container-selinux-2:2.95-2.el7_6$>0v%|~hlx.>?2?2d$ ( P  &-  8  H  X  x  @  H h     8  l  V ( 8 D9 D:gD>/5@/=B/EG/hH/I/X/Y/Z/[/\0 ]0,^0b1Zd1e1f1l1t2u24v2Tw2lx22Ccontainer-selinux2.952.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.\ɳUx86-02.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&BXZA큤AAA큤A큤\ɳU\\ɳU\ɳU\ɳU\\ɳU\ɳU093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d8403657c1bfd05c74802d944abf9ca889a98fb54cf14ece3f642e932b6bf34cfa31caa7e754201b0e717c78ab200dadc65cc4091dd18f3ca15779a22d5d27a83rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.95-2.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.95-2.el7_62:2.95-2.el7_62:2.95-2.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.95README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.95//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,^Y]"k%u#qXPNeR@Qnt;P[be0nH%B``H-s|1$~:;!j_4 WwmY JcyVWiHdl8I?6zBۨ#Kʭ_n U}ɞ.u@B灆Dm8#дE))8~~#kʥ % G3H"èZB@pmr"fp2o;(Rwd$\@i;ȷ:Y'XXYC+p!ƅ]xb~ !)Et|*0"QBU oXN5Gue6\M_҈T"#qRMsŒL.5.}Ь*h4 s7#>5MA n XBSؑ9ځt/ = @4rl F^f?TaXίކ>l7nI|e.4l>>N\0۪Row_4P[ .#RXg땣t[kB~MvN$:Ez" dY}Lp:_"1 }FDYT#('()oPk*ewi<ٯ]c%mɰ٘8s<|`軆Xc|ȯ^ ͥ7]^4#!On_|.mN*!d$B 7@ 4t L,W4.}}Cr Ca;4LpwЕ j^Yjq=u,IOZǿCnB6"Ψ84vBtHTR[r~8cM9 ѬIqa] X'Z !]fR"=w|D>F"`;^f&&jYShuq FM*ƊA*riIrUňlXeʦwe{IWncz~Tqݒ+- 97;}CB}/d fv Q hH3I pn׷d&owbg5yT#! &7s㵦qWv6Uubrrӛ}vl<;?pkCnS"moCc1>yOpY?aƎ9Ny,w.#tF*mЬ謀CNOUm5ߤ?qz២nN8„ m[mӊR&`_e}z|_![s/gؗ+g7CSMpvilR_m7LV7o"Uv\e%-CY.G)7%(%Ǒ7e~8\+dn "nxErwT0 m8?Kڝs=mNp")Bt |w鰭e큙WYv BPL֟<cN'ڱ7a"o;zl =tHO?|0J'1Hr_&1+=A`Q FAk⯖dt::!06M&ofA|7W?dF¹u 4@ ?XQD!I'38D~ cgkNH%ď q(-:M:&{w($ WhJnST>/T,l[xvW[:uۭBW:26sm{9FKV8cuy^Z=%Xv;[@>dKo{`4sqO1 1pqr,~$u_x-uw`=ejte؄Y CÙ8#bجZ s*%&r,LwEJ!-扒ŝ8XHdgѤ>G܆?ڢZ@hy OW{yψp##ؠBipFR1MrVr b߆gX + 2xF+a=4Ezz8PR,n(9m3i𤇌 :Yp/S=fs+RnIUUn$qFæ?E %^\TDCȒ` O,vud8UK]Rᗛd橨?@?@qYI9~;6PU!+44X>ѰKD4qLntq`'@*xU*nZ;EO-䂄*E6c%{:3}k\fvH3$>ILI5q&tLpY)͚W]['|FrgCTF7{qq>P]5-]Vcwtsiʱ ?0[ܙN8R4f"ў?[![o!1`-jw=I,B:$jxGPD u];E-d1梕1ȸT~Q|'[S A!i%i `{1_[_r@+DO1!POU$/L$Ttc| #Wx;NՌn}WLØ%0ѝ3-٪(u֐=|BW⬨@75EٍPwM׮Ƙ5@sr Z6k{^>[\cg5 1Rؾ4"9Oev ⤥zPyIN/Mh@ao/gv.ŽB-x^%F4~e-f=TRfJ}{95HŦX͕d čYg%t?1?Фd[&o)UCю;5 uCe-vkc3b1~Y0fH$ +L8p$gU ]-W*9 3OI|I /FGJouWz.M dp[o5>ctt%41*Sg_YxK%tw 4{RhbZqmϜ4\3kto|Po9~pY\<@nïK]⎔ 5*1?SbZɧw4ů&ћӢES$1{Rix7T*1YiY(j{< j4EBJ`.c QF.X|~f%RlZ~\IlkՋ*h"RHQ gC֚]A1 v/~^dXfvC"BZ ihlfĀBlnd#J\usqMU]v+ ڃvz'O邻]+2?|rެHhyiĒ&Hl?wqq@yb$FJIC'dJ83; @)P0k7hLBk73Yt[l-_0=|AD4$+z_ߧv~w`ݔN"5ֶfyf&1;+cuu?wrսR l=5DD'7!`?MD3eYu뵽/U/þntd8eK>XhZqD ~m?anDsFMU.9]22H%f]V"ku {5[U߰OJ67o3@:#4R7뭻// j͚޹PGJ; GcȜTwDbƎW9~I ^圬g":)d;o8̮06V-U"9ӂV`]aq|&+ `79];xغ97 \K.*Ylt;Yw08D|wa|QG9+ j@x(I &Gc:V0urno~8f||nW#&]{-O^ݫ6Hkvzrj)/{ %.(W5;STQXb<`Jc뮎yYRsi3d,> ߿(WtL\i,4]1󥾀DEi6N'"1ˌWe瘃bBсY.AAL4TFc:tH(Ic\`07qz%JcR愃,=wV?,ggNnC3X EW׆}$ 9_: 5bPsf76X ReA{ݧs"fZkJR׳Q|TzT'gAmX7><'ʰMub` V2/Y!S&58jP3S9H9_M/wb! OF{;j0'tp!jK4׎ 2b|=^Ǹjç}_uEbvU.UN=>Z FaʓDwbx{\NpiXtퟟaԍZ/Fl %ki;˸PJ^lR^23tx$} PU[|| Q`aT 珳W؜?>xz-/\UąhL@L3ack[cb ܋2O1ca@?u,'C+MdE:?DJkUb0rG 5 86B;㒀Sxډ7G0@{d#sG)'My0'x$5@axHO$ MUD Z#(;rҿԫ~{>(o(]On˷/#TW3?4"]gKfqkZBA_y1Χ&xP |({RFzYca pIVxmǺR? 4٨WI'y;*.]x35Zby'z 7c[8/m\r1ůA1$Qu@H4^UumX5w3!Ĵiٱ%OwEQzeP nD?Aeӭxj5\&H2|nL=($8:جŅSgRFS^ҢGvG:ΪhAG^@ՃFy%ˠ h -o'Q#TőSyX 5p!h<7 ߅1wQL<@p/|N=owI4'e9;f.Bmc7ӞtAR9%ߟ[٦Z=(JrS/Xb2FۤNtݹs}9mWxoa&ofnR)y[\CNr˧:u :%L̒!#" I T|4G\vSKKqbDsz_FUZNBP̘lCNhHmzqɖ8bq]aUrH1gNꋠxݎJfQ0"H]o׭q:0=yLJRhbc)7wsF PUfW`@-gu bĉ -Cܪ\D$Luj>G(BAY3pcAǮQ#(}9EMzD}ˠ8mㄙ^O.0Pf*;diQ?3aIYZ*3͒ UPmb̛ǁ.=i~o?(æǫm8z5a<ѼH6vO}&sDVpZ|xqUmj+ׁqeD' sf_="}HcQpz0->&y8+ -#S_#F8"~?WJVWUެ/A# LhWdFڭ W`1"NnZ8 85_ET ?΁ ̦ůIp@/H{-Y &lq5^=F- (U~E=?Bpi[#Чz.FY !aU,AA7Z"L xߞa>%"4ls;]QHe=G:|"dg[\T*Pw*щ黒]NџCԽ5sվ=ƴ{zD^ϐ{RNܧs5Aw@x@>+w)/&q @vg]K XJ3R1R`;, $"Pj6(3xP^ŏœ]ըKL<\~$A*3<# qƜtdzB~Orc,?*܅?~K vsGYU}?̐c t,lc*b1N*xa b([km{!NBJѩo^t:EWk|{}bt:,hf##\ܬ3cD?_ Dt{LV;C|k<ˤ{1;<>7T oxzhWМ|ݽIv7G\G<34eIpI'*[S="3ty[f;8 wGr#~D|K&=zt#ĚZ3gY‡Lg:i@BR̆"'?#mΕ]5 ې Jja#Eb ޜrb織6ȶH|Kδ-լ*.[eWhxgn+dTiX!j`+uw!}^軴̨Z/$'0x:)=<ֈ' d~UGK`%@1c|z r&^r8? ը0I)C77xZ%+wFǕ*[v˄e[2&t) NoϢMqH]U$sՉo6$l%B5A+kcmM ca9ݟS4>ҹˠ o߽~QR}[_Pwr& _A2^`u[tdf}-cT46V3gEXyT ['|AAo鼊.iC=M=g"k;)u`wY Em#DŜj0 /^Lh_×z+kC`P;s6΃q*U?6U|V'C_0'oQHNQ~k*te`v N' fFez1J~}p W ''bJ%Jr˝4vfqJ"$E?#CO硐*r/pJ`[\ +Qwʄ]bγ.V}-YsMAL' ꐱoӥviZk7d:-e1[·:mM)6ٱ.iD]:¬L1xC]f <3O&*A,q( 3םU[yJq^)ʜ]oD؄{fzm šr¶@/q/=).E 9&ga{d~"Ƿp$?T-w+䝻WYn 4LUܵ83gAH&I 2Z"3Ѽ6rLَU"Vx^n ,+5'[ EJ&x)CyPHH ` EGP,=`aJ,M戻=WSvS7k\}^ ~)( 6@y4|:{{r DO*v3IΚB"NSWG^w@mWhǬ!@\+XTWKCOj!#C=#%mͷVȠ& PI+7'd%g#ìq\E2"eJ'T(h^KUs5Iۼ83̓spArTBy'm۪R7` Y=i  Ƃ\*pi.dGrf䤌~GS!aȄt&̃k>z# 0l)Jmy|k3uO;`7S_79G {Ljʖ쨡Z5 ÄdwB5 -! .V^lǦ)f#[/^{zoMhb8VpRCMECkjo/PK*ǁ#VJ~(P8\ܫ_=]}TOE ՜8jOmWfA(gm./QW}#W(=P@6=5}%L5T%šk.;l:ԃ̅V^]m̚ӧuwwt'o>Z8k6$.?'׫U C*[k[ oTpNG>dٹ"5E}LZT=g=q0Zw!pSW5p 1%<& rGU `w~dHwpxDs3ۘiغQwS ޮXs kP ^(-G1 H:<=>xpA[$rt0P3tkp[ hjc'ғ%LC``׸LaC3W;%蟩|*oVO U6xݞp瘟M(/lG ΄}[U!IWe H% cWd)VQ/2f'̪CEY9TL m5,Ft[1l>0+>DS?[ fkjC HyA<04Lf+VHyE)>{s+'B0Q.%{RH̩ԣd(vke7 FWf?i&Ne);R^x+h(sO>N9Ŋqyz69=6ȧhC,)Ev+)ha2/ԧÞdbDyɷWtD$Jc$*H&|% h~6-7(8uiJA|Ie ̽lI ʼ:flRHdd 7azu4tvZN}2^< Q$8ŗٙIk2{b[m^Vpf 3P|`.(;Rs QIҮ1M;wM.Ɩ = ~1p'_+ OLo܍;g2D+“=r-  *KF>,6?2 D}1t1x^Hhx~%l­Vlm1 ?KJ5Bp@U L PSlۋs'!и<q5J%MNt4GVR_P{.vgDPڔI*hAPMP_E@1IT{N?ǥ{  A,{tJ< 4Z߃ENF̚} oHؗ adx&4MB0V߭VLZؽ |TN3p"y.]< ʵ#/윟kOMI#54㚭I؉mWIb`})`d"Mu2oD>UɵM?.%e6m qSՠyay"9 FRQ#w{B|_xϽP(|%||N}ӀŮ)rJJ5;Zސ\=ʐKa14uOeZ q͟]>aCKu|m#@ ͎}X|钏Fx#%*^%iul'9XL zMs?4d7) /3s73#}yH8 U4XrAv4&e QG]C%Y&zM*WXK`ECGpr &]Yvt)-i Ni)leFmsWfiwO7Tf&zʄ/"3ZDUh~]ɖ|LSu#y1#A ggW;%e ' bIvb1RzNYٙH>x#Jb t rL;cϺ,ju?C$&P$GA(K%sL."#]ikHN|>8q Շa^# )D@Ҳ^/hS%<{|]OXmowtA:W( ۵i#r TxR xJہ67`[Z9ޙwT U:9i*D]g} pEkxOpRR# d0 f1}<'&'VsM"T/cf]Q/IZ$9wҙ1 *0TY~Yض6֮8:^ CS+̎}'hTz<:]t Qn6b6{![m3s& :NG'_umxXdp\F{M!^jی(.?WEum;ˍ̓棥W S],G2CZ&iO(]5u-4Bnkf?lcQ^kCB>"zT|Da"XЁtٯg.C•$5u9BEA (\3.?ʤ(/k -!`Bjy <>pr S%3N"G׎a 0hOZ@([>C r<]:2101꠵:3?HzJzD0 \y+O&y[3āSSE/o ZFѲ F k Jq/"v{a JұUtjgI|-D} "KU5Y LgJFs|zp:'F00@WE6|N->Ifӷ)Tc䞜دG槀8HŰ yfOIstü4ӱƪn -p͑gƆ'Tèpol!&\鸉7P)Ef.X)2)2XWAɝ1lQtutQm!_~ΰ 0#s$ߌ==j2U<ϭcOjq/T(>;}-$֚O[׈h]S(ɪ0$:"Ȝl(Ytswp0^ҝݕ//IΥ{AK[<|rr(rMT[g/gnS=6h]n;0#6itûGi“f*n=ɵ MS-X -nI0}Cc!1ov}e y^C戀@o;?ӯ*qhMmaE&P.+f,;WT3C:q 2V AH^+p8IB{Ycf/~]UCT*\MCts:vȎ7I~i5%.( s*';gk{%BD] 5*сh%Svd ւC)VvktieEgTZfczmܩI%g*fjX];%dBWs2=]>WZػd*Qow隳o%D5ߚȠdRВaS8G\'xMg6]^vѮB츼GMۺ͚`e8)֍1KEVSV, A݇{_c!ߗWJ4q5RJL%؞[MN:F`1C$ñ|UϢU N7~NF 0ʣɾq7I ?? ZlnR'JdVS@!Klq3`Aƃ[LM,f`H`Xncl$5L>-Q:,)359K,1EPbS=!יtňrҥ3`0`֐LjFNy"pgZVj Ǽ`Ɋn@EiP3eB?1-?wДyX+h|"7wu"8t/'(c~ @O;T7dW> 1ېÃfmJM%*t!*n,a`^ߜB^'nE8yaGEHJ٫JV9VUXPL3[Ic Mn]!T֩g(-5s#v[̢]N"*KS&;Ha=YVʗ4]c=;t nvbBHۨA9\"({D!OFtwpn{l G`qC0fad!f,liJ~%z}K E֗D˩\, `se}gC9-&* M 3:)eճўY3rVt-p0hyMy*n3M*0Ka/Xw%ۇDYSe شqdPCO(o[s;t(&9N qq30R'|;U-{9,P=eu(,?;dL.v]@elR2|[:.76IoN4▢VU_Iu/aCr=M)# p$Q=D njmTobzZ8r)"gGsOX0j.%WΑB@ 0?gcT.ٸ뛏ړ>̶>b<4>3mK4C^N3F@Iyr|Ldz#• ʠyOZّاQ glzdyf? X."XB3Rx>D4E=`l $lN+P}F-8Ӕfߪ+Ͻ;#4\.i5 ]ۼDFt3KDU 8w><̗NiՂ5R"nNܧc8XT#rZ3?/Ӽy|xjjKDvz\ : 4PӶtݏzȒ:D tT3Y?,SP,?_J7? j. Xx4 neb.z$ kw0 QW]R/]_# 'qj'hR{ۚRH@<5P [) 1; gN!B3SY[NcVw<-mRE0ٸ<Lst 㪖q>Xg; p[MTu?a&z.mٵ"JIs$KH7ڌrwf<k nuHe?+iwayÓOR ܡKSЮ.>Us̹8EbfD mh{ Hjnh:$nɊV'GA_XY 1c Ԕ?%?)n}vY$[N@$wD~3`Ph)g#0J X@5 7[U}fײDLc^BC(30=v+1r<2S*M)z!HnNe^j1b*ek ,xV}wip)sVD!@4ذ.^=}i1ZC6I)M+x=zTogկk'>SԐF'_}6CX$ pcf SFe(z(,ebOzD~+y z` dgVqf ҧ6a"lK{xX / t [u䵔t4C)ؽF_[dKq&wJV79[β8>b܋VUk}5O!?J)1zlf\e.̮Dc7$V!60N>[7Xf[O<:wT2c瀢D+u[٦BɘIijpcz |z v_=zH c}͆6)3dڒ~Q-J8!F`J ϻJ'~Oy܃6rS`E/>^a\2IV%ޑcfG(&\SzexV1ge/+ڃ ;o8gޤF9y-m}bӂir c ~!&^Y:^ ?(J?0cI<4h )$T9yv <`y]||X}Yҵ,>܎L3gב }<(W`ڃAi*7Mҝ@`y~jh;p5i`C4v-fYP['gtyX{Tgu>YteNlUyqw=gd/ JȲ0+LyGdhp/<ߊ)ޤabpI&N. X4Mml52&nbK~裑w'SWv5aI5,gϑoNSohl﹨u~ǭ5~]f81%-CDqrOX K'=o݋ ksY(yQG7 7LuGG}b=ζ\mxlILp#h!ϵ:N{a !r|*Ŵ*",;EaoQݝc$ѹrufNvm|{gVqj<N[&aH!vE,}tLcP-po|btǞ)J{0pj6;O~љgfJ 9V>Rۛ,m^R:x `nlœr 7#EC$4RDS<&sr2Nb<ϵi4dԼW- B[:yA?O)`)@X{!:axSi"|քp˥gF= *$`LF51{}yEB2AxnI}edR#cUCWVp%FV89~trfkaf|.%-f\oG0 ɘBf>1{I9q%Ќ' E12ZBx-X>C!wH'ID[a%5Sfyf82FƤE@JzLBJKO k8{wZ枞g~8(/h/R nՏPSWã"!sĐ#^Ǹ.-ξoh4Dz+m5Bh=7˱%,x5C,}H"A-a  Ӣ:7J) gW" o\s/$jLզWSϽ9fQ^ń~AROT_-)b?L)egRO}K13tQ N'VgEcSy'_&]s:;$+= < Δ,CV:qf]|'iFT߸٠YEЊȣI(*)!)L} AM3 QV>b\䳗yʢI'B|u$@]"W.GWwe#fHnP`^[ՙ<ϓ1Ubf"[k g289(i>@XW9;ݨzv*Inv_ h,?HYvBJA5rS2-/v`GwF O2PyIO~ 6i59{֋+Nrd\.7+uv'Ex7^զej|@]k,+ ;q̵T!鄿ȅh]OzG [ 1;ZLR!p0-!NJ2/Mrlf5v.[3kxȪW.bN0@ld(/ us$ǖD,bqF<#_X0~T9> foc7At_NŨU *aQp Eo4fށEB+e$0"[T2m<c Hg6*,4`vԅҡȶܬKU&{#҄ 3`@䭔N, 㖬oahUZEbciI6X#KQ0M *|:-3T҅.: &X]Cq羐mQ&.r42W,lOLd5%w޻` =(ᵝׅ+ﮣ@&' yٮ,asKV1̃d̼/AnM>r> fK~ Oȴ)??ڵ`&51lzљZdl8% ?* 7}`Ώ /Yjα9&vy