container-selinux-2:2.66-1.el7$>F5N-aBa/ze>?+?+d  $ L ")z( 8 H h  0  8 X     (  X  > ( 8 99 t9:9>(r@(zB(G(H(I(X(Y(Z) [)(\)@])`^)b*d+%e+*f+-l+/t+Hu+hv+w+x++Ccontainer-selinux2.661.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[Lx86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fiif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&>QA큤AAA큤A큤[L["T[L[L[L["T[L[L093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d97d35871d6dcbbeddc0e5d72140fac6e392d5576c1c630518591023309742ba4bce007968a1dcbdf298e23d31891aa8cf7f8c8ac3db92be4206acc5e8f1a699brootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.66-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux       /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)selinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.66-1.el72:2.66-1.el72:2.66-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.66README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.66//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,YT]"k%xĉNμ5#+mz qs'Rt`% _qtxmDǹ|>GvH'{-Jzk$IVȑJ[*iyT3o)کYҭl@:ʘptGhoE(lk6h*䓣iM6RX:Jef>`"WB(cO[ESRe#5{-elސ&b܉Seئda掆,E^WȢj;W"J{qY'}t} {7܊dUD3e5)ep?E̹+Q )t:-" ޷WIV制?:2KCqygh-{4R}G`換saA'%QF(5F5C9_5bۉдU|%!9\_É[}PϥД;gI c`X`DT ꗒd!wCƻCf8&:r|v6Hxkؤ&(p̲0_%~doRQNż2'Gfp'7]6f$u:]6MZwdu:H[^u,R)mZ q^ JGOu hzLu;x\Nʵ@e\-5R&ʑy]|6t|]̊A !|jT<\KLHLV۹W:>ǧo{ذ.20c6㴎s}A^#UYh uڭ __Q׽JZfLG8:~Ԅ>qհm?CL| UJ7+hJ X1dzUH@gd)&USSK6jx<*ZDB;uEE5GM!漢t69炪ӭ_e':,$aҏiZX5@5g_u鼕nd)Z cmа 3^:PɲU!zeTœ/oy !a<!YAzAo *3w3b@(ĵjM8AmIS*~9b~r-LC勉/ ~ݾ ߶)[8žI`*?wX U!̳m75>9hCfo[Qu7)RLX3Qbh=v+h<ʄKx$'[{ꌼN3sdZ o7ni#%ح3}H mߍ& ".Mc&q) ~11JBS=+)~ fP#ByR> {F*fWi񿾱%@p%\΋xq>2T")BE@'du.ZKkӾn2C2H@7Oވwed ;f]e쐼{CqOJm [ vXpx!EKy+˖šu]BϵWuHoy&2^((Rװ4IMPq5e*EĈBi 43^&gLBF"DZy\c$2r{V󈪐5QbQ@WW6jIi6 Ro*i:7Riv$Đ.^H± D``->QHjg@T⁰:f*ɏ>4y5AG @G^X]IsA " QXqb˓XRaQ S5GP0 ftnt hQ"IL#rR,\p^̮%A]k- ӫɤcNUK. |^E|v~]7Z@9fL@ zQ1OҪ qjZf;hW3 Mպ |$İ1b.`U&ɇ>PvM9+8C/G?WV/P-=W '߇7MuճhDdVYV3ise@[34d|dM0p."Ŝ ˡ~gtshhMV~;?la(OD'SOf՚oN1e,!757cV,W'ϸFmñr#F9eēmo4< _[!ĝ.zB|pWg/Ȁ^8؜ |L0.l bJY,rr#ö[Ne̽;OS#{yI.?'$Zlr&= r$ .t-L\ T}T7,x3j[GjobN%[ .jZ+;ұ? =Z[4T[䂏\f藲J 6:Dײ<.xe2:QذQ?Ҡg-tX9\OTM6cj%29bɡ#***c!fh@ra iūVOCۙԂ•yI8nHwsi8;t6[||8 u^~-S/!>>b20\x^.>4<1оŘ$ǂ|"1 4 qUiBȾiFvS=&6)xBV4r I[`1băn٤p*hR6̳);\FbeK M;H~41A[6EGթr!̵`@JRx%Ptm?I ,2R<1@໺BN7"!gkb3ld,߬x.a;HoX=FMU +t%T+u{ :JXX`E}J__X84_KM(EaCntYFkAK`7]jF(?UW$(r6Mg*e^Dgnw>¾!W%Oge%.>9ǵQV)S 3@? Yς-Q?<1rDN&sb,ijڬtt!lNk N3N FV^PsF* F PJ{|{aܾDMG-i{ "R(2OMLm(OMGcƻسa̦|^EM UaQJW֖܁3^VMd$Z8*f!As8\Sl'U[)။Ò{Iw3 uEqkLt$X8Sr SXpRrG jDƐ{=5P:y.׀JՖbS=.GZ8a "|= Yd{\+PlZ+` o<~_ fԙ~b/'w,R`\4\f̅M_jq 3\?,(鴍<e5ft97bM-BVlҷ\'J gOOɢpBðϑ?]IهQ{za}ӸOѷ]u# tkՁzHUmr?ڗ]:a(bFa[K#*^E͵t;2~? !Q8lkvxڟHٓUS𘁸dLMB_Z b"ϥ>3Dz,/yNh]b@8Qݒ!Ie[#M.v}]uHvL{V% R?݌Nc^Z+jVک?8^nO+@w>Jcq5 _!6ԉ+O~YK -P79n:+_qN|`Mщ=H-+ #4qգ^{& $=D R[G+/@u*ݯ?O3&hi?yj3.XPB7l|1dq{$g[}ہ$Q 4&jL'nN*ȏ04t!08Jvt׬4=kJ- m5kԏ"NVB]u)"V6@N"ydPdI}"9̢~.#tK1>&X]r3^|D͙՟"3NKZZ%uS Ǔv#a|k!cm,;;2.D!c M2xvu5H!|q-]⟔Òbvz*¶Wc)Y鸽WcFEWZ;cmqξc^1ODݼ0!YUWFP5F(΋yu@mG˱O5ބZKls\GNI9^dU^{+$twK}RFT}l3xY"0ξe߳eF_`}/}mXd):M\GY1, }5Db9} 1܉8?\ZLbb㦌K>ӸΜx>k(^<;ە{x:ґ$!WOQY Pd/Q$wA.2=BB涓nMKm`P\g6m/Q!,K˭Vl: T3UؘVmZ{7-R8Xϫtp8^!N`oIhsmΠI|X@+h.iܾsFKzr7H)J^ki-@z([䜽U=s6(ʆW KrkA <>*<ĆICǃ8𻆛hIiw=L%ŐVJL g||6AuPqF]pmpvJe?TKU6 Z)WEzً rɌHV^ҐYO hVH؆v7FI XL1]* m%OT@rXM~z؟l/Sr@N3 ێtD>3I:nk hk w@h]/,$ 7Glr'T&0@Faxo"9P%>C6F1UҾuY< ebod$;-r \y [J_SuS̃z'b5<+ q A#Zvlw-DDG#hxԻ9|T "khX$.5v$oxͬh MFԾq'g5ȼ5<_<;PeMR((:cJd.=(=%zBm9ZpnGWk?cgtٴV$)1˄062>^ƀ{CgJU;gE;i-0Y`Y`Иq623cFˠQJFl1s ~ThNRކ2J\/ۘ7vي$]Ԑhq_ЗY狒#WK0e +r#}n9ѵ>,خ5^,.NӦ,# ·0)cAc yMo#EYl*vZZ͹P9;,uuAff7': %]@U2[q)ɓ4vVer"`@22K9_?KKd 'g/sǜvWu ݵZYjᆬ =J9U6N<7V U{hKl:WiMVn9l,cH!A 'G/aj^$ ̡WtQ8nS+/#sUWSmਰOiٟHv͜Yh,֐H{Ú)3o4 l^Q):B_ߢ'{2:)CAș' й2T[b$6%+(q J'{oP?:.e%#|ho˭pf+$acdꆊGc,^B:DcYX} ҳ]lŗ$C:W% zHy-QOXBO#d:);l<.5k&]``Z_ }:3pB*E1BʧZXp <ګR^,aL#`Wkx)({_vu4x>? :ssdoE "6oX=[11z^ XMPq 8H5'ȜrCkxPp(v&*fFS R<ܛ6;Vc_,J&* ~(yG[|-RM-ZԮ;O!gS>Ġ` fϚ@lE(uZ;]~䋈OGiXu[{*Pz*ʫ N-:MQ)..K5-I ӘO:HJ4*cP_ۉ-s9Sm;2+CxXn~c@!Қ9(0^H+U_p_D]&(}x>}(iB2 8CPb0I^v򖪳ZDlߢ~ْ=l! WB0)̡:J1nn($ 2OdIV yVTߦ`(ҟ8i3Ù ɹopĀ5ӎscā%]-C6Y f;)Ϯ+&Zs } b%<\fe5$9~m?^1uA6o*|5JmVS1>I:cH )U7KI3-쇋*:zp7҈%Nd>2Y,j}G >.]ZQы^*ۡlu vͅm)vy3 ?s!R/^+{٥ԉ!9j .} ~N`fXtM^/uF-Sט7óL(1CH\MYk0Jb4=ӛBq]M˲KߚZ2ѱ+ z,4^Z$w긋ֆҴ]8#4`+سqꠤrK⧬ll[G)ȥ dL HSLiS &IQn1$.["[ 鉵<+nQ廬OWcw_0krF9R 62⬕i`&xRz/IoycbpMr/CFԠ3)e0, kɄIZ `ndQjWްΨLq*,(pC׍ʅbPֻP,(Xk乴8Gȵs,n/ݡ`Ԅ n$3#a K !EwZ馰EæãeAx<3IdRY[hh1C0h) U %ף%(B8Q;طYZYuC ^t=UD (kD-ٜeCj/lC2嫦#0蠍U z)_%Myՙo)0g]LN;78pp vc(-.ߓ}d"eվ]JW;Qܶ! DOH3$u9(J켐V`#ÏrOZ>Yza/6TU^zI*F|}᥿D㭉Yw"E?Q}.`{^ ؘ!bpNw}DH-ϓX!p|qK^(|]-*|Zeh([okNJZ;k23f"Q zmmFag+vFX.OqEIvc/D0ל2@eOQ*E*T&IzyU>2CՎ而HBcBq4HtCŞ yhF1mH״)fbs&k>Oglih3uM6'j+pՕ5ze -E2ZB pR#YW5OD9ӱE!>@H'Ȣ$ڌgdt31G*%W0Zw)@ x@P?Z!S 820\NUn{5ʝk)As3ӎ2bn]O|/|.ۻ ^㪵^F+7^ Ŀ]pjƖ0ZaT ptKwlO)QM1) w2J7E<}ygEYH@ w%Yt^K/|J0iɵJ}8_gaɤ5U!$eplfR*u$/ XXn}{21+9LXFht~6߰)g?Vr@-n]3P䁮Z%X3/M4\'q5e׀{S.FjDl'؎&SONgA$0grpP<߈ZNpeEP&o@s딳X*GU|%>A/Qʳ_؃6f-Zi~{⨳tChel2ӷeJeo|U!ڼn)aSƚ >LYJSJ637tzDjxmn>T o3ZH …y'ȣ)@5`Ds,zOghdY4.I@&tU&o^ *77Ͱ.h.f1̚Υi~lV/\TMP4m)+w֑hMP:DsƺɶCX4'32/ N.O-*C +\箻FاLW)^6T˿Of*l$[[3 mCܻ *AџAe~K;nV? P/tcq7 ')Ӭ7mZ4MM ppCi1KUw5;.9"}T.9(QXtBu]x뻤NWA= 'i&){8(>ǜgtx! rU y;ޟxS"n&B7* b`ÿ́i{<:nLFNJqDS{)j]arY9No2H2_{: aͥP"ӫuI~C}×Ri #gjVRn_Ll=I@iiG_ϪI\7 b4nN؄>D鳓؎<''Ugg蛑F.ʚ 6MF+gR{Oe5V1 'ILƯuҏsk91}$xN!QyaB Qt˘F*+R`Q!hˮK $JXwˮJG}f,nϽGZ.@{fk /MC(a `vd"1Q?#W ޱ:'~xz E^~kI~|s1hed{Y-lJ3T=R=zbH.Ӯgfw.-,S:ak@b:y"24Q {o fNXUŇGaT$Gքrrx1}Mց'KTТAR2ДXm/R f7̻'[~#Z_ ձec#]Mb.jrnmܚjcB%~k9Iy"Zp] ÿVEVd[q!g7%ߡ%m,NJt7fay㘄hC[–jOmɝg1(|eWpu,az_񴢧Sƺ'tB&~1; (ՀEbX ɏ|t/6 s?(ipe"lC{[ @XG3Kv\d~ HAԘ+}hѕt!<0XcmN&Ϸ2jlh }D )mT,vU]G ~#y!\,Cr= 3R1͘*:CO$6^6<Ď terXc@^"5>٬xc_fvvKsJ7/T)|:/#T^1[+F#)s[x0gEIUl:gv"r}Pyvٵu YuX2P^[SLO܂P~ݥ\NJ=ci^pCf= MXy3BENGτn:G^:&f=)Lt8p|Zʕɸw+?x;`oQ JIKp#Ilug+hGwF`|&ë/3rcgThaR q5r`_-[!)P5]О\8)|bBt58lYչxPƅVP?3G=}gv_#x|AuݕLz&>Ob757cwe :h3߶g) {T~-"F zSK[-PQUA!/#Pxg"ob!Ŧ3^5W' cM:bgC$ B /|H]"|1%%㬱CH aӐ㝈fDg@P}ɽ"t(wYc}9q){(6HBចs\ƌ;8M& 'uq6kI] $Rb].IlԻj6I Mai4C=o΋=€JO'./{zM̋*OII!ӢXxo7Γ,{LG: s+{+l _K4P}2W.u*pJVBM"G(A s8jxYҳ^:u^Ew+|$DɇIjI.3۫ktt"APn˽[Zp)"bʀ!{Qb(퍭 2UZ(!(g{yG)84Wcʾ9]j?7)=ZӠjiٹ\q?*iN &VyfTCu $ʛeC^[ϝ4?Aʇ9[\F/g% Dj'+a}!"$%$RwƯԥ,2=D+kzغa^ -zF4d7C`+{M6>ub &UDtS=:jNAi l.c$SX pFzmOܬ|an&Of9/.0 H)`<2RTпTJu~ +B`~GFn=PUDCeЀTׂjg}ee<#U蕜b|q ,\5(_|?s[}8'e Z];wr9:|cyx6DS sS1`iL ;VY nQPlWA&x!A  ְ[B6 [Gld@*f|t=No:F.e 4S >9(vs OL8:otKK5Ƚ~ '"% f—_5ֽ|2.kq^Mn5M3rVfg ^}P+C˂ 7H\Vt1Q0!Lv.]E_pi>k SB0HŚE B[MLj$ssv$yx EjQxhLOwq#,Y]-yEK~W7_-זÜ<1 iN spLAM9ޒZl/߫7lVe0m×R][RqT"lg">@߇WF=j-4;!)U^qDw]i_7Ra"ev}r?QҶ`h Fȴ^t4O'M@ΐ:ngkQsxvO<[8ՑJI>a :}Yǃ*!|g`k$ʠJ|V<]ml  FX)i?>1 XI4jCY,: Kд'{D7cLVI]R$qF  f#sOpuCb rB3u5ovqL]l_ACѐp >[-O< |THq¹E Km -\P9pl*>/݊yaXUh[6cGg}tWSC=@¯M_<1n%]x`sKp :2fcRn;֡v+d춀I [I/Hw+]\\fqB ŬxAX9s h%ξ}6R;_#.H:>lU,ښ/]B] Œՠ2}lJz٭RfD]=&ϝgRۀLY=`}5A(L;=4P۬#/O=0)̧'JySrs*0œq[̇UUsZg0pAcհ?7 U*8.d9!hؿk -'mܱYOP&1l]gȸwꖴ˫J!=ley'.w;i!MaŧrղRԼ8ͮYYMFvmkG0Yc/>(2Tt:q{! `js?Z)8z`ƃKt׷f R 1/yobw$f wS3*'Ƴ3dT oFƙ۫@sF|iqBr=q[ Cnҽb^e"1 7{AB̫^jCK\.cua;^t]\Gj]>ee+Z.0b'?~w6E(MҀ-)qPm<u8Ǖ\zIOѧU\}y&͂WKPJC3#ㄪG|Xu >ymؕ:n'L\9Pku`س%ԺM49o#֮gDvpFЌQUm>煁<=;ճ#aI, qLL+A<٬ucIb$=9Plw[G?8 ]2^_ff!k~a{43Fmތ!oYl7 D`uRC-lv^ޓ 0)8}=C])%D*1KOz┬vf>D;*f@y&TWrza$^B0oRYB6%wծ9-]/mf3}@ƶ',]C]^"UI?X(L`'KD|`:xVpҘ?{/ mWOGY@C[41Tq֒ I(z@=Oh9[tWy\ֵh5)A('2m_iʷ6M.צc㬩+oW#^HnBqYln= ASnR;3 1[mEOPm)a2DXbJW列4bɬAK'E_4i E a5P,6}!j@ezܧ RA:dZ%ijPϽw\kwC{1+YO/- ~AJJ$E 4R 'O5o"Se {MڇKJ 8ZLy] ?B6ՍٻhX,x+4_2^||0gg"ּH"<Q EI5H\+gbٰ*zϠCߗP^ϳn!)bZ~ZNxvH^߬.) x 'ag]@b"ti7YH!`A>AoY=:T9JӳZ|EDQ*yIs2z5v 6+xfcϫ$!⭠~duMp;$YP: W}wu\xC<K$ɒ7iF]Z53YN$ѸѪ]ϮOnN6+XxaDd̫ @h$51-dYe!47r;'-+RLU \GwnTzr?@5?k,>'1G>O+9i԰"́~@c=jzndxCbʠVͻ̝f! f} `yR++4[Λ@~=mkL KdeҍLLw,VYL 6[`4s  &'kw0ۜWrϹ9r~l[ͮ0Q,9ޔI`8 N}nھ_qXY/z c?+#$h.G:BUQ'= ,>vxi䓈49L <%;v|$"H<2A DP(l\| <r3Rv u)5PdaGl7R/aʳ#dj{3]Y; Ɍޖz;4U)٦;)qߺVjޕ !B8x - <S 6x]]/ ܿR9.ᛱx)Q;11 mXLg< v99 n?*GͿŽ=̐0$$/.R}$+%o8O! +;!aK@qg0oVrsAn(u:KlmsW&/0l{&(gNo'ÚT =$)J~x4g1O4=`L<:8%S*{הbQ"㳊]8xO+ w^wx掤wj ZxGm`;f Yj1܈z"\T _vY/\4H|-{ţM5˨#ǻϰPlgtʨ.7*~:[N%+vi (L+>iL$EԮRU:Lbu\촚 @^5T/)\zO#pTB>\4t}_h_6lVۉYQ.6VW==f˂H(MĖIq1H{Bm>vKɒ^o2ǃq;jp wFgLۋ;Cb8"aG0GGd!/q=h, <5JHq+Tmp1&ۥ. HVGbMM%t976f 2YaJTpjE,}=v?H-2 L8ǡ6ђ W)0Z "&l)oL=M|)l[-;MpuG֍44긺*'}WGE.@?tK{͛?ij-CscZ{rE.YeF((! =h6r 󔠘!@Ifq6s \0ΒT*n|ۜs888aK`[6jx걙aN\F-.e) sG YZ