trafficserver-selinux-9.2.10-1.el8> 6 6_ ܉3!y덏%!E/֡gQ !E/֡1ψ0-p$\\R rѿf]I!K4n%XP=ej9nb " KI949sLe?C޷'[7>wrӶbD v]]I(u1po#xرP/:ܷt<$A۪'waU.EZ"eJI[C$x# &l"Lz|hP4.kp?Ёc٦d7હ' )8y|~or7UkyvQ{Q|E?{ENcdJkjq}=c29 /@GV_4jUE}-dلQl@% HfT=s>,Ȩ2di\Rĺ|R^vJdk6Bo> ݩH()@WĿMv&eIkv‹ʕ ߆$F:QԦ_ 3*p iLG=oC_FW{865d95a7fd30fa4d771c68d391ba76e437670927b38d28393c64b7628a75d73e5c729e9479a7a236494c01c01e0e934b22015beb)e=PsԤ_::>@Oh?OXd % Bhl  `44@ F L X    0 < T  ( 8 w9 w:!w=K>K@KGKHKIKXKYK\L]L ^L@bLdMeMfMlMtNuN vN,NNO OOTCtrafficserver-selinux9.2.101.el8trafficserver SELinux policyTrafficserver SELinux policy modulegbuildvm-a64-08.iad2.fedoraproject.org8Fedora ProjectFedora ProjectApache-2.0Fedora ProjectUnspecifiedhttps://trafficserver.apache.org/linuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i /usr/share/selinux/packages/targeted/trafficserver.pp.bz2 /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fiif [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r trafficserver &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi fi .gggaf9ca27482c005c42ce6de7033f0d4063321e0e5f2ec9348af8904f9ceb08df8c0560d9651deece675b174115bd124350066e932957b7aae53add24420e4362c@rootrootrootrootrootroottrafficserver-9.2.10-1.el8.src.rpmtrafficserver-selinux     /bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)selinux-policyselinux-policy-baseselinux-policy-targetedselinux-policy-targeted3.0.4-14.6.0-14.0-15.2-13.14.33.14.34.14.3g@g@fffwf De@e&@eSdddZ@cʂ@cR@cc*b@bb&b=b|bs@bobf@b]RbN@aya8` @` @]{]{\sZ@ZY+@Y@X,J@X,J@WSW@W>@W3W1@W WX@V@Vm@Vl@Vl@VVV<@Vj@Vj@Vj@U@U@UD@T,@SSϣSi@SP@S}S|@S`S[SFR 9.2.10-1Jered Floyd 9.2.9-1Jered Floyd 9.2.8-1Jered Floyd 9.2.7-1Jered Floyd 9.2.6-2Jered Floyd 9.2.6-1Jered Floyd 9.2.5-1Miroslav Suchý - 9.2.4-4Fedora Release Engineering - 9.2.4-3Jered Floyd 9.2.4-2Jered Floyd 9.2.4-1Fedora Release Engineering - 9.2.3-2Jered Floyd 9.2.3-1Jered Floyd 9.2.2-2Jered Floyd 9.2.2-1Fedora Release Engineering - 9.2.1-2Jered Floyd 9.2.1-1Jered Floyd 9.2.0-1Jered Floyd 9.1.4-1Jered Floyd 9.1.3-2Jered Floyd 9.1.3-2Jered Floyd 9.1.3-1Jered Floyd 9.1.2-9Jered Floyd 9.1.2-8Jered Floyd 9.1.2-7Jered Floyd 9.1.2-6Jered Floyd 9.1.2-5Jered Floyd 9.1.2-4Jered Floyd 9.1.2-3Jered Floyd 9.1.2-2Jered Floyd 9.1.2-1Hiroaki Nakamura 9.1.1-1Hiroaki Nakamura 9.1.0-1Hiroaki Nakamura 9.0.2-1Hiroaki Nakamura 8.1.2-1Hiroaki Nakamura 8.0.5-1Hiroaki Nakamura 7.1.8-1Hiroaki Nakamura 7.1.6-1Hiroaki Nakamura 7.1.3-1Hiroaki Nakamura 7.1.2-1Hiroaki Nakamura 7.1.1-1Hiroaki Nakamura 7.1.0-1Hiroaki Nakamura 7.0.0-2Hiroaki Nakamura 7.0.0-1Hiroaki Nakamura 6.2.0-2Hiroaki Nakamura 6.2.0-1Hiroaki Nakamura 6.1.1-10Hiroaki Nakamura 6.1.1-9Hiroaki Nakamura 6.1.1-8Hiroaki Nakamura 6.1.1-7Hiroaki Nakamura 6.1.1-6Hiroaki Nakamura 6.1.1-5Hiroaki Nakamura 6.1.1-4Hiroaki Nakamura 6.1.1-3Hiroaki Nakamura 6.1.1-2Hiroaki Nakamura 6.1.1-1Hiroaki Nakamura 6.1.0-1Hiroaki Nakamura 6.0.0-3Hiroaki Nakamura 6.0.0-2Hiroaki Nakamura 6.0.0-1Hiroaki Nakamura 5.3.0-2Peter Robinson 5.3.0-1Fedora Release Engineering - 5.0.1-4Kalev Lember - 5.0.1-3Petr Machata - 5.0.1-2Fedora Release Engineering - 5.0.1-1Jan-Frode Myklebust - 5.0.1-0Jan-Frode Myklebust - 5.0.0-0Fedora Release Engineering - 4.2.1-5Petr Machata - 4.2.1-4Jaroslav Škarvada - 4.2.1-3Jan-Frode Myklebust - 4.2.1-2Jan-Frode Myklebust - 4.2.1-rc1Jan-Frode Myklebust - 4.2.0-0Jan-Frode Myklebust - 4.1.2-0Jan-Frode Myklebust - 4.1.2-rc0Jan-Frode Myklebust - 4.0.2-5Jan-Frode Myklebust - 4.0.2-3Ralf Corsépius - 4.0.2-3Jan-Frode Myklebust - 4.0.2-2Jan-Frode Myklebust - 4.0.1-1Jan-Frode Myklebust - 3.2.5-3Jan-Frode Myklebust - 3.2.5-2Jan-Frode Myklebust - 3.2.5-1Jan-Frode Myklebust - 3.2.4-3Jan-Frode Myklebust - 3.2.4-1Jan-Frode Myklebust - 3.2.3-1Václav Pavlín - 3.2.0-6Jan-Frode Myklebust - 3.2.0-5Fedora Release Engineering - 3.2.0-3Jan-Frode Myklebust - 3.2.0-2Jan-Frode Myklebust - 3.2.0-1Jan-Frode Myklebust - 3.0.5-1Jan-Frode Myklebust - 3.0.4-5 - 3.0.4-4Dan Horák - 3.0.4-3 - 3.0.4-2 - 3.0.4-1 - 3.0.3-6 - 3.0.3-5 - 3.0.3-3 - 3.0.3-2 - 3.0.3-1 - 3.0.3-0 - 3.0.2-0 - 3.0.1-0 - 3.0.0-6 - 3.0.0-5 - 3.0.0-4 - 3.0.0-3 - 3.0.0-2 - 2.1.8-2 - 2.1.8-1 - 2.1.7-3 - 2.1.7-2 - 2.1.7-1 - 2.1.6-2 - 2.1.6-1 - 2.1.4- Update to upstream 9.2.10 - Resolves CVE-2024-53868- Update to upstream 9.2.9 - Resolves CVE-2024-38311, CVE-2024-56195, CVE-2024-56196, CVE-2024-56202- Update to upstream 9.2.8- Update to upstream 9.2.7- Backport fix for broken oubound TLS with OpenSSL 3.2+- Update to upstream 9.2.6- Update to upstream 9.2.5 - Resolves CVE-2023-38522, CVE-2024-35161, CVE-2024-35296- convert license to SPDX- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild- Enable build with deprecated OpenSSL Engine https://fedoraproject.org/wiki/Changes/OpensslDeprecateEngine- Update to upstream 9.2.4 - Resolves CVE-2024-31309- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild- Update to upstream 9.2.3 - Resolves CVE-2023-44487, CVE-2023-41752, CVE-2023-39456- Use OpenSSL 1.1.x from EPEL on RHEL 7 to fix Chrome 117+ bugs- Update to upstream 9.2.2- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild- Update to upstream 9.2.1- Update to upstream 9.2.0- Update to 9.1.4, resolves CVE-2022-32749, CVE-2022-37392, CVE-2022-40743- FTI on EL8 due to lack of libbrotli pkg; use RPM autodeps instead- Update dependencies to enable brotli compression (RHBZ#2125520)- Update to 9.1.3, resolves CVE-2022-25763, CVE-2022-31779, CVE-2021-37150, CVE-2022-28129, CVE-2022-31780 - Resolve glibc 2.36 (f37) header incompatibility that caused FTBFS RHBZ#2112282- Don't try to use Crypto Policies on RHEL 7- Cherry-pick OpenSSL 3 compatibility required for RHEL 9 - Switch to OpenSSL 3 on f36+ - Include automake in BuildRequires- Exclude s390x architecture -- not supported upstream- Further changes based on package review; perl dependencies, paths- Changes based on spec review; change "RedHat" capitalization, and add link to upstream file layout discussion- Changes based on spec review- Allow self:process setsched, requested on EL8- Set SELinux policy to be more restrictive on privileged UDP ports- Initial revision - Adapt to modern rpm conventions - Add draft SELinux policy - Don't run as root, just claim CAP_NET_BIND_SERVICE for privileged ports - Merge and cleanup of upstream .spec file along with Copr version maintained by Hiroaki Nakamura , based on long-ophaned package. ChangeLog included below for reference.- Update to 9.1.1- Update to 9.1.0 - Disable mime-sanity-check which is usable only in debug build- Update to 9.0.2 - Use yaml-cpp vendored in lib/yamlcpp- Update to 8.1.2- Update to 8.0.5 LTS release- Update to 7.1.8 LTS release- Update to 7.1.6 LTS release - Return stale cache with s-maxage only if cache_required_headers is 99- Update to 7.1.3 LTS release- Update to 7.1.2 LTS release- Update to 7.1.1 LTS release- Update to 7.1.0 LTS release- Remove expat-devel from build dependencies- Update to 7.0.0 LTS release- Return stale cache even if the origin server response has "Cache-Control: s-maxage" header.- Update to 6.2.0 LTS release- Add patch to add new value to proxy.config.http.cache.required_headers to require s-maxage for contents to be cached. - Remove patch to concatenate multiple header values of the same name in TSLua.- Fix bug in patch to concatenate multiple header values of the same name in TSLua.- Concatenate multiple header values of the same name in TSLua.- Remove patch to add proxy.config.http.cache.ignore_expires and proxy.config.http.cache.ignore_server_cc_max_age.- Apply patch to add proxy.config.http.cache.ignore_expires and proxy.config.http.cache.ignore_server_cc_max_age.- Disable patch to enable unix domain socket.- Apply patch to enable unix domain socket.- Enable luajit- Set prefix to /opt/trafficserver and use relative directories- Update to 6.1.1 LTS release- Update to 6.1.0 LTS release- Build experimental plugins- Just use configure --disable-luajit without a patch or deleting files- Update to 6.0.0 LTS release- Add patch to cache_insepector to split multiline URLs correctly- Update to 5.3.0 LTS release - Build on aarch64 and power64 - Split perl bindings to sub package - Cleanup and modernise spec- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Rebuilt for GCC 5 C++11 ABI change- Rebuild for boost 1.57.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix CVE-2014-3525- New major version.- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Rebuild for boost 1.55.0- Rebuilt for https://fedoraproject.org/wiki/Changes/f21tcl86- Bump release tag. RC1 became final.- Update to 4.2.1-RC1- Update to 4.2.0- Bump to final. No change from rc0. - What's new: https://cwiki.apache.org/confluence/display/TS/What%27s+new+in+v4.1.x- Update to 4.1.2-rc0.- Buildrequire hwloc-devel, since it supposedly gives tremendous positive performance impact to use hwlock to optimize scaling and number of threads and alignment for actual hardware we're running on.- Rebuild for picking up ECC/ECDHE/EC/ECDSA/elliptic curves which are now enabled in OpenSSL.- Add BR: systemd for systemd.macros (RHBZ #1018080).- Update to 4.0.2, which fixes the following bugs: [TS-2144] - traffic_server crashes when clearing cache [TS-2173] - cache total hit/miss stats broken in version 4.0.1 [TS-2174] - traffic_shell/traffic_line miss some stats value [TS-2191] - when http_info enabled, the http_sm may be deleted but a event associated it not cancelled. [TS-2207] - Centos5 out of tree perl build fails [TS-2217] - remove the option to turn off body factory - setting it to 0 will result in empty responses - Automatically verify GPG signature during RPM prep. - Build requires boost-devel.- Update to 4.0.1. What's new in v4.0.0: https://cwiki.apache.org/confluence/display/TS/What%27s+new+in+v4.0.0 - Upgrade instructions from earlier versions: https://cwiki.apache.org/confluence/display/TS/Upgrading+to+v4.0 Important notes: proxy.config.remap.use_remap_processor has been removed, use the proxy.config.remap.num_remap_threads instead. Default proxy.config.cache.ram_cache.size has been increased by a magnitude. Support for pre v3.2 port configuration directives has been removed. The following records.config parameters should be removed: CONFIG proxy.config.bandwidth_mgmt.filename STRING "" CONFIG proxy.config.admin.autoconf.wpad_filename STRING "" CONFIG proxy.config.username.cache.enabled INT 0 CONFIG proxy.config.username.cache.filename STRING "" CONFIG proxy.config.username.cache.size INT 0 CONFIG proxy.config.username.cache.storage_path STRING "" CONFIG proxy.config.username.cache.storage_size INT 0 CONFIG proxy.config.http.wuts_enabled INT 0 CONFIG proxy.config.http.log_spider_codes INT 0 CONFIG proxy.config.http.accept_encoding_filter_enabled INT 0 CONFIG proxy.config.http.accept_encoding_filter.filename STRING "" CONFIG proxy.config.net.throttle_enabled INT 0 CONFIG proxy.config.net.accept_throttle INT 0 CONFIG proxy.config.cluster.num_of_cluster_connections INT 0 CONFIG proxy.config.cache.url_hash_method INT 0 CONFIG proxy.config.plugin.extensions_dir STRING "" CONFIG proxy.local.http.parent_proxy.disable_connect_tunneling INT 0 CONFIG proxy.config.remap.use_remap_processor INT 0- bz#994224 Use rpm configure macro, instead of calling configure directly.- bz#994224 Pass RPM_OPT_FLAGS as environment variables to configure, instead of overriding on make commandline. Thanks Dimitry Andric!- Update to v3.2.5 which fixes the following bugs: [TS-1923] Fix memory issue caused by resolve_logfield_string() [TS-1918] SSL hangs after origin handshake. [TS-1483] Manager uses hardcoded FD limit causing restarts forever on traffic_server. [TS-1784] Fix FreeBSD block calculation (both RAW and directory) [TS-1905] TS hangs (dead lock) on HTTPS POST/PROPFIND requests. [TS-1785, TS-1904] Fixes to make it build with gcc-4.8.x. [TS-1903] Remove JEMALLOC_P use, it seems to have been deprecated. [TS-1902] Remove iconv as dependency. [TS-1900] Detect and link libhwloc on Ubuntu. [TS-1470] Fix cache sizes > 16TB (part 2 - Don't reset the cache after restart)- Harden build with PIE flags, ref bz#955127.- Update to 3.2.4 release candiate- Update to v3.2.3. Remove patches no longer needed.- Scriptlets replaced with new systemd macros (#851462)- Add patch for TS-1392, to fix problem with SNI fallback.- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Remove duplicate man-pages.- Update to v3.2.0- Remove trafficserver-gcc47.patch since it's fixed upstream, TS-1116. - Join trafficserver-condrestart.patch into trafficserver-init_scripts.patch, and clean out not needed junk.- Add hardened build.- Add patch for gcc-4.7 build issues.- switch to ExclusiveArch- Create /var/run/trafficserver using tmpfiles.d on f15+.- Update to new upstream release, v3.0.4. - remove trafficserver-cluster_interface_linux.patch since this was fixed upstream, TS-845.- Remove pidfile from systemd service file. This is a type=simple service, so pidfile shouldn't be needed.- Add systemd support. - Drop init.d-script on systemd-systems.- change default proxy.config.proxy_name to FIXME.example.com instead of the name of the buildhost - configure proxy.config.ssl.server.cert.path and proxy.config.ssl.server.private_key.path to point to the standard /etc/pki/ locations.- exclude ppc/ppc64 since build there fails, TS-1131.- Removed mixed use of spaces and tabs in specfile.- Update to v3.0.3- Update to v3.0.2 - Fix conderestart in initscript, TS-885.- Update to v3.0.1 - Remove uninstall-hook from trafficserver_make_install.patch, removed in v3.0.1.- Note FIXME's on top. - Remove .la and static libs. - mktemp'd buildroot. - include license- Rename patches to start with trafficserver-. - Remove odd version macro. - Clean up mixed-use-of-spaces-and-tabs.- Use dedicated user/group ats/ats. - Restart on upgrades.- update man pages, sugest from Jan-Frode Myklebust - patch records.config to fix the crashing with cluster iface is noexist - cleanup spec file- bump to version 3.0.0 stable release - cleanup the spec file and patches- fix tcl linking- bump to 2.1.8 - comment out wccp- enable wccp and fixed compile warning - never depends on sqlite and db4, add libz and xz-libs - fix libary permission, do post ldconfig updates- patch traffic_shell fix- bump to v2.1.7 - fix centos5 building - drop duplicated patches- fix gcc 4.6 building - split into -devel package for devel libs - fix init scripts for rpmlint requirement - fix install scripts to build in mock, without root privileges- bump to 2.1.6 unstable - replace config layout name as Fedora- initial release for public - original spec file is from neomanontheway@gmail.com/bin/sh/bin/sh/bin/sh9.2.10-1.el8trafficserver.iftrafficserver.pp.bz2trafficserver/usr/share/selinux/devel/include/distributed//usr/share/selinux/packages/targeted//var/lib/selinux/targeted/active/modules/200/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2aarch64-redhat-linux-gnuASCII textcannot open `/builddir/build/BUILDROOT/trafficserver-9.2.10-1.el8.aarch64/var/lib/selinux/targeted/active/modules/200/trafficserver' (No such file or directory)https://bugz.fedoraproject.org/trafficserverutf-87726af79ebe6a92d0e036aad7fe0beb7e902eb0aa34e9ea55c1de9669bf634fc?7zXZ !#,:-] b2u Q{LZk'Cun%B4P4Ȇe/ AjG#ݢ}GےTIK,%/Ch7N%3)y m35TgӖoz6.N%>rm8 ls]? VSD`nrRj0s:#I٣3T~+(J2]2720< ]TQץIy޼y Bˏ#*v3`A_ŀa2:E{0r89*]kj"#1Z'HOMvLBNdH U,g?@IX%}TnzĮ PZɔNeo뺽wP5~H3{a6$^{餔<,bl 8:G9Eɏ _1hxT 賉mN ṇ$ZQ@qڃ˵?kQr j!].ocuX>W0 [(4Yr}9< rJU}kX ,-t% z4"|1B&(xO79Ǿ3x-aA/"Px/u]o" s# o6k,7: ՘IDW&%](p0^ D5\Zk3=p(x'M5: KDxluO[`s@hGk6+YCvusZ+?v_;m}g gC]*G ˼A}o4K>ژt!M#-ۆK 3}K0eb|dF5]M(H4%xd!1NjC>R*Fe' -]-O_CJ2?r_%re17; ynvj}}Xb4z?)FfvJumY_&ϤJUEbB~m!]d9{+zQ('l&;8M=S*l Q UL8;S.w"./pVx@g{)-9q!ON;]7xF2f>ŠŬfiQ^ǠL0ڙyŒ'jH㇥%g햳n5h62h|/3Oظ/q{BsaȡKQmvڇGn>D %b "VLڮR'u|jyNa"eL 94IHiVX:.vd~ᾑi$oD8SO!ۜL;6=q'!l}֐.{/uσ G`pmDt&!\ܞ;&'myfv/y1Xpό/_JQAuӌbBسPcI>`tnArvbDb(u"ήp!27PH\_d=jt&-SՈvJ2-,q+sX-5.:&I g$wA:NٮB "XVKH+ τs|NlzTrԍ{|ߌ@칦><|$if~{-_YcH\-dRِI7hJmXP|!ju+'f̿I+ɒ^3A?`]G6j La UeTfeoK>ٽˁpF"L~jFUQ,V+H@B4?GBj'b<<$n&[q;qi8\5ⶌ7/RY*h%0:1 : +wCVҵ[7-Gȡ/K0F3wum","f=я b #W b7}ro8¡x|׬?/I,4%A(]&:Vۇ=Yt1j0`Wk!<1@*~Lgzbo 3.0WZ\^Dv ߂ؒnF?m6tػ?4F,ɂwְȀұYKT4éC .{Š42VfP;uZuQ֐3<3 Lٕ_ Ȼ#B3b ?݊W% XWZJaKo{$Z iƥBL/Pd%ޥ$H]ʭ[C$26Fm3HΥDD-U'__!F^2(@cգ4 Qjn`\sE%X`R/?cewM/9A0)=ئK=PyIDjJlf+) 'R6ϙ5?L`s,[?JQy[{ov2֦ |B[}`[Ry_!bΘp/is߭sWlP] "0[0oDz-_]~8xKLהo~~XV<>ĕU 09y"vsGC$R:|s%:"=}$=G2T*85_dz} JWPG-r7DC)F5}m%![. aFjk'F!F<\A4 ?\zRMzJm2s!}N QXGEr[na%"#]S5e!\`Ӧ \f!(o8RЎ6?}.:H¾0=͕0k&`B:XC6v%}~.>h:dqussQRYPN=}%~MhkK9A}er_TJ.yx&$F KHbXp9mqhrA72dg&+S;b>=H0a&MxvBGf cEJ$SȞ.xNwv&7rrzL͎W)Hײ ǐH?']qBWt n”9 -I4Iːi5 d {xa$آMCOxʕ :IB(=\_b0bhrix~2GBw69xQiQZz.tae{!&3/Q& b(λp^ [qk{$\7wwu]KW-/|2`s'$mlK C* @mjØ'GwW  >lFg BC0{ Bjz]; ;Mq/"T>!w?F>l[ktAQϰr)0?Zb3ˮs4_q?o>N۩+??0^A?kݪlM TTCYrUÃIr$+K "4N#&ڒ+<#!D8I>7oh7$z8` 5] g| oP1șL10m WF ҷإ)}ۙs6̨O$$Tu*E0p핦C+fShw+O+Y)R!x\krYդnMwm9LROcuG<%#쉂 zԒ)hMC̜}hؖК4ۆp 1S&M:d3׵^Oa#O I47;X*}&^Pݙ,n+Jw6B %~:‚Nr[uC Uӣqy{]4\Ia_]h d Gp4\P\3bl՝%&Uah'3[$ ng erB4sy'R͑">@9ܥ }\M¤H%-W>)Tm>+ Fr_Z˖)>1 xSUejl)+C6w@-TPO" )2E~;tq}_@J BS!殛gcI\ anX|Sε RjQ2Jg}'q͇^6Tw&bK{@~WfRn:/VH64S~yRn#@[DiwC}gX'EsID:TPz620 vD\rrcju{DCY!&X߁}sliJ/hP~ eUXu tÓBsx YVU@6 $SW5yHZ"Qe"!! R3I<^~v@Ir Uu0Ւ]6D5! ,b:kӤ^>D8IΟH˸XFͶ s5D-$7cKCRN",9})؄PԱR%l=Z7`C!1y+<T?"¨<䶏SW^#E-t,0($B/6TAgnꘞ9l{u`3ژb:Ӆy O_>9">*aɗRht1.IX]aMNT& > "OzYȭ0!dJ\ Yü^ /S'ݴ7=059Q^+]ӥᬰWFg*QScu:wum SqKFAP`j#1Ŭ-At'IZ T6`UҴ'ޜs3&w{N㤼af jB2 x^_K:߸m'=)af_Vz7NfA RD×>,v`A#Nn@V kAu W҉dmΐvyp7=YM/f+pB||S`S&+;˖38BKT}{ H.ϷUe<|Ƹ(D20VC>U D%w ߧE Ϋ3|D]K60e^n$`il /ԭ4uYO'Ihy\=Z9BȮ,v 9kwG ksm75bq6#z69st=o$5]Y^ggXyE7g!9gZ~8Z='7 s@=:*d@u{?h[-"Vr,Qb/cڰue-OjІCU³s=ב'2ːF[-cUF# [{R}bbYja@͹֞ M{FnE(o~< 5mx+uUZk)x0?GMG,+[bp5Klkc0c :Fjt-j.v;R?'aAuU9ӗ/1mH);,l߅5T毟{-e[|*y#b=5t̒ICt\#n\Ąf,1њ<1YH80dfTWk[ үgfH2:Ha oܜCRkN~rE.=;W/X yq!&Ng_Qt@+LDk 8VO'CjԝvP /_xJ?+- >Wz(CYV0ik ~s&g2FZǑ0s"^Wxי"fKr0)ue[qKɺs%OJ5Q+z !rM\c0x:v_ i? };ha1w?n{/nbQr$o8lN$ol' 0YÿT Jd$p,DKW? `q%ZXLm ȪX%`%j erˣdttbiH7vIX o.Ă DbH]qzd"?xOÕ--h;і֍μAzZfj{:.|)8_椓*%4T +p[tsE \ګ>RIL19~X˿W.gꉶ7^ 2jRIH^բp:~HZE Mil0z07( VN?a(R;DmWɒrL#Ed&{!+Jc7RDO5T8t9!Z{YA Xf?f؅QHJٟ iԣ$y('pF^-93m? L62~糐 w¥q^e{!i96O.{LcmX% =$BW˽ߛ)bhTYdy Mx96[:D( (V٭vL)̸qM.;&xf +sݘGG^&pٚgp[.IUgW}YiBJWhc=З3ONV܊w^G/:C&m'i^bMQmh*:]wr%O:W–Rl刉x+RwԡD-wWh.q'ǔ~c]g68@u&A5[\'/0 M#wt(u4/eDs)(ɡ+7mK_k8tD ;nUaё7.6˅A^Z[<2j[inr$`7gM&P˷fI%٤S)`#'CL,&TNL%?, mUb ))GVUoPZP3ȓdD\'@Y{ zq̓a4T("7H셫JWuBgTSl,npxUȮ/hx$K.ٮiavãPz;5'?k8HצJЉUKWRɘ-v%o?I@wR^rpJ8Hmc ChN'Uwi)f\lT>GO"F³hDj71w-s/wn,dby$a˪6XPSjX7E] SszetIxjKȾlHe6C,UyW~,;`snQ"yfvYeK2d (pW+F}|3]pLMy$٢Q5Yܰ}KF zʤ 3iqYxuT-|62~ฯ*_}PW8KIahCQ@,I-a']y\yy}6dفi@Q>djt6S0t0Pn !ۆKnj1ayiO_@ٮo 4&D~WgD|?;ʡ6"._Ox*ܒ޸h\8Ƭ?*VuPLϞn 8Kޞ˃~Qi:bR0X5989pN6Hx+s unn3Y2,&DgP#:Vk=![l3(3O~avJӔ֛Y%wO!nC U;r &k)8"mqt>2FB2h\3R(SFq};ЩmZ]˼жyHXKKx}<DiStM4t_M˰x'mg~u教 %ZG{6z/Y>=(q;z g}~ 7y]0wdrWN M?Y=mRE' }50 n`YE4Uw5Dlp#A :bp8-…*5:($L\.Leh8)qKj:R$@G~䖿O/';ƨLz"}2bl`+KNo3ahQ$NmA? *mYхjl %rJ 3:wSkyX1~c_$"l9\v=3Bб$ YQA ;P=rn0עknmxNƉhu&32,*fJ5; 4tdNZϬC{M( Daefyܿ@f%!!XۀItOB ÄS-6YF@νBINgJck'fj݈ d7$#ߑhU/}×{j 5C:YNjY i=ٓoAx@KPȬ`y(DMwDrJ9g鍙i| 9,_wm璤YKgWBme}k# MNҪ#;lנGBQaF׾'>6q.䷷ p_*iO41(*ɏHV=9df"-75 bò)RU8K/| mb64KMHm/;ꔌ0ǐ(Po5:57řJ'-%hiuyH3|>j +{!F`p^|{$"3)*;զ&/_ɖ%{ gd1^ܗ@,vwoy tx>ԁO"ڧg @,MAF#4g }%~s[81BN{>NA%rɮN@73qϞ&N|m[ #x)]k j[zOleY&:CNh$;>[#D.AU2zҠ)^2҈Y&u V(b5+?~2*_-B7  =K{"IJd"4Q̫IՏmxs@s+)Td0xaXnp9' 6&$FA}G\% [P8==+kGܚ0WE}?nhӑlOlj,@dɪpb9NjZe|N3(UL֬3Qٙ^z2=| 3CJJ"mnH[g~CN,CT{WĊ13柔0 'z_S4靯VWln;ʊ;G#b]G0,%TBX{577 P0o zfAQ_@/< fR'sX\Jٿhbuc3VB(S<\M5"چn3j!^,2TdI H~F}P~ XNB,c,c ~=pR3PyY DZy<0X5UO󻤬b H POVhOY9֝➳i B ؙm*NV^nVW&UB%ٓH-1hξZCe]牀_ۺ![c.r'ژw3h,|Q;9NB>zc3X-&J0nS,gCk, jmɊo{n]q鞲v}Jz4M3sG~e 29Aэc^vCMx@E&JJokƌE-y+|5fHhx f(4GDmqET}g7|*5űЍcWrOnُ|?ͼܭ@@یXt^p9B<̰6"EFoHjzq- Qh5 bc)0E)-ÒhW}D Xn>7sR5v*T]`eQzV$5gh‡$[j*Fhy3<̓$| JqTFE \YGrZu]㣶 YZ