container-selinux-2:2.95-2.el7_6$> 35K ><=>?2?2d$ ( P  &-  8  H  X  x  @  H h     8  l  V ( 8 D9 D:gD>/5@/=B/EG/hH/I/X/Y/Z/[/\0 ]0,^0b1Zd1e1f1l1t2u24v2Tw2lx22Ccontainer-selinux2.952.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.\ɳUx86-02.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&BXZA큤AAA큤A큤\ɳU\\ɳU\ɳU\ɳU\\ɳU\ɳU093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d8403657c1bfd05c74802d944abf9ca889a98fb54cf14ece3f642e932b6bf34cfa31caa7e754201b0e717c78ab200dadc65cc4091dd18f3ca15779a22d5d27a83rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.95-2.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.95-2.el7_62:2.95-2.el7_62:2.95-2.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.95README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.95//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,a"[]"k%xĉNμ5#+mz q{@gPȃFG=uǝ<%Пv!8)级}q s>!2i?]D?߻yȘ Y&q5?0uY7^}'4@;`RF{|_*aT/&>N^v cFαPc)]Ytβy(O|"Q\^p>|`(Tfu~T'm#9nN9`3ԳsLu%lȺp9OӥDY8jxP^c_VG~`>`(典֙h'tm=Pe-b0xĞQ.g1Uhc{@.i0-u#ޔ]m#BdK$ͺV2iJ 3 j"Ph:9q;WFPۢvpzO#E<(-.tڗCӿH~X?}$Z=CDž)Zq$v{؝vƟ?M4]led6k&k)"P/|:zÚss/Ί'29@|9֟?l.<#4[9~ȗFQS $X#)w jɷ.I2  -ݑK4H(ܨ+(sWS[aPP'1jt:İMirGÅ{qfBA2 ;ϗԐ47D]|ͱ0"Y [6+{#DwarRz-N '8z6HGwNZsl,k$J|?}V#d~4Y6ǩ CE# ?RyCmdb4yH2@\y8 Z"/IE r":ϔvח%: qlIv9{b !nqXD!7q^]gP7c>&d?c9M3 EwS5\UO%DWc:Ya`)DzʃjMBf {\fT¾gYHU7$gt7Ba g]4^wlm>ӞO*vL7nNcB9G4 eEKky#g|52B>gl_AIH-q61f\JMj_0J9a`jF3M֧X; !2̥۳O-͹킲9wzŒ$S42> ^"z,<$j/?3RL" uRZ 364S PrԆgd"\AX#X2m:b|Ƣ^6] Uʿ}RD+ l!5ҷBTj61ec E%1JXAd5Z 3bת爻?7t>=j7( 35U2T)0s~D>U5*AV%-i:_F!}C̷0miȾGq}&N%Y#?bi!"؁Z^, \쏭+E'}mH+ӑqsY<2lqSFO+kŔ !o=AM D嘁W#:H(Dޱ -ƙX<9ӓOFa Qū]FCDȪ&?ZQێAVܶ7QQk CI ^@yPxT9;E6 ^XXKtlVWÓ!`` >PDi8] :>:p.2@,N?H!?_QTfg4͊]E~@FP C|bZe%'h=\ڛUxoB`cWxߍx55#?zרn=ʺ')i@ؠ vb,g6z NMJѣrL?Kkz;IB|#;QdoOHj i|܇k,'chCGwsZ7os{L3#Utϻϟ`v8$[еE4q@fSZpmMkȵM`\"$-a UYw.y@phqMHiΊXgN/|#EbU*͢ˑuI'dik+E kfZWr6E7푽3N>G}|:xn@ k_N b. bLo,(63>|)/ z+j"JV=FϹ+qh"]LW(. HO pImsP7Ss ٓ ʜ(hJOMbcBzZJOP>D-FH =q4Mgs.wj3ěaQ_t>\} pss캖BĉBHn?0 ED*Drd%!Y̯N_9Ðf;| LDN>=\.'USDqED$?s@; CQdY8^*Xof ۢ8X}Mܗ;$?ɓs`Uce{M867~*I:dcb^gsy-AP Gxc_GgB!囝nNQ4O65=b!2n`Āoz7:6`);2[{tdkwdC}߸]ĵL u:JGHL$L Ϻgxړ}k\G}?._6(~;&( yobIä_[gϥ::mMc>!.F铛SYYcݮr~ZdWS&&fg\٭oi7㎐Ň`VA q19 6)4OYZO #:М nu<1 yaԻzD1Ms?۾QE26qWxD 213-/F_:޾0T*;[EQ }X\&j5aV 5$:6=`yR9I1/w(-QSh{ryhKzݍeʨGmy|^R.NO.L^!fd˶t ]lݏU]ǐq1 2aUS>UKt fI ]K24 34Gr2`½f = 9FՄʋ1v&I@Rsq.ݩ%7˿Q1Î?@nҴ}àz86HӁ4iRJ|ݾH! IŐM* "pj1AҎHz<bR> @ K0> lԫ:1L8hr@ ,M cE,DڗY|sKu>ċ3"G2X kU nJxFz(dòOXڟ1b4U- rQ٘~5 [%bjA,Y" 4NVfkbЌKvnL:Wr{8$f5zR#,&3L֜7p۱㢮ſ߼ȭRhA,9@P窎6TC,PbF689#$}uR1$Q y}9V\66»e&Q9rjۇ(iyZ[HuK}C\zگP7 uVEmJӿ,(D4 ) I+AJ}3r.g3R5XH˳ H׿]Ňff-#t$ N9I/M00y%~$!j2!gþ, DqRG?dTjqW$iJ)yG?>hDvAIyZc( p]Ui=Tw7KnX"6' ٞTl $nSEyo+鲳(s>YM}41 |zF/cIG+B#hkg?SiTvJߊNftlQCe/nYR"gv)9,uPw'`>.J]KZAp :V7<Ȑȼ+3;*i\NjB>,WGө`/nLynhzӰ'M }{@D6@dp1B/C=-mp/=Km if9i&DA\H~* X;Z#oֿS\0ݣm\e~eoV.kfs(T4)Pft]yۏi ?&Sp'̜ړ 2Is܈ :|_ul_r.I1m[0˜,[}PPȷtPwiE>; عQLJPj;1zip2Ҥr|5 ?<,N<e߉?gA݅=/bZtY* zfBA~½iycTБ>e P(OwQ 0R;[,䴈Sgi6[+X+DYݝͥM|o=)Bs|]!qvUUu 0"i)7o{֦ʇr$yA" rAY4b$u3_#9t{[וM+渌-,HҪ÷;5'wDщ] U>>[s4pLONu F+Z.H}xD/ W,5(u١n&^!71 Ta,Rc:QQ|kLIg!KO݊aV[.tbF+pz &m01u4 \D=|C2)4e46OZ/z{+n2ѬoezՆĔ&@S)Z(xRj fWF..V`Le> E@`c-j#?oQQCqԦpnDLO/MoKAedQsF| C}ٕfw4-(4*#tݴFg;ic`BvڊSjC SnYlfXc+pq?bRK# `;mA<}_UL\'k1éP,X,"Zmb]kbK 'PN}ѭ"G7 Ms4 ɂnceH}MPB߉Xh~^ IAoe4*Hj Qo|Uʉ{vU qUTjwЅ`kR'JNEnD?޽cM:&h,?&˶bFU*vOgmH@“"w`U㰆 -l0a50DqvH(J<, tTIjX<&D=u|dq#n%'@޶?nor$HR2/RcDE_+) N['Q è@ fw37oχ "$k~W6c`NޘD(A{=ǏКd2P%dzj*JG[}ߜOC@9l!vΜDVlÊ7eB䂄}\aqR}iIɃ<#V @՘Bd Zkli-4b`]E`9'c)Ό~鹀*̫8ۙWyVE;A_i10k_RV};g^,kЏPċ2K&`—spf.H5"##ʃ%UQ3*T6*/39`\e3j'S[;wH`xVNW`k;lIdR$j#YQ4_өEbh hVE[W1E<7,!){Q&3"ujYʪ:{o=9TWwDbK [ dTKc޻F g㏽aPm0e2aǿ&BZ)G40>j2kNѣeh, 1ɃbT/:t~{(|Y8m<[{W)A~%Y|)Gz][[io*nLdRg5B}|uc8& >>]ߊ,"9+zmkՂ}0. 3*R_ū^dDoʇozO !+ae!ht.[ FP>XAJ̄;y:ʨap~'w^1q<3dn@K`LBE X{p$F @Ų4YߏˤC)i5 &h$v]ܒħCxd4Nw8(թ>3k,HzK* hlDȒԅԶT"6 ld)ârǁN ^MFb14k V2xu7_.?u޳R[M<MͶ/[X DYU6|h ^+wWYDs<'?onnM= \аowx=6 FlHʆt!Hv(}I n8zLi2Ңf;Z](s^X#Xa%ێO?Α0V5|"}n`AN!߉9{5u .̧#]ȢUZgK}2xq_0ə[|`M'#4kWæ25(xHV6Ag2 3Gi췥+Ie JN*|.4MH)Um`]=i8'x~/n{Rfٽgѽj6`Xyb.x `!tK?p:nٶͯ_zSHn#eb^҂bS 8%ԅܼt>UP甅짤:mFNHE~yGwS0A#A7T K\{*Td7[ӲVh*Adz%}*tT}? w]QxSb7 oK9T-p0r7K+w.JH61nY39rگf͡)Ƞ5L4ep3XGRS$VmFwL5dWA%QŇ{lijWգB?xzs! eyB ja;nZWH&b/b=Of 9 fm_Z+ [*^=MhfY HC13@vßnI|U2#`C Raʔ5z e<.K5)bٞB6;PRKUsh$g5ԀGqqc{Ɏֱl ۱z6 "j,hڵLܙn30zJH`$0"%Y#0  >7E $-T5,O*/K!o z.-Cbuf$ph%ش>㱕!jGp#&Kҝ_BEtI&HL)ܛfD%wmD~M]e-/(2 g*WTcOICA= |s{L;6~q)͉a#{@^ nnpVSOެUw%Ά2 Y%dMw@;5p#g|J`::@Yn3-,!x(6~[5)]ޒEeL?"T&\tE-R-Nds%&e〣 a{(hi \tEޙtu+@@˛܏aS"(яDAZ0:l^uD+S~q* sa@wWVOzMJ"se137!#B!(ZC*҈<7VjgN7^dX4#%N{Itz;i7w;ڦTB(Is])aO/4D?55K:{S?uR^}zx}$xC_ IPn8i=が&ZTƒ`,yQF*BWc ]#rYC>ҴSҌd~̒8ckݷܮemykw"6QHa؞# W6ϊt =DX7tdO5B5A}TwP#8133Hp*cբ}ƀ[c?Яjp HRBrq*|p$_K乊b}R r31ETS}|ڇO/tG/L8u(9wUz @{F]9*Kwd. n/ETYOavOڒw 82Lq0$c%'qՌsUכТ/09PG\ x@ ayU#vI}SDjbE^Q^8O\0$Q\"ucza'SfO1ie^Nێp<^i^놺ρțg&{q6Gl5 P(PV B[ vl\(:ǀxn<Z4 91d|`^M򮟲#5_݌pGuŋrR#^8&b>E{>Ul=}]U#b3Ɛ\*QH77,j<\M4*kRŒ^@\$:}st$@{gY*(? U~Q_*yfMѤD@ҼXPȀS. ) T, ٙX5:t+RM<]Utt9 "%Eu Yj+Ev?kKGje9Vx3t8b$h1 :P<3pQhvWQ,O3c]lm6tvm ݧ{  J*;ATa`^7ocysI8~) pV') EkGѽ4h}=kq3v$ә!gF& ginAo^8 D/Z߯C4euR_-r O[ =]IІ黍;u2jmim1GL=<&p!񗭤F̂TU"r*ux}u^W/&@yjjo8Q[Y>J.P/v mպ]Vv>y R.+4]kC. L!%\2&5pJ H!٪֚^OcYK #ykFꏅm1-iXrA3q= 9"!!#?/ =(F5Θ{hr7G9o9{a&;Litk0l}Xnx]xfɨ4 efj4[X-sV4물>_yiޫc{s4Den݂ô*63o_`R X&W&pK^Z۸u,cgAu-v2FDŋ/]qAtq-"c3mA2j5#S >Z2: eE`a pw} g#ՠcoL_ ,e&曪3p!P!nqYn#og>{ȡi%*]e\'5Ĭ;d 4_F7rh_q "da-O{h&iKnuZL軒-j ' OYF#` Q~qR KyIcF$iFx.ҽk"W^}+~6 V^WtKG\܊9FRK1WXExg=}ڂ No6m \E,"Pgւ;[ʭM[ܐމ_cC<-\y[MT17rGp 94NM%"}|+%"W+V2cc# 2S8əK:mh[wA\-X֌٧1[~~Jl6׋kn]; BfmukFp6{Ʈ"Li{U`Q ,23:~wBvM>;-+!뵦p4w@HpPtB*izhƦ;2Ԣ.mEPDS]S< ,[S T-(ߛ=HL01EQ9uPB#0#kHemƚZ5#rY?su=%=~Lm*r:TaПJ_`Z_grLPڝA>?qy+1$gYHŒ9N ORr `X^&^̢Q $eyYR `&܂&<ƥ>WyKv0N͌@AAwqO48hp\HACo vW%)o ouvztSڔ1@5g?UyNƢz㨺ϪުT\jd{3KdY/ZP%qȐna$DV^3ϊ:5bOL{IR|ǭ%2RyB(C<|}b%(8IAJ@ב^s3%+#N5NT)P~fQoİƁQѷU7 9b Ys_FTq愙X ӆƖ vKp||^awUJ&,7-` g 6԰ mʾD :Ku#zW;6Ǵ,G,'7's?.N67 (`@P]a> N]I<\>9Ed=D|3T,xɈ<ݗϢOحdGVoX4qOUp;vE>T t;Tam:%x$$[tCwG5+mh 2P( Xe»!X]|H}fբƢ-p\2hp)@T4'KZϮڪiTp U #4%MrZ0&!;QEIdأ=xHZ)QvGA ltFFۆ"}EH0OۯKKn^GCNw-+.pׂ B*dyoa !(F.Qks)Z0{֡oG*rJ7:3М ҡ5F$4 'ug6 fZ,GsV ݂0>Z~*&?7tK]9mN(P$Wދ~?.ؗnlh&VfsH=#8bfLrn}T~Q/V>Z/};1eCNqewi_]Y̙#vM3#,̐,z=Imʩa.̠;@qaz.:*PTQC/S}9/UM|G%zbzolˋ"yv2j@t1nÂ<9z@ɗ4HOAjc ; [yu"]0Vu-`tAY-v[90M̠Kpx#yvY }1^\=V\n <`\E~U᚛H`1z5gju=t" 뫼Y\$/yDnحėȫ?mD⃑2(^?ǛK$nsx3p5+.Wm9IY=lCNK!θuyIh X/!DE$\lb؋=PWr!gsHmږg"ο) 8Fx+1xJ( ?O,-d.d؂օlpʐiayo < ۟գߤZnraN?zz< E:#Qn:Yj*ݲ\^>c9AOjOdV5ZXF2,i+=%@5 t*pG0uyDbuCƪ@Q Vec5;'pbb$S )L|du*HZ#J0)H D<(ZTU]o!w@tjMEvbթ`^"llVWvh0li1؀~ÒPbX`V=M3Wi`b8Wx=>)0Rlz6\ZL]şv-rk%!$.nu5.7i7WJd/{棻=潭c25:ɔonߴ8xO˳CG$8e }ҒF֠rDۉ|,,zvG?8i;OZ |G*)'ywL:)uwXNZ)u ƣwnSPG6]Uۘ=bs<شzsb8FŢ1z#zB}fy#7(ӊM?łikab̶ $Ϭ`{֕ bDzݥKNm[m2 ԚP+縇9|1n/*e;_4̡Ғ1{~~9>f(3$*3A$>J%N:s,u%L@\<-w89^ELB6$}0K\=J<1o:N@UMw\uw4g%$t'>ع GƂ!Zo}Ҕ}dMrCsb>aR#zj ?i52 ߇e6ɐTKOCY1Hx[~d; "kH^ە̇D1N%A[ ̷1~^-xo-K''WLz ;UO')QAj`~ ~Pc2GL4ɪ-.~]&$.B| !#G8 *=b+✇cU @(LQ;P"Z9{>Γz. t>3[F;o(0Em<u.1Bb6`|7jbɌi7\Gf+mvgLeUGo声OzZ-f*f\9l>,A9jgAƹ'AxwhQ@[H-#Ք\nTBEG>q?=E7vtmJ r@ޯ8.(ɀ?8 C Ϲ:ں'۫ĮlnsBYÈ|gNPjzŐr%#Y>q,gf.bp&o1( 07!7fѨ_Fxڨʃ!p'̘׶qpm1TjGg(c.UBC S]l+n4jSlqNf%5am uKT#W3=6lA.r`|%Z4>4K#QAIDyP٧_ .X=WB߼on+Yݵ0OkHDGяt{GDDBU=x3HK &Ŝb>>$EEAᒱ:+TaX[,>UCeEI:88cn]q[e^pl3<>Q.ݤu:6w ۈx;!EKDin7SC80Wh˾X${oƣҥj{1[lnzyF^l'7;J;*Ќd 5VN$w k^M" E߽ut Y8+΋:Ǥ?] {)!J8򧂳K4G/Sz i3uCr MAA o͎HYZ@YL~n}/^G-[M`څ|M|2x^ͥhV>q%zо GQWG+9 ODw<1^f[rIHdOx$P{f^`nĝ8":ì[ng٢ymlϗ5o!vLk rLõG`O{Sa!@>NQ4xyֱFd'%X tֿf)A soj-'f]<EfA|iq1%KvQD1!dFXblG7\"U\*Zlt2)t!6BJ08GXѶ:[.4ډJLB&Rx诿ڑVpnW@7i5>ILqm'v,gbpT_>ȰUyV>)8eTOBo芭0掏nb5 V4|O{UrO@7 Pʬ--LD!_]t/bRMqȺ8`Kn!^\%ԧ LqyfL`6.q}R&4yYNjnXJ &3H'cj=MDp D̚AsB&Eiw/N#dP G:n@waTt5-[%?gV+~~SJaeo4LRﲂMZ3S\ KQ?]|P@U[V>a y0 YZ