container-selinux-2:2.124.0-1.gitf958d0c.module_el8.4.0+521+9df8e >  A _smU]@lف_ʚdB Mm$`[517G؟,ꖚƼ 0ީ7pD^^+Jm CN@siЎ2e i_kt˜8_biT+]W\ϡ^A}ɒ>BRHmE={LP:( j 3`5:(]n=,i#j\׬S0;}XB74q>PO3ٍ}"H!8)w05yy6 ?q"?SY~w :y{U裻t>H@ %ĿcF,Hd)/|~gguU69b9c0b8406f1991aa643313600cd76c586cd72620c9e6cab80c8a05bed135344c7638e16564cce9f97ea2c199f5b17240e025d7_smU]ŔsR]EиZ1l~A|ǩMT?yH$ՙ#K]pFT^{z8Lt06 xS-Os3FkAZ Yq6NXd;̇4v-?{л\>+K VEpT`QVP8^L0quuϑvx\A/  ̶Ƚp5ĖIY\s A 1`o"3ZlpWzPuH)VȃDWVppF5y?5idH L t BHOw   , L     < d    0 l l( 8 E9 E:E=.>.@.B.G.H/I/4X/<Y/HZ/[/\0]0$^0~b1Hd2e2f2l2t2u2v23+44445458Ccontainer-selinux2.124.01.gitf958d0c.module_el8.4.0+521+9df8e6d3SELinux policies for container runtimesSELinux policy modules for use with container runtimes._sppc64le-01.mbox.centos.orgCCentOSCentOSGPLv2CentOS Buildsys Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi)LZmA큤AAA큤A큤_s]#_s_s_s]#_s_s0389dab4c8de315b75e65f20f4e606a015aac29056e561d6f7cb6aa588f431a9d40cc7015bcd8e803bcadea70e0bc08be172983ecd62b40e2225c5d2ed2e6265c6d499dc427e2d649f8d0f04eea7d920e5c7215689a8106355a673679ca873e7rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.124.0-1.gitf958d0c.module_el8.4.0+521+9df8e6d3.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux         /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sedselinux-policyselinux-policy-baseselinux-policy-targeted2.5-113.0.4-14.6.0-14.0-15.2-13.14.3-9.el83.14.3-9.el83.14.3-9.el84.14.3^|@]߶\@\M[[ͻ[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.124.0-1.gitf958d0cJindrich Novy - 2:2.94-2.git1e99f1dLokesh Mandvekar - 2:2.94-1.git1e99f1dLokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- update to 2.124.0 - Resolves: #1816541- rebuild because of CVE-2019-9512 and CVE-2019-9514 - Resolves: #1766316, #1766215- Resolves: #1690286 - bump to v2.94 - Resolves: #1693806, #1689255- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.124.0-1.gitf958d0c.module_el8.4.0+521+9df8e6d32:2.124.0-1.gitf958d0c.module_el8.4.0+521+9df8e6d32:2.124.0-1.gitf958d0c.module_el8.4.0+521+9df8e6d3 2:1.12.5-142:1.12.4-28container-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power8 -mtune=power8 -funwind-tables -fstack-clash-protectioncpioxz2noarch-redhat-linux-gnudirectoryUTF-8 Unicode textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-862516339f2f5b45460afb6699e164759c077c70910fba0c22cf5a52b0a87c9becontainer-tools:1.0:8040020200929203834:59631bd5?7zXZ !#,wcg] b2u jӫ`(xy8ƙ3a1L9N6 =鹔$RkjfTf0ad_.W*ҵqi ^I"HkdD`QǸa!fqͦomtELze}/NF)x2ԏ61IF'T.۷K,@C<6GVlzR7哎$iYrYϵJo<hI{d6|#XEE y`oG +RNv\bA尦(8/S|O3n`v^;J;bYҋ7]lU_aNDxr['drugo [!06M,I|PGJD>UٸɟF8GR`Y:I'q:iwZwI oUW4Mт/|`tA61B&j0wt+I6|C<3w2өOE#LU W!'8Fx1U`M0n){3?s _Y NR/`X'fOWk\`B)2Q?1M`;[h7DmI7G>b*`c0 3<mբ:#{CM-2txoz;,pWߑ~2ŽJn&ݭ #~w-.l pw% C"yVOt1LS̉) \* d]~haRM7Հ}6< M^ku*]ۆQЭczi0PE+ ٯut;U^<(s3Fh"T~'qKsB4>8̽7X~2'~խ0x &dS 7x T(zD R Tg 3O'G9 vbX~~+%5o|&[7oC!>G1-:]w(P}(y0 Wbuϥ J䯑av͛tlڀ(`b 7۞|wA]LV\u[|KTsʏpB%}яO-]!2ܫJ4|57P솱pYJYr6zQ3tizJ"Yr[] ,DG !DZǹ}`b տ~qǷz;R )x .?67t9o*k2Z/b#L KgBK,\hMЍ#Y40}FnY؁Ni/0ԩg]k0/QנウMhc(˼i@U4Y2qHY%­SA`?.(`aŬp v"/Ǎ"NRZ9S(rv>^RR:Hf φMdJѢ#޳ ?̒Ddt~I8pV {jsRv\nԙOE@znM w> Q_1| N^Sy (@Q~{OJ8ˠYg= _ݤDuuyoaL]_}M,Zw]p]QW4ŨIH,*S*)Šg|^r..IYPsһ] ࿲Ianf!uF&0OTy SzdE!w\N+P f`!t*(AH.Xs4GlbTZIHhhw"jߛ[)A滜[?Ӿެ.=`J@$}]YV-fu%辺' UFJ:ilNfC84q6d0vUq9te͉(:t7:ˆ>QKNըqF@éJ|p&@W{uMZGl^H٨Tć\#9u/,TXV2UЏ KSsFk~ok묃jfX|=wS#kU39 :SJ Fj ޙi%#o1Ʋ]U+g10- |^.;i!T1W} /-IH}L3sҪ "5Gd-E?Ii$lfyzl\$)aod@3l&4E̚+p,J)H,ļ)yh )]{a%{R vei/ɵ2ʪ[bTxE N[Hۍ4\lcHN\ sed 9XAIIÄDpү}5WOCq`IR2N\7-CB\v͵qO!@6v^7VrR7_^Ca9ѫI16 ^/@2:esckN>%2PEͤFkpd):HLJpҐ΋?JTp.!K9T39ӳ! aۚ^XHr WFÉȤ,RɹoO;&%k·.ʚ9JJGεFCWHE쎭$y0hb~>DT3̇vf/VotBX%U%MڐҨ8:/l[SRhN@Z9Hw2 sPBvㅯxqH lw|:%=7L=zNl\U* v5Jr2QSkAIx3:KgxAC؂Tؑ+_͒ӡm=QawIV.RҥH5iT @=ߺڪeUɦ} :.̬yZY/vjyUUVc* C#0g ڊ-ŠN?7ٺV1\uz4?/ύG9mPT< -諀sB:YKBʥﭓ}< F(|/>b456Qߨ4ZqyE,B.*s]%c{a^aGc%7Q]?S>f]*4&Tۡ( |$zRl("&knӌ^,D#CӀtdѵ WB>' MтWs]Bǚ:a\bO,eZ%Dxm"C9Q~ `ĉ\(zrJybu|zi5LB%޽4HWwȊQ:kCI=jQE8@_IY/p"GACfUfx Sf{B"[uH44_f0Ϲ"O~TkeP`Ao5ˏ/s$':N_ӑb4KOp?!|IJ= 'hB>I~S2=A ߴ$~T#Mbk.*Xy Pz\VTcz )؈HօRb _&.u+xz^d[T^f'⻻=; 6+81+I;BcY|tF,\'+A&c=Iw£f@.Fx4chV%߶2,j,ٶ֠hDyaJrth55Ȩ72=PS;Vfk4"€1chahi%? 41ר] t%U!G4! `+\왍L/E,ͤM+o^ŵW7mP#X}ҽ# p"=q1\!L  \W:Vfyl EPr<)'|-Ἷ.9ⒹDQ8H_ZωU$D;>NɵsDHWGD0[T~:,2N?0>v~=7|>Mc,a]+T~ӗOGy2M ׸'LVk;$m58'(eh癆Vd?'o8eA;Wr=RԶӔtԎ68KC4iʦ厁r{4u-%;h>\i^̺pz]f%p97pκ pƔT4`PQ!8/@gG>xq.6v/: 䦽_>k,By7=|3q2XNJ |=CX 6ף/޽.ߨki{YQ ̧](i| k"Lb[3x (yoZ,pYX:[TAB/4eH"!9 r:Z fYC%oHpTBɮQ9ZEG*eCgQD}GaZҿ;RTYWEXbaDct+j% ݺ ڋi[ K 7|%2yfXxcoD?SgA 9ELt2 <_ŤԚ[ IMQHT$JBl>ER v @qRuu$,RD &>Rme-#V X2!d Kk8JNuҕQʩs%rR!ZAZ(Q[VBB0?>ySL[j3<Pd $l_|XwΒ.&de_\43~yN{'? V{xAU5~Ŀ/NQZ&M;lEDʑl`!,Nn煁_}?XWa]S[JvӁwcoKfmk` jƆ$OŃ\m4QXUXC]Vbc`^DžJ@w@rI\sqsc? t7v^Ǟ15ؖgꑊG \tRq>}a̮qe}/Ցҷ+}guE&H.h 5kMyq7'7j YΤ$ X ^u&AJ uN9̀5xt.u9 E'&r<;hդil5/_6L?? ΀aWaN䘊QB7dS'Ab-ɬ13WtDfG fGBAJKQ#9vT+bxjY}h&ASD6W7~(ZU.A -ؘ82U8Dߔ.}oDxD8VƮ 7qd%;,kw[m)C2H$CZL,3kBCƿ_XH0UaZ=~c[xŹzd쬃~X:jdmh +OH$Z]ef ULEFK 1rL| /z-~ֳBFQ>}D"x(&Z_H=K|Y;ʨLT{P\n4Uz};PE_|Ĭ%ꏌ :q#mrδc2Q:1YZ1!(/aS{W3݋_D{Gt6!i@Ykk^zQkodxEiJ, '^R̪I11eK>eW5QV]5~ueVmgppUdohnMy젱J5i/QCd|x<YPeR2t/g"CR^-֮$P3Nv/}*+"(s4iW(`x BT8zjK%.+n;F=v[rfCvM/)i@|CkiJ]zOԐ@xWŕaRb\̅g%1oVGBτ_v{E[4 t[|AI/QdF Wr9*PF;Q@} |D5nrDGF#`YF/J*PCc6a|ΔlzPaK3J9IS3q]aׇ7FpI_jK@fqò;)|pnv!v1g*4jiu\$Ӡ@+Bק60Fĝz59dڅy}QZyʉֈgoqz:Tj:CnFB)N;y^{Ahh4!cآԨĤZiwQV+w7b̜Bs-]R>P m+6Fmx9XaM*=+XT$|$QBa2X1Myo«x:^Μg@AGA3C7EodFPWHnt6W\I Uy%w6E4< Ag2@kaqJyЮys^#}CmV+J^YxDג@ ֚ lN{|أ%Ӹ TL'Yo; ?{i_)#GOV8;z"y+`ˆPt5U_E= l6RDZ:&HbǗӔ){]JЃ+;H%]: Ʌڑxd 4 zݚj2QͰ $%#*I?K!1=v%%e?YBR׉4q:yA괥|us*GnOz u `*>j]<_,*@7sg5+`%G[|H]uLoNX>;eK$ !6ٕ,M6nF ['q)\^":Sխ9 oJƬx y2J?8ONU W@r΅Vv^4W6W8@"aUUs| %mTkrWZ>>/ YƼ@SRƧ Ƥ Ɉ"e.}IKmWЯ7; m]ZH=N.Vr䦐Ѯ?,b-Ij6 Ma N(T:[.͖~FN[tXk .Z#x|1H~y`jc{;P\}k 2Cï^evB"FzjF 9R -j>-`+sDŽK'j: ]S(_ W~ R6+H!Keڍ QwmYM$ߣp]vsѩBY/u~tLo^_]ߍ Ee&.ۇ8:͎u)R )ZkGPI-hں+zT4opO2B|Fv j. Gl_/<^b{ uPVV~jjgzf5D?#oתޟ_= ")%P@*uAfuM/ &5|x帢&D=)izJ&-':o;1l`_+5!).*r-]ib MJmvΰ]1$8 M/\vf$`.T})1T(Frk7IUZ2&NZ=iOFm.*6h}6zpi\{M f:yhy[DSۊ N&AMQÚzV{h ["ǿkn^͚* o[vL2v>cv,E"{aU:X;2e挮m?q0 Fd mIKˠ禳7p &q2./󱸺(1cBʷΥR$p t:ۀ*p_O= ]9 {]C^P" Cii%j xb"$s6sO]j c'pd W܌WBz-: ]/dNp94-_O ix|K昚X:1[XjGyo %8Ehg{xeiNK$)!IŖ:C@o0]pR7Jƭ.A<(HO?7y)RH>T/U8j_46K SMO7Cg/fi&OS,PUksEkHH.+%@ ֌`J2 5cg[F[U`;4c ,B #_( zQ^@!V:"q&63Ez%!Tws) 1LԦn&ҭE1 |@(Z |E(}lǔGVE|+uV!}k &p<[BRbdl8*ۯƳI)صs{3$ڐ) LiX_DtD jWiBUoQ\؃1itL|K9w}h xrȘlBourć e3FI1w:q|0KJbڝ>U9_!XvyploSUU(Zq^/P>q*=k/[(odv|58]hIpHpH9`X5jb;ACs-P*njpHH8ڶۗK.VS u1l'] ]Xsʣ$X$W^DJ!nn/&f i*VNߋx8n~ NOgF3LR‘m픹DGWQo2WLl. S9r {^c,MC2S.[硯_d*'_nʽgv71NṢciSv^(,$)U۬}̷OMx^nS҂mNh7],[\aF;Qc!$WDN0&iG󴣑yspwW!}rfAw&/I-^2V"CLm汉*ϙ0_|{uIi+j\Hn1=L2Us}?RBRh_ֽEmB .q'pTF<V`77iQG Uq}0VVvS&2 < 60uu]i9K,kd!e1!A2ge ^x>G53ee kV׋ᜉeڳ cSqLjھ/ ˍ>Fчqy|T.1V?L1 OPe L4tM]s*>Poqfú;ȭIcpl^Ы'Tآ#5M둴xP{?SL,Y#61SIZ%0&N"R"Ǫ-B[} 6O1%Ė;{񨽦Qu jG1AaR-Ib.sh =I0rLlE 2&>Lzh+N3JF"0ހWG9zj hj z|AEN*;Q88z+a{p\`XKu+"]o2YO\|jy/M=@=Y^Tgq;cLxF:ZDQ{+;ZPNr)`YB uC?n D(ugy,GM{[%y_s[ALc:BXF5YFc?7Ј Q3/|T6 ~!Wh9De\'%b1Ep@Nr(FȹL}&\솆l_{X, #u 'zj:xNJ]Vsgi>C(?:`Q/:5Wu},UNl8(5|2r.o3MQ_#^i)N([}v&?gq?6P)舰ذ[ :ssiۯt 3iei恈݊)~?7 aGZkmנbO|by4wܑ}F&)+lYaO `==/sHμ{{~!qF?9 N=QN0A#\*jg zP NGZ3W_Z/Z׌S8>p}ҝK:q5Y&3𖼢VoXnVE&W&B&Fx=eZV ,`_Ǧ;~p-]WT& }?d)57 99p,xy! *{ʀ'0>$i]N4kD&*b+C oj6Gm&n>SH͏7?C\lXI`v>GXCBQ:;C`zk|e le{tt-CܔłpZC5en O":'G mf Qp!7;``.S\* *5 K\OӒ(y7ۦ#F.rS,C<Ck)?#"ͽbfǍ &*Ļ1ġ,nYhUz7gS}kGC8/6z3;=·tz%q9Gb uRvdr)+zG&چ/M֌NVA#`ԇdږ5" ad`L4\}p4%RgLyHE aV I]?O`[xXrb3L@c)gc # V}Y"cMWM1%V-C3hS}:`"iKpBJ(3bkw ǧڋgKu4&tl#fA]f'U׮蓹ϗ'0"+РNPЖJMR6cU,l+㫰0 ogR~8~11I#x' @bR;~t/ṿ_5|YW4SsEw̖p0CUiEM{1G ;^4Kd34+ JF )nijGO?yJ8~KCf.:ۼ{TFsY=Gߞ\9oGj|"lɗRgv5C6ě Ll$)M;6wԶoy9Wlz"xb0az~f<pU~nwdvl_~|KJ,ʹ fGzdħv?Gcwʒ- M З$_"wIhjN߅DvW)k:.xFJ7TLw/&N aEz(k宺ðB|Ԝ0 M|W“_hk|ZBdVf=KO*MC1r\:.]>`A7>==EXsKTmW %@jbC!l‣QLG nGY: c"eJlo3kghvz7KMBE5r(#xCSIbήvgkYU&f͐h(_3l/Z+~wZ~SR/ d/bAL>)XeJ|.C7? ǧ u @ ˆ.ȡLOX -0#>2r2A ^(Io*(H_k vZ̈́;O_Z:ޯwjzvW\Q`1:M ):V}g*ΠgU֭BK_ >Ҫ<9,0esb-سJr 7ehL&թϳMCa Yr´#/xd|r<ѪE'vSwלLJZxSCen+789q?ï0EJ+ Os=#=U?ާOe%Qg }ach%OX7j3Lӳ÷eK\Åf 3 4dKw6+}5@fj+*{ >j<ߦBVy~_M~BQ~묜F]r,+=vv#^v׿A |x~iyX?;<4г9~{Eͭ_,A[!1&Bj\P$ _BRPYkb{7j~ޭAh)#уR^`T߉yDqi\6Yʰꡳ,69mރk7=,,OE8 n937*HʗM6 ,w9FxsDP >}DLl][\H٠$=Aɬ%+77Pս V7cɾ ۨQO^ 9!8.q|dAqZ9H;ҟi.QԐ!lYRINб$eylmbl@ڣpe,c r r2Bm3t6ܝ:)$F;=w? {!1gwZu'D!>tP^0v #Zz= Lqo SȊ& {FhOBMItP l[?ZR*3+5e/I@kCH[l#>4FuA3[T HC;㷯4cj[~Gr_\M7-i0<;ћ Yqh5>+7O_g?MKo[MDqЌ`3/b(߰mD9l#_}=RHp,."!Tz:2 _wSu'8~z.ddnG(q*Ϩ=fǼN|icvXM7sjsl p Gԧ*qSo]YI起-kB85 I~h:]޳󗰧=`7}zilFe=J60v > [~2_ڥD4*ENv˴O8mGt֞1S?`ErEqYEη|,vLP$,<'ڞ #.&[ /}.~/i]@ڎ`Q,{W|$TڤMsMb鉖af JÍa>M- i=ߕ#70\Mɦ\k[ 8{oL&>  JjER<rtHP/m`'I鎙;{T/N3̧? )MNDŲ&OeF'`=цiܱLzzzO? Sج34$<ӹS!Uc9[#V̍ k>"<[L9m@p0Ǹ&-(H?r^kI( bJhp^7!xZ=:@^+^~(?7xtμaym$)ȧ HE%3&8k%0b3$7׌_-)M-Ľ<6̪[w{  g>M|f|\3%yifs0 ef6&;]kEٯo ]MA䬼Ρ[e\Bo>3tAr|@Dmx7zG!@w Hs^TZ%E$?)?b!SJjѴ|șS@BIp~:sNQ)W]?rQx[G"? R | !l˙c-a#Ul%FY&UF#l)^4Y4` -/%Bp.өiq{r9=wBNhivE`Zd:j4_ kQMHq=wbbD,AflbڳPgG<>Zw|6J{}oHE}dRJԌUвa?tEsH͢*0#N qw+pt׵b'm*"'>='S܋뗜54S< YtoBLW&2;aL> Eϫ9K(ճӁTsЬE.I*H)$UMU7Kbg̳]rv)Dїҍ`!~F2m}ocO~5h*_ʔ\K֖ ^Mfp4fG`2 m!pc .O?i?jeJh%KqaZE]~5SYhǼA^3oX32iXС$aomGُ5뵎㿖n.5]B?( (cwO:k|ۤV;YVˡ}Ke+)tęjbŹ /\-B{'"Ms3@JP;JZQ#q盛Y\ f ڐCA=~40(s$}w<" =AC8i™!56},ooe1Yd.=.f I>7R/4r2zzH.3/1" t3! M?XqsJͲMDdm8{őFqi"p0ʞ+dHdbEV5FF%je?Vp.=zl[? jU-Njua'Oe8`f(JM_u3[ZIa@ fۄ-x`F> Lpk/b]c,Xth,y99)Gu ϖQs&N7(y]$W5Lf_[]&W1>vU[CM:3{᫛HJ}8=88:Nf*"}\M.\mJ XCך:Ը.Yba#%~I6 dBҘXpΔm{pZGesV1zS?Ar]!Us+2ҊD8t9l0CpB.D]GJ 3 424"gV%@(m-BSۑ.C96Y";@Q3`],A}홢ѫGXk ~7Zz2@% ;~⊯3֩P`Ck˧(ոN?VG$R^DFM\[̸k #ջ}ce Pvd󼹛õ0X"{.NbU3|PNYvfJӱȜeBs4T!uk(mr7ٜ<9h>+xZa2@ - \ Hv8ƣJ!P'PxYVQ_I> sǫ_pD]+u`SjQbcf r]A΁WI*i2Ze}oCѢØ8Tg`Jd1@ED$Gt3 ;61NfݷU^l `]vTPzn0͂#kEiΑMAp.KM-]{^qՇzKκ v9+lo.n4CVq-Y4@!>a1036u-ǜV#Ӎ+mfsݙf2}[<);A}&JWű` <.p\-Hk[b(C!v ^NՂU;A+2'j[K߻vi5Zp`@,N]\m2bo/|jM>Auԓ=v]"AASlB\peIJ3&vAk@o 1=ۥ\{ЮRLvT+W 7ڣP>l|+*2`Sz!nx(=Ӽ{RRV qI(U<^r-L|+rY(:4E?=dOc|IV{{10U$P w7(}Fԇ'=O^oȝ̨3R*[\P SK}J|kTAR7m7x:a0|9n#$lI_Tk]jp _ϵ@=·nR|"?9TIZ9`VcW6a]8i1Ȏ>y;9-<1^hh4%'OZ`䫜#5=(ۿ{ܗ1'"kZerY}luj= .Kn4= H%5[lU7&-Elq۟U S5YO9BޡOkFBol"h_4Yd#kUb9{[Lǔ2,.*| X`CB T1eL"ebvHCYRo/ ~Z{˜ A NJʟ_Ɛ~)N >EE@UOb!| V]oO W͔sY/j< [woc3rY@9轙zI*yW0wT2S&Ki;TlRq-qb'M42娣[,;c<"T!{]qdt|A٦i?ވ)mL٧YA F1ʹ{mȳȿ 2)ؖ#<kU'n'b-dm:닚NJ~|kc"tW`B؞Ku=޲"ɨ%v)3$>YoyŃG hz# {T7|g&pimu_-jhx4/[rA[,=D?X4$/Y$yMe|%MuPvC"e$|Ҧbׄ: K-)\(hÏy:Pm@E @VS|Vt iU#27z;!9Ui‹Gv UGq`ý ҒNƢ,r;A+>0&9͛;8G+~֞k