container-selinux-2:2.164.2-1.module_el8.5.0+877+1c30e0c9 >  A aU]$ 9!&B?HށGq,eVWwnkfpQ;w[8xЌ1|4b3ߠ:+d#K0W=Lp:D d92&Kfog&kyqfE\eem„[IS=eW5{D@.£wzDGvĆ6mޟU<Ƃ_t OJ4|kGd 8S(E͚Rx)cEX3sz8<3t£JEFn=*R;*^KuNptkZŊ) P^ Ъ^pY*vANB P~)_ % an|e!Bȋۑ7;X6Gw! ꛮH rG%=2ٝ%yD`.h4ӀKtVa> ضOkVQWvXgL͕%-8CǏH%~\b$7~KK;437edc871df7358584ada6b64b5cbf1baa0ca7ba0f03d587611346cb222931f7921d6be8a30c81359303706ef2f068798f178727aU]̙ofF孕2 aOP0G^ Ra\,O!>i;S rBN! Imɺ CSA/D6|tUQ,s)d6rvCEeHؙ_` w6wihr2OJo{\\j@y>}E0 CKH!;pDe[uMYm1mD1ʵI͂a;X4N~ZF{QےzLp  tm`f- ib`t^OhGBH+{VŏL>pFM?Md< @ h 28?x   (  <  d   n   x     D  l   ( 18 8l9 l:!l=F>F@FBFGF HG IG4 XG@YGLZG[G\G ]H ^Hw bIwdJeJfJlJtJ uK vK<KM:MDMHMNMMCcontainer-selinux2.164.21.module_el8.5.0+877+1c30e0c9SELinux policies for container runtimesSELinux policy modules for use with container runtimes.ax86-01.mbox.centos.orgCentOSCentOSGPLv2CentOS Buildsys Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types > /dev/null 2>&1 matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi6)R_c1A큤A큤AAA큤A큤aaaa(aaaa(aa8c04ac861d425e9947eb5bc06c3125d682dc981f6327e789ebe1c4eba0d856fc0389dab4c8de315b75e65f20f4e606a015aac29056e561d6f7cb6aa588f431a9e194e1fd0b409d85b63543f76708a9035dca5d5e802b7f61527156b8fae903dff46ddeb8e067b9a26ff78835ee75a32291954d7295ad7b7a1ed85bc975d4ad35rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.164.2-1.module_el8.5.0+877+1c30e0c9.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux         /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sedselinux-policyselinux-policy-baseselinux-policy-targeted2.5-113.0.4-14.6.0-14.0-15.2-13.14.3-9.el83.14.3-9.el83.14.3-9.el84.14.3a /` @`9@`Ȗ@```q`@`@`N@`@`dd@`Y@`&m`_T_`@_%_%_F@__"_5+@_16_p@_5_X@^n@^Ӝ@^@^^k@]@]B]]@]|@]@]X]W]R@]@\M[[ͻ[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.164.2-1Jindrich Novy - 2:2.164.1-1Jindrich Novy - 2:2.163.0-2Jindrich Novy - 2:2.163.0-1Jindrich Novy - 2:2.162.2-1Jindrich Novy - 2:2.162.1-1Jindrich Novy - 2:2.162.0-1Jindrich Novy - 2:2.161.1-2Jindrich Novy - 2:2.161.1-1Jindrich Novy - 2:2.160.2-1Jindrich Novy - 2:2.160.1-1Jindrich Novy - 2:2.160.0-1Jindrich Novy - 2:2.159.0-1Jindrich Novy - 2:2.158.0-1Jindrich Novy - 2:2.156.0-1Jindrich Novy - 2:2.155.0-1Jindrich Novy - 2:2.154.0-1Jindrich Novy - 2:2.153.0-1Jindrich Novy - 2:2.152.0-1Jindrich Novy - 2:2.151.0-1Jindrich Novy - 2:2.150.0-1Jindrich Novy - 2:2.145.0-1Jindrich Novy - 2:2.144.0-1Jindrich Novy - 2:2.143.0-1Jindrich Novy - 2:2.142.0-1Jindrich Novy - 2:2.139.0-1Jindrich Novy - 2:2.138.0-1Jindrich Novy - 2:2.137.0-1Jindrich Novy - 2:2.135.0-1Jindrich Novy - 2:2.134.0-1Jindrich Novy - 2:2.132.0-1Jindrich Novy - 2:2.130.0-1Jindrich Novy - 2:2.124.0-1Jindrich Novy - 2:2.123.0-2Jindrich Novy - 2:2.123.0-1Jindrich Novy - 2:2.122.0-1Jindrich Novy - 2:2.119.0-3.gita233788Jindrich Novy - 2:2.119.0-2Jindrich Novy - 2:2.119.0-1Jindrich Novy - 2:2.116-1Jindrich Novy - 2:2.107-2Lokesh Mandvekar - 2:2.107-1Lokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- update to https://github.com/containers/container-selinux/releases/tag/v2.164.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.164.1 - Related: #1934415- fix the build of 2.163.0 - Resolves: #1957904- update to https://github.com/containers/container-selinux/releases/tag/v2.163.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.0 - Related: #1934415- do not use lockdown class yet - it is not available in RHEL - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.161.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.159.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.158.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.156.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.155.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.154.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.153.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.152.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.151.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.150.0 - Related: #1883490- synchronize with stream-container-tools-rhel8 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.144.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.143.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.142.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.139.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.138.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.137.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.135.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.134.0 - Related: #1821193- synchronize containter-tools 8.3.0 with 8.2.1 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.130.0 - don't use macros in changelog - Related: #1821193- update to 2.124.0 - Related: RHELPLAN-25139- implement spec file refactoring by Zdenek Pytela, namely: Change the uninstall command in the %postun section of the specfile to use the %selinux_modules_uninstall macro which uses priority 200. Change the install command in the %post section if the specfile to use the %selinux_modules_install macro. Replace relabel commands with using the %selinux_relabel_pre and %selinux_relabel_post macros. Change formatting so that the lines are vertically aligned in the %postun section. (https://github.com/containers/container-selinux/pull/85) - Related: RHELPLAN-25139- update to 2.123.0 - Related: RHELPLAN-25139- update to 2.122.0 - Related: RHELPLAN-25139- update to master container-selinux - bug 1769469 - Related: RHELPLAN-25139- fix post scriptlet - fail if semodule fails - bug 1729272 - Related: RHELPLAN-25139- update to 2.119.0 - Related: RHELPLAN-25139- update to 2.116 Resolves: #1748519- Use at least selinux policy 3.14.3-9.el8, Resolves: #1728700- Resolves: #1720654 - rebase to v2.107- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux 2:2.164.2-1.module_el8.5.0+877+1c30e0c92:2.164.2-1.module_el8.5.0+877+1c30e0c92:2.164.2-1.module_el8.5.0+877+1c30e0c9 2:1.12.5-142:1.12.4-28selinuxcontextscontainer-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/containers//usr/share/containers/selinux//usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2noarch-redhat-linux-gnudirectoryASCII textUTF-8 Unicode textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-8a5e41b392a31d782786f5989b5e930fe8d68dab7f10a6cc0c82ccda87974a848container-tools:rhel8:8050020210809211137:faa19cc5?7zXZ !#,KmO] b2u jӫ`(y-o\礥ܬO %ӸP/79cm7:bʲ1% lxHݖ9~KqD77fxx'^kލ{*nl ޠ_zb b~2{HtXTMwsڿtDF?n \STwB;& E`fxqVr+\Br=PM}7J8@aԈO,T#әIUj~m0Ev7eh`\SūQdC8_"Gӹ #hI'$:9p1Jo*j9EtޡE}˵/2tTG V-3ǙNJCix֋tTGTH 1іO BO1M5bqي|`1=*~*m==:SN鼷8p<}eƁ f~_]hI1IurZn1+75hN ?ti&!@ Ԣ8(MjE1Kݶ_jtczBPO2.(@RqFCT[d@<*w>>YJ,:CL"Uy%N;Rџk T,a1IwzȿֆGNܡV՘A$nPACgPq7>ʟb'׵EZ΂ Ow@C4W@r٣id~mݑ#߾X@N҈)MrH)@B zpi7ybajGB@OVڲ?QӭXchګoJE]s4zP]Φ`TURPc45$2aUr9Xlb# _;QɿV N -(2ݣ|mX1ؖ9K"L-ffWb>T,ĞW_҅PʟQ).*|thKa .5t[:}ec<ؿ:\Sȯiɫ  uf(:ٝ>t=P%8@LاzA.=!EAgGsB\ൎ@T`b|C1j')[x_rΥ;Uy~d@<.sʎHЬDvEuRT4*M"0 ?QoKMw֡Aj;3|%3i 7z,3M>* 30}CJ݆+{5Փ<]c.MIWLy~ d/rMIxʹzVHQڏEjBXB*~(s&~%`p9`6idXH9i:3<᱙qVR!Sf 9`<<n 0ٖPzb/;KБ2LУh#_0lķ~TYMN7uP6>]2$yKu1AeH2 lW;;x8 &6]DINɑ Y'-/qOo;y8Wwb}qXwoX05m] @Utkt3DMN!36>8 ԯ+ֆkYZ㺖˼jk96#bzS p^&lc)躨vw* T,f5>ݜg=GGSvPNSA å AR֡帗>W}(U%J;}ZBze'#nd< Q#TL٫6:TSiHÛx4LkиAz'#hrs̴lO Pa \_q$M_~q~lGÒ^pj$p({*B -co>'́{u?xɞ,-i'"ku[}][͝B̢pg/+C[t%DS--G 7a;أ),F&,JZ}^dT-;[MTC`cNe`k^ }7:V.m bpnlHdHח3"n X<> Aܕ~B河Q,ovuo!lO tc˦|g}2{FLzNTR8^1OED=e>sESvgrK/r #d.֯q_~oUS}y}Yr,Ͻ f#9rbϕG\j|?{ k 79-6@7,1T(9^A=Mf؛--kٴr V "L|AAE1-+mGkt4/k - +<.MQ4wzpUh|Pm@'F-qu.HJ*(_ "!ᏩR/5 2 Lح`+ U[~`}T׬.#%HC@1Wj.֠*^*Tx-I!ՖQoRGXTľ\r:B$+/l;CiOT869Șc yAε7\GLįMI:ⵤՅ8i怄,cRXXrOgZץ2,Xpf8\#rHl$@ZVI#mE#^-'{<½'(cO˶$TPB;R|OjMnr/m-rc^™_gZm3fn$wiiXl*+$1Tb\i@ʔ0L+T?1~j{PKtw# i1^#M%F2<}BCg]qf#D];~`RL0rehJy{γ|y|C Dy+܍Qĸ *t~l?Ȧ>s"((Lm Pp ?e]F&[ WL^{Ri0R@f(r KdlFS"wа2|y"i4u@njŝ A#rg[*\!%bc;644VۭRj}8!y8QCM@T!@AV:J\6D%lUdD¿XWȝ@I% S ()ZE6t1R A?gN֊\5plZ;9B _$0Reߘ#+ys nNJdq"|.AApT(~7MUքQg[Cu%pʝG=ܦec7gMn-e_@墑< jI}VYT Ʃ?Nnvh[}⺧2l荱cJO9Y 2gpVuw 41g9:"}iiOzMHI0w(g@"&hpB(UY&]t[ Q,F%QiKꝋIkIKCz$(Q "'b 6mcn "oc!l\(LCt9ҽŲmKh{`Vlx:X6\["]5&<ȣ"W !S NŇFkרIALXUZ4mZVK88*jܜQ'd/c/li!8.i9ȵ̢:1ݟ84["g*ޤV+WX0U?4{WVTk]dmH-hk%wXUSCEYdܥԣZ BfUN@rtEz@-9S1"1ޟ:}uCN]!04uJ\oӛ< ҦD j~pUwK #^,2RZL"d D9m Iz۽@pAz-rm_D28b} .\6zϳW_*8` 㟜3ű:9L˭X-7r'NTsMRYwM'XJpHwpmkB7󅵔b $.] X-?lTyM#\i~X9,vfH j  }5sm~嫆H 4sNلr!ڹBZ4u\\.)25W1A}X\Gv * Z*[C7'e;~f [2l 2l!@k aK<} [JQVpwijYDxMYHM]xi#ހY&jܐxw iů:-4,!;C=˥[.5_0gPhbӐN9eiKs= OU-MF=2̀ݖˎI&:x,DW! 4 邩oKh^m>] f^X $ BI?eP_1q*S ,I cпlZ'a>G)\S1?;&@;Ĉv7;SB` C__4-I.$̝▓PY$蔶Um~o5zonM ) {|oq d}XS>uAK 0f@dG(S~yOkɌ,&]Co pLd vW-c8M_ΤPT#`OJLtV)0g=iOZ>xs<KzƎ7:u=M1*R'ky@Bߌ,tWߘ&'aAͬoZDRÀӡDA[E muydCˈq CEÕ]D0-Yyء+)d"1,`[F5gZQQXaf;(Y\vGSx~ +e\D~UGp+6b Bx6C!'}՗Z2D }}Js I؋^oX̃UHQv^a>\ uPy ?z4E%0zĹgG0tBr>w/V{,I0Eq-f8[jm)|o?5_1P<k\r!ֺtMgg ;> ǹhdFZ$8gd-:HZf'/JvBU@jhp~]Gln8Gzx<5^)|!|wJDpNs<Ҁly:mp-m+.Kͳ6L@GС^>=۳EDp͝)^cK֓H~=5E)3}GsC=s:'gD`s Ɯ<Ϳ`"7T>_o32(Bv#om;=mܥ×+!$x~)ȫ@Tһ&EaLAEOO-y^5#c:%`‘!}Avk 8ܑπ Xfh@Y3ٺXgŻX j߄aDl0Ʃ-m*N;J L< o樓,0;anMXdG{Ȉ\8:2N]b-q6o?x:Z0>H &mopX+r],üDrdhQd oͷY̑Re쮬Y`$yn|p-qdOu< &;Kx c޴2߅z&b}cCm_>͹Дc.w-!Ѯqt+m7/dN*;~0u.ŝ^9}4&\AkykќĠf,xKrr3QƈܰCw|.F]2/ t-W\Wֲ: -nfX!my_U5yא@W~I#䳬›OxQ{6A6 84N9m'pdfΊ*&~Pqs1cU-jFdD#&zo׀M .$@v.SOh7˭9MN`]Ե:l$YHqX46[.SRR엚NOuHHCfZnd:fIWC9S[4m\,#<MijonE$gW\nbg>o/YSZSm dnwiX&A/{z~8F^R&63 qȌljT7fb~˱éSlj%Qc5 /A szaP*n3t9lKQ-+4]ʏAXkyw SHcJ_mJIl8kj =VWn"G:Kj!D2/]y*ӓgb2qq,ٲ}bG$y<wGA~=)[᜙6T){„j )e8X 8bH['䈋VvJHl/zʽFG>f BrgA@sj^Z,XC@G6Ndu1 Jq*nq朘qpF{z %W7ٟL3 V1B ⑵Q@:5oXH_췒9L oI\,HmOc[ DWLl0&p!eއsV>}ӿ?hELFA2YYHVyp*эo$ux:AR;s!u8gM0 x6$gѪb6 p2Sjp:(:1-u?cZdH ݇ GEp) {%r-e?xUonSG=Le,>uӗ+COr-,w(A6ђ?WQ&#wtmO%| =Nji W-)5Mu@G7eGI<& A`T.IfEۧ^ g}IMBRsڣėgFHTX6Obf-PޒWZH8QuK(=y]+z]L x9dz5p 1gq ~oU3F3/jm6pqG#ztdzDdw_Fc?׳ap_ps {~hp3|pW %=&({z?z]u3FVHT0",g*Hj-Eȫty?cgk-ތ Zƨ\gmɷҞ60kϲZ,_zAփPv: {Zb=i=ZJbDλ;Jh{s@,u8ͼ=pa {!Rrǰeڗ1V˕hH1c@ѧPY/78v0QjF0 hO4C 4!ju1fԹV9?V! `f ?F P-H]P`NW2 _ǁF/0G))#` !xBԇ Y|]qX6XU-A\GU&a?@͕s;OL*;RY:=ˎE`io߸7O s.0~l# `Comє9Жt{m 峿 ..Vg aNbG#e*0f'kV կ3hgG6vlVCqrZ=c{~menLojl)8flzM(i±Jn4ܛ hGZ,l4"R$o,Bq{>RZמ$"Vgc" h-fkqF8RKB\"DYGYgU`>kv8r*Wgl 3%( rb{R뒨.f׺ R"e]kjM \ y@Ӻ}f8d) 7meEZ\g/8a`;ap $%+A]Z>+MT V5}i{h8c%b кB6p խNwt7x' ؔ~HN`'3(9<YcûDk#oe OZ#ghi.7hMm[b}!-jȎF%r]HPOjm(-,@k<v E#-$EF,fwoԩ `&D'l:]1FF'o=neQw;X3#^Mv[9:,p2A\3 eS7(W=LMm\rF&(g;\_$`"(ES* }e%ޖKS$VŠ(g@POeF?QGcFrfN iWجd U,P{ }I^m'Fk`MÝ>jsxtPrH+xA`-ECMC}r3G5{-@6iQ/jRE2î 2q)o%9#0jS k/=0|HIvQ?%{4mH6b[=/şJ ͢A9[ZUӸ8BQ>'x☠|ó¾19(iau3™@pa C;| ma9bHh,*{@M#51_?ευɻR}L #LzU^A7Q>^E>߂8%cH{(T)K>-~,*؉`q ?CJՎ0AK/Z;WU!{U\`N_lۏb~wN?/cu#w-yGe4K}AO^@8l>oD2WӌMPrM6buC9#< h*=w[kn:BAuR 3Rw6 O/lW15$[bpQY|+~Jo*Zо@xڱY>ip!c ,VY^y$:V@;sY ȓ2f}u'x(T/S߭fd/8uS~n4F9|]n= Fnd\z7BPO(ít RThbqTK>SY}ʆWTƒm;*_LjCo() D^ZLjk Ѵ='cAuBp@` >Qmk.x3KnT3SsLy-{}Ch^IL:~B1s4,7ᑿN$%ߘ\vEFյp!dK6 fJgPd"؀ ly{O+SυpvVovMb6G4/lۄٵh?[|qzrL6Po`~p 6ewl[oƢEvޅl*bD2o]K̪=pY' 08PppATpI|m -0cye(}nqXxMcw9JA^EvCo=q4Bc7]یZ"ߠr,1I6#p{wX*׌4UybNi~  oC%:’)o%L|4\L?~3rw?;jvVN @rp篂QJWF gڑ]A4X:FyauhODmh,FF V;I5']]Q<^Tn-Sb+"cn& s4F\nKѺ:GFږ01Q.v@Rү;ivJT6jw"IGq|4w+4&= pJeR)H%}rO gꁛ3JJǝao1; Յg z ZniC<wSUW0< o_bUQFb?Ē:{I~nCח w"cyQL׃Dx,l>y\>J0m.tu_?O^~,x|gהiPS#r/ J孀7KjlڮL.MQ&MFy$r^roG@ood 7FC97Hڣqo u#dv!Gzle f+zHޠuƦϩ] \ſǫя`@wЏpʞt爑i`^V+fB}{W6 TjD(#|dәC8]`8=؄Q_\Lsb u?'U;ˮ0|{Y1;,~6)#znuٟ'Ï/QW匨As-a&,`і;HW[Fm]da ˝NUDp)TڌzYJݗgTA| La`BOkt+xݚ 3!S䀕e¾a 1@rt0/c݀Qf> 0eկ~1k]#N~b>"ڿ4Qũl{` 6NqoWЛX/.pqj-rgM&榈uuH hC3\:ܓË:3NF䭁Aiq{gc-;<z߄?.z&gn XkQ 9{:~dC7-ԾT'Mɯ"ekW]|t^gIc Vu+Ss\A0O.EM> z󐇜&CHY RCgwj,@sdn9)@4oϤ>GxFK&&RlzT ɍdzdtj6ent12WJb@5n!MQ> ܘdzJ*vӆܵ]&rHV┌&Mf"g bӃ9(d6mpJJ0yG76~Qe¨ !#MI{A1 I*12u Ak߻@ҁkoozx 鶡 =#U~@nf\6I7w-! k10ƕ_"kj)NƳ/},Y@m¸ꗗtF4p;XDj (@ͯV<@ٺ{ *L\}9F%ѕy> (%KȈ2Π5ԿYfGcߚZzQYuqaK+ K\tRq) 6x:|?H]p$!}u^=c0 \H.LhH^i7 /[j Fr2w|0T'S j6CzmEKb\Btp%cQJӚ*bonPvU92A#0"_LuzW:dzfUx}?wzs&Ҷ=t}yc-z*w[(YMWhܷffOaCwU;z k57#V9Iz7lzAkVrBZd*3?nj5{fyؔsmEΝƳfw^ZҧU;[Wϊ[u&N'Wm"rG,^23׋McS썉bJ&R su;}(HcѸܦw\ak3CDcA~w h"1oG)&_ |̽I{()Y\U^؟y)c=_,3{ E1g4,|saTL*v"Ń(ֳ˅̸ nzwit\QY՚sg8&4Ido(U\얿APskh'b54QŰ=FQ$d6 SN4p=ՄXVPrH?5p̱ǽw]]ҜG]wJ5)v˜ӲˣR 3j RX4$ct c@zJ!U7K?B)Su:7G 43τ`fw SM\4&AJ9&fic :F# _#{WbLbōK8`Py<D45t|Şa#] /}]L;y xEA>zTdsWKU9ӶPH0{%MAkSq}y!fiw! {rG?֤Ѱ1͸ǥʾ9+Ƴ"DpQOO.G4םSlR#4x=sh"G{:ecסp*63 qg\ S {Yj QjX3-W=ߦ>kȮG2\( 1lt 6B*b.'du\d>4il:9C vg wd ݱIp(Mh nJՋA_Jh!Xv% [(>+em>L`"-uCăc#PIrXyZ Y%dZtyV.T+$.i$N;v`~TW#s-;Pz[|MR-/=E֐dF7x'gNa$c)܁?evD*#y^1&h +&wjmҐ;š_7%ܬwP%e|<`Ae=\<^0VwXcnw^N%ANūMN |9Jpy yYd;ge/[< 'fQA-#;tV=+j=FgbqhFyO5 n\^ e&hT):,`=,P~wE-Jkp2#N0X1sT(C_=I&EZYc~c<䊉ru;wﺈx<_ /x|*oA٦NcAU] x} WNs ' FzUuJ_Hȝϫ8}v F լb1FY68Љ a5v̰u}1@5 SOܠD_%gOpͱuųaґܬPy>ȆUp.1T1)s7aa?sŌw`Zlox-['󖖪o&O5b9\ `! @RHKs rIM(GHCǂgqi|d; |ZOuߖ 'FHeAợֱ*a}AY}%})Sѿ`t؀zcߦ} FdcM6Tr̈|Pg pCQI|~("TYP=~h<5JkH>ezi%M. [rIt,L;.mTJGUpRPPm(7P\ewppbV}Bt=q覿Qqiz4()QxD9-5l`bSFjU}&k89NAY_rf$nC(:MGrVnIә_MOv[*c8/Q8P.ӲZ̛lai$NE3(1_VX,pYw$KQaOߢ/m4|g>M 7ހk xA滪+  u]+[: HA1fXI{2S+_E ( lu!|XPU&#?GjHnm1mWQI=hݖH,9QQYD-FUKt_|U!Vy\kϬʕDz}[ ,NʝC<P3-tv~> 0 fO1*[of-W1worN3s&|~Zt'S4e@.OPCzA 禺[BÚ\Dx"xl[ mmUݯF*z(FDġCR n&g5'= P.TQe&x<՜ ں,8ɩD yHG>]X_דN æ}ۻuiDNvˊOV`>V R)h &zk[‚ĦwѿP[r-A}H;zm_3-1CW]Oi4DVIUGb F[}H޺u#Q̈́uAr%$|EmY1t/,PZash!N !ۡCacT_u/S@ozboo/7:;apI{tCV,9GP yױQa?KK= '[&J3}H@9a|_WW\]8PQ|T>xxg"Dy@Ug`ln^M1f-2L_750ako |ܵfwoxvaw0߃Dx/¨8~''cC7,C(ȗ?0@d%Ph%j] X80_݌(1FP]v2,T$ZmUM.*jc3i?mПu8R Zz, #T_nnyT_Zw3t¦oɎQBKz#/!Zݓq20Dnb]Xv[erR0^D l=㟸Қ ygKy 7s&eRmeOLKB|VԊMN*w=Ā#tSUpĿxc_TZ{+l9SjLY_nbWB'5*asQ~; -T$,R>zHJ)<ra^68K;*LIlD 䣷zɚ`5<ɰ 1h 6%fC =pb MVxVqsV+*GD:D^1rS"aHRI`D9urueH~6D2D;jjy@!ac;P DPr4a+ 0Ֆ l^ʭ]2cOwı6vq5a"ſ(w=@zh:L<J.Z$D/}=`yholr E9Wjsy= 2GW{Ypys(Mdt:]yrj\}ҋBYokDF { ^nW&Iio*r3S uX:n23+M|vcis X-| zXO֬U>szS !Mu.8`t9c4<>^a@$6Lˑ"nԽƔ)m4r8Qu,&m1fﮦ \?;I'A#v\t\+ոpѹ2#ߡwtyɠm\#%9ɍs LO/s5Բ7n;C^HtJr.](`Lw7v'/ƥT>M")[ mz2;czǷ͙bd j@r)9_Xq,qy܉ĎmCv@CQ^I=/ 006VtЌ{ƹzC" M|NaǴH9EϑSo]^k%ȒTUqk"y!&oRJHucw EE.d 8\0)pr}n2St=k\+Da>8; e;Fz"!CZk̂qO+Zp&^u`W ]~Ia77ΐOk0zNһx㺭f/Zw'XNjEub'Z>jmo}{R"oض7JEz".XHR{]8'FX[ X"B?&}G vse|t/G޳> >\<ߘ8Y?0j|+W1r@sO6I i#e@"L?"}?ZN8Yn60Bl2X}ybJհr15 {GhHjx?G8m E _0M!wXJIR]FzRZI+CpγKKI h?d` ;~s0gNaf\]qܘOK6G *UWq=EN BYpik,09'貧2GI9`gPܲ/kJ#[C!6jSyI9d54[7 { 9UݠkRoHvyuPxP+l4Q~)exE{$ V:_rc㛜%CNlDoJaw\8rӜ:'1 _asH%/m\v'*q=P񯍽$/iP2b:W9:c_'?uCӼ?KxgP;XU-g"'LcF LIj s4CڂK(йLN8n{r[]3}oUb7TA}^c?Hujs\VW.oa(> +&8yFv lx7\B~ ߯ BAIvkL__,‘  5X@6[{3Fx#O=m+x̎?ا/~N"\e:n[xN&b:ۜi5L2SeJ6\zh'к{XI \6y\,Ա1"bU"v^/$ʡ 7[;eOWg`/f'kG P 0FD65zxo2f03r ZsqizQ{/nTrJ kS;ߗ)AYfMEᴎ}#vE\8e9 xHi>$9S:Z&oX8?sDjMw[(ĝj Z><;J$8Œ1:d6}9,hW>tNӔ [3Yl@Rzw5*/ JQ.h擟`? əR>j\>i"n<4BBhϫ$`:կm{~AgOxw]8e>@.+-5{#5zJ5/=Q;^l0c3 BEէm4(T [فT4 Q6=8V*#gUzfP;l@ӿD p M4@VE>EhgH7 kWRxF[Iމ}H֪-84^5dB뾷?q^J*#XdlǡύJ1`:@'h;^\ ]{m4}c)WL kk˻`GX Q%%! ɓaj'<Eh%}͇zPkEn+gKВ®S<Įf  d@& =h,i`.(z1W"Տ]I K'EݡOT n6AV' p`⥃@%Oo&){>ПXFE' Nj1UНp䯂|5PW;t3R#\JD0)9kKd$՚Èx,O򼦴O_H%/8{} '+i=D{^Nn(GΑLϧ .u^y'=;AAsy'X;Pop<\y806Vˇ.ƶW8[_"$1coBu\sv,G#{VQ5䀛h hilPq4GPA1*t,|eL=HjAT,kCaC"$oG, ű|BUw$3s@Tp }M3g5ʖˈ%֚K sb0#P3K[^8mͨaG:$Xd  0DČ^™ \i^VO+'2H=1ND|b5݋8Vr8Hv1:5?bʦFD KC@8M,Dl3,@{numV)Y:H˾M?V$i?/:  2,͗QBzCx=V) }|<ۮ]Ex NwPD6d$kD' 8dZ(42G)$ʞdc2zZl~TO(!/[,IMفS:-f@27Z~K4D">N|㴢`I? 'TIHw*'2hRM|>SYZVA0V3fB!s}&JY9z)*(N _$P4 A/!5 ˇrh [OMz^":V3B\ݬ*pZW_☋3Cg725 wM+{9Oԡ4Ei^\Sj#inmj?k?XT;E[:{w>Xs IEz5)cЛ2n;O]c'Jp 75F0kz6?r/ς#)wh|~ ~Uη /B873;*tF*?D*]kLՠ[&YPM ^@ٲv9vrsȈ: bK1mL`Z!Pem /t17r%E/P$Scm9!GLS/J簍ùϼ_ aO0>ni*pI_X8ZVHg|{*̍:I%Q1$oÑS2F~Ѡfa?P3M%P3 CY'&|&'B^%o2m5u0orPd#,`9meKQy4ɵDY"|[FU&w6S(^nݒD'U`6:D»UH{;x ZH>|)/ ÕzLTS}MApBo8u*URb }[uL6s]`40iػ$&!vIUnJ >mJ9u!o?` 鍘!,k?$_A1Oɡ)wD w_LIm+"va$\I(pO HcLf^W ~]T$^|G)h1"*ꯢC6C:s'czG]к1k0ͷ)9d{рEp*7ҪWoWH簻¬J@ ̋h[ݘyĿ:ڃfQ(i( J?˹1~ͳA&0Ex! 8nMEߜhHC{>s7%?.(m6fuVMx#)[qԞ ? WoGJ )w\az{$88i Kjvi,ea(9[Dz[fLξ F,W%6: UeZꚻBS ]{pϜvjo{OX)ҥ1oz܄UwmRԨ%Iɖ2fʕ̝FqxPd@wrV)8`]$0!|ܛ7gt^HCH5m`3ε<ٮ0RA!C3R[X/#(鉱-Vo6V'EQWn?CĻ"6 y'Q-*[4v O-C },UM7NRi88ڭG)XɈ;"Bb<…4> @ ޳KwK319$IqhSϒULKw P/?:ŗ.*Jhk}ly7~-aI^6Vxp%v:gO6 fXڈh8BK.uԎ#ۄ]䁷;^lBpd㈮/!\$J>.DO:\N"0_O|a0 !B9}}