container-selinux-2:2.68-1.el7$>12&ͷ>?-?-xd  $ L ")+          0 X     ( ?8 H;9 4;:;>*@* B*G*8H*XI*xX*Y*Z*[*\*]*^+Sb,"d,e,f,l,t,u,v-w-4x-T-tCcontainer-selinux2.681.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[|#x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_typesif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?R|A큤AAA큤A큤[|#[L[|#[|#[|#[L[|#[|#093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d37e0c13396ddc379999bf51551c20564f0e280300a625f2a691ef2e11a37595ef82d3ea6281deddef1cf257723cd963de762d45831f34a25e2c20c46e41b9f8arootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.68-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.68-1.el72:2.68-1.el72:2.68-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.68README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.68//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,XT/]"k%u#qXPNeR@Qn]s;2x/}r#=T"Lh"鱂T>-l t6Z{o9^aV'n\UֺCZsjpe~y~QA\Za:cTL ҍ߈J9`rUb}0D% ʊo$F*<TvvQi-o>% 6a\Js0!`STH&:bʝL=@,YែPY2+Yp;Ԇ1Ke,)?bO@U~2_z! Yos<[&IR<[Xrsq @N2Y53)sS [l} ?VxWxEAo 4maKA) 晴Ax̩5/RyhD~2OFh4bZ)@OzuMXh9XUj'2X"I!3a 0͏#wpg^v/pjFwQà^R }iF oq0B0j0X&T5䄘|fUv&nBOH%&6ZIp a+Λ IP_^:T糒oB33QewV\a@LDp?Q;&is} W 27>LȲj,}WpF$N<8odړg?L>Nb"ERS“|.~-|4&[8)xVLa\gMjXSŃ1Ma$kz=IOp`B߄58B)&Vu ;FWd}ʢ5ˉCvQdH? Zh)ۃhz&KEavx=h !:8T7q;s0ۂWK@%A9 0f39y`?XۘUK[OVhg y՚Y}oQjA{c< =;eڭqIŷo+PH-_N>UjD?%׈Z1A_,\B}v/!4vCh0ꓦ|}gs{kP3Zsz;MU2ObĞ[dfמ=?@ߧyzLSՀ?ЊQ7hxө_8*qYoEg*E$좭M‰`mӲlHYxItb#rK =uɰZCjB`)Vфq|:i%p^4 K $HU> t@?J|?+x`gޗf L꣬ S@<Oc-zMٖOeѵAcTKDPQ̇@;d+FOAB\?n #ϱh C\깲r|gD*nYd6Ú_YXng4n8VϫZ BŮ_ԦY7ʡ[H6qAC=YiЬcj\ZKf2K6)GKH JNdUaxoj7jq73r-^UԈp͌@ stC^[,#pf6c#mP-@v>_ 'W_eܔ={L626 8Ep Pz;||/A2r_L`?W][ܼXgۄ= UH黋ՐԆ!܄;v/2Nv)KB\g=?^Lw蕩y-g%rK6@zXbЇ>˸ [HZ̷XV~. e&_gy =Oczv.fq;Jy ]Q}#KǏ^V,v'Y#ZQ'-I԰!6Ecydݕ|4ٯnpG`}Z|eBbzRhw] hļnaz7(Z%8ңCK" >j վ4kqKG`C'(6)EFíK6 #g3{n#:Z[{kFn<;x:$HNUw6E7Gy0aymi7|:a媼ݢhp0}nH.' Q)!\A//N S)uE&rB<,mژ0+p){Jq2n5xXko*m#rX9( 7co֊/^W)"oQ63RH8ܤ ®y8UtE7hQ9SK! E4z2aWx/o/Ua\w-Qa8X)}"Gߣ̞$K3Ƒ J};RV]k0QhXixڶ 3p [#dԡ$4C[R$r hBR1D#޺S6eL#s%Av"˥O2[s(>[}4A@W&- #K2?(?󔫦eAѭAůͦ"Oo]@|R8Y);uA$ `#.UPM3=lyxin|LoSHt&߯[13|?.W^+h[f !&ɘCY&e=0D5l@'붘 eZJ:`ssH)5݀@4"l33q[_^/A䳳SA lvyR `CQT[ p,UiLuk>=- ݡ`^^VZb NQGשιvۧ2ͱŰCI=%":֝'՗kx * .80Wb us#O% jDyH7- t8w=/+x87ZWtTGcmいLjXvX4 ^Cf]pHS = [7ɉItKpkױ.&r2ҹ[#@B4d;BB[ uFX6'5<|t()+ȴ 9%S|%[8yV0n E-Juq{]yןAHePQu[w0ݐ- ,],iǁauC4Za?Ty naEn&':ܠ@5zg]+UeZ/eK!C˵Yld3t4EsaZ&cbV B g3ad5]F%4m(dul{E8egvt!%IUX}gV%Sl8eT/IIb*/}G\&4ޫ$Hq88 `ܒ0J=ڹRܝ$d!z R3_ƫpsO#6$ffN L3hM# ?bN%vbީM,$o<<#^{lDdhˀf_h =m8F&lwqA Fd!>tE&m}FgSQp*=:zX+N t8!MА] MZTq± ¸^079榹ɒxI -վOYKTUj H0V|,d mT']j[7T]xy=\UlEr+]e_jF-O[}y iu] FM @`i!rv  B=Bl@̷ҐϦL{3 [?FF -/^B(9]0M[ ;W),l;yXi& ͽ$z߷I֊Οa_mZwНK #b)_b^yΕ NP{gC{Av6 ZzYC6cfVzzܡ`?~>(-B.ydkĦ7ne{|!O\طzLw8T"u#Co*ɛȞ,bgƫ ;ۻK ?Vظڤ70&U(!o.cX+|됱: z ˂'@m݉,+GS/>;6%@*:UqՇ i#f.WÍ, 3,CīVOy #gxR/Ul -?v9ұBL=y,؛X]/gt8o&k Xv7L|t5qąT0rY$wa,kڼ̊E2R@e)֓Rj˙*0kGN<*c1 -;Kz{՝ aW J1:K3*q)ۉEo&~/[g#k~n'0bn,f &PBgVބR鲮#k ֩{`l_#XW~_0E ۯ}p&}0I3,LŁy?+Nށ/tmsblS8q'J NJ|װaBIRO|EkEq>J:"S Fglݰ)uq1:-R}(W1un1d^SrDM K8c:0CYn.x]e(lmnVv-ߔ)k  iFKUy,_)!uvI-fWSLEuV>8qt6(bXPrKVmeO(hpu^ 4A`?H/^'7s9ȮPPpjk @<?RmT|5z,@$nhnI'D1!r[ChpS>A,+d9T&t]?(#C,xWnZL5yS`숅vbo PZ}B̭vtG^s?(ݧnupRQq=;|\2Tn~K֙{>LH(E3yk-ʥKyqlRV,CoVo1%lFA,'V1]\jCUWSCCcTQɋ̩셣TM+HT`@C‹[\Xٮcp ~5H'?er$bN(d$~m, >22Y=]:6^ xLuM|r1㱪Wn̈1蔑tg [&Vɼ,(ꜩk4d4@F+0Twh1萌Ȭ'P}50Rv*O)(T_ ]XFl·*ۃ(^ 6hP- f %ߪD[)zO0P>iq=wK*8 ^I8ɷdi=OoIx%$C a. )#ip-s ABK4\(k-ش'l/"vY%Q.q43}>bXLJUO Q@&ˀX9R&9?,X,<+-HߏAX3g<NG壩nt똧 t".Y噈_59ӧѨG?=JМfҎUey-B IV |"քý9fP6 O\P%pWϣ =&$nۏD>͙rd7rfnR+N8Xy6(J/?ul$O܄Ac^ -{`4iF{S~K:^Ii ]F&9Uf52K;{n g5ٟ{k1"v:DMGDbiQ]$RtE(P7S8],Ka_ ᪖!bǗ0o;; s;3zqESmx_řKf|܇c="=ۅYdW[eqq [eldME,.8o=_b8#DD 2>T}gj;rANcJIOo)qR!$K3Zo; S0u7nlM@N001$$&Mt|_qҦ<:2rRJgK :0#۾&)gr)Vn8ub'Jv/{ƒX~Wr;F“ۏh{]+c~ū_"pM\fD 4Y]ΛSboDP3'V4.L`~tIbGFtڂE<|mU;Ibiwk=WX`/`]MV-Ļ۴ou hdw)xGG= Y-њ!5)bPYA[7*@:zߖSG@CS#-)2Rdp<PElm_}./4>0@PەkXh/:TjxccۥRh5LSϽeȡY\4Oqfrx҆e4, nؔ&m~c<Պ Z17t_x|Eajmsd_ xET DwefQ}{@+T6.8W;h~Eֿ]2@pmOM5IJ`dD (ZԺV^fR `IB7$8[/̆Qv F쁛xfNԸb xSo7[Y?v\N:ɑ4PͲ"ex{b^z SP[Zi %~SnÂ0 z씿317kӢ{VߴS0mw}4HL}t?RC pO͏9ًC!U _/s#!-R0pߞ@ll2Rvj4$:*qya:h½|sCɩ"CR(\O_`piN⳯?ih>ͪHcϮvl+L8Tz؎·x˽%^P? YV;g/#/7 /$_U9A_:åj5M9hMd8b]AeDJ3)6{ېNoWdlbP=ʯI\Ĩc^K f\JgYŻ tb4h2^C(n^J2}$IT5iɜH&͒2ŽpksjGp8)8X U9:C?'KsO*L2'ma:ե c1ʎ;S.\|>J۬dɩ`AyC ZWQȮ&nEvk0!/X=v 3+mw[)h=G ȷD6䆓\(an=2Hy'5 Pig QgKc ðRJ<һVKnٌC3lԭތ& Il ) a,1Spulz@uXa8 *'SZْ]厕oũ1p ӞǼ &xIdŀa}e~ZCgs*IAxa pC*ID_Bر0Y=*Yd Զ) NFS Ye7<+h '3˧'ld8:7 z\bs6d S08 y(ꨟ%Fo]U1N*gp$l Je25c}uDsnaޡA8b1"Kc鸟yubҢ"t.Ue[-zfUh+':MJNO;0 q^b$)Z@;ùjv)(Ef7 ?obE QxHz|D` r-it5e/8M({Z@_ 0xҤR+`MR뀝.0ēGjIB?>mgʫO9!!:1nuԿm߮H>/kGִBX,ީ zg--lL^p(5ؾV4 [h.rGn@XH,zL. 'Kn컾i¶uE"oG&%CnWt6/IQz^ 0wkxݽlT?jU\^,Jh)F[i_lW뿣A/ݘk4syuZ!&Ees l_k٢'CIzЪLOy|&yKa A障6dz?*W3)E9 $qA:pGSZ&1CMpx^dRS_0$D8Qe"0 CfdD;.T?+Y9HS\T}Fv$B3!q6Qka2%ZeW#82!?4b0IQ.i1-/zeIܭ+ؼ]6ٍȺ3k>5_oh$a<Dh:r; O.Is Hkk;cC3o<3{e3[< ۺ˘kn!Z_w$gE=j{aH4J,P57B>kZ&Zhs Dj+j'\ 8÷܌DCB2A0,ݽr_U5xJ8WҤfAuwk+$ZSŬRJ4lumL& 0 W |B|&U/+4R"(!R뛰V!o$UY43Yxb71:13|.Yuc@,;(srG!?^ l'8y#&#(B#zX!%?:jōB %yPum*&̏G|m-LtFK{}9;fq.[hHoKߞ­@9ϙ²*8`$e:Y [*Ɠ%"nlW@m6!eq>`$Եpdc-޸+\DםrۑgySuOk=gLw~U/ݤs>I a$e11=x4Rh+9KGRƺ>8|sՀy(EW6zO[ xEL}>NU!f6T!]Q{9b٥VZBv%*Y=nHX~1h+_cy*;*N1уTr༰~8o jyc.GƸj)ɝ;eýLՈQgz5#fXN :7ㆹڞ9'~*P|ylFӚx M:c"0c Mc$MEߒBA;gcmH+!nZ%,=Ź`6>=1|A򺒶xwMzPdv4[ڕ l`}|V1YM zqLsNPҒ5bIgu\nh8BH>n89`XwYIY^li dG|\! G)¢%;-i7SA[V)ȔS1#=>I*x R"%$,"u3w)V`-h*Eȴo5JPNsbc+7&gG0͠ n%TƯQ%?Ð64jBvA@GP ߐ|iq! 0Uҷd*̶XoF2f.`~'@:vG5ۦ%9¦jpuaL[Ӆ,Abí +_C1dK撽d~.[+7{;V&/3ifHqra)u_4C|])o_lfH %،OȻ6[WB&|\dO1Y^z*jy{wi( AB\sՄZĕPI&o:{̽ZR"|}9U$װ=)oW0:"Y8flVv.z8"Mx S=SΓI!8^+64wiASX!hPUwcYZʣN,mm? __ޢl؎7Б{tpQ E#vakuuB# GfLU['`!_ALōr1',}+T>\` ;#eM$M[-׳%鴆Ctd$NyxiCeWtfur<]dkLVœrɞ(\%/gmw^A"iѭL2㝳?OF ܈ $muF+t.1J,1ٚ#BS8/(MslL ZyX T?Sqrb& = !@Rؐ&$7Zv5AhzU]mӟW]]m@˵ܮ\q[^QnԂq# 6Ŋ'"lD8qD"$A! 5"/C p"'fs^[gh9L WS9s2aY$AY\,Q &>ujMP=2E^]-IؿB>Jt:%G˻;jx`!Ưؐ9>தc~7- '$W\-ONJ8!6NT#G]B'4dGh". ZSKU u"y¥YCaJɤiPذ)cpk Cx@&ڜFe'rAᕎa1}e=ի%~%W8~aB2kЈDӖL{k@LM@yR7k5B)`<1y|w9%6"TPLͩsR7R÷$o{M'dQ$[Ms!~nקEqawX<Ï>a⨬y0LK5[Rd;фI0>]T2O؄zČiÛsHi5m& C1%,!ȓ}ʽ_)r$/\*U=bh sccP ٪V:go.xz<BM5 (mB!R)0 mBju՝.85LU\6ciQSm rȃ>E:1<)>S,$Ѡ8& ߱E >8 ^^ Eʼn jHa0ǵ$ю+{>eg:B} ;~G>K`8|Lܢ,PM{+ư5$ B@[MіB~(lKP,yXMk5.Ķ$pC3~&0Ys/ۓ9߶* V~zg;5i^ڙk6÷y#]Hջb3I\M ]Vy_H7{IS h#D)j< U,<"Ac-/7 r.,d-rK)юZ=5j<=U@"T4INv%bgF9\3޳†tYr,8~8_sSTLQmWmH4c#\c\90.ڞ"mSu@qoq[+C[4doлTŠu_u+/%+͇~-*q6Qu)lQIgOa^z…~>yKڰǢw*<2ϯ3Zza.G5 'YƜNdi bx|>wkR*JPMwu:Ga B9-OAz̓h r Ejw*n<K}tP.FZK`rjp.^7ni1oUaU^ jiuݏ10(c ov>ދO j0;]Ϫ,0֓cs v8% "Urocg^yhAe !Fk6*P@(voMKȄ[f x )`FwfA5Ziz-wAǚ/_cl)ʢ'sC&Dk.Y3[OG#@DSf ,f#ރ:>)m&}1e"B]7>]x/d*k\_(32~rRLǝ_ MҟH#HU^PO!n M:?22cI9mN=i5'3GQ@ܾ۬~-3bT[V FYWkwˌ&xV4\=Y(6,RhGn bQ?t 2جk#+`X!EduK2A\l4ѕ ODzcK_:QD81jy  G`xwZeHCp` HB2RB`hJT{`HI|ד1lk+xR|Y=&q6)Z#!@s1cnD\M˻KZM>n!vԩϣ5); w9(BYeTO5t{ܴw4RT=ܾkj$1 @2km7*5(?%ŹߗKv^ NQqQP'NdxegW+GgߨË)Һ^Xo>^pI:zIm `˦Xq3JE( (P^~̬2Twu[i)it0l41 6,ܟm.hMBBZ<[G>H;MST*>Yx5򞜊FE*륱dXicc"kw$SA7`\2M{3קeįĞ=:%6'$<#ao_k?i 4ܶfA]Ruգ| 2lȩt踢LB2gJL,_ _V]9Vc> Q l^P?1ǵsWGͷsFe{a"jYqHrojZwuNVjc8AJj5\2AUI/indeDv6*}tx;zY$&Z !1@1Rlp.KH, e9`l7+@*ۧݩg~ BGÈps[XnJJ\6>3tSN? MFBH7Ľfva <?NA`a[M"9j98C ϜqHQ܎gnfX0p1H0wV1Wzҽ #2kг;4,v!Znl| O7^E?݉PwZ%S*b(vv]h<+ё5-6J*Nj>wT/ŷ9nu߸hw12.!Nbxc:&-|tɊlºXܶgq ' rϜ7nVbvmjBʮ+bu6]*VQ`# zhn76i 0WL ,/orpt΢Eg׹&FwjfLwڲ)k 0$籖|>`4Rtsݱ3ϤȠ'񹷐PԳQ]+c=L(fΛ7~PT8qLu%|xo x/b@8 є-ᐝ@hPXpl09PS c_QyG̯UL5/YOZ`ASD"w8Y&F8 rBT_\"1?H򓶽u#U^ӞROk-G9I rRtFNOm>SwP_FSc m9¶Q410Evb>qS'GV|wL/Xd0YKϱ:$!"yD'Cm9,:!vnyDXa|NXz-$Dem#  rRK'#)=&8$Ci6ȼ#] F 6G [w}~'.t!Hs MSh`C h1i=(Ydߒ,v+X>.aY27blPU@ٸ H3ms2OC"'fOmt j<ntAf𮴽ӂBEXtA XqE>k!޳ukKW~&1ZC42_SdW_ &T!a 9\c7a82KWP R;`D0:|3CU)n]yQïr]d/GcA+ЅOqU)qv$ ~+ÀCHحޗru9L3RsIH"E$~AxIUs2k?]@ O$0D,QF/ ۉ<р? Y]i` YZ