container-selinux-2:2.66-1.el7$> eA޾>?+?+d  $ L ")z( 8 H h  0  8 X     (  X  > ( 8 99 t9:9>(r@(zB(G(H(I(X(Y(Z) [)(\)@])`^)b*d+%e+*f+-l+/t+Hu+hv+w+x++Ccontainer-selinux2.661.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[Lx86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fiif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&>QA큤AAA큤A큤[L["T[L[L[L["T[L[L093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d97d35871d6dcbbeddc0e5d72140fac6e392d5576c1c630518591023309742ba4bce007968a1dcbdf298e23d31891aa8cf7f8c8ac3db92be4206acc5e8f1a699brootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.66-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux       /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)selinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.66-1.el72:2.66-1.el72:2.66-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.66README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.66//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,XS]"k%xĉNμ5#+mz qwՕ^.Y4jS' N XltfsȦNM7@inp!}t/@@E,Z2-rkȺaq۩hot7+nj Pm Om|?$39V`a()F{|S@E:s1wBW;h ƈEqų̔ =,C^cI1B{NSbp4L<%ﴀ'kx,?0hGˋN3$+fN\'j#<}jM/lU MJ )-x bMjn d* \JBCP3C+. oJ*.tpH7hڹH*,A0K>9¦Z`^;0W2B>#u/,x̡Y:Рsy,C 'DV. *!dWͣamǮʎ{ls@c*"Ǥfǯ~O4?w,beQ/qɵ[~dkG'e!IP ]X-f7:ΌKTQ3UDOekV[d +˺g^mq@oimhy=Z0Qv[Cq xR}T:̔,:Q63iWdXqn5<%v <>NQkXlٛŝ|uy]YKuz8sL1ZK>~Et3SueY3WŨA>Dܣ\t3̻BE[Sr%E x1܌Qta[2^<īe +ElV(!LzDy t&9f>w>FT8*\ OMݐȳ׈rcgW-] I\#!2c"Hj"5"l1LJ TAy  +YwqW&ha3.hAKK}rɺ1'+>Dh(IbCВ,pj]mS ].'+38;+.Τ4xzmJ %:i?TTq[p_ɠLa΁sli7IhLO XQP?bpUS!AMGQs=\+*yy1#@ƛoұAk+DTL if1;2Q JhM/!3]?v2i` =qlLmG #o:Pmy>-F-(7҇!)Tiq1A7$JldFK̕'+18U>eKߢpL&`Y|~'a8Jx/a[j&z ZI6ϦEE%)bMT~{NV?$-t8 ?(5F뼻yOi $ jٓT(;Yk\E??̸(.|5^5d\Yam/C FE,gf> FB^A%㯵+ >%:S>fm%;-3$Ӿ"N.~7n a~/^g*yrBS ban?mO)Y\F#C*DΙ}],b$#tEHL/8K|l|w2tA].s>I XT2 ٩Y$w$"iaI dN߿? fRln,8숦,t3`&(%=>9bӃJL ewTOe;yONdU[ۗP3J9޴]G MGfZkL>ܼ?-F+NtQ+BbmF36Ywhvw;%Vߺf H;'6ZS{I8O,EAF $pIB2)y{ @qҖFjӟ˹nGHA'| PQ{ Q^MlQ[ mE4 X8*xt*;5е݁g-ʴtOA4n WsA;aܡ|"5[_ Fy1UŜ95U΋sg`&%م㭸Heue ;_m}b'pl6A 4q.v1 Ay7O@E2 8UGa2ԗ]^ LU< -r ?IDMafxLiXVY :<Īd^%M~ƶЖ7חAA F5N!4`cY6~hJEpESlv\XWÅ:ВUCv}ν>eQRb Ծ)uɆoXd"k:ĜF61ʼnC6+fȪ[vԔ^2B"B2SN,Wh&TRKs4fwbjXǔ?D/ev5-YNK^pүqI?t07LK[V> $Xbk=,kp-Ԙ9I^ߓ$-vu_gv5__sd#_Cei<V|n&)a">1HibXcmS¬~V47PT6<Q?6J^ܩ\uno}a U|v^Q~=U,eQq!:jeao?F]}l[[kkgP:MlWGcƯC`6^KYc !CbxkOdv=rǩXnT3RH̖Y$/`W9N*P6Y,0rmS>̻AIs(2KWax\9Jare]aմζ8; x`6:2]%nB%c/ߨ?jP`1g먵( M% )c]]8_#e$XԩM:L(MCͩ)0d8CMgd3 .$&7ѳk"n0ǚ1O6Jmb`=ЗG^w|W I2${Zr86AZA.P^I & e kMo_,`AtowB 5̎[iqTaŸQT԰XRR"<5*(_+zQ h-XIېaD~me>|=?Q1x9$b|to _5:,5{oddԟV4kIi&qx M孥[7|yδV6W!ojpH,oRa=ϮTQtT޽ZH/Pڃe2'!H>+5<38H(f:t60T9PKx$YFǤ6ʱkX$(k0QJ6Oj* t%gdʴ|y:~: [Xqk$zp\GC$FOw2y"$o3S_`[-3k]7@O"ܝn!m =?g"rrnixsZgMH]X Uc8GjRk%"`Tzq՘KxTkqe /4ZD0zDŰu٠ M46:4Q*E}\so^NV'+ήYkzX'EZTT/ b\w< -j6 9%Jdo`*x^رP-<]$0Gڄ׿*h4x\)k*X _z(&ݒ6&םQ #-+'4M7tڲβ 1x)^/=ak Ф WW%lǵRur#:;o{ j-ge]S=6G~ʌFa#ֿ gi/賦˳8{e/}뾡Uzu;zWؾyiPBEo>-?lZZX_oMUa E D}A|&o q m~:p)vKW )!rfhv$xVe.n_J t3z$ km_Ɏ}јsF?ŧqQѧJd!{݁o,Ҋݴ/!Ծ`pAa"GⵝlXgzϰXvݻ=h*c_@?-㽫el:j3 yeNSQ?u`|uAy"ܳ7u{,w;uɵ=f% D2Eɾ`Ѕ+}·~G!j]ȵDM%Y)+;I+3T--vhR{uLU!eU8ZQz) {Y RTLr__| V&KՐ^(my Nn ~UctSIǘҖP+Lq6,(&kOXXTiQJ I#%lHDRm΅t#s 3몈4 DGzM-[w?!9Eg:XCz84h-5 -)dਟF"5X.ZpV{AQk|-w}=oWin7* 5o_Jw4HW]So3_Jcqã‹Q.)458iꑤ2?/;/}UGk~ L(6IS qKfqs2Vef<\tč$)i!V^E.d7k[Ur*?AtB&ۜ8< ޏ9jQnKM bl&DS3CR8yϧ:<@{j;]E}[EA(,VP8!Xhn&M0F6FLߎge8]MeJ/鵨{[7`au ZhR(wz"7Ȩ3O`GRDe5,ȘcyQi^]ޭpHxңZoz@]ͤt8&tO튱'U] mNmK ~ձ}tx7=ꮝϪrruQhVNvbXD}0LQ[>}vqԔ}jm}`FRr0 9IiEe/L3ƶb4ǂuk"Z]Q Iյ^=k3PP3^a5c3 EjeaԎ²Bh@HZB7?|šZUap̆Ӂ IF 2l:MY^ c|(8FEڝD )_hqڶi[@&Zh]ᓎѷJԑi? "0gGL$HrsG!Ժ1!p ,}S=mQ5g?7.QDqR wFe ]^!QqXDDV6EiL[D~"Lst!(Y.yQcMdåɧ:Ϋ Uh@e[JRκvlƯu\=l|L]FU:?`8>hǀ:FwSyM DgJtd2]זQ]qK]E4T훇v ?qPU&V~E۰>IG3ċy,NQ@8y4r;n62k8v9(T2*grͣ;M7-fb;}ܶ)櫜 -DF\8-2򿜽XޘA{#H}e,KI@dζ+W[2mc8}m'ʾ=hja!36m.V ~˲~F/q@MV&۴[}OW<KsrtD{7\yy74jv-v:md*2v{i6[M^jRR؍>,SOsQgI'x壴_]~%O0PgDgV(U՚5>\sDI7L%><|)Rè~:c)h/B))ɮw v7$pե8%2rak%U%C;WL9&}9:֮N ;ؙILaDz6@c"8^=兕L_+13|WĎ1`^:SR}3$c-7dȩT9 Egr}e![:NI*ID!+Uj"hy:`?דqe8}xq [Q'ܟ3$ג(.4'-O{HZֿ_Hxt9wbL364 ;Ԥ1y:8 K4^K =@/-^~n)Rݽ 3>DF 6G]!8`M2#9zs .gᄂЙﺝ}jY]+5e7j䔿gcl}Ə^-ɔ`Ti-s\e? JnV^*+> SGOc<,x|TBi _h)yVuk['A{8jb")xdP6^ɶCGiW@\7KZRIl3TaIkDݰZ/)<ґXӇp0]UhͪXNԣR$DK}A١ T$ݔHi" HGTVDJ'`2b -2oR]lnL=X/W 5h95g{+aI:qcL 2Bؠgp[gHRGt~z+k))L9o 9!D(CNϖvF6ϡ:O^U RUDuZgY~z !L*Lp;%tA@Fsxm ݩqRݐ֮}dO\(/Ug59lITd TW/F5?qt=0&=>$ڲuE ;[R=xE$\fF;6SV5݅3/Nt1s8PbR,:v3O9'*vcOrhPz_4PѽD7FJIkDL A*~ӫXI4LZ4i]e4,zD> 5DFXhJu|3k+_I.EkEl&䂎 w,[_F*gwG%2PFirAa.ٟ%K Sկ59ڸTf[*!;_Zd6 izl0w!(y&@Z'恦pY,NVRJSrKC,KH)UaLjWcRiG=:cxpu(7=^zq|oLhZAhQo( $ԍ@dY=8ϛBHp񃤅17@ T}CZ~祇 wB6[|B P02jى\A0k@$B#nl$@ z]ɀ'P3dKNi¦'Yη4L[z-ZɓDr!|AQ,r${FCNFHmԵ7Wdiۀ lᎈŻ4]DhcA=rqPNߥ[[ҼWkN^oEۦzeȯWƢJ0'Ʋ"|%Jf2Ѕ7r?nsJ]z(ۥgCk;!n-z"!"Ow7UZ2ܵ掇tgA83eA7s u۞fܥ ^~IdcKppu܈'{C|ԁ5:Xw(9 xTX֧z(SU6Oxo-sf ǶHfI$|0 x&&X(SGR&s-\ ;] DA* ^%KƔ)YbQ쯲:)v-T%o;u'Iyi؅3\g]ϴVhEqWQQu֧6rYpM_I%l`} @CRR. zԤ楸Ǜ~}*;sD"E6ky_KBHLu}P}0#4~\R~O ِV6XG)ȗK-+W"%@NXт=r5_1zf6x] g}#15䟂AީI+0Wb6˯)e@7[H=g *^SȆQ7)(mu!LJGpK C?4Êv (q;JbK. ;/&&i@;!c0t]..n/쪿ʡ[c<"T,)(B@suTL(J]^ k`qvV_Bwccr~g]g?Л~-ṿ #ɱ-B.Xt3ҍ UYGPCUn^9ddLG^$fe1ewOo D.fΘQ;JD(MZJi~->l;ei2-FFT\[ΟaF\!6L+ga OR 山%.htʣ:"L~5KH!/MPM}W=?&# D- W~1{UEQǤ/,\R|j$-VI+f/oW-:mӟ1m&]eYDɑ]4Bfp 7}4H&ɑ֚{y+>j@ h^R1C\(ҨCeht~D\p2c_n̯\} cfFya>w-N=ٞ%&O@C\g-5r(x (?-&_q  sEcéco7GzcȚI%Y祥T.PݙSג s>Y*hqU.4#z6םc`,-)Nf w%Tz:ԓؽĕSVau:[@p;l@IE2>I)/CY;_R&"̸}}l`Q*1 ~BTj35&d_&$b[׃0L4['c>򸩱&.5gvsv~x("咗\S;D 42s")H*JQܾ,_3-{脹f~+XX.G'Ӗ ҾXM532K;zT0%7v2 U5g.gK!aJ߰/6d4{C84gV2NU)$* ]H[d 8Q\i^Z ?Pr;#H̬gM ?ac}$9Iwرi(=옫]j-x>7(X zMF>^gmM-5ѨZv%Fb.ZY;';-+=, _}AÓRó5I>/#ŠAè,i~BJevQcw @xH)HAZeC5ee u)d%V!k 9?n/ӖULVu7x/0#A.mƍm, RQ| EpjK ID4%jBP6Д,益L d.8ø'z#wWQPy}>) 4&2BO[ >;2YVfs8HkKz;Q=+f,.}aպz9iM̗k L:xXߌP ?vT2;˽PS NP:"";}(#O5{n\M9֗<7> n&-aku'Y~v{7L,IvS[՗t'>F;m 8%zlݑBnIv8j p77罍*ɦed/X@gդJ&{wb8SThSD@XۣUȦ Apl}X(q[f "wahמMt}3iX[<"y0RmPe3%?ؚ֔] |: }?_aD󸢜c/-S=}}3G@!8nzF.n[x0ϕ,նK'F1-֭CW&+bNyQZS5WlUk' jQ ;Mys>- @YkAGֳ&̟*Rw-oW& $i-;[#I6F!<Rb@v'|Hu|q4`JÑR%j4}߫^SΤbOc)Kk$@);J2B9OM 51E\,h60:G ~Zue8+kBFaM[bC n " !,PV!Y+vMn0dwY%DB1ZA蕧EѲlX7J zȬr(bM}Ghl~|9{O:Bw>_uZs=%(6{/#Y2E ?t(NS;IYPKDF-ɓ 6!iMd鈴c.O%LLe-5vY|6*,@וR*Pg_wwZ_ׄ-38Tﴴq p>![,ҒmuX(rFI'OKwj!jp C1B=1vnҖ-8-W~^];EG( \,#JV5SanA /,ər #%Xg7[+u⾅8Gz~|<9%)yz C2o(GձG$ɀ[}*_ gf5W(W/C̃`7Ax@rR船dt jS*>7kBOO'L1ݾNͬ Vj}mgm]ly.N}jn,x͉E(쳞`ƚ^>!Z=}a BbTbC=9i=ev]y5@ ,扠MLJyԐBAU0=V)"5LrkwT_r^G_[8;\ 6^pl올i&e6B뜽 )"Fʀ*6+f2':˞%!G4rzo!h6V]uyGw]]Я;r_֍e+l45 Z 7gTR6WRĽ+Q~v%ѺQ:껹DpcYtf1ܱcP9|{XW"Q+ E+j۬hhy`pAv>+e8o*Vx0(.6Q&M8j6m);yl@=ݔ$E( X׼fbDpk:5\J9?u,y9 ĐkvlXƩ}ÛwG#2eyWCXO!i|(I{jsG b^n&?բor[1{lBZRo+H K^ h.RkPbbFdz =O -ujTi3۾`0hhؤPzNQ]wb=1|F{pc6 Q%Jm5)X|Gz׻iE=+ !W @+qK`2ދ2 Z?($5Q|fͷJāiv9^:_/\akO ,2& T0hcj#7" &'͆[ :6C>t.UHԁ L.&=:}"\<(Hb4_a3j=0jƳ3wֺTpzDs=_(6w~/aѵ{+7 'ROo]hHz$UvWоo&b#wZCѡ҅6ΠXػ!,cE4`hXU6*N|ٔ/@4\ɝBAof9V%9[&T`9,!#L77wS}ʙh:Uh(`0n azWB99)xLy8KʙG `rŀR;(qQT&9'5?Nq,[Tz M>*WW3u4J0G]Š]BSNϰ5DHI\MA;oUqӪ|5f"X̴z(C )f@Ao^[κס>,̑+wwvz٩FZioӡWp)#P]edqHVLh̎}uDf}h`FH-Dbv㽆v ># .5F:"qoLT U+)@cqt-7H6؋zq\Hp.8YAqYǜ '9mD[ bcrs:NШ-Ul/2I'e a+ec!i>3VH>k/L3.lI+Q "XoYIF@5M4RM<;qs8Ø9'X \YK@Eȳ-&Ei}xƓnj>t<WEe-OTU oZV*('8ֵJl辀q#7la^xL-l6h~p=7q3=hjdCիo^PF6>鲱|?ݕu31XЋb8wTYË'ACzt7Av9 |_ەi-O~,:+ @+zgm&`1D EQKȷf#Bmю,T0"=l>yUl <]`]fkoɾe\*{B.7kSF2b 79I[ЬO9FW.آ8gc.m)%KkgGk[#DCۚ ݒ˗O# QKčq-s=A<Ռx*$/4 =I;;L-|W%iF촱jчa-qo.j~K'gyClrg@%1mURWO }uȐ[:o 0F/zZO}퇡g4]IY{G͘;okW+nFL!U)Pk.lD-fD 79_ Ҡ(7Y[H<HB@ySwe'O<{1LPFXA5RҷElFr^>aׁ +qB`gR~)pYmqhNLϒ΅}wN_m-r &$32 cJQ L ~l`u`ZָA_G൲ӛSjՙ*?!tPT|b97uƛüHsP]܁ߥ,|@em`|2\e =ڛ2mHB_,i3?o;}cve5:;%_^ڄToSuepwxgo$QnqVqJ榕h5R! 3I ^Te7j՛P[GfÍC uqgo@۷4e$LNNȼx:e2y1œzQHff@)3LJQk^^cPNNAs}ܒ_Oɂ^zxr $ t7UkV^ hCnjeqg)vo""#;43$(/uHRDMoIf뵢L<'˟j5j]jnn4[H/+~c M;fZ;S=S;<'Uc,edDg0yGh4*OnjlkČM,3Iħdziݼ 1*VȽYp&1+{SO-WD")}4[ d$UNW$SayN9GV|'E~9`oQ OysC|բDF.qsB(Wch# ]3nQ4Q-2ʊ^ KKEt ݤӡw gIIS>~M754`$!{vBDmAhS8!K07˞m!Pu>W9SNnضҊRs}8vgjn)1$)p}ۤ+,[% .uSǹKkypg> u;Lpb74׺hHK6,KBZ:.69}:TPڬD> ))߆iJTmaSc`*_4w5LńxMl\"|}s)v!j..\Xު}l%Z` Bl$vS%}EG}8\ww&4,̌nPjxfRfXE>B(a|noteIn|tPPAdq1Wsk!݁Jowo\Aa0Ǡf` Uez,{8@ Aaq*t{m^սdVXWo:G'ӂ;6Xd#)Pv^cd~s +@\CJ.It;m'M M -ůj(K̜mW33"ZD`aRo]ȢE&n>4*lSxqQ-B[,%ފ7b$~Ut¡ĀGkU(܆omSsś6ՐZJ1saGAA/#tIM0qXN[!Buh5 Hֹu@tԂ8T?4#ӼSskwfPD(y<0 Hd2UypeI0^{c+ ??M)9MZ\Z<ɐUO/Q I ѥ+"7޲GTPI(HV`U8E&Lxހ79ъ 66Ja^-Vwh}u4׈/c6! a]=L&kuP nmF\-WC$L ؋ k:}mQ΍4p SQH,xKH;+9 k1\zoǠ'qݱn YZ