trafficserver-selinux-9.2.8-1.el8> 6 6_ ܉3!y덏%!E/֡g&b !E/֡ :cR[Rv=4%NB RIO؀h:#3&8:9Gb:laq3K]r$Ʃf@&koOm V1U妰lXD % Br.\Q~eI.r yyW{K:l[e/>IhTȋDCtd;Y/eT~#c'An]7u 8Jt9s;gt q b0„_&ÃpJYц0*wjI ,ۑV3T*ENC(ή + SA.Aϙo\,,qP9 GcFu㞦Ex;:)a_ֽDFuEz;my4̭X$cK].`9VN|Rx8X砭P61:Xm@hcWvuvL)DT+w87= ps JIoR[=g dȞ#G2ef393f2ce1f0eea3d039e65d52b333c49ec0b9273fe29834efe72d0f44ae91b4fdfddd29409d30f65868786a8dd4744a72dc195#lWgG:>@Nl?N\d $ Ahl  `44@ F L X    , 8 P  ( 8 u9 u: u=J>J@JGJHJIJXJYJ\K]K^KHbKdLeLfLlMtMuM(vM4MMNNNXCtrafficserver-selinux9.2.81.el8trafficserver SELinux policyTrafficserver SELinux policy modulegobuildvm-a64-15.iad2.fedoraproject.org8Fedora ProjectFedora ProjectApache-2.0Fedora ProjectUnspecified . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i /usr/share/selinux/packages/targeted/trafficserver.pp.bz2 /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fiif [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r trafficserver &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi fi .gRgkglaf9ca27482c005c42ce6de7033f0d4063321e0e5f2ec9348af8904f9ceb08df8c0560d9651deece675b174115bd124350066e932957b7aae53add24420e4362c@rootrootrootrootrootroottrafficserver-9.2.8-1.el8.src.rpmtrafficserver-selinux     /bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)selinux-policyselinux-policy-baseselinux-policy-targetedselinux-policy-targeted3.0.4-14.6.0-14.0-15.2-\!g3C@g3C@f>@fffwf De@e&@eSdddZ@cʂ@cR@cc*b@bb&b=b|bs@bobf@b]RbN@aya8` @` @]{]{\sZ@ZY+@Y@X,J@X,J@WSW@W>@W3W1@W WX@V@Vm@Vl@Vl@VVV<@Vj@Vj@Vj@U@U@UD@T,@SSϣSi@SP@S}S|@S`S[SFR 9.2.8-1Jered Floyd 9.2.7-1Jered Floyd 9.2.6-2Jered Floyd 9.2.6-1Jered Floyd 9.2.5-1Miroslav Suchý - 9.2.4-4Fedora Release Engineering - 9.2.4-3Jered Floyd 9.2.4-2Jered Floyd 9.2.4-1Fedora Release Engineering - 9.2.3-2Jered Floyd 9.2.3-1Jered Floyd 9.2.2-2Jered Floyd 9.2.2-1Fedora Release Engineering - 9.2.1-2Jered Floyd 9.2.1-1Jered Floyd 9.2.0-1Jered Floyd 9.1.4-1Jered Floyd 9.1.3-2Jered Floyd 9.1.3-2Jered Floyd 9.1.3-1Jered Floyd 9.1.2-9Jered Floyd 9.1.2-8Jered Floyd 9.1.2-7Jered Floyd 9.1.2-6Jered Floyd 9.1.2-5Jered Floyd 9.1.2-4Jered Floyd 9.1.2-3Jered Floyd 9.1.2-2Jered Floyd 9.1.2-1Hiroaki Nakamura 9.1.1-1Hiroaki Nakamura 9.1.0-1Hiroaki Nakamura 9.0.2-1Hiroaki Nakamura 8.1.2-1Hiroaki Nakamura 8.0.5-1Hiroaki Nakamura 7.1.8-1Hiroaki Nakamura 7.1.6-1Hiroaki Nakamura 7.1.3-1Hiroaki Nakamura 7.1.2-1Hiroaki Nakamura 7.1.1-1Hiroaki Nakamura 7.1.0-1Hiroaki Nakamura 7.0.0-2Hiroaki Nakamura 7.0.0-1Hiroaki Nakamura 6.2.0-2Hiroaki Nakamura 6.2.0-1Hiroaki Nakamura 6.1.1-10Hiroaki Nakamura 6.1.1-9Hiroaki Nakamura 6.1.1-8Hiroaki Nakamura 6.1.1-7Hiroaki Nakamura 6.1.1-6Hiroaki Nakamura 6.1.1-5Hiroaki Nakamura 6.1.1-4Hiroaki Nakamura 6.1.1-3Hiroaki Nakamura 6.1.1-2Hiroaki Nakamura 6.1.1-1Hiroaki Nakamura 6.1.0-1Hiroaki Nakamura 6.0.0-3Hiroaki Nakamura 6.0.0-2Hiroaki Nakamura 6.0.0-1Hiroaki Nakamura 5.3.0-2Peter Robinson 5.3.0-1Fedora Release Engineering - 5.0.1-4Kalev Lember - 5.0.1-3Petr Machata - 5.0.1-2Fedora Release Engineering - 5.0.1-1Jan-Frode Myklebust - 5.0.1-0Jan-Frode Myklebust - 5.0.0-0Fedora Release Engineering - 4.2.1-5Petr Machata - 4.2.1-4Jaroslav Škarvada - 4.2.1-3Jan-Frode Myklebust - 4.2.1-2Jan-Frode Myklebust - 4.2.1-rc1Jan-Frode Myklebust - 4.2.0-0Jan-Frode Myklebust - 4.1.2-0Jan-Frode Myklebust - 4.1.2-rc0Jan-Frode Myklebust - 4.0.2-5Jan-Frode Myklebust - 4.0.2-3Ralf Corsépius - 4.0.2-3Jan-Frode Myklebust - 4.0.2-2Jan-Frode Myklebust - 4.0.1-1Jan-Frode Myklebust - 3.2.5-3Jan-Frode Myklebust - 3.2.5-2Jan-Frode Myklebust - 3.2.5-1Jan-Frode Myklebust - 3.2.4-3Jan-Frode Myklebust - 3.2.4-1Jan-Frode Myklebust - 3.2.3-1Václav Pavlín - 3.2.0-6Jan-Frode Myklebust - 3.2.0-5Fedora Release Engineering - 3.2.0-3Jan-Frode Myklebust - 3.2.0-2Jan-Frode Myklebust - 3.2.0-1Jan-Frode Myklebust - 3.0.5-1Jan-Frode Myklebust - 3.0.4-5 - 3.0.4-4Dan Horák - 3.0.4-3 - 3.0.4-2 - 3.0.4-1 - 3.0.3-6 - 3.0.3-5 - 3.0.3-3 - 3.0.3-2 - 3.0.3-1 - 3.0.3-0 - 3.0.2-0 - 3.0.1-0 - 3.0.0-6 - 3.0.0-5 - 3.0.0-4 - 3.0.0-3 - 3.0.0-2 - 2.1.8-2 - 2.1.8-1 - 2.1.7-3 - 2.1.7-2 - 2.1.7-1 - 2.1.6-2 - 2.1.6-1 - 2.1.4- Update to upstream 9.2.8- Update to upstream 9.2.7- Backport fix for broken oubound TLS with OpenSSL 3.2+- Update to upstream 9.2.6- Update to upstream 9.2.5 - Resolves CVE-2023-38522, CVE-2024-35161, CVE-2024-35296- convert license to SPDX- Rebuilt for Enable build with deprecated OpenSSL Engine Update to upstream 9.2.4 - Resolves CVE-2024-31309- Rebuilt for Update to upstream 9.2.3 - Resolves CVE-2023-44487, CVE-2023-41752, CVE-2023-39456- Use OpenSSL 1.1.x from EPEL on RHEL 7 to fix Chrome 117+ bugs- Update to upstream 9.2.2- Rebuilt for Update to upstream 9.2.1- Update to upstream 9.2.0- Update to 9.1.4, resolves CVE-2022-32749, CVE-2022-37392, CVE-2022-40743- FTI on EL8 due to lack of libbrotli pkg; use RPM autodeps instead- Update dependencies to enable brotli compression (RHBZ#2125520)- Update to 9.1.3, resolves CVE-2022-25763, CVE-2022-31779, CVE-2021-37150, CVE-2022-28129, CVE-2022-31780 - Resolve glibc 2.36 (f37) header incompatibility that caused FTBFS RHBZ#2112282- Don't try to use Crypto Policies on RHEL 7- Cherry-pick OpenSSL 3 compatibility required for RHEL 9 - Switch to OpenSSL 3 on f36+ - Include automake in BuildRequires- Exclude s390x architecture -- not supported upstream- Further changes based on package review; perl dependencies, paths- Changes based on spec review; change "RedHat" capitalization, and add link to upstream file layout discussion- Changes based on spec review- Allow self:process setsched, requested on EL8- Set SELinux policy to be more restrictive on privileged UDP ports- Initial revision - Adapt to modern rpm conventions - Add draft SELinux policy - Don't run as root, just claim CAP_NET_BIND_SERVICE for privileged ports - Merge and cleanup of upstream .spec file along with Copr version maintained by Hiroaki Nakamura , based on long-ophaned package. ChangeLog included below for reference.- Update to 9.1.1- Update to 9.1.0 - Disable mime-sanity-check which is usable only in debug build- Update to 9.0.2 - Use yaml-cpp vendored in lib/yamlcpp- Update to 8.1.2- Update to 8.0.5 LTS release- Update to 7.1.8 LTS release- Update to 7.1.6 LTS release - Return stale cache with s-maxage only if cache_required_headers is 99- Update to 7.1.3 LTS release- Update to 7.1.2 LTS release- Update to 7.1.1 LTS release- Update to 7.1.0 LTS release- Remove expat-devel from build dependencies- Update to 7.0.0 LTS release- Return stale cache even if the origin server response has "Cache-Control: s-maxage" header.- Update to 6.2.0 LTS release- Add patch to add new value to proxy.config.http.cache.required_headers to require s-maxage for contents to be cached. - Remove patch to concatenate multiple header values of the same name in TSLua.- Fix bug in patch to concatenate multiple header values of the same name in TSLua.- Concatenate multiple header values of the same name in TSLua.- Remove patch to add proxy.config.http.cache.ignore_expires and proxy.config.http.cache.ignore_server_cc_max_age.- Apply patch to add proxy.config.http.cache.ignore_expires and proxy.config.http.cache.ignore_server_cc_max_age.- Disable patch to enable unix domain socket.- Apply patch to enable unix domain socket.- Enable luajit- Set prefix to /opt/trafficserver and use relative directories- Update to 6.1.1 LTS release- Update to 6.1.0 LTS release- Build experimental plugins- Just use configure --disable-luajit without a patch or deleting files- Update to 6.0.0 LTS release- Add patch to cache_insepector to split multiline URLs correctly- Update to 5.3.0 LTS release - Build on aarch64 and power64 - Split perl bindings to sub package - Cleanup and modernise spec- Rebuilt for Rebuilt for GCC 5 C++11 ABI change- Rebuild for boost 1.57.0- Rebuilt for Fix CVE-2014-3525- New major version.- Rebuilt for Rebuild for boost 1.55.0- Rebuilt for Bump release tag. RC1 became final.- Update to 4.2.1-RC1- Update to 4.2.0- Bump to final. No change from rc0. - What's new: Update to 4.1.2-rc0.- Buildrequire hwloc-devel, since it supposedly gives tremendous positive performance impact to use hwlock to optimize scaling and number of threads and alignment for actual hardware we're running on.- Rebuild for picking up ECC/ECDHE/EC/ECDSA/elliptic curves which are now enabled in OpenSSL.- Add BR: systemd for systemd.macros (RHBZ #1018080).- Update to 4.0.2, which fixes the following bugs: [TS-2144] - traffic_server crashes when clearing cache [TS-2173] - cache total hit/miss stats broken in version 4.0.1 [TS-2174] - traffic_shell/traffic_line miss some stats value [TS-2191] - when http_info enabled, the http_sm may be deleted but a event associated it not cancelled. [TS-2207] - Centos5 out of tree perl build fails [TS-2217] - remove the option to turn off body factory - setting it to 0 will result in empty responses - Automatically verify GPG signature during RPM prep. - Build requires boost-devel.- Update to 4.0.1. What's new in v4.0.0: - Upgrade instructions from earlier versions: Important notes: proxy.config.remap.use_remap_processor has been removed, use the proxy.config.remap.num_remap_threads instead. Default proxy.config.cache.ram_cache.size has been increased by a magnitude. Support for pre v3.2 port configuration directives has been removed. The following records.config parameters should be removed: CONFIG proxy.config.bandwidth_mgmt.filename STRING "" CONFIG proxy.config.admin.autoconf.wpad_filename STRING "" CONFIG proxy.config.username.cache.enabled INT 0 CONFIG proxy.config.username.cache.filename STRING "" CONFIG proxy.config.username.cache.size INT 0 CONFIG proxy.config.username.cache.storage_path STRING "" CONFIG proxy.config.username.cache.storage_size INT 0 CONFIG proxy.config.http.wuts_enabled INT 0 CONFIG proxy.config.http.log_spider_codes INT 0 CONFIG proxy.config.http.accept_encoding_filter_enabled INT 0 CONFIG proxy.config.http.accept_encoding_filter.filename STRING "" CONFIG INT 0 CONFIG INT 0 CONFIG proxy.config.cluster.num_of_cluster_connections INT 0 CONFIG proxy.config.cache.url_hash_method INT 0 CONFIG proxy.config.plugin.extensions_dir STRING "" CONFIG proxy.local.http.parent_proxy.disable_connect_tunneling INT 0 CONFIG proxy.config.remap.use_remap_processor INT 0- bz#994224 Use rpm configure macro, instead of calling configure directly.- bz#994224 Pass RPM_OPT_FLAGS as environment variables to configure, instead of overriding on make commandline. Thanks Dimitry Andric!- Update to v3.2.5 which fixes the following bugs: [TS-1923] Fix memory issue caused by resolve_logfield_string() [TS-1918] SSL hangs after origin handshake. [TS-1483] Manager uses hardcoded FD limit causing restarts forever on traffic_server. [TS-1784] Fix FreeBSD block calculation (both RAW and directory) [TS-1905] TS hangs (dead lock) on HTTPS POST/PROPFIND requests. [TS-1785, TS-1904] Fixes to make it build with gcc-4.8.x. [TS-1903] Remove JEMALLOC_P use, it seems to have been deprecated. [TS-1902] Remove iconv as dependency. [TS-1900] Detect and link libhwloc on Ubuntu. [TS-1470] Fix cache sizes > 16TB (part 2 - Don't reset the cache after restart)- Harden build with PIE flags, ref bz#955127.- Update to 3.2.4 release candiate- Update to v3.2.3. Remove patches no longer needed.- Scriptlets replaced with new systemd macros (#851462)- Add patch for TS-1392, to fix problem with SNI fallback.- Rebuilt for Remove duplicate man-pages.- Update to v3.2.0- Remove trafficserver-gcc47.patch since it's fixed upstream, TS-1116. - Join trafficserver-condrestart.patch into trafficserver-init_scripts.patch, and clean out not needed junk.- Add hardened build.- Add patch for gcc-4.7 build issues.- switch to ExclusiveArch- Create /var/run/trafficserver using tmpfiles.d on f15+.- Update to new upstream release, v3.0.4. - remove trafficserver-cluster_interface_linux.patch since this was fixed upstream, TS-845.- Remove pidfile from systemd service file. This is a type=simple service, so pidfile shouldn't be needed.- Add systemd support. - Drop init.d-script on systemd-systems.- change default proxy.config.proxy_name to instead of the name of the buildhost - configure proxy.config.ssl.server.cert.path and proxy.config.ssl.server.private_key.path to point to the standard /etc/pki/ locations.- exclude ppc/ppc64 since build there fails, TS-1131.- Removed mixed use of spaces and tabs in specfile.- Update to v3.0.3- Update to v3.0.2 - Fix conderestart in initscript, TS-885.- Update to v3.0.1 - Remove uninstall-hook from trafficserver_make_install.patch, removed in v3.0.1.- Note FIXME's on top. - Remove .la and static libs. - mktemp'd buildroot. - include license- Rename patches to start with trafficserver-. - Remove odd version macro. - Clean up mixed-use-of-spaces-and-tabs.- Use dedicated user/group ats/ats. - Restart on upgrades.- update man pages, sugest from Jan-Frode Myklebust - patch records.config to fix the crashing with cluster iface is noexist - cleanup spec file- bump to version 3.0.0 stable release - cleanup the spec file and patches- fix tcl linking- bump to 2.1.8 - comment out wccp- enable wccp and fixed compile warning - never depends on sqlite and db4, add libz and xz-libs - fix libary permission, do post ldconfig updates- patch traffic_shell fix- bump to v2.1.7 - fix centos5 building - drop duplicated patches- fix gcc 4.6 building - split into -devel package for devel libs - fix init scripts for rpmlint requirement - fix install scripts to build in mock, without root privileges- bump to 2.1.6 unstable - replace config layout name as Fedora- initial release for public - original spec file is from -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textcannot open `/builddir/build/BUILDROOT/trafficserver-9.2.8-1.el8.aarch64/var/lib/selinux/targeted/active/modules/200/trafficserver' (No such file or directory) !#,:-] b2u Q{LZT?d NYAl8ex;5)\fh :b#y4\c ;;OZk;(?s *ᶗY*Kv8~'}Qs=r/;2typ<n/bD"̅:nFsH|JdL,4Zi爕@9YI]hT(nJۖc9R K|vR#EbIP\xC%;?&Ww=+r>5xG S0Q~_ x}W' i;Ii LLGuŲX0-A9(~cFiz[,[sߵW5$==UTk".;|ޞ?!3W<"kŽJ?4h:wS`d&c~;,4bNxEA&Ll>t  *>A_^c0^؏=ܘ+u' y&^OEY:,ϳ„/Ҷm;Njuk (&8m|Fܡ)k2h0aU%1I4솻ȼ5\ykQijLm;AA3C=. "V`} cSVoׯHGɖ7a*/L2zuN"Pkps".]㸰/oP[L\g:1%dyL ic9Hz'Ң]٬46FB@V+r0h5usӝ wm`Ov=,%/{!0x3|-ucF/ :Py{-T`i7?eҜv K-yd@'ZmnQO 9myQd}#:}΅^%|ǐӂʠ6H/ު5\`}'U:*ߚIb lxb~p))Ҹrsݘ_54ʺb ^ /Iv#70\ ߁]a\1 F O~gf=,d @ڵ6ү 13[20)C'#y,/nja 8NJTKh7ptK"1L%@yRR{Ԅzsx5.a'eӱk#uvy F,܌r0+Kj2eGeWm _5daaիeIDja5azڴ(d`(q׿YWﴷJ_1Z&xt$0^!^=Bq5%6K"U2bˑʗQIgE.Cd{ݦg=y$٘pXF,p_fA#u>) ;FT<$U)݌=1{&g˨ ޽VfO&] n;ZmNڴop"D"44(%Tij_)+`@8r,daa_HO@^ou#)WƹyH#t-!B+HT>F=7vAg,X;6!1Sv\KM.᡺}4%EF>֔*Ǎ#,=0qD.8.-iS5UQlEj0^w<{#dik@b 1BtjwɵZ:i:.,Y ĝ(UI8چNP U1fapj&Tn1" i!N?KV'OZfz(7WD6mw B`JQv&A2{1x_ހ1|G3*lsb\k3Bl4[ Mr=/uC"V*9V3baN>,[a"fؐqni9 !RWf^ .d1ڂJUi?)$rwd 5EHFb].į)0֤,zQйksF.OH^l o$a#vnIX>p8A`.bqw8q-G M&GXǬnl|GȺKY{hReAW{b-0xAHj=Cl9A"ƪa0wjcx 4ߐϳO'0+Ҏ&4VЈʦV H.4 X ĴS؇%C9|p]ryIxZͰ˗3o&;V:0:rraw+7|.p}47#ϱXKw n<٨րtWE:vlqWdzNpN.c>Ew[)k4E#FH=נ ]A4k-jeޮ's Dx.%u[ ?!v (~t])XXߩI\g3ґR[8d.j+x.jHDb&DH~3 n:+FC "B}C܅q(>/8ֻYh'ј{585%ŶJNA4h&49yvPӋ˔ 1⭘/=Ƭ :ڝP9:x7تX8&qij Nflh3$ͬdչ͔I N`_ĿϬyZ/ 2rM^>4I#6^ X%##Ӄ$/GPu5dBe=k݇hP4gDIqR ɪ tHc<>v>ѢEѸm"Ck_ƆFnVx63^!3.VeJZE8(W&>J4_BQW(Ê*A,m HcF`$o^⚝lr`۟deKh=Mg9^k>Z=0$aG?&!c>4mY/zYs)H0.%F-_8֫bes}3~M%ô,P_4ô[.BlwOHսىy Yk?L$YZ];ӖS8^8?VTܒgtݬ4 ҥ 2 M@ ,坿Dc"!3QRi: uc,CYlP^]Ұt/˜'J'T$^VyŦ.èϜ}SK/T<~.9?"]~2h#Q%WU/ Q xuO|:~j.E=̿X/ Qo Ff$%KWI=RiM52ܤWX H`[asa[;t $Ԕ 0L\xMhE{YQ"ݍ<\>6>-vE䂽@HfD*Am6ͥ-00VBoAJMMgo`;=]8{9 XV|Yr- UݷWKBY JSZl< CXzuw:o1`Xd'Lk٨ޙ PGw+oY VtGv{+~C&(W/z;G5kJ&е*`NOE F:4 u-Bǁ'lch:&{Tl<^q">REZy,hZ|T3ܓl'טlFO-%(d\%5(|բxG92c\nRf%Ø9@іlMaPNWAAm-#\yKŖ +SƳrDא=,e?\zcxgd"^Pq[R:n]]NUuQ6t$ 㜠,覀^p"ߝ6b~P֛s4W=b_>:TzT= -~C|/NZ0xP?@DO0]G P(U%0"UiC!\r~_ .򎮩I^cܝzH1զ#ǝEF]|MLh9@_۴3˿+l4p^/gsr 2c i,`ߑL%f]qIR Y4E1]#zxTpLNBc{U1ڼ|7(VKo@lFpF:_UgL:4:9ҝ+C% f҇Ө~唂ŒqCՀH^btWb#Rlͧ]~@L_. gs<΄AMz,M"o3,z]%揣a$ x[ K2#Ku6ݷDky `X'jSPCkqAh/Ԟ oB@lb@7 ȑ9iG, _ODBԤ"h"*jBZ 4w1|bH<"ӬmdFʻ9GS 4s^xyݹg0*UdO$w`l̆hA{3#H|ni^vtQP4` >˴V7(U eby؂E輫sD8$HsJN$4ב)m3eRRz %Vh{~Ґp# =͎+; ՋȮ}))kn)@{m;4M(|iR\ÆSe l>Qf$Gl`اken>Mdx\EqFp/?-q<3Ks+v0^+S0ېB qpU% HI&̐k`VuDE>h0mdM,8f=T]_yO +EWy5U\0Y牅B ?I`s@C̝f%6o\F~{^:. xA>E!xn펲մ'N%TE&P 2<9G9LfIE$-gӫ֩Pگ]w?7ֱU} ۮ0]H&4-8RJW avHaif3k7^E W6bQ|j !rM{y0 (ұڔ2&)+$tpak΅o(_kl!U$;O [C+&9' }fޝ _fUHڬ$sA2.B)(̛ZG*,7Oϟc$ݗٳCѪxAH`Mxe%8y p@:s}21Z0='&ܰa7T$sjOc?B=A 'wX3-_` Ϥq[*PMz_ni*n!mQvaAa[T[9hqN00 Xf+'VkcjǿE 0qը]Mt2–pKBeq'&̅4[>_9XVRw!`t\IMHGI}m۬3 :GN^ɴEG?"Pd*ngӧ]y ׂ 1 1܄T$n!s:C٢A22ltd@K}_FÉϏMN$8(>9\| . /*<m'SOUPJdj|H²gq·d*,Oh`=y/nN#KaAvmr2 VمE֍a"{ #[1L%d6?]1~ɟ^U 0 97`+g8ݘB#0p6gÝ+8Q6`:i`?eZD˙-4 !9聯\!DR%n0٩'y&7nmfQHؕP[S8BIu1|;6 v2k3pi\[Ef|doV ypw6E!/V[]X>&/=BPz9E<1$I'00#Ԥۓhk#6?CÊ'"\I,8/*'\B.4L*x+OtR#'2L4>mO;|e̶jJ%* >m ^q? ,#~xOɠfV u\K~>meE% fG÷{?u81зْcrg]SG~Un aS{#BS% ͶBݩP;b/L:J*uq,P'_ILTJwW1ۍW(z;ˈ0)kېN.t ɖƷ.{™+H"rЕX_wOԜ4:^=:%I(%OV- @(i-ʕ,Թ.Qü<ӽI7S,Vo+lA8%&g ՔrSߠϵXܚ)~1n@N'FiP ƟHnXD]05EL*C}=TG[վWaxѕ)bߙlO;KYG޾ǂtr#Z=nIETLBw mM@T&;`<)ZB/ΚT͉qUM։C<Jb7!B%/a;1.iiы9#ktM,w- ]Fn*A =RVmA]}qR7>X9i~,.vrg"0OpX5blvkav˜CLl! W>;I0J3nHիL ^)G:Q~{6KX6eA7A lc~[uSՉb L(h!51r^P TJ0iJ]VRY&j29sHgtdCč'i N_?b9ՎS'#1o]˿i^MgmK:M1-lcz_`Ry!Zp1PX(ix.r<ңU!/ 矹(l?l͟ZGDI-c^w3Tzwf%Z"v8!e=] ms׿0z3]4c0oq-4S+ ԛWVNS5Є( ǩXzb +qa6b3sӘVk{M+'cON(Fe`f[Ī]߰"Q Ȼ) qVBn?A*[ڈv#oszO P,w1^DC hS ߤ8It+H`Jۙuy?$$aS:֣kXr8ӒײS3u3 N5dzkN9| U# mP|>1~k+A31,&@rkY [R\u EPg!~ ?y:Tl5Xmlbj3͓Fګ[ü ?l9?ּRY0Dc Vd 2 1v姼eJ2"<&tnS2_I.Oz]ѽ t mRYxdmP>IBkچ71;I.&DVJBx{G=kd|;H f&8t>c_Rށ9ciI|x@>>_KfF_20ZX8> )X!'+=0v64Qc糉d'PϠXUc+D@r8u۽v5Z!R)BEMQ]\~nvXsP AY^Ud|gGVDA*tU4=CXٙ0wKH*jAWXʒd?3ͮ5Ɍ~H3wc{֪}05.Em ȇ-0m@S,\޷7H\ϲC%DЬ1 79*MtXURVJwPP҂'`!tc=/h G~+f88W=C -fU2gI؅tzۏyny"|vJeCL/!>= #YJ%u䊆P_4|0\2Pk9*EK+,Kbv֋^ O)'MпjC3̙%?ЙZuh YZ