container-selinux-2:2.167.0-1.module_el8.6.0+1107+d59a301b >  A b1>U]piAP7Ee՜ 2}&uˤ$:ϻurmڽA_F8ZH9hV4.}rٔbUwVȁ߮aI[^GHT4hsXSB]'T.$kRF>t|#IJV `/<ן($kj&Up+[[H2?>υ$1qrUhtdM ^IdWNG AXV#y0U!KE].o1Q U=PvT 8GO܋Euq-db$4op³ Tfl?T6 XyHEM|k*@߰뚓J"ڋbOC"d5%]=gcT=7FVHp{da*A*Q8DWݙ6w u}V>lz89;  غGIRfщ*Nbf5389c734ca0d4ef040724f07ef96cb58a74722e1ab5ed5f98170ad1aa8c39ed57651d97466d9286372644f47285e66dd36bf78b1>U][2\x/)p&%;Ԡu`#)uIxuLf`a||i a=.5w{圅aݪضbwE0N.ApLj~mg-ApmIQ5NWިuIuC]:sb\rZL4'Bym~A=TS바x06ԃ#~NhgXlFyUPmۃbPt!W W?=v)ckd='$8`ryTPn  -'R4u-?+⡖p\JggiP8>T'֎^*mRZ(ϐ{ydw~C@֭#Mj+Q: SypFO ?Nd< @ h 28?x   (  <  d   n   x     H  p   ( 58 <n9 n:"Vn=G>G@GBGGH HH@ IHh XHtYHZH[I\I ]ID ^I bJdKeLfLlL tL$ uLL vLtLNrN|NNNNCcontainer-selinux2.167.01.module_el8.6.0+1107+d59a301bSELinux policies for container runtimesSELinux policy modules for use with container runtimes.b0x86-02.mbox.centos.org$CentOSCentOSGPLv2CentOS Buildsys Unspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types > /dev/null 2>&1 matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi6)Rc'A큤A큤AAA큤A큤b0b0b0a'6b0b0b0a'6b0b08c04ac861d425e9947eb5bc06c3125d682dc981f6327e789ebe1c4eba0d856fc0389dab4c8de315b75e65f20f4e606a015aac29056e561d6f7cb6aa588f431a94dce6af8d6b1b649d30bf5666e4513933948397b3df5f008711cc4365d831f28b727012811742e205a334fdbec048071f9c1da9e07da88503c521301217f1148rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.167.0-1.module_el8.6.0+1107+d59a301b.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux         /bin/sh/bin/sh/bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-python-utilsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)sedselinux-policyselinux-policy-baseselinux-policy-targeted2.5-113.0.4-14.6.0-14.0-15.2-13.14.3-9.el83.14.3-9.el83.14.3-9.el84.14.3a'@a&0a /` @`9@`Ȗ@```q`@`@`N@`@`dd@`Y@`&m`_T_`@_%_%_F@__"_5+@_16_p@_5_X@^n@^Ӝ@^@^^k@]@]B]]@]|@]@]X]W]R@]@\M[[ͻ[[@[[Xf@[L[K7@["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2:2.167.0-1Jindrich Novy - 2:2.165.1-2Jindrich Novy - 2:2.164.2-1Jindrich Novy - 2:2.164.1-1Jindrich Novy - 2:2.163.0-2Jindrich Novy - 2:2.163.0-1Jindrich Novy - 2:2.162.2-1Jindrich Novy - 2:2.162.1-1Jindrich Novy - 2:2.162.0-1Jindrich Novy - 2:2.161.1-2Jindrich Novy - 2:2.161.1-1Jindrich Novy - 2:2.160.2-1Jindrich Novy - 2:2.160.1-1Jindrich Novy - 2:2.160.0-1Jindrich Novy - 2:2.159.0-1Jindrich Novy - 2:2.158.0-1Jindrich Novy - 2:2.156.0-1Jindrich Novy - 2:2.155.0-1Jindrich Novy - 2:2.154.0-1Jindrich Novy - 2:2.153.0-1Jindrich Novy - 2:2.152.0-1Jindrich Novy - 2:2.151.0-1Jindrich Novy - 2:2.150.0-1Jindrich Novy - 2:2.145.0-1Jindrich Novy - 2:2.144.0-1Jindrich Novy - 2:2.143.0-1Jindrich Novy - 2:2.142.0-1Jindrich Novy - 2:2.139.0-1Jindrich Novy - 2:2.138.0-1Jindrich Novy - 2:2.137.0-1Jindrich Novy - 2:2.135.0-1Jindrich Novy - 2:2.134.0-1Jindrich Novy - 2:2.132.0-1Jindrich Novy - 2:2.130.0-1Jindrich Novy - 2:2.124.0-1Jindrich Novy - 2:2.123.0-2Jindrich Novy - 2:2.123.0-1Jindrich Novy - 2:2.122.0-1Jindrich Novy - 2:2.119.0-3.gita233788Jindrich Novy - 2:2.119.0-2Jindrich Novy - 2:2.119.0-1Jindrich Novy - 2:2.116-1Jindrich Novy - 2:2.107-2Lokesh Mandvekar - 2:2.107-1Lokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- update to https://github.com/containers/container-selinux/releases/tag/v2.167.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.165.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.164.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.164.1 - Related: #1934415- fix the build of 2.163.0 - Resolves: #1957904- update to https://github.com/containers/container-selinux/releases/tag/v2.163.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.0 - Related: #1934415- do not use lockdown class yet - it is not available in RHEL - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.161.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.159.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.158.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.156.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.155.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.154.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.153.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.152.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.151.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.150.0 - Related: #1883490- synchronize with stream-container-tools-rhel8 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.144.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.143.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.142.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.139.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.138.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.137.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.135.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.134.0 - Related: #1821193- synchronize containter-tools 8.3.0 with 8.2.1 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.130.0 - don't use macros in changelog - Related: #1821193- update to 2.124.0 - Related: RHELPLAN-25139- implement spec file refactoring by Zdenek Pytela, namely: Change the uninstall command in the %postun section of the specfile to use the %selinux_modules_uninstall macro which uses priority 200. Change the install command in the %post section if the specfile to use the %selinux_modules_install macro. Replace relabel commands with using the %selinux_relabel_pre and %selinux_relabel_post macros. Change formatting so that the lines are vertically aligned in the %postun section. (https://github.com/containers/container-selinux/pull/85) - Related: RHELPLAN-25139- update to 2.123.0 - Related: RHELPLAN-25139- update to 2.122.0 - Related: RHELPLAN-25139- update to master container-selinux - bug 1769469 - Related: RHELPLAN-25139- fix post scriptlet - fail if semodule fails - bug 1729272 - Related: RHELPLAN-25139- update to 2.119.0 - Related: RHELPLAN-25139- update to 2.116 Resolves: #1748519- Use at least selinux policy 3.14.3-9.el8, Resolves: #1728700- Resolves: #1720654 - rebase to v2.107- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux 2:2.167.0-1.module_el8.6.0+1107+d59a301b2:2.167.0-1.module_el8.6.0+1107+d59a301b2:2.167.0-1.module_el8.6.0+1107+d59a301b 2:1.12.5-142:1.12.4-28selinuxcontextscontainer-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/containers//usr/share/containers/selinux//usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2noarch-redhat-linux-gnudirectoryASCII textUTF-8 Unicode textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-8e96e58ef3d60f085d86593efcef983a5377296cf815c7eb6abb7fb724b01bd56container-tools:3.0:8060020220315184500:2e213529?7zXZ !#,m] b2u jӫ`(y-ctm9/ģҥmچos%ֶ;n*k%.]|}'Y5R Ϥ=i'8?n .*-!S#~uuVW" d H[4u1\tt75mL^3$qHE:QP6$dCE?lPiP%:$0oPbn+'w8YsexX0Iڹv (ߛ( 9z QPPDQ{܆]]k'[`0 (CTrU|] IJ.Ŧ[T?X$1`FL"Y!DnIΩ'je .5WO-hdoT=60~< ]}ķ9MhY8F""NӒUي3V͵:j;- >Y3)6P(glIe#A}=xZ0y:Qz"Ms5ǼՕ]G']\ 4)T B~lp(I ]vrqQEfMAf؈Aw}ieo%BCM~jH~zF,7@El&63\7f;D #wm+=oWq%->Dm!ak7L Rqhh1]:>h*̗vq!*elcL0x*ԻYzΓI; V> Q=gPRm] ks@f W&H 7_v3*)T;<\u*P,&Ҵ/Z67urõ֥@4ov*Q /+Ķ QdA3I(]^&¬UuMV9vs\', o'2\VN Mٿ^"Y`"$lPϹ-{lV#h,Rh:ns ,<7ybX'߂މ-*BT< BZɚhSZ0>K"f2>ᐦua9տN?hv> 4tũ1Y gj%hȒhX׮9]aNCx|l;Ա(r}dh&.\5ȶ?ޤa<ޔ;!^qOXSAEzI 8*+"{+s|+EeVm 8L`%; l0f*eй8 ЬTG^+lkkstY2P~edK3aoW<TQp3jr %r):[@#ކe9\ |SEAa}~^ձ: ׃n{wxRt[&a!3W/땼'F > mKkNA+ VҲ}%c ɴR"|7聥G2,MArMXHQFp(tlū۴\F<͢xdIP_6coLud7:/عMP5&vV03Ut>F>СOcveB +i"ң, 5kOVMF ԜS@ -w"_yv?O^@ؽ K8&Ʈ6$'MwViPXD("2cC.X"K60-'@*-x>Z '}B1Hxii 7ii-QL^ie*'Cpwp}]Z+Ŗ85v>S^gm+S`OS&d}W2D+8<+m v`C{kr&qp/o)dwmLֲwtOψuaOMK1"# fa"_3|ƕZdYlS(wA45iǒ}k,#/:A+6Ep%M`D:9)' HHLwz>kp4^{=1=xW<]Ze9Ա<¿?Jx,Y%z]Xqbh_Xv`(FS272\6QM ̶؁7pd#W;85E6ϞGO=4:*7" |J ‰$3L {v؃ ]]I'ܴDJ~dLئ8삺d1iaw!(G?x|ЫBmUl<35CC\>-ϱ7@vZJL!^7?@ ,=eVVc˹M$}AӖ=UwS;SUQIIVP/Ak E Toqxbrt 8DGd%ŭgW%~t fgnltvWʵ$ © ☸C"C 'v҈P?͓*`=;ԋ9gj1Nu!Q1 G[E.^**4pQh=!{(9`q|iiQ[d%=}MLFy[Hqv-#ԹXt <&Mm_c/ϋke۲ث!/QNNp~h%S~Dt%=S3+fyen4:5U0?\ؓtDkǡ5R}@aK԰FAoK55.AlQC^s +Tgk@Piхe:~8;vJևŢ3Rܕ%R4Щi;N+ nO):O!<]ȁ8/<_U7JbDAJ@c7A "{k{$U~D9nZ?\_3מ{3׈`*^]O]gPesuui&j'QIEf]VTp}Dzh%\xxempѪ͔Kp5O6 탰̱m&lEV):iC4VgrrNXJ2 IE+,AEl>1D*CiJSBK=- Tu\5xsSt߼T}.>PJGr- l 3 3|_qX cg4/`ogɤbjZ]"ܴp0 ۘ i&Rz9bHOR:S#Xu6J '8{Bh!PM@QCLuqWV:(Eq=xdv9 5|W)Ex?Ii# ݗ{ mqw*hc)-F]YG*[ɀc4vl5y|yqQcl&FLQ@ ZȣdDMȣ);^|QZO> :yZ_+1^8%aRT\Xmi>-DGvsjnϫ!;aT_NB% O5Eag.֧DYIM T} eQ_& sy]6 ?S7b.X$ar8KKK; *- v6]v{/\6P=q(:ױkqToY5,;@&y,W\בMAbx[ѽkҗp˓.(̢ Ur1Ekq?`4-" qsydpPB"/GKRVR1Hm_'jȲS'].}hG:d"Hf d@5v:gN'V۱a D/F^A<4;-E.ݱב)֥`I4^. V5EbB.=5yyōU!xoĖ;3jؿ?ڡ 2o<(*e.0-Hz:P~qo<[#Q=3b[87sy[K/OW> E^\ݑ?;A.Eqzţ/+Tyd2t=nij_a!B:, I 9Τݛ#zCxPrܫ+qa];|#Fc &fGfjoe [>rm^soUf1NytW,ESNi2B=NV{A[G{ƚ6<4a|%a9NG{$5,\q|I͘^MINGD7:\%U૆2h8-Qj3N<*ccn*SBhͭ6螫}mazy\Sbf G|8Ey@&C#/j{Q!؀D ſX7fVVzg)y^ÅwҖJhKv-I0}gc j!lހ;s&fy$ #`r9aC| K7?rL*DFS, H 7LDO̙6(E68uS0-$7(V|R=7HCt.^NLC:K^X 9M_3߿mev1X 01/y3ȉr0t4vW.jTy`4HFj;^Ǐ>+s8 CT2g'D')#Ҍ!v( X[mpѽ_*v?B^/m %J03M92PWGxT}28aj#_[]\Rmz`e=CWD{-갎PQH4VH 5t'.tK-s pX2`׆#k`SPb%d1#M|fhz:leXYs _}Y(t-DgX\7{F\_V yƮSoZf1Jk^?uyE$9t< ƎgUՓR=/юxPK;K+8Jb'yK (bNnH,^cJg^Mj,HM\EF`BG|j~bXVDMc2p*n$^=!ۘ:|n<ڒ枼FGzwqݳ)]!/1#$ԝsmc#lu2Mʺ^ gEJPV.}*AF(fb֥6ՙ!6cjz%:-,DZ=ա̬\ZO< B'Zߜ;H>9^'̇3Y_3ZmKJ;(s!,{zzn;V 6:aۦ# h+Y 9e`b*F .$q>*kG`[߮bh 7!nb' X6Rr$ve5{}?i (| 6Vq ru˜yl=\&i*sRB=>Os&S|AJȉKlja 1M( D*'CqTn4O?ͽ A!E}}փM8O#'/?ao֤NיB'zt }{S%Ù' ]Mb_Eh8`}adjݾ9y~ ` vTԧ`4:߶[f~ kwoѭ,Q $(F1FuQ8cwDz\ {gͪ^-sxP8B!+MIHTnR&3zD V`V0>iFC[\@ʫ|+tɿhIV@t⤕eti}_wFvEtz4+֍YT+՟~TA.vی=)-op "o:vPF8ۥah;Ȧu}IvgnNU!kol[YMЧ;+U(3fP/B L_(fxlM_ayk c *(YH|7Y;$D"dp7(G`%<1n_Rk%EάI*>8-5a*igyR78{)*x%d#D;HR ϯ PGSg J² Wwt>hFk35͖XDӴ@ab1Fx{1L&ѭLicEP  rMegPrE\\ ɡu>oY |Chj# +hl.U ;o fv7m#Ћ(sn/CMndtGjLxR;6f?g9ZR`"Ht9̩gC J*cX1Ptc*H1r`1( Z1jDž_A=ݍʳoģʽjg'{ZK1ۗ G%Eh0ERL 5`쳒j3ލdԚCWZa<#'mu/J/Uaf}"ܞ FoF"!V1 DL,O{ ͖r`a16N28>%CG}sF>&p.bLX奌}~;=xaH+=Ap<C(%|Z>JQ93* \p`aE ђNIL,d?t+4ִq Bʓ2-Ɉ)~(SYbK|_ۖ~%:-%wmxoE?l׽QVA+ٲqstUsؔǁjjx"E~"yN ÔP L}&YktqT7T% KK.!IY^R603 隸줕e Z1PYF,y>[:>I]t+ż6 Zʹp~VFؠX b|]wyz=Wr*n~qx,ٸ I#gL@OT/jGN! &Մv1uP!9dE ՍpRwY%]͹.]S1\ T22c6x%5AJ~C(Ut蔚s=0.62[RbVϲM t{0!]1%3Vh>-BI.M@#2bϓ6# Dt6՛H*WE$ۙk'%\m ܎7Y<lyH0$cظ> D}xj#ky4FS崑lH`re]o{ g&>}I$WhFr+Cpu7DPG0([0V7;8ӧ;4IoV"+]TC- ʀ_וC.pڊmt\Api4 8ً.̧&٠shf%\XŊ~`x+p9⫑VQBN s9Tﺓ X$.IJd]׎cЎ@"UWMPxUPr{b2UVd|?!%ϊI*aիTY6~АME !NOieWlBa~xty _rT=W\eXir]aHO]lXšō+Y}~N%g"@ɯp&Dm?8k]D%hJښ(X!mW$z laV0.䴉7R9q3i~߈N{LnP sX{o۞V(,/k u ̊Fw׷/OiWtKPvg D#Jwp=I>pAX  qJ6ByiN~tc/ e& 7nsvk]̝Z2jA]%>l_78qWpᦩ9,GKF:{ʮp DURz OJ"ڧMgbu%2"{аw_<Ȏn 4\l!!7͹{h ,mMQƢ}7#d(!`A :PP\lZs K*!͙@ٕ{Rܣ-b- +55` .duf0ǽd&7RJKTN~%fTɚy[TE\>_4 L#{n["eV}eAo VMDMǪw-bHv2'oꮏzGWzl'ԭm:0#bct fV f̮E2V$+=i/b̰mD1Ws?G_'UPo%Oy+0FtF7B_6`--@$H,Ls^˳{N#cJb<&.yWp `'(KCĶ(f?_/, @+h^ГUq$3:?|F}/X&4SaE邨zWC ia}0q(h$=8mq&M@ΩlQhP`E+Ǜ5#FWU?NGEgoŒoa9=dUqO12˧M\pWء{cKZ=8\7yItځ7oGu.8a]mԶ6[A s Eq \|'''f=PFC%:s[Ղ!d4>p`M iLqĉd_BޑݶS΢ݦ wm$[KAh|&-;-Lq wi5XKD寶lC^J+o{a|Z ]c3Aߵxs_hT0ŵH㹗<֐,qK>5שNbռ6)ೡplxQ[IKߙeD،(  |>5t9@qI,Rc;_OKU̮ CDY@nEDЯNg}Mh0dgm-dsF-7N?ҼW bSRvf> dT"Q7E]Ć U඀N+߉ǜRa//7<{27C0 3>ˀ:C.xb;i&wڣtrY `Lt>DvX˴^4\|PԂx~1 0 "@!W9 GO!$t79ts08um/;BpR8y93{+&KOK~'kv7,[Y⪙3e88Q qh8IBFm(=\o5Inw*hrS(BоW)>tr%SڲԾb v ;ad?#NR8 5^") 2Pv.h}LeSemAlϯM:'^85K$Ä3ꄇ›#ᒁD,7za"!DY]>bvxI;6S&P*l=\c5WL@>`o.CAlk0ꊐj8Ƽ"JLՓnj,svYnu`B+FP_n~H˕q_ao0 К/~|nLz7!8ȟ4TǺ;J}R* .N9o#5z/_yk0, *9jܐuW>f $ԑl󭺝F\Q}i aB6VEE"Vw֊}n/k]҂?F$\$VnkQu ڂlH鐨I|"I)C/3.RM5WN&!LSPMlK]YlIn[ByqzW纋oB 5:lϖ78cH_Dء1҅T; (u}U4q~[2²ʅM4 ewVCK> 4P:t Nx}.>G ÍS}m[[2dxb.Q (R)#s֑.c[f?7sla&6o,ٮ 6[T<C[@;Ar5X!}`,b"Ro@.%j'=X`xhgͩN͇gRUʀ޶O^~4uCZ8UTMEn.kirSZo`D!.![/D כ@#o=5Rٙ)E)Hҿ`:%싰n %Ļ~eƵ-P/P`QcwB1Q ~ "}u/I(1V3r!B#Z!0@Ζ[[H[Ĝ/RDLa~.Y~Q(=2;Av_ tڬvCƊ0d@x^ -ԙTM.[a^ w-@\&!qbíb, .K[|$ _bl2b7,@81# \hRW-gbplb#O7b|NjDGS 101:ϸ w!-6 KqM.ub8*aU+8Li^C(]m_Hfd$akgӦ<ZCwj (/ Iڬmj P"NLY<8*Y3Dұ z:! W W 7'eQCo7*pDO18TCو3s5ԅUqOgErb^sRyU!_ds}KT34ǝS9l M^m.VYG0gÚ#;]4#Sn=7X8K1.sVi5^^ݗQL: ')]xGM+k Tʟ_@q܃BwRp 95S!eBJiꤵx"D>엧 M;Q^F"D t|.t,<&Q!@Nd44iZ/Ϩ=zN uůGhqiPmCo_ 녊c[voE$쌻QErI]%Αp+RPDLwLҧ[h6ءX&0Oi<uO|"KL->tcWjn/UFBt"pe s0FcB3P.ifQҼ护MdÀD6- 'xp^㪻VkU9 SI0^9u k V- k!Z) CD.EgoD3uӼy{t+yۤ(ՂIu@]v$Ǝz ^:@բ",/){_ҧ&.IX@\hj\ Z3W\w>ܢ o!QjkX4X=F?~eĶr:|+ZA.SKW:bnd|4Ň\2s( sDDH(= s2'7'd=XжR 1_}K%AL݆l9֝+&{}#j˾PiTv8ƅcBG{tC^}JpQȈE ;;Wn_Co1n#pCD*:b~rJEzWFLg/E' -trd1֥4%BHJ<{ y Vn-mݡa{hw+Ԅ*艞LUx45\EM$kBއ0"!=ԙ&=Ei;}X-lPNSE 4 :.t`ߊ9݃]bpŞo՘hΎzxԝK"Ox${WVx%= Y 7]:S_X0DUwF?FF3Nw󅰞Ok9~TbkVb@iq <Ƥ s^འx~T Ǹ۹P{N~HiKzJ nIl bИo.L.: Iz%mY5}ژnL̲<'?"_Q0.z@ Jsw&egrHhW9荙\$3}ł⤲-@%WP`%,.Z`&<ٶeHr-3!^P풦猆-/kk|Ї'.h0+SՈtٖkKxÛ{HKN<2~ /6,MG++nJܭ0@4xj4`CWO Ү$UޡVWujʢ_sО3=z\p,q qT @1wX h6>D/21"d8 ,BP(r53t$(nP\ý(K)_eɤ+RxdgO6/42ѐ՚U38YLȳ6uS#Oفs^O) I0~Gq VFb~?u;(v&֌ h#DZvqǃ)Z g(]; FUT{ܒ^}M =+ ż͏_p̑p/kq!#q2>e&Am FWlu-]x nr~s %Osٳt%u?{)<Vlgwl&; "r}l}OɝY& Vu3q:JԵ>۷w%JߪPL-ۣ /Yj&^m98&&b *usP#" L|{؟R} RCM`Br%m1A I $BJ*ɘʡ_HgP dmtVB80<7W'ijG r&|'CD9SJ#KD' uPO6 cͪI`e'3Tc`% i:Cl_Zף@_R o#qر'>(ok1)Ϯaxi,}55j# +7MR<,o:xNqi5!]j'u(CF E2V)= x͚YcT@Y|kR<KAzNz͔jO)DJ.? ХÀSբn< .d;gEV7bF8 _J}sL1\LwY޷e+_h  2[e$"ϗ)3N55tT@;¦!^n)"ժo1[ծ3N@jեF|ecp)V@k~&"|4-Y3UHP( psy2z09T*d˳|Wkip.(Gf`ۧ`.bg[AFPe:;Ղ*x1itY5t3O Pdž "Gttm>'d= LЏ)h"Jm+9Xг4 鿤~ Dhinꮚ(YXڛA6j̪;Fͮij]v QJ+#;\_gW\64N@ܔC눣FE١gc>~W*p99>,EN+C#@*WG>UG jB.0G;pS{,$nّ aM:`#>zOV$O#FMX'F|tm9 D}f"ĕM+*nb5#qer X-/uQF6XdK(Be\k0>OD}d^4P66q` .KUHO0 XJn}~,jB\.nТ%ߙ%c!Q38 _rbì rO=G͛>`}#W_&0@[Y8^?OȌ82}m#B,`lMׂuXrudߴ5/Yٺ %#g~z`ں#qB?:WGd['s!Ii[,D]IJt׀ U>Ae!xaCYt_Wl,b{=V˵~:C?'({Tzj0_/J,[hRb5m'LXtkD)ߞ8`L>ۀ'mGr [෧ޘTIKx*g˒9g2Y6YótlCֶHtM)ƔaX=-'=vve#ـ.XK\B^7dd^me~ *4*nAefsD:59a2gTyoQv_ {`VjsH-!!"0`=*b A(C@0-7Otd/OR H?]S]NǞ^w3p# k`h< h23NQb&P#$ُ4>lmBw#M8%mqzgJ=ZǣWxwiQY@Ow5Aش9gAi2rMBde#qT~FirLZHp:%F)5'M¹,R1ވ_SP"/o_# ]@ 3cT׋YLlR<w;_UJi߿` wLSuTOO&?x(0)"`*uV:d 0I,vɋb@fBt 2g?h>"ף3S{K*Z%j`5ns "C0s0qU%JJmtq8{ȳ&y7s\R81*  *lpvʌrJ1Jն90LrgT7-da%Zgy$bݚxbL0 jƫ!QOA0!Bq qb382hj[0fV !F[3c}ImLNŹȊF ft=xZpLO9pzt;dlvc`PyQ,=1hmDD1]7+1@OӴwo#fmݔ}%qĞmvl&5P;HkHe|9MHU9@"'|넏-ѐOH@ʷ (k X|2d0@Ǫ ۤg*U4B`-{V (Uu[s2bӄZWq#on]҉(fS*F1]̯#|6t?SuMk*d,Nv`YS[i߷=AՔb/>!.$[E9qS{"+y^ſ0}4|&6D7,[6"c.B=  ' \a0.# ώ'Ќj::A %0RC4Q}ٕ|GT4߻[UfQ;>r֋Zà|H@D|~D\C߳^3#0"l9'1$]A(KogYpޯ %Gojiau?{<͍Ek쁢CB_PGo]pc2MFY{/_w@fFy2* AO5O]f:4),C_^C<[`qUhJ(' gO>-*>h47&$>xտ+D# #o$y]`=C#)q"1Լ&ɹ#SЭA}oAQ~QP_?}s6__c!tcw Me]5×3\}pONE{0"8-"⧵E;PBŠ0Mp%ޟS0U8˨pi2;)%RK'j\S g\lV$kCM> AjLW >{P_uQeHa\O߫&37]bo~NvPtjy @F(X VmXOj,߯ۉN[~{ /c>Nul/ }ECrCS"cZoY1ƒ3/t좌s_>]zڥlwfՒŜmkg?;^KVksӏtC.p;ͼ^ S0b Z ҟw4JKHY])rf|zTM_N]~D+ĎihYCq}~n3tvވd";X{ AH_WӒ=c+Fuϼ-:j ,^2Gy Z @=ȽdT|(U./a\JR'b0蓕<%YkկSW OO7L'@zS{_Z^~FPV{-5ϰ~ĕ26J{PO@u,D2Oj-y޹(W*Q.΄|ͤ4N#~d N KkGyVJƈ7h۴M ! U wʒ bEEw XDCBFs٥.Sz wa1;6h`'ly[.3{o} q)~4qgo,e:u4 3S{K2IpoMB|^tswT*a^ZvovJŧ2Z"wo8b@Yꁷ*q%>4*{tr\-*ur^ !sWL0p&*W朎0!k>(¼վn(H#hWqX_#w0lCF4{DQnȥsL"8P9 eSEcƄ3SUzvIHr{RֳTvY.p5%lkWqOro-$z҉PJ]zV _xڸCӽӊϲIs7Uh'L#p鸪Ҧ{*?F@`εz̴ƄKӖ՝MTF'pq x:$^|u?ҡN?+(Md;1)l/[jPv>-ϐMO^Y)ϵnI^q&{m&_oj4cmu8Z^̽D1J6D}3Sֈ+jVjCb.<'Q:~He֟^N9372RJ p"ȥ̞X WDZŤcXGG]1(rT'.9K/mؤ#+Wtc{{n18C"#3cbgS9O^";S 5J+2#c5NXܖ'UZ7Je