container-selinux-2:2.74-1.el7$>*&H#>?1$?1d  $ L ")  4  D  T  t  <  D d     4  h  R ( 8 @9 @:@>-i@-qB-yG-H-I-X-Y-Z.[. \.8].X^.b/d0Ue0Zf0]l0_t0xu0v0w0x01Ccontainer-selinux2.741.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.\(x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?=V.A큤AAA큤A큤\([QG\(\(\([QG\(\(093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d492fea535317f79ff2e2b9e2d9c8b22ada5feb7f1710482f31745f8381dae4fd52b108f469bee7c4f50cbd79c03b4c27b048e50468b42d3aad1a4bdd14ee4646rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.74-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-216.el73.13.1-216.el73.13.1-216.el75.2-14.11.3[@[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Allow containers to setexec themselves- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.74-1.el72:2.74-1.el72:2.74-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.74README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.74//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablesdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,[W]"k%u#qXPNeR@Qnt;P[be0nH%B``܍z9!NCb:Z7?Ԅ_T&6%Vb']q"!'mBp+6Î<^~e~#?,8Lj\*BؿDïhǔ:v -qC-Oؙ6%t0aI!D5)$a,V+إɘ \ | VUs& HIA¥u;QׄKIJiI`Ric!aBəM8D)Z|qr ¢ wj<2yU =mS,"K/O(qCgȉu4Ot&F {$/ghM[]kM//Ҡ~tf4㽶o#UCQ Qǻo0a ?wUŖ0K~V?S+‡qe4[|9Y"#1H1>1V>Air^ rw&rؖcҥ=tL Sia fn݋k@lsD#a Lx~N\/u\S@pT`٘{P"ic6˛~e(j>!x΄z`P#0~Xc@ Vo\G9<pr.Zq@NSF[;.X6sjqrbb|Vfb*rnv/'2IX'NjYzkK|5qq7!^#E?2tuZcA( 1!;s+oo<!'M-l<Uj3"޿,_`'rO:dB\qz(lpw/$S*tK,H&.Z&DNxS5@XEU6$J!. VAceC 0* Ju_ZWaEw{Ґ0fyV*!2'q%u_ƩU5zq76X1Vks<m%:[8v?1R_NsweL&uMt;tP/|BhBܳ19>:TPx.h*+~k\Hl+y_{Vy钧sNU?Fu$uXaf:]s$=]BfR BŒd gvu..yO(۪dgV]I7fO-L5w<;dLSCtzcEvpm;GMYFR蟶kCgM^ ø|ŕ#YKhHyʎuh̬UaO &7n#U(Y3K<11|}ѝA|]-w FFzc©< }[ Y&}_ D(ɹ?;^.7Ϥ+B_"v_߷Bdnnޑ;y3L CywtoG7%[8}0kV؍_Q9 %T(<>k<1SYfvȑ|X }{F9TTTΐt`{no(ܸty+oC5N J:vc9 "-DŽso1gDwmݾXkKicBymmyɀ 93;pAC!@N;g'G׊}ɽp4o)d{.dVJ#f"NG 1zEK+mSoian[?Wγr]qcZQ ӜVTs6e5sf|eOD_cYW,WV ?{-{(.\V :prF!PjVJ@$^f+ء=褲'E +eJ5pNn\&*ςA ꥺSeΎDs?z7%I7),A^=T"4Ho(xdXƿϽtpF 62?jbR5ݾi:zؠys@-d{~cmN :r)Abv'+vVG9%R̡t9rr[K!<~5))U]둄$S g^>s^7DWe]eO8x"O3YDB7>r %Vv] <V4/8傘:.UR}B^L.Rcb-m'nkO?ƣ}+nh⮞w#C n0slsCdK9η3%2u+on-hG9yTOR5~$bӇ rZ AqHûQ"8[Q-=a˝‏ZGaufVQQzt``cD[r DNiarW G|:5H* 8'q?'$JuhC -=QD),gIf\iGIa.oşf7鱢X ,*AKPr`4* |OxqϖDC䍒w${u7nlmҕ. a4&8-n!enγ'rjlRsm^3+/FͿ/*smߞR 2iR8w:ʪhFeofR?{5/z/UXgHj9.ɽ|GtA$ thE!-m.Ze .KVM!ۂ#6Y'sTsӣz[*lu+‰J.9&K>u 8]=" &~l~Kwš=\Q7=*&80(R/S&t~Ri։{)|DZcqxjkBɷ_|ǢDB<|9뾬c$6j a>IbBXw_Jgg #[rpllssef34V`IjeSj׈mSˁc'-f^e@h0E)\hA-xr `?݆0$ѓw`69CY"@ ǥw'K9xݕK Z/h=9Ɓ?i;LAH /QCrrDT6(SoT&wTH9#C%. ).zr?iʀN*!~V30{ \|H:Z $MZ~e4WJ%\{ٝ%JmͥHl'%~lUZU}N/X0b%| Z]X6[P*D nt+xh_dM{'EغQV[g҄DS@3ћ8| 1JB.$\2h*ҍպcB3?偝^8t͎l@H1 4MoxgLNUv&E纾bu(qVuf =ٓ^ל=dPEFVqGr(TмjXsɻ/NnܔJY4q085.QhwB5pK%a8t㌷?3kOnSp5*_0^<9j_\~l獚aqZ5.V|4>e mهcX˓o f z'&5^љ#,m ^7%Ts/ i gHQ`"M)^=2٥41!$Ygj1.`إ-|pk[TĪ@24Go̤7QEgLs.RDϣfQGi!qU0fّ@pq0%;m zqB|Z\9d(* C'Glָ&p td򖁲řLs]ޑg c8hIƚͿ eL'0ʅOZT;Uo^ۤ$- I҂nVU3*}XlG wBV 祧sjYk}-k,S9yCl_aWE(L4ŽUl *LiR5('1rk+ !}7װl sv]kgI%rBAθÜh(ksS\XjKQHD'lt^FY~Pf) @{ >8vb'5 3w4_U1l‘T[޸v-;Z+N({] ϺY\jyW~I<9rf1_`++~ (Nw|;_!LN;Xeϋpv99ݏLZ- Ö*^ho=Wh@r[F./!\L!P*'Xp .L΁p^iOGF z18`-#~9vi p{vF-dxZX?}ݔ,wS\T3ڎ m z* .#dXʧ  U]&cZƾF,/lYՎ.]5EK~Ʉ4YNs[THlN ;@bT*oT)z@`,+@9]$ϔ>ZFs!&Vɍ=4͍=6쥣 RaO)p:n)~^j+>JsKK޹Ǣ^0'T~ms}g/2 (/ȶNWd"`eKl 9cgG>cVN~ iU8n ֜D@B}-ʜW q'!%W^2ye-M_ݺ;@0IT7&" 4?Y}$J[ݝ;IηSvmo2ᑑ`,30h:4H+"HF0JFe1&;(}NpA;j& Gi|,p;>MD )1Q~b-'@ᒐYPZ Ji~*O 8-d4SNHr'b,$;N4vfv-qs i)Ϭ.4qHg}:U>43qI~'+@OoA#|K<gT9!DE"a^{(ߎf\haxFE;xi>jKm(녪$DB>Qс@`\p60sHa')d+" އ}QOi>c<u 5wU(vnY9ȥ[ze~P3SWZ} 9k5&Pׄ~!.NLoQn+e*<].Fz`2I-g3Ndr ePSzMHǤ>]"FNA+<-pT :sg, ,w̤q).Q#>(χHIR{ИW6<|s>!/Fa:*9͐מBqC=oq$jSX8PomF2JhFeL|@3>31\,^}=zME%jt^ПၝT΃^xg&iA`l~W:=]Zbrנwzd֋^ IuO룼yp-PeoO# ׂU:TDIeAb ׼lPeDQHuj$:܏6 Wѥ벜A]S3ȇ_51Fr׌"&)Z B-#de%.)A|[k6Vz͉R^ %.΢>vJ?W I~ڠC0fu둁Ϝv`yuGju\_l;Bq̭<$,rT=i"]=ۂs&iિ;zZ^B>^('O$S \a)9!`t3G:>r&ȷR.^`"V=氨Rߊ㟳 Ip> fwGbj*.r)=XrfӮFte.( wR0b+XФiޘ_ire+*IyYN|/m,X)҉੮K67o4@FN%Z *1H9<1k̵psK %&,_4ȇrGךY^2O`8ף</3JDS4gcniU;N.|ݍSD.skb.mNѷiQث1N-.&<j:wEM4 쟜~NWP.ofWcIҐB@򖫒xW7o _L P羖c2}.oإO8~9[3P7\oX`S 2*_e3G[ 7]{M[uTQ\Ӽұ\3ӿi6{MsĿfHEwb>;M({c8Zr3,k7AgW8JqCρCP f8o5ci oGuN/fԮ mV 0`oFHik^BONR#mӯWEN12KKqX>a&rY|!'))T'!ɣBAYG33F)v/A@YzY:Qr>Wu\LG,Zd QAׯd;ػWzzA/cH Nϟp-q/ Cu} 2(Y1pmdbymJYދ3|+mRdo:֣S+ZI9YL[M3h`͘RcbOo~|>3 #R8L``?zgU-I'[$uU];'~$#^;|X5+Râpͨgm~KNC|!:`A2@ai]o.dH{FL*bT9o p[?H>~jH ?۷bQdfh&HV2N8ɢiC ֏ihjR9rIY/aci*Ǥ>QNp֏rZ u^b4vs3(vk06Z\()NW8&kKr'',oirHz0^~ vsUǀTQYs+eOtUUSBo6>g#i%sZNM]PgS)W kp2gTƒH˭A1ASiD8`IcJó$σN?9&_gF\ǐؐTnТ[BL0sYb<(Ҙl私" LF=SYL 7l;n6!<JC 56M?P#wÙ+[J zjB1,Ep \LA? 5ڙXo.7iG:$hSk^MI]H ^y;Y+Z:lQFk(mlJIRPʳ|a| W>fv8 M/\ JCL~yZ=#q+8j,&ً)˯U$0b8ҕ_.̮89t옖e+sW;b0vK7&|hVV8s}~eE/"G$,^C^DN2:$\tm GV9@6(W.$y|FYLUvK Y&S3[#Yx{&͙2v։!AX΍bXa~m2VQep#xm<ϛtIk?VeHf͑AM~RM-#`dCW{Cޓ'衼6YfrEٚl{N\eh (gY+%7l(~VzJm{@doD֞iG0W`駳 ?Rl5(YӠS$' fsFe]dTv-e<IVpX&öf9 `S,IHeSdh;s;ض{eoAB&s&x]W-q NX@2إE>DDgJnFdžx[gѱyeJVߴ Pˢp5o7ҠIÜ;R*`R"YE"l>Ůz2dv(?nm`lFNJyr fCcSTf4"K(?lb$1@!i 51 6) c׸j4;X1ӟOP P@:JZC!P |s'7{\UsaaSEm6)_рbCdd/*.ewdO4r\yO.CcoIO"sA=vRA9".fMyV!ISڣwxm;uTݪJH)?өCO z9MĦ7dsӉ蒓d딭3d-Kk($6@/6tĢ9D]!i3̠BJa/!:31],*g<lϑ/` ,⒂m睜KDrxS9\+2jRk+GQGmz""#;WƱLEG}(񿭭F%e+4BxDQU482 @IFQݽFxy˜ScI?Q^s,o{o->sКÛn~|…6O WKLDBT,V)I兀owUN^ 0C3z~V\t7Ig?ocj OA ?=`Sb#\=~kR61*HKCh4Sw|Tr@| X;C%_'۸ڼ+OMJm?޷\?V"֣ftӟgLR\Z{YQٸ9^}fYy%0^-j ,q]6 zЎpd 1}ko7u [g4Wɡd60L>fʇhy,NcK1X$ _-(XٙZIF]%#ZJƱ-C[GF}z*TwADHy/,&4kdRMy.êdfu@Qzsz%@q,%ހz$>S>e,kAK?az܎,Sx<*;m|Fk7'z.#or}4k&6%zJœT%HMՑcF 6e4l_jNf7SKw͚Qg%?3%=yX[EI~p"/{ijjP4d1E;>IiefBF:B2Ac}&"glXᰐcZHr5rP{Y0yTG 5LG 2#0-HV/5M׃mMp_~" ~˂0I_(Ӟop\[z`ZoѻIBK֩첔˷p-G-||1^I]%0PjIԈ9ћ<-o4hK"@)uq vlH#_Ũ+, 8"ȋ!0CG[g!3r/4J!cH5*"si9ZDUJ21%iiB:I&6k=pڛPO44L*gBqetmʣŋ*{&~>]RKЕ r{ۿv?Rם.؞5|,3%5Z]N>+%}6:\扗bTAD* wWIzY,ي`M`ٸ驌=W!~S˚|~iMFM AqЯN[K؇1.A/yn4ak.FHz#r9;ΰ X.Fl7,"[vi0iV "YQ.@ӓmk'0S7z(]]ؚ9^i(ES @=" VkñZL);("ŀ]U/aЮCJ.8qt/e2ln8:&+c%0*޽=C#5w𰌜ꔁ#7%Qb$/4_(z>JȚ>p)8MijjɬM!xuq6TTOGQt 3ȕΦۺ9 |VsT).e&}`vϷ8Ic𶚬dD͂BZ+>4x!pY}7*[69;2Usdfى@‘ Deja_C "g i2ay%O_  ǟ\,nwl~9sln Lf,VZ76+jFɊ@\1_+^`}P d>PۚPtf$M9'NFMm6A$Z_@M g$AvQ!ky.̀DJEᅾ_`hwn(Yz5D)Ǘ \魀'0J]u3N"T#7@hQ# 2MEI ;?B.6$Ao'l ϼ9v:aVi*M&}e;>]-w|nH5Nx>X)d̄j91қ4(rq65B4urLWtݗ-c(m ͰaXV6N<7{w-8tu??E[\BDƫ" K(e\}u|[ٷNjDbV@6+yy׷ce)A"d2 /SXt6vL :,N9PèqyuO-&*RkFapj7#&f"ª)tJNC]ꁡX%2nb˶>2ˏ-ٞ>@V]]l <ȄX$Cs"XяC-ȁ֭2 :S;Pmvˎm_qF|_zqa; Q3Qů"nC–nv\  M3rͰH"﬊1_ݑ@hLѶ_ ^sz9R\.H*?LlGSoӪ!^-u` 6uPkbٵjK6AإuX"1Qfv܋@2Cl1Y3eqyݻO=[iϓ׼AZ^$! P* v.=&f Րz3χ&И;;B# z`Y(`T)<@& y.go}S:! }=]OS$O-Y(6;9``WtVIZ > \hOfHyN"^$(YEß眳zط$smL2@Kp[΃BO'IOqЩJ-1x7Px,S~b>sNۅ{-J.=Ѝ gaP8JO9 I+b =Fh~PdT閾LhH{Yx$undT6D PۘROjq KN9Ϝ<6Otdub>%:MF50JAt6F/9əYdaG=xtm{/<'lMaҡ$mE_5EpI!HIVǙz-ZC(F&;DEeY1dPfL/O]W:έ]FuES r)D[!`b:2R ˈ)&) 2mst'R"{S=WZ{nFwUiϣ,d˄|dwjVn&t==qkcfQY@ňu#k#cL%#@E$ % -,Ʋ\+;'K/9l_ƃ}Z^_ Rk7c#%<ѳ0\8"E Px ˢ4^#]7C,mqS^V^Z0߭gX=0RQ1F`o}QǷA<4>86?I]!zozT+ /6b晍ƈH  5R> T06#y.L;c\_ϵUH3vw-_U< osk?7>c*֛E|akpqHeS~ ̝_uS͙ٝԝP<{N~@^A-&ۍ6}; Ϳ2f>'"D@Pe,zZ) >]slMgP+?aZxlp!b"b!fX|~iyK)IDG/sȍ\$K}#->jy=^Kh}8LW2̟wWu="d 3xjG:2CwAwҪѝ _FHa{j<.*X1@*}-W,NxߤB v*C{%{u8)y/F`\FEn #R^'lk0gl`=e0/>z7l/QHOel/XP^ BRާ<ɗvO}0"&LW @̙U]kI9,T:qr(pRZ2MQ %7q8uͩ};`.I (ݷaϾ@ sH5W4'zؼwOuߓȟe3LfH&e yT 0,Cq6Z%]bDE- ]Y44Vy`uvT4 3ͫVV 1*WdKWj<~0HB>2?Eӯ?vDŽej#Y~: kk 4UR0)b(7l943#bK^f)E@{ Uit3ސO)aFjƃ[t=mc D\SD@a$kjMȨ=VgkC[MtfS٠QѴfBY"*3#4,qq2径.1XSl'l7#@ ,蓺 evqʰ֮#BEkU&Clc52:,Z.9+t(XG :Y]SiCqu$A}{4D+4W{}Tbن%H5V<:Lyg GfL=u?xPulU Ѝ#>"&MpJSፓ\nmF*."Gx6 `FHR ulZP%7C@- GPO<F$nX:-ubOں]H?,;>vuJҊ()8WYg?f؛l:4{cMZ#dh@: Tj0L@iVD"o M /e5ʆ"wƨ3E_50*E'NTk 6ݑ4`-MT~c؈06UOj.\R4VvI..0$lSlnz[+^ gRu)Tݽ^@Hu9a鹻WTg& mg5( ~E&}M KEL3NZ i%tm T @>wP%0EC 'x,.6/$:>eK6TZ\QFu3lﳀKgz\=\t2ה!}$.%k~fYH&JBJfާf:XGw* N81+Q=!<XZJ]$sBܟFtDl c`tלe7mTUpyu`XgdThp/3s|ݤAb*Qwj otOh8f\4k%>NEèNgb?wf[{):7j.랥C(P]\>7%彟^~ʻ"ZoBD(3IҪ#_l+H_T3s@R&t[X'iE8/aE3҇Ggs)PcKY^*/ͻ:C*oGUfNέW=Fߵʙd+u /5^7@Xjq%ʆ$rq1^^[*<~{6=%yrO\0- MSXgбn S 1~qe Fa\Kpp?VIO}Q tӾV۱ xc} @{IaaX]Da4ڑM*xK'%Z*0"Fy=>#oIe^% 'tVivBY ^A4WGqa@H)i <=5?ej)vk夅\ :L-vto7C}mDK?GA6U(/9[\EH[ p+[YEa-aa5Ͼ~Aa O+ƲujR {ppKF 7rª 9zh^cFYѷFݏTs[)=xX6o1}"Ac-ڻ$mͬ&JO2rdT' X@SX88.Q~אZtZ? A!(Wk{Tל Эt 5g>K| 2 -d#}.UD$ F31=Ǵ 3?H>*R t7UL c*,W0LR:A\plO?bEUΔ"NO% h5w<~ŜLjQK Tԏb9qazߠ5^iw aP-|=Dc.f8Ō0 @ v t]0zT[{F@̀^"ᆉq@BZq.eOjC ]T*Fdt@F$WQ;gd!uFZkKe/p,mƾ_PQ@K<&:VDj9 4"7N]8ogԺ# s_06#r6RZ"].3MY0]؆ c}Důs{9tV`KSYT d+ t kR(h ŕB?+0J(=M1g KEnP ;s]rr@\ߤV) <4oT\ <x2LbOГ$MR/W;+<m/HMu'┉{YD6Ew>.5 ['M&`رO̺Տpj0 TN )dyg-C(Tf@U5܆_KCe #_