container-selinux-2:2.158.0-1.module_el8.5.0+736+58cc1a5a >  A `^U]O%*3|Ժ'P; nGp*^t{z<~״.v1"y[ZO@dX9f\ml>[Ia 8WOxR Bϳq Xuw76sDӚIlrԻt Az\cp!((l 95%|wH:*;2cUW7 pօ(q\P":"H{뭴$s@_ܽb?}0uv5u f0NY|ddU"\eQT\fV9#4%_R:#%dLv\~á.5=863ww_n4ՙh_6z VorAb~[E&H!^1DVbu`ɟi,nS^lO8X^5F}Eg!Cm>#JPp].3b4ffa08cd31d5cb8b89efa0618818e42df77158b45d5128fc6d2ec83c25713a79f67b8e64821c42939dfef230dbfbf7d878e7e8`^U]-pw}XـqEKO jEG(TƐjamf_x:4[4nFc%rk(PͫGB j ģJN]դLsf4SrױSLQ,'/MX2!e):\Vewxo-v-|`܈8>ǺpB& IҸC9': NC[;N[0 Evqm"#wŻ{+SdUVqJ464 %>Z(gC|̌tIe@{L5]H8 K(}ٹ0ޣɽbZMbgyĨcժ,Sy8Ak}h\K[[U׫m&WeH4qʹ1gT]pFFY?FId< @ h 28?x   (  <  d   n   x     D  l   ( 18 8_9 _:U_=?,>?4@?<B?DG?h H? I? X?Y?Z@H[@P\@h ]@ ^@ bAdCKeCPfCSlCUtCp uC vCD EEEEFFCcontainer-selinux2.158.01.module_el8.5.0+736+58cc1a5aSELinux policies for container runtimesSELinux policy modules for use with container runtimes.`^Fx86-01.mbox.centos.org7CentOSCentOSGPLv2CentOS Buildsys Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types > /dev/null 2>&1 matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi6)Oxa`A큤A큤AAA큤A큤`^F`^F`^F`% `^F`^F`^F`% `^F`^F8c04ac861d425e9947eb5bc06c3125d682dc981f6327e789ebe1c4eba0d856fc0389dab4c8de315b75e65f20f4e606a015aac29056e561d6f7cb6aa588f431a9044f4c44c63d2618337763262b14ba6105ede94f019c303adf736291eae73060750f7d50ff0d3c28e36230972a30f00f84c76a7bd1760465cdcc6c7906a14a91rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.158.0-1.module_el8.5.0+736+58cc1a5a.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux         /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sedselinux-policyselinux-policy-baseselinux-policy-targeted2.5-113.0.4-14.6.0-14.0-15.2-13.14.3-9.el83.14.3-9.el83.14.3-9.el84.14.3`&m`_T_`@_%_%_F@__"_5+@_16_p@_5_X@^n@^Ӝ@^@^^k@]@]B]]@]|@]@]X]W]R@]@\M[[ͻ[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.158.0-1Jindrich Novy - 2:2.156.0-1Jindrich Novy - 2:2.155.0-1Jindrich Novy - 2:2.154.0-1Jindrich Novy - 2:2.153.0-1Jindrich Novy - 2:2.152.0-1Jindrich Novy - 2:2.151.0-1Jindrich Novy - 2:2.150.0-1Jindrich Novy - 2:2.145.0-1Jindrich Novy - 2:2.144.0-1Jindrich Novy - 2:2.143.0-1Jindrich Novy - 2:2.142.0-1Jindrich Novy - 2:2.139.0-1Jindrich Novy - 2:2.138.0-1Jindrich Novy - 2:2.137.0-1Jindrich Novy - 2:2.135.0-1Jindrich Novy - 2:2.134.0-1Jindrich Novy - 2:2.132.0-1Jindrich Novy - 2:2.130.0-1Jindrich Novy - 2:2.124.0-1Jindrich Novy - 2:2.123.0-2Jindrich Novy - 2:2.123.0-1Jindrich Novy - 2:2.122.0-1Jindrich Novy - 2:2.119.0-3.gita233788Jindrich Novy - 2:2.119.0-2Jindrich Novy - 2:2.119.0-1Jindrich Novy - 2:2.116-1Jindrich Novy - 2:2.107-2Lokesh Mandvekar - 2:2.107-1Lokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- update to https://github.com/containers/container-selinux/releases/tag/v2.158.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.156.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.155.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.154.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.153.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.152.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.151.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.150.0 - Related: #1883490- synchronize with stream-container-tools-rhel8 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.144.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.143.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.142.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.139.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.138.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.137.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.135.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.134.0 - Related: #1821193- synchronize containter-tools 8.3.0 with 8.2.1 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.130.0 - don't use macros in changelog - Related: #1821193- update to 2.124.0 - Related: RHELPLAN-25139- implement spec file refactoring by Zdenek Pytela, namely: Change the uninstall command in the %postun section of the specfile to use the %selinux_modules_uninstall macro which uses priority 200. Change the install command in the %post section if the specfile to use the %selinux_modules_install macro. Replace relabel commands with using the %selinux_relabel_pre and %selinux_relabel_post macros. Change formatting so that the lines are vertically aligned in the %postun section. (https://github.com/containers/container-selinux/pull/85) - Related: RHELPLAN-25139- update to 2.123.0 - Related: RHELPLAN-25139- update to 2.122.0 - Related: RHELPLAN-25139- update to master container-selinux - bug 1769469 - Related: RHELPLAN-25139- fix post scriptlet - fail if semodule fails - bug 1729272 - Related: RHELPLAN-25139- update to 2.119.0 - Related: RHELPLAN-25139- update to 2.116 Resolves: #1748519- Use at least selinux policy 3.14.3-9.el8, Resolves: #1728700- Resolves: #1720654 - rebase to v2.107- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux 2:2.158.0-1.module_el8.5.0+736+58cc1a5a2:2.158.0-1.module_el8.5.0+736+58cc1a5a2:2.158.0-1.module_el8.5.0+736+58cc1a5a 2:1.12.5-142:1.12.4-28selinuxcontextscontainer-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/containers//usr/share/containers/selinux//usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2noarch-redhat-linux-gnudirectoryASCII textUTF-8 Unicode textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-82889be9c22269a53407239113afbb08296d3d473d3a25d9233d1b50cec9a3468container-tools:3.0:8050020210326200241:faa19cc5?7zXZ !#,ki] b2u jӫ`(y,dX6r q5H9&OP?&|> :,B UXt ᬦQ7ɸeAj.wF `rރ)R=3*&F YH$ͬ O.H$klzOP-`jg0ʔv#.m[md9ymv q61䏓jVÔ$Mr_'Un6ؐ0h3IK^O 9RMD'oѱ_*!SaI,2>Q8vbdjkGH_U=/ڲLgp\}ܢ噭'@e`Xj Jf5Fr捡lf|%!4_|5@2E! Lh8?$-yυ&/'CMʬ t :(z}$g)1*95M"u%l%{/wl' (OL6C N60uB 刪7 zM_9!:3- F,7:/jaVj 9‚Ex!x:c4roa%Kڭ ;| (+^z/cW 27Bk?O n%sѣ?ܤM ƣM}VX,l\;4Xm 8莔+% NyR00 z~="hט8} ̱BǷ5=l>yW E@d|L.kw4桩y )A{ʪ.0߄'TT 3=ןAespt%Vm o!H[YX7Nmq <ڶ3jBRc#@˙BamfZ DqS8T>JeR=#u.ŵ̔|\.wu?,'j L*g{bqRIS6 fcp_K0vo^x&6eҲnƹȳCxς C*YA0^M#rX8\]?+D!v_r=_<㳿.mKV};D=HߕӺK1Yr4)̜8ATq稗E]U~6'3KAxD!"S0ug}g=<OM Iw˞d)?bh:@koȋ<ߗGc^VBL G ';|ANH%Љ#*v(*bB:gp'$}m=c;+f-7w]]`@Zx 9"4G|6ȽxNRah(D;~6`&#>m5F߻V|s^!ˍub e[ڰyr*[ZRLF\Y"3ɐ=H0}Ře{9ON$f MX_Zs592zKe6 IM_s$!GN"5pwO+ tPӽ*?QCt`PMF^(7{#JYk^|eL>w =6zBL"<2nKBp/pZ08'm6ё8DqTdn)cQYA6 KŸJtԿ R*M}'43~ȁϚ- Sɇr^ܢq,(&} ͔s(__-r7Z-"B%*s@eu姜3e&y'`] xJtk xGj{ükG.wJf: &Jј +=7kG4F&V|hbdy{ ˢ<5sb{|sKCq fIA XL7py`Grm6Rz?*tnͤ\ُ$\a4!R3\@8yҜ]|_8(yN}oтR]D<4ғ/u4}zr~A^|S\kEKOF,d(\.AY\xKoHW}4*&h(862Gi e+j) " ^ʾ^} ?ERA۫=K #fN(ArcҰo +Øs9i@||M61[8rBc,pٳ=RϋpЕ!Dk؜ѐDŽn_ڡ# $)醯by~eּ玄af3o)t ܘFԥ08Мt1>o.8_(@nAo f'ݒvE?}U R6ۇ@C ȂzK1 ȩF& H6;oNU4.Jjdߵs,?Kbٝޔog\EsF²A<l6n8s:Ø@.ʦlr^)x"vе\J8h33 *oF/`΋E"&1؜Q$2XQJqt*yINP!>"|)ppQJrN!Ԋ"T|sxJ]2ؐɛ]66xLe[9Hi>G,zh9%H, ˩x7KV`Fu\GWXsօH[k՝FPc 4I? Zm޷.1ɱE.ZA>M:cO~7g@j 1 rU)[;zVR%&# *Q'7 z3{{ˍf+ R^6 7.㹙uMv;rw[3xS>\is}DY:W%Evы` Rr5BKb|rk/DwĜ`O 4$o )GՓ2IgD X69ejESVOmKE,(X|Yy˾J@Cl}1Ä 3rGbښz"޹_6 C<8ȼh{s>Cj!2@a;)! RR$[ӻé"1BJnԚa,v!' 6B T%ē0&sꨟAa&aI9 zy}Wlvxpv0#2]Sw2YmDe8 -ך.V:(e$BDgOT:b5C*c/Ѓth傑%]6l#B24^ǧo\L єև=ЮBw`gzƩ@s@[e:eR*!d"QMvGt-(^?n,ge2+?qmc#(kg"_ {\Ks~}}]zMܤ.Vb<HuT,p+W3 Qυ8YVцnI!R6Z9 T7~0oW"8o\O!J RW}#>{>9sMln9Am!Nto$/:ǫ<#`<4vx^b<Ρ'^0JE-bP)K7vpf 2t ڒ)#7_=EM㊩%Q-8ƫ僉뽓9dh]ߖ%l` r54K-FMִ=;%?+$50g)H^OED:HT3p-3@߭Z>`DL!oRəöi4|j83xoDP dड़rف wsiZ#( CXWlǙ\" F <O}y <9kRz]4kxoreCnQ2KK{!1 &=^&hUMV k_6qxUJH9~u&Cȓ'.g-omQA)W,8/R5E ?䅏JBȯd|~w /)b_yGtIL V@9%T),~ M0iv;+ +W .80ErR0t%ʤ"麋"(8F'mmy<l|A0Qtr&,ʗجC,<<)FEgr73=PL᱒i暫ͽwϭzDD50qPDOK]onggx# 'jEٝSg)dHR/ɓm?1)vǞb1$.LJpPVCa)KO:HfgBtƈ2!V~#@$A9Y="lx&}AҜEf)âKĴ/0b `?7c_!۶qoEW-rfJY?8/sdrby U` I qrtΡ|^ @`39>aCLEk!`3GF S#9þd8LkEHʆ-^ёHg'` +iɽqX&=<9¤GpiHW>`6J\%@E7LpQjDxSb}Q:\`jeJ?=qxY |_r{jXJ`@MW[7Y N14vd㽕B/p-]#JY{2t4߱Ł%͇wI@2xW5\i%wt{m! $RY$6e_uaW5 0AortqraDڤb(A]sŒ-P&|/HBޘa/av.rnQ{ htnLPن n*A΃6W2lpC}`->֧#@*[JpDoXuʂX"Zn&1y7@i\7eS$}۰@[v;{& vXbF٪WˈZGvrTg[c9${3[=>tzŮâl^=Q(#}zqlM2_z,Ӌ֓H+ [{H ~FK&.)}chIXBRkFJе|'k: 4;!wfR ro6ͅkSDIi΋~k0',\+QRs/@YXߡЍ9 ^oo"c`;3@ls @֣4.p{sg pBE==~c]3fG[̣&)ģwZCQJru0{ˆIJ't}ǁ|#ύw_k9(epdրA zpm.-"ט0̪>DjF?m+V#yj2`eE[-ii2m l(tA~ٲ!}92jIpa@i3;=F1tN,6>ijVSg/tAtHff?eylf!3r$>K[=ܤm32@¯9h`A&8gЎfys'bQnʅ )SNq59G0xۛ0#E4 Z3w% :8<iK1srݒd,fVο1b\,l#3)SLӱ 207\54A~R~9X$hogQZ &zy͚@5oOǞVϬ r4jWpߍyMl~[tvPԒȸp? ~֯?Yf.;?O`P#q8W![,o1L9SMbظѧ[a/ ZV\:>NY CAkCZ=Dj$ac r61Dیz,X^,,ӿ#6[`΀1LQ5kb+#_|vYTX3SNbUA-g gH"88z_!)|INJLWmW]b ,DQM -XKd̾Ŗ+{I  -L:RUyWKVĒoF 9|X2N, BnPf:{0*s1ibVL uDu7}م(ě.={ֿCMZzy/FVWMc۷F~eb~sSEO*G^_'w)Nt8óFOBclѽQ1hp#PΙlfkkD.fMqr,#R=P»{p?,z5TEbܨP9nʂiQ`Oi2E]O? CӤBHc^P`2(H~~ ]28lzyrNmZae37T'?G p>yTb|FEcӫc]'b0d^9@ 3Gd˘KEF)'^v۰#1P 3Q"p\u9H2+R6tـWņҴ볃'){y`n%J9_Mx_F֊6#(0ҧ˙F An?K_|j]"QeJD/)Dʙ:̚Idc|(N+%vk39O912OB0`6)ԌG&li;I2ED<ƞ`u'ȊrZcxsأ:s*woJf8&C b|olWHMVgѡ+p%њrQQoLd X lXnvrk\!r!+} a$(m+_=R4E7/Z.a] 6KQ) 6\[X">ɖ:aDͰ87@G%$|c>yrFo O29o<`) ă> |EY )L9Švl2\i=|ak y8u2NȓL=K izi*^Ѥbf>͈ǀЀ9`? j \S 6}k\+dK U~A=3Qj/9J*rQƪZiurzj)4(~@BN{q_b9fEvFaHol>|ac\lJ9kA/swiĀ СYQp7\p"%#U庺~ወ]h-QsQMġ>ݾy=\4Rȡ]Ib eR[/7^ު eő=XnetUHr.a]ݖ0t|Egt0 5rbv#įHlF~z QXdv~X^qX:v`vB:ؠSxo֋A/a/+k,)Ŭ߻z"B :h3!%N/<l!#0 _7f`10~%)]ߠnPg^Dl{ECI9ij=l5\Cyaea4ٔrIZ#y?:-qX2G u[ivY4te)^ؿ8D`fh]!zr$ 9K#a0/1@Z/Sr jq~}kg/QYԞ%*ΰ]X1ppsaU"'0D[L5ѽzn fM_9]){'9l3)^tĐCc%UK)p׳2+']wiȣf TH/2/ Vքk=lIP<6vY-v$٬ily.G;rewYnS+J՟IKJRN_KS*/nҙMr(f/Ġ\xK)B5s q:}Mg}R }FÆCqPf0Evv!汵8P-˚^Ff+\ª0.G8b<(A*'#~+^wu;?O R\֖b &<5gf\qk%lL Yۙ',S!k6`, @J)Tpv% "elޅ: \Eahq&w€A;w.'7KcGb3j":,bzqm!uiw|ꌿtG˒ EťyНT#*@@jNxi6C";n{ *QL?N֙c."̓_Bq- W'{; HR*: :O {AZo+r6&vpe{qS>fEkh"dž:N0ӎKV` .j֣%EJ?'6f2]yQDljΣ w>O=!,SmwN@Q$چ഻忸zoz oy@ 3Qv"v!y-dQ704g<5 0a %qx?p"N o_ ~Ɨyټ֓~,'Аk!A >IgK*xXǯt:"a6#!63\Y9Hx< l'YzB6OJ09dS@2dS7k 3e %t3"]e=w=flsu,@( #!/Ax6f;OdmЫ:]j.׿2 ^&zGrx~swa*bD.OK* xϰ"$1 1XQ o>=T i={B%ED/b;MbC {{ji)>5CGʂG[<~- Oz9]bLؙhYp+t'9;_A zb^3[G5C\AdRD9r 鷑[*e;>2=v yE~xP &PaJsL`;+CQLjR`A /Z=Fް ˵P"IIUT j"|[3"1d}g_øx# 1IQR m5;5O眭Lڊ0,n|5p֪;|-΍5l|\v齖S`ϘMCf>PECm_?1 '{pS&qwohq _(eKOhP!-seTNMҎ@:nަ3(0m# ^ oWRv1P\ Hi9Q.̀鼯KDz8yQ'BFQa$zL%t^8רd6Vw Y3 "\=T#5zνo(YjqN+}HM}xmM#ivڎ{,NS^(F4*+P0ͯQOɭ%}^uWpa`KLqjlK#RA.lOT@ozY5%FD$spƸ[pli<:&7B֕@ `Pg)s` .ܦ; :^[ȁ6FgV>!`;+qCT%:98ڣ0 'zbFmbTVNȐ@6[&܎WNKyWi&ni#2c9(K-9T<Ƀ+^0>q'zG.FM[c?b²&Xm!҇_UR]UuUسQ-`1q4J y=o 6Fm$R)e5E&x˺ "SE<0FZB_S(V.ʎr.rIyqո쨯%.v+#XQ,-7 DtAFhMP Ҭ5b##L:{`ۺ+D}E1⸿һ1,ZϙYwlU!Ln|Zd2fc!Ya~-YGߠ3lԓ=EeI#.N-W[j_6~VM`bR߽w V~s@6Ő(\^~0~bD|\=Iek[ڸvFlұo>> c71t'-pN&IԴG}00iR;^Mgx bV2K`>ݧ%R$l6"*%Nݡ(0i 7&nNcT;#z &[#h6x_Y)_wEiA )g Ggio~[֞]!Twkd'3g7t/%|ҵTk)Үzݗ+vKD~!qUK(P8i݁s۩CD1a]Wy{ =QlcH?Ek }0x">Tl?>3X Uh7SalXG5ght]K L"P>#V̫PY(fQμ7&(3s3TA[Ac`5U|Ϡ,$PHH8Xȉ$a&>'IĹ63dwpWdiŭ8s}I)hLyc1@ڈh38p,4<%BN? c~|^-a-:K{uu(`.;&Bp#TA$щ"OljKH/JѕO9[HfUպ:P%ws Es*Ux=؉ %U.]`RD2 irTHNy,߁ugFܫ\,V1ͼ\-O2!\Z0䭙@bSrGBN-w/פĊ^HQGy#c@)'\Q4CMܶ.!huO4nli~TH7:(b~]Ʈ3W&A5)w.L~ȺQg7gV=!јԟ/@s065Kf1I󕣔;(:9ZB </}dID?uBOY36jm`Arr^MC$ҏ V-o1 j)À:Dš(ظ:Or$%ThmbX|/a}Pl_!K~<^b"}u ĮB>D?QZ wc#8s?0M HRVc̍wP9M< ?j<ckA?h49rưq-](ftr9%$ߪ(),52LQ,ʀ+o1JcUf" Ho2&r"KEv0{ឤk?%HK^.&}Ƞ(X "mz*W*̼*a|WE̯ᑓcn\N/GxK:@ ^__DS ]eΓk+lyҨ52HFgiLzen0n6{h?^/[aʿFⷥ/GXYʺT[t2gtR6Жf7XՒ#C^.-m>wa$r٦UtU {m(.&5M?gιdR4  ^VrMx+!/ÇWoJ ,BⷐpII!@3YT ▩m~4Wrey<#4kRzldX}y+ m CxXH[piBփ,/ KN] vQmpyrdz PHwJݭמ 0m'C-b}DmnP+fU9UϯFuyW ek.xqEb0y6ʀ|Y8kBqY)􌭌|q9lX`ֽ-B}&l1heGg-¨&񈃗xI鈳VNv?A-Ѐ\f\jI 4F ؔ蝝 u92]th0`Q/%;5/POrOAn1q?(eӑv"d:?T56~i,'jMq6}D~@ }bg7AbSJnycmJIrS >7 _:SߠT(~:/T-h,V\°XvʼnqKχ$ j l0_ hrXq JQu8MhLFg@ve>0{5>{'MZX5גּWxЧۣw-iWjJa% NQ_nD%* 6),(+X e8-L^-XBW.c.py̵{A4i1FDf]ꈪ I0yutIV sL4 A|479]-#=3#[Rdc`ø O~'9M¬@$ ϯ}>1lpHk׹O7ШR37J++Fm9,nkf RSHӕWx`E9m L3?I?Re yk{tWn;F4w$H܏컰 i5;_Үw࣊Ňe:R,Gaޙ vF3m%x$n fH</pRCkk37_T ֬8dyfBA|1E4&k';m-a錽=Nȩt4V'I]vϭMmF|e9YM obWp].lMʹaD陼3FeDXrVy 6ƌU?>؆q`ᢚjeI[ F><_QŌp{g 0x%Qӛ(xy'%s / o(ՠ C늡;0εiZu d~xfJ?8嘚kʱI#c3bD~5\PC? 05s6q49VZsxLbfqi ԯdf%sRP*bk|6gzc~HsoJ# q*VEX!o)S.j1ci Dn3E7*,v ՘ؚdЎS5D-oWѕE;ȉ0Ów9t1;W``F`=&l^D:<Mi %CO;Pp;  "(ݥdCMJZlZ+74 G.Z Bӛ~LFh#˴u#B&uiI D.Uo5kz\Z)gʔfq(U]>G fĻdSb(b'1 ٩_PL̕D @fJHN77hHt}QS ԪY 8xAu̞QeR8]X(8m !kT]w/+WKtӗJJl-Xo|ivHZC_u'z?/]$;jhDEa <</MtfQ\$vQ39f̿B*ah/ 't yvfא[N}۸ch v)?Uقо\<]P9zΠO#pcG>? QݭOZVWC1#İo2a{"Q)qB2Zn|aL2T)FŒ_p8VҎt+1 v5뵊qO#$G}F }.y3 ?:w5ɫHY ` 9|❄N:og"k\VnxփAA$KV\6p)tZ3vQ4)0qNPg/Bm̄1Wq[1R'xk$ ސ>ہ)_9e\neg5L~LVyM岊gZd)|02ӌdH,%۞T[+EtF `iܬ d}эzzt/f8]mS23w|+, p(n= ʛ>SMK~U*Jm Hf sStYT0mn7% @mE jv5Wq]#=YcB=]0kD''kw #Vfcw|"(H6AhGG7񕈒>1oMLv%#uÙHLtQt;Õ6^MI"൅ &'Jrh>W9ˊ еdn/dknc䱓aR2m/od=E5 "J)7&*$y'T[qMhb#ޑ5;kgwuO,kd^BԮ[0V ²E9FbdHEܽim}}t[d-eި d (mP0NaT`~QMt H/Ft$!ɯ6S+#+莄 \r&=) I2޹yE{w*ZR<B4o֛OզRF8l!%|hp\rmRfem KeenQ)X 7=| G9wmuy&\eg!wŸ Jy =Q؂( 1z"As> ⣉ОN-rU6B$ 7e/l@R 0u@@ȦA O,5})QoVDN,sqb͈n!cG~.ILY&Q7?)+H^&P$k ~fenB gإN:4@Oxɳ?EomӷJ7ՁAS(*rtB$+JP5aL vn}KO=)2HK:ʤ{¢wm\خ:dz51Dl_M0_ǑEqsl-ܿ1 92 TZ =Syn$|6(+^zs"+CC[S׍Wb>Ŏ,8̌UwGo2$Ë|`%ݺ]+9w.6RUPi@ߴ?"|=rΓ5jnjٍkJ;>Vt2X9wR6/PPءo{ h+'(,5ZRfڸI6\v5]=< 2Qw1=fIPHl̀dp-d$=)ݍKhjfG#u>[zܱG>]dDPϚ~ظd G'[KaLn4CX&2¦[=&?~g֐aS3ۑ iY:5C׍Tj)]t VcQ4YRCeY}C,Syw¯02w=ohy%c\ l D^mA::MpܥȍQQEB*!IU V%ݱz{3ׅx&U]Din\KhSCfX8qH1RtBHgr'x.mx.r>^HiG$u$=Ml(״ ">fX#-kH ,WPna1CFL[ Nת+Vq-&^x.IĎM~5 $xk:є2d¾\  EWt*u$6̒[E]sn 4dY@XT*Bb柶*zeVQ(\ QWF=Ղb!ke'O>qxI z[SUku/y9|;=THgkf;Ov0ь}|M2ͳ>+Wv'ɯ7#`NZ&/=?BcZ ł1VEȄNbAV|FCkhcQh;UA~*::K!>-ahƭIPe%DD auEf}e5t:H{n.Τ: 6KV_3B7?ccה BЗ!Cjs2x_jK7ƣO_Uaٽ\=D 9|T^|RÄW8O"KS08 z5&kp9+uM3N\҉K Ӯh9)B%,Rk -UhRb_NN4,UF YZ