libapparmor-devel-2.10.4-19.1<>,\Ij⸋/=„rKwK>@TR?f|)WVlh\%"xv:9 ?d  R #BHP     88(8 9:0FHG\HIXY\]T^dbcdef"l$u8vxwlxzClibapparmor-devel2.10.419.1Development headers and libraries for libapparmorThese libraries are needed for developing software that makes use of the AppArmor API.\Ijlamb19)openSUSE Leap 42.3openSUSELGPL-2.1-or-laterhttp://bugs.opensuse.orgDevelopment/Libraries/C and C++https://launchpad.net/apparmorlinuxx86_64DBK "   4 A큤\Ih=\Ih=\Ih=\Ih=\Ih=\Ih=\Ih=\Ih=\Ih=\Ih=\Ih=\IhE\Ih=\Ih=\Ih=\Ih=8f488587f289913c269505338ec7aabe7575886941f3015b93b1cea16c54a78a94d339e973197d18adc44389bbd353540c91984b88080eb34fd840ebd2473f1c1c3146b9c572ecf2fc402ae64b66067a42ee61c531c4ab62e0f2628424b13ae6b4b66c529e77e3e870fbcd97750cee42724d2a57d0380e91c4ca5065cd0bff878fcc11ed758b5f07aef66b49785369a922ffabf48daece0d6e8a893b9ee6b9e6cbab5e5705ed7ce6cd23c9f1aa1de4a71eea4ec2ecd2799ae598d954814e1f3376f8dba52c2a53ed1af281f3ea6e3939libapparmor.so.1.3.1aa_change_hat.2.gzrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootapparmor-2.10.4-19.1.src.rpmlibapparmor-devellibapparmor-devel(x86-64)libapparmor:/usr/include/sys/apparmor.h   libapparmor1rpmlib(CompressedFileNames)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsLzma)2.10.43.0.4-14.0-14.4.6-14.11.2\,[EYX׭@XX*XAXAXtX @Ww@W/@WDB@W@V @Ue@UU@UU~@U:0@U0U*^@UTgT!TܕTC@T6TT@T5ThTeT_W@TBV@T7@T2@T12T'@T @T TT@S@S/S@SES@S\S:@S5d@S*@SRRR۾@R@RR;R@Rt@RpRcR].@RH@R<8R6R2@R1RNR@R R QQQvwQZ@Q5@Q @PP@P@PaP\VP#@P`@Pw@O@O@O O@O O@O~O3@O'ON@NNN@N@NNNN@Ns:@NoENg\NRDN98@N7N7N"N|@NM@M2@M@M~@M~@MlMfH@Mc@M>@M>@M=iM=iM=iM<@M<@M9u@M5M,F@M,F@M*M%M@ME@L!L!L8L8L8L8L8L@L L+@L@L@LwChristian Boltz suse-beta@cboltz.desuse-beta@cboltz.desuse-beta@cboltz.desuse-beta@cboltz.desuse-beta@cboltz.desuse-beta@cboltz.desuse-beta@cboltz.desuse-beta@cboltz.desuse-beta@cboltz.desuse-beta@cboltz.desuse-beta@cboltz.desuse-beta@cboltz.desuse-beta@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.decrrodriguez@opensuse.orgrguenther@suse.comopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.decbosdonnat@suse.comopensuse@cboltz.demeissner@suse.comopensuse@cboltz.dedimstar@opensuse.orgLed opensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.dejfehlig@suse.comopensuse@cboltz.dedimstar@opensuse.orgjeffm@suse.comddiss@suse.comchris@computersalat.dechris@computersalat.delmuelle@suse.comlmuelle@suse.comopensuse@cboltz.deopensuse@cboltz.decoolo@suse.comopensuse@cboltz.deopensuse@cboltz.dedevelop7@develop7.infoopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deseife+obs@b1-systems.comopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.dekkaempf@suse.comcoolo@suse.comopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.dejengelh@inai.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.decoolo@suse.comopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.dewerner@suse.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.demszeredi@suse.czopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.demeissner@suse.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.deopensuse@cboltz.decoolo@suse.comopensuse@cboltz.deopensuse@cboltz.dejfehlig@suse.comopensuse@cboltz.dejeffm@suse.dejeffm@suse.defcrozat@suse.comandrea.turrini@gmail.comjeffm@suse.decoolo@novell.comopensuse@cboltz.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.derhafer@suse.dejeffm@suse.debwiedemann@novell.comjeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.decoolo@novell.comjeffm@suse.dejeffm@suse.dejeffm@suse.derhafer@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.deczanik@balabit.hujeffm@suse.dejeffm@suse.dejeffm@suse.dejeffm@suse.de- update to AppArmor 2.10.4 - parser: make sure cache write failure doesn't cause load failure - parser: disable cache write on read-only filesystems - add support for conditional includes ("include if exists") - ignore "abi" rules in parser and tools (instead of erroring out) - tools: fix writing alias and "link subset" rules - remove group restriction in aa-notify (boo#1100779) - ignore *.orig and *.rej files when loading profiles - several bugfixes - profile updates for samba (including boo#1092099), netstat, ntpd, syslog-ng, mlmmj-sub, postalias and dovecot - abstraction updates: audio, base, gnupg, kde, nameservice, nvidia, php, python, ssl_certs/keys (add letsencrypt and dehydrated paths), X - add vulkan, qtf and qt5-compose-cache abstractions - tunables: add @{uid} and @{uids} kernel var placeholders - see https://gitlab.com/apparmor/apparmor/wikis/Release_Notes_2.10.4 for the detailed upstream changelog - remove upstreamed patches: - nameservice-libtirpc.diff - add apparmor-nameservice-resolv-conf-link.patch - allow netconfig to write resolv.conf to /run with link to /etc (fate#325872, boo#1097370) - add fix-parser-abi-crash.diff to fix a parser crash on invalid abi rules- add sssd-mcpath.diff to adjust sssd paths in abstractions/nameservice- update to AppArmor 2.10.3 changes since grabbing the last upstream patch: - add permissions to the dovecot, traceroute, samba and postfix profiles and several abstractions (including lp#1650827 and boo#1057900) - some fixes in the aa-* tools - fix downgrading/converting of 'unix' rules to 'network unix' rules in apparmor_parser (boo#1061195) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_3 for upstream changelog - drop upstream patches: - aa-unconfined-fix-netstat-call-2.10r3380.diff - profile-updates-2.10r3381..3384.diff - upstream-changes-2.10-r3385..3390.diff - add nameservice-libtirpc.diff to fix NIS/YP logins (boo#1062244)- add upstream-changes-2.10-r3385..3390.diff: - preserve unknown profiles when reloading apparmor.service (CVE-2017-6507, lp#1668892, boo#1029696) - add aa-remove-unknown utility to unload unknown profiles (lp#1668892) - remove deprecated re.LOCALE flag in Python UI as it was dropped from Python 3.6 (lp#1661766) - fix a crash in aa-logprof on specific change_hat events - migration to apparmor.service turned out to accidently disable AppArmor. Add a workaround to fix this (boo#1017260 starting at #c7) Note: This will re-enable AppArmor if it was disabled by the last update. You'll need to "rcapparmor reload" to actually load the profiles, and then check aa-status for programs that need to be restarted to apply the profiles. - add var.mount dependeny to apparmor.service (boo#1016259#c34)- Recommend net-tools instead of net-tools-deprecated for 42.x (boo#1022963)- add profile-updates-2.10r3381..3384.diff with updates for abstractions/base, abstractions/apache2-common and dovecot profiles- package apparmor.service also in Leap where it was missing thanks to a wrong/outdated if statement (boo#1017260) Note: If you manually disabled AppArmor, this change will re-enable it.- change /etc/apparmor.d/cache symlink to /var/lib/apparmor/cache/. This is part of the root partition (at least with default partitioning) and should be available earlier than /var/cache/apparmor/ (boo#1015249, boo#980081, bsc#1016259) - add dependency on var-lib.mount to apparmor.service as safety net- update to AppArmor 2.10.2 maintenance release - lots of bugfixes and profile updates (including boo#1000201, boo#1009964, boo#1014463) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_2 for details - add aa-unconfined-fix-netstat-call-2.10r3380.diff to fix a regression in aa-unconfined - drop upstream(ed) patches: - changes-since-2.10.1--r3326..3346.diff - changes-since-2.10.1--r3347..3353.diff - libapparmor-fix-import-path.diff (upstream fix is slightly different) - nscd-var-lib.diff - refresh apparmor-abstractions-no-multiline.diff- add nscd-var-lib.diff to allow /var/lib/nscd/ in the nscd profile and abstractions/nameservice (path changed in latest nscd in Tumbleweed)- add changes-since-2.10.1--r3347..3353.diff with upstream changes and fixes in the 2.10 branch, including - allow writing *.qf files (for disk-based buffering) in syslog-ng profile - add several permissions to the dovecot profiles (deb#835826) - add a missing path in the traceroute profile- add changes-since-2.10.1--r3326..3346.diff with upstream changes and fixes since the 2.10.1 release, including - allow dac_override in winbindd profile (boo#990006#c5) - allow mr for /usr/lib*/ldb/*.so in samba abstractions (needed since Samba 4.4.x, boo#990006) - abstractions/nameservice: also support ConnMan-managed resolv.conf - let aa-genprof ask about profiles in extra dir (again) - fix aa-logprof "add hat" endless loop (lp#1538306) - honor 'chown' file events in logparser.py - ignore log file events with a request mask of 'send' or 'receive' because they are actually network events (lp#1577051, lp#1582374) - accept hostname with dots when parsing logs (lp#1453300 comments #1 and #2) - fix python LibAppArmor import failures with swig > 3.0.8 (boo#987607) (libapparmor-fix-import-path.diff) - refresh apparmor-abstractions-no-multiline.diff - drop upstreamed profiles-ping-inet6-r3449.diff - add %check section - runs libapparmor (including swig bindings), parser and profiles tests - add BuildRequires: perl(Locale::gettext) - needed for parser tests- add profiles-ping-inet6-r3449.diff - latest ping also does IPv6 (boo#980596)- update to AppArmor 2.10.1 (2.10 branch r3326): - fix incorrect output of child profile names (apparmor_parser -N) which caused 'rcapparmor reload' to remove child profiles and hats (lp#1551950) - fix a crash in aa-logprof / logparser.py for change_hat log events (lp#1523297) and log events that look like file events, but aren't (lp#1540562, lp#1525119, lp#1466812) - write unix rules when saving a profile (lp#1522938, boo#954104#c3) - several fixes for variable handling in aa-logprof - map c (create) log events to w instead of a - add python to the "no Px rule" list in logprof.conf - let aa-logprof check for duplicate profiles - let aa-status work without the apparmor.fail python module (boo#971917, lp#1480492) - add permissions in several profiles (including boo#948584, boo#948753, boo#954959, boo#954958, boo#971790, boo#964971, boo#921098, boo#923201 and boo#921098#c15). - and many more fixes, see the full changelog at http://wiki.apparmor.net/index.php/ReleaseNotes_2_10_1 - drop upstream(ed) patches: - fix-initscript-aa_log_end_msg.diff - syslog-ng-profile-boo948584.diff - upstream-profile-updates-r3205-3241.diff - refresh patches: - apparmor-abstractions-no-multiline.diff - apparmor-samba-include-permissions-for-shares.diff - drop libapparmor autogen.sh call (broke the build) and remove libtool BR- add syslog-ng-profile-boo948584.diff - add several permissions needed by latest syslog-ng (boo#948584, boo#948753) - add upstream-profile-updates-r3205-3241.diff with several profile updates: - add /usr/share/locale-bundle/** to abstractions/base - allow dnsmask to use /bin/sh (boo#940749) and /bin/dash - allow dovecot imap to read /run/dovecot/mounts - allow avahi-daemon to write to /run/systemd/notify - allow ntpd to read $PATH directory listings (boo#945592, boo#948752) - update dhclient profile - allow skype to read @{PROC}/@{pid}/net/dev (boo#939568) - and some other small updates - drop upstreamed apparmor-winbindd-r3213.diff (included in the upstream-profile-updates patch)- netstat moved to net-tools-deprecated in Tumbleweed (boo#944904)- add apparmor-winbindd-r3213.diff - add missing k permissions for /etc/samba/smbd.tmp/msg/* in winbindd profile (boo#921098 #c15..19)- add fix-initscript-aa_log_end_msg.diff - fixes ugly initscript output (boo#862170)- update to AppArmor 2.10 (trunk r3205) - profile names can now contain variables - improved profile compile time in apparmor_parser - lots of improvements, refactoring and bugfixes in the aa-* tools - new apis for managing and loading profile caches into the kernel in libapparmor - lots of profile updates - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_10 for the complete changelog with more details - add new apparmor_private.h and the aa_query_label(2), aa_features(3), aa_kernel_interface(3), aa_policy_cache(3), aa_splitcon(3) manpages to libapparmor-devel - drop apparmor-2.5.1-edirectory-profile patch - it's most probably no longer needed (see boo#621394 for details) - drop upstreamed samba-4.2-profiles.diff - refresh apparmor-samba-include-permissions-for-shares.diff- systemd-rpm-macros and %systemd_requires were at the wrong place, move them to the parser package (boo#931792)- update to AppArmor 2.9.2 (2.9 branch r2911) - lots of bugfixes in the parser and the aa-* tools (including boo#918787) - update dovecot and dnsmasq profiles and several abstractions (including boo#911001) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_2 for the full changelog - remove upstream(ed) patches apparmor-changes-since-2.9.1.diff and apparmor-fix-stl-ostream.diff - replace GPG key with new AppArmor GPG signing key, see https://launchpad.net/apparmor/+announcement/13404- make sure %service_del_postun doesn't call systemctl try-restart (boo#853019, bare systemd edition) - add samba-4.2-profiles.diff: update samba (winbindd and nmb) profiles for samba 4.2 (boo#921098, boo#923201)- only install apparmor.service for openSUSE > 13.2- Add a native systemd unit which *at the moment* only wraps/masks the early boot script.- add apparmor-fix-stl-ostream.diff which fixes odd uses of std::ostream which are not valid. Fixes build with GCC 5- allow lessopen.sh to run /usr/bin/unzip-plain (boo#906858)- add Requires: python3 to python3-apparmor package - readline isn't part of python3-base (boo#917577)- add apparmor-changes-since-2.9.1.diff with upstream fixes since the 2.9.1 release - update logparser.py to support changed syslog format (lp#1399027) - update usr.sbin.dovecot and usr.lib.dovecot.imap{, -login} profiles (lp#1296667) - update the mysqld profile - fix network rule description in apparmor.d(5) manpage - drop upstreamed dnsmasq-profile-fixes.patch - update expired GPG key- update to AppArmor 2.9.1 (2.9 branch r2831) - fix log parsing for 3.16 kernels and syslog-style logs (boo#905368) - several fixes and performance improvements in the aa-* utils - profile updates for dnsmasq (boo#907870), nscd (boo#904620#c14 and bnc#908856), useradd, sendmail, man and passwd - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_1 for full release notes - refresh dnsmasq-profile-fixes.patch- Fix dnsmasq profile to allow executing bash to run the --dhcp-script argument. Also fixed /usr/lib -> /usr/{lib,lib64} to get libvirt leasehealper script to run even on x86_64. dnsmasq-profile-fixes.patch. boo#911001- rename lessopen.sh profile file to usr.bin.lessopen.sh to match the script filename- add apparmor-lessopen-profile.patch: /usr/bin/lessopen.sh needs confinement. bnc#906858- delete cache in apparmor-profiles %post (workaround for bnc#904620#c8 / lp#1392042)- No longer perform gpg validation; osc source_validator does it implicit: + Drop gpg-offline BuildRequires. + No longer execute gpg_verify.- fix bashism in post script- update to AppArmor 2.9.0 (r2759) - change aa-mergeprof to the final commandline syntax - lots of bugfixes in the aa-* tools (bnc#900163, lp#1328707 and several bugs without a formal bugreport) - small additions to gnome, freedesktop.org, ubuntu-browsers.d/java and user-mail abstractions - fix mod_apparmor to not break basic auth - update perl modules to support signal, unix and ptrace rules (bnc#900013) - don't warn about rules not supported by the kernel - fix logging of "audit capability" (lp#1378091) - add support for the "hat" keyword in apparmor.vim - build html version of apparmor.vim manpage again (lp#1366572) - see also http://wiki.apparmor.net/index.php/ReleaseNotes_2_9_0 - update apparmor-abstractions-no-multiline.diff - remove upstreamed apparmor-profiles-ntpd-pid-location.diff- add apparmor-abstractions-no-multiline.diff: change all multiline rules into one line. Needed for yast2-apparmor (bnc#900013)- add apparmor-profiles-ntpd-pid-location.diff to cover new ntpd pid location (bnc#899746)- update to AppArmor 2.8.97 (aka 2.9 beta3 aka r2721) - several bugfixes in python and C tools - rename "__unused" to "unused" in apparmor_parser to fix compilation on openSUSE <= 13.1 x86_64 (bnc#895495) - usr.lib.dovecot.auth profile: allow access to auth-token-secret.dat - various small profile improvements - update and add several testcases - drop upstreamed patch apparmor-profiles-dnsmasq-iface-mtu.patch - re-number remaining patches- split apparmor-profiles package into -profiles and -abstractions- update to AppArmor 2.8.96 (aka 2.9 beta2 aka r2652) - add unix abstract sockets, ptrace, and signal policy generation - several bugfixes in the python tools and elsewhere - move program-chunks/postfix-common to abstractions/ - drop upstreamed patches: - apparmor-profiles-clustered-samba.diff - perl-apparmor-fix-bare-network-keyword-handling.diff - perl-apparmor-handle-bare-capability-keyword.diff - perl-apparmor-properly-handle-bare-file-keyword.diff - re-enable installation of perl modules - move python modules to python3-apparmor package - create symlinks without aa- prefix only for tools existing in 2.8.x, but not for new tools added in 2.9 - make utils filelist explicit to ensure we have the right set of files without aa- prefix in sbindir - switch easyprof python module location to python3 - drop unused defines APPARMOR_DOC_DIR and JNI_SO - refresh patches: - apparmor-utils-string-split (file moved) - apparmor-profiles-dnsmasq-iface-mtu.patch - apparmor-2.5.1-edirectory-profile(prepared Thu Mar 20 23:35:03 UTC 2014 in home project) - update to AppArmor 2.8.95 (aka 2.9 beta1) - complete rewrite of the aa-* tools in python - new tools: aa-cleanprof, aa-mergeprof - extra profiles moved to /usr/share/apparmor/extra-profiles/ (bnc#713647) - and much more, but there's no upstream changelog yet - drop upstreamed patches and files: - usr.sbin.winbindd - usr.lib.dovecot.*, tunables-dovecot, apparmor-profiles-dovecot-bnc851984.diff - apparmor-init.py-gsoc.diff - apparmor-2.8.2-nm-dnsmasq-config.patch - add %bcond_with perl and disable the perl subpackage temporarily (the perl modules will be back in beta2) - drop the apparmorapplet-gnome, apparmor-dbus and profile-editor subpackages (they were disabled since a long time, and upstream no longer ships their code) and the apparmor-profile-editor.desktop and apparmor-profile-editor.png files - drop apparmor-utils-subdomain-compat patch (was only included for <= 12.1) - remove libimmunix Provides/Obsoletes (libimmunix was a compat wrapper and got finally dropped) - refresh apparmor-samba-include-permissions-for-shares.diff and apparmor-2.5.1-edirectory-profile- add apparmor-profiles-dnsmasq-iface-mtu.patch to allow dnsmasq read access to interface mtu in /proc/sys/net/ipv6/conf//mtu (bnc#892374)- usr.lib.dovecot.auth: add '/etc/dovecot/* r' to allow reading plaintext password files (bnc#874094)- Rename rpmlintrc to %{name}-rpmlintrc. Follow the packaging guidelines.- add perl-apparmor-fix-bare-network-keyword-handling.diff: perl-apparmor: Fix handling of network (or network all) (bnc#889650) - add perl-apparmor-handle-bare-capability-keyword.diff: perl-apparmor: Fix handling of capability keyword (bnc#889651) - add perl-apparmor-properly-handle-bare-file-keyword.diff: perl-apparmor: Properly handle bare file keyword (bnc#889652)- add apparmor-profiles-clustered-samba.diff to permit clustered Samba access to CTDB socket and databases (bnc#885317)- fix problems with dovecot and managesieve * usr.lib.dovecot.managesieve-login: network inet6 stream * usr.lib.dovecot.managesieve: +#include /usr/lib/dovecot/managesieve { [#]include + capability setgid, + capability setuid, + network inet stream, + network inet6 stream, + @{DOVECOT_MAILSTORE}/ rw, + @{DOVECOT_MAILSTORE}/** rwkl,- add #include to usr.lib.dovecot.auth- update usr.sbin.winbindd profile (bnc#870607) - restrict rw access to /var/cache/krb5rcache/ instead /var/tmp/- update usr.sbin.winbindd profile (bnc#870607) - treat passdb.tdb.tmp as passdb.tdb - allow rw access to /var/tmp/- add Recommends: libnotify-tools to apparmor-utils (aa-notify -p needs notify-send)- update to AppArmor 2.8.3 (r2122) bugfix release - fix some cache clearing bugs in apparmor_parser - various fixes in mod_apparmor - several profile updates, most of them were already included as patches (except abstractions/winbind (bnc#863226), abstractions/fonts and abstractions/p11-kit) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_8_3 for all details - update partially upstreamed apparmor-2.8.2-nm-dnsmasq-config.patch - remove upstream(ed) patches - apparmor-2.8.2-fix-ntpd-profile.diff - apparmor-abstractions-r2089-r2090.diff - apparmor-abstractions-ssl_certs.diff - apparmor-fix-url-in-manpages-r2093.diff - apparmor-no-perl-smartmatch-r2088.diff - apparmor-profiles-dnsmasq.diff - apparmor-profiles-ntpd-r2103.diff - apparmor-profiles-samba-create-dirs.diff - apparmor-profiles-samba4.diff - apparmor-unconfined-lang-r2094.diff - apparmor-utils-po-de-r2091.diff- use current ruby macros, the rb_sitearch is obsolete since at least 12.1- update apparmor-2.8.2-nm-dnsmasq-config.patch - allow access to pid file and supplemental config directory (by develop7) - update apparmor-profiles-dovecot-bnc851984.diff: - do not add access to @{DOVECOT_MAILSTORE} - not required by the main binary - add abstractions/mysql - allow execution of some more /usr/lib/dovecot/* binaries - better restrict access to /var/spool/postfix/private/ - update usr.lib.dovecot.auth to allow to read mysql config files - update usr.lib.dovecot.dict and usr.lib.dovecot.lmtp: add abstractions/nameservice instead of allowing more and more files- add Recommends: net-tools to apparmor-utils (needed by aa-unconfined) - update usr.lib.dovecot.lmtp (add /proc/*/mounts, /tmp/dovecot.lmtp.*, /{var/,}run/dovecot/mounts, deny capability block_suspend)- add apparmor-2.8.2-nm-dnsmasq-config.patch - allow dnsmasq read config created by recent NetworkManager (see http://cgit.freedesktop.org/NetworkManager/NetworkManager/commit/?id=d82669d3fdaa7ec70ef1b64941c101ac810c394b for update details)- add apparmor-profiles-samba-create-dirs.diff to allow samba to mkdir /var/run/samba and /var/cache/samba (bnc#856651) - add abstractions/samba to usr.sbin.winbindd profile - add capabilities ipc_lock and setuid to usr.sbin.winbindd profile (bnc#851131) - update dovecot profiles to support dovecot 2.x, and add profiles for the parts of dovecot that were not covered yet (bnc#851984) NOTE: Please adjust /etc/apparmor.d/tunables/dovecot to your needs. (apparmor-profiles-dovecot-bnc851984.diff, usr.lib.dovecot.*) - %restart_on_update (in parser %postun) is "translated" to stop/start by the systemd wrapper, which removes AppArmor protection from running processes. Fixed by using a custom script instead (bnc#853019) NOTE: The %postun from the previously installed apparmor-parser package will remove AppArmor protection from running processes a last time. Run aa-status to get a list of processes you need to restart, or reboot your computer. - reload profiles in %post of the apparmor-profiles package- add apparmor-abstractions-ssl_certs.diff to allow access to certificates in /var/lib/ca-certificates/ (bnc#852018)- add apparmor-profiles-ntpd-r2103.diff with updated driftfile location for ntpd (bnc#850374)- apparmor-profiles-samba4.diff, usr.sbin.winbindd: some more profile updates for samba 4.x and kerberos (bnc#846586#c12 and #c15)- add apparmor-profiles-dnsmasq.diff - add missing permissions for libvirt-generated files to dnsmasq profile (bnc#848215)- apparmor-profiles-samba4.diff, usr.sbin.winbindd: some more profile updates for samba 4.x (bnc#846054#c5)- add apparmor-profiles-samba4.diff - various profile additions for samba 4.x (bnc#845867, bnc#846054) - update usr.sbin.winbindd for samba 4.x (bnc#845867, bnc#846054)- update apparmor-init.py-gsoc.diff to the final GSoC apparmor/__init__.py- add apparmor-fix-url-in-manpages-r2093.diff: fix URL in manpages - add apparmor-unconfined-lang-r2094.diff: fix aa-unconfined to work in all languages- fix ntp by allowing read access to openssl.cnf- add apparmor-utils-po-de-r2091.diff: fix some (mis)translations- add apparmor-abstractions-r2089-r2090.diff (from upstream 2.8 branch) - p11-kit needs access to /usr/share/p11-kit/modules - allow reading /etc/machine-id in the dbus-session abstraction - add apparmor-init.py-gsoc.diff - make apparmor/__init__.py ready for the new tools developed in GSoC- add apparmor-no-perl-smartmatch-r2088.diff: ~~ was marked as experimental in perl 5.18 again - use grep instead (upstream 2.8 branch r2088) - fix ruby requires- update to AppArmor 2.8.2 - several fixes for python3 compability - various profile improvements: - various additions to abstractions/fonts - move poppler's cMaps from gnome to fonts; gnome includes fonts - deny @{HOME}/.gnome2/keyrings/** to abstractions/private-files-strict - add read access to @{PROC}/sys/vm/overcommit_memory to abstractions/base (bnc#824577) - update pulseaudio directory and cookie file paths - add missing permissions to the nscd profile (bnc#807104) - deny capability block_suspend to nscd (bnc#807104) - MariaDB compatability in abstractions/mysql (bnc#798183) - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_8_2 for all details - removed upstream(ed) patches - apparmor-abstractions-mysql-path.diff - apparmor-profiles-nscd.diff - apparmor-python3-r2052.diff- swig for python3 is broken on openSUSE 12.2 - build python-apparmor (for python2) instead on 12.2- add python3-apparmor subpackage (currently py2 OR py3 package can be build, but not both at the same time) - add upstream apparmor-python3-r2052.diff to fix various python3 issues- Ruby 2.0 mkmf gets the path to ruby.h wrong (bnc#822277)- do not package directories as %config - especially not as noreplace- enable python and ruby subpackages (using %bcond_without) - update/fix paths in %files for python and ruby subpackages- add Requires: insserv to parser package (needed by initscript)- nscd profile: add missing permissions and deny capability block_suspend (bnc#807104, apparmor-profiles-nscd.diff)- Add missing files to SRPM (bnc#777471)- update abstractions/mysql with correct paths and add MariaDB paths (bnc#798183)- update to AppArmor 2.8.1 (=2.8 branch r2069) Bugfix release, http://wiki.apparmor.net/index.php/ReleaseNotes_2_8_1 Most important changes are: - add various missing parts to profiles and abstractions - fix a possible x conflict with hats or child profiles in apparmor_parser - fix and speedup stdin handling in aa-decode - various other bugfixes - add pkgconfig support to libapparmor - remove upstream(ed) patches- verify tarball with gpg-offline- fix directory flags for /etc/apparmor.d to be in sync between - parser and -profiles subpackage- remove %stop_on_removal for no longer existing aaeventd (bnc#781564) - don't hide TeX output when building the parser and techdoc- clear and update inconsistent profile cache (bnc#774529)- abstractions/bash: update /bin/ls to also match /usr/bin/ls (usrMerge)- Add required fonts for new TeXLive 2012- update /bin/ping profile to also match /usr/bin/ping (usrMerge)- update to AppArmor 2.8.0 (= r2047) - new utility aa-easyprof - templated profile generation tool (the resulting profile may be less strict than profiles generated with genprof/logprof) - various small bugfixes - removed upstreamed patches- add apparmor-techdoc.patch to remove traces of the build time in PDF files- update to AppArmor 2.8 beta5 (= 2.7.103 / r2031) - new utility aa-exec to confine a program with the specified AppArmor profile - add support for mount rules - see http://wiki.apparmor.net/index.php/ReleaseNotes_2_8 for full upstream changelog - removed upstreamed and backported patches - remove outdated autobuild and "disable repo" patches that were disabled since the AppArmor 2.7 package - create the Immunix::SubDomain compat perl module only for openSUSE <= 12.1 (bnc#720617 #c7)- replace patch for dnsmasq profile with upstream patch (bnc#738905)- add apparmor-r2022-log-parser-network-bnc755923.patch - logprof didn't create network rules because of changed log format (bnc#755923, lp#800826) - add profile for samba winbindd (bnc#748499)- fix dnsmasq profile (bnc#738905)- add 0001-fix-for-lp929531.patch to allow reading /sys/devices/system/cpu/online in abstractions/base (lp#929531)- Update to AppArmor 2.7.2 (= 2.7 branch / r1894) - move various permissions from httpd2-prefork profile to abstractions/apache2-common. Backward-incompatible change: *.htaccess files are no longer allowed for ^HANDLING_UNTRUSTED_INPUT - allow access for more /usr/lib*/samba/ files for smbd (bnc#725967#c5) - allow various .conf files for dovecot (lp#458922) - disallow wl for *.so in @{HOME}/.pki/nssdb/ in abstractions/private-files and abstractions/private-files-strict (lp#911847) - update abstractions/kde, private-files* and ubuntu-browsers.d/user-files to use ~/.kde4, not only ~/.kde (bnc#741592) - block write access to ~/.kde{,4}/env in abstractions/private-files (lp#914190) - allow write access for personal dictionary etc. in abstractions/aspell (lp#917859) - when using genprof for a script, include read access to the script itsself - automatically include abstractions/python or abstractions/ruby for python/ruby scripts - add profile for smbldap-useradd and allow smbd to call it (bnc#738041) - allow creation of the .config directory in abstractions/enchant (lp#914184) - allow TFTP read-only access in dnsmasq profile (lp#905412) - allow capability dac_read_search for syslog-ng (bnc#731876) - add p11-kit abstraction and include it in abstractions/authentification (lp#912754, lp#912752) - add audacity to abstractions/ubuntu-media-players (lp#899963) - allow software-center, fireclam plugin, [tT]unar, exo-open, kate and /dev/nvidia* in abstractons/ubuntu-browsers.d/* (lp#662906, lp#562831, lp#890894, lp#890894, lp#884748) - fix typo for multiarch gconf-modules in abstractions/base (lp#904548) - allow avahi to do dbus introspection (lp#769148) - allow access to ~/.fonts.conf.d in abstractions/fonts (lp#870992) - allow transmission in abstractions/ubuntu-bittorrent-clients (lp#852062) - allow reading ~/.cups/client.conf and ~/.cups/lpoptions in abstractions/cups-client (lp#887992) - allow read access of /etc/python{2,3}.[0-7]*/sitecustomize.py in abstractions/python (lp#860856) - various updates to the sshd profile (lp#817956) - (and some more changes I already included in the apparmor-2.7-branch.diff)- Update to AppArmor 2.7.0 (= r1858) - make traceroute6 work (bnc#733312) - allow access to pyconfig.h in abstractions/python (lp#840734) - fix logprof/genprof for hex-encoded program filenames (= filenames containing space etc.) - add apparmor-2.7-branch.diff with some upstreamed fixes: - usr.sbin.smbd needs read access for /etc/netgroup (bnc#738041) - create /etc/apparmor.d/tunables/multiarch.d as directory, not as file - fix syntax error in abstractons/python- changed a $ -> % (typo)- package subdomain.conf only in -parser, not in -utils package - package libapparmor.so and libimmunix.so only in libapparmor-devel, not in libapparmor1 - make Provides for perl-libapparmor versioned to avoid self-Obsoletes - move libapparmor.a and libimmunix.a from libapparmor1 to libapparmor-devel package- update to AppArmor 2.7.0 rc2 Most of the changes since rc1 were already included as patches. Additional changes: - fix logprof/genprof to recognize "mknod" in audit.log - fix libapparmor python bindings to compile with python 3 - fix wrong status message in initscript if apparmor-utils are not installed - parser/Makefile: fix some warnings, always respect CXX and LDFLAGS - fix some warnings in utils/Makefile - remove 4 upstreamed patches - remove mkdir /etc/apparmor.d/disable - that's done by upstream Makefile now - update line numbers in 2 patches- make abstractions/winbind working on 64bit systems - allow loading the libraries for samba "vfs objects" also on 32bit systems (bnc#725967)- allow loading the libraries for samba "vfs objects" (bnc#725967)- include autogenerated profile sniplet for samba shares (bnc#688040) - more helpful error message for "aa-notify -p" if the user is not in the configured group- update to AppArmor 2.7.0 rc1 - aa-notify: add --display option and warn if $DISPLAY is not set (important for usage with sudo on openSUSE) - fix syntax error on "rcapparmor stop" - allow read access to /proc/*/mounts in the dovecot profile- add patch with upstream changes since 2.7.0 beta2 release - add example parser.conf - print warning if profile cache directory doesn't exist - remove initscript for no longer existing aa-eventd (bnc#720617) - set correct $HOME in aa-notify - enable caching of profiles (= massive speedup) (bnc#689458) - add comments for patches in .spec and comments in some patches - run spec-cleaner- add libtool as buildrequire to make the spec file more reliable- update to AppArmor 2.7.0 beta2 - includes fixes for bnc#717707, bnc#678749, bnc#685674, bnc#679182, bnc#691072, bnc#705319, bnc#713728 - add some missing perl module Requires to perl-apparmor- update to AppArmor 2.7.0 beta1, for details see http://wiki.apparmor.net/index.php/ReleaseNotes_2_7 - removed lots of patches I pushed upstream - disabled apparmor-2.5.1-unified-build (patch to use automake, does not apply to 2.7 and probably won't be accepted upstream) - disabled build of tomcat_apparmor (doesn't build, deprecated upstream) - run spec-cleaner - remove *.la files - move usr.sbin.nscd profile back to apparmor-profiles package- Update patch apparmor-profiles-usr.sbin.dnsmasq to include /var/lib/libvirt/dnsmasq/*.leases (bnc#694197).- install SubDomain.pm compat module (bnc#713408)- Update to 2.6.1. - One patch eliminated - Lots of minor fixes - Split out more common abstractions - Add check_for_apparmor() helper.- dhcpd: Fix apparmor profile (bnc#692428)- Add apparmor-securityfs-systemd.patch: do not mount securityfs when running under systemd, just access the directory, systemd will automount it (bnc#704460).- Fixed typos in descriptions and summaries of apparmor.spec- Fixed building of pam_apparmor to properly link libpam (bnc#696553). - Fixed building of apache2-mod_apparmor to properly link (bnc#701821).- move the requires and prerequires to the right package- make the -doc and -profiles subpackages noarch (again)- Added alias from Immunix::SubDomain to Immunix:AppArmor to allow older users of perl-apparmor to work properly.- Properly re-created links to old utility names.- Added /etc/ethers and /var/run/dnsmasq-forwarders to usr.sbin.dnsmasq (bnc#678749)- Update to 2.6.0 - 19 patches eliminated - Lots of minor fixes. - Split out more common abstractions - Added more local includes- Additional libvirt related fixes in usr.sbin.dnsmasq (bnc#675867)- Added 'network packet raw' to dhclient profile.- Add Requires for used perl packages (bnc#670650).- Updated dhclient profile and added dhclient-script profile (bnc#561152).- Added ability to completely disable repositories.- Properly indent sub-profiles after genprof completion (bnc#480795).- Inherit flags in sub-profiles when generating profiles (bnc#496204).- Stop treating profiles shipped with the package as config files. - /etc/apparmor.d will still be treated specially. - Add support for parsing network operation events (bnc#665483)- Fix for sbin.klogd profile using kernel versions >= 2.6.38-rc1.- Update to apparmor-2.5 r1445. - Includes 3 of the fixes below. - Several testsuite fixes. - Update for Thunderbird profile.- Add support for libvirt in usr.sbin.dnsmasq (bnc#666090)- fix rm call for nscd profile to avoid file conflict- profiles: Add openssl abstraction (bnc#623886).- Added support for sys_nice to ntpd profile (bnc#657054).- apparmor-utils: Support newer auditd formatted messages. - Fix two x transition conflict bugs. (bnc#662928)- Splitted ldap related things from nameservice into separate profile and added some missing paths (bnc#662761)- Fixed pod2man macros with older versions of GNU make- Fixed building of perl and ruby SWIG modules. The former is required for apparmor-utils to work properly.- Fixed use-after-free issue in apparmor_parser.- Added fixes for logprof issuing uninitialized variable errors while encountering audit messages for unconfined processes.- Updated cupsd profile (bnc#539401)- Fix {proc} vs {PROC} macro usage in firefox profile (bnc#436262)- Added support for eDirectory nameservice (bnc#621394)- Fixed incorrect /proc/*/sys usage in usr.sbin.ntpd profile (bnc#634801)- Added fix for another case of whitespace affecting profile removal (bnc#510740)- Added support for unified build, which massively simplified the packaging.- Fix for syslog-ng profile to allow upgrade to v3.2 - add mysql support to syslog-ng profile- Added support for enabling/disabling the module automatically during installation/removal (bnc#623246)- Converted archive to tar.bz2.- Updated to 2.5.1-final. - Lots of testcase updates.- Initial packaging of AppArmor 2.5 - Now contained in a single archive so built from a single spec filelamb19 1548315362 2.10.4-19.12.10.4-19.1libapparmor.alibapparmor.soaalogparseaalogparse.happarmor.happarmor_private.hlibapparmor.pcaa_change_hat.2.gzaa_find_mountpoint.2.gzaa_getcon.2.gzaa_query_label.2.gzchange_hat.2.gzaa_features.3.gzaa_kernel_interface.3.gzaa_policy_cache.3.gzaa_splitcon.3.gz/lib64//usr/include//usr/include/aalogparse//usr/include/sys//usr/lib64/pkgconfig//usr/share/man/man2//usr/share/man/man3/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:9516/openSUSE_Leap_42.3_Update/0b4a9528e9651a762f72694af3f63dd3-apparmor.openSUSE_Leap_42.3_Updatedrpmlzma5x86_64-suse-linuxcurrent ar archivedirectoryASCII textC source, ASCII textpkgconfig filetroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)C++ source, ASCII text (gzip compressed data, max compression, from Unix)+K3)m_?p]"k%]dm\~ nxQsQY=+"Ԏ9,EC]>26O>꟰AC|}g$3~ip@!)a_VT"G&^8JOQs~rQ왳 ߮֊~k)ەX t϶kyTmǴ}uqf8K;ERipdO6w?yPºKla?5&YFȄ}'q*k (*a#D6Jn/x3?^ҹxG 6šָ$Y啔Hˠǻ$܀:lXSYy^&&UzST3 :CtVwO),b&;~M)Ldph/wӊmV UxM0U.q' ~Ο=|ZCEZvENSj|.QqR\IE+!DkR˫>pǧ7k2ԩBSׅoBay&@zW}jqǛFB<{ ޥpH6`GS2VE3igbK|z.# <6N{+ ,VVv>ݵ![3n?GQlvhic>7^0(o[B%-mVFNw<ܦfyϴ05Tr$9isdT^4F6H_rR=}hTjG$^K٬u:IȕxF\/A͙2h3/sRpÚӟk&"*y.hW^J+l)!+6V;v*f ^R9YT4mG݁^Z_ N&pGE*#7(o0٘6.zVSZ{+E)82Xi&z.V|6ZC^#,q sk uFjѱWnσ'r:2}~ (wZXq\SB{wOAX[ΓE#Ԥ*!C+$:GN1f1$ Pg,-Ϲ(*Mj븳D~!hbk@U]UJ؅U"\ +khb_xwX׀oIL'$w~fB Sp(t-,Hn"ǘP4P꠶.I+NxTX9ptz˕Gn'5i_0aIzxn} n)ا8n(Z2Q`ɂA Z?DMgYLh>,0C!hbzi[^KED X d&Ѳt؎@i]0c 5_qS{^N—"^Ǘ̥\E; /lySx]b:Ho3#~E/놵Gb4R{ꉹu`7j-3q|IQڨ&_Ohf+L>j$Y"M-]ѹ(2HN 1=a.q:_/ D @,!bKg\:;.3ǔ̲ dlEWVkiзC "ax.鸿_tUHX ֲvk ,H'[ 7(C7(ZR0&hΨ,!·ɥ FLoq1TâN~{gF rl,F%g9^+S8$/HE{}SD~Z] OTTil C%0QQ#A T{lH0`D]rXJBR4 /"NYy]cq`ClRBإpEN's%2NYF2d@ L֮ ߵ b0=9b"0F:ydmJD柯g?PZ7Z(tˠK0?I" #˞؇5\?+8E%kb*EZ P_ Qv(D̜n ~{P?N}먹Ӓg5v>sBxԖp,LRї ۱VE OA2H2Zb$LR{/߶GΙ`G,[d̕i朗?-<9䱥++mCh\}3>ayU.olKՀw.LJp) bTZ=-Șg3e0zbX7J[){P M]ʉ@PU zC*d=$`bzJ^(Ӭp,pn xfpvz2L{(uQ=h3G1Шb6ϡ[RP> ?lr۷, g'i5@6Rݗ({E0ܛ)>V3 S2 10/`Ƴ˼M>C–; Qy5Yό`ȡޙObM>QjˍrodZJR?ڡ?*/(R(W}|RˈS 3\7tQ6s]+> A0B\Eڣ%aA}JX͜cuWk5yޣMGH"[)|t !XJ647m9ܭ w^*<ǁ d-Qβ'뗥kr>6[`6~#j'fdH8w ؞æEpQ3c']1s}4;L- Y_Ɲeiz띭10&u'8# U3MݷcŶ^M_atgB|yTٶѷ |l8txJoZJW=ϐ0Rpxٕ/al..0|ӳ]i=|qSbn43ˣGӢN(CC߱R@ ڵ̰9S)=qyhi|m`IxgP:yb9&ӧW`BZ4Lia$-t2߽h_ǐt(rQDh|HԴ}%)θ0Ts@[q;*ӘaN^V >m, fM_R@ #trg22,eOEGdS( }u=`t@\x8ۗU2%Ok %-G֊yvIq۳%媫:SWb?[9S$gzPnBכ$'^muwA}КskN eوe.CV3; K S۹XŲ~խ)Xx};v촦Ճ`R=R lUL\d &ԵVZS?`đ!ET%T(8 YWhzjZ[|qD?y?ZWk/uД?0lbghĘb~z.XA %WdgRm0927_L2ZnWb9Ҟ]4Au~Zz5||l1(z /Rk{Gŕ81&alJ[iT)挮@Bs?4;NPmI= ogFBU|/_V߼O Buz6})(Т^ɓ[! o ,,nӊaIxx!J(?q2i(l ntwMJl( 9'=}T1H xa!+$oQ$1}0c՘9_v'zo]Hȏhj%o:\5H3VvɈyl0WzKIwk!V'";ۋԢBhM*!K~??P\{n];Jw؟ja:L h؛_dV dXy{KX.oQ 0±)籆$f(=]C'>. 3'"!1z+q||aǞ~baYpԘiv u#2 }̢&JYg*/fx"CF'M\ӐA;)[p{b .?kFмa$jtg6x-gtʫu%%PVvVyuCa 71If'&Ijw6 "fKpp@Fޛ;r]^r[B{-NSl|9u]*I߁Gm = %;]q<8OQ'w?~G"Ga&tXQs4alB|uXZ'FfLod{%~?݊?kMuFBΤ帳niQnJ r7ƻhіxzdTCZ>$s.2wxY=jc9FkycG3$#T'ҋ|gmo/FR%$/KnjkZc;|laB&oOa 1=qe\" {q|SS20\K4%*8z) q:6RquAW#ֶa]Xι J`]Vdeȗl9Dhi;(X޸uB\K`H9et_Swx7 T;BNWBr6Ƶ=sK33f`m{ CcsBBEhe`jS=n=CDhq'Ae7 O)LB-^D{0S+L!uǁ_RiWf?.52b4%K#U2I",VtԺc"溊;% >͔%*r3N@R]"j>d{,|oZ \G>`A;*ہ$^YcxFpjUk`I} < (lzY"s hno=ta̯JD(Hϰk|m@,k f 57a]b۩;Çi}%6Ci)5LQz!ض>6_Y§i䩸EV7sCzh1\;I6 &=`X׫cc# Y]g#xu[R$Xnw@LE5D +ԁ<ÈKc Ptn$'Ǫ=mgE0t+q%sk`R^Ry+XTg|%F}j&Ypu=T< _p v^+ߣO H;G~$3b5zWj" V N\jϨ<ct1uuH[7rY֓~y4Z\kQi!fx7b0iD#YT)#Iݲrq6q%$xccqZEre`A+"fT^Ň'C .47z ' X(@Z!a,+q4Xv 5th P7.Ce!Z^3#cϨHN{frF2y"WltdYƅQuDG_~E `G<Ӎ W#bdi6e8sɶ[3E0FcMcoS24\pnHR^s$5ok5 8!y,"J*$Z\2gQ9zkǏ((nn%S;#` jpo(|$!(e/R%6C?hPt )&Nm21JF0PX{'~Ly1엌%ªS2&0YCE:O Icsk(~?Xs%O>^{zߞ肀{m2Tuk'+niSi oCl,ql{;"M#?A%i?YRODA0 5ƼfDǘwʂ~M QX\Q@,Sl-33,q_6h/uԞ{ikk'p̭QƄP |-гRQJW,@Tg(]m^HwU&_e`[q,q8׋@_ѓH[ii7*t]X}SK,)3 TRCh&=j? &,n{ q6)]\q51i:x񷠔Gcw6ZdV?/7,iuyv鲣WYm~~P,h6sE*ށBt_z}Xϔk_P:d^dƽ".c!O`oQVeoO2=%5fn ?{6n70TUH,{ ~:i撅̠p{] z3d=;ES{&/W2g=SH dB'b<." ۹+(!4'!NNqj#x=ADD Jbc{QUGs $@}35XXʴn3<_k()9Tt FrZΌ^ˠ ^pkГγVc2La4X_\m 0#sƜum}H q&qY--kNxŇ046yRg|V=Ƣgds-ѭ Oi9:4(/\vv!ZF\a2ߛf8NPy$SlV}.fy0q1O.l>ğ]Rdh&ʆ̫(r!=D϶uf}JtXV8=ADi"C:3n~o3=y(t|Y&[ko/6o9w'~s3D"ıe 0@Pf{{`+D ?_x>9Q7tH`eOQh3:|2q=I/_bWTbF?"[7f#+I'ѱKlzSL΢̈p5lacy4 ZM..Q GdB2sv 6g$kjV+^SLjl1BĿ}Xib52<qr/"s^NnM#>1>$j : /!-L&<Ņ WcC 16慍K, c"z iu%r޽kgR]5, _FXeEm^ pSNFbWhm0MeM+m4LEz.,g vs =1@%ObERb9$ed Qu4Aǩ'ح:_(XF~&-'1s"Mܬol-Aw+޿xry+JfDNs0STT`IƓHQO AaSZ/fEzr(g+*wmW|MFR]K !nJ&Ife1m/xV؈z)98>>3<]T0gK,:UZ] $N4xb uؠCB&Pu;jz25ð-FRӶDqYx:>pCPؐ(B<:wnjƞ}t_ vuc=_1tF=N Gu4\gGN[4 "H@:?vp"$ U2=]WUol+uh-?ƅVi]J*yK `I--G1ͬ0fCnK `Ͷ0bcqmVE\3wTu Iॽ^6ivh(3$o \}O(uu)i Ҍ{,'߬^^E<Ӆ_B+HӮlfN%`r?a*(kׁqaB3#NІ}V7<ÃaI袕p8q[JYlPۻ?榦%,O4➽ eѿd'>#S~4{u81aU< B9gȞߠ Nd5lu,# 1%h~υ)/x\H6i`KFɶ~+:&]Սڦu(`^¾C{E@?Jpy6ڔk[UR},x;u Aϴa.5" P^a8zA&po-IQ%:N&rrJt-hћ:Nj$J%>ō6)|չ=zw2Hs&H[p)7Чu@!R#vzcCRd6,7Sn|CU05NwGTFH!sřD~'>Jҩ-HӣUZ(K[?]%gUueB hNR:PlQapɄKڔ; <,\-ȳݣaO+W41R⼅f59ȺX.J[ϫ`B25)leJ4Fu|f8GbփW~ORQ4b~SS}p酳ƛ\Fd){M¡=wTE:po\,Eєp-.\lﱻn&A#< )7~<[KIk|"rmZTA5(mrSw;QvUq?@M~7"s%5>"^Fb,0! ʤNJ+!QS%qӊ I Xi9" $sx Fy؎HMl$:w3'섌Y*+z7m'1@A-JdZþ٠g%u9V,Ĥhw4i>}- "zT,1ǜ~5h:"sM$N"Tk(2uig2wAˆwh B>qM9 \G׬Vvקn0Χler Cmlcq[%*W+#<E^h4.FM'A;P;"mZFi %3 _4w?s9 WKEc8{8u^a:y=zKpnܘME@97P?sf y9ENIluzx'7'=:O1p)Zٛj:5$iˠ&a4hfVTbί@Շ^eOl4#yF!E|*rM 9 Ht|=6utճE{wniɕ%gW՗!;~HP~׽ ->>tͬrZկ~ >?}mmuŝ^͔\\`C=~}zW*1a5_ "7/L\#944w/8;*œXumEr+|1aauP<[(͏GTohzKsp2s?8'en7HC[nC}`ZJp~z\)$W1F.:Oz[뢠8$~;}NRFzM IYyFaS^=r בF e?68`2f*gAO-87s/Hg.3ޕaP`z83U0r~x"78kbco񢞨-%}M7:Ĵ>Gsw*%1M.;3kkNܔI~f%Bbd \>m9Gc.'~7n Y{xǀ+SeM]=˟jcg~qB.z/*Ԝ./R~ ~{jOnSY%a(z2:FYxSLֹ[Z)=,9/37_$Jr8`M}||O24vԤd'2!+g|'d8]N"PGՆG/H9aAxKBQ|3i̔踕R = 3D`>', ~ ;{!<NxϢV4* Xom$Z _:b*6}3dƿLև 7oS{èo|;D KLasf }+]Uo-P9 T{cܿIt$A @[ҋ,u(:'Ow|2 ch7DU޴Ub^$AG\@8 Fc(ŧд6"S^Zm-ր4 AuO4$5*h\ ~<(E^w%R~51=&W#DF[yh\ؠ]<}E=`tָ,r;:$F~grΣq%sAbC,R  (׬oP/m,%Q*y;(<7,Kēh{aՔ𧼂#=1E ke8#kGJӃP)eэ} q4A9rnӭTpfeu5;Y ;vnr?|Ĉ Yr:2<1VrLV} w#O:28:MPUs&Rɝ.LJbt5QotQwFWrOS.JZ(6V^§ľ,)_,؊F4C<o\&*2V |59:\ˋ~Wt4@Z>>Fx7ab\,g7ivBUǟK2x0ԋi ̃AS߸')?%w3L!ww3{‘ʴ7t3-ϹTH;3)Ғ1WoKdH}$]T^0Ruߢ& 'V *p $)ECe մ`O{>ecmMK{ tSnCR4&'A@J itލuӚQ4䊪VWΉUM̛g*H}&fgKs>,' [Em,͈N=`WP2LĪs(P-VpXH/-aw/$/haz ęPx[#žSy}Ȯ/s~l\P2lghX❆ks0G=JG> ҈,.^ ܇(ͺB;ܕX=с/>?:x 1,U"Xt-3n8O@yv{iQXYrT1@@I¯(s D GΔFLe'jݫ{c  ~Ur/$1.G@݉ )C5Q`}6WYM䱞kAr 4ՁLF_vwoB- ~B#G2Gg&yklV2Y Uj)vX(9/sz.{Z>NYLT0Z*~84=l KCRȹ돪rhgi+͕ i\]㾌F߻0*[c*+G2Si "BM)ep.K&+g*qI\>?&^{[ʵ{Cezȶ|iU4*wp 0WZ@jJÁT'Pur++CCjoO7`/v!]cPȚ v!ʒq_ސC){}W r]8 U(V2{o0oU֊P``jGTLkzEJ?ZOsjnisAo׃!|SwԦ`*MpW OkaԃStkT6d.ySL~O\ g5P#j=vx>䄶Y[)rE|GM& eҿ5lӣk| Cl ue ׊MxϮ̓T$]z}hT!Ġ˘Sn>є9[˸p>-#PL+a&PbI}=}'J%}!C$io}jGTx.aMpF"8Ƞ[1GnhU" rie RtC u!u{E@v9Ec3ᾼKns3g5g4x{/ Y.׊7Y rUaU/#;3"OuՓv% Sd dMp63?J Nqmp)cJCQ}GT}zIy?6% GΩ~:8qh٫ "{{,ef@.;lCQ8Tn}Gת:!u7??0'kI]5KG#j^MJHWq#Vg~CM52:óNS6*Nm^? q,heKĮf)v ${z(G*' d%~)_+K\Jɗrո vG|S6IqJ&k  ),cM@3# |F>9`y] %9o!Hp*diX1T*f<4Oa&R0 >Y?T=Ҥ}_s}DYF1:L4MضٛPI)#EcEϤ!":̿st\0 !?g~ԋDnTlZ=wI 䑊B6J-Ѹ'Ta/A[jRt"MǸSi 9+APG~ ;&r1Pި_ ~G~kB#qceuq#3M X &6rYCw]H=u9ȝT0[o ~BQ[舲uց 3 JR3~7WtNzX7苁wd:#lۑv.&5l ]6}e]T,P gP ʶj}=)jTlŠ+<~8M^EW}# Pu2%HHj›1m )8r B)}pTs'=)r/"WJgEU[cR('Ǝϭ/-|i4yhg2`2~E@/Z/-re4Z$"% uܝZP29+x6_'p'|J%zw-Dc.87'zܿ[$jظ~^Ǹ40fсSNni\G߈ۧ6"kfCHKVMWy| K0(SAlL-ZRaӏ~&+1l/PQ3wL(,Āc8@gIoЌ}D]+\EaocN8crUvГD$˟ňU˥Cv}<|+crNWqV|kHHO ?qN,:9dʷ'@5F.kV&vGkml*gS sTąT-ꝜË0{k%1*'R[p5C9Vs#  Lf]̹Wd5 +oO27WWyP",/7\Nkb >*m}k#X;X~84d M`J`E_m\Hc4%9}%pv5IúSԑ).ؘ<=K rfWTԔ|̂ܲ`ؚ~8JucWٓqO\y$wZGfbW!KΗb;A.'KdbSQ_8l2~bU lЦpхk'/ `,FMKl1XMNGY;!\f:_#_j1T;YM-p+SEa@K udT!a$eˊu6AkRLq#7^!< ^s@Gom@&ӊ1_݉ .ʶ^|Gȥ% HtBbFZ̦%ڡb}5yâ={'M}€ ;i*`tj=n\#I+lWFCVw_`PRUBDm@IefHl(;Q4+$ "gu(Y9ipRT6>y7I-;mtA{g-FM4m)ya/ٱxhM>GGD!kJ/JN״32b<x 2&ۥm l>KE x |ԧR3qHG'?Es )fyFݎ#10p_6@(c &hJ"C?({P=sR J˝ ue5I<9'45FQ+!?J}3"]91דA+ebz}p߿8T$U_yMIBX1:(fsDoѓzKUb/͏_\؎ܩ+J/bvf^LHwثMNEs&F*6#Q9*S9Ow{-pQm5,/'OlA"FFW>rſ^ʕGi̞~팸~ħ0cc/ǒZArYt) XޝxVT},F24ҏa'r ӥ͜$J/Q+*mL:Ol98\$> QNe/0S\X38>~ba] k$5V~m_hi8^{WWƙ7YsxyULs+v2IjQFԁoPݦݢw[Te0|Pz9 /Vg ; $ x(cb˳sdx;ȼ[ zp +L uMmefCHZZn*܊ q_yʰȹS *( _]Yx(k񋼞v'~5؃R,[k׊k8ѰNZ^)uuuj=dmnʓZJ]Ck)%R oK7VNWapAɣI K\ɣ$+Hm|!WjBJ'I"@laZg,faO(;\iM, s*]$k0@{FE t ՗*,^ љlsaeY `ǽ($g$2+*8etf+ߢG&4̓mG65z>9l%fzCRuuF5:p8?FxcWu)i%wY(!ڪ50!@[|A$G*'?9BVOdڣiN ^kzs7[Gժ/M+})hT%{^0Cil s%vm=E҂SmD < BG6o\{+y!Tqa~3ZDƖs^Jc0"&:pASK]o +5>u4FR.8r'4b)IJ +q~$Qةd<}vj|ҐQf6u|.j>:fq UQjcD0žO!mDۊDX2U{K`6 ks]ˑ>;7okzTFt'{_ <rp$PQ:]G'eK?.o2 9ުZrFG&;+667M P i)l0dpfN1tSn>;. zp"eFo6.)RFFڀ3\0+'·AD}qY'. $(3~@z=#l;/!igaqf󴃛M_+AXF(|}q`B֐U膇rGq¯IO5y%Krܰ RDBoeore|sRq>^M\"'\鵀y~Hn;l4׌ BB@tT.߇4UM$; rWNgѯ8 f?4#}^/UhdgY@g=]>e]llt@7eW=h'%9cʐ"J?ǛCVfPH2 &Zgimo;3ӛ5HdHu((En`Y?/DpfO&I7Ww O;0ή`;[>E8Oԣ 3'EO7o!O(d Ooْ zCJTpcpEӕWD9dh'xx9-$fH*7=GD{Z6)5Ȗ6|3rzi^רACwL뽌-YC.JIEuǸD Eptyw Aj2Nz]W)ip]оGA//|,P ֭:AAdL, rF?)0}Ĩ:3q)@;:6 ͧ2Lo3jБɶ pmyP"tLeס7H؋"W6?.}|G;ޯZj,.YWg# =v\Z zQ{[nܓٯU 6e7OD+oZ%JS5΁/8P3,C3B Nǹ,~[ɮ 'b3F(dF aLB*MwmT]#J!8߇@DynQIR*AJd-Eg`aZDLZ. 3=T3)NwXEX$*[nO{i ,݁ڱF!8ʈ8XCMKO:< $]"e+ 9zW8Eɹ}D.W} rJnnɂ&SUҔ_ƿSaµg &75b.%l pWl){s2&m f'B"5(,{5%ioZmlyPϠ'E@>Du'G ʮTa͘;P=P-)|wu*>-NxE6"T~&[ I@a`3FI]KGrOn01G?/8qusskKFS"a8A#_k9Ύϻj-+l[&ǙD)i Ꝯ {85ih5Qy>ܞ 0A /F3cZ ?un;be2ViLÀdeoƿL9U;;APr ޡ]3[ˀsR+6!L!YePui |=MӨ.ڝ,69Ơ\},'‹㋍WpCE"VeD[rpۓ54~*xKtR%b9$={9q_ܘPtdy M oc;~J:- z4`uAs?QNYC%R& RB;z eGmu!"Tг$c96g޶s lZS*>qH LMѹ0v0x$ FF~QPZҲ㎚?a1=~Vը'^#ZQh>T _gM*JcjS;YD^O3]`e<(soU(ZàҤnO1rS* E݄!n~ ; :Y Rm}a j:Õg)G W+vOC]Y4Eؠ4׫PBSWa\\^BkQACd?+iG,n]]{( ~ 5s1 *x>e{rș8xYuh] {v>`cR1_LaNDJN^:":뤾C[ MX~dEHAN%[(a"G)a;.D2U:m%o=C̘,?sH.3s?cAv p4=X sY|YbKjego:Ԩ$@WfJDmVϋ/\}Ҹf[ hȎgqbSr Ƶ{d^Qd"ժ߮w^R>=zB__,1cu@䬶wDna "Acֱ"Y;̡y>AB/Dh:i9P.Ө/1h<,s("gk4T$ {%A0%fcx pd|y-^]Ϯ# WT(OS  -񁯮ӒZU] $hXGhJ4b!y4}(ωFT%{W|ǘN zFv6t 6`TC0yɿe @O53s}oٸ䔩*kYoܛk }Yg!'[y`|--=;-G,b &z:롷*s2!-|&w2d_DZT k݄q%]|ВQO?2DEv^`-K!xnkkA؛f?>QL]i+DX՚b #O?HGRzf.Mɭ.]\XNuixqcGDZe1m[byA>n pe 9CX;y y* {fav/.ӣlB xú:)7r ZvH~kocyI^b(yXzq l[/hmi 7)04Ъ59Il0Ogveb7!XxӌNe]]?{5pWKSK,nJZmhc"gԙQN@neA#~@# ϴl@$F (&D¬wdfjM"cmFFv"5M3X@ [H4;=IVפ.Yv ڃcפ_Q QJP/$SL*npn̗qP/Y)l.ExC -j+UbQ]G B*Oc\36sd+:lkA5ڧ1Mzzb  SUASgD&F:'5;E@Sodd) !zBGI]gI\9B @h`M$b@g_c"]Ay9k1xCUq*JFH-^<3Y7pG pp?^Zg W 1Gzzw`B /7\{~MV}JVkĘ,ƳO۫{M!=E(񇩵! [AZgǀƄC mh-0}6?6`hQGävj1Xh?*l16ͯѵWp/:9#D2( 賨 kӉI7_JK)zmٻLM|eISG[ d }Zq&8@;? b5 '@.GN Y72:^`C}~KQ7<9/PwTSH1qC2[Gr_l~WTAW^e4ge`JDŽE|WH*'1A;MgV(oc QU@ja逋\EbqB9SҪh8"h_om"ǚ%1e0bOЗfIXhFݣ!8.]AY.sF,&2Cw1m ,#4xl^#tT;iX T -*O3BZ$,d(xX~+론,U?.7|۴+D w@7,K% EE w۲U4gtӪU4& 3+}LV ^Nīzpz)擅 ]B䖬~5d(rC,n,ގo4+^)"&d8a*'9B]~SB91eܟ0ӧ 5`ė h[`.wg :.TJ-֣U 2U NJRw N`NiO|eXd.(0݇ rwJ~fT!l=a!?d?T9 N˫' BXHxUd"'jisٌG(\Tc8ܬ 26\-GGW+.hL(LI 7 ivv0.V1};5:zdQs^J%rA#%&иb&s5t!pOb<`7HlN?$ iOݿ[?=fyx#@ӘU >E,l^_ƽaȂ1JĖjqPB}8klOyyI.ߎϊLŞLkuI -lIR(ġwR7 C1a2gH1BhWLj3Y[FZ vCrJ<RuC[@ >.^icpq#bĮ>^L+Mh{pGYsVwv©I;'\ Ȍ n:} L ܆7Nkziʴm^ RXwx%~ q*Ia]Ѣ#'b :3UU}Qfr=r=LD1l̎y 7"$ :5a*g_CR."Z&i(q9CpRֱZZ.P9XB薚k1(Vl[x:VzU*M^, BaJ&}kpe& SrjF~Ȼ`S\{ D&+1{NuYHdr>6<. M܌X<'gT[㤬>}b Ϛ"15}TKF)M\qϖ1e,7̶$0 :l٦L!K