container-selinux-2:2.107-1.el7_6$>g Dl\tkq>?3?3xd$ ( P #*  8  H  X  x  @  H h     8  l  V ( 8 F9 F:F>/@/B/G/H0I04X0<Y0HZ0x[0\0]0^1b1d2e2f2l2t2u2v3w34x3T3tCcontainer-selinux2.1071.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.]HFx86-01.bsys.centos.orgqCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&G=YA큤AAA큤A큤]HF]]HF]HF]HF]]HF]HF093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d8491a1d23bc4df52b6735a5d3c52f1148999a8108d02557774495e4cc87beca036f6566a08b292c96be1bd93bf7f15cf714fa799e9570145c2ecf4eaeadef8a1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.107-1.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3]@\@\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.107-1Lokesh Mandvekar - 2:2.99-1Frantisek Kluknavsky - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- bump to v2.107- built commit b13d03b- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.107-1.el7_62:2.107-1.el7_62:2.107-1.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.107README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.107//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,^Y]"k%hĉNμ5#+mz qɤM{8ҟ"H(4Uqmچφ$:$vo;cE (WUkcAQj9IҐn$)mS'E]LQ|D82N/:( ˑd`;=.rz49A7gCzj8L% tTHPԷC6UU۞9XӞ0_ 5I2n*[POa2kR_$rK<"Md(_e2sFܓ໗k>7aņFP^iQ~G۷|H(k Z R.}i?=kw&mݮU0KRsVyɓ;0@O'N&,qQ՘>c&1;~o}tGn)e_bcF|3icݼoif:22Ֆ plW B}7w9!+wO̒)՜pT/{1q(no6|}_tѬ O]F60_0vn3Bq uANlQԺKޘb$0/nH&%B~z6~d{.JgQeg_'_Ӡ swo/<0o"Nȉ.H?bMV4%ԈNaOE KT͚{.I{o31EH[ԀÖwS}$ӐOy<⤚%G6 #;ʠE5|m 58R.a͇a6?k:CDPwJkRRNbҚ^ѹ'`˛m;rw綮BP^ź;@Wfz*!z64L"iPW`Un-&lopU+ۤ!=kG/あp}&w>yɕXއx, RӪr`wΩxOe wBYΛp(Rv~s<ިZ<~W1]n+]qɗ gnTm-v̑(kڂ(]DXtɓ!$)Q-aڐ;3kWf(eݷBEaw9%UvUao⼱A"˽#c ?&?A; Ł TR:7ϘɃDM]A-+^w/(^c܅M&JvOP$l d V`$/BJƶ9Jf1&ܜUh?`~~@jjz [waޱKC~״mY"F+] Ls-mAJso$y_eAme~fEiT>ec39 hؕM(e(e%^Gx\ _EV-bTzkb-ہV) SW6`Lx \E~p9Y0>q&m|UI_<4"i?ΚgO9`u-)W8QE;w>-MoVVв#%SJ-}pR@>H+ԋ3Ѧ [ݙʠ9AVN v!Mz"˼7`xRtde n2ɏU;(rUu44ifu\Q4ߑlUK-QiVsur!N~"+Korz\/R-eYJ-&h\g} 9>cmL`BG=8G<ISޥuoCAE|N@MK.`p?X W <7oEq|$8¸yH8h5N1 Q/.m {Fyߎ.˩`jR܂5!D.h.,EUzF;M?G}ό}7iP)%1OnGk0iQ60Yf.0}^F=F WTb2 Rsx. rM zrvM;m={10 Sae'>;q:! ;w솄tNM #+D-u\Y@CV ͹nճm~fm;>NEAg2hHsSǢ"'_?I)w/車l/4॒e?0 r D@婰De4Y(1W"8"Ptl | |$v/UN.fo|: 3d1I>!n`ɶ?G~xǜ6+"EB `<fNƊF8=d؛x-YNcYH")͢`ga hԅuk@n3j < yTmlv[壅0!V W DeД!+9c~[фڹgAE5FX>X}I%f]95=q߁I<a$PsAnB)G m:+XdbhaߜІn+*oY3v\{zrxU/gR9q>MU^#s)\6w"T*҇S](Ɇ&w4&/ ɬϗZJvvr#&~oRI#Yȡ*U3eꟁ%@}p*v7h2M`/ZyZ Q0mNOjzM&LGz2nrA13= K}pWP $v逄Kw} Ց,}H1"UԱS&ʌ*P~r.śv\rLf]A#3!~B[%Tik3:dT1.AM[0x_Sm˒  )%4eQV cBe7{ɱorf@dsKvE fUf]x[bmb޻ x,BJ*Ǡs4 /a~&\M"@TǜL@oے㶪ğ|AB8qG?4%$RY}e &/+!'qh*&74&O3+m1{uAFΖyLtI7s-uY"SlyrfjD{ l@Cˆ},D(8I@P3be2w{7ҽhyf)̡pY~?Z7$زGj*PJ(~ ,xWi"6`чX(Ud)ړ.F񾪫xu 0Em0Y#!.τ/ef3Sҳܷze#j^Yn!gNsMo5q,m Z9:=5*vcik.]7*KށsUE<oDᅆWD@9ⰹM$wf,Gs!nWt:ͺތYw%C~/]6 @u|m?u,0N:Ё;:3O$m]Ҹ[E A%-@-kgc|d'SCC$a(7ٹEmu}L)HmG6 Mtn~4etr;pn^ucMV^ΘA u06]1-#&u/yJIFT5p7.m$-A&i:\^WɋyQKFO#D[ r8O1CjmB5ģ%\IkԮѵ+|)iCa""_: W≦]!mb'A% &rvY VXN #qN +)*BbK#CJ+f} 1RԻ|"8j?RC'I?]a}oAt^ YpF]566RS%3|xRj-h@Fxz!O[~YSTN&d?ΘmQ_jhi$kaL Mό'ArtEIe燧wQM#ߋ"粵v&¥T>z?U|(|::a'hqE %Yo-i~-)fh d6Cz:2y7Iv喺Nk) V݌Ch+"9 }a p.ste|3٥Fw''(ړ{dYsQ&|`D+c)\8جycsxinKf:2lhcm\%*0; A%⊌g^K;$M)0Il !2vm9tha#;g!C(t_SU9,¾2XBFRt!&Sx"T7TƝi9 h,CG[3gDy-B)rKEC!)n=OQS:)B~n2`CD;2!aj ZLH"q;CuuBZnz M4Vo 4ޏ:ީ uf,Gl&\d}Gi/Pj>W@6H=^RgnvR#F̀<ךL~޿?BY֬:xؖHvtlO ctr/$KԩO괩\޴ {~)ۯvpJqD媛 Q3>\=pk`se>t7' b,Z)&$´C0&Y杔6u^!ے>L~"iV"FdJ Vn࿭R#P3ܓ2@vuBx ׋!_{:{ kXz3|!38@cK}x?3˸wvQZ]+ZJ$U@j ~m^KWvx'` dEuXL,007oFM+]-LY_7uxrn6yoa% hv4j+-45:҇Ak5߲;uQR{ }8`XLk7׬nYGtX7ĠV["llq+'J'ɶPe( :e7- a <ʅ[A0S_ZOx6M R]"޷SbAl^EdFmS.zě_&9[u3i[[l*1Qtij#h=AÀ/ZM%$Z0&R&A :b"@_tĢEhHLڎrVOȊE83̆$g eGеRaCu Iis2(7doTOK}s򫠛)(9c~-i?E>jҖj">TN+$$EtJW65bȲ';{TG!v-K0ܱ|\qϥOeyo?c*- r"~E=`N}/,pJY>`0tBCt.bDK@?wj]C-|b;W*7x za+uQڢnJnT|0We->PCl2*j(NpJ88pnDP #ڐ`=&`n0hYDM3E|S1ZH`+-1Vbi: +6<솵A0lx^3&u]<"1 ZckXO^'n>T*6U-JPFG 8͜U 5Q 0APTm&&r,e.ZbN1ԇJ{RB&s1ޟT RpOfJͩtgyWZ`ހA Vб[}~qu^Οoߢ`S.#\B:s"=Sa$* fM9U~XIbci8Y$A*RIӜFv1I)TrxSLT,Wrt׿.%q[Hv*$1#uACCJI#t>{ ܻZ#6V=k"6~3 @W*"Q|1goEM$Fk'k051 <<&1tҞ{,B7oNpΎK֐嬹#U̴PsV`dD'\Dt 3 qAw{VcL"p"D,c@̇@2٢ #{4p%0(\"LQ`?j]yz< FT;`s&{dZV_: NZͼtGƲ>c+ P[z2\ '&fJ姳U5P|gD'y^vt)&v2@68//UJ1Ad9:UFqRA5#W1H)-387މ?z]b@K*xO"Bt/S4mVisw:WD_aA̜͘,ЪI,ǕA甮zͯWC2(s !f+?^'cYW(&}:UM^Ͽ3L3x0u`O;}x gZ>5~5(8ly;Җp$3cEsڦMG0B.4$gw̚{f`P|(,hgQ$_BvI…\D v=.ֻT#\a ovfrjIN Ps0B:A) f":P/~CA? 1D/\L80WX^/R[W |ԑzGK%h؜Ķ[/f.æHL=]D!me̤rѾ3/gpmzrR|MIlh<-pM~}<]Io>J#"ͦIuԇZPn2j EFq.=H0SW>`W{AfkapPyBo CB6wiIGP%@f7S=owpICFTop==(IBj|Y_DFyI+=OS~c;v$Z2Z*ɺKPF=ktܽpk^ƨMSw$aC-9|;W5ŁrRhB+$Ѩ[ìJtTФp{,hHJnHp650iYZc%&Z*mUXu_= #*t6H'}?fy(Yƒp$_[fV[IrA#V(wѫtV/E_!wؾC]%"(Yfoaiװf":d[a;Y[Hú`/"ˬ_Vވڢ[8|2>҆4Z ̑ HyOsu([3@tu'$'AU>F~ ʫXd0@6Y+AeEOՉWb Gx$%:* jiw$)&tsK1â#OgŠ*.t !- , Kha<.8G".s"h GH7MJ>?b5,$u+7iiHt$RW'`?#i™:`Spw@ 0'nRu~8Q7)լ) -33 ܋#,ҊZvv8 " iJxi Hw!{9+QK$D4uT}]V;<ʘT:*xLo ;"n1mŧݘ7<&R>Cuz.'T줇=kM,-E-rWMW[} iu 'ϫQDb=kpW25[ {tX|:z&4QF6Wds"@_NY%XR)>"Z r _S*dX@N˥_Np|pxqS~a_ *-|H~ix[7O% Q񼉟8{j`ZDdV΄MmWFJay%RA}A-Dȯ6Z =?6IwgFx:J #b랅3$wdlq"EbCg$GWw5 Ojȯ"~}ld#5:c-9/;p_'ZG9ۉC!{3ԇt &s'T%ɥOj;'7H>Wk9>ʃ_+  “A7~/խvJu9:['B?,F\G#1;q]im\y(7M;A0tgTeuc*oBc<i}}@BKϣ*e){;I۞*2q!vwo5Csz9Dyٌž%eSfP{DCZX<#o5Ȏg; #;€ 3.8||댒YNk:8% =k-RzOjO P51E Ej~ؖgAr.`}Fē) *9l.&U҃:y,w#۝Mg\RLsJ&G #3u\k{est!1-,>Я=D+mfI{HBHU >9[ æ,uj8I/)#O">$fk_c>D,|\ ˹;LU(xZ{b̜P|Э{kENUSt+r|LaZȓ$;ԲAagt]f)?}y/ܲHM-)@m-8_3q#1.%aqI knR928txJ8 50.ÜӇL ;Fr%ܦe!c*UH,<\ϸ[nf55#y tepBiIאmi\ʤ~7Ua]~O>}=^n[3==p/pr)?Lۡkp F~=J 3`!Y ^efѭsAkc}&QK0wE+X99; ]aF)A*4^mqݵdt'mK+YdޱݺAL^h(d(siPSCIT?""W'.[+2jUvSdSI32T"xnꎊbΨ M(Fm Q17Sf16+4B<~?K lqXDu0Fo5n^ =<3ќK"+E`WԘ#BnJHU@`H&-p'͛5kL8_8w駄ODs[V D:E.'ؾF =`Ӂ}]ò휡13 j*ա?{uG` R!wŸDzIb] s/Ts",z&~X|mPimgZ7VjƂybAh im*tp+4S(訌BfbҿuzDS-X<< OS#j4GF*l? zvW C?K-5or-V'W=_Wh_OAZ$o<:ؚz(C;M9xrI89ˆF:|%rW 6tAs>F%_l D9@8}{OߟM=8طY (Br-74{Hu8zˁ_16 49(6sO+~PsVޓ)5[4b;BH>h? 5L&rg")ݑv/4AN{ȇ`6 $[_n֥9QbCFwࠄ V4vl2w`$񾘭Z%q"K&Q "ږrM! Úds|)wg-6Q_Xxo`^6ej[CQT:oL屰&Yo;v}"(p_s(tDC(FJ${<m1–ḅw<ƁMW֗ԸB^DJ[*w7z=\%79JJ- L0@.zǥc Jً͗$i{kw+RWcmQІtSiclAJκ|C14Zn(%I[}.2*N^.Omn7;}qt@lg?Z\*L٧Y" I{c*MSګrZr1y"Sb; 955㖕Cd\znhͩM;F2.m MsƓ[qMP":s|ׯDM *☿nqZ|%³'mWӸj|}ܻ1ل@!~SP" Z&öҷaŒX︌{ eHN:XǮp.I*tkc-}̿x\|_O~"/ uxڈףUNǿU,a ( 4E; k'[PM1HOgok=qQ :9dqI}%.E` F@&T 2e?ڔr#|,NRVՀ NM^a_SDPʃd꯹rj/m6CWucNyNt33s@9ҁ$uوNT~z4UxQ5ӜamWR^$O8en,:_D;>t,,Ih Ԥv/R,n%f^>`gH*'|J+(kmS/6R@5Nޑ~L L)"3Url%d@"2zd=m4y 1|sb42 *5n%r/>CbzsAAZ\1jH^1lX]FI (~W:3oERod7Mc0\SzBAnCbL1uM"'#~Qg@.9K҉=_iafrfr A"йPoGlg5?=Mmc-.YtY>C:]7-,m/x Uau&" Svt_d=eoG3aqsPnc/c:%ŀ6VJD{L;GNJ;5nK*~g`dj9J&,Sv2Xrn:}YqQF;n,ޡ_n -<#ƟCeqN"wf2pm][Bpe;aXXysld.^CC皚t=TXM9h 0'F!w#2)66*N>-P^%4)wiKďH˕_X]2]2Ko[^-B4ƪb 2%yzV}!1yg\&i<9V|'[tOhH5%#hǪ35W>`p~U㷡*->{WגI!vZ=!uPbv6&An/v\EQXL7HWO|~q ,OsB%mmJom8,8/N*t{7pvm9iܭga:4%b}|Oɔ,p^pJI[X5&-l}]89$z5Kcomy)Jqtgs[NJZ>td gd}hUhjd׸/Ոw6e~ 2wAefEZZYA  (} 6"$W~(j,֠0Uۑ&ƂrGE=[i&`~1J!Pͫ(G*c%r|i(۴<"E!>I*םF7'b=|r=RshۇYj,7M<%"BaRwa;Ez+)@. N9 [6:K֙(XVu WT81x"op^p+jmlTMjGU}wn&iRe#ԑgԭuP I4|UF˳W'D-6w;aJ{(:x=^dw,F!$zRVGg^c@#>LgjՉf.V5q4~Mе5^V?FHPg5US(;i .F.}+b:j0JQ>bz25w30+rroETQz/\uy 6Zw{awkl+N,BXmaλTUѬbRc[ݎzi%>UJ,˙ZW q%sq^߱Ӝӄp!*<& =4%_K1D9ifL_0yx'ŚyԉWL A*j $t˅NOry=>h_Ͱڇ6 vy 4I7fۨJ>[3-(*=tοyqC]sIQ(NJ@EPiD7iC/76.,¦2pV$ވVV~׵'~o[3VP)DDA[ Fd ִpǖ6rk`P;zz0*?aWX:#T[hIdѻ[ݯ"vܴ ou}p Ҙi5ťӐsEB?rC|h:3NG㫅ji<܍d2iw /n"4A>Hěǔb:$6 T:Lue;:\,pI{} *bqWdo<  < 3Ox(Fy<92%#\X;,ƨ1˶PZ(;b#.#jhKՇG_y)BPw?&Зt93I-Ujg@zrEުyo QUn1^Qm~ҍ| `vG/tP\y?-'Frսu7@:}IX+nH"޵{Ǐkf&.c*6D~ .ĈtUqQQ8t, xh;.!޹;9QGY9B:!*jÍ*(J>NێLbJD]nlMn:$R1akBS A]_|kD?*2 H@ u$:lҕ@0v{]NIu"+b`@A'WI2  4ܢ|TKVe~O6BHԔ& Y=&S^1.|.7>M8̛q!-jNbO~wB?ߺFo+3šy9آgѼdhfmuڔBۡ }6h"M!v"ROV~JG 5൛峛qK8N=4 :q<75R9wr!UP!9vKwVl$S :|^)eh9VRI@.!Ƽڽ$-2_+YI]H|hYsưDZ(HRh+Dx;6qœHxrfpI\їT@0s=+ό=tbޙdɬ™Fju(ޝln7mÈ I~=sgH,ec/iji^ xJCmgNBTo.M@<*o ;B ,6NkGKtzjDz̑>%A)anbz[;LX}SU%EcͶ$M/"W+N!D7{gS+TB:TΝ* e>-d6axzWܳѰ=9.$^gk~A `4jMBt.a|PmGIzQI9} ROG!Z2a O)(yW1<~CΠS.Y=XjPZ)i c %08.#] W{11"6\ \ѻЗ [ɪ-QLDDnyB"6̽ YZ