container-selinux-2:2.74-1.el7$>cL3Äc0>?1$?1d  $ L ")  4  D  T  t  <  D d     4  h  R ( 8 @9 @:@>-i@-qB-yG-H-I-X-Y-Z.[. \.8].X^.b/d0Ue0Zf0]l0_t0xu0v0w0x01Ccontainer-selinux2.741.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.\(x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?=V.A큤AAA큤A큤\([QG\(\(\([QG\(\(093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d492fea535317f79ff2e2b9e2d9c8b22ada5feb7f1710482f31745f8381dae4fd52b108f469bee7c4f50cbd79c03b4c27b048e50468b42d3aad1a4bdd14ee4646rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.74-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.74-1.el72:2.74-1.el72:2.74-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.74README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.74//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,ZeW]"k%u#qXPNeR@Qn]s;2x/}r#=T"LhR> 2{)Pr=,ΠhbNDϡ9 M"?=ͿV](co.ͺ&C)aL:F~@?\X5oG5Je@Tg0 >6};Bd6ɜQ~)<SE| &wwo DG>? _hgߺQe?Au;d̋Ep2bH0]E*`8?mr 9_;J̑#p|me Ƙ;!hu^ H /eNtH{.?*GZF~[ =Z@j0%zF ~S]s ^=9ϊ!аyu2|adPˮ &w y&ڣw8]ks 0$ʎ"n3e]T|ĩ-E:W(3ݻws@yp-jLnGM܃iZl˽:B$:yu {9Mn7ϣa,S9NwȾ2/ irfvIA%z2mx](ˍ!Wfa-HPbJ<>,Yv-Ð26l5F3v"Z9ܝ.x& jɷ$(aSqJvWbn46l2V2̡S݁bj u' yؗ8$#{F-FVrAtHAvt [[w w\CکDZj+龞ϻ?RQRbQn"y)v.thn;Ź2Rr<]$w刟4CP5Tf^gV)NI\.sj2 I3.{ZJskWlNz4>O, ?~TN1/6ιxdr+=ڱi# M"!1G;X X ?P~?e lHjJ+<&D Ӏ4CěbC~>{`;Q&k~Dؙ>[6fb-@ĜC(.$H-ETfAsF91.5lf\ÊwIBa'u׋j3^_.E%E)v X1ҏ EUpcSxqf۳2lG@WU VA'PՇ.(-78.|W95f^=$d4Jz<N$"B8={&Gc2,+%_`1`q p^ <}u-m oI{V#>,?w>'T\-F_M7GX8E&7 Y$Auf?Ƈk*`{-Ƭ;6@k9qK zĨER 56412{9N&0KMWbqHXE~qL cɜ A`"bMo&hP^l ' ӄa4TlgF}Q6=E5rya<=[=>-OI)ILYrÒ\͘xje+qBxra##0H. X':85?܀L>5=cŌF[. T _ őA&;v˃s&'R-#{ճ]#ş_xOSRڊvO& *% 6̊h甓 XT؟h賎EӼ'h.m^Y9 j@#;%NϏKDba gǯD6BP3BK9abV*="NJi6z(NKI^ƶ+5DЇLέN_NhasLbMWsnQܙĩ;>dV5y{q*_˂gXyUd=>6w'L\z|#)u;lq%> \ҪiQz, 4{od~xKB0Q<5TRofs`O<4XBklmCIdOHk³*R}L!N[g)0ޘe9<:hѧS{k&6^$ehJ`Tmйp>8{ѤCS{MQLCE}ی#녀dx>t#G ؾZE^k2;x6v#ksxK`ӖE+n~ٝ=q۾ԣFW'"M湈ДΎNjoƔEYMMgnI,_TI/%Hk9\F}LtfrE4(fe^awy]aID12Tw(ᴀR.eh sFK6$8$sIpWeNÉE#S 71r.W!Ă9LvyRŠJGꟂ"4xi@n8oޔnN1u0ȪHJ1Ml,ΰvmX~h띴j=Ks%nv|NɵM*qa)ŅyӶ*ڟ"'5I l` z IuVjC`Z7/a8=wmuo]F[xhwײBy2\>ZpelFtvY-F.<ÈU,B'oUhtE#0 u!hI[f5?^ssJ"vOx -_9bA3,K^Ƚk΢z7a\kc4L@(]Qq$J\=Jzy 8r}A.^iK'e'z郧(#.D76d:5 Ho=kP$BVmQ&]l*w6bz[c^y1l2OIǠ=cQ?5Okם]a0pTCf<{9DDBԛj@BU_]S`g]e]CnJ9<<($V%~N:2WB) j{HOH#5ak=ALw6Y7j pQDsyVnvLxJrN2G̷"Ywﲭpk)z?%9ӪD`ܔ(!r yN`h jvtw%m* Vusl5\ve+*oЗxm C4 tdnbzTfLm+9$ɯ:jHϤ21NahVY= ȿڗ ]b f舆)T'/4Dw4 =L/&>Р6!΄Q5 ХN,oAgSxmOzv'1 [dC֯pb|ʂIވF([|\P7g ֺV_%2φPcgCEV"̊$t&$)ѢZ@%AԆ,S ؃ݚՈS7]m9s xo>1uu fi'30ps)0O?( !UWܟRlDt0@%Տ9B-Yѱ\) N_*xC|MR .#_EIXg;Bs2|lCm0$++7aԧ(N3]吽ɩ4C բdʋu]%$t#0,=}9ҁT'*ovhnhNjBTDG:^8RcS޽Ҩ@T)vGHkDA\EmQTDW̜΢ U=m9kLg܂CvX?17cHLQe !CH8nԱ)%gf zYF9gq%vӹb&l!goD3%=3- *{r*k6$4iL}:Z3 ]׍q帳Z5u*uYd, 1R! EV׎AђK0+6rg mG0Rij czSsr}T9 J$$$;"pzBrH Sb #hYs`.}"A2MvmXLk֚U>||+NOG-}Ag~8+=4KmIy6 P[(!^T6pK^Ca-G"JtRHB=$8 ~ HSRHΰq}׿]X(P]i"ms#ww /?떦s7x'by"Qe{)dcX߄KyN,aeq.BqE+4< GQC ҧY¦Lc6<+{M}֙a!-{1t.6 Sv h.e)^/c)&ѲpO<8 nZ `$-̼ ,xrv[wR sw z#MO.gZd7b`_H1z ˋb7'3O2Lvl!0]n画uı\e!5T0Zα,`"CS)k T1ڐ;(k͢r(ϗG<fC ֮,ɐfkETX> J鐇`SQ.OQ`jS곓A`lUeoAS +v҆$^՚JWq `UI !h,Ҹ#ӑR@^kz " QMV,@_&ܢ@C>uס"/.0uPyjw*z7fԕvK\g9(UUV1 3q7ǫt}(K)j&'kxԿV@ئ0>"dkXhO+ { y p7L@OJsoJj vSl T2ۼǹ/YTڮvz8ŐzGyO#$l~@5y+QdoSM7ߠA7q%2w .In*^*9ć[O甈C 81$r`,6TR '!2du1BsL4 k(( Ґ[<Ƚi iP}mI]CJcJr OHnwyx5;<;|"4\u!tbOFA|੬)pƌx:QVm7ey-'ǕVpw0MVWT`v$Ny[9YS9/DkFW)4<OPݩ- rC@Iء̺i׍I?Kl󚾭ouF¬FB.n‹9#~o¬`ڪ M|;ZǔΣnk>T+q[(*dG:L~+ Yʹt*= 0,J{P{^5\pQ'|FQ>R`UN5 {6lJˆvy5ٗ>þ&7TTL1 .riŔ-n Ƒ+ ;$\+^mWIL-|r$Irbw /ԣw`hL IR?Sqt2DgB ,+j}@+c3ҦaMǖ$ -h >k23( *LrZߟ L-N5`ۜ1?ȮdvgSo(kpr\h) Kc[~(PbDї;' :)S%fkLx> oǹUpGvֈa:Nֈo腚Jd/ϰ3x'q 6q-kx2v"HO} A2=?yk5@QMI2Y,|C=:[+?99i$wAq0%(gk>p,/Fĩ<3LOՋ<t$k/,QBFGFȨ6LO2wB]}tF3e4MK$lyiN{8ym ![>HXN;!%xT?/xO O/"V_5[nUd4d`He;N^j=Cc@y4tDg͓$0і)a'Bi u߽!겳 pȴ.iu=UJpC5}ie ^1>'/Ϩ-%߁s/BV >SHid 9sK+)Wg됶h]y/u;0ܹg)I-''`#ʔԢ'FI:J WSO3..8{1KsUKLὥ>^/ߋu[1%MĻϱ\}޲M#扴DGHsqu84&g*Mcpz_&[A 0rv/"di$HymyR/gVޠ7M/ hN)FN/J'->AF5?fM=rT&i>;$:zc9U^Z"ҋd+Zn q`Yoɹf)xӄ A9YɄ4ª+/k[Dp!QO8P3|!Јy tXauqZ >[(Ĵ5-idY3MvWIۤӃQ]*Yx!X W`V!q~[GF4g;Y 1K&:ma="H2̛t#n_O~XCAle֠0'UЕRuV4?")VdOg\]I)Lc{0 7A4גӽ9ѕKβQJXbhQ4/l)Fܑ)*6q9Z}`zH &A7Ne)iPI:Ml!)vĻ)#ZI<`[R%;7aH& \۔UI*QغL&o)#$jT2ݔ!(cQe, yICim, D芢$5qp#htB ̛Љ?ZTJ'{A*ȥ]èyt4=8TT@; 1 (ږ.w;e8I+؋]He6C֠H펒;,yWͿE4H-ױooR^\$LIx8wYKշ'4i-[~0Ȅ+6FNHR~_; ^ž/sMط}yK]ؐ{W9x~ZL%.\^7Nu2>R ӓ"t: N"JF G^ꂣ.f09@oB5\ qk(:ۂ1?pUoͰO?y&~AM2g~/V[% dQ"Pq\hH⍹[jmW ]'NזMI3J6n:s3G~rg/x{z Su6{Xm#4G.(#mI'{:7np$:Q,BS up ި1G}+Uц̏\(ðvPm}v- (k.׫~y@%f."cw>G#%Z~ӊfҬN 1+ۖLZ'(Y)G:/$KMmrv4JSS-ٲ.7j6G "rɺ\iZ'2Z:7։W b~S%u*M 䣛a!k48jN7!ά\7{ ZN@@O˩SoO-+j#}L޳q9pb>ѫ_R/mqP*ی=-(]q i]Pf*Z^֭1ٴ755yd\7iNH!),5= F|-Kv̥ewܛΝbF+(mDi0H7gv6n.7x@|cP VEGק 梈{SV1%qxN ћ /cIpNp> 9mD9 j|OtK9)pN}x UNJ!xm nOa^H%XK<7ϪP`z>u"d1+_2ޣ"=%i0(#Hu v崸oxxFqWJ8p:UkertP@r(iey#d873r9!NedjJ )_l1""FSKXRɂ%FaCvql5(谸4Y{CȟXAfs]| 01=*\s,F yMJw}Z%gEe;4lwEfT2KG"@E>dHsIq?1Ju]g%bym&_:236r|0.i,J jCIgEvi_n7ǴIݛ t) \Ajqe`拚\|4!Ӱ ;' 6p9+rsY_OBlMI]ެVWR؈kY/̮"zMՇD+tnc14SoվB_a[O8!O>P4QKd U*P2" ^f>vRP\(]Chk*߶t(d֩ dGY6RN5{S?10N~NS6<?f+jE57a| ,ȟa<_wI8I!'l|;%|e 3,([u IUb u":xI0hJ8{*3l,tQI_r]",wס9χc$ )Kn?~zKEܥ~g3[-^.B{D^Ԩ> n4V=N5IhTRmlx$5?NN~Ҷ^Yrwmd"EnlhLY_`'? ]Ek&~ kEXm{,sc<ߑז+E;uǎ 6,h+$;8QtmRПKlC_o>$%g{[^*ȅ7?v`jqd/96_*zG964"h.>i _TV-2.{B;kp Sv^nN*i(;e˂AZBSWc q( R6ܓ?yS>lA Zò5R0blj}-+fmzDoph ]TD_ꀲ@ - f^ņbGO#+<,WghOr/o 5`G{ŞJEIe,% =)0($U8%׶"!'#6uWkD[)bgXo<% R6XmTIٌ(陕C eQ&tvW .B0[ X^syAa 4)O> }o1;,k%-uwIOZ]ǕY\7s5s/m> :w4[Q@q=PpwJlܶ@+g4mr.Ll]#X/3ӑȪ]-x>e5'!wv Inlq=Muz BǍ', +2#)F];cfͼ;EV478ZR@YXG|bdN!m7[m4I{ i׆c䯝ԒZ\:I](YH'aHǽ?u6{}Sb5c}0ypLhD ^}t2iH͏x\SǪkNX-ގv18:PVS@C)`} PS)Y5g Jk{ ?1Pр|b]?̗}F*rʮaΎ#v 5v:`iz V*-ꮰTdFQ Klom#7,S;)C}=A aΨkJr ^yL~ 34TUeFl.~MHkAё<4Z&A# xR D R-Q3L$ ,F[FV[xμZx;mjXBbS>N+$,3ػصK;[l ]fJ9(o 8h2M؞w#K$#`gkyFJ/鎇>-C0޺GgEU[We]kލ()cgSpx;Le21RԤ-Pf 'xs2Yt碎//=7|?kصb %\~C_Tt(~ۥiEG-iR⒮2M.;+0I\/PNspE/Xq+aL3H"S.Kރ )#<| IdX(;7TLM(M<ÒWǩ+D™5?IKQR$48h'2cCcX+B{jeC']"؊0D}طU}ZuUq4ױմL{l'V4ӥR./ޖZ#w<Щ Jb,eSrk[XU*h4!>3RyZXVs!_p\4aQ3ݷsnBwn8lFB3iVk?=◠V6 Ea)oh8mm n51fZkzW?f,XۃXlL*GaKp!W8LyxMufK Ȩt 7F"%aџltS '2|Lₕ4\$>5]>d e5#f^J)ZɅ+X(# x p ,،2I/ˏWԏ' 9 (k(9MP a[Vc-#M]<7q$žpY'p=,"Dׂi|6Dw%5F^IJxW&\e;^]^B6,.f e'-X@gR8O47ɐT9p!vBxBH'!E 8H/OqN;F<罹C" 3ډtTK^p3iI׍KKȅUSY3D0y乴;6fXD?@{9m{%7i{9<>Dg*ֻAW|8# کMd +ظE2? ]ˡq%+DeZSF89hz^.-GD +2.OL_n`XT^ywƤhl5oo9!c#ҙ^F` d.|xt ߆aiTyp#2r*[2?pٝ0喇 Ǫߔ7(oFmq?̭^!UI%jQϯ/LVo` @[?$C`$_{!0RW#<\~cp2OE .%LPh^r S01\{|i7kUT;ZZr:sVQsfH&שVfTwa2dXaH _&3Wøe'i$h}e9 L. 7cN9Q6O es^坄5&'k8D`,DÕv1Ĵ4}a(Yȓ91X#o%Kg*0Ӹhx^ 1|Z`3spH'K& '>1~ӁWz1=Uiؗ"˾*2.UxeكЃ,]?ve#.٬ !46r[uJ casE\kSqYo'?KO7ُ pI*p7=1n j:5`#ȬM܅XZ.4~4NgOg?Yˉȣ'sMV/Twvk#k:,"S;Dm:Y46C<9v4ճ.B8x82]6|< C, >2_on>'CIFuag޽H\ D'۔oۢHKɭTf!hX" q x vOC{8-gtA:>T@'6E_kf^3!Bh{[E[/ϐ5ܭk" vlpYdQ4*JW^UA Sj( BgO2.rhIVX0'n, &QЖ0s1Ԥ05m> (;kD5Q KVCYvqL|K%FrJV󃘤|ib`@*aܝ#PblB.xq?jD 0LE*Nm |2 {m:7#, fyȆ xMR5rnwn%iJ[~{V$+@2ՋR'TY2\_8U1 GVEM#3 6s3i/4}sTzίdX:L)/G4P\R ᷠca%zE`?X 89y8C=h |JmӻZ%os LCrv"v%sVdTo^`SsZ1)~h?\F f \3w>w,dϥj= ҈)l 0`{8/@!t&CX6,~𕹡WuRM x*flژZ_']`(n8#aAOi0Vl8j--$mG87x>]Z{1.K)70(qyK5V{rEp]:Lr/~\wa IbCZ.N׀r"C ~WeO7XL |ZHEW:3S96\p-wD ki6-gv5ӉoWJzLz4 rA%Lo^s Έ 79PYzOSO8.q*y&U@ߪ[s.v 2nA5B|FV<ܑ꘲U=HI@#T*zA{%~5AINҮr, 18tW4\i pveg8]z{ŧ"oN[yV b$~-tt[U3PZ;a+V}JLɴX"-kFA/Y@kOdkM~Pre59y_fS-7pA[\1F9 [T:) \O7pqO-Kߙ'Qv%X-73WQ3E%XE*RlYb ?;(52y5ԝ\iɘ-,Av!6 ` =o$d,(z1<alTqg'Kqgz&:;&v ٝg*C `rބevr3dYϖB}g$&XY >ku `.L+"lF)ߴj& 3҉_\D _I9*l?UU(Uḱ `#)H5V<5 6q&GNy7%E2iFKJGiW ~l.`NJ\KpC$=Y+~/~;Ht s&2Lbl "2dtŠWne_)'ɸ-Жk{/tƊQ\{ΝϡGDЯaxfpdg0F1Y6̘K]zHp)+ Խ+d/?K_12Ъ"1?"{bO$7,{dy]l4ܺ]Z] TWAb*6e4uxֹ=<+E~{=kRݎX]{Z74Vmq1"0<ӛOW|-YhP[i]-tFNX1$LC.^,v >``A™_/ 3CPmЄ!8:l +E.ڄ mSUbf݃h@Ƭw$&+ UK]6'[eHr b>TnO n;x9u \S}.:IAgc,[6j\$+ fx(l`ӏ\? 3Dླ- Vddٖȋ8Χz<\xyV^֚ /9i )lҮSɱ YZ