container-selinux-2:2.74-1.el7$>hiZ ~8a[>?1$?1d  $ L ")  4  D  T  t  <  D d     4  h  R ( 8 @9 @:@>-i@-qB-yG-H-I-X-Y-Z.[. \.8].X^.b/d0Ue0Zf0]l0_t0xu0v0w0x01Ccontainer-selinux2.741.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.\(x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?=V.A큤AAA큤A큤\([QG\(\(\([QG\(\(093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d492fea535317f79ff2e2b9e2d9c8b22ada5feb7f1710482f31745f8381dae4fd52b108f469bee7c4f50cbd79c03b4c27b048e50468b42d3aad1a4bdd14ee4646rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.74-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.74-1.el72:2.74-1.el72:2.74-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.74README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.74//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,\W]"k%xĉNμ5#+mz q{@gPȃFG=uǝ<%Пv!8)级}JuX$ш7uV,9ՈՌx䣐Dk+ 1Fٍݝtεle[SȻ# V씔x94+/hIdYy4/R͵ `CnbVEnm > KЛD1OG-VK9d4VtU(eA%߻t*Fd=ӌ.d9.o2eSyf]ςE {pi44G8 NlkUje2MEu,W\q<~S(0h{tϰ(7llrR2hޙ-utwjPhP2!0ݽFqVs7{RWžRAo䢰ex)>864P +§t n\ž^ϡ wvo)hZ]Пg__sref)cr u Y3!X#P 5Y$8Cj\wA3f +!u8El.y|2I6Xȷ &]n3rCh+Ɉ6R2<<#htSiiKG(0ndt{JǭKN͞i"=!m<XŭD@tNǾ=h0OC\~V|Nƽg#@5p m=.&2ys 'FaS8icE M|ҠsV7I Ɋ}WLDEovA&J8t{ۍ ztiIй-o:NҮJ.-U_/гßD~I~fsbm =5(P9w@{sCmA? A $idamVK8f iqcf&U4ށ#aHcFTjG (1C-&N峑\m`z;p,vcQDGp!Uр($>>u#2BϬaJeRCsQxr/8}$; sX֮rl3dхU2JΏ|\ Yۡ\?n Q#Qm4Ag$#@,OZM_t*l{اsǞ!V4=UH_\,zWLΖ -%'T݇W Mh神?^}r*!NЯr\>+$6Q:0R}UcmC >ϏU;'Wn)nü:9FzC6 BNj89TZtY`*@KH-%v^F+ɏUS59XN3ٜG5s @q6J8tM{ͻx{\>!HnD c$S!L#'\,cʭ2sE ʼn5%}y??MW y d*1F&8価RGm=VuTieXz뗂; 8aaMd%?x9ޢ71`r+2n%̶QX]_|xWxwn>@z Jd֠yd4ݎZ84BˌztEjmAplMjd<ąnRJo%NGeVj!LnX31MZr^3x@',N(^=Gw,j cJ5K_NXIeW)0Ȋ4^hN ԂcgnџVE!DkZjNkFSΨ =CldR ./PC&PZtE|}Ch ϶i6&#ѣ1 X_q[}_e5B?j nR&H{XfF[yn^sI)y0L<%K_0+Ү5a:la/I#gA$V"G<,mѿ_!?YJQE 7h9߰Rm%2>L8J]K ;_ټ'˩:lP(nP6k1RVp'^t8߸u_qvŽtƁxJOUqaU (1J~dJ#K -)U̿J!XSmY5~\ch_n۶,ًIDUn2v;eb8"etD9_rӖ{{Z4mbޛeD".d_ 8 4 !|O:xߴ+8LBD\UcJ VI'N>(6R[K4" Y::R;tq"T뤡 p'-VΚk0qFzEiE0*8Q6 q'bu\ܶdlx0r.O;2+kBzĆoi j~:b3& UHȚWHP?!\%xZAvNeA`žn>̀6YNql_6q9p0؏fMK&u9xuW~h\pt@=R믎kt0sKE+<uЋذEvMæNI.``2:gPdAnq4h| QJ/b"dO>}܊&bca pPi}[K1tv8 ;37"y T lfA荙cgR׳<ߧ-s.Ila !zf5M[]]Z j@ϹWѐ1mIa9ƍ9-%]~Ucsb>F @7ğzM&kH? at5\b{=uD1=.|qX͙ŀ.F1`֢4A?jtqNL^ѝi|ٕ0 ^D lq&HLBE5-}RXE^Xk*,ޤ i^ V&{p[)w Оreʲ ukbQ\%.1{X-Q35Gj/$gemepO[3!ͻ}GQq뿁gwc@pItvW .Ozq )sJ"<pT-cpPYj^Q/*;;H]٥E^!QS Aӂ(CVFlWiqܦSTMA6%j+@Gk3oE2t ;n]DG;[-r+4v΃*! P䊯j?\&1E\6{#Vp$xhw`i`SѹξA>JYOLCzqT^=gDw.xJ5cNʟKx5FOn-yey΁23[Inj[P1n^XϐŞђgU=HU]qGo坊v],.Ia%c14-M4InXs%2SBcrDA H.>%ƻivH\|W`Cff5V̀g?jB X1]o5]w(Me" Bbmp15+YV-璧Y}JjALP*Inj1KZ?<:3bNFv62]? X0Wn4Ii9bzt^pD '3&GHuun tPmCKq$b( X jss𨰟x@Eq?h愊Ϟek f-ut針ϐ!/A4=:4yexf2{ǁ5-׳$skW4֕(+8jXKwa 0]ċ< 21O7yrIs<-FV|^)7iXQB4ji6̥<)}@qt: rWvQLeF2bNNzjzk%ff cTig};ŸuwSi'Y ҇a {B<|eh_EqXIsDQN#?P/אS6 #m.2UHKJR8/އ"\'mMe2BE<9^uI慜|=yDޞH!!LkϺ][{Δ%) ,5Tg ӟm*Y[LYuqc~&xl0!O4.;b.=8)F(+;JݹH%qi E3:?f@TL˾#| NM5Gz-+<5'/)ML&q*%xE< }tj=Z7Hw濃Q*F:YF&@"j[py֚bZE?Pz"Dg/YOa-"zUT#nF1]u(zyo־zkHje/IFX 1"O ֋$ҐyGOrD:&͘w^-@3C oX61Wܤ~K E/@IP3iƮK'ۉ&@/%t`pp|y;~((}FPkm\^:k<;aHyDEOfV:XaOI"ĥشjK z_CwV 6[w73e:_$WֹE>Rg$ysߧ xOZ\sg< xYzv4<ՙa˷6]EC;!X>r7ʸ]BK,?~i!x,12CMŎ'?kP}єo)Pa*".1e>)(tP/B3`&mkٳ~Pڡ`r?`<^~qL빠 (?;jf,qzJp`d47p|Ve:g3nG4rٹd-#GC>v1 Sh`bDy_ĤGJf~}7T-.&u o5gL.#UG#Zd-_"Ư ZH6c0{4muzj*{~I(Ag n|,|>Hqc}9d e{D,'+:#J_%bz- %eZsL< t{!U&i"\&}lF`~)ɿYjUyh:瞵W;$5u D;^[tޖ-OUZfx{.e20:wf^TY0Ij (qÛO$Kk&"XXݢ{r0LjEˮ'MLۘTnSn8s# v>%jO9F ZrAQh([⿿DA}h0/Hpt<&|=f֜4jn/d>Ww:(er[MRvSd 7sciH9Ia.`qP)r:N< CU̧j A¹tC~s8n t]X2ùf, @b02Qb=sZIz;r09P(9K}]_*Y&6i(!L^Ld..G CEPАKs6\BqiEw(e{zQٱ4;X(F}xpFy90\*$Ҭ禍.06HGL%Lݕ;[fw( nĖ]OuNt1|(_6c2t""򦿂b|\F_~*v/ޓkUi:1\|roo'nJ'{l~!3;g IM=zDS:o^X?I:;Qhl8IFLә[:I~ wiZq $_4;u+bx Gىeu/2#b2.RdGIK7J($/Ty=[hnIm17(e:Iz[ 7K@վ,x{j4yCy}+>ƥzv`_k8 '#K4T$v4[3`<'t lHkhڕE;򣭛YaXprM/Gu'\VhK}-YNOĽm %r'Rv=8}TT(<x9[DwQ@;M~i|JA]JOqX1q񸵲߬*Vw3U"0]IU73b.`sbȕGTtnU _馇d v^~gM*V@X L/3z=Ǎ qd0z^3m26'(l>*vhK<7uuofqF|%X0JVJA@bD<*r\Fmxg;\}BG8XCp`X]bZh"m5qI 59{a9ygܢ=@D*Ӎ3P0G2_ ?̒nQ<oP[,p4ҊѬDVUp56 Ԃ2> /D!լ STvMwㅦ/C1ᾎ~'\g+ LwȉF<~~n x;|#w51u$H+w.j(E.u S.,oR,eO&l 1TPpm\94G4)ȡu%kV_A-Q^ v*(gҶ'k] l/q{ɚEx7KQ†9a+HT&qٚĶh7&%wA}[HC:ehIbVO֡@15 VEتK&3d:{dG^a޼<tb"^,,WA[ՍŹWJ 1Ë_ek&AT@a~,嗩1`D%nEf_ Gb$sOdڻeG>]dL9c558t|sL^rWPv^mZ *A L-NSQU }]Rзڮ:5[ʼnжPYw߃;rz.aUq 6ChEQ> ,j|=~ =iTԮgpf҅.DaLrZA ˝D4nmc_PezQsA L#/f?6'"/u _;ɒY1~֏;veA4>8P鼙i/Kɚ!7H*t",4pehy# rKǽ Aǘ\.I!炘!@ӵVi s~ŎH<3- {m@ϦO$!(K=p8m(ޭmU4WLgF_b͢7trDk6b$8HD?J-[uyd),,fs<'FF uA}ؤsŝ :2yYQ,k A(  MD*pl:`f:Y0¦S;-V.NzwT6Z#|KM] 'FxnrQ_ňk.:@o:f5AR]ȭU&϶$j)} (Ԡ lLO7ItD?FqoRN( w5dϩL9L &dBO [lR$g݄$!?VI/XC(HqA1 yzH Ē,gǜ.K5Q/"DKaq/lLJlmT9%OX!yё)LrQd-w<[-#q݌4K(BYʒ)ĝ1 @"0VIO˰26oK'aJU7b XxAtiĮ /Ãqº 7 q3Q6Olw0ķA{5'rv!`_}L|3>MRLاirΐM*bq6:KH0E./E~c\Ql o]6kG0s9L9} L>Ɲ_ޑ|^Β//ٽ&ȃI38#RmGb+mo@|.. eHKgSddc)!x [IDh8@G_&@/QZ@yU1Hz '6#r $*/'sA@ 宊.A](KGm2ROٯ91=cj$d.[D/og%VG4_pmj2G[:}ˡ)<+*yDIo|-[{MW8x~ft_mֶvV֏2۩nrn j7"6I grrhˆ2I y`SYbՎהw­)Gqr}T -2Β[GnZn%r*M~<H4}Z˷-'OIGŵ$[̦;}>iH$`;S-) `fP Fa8[ev7jɣKFkAyhpM A59,oKBѡ8稳b?(ϕp?tmn-T_v9NgD7-Kbu unJbtbBz"hk>]]ۛhhdhQ01pbXWKol:LAQ2%jUڜN`<6=*njCB `y~Es4Kq Y0TֿC%4= m:ma+AeEVH6Aybba{,GZ{&O!x vqe'WRʪ2`Va?C1!BڃA '2RPd굝r@Z S\, Zmn$b]+YyΌ"]b舷0őf*E4SjN()J4 GP=O[95;1T?J>wTϊ 6GHp$f:|?8n?"h,NovH?!xe=.o\|Us^hoڹR~Jj^x2Yz[:񭂓^s'Zu?T>+hΨ;}CD2aܾN*;toSQTDoL\.7JB2[%E"q7w_x;"4n̿5Σu ]L {1164%5$p $\3^GȂat-P)?<͊nϦ1cvZ8<u+2V菅C{~bw 4qKB]9)̴wYɤ-2S'*;FqI  u=>Rjh!,4 - + Oʮ{Gn9/_FXaB8xbP<0Q㟹R63,sk soWVA7 [.96ze}6ƹD8Ñ:]'vp_lӇbgXyX?3"l' qfWcg<Dp+e[{>F<5eF6:1jGq3h^BeoTLT3ZyPt= Xb@R; ,U_}[ÒϞ< ;׉wk=+Vf{.l*k3lm%ǎO==T2$#6VmgB:W۟-7ƿ//*1Q.o{EMU]9K?3")I M"= Dѯ9с,G2z]>ksN(/`YƓC l@* =_xQ@`Rh}c* f1yqA .(^udaQ8Ow:ZU"[b7C=ssh)S $Kq9cZX+^fwm2S%m{?|4HT4~B}2gEHDsX++3Fؐ^/e]؜aޭ0uzۼz^c 8)9 {Tڀ4,ǯڴnCqJwg o9<(>Ao>ajHy,}xv͛4(*Dz>p߃ 1מ7Tva 7Jӵ1y{I ă&ϓ=g.l>8WC z,3/bM~IH7yy0Fjѩa)|D/H -K(_ΥZ-G]=npZVE+jm@di'} +;Q!=tJM^o4Vd_Ƽԙo bzIƿ[tv{u@+ˑ5.KqhIq s|W3]چ{,NӠ|q;%FZ;KW2yF$ #Fl yIc@` jxqӮ }*7ߢ%'GGA h",HDBq[iI\ nA+ܭ_-v\RNТ&Sld-m'WݠI'ֿ|(]XFo[?'6.f,Cy9W{ZKVJoOZ̮Wxn7 |\2`PpY^wM 90 v2 t==Eژ 0 "Չ7awQs,{<}{-7 `O72 =*Ď.(Du(>NJ5~o#z8ҝ낷Y;pXT҈GXճƊBnD ezʪ^_Pz4 &NR9!a0k`?Nx5F|3`o@6G KGs g֡L`JpYJc D-/;¿ܬUPbh,ҸttgA.R 3t4s c1_#4cLY /5|3$+V~O: B uYZvżnFSlmf=U${*.>M `a_Mm^U|\zU^XyMd|tiiB˶c \Gw]v* ?zxg.]ޟ5l7L?l|]xAw&=iso\_ [n]90!ó|*)ZXb τXVKMLsgHm1*’0DTASD9&z{| *0I?Ãe?3?p ўAP7v]-ZoG$ONPsyoD Wa2{lE;O?&ɌΚ*-$br}S~О!|.1,&u;=,rVB%::)&ȰEJWlϵ'Qc'Y&RhӲX@aT\6'0W5n,FgZ<,7ʽRyZ'CZSV (F{ND f-ӯ2Maub:/dd[zO&[F i“eL] X3ب@`6(L䮗J'w`'3Ѵ+6r}qmCisϛݓ9jYamnuE),<3!=6;ߜ++`D pzjvt/ TP)5Fge#M?2E3IPqG6;Jݺ8 y t^}L$ލ)aBՁH-|~KOiS{ Ruw[ XfgZ 4I+6~N.EvЏ딴H9bd$^.9!H{O)vV>Yw e\/a,9 aoY;fR3(Q!S%˲!k}2AYrɑ~bouǂ 30{41r ڥ[:>\) zn֢A D6cLp91"Ry o7kczc%PM/}nH3;}~7sE]υJ<;Ay4-R,&o|ҧmȢyk7@%Gom(wJO I{"ّ᫰S?>Fl0:;"nOa 9+H':&sC <+Ϙ4}6 QWm4i9N?(-Ó$@~X/ *Rb ,@ޅzj qb̓1rOȬA0'A83&b%Yo+`$(2 z),naM[IV{ќ/UNJs^vёAd7rM$IVo K9=v`sWc':5d96,H2.ѱ3?0Ĕh'~L.:>G~S3G3巡ItRkjPhl8f3܂3EН.RcCiebtߨ/>pdR4M9 @ݻ;#]o)Pj-?v^5jPܘ@-LYwb#2𜮑,H[vo8f{rQO3"NlH^[A|L{$q"ɿS1tIo= r͡I>XZ` ۭu'jLsl5@ҡDkz*Itߩo4dyKB|2_[N"Oyrhh>{)| 7vL<!j*P;:E5Ɨ1=D_' *NkHΖAϖE"t6: ~cGR)mT-N&mYo| _Ujccv"ɥ熰7`ЦV|@06RbKk!-i4O3 TJz;3P7'2Fh,niLNPk!riFSt/(%U_*I#_?ruQ. =@a`xBw: ǗtCyyYɑ#XOelڄnm_rJzJ -пa_>.%߿x%GLHbj-H;1`Aw7SvU%{ئeb!s֗$uS^Q ~}FjB=W} 9vQ]qݿϙO[Z /&lԸZǥږܣ cE/Y)hH1.X @l]=X4bmBSg!qnU Icn3s 23)%S3q |d5;*XK#f)nB.iR`9!;|o=/;ӿs,H㨽4{n@r6GYgG̺zt'K;|~Wl䗤MyKS,D5̗m6=>䏖JyG(&'1ECIVIK(; @좂P&%6ݲLH%!'pSQCۨCc^S⺳H@}'t I ?a>mnF $1j+<9B]H*:msג"~Ρd!Uȇ'_c⑵x/짴Su*֍5  [k-}DM Ķ2 6cheuA?R6m7ȮL}AV~Nނ] gıcx":DA"d~1KʡqOl# g}8&_SczM4<~ rrؓ֕JKֆi.Sk2z:wJxy`G隵 -khy&:HG @H|RS! gn=aH_nG6ҪPiBL[?|Fh'4F.Ig^co?) c$Vptr}fI??nH~OokyF[txj#.Z۱j=ø+3ʨc< ql?Ym%f#  R[(T4m2 rZ&I|<\$ϚnW9)תNoOWEMuZYT]p6 l ;ezew$y֜A1hԍc9FuRA3ܸbFy^^qI`,1[u ~hn}Xh>B GJUyp:D'.7Ә5D\dT\?Ry_gWYs+GU2Yَ- iPNZ]NhR\I:^ ]5B,tOm_H ͝{`I8R]v5s  pL @ 8_+OMqh[2Ջa.mu_8LX]F &P2e;qBVޠU<Mt ]Y*ڨvL"W =f5XU80P7zFZZ,qwoD]A>D221"tABJJDZSXPPy硾 C" rB8(_^v䑶T+9;~ޭEn6Gw#sf.+ QV۽B,2JtF{$tm1OEwhx~$.Η@v d2 Df؍C5+%(XrggN~{\ֈy&qu=VaxG nvi[2Л;9 M7sH($5h"fjuV$IÎpumJA4ѫQXO+ZN ǃxYUcCM~*ܔK9 lhyK_RMXX1Υ5?ͪ3HژBӄFRàl퉚R rE"Kj!<0+(0 3C7`*()K蓡 M7zCP\%Fh); %Iq‘<7/߾~xi YZ