container-selinux-2:2.66-1.el7$>nst."f?`C>?+?+d  $ L ")z( 8 H h  0  8 X     (  X  > ( 8 99 t9:9>(r@(zB(G(H(I(X(Y(Z) [)(\)@])`^)b*d+%e+*f+-l+/t+Hu+hv+w+x++Ccontainer-selinux2.661.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[Lx86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fiif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&>QA큤AAA큤A큤[L["T[L[L[L["T[L[L093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d97d35871d6dcbbeddc0e5d72140fac6e392d5576c1c630518591023309742ba4bce007968a1dcbdf298e23d31891aa8cf7f8c8ac3db92be4206acc5e8f1a699brootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.66-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux       /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)selinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.66-1.el72:2.66-1.el72:2.66-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.66README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.66//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,YTA]"k%xĉNμ5#+mz qw+pQ;le?ȃbfF!pQ~A I?0 zFuS0$N}t& ׭DAW R*:*oP-dBq.-=?odcxb<_y4d eѧʥU/v'G'$*yQT^N)664~%p-Ђi)X20dLeZ߳t!޶ B߳8!r z " ^3I78­Tj$a7Jօ% Ჿ"_} }է?m.V[vq#ue&ՠR\x iKljuq>ԍ1{D@P/ A0H37O܇4R .FЌ:[@X+hb{wb8$S ^=5W1<>5+b͓<km k-T=4vtG%겝)Қ~оԨ5/\^Qtyajw*'tfvKs.U/d"[%^gmy`c.9iN06qY{IDn_A0&u6bl#MU;oGʿ cwduJ?i]+xM`aoßWM%1J `mQXD:qX7R{YvBѯ犵U'ٷtqY5[VjrvEoFXe>u)ލjf7/&M+*>+.s|RԨpL*"B*]գӁ$L;\ƇpV(<]G&0Xq(3y\?E~z[$DI5b٢ C ٨KA\qu*Qe5͉1iuS{b&'. N]$&/ ' K7FȚy JB>tP/֋o [$!>GDl@OEƺ+*|KÁ&Y9 Ԣ*O#敻{|\9 Ixb\Y]dgK˭?'y%nk;@ Z<ˏȘD&ZL=)0H`D)("m) GlI6'4Dz/\o0v s,>NJ# woRB+Ma ~A5rZ;Y}5uXPcGXd}f%i;*|Ī.yI>Ztw同P]sGvoMNƒ.GoB[S+[ CQm+eR|wܴ""PsQ-%хŀ N w;ekHX-34R'ǻnKA!JEU+66?6SI/V!CKɒ$3O9_TtuY%avĊu}R=`K1K_>d$\zKLOi+U1{xquآngfk&ZR9r´sv$U^/n2Tɬ)Wb) `y~"I8/7tpDǾ˩~)( df4ڳr>_d=X^BـNi4yDv4$a r.Y'$gq!\8 le dJaG6[],]wXˤR1ձǷZ_mVSC#K.QF1^b3sugwq͢aiÚ_N&|1l #E:iFS Kޯfr˄v =L2J/Awˮ/Jfo^:d+~4`;ѫ̿,MЛi9Wi"=c;X2p1 QPjPQX\ݟf.i{% &'iJEXnޝB cHAs'l!~!q`q:w#bϮc`fcheD"T ۥ 9R4Pú859Nf/ktT-{|_˯]c"B9Qˢ9WI| &RgbX{ bݣP؝hnNUEDɛEAѣRۅM'iNcC8찗rX}t*r1{3'1VP]"=NUzֹ`?c%w&[V^GR\I Onl-rҒْ,J#WWQOVEg9!;QJf:ޟpue^ gBn oΠOJ`\yz2+ȋBf;O}ebF! z%zIմ<.~q7n4ֈT5HaSa7E-`iҭ6|'#e`5 I6 l% bnp]/:)8wDu3K~c/5͇Cz[r/E&6iՍ)t#Z0&p`Swh۳8i;G? ɺB 2ATr!~hq1-K"!:J~l9ҔT?/Ӎ_SXb9}n@bC&uF^3v,)~ ?C/cz4 ԃM!*+%ec6{@|B~S]S"h֣.YvJͬ5 q~2)uz~g٫ tr2y) OQ£g,M OHܷüWFey$]C5-`j7WX4 ^9Hs~j`B,Xj9A⦩Tpv>(qOaD[ZB"1 _ژuߪq-J/$K@SqMh..WK[1#B!z6Q[Z:&:x ѥcEqyem&wiTn8`/ ;F$eMqW_Th^Z4 zw^"8f5hO8i=)R`(h ̨XL:22%]&J m>Q/'_Zd&@qTQcT}Ap@y{c/{ҍz1>Ak%'-XW9߇6{RqiҨې!Ubm4^|\V747AW0y';x$ X28WN;zSR F;H[ =As,p)S-@0I(%=`|k(oXzn1@&h<})lYxؑӔ|p[|)Z~?Ao66-GDMYt-$܁$1թU{gealj&DNO>4՝&IzGy[\N5 0"T&@~ezD"y䏄\Ρ `IUCptÁȆEl&5N= أTq]FE;n%%aO 1j w7QVh0o**񇤖l' YM>Q['zTn[ s3f:P$Vet MHE pIB[Ɏ$C 04p)\n^V;L, y#ũFC[A7B\FT>T(ff+mN׫Eh}EhA%MDǒ@ W0g5SPU\-0b\ #C?jep:[@>ib(V8鲒&2z-*6?+ȆC`n r)ix'b \ a |<ЕGz- wkU[{?5 lؓ|bMu*$&"혧:.)1^;y)= lꒊ<<nR,ȁ7_b M;W{wlaEߩ⵫` J0Uшf6+dG(Vs_+Z*̥C SAJkt!ֵ:Ěsqǧ_Oڼu3ķ3/x6cd}2 B^r|w+un^3y/%McI<;CRcYFBJSWl֚0ٔkM6KjF_T;'lx?x6W+5mq)S`gԞ Θ,vU~%,DR[,mxʵjĽZ!]Хxvtmud2E4$y_'ނDmK % l_\Q?LvǨكؚp&JA`SZT ͌,D23m~ [ w~q]q-\(:ՠ "ITԻI?i{]7lŝ݂dVʔC<a݄Fݖa݋dk_r 50Ul+U"Acie(k"m㰘T;O)yH0۹yěK?nŇ#2 WM/Y` Ă3#GuM*f5uZue)WrTc̔NŰ%rI>"9UG^7#1ipy󆸤] "Q" 3m)nDqga(( k+(۶eATlzSX.$85Yry|Uy5m~{+-%bQ۟ En(i <.6Hqy?/TdȆU#yOa],?su^2MذF"X^S%&Wg#Umn(t#WZkS 9TR^gZL$ۼE? exȍݠ1) rKf A @$٩*T=JS,[jZ,P"@i(/D>udER\,>tNL=ƓJ6  pFMk+<4b"<C\,̴{3Lr(3vB@  B/QQPY̪ >Эș4u8;bEBtzC֋ NJʇM|6) Ұ,D5pXT_c/1X<֝WI=혶cT_?3޿Ty`K@fC#uwعx%!QIQS9֧Zߴ7M0]@ٷĸ' /ub qB6ߣ s|6S'r6NL?[>rW9(5}־-m:yd㌏MK ;TZq¬O5Ke2W*J6cdFAafJdb3Xa3:3:3FUX\&oKTP%,V.-.9/pU/ 60ޒHNsLK;^2C:`9A5X@uGk'J$ 곊,p z`5 /,f(%Fm_&}Qs(L>Emo3aAzwc[OQyy:X\ g0źlG~y,Bb~$&dš3 ~G Eo> Hۖ\7?+"&ZBcu%G #-rWzЀ;ǍV*Q&^d1 r@9p*F XXߣLJcטIgHX&`ϥ3?S[C O^c6䴑yQ_Ƒƕ)"X>J@gpm£ k8 C0 o4Q8̼AzgqQTnarlJWnPi =|4HaMQEi龖D+QL[h ]a SDuEe%Ů4הE53i.wIxoqp#3n]gv  3^c+Z|kQvTD;Vb(:Yq! ;NT\G[]Jr=$޽; KlO)6+4.{Oҫ8*22P^,Ea CE103C6 KCE 3w ;Uቕ'\t.K@!E-}feO]V&RN>&0ۦ/zͨa>Ra o5W+YğI] #Rw^X ?שc.}R(TfQܭMji}(&b#2s6 '7ؚ򯚼iXqT(F%%ەRB/~?gwt}Α'dzXܙ!0;$@z="y_ [Aݮ&EQ^W';_k ;dǬөO΀B̥VHjL28jOڏF"(/a }M$fbewS0&ޤ-$Wg<VgV'b7znre$ϵ1j$F[uLj ]nӤ[_C1oݷ3ؐ4o.g ?K-1 aHra!qS,\k'+N겊e#aDAL\j4YrŚA&GM5#tQHurIt/,^vs>V9" ?#67^f8/ R՜g}RZSl !+4\p: U8STر.=mMk00ES"/*ӼP{q1 ZjSP/ MEn ?#DKH"Und]}9Z;i=njEBI2QuDIvvKƾu}'j;}X{)&k?^*}"݇DSWv\ZEGuU6]ۜfXS@;4+8mΠ'HF-(SI-h"ò c=Kuem%ܭq0ZBV5X5OtwƋȦCQH@k廙}-w;؃뢕{+-H 1$4.w1ͺ Սm/TKwnB` sin0=J2#Mbq>asiRW^qi͟V$F/C{F2~}t0*LXj|\FlJz+ <\/+V'HǙ(bDiݬLs]C?3u/}f>L%5X6h˽s"XlcǓcMAqk!R驹UyŃ11*#Zbyta5#$< pigc:)B zʓ3)<]}:0(FfR\*ӊ2`WNO%E oJ~"98IdFX殚݇:q02nVڬ LOMD=-<1JԬRl.WX+\4T"nI?4_U'Lhh  lҡgvrPEpF*W5n^C\p׏Y\NS h܎e[R?U#kᏏD 1ME7@xЎ&̜\JydjC힆qRs:'EHuҏ랚u3Y+vdjC'X7z^'τeC`$_T sU2yҕt𺽇(&u ^ik?`-$>B"R("*5_D~xFݺ"(Mw@\"!Kg;ԹdջyyV]ov"ZG)U23E dbϣ3Wҍ_^-[Zi]^kE"R5 p"zDv1YŃ| tӁp^>N(ЯQy"3 9lIhEynzy~ƥG$7Ý*=mjĪ3m\a1 v ;\LɂIG [s?˖)Pr@qyӢŋF:maFjϯݴv%e_b'N]N ''7P IbJ8sl@i|J"sR[GIf-3ZRĘ@<ӳ2_x<1N :R FMJRS-R58;Rtb+Nv"2c`%!-f;B\ZYG5䗁1qEwrXEٚxbƏeu P#dEI`eU.Q]}k0캄vKѭvaL1˫wz{sgnn˾ë~O-Fș6AzEY3s q$WTlS'`Gູv8)Wcۃu\4`^Y*Jw/us#B\SOVS=?Kع%I%P7jZD iOC˲枧"ytY3k[!pL٩O-دmd'N/?3Tb%Ysq`2~m;ߚ"ঝ.ΉdTA:!7V}t >8᧲# MABp͒c-Cz28Wg:݊wξXQO4=<@,ʢBݨDb޾[0>bRz /<~.F-ZtU%<=* }瑟umbLN~n@5S_Wyʂ>:+e(h<̝&BFE5S0¹8k`I_wC#S#q0¯|2$sNuݳATC>+oeQ8,Зrgt?)й O]3ybٵA"Gp)ŒgdL;m 3 1y]aC@ NFAX]Te}(Y(/wN۔(82r2(oV6Rnoŵ6 $5YSrU|Nlu(E;Sz ֗oѦE0${wRưTwfmjQLS"X M% ;&)x_nd{dz]Q\Ddϫ`O)KG֎_w,a"+zA90OV ɱ`27@ ?lm:[HVFd a|BQ/U[D%vn[KkcTqɂ̦&ojՕ^S/4 U@q:97t/zS)nA&vC(pO0OSR5-}7W_`Kc=$n,ͫW(Ҥ(wYUカl_6Z>Tל9Lk /I٘E0IA:3Gɵjш_fR]lЎ6|vU9n'oHMwcW!ϒLt|3Jz nM>t_Z/`:P{zO xy|6jv%]]F.[`de n/ubO܅@𙭩ϱԘp.0cܲ5PA?EЩ k[BH.:>wx; 8̗cYFd%~\3mWV'urWe /:"HMu"L_+׽[C5/G $ 't&<>蜹nI^tHTyE9"wE Wc PDj:k /*gb+gl^>i9=o {$sb&m![bu>"q{òR_\V#3 [-4mo{'wTnl+^$S0m9j &Dp[FƐN"r3%,! ~W8`_@5jhQvb -BJ8>Xΐbvv,3HQ (?߸4t&O\]]Md3~ o׈eH0ЅPϩ:ڵS#@ˋ!ٳym@;-߅OUB([f[NCτ~:okC"ۧGͲ1eg.qY{oH1{ $S5ŷ2"3sd)9}N ]n3'BgL yQ8Tpx}E6 TЛv5)xMRwn)Clp?cۊyD/NC= IyW}@vnؠ.AbKXY 1<:-3^(wN[wi?oDuaDT8v3Zw.G];pB|Yvrj!,Wzǟ#}_I}J"ҥ+9ei.~+I? 7`FCps7H߹I@^Sdw()>XXU,q-(] 1qXAao"zC6*Dgz$D<ٹ(-:;ь`%OoáK] 3TttGYFû}VuŐ>3Y >xZbL͂ظw?5W]GJCNE!|J$0Q4aaI `&P1ՏMI :woz_`.]!Bk[h+ij^qSTgG9 X#5Kh0QJJlaFDAmIK.P6<A& d|H8Q1n瘧`3nR>2A@*Dr<»]ȎК҄܀]-h'n4u'Sҡ 6s]NvR#ؒM!㊌SEk(#q~w$$[KۂM EXy"%ƻ;Dݘ9MddL%Jburb:0xq |Ujt017kNn}<ϯcHC*\8㼚Hê*>=qz<( ۡli"v^S.hMJGcɱDdi3^+T_Df>+|~!o{\x34 UGDMUwjӸ!y2|> oGTbH(_M`\:`k5.D*n9ٹ5|ψ0JÉ4ː53ϏPg=U{rȼ>;qL l@<"KI'G˴w阽=GC;o?ݎ 3-N謃j{`BԶ)\UN-3+ȀW&9-h+[/@ۺ'HGm{NY3*un^*}, ȗuE.eԲZ+Hi+eɔ^^AܧX"\h5wEfN݄u+ͮ͂ef&y2v]//"hfij>y WD@ג=77 ǦI蹠U?c}[Tgeb^<}iknX*c uζgXzL<ӛR WA" l9j;4\-$Y-מ'-dc6Jyy׸T୻b?¬fSkq#$VPĶ W2BLVdž{'yޠхb5R'Jq0⥔Bzo12ecM/ݐ CT#&@n OZ)wc$-9F@!bz5yof "KmhemtEOI{TGgpF4ĞeɟɍNz`ܗ-a1+X%|,oowYroT2Xi`< 70CT Qfclɝm/`*+;KE'S"*gB@L<[^o];8#щ/]2&+_(/tL7wk-(oTP3Ɠϰ^+],J!YAZJH6PlP)7sDžOa1Tԑ$l)MLZr!~ BKuݟ'_Pm~h1GJ ҮA4#3*z| %u>ms@L"6J86\%4D&$n1*C"tC[T82PN@p@z৵(;-Qݰ?jƃDJ: o2 + Pv ۼ-ՠK\iYkRV 8ү"5zX$)`S04.VARe-<{CæAyLPB}bF 9+v|;歓f̓Z Bd8lzJ3վ{l(ZF1P !R:XZ,Ra@NBп=T2ݟAtHtHtEUBۡ^(!¶(A_XIMuS=|aZ< G深2hM'z<3~tS}YUn;H_/HMiCnCzɉIյ2"{雳ba.7\ũCXSkf6觉ly̗J7YRV3\G, YgThfMfQ+j7"]x%?pO,sF̘x$oQM$ d,YMUtB _%1Z}bj \7\ ϚKeCTx_i?$wbfY li! XdŔҠAd~eǬ#ϭ 3^8߸aУ]ZR/14{vt}yn.›ZE }GׂT5j}_JMM"Gp}biRhuڼ$jčo9c$~1b~+U4n|b;&zxTIlLVv`=3ieٯS(xxr ]jYD})gzv։r0V~_85!1WŦmjGfHGqPSf e_hX/QnBE0J=.1k悲AR( :;@B8@}tj`tH^f:oLu: ڒPN.AK" hi&= C}ΰ\a6{D[ʳ>16Z YZ