container-selinux-2:2.68-1.el7>t  DH`p[|l$ƨs.PCAOhCfT ɩ29)[7x<&,q^Mr,yiX^J +X>dS e!U'[>#޷ ( ni ;Y5n+ ;IHt4B* l? ȼ\@!<zAMNP.$Qr )&GC7InRBS ~yƍ8|GCxefAʿOH2+ 7DPAFxIaGac4I{ R ;T#)maL;cyW/ 5jh3[,!o^J[65vchV%KS؉ye% {`4އ)˩%eJ@3`*J\Ȕ^s}A$\'C8~q;GBN&L,Mʍ׉ʴIše TO (fG^[4h6&Ҿ{~]o*\7b9e7422554acc8e65f4e78105a20b3e8ae60ec52[|l$ƨkT,Kxb^_'H翪 00Yq%qcTkW0! `%zyR$lk4.'4+pȤ3Bo hm#"HCەLie@ʿ,xCTwkP]gOq=8ϼt?Jp'SGh̿j$>;'S#GFIhj-0}، `؂l<9Wwn7O$>"Ln˱֑+ȃVz"\#Fʱɏ_Q ߵ[`˧X3(Itw5A"(iDJج˪ma^1QT(\ϗe\K;=Wj.H_c *>ˠ˔ 7qw#yWi"N T?-?-xd  $ L ")+          0 X     ( ?8 H;9 4;:;>*@* B*G*8H*XI*xX*Y*Z*[*\*]*^+Sb,"d,e,f,l,t,u,v-w-4x-T-tCcontainer-selinux2.681.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[|#x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_typesif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?R|A큤AAA큤A큤[|#[L[|#[|#[|#[L[|#[|#093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d37e0c13396ddc379999bf51551c20564f0e280300a625f2a691ef2e11a37595ef82d3ea6281deddef1cf257723cd963de762d45831f34a25e2c20c46e41b9f8arootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.68-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.68-1.el72:2.68-1.el72:2.68-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.68README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.68//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,X] b2u jӫ`({uG 99^Q}CC.Z Lf5 IE?f YRaiE}P5j?%ALCZ9eY` 'r/"k nI (ü@^@ ]J1߭Vvɿ$8ݢCH?ZIU ՒG 1q}R;Dԟ%}=O5%A& ZQxջ@eU &o!+~7v;Yב8Z%7*Lc-+]1s XA&E-'ѕ-lUsqUΆSr%g,k㈇0ǃBtrm\A[HEO1ܳ-= Tę >xg]QUۧWO}mq`-vt<댥-${eTo2蘬f`8`6tJQ@uCETxɲU8rq>mWNtoWGh1ݷ)zK*\B$3>H5q}X>%0GE˚5TWy:N]͑#&8N߭kօjSz>vk <\FӢѪiK`uY"3xj"ڛ%?(ϡU-dnW#5Sm(-ٞ^+@^䘋׸wijݳa}9>IE,I2y @Vc{1j1P Y*,S,jȻ{4~1έv uX>,=тrAr>GZjL ]Rk:֓$Ԧ(Mgq cPC|GmaL !K B[xukZU,>_POIY ~L 23 6v`Pm YM Qc3V$3T^05B HX)ߍʪ}X" X PXKCF57I3h0#Zzd:~*Q7]3= ͳ. VLG7^y=c ?$i{lT X~m"f&_M2&H8ɦ!%dc;v#U.cn Lv l!rPs]eTubՁa?Y LS&B“ ],,,< mE/$q-`Jם:NQuې7\hc$lՕOB%LHWj#d`=&[PjdZg 6xnVx2gz:ry_n)0uPڇԇz$GG:F А9="#_<[up~T͖Om>WFBM0(9HʙH#CX;'FkBlɰ)&^f9uyb}ӵ4-GyAH0oQ:@? xU2䄷B7hθM9Y}uMdJlm>f T|0 AbY$H&]/gT ڊ`CZOTUAc 2*=bKкFZQtA_xCIڌ B89]/TZ8^1,`wiFzn]e)@Ud =w,,T`rOmvĹ~~xUP$Utg%^!D|>;DY tY3*.Ǫl݄-$ޖb>*)$^rַ'][Kl[dSu7sęa^|B[@*l#3QøQY$ZZcHy.? fgU?1#>9_1s/D>nC҅Dev@~|1=fqR 3]%O)*,#/ Td]M$)ƓU^TGY|dJzy8Ss~Q('~5fهU/!PE+U85FlAdF~a BQbCbGn9 Y]Uy|(j~uUwW;zv@[bX~0g EiIϚib:%^f\(jŰQŌ& Ņ|ƴB7a:)PC&}6A(kyo6/ًKd!qp,fW?zaQ5X}G= i؃B7Q'Lk|!C5?NZis|U"etQrfH)$+[Q HY}SI1*^2? o d=d |nҮgǺE66zVdYO6!+Ŭ))Ѧrd!e8"l]Wi 4ᓈFEp [kkdQ@x]ȼuje@2xf)VF;1'^Hd}sGS<^Lmʟ!6"<4x#omWd) ֌E*Ej ) EP|U+%}{Pqʣ~> JU_lƍp4N[x̦M[,h*;!FvUZ1U_"罖dJA'[aACGiUl\tF>C-ˏ1׺Y5b9ߪH2?^T"bޒr t1w,Lj,z=#AH#KY]R+=_:r}nT s鉵9ln_-y*۠g(eGKܬ;]kh( 9Az<})fsVm;,Δ.Gm,pn* \ (wKѻ ~DT&pu5~fCjTY`5ʙ_OCGB؟h2(2_+b5rb+^İ:\ ׿KFG,|RvҤto>xOJF` 'x  - c D:;`?Mc~EZIV wE0(W:Wk-֤M}KcSvC߭#rI_+WraО?MLbAp!# {]7 NaWl6 xPKn(!ӱ~2P-﬎"9)Vp\($&a ];b+M1ތy7ڌVNWTK UNGJrxH˓w}g@wrLo"b?9k]U \h$u# 94Z)FF֝2>cP%ѕYpoX*uyf3dY|.]s;XK;Re&`dh4KjlH|˄7G@k. U)(ϴjc&Z)-ӆsں%X ](޹ǣZ JU樷ej^BYƯ= -@)8pߨnnIϷj,VAr3YzYu?מ+f rdߒdQh͇w0oW`Qr DS2N)TkOo$_Ϫ,)s_\&B51%> &$9Oxv,tפ}+Z: גD$9Sz(gKXsbٍ ^3_Z  niM YPm]bӔ1!='CfşmDBkb<-+x 0(UtG | T/ t'o7'`Y;b+n T^ lùSFv<x"Q8I8>b%['[0 K"u 1\T^oˏFy3AA\Z%$RovH/ S!Oj@Ћkƃ(4|2 Pӷ qWɃ5,,qL{AI7I$\VmÐOϫ+aSIgHu[k݉1hPF*'ovV?6.g&"{|O=5I)7_.gqHQXᥢL/h&hM--o``:q7YfnAIrdϭ_52sBPzXE=nReġ׾ufDfiq䕢D nxC ȶ8`J V 81&(::2-r ҇ۋ}̩yD ,rmn=!@u&K[1VJE27oKG}5NqS1mG"$hJwٜB$ ókfM^ /ճ%h&rrchU'qٛ[Z*VR:[t}8YB=a|4܌bC }{Q`RA:_8>Z$4Ɯ|c33a}!9pu~~q6@Pi&e})ψ0(m]iENu>(B!n~,Hf5@!vAtTJ^ zu\:F'‘^ƙA0gA >KR0V걨UkRJV.(r+#$Fe1bRș?ݵb z3 lĵoo'jv>áZH+0HRMFCb "Mc]x@$^iftR:N-T$Begu0JtIr`_N?3MA ܪU6;BX0Xܓ)yEȴi' xxcYӿҫj-y&).%kcKiuAsr9a]hx?aKȡe p}-¸V7܎!vw jʝND99eJ-qGoѼ1\D[0qC:f~5.U岅ªnWtҷ?P<((yʹWT6[Dԧr&J1Ef6ٽ\RvMޭJT"4N,kdkHn_Gzt ҈ 1>F|QO"OG=Ms`[ZRerC1!عi-)`}P.UJ}qouߜSmJh ^`,Z Cm,)R;`0j9*Kn]y!VC_  ݲ(8^h!RhfYf"=>qpEc:UFȻȌ\( O *":j+R ԼywRsNhrP[tz!=nsrRs0B?,!yLzjZenFěQerR^^X7A+ 8$7Ĺ Ĕ0 acv o%]Yo| Xc'탶f7K:xxQBR4o2j#pdݧ0cʎX(]CwkAAE*$5,ͮ9$ǀѹJ'y<\uH|uz j9ӻpm1:Q~lo:zCF$+>[28#&_ԍ7qmVk ט|כ(P$^!&.Wm^!z8?M/RuXXlܬ`M)߆,EN6g{yQ$UmX8o\]A/Cvz)=[Kζw{&]clfde"BʭP?Tk/8W¨&dG|mT&rev}EH*raRTh['<) hs쑴Sz#s0s_xX jc!Nyn1ƣ c#r6g= rO t?1?X!85^!i_߮X[^BOlazhdO:WAɶ w㖴sW@<]*DlX<5&?zzu(:N 2&LƊq dj-v~U=? :]ϔؓo.l?A mZ~0%r\8O:e\/!? 5adww<ʘwSx^,bzTϛ/N)LjY3wDH=P = YigA*<3fLuIG,$V:#Fw;?" @`h?Qf ygHfC>GJ-<vDxsJ;Hînۤj~\(TUw~+XgO9Iە^^yvJw,km`WK"q 9rR\[P(GToL%ћ{EnqQptTW'BHٽ!Ouj0ӫĦYK0)W ݍC?;/H"J*_Qls_iT+P,g[| :?& &HHPR_6mvQ2˖1-fzPul͂ D$lB $ؘ)w~!ԡR&pENR?O?T'efaLˈ}@TRSOˍJ?fJű u2Uzcxt. A3-0zsK;Xt>=L-?8C8w&,Fmׯ%_1r#u+m(1&iF=PA`zcW;z:b@7byWz}$R-9ٔj.9|m請é Dje.) ؂Hz(V[4ْFĞł[b/r'PG0A.-2uaTqYqLf;6nmv S /@$͚O:6 B}^?[ XxHcGaec5וQ b%[@7jѩmo{  -ToiBvğ#( xANl7 QpA a N{$9 ̒6@ C"n~}x /'Y{&@ƪ+.X_԰'^+f/ZD|az0k_1o[Meɉ>CR0Ewh'Dd*6ĽHXw}+d?$=T[g{J S؋;bo;%e53JQ!nLVY4!d к#ÏӬ=֙^ܲ[%nd2 Y8ĺ"`})6 k,!9[EGžolW7i)D ) δ!Ȃ"ZLTM|3]|.z~c8V IJv#evX04*>R)mkTcieI ļUPg1Ta8HՍڿCt \t*r2Tf'zr[Z5,]Qrk1%΅cޛCD[ՏiŞ2b60P4'Hk ,`kUfm;lэ@aVpȏ\s?qhe]EmQF0oOg۸0W11Å]GTb&~Vmۼ\`S0$Ix$/iY,V0#&\cPŃw.OsNB=Xìp!?DbN'&,56W|ywIiعU -AąYȩyeoNWh%~{ʏ= zW#21HyabTm@UiliR%T+ݍI',h ¨ pW{9Zw h!.7̨]'^&%jLj3x[uàb%lqrODx/C_( -޿x읤F8% m=HLB ˒0|!&> \?@!f1,p~(SK_ ]y82aO;z{rb % +c2"X\Ey#$>6?D(}T'=ug$#>Z~)LsP{N3n6 ]Gi{lBzvbX2;԰kcK*3-9͸rܯd6wb;Z`&tl=kicF\JF=B7A8ò`G[\:. |418 @sC0Fe`[qlBOMfe.OXkI{;MhE(' {iO.{ ]RWzxpƬJRNP$ĭ)J~)cO{[\ʧוS1r4bJ15<9EҸwKW~K!"Źc 6uH}`hRs8玷OSkl(Q^I{4sS#6ʀwp J %6j2]DFCJ8ap$ߧþxw.\`/5:xhC]nJ>x4@#J^'(3uzj]Q&0dYfdK:ϮU6`Lj*T9UU-ʗ &M > ">:%Զ!{Ur6-91qoh{ |`MkN-.OM7??e)x%NQlghp ju& k4uQ ѵb씯ypE;amp=`Nz) 3we`yuSKx'Iee i91PT<3F1W}xuA::,6y(8ih47P,5U{= =wޤ}Z|))iʤ4?gڋEqBԯi:TBco!V{Z'bkG^V\^˓h7V.3Le_ErϦq!Arl}Gz3C@Daj5bQ|St>D:lJ'v'dc6F$;_ݣZydB1FAQT}2ueڪ2s$tć\*AIҴb"-nh9ό댳 =5h;92bk=Sq id,7: Ma4}[ 9]#g.<}S Gz 8P5Dm)}jIrW>,oҗ&,7)T] ej̫Th  @[[.R<ȕ k&Ż@gK?_Ǘ}}t/iSOCZ%!5RE]p +Y ;E<32J4ޏ :PH)/ur伓\ċ,jjF_}k`:]9I:3=0&,r~*8U /%ٶ8]byA@{&*"BkOY1Lb9|%1-J"36f KhSWUпL;D4Kp|es:| ]"*>tp0@3 f 8y# HMԸ{4lA̫\ |{݀Ȅ)O _a|)Kk @]%WVIF6ZvD~jSzL?=AlږvǭA1jy *|ӨdL8Zev*|rG1sQh”i/=7q<g0\K@ũ/uAF_fe 4&##:J%f R1h*e9T@2PN,2Ty] x'<ȍ([5=e6h֫e7~ү8ƼUBHJ9$$tρ,)]à.+D4hK5D#L q2du_^/[ſ+z *hc13^pΧ  Ql1&S9MH*j9_V/-B$T4\fcêVpݷ&u6gfogrf,v.K0ͫR_P~ǙC9ŽWO KF?cs]\ j ax)5HjȓT)!@#zsLZx{,~YdE6[K"Xc?Ǖ4PL _HMfNt'Cf<WEXN?d])ua^f~`~,7xf| sa-<-d> srg诵ćr@5'yp{4_hCTz;8_7 _y5H˓d>K'̈RnӨ\=Y2ojdrS_`m~#]z.d炤y"~ZDZﺪY e7Ҷphz.Z*~ @ԨZ֯e,#dѻlTK~_4c?C,27zJBcZ 3)(,V[?~5tŋc;+CB 1# t{ y:-ӗNA3D~8j yg%ryF,%vs@Lo2$o.7\8Q4[ä,٘\^vqz>9c>n*QRYGPngܲ4qvs.8!/|>ϵm+Qb0;+NFk|oZzHzоWgV8HmXZ?*Pu06~w= \CVZFHsaP6<#}6},A6M2dx?$G?Ub4J0%C%$vT. ; #*g-!i&PSeɢ7"I;g@[LYJP:a GqrU-^΅ڪqdD{=Q&~?'*)3MD"~.w&jy6԰ ,식N+-hҿ%D*p^4g\e­eɱdlxcgt|icvا-̺0W9MA nq90>f41%1 !NGl)*1,CR_Z(pn]h:e Eqж./* L޿ PBBu82>ak^69;k]#xv=SMQV,h{G̣9cFuW@OyFnahȫ}LF5X+vtYc^}no֠ K兆Au&oYBڮ _21O,DsQ_F!v,SQZRyJч4PkW5KԅH71fp?\kdjȃc0JSOY r'UMMsZe ?X' ui.x1_/zпkһN˙’۔-j-{v/.E>8a_RAU`%/_QAq&`]5fg7LLi۳y #_4'[{GX7 ,:qC'zꔷ(,:c{k̞s^1l!ۦE$G5Ldl\-LhOP `j." EvIg[2϶XP$#j󓦴j{w'4[=x".U^yq?wCAO|V>UT 䟋j]'B;oiSpZ|(Ͼzf3XϾpK}ﬔʇT*bet ݥRbE[Sn s`''j@xVniJ7B`"E2NktE )&+ݣd{`jڻή_r3.E\oc5l-.JOU݇aۥ8²/yb@<88|mh%Kgu[܈M= ǡpntGՋ ͯL)c` yrPoŋVniNjXey%/UOWScŌ9*K{O<D:w>@ح 4jg&(])!- ^\$UipxDs*_PP]CCAO2iq@`C-TǁʇXU,0p]Gnm\`a3-Z:2#j'G 5u=vgL 4!jƳ6sOIt[x~auB= $Gmk#V * .p^ߺif2ـ17O̴s\ohŪHr\7pvsBM