container-selinux-2:2.107-1.el7_6$>Xv 1J>?3?3xd$ ( P #*  8  H  X  x  @  H h     8  l  V ( 8 F9 F:F>/@/B/G/H0I04X0<Y0HZ0x[0\0]0^1b1d2e2f2l2t2u2v3w34x3T3tCcontainer-selinux2.1071.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.]HFx86-01.bsys.centos.orgqCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&G=YA큤AAA큤A큤]HF]]HF]HF]HF]]HF]HF093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d8491a1d23bc4df52b6735a5d3c52f1148999a8108d02557774495e4cc87beca036f6566a08b292c96be1bd93bf7f15cf714fa799e9570145c2ecf4eaeadef8a1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.107-1.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3]@\@\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.107-1Lokesh Mandvekar - 2:2.99-1Frantisek Kluknavsky - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- bump to v2.107- built commit b13d03b- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.107-1.el7_62:2.107-1.el7_62:2.107-1.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.107README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.107//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,aZ]"k%u#qXPNeR@Qnt;P[be0nH%B``UORѴM(5m_{B6zEKj)!+ {ܻ; q@7ȣ=ʎ~փUV`(uz|`x#!D /1** nAI\2(Y'+#\LJ|VU⡳_5'A-z8b]OQ]nϼ g*&Qzw^xBr3TY%OX&qB. | [[ χp^]qKF yF!#H:-ũ]ֳ\Mط"N'lw[I_#R,u8M];T=~.RUnE(=^H";Mm@C?CI&vИa6m5 2 !4ǜ7m+C U-eJF^׷taLĕKv' |כ+/e)@}RfS놟C=C(qDƙ!]^oi6f.NIԱO%꠭ff.ڍ3p'mhQ<&'HwL}G;UI֝X5qLu$kujVu q(:hX^2$)&}3g![p˿G’Xl|b .:!8P4{;I/)n, J14<{xR^z&?{8YJ*?uLGe*O6Сc!>SB8M UA:^ƏZYfO>3Rsl3 ->|vI4),:{T B2/ :FddlZnx{-ܖ̚;5MlJsOCavLPGwh8OX>ٔV2Vt>)װo"bR dáW Je/a!#aE)⟳zI"avX:XG1Kl-J F^NjR%$"e(BV#V$?UR1CfPrΨ'UoO0&><7n*&å|_5[@5  e4RY.0?ӄ=6>%.8"a SD/Ӏi*|F2 E'mu8='sZpTM l R8|T|Fo&DP<7+DSϫ`?{dmvw*?~[Ѕw@0qPωax `k} #!JB+i@zFx4M*D7M]y"TYE[aS nMմtp8ZՁ+*M$$1L709YZqT{;.k_{cSi<&SEKr'$Ya|w.Z'U~˂;8PMg@iX)Lj}4*aOCNDy`qJ魯X#:~Y$Wg) -V/%dY-&]9\},NǪ,:EPTPB^!;(u+]FT Eqi1CXb!R q;-{jܲu-D~*}^y aaS'18=\Z#Qp`;'[<Ƀ$Bl&M0&=G!ysEW>?dS!V»k*p<%$7t"70,3+Rd †ko;B:zDRW͓8OI1}߰+Sx59Xq2 bw~1'>y7+:͐x2`.P7˜+;J r>[K\lG::5xdͶ2P%8zhd(-즱"4PZF>{*  #Q$-59Qli",XݚOLwIԅ4J L'ӭ[޾pΏCr]dW?kYe#T;f M_&%;Rq]P'A.jry`ar߿/sWx#n[DG8첋ȔVЪV[TˡʉE0rذo65|Wt$u83P~M8dxo{"tMFn`ˆlz 2΀`O7 RS/YuCTV(t`#ᖲᩎc+P%1XI>wOfk\EDYIpR KGvm JE{J4Lrw#!n￶4f.}Қɧ=Knh89Bzp{GDoaPb{EE{~"{sd4F(uA<Պz2Z5Q|;9eS䲶ɓx>Mgfu1o u=Scof L{ã '7Ibo?XNp`ܹnbRqS50Mh?~s[CXuޒ(Q &~kqRG\ fw YA%B/GL(#&gX&sZs-'4 m[7S[.6~4`u~c ?Gd-X. Nq8 r;Ry8kh&B/툤MBPV` >KPG "|&}}F;$yZnb:#_cMI&pEWe^.rxM sK$* 45يٸ%J]GOZjT;/$O;5]p=E%(a D+|6J59bj}ba`0*U6%.Eki'4!8^hl.랞,EL'p?OF 8__]N!AnUean=R]%"&vwR?=[e)K'DYgEwB"!/qӎd[CsW"@ U]4[ nG*p&DNj*+vh*D/O"P&^RGl@8rlRY8ѴN,  8UL"{EIRJH%[6e}atRNq4!(IV>Bю(_V( a8ML}Z^1poK] 8-k1L}14:`Q q'ϳ5Oΰ+5'cyhv{RfoNڪ)I jK5>`-$+Y]cT֩3&KJd^Ģʤh({StD!Q֌N6'\3W t򌒻f^ g>u`?+04,% eϐJA9O[*p򃦛}m*2r%u"t!KN1VBhYYp>88tݙ:xzQ G umQ;kl.8qx3wGnc[f@c*T.|17l z@*]6tpR]7G-_'A4 p/ӃOZnYN>WA=^xۧvʠ^ afm8 2%fcR>hnϪ٘7j.(nۮic]vtˆ8{J\siM~G-aᩩfb̔L\;4<0'FYnCϾ,;L?Lu&{k;;e ,\*;bQ6|" Li\srIN,Ⱦi!.76Զ˫Ys9v7l)V7?Ŷ?J^T"1 p& [*YA{(K5r^[L[,K=Pb24-`g^H`X2pu'$&Tkھ~4bo@/?gܒmXttU N:!7Ě4mMD {ppFǎ?И2 ew\1uRhKJo'uLz%.5`7QSs+ FV,7r3.p-d5o/Ʋ+$4o]W#ϹYFTsa&Uky4X`=n'яxҺ7+d!v [Xw:2t4:E%f1H%Z-ֳMeؙQH}D\D߄3ǐ9@b_6I2Ab JHvo-#̬Lls_6!M ЮM5m3+>YCj&Өt9mka7~0y+S@sklep5)*c,5U>Rmմ;nJQ̮j(y!aAoܟ'z7!#$m0$vٙ;&Nm3;35{k!Q>6tUM]ptP?rQ6m?H ׼nXӾ]v.X@FKTZ2]es['tFs WQ< |^u9#Ą'q]nnY!(Fm^x;SBx fS jT8v#Nbc"L9E\0hoKSƲz.6 Tr_jgK5+"C -| <N !&QηJIAf0D;]Y 6eYV JʲM7P9"} =~o2uw߹Dmڪ^(33p=v/Wo׃X>Md3)yU$+HIT@CΫHBC(gҳǝ{Aa[n7HVkzȻ_hxM;!H_hqt70iCF0`vڈk\x?_֠W=)c4׍( Ճ aHkHJ׷42G8e&9%|[Z![({S]hKRlNFsav;,?:^j5GEbH2M0գe&m%oԭAdOGRb~˽N>|m(c[{X3,Nou:>^!hoȨwuvd#̈́ &fn}v;. F:,Ӹً (~GpCmvSf61E8^a rF}VJQG"VXC.k㟚+#H~o#@ۄ $zVcS!][ ?r2!yOQ$GyDD{!- 9PuVht+&]7;$.I_FaZ/T!yZ/ӃHq{z,'q:\V'DiBV!M[z/qł5d!|#a"ד"ƹ &j7WX ЄM(Pɷ q Hs.>O!>S7ŽnKbN["}5~zNϖcQظ[D֒5M>'tР7:>cg/3nu/jY7]0k_ eWЇ6;ټ3MAt6ASC"L-#|Am 1sS;#RiKܽ 6pfM& Ke 5eTuD*Q/P/|U._Ձ !F`B&/!;4,iqoα&k+~AL..fK.SIO5sX^9%tp_xƔC.3҂tzU;+E>HNJTNYjސROOR4܌'5JqnxSv-bʷOzEO}o$ )~Zuqzv :5*p(wCtpjУP $MKJZ̎H$pa sʷ @)װ#a ;+`⁐7zGǢ菧{4f| K-Hj\]=bz;wymw.oݔ6n<3ٳU-rCNtɅeac=N;;9e{C@1Li<!*#y 7DtG|[:첥ARmd`z 'cAm睏ߎޟc[^qD.zG#%R5}:ï)Fl~V~0-=})=@bs;sI̖QPC[?}槷4W n-,|/F:FfdoSLU+wCol ZKj pS;ժ$fF,GN^;ݮzlbk@rKczzKSb(m) ʬ SA(C¡Y[>'L0c_߫WaۗDGZ,~ulv78WhVOeё =Z iMD?oIdytCQ}l{uZ]dUŃӗ-I:F^-/7_q&>ADnF d}Pt@ rؓhI`LFuP|cbvY?2XV!&sACG/(b*2~z6UBUsrOuY-W+馬|){U|t"5tB!Ee3۪ebY0<Ʀu$RoH_#5Yp[O}f?T}C3bMd~DT {SʻUe%O $CFHîwf Hsøh}awO/E*.PoT4A`B;ل;︞19:T3G|5\G;KE^ĊzqML-#Uxfd(_%xrIָt3d>K' ,?=s\zn"뵐%Cq8qw"}907J ׭HE,0p lboN>z@s 1)<>~a,irhX_MYhvR>GS蝏1-PTlUYz]lߝEjM)hЈ۔_I:q#$n2޴?0:VݍB./(j+GG\0h<8mwZ5b\O}]}2^ՙaIT/2V>|!Tj NfyH:9R,wpUUbQΤfC]㝝QȘu__֡boMsj+s`7 Gd 3V=|`]] ¤M;U %,E ,RĊXib0x,F:v zYcp&bkp3='Ni_pYԍ4ҡc1Spԕ"oV}&x{<qmG8MA^|.ksb1݇왢-cMW*LIIa +jŊ𛪓q\s_ENdykeG`]CR95 VtALA6Fu%˵_ptX5[Q 导E#UP2{F{;XP4F:b!K6Ұc`2ދ%D9d(8NRTY o[TS7S}(ԕN@pYvi{) .;'pE={sf/bEr8L".߈-c,cjVg끡P2.T@t;qɷ#pDZ+; /[> o &# pd|*hDl9ބ\A Z=z*Rrw9y0u:g#xs<ӓ^u{Rnژ ~$$U/Ns>HSp~F^z}M❬xVoѶ>_hB'ldqޚYÄWY`A/SWI6d~iu:t+|I 8gyˈƖ1Qγy6cZLT봽:M58sІX+e'ԡ3}ﱭwF* Xkmzz#x/p" -uÃŢa_Q, Y{.V(J>]TS~=5q6J[Z(o 9m/K `l ~!J5I<;iu;3\E棄phӯ|B~RzR%714#BY% k[1se:]>7M(XH=>6'p.'1uz37E߰n{ >? [o !_5gKyR bW'.ABybq v)XcDL?(#5əE盤]XSv&q? :@eRH+UzQ]M!S;&^Ԟz#84~qa;W=MZJ!s+:-Թ\9P8Zmw(?^!p 좑y{Ck=%2 4sQ?(@h-xɲJP DureI5.;76_NP/LBBb>_ :C(~}N+0LT.}jb#ɏwW!(zWnoEy3&jcv1-o U|''"rC5cE@5 3(KM(!hѿ@_//(dw|AS:ӔjG=cl úbRé̚3*/_$T_۲y)8}O_a0cyαdkr\B l !"L7F,ա֝8Jdtd|Fw\dӲΈuAPReh"ڶt!9?vDb:2,GkсNJˢX'+8rl59.L>lkuLq 55AYbue~_>Oz3=_حK䆅WعzHx?vsòspBcUȑ 62|;.ޕ*6lD{l"C*+cEΟ^:ٝn>['Ҍ%Y΄ ׺8XdȢ/~L^I;x-RЖ,KZn F<ޯX)G0xk Z96κNuaO9fY&Op7+hOMķf1.[1rcS<.\w3l G%к'׎h qsR-suDTdaWs.zׂ͒rГt˩̔&{?moQ¡ ^Ϧ/`@@Qg^Ƒp<`Sm,qoߢȓ _aʥN'<2͞}^*(_ uzcYrzC+urWa8* $Ng&dcx;.f&(kcўInִʨ,`y?ד.|ԾMk3/%/~`Ĝ1_w»hں&~SedFD5H!?1aCErY'T2_Eڡل:_dOPr.58E*a+NfJpnBmAzbd+#'>EY;<#iZ xȉ3#E&^q8 T Or_O)^_P=4Ӡgun9g)QuNȇ ~=xМ^_up~SG;p$lĄhN"SEÊlg/K /:iڷ`rZe}LG!C  8 *$x-Ag.%.ig !x@6wJxEC]OMRWM2%ot7Il)3I.yKQr9pV`Zߢ'=eR"O'g0ʈ7fvJXdOz+$Q`}Z\NJoNֻ@dL=m&m׊M26nL->Fqr@MzeǖA^^WN2{ӏ4 n>řAaa .QСVp  bv"/d/.}o^}Do4:~tZ c%c))—s g JK}UD'c  :̵YGɗ|w*#rȑ-4[3K"-xb6'mML"a{=ڌr 6/ӓ?0`WEHT|"+FN {&vP G"Ǐ_$b Bn֣tкj%2\Co-{A96Y_wPL`D]#Fko8Ԥ oI,QEXۥл~?H-i{Zy/Z|t Z,.lU"%*{FG}I,eT P r3Q␬:~=@ޢ#<51C<,ܲǐfW&G~C4 nQbkZ `:ZS7)3UWWZD"tf?Tf|}~0iiG:X`fotߨTf_IHI,ӣܾ5Y9mU}J3<50[ @g-45Jdvj5eZG!Fȅ$X"~~(m3}; 1y55?9~_}c )frqUn Հ9$9P/yᵔ&oA8T~C(|_ j:Fh[A]$+`)`oQP2Q-"7pwIB1[. \23)(:2>覚 <׍!ck',hƈ0|w>UR0)"ox.6 f-M/Z1ü7--^?4ly2m~cUJ-zḵY6 $'kqWP>N_L~FJC|!%҄(6 C1pcPC \ѬϹI?R5(xfμq/(6Ѐ)c_iL* $56^,^ ykGITH:$]fMRNgli.C~\'K)sp$n4rԿp]AN,; \[94|Y*鍮)%{7ClR&ħeJ,yઊ&dB5'ȷ#y =vK]kߋM/U9Ęk煇Ut1~ Nޠ\-aغQdgGGibfenR DTe2j^)q?1s7֗P~[('>Jo܉y|]n_.&r5cTpz3׉ƾ?lXE`13^ׇEm_TGGHR E/=9 72{3fY쾃,zayuv\>szu 9hm蛘 y=ٖx(.B }JG)LZ|iz&YJr>c@~mĩf-#U$W)΋Sdd Gl,kXD C-NԦezǞX3LnX`t@鈰k-rD.X4 ,Uɀ\\~cY60Iіpm;zjPw!H-ZHN>Vb)TP_?#4ym&0rKH^9_8isJ]j䋝=VKb>zrc^gPˬ$֭:RtVj~v#gc_nR"k- zXHP|S՝^l o[LrgRYh`Hj[GBWr3ZTKh%'vQ2a|:+ {xP;9:X@9ݒێ׮GG`v1oKM@ AK l0e_cf/q;;Qꯅ)֫hђOD3) <4`)#JeE]O=GiɞӆPzyFAXK\ vˑc=jHO%w;t+!00v6|mhj,c'u 7r'HVO6=^`JD5C5G=7jBB u/Ot@f ǠfRcZ= g"W +٫^+.{V80&3z&{!YCl2NqQpU8O61ĉ`3Ɉ#Lfg*2]࠺/9>rc1@ Bi {Ѯ8rt%+vHȚ#0YM8o=さSS] 0Ua:I:haPz,:i>!GJP` W**V2N^3FBYA<{:96c Jz ;wd~4 DTN.CSR#\KSNk/ (t"ۂ3ChP0ervD ,~ϙ8,d牓|.`..1.+A}P+6cOgz-)ŏ@&-',&i8yQ)djq= ǨͲkjdu:]=̇NTP`H~>6'В-A]CLq"p tp(AǺzt&X"x+RD:^3O"]8kɻ3G2ia $1,qauNѰZSk AqY4b,7iX?GaPcP0dd&97rnwp"BSBpQ$ofb- ׶4apZ!۬('q27]>M$p%E},̓a@t'pc=fH]|dh2[%W^*-YkO-B\TQ 2NBV:Ҧpp TלZ79oB1м:Y{QBNlO=kfAmmםEٱJ 4zD]/~>$qT$,cSfppkrc>l^9p`Ut% PxC| |뒗/M(pW7mMCxFG/) jּu_?Z >Nt-O,] 9v-hzb8`?wt8R#FDIYʀ 3 J޵jmɪO7lмO/*ҏ3߻a`Q-@Ҿ$xnt-;Dy'wp栒e%u2 -!k&.l/rs)263;##Ijȟs[qׅNLDNxM-xlG?GM1ۙK1<Pc2P4ACs9LpK2k8IK`M+RcQ\Jpe! ^OϮ/o2E-P Zj2ΩӘ8raDZ!k6z{v 3ĐXXcQwXZUr$/A/&^/т__ !u-ɻlyl[^ \r>fW\VBK)wh u}ML<VBz^b5׌ڥ\ㇰz9)Q?ㅻRE# y1dǑ4mo+Rpre Щcs yb+ze>.#PQs2WWzsEB0j'tcyoj4HR@QE]oL5 W1ˉc,c-]ֈdeϗG2IbFL?/;^\8G< dk?&iHgX ̰)k|GX .h H,d6 qBK)`J>S/m[jxKK0\"v>"/n6bum.N5$Q2Ȼs YZ