container-selinux-2:2.167.0-1.module_el8.6.0+926+8bef8ae7 >  A aIU]CyrXڬ|9~ SG ud^]}ɾ[p_1uNKG:tϊbE1e3<7a֣cp,mV , D3pFO?Nd< @ h 28?x   (  <  d   n   x     D  l   ( 18 8n9 n:"Rn=G>G@GBGGH HH< IHd XHpYH|ZH[H\I ]I< ^I bJdKeKfKlLtL uLD vLlLNjNtNxN~NNCcontainer-selinux2.167.01.module_el8.6.0+926+8bef8ae7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.aI2x86-01.mbox.centos.orgCentOSCentOSGPLv2CentOS Buildsys Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types > /dev/null 2>&1 matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi6)RbA큤A큤AAA큤A큤aI2aI2aI2a'6aI2aI2aI2a'6aI2aI28c04ac861d425e9947eb5bc06c3125d682dc981f6327e789ebe1c4eba0d856fc0389dab4c8de315b75e65f20f4e606a015aac29056e561d6f7cb6aa588f431a94dce6af8d6b1b649d30bf5666e4513933948397b3df5f008711cc4365d831f2894b534da333780b752cdbe5dc8ad8ac59be52c0142e210fa49e68d1263234b9crootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.167.0-1.module_el8.6.0+926+8bef8ae7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux         /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sedselinux-policyselinux-policy-baseselinux-policy-targeted2.5-113.0.4-14.6.0-14.0-15.2-13.14.3-9.el83.14.3-9.el83.14.3-9.el84.14.3a'@a&0a /` @`9@`Ȗ@```q`@`@`N@`@`dd@`Y@`&m`_T_`@_%_%_F@__"_5+@_16_p@_5_X@^n@^Ӝ@^@^^k@]@]B]]@]|@]@]X]W]R@]@\M[[ͻ[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.167.0-1Jindrich Novy - 2:2.165.1-2Jindrich Novy - 2:2.164.2-1Jindrich Novy - 2:2.164.1-1Jindrich Novy - 2:2.163.0-2Jindrich Novy - 2:2.163.0-1Jindrich Novy - 2:2.162.2-1Jindrich Novy - 2:2.162.1-1Jindrich Novy - 2:2.162.0-1Jindrich Novy - 2:2.161.1-2Jindrich Novy - 2:2.161.1-1Jindrich Novy - 2:2.160.2-1Jindrich Novy - 2:2.160.1-1Jindrich Novy - 2:2.160.0-1Jindrich Novy - 2:2.159.0-1Jindrich Novy - 2:2.158.0-1Jindrich Novy - 2:2.156.0-1Jindrich Novy - 2:2.155.0-1Jindrich Novy - 2:2.154.0-1Jindrich Novy - 2:2.153.0-1Jindrich Novy - 2:2.152.0-1Jindrich Novy - 2:2.151.0-1Jindrich Novy - 2:2.150.0-1Jindrich Novy - 2:2.145.0-1Jindrich Novy - 2:2.144.0-1Jindrich Novy - 2:2.143.0-1Jindrich Novy - 2:2.142.0-1Jindrich Novy - 2:2.139.0-1Jindrich Novy - 2:2.138.0-1Jindrich Novy - 2:2.137.0-1Jindrich Novy - 2:2.135.0-1Jindrich Novy - 2:2.134.0-1Jindrich Novy - 2:2.132.0-1Jindrich Novy - 2:2.130.0-1Jindrich Novy - 2:2.124.0-1Jindrich Novy - 2:2.123.0-2Jindrich Novy - 2:2.123.0-1Jindrich Novy - 2:2.122.0-1Jindrich Novy - 2:2.119.0-3.gita233788Jindrich Novy - 2:2.119.0-2Jindrich Novy - 2:2.119.0-1Jindrich Novy - 2:2.116-1Jindrich Novy - 2:2.107-2Lokesh Mandvekar - 2:2.107-1Lokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- update to https://github.com/containers/container-selinux/releases/tag/v2.167.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.165.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.164.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.164.1 - Related: #1934415- fix the build of 2.163.0 - Resolves: #1957904- update to https://github.com/containers/container-selinux/releases/tag/v2.163.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.0 - Related: #1934415- do not use lockdown class yet - it is not available in RHEL - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.161.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.159.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.158.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.156.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.155.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.154.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.153.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.152.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.151.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.150.0 - Related: #1883490- synchronize with stream-container-tools-rhel8 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.144.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.143.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.142.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.139.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.138.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.137.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.135.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.134.0 - Related: #1821193- synchronize containter-tools 8.3.0 with 8.2.1 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.130.0 - don't use macros in changelog - Related: #1821193- update to 2.124.0 - Related: RHELPLAN-25139- implement spec file refactoring by Zdenek Pytela, namely: Change the uninstall command in the %postun section of the specfile to use the %selinux_modules_uninstall macro which uses priority 200. Change the install command in the %post section if the specfile to use the %selinux_modules_install macro. Replace relabel commands with using the %selinux_relabel_pre and %selinux_relabel_post macros. Change formatting so that the lines are vertically aligned in the %postun section. (https://github.com/containers/container-selinux/pull/85) - Related: RHELPLAN-25139- update to 2.123.0 - Related: RHELPLAN-25139- update to 2.122.0 - Related: RHELPLAN-25139- update to master container-selinux - bug 1769469 - Related: RHELPLAN-25139- fix post scriptlet - fail if semodule fails - bug 1729272 - Related: RHELPLAN-25139- update to 2.119.0 - Related: RHELPLAN-25139- update to 2.116 Resolves: #1748519- Use at least selinux policy 3.14.3-9.el8, Resolves: #1728700- Resolves: #1720654 - rebase to v2.107- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux 2:2.167.0-1.module_el8.6.0+926+8bef8ae72:2.167.0-1.module_el8.6.0+926+8bef8ae72:2.167.0-1.module_el8.6.0+926+8bef8ae7 2:1.12.5-142:1.12.4-28selinuxcontextscontainer-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/containers//usr/share/containers/selinux//usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2noarch-redhat-linux-gnudirectoryASCII textUTF-8 Unicode textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-8ee3f8d50e4f30784ed0f3dc68bb36f68852d35d455a06e8035fb752d7a22614fcontainer-tools:rhel8:8060020210920222800:2e213529?7zXZ !#,l] b2u jӫ`(y-!X:`ׂC4A6>laZ4RWF:zyRAR[aZd>FF>WT ȭjeSu4:r QJdd!1D5!3ߗ=Jq8'qb>&maQ` NO|E ~e(=\,!0-*wo=P5n JcXߺ,˨FE#hr_*)Jtvn"}DPڼaY,rH^Pjc߃Gٲ3sĺ󦒇b\aړV Zm&O=*n Aa65;ɹ1>%"uTWd>)Ծ^.YJDXzt࿽@wQ8ŖŌ3U(8dv7GN,* Y@W#>q1p*mP/ .TI"w.U6* e{0žUt fH%Upg2-$u rI.rX9P8 ڏ 3p-)иSwo 9ʻ/6sC6MLwݙb1,z} g>$,:Iv/]rK|a}Y^MZ$~#V v*&?q?4^2cW]oɔUx=?gf~܋T1- PҭR!Udf(l;N6\SU!L/fh4gBG26 .Goey4H4ݭ ܤ;j:7-P46z_'-8โ^#jʓƄhĴI|7NNM=kQ)0ߚA h>3gh6#)'];^ۂ@eEqC j,~ KCt!7u`ZLUqt֜-PGkuuΞlZy$&4eCLpբⴌDb c l#Q84D/M$q:vw",OTu1=9#s( esyZWh`B+fVP9L((#S10iʈȆl>zJT_;I??tєHOW;\55>CjVyP RXPСr'4 O)f ȼ$ DN>|qvXI 0{ze|8;15<վRgqkN]ɘ3Ŧj9 Т>' ϾD_<`g:ylҟhm&a(. R8N@1֩_blXF/j  E˖V8,W`N9WKg \?5Gq=Eki`ve 8sDK;$*ۦ%35.b_j/a +t2C4*b!c+BNBV.VotZcO:88]l%#gLy`دLr;1c}A|0$UUViNpd#~V`6狳>\]7=zyk[i Oe3J"PDmFɝ =YW#Xc] :(AgY(ͭzkD7d|pBI](rR7@n=-2 o.'+{J,$yL%)I3]3iP TDƱw{UHb{((ȆRPdN.U$HJf0/Yu έ @[ԲW,M{]4YqR醑C7Ҏ/ @iI\}cA:XB Mc˷|`6IGvߑxhm[L V}bV;|ƓŃS "J`0VU7C滨$,&%m 7UI &`˻|dDo}4fL?/9IuxJ@B٬ f |d򶄃^AbA}K}x[I~IFM.`| ڥoNqcP^G^)QbTrFvɴֹ׌c}U~ $\hm5*zrԖ2c,QVب DR#[KSŠjm,>vv{! __q/MHɩr\ud֓.k}:nЖ`c%`;yk+4^TepEfg2ՁUFE}7GFErCHTB.w[,"|ٜ QqR$x~%i f1I;?`oJJk$a0:Jo /ԛ ;].I|7` OaE X 618B-c-ǥ8\SO}Qө,4uZU9ZV£ k _rɷAݘA yRuXC jC%H!O/D| ac8Dr yz3{}Olp@o7]Q(UMѻ_iJwYax\ SAHzسCA} aZaɶ)qY{YL?`wpfgp&Q% Xx9'сDFQh8z,E\avTu39{W ,xxZFzAL.}M`e?<.Ŭ"8@.T:D%>}h:B!ZeV1^Ź\/O?}}["}ڈopΥh "q10"cG&/8b/Lar3*uiɚio*Ɨ^쀬A e5 ew;C8+e0dk3J K %c@#p(vV5Q0l .6913wD‘Sn~{Pb%]UP1jOw?IR} !$$>˜nڷB7洵z(| U8J!o,uY ȓAݮ(Al#,;OJlj{9a\t$Hrql8# r Јp9KԚÅ8;^͉I[p܈Ad~z)柲e(o5p{ k8 c#Tu(b` xZ_qt!6lLQC /Wq(yR5XvBm*Q/ۂ( ,ꫬ b]76ē j1< 1;48ojAP)i d2JyB)}t/;6~]yK&JGf+^~@Z"”Bԋ-yThCz#JB 6}@U FwPC<-e؂;jx_dsT’l1.Xw;kpTV"|FU"Rk+@U;,n'wŋ<{x#*~F$=evE9M_Ѿ$6xD*YS ?iţ|$LNbBiVq~GI1ŻuDO꣈}ЇC\;NK۠μCj]c۸6̟KQw16IoØS(܅e!KXRnlt8p wJVZRU^$z{qYu0LY iCa!:VH&P`lj!\ӣT"p#Q)%C_o "Yv85%i6k+= <g%@oO&(C.^G !B m5پs]lw/F>vMFWҰM[JknT0s&5S4KΏ@>/]z'^WZ GhԶín9)«ǃ2gJj}Ôgs!"OPRvIyՓw8k2Y]})^%޷}.'FD$U;!<늅[A6+z%]^~_RCQNF=y<)*b~cWJUWWHJ3kM U P[>aònA @tLo 3M';>Xjha@NΪ+{k 4)U)DBg=|U[;v{t=$+z&"F@}&2N&SwE+ճ {2,bݿݶdSךY)X,pg^?ݷƗm[}j\Ձ$S MMh50};]-X%KˆuNa~`zp6fo}iE}JkHZhǿ2 9.yz!"KeX Y,Y4H<RqzՌ?>~cE!L#r-'ij%4Lt^(h\@i6Of\}Y>oqV;ho6xtUF"QS)̇ua{EJvGkSԭ,UZMsBBG9FIsUѻjݔ&ƈӝ6ZXڢm:MBԯCce> Y8yjdaw)2[]0@Dm bٖnk읃ef(|mqDG\+[XəWc'4&ur9o5-GEG1E>{Z;6o3kJm?F)[ؚeğeuo<2i*ؗ "sp챣'B3HBa|)_?(0WnWqASWo XCMmIO 5 sgNH+~uœ0;t{[4 ^'PA۪n#|L<3"}Ag#׭EHH:sYFEA j3}!jf 3_F܊ 7O@9G&萕z tgED$6^h*@Rl$5.oŬIR/t>=9y9\c?d`[H%¿ԅBf x _7bҼD|eF7biCU_Ef]b&ܘr-A[3d=08LvjpJgW u cwA ZRսM\ "bW=}IF۶EYBcb!q /nTGɞ՛nn!]^eV]::]en3-Wև59 2e(` |Ԯ0I޾0?A)D<`uP,%`^} ՊX ڵЎݬ/)kPKʋmXu@5‘"‹LP4[җ]rm!N5g0] %̇Ƚ ʃm+SΘ i eeQ7eIcz$8\ܷWjbýSTf7 x_q Pܸќϫ^RFG쾜r5^m>lh:!pg:/Xv!DͯptukFTg)G?>6PICSZ $AO@yIMؼ͓藨Qu B1˿77XQ5 x*t [Z,WWH&Eg\|w Aq ?5kƤ 5:S]C mo[s_IIX s2_rd@ wrպGG[##ā~2Vذa8t:?؇M]:ݢm1O?K rOyXj7pZ3PhDe B)êhRzK(5G/D,S $v'Ƽ20*K`D(bc.۶!ѣ[NeɈ S7քd.aNbe4n8rBU/HǀMkoޞNt>/cs ^m@PQc%yW`^y`lS*cz#;x >=n@k=lpaBuӶN嗕PUyV B ?`^k-J,Uy.%]&[:N}[ ו$l,TaZ:o{bcui@20d&sv⠬HDLt%b8Lbe'hҚaѻݚN[Ϻ'3p(S-j|_oI_r/gD=6 NqGof'j=Vl$ёM_ؤBNrp_B$Rv/Lf•t/D\Α'Jҕci|iiKpow9pdݥ8QKo<+^|8AGGW)5v7=m]xnڃr[cUnz X" CZInl#241qlm6q?L!#HM4'/J ݙFJH`+޵͠^X)9^ߑ\6}3`*HMVaJ;8A;n}AAX:vt暀,z -tJ1ÛS&[=v_jPP >CGR5p d|+-]}EȅҎoڜ{2۷WD֢m_|#PtUta ʞvu=拨Ju)^$$TNHgSW!E^r˔JxGoͭ"?3(.,ur-n2^ VHyJ6TR0Ⱥ} {pC .:Fǝ$a[r %ٿP,%'@jF6͗GXt$XHFSoWVϟ3b/9Un爚O~/=/U`_ˠd6{kڕ3ᕯbc'ФY(ANmL20TN*HkFQ!GW*@w u& 8p32 IGcT38:(avtPvy4qHǘ~%Chnp],A\cǟ=FGK,^>oeer$M va\rb+?"J>hҢ kÙ7g;Mtx◦48-N=m@}]Ú(whf7$`I۝98TtHElDPtʽ]REC`?)HI?J!;G$@M#/pɸYm~+d& TYѩb[iRr-{@lxwKt eC؃/[u̍1ފ2σl, J,\y~RUa:YO}XT!JaH+x<-'6"/:_Ab?RA։KFr۪ Q<; ZOj=s'JoӍ\_յM{Ʃ^)QSzJGF1PZƏ@U$zq) AKB̟Q*ZnIbh6cخ=9_M>wQe`pܙe2>*=!}WUlD U"ݱ>_{g{h!{ZfSP'C)gݫÿ.q<^SO(E<(9׷up u{߽3{d+OFY.w#E sDgo] P3TT>"X5zMGZO l;Dkn&$ aӿVjbAM >-^Zq.U|lhy!lM"e)y [bZfI͒@,>Nޜz㪪 3Z*600*6Fnj3IrTʇ캱،#Q:e=iy爘~o\-Lczd9;}UՊSD`UtM68ݿϨ CTSCҏH-iBqc5c#]3 VP - {D.?7kpFw+}苊eM9(]C16:V2][vIy<%`ؼ R$FA9SlryRc76>8 ypn@o[m\o╋]\eGȝίbGv ? ދ|Kxji>G|7.\jD 4QUEzfWQ˕Qa(ư+Vv9^wWC`I{:h'4gF hT-UDf)7: "!( ksgOhzy26mWR;janF4΢ y6Yɚ=Ņlwt GutiX2e#H XTDb"?p3m^Eߍ~rencQ"—,~$ +E ,NxNE{^ž=Rï| I!S0BgMn=sVZCv`f6 vzE#ޣM~ T.9;d;h$ǒ.S>]/Ez&)edNwpWu,|HC3ng\gp<с̈́ j%( bM z75 U [ sp'ٸ4|E3N%Zˣ 2FRZ݈#vY=;9rb,N7.e\~%O) OAg heg)̫+)l~mCVe-qm0qf[Һpjq-To,6[{EӒ_5[3]:P1(x7WګAJ-pNF~kS;Y^W3 gVKtHU]IjƬL^.f]~,oᓱ2?T{h wҮ]r=ꢺM&T@wY8>,rp:x⛦@^']sG\A^Y"W<0xj|\$@G[P\Į栃= ">ˀٰ`vسY'Zm' rw],('1ԠY]e ^u@W>v0@rBDA%gh׊!Y+ZCC|'JHxvPҤVa; DB\_C/y%"{{-/qZp8X@(iC, c~HwZ Yw:~OS%eu!0JҸF0f~iS* C\] _))xLΰǪ+.=vП٫Ӵ@{Me_oZG'?=7ΐ5#EK)Kaum~oW^6uY-bJ:s^| Lg,扠I2=\rtuF٥=ϛ,l =Ks0- ⽄5&m(bëGM/,c<黛(gcBW lP:Sz%c8k'0{vLt{ 2q~. L&#&bf۰Z}:bT-b >HILV;1SU,QOIH)]ץ6j*zI 1$@/L :҈D} Kbg}-^i"ZC\d.D\$7& =Q2cM a $} ̑?IIW9sp8{T$$c΀Üsb>`΍-A|T'l+0vtHtO5] 6_+t\qh:NlBbQjGF0܌k/_4V5oCe*X+b[ aZ #~uX o,L_vx0f\oɗvڛ-{5Y`aH*P6$詹\\ AYC/OEb0wݦF;WLEn|I!\"JY]C6#EG^*ce=e9z-T|©F[@Դ+sP8G۝'dŒ)>.,2Sk~[z"22۩INⶎ;HOgO~LIC:}FHc<1BGZTVI. "ŽP~n(bK\^8k}>{5GYn" 1U)9:7XB:p!~Đ n|'U3IFY$ Fܗ4O k3;E#ԈV& ) +G%nN wZͩ`o.ǑJt3@&~{$ﶋGrgPޚ 37T'|GZZ2%1nfEZDRxBDzoMKRf|mg%Gc L$inTCDtdD$$t~%my8 1O|-Zn*T0 6@kmqv =9,$ :\tr[!0u3TkvIu)͚BϏk٥ rE)YϪR*q5Om^55o)>Y*0JmD)~ Yo~LAvn-\|X3TPOǗ,s[1 mscx$Nmgkk+0o&2[S4D? AlH6dcv-Dg-Dગڮ&nwZ ICdI9X6MrخA^ytzE UEw+j6l\z1Qa7$ϸEV昱bcJ`Ok>^7n|*}LSSv)Wذ%&W ,Ю$<^}r1O%pn[x͉՛w$FHT+`LX ), Z$eǦOL_7GdN b8 uϙ00ϩE7!9y1P G`@%`-$L̽`! ENHWCFU"7ңZӅ5c %g2r;x$2%OW45ptM9q6cf&t&a㬌\hm [-,5 LR{_gɵv[f4UloҠݪڜ0?'z ~U+n{:e/ ǒڇQ3k gY[7Yz=D=MU#0۴vMNѩ剕٢ Pȼa;=lAX5 k#NnȂHp[k٘ݦY,/.3&i${Kԑ[njں 0N ȷp_Rڣiq;((ܹ/)TaNk[%?]C|BO9D3<9*fϨ^04OA~R1kp؃ZzN)rͦˈv@0,^< iN,8p|{ӃF+]ܚL8qz .E#c.ḧq7Y赣rvHC!T<;.جsx+:1+%mXɖPc;WBhw*H3ijZPXg"HSCpb1H/`憜nz؛lZ࠘i{WEB%X36/ׯfP:ܗ_xx t{d::d4N٭㐣=,e%F!,`pwR(mQnJy^Da_'1FV$V&v-G׌"\p)|& ݤđ`_B/=QUfl}Tz&^DQj;:b =nCq!9ݪ:ܠXqVS&k̉.st`N\t^Xv/czL$YXkf&ho^]l{ V&U}´2cY-[rHu*4G.:e}nh//{ '{V[&KA?JWM.`q&@S21? Q.`xn ֐)1wXOiǃN.n,$0$7v.28?W@SXr`\Eb:nSt_R;S$%ڗ Dr Lh7!&݅ s\o7;KՃZ~ RM!H5dF-+YT?Z3Dnsds3Lh ,@xذ&0 yDQBnH_;γ:dDڞx{-zAJ?ǭ}56.1}/Zpܲ_帞4*r ^ۙqE +%ZpB] bjZ~d!ڇ)p$#GZee_~Ek@901YR7OɎ3|&g6oKGr6Z b + 9|ӹTQ`XMf/#{39%\ȻS iH P1#'{.8 3V%ԭ -\oћ+^2ؓ4a7?x rM/M XP-Oך۱71ŭ,~+o#Lfļ@hx_fC6a8N)w* ?^X=#+d@S Ϝ~SJs%ٸ,%'ˋMĶi!,ӥ $z5v`,[MϬDAZEnCƜ=)w+úq&Slz>~kojtD7A!ܠ<G\n\~Z47_Źeg:k)Ta,0S."c]AqnUt*"[Q%7\tB?*^f/obv ǣrI!-ZbA bRp"w]UaLQS7K5V}߬\t2F2q^J|%dPPC:2U/6A@y/@gZw.s,-\|P<`n\YZ^l9* KosbM\Z+ᔿ*h\<|r*N%!} %mVfIƅa!<@ů]NE]|p!h"| r.NumA71qME]!Tq0T٪\"M &ȩz  \z$4ԪXvSCJb]I|;rvrZC^w=Ju(9>e)UF %>)AQ(~AA ^9,kKARyZS 餭R4tu:XϹ|Xqv5$͝~VT@ޜ nQ7|?wR&^Zp3'8hQhZw#Hl浧0-L-d9Z"KfV[ x 퇝'ÅP웸ՄcӶ|e4F 9*R_JV$0C,-`4չbj5D-n8/: 55!&2򵲸#7sN}=9|Ȇ ǟRfaFCc\]c,}>+4RΟ(w=s^# n9P Ss \)w=m6#ux'^jOڧw҈A"^lJCIjL@`+V](Im0Ə<|]j|8H%oVegҬ7 gLvd! 6YL%PSXYΈ#HI&GE@ (#1cu{X d|SuYH̠E\*.L Z\7X\Uw(Jqρ K,ઇ̴Q^^d,lmxaU14d [g>9O+lUOwpinHG>Gr@;RMUlXIґ1 ILFI %ܓQ8%8-'Sy3L>Eg*0#tMlg;-jU`rB#&G4_Shf&~u| N X$)n~sKjGwJOFA)Tu }xLSJw 03*E:}`2E{S*WK@cG`YW/w`"s#'8]P~D3uO`ܗ}z/M@Uc!eP,C Ƞ#O&cߦ\aPԲŋ/"쵀H"E=L*7UfY{a3FChHZB "gĜh9yGU'hmfOh0,Ža;z14F=FH:11lzošEg3)]Е/i ر(?B6М0:Rۺض%C  yC|ښC{khnt[؄ fވo۴fYA8kRD! -x,eؕVAeS4p9ܰk9p#"Yɿ鲳M1-OA3yvX›'=BUeouX̓EKUy*qM*}D\KѮUjvm7$-6Twg8_i3.:?п EOE {w1bSa8T8'cI&guA$IOͫ=)ns!Tm"#׀)Ј<\/*ܔ!0KA*7BU*zFp~=#!>״ SlҒaL`6e$-°SE pJk/tOnV/#cg;~KњdYLjA4["\R u:V`<'P` yo_-Q8[ݦaez,1cdɲԿi*D9œ?H3E0_6%qXP2P4֣U: '7CŢpaL+E:8+DبR>;_1~DumP p騠 ']:"pw`?r<+XE{n 8m5_Uza+5`@)tK8r8e6ѱat ܱh,ua/fP#h.*|dpR a=6w͵-rXBm$:b,a(3I㚍87!@|AWMXgZ 2fB<~ND:^2E9qm[֙6AcwaQ}z2f9^Xw %Y[/. Q;ҏvzbV|% -fjv踤]U+I=_uQx)5 H wvV֠~n3f֪2Sx;c$B.W< %A` '8eg@$f)vUad8 vjq=z4,NioWl& ]- /S=Ě} wUN\0UeJ]#$C|#&V34dzp4p+OˈҍkuVrmأf_Xll|##nT` [śۧfFbWŒй$齏v6,jP-F1-^ۖ&)YHp,:iac4a=X?Dⶁ܇ :<ƾ3~3f㐿zNf @{hDx*OUoHKh`Bi=l/ vs9*;vÍ5W[ɔ6QMRM Ygd֐R N&%uz;c,|FBDq/_Q ,58C,2.55ߊO< ̞1'*j Jچb ¢N31X:-Eg` LAz"JQ:kҰRʸ0:UW*i>K;vod%S-{ $h9AW,BטC@5275]ȮMh)x=\|l/FV[=qyEz09B ;ƌ5z2c".ypkj1Ș0y²MZE'Y]51yV|l.&3Duحi_ǘ2a*[VHl6O &qJt>X,Q}0`'؂N?#l ]\kl u)B1(if|NRmvp}cΞ&(G zB|d?V v: e!W=;Xw@>r\@^' :H19#k\`ܓ&JTj݄kn;9O"Ao-Xόbw@D3k15a,!/IN㌂9ZrS7h*OPDb9ef' b:kD/|\Y_0Ւm gHDX?sP㧝w4mA*!L7QMq ,I"zbCEy$*6lVyx9SsjgMul_F٩8bTUdl旀J&Y_C{,8P}JvIWK_8b^:kS֜<8Nh|CF ?m>fF4TO܃7ktR_޻^xR#iɪܼM2$?0TyHPGQFlwuoC[nqPb{ʳ$ToQrDCNMĻx܅kobd;Yr`5DĤ NAt+,Ud-'AymSd Zf(ˬt^ݍ@j 6gYfiD[:Fk}Y:.Z5yR0GF*$:d_KW&6'+CHSk^"Y1گy*/̓yr@`5C}nCOjKQ1;Go3:דLq8}T.U][M(ruf[8b(T38LNC#eA#YrD.%EgK~k4&VS˴!@p۝WٜB-&0ou%,ĢBY0|<y[E"*z4Z&$|GuZalcuar r`$s-<J y>Qv6g<7m2凤:bޞ8Rqvh',٫ HЅL%LdI! 52j?aenڮdThlCOC `q\"5HM z>_)"ES!< K+\7sp`RyvTmen8R]_]n첆(@ZxeMǧXJדr skabڃNSu8DnbrY'+eO{Hײ B,@T n,w`h c6 9sI|*}"2='>N"Qe+ԋIQZCbnܞep Ip-~Q!Ep"|]oᴺx騮6^̭Op^ʌК=|kZ*TDZh-4NBU{Z¸NE n6F8U%{3Besix~VDacʂ`I)xSwR(ҖݨuȦtM )^Z|h6/՗ ௴Br3K,6 ޘ, 4rH J()h1"9CZj>lϯ4~fH\mlvI_,!Г X/ r#x?nG֮m MeԈ'aW,Ĩ++S9zsy!\xS+?E3 `[8%bf1߈D\c0.[`*P[eKePtuH G$i>5[D4$3ص &r{A3 >EMP YZ