container-selinux-2:2.167.0-1.module_el8.5.0+911+f19012f9 >  A a)NU]tJq1mcmlY|=TN MOEWovBG{ 6)PnY_1 +K@h7y?胀@9"G%FKeZlF4,%ߢ\PaoDȌLS9Z|?ov1 ڿi bw;@mޭ0[_t#^ v3ν,+! 3gL1npā 85~vtF_.,u#|/ǎ ܘ&iנEoP4-37\^cXz XUyQlb<̥Zw!W/\cLx֭xjAMaٟlG3'WGkdJUlXPanó`y"Abb mk@Mo^ɸ*U_v/Pf8̗@Gtj( U wXKsH=wg3'E8JKԕ <al Ltj,>Nl!dFss4s*ů ~mki5'3SHzlS*{y)D\/w\>;nrIU@+5"ul}v #+f.@HԗP0QL8fy &5m֝G74q;+_C6m\XBGDόKNpal5(.,js l/@a_jk4@تOU|}t6& =@ z!DԺŲȢaGjr-ţJ=#Ċŀ>pFO?Nd< @ h 28?x   (  <  d   n   x     D  l   ( 18 8n9 n:"Rn=G>G@GBGGH HH< IHd XHpYH|ZH[H\I ]I< ^I bJdKeKfKlLtL uLD vLlLNjNtNxN~NNCcontainer-selinux2.167.01.module_el8.5.0+911+f19012f9SELinux policies for container runtimesSELinux policy modules for use with container runtimes.a)Jqx86-02.mbox.centos.org$CentOSCentOSGPLv2CentOS Buildsys Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types > /dev/null 2>&1 matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi6)Rc'A큤A큤AAA큤A큤a)Jqa)Jqa)Jqa'6a)Jqa)Jqa)Jqa'6a)Jqa)Jq8c04ac861d425e9947eb5bc06c3125d682dc981f6327e789ebe1c4eba0d856fc0389dab4c8de315b75e65f20f4e606a015aac29056e561d6f7cb6aa588f431a94dce6af8d6b1b649d30bf5666e4513933948397b3df5f008711cc4365d831f28b727012811742e205a334fdbec048071f9c1da9e07da88503c521301217f1148rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.167.0-1.module_el8.5.0+911+f19012f9.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux         /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sedselinux-policyselinux-policy-baseselinux-policy-targeted2.5-113.0.4-14.6.0-14.0-15.2-13.14.3-9.el83.14.3-9.el83.14.3-9.el84.14.3a'@a&0a /` @`9@`Ȗ@```q`@`@`N@`@`dd@`Y@`&m`_T_`@_%_%_F@__"_5+@_16_p@_5_X@^n@^Ӝ@^@^^k@]@]B]]@]|@]@]X]W]R@]@\M[[ͻ[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.167.0-1Jindrich Novy - 2:2.165.1-2Jindrich Novy - 2:2.164.2-1Jindrich Novy - 2:2.164.1-1Jindrich Novy - 2:2.163.0-2Jindrich Novy - 2:2.163.0-1Jindrich Novy - 2:2.162.2-1Jindrich Novy - 2:2.162.1-1Jindrich Novy - 2:2.162.0-1Jindrich Novy - 2:2.161.1-2Jindrich Novy - 2:2.161.1-1Jindrich Novy - 2:2.160.2-1Jindrich Novy - 2:2.160.1-1Jindrich Novy - 2:2.160.0-1Jindrich Novy - 2:2.159.0-1Jindrich Novy - 2:2.158.0-1Jindrich Novy - 2:2.156.0-1Jindrich Novy - 2:2.155.0-1Jindrich Novy - 2:2.154.0-1Jindrich Novy - 2:2.153.0-1Jindrich Novy - 2:2.152.0-1Jindrich Novy - 2:2.151.0-1Jindrich Novy - 2:2.150.0-1Jindrich Novy - 2:2.145.0-1Jindrich Novy - 2:2.144.0-1Jindrich Novy - 2:2.143.0-1Jindrich Novy - 2:2.142.0-1Jindrich Novy - 2:2.139.0-1Jindrich Novy - 2:2.138.0-1Jindrich Novy - 2:2.137.0-1Jindrich Novy - 2:2.135.0-1Jindrich Novy - 2:2.134.0-1Jindrich Novy - 2:2.132.0-1Jindrich Novy - 2:2.130.0-1Jindrich Novy - 2:2.124.0-1Jindrich Novy - 2:2.123.0-2Jindrich Novy - 2:2.123.0-1Jindrich Novy - 2:2.122.0-1Jindrich Novy - 2:2.119.0-3.gita233788Jindrich Novy - 2:2.119.0-2Jindrich Novy - 2:2.119.0-1Jindrich Novy - 2:2.116-1Jindrich Novy - 2:2.107-2Lokesh Mandvekar - 2:2.107-1Lokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- update to https://github.com/containers/container-selinux/releases/tag/v2.167.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.165.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.164.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.164.1 - Related: #1934415- fix the build of 2.163.0 - Resolves: #1957904- update to https://github.com/containers/container-selinux/releases/tag/v2.163.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.0 - Related: #1934415- do not use lockdown class yet - it is not available in RHEL - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.161.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.159.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.158.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.156.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.155.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.154.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.153.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.152.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.151.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.150.0 - Related: #1883490- synchronize with stream-container-tools-rhel8 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.144.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.143.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.142.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.139.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.138.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.137.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.135.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.134.0 - Related: #1821193- synchronize containter-tools 8.3.0 with 8.2.1 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.130.0 - don't use macros in changelog - Related: #1821193- update to 2.124.0 - Related: RHELPLAN-25139- implement spec file refactoring by Zdenek Pytela, namely: Change the uninstall command in the %postun section of the specfile to use the %selinux_modules_uninstall macro which uses priority 200. Change the install command in the %post section if the specfile to use the %selinux_modules_install macro. Replace relabel commands with using the %selinux_relabel_pre and %selinux_relabel_post macros. Change formatting so that the lines are vertically aligned in the %postun section. (https://github.com/containers/container-selinux/pull/85) - Related: RHELPLAN-25139- update to 2.123.0 - Related: RHELPLAN-25139- update to 2.122.0 - Related: RHELPLAN-25139- update to master container-selinux - bug 1769469 - Related: RHELPLAN-25139- fix post scriptlet - fail if semodule fails - bug 1729272 - Related: RHELPLAN-25139- update to 2.119.0 - Related: RHELPLAN-25139- update to 2.116 Resolves: #1748519- Use at least selinux policy 3.14.3-9.el8, Resolves: #1728700- Resolves: #1720654 - rebase to v2.107- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux 2:2.167.0-1.module_el8.5.0+911+f19012f92:2.167.0-1.module_el8.5.0+911+f19012f92:2.167.0-1.module_el8.5.0+911+f19012f9 2:1.12.5-142:1.12.4-28selinuxcontextscontainer-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/containers//usr/share/containers/selinux//usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2noarch-redhat-linux-gnudirectoryASCII textUTF-8 Unicode textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-885e9363d67919977b8e809e042ce580232525772a7a6c76beed9c932e5c33101container-tools:rhel8:8050020210827195155:faa19cc5?7zXZ !#,m] b2u jӫ`(y-qNMeF,)>SJ+~.DFm!x@2/ys@-W6ɱp!TߩZIq-%s:FmEZIB:O dYz9_ܥOfW1Sʩ-6 29ЭY@Qf xsUl?` ؙQTMI{$im_ A516AᇛO=էy3?4ܭd[sqnxZ( T Av-76SSRdg,WgkBGZL^4(!|j˹﫽Sq@6Y3}G1rAhє꘠i) 7zz%$o '蕆BNF[!qʭ=xmxD6  oB'Oרė"n=M2 l/<v:>X%] AI2 ZG@$rf`#$=DyW!XpK &L^kpJb0ՏPaWX҅PψG7gD+lqB pl~<Q hW "ھvz?(*J`_Y&"5<*}< Q\c4F;VА[$}~4ii+]G#M4dmiįk2G!KZ(/^}a?o}2;BTl6<aeE/z|՜UC-bB;ܞN#O9GtQ6Hwgwz1/%KKD!fq(^͋|POވ%+P@6\]AT#ˑۺ$9@j{$8t,:n8J]g|&^M&t؀&V.'܄Y"ft P">tq6!~ Z-s0LwY=N6i&?dV͕lnv o*TROCR{ ǔ' BU`!U?썊;^dGm2bW"vh7aNjƘrJgAjc?!ME-`xYS hMJ@ yw Jߚ}C/Ԥ@f5z I2ïDv; "$|0*%чĜɛhk?\Yc/.W#K;Q=<+@é6M;ɜ77ݕbGj X&2DIF"2Pm"Tx9OZjY.B~@k€n M"Ap,KA~k̤h#o KSЧ81ԙL8 H?EU‰9zcl %vqj;Y^gQKs{FNLf9CvWG$k*׿ ꚵwh(V; P^9RA5Rx%*LwOkRVnƔzj+o_'I]~*0N'Q]H㞥2w"͐* U/sTeD0xB] 15"}lH݇?жu`V[Y5ƣX@ag'fِv, pvr&ҧ+JZER"/f3п>%GJg0 *Γvg'\>lbdJ+RHXa~/ N- 5q)bjx*,r"Yߜs_ؼP``JzLQE  Eg8}r3* (hv|`ǖbI2&QdxN#CѢ;<~V$tmȣL-T̔щ*7+/"Lc >|Υ&}슃b Xس5j+4|Tc^(t Pc 5~c52 @?7~:Uƀ4Ӣ w"3jʼ6^*黽鞶Vn+e[!DE}^"%aqN4dNYu&0<sP6ZUA" @ςs e-䝫aPļ $ S_:Nl攼D䀐KEcߛC;¤{,m\H2 ÏazQVV #xYӝn0j&FS0ٔnN4> |S+P`7(vG9t Lc?6?q#K<+L]\tr/=FjPH!bΈ2w5ɒ[ˮ~e(n{ҵ뭰o؎$BG>S9S"\eN{cEJ.Zx.8$*B4BD WW;= 컬0XIn=fv}K/a)7M\5)nK{|Z2Ϭ9,=sUa2LQLE/BU`҃O(%r`dTYԒh C2P VP1AD"0YgUOV"؃0JDᅬޓ\hՇ{zDF=Eh0U3?r$+n Xp״.Zowx%;S?&_/٭kL UP줦1p)n .hp27}*?E4{6A c`ґ %n<aFhUxȯiSKASU/!Sh0h=6c^&vD3L,= fʲt:3~'Jp(̊S;cxYc%Bv:0mM\W5YH9ϼx$'xeO^C"ic_RBP?Z%h{CX:$ i|fqm@̂8u!I!{dv޿np?Eہo xSŤ5yP[E}[=;cu ϥ6%|-"p^ҙOT=" oh.љjhљ ~t6!)vKlP}{.CGK KHM,m\骶Ѱμ!6 7+!<^FCZ#ΗsM|O ü|4후 tE_Cs;uEKAg^ c_F/}z}BU2Gw:ލeawp )9kȏO¢i vֱ3"c(H׻g/8,lyf*V)}= ƞIn4vw~Vjy᭼„,Y:VNgNqDT h3C$xʻ$|yJXm!T:D^J]VTK4'GUǖ_R2ZlX-^='wp?J=ravLZ NR]$TJ@N>  OPTC ?M&ث(3D3>/nmG|X)Hv 9$i.w&@~ ZA3u㊁ܜ;Þk W*З Af7rvsI4 5.3#Q-.$̟<ؒ},g}n]Q6h`&lt4H[?h^^@/_X pmK&̒./n1y"yjP8] _7s@I #vNqv1A6 8ޙp*H֩Q}qǹVu&/c @m,Kr|;Z}6C Zgjxsig+HB,-NOSmAX!l[_ƖMOqyEp`YTDJZ'LMH┸pcq1_p^"uRI,2+.@n@G[^Dr6(Nxi'/*R&ԲfJ'qap!.-߾ U8L.*ZI8;4So|# To+FK4ih'˙s.UBnTĸVS.jGP-Ε򄭁XSd׳:@Atgt<\@ry`@-頻Q9S t5G PU.a.j,X-KE_+&D@5c2]1wxY@feXQЏh;{ѢO||q+ oԎsE0p DS?=2Pub^sF*]5WpB]⨉A˩rPAg3=I|% {LU(Y˝+E-z !Ƞ 󬗢f ^v"s MW۽|5KAL[;fRƌ$ TjM 9r+e\PiY iqb\5S} Q%?t*)Eݜ@.$~͙E|@)oiI{m@ iV=f6_ @bE\Qf *:AV4lW͎i;3*fڑ_UwhHVØ&oֈ/)KkZ@L ;1i% 렠+0X\kd+Gzc?_ w HvӅ8L$ HWR<J#._!x@x׵j;?HUu/iVlu XB{'Yo`u^ʇZ86hCN\7}tDž }en}=Qb~ntB=ybȕG Kqf1s-sPd|mZ:U)L'7~" w +=Iϼ o_ t{rm׾˚<;|TFJÃ&5nyh3qt,ؚ[}s~5{a2yBL7$ /<I:ӢSE- 'P+#~m$XNM:gfXCO+N-]k02 5Qfը=<~ 'JfzX0) jS-"!PǺ9?/2$9p銛D8D d70e߭bS CAc*m3;tFm od1/Xkku޽?y;Ԏt4Ϲ=$飒2 @FkoF!Tb|7e囆 Odst i4:֢r)Nus(U lOK$\<ؼ Apl#B^w< I~UK/MjkŲ5棲_7R e#-LRS_95iCẼ~w};%?bѣ~> iT) 4FB6fKuOj%D?sL_,8X3:C1OŐ k*bhEOȤcRS9U%Z9Ƿ{Vیg׬FL0_H 1"BX 'n3\*mB_Gtx+ұvDtT𘤅"bL\|0:z= ;gPO&pzD8!mG_=>ە:bCCkz/8&iR-DvTJa$8Ɨi1\51 Xk**LJ^vZ;GwBݖ+IϑHdr`kUd:u{ϔt'JFսVw L24㲜jg:dDy嘓yG M^c?<8g);i[1<=_dA:ɻG/eN{9j7H|B0$:)&zMޓ WO c,7NQ67Hu9L|!t:"uWOK$zgQX%+cFM*-2fow>@-H+2%l0yMz>5D?94\JVD?DB%Y}IJ?F L+G 닖9p;V#w<>6s/%Z!<؝KuYh E*J70&M쓶pzrȴˎǐ5XWJX,Un-cv$9۔8?d3aLURW1ht*}Ow- SCշW+bW6$} 1?FU\g7nB6^t{y^CzvhKԁȔV!W;,}oZO4OW0z"ryק OB7@  ԈyҶ:2{Iة\x;@3KK^ڢF0#K":E;u[eXoZH>Mn,ط#qYLǓy20=T.5i漆빺\&N,k q%p[Sĺ5Eu5"YM ^%?ء'=1f(67=*$EOe.@O9H)`WMǧyK9nJ9`>.'. eݟI#:j'@ʣm3Oz1}͐%Pe1SR 0l2KZbkg Ykqv';JRc 2ǺVki$ e~R=^ c ,[7p`s(Y/}Juyd?~&ݡ}=}bng/ؾPc8(Y"1gu tZ\'G7Vq;[_5s RNYҢƑnIfn.}$ n@.M`׀\v9 AWǿu?ifoXhZlJ$ "]#,N̳L1ەV lO NvB78l]sCDu EmusMxj-D37u_ʗpS`!i=n;ZaDl%D,glYd.DhO) .Ѵtrÿ,$]P|_Yr"z!qDM|'-˫^Z8`S`&@[od"WZ+$fD`f+V 3v3x$* \r ߛCq>,=&B)*3/3=tN(?Lg3W?7(Je:5V]:[lAȌ#-PgS{gCzhצe'6]fk]N)g<}N \RS2P[K'8pb[ݿ&*m: BjUPnYw!hbZ)y,g0ARg>#ގ%Uޱb>HX;|+[x"q7r~{9.,XF Pzhf+E[z;I¨;+-;N2J+R Q.ĭ9ǜBOɭBӁ쾖عoYHa?rK&G̷JUz7PqD7VB✴V:2Z\B q iBd5P?qjR/ZZ,@!7i\z㗇K@QI#/ikl<Ӳ ͭܢ gc)7S%[U2BUP)9[Vc:?#R#^sdaahw蒡-j c[ :&$36wH4y<}lfˈ!p|1՟*8N.`KF42Me'xc _ eBPT ftk\"Ed}~ `WTN6񫭈҇E6׼wyuD؈l=2kr aK٧WԬϢWʉ0ʌRdb10lM9|ØQoɐcHl3h#m٫QS8r}D7+!EOhoߎbTezP8h Ӯ'u`p}9hӊc? ==Rrlc$-?Qr3k)E^eӹK}׵<ˬjX\u4ZF IM2m l:֤; @6J#PLõ?**?ҲZUqw2Hj|cb֙,m8AY7т}ez#=.QJgw"UqXG];9;U 3 nW2-,Եf)a,& 8 I>[XD@\бy? ɦAjL$Id[DIɋXeh@5"-4S uCs_ϕx̱kKr:$aH(U-OIvQY>v0M0u 6!0N-GNi[;pf|ZTSQvDE|U+VJ `|*=6UsD_ym4?=+jWJHMRK Jڇ6grw/ʓDA>*ܺ^0?$/U /t"V>!c~ӝ 'x/c!V'd%`!sf/#JUr_3f/bOk/2rׁi%ia{>3Gqi<GM ۗXi"{$~猽źIrG:iml}N\Ч/vG1%&qgMhv/fD#0Nϰ+M:@_r P(z0P?(~tA/X]WrqVF]8(+ ;\8DH6juˬvGO` c[!sJ${J Y1]H9 Efʡݡ1y5Yz|M u\J#]-I ӓq #/ca}.!wr3z{/t\H #4O *=4\=čdyi{&0-F\<wC{L֏β'wx0 j*2Z5P1kHC[CRn("ӏ0cO^l1 UG8x=# lzJI^:- ,vv@^k:/퐥8AsLF c^ڡ3C P>\7ga^AsSr޹د-( >g9by}pā/J=<0z|5Ih ny{%]F)VETcg7dRB}xBZk-+)Rɲj(:&$tq+ ZR'#R]:3u«9G"'Q_s7;Z2p6!v`oDeAiISN|eF kfF _ȷ)FJZɝOLo3,xk0FͥBTt,5֚RFʉ/|oeXh 0oKm `s7 ̗ؗ*8+/M;E= 9ІE`hF*l"|.=> e`LiԺ&1mH `p2%ˤG:)l35ǎM-Pb;*'!a2dYe/ )ebV/`+w7W܋=4l hk.网΂'͎wmq N$r_v',Hq5nv(ke Xdeg ru/BhnFC6ՔfZk4-(Ym_5ߒMr[Y H2γrFw@huϨB6~N&!zmf]egGHЌRQ 2n-FkHXP:r0[8{Dݳ򪧇Icΰ|l}[N˓9)ghJP?xh},1[Mch9Os+|'2&ySN1r;D9j-Ί =P@"x]C"Y`<"]UVgiI̶a QePrxY}q r$3[T.0}u䑱j$֝4z@-1dSi@Oh ьNMJnXѻytB biq{P8:Yffx-8VZl}5 Vُjev )A@}۔Ka{4muG -FiPwWBՓ^GY;p|TPb [~5:4d o/24${_(Y]yK7RZr)tयAhYke銮i*s,HZɸ4+h|\Jd ;Y]["O뾌+!7%Tپ9H\hILVLO "JFy)32(a`.kew_l';8ɤ>_),amG߻_, 9LVDjh\e!yHDVKp[)^wUNV}.h΁q)xWZH @Y-EͦDix +O`[x]9 sh:g>Jn!=JOL :HYQ$sT/BU4$?JK(u%>#Jވhi)kpwW\uM]a?{T6[g =)h `h8zٌm>uo.N;lܥ`KwiҲHd0Ηtz#a;?B^$Gaj Mmd]P eŶay{un*굙t@&b#,NgV*3^&:a[f _A*DVXrY:|8gTq/EٔrxmQz6MFgb?!:Y}wum` WY[#f`pxMϱ $ I]K yD#WHx5n `B%ɑ)^'ㇰ'Atmku{&?'IWО)!塆A<!>S6MoMMQlDF2Q; jAEEUS&PY$Ou8L?SgVUͮ5}M%Ҝbr''F?Xv8ġ.І.k}{5^$/˘cɼ݅^)0S`) U/!#d`d&ʦێzMYQ;"<o`nq~J9QO)&f_2g ̽$ys+VU.5PR,:KzOy 1܉s]Gx"cj ǬfG`%eO'mGwoQgS=Sv@fvq-&HWMfeWWQ]2.9|꫖I> 9K? V}IK))W5,OX5k}ߒ-3in8dX9DN_'/|EKk#}Vh΢12="FI謼Dp\걍k[E>?)o7!=$<,*D@zySFndU~l`Âܛ@9gطF.s{liR?neb\|vOq6@UwptLnm#jAS-bG3g;ƅXh1@yٙ٢ʜ5(_XGyP3F<蚀9\PqF_M)\fqrkpn!SpJz`)X ܒ>9gmgH.kk-~VÓ&ӵ 5f76pChhD`c2*" ʂa,=ȫ{] *7[5we/;6 p.+d܃U a\9Z@PA.9̒Qv)_D͘* PGF#z^PYt[w6Nr.$GV)\&ծY΀ӟo€U8CĔ ê"tI`e̖uSL#")#㞢^D4djݩuN2sSenUh|aOwMwӒ[f]ϮxãpXbd,ƚ(#m=w%ă7tf܁Z"ѓ!"]eb|Q=&y"&63pg@($t{AT* k%Èpx_{ Q)Bk 4H8ʻ.ߛ\?[QF;qS+q##h"8& إ|I E>2^snȬI'Vf*庋JQgqa=Z1,?'Aqw/F[tW*]pciLioûTLr+c.xtQIqW.2in;v<\D>vWfFBn"s[Dq~q2a-+rD]w)W,SR:^3I':0ɉ-*I!,a˙`y%qi;(ۥuH #CldJ*c-$ O_I~uq)JM,F\%pݚ$TWazu)xBFt~[z_"EUiCYʼn~#% *|sfGgmr1\=pJu:EvH}EZMFeMH=#d#͒;[IX}eS{YI9Ng(#|me 6(*9FZn;3pɟҿT0=PVHӣt'rg)᮪{:cX 35up/n~VPWp^?4E-;8r7NEu;3~)mr 7!#ɑH׳k[\uG;礯K5<Βo;<%Fpi&y/fa(#;GIN+B+8 ڒU\ܝs[ˢ8LR=`J^b+Uu7o 5)n?f1{zOwgp8IU?5Rm_||2_cԦ^GW9IG_ܐfef! x_AbmIz3N@XWvTBDu4_=1n^D[e!sc2qȍ8҆՝1NG5MD족K>A/"܀]z+h[$q86_Sۆv~,YRB`$|Ey*N 0f8T[] Z{}Ca1n*;=\$x#k=ez_/ :YejR~h_m܀h@jqLU&7(HȾJ%/ovT!8^kLɂ&=ׇj &|'ene<+NrLR` Ld]"a)!εϚ<'r}ţrFΒĔTUޕU9lY7$E< $&(OxR;I`VbVh?yt@ ChAwL^؛?*Qm#R`1[m`}Qm{$?ͮMD2aot(u^8Zs&v-c b!FX8I=쭝+$SlG҃w޴M2߅<Tf/e^o7tD{I@](b}E(0-ɫgJCҥmgT]h}ge;j=;7nV)pɳ3r^kt bN2!-igYW'[w3(rrm~rV9ڃJnf_~q:SgTpuD+Z'b%9ԕ PYmU#ivY.[UzBiMfC41xRۈIhjEq˔DJ*QGl)b;zh < ScY'jX^ptKXwZ^rR_#Ĭ a8>[(H'!U!52fdOiYhBeHmGX59FM# ˳~?SyO(ĞQH Q3/u|S*%n֫Qݶ0](gV-sSт!{{W&!/Rhrŵ*+s3+BTHaO9$}SJ,)7̬IW(ܹ͙VfĎFx]ǭQA@׷vk9@ : l45/w3GŔ b:@W+Ws P5Gvl]ی֬P=T6psSe*J1c֭y<8X[q7"QIΤ3JAaqN2{xF #r! `5)݅f%Ϲa11{zo8k_`ꙿ9"x UIC(}̢9ts,F!ֱ1x* 7,43'xK?K`7$\hMT]I`?MXZkIIzh~xܜ~2+Ƞŵqѱfa0>Jn5ꦎ'L4"nuJD)2J-]q /UY2$Fi@6ufp'8jڰ]cWS9}9}́q bY0]6o14=&c]n;ӕgY'OUw:O#7МǯA/QmQZ7J@ej j|`-*-V WVs}C3V&b'"Ė6Z%*@&#W1jj< NNtAH *R(C(֗( Hp'NnǶo'?{FeK 1AT:qnX;jnؚqbg6wUkSn ya~,&|$4Ĺ]\7xJۣL&NG6DDm(AuQ4d9N/AE}4Z&vozϊhu֔p2Dq__;;N.ރ! ׁ=.hc4$-%I瑼0tU݉UvQjخӹwuq> MZ\Oh% d*7#I[x 04aUp\7<k$]겴.YHSzv+ȥxMh?P>\_(pPw9)3SRPa@"he;#Ft؟<@q0t)m_NcDPIX? ]ZVdf,8< Nd-D-Jn~Z DRmy"~ˬY͕qCHFb韎} aVjs *|ê6]@"u*c჆GoV*[)p*Ƣ2ݧ`i~d2'b/Vy歟E {w~;DC:KLKg)Gړb $ [EM!O47ᕻk`rCߵO" ebBz̡+j7t9nm~jҳ|P#~lVP$Tֻ μW'ڼ|¥&!bO2"Z̗!2BiK|T^'V b }ӈ=^EyNqd9U]:Aā5_TU:Q0i>HӞus0<3!axM~j_$Oz{DtG Գv*8b܊)L iS)5RxU*Pv"3y^SnkWֈ` /qbf8 u=]zߒ324=ե? cKg I,@z_s\ t5k6$ Źĝs6z;Ll.8Qyexx!~5V}'lGK഍n΀c8-DWU}>;g=Go . !~+iEeKQOH{bكkړkLb݇Ց YIJ:PVTfx,fRC+ $ P^,<4FQ*۴TgZH㷧[E:^A5E ZFYan6c|>+!†@.XZCjO96we8P⦞yEGHIS;تiuxcWq5l 6H꺞{c 1c]`)ujT8rǫWd+IC9&ٖYf1`/Ϯ޲pl3m37y"48v+UK@oOXȴ8DMϴ(b)]uY1L\S' /\x@=!w?N*ev}x.W3aJJ%HӺ{"l>Nar"ibic6=J뫹)Y?K<1EЁWv\~ICȞ`XǕ]-iI-!I锕YuUn,a{SL|S-!u|.LւDF̛ iu=؞ۧA#JʄT J4"$DjxOp1{O5=TE=mw-2⸧BvKF?裹,qu,eX㿒\2ӟЄÖ5`x`&SbK~4o<<@L ~Z䍈g5Ӷ v ݿj"٠uP|t4;y\Zai([ͰpY:+pq=Ed.<]PlrE{Th _GQtd͡Pfˊ &F.F ؼuEGll˷aLvy03-p}YTAvt44k/Hf>EZfB?9op ffHƹl8[\y(a-_SB繠LK~=ъ+<<}k~󻬫c14 F'>4H{Y(T{[yk=gAI\W CZ%_-Sh[CFrya$Fؤ/QU"RsǽI8P=iwZ?H׬&͆y ">H[y$;5K?k?Bl31~T|;?7$;5.2.517!Q~R*|/3N']`MR4.cXQ}Ĝ2^ BEE\7#Kzf%2ж$ْ65yC_-їҊx .N }ObF9|c݂g݄]aa=Ĵ "Utsż[Vdmtk`_|Lq_6wd]Xx-r V]TK_ZEO5!7?oȒih^3v Ή\scVDŽxh߱{;?M Q')uq1ԋ:.8`: ob02iT'hW؃eټ aw2C-isd-?p0?E!a|yT򒡡MpOXT+Ϻeo ( 3x,L?ǩ,ŭ 䜬 $L"-,d@ĻW7 DK*#ꀺ}sj[5c>q rÈ"EeVwسLlAIAswjpS6JИ2^vtJ$VkĠB٘+}*a+,> +E2 gPh+ QsO鹸x;8{\Ơ*j'ȩ$9!e WI41rS i׏ >IZnfEd}\IC*zl<+fFE$)˜2r<).^>,4r1ϒܚ3.U*hVqPPaWۡЮ3qkUxa0Q:| n2"jXp̥_o~TL[A }vC,P}!>by41'Ui4;s55)ךkNzoiOW;?. ̊DL3|*D)0hvEjx^?ie+kp^qh5`c5pR(|مuDJ-Og!@R v6I [Kw٘U8x3KRCY<? o{ޭD\TF!pԌ$`#_]P*K١>>}q^ͥ a$$u/h+-MV rqy[3 $ۛ ۹S^Et "u222 4UjfEIu0Ջd+'%;6r@O'<LL’\)Uo%2 ÷_p,*7Q3-=g5s|ָJ~C MclMWMBHAid(┨ YZ