container-selinux-2:2.107-1.el7_6$>Y}Tr>?3?3xd$ ( P #*  8  H  X  x  @  H h     8  l  V ( 8 F9 F:F>/@/B/G/H0I04X0<Y0HZ0x[0\0]0^1b1d2e2f2l2t2u2v3w34x3T3tCcontainer-selinux2.1071.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.]HFx86-01.bsys.centos.orgqCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&G=YA큤AAA큤A큤]HF]]HF]HF]HF]]HF]HF093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d8491a1d23bc4df52b6735a5d3c52f1148999a8108d02557774495e4cc87beca036f6566a08b292c96be1bd93bf7f15cf714fa799e9570145c2ecf4eaeadef8a1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.107-1.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3]@\@\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.107-1Lokesh Mandvekar - 2:2.99-1Frantisek Kluknavsky - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- bump to v2.107- built commit b13d03b- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.107-1.el7_62:2.107-1.el7_62:2.107-1.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.107README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.107//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,b[]"k%u#qXPNeR@Qk{=p]s;2yT?WW.We G]0wB0RT6EW~pƮ:QN:*NPcv T2>D*mv͎׿5 7rL^<>G2wtZ"#n >2N, М U`#0X>n%}╯  #&?U~ߖe?ghd_2fwRЮhދk ! @.V|-soԘ#2+8O#y &NJ(ceNk>(SR<opU\G'EVoRϳ%mM ywd><K {h!#Z>>xróm6 G=LEQ_ϾPڔ75rn%yjPp,7NArՠ<غeu: 'x5%aKTPr݇a  YHbKכ :?Prb.{'L9ϧ\m Y.]$ӷ{0D46*,% -=kA3pg}bi~Ma˔ ]Cg"pN ʞR Oo݆"W])LRl VVډr[҃e I Wrz#2YL(u}r:Cg <ؼ+y6+ 19OTLA^!WS ;u(*:N;&LE3JB?G7y.f?|A&z-OL)R"AIG|,ñg'K"W%dܚ8n[FYW| uL5VkP-4eC P.EݶPaw7X>͞˜Y+<܎[} N[k߲S\Rd>N)D⫬ˆ=v  M] /dHTSfSNcl_ˬ1eoyT>:}Zpx.&i7Iغ 6?vZӓbfz?#@&ܺB:L\v3@O>^quaϟ? Y>ɾUSD3X 5Y; 7"ܳW=of 5M%0*vW\ud>_ G|r>GZ)>p~ ^Eد6-c{h]|`AAèЋ'*7gtqBLC ΘgO# ςnޚ֫q /cHc"VS!;_k+fϩ&Dz\%u[ݴm}$e no|QoF!@WI%b/>ݘзy"GA2F y+ :Z@J̭M4[=,ߕ F(*Cs-ZR՛]`Xt$CHx,<'Lklvpg[%ƺ^321O(.c^= 'hj`#)xd3+ Mc"leeVJxar2L^x"㽰|Yo2Q6Oww-b3D1-,\2F\#G nlo Z_Ot@_!{~#RY`l7l ϙZ 9+2RϠeߔRXI42ݠ~:ȑFMm2dsRX \L嘭!Eaq},VtZn@qlx::د\QBP]<\Ub*\`aW TaJ橤|XCNCSn>EV^tG02kED%6\Xb.5+u9`d̠,޺:'_^{7EoiwմS;$B0&yb3{R߄ZYICao @n%`Ld< e}n/…x:A$nclKvSt/qĉ9%xH2\?̌L<εC7jfJu֘XPOj .㰳ɗ;,S,޵2o 'EICvfEܨL4{7XΧ"$!r|: 49,ټw%3]X[?(64 ž 5VaϤWɣZϳ`Ӕ4|:|ڞO,kho<9 "ʏCy_7+(kzfqx!~侊!\' ,|?bkm` GoWU.xdؔNc-w_ RZj<<+.da]kӴuj'nH_H_lD&opmK?ʲ^LRzw@N%gD(I+蒱?A!^TPzjaߥιY*-=#j&L߯'{`\ҿV b*օ '}e~,ghlLS2A7qTR+;YZ",^U8`2iܠu`%3v : { /7<',!$;]nq OX9%Gc?Ɇ#GWPp@2w_{\-?' L=Ǜ;Z1_&[Wku`AH*cnB^_e 靾=yl<(9H}鬅w5S Hp]kE22b܈gq:_B2v+m9bQ#&f o| V=OTn yI<ј@p-POD{ $i,XOuBscPiS-նƮx/mA&})Ւ38m_ ?>G~ Hcupt@e(?C_ؓ{Apj.3hp0O6 GQ RYW*SBڭoϯׁ8֭  v N̨YٜƛQz %}[]y &ՉF(/WO5yvΕ^}j&Y/x~RV +vD^N\ x홋=bOC\ζ<(`PaP G Ӣ|`.=^a J6c7?Uc֙L`"mT&ʄņJ\ȧΖH&彾v? [$gQ1 J>|n%PTT](tgw܉dתz(Sՙ2亦`:X&|,M%yƛ[-N8qNG&IPb\)7kU!؋%('O9oHսiXʱ5$Tzm ?tMVLSt >hʆPWk*yڐo Fet{%\:B*ҽ^#D.AzuMF_]jP.WTУyбN-7cwf [MZ =##<Ša7|mBW^j&nkLE;y<r܂tjvY.[7p;>l p9!RO˛qݯnjG;:ApOT* =igBfUni]t{wh"yw(x4 $]A1#1n]M"ӑ$.!<<>b"M*o pb[CƢIo'RM}}2jHIsƄ`+jQ>GtD0㦍0/8,&qrмs\e2=QɛO w3]74w3ռz|P0_׀mf;aP:zJM[R@-RbήȍżDͷev*@]sPsdEv["=.(v.g.G Cx5ﴂONC*-oBq/Ÿ{@ 0{UeV%CY\~^1EGߗQ)6:7e0uBDzf 4|0X%ͧ_in1?0tC,EU PMo_Q >>&TN| L b]ڨ5! %Wմ; T頩e-PrHdIvA5+ǥɅGۭOZ7: KQeyc"wsڴ2Υ3T Ĥ6|/@ KϏXknQp_-akOetN'Bݐy]ofەϮ G΂̔KGt ]?,hr(P)UרPBr4c 7^~JDgt"G3 2&]0jjy">byUǩ𥟛=bgϋFQrRA8]V+H&.R͈r70.,0F|2fk&8ho3 5o~~!]3.Non7yH`p9c16oa- 7.`\x `2톶YtFbj'jKBbA>c 7LwGqKXEQf(<=i*I-bԍr@VIdNT^ל 4QD6\Sf5ql/gт"/'2&uCslS̛ ]D뷪@i@Zx7i] z#iz&TGaiֻtF6%}5ö!Ӡ*?X=65 'yYV(b\ Vwp(OZ*Lwᓲa1m.ō0w6"+d'Q!7Ŭ`k#yͭ+HJ{wZkM[ܪ߳[ j$L_08`r :2bydw%p,46+kfD6{L lE!۰,+ױ@1C(5-TRZ7XL1[%7u"b*E7T6g9-u:g e1QF̐&_B8Fڻ{9"ݑc6.)9;_TH݉m3h'i>kIg&^i |EV|J7/J)Џg@Wk='xTk6-M a?,F6yFeP\J_v@iY_0gR^B{}-^hwmr B1 v0 EШ7?uLE*-K)>OHcG ̡+za'>v2SRq3KG7aqvO`1Ζ;FhF&@J-# ,R/}W欹=9ـW,wk뉬ʟQn>ڒѹ@h6@!xik*iN Joq+!jL:D!۶YNN̙"5!y)3_~P xe4?b|εhJ2)6 :D ڎé7C6 E=}F)Zh4z%Z(dw5\WΝjpWT @~'w圐 >n}z $s ^MMUMƤl;zLy Sc<`ZgE}[x[j*Cѵ*r n`0&Y}P5a'u ,Gjje.eݯ*lƐ <&dz2ooz66;얗@ 3~?vreo~XqQW}RZ(% əP*bZ%W$G;2א.lӯW*2wbnM=< m"wH\'\dxDfZ:P<=/ u{o&vV;pUe_qzqb|QM~3z '3U?K78gb0H#UGIYZS6wu]N/d-[Y!1*/A-TܾPlPf]`k|9dCͬE.Tu^*mH=pMjѫvj^RRXmUyYx&`G[?8p(gmM:) *5EvhVlM=cK$0F xUCz-0e g⑵ʠc$if"ٳ^5-mv;*Yܲ߬{.Dn]C%FS My !5'ÒݼTlfff^];~ =$n!ũ"H:@gN_B b򑤤f+tL3l:dt"[#h ̀|BPRQzitpHN5(9 >w̹3fT+x3HS>Dke"qKw}9D`lŽYQؓ[4g9'ُ_I(&B}w:7G]IJFc;$1( D(RTgs6GW_I TǏ*!*bl?{MfmFvK3Ot2R9J[GݸfWrHW9AZ\魨БR+}V[n 2`}snL*}rL"^Y|p_I]$6uY.04_]?LRq n7$Mޒ~ԫWPg3)I|*K'i ~;|yh/L ݎM:YnS 6{jvb3:d\WGJ,ލ]坜bz5B [#wmC 񟶗t-(ձ=n=/^+p:y*"'QpBb~w$v9g(2j 2CYVCJ{[__dťruю> Jvj4 Ϣ0+ !4qvi/("HB'sYMLki HLš8$h$n ǥ o1Zt;!LsiG*IѻQJ锱IBCz&N,Շ,54I^|4pGe-Lw:zjzYk.7R|w$ ҤO& &GF&QC7 - ~J0?~s^˷7ʺFU W)?H3?E68Amq*'P7HۑU+=r*L!xv-P”y=sցw}qYHx]Wo|jT/XRQŪ>t ;Ī"fBkPD`u( /d,"FZ? :z {lؐAr ծ'QY☷M,Jۤ.O_&1鉠Ye1@2#{Y8ӫ8P%Pq(/R{č' fEҪcG)oɤw-q!Hp{&r 5 Tx`쀥 ڎ+"F'+d2x)E.skѪ,o{|^ Km|s 7B8@CPGŲYX3CD L~f?*E_)w1-5M ER ja%_07^7ۆίKuwL鋻ԎJD Z;s2#2A0.0VXm$q`+܈=ڵ@5_MPo`"v;!^x`Ć~zw yihYFȂkSZ[ ʥnƐ]/kb7WkuvnKJ{A"BFwfWA"s >li7ȳے'pS}ߺ%Ӧk|4h܀XUE#ӄ'aD~j6,Mܟ oJ0ә)/Q ~]kɰeAFVQdî 6%|.z L0g&vK hf1i™r?"آI^zM6ҳv}T@!_+|ީ_ǭYἎ2k/8RZ)d?&ng 1sP? &&Ckx=*~œ*Sgv)9=T!q]ݤ2b ښ#9!&|(a_l$(?p{jaj}ZD5[ڰdRGw4Ѡ*; Yw2&i0ƞ]rY 8ݖˊ>$%䎕xuG]M?BD#Η*(W9IC%n2_ Tf.VG&(A#$ңM 1g֙;d b=so7 X|q`3XX W\ e^;t +P#Q;WmNɸEñ.p{Sm#m z5:';_FʂcLm/?/ڋCix<n.kbX_/Ò4k¥@x@@Ա (aDXqTyʹJ1 $iR8ry[PL);ިY'2k.F;1 h1~rتl<> +K@=`A$6L\ttrT R(asPg !.ZhQxJ ^Gy[?YSt/^F1#骢/S=',oCs9HL{cSQBy5;5xn{\!(nLNtaw~Qa,jD|hqYU͏_w!W~=am}jj7(Q ˘L$[pB1o6FuN&Iȡ]Mc9Y;$ڱT,0v4o2"W_AO%aARh&앎@CIP3> Gn1鈞Q1A5He s-0~FVW ɘl7^kvlp\-Zo7i=%(뿠~hhIak|EFs#Ez_ܚwku~՘]VO?47T0;Qd\oe-eptYZ|jgogl4lƵHoGF.j}s;Z '̗FU!^NMQՋq!-N; Uyԑ\lмbӗ =JWk]e}ZLnw>q!W d#I\iםGK3&'i-&Ic_NqńE^[@.M<аm̌1gB+@> *YL%;KrԬUp f-pz0MqϛRƃ(#JWF]"@u*c&6NS &ߒ1~htfD_ByYOB(rfVOoLjA܆_(E;qp] T'P# wBw20`m0pKiE>`y؟*adZ~by'{eQS[GPVC0Zw;o*QBn5S5V P9Z]&3&vDxǞ&2~T?<餢J8p/Yp$W ജüd} Կ]}m{pFi>^(|I9;v[A Ahf^  W;`/mHp *N"0&e yt2f"|Er+u@u&РnxA*.S*H<fz트+uTxG9D&`dvAs\9?/e{ I.$Z6>:c] 8'  k?`/Ė֪$-5l9'pB5~z//V5-߁UCYkCp7{wU7r@z@ٙ()c+8gldxH5~ o86іo.39#|&F`Ex]h]`T^Zۤ^U ۾37G\2ThK(ݠ3>Lkm[A" ;8f@4 nˇ5]e%<|(u$Hf?)YI/4D ׳+-Β$l*ߝӶ]V5TF d9ZW>wA"=Q^ ds%/ST=6'.gywJoiXus(&坒nuY9Ѱn;G3;]kmSd  ^j8g@s[dFnfBݗJ?tJ騌c7C/@..d,<"` qUIy%ri\:MPD5$;gt#r g~a;P̌i S01_nܩߤ3خs3yΪ2$[$(( I qWIVKJ&KL]FSWY;l')RE4̍}?$bBtPvEbgrbx}sps#R^!5fzJB[wMg 2;3ߔheb78p 6o#(O8xz4i?Ŗ/Q{e!6mr `C)X[/b[Eť^0tӁSv@m$`藝P _)ptc%_j\Q[Q WjL:&s6= 4w7r. xzi5 @լۦJ&Z$ߺhʽ6ߙ;d+j/ kUc?q5d_W:'&(竍 P9 HR-C/Y;ѣ.SxpF~+S#rEgc [A)xxxo߹n .)p^ڐհ:9~+DYՖt=)Aچ""fn{䋊,urt H 6h@1"_w}FZJ^W3ʴrl-ePSp}i s|Mt/( 8J3~<߮((r>E0*RG|jX,Rc\ˍiBBLX/*5 ye8G9GO_(n!-LuD3ΈL#q^72n[qg?>a sZ,iF" ӕ eقhV  '-MD)Yeg .Sκ+N&׺Y;P⧄|j'H/{15ge'P~ sj=Ui5m}hiC"u>mZ(0wّQP쑊I3$Y *? ,vW#H"JQT7&!F~.'&"["N#}^>2lPm$_ ~zq9G"_CgtiK/RPJQvM|*Ude9YPJ`rvnw|(DaA O#Z i&[xӽQ)BKpSFF]BHFI~ v+HTœ4w5y'`vg)K`N(jd`)8M?l 3ʖ2:\[\g:i:`\i5ccmdRLYyX|WF2J~t֮e"Vԝ;2}Dϗp.s%/G槭&Am֐p -6S@N"}IJ*$Dh@4 wIRsY9MJ)=TW 5kfie lXU `ڧ`2ZdcL}@^:) $96VnYFuԹ o[vgt뫍jIRι,bAR%#dLg}K!T)[BFk V`2^"'آ`gٛgq s)XZP/ ?jۀW亓+/4#}[0;0^)o+{%C wahI K[dd>Q*|I+;AUmx6;U3)%8t^*^ 6)!;*bW#M9JH@:}j ͓wP~j~A(g- jmTiI e@rHyr)hu(z9<40ag,gl4MiwE3Ze.J0Uw >]Cn^4'oiޥYs<^mi,bke'7˥K7ڥ9܌}p*PhVQLnu ugkï'\fw)ͷ.D}nPB‚Pbe{N['Mb\E q{$ݚ4&sDAEOzQHbV>Om(k쏖BiǤ[+5=#deeA:>" t>D)UOeaF.{wCGo[$$Pw־~ٕvsn%+K]ۊ нVnX3ϙmcaYlr,<|zQJBhoM70.TGkz8> _i$*il}x(*]RAud R>)N\ =D7!ʊ#R#(C}]PKp8j/ss^"sLɖd+irBgU.usA@L|w2):ߕzFځ_Oκmȳw!us&ȵ_M\io/}ͳ0%+uHE8ſ)률i/Hl){rx8LT\@jQޓOPw Y/(RPJd\p?LZ(ȑ|'=;T~ W5Qz>z7Uz\v0*.j}Qa+mn# 7vi69ӻp@@TfkbsSЖ>Bw;F ]vb ]yIz5H(5d"2jtW%=NDŽclqdr.q{[N`ڿ ȴ(НbЃ6հ.Zr/HrVb%]gCh^ 6LA #X/i_$Z4l`JrצR*bT읣nwr:<2_$eY beY @؈R]N =d&\ףXQckb}RX8m0IH=$o HjX;pl)BA %vɑ6_edn %M$ҕ /j4f[[3 ,+GDh*Q ǡc=(Z3"+ t&t5Vš_.er]ڙ_?a 2i靸&Ŧ[x,(_phE&A9{ov\màXB%|s/h+F.79G荍@?Ԩ!v7͂rtt''h&b.\G5UצVP*Yi dwocc.~+T}r0A,ߧcL"X!EKj GTi{@'3jCc0VoD}G?vcV3ip"[*e Pb@̊xOTq&n4'nN;dm-M#mCirBS"afa5x䫌cN#Q"v0YgGlU,H?ibfCћ6r%VC hHhNɸpLzp@,qocn߭&1\g Xu19V."MA-1l0 i5?S}|oO TuXbRKmp4z=Ck,y~5=M'2s#71u:gԸɊ 5WT8-I,fjgbq=$Z.4Am>eI#q|Gbvn'sjBfϙl7}: z35W+QA])Ji X"eN&r }:+Ti?uѤlC$Qȵ-<[+ ׶x _$#U+R˰Vdr:ȴJc/+7; :衕268ӃTrf1c+}wu\\ڔF>! 0I-& ZE(Yҭ\T)9u#/V Tzx[U&ac]`Di4)`mr]e2Pg`w}-:-B+aVEr'ȠXeFћY>+;'iS>=DQ&Yz;’ 1D\jklH c$04.umudnuQLOD:(yCW"*U10nӂWFPZ,q݆kb +=ޙ s6鰠:u~if&iRgNhWDA煌u(d@w- J@40XJN+Ei|ͶsSY&++ ײqVeK2 ^L C 2&OQ5`.*Ϩ?kxj`5}ɯ/T؈e>%hO{l]UQ_HX,2VQd(3d;bkEjŃ rUd~p8$w9UѬzNy4 G}/t|p洮Ge׮{18F~ʕ &!J_eh$s8=r3GӷUlhǩ;Tyo)>wfxdz'].8SƍE-byD[҂<&ؠvO{ai`=/#g7 X&F{M\<ع4Θ!(5+5_Τb5[}@[|& goŎ/~U];ŕH9Y=N~OFեΰa Xڃ´+~z]4'-I)E r#t0Pj)dÅPcxY8^m"  ~z!$)}B.f8ؑS%P\*XcE]ɉ f0YU?6}AU+B^n*4[˧U:wr_Xq!wX$~QY}-d3 .Y=d]z<ǖ T_W}(Q}?1g*ȏfc&>M:u,cM04Ź8d  GqV(+G7AX Gj,琦*gVbf.盻" B&>NBG֞~X.}!P]_!ey2Je)L")K̘Ҝ y|gĵDQޑo9-n/l4]c7tVr>f)KQnV TCa eB,r\^<-IP'㕵ht_Diu"T]{~qBշF(쯣NjҌr t\/Y[|EU/:x<_E{%O5j?J Y5qoQxՇZQao|AƆ>o#޳_zBu)":l)y.ϴ& Hu*~J{/dXv" k]g1DbzlJX:!>m"ڡ,H.莸ux(koD$,ZNB]S%BKyu~QmFPb칺ǰ&oV\nu; YZ