container-selinux-2:2.107-1.el7_6$>cq&uYE"H>?3?3xd$ ( P #*  8  H  X  x  @  H h     8  l  V ( 8 F9 F:F>/@/B/G/H0I04X0<Y0HZ0x[0\0]0^1b1d2e2f2l2t2u2v3w34x3T3tCcontainer-selinux2.1071.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.]HFx86-01.bsys.centos.orgqCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&G=YA큤AAA큤A큤]HF]]HF]HF]HF]]HF]HF093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d8491a1d23bc4df52b6735a5d3c52f1148999a8108d02557774495e4cc87beca036f6566a08b292c96be1bd93bf7f15cf714fa799e9570145c2ecf4eaeadef8a1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.107-1.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3]@\@\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.107-1Lokesh Mandvekar - 2:2.99-1Frantisek Kluknavsky - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- bump to v2.107- built commit b13d03b- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.107-1.el7_62:2.107-1.el7_62:2.107-1.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.107README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.107//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,]Y]"k%hĉNμ5#+mz q(=i%ɇrD=E-f8We}NC 8`n"!݌[gS4Zjx4ljM X`E0xH8=O&}fc ̅2Q2"FuEőưh?Z?@{㍒w`&یB۠:myG7ߝķ$kwcD!KӤ 6B?M;'%,yX"۽(@dhvU5&|5U>'`Y+JU{ H,z \cx|DpUVig7")*=NQ b3> \|2_4;b 5Y`zb>Z5z#3nKw& Lo+ۦq^eQ,D/3@?G\²uP3q JCڣ8&,qTnPu^qĄ+|"s:uBP+ɡ-7!;"'4&H. t%G:;V9x)u8qKe\$֧zLM ݀&$ 4s:%-$#HHqŒY`-H.˟ %J@h,-ٽ#aMY|H 71Z6yt8wOcM&,*t,a1 ؟ɺ?9@l,B@ m@佾S j57; Gd+Xs9mv4&@HR0iz(>瘞ͼwiGlr\7꽅/6#\RwR P4)` Ⴙ&XcmZFgGQ/4"2+@\4CN\en-7;>kOWNjr, c>k0$/S,ɿ]笸r̶qe&RTmak*sZ2'To\{6#&Ο`M~>qL_@s88.F2% sbNj{ˆo!s YT7?MJ~S]>]?ֱؽnG+S,L :VLf-_t7f=ʖ f)g*DB8|u7UG?VSK{6=^q.6 g.%2v!C `QEe2FB`boVbT4sDg\$rh/nvӯoK%S)57*~hۥSɯ֑'`u} JVq&&1V({LqUN-ߡ=ZxT@$t5H"`WyR'S;D\K;#35ifg:X@p v~#Ʌ8Ko;j;Ӱ_ @_ϋTP^, VI^/ͪZ\5qIwni1'ߘ/a\7[5-xC6N`w5$+Tۣ91yG>0^rI?Eai%G1@pνN1}1UL 4$_qAQ:$`Lj9_,ESvWr:`y^T~^8_dp6AYg$§RcNzl *p3 ' }9o;($7a+j:!TĒV6+ =%R:waok.*l75#c$VRT`f怹 DIcg{XGr@'!@"@%]UN'.{0(E6WucaZwT_>i2k, sTڗ "(^U7sIXqMBk8Y3lhIi-SV-wI2N'8T%ٝI5i&|!0+RR!mZưT;Pû/g 1Y),{3@5ɘ3!XkpJYI憿4xpӨrj[zCft$ ;ROCg̹$`UQ7E:@$9BѮrNr׹A eǘsOuYÒ0\|N䬫In_c45BDUu?Œ-gaLjN?1>+( ΐOux! -JhY%T&j(S8]]Ԧc̖k)DUqKU=ؔ7}h."? 1hQ׭6DZ i j'y@AEi`o*xzgȃVz;5ܷdEc})Zz GEcw3RNB|VZ_ kmeRګno[-Ռi8W6z& VER9ڣlOr{"ի3Spy4{s4(pTYG h,ΡhjhvEە,?2=ӈ @!"i\f\1'G75b]M(-~Uء XMytER1}(J͕;+#ADkF &@h$>,+74 iiN)al;)9הDXsW \L4N82cU7URr|~KʁA*#]&,Z;?G&%ӆ\w |90s=|4r)rD>fڣx$iKN:B3] _I+Xfo~q `uU|`)-ՑFWo#VL B4XHI D%A)wIW`Sw-4e;Pͬ0$Nh@3"@{6Zm^vOf^#XCo& Ύl%fuڰgM+0{@JLsҒn{g*V2ܚ9:"bɾ*VP=|w wg5vaN-&!2c j?ϴi2OBϏnBrp7VX`yRufi %չ) 8﨔 [ (Ν0)ſ|7*XWD&Tc&K+_(w3E슒>OTw;cNdy8!V:]?uxW)YǰxMY3kWtګ=t Kc`yENJA<׳M; :Ycktzeg*ى;HO{'PWa:fj\Λe-ur ̸T}nh*NJlbeˀ[h9C] (mR;_S^F N;ë *G& =aoU^x1-àsI*Ru`£ԣ(f8UQ產 C۸R"*t`5f iRiX{ ER͏ xKNٞA!E<W/qqSZDa^0{v;\凯qRp#- $?gg8^3i{UX❴}]wص h+KkQKriH&ٞ+dXL'! Mwl;ZkU%.=UBfElKuf#_0hٿeEa{U^ jƻ'^SB{ sM٦0qӊ t_k{D},1{IQn<1IM¿n E~\ ҮBUq{]ϧ0p9?BSY(.$"_?5zɺ4,2 <+do&PPu+ؙߏMRVVG h>?46  į:&r+V&  VDJꘅ e =VPmM)}q&Ƅ#XcXj}YYdk83#RsIsgM뮏1RE TeG➮l,~{iKxBWXh*miT}:NB캾⮆¡|%㱕T^oڳm21re!_jޥDjُBȣ`z쿿f?A$gS^o 4eQ.!u6r<rþ*p aL(M?y>OlZ/of'/M5&hIq9׈➨rWW FñeI12 LkzAY6 ->_M\;t1ٱf!~:ލ_h'@vqX`8(suR'y ?"lS@޿zhZ"(pmEA?J-2S޻q:帿']SY_D£fb 3K 5.p]ݯNwkN%tR 30A8>\]Ԟ;v;G嘔prBJ#ūmY# ꑂI3j|ocOPKA%Ф夔 T7O#Ưˋ7E_l[!a썠#ؿʟ8#K$ LP } i h/I7[*օ5椴?4 m:pjAq˄nyx[f >2#x} #&wqn [?ѹ>ZB{C9g-sZ~ӰX$]A o`@D^h`Ѽ!3j}RVKW]0vgn⪴x`S.8l/$hB)lM d!uRB6JpVor ȯ`͹{nb>SDyPt7Q.U'ceAJo ,1 /ԇ a p9$09DzJV yB8;{x»(G\&rV*u0_~UчT.-d`^kNDV=(3 ejB=a^\1U`dCX bwԎܴ{\ƀ(,=ϟSo(kS( ZtOKYHC*u(g:Ksj)&U/ ^AM74Ї @$3[ S*}@hk TO0, F\I윒$+AH60^C#AGoA+  (v%8<=ئ!BlfKm/ }FHҜHZU$"W_ ԀٿY}-AITҢ/}g{~Cw>kJ,w @]l87@C<6b/|é r4$v)Qrz.;*y. 4nƪJc˶O5V@PؒmZˡ9Q%|Y[ކX J5ƪ́`Q<8q{\t?:WD6,{n{:x!ݳK฿s[6+~8pM;qA*Ir@y[a}܆ @)[U/l^gjN`'RwWK gicNh'hX[qYb)\]97}/R $DQ3QS.H{C,}^f+?JaiE7G31!>)9P,t=V뻺'm2%HQ'=U^t(&L)iw40_UD_F"&1W*)Uj9w:d hmαkA,D;Cd_N{ z= t?uWke+jtT`3qs#Dve夁#_ƐdPd"SkȰ&܎V)ZR`ɒ18Nלk} olxU4bI:^q\7Aq2@ ~@,3Zkgaf7 j u#{uA|7Z+m#QA H$N@%MX_З0J8RNebw_ͥ%>&ߎԍt衻=Ky38Yza%/V3KFV(wKmt,Խ Wktt5EMj 6Z߳)p<ߠ,Og dSkEl56Ȗr觃EvJ:xGJr]q |}''[ԛ/Oמ2tbi#Pgs~t|M'8~}wR5fr1U‘J"dܦ_ψ:˟dEXڱD>{KXvPk [qx?,_rmP: K`.3i4!VX ]^$;'^d.WN풹[IaDm+@>\tz< \K&.<07l=k` t|['t᥹Y'ɑNzTՖ{N~DJ7(}#ciE9kyP9vcZ)AXH %[>Ez w︋nۨtE@!x݃v1B|}+4.~IH^ި'ѨG[az(7IV]H&Mßk~;lYo!2C\:X)i׻8R>̡a<—ݩXx"e &&dCJms}d0+8.%z(ePxJv\"W{з$E!HCu* "8f~zZ#pxo_}[PP9IS_( {8 -K|$uFJ"^3[tbZX1o.L&Q`]쨺׫!D Î!oP͙IIXD}l"11*u| .<2[ Ќ>ٸ|рeœ'9&!֤s&\?ëH}z`L?>19>ӿ`LqI}~X>3Z3T%FCsͮ YR138vOu,̄*&b$Yvm]rdX n;si^\Fv R {a =҉ɍ%_k:,Af+4`idUjwFe>IInTѧ$jv&EJnP7QtHil X~ɉ_RNp}n#wL:@Cƫ4g36,@w\ ηve9*u 8_8 q lK OgƖ[89!.1 8TP]v57O^yJ:|lnf],-0CcJPd5MhgJYKTv NܪfZYܠׅT,|ȫPWuU= 6"59:Pm򍒔 *3Apy_)G[Mn}6NUC: w#jcdZPԼܮzi{bd OmK1ȤG/?Vh|:Xk;va#KkhPE{mkEPԕ*+nەS{E|]+=CJL¤6܁ReZ ^NDS_OdiX'js\6)u(ʦUAnO77WLJQF7OXBas6vp'%5 7!zpn`1+‘7L}3,(nH%wqhX< [7RBacJ.8G?Jp]Hrei~[5úQ{'m/L 5ek 9D{[ĬklQ+Ru4 \pD`7[(k=C˦pssF:v{QBslyFI7#= g3|t"2᪁JR؞[И8ca ]k!t- ڀQ0-6qR(hfHQ_B_T/ IDA$uB @,9:˟wVB*ìF,huv(Cv9}!zˇz7I/"~gK+IN,Yz݌c}x UO!=:Y %b\3fs/U_m vOt$ kW(FRҥ=jtnT 駉qK:~Ъٴ:Ho~|x}TH $ϣA==iQTo Á+x+q,Y)EJ' pl3PD" ا"-|8cۃF5'w1ބ {1Ef>Yjҥ,qm_jԣvԷ+_ܧxF) -!F?= eYZ<1 R!W&<4<"D:NAƁEv 8T:ѕkeunCF+R~{\1Lo}Gg_M;sCc[x-&C|,ڠ)Ծ:+A(U#hE N6)p?1\K@=Oq4y,wt/1^moj^#JwcŬNT-vڶJŷsjy ޓUcT3OKtldք#A{" eܿDG"pDa\PEV}ghYƝ¶w <-YS?{kB];8by ua{У\ԶA–f&g0?{?C~gk3|eR^3䫲`Y;RBha7FkP W;u:KbZa*XzOs΂o7_g0<[O׷1%\]D?k%ZzntͿ"ZXdԺPY~]zZhC RaC';P9u^c~ \ynx}̓1uQ(e $ǔ,M /CJ6/)ѷWp !{P>h.O,[ Ck602F`t[Ԭ mYRl8WqxjuM++Ae=銅%>y/qRp$5ߓE !69p;Tߢ=Sye X<pԉR4~586W.[Qy@&7΢z_w`;Br5",a@ < kڤs؋7}<'.AFk#ӎ7|HrhIIY @ZP0uٿ(J`MC |NdS=Oi|ѝ wo- Mv]E8?/ t-@'t%mk5 T,4WS2t0ȸ uX"MDvpTaұJ*.G輢wHIwL%M)!O[0xtжGnavlJa'2'K(?\1f_?]@Y//Y$ $7M8FV+ [RZ~1I{ԠqEZybEaN8?] j>  No"LEXN:iW9&~HVvT{EHC]aشm<8~/>kyPO΋Fa*ѷ~1^;g?TM ɥa8x"CQ~ iZE ρ# ʖR/BQTo_~;S{9Ԁ4 N4mtYe`LwJ"2c[ =`T[^hʑˈ[]+SvZx%vC}/$0N?f^SmGh^PC4`t`JdP8.g_nd;͇%I7DK[~Gv F BO%f~ a<Y_rshEV:y஦;AigR&ߔcȂyc4j!FQ0)ngϵ9s͟BX̍""5\GmJQ,PjQ.Q,Eu0c+RH8RXڽueX`Y'՞3I :®| mRQIIᄇ[\j$$t?mR.hǽNw*`Z:]yRPmC6?7ggy&"buى/6yZf :"1Qp'#+3w]KSIWN .{P# -%agb6n퐲Fj/:cYg 1vyTɬnIo d_"'It7ƄSy#n QʼnWd&GD;RG}N6ԩ@&Mkh5!i;<'I믆1`2bl"1yx$9>H b@~]sH&ttG/5hOAHpmц80$̵va7r8)EKG]Yм°/LOt/*57I^Y[8_< C뷴 aپݓǩ~\SAC1Ofѝq_tǯTt⒈E|7MA~贕"g77$2tdHⶕh\m%K Ğ"MэpǘqCrhV< ՒRc_B mKtDI򌧶5G2+Nn´Xj":4, %juo(u,?z:}KPoÐܝ-ٙ){C0|ęjۈ!4kғUEfh6tqu|OI¦C3p .b=2zΒ5\wvB:5#@ Cd؟ |u^ |.Ƈ{7W Uf+RYʐ K!]Ӂ=*F Ar$1$$I{zbVnrTzήsr:-7pW D;"L^1^>YFPr09ܺ'k/uP?8=Nq:U&Sv&8P"T%ؘ,ջS_k6YC\K6_*R {Oox;{Ayux8fAP;JހAcGܓu"lشjy8ly:Ϳk>/}*Ux$,.e076lZ|> &3,N$^eu= # ,).}#򅿙hw$5P&& Kuҽ-;ӷ:e1z7HrHkɆ$ח{!h"7mɜڿ6?&j7re3zyZ@>$jY%5=Pp* 5{琹emL7AϋPUd  \Wv$ )yΏO;EnRp4D[r.\ܑUOJPYsxMS`i0f,Mng0{x~x"+~p#-&K^J7 ~ zk Lt/|ثo`9DFrو-} G3u DEGLyQ AC#sMxLtU'Oa"ǪKG 뮄lt40d` YfhVP%Ö@H DGi:~r9hL 54)ˢ^c`姭-ta8SMӅHz[F).E eʕI!!;%I|nl|RY $n"dІJF^djnďdXpBPܯO=^%u: f"QzO/j#o^@9Ӈ섵\ +QvQ"#ڃ~; s`~\.&Ycf`k'AFd췥U2Џhpe(AMХ+D@v_;ZXZ&xdf sb)>aܕdk-&"ǃ[2=֠MxApOl u(TQXQ4pSnDQ:E"Zd~'QZxx]jˤ#%~[emQk(@= ;S8apa*@q>Gc"}"??H"tpFٽv=# Iɝy׫ щ7F'fO[u4/†Xw/s={[PLHCg\!? r A.Q}q Gy]JBJ^!_+uu@N\%m慨d]Tqf@r2m(4Զ:΅J}:,T4ժ肩Ń#mɹ#D\m4$T!OgCY*.`/N烢T5A7ȭmX@ ͘ɢoUO@ۭ 1,I:p "PPՈ Ig { 91"-UHD؂s9`mL/qwtt i]JTyRٶu5F|BLX#ՠ Y87~0RH/4=Sp8%@y*Վ|p*[( `tD?]8  Bbeovcو^렭>Swhy cߺbSM)H8G̈H9X8n=Db1F\D7a,6q (L!ET*xZޢh&"b[Pఞ&MF|ܡܺ;G3M溾B{c!rK3/@ƔCq,u[@CދIԗmlw͊`e=_Mc\\J+ `WqVK $y\#^l>i黯

ti'KfvfuP& UxCy tKYɷ昤\, ^E]HԻi(IlxvO! E_1}S՛oVג>F4tL&%YKJhtJ?*#jsL%\5JW#e&a"Ӗsw^G6F9aMR"ЏrؼiF{Z^BgS5_ z/є~biN2@#_.?(?E Ӛ)^A3Am/7jbLoHr|IܳMAB bZhB"Ă:Hك(U# !%.@u;x_Qr3mCނ8̻jh0rDSiR%Gk0ܼ,a}҈ mZeSߘUQ9ŋ:T@@? ]S1V}*lif䏀9JqP`=Zt7 {=۳}9P9K,:[9_:RpεڠQԔG9KG\o| LjZxӇbq<-|t߷,|x|~ ez}-˵Lhw, |>^iUfvU It+ɝx1 ַ Xx<=Jkk*XV#o\80#!4bLyR*G6()r}]3|~ .wz,'%8Rg,,[RaA(JIZ92i@N\YLQg ΊJLK=;C2(kT D"߉BTK}cZ !4X5,I4$5Rr+iꍲ&ђ&if©;zYtӫ>g/- dJ +gI#ܮ A*ĀZ!NT5ńtlTw%8]L|b^WE:tbx¾ G^?)ǼN497xEI3bԺO%co7~"2HS+SK+8>8 r)Τr6}\Kutſ ~@1<޲+v}y7*T5Z7umNTEi)୘A|>>H\KMI\Zs# K'.U:NJ vD;~{º,n9NQwÅyyi*gC)FSu t6Qhp[4}tE[-XicTnHnl9gKK2GkʗtpK[."iLPeY2O[~kmHP*y[|b,sfHxؤRK2:d=1d>YMs-=Xx!Ep"vy270951z>׾oo  lGH[K0! $iFĉ;JrKlik-"ג5lEXD5Zg*Ų#(#dFjLBt fPֽBe031l&`w0oϰ,X)A^Â$Cj_ '9qZGwl 1Q|g&T~ A#5i|'Y Rp&ՉcWT#Ơ6aP.P Z-Ԍ0ͷÕ@J<|i4,lz5(}=8\x}PðV~ ŇM+W)]]qg|wZd_MB/%iU5zH^N5Eme׀!g&'^Ӛmjy%Upc Z"Pp Em;r6@!ü/X A>f !Pno4vmGcoF}(Z}dB_2 t_f&Fޤc cX4RjNaҨ2Q`tU'WPGP0K'lj2ŗ Or鳒_\29ٔzT3z+U{qA.dXq!0c#gH%dt~e6q9HG L5cKT)c+4{8R-k .vq Ex?zٳm;h:3?h7W3#n.V"gCa_$}"07і?Kg 6jBuv):Q链SCp$Q>B6,n0Esx)CϚ [>8A˖Kٷsot{͕w-Ao9tYIb -l{/`m0@/>\ 1 afż߲NF-~Q`D nn_QХͱe }zVew%8HBl4-P2,~wAH2LTKYeO1q[ROP{R e0iνQ"uRmvUƫG~N!7-8;}c Kp?TsY#\qvU7,S!u7ѿgU|Q-V\Pd lzNoy=Z4V1PmfD}֟;3k+l >UTWmQ_k-{K%“Jb@S'~>Q?i'C6.Muݡ\%oq%D`]QZޒSy YZ