container-selinux-2:2.99-1.el7_6$>d׺xN>?3@?30d$ ( P  &-  8  H  X  x  @  H h     8  l  V ( 8 E9 E:E>/~@/B/G/H/I/X/Y0Z04[0<\0T]0t^0b1d2qe2vf2yl2{t2u2v2w2x3 3,Ccontainer-selinux2.991.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.]vDx86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&FXA큤AAA큤A큤]vC\]vC]vC]vC\]vC]vC093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d06fbf981e1300e33caee8aa3f8d2b050efa644cf7f007f199b2c901486b577db0da136008666de90c3f116043630e0658a3fd00690d649d99d735f9f0537dcefrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.99-1.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3\@\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.99-1Frantisek Kluknavsky - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- built commit b13d03b- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.99-1.el7_62:2.99-1.el7_62:2.99-1.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.99README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.99//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,aZ]"k%u#qXPNeR@Qqa9ޖj@P37//DuÆ0')a~/{ O.peu៿Gepp얢z>5kϸ;EW}|J$9Àӻ8N;g$ zK6+-@zR6W%[=mIR: 1ueoK>ZxڐҼf!ô^G%ޗH*!r8c]\#9{ $Hwcj!g49Z 3qxad1nۓuBʟۘ{X)@Tq7ۂ`J%gjc(X^^aQW;&UU:H7]oOEZk(:"ijd)댤ẏwuZKwdmeRt|j @dJ7@ű~"KOo]M_8wod {4IIJ?1A[>G`2@,e]nHFh{5&'3 YQ+`ӆITC7bwir+~e~'4{; Eq J=:f $BBfTYWKWUٴ޶=s̟Mirltn݁_),νleviƾ2X7mΐ{,5RuR_>I /s~NUaǾu8_ {X1|Sf-Đ+[ oWAς :Jlm%4BiM0F"w7W^I!5ҬU˞hܻpc.xM&{xe*m(yfoq-jYŷ]tz`p+h|t?0Υ2j79w͵Bi؟fEiB$&ם/3#$U z Mڀ#͘~P^M=I_;45)V%(zu.0p~uɶ]qoك>&}x0oz-qt^z Lhbynz˜is2$L™{*w='7 t—Ĺiri4E?|Hx߫AJ [Gc7V!=ĉ_ =9UΩWcb3JFۄ=T) hgzYH$~LC01s}]RW\XϘDH}(5lnv v]{D7yC"]ڂ嗈N/̱{dZqC$~}u177PDyV+SM`5j-/EY#Ruv^~Rj8O j>'q ZL仹6ᶎPC\ &(>yHzµZɑId<*׈YD*A:2s=fAѱ 0;yרS(FwEqF74J 2&̢w<8`|5_&$c5I 'Wmrpf2>YzV%/w̋]5X, ×fpf„Rii19t̂8ް"̯/EbbQ0mIƆւ4238LiOt{:Tp9986.IjyZ5l60 輁1W|a-i9&u~6`M)'vAUɂ9KN0'q)1d$|Pv :TjڔH3јI+_Uh}y Kv7֣[ Ix$` 9z3m vv.T: <14樯sf+a'T %&l-Z[+HDT'omi`:ubNCN (8H_klN>$Ɔy* [f dt5Zv̌O0ET\wC m t=1~4)ikBĆ*>MԀsj0}sӡ"Wlܮ܉hb2A2c`.?؁lÀn=w^蟃UWbf7 2b, TᾸ8̃w00XJLʺ{ȥ8}HzZN2t1reu|PwDWoy=Qcv`bquaI'*!d!26瓫Kҷ/Rp1C4q, 9-t >%#D]WLhO jTJZ|MKY$* n 29% cURmWlu\dpK! 2W\qT1^%X6HӚۊ= =|WjW9ḣHIwMVn Uo|t7GG]2z.(1Mf(uJip xSPފO䛛ŵU(uz![ڛ§^V6\*ApTb7FgŢ *^nK|iCj&?T7)]`T On=zp1}x~%*Aa23Rܻ[ 8E`][4:kJcD#Fa|_Aܾ=@ i樬/Bo!6))bi3ʉ:*ٝkg^JEvP鼣Q=|쩠*!_ 'ҍM EZݏ84,>LJkYa£X<|hu6pק~:Z&+vȊ!˶t:=:V~]%!y;9FOrɥO=Ș{zqx2 p!⺉d|"_ 8rʢ򓵝 x 1Dg(7֭c jb 4 c,foPc]WN59b,4QptEuIb%Sv~qd)ê~i1Ʈ>,2FTT\ ;( A16 \p,hD@^=TB)۞ޕtewμ t}vF!~[b/#'?'kf޽J# xP߼S* v~6 2Œ#qf[8IX~8@Iȕ (`@A$C^F6)XT;umxcﹿ:rވzoJzBƒfUn$Gɍ&6*Vf;p'\ >OsiU|X8 _a# t^O}n9MW};zf~#Q}Q|1~Jm2t4hCTulJ @oPm Joy@oUB  _]8oqO#ZjK Yc| t,n IDWʅ጗$Пqmtӧ7_*i4ޱ=QƜx2t>62$D%i4 @e;@e abclkdbBY}҂c/LB8hBV5,; n@(Tw^T<> PlP=^6^S?dc^_PPY.Gآ2u³Af`L?ިw  9 Spj3R|O2vٴߑR?Bh6I*#?&fN6辰k.04xTrק}4UMͼ Hۍ5Z6?wë\B7fwz"U({{Wߢ?P%g^bu$Ub>fQBqc_/"@6Ǩ#f[)p-_fz15*g?]@uu.G"V̧8'.qdlc0d{zȰյ哿kj|ڦz1^8cò5n*O?ym^mƐQH2h/ބ^ $eUG!I|GM89ܨ@('2ÝBYvoy,*0}wG$#6Z$0 U&{K4R 8qү'6Ȋ6{!d=7lph>:; r /zG 1E)ŬlwkX r?o M>6u&b7+M)iņ-Īg|;w4 !if$lڥBlzhiZnLқ/u']A +ݬ[P0ks-F`7ًn}gm^i5I5Bht˄4MN.d/x|Pu@Xv|_$u  0Wr7@дAPMRF^-i*G9ży %?h3ahNJcwHJbyi])M2={dƴpoSDPJ8<.NF1p8q|/7tF;.]+6P Po ;V$J@-|>Z~V%ə ,Ιr9Owy>*]mʀ~."6;DdY搌W]ObݶM}A|;1Yl\dzcZ  oDJZϰW$,7Nր!B6]8Zsf[IiFhAabt/ui881 p7f`[ fّpCܥeRוF-9Ĕ Ġ{)^29͓+7蛝2 xϹ-;UЊy.y!;Pٓf?,qaRܽ7+0ekX}evg+Z=Amm "_'N*%&wj%9mVk+̟9M ^~ k?Sؘ]`/7}3俹cj?#1<auڬ}K9Գ 1Ù uFgte!V%5W:l^" ~7Utֽ%J$ C683n"*r؅ۦ#Avs8y*=XZ]2$4e kX߻Z&u_‚՝W0Z͙vĢX*ʟPs `aq.lc _mb *p6]hjH?uwxy3#>A$0J{$YM# $\8.clLc@f)OeG0KxLPTdVU3mS/o\"`i!s=}pBŮ/O2X kPlt\4^QUFNf32فvCd󘱺F-Z] XQ4丯fqwLݍIC 5u&r6-kosB|Ra\; |fL$otåQw*Aa*Rz\3{:~W*85tWj2Jgi~j&E/Y`4nFsʗԉUkd!Քz~ vO2#5"W9"$'g\jB(D>bt[Bz#IFw?1jfz,;|IVv??X'L= ѥ^xa!$nv|){Qo oH&iZш/R9 RUO#SKgf.*P zu~y cu(l 5 7y,~Ns4Ϗ<|R,f.~fESsB᷅ȥ]"uA17BT vddSj~ŵ*-"6~/Xh |,CȋҶ. Gr[!*Ic~g]DX#P]nh3c⍲?f`L:V*CL@=[- YȎP"5;ѴTphO!YA!ĈyegKH -,-}"ZSf}[Z?ΏΧs9s:ʿ@.00G(}ZG͗R E7W6k!varA:nl>tPܢJȸBfgQq"_?5So ̝Z pWQAx^JQC"Wq(;|jgI#Ox_jpM⴫19 ^ u= " Nhv!m=-~?USfηH'evp57ϮK*U:J-1<ٍ6eŪ%g$-@FfjJDѝьU~EB H{."u]aqg~s@9QVb'0PvĐBW |EM*D]9ZȺP}9[R^97"r d%\ORdsTy5GHda0ja-P7fT.M.iT8kWd1(3&t<9*=`iGM Uf6emsسtViREԧ$_X% D=5$9YqG"Qg8۠=ˁ9߼Tݷ)%N۔? qy4 mKpY94ن:4FW#Mdj-isLmMW)+d棧 `I1iiʥxl_eElM2߅#[|XyǾ EUO/F$>|!1WkgIP uL}tU)9D7^`GT-Nɺ>gZ=E"{PwLjEcX9Sr I`fIi6+7Ȫޏ!f 9_=` ɹ7pa9_ǃTXU\V be1Tgf@dT#->X@C{ HyvkxuSeiīw|gOy 9YR& p<\Y U{kl5|*cLO{v gR?FYYhfH{LWʏH<,6:q0h2[^2njC=U;,$fO>+cDOtgD =\YL#-WcUzZnBŽQhLRS5bj ]( vJwM N1 d3Zڲkt"Mj 8$Hf0BW*O A$> robBoӒb$>񼧗[ݷM`Azd,a\ oE^ /VtNPϿMɾshbh,@_Di&H#Dk8@{y E0&0_#D@lk:[|/Jo9\'vQ;V!Ÿڳ ř-{hUNeMSYzZtf24 ǕYRt2܎m[|VO@p[u֒(3 "E3.q(UӾ]|lqtTrM,[Nx|> ^*G~N˵o\7I1th =ك jʢK6)Yma*!&Rr0y/hJ/l.{*@J6[d\FD tُ+uƥ7+DC]YVCttu}7~Z Mow5HF$.Xb*_kZӌYeZh֣.g:9VuL]mLz,)i!|uCWw1N*vM%0ܐu, 5 Y 7Qv?q䣿y.+K!$(ri=c< y>}n@  d6-Lͼvrl+Gԃ5;F8E=# kn91MB`A [LD[p]jdw̌i/LUjvtHܤo$>-DD2'+x2 .h#wERʪ<1 ϔ9 I6 ] RquhJؘi*җP{J?p& b= 2,4sQN.u+3?/p Y{q;EЉy{s l8Ѳ\bQ-hdG F(#0+ IUZp~=d塢j",7jсpu^[lC_&lT6DL8?"#F8ϢJ(1Tfs>Ym$&0بQƂ[5騈cC~O'y@oKWAJmIܢ,GhfdtSw,Uv8M*P#$\N(V#sn{lƁ8VÈ%N4obh믦VZ=Zh_FE36j3k-+!ИarU'S( | (rLt`'$W@4vzƳ#-'FϗM,MTy=2`u:&Ǧ;?B+47/z"-X)-!,]~Hy>83(6} oYAW?+R+֪ƅ D]٠PWXojY6j(y 8GIs 2r 0K .T +L5$Lcp[ErOCS-Pҕꟺ!|-rfWv~mMs"%9侽AMVJDVm=IT!hyٵcW597H*d@~jv٦kb3po nKلcR ɤb M8すvGҊ=G.?3%)@G@>(#xsN(-A-sN@n{#F>x=]g0~)]FFKK ` z=ER9uKvL$Z+ ~[ѸdzEb;Ha:dE+O(({Fk@&NG\O]Νdd|]~ϸ403i6ViyTXea0:K˨.ܗNO.ޯ]K619{>JR(U)!Eɦk Z~51LeO9rvIm_{yvW8Ĺ&i KrD3rr[h{+| .?x"V ѩ ñr6E0՚?ӡG:l~^;=;5wXsP+(uQU%,#S!dMmc'5#b W6 e>iY{})4 D9|VI!*l~KZL}>&~[ؖ՗F5$~5Q-/ X#ܾsz`bC =n, W5tq'|OyI+'lhj@{`it_/fSJ=V*bIV b=`2R+=Fj/`'$=z>k3mݾ. [ z0=0-T x2HqjKƣb4jGש#ԗ'@6dIEJ? =8@6n\HY %o` 1kG=n*h)TSm8m&M;hC겤XPH*ejY];T 'ub@YCLF;FLG($a 6 HX١,S95}UV`78Aa2.+zA"UqSСǸnj T%^)*RRj'.n5P-gn>pb9BW'mE`E&GV 9#!z3 #\+d0<>u*<ƶIz-.BZBP)~+G D`ɣ:b3<;ќ3KJdcB,X jӃ摝d.@֤rs or3|/\`o9:v痹Ø@B0kxb [t۹@Rj~zr2r BA BX65Q6"๽k4ÌM_cq1i'W}xk(eщy?EIFwM ~THJH Nuu/&jf3Q궉l`xH>Hܰ}C4ȼ0O4 @$եyriImwr\.~{u،%ed$+2~7\`ʃl'eB d0Ê^$MM3_# R,Ғ:R~*Oh K\f%=<de s.q s`3^BKL0]@(;;P}GO6E TltL°?lbs(@(s|/Q͕%-֔VWZ q!ucc B`h+x1@`cMɔ7p]aL9XHοSD˿OQ0!X)}'M `=ͮ?{ӁۇF.҃R,X&StO)f/v6hdWڀ|sba/4$3ЦC-a+h+R> 9Uk̿|zb9&*D9L'Ck ħ&v%@ Dc|(]?L ZQZ+f/Ļ̲n3y?Vvo\` JR^O%xqs:d|)/a>)Xe(4@* _ %΄u.DP9A.Fke'[l_5T{tn<'o9$#yOWO=S` i}'SrˢM}<OJ?K(e&~ tz%XpӺRW௹%%8Jt9Gcx~kI"zJ<3_[_4+'_u/7+M(Km mW 1~çʪCr׊sg+HIafc[Z/ޏ7"%o{ѩuxg>g^?Ξ&:;=d =^7|e,׬ K:ٶ{Z̧#-Uu{B<[97l>hZ?i }6*g _!Wjyih-}.!}~L7Fgظ4j9mlUT7X GWlO0;qrNFa/Q0Ծ# qw&ȋMj+a(|v88l%Q|U0#n6~yƅ-\%jb؍J9JL9f륬{Ez`jdz9K S8osͺbYT {FT; o\z6` ѡp|(b rFq_cΎ 2fy%%sBDo 8j64@(J:T׫ղJKAǜϳq7>9 ;צ@9ǜa\%6H_d˩$Sy vN"Sx7LGX'_(#}Ez5ۂA3˄+(LĔԨNkx3|PÊ۩hdŲZXmArke CE$_T_fCF5ⷫHMqHke:ps>Szz򠵜< KE)ifVi>z\_ <@_gVj'8Bh.a#n5X q ̽9 Fy'$F`֚^,ޟbXԷۉx-p1;fYLSb8{Ow.sshI-$nzǷ߂7|{@#>cؾnCM}[L?FRrɮe?\eb̚m~pQzŦ>' !nX(B PIzyj)t )jl۳9ǩj2za)`ĬXI |'eo1Ym+YxiE׏lzhΐt ]d+~1X4Fr+{&ZgSҸfҘ!+<<΍ž#`R2`FPd~L >8T>J>co8D=*HeEݽ 5pga;PI2d\Bؑ`z]`Zp!e¾-EO&-v]jeUxj y=@pe/ r}d\ib/}Ra}[`CC䰉]O=)3u$pzJBf:Bqjq%t۔=5pclvSuXB_0ЌĮ:M!7.':@n[@]2rEC`oYrJw#U9ˇԻ(+:?bJZ{ՆzlOK-[bsίJ\LχRگ_j93ZvEd O0`&)8DN!masp&%V,׼;L6=h|J1HU)=Io@H?G*-1-F. JA%"Jy H*)9L$¯,IG,< 2{R'seYԈDֱF1Dvv"B"O> -ۍ~H̼u LV4U'i/QKK|\6n< ]{KI-)XN*l]K6D&y'm}Qu=(ިl"Bʹؖ-{[F/-?Y 3$RvBbpb+t(5; j-gXB \Rt޽;a 8F6 ID&\v#_ᒚRǫ(=/=]ϔ j\#H:bPP3 2vy^Y6E!mrOt`^&qӉ]fxw@B(n쭮]k-"ŮcVwې/{lgr|$.be^O ~0D ڤeúrSf11d3~JEtBu&f5[98ZY\|e39KѝY…hÛܽ>0Sp'nO}ILZ | 7o8 Ol'Ȋ;KD#i('X7,CDq  TK6O:Ҝ\~S$e<}(uF/B=Ie%V-P|ߐ+Lp|)πa(BDf(M>ҕ=Ϗݿ)~!R(׫yzIQj`|Së^LvnK#`0X--Wpsc[{O ]Ŗ` X }[Gc&Y:O*cj \cU/6i۟.#eFۇَ9 8Q+jՅ-G2:j*+:3":y 3/{eȣ*x< 88<֜A~W.{MlH)LȾw>[NtA"+lw~PZ=4l&7޲B^u(4=Gvڱ?8ϏA>g)S?soEH+DgZN3;:沌*|gh`TOTø^܎U ԥ?'(C~N(,\> -BA@5' E@C()W]dT8۠tU21{zJ!A^#+֞)ѡ[Բը"=٬I{myÊ.w֬J_(nm̚V kƛIDe Tq5A#bפ\Eإą2oRx44sũVUQj6y[Y_= uϐ|0t%e"NJV#pR(minSdMS <*O%}tA$ ]Nq*huo / ]z2"oG|EZ6njDDȗsH0L!uUp2hl'VC|խ;K~^UNhvý́Sd@ȈY 5ijuZlS&@}bEe7QsTRF v}O6}}2ZWO!F>CVZfڅ|@*:hXwyw[l`HyA( !c})>,j(s[8j}zx;wQ\ZN;@@bY(/>()ymc/zQ< rȑ:]kg[oE$Y3,̋5:%fQUOA#ܻ1<(=5:6Hr^R0[o*:{HmOdӠNۚ;)zR&DˮDX?zl*t%\RʆM3a&hmzNy0rQj/#nsK;ëxN:POkt3dqU?#aySySPxmLQP*\n[ʙژ}??‡N]lq!4}+WK%hm47^n:1vOJupjJ\ r8Y6*HD P*G}5W|*^>#Ϲ_gg}C|MY3r&|'K(?r. uxT1:ba G%sȶ:.KxhUPC)bh|͙,NhWË6h-naT}ę齘sCO E;}W!m)W=>Jz{w>+7_9|ϡ1O G~.yFN4MLѪD-MKZː7eַO h= \L%XNwHU3x@bK)QnB#bOtU?Wǃ%n\m5]IUV/?*TO& -mf{nF@9c[VsM좘Rz!;gjXH04VBj>?vT7D^U;R8k~)M˘=)O8"3 )[!GbҔ R*0_Zy3gWrG>A&DBߏNɸBRszrI]8L3N2#0o; yL/Rak.%"Ùu>gF "\TD#эTbԏLM!|մzé >}%XV^GBTL:rXF;, C@Q^`"gTh ~9Sis{7ln~G pOʭ ^Djc?"YTW f:%HdK%HQdܟCM MB{ o%E=B(,h%@V2#<))M=i3!vY؜;k(rOOf}2Hl¿K)tZeh+,&m44f o-xuԹUoC8v଍'U'r]7cjU4{ڪTYP0 qx:2 M?qAYjR>.ya1^ ܱ&Ӝ`"` ؙ8d֙cr1TS>굍rq)Y]-`<133uFlL n~ ̠vxhu!S"}q s ;8c͹Յ‹Є-ڨHS]Qr:! }rGy,bvGy+ #ap@V@-[&8b@4Oш-ı@DJ]I{u@OؠvwpII혣wxv߽ 7jm>5uR{Em)P&:'w^dJjHC7##?Ƅ s ѻkƾukbq7S)V)U(dqN J1%z;*='2r~PLuYa!cP ץ@pϥD蛛y`j(a̹LvZ*__]e«pu6)a@G뚤$mfUFQ}i x7چʷ<6+&nw K1ZJ^Z #oO?yx#"$NC/=98& abfvu1Ak RS1 8£A[N X #Wж YZ