container-selinux-2:2.99-1.el7_6$>cGڷT _V7>?3@?30d$ ( P  &-  8  H  X  x  @  H h     8  l  V ( 8 E9 E:E>/~@/B/G/H/I/X/Y0Z04[0<\0T]0t^0b1d2qe2vf2yl2{t2u2v2w2x3 3,Ccontainer-selinux2.991.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.]vDx86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&FXA큤AAA큤A큤]vC\]vC]vC]vC\]vC]vC093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d06fbf981e1300e33caee8aa3f8d2b050efa644cf7f007f199b2c901486b577db0da136008666de90c3f116043630e0658a3fd00690d649d99d735f9f0537dcefrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.99-1.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3\@\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.99-1Frantisek Kluknavsky - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- built commit b13d03b- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.99-1.el7_62:2.99-1.el7_62:2.99-1.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.99README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.99//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,`bZZ]"k%u#qXPNeR@Qnt;P[be0nH%B``H~@_4ezIvEهT^-&֮cUteAyħ@kG±+b Lep6G$JQ+Jt^o %4 o7Z"xvF6Um_7fL_̛!5ŶĢ0U3 ÕO}2C9ȧ8>g!:OoT4\T茱Ck꽅 ٰH} 聝6uՎRk44#pJiU[ HvO`&|Te==8k\R)N2!/z﮵ uBN/le#1ܻ=>.7nAd 3ؾï'@G F HLH1^J(l֓VAH)==> nt&W~gsb#bׯ˕ ΍m+4yPu y'ZEIf鮃s :xĢ`7F=cqG'DG]O @ūΦM/CoO9yxUuBh 8R.DΏH2IW9__bx(}{18 vP#C8@Sגk[HEDmx%'^&Y760]OfOl س65OSc-/&8K ;Y H< .7{oU_΀OOG$csXpP1J?[}ƚrlF<]'{'mL=Sm& >!Lm(>Q{ tFu5(nPKE"c0#29])/mA7 rܘaRz#XD2pHY96}gf3:lj:Pή S$x7k([K!m^Aq.&N rј>Rf iT 6Θr[zd_|g\09)l4Kµ 'qln t)loCF`_٫p3x(] rf b@r3kΪ=Dx Dƻ Vm:+&dv^k#HT³Z2:⯾ռd%Rַ[_q- ӧ #~GY,?7CIHF.IU@2Q:J U٨Wf[dU 62ՙ$GMPu1T3-> )De }"H%e%-ȠsWTԆ᜘F Rք@tY.& u7X%AJB*^ ݘh7QMnJٽ0F+xIszkmb$E ng #Ypro"7%Ʉ*z&oL-6ۭ2D3x5~jy>' @*oMXDJm'T&nXZL,8c?XrܷJ 綃gNb̜/Y:fhZ%ckjcʧ iz_+;È4]ێ#1JKNB2Fc߮E1Y>,E\:(NPGݕ*dd"$ku_تjNc_/Cع"; Q4Ty @\CA;bUe#UvXvj)LcX Vkvʚ525roPzc9B:8/h pt;ۙӞ(Ňj*ь V.l(Lm^?*3N٦kX¿LLL[;/sujjɄݬ7r.z.p& Ou` 3u#Pf18`0PTaVI,6m^vAL>5HGRS\ӝkC" ȋGqedQԚt YYܦmy8i=Fg3*Շm[P<.d)==;ua'HX#gӁaHʏ׏Ȋ1sZi'ٱ?ε#T4vcU+ YoYeuou^So7m^BrW(iy"/Ѭ(QP19 欖7[Q05PoM+Vv QFz/Dpԁ=BEoW̺:mKx,^v]y>s|(*f: ~F(F(?MXw/NT H|`H8o-6H:ЪAb6 30O? E׌e/+mE?d6$ uMLCFo3mHS_nQ{[W|YRo)?~87p %9$QY%j@D)òR\ )YrvZIJlC$6ԍSFܰt*w)SڀS~a8M IbރL;!4j)㉖s߀B+Ԍ Dm>MklDsΆ,7Iahۂ|byϧ͔)+H0NꝨVaGt[!Y!%n E¬tjW WMk_tPJ g'*KƬ)\Hٞ%tE(@l%[(&E:6AR.۰08hr';u'Q{cjrc-Ѳ Siyi?UDaE8GeP pQgNrg9ج~zYk~uQ@Iv̞J.e=R$\CcOKx1~JzaN> 7,6$sj?]+VtT+`OQ 5pYk.Q5PM>KGzzF-^HޮG锢mZDQ ~pZ.f}x7<. Yo +8LQ9D"ϧPz_0G"E:"b$4{ԞΜn< PM7LVv|FxeMTQ~^}S8Y# Y^v*KIuJӗ!9v`*\O80e'mlbEÄ{%MO!죀f6A#FXAMp_tTD x3@ sgu pf{)Gٟw!5_OU4< X†_'ikabl(#cӺƄ=4Hc(_mUme`jpRrglx9R֨8^`!lLJ$;[\.?ӕ72:Z1^ bĻ- T+ಥ}CP~ 5 ~ O׈;y@%:^w#HMpi9t{ d|FkDtZXr;9&tZNAD,' %vvP'p`̓ۛm%_0riT`#nPhW3#F0G Mt% ŕ%L}gUר$8 _@Υ3@o˛{2Gw6IYP{[!+WĨt@c\͞`*[/!3י*r²ve$mftH *HXO#%5hU' JśM賕&vދ8-rq=F20`y)1wm:Cvd칆%(+r 2. a-ֳ7*`RsqE XeiG#M Bg~yQكnȇw-hoi jͼwb =j hmGG(|}k݃&hyB+źzw}oy ,n Yld?Gr䉮4 y#}`'2MV)f.ͫYt)`M)lF fЂ)rUDU(oQi*qG/Ϝq5!F4QgN\?97m\Q!Z]" +"_ ) H);}8uE!lP]% K]E[g$a(V+=bK 1<]'  vY=5y*~uObi^P9,h$aFgՈ2i 6^7w6~&7V-* 4;?Sꑂqa$2 6tك@y 38+O@1$`Gi.UvP@~lOI濬`cσU ĿѥCoվ yZZbccIucMokA n- &Z(θi; l34.9ǢE\ 6מUfe-;cvW#,ZgIKJ0.8o@7P{הF 4|IN*B YS;]1 i@-QG\(:eiq MWWܒWyI<=M3m#]r ! YMC"D!jKN3v`lvӭ7]v/nA*o\tAD[ώY ,:6 Jʺܘ+i7>ɧ;Хk<` գ>ӻ<4*9Ϟidw* _l"W qtWo%cHɝ(_*Rkg$H@F!UpP#& hN;HTChI7H %x2Rz*KA#\<^΀&f#+Ʋjjw,GtY$6Qc_^8%X*X]#mhƌT(TkybfLlS z-P qD㥖PչaUҽ ?2PM:T,+, 䴂;=@O2$`)ˏY7NaY4J&R9t?2ۨ> cyܷÆEmBU%܍D 9ZȐ&^"K[_߰O|<\|H˟elߦh̡̘@^S.' !VhpHxZv^PlצNʊuخ)ԎBH%v;] c2~ORy"j^ͲZø ivDIeu9"sH :, `9u6Xtq[Ej-~Ád(0k%w-tjz 0-0}1ϐ2qwqcK4Z뭠oRUj.]05 8XqLJ)hǞeImҞ›JC=f#GACegb`?3 $m@ќ!fv/Z چl;&zUm\a(?VNFCma_S8p38h' Ff{2P=*CY(;)+0Ù $Ѥ؇I*ь^;yo'8>7c`y%M!S'bSŗg1{%zo MqTx܍WD CZYQ =l$`E&^Q|\Z^}| L$eB[8:1:MkTt:LT^ g lJk`d> (G"YeթȕOoW \e@.3a'+j5J֣I{ G\=vG3O ێG$80LP,ǹ Aj_ϨL+pU-,֎dc- TGa=vW9`gsҭs'DOZ/'_+谁I=,nqoηiHdٝZ|3fMɮeB\/;ldĪכئR'f@mܸ5G`p K %&aj 8jR\`LtW|5vȹ15NbE}ԍںcP nP󷎒uZgB{ 9O* RcЈ!@%6~>`E2UaF {E?\ 4* c]'"MB@ωFd#MT<PbQkfghs[)-$<}/l/zYΖ/p 3lօ0}fkxGX*ܝhFhtJ&Nl3`c2/'g &0ĄIq9@ċpR^#(Ɏ.W2g*7_@B~mф[10 7`AAsc=Y@A" GD"}QNvH}/Mvce%%*_~Qj;$wz*]ϛOV0Yth7W#J=ҽZZ V 4zz߆ L-K-X衴u-m3PgT0sD')OJwSQ/>{)u>m[8]\mIہg%bTJ| %ex5datϸ u{9XpkHOA5SyZm=B+G3UmNf*[mβ9im1Du&Wʥg*J[UEإT>p|,{vOP9]E@; Ϭ&TU6)~qLp+.{g(~@\c^qzF/Q3Q Q:UvxtkBժédԋ"l6 9ݳO>LP>H8 >ENP8UM0x|}" 6ҏW͡\9:90֍Yk4Tlţvl$56Zc%J`oنEyhz-]c40sX |44xf{Nӧ#b ov:6Yr5~ YXu/,$PRJ!₷Rȗn:|4JptKZ,C+&crNMG |D\TgKp;.hi&Y`VM&z,mH0>j{87HF2ٜ{׊$wr@UY)6Hp0;;8۸(VT - vs|%uWfSs К3.|(g+ u)?Й-*_T-2Xcy90`)%cO~.̿Cy=K/J"YH4GYa= 4nuU?\TZH_{^J"n~[9"wީ۬ʳ-^BV2 !;PkK X*X&%CG;,{ d>gk@|Tb(W>սd8D^!%powRIJ*ldp;g,Zh[׾pnu݉Z$LOY,dp}֟xdup Z7Cƈe|~U, }q-RcO-B4b+tOc%A?XxLODm/oǼ72/l@%h$ s%p }@-鵽cr< tN,Bt]CB'\ni9 Ls腔hՖc*}]  ST%d߼AUJAJ| |ՂHWZsN7RP1. Q-rnGgOa[jKٰ/Zc[e5pwǼ):Ӡ+G0R|J&'Tz 7S|HbMvXPB3f: "BYIDZrށEq[ "N8gJ; 2ވn08 {ɜvWf~&[`Q:xT GFȋ\[= m /fۘк– DJRI^Y,!nqW ɋf%w&[qˀ<32}` Ny-|;sҟQ:T2\{E|׻Qխ2ϖ۶Ovtoi~m Hb0J7qKƤ|LI"!0nhRt>NUvk`67q9W&|B8NH-zoŠ MNDZ3K<FY,*iuѝƪ\K|?$+>`ux{߈xiϹXXCf&NFXAiv<}X9Vy:6nv=S5DM&j~V+ m-e X+.#1 cn㖨B|7r~WKԭ䯲G1գx`b`@ۮbm+##^7ֵNj=~3#|eXS.rz  K~\0]5X2k1纎5žݓY06:(At΀$i!`,<ʡ_y'@,Om¶6dJN{·5~ {jB(gs&Þb e.iٽ4Yۺg#d0"\R0ɬO=[nT!6֨UNrsߦԃ!QzzۂdJtM,JigkT! hyE ?" :%'?FF1pM8y“= GdfٳWP0K- \k=pi\bgmS$rn9׸E͂!=(/un6l}&Z<{?'5;ʋcGJ D,B21b ʁ}!4i$Iji>wu QxLD#CSI,Ko [SYŝYZKV^5zrYbu/ϖGM&_{>^CZG}d{djC-S%@RbGkGvXHA':A®/)ԚGw_pJ~wdUo=vSML6,VT k^2*.\|:4#' .,<=|nr%iU"9XhcE-C5=lҮ5wëF'k2Mcqb>tP!_ܬ.Zڣ0<23.yTnӎb=t[I]ΉtV[A2veiRx~AKu\Q`dO0~~'c=oW!|G(ӡiKB`:%ۈ%UWaTVA{-0m"|ۈT#q**AO~}SӞC:~<"q卬ǣ(@Բ{0 c.Rg`_ >URQ5]Sw<< JTO1A)wˠEcDZqU bme[gEbęR %%ҶR[ؖqeSGԤ(;Ikptos=v3[&}2mgܸMB<#wP_ 8IovK],k.;W!us7@j >\( F(2bS .aC6Р8^2I}ҏV *Z#$>zRD衠nos,K;GOI:d*SΐX^4Z4Xo, 1nҶ?DgG|ճP~efE)&om3pGBͧ/u=C ScPknU.Q+Kƹ`x'6㓒Zĉ`AЮ;͚T9DE^ JA&U"Qs)b}Za28{ŽvQóasg zZʁ3TqWVbeۻۂZ&-sne{aˮ/L>6ZM/FLA4l<{on@zJ&~`_ȭyFkn{i龍YIWֈ!Cc~9n \KSR~FωY㉰`@JgٳlqAnw,lXuo$fJs,[oJyF. 2}ۘ2f{RR)NDBD1k٨,vՀ7hca) _v~Lx/S@5@aW,@̉T>4Tkwֿ^K,$m0lZL8NkMPc}fx\"WU }P5A# o\U"VfgR__$m-}Yh|-#*%Z@w"ec>lWp/L/JwWFOLZ+hO/F=,lms>O vG C^$dwTZL V@0o,rf7?$6}@M}@uv5Y9~b$?ԛ+ ,iUP Po䭦9ÁzoBlxeNEJ+RQ`bх3[3yn,rh%֬ x1Zh:PBUg\NloLޞ%O`$l>yY!!.[. XZ%ĻCLXpqyA. 0BvyM\elv\2ø],.݌cG rd+pt[HQ#y cX meMݘX9[ pFOX?Z<=j%JْA!Ǿf =+foJ;УnC vۭm6`OUQ &q6*\ .@ȽqVU{isU /23YY\bSi^QwG WL̢כStH|KW(gNldİg)Lm~`T6<bJ<އ8]Q1r0g1sәu ,ݞP4qs"s+EÖ1pn"f.:CdiBi~d:|i$\NG?pS(h;/$6u#ehOqpL :R6`P9=t`q7ޭpX4-_h"\zuY"T-mB8iO{bֆT('?,ksWSqIn<۳U`<ѮhدD1gD\d8`?YUKjvəvWywgYwVqǺ5:ȱURԘ5mGWd232-c(1AU( #9PY8TZ,O"ԯ  >] 0xQ}F17I~Wz^{(([?J+d˘i-ꨨз@i1 2ѲIw #? V$X:@sԅDoC*f)oݼLp1C>ϘO&!n;A ガ&f֫t"^jb,fB 1@rm|޲ *۳iϐWO/+@ǔJ?n Ș ״..ыPrlA9~YۡO iRYE9<3rej>E6[rڊaY2eIN!7#%WNm !L?0~(ciI!@►ww[~1sMeI5Z",Za Q C!CZ* >= GbfAz="kO:cw\US17': Ȱ9] .FRfVGt<ףw|l!(Q2[.JWҡ)ɉ4 +]E"QnG=ok(icR/8073Y"F,˘ JTc2 `?S{dL@y/K cO/tAHԒRKKkj9?4wn$V'Ͳ|KILO )~wY~z`-R쭡H>#F&b˳~C:D{c7=Tn&RKʌ8lך/=O8cvy_Q(o=}r&/ذRy'kƍa BPͶkmjQjlI 36v@>gɗLnI k-Vؽӡ6KT~ids0K!)n#k}S! i%̑/Wr@h?4#%Xxde yIxOdslZU m;j#;;b1cVdfL?Jg5,{StR0/مq3 0f,I'8=ΘU[ DZ{~%s6I{$[̶cȢ/E%'_CӾJJ-fӤ"<[}L{d$(~OٟtHW1QaI3|UصH??N:oۍ Ax d+e!]R;fk]G[yiDkdh z;gz6IDJtG: &qh}i Ƃ#10 }Rw"dVWQ%b|55w7K 44/<>-ϥõ15OQףUzЫS =zrLam#%<0` frά1Okd"ڑB%jj>[sjrek0+ܴQ+#2ƈXDf%=2D)9A W FX:^7!6Z̸JHzT̠a[\ Q rÔWh J %N6@,!HIOXe }9gB(ɴ[E@Y{jil *`* cZfT"{Ԃo@~~f]Gd9?Ef2;Ô}-o?7j sfe%_ܪǙT6D3_s5J:Ue[ ZX7ʕ&$y絊+_rq\|a 6A,A2ZCr˷VN2npʊ$t}T1¡ҔpX̧jvDfB q/a@~;͜H>֡^aW/ Q/J |!7I>YxߤJ(4pM(&%lcAjIom^_)W,\YC3boMYYF:SyB`rTI]ĭT'[U}@>$?MƝ>@:VuqQn궞̒~ﮓ^^kA_tp׈def (99g2E-WpYW;X(t~"^bҺsu->gш#@FX-.G)gksDkx]J<P 2C̳ ΡXBk1e[8۶kOfI?tӞ1Y!V= -Amqmi Q9(K1D3Ų&Gq ھȽ7]zBƍ;JwyYR|Լ&8Eoˢ;o3y-{τ՘i÷%2IMChFӻ{qD гo_cD&2OU )?J`z gz zm]<$dž(k<47U[SޒB5+ n^efTao QzrTb4G`;>"w(o¤f̟G?S[>\kP>g]⳯" g枵@~ĐOF[nUBVIQ|,uI; 6۞#10y5.F||w"7K5 [א飇EALvAUQr;l'g"gEݿ,4-6gҔ6hw߃Uܦ#nv$j. C bzj ׉+jHv<@.hͯȫXs'Oe]s} GB_]%f}hZRd8H*adƃ4<=i-5 jc۴)MLntv'YgU0c2 i .h2j7MI:;W\JN>ɜ%Ya"NѿGr{EѢӇE( 5w H:2? 0 8ݣ+R V\ 9J 9An.]r EiK(A#BRg6 ?kr $ͻ1?OEZJǃkmTQ+:L*DCndXUlzuUוA񛤋rܦ)C8WM=Kڢ[$*Q Jԩ%V+RqGRS-AM~P? !KpAQ%W|N{_%Rʋ_轍 [!TI;YEi"Uy`7.* 615^4j0sA eіݼ U;h>=״~iHyAbo"ܪ@R4ghb2|‰0 =sY'LԺBq}PJ4AL)Eeax})+OA?l|͋fw⤂"׍A}cCEsH 1izIVHq f>*ƦG'쫽ќ`Q޸G n Zp&X@|Z K}+~coŽ.c'#Ukr.(x;g&"@a{B{N؈|Z)|)Q\/.zk!FQ@,r{1ݬ˰ÿ|3IF0zPGkX۵9h?1Uz-@w*GvxADMCP^ogfHTǮrgUeuiv|sO# 9$r尃8 zp܋v1o8ovJ?kseIJdI:BJ>Rr<|>KL/u.[V͊SESk>NrwrciJ,.gj),TOjJ2>d _t+**t?!ku(qum(O 5N YHaU_aó\2U- YZ