trafficserver-selinux-9.2.5-1.el8> 6 6_ ܉3!y덏%!E/֡f{ !E/֡g{">LF8M׶7},HNۚ@:՟mC.іNwJliN)-zJR-9aVˏ5;8"sk c#dKTdMib]dPÂcf{sd-h>sgN,Bߪ=n0?xӰ"4F]UYVc6K( Y[ QG~ m5mEZLdCdmH[Svtb ۦwmPL=f"c7I < |м70{EC̩``gUYfsc! `Gѽ(G!oL7W$zɔBX\KI!B."_'h8چ#G6J`PT@&q$iET<+@OF}?pއL?619 V6%j_ EجJe)1$! ;Rr T89860b5250f1ec2c7b384f9c8ee758f65c2a354263952f89b0e53cd964513dfa37d036a6a30b3e5cb4192691cf9058d65f2dbef1~tڀ΅JXd:>@M8?M(d $ Ahl  `44@ F L X    , 8 P  ( 8 q9 q:q=I>I@IGIHIIIXIYI\I]I^JbJdKeKfKlKtKuKvLLLLLM$Ctrafficserver-selinux9.2.51.el8trafficserver SELinux policyTrafficserver SELinux policy modulef buildvm-a64-06.iad2.fedoraproject.org8Fedora ProjectFedora ProjectApache-2.0Fedora ProjectUnspecifiedhttps://trafficserver.apache.org/linuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i /usr/share/selinux/packages/targeted/trafficserver.pp.bz2 /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fiif [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r trafficserver &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi fi .ff f af9ca27482c005c42ce6de7033f0d4063321e0e5f2ec9348af8904f9ceb08df8c0560d9651deece675b174115bd124350066e932957b7aae53add24420e4362c@rootrootrootrootrootroottrafficserver-9.2.5-1.el8.src.rpmtrafficserver-selinux     /bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)selinux-policyselinux-policy-baseselinux-policy-targetedselinux-policy-targeted3.0.4-14.6.0-14.0-15.2-13.14.33.14.34.14.3f>@fffwf De@e&@eSdddZ@cʂ@cR@cc*b@bb&b=b|bs@bobf@b]RbN@aya8` @` @]{]{\sZ@ZY+@Y@X,J@X,J@WSW@W>@W3W1@W WX@V@Vm@Vl@Vl@VVV<@Vj@Vj@Vj@U@U@UD@T,@SSϣSi@SP@S}S|@S`S[SFR 9.2.5-1Miroslav Suchý - 9.2.4-4Fedora Release Engineering - 9.2.4-3Jered Floyd 9.2.4-2Jered Floyd 9.2.4-1Fedora Release Engineering - 9.2.3-2Jered Floyd 9.2.3-1Jered Floyd 9.2.2-2Jered Floyd 9.2.2-1Fedora Release Engineering - 9.2.1-2Jered Floyd 9.2.1-1Jered Floyd 9.2.0-1Jered Floyd 9.1.4-1Jered Floyd 9.1.3-2Jered Floyd 9.1.3-2Jered Floyd 9.1.3-1Jered Floyd 9.1.2-9Jered Floyd 9.1.2-8Jered Floyd 9.1.2-7Jered Floyd 9.1.2-6Jered Floyd 9.1.2-5Jered Floyd 9.1.2-4Jered Floyd 9.1.2-3Jered Floyd 9.1.2-2Jered Floyd 9.1.2-1Hiroaki Nakamura 9.1.1-1Hiroaki Nakamura 9.1.0-1Hiroaki Nakamura 9.0.2-1Hiroaki Nakamura 8.1.2-1Hiroaki Nakamura 8.0.5-1Hiroaki Nakamura 7.1.8-1Hiroaki Nakamura 7.1.6-1Hiroaki Nakamura 7.1.3-1Hiroaki Nakamura 7.1.2-1Hiroaki Nakamura 7.1.1-1Hiroaki Nakamura 7.1.0-1Hiroaki Nakamura 7.0.0-2Hiroaki Nakamura 7.0.0-1Hiroaki Nakamura 6.2.0-2Hiroaki Nakamura 6.2.0-1Hiroaki Nakamura 6.1.1-10Hiroaki Nakamura 6.1.1-9Hiroaki Nakamura 6.1.1-8Hiroaki Nakamura 6.1.1-7Hiroaki Nakamura 6.1.1-6Hiroaki Nakamura 6.1.1-5Hiroaki Nakamura 6.1.1-4Hiroaki Nakamura 6.1.1-3Hiroaki Nakamura 6.1.1-2Hiroaki Nakamura 6.1.1-1Hiroaki Nakamura 6.1.0-1Hiroaki Nakamura 6.0.0-3Hiroaki Nakamura 6.0.0-2Hiroaki Nakamura 6.0.0-1Hiroaki Nakamura 5.3.0-2Peter Robinson 5.3.0-1Fedora Release Engineering - 5.0.1-4Kalev Lember - 5.0.1-3Petr Machata - 5.0.1-2Fedora Release Engineering - 5.0.1-1Jan-Frode Myklebust - 5.0.1-0Jan-Frode Myklebust - 5.0.0-0Fedora Release Engineering - 4.2.1-5Petr Machata - 4.2.1-4Jaroslav Škarvada - 4.2.1-3Jan-Frode Myklebust - 4.2.1-2Jan-Frode Myklebust - 4.2.1-rc1Jan-Frode Myklebust - 4.2.0-0Jan-Frode Myklebust - 4.1.2-0Jan-Frode Myklebust - 4.1.2-rc0Jan-Frode Myklebust - 4.0.2-5Jan-Frode Myklebust - 4.0.2-3Ralf Corsépius - 4.0.2-3Jan-Frode Myklebust - 4.0.2-2Jan-Frode Myklebust - 4.0.1-1Jan-Frode Myklebust - 3.2.5-3Jan-Frode Myklebust - 3.2.5-2Jan-Frode Myklebust - 3.2.5-1Jan-Frode Myklebust - 3.2.4-3Jan-Frode Myklebust - 3.2.4-1Jan-Frode Myklebust - 3.2.3-1Václav Pavlín - 3.2.0-6Jan-Frode Myklebust - 3.2.0-5Fedora Release Engineering - 3.2.0-3Jan-Frode Myklebust - 3.2.0-2Jan-Frode Myklebust - 3.2.0-1Jan-Frode Myklebust - 3.0.5-1Jan-Frode Myklebust - 3.0.4-5 - 3.0.4-4Dan Horák - 3.0.4-3 - 3.0.4-2 - 3.0.4-1 - 3.0.3-6 - 3.0.3-5 - 3.0.3-3 - 3.0.3-2 - 3.0.3-1 - 3.0.3-0 - 3.0.2-0 - 3.0.1-0 - 3.0.0-6 - 3.0.0-5 - 3.0.0-4 - 3.0.0-3 - 3.0.0-2 - 2.1.8-2 - 2.1.8-1 - 2.1.7-3 - 2.1.7-2 - 2.1.7-1 - 2.1.6-2 - 2.1.6-1 - 2.1.4- Update to upstream 9.2.5 - Resolves CVE-2023-38522, CVE-2024-35161, CVE-2024-35296- convert license to SPDX- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild- Enable build with deprecated OpenSSL Engine https://fedoraproject.org/wiki/Changes/OpensslDeprecateEngine- Update to upstream 9.2.4 - Resolves CVE-2024-31309- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild- Update to upstream 9.2.3 - Resolves CVE-2023-44487, CVE-2023-41752, CVE-2023-39456- Use OpenSSL 1.1.x from EPEL on RHEL 7 to fix Chrome 117+ bugs- Update to upstream 9.2.2- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild- Update to upstream 9.2.1- Update to upstream 9.2.0- Update to 9.1.4, resolves CVE-2022-32749, CVE-2022-37392, CVE-2022-40743- FTI on EL8 due to lack of libbrotli pkg; use RPM autodeps instead- Update dependencies to enable brotli compression (RHBZ#2125520)- Update to 9.1.3, resolves CVE-2022-25763, CVE-2022-31779, CVE-2021-37150, CVE-2022-28129, CVE-2022-31780 - Resolve glibc 2.36 (f37) header incompatibility that caused FTBFS RHBZ#2112282- Don't try to use Crypto Policies on RHEL 7- Cherry-pick OpenSSL 3 compatibility required for RHEL 9 - Switch to OpenSSL 3 on f36+ - Include automake in BuildRequires- Exclude s390x architecture -- not supported upstream- Further changes based on package review; perl dependencies, paths- Changes based on spec review; change "RedHat" capitalization, and add link to upstream file layout discussion- Changes based on spec review- Allow self:process setsched, requested on EL8- Set SELinux policy to be more restrictive on privileged UDP ports- Initial revision - Adapt to modern rpm conventions - Add draft SELinux policy - Don't run as root, just claim CAP_NET_BIND_SERVICE for privileged ports - Merge and cleanup of upstream .spec file along with Copr version maintained by Hiroaki Nakamura , based on long-ophaned package. ChangeLog included below for reference.- Update to 9.1.1- Update to 9.1.0 - Disable mime-sanity-check which is usable only in debug build- Update to 9.0.2 - Use yaml-cpp vendored in lib/yamlcpp- Update to 8.1.2- Update to 8.0.5 LTS release- Update to 7.1.8 LTS release- Update to 7.1.6 LTS release - Return stale cache with s-maxage only if cache_required_headers is 99- Update to 7.1.3 LTS release- Update to 7.1.2 LTS release- Update to 7.1.1 LTS release- Update to 7.1.0 LTS release- Remove expat-devel from build dependencies- Update to 7.0.0 LTS release- Return stale cache even if the origin server response has "Cache-Control: s-maxage" header.- Update to 6.2.0 LTS release- Add patch to add new value to proxy.config.http.cache.required_headers to require s-maxage for contents to be cached. - Remove patch to concatenate multiple header values of the same name in TSLua.- Fix bug in patch to concatenate multiple header values of the same name in TSLua.- Concatenate multiple header values of the same name in TSLua.- Remove patch to add proxy.config.http.cache.ignore_expires and proxy.config.http.cache.ignore_server_cc_max_age.- Apply patch to add proxy.config.http.cache.ignore_expires and proxy.config.http.cache.ignore_server_cc_max_age.- Disable patch to enable unix domain socket.- Apply patch to enable unix domain socket.- Enable luajit- Set prefix to /opt/trafficserver and use relative directories- Update to 6.1.1 LTS release- Update to 6.1.0 LTS release- Build experimental plugins- Just use configure --disable-luajit without a patch or deleting files- Update to 6.0.0 LTS release- Add patch to cache_insepector to split multiline URLs correctly- Update to 5.3.0 LTS release - Build on aarch64 and power64 - Split perl bindings to sub package - Cleanup and modernise spec- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Rebuilt for GCC 5 C++11 ABI change- Rebuild for boost 1.57.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix CVE-2014-3525- New major version.- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Rebuild for boost 1.55.0- Rebuilt for https://fedoraproject.org/wiki/Changes/f21tcl86- Bump release tag. RC1 became final.- Update to 4.2.1-RC1- Update to 4.2.0- Bump to final. No change from rc0. - What's new: https://cwiki.apache.org/confluence/display/TS/What%27s+new+in+v4.1.x- Update to 4.1.2-rc0.- Buildrequire hwloc-devel, since it supposedly gives tremendous positive performance impact to use hwlock to optimize scaling and number of threads and alignment for actual hardware we're running on.- Rebuild for picking up ECC/ECDHE/EC/ECDSA/elliptic curves which are now enabled in OpenSSL.- Add BR: systemd for systemd.macros (RHBZ #1018080).- Update to 4.0.2, which fixes the following bugs: [TS-2144] - traffic_server crashes when clearing cache [TS-2173] - cache total hit/miss stats broken in version 4.0.1 [TS-2174] - traffic_shell/traffic_line miss some stats value [TS-2191] - when http_info enabled, the http_sm may be deleted but a event associated it not cancelled. [TS-2207] - Centos5 out of tree perl build fails [TS-2217] - remove the option to turn off body factory - setting it to 0 will result in empty responses - Automatically verify GPG signature during RPM prep. - Build requires boost-devel.- Update to 4.0.1. What's new in v4.0.0: https://cwiki.apache.org/confluence/display/TS/What%27s+new+in+v4.0.0 - Upgrade instructions from earlier versions: https://cwiki.apache.org/confluence/display/TS/Upgrading+to+v4.0 Important notes: proxy.config.remap.use_remap_processor has been removed, use the proxy.config.remap.num_remap_threads instead. Default proxy.config.cache.ram_cache.size has been increased by a magnitude. Support for pre v3.2 port configuration directives has been removed. The following records.config parameters should be removed: CONFIG proxy.config.bandwidth_mgmt.filename STRING "" CONFIG proxy.config.admin.autoconf.wpad_filename STRING "" CONFIG proxy.config.username.cache.enabled INT 0 CONFIG proxy.config.username.cache.filename STRING "" CONFIG proxy.config.username.cache.size INT 0 CONFIG proxy.config.username.cache.storage_path STRING "" CONFIG proxy.config.username.cache.storage_size INT 0 CONFIG proxy.config.http.wuts_enabled INT 0 CONFIG proxy.config.http.log_spider_codes INT 0 CONFIG proxy.config.http.accept_encoding_filter_enabled INT 0 CONFIG proxy.config.http.accept_encoding_filter.filename STRING "" CONFIG proxy.config.net.throttle_enabled INT 0 CONFIG proxy.config.net.accept_throttle INT 0 CONFIG proxy.config.cluster.num_of_cluster_connections INT 0 CONFIG proxy.config.cache.url_hash_method INT 0 CONFIG proxy.config.plugin.extensions_dir STRING "" CONFIG proxy.local.http.parent_proxy.disable_connect_tunneling INT 0 CONFIG proxy.config.remap.use_remap_processor INT 0- bz#994224 Use rpm configure macro, instead of calling configure directly.- bz#994224 Pass RPM_OPT_FLAGS as environment variables to configure, instead of overriding on make commandline. Thanks Dimitry Andric!- Update to v3.2.5 which fixes the following bugs: [TS-1923] Fix memory issue caused by resolve_logfield_string() [TS-1918] SSL hangs after origin handshake. [TS-1483] Manager uses hardcoded FD limit causing restarts forever on traffic_server. [TS-1784] Fix FreeBSD block calculation (both RAW and directory) [TS-1905] TS hangs (dead lock) on HTTPS POST/PROPFIND requests. [TS-1785, TS-1904] Fixes to make it build with gcc-4.8.x. [TS-1903] Remove JEMALLOC_P use, it seems to have been deprecated. [TS-1902] Remove iconv as dependency. [TS-1900] Detect and link libhwloc on Ubuntu. [TS-1470] Fix cache sizes > 16TB (part 2 - Don't reset the cache after restart)- Harden build with PIE flags, ref bz#955127.- Update to 3.2.4 release candiate- Update to v3.2.3. Remove patches no longer needed.- Scriptlets replaced with new systemd macros (#851462)- Add patch for TS-1392, to fix problem with SNI fallback.- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Remove duplicate man-pages.- Update to v3.2.0- Remove trafficserver-gcc47.patch since it's fixed upstream, TS-1116. - Join trafficserver-condrestart.patch into trafficserver-init_scripts.patch, and clean out not needed junk.- Add hardened build.- Add patch for gcc-4.7 build issues.- switch to ExclusiveArch- Create /var/run/trafficserver using tmpfiles.d on f15+.- Update to new upstream release, v3.0.4. - remove trafficserver-cluster_interface_linux.patch since this was fixed upstream, TS-845.- Remove pidfile from systemd service file. This is a type=simple service, so pidfile shouldn't be needed.- Add systemd support. - Drop init.d-script on systemd-systems.- change default proxy.config.proxy_name to FIXME.example.com instead of the name of the buildhost - configure proxy.config.ssl.server.cert.path and proxy.config.ssl.server.private_key.path to point to the standard /etc/pki/ locations.- exclude ppc/ppc64 since build there fails, TS-1131.- Removed mixed use of spaces and tabs in specfile.- Update to v3.0.3- Update to v3.0.2 - Fix conderestart in initscript, TS-885.- Update to v3.0.1 - Remove uninstall-hook from trafficserver_make_install.patch, removed in v3.0.1.- Note FIXME's on top. - Remove .la and static libs. - mktemp'd buildroot. - include license- Rename patches to start with trafficserver-. - Remove odd version macro. - Clean up mixed-use-of-spaces-and-tabs.- Use dedicated user/group ats/ats. - Restart on upgrades.- update man pages, sugest from Jan-Frode Myklebust - patch records.config to fix the crashing with cluster iface is noexist - cleanup spec file- bump to version 3.0.0 stable release - cleanup the spec file and patches- fix tcl linking- bump to 2.1.8 - comment out wccp- enable wccp and fixed compile warning - never depends on sqlite and db4, add libz and xz-libs - fix libary permission, do post ldconfig updates- patch traffic_shell fix- bump to v2.1.7 - fix centos5 building - drop duplicated patches- fix gcc 4.6 building - split into -devel package for devel libs - fix init scripts for rpmlint requirement - fix install scripts to build in mock, without root privileges- bump to 2.1.6 unstable - replace config layout name as Fedora- initial release for public - original spec file is from neomanontheway@gmail.com/bin/sh/bin/sh/bin/sh9.2.5-1.el8trafficserver.iftrafficserver.pp.bz2trafficserver/usr/share/selinux/devel/include/distributed//usr/share/selinux/packages/targeted//var/lib/selinux/targeted/active/modules/200/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textcannot open `/builddir/build/BUILDROOT/trafficserver-9.2.5-1.el8.aarch64/var/lib/selinux/targeted/active/modules/200/trafficserver' (No such file or directory)https://bugz.fedoraproject.org/trafficserverutf-829208a4bf03feccbf7a58d43622e51636dd76c5dc0a2139254843f0a76f67d7c?7zXZ !#,:-] b2u Q{LYYVE aHPr=i U%:*ZMZ @{4{ PRJ]L>4R OY(N՘I4R rNG{b-Af/axςfݺ[5`eɇԃƧ ]~jl&hx+FŸ E=kLG p2u9ȘLܛ2]~(g-ƙ 4?7)zwVmu0æ0 TW]=^ P'1ɕeH}D4&&('6CLҁgG}[0fUT!pE\H{40FTYT7s:;=+z??8QPCY!A%ڄ'hЉsG Q \[SߓЈCO!T)W[ )2`C|l*-ĘFY%Ry_hZ):NgkUE'W7g]ŹY%(n L֮0nQYy2j^5m>=kW D2gp&:pK7PV^^'LˤNy}c+iL47ǐ%R70/kc :Ъ$R5lj*$8ًą2<牡rbev-pޥ>`m(v]=秚]+U:}1Mt^>k3:o-0zclGR]/5Pa\s.fQ;k߁iT~Fk_zl=up^=2as̒!C^%u.9ptG/ͷ}xd;#67d{?O㋮C"`aooʑ@)w&P#uL*]#xQ ) g{*z,A^ |kw5FeNp iLt}s2fKQm Hx9CLd2jcL* 9NgB|ZcQY2ĤH!BhRR._x@Pfåm2@G× eced@fܸYFJN"(}\np_{9729_y[ KN8:>/ I}s FYBbĨJ,_~(" d c]䗧f"?_NWfP~̔ܛrŁj FDV.Km?{U%B7~YC nⳂzjV=iFp~օ"ZhnĂ4FlE-1BtR\V*>4z *2\ eV7"τi'v͙L*R ]Xz_NL)Enq*DdB1tO MW$!È%sDW圭|c_.rY,g wc[x`.8{[j~znUM df/PR$٫Q`[AZ$7wi[߲T޷*I_}TnD Qb?%^u@u>~W̍O8zAA 뚤ZbL~nrWi VWtUT2cFoӠ󤈯.ӏqf*m(kQES B+>жG NR_=q' ZA@7QaCРHj\+Q]۩1%%^ZM uAdn&D3rr.2HJːh5?%݇a_Mȉ_7Ӗj3;96w3@_rI7Nj(ʴEDJPA/&Ւ kV@4%XxRRD#Z,ls).o6vvuyK[T:%}&"$ HC!Xa Q(˘W33.-Sqvj4:ݏOFp($P0_aJU/g<0*83&\KXΟ5Um1x>O)i_#2uCvG@k'l;qQ+QL%Jڭ9'9f1q8 E;{'A[7:y|9mԅxl%7{ zj_54T<\9JJAESk%M5͒W /A/dҵT?YC#٥\w^K$bwX#t Zו^iK_r% Mw8*N,qZ lhp=.O&sUxE6[=0W"ܔwV(ܥ~qzYOnf[sЈ?]Yɽl0%t=/E_Gd/jhНeka"d#{#>>ק'4\ %I8בn x&SLUL@,ՌyvPG@b\CfNlA: o݁La2ۺ:PjC @?: ͑a>)SB&25ylCD@?j61|CT\OOv09\ wA[K<>* X)no& I5w[-LٔbMØLSEG!MM^[D H&6o-VdaTzB8cjH sM 7OdioZ \ d賏J\䪫^r6Cii5[QZOսy5z9ܙ>g0j׸}z @$75Ğu((>\j`HTYI*3.k:n[4zX^L1HJqJV9(K2ReL"^]mI 4->"{caCy;jwge8뎚`"p#ݨ$21g WF$FgF" {zz?/))%UFc]{*׏<45I:w|?G#7yg)P{8TN嘉AC37^[V~ Pgdg%5u]BG#& 28'oȘ٭~5 qhpR_Z4h5"ft>6<㸸i bGVDӎ7êoF@*H䎠Y4fww\){/nt>^"G5-/#RnP43}׷f.rhPn(/ؙHF5%$]*Ą]a$$D>J&GkyM2!'e>T'*O-AJvp ?Pk[ ^HUHwO"{YV@7V%.³yċyvl `)}OOǨ@GKS2Hhx`˥U3 ]`虩i?|(ZAp8Ke40ʵjޞ=dս_wNɤ,L*g1 xe"|qs8LnU4#CX9߃jBbzdO҅hS~,.!pbe%O[a<#zV-cq-;/}0z޺lћ<`{aEh2Lk7l:q ڪ#&HjCvuǫOg=f" }BhdR >>Ɗi S2 YUl <ז'ogԧzFz1ğB^1ф3Q9C%=uJ|j3~qTyd> (…#.(VQLѭQq#ϴP>ˌc/v|>Bu9>!S=l&&NwqSN:&I@\ ur[ ϩpm+n *NVpـ%Yb~WnoiÊPChAȣHeC޸GVzNޝEn_:Yh8ͣCm^ĽyWs̫ZYwwl~*XQzyj>tWeȓXHb M}uMCՊzV]vp-e4lȒEw tYS21S_,:U_):[-@hr9U.pA*.Z)6 2!u82ӻùlu-0`Q5|$V]s)R&ulAθ[ʱ(*O V?5ߤW{es2fPˆN2Ҋ=;ࢄbjupW?hY]|/P?idd<̺2(}fx,VLo]&T~v$ËJʤm~tړ#dPB{'Jx*gu"]zRwDoC0# /QM#{IUxUşUCL%ឆ͏J ZT׵s-הzs:eKU@uVoS\XYks@ <& t:ӔVJI%>Fꖣ(-2ܒҩq1@!_'[SX:w@2oyrӛ^o+S܈L C@FV+KL!s ✿ϛ4}?nB {t:=M,\X"fY.,ĨJ2F$iE 6*Jа}"$(^xyƑDZT9 OkJLJe 04czB~r^=}J-G%sЬn*2DK{}ħK0i_+sOƯe1fO[9Njy_9PoĽ62' [=1:KJϨn\C?gqwM&dT՚ dTe]ߣE pYi5J /ǽp_<Їd=q)9r⮜v ZB GRoQ֨~sd,ǃi@cŠ*bMzQ* xa#dV\{y_fx%=c(ʌy Ь X⨂lo rurK&n 6cabfFd#s >r\cs~z N5&) %Oa͘C'A2jO|wGT(mng-#!ܘ$܎8m sH:H Iհ6?m:D[;].`qCTXۀVv(g{Pj^VV  ( 7tJ/7$L("obQSv":Cb|aG.} ZDQ[m=|$)VYbB{1ZW<+O[0c$/]|2]3U?^=Kǟ%){%}cJe6)f4m>_j@x##BPٰUYTB<(oh3?D,~T]N/3n*w'"C(/2"A4 $[n6p @{^;-ˌd*/;nV%q9Ii"A*֧{g] eK)ѡ(o1VtZ sSfRYW< u4Heڟ{ I!1ۤ*l:OZX-n5Ĕ5Pb %Ƌ܄ݮS9KԢѵdڈo [ T둦 qc N8)w"D\ɢ8p- ߩjU;P8zln%mm!d* ˰Zgł |bSiP3u!~-mgM>ԏi! q֤/X<\v+x _~5C6PsRwI\y ײGzvn` aٜ*Bs4%,2hk8WA.p5^`_ Ei*MNG}Up>H?ThFQK#jݯDo2pL}E,B;Vcԣcf6}ҐeD}iXl?- 5ĵeeu [G6ȟ`8.KUTOֈ3Kb'zEE QdJ}#d]䙖}q6'2"D͛NŃ)Äg#!ea%Tj(Sj7ɌUsyYh)yAh<|` \w oFE5X12 .+R 3-_^&yFgb_MڈWR#pVdpMG_4h 3+ ~ OBjltȢ6/?aM׍X㿂݇|OsO3&p^֗ȷE yƓ 4x=}eX;{\lÃ|Rϥ1jJSk4 GOfPruUjfUl261U䜂te휿dGXiE\#u&Z8{{וʖڥ7[#Y(hMY#Uma@$ bh 7W^r'[|#ԭنײ &)%I5HQn{Z-!{?v7NObǍ!BUD62$1lD7b;ʏ=%59e¥D ː\VIXLѳttNgPߩ$4 U=ݞm ςwhns=Uuz4*86wo\u D=}LD;#7 o iB5F*{+{wi~gԫqU#RX[BNE-8%uD/!6^_TR $9З!L=.fa3>ٹA x`ڸ;I,ʀ_chiIb X6'U;6c-^*0*n}=&!_rIdz3/@Xn^M׳yo8p33Rs! ANoFMmX[#8ط3eD8ص48PlU:04l\b c .pbsBg(@Z)jJw8<5A2\ϊd |T=HCҘ}&yS 5.*o*u@g% p:A7E '9:j0MFlq4)|UE'yMk|'~^E/5IMP=Iac!ni~iZǷנޏ`@G͢]&M#B ˯OjH :-@ћq`Yl6Xxzs^D}!e_6H9|(x 7;J3BNjWά>II_7`BR[T?
    :_7雥*RU &mx3gUU{;ߠhKU/_<9񘚪pT#iCw<б8(*: L~=EJ;?UN7 d7a܁##.JCDf^S)ijR&#KL3G@+88G{?>l"I@=/*T .ٝn\-A*&%[+D>njx{;rXTfOA@(0$\ 9 >g|Μ}ȟ)JoxxHt[.+c?+uyg$P /K!ߠү!1D1L2!W[x$ۊO})`^n FXNk6s?(Ϲ Fm"4qRjj1 jML_̈́l(XJ",ىoSGB#Dp0*@@{W~[;Ið`v̝lAd@OmDzЦljA$) Dd쓆ES^+ޜLH{<(&o֪] /V=-Lj0ecidCeYu^8[^ 0L11J @C\C=M+O4S8UkO nO6EW㦈%tJ/dz C[Z=@-UC!qa! ǛR7Lj)5a [6ju.Vpyo7l Aϛ0ˤxy4,!`(}i14L$O*8~rC%뀻Ey5'lF _Wr2kmh^f<_}At! +zuV~Fv9 d7]5]fFAQ)Pq4}7A#7Jq'K3hZuh YZ