container-selinux-2:2.68-1.el7$>^M .CE>?-?-xd  $ L ")+          0 X     ( ?8 H;9 4;:;>*@* B*G*8H*XI*xX*Y*Z*[*\*]*^+Sb,"d,e,f,l,t,u,v-w-4x-T-tCcontainer-selinux2.681.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[|#x86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_typesif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&?R|A큤AAA큤A큤[|#[L[|#[|#[|#[L[|#[|#093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d37e0c13396ddc379999bf51551c20564f0e280300a625f2a691ef2e11a37595ef82d3ea6281deddef1cf257723cd963de762d45831f34a25e2c20c46e41b9f8arootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.68-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux        /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)sedselinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.68-1.el72:2.68-1.el72:2.68-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.68README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.68//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,XT ]"k%u#qXPNeR@Qk{=p]s;2yT?WW.Wcb)UmT {g%Pҋ IC4IEB.V6ajygީz) 6;^ 8)OQ!N&Os* ),mrd%Xl$ākQEcvc\P%^oV aPb_ZrIGuOb~D('?siG>.ynN_c"ׯg=IdSRSu/t|s)eNRM*EU *1R,YksqW'T&tD%ѿgI+0;~vA:`!t'BtLB!(QP[*Jjw,4,ZpXl~U%#\͋!SV y&H0x/IVժPa K[r970_=2})g;U? S \UoP#@ hM~[G>6-% q;Ɇ >˄CWf igԸoJm Uf X,x bȵUV&|z↎.T t1;۪@yl"xmF?]"|wɖeĤ%xGT1&E4TQ\v_>69wLi++%gZt (*?_-BՒ}GyTہ&;ՐͳRpƉ \Buf. hb0gm3f7T"hPxXG;'c&|WCxSֿ3ynkTm# &P}长j^0WO+c#/U)J Ċ$Yf~8zlRy~IRueIกV(s:\Fָ=%ƨwߔk*9#v]Cg汻q㗝) KOP3p-fwQ!&{Oufqw0ὍK:h` 2͸ZZ( ̑BF ],q|D>{[筙̑~q\K(+`MQ MS=r$;1\~;҉LQ΁۪8u1TWQgIr4j@0/_k_x9r9 8 ^8xi6 D cע65N؞N(ڹ=wD}_Z|L~1m/(> 2*&}K-h:wTt_z`BUVi|nފ svDȘ7dc܁lPN| n q͗D:vْQ*9eΡ}~cq0Q~" zvȮR5swŕE2_OonIM^k˅cuBLrWyNL>net:(qҖcB~lFkxgi#jO܅|=wohp)re? 1I/ !T`j=nYuu݂Tvew(tλLd S(j$ֻ\)[֣cmM*8Wɨlyrn# ݪK5)[̆ig__(J?Iϡc;zɆFKͼ!3uJ*[~H-9{{B=lfr}_ބb"$mV?I*]aFiJ bf j([1\jO*,%olLJy 0[z f%7̯U&:8 ̺ Yܔm T"XT5j5Ge(\aW2 mi[Sr|;3, ֠QƔ7>=kB X9Y&JLЈͮcy @b@<g򄋳8.RCbs㐱E]JߎĔJizi7vlک`Q8=;(ުiQm_YitYfpbȟ~R^Us De-J*1p3@_9]wF7dDUGo.|:Pu k'Xϥy9"γ(/6wA-ߏb_K,Q{#"BRf2$We $4̳̉p;YP E;, ¯ 1Th еlmj#&N4.`_359H|q%.LhX+ޛ . Κ%A޳)_f?~ⴸpzyט#llBL "aCh9h„P;f(~ ІyjPTpgڳ ;mDX陞8QӶpPi w:*/sIXPWn7D|,Gt@? /;9/'癕A# 7{E'I]"XY],>/jGc䭋9 {fMUtYWJ(^2ARos2@'\bx=e-G`&tv(2s[)/$}x͗Ȭ&>@W\bv8, (5VhtKb*'9?4~Z rƊi=^܃es[obq,HV\=5 PnXp^k`5DisU}|1q L ?vHNzPEpJ# y;g})ɍQ;^| 0b M8Xѵ7, pXpvF^n}%Es.JswuNx @]X{{)V_#_@X Z)  8RD, d]Kq. B [ 95#e%PBm8A/9ʊ+`Y+2&GCdhQ{@gƂ Pf#%=gr"PQTцtnEQ7²TCIWiX]>V?wͦc9ͳ&λDIkqw?!#ٖo˳ahT2ЉbS^O#Y] =ÕG!gL D^&5;ϯ#U䳫!z74EV[^Zd!">4¡|l\M4`U4nxr~KDrxf==^D;ח8@v֗:a?Bz ROT 9H8^ mcnc-ntڏe7Jbyi)Osf Sf=%.u.C"ה+1Cp檫\GٶlCyǵ2A]+/ RR)IIm-0I= ^  $8xLꕣ?mtl݀dici* \>M{a7(a%NBny sѢpk'nIwjq4Y֒ѶI.Ҹd>hjNs~0r)k G@ ؊ 8S1d @ ]y[aoCck8mkz䄅]W# &61z5ILauܣ- 箱! "r F9e@!ohHf'((¾זР~( Nf8h@dz316Bc"P# j^VC 1QG -RKg4S.E+_(a眔I;CosyyGry{@RxUh#+*fC Yͺ%A4sI wZ2xȁFEćK3yf>B FBНWO1%UP0 Y)Q^p6~hq|>PJ"y*h+ )KX]w0Vgojxm29w!\f8(ImG!c;sԑ73TcP)=`'ll8qrC ]{i F(Y&hL+߹xI:ZX.Yo&_QKFh8BQ\Wb^AHeLu޺ =#g4O!  Ǥ)[2`iϳRB&"!W-e8bbbWJV?Jf8b J9(*dSS,g(T9-5g dXqȡ*}xP32t'Fz"#y,gPKfpaa:hBUrlc\ٻbp\ЎG5=k9J\A?]t|Y>EO`:̵v}kT $Ǧ.:55QőH.,?/N%F t=zB$QָM-V V6 ENi\r%ًSqsv0$!{ ɥ4+%g_=?7;.9=}t*7>o[aI!5E\٩i$dQ*oyQMmj}:`*+Z#:~nHO~^: Qj`}t2b änUEޟ:bb |L +|u1X<ǭZbaQPbѰvnZ|4L~MŻuoՖ{H/OGI8w2tqu6ᭊO7GDQ ۼC=ԀƠJ+pzHdh Fڀ QBFOFnG  7 zItLMl8u訬H}Iz(L}u~P#R+Cݞ JWtgTFt/!`a}Di!`}kF|ީA*@E5DbV_ LY=&^ vTCe[ bsУ늖NFo2JĶٚ[bm&k"  ![o>f9cmİwoC6JGN;xLfkn CSypFZL7M+%`U61{3R(-/R!_R~ NkML7gE>BL0%-p,oĩ=> v녈i=f{?5eMj ^[Q5loҴ'j6yLMnOz"y0+2JFhDh5i1G9؈o7XD4 d]sq`;'vDB-Z,1UJTQ"y3LW C*0GƄvR<ꜿY?zbҕ׬c1pۢmAH[ήFzTS#XGo|^G*a ^=//ڍ(Y&&z뒇yDVuxβG[BlYA.;իfK`5XGrjGI˖"laaevq녿\,RAmeܵI Y!=v#պ~)FbVXfJ&:Ƚ ?I?)Zy 8a{&Ҕ]@1Y6)>;5˦ KMP$dV/G<[a)/zq|+;ubL`±>2H-`IE }_a|y_7vȁ=I?j[Rc_d<. iET6ϬKƝnE4ޗ+2/SP>O!{=45h"E N$f\wR6O|7ޝ'ڒ$x=ր\$&`JYtKJW==}H)nʤRrX8\!Z6(ȧ=560}F6Pڻ}k@`f('N9$fÐ3w6~z`|{:XZFgځ̃p(ՕWW%uXvx#~0 Fw{ts!-F VA7Dwp ЊL\;ߐ"$e'6%]/o`^f5$z|. j)h|Tsׅۻ3fR)xAkDUAƏ]a>}4'%~?X8\V𭿔~9 '|bfPsk 8L%#L4چz:~~omdg2Wkyz&: }zנt6'weRf^AYl^ KrT$6,Q8RsI!1j_ja 9!'`, !},Gݮ@)ixD-c E lF׼7YƷ^.TcՕwC ήa3zÖNݞ`p ¼:naA5QTHgQ[*BNpFy$ O4fm KϢ ?L{}'Y-'AtEU2imU-暢1>Ͷ'2v,X*20CkXz6A!P\*' ՙF.jԐH%ѾPecq4Yuȥ\1AshF9ҳX< KF`}#qW F=T NΐjY賆e3u': izbal3qϹ L"9 =;8rmhhC)Y%h up77H9GL\c}OaQg :r!s|UT\d;$Al͛i@CZG~uU)M ,HC=&WB..1x`d(ƖTD>e1 tPE}svu K~Ly10nK. y/(eTvz8EfJH^iE F/ +X[5O7mͦ446?U_23QA9%5;wB6 Qb3 cB(־"_t#Vi"v1+ 'QLd7ʋEh?j}U}xežZ {*-VM鮳ɨ_jBr.<{2#p5~[Zږ=л{ TN|.J\+`ZPٻT3 |-WP Myp}O,ܔav Zm(zyQ'dP)lrw]?#1JmH~y@HN/Z˜]^ͨilhiY.dj}U"593N\_.2 =lF[- 7kusflŴ4 q^ THKٸ]Ծ,=,2ys4q!,HeL?*#1|{#{(zǞ + J y5 +ج#4Y~C0*ܼ LΠX52 {-ϟ-dD.ۂԖڼVp>藱gjEC-h*&gkK#|9u+Vt0|I6U|H>#trKjUT኎u+9 QZjc4#'a34;(ةMvYƙyީUB$eٞ}6({(\B%OיZi tq*n>1TP j}nanp7͉GcWGKubL yc@3 C6(7.}@:yɣ{3 ޻o!r4`%\h˼PէCPIb|6dw,XH"2ϼ*P~v,VFYi4`Vƭ稜&|HբxPkO(MC9np8C뙟 ʒt<l 7ށFD$!);)JblJ8~U*v쾬he9 bj ?VQN̞!d^K1r \R[yW% mkrӥwn/G [8p&9iEqb:% /u`|үqO{>#PU2p- tʒ@|_=ǿڼVh ڻjFl4!}M]PADH cTÀe?o ڝ3\>&n3& j3|=Н8ݨ?!F# rֿULG67<9,ϫL-'| [R Ȼ;Gv{5o !aɫee6t4osfR^k`n znuEL}.6w‘.IH_/uv'ܤ._-48 s00#1=,Z{TehPq.=BԞU5MZ{hv}ܐ!h?}+E9hw ^vP+tGl ى:ʬ0+7 b%Rlqf:IhV brD+ȞIloQwg Zdu-5uun3hsɼa3&בL$l+76hyDksiMhMyxt(f,utEg67֋ 8@1"C"B;%D} Qh$?RNT~\O8gLy_D`}=-zdEsI,B"7r aN.Ĕd&P[fs;]>!.kCt\C=+q1gҳ^{!KC468KGPMٌg,ݒ9- ⯖U7Mf<:͵w&'INdݠQd8P[tt$@Kz(HˇǴڍ [Iu[FzGc߸Tny5M<9E{teB͓F~0Si5VRx]?x:Ao޼k;C"B]Zʚh,!eB<Xu"#/weE)2^=QT.Iļ"ב꜓HJ$ .ўZ Z+0@ ?V0+hɇ&p;%ֳ2˧hpC=Q7uKR7VkÅ*%UKOg!\#uGcȿ+9~ Fho/1R%bu N4dOj̞X7}2.,N@`@>ٓKnp+[ ūM((K|U29}f/kN8dL60aAՆ_cYꠓPd7)JRa[jؑyÎRvai/Q0$)fi͞0;RU[lLs|;ee vz@~)CVQ@Oa tKNCKWjPGrɇs}cE-zr>u#r8q 7҄58ɷ>ҳ~Ƽ*nȾ!a$GL%J(o}]y^wZ=ša7墠dbݔ*¶ܐ 6OC,0oZ;lOZP7';_;`|_%A Sȡ>ļHo_-t̪:eB]묿ܟQT )j Z9ی<攚Z݅C\.:#c3q_:\0y͐xŌRe%`3 %M>DRW{0XA)$K/#LDNo|̈T9C] J#fAd a/eJC' nyoQOMnY<'W6Z[$ \`PjހtIًٗ퀆^ly3DʵkS" .Be h2d18IeJa VYZ*A]*XCM9Tq-<0wE+N3^u(Dh2CfQT:ֳj_#`Q}naQC5k 2}ş Ɏڝ=I2Z;$i2:)LIw%hfQ{l(˥œ%Ea_FGd7$^ NBy3O| [G' mp򨽅wxŦ㷬׳<6+9oѪmct8zxSt/`', |T2#/"\`YoMݲ. -@RV`~`gRθ&%SIYa0C).%}l` tÃr[L} y1ҴI@8z JږV_GZ6ojAYZqjr^seO يic}Z!9v/k6#~RoALF!?>N-]w>kr~4%oUI ؤ7j2[KWYy2MIM Ts]^1 pxSv䘑DLz . cu"/j4HPd02c KE׷Y`wL[R1$*Ɍpըa.eO}ЌК% %1?O ŌPNo%avTˠ:O_~QŻc y8nSpܴz#{kG7پ>.djJ*R'b`K=ydYf7—B dxRaLNagycs\_*@Wl_5s5`YK|C_,ܴA;?r |K&V-IHb$5.o12;9 X2@*_6lP˾ ő3FRufZm)<7UE `bBͩ9f#Kb"V C39׈M+ڧux| ݵPӅC(ك6k]}Mk[O{Q`-J[.$t50FQ֪as*ߋ  ;¥}#%̍Di ZM( eW{׉oJT(V濗7 ;#Q u9 jetXG̼0X]3REF^ Vz^_F3s`ԉ>KX\qDZPs(@a<_uU\[봔P2USә$<N\+G) "E.'1i#R 8lS&,p3m[M j2CV/c^B 95A(9t5?uw?,ƊXJ-)Fj.J;ȠX+Rfs"(MDOw&v4@5c-?JgߒFɦz`~.%R[\ǒyCǔ,h L\deRs`:Vo|Wc,n.~5.SE2Bpl$._~2´uFN-sl#L'*]1[Y?PN['Ю d,˓H:>h> *^yc6 #8S4d CT@Zlғ$p%3#ƁPPyo$uBV#0?^qh5!r%&obtKjҒN3y>9~#+ͦ ŲupЭ+}n8fMMWrU⭚:,!iro pZG[F9VfKҲ݌9E 䔳T\h|[W<(f3SO-鞨o ќU> 3Obܚ,F0t~+^l1;Q7\'c9ikKkspen5@߇aJэIՀ AsRVlNܤ U.Evz9D 0* KEY[,žLS]+7?VrWF3m(P9@?8^Qo@x=M* j)Ҽg2peǖoLFTd$tӼ{X=P0AZ>l1ܕD9) :A .Z] %#&T!5}IRQݿSmWr)caVy+Vn-TӨ;6<ıqA2HBP(94^}VLHq G4b]40H.*O +>F#`~$<o?HQ(3P7_-YiEg7+!F9qG@|泯z'uHdں炮ZEQ} c5#i\lQE_gZOt5AbمOl6nbS*SWČߙ:%Et#f0xcLUFpmEw$96Cn{;(D iUvJ&!ಝ-K="v_CCn.EL@m|hh*fa 'aJdc2aXD? g,K ئ"~\^4h{xX:JTA=ؠzhޒ q&,&$|+%e~Ve8}XDn.Q)'|m7Y*>G<}( Xz cW-(5#dB9hE5 ~Srl%(͘&-%2bvnǚ\pHw4Av;H /vz $inmil>BͳΆчb:vלn?jrЋo2|h@ ?+b4D tryY}dYFFJN6yXNӶP:?yO"U.ss-%hRCWg[yXcf3,(>k`4L msi 4dF̏93ٜ&Mm !ǩuW >;hoV(Zř-&+lOPR]QsBǫ~$G)w !KO +iO u}S߰TŸ}aWƢ1-RU{ۿh o]x}䟬D"^Hw2NF3J`yd+{Y{Du"OLdrѨCz?(?W^,s\0]|3p`R%ZX}tc*4{O!@ #D5\سbV=|hR04=.$라׸ѩ#QjQbty tG: "4#Y 5|Z~4>_x({soaQR^h#oFXHBh9EKnMt JG~r\!Ag;^3gW\m3(''$w%a'wF܌*\D jYXQF?8v _02a+(A/u!mC4}J)#{UD~+KE/M~ŃTyq0d<V's`(8{TQBj)AYuSJrcg DSBeq{/+x(U(Vu9ͺ޾O/>g4z7a ^>TnйA;VӀrsnf+sϕõ(qmAvLo ; ӽQES4l.>7r ך`+57N|.O8q1OGXW-+U3Z(:M`A󇼠7ՂRGtL(:[RUYftY {mb3]Wɓ<J\㎩ز3Vg ;f;r>.zy dB#MٹEBE6@N_xinjl]ٽ&UhoR܉eHNs)4˕$8EXg(5oV% 716Bdl ޹}r$b2W{!aP=VBX?H;?AaO^՘ Dp 6)Ga)Ҋ~ )G%UIAy$4[VRAievEiW*A} UhIMp!P2ǯ5^]L T4誔"7 tِ(C1K[%b3ʬq%Z8R~b.߃5ײE4ܖE6a!{Q{-5Yepj5w5T^(”&+<+r\?iᑍ#xfڼ^%oFݠMp&FŵW󰰝%sDI~ iݢϰ gSƾcCȻoB蓿BD'',Ԩbն YZ