container-selinux-2:2.95-2.el7_6$>`^l't,>?2?2d$ ( P  &-  8  H  X  x  @  H h     8  l  V ( 8 D9 D:gD>/5@/=B/EG/hH/I/X/Y/Z/[/\0 ]0,^0b1Zd1e1f1l1t2u24v2Tw2lx22Ccontainer-selinux2.952.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.\ɳUx86-02.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&BXZA큤AAA큤A큤\ɳU\\ɳU\ɳU\ɳU\\ɳU\ɳU093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d8403657c1bfd05c74802d944abf9ca889a98fb54cf14ece3f642e932b6bf34cfa31caa7e754201b0e717c78ab200dadc65cc4091dd18f3ca15779a22d5d27a83rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.95-2.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.95-2.el7_62:2.95-2.el7_62:2.95-2.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.95README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.95//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,`3ZG]"k%u#qXPNeR@Qk{=p]s;2yT?WW.Wcy" $6MPu2Y&Wm|2&ݥ]RT>F* !#`cnP 7,WТZ#o)sR"ӣ_6Ս@vhsE)Om;XaSW=%.ϓ)յZ0c>ǘE]fm ˰SjH' []wGzETzM,F:Wx!{J4)@> JWdN{F* 8#A\^H/T"#0_1[>r9N%uƹy{&m9Dܻ@)1 ;iFd?iyRJ>vЄS&w%BfmUЙ UgHBFٮ(fDWas2ȩWpU\A>A5UocޢiC8FqD Âv֨Ftuz$U( 8 }=O E)γE7C+j1f/(v/wZRR]OoFM tpbڈѼ'@|`HV [W_Ǹ60r, >xLgߑTQ~dIAT%b/ )lw!KW5pZ~kb*Y&CLgi7{DزiyS*Qn*G.'ʩէIC֋Z=*y$7sPwaBl *R#?e|N-8jgBZ @FۍʌF0&Fsw[O%]16{&<>A'\-?2W^8n-ۆ_=Tqi8AV2 P#!;*t,5|[$P9`\卜4{@6%.US9`8x3~rj3 (cV8~~rhgO߄&LXxR!>aSH D>QH@G>h]lz_;b֋y@N8C[vJS["%~ H.A6'sȊWW[L;h:O H4/m4:7C9sP ݒ-6]n^?N$=Z" Ő̦YP}o,L އv<gf iʇR,E*%ȷҿ2]Fw!.{K 7)u{R_n?Eª 9*'CAP{oY67(;f`44wlc2XD/flb>*KxA1V߶٥=ثF,P-&Y& aEf6![W>Jr|xX3X|BI@6 ˒d"5Q +a%3}^ҧx}LUi|6+{D&P$ FDzEqXYT3&3)T1+J2sg2PfŶHL ]5svІ\o7V ZwD g.lb\y@4/͖?` &B'fF hjkdosGs##b{cߒ6㖢]}2 z&Z12K9Ma3A(h FD[Xv\X>wc_Msz 2Hh߄bR*yJo G1ýc'Da/A]:اmd=̅Ӥ_{GߵXV3H]OMЇ ;X5+Qcq‚-Θ_~.6<"وI=Wo^ ?Q[(F3][.J$6ƟS]9?xQ9F^i}*$hMp_U&W,e{n3"_zs2A:YK`64g,D[mSk{mcŶ :-K/XSU o,7>)wM\Z9}֫rn.4j3yp\ﰎ0o.B \31hVҌ>\LK⑟tL]g7ILt]Q63z'+p#vTƮ_FS $TaFYJ Wi/ pX Nci( mzH5u.A]iXɟ#WN=Q5 ?dk9X.H'dr9턳n \cFRgjeRI?i/3S]egєPz?.O96&yA3YꮤĐu&Ud(+-~ǝ2.-8x W)<2gv avýĞb2L9NSOm^ k&Yud8y_5rov =ԯ2bIo mMNƓY~Ii1Bsһ3LĬ)9p.]V1|qyOx)ڋ_r۰wfbnAVC#MѹF:W Qv0Ah$%PIۄ\{?3+H:Ha6Cva:R4SN"nӾJKtNŁm.,UZ f$ʖA+R~kKB9).{}Ҧ.lAz'HVx.,.eσfnqr]),iHOY[>BjGf"ד SKh?Kut?=eTPyg%AY![鐈_Oi}a#\YΆ)sV}&19сvSO):߉p_(,oI [T$wS"GUU} V;ȁٔ~iF ;ȖE\?܌^ i݁Mi"hAmszed.s,NjByHqV̎{Ӝ;VwYkB<+`WѝO>LIZ4?wDQUlU2BQmPRH>7x=)nfq{"V41ːʴrJ{ȽjZmZɱX̶CZMʰnJYJwfB㻿9K3%u'Oxgh)% #+6aP4#sܰ8#,oNfS~ ;RІj+hߚN햘 lO 0+tI{[d㓳'p60Vq14Tlٯ? a7!lȢA&q3PF0OdѯLs(\\ϿYc?D6ڝsvUx !JtChp%ϸd&GĜצa(QqF LsҜZ-+42ݺ脃Ft=7烐Q+9zs*P,tA`o.gvL04ssEل+2KM(p)mMu1l?΂%vajA 26?AWu}BXovɌa=~$+% de1hKW .Di|MʂsD;.;1qK,O9N&榔3,::<pӊ^`;0$ LgAUM3X$ mjRG?N 7F ;OGY\Lmr"زmYο(X \cΈhuK?Q=%˜+tmv(HH/KT xꭦi.B|iO7e-šp%x<ꄟ4՗(9:4X $/_7(TmQw`d*_{Oby k˱FXjaHg=)b@} φ=0@D 8x+Dfxr +%^TgR@ V`!d,; ~e:V+'xHi3md^*Z9E ÊK%x:)哅Q mk Uph5/ :QrLe1E~۱>X)³+MMҫR,meΰWl'%2~vҫ7hS.h(+VLy{ Fsͼ/'z=ruݼb. * ZZ?!xCԚ'4U<8TUqc1",085":qQUU<|kɲ }͚@_n0ӽҫR|َ;sbD;FV~lkՓ7zҊ_ UQ3Tx4!l\T0zQXhS_ۍirn&u+I0[$%:2K4Suuv/y[$V8c~F?|ޛ )~qToR<!TZl&+Rdڌ;3\p6 mO`1NT4tAzJfWU)iv[mHLyw[1I~%!bت\Y6їE@ףʇE:"h7TY{ n[D1Ə])꼁dc/z^S?~3*FprdbVӏgYXn9-YNJi])޲oc\p҄YiҺU]jku&֠' O}ECf"āE֒8ic~9o^ٺ(IdKyq:J>p|tu҈ktfQ`?r>0F)ct#z=T@|?7{#;Vht_ iS|Ѽ;{l +H$dkk5#{8 fk@%jǭfbkݹ?#- e797S4~vdo[tn<2ke!6=ɷ䓦JZ;\5 R+?肵6A{% 80JgF10֊V|̫9vBT}.ed |DP AmNQGp603IR!jdd2YI;%9tuFf4aq#0R[ig3 =f䇃y[3wU6yei ngbvfd\*XxQUV'F^&j_`u6|:i'7?:y2eop>B"µkHŋ2&&! {=Ȳ;1bȘ$TjĹPcnsƶd mJeG1 wGS["t,ȷO]]V~"|apۤ6-Ud@D8:~X5#r7pnjG<1kdȓ@5 +WkZ3sϑ-($% k)տ$HPA3#l(=M`A|N1 YCZG? AF%CN[>֤<7,?Y2Ri}eFcItH4Iit0sCp州eI%]_QiW}9FAW0+Ӆ_+K@ri30V{|$#IeKZ~o'êێzGb`N1o* s3ϗZu5*ju\Ja?HYiCaQK' &)kc̻ Yu|$blD MamWCӗT7.JsP&0n:)*]񲙗Vr9^ɓOLj&q/;gk+^.,_gY |2lD䒇N6Lxl(hUŊ|.g`/3 8? s!_$R e t7}C;sG@Ә,옊E2XˋQqnObZuCsLxt dLWz[!qpߑ芣6x]Lgt2WA0{M& 6U{$Za=}@febޭ7"f:6,3cÁ&jrao.a,_uDJƣǷF @ p|m0zZ:k0Oœ{hpa&蜴Mʒ_F33SYƂiR0az1+ Hx9U|QL <H??{Yaa.)" %=HGcf\O&{*Q7L,FUR &a9zSREL_-YqReI7M`m}sgq$c->6F7tЪfL ѮĨAF'OfMA̴@l+t6q/ eXtϸ)swjn;B$U RʻlkedPkj^W@7-N6 Cmbv`W ){aKrx48K*72׭W[(l>kg_gqx s延- ؐrW5;&7Imz ︲!p@EGf4\Y7]j_!It) h;b۝GI8K;-'Q]OqvRؿE~pX1cB\Hn^N'\Y`Ӹ<+;C--TXIB|wN?\>> ˠa'mc `ah,?N 6V4kPA,Ded52zcшj}GF~d)ӷi%K*.B\ S/"??KPW-XML,_]Hﳵ/C #}Dt\|{b*31<;Gl0}q͞2i4xyȵ]DչͱAM!!(A`doa8el<l^D_ c/O%M  8m[@].lǶ7@&t _d0)ޏgS+ -дK?ʕEYDMNW,]Vm1H> uO؟@R"!oרW< q7vOv_@Aθ#)a\!"yC//axɳL+HA;+)g븮Ӟc` 鯛p:xX݉īfX;`)m𡻘/8M`\HK2s2G~qUys%k(]X|DѐOY.VUh*n=MO@ʜ^9C/uw|ʿ:&k)U?$^=pӕ+qC“z#n)W^ߘ-tM,tyu 7@֕M,J I,|4ƪC9v{aM65w_/,dACű?i  \2t‡N4v4FcYC ڣ8`eh^&kL=pb(|G=&4?Q&<<@gΠ7-C((hdLsYYM1Z<0F)j36pdg|$"|/Z2_u5|%2FǤ-;HHZnN~'e7o+:`^7@U?U.S3F34x/t4ѭ tM=0^!Qf\s(u1PAv$?'D}wdV赋ӭ|xȯ#հ`NZV;YCn^ǥ6A-?i^>$M 3N/K*Ro zX7i .sҵ rx1E'F?a"q[ -+Yv3dۈ,N̬Dz.H# `#~x(C{t{Zǟ} Q^TVVvp.;=m=VPYJ,\v.~.S|!3E'Fh x`DRI" *eصk?MόfdgM]#ZtKԑEkyȶJ1皎?^߈>r ‘ =ߟJo>* v>m . EPQ릋9j9TqG)GR/IŹ,y6~AÃj q/ReӫBg)k *kZs` U2V M:Zn^Mz3R$B*n.fmpa3gT9afoy$[JՍʬ~(aXjm`j9 JUZeO핓mKNy s"-zdGnE{aZ/R[-O/~0oFGB,\+r}-_f_CQbVJSj4_ٸ/ղO2Lů'"FD8TY!8u7P p-k$3Fn}q"`)эSXhؗF$ Nuk̏@M.=8s*α2V50hgmdM7!]i.^$7 ~WPYA%ѥmUcR<8\\Qbɩ;>0 .Ȧ2ADnbAO#,kM+w|.7!yhx4zwp|'dǎ*^vPglT˗ ځhq=/Owt\&Aŭ'n>\-$ˀp!Vo%0^k*}1Rf{Qe}7ܟ& O6g.QС??Mh={WqN  BR#&_bZ4(IR>p i?NI9F8䧩'UTa­k}k6 2`ÑyŒx f sm-%`90uvwsAi_zRIr^V'.Ӥ3XG (bC`Y [bu͍1&Vr r)?Hbj~]Ώ$Y 5@_;cYcxݙ1|pKd[}-{^c/ sףvp/T! W}j4kc=wTQ[CgѶW 5$߫ICDC '*j+Ij܈P$jzuxfk \嵜H+u=Blʉ׬GASFj( o8,,wWϰh%Ja)> 5#$밽k.4t;a p*\ΎOa]uQK {3v+ U}`y4@(Mo>{v-f J(\sWq0EBF^63Shˍ1J6؇ƴv~ S&9(J6ܕ+PAs̴+'!2 5sL|:'o`:DF#XX[EyA Vn k`Spy0! ?aw"z!zNwo rUÍʼn,>G Q/~⫷c(1ш9}UvXNLMm/u,_ Մ@g*&L׷3nYDNKKMA:=EW/DP3J, .!(=@[ҖlmZáx2~Μe8#pfђW="ӈWmgײ*>)4-<#!Zac0gwQ~#35*` !V7Q&gBǫwV?Ŷ)fGZ_1 \>c2DHɛ0 2 []23R1TԪTGk:Dוv_xRg'>ԉn% 6|ުԮsuloϗ,{*}tH9{uz*&X7[.˯ UWla0m)mޭ\}B<9ڶ?SNjg` aHUsQ#>y x78;7ܪ`'^Ao<␇#gkP.vKt3*{)^d j"]TuU0u<#dȰz;^fd)3|jߜPW }`/p&$ dOQ.V4\B'5u\^Bt֯ OlfiJ?7d!-Dp1+|4X:oP3pΛ+WC9zsCuT&XI.%:_(iYAq5%tG 0=f`qLrC}(A sNR?!g>xֵBeؗLwl*^- {]WK8pRj OysoO6a04v#0n/քAŲҦF}t}2<9JێvǦ3|-Ē 'kRxC}{rI#tIb-(ȶM8GUX )*Yͣd6 #8]ukx -oӴx!UVMZ^&>$\@l2Hh ImWC9 J0[OH~u=<mI&PucO&OEÈ]$/3(CI\"xzx*#F?i;WY»dB/O7:Ae) DW~mhBT.)`ͧs 9&x]DjlY@ !PqƼLO,Rt$tMRуzZbO(r>/ş$q.j(PWZxJw w.s i̪5՚"f4un.9Y42m|_a>M &b@dx^hb V^$Rhݷh">Τ70s!q'S m*wt5MA$Vdta)âDrꉬWhСKnޯm{OUőVukJ&G{p܆!o8(* cY4 HWppҢ]] 0HB^_/ DɘL L"+x%rVtDR߶DًαZ3}tXOGg耯r<*7z->QBm.|0o2b=z%!^ﲅ;-^4D_4g(^jn0:&@qoU!VF}dZ.>R' TeҲ/&UGLGB:ݹ:T Cyu#&D虱ѹ"=yO+sNЊD(Pc1 i$۵lW{Mj Z hCT{zCՓT8QUx]F+ȎotՓ_fG`m@)1 mJEeԯ-:<-}W1@T+83"QV߉m+l2yX1#(ZCO&Vqa9?R1k3c\Dzev=K-Lb2% A٭(mv tɇN)H?[G%"ǦEXI{~ov5w4K 36?;0ҫ+{xd!Nk/o"Mxx՘BqLc%JA=ۮbv@{Ԉ\(V@ZV=FT>Fa&$oY%%}dUӀJ@ֲNBSjz '$_W; ':›#zGS98k U%ez3-q^@v^̂:K>FbL8{L;#,]}a⳨|tS* Ţ M-K{DSĒeQewaj9P^rM3q@eě\n1*a%`]O=ݟygd qFʚXfp{b%\'m6 fSWi\^5W:EkpTI#0G]KӢxT maϋ ]]\2 yM4TGRUMi[vS*x~<0Z! .{si i5T9c&(nUݱkp uY)Ɯy=25'v^.Zv- Π$hBB1:/ an̺wAIjze0"GT+joъuɆPae~"f>W6bϗ ݳR s#g^!$~*qu0*=M$zh=wygG]]g:;L$#3J, Ԡ;R fգ&g={g-͝ {'##n~(9π邥Oy63/7WXEp[TH}3hnfo'Ӕ#?!2N4ȲkxK6Z4w2=-Eգ$ֈζ8LQT`eӈ$Ĉq1^S+'%Ԟ}7y,He(N6< LThtϫkXYjc|#{+W3k1w?EQϋJw6qib?pvvTF{bUx%h57FQ^{׊uqTPy=U/eՃo[$N ğØ}7;U|.B ڿґqh9$eVA8-q#8Nu[_5lp&Ȟ]DT`-i; ,a`&miwmmg;]ͧI3h}>5a$Zz Q+hḚ`}H!DگN@&a%J?ҦHZ;|ѓus^rfr1=CobÛ?]wb%ᎄ4/a~AgU rB0CRkh+2!2Y {`^!K %3x6_/PiD}` W NQH>p/ƞ0/n!9@y; Ft},\ |Y&^_ْ/ )^ksrI=]+pQHgKnQ7=ibh^:ehۧ`Hwװ!,rҪ$SJ}yY{[UK]Rl#^~܇dt*M޷YJU#P0lh;?n>zR{w ǡ=.d08; C΅讆>V$>>O1a@۩m nߵsH,aAކ՟:97)4֟ :A(5$Yt1c7]\-osW˪b0oD꣍xZ•2~n> f "2^!iB'x؟7&q#76't\-mu@tj6:0/ i|ߛцm?c%&+k,qYÌ B^$ 80\jГ_pP]!xⱲºAo f+YQA_?']K<$nWGO ئ&ÁKZ;dϻ}}\}rs6ahE8+/.,ۀQ!Dn fY,_&uqO|-%-3Llf0B<" @`W4z`0@=}"|F<[W8|PP-@pkYtvred@ߞ-纈^L#t[rZ7։uMƭ.a|Տϖ\=z% ,v%ʂr DhmGji!iR֨ܬ }5Ӥ92NGk}%fh|1 D9ɇeLc;I[&gF#X \Myo U^)?CI zntdAcզY!қѽsigffTn!# |Z?e%FD) tH guP>~* #Jf,ty/{f;?9A ic \rm-gvrqC/x9fѠsE.ViWq(f}i ݮE 6- f("*F INY{Y[ӛyvH"jJ7kUg~n{kӋ ďXu]uUujԄP~|w$8fHd:,<ȹ},r,)' 1 Ǿx(>]{붟PU<%?VC'R] wCSrH-:p1Y6o b$/7Wg7H8aq*#q=vnsH!ͲJC9ԩ@?siMi`t ǭpd8*Sκͻ$yۿ2CeR;lQRŖXFێ;j5`"t'H&oL.<HVt+ Ȣ8-PKsc_=N1(6eqֻ4 i³EWsSe.4YO&IǑ 4s%LuI2Sq4t/R(FrXm2AkLeqC4RfI߰#R1qHPW^7!naΞ_'NtQٿޡ Y ˳?dkiAi0onakrhU. Ot ҡ~ >,a&Ttjcdﵛ ާo&pF_ͫܟ0Mx #]Zp r&.F 9eqmh檦Dl&XlsrV]xcoo59wEetc6Gֻ K4ގ!!E:48Lw@Ԋc;pqƍ6"bGJϛNVpM]vEN0#dkJqW[q^ޔeՏܳ,:Djɽ&4k?"LO@`nV&=ύ#MX}m05HA\~9 rF99V0 lt-SNS;sj@#U7 CD KC1̋rb:'ɿ< %ۖJhG[_>Deec[|&U 5GMFyw _I,TLS-2/${R;Vd'$ѥVTVF<:^$־Iځ)ҢՆ]$/r ;E}JM=2r˲,My``u;EQ YZ