container-selinux-2:2.130.0-1.module_el8.4.0+522+66908d0c >  A _suU]LiIZ挆6_ewNe)/6 зI²2LKȡ Iuqo[2vv|Ս뒋?:1xJgTtdkjѕ _ Ƕ&DbA%^F8L ̓/m9^c i{јKM084s 4S\8#Zh/f4o28kX8 o:MoJ |h=a02f5c4d77b30ea3b5d47cc70148ac1d7d75065e75a9c1334756bd228516fc207ba3de0c804e8b5a786a9aca740696bff36f8056_suU]sFeZhŧLbVer Lkpu#呈P:5H@kPڢŶm 16c/öJ,V= a-PUma'3N54M y{,UVSs.,HkEy:ꅞSwHZA [TmfU J7Pw{ro2*N=KL-el 7 DcvY0x/:GjiC4SDм 8jJOuManw9Ȃv;S5U@x+!uЎkk~7^lv\Y]Bt (t4>pF:?:d< @ h 6<Ck    @     0 X     T T( 8 M9 M:3M=4>4"@4*B42G4TH4tI4X4Y4Z5 [5(\5@]5`^5b6d7e7f7l7t7u7v88S:::::\:`Ccontainer-selinux2.130.01.module_el8.4.0+522+66908d0cSELinux policies for container runtimesSELinux policy modules for use with container runtimes._saarch64-06.mbox.centos.orgCentOSCentOSGPLv2CentOS Buildsys Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi)M]A큤AAA큤A큤_s^tx_s_s_s^tx_s_s0389dab4c8de315b75e65f20f4e606a015aac29056e561d6f7cb6aa588f431a9bb42ed8caafe82e1c4c84bc7a8b3fe2b5aef929064660662f8b1d9f46916b726433631ac959e580cbbc4852eec01d4a1c4c1a1e356198bae8bbc761526cb3796rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.130.0-1.module_el8.4.0+522+66908d0c.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux         /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sedselinux-policyselinux-policy-baseselinux-policy-targeted2.5-113.0.4-14.6.0-14.0-15.2-13.14.3-9.el83.14.3-9.el83.14.3-9.el84.14.3^k@]@]7@]]@]|@]@]X]W]R@]@\M[[ͻ[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.130.0-1Jindrich Novy - 2:2.124.0-1Jindrich Novy - 2:2.123.0-2Jindrich Novy - 2:2.123.0-1Jindrich Novy - 2:2.122.0-1Jindrich Novy - 2:2.119.0-3.gita233788Jindrich Novy - 2:2.119.0-2Jindrich Novy - 2:2.119.0-1Jindrich Novy - 2:2.116-1Jindrich Novy - 2:2.107-2Lokesh Mandvekar - 2:2.107-1Lokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- update to https://github.com/containers/container-selinux/releases/tag/v2.130.0 - don't use macros in changelog - Related: #1821193- update to 2.124.0 - Related: RHELPLAN-25139- implement spec file refactoring by Zdenek Pytela, namely: Change the uninstall command in the %postun section of the specfile to use the %selinux_modules_uninstall macro which uses priority 200. Change the install command in the %post section if the specfile to use the %selinux_modules_install macro. Replace relabel commands with using the %selinux_relabel_pre and %selinux_relabel_post macros. Change formatting so that the lines are vertically aligned in the %postun section. (https://github.com/containers/container-selinux/pull/85) - Related: RHELPLAN-25139- update to 2.123.0 - Related: RHELPLAN-25139- update to 2.122.0 - Related: RHELPLAN-25139- update to master container-selinux - bug 1769469 - Related: RHELPLAN-25139- fix post scriptlet - fail if semodule fails - bug 1729272 - Related: RHELPLAN-25139- update to 2.119.0 - Related: RHELPLAN-25139- update to 2.116 Resolves: #1748519- Use at least selinux policy 3.14.3-9.el8, Resolves: #1728700- Resolves: #1720654 - rebase to v2.107- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.130.0-1.module_el8.4.0+522+66908d0c2:2.130.0-1.module_el8.4.0+522+66908d0c2:2.130.0-1.module_el8.4.0+522+66908d0c 2:1.12.5-142:1.12.4-28container-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -fasynchronous-unwind-tables -fstack-clash-protectioncpioxz2noarch-redhat-linux-gnudirectoryUTF-8 Unicode textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-87b357ec2395b4e2d3bf44905ee4590fd5ce5934cbfdf12a659432eb356a39402container-tools:2.0:8040020200929214137:59631bd5?7zXZ !#,3g@] b2u jӫ`(xy=9L(dd_7hdgI77zX]eP8*qli)K`z]EkRxdZaJ&=)4Sn}` n/_b! Ԝm R}ۮ:<)femQ6['-QN$+6Xt.r$KEx0زm  T,^L1_.)hU=)Dizgm"CiNZԻQ 2ӭu]p4詰b"G4̓~4Z.e2f?ᝩnc#9#|XS xq_aݥ%㩕-f D [SvcGy=,Id})L)kg LdJ{Ƈ'v&(r:c#\ob+i%lQ5a0͓Zs#fX{iΥ5*x'v=Lv1ŴQcOwzIHsq_s8?H=K#7Gɖ߄ 3Ь>܌kmkZ?]E~ J JVwls>|$W-c,"niI~"7$ɨ;aLPvt?=WrchPmxNMG>'Le; IUBb#MmsBu;`[ZaF`&Dj<~IV24huQE o^8,[ ް5:cw/Gi'òβ_1`"# ieNdz[mszĸMCE!bfƛ8ЗA+Jj 0Xq%!rz: ) dBu rXqiWtY YkOhᖑ/Pkq.@V0+* ,Tv™ftEIp!,78DȤeϳe x'50IM-ŘcLX'd#_<\bIf;̸sWsRuqh5h3}0eD kBl~ wJݩOO]lEW?'/ S+f{xNOs_0Ҧ ǻn:]o%ZW%g򾍬#fMaezdKukwT|=W:ءcTX'D9.ߙZL*ЌfBc'wS,T.Mz?e! sw;G쌵kMe@ri8T&(1U˷j g:D0t9i+G4I`̋g#.rdDG:K J纋p+{8{"eGxm]$^ _S8A{3{gJU%^ b,+bIsKAi =kr_G|CqZ [#r5 j+j[`DL#hc[Ɨ|=ٻKi #|T7$$ŐʸV=.5l{UFҦD%59,YB{jZE'=rtso#u:;%}g]~y\ݑՌa H4yLD9VK- hKo6̏hǫp4d| 8aՂV;$4ĜDi$S-a|<$I#LmhߓfQR ^FwBQCRg'"yɅ3`dH.ь ]n"79gElF PHN+e/șǻI)=?H8YVqM҈V3cwߞu "V浥!q[闻 w1b8l:EO8;G $fKӎ XJ.DJ1֦JdHuN'gro)a8*m_Uo瞹UfQ q~p{X*)khCPOɾhqȹ b]65{ndm.H8x-6&hExzz[QkLo|(65iùjM5E_JTa+ @Dt~'1`yff616De!m oYзĿx S}*w bU:}0 :.k-%K/#mSSSg<__rA` )@(,dYw*" x֩䳿h59Tc|]J"X=C> 7@m&!#ފ|:3L\DX]2$WEeHƢr,et6I!^) qYOd^B}^rjdfqm]R.wY->\Ypf3speP21Qy@e;9- Z/h[,Hq)ǕVʈb͢o`PH܎i;'T S8Uݲ38l6pGj9{(B~KN]L%VylRNsytoHI|QTb[n- +҂/Oʝ(8pdbI/ Vn2K7ѥS`jKdǚʓnq<\\Z^߸~>$ wWeAc3 (`L`HC OR@ƽ,524s=Zg|>J1HZ)z;e;f7 N Б~ϕ+ 7KܻNWqlnrB+Ċ}4څwKJWD7z/  ɚIhyMɻWx@h+!1dqk>U>}@)pA>Wߓʡ>;{}E}g0W\|L2qY\&Aޘ{!d8n*YI+>隌^isI|YH'-<h]gwh@^]Zbd:bOK^.#.Jsaۈ R.fYiŒaHo6SwC!y\ȁpf&C"iL(,R#n2|k+7dk:ƕYyg +C ;.I,3D5 M65|~>G8Ћ ,-vAi8M8w󧠙!Wf谸g[}BGtxٛO9[J;+ ($rc$gLȀr6Z$X~E*!-7}>t/;+G}lIڣPrMSRbAڻ7`0XV_+ K?!SB c;eG"Ӭh`mǑ}0AR8-؎S`kX95]ϱ(d(.mYB3iI\UҶd]r6˧es5o #6mD} ĦI&[tGZtjcPТq'vd0 xݳ_< ї7>bPrNDE\N˖6J$N+Zb`3@#q5(h `$sDl98C{eQ ҩQvkZ7 ft?ɝ0KbͰ(r{_rg-Gq :v+zT䓳;Ά\CU"v̿$pD]bg{ 4Y]E8KP B)'Eq;eR+>zsKa zX:P, 2! w /xhׄ ߥ S*6 c &Z2Oü.zqdIKG;dz^I$R5SGy_wC..XjW}Hjf/R&b3uU~37ET`Qn6 )̕4 O"P;P\㬛NOs9t,RJC)q}&nJKEd(xX muP!y6BҽfB dyOFgkxq1ֲ&}&fTgOH7ȸgqBUt"|q2_.@K럜IHM%HUWR}8_RD 1yH -w!'oY}+9Vم#Gxԯ2w=Z\JJ3j6;7&Q^'ʒJPH 8^Vh2Ee\!ctk^Fa> ςOg;鎯M,b E Y5Z6|B᳏%}8*=㎚ߵ׃i,mAA7 S:IStA:zӼ1VsLPNak"OدS#kq=vxqk(T 1kb 90Y{*Hϯ >1: SzսQYw[q}阊(8ŏmZ?r5ThAέz%>j+5͢~rAť ebx _.<E1 |FW˳>cSXro4!>/ial挛kί&h!r]ۭFdz;c0Ҫ ,9a?6܉>'_{t! u^]v#PEf;B/[\لwc8/:_1l#~cT9^1+ḃ$KH1Ȏӑnc8&Ѣ_09/F /5Uqy̏a"&%'gTqD =j31>46wfNU#ƇvJsh*R]s:ฌ ]&oS_*h!< 8Ġ[Z(/?K8.U 3?WMCo=) ů#v?W}p8b1]9ks+pQ 04Q y'e6[S?E; G4j(G7f d\K' (tb(䘴4p*"~Bn2 +nE F^D%l_mPY|0gGC X_ 74'Ui ibYp+ސ荆"cL^w0;d4}vM(촒@Rf 'ȃy[G+M#Tt5(v yF4;ԳZz\RA 6`t.3~f9l"Y>#m.!R.?ZG+Rrb1hF$Lї*YM*+o\ :STlh1#hoj%W1F{O3bxEߐfu_$qaV"I-w8@+xͭ _SY1L RmY|;)T0VWp2yNֈ-W5 ON=EGC9qa @-[NS@e PGJ|SF c7 ,v!l]=0c 144 ^:oOn߿}A 5ַ1 D sbx- Tp" N_nUM$z:pwka϶Bt`mS ֕b w%Q A@̙'K~Z!G^'{ 5B[pr牻ϲsCc . ҽԛx_в-]톀d;jJjl2)БlB"|{=4bIPv5v׉Fmϋtۮ3z{[ K# 44I^) M # 8Aj 24))S@#,*b{6Ru1Sy zKŷfy81+\c fs{,5]C!m4EE&\ fڗbKlzO/Vē.;[y-](1=k|؟rS4Dz*}"zOΟU26`$!nGsMey,>b`!S l5tm:~h<>1ѫ jFP҂hLa%G ԅ=+ZB?OXunzu^س2qaB#!k?eX9|cç:bo% 9.n+9&:Ph ]ĥpw,A)>n&9QeY d0x,(\pm;L;oX_ :ף)ќ[ {%K!џμYBʻ|}*[J ՙC2ddc5na!Rq=Ym2P>wJ WƈR!Whe q%~Xd˱MRL5kg86qڥ7Y5~Y -Fɶ$d,NINM上e`lw)GY}^BJ =sgS$[ae{䒽reql:=: [ۑdM ,빥"Z_.R\;QץÁO hEJ~[tTzbUȐbZLWk럡Kh`kwA}n}?M L$)Z´P$)jf[l^Qn^xlY<{?W|SKB#D CC8T1mc `N*Gd%|Nl՝ٽ.[}Q}0ޓFhu*$Qퟤ}HSGw#^XWถ]k{Dٌ+m".5.:;>WZ׃fߢ27˜|M uHRg,e.8(1 |?%nD6#M*%M>vhߘcOϴx(`GKN]Oeƥ}:] !f7Tb+Ӝc,(8\ǔ5flx6(&6j!H&5E)D0ɽ,TYQ~_u72Hs2ɣq2շŭ.@ [fi<9Fjnh٨ %(7D;G vV1Ps.Wtp]~TN'8?ykm:+rydv\| eNq-.xoGJʾBn~WKY7?=/}C! Λ|qR(PL5N7=n+]ɍ#Lx+,rI&=٢;>2EpRҚKt'S6{ΰ l@"P;[W(d~ G:)_IMJךH<33Gs$̢+#JQo?^֮$c,/JYgO_9yn bpפSElrRy]ٿr{+ug;p'zXtnf^g!XJtIm?dN{Y*z.*8]VZiLJ;Ad$wѩ ?N5Ɔ3rrB.VQp6,$w竣ߓ}GJi=lʔ'(|zJJl@h/<Ԇuzn@vK{-L?9Nɧ5yQ@AqU-jXJKsKn h』%$۾*ԇU t {"A_V 03DZC MD`ks"߃ˎ*729oE@:s|GM<Nd=iGnlbDtgˆ3]"ܧQ: kƸfzPd*'JGw9*[GaWa*kMήF`}l^}yS}!Ŗ\Ls_ #~vP 2GCJɄc:I>:ArPP?9C)NqA LZ\ \-[x>j!njZrfY 6oыU;>MFuHtvz3dVc#p0`SJլ<ߗQ#|.`<$vb~p9ۀq Lmz7Nܖ@/T2cwpJX tAl`UWeѓ븫gA{J9U @4)v s!"yp(=^ò[atWvFYt b)uFR`ǒbջ~S^i@ߕUgoo7S|__LS"+]e[Wnd\Z{2Gj^i+/;-!mkۼ#1-ܚԘ ]3^)401OÈW1T Hҟk֘gOK: ZK/|^Ծ`WEӠ9EҹŽS٢TXDw8AS3`<楮mnk> ? Q1@/W+wx)g ىY,cX6H9H:,{2/r2#tY|ccVQg^ l&,;;`S t~VYY> ]KRݙ35O\T_s˰ȋ<PI9& "3iw>N;m:'lѬa~SX |[ "\ N{:Vбџ3[j/^.>ǧg"3x^j?ӯ9t26M}5FZa ͖Qb+kj%̜sQSħPޜ:. Ǝ.j!;)'@ssrIS]-r7lr !~#༭-v(gBϒS顚'㪪7nè/gM33fw.8h3EqQ-Ųjb 'N<ېf#wi,dyɨoA-m;\z(^?$XDi:)O;YX\ωSq/kQv!BWF9N6ӧ]M)oSlJBٻ"y7 CK'9cz25?~ml HmQcI$nط:Iͮŏ\ --g/K5ۦ;|U-E\?G)l?xXX֬HWHfu}ǿqq."< Sn*5ds8kM:LLh^ w{A }`f]c>!L<<;|x#f9D<[qESjB|(b,$bKĶR:§DɁh{&\PlFV4i6Ibˉf}:R~8DZ{&ꑩBlJrĞؼiEwd(ܪ2헝JLUzR}ۈ S9YvT{M ׹}_! Rxm3}6|WBTKȆڔ! Si\7aswѯ \ b,6YtV_NBi&xtn %+-8#HB*Ј<U$p-5!k,N5DGN3&n7q<9::faόLyog1ՍQ=_f]M/c]a0sA;{US{$!EgY +r M.{cQ{JWCsS^Q轅)is Ѣ ;`]$EY A5Ҧ͕6Et_u۬TݍYǤhhzT@uoԳ VWJEhžlt"c[>qJӝ B3.#-y>ȧoڊe R}2#A4Q#hª5Pׅ=[ ؇=HNSC^a9Ʋ['/-L0zߩFޕǨppz@VsEosƏ; LX;9b]Lc=" yҘ U o0YE'n#Ma0 @0\lc| fߥ~[DluuV~f# bʡf+X;vս!n4QM)\zLgtug 58~ʜpJuZ ܂>&$KչܝUrsY:==m* Z`uJN' {ԯcOY3| M!m=j{U;t8yӏ`gɡaR͂IvfCXJ2a-Y# tgg2hGѮU߀#Sy(ݮ7vDܪ''9u!euXw'K/cKߒ͓E- 8!twGE[hHl? + FT빠ɍ"[R65*j0=!hէ:{{jBE|DI:Pe~bwq;Y Xsu >*B0[oD!!sddNKʌϩd^1=a OWS3yzV~>(cOz5ftK_-^:#S!ѝ-Unځ]XWjU^]dmݏA Bm|G+Jfut oJ^}הҵpj4+ __{l 4=cfO Xީ'E!0>\~#Su';N:lS_A'lG<O. !Zkp%Z)AGmz;2ɁƲ#hʡT-1¶*!B(/Ty }2-}%~jCzD($BakC˹HYgyFAn PzGM/|Lz gj~ͅVtq內&:C*7^H|:-iw-QC» Jh?FUFzDz(klshBr4 T|;4x5-D<́'u4<& dy 8^^nEz%޼mQ/&g@pE OJ dpU%̿JtҷHy D DBof8M$ճuE|P};k5ȋArX/lmJ. Tfn%LmIhr%Ź\;8 oWɅjEiKFyܔ'K<*JoLT?lU>R(C'U[P`2\ b޵б,wc*DYPxGCT['\M ~4ҷT*x{~dI?2Dw*Woop O*!`RSE&ºW{&67zIs .(Ȩ֙9Ù lXIn |]>AQܻu7;QK Ӄ{]f9ݛzE]31HոHH}׃( t|u"ʚ30DqɈ(! e+o?+0VAcU6wQj nvSCSkҳFJhz^{! I3C3_+!p$kP"7tM&x#gjEi^9;?ɋ-]PÇjIUDAJc8.-1(zɓ) j8=Bq]뭎d&8 cA!7j_㻧U8_sB"N@W 11[#9_ˢ| LR1ڻYm6BIтvgKMd} U='^,SYz?{W,<|h0ܴO|[ڷI"_牢ZZ,]ѷh\itwX"@5ڭ]_ uW:4+£q%:Kn* ᬳ+.F}I7\U?3_E; F,/D}0[VVfVJ2T>/~DB_Kjɽ4^%uUF^ \lo"ԽNM~Q/l6I9G!R@޼ZoSvsbhh`h,(brlJv,Őu6Iˢ"DyXB#R|%>ea5MKRo=0W_=qj%z)0h7OHԕgJQ4VAf~є/" {IMa8ʏ犹xvU#Fx +%Kp#u9!:o0GDãH3⴨Uڷ0~ɭb?\=RFf̥[4UHd:HBR;.z RF<=Y]E[lHhfrI4V+;54ƒl3*%> w3$7]d û7) 5 \(tNBزw0BvU gS`fk|QޒN*[82wRHR4ĩp+%}" 3ֺ;;2`NZݍѓx^(tpD; 0Num xdZ{܏۾H cYR $>l4ެo' m@0Uw1%R q@|yEwDrСSŪ7(P8(^: Gst<~'ǤveY'/FY|? [ndfEց2X`vp ϩ[;%wFDSpvGPKֈͰrd$hٮ܉[DSzw@ݼӂ"h"=co"j@+U6ÔwxzAu&x 56!sIs+PcBDt+U97zA,0ѵ-;fS9V*#t\[eAJ [FG\aE .Ȇj\-J[X-CDNrLތzmazB|嬧>h[w>](ho(CxWhsJe*}bnѿIM8>7W %0Mi^e>kL B0e$%Sy"* J"BJ0LzO8t\I^Le}SS]_Z3̢~ ESi(寐k [4fVx q0/B-g5PL'q*`sT<'x 3҇t 5%U bl7  c?E>'2tVt@ @+6Hd`bz[GAo# Ms\Qub^@dtwS,db'5FM!q{-'_C]:yx(pxv>IpNl6vH7<Ѐz|Q_H7McL]o,wr 70C *$P@yԙIӋ5;$w\++k/&N7O=SE"^_cB02eCʩ@"` M_lmL_mxXX:6Re}\uWJg>kmu3,U|+V #'t7:=d+wRdH}FH͟1 U6a'…v G5j{tE>a޼} karVi‘Ʃ3QtY},ߘមm_Б|.))e0j@Y ؿꃘrل.@T$8w2xZg kg8*kOX2[^,&= m {7lW V}r !$c܅U% a(FN޳:}1էxm}/"7B\d' {(\^4Q22<(E|CR9'dK H`PJ8{Mj1w Mff=8'*V͟4/$n0dg77 uT<۵Oޟ3ht41S I'6(12ř&GmXBiX$HNNVT0` =+_[nn6aˎ[xlIc"O>H1}NSq_# :$s%96#?-Wd DU%/E,oe qt :ѬJ @X?[!CJ:` iJ`T/Z[V] Eq*%wpiq/V-=A*=J ^G[EI[1UdG];߮Qd q>.&É3-@K%%"rشe!4єa_b|?>^AVQ,W#Q:Yy} ׋H8gPJ P"@/=}2F(}jϻ. g%!Nrދ2oh}I=@[dl2tO&L;@[9Q%9kE ?I& WaR#ZG3\.P`w(yӤAb.sL" MzҐ6A($_@=Ik1t7Pvss'nG"2KnR-K3a5/YplFsXz2\_ڠYҐUSH3u[ZwěyKsY;}$y8vp5h2op.Bk|Zk1nm ZbGB-+BYA1Z0Q!vcQB;72-nFh[s* )[cGH!У's MB51҈+ěNהQ!ĄxėWp^ aWՂ]z!* <9YؿWCdwdXQL@ځjB?> Jq-sU"4}DHXkM G *3}(ݐM-n ͏a3GQX6"jֹΛ(fq@ e^h)q&76%`?Y[ W*SVR޷{Vt2q"nlOz}0%&]|luhð e*27yiG  YZ