container-selinux-2:2.119.2-1.911c772.el7_8>t  DH`p_6!$ƨ2k'rql eɺ=B 3m;_L//BqrNQ>ʏ1Q(ő}N/`NC6-`mav\kqd"1v)KBg<׽fRJq>=!,1 CqSF}OߠcE=K7N9(=a13> W*e kF:x fA/ z`9u'"M7O^O0΢U$_(MsNF"N ]dF:n+F{B1d7kco'47s+sxq=v%!.awBiihqL>?5|?5ld, 0 X %+2              $ L     ( K8 TJ9|J:FJ>1@1B1G1H2I2<X2DY2PZ2[2\2]2^3Bb4d4e4f4l4t4u4v5w5(x5H5hCcontainer-selinux2.119.21.911c772.el7_8SELinux policies for container runtimesSELinux policy modules for use with container runtimes.^x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if [ $? -ne 0 ]; then echo "Error loading SELinux module." >&2 return 1 fi if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : restorecon -R /var/lib/containers &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&IvZ%A큤AAA큤A큤^^֊^^^^֊^^093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5db1581d0bc0ea7dd4f3844dd771c2e1f30d62ad976626ab513efeecab4ded27c043ec4bc5f89e7db14ac000efecb018aa85498b1205eab0226dd943db19d6b718rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.119.2-1.911c772.el7_8.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3^?@]]D%]'$]@\@\N\w@\4[k@[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.119.2-1.911c772Jindrich Novy - 2:2.119.1-2.c57a6f9Jindrich Novy - 2:2.107-3Lokesh Mandvekar - 2:2.107-2Lokesh Mandvekar - 2:2.107-1Lokesh Mandvekar - 2:2.99-1Frantisek Kluknavsky - 2:2.95-2Frantisek Kluknavsky - 2:2.84-2Frantisek Kluknavsky - 2.77-1Dan Walsh - 2.76-1Dan Walsh - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- fix #1811759- update to 2.119.1 RHEL7 branch - Related: RHELPLAN-26239- use 2.107 in RHEL7u7 - add build.sh script- Resolves: #1626215- bump to v2.107- built commit b13d03b- rebase- rebase- backported fixes from upstream- Allow containers to use fuse file systems by default - Allow containers to sendto dgram socket of container runtimes - Needed to run container runtimes in notify socket unit files.- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.119.2-1.911c772.el7_82:2.119.2-1.911c772.el7_82:2.119.2-1.911c772.el7_8 2:1.12.5-142:1.12.4-28container-selinux-2.119.2README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.119.2//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,`1] b2u jӫ`(}a_gs-屑a#WR00[Dhr3SL_eKm ۖ;ljFMwߌt`zCUBO=]#@RF7bâ܂b4#Wʑ A[^hq'AޘqYj"pF%=؁8KZJɂ<@娓-EsD8z#OaVnY_(>E(P'n\{8!N1sa |k;(~ ig<&-z|;]D Pxn$zqP"#?O;I Ui_HŏcxV~ ,2!gXe}<6ThRC1BBZBWDQ훳[$gt>NuHpAJ +6҃?b]}F l+\5>^?"UTnނ5>gbܱ>Rlk*p/]ӷ ݿ$R-pM*(̲OԊ{&ᖦ2ybȧ{-|h~潝&U ;Zw=y펲gd(Jz6d6 +:wkNr"oI{_hq!mm<0u̹T#ZZ*FUS''4) iMͱ6j%2=rOZ'8B.'hUe=ҁ ޞ+PܝWnG$өmoAq! ݢҫtǡ**5tNu#nAhQOM*}Dr;e|}I1 *li#su†zi,B񚐗w f>&豣e- [h>brC#&2.(v̎FWECA]Q P'sͫ6*uCūri_;n)Ny@3-T[!fC՚9\?%r=XYBAU*)'B]B$2,9H|P똶}M[]M"m1@2|7u˼:lMzPĿ]+y!R>C .A/[;q YٛPqgqs/U`縡74x2Db$97&KNlH}@Ut|7ADm@ƹcЫad!,L]Ln+z% Z{.3~S|.szmgF!SZg$m WS^2/P3_xphS0]br$C VfMw|qe1P8ӱD/tqF xWW i.Gq(Xj L#u+< ޲|8grSd.A R3ߡIH]]ƢqpUt<2CxÔfE)K 2IgXu`e45* ʼn#\T?nUG8+ 0}/k!.Ԋpoc2X;,UG lAڜh)HiNgc1B,K^Th:՞ڦ5z#6O{hd(@]֗UUaY6+]ɚO5r]@7wsDRB%AQ\[V]&zK29k,c7 ([ ! e[9}&Ͱ nrJAӧm|:1$Dg 9ٵtvgo.5~: E272;/%,t"i+6{"q2ѸC a40I:*!Y ]:gs@gBUX`=<6D`6jP5?CtAm`!sۋ3oxgΒ&%qvЋ*j$ڜ1~28;N kVSf8RrnLYϽl>m0˂LC=GI?́`\xY (][3xrtcsYZuO0p7ciǗF.#+gM#`B׃(+kG-<RO vK{^E[DUm֮fl E~)YEu=Z U+FH!M<,x%gWu"NV#Gv\S[ 㠴@Qࡡ/lV4H6ߢo=B 2jAuOH1|&$|DS*qdG4S2#7DGrT[R׏c9|m^ ;{l2-Ȓ:b?1Ly 8C3O/)-\7ݎ_F9e){ hؓݛ#Зr]B/F IvHL@*T-hy7y3IP+Ѫ!&e/~Hv4/BZdfa!$Ζ VK64iV!?ܢ ?E>O#Uy%E:gQ<ֲ2lEg^$!<o5!@h?=L,%uIj wIB4`iw FDf(i#.쌁hcEwKy*E,SnoG^4d~pZ&Cb3'}˛-@Ԡ/x}h7-U+MҡES qLFctWm@?E+.TX t3Y,NҼ> taƩhA/P_'t-Dq<4*KZ pJk>RLiѹq o6[89զW0X'h7ۇv)ƵCpI+%rIKƐ8[}"עEZ y%|4QE&rlǘ46#.:x߯ӍګWWg%m2]Ȥq#=@G:s:B${5wx mkr B#$>yHH+C:fg-%Zl`R`Ɲ|5 OȒH]Q%. cy8į1^!N&ApU(7aG!V](U^hK ozE]pKk`R|pm[K,j,9t0t 32XeVץkDʺ'(ryȒ ,N(k5qL{Unk?"d!BOD? I?'#!0^ɏy:te32?Rd i8)w9 db3Pdr2[ zn_(L/u_'scn;tizb*QzMT5~pbKdkPRf-m3KR vMl!fqvu\;sAGr0N/*YkW΢Eq8elWTj6lGKY1quɲT7FAgHOsk -c>[${ne cɘՖQWMxZ2q _u+|)h.+Ttde&*Uϱmm0""<ɸk)[rqU{m(JU+(1?8m"[/mFjuUZTAbeWz=>Z[Yx鴙[)|1=֊)IߛĪ\R1\w'nP):at&!Ws625,? &b:fg"sV+𨐫ivlVR|&puIS;=<)ذeUXD8^5 FA:|@/ eOj0,:ljZY)^m o8%HÐHVT-bm_&+ Y?sz1@2h瀭0ikb/Ow*.l 1<I2->{T6S ,rj~w ax`Or sln,Ypi~GZB ?|ٙ{Ӭ0xV:yufd騚M6@3~[+Q8-[K${'{ڃN(++k9z){"2$( LwZV-Ăd.~2\M]+U~ϻ)p? nJZN>~e\kH:v[- D%[odN7ξϙe3OʯNA6nS F }ag4ߋ81 R)s15]|"܈vTp*4垡U6f &ľli|!Zf)O@Zi¤20O\_ T숪Hc `(tK>{v`@}6p&İE{P(? {%l3] FuL^.j-lhי*VUbʰ\C3aclKx)@ojW)?=`dʋe0 H6*46M%*$Q/NuaGKnd4MGɄZm]jғNFuמ )z z?-f1@l4|^ .dH`.F1qRݞXpLsDa>PҼ0FÊAki668 *BD~ ~INrq뵀.(  }?Y&l!py2cxU;=+.vv(yP榉N5pސdLY+ s} @}F5%{XNJQ"R`F/J`Qa f 4c5B%@3{ ~!M~l; *D9b h+X92}+Q|WACCH4y3! DP:jC?1["\2Cs)M ;~Q 2hgcG23r~Tbut5-yer6a9_BxQMzZ"}橆0q|KPUygViFQܘ[xe;=OBeDL`"H8`Bvv,=oV#\wPWt_teux2Oi3O&Nޕx?-W18_iFA>5^/t+' PvbSY'䰇m!ۀ7H4܂V*OyL:FVvPYaMkSW Wr8 +՚}'9af T.C;lxI9VdRh!i}#cg>@00Pv\$s.K19Jpe ͹34BJX?.̤JkZ?M 9)Ue0Et[s-WA{٦d?tc7Y ]'њd>T^yQ44&DJ2xcgf7nql?Nd6yc7EOƐ E]lԷ#.dVvl0nnC) I'8W2u&wpi "R\BU/z]xG,lҗ\ygo{Uixj4`uq+'[6hU6wfYln\lZ֒&5Vy$ݵ~_r{k&0 u"s~B@l(O(d/@/kv|\eu#zvaUH% h&AWIE uW"ɭeeFX"bod*jbБLB[Zg'۹k"3~d@C0"w +(AYF>uzfź s TKe#־nKi+ᄂyX2ݹW: $%(u $r752ofڙf<:&%̢"y_Ô\0GNxij0N XH9qeGz*Ghu:MILg'_S*U1c?%tw,tIB⠢SLok*U'^ Gm䧸*1g'?4շ? #Iυ}o)yC Հv[ˍZc1uDT(mRs>'J'᳍,Gswqyܗ`T"RTS%X?a?}N"#S@J|X=qA!R髥ř犫7<~J4'tql?,E:9-YplXC<+J^yx eP'.Ssj3ueeO FERsH eZy+l'xPuenVv)V7&:S `y!YJ;}դHiFMJҋ!̄ъԑw/ zG *Z;px  IcT-(okcf wd +W};k싨:r y=pq %(GOw UͫU9K*W3h/]0Qz0Rp3]YrnP뗵9b[ctP<5AÙ`HZm<|"fa!]ŷ;rz<9WsOi_]xWػ#*X(E*zSto'{a=WQ[ GAr7zd>"dT Vmn4$Tp+"OT~+Nd'?J S$HJ䘩T #EK=RSx:x dBdF_AˤZkdz%o4TIXKNsNVJ~Ra*"v(IMkzs[ ׋ t=ZJK^ʚt{#GSFix<⻇\?v`~yt1pD_ԼjLSL5 t跟>3kd~2!:x눕´," (ygbǙv>b MYmMQؗ訾}guQDXE^SYI> f&.gcvf~3:ZZ}[C #ak(7>):B.jX烏3Ե <ńZZuuvqYԥx o\m~=MZ_F/zlb)*(HUʋt\ȃ.r|7T+YRD/X2Rj~" m*fTnČ}T$Aޯt9ϽtQ?7wo-DP>S=}ms}bjZ3u[R7SAl=E J1㣂Dq6ӏgWgm5/k o!b]\e N .[CʉX7=Nylүm܌(ZW5;G zߪ^d[Qݶ<7 A;= )AOr Ml 4"8ff~.aFQ܎T}\+&ĀKL=;3 KuKG9K"o ~PPv&q̮ 941b tmA!!j֒Ywk\˴ RA(y)%BhJ}O|Pf{8GFrc4V pD?xTsK?*6e\x. 6ަ˕H?8'0'YޝR;InwJ&[[msvƠGPMFk 4?̎/R9>pY/.Js46Ro{ɲX wL}H1K4?塋:[&Wt•Q kCuʅ6!>cmdAԩqAեET}5 q$L jLXLTJ5!WZ,?tRSː`c+PQϚSg M%zGl&0+zK[/Hk~*4]A(TbE+#TEAqCn=-JEq`o+gx+ѦBJp$dD L(ͺ/ћjQJg͟ n⥚zM3)΃n> r׈bkNx5cAn̦}F Rn>ڠH !9V"Fk)é);$DmY3NJX}E& a']#) y,l>!OI~$QS9WΥ+EpZJ̘+P).⺈:gRV^QoUj;ܖ|! ;oUS*]XqJ1V1!i@/d{9\ =źBwvr| SK-|QՎ8BZz{is?\F{ꍐo;uwpr7?3JRN'$t0iDLYJ(D 7_}-= U4kbIRJ!Ge7_MM; MyNS dnmٙM[=wyz!5wBAg; @-^T*/FBLm2rQh9uW(טeT{4jRNMۄa8סZ!WMe:.p]\5 V/s\6O[ b@EkS$ɇ9Һl4L7_d+y^M oSJ_%d\"_5ߍ g lI{l.uq,؎+kfǣ駝lOQQ '~~.{ hy_S;]UҬ:eu!0k@>ƮSlY4d/srn!gDKo?,(^|@C>Ay^2#W4V}\"Q,҅,>dRx]`VI/ss *sހB_z[@3 -֕XD^Xhm1+mon@bMOsjtz1pʲE/@M@ C '3ti1yhA f.KݩYL!f,\N;qAPi!c5pZ !46_]?<@C)RYez쩜Kp}kD#HkcB,k3̱2\g}4z6F@"C_!12>P*N>,{;22zű7^V7uL?=O;nhhK$D}JDžVjK)xhq V*fc* f,,. 2%1|A@oO| z;fqqP#+~^ՌHGVY1ߡCQϴ!3/e=SX@&9$4jrl /Ft-/\yI)= 'zgr*bF"YwnӅ\<'5C&lLYžhr*Q#q2*a,eO$b˿mqpB=}0 $Aѧ.cA~ܛӤ)t^9P:FY3;mU5IuI⃆ С!КHG_k^S@N(|qH2r:&Ñ~{(/nkY!Qa  nbv.N Z`ǏX =rX(2j_Cє{Pɴ@ݾ|GzК݆puSŵ߱"|ڀ%2opT\bk`9.pwO/#Ɋej0oױl 'j jڈ9O~#g< jEDk8;1-C zx`=㡯eZ3glp+)ٻ5V-ejvhg |P׷u+mvڶr=%dAڡhUn= 88WB0MDBvՅScv}A,- vJhƦf|Iod3*(̄P</}:(5 HFmzms=gK U/q1mm-OE]Q~5P ӒvH^›e)qk 1/.C4XDHǯ4eͬ9](p'{ݢIҒ?y4=uJSoag_{p2 :q@ZYg6127v1ykB  әt|^y!*Hq#] nĆV8~v;§KQ_[1nw@sr#><V=:% ﴌe9.Zt4Vǔ-yթ?cV$ >(qIJ!:tmdl%i-NtRBQ;n35O1X4~g@ @GړyonF=ې3S&.eEB`ґ i& .6c67E9wu# 6^=TmE9HG<r D;";v| B&9 t49(Xk iWNtT;T Ex_gZ2p'XbC9> g AU(1cH. @e ZR+^Uy:nWVf\Zԋj/Q ǫ^&]y"5E,L .G"L"STv&m%ΒdR,oqt}ԕ+xI:Q d4~yqS1؇l%%Űyѷx8fhZ[cd b9'CNGaeOdµSk.omc1Tuzsh]*_PM3t-tվJJ*Ibˇ(jlQ7nmzDw"*fRJR,Zrn 6m|A~be$v~ǯ1ѓ w[m'$"e9P:?+;)_N 9ټFچG4ރ-fZn֠E <;B~7A )"7 w$S_nAoE7*PM ![[ {Y!p٤ﷰ 5)̶ _:[oMq/n-*W$;Klv70 'Э6L)K1!t^҈chY@I㖊S8xtB&<0{?BxrXMdIpCjLcǬ?No,sA}?=v$6b $![\Xd57jʮ'|7*gd \<#nJ\7&+'  'yTzŋKz:q(_t_L-Ґp6"-)C1`,uK*n?ʚbSE@6>/ պ`z,Y3G_,u)gVM}17iVJ5k;#SA¾~m ( Iuٯr3eq׌d[Q:Rۈ0F?LMA305jhta˻!p@ [p~Hx ƁOP'(mp[l7{Gv2$ϋVk22CqgO򉳊"Б:~%h(.P]u0 iL!&]{P'Z6Cz؇(ˣ~h32- Arz+phVL թ*@ms}*rėm`ZU|m2  * 0%e iĤ!w+S oºJBaynӱj`*pAӹ-1͇/pJ)$vU,?J7 jChHN4q% 07oXMzez:?AJ~eto|sjl y.+R9#D9`:fY6 &pސK%$;. ŏA:: F]kuCmIUsF) 45v(A&)/\_WYo =kV衈(?,aM=Đ,S(}T0WDpŦ#p;E*: ТFx!SDN>r"dd?( y^л{j4R[o Eb[g0 +P6ޜgeSYKeg{Hl8:);7q4ȱru8B,&릂fM}KJ@9ǒJKu~>RTzK,W0ϴPKx>>ByngqZjMThj\sűkE*9K*˨[4- Pbg䷶`vkpXч9ZaA2^I bdTgDQ!ۯn J[9j#[CXXYOzFn|Q6SHtg&#|^) Yy!}5?s@.]"6ZɍL1c[b 8tqMܟf8dbן׌ex;` u+hśeZfSe>( =]Ny9#)L+L-3(8f{kD$˛5 IJK&((]i1gv0 =8)O:(fF䗟PaNp`7wbQ&Iqa`8&aDw+2MO[)xC+ŭ(l*7Rė-s>Bxmܚhz|݄Rl"*B|ϽY&1}1 v2뿢K*en+8@ntn6I|I>Aب7o,jڷa(l9۲5N1fF1Ma;0 3:dc2*w QKB۔N'|_}ǖν7~6R,ŹH^4 Ear)h{W1 [v6,%z6r0bnApQ-J.)ڧ6.ErS06&S\Rr3ֆYEB,zPX"5Gt%H|bP=ihqvXU0l07^ #.|ÅIX$jڋ@U,gSٻ#_Ր\R-=Ɓ+a!j0~v qB=;䬂D?9*MO6_'W?A+1}k{|nܤk;+:Gcz2HvuMxl=6o6v+򘄿u)w;:~|u~#%#l*i[@SY>6mނwa{rJ,E$eF,9M#YdZ#MUfa$`feη}3 i*)KEC>mY ٠iN_;E*R EĎ4~xb41AT>`GED5bA^o#ol) j?"$6etLIK_ xl\$7u!zƙ|dh"83̋l𮁫=BS, D$մ&k9TIIX)Pv>k)|W gmBVFeے5s(,R0$"p!4 O/Px|8(s?GN ScH`-z鑪aN4I}W%VA :IHc}x\'uHR c,/(QƥyLCXGnV/ 1KC.ERL*X؂i6!nf_wQ]ß'}mIPiQbޣ| M;^#mIz>_*lQ+ c|;93#ܡ߇&g^ jEylzY6Vؿה?_Dg{E1EH6.}rõ6Q${&Rh[R,ȫo3=P|!A{1Z1e3I<򄴦\mNm@NNv`AR-y!8\-i=K|Tz4}Һc_RKPg _qQx˴s^XTk% 09UXMĴ o3~D8{ dfp MTI޴^ՓM`S N'ud4Eʫ9d*(G+X'3Hږ.o6>22?R*Z*Hbf_JTDk|hZ.D?Sۄ}bAI[Vq& PM~NyMQ2rw3hxALSmz7'o ߼C Y"~M .7>&Q^hX@oS .H'ࠂO4 = R†X҆`Yj~U7!n+zdNЯ7,Sxʿ: UGvEVX{+X ChAC˽J!`? q}:CGxulY 5`ku! GEߕ*ђ^%+zk*)cE͢/-NAq1: hvE3]J)D60d@R`_GIGKCύK>@#{c-肀e.$u'BaB߫Woc 1BqT5I^(V4C P$mZsLgc~XvV3  @z,h.+B?!xxk}6np9]vC[IsĂ aD\#a$RU,§fsM+1+@".0 x2~o 涳\W^6AߥtL9unge5mo\u\70br)}$8x;AA EKLE`uB[fO]m~X}jKJo%v?6V }& B,ݭ jFXw;k"Q6в>HCIV0pΕ!JoS* Tylo;%lvze>7|O#,Mp)UdV#s܎6MќkX /0-A6pk/p+XMq@wlJWUʙ=UGMЎW8.!J .SS8bqMa=e܏Rê9qMH!O)y?DXjPv`EJob8 z[cb~6xCgv mmxf,Ph Oѻ; ߒ8cxRg0  zB0ٛx{j*.Ro( MV7\/H u|`T, $}ƊTs P6:y.Es)3,wL[(By QvK`!ksI5Z-';Dd_xf3ڠ߾ₐe<*_`K[-[n8Q_rqDg3!L/4c,X]%SM>ԺwC*dwă kT9$<I{qgf&O5OnyAϪ @>zc9ŠR'-:LzXS: Րt%px,z. BD9RQ'v|B oz֜U9⁓_>~Viۓ:j𴏱ԗ{`.Ŵ mzWzBڵq~:M%pbKR.i,cQ6Jhg®f'dEviN?V) \+I;$fԮUh*_ 3aX&T|aI!fA _y(mdFWrQٔ~R Xaʚaљ\B;ĝ[*F`+{5>+ X#$UÇިOSa:7 |c~pǡz YJFT╟fa,8:"w1 GvQI28 >fg .O/ZLv]!\^_n[¿qp8VBx$A 6 &I;۾,L o1m!A/R}FtkP2gLEUSzO uR)&g I(91|bY& 5Sɖ^Mu+>]*+pȔ>\P@8LuŴZPrfweq=-r,4',g}[4#xw-~ UER}DE?6o+No:]؁QniIN䁬  [nB9sL=yCkPz=pmh(fa}yS1< 6"<^6IW%o9 yWRہ9qqc;&g:dQ\Neʁ\Sv?>U!hZ3ևoMhI Fr b/8ܶhr_rk L-OQaA)CZztIq}tu?|u nJ( _u)W}+Y3NBgaF\ؑXWþ{q'w?(f2Q%f|"yJᛋѵFmYh阓{FŒLf*B{P*Q~_-iw-`3xgGЀɤ\naA GzE+چ2o7,Ega}gMhT*W_%ZtFH~ղG,73 ~:vrU$;hɑRw< F>DXǼhlTVzqfWڒ9`7B6䑓GPSIg磇$4L|EXy# LK!qT`$U_q(}T),R3.L}.^Z^[-GeEP |gY{T,}DlIL%s;rHfw^n `͍ω*i{J2 ʽvD~oUf)DҾ;N.~9X%ݺNa2txɊ[PDm'pn 73*v|>,<7Q-6Oe:CHžXt^Ed+h?!*/n`0 9hgL]}y4I±sOg=4#R^ET}7h`AkTB"ޯ5cɾtrg0r"""~gm.B>{NX_O5>CfnWN0w'dDw&j6C0 ̙Yvorm-.fADeWZq -{ zHU%MH-'MRCl巕uu([>"^|Ϊ $L DeX{ggAȌ!q%wݧfXOJqvz~g[; .q-ǗT>9g,BSPyC +rzEjh7*!ݙm},1IeH $ݫM.]Z2L`(H'1< 2߀'=ޯf4wS6K.#Clɦ^74=YS :Ṣts}TܳgRPIHC4'2lFs<)fPdE d"1&!h!˗pl6RHϏDnESir[HPo~^qwqī6E%6@um!UJJK3[ i`*( eޥ &t ;OA\ӛGOk&@W%=@MA71ڂ}A&D0 h6@E-w"qv7o8o鍉A:׌;d=/fD\;p@ yO}-`[Cv=!e!3*Ƚޙ!' $YF+жɂK4^] 4\w}ݴJiHcU`7W쟿W1$ Dkgƻ)|cV:M.hJfDŽtw2%5dB)_'JCUl@eWsp RRAZ$kqdE/Bm<]g*!pC =h)W@oN(%lXݏ[mxWO=Z)= iV]g)>Vن*"g:g_*TE lՌWy UH|=Zbz2=PNB J5Wp  Ǧ& Zi}{NQfz_[C !IЂc]ĀvhK!Ҟ5Ьċ5TP&%oz8wq59ǹDM#wc{f $Cex-8]# ywnEhJ&*Ra)_ d$ t:-k]pw6yd^yxߕGJr(=f`L3*;bDg;4apEc.s u m(cHJ שG}K(H_uxIďz>DFWS~$|SIo YZ