container-selinux-2:2.95-2.el7_6$>QwPO '>?2?2d$ ( P  &-  8  H  X  x  @  H h     8  l  V ( 8 D9 D:gD>/5@/=B/EG/hH/I/X/Y/Z/[/\0 ]0,^0b1Zd1e1f1l1t2u24v2Tw2lx22Ccontainer-selinux2.952.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.\ɳUx86-02.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&BXZA큤AAA큤A큤\ɳU\\ɳU\ɳU\ɳU\\ɳU\ɳU093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d8403657c1bfd05c74802d944abf9ca889a98fb54cf14ece3f642e932b6bf34cfa31caa7e754201b0e717c78ab200dadc65cc4091dd18f3ca15779a22d5d27a83rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.95-2.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.95-2.el7_62:2.95-2.el7_62:2.95-2.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.95README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.95//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,_|Y]"k%u#qXPNeR@Qn]s;2x/}r#=T"LhV]>$3Rajz 7](ۃW&mG 5q@ ;@Az>ϯ%j_N>U͡Ǚ ~^1L`Q=_p 4S.jZ( u̵ks$Bﷇː3iLe#NkѵcXyxf4 I ϔ5![g7C3B/:m~< ?2) um}'sǫ'H  ozCo WyB^Vh*CaWNl.@Le t*.dC2ƈUH~L2YͳY@ {HA/3m4tTM{yӲI&s8SD}9 nGbiaO>0*{ x<[ȥ,bDumʷ}X?JI9ṝ)n6+ Uq3fWCM8,7'7owc2y8:\Ǖ0 ܙpZbI-Xϥ3tYtpR-';UNq+pERm9thkxsݴY5-جهQSO2( .L7vDMD7Gyh_cծ3yV8)Ū8렙 wB\3?^/.%/)}$s1F)/u48+HaXq *T'^Uh&5%SueGML41j\$&fOŤ0Tj;51G8IZ&G1On<:v-)|MJ_Z *D3F+Ky{`C5*T`ha+>ƺdy:P[J8+ 0E|hl?L?tł/ 'xT}˱q<}"Np~1%&v`\l|Xox+t-,k%]cs tBǑ) '4t MՔnND ||}!p0KKw͚o,%0^}5.2"5"ɑ-9RB|Nk: DNh5vbv`PrD]d9KSlFMEq:'2C P=CaR U'Hȡ#omz^ixoJ42-M|.'07-wy/3 02@U#ۮ\Brl=ՑZngs/G? M,Ne#BNӪY,A`t 5ϣKO}D)z4W8P^=r8zg'f#}|l4J擤WjTjۊ$Fbmbn|O(?h/F7",k]rh8کW*HY,g(4`L:9I)nԱV-)?(NK vFh ΑMlI9f3y^,_o\Ybܝ6!J s =gp!Q= ,5:ْ)'$_ xN[HґceƆY|pkƙHM/9Y&ﯓJq9<"kɴ_7Z<,T:a +Y#1:BsD_qn}.1;@чOTB0=jVU]8UW^?>V8ZoHu0`FXy<~z28O2f,:yٟTɩ$OS{iR?O-{ZIƠ<8$Rǰ8X$sUN(yr&H! JԔeuX}ca> V%΅7M;MmK{'nhp5ꕦx倧+MY ,b{AI+eyEjǩ]aJ06|\PkWS5[k Lϧn IRUhA -COa)jż :$Q0F9tK>ޛC/0A__{ *)0( |ƜWRdd[W&Ը=|TƏږYWuB)HCC\r_OdoV#ԌQ[:G^Qƪ\[YZG{epO Ȏv{ }KH30;/%O&n=ݯO5"BZ/|9׃cQi,5Do,~T2J zrWtt]=)֝3+b8K2Qu."o3@ABrNJ,hn_AN*<}5_v;% L ia3<'Oҋ;[enjjzU=KlFk1ͅO2_s_Ldб8a( aj2GֆyFD6Y_Y=sajny]e#3@.#i1Eaz:i/伮HQiZñÀ4rz;Av. j'5 d3dԉرBlNهf6S\%t׎Q]TX/Q Ԩ&'SBʟ(1b6gx|N|o}xwv379gR)x%+JjhiAr\~̽1yn vkNBB=O#Q?jq =POS~|C(I!b&/#r9~݉X$>L{*26fg@_2·W׃BYD|i1crf(+, .g )V\dHSrѓ5 lv$>@#JsEpbT$&ӝt0Ts=[a=Rb 3=<pG%RIS[KNx_5?W@LR2i͆?-qisklJmӣju= 0oW?uHOu;t<7{uX&bO|3U_[TP3qE3߀`1o)4aE(2 ":[R&e?R)9S/TwB7 O^))YpͽxoRF̫Ek'EW<$-]Rd;h}$ή0 hEY-=_j ! ײʷ~#=.FYq{Ԕ jEFDnƗ'x*cfaFA/šzG7:v"L Rv]=:y`YM:HƏP+!kF{iYL1OX! а*9/ J?Qe C?3b<1.ӌÁ׭&>8+H[c.$K`)_rn6We :<2hBj u+T Lx1O1+DhnsI=5W~+׆q"$KHxRCi|od;^ !OF^W>a F7]^L&!0U)a^i8$=é5נ#ݵ6]Oᐯ0'#67/y_I}>NJiq!^o+PɃxI(&"6CA*ʗP߲ ITI\3Fr/ /gW񫮼J'\+w) j`LK:)¥ܔƈkC\O](FcJGN;7-Z^GxrNG܆F8+N\~EG9n wɎ?GV9;Se C0n }*EE9ݘ-P僌s»_`RRvy%YJeǐOelIU(Vҙ⯲ۦ?WL78WIf `UέbƆ}:£%wU}z߶|ݺˣMmK.8kK`鲸\k\|_f\L_!cn ;D܁!+bR+ ˀ *zE6| 61m Z~aE)Ba}&L B_ď4""뵡,}mĵB59Ht&J_\EOF5NBqj7~_B?ƐAj\UH'pzTVA]xͭ%T|]GXat;u3y52ze}bFfh9UCޡQ_96}`dx8ZǢoj޺{BFo#7X peg C@7V\׊gQQڡxe@֡_.`_T+5}Bqa/SX}cME3_NbfO_TDzRL~;[#k+7I WAƪz W#is0 O߆1w}v3O8xU'ڼrI }Y_(Da~f6LKDf^O&8Dt6Y%;K VߥHʻ~V8',T$D0L$d>DGsP]Sehd f\1J$A))Hh]Sz"/Go /s$ny·Ь>f\EF#EmBP6SKeKy|O9O^ ?'[!a]&wȆx gq͚ WL"9b_:>.%URjT-z6".7"'}D%#dҥx{2j phaީbh K2(W>YhsN @h-<%cNC&jb'^G ںAk97F *r-^ EL#J cգLSp AdJ9c!φ5@5ujhzd(A#˜:r*hUIN)yV (lܺٗ*it4MpfbOhQeL1%ڇkߌmeKX9w^Y)ARu89%9iUH^F0~C1T.:X9/]1Գ`42{En~Fk ن .] .ykŋQcH$^05|=LSEօ - L$=ns }>Z ÜwETQ9+/1-߅ ~yfN΋:OX?|fIr!1-f7Ӟ1@+^5]) =IFI|>>_烃&2xm4/v3># e/[Bb#yI٫* xZVح>'^B B>HE|9x>w/o,u,T==?̕n[G 68ZMz'&6ch ?;BD1 ~"]t]bږ5UYS+8{HRz&(f@(86AɕōL=ۻQmBLd+&gX@-#h- & |eA>Of3]kģ%qghPwr[7{ ҏ gYws7ۢٙf1<`9QFI?OGJD07lx&[ ΅U:9H jI>aev$k]/ eotve ༳(!~xtЗϓ2(,6bӲ%cpBap #]? p>2"^bTuὫ]D_Tn3|,^eq鹀IX7*'NG٘=fT㢥͑??7^ p! hޠz 83CSo-bB6{/jBxm'DzfC5c |zwM,'rlN[G8nC-^>+Sɤ_ozT_.<5 Ϗ<3X暹:YmAo i! Vt No.DM3=Mp +V**^鰾džfC㓛YA_-z|h_d M4m|ӒL˴'a@ w>rcF{Q~\<9q|soX;]%' bD}L=T4G A "t]Mfe.C66)牋o&N U3hZ^x:bXO8X:I`ZwJ#90;5WhA{Hg3  .F!ղ[rsxaqzL݋W*zƤz񓰮a2Du P[X|73m_gd tnAU ]o(JI dMy$ש* "[b1C kS17ZU)Vx$_UN\iJiZ#s!ϖ6AfiScDOv`_~Z*.88^ sVzHӄ'MvU~}TýqSsy4WÞgG^, TƟ uizb'-=_q2Yэ"/74ZGBs'탻mԺg@ъ}p|X(cԐ; ,H:ugfsu #O@.N\@_ur-:JxGib @,ӒCb|GΝ ҶKR3 @9@]g6u{>tҿ kַ۪RNd]u2Ĝ.0ޔU~tMZkW m;FCCϘEOvX"%'[фݑq*"c7_t(b D۸28,%OSA~G=P#"wJ"LK[$zFI8z 2a,^Z4'邏aq|TfEeф j׃ v>)q  Bn MRfmdek-SY P:/~tYN] 1Or)c/#qF۳=qpK+Zomy}3\]#QwnHฃZ>mWcDB$Io*ySɍ 8W-HRǒv6gCM8![^1k`iԝD܌oEGx k2#FF(2x40 C lr\ Z.|{_ҍpG;nJ~К cL F1*]RY5s 2k}WTط |W߲+g4sՔUwj Mt9lU"hp+'/j檷ɲms*(&"=C<p -Z°ؐ\ZO /1, f l7"DFO[6:)`јHjtU@:Wj~*|nE C,*۷g촛MI)QF'hX8".qk]9(I@TJ6=l'GrPEʘk[Y;v +P!2}ٗG P|ϕFc!E_,AV#]{?\?@/A*9AΉ&b@HaG @Ў%xn&N y.do8Ci:f#)ԕ, CT &A šU;k괓e<yOd' $ /cuD͞Js?:"RPp +?O9ʴf~ /2=lŗxRoyc%4TԡlN H^x@o,Z/A,BEe>UjK*S]L4y5ofː1wfq\a2ؑ"z`\ap1׀ÜlB#=q05 E2w]_I%w#"&2xLGUJ"³cC0fg1L<.q+͉AY?H^ 7H~[̌MGԦLI;򛡹ȢH؊`O)E?o;J"ULzgt3J+8Z&Aμ~EK-\em.‘>NAn\mr}FTy`\{hF t Sf+ t[P|&҉.,{ 3ZApv^)!IJ*|nO 8ucHo}x4Q ^mۢ%D] md_ĕ[F>~8pM _Ő85GY!W,H+)9@SIe$N @\enP(eog$ÞXu2jW&z%#ȑ`~IM&ٗ.,hq%agndҟS3pPz12tt37_z-Yն#PEffMsM&;5mRFd lHPڋt, B0$ n8J%N]ns䶕:>J;8K8~iL/O]?_J2W KK&EO +ӓO"ïNwQl0FA]Ѫ޵A,jCދ\>G w3>L6ydV>pK)]t@Yy5*SAQbﶇaB~ uƼbFW2QV 6ou(И^Ɖ6U,釞G O`Sû;~W92 %70fZvT<|V$E(6d{d%mF5c%f]J6AG]wTۑt2PLR6UƼ89K608֊ owꎲSeŚRR2Ěa  $F R"eHTފ` ,S͓v9ԌRb!+y~? GqA| D||45Mh|V vRB-Sdg>!@\0Xp=* H^餏 3*"D>҇%)6g0a?ą1Ϧ+Ko_/Zʠ!9|yE[Lir#-`H[,NtV"Pύ*ygWF\|_Av㗰hS7d~y<+dEr v]<~~{)3<WT#a͵3zKĹ@7}5<(Q2A,]4(N#XAv;⍌ \:G~b]"i¡F}Ԩ\xlD(C}p'[;K`WU'k)07{-_ep: J;;Tn,/ 0~r&Ϙ= :T .Qrs%)cͅ|Aң\?Żv&a-DfTUuFة1$l|yzSO0>k5A ~%/ףQ4 )AVP$s&h$ ǣb w ٶ ny6zAt< H@BP9'<F ;D>$'bTl*g%EjyID5V0~u΃;dž`{YKUcRPjZ^YţWNЬL:z{u0#~[54ԻT*L%=:X\i5a ;$""C2o{gmv{;ߑsHED;Ec:8~PTO e1oF͞}aKYűgmLL޽?S l \ǺkPh;m9mVU3C9zg Ymc-Yy<+"Gyl?-*nkML,`]~1 9A"8,$9To`w[%5 $%yZQ2NO?Ɠ'lVY#ix|@&Ɉ5K>D|1b9[®_{uԒK|;7L2L,zzS`@T5tm#NӎeM`ZF>f ]rm_ё+OO^#Sr"cxh-e D - gy0FѓA%KZ0G2eDe B„;1rwyI݌j(?XSy%r*eO-$(W>x:+60ߙ몢pB3M8 Z n^e*Đ_iݐjFZ.%.t/f,C$9ST4'o`cؿB.=6iS+KXf.!m|@( +s5,fs'UJ:V]PP~MDw&#Dhw\s‹*,|[YQf$KosuLAq,v ڣ|Zy=ocyIQT>wL3&K/.v&xa0[X'fKWZ hnOnjp;Ҩ[dE{ӠxZ̅r%ѓt} nAiIO0ض2oӻ&㉔p zr ̣{]H/!G>ԃ|[F퐴j~}W)E>o}ˤ_D(Z҅RN ̰ʳԄEtY^-^+ݥY> ,EJ*V<*Q[yԭ$Vr:+nzi+du<HԳ:&\_7\iM̯x m#ހ =[\(t.2|N'ECvڢ=~BKy3]BZy2Rdh-V c8S%Twt֕:P+ƩHu `4I(d, )F3/9UbJ:@]"ᮙ麖|:*O:g6$¸P.`8zȸ9ie,V-_ ۵&6=Ea/jRA8+6m[#1GHS:GYԏwa]W2I6**N(nov@'ET r&MH"I 8 f8sNR&5&Ilr$1n`-=e4!ۀ7_6'Uw/m+!Gv7Xw\MUJךP3ՅCesǭ}I:@ࠒ'+at/sѺY5] ;ԾRr1`h1's4Ō}„vDT=fw?s@l [J^{)B.lzdd3 .Uҙ!Go5>e}rӴLi_p\By\9j}ڻa`LkN>YM1at6O`I]]e&'Y Es"\3dCF{@h!48 OR՟=O D$ $;auZ[*ڿM5g)x*9x6;,`uALTbiL)"=AF8Lk SR. ѩIyH@u菩 _2~ώFE"~[<1cf@o1@A^AaIؒ{Zt%tژcvv GeԘEouwLޙvoD_/@EPo>y<5PT:IU}cd;V 2N"4SZ12[X&&ދz/![XrtȃߘK\q8Ԁ-R`/58 d.@pRxv~DLQ)_UHgKoBfP~*nNCAŧ9n63?{ Iia[Q񠩩 Fa$_t-neȇc&j='ǒUk2Y|F04;h]T=d#O0NL tvH{"=Hiȓ|L!$CޢC,-#^3;1WDEgPY!:zQ]8dA(d0,#u%fxr {k\t`.h5 =PY> \)^Gb?_.$bdnaW924эϲJHo7>T8L9\2Uf$Cfj{V?;iz}#]! WRDˉ/z| A%)\e,YV {H/ńW$6?]|[?QݚbH0VF<,hF:e^3Gus2d?JQ`61&Qy@&TӈE=RVU 639Hc:zshK^zҹ.d>f]ՠlp;P~k pH+:491z .P! ˞VRu0Nx}")/q@Ȳ(7o)İ h XOJq~).,ṕXJIF=n0 \i$a.}*rUZҖR/:14)]}CZP &r cKJB}[FjQg%h.8s#E4KC5tTI#/F;,ڵB:4)UQAѬz(nYsql[Mڈp";a8˨YS>_H`:YFl:bRw]ixш "}:>jXȪBXt_9Tz[GhͻӚА=[CZzVMFgՃ+9[ Ω_I;b+8P_e~X }7~AhsqHrZ3bxpl1[ҩi1UC nTkgs>޲c+{ o֜SY7Xz bwr9q*}ƛp cA$(]l9~QFCb=GZqnVG$nzQ X/SD#UM _SzzK` #tADj44(.ID t.G&,6uj=pEq"Q~ôy׍5 "ߌEmyBaG'O9϶ضCԄf? u7P=X#(*НB՘Rl|pL;-!*$lJZ+/a+Y9APiuRgNZVX/E3gD+7 ~R*ӣT6>Β'X!ѐ7_@<'mF61JH>HP'" kf}E |"y(}.FnaOn8ҫ YZ