container-selinux-2:2.68-1.el7$>$T*#>K,+;X+[>?-?-xd  $ L ")+          0 X     ( ?8 H;9 4;:;>*@* B*G*8H*XI*xX*Y*Z*[*\*]*^+Sb,"d,e,f,l,t,u,v-w-4x-T-tCcontainer-selinux2.681.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[|#x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_typesif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?R|A큤AAA큤A큤[|#[L[|#[|#[|#[L[|#[|#093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d37e0c13396ddc379999bf51551c20564f0e280300a625f2a691ef2e11a37595ef82d3ea6281deddef1cf257723cd963de762d45831f34a25e2c20c46e41b9f8arootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.68-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.68-1.el72:2.68-1.el72:2.68-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.68README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.68//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,ZnUD]"k%xĉNμ5#+mz qw+}ke ]j-fX*ZvαQsGE&p3am0\Id%bэÉww~BlZVث{$g^*aݲҿRl:/L|W E; IA02?Sn 90Eд\pi@S>;DʅsAJg9s>b_xOcHDR=_Qmڤ;h6q#P [(1xZs؟af|*J\ƷB';MSp;(Xl>>)kL6pW=*EƐX½58C1^yK erQϜ$iB(5_.82î2PMa"QtXqa A4}ܠN3i:2yخy}Q-]G<=qd &rxv|l´2Q#&c꾟(v:K1M+ D6ZVHq+b=)28Y.4@ᨛ"=5ng@eo/FBVa7:iqr(_ujzywyT X[PdBoRo猿Q((X 0Zmph'Z2uDycG>X-x/?=MK>>GTAݍ7U%~iUk2y:Dn\V;{|!] p%x{^zRN}w ϰvlo3~-pAT@}=@ Cmpau< ccg( Eg!Ϝj$32[H Ĥ'#jM5-Y/xh$FaIDԓ*7V~IzA|B N9R`rUR=x{P{̧:WHvSd2=伦a(~v960^f pb]<\ػ:ϛ-GҸm0ׅF+ǪD&Ӻ}-M>=U]qƍ 6l/Hx&Z$ez++/QWδ~d9Ǘ^{mi",Y/hjw9Age^>|Dї~.,_}a_6v9M7zQ\xHg mU)nh~._X 7qmuxT:8-dj4P~Q' jE_Oȱ6*W=}Ե 6Z3P%+FD߸C-(Gwqmh8f<| ߠ-%8(621ULeh0(tzgy9?nj{':=t0gR%c#5Ksf +Syɑn`ʨ#NŐ>λ^p) }^X7a < F6T3-iwh9 *rLN)L&^qQ,:U%$)- r"!qEռ B>Ju \-\ITX:@gF j+C-658er!H<]ήb[.%}fw zPP7d>iNXd,AW{Y׹ ё٠!UNAU@4VҘZ5teT替o !>YYu$n\d`% 0c;$u[|QU "[?1?ߓp SX$(ȌzQd[6HЕ })e*O`D5a 1ߞ(;>ǔ v$gcCzT~zE/TQ]D< 6;HA}CP:g. -$a|\4lV\B1ngMKǚ*SKIw!d5BmglTP)PZ4"٩u$9 [v1ys RFZk ,8ҙ.r jQny#u0휍ŕ8Tnڃ'S0RGndFn c[lm]!@iKrsQ=b{ dZA1+xKTq;#Cs'?;ʘUP/Kp Ƕ/W՛+ueAwS4EIuaKCu 4Kdy{@OGOVe!cek1\Q9ѵJ}DCG๷qh_պGAEpdİg߰n^Ld&]?2W-%1]a;~ά;{K?á*@1 i?fұ6ٞ(4,`QfSѱC@4C`h3+. D>S7y[rKɲ=Je{vÙX|S`xD輐}/rɺKU:ьcPK*DF4b014CVz Dw* D\rQGyU҉܁:1I^|)oNPvx֗DWF DD N3]ŃE'*gg NtS/ _@9 o}ÖWr. "\{q cIk!YO:vM)ÜюuZ)s!탐9\'$d!w;(NNu.1MVmNn?#HjEߴ5`XHn^B/q^0aDXGP Lr:+QM)b 9|ؙE OuX?Fsa=}ѡm}7u S&57N:-ċ_68T}}*C uPHW/~mmz:S%0^tKr3 pzSrU[$(ź[[E\9!Ȗβ9_@\,l5_˛f5eOfM% j#%fLc ;!U^ohP JT w,pJDo#rR1נ*S@ ԩqvwd;a6 y;iU@`x'KBA>s NQ&SI.~F-K+coo9'QDY3k"F$Jo)w&bYr jԢ{:u}8 =ի %xc5O,yn$_*)&Wr^upu 4lr.j!DЍ*2[ayW/'-c[%O|ΦUÁ'zGgnhuzSeh}$/gKgLɿzvƿiO}a̮wPg<"1@9{a+ԧF m']+& Y \^au >1m]gI҇G^iZ%dTo&iwX:a7 $h_e w@l`=Wa%] >6E OnoTVbw)L>4NKa阘gm5{cu󊝲[6x1tZz(;(Pg )iJ#T%Fn@?OVm`ԩjTJMdKK{MjW2xs06'F[ 0[k#p@3 4İy]kpMq1Ay3^8)c+N;O-/i?&{ʬ(u g}(¾ڃMm5+#V=ENڒ$S~ŇPwdwxnrGcq틠QaK7j98>\\O?k.ĀdFFj3Pj.ʾ}ܦi vZÉ *]e}W|Ehq^DRmxh:"#5a{h?6 51}jϱO'8A\! ܊L(FIv6,=MeSN埬s@kkFPGntdf':kUqqt}vNjS)ݡ)AR3DM?`K#"ԑ }jziy(D !Vx`>hd h,abQs|K쫁ҸeQ\\]-$h /޻]r ȢqZ l0/lKr c9sIt&_r<ĪH'j}P3GȒ`t yBW?y9@Sċ0+cjX= (" q_yr:v !$}Ε<<1k*E?[?kEW@6vL(f΍BDgUgMMߗB)eeKB 'Wott$7Y<hrISTiTmG"kfc} uDv+5^A,n ,|Wp牅%apӂMj)( >HI@s5ơv K#Gu|2b2ȲL1#c ysF t '`a ?@-ܢ4K6 Mk&<x 4Ud7: KⳊx^eF`|հaЭWAnV FI}<`?Ϟo =u!F6@xhSЏCf|7w18+:Ja:B`؛+3- M"\Mg+a$ X:~ Oˋi D#Ф:/`tQPL(^Ef GAٿ; ! vsλ ND,Ĥ_vU3{e뀄6gkm/k vH6c3i^>yn OٮR@_M%2/>7=RcB)f(@c/Ke0jtT0Jy.eD;֍r]4e%d?ӶwԢ3ߵW/J~zCp۷/r]I >+.CwnU52j|禯 W4Q1!@MœYj(4o_M:z?m b̓+ݬ@lm[vD,#P?hk>V {$?~Zj`ŜadAeˣ6  HjnbK^1bzl[b_,'rG܁) OQ"[~M#j@?(ji;bkDq'_Vu<Kx˺6:"Џ?w?OGyy|"J¾\ZoڏȌ Jej/=b<1W$m Js̆>p l@0)E{|yTN-Ge5UT;Ay X [y(Lk4aF6 ).w# e|Bք|1';Ջ%CoyJ i:浰uW2Kw %5n XBѓNDV|yi1_"oR&). 6DC`7oso E[ zX 6GX yX ɫ&y.yN5)6\LDy3ݿZ9@b|O?FN.T>/Yv(ZF<֖x Ժ*tFbvM/P`7(>v .>^d~lren-sg_LT'(Z*O)Cz1ǗUb&Z?`OW`ߟҡ[߆쮿kg;l\k&ͳ$gZl]=l@B~N2pu0ewV V}јǨL9k[G*& Zv4ޯdG<%`vWҧ+dNqC}sΛccϕKح="[p6G 7>X-Z3~jq@ΨMU("dZ܆r珒 Xw$OdGvΰi##7':MՊ{*pb 7}XڄFݦwiM)-jPӑh<8Kayx3Rh(nr(@d2G+}K#~[+t`j՟Dj7(Bu⊣owIG/L A}SݑIS$2'N &@՗N\(sL3HkX04a U(Yth5#K)^x0 ,nO!%V`|mTlzVe{am.ZafܽD=D%j9gC8ɻy4 PjNj`ymGoǠIߣaUtbz+E{VTiRBBQbX0/о4Q)H,oi̟XGYN/3yPqu\'H8 YZa0@_fu!ҾJ.0%ߠX 7#3K7Ӥ(,~ƜXG*mNh›8T!K͵eEܨ\ 6Gߐ[ɤ) Ut<:~jMPBfe'Z=[DzGgLg$܌0i#MSVlPf 4r5ǀ*؇G`6B7`b-³ߑ, 0B,[&ɷ*CǼWzSD.[FU~MMׯ<:T)Q*cU_ , :&ld~ٝ©I_SõuOee:v;RvwdZr`Rꓳ~)x$ B{O: gTHF-/5w]$M9Zpf\B=).+GG-ȶ[K(t'lURpLJUjP)[,-"eܯpMGy; <,YnW32#T$o7h닅L_5!B1Ӎ]u#]?S<"\dpV :k0I^bi *8xiL s Gx:hw@ )B.iF%ۑ#([ f%ӳq8d鍫!krK!XPG/lElؼMxV7[=3QtKL[3!0<^Vu$%Ng :X%t- H_imf fA\ǿ@' :E/'9z3C#ܑb~9if6E ިOHMܚ<̔wVz, F]|V&"eW3pzReˊ6b%ۺ3_9OV_5R<^0vZ2LDR\0x3t ' ] "嬄^ܥnB=*qΘᎣj$ep0ݼ> V0ZE'*hʱ#tYȔ_~*y~M"6u5n}p,xe+K>4.R 'L@-.6/?ʙ( ڬ F+*KV${A/P~JGKe/FNY3^[D:xw#BY'Z,57ͧ?1djyWׁ .ehe_Ѐ>¯6QA&xFXG&z+cU%Jf."ͅ)&_t}Y=}@wj>=P:5iof(̠ [4 ]yCh4gl%.qSpHb8F_; Ԓ+8^)\ޙ TH<,T\ 8`DL\OHRDS:Ym"߰t~d5LY?Q57C0+7טZNvxka0~%3Y}RTYEݒnClۀijxsX) U(kRqF r⿈n07w%dQcZv׈W #3@K4ִ2ZXaѸlWfpUОEDfpÇaW%H a`?s>L%,r" _ XA~rXkB`ۼj32 kBt,哄 $G)ӜZH'2mmk|]i+FeбT|e(aI1֍t"F2|)⍪FNhLL0rjt e@;uȲ ZUZUe0ܫ)3.r;,_ {O`7i:o>l4Kh$Am",G3 ǼCi<'?!޸X T#kŸt n_>{B0|RVk jyAxgzҾ֨1>aEg^M % 9kY9bLM^A>*3t_Eœ7΂!ºR#8 !]W{Ԥ@Jau xeuMҵ3!=LKx h{f(-aN#Ud$O@a[[u6%_ W Q)hf&z%DzώI N}BquZɡ(s:.KڞgϏъE7ZrRӗ)̋җ"Aܛ|]HD%՜Ƹ(tnK=B@% ܦ员T8ԡ9 S|,܉sN[{>s:LUS:2If+.;w\b ĥzUڷGti9!mgN_)+Tꤽ&4bOH7$AjCK7GЯ'x(/x ~ D \S.0]A臊i6GkmvprE\7]h%s+ ;iP2 /-{$D,N!)1w0")%"}(XrW]zkm8inʧIAfXY wɘxiƢFdmӹ9FR?F33ZU -P,m/jnY@zdC8n#sJ!QsXVA7wd'r!YUPt%;Y܈ȯ,+rIhXh!鷪H~@)=xYȆ cAB;̑K ,{llOg4~u+`pkҫ5fguv)޶$&Tj|c38-u8(`<A mǛdCkjxz% >l}39# l/RO+Јg6 XB*v 4vc(kD߽Us䧲LJg-)NB@{ Pˤ<ݎq3-lx6ĭ@H3ì\fq(-Ųqm*i/:3SsFM^}9hT&EI&xA($1QLF9I?R4'{H{VaG VDC',\Jyza:)9G0v=)ǘ!f9= v,τ7Pv"d; -v((y$ E,@ 7e2ngIwϋ9yə=Rqo.̣"dg񑴬@qj}*k ,W/Ԁ*L8.JٹgO2q-gA.&U Z`: ttOl^"8|{),/>$-5X"įL_䍶$IӺQQ1c z`ձ{46Ԁ#K)g2,,>; ܔmMbkaw@Cӎk`ȷZjEKYѧևuFBq?^*45?4L\GkGHp,(Rk`ӥ6ۣ=w 2*VҪ ``Lb0LPP5fg/%U+?Ek6Y+ ,RNT>4\vY+Nrv wǠh5bu61ьw֗P/𨴈T??p&hfĞJ479霸1s^vYlXci<Cp|| ?bX dƔQ_zHv¥ަm'׽">E52lר "`4|;ӄ7Ci2`hհ6ۄg~2b0QҹdGCD:A'[3N˴! hN5({>.-^:m>xP/(|!gi<$(~H[۷04hpٛ2"?#W6a'FH~ؕP <7"`=jXߒ^"9Irz`4ǘ.&]L$]o5~͔V`:N3U>[g'۲ "m 4+!iDNͅ=:\ClIQ_H1eg:VZhwy9g4zL/>ھTK_;PyPE8ySrsn`$SO7 >ʀ% 3V\ i2Xu#m)2]oYG٦!%{,:gz0['b}ك`^Mp UYj'+Yf8t0ZXŎhp]|GYa de|M4C0sݳôMvϪM|ʀI$*};c+"Cd͏AG5<>E$E fA?jSe$u @MiJ žtwtUKqmUpvSLN!_&⑕'(c݀q]<:iDH Rt* Tѫ%U2L`Q[Q eLR$Fʸ ~>pjH݅aέUO <:~_l6^dzncqFxRRyd[CriQ`)༻y73si5VCVlh`p@"^QDIBV4\ A40[J/hf}^eZnhnX&;J뷻`PQQYFU{:)Y^c1w2ȡ K4" g69JNϦ5xv]o6=XK ]BW;rO3@iB9#`UvS[>d2' {*u~;ÖtʲIvt1T;`WPa.;>;M!O}{H|H/f |:HĒd]xmguoA$9>~k"9J*J܃F G()Tg3ɠ5y[<+jӖ):۞=aubmŃOtIv-f!@y( Fۜ0CϿmoffATiǙ9'~]7Ԡ!|c}$qjE:2HsBbɄVkr弸E6Y2id7:2y -(OE`&02bȳч |F,cBPU-rQ9Q$^"tB'_'vbĉ^sݳ !Y\ywfU_8ԱgiM&'m #z|$Eo:bQiHkhEV#9Ғ%=)oԬ 2da; {ݯ:pa~)K^\7_C0G4H)<+%ϧrʕm~W]tuٹ㐕?H>R:$:۠9]$e( I Y I$ҍP,^I!?|r2jf>]J֍{XqsǓhe!t}Ÿbt4N %NE208y n;S)RB 4":m{ai4X>-EާBp)K\;ĖdcI 76"t;ћ 0 5erDIJ31l|_#ލXD!3<_9!FpBCx`KIDTN#md_^.&+م)eY5LqgG%ysN({'NTVrp6-9rKcEg#5aÆ.m2,sr1Q5/ qf)T"W$LZA0 $D^G 8xVlRSH];S%VID&'i7߱^ )1}YL{}h3#~Rgw!݅&c=s [|@) uK. 9BU/@PW|IUqTdF3q!˭:#9٢n_! i?d1xk*y=ǓCz&J!*18SJ7C q߳S &Zi1.bwWB HWEv?z Ke x.TaKS*r}dVHuȟƭ wSP1-!?zfM wUJfL@FçUK}{oWؼc_\,S`0`lm[,̅ԑ!;߇tc1,Fl,)<)̖Y}~&)R5 _t@!ĎYܪJXN+FfoQԑ8/*y9* tRۑ#Nͅ"?U)nE_`ގOu$-LkΪyZ)PiPRMh̿L6`7ӋLo)37YqbڌhJ+7 Ny1'Yhi~9b4đ|7b.b\'Yxmd]i1 EcxDt~ݥ ]SNw 8; ovF}AC$@|)f;IO3|7'U;3Y"lEBOc9o&~,SSvf[M 1:XE+O=+Nt#ؕ "GCAwT!*'X/hpL>e0ne]wi1xeuyEZ;ӕ:1w#E*=?r!%? 4i5 E0g<$r&P>\+v[saލփ<rC4S߈%n> bo0Lzak(~,'vԼZR>DInh3MZ^qvrSUUcel*;^ xF2SŐl9=Ҩ Tǥ 9c G<.8,52R_nȽl-ߧc'SߠgT,룫 ` R7Ͻ^lrɲ9C7M'^ ^)o>O/=N'N[?ʁ|Z1x6iL hzF3dûDUkAl% 6V=H'>|%R9rPޛSeE˨&0)HsP7ѵ\ m%-zw6 4n§y./IPY Z2aϓ-" ^{N`7liA~PÚ90#': ;'nd&廊S0WVEs=KDž5% OYahN\NqW 훛=)s\H&''jNq4R7ϳ3zs Ԡ5׻8,4|2}j3/,Yr{(?sM_v:t}l}@Upଉeb~RJ qU%m)M "^1:A!~ع8`9 SۂgcKLhWẋ[]A2[o]1yX̤SVݟ!Ej!=SvZ-5h֗xC0:\ J#eva͸z?+A)N"^wn¼)JQu$E'-ߴu:ߘ[O͌9J9#/>ibd0IhBF|eqB}Be ʻX!|G*Lc YZ