container-selinux-2:2.107-1.el7_6>t  DH`p]H$ƨiP`~(/.i)n*7c$LZdmj_Zmx-)1c 9=QZjgeMcoorG],Kް!2WMUƘIrW (\\gQv\xGkC._,80؇[Dp:{c?+.jȕȥotZ2R׶פz(hlWw0iwIw0GR'?\Ю3khְ<'imUݔy6wz 2{8sGql2zIz]R._1*ׂ,,`6Bey7 cQ+{U0]` T6m1Rjj{ 6e9020d76fe5fa6ece5c7d3fcc8e95cabe77578d]H$ƨo6*\$7M DB>5Mr m,&G sJJȍœw TTyZc6,x`Myä]}t?ΈRNٜ6|#>Q3ٚ,r_[P}X&(/wvB4/ `2#Ų3:BЋ˃T̊]gÉBP{ +Ȳ4ĨN4U[| w:z8?w*3?g68o9f&;`"# IS25USMž$YfPq3X=NEn󹻿zjr2T=tIλP gnF14숲'+,&p^RZ*Ӈܰ+h S &W#Eק砻ҘO1G\(R@kl/zہ!L[Y/sO%qޢ`P'g2&Y6-4u>>?3?3xd$ ( P #*  8  H  X  x  @  H h     8  l  V ( 8 F9 F:F>/@/B/G/H0I04X0<Y0HZ0x[0\0]0^1b1d2e2f2l2t2u2v3w34x3T3tCcontainer-selinux2.1071.el7_6SELinux policies for container runtimesSELinux policy modules for use with container runtimes.]HFx86-01.bsys.centos.orgqCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&G=YA큤AAA큤A큤]HF]]HF]HF]HF]]HF]HF093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d8491a1d23bc4df52b6735a5d3c52f1148999a8108d02557774495e4cc87beca036f6566a08b292c96be1bd93bf7f15cf714fa799e9570145c2ecf4eaeadef8a1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.107-1.el7_6.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3]@\@\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.107-1Lokesh Mandvekar - 2:2.99-1Frantisek Kluknavsky - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- bump to v2.107- built commit b13d03b- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.107-1.el7_62:2.107-1.el7_62:2.107-1.el7_6 2:1.12.5-142:1.12.4-28container-selinux-2.107README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.107//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,९^] b2u jӫ`(|#ag?)@^%g$Z_Diy72"95fM0`?F5+? ShS {2Bx|HݦC)o,Cz܅\;.@Ă2G3pP,rtf QE 94$޷=K}Lۉx)y(ӸU.+SJù+P0Ѝfz 0I,ί%ZO@=T?t  e4cP3Ήkƙ~_GY`$T2R¢c*^^]+zr@H9ϓ3Dzf;M1J:p &GG77yIҾ3WQLaEߖN?;X8+z@rߚ^]ewH)-o,PP8*p0灞6Ld T Ά +p}K鰏3FvUrKLf`U7nxJw}hvϳg3ǵ\v ^G5',dǶAu(s-Iq#wo%1s#?+DcemM&7 ߃2"d? * ^PVcBLZ{T"feO ^W4LU1\,uB ;_jcܐWwd[ V` b-59Inu'.8d4/\:ifvOchs{1Xo&{nwD le3XO}1\50,'MF%?AS@I=d]`0+1lE3yO#ϝa[{?bi<0<|tN|/!G[,uUgxO x<3X-YswVgBFö:(U8 QwkJnhIGd"4A"7=0ub2b\A}ivw\˸\VP.QU-^-U;3eCM2&H–c{INLUU_I|@rrܴm 1o|Ž˧ɺ cr~kU 0u (T6 Fy/N1cHK52U$^e+ jsJو0(QrYsX=1M36Oi<w&ր6ݓwvQD ycKU8]7A&YAk} bo]5GF`N^Y]L?X &$oeX &cYO)wwz}]:\*;_z$wb!:l- -V%Hұê[dHf)*P(i##{;0C,tӻbX&HNRc/<'ZmwzeftW)D˕/'ш 0+,Ҝ/S]0G4q^~tOK\O̝=dzM]ig óH1\wd Rfd F-q"^i$fvcTTWNs>!0+"{^EZFoo.$.M IO pNc8k)ա509ZM<$!AD.`JjQy|V#`Y8! ;=?xYPUwA/hPY|Klu_l(88J%^M*Y XaI2.*.f <ѣ$bnX~Znʯ1qY VWle<ΜbYv|FO]Y9@_koKJP̬"~1噵0&y{ϧ >`ܺnSp3pY?7+饷ͳ귋 rm?szQ=YoGHR KGu0:|tpj25e I }?LQ 3Rq--rPk~asHYUN)Ґۖ6Fp׊ukjdSA _ {p zcs r,[ᴡI 7i\q ݸuvr"<z:ĶWC?H{jw8c,_EBYF<=^ڵH+߆p1.lͦhK VsLq<|tm^ t|LtLޢCy6S3DӉ.SuFLd@u DT|BReF%9M,A \u xαɸ왾:FҏI`.kcpVMPfՍL5d9WzAQ HT:&CAd6DDq@Muv&o=U)>T>'}:P%BSO$XUK 9ߕ&͢BGPOj+f 8hy&&M^$Mv͚ 5 FsdƂWY,S5L#D7K:{SPۼkS b#zMKu4*Q&4Z}Vz+y {8^%"IݠqedQg#w; J8+ANah[!hDQ/ H]EF VĚ¾W_ dI$ƠVtwbNd˹s 5'Y 6ɩ,jmWtVňj@փ-RCQʲ@[JX0Z#hƣ^:9*9j0PFʖ~Fm7t HM5ܑS& .ٴ3yq]Gԅmd(:@S8upah oKuJ3۹M kPFR>:tF_Xlӥ$l<܆=EhEƙ%$FuD[Vl9L+0Iiߓ&ޅ@vkr EnM3{:xV,8TKR|2pC2A)>: Ya m8mDN}WS-";\>6Q_1Syؖ<16HHQDr!'tGF#kkA3, B2ş _;-5rזGpY%a 9l"Îb3Գ.+ ''@OK'rd@X`7M!}ڶȀ"۩]g+ V$!,ړ|p>^Ft]̳]"hnsHwUI="Xy`lpbt➃: #:tLt>txr !$5hԀ:(cw 9 #]A$Ӱ4QJԀ9I( ;;$!L懙|q ؂f@Cpy kE#HI'`zLl%0%yƾA 2XMj*!!8(yc9+ '6B>%I/yGS v2.2Z仒{Q/Y(/^Q+=]739Z&v.tI%h x/W5t 4ȳ0w&lؑm^:_^uT@$db`#X]ULS/xSx !A%+ sL:ץŭ5Q'>v ΚoA٣]CYa5bg25b4ٌ)y62S2_{ᰨ%÷O虸$ċb$ I{yB 0;C1kBrs 9j`b70O ̓ ,|d^ HQǢ磿.Q}` QS'vpG{R|6k]s3&+;5ʲF+PVz =7ô*Hٮ65QO#d䀔qBv%"(jq(6 ]`:8L.nuoCV* :I&K_Y8PDY('K\t]{U7ff6|{I%-Vv/|f5Ki!D<$ fsd?RoXaYhtX= Kˤs72.=cE;f u6C&lnH&?>HX 0~ #{QM:6IWV1" ۟#0gVfZ]|"Y=jSBZۨvPů`2GBý1H5o.S/Pa}ho:fB]H3,4pSa^* ?ш]E/-g[AM@6JB&VVYWqn"̶'h )j,֠TKTGªPgD ^za/*bNsAJ[q1=؋{bHBp>ά nVsgГ |͛7ar.-~3Z^KdR{Dz$+)\YÐ]BRlpCE)=+IӒs'?z΃iX[ZصM7=[I1nw ^3?Ɠ6?:Dq *Gw蘡 Xi^X46Q.w`I##xZk%_b)mN'$/#0!ULb /g>3&vJMlMg#^9\ 67XvϝoSjwCBh/Cz(E 7(Țrs JRnpk;wyQ*9bDlA)yOc_ݬ} 0m' Tj?6PIǔ+ZdqK1IT/Ws8Qh7{ӒEg-[mP&7UJZXW*P?> n;ԬG.{󅅙J:&\;?G]#tM1QqsgV*lV-Vg> fּ;ԞcPb.#77WumA^߬,du^̕ݭpqҋoe&?~{I4I}ɿl&D<_,UemM8Zn$^Q,2Y]D' CNעf")AFʒCY*W7o/*"JZRz34j]̥V"NmU *Gnym [=t4mUsAruNoh|rpRO6yKE\SyaxtRLNvZ ǃqşJ~QM]8R'B0%H et;i@u Ʈ()}?-TTx u!hTkLjG7ٯtD&8=.|r+7 p0!Hjl; =͚칤ָ*9#wAB-\x7CMy]HvcrKۭDakqy9"=QcN*^_K Mn6=uP lW+-2\YT0ұQո֋ <pģwx-;3T2n#iVVGt{ (qi} $6GJrř ˺k3Ծ5*$vͅ1Z繇$Бh3Թ#5tx.U V)zPZB+9Οܕ\\g˙0q&b3\^_`ź%9*Z`*8,YFv26)xu_&M8pSR<l(;G_$֥Ol2V-,4zPa"Z >XnhoN3KyG!V(2{7(Sz:.FbG_%l_|`ohŎD0~Rzl#4C6gѦazor.bJ>l|$77g7Io!%zNJA1'IQ狉)ydU"R.v=B Mj pd}D# A!f.a(7 ѻM|qޅ7MpR.)?Z4nl^33Uz)H4:vDV+5ȥ v ZѺ8B2vv`hƘl=\54 .kDUH$lg0G-wWHp=o_MU6tTvOUp<媈5r!kt% c{y il1ǹ-~{W#1m%hTbwOq(i?shcߙJ[+B#8| (`ljxMRo D:p.YqT%&)Twh5)0(^T_@("kZtà, Rwp(b & u'Fn(t/\S &qq T^ K7g!lNn>*6ѳ*EG4\0i&HQlxp`}(s ؅ҧJ=0%tHw"雯g`z-Z¹ҞflEBXmE83hEkCsySgc`?U44$ aq*dqtDl@@MR1(Z,P~D Ք6G[Im\@4EўڴWrl%- ߍ16L,RX"}F>|eFZPJ+8[SDl:>O%^wUr1O#prbRń21Dњn5k6+%-tU$ s] {U,)X煡w%A>n&8"C=jH9FrYܪ)2}жeqn}NYla+Ә-rAbg#,8&wGXW+ƇN2x BeX2 W"]eD % (+a*23бTYٙv'e _z];OMs1dph[; TM4]ApTn\ #Pi̅Ęuq\Q _/`ձYSm9phE ɚ4`wUZ j( M}'k?^Bt} m6xJq\(#$2+nerN\탏Bxt6 aN:XV€ۊ`η=^iAv; "zu//4U,x_@qs%:s}.R-cU*cT@ifzq^9 OSGݙvt8#3 Yȁ Fqoޥw&MgX^Soo0cLv w 0$SFh#;cXƮ~"}9 Jủ)F-}PgqƬ#qoٝ&X?*X(l6?:):n.wҟq5676`e ͝<{K9?5&q!0rq"mI8E&=VK ^1"ҳr7Tj+_gil63m;dߟV6mu_a}e0Tp- nSO$zj "iԛ-\J{E8r viGv*aadbX0-޼DY=gqt|}u[=@-RݥӢ2AgkEL ON䪣,1_MWͯۯW2c;K0dHЗvz_X6C Q)) gkINg3& !`Upbۯ_iUөO}C{|UmэFP?UG1ni?8=tܵUbRxg H64$jY*FM&Q|/{s^w  6)bYӠnJLRm&Nꎕ427`Hb$g8&ئΕvyz77Gj [Qם(fW%I$vJK%"K>n/xYpt.fzՐE4֤*A1ME}=!xc!ƬZY!E'ـ#"y]M,BѨ>>x4j^5(j%&N/ɮnkw%UJO O7J,fIeBs(,шXPAfVm)HDITL26u0f{ KϝV87Ⱦۋ yϪ,JHN)jh?s',kDyPסmɥ'q2Ga#ei1SHtGXhRHm=?o˕y觞ۥ$čWIJs]va~ ,Qmp~kjfCh"{AeNaiQ!Qj(leLE lW_k$F`g] Aw8FaY{ž;do5Hym?/Ў [`Ѽ!N`lɳ'd$n#¸gt]O2kulNyk;~:]kc1^ICީ%ksz#v/#oIMZ"~ϖWjp%vُ>&dAh%{ݞ3qT@Tt2F&%+>3hrl;^?'cys@ z6FS۲?ԃ1Y!Jr0mD2]BuİoHBD@9ƤԢ+!گMj?Cd:6mWCN0a6laE`WJ2E~&]1Ie> U[ۂ!eOq͐X@.ܢ !Qh|]8Ӓ}A3n{fP m߉kQV%T_A7'p 2ݣWn|pCBq^OW (`5"Ɲx(*jUtՀU[oՐRO$^C_)NfBHW2nM[_ u-[V>YXjek!3{?' L Sᄗ/#: E|i5־pE Q=}5q 򒵷5:W>`{{g("Pw{Gsii>V$I%ƀC9p)ҫ)JWL'\JrduÊC4L_ ,l;`Ih*R.7DdI\%i-'=կк\W$ awwܞdZ ύwހI{iauִ߲t3lpeּ>鹾TJq~lS&L(9vђN-ͧ#v"-^xm4ἣ*T?!Z"snD[g}kL6Bn6Ɍ+V0w%")?4-2Ri.o7K?!ږX^Y}Ts{{Omv`=Q0Q+T1#>$/2&Ηt% M7G|hTGTɥC% jx1O!ޕsWz"RF9a׏^/]@}PbR>ߒ FLʼGsQO+~Q_> KFρ: rz䗵K/?x,\u a_g9D)Z!DGvEB;LJ!~ZENvB}h`Q&Tؤo?Bqn Ejedk ߆h3~WwIt[cx섢k 'k ;՛`hDkd;h!H}\զQЂ9J{aYt'KBVd39h7%Q"er _cp%;C 2DߙR.{ =c]#gAF2%^U{̷! ,TV ^+`h䅎bOud;]AWS'|QbU^[viFt<`HTۀ<YPp zDmتV6\\1"!-" SsJ|E׋)6q[$Y}D{8E2ѝeCr2}6gQGL^=vD~dv7SV_$AB g$҃D\rC/+ Eu$\ʌ9+PYGr}J*$٤C<(9{0D? 㩅Kʨ):S* *LҪ8Tァ * ՘;hDܼwG5*R4Χ1uȮJ7ŲfEBN̡s52vD!K$Jz0ߗo9N~׌ֆ}qc*#( zm5etIqkR{Eakxy{\lT:ܷ[h]9R}LC?𓽵F0[ W(>tH׫꣗fxSZd$!d`{Z {;$c31]= ({OQ[C+f4b$>>̜ *^!]WLqF)6e95تf[b=^m? [ef~/6 `(=Cvggoz Z K[ۈUwAqOz@|T\I&x &@!r]pmN3^s]|ɬwHxNgNO(^H-Bhoߣ11Ri|ω-e#}.SQX2 =7g8=k(؞~c*V q/0@i<{r+N|D:VB O"Bi0lqBun* zaCoQ{1-)T`o;`;ķ~ul9B3m l 1%ZM 5X HP UDIS`}=y Q9xT{TfۋU:'hGܫ5!T,6 LG_`q\Ǵ1g M1:^e !+ ZJI9.8 Ɣ.P0]Ff%s~' M-3̳i4C@!8;1{t_a{aq%}Ò7!Z+"̠[:l-3ө5ՔO>|ڇ^C^j]q ѕ#3o 倧_ ouo"iJ(VNVXJZۍ<91?jL ,ñxEޥ3U4C"42ՙZ˥CPw{}˴<7/s|REa$ШXSQP"=\Qdk7fѶB؈BE; Sygr5 ok zP!^╕u%t+bL_nz vVJIȎOu6a.-=ĢPݡz@[L}-zw7Rtt~0\(C9֯:M &76ٓ2̺&#:Eہ(xˍn n&N1qoE3@mr{ rv-4}6U(D͗S3'}W7`1aդJ4+)Ḍ=p[gr Tpo\WIOYNF>y* q-(8nQXU/%8[& j}ܳL($&E'kCPXJ|;6 b]_/*xl;]%mx"WO 07Vpo4n|k:(3Gw7Drul:uP(i>;vl!{L"(a:rYbw}$'Zk4waQzZmyNup|}}& tmV`DN^2u[@.WDWZ 2R uUW?m=Dku SCȌxNHڳD͠e8&@DMo^0#Ǻ +=s:`ՁN8m^#-6I\g`SsM`FNٺR1 uQShH6 6׮ {͕0W^ {:QȆ_^%ΞIak*d1Vxq~,vGGwT¹%̤+-ಏ4d,Upщ̳ǜ )ePI;Z[ +x?ke;dSjC  V)J>y+^h*YM?0)n$GrHni3pnwP~?ϷdjA ;X`U3TmV8$&j98+ ҴF>Ev(Gc{UM]qho@bմs?CL\mK;pѭ@ .)A+)1f!܃l,ILVlZUw[*evOFu:\1%l_kkr?K,uT2+t '/fqgxUR֢db>GhΦUYm{u+c>Q.Mv9;jq ?nyoedzǝ|)oo7}J K_?a}WLURF!Xnp>du"{d݆$NM7DZ!2J^6X,YvS|؋M`ؤE{`dP^kBKxEn y&}dl(|dV~Gq+U JO)?q‹B8 P _PݘA(:4|`"55/H=Ta?^w(d{"C6(f۾VmjFiڷSKy& 3ZfʊڍˬB(|#0xH`0a'9 X? X!י=:ap$YexqĭT* ]ec/j4$ފ2鬀T Hss?e,_!"4 ~ޟDY z&"zdbh5c_ cnyf'9j6$0M@"ųtpLF01mHgQ ćI O4S`O <!ݚ^&L-Re&QD_ .\"p7| dY9FoeS>F$j|4Pz!a{f5wcJ<FtĢJkԮ w%tN.K=RɒJ̞#W#[^}eBNp4qCe Z>_Tx WiScV9QFbvMe ObS!BR'-m$ȉ0CX|Ȭxi ^S(w[\Ox.) Y3$6iIDX)pN2y Ԯ3udȻ̲B@G4Z+Fr9sٶѢ򛨙<&u6u=ۯm(cwFjFdN?L "PcgW]ƈ?USul,s(3#)bkH~E/nэRhEg틔e@yhժfp݂#Jn"MJ%sƀbdb6B'4̏EȤ5~:y-6_ KM/[@^=v~S@: _! >~H{q+߄032t*%;PR* tœ=+̠k1CXHY8QͦSJ~Xj(}.6E}T2[i#OTPZ:n{Fs[%?a}MjUH7\]"QC݉Eܨ$˟?[u~`_(⹺`Ѧ4pIn'ؗOxY|Þ q#5iW rf)ó =t¥VHS[o71e2F1{ E;q\BVܣL>;y~,ʚIВ{E!IIj #bVO;\i^,c>Opgؗ2:Yxn[nŶZ 9(Fț.2)@6U>:I*Ld{m7O}eΏlNs19[++W8uMr #>֋!gAm\mNuF`17\#jma)zO2p.|TQElD s-G@|ϟ,RKԎ\#ºΒwQρFp?Q,r 9+˅hh#Tj7I@Y4ϿTﮛhAdKxI=Q~Dz+~颧u8Ԟs3ߗ:á_H#Y,ۍmg`y-?ձgK9sߝ%HWTL[8kD6 S ss]575&W?Hkg*Ӣb?R,7x¦{4.#I$=bd܎ iʾi [/y!)ŌH1%E&@OpEͅvU}JPG׶ZWȬMbnyFVʺMJ`ޤWJa_0,)HN9@2c%81hOJs%{nM Fp 1 TIlrip)򽊑1!&o˺%=^ ; ) 8ID6U 釶I0?1d!%X ǁDjQ4,7AOϞa~`iF5$CVIwY=!ڼ_SiY;ӷBLund=W{]`7hWSڗ[{O -^XߺN@s8iOȆԦkooIx9s.ؖbӻY'*i>] ɇş 9Ax@ѫV:E`AL2 ˝_(&BmXД_8&n6e4brNqà23ɨk0qYhħE:_ٷ%߉ku ig .4YZݬ.8 gz87¹ ![ULc$sFGr`4m!ᗨE؞!~E(zmih,$rgyH{J>'V4w:T8D-Lܥ[ܕ FQPg#ʣhFkL^0~ȺQU#;ؒs`:i/<(=SSRqѩJzyy: ֍z,5:E) D!L;T"fݕυ1꼾g[FBp^FO/z\Q̈́,ҹ?n_h짴hDGG A.t=L[7Gވ+&`M 9г*-S PnJBl|faG. "2nIO1OA6CLcFդD\F1.Ś)@YQb2%bz4~ai.\Kke4Gq`VJC\e*}'M|` MѭNi$do\ x{Nm^=s= 4h9|"|e.ܟLT)UYIEXM!fGf%Y=XSWikQj8@vvof(y (BۥqN$J}I8ʿ;x(P!JKIfSz{+/Kzc3t]"%[®X:9,6VG:O:Q Eߕ ⽔`^]}k`ώ;5 0 @/4<2| 1Z _jQ)`~lb}/G/t1723(z˘A6VH̝j  \6u۩qFVS.VUE+SS伜+ c6sAۖFs{,3J, ׾鄣٢o-ǬEdFU,)V|:猺gݢVJ]zJcQlh=)|q"Vk dйebuWK10ޅmrځǗ(ѱ*.XFIPlx)ko8[LrcjHQY!SDrh mk۱A*t_Y?KK Z/bzfEi)GWr@Ey7Kt HDݏ"_Qک&lN<q/dWJ9+Aid$_|gw,٢ǒY\,ZZqq?w~ 9f0˺Ab3͸%iL H;gT3ra<ԐoS"R➬Ue4Bx$?GkݗMs V]UW0լK s' ]|U1u +=QT7yATeGṀ]* /%TwB"SRdM wD_Z1:kgs{휖8^F?tj:!;Z^8ra+=cv@Eژu=B?p!kޔOl5;B" OCrDʽs` %+(h՚S۝ӢTrb= oVX т}F Зy/3%%7Хb-_q*""Uz yKԭg|b>7hO0j[hrۯTf,2̳Yϣ㾪&|6XGEo\6F#QpC"Ď[qpH)P:1ȼ:ZէF. `H{Ѥ$I4kt}W^>,~5!&^|Q]4 ʪ[| lQʂiӸa\vNNEjg>0Z-;]$,d ^_"`kl%If6v=Ȗn .MxyzW?pmYP*YCLm*}S}Ȁ&H~Ȝˣ( !S n:G1 | G;f1qT&&LnSUpjg:0dupVDմ'f}$LkoVغe w_$pwW)?t74̡mV