container-selinux-2:2.130.0-1.module_el8.5.0+1004+c00a74f5 >  A aLO+ $L};,Pm#q$ǭ?G/*f; PhNoѨ4R\c4[3{Kpq.<!{w,o10Yuz8̗=6XC$\[t(߰]Yo3X2*g5ޢs,C|l)g\dҭ\\6764pcҝ{p[W_}lTUKIuv?ɑ ٧88_,DEAz!bTJe@6I0s,Ob.9 2npxĉk< Id'v|N!5H e4714967654ec5e711c28e027b8ef5f2fbc115b43179f0c9bbf403dbe0ee2c249e76bb492e9c83973beb119f41590d0b9f772de5iaGbeXo$kTt2> * 1[ |k%<MT/aibQJXEv_2Orf] vlʮ u*[]GMH Yd,-zb!SEQ@DS/=_c5teZbc}j̓Kr_}d>pF:?:d< @ h 28?g    <     , T |    T T( 8 M9 M:3M=4>4"@4*B42G4TH4tI4X4Y4Z5$[5,\5D]5d^5b6d7e7f7l7t7u8v8<8{:/:8:<:B::Ccontainer-selinux2.130.01.module_el8.5.0+1004+c00a74f5SELinux policies for container runtimesSELinux policy modules for use with container runtimes.a8x86-01.mbox.centos.orgCentOSCentOSGPLv2CentOS Buildsys Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi)M^A큤AAA큤A큤a8^txa8a8a8^txa8a80389dab4c8de315b75e65f20f4e606a015aac29056e561d6f7cb6aa588f431a9bb42ed8caafe82e1c4c84bc7a8b3fe2b5aef929064660662f8b1d9f46916b72664d41f7aaf65124abf9a513c8c78bc608300774bb5e67d316f7d47343b7cfdedrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.130.0-1.module_el8.5.0+1004+c00a74f5.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux         /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sedselinux-policyselinux-policy-baseselinux-policy-targeted2.5-113.0.4-14.6.0-14.0-15.2-13.14.3-9.el83.14.3-9.el83.14.3-9.el84.14.3^k@]@]7@]]@]|@]@]X]W]R@]@\M[[ͻ[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.130.0-1Jindrich Novy - 2:2.124.0-1Jindrich Novy - 2:2.123.0-2Jindrich Novy - 2:2.123.0-1Jindrich Novy - 2:2.122.0-1Jindrich Novy - 2:2.119.0-3.gita233788Jindrich Novy - 2:2.119.0-2Jindrich Novy - 2:2.119.0-1Jindrich Novy - 2:2.116-1Jindrich Novy - 2:2.107-2Lokesh Mandvekar - 2:2.107-1Lokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- update to https://github.com/containers/container-selinux/releases/tag/v2.130.0 - don't use macros in changelog - Related: #1821193- update to 2.124.0 - Related: RHELPLAN-25139- implement spec file refactoring by Zdenek Pytela, namely: Change the uninstall command in the %postun section of the specfile to use the %selinux_modules_uninstall macro which uses priority 200. Change the install command in the %post section if the specfile to use the %selinux_modules_install macro. Replace relabel commands with using the %selinux_relabel_pre and %selinux_relabel_post macros. Change formatting so that the lines are vertically aligned in the %postun section. (https://github.com/containers/container-selinux/pull/85) - Related: RHELPLAN-25139- update to 2.123.0 - Related: RHELPLAN-25139- update to 2.122.0 - Related: RHELPLAN-25139- update to master container-selinux - bug 1769469 - Related: RHELPLAN-25139- fix post scriptlet - fail if semodule fails - bug 1729272 - Related: RHELPLAN-25139- update to 2.119.0 - Related: RHELPLAN-25139- update to 2.116 Resolves: #1748519- Use at least selinux policy 3.14.3-9.el8, Resolves: #1728700- Resolves: #1720654 - rebase to v2.107- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.130.0-1.module_el8.5.0+1004+c00a74f52:2.130.0-1.module_el8.5.0+1004+c00a74f52:2.130.0-1.module_el8.5.0+1004+c00a74f5 2:1.12.5-142:1.12.4-28container-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2noarch-redhat-linux-gnudirectoryUTF-8 Unicode textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-8d03ceec61c09a3366d210c6fa99f0674329c0b188a45b1fceba8ca52ed88c099container-tools:2.0:8050020211110012904:faa19cc5?7zXZ !#,g] b2u jӫ`(y-$s.*;t:-'FGK[UH9l]?v)%-lM{ԯ"9_"f4}#=K0elڼWAO7)mJ iK=|]Ud ʃо5o@ѬW 碔_< q8[Nm p w_wM-.gvԦVr/Q?v5u탞cB=pSURK]?R-ugc&{)-= jV " Nrk C M96:n 8K'_ @"WwS/%8,8}c2 ;z$H\aOGv=dlmdN̓|}Lv@Y1nGvy$[&zkm߶|YI=fY<*,qnd,iқUa,>G~% "LgSQ[!62Rw!OE:]4DJdu2EEϘeƾTܝUA}j `˱%QlԔq -kTꀦ <ʏ4A`go^KL_P{.pBN8XѰGf{"k]ĀZ\llkS#"ZsW QE+是EgoH >bAMrjOfv-b,G`XZEOm?4u \jHhxn2)?7t\kR4ј\)UQ9;8Ss2a""qp` 1wE!/Hߏ`:,*3~Ȇn@k_R&$ITPrӝY$G_U1vy:SLAn oHq9~ vHq OTdb&%VeRszwc5.>&΁U!= L"/c(IwL ñ?u^+$8FoXOau;_ԺA `~O@eצSۓ .xHDN &K]?Pe"XJfR{,rm6ɨ PZ1B[èW]{!SCqr ]6ED_phmt?,CT0ZWx#riThgYS JIC<PZop ]Z GrNy(Y*RH-R`k=wW/)Lm+W2|&?ItWtBCLRJ6|BVMx:7;!螛TMΤDa= X*+ VỴGq% - [M`rɳ´rP+I_zq t-5K$%o=-lN=ZXxtM3/K-J7pڝ&Y05fʥTI5DyDGg Vf,V6]nloE|D*륵s{Yw'\ 9$X+"u6"nԽ&0FIy J1鎄lҸxrֹq VtMyE3n+lmҊ[_=j"u ; {K6ƨ} %)Ţ[]*NXmt3zK(.*uAhm92wJSiM& Qll~'O`!h拎Z8pQan&8mu5 Rwj8@K] rm.buSxͨ=5aжpͼ Ӳ%}Ảކ9 oӥXoG1&Ǝpӿ겯=D:r!ż+AݐDx5[ "*ea/h t";ߜ7dj{gV7\TRZYC h(kɋCoZX@Z|jP 4zEJw b϶Ka@:}myԼ?+n0.o;e% }*373Ww -d'OmC FfX=CR@ΙQGWJj krCZֳQn&%WQw'\߭47ӅcVdWQR9 wz1 -k.y>OSœUF>V9Nm9)vZ^wAaXZ]"*!\ ʋZ%J$<+h0Ʋ3TO_9b(5uUMD-AF'n)2MSيca]Ew_vsc`0OB@LtY  Vf;7qEbggi0F;GkZ.9:Oye_LԓR#fthO¾O摡?4ǠTǟ* suv]`漖ZWv-%P"5Wإl Ae8mv6S]P|ͳ`go^NeuƤ-C9Ǔo|s׭T.q< SC\J.\LqC{S|Xř)tl^v[2 >$w w)^123d(kCc+]@غ1xn-1' ,Xֆ 3jPSi}NY\e2F#"':L'B.l`W։ׄZoUPEfJX_JLSn[ۑ`#2j7߱B TZeVL_}OQV)8cmH:QjĖƮ5*ܩ,Wz6JXkz>|8:s~kT1x%Ey vzCnWG,{6̭p٫ t8M2,`6 Wp~W8US-n)36f i4HWn]'rt[ڎ̈੣ʍ/Ɖ/+9_b9uN3f ՈJ8??7 x|̉^F1b[SղykoOI6yFɴvZ;=9)aV""%`'(rb8ݠ w7lC.콤b*-S ׎u妜j9v`eeq S.dN)]W6@DlխP Jocñ[k}/moչtiqęTPZ y"XzN'>4'_>h,x>チLק5zpo`N:Ot?Z?jM(FcW7w Y.*0 &C1U&.W<<e$Cr6vtO}O30ifX_ t{ Ff}mK6 eP[XVJ1Y+2*KW;l_ O`qmO4~Qb0C6̈|?lm0`..п*fFZU%ph%S8p4੯ʚ9 ,WDcLNueyF#{ ?L7Po2 խX0SZKyKjh呓ZzloɅ`ɿ8|X:R 7{nv^ %}fZ)#66fՖ|r'l-^QT1bGHhruuT VMoI➖sг ':G ҆Q\lMiU5Wg*Cod/Vg_%R-r{KmO) Dj nrm96Z1ھd a@t} {Q ["@2Z@y27/m~Wq'l56/'Z_^D> =D zdv} D%.F3Gv䰘ܰ$~|[gew%~#x""]ZiNj9[52 #MIV":h!B3CCjyKЗBIi͌ie3qlhOR=<jR7&ps h$ߠ2fu<۳cM]W |SxJ2˔\{kxOžުI3 Ѓa֢ Tc*&{4K jfu|.!\FTn,S㣌ׁJ3]5>eН!b'H y3; gaԅSJ9얂)l"QT;-/)<2BlvE02p '9tPCZu؊C{Q7h䎓Svilj|dȾ 1fiOaX~.V}/bfhK[IJH(N=tɕ0]PzhZD@sߎP~%9A1׋k`0-ZS D_"Ŷ^D}ΕjOsbg ASr -}+le[o#M9 6\T2C ȥ0NDȘrsi:2Fҗ/lLoQ=ak23tD^+VѼړG/y;HJq/K"r恄Gh[XS"S=w^Usƃ.Xx̍v*x¤!$rT]xv+W)5{w;+;BazKz !$⣇卼u{tYe`; !/ ZByuq(园Hu2RY#W 8ˬ&QNQ)䁴oG&D`P%ȂNm4 ]5sDhQIr;zWqZq۩Q hlRUdC#HSGƉ{tQ!l}a7SP=X Sqq  3ǐuQ#a~DP0\LYmC7_b:)9= gt^٫GIޥY\<+_vY vn0!('+I 3jC=Z"TBp"9][ǂZK9cTR):g@tYwǛ`$ZwRfp`Tt*/?!ا,^3IH2 ^;[ӑ Q2IXme12ilQHp[yF/A1&un?((oejmU/S׮C; '! +K 9Hp<:F~Ό ( AW +ԁτ|ԝo K@]z8 e^5p?µ*r+~'ħRNytS F\ڔ1 AH/LpG`ئyM.OXx]\{p$ߎ}ww}DBRP\k[x/VW!VȡgQR&"q #6G#Z re`(|*[,"  c꿣zJ1Y/ԇ[b9G2$YCa]u}FS=bo@%nzsqYPڰ +~+s96%md~0)1#i 3]z0S'm6 .{c,)6w:xẃ2 EtRUx@4!->>k@%LerZp[$b=`-Gg'OË={I?V7m0({݄:Кɗ3LXiSf)bs͹5!+o a1R ߊ.u+jҕ #|Ċadϓm΄¢'T)H uw{#S޶'f Iw6Ņ~R+`lvJ<_Ĥ:>blMoB.p^٘kڜk_ΒCvqX|)=вW:*g{ ']IͦGp5T3p)M.Y^ rl+s$T/MӍa`醰{_,!!(4-Eʯsbtat~9TX3IauH mB*7^Jlo'^h?\=_V˕iv 3B4WlE/vRwG|zɤo,=܍6fPI;TijǨK }d΄GyYpRt0RmAh,;U$v 4'&]d?yh#w &>އTy;~8s鹳fR(5"?\ O"U08ޏAR娺v,z6="1 kX$/9.R'm\ݡ4Ɂ_Qgw G›+_{(,kaA1 ;Q5T4XyRYrtv@")+Q_+SM:8P+AN3P(θMDԭqkaeeeg;/s,wqq6,-_Pڠ )5: Qgj=- 6OMwO̩~Cé6CWρt+M)/;CLק'`W?\M|?8+Cx-@«S&ΚڌzQ'9ّ!8WzcV+B"iCjeY,pk=PH.ح fyDSE55^\(~Z+ yDB_:Iİ{żkѳF9@&S=hx18;E6nU vbŒUGpX`2MiQvr`Өt^#*z-pte_ȈQy'=@OF5pCtpF1H\;8Aۯx|yk壃C̗|:a\,tQH~%guM 710ds)WJue~, a.;kdl2W&gmLAmtS-MnGH/Z}b7vٽc4>#>_tRu( /\맥!0,E/NN" Aa TZ5[2nG%{;}ga ;ܺצ\`گnv%tN`AK&rf,* ggq+d5#*Y%t^t,фM^ʞ-8Ye.~X!:ktωĴ B03:x#E4+ޤ76v9EL퐺VC;R! ;>c1Ø;ńXw3&nZ)D|A"4(NSmxҋb57d|rYXDոDس7+i}lʭϓV0^ߦ0!Q:b :x}X#B}0zU;ŒaR^ıkPdhbQ4/w։&t!I[7!"9Cߨc+S?o2h炠6 &.຺NOG٭$d3 W۽ڴZ6sb$d-;x|Y w7r3Pb.2ÇxvY75tjJ%ϷOPLqI)NN8n`ӮnXyaDoţW;편bi)i\!萾D码Ǹ>.rVlrZ>MUm~!3f%`dK (Z}εu(m2v&Xޓ>b?Yh<NWinfS/aOvIc|lDȀoҍaz(r-R2vƨ"O?y/t-Bh#nY Ǫ#cmJ!^\W˂Y9162w{-P)Cp([nf`V;# KEwC׈5̱Q؞v@:(hV0 j1M苶$sovs2([0\d.jB1`ag2ByůdÄU~_w2Sn|>1E-vIˆ]AN1\Ch+?O9D#jIê'Wd|7&z|%[T;OvbAATPƯ'XEͫ dQ7#ZW^h Trwr/ʯgGѭ8+;[{rZZkA=ԡh mH7}5'P L ( d>.F!`H.޺헌_K*VYЋܰh$ؘid ֑sW* K `T"T#FTK_]!.oHbES,[hN-Ч:_/mǬ 2o=څ[" :n 8ɣÖUgkۣ7qʿ6Igsܟ4F1kqB4eLT_r}tآi<9C[ցO^*D7SڍiSUb_LxkW:IK`l-Jc D~'|5@MaJY *Xҕp0ՀCZ#ĻcVaSRP84I+.=О5 RՁΛ#{3/-Η=ޥ#Y UX3t'=Z .|/^3%K$*?!v9yi5z).@Nnaa<2 Qס3CI+:Іv,<"T8fK+/ R=3.o5gŘZҿSt=\猺^2vM>v!vep gpoAG]_;AYCOJLøB; %'a .Gyp }ZXoj/xzi a|_MU4`b}ePD\j7AɯOyn >lڇTK4 j> } ~$A,'lW[ErN@"I29榙=^nts=oʯZ.V9Em#`,Vpq<Ƒ[x^`Nj.$T w3 |FSP-E67da&Ɉ CB~hܻ}k?眢$px'aTѩĐ9 @6N# l@_egPd U!SEQဇ.9Ayl + lϘ$!mTI;9UXfʐ[\aMzޜ\%вJFIՅx*:<XmXU6Q.mtAˀUt%.#ZNa;EHM?2ժ*b Ӓ#Ca?#̛AӍ~ >[_a_=HKPl uoPD?׽x)o8`mKV)rVD`u$PrX9%V>X-҉pH.P$e1]]6TލtLqbw3bd\g\r } tgrڡCg@aA!FfgW[FZ[kOd)3T}JvU>j]..#W}K(M p=rr-jayx7qo*!\TtyXQD5N>< -%:]M:M9~A&Oe)Ldd/ '4msGH  ƢZF hxx,23מm4z˵YC |C'Z#^sc_ $ϼ9Q,ꪓ $zk^w*Hˢtxf`֒{F^/W<]^%=xN&g;,ψϋfӐ ϝ=[<L.y^Ç+1'tlclHmB}(RQ~.T+/վ)vM'x@ ЈD%%[W`Y@s }Q7*a!H>j9}M.?fR~~Wfp['u•`rhq{rTCdYixVOSuHTڮWV܁&(eơ@#$.ݿt^f  ^M-&%U@)u-ֽqrDbxمbl? # ;k`//f:8$F!,NW4b~볖pƫdv𤉿4UqU^/bTDQ"_@% >l83zxL1u%aQ9[TBd؍m5kj&nLKLaJ7ׇF~3fV5"f,td+L~9 GHi'E'џфԻEgMȅp`gɱkFI‡u{,KY*W36DqkKfUK/ )uΟlᩑ$;IaS%Sun(4y~Tg܅rBJbʦY)ZRZ>:j|UpSAD(PF눨b0^ yYcrZEV)J|WYPÈ2u*Z [q!}[eAh .H5t?ӧ~Cx i{Jkcdܻ^9p_u/hm.ܰE:>-EUcf%?2-e ! ӤQl[7("S665S.MY8?,aǔppq؊[Z&Pv4d)b2Qv{~i&Vzr{;<^L.-%(ʘ\:'f9$S(?oSeFp4`;S`/={RQҰ (7zm11`s0UMDq\ҟ $KA([#\o%&It  rfK*^:q) cO_]qVD$C~+Q\acTI}**Rot/褅SQ,]&Q1!_0q$}\xO$q,PaBD-Vj*ۥC 8??jW ګ#i$zB`u}UZ'YLT@x[>$n'ɼM(!H̻J .Fo'N NB qӛSڰ!Dppt0 ^tzk+K!ٽ~Xy8<㲈*/ȔG*۔s3d1Dhd}ˎЎ`Kb-+6ĕğꗢ0DyyYrvG\YꕞVT~&b3 V"jK"VNЭ?pgh#Xl/bRaZ~ݾ)?k9z5NJNT0 C]Ŗ|pIw2D qt𚾁U_pp‡%@*Tv-y CX<9 nF#Jz-FLA+.tp7ܧћNݾPDhS5K O6;Dudx +W譏6 V ?]Ϋr'1R$9oݥHX`f R0i oG7(ur4{Ԁ8K%L\/>Bjplh/FJm*BsCpL~)v6-Wf½ݰ&4A kbT_7.hRM̏ ma1GhL?SS[~ 81 ?Q6Shrd;c8sخ15$Çc)m,!T$cxk-<.u@ sj?4AD =+78$osqdBf ˷R^mV3B6*i$d7Wr~j˙Kj/JOF^ȿ{p{FdWʌ\37*p` yV8sݧB'^)\}FX*,( }O6l]TF9t*3ʋ۶Mإ,PYZ+5%T aĊC7,IVRZk8Az KijO.B,^IwL6q^08͡>Z9mq16]KY3|7I6`Vi3.±Z{Qjv=<ūB$TM-t[O`n**$*]"СĐ6X!~pHHeKt禬Ϋ Map7S")6&j e |CZ7j(,Th%iw7P6^$u%/vTj[#]-'6L #ijVx_ [ }'kiƋFɅIŠPb#+.}R+Jhꋇzi 9fJFX$0Iǩ g.%33& ~_;ȫZ$r32(|Jmx։ttDފ297N̚!>^Ni>ބ2Y HƥU“6O{= <Ly $O}8"诡Y=y\"~8ƕ%=W=] xcuGU"za"P rd@kؒw\R_Be#J2F" k`@a紺Xcg&xtlgpߋXYiV-_6gQZp_l/;0-J*T'pYN)L*dlͦ*G(v8jgX]J4Ik*9/b5t.;Ӭz^K-`r\plzj~f$fu4Ei 3 _NxV48Μ2"Y; &ipU:h"2/bwZfT|{ƫuZob׃)GSĿ,EJH KS7ӌp&yW8`+ڇ3OԐf@hmh")\exrxR5bo{D:})Mtgd84e'Z(в!r,HU{ lJ\v7}S "(Ibg6kL9>Zƥmwp/"XKxZn;M\q5 o38M$* c@*H0/<~NpF$ ׍|4q>0.lW,CCj2 ,j;(ukU槟:_֥ 62 \uH9*d:Ch9Ό\Kう$}s Gu O%G)/,Ccl5kyreuH㔂cCG5lUoCcav6h x2 xuuL:M?~/ϖ DesRYk/"KK'x<[⛑97]sh| T^xV.n:?Wb}0yF 9'OWN *ץ҅/Mju< `Cnc#xAE2Coprvh2j.*S t .cХq_؂UGSpB(+#"LJ `KS⻔爪*Ԛ|&x HDB {ȕ՛6M6<5,rQac)&6kӝs+#9+t{fD5tt +@gEۛEK{DTGvmf.TVNay8B9T_Ϲ{JиE&Mfu|AQ\!"Jk ǿ̃;BЅ)O8~ka-B~ TysY]ԣqND&< :z0m*2ɕu"YfZEk=+03$k:O ̟kC-ODSP@3"O!]&˵ KgL*\б6=cӝMS/79'nA;id$WL0*<󀴞/ 4g, $0m Ɨ0U 崘Z"*x/X6  ܇ wzOC2n^iWG u%R,v5`4I%3:n***{7X:K3׬׿?{4-qRn,3g;(d2ړFV׃K>J}Pd9Q cbF9h}1e#J AyɆ al"eDbPL3;M\Dqȥ_4T3\% oUz0oB\֥Zo2Bz%ٽoU ZQ.l/-(d>c2?ZRXZcHgIV?㄰<\"% K(K ÜruO~EMak藠.[Z#V-RgxBAd Њ.%9&Dq,JIя+kS𝕚T!-:ާX33&u*;t & hD-G dhb'1>:p9#G/g(JPE7tȢ=Ƶ1`-Fm.dmwɑ~1(D %qĞ،Τi}GgoKʾ8Xיhn_:orTwUYò(ه( ubrt66%U)7!][[&J,]8ןץD)!baog]j)>K`)_Ӑhh# GJ 'guۂ~| ܤkFcBhnyO)JFz퟼q֒T 3oGZ9荹":HūT.js@Ue. %G1R46A@O"v ;:>%a> 4T*eJP7cB;~kݝNjfwlQ*H>9B7R-Y~}4ZtzԬl!=:)6>ʘ@`hUDN W^uZ!`UX R{KjU|XYN b5I65Ei1™#|b9×Ilc4f/1"d04#x'I;,,Ey*vSݶ8m?Ho]4s+oS"$0x"/́},̹;ȷӕ!GA#g7m)@ܞ\ #C} ǎ7\lx2GbqbWguZ"&btMP,ni&PN*v?e &VgH Cs$0{Bn. v_-UE vlڥ S*D4JF_qOeƕL f[:oav= pO1$ 3/`ʻ%m)Jg`B]gpqg Q4{̸_⒁ǃOZvqƤ;|S"Ymڡ7Q ZZ\X  ckgrC5SkY.8nӒw9AK"Җ4liQd>$&g2]C"d&拏9W?[Mm/2`BC"/--´,(?\x|>΅|-ﺬ)̸TWY גlzk [HZy8u.dcd~KkYDɳ){o ypV>9LT#zB&!Y$45۷(HK-wSk.z: w-ntN@p 0xBy[On{Qc]6MA7tO ;aV*ѫyNiy5$zRB/Q0vM\W՛b>JbL|g9OҘ%Tp61ۣ!B0 Z >#bptu1+3(h:.t#eil0H{C"OJ֙{Du&R#ft/,Y_wb-X'L "LIyc~a6Xּ=5 )8=mKŻ% D+~Jj7Wv 7пJNܛ2E{wP)7l$3n2t5 iI '^:þ~