container-selinux-2:2.74-1.el7$>V{=xZ5_>?1$?1d  $ L ")  4  D  T  t  <  D d     4  h  R ( 8 @9 @:@>-i@-qB-yG-H-I-X-Y-Z.[. \.8].X^.b/d0Ue0Zf0]l0_t0xu0v0w0x01Ccontainer-selinux2.741.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.\(x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?=V.A큤AAA큤A큤\([QG\(\(\([QG\(\(093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d492fea535317f79ff2e2b9e2d9c8b22ada5feb7f1710482f31745f8381dae4fd52b108f469bee7c4f50cbd79c03b4c27b048e50468b42d3aad1a4bdd14ee4646rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.74-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.74-1.el72:2.74-1.el72:2.74-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.74README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.74//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,\QW_]"k%u#qXPNeR@Qk{=p]s;2yT?WW.WcXkQVDͽڃ)x+Sb-~q&>CƠ$_DOm  o2(4#:O=gThڨm|MF`#@KQr;{Fԍ7 Gu18P:ӯRn)k㈫ 7 NQMjH?:݌\(k9B ]`б$mwd [NX| TrAC1n9&Mf\_'6 p_ B4}TtOL襣.Pi_ jf[0[ zM: 2˅9T^%;`3h]Az!37κg3Ǻ(o5} $wgwsdC;"eY/>vKu'78B(ǐe=dݼłSl &@pvY2=x&q p3u|ٽX C9/-nx58dxCeǦR&lݫTBNj,QȇxʖXXK0:2/qѱ:)GثӵvRx]sta8ŮK^T|Q0'"3T5H÷.m;[Re(.U?ɪ<~/[PΞ9њ'BޗBݭZ"H hQOLKJNt">&_\ ĝ뀢&vˆ]ێs&gx2z<,DǝI_g:hI2aIoD{9_CN_4}('6^Qb -FG& Q?ߗcCX#Nδ"O0Eǂqo1.2d"e׶eo}_GDSzL.8*e\3e>G6c@iܠ`J♍~Kyܕ^28;i#_ %+^SXYt:I]V'BL+g10"*+P;\yX'M ^1* °n0l& P5k޽_ֳ !;el70Qf8 X`aN͘! H$'SdZ9٩D y G"fɠC'vE@S; As 07pF{:'v⠝{BId x`PtE"mըcmϾOptu0 c\A[Єxl#K֫њ>& !3J$c1!C4@1zSU܁fM & G*fKa p;=4]8o51b71Kx8|Sta(=8RPl]( U|C꩓-SܵՕR$B|:8ZAJX:;^CK{,*#hXg|zVԀ\ψ-+zXQ]닖v Jg8C8P}Ȉf)_\_QiEC z;ﱊJzmҹA& AD^rAZ1 =n2*VLk[c%' ڱH{@7BIHԄ6z\7;x|st+S鐋I:KI,Fꜵ\xjxBf҈pi)IWprTm6Wearh2Sale6P.R*G8ӓyZ#F`&R6*kkJ c=< 0'=K&CUC\0 kq"(bT[2ca`k:EŨl*DG&\4 t9 t1ޡe=}5i`"Sj5ɦu]*)fce6;l}|%Ͳa]Ó= ѧ#v U.fllGUN_On ACuah}.Kl/@on1BCS+*35ަ8М)ۏ%`~G9X0 }s&b!od.sFD䶚/&td}A3Q|cqWZB(f>Drٚ/ik`B"/X2+|2+BZ1 -OQ /F3!O.#Ӈ` RxUMneWH^OgR3aR%c2hGQ J=dH۳/Y f>ulB@cdZO܂M]0 %%I@[o^[3_8ӑ 5uR}i|=w,D~\u׻= O'a6z8 pit(-2=fXgW~*{J{-V^zhX~JSI :$VhzRkthDEVCDC6sȩYa~*:lx<Xy8Yu.>] ^,2;B%<,HgW/ \M % 6h`w{!'89ā?Woyt 7.h/)]ͻoja5؇wEYGQr%4EϢDpfem&'|.w砡 iڌM>jJීo[8w5jWZ"2(*q8WDku/}U" GF\(}?_?hV)HvlI9υve@ F@ 2 nF\6 a\} :8t9_r_i-t Y+VvF[<-7{6 $}j;Jޮ&f-hV\Cߖ/)_Q] c,NܝjasgUICd_ ~};lRJmz0٣-#A(R 4z.d5 TSc:ѐJAcbp䍽H˼ƧX!^B Y8OT~=_)/ ;\!¬9#x٘sEלY9 V߈jV7COg^-[A2)"ْv2c ?yy5#cߖ4p|xǵWSɃɨבD,4?0\YO+߬jxS h Hզo<735O5n13WWcgUl Tx' EYEބVw/MMZ׉k>QoT)A%SZ'*4aCv3 a(jpG{JjV̲i頀Vq2׷mypZ|ۡ$) k j*: t~XCFf$>]jeK,쬋,V<\"b|9Mդ7MղA2T>/<̱7Qcc*ڍX΋VΌ*pGWd=M1}$ՠl]lr$#-ݼk%t|Fwe-hR]Qc;Gu*ey:XJ.B-,nFD|ꄲɓbͫz]CMJx h,>ȪbkRعUMć@0O:1<^;ɵZfkUqx2."j"d%;&'J̤o\=Dh 5eRU[,Y*m#$ |6@~l퐼PubP_ 0N$[KxPy`{thQC%7>Sc_;sI ˮ!j f@2p1_o4]W4.vVE}h^Ie$c+b{lٖ 9@LdVuznQU1p8!md`̽ P #|n&$KB3 pEƝ"{]Q\62O񀯅(~WԎ_nR`8|DOEꍼ\38=t,0C&isUBTG@9egwgI8¶/ﯮ%tF&*& ^%- dafy8M#1 !?Q(?>#ʷ5XZ}@w< tʰC?ʲ&Fh.)j!:lqӕGb t7*=~ԂJ'g/FƵLޮ9BWr )gqq [:GGzAt^H|! nStNWX`dX'Ӻbxs]PA& uFk>[tζV!q/X5LORcpx1 TEq]ۋ^.^}5:, n6©t@e; xgO&.z(o ıw3V&FE>x;0A[$2dYfnǔ޲L-h\,ޑ]Аb:5Dѐ4Ҧ͹d?XʿCzL?M3b"bǏ`!GJ!xΨ/t" ])Q "ke?DZ)'pՅ-O&F_ p=et>4fjp'k[Rـ #-PH/@72&`]6[3nu&(xs?#SRx.Ss Tގ=2J5i, %.@M/R;P=06pi u?=6hF_x eЊ\Zj:F{դj(K\2Jx]%8RܛqI1Dp6i'hlw:-NU핮mܘMmf˖L2|{dGWRxi[xΘUaG7 T_@9t xfsx$SP?ӯ2KIw< su$v0(VwY zA7W|el]Sbna :| 'C:*w$>D2mDvb"`tjdGj\"%ʵrjb0E m &7kksy]P?>$BL) 9cRB4EaO`9>$8(M/c&7RqJX$&az]3 Ҽ<82][y;6pOdUb4nmԤc_uAc d'q*otSl0ƗH|L 4QawD&. K.9RýH :dG q+`V '])M %}n gxK-({R_Nn 0FyԿ  jB9O4N2㒲ZJJ"oZ].N쌰~O! aQ.8~vFsX !LBcB!B;^{UޔHd0HC TsuQ:AZj;>0g!0~xޛu+|{[V Ugp&R.*s5SnUP/%:_7wҰO v۰Tߥh\gqRkV#R+Y -~O1;)$לQ}??L鍗;s; :en(V{Y?#=<KE\R<#ؤK֌(ml p0g&=R9\47L쎣p{ ;V$rfyrOp@F}!qLD6jO?̥0Y% _^k^Z/=]gbVdMk`TMq=*6mn)[}*,y=|AD4#_YZ0#+|BK. څbU{͆f/ YXs2NWYf2IXTA=p"/Z0 8Ѷ!%YS Y)"U:A1ոlee4']`6 k9=XK>ВSIŽkp7=''td̍,O?D{^Qz: 5D#Fp[ yb{!?%SS $ bTc20ǀiHJ?ҚIމӸ;ےc&̩ 8/)PWaOl1)g6S7^!=ڿZؤ5\wtu(e=S/qreQUrǏqL4NEb51 $$h7$'޹3ލ *Q%=a\ذ. ?'.x2CB/_A i T;rˆdL,P']F!nnj/>kVp<";qZlAN4灼{֋Ҡ9]$ī=?=9YF\C9JI\!6< * J1-(*)z s#"S?k $^;yS O]?g!)\<Ů6%!ݔS϶\I'Օ[R4}@ԓRשzK1%<#J;GwoR$9 b:~ p Oe֑4N)E?|anԲ'oՖmk9 .hz??D`asvH8`40T $HKYfXj8u>$|IYlj!EC=څunkt*Բlp¢47>Ae..R4Xc:O#ioP3j㭢fCm-1pNJvU `evurmmp-=op١j=GrLt ů2PqqGWqK֫F4%ĘɃstqʭt~.JFfdyԫr!|f%@8*[~e@Q*!̕aP&tQY>7])mQJƒKamefr9R`=)^^>$C*{Lc2\nrN(9hKJ:P;QPpu? ,IRxW G 0'rl8^K*,$%%A*?xVd<ا=Ӷ 4gW$g,O`j[=pǦ'v W@RXvU\dt<⬨=ǿ0qnbJf^ͣh˭^׷o /I}ʀPSCD4*QWlq/eDҰYiLu]_%/V&iyr!"D\)/;< cd60"%)莮Vޅ[НaQ(CÐW^?q]J<"8rErx~|%vm("q ^-eFUF8WǬ$XQCa<2s'1K80b Kq#Bîռ;@gxD垷-&_UNzpQBICGJc)ܥr&h!*cJEj*NzxQ5$[߳q^!!PZ@xi4z+% 9λD2ȀнӴ]&mRwlC2𗉣C/@+7"ð/X>qdTW5ǀ|!'Lbŧu~.Dãqq3RdiA^QKJbJ8BCK+b=UiJ|2"oC'(MQBIT,A332XVNUɃ5iwhZD~a>_4uG~6ccW௺};i2ϓ̟tގ``u~b˰*]P\B)SN$#,1nnIJoЫZ՟NF:<!=OF8] tcz)qO>oV$Lpz7~\J^"hH˩wLЖvȭ/s,~n{'i'u7S񝛟dI]YKS(Ŵt˹f\G\HO87U]e-XoΙJjs{80@ gFb>ӞQXwE@cYOiF޸ };"Fams<ԔZ5)kb\jigne+[(./ '饩Ty܏CJrITOZ?'Xj;x/we;<  {3۳O4 42\#QhG¿_[wAS=Xk} KυTFǪ"D5A;"9ޝ$v\Ts5-␇6E=n E6HAD1W AQc Ԇ%A4Z :;W = FmzE 1yTZ)5Q/ s w<t˨϶nðTHAoApL| MsʚAbu,k) \}Vǻ-JUPȬ%ަS-4 ܢ1~{q9vgg >)Jp=iY !\)~syL(fR/:4(e݈BF7z2|ժ;2)@K7Lkۣ1%o:v۔a-dѴjy$q2SzxM^YNS(,k;>pIiQT%`J7o"{LNX/"Ad{?gC|!`CTQ>UUB :In* g>/ .qZX:P{/#ٽU]g:YĤ~k:NE#r H2O"u#h(ʪ5mi&{ AKVa8{*tQ2a?+h Piv>z ehsفu;x^5{2" hM9Kr0O{1GXW! |Є܅+KJ*J1F25Y BU[xNoPÜ)Jr_ MYj'm`tM.J[v^Z!cJ~R6pzF7IPg?nPEhܤ,y>enesZAV:x@$a Z#_KNOQ*$yx&Iw`0jKe6DrU-hsozMp9 pǎ(8ꯋu h*2krYG;wBy0!^94d cfG\Ob2R3?FǝP0aeV ޝ;f4=2p I*roe nBS6(cdGwr-D6ל4\205Hvf7" <:J!t3[kb(dq'h$MK{aa2RvrˢUbɳR;}sBc(+^6"!ŽaT`utދ͂jGYTRa c~$Q&rdYv_'gҊ|ʌjCj%=pSǧď5e)K/K:-/i|^V>u,'.=X"l??ŬVBSe4UM;Wr[fƲP合NM$0Ti vy6Y1QPy)a4H_䒖ɾ.D*EQ ;&<%>p5;>H{/h?{иv`榟$w/l|NWEhX2n.ARF3N78 xC:kOd4Gjkh6EV u Z#ЮzzJ"nKrv?NxQZ]]0>k +uk6"D} !hZ,@π- ܎F#-k#6e$d`k&M&faD0e1q4%TQhW0E ðM;&?Euikϗ"R:B`] SRN=m#,w?m:y3:0FL'j*@Qsw;[!i珷MH̤¼s`Q*^Ua(CB{ȿ#vdAͪ>ywTk{,8UfnQNLqq6>QI{7 XV${# w~~1"v;oMCSvTT%nDsc!lC|~_1~$uVqG~/d7r](/&$]GnUt\>ic]/ʔ$\WY%[$<q2 _[fQ7p:xrB\ М\ܓ>Jѷy')~p&o4 J'ݪ$^NBZ?L(RsKH*7~{഼801R.x*=D#a:"Bt*rp"K`9?sv3\'Ϥkb*O$hX9+٣{;fPW:NKgOҥe,貮B+^lZǓѯ8(n,fC WĦ̑@+wC~U碱mSK޹&/Pΰ 3yC&no"d'◵$'?w67,ZDp5fHp3\5yahZQJKa@#v ul僀0 )m nH@A*#M:.V ^2iUGnMTSI^+r>ka7n(Sx_42 OM$[9^Hf^SХ;0)74k-u qDM;#eqcXl;mlSZ7fELe -!g\aPb(Oڝm /(|A'0EHr"QwU;ʎ<%s04R/Jf* ϩ;CWW29rfl=@z/?# MWe9{?W<IR1CE K<mz,4w̔P#W+0669My1ms[;COJىN&0}Jm"`M|0U7d4y|ہZ)NrPCE/ Wu`))QTCڊW#`ީ3PnH!YR?uVd%WKB%>' U pcsq-P%Z?U0b /ji_6 9K ѩ3K; @YtԻ'Z?} Qdc=uοq5vqwmaF ª҅AȨ}Nd::M>Jq\-nN7"8ь4LuF*Ǒx'DJRbxUJ |Fc=W(#"Ž/>qC#9w R)Z9A8d~@XłΡ]ԓ+~`LL%ؤ3P޻Y8+MLEjN =ZUr!dysO4Q^$zVdd%w{\ R󗠿d.Q Z֯R,UF`%8T;.G54YH@{$S[C# a j\DҸy_Ԧi. h'!P&|OQT&~&A_TyrHN299 mh0#rG/Sw0@Bn ȸd:,2FFA* gqlEl!FƎʑ} |-ffqkXMGդ#?mfߧғU.hX˜fkv`Ou _3$&(Ogqv9D_^__bi>%cGbIݍ$~WP:Np% 5-A~LJrHKXxuWeGTȂvթW6n2nwhY7<(n6*r1,HR𙺐 ʳ J]C $^f8*`|)xOCİM"!{`mBYL^mtn:JJFn~UVNy5_80}1jogFл J޶j$rz7/1ߍLr/%FWTxշX'ݟwnkhxki~fZᦂ 6kh:l~VSd""6eg>fd0ݏnɆ&Q}vx#v_׎p3nؓk꒏ZM +[Ș֯oO7 o (.`ңc!yR:-c޷A}jdO(69⑥3{7w5XevAWI`ByR"u@s.{\vRC\+00D+TYN4&#~9 JLÓu>؟c|p?Ս} ã\6cA9x ?\ ^O\"Lண OnrxB  sT+sq5 D$m`Ā^\uߩ|lZNZ"QЬiˣ%[sOx@@+/Ä1/b "9+M9r1YCjwiCXhaKƜ?ŁDM5Cֵ I*m)StX֣QEdӀrտll0t#$.n9w=ʖpB4vN!*Ob@aFXxc]#^.wpxSu̯VoWN~a"n% J=9)`M4t<`?bb' ;l_ZQ'EuDe;{I>z׊L޳6`1,01_p(#gy:jBs:r*(;!4~,moat3ݭCMwŀ*ƙТ?p,/FW0qTGzgEMDĸYJ3J#:N(Oט sS {zF2˖Ubey4`ҧ/kQƜ&\o{UR~tF59`9LmF #YKV7ƨ瞆%A9W gѩΟցLrڕ6V]|>zTZQ{0 s`YUVb9kh;m_sq/c)HIHe*n=pȄ5S ȩgf]bRǺf6B=DszM\ӐMJ$o|T)Z) XX9RGٌّ !CNL,{roDe8/'v->e0:P<5¶2BV#řYLщXv@|7̈'Jk^[ʹ:2UB(*j_K'y~`݋`[.IP$F/hb1 #[ZӾMln cͳ̔={;84Mib8b1`[Xkv_>2cHޗ~#pB\Z uMt@ A2!m8tVEacj/y46;Ŗ_r$arE]g\ʕΟ`흵=XI|n;`SHuh lQE.wQ_:^9.o89fmP{64cJ(MCQVy`QcQs=zpr('Jr$9ɺVvo?99^Y@ͲWA Y\g>`9>䝚4R<2>xp~fKN`6brW)0QC~]=_U 3~]SFd;|4pLO9 >H* VyhTr&]AE_V=!Z1Bv9.`~R9ܦ5W8t,2z2.8wwق 3L@Z;f;[S1jW]G JNyBW05$ F]3G0<-{9CBrODaT Qߋ %ӽ*e)c qb >%3֖кqi܀ 6OsS/E&raJm$/ c.%GH^l$hNG$;9(%{VJ]G8BYIssxB>z( MGG[V),jX*Z+n$6n\!ؖF횅  JDXzaNt qh7 aI" 1a#!:hNJ.mY _7 B}.iaAHո-dIU3M~ W4+tIJ'vvBk޶؃sTOl>o.j=HxBpM:0ޠk4m1MBYh̼u٦U(;v,thͫYs gJ׿<ő?dCC,)5-SP3)CtIF24]oR uv`+g_)f= =v6ŷ PyCg{s3;ː'Hfx!AsIOa&ɧcsuY!;b I|G2{X#*{;aAyafvM[ԗ{IDW$w$*uKGP+Sc?j`} $|LxmO.:LPI-IpY7A rc(Vk8$b]P 7ҲBҫa+hcMblXp{(*/[oeo=XЫPCI%`MU|J΋"pj c~ 4MxoϪLaS:lc۽{cnY4cY>i~*PdNk%~XdҰׯ t`q#[&D"DS!#cn{'3@G%C'Qo}_PUv'{Iٝ]^>ڰ1>iRV@]՝)kr.OmLBIF |K'h%C`~qU:aN1>NPYu/GpӾ>x}΢Y/}^f%Xz6ʕ>Ꜯ9JGAi8-_K%۩6§tKf1z> ?|zĜ jKm<Κ2dҬ& +&`5^|^~MJb [,CLc"¿sK({'^(QFēghM ⧹-~D7~ _֞O Pȵ}KҸm-+֯I?6tOe:sq][4!Mm@E`.SpGD8Cɿ`;#7w^Uz@'u?W%}^ "2y"~/&Vͺ 13vZvX'xV2=UA)=Y,m b&D+#^|R1'U# Wn|k$[:Lt7-rQ+ϔJ~>77{{ҍboգX"y8 p b{Q%̔F3Q}ߨW~$I ' ycaZ;> Jds1jck3!`Vi)S2Mŝ$nUz4uV];ȋ g,ӡfVTϊ_6\yTu)PxlTzWS#* y+Y])XCun}LsXI(6BQDM`T$7mTgV/w -u ؏a.wXI {XGⲷeYM8AXNbb_posYoq{UҸj*zǶ YZ