container-selinux-2:2.167.0-1.module_el8.5.0+1006+8d0e68a2 >  A apdNBRTB490bμ:L1̠=ޓ@[bqwmgH^WͩJAjިjs3w^687981fc66fe3b5782a208c240f2dc65287760ff67a57889ed72be18b3b58fc24aaf9dd1b388687b2a66b753460829f179627d8cuaډ REщ0YБdW@zadQuQѧN??bp]4w0 7'=5=OOG(1om6l< 4QRHBuY ;FTO&d胰.)A2s,vے ᐙ"K{]<ƛK<NvSj'Li9&J4mLӉ,e|0K$EjїU 9鱦J 0E*6<ݱhI9[F Z7"3NFF?,,8!*hQp]ſ 7nƷ> 19~%-O887}L=$Tsq&H:?(k*GЬzh5ra ){Ht>pFO ?Nd< @ h 28?x   (  <  d   n   x     H  p   ( 58 <n9 n:"Vn=G>G@GBGGH HH@ IHh XHtYHZH[I\I ]ID ^I bJdKeLfLlL tL$ uLL vLtLNrN|NNNNCcontainer-selinux2.167.01.module_el8.5.0+1006+8d0e68a2SELinux policies for container runtimesSELinux policy modules for use with container runtimes.a8x86-01.mbox.centos.orgCentOSCentOSGPLv2CentOS Buildsys Unspecified . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types > /dev/null 2>&1 matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi6)RbA큤A큤AAA큤A큤a8a8a8a'6a8a8a8a'6a8a88c04ac861d425e9947eb5bc06c3125d682dc981f6327e789ebe1c4eba0d856fc0389dab4c8de315b75e65f20f4e606a015aac29056e561d6f7cb6aa588f431a94dce6af8d6b1b649d30bf5666e4513933948397b3df5f008711cc4365d831f2894b534da333780b752cdbe5dc8ad8ac59be52c0142e210fa49e68d1263234b9crootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.167.0-1.module_el8.5.0+1006+8d0e68a2.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux         /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sedselinux-policyselinux-policy-baseselinux-policy-targeted2.5-113.0.4-14.6.0-14.0-15.2-13.14.3-9.el83.14.3-9.el83.14.3-9.el84.14.3a'@a&0a /` @`9@`Ȗ@```q`@`@`N@`@`dd@`Y@`&m`_T_`@_%_%_F@__"_5+@_16_p@_5_X@^n@^Ӝ@^@^^k@]@]B]]@]|@]@]X]W]R@]@\M[[ͻ[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.167.0-1Jindrich Novy - 2:2.165.1-2Jindrich Novy - 2:2.164.2-1Jindrich Novy - 2:2.164.1-1Jindrich Novy - 2:2.163.0-2Jindrich Novy - 2:2.163.0-1Jindrich Novy - 2:2.162.2-1Jindrich Novy - 2:2.162.1-1Jindrich Novy - 2:2.162.0-1Jindrich Novy - 2:2.161.1-2Jindrich Novy - 2:2.161.1-1Jindrich Novy - 2:2.160.2-1Jindrich Novy - 2:2.160.1-1Jindrich Novy - 2:2.160.0-1Jindrich Novy - 2:2.159.0-1Jindrich Novy - 2:2.158.0-1Jindrich Novy - 2:2.156.0-1Jindrich Novy - 2:2.155.0-1Jindrich Novy - 2:2.154.0-1Jindrich Novy - 2:2.153.0-1Jindrich Novy - 2:2.152.0-1Jindrich Novy - 2:2.151.0-1Jindrich Novy - 2:2.150.0-1Jindrich Novy - 2:2.145.0-1Jindrich Novy - 2:2.144.0-1Jindrich Novy - 2:2.143.0-1Jindrich Novy - 2:2.142.0-1Jindrich Novy - 2:2.139.0-1Jindrich Novy - 2:2.138.0-1Jindrich Novy - 2:2.137.0-1Jindrich Novy - 2:2.135.0-1Jindrich Novy - 2:2.134.0-1Jindrich Novy - 2:2.132.0-1Jindrich Novy - 2:2.130.0-1Jindrich Novy - 2:2.124.0-1Jindrich Novy - 2:2.123.0-2Jindrich Novy - 2:2.123.0-1Jindrich Novy - 2:2.122.0-1Jindrich Novy - 2:2.119.0-3.gita233788Jindrich Novy - 2:2.119.0-2Jindrich Novy - 2:2.119.0-1Jindrich Novy - 2:2.116-1Jindrich Novy - 2:2.107-2Lokesh Mandvekar - 2:2.107-1Lokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- update to - Related: #1934415- update to - Related: #1934415- update to - Related: #1934415- update to - Related: #1934415- fix the build of 2.163.0 - Resolves: #1957904- update to - Related: #1934415- update to - Related: #1934415- update to - Related: #1934415- update to - Related: #1934415- do not use lockdown class yet - it is not available in RHEL - Related: #1934415- update to - Related: #1934415- update to - Related: #1934415- update to - Related: #1934415- update to - Related: #1934415- update to - Related: #1934415- update to - Related: #1883490- update to - Related: #1883490- update to - Related: #1883490- update to - Related: #1883490- update to - Related: #1883490- update to - Related: #1883490- update to - Related: #1883490- update to - Related: #1883490- synchronize with stream-container-tools-rhel8 - Related: #1883490- update to - Related: #1821193- update to - Related: #1821193- update to - Related: #1821193- update to - Related: #1821193- update to - Related: #1821193- update to - Related: #1821193- update to - Related: #1821193- update to - Related: #1821193- synchronize containter-tools 8.3.0 with 8.2.1 - Related: #1821193- update to - don't use macros in changelog - Related: #1821193- update to 2.124.0 - Related: RHELPLAN-25139- implement spec file refactoring by Zdenek Pytela, namely: Change the uninstall command in the %postun section of the specfile to use the %selinux_modules_uninstall macro which uses priority 200. Change the install command in the %post section if the specfile to use the %selinux_modules_install macro. Replace relabel commands with using the %selinux_relabel_pre and %selinux_relabel_post macros. Change formatting so that the lines are vertically aligned in the %postun section. ( - Related: RHELPLAN-25139- update to 2.123.0 - Related: RHELPLAN-25139- update to 2.122.0 - Related: RHELPLAN-25139- update to master container-selinux - bug 1769469 - Related: RHELPLAN-25139- fix post scriptlet - fail if semodule fails - bug 1729272 - Related: RHELPLAN-25139- update to 2.119.0 - Related: RHELPLAN-25139- update to 2.116 Resolves: #1748519- Use at least selinux policy 3.14.3-9.el8, Resolves: #1728700- Resolves: #1720654 - rebase to v2.107- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux 2:2.167.0-1.module_el8.5.0+1006+8d0e68a22:2.167.0-1.module_el8.5.0+1006+8d0e68a22:2.167.0-1.module_el8.5.0+1006+8d0e68a2 2:1.12.5-142:1.12.4-28selinuxcontextscontainer-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/containers//usr/share/containers/selinux//usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2noarch-redhat-linux-gnudirectoryASCII textUTF-8 Unicode textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-8a3081b9932bd37ea60a74407c0d2ff35b82ae939db1eeef1b689a281bf16e7f4container-tools:3.0:8050020211110013114:faa19cc5?7zXZ !#,l] b2u jӫ`(y-$s.*;K67Mva00'/ t| 9L'`wDYeƴNpJPyt9:)~QbmijdNEFP8=W"Sc&aӪ`ksQ׃yĴaA6flR)IPp2I{ un[Zٺrj( /knJGQ$Z-XWz2 6j% "FÂ.Ccɼ^+FarVdvđ__hDZrQ#R/P=NG Z Xf~]pg/;cx1(&3M5Vv1ߎŘ}ๆ )d/eK51D}%uB-U0I6,:pu#yډ&6̑V@/XE-x,7e%0Ћ%̸KclLbI3B݁Ewq)N $G  {M7nn>J>]? _7kIy(ŞSc580^.p^Ar?\|8>ܽC/2(2^-ٞS#[ o9A뇜9VBe+zMf[͚?vZ_g0=$,?]y.-d*sYZo>'%_Şٍ ?..ҩ ;J y[7"^Wt({iZ>(!xUF|k$Hyu g!FĽ:UufP`JۖRCBÛ ϑ]3WժjK7pjkw5k?c2)٧-DFj _3fHrIkе0bfI\)tPr? 27!AAFp"\fJ"|`2J-} `ۈ;LĢw{I"F:點~(3XPo(pE,K)g2<(<<̩O`wGDr 3WtI%ط7llaffbHHM ~\ʬ\;&-}>&.6'RHߧi^:Nɗgh6? ടx+KФ"7RQk@s~M:ȱrKh75[Ksg.fJk|Ңj@:nTZ:}f[ E^csǓr9?^+_kP˝m%jyՙ/iI)˼CVeIz31?+ UX{&ѧZFOy٥%IL8P`*bC\,j#s%7Ҡ\lbDGL!  "x/4>NMC@rZŚ4U+5Q8{Ew%O㜹slM:׬LRU%nun/@ad |s:2g@NKz(S˪0AC FSZ SXpz\fp9< <\}z箫:lz۔%5a@ N"XZ[92EҧaBٴ2pAtZ!aTޤ;CEa=XCBy.m՗cK Kp=ZZFe{NW5r X15y E-ъ#PT!R`;Eor>5Q/CӒg> '1Z褛 [5.r e%Iq\P) u;pp۫<ꩶ*.ż'#^"r_QŤ'{э;84)j70ewjNz8%`{ jћȄU!6׷HLe:0W"Mv?0BfkxUU VL荗\Fk.­_7%?vkȓIJYs׬-ͷ#M{cz ^~YA fmΖ"x5>=3n`6l,8tH1ʆɪ4L' &NaﳤͰ7NLɖrq??{LBHv1+\pԭnmO׵ћ;R ?hVWP2XL iWDc(oR,W^J?֤&)U~\(֦D](" &|UU^ppy$(؂Ǜԗnliv:4)qC)SB}X:>QnBIg*+# ^gnGV2Kw:jWHy%P.2 fbP" @') TK<2.o;y]D"6#1H7'tHHzZ|f[VMnJ Y5 ӁN^ןS;jWpUx@$F(mz!/%(hP(`j 8dC <H ht>r㟭~~IR+Oژ%>Xbӳӎ)Ur/])9lcH6RxRt.&)jsMLm50 3%P;8"Mxu`K%.eиY:hV1Z0{TY,{Y8/qq{IX;/Zn~ƍN'4[% T|7GeIAm1GKS̉ټ!Wc}h! v@ɀuZeh"23Σ$~;҆jsHz#We) PRw]`,]C *,_Ij){7)Y˜$86KUՍ )2=^bYҔTp=M #'Lp)?2svǪ.I]g-݄lۚ*z!"u>h[16Sˋ'DziRܔz`-łjh7aRkNs9d|w|x7%םfz#ҴTFW%\xڴAY\ %*N$/y"[߀d 2>-d7Oі!F2 NwfOû6(1S|M>,Ot,z\}Г Ggh$@c'_*մDt7/P '+taѐ `Lܵ;T dvm"O WDs%;^Kz@eVM~W03)5&qVP(!"o6hLâd5gJK6UEIqr9o&Qb,tsW} Subt>a|b; R)Gue0Zfyp!̤Tr)jP rOAI]30l|~Zܰנ%?Y۳ mIhr?>} my;&&)GGHAU#(:wx>Ţ@Qk_&qNT ]Cr>4aT8Xc 3QT`,ƿXh5 PG~i7f/Ğxפ[~W]Wt zT9ܫ)cu`hյ'R${ b}N]Ks`[, PIiNi v{25:۴C3 FriAp3;iDy`L^Q܊ifLMow^l'F+YW|d ƱxT ;{|7gtZ7cPӻaY xc!RNh5n&š /-*Q`3 Kê$~%|'tmIDa0Ҥ LGPs|=y.F ԮG~X ?]!ygonED]}Nk/kә?ܑeSA)\M u1˰$[Ți<7SxH?)1*u%,'"f_Јɾ3BDDc$يyS&nX^ؒX?H5uCX` s t\5]Yu)ux؂ҠI3sG GdMw?wSJ94/l2^XϮwl$&!zPeEm<&!ezĻҪ~ \yhϟ@7y~1KJzpy7AŐS,p׿Z&V67K3Iy[3dܱ1{P$Œ{ =alyH5a;7c\QNbƇSHG$h׽!^+Y"-PXY{hQp؂s=0I;,9ͮkW`ʫ.CWBWI$_UHQZ]Lvgc qs}^n#6KLH%~wb8Ad7zڔ#܌'M@Kpf %"?ftIg20&mL}06Ha=XhA9  frk1{p˘$cOW>'68 NyulH~71@W%@sIUm:C{b_3iL#zL:?DWC9 t6xs~f/大"Iq2=B>ǀ(J3:c* <QEb Z1i84M!ƍWмogSmE _fNGF#L2/A nʏ胎9ӫ_? 0'wOzbe't΃wuف`ִ:dq>d#b!3|-c,)Kz%wsy@ ?dWL<}25̄`_UהIeHxkqk^[{CC?D-~xvw2D)FPIj妔z* d?F{m+3L(ͮupp-vIr)[NDn>r_;&_l+HX\Vani.U/'("ˬ^iU>+Bь5|1wUY(G9Yx[46`e$!1ZuCP1l{UB*Ma:ժEޜg{A hS 3,gq|n00QR%X:({}# H9X.?2 $䌢xwn4Ӓ!,DݩPNކ~d-ׯG6#(!8pe}P:MOVB/q"v淾6pcrl[ Q89QiV HˑV%*Ƌ6j*(_ ; A:EQiAťɸ$`իBNP^0UCY ƚ61/1&8֟.FPsYԅ%x;^TӘoGËqRTO4I3Ű#o037B^a[~,&:vQU kK=g{g8UhB]ɕhczC荛gmJ:܏) 1'2H/wM{Ϳ?kCjX 7P͇hROICg1Lo[ռ1̐@K≩!T}ATN˫NS*AtP&Ubt]c<u4Zgyzȋk*DVyLZJ4%w_l4}G C#Ċ:+f^Dd=k|#?lை/eE!}gra54T YdK{5 )JP Jmqs\@M9fJPSg( 5C~mq5{=Fvߓ}iԗ8ՌI@70J0F+MLdOrBXKj]eZ] )p*<)B DJq3nr#vX7ETM({7^DA%PPR{2vA&($^56%*< =9BT?ҹ](MƆme;N4t~h%%[+—bO+NJװ6Owt ̓C GllNJ25ؽ͓%81cB89<kfwMcME*doS3 wj@տI4_ l|ȅ z1y;C7T|n"1!Ñ8P/go 2u@ Pm2(ԋdq)8I%Yr0>NPec1{i4̨ KlYsro>Nhz2qk } /n[!5'wkN6B =jgޏ} jg^$=NSrd{X1bw n%kfPWȃCYo? ~0<kldY~o:7]ÞƐ8q5 05Z?f)ƥ۲+.ߏ/`(~JG+Mq] Ik 4 -82-VHcȯ&+ +. e?%)l/`u|΋^Vc)֦bS4,A(h-G#qAeaD ~;v@A|c{ ޕ[Nϗu.-8\U!3DxiѫDM̚'HzMra 7_Y7eucoPҺiNB(qjB49aFJHt`t6L<1wՕö$Sh#֊*<B@4ئY[f׮Er{ҭOSG {i @V>3Z1(h96W? ZʇRqKֽa5=n>[|6,d0syIuBc!;q8fs)I#PsَvRj7![8beVaB2vwώ g07Hc9. wq~~*)(A.[1ݸ6r*\i&t4$' 1RQ6 |5N7NISssxЊPt aZAa-deoJ<8w]WF涶po*_Xd#3 dW)ζ*Jvkq>zEztnh@dH_*:Fp7SˬKhW.bX携])q~ȕs*i鷝`wo|b[\"K Mpٖ'pB/&DRK(KW?ѽq88ˠOB9cUaO|G%ʱ:9`G 5pUV ;3xhztE^Pss3ڲ,y  ܕ|3 k ]3hULnA ,GƪX2q~']zs9j 7ۨW298C:൤wumv!.g4ӊ0U k١^OK18l%?*LV̎P%MaC XŔC5Z8/skuB p}hFL~]|jHzSgD 4~Nz ΐb NcAQ+gҒr!+?Yy=^ cS&JKc '~l 6)/T$aS7"Ψ`G}XrΈ2OwA1x5RWUoݳ%约8,yv5p4LNi Ë珳az "%l D[="tomf4 eo%>qY޵Igo8yթ>42AAD9V3=Ped^t hmťRC->HXalpȅQ6ܿRn"e*&-b)YfCdͶ-Sd<_HM—>}pA{cX87›pc.?@D:Q uޥe]ve9 fY쾧V;b0 (=tN5"ޥ015y"P/G4w8ƑځmH?$٥| ,L8``arN(߾GIiJ^)t\G}XT~Oe:$֋8=V0]U/%(]\3ddGzG'"g0b)Z0R)RyjŌթ*)xJgESQ/3鬩%]dG >Ev#By:%A ɍ ND\Dl%Jʿ SQ{ֲNC' s:$y;^Z'ͦ)5FO4Bu;BgX5n,N6XRc"L ?]+-ȫtEgOƨb .ș#MFmhj~8<^|#|EfmCʭ !tYʧryg\3VgmqJO~W42{g{N Qh+%8MBCi~륆}qF3=t 8 Qն^[4}5WD1! j5{D$8ws *MTNa=Rۙ[0?c]F .E D~LџG &3G!Xm,*F"sc vo%FxZ~#€XKq|4䌆 A-o1/E.JBB?%7 3wӛ7wQNP>IfHj +^Ǎk3OzhzOUe; .'*96~?KP#{yO#j*EOwEK1^샌"k/?’H}%G>YSxNvmT?Z^&lI(O/r:i87*@F&,F- ,h;jO"Unr_G(C1׍, LL*7\ ZTQ/6_:ӽjJ__AUmؘ* ^]ZɓX`Cfz\HM:),#r9'k)N"HEE䘯ÆaDvhO]t1ǯt Fw%h_t\'BJ. Ľ+8:rAe hg+4ZX#$3ہ=q@'$;]l!reT$[6omp0a8&T՗>z=˶6reeQtʁD⩮_h=ݧT&璁Vw}A yC2.QYdz!n?9P>GM|prkn@;2&vNf) XQR;t桿RŠNQܲ9.2T+:K,cd駱KԯZUbdyV1hWa!VRpkIN'Vmt,vEGBYs1CIo[k6 )[*5%X߾ ~j>1>$_J@`zp8UԞ:u|)6ta a2)##`(Z(0O$7E1(+6)vnvC 3yr:Ԕ* sKf)+ɋ!af"AZrfPm>Э/5oUzzǛ znDHY_)OhjN,]xՠd7TsW :82ojn߶Mo wVlc NlHLƒ2ͪPcb ;Ŭm)*[YLDQVZ’ҫ釡zK޳y%!q|њo4ɲ=-lrgbd(-1"jt|͌oxprNuA!@5SV|}vQ~r;a0#DS{/0`D8i풬"3#[+A}o{E<'~Itc&wN߬qߧΏmn:9%y76(Da1~㘭!|7-)HL%*qp LZ uRM2ѕD^dt[ghUS XH`.?SҐu 6Xq!L #!~.`h@MR!2`[> epǵؤjN t+w&xu nGr'.@H kǤ/砈b7Q>ǔ?jsp\v\ӎT!6.` y<.phMUA?p0z5qQ w"D,M#Y#Y1X#}\a7Ѕ=X]Q\=.w,]JC}6֠O$3e&]zCnM3-b&*=`]mĕP6?H=ػѢ/B#)Mٌ)G%רPGBw6l6y;1ѓiuW|P h8sF,,QbӲ2e4e5ދ@0$sqR{8:omrcfBGr@1jLJZjks* ҊVW{qjȾE(M~0N Zc~ yBAA-8,$`MBo'uA䷜byL{̬?=sWP10Nrcɶ)?cmx2p38F=Y5f\Ɇg`8ו)'ӴA[kθzF亮cW8fjG+2Pj(E0Du}cLpYl+'ۜ.Ů|ડQ esiց9_?fG ylmZdݽ5M "h5zW[?YXR xL{cݚ0% #AsAXzt6D% 25(=)+R`BNeAH~D}yyyNhJTAOThߺe}/K65HU$U H2A{G֍Ow(5"L310hzͩ[/PxoBfbBF̅Nj˿}O"UȮ`MW3Ls|:D-Km=ts Tq6-9g Up @*SB? f/.]C+ p0%) )[2n#\|кqnoĩ-Zꆿ6kf2{5:OXmuP1l^ڞPr.++-8f-=V'vKR3GiLx,4 Ldtk+)J/?kS$:;ָR`haE@]q]J|NLzmbGxEs /Pm7)-3T |5t q3S&uk»f~k,IWX # $ov/dU}|7p| "ZYsXn$'0յa'OD %CP4:_,qL00 3 6]eH;|/F\[Ȱn? ˴ Elw`Ne* e*APLF{)zūۜـd2Xq 5g15r;4? 0ͭmE\O2<ʰ^Q_R[k&)x YG=*1{N9|X'7D3Z wnoF..ؘPB*]1P`%15D 'ǯt,\ tq"5$:po(U}$2qM!?  ,͋IC&%VR{Uf3eZ4f+K52jemqA|Eݭld[^e0:˙\"[S9uܿ/=AkҰ? ; \V_0?=7 TK;mO[W$I 7b ~_?X&5덙ڴLk#aeXlP,uʫf2TUԅpKnZeu 闋$q@S-<ۮcE~p:+ VND^@dD Wc݉_})v 5%2lqW_:+zC*ϪvA'p:qA!z]GjR+Azw|:ʪAn¨snZulhV-;ZXQy0!3) G"&BL)h.0+;S-喫#y1}KhaUEg/W][kZ+>PM۱9+ ḻ/4 g2ސUNH(~C* n'IO;︤ (m^{OT"ϪVD֛ZC4g](utSo>ȧ8LÖ!ُ} =7z 2Xbc^&Z^?W_R]s:9]Lspnjk3(,Rg'8Xi}<$%%TxUuHP&frVX1Cžؼ) :uW̓/@~uQw\ an?B@-wb4F3֙ٺ{f-ctӀx;8SꛬϡVx!k{5f *71BVv3;J.^EJ?p?OhUQsr` YMc<^XXp\D53Jx͛fՆ̓4!k_ "\кsĢ'(t[Є+.`cگ[W`D_͜]]| )d&TB[0C8qce,EyHg9DP o|;5@ ]p*"]) |] vNdД>3^k{2pTT/i7ݾWcsm$PВ=ȄyT@1sp{%}r T$.b(T_܍yOE|[MgP8cA HCMP-X/z]98 &5-*^Xf>x=spnpY_S=ϐW tL\]7U骚Si*|6HfǍFVf:xKD/7]8KRظYсgHeV tɤm5okJ "]@}%A?$K0 =\_0>RŘL`*+\5ag\q0ٿvh):®spA@R@\>6Sҥ*% j< $ddjS"#>Ʊh#?bHbpW =VCR`IM,4>~z :=ͥA\wQVƗI=@8;4bF=rĄѸ1Q'g1X}wF} 9 @3YtI#0)/qZId͋ W.PO}u_FYJqNlBDt:˦rBى Tjz &|b?X^EFWɐ,N /ycq۱z; |lrtdJs3ROl~$M7\E5-ri-Hձ7#B ^|MxkNB]Jwpsv-#Qn.슝B3W&ioD7(~Z{tQdI1~ز*7A7Z> {Oқ.y5Չ_q [^֢+!,,4ɩG.Kņ!y("s*z\frO$G*Jk\P,M7\S(~ XSO::A ~X1Zm(v3]~K2OTQ ^UgeNEi2^ hC(Kh3S)%<%to 68cwM DxΖQִ= Ӑ;+g+L*%o+ݻQdj4̗=q!vAWᰯTWQ31$LDf: vT\vpWT)pBtZ[mcQΌr0̶JFFkrȃ1|T8M{֫T}㒓hźby^bDP [{fL""L"OB6ef^t2 ANI kōV|@%7)Ekڣ O Y(v޵+lӆӍP8]vYYOӷfu҈'iBuEI+Hk#jNl&9"ԎIVoPփxfM0jlNAá A]_4+DlKbYϲio㑚<]oq.AN3e bޤL,mg lz@$VvvJ>0w,1@autqx;܊u{.1lVz/[?`WlW6facn9;ot:gҳ5|{S^ʹ9־ȉGTAU=YNo{ޔAYO -220AͿ\:Fi d3{pLMPwX/ToZD{mg=QuTxyQ]lcHO#%fr7.C0'Unij/4}% pK¢䛐JYImvTKjXzchArN &$xqs 32:h0_J6q,s/L8VȺ(F"HCD[jCU&\t&sy cg{}秅JW ,OBzB?rlj/ q?FZӢDx+,By:< ߎwdgn<= x6+,bi`8F,|NK̖5Ct9 :ߖJV2t}o^ /fHaN'{6NVwbZW2SKgsB3eM} kLuYCf-LiF{orr74X^s4֏;FьyE[E~4ٹWz*_H`Iϥ*f1IwW"h=K`|{w>#j!F?-֯w*dLhfGj 9ͬ* u$X$~]9/ xIlJo- & IXڐ%5OX4]O |4g.ȓ؀F?;NS :d @+݄p Dk'3m-A}q V!], -M 5ЯZ3 6$Ct얅`*MUt)W WU-gY?ʀǏ.^=0a2x}Ow}Gc$f $YGk q؝pv&UR|0brۍilXZp-ߊ#|/*`ϼyO<RW%(8QxȏE&~5Ze띧eNenb6SB{=n5d"fAWo䆇?+ q? cR~uߗ SLZ8ȝ- Xv߶_JY<&;uG^>ߨ^t8Yv۬}j3]WF:\4]cjj+_#}V>hx#fJh }*wUH= ~dy&):ƃCSn65^z@-_KٯinEO#sF=-~ɵukWVJC_ˢWLD@ʋ٢%gSq7.y N=k4} 9Ql9(A 8^I޼Iko~MA0Y=7_)AWvqծU%]/3״ AO`6E{kϰH{g~Û&[Q \(ٙeZ~–dlgi#])|w% ̤XZwuxs.H|r⍊=[xGqmETq3Sd x~{V80v3w]s ( knݡ9oL `0f\otY1ƒno[%j~M-V3}nn$>zZj;-YLm}No[H{ Ł;XH3q@ǎEÙ6y{ e[%?Ow9Zd?3=' 1Ð%oiLjp-&.P f\l{UFL OW& ߢw6MV4#o@ECG鶲Snn'd-]%yUw'Bܱ aЀ] Qc]X ,l(~ v^X8K 8o;{CmĒ{mZM y j(v=i_2[^_RZ =UxSs(ӭ @ ݾ XX*ˢ">,f:'ƏVm?{#Zh"_wfkew/mb2m^U36͐U f$Mlkcf2Vv-;oW,#csa%JְCǘ+"evD %6xai%/G=ͨ+8S+wmHV*֙D{G;#;a؅]쨀UR'ѓ D6'ȝ,R,p|렝fF;ը_\JM<Ѷz"'T]~08AWnL$z,wi &c%}Ur&-kW7F6(PP2eWIzmIҞנFX nOn} /mS2Nـ`, K4>,Z,@T? j^z)xr[|Z̬vʗ)yߚ3 )o1}P"V SWLWd  g7Ϧ*T H3iĤfT=Xwa418⤓bPfL cm(@$G-^uswoױut.`&kuo6>MR䄐S:'$ S!= VSTp] c~$3$6Y}A%Gjk G=ɏwjx=>wlx