container-selinux-2:2.99-1.el7_6$>̧mSɖ᤻>?3@?30d$ ( P  &-  8  H  X  x  @  H h     8  l  V ( 8 E9 E:E>/~@/B/G/H/I/X/Y0Z04[0<\0T]0t^0b1d2qe2vf2yl2{t2u2v2w2x3 3,Ccontainer-selinux2.991.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.]vDx86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&FXA큤AAA큤A큤]vC\]vC]vC]vC\]vC]vC093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d06fbf981e1300e33caee8aa3f8d2b050efa644cf7f007f199b2c901486b577db0da136008666de90c3f116043630e0658a3fd00690d649d99d735f9f0537dcefrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.99-1.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3\@\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.99-1Frantisek Kluknavsky - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- built commit b13d03b- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.99-1.el7_62:2.99-1.el7_62:2.99-1.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.99README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.99//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,^VY1]"k%hĉNμ5#+mz qɤM{8ҟ"H(4Uqmچ#Xۢך__]9 | 窀Lvƕ;Yx -Xu楏v*H|U|%^ XIr}l'ط1^ݎm߆lXlKnwI ['io̯ +2Gp#!cB-&wϘ*+L1tXRXz=ғ7'ޞ4ty`4\P;~wEt0. c.lr:f(%r츑͗kGnlK3ΙMOX {OځS(;' Ȏ[;R1F3YJ I>@05?KJa=kE2 'ҥ[iػK@20٦̙?b0YDCBBSzI.yæ+e@[ CӶo4vI[MZjO5ӫRS (WPs~6_N+[JqFQVb5JYiCKH{S;'tRѧKGypwjFA0zz(TÚǢ5DRf-QkK\:TqoC0ayʙTل-'pѣA b9_4_'C!7Y ,if,\j!ls.8 22m+ =^ۊS/oX:p1 7SȜ0ˁQh!4r@B,*`uj'駡#ڟ|ۗkVGG>͟E'ךz4he{dNIaZ\@nv'V"I&N<|P+`-Izi:.u:3C.S%Rw $@A)05%l09HzFCPñUik1dnjߴIXX]K%~Bh $Q?ٗBlj*VYGT-$s9DCW\@K)e8ps_S{y$$)F8Hi9dhK>F#  sHX(Zs(bF*I2ۋPH q}s,? Ryejs gG)O 챾ɱzyv &H,0~ci&*dTe&4^loZ]#ͅ{3moO1~d\5Y|"?7(^ot6_J* 7q.q rvӱ|YEHv9_+Cr' (y#$zGsWUT<7_qZ#GHeQ)W>՜#KԜ(=X!f#"@T!m{!{mW^+E,Cټf+Ygl"-?u3ģ;fj@kzJ͢85L8 :-_&dN#a؂EYU }3`HG2W2mq)P R m,~A74V05MR" %}xfNI׭U?XBDQf .S> dI.0a N[< T_`]+)5׹ 99n}5#NDpwҺ/%z5S>c+A3O_jR*"%6n%F=Q"n,yONRbiy;ͳSF؉Kn!洮G芧EX5yyR0O2#( *$F؜8;Yq;a|~%XhI5,mWdooٱC k߶o%'bu 떄SBgWs 5¿niW)} N,c͎ Iaݔ]&?W-6f3{XQuxrir5W3PΛ w0Z*4E_w\:R}@lZ1*1XK<ўhD1FPO6%N I 5/6#bk?' 3L(튳G %J-$F둆nG##Z 4=p"L}.dtXC^>q|gV^hȃ^t˜4opb`t3PN:icVL'Wk2@ 2$boI[F{āq >{$7Ƃ}y8Vz5;O5SIe_pWx;J@/K!:g2I1yfїۧEa߭GWpp3`dGٜ'Ũ x:U sZ:<\EX{ y,ߋ {OK2fmwz"8^ƎZ|Bu GDn`An>MbX,:)+OSRG&l>ex.UQ% USd73;:Fah>obm61y*Ի>_mt^.7{p0`,@U>) Ogd-B={f?ѣEt[GD2w+IVoӔdJN`j:ih>GD|,`Nwɗ3Yxv3`8Χ\nfPrQI |1楢+BE[ }EJH8?cs= Tq$؃ Iq0:cgAg/ĎdG5ů9:{1U`P& I1#>4$d >3x9mImM"$EQNBZ#-o pk3BLm!kfuvg8w=D_ o9f5R*A.H< '9{bK@pDeo׼DqlHԟR ͼnrC*?-v#I) O~r5.<.:T[ @d~hV윌%י|kiñ7Lc9L q>dP[j@- WZ-9M򑐰9 6iD3k`.u 敢 Qo~L9xѨ/MjҚ\Lcƃ4HzH@"F'@*] >ݢpvvP&.4kSտ.ϱ{Cd"_KFu58wV>m_aO+;(D1lI8s% ` s0/ 6Y[۩\); 8yrJ(vKN'"=m<3#䑳gߤ+3UUXve&eDItacFIhy9Wq&)N]WZn­!Ε& hx;S:0V?5F[[r,sh٥BNt7× fk p3rT+gmsh9 aSP!|8W)K&06[܂ҾY4}dTUAҤFtR\1u,q8}?D伨 Vs)^$!}^:"!T'g4qj,z`]SQG ,3-\ ט$/ P >s>Y;ZW`猵}j'A9qj82Y0ʴaǢ=JaDц4@ aV`홙g}T=CIѯ"A KWgK2`k\4q Jw1ΚxNakv|kHsMGߐF_tJt˅WV' u@"."@XJ?f6ݭٮy2>/vzy9u=T,c 7ۥ]׼`O% }_uIyWq/wEN'$ѡO`ﱉJiܖrL>68 KldyTRIC[`%a|9#Drnh¾ީn;$ɂ󅤥oWܗt«˃N:@:o,2Sd@LH>roC~Ϙ/gum$ȳaCXp,zVo_*(/~$8񞻇ŏ󐟣L{y/OƦ"jK /|wH[yh?%sYF T2$[fs]$Fב99bVJ*rq%%ZSr* aбԬrQ@?qah_MKcWhlĨfSJe[E "ݔ˭= E6HQ&)y׉D:D;SVU )!NM?4ʀ7͖bJA4Y_Z.[Xw:3|zܽ\7$n2,$ XX8rx7~O!~*\$V.bMqi5/('4};xRdNàKkǷR8HvBVct QGXe3Z`P9It͡3X wK2h@D5zH s0׹ZO |z[Գ˻U4I}ԨvQm&_EGhPOe o-qEicc:!,u#b^1ǵIuj0O!8sUvDug([:CXzH"op"cw[1~AĀ=븗%ѩoo~gYn1MNeb##Lc>#&D+0d2Oy}=F:oVh)iG~qrG;=T66LN=],M 9 hLSWj87T ViLkzXз)B-{.Bc]YZ]Pq0wil;K..`i;Y9oQP/jDPazj/Yv/l[ ߤ{v#iv "6]R|PKC1PT 39Ph^t6NBD.X3Y=^KA=53w }6/)~RC0 I Z ?-{)*5L,Munl|セlQpˋF}<+<8GǑ1I;Q{OksiYQ5#K)rpd"nimJ[4Nc'YF/Ycش77V>XX{ƵW%ߟcR^i)F0ɵwY2#1x=$L#{1T?#۰N f]*^݊G\A(rrb"2ng$𭴟!MjG3w#I /oϒ~aiGV,r*r4T!T,W~[>BՊxJ`Yͫad7{6(Yc%LX$OHQn"I*"9UeDSMC_"^W,"-;ޟıcrgyARsJMPv^}Qąt;Z„oaod.֊ƽ~Kw_ЯMq=> fb ^w~ fڕݗƈNӭ%^AaWꤿS3-wGTd`?Y\"vlF .ŗ YfXt|VABܻjhRFT @4sOɳgH LD h7SжD؛^롭~56&QN$Ulb"VAǧ $Mktl\kC ƛ?Հ㤔R }SN+P7]U2qc ˦뿰4QHy ~ 31KLMƧ{K2xe$f4n:JpihR9X,U%osԴ 2na~UrQ38U.HbNSCLd m{O3ES(ȒOy@5X ER,DWr&r/)wv4:v-iעԪ"בB8c7t{k3pl7snbWUR[#;;˓󗣎<[C%O4 v[^X`Ƒ"1t|J `-]d%%k#>HŐ3 a=?5 =pM;5\-7 SጿNtq:<'*婟5@c$N ebD9E?Q\6xHYp_.PPeauuĮBr| #n;VJyUI.o汏b3(!{$yyo?uGFjN^+ }UޏCbБ'Gff4;v:+Io= 7o"9#rIT9X7]e60gM7wԇiGz ' 4bstJ=g<ĕzplae&Ybs4\ɉC@8"@Q$O4);vKd.ElOk1$\ Pv>!Tޫ_kty>`(53e@\FM~%qN,T':0YWiV[R"Z /US\}ϣܵym afoǣRNR ZRbbE9jWIL?3~N[ _c>j[,/L]8W:H^Ud  = :g{pZ.Jw%7#v% r6KkxɫNk܈ؘQ[`r, QtM.8?#6G3IΨ _pyǖBuI@ ]%U͛lPWoxk8 l 9*/f%|R*@OUr·lʋNH׹H3%DpMȱ19jxuaHkTRs ȃF8=:SOf.lU](* {qP-YkV O)Az1w9 =V hd-KC?v0D]5%EW1%_ssS e.0>qaDhf [ٲ "FG"e&]ظOˇŸbHT+ vE2FU&139^5ymtz# ӣKJ@ v 1SG6 HĻ@ EZɏҭYM "8 ^°d)0u-IIv/<<ʑߙU̪JB4Hb+KzLq_p/ǂnq@S}|1lW_f{arpQ1)٤,x40HE&7us\k.c &1[/lGP+-QI>͙.7`"A&WGNRMiq;CܽLX׌;C+dAn900"'8+i ~#XKޞ5 e!0ȻǵIwueW^EL^cWd25߭5BD_HٝV.d LnS j 3]2ibi-wX@NAQ4@m?uj2b V-+HlUD10{>eBAX#sf֩VY؉W@EdHl0PtPX;;מlk,h@m9P CPd7 2hrQP18cUN8cЪ?<@myV;KrRP Da(w+3L+)@@( %UҰl"ޘcFLF-LVF*Pofў!$oމxԚ#RX"}q3:::E0my '=!gGIrw0҄TU N33VHΪaxEe7% .J FjNuA! d.{ܟR8"Y:Fk@|fu~yIvtUq@(%ߤ.<^w#ŗG$?+iJ1g$^ -&@O?tge?Ȥ>$sc8OpjֽRܲ1d 7k=F9/:dbXUP~`-E:8ʗ(GЧ5=rl٠ȌcdPXۃ5:9N Bݒ~XX7S|ՅwYwI Hz_Er!hv:ЌU#~o!*sTOKmAvk Omٱ5]Ҥ6sO_|F:( /$a1$VЎ^Q @AQoTw跟d&H^rDxhE@GIԷ7-K?uvJTA3߄R 2Hጪ%9uCICrCp&gmcLic̔Դ:kV/_ *Gzj/2(Y SǬzg1qr#KE^yHF&tڦZT6\l!g1Ps Y\.#V>[ YE^^V_ W\MkJ;":QƠTi)%ҕMSn+!Ni/m@ȝp/fcƃvm8FzBɔ.R:A2$,4w0Ka chgGVLsost ,JۋN \NPJ|pEc)'@8tuA ÊZ13eHf{;W,EAQ [AO\}^q-@s!hsw&,mᾹ}J?)o{w0ԝ;૚xEp1*u #{dAF҂YEsR3cP&)G78[%4_mm@3fj7B0Wj ucS4D該ݖ(dq 7_3;^J+ɇ,b=߫,/4\[G*rKwdx˱:Vb*^xvmBm`4ڦ~d&ў];g>^25DNuy̾rR7–<bFJBa?hJoH$T":To:U[65ƶ+Eֵrag%1;ca߹sWgQXu\y %z+IOtF8Pˆ\Χܦ")xm,%X>oxiu&;j ;i<̏ y,<2|hLw틋 )x"-T_GFBMk|V^ 9Q%s{=qb]l*5}G^(S7eQZfxp\O`!)!~^1b{ r|-5{VX/3'a˕ڃ7% dr~UWAd.ٵhmX+6|_aA`eLh+0RsB:{ݓCp2z`SH4KF<#!5Llx6:8 æ fah``da3MêH.NXa:әPO+pywWyojR#{!ggsp aBx߫ab߷6}UBQZ&~Qؐv}jGLjlaD&d\ٹ-&ǒJ m.+["_#9* aELX0̡4 /u28q(sT˼G0"jQ̈́KqbzbvffwyQ⪱U6aL7V&%.4r9-vò:Aw4gہA Hi&Ctq"HZ ʞ/: ,+lY#̝Bߍ+qk=&= 'YyG(F$9}lɝũxYL<8bHɡ]LWbPRU_eHVz4uϒ_7VN2눞yYWGc\tڭ<'|ɓ$U$Y01$7X/BmjeS*LLfۤҨcz.mMd*TO g4ЙV=RӠV_JEw{_~;1!&(ӊ±Ї^b8RǕ&h"8(X4p"jnIa`NÈފlzVb1֙ 3~NqMI^`{ :ZN@֚$PޚıJF `C @Q@峊"V[;)(q*9r<-u^-1jB?[ bGpm\EN9TnZcR^S6yަx`+t=b"{/ǎrtxoC`4C ;EN).R ?\CG7*|n{{BIY|"$l =vN7 Xi+>vQoު=Ԑ~U*g D]R&RG7ԇdj0H 0?+coIO5=LRFmj $($36է$0E _|G]c:RsH"?MOs;1,BݷO]e ,ۉkFD²{zzU G k')m vԂyq4Y$, ~l1zuQI}Ds( $*N8m,;2)ic)]h+&L=y:X7VTB"i]c R pNcGhm6툲߳aEEDvҜ_{^.x3}lJ &SalcR0Ͼ/ >hI4#X屋ycSgrx&g$3',#1R@[jn@]#_}cxH cN|ayG| S(Z.ewћb[׿/5!qT&HRm؍MPR)+-mdKw^)# 1ׯ˽jߨUCnMw\J)PN~e<ޫv{\LL_#B@P鉚RvGks$7( K|EeN]a4`fk'xR6EB82+-fUQӯ-73/ '˒@V@p5TŶ)ͷi|A)Sn\HZ#$Mf&1CR "hPs1'&ײGULCFٙJO,hZElj] j,h .G?e]g-deRL0G:=GQP'R Fڙ ৫*-Wxc+`z$%C U|0GzΝ@)`UıC ]<|UGQ݃<%B/Ʊ^riKv!6-_:^/S[k0r,uqZؓ ޔmAaSֵ#99.(վy>|b"qSO}uI&϶}Aڑ{uOoU"<^Ar~j^E]x!bIPȮ3X;9qX?T 豝MٟYy2սRt2m'JK‘|23}VsPn`J%'7ד:˜pndZz $i?6?- x A`Rɨ&Rؗ0Y3j,)mʄaEF'-iȴtJs,=vfx=8,Ÿe1x^Lƣ|eo9<FdqChrĪ }^p^Y4ƿΎF{ƒ Cfrľ^Z^wKָ2RC|/kAPN餴7-ہ{SIGej(Gw"lwF,OUR늒vx[HiLQʡB"wl$bFT'F*)6 ie|@*[ O|{J'vAo>;.پcuCGet;= ҙ>umf>y^oFN J `6wmQrzޗMlcjv9F=\j;b pVE_S$[ :f_,uV̧vsu6Z=XIqhu2z *#& s@Vi\)9ܥ!q K/Xi+44|86ӭb836pS;iq]&*._,";u楪v~&~-: ˡ>7 h3$f{蝆uuR}+Yka+G3!OU: 0hU=rO ֏H/M>*d㱔]]|]%6.$=HE2}% NFb$Q1IX~e R%TS~}^!/tQ}zPy"O(]U {0H֡{[MT"=Xc5ɰjxiJ1g(axl1fKKgRgi_oԸPa s4}ˆzOVZ=se7IJ=X57)9e[$oK b:;'EٱC_5ٖoOڹdI ,a܃ǘU?:43} QjJvOq+'W&`?ۗ4ʉ.Ό3g>\}njݯ$@p__P8oLR.ef aͺSE OSIGF+4Ӱ~KZӤX.ĵϹr=yq$F  1KfF!B3@mC<3/,S/^}^p=~mKB OâG]&*u6SY5:c1 -_}hld\WBZy? D9*kHU dW9ѤED{m-tLL|q=M[#?ks+dOyvYx5uWr6s;hiBw'c"ll{Q(v# h?v!Dru:(k{AIK>ka F,Tw9@D\/%F8)E U~|U&ʖz*5^Kw|FJ(3YtbšC:w{2*{GZ0`[;N7CxEEB@>) nw:up]j ctQ q^sV!@]>&Z% <338Gpf:U$OG"w w<fM.v ; XirAXE&X0i%-lx{!o,R$+f69?4D|c"9dAsӍ< 7FR 9]Lå%:Q(a3UD(N+&(<@ <o[n[-y<.n5j*FNU#©>'ftxcuL++5[$١yy6 QʎOZBFЩEohت;FMKI ^~rŽDn]9t u)nF)<*v|K4})oP jNg|#h5H҂f Ye愬H%!*ut"U Xxef3ifrO#ȾՑ:q{coq#HMJ_,GiGwn um kkK4ŕOr>яKXT6 G uZi 爎#~K^`LF?= x4;>[75N;겚@aW4=aim&FJ?QZG}7zr^_fۋz$BT$,Ӗ.Xî-%d<[cT#xM۴)k w]Dnh$QJa6]uNnƜRvRq+ek/-ì!lm%$22irB\h< YHM0C{&CgqHRJ|z՚>Q?]g")118 @T1B,fB=Vx3 *rbu=jߍ/ZOh(};Cʹ}lֻnL@6ݯݐ,8ÎvI6ց%2ƱQIuh93s!8  -y 6:r+dWW5j3Έك1^,!j֏' *5},ӏh]@jF#KoRu,zB!5}+a5 xU;yDzg|DdW.ٱWHm|mƐ2(js+i:!3W֚d'w%'Ef^!\i2A rqP}܅3U^e HEAKbhc%_Yr|e,{@÷i?ta<bQ`ьl=@ZVőK ?CI%p:b{mU^~NpZ*v C%/;_: .璆fw]&QO8΁*v8Q*vbv[3.c ިNOI+Cg4f}߫M燖!=T}0pA(v\6{'3ŀC@Z- ӑB;ruՒԮmZ⦟&T@a\ >dZl]@Cym. 5uPZw]f_1x#Q?)tK_ P+'dn4ek  k/ϝ[uqo2Vq >K"<5>wufGjPW {qy抇 EL PJ^oDKb ]H aU@RȺb1'j Q]el봍o-h'9U,fgt'<)]PU0}-_ʆWX% `D,?̒3 *o-Hb3@Dw}> ܔ2yM [p/iG$W",Ww49m(/I X5Hѹ0-(ziSdYWk2>2xeI.z vY