container-selinux-2:2.164.1-1.module_el8.5.0+870+f792de72 >  A auoU]*`p( {DrMUq;Mu-)Iۍi>{x}Kѷ8_a7ZPN*vL g5]bQ&wt T[Pܥ桡;G|䭨1Y3Egcj-U n )L) $Y8Bl#uT0& {Vٸ<2[GjQOjX$DVJD.S)(ӵ'Ѽݽ4F#AJ#h)qrM¿,{w j:@=\6671 ciy3u$mE'DK,<_6=16lϾ !U1M/mK)rrS#+1t<\!C|ŠB4*#TKm9P=ҧoxO=u(Sg?l#wmȢ_*d%:NbꅦK1Uz}N[)䇍9Ī% 2a3aeec70494f0be0af99421e5e91fc373bec31ca519c59cf5822547cf9fa3c135f5de86a54806ed570e44f189923b206c88e184wauoU]?A8'~;gyYvnO#<8n Y7_bICH:U3R uʫ>ZZeCN sN}.@;rxh@bx9P9r3XD\)&QrWga=9 v lg)7s8q]YL aUW $?m4nb?U*ĨvʰZucaҝIY-2s{E~@HD`HQn1D hW8+HTN45)IRvI`(Ix #EA,4컐etYp7b'~XXkud{k.IG^TnHIi"P[Lк|>pFM??M/d< @ h 28?x   (  <  d   n   x     D  l   ( 18 8k9 k:!k=F>F@F BF(GFL HFt IF XFYFZG,[G4\GL ]Gt ^G bHdJ/eJ4fJ7lJ9tJT uJ| vJJLLLLLLCcontainer-selinux2.164.11.module_el8.5.0+870+f792de72SELinux policies for container runtimesSELinux policy modules for use with container runtimes.anx86-02.mbox.centos.org CentOSCentOSGPLv2CentOS Buildsys Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types > /dev/null 2>&1 matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi6)R_bbA큤A큤AAA큤A큤ananan`zananan`zanan8c04ac861d425e9947eb5bc06c3125d682dc981f6327e789ebe1c4eba0d856fc0389dab4c8de315b75e65f20f4e606a015aac29056e561d6f7cb6aa588f431a9e194e1fd0b409d85b63543f76708a9035dca5d5e802b7f61527156b8fae903dfbc1acc048e5207a32a465f3408bc4f2766024f25614273f18d54a7e6581e608arootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.164.1-1.module_el8.5.0+870+f792de72.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux         /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sedselinux-policyselinux-policy-baseselinux-policy-targeted2.5-113.0.4-14.6.0-14.0-15.2-13.14.3-9.el83.14.3-9.el83.14.3-9.el84.14.3` @`9@`Ȗ@```q`@`@`N@`@`dd@`Y@`&m`_T_`@_%_%_F@__"_5+@_16_p@_5_X@^n@^Ӝ@^@^^k@]@]B]]@]|@]@]X]W]R@]@\M[[ͻ[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.164.1-1Jindrich Novy - 2:2.163.0-2Jindrich Novy - 2:2.163.0-1Jindrich Novy - 2:2.162.2-1Jindrich Novy - 2:2.162.1-1Jindrich Novy - 2:2.162.0-1Jindrich Novy - 2:2.161.1-2Jindrich Novy - 2:2.161.1-1Jindrich Novy - 2:2.160.2-1Jindrich Novy - 2:2.160.1-1Jindrich Novy - 2:2.160.0-1Jindrich Novy - 2:2.159.0-1Jindrich Novy - 2:2.158.0-1Jindrich Novy - 2:2.156.0-1Jindrich Novy - 2:2.155.0-1Jindrich Novy - 2:2.154.0-1Jindrich Novy - 2:2.153.0-1Jindrich Novy - 2:2.152.0-1Jindrich Novy - 2:2.151.0-1Jindrich Novy - 2:2.150.0-1Jindrich Novy - 2:2.145.0-1Jindrich Novy - 2:2.144.0-1Jindrich Novy - 2:2.143.0-1Jindrich Novy - 2:2.142.0-1Jindrich Novy - 2:2.139.0-1Jindrich Novy - 2:2.138.0-1Jindrich Novy - 2:2.137.0-1Jindrich Novy - 2:2.135.0-1Jindrich Novy - 2:2.134.0-1Jindrich Novy - 2:2.132.0-1Jindrich Novy - 2:2.130.0-1Jindrich Novy - 2:2.124.0-1Jindrich Novy - 2:2.123.0-2Jindrich Novy - 2:2.123.0-1Jindrich Novy - 2:2.122.0-1Jindrich Novy - 2:2.119.0-3.gita233788Jindrich Novy - 2:2.119.0-2Jindrich Novy - 2:2.119.0-1Jindrich Novy - 2:2.116-1Jindrich Novy - 2:2.107-2Lokesh Mandvekar - 2:2.107-1Lokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- update to https://github.com/containers/container-selinux/releases/tag/v2.164.1 - Related: #1934415- fix the build of 2.163.0 - Resolves: #1957904- update to https://github.com/containers/container-selinux/releases/tag/v2.163.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.0 - Related: #1934415- do not use lockdown class yet - it is not available in RHEL - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.161.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.159.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.158.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.156.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.155.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.154.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.153.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.152.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.151.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.150.0 - Related: #1883490- synchronize with stream-container-tools-rhel8 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.144.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.143.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.142.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.139.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.138.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.137.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.135.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.134.0 - Related: #1821193- synchronize containter-tools 8.3.0 with 8.2.1 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.130.0 - don't use macros in changelog - Related: #1821193- update to 2.124.0 - Related: RHELPLAN-25139- implement spec file refactoring by Zdenek Pytela, namely: Change the uninstall command in the %postun section of the specfile to use the %selinux_modules_uninstall macro which uses priority 200. Change the install command in the %post section if the specfile to use the %selinux_modules_install macro. Replace relabel commands with using the %selinux_relabel_pre and %selinux_relabel_post macros. Change formatting so that the lines are vertically aligned in the %postun section. (https://github.com/containers/container-selinux/pull/85) - Related: RHELPLAN-25139- update to 2.123.0 - Related: RHELPLAN-25139- update to 2.122.0 - Related: RHELPLAN-25139- update to master container-selinux - bug 1769469 - Related: RHELPLAN-25139- fix post scriptlet - fail if semodule fails - bug 1729272 - Related: RHELPLAN-25139- update to 2.119.0 - Related: RHELPLAN-25139- update to 2.116 Resolves: #1748519- Use at least selinux policy 3.14.3-9.el8, Resolves: #1728700- Resolves: #1720654 - rebase to v2.107- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux 2:2.164.1-1.module_el8.5.0+870+f792de722:2.164.1-1.module_el8.5.0+870+f792de722:2.164.1-1.module_el8.5.0+870+f792de72 2:1.12.5-142:1.12.4-28selinuxcontextscontainer-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/containers//usr/share/containers/selinux//usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2noarch-redhat-linux-gnudirectoryASCII textUTF-8 Unicode textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-8f3b8936a84a398449d0c6d80a5a78384d7271931faba5b89f5b7d9c10727487dcontainer-tools:rhel8:8050020210728141601:faa19cc5?7zXZ !#,{lp] b2u jӫ`(y-qBت Hr(uw?*c!)Tq_SCkŻ aC>cXP,o0rÉ#~kvS=7ozwګMJ0pܳXZ0}vƕXRDՆF5b$nW$bY.̿`uxseɡ=23)WH]MĞqyFNeyy y򗄞[5[PU9/$V[vіBu#M>in{WaިV4 sA|MV +- Y]M礻uKhYt/_f0F *.Zw2$vx0mM?[yѝ/utҬUW կV` b0Eē#?D0\b#T[-WT^dZ r}}q}1v2ZUQa@>G&<̦b[,bwP`(^úH2sq0O(Am3u jSH'W[GYo1uy7e$7 e, iHM16g`#|Yڙ2 KB*D3)&M!"~uo(hwRC$~8Y=nn0hj_'f |Xv?I;+B,? @0tg )L[OKkW!\iri+Q, ]$rYήgMdzE>whS U{eQGutrkBM&(m;#j^8\YPeŒZl܋wPDLAsk'RYȣ9c)]L+I>oŌaSb/+<&jע d:~,.mt ʒ6OD a&k?xNEm%Hɥv5+׹7˄R \wkp)DxN5=UEDB5Ssb-[9tYy8յj~U2P4TM=="!ȃG˝,4{ Cc%?KL+ iY1-7SRLs<($dNfDNĊ}-c5zϦ2O9&svW_u" ԕDa1sVEe&I\dQ+'ѸEaTEq]`v\"բ6E!E/x`P:ӦE%a>p H^oX&( DcC:WU*i.jkmPG OmO_Z2wvs%C2mP9Ry JF_PnhfU"KXog4?; ?-ʧ"i5ն8t~%MπZDkAY13{m_BH^1ǐ&r(\D'N f]ظO1@x{QBqH~6Gj~Fo'1 y!IAZS@Å0l.{+5&EUkN($;wBfQ4t"ơ)Æ6*z)}[؃"]y9;eP 9u"ڮρ g_@:)ixo;[;2&RJTqGŜr02_G ux5©aC:u=ekեfIaZ#Xjz* =p#BfRWm8bҾHCPvĚZcvglj݉P_xW9#ved L75J%WV5P>g@Y8W5 1j"v:v MGRۦX[Mz3ጘ)8EhvNTSB|Uq_ jj(OynS6׏汀1*ܼ8aA 0v8aRuK/S4,^F&dSsxbٲ'B"eXhҥX ,/u{m]05 ƈ6Jw!(^ɴ!AjDtu#Z"*YBv>pJv$B,*huPAQV099]]ǁU[q }8Qh048X%Puk(`qh3=Ź1$Bn"?*1u7LCt^~9~ YhG5t&:?v! & C“C4o<˷=^:; ؔk;'(/>iJyh>ӜـQ ɸLwuS%*|Pu}V_ukF F? \ً>+[# OÈ^t%IPEuکgoJA 666Q#3 i|sj? 5\aUA2SDŸR[m_K[*0ɈO? Ѱ%36i(0oW|U^Ac6W"^Oq{(,z\BQ(J*!# ȈUNa5AP F08A{A Et_kLIٳ!.%,+dNFN_en{\0aB GOH~'p*9f{ILwlXDN bct;3y A[!t˽s`֬Giľ-(ۼ ôOv0s8o .J2Rv_lBZl'9*bHl 㒍=mou~m>-|Vx Y+3n!5)ual%8CB jR< 0a sqQz1ďO]iS/s'g\_ ,eAZ=Ԑ[U869 ݉۫Ґy%QY1;3$ );pt~oYB6-2 fAf궫p*CYi6M fiˮ߂p@UQ.):]\s5/9 ސx)xιo=?MVٷ|(xDs\RWխ_̘~ɶ*"]BB*qpz%'! =>$Fe>׋Kߨ4nOYn˚'0T\40V -Dݜc`?!@χt#ATH. #tNPW Kl}lZ - <Ĕ\Dp'y|2S<W%n} ߎiMYo;IhjKM %v2l6>1T_k1߻[.mݺ;*w0hi[HFA!͉tΐU-kF[\Jq2ѾFQS-@Lsp^<#La32ݚ5j }_fl?iAG.Y+7#B80s-h?+ӓƛ4F|Emt_(@M~`Y{:<-2/ ,@9P)Z^lq*G؎Zi#qɩ2['~Nl1qwYLe]I,tVF!=Ȋw䓧Uhs6#Q5 _ۡ}('5VÔ$ VJE;cdLvc:HB*gez d\ 5=6!ZR!#;n_*cF߰i2\ *^̐8EVۓ<[bo?77RH"'7ZCg㲛;|IVM_0Pxb[bHZ^}ЋuN ~>@-aqzV8itNB?w-дz) m(Xy.X z1Qxi-%,` ,Qub}~-ȳA]xQnŒL\iQ;./N@_Oezs8U#2K_8Rh\Rj{>^LK:ž5/[=CJ \Ɵ7#8y\닅i%i6 Y*1wԛ[>2 Z{'( KuqCOԾ0]ҷX`R/\9~>I9To>^F S eXqIBe~ Ҵn>H+TF"Ο 1$m#XBWGf MbW2Y 9htudԝ ޡHFU6@P'E5:1G-0: DK4!=\vN +X]ŢTZ2>x7V5(\n~998Q`t &s? kW}2fw=G|pLKՄcRrꎽLlor֑,m_K-EBod1+8(1,T`fၸcϹhfusla2Vv 4%+ݠjge+46H^]/6/ eT2&QD[ykk/]lR <:_u-B5Bs'T 8z]/=D$hfOU-مH?t/s5s ˙ ;^9ȡ #cd ~[*:ؕ?87 mG6Ļ}ϒ xuv@?uO;t^. qAXJ(?6*c#7ʌ z=Ϋa~@jZiO+R"nv0l\~nyݟ^2>XwM0; &¥3<P;eG˜=6%,,Y$;\\XU'ys`|M/):&hP+Hw[>_pvV;Kw]j1'<m%Asɕ8HAgB˳y:1' msd 87t1?o(Ty o0in @N;<2& '*b/=CY1Rż\'Q-ӛSs+tܪWfjm&=_;< 2 >ޞx\(sA3{}.q[f ga!_,N q$5Kt_)H)վ#raD'P'MWZל5ʶ HW$)%_fﯸ60Ol OuԸc\k(]hB~ĭ*5Tk#K9Iv,[p # t[Vuˀ l(CƀB*CćkPQh䛮)SyDfppH@,-f$uuU䯏6/fG_qmV2Yt4\WcɃa֌J+X_''ng>Ϲ|[2ԺOQQ {=wWYZf2QEDPv8> "҆[H?&X`U>\/, -iKA(a0CmH2}K&&2p!(:xv:-{-j}s|*f7yF ELDi0ܜ*Fdö 7(}J(nʛTη~>1>{S 9?\xg,jibi;'DU2s/m/·zy4tjhd^>|qfu#ٜw"4'oNY$[ ӊQ.҇5Jv!kq|F5VZZ<{Է_"]<Ӳ{h{ q> nSlG0'dsF_auazl:D%ZjD=ݫc8d؎`0DmDr=X0a!cʸRQ51{ȇWhswe~U-[?4K$rRQ ,cҒ<͍qϾ.pHh\ۏ0 гt)QIs-#B{1EoҚvI J1-PjA;O3QZqHm?IuaEU1e3`Vŋ H_M㫊~"izOoZӶuL㎶H\a:P)#Ӆ,:\v9Z8 VΪ<ၦɈiͩrʽ=1p)N.,-->02HQg(SO} aa[.-P.-ڻn. n0ThL#t,(13)Ptʌ^ _Mؙ[Zt#)`"SW=kv% ,`eX0JjD:}8Fr=/8w>E 87CFmRV9RV\wc#֛!:bt}6+QƨﱩY~2C5yY5{BDGs7"R3<bH#JV4Nk[[Ar3Qf`f:Sw#H!!mxl3!XԉM,So=_QPAq~w Ou2YT&@qeM 7ev埾a1'=]kab (8iKWbolG9(l\/׶+PJXa\AxjyFnf8lT!1Ǒ^/e4T}ЭQ=*IrSA2e}9Z VcY0ES9H1 A8@F]2[{wFR71 RnN%dt @Zj7YE@Stoqpa3M_9"Zq'(m!TmBrT&5S}ꚨ ;*[}.&~drEb7j/Tۈz+PWhq)`o)* 9?7״Rڹ;D he>Dkk4Ew; JΜ]W?A^T/霤+s-ZbQC۲WBna\bpey.*~l Ha^vO,zKuAٰxt:]'j$ JN}NQ19gٹx׋W!H@搇WqއugC6-8ӣƩN `}[4l'*z#-`DGԟ-ZM08,'>~\8%w##}zKlOM(d" $@7 bfge( OvVogŬ-s+%=Z_R;jggezQuҷ,uT=$+&=2#˝a`I{~00s]hSދzudkB&ZmOnMhF|r0ծŀ5=37(9Z.32YsA_c8Kk%"7G} v>֑{Qbt`~u$p|棴1ڭl?d=*51M~?d g?|^Brn­ Tw+D wU?+:9,ׄr[iW4el~@JꡲFz,~xK<' ^[w14,m%D k _88w \_*^?7,u nd;om{ Xb- &+yQORk_~ <⾍ ?#>k.*m3Ah׏J$2}WBeg$'i"*-cP2طZÈA+ft@Â%$&.. 1*,"<\  )M#XFMaWF[I>0&Ј< =yV?2]3½%Gܑ[3Zr/ S`/;TM[Oeܭ ZMLȊÕMGUR_fNn=I\(8 z^8.{ #{vIKp'㵝6_`r2#`?a[R\~qߏBrԺ1r:8;]p31EEYKyIXk7*]J,`{*%F)Iܔ8Y BFB F$"BPS[ަQjfEe^щ)CU=S;h8տE:0jW 5to $}CCbq2g1iYг]ttϊ;u2M2D†1oOvd8x5Iޢmc>A i:ʣ*P98rHA$N~}}/BF#wl7ƴ1F.DgIv-}cc6v9Yҽ~&䵻LۋՖES^ݩ+( Ŗ~[&jgeZQ.4r$oȿlw<7v㶙8YKb`?W@6 tZ._1~pIVK'%uٶ|a^a EU8զ7ReYR]$OK9?ڑ# $G{8*~mYM|Aq<(a6߽" Ka"TX]W侬lVNr݅AV;-,QJͣh6w/ĎUJ;he8,a F2ꑯiwjpeC|ƱC+@艏99W/rq΀NM*? lJpIơ%lC2.it1k'@kH^-) t>c~ގ/=j)!MrOlC}/ϧٹs3Rw-R}ohci@T*k c""bSq(XL2QWHb#$AlFpO%v;6^aPH|)  놉FM )t~q=MOw/*u Ail _PyOՅH:cTwv_ZRhlW+bm ߋ–!HXŌsGr*BFQ(O橹qlK3'23)G2T?vnoU>CJȢ-<{SNkx f^2'CܫL[lr ܃Ws7;U^o NY[nYY\M9b&>%sgM+?yUp̰>(Ţv/E:$4RWA AhlQ2%ܓS%uTK.Htجe1mE~"D.ӷ,1z\Da݉N~e[8pEg: ђ`pmW<|"q(ǵ4kHǟ9_غe;xC!%ыYA7ei.d QfmxqH!}1zaCJnFRyb/cT*ӎ8ەN)y4CGwӡ T -v5S' M~\jf::d4դ׳zw#gu,: {%GRÄJK'0bYVژ̕=AM y,DK^~ 8lנ=/ldm^k*u}G[&&`lj¦H3kbeXݚEOs٤>te)@D1_˔>OAD9)F8FcLG2qb@#RIl~}er)*uGeI!).y|?JolXt\-ُ6Y3ߴX1Q9fYfb?,3Fl߄kڨMO@+ޘ7ՄaJzu#WaisƴYP)^f1MK.ߌ*5VۃBd/w䳗 bSG5$%jըxr,h wz!UԏNHK?6~+QflFRg))OpZ(f," 4Zk#/!7>'F=/ٻ&:ƜZ:%RBEVi?v4S޼Cc{Ǥ (3 bp I"%G)c{xˍh22gť'N{FjQ,86ٜnT`x'kV,qP44ilZ2hӎ 闍Z@i}N"yP.$/S,bK|B6aATA-LR?@qa֪h)9dBqOZ$Cmaa3$ܹ3ՋtlQ&]6+ePu. o!Z,~M;H+6Sf,@S/k4uS={6ݒ}3*-wlJrB>=hwDզI{ T&?Mg ҳzQ^$`5M8]:Խaf1K%1EL_ ′h=-<y҇+R[ؘ Td|~wS䭓xxOA"4SCE.7^O>16t@ sߒrpxL8 +b@ӽks;KcsP3gG` ͓oIg?58L>2BFFpchphi8W#wؠTO"5:k'`)SYS7G*ZzoyqwqO.rT[c"'-fN7 %a)(7/S&77LP%wr(okf6~ ȲC(ޤ ([3ϖpΈSOr*ׄ\ۧ_|GY*k57v8@go~-'~,tMH0*vhC!l$\NozIRցܠ9tʯol㳱S6o _كlph2*sUƦBo==ǨxV? D]=ނ(<*ψ!:EO5s?;;C-80F 6K  WS5ք9R | Stz&zj4my"ZC.bTJom؄YMϊqs(ҴphVX{QeG:-eQz!Sr}outR" ۲^Vd8#^8&89 3b:\ݎ1D>NtLZMY"t 8w0QrAH6ݍ fWz 1l*Y{ dw=9>@8g"!; Ҙ,U3Z%pDq?kR]֪aƉRy)ehif|[LIP qݲ(`9{z %`AIJV-d'oLzr\鈥$trܖQK ؊v"֗U!|-N0̻?=S9~Wx4J[>}HmuaV EL( c4^ڏ '@2krt=9]'nƲCza튁 G }e葫댫WmU.ZVq%6W6`k?ը[Vζ3~&-A&݆>~3O).T͂hY{opKzH>_=I hSD׹ҘqУ "^rsjGA6 55oA޻CaZN|Y6ڻ/ Y-͢+1F&K r?LJKa- 2ZK`nEѕG\j{VVLj-$/S qQ%Q)d.ZV~YYȧ I_,}RZSq})L+b{Nq„#ŘjQ}#q;#aנ}}?<$Z^ǃգEI ι~0wru,DN|L }ͩM(i^`5\hxoÄLVO UEXv#&.CACa‹k:<#GdYN nu|V1QNI5И8Z >pM4/I &jsf%3@zg mqsenI͡RKWfQQ6'؟}HB-F@Bu2`KPޅHa T&lkL$>%[+țVj$L}L?|M'{RbR/cGJYo$Cm~EWD !2SzwZ)EQĻ ?U-rCh8]& f?I`>*i~rdUI5e SWIY21x .k{ ~vyHOM$;-g5=?w:d:6S֚L IG%eJ?[.H= 1!:$IL^+\ޑ5IA(zFRh=EC&qaKM:ߊsd2>3/GPљ]/VN_pCՊC>>=Beڮyå~鰫bVlغWZ"/x˅YdFOHQv%p:9zcBr!jA~vڟ װ\W iXՖ$%v.E ħ Tvv7.b/tGX"a96 ^+Lw+FrאZ %!A[ lͥ⯘W[L!K2IǣF>>Rf/l!lk7R#jPɿt D$ Hښ&R5/0BCq,8x\(+Za Xˎb,ҋHGUd{gFn739dڛ)Y=S<GA4C`/'=T/Ѱ -y //wq]UHA<"0?h=.bsy`e52zM-jǾXbbe[&lR?#1ڌq!YIIHRa4m`爩Æ5n^Vu@ށ%7ć_Y@NΙ*Щ*Ω\s! HL&>wX+8Gu3G{~HD=UE->o]Y!P>Coch%(9%<@Uaqٺ$& ^ކDc5UC"QDyt;'i*=xN<ٛ|:} &jz|s{hc4J|f_2ZQk>S~IK2ͪ4B ڒP=!en=HDrmP9Pկxtw fC]V8YH^YAxN]֬:Otf)e%@Q+ES`:oC,[L'p{0hkٺ*_܏UxdZ8M3M(*&/FvDDlWX`ēO̢nLDl^Z A$ݽ%3P)S;맟zvF2*W^BX%,E!V;_(j":A1?1&1tXڐb^+Yb~ 7sίB+bIe0l&<Ӊ_uP_,fĢF^]@1j^[t LH +E6JYˡ,GƎm5 $t}EF]Ҧ5c4™Ho:Byӽc>6a5~5=y>9LYm,80e6<(cqk<O`D̆dhjj{~b"wL=Y@ FQ#(6 /sQ/K峡)ĊTPfJ$ <ŅԄtU)YrnHUiSVo3ЛrY3 Sk_(YUl $_n%uHnMhU?5uoGM b/-|LgQsqpd0]_~=+ęgL /6Q/&s3K^X^_x}wеy!& Mt6I->ܼRD _H6j3;Osˣj;_J!j ~렜uLJʐ;N\FV~*O^֡.G?KU! ǕCJQGp{p/Fҭ[@)C,`j|H͛4q:2PO7o3~DG b@U4)5.Z^Kb%Ȍ|ޗ@Yn{q׬N$لwr"/¤ :.l,nƕhVF5?pXCH_>sݏ!hFX܈D¾9#'&wYo,>ܴ"k} Xk䛎اuti4PQ|~6Fa07&Ch-\ E! 0u)hw@An5_YA 2&='}Ҷ?h"NsK18+@s9* ƈ|Sb}HycPH- =qmFhr&ƹD5Ȕ/\Iv5%RP4n菡֨лU.#`1E'6' ظJ=Ǒ^E'Pqw}?;GVR+TXZMz’e?)E4-XýP|w<ٮ1 e >D mAp8n  Ta[F῕,)1ZB^KFF@f_%L=)&ِdwξ]jXH(h& $Luu\Juϑ.m샊W% od^SVz:O(*zO[ˤnۃv~:Kw7MG9_H~lٺٽ#_5+KOD!ԑPyŠmD4"t7Xb3/ @iUg>Jfw9 2_l2!KAX#^+1!O ,?z,c?+#[yXjdUf$,4v]`SŖaF,V 񛧴ﴘ]+5 $OL/KLBuoQHUϜ^Q $9Y1臋̚,)"pf bfL5Eb]~ !A᪞'cC|EE!5j N.&6kS,qn\ΐe7Ӑ9ir\<˔pp;J@?0NbZn s|X1"imkcD$%b (C:FM! @ s/+)U.z. -!GINgP 9p¦\̰H׹Dʍ -L| z\jyuг .şqIh Ze˦ -2 ZEfp7*+pG4vA7hfux6=rLP8y]g˧ߔG^m#%wAfS#']Ϻ.x$Yʶ L}8{'P/޹@,k#tf|]%NتH=%{\C"ShH%=#f0Z=gz,)'=@ hNH/6r>ג8!C _[t ou/-AP*܋H^(kgM}ԝhLnF^ip&u]S,V <0]13|Ӡh=S hy]8 3H_͍-TmQ1 ! w/,r=?PJf~jOB9`c3( N…0,,]B_vB#5rY</GlM?58!1<vIJ٬ Gm]B)3F~ѧ؎r x` gPh#Ht8Fo_┦v<./",.'\P 8bw_Hs&F>` 1IZ/ Rz*ex;궰]}fY&=RLN6?~~n rM9,&1'*<s-&Ҹ;=߮wv)rc RD&L~'q\#O%H@r+xGT(XW>j?3^;?1FL?A9-RQ׻5} Y&|;FX'(s0 eehRnB`1#PqnqR!UYgQqSu7L:t_|\\&^E8mCo{ѹsȚOm`$#Y8c'\ܲ\GUHW&]c'OdKtkt"ukH};\O\*.j:yaI99~i&-YF *)VauBۑ&`j Q@J[ş#0g µS%t G0 w.h93LJ2TS}K+ b.'dltEl޷h$PVId`,)LK-3Okn 33C-KJ\/d+CkԻ*NLՂ\>j)tf6Th2('.lŵ;y ǃ_cCTG4} 283ʖZpB#щHPkŅ^ko*attEԠ鉻gs)}TPÛGCE9+{/ I 6YXI5eszPZ<ƅ2u(99p;S #15屷i,(:y=vU]q?%n/y!h;{/j~lQ$K\N˨(|L"ǟc8o, 3o*@-cքN lTL̪H `*4MH2ݐ.GN.,15i'_,c_%Er9zdyrBJw}ʓ/n$O֘Su͸ԵgYԜeVTYyIl k r *B iJ/UbAh".=1Q.t##1:ۛb՛'@ercv#"g T S}z7&(m}|dxkA2gDlfT| vO6%^edpo c8I|b-RLa"H FORCboC*6}k%4  YZ