container-selinux-2:2.124.0-1.gitf958d0c.module_el8.3.0+569+1bada >  A _ˡU]UU?HAw;!H;S*.&ԉX{>wsM`uC97Z @J1Vƥ7.,c*|fq/o`{ nk%[9k}lhOy;] 5Dw̸ۨqCHRmw'}A] ?Z=諆 ?`WK]T^/F .U'(Apzt_߰l뉂!p,|nDo3PDZOw_ pELuSWnSLZUc,I 8T`fj,zn9$Kw^mTU S]yBF3m 6hZҀN9*ȌV'(Q2+ LR4V[F6.ԌK5 6OYRTWs}]/$,HopE],hxQ]OK ˕ %@Q#4ފqz压|bKY!Y݃[gHvCXkK-e{pdT@bxZh- x{d 'RS@ gUSgqcƵA%!ѫ19euCא=ze9,Gb!Pv]g/$ť/]]& yM9oiABnt3:hz*TTa%t>pF5a?5QdH L t >DKs  ( H     8 `    , h h( 8 E9 E:E=.>.@.B.G.H/I/0X/8Y/DZ/[/\0]0 ^0zb1Dd2pe2uf2xl2zt2u2v23444455 Ccontainer-selinux2.124.01.gitf958d0c.module_el8.3.0+569+1bada2e4SELinux policies for container runtimesSELinux policy modules for use with container runtimes._Xhaah11.rdu2.centos.org@CentOSCentOSGPLv2CentOS Buildsys Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi)LZjA큤AAA큤A큤_Xh]#_Xg_Xg_Xg]#_Xg_Xg0389dab4c8de315b75e65f20f4e606a015aac29056e561d6f7cb6aa588f431a9d40cc7015bcd8e803bcadea70e0bc08be172983ecd62b40e2225c5d2ed2e6265f54ade403b22e2972c41a047dc8a9945271a360efa4957ebc1d50d96f0b8627drootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.124.0-1.gitf958d0c.module_el8.3.0+569+1bada2e4.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux         /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sedselinux-policyselinux-policy-baseselinux-policy-targeted2.5-113.0.4-14.6.0-14.0-15.2-13.14.3-9.el83.14.3-9.el83.14.3-9.el84.14.3^|@]߶\@\M[[ͻ[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.124.0-1.gitf958d0cJindrich Novy - 2:2.94-2.git1e99f1dLokesh Mandvekar - 2:2.94-1.git1e99f1dLokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- update to 2.124.0 - Resolves: #1816541- rebuild because of CVE-2019-9512 and CVE-2019-9514 - Resolves: #1766316, #1766215- Resolves: #1690286 - bump to v2.94 - Resolves: #1693806, #1689255- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.124.0-1.gitf958d0c.module_el8.3.0+569+1bada2e42:2.124.0-1.gitf958d0c.module_el8.3.0+569+1bada2e42:2.124.0-1.gitf958d0c.module_el8.3.0+569+1bada2e4 2:1.12.5-142:1.12.4-28container-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2noarch-redhat-linux-gnudirectoryUTF-8 Unicode textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-85d563103c4b364306701972743579ae67565667fcf923746b4056cd7435d5f99container-tools:1.0:8030020201104065729:2a301c24?7zXZ !#,scm] b2u jӫ`(xy0{^1NgXءbWlCqFp7 W֪n4% La,\@[~^#.ܹ ~KW0gNMRl&&V?;K%Jy!גsEXi{1sT ϕG|4 thyA#^.֒wjZ9Ua&{ũ( 0v.{L:eH|eOp(D0-*~toahVWLj"}XDOG E& a 4M fz/1Zhg@q}ꪐ D5y2r?#)sxAqK㸘k:B 2\ #>;-?2lu;{\/=Is7I mASMi;Ü]lb’2PSݪW2$L=- b،n+ _7]J*F#B/H]At?P67q=݀z9 *3< kM2 d obM҇P BYf07uzҖ/-DvcEjDm^!_]Pв ٍF-ԟ- SY`x OvF&SjqlR!N|1rGsa͐@yɭf{g: Lj[`!d욞$?@D11MA_\[5. #.g뾿A/{2&x.KGpAhWfKYEIDqM&HUUdw7$NI5E0'=QYB< Oq; ?UBG/ 4 -L!XU23"<$g˟88aɜ${ħ4?o9uZYl|s!̥"d|`c0gUe&"f*\!ӅծjrKn]ޏ|~U!3Չ}7$>]B>~UDG|a4u\,UQu WPN|,Ґ U|҃]:4E;h1M(k7UfTTr~P)rݴջ; e@"i34엝_F; 0?k5!@XAr?&v5ޱnUЬQ3XhmfL]=_c9?Z)c7htŹE|)RX8]0wCPj1u1~$@Tmо]V,c`YBwwQ//J{ 2S!SowǬ͆>_n\h=wJ=}MxqiYoܕ޿izk١a%Ir-mi\BFΨv8|D"`>K$a4DkC+%8qGA2\F.AL(vyWY DHM^{B';][us# >AMC'Q>f;-c"dzۙ㋀MV̰&=ySKIed?91-NP&U/#d+Ѱ,kӪx* vCK%^:(O8)P(+;M kmN^wiA y1/mV-\s*b]v̘ս%*yE+2u{o n^=-~SUKUFf~QY$L۟6BC Exel ~ ZZ%g NP1qcXxL&F/-9" ~=7'gm_+Udu<)x0PgBAm? O~@sH;"Mќ=\7v')vubNnz拎sPr{0H2owF+;`~Zۓ=苓A!8~Jv>#WNMFwOe1 <˄~11 fX٧5_*|+ҙZ|m'ExG\3-Al Xr @e33xKx  Hpz믶b2] 0/]%MZ-&82 &o#nj6Sɡ0I-|ˋar:q-;u}Ԉd 7lQɐAժ㬪^bgF ;֜|Y}@N,f3WpqDkEj+Ž&ʢ@B%Tm sRl}?i.D."l? F|Aj?\YQ{@R\93qFg5`HgM~L?,Pq[I¶AmZ.UU% =/OF !}/?]EZe+?ʚ?ޤZ+S~oP-r K+L_ca0?ƞۖZc  vx4UA,n9[`1>?߹$iWYh"Mͻ? NI p@_qÙVNя%Hk w~RXƠp\񈹳:hjΆ!Ӗw6?Ϭ2=^?ccF Tb >/i+MF :~/kRDh zЅ?.S` [M. :ak w`q26AquuajߦݎEo;7Qҧ[sǵ& S}`oV ep~"?pMI1K61wìAU,̼Y} X$q*S_SrU-T#fٝa>tPM х)mvnAW- -U )]ʣm#~Gd9UYqy;ƝYzK4?I ȧ$mZ_zv35B$YkK;ƏR]`CvɷseoI"J{PK!:8;1yˀWw+si}EJ1Ϥ@&6ꯨ#\5.lq"$yD4|̨Vy`}pfipߍ W:STZe:a*;%yCY`OƧb5"E410If<˄操о3>TcV p3}bF(5n0JXf>ˎJJc1[ˆX[ze^s=y<N(!Gm!d\\1MFèdߴmV鹳'@z3۪> RA) ZAu\ЏV9s2MMMOu(AId%k/ɼѭ1,~ѻV,`<kX ?Q"[Hn/;ldV~\|Ы 0Qb?KQ;$Am{Oۧ@zy? T:S4!P6Ms!T3 Hl{0 1ǀ}-P1?%9Uc:TdidA]$?P3e׋԰[[ؙ`ռoǿiKl v@b;GSyR'+9|jXd)pe <~ -} ROm{I`ْk!B'#YT d,P?՝$Z N i}h+Pmd]EV7Kw݈&ۺ#=bD"6lU˳uDgIfxo+M. 98-+C &%U6{N8%x 9[ۯk޾ȷR(fK;aMn&5q_q,q9 upYF"?A lVM|VV}ZM,l}˳S:͖k\:\ u]UFk6|aWL7ٖv.C9JOjv#9xj^R*nQUs%OZ1+3vޏ+: _eJꬑdy@2_ ,E\ LD|a} jWظ>]rWgP]rw6:uq{)l*ݴ1kr/%=u N?F jGlGnW#)OWo1hg5O:eOEˉ5>SkKg6^f$;r(!"c 'td{efo%+% Ҿ+TN?B%%wpWۇ B8wL Y:¥Alt4|YQHeQ@#6.L-*<>H?Hׇm.[} Lo>4^`t=) kAUƜ}@ jF߂w_32 :tQ,N!ލ6<"QiC.)MU6%oO=)./n Wn-leP_-%ս[J/r?e S/zک[ԩk" 7wr{kQṳI`eJsL9&`Jzu}!UTs'UPxDG"Z )%?R͢cKZ7_EAU!Z"Kk"Tp}ŔNpΡD ,sgץ7m<:բ/iy1Op{8HIiK;_t a:fe&#*fW̝Zg\*R֤5%r0XFmLQwD͗7)+*yVb/3QNFP6VgE6b+C@A :b` Tܴ].9NƣFzmjs^[2vgNFL\L?[N6H-=>w(Vl֨xWzBH-@Њg`'^/ݭR'&֯Bee&5g򩥇2ho%FCp/N8=fl綌"M4ϠUǔmLqP{fZ[}DsW,E˩\HfyhgW{C;L.eH 9{kx{Z6+&-uP*TB(V<Ş>=hW(LGoj@_jiW1{ |'I[$*(2r 9=۳HgT93oѧTX#>rŔtyz)G1jZư)fpY;_&k\m QP)T2P MDu$Ā 7 ~YXd[DGAC1S2뙤ZFt{ Iv:($, tJQ^υ7~%-D =b>c#_ȏ֏z4 8x$\dB'?%$hBiNqq1ݗ`=ZDm&1fǒWH}1]”+P`׻y|h7hrQ#'d.=0IWIaXt6F_Yƾܚ \'rc=yT&O-Z K;Sdq@pb{TpT%NdFNY.bYPn|p0@9>1 5P328TFoi@Q)^ASKٝ_(h[Ix+rXmyϭ!=Z[^=ޢ\`gG?$fXS<#DPIO0V|N^'5ܷ21'q"4[vHKrsD#Q_D-|Q6O{MJsNSiȆlnCIAtH|cЍN$.2қ٤HV\>/G,g5|ͯN6TR&'.J6Cޯ&1lADSL-355y}4ģWOuoYQnO'þC,.vx.!{V=Ҡdm۴|[F|-HYD|-|͡ tr%XVx+rלxn9fw"90N>kυ0iY=>=Ūj,^,Al{̪cÆF )H0`__5LR5 ͵ ~6ѹ'D(jKA,BlL.I1_ޓHjDey^TJ휠8 "^69V E/@{9{Nt#,mcd1yIVXZJ08ki;W2hLcB k1g`a^^jVG68 UǬ%yP%!(l_S4<]Mfi|Qso:_v^<ڨD+]Qzv F}c\8(7p~% H{P,p>[HmP(b$ʛuR>@3/"7)%J&Ũ;OMk!^"ar׶ƨS sWΦ> SĹ[E1m,eV|~X4c"VR ʑCfX-\6so9b&֚f ^kQXPGqlV!$urTsa[BsIW\ [Ե( ͗A4gBD$ Pڃ$/if_qB;, H(X2u/&MMbN8X峐'bN{$u:qDO>{X:07Ay# 3w#K:h:"Ye7#N^9NN~˞M$zL8j0(#J(e4a{ frMO#YhJ/182֌es 'X/(+qb2{kvXDFse۹ܓda0s{7=sayP8fEq`.9`%Fe?%˭qrIYACj'qa X׭:fs=&r_ʰdt|ΚyHigp随Hk^m C-RApp>4.sAFoNttbsGHٜ^G}%!pMŅ&΅热UTJXo_v[7? b]o~bJ;[:QĤ bJ C93Z/cCӒzaqU2~2,x,Ztu;,@V4Ї(Awjzenڝձ&RV[<|!.މƶԭƕge<(xg(t,t^}VN'"/4?|R(,HG7X5y} S# E_fXS8Lo[98Tf4TxWrC'րҗ6YwՀiE|g.~C_l.q7ILgB :&2-;dbbb Zh!$NX0Ǯ;u gjgX'=4~1B3lϿX䕔\] Y"C %4t "'D86^8DIHK,zRJM[p߫m!6%[~7;$U {8 Q'RE Z,"b䫰sަ;]wYy6g(_լE/s"d}ʠZl%YϴZ4cmg<[A~⻱5[=E%8>OPf`W7,M, Fn~`n[ʗZ'ojڋ ǬCdVlќk:K[t}YȩC=Sw9 *uв|5XS< XM9&)gk -GdI 1cÁO[xA|=a>yT^낵fjϲ~gi?=nQRʃj )EDzdר9rsVhg-K& H]}j+nUػG eYN ;ٝP3˫ޓ3/6Jbq"I;B[5S4.`G[b憦]Rb?O肏/C>؛]&j ]KF٪PǴחnRw^=YA,tGjFĕȳXɆ,5.U*AY\%)vX2t#RN5" Zӗ hkpWb/ >Ȑ^U ǫ ~uPIZQ1F9.d.DG3R;)(_}NJl>XeʭW5Y]c/dC'<$'v" ;u_BQ 8msJc8Jm7n 8SSiu+Ao>.%awSp$`@$Yɩ ǜdzXcd7`.H4z-r{Nخ(O;Ͼzp;LBݝ`}n7̪K'Z<1S7'eWLp@*;n:sKC1 'g}*HdqLCwF*GCZdPfp' 1.Pn^|7D93Ei٤&׽uTy0Q3vwzi<[QY)U)$]ԞM~ԇ5!EmdN@A8 >1E˞\7}j%xik] _/WloԩฉzN(9~*g2'w]T@"X/[>]@ tV)kZ϶`.MW0.|:Ĺ fG]D-[=.rZXߚp&D04Jv}.xf0V"郫'4PmNX_ۊet=w_jWKI 0lUrzswB̢eI ?ϼO%k~*:{dDXu9#OhX%DTCZSՇr 3S8/ Ρ7x?lLM+ >d?Pw 5ǡJ[uBܘqC*}9aS<wwtiQf5cI0%uɻ o.3s`Xʠ+[/xWy('[M4 :-70|,` ⚙uҊ%Nȿ`LYӢuN91a,;hIb4 =ҋQ,̕* ݊*-8y)r;lCεB$ .0ݛuJ^YXjU:\u![xDÖ$ouPh+b2jla3-"6KX8n$~We:3~Đևڮ,, Ȥ=[|+7{JrEo;wԤRL,ٳ nɏ=bBHG .9UlāaHreCW0<\ns RomG娯/`sne2Tƭ `I1QsF;=e!8pyhUs)rIC< WgѶJa?\3GG M԰ ΥOL$lRb`*e!@['.[6UR<9wTL$u|_ PiYZрw@tRޖpLjEx2%b^qq |H ~v~<Pb"U]@guWY%lZBȠ~ѵ z#tQ׳u2&P.bJy:Kg(vnyB_~lz'}ӚCco/Txa7` 1iDb|(G$bYA0'Qpw}NXr5ЄAom|뫊)Ĭusv0XÍ\vc9Q9`AYy3q>!M|+]?iL~'* r6~` yuw| *ۜ & Ѕ5 "Үp,CRFy1ě[?a[MW(.8naJ!Tӭ#o6@2зBZ~?Ut %UcwUg֩DL0%dol-*u_ĄXJ0%t k. ֖xL[(zđv%3B'Ǥ(gF%j-ӄzYZxXWږH MpT&C5&y&.d@olҭ:Bn>XU>N8Q7sF\9d)-PYݏ/)z}"f!Vz1#5,TV1JQDоJb# Z푈-ؽfN4Q _]7ٯY4hW ]0B@0zG Mb"jIK'\r *M ?RSaPU,t\=|.C6LmmB aZkK4eaGrS7 -1$L,2^3{*M.. D%B\`g*1|򑆛E(:~g.p2w yw9J J"'Z*[uNЂÑ15'D-'Y:'|ZsBYغޓO\ O2&VIYfۣw>^y/}4MIԝ_'<#e5͉c:x_1;qfɦ;Z(f,9|]TB|BGщAJl}{=X4N@γqsf)dT -qKSB5^Y2`$a3GKwl W. ^8sWPwo}Y*KAJ8Sssްӊl39@]8ngˤh$ƉvJ% +!`Ϻs' , Ki<}QG+8>]//0wIKVѴIŀptk{ed>V׸)R݉Ce=V}L:u)tjϯ4a_s} bSpq`ZYAq"p?c.]FXPv]Iglچ/<[--섶YRJ_eu_i-PN/kxO)_OQ74NRf zW \nEЅ*{U‹RC\{XbA3v-ul{̻Mq `2@X^yL6s?QmijSofﲍU1jO# ٰ?LIU3 q@Υ2㣯gJ󕝩:!6AwFi&&{Ck-,( H@EץQQ>M uA͇4{3y[g<22+"$LaHŽ(uO8H4 wJOAў-^! -#X2vH'l9{>$M<qB[ 3M)hFg/Js$w4Ȕ k# )vRocDD6QhնˌNwO9SP`3GUj5RtQ֋"dk#[g3Fgj絭}CޘЛ$T~5j!RRrcz}s>z;]]v ="6O|tWiD(\lez@OSK`޿b)I_5FL_q8Y$&# ZjGG!jL}''/iOJS,w"/}l/[ G6>?P0, 8cT z^ݪ6,Zo̮2cՁ˦A 1R !}P`-7M#ytFE6;!Ik˅]*<vml*)h^F\qpOGWKyhH<*ƿ 2Zq%޿6m^lTFI/Xj)}=Va !?oHG%\`DW*'o FJpXOW^ a G݃mG"*\tW$oW53Fvˊ#?*T1BKGk@$H :v.~6DDpεYc(5g<O׭e_-[/ Sv|KdpVojr>۫s4d SP|+O!45H+0lq4RRZ=6e+|dn/JbP=*v5&<B;ʴ>ȡBA?(5CKyOaV: UDʐ{Zl%0щ&=Bkw5ኦ6Z-ȝ.zɗ1Y l TіOC n\ź^)ݨf{*8>j@@Zki2=pW{KU]ۥ+.XMdqFK2K+;g."+i=8bvRJ$.M.% (h?HmL7x ../,t5xmJ}ɝ Y[7=K00mrWy=kH[u4wlyUZȇsMleʐ"4s<ѕHV'V¤ >xjiGQ7DWgX\< :&,\%# ]1\. kwlŶޟ{b= L he"< ٩XJs@Bݜ6I V׺La8.lV1>FU͹yh_]È,IKmlOq`Y6`mՒX7"^NRލ>^k8M鰢 v:#O$8H2o(}-gV/R T#vDJpY. iU4$NUZv3@v(Ćñԁݣ5\7 s;/N?7BsW֔KFa~@٩r'u&Mu ډC?9 4 ;9H2*. rndjϸj2}HD0t~4![^a}(+v(/QZCj49B8KX^G YU_k\ҿ9e u ͱSMNT Z$m 6#[`o}Vn,S\x NKpQN 7sE{tN?/?7x[5pGB1@'. 31fl`W2F~Hv /|,,0FUP̓.hb}L߆!өaBgɧ!hx⾛rubW7Fvt8i=<{dE~<߆a7&L|Pfh|(۲K:r\ppyδ Wx`幚8ߢԵs/ICUUJpKS n!wbw+ZCۆl$&%*ӛ 6MS)X}Rc QX*FMb |&$T%ّ|]8dj}aQyjZ5ˡиۚרDr@Z !? o(4aH3^! -$|3[-I 5V*<7_(.89fҜV.|'kێ*q.-=4ŇJ49w7wEӻK=وw Ed؍hJ<0qIA~ػv̉Ӭ$\b}ѣk_ȥmuuuҌ]xכY@] >-ԸZR'9b*_X3 :?MвfъzR3lK{ni'1'z⨫Aٰ[ 1#! * `Vf?O@8Z2aw HAxڲ*ğ7pcz٬y%jɔCA$}݌gW4T rn(fyVj&*&A2Bbì}fռo:ٙ|<'̳וB~b@fh(X_cL2:Rt۬=0axٝs4[ sVO֖uFPg "`OZ:xcS8P\c$!j*`Zf;meEEDܹElwY އTON/G'` ulJ]._/$+fkǴB|^U|lPO\.J7^`!7VwEXxZ֏ZOtZ\h1#`YEfv ;?4:DL6Jyz W:{-sJ(C ;7Hq2Luz؅-YՈ3^H@b\r~UI ;] I:92H߷VuoG9{=j0Y~T2n|qh(搧W! ;O̟A-Pubޱ8.۸pb뤁lZ*6@JF+\12'ł|Y8-JHpMP- eQ9<ԑ0uq=.,ul uحJD E f׮-Y4 Y^E8AVm_WӘƕ\O}qBSK!s>_pNW۳_ЄfR ACk:C tJXQ 1l<6XOPq2z1YIbTy=k߬T/A/veuN'B r1xcc0| F}(~%Bn `'1~;S <`0 #v(H2J@ʜJܿ۟:\0i!)2CcB\`L-?Ԡ^e+:,Mgs6q? TwAST2쿓±LҏԷRGlrؗ(O+CF*/?^=lD_k=ib~ R> }e/v pvoUY+2u"}Z|P';\$v^>&])t=+<7q.`/OM5"8p%C;b jɏ fNHK3;G%TUW7](<-º`ETwgXZ!eP6L.$Hv`j/n˔ jYܺ1efϓH(AM18($^gKѥ9 B}_ؕ󢔁;q(z%"8t>7!av}fS{R\n_Ja,nC:ܢ/Y ?{kPL4 %^vNAQ'Kp 4[ZK$J9f߶j07y³+i兝xpP(NRAL'->^M~L0߼=]@IR x *:]Foq/[lQ(cYQs"X3ʁ|zizUG7u{~VX ᴖMlRR3Щ2Q*M%ciD_?U sK8, ,~t+\b[%_`(o1_,"2l栫>{ n {g\F_ff,(N\?'q T~ޕ6p׎z# #=دTh/Dr:/Ug-AŤnyZOiU:>ܡsn?gi/$Z\۸ٝ.c/5!a2kDKDt|vZ8\[3ws(foI`rIȪebtLҘ fLWkw;ȣ>Oȉl& )C΋ Du$lOրRn#?/VM= Ƶ7o] t(*o;`~:Ěk{dž&(%SK}5Rhť?( Jj_qRSDq0ԶױcSҧqx=n [EP/R݇m1) j# Mk>r_5C(Ciu 4w7)+H+Dt)Dx}N]rSz|FJ"{ y.P솸qV8" ;⸼Tod4F5e38= /yzVx\~eeMyπ%ƳOL_L,/]{rA~=#-w܁1#Y06U}D-iD%,@Nz[SV;(]5 [5U:@"|`6!:zDL \ W6R]"VkBE؄W< 2R_g(/oItJ R;6'Yz77}5uSdkZ0: qUt}zL(!s/!mC3Rh-2/3QBɠBk橔!.Dr3j9+;(C]*GIi{ߝ#u D L]iY#&wPjX5_N m|NgA;Y5:&(=EepCLdpStbwHk)u>怙{khR]m_4-P#o)ZR,9>?R]#7EU&Am8nf"rPCEQ$&R&Ǟ dbrR}Eᒳa=lRJm$+RhF!R}߇K52.,^;s0uhRTD'þT A뗰hZd!-ocS8?sjq`Ƣ}#d?Mb; Xq, §YͭAROxA=^Q<6L67탆Uo^`Is@+fC>۠E~* eom N^@噲DXWp[%2:ߓf \lz\"_%e qT-AEO.!d게xR7&ԭۭ)1?Jd:[Y% 1HnK/h0UJh\۫AwŒS& 4LxT1GPl17ǃ&⮥7{͋F-,Qq&RxrT8 YZ