libapparmor1-3.0.4-150400.5.3.1 >  A cIp9|Cr?<6),wʧQ2PMMɞN%|ukv]ЌRZ\vI*0: Pl;J9N u)8TfR%y8aT" #^<K^+opQ FˁA1: ]'*}G^rs?W,1T9/MnѮG٨dP{ h2ΔBdcac1a2369f0a65bcb63841d69e291155433c58e5e5868ac56503f646ed477608f4ae356c56da50150bf728eff4964e47ac01782,cIp9|u ㉿51⢾)7VsuA/^k֒мI+l37YJp.C3;"RH0ku[HlAVLCFsG[lYruV%px0EE]l`8ǝEVdJ? g\~?ܿd+Uv.'vⳝ[Ԓ6p4\deFv;ړ>!yViC66Nd>pC?xd " ? )J\ r       (2<dl4 h  (8|9|:|>@BFGHIXY<Zt[x\|]^bc_defluv wxyz(,2tClibapparmor13.0.4150400.5.3.1Utility library for AppArmorThis package provides the libapparmor library, which contains the change_hat(2) symbol, used for sub-process confinement by AppArmor, as well as functions to parse AppArmor log messages.cëibs-arm-58SUSE Linux Enterprise 15SUSE LLC LGPL-2.1-or-laterhttps://www.suse.com/System/Librarieshttps://launchpad.net/apparmorlinuxaarch648cÕc×6bf7432b78d90c7ba4a3cea9a00792cb45d9ac06d1bcf50bbe16d9b96f798ccelibapparmor.so.1.8.2rootrootrootrootlibapparmor-3.0.4-150400.5.3.1.src.rpmlibapparmorlibapparmor.so.1()(64bit)libapparmor.so.1(APPARMOR_1.0)(64bit)libapparmor.so.1(APPARMOR_1.1)(64bit)libapparmor.so.1(APPARMOR_2.10)(64bit)libapparmor.so.1(APPARMOR_2.11)(64bit)libapparmor.so.1(APPARMOR_2.13)(64bit)libapparmor.so.1(APPARMOR_2.13.1)(64bit)libapparmor.so.1(APPARMOR_2.9)(64bit)libapparmor.so.1(APPARMOR_3.0)(64bit)libapparmor.so.1(IMMUNIX_1.0)(64bit)libapparmor.so.1(PRIVATE)(64bit)libapparmor1libapparmor1(aarch-64)@@@@@@@    /sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.26)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3cbk@bi0@bZbV@bT@bRbBb<]@b@a7aZ@ap@aabaim@aEaaua $@`#@` @````_@`%@`!'`>` @__ǁ_ǁ_Q_h__@_~@_[f_P_-B@_@^m@^@^<@^j$@^,-]҇]o](]K@]]@\\@\ \\v{\I\ include in apache extra profile optional to avoid problems with empty profile directory (boo#1178527)- prepare usrmerge (boo#1029961) * use %_pamdir- update to AppArmor 3.0.1 - minor additions to profiles and abstractions - some bugfixes in libapparmor, apparmor_parser and the aa-* utils - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0.1 for the detailed upstream changelog - removed upstream(ed) patches: - changes-since-3.0.0.diff - extra-profiles-fix-Pux.diff - utils-fix-hotkey-conflict.diff- Use apache provided variables for the module_directry: + Use %apache_libexecdir + Add apache-rpm-macros BuildRequires- add utils-fix-hotkey-conflict.diff to fix a hotkey conflict in de, id and sv translations (and fix the test) (MR 675) - add extra-profiles-fix-Pux.diff to fix an inactive profile - prevents a crash in aa-logprof and aa-genprof when creating a new profile (MR 676)- update to AppArmor 3.0.0 - introduce feature abi declaration in profiles to enable use of new rule types (for openSUSE: dbus and unix rules) - support xattr attachment conditionals - experimental support for kill and unconfined profile modes - rewritten aa-status (in C), including support for new profile modes - rewritten aa-notify (in python), finally dropping the perl requirement at runtime - new tool aa-features-abi for extracting feature abis from the kernel - update profiles to have profile names and to use 3.0 feature abi - introduce @{etc_ro} and @{etc_rw} profile variables - new profile for php-fpm - several updates to profiles and abstractions (including boo#1166007) - fully support 'include if exists' in the aa-* tools - rewrite handling of alias, include, link and variable rules in the aa-* tools - rewrite and simplify log handling in the aa-logprof and aa-genprof - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0 for the detailed upstream changelog - patches: - add changes-since-3.0.0.diff with upstream fixes since the 3.0.0 release up to 3e18c0785abc03ee42a022a67a27a085516a7921 - drop upstreamed usr-etc-abstractions-base-nameservice.diff - drop 2.13-only libapparmor-so-number.diff - refresh apparmor-enable-profile-cache.diff - partially upstreamed - update apparmor-samba-include-permissions-for-shares.diff and apparmor-lessopen-profile.patch - switch to "include if exists" - apparmor-lessopen-profile.patch: add abi rule to lessopen profile - refresh apparmor-lessopen-nfs-workaround.diff - move away very loose apache profile that doesn't even match the apache2 binary path in openSUSE to avoid confusion (boo#872984) - move rewritten aa-status from utils to parser subpackage - add aa-features-abi to parser subpackage - replace perl and libnotify-tools requires with requiring python3-notify2 and python3-psutil (needed by the rewritten aa-notify) - drop ancient cleanup for /etc/init.d/subdomain from parser %pre - drop (never enabled) conditionals to build with python2 and to build the python-apparmor subpackage (upstream dropped python2 support) - drop setting PYTHON and PYTHON_VERSIONS env variable, no longer needed - set PYFLAKES path for utils check - add precompiled_cache build conditional to allow faster local builds without using kvm - remove duplicated BuildRequires: swig- update to AppArmor 2.13.5 - add missing permissions to several profiles and abstractions - bugfixes in parser and tools - fix two potential build failures in libapparmor - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5 for the detailed upstream changelog - remove upstream(ed) patches - changes-since-2.13.4.diff - abstractions-X-xauth-mr582.diff - sevdb-caps-mr589.diff - libvirt-leaseshelper.patch - cap_checkpoint_restore.diff - add libapparmor-so-number.diff to fix libapparmor so version (!658)- add CAP_CHECKPOINT_RESTORE to severity.db (MR 656, cap_checkpoint_restore.diff)- %service_del_postun_without_restart only works for Tumbleweed, keep using DISABLE_RESTART_ON_UPDATE for Leap 15.x- Make use of %service_del_postun_without_restart And stop using DISABLE_RESTART_ON_UPDATE as this interface is obsolete.- libvirt-leaseshelper.patch: add /usr/libexec as a path to the libvirt leaseshelper script (jsc#SLE-14253)- sevdb-caps-mr589.diff: add new capabilities CAP_BPF and CAP_PERFMON to severity.db (lp#1890547)- add abstractions-X-xauth-mr582.diff to allow reading the xauth file from its new sddm location (boo#1174290, boo#1174293)- add changes-since-2.13.4.diff with upstream changes and fixes since 2.13.4 up to 5f61bd4c: - add several abstractions related to xdg-open: dbus-network-manager-strict, exo-open, gio-open, gvfs-open, kde-open5, xdg-open - introduce @{run} variable - update dnsmasq and winbindd profile - update mdns, mesa and nameservice abstraction - some bugfixes in the aa-* tools, including a remote bugfix in the YaST AppArmor module (boo#1171315) - drop upstream(ed) patches (now part of changes-since-2.13.4.diff): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-fix-utils-network-test.diff - make-4.3-network.diff - abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch - apply usr-etc-abstractions-base-nameservice.diff only for Tumbleweed, but not for Leap 15.x where it's not needed - refresh usr-etc-abstractions-base-nameservice.diff- Add abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch (bsc#1168306)- fix build with make 4.3 by backporting some commits from upstream master (boo#1167953): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-network.diff - make-4.3-fix-utils-network-test.diff- update to AppArmor 2.13.4 - several abstraction updates (including boo#1153162) - disallow writing to fontconfig cache in abstractions/fonts - some bugfixes in the aa-* tools - fix log parsing for logs with an embedded newline - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4 for the detailed upstream changelog - drop upstreamed patches: - abstractions-ssl-certbot-paths.diff - apparmor-krb5-conf-d.diff - libapparmor-python3.8.diff - usr-etc-abstractions-authentification.diff - refresh usr-etc-abstractions-base-nameservice.diff- add usr-etc-abstractions-base-nameservice.diff to adjust abstractions/base and nameservice for /usr/etc/ (boo#1161756)- Properly pull in full python3 interpreter- add libapparmor-python3.8.diff to fix building the libapparmor python bindings (deb#943657)- add usr-etc-abstractions-authentification.diff to allow reading /usr/etc/pam.d/* and some other authentification-related files (boo#1153162)- add abstractions-ssl-certbot-paths.diff - add certbot paths to abstractions/ssl_certs and abstractions/ssl_keys- add apparmor-krb5-conf-d.diff for kerberos client- update to 2.13.3 - profile updates for dnsmasq, dovecot, identd, syslog-ng - new "lsb_release" profile (only used when using "Px -> lsb_release") - fix buggy syntax in tunables/share - several abstraction updates - parser: fix "Px -> foo-bar" (the "-" was rejected before) - several bugfixes in aa-genprof and aa-logprof - some fixes in cache handling - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3 for the detailed upstream changelog - drop upstream(ed) patches: - apparmor-nameservice-resolv-conf-link.patch - profile_filename_cornercase.diff - dnsmasq-libvirtd.diff - dnsmasq-revert-alternation.diff - usrmerge-fixes.diff - libapparmor-swig-4.diff - re-number remaining patches- add upstream libapparmor-swig-4.diff: fix libapparmor tests with swig 4.0 (boo#1135751)- Disable LTO (boo#1133091).- update lessopen.sh profile for usrMerge (bash and tar) (boo#1132350)- add usrmerge-fixes.diff: fix test failures when /bin/sh is handled by update-alternatives (boo#1127877)- add dnsmasq-revert-alternation.diff: revert path alternation in dnsmasq profile and re-add peer=/usr/sbin/libvirtd rules to avoid breaking libvirtd (boo#1127073)- add dnsmasq-libvirtd.diff: allow peer=libvirtd in the dnsmasq profile to match the newly added libvirtd profile name (boo#1118952#c3)- Use %license instead of %doc [bsc#1082318]- add apparmor-lessopen-nfs-workaround.diff: allow network access in lessopen.sh for reading files on NFS (workaround for boo#1119937 / lp#1784499)- add profile_filename_cornercase.diff: drop check that lets aa-logprof error out in a corner-case (log event for a non-existing profile while a profile file with the default filename for that non-existing profile exists) (boo#1120472)- netconfig: write resolv.conf to /run with link to /etc (fate#325872, boo#1097370) [patch apparmor-nameservice-resolv-conf-link.patch]- update to AppArmor 2.13.2 - add profile names to most profiles - update dnsmasq profile (pid file and logfile path) (boo#1111342) - add vulkan abstraction - add letsencrypt certificate path to abstractions/ssl_* - ignore *.orig and *.rej files when loading profiles - fix aa-complain etc. to handle named profiles - several bugfixes and small profile improvements - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.2 for the detailed upstream changelog - remove upstreamed fix-syntax-error-in-rc.apparmor.functions.patch- update to 2.13.1 - add qt5 and qt5-compose-cache-write abstractions - add @{uid} and @{uids} kernel var placeholders - several profile and abstraction updates - ignore "abi" rules in parser and tools (instead of erroring out) - utils: fix overwriting of child profile flags if they differ from the main profile - several bugfixes (including boo#1100779) - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.1 for the detailed upstream changelog - remove upstream(ed) patches: - aa-teardown-path.diff - fix-apparmor-systemd-perms.diff - logprof-skip-cache-d.diff - fix-samba-profiles.patch - make-pyflakes-happy.diff - dnsmasq-Add-permission-to-open-log-files.patch - refresh apparmor-samba-include-permissions-for-shares.diff - add fix-syntax-error-in-rc.apparmor.functions.patch- update rpmlintrc: - whitelist .features file which is part of the pre-compiled cache - comment out filters for the disabled tomcat_apparmor subpackage- Backport dnsmasq fix: 025c7dc6 - dnsmasq-Add-permission-to-open-log-files.patch (boo#1111342)- add make-pyflakes-happy.diff to fix an unused variable (SR 629206)- add fix-samba-profiles.patch - smbd loads new shared libraries. Allow winbindd to access new kerberos credential cache location (boo#1092099)- exclude the /etc/apparmor.d/cache.d/ directory from aa-logprof parsing (logprof-skip-cache-d.diff)- add fix-apparmor-systemd-perms.diff - fix permissions of /lib/apparmor/apparmor.systemd (boo#1090545)- create and package precompiled cache (/usr/share/apparmor/cache, read-only) (boo#1069906, boo#1074429) - change (writeable) cache directory to /var/cache/apparmor/ - with the new btrfs layout, the only reason for using /var/lib/apparmor/cache/ (which was "it's part of the / subvolume") is gone, and /var/cache makes more sense for the cache - adjust parser.conf (via apparmor-enable-profile-cache.diff) to use both cache locations - clear cache also in %post of abstractions package- update to AppArmor 2.13 - add support for multiple cache directories and cache overlays (boo#1069906, boo#1074429) - add support for conditional includes in policy - remove group restrictions from aa-notify (boo#1058787) - aa-complain etc.: set flags for profiles represented by a glob - aa-status: split profile from exec name - several profile and abstraction updates - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13 for the detailed upstream changelog - drop upstreamed patches and files: - aa-teardown - apparmor.service - apparmor.systemd - 32-bit-no-uid.diff - disable-cache-on-ro-fs.diff - dovecot-stats.diff - parser-write-cache-warn-only.diff - set-flags-for-profiles-represented-by-glob.patch - fix-regression-in-set-flags.patch - drop spec code that handled installing aa-teardown, apparmor.service and apparmor.systemd (now part of upstream Makefile) - simplify "make -C profiles parser-check" call (upstream Makefile bug that required to call "cd" was fixed) - add aa-teardown-path.diff - install aa-teardown in /usr/sbin/ - move 'exec' symlink to parser package (belongs to aa-exec)- Set flags for profiles represented by glob (bsc#1086154) set-flags-for-profiles-represented-by-glob.patch fix-regression-in-set-flags.patch- add dovecot-stats.diff: - add dovecot/stats profile and allow dovecot to run it (boo#1088161) - allow dovecot/auth to write /run/dovecot/old-stats-user (part of boo#1087753) - update 32-bit-no-uid.diff with upstream fix- Change of path of rpm in lessopen.sh (boo#1082956)- add disable-cache-on-ro-fs.diff - disable write cache if filesystem is read-only and don't bail out (bsc#1069906, bsc#1074429)- add parser-write-cache-warn-only.diff to make cache write failures a warning instead of an error (boo#1069906, boo#1074429) - reduce dependeny on libnotify-tools (used by aa-notify -p) to "Suggests" to avoid pulling in several Gnome packages on servers (boo#1067477)- update to AppArmor 2.12 - add support for 'owner' rules in aa-logprof and aa-genprof - add support for includes with absolute path in aa-logprof etc. (lp#1733700) - update aa-decode to also decode PROCTITLE (lp#1736841) - several profile and abstraction updates, including boo#1069470 - preserve errno across aa_*_unref() functions - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.12 for the detailed upstream changelog - drop upstreamed patches: - read_inactive_profile-exactly-once.patch - utils-fix-sorted-save_profiles-regression.diff - lessopen profile: change all 'rix' rules to 'mrix' - add 32-bit-no-uid.diff to fix handling of log events without ouid on 32 bit systems - no longer package static libapparmor.a- update to AppArmor 2.11.95 aka 2.12 beta1 - add JSON interface to aa-logprof and aa-genprof (used by YaST) - drop old YaST interface code - update audio, base and nameservice abstractions - allow @{pid} to match 7-digit pids - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_95 for the detailed upstream changelog - drop upstreamed patches - apparmor-yast-cleanup.patch - apparmor-json-support.patch - nameservice-libtirpc.diff - drop obsolete perl modules (YaST no longer needs them) - drop patches that were only needed by the obsolete perl modules: - apparmor-utils-string-split - apparmor-abstractions-no-multiline.diff - drop profiles-sockets-temporary-fix.patch - obsoleted by a fix in apparmor_parser - refresh utils-fix-sorted-save_profiles-regression.diff - add aa-teardown (new script to unload all profiles) - make ExecStop in apparmor.service a no-op (workaround for a systemd restriction, see boo#996520 and boo#853019 for details) - lessopen profile: allow capability dac_read_search and dac_override, allow groff to execute several helpers (boo#1065388)- read_inactive_profile-exactly-once.patch (bsc#1069346) Perform reading of inactive profiles exactly once.- update to AppArmor 2.11.1 - add permissions to several profiles and abstractions (including lp#1650827 and boo#1057900) - several fixes in the aa-* tools (including lp#1689667, lp#1628286, lp#1661766 and boo#1062667) - fix downgrading/converting of 'unix' rules (will be supported in kernel 4.15) to 'network unix' rules in apparmor_parser (boo#1061195) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_1 for upstream changelog - remove upstream(ed) patches - upstream-changes-r3616..3628.diff - upstream-changes-r3629..3648.diff - parser-tests-dbus-duplicated-conditionals.diff - apparmor-fix-podsyntax.patch - sshd-profile-drop-local-include-r3615.diff - refresh apparmor-yast-cleanup.patch - add utils-fix-sorted-save_profiles-regression.diff to fix a regression in displaying the "changed profiles" list in aa-logprof- add nameservice-libtirpc.diff to fix NIS/YP logins (boo#1062244)- profiles-sockets-temporary-fix.patch to cater to nameservices with the new sockets mediation, until unix rules are upstreamed (boo#1061195)- add apparmor-fix-podsyntax.patch from mailing list to fix compilation with perl 5.26- do not require exact X.Y version of "python3" - require also matching python(abi) which is arguably more important- don't rely on implementation details for reload in %post- add JSON support. Required for FATE#323380. (apparmor-yast-cleanup.patch, apparmor-json-support.patch)- add upstream-changes-r3629..3648.diff: - preserve unknown profiles when reloading apparmor.service (CVE-2017-6507, lp#1668892, boo#1029696) - add aa-remove-unknown utility to unload unknown profiles (lp#1668892) - update nvidia abstraction for newer nvidia drivers - don't enforce ordering of dbus rule attributes in utils (lp#1628286) - add --parser, --base and --Include option to aa-easyprof to allow non-standard paths (useful for tests) (lp#1521031) - move initialization code in apparmor.aa to init_aa(). This allows to run all utils tests even if /etc/apparmor.d/ or /sbin/apparmor_parser don't exist. - several improvements in the utils tests - drop upstreamed python3-drop-re-locale.patch - no longer delete/skip some of the utils tests (to allow this, add parser-tests-dbus-duplicated-conditionals.diff) - add var.mount dependeny to apparmor.service (boo#1016259#c34)- Cleanup spec file: - don't use insserv if we afterwards call systemd, this can have bad side effects - remove dead code - remove now obsolete 'distro' checks - Replace init.d script with new wrapper working with systemd- add python3-drop-re-locale.patch: remove deprecated re.LOCALE flag in Python UI as it was dropped from Python 3.6 (lp#1661766)- Fix RPM groups- add upstream-changes-r3616..3628.diff: - update abstractions/base, abstractions/apache2-common and dovecot profiles - merge ask_the_questions() of aa-logprof and aa-mergeprof - pass LDFLAGS when building parser, libapparmor perl bindings and pam_apparmor - adjust deleting the cache in profiles %post to the new cache location - silence errors when deleting the cache (boo#976914)- split libapparmor into separate spec to get rid of build loop involving mariadb, systemd, apparmor, libapr and mariadb again (see the discussion in SR 448871 for details) - libapparmor.spec is based on the AppArmor 2.11 apparmor.spec, but with minimum BuildRequires- update to AppArmor 2.11.0 - apparmor_parser now supports parallel compiles and loads - add full support for dbus, ptrace and signal rules and events to the utils - full rewrite of the file rule handling in the utils - lots of improvements and fixes - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11 for the detailed changelog - patches: - add sshd-profile-drop-local-include-r3615.diff to fix 'make check' - drop aa-unconfined-fix-netstat-call-2.10r3380.diff, no longer needed - refresh apparmor-abstractions-no-multiline.diff - refresh apparmor-samba-include-permissions-for-shares.diff - spec changes: - aa-unconfined switched to using ss (from iproute2), adjust Recommends: - move libapparmor to /usr/lib*/ - drop %if %suse_version checks for 12.x - change several Obsoletes from %version to < 2.9. Those package names weren't used since years, and 2.9 is still a careful choice - include apparmor.service independent of %suse_version - techdoc.pdf is now shipped in upstream tarball to reduce BuildRequires - drop latex2html, texlive-* and w3m BuildRequires - techdoc.txt and techdoc.html not included, drop them from the package - run most of utils/ make check (some tests expect /etc/apparmor.d/ and /sbin/apparmor_parser to exist, skip them) - BuildRequires python3-pyflakes (utils tests) and dejagnu (libapparmor tests) - drop sed'ing python3 into aa-* shebang (upstreamed) - build binutils - aa-exec is now written in C and lives in /usr/bin/, move it to the apparmor_parser package and create a compability symlink in /usr/sbin/ - aa-exec manpage moved to section 1 - aa-enabled is a small new tool to find out if AppArmor is enabled - package new aa_stack_profile(2) manpage- change /etc/apparmor.d/cache symlink to /var/lib/apparmor/cache/. This is part of the root partition (at least with default partitioning) and should be available earlier than /var/cache/apparmor/ (boo#1015249, boo#980081, bsc#1016259) - add dependency on var-lib.mount to apparmor.service as safety net- update to AppArmor 2.10.2 maintenance release - lots of bugfixes and profile updates (including boo#1000201, boo#1009964, boo#1014463) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_2 for details - add aa-unconfined-fix-netstat-call-2.10r3380.diff to fix a regression in aa-unconfined - drop upstream(ed) patches: - changes-since-2.10.1--r3326..3346.diff - changes-since-2.10.1--r3347..3353.diff - libapparmor-fix-import-path.diff (upstream fix is slightly different) - nscd-var-lib.diff - refresh apparmor-abstractions-no-multiline.diff- add nscd-var-lib.diff to allow /var/lib/nscd/ in the nscd profile and abstractions/nameservice (path changed in latest nscd in Tumbleweed)- add changes-since-2.10.1--r3347..3353.diff with upstream changes and fixes in the 2.10 branch, including - allow writing *.qf files (for disk-based buffering) in syslog-ng profile - add several permissions to the dovecot profiles (deb#835826) - add a missing path in the traceroute profile- add changes-since-2.10.1--r3326..3346.diff with upstream changes and fixes since the 2.10.1 release, including - allow dac_override in winbindd profile (boo#990006#c5) - allow mr for /usr/lib*/ldb/*.so in samba abstractions (needed since Samba 4.4.x, boo#990006) - abstractions/nameservice: also support ConnMan-managed resolv.conf - let aa-genprof ask about profiles in extra dir (again) - fix aa-logprof "add hat" endless loop (lp#1538306) - honor 'chown' file events in logparser.py - ignore log file events with a request mask of 'send' or 'receive' because they are actually network events (lp#1577051, lp#1582374) - accept hostname with dots when parsing logs (lp#1453300 comments #1 and #2) - fix python LibAppArmor import failures with swig > 3.0.8 (boo#987607) (libapparmor-fix-import-path.diff) - refresh apparmor-abstractions-no-multiline.diff - drop upstreamed profiles-ping-inet6-r3449.diff - add %check section - runs libapparmor (including swig bindings), parser and profiles tests - add BuildRequires: perl(Locale::gettext) - needed for parser tests- add profiles-ping-inet6-r3449.diff - latest ping also does IPv6 (boo#980596)- update to AppArmor 2.10.1 (2.10 branch r3326): - fix incorrect output of child profile names (apparmor_parser -N) which caused 'rcapparmor reload' to remove child profiles and hats (lp#1551950) - fix a crash in aa-logprof / logparser.py for change_hat log events (lp#1523297) and log events that look like file events, but aren't (lp#1540562, lp#1525119, lp#1466812) - write unix rules when saving a profile (lp#1522938, boo#954104#c3) - several fixes for variable handling in aa-logprof - map c (create) log events to w instead of a - add python to the "no Px rule" list in logprof.conf - let aa-logprof check for duplicate profiles - let aa-status work without the apparmor.fail python module (boo#971917, lp#1480492) - add permissions in several profiles (including boo#948584, boo#948753, boo#954959, boo#954958, boo#971790, boo#964971, boo#921098, boo#923201 and boo#921098#c15). - and many more fixes, see the full changelog at http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_1 - drop upstream(ed) patches: - fix-initscript-aa_log_end_msg.diff - syslog-ng-profile-boo948584.diff - upstream-profile-updates-r3205-3241.diff - refresh patches: - apparmor-abstractions-no-multiline.diff - apparmor-samba-include-permissions-for-shares.diff - drop libapparmor autogen.sh call (broke the build) and remove libtool BR- add syslog-ng-profile-boo948584.diff - add several permissions needed by latest syslog-ng (boo#948584, boo#948753) - add upstream-profile-updates-r3205-3241.diff with several profile updates: - add /usr/share/locale-bundle/** to abstractions/base - allow dnsmask to use /bin/sh (boo#940749) and /bin/dash - allow dovecot imap to read /run/dovecot/mounts - allow avahi-daemon to write to /run/systemd/notify - allow ntpd to read $PATH directory listings (boo#945592, boo#948752) - update dhclient profile - allow skype to read @{PROC}/@{pid}/net/dev (boo#939568) - and some other small updates - drop upstreamed apparmor-winbindd-r3213.diff (included in the upstream-profile-updates patch)- netstat moved to net-tools-deprecated in Tumbleweed (boo#944904)- add apparmor-winbindd-r3213.diff - add missing k permissions for /etc/samba/smbd.tmp/msg/* in winbindd profile (boo#921098 #c15..19)- add fix-initscript-aa_log_end_msg.diff - fixes ugly initscript output (boo#862170)- update to AppArmor 2.10 (trunk r3205) - profile names can now contain variables - improved profile compile time in apparmor_parser - lots of improvements, refactoring and bugfixes in the aa-* tools - new apis for managing and loading profile caches into the kernel in libapparmor - lots of profile updates - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10 for the complete changelog with more details - add new apparmor_private.h and the aa_query_label(2), aa_features(3), aa_kernel_interface(3), aa_policy_cache(3), aa_splitcon(3) manpages to libapparmor-devel - drop apparmor-2.5.1-edirectory-profile patch - it's most probably no longer needed (see boo#621394 for details) - drop upstreamed samba-4.2-profiles.diff - refresh apparmor-samba-include-permissions-for-shares.diff- systemd-rpm-macros and %systemd_requires were at the wrong place, move them to the parser package (boo#931792)- update to AppArmor 2.9.2 (2.9 branch r2911) - lots of bugfixes in the parser and the aa-* tools (including boo#918787) - update dovecot and dnsmasq profiles and several abstractions (including boo#911001) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_2 for the full changelog - remove upstream(ed) patches apparmor-changes-since-2.9.1.diff and apparmor-fix-stl-ostream.diff - replace GPG key with new AppArmor GPG signing key, see https://launchpad.net/apparmor/+announcement/13404- make sure %service_del_postun doesn't call systemctl try-restart (boo#853019, bare systemd edition) - add samba-4.2-profiles.diff: update samba (winbindd and nmb) profiles for samba 4.2 (boo#921098, boo#923201)- only install apparmor.service for openSUSE > 13.2- Add a native systemd unit which *at the moment* only wraps/masks the early boot script.- add apparmor-fix-stl-ostream.diff which fixes odd uses of std::ostream which are not valid. Fixes build with GCC 5- allow lessopen.sh to run /usr/bin/unzip-plain (boo#906858)- add Requires: python3 to python3-apparmor package - readline isn't part of python3-base (boo#917577)- add apparmor-changes-since-2.9.1.diff with upstream fixes since the 2.9.1 release - update logparser.py to support changed syslog format (lp#1399027) - update usr.sbin.dovecot and usr.lib.dovecot.imap{, -login} profiles (lp#1296667) - update the mysqld profile - fix network rule description in apparmor.d(5) manpage - drop upstreamed dnsmasq-profile-fixes.patch - update expired GPG key- update to AppArmor 2.9.1 (2.9 branch r2831) - fix log parsing for 3.16 kernels and syslog-style logs (boo#905368) - several fixes and performance improvements in the aa-* utils - profile updates for dnsmasq (boo#907870), nscd (boo#904620#c14 and bnc#908856), useradd, sendmail, man and passwd - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_1 for full release notes - refresh dnsmasq-profile-fixes.patch- Fix dnsmasq profile to allow executing bash to run the --dhcp-script argument. Also fixed /usr/lib -> /usr/{lib,lib64} to get libvirt leasehealper script to run even on x86_64. dnsmasq-profile-fixes.patch. boo#911001- rename lessopen.sh profile file to usr.bin.lessopen.sh to match the script filename- add apparmor-lessopen-profile.patch: /usr/bin/lessopen.sh needs confinement. bnc#906858- delete cache in apparmor-profiles %post (workaround for bnc#904620#c8 / lp#1392042)- No longer perform gpg validation; osc source_validator does it implicit: + Drop gpg-offline BuildRequires. + No longer execute gpg_verify.- fix bashism in post script- update to AppArmor 2.9.0 (r2759) - change aa-mergeprof to the final commandline syntax - lots of bugfixes in the aa-* tools (bnc#900163, lp#1328707 and several bugs without a formal bugreport) - small additions to gnome, freedesktop.org, ubuntu-browsers.d/java and user-mail abstractions - fix mod_apparmor to not break basic auth - update perl modules to support signal, unix and ptrace rules (bnc#900013) - don't warn about rules not supported by the kernel - fix logging of "audit capability" (lp#1378091) - add support for the "hat" keyword in apparmor.vim - build html version of apparmor.vim manpage again (lp#1366572) - see also http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_0 - update apparmor-abstractions-no-multiline.diff - remove upstreamed apparmor-profiles-ntpd-pid-location.diff/sbin/ldconfig/sbin/ldconfiglibapparmoribs-arm-5 16625673393.0.43.0.4-150400.5.3.13.0.4-150400.5.3.12.9libapparmor.so.1libapparmor.so.1.8.2/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:25815/SUSE_SLE-15-SP4_Update/dde69e3d971248bd3c4519fa7d31ed5e-libapparmor.SUSE_SLE-15-SP4_Updatecpioxz5aarch64-suse-linuxELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=6ead6b01d17f5bcce7c56c7f9ddbd9fa235d7f25, strippedP PPPPPPPPPPPPPPP P P PRRRRRRR%E< <utf-87caef5624d0590334e458d63bc80964f490ce7c8447547b4aed5ddea43b890d7?7zXZ !t/t ] cr$x#GgmT+^%1ЍhݓAM뱆i&I-E] I@3bdE-ϫ\vl6\g ϭĹ]г9_L8T_ D5ϣ(ԿaPa_T$cceൿ8漴 CĘ1E?PQUTj{$#G+lxʭŝp`\sxq!d]9/#D=Lk@m{EX?هq_1X NQxIUKn` {ZW@\qsY,Ht,ańU<5d4ٳLOCs*\"z&T@1#$l떷IJr@ZwlH ?#6v> ^Ql|Y {㒮DJ \0`*god`6E=@Pq{$L vm fﯫ'12w%vkT^$2G(uI&qzȸnĢkT}ʅ>{S;To_ C.1E{7,f(/tk=Qгm nӅ*3~!gnb!3{~KWU`f񝊽$T\y6vm27a6m?9'TJduk|bu[ 6QOT}0]TčTWSKmZ}XLCϗ[BPHg@[.%p_m \? jB2eRq?q "lSD/SFWۘ0]H W<]׵_>grD%%.Ga ArmHDEGʯ$(w.8daeMZ ;tc0jtO%)E0r_r[qU"Q;JyZTD`~*~L,&bU4L_'y - ^Ok}'5~]#~oM3Mr{.PGH(a|%| |RPbcqF;t+P,\@eF!JxJ=Cx7 /5;Q@HSq;pz:H6_li$hEYո@+'CA߿`_qB]6[]CU-`G_{NC̷抽,[ a3\XRS$V#@9%fVi]u~-Qy uh]1i#lsX4]UdU/c)C?["|焯DOnX* 33j#n13m7Pe)9fs4|w ;*; :κ9_ oNS'iOAIYʁH&A HEnyԋ 8rM{|:")e,CSJ<I*ȝucfTZ^aD>2kZ/}n78YgV ɁVR%i~HMp̍^v0n F.`kGj\O?zf#LH+oy;F4y𳬣vP_`M9g_ulC]݋(qEIlXY+>`meYQ!gB;YyATj7VbC`ee֕BU)R8L'պZ<~#C_hG5P^׏&aZ|5MuڂRQa=ekbZjEQrMT?/-8b˳7!2ukIkc}1\qM>>ٚKV 8ERyMeudކ d=>R|}zJcnQdg}2ntԤ/Fss,=6ɫ}yhrD"'9~F2M뵹90.\ O2]~1[݊Ku(EuXljmz.vwKs}h?~YsJ %@NAiݦIq rBhƬ> b8G$ C-Ij<<[/dpYsH7/DlMKtuߢ Ts:.;902gZӜJ c,{ x 3e#<,DMGYqQ"k;_/БQ&C)~~S>%颀Coq HϏ]#D|BE9|_,P+ud?jo@ YٻZS e>јU%q,\m\VE%n766Hxn@L wso&.,5OM#,>8خ@oN$I ]#ir&Nct`]}3lnK"~ :J&Zz;v3+aez벱 ?y "G}<6Qv%e)xP6 TJ|@7 |T_G'Xљ=d1鮢HmцSd_wYcșCu;1XMy&Dfzaq?27~' D / DrŦFeҠ_PuS#%4Fc(N~ؚLyȪUut%]A37 FXMras':6sAV _HؘPb)q/K 91A Hzo8̴ShT;VDtM7a*QGs׊)dXq?kfa+'d9-4OEcoxGtP6kǦ!BkxRqv(ji=*񂷑8$Rh=}8C$?7ʴW'5!鿼z3?;:88|&dO0񧠕qgbC(ҷ%^(~%tn0ߺ$.La&TQ吰iQNd1ɗjrۦ s}8+i.D zZ=, mWS161H H> &)b˞P&HW1-Ps}\"NPH+U# 7]yAeq,Z.ia+qNaWtBM{S jGxԂ':@9 e O f%L̾@6I!1+^)ƿCdYwKn_!a;="6Dg'iZH>HG#E؛l_0ωЍ֔9\n3ee%Pi W 38ʍD 1J94 {Ri^J`+KZ"4nbZ,B3U9GsqG`[r%֛PIƘFJ{eI%*@*uS@sh9m54WXՁGuo#FnG0:[F <4 :S$0[^dH~~fz"S9n 675X2fP=7ӥ$Z]0ȽMD`CZ&ca0]غHq#9!TEnhރQHς-+;5p$}4O2ЎoiihXc7z>t˧(^ kjJЈ|F|0=`ת)-:*~^?u]4d̋+PU%/ZyDעU",]O wF%6^YEցչ iq%^~ǵ6 ց4њ&5EJ79zՎ^.UoܜeWl!K0wE8]v:`t9BFӴ äIwy4X@2IK`.:9 T2.Z1g  k ![sDռ=7/ KVXӿ8T638.D)sC;5I⿓9 1^:p'B@EP0<v8 %h `qFFC>Z^ECɳߓ/HٶO>?RR P!WET{JcV&r7b'OmotղOXZX[]i_~1V̅Mue f|R<9p`բ^<6mRpG2`.dV.bӓܴxuTd3I CK=%J<-q{ x;OSȠEIC:,gBFyOB֡W93հ:>KF%OÎIx0&xˍ5=B*0^x? lGڀyH_Q S >)NSD]ރ֐tN/D;:n"U!b]q)#p2XKG!3"Kh; bNle Z>q,F+80%hgf쿙']#Zyhf9`*R*Gt`\^뇄@z| AHJ^JT\\UwfuWb(7qvw3<|pL5I@8oA[d9ko-PDB&nOEwJfKEpRkR̜06&h@AKlO(` #.+D/ljH0)E9D@n_Dt!y-JPQAx/4p U!_h1fл^ N\ң55tJt o%ҸT6!MU+f9mChWKJ\;Lk"/ V5N4~uD܊0KLē?+(8hM5iŢhcJgDfbv_(e9͕C'Y(.T4!4P5 %&3d9Zr8#g9X*"ku'Sˤ8wXqêz.ت{wCEhEϲ^ۇ*ojwkpA$YŢO==ГefNnT |== !Bm^gzsby2t0sB쓣XdM #Xj(麥y9lj ڮ=ڇîdS6*ιa! R^Xft|M GT]صYbh !iwkRcXۏ#,92at}(fu}@#4kK~EBsH! !v! U{/V/"y%($g]5ݰ uFDHwk^mY,/E,Tl.J"3亾C5j$gjUp oelKɬ('ȀF$& P1ҳe:b a؏ {:<)0Ci?FO˒7B0Rwg]59HwBttT1ZVk(O|?zٲZިڵb"~/b`>v"rT]VBž *)hͼ*_bjdߢ 5 8Xb;( 9kvZꅛUxV^#o[EHӘ=XlBbv˂Dآ(뙋!W_\l4)K=U\>0^6p@!+/uKZAAmp!QKK]7k680_7Mcѡ׿TzNܦea9ypKhӨHZ&*ܩ#= syhlVHiP#+JY4U_g2,]f1]8&h2F2 1g%PkVӿʜe@ne%*ltWڦƆmtJ4fs%D6٘?Ǟc+U~K]U{ Cs9C: )!t[-8/0)_9ʱvY$qhβr8ԉfh} /r tk KfB2eGێpJ'>okN%樼#^Ϫ7T:χB#=91]|Y'2/W PiN;f0eu,bVbFJx[k6Qn Xl8{ՅA > ;wﻒn;" Sϸe ,M֯(=yi=s=~#H1 i>3B-q "M1puK\E ~Wp\7.&C#GTW;{ S\ϙ#V,YMk0o{Kݶ ]:. h ,tIXQC'3Y< / 69&,n^HTnF68 "Hd{˜=\\GQw҉]3&)؇pM:܍è)F90!ZKoOt/19؅ QC JG2߆#n;{ҋfjGj%s( a68 1K~e݀ #ܵ:2["8rR&4;% `9'[JK-:̲OmXjȊ 뗧}Ȑ Py@5;S&mЛӖ{8TGSS;_iYvlZ'KQ|s=\"Or^ `#I:4;)Lg\ d%@ n{~Đ㫎t:3ɫ95S'"W@V0*ɮbwurGZy)Zĕj'o[F93=(ܠ/'P=un^-qA/+>w"gu(RNluktբ'D8 #E22,D~{9X9q5S.-&۟HЏSmt JD}k ڋI.sbMi˱f6U-qҟ9@p(]E.5t]Wncc4xj׃yifqzD(z~\Zk(SfШ]Jw[E@IOj QwLp;.:Ÿ|ˆ{ %CSc A㇠Lq1í`WR/z'|O,麳OW/rm38-{^)Yrp|+wP ЋHAL¾9rs>x]Jl*x.fđr>\ȎH[BdS"&nH_Tz&0H * &lZrrKhjޑ<х/wE"~?[ #\'%GM%ic>xMW؄ZGp,v~cX{RNb auZȐX!!eR_(F;tk""Rbl8 蠌Y_g}]3tp.rF0fG4iTIcQե2jM_hQp [.EV|sdLyqЈ7*yIyCC:AiK!"'R(8P@Lk!KźrPBߨI]=rq; jsnU)VNˠn"ĥ\L *gXj+f0@RoX5K4y`\βpsXci9T\芽!\$c /Qs/2-4 * |9\-yc›1<}*6L`=Ԋ?loVpbM ccR'nn.8prQ3w`p6T.*S=jOϳfulV5j'0#:5 ",`,h%p/zHp 55ddi5{Ug3+)uA.ӯT@aG/lb%)L6ym,,@eغ؋M#,/we ?q—/4eǁl\$PWJXݓG,_܁,jԱDIRtzЉf7PcY (!ز\i yQ$U0#kW.zXQbFk$Tx;nR({WJzv]Dx8=S֟#x{Bce@klcDzaVW $~r0eI%(yuT>Yn0<>RGnf" ş ۊ40[|HüѴlѕqNkZ#~MQckӽN,)4WXD&֯u u^.|$Э B6*k+PI% 8Ͳ{q~%wGXQ'Pv*=zMc峀ĉfLkjWc0iWssljEMHnlJ:Ǭ>BעɊ/5 %.*Ø}O vrPwԝ$8;pUF'^L-A\mP޹8 n"%@h,1\KL40gѻJ'*0Ǵ &l㦍WdG4p.ګ|s1A=&ڨZ_f$|H*jts1;BHz8YzɜQa^Į|ԊgҕMV2th.@>oE @ݧHEE(:PhN㳕Y]zk2?#ɉbz+(g2\N"g$}ۂ7&C{W:K[g8)$'!ҳ0Ҁ$ `W.b[@\_4TF#Lm)}d$fm+.d~{QpqPdxN&.SV #% 74R(G]=P\S(DzE%%BZA6(%Iv8?x>oAMrcwO~%^#AW޲8ZNܤal[1"O̖tP>\4\8 x}Z-j* ޞ馨ZOzdYjR:?סűUY!}v/[ -H^nOħ5sdsSM|XzWxmAQļ!X+ GIa>pt$<.2hS}#0 ^xRr"FdBf*o/(ԑ/ 7 w퍞!MO*z[5Zɛ0Jay/aEdOIܓ6ՂhH8  %uvDc(%7*%{І. F }T&pi6t9uji'AEglǻCbtvQ*GHYv;.S[ jLdB铯u>K}MWH@l"Y^BBy(zv=tis&xJX@mQx6;5y#`f]L/qI{ӥla6Te52P2>A95IXVU˯@9\A5Up( Àb5?y+t/rJL۰wc[`~AY do\BU`!pzS/κwR{<^k'B ly$4;(/gqBr\d!,rUKp lAe-2*&ƜАn^q u^qbP0 6A[gg)*L%fNQ1.ݢI$-d6^5 4\>q벛֝E{SMFTW{3$bލh**g]TC7'D 1PN! DޮS؜Ǘ9Ŷ=?Lt'q 3Mg8!&0~% >8TVw`ܝ sGu\ g>}j!괊'Ly<!$WCPE98>*xH6iד{1P]|KD+SdSq" @~c\dӈăA[7&E,iUhgqyחO/9LނZZkc+79uD1ʊJt1u8Ţ5 Ħ(>b!SElLW_rzL߲.KϳhVicΔP??v 2" nSCP&vw߀tny+;=IQʵ%;%>7ldM]{iwiqd$g1Z!kPk&֨qQR99wZGĵ((RQ vc:6XɪE k(-|4?״I(Q$~J]yj>R ת:oK "~Y>f CGRVфj7Syp1.@m+d͘mkq#ee >n{q>ɂ4EAv&*g`"DB}>u9JZQ#E{.6bpO8Gln pP~IӭS/Eϡ)%\w+ ,%Fv5؛M*->A4=#Fȃ) =H㩈t^^U{XdH6S(NGm k=8Ǭz%LI"G @KO*3K衬@ R1 nHF{(9cj X '1o+mLq律 `c"L&ec@fj KBtJ0[d GB3_`\ep&p67?̢ @KƈZ&#"bgh}n{Ŗ blf EgۙEYE5D̟jq >V[Gtja6a= 9Mi㧡Uc*Y*{ =O+I&}墪4Z5拔/hɀ 6_L7^Fx` o#y5ThKnP(OY#oؘuE$>_v @}~[JF_Dc.kq;2D{~e3a[flUܩ'=uG[?]Z--(A dxԡSS0_{D#gXW+McD6{Thevggh<~ykgI'_fcd3yLT%K^s18k7\}U^dBfVϷ˃u@DYpX)tbgG'bwZ&uVW U%DHTn\$ΒIk{m[0'.Ѿ#g0%gkZ{33a0YJ+Pb AwI 򲒾]UxXp6UR"mҕ mibIz7}j>[gIqj+yhU u;fF3xm1!P#?ch-NpuHLY8Po`* &LmzD6t*n=d(#UBqLp_%gϜbe+~0KoyjWTeNqL]3XLDbWQ[(5 yJ&Rf J/MK.D6`F32@HtkE^۪_/,YXr:,17D2\~da(};,³"km+퍚:ht,Yڢ( 7#lȷ# }v2m:!pfhZL?Vؿ>EqQGH@kcS[4 kBJ:8X$Ga&zǗ?Ǝ3{,CAc`OKΉFC[)hT@q 7J:>Jp MڋЛP0{]]92ŶTŠ7-yV G.T6Bå.m4#Ъj!|Q+U& Z3\3y)$4~2SCL2^ mmbW_(ȩbZvcrjo)b]2) *XQLWHt3:=HlCMG?L2e.vyRoN+F/e{(WBQ?4T{a VXsPD>"d~jp SG]Aտ/xS˾(c,vRUlQJMpB.B+Q%(ssr3&U"-_e1Miկ,ãR--+Qbb]~bF["Y$WbZnoO>wK؜{~067ьh ox1v3VxϧLz0VO!b@3ݸ8.ey2H"XVwҽ̗C>\3)CMR[Иo$^x*תNzK{YТ'H.җ<W6mfx^7}5 4AW_dG abjfxؖx^N:H.(D=ȡvrH=z7KȂk6R~1sNLWhJpQd"Ϲz#"LAZ1$`zsYZ^0!û^M5.(*X,}{-5WUFf0W(&zY)ZvR#Rqi~ 3@6t > MjT?FD'r 3uȮ3 (_v8MϮމC2n:/Oǵϸpy)J5"p_bUxpmJZ7Jj*0 yD1)x}L~ҷy]<3d(IU *Ł` m E-Jm^<~n0Kq&]ѦۯAv[lD2"=8T҃oK6g-R7""'aoaj,gUy|/g5)hF&x*H][,CycA1ꡇT8Q9dRڇKDdRmXMk²RjZ0mJ.E{4ӊGR&is_wE26עc}i̿6j>7Q-7a*ҿ_6yz -P&%ћ Q^Iy~6~)vڜ҈]`UnD/v|0'qz>h٬poqo>D+ GSx$NZq + q MJWz[ϸrfu/,uc;8LKXE9v93#YrAy䚻 .m2i{S B#Ư-qpxy :/^l!ܧs%&gsgmۍP{6\ 1n*~|f ,%V\ ](W0 iʚiVT@sTQ"f`xٙM eg(- ZyuHb,;b:zxm+"GT:goM ۱l`F}<|mTcZ'61>2Jpp00t#y*͡E'ud_0~PT3)@ږ_} Sb9˟N`:2.c4)S9Xaa[xNĎKӅf7f$4J{; bTS۬ٔ.7e8VLckN]j.ld,t'۸QO_5/㛆« KR$!Ft|h|Hqe**cpxi2jj>g=nǖoM@ s$00F\KR9fľ?]lٶ6UrŢ]N) OkOud4gIoSM^ᮯnW׷a'\ {Fn%0 !}]tn#{m.BUj"/ 3pdr,[SԺ~Jd;֘s<8CkOe } ;x"FbE##]kMJa2w|U`!4dی0t2I瓲o w@HA۞$Ǜf)rje%eMz}hiVZ~mb-N<-IKs7 <((l =XQod/ԘS:Q& aW K¡ Ph/ ,؍0^0H Σj8%WWdEy]ưC370 GLhz},|2U'bgaA'i1XB̙NhvRGi^ _jS{Z_ʤdo=(OH #|套'foֵW+ɚb5s2_UjWf}8M{Vj U[[n o}7[M$iBC;i:I8͔,9Q) *R*a QVZi4&3ı,QUa-vS42T ;s-șN2 '$,N6J߃lN4M][{t'Z` pV=&`+TۀV*R`0h$&[޲ K*6?++a0v,gQKՖ[pB0-1A,e}ki8D9 Rb Bj?+`ju\<8vviY*2#"^H UM7a E_pvyH_Bt5\d]T&\lG`zH^gPtvsz56$d x|Fc羳 w&ǟdI9fcퟏB/$̕uVo`\.x5ſԴ |UxC_5#uyQVi[_Q^tu3 !-܁T6,Vf,Gbs#|Kn2I\L gvllb/Ny'[Y(S@ug>/*0 `31)C=Cy a+[aGp""6JbG%SwЁlM,5cPDh6A\!JPKP=3f1B3Q&)ŬwQA`GjNL| aZ Rfn0`:*@8 P4 PfjׇCw-;-5U-n#ӗ6t Qx~>,<i㇒ H2\} ޠ쨏Դo'FKJrNh)#ʟ*%UQrŞ+eٛpb>[boJ~ scHP֌I e8}@:}E.'Meh#j0~Y"Ƹ` ɮ{]h#Y t*giGB܁& F[VZϫseesi&(KQw'2E/ l̜PVב!d($VVL)"ӋH3iiKT+ӾD26B7nZĖ90ɪ_?`ɫYRqps@VЉZY( @ S~ڜJN4eWO }-`wd&% W`"=r|/4I=vϒ>Dvѡ'A $ˎ/ G0u{]7jNk] P .Yx#`I31>/ͭ#kE~`. SnZɑ9jF݅CeŠ~Ə!\V[K[wEo{3"{Pʊ8ZCg+}<5k܌va&-D8Uj.j̱Ш:qjqVDkjع7P~,=f榪;8}ü ׶@?U $SuUGZiuᬅ[\Ⓥe#~H7Dwy đ6rشSPpu)^l/tDz(xeV+ﻌbUёӺP7֊Ca.D=mwk4VNou>'(mI$a*pQ 0mSiJd,L~Wy3SV>&u7K@t?;wo6ЭMG=62U2(#Op7f0ZQRo\Ao ZN5 'z%9WZ-$? }C I1_ <>x >Q>F5n<l)[[P2&{P0S:#+;{ܙXjjѸ]'.sپEPWy*va$&H3̴eSh M@R ᣴjSF>AKnh$ILTa;ې뜂sZڌHYK[z:W4>2X`̒w]μ$RZnNV4٣hQ֪! PP~ F|z6!}?A=QFU ߬lVǚV|>(7͵4JU8J-$(-@-ͻ_z@.G&:W>:F 70o~NQ\OF0o}>8KQZ, u{SN'ŝ3YxP\/wxUhKoQ?W+fs^Mfy|o KQ:./V\ofzE䪶}Ď'gq]|ȗMvCꡋK/ea0TkPb7G,X}IcPۣ!ϼ&1E.,Ʌc[za-\j [h WTCq:y%(Qݲie4-_NO,tE.Og1as7q6ɆOƂȴU%XJ~(C8ߧV4=?#"z]g,>:i{uy}?_iQjbQwAn6K0Qd\2@\G1y_iN$@PQZr|oIջ|;ʫj52Bsi*Z@2h@`e>?xB _4(~<0(:' P{c]1a x)uفr#+@(>ʄ*j'~:=Mb7zO¿f vJ8VV$Lňr XC%¬/0J\IQekuZWoYHKAzPa7^DžKL/]siA2CU,:bo>6zx5߇w!ĆwE 64G$1< GSR4np;)5H|t 9AV?+k[=0-?cr)YDwCz@&rv2٫Б+D,娨6I|+b osT~.քjlŐO4ADn8C]7hFֲ溴RqEl-b!5pݲ龖]N|8ÀHk #cH,?%=U{u~ 8mZɞFztƝǡtA/;IٕAYDHb/8[x"k:pk+DM#DH~YW;sdB,XZ H[=؆li !c$tDmׇ+<>U 1"?gȏSj;&!Ra(U_8 eͨk -X*"bTw2^x<$𖤇R=*@TN q ?g;]v>ǟ_r&lP"aW(ݿqR"ܑ:qn}R xIg?{8Eu<ۺFsrb2tO)J*MA%F'k`A :6$ 5]圠,5 \_uWD۔ YVRK#NdΑlv'?_{6 9O]|ыx1"qTt9[FlYKKTknojH X [9_OЗ;VE+X$pX01ĒghWmr o{({:5mL 8ɣc q_`:gSl|q]]w snL( ^e=) IL{yf-I:t͟[w0PWQ!zp۵(X2t\g K=TnD߼$Cʼn85EIāFp7^JI'SjL\_C<}7m%z ŀpАo:eZ!NW2R1@^+:hp&K೗Y%PBCI›T#xNebfBHͶ \RoA%ACdU@-z+5  )'XgIOEĦ˞]TE_65T9 l# З]8jLDrxr3˶2MUút1vC0ԎeLu!&ך.+5{c jB[Ҵƒ\-j˄tf_=eo/ݩI#z,}LlIÅlPc3 J/+-z+FF߄ N/k"*k[dv};mF*y8bDAN5(K+T%X*sM2cUuCI65#o'g%f+ U5oͶC󏁼ք[ac8[)<ճ!9P14ӻIRމUJOiC/_bģG@Y""( 'qQCyfjYr2¼uY6|,תgBFr VF7].o!@qx:vBfJz1O`mqd 邎sf }EÙ#!R7*JiqIගCBm.'JHu䐯\q? =dNθ$FJD߮(%DQ̍v펯 BeM Z~۰ZwFΚV@Xz=`LGGtzR2Acoj1Pxך=ϢwCߤ FMͣtUBP.tzse#62SBaqGL$ YZ