: processEntries(): introduce EntryContext data structure * chkstat: introduce class type to deal with capabilities * chkstat: overhaul of the main entry processing loop * chkstat: smaller cleanup of Chkstat::run() * chkstat: remove last global variables `root` and `rootl` * chkstat: refactor parsing of permission profiles * chkstat: replace global `permlist` by STL map * chkstat: remove now obsolete usage() function * chkstat: refactor collection of permission files * regtest: support --after-test-enter-shell * chkstat: change global euid variable into const class member * chkstat: replace global level, nlevel by a vector data structure * chkstat: refactor check_fscaps_enabled() * chkstat: refactor parse_sysconfig as a member function Chkstat::parseSysconfig * chkstat: introduce separate processArguments() and refactor --files logic * chkstat: replace C style chkecklist by std::set * chkstat: refactor command line parsing * allow /usr/libexec in addition to /usr/lib (bsc#1171164) * whitelist s390-tools setgid bit on log directory (bsc#1167163) * whitelist WMP (bsc#1161335) * regtest: improve readability of path variables by using literals * regtest: adjust test suite to new path locations in /usr/share/permissions * regtest: only catch explicit FileNotFoundError * regtest: provide valid home directory in /root * regtest: mount permissions src repository in /usr/src/permissions * regtest: move initialialization of TestBase paths into the prepare() function * chkstat: suppport new --config-root command line option * fix spelling of icingacmd group * chkstat: fix readline() on platforms with unsigned char * remove capability whitelisting for radosgw * whitelist ceph log directory (bsc#1150366) * adjust testsuite to post CVE-2020-8013 link handling * testsuite: add option to not mount /proc * do not follow symlinks that are the final path element: CVE-2020-8013 * add a test for symlinked directories * fix relative symlink handling * include cpp compat headers, not C headers * Move permissions and permissions.* except .local to /usr/share/permissions * regtest: fix the static PATH list which was missing /usr/bin * regtest: also unshare the PID namespace to support /proc mounting * regtest: bindMount(): explicitly reject read-only recursive mounts * Makefile: force remove upon clean target to prevent bogus errors * regtest: by default automatically (re)build chkstat before testing * regtest: add test for symlink targets * regtest: make capability setting tests optional * regtest: fix capability assertion helper logic * regtests: add another test case that catches set*id or caps in world-writable sub-trees * regtest: add another test that catches when privilege bits are set for special files * regtest: add test case for user owned symlinks * regtest: employ subuid and subgid feature in user namespace * regtest: add another test case that covers unknown user/group config * regtest: add another test that checks rejection of insecure mixed-owner paths * regtest: add test that checks for rejection of world-writable paths * regtest: add test for detection of unexpected parent directory ownership * regtest: add further helper functions, allow access to main instance * regtest: introduce some basic coloring support to improve readability * regtest: sort imports, another piece of rationale * regtest: add capability test case * regtest: improve error flagging of test cases and introduce warnings * regtest: support caps * regtest: add a couple of command line parameter test cases * regtest: add another test that checks whether the default profile works * regtests: add tests for correct application of local profiles * regtest: add further test cases that test correct profile application * regtest: simplify test implementation and readability * regtest: add helpers for permissions.d per package profiles * regtest: support read-only bind mounts, also bind-mount permissions repo * tests: introduce a regression test suite for chkstat * Makefile: allow to build test version programmatically * README.md: add basic readme file that explains the repository's purpose * chkstat: change and harmonize coding style * chkstat: switch to C++ compilation unit * remove obsolete/broken entries for rcp/rsh/rlogin * chkstat: handle symlinks in final path elements correctly * Revert "Revert "mariadb: settings for new auth_pam_tool (bsc#1160285)"" * Revert "mariadb: settings for new auth_pam_tool (bsc#1160285)" * mariadb: settings for new auth_pam_tool (bsc#1160285) * add read-only fallback when /proc is not mounted (bsc#1160764) * capability handling fixes (bsc#1161779) * better error message when refusing to fix dir perms (#32) * fix paths of ksysguard whitelisting * fix zero-termination of error message for overly long paths * fix misleading indendation * fix changing of capabilities * fix warning text for unlisted files * fix error message with insecure sym links * remove useless if around realloc() * fix invalid free() when permfiles points to argv * use path-based operations with /proc/self/fd/X to avoid errors due to O_PATH * add .gitignore for chkstat binary * add/fix compiler warnings, free memory at exit * only open regular files/directories without O_PATH, fix stat buffer initialization * update * rewrite while protecting against symlinks and races * fix whitespace * faxq-helper: correct "secure" permission for trusted group (bsc#1157498) * whitelist ksysguard network helper (bsc#1151190) * fix syntax of paranoid profile * fix squid permissions (bsc#1093414, CVE-2019-3688) * setgid bit for nagios directory (bsc#1028975, bsc#1150345) * global: removal of unneeded SuSEconfig file and directory * global: restructure repository layout * dumpcap: remove 'other' executable bit because of capabilities (boo#1148788, CVE-2019-3687) * add one more missing slash for icinga2 * fix more missing slashes for directories * cron directory permissions: add slashes * iputils: Add capability permissions for clockdiff * iputils/ping: Drop effective capability * iputils/ping6: Remove definitions * singluarity: Add starter-suid for version 3.2.0 * removed entry for /var/cache/man. Conflicts with packaging and man:man is the better setting anyway (bsc#1133678) * fixed error in description of permissions.paranoid. Make it clear that this is not a usable profile, but intended as a base for own developments * Misleading comment fix * removed old entry for wodim * removed old entry for netatalk * removed old entry for suidperl * removed old entriy for utempter * removed old entriy for hostname * removed old directory entries * removed old entry for qemu-bridge-helper * removed old entries for pccardctl * removed old entries for isdnctrl * removed old entries for unix(2)_chkpwd * removed old entries for mount.nfs * removed old entries for (u)mount * removed old entry for fileshareset * removed old entries for KDE * removed old entry for heartbeat * removed old entry for gnome-control-center * removed old entry for pcp * removed old entry for lpdfilter * removed old entry for scotty * removed old entry for ia32el * removed old entry for squid * removed old qpopper whitelist * removed pt_chown entries. Not needed anymore and a bad idea anyway * removed old majordomo entry * removed stale entries for old ncpfs tools * removed old entry for rmtab * Fixed type in icinga2 whitelist entry * New whitelisting for /usr/lib/virtualbox/VirtualBoxVM and removed stale entries for VirtualBox * Removed whitelist for /usr/bin/su.core. According to comment a temporary hack introduced 2012 to help moving su from coretuils to util-linux. I couldn't find it anywhere, so we don't need it anymore * Remove entry for /usr/bin/yaps. We don't ship it anymore and the group that is used doesn't exists anymore starting with Leap 15, so it will not work there anyway. Users using this (old) package can do this individually * removed entry for /etc/ftpaccess. We currently don't have it anywhere (and judging from my search this has been the case for quite a while) * Ensure consistency of entries, otherwise switching between settings becomes problematic * Fix spelling of SUSE * adjust settings for amanda to current binary layout- Update to version 20181225: * etc/permissions: remove unnecessary entries (bsc#1182899)- Update to version 20181224: * pcp: remove no longer needed / conflicting entries (bsc#1171883, CVE-2020-8025)- Update to version 20181224: * profiles: add entries for enlightenment (bsc#1171686)- whitelist texlive public binary (bsc#1171686)- Remove setuid bit for newgidmap and newuidmap in paranoid profile (bsc#1171173)- correct spelling of icinga group (icingagmd -> icingacmd, bsc#1168364)- whitelist s390-tools setgid bit on log directory (bsc#1167163)- run testsuite during package build - Update to version 20181224: * testsuite: adapt expected behavior to legacy branches * adjust testsuite to post CVE-2020-8013 link handling * testsuite: add option to not mount /proc * do not follow symlinks that are the final path element: CVE-2020-8013, bsc#1163922 * add a test for symlinked directories * fix relative symlink handling * regtest: fix the static PATH list which was missing /usr/bin * regtest: also unshare the PID namespace to support /proc mounting * Makefile: force remove upon clean target to prevent bogus errors * regtest: by default automatically (re)build chkstat before testing * regtest: add test for symlink targets * regtest: make capability setting tests optional * regtest: fix capability assertion helper logic * regtests: add another test case that catches set*id or caps in world-writable sub-trees * regtest: add another test that catches when privilege bits are set for special files * regtest: add test case for user owned symlinks * regtest: employ subuid and subgid feature in user namespace * regtest: add another test case that covers unknown user/group config * regtest: add another test that checks rejection of insecure mixed-owner paths * regtest: add test that checks for rejection of world-writable paths * regtest: add test for detection of unexpected parent directory ownership * regtest: add further helper functions, allow access to main instance * regtest: introduce some basic coloring support to improve readability * regtest: sort imports, another piece of rationale * regtest: add capability test case * regtest: improve error flagging of test cases and introduce warnings * regtest: support caps * regtest: add a couple of command line parameter test cases * regtest: add another test that checks whether the default profile works * regtests: add tests for correct application of local profiles * regtest: add further test cases that test correct profile application * regtest: simplify test implementation and readability * regtest: add helpers for permissions.d per package profiles * regtest: support read-only bind mounts, also bind-mount permissions repo * tests: introduce a regression test suite for chkstat- Update to version 20181224: * whitelist WMP (bsc#1161335) * Makefile: allow to build test version programmatically * chkstat: handle symlinks in final path elements correctly * add .gitignore for chkstat binary * faxq-helper: correct "secure" permission for trusted group (bsc#1157498) * fix syntax of paranoid profile- Update to version 20181224: * mariadb: settings for new auth_pam_tool (bsc#1160285) * chkstat: capability handling fixes (bsc#1161779) * chkstat: fix regression where chkstat breaks without /proc available (bsc#1160764, bsc#1160594) * dumpcap: remove 'other' executable bit because of capabilities (boo#1148788, CVE-2019-3687)Sync upstream SLE-15-SP1 branch with our SLE-15-SP1:Update package. Therefore remove all of the following patches which are now included in the tarball: - 0001-whitelisting-update-virtualbox.patch - 0002-consistency-between-profiles.patch 0003-var-run-postgresql.patch - 0004-var-cache-man.patch - 0005-singularity-starter-suid.patch - 0006-bsc1110797_amanda.patch - 0007-chkstat-fix-privesc-CVE-2019-3690.patch - 0008-squid-pinger-owner-fix-CVE-2019-3688.patch - 0009-chkstat-handle-missing-proc.patch - 0010-chkstat-capabilities-implicit-changes.patch Because of inconsistencies between the upstream branch and the package state the following previously missing changes are introduced by this update: - Update to version 20181117: * removed old entry for rmtab * Fixed typo in icinga2 whitelist entry- fix regression where chkstat breaks without /proc available (bsc#1160764, bsc#1160594, 0009-chkstat-handle-missing-proc.patch) - fix capability handling when doing multiple permission changes at once (bsc#1161779, 0010-chkstat-capabilities-implicit-changes.patch)- fix invalid free() when permfiles points to argv (bsc#1157198, changed 0007-chkstat-fix-privesc-CVE-2019-3690.patch)- fix /usr/sbin/pinger ownership to root:squid (bsc#1093414, CVE-2019-3688, 0008-squid-pinger-owner-fix-CVE-2019-3688.patch)- fix privilege escalation through untrusted symlinks (bsc#1150734, CVE-2019-3690, 0007-chkstat-fix-privesc-CVE-2019-3690.patch)- Updated permissons for amanda, added 0006-bsc1110797_amanda.patch (bsc#1110797)- Added ./0005-singularity-starter-suid.patch (bsc#1128598) New whitelisting for /usr/lib/singularity/bin/starter-suid- Added 0004-var-cache-man.patch. Removed entry for /var/cache/man. Conflicts with packaging and man:man is the better setting anyway (bsc#1133678)- Added 0001-whitelisting-update-virtualbox.patch (bsc#1120650) New whitelisting for /usr/lib/virtualbox/VirtualBoxVM and removed stale entries for VirtualBox - Added 0002-consistency-between-profiles.patch Ensure consistency of entries, otherwise switching between settings becomes problematic - Added 0003-var-run-postgresql.patch (bsc#1123886) Whitelist for postgresql. Currently the checker doesn't complain because the directories aren't packaged, but that might change and/or our checkers might improve- Update to version 20181116: * zypper-plugin: new plugin to fix bsc#1114383 * singularity: remove dropped -suid binaries (bsc#1028304) * capability whitelisting: allow cap_net_bind_service for ns-slapd from 389-ds * setuid whitelisting: add fusermount3 (bsc#1111230) * setuid whitelisting: add authbind binary (bsc#1111251) * setuid whitelisting: add firejail binary (bsc#1059013) * setuid whitelisting: add lxc-user-nic (bsc#988348) * whitelisting: add smc-tools LD_PRELOAD library (bsc#1102956) * whitelisting: add spice-gtk usb helper setuid binary (bnc#1101420) * Fix wrong file path in help string * Capabilities for usage of Wireshark for non-root - remove 0001-whitelisting-add-spice-gtk-usb-helper-setuid-binary-.patch: is now contained in tarball.- 0001-whitelisting-add-spice-gtk-usb-helper-setuid-binary-.patch: add whitelisting for the spice-gtk setuid binary (bsc#1101420) for improved usability.- Update to version 20180125: * the eror should be reported for permfiles[i], not argv[i], as these are not the same files. (bsc#1047247) * make btmp root:utmp (bsc#1050467)- Update to version 20180115: * - polkit-default-privs: usbauth (bsc#1066877)- fillup is required for post, not pre installation- Cleanup spec file with spec-cleaner - Drop conditions/definitions related to old distros- Update to version 20171129: * permissions: adding gvfs (bsc#1065864) * Allow setgid incingacmd on directory /run/icinga2/cmd bsc#1069410 * Allow fping cap_net_raw (bsc#1047921)- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- Update to version 20171121: * - permissions: adding kwayland (bsc#1062182)- Update to version 20171106: * Allow setuid root for singularity (group only) bsc#1028304- Update to version 20171025: * Stricter permissions on cron directories (paranoid) and stricter permissions on sshd_config (secure/paranoid)- Update to version 20170928: * Fix invalid syntax bsc#1048645 bsc#1060738- Update to version 20170927: * fix typos in manpages- Update to version 20170922: * Allow setuid root for singularity (group only) bsc#1028304- Update to version 20170913: * Allow setuid for shadow newuidmap, newgidmap bsc#979282, bsc#1048645)- Update to version 20170906: * permissions - copy dbus-daemon-launch-helper from / to /usr - bsc#1056764 * permissions: Adding suid bit for VBoxNetNAT (bsc#1033425)- BuildIgnore group(trusted): we don't really care for this group in the buildroot and do not want to get system-users into the bootstrap cycle as we can avoid it.- Require: group(trusted), as we are handing it out to some unsuspecting binaries and it is no longer default. (bsc#1041159 for fuse, also cronie, etc)- Update to version 20170602: * make /etc/ppp owned by root:root. The group dialout usage is no longer used- Update to version 20160807: * suexec2 is a symlink, no need for permissions handling- Update to version 20160802: * list the newuidmap and newgidmap, currently 0755 until review is done (bsc#979282) * root:shadow 0755 for newuidmap/newgidmap- adding qemu-bridge-helper mode 04750 (bsc#988279)- Introduce _service to easier update the package. For simplicity, change the version from yyyy.mm.dd to yyyymmdd (which is eactly %cd in the _service defintion). Upgrading is no problem.- chage only needs read rights to /etc/shadow, so setgid shadow is sufficient (bsc#975352)- permissions: adding gstreamer ptp file caps (bsc#960173)- the apache folks renamed suexec2 to suexec with symlink. adjust both (bsc#962060)- pinger needs to be squid:root, not root:squid (there is no squid group) bsc#961363- add suexec with 0755 to all standard profiles. this can and should be overridden in permissions.local if you need it setuid root. bsc#951765 bsc#263789 - added missing / to the squid specific directories (bsc#950557)- adjusted radosgw to root:www mode 0750 (bsc#943471)- radosgw can get capability cap_bind_net_service (bsc#943471)- remove /usr/bin/get_printing_ticket; (bnc#906336)- Added iouyap capabilities (bnc#904060)- %{_bindir}/get_printing_ticket turned to mode 700, setuid root no longer needed (bnc#685093) - permissions: incorporating squid changes from bnc#891268 - hint that chkstat --system --set needs to be run after editing bnc#895647/bin/shobs-power9-06 1639052111 20200127-lp153.24.6.120200127-lp153.24.6.120200127-lp153.24.6.1permissionspermissions.easypermissions.localpermissions.paranoidpermissions.securechkstatsysconfig.securitypermissions.5.gzchkstat.8.gz/etc//usr/bin//usr/share/fillup-templates//usr/share/man/man5//usr/share/man/man8/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:17259/openSUSE_Leap_15.3_Update/ecd2d65ef4113a7223bccfa02a0010d1-permissions.openSUSE_Leap_15.3_Updatecpioxz5ppc64le-suse-linuxASCII textELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, interpreter /lib64/ld64.so.2, BuildID[sha1]=6a4c8e3966ceb9f49e63b6d799222a254f6d91ac, for GNU/Linux 3.10.0, strippedtroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)RR R Kiȧ3lvutf-8386787a83803d1008418b92f40aec974b045d3a7e567c0e5ff4d3aac33708f8b?7zXZ !t/BcK] crv(vX0rr>VnJ8ij 4E+Qx1XyQ !(^ 4!&??8(!(dH#HxAB7)h`]1AuGei31ѠSq24dŰ|X$WbiY}V& A50<^_jP'\niNj0Ȉ2}|=ͭWlа`@ȵVSV` tUMQ8M0ɨ;!ɼBdư"oG4_gd l,THtNk(I&<^eFK_%+h ҝ^&+Ԥ Â&<)!wNzl\M˽$Pc'g}ÙM3%pzi x̤b,ٯK#dӧe-{G8=A]$a68(:"܄`s|*gES}t+q&T?N4oesx{Č +9h\e2]a*7ĢMR*MAQ-~pEט;v5pRD\;u$wR ]OOJ^wDN{\E.V#J픇.Zƚް +?x5%Cwܲ[}@?mϔ  M&g&ya .{K =i ~.~{3ssۄWܫ};Җ dwNwQ5Hbm0ZV<-x(X6lKl'ǾҌ̴Xw^a;{cu#Yʹ^ +I W cg|mueIa >>7[,=8q#&qGڧڜ>;m_j&]Ch SfB4 Gs.Z }#db:(A'% WШב~e7ڽcԪ,$9~Fa @s3Sh{*pʰd\Ux/&lP=R@X/汈s:6- L= ~z )lU+^pY^zY9iY$AnDd jT`NJ[uDSgS؄32*@<{=1t(f.OUt%K #2lW.Jl9"PDŤ)AH<"7Bdq !{2'MEUc9ujejN'<& XiQn%J]@~*U}2Hi)98U%=ʯOe^ˤ<&.`> M<*EQ ,BE]U ǣ80!e`.``Sd'K>p&7|FI78"dn6$f[[2ef$2f$xpp̻&,Gk%I<)HnraXT+㘋gtSgv>)m0`aҨaA\B-a=u!c *\w"XH] [߯;0`{/ PtT'a̬:# bU?{o%<8mz9ޱ-.:EEfңz.!Ƙo`J6&QogrтMbLco`D ׫*zI2smvlcДZ%1G|VRCf ޻SsQX/taEfxFq/,Y k j:& ӹ=&"rFAJ{ХU1.:\FT}гE󋡔/J*H,אQrk5 @y؆ҙ!.jl=ݩi%[q]^F#qQ;ٕ/u{ߗR{rG3ebȍRpmX|)Ε Zɏ, _ 1xkuU Z .k73?^c}f ZNE.jX@UkrMKK@0Z6Ri 6c$BORflM & Pn"9׬|kB]vX|߲n5/j=$7T E߇?~4 l hRӢVӽeL/:Tt'm'dZhk>s+\|3[ )̭oONƬÐc"x$[&TS+Oz|`ś|iX@;Iwss}['ru¯˭3NvǙȜ_ k2hli>DVO䖧oE,&R—,H8r~[nSl~p.$s g쯋8x&RzIZ<˱Y \^56MXD IkڋMMrRoNIVW|=,/A<o$wne̷L7d ucAARBW]r(.QUbK mG3t8/mw7o6. mݬ_ﳵn:n¨/pJ bqxl-ǐŷXXWƃ"_:v5҃aIyYšv~L{L!+Gizeаee `⿦xPī!d9SU:[3@^PoʾR0H%j% ?2`FxF=_+l:]$=Ƥ7B}3?%-d7iRX%+C0H8I/{l+ *.zX)ӘMLk|XCnL:е F*sgZa"- (k՗m[{:zH!!uW₅yۡ~oKa!3{ϠO-c\'TzCJC`EG[5[Om(if.sq&MfC qeB;P 0xS=q '4}lg()Y_\9. _].Ⱥճn T| YWj̵[xU NC,qe.2)GkR:sM%Ԏ 5_w1!2;_ECw1/Փxo:Q`y#fXQܛJʁIOI<[@R Vݼhs [T->9.;U ;鐹[~is%J+8*F/ǭNoȇOnzCi?& MfG5Z}!tNR^S6ţaGὮAɌQ8eLgN^`0%g?4}^{~kǸR?(̻EȞ&P^xgHp5}IϭХjG.eްj^k "#,9 v0'yL(`e JӟfẊ@{?gJʶ@>^Bώ\A 4֏6uwq$|,`yu 91`c/XЁq'S>=ۈyDl;P/yϒcG`е=pCcvH`Ȳ`9%w2oHw7DR/~5pcх#,b;R=b0І-w<4 ˻Sd\ n׊]\47!`D:(kt0׫J7n(b4Qpt7Rn_pLh>JrCOApsJQ,g ',~'8^hImWnvJD ࿠i~MzDDEAH&"buIދpE"1IKy)HE7! d2!7+7#K:ι1q/OuV$tQ?S"'^ {2'QSO .Dep,tҟ_z]ȍxUL <-(\EHvwKrK ;u_qg(ʼd47w Qirx}XoOKg! |aN\KB{1sԍjĚP}I͔ P /T3j _$Or Ʒ+!}r#ij;rQCɥ2,kz+da5evZJ,[ +q4j~B˽`iQiwcD:]Xm=PJLbHAc.Z4*K]$%Oiٝo(5MjzZޢb/W"4-n1?a_(:LW xذˋՠԐ-=Z;lR/fe%w~ WQ6y Qx.>E膋dn7wz,+ W5$DGX䱇_A#ħ?JK&Z,bRxu=#LPj!FgG|XLFv=bM[Zk;`GXk~+A! BI$Y1gN>2+ye9 x9Fq09+u׏i~@BqEWd!k%?fwQJ"uo9{ /ž?P;NrLn.X{ sxT {]LĘƥ쭫Qh$ȑ^D- u2%_ kc/pd9`UGc6[#.+ܛUsv\-.Ń"ބMQJKr5 ݗ/GƓJaC 4uEi9?`M>h=Q j⋒M['^ -NC v‰攪ƾCKN#~+ T M7 -`א1]TH};lQޮzP]VAFe83sZ(]_{{zx]D*jG9rVi=""mWJְ9jڼ õA ٩PTKn)m!?ЂSxg%^GAt&,׶[* gHd%~Tҭ*ysȨ b0 >xKpC])BӭĪ*>G,_!uGNzGm_"SߝSIΘ׊#<0)úu/N#| 2;:Lw]?!,21_x(KyT" c2(@<1E] d" N3i[~Vtc:xuPJ97צ#{ag .:s0Lݬ#Ȳі mӐʎLI1Ѱ3jsK|k>9-OOt{FioΧ;#|hN& ůc[Ѕg318:ҔMUO'!{Hw8Wy0bSWхk2p!9Dҋ=s1}ϐE딮9AuSh(q` }ʕH Cf%k*R~=r ! 'Zo)*2Vxo ڴ}L^xeeOIrjQSooqyuҩvuwɲਭ&plj7'"4$ fX+82Q B]vV~_77H ww[q7L iUT/͔P\/9 *%w`?LuDGhm徧;g W0;"D_|H>Gw:FBe`ZVzb#jWUexִs^Qu*22T9Z2g{ƥ7g"}s]$.FՊ0|(><=5Q|`+8yI&4m^V Z%'< k@[&be&UXuhTX9fe~P0:Y+C\ΞSWmJY@L/PS;lL~{ `NB$g\8D8-i4a8|lN{aO*df1WUv0=_v]SI8HTd5^s9lZi⑮{0~!FzE|z =>Pe)  aHx^03 m&^OQ?*H9<~+b﬷ֺ ; ޠ7'Pu{1ϔ-G7[L ¦|&X{Bz[. 8R1l.ԛ^Irgy7^wM0leFTD1|xn_Zb77d*mҹ!6 )nG[a4QN't uXۗMݫβJU)^X)įVcbԭ#3`2CMo*ʭO5 fGz{I~ 4$v{4ʬ^!ٳX|9:F -2rNFR%'8)d8#?KۛTU`x cfmNL!D6BFQ#{>~jVw)cu,̿Rv[J۞ڗRAr5΍K%54BV'xp,Ӓ*6k*$I0G{};9KRs Fazs xI &!A3s/e=C>{5qcIo's8"enMdx3c(W Q[_  ms^zI J 9jt=n7GN ~` fm˂a4Es{D;p\ MC(vE2QӐzX O_5FDeH$$P~-+G_ϸWmE&%u*ԵQJ5$ނWOn&AIٶɉ;l3^(^+#K}w 9k ej,c+v~-.}TyCMcS04 q埂᜘8OUf/H9IȈͅIHZ1׊Wz |D|QʛH )rɪWI S /uMz< c5%dNV+ֳ֖M"Hж#.sDFv0L9TIGwulRcRuU`Y^I G]|FYN~UVF^M1)U& M4 rFΠ`5ێNV9[7$P4&^V@#㦸n 6]r j)znBtZ8vtŊ3"&/ǃ(S*If Xl fqYAa.М;fvZLO\($Su7Q?m{\ @&ǓEE~(i_I^(ZOPqK1QE'l7!`%<\0^J%>Jxlי (u:VSeߣv&|I!Y%p*P+'HnMD#> ݛJc:=-p P=:4 nv!|e>^~mR ݮ2l`cwLaȨ!3־i{p M@DTm @dKR \u0\^}$_î0ZU^c=3sANu4rZU:?a3IQVOґVLmKl6bL२uL|lCN;/8s]*鸌K8T %^Țts"6O$G4Q1/`8 ]d$ up3$_\?_zݭeaŲlzpƉg!fYY! ojuȥt{` J4!X EJ< cfUulbVa:.K Q;n7|KtB~LZ\4{ک`-.̪ kRp˛;>PYV5ǒn^3祑|)_U>mN{Ȑ||=&{A9v^óڒ @`J.C1${JlQD'/hf'☿e_\5~`\+WMt]nyO]6{cDĬɋzF{1Ѿ #}*P"-gB97U2މ!n͆lw:Rq = {ev&ED+H1Yeܙ7<> vIk )Q\DZ{$rwB!VR6Ru'ݺv<={4 w-K,ka9 X@)iT@ u:{_B!Q֎uYKj=@X[8899_j3# vY.|6O +64Q2%Zm0 'F?hx`&.d.qaKGh'X6^LG{o8 z6z6^pcУt>رS|ltBDA&Y^ZmhMM)ec) M#Xk$1_z) u'$`^WAعdN}AОF䊣K0 nXWFC࿨wvy}G .GiC qK0E k@Hz[ S~O~1G)6w@%z-7roMЭVc͖nn%;F@KqaTX%ފ0Ǯx3VYM5#!g[TO`6V|k.Vv+iC^6 nj Չ:3s4(Mm1:*$ h֢ny=awi+J%HNbLYR 0! OxT<EmlQ)#щApyE,RyR>JD{<#1*Ř#RZs]sw)^ֲ@:|yK>ίeOɨ@'B>>i\RG1']\*YF/岑 T^ֵ}"ؘᚤgQg`զxOc,hO6`5c$ ' ˫NI9n1WE~ <5wlFԑ'݁{"w.pSfkXɤM&:25Ad4cBB˺Mn0B_(½2ۨѶ͂Z)Mj<`rBohCēlNx,R҆ ݾtAOU-R lETG}WK]W%ݰZ㐷ޙ`-6j֒2JƟ~[fs, B䛀 9 ON% poWˠsi1Dk߲I3d d` 2&j9{2'[:CmMDG5bK=UO7žK)@@|̕Bé 9pVHcYfb 21LQšf/6ZncHO|̣qBA4 61N\S # {aʴ+Teå&y\$-ވZ=1{.{>, ~{?E?{c=}Jeީ}$ KTu|F NwEwLr~{?YxL>Z939D*=Sh< 5?a5,lx~4@].%=vS s ' >3@#"6Xc4KCxP8}%r"l=ˆ]8L@"Va)6W)Ia1jߠFe{2wľ]![#c.cNu[9Gv+V7, Le?G5W:"'3&koW'9IY ^p;Nb3E\30CW]hn.o? *&Kϕ>Xz;00r F*XuΚJYvC8rubt&A/p.9Trl7tXuQ$ 3dF!;k?ìweoWQ ry6&McUJNfEJ'PHyY(Jy[uvgz^){ɆۡMD9 *!]k*9I Sˊ\eiP{1==XZ]/WH09KK6*7-3ǫ燑跳dIO3s^##qM a}؊aK 3K\'$Tªu@^JX%,3MuTx8e|Twij(o$+I zf&Gfuu;)n,."Wm(>d8DDT/0?Z ƫR|dR!>A)I~*e>qjG'z]fk~FաOcm\J遱2jӥI`SR/;\{䗍گT>XaфzM'- Zc8G5~_3d>W,.Ώ D ޠ `RTw|:$/|rpӀQނN7'1S5ܐp6x^U5E@~͆߫ sBtL!"eؤi,eZ3T3C\-$R u ,K%A"jD'PZCP(!/{M<2AĤ}{rXɑTLPԀy "^ʓW]&d9ƭ(wVpK=ARʕ UdbEGg T $Boj$Rq?Zɾ~31ax=[g1P6q49P4,"Rj\b :" bE IrQ(:,{O`z ecWX-p[3ݯ8 aogى1j zLq\S% _{nY;2$҅_6RԢ1\0rP Wp2xX@ݪ9az.E(f„QdВ [{%ؿj }"nm.ϋ_5քz :m 9&PlQGY3#F[0G3#FALL \Ryx\[u.gxŐPC~O}I, 0/痦K;W?!YO;㫍jKrsӀ계i& ~;T궈޾$a,L哦T}.XhTOLƋ2KBti@3A,7yxÜ5e:53J"eÕyJ8ILa6Re4Q,(h ?\<˴֭ڙHnO G&I!A f@gcMPPbv%YBS^ 3ꝊO>@J! O"]"3::XR1- ZiH#-vzj$(-ǰ\~f&W ^kvwti2cng5Y|<賟s_~2:_L?_hlj8svVku2Ke촥ԓ *T"R}z@;A֍Dv+R+&bt=FeGlUIӱ45SDt~i$GKHd0 .n%BKD*0/]!̌J'y|Q/ E`9'l (w{IwZ_malp f~Uo[!dR63 @-o;B]7^3A@"zv<.F4?0Qt1=kDBлh9۵1 F(o-0]+l?^R ;2ۂͨ`s-QDA<F}T?{C5Zp L =eMM ! E K3t[e;Uwq#jtv:/kP9C\ EU~[.%xQ+XII29"5Ҙ=ګЄ|}DlΣd[$g8HRSB)5V3}IޮJ  ka:ը,nJq&2噖Ԋ+FWaAQOj I_pǷdϥ?#c `}eu;lJFkTczr\fQ=d,CxD5}rFyQԨ2_4.JQ0숓MhSw<:< WSj,h!6yaX(3צAV) gSuaJYN%@P,7ݼ%EQu8K5M]SPB XҊSjJKe{F~*u%wc o }J-8o2qrJn\gR!dٕ5"^ؕPK!pzܑ|6g[a$tڗ |̦Y6nAῑo,C6UM^P`~4\M#|HG\k[^Uq!`~2~!6 U%~}J5 pT]*R,Y%/] ۀj{=ob0Kg5 Js#XN>r)i74rI]IUøe]0> BxAT=saA[դojF__1;z=@!!]Mi'޻RĜn <  DacxE)J2C CYǒ`nI3nҲ]; chǴ8`ڇ/Tl [RjEΕVʷyq ~)mCeX:ck n;S_.5]^яUF?CX(%Af8Rn%%6: }0EIl4;HhbΛK@`EvLykiڈir<;Jl[R޼%FE}Y~+;n:~VW54`s71t )*SH}ӍFU&\]X9y{%Zc0"bCS{-`!$iܾ<&kNJn|Nn:mu6D: m&G1~c#Vt]_c5 q;X'@k33y۽|u{AAf 4ݱx-.>݊d#,pBЁ!7$.߈* . "mpT-#(\ĩ q!O$K#d+BUWkczM2;((K QGųM2Pƶ_ʝX/fLףC3 ! j5i*`x^Sb7DB{L l:sFrƣ.bﴓ'!1YjrkCuJ'|k_GBJ]R)1 sJ7"{)4*4pFa$DA98E&Z_<;_m%"D0.Qgy)=r̙eAm!%v dHJTT&RL3R~)ѡ#"%MRY+%$E)"U`)G| BD$#o8oq:[x8GHWS2Ԝx3SCZ7_t䎐A_ɹFxQ%,]C̊\ƏE\$XS.T3Ia>03pӉDI="gd8 y8YFۛONCVr&321ʷ`SE?2sէ(h%cI72%lFt@qTg"J¸4›6C/#xёQ,j 3{Gd~'U?F*U􍙖 ޠFbˈ.\^@\?ndzp7[a%̖1Bpu0 )R ٜW%PVi/ (V`&;ln ' (B6k|Rh[ +ʂ/|2ܨ\FjVƑ<;5G$>o">dlȰ-K^Jϡ~1S,A',ITpc"7<ꈻKD!K855#e0T50kHq"K1NmLҙ|RW|&b=IQU2"^&`){OFQOp8(N5Vػ?6Ay,]raȈq O,iR}kF6{4"hɨ&[q+0J:#:iLΠ|-ش6H{d.%CGbDx-PY٤'d䔊3\. 3 gCQ֮$ 8)VUbǧߘp-$a/%p}]\1s% 5sr@B{YGwa3PJ(OQ}*w3_UPu-U}if׏;WHv4m{Q·_ VD'`!,[ o?: B(cEقݽGW7YI,C L X$-tTV}0vX\FN?SSf-QCč+WN{Eu")ҡio8rP*&r^K7D)eR~t{_ؤ!@,p/2u%=<PErL q{vcV_ "AݍҞ{P Iy7zϬmkD_l˿o]zbf/$(Aw1L$7N%QR m<۵h?/7ᭊjI2MAӶN1s~P~s`K 6dY$4BzxwQgM^8;#E膡ȏvtw#fi3]S2 MmX}f؛G=4A;%Zb"vr/V# Ä? z/vV_hh d#+X^jL'TD^7}ArIy6n6ez5*q#{cKkDeۆ4}6ME2+urdtk.~ :1IMb#RpuhD'uM1MGah*xD*V&gEG9TَhvB10(DRἁ$Æ JKGiE*sn&i!CT  /!Sjb7&k.@gcw^L/b7LEz|D.UM!8BZٙr~A3I\U\\0hW_uz !MVdk3y<>">&Br֒,hN>m "M*imČ(̦#lYL(6F{TL ĴφU&bAL LQy&B<{%7^=DMlns;ȤK O w,_.ޖŃLW7Z>7p'-/ULg0Ϭl[-PksaBx$WzlgNAvqb1i<ܚdG7=U6b?E+j0Xp Z,+s4њ)VՌƟZRvRd>!>S_xY%nQiF`a6^ϑD^|w$2Y'/4Yf)6Q #l GK(J'"0aAruCv3 .Ri::Kr J_eF- 6y_(1md>K4dp=/t`Ut((BFR ?6ܟQn!? AJʉVl~ck!?!׬!hI޼ v6L\mw9n0?B|G;8a5'k&$7$?34AIWEb8 *j~'J`r3tq: }Whn^%*/Nr=_*9@$ɸB:a~ V(`R|s7Cw)<idd/֯w{ǔ Xw n N.?W3P2qto.kƼ ~Ynȑu[´҄5a8$e"͊Qؾ1 -{6sKqܜ¹c(CT^7bѭ6sFH=TF#9s-سt"_el?2p'zB+ëAhuxtNE[z-6_Xܞ&Uđx%SXuR:=- X(1c$pl6f*V6B̓o}(il%UTb-#ª9ED.TyFpoG|tA2#ڟ׊cj2Hɇ=]+ck~_]Pg< g?I(xiLJ= l !ljLlTʻGpcpWFX}tJFOfEtd?LR̖W 7naںѫͳ`iOKh NtGNU uP|A\54fN5OfQa9WST٦>{/wPbq} ag7#C k 7-FH\(\ Lh`&n(ܫf$ '4 yVBgZO: >#^>-$13<1y,@'AcYuBIV)x&Fa>_Z2FVF&YEAF;/ld\t_ ܧ%m9 JE9.kyI >3Z%aQQ:W)TV٤mN25Y5)tϢH&aR%פDځ>0ޞ2!AU-֋Wi+_GE%IЗzԳJ𷥏SdztTxv#|!CAH]ùhϣsؚLje8e* -=Vm ?ng0ަMrcV6? [Tqi '9: AbYiarm/qy5] u=z+~4 ёLGdØpJG`^㸥'L@/'o^R~56uY@#V1W1R"\vyf?|osł3=N]|Ř_zvwbs&2d IUbd*?iWVzhgNI'rt@h~edIc$TtYA,_TcvPKfeɴP47pz@6tD   B#մЧj$W5ϥ-t 3iXKN,X#+hb ^2Lfh,dRI 6 ~nW?L7^X7L~}UoAHi}Й<}h\V\\ +fs +-mvN ]N篶|s̀Hٖ jm}rw*YoDŽayH)[hqE-p1a+Ζ'rhE+_> #'[E)М[ᚓ2|G9-iT) /,u+p_"Z:!ء" ۍYg¥ATDv'_c1.If^c8rO[]K8utZɌI̗H6EMkƍfD|ogmtS35U'Ar.\z{Vȅ ]Y YZ