container-selinux-2:2.66-1.el7$>@ցG8/.n>?+?+d  $ L ")z( 8 H h  0  8 X     (  X  > ( 8 99 t9:9>(r@(zB(G(H(I(X(Y(Z) [)(\)@])`^)b*d+%e+*f+-l+/t+Hu+hv+w+x++Ccontainer-selinux2.661.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[Lx86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fiif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&>QA큤AAA큤A큤[L["T[L[L[L["T[L[L093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d97d35871d6dcbbeddc0e5d72140fac6e392d5576c1c630518591023309742ba4bce007968a1dcbdf298e23d31891aa8cf7f8c8ac3db92be4206acc5e8f1a699brootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.66-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux       /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)selinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.66-1.el72:2.66-1.el72:2.66-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.66README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.66//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,XwS]"k%xĉNμ5#+mz q{@gPȃFG=uǝ<%Пv!8)级}og "J>UX)l b'Bf7DiWW~'.ߋHG~TwMwoj!&RL8.y}i:y|)B$Pfߺ3u 4 ɑ6 5Wmh,Q`]U";*O}Kh4+ ܻSΥgOvYi$+TLf1p.M*q'Ǚ'mHX#G:=:"r4?:9>mk߶- A,7V!bcL1T]wm#V! T 傗Mӭu,Ul  et0 끠ʼnXT4CYBӦ5N||T $ $m\ׅW,Ujʏk2HxɰkcF$s(>wƜOv&)¼-ތ4n382^M T%װVL2k (< DmO[{\)>7?7n"6}jT[,"&}%]E4f% >I ^f>2E=\He{DS][[gT92ܺM $mA+ F% {_ؕ*/\g+}MH{^?,g_y/Vja.z2%uۻ7KV>iiw ˑ ֠(rk3UؾfnHaX kܕ z J882x{&fB9ywh_JlRR;8kl}rH3At7cjͺ$:`M>b1U`8C4ѣ10gW'}6 RxH LtDK B=jC(սluӺ͂mY |I,&k'5ȀFqϑa%6+E1qz] /Ĕ 4\4w ]Ş8)[4XF<{{] O8aYSʻlG0 o*Ј%*>=LJٽհLʋa dgުnJNgt6_WhԯqΉFr7 E2,"Gw֑{eMȚHܾdwWs&0U3Mtv5ʙЖTY߹ceHS?=!*GOtܵ:[Yuxf Uލ"=<ޔcnՋQU)[ﳰŏ=xl&tC` ZT 5?oola.V"@K2Ё-uΫx.!?y9^V=Z ߱rc*NRFuvU'Z^ s Ug!tFc~TYdJ*iX:S(LMrҵs}z(ž:oIRӑF:$,"MDjo)̤4]V#S_0~ZaqIμ-G 79g55kG׫S!ο?y{sNLɮ +>EWw;A\: ܧ򸀱uZzXB+W&7@"ӵ^[5Wv7![9opG{2>bP;# iD7z d-43wF$\Ez,H y?ɇ>x rU­.!Ws ~ lt> |`͸n0 yrnMle' MqDSƋ[ҐlfEДBtdB4mu]6'E:yqVYvK{%޳'O zn 7D{ryv|*ۀpgzΩAA3Z*v;:@w;Ppl{/8ef\$] WݧoϾ2mPtӥЮ_K]% PEyޣ\qU8 yEIRB3MSB'QZlvq"`nHV LWW|Xq~ &B JFfzE;&PeƗA,?N`V8D7UH*Oi "iԐ[*ƕ/Dϊe yV[Z 1@ nn==NC\|hV% ZF@f{/]7) @/ cTv*<LjZ~iD'|=Q"O0'*6`P"xN/Bm oW 5.{TfQ#30ZNU(f}s) ޙt+HF@7SbB bny?1QQY]qXp?p,J~8C ;:ϛ(F)=c$4Ҩi(ERUe_pV+^Uf".?ֲͽ=`I|lY Pn6+ @Rcie4^ j\; );%gV/; v],.USL+\7<%hNnm\GSML6N?ĴS(+ Lb8HёZ׷cTML_o-%6}MJ/?*R"yҔ}b`Re-<`CWV4Ccro^ ȧw!\*D6oC86.Vz? $/ZR`wB[ލ2 [Rtn g Gf Cpn9Yt24es[5xaEL~#8PoO6IF$AH0 ORKEϡlyR\.%A  ^@&JEҹ-436=|;~NQ& 5^MճB)+f,iG2K"_.nO&+"r! v 8^KcBKZ?dE_ҴтpeE̬\x߿{ş[OEx4+PA#qVAP-_4BcJڪtJ9Py\czLfoI2 mlU{lu“@@r]e݈{g!$m4lޝP܌BPEm96e"B0` eTq BrE\Vz5<ގ01+Zݮ]C*CV*6-׷`E_k(]g䪇1?#˵z.tm/ D&^O"nr_ '1%A:r{'WOL޳UZ4.";P쑊A̻B7c>0e͑0׸,hcE0$k/`P8Rֈ PwfA*}"lFٷC&Mu Kb>4Jem:*z |%TWL&̅/ΨDtH-TN'Uyk/d.3q\r I|=TG<ܑGoZL)L Sڍ~SĸG'5zOo.HMBXiECIhVp@~`*¼C힠X%4i84n5e/=1j*tVe-=d{72ɘH ꈧ/ b\cpihAEcuiub% %B K!ܞ&us9Eh&_qK^SJyixsZYHKש6KMקʭ~k ef(&}/αtN; ᫘> 8BG Ab?I rB}\6u-ܮ$܋D^wUt+Gs TZ%'!]јc @;ˣTj߸ Iz qIB!Z&-cńbvN$8 p~sEJ3њL:l8Q8@J}Oi v%ހ4etY܀{x-]e"57JG!+6v( ~gAі _F όyrH` GWF<ܾlu~1A;d"]CatF 'ߠE <#ZubkF'φ610ً% OXthE+4O(W_plWu]O w88b"R/'{&vV8T F#WQ~Hn^ݜ.kb!J>K pʫs\FjTT.(%[ʀbP%-xB0C @~Y-gUN1p$I&Qi@K,<ʸa0iPLuEŢmDa~ j f.iKd ({IX%l[ odU(`m&6_ ~%HG r \q78z!"ݥc5PSV#4}0PR)g_JD&Hft;=?[Whjp 򘾵uâu3 *xyC $?QF`OWLfh@ޅ 5ǿ\YҢ#|M/c\j|+`" h/Nr $mnd_+P6`%f˶x0VL4J(ȱ h. _u$.ڮ{#GRS,bM+9WOX//v{ْi KE e*If*x,qjb``Maоm/%I#hB+SBBLLRFsE|4\=Ȉ S+)ڴ`̦DI{e<]9,.$LiFRnK4Mur4TQ4ċ8PHJ DD̙v>f)$)q)`=ߡvڥrQKխaĴv^,iH3.&K6#\*%xx8 Y qKɫջH(>4Uqe(Dٌ w}u+Q |Ĕj)F0= }\^y2坁[m#S)q؄ Q&C14{JSC-8j&wG:׼v 4~,>ڋt)O!ŚD6IgTy[ >SV)KcXbGy;wzS_Tu^EFV-/S+|"oL .LoLUCGM1;8S^JKYu=*U,H./[cǫ޴4HREژ3o#5ßQ"#C>t|acYQSH 3sPe}f\fOeZKrR-*JvʹFq2̲ٸ S4-MhŠ\|U"h~CTq@S e7 M>eQA'p ƭ\O-Ǭaa~P;_Q |PAJV64n*"Agi mӧk3q AciWh=HWј-M(gB%;zKǂdOCE"C tyH)K&棞4_*bpd-@(k ۀa֟VQ=Y!nbsϭ#Z0z~ T%Y~ LsH p#.܍-oo> 9x\3%@_+յx03wЄ'oӵ|hq=BNGuhREd-0tŋU{ B #>e蹮e)&#n0$0;&KwG;tq |gz@hߗf0_W/hto{w1%)Z 3[uJw &ʷE=7lUS5 k5E!l ?^eYm QdQ**H:AZ a tEq0#<5DR[#Ǥ7poe1?S xqfrZ&B#S^ }rRTdcM"V+6g'!gi0bVǟd6ӨNi1Pvs\Mk'Dt*yŦ: ;D¬*4O;>Tn_ ݮvr)1a19S!;(YF҉P8β5z]fٕjL Zcd?`J6BjXnR%_EgTJo]L&f+8Wdi_=fɩ$?;F=:ɣ=/,Y[F9%MŘHBUZEOle[vɡ^]: T%y V>YMNl+%6[5l._pXHZArw{SeUb z,\Q%ȱg-ZB<⽵G:ėb_ŧ PTVFR|;Vr*9}5Iq?:fkK'[::|"śٻ{D+rpy&E,5d0ă(4@s>px*OJX/ F+./'Wr|Y> (sbѝ[ŬfS@j/y[*nޡPJm@/"Zxm{G;/F_Yx6 $qF9:ubh\'nbiɹ0vJƌCm(#̦}~J3 <.Iv85Z:oJsm"2y9 Y#$F{yz(sźp8/6{ɑS#sOrEaa_UW9e&x_eQ)=ԏʔ G/巿o{mm[ʳo Z#|Klyq'4%.]@93&?ry4D7$k ?8e DDzO¨|! qH,Sv='br;uG $lDMn3áW8 ;EGɗ~ߐrbyĕlb葶cϗCa@0V"LCJ5 _eG^_@4G,QV62`tZ'(ID@ N?vy1c6>gFk:DŀߠRI 88;t4!:=COXBDZmV1!<^p^ ^FIiլ=98f҅M ij &{0ЫxjҖ~#U'qvg{*ʗiLJGa.X>`h8}4 -RkR_&N39yp'3Ȥ5y$Z.1]SyQx2g͚Z%zW끦eeQo) Qjp{2vZ/-H6wWv-O,݃ _ i"<(4V1* 4Uuu&؇m[J.>woJBi{aGJӓg68yUXc3 qTH8N|଺`)!p>qӒ`,`7<Ďk"ru8y$YSsE8=efbFc o֕aqy(MVTT Mz$'3D674NЁnH.9 K%X5xkör_K};xl".cR?jtďm%r]]$w WE ?'5JS[2_z .ĎS0XԲH0,X2`❩{+ +Sȵ|M_r9-j H -- o2?)a) dI CO8/u nݛqBl m8󮶜AE~0)Iws"Fg,W;35r>-{I7'AŸG,>rcyu~ta4dcd gWtlפ6;:Ryx!)^Jק#q6`/_KP-3x"_iTHErF]Lɺ]xgPv'Hj_Who 0WXYoY\be;#usZdN=$P #Gt=PX+3obr%o=ʗV :pОR;vXS.b./ٓ EjR06Ӱe6eK4m,E@dt$ծ[sb7#.4,"nijTpxC>@Qd,|Rc+A3r =GZ{1 *Aȅ"QJ5̸x $k[ȡOB{'c\âD@Gȟb%-8vYUavQ?} f2=7BX Ayw*aFh=(T$ILOmI_(c/6[ !!Ax窭L1ub 2bM?r]߉~YNJ!]oRxVPW箓G@p}5u-_6'3T#iƖ,}tto>sSG8Dl9㴴#K[&[*VW%AI+j(U ^xnwO !}JT}$]Le>ji$qʳÿZ=֊{zBА7㻜Lu,C vF5ܗ%J2]"ҕҊ_v8NB>Jaͳ\agوW{ivwTs~maEQTJ@8M#"g!` ˠ]PxvLi% @m=Vv_.MN'|̲{9ݸS(ȵ$w"C}8D]춵.<>bQG V+>LQ |Tp2pL1nZ1+jԕwM*Ĭ /OP9Q/8hfMZr?ȌӾLTʍ tiFO Wg حکTyMgV% .AR-FRI6t≼mLD{QP>-?HQ>=kY{ aJn72*-W\ j0 tU|A'tUu Y;[]_!=J A0ZD*M_kCԖy0qG>z\PE}_,|cbsȱ𑄽s, k;.㮅We9`L(9Z6Mxm^} #J_,FR}cfhH1[o:EcNYjtu#I#߫n>gC;YvE=93\VDh\tӻ8Q;'ؖ9fJq}}7O X~BHRO!>j`)h7c"ݚyu:bEMݣzC~F%nud.k_dWs:^@\f>|rlX6$s1baeFF!%&= ~jy,8>+gv iŰ־6>STT`EX77mȗk' >:Qxk4U|0 cMo^+8h 8%xH0LNb3-&3>'mxbuD0XNTy8~l0J>㵪ySw=Je$`A^bSxkzl4Sdl'pB@ D0pGp5d#=X-/켻s+(4&*H:LS;/ѐŸ;'N_:g]&Tt-CgS*_WI{X/(vZ.u>j|»-*Ёq 2c1C;ꘁfqSVh-Nظ^ۮ1>ݑIVA0Эq_HnW z]97)ۼs'x'کۏɜ6VHEOZEH(in8wG1 m/fyx~ AΫu4Dr_ü^}7][Mx>ܫ* ё*K|:!-囲 F'чJ.y7tiU?%4߿@a}|lBg8Ȗn y/)`"9d"%d9غEkgff Inj0ˍ buK hK[ZEc탴Σܕ[̮ӕ;l8k[25K 8eC:1:j 8gda A:Q3 cܫCB`g-[{ kZ]q(Oj>f*#6JI l[հ[,MsJ4EvXKPhH" F4UjMQt|27n g.=6[ME#DtJK0Sqzq2]钾&J)d$c_SA4@ފy0b?pSn7% bxaG֤|%p¨?W_3Q457 a0ݲ!R"8:hJ/-OEX ߰/=to\zZ- 0i/6n*0_b-%>8~ 4hOLb'_#-E f*oXhh)eT4|\34F8%)陾CXmLk07:2/_4Bt)p'F>Wvbڿ#e_ ч吼Pm"S˞gPU8K&C9itQlK|s؋4f6o4^@RVˮ˾ڟGϋnQzl0WPMM>H](qQ1f L@h}vWVQ]q|ӑѤ [GqA*&hd?-;?}{ڦCr;t_yܜBT[oEpi{D_)I0z&7 3c2s͘&$]/F^T⾨*۷DsMQ$CFZ6&r<8PC`s9MR+Ty`)m&wV]&F7bAq>!֢\l(e3H-b rZXp |?U>JP1-x-Bc7}],l?/ ~}( rwy2e{p<A8Ϭ_nGȒ&lW(JB]/GV0p]wmM::uvs'*d ?Oj=$˱_ HC^3 O}aa\B oL']c)s?t{@|.. 05߽S%c2x6uEM klj (9Uz+V=}2"=BҌ|WT)~z%_dm^ΣSg'`U8 -.\$.3tBF<(Zgsdi 蜿 Bp||8ɔ{fzRCq<}G$vA|UCI%ae5"i'|Paqz0B3HػDL$M# ;M ]}\L7 srÇ0q@Ƹy-Ҿ+gxo:I"|񖌋=$ܰW_sLgoKAl赋qsX9h 0PQ r Ǎ+HbZ*fKNQ4IB]yLqn3{mQ Mb. I.  <0uAcC´V]-,['D6UE[b#X3؞c]*X{#eȼ,"zȠYTg{ԁINU#'$A& K@Uord-Lq00B/͆ז@^~O&Vai%?Z媽'Zy9RݘlbI;94(c|52f*Z媮~-<"ߴD.< ҧޤ7 9V2@oǃx 2Exs7ix)jINC؅/`KXu,LPz3hA-(!uF5>}wST8k&x~;;?;wYlD]jB۸F0"q&GlH˄ 6]! AnmM@W\'1~{>w,'x]^WSH6H$mch[2>XFB=pէX992^0  #~aRq ǵUQh}Ι1N/+qa}_NMZ|J [Kw9'G6'GqRq~f`LI+"V7d\?=Xt3Ya%rbwO1-tz/΁frF* Bޤd*pMO]&pI~*5^ {xj| Ҟr{ĉrrNS u mO0]3!ҭ\cxb#@=5+.}}$BX|YFNP}}唇^hYABn2i֍U1,7H5l WÜtCxPnUJBc~{iToS ANz2HS[nϒ' JKEKI0X%sJ'eM. z!wx*iy;U)%7~^\Ú sXqWt<90m}סhӜwD4l@J]I~  C{^SO-~3N%D1e 3̂5ջ60gt10qC[0YkHܦ'wh;!m$l re`'o1c"3׼U6zcҵmIӷ] 0~6} 4nCTA (k4)}ݝ:N{W7pkG; Vl8@v xC `M`䨯 !L^z6B$[Nruară Cm>pC75$J^vKd]hfʼVJKY,ߏ\4ڣI5*ji6K"/yf5{Z+{]>AĔri,lm$U((V6 -"KYg/~.T[v.5Rp(ǑQ* ^Tjc/祪 zJtXI3+nʿHgYXX(g{1xMb.JtJP׹2/+f)DhC$m5>ax|ϱ80h̢a/PA" Kk~d3i4p5a=sҞ?M:mS(ƚ,\ݖC2+_u/~T%DM{;[`@"s~r1\v83ԝ#mxnpQg|_).>Z駹',ޟg;$a9KAtT37E88PHn_%\ Vgα+v|<].Lc% 1sY NBFe̛N>5|(CQYOZu&/^eb_Pj9x$JNc˫-I[vuь\0$@MՅT%P ZZ4;|;kG]zYK_66+LgFY zP0?{)3U'n.X)qGnqO}n3ECO,oGr^\^;)Ri5A89ǨP,7IN<Y.(| _/]~]8kSBa[+qoZhJvU/1tI~ /zǮ';@L`bz=8Ig>_Ц)'Z0|H )_()Amz4K$ŃidGb5Ion.Hb^+j:[el(7ↅ-/|_)Qe9^В;,FL }`B'' dYB"j}h@"> lAE7ad! we+? Bb^Ns8aUi+.M%pqG}. ʏ[ "T<ۑ" no֞m%?i[H@#s1Bh$_N21M\Ῥ㸖2"᳸q>VhWQ5Uk#I3>Ń Ea\&[v[b W#|?r^ze}6]O8zFn@?Uf)#ǣ%U7YWlFwz}9|L9?MN:{0a7PTULI0Nرr56R!WϊwHt9'dߚԜ$cEG'E-P-e;jNpc{FETwJ=`O~3r~xxDp R<J<=nYL]^