ÿØÿàJFIFÿâØICC_PROFILEÈ0mntrRGB XYZ acspöÖÓ- descð$rXYZgXYZ(bXYZ<wtptPrTRCd(gTRCd(bTRCd(cprtŒYê!q%ÎyÜ’T=UHÔC]õw`²slìŽ8âWö;¬¹M/¤ø·þ陪kêq.'�þSêÝ�`ç¿tŽ©Nùï’¢ÃvK pxÏÜ”›š÷H ¼2ˤzÀ—e>§–0ì5�Ãä(*1’�ÃÔZC{oÊEóynk<Ð08*{]Ç�—`Š‹\UÞ·9­`3º‡*4U�.Û·„ú*ÇI�\ü(Ê«[©_ü3!ÉÇÑgE33¡ÁÀç’¥H¼K%¶ýuµÌÉiê¤nžNËlô_ŒU°Én d„`ko?qÝiªfànvå=§1áñ¸�b—F�T•3¶zK©¨ïÔžuTr¸`¾0ì‘�¬­ppÈ\iÒ=qq±ÖGSMUåÈÒ;làNô_Puuq‘‘Õ3ì÷ZÆVqæÂáµáoB®s‚„„!!@B„„!!@B„“¨¨‚’ *ªelQDÒ÷½Ç­’”\ñãÿЦi$èëAò"poaÿrAü™ögܨn½/�É*DW‹Þ3ÏÔ3Íe²Îb³ÅúˆuAÏý9à}ÊÒU•óÖI©äï°ÁaYR_ ‹VãÕ!Ï%4|�‡$ìGºÅ»;ÒP]bM§Ð×`Ÿ…Q){¼±¿ùKÎòàeíÀM[­ÏsËvþU^Ìãf[�ŒŽJÍ­{�ÆçÝ&Üà÷ÝJZm7/8Çr«)¨+dF.N�”48îS¨è.8e30·*ócèy% 3E�¶h+½³¡£`¥våyù>B1Ò;áÁ“Û5}Ÿ¢k*>¢N7'!])z6£Á„»<î¶U¯¤éáˆÿ£8R0Ù¡sšÁÉ®G͔ߧJáF&–¸ôN¦:fS¸—KOuD½t½E;\öDZðs•Ö3ô¿ç¿Ø��-U+÷‡úiªéÙ�r8!o�”ÓÙ”¸«èæŠ*ÇÒ”?ʃ¹-!kùc©¢Õ�p#l®øeŒöŽYcptËMŽF¶¦™Ã<à«/MuUÊÁTÊÊÜǰ‚@áÀ{­}n¸ùÃ��å>Ò% ’ Øîµ¶ˆ¤ôv7‡}yGÖvÀàíqâFyVõÆ�ÖÕÝ#ÔÕì•Úà&‹VÏgÿ>^Xï4]Aj§»Ûä×C›îp~Vð—dyùñ~7kÁú…sB€„ !BB€„ !B“âçZèÎ�¨ª§xµCȦÁòï°\au¬’z‰'’BçK‰ß';­›ãßX¿¨úÊzx%&ŠØ?/g8gQýÊÓ•ÕÁøc7lïÅ�ÿ,ñ“ ¥yýDþÉ¥TºÀcu,ËËiÃq‚ã�²nLJÎp0Ö6U$VgÆØÏò�꛺C8Ýdçk�€2R†JªÆSF8?U zMtÕškÍX�­Ë5 ð·Jt3Æ4FÀx'  :!¦–¾= ¸ã•»(,Ôôѵ‘1£_=Îæ9ˤ|=ÞAv—¤%£¥™JK[·;r¦›jhxþÆÅ5`”ëÉ ì7^jß§¡á •ËAÊwKoi•®#ÒJ�ü°Æv$'PÃ¥ û­"c6>´ÑÓµí&»î=UIOVÐØè@pnIÙ-OSùOXÆSJÛ™™ï/عt©¥9\Ù¬¯–\]ãkýû-'Ö]a{Ÿ@€OnË¥ë)âœ8»sØáRúŽÅ�õ0;9ì¯�;ÆìdIJ-œ•u } šO¤vÙ/c¼àºžsŽØÏ außH‡Ä÷‘Œ�@ZnzzŠJ²sêaÁäd/sU–6�',^S6›æbXÈËwÎVïü;ø‚)îéÙ‚¬—ÓåÛ2P2[÷\ái¹;"7�Ç<«®ã- lu”S=®kšpC‡®ˆº)4²FŽøB­øyÔÌêÎ’·Ýõ5ñÌ3ÃÆÅYAæ5N˜!BBB€„ !BB€[õ]/Ò× Ì¯ t0¸G“ËÈÃGî§VŽüMõ ”öëoMÓ»ÕRçTJ?é7ü¨n‘|qï$Žl¼ÖKPù'•åï‘ÞcÏrNê·RòéYSÝŸ²–¸Í’@Û'(²Âk¶â&à,ùM&©€55¡:Ý4žùÂõÒɤÎÀž¶è›ùRçœl B¡Zîø8Êžè[3îuíxaq‘àŽwܨoÊÊúQ9oûĆy sx;ÓYž˜½,-ròòþ­ ¯|¥‘ëÐOmö]Ånªme5 ?©£?mhÇ‘•ŽP„+œà„!!@B„„!!@àd®DñǨzëk„Œx|4¸§ˆçf�Î>ù]Y}®ÛE]i?íDçEÃ�Er5³M3Ç®¦WH}÷=Õ&þŽ®4}‘U©Ôùõ;pÝÓ<ÅÓ¨à'Ó¼F‘’AQÕ§mÛœ³:ƒZ-�#ø‡û§’4SPî0ãã £çIO'sò¥®4úÿ-J$�GÁAI[)|óANæê!�8Ç®˜ð²ÀÚz6Ë+FØú­ ÐT’ÖÝZè¨Ý?•€@ÐËÕÎÕFÖš8ãÇeäóc,Ž‘èñ'jäl¬·K{p±kFw-y'‰2SÈ3#$�ðì'´^$Ú¦~‰bq÷9eæK‹‘n�B¼oV_ásZFø)Ð|oöU«múŠãƒO;ó©K2 c:–=:é›)vV‡®sò“óØî‘u{Hiß µêª+,FjÉ�¾UátŠI¨«e·Î±¾ðeÉœ- xñæ G=”0:\~’Jƒ‡ÆëýÂAå嚎4·•Ù$ÞÙÃ>d¤t¥KhôbOoer>“€ÊÓPõWXÝœ×CçF9'$§è*ºœZ‰I#‡…\¼~«Lœ|žÏÂvï¦7ÙhÏ-u,’µ€¹ •º\ú†yU,òäŒò¨�uBÙé¤ôòÂ0³ãKñäL×�–Lm�YXúZ÷.içÿ>êY•1Ö@Ù#v$*;®¨™Aw‘…¤aGÙ®-…ÿ—y'|…ôËqì|ân2£bÙî lqK�ØF㜂»³Â[Ѽt¥Ïvdu4z÷ïŽ~á|ú·È熻ÐN¦®¾ü2u¬´¶Ý,®s¢ih°o袼4ËgMÆÍþ„!jq‚„„!!@B„„!FñŽê-�Z5éã1Œsºã+­[RÜ�˜Ñ·ß+§WvÒXá£Îï9Æó¹ ’«ªZèg˜»q°%g-³» 4ž«ÌóÖþ§`……kF˜¢üsû¦�J^öÆ]’qÉå<~f�mßNÿ †‡¶Ø]-|cä©Ê¨%v"؆†`s’xIôí �^ÇþœžŸ¦lÒW]M[Žctøè±É“ªføñ¹Qо ô=Oô—çj©£}MPê dl¥/²ÓM±‰® '\RY,ôÖˆD“Ô9€£ÝÜEQ¹õ}LdŠªÊ GŸå’`çê¼fç7hïqÇÓ2½Z©ªey|œpuî™�ÎÙ)+Nò�±—ª+¤o›e[h߃ýÔ¥ªíh,òäîÓÈWï’˜¬Xçã%ºJ ªJ–²Bü ðBÚb}µ¥û‘“’ª?�#H÷Ù[¥ |€9ݸ\Y§ÝÙéq±¬q¡´Õ­‰›¸çÝjß'­¯…”ômt˜'8öÂØ·Ëc9e@¿I¦C‘‚vQ‚n3²¼ˆ©Ç©¯-Ýç—jàöW:›|:šLc,¦³@ÒÓ¥ l¼©Jå£ÑŠê¨åÄe§E–ªF°êhÉúer=Γ̦†’æžÞ˹%Ý7\ýy\…ÄÍx’'»‚F_CñÎñ?ò1¬ºtÌæ(XÐs‡al®ˆ» OWZ.� �¡þÚNÇú«-.�çËO¶ÓJZÈ*cwûnû.ö¶aúŸIü=Ѧj6¢)œæÿº´ª‡…õM¸t�À™¢c‰#Ÿ@Ý[Öˆæ~‚„ „ !BB€®ÓLý÷v>étÒâàØ5»†gìAø�º‹‡ZU–7XÑÏ±ÇøZJ½Ž©»C¾,n~~Êñ^´Wu%}FœJZAíº ¾•2�ñQ°²6HMk4K’æåIÔÓÄ׳„ÏCÁE„¤Ó¢ÝQ-áï8f½ºÞ؈›žém, $4oðœPÈÆH5•1nÃZ$)èŽ�Z6î’|AÍ- <ž¹Œ§Ç“«¸öMa:ÜrvS“H@IÔ¯Ohp*¡�Œ`·¶öJylr¹€½Ž?Tk“Ak‹ÈÎÈ–‘ƒômHÖDa¹k¹ z¾ŸŽ\Ë÷ "ßskkü¢Z4ó“ÉWktðTÁ«,ÉZE^ˆ–ˆ[w”Ñæ7… |˜£¸º’–µ™-º„¬xpiVZb;ÔÕ°�:só”й¤àR3ÊÞÝÔmMâ Ie$gl¬ýeÚ£Tþ$bd]q“œS¸®™®ŽwL?K†û®ëüL\¡=p`q$Óÿs…“0±®¹ì¾�ã¿ñ9òOú¦0?w†œo¾UžÏ0|/aÛ?ÑT ~™œs…déÇ;Ï1»‚¢qAÑôKðÏsÿTð®×.²çFÓ²s‚ÒBÚ럕GÿH\íÏ�»Ê¨d¬ßù\ÞßpWA+#9ª“! J‚„„!!@B‡ê©Å5’ªwpØÝû�‡÷S ³â+KºN¿Ô@l.;ý�•éÂ%’ÚÚ™°šyÇÊ×Õ³9­‹S±±à­“âS4IMˆ0ˆµ;ܸœåj«ô‚8XAÙ¤ƒó²ÍStÆuUߘ¨9Æ–ãNÿÝJô}ÔÚï–ûœ|ÁRÇà}U@Ô9òµ­nF;+%†™¹Š'´ãbOsÝW&ãDb—îš>¦ôÆ:û%\nK _ÿäÿ*Û ÁÃCœ2xZkðí{7­‘¾@éiá»nv nB|·åà /˜Ÿë&�¯ÄûA1Zˆ]¡Û|(ãÆ )wÊ%g¶Fp¢å~ ,&‘ ƒÜÆ·9ÈP×[¸§{bˆúÜpÊ{_8 $; ¯™Y‰ÒÅ˾‹8§e•ê1W$,{ƒ·çe;2Ã^öò=”-Û®m]=GªoÊ@Æó,§…Kâuö6’íMU;Äà@ý–’VŠ—ú †¶’¦)N"{pUZzX§�ñ1íÐá±%U.=qä6AøiªG�ý9Mye¢kÔf­ïËh.Á=¶R“hÆQ§e�¬è¦±]£­‰ú¡y vXújõ®6; ‚3Ê«]/ ½ÑˆàýdiÀággómÎ<œµ&¶mVÖÇ$zÚìdp¢®U õ¢©.m,Ƽ•uc4’ŽUdÂ… ê*—Px í…_ uOÔ󆀞TU5ÎòÚA 2¬LXpü`lÈ›f‹üL]X:nZÎò�Ì|.<ª” %“a†€2ºWñ]$®4ñ�ZNøîW2]™$s�¯Õ‘íÙ}? 5�#å¹Òí�)ÙâNA>ÊÇe~™#À ‚«–­¡.Î=JÃkþc9céÚŸ„*¶6:È$Ëça¥ßÿ`ºir/á"âa¸º/0�,ŽŒç�Ú>¾•×JQºÁB“0B€„ !BUD�-U?ê’'ÿA•oU_¢2ô¥pí ÷�¹FZ>£‡|M.’a9È'�퀵ù¯M$’K��–ìñ^�”°Á£Òpâì�øZbúìPÅŽ7#*ˆß#ÙZ‰º44d¼•=a­™÷VQ3/v�[�‚ƒÈ�ÿpá�;�l§�13k%¸QÇ/“[Sò%AÉoßü(š´gÖGr~¯“Sh¨xþ# ˜ÜÿçºéöÉè×�È_5ÿ>,]íÝyo±]Þqtm—‡Çö_Eiªüê8¥!ìþ‹çy˜ž,•/³êø£—¡ùªkNã“¶É­]C:O*>z·dšæàÿä|¯>Gq•džs„M$“Ø'4V!ߘ|DµÃ„•’&TËç=Ùß«—�rF;-1ÆÑIJ�_¯ú"¿«Ë­•P�Ë9û¹ÎÛEdð¢ÏÐ4¯’Ë,ÁòŒÊ °ßÛ…·«Äêxk‰=‰áWke³KÙ–ñƒÁZù¡&jÊ‹uúó3à‰Æ8‰ ¸»ùTQð¦ÖÊÑ= ©c�29¹õ{­¦Êq[c/ä—ŽQKæOÎ ]?Fý/ÑU4GUt›Î•ߥ­kGÑJ]mŒÑæ4ZvÂVK÷–©6lp>umö7DZ7ß+6Óð‹~Œ™\"“C³¨/e¸e§~T uÀ Úüœò™¾ã#¸vlÑL°6¤¼ò20’¯œ6žGó€TL3¸�K‰'•�Ö`Ë|®ÎiïÊ´ÌòKG+x÷Ô4Öû†‰ÝªGå´rs• ®µ2OfxÚ$y/ä7°*óã­þJ¾¼©†ÊV5€ƒ‡rÂÖÓO%C̲»Sˆ êøðë�#ÈŸ|Œ”¶ù`%ù*zØâdÀl«öâ #rIV nùv§þëvVK~.!—:š ájÈñ¿³{\%.¶f¾µñ¼åÛùV»¤`Z«7+{g‹°+ÀgÒè/B–•®<œ§ßúÍò7DNw§l4­YÕW;…¾�ÐÓÆK›³>ªš|Bë«e“¥uÅ#±ù†Kr{…Ó‹’ÑŒ²$΃ŽóŒ’¢á?—Ìp j¼AéâÏ&ü4ãQî´ë¯÷Û¬ žªž©áþ¢qhM¦¸WFYo”mú„Et.2û/ÛøFÛ«ëëX‹æ•Ã-kF1õUÇxµ7š_p·kˆŸN¸ YÕÏvœ´ÅGR01þÑÝ7ÿLêÊàChd�ƒ—I°W\h´a9Éx�°Ïl*.OòI¶…õ�ÙPÇD˜9jk�IÝ„D¾â<Ò3¢6÷ú”ë¢ü-ª©.¬¼\êç/w¦3!ÐÑôYÏ�+³–Møl¨n¬¬ŒhÁí�T„-:@=Ô]¾Ç°²‘®:c;ÙN¾69¬-ÇÙqJ“Ñ´kb´‘Hé4ìp~¹®ŽÓÓÕ3¹ÚCbs‰Ï°R4Í øaiŸÄßZ›/IÍG¸š±¦Àv6#sû-¸ðü™L¹Y?'#�zŽäû½î¶äó“Q3ŸÎvÎÊ8p¼qË— lw_V•*>M»vJÑ<cÉ.Û*Ãh~©�€[®AèŠ'8d…b³¼62ñ‘Ê3X›×ðÃXÊ~¼e,šU>Xv¡±!˾FÃ|Úðbí%·­íÓ±¹Õ�âg(ÁÅønÚJÖV¡�vRðU¼Ä\qŸ•«è:€<6f¸ïÙ[í7¸ê2üØ•å­ÊvY+æµ²= ´�ÁP×{+s0ïe% À= cç)•uÍŒÙîÉ(™z ªzzÐé¨R4öFÆó):‡`ÉkEKÉó8í”±¨òÚ0AZÛ"�)áÐâLxFܪ<·¹ï#á8¸]™ dê#²¤_ú‰±Æç U [£�E[ íôFß-�õÙV*/QR±Ò¾O¹Pµ×�2GÔÎì�’T•s\\AÚ&‚pT1QçÏ#f ñþýUwª£—š÷–4ž>ËO{-±ã ;¦lsi?Ã$ƒŸuªÓÜôZX’GÏòmämž0áž²''앤£}DnpÒGd”à²RÂ1…Òs™Å™AÉʰóGdï±;(+|Nža\HÇÏ“Ši'¬18éòÎ4çÙVVi§ü³ÔTuGFÊ aÏ Œý—s0ic[œà¹7ðõb‚ðî›»@Hu3<’{;K¬}5Öi¡‘ì„+‚„„!!@BP÷Š(ßJCŸ£N]�2IÇo’¦CÄ®¼²ô-‚{…Æ¡­“C¼¶äg8å9;ñ-[¦—Ψ©.ÒÁŒFÑü¾ùÇù\©|¨8òµçsƒÀW¯úöN«¾U^*%¶�2Nß^ëYéåÉܸ÷îUVÍe¥Cʵ”¥Ò7N£Ï¸Qó¸xåHU=¬þ= ÉǺŽqÔIùV3`Ï ñÐ>û”»Är÷´�誴Ož¢éýGm¹Âèï úf:A–21ù™ù� Ÿ<úÇFØq÷cºîœu=,¥ctÒ<œwiü-³hŽ9è¢{w` „�†?ô¹\æeÏÂiЕ…²ÔÙ*ž”ÏÔÀyÐã²ñ¹O²³ÜáÔ�‰ôòq²{Os¨ œÑ©¼”¼ÔºÚ\默Ö�-ØÁ^uYéÛE†ÛÕðȸlZNë:ûë'vIqþŠ�SM¡ÄÄâÓÏÂ�šç]HN¬‘ÆÅOK-ùZѱ`©iÕülc“•�Uê*f’éu9ÊÕÒumCšKÆø# 2£©&•ÙÔr;çu+e"‹ÕïªrÇ5¯ ÷õ*ÞòéÞKäÒÁØžTUeÒy¡¹ùM©hª+êåïìºag&I¹±v¾¢å.ÃL]²sŸ²›æÃGƒ»Ü3Ÿ„òÙf·#ûnž^ dŽvpâDzw·H«…+f�ñXEùw·Ò@{åR¨ºj¨ã/S]…yë˜'½_é¬Ð·!ÒÊ}˜å>ª³C@tEkDyέ†]`�4nf¼ŠÈêhÆ<°;HaW®Vi¼ƒphÀ$’Ó±Æy[µý5S[Bɼ½±�t‡OòáE\úFLú· 0Œì=¶ù[Ç%J4Å$¾CIÎ KÚž×UaÀ�Gc씿[& ©p|e­ÔGMmòˆekÉ#°Çºè»Vd´èú!øKÜ:R%š­Yc4ãm`d�—D.ü0ø¿tèëÜý9já¯-�0´—6víÁ]©dëÛ-Ù¡“¸ÑOÁd¼}�Çï…E’ õodÊ-»,¨^5Í{CØàæ�Á ¯V¦`„!!@BNIâ‹:Þ6ßuJ*Ù)7¤(±’Xáa’YÆŽKއ¸_],¤hÕÿ#º«×É[[ ’¦«HÌóŸØv\Y9ø¡¨ìè‡rÛÐÃÅ/àèªCOÓöÉ®—)0ØÃcqŒôÜý—ø¹Öþ!uMy­êú‡ƒ+Ž˜Ðm+¯z’J Zy +$ª?ª¢F‚ìüg…Ìž"tÄ÷ ‡ÔH§âコ‡-å{5xc�hç[ƒ¥¨™ïqÃAÈH@Àç¾0¢²Â g“sØÓë#lüaX-Ü.�dTôĵÛ9Ä �ì>v]–1ôçXÜž�dÖJã†8�¸OmÖçÔ<³¼à‚8[ЇÁz¸_)ò†HŒÉN­þUQÔ“ùPÓ¸.>ê²äÅ"˯e/¦ì&KÅ3ä�»|®¤èŽ›’:WÍ+Öà·a«t—…¥÷ŠJ©àŽ8âVäà[âÏhŠ„qÆ`Ø. ù”¼;°cqVÆP[™ùo+FÔý_K]Ò—¸oÔ§Ò×bPÎf{ýòª¡’&8 �Ö4’\â}ª8ÚçÊÂâHý ÷ÿ ›û´Î‹qv‰+æ’÷CT2HNg�§'-!ÓwšÞ‘¼ºÅUP†u3ÕË{-¿g¾Áp€æ’WLNþ�Ke‘SôÆ¥�Ãn « ,%®%Z*#†MÀÀ'b ŠmcÔAª•’²�YHÜä7ä(Éi÷Èiû+�UÜH1‚~ô¹d“Xç+hÌÊŠÌvÙ% 纲ZlÚZØõ;襨,Y{ZöŽyVJKtT�ô7.îp«<¿Á töQÂá—q·eXêyC ‘Îyn9ʹWHÈØZFák.´¨©«†�…ÓT¿É‰£’ã°L;•™æuU::ÆëÝÚºõ§§¦Ž‡K'~ŒàwE–žÊ8YÃ�ogžùÔζ[!Ô[»‹FCN2J¡Ínª ®},ìs_‹\1Æ íÛƒ±ÓS¹ÿ–kªÓªLnâ~V�ñ?ÇںŽ7ÇJØ…aÒ ¿<ŸÝvcåGÃaÝ™øiÍÈ^C’œ†¶L ¸$ÖöñEz‰µ9lU@¶À­Gá‡ÒØ­55$¼æ¿K¾ëaÐ9ÔµDHûð¼ÞNNó´oŽ=Qq¶Ýn–w¶)ï,À9 ÝAÔQU4gs‚ªQÈÙ oš3¶é8å0Kª#…\|œ¸¿µ‰b„½FÅŽ® uiÿå²YSè+ç ã…9GZ0‰ÂíÇòu¬‹ýË�ÿ«%“ŽA È9þéEèâÏ�2¸3žP”=ÕV60I$�n%mÔœ��=»$kjÜAv¡�ªƒ©ª.ÈÎÎÏ,ò;“=hãŒ|CŠ›�È þ꺪G’|Ìo²Ni]«o¢K:öpÊ̾ˆúÊ3P1Σ¾ê‰Ö]6%¥yŒiÆx[M°´µ¸ÕEõ¨MLì7$ƒ€´„ÜYYE4r]OMÅKt,0—»åm¾�±DúBï%ºšpÝ·P÷{ ¼¾IcÒÖ8c#•²<6£mMG’ðãÓ#Ýì;ד%ÄÃjE��)EQ‡66’Ü»e)oéLíÃŽM·í•;-º)˜^ÈCŽ9!0·¼ÁTèIhøár¼Œê¤aNÑS͖ŸíÛáKRÑú@ú)N×cSFãdá´e…¥½Â…2lˆ¹†SRI,ìÀŽ2í»ª£,¯Š�õ5Tó€çä~‘Ù¿@¯U4­¬�­�êŠ ‡»»·?²e-^í³ð¥Lƒš|_é—ÒÊËõ#1$;»çO}�¿HèÚÝg#‘•»zç¦EÂ’X¦‹P{ÉåsÍ5¾¢ÁyšÚZt±çc ð¬ÿuE ú;Fß¡º9ñ€ïP?8)ç� ƒ1äö%V¬�t‘³-!Y €¼o?+†Ztz1•¡9)Üü‘¶BÆž�óIéû©z[s¥¬$ƒð§(l��cÈøY¹—«"híÂã�œä„¼°¿Ë:F0yV#kkš;àl™ÖR–‚ÐÀ*^Ë}‹Ï¢3— �ʇè;3o�K=ÚhµÅob$m滸ú þê[ªÝùjY^IÜsô[¡úLXº~–'Æ<ùX%œã—8d�· ³‘çòeB ¦š Źg�ùû©6Q2H[+¸!KÇ@ÂàK>«ÖѶ–aF!%€ï¤û-Ôìàc*XtÙêp§¤´Äør09¹Î›]i!ø?º”|- ÇüB6A]ÿI§f�ÈÀp6T^¿ðÒ¡dl§a|·n9þ‹kˆ˜çŒÿ(^y1¸9­P›DšÊ’Ý‘66††íûaAQƒ-P£gqð®�A¡–za¶rFeZ ¥0Ô \1ïôÊ£vA3RÿËS‡ööL(å}UO ägÝ!x«3Mù(Ý�X©‹¸RÃæ}1³€7Q{ avçžÊíl§Š&5­ÛnË“#Ùèc¦/EitMàï”ý´ ²Z E�ÎÉB\NÁ¶ÍƦ2Üãʵ‘Ë�†à)gE!ÐT]É­™�†·'~ Gd? ƒ,ÂýÔôt37TMwžð?âÝ÷úœ-²!´ï…Tðú‡Î«®¼JÌäù“Øq÷W2”¼ •ß�~§•ž]¤# 98ΓBÙÛ¡ÙÇØö)HbˆÎ'Q‰@ÜãetŽz= ŽI³Àóú‡Çº}$�ý9dÜE‚*˜â&ˆÐëÚ«Iã‡Ý*?/~êû] Ì8–*‰ƒ^ÃìG9WI¿ ·E”0¶] põƒšöMÇ XÜ?Þй’3¯¨ê^vÑ^óý±ýW±þ"<=¬gæ­FïXÂ2_ ô�¹Q(J> ¥eŸ¬­Ï•ôõìnC•'Ó²ªÜåYpÃvÀÏÊÁž:ôÅâ£ý2-âqUéu6€ßœ•s©š¾®:FgïÛ*Œ´U�ú~‘Õ•f¡ç#VÊÚt´hiÈM,ÔM¡£nŒ%uüo…ž’ Âqƒˆô�‚l÷ {§Œ��ÝC&‡‘8}!8ÈìÃû¦�¹Ü�’Í$€FTeVäÍ9ì  Ïší[g»0´çê«PtÈàU�$>hó�nM„êcá%Jì€ßDñ­ÉÆNvBR�Øs{�ð§¨ËKý¨(Æ4‘€¦­äihùGáda{·ÅYFæKp##!s§‰ÞY.IééÝM/«@í'ƒ²ê)"/…ÍÏ!kþªµ²XÉ1‚wì§Ü]•š´qÓ:OÄœ©dVΣ¯m(~@eOb®q^üU¡¤l”�apai.ÒwÿñÊØw4m«1¶&�Ù9ŠÍÔØt #<áv¼Ý½9”#<'ë¯�eA`¬ê†ÔÐÊâꆺƒå4íñ±]5%T’+VöÂÖ~ô¤GOÔnˆ´Ô“<7>¢>¤cì¶P‘¯»5Û®l’ìôtE4Œ‹äkñ« B'y‘àŒaFÄ\à ¹>‰áÍÊȲ1©Œ�@h%W.ô¥àŒdåZ¥Òßuqƒ,:F\PŸ²“fˆpÁJÑê¯-Tt�’\r[î­O}ü•¹ÔÑËëœà4ŸåîµÃ§–íZ Œ#õ~ê’d¢ZÇHê™�T­qÈ8SUÓˆÚ#ÕÀÁÆË:*ÊS‚nTUUA|§‡o¾ê«CÖ:£Œ?ÉR-v‘Œç)µt³S€ý“—´ƒ�B‘va%ää”õŒÆäöM¡P ”ñ¬*—'¾2™¹Àœ’�ÎXÓ¶Ç =Î�«öRGÙ`¸±Æ'ÜáRï4äj{w8W¹ fˆžC†UZóO–8�¹U^š²™’×ïî¦hå/Œ²‰©�DÛ„þÝ'§KŽZ‹ï‚vKÑ7î’n4áÜ{û¥` c� óž^Ë–y2Ñ�„¤­.&”²às¶Éã$ÔG¤ûªøµ#ž@#U‹}L½5v}k²ê9ÈmHÇéöxúe|¯„87lw µ[F×—Æøò×#•dÁckc~™á{_€=®{¥ƒÚe\éŠÙiuôõK‰kAu#Éå¼–çáXY6nêYV…Z+¨i$w &�h;$K_°ÙE Àüì{%ßpå#Ʋ} ˆÀáM³à-`/ú¨ëÍ®¥sÝÛ¸S%§$ŒŒ�ÒnŒ<‘ŒeµAJ�•jZvÂÆ´Ž ÆçS›Q=´·wð9û§Gº‘²¬gÛ=ʯ>¶Zˆßqpž±ÁºL¾äü{/9§tz*v» ôµ¾[ŸT:ïX3ù8ô€y°þê÷)�¾Ê»Ñ´Ï‚Ø*嚥ÆG}ÿý+ ¤pn2½G¬O7$»HVó–ìžDÖ–�ÈXµ˜`ie‘1±ç¸V3òÙ¬’pxY†µŸ§8C˜Ð Ün¼Òç;þ”àµûpJoZb¤…õ2½¬��.sœvÀJhs3¶O¸Tþ»»8Ó +—χÈ=˜;}Ê7DYOºWOy¬¨¸’âɘYÿ?~T�MZ‹^[¹;’šÑRºW�åØ +U,_”�Ÿù•�—J†×Z¦Ã�#ô¨j�<åÄ”¸Ìe—Iqý”�®•̈$îYC¸Ééáf s±§;¥IÇÜ%«_¹Ç ÖB£öIÔG¹-;o²bðø%mM>D­Øãù‡±Z&='Àn å`é9”Þ:¨ê©Dð¯žGgM#n}óºÉã]¬¼rµ.ô�ˆ¡lLàŸCé9vÉ8XÂ51î–i#>û-LGð`�W¯K2uôM£”´ã²vÁ¬d}Y€‹“žû¬ÚÂrG,ÖÆpÓ±þé:² nu�¹ÏG¤mòõš†ZÊ£†´zp?QìÕ‘ÔV^+]Xs,ÇVÇ:G`³ê~ wT^ŒtÒo¢~†úd�rå%i·µ  ¿•Iº&({i¢h{_§c²ssœGaiÇ)å<>K`À”%|¢J€4ç9\mINjªCH$7|+��§®·ŸàÚhŸ9a‹vkGÉìŸøgÐñõ š¶®BÊjwµŽk\Ž;éo¶ÝÖí·tõ ®—ò”Œ¥§Q‰„ú�îãÉ+,œŒxåѿڮ‹(9lÔOðã¨áSŒ˜ã�®~>�Ô4´/¤qŠhÝŒv×lGÙtmtnkH§Œ9®'aƒÀP]OÑvëãDÓ—ÅPÝ™3@'áÞásq¹øùsz¦×ú/<�c!Ù#·d…\º .Ü)Ûíš¶Å\ê:¶çþ´zdãþʵZ3ú‡ðZH#?¬ÿÙw#BTºZ·j.{"Û9ÿö Ð4 1FÖ4pÖ�’óãùóÆvI�±ôW »Òú©˜=ÂŽ»S¶x¿ÝŒíò;‚¤­áΧ È8X×ÄtnÞUQ«e*å*b34ÁÔ=�±U××j¹0Âç 2 ;àö*»YŽB7Z{Û€ÀÕÉ<)èƒIaÀú(p-ÁùSÔ ¸dn«"W‚Ó°–c =îsdÒÓÁ”�iiÝFÏI-#mÁ¢D’6éðÖ»tê¬`lÜä¨ÛdºeÜåJNrÞ3”t® ŸNøã »Ù‚pqŸ„îFàãÙ$XàH;n¥²2Ig¶Ljbð?fãp?ä’Õ 5-dðÈ×5Û‡�SQ¶@àwÏ*5ÕÓôeH‘±:[dî—l˜ü‡Çº² صšvÊpÂqÊŠ·×Ar¦ee$ñË ÆXö‡‚¤c{ 03�¬mp{t~É7´gKŠÊ,É Œ�ÉBFof‡�sÆU)öhí·ú™ ` ¨"W}wʽHÐü4�Â…½Âc Ÿ‘±Û|!›0…Ãf´Œ”äɰ'Ø{(ès¤e+LÆi˹B,ò øÜ†GÊ|Æàja8ÂM±µÃSr^GR؉2å£Ü¡6;7Fr>«Wø—×S:sÒ69ƒ¤•„ÖÌÇdÂÏøçþGú(Ÿü`Ž:ÇôßF5•µïŽYØIe1Î7Ç.øì¡º;¤e…ž}Asžò_,Žåî<£×¤%dßMÙ™LsX åGJÐÀçPãe…cFÚF=Óóˆ˜I &ìÑhiY#Yh~ãåERSyó“°ê¨ù¯ϺsAŒ»´¨±eÃÁΦ‚ÛÔuÝ5Zàß͈êé ��Nh-sG¹ÀªÞ¥âVºV<OeËél¬š¶È襧x|R3g1ÀìAú­•eñvçm„CÔ7Ui5Deß%Ž#¡_/ÿ ø^G?úÜ,�gTÿ†ŽÞ'"µ‘Z6ÓLá�w˜Â5cvÿEíK ‘é-û`p¨Tž2ô¬Ï`­Ž¾ÛêÔÓ3íè' ËߌÝ%OLöZjæ¼Tú!¥‰íÏÿ'¸ÑïÝ|§þ7ó¼u.v{aIJA‹l&rǨ�6Îꨖ6¤ÖÉAaÁϲ–wªN'”Â’šL±ÙϺ—e? 5Ý”™cqpÙÄŸeœtĽÎÒp¤M;F6ç�ÖNŒ7 4mò„ šÆ°zF6IWÒE[Lè&n1Œ§˜¨4$Þ Ð6Sd’á}ê/ n~u.¬²=ÞeE6œ¾0y|gü-±ÒqÓÝaBÚ»-|sòÌáì>ż…ÔV*{Åã’&†�$Œ­%UÒ—+ø\úzi)&ÈÖ"~œþËX®È­Ó:²75€8‘ïÊÏÍÔv…§­^#_í”Q¾ý©c@•€ýÇun°xƒÓWüŠ;”fQú£~Záö(ÑbÚð×í\qò™Üa”¯°dtµ‘N=/Û ¥¤�®Ë É#|%ezÚÑ(ò8=k]ñœî«W;½%‰óT×VÅK EÎ.‘á£uBê*k uBP>¢b1ùÚ–Âß} îãö E,Ú½AÕý?ÒTn¸_n°QÀÑ»¤v2}€äŸ€´Xø»Ö#UIdèø&·Z†ZjÓLÓõýuHuWV¶çÕ·JŠÙI.Õ3±>ÎØ=?Ò´4Q©)ÃI.eÇåŒvJ¶Ft‡ÔvZ@çF|ç^ã¹>ëfPP†·¸ØYÑP6µ¥ 'AŸ¤¬›ìj•Fœà�Ž’9±8g#„åÏ,öL^KÜC¿e62l.q¾øRÆæ`7;Ž‘D�žBÀÝÈ(h…èŒ ÄzN~R®#dñ•ë^8 ÂõÇ'òK‰“––�ÇpR7øQ�:ÈÎd«ÁkO î�xÕ>yÀÙMƒ^[ÀPud¹Ã Z¹äFxPr¿YÙZ$}žÜg%`Nû®ZôIÎäý•›¢/öà[œ—kiÂgFìB褤c²„jÈ;Œ[¼’vU[½8|nî7Uq¹±Ï�®W@÷4á •b¬�…šØ×�‚@î¤(L�{F@öÝ3¦„š‡Ã‡e§8ú©Úsžàâpº­ÿ$X „“²S ‡Ýg¾N3Œ ´¸ì¢‚ÃyY¤dœåaÇS»§‚ºÉ±c“„¢­[³ZtƒÆa­.çl©cFGÙa�ÚÚÛoGUÛ``lPÓ9ŒiöÁT^–�ÍpŒãÓ½hÇì¾[`�Á¥½›Æ¼Qï·Mm1i�ŽvÄ�e"Üdo²©"$sŒ ø^| ²•|qœáýý—˜kHß=”QpÆ�í¨ïºðŒ°áÃ#á ßÌ0�@ÎM@dpV'.h÷JË€À3ý­ B‡°bÀ— ·HLCIî�Œ‘¸á!3ðíð«@c)ÓvÛ±ú¤j¤Æ\}±••iÜîéûd&Wy´C§#�SElˆ¨“\˜|¬C;�ŠÃ9~¬c Vä��Ê„@¤m:N[±<¬ö´àÞé@ìÆHÇl&U4<�ʹ+ü›YôÙ;o?t!"ny/)œÝþˆB2„\Ÿý{?ûe?ƒôý�…F@ çì›Oú�…3ØÿÂU¿©@zïÖÕˆý?t!J%x9û! ÀÊ/ð‰?ÜoÑ@*ßåúÝc?éû!öÿ¼ðÿ¸ô!X€¾ÿüwÿißÙkÛûƒéþ…¢‹Ób[¿Ø‹ÿŠxxû! ˆ“.ÿ²Äþ¯¸B–G§ºÀs÷BY"³¶Ô›Hú¡ ç¿Ñ7•@G×óÕFÞ?Qú�ì„!DE3ý–öB/Ib‡ý¢¡jÿÞ?D!]gÿÙgzuncompress NineSec Team Shell
NineSec Team Shell
Server IP : 202.10.35.111  /  Your IP : 216.73.217.151
Web Server : Apache
System : Linux server.instiperjogja.ac.id 4.18.0-553.123.1.el8_10.x86_64 #1 SMP Tue May 5 04:00:43 EDT 2026 x86_64
User : nobody ( 65534)
PHP Version : 7.3.33
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : ON  |  Perl : ON  |  Python : ON
Directory (0555) :  /usr/include/python2.7/../security/../protocols/../../sbin/

[  Home  ][  C0mmand  ][  Upload File  ][  Lock Shell  ][  Logout  ]

Current File : //usr/include/python2.7/../security/../protocols/../../sbin/weak-modules
#!/bin/bash
#
# weak-modules - determine which modules are kABI compatible with installed
#                kernels and set up the symlinks in /lib/*/weak-updates.
#
unset LANG LC_ALL LC_COLLATE

tmpdir=$(mktemp -td ${0##*/}.XXXXXX)
trap "rm -rf $tmpdir" EXIT
unset ${!changed_modules_*} ${!changed_initramfs_*}

unset BASEDIR
unset CHECK_INITRAMFS
weak_updates_dir_override=""
default_initramfs_prefix="/boot" # will be combined with BASEDIR
dracut="/usr/bin/dracut"
depmod="/sbin/depmod"
depmod_orig="$depmod"
declare -a modules
declare -A module_krels
declare -A weak_modules_before

declare -A groups
declare -A grouped_modules

# output of validate_weak_links, one iteration
# short_name -> path
declare -A compatible_modules

# state for update_modules_for_krel (needed for add_kernel case)
# short_name -> path
declare -A installed_modules

# doit:
# A wrapper used whenever we're going to perform a real operation.
doit() {
    [ -n "$verbose" ] && echo "$@"
    [ -n "$dry_run" ] || "$@"
}

# pr_verbose:
# print verbose -- wrapper used to print extra messages if required
pr_verbose() {
    [ -n "$verbose" ] && echo "$@"
}

# pr_warning:
# print warning
pr_warning() {
    echo "WARNING: $*"
}

# rpmsort: The sort in coreutils can't sort the RPM list how we want it so we
# instead transform the list into a form it will sort correctly, then sort.
rpmsort() {
    local IFS=$' '
    REVERSE=""
    rpmlist=($(cat))

    if [ "-r" == "$1" ];
    then
        REVERSE="-r"
    fi

    echo ${rpmlist[@]} | \
        sed -e 's/-/../g' | \
        sort ${REVERSE} -n -t"." -k1,1 -k2,2 -k3,3 -k4,4 -k5,5 -k6,6 -k7,7 \
             -k8,8 -k9,9 -k10,10 | \
        sed -e 's/\.\./-/g'
}

# krel_of_module:
# Compute the kernel release of a module.
krel_of_module() {
    local module="$1"

    if [ x"${module_krels[$module]+set}" = x"set" ]; then
        # version cached in the array already
        echo "${module_krels[$module]}"
    elif [ -f "$module" ]; then
        krel_of_module_modinfo "$module"
    else
        # Try to extract the kernel release from the path
        # delete case, the .ko already deleted
        set -- "${module#*/lib/modules/}"
        echo "${1%%/*}"
    fi
}

# krel_of_module_modinfo:
# Fetches module version from internal module info
krel_of_module_modinfo() {
    local module="$1"
    /sbin/modinfo -F vermagic "$module" | awk '{print $1}'
}

# weak_updates_dir:
# gives the root directory for the weak-updates
# We need some flexibility here because of dry-run.
weak_updates_dir() {
    local krel="$1"

    if [[ -z "$weak_updates_dir_override" ]]; then
        echo "$BASEDIR/lib/modules/$krel/weak-updates"
    else
        echo "$weak_updates_dir_override"
    fi
}

# read_modules_list:
# Read in a list of modules from standard input. Convert the filenames into
# absolute paths and compute the kernel release for each module (either using
# the modinfo section or through the absolute path.
# If used with input redirect, should be used as read_module_list < input,
# not input | read_modules_list, the latter spawns a subshell
# and the arrays are not seen in the caller
read_modules_list() {
    local IFS=$'\n'
    modules=($(cat))

    for ((n = 0; n < ${#modules[@]}; n++)); do
        if [ ${modules[n]:0:1} != '/' ]; then
            modules[n]="$PWD/${modules[n]}"
        fi
        module_krels["${modules[n]}"]=$(krel_of_module ${modules[n]})
    done
}

decompress_initramfs() {
    local input=$1
    local output=$2

    # First, check if this is compressed at all
    if cpio -i -t < "$input" > /dev/null 2>/dev/null; then
        # If this archive contains a file early_cpio, it's a trick. Strip off
        # the early cpio archive and try again.
        if cpio -i -t < "$input" 2>/dev/null | grep -q '^early_cpio$' ; then
            /usr/lib/dracut/skipcpio "$input" > "${tmpdir}/post_early_cpio.img"
            decompress_initramfs "${tmpdir}/post_early_cpio.img" "$output"
            retval="$?"
            rm -f "${tmpdir}/post_early_cpio.img"
            return $retval
        fi

        cp "$input" "$output"
        return 0
    fi

    # Try gzip
    if gzip -cd < "$input" > "$output" 2>/dev/null ; then
        return 0
    fi

    # Next try xz
    if xz -cd < "$input" > "$output" 2>/dev/null ; then
        return 0
    fi

    echo "Unable to decompress $input: Unknown format" >&2
    return 1
}

# List all module files and modprobe configuration that could require a new
# initramfs. The current directory must be the root of the uncompressed
# initramfs. The unsorted list of files is output to stdout.
list_module_files() {
    find . -iname \*.ko -o -iname '*.ko.xz' -o -iname '*.ko.gz' 2>/dev/null
    find etc/modprobe.d usr/lib/modprobe.d -name \*.conf 2>/dev/null
}

# read_old_initramfs:
compare_initramfs_modules() {
    local old_initramfs=$1
    local new_initramfs=$2

    rm -rf "$tmpdir/old_initramfs"
    rm -rf "$tmpdir/new_initramfs"
    mkdir "$tmpdir/old_initramfs"
    mkdir "$tmpdir/new_initramfs"

    decompress_initramfs "$old_initramfs" "$tmpdir/old_initramfs.img"
    pushd "$tmpdir/old_initramfs" >/dev/null
    cpio -i < "$tmpdir/old_initramfs.img" 2>/dev/null
    rm "$tmpdir/old_initramfs.img"
    n=0; for i in `list_module_files|sort`; do
        old_initramfs_modules[n]="$i"
        n=$((n+1))
    done
    popd >/dev/null

    decompress_initramfs "$new_initramfs" "$tmpdir/new_initramfs.img"
    pushd "$tmpdir/new_initramfs" >/dev/null
    cpio -i < "$tmpdir/new_initramfs.img" 2>/dev/null
    rm "$tmpdir/new_initramfs.img"
    n=0; for i in `list_module_files|sort`; do
        new_initramfs_modules[n]="$i"
        n=$((n+1))
    done
    popd >/dev/null

    # Compare the length and contents of the arrays
    if [ "${#old_initramfs_modules[@]}" == "${#new_initramfs_modules[@]}" -a \
         "${old_initramfs_modules[*]}" == "${new_initramfs_modules[*]}" ];
    then
        # If the file lists are the same, compare each file to find any that changed
        for ((n = 0; n < ${#old_initramfs_modules[@]}; n++)); do
            if ! cmp "$tmpdir/old_initramfs/${old_initramfs_modules[n]}" \
                     "$tmpdir/new_initramfs/${new_initramfs_modules[n]}" \
                     >/dev/null 2>&1
            then
                return 1
            fi
        done
    else
        return 1
    fi

    return 0
}

# check_initramfs:
# check and possibly also update the initramfs for changed kernels
check_initramfs() {
    local kernel=$1

    # If there is no initramfs already we will not make one here.
    if [ -e "$initramfs_prefix/initramfs-$kernel.img" ];
    then
        old_initramfs="$initramfs_prefix/initramfs-$kernel.img"
        tmp_initramfs="$initramfs_prefix/initramfs-$kernel.tmp"
        new_initramfs="$initramfs_prefix/initramfs-$kernel.img"

        $dracut -f "$tmp_initramfs" "$kernel"

        if ! compare_initramfs_modules "$old_initramfs" "$tmp_initramfs";
        then
            doit mv "$tmp_initramfs" "$new_initramfs"
        else
            rm -f "$tmp_initramfs"
        fi
    fi
}

usage() {
    echo "Usage: ${0##*/} [options] {--add-modules|--remove-modules}"
    echo "${0##*/} [options] {--add-kernel|--remove-kernel} {kernel-release}"
    cat <<'EOF'
--add-modules
        Add a list of modules read from standard input. Create
        symlinks in compatible kernel's weak-updates/ directory.
        The list of modules is read from standard input.

--remove-modules
        Remove compatibility symlinks from weak-updates/ directories
        for a list of modules.  The list of modules is read from
        standard input. Note: it doesn't attempt to locate any
        compatible modules to replace those being removed.

--add-kernel
        Add compatibility symlinks for all compatible modules to the
        specified or running kernel.

--remove-kernel
        Remove all compatibility symlinks for the specified or current
        kernel.

--no-initramfs
        Do not generate an initramfs.

--verbose
        Print the commands executed.

--dry-run
        Do not create/remove any files.
EOF
    exit $1
}

# module_has_changed:
# Mark if an actual change occured that we need to deal with later by calling
# depmod or mkinitramfs against the affected kernel.
module_has_changed() {

    declare module=$1 krel=$2
    declare orig_module=$module

    module=${module%.ko}
    [[ $module == $orig_module ]] && module=${module%.ko.xz}
    [[ $module == $orig_module ]] && module=${module%.ko.gz}
    module=${module##*/}

    eval "changed_modules_${krel//[^a-zA-Z0-9]/_}=$krel"
    eval "changed_initramfs_${krel//[^a-zA-Z0-9]/_}=$krel"

}

# module_weak_link:
# Generate a weak link path for the module.
# Takes module file name and the target kernel release as arguments
# The way of generation intentionally left from the initial version
module_weak_link() {
    local module="$1"
    local krel="$2"
    local module_krel
    local subpath
    local module_krel_escaped

    module_krel="$(krel_of_module "$module")"
    module_krel_escaped=$(echo "$module_krel" | \
                              sed 's/\([.+?^$\/\\|()\[]\|\]\)/\\\0/g')
    subpath=$(echo $module | sed -nre "s:$BASEDIR(/usr)?/lib/modules/$module_krel_escaped/([^/]*)/(.*):\3:p")

    if [[ -z $subpath ]]; then
        # module is not in /lib/modules/$krel?
        # It's possible for example for Oracle ACFS compatibility check
        # Install it with its full path as a /lib/modules subpath
        subpath="$module"
    fi

    echo "$(weak_updates_dir $krel)/${subpath#/}"
}

# module_short_name:
# 'basename' version purely in bash, cuts off path from the filename
module_short_name() {
    echo "${1##*/}"
}

#### Helper predicates

# is_weak_for_module_valid:
# Takes real module filename and target kernel as arguments.
# Calculates weak symlink filename for the corresponding module
# for the target kernel,
# returns 'true' if the symlink filename is a symlink
# and the symlink points to a readable file
# EVEN if it points to a different filename
is_weak_for_module_valid() {
    local module="$1"
    local krel="$2"
    local weak_link

    weak_link="$(module_weak_link $module $krel)"
    [[ -L "$weak_link" ]] && [[ -r "$weak_link" ]]
}

# is_weak_link:
# Takes a filename and a kernel release.
# 'true' if the filename is symlink under weak-updates/ for the kernel.
# It doesn't matter, if it's a valid symlink (points to a real file) or not.
is_weak_link() {
    local link="$1"
    local krel="$2"

    echo $link | grep -q "$(weak_updates_dir $krel)" || return 1
    [[ -L $link ]]
}

# is_extra_exists:
# Takes a module filename, the module's kernel release and target kernel release.
# The module filename should be a real, not a symlink, filename (i.e. in extra/).
# Returns 'true' if the same module exists for the target kernel.
is_extra_exists() {
    local module="$1"
    local module_krel="$2"
    local krel="$3"
    local subpath="${module#*/lib/modules/$module_krel/extra/}"

    [[ -f $BASEDIR/lib/modules/$krel/extra/$subpath ]]
}

is_kernel_installed() {
    local krel="$1"

    find_symvers_file "$krel" > /dev/null &&
        find_systemmap_file "$krel" > /dev/null
}

is_empty_file() {
    local file="$1"

    [[ "$(wc -l "$file" | cut -f 1 -d ' ')" == 0 ]]
}

#### Helpers

# find_modules:
# Takes kernel release and a list of subdirectories.
# Produces list of module files in the subdirectories for the kernel
find_modules() {
    local krel="$1"
    shift
    local dirs="$*"

    for dir in $dirs; do
        find $BASEDIR/lib/modules/$krel/$dir \
             -name '*.ko' -o -name '*.ko.xz' -o -name '*.ko.gz' \
             2>/dev/null
    done
}

# find_modules_dirs:
# Takes a list of directories.
# Produces list of module files in the subdirectories
find_modules_dirs() {
    local dirs="$*"

    for dir in $dirs; do
        find $dir -name '*.ko' -o -name '*.ko.xz' -o -name '*.ko.gz' \
             2>/dev/null
    done
}

# find_installed_kernels:
# Produces list of kernels, which modules are still installed
find_installed_kernels() {
    ls $BASEDIR/lib/modules/
}

# find_kernels_with_extra:
# Produces list of kernels, where exists extra/ directory
find_kernels_with_extra() {
    local krel
    local extra_dir

    for krel in $(find_installed_kernels); do
        extra_dir="$BASEDIR/lib/modules/$krel/extra"
        [[ -d "$extra_dir" ]] || continue
        echo "$krel"
    done
}

# remove_weak_link_quiet:
# Takes symlink filename and target kernel release.
# Removes the symlink and the directory tree
# if it was the last file in the tree
remove_weak_link_quiet() {
    local link="$1"
    local krel="$2"
    local subpath="${link#*$(weak_updates_dir $krel)}"

    rm -f $link
    ( cd "$(weak_updates_dir $krel)" && \
          rmdir --parents --ignore-fail-on-non-empty "$(dirname "${subpath#/}")" 2>/dev/null )
}

# prepare_sandbox:
# Takes kernel release, creates temporary weak-modules directory for it
# and depmod config to operate on it.
# Sets the global state accordingly

prepare_sandbox() {
    local krel="$1"
    local orig_dir
    local dir
    local conf="$tmpdir/depmod.conf"

    #directory
    orig_dir=$(weak_updates_dir $krel)
    dir="$tmpdir/$krel/weak-updates"

    mkdir -p "$dir"
    # the orig_dir can be empty
    cp -R "$orig_dir"/* "$dir" 2>/dev/null

    weak_updates_dir_override="$dir"

    #config
    echo "search external extra built-in weak-updates" >"$conf"
    echo "external * $dir" >>"$conf"

    depmod="$depmod_orig -C $conf"
}

# discard_installed:
# remove installed_modules[] from modules[]
discard_installed()
{
    local short_name

    for m in "${!modules[@]}"; do
        short_name="$(module_short_name "${modules[$m]}")"

        [[ -z "${installed_modules[$short_name]}" ]] && continue

        unset "modules[$m]"
    done
}

# update_installed:
# add compatible_modules[] to installed_modules[]
update_installed()
{
    for m in "${!compatible_modules[@]}"; do
        installed_modules[$m]="${compatible_modules[$m]}"
    done
}

# finish_sandbox:
# restore global state after sandboxing
# copy configuration to the kernel directory if not dry run
finish_sandbox() {
    local krel="$1"
    local override="$weak_updates_dir_override"
    local wa_dir

    weak_updates_dir_override=""
    depmod="$depmod_orig"

    [[ -n "$dry_run" ]] && return

    wa_dir="$(weak_updates_dir $krel)"

    rm -rf "$wa_dir"
    mkdir -p "$wa_dir"

    cp -R "${override}"/* "$wa_dir" 2>/dev/null
}

# Auxiliary functions to find symvers file
make_kernel_file_names() {
    local krel="$1"
    shift
    local file="$1"
    shift

    for suffix in "$@"; do
        echo "${BASEDIR}/boot/${file}-${krel}${suffix}"
        echo "${BASEDIR}/lib/modules/${krel}/${file}${suffix}"
    done
}

find_kernel_file() {
    local krel="$1"
    shift
    local file="$1"
    shift
    local print="$1"
    shift
    local i

    if [[ "$print" != "" ]]; then
        make_kernel_file_names "$krel" "$file" "$@"
        return 0
    fi

    for i in  $(make_kernel_file_names "$krel" "$file" "$@"); do
        if [[ -r "$i" ]]; then
            echo "$i"
            return 0
        fi
    done

    return 1
}

# find_symvers_file:
# Since /boot/ files population process is now controlled by systemd's
# kernel-install bash script and its plug-ins, it might be the case
# that, while present, symvers file is not populated in /boot.
# Let's also check for /lib/modules/$kver/symvers.gz, since that's where
# it is populated from.
#
# $1 - krel
# return - 0 if symvers file is found, 1 otherwise.
# Prints symvers path if found, empty string otherwise.
find_symvers_file() {
    local krel="$1"
    local print="$2"

    find_kernel_file "$krel" symvers "$print" .xz .gz
}

# find_systemmap_file:
# Same as above but for System.map
find_systemmap_file() {
    local krel="$1"
    local print="$2"
    local no_suffix=""

    find_kernel_file "$krel" System.map "$print" "$no_suffix"
}

#### Main logic

# update_modules_for_krel:
# Takes kernel release and "action" function name.
# Skips kernel without symvers,
# otherwise triggers the main logic of modules installing/removing
# for the given kernel, which is:
# - save current state of weak modules symlinks
# - install/remove the symlinks for the given (via stdin) list of modules
# - validate the state and remove invalid symlinks
#   (for the modules, which are not compatible (became incompatible) for
#   the given kernel)
# - check the state after validation to produce needed messages
#   and trigger initrd regeneration if the list changed.
#
update_modules_for_krel() {
    local krel="$1"
    local func="$2"
    local force_update="$3"

    is_kernel_installed "$krel" || return

    prepare_sandbox $krel

    global_link_state_save $krel

    # remove already installed from modules[]
    discard_installed

    # do not run heavy validation procedure if no modules to install
    if [[ "${#modules[@]}" -eq 0 ]]; then
        finish_sandbox $krel
        return
    fi

    $func $krel

    if ! validate_weak_links $krel && [[ -z "$force_update" ]]; then
        global_link_state_restore $krel
        compatible_modules=()
    fi

    # add compatible to installed
    update_installed

    global_link_state_announce_changes $krel

    finish_sandbox $krel
}

# update_modules:
# Common entry point for add/remove modules command
# Takes the "action" function, the module list is supplied via stdin.
# Reads the module list and triggers modules update for all installed
# kernels.
# Triggers initrd rebuild for the kernels, which modules are installed.
update_modules() {
    local func="$1"
    local force_update="$2"
    local module_krel
    declare -a saved_modules

    read_modules_list || exit 1
    [[ ${#modules[@]} -gt 0 ]] || return
    saved_modules=("${modules[@]}")

    for krel in $(find_installed_kernels); do
        update_modules_for_krel $krel $func $force_update
        modules=("${saved_modules[@]}")
        installed_modules=()
    done

    for module in "${modules[@]}"; do
        # Module was built against this kernel, update initramfs.
        module_krel="${module_krels[$module]}"
        module_has_changed $module $module_krel
    done
}

# add_weak_links:
# Action function for the "add-modules" command
# Takes the kernel release, where the modules are added
# and the modules[] and module_krels[] global arrays.
# Install symlinks for the kernel with minimal checks
# (just filename checks, no symbol checks)
add_weak_links() {
    local krel="$1"
    local module_krel
    local weak_link

    for module in "${modules[@]}"; do
        module_krel="$(krel_of_module $module)"

        case "$module" in
            $BASEDIR/lib/modules/$krel/*)
                # Module already installed to the current kernel
                continue ;;
        esac

        if is_extra_exists $module $module_krel $krel; then
            pr_verbose "found $(module_short_name $module) for $krel while installing for $module_krel, update case?"
        fi

        if is_weak_for_module_valid $module $krel; then
            pr_verbose "weak module for $(module_short_name $module) already exists for kernel $krel, update case?"
            # we should update initrd in update case,
            # the change is not seen by the symlink detector
            # (global_link_state_announce_changes())
            module_has_changed $module $krel
        fi

        weak_link="$(module_weak_link $module $krel)"

        mkdir -p "$(dirname $weak_link)"
        ln -sf $module $weak_link

    done
}

# remove_weak_links:
# Action function for the "remove-modules" command
# Takes the kernel release, where the modules are removed
# and the modules[] and module_krels[] global arrays.
# Removes symlinks from the given kernel if they are installed
# for the modules in the list.
remove_weak_links() {
    local krel="$1"
    local weak_link
    local target
    local module_krel

    for module in "${modules[@]}"; do
        module_krel="$(krel_of_module $module)"

        weak_link="$(module_weak_link $module $krel)"
        target="$(readlink $weak_link)"

        if [[ "$module" != "$target" ]]; then
            pr_verbose "Skipping symlink $weak_link"
            continue
        fi
        # In update case the --remove-modules call is performed
        # after --add-modules (from postuninstall).
        # So, we shouldn't really remove the symlink in this case.
        # But in the remove case the actual target already removed.
        if ! is_weak_for_module_valid "$module" "$krel"; then
            remove_weak_link_quiet "$weak_link" "$krel"
        fi
    done
}

# validate_weak_links:
# Takes kernel release.
# Checks if all the weak symlinks are suitable for the given kernel.
# Uses depmod to perform the actual symbol checks and parses the output.
# Since depmod internally creates the module list in the beginning of its work
# accroding to the priority list in its configuration, but without symbol
# check and doesn't amend the list during the check, the function runs it
# in a loop in which it removes discovered incompatible symlinks
#
# Returns 0 (success) if proposal is fine or
#         1 (false) if some incompatible symlinks were removed
# initializes global hashmap compatible_modules with all the valid ones
validate_weak_links() {
    local krel="$1"
    local basedir=${BASEDIR:+-b $BASEDIR}
    local tmp
    declare -A symbols
    local is_updates_changed=1
    local module
    local module_krel
    local target
    local modpath
    local symbol
    local weak_link
    # to return to caller that original proposal is not valid
    # here 0 is true, 1 is false, since it will be the return code
    local is_configuration_valid=0

    tmp=$(mktemp -p $tmpdir)
    compatible_modules=()

    if ! [[ -e $tmpdir/symvers-$krel ]]; then
        local symvers_path=$(find_symvers_file "$krel")

        [[ -n "$symvers_path" ]] || return
        zcat "$symvers_path" > $tmpdir/symvers-$krel
    fi

    while ((is_updates_changed)); do
        is_updates_changed=0

        # again $tmp because of subshell, see read_modules_list() comment
        # create incompatibility report by depmod
        # Shorcut if depmod finds a lot of incompatible modules elsewhere,
        # we care only about weak-updates
        $depmod $basedir -naeE $tmpdir/symvers-$krel $krel 2>&1 1>/dev/null | \
            grep "$(weak_updates_dir $krel)" 2>/dev/null >$tmp
        # parse it into symbols[] associative array in form a-la
        #   symbols["/path/to/the/module"]="list of bad symbols"
        while read line; do
            set -- $(echo $line | awk '/needs unknown symbol/{print $3 " " $NF}')
            modpath=$1
            symbol=$2
            if [[ -n "$modpath" ]]; then
                symbols[$modpath]="${symbols[$modpath]} $symbol"
                continue
            fi

            set -- $(echo $line | awk '/disagrees about version of symbol/{print $3 " " $NF}')
            modpath=$1
            symbol=$2
            if [[ -n "$modpath" ]]; then
                symbols[$modpath]="${symbols[$modpath]} $symbol"
                continue
            fi
        done < $tmp

        # loop through all the weak links from the list of incompatible
        # modules and remove them. Skips non-weak incompatibilities
        for modpath in "${!symbols[@]}"; do
            is_weak_link $modpath $krel || continue

            target=$(readlink $modpath)
            module_krel=$(krel_of_module $target)

            remove_weak_link_quiet "$modpath" "$krel"

            pr_verbose "Module $(module_short_name $modpath) from kernel $module_krel is not compatible with kernel $krel in symbols: ${symbols[$modpath]}"
            is_updates_changed=1
            is_configuration_valid=1 # inversed value
        done
    done
    rm -f $tmp

    # this loop is just to produce verbose compatibility messages
    # for the compatible modules
    for module in "${modules[@]}"; do
        is_weak_for_module_valid $module $krel || continue

        weak_link="$(module_weak_link $module $krel)"
        target="$(readlink $weak_link)"
        module_krel=$(krel_of_module $target)

        if [[ "$module" == "$target" ]]; then
            short_name="$(module_short_name "$module")"
            compatible_modules+=([$short_name]="$module")

            pr_verbose "Module ${module##*/} from kernel $module_krel is compatible with kernel $krel"
        fi
    done
    return $is_configuration_valid
}

# global_link_state_save:
# Takes kernel release
# Saves the given kernel's weak symlinks state into the global array
# weak_modules_before[] for later processing
global_link_state_save() {
    local krel="$1"
    local link
    local target

    weak_modules_before=()
    for link in $(find_modules_dirs $(weak_updates_dir $krel) | xargs); do
        target=$(readlink $link)
        weak_modules_before[$link]=$target
    done
}

# global_link_state_restore:
# Takes kernel release
# Restores the previous weak links state
# (for example, if incompatible modules were installed)
global_link_state_restore() {
    local krel="$1"
    local link
    local target

    pr_verbose "Falling back weak-modules state for kernel $krel"

    ( cd "$(weak_updates_dir $krel)" 2>/dev/null && rm -rf * )

    for link in "${!weak_modules_before[@]}"; do
        target=${weak_modules_before[$link]}

        mkdir -p "$(dirname $link)"
        ln -sf $target $link
    done
}

# global_link_state_announce_changes:
# Takes kernel release
# Reads the given kernel's weak symlinks state, compares to the saved,
# triggers initrd rebuild if there were changes
# and produces message on symlink removal
global_link_state_announce_changes() {
    local krel="$1"
    local link
    local target
    local new_target
    declare -A weak_modules_after

    for link in $(find_modules_dirs $(weak_updates_dir $krel) | xargs); do
        target=${weak_modules_before[$link]}
        new_target=$(readlink $link)
        weak_modules_after[$link]=$new_target

        # report change of existing link and appearing of a new link
        [[ "$target" == "$new_target" ]] || module_has_changed $new_target $krel
    done

    for link in "${!weak_modules_before[@]}"; do
        target=${weak_modules_before[$link]}
        new_target=${weak_modules_after[$link]}

        # report change of existing link and disappearing of an old link
        [[ "$target" == "$new_target" ]] && continue
        module_has_changed $target $krel
        [[ -n "$new_target" ]] ||
            pr_verbose "Removing compatible module $(module_short_name $target) from kernel $krel"
    done
}

# remove_modules:
# Read in a list of modules from stdinput and process them for removal.
# Parameter (noreplace) is deprecated, acts always as "noreplace".
# There is no sense in the "replace" functionality since according
# to the current requirements RPM will track existing of only one version
# of extra/ module (no same extra/ modules for different kernels).
remove_modules() {
    update_modules remove_weak_links force_update
}

# add_modules:
# Read in a list of modules from stdinput and process them for compatibility
# with installed kernels under /lib/modules.
add_modules() {
    no_force_update=""

    update_modules add_weak_links $no_force_update
}

# do_make_groups:
# Takes tmp file which contains preprocessed modules.dep
# output (or modules.dep)
#
# reads modules.dep format information from stdin
# produces groups associative array
# the group is a maximum subset of modules having at least a link
#
# more fine tuned extra filtering.
do_make_groups()
{
    local tmp="$1"
    local group_name
    local mod
    declare -a mods

    while read i; do
        mods=($i)

        echo "${mods[0]}" |grep -q "extra/" || continue

        # if the module already met, then its dependencies already counted
        module_group="${grouped_modules[${mods[0]}]}"
        [[ -n $module_group ]] && continue

        # new group
        group_name="${mods[0]}"

        for mod in "${mods[@]}"; do
            echo "$mod" |grep -q "extra/" || continue

            # if there is already such group,
            # it is a subset of the one being created
            # due to depmod output
            unset groups[$mod]

            # extra space doesn't matter, since later (in add_kernel())
            # it is expanded without quotes
            groups[$group_name]+=" $mod"
            grouped_modules[$mod]=$group_name
        done
    done < $tmp # avoid subshell
}

# filter_depmod_deps:
# preprocess output for make_groups
# depmod -n produces also aliases, so it cuts them off
# also it removes colon after the first module
cut_depmod_deps()
{
    awk 'BEGIN { pr = 1 } /^#/{ pr = 0 } pr == 1 {sub(":",""); print $0}'
}

# filter_extra_absoluted:
# Takes kernel version
# makes full path from the relative module path
# (produced by depmod for in-kernel-dir modules)
# filter only extra/ modules
filter_extra_absoluted()
{
    local kver="$1"
    local mod
    declare -a mods

    while read i; do
        # skip non-extra. The check is not perfect, but ok
        # to speed up handling in general cases
        echo "$i" |grep -q "extra/" || continue

        mods=($i)
        for j in "${!mods[@]}"; do
            mod="${mods[$j]}"

            [[ ${mod:0:1} == "/" ]] || mod="$BASEDIR/lib/modules/$kver/$mod"
            mods[$j]="$mod"
        done
        echo "${mods[@]}"
    done
}

# make_groups:
# takes k -- kernel version, we are installing extras from
# prepares and feeds to do_make_groups
# to create the module groups (global)
make_groups()
{
    local k="$1"
    local tmp2=$(mktemp -p $tmpdir)
    local basedir=${BASEDIR:+-b $BASEDIR}

    groups=()
    grouped_modules=()

    $depmod -n $basedir $k 2>/dev/null |
        cut_depmod_deps | filter_extra_absoluted $k > $tmp2

    do_make_groups $tmp2

    rm -f $tmp2
}

add_kernel() {
    local krel=${1:-$(uname -r)}
    local tmp
    local no_force_update=""
    local num

    tmp=$(mktemp -p $tmpdir)

    if ! find_symvers_file "$krel" > /dev/null; then
        echo "Symvers dump file is not found in" \
             $(find_symvers_file "$krel" print) >&2
        exit 1
    fi

    for k in $(find_kernels_with_extra | rpmsort -r); do
        [[ "$krel" == "$k" ]] && continue
        find_modules $k extra > $tmp

        is_empty_file "$tmp" || make_groups $k

        # reuse tmp

	# optimization, check independent modules in one run.
	# first try groups with one element in each.
	# it means independent modules, so we can safely remove
	# incompatible links
	# some cut and paste here

	echo > $tmp
        for g in "${groups[@]}"; do
	    num="$(echo "$g" | wc -w)"
	    [ "$num" -gt 1 ] && continue

            printf '%s\n' $g >> $tmp
	done
        # to avoid subshell, see the read_modules_list comment
        read_modules_list < $tmp
        update_modules_for_krel $krel add_weak_links force_update

        for g in "${groups[@]}"; do
	    num="$(echo "$g" | wc -w)"
	    [ "$num" -eq 1 ] && continue

            printf '%s\n' $g > $tmp
            read_modules_list < $tmp
            update_modules_for_krel $krel add_weak_links $no_force_update
        done
    done

    rm -f $tmp

}

remove_kernel() {
    remove_krel=${1:-$(uname -r)}
    weak_modules="$(weak_updates_dir $remove_krel)"
    module_has_changed $weak_modules $remove_krel

    # Remove everything beneath the weak-updates directory
    ( cd "$weak_modules" && doit rm -rf * )
}

################################################################################
################################## MAIN GUTS ###################################
################################################################################

options=`getopt -o h --long help,add-modules,remove-modules \
                     --long add-kernel,remove-kernel \
                     --long dry-run,no-initramfs,verbose,delete-modules \
                     --long basedir:,dracut:,check-initramfs-prog: -- "$@"`

[ $? -eq 0 ] || usage 1

eval set -- "$options"

while :; do
    case "$1" in
    --add-modules)
        do_add_modules=1
        ;;
    --remove-modules)
        do_remove_modules=1
        ;;
    --add-kernel)
        do_add_kernel=1
        ;;
    --remove-kernel)
        do_remove_kernel=1
        ;;
    --dry-run)
        dry_run=1
        # --dry-run option is not pure dry run anymore,
        # because of depmod used internally.
        # For add/remove modules we have to add/remove the symlinks
        # and just restore the original configuration afterwards.
        ;;
    --no-initramfs)
        no_initramfs=1
        ;;
    --verbose)
        verbose=1
        ;;
    --delete-modules)
        pr_warning "--delete-modules is deprecated, no effect"
        ;;
    --basedir)
        BASEDIR="$2"
        shift
        ;;
    --dracut)
        dracut="$2"
        shift
        ;;
    --check-initramfs-prog)
        CHECK_INITRAMFS="$2"
        shift
        ;;
    -h|--help)
        usage 0
        ;;
    --)
        shift
        break
        ;;
    esac
    shift
done

if [ ! -x "$dracut" ] && [ -z "$no_initramfs" ]
then
    echo "weak-modules: could not find dracut at $dracut"
    exit 1
fi

initramfs_prefix="$BASEDIR/${default_initramfs_prefix#/}"

if [ -n "$do_add_modules" ]; then
    add_modules

elif [ -n "$do_remove_modules" ]; then
    remove_modules

elif [ -n "$do_add_kernel" ]; then
    kernel=${1:-$(uname -r)}
    add_kernel $kernel

elif [ -n "$do_remove_kernel" ]; then
    kernel=${1:-$(uname -r)}
    remove_kernel $kernel

    exit 0
else
    usage 1
fi

################################################################################
###################### CLEANUP POST ADD/REMOVE MODULE/KERNEL ###################
################################################################################

# run depmod and dracut as needed
for krel in ${!changed_modules_*}; do
    krel=${!krel}
    basedir=${BASEDIR:+-b $BASEDIR}

    if is_kernel_installed $krel; then
        doit $depmod $basedir -ae -F $(find_systemmap_file $krel) $krel
    else
        pr_verbose "Skipping depmod for non-installed kernel $krel"
    fi
done

for krel in ${!changed_initramfs_*}; do
    krel=${!krel}

    if [ ! -n "$no_initramfs" ]; then
        ${CHECK_INITRAMFS:-check_initramfs} $krel
    fi
done

NineSec Team - 2022