container-selinux-2:2.99-1.el7_6$>Щ1+%;ݶ>?3@?30d$ ( P  &-  8  H  X  x  @  H h     8  l  V ( 8 E9 E:E>/~@/B/G/H/I/X/Y0Z04[0<\0T]0t^0b1d2qe2vf2yl2{t2u2v2w2x3 3,Ccontainer-selinux2.991.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.]vDx86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&FXA큤AAA큤A큤]vC\]vC]vC]vC\]vC]vC093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d06fbf981e1300e33caee8aa3f8d2b050efa644cf7f007f199b2c901486b577db0da136008666de90c3f116043630e0658a3fd00690d649d99d735f9f0537dcefrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.99-1.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3\@\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.99-1Frantisek Kluknavsky - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- built commit b13d03b- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.99-1.el7_62:2.99-1.el7_62:2.99-1.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.99README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.99//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,a#Z5]"k%u#qXPNeR@Qn]s;2x/}r#=T"Lh}5ck$Zd8ԍtttTIO diMs%CفXT7`&<j~*@ =0eHE=y YTU,S;tڨ[x զϖ k՛\xV!ǎ~5j2Ĕ+$6v_x;pxKՉ.u$@bpݴOUv[ VHf5qJUe%(!2wx0)ջUuݏwrT~]=r<#E݂<;BxvUIm8qb)Ƶ1 "A$cl5~n^bǶ{VO9dAf/)ЄqwrM} /R59*O@}Z=ì8ά+ UWm͔v0oc XƢlfa!_Reh ZPxkǸ *5Dc猍I5vr Xʀ7u-bһӼs,5Bdjb ii7_*gFs2[]5yncwZ `x(Z0|gm_Ob`^ IANؠo2ڿ-KDP#ձC0=``C$(=iE6iL/sgX9!MnE3"ZG#j3NeIʶo( 04M߫(?D%34u^sq7~/4 SIfpk P;TE# O o@#<1*XVNUZ /Ya9_GqBx.]8l!?H:PXp$@C$KD%:0{/XqSyA$G3MHT?AH꜄%xK>;,RŰkJ)J:{ aB~ZE2"EΖS {TL {,.gd~aY ɡuC;?^0O:bяO^^HOUON'{ %W}ڲ|դ(!p=}+t,RqBcۅ |wPL&M~K@(F  U ,LzUdTm`%^!aIn+\ >\BŁx',_uln_qͪ[w8%DhnE̖lȟ7A=C(bhe 8΢°r{Uxx?of^crH[!C6Ato iBFwz6O[8PYB)$Dh;>NnJzm5_k/xQ}pz+}d&dƺZx(RY]WIx!!vg KyنRLG-&#ZqMB^ԿCct(egp0mdK_Y1mEF|cWH$6hNr-<6L^nĘZtt9 PRhyd>U4%{2xlb5O00D}}jF Y5/V/& _F'TeMψ't|]{EMΩ~Gf#Kv9z WdX3:;b\ LޅIR<I& E;/@aRh;A$ 0B 5XNOTD97tp- &$cZ6)7ueNyh$Xeά`y[戸˷zI:?c"m bs)R"[f ZbI0dBmj͈bH%(BT>`[RB4qAP#?pAߚ΄)6a?ʷjjEe]lahʄ ngYgBC L7']ᢢ\ckYt\P+rIf{Jr0?f"=*Cth1½*p~NM~ k%İ"QfJ.8 DQo#}3j -PZ I(*oI[u^~[N~;n| {GA܆;w `WPm)8b%/]&p@3G'/JsT'70b Zѭ~Ac'qGWT/s B֓3Y}//q{wI D!d?59!>\8;6@dac{ɾcig8b> ͣDwE+6tױN& (+T\G66nҶgAL]#lc͎]vu(zeJ н1A XA/.=U'gUɻxxM^DlJJl&>Z)I<=8-~4XU=)xKOX-LpZ=x㮁ԙR8@+˝%@?ƬrA6o@MԫXDsC*h0mCJLC¢}wgLyj_.dE<鈄z]\:f@:Q(W'lRn^ П"ELK-Xioq|W _ؖ r{B/mMKlD Rp3OLW0]DԥNmzЏl(r&EC5Ž!lW 0,W{>qMcj*Q0`4,wBjV3;8l1(fBϻ-\4M?jNF6xܒB5 +æ oVƪTq(:FVuT5~au* AK.Jr0 u-G(4Uy*SJX^2Y̝$Q3%Ink&j .;퀉Do;.]w*-ݪiIs?0ͨ².LtmcQ9t@쓁/'zyTז<:ݺ Gz,嵕|z aݸS -?ׄuBQ`C$~b媙,Lͥǿ޹wrM]ݩ,hCf 矧 @# Q USS!zd:OV̷WM_D @ U?Pj}hG$>1 zUAJRKhQ-&6]5"3s`x(BAu,?7}ղaHjݗ+B4~Dz]R9jHK , @}~h?T%4yc^Ҽrv'6wu4|s9Lhc 5K^z|.~\uW/QS2d3;ZLysـלG Bhm&y`p'I"/EK)xَXO9|mc#il,jNd6[,[hY[m^,5چ|  DD}ؑ=uNUuiK-s|!3$*y.hXRXoLj68!ظ7Tz: ˘ps]6k$;_A9>AF%ˋU=&6ܷMz(tK }sWT<(.YLv "쨘f?OzX F fh{q?ȥno{STr D5\>Ӆ9WuX2r3AgM49]U}Йu?4AF"O&k_iEIn94Ʀ#)<Pw50K3'Nïy`ez[~C!wS'@8A17p8 3] ѳhŔ'g{Ogz.Crws<3v=]νaд-AEySE؝r1q}ܙ)M4ETZ,uԢ`wƉ)y^ #Vޱ:T3Ke;8i xAv٣@RԆ%):s_[UFArxßi%Qң0( l&zܘ<`z ])Ͼ;$Dky@ CV/#u N&8qjheE< XLكdq~;3|*S$^*%p=e7,O-K72He~Ƨ!B ~>4ɞT0w!f&`xG=ڻ[D!ZR{=eMYTɼmɩi Lj'pT `=#yZ6i}ݭ|P%Z~p\=7mo+6bf!6+X?@j%y`RNf/x31E;z;%{>Qpf6^5lJ7}n&'bFcR#yCko j37<[&d>K9"Ftc&GeW>A`BQm$!~jq}ʎh}wlݗz?usb:}#/lk6*R4;g@K+|?Byu+ -Z'B^;HiꫡRcq ,js5Ԭ1z@H6ӷ1OY<m4Tׂ)_'vZiBOm:z-%uɞd(8J@ '~刊B#/3dx%PR9̔ Ӄ לbvhj)bʑ51' 10;P[S) R]<N k"T>~BMc'+0'L8FJ#2d90r+/MV@{.c6`b4Yp®8#}cQS+]`4m~0xb 3I-g:ucmryjӿ4nSUJvEBH%bZ]{W:LyU,f.'Vn+F# : 2+/`x!+QkF+$`ĦF- 0mcQs;o.Zd"p] !DuGy0,GZ_Z0@ORZLv=m!I,;t+ߖF`g[PT}?{P7Qc)TkI} `xEAF&o4fX 5TRѲFNL'Ѓ=q8穙# D@ Ʌuy+=Ƹq\6N'4kߤ,u8C'/!8gOŊ_+"<عԴ{1mpTZHp`52_4W|R.`шoYVc%*$ޤk)dT{`6gyz}%HY{aqWOIN~󫣣`I(:es9LkD aS_N\׍-YQنĿ bFf.~ .Pz#c/kCh-B5P:|$Ճas3/=#nÑ] Z>^K<db9ǽNME^ ~/ mkAќ3B@&WfE4upTZ;%Oghtbt9"o5Ai#s bW3|=TӍ@1#ɉj8[WїWCo0!_uH$?)w3DA«0~Qrŕd N]:IN[lpz=TgCu:H‚D}a"j+7buX\Bf9HQ"OˊkS1hxo?z" eTn6N>uR@\G2͑a. Nvٻ+9ͮtSTU@ Ƞ3Lv`H-"GZJ$b> 7vQ d,719x#nyQ,1IljB"Qi{kX^)4;H/xM2w`rj:-73uY5`ʜkk'Z K)%H Pm8ȋՕ>q@/ =SuL&(f4MpA1})Zx[k"nT0ۧ?f|BW߬ ѡX]<,)ga{f}c:ɪUJ3UY !FNs40ODM8cǛrhi9a5G#+ʞyqm!px!cF^E͚Q]ǩ r&^}QfSMU:+$/ϟ!CRlnXHL; >ۀ,Vߒs"NFWg/'54B}G3œ5ۋa +>/'&oQ[B5-U,,BN֑t}JVnl[!F\[B^* ۂc1V"-G̣LύWV!),FR$)%fgSZtq$!ՁɧLa =RtvPؗP[88x49\b.Iw:9,l  `GӄWZMM,ֿ~XA_KHn{R,7qp'fw^׵/nu4N*y11V0;b#(^v}<=vGX]`Ey:.t߁d:F{RsǕԇQ^V@*pbyhfufF(e .mOCL;5':*]zv\fE㻪ǃÒoIiI WK`[6k`(YF&[z,Ǔ;TS8{C9qƨKV" K;UM@ȑͪ[oh"3tT?nq-].Y^ETeBrsdU{~cJu)?«aCCtNaگlp/׏];6ShD@"o7Hñ{l5B:\2(X1ٔ G.Ҕ ,-w{Z=E#:vR8)yV ~ZP핖{%_$%|?&ӻ-"B×}\9I-n61iU i8&hQC*w M1Qz^lT7o#*ـ!q_-1"WnPRE xu4 5ը;פ~[{S>Ue,%gGELI<9QKAZ,@hbIe]ʈlÎJtY 39t(SoO}Ũ8U5K 0O #\%y9g3$謕 韈y>Г|7-ϊ(`|){cѡ*ʑ"gU&1 b,Xܖp&Vd6hkdH/NxEe7G֐ab+am|akFӘƎ#^49%\PXr_C1O$ټ>3_/ޣ\+V,ps&D1s 1Hb nza4܌uXj7> ҍ3dg <:tzm ˟x,=XStՌ:),i*>n0 +9oA . 6HqϴXl7x4zd.>!ܗ?I 3íPn.n)#0ǚ >,NiNaJ#f"4ޫVf]v AVp SBqɣ< ꙓI%w⤋1CZͿ?gP2:PL3^LNq(xff c(qMPo֍7P}'NV{;&zENdR;hP+_PU mCK O |fjdl^'&yJ Jf jJH$q7sj`O&'B!=Ia9A=PAx0v-$ :]Xyᔟ,kt\vאUZ}gQ4+MֱͿ^:c!J5F)2U'1%˄<g,x;"NC̆Uɖ7eslyg@w{sbp'Y#8ܕv wƜķ.eh3 UcErH~iu:bECPsz,2Ds JiXa\Jor00Tɖ ~}g z=yLnGEz ؍6*V(&,^ߌM"c(YBEAS`0u ~<<a=Yιh-+6W[RDCY M Tpгgci!iY׃>vxr[RZ!'ֲ<;|=0\N;Y k[ѹ =N8yY7+1?Rpꅋd[/kHu TEo^@,R`E|ƶ7ْۧ'Zي9."/`'g< Zot(>@XpdR 6f,'bpZ-O,xd WBZ~$qQ^b!t)Efp/D g2{# 6,}_:nۓ>Y;鲸1;_Q2;׊Ëѫ MQ H[z=,3A/<X7(:Uvղma.[RDͽ"> 'TuuBW v72rVtBzЫX$[#LywOx]գⅥ- IVU !]OYvrEv.kL 8A/d4|\?20~-'jƉDwTTdSzƪ0]-8t4[m$?Ύ'=b W ߵm0pReS k厛GYc o]$mKӱŊ~b\/RiUq#m#*x{se @' bʥ?[%:c,ÌZ9*=Dڜ/`{>0 "^meJUWYP=R543n`)xԴTqp\y%.zP8 >D$US'J.]+&@Û|Eתzqj{-Ċ'!X4F&bUpJC0*R 0 =fp["  cǩD`PqZj[(^6o\@M࿒-=Z0 {Fg#> %^k rqK{w-j?pqwDS5*ktx[-;ҎAփy#Hn$eX0cQDt'U@$h.~Z5%Ęr!uߒ-XB߂;HO`q۴)oAPP`; 9zƻ艂]'})Ĵ76a+E9z&HN7ʷwČvT{PyeI$./53#V͖e@l16_)fkHS!CC҉ sm~,J 73 {&o9Q՞2KGر2p!rޱIa~^<"%3"7ߧux}Jd{/!MѦ.MW3sv [w;E#Hf.{&ýo"m[W';{/U?F6A cwk* tV;TP11ۻk%ˆRb U. $D5񓬗sO=WPwr9C? "͒"E,obա/B!xќ,z⾕t(}JlmmJ>{#CG}i6;? o%<.` xI,dHJoFcRJ[ x'^fya$?|`H_Ѕޣ سoqJL$eLn8ʹ@Oܺon^s7GXȺ -+NUYo'ㄱԯaCC<zGӪMϠ!ٚba db(:OvnX%8Hwuhi1r~CrHTr" Z 9Ue_|,:SHEdk 2AAfGDcGkA̝wE7&C.p|2+H4]28|9DxkCmb D:2naC*Tb4LƲSxl_Qyy>ˆYh׵/bԸ ?e{T:+JY4ۧqsQD>ޒ18\ 'YOYnx>bq#fs*}cՆò3d cK: sn!d;u< a;wn Rkؑ߱vYRm,M@{ RV1?jmS cT/W| AO7u1 b.F5Xژ ЈʎLU4>C^r5 Nq`Wko"^GF:yN~g1_[G ~ui`ή#yAzD "_o)@΍z_BY8Wlp`A1xϩo\ukd ժIciB;S_T}}Fru?_c,9n`b\_z#BTm1'$MFZE U7%w?䟃_4M}3 kvzS-fj$]̩uH_M歞kw-)MvjmW]Rx`۵m/2WZn?u7{\ӠPln^TV8_y <;"norߜ:* X '|ؓװq<׬Эc299ȋ'fJ^{!=_<k(ATWsZG[CLMC)Jׄ"1[A0[-d۱kIcW]jU[ƭb8/ +p~Y!;QEւ9vb=nh&pxh[X-auRk_]G6$>Qc%浴KQZZeN7zp{C:eK$[%z]܋c3+YP/-/xP>Ú`'j ] .ذn)tnGmM=0^7IPH?݅}++?|@IӪPsrkNRMJ6*8Yd"X/upI9ᗆkVU%_@l5Ũ PJ0|BUd5e iCmq:dK1uE[YibNjoPobGSAs<;iЅ6\@nF aVEӘPe4 y״%`{xʸ\`AT?Z}jr:4oho[ "2gH[Ǵ!صD,ݬ<c\tw Rû5R8pO<Z`jd絵br}H{f/ُ-Lr+WhP۠7N)[ 塧괾gRǔ/T}II]E78 k~찟RFq6Kbr[fHLF'Yu/VYnn7VXϏt_v II]\ ڬ*z)1J?x1SԞVT56>yx+)mɻѭN,Kap9hט:> h̆-Y,9:8a_@8ɪhƹm7c%Z.n`_/"ɪ8I%;U Ɵ돑έReLXitԉ~,[ `H].{5j%Yl{N3ta˷F4|g̺ #96}pC`$l V#(\$ g >.oז_ֲgj"Up)֛eUO:)pX 'm*^2 H4b1nPp[mQ$y" ,hڑ}?&+2Zso96u0"CO~kQvf˄<@8l)wbֲo,Rҏ祱~G(;Uq~":,h)se+ " ޕrC=)r2S#A%,Le76Z],w/wvS?#?pO r˫]/:="C~\wRFW`svnNUu5ε:L/\Ӓ#O.XwܨeKkؙ/ʃr: #ݶ/۩U\1n(:7],li/ΊˮsRp(!ځg2!$jn6cf+Ԁs&20oA4B8`!P3KKE L#[g{BMqA;RMQZ|#|M7p< •iT9 &ʕRL[bY`Q 5ܑ hd㔆qSadסlgzd5 ;UItt;̭#X$o N2 t$ytxS-Γw|sCf6dYܓA2۽_uCwџ3_%V7&IQ9b)Bs'\ 97cX-mB#/e"eU>7"6]:3eEb) ]!͛Httze.i~And44+ffj$$'p`6i[- Q+YQ5K9C\DR0_}VGc2q88u,svE 0Ehjb7YN`(9M? A`tQWj7~wD`9ջo3ME19[e! (Dkvl!>% e䋗u]Jx{wTW?;j҂HP)0P˫=t@ !) b[lr4#'h>)Bz''&ԱJc'<ј/,W:cl: g+֏džXx =liRyUm:%A9 |a6-2_`.Jn칕'jֆEZ6Al< ck[í@v`ס@5MU"}h&|.YK܀!F8!jrm/i[WK N"Hiޚ ^.z?a&6_00ouUZȢV+S տURGx5:?eOvNgMi4L_+Gtny4GQwʎ{л!"+·"xbexT4Ih-qu-洑%}ץ/-phG@V);jdέȥYm\B{bj?3DcTO ?lWQAd*sR}i$+0ytt2)[m0%irXL j :EìvaӲA[p]j3:2soʖȀxl{OUԵbY  ;4j3#Ps=b:V= uxW ia#{Z $ZH8ņU+&1{BM^.Bp(˴%L}$j -es .K`?s.}À^;{3v+=m+ ba؁-sav- v('x\pbdm /xg8JuTiqZ'!UdN(W']>Lol_ɊUXgJBh$ ɔoK<@#qrfzՉ7ng`cq֗C'[G^<޴!sh~i<ޤ >7!(k"֬O/{`aB&:NyHqi-f~Ir_ﶂ655p."Ų5 +({rd}%k6-~xs?tv5lħOH%6q& ZGdNG{\9I;`4I 0(YcWjSeWò焗wTN{'$s$HŗPT {1گE`(o(W]NRpFah<b"Mb TK*簻/ҩ9ůX&jlLz ֞%'g)M,_1dpk!$ќFPz:&,|*,iLJ#~{cx\SnCd]"O%3}*.5e7M5>Ȩ;s} FZwQ|PNRH\ tmqM*-wl2AO:= |0 0 SygeT[=s «aDLx(ՂڞXcB>wb<8hg*/C_Kؿ֛sT6 ݝmPsU)h4S- 8"[1@ n]c\pȏ tA-tLQ8.@UH֧budz~ht35G`|"^!EYR}nn~S6*?WF|4OepŁ,tR]ya9'_ YZ