container-selinux-2:2.107-1.el7_6$>m&%q~6Z>?3?3xd$ ( P #*  8  H  X  x  @  H h     8  l  V ( 8 F9 F:F>/@/B/G/H0I04X0<Y0HZ0x[0\0]0^1b1d2e2f2l2t2u2v3w34x3T3tCcontainer-selinux2.1071.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.]HFx86-01.bsys.centos.orgqCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&G=YA큤AAA큤A큤]HF]]HF]HF]HF]]HF]HF093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d8491a1d23bc4df52b6735a5d3c52f1148999a8108d02557774495e4cc87beca036f6566a08b292c96be1bd93bf7f15cf714fa799e9570145c2ecf4eaeadef8a1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.107-1.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3]@\@\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.107-1Lokesh Mandvekar - 2:2.99-1Frantisek Kluknavsky - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- bump to v2.107- built commit b13d03b- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.107-1.el7_62:2.107-1.el7_62:2.107-1.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.107README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.107//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,`Z]"k%u#qXPNeR@Qn]s;2x/}r#=T"LiEslq C@Ch }#\C%Ml MrFPp |v[,ԩ‘04>sz~̘ZR?(ϙi6CiҪ)S )PIxy{4=LMηn\ h%G"\9&WZNG<}Ě|2eHz&4ӯC}8-WY| :seU$^7Qڪj~#A!@B=L4DX ig?k01Q6M&j3_VWfssȌHRMR!ϩy>>4NO)4$3&꟣b7y0 >HVB>16ea֨E:!\3@PdcŸ6"zBKOv[+hmҢoP7F؟uT.ΆoC+$P1e0ͺ` S6ByI_3wҭNoFWhJĺ5<Ȁg(Eˤ7 ={J@WMQ[=VSG'ާ3Z21Tj\̞B H&akF+_PoH㔞awC5EѸ Qk'D7m/B,D-oRi;A HP;U+^'-{0Ц[mT(Wȉ= :[)= egCgoo غvH;Dܿ,QCI΋,_&.V~?" +qsAJK#ecNIQz/vr09%8,\qB;V9GuwT0-uϯL5sv΂oG| 4EU]Pq @i QeLHoB&xAFܐlyV>ad[qHBSvn)qqdB+ bŁa^S=HɭHj1wb'7Sl*gƴ0د ?B.)n9r,n&|jmdxE6^^R#fg\8UEڭEl|Ŧ[fb=([tqbKͬ3Qz3S¢VfB4,M 9v  #\0fV1čtg_R??J 4mI%W̛AEdntS{NYK3N낗kzqNt H B < ;%̮l)Jdm`*9sxwԈ_^Ņ~ kPJ$CTf*JN:*s>ÂZi8"ľ'tDCyg ~@AֲJ^reh:KoՂDm!gmzdжمȯ>=]J6}uxJ.ČDANtK_UΟ>4WJ'Xp~- sΡ䧄РS@BUNCMrC6GRS>#9%7cfJc֒>&~0 ӿ=0z"ð$t6+dS0}S2n0?rR#Z4Jzb< iQa˵u{̔Ir&ny=rQ"I P]+(m1sd&S{ q9]> ^/1Te13[ &Պ? Ϲ:gepvnlX@;k#hϕ3D cIInݒi_{$B:QWf3y a i!a22`yDkbNQË)!u(S׆ܩ$T.=k>:/ !BIύaDZ-0֨}R3H.d0*c{<sFA('qdq)[Euxk1i[`T' u:.}mՌZO{%wSl14hdZiƇzҡϓ]jQKtn> >Qٌ3R_3Rآu]cDf-hKaZ.r~a ×a%l@J:" HeLbΥ`L:Ko֗rI5/6N( iՅp 0 +X,=] p6N6I?94:`s1\9@b,XXӋa}IX'igsZk4}gtn;s*-fIi[TBpx6DO"DM>9ĭZ9MD2RMf7qO{!vgr\r1 iQeԬݨG[Sfnp}uy׎A{F]aĬθR*d8bB+֊)H˒|dg NyOB=rUa9^vp:{SLT{ JZct;=pPyMC9Kٜ"xb p" Z 9pn\QIiڢݖg}Xlo?؏W45KgqL*Ԩw@1RREq\U}Ķz|oX4#03ӏum1QTЖ2h*م\ Ŀ,23?K ZCPV?tB᎒۩MTɨ{qʞiQV$ptf:}]H;>f= Nya癟Z9TT例kZaCڭW4*ቘQ.}1*QEVq{~EΔ$;/HS:dCS) mn !K/@zHޥ{'*̃Cj%0x~CI"qėV4tR^~j|+q{,ǖMQ(Q&~._.mH;!H$uwgݹWJ"'Pa/ ;Zx8Ոj6p{hbP2sS<.Xw56|Ls>f$YSce$=O.ީ,Axcyi1e@f-=f+oAX`4abY2*~#ǵ~n'Wc Y)C@ =wp, P 8N&Bwge=4qLS3{řno٢%`vA@)[Y.oG9w^Mw4{JY5{+ m>,ءxXL5`]Yi3.w٥*(+ ly>3 ٠2[W7i%(IxxV e`?r xp7N6z7ah2@x\P~%]B+'J9v+'8~ZS mgIIGiy<'Jj0WgRjE&z!Y`? rƋvRLLDgֽ$Ӱ.9ySi1U>]N'kƦ1pc3-j3I ]CmqK:cߚbiZ 8 k}؁pbuuh[]Zcڙj'S*ita6X@oIm\^U `f. m7xR?aUloiLq75◤).P u΅Z* |mYpRŶW3i>94M ,ԥ\v^T*S[*`ꔗrlY%nca=#ȫ8O~p9Ks:QB|~6A#$'gGɒh5c{::`Xh}:Τ 8'n*-.?΢"Ĺ!!$Icį]5m ڗ={Dm7_Jب_D m+%$JV4tr|g?)  :MmxܣotfKah_+2p#`Qa^致:[ab~%yD֟I\ {rM7>~1M58S.WʙIYDppL"9IZ"?7h"Qov? Fk& g_gK#@\+ZhTՋ-Yp P ?t390@H| 9Iv R=+@Wm0t6c2*E%PD3f. tժJPu)Mt1ӆM`ں𠦊O(1݊bUʱS!cA+gbQ[_mU]_FA%Vp .gMlqn!5rsPA䝬O>+%SZf/%yIϭvNzs|t|)Jv4հ )v'MȐ`#%3dem ݷ}c"~W&#!R( F>d&ҞSCjdwHA}Esri e݋GpQ;&`7-n`-\ v]?JK@Gsta C~&\q{ִ#Za܃%m)7d-pcƔ\>Y/>%L|a2hRB{ aA nɪgB<虭)6ژ$(T[ZGd#{@@W QJZ%U$!{*"Jf0tG. $n4Xǹ|3jw!/I;6:8?ڰŁR 3Ϭ́[p цnT1UH6 92~وa!ח*4$dQf?B¹7w:F-a/8־R#V=&ApgCG-ݛuܶ~rY2Yǚ #`rme¶b:XinZq逇qr0$%W8#zx#$AreQ~ީ,̘CZ&_l$9 |wVhYYr}Rd[-JƮ•9 6\U$ϰ">(I&QL{'qnFl")= f1~-|"jYGB8Gs,.R`_̈́t=dvK0T }y "Z"QJMcWp Jк|;Gzջk(܁߹nVm7 y= Hɐ́.ՔC« )EqE.YǕ8i$+7i }wss!ś?f\j]J" Rd9US )bVe!y 6hXUv2U [HCkFyaC#?uK/ePs6-{?B*b%gͼ9O5;gNE)0^iv>5Meu0`(V8مP'Dw`.JM Owz}d Ȥħ[===g}Mi{_TY2ɀB/kS\hWC%ϕO"Q6liM5BЋY$ FDʎ^5>p`@/orqL9jn2cb5gsB4J+/^ G538ՎyV fҎJHX4}mD+U<2`WMm:d#WN JԫAJyϿpoOcYַы܋u]K"Sw?y&74x4x )LjLf[TY2 hvhx/p/"wܢ^9/"eTO1~~3ʐhrqkC%Pt&ISU7bZ CMIbO=S@g1dIh~(܎9|"ËS` ~.G|H@^1I|ݿSM xNX և2)E ͥq&}5W,>nMSl~[ VF*ԭKhP8{[)\t!C_p˶kWAn_ZiQ/flkqݢk3 X@&'Kդ4$/=<9 _.3iL(T #}x4%]+Ϗ HӶHkl14GME-I45m$ H/]|&s*bJbN !~!P@rd5҂{An_IH22G7RϑMўO) wl[Ap$?p|W ET"  `*0iX}/<_RT·,h|%d}]^8 }SÚ8 lD~PL";r ֗'L#ЊDJܛ} ԄNJ.gÈR^kObalU;~j>4 u~Lx9gB''UvECgGk[Q8jPԥ!iЍKy'r4K_)cYF6@WqA4KNfG|BUښ[|PT|~- #"Qܫ1=% j>Z K&ґl6gNWAsbs=sѾ773dД!`eSEH;Wր-~ O1L GC,NBxaZt|9SdEE*;0a -I{ =RIxri}AGxD^<3o leB,CM⓺Xל@#v?ʦqDZ"y+ga{)tfRy݆;3 qoݢ Z#7^܆h7P1t_٤ŰDnj'6NL xI 媣C9@+H/ZjM36&Hsv`MorO!RdS4,(pk2Wu F >=o &yHQ޳fj=To/̠'JN$\9 2yZu|b{ !^8s7A  wsnrtw lKi =[! xցAs` rvC ·dIϢ'9W2I3d hXz̺Rp]Y޺Zv _C@Y:e)[CZcC9mah4k~>SxX܏o?]G x}'A/8iH(R3i~n,/"v)%0*hC4&x;Y|?~Eb㊱fvm(AW1ؐ,]Y}.Eua.xVބp\2.X\b.zMUCk݀ c|*?%t̀;k8MZjLC^a8 Wt 4DI|fmr\.maRvlL1)Ej$gK2+~_-Ðw:62JX b":iKrϩ8!*a%9`efջg5W$agKqtd`.V#g}_ lW{9&a_30Q8򛸫!KL2;תԀ$ֶMBҎQ*~?4Ì~z&&mDa]'ľ m6,>} ^Pm~.8wbrUc`fJŀ-m 8SE:5~Xr+ n)CZN3_lR J=1 <ɴoW *<ݰh+Rsm "Ȃ40p~ao⏮'' (/}=L`7XO'1tX4sVjĎ^;Nw[(E8]z2vB#|^luv_J|o(bLl/@9V}LV"NC=FZ7$/uımϩ+yp{,ʔE b)>|؅T/}[>bT107b4hl^R?{rleOtDc%#$K @S*^:չl…@Jѹ51FpۑDŽ`# ڍS*"D5QkPzI,KxK]Ot`ɳPV#l#1qa Fa7Bno pӫ]`sNYnIv Q2x|{n|:>~ Id ݙ{7+S'ʹ}AZ)et.sGP*d2ϥPEo ,=jۯv%Td#tCM"O )KnrPVvׄE.S40[_-쑇j!CZj ,]ZKT_}P/#΀u4p6RCNE&0"褛~D={ih)EF0?V m"ʒ5C(~!d aiy%R[H <{[P/%߇]ڌ$tg-?Z$\@pMJ̄TrTEJFUMoUز֦瓬C1K ]=ޤ٬p%ׇ..R tLZZj6o=;(*EL 0*8H8Qf\m1? ~N\pÞJ:2PQ'͈?"AT_{Uw0DLN1(.YC-LaỳvfE[ قU^ᣥ41Ƚ_uA&|`P{uֺP_spMҹ&~Ǵ蝌;=V)ƢYGփϐJ_ްTa(VQ!+9 ' aTʥP[P:t@chCAGi/g_W/ QiOjx^ Ťɫnǵp"jLXKDIǴrýw]n>2_)41Xm;m)+ٞ\_if<%O쉈+\&;x6^6hÿ+ 1 Tt8?_1FXJ?u=%^,kZB%& !8ZSSf`bm kowٝHU<W}[CKo>h-xoCzŁ"ی"U~F\`n*dAtSՔ ;sH@5G1`hMc##I%TsTdib|:_)c8LvMvX&SO:aٲ+թ .\kfɌ~?bx- &ܬ6Q?aGm뻂!%#p0$$fڤ* @=frcl<_0oL7b\ |K4-0zڬI/Lɽ6.MKړ$Wu<؜)%NtWOEȎ\M .mO;C>@UDcv_N k<M;gB (>hѬYAu_2(aU +]KY'c3'8_`ˎ|H8-*WlTo(FSx_0z(A"-YS~P}m/ٯaxi(,ݵhԹդ2t8Aټ6WXD39iH$/#afXyۊ%q[`!2Vw,R虻{5>: }R׷\&Ff9W.ubhuz:ِ ?ґ!FuޕA\I^ .ydixG6eFHqX p.fb!M7BnLi[޵.rMHa/ SLa2=sP^[65շk ^rէہ<|w/A!"Z V}u%+kfbJn;YCzȱc>u W9zaMEGXZp'D T1IQr7~)Ё0-U2ADŻg_ڧMUS=Jd$mt5^>gY2hd;:}c#s@D֏o>!F -!C}#;N.PpW)c =(<%p`}W[*L#qr o6՝54O*o#kȔm-f[XM˶}+i2W <7 nr\//JxMHΘ "IpiHl֧Hq1q7 F5V2l6h 3fo&G6Ε^ UN= \ Tk[='eBH0|VWK*Kou[dt(//*$v ^֓ӋcpO߁XQ fS5E]@0I65Bq&6(+!19ΛFԶACÈs1$8ހw#X&Cam3_>' I%ʕLcYxH>B󨄄{ӿǾاZg:B 1ה`~;~n*U(ml2**-ʘ%A1:ʚv&"jQ#OE`<"_R/G4(USՉgB."h [k=piG Kj ogZ4)u˧Ej'$u+T(?U|Vg u%TL\O+p*}5CΧz(k%[ 0b@z/Bw &fzҼ.x`$B5[cUkCtr2~> JM;CXZڮtN*(̩|# Ye rԜ5@ S6j}R(ՈS8~4Z jeU36dxjj$WNP6I3EƳY] cM1v tQ̵p} .o)ȅ3yDĿp("-r͢t)ZűD|M!jU ۛ) kJn|ڄ.ׂAڵ9։C߻Ψ2Η|=$9a[|e,2DmcXw;p=N;ViQŚSO@WQue%6Zmk0τp7'jyڧw _ y"jrȱ^cGY]U"14ֆpY1]J|z'l e4crnh',`>^%hzq (gո|klin4l. a*^)ǬB6 ൏`%8%_s:%__ޑ6=yɒDgvmzdXو0W{KrcPɌ+ !3^k昢9#aA- DRJQzl32m8Jtgs[hbjK ^¥WpәaҡL#%h2@bvLL <82c:U8X2qi@Oi"/1qO ߷|Ԣ^&)r!@.TCTMS,ɬcnf\JNЗL) 3Š|_%4pdGp|or ]SHT?BĜ,ZɊ&wl@u}y7|'-5[z+ܴ_a79_U, )=.pDWE'/ـ١]'B `{7Tg šNM:~gaq.7q{y^ ydb Qi]C;G@0(vT)/U$b? ,lf ИKI21k\KХ%s lMjJ' i[zUݟxSynZ0( sN ]-uB: P>Z.6}աE Xn(3HJ)OR,˷ Zyk> \ [uxf7jfvA#k ;ɅzrNZzk" ɏޓ"ˆxwÓB͖i SYt̏וc(]5IaZ-_S!#rQMu۲ eIc$rKڛrIhΏP ɹF-R{E:o3ۑVSW0fbmj;dm7P]4$^,%3X_q!3 L~z@jG{*?N _x !l0t5Xd^e{GrCAr:[UW^21Ka x|babX K:j!H;/bk5m6U%PQ-^yw0TKyrŲ?b̑0΢۸!HN(b,ͮo|j@!3ʌcRb6cP_U; Z( K|nJGe8a^y!w$j7/$Yd,!CXc7mX:]Ŷݰ^+v npY')炂f ѾMO~)J/^F~Ɂ[Zڷ]e+cM:1pY{Ox{">c%e ÷pc;T8p@g:)e4fEu@aI75RAҕޑo} MX|11f0%mo&B.^9!jˈAЇ GezJK!˒ !e&)KRl{-B. )U~B.R E: NNGF3+]>NL쏹Jb@#V dHKцzSUd92R*O%|1o@mU rGȯ=0f &- VIӐ8qڽ=`nsՅ=|n%g'<5}u|0U}RD>[}4%y6 'L]sbYBhrБx776͆Y+&܄LMo0 A,DW3}; &z>206%l5.pK׽cGTEA0- "wh`LٖKy~vn,3 [k<s*nfK вtbVlqaYs28VaHU3It?gzGC+Dgt@-jeQ \GsʸɒPf6L PGbj6?ƷVMVYbWT sHrb5HA#՜[.sz3VR5|45nX_;F bޟHnYqq-V!a˒\̿rɴTZ-og;W -p8kQD*0]kʬE_)B]u; ܧΧ,x'H)@8Yx})PtA3pzބ/\S]Ɋ@^:؀pA &GYCrX`7WxXOuIkgMVNjˈƖ)8/#D3p_A.^` QA_f|bixr=F`L0jǛcZ}*&,W a= C#KiRc@?蕣fRAY+a47jX%3FThooM-ɪ&3A {¡(-:59lVoMz8p ]n ңCx7yk=Auֹ1P|Ѧco$ 2JL#[7t^S髬a02y y妆p{+?YWdQa:FI_D l4EtÿG$Ȟ=%>5)?mh1"sŗ9'Z).@'.ўf ]gQUG1[ Uoo@qa-Sݿ@Va]_9qg-f{44-H|DGLxӾQڐ~ϰ&c;.M)ĪV4iԑZ_htСTF l{lzU,k8awTϺ(mR:kE_ԙ^nJSeNeiemB( f)|-Ż*\&u52 1tJ'cFe]Q*!}WRR9IJVATȼ>92J2z͋?Q~be hS]ק%D\|Z jrc-D1Tؼ?Bʪɀbr5aE^Mc{ r  H%z,,<%k@~* yE*7X3 .#o.@蕖'#cwж /DE^CV8vNЫ6B1"Fܢ@ia}mh @#nb޵G?mxn)ȂZkP};!1N4iLN |y6B^]]Iy!>L"#b1&(/^/9lq#l{5GY&t.=1%2ySNJ%~&'_Wc3"͉V`ۜ}:F{6i}[F NM :Cf SU7ˀBr* ۵re|E7#v G0ne =J!*7(G3Jj<6kd= K#:[Nᅋƶrl՝6K~~!䖾(TFSoA~͸V頺jRM,n=#iyxx`<ޭ 8F*" J+ GƎy RI>ݟle:DvFUW{HsJ2Ŀ~y ?K09"l+2iovS>r`. 鍽RaptcJmF*FR>$g OVУzinC;Aس^ Zu#&EJ""Dzi`b#)DQ"ፊ;W/F5bo\u*S)#IQ$0L &/f EeWoC*5dJ|kҊNf"gB#oBޖKsSuRqX3(L ֲł,c 32"-V,13m@SM-s?ɾlv=ASN=$M6@A3%B "U`H@? "X3U6F̀TsE=jirGO\gIXgYxGc;kRzBF}()qɗѓީ}O{C4bPk hFXKW82뽃O?~F $_ZDY7kho^(oAfrE˲̩|V6إ KE9!Mk-X{S ^åj lSYsck$gXi/1-ȾpB= W/YP#2K Feg0 " XCtZ%^_k'ΰMjzxck"mCdmR~ν>'/|QdA`N4/~ /gqś-$; * ҚYQVF5:=gimUvk<+{Hb>eܺ{-*58"x)X?ۓCW27 .(,>a@=]k>fr hM@Epm5Cȃv^02.dn|ab'ƑI|_@1\NӲHmYMLngvύZEiAXA=@@????hiE؃B0}qr7$JO7En盻 '^1+ Q!U>"*xiX m6N1Cu-~[_T;u] 3,6u%bTvԶ~#;;6u5K̃ߕM㦫{ >}|8JOom6xa>oa҆ꄦ-ߚ4lU$x\C woIZ( ~VFQ'@HLUꂔ+`6 ]FP?'XJ[Z+fB|d֥IX{,$#R0/EBDa<'Q+dPI>, iպ;bf4P |Z վt_Lh Z$㯫pZ* L/8?o*+@ajTWh^ x{h! ߍ g;sW\6!طOwݵ. ǜG]JOd6-Q+q;Ag9*ˎ;szN;2COp50s_&G/pJ : 瑦:qDIK&`8`v M`6, kŧm,,Q[be9st1lh/kBxbl[bntl((0r}6>MErMˎ\ԮUG ptVy;]0=G +G%.G:7rVdf|ϲl|,C͖Cj>Ȑ_[ԆGDzmO~熃؋2L&QW y@ouEӔr\{ v ygB3k݀'.TzE9&btMHsJ bG%\ a"څrT h%[QWt$>;y3ޜ.tj?9}PkENwZe +GĦM7ǀF[:mb83lXgeL+;[*@͸ks3i`7`=j>{qQ"#uv"YnZ)ؘ,WB>OM&H\< jc ߉`-x|qr o&ۻtȯEQ6Oz.֨-LZTh@fgԹ ] kh(Eõқ qXRٗ7r6&*8NC5Ւd%.;7|=y} La45䶔)ނ5 wjVLVח\.~bNî qMWTROS6w1*P`r#єS#/GlyDޮ262Τ|͓-%u[C[,NAu3^/ Mj_C}F%C dc] CBgM +PKƥ).jug*ZU0aUXD|eI{*ME!jUd\v/l}JNa!G|!e~]S8D%$QVGOL('=.~AsZ?j)%`_w[r#5GM! ePqB^99hFbN`oZMN}t٪Un& uFbWty@MzE?303"qgJe;~DAdRb@*I Ff@L0̛{u:Bʻvn?;apZz8hIV8{m9D0@ο$ $P UG5GɝE9o]qgS6uPFȬ;Uw-=0P؃QLpKO sC g "k  Єg>xA 2vio|ϨqKE.TQӵZߴHhܳJ7lDc2^&ָlH[ Tb́ >4O")'2RfXfl\r|$]` e=".}xW!«s~#( ]x)cˑ~볓N#;qX<.+өtˎ& 橵>='&OJ/3pY#lFO6(ZvtO3D[aܫBad{OūdbLeJ\&,HۡTi#6".s}.\Gapڤn=Mfj`|ƨ$9n7CR9$br$p>sXO".NWt"¦5jRm>Q%]w(2SL>RQzK-˥PXk(+P)J s R:ᯅTՄChwWYu/jɮsm#S+Rݖo 0PᑾG|lY9f&?y)*2<^tHEq0^th0!Fk9P7eF#8S D2Tqf؊/]KWáe+NX@c跐/DN~fhsIH760mGl @oNX֫ŔunXvU0oc K[z-JC̙lYpvoQ#i$ CoOBV vٲ0 !Nu7GtQ~+LQ@aյGG^GCXA{Mh@; )8\JsP^FT>`345&(^'-Ǒ $r4κB~(kK}чd8`{S^Jt)F);y>/ KЕ E1=n(x WmŞF .$;5#a^!"B1,@`e}|At\7~=b?=FUjA~B!߷?':h bI_7,*dvc_ɨA^&aE6Wv=}~V$8j9L6٬ V]fSPbnVC$>H<4_^D{\eywSĮGzk.l<8Jusm$4BR?u~l?iUNܻxz7]L7VpBVS4Zr6J-N?g~YbR*% %12+{݉>Md}iy2K mƮ-\em:OP_`]}9oeMɫbSKHj4_|(z/@k>5Y?S-|ԯx04.O{= s>3 x:rO’Uw'?#%D}imKV9pZЯIG02Y=C. eK&C;5p'%ٓVC62ՐU[2^UҊGb7b*,K'DPia 7M ְX;N~kt7CIԵH=`*-GZi5a8ն YZ