container-selinux-2:2.68-1.el7$>4 "$E՝r{o ->?-?-xd  $ L ")+          0 X     ( ?8 H;9 4;:;>*@* B*G*8H*XI*xX*Y*Z*[*\*]*^+Sb,"d,e,f,l,t,u,v-w-4x-T-tCcontainer-selinux2.681.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[|#x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_typesif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?R|A큤AAA큤A큤[|#[L[|#[|#[|#[L[|#[|#093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d37e0c13396ddc379999bf51551c20564f0e280300a625f2a691ef2e11a37595ef82d3ea6281deddef1cf257723cd963de762d45831f34a25e2c20c46e41b9f8arootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.68-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.68-1.el72:2.68-1.el72:2.68-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.68README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.68//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,YU ]"k%xĉNμ5#+mz q{@gPȃFG=uǝ<%Пv!8)级}Z=Q V✠_[DCULJ`CUh>' I^A"x@yl>8JWlwwžܰAKRMXP|ꦁ4_wT CIu_5wŇyK|Bf!9em9Tn{iQ*꣔'$4+h?%KvI֦Ƹ T}_$i#}F6Ӆl:"r_'e ο{X}/ $}-i>???&|pm21q>qD4/.1y[5GʏHVdW0lLZT[+qB34٘Uoߍbtss#ڳ3p_1on_+ߠg][55k_qJ?I~6!'Y>B}PY6hemۼ"O\])nutpȆKpRau5R]^SX+ vJ/$w7:x׷U  4YSݰU1<=8-#$t Lc?-kwK||h`|o~L=^2fa@tl,t0>j쑡|'YF޻|!U aK7Qǒ0H!1v>r4\r7>>)0ԁ`w q4jz:*V SR5>k3Rtv6o`,MĵNwރ|`T ,IJU.Tj4u}d峁m]̐}'LuCњ}TVjLXRHo Ș:ʘ5R |p$(1]܋UAa$J[5c4 (Nw^fL_~Z*| 7Թ`$81KA,#p?W_R"z7z^avB] q \*BTLۺq<ؼ)ai"1K@iQ׍S?V7'muEt|&WM09%g0@oXkq~PQt,9#DxVO0bp2K( ɡ /hGrXI! D s-\p3gEu/ٵ7!iIʄ-]nCce$]@#~tURA]^sd󫥁u4SZ"PO~䟳k@dY=yrh9_eXlL6g &2ی5lV@)6/=jߚjC7?۽Yp=ˎqԘz8Q8-9t_\\ ll+%hIY␊O,-%;U"miWvbm׃td B+g G})}t%6u`ݚYZ=PL@"[3z=۹#$%?w12"E{oG@i#d4n~.ڞ<\n-Cs趟c%'!3È$☛2Nq K)- `HJTA+o`+LVB눎~RW'sѣ،]GJ9ڲA! 4zXq⻍ي~AÕ|szo< bкЈKwHfeEc"'sf o LSFtؼ$PRC!6:q$*@+JPo7I{GM̏m.yc3fRQDP}z)E;~v͈׌|j\kkcךHb e!鰹^[?w+L2Bx n^vbzcF$kx+<j᰷ ^ M\F3V 9/IFKϐ >T(@?j>LR7%Δ5NÐhwqM׵Oǒơ19S9yO%ElƩ)X0nS=^E }YTrM|ɓ6-J?#0GX']ؼɯ1,l~_ 0/"^R}@"/6$>.矰 fuvObn>Y*f7k RH}ʰlt߲M*(ItD7ִb"4W\ ;mgHH h> t&| mf =TE :3!LLq:)G1M;\B\)Fر$͍tMG6 [Q+^S_қ+(ev ]!%Xʁ(jgz;2U9d1ww)oT=PoW0rzyvB+_s$`0&oZie\Hy)(Q{LRi5=kOI}HHKLȽ!(9l#(hjFBO~vя;QFFzJ'>)He #rGlvhRHu晑bBξx 47[_[?H˷yO3Na_:caxRXm-![/ɑ7H:t]xCّi85G۵  pŸS7ZEG7ڝpjÉR`D^Ңi:g:ۣΒDzdn7O9AFne'A]񠗨Up4{BS!P2Ff9 Sax"v5aghP0> |?Mx^6-f/q|WtMH <~||4aVk\%&˚hL'OdNꗳݛt 37K!FjG!xȤI]vލUM:CF``__>>5>Mo, 3L:x9H@_!=h̳i۟>ޱ+0#ynL:;l0KF0Mֆ?lN „ņǸO.07 ;2xKȭeڸNCPۊxj8b]FXqV6T#=&x9mVLqzɇICFԙ[mT>SZB<I'Zdw6=DUN3iekH7cd9'"CFcΝIVCܣԠo RkᦽnJҴ Ҫ1]q }"Y̵ţպ^VN1aWmoW0E-UYL%P f:oRw/{w8f7N3{~EQJv1ú}+vC!'>%>)9o|-f?ky4`MR3;ҋi g3ZȪn-o6x>vHj5O6cvMp@-N)8^y!Nken'æOnJBw0^/J[s 68>,|hjryt/Am}0#1i7K#X m355XTCU韦zkRwE|Jm )F R ɠG$^&筇6q`Q%\Y4<_&+P?w~]n= m kF21!'PQV|P*5߻e,7FbiA^o2 h뗗ξ(Kե7+N'> y!`'3ї#ՋĖl`t5ίÌf}_ >6te%v Yza5G]E -nl4 5ԊWKN%J. Llph3!B^r9u"ԾzQ5dX? .X+t"O&+|9hu?ez>v2؂]CgOe'VhʉŶ5$"[LZߺ# 2>J6곀~/U;znkr ҘϨ1vk%C 1V7$7Y&Ks\^۹V.H6;#a-iBxD iP$\#q dA'IDvSTM.7xp[F#a{Q锕h[COc&1x+=_c!Wd@mE7v4V̫͘ .t՜%2>!1k?\~h7?=RH8 YDl^"pNovNܧj"I¸1;|Y~iHo%s~0bic=^o4Agf<B`x$Ok({ GOyhƉb3e+9Y|\9>̀wG"rFFa!8 %H;#~$(N*{Dto\P4ϼ9 xXeo ,jo yOS<<boHM8 i{WĞ6FMw ;ԄK&Ӕ*i<]2ft*lL_EV0_Xi #!ld,;"lW$& _,e<0`p~my0)i]- sX#7w縔tҌAUBw-X8uj`k8.چe^lY: <i<~ CZgs1٧ U c6i:mEep#ܧ eD Bvvd%ܕ;w"FXߘF(QbMgU[\k5(/]z,{..DN' dN R²4NAעOr6vY J6o΅єFD,Po 1ƇSvLPtr&ثd\[L>s,}G@)\v^Sru\"62v !ޑCZ-GmR>*ӛ@ACEs<ײƗȤC[2ݳ"@i(-?sT_|6V\q>5=;>PM~ 'NQzz:2ūFqご<w-*bLwA4l_D]2c k$8B̩5Kr5.3Es+5u45v|TTоpC"EMi\{da^SO.\lL-}^93ýOC:A0rL[oC?d 'ڐ.Fuhy"(| B,5سA -OQ_wZ q;@4ܟs,-ᢻ$_@m]kQSsa=>f]eHs8YFY4Żެs0ON`_U 8CIS$N!)~勩ۦ-+Gt)>I\ ў_AdP+zٜer u4GMn*7B=[(?JfpbZf|F[jhD[0t.'qwS{~~$ 6xR"R3$S/}W b)pIs\u5>'l#,˩(3{lvWgo2w3n0/26GsTp+q\_&ε ^ V*XNi/~.dP5nU29\;92j0o"k2:Vv +S.Y_q G:p0-%KQ?ܤu{qˊn6à{#~CvDtot/Mm·gC`nTvlYU>Hm.iɾb[ZYʘ_nZj* 9?F FYL,ڒ7_Suy`&؈#.HYGr)+/T!r? RQfmĶaJ7BpbBKg\ #{sa\L{ާYr`nh$Ou@7x74x%~.%訰 /U6s(R>U!\h,k/eEES-l-^{5F&k:cS='n\ y~E %đTn[/p>%gF[[-<üYBG$ϖEo=6$p1336 z<&p!?Y@j3kESCJ*ﱆ[ pI˱ ck2{D媧F&'_/tkfg7\l2!1KY ] _o*$B(~fOL5(K<uXA.:oeCç*eW4ux7.HĪ =<]2X b5M#oVS]N\1ݡ8m8ifW;i3ٹ#9h[Lb'`ّ81F~0IMjzŝKfpo˟&x>q1Pk_.R`C<-':A<>H5n) Ā)KM&%M*CsMH~lN8@Gm&[]،6k ;Ŝq'kenQ\YmEE? dJW7UK]Tl:6!5eT%Jv`w^y0ۻ}֧w?mڋ~b^L_ Er?F'6v C Ez/pGC2ʁc+5\W9(}L]LLKn-odnuǸʴ+PY{A-͆gT0 bZK*PZ6Ldt,soy5%F-`aw%`q3} &(a H\tkQpBziTWM/|<+}C_aB"-n+B oCwU79~Zč}/.{*I5 he# ;a/b6R9U N(mk`i}ܷt*#9"+e`[\#aB OF{?.ݽDk-:yL-;wjzC2bQ,}q֕rﰹ6^O R][Y!ԱA+yއnōhSd)Tʡ6sq AL"վ~]: 8TH)C_ tV/x!I/0oΩYk0]'@6i!<^BWpVz'jˆ{C}zGAŕ!yWSF~ʏ l`ͿTQj9voAbVU+KL^O$J$XT&'~ڇ;v}FY On\֙Vx@T8 +zASgU(w9'Iu7o3Yzx I35$[_Ckzף*GC:Lǻ&vls^_L eg 14%AqpLɭcV10# QK#WdaѤcMr̪ӏa7#ƒiAzAVپgq&Km2iǓNm=/:70X6)gYh44Aqroz\]\n4 0LNl-sḅ m0Xw6~a1BbɄq ?7O(O4s g8cBS5TEk9FZkV&xb(kFL>g!̟:&quDzgL[jWMT.kgs|Cĕ{fP* ŜCö'iC"C5Ir~3{5bӂ;̫%!!G)K୒w1p/\jwŘKiPNBA"mhxj%Kpb0Į<5_'-嘸._R|aj / \wo۱. Q;.#}",Vcһ>3+]t"5ESЖFB2WaP?;~l?˾w?‘,cIˍx0K@ $ZfcYLNQ@0aiq~hEēCnKC{.h9NYt%{z+Fp'T}1{3 jvE4u'}&@6l/^-o_5z>~ˏ)r@h;~2l"i <D2W.ǒNia2J-+Iu{T_\ U:ߧQ*oVK (ڀJ @C"}edgMV9O*KZѤ>l`ʭbAWY;^BV'z-U_6@yĺp{^U=vmXN ,`vh/.ۼa܎fOj^xr~ir%b,%2e(KHQˤѵP|QUwqIC\ጘ7Rj{t5<WZz30<ޘbyK^alRL#dEu /kJLyCj`JVbiߖ`wju.N.SܿȁV}Ee&xX@ ToR j~Dܪ<=|>~'ka~fZ˭2_{(i#Q6iZ}"kiJM? EʀPצ Q9nTIɾM0[Crf/;'1Tݾ?P[rr Y`yE@޾R^6d~~j(/LsIlJgjuKG4_ Zo:v%MFHy>>!uв(3{g.j@V" | Š`飋g(g/G@z7bFn61hhbaO+`7?&וWNHG G=( 1[c8zq[i>gk|Da_84DaE sEk=zr1^M$_%fO@xNpÈǦԐᰀXF)TĭkG+%&g/?ؽ7 2{O¤ISB`8撵RR%'33)լ4o۝Ma`<ޫ#V?0,j2UQ&Ȥ$W7"Me` .ŒҸagf~6{7pm hi\=\[65A :V0a7u>JJ95*_4t'{)Fj\.?.f5|؝D[ks|{OfhWe>ipFtzoBqilt f(1 v`  OcDo֊5&@2p\[GDG|,b?GɘjȪq) :=dEoS_LЂʈemEɧ}ҳʺe!Ǟg/I0a1_xeOg,xT/eSd˥Q[nUSWK}y(KߙrG y{E=&fptTj&A$2&dۣ:̸*c腐_?5QK$[w%=SRRgXU>C>H5Qf$_5sBG3p6{cK-UV"@s4.Ա~0_m!h^Nv`}7ٌ nȡn H}^eѓN-Q+^3ց"9|Jn&zw2~f ~QؗA|7J9=SB?a4 (|c0 }̪AA?tR4'پT('bmf3Y&ST$w\SxMN-Ȩ6;pESغ %KЬ(ˑ~zQp6븚'"W 81l}G8?  Vד :<)S {3 <\)W+i| IFe^Ksw1ߒr_)u7lÀWDӮ<{u}!>'X Msm޻&3q[{֞}j@.} 9LM2",Nhf>z/> Y9e}tt35-9G3lo]fKJ\NLX_mll"we{nH' Lӎ7){WYFG wŽسGkx-Cwéi| ӍJn\!ΨYn|?霂+migܺ?6-~8MG쨇TO(.i=)ς"v8c/)H२CQ7w\I  u\Z҄QՈ8BpFM;ώgҹH}X6v >΁[|wc;X u?qX+i( *'#)leF8ea Y1h}'FrdQkU`8 ϻSX|::rLe84_ex$*_8LBB1c)`ك\*)pXZVV2r$ۊ7Sleb h63(``!kQPnHs񑀝q`DrGEQQ2vpY:VAc$ftAEkڄ]c/"fZ0Da$tcΪ-?^~$_vMD!gxo<]S#A i) ޕAj2YV̸a`,'xN` #&k,Sl8Tb)d:"!A5fȉWr, ovpU:`"]93 n#Vp>e. OƟ*fcb.WмG3tNS*K8;;jiEOL]_&o˼& t=YVIq6VN9#N*`3.HuK[x}$m7dF0 qXFd2iɋ `慄hƧFF@P˧f(*.GgVDrlI%X@ľ&5!U_lI͖|ʳ.:[O#$Nwz]8n;0q*STONP G)<9)O OE [ ^btT,h 4:Q~XH&8 ~0MK/#l^eSD;Rn뷮ڞfȂw#jn2dNx$q'P38uՒ2sV@Լ.c4*z Hⰳ?.D83/O, O+(S3Dg *A@D*pP_TрbXDk@-3Q!oFHYbȈ<`[FțEnΎ!:|Ok߳dFT&>GQ>c< yр*,FL44"zNx?^8wJe T={UxQ#6Tr{a R.()[oE' ǠŘ3,4=1|%klUr!RHB`r0.SG)$3 2?JLw&Ø MFަD'`C:(үM{R9g1ŮP//0bV :nx11ADk.}!P!o{'4ԿTQ.)s`jrӢ7Bs&Ù~FٚkHWӆOaл*1=۾z\b;f4PP(p8WJ&Y;y waoNhݛ 1Cp6 1&Dޤ4 Zzr,!c.o_E$J`F [zB8@'l2bzQ?j:eC#, &,{w靋x o ,qYqAj4kq?ؗIpLQ>1?nѧKS'q.W] z;~6l?H@6VxicEd̗SX7P+|( _T~XRG@hf}4NA. `Eq2y]IWl,_:~{d]F`O(gLTK;Mqrw:ә9}W䉥5>V'i h b豒qJA*' Bj%nI_N *2$ND͈A*JQQ&nySYC2X_%*DzLb&9E' m}) O5zWM5 3F8XEh3{ )-l+tuN*0@8Rbm%[ {:vJ0ˢUDڲA&[)aqYZɎO"#0j!0Y恈.aǜ2ȍt19=DXʾ] M#i-\-ݸ>,h [>T5pc޸v@@{*e^( ⟬ "z*,YJd]-L,}{^rw <:v o$۳PECˇRZe2p*llx'͋ *A:Sb# etQBQ 6P%}6<gy>r]*fqje!p0:@C oHt.YfbuCb{%JunGߔo@,]1EL, b&ګrSc+Nʐ7M)]׉Ѓ=fэSR7rgdԯ؈ʉ+~f6jfE[ᴂ_^Fב5MRg5C#bLb6VI+V?"ފ@f-*-VW)ayPj[!)g/bgHofx QJ fp^d(ĭP8 8!hxYjP-?{Y} dsN?m4S;R~RR(2H"&G$|:Uq $is+e4gw>L 'v+k}kUa">~ߖT秮M+,1t04 hm0 Q Bīw*E^9D6'*m86(]UXuf,o~iȗ,^)\Euo4~Rr o#ك4~.RvHHn YZ