apparmor-docs-3.0.4-150400.5.9.1<>,$da p9|WggG t_gU2fvS/cI? "9AH* f=PW-x}ztc 9:f*Oj0 'bįVrM)!~kI[1юL 0:&?S+8x@7Xc|B JH^{dha/Y^FeSEt#x+'2LnrN'I}&8l \(wvU wIj>*l{2:k ʢ %>;?d # B 5Ihnx         G  T    @P`(8~9~:8~FG H I XY \4 ]` ^bucdeflu vzsCapparmor-docs3.0.4150400.5.9.1AppArmor Documentation packageThis package contains documentation for AppArmor. This package is part of a suite of tools that used to be named SubDomain.da h01-ch4dعSUSE Linux Enterprise 15SUSE LLC GPL-2.0-or-laterhttps://www.suse.com/Documentation/Otherhttps://launchpad.net/apparmorlinuxnoarche%ME.VA큤A큤d_d_da b`b`b`%b`d_b`b`b`c30036de8e525c68d8474622f3f6984164dc60e91670039898e5b9066ae562d630a0adfab04b7755e093632fab7b8ab2adea32fc2eb640ec9586faa0cd2ebbd4bfadc5ec4cbe5c894595c52b95c516d8daa27a76a6cc356b77065592ed8a0299d383e3f1c2fd71198fe319a325fbb9a2068dd73b2609e27db150d3aeddd9ed06474d65c9a3464d4a98ff295211ad0f248987237746fb4491779d0d2887ebf76c5e33ae4afd85d4e8a3a0f579068ca74e1686ba4651958a25e6792c6e1226f58dbb7e15ffdd6bd82b037c217dfac7d3cd0f310aadba0776760d1d3b73f6bb778c6060fdf95aa753427faf0a9b7f2aca6de48d1e7e909009845d8a526d25e358a584c8cdc92165201b233cf1607b5c1096de663abb9ed9afc9d3e92da2db5b35c6rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootapparmor-3.0.4-150400.5.9.1.src.rpmapparmor-docs    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3d@d@cbk@bi0@bZbV@bT@bRbBb<]@b@a7aZ@ap@aabaim@aEaaua $@`#@` @````_@`%@`!'`>` @__ǁ_ǁ_Q_h__@_~@_[f_P_-B@_@^m@^@^<@^j$@^,-]҇]o](]K@]]@\\@\ \\v{\I\ include in apache extra profile optional to avoid problems with empty profile directory (boo#1178527)- prepare usrmerge (boo#1029961) * use %_pamdir- update to AppArmor 3.0.1 - minor additions to profiles and abstractions - some bugfixes in libapparmor, apparmor_parser and the aa-* utils - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0.1 for the detailed upstream changelog - removed upstream(ed) patches: - changes-since-3.0.0.diff - extra-profiles-fix-Pux.diff - utils-fix-hotkey-conflict.diff- Use apache provided variables for the module_directry: + Use %apache_libexecdir + Add apache-rpm-macros BuildRequires- add utils-fix-hotkey-conflict.diff to fix a hotkey conflict in de, id and sv translations (and fix the test) (MR 675) - add extra-profiles-fix-Pux.diff to fix an inactive profile - prevents a crash in aa-logprof and aa-genprof when creating a new profile (MR 676)- update to AppArmor 3.0.0 - introduce feature abi declaration in profiles to enable use of new rule types (for openSUSE: dbus and unix rules) - support xattr attachment conditionals - experimental support for kill and unconfined profile modes - rewritten aa-status (in C), including support for new profile modes - rewritten aa-notify (in python), finally dropping the perl requirement at runtime - new tool aa-features-abi for extracting feature abis from the kernel - update profiles to have profile names and to use 3.0 feature abi - introduce @{etc_ro} and @{etc_rw} profile variables - new profile for php-fpm - several updates to profiles and abstractions (including boo#1166007) - fully support 'include if exists' in the aa-* tools - rewrite handling of alias, include, link and variable rules in the aa-* tools - rewrite and simplify log handling in the aa-logprof and aa-genprof - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_3.0 for the detailed upstream changelog - patches: - add changes-since-3.0.0.diff with upstream fixes since the 3.0.0 release up to 3e18c0785abc03ee42a022a67a27a085516a7921 - drop upstreamed usr-etc-abstractions-base-nameservice.diff - drop 2.13-only libapparmor-so-number.diff - refresh apparmor-enable-profile-cache.diff - partially upstreamed - update apparmor-samba-include-permissions-for-shares.diff and apparmor-lessopen-profile.patch - switch to "include if exists" - apparmor-lessopen-profile.patch: add abi rule to lessopen profile - refresh apparmor-lessopen-nfs-workaround.diff - move away very loose apache profile that doesn't even match the apache2 binary path in openSUSE to avoid confusion (boo#872984) - move rewritten aa-status from utils to parser subpackage - add aa-features-abi to parser subpackage - replace perl and libnotify-tools requires with requiring python3-notify2 and python3-psutil (needed by the rewritten aa-notify) - drop ancient cleanup for /etc/init.d/subdomain from parser %pre - drop (never enabled) conditionals to build with python2 and to build the python-apparmor subpackage (upstream dropped python2 support) - drop setting PYTHON and PYTHON_VERSIONS env variable, no longer needed - set PYFLAKES path for utils check - add precompiled_cache build conditional to allow faster local builds without using kvm - remove duplicated BuildRequires: swig- update to AppArmor 2.13.5 - add missing permissions to several profiles and abstractions - bugfixes in parser and tools - fix two potential build failures in libapparmor - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.5 for the detailed upstream changelog - remove upstream(ed) patches - changes-since-2.13.4.diff - abstractions-X-xauth-mr582.diff - sevdb-caps-mr589.diff - libvirt-leaseshelper.patch - cap_checkpoint_restore.diff - add libapparmor-so-number.diff to fix libapparmor so version (!658)- add CAP_CHECKPOINT_RESTORE to severity.db (MR 656, cap_checkpoint_restore.diff)- %service_del_postun_without_restart only works for Tumbleweed, keep using DISABLE_RESTART_ON_UPDATE for Leap 15.x- Make use of %service_del_postun_without_restart And stop using DISABLE_RESTART_ON_UPDATE as this interface is obsolete.- libvirt-leaseshelper.patch: add /usr/libexec as a path to the libvirt leaseshelper script (jsc#SLE-14253)- sevdb-caps-mr589.diff: add new capabilities CAP_BPF and CAP_PERFMON to severity.db (lp#1890547)- add abstractions-X-xauth-mr582.diff to allow reading the xauth file from its new sddm location (boo#1174290, boo#1174293)- add changes-since-2.13.4.diff with upstream changes and fixes since 2.13.4 up to 5f61bd4c: - add several abstractions related to xdg-open: dbus-network-manager-strict, exo-open, gio-open, gvfs-open, kde-open5, xdg-open - introduce @{run} variable - update dnsmasq and winbindd profile - update mdns, mesa and nameservice abstraction - some bugfixes in the aa-* tools, including a remote bugfix in the YaST AppArmor module (boo#1171315) - drop upstream(ed) patches (now part of changes-since-2.13.4.diff): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-fix-utils-network-test.diff - make-4.3-network.diff - abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch - apply usr-etc-abstractions-base-nameservice.diff only for Tumbleweed, but not for Leap 15.x where it's not needed - refresh usr-etc-abstractions-base-nameservice.diff- Add abstractions-add-etc-mdns.allow-to-etc-apparmor.d-abstractions-mdns.patch (bsc#1168306)- fix build with make 4.3 by backporting some commits from upstream master (boo#1167953): - make-4.3-capabilities.diff - make-4.3-capabilities-vim.diff - make-4.3-network.diff - make-4.3-fix-utils-network-test.diff- update to AppArmor 2.13.4 - several abstraction updates (including boo#1153162) - disallow writing to fontconfig cache in abstractions/fonts - some bugfixes in the aa-* tools - fix log parsing for logs with an embedded newline - see https://gitlab.com/apparmor/apparmor/-/wikis/Release_Notes_2.13.4 for the detailed upstream changelog - drop upstreamed patches: - abstractions-ssl-certbot-paths.diff - apparmor-krb5-conf-d.diff - libapparmor-python3.8.diff - usr-etc-abstractions-authentification.diff - refresh usr-etc-abstractions-base-nameservice.diff- add usr-etc-abstractions-base-nameservice.diff to adjust abstractions/base and nameservice for /usr/etc/ (boo#1161756)- Properly pull in full python3 interpreter- add libapparmor-python3.8.diff to fix building the libapparmor python bindings (deb#943657)- add usr-etc-abstractions-authentification.diff to allow reading /usr/etc/pam.d/* and some other authentification-related files (boo#1153162)- add abstractions-ssl-certbot-paths.diff - add certbot paths to abstractions/ssl_certs and abstractions/ssl_keys- add apparmor-krb5-conf-d.diff for kerberos client- update to 2.13.3 - profile updates for dnsmasq, dovecot, identd, syslog-ng - new "lsb_release" profile (only used when using "Px -> lsb_release") - fix buggy syntax in tunables/share - several abstraction updates - parser: fix "Px -> foo-bar" (the "-" was rejected before) - several bugfixes in aa-genprof and aa-logprof - some fixes in cache handling - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.3 for the detailed upstream changelog - drop upstream(ed) patches: - apparmor-nameservice-resolv-conf-link.patch - profile_filename_cornercase.diff - dnsmasq-libvirtd.diff - dnsmasq-revert-alternation.diff - usrmerge-fixes.diff - libapparmor-swig-4.diff - re-number remaining patches- add upstream libapparmor-swig-4.diff: fix libapparmor tests with swig 4.0 (boo#1135751)- Disable LTO (boo#1133091).- update lessopen.sh profile for usrMerge (bash and tar) (boo#1132350)- add usrmerge-fixes.diff: fix test failures when /bin/sh is handled by update-alternatives (boo#1127877)- add dnsmasq-revert-alternation.diff: revert path alternation in dnsmasq profile and re-add peer=/usr/sbin/libvirtd rules to avoid breaking libvirtd (boo#1127073)- add dnsmasq-libvirtd.diff: allow peer=libvirtd in the dnsmasq profile to match the newly added libvirtd profile name (boo#1118952#c3)- Use %license instead of %doc [bsc#1082318]- add apparmor-lessopen-nfs-workaround.diff: allow network access in lessopen.sh for reading files on NFS (workaround for boo#1119937 / lp#1784499)- add profile_filename_cornercase.diff: drop check that lets aa-logprof error out in a corner-case (log event for a non-existing profile while a profile file with the default filename for that non-existing profile exists) (boo#1120472)- netconfig: write resolv.conf to /run with link to /etc (fate#325872, boo#1097370) [patch apparmor-nameservice-resolv-conf-link.patch]- update to AppArmor 2.13.2 - add profile names to most profiles - update dnsmasq profile (pid file and logfile path) (boo#1111342) - add vulkan abstraction - add letsencrypt certificate path to abstractions/ssl_* - ignore *.orig and *.rej files when loading profiles - fix aa-complain etc. to handle named profiles - several bugfixes and small profile improvements - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.2 for the detailed upstream changelog - remove upstreamed fix-syntax-error-in-rc.apparmor.functions.patch- update to 2.13.1 - add qt5 and qt5-compose-cache-write abstractions - add @{uid} and @{uids} kernel var placeholders - several profile and abstraction updates - ignore "abi" rules in parser and tools (instead of erroring out) - utils: fix overwriting of child profile flags if they differ from the main profile - several bugfixes (including boo#1100779) - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13.1 for the detailed upstream changelog - remove upstream(ed) patches: - aa-teardown-path.diff - fix-apparmor-systemd-perms.diff - logprof-skip-cache-d.diff - fix-samba-profiles.patch - make-pyflakes-happy.diff - dnsmasq-Add-permission-to-open-log-files.patch - refresh apparmor-samba-include-permissions-for-shares.diff - add fix-syntax-error-in-rc.apparmor.functions.patch- update rpmlintrc: - whitelist .features file which is part of the pre-compiled cache - comment out filters for the disabled tomcat_apparmor subpackage- Backport dnsmasq fix: 025c7dc6 - dnsmasq-Add-permission-to-open-log-files.patch (boo#1111342)- add make-pyflakes-happy.diff to fix an unused variable (SR 629206)- add fix-samba-profiles.patch - smbd loads new shared libraries. Allow winbindd to access new kerberos credential cache location (boo#1092099)- exclude the /etc/apparmor.d/cache.d/ directory from aa-logprof parsing (logprof-skip-cache-d.diff)- add fix-apparmor-systemd-perms.diff - fix permissions of /lib/apparmor/apparmor.systemd (boo#1090545)- create and package precompiled cache (/usr/share/apparmor/cache, read-only) (boo#1069906, boo#1074429) - change (writeable) cache directory to /var/cache/apparmor/ - with the new btrfs layout, the only reason for using /var/lib/apparmor/cache/ (which was "it's part of the / subvolume") is gone, and /var/cache makes more sense for the cache - adjust parser.conf (via apparmor-enable-profile-cache.diff) to use both cache locations - clear cache also in %post of abstractions package- update to AppArmor 2.13 - add support for multiple cache directories and cache overlays (boo#1069906, boo#1074429) - add support for conditional includes in policy - remove group restrictions from aa-notify (boo#1058787) - aa-complain etc.: set flags for profiles represented by a glob - aa-status: split profile from exec name - several profile and abstraction updates - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.13 for the detailed upstream changelog - drop upstreamed patches and files: - aa-teardown - apparmor.service - apparmor.systemd - 32-bit-no-uid.diff - disable-cache-on-ro-fs.diff - dovecot-stats.diff - parser-write-cache-warn-only.diff - set-flags-for-profiles-represented-by-glob.patch - fix-regression-in-set-flags.patch - drop spec code that handled installing aa-teardown, apparmor.service and apparmor.systemd (now part of upstream Makefile) - simplify "make -C profiles parser-check" call (upstream Makefile bug that required to call "cd" was fixed) - add aa-teardown-path.diff - install aa-teardown in /usr/sbin/ - move 'exec' symlink to parser package (belongs to aa-exec)- Set flags for profiles represented by glob (bsc#1086154) set-flags-for-profiles-represented-by-glob.patch fix-regression-in-set-flags.patch- add dovecot-stats.diff: - add dovecot/stats profile and allow dovecot to run it (boo#1088161) - allow dovecot/auth to write /run/dovecot/old-stats-user (part of boo#1087753) - update 32-bit-no-uid.diff with upstream fix- Change of path of rpm in lessopen.sh (boo#1082956)- add disable-cache-on-ro-fs.diff - disable write cache if filesystem is read-only and don't bail out (bsc#1069906, bsc#1074429)- add parser-write-cache-warn-only.diff to make cache write failures a warning instead of an error (boo#1069906, boo#1074429) - reduce dependeny on libnotify-tools (used by aa-notify -p) to "Suggests" to avoid pulling in several Gnome packages on servers (boo#1067477)- update to AppArmor 2.12 - add support for 'owner' rules in aa-logprof and aa-genprof - add support for includes with absolute path in aa-logprof etc. (lp#1733700) - update aa-decode to also decode PROCTITLE (lp#1736841) - several profile and abstraction updates, including boo#1069470 - preserve errno across aa_*_unref() functions - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.12 for the detailed upstream changelog - drop upstreamed patches: - read_inactive_profile-exactly-once.patch - utils-fix-sorted-save_profiles-regression.diff - lessopen profile: change all 'rix' rules to 'mrix' - add 32-bit-no-uid.diff to fix handling of log events without ouid on 32 bit systems - no longer package static libapparmor.a- update to AppArmor 2.11.95 aka 2.12 beta1 - add JSON interface to aa-logprof and aa-genprof (used by YaST) - drop old YaST interface code - update audio, base and nameservice abstractions - allow @{pid} to match 7-digit pids - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_95 for the detailed upstream changelog - drop upstreamed patches - apparmor-yast-cleanup.patch - apparmor-json-support.patch - nameservice-libtirpc.diff - drop obsolete perl modules (YaST no longer needs them) - drop patches that were only needed by the obsolete perl modules: - apparmor-utils-string-split - apparmor-abstractions-no-multiline.diff - drop profiles-sockets-temporary-fix.patch - obsoleted by a fix in apparmor_parser - refresh utils-fix-sorted-save_profiles-regression.diff - add aa-teardown (new script to unload all profiles) - make ExecStop in apparmor.service a no-op (workaround for a systemd restriction, see boo#996520 and boo#853019 for details) - lessopen profile: allow capability dac_read_search and dac_override, allow groff to execute several helpers (boo#1065388)- read_inactive_profile-exactly-once.patch (bsc#1069346) Perform reading of inactive profiles exactly once.- update to AppArmor 2.11.1 - add permissions to several profiles and abstractions (including lp#1650827 and boo#1057900) - several fixes in the aa-* tools (including lp#1689667, lp#1628286, lp#1661766 and boo#1062667) - fix downgrading/converting of 'unix' rules (will be supported in kernel 4.15) to 'network unix' rules in apparmor_parser (boo#1061195) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11_1 for upstream changelog - remove upstream(ed) patches - upstream-changes-r3616..3628.diff - upstream-changes-r3629..3648.diff - parser-tests-dbus-duplicated-conditionals.diff - apparmor-fix-podsyntax.patch - sshd-profile-drop-local-include-r3615.diff - refresh apparmor-yast-cleanup.patch - add utils-fix-sorted-save_profiles-regression.diff to fix a regression in displaying the "changed profiles" list in aa-logprof- add nameservice-libtirpc.diff to fix NIS/YP logins (boo#1062244)- profiles-sockets-temporary-fix.patch to cater to nameservices with the new sockets mediation, until unix rules are upstreamed (boo#1061195)- add apparmor-fix-podsyntax.patch from mailing list to fix compilation with perl 5.26- do not require exact X.Y version of "python3" - require also matching python(abi) which is arguably more important- don't rely on implementation details for reload in %post- add JSON support. Required for FATE#323380. (apparmor-yast-cleanup.patch, apparmor-json-support.patch)- add upstream-changes-r3629..3648.diff: - preserve unknown profiles when reloading apparmor.service (CVE-2017-6507, lp#1668892, boo#1029696) - add aa-remove-unknown utility to unload unknown profiles (lp#1668892) - update nvidia abstraction for newer nvidia drivers - don't enforce ordering of dbus rule attributes in utils (lp#1628286) - add --parser, --base and --Include option to aa-easyprof to allow non-standard paths (useful for tests) (lp#1521031) - move initialization code in apparmor.aa to init_aa(). This allows to run all utils tests even if /etc/apparmor.d/ or /sbin/apparmor_parser don't exist. - several improvements in the utils tests - drop upstreamed python3-drop-re-locale.patch - no longer delete/skip some of the utils tests (to allow this, add parser-tests-dbus-duplicated-conditionals.diff) - add var.mount dependeny to apparmor.service (boo#1016259#c34)- Cleanup spec file: - don't use insserv if we afterwards call systemd, this can have bad side effects - remove dead code - remove now obsolete 'distro' checks - Replace init.d script with new wrapper working with systemd- add python3-drop-re-locale.patch: remove deprecated re.LOCALE flag in Python UI as it was dropped from Python 3.6 (lp#1661766)- Fix RPM groups- add upstream-changes-r3616..3628.diff: - update abstractions/base, abstractions/apache2-common and dovecot profiles - merge ask_the_questions() of aa-logprof and aa-mergeprof - pass LDFLAGS when building parser, libapparmor perl bindings and pam_apparmor - adjust deleting the cache in profiles %post to the new cache location - silence errors when deleting the cache (boo#976914)- split libapparmor into separate spec to get rid of build loop involving mariadb, systemd, apparmor, libapr and mariadb again (see the discussion in SR 448871 for details) - libapparmor.spec is based on the AppArmor 2.11 apparmor.spec, but with minimum BuildRequires- update to AppArmor 2.11.0 - apparmor_parser now supports parallel compiles and loads - add full support for dbus, ptrace and signal rules and events to the utils - full rewrite of the file rule handling in the utils - lots of improvements and fixes - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_11 for the detailed changelog - patches: - add sshd-profile-drop-local-include-r3615.diff to fix 'make check' - drop aa-unconfined-fix-netstat-call-2.10r3380.diff, no longer needed - refresh apparmor-abstractions-no-multiline.diff - refresh apparmor-samba-include-permissions-for-shares.diff - spec changes: - aa-unconfined switched to using ss (from iproute2), adjust Recommends: - move libapparmor to /usr/lib*/ - drop %if %suse_version checks for 12.x - change several Obsoletes from %version to < 2.9. Those package names weren't used since years, and 2.9 is still a careful choice - include apparmor.service independent of %suse_version - techdoc.pdf is now shipped in upstream tarball to reduce BuildRequires - drop latex2html, texlive-* and w3m BuildRequires - techdoc.txt and techdoc.html not included, drop them from the package - run most of utils/ make check (some tests expect /etc/apparmor.d/ and /sbin/apparmor_parser to exist, skip them) - BuildRequires python3-pyflakes (utils tests) and dejagnu (libapparmor tests) - drop sed'ing python3 into aa-* shebang (upstreamed) - build binutils - aa-exec is now written in C and lives in /usr/bin/, move it to the apparmor_parser package and create a compability symlink in /usr/sbin/ - aa-exec manpage moved to section 1 - aa-enabled is a small new tool to find out if AppArmor is enabled - package new aa_stack_profile(2) manpage- change /etc/apparmor.d/cache symlink to /var/lib/apparmor/cache/. This is part of the root partition (at least with default partitioning) and should be available earlier than /var/cache/apparmor/ (boo#1015249, boo#980081, bsc#1016259) - add dependency on var-lib.mount to apparmor.service as safety net- update to AppArmor 2.10.2 maintenance release - lots of bugfixes and profile updates (including boo#1000201, boo#1009964, boo#1014463) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_2 for details - add aa-unconfined-fix-netstat-call-2.10r3380.diff to fix a regression in aa-unconfined - drop upstream(ed) patches: - changes-since-2.10.1--r3326..3346.diff - changes-since-2.10.1--r3347..3353.diff - libapparmor-fix-import-path.diff (upstream fix is slightly different) - nscd-var-lib.diff - refresh apparmor-abstractions-no-multiline.diff- add nscd-var-lib.diff to allow /var/lib/nscd/ in the nscd profile and abstractions/nameservice (path changed in latest nscd in Tumbleweed)- add changes-since-2.10.1--r3347..3353.diff with upstream changes and fixes in the 2.10 branch, including - allow writing *.qf files (for disk-based buffering) in syslog-ng profile - add several permissions to the dovecot profiles (deb#835826) - add a missing path in the traceroute profile- add changes-since-2.10.1--r3326..3346.diff with upstream changes and fixes since the 2.10.1 release, including - allow dac_override in winbindd profile (boo#990006#c5) - allow mr for /usr/lib*/ldb/*.so in samba abstractions (needed since Samba 4.4.x, boo#990006) - abstractions/nameservice: also support ConnMan-managed resolv.conf - let aa-genprof ask about profiles in extra dir (again) - fix aa-logprof "add hat" endless loop (lp#1538306) - honor 'chown' file events in logparser.py - ignore log file events with a request mask of 'send' or 'receive' because they are actually network events (lp#1577051, lp#1582374) - accept hostname with dots when parsing logs (lp#1453300 comments #1 and #2) - fix python LibAppArmor import failures with swig > 3.0.8 (boo#987607) (libapparmor-fix-import-path.diff) - refresh apparmor-abstractions-no-multiline.diff - drop upstreamed profiles-ping-inet6-r3449.diff - add %check section - runs libapparmor (including swig bindings), parser and profiles tests - add BuildRequires: perl(Locale::gettext) - needed for parser tests- add profiles-ping-inet6-r3449.diff - latest ping also does IPv6 (boo#980596)- update to AppArmor 2.10.1 (2.10 branch r3326): - fix incorrect output of child profile names (apparmor_parser -N) which caused 'rcapparmor reload' to remove child profiles and hats (lp#1551950) - fix a crash in aa-logprof / logparser.py for change_hat log events (lp#1523297) and log events that look like file events, but aren't (lp#1540562, lp#1525119, lp#1466812) - write unix rules when saving a profile (lp#1522938, boo#954104#c3) - several fixes for variable handling in aa-logprof - map c (create) log events to w instead of a - add python to the "no Px rule" list in logprof.conf - let aa-logprof check for duplicate profiles - let aa-status work without the apparmor.fail python module (boo#971917, lp#1480492) - add permissions in several profiles (including boo#948584, boo#948753, boo#954959, boo#954958, boo#971790, boo#964971, boo#921098, boo#923201 and boo#921098#c15). - and many more fixes, see the full changelog at http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_1 - drop upstream(ed) patches: - fix-initscript-aa_log_end_msg.diff - syslog-ng-profile-boo948584.diff - upstream-profile-updates-r3205-3241.diff - refresh patches: - apparmor-abstractions-no-multiline.diff - apparmor-samba-include-permissions-for-shares.diff - drop libapparmor autogen.sh call (broke the build) and remove libtool BR- add syslog-ng-profile-boo948584.diff - add several permissions needed by latest syslog-ng (boo#948584, boo#948753) - add upstream-profile-updates-r3205-3241.diff with several profile updates: - add /usr/share/locale-bundle/** to abstractions/base - allow dnsmask to use /bin/sh (boo#940749) and /bin/dash - allow dovecot imap to read /run/dovecot/mounts - allow avahi-daemon to write to /run/systemd/notify - allow ntpd to read $PATH directory listings (boo#945592, boo#948752) - update dhclient profile - allow skype to read @{PROC}/@{pid}/net/dev (boo#939568) - and some other small updates - drop upstreamed apparmor-winbindd-r3213.diff (included in the upstream-profile-updates patch)- netstat moved to net-tools-deprecated in Tumbleweed (boo#944904)- add apparmor-winbindd-r3213.diff - add missing k permissions for /etc/samba/smbd.tmp/msg/* in winbindd profile (boo#921098 #c15..19)- add fix-initscript-aa_log_end_msg.diff - fixes ugly initscript output (boo#862170)- update to AppArmor 2.10 (trunk r3205) - profile names can now contain variables - improved profile compile time in apparmor_parser - lots of improvements, refactoring and bugfixes in the aa-* tools - new apis for managing and loading profile caches into the kernel in libapparmor - lots of profile updates - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10 for the complete changelog with more details - add new apparmor_private.h and the aa_query_label(2), aa_features(3), aa_kernel_interface(3), aa_policy_cache(3), aa_splitcon(3) manpages to libapparmor-devel - drop apparmor-2.5.1-edirectory-profile patch - it's most probably no longer needed (see boo#621394 for details) - drop upstreamed samba-4.2-profiles.diff - refresh apparmor-samba-include-permissions-for-shares.diff- systemd-rpm-macros and %systemd_requires were at the wrong place, move them to the parser package (boo#931792)- update to AppArmor 2.9.2 (2.9 branch r2911) - lots of bugfixes in the parser and the aa-* tools (including boo#918787) - update dovecot and dnsmasq profiles and several abstractions (including boo#911001) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_2 for the full changelog - remove upstream(ed) patches apparmor-changes-since-2.9.1.diff and apparmor-fix-stl-ostream.diff - replace GPG key with new AppArmor GPG signing key, see https://launchpad.net/apparmor/+announcement/13404- make sure %service_del_postun doesn't call systemctl try-restart (boo#853019, bare systemd edition) - add samba-4.2-profiles.diff: update samba (winbindd and nmb) profiles for samba 4.2 (boo#921098, boo#923201)- only install apparmor.service for openSUSE > 13.2- Add a native systemd unit which *at the moment* only wraps/masks the early boot script.- add apparmor-fix-stl-ostream.diff which fixes odd uses of std::ostream which are not valid. Fixes build with GCC 5- allow lessopen.sh to run /usr/bin/unzip-plain (boo#906858)- add Requires: python3 to python3-apparmor package - readline isn't part of python3-base (boo#917577)- add apparmor-changes-since-2.9.1.diff with upstream fixes since the 2.9.1 release - update logparser.py to support changed syslog format (lp#1399027) - update usr.sbin.dovecot and usr.lib.dovecot.imap{, -login} profiles (lp#1296667) - update the mysqld profile - fix network rule description in apparmor.d(5) manpage - drop upstreamed dnsmasq-profile-fixes.patch - update expired GPG key- update to AppArmor 2.9.1 (2.9 branch r2831) - fix log parsing for 3.16 kernels and syslog-style logs (boo#905368) - several fixes and performance improvements in the aa-* utils - profile updates for dnsmasq (boo#907870), nscd (boo#904620#c14 and bnc#908856), useradd, sendmail, man and passwd - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_1 for full release notes - refresh dnsmasq-profile-fixes.patch- Fix dnsmasq profile to allow executing bash to run the --dhcp-script argument. Also fixed /usr/lib -> /usr/{lib,lib64} to get libvirt leasehealper script to run even on x86_64. dnsmasq-profile-fixes.patch. boo#911001- rename lessopen.sh profile file to usr.bin.lessopen.sh to match the script filename- add apparmor-lessopen-profile.patch: /usr/bin/lessopen.sh needs confinement. bnc#906858- delete cache in apparmor-profiles %post (workaround for bnc#904620#c8 / lp#1392042)- No longer perform gpg validation; osc source_validator does it implicit: + Drop gpg-offline BuildRequires. + No longer execute gpg_verify.- fix bashism in post script- update to AppArmor 2.9.0 (r2759) - change aa-mergeprof to the final commandline syntax - lots of bugfixes in the aa-* tools (bnc#900163, lp#1328707 and several bugs without a formal bugreport) - small additions to gnome, freedesktop.org, ubuntu-browsers.d/java and user-mail abstractions - fix mod_apparmor to not break basic auth - update perl modules to support signal, unix and ptrace rules (bnc#900013) - don't warn about rules not supported by the kernel - fix logging of "audit capability" (lp#1378091) - add support for the "hat" keyword in apparmor.vim - build html version of apparmor.vim manpage again (lp#1366572) - see also http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_0 - update apparmor-abstractions-no-multiline.diff - remove upstreamed apparmor-profiles-ntpd-pid-location.diffh01-ch4d 1694064909 3.0.4-150400.5.9.1apparmorapparmor.vimapparmor-docsaa-teardown.8.htmlapparmor.7.htmlapparmor.cssapparmor.d.5.htmlapparmor.vim.5.htmlapparmor_parser.8.htmlapparmor_xattrs.7.htmltechdoc.pdf/usr/share//usr/share/apparmor//usr/share/doc/packages//usr/share/doc/packages/apparmor-docs/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:30575/SUSE_SLE-15-SP4_Update/509e71de7e3059801e8af2f2d82e38e6-apparmor.SUSE_SLE-15-SP4_Updatedrpmxz5x86_64-suse-linuxdirectoryASCII text, with very long linesXML 1.0 document, ASCII textXML 1.0 document, ASCII text, with very long linesASCII text%Y/'ގutf-8bc141ff7ae09a1486ff3c29dbc806e274a4b2b9f51dd5b6a88bad0b1a851ca69?P7zXZ !t/3 ]"k%{=CQZuǡjע|{9h~Xe8 UC#|܉ı|o%2FkX+.Q^Y1]DN~;#|)1cޜu?~%n(X6&Ru¹ 1g'Zo3D94-nK ѩ4ʟclzm`tC4|,z :wkݽ™O < *dٔu#mPK yM|.+eĿYjfcO[>N5tV:/ʞ 1vx>z;D@ p x97z3N"lvj`UqBڙUˁq<L4ŋMhnqKpb5ɭ'eq3$uH &TEX`}.^gul-:Botg'aĽ)ho\WDW76L74\h=]]<+V\͍(p2B'x f"gq@4ۜÈA,b{vM}%ZI%{8 CKfMmkxBZ7¼-3hʅ{a,~gk{}W☘ /{.4)3EʉogEzX!o7YsDڤ7Eq4ybG)M-Kߔl:^ NV>I&('q~=yG[sk/m3vZFC{HBfFMry`%:Wf6G?qQtT}]:kC$BDWKt _slXM7plP\ĵȉ#u7X4)R`Qņ>Qج6 J3 /%PGW<\ {)EP~WU0]"NQUzY;X$S=3n27%Fs1&jqԞ:7B bߪEdX{FOLKXNsekNj_)Na;3K9k*,%@ܗ_"WaK4>2Sgk\&4_w=ㄟtye8ar DTF>Yv ӐhV|!NظE! U#E(4nGGCe2DRzD BkwC0&ǹ~ZDQ^.ļ:S'=MJ)e m=#+.-1晌vm'+W7rْL*.- dWʡ:՜O<`#z\k5gIvc_E/eâ\.DZ%dvj،n3gޕ7On|W\%)Ւ.`Jh/؝fUX[D ~RBяzy+:{Y$B~1/bb%POmUx}QgVa-lϚcTjTч8K-@5{^s ט[!0Z@j3wfNpqxi4 q9r!KՁ#QYi5̢*moɢuj;k%_ڣ\9wpPZ>$],%@CSԕĻy@H70y8[ASaP>hs #^/7e2$Ts8]-MТ TW2ɣ%.Ԥ$JSIz+m\3/ӳ:) }j΃;HjƗgJ6u0n0%e#M"l(Sr6\_c(6|~O卯v Z'îDvq ~0.uァiR%$PrB;:Rw~<뢇JeOĹ_L6ߒKM͌xbY<婗Eީ?{c(ث+<,Wu"mj$?$j(4 8 ^ ^A?l%si؈f-/mTsvzƋj_0}tS a )je򀂮Cf+UwKpPTJVrg 4@ : ʝ4NhxڛҘoa dE;NtEwE/Cru| Ys9+OvMA΅>`r{P· J㘛u:q=,3d;oע,"[*yks}J?o9EXNPjYUE첛Q_YIyv{tut+sJ כiJ[]; B:gR5LxC%o³S/6QW^`pc9ntg݆w0ҏO$ 0_'ZTOID]7<_61;DME29>[E+|=7^AKs7JWsn>d9cI"_<Y۪ tr@f-s_=5/bCzvNŗYcta`F<ܢ'w9Lح}eWTt#qst{Rc]P#Ѫת} ɫ!VפʌeOoF !?q,0B/־h+xu0 GP0*š2|\ (+ozd"bӼ%Pn\"YnXJx`jh\ Gm \w3qWkGQ8JڳԯLv3uW@iEEd+[w'|np\6Y[} lKۤ T{]pńpBI;L&̭9Ju=O\-#L6,N?a@A'0Nv^yU!;\YoumY&όw8wͳ)`Y*CwHĎ* 5lf {iCޡ f*,g`rY ǿS-xWUu⮐*F/<[cNKa=߀+3XFmyG$. T<(*($=#ٰM=)6=~p]R=9t|a vۧ'5Ջ6{K"G&eG~r/BP@8M{AzۤcIa8&thkCxxMP`Cf^wF,& bcT`ҋ9VY\),(%{ʲ̲D돺@_&Hmr.*?x#3? Jlmь}#v݋@Sjsn 6vBI#$ǰh+Թĉel)`Έ)GڙV3E n:bTbǏđor(.AqKTm|`7,!ƍD΁k{,"qˠ0 薮 .[*r+`t@ 3um@t krf X~%|E0T2:S4G#~O8Ov -O%: |c!^^&VaL#B|DXmAsMQfz2ƷwUfpS7)xZg5sK>;T!`,\uq5CIaⱙ^CUFYB^Q%ZLt{'@0AOeZKm\ "aBHi%QLQu־aIzIKF <gx!6(~Hm)Pnt@vBKQUΏlQ4k.okԥmɽ1" ؼkI%O@Ȍ߉asʢm`8!$)'f^OW; PaQ1-8i,)_#=}9irXcJ}1xV Z&JW'S&Y'lxf%K9(ΕfgsX-kS7Zmp5nbxo&2BQlj-<7AW3.Α{r9ȿk]:Mgyڑ74G<? I[SרȩLJMU @4ABl[9+?/x>2'LۺmSm0Эs`'913F+xpaZ-ZsyTV3gW,`ϫ5 YG;: 㓧MXɿJw~Cms9u$]duzu!Y$Er{.pP˝~>]~ ҵg ^TQ=hG8/٘idH?ԬsF0Pd}H5Q :|9ښG@65H|yjCX+SIK?̵^ @0e3 2Wl|zTgp>hM@&wȨǖ]uE)P4~rެ.EtJ&'PI2H~s2TwGKQS!B%45 |RАV"/1 ]l $0EzKam?qF'a"sܬLڤ: Kx([R7 X)cێ [#l<d⽓|;ls8BMdmϔmg:ĠB7e2E?>]Lk*Ej*M`waV.|y=H#65xytlttxtFDv0\''dt nkX| t7vV4$iOH.h!f }*խd`O Tt_<ʋmYݬHճ*~6 ~nN<.g/9o5Ϧwz)tO/Czy.R@x,5S[<4~S5]Ԥ;VB{TP/̉shۯ8̫ʈuK@QagnI7/|?^:N0dJ6in<+=-* Rr+?Dk-x&hݑ̕ ȄVU( x72WB8Ncd/Ok@\ʻ]1Jjӹ 1M o]5P"vNSϛft8 *֫h7y 21\Q8Hc^*'F.ԇYw(3mZ$r5+e^ņsU?"PDˇ켑M{^Bv\.ۂ-4@( IwGН~Ιk0\X%W}$Q= jb ^. I9 p*s\"i^]!Ih>m+o]#%84ٓua:莴XE4%190%E&!X}VIE^!|0PqHQICɊ^ Tei\4 ֥SUy[:*ȟV+\y ]JUYSF[MK䣊zI=H mRD9aI_PSݛ7x> -*y$D\ܵ4ļc>+Yq-/y#]afQv]-\90@CmtVEYc_tSfz%=E5٧$X^Z*|qpi:װVilpyAuW6%'29J>I4%H^i/R*h)H[BhhvӁ\O׼KAv=A|WCN.fVlciGi8f-ds(F,TȈb\z\&̎'8,[yM,<) 9c| &L̕Ӟ#d- \ ܃!,[<_,Zm&aJ/M-t'd49BٹBcW +[ݒZ*_25inzS_3HvJAI0&L  UVq{P۫Tdm} ]$:Y̍J1΂m;S'[xT'k "^B<4p QV6rFg7<3LS 0u}ELiLR tO1VίELm6479-dҌKK([ř>~lhU  dnOƔ];LaLPIr 'y֎$0@2X[G';TڼcRt$DCgCBSv^f4ȶ} TCEpb7G7 Ufs#S%;>GzVY'7Ӕv$IlR{+e u '-$b[7ڰnzQ]g;X!bhA7u敏ݥOdO^?SȒGax<(7c9\7}4"]nbJ1Q}F9J#yxhh D`w”<Ә2g U ;1ٙxՆRo:$XA\`4O%'() d/O@WS!um.ۭ@m;T] .ev2N%$Am.5ѯ ?EB~yl{7.3fC -$.r~S tJD,#2H]MD?;֟-BV92(RryY17\bDžĹ&+7q)qN?0YɴSf_nwX;zZ!8*m4OkvJ]#%;^J2vM\r=~3AeY@^E<D&]A،#C/ZTΔZ#dhrÇ'-R)ҏ,g·$xtWET3BwA V6y|@IGy!cѺeSq*OLwx_2AۧaBT n|GŒ]7Za1SJ_rwB0x] sWudE W Ƃ s]>77=VldX pd_֭Q?eYA6؏qzXluVWpKݿۖM)\>ZgE֑k/ Gs a޷_ O`g!\dYZNws'f` Y(BBf][nvSȫBMtQpGa"< *|&\')f9 3OY\d\{:c3i+BgZEI&|@?tiA*76pm>D8[Ќl{'џp*ѳcccρ5R~ 2˛ ؖ髊HKRX\ dPW՚XS\!'p=]fXNQd][N-mLjcżE SfO%fh|lI\:1(~+HR!U4xߗ>Neޘ%f/S@dTHa$1ל=9<G6^OS*Q(<7*#58Ylv,}դz=8]~'À A-joJ U^3Fd)L9}gVA< ^;tl@J􂵘mثY76 &ZT"H,#.G+S`0< bަA[T }yxue_S=="A'حŶ:ܱ4.L4x\DCtMe%Yk@#ە>J=m/vF၆CBG("i3yibJ&1" |M$:ɻ02iJ[B).(WŐgmc0Zte5aOhs,2mUjQ5|pW-̈ Xm PEM3hE,g:@Og'ޯ$"͑Cٱ+Q95'B&VȢhD{15Fx\歠*Ol d}1D|tIPʭ"AIHw?i.zTHV3!u4N/PY=P5ֺs9m΢㋨H 2f{[+:CnbNZ㣥[3$z empV_S )W'1åWHmӸRzwy"+)1:T#TCjHI_k)UAST/%R`v8dYnV'<dp̟7=mA Z&w,-M =Aѹv8W͎)l`l|J)_e@ު; } ޫ5]\RٿSA|^zCvf&%W"j( */b`םb KiZ`;Q"*ye}d9mAfjyr]ᏉL~:θc)ƯQkAPǣgX (?Q7֌l j3J+E܅ت͹WU.t/g\W}fy-]]⿸dn, ~]{m|-OKƋ]*S5*Mdj&N1cp&4  "иނu c9_BlKU,z͛N19;Ǘ{!a^+OSN37+f)*,H,k*\ѝ܇: V͌d乓 J1-6{2t*`sBFɩl[ kp'.4Ymm{c̱K"e:G z/Z薽=729T,|נ FהoBM?]rgݡwcl4?*62Ra;Z"m Z>m|وxa[">$*R.+fHp26D")ƬiSMy_-'Y%/CM,8q-3@8wĕ7lHm\%&u٪W !̯Ø p*<ι>)0d*^)'(@-o(l؇#( ^ޖ0^>b*C~w lQ\=źf* כ͘@'36x>c4f #颴,s=G0-~L8)d!7j1+O$? r$N|bgw ϲRqf~UzM 4cpޔnQju@VG&yh&'WO; N,`kGr5O4֌C[ئG|G! wSӸӎr osr& Ͱ^S7R\x a"M8NRbш  h%> SN$(8%Ctʯ WUM0cvL 11bg(<4K-a(oJn()%ŅR\AA:i4s\!a!c> 8TI1Ŏq Hv2h2TX8>aTv$z .ls7ґT"|qyDsGD5R1fqɍupih-b-<_6&=$?C3o0%eepiz=/_Dd+D!^TDy\ؿklϞa,n9}^, .6T&@[h 2b#ՖiIF.A+P09qמLߏ_I^IC1J 70d'2KԢ;`%\. 4sFeB +Klp5#pwn2IR'=d? QN7axP@5PKGm>b8Kt-41"2[>_po; yE{4@RWϩ,'Vk6"D%h~e$awO3T$!XMUxł*PY]BB)<@=&%" y&wv^u@slqAP\VXzRe`/R[A̖G~T4_) `qJ+ٷ@MYE{fa`[,k a wVF 1yu ax#qw [8"а{66w8jRwC~GXi6㐬 tA9{G4EFt⤊/'>vbWu_2mNs pU1 &E% W]7/sY9$'qC1E>%gH'#f$`q@۔qҡ3Z73v;whüvXO@mfGY\FHdFerO e{%h簢egKFN`rIڝ{B*"eE[zfC>[(jyZ׈W,+xT):_}w5#hăU}\şLdowl bb=}MM&>!I|eڤXE&ٝ|B龩-ݠ/rѿ |O|³=*`V;:L7K5] 4_g07B"ZN +k7IR2U*fZ';J!RRY)\*4ܭ J*"{YbTULgHv4Y 94c#lb$Լ"~ ݎL |$@ et+by'Ҡ{} ֍]cHeÓh;"F1- PۯZ70׿fFS'0~29H(O*qj2A*ȼdyXhX,>95pnPn T`_;bt1C'#e+>[(d\'5/=qP 9k@k\=v:?pyC' Q~? !t JU;D BW.^F oaM=_v-_^I Ld3TFWyfKP! _~k~K<ދR'Ga)cQɓr3P={;\;<(lQ65v>#~p=s4=Ŝ*+x̝V2x#o4]iOܯNECڋi`JQlZtkQp!I)!Na%B kbj :Za</=4reKq·R4@svP)B!36kZw9 lHDpE6M1Mx96,Iw< CIiTִ8:~s?+Hs{@X8({:v| |Y\{BI324$L? oD~OHcsNBKu!DF)}}wn=JZ $Փ!ΕcV {3Z_olL{xook$VOSN=.ؐha>'o8]>s `A.#U W5] P^IU,>Φ&4 JH&|3YQs7. BI'ytq e2Q=n7>'&(%Ž>313MG4zc}ߊi3,1yMyaJVGHG8-k5G_4cRݬag"Xd!N磰>(B4lV&%f $ .9DSX^m %G _λIif$R膪5PvSSiBtK]6BZVz} _"< =9Zʓ(sS4ebS٪kn<|!|-+0Y#@iACeCCjj[q wc$ѬWm8?P bϑΥe fYEÊ"Щzh̏r8Owzoc-s!b+Bo<"{Œڏͨk7$lRwVx=BNsO =[x8;/U4~o]H xeЂ'B\Vޝ:9=uQq儤  ץW~`G]Aoѵ@0$c?^6pu`J+|w?N8O\^vq iQ`/ j?Kn~<@Iv&#k)z 8ڠpl•C pis˫|٠@Pi X3hzdtdq;n~y3%x ~TfR0QMѢ9qWit}\pP]1,'"T_ˈ^j0Qp|eiEeEOYZ'6w2fA [^ԨkF&8Pe \O ~?n/oU1(.GFf&4цX/n|t:V3LĭXBьG_W6UK΀'υr֪mag4XCc!d.>.ǏN0sEOJQKAdti 'k謜`2 ;\%kͪxHJ؞ ~87aϿXUns4YjIk 4;J`|PhTgFtĴUڇlZ[ 6 Bry Vvuj$뿟Lx{Kğ;Ӷ+e' kpA%;"^b i s {:;6v_"Lۥ*9&׻l@6y>VgT5&efe.U1{Eu㳑wTxY:o_iصoBe:ᑘۺ!=MfoU?tۣ1me-qM=}rArQ߳bx 0Rc(O[䫂OT02r?0zI|1wˠ"X Z?)HKTy(_b:m`jZ9rl$\[ ? îdyw:qa:_ʔ窞~[wbnwa2K! *8¥P3+*lwҚC`q|&ĊǶ4<~x+:oěNtaN,#: +?x16 T|e]o}[0&+Յ%ij. 8i+oQ] &'~mElHNO#ƊpW,8]nPMhdPc;^ox>.d&Z$4UxR,FZp?4xd Q44dvW,n ,o-KQ8x,wt7D zELʱ +g jU܈.&yT}=XɅzd?2"2N V`B?+5QdosGZ\?Srt?A?W =.PqdSu {'1b$`d@{=.ěh#΢i~117b)={]׵ń*17OY~3O@J>%2rvQ!A{q> P#8uwr8Ѧ/tl^:c=[-z[mzAg)BxE>[ X:>׉FP\V}-t@,JH+5~\CRuA7VF _kȟ&H!6bbg᮴IE0ɋSV72j Q JŠ^h}D {]7h*9Yn8rԾSbV [jwUp)NQk܍RN==Zr6`T8ѽvĬ[ b}:k(Z^((ak>;TIӟNH{ɁqT"+i^klLJ_頊Hy|@޻G04W@mA׍GoyHU\V7C3- LUD0] XB TEH_1TK yCf'mM)rE.dIi%Yn;dJĶwPxMlA/ppF5r>if9ا^C)^: >p3̿3({bo N==g,MK_jO`糞vZ7RQ=I\ hlbL }`|@˨}C{e+y‰ϊCA> q^R׿;_(Dg 6)q :P]DHxpI%tO1ynG>\n:YkA bf)_k~ZYCͪc[C@SeHOCb]d!?rbnb,΅_ ;'^6_B'nӢkNwwpZ4h2X̾"UV?G.9Cu#3߼[Upb1 Py4mѳkhԂ0X' tA!*F'žFEC@܎,Qd/5ڶ` %#}-@e/Cp녓I&䮠ue{Ec#,zUbW&u--sx `(dU;!w R1?d'FRtR"wO628}J==,=PXyyc"vc5!&51b,^Av%>j- 5^s  pkH_/%Ѩ"ch)>#S#PW8l CSBAʯkqxP.7ZopvV+PiJmGܖS^Ϥ {ݹy2Nc"JCQ7tVS!DtsFj]< b3 'f/`{ݶdJH1]S?'m.2U֒ AXy 0G)hXE!g)ad$s&A\9bq{Iz4'Zka=W 2!޲K\mگ:2'݃SޟJH#B `[&}/^k[3׫L3̤7jv(,pՀm=w0ώq]P7MSq֗.Q_Sz㡶h;+ڝhE)u(MSP\ͪ mѭ0"3(s 4M߲)c2aKl\pen?){A@ }=7[LgLkB|f7F= >J'JK ZuɄ/RYbk=e_ŏN!MvH*KS\ը\ sgtrGYrxknSӴ^xo(נzF l[M4dN\&M\뱦^zߍֈn\p\';CohHպRi0SP[[ 0Pk\ 5@ҥ{zLw;VcF5u%+qA2t(^ԯ5ea>=>(C VAi,c1n"+TzϥWI|÷5==%;QI:$%SFUirҰigޮh%5'}x3t^C \ ކёEWygj/n*)N?nGzyRJ=Gfr2-slK٠o|7~Y lq ){ :-;PU$s3|~8h>z2#SF?zZ2h63z:i/OYBc((f䚩O2'FF=^|Yecl4[!%w$:+%q(s0x7nߣCWAToX .ַ4eCת-A*e;_GYPrD.!)2|9Ί5mN2U~TNb+=^-vknRp%a43tkNGgbК:hY㳮`rfĭKuF~SUGiIgܗ 9uP'}X ׫G9Y׺tZ(݂9I UGgqwsT[+tf䐩.[B`#&jۼ VRAru'C;eazLY`lzn$}X*#|u9q,ANݒt~KBT @b F2C <^OPe9(ul}m ʑMT0^/JKo|lX[EJ+I]b߮CډxOw|٘J(;paN<͹oer5EG9{c$$X*f.zj(˔ISHЧfN_nS*wKD% =ʑj9@-n#,N4~ƌS 1wsWH|Pᵶr!l ?E]xTBFg  a 0x+d6btbJW6`3B?D5V65q͒iKpC(tiLyȣJ =4c˔me$B z - US .^ t64r5Aà?#/*僵F30F;Q_65eESe X)tTh{}ݫ,5rR' 00g`g8]7Eg_)*O j"xe>b窳袄bLD?;J~|>P x'”=lw;Ոi m9M TC9ׇI1<0Ȣ͖&h*՜:?Y!$$'kpfMB*_|iD첄Y)+ Z.Rv-`ЉT8I\4ӢlkZDN𹡪g7(3í DnyG1 7CS!djd嚬LjKo,ػtĂrF39-suX-X;=d< H>/A !-A*s%,]_<0ÀDlR/EuATP#V`'I&ѫZ:x;hF^u Q3M)*韚n, z5 n0=Q6h%Yki J¿x~1<+J|d b* ,k/ӑm H"d\\ IɈ >~ .": f6N"<gkL9[stV.?J/kJȴ. Ätl 2Q2~"u:79UA BT6WH Jm_5 w{λ@D.Hl(zG-@ mGcfj"eu2,MK7|͑%#q+uAaB? I n"S-y:uzيr{\N>0<`E~lGPPACɹZ %^me4ݏ$~ o))IPw@bb@-zu`t$)yx[gʮ.!4i<}1Wwa"n g̶ZTVjמJwt8a5v?ԶPt-fCbWrF9"t GK ?Ǧi!ycL剆e˿gl=HT W~ Q9-wH_mЊP ^8 p%gdŶX@fWaW+pN(KJV Xx\֯7:jɶ۝ Ε] +rn Sx0Vy#.H~Xm;q^)X&/R7۬vnR0@&:8!T|DIɌ>'`w+jEjW&(,;A|XPCT# Em:vӺfJMI@xMZ ;w|13bV.rxW>1%XQ:U֒Hu^nr˪=$@~2{\"Oby0bjʖ!TvWXy͒bAtKڱ<]㟋=`y(푖^ï+A 5b2hM0]ͪЬUS2xCЩFm+YSnN7P/6)XRqaH+6}C%b!zvq">>"w(~ X6}pz;tK wB<;7cf읳"V \Óuݜ.g) wl 5u|. 4J|V}F{>J0}X@QҌ!J>{K | ,_( #ص9\ʫ?G^&rF\ҞO 3<ڶ%Sjhf(Lk.Fe䊻pze~r:>vw/1%jAwj 1w)zu#O,i8{[d9Zo{"Vʔ]% Ż.iIl,S ld^NKNy힥%F_=^ƝSN]yT`}#[R5Jecwgq:?vnTsaf5ClJrD x#~. R騪X(o`k?<ׯJMs>H|)-BW80h_1=5`-D8^Ի'>HPm@FE@a'Ϸd$j]Ĕy`H]VC~l"C-%n64; bt8Z, /XI`]4ׄjc'B7 [:5_{|_2'>P~CH)mH:BTT5c葀E^& Y={6]_y >.T| Xi1\1k UF|v򧱍.}("V&}ûY$-#C/#&z&ؓSý{A", '4BX]e 8gt'h)9⅛ZPwݍHoR9#ʯ*5D@WHqۘA,:MD “gSxs뱨2Ѽr"՗ۣ":#98ۃK{N|=my#%σ_ϥ-KЀܬ5yɡb ΂V-(!ӦFIsMr(R6@cϫiD"C~fj73/pدpW,I]/NjH9oH*']We WBrryP I&|Pc^Kߜ8ѯ]vY74%/Eq]b&%IjUVe#h4 (w]r{PN%fni{┎yF^ӹ=Sve !"V㢉 N%`o,Z[_n=&A.)<> >h"p3-S  ֢|AZd[!z9>ֆAfsGIU1 LR .[d޴,ITv+-%VJݵ+% .%ݿA]e{:_ըIEv$m&GO)GHJR> u".LmTˆoȦ[ Nvsh;yM(#UEiTйcNFzZKdGNU&|tWZ 4Yه B&u!!N(7͟)V͞oiK'6DIu&mgp .8x^VmXz=DEulP] 8iA*TO^ F7 jcFDilA~fqv%[SWE΍WrʠH=8/^ΐBq1LڈUM5d0Ԋ#uso9F\5u-I]ڔ7|Է@T29J=<[2\GEOweb(݋چ|ykLƅL}WFTpvyyU,xT۝}됆I`P[Qegt.qtVTHI67MUt h5P0[|9Z|ݮ7Fիe=Ż v*.-ⓧ$ezD';(4w Yb4=$ݐZuTtu W;Iٞ^·-?TQ5&.f&f\BUuf]P[Vђ)[xcVXB oyĞ}$jQr0]~JeC&$P^32\L3wYIn9#;k=/Wϙqtj@2'7˭] IhQ=As)WpZ]mB 9ɱ.ʲ>O~yQG :@h **A6UC4k,$7茶yD %~ILYltp#(KTRݖioHO<ɻnH\H@C~6O$!ɏraq`a)?yIna- \1)'Ug41wn%Sc r+H)sXa>'^~&zFE-a%9[[ek1cq4SٕCнU\&k}Bq:NLfȟޠ"5zsP@%C#[Aum.?݋سTfoG}m&0hòCoTH/gDhs+ƸȷIU:Lj :i=PuPr(GDu|%i#: =ý}uC5Vx# ҢEc3%~!=qA5*&A>uO͝H\ħ J$3\d 6xH'?I|۵C4΂H`E6n6I( ^k64DkfeEiV8轀c'$a U1rI5jȩn` ۿANMF=X˰]8yJ77c Ɖ/zY0֦D}{Ϲ[>?+^"b=90uMCd䯞uAʛr y ;*&wkUWsq*ɟ@|utk-܄R.vQ2Ø ى_%͝0+ɰbOdlG/E7p@EGf{Z[!^g`E3oR:;M8G=NM}Y?(=5ز.h 1j Ĕ*HL2lRHYrfι ivf,':`57u~ ?yHjG?J&~wx~kԼomU1N?vPw!!pHz4l1lɄ9/[:3kcd$hXB]ϥc֭-#ng%s30^?M.j&@7@A6_8QrMQ<܎Y1k $k9ld8觕}葢 lQiF'IԤrVfwA]A%.##;͈}X5B k!ݪ~y,ÈoџE\ px2?tॸ#yѡ:ì2<,, G0 Vv| }׆X X}(~ȻtSQ+,/gBɦ)VfX]&"KN=b_1oMЁ%' T1$R ڔn,ɫ2,-pskvзE|N5kZHo;6R?N`Sqwc`lk !>;dChj{Wujv),Y땱hϵa]K.蔴bt49Bɬ9ˊ_Qc܍S8S/XZ !Fm<ľ, ZGƶxmYS?Ԗ<R [o=( eZ"2aNqSn>. <SvS߰&q<ԯb i-KYإ[;1klA6}$bu3wE4*$bR\ѿz' dK82n$Qϖs 7(,s'pU]\2`)t4.R1s"$ }DzxRFQk9L:pXl;N(<̺*АT06f̢6\QM zbbϣcT-ʏ_)ضg0 ܶ YZ