container-selinux-2:2.68-1.el7$>bd1+s$RT:x>?-?-xd  $ L ")+          0 X     ( ?8 H;9 4;:;>*@* B*G*8H*XI*xX*Y*Z*[*\*]*^+Sb,"d,e,f,l,t,u,v-w-4x-T-tCcontainer-selinux2.681.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[|#x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_typesif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?R|A큤AAA큤A큤[|#[L[|#[|#[|#[L[|#[|#093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d37e0c13396ddc379999bf51551c20564f0e280300a625f2a691ef2e11a37595ef82d3ea6281deddef1cf257723cd963de762d45831f34a25e2c20c46e41b9f8arootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.68-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.68-1.el72:2.68-1.el72:2.68-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.68README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.68//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,Z~U;]"k%xĉNμ5#+mz qtQs Os9gGAٷjp2tBjzTC ka'9`='ՎLx0%C.vwQMՠd[A%>iZgqe(뉧cw&߽p>v„vцv[٬C6.b(ӊ PI 8% dzHMpZYFV4d;T(B81bM~6%"qUZ|>$4T^j W pKtɯ 0&>VoAخ1 %2 !Q Au"q;F?AN Ǹ&$]hdr[Qr%9B2u XKqJ UI`Qڢ빅 IֱP3x/Г'2a*ubލ#ee?mq빙}rom1p/ )iYfx+^dzo'GI GVĄ藣$H0@p>[l%9;jܕEM 4DObr[b}3EJ;YCۡ e= ?Sڥ8j5ssucHO2Zc,,7Y6Zܡ1t"kgC2@%Ϥ4`HmчMf]d>S?, T'@r;1'OK}d zn㝹=Ȉ[rK⼱n @Op0c,eyFDm_)Qkx|* sv="f{]>Ox<{8XzF >v>H-luyZ-Lf;T6*)Cld\eT2܌s8C;h#;l'>E!00c0?B*c|G6hzv;o^ %)_7Bb9g Toc%]B fZ$v`YpYhbo> IB}PÖyM>r8Nq}mI1dt ~ 柴|f񉄎gs +3'Pom1!HhXqT3&&{ܪs4`Vt'6@F,m1ըoi'Z.;}tqL^;CC]1!]q8O xW@' ٲ)[SDE,- N_q9QwC?Ļx Q{`cqtrIC%t֥no*2u.唗;V#$4ٖGHWin L˷CP{CO![u?xI'ǣel{8jIg̦G^dĀ^kjnФhʚ7ntz_8Fԟvɋ$cM@ VE<_Kd^A'r.h6#K p߭T0P16tS(5\Hz>#2S;%׳ pUVgj-mv;d!TL!QXTװ*bЂk;AEBIjv1Cܱ Ğ j/opp}S$i z"rGE;7 i$M# *l{c?('(6jUiC#|7s`az#gMH6NĦipa{鄵;3 aL8+Sq*-eh&7"K(gOZѼia0 SxW5KfaTAQ#%VyNUSxN<;C\Xٗ1?TȐEidЏ4\ꗧI4}5tt C1VSnrnkʼ:꣐\> wl>D[UbB>FlM KuaÎL6稃8BՑ* M'U{ >3>dno lA^.^U& ^'o=֚j^ZVsxy@UInr2+1rLi LƟI'=U X㽦]J?CŤV`Bc~g mم]Tl15`Bx]nhHnwF.KZC+ }NYk:p_'5[]&>P 0^k*ni4^jR~"o6} PIP]%!X$Ap| 5צy3A1۪hDCΣAlCGX7`_Y2~BC">z)G&Q 0 z WN$Hna5Of!3|®!jO)^ F;T3xN0{7HO *LAgKfu>5c>Jȥ>iX5`= 43u#҂R4sTls xyg€3 Uw%FnLS;GXblxa͘\¨̆=k:׀#>]wE Swx&*jrx] e3Q;9&m8PxuTqӚh՛)c]>a3yO g)r&G7v6SCZ}d3"f^܏id:s9[~/ J.g35w8ϵ hH!?Sa wl& J8 '7c}4]}9($70JG1yYM!!]\`sBWсG(vB S*\zOEby`e[o8qR㷿^Mvcr9K%bF#sV5g: pI.!|C"3:oqORZBCdt%Q ޕthuWw<aeէ kɐ6_K]ZFT޷J{q4jxi}@-2@CAjR <6F < ͈78MWf~nv4fDseyW5,)f>&n+VpVb( !aznwU=[5q+Nl&("(>2Dڢ ,}RZxUװ#`ODRR'An&TFdݥ6&L aW)'}Xψaˡ̳ncClad. /3N\!oE(rZ͏>%JAބMWs|ZZ*q_Ҭn֚c_+B>.|5(?-'Cٜq ̤`f`:]S8 k<1M3!FgXOv-k={naM-2p 2*;h)9+)Ԏy3ym6s{noR>קGPWyK`;h8  -KvLB,@a.# ~0@,[,]z>W~Jd0%Xy.lnsFUIm3")?_%y'&g.vFSAŽ,N07^z'WY1-$gpЕR#{In -NTymǙd FЁRW\5 4gczöe3.j*'$Oo@ar ܚIo!;/ȻOЂ6';GG>B}k;[s3*= ϠW4%Nd=:P^3 ֓ug:xt,&NxHxBH'mx;=G})p.aL:庋AY -x>/Ph"[ϞѣH19kPS^La y<?V'1Y.2} f8Ly(% X)Ib%¨U:{Eܶ`-g~:=vۥK%^EM XsCipeA?H<]%BuAF&X&Z@S K).nf Ne 7KgԯX$1 P<%'c>jT윙8PRM_aDz#n1P&˜yǙBgw .qm?fK2ހQBy{E\t! y9Qo]/t9h.@vN%lUG=8tj &̪DcY X2j8@;ΧWwk4 7i#ڣ0|%36y@ewOcc!LS7ر2=\;"EؖrTH :;!Au ;hqlvT“T+ހVp˜7⎉rܓ@QsDC>\=9ﱴஜJ!f@9th{cvW\$3=Ɨ8qF] P:rlq^D\"ƀ Z96lɚ9Ә`ԏ-tw0kݬGwڀo=|蔧=o M #tôR!!OXM: Af17i^H |7 m׿Y]u <ǥw]!#dhgPച9/uX.q8vwֵb3< sUҥe-c 5aְP1ݐKc+6Fplx_aK+Fιjڜrn@sgzW r?a| 8eZ nS^Q0$6-X(3fZ0GH@sGSţAqf7C '̏3 #r D |g3a9^#BCB:MGVT*tR6BEfB"80gCC~og[ _l Wn5k͎(o<{u3\*hA_X%ҕG$ڢ[[|EFQ߽Z[7VibTh۪L `6#ÀY'⁜ݗ[z0<,Ͳ6dE xu3yN!}1D-8ƦZLv_WbF[.$bhgYģHg% EˤrN!}ta7TM/RW~*L8ݹ8]`ñq3m0Ո\IdsY.n_qCW}[ kN)|fjY*䙺ғL 5l'ޔ<8$ S2 Zq1,-TW_j]c0T=$Y- dp7t`j/#DR0 c,uo-7)鈹jWLs'tʩ㩃:+ރǐrtqKTmV)J絼~1mNDq}%L AŃ'] tF hAs$@7݅|\K5E#(TJż@uxTB+)lj|jwXP)QLUL a9$ &`#uߊc)xGˮѢ qD`([`]V 1"[!դPfn Vab!pH&AFۓIaE4w;`_O:PʽF\t޶ZG{˔WO s|p@ s g@%w׬,4Yz;j]^jKs$l&87;YQKcXTcYW (tVlq^Ф-O/ \HL;TCi}UZ!|a7&EFU_'0;8* w- ?MDxFэT\~P ~jau^7 C@Sq/HEl/ 0.eYz䓋h Z!0NjGZIDٔ,eNrLZjp):MNaC;@a1!lĤnSQl߄kdXa$e.`𒲯 ׳^4Y8]R'[X8!r||- %1p7\;tfW<[ h< Ap1s<5}R9-YH/bMj[H&թLW̴N[CTXZ73ckfIzǙs8mq= Ĕ/YN&*u66fE>~wЎ{ؐY-/) J:n} Gl :bҍ6s_OCf#+ه,95"] T lMCQhW%P'Y^ez@{y)'b7td!1<"2=>m)e->RޠMQV8U&vA~AsUD1Ă$vu/u~c6هB|},)z8呣ضh5(Yp-/Gҙ'WH;zާr"^mк.T'r2D 2ϾRPU6|^M|Kvbr)"S] _}гWx {1E`iisaDĄ+y$f=}L$c3;:GyI^3+y*qѢJIvu6N`B=pYX۫ 8;ˌp{mtlW_c~{<š9&Π'eS4jԾEh]-V b ɦD͒T#'B|rh-kbbnto[;U ̎Ci0YrLE.:&\47Yjw`P[ 77Sz>S7cM9)O w1Bv',fANFIP}͔oSf1!L}O-|Kh[m{œ ~kIJ8# XUh >6Pl[83 g6bVH%'lJEw {G=,;&D-3ˋRG%8{X5UQRpUU1Ni`)à1a@}kjz'fTt[ w؞Ĵ``e=\56;k`HQǣk"d%!EO2+¶56k j/Mw& T#D}>; ?A%*u锹Ds~Zpxd*<,]Vq+;% eOQ>O ~]z(ߨIA%)|Le ѯ9pѴA|=.\Htz1gi՘ (&vޔT][七UVyXɖu'|3l7+pe,bofj%^q/Geq5@ 7Dhl"rotڿRcʢA ۽&:f@M[5in %a3E(R-S{eD S|6`vrlhV"B+=[]2*'G$|Up 5Nn@mLfEGG-Svm"(\Y ps(%OBLE(c#.*S\nI'^s',l$/'9jBad2&PXt\;ta ֧$ ЧYʥdr9+zg=sC'ѲOߏI9yK+HLGB>'=M$E? Q#2q} 7pޯ-617K['I.78 Hl ƮKJӼ=L?n^~^G9M΢6VAD@㓄M 8/E>5_pLu&w s[|&(G /M]"<g@ζslkElMj><)^oU䝒A˸TMOU _e?tås}SWpNeN$EX.ǶT94zonk`a@W_ rs:ؚ\L`bWv*JW7K#$WZ#_٫FOQ̍l)۪sq^2Xˆ,OgEpVֳ.l;m@iđFYmv=O]9#nY5%p 4p+ O ~> n>fLPB7w3( 21.e=9dY-9Y½lE4bbR >| {8!iй J"ٳZDFW[]r9_/]VeCZhxO jCjĚ/k§ީ\A/x{@NE~ 9FYbT0J `>j}ѭ|罐wJ"g ~`9ho @I$/KsWxnRGr~7MOD(Ec*~`e: 4/H '.$N/)ۡ \.1>9х~33EniTOd'%t +">e/Ա]樍,upq"HVHq0,XtF뫎̡b<}M㑦W8m4B*֍+B>)׶U|o4-nS DzI8ڧBE@=S\̺_QA{*Y"&0u#Kw7C[\憡\L3،yHC9 | SP$%uґQ6YLm G<-Myq%l2w9+bpd!>gFue3EOBWʚ<%<|vA&R0G/r=\8Q1@ :Ü$e")e|QʔTa(?xhZ_gx9&m|k$LN;^#F̥Dj,=@-yo.E/@gW+[#’Ԭ^-pɁYliqŝDrF:P<>`"n%M?VĈ s rn4/R m^=<:("L[ 6. fq1YR.~ݬt7 ߭SKAYw Ge(]5ewE:"[Sp^D1jѕGPO5ꕘS<׳hG-iL,O0l1p0Po2*tHsܯ$#\O ]L=Cc4Q~i"7ԍCu.UC+f/78G_9PgH|Q!˝&ir)[;@D;Ъ'*j)&{ ^M2Yy?RJPW5f 1zQfBF>[w{@y"^m<8Ѳ敇-i·~mv:_Zeq?.KBhKHӳDaj#g /)\㭊^ i~XMX%D>\2R E50(QX-6`PC-68a2>$">dj4~Ƿ&&}} 1S, LZ稰3 W 4f2!"|;F+U@/5K_8n"`aaٯLqp,`asMHxܳΰa;%s)|_:= y%PR12`[#9a4sx{f\UD8}AT;Ka!(+ءC4=y8Y^"VѾ|#TI}tFz;UwZ%l1,I.퀁DTLDO@"|I0oO"mgqf11?aqՑͰ505ë}K|C4Rl- ZR=9^tO%mBoSOqC[x}aҍ?,Z#' fqnJo$O&3~i'K5H-^+F~nCӻZ "0]sl=diPf|PmcTl0%?4T n|4ddNx,ӝV R'e(T;3WD#7) KfC),&a;!RBQe`ڙ ;с+g±$ÄuJR@|`m; t>OX"h0J:LOٙLZ?c?m3˂t7$/eRTg2Z3 YJ+aUS5:#SU&+X?5":2ꔺYOVT5䐩'KФ.p_F1ųLSǭpTuF)l~oмG #zaF>Arr Ԉok9(X&]P>LXA pކ"AR[l庴DZeFs=-P۸8"c^ߞpOMgՄ6k9TCb#/ulٛnd!LEЧ$|ܽEXtEB!}5OHYܖ)qCeчvC Y.&|^8wM|)%@ס?5^[y0brE0YX7b5zSK +,R O~g&9 Pd ^g'?Z_pJ8fLFo޾/]gDbO$(Y,y—;jᩱ֬JC{$iK?/ .-HEߒiB"Fv'( ɝ}T_WIs(j8V LkoMݎ:)kYl:VZ7Q޿ sοPZ&P3Iؾs4I!TiR&B6EK4rmOuU>4G;ct^ Z`Isѣ6/- 8`Tף"5t_񲒽=]^T [~q]JC[Cʳ3XC#a$^?M[ e|r.LYgǗMdu /UPt2D?Ą^qhK]Mo91 -lH#<PPiG۔Ua[|q-1 ,/JH{ܯ.zh"G傗R0vrQ;QLU~:.r:]X}X_ sG LG;,9'tp3E*'x)W4b'$][O<<EJ^)[N(j5H>{;_<4$S;}eQ/MAA8z{{xbJlHI}iq0$P1KɱJ P[~Cz0txKjQ2u;L/GdN=9oE ѻC}}%56<9"m/&;`5ˮ\iacdP"h(9@&lAA&0j-\ s)3zk7`?6ac}QCZSđtϰ@M0-D['")ٻLb:Ñ6v``URbߤٹuC:Ȥ*)|@{\*Q,LJݸ,W \MNQZ rBtg{18~ΏO5H!8U9`nvdc LA`[4p'=.9c{V)VZuafP*ݜ!⬅/^0Qh`{vqoRq&e: (Rwa$ TRwY~ĹNGFG=1|fJ)ZG_~-Zr1d]đ 7}hB/ϻpHlWLޗ?(CK5c,yE2K+xeOP'HVOq0dU|VM}..<;O) B@Kܘ*u 1hGqhӂZ[~>p-}.p}j\&jW\Q#Xv+)|]aKo׋S5eUO6PvxJCnq'O(8Ur sS/^@ ;c8ןUt ȝ&27-9P+ZxoC+t(앬1VGCȡ֭_MUxAn:G̖ģ*"Ps>å*i_]8+s߄Q7ב9hm!=5Rcz1OxbɾЙ?=v"_Ca덚$QrYvEBYv^Ȳt 77l5@ l/[ƾa ،r4>XϦլc(s%J7m|K]0\ .&;K+5xf%)?o=q4(͘0=/uYSU)gqNgV*|M^#o~+*cv=]]|Ze{яJZu!j#aNfX]S%އa\f˂N9FZxWK gEΔq\ϗOCOMAA ʣI,Vub@Gwr׃<0Х@Uh_j}!sJ㤃Psƻ7UUT|ܓl w\A6eYMj]3TX,=ÀP/،CgK@A+ s? 8=y0WތM.&);J8@gH_8:ӶS,Naa[+(;[H^/4qFWJ6:lq'?Y }_[#;?afg^B#rN BI)gyXi+џ3t*HrNDA8,.K%-7܇`b'Z_(^$=3sjBIqJV^awX+[ RGZek7%W9ˢUiMkNpGR$n9!-5&Q{1%4SPV=|Sm牅)_UkvOWH_ZDqKF(>q}#RO?N^3kgMnN~Dz//CLv7F`!~>@iDD5DpsaU{n*t7xB_~Fyu@VjO 'ynuޢ/#o՘NIےi]RA'([P="$i݄PkHG3 30C;`Me io}:PPHb!i%K41W H>Ə S*•+DN:|`7kAΧDvMa ~uBb\-3 Ez5fqg҆A ~??;N Ŀc/ SpBvvz^I'gwL:'yƣ`pryҲw` !@_|)Mr ,lX{wF]3Sxn/qup@̥uv+W`e.@ЀhXh>u%GsۤJ$B {E5r 9P"=Gz逿Ǖ#;{ChI+sf&lS ch5KIvͷ`$.Rb-k K,井I ʍV꓂zl{lj:`$/!/_ uvE';IJ=HߑZY^vL?r'SsUÒʻ}nTO}%4]$M7:}D͇2ݯ˺ 1{Rg?=]yW, ݒ(G~䡼*,`d~2팰X6<,݅Rtt_lUzmOg.%NƋah9Ƀ&v~-/8|u3"dוC%&4gahk8YͰ N1է97Пcj)Wݾch b 2K؂*% Yg@4a+iGa2qKOdKOU|~0mOчj#'m1hw҆KA^{"h8TyԤc*^@ @O0AliUj^)GpKi,?5L+E~<䂛QHJC'Aa"Z-Vakqy,J+ o/uAۦhIS~o_Y8^x ?b!+j۸/c_AtaM!x,;w^Y^=#ȠB Fa>+oL쭝;Pm^RVST!cu=yVR*Ed;7W4D&\HlI8g+-ܗ.cG j)!uaȘQͅȌˎ:--;d7ܦ7DchR>uZ^|Z$W~DPJLGYz/:$ o|ERCjgr!MAޘ2+Jxm1 YW"&qEřQF/ ^]EĊ &NH%3WJ} [lmk f?hwRtF2r{ aI&݌K"gM/`]i,CV[\~:ȉ{$ |`gK.Nq3Ytl9eكɽwS1b#H@o.Da^VkdNWϣdC4Rq#aD|%9>6#1̢وUDMqPٲuQِ ?:)mP /"؋M9;miR\sz=n8xYe7i_T\2pk'gPn bP *u_QCf=Wy qls=aaN O*4Z YZ