container-selinux-2:2.95-2.el7_6$>|Ŭ'FL>?2?2d$ ( P  &-  8  H  X  x  @  H h     8  l  V ( 8 D9 D:gD>/5@/=B/EG/hH/I/X/Y/Z/[/\0 ]0,^0b1Zd1e1f1l1t2u24v2Tw2lx22Ccontainer-selinux2.952.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.\ɳUx86-02.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&BXZA큤AAA큤A큤\ɳU\\ɳU\ɳU\ɳU\\ɳU\ɳU093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d8403657c1bfd05c74802d944abf9ca889a98fb54cf14ece3f642e932b6bf34cfa31caa7e754201b0e717c78ab200dadc65cc4091dd18f3ca15779a22d5d27a83rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.95-2.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.95-2.el7_62:2.95-2.el7_62:2.95-2.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.95README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.95//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,_Y]"k%u#qXPNeR@Qqa9ޖj@P37//DuÆ0'?e@bP"݄{p ?2+oW^JoS _U͉Sl~.;%Zt9,<{Ȱ7jAoD/!Rs4 \e;ACc/ӄ y 攤aUb`"d_@S9*1]^C2QYKqIF< ,ܨNѾd6\2kDh) *z2nuwqbɌ+9W-t@?< HP -鄤Y [d:%=cmG0 fbGJ,6G|XĨ&IN[87,Hvz29$z1 $49v3Qtd5@GF~1n;Sh<.^A.ܤ GGrP;&@bJ? mC삁} AsИY_\.ɮJ<0éP|PE9}nI(S.CR9qVh(M'&>2 W wЕ`8{ix=+L:N;:%h=囐mm M6;yTfG1awݤȽ)Ui(˷OTFiP޿,V%n q13v=@&Κz"pxQ{CˉtWvOuon ̛(p;EcD!+)Wmj8<"tG׍SD=MP.aT]{=Ԕ%U5dj̥xzm8pY!ۃ zg|s 'K GVB뛾$/)C'kfHG;CmC4 IBC#H钮fV~^8ESZ3G_ $uC@N ^m4g8V!|Iu%hF6QR(]'/{'"Ab .5O̲E*> {Mw]S-3!/Hۋe&6do8^ Q)$2]r<>O4us߰^v?'W|s`ӭ\6QZ$^y"cz++;Z3  4) [1ՕKF"0HH>ֈ줓iʐbyt9'yMY]*dj{ðf7$wjn=#*V7$˾,v鼩pC*'S Lhc;9ͣ|O/ kKo_oU+q$/b o#6xt|&m0.6Vn^@ەv:T 3)D7U+7O}v+.0=qA {( 93\. a밻+^SYD,(Z` rVNizz1}L%~*e 1 TQhmɫB'0434kgxYظS͌%J+ndrR׷|n;6A r3\!s/=`CN$g]WKTyZ+B`7ė:wk.L;rwHr} xVqD)\${M[Hm$g#}'KN[]Ǒ9nou jhMH>^M˥1v!Q1x,r(C f~2&l;籲7DF CDmĮ8)83#pbOϬߌv)rh@)Vn9<5PTUǯZ@jV*j,ԣaQn–*w 2󽢒ҟU!V'j!%ua\Z*“PT5S. 6c@V.KXn񇲋5cmʴ\L^|4gvdfX@Dq6E>j]Ŷ#Rw2A:'bS5d?_zO H}a;4!EH :}z┶>R6VTq P*my8W̢VKM  65ksatrT~Uߛ֛ZkMC a(nWiPs+㦤BDFl:堵a\xg00y}Z?`BumI&n⡑rA(~ɃS^4(v-E~s@_=mZdRuq# /S(G^Yϫxᳺل8g-j-By3g'll|r&^" lI\ qX-" ݑSOf-9n ݶXSHǑN@Yt32CHpįTR;OB?ܡS~(+dO Pɵp' 4lat$+Sɨ|䞭P{Pz= F)rJi 3Z`h_#-y8>h9`+)QˁŎrEmqZCj3%v{s]}i3mU@~ٞ*]-)خQ6:N3Zo|7~ZLNr0JH+0gUnFq`[ 2Vpg<`\rn9ɳ$E\Hm4&c$ e3߅qb^F tGȖgQ\Vu5/& kT GA GJbjzMB 0bHMNJ;)e݄;Gs3W%bj&[mi.ZweZ'~0jlgw+- ɽHe‰:G鴵LQC=L3rP9}8-0ym:̦Vɋ%lJ#]ߧ1{ۚ;Z@S$Nƕ8Ni8 (8kxc>?FvU͊&.Wy$gB gw@,o(6OVeRYPMƐ!{؇`opN\ U'tTS6j; ͈Znh[ e(W-}|0v\T/y_. );'!k9:3;twyS%LaQ}']62 yt `r?Xo TQW#_*boE!b1{w1q_R~6|7n{ܿC(fjiFNɡp~hn n]|1ΛrBO8eu+&[)_[[WEZ~X2ҿFdT!{sI ( VUsemMXw[T; Lh`L5|( N8"zHJEY77v&w6u'{-FmVRM p`68nuֺˠAڹ,A؝#p/ծ թxgk7rl=|-SSs,yΧ6vUR OcA9 yKģ z=J%˸hrP[wPmRJzz.՘WXU\A6k~ (Z!hHFqᶍ l1]mUh =&t,l">M8c0ںYK2l ![sco dRRvV~jEWDv49~"(i SO+Rٳ WFq^8ǃ s1x7ڀ /Sٱ0~3Y<8VܘCxxWیA(ϧܧS@ c2$VR@v<DZFCo=L(b1o>g!aG"N D/fXvPXwjGxÝ@}%iYJK\(,!W8L&19*i{!^|hzm+ ^`&<'3S#qgO!Ow|ܤ}(OQE+˲ "P#*;b$s+/p(LC%Q>zw,ucpe+^_L|PUL'r'} ۂkiCy\ &<[?:.iWX$iXt;I#][ !DMNi(~ȿs*=DZ;ǾcADy/$a7Prz+B寓nnd¨WoF T{A"Xb"o #oIl']W w[RvF/>p 34߇^]m4 RAz^ ӳen&Uݔlh$߃aP |azl6հNa+L86eQj{c~Ɉ܋JH01JwM7_R*X_jZ^6*ւ[.n:0&Հe Ǹ8?:'Xwڬu) ?uT>}З BJX5>A((ʼn` *BU Q{v>hnV(Z_: ӛ%賶P4bq~9և_Y>@iؑS@[6 ?kz kLb; uSi`F4[.3vU*\Qz8N*b5)BPv9XQ&#CFOH 4ywiA,nUٌ e_#v֖6_Ɇ!7Lam N !(ɴJ=KɿtȂk7,edyk7e4+2X>dît/$_ɸ;hc<؉4NcB*^g B?/"NHUh̡Rp)QLGRs5?e0熗SY;!M wc.-ՍH$pl$k4\%@KqӏjPV#iۢ% R'fq}c򪭚h35v"QI A ,TZ|S]MBi$ =QpE 98h|p)IHcD[f_^i$gZ9rW+*9pb~RExϫ R CIZ(jpBQ&QZPFC0ި=-k!d( @OS$K_+/Ǡ1ҐXAxC'g!=x#AxxɆ[^=#54abeFsƨhd ux `}fLP '&lAx1b$Vz>1r~[ʤLM}*zߡYB(ݰW>H~2&ιZ)EЎwV ϫEȨލq+nڰvXr ! M&~ʝ AEp-HUghKM%ED1"(WkڌG#I9~B"foѼ2h}&GT:q@XBEZt"=T|rt^Q|XiG&_%:jb?7@*"|aqҠ9yzya2J`1T$IE-5ƤEJ~TS$K|7V|0].9ezw!mEf~*|{u2q\0 A1qY0˾\4}w _!}/s4o$Lբg頷WPiL;T`UU$k`*v|VBZ;FȦ=Me]hgut!MY~5%b֐ )8f:z"__$CW VIe;ZD9~\6S'St%2`{NAxzsurx3p)|Vl;ոN øYn};VA?HkO D;gbV:ݑJjq5NqR6+`ي48bQ t+Ks<9=SW 9̨8^ݳ"),L:W/Zh塁j,#Y;R4Ԫf6D D(1j&:v(K!~5} *7\L?qJ‘$Tw8s)mHMtw2YsbB` T{% ~.@6UUJ2X,;*oyXD5,=V_thWKL'ᨖ8S(`ĺ(iD\3oHQ oh+*]˛?Oy/]$qγ8^I20[,Ó$/A]2zJ_O-#<'Xn{0\u;}YdY۝ˁW6$m@ӜjRr7-C4c}Ph fȋ[&qy{_q0!jawsC]WGՙHqQ&m7W CHhlL+ȶU?<2 >z!zlrIzk$Sle%؋EmT1Kcg Q v . k1bL_ 8y߄TI_'ҁ%G\Te۴GC_*MK=5~#ES-OLn'O ?׈^fs3Cž"J"Tpe""@&,vU[綋C9v0E1gOݶcj*1)`qnwoϛnq! ɹa7tSrꋡ5 gt)N'B y$nY3oYZ-"6`y| i|qzPvNQ |*p]+}pX1G3U3OKQMdmQā9 /[ˌ&.Xh!+N(6#\?OWefMMA-N rYnd1A9)JtPU2 :""zmU;ߥ)FT2΄^4r$ 8B4WqK%$x5liO0NOdϚԂtVπH#ep%>KֳL&֍$/R\ێ[okCXL2IBl&A,~%Zbf~!ۃ._y%ڏ0*y@bTyCWO~mr9.b2p&‘w#tm (c hH)pK2+p:d ҿ%٧Ssdj^PWt5%d~mCz#~4&T4*Kx3+~;^j?든Ev$"9&6ú+u0t)};Lq>C XؙWS?uR T A15<032ILLP0P?s8sfBV@VhbAC=LKSKb0 <%tٺ- .WdEy,ô^?"5֧0 1"A< ON"2}8Eh;Yt6SnnYy7f@|yUhfp2|-sAN׏åYvq.n L 1Gpbz'N_:7L{±j jkU\7jA v9XXYq[K`[ʾ%?O_W.oUBS{4ƞٓd֔avEFB(D ݚՓf4Sz[T)JIk.q-+tC6Vx4MqGGlbqQG+}J1=#`*E&~~;ђLX`Y׾MTEf9m߻&X_ OZc3RI~Z =$XA-(תZ?sSBo o|/*/jnhO87xyI^vGg*NrwX{BdMRouѧXzeq Ҷ6kMwl W,I 2(/<\$ɧ5*JF78MmAԍ^QYh?vJE 5)Q~4 cu^=KWR}Bs`%GI pC 4dHS[ Бxjx%wAD)G_|hsecMh HVaJ{M%\( Q2 pyZ!@kOCvW1)@ K|24GeaibNu88!}8 8{s3đ*1scQkLv߀D"I3ߡ -!;R E՛G]c5aJ YXa+jT84;+|j躯!X,˗'O*ȫӷ4D+$Xi0+c[CO"6n32 sb;((&k=ĸ )0q*KV88¨Q$18¹p}C inTu@\{}>Py2:nGF4Wd<lڿ63gRbc(Zb\mQ.jQ?ƛV:g6֍#C@ZVɀةcEv3W@l[+C=ZY )nQ[ c b`ˇ`whPڈ'o0+6iځ wi9V$ʋ/pXLx4f䨨$fUodPYA+[\8zEԆkƏl]up/FT.1"O@sCZ&6L^G5so@#͌~8a9B a[SHd`XnXpK(4e8Zsh!|Y[1cUնJ˽̠=~S"qJ3XpFޱЍsj?cApؼC%dz׾윊~:Hrkpӭ>yK.+|L* }z.;Ijy k'K ii=f|<$8\ ~O! *)ƛBy#"kJ2"v CB-xM_2>bBx EA?m!nÎ2Rt*W8T+-Mu@.J!SRG(cn>{UZ"^T6@*䛡smIr(e6>QlԲCyh257u4lxU k/l} B̉DvF+?#yD w큁YYaY  .&Dꑧz8 Q}:+$2IњB*aw/=_AtKbs4MI19=թ]shRt)m3m pױhqVfV/%_%6WȦk.D z2IvV5ZX׽xNֳ1Nb xPs@@^:f ;6a&z蝻Z"‹ 26  Q-ϼ%"ipkD6cېRvlx[!njȯ1Q{j;:3ny&_o׸XN&v~ݽm{dSh >4"Db( NNH}OكVR=?(kCI,P87&_4Fak>9HX9rly*¤;?=3v~a @l>\<49X^tubaU^XSG+k /LF vV 9X}i4uS]ԑYr}H\ oM$9-q\3e+9%.PY閺]e:,bC2=0b/P*󆕠јOHZb'GӡTD=>`aJ]bפwKaN{ S* ވXj8޶ۺG+M%!# QsלC 0ԽkÜuY94DfĴvY``τ1٧l$j>Kծt>\_%HL~Z~hR~u2H#+E1\%>Bt$ΜO$KË^cWb`Nkt3e|ݑw&s&˼'>3~252O9&fTA; >\-qɶK\I%s -ڜ?CNcCr uJev- OXؔ&0 ẉ1 'q[Ph'wjoWf\3<,%-4>2[!jv߂)GG'sp:S>pPm W(aJ2iOFa0"eѽmAJ!]4\)(I/ԗn&V9Bwդ1pcٞ/5>,yCCgVNM۩棑M8~dm"њZgYW]WE icr:@ir "75Иl=y+ @BXk2Ɉc&$9\L4\h,;أ̎c8^S5Ps1oP43x} vǰbPğu1g{am@ nJ. &|p2K$ ,Qp뫢42~F-L+߭Fg ֪6<;ޅIkw|#r"G. 2U1V2'jPεNXd+޼H?͋98/n tau+n.Ny 5$7VU^#)aWDPbh4Tfb_c@vXZ)MMpI@Kshk![q 2(6GTfyc]@ՉQZ4}ľ(3v. Qᵌp]M:Z/Y骧.;9Jt-Glzg~L0F$eBjժ_lߊl[L1*1Btƣ)CoZ-pX-X WݜlqEq}Vu8?MX qN_GXwޜ -/^5iXLCiñZa!WCWw=k?NgZҺ%=wJ+^ƇAݒ{'Y|Krӥ H~8i;btz6YYmYXK{V&8' 7jf%JHq[}V:|GI; O OP" xdj O "Yydҁ#ͤh{}ygmN5oXE=tB%#tH waZq߾JO6CxzbݶDr!9֛cOxiy.#:8i C,f|Vy,ZJakREښoA9x2<"zC' 'a.q JxI9b{\O/v*]} #rS<<|) )b@P B3DZ?{7;'mfI E?WյtEim4g!V(O)7T!TlK!3[9A%~1vnwmwc"ӎ!4?GFzec7'N%ȨnB WfjgWr>W7l|nAq0 !m r`a{l\5*oJ01``RQ /Q}ˡԀ.=) g僘NbZF8W?آlIdn#V8eX3ֽ`|A6":} S[ `J4IS0-\2@nS=Y bB6 t옋1BLG%iFVѥs :ڼ(M#w:܋B/6lR-5TGᗳh*?[{&ņ9{_t+ޜZɄXU*Q5eP^Z!sXvۚX/w;V=I' Z2s^>a72_mspM:Z }W c-޺\5"ox%Z|ݏ&~<#QIOsWGA1# !^H#l_L^p v:е*'e%-Q$py0o\  A~{PJ bOgWH&ZyNsdI5*/6F3gEX(tkӑNmbWk-;wQ.Y?Siܼ=2FG&]`@ R`+|[:BĪü?qdPp,XyV9\Q{^rV[, u&W=)Vլ:<ƓlV '{?n/MebTw3fLPIXz9塊^KWEΒKp^^r.6^۴ Y g9C.5,X`c#܇K|ƍ4fEƠ'#Z$Ӓ#+` $2 Y$l4?{i\0Ke7[ӺTJbRzY+9]=;E!'?h!޽J-O'\~x+Cy{{j)䕽2ڗˡxN|O8+M7qNirvۦKxtKf qA%?GV54pU79fMmdXٮ-40JjfyBԒVm%{ßL-`H' BfT>F0ˊMy.jIHF寈+RI/7zw=MWui]FCzGܤFEM}Y, 4Ȼ57_#g,11uXUD[!+1B"{LSODWhlwHL8lG B,-L?ÀXL7|qk6H8/7^YnC϶9-J(_YNt'&sZ?'H|%8jzHN/"љB8\&9X@îF8SH+tTEη:QQ; ÉP?#& A2%o;#Xe{~, F ubo, Ϝ&8mhctRXURz4ҙ 6I،o<n+LOw'#1)LzkW=c# (x{!k@6bsH=ޣfQWh38 ܗ^aj,)2åJ Tʉs+ܜ];!S zKr30as˶$ oC<@WB^u\޸5BhATd{w2Cwñ,.}\]!:r*_.)l@[ ~)ڽ!ҁԧ943 _0 }ITrDvV'~$#V6$& ճMqsfBxvy>~nZx5>UaVA.&;,)oM# 1aj(<瘡N =2ipcj(Yw(qnv'slT}>8^MG(;@,^pT',*xQQM{A+Ȑ J@hH6v!<@jXF;T銊z)wlj~a]5G<CLZ*O!}ͷRu'#htKvzߥ?+H3zhk͏a U#ķJ K)*7IE:}cPE co,TElӇ$_Bj1[ ͐X^TK]cXtݥc嫳n?ڈv]͇y>:H>RoN1n fXH @ 4}㚂5%Ma#0CV{2].Im. ]- I8k!۩o݊-4Ҫr5Ta.S7MM <'/5gz>_. Dǯuў8HKM*E "F0UNRi 73S_gHe連n e03fhIVvY 1^`z8NyQZsQ\J֛@gQlq aI}>bruG)G-.Q SeȖJߦOַX6h(:M{,Ov} 6%GIܿlLlXʬ2l0Lfݱ40_Z;6ٹFgQ+H$$.",H }[<))g)8dK+0V7$pE`ֲ9 ,1Y@lݾaSDFZ]č^wb&q-{IHdߠqߵ?ŦAUJq߯/6Y$LT!Q@jv4 A W( !U!."o [UQuTZgJ/w?ơn`Ƙv[ҩ[XڎOnl6涭r ;HW97ՇX610l ?Csklӏ6_]pӇA:`&B'"tL6sQ{yNkF"t΋з$LFNyK9֝]cxYѲ҃maEm ^'KB(#V)FXP^R~6AAy'~kZB0wuVKW F|w=? _^%07 B}VWݤ$kVuikaq)qe+H6𨑎Qej2I'A,NYw}'& |UsH"te L;  Lo98pK+?_z擝"7įL*fk3XHl)#g,Hcw:2)| &~1ށ4Z/34PZEБ D[Ğ-xryhBQQ.嚌Mhɐ\ə5PymLoX=VX֙Wkx-|cVfvC4fBԻ!3dZ%JA+ϙdɧz}+nެ /9zUh__eϼ| cX)X%3>_ ,"`Glq1V%:}xʰ㛜z[3 SzR1:@ 0$j*6| -yqQk,BZӬH8Ϯ xs'蔀a82WmUsœSi"}KBEѷ?W%9,m)3H0~3Tbݘ@ii/tFfպ b^{f7jEúקuA!S0\0!(̩c6SZ<֔n}{4-0ci~+% :hCpcnVq$q۳CP?҆qF ](;lͅ_N_PF anRG } 1vn<`+pY?pJruB|!Ւ=?k$B9ޕy=gGBJf+=/Nn4==U}5!)١V l͑2:.x ~TF1@Qri,%K*of&.YPL٥ёRzfM~m9vRH]r6v*phajkM? R޷2FIFiPm aJMO'ӗ-!e<. ^ϧzĪ@O"ۣKMc.M 3jppIzA :1FDQc%ГƠm 5PX RrMx&|c}p\M4Z~c連o]E_F?g:}gB%Jf +ů iAi c8pMT_ṿ")U[*`:""@D`f=D7Au7 r̹ũ$_S:P3Y!w 8Ԋ Nv[wbyԌi Ռ\KN맚af3R#AYŗuReLS Mh-(JXV[QUqS^=.0bḽрӠcoLORU5 rs T.U 0P5;Y0~ +w<0l7ibZ3!rm?=[7w쫸O+ňܰ N|51vE|7is YZ