container-selinux-2:2.74-1.el7>t  DH`p\&$ƨR vmx'BkPyy?Dt!'BLdboFCtbM nqvn^'u=NɿY> - H:v/sAr"λl5fj+k+/ - &݂4ϺGRf2{N^T=pֱ'H. 'csb܋YRjDم.IԂP_U@O~(/Sk9!:[&cXgB"496ߒU@Z(#rRsZ@,_8VcBV[xը/Ejdx\}Gg=J~(qo:Up {A<@yFjz PU5ISm^"<ЁMp)83H΀EzI* l0p%E~4*j }^^L *ܝ1)m7)_@ʝ#:& eZo@c58994659f2afe942971498b70f954524df0086b\&$ƨOu4Óob$ljXXtF(ߧЊEº[}?S AHmҾ4X0űA^Iu ܈+{*O&O o9{Kƹ8|L[(ˆU怽x0Z_τ QubthlP4:}\Hj VEkBjq>.?#\/zjo!:V\I&V|a- _ :?1$?1d  $ L ")  4  D  T  t  <  D d     4  h  R ( 8 @9 @:@>-i@-qB-yG-H-I-X-Y-Z.[. \.8].X^.b/d0Ue0Zf0]l0_t0xu0v0w0x01Ccontainer-selinux2.741.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.\(x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?=V.A큤AAA큤A큤\([QG\(\(\([QG\(\(093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d492fea535317f79ff2e2b9e2d9c8b22ada5feb7f1710482f31745f8381dae4fd52b108f469bee7c4f50cbd79c03b4c27b048e50468b42d3aad1a4bdd14ee4646rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.74-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.74-1.el72:2.74-1.el72:2.74-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.74README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.74//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,[@] b2u jӫ`(|ɬc>kvڞXT8}[JFTDS0QpDtQ5vXRpEu6vfcEEmٷ8D7CHpzz$)юji%e&][nwÃ눅 jLg.t0&8;:R<e;'9_ܜL l*?% QJg!@9׹.Da4[;[7n|IJ138 tRbA7|{*dļ`'s=A Z v}8g-7ݽ4U¬CObCh_ _ Ǵ+:`?MMP _ۜ|N%- -T32,]Kq5V,@ܜ;.=>6\l銍%Abqq'%sŮhmFpbA:rͳPRBs,"F>E-`6p+j'&ތ,z'Po L\NkaSAt_n!QΡ}&p̊t1cC`Eޅ^d /kYD7w(\9(nC8}AJzcj%޴5:&1Zuc|6 T0Oy.(6ĭ`3.QszAՓT 0Yopw(Lcv$pˆԐ[] qO$?"SInY$'9| T_yxE7xY;2C#Q}}_,=nqqӃUԪJn, V$/ Ǜ x;5>@*P8^UR*b 0Ӑ1|X4au G4lc%Nێ(OsnghfBJ!' 3P6Tm{LƱ_ɇZ:A4Ā*Ll,op/LnVҩboUg;sE9P?½TAж zI\JJoq2M}$sDD,$8*狉 (7`yϖ4PdIdRBM毑RBe)l1n?c{?d m5V( ͜qIv~s& XQ  BR!1[M5 _5~GXg|#=l ^xt yjG1g%cs˨Wm렝x_{xܽvc0 R`YLTP22FiۻJ< s(5v @!R_2ZB“R(^T9 }㝥S?zcnP&\YUR7Te2Qg g`귎9dE%nEsga1Ycy7azޔx~}, Hu"[yYi)-EDYeϸ=QW  䝺ks O\폯Nn Y%te|<#]:&2s$5. g"LcN>Rሊ<-XxjX${2_.7\?,A>6@a bNHđ)nxX@Jv  Mh}A7aA^h߫.@: ދ@L s"opuqk;S{f#Cev(i49j$ ;d %O誱I8֫h˹JzI._)f|3>O|" tU^1D!ZfE:;8%]w|7)8`g&$%1I3A_=#5RR nq]1wP¨̞ۉ!4T X#^&.UY1| >G?=US֑ uׅw+8%E (KL6rPDၥv}/"D~=L)ؗ;= o ܄Q&AqmOb#SfGdY3!?$0exc:FNZ]xj-PZJVS'>ؘ|߬K.H#.f-<*lti6o%as.KMݷ$☑R=[73*gđ|E|Pv셍Y'u3"Z}ElTv ^~"WנT*j Kw*S8JX*# {UcUBQ}xcUlEUdS 5d3ߡ g Uh: ~M]TT@e#J]W*,o~i:%5Oi_kAdvqdcSm0jNgΏ@=(0f Lx`>NXGoK4u wMzRp"iđnKํaG" fb;jr.C#olS$C+avsٲؿb&LM9_&Vg/!z:VJ-)Xm$b,CZo&MFs |kY-"]А?PWUW#HTT'vANv0(ata N17W6#~3&֤Q˨ME pA$٤-%yi mN,r;>)TDb\"'ljсJ Cp) 'ݔUi zWȧ&@X1'ޥ7ۤ$S΅X4ۊ :;VWIC3Ń1,G-7ĝD(YpxW"R|%zEnXI^-"~^eS$ڪ3qCڀ.X튅8TW6{lE !|,edQ: u/ԓLQe;UJH]SAE'MTyAڧh>c+^/ĮΤMQ`C~lA?}V2z!&pBa "qUz$)?[[Ö[g 1pDv,iR6=K,TqQ%vz , iG=Jm  DMb)PAD̈F,?j9.zȐ?Ut(n qFX 5 f2z ސXGl CifiBTK0(*Qq50/TK!jR!3 ɶ/v?|~od: 6͵$Ӓ.Cd6D0|hOk\K5&6̘+YmXT`K=Z~F?(4GT `18 #)tEFV?~)} J?ڀ/#κ$7|n\\i &3s|'c~Cy7MPexa񠰁þ"*% q2E2keh6Spye+m/ouxwG͚hN&Pbdه.zp-^2 v"d94K̮227td[YNuv.#,I]݇X"F4ESm'B3-{ex9xdLP9|#=R}̈́NugLkɊE}=)J@^/`,B_٘er\Y=}.ٱA-`*w:5;Om JGYNN*GS5ȯ?pۼ+a(VлV@2oA#.2b>7\fsb,0'fDٷ+cF*aԤק6}zTUa. I3M6Зsgh0tA-8&;" v\Io;]zi;Czd4SE=܎s%]-M64B_qrzUqb˒~ pa!5 L@,g!aQž1/fbMC ϋEO,q+T㔩D)g0ov7BB"e:kD_An~x1*'A(NG%{ s@!k7<,o'V;]qz3gnJ. guwXP|~P~vIBjQ `D m 'Mq^AA",cH1%.>\͚=qKhfɓ(LZ9K1H Tudf;,8wʙ W{~̖[4~8ͺMu:R)p߇gl' 3-M `+ȼh#E~O&W*YzQK0sTn~Nk(1="'G5m|Uܟ9E h{wFC犝Ex[َrHU.%Ͽ~VK-׳^!OwyW{@XbT.S?]SB6];IT49Q+`h-Fz{ ?Udj[bㄛuhG45jgW%]A/Spjb,(Cc?hidi;w|/ͱS0iDE>5273=ʊ-emGÃ4 OčzK?mf"vDM+4 -O"HDC4عx,=>ٓ ]p''!d:u݅K30HKXg>"SI7MEwo9.*${Py ; SqIHHg;4ep6sbC2"~ s2X\]xmhLp۫B9)\!ϧU®p%M D±6AJHfRS";/SBpz'և2S k<b&XvW+  _H<|y9IFy[k7eį6rJh.yOXn;g *_k\$AH&ý*2h/–cawlDV(ë('a& ǍCQخni$; ϛ'+ܡWZS<=d?Oep֐YsU [BSW.ܩo $Z<{Nuz2EkGn7"lKn͙ghT;9ZE^|m?C.>O WMcF a6Ql-~'| BLc4)l7GP#Jq oܤ4rVN>f#0@[1,NMWoe^'`k:Kh|Q`gr3~ysρwaW| [ƪΝ;~Y@ˏ96r+R:r 5uDc4rLۥs44@>C6iU5޸ `<ةn}5n*,:ucZ靀ꀍ7eL(ɑX{J\Pzb+q3YHS$JG-M*>sL8.8Egr >b*%Q2'e#ؿ0rUno^[\`ʞ{9U>xxe) ݽe.2 ` l7$p} љ93[*1V6b%Fe/.xkcRji+kL%DnF@jP>SΨD!,9IkY5kD 畩Ni1tdOQ5' *- !zIh`b;cERh$F)öN$k?>ǩ¤-[m[ї" 7F:o2? ˩i6vL(%ӧoMFt·\rؼiz%zolwed'*wI)9_̦8{kqKAC F} coq˒S HD0KHhoZbP݅蜦YWFr׫{u=7c([rt[crr[Ҳ T"Ȇ.N9SXυO_{+qC@C$;ܛ6Y@DfҖiKT5CzcGOh0'ֆ)rԪ-Xl'W1/߀έ ~\K4Uj%j)dIG  bKH)+| -_/J& \z6uɀ(g>OֽfgPm@(@Ei)w̱=HԦ"-ٻ;66}G﹙Q&ƭ k y#hB/iJ"&0@z#9kWzIڳykk{x8;X0z&'s3,t²jr_B@&zqf2hܑ)T݃$s\^ʛ4[* ,GzbE C'9AzIDӛID+[Ie9J|dRï'‘ "s|2P 2MxkfN:0 (? |WyB'6V,@@i26G9K}X 3 hL,#`l-7&E6#…\BnJ#Ul28`ERg%Mݱ'޲>@ W L4x>2ccV{3#I)6lE ĶaYjfgch\47ACiQ`qi:NBM`ut 𾶐ziFw f 4Ԇ[I8e4g 6^^UwH__w8s˶rƵ*Yl e1'F0QxtUb?a%@w؈A2u0;3x4KqMIƢ&%tygE(6]c0#vLW1ug[tX SFgo/J 0#؎\z$v-{L"w~2‘["cpRO5OAъ ϧM6A4;KsP!naЌ5Z}(Ts!cˎ`RԕZ.aH~-xu #;}\B!m5i \i}2!{ Z}pf ‡=`uoP\ 3;!Lj"X4l.43aodg ʌc <I]mvgeENNVU8 5eEYm.)kiPGX9]ׅ{use A **fJjlݧXKYNcLJ;38gӅ'L>ަv 6AWFW(EF_&-qӥ6T`{\t/7ݧ72{Õ. uWϥs4)W%א4Bw8ٯ&Nʹ Mc Kx4T/.+[b][Tf 8Yy1o̍KS&3*fȆ[:xB񍫪o晙|{: +}{+,z~V[Bڢ߽ԨQpb<*whkHuD t2 x/\&̳T$H``AH\KBC)uFr>`iԾ)~5] @R\'Ꝧ(V'RVy#,T{-TTʐYHA%#$4 .ƭQ{|9ZR q%E pyBOq\ g%{Y(\͠t\pF!&;918ċz{ܽ@Y~V-,S)viV@=qQu>'N|jpA3ZZF󎟏;`O6㳮ޔQ6ue/ʮ۲]sNω) 'bR>'u-xX_ aM<`? W'쿬j,ԠR|peWٴW>!D5IL}1 @bbK$D52| W2Q'Swj*m<6I;5=:CV\~e4P N;bpBhxgh9iɮ;4]'IsQ L\JI1)nxbCcuLbwfȅW[_bWVO [tϷ.q!ht&:n5xx21c+iQ 'vcq 9g#$K..{w}AQ)+zml`96St4Q.s^־smdzUu.ۻ,=V`i6]ѯTٕ:|pj1Q2E簺QhuzVg+tُ;C-3ad%݁{;{M#!#G+ИTejў5zBzR?ߊET(5B5:p{O!H TJdn/]i;%BI!R4#[*JrRu}D{˴X`Q* {3 $+sN+HRH[Rd] 9\̵fLMs? It4YCV1j:e5ҏ% OA-ە @n/}ucELnΛu^~+E4gJkMz`vvʎe09Gt՟'ޚ?_f .s`؀l(WŅsTRg'Z\39CvmG{%60BgKٓjjd$9I]Nt%2K1acY }I ޛ\ 'Hoa9ԎV36d!5&dKjSخӭKH&6-] AKP7}XS}x"drT ,QPtRڎZD|# ؒ$ p8Q{)7 Hv a*?-':kohY4n }{~vִb!M0Y+KOKcfCFQ4?w奅a=H1@+2뭊g_ X^}q$ R<-mMkܻgp2ѸԅK*IF/DZ]j+jpβ؏PKm37@DGTT"xۻBMTgǯ%ߪ]M70iMT9anФ"+I 6I,r?j5õb$' ?5Rnܠ_eWָPY t\o:ZGȴh]Tmu7z{X#EIIj 3Oq DTxrKp,(>'gr]@cfS_Vr`; aS"Woebeb/a *P~cĨ`\H8w3fd$q .WX?k=2- IG&p `hҏCa >7RB&ae YKQE裚R$TEe5&#vcw#L7EKXV%T혉h5#`hL%G r$_EW(Ka4Pʒ^VC꛰]vS*h#(=<@rO><"᏾Zd[vd#[rI!SGF\+O ll] FyL 8CpF_n=$ᭆ&O)jhpJprNZ!cJ;n}MIi5^[H>0$Z 9 c-9QPH=}ݶ>RoX@ӯOy}g0e;ZNuY\I2$ tG?u F_ݴRԮ=:r{OFw;|0aS}6- uɹr<El(ud;4nY2S6^ضeVH~)VJ6r)s: k7tbO9nr7S&h%|siN\S.8(>.XN]'rn_ '>k?,ts- ~Q<,)FxԼ&UDLgbIfM!<3nk@}>|՝  :[n<,p_'eÐd=['Ε(}Z?J6wFۭ-IoUz::Ҟc8Jwd8JaAknO5ER&3L~ߔw{yPQh YNVe~62j7gt^ίA<QݳQ^-!ɨ=s"y sQR[Wo Y/DRES( ^#]sbl(ֶ;br0tIpk1Ip7\n0Wכ_ }B0IQp?>s D Pp~TZ=C,,R͒Zw1~3jp!),$(cOM=L(syHCN#_ hp!05pmc'ãhw9 8>W/Ira`uYp}or3ZfaϰR =s]IsY#Bp5:=?oS~>0yZS0N]n(`J~pRee2DЇ4:/ 7F.~%(b:m͒KJO!Rul`I¶ RO e5jo㚡]2(02|i}⼥>BƘ? PǭG)WHjhwv.cJ [|v Oпĝ-z:=a8= *\3DIt0U`[[+5h> [[+Mj?STVqwJz9z^ H @5GrnJ DRwRm x^4UGp"&9*IipCQkso5?P#qF%̼ XE 7;]}4kzQWܽy 기&kHAdI|ӟ1#lݺ=U< M'>}BNg,E yX_bOR+&F3YH-(!EGO\VNSj@L_iƛg7*Z,"n(,/ewփ9.CqfnX|/L}k߈ ݥ6W/I 1Qer.{vh/`s">;<<,rȱOٍoBQKţQ:tI<:TU~hΐ~ Hghm)T-[ ?객RyPyP4 賷FsNJee@e<jM8{ϡ2S6?Rc~E˝Qb.Z EjQ[ΉBu+)I H`s/0.L_Q.h>IYFl>H׃+G0] v>KBF,DI4waP\c09aĝ2uQ =>F^ӰoC~ OS-8dRɒ;m8}$i+`*Fn`fk@>zq]zQ?!^2yZNs"'sJ?S[PnxD6Sqe+C*}Gxm5R'1gc)J`vml'ƛkkP879}PW~à'8{qK͓]_r)z7(pZMb_i5rןo<UT|ASd) T.!AaFdS\gxN{HW.+kŒ+ D)>sb4iů1E=  EOe4V5uPs Iʰ"l.T=nA[k[3K΋ f)և Wԑl vTQx(Җ}F3lkvY mз1BoE8\(홢DS68'o(6=:a@s5݆}l}j]- ܗ(ڹ;0˜Ũ .vNl-1cscO#yAգ}I&zhC`%;oO47}u.q yvT.)RBi3 ؈3J;OA I\= 㨇j\%lJ<;bb=tԽM9= ޙ8@"~3( []+TFa8%} fuōtOn&8buCeKKipE҆-TЉk@AMayz ajEj,RE% 0)"6eZ)~l$!lNO}ˈpOG3x(5\H[wWk 0?hN.(_h8x$gmҰa&=Qܺ!g;9ۈ}"Df%? |A-~~p+PRZNd(ƙ@vg^LK>pپ!)$&fBƴMxfPwFKU-U8[sᄏY @IqJ/廒`"V[ᄇ^KYCEp ލoQcJQZK#tVF!+Ҍok3V !`#zZ~`\ H#2kd*dppW@غ$aA=b"<r: i9s/beKn*GJ"e ^+D߄7!ge(RXH=GbgM3.)3 ܌CO@&: T`1Czv }q2%O[sF{B:6Î%OXVȅb9se7`,,NϿah5eVpVquǢXt̊a'a+wX,`g0)>N}6 ddVVR FfD#l}EP)P+c5bŖr$C=JzKڲ1QsM Oqp~K!9ζS_!$ ;'T qscu2Q6]@pœzgNub~ 7+gVn~g[\+v/]7 !1̶ߡvf,x(ؑe:Ęч5^UL۹͉ Ö.:Gq}#+,f"T88C=c''?ue&dP=Dd]v۞ÓQ@}$U3Wؗ%5lvp ,(\PuqO.c}+ٰ R=jRO[ $&\%#Qq+zza>1An$+8_|'yP#еX YZ