container-selinux-2:2.68-1.el7$>ЉHL%iځ^r>?-?-xd  $ L ")+          0 X     ( ?8 H;9 4;:;>*@* B*G*8H*XI*xX*Y*Z*[*\*]*^+Sb,"d,e,f,l,t,u,v-w-4x-T-tCcontainer-selinux2.681.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[|#x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_typesif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?R|A큤AAA큤A큤[|#[L[|#[|#[|#[L[|#[|#093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d37e0c13396ddc379999bf51551c20564f0e280300a625f2a691ef2e11a37595ef82d3ea6281deddef1cf257723cd963de762d45831f34a25e2c20c46e41b9f8arootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.68-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.68-1.el72:2.68-1.el72:2.68-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.68README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.68//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,[ T]"k%xĉNμ5#+mz qs'Rt`% _qtxmDǹ|>GUM ru9Vgލ }; ٗ-r;<(# axr?C~E+?Q~,HE'4@R[X!Bv5~XY:(1!='a;hvUo r~޿u`3 G2Hʼ;!*p|NR3/3dH gega7'MB/;4 WOָyf} mKb7s.l͇JR>'iǜg;!o؄2x:$yEl; ae~9NA7Xxrs7rpLg?aJ8jS@ Ius!!`_^ ;a%MÜ0Gya.fcL*XO7d(1v+(BK[s8n'hd-GsX \8?vf̜;Ihbƨl 0%@"Vk ]WSFZ;YA$*k6/M!i|;P Man/1]z4Zں vgid&rG%2ܥ"7GwQ2JemՂin2K‰ [;s{Pu㩠[]8k.JqrR:]JdkX1Ap|x@D FjoEo_R_gʖ8L?cOr+$ћzt؟%鼹5|Ot؍%=I^R\\zPԻ Z-,0Ģ_:ԗ6(ɔ΢}aCeF̵ʡ[Dp;$[0mZ%(/ƀYʘvi)믚}_>#wHx~$SMĄnXUfyՆMsA6L\i <;=~xlZ#77rA2oϡJGoL)2\$*# _zY n!{^$? @ZqW"29epjrЁSj6ʥ)O%TТ]v,[ =eྯ0ɒ+2hYi&&BW6K1ք h%Ѣ 9#*_!Y8[GnGwCyR!xLZ3tVOD9e s(S' _z3"JU*P {U8!‚5,0fhl9y4}75aàOEr}.`Zp>tQCLVgYE.%fGh6ԭV'6z%zzҸ w>yM Msk3b@̮jEƇ2sB>iUcXo.ԓdq1U\\pEb3h32z7 Q}z`>xQH/|kny-}Ijٲc@:zXMY,;3Jᚔ` /sDa2^^lNjm 2N/ ,BHRK4=G|)_c f -R.X`#i!sCL ;N |֨iR7Bj<U7;ψnW ӍhC|YAI.#HvjR|s.H?NFv?)3 J޻եs7#=} *2 @xRKmJSTbCpzbGyy=+^pF;M7(TC¼M}BZfڼCa=qH O%ʑgȱSOAsb59sRU0ۮha(G熏O_zy@vԴs?Emx=Bs4]_84;YS{ʬjĴCm⽍J7{{Ǚ: x[tCԇ xJj1ZU`ka Hrř#T͊CԻ-a7 ZZNC߭MOEϽkR/;t6V-D 6DY9.nkٍnL" n3U7iC}٪%dWE3™s2"&d8č2oOGZ+{35wȂl=~1h~]qXcW\O^6uݎ0>ը09t_>nU3h iZ"B^D-HFu\3Nd]Ti٬24+NO4GF+o. Tĸ [$xy/M׃'t9_n~(݉q8#fwd{@$2># bK. TuN{>Z MT9|}P@(a$me's=5UGm7Dw%VQv²#DͲ#mxxF41Oky/X}"-÷g4wןQ6` [z(^:̀YiQAgA !4Ms,8z qL ^.abb޷T?p̒I)`RE[/sRP=$[:\\߯ {ݓ{R|v\db<89m+oȐ\}a L ݭ4l8 J 1_z,|_gž-8$_EArz tmWvvEIã&eX~^Y+6n:ܔd&)Q5)dV[ܜuO.c<=4L3F=TNMfe,xzH,mwAF~+NB+ד}*ԏPMmUc.iDZ|MJrecqZc2sʬ{+_ZO d^>sb1WWMQ[0ƍHy jʠ >F܁*8N(&dw?~KVxțސ Ɏ7ER&nLxH疪D^Ψ]ӡ~k3qr<$(6 ҫ7/6Tz`Oс{bmtv W.rr`M1 cqG M!Bxpb*/ aL c?=z)`N@T1v: ?ߤt䆯w}>Mtr :1?H6ƲU`w LMS }-j,{EPw0ɮ8lv1$ oQ-OZ9M\E#6nRx4l]GwFΕF:T0RE؈rY- $d)uwSV"!擴 $ f'KLiָ] ]+L0y"8R,5˔sIJ!ǐ‚N[EY `oskϬPwJsPZ_MԿ]Q*,=.RLOϷ=,ݽ_NRo#s< ůDL_u,v]+j<1XؖA,$(PBY#᳅ C/w;޷tFfϟZΣD9 W ;3M`;dFY+icJeѾюMXzB?'U7W_L#ǝΞ`99&84wGMx eW ;dRs|-6#VLN+Ի;)pFlPDS꓎U7 N-O~1pg_ݕ9H55 l;'A辘 T#,]@բ{AP{FY|O4tA{X7>t02J >6)7l`⎃ |Xi.xk!>P@Q7pn]PWxeZ,En0+5^W]h9>3eU uoSdHP\֪M14l§GV:(dQ(C#9cO+׿r9^-שlχG1 Cm_l$?d:Bit AdZF, !0ɋ >e-pOAasThѲhX-B ㄣ[܊,cFLDd1w&$ɚcm|ų6BIG2d(6C$$oڥz+RN%}+TJH-&T5EfmH!#V1 #q17Y-fdP9Ey7'~E.L{`mzo+yGn0Tc l%+г9PB6x`[bPO!R=x[6sfNAi?nA%keXZs ##;  AXt2R'HR ;Cc9-b['6Gӎ>PEM 9dcC֚T.۶-1 LĄZZ_PQNZ!af9$5鑯ESfR3_>ŪGa ^ %Ww~2tXFA`ӸYu (y/3 0+AgrTH;]&/E!@dΞ pZ&"38R` 1Ȑ%볐ײm?P Rrmh1\=[0N5jfi;d_ѐ#̚4,B6.|;:B3~TVds\?nUEyp: <"eEvNc|"EEESUz h]VxQsdg |[L0=`>Q+k*K$.ȇeLrܮq^2wj̩7b('ш1mW \S#4.MU8|nZYPkH!~ fFsX!s&+3P-V2dZrRXSd Hm{&ᵵ鞵WQ=*FE( ml&ni#|:2x]*a]۬8'%e+P^Q!՞'A-.]N$fk^z}Ģ'8>E t@Fq}ڲOS]$M[ܖ75B%aqazWMt-nOXx:ub+HE4庱oy@u(oVcsuf2XUpTeXsgq6o4뿢yhHӲ?9I-XpKH?Y?vE>^5l8Z.<>!*@[^OڷU='}(ehۢY8mL)";=r_F[me PШwH_L k tk7H{Te%==Gﲟ>Ob2*"ߏq}h Y, &҂i8܆ޤsob-.'V{>kide3:Yبnǹ̍BX0/`"}!Mv D8"x F£=qda5Bn˻>=j2(­FP>V ./3mXmPOm۠7|( -IvB8HgMuFNq[:GV| dbuk72<SLAY+;⨭4~"kBYíl [LX.Phxbd|` *T[˳Y+Ď,UD3Z~vǂIbkBm0ثpۙe!YYT-?~:JӊP+7T֮DRqgć1k:)xdQmnBH/>EY.Ff"pmf%/踧#?a_3qU9v|Tc&FԨow['x{֥6b{ٹ2\'4R~rx?7hDuf6,)s 0aMrWoae !42,J4WdP'ؒhuX Mfb` SC <&XmIM|[:>L1ێQIAj HTZ>ePW*shgN>U]L~z~Gٔߔol@ #9K ~qcC;|8C0 kUM],WPTG`6;[I PKijP.tgAH:gv,_[]^kl= W1yDLoU$Nj!UF=;RuUA>ZP0BvwȪZɵ]$V f+8-wʌuÇGk%K' Da6#ۊ*jyXQE@ RtZ!CNrK'r@wкiE=b}1ȗdxOݏ6eK]sy?އl߁^lםJ{:gm@*IYTHRh_6Y $bfo-K3,ʍ46s?v-Ȼ\HuwY  5 6p#TF.z> XvU}!2K?v<V,W+NA=o@1ȫCygi"saZLw^81Wf} ܨ#&>M]aEu)♧p<MER1_lf#P~i݈h9`uAs!4 㙄aAHh(#ȷKvx>4ȒP{vE{oC5A-N;Z[' :pu)PE>CFXQ,):St`h(3XCUBw 4_gTˢF&tPhis} (?1-=r n9, @Qx¤+3 nO圻RѾy^8H]4BI9 ! L b (I1_( 2 \} z4m&z0K{"ЈA"rf-Ȋ5q(*v @zNQi'rd#ܬjG~} ],&);^Z׽v)/E$P*ݾ4[t0 ?2ճNAm|EFt:v70<%0񏍉/ࠛVD\3\Xc^4Q%kPnLY`@SWj?lŃGZ+Lug]+N݅< /,@4nhC{skiƆ%3;JY³{)|OVuG(GJD~YQظyr". )URatuU .YYo~LrxxQ .}#~:Qk%'E9$SX;,6'ןOmījr fbJnҁ  ϒz]~T0XFڦ5cqꐋSi$ F(P/P>iBpÈK +\aKVb^mdUz$#cg+2`މJuO@M{kW^O6Э46<`߻㠉6,=gG7!:Ԗ[յv9& 9p'py9:(:A2s^4d6k%)1&Pu:ZҰ챤J&m1, +JHҼ=`B{4o̥71H{^iL_C];`+N@;nk@WD/h'p])LGB:w )f8mϹ oBrXة(a/7lUx}}hNPBG SUrǕ$[G#o4 ^}BPb Q82AOɑe0A"m EP&4F`;ГP^.B zp2hEqf?UC)bIIN+mvi H3BvȮI7` V*^V􄏍I/g L)$ܺɢ>nCh8N_4 &Fۅ˴w<_gM|e~#nj;W +xL:aZZ_%ldhm6Pe<ՠ VYmޝV/1ěJ~ aC(Aۄäa҂f]zUŗ5Q< lD:[i'd=!~qjS=αZA&S gW9ׅBdEfQށaA@qgU1&O%o6;<)[~|䣥ǜVjr2䅜_:NJCa%G@ie~&Ӧ"Pь.aǥq|TnGJnۿqf`:к;Uidʮġ}18! p!zʌF.stDھdLxW&56@8,< f/Vl,Y0,wO&#[zz+%dV NAxk`+32_SobA J& L?8PwR *7h ▿4#,N%npϙk!ΣsB}ncm[]lShMM)%_CZF =[!&S)/^ BPuy~(ՇocjG=l2+ifyS╪7d6굘*6a -zPnk, `VM\ͨ¶'6#5׿ 3 FaKvm`WAK57Iإd:<>+(Q.v`[f6J<~XBv HFU4/s87*t.- }{ۿzpFG+\_^*QX'vTm2-5q"- e^շ ?5!kWo`0$'އtb!bT72UEDSQgǜXarO4S:v}) 7 tkǙ%WUxWGdyM"d~߳rhk;.(K!TLP&0b ~Ϗ~:>:ئ5w N# XB>jB7$G:D2ok0'KjG3 Tq"mX̔Ȼ yPuN_2qx9.x{}\wMB9yu tQS,Hg͌-ۼ`eTmّ "P^ey{ailKBqTfB4 $M zyDX  +~I ^sZ{gT)D[&`{Nl8<$"Y (ڹ|rPtyZRJ~8AMTq*a\^//1kEBL',tXbwk6[ GB(t8L#܅Dr, _ńŦo Pr4-?`jxhl`'0C)]NKIaM҃ԾiH:5K?wyf>:5PЭ}Qp򞜴0&t''!*R{VCAM_BzZKݘ( YǨˊq)gsNgQ= O M\ȗh؜`ۿ95P[*a&XY<͠M"ЕU:pɐey?{szYޏYxܐ8؆%EwnS55Gt*n++܏ʨ ( O\iN /^Z5Z{TH2S[ݗE'wyKj·US)4#1X7xr3 )nɡ[إgU _w?J8*VJtDtN`WN<۪x/oD_iAzɄܧDHJ+BMHukC`95T_C)UjҼȠrweU/OV [{OD^͍@_Nqi%u8?Z}ƤkjP'i:.@cE?N te$.`q=ھc|?Mi1NUЉM߶5Gz |Qw:ŸUhZ.<ö\1w+G SY9wǧ f[͚Gy);8TD@&`+5p}0kXW,6[[wQ࠙ogWצ-rBbtSŲ2m$ƞ1c*w7'"6ՙQV2ICWD%,lvva/g)C t su:XdYܓQ D][׺*InC4W mlDӯ ȗQar6H8 g駛w%&1=N4B/n3K_HTh^7,K.1OէA*=}Z1zE"]]z m戉ƴ0qH>ҩI m3u ,~>sX$nGeIxt2ɱic0@uHZ 7D‰ [P?BWJ91c1z2/NwR/~h_ۏ2ֿQ5Gk.™3T3N<|j nI 0QoGe<J?c'=†XHK;((9Ё +H|A^*GRAjMD>>:CpUoTEݤlmuUr}78JG@:;-Y~j.q yh0|-Y~<_ a>8cb9o/2gY'o+Ov[L|EK|Hq;PPAOP"F-Пo wl%"+!ȗʓY 6kΟ1V㳄v͐.-)ЄmOF1kk40j<1Ƀ>Z+ ݈.oˮy\h"VsیX."!<_P+,)FnhBCq'@83bP. Ypd!]|zt#=_HOSKoc4,,W`|w #+4˛-i!X%9 O\73LK()l*ڝBey컩bqʙ0> mgDH!vV_8n "~qcC=fbd͖~ nWOŀIHQx #.D Ъ S)D@4>~&R܏+K%,s JY|zsMIm~KJ]^T.EkV@H_kCFm Zz@ #ܮmvwߕOU(Af݌x`"dOQ1U*zըw>bN..Cmm'#4ʃ|j\v|FϮ{^(e{9A;܅Y@L(>+m|9CJjE+JNS;~LQvEH 4Hmv}"j$&~ XXAjذ9/dXma_(U]-x)vù "AۧY>w A#mk+.jW7\oi2J ~ p m= vV)QZ 6݅C(v0!b]kh&I#k|nU6U7fҋ҄obDg;%c`/<ةRY0&*T4NWDI@l9c)lj]!1 R1C-LBD[dv#M$G(hC$)Ͳf"bzm.!Uvy scybꛥƏ_1(s#[P8FtZHyX#b G7)f$u6Fl@ 8]8A,y~Gq>)Rn=mŖg/t vD8Q~GϮ\#rc00MutCHԏEu]iq GnEB"i}w0sP,jsExx= TFW0ibI!ppֲ:0H M ~|ht4 1)qQݳ(E&*DFH`ڶ븉Fx:yguC_;[1uI(6M2([~ 4MvU36\Xw_Td gR^,m޾V4K~oAܫ^UUH۟ɬF ÐUs h_XDϝKlF=ayiB:iv,-+}ةȄ+ ZdΫI:pW_lh"CubWETwl@64 #XI'Q%2HW!(HrF1d95c( p~~Ui 5aƓ~F}"B- `@IPY}ʑ>#;#զ O-+Hj+G8C= )8h1b8(U+M.صTF>ÏAa7dBpQ3vuUPdqaEZsإߌ:wL e:?fi#?Nbl"rq.:32hh5 q6)ckR'ߵ`#Gj(d}%Xx 8Jg4eF }"r{`M~Dg~Ǭ!Pdft (=EbMۨ(movC9ev Vumfn8p ޱ44W\k.͠'ь9ܒ6!RnpY]Iva)/盅IGm+PWz𲙟9v£xd,'AV#KGdoh+0JNeh7ԮnD}C}g6m$b+YHpiiK7{YFT 8Q}¸>$SkB  ϳVFK "i{@9cӷBW$oyfE?urm5oeoђgbPJiXu|cq8?nsf^[ 뵷UCaƼn+YRHnx'Mc $9&uW:1өj{g@9ʚ]evL~㈧^0exB+JakH%]-XsQ ޕUFyt BmkJRh=(cԸT,)ڲs5|KbL`G<j_?ɓc-G+Knf۶$R̽UW2apϋӧzzWs QY\P<д~/![2]Lv^O&Lge 2RXBkS(yMocSs'= giowG =]tyj̙lz=&:K]kIO i3[F;72^e3;~pϵevA6cj@ W'y2iγj goUOuRمXؓVhWFQP I2p.Oa2|I֗؅_`tbUhfA*GT O^dl Ar~8۔˭ʙDoX:7AS)g]C6B;_P6a`Dzmʅ( s1KWo*[VR5G <b$n`It'yQ@  =}E;݄Ŭaе~Sn`{uM QU;(,YOM hArE'ޥ_.osI47R1yoj.F IRq)ۧOE+&r׉>9$ ҈6Kla]D$'[*6Ӿ3[ L{u$Lh 9\!$>ܳՕ]RpI3;SrvrWejX'yB(I}ߠ .Ak)\]%4ʢPTj!^Nrt@ !#yb~:k1ڶ p!]I иdHYG2;fG&/%#jB =E;3w?fT-mal,YS5)Zqx3hy1Z6žDA 6xI 5)4l[ws`+zU@֥[ =\bk䛐F2s{O|i[e>i4lO,>LSOt|~F$Ȑ=h=C&fW֧74c L8tp(1ֽ f"}aw&Q$x=tV)$P "I ;C6h;򄅝T%FkL(\Dq/vW_#d Ljo i 6I~yBk.+t®**u1oy޲5\Jvh^[GKAqHO$" "xMp {"}WeLj^1BXC٫!H1֑,