container-selinux-2:2.66-1.el7$>2?5{V s>?+?+d  $ L ")z( 8 H h  0  8 X     (  X  > ( 8 99 t9:9>(r@(zB(G(H(I(X(Y(Z) [)(\)@])`^)b*d+%e+*f+-l+/t+Hu+hv+w+x++Ccontainer-selinux2.661.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[Lx86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fiif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&>QA큤AAA큤A큤[L["T[L[L[L["T[L[L093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d97d35871d6dcbbeddc0e5d72140fac6e392d5576c1c630518591023309742ba4bce007968a1dcbdf298e23d31891aa8cf7f8c8ac3db92be4206acc5e8f1a699brootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.66-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux       /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)selinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.66-1.el72:2.66-1.el72:2.66-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.66README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.66//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,Y>T1]"k%xĉNμ5#+mz qtQs Os9gGAٷjp2tBjzTC ka(.~]+"hA2y~bY]=:n{g{o.Ǐ= 8)*o#=FKǼ67i2Iv/.g(X;!ڬed=~7;z /amrT ̏js%lUZ~ i*`|H!{?d|FF3qFr.+-/EqdS|ק~@W^\2?&_yLK\>xvsL;эu跳=>JqVfM ufL'_G@I?5^v< SDy-,.y Rgr+9Bzi]OSfpuHFPtwP09:xed:Kdۯ]bƺ \}jb y {A&o!u6ѡ.K2.9QP?P9mޔ4N>$;=$b&&X_{V$F#owVk=3 :QVצ"$;mPrIq"4cS>V@TDZu7埾9{ozɓ!|3qt5AYv=< zw U/kf̓Mʙ XqncoIoy`6U#29{"9|\o9@ҒZbE^W3FҾ4Eܺ3CIxƐ!0kư#Xk0L« PƬjsY]?_'&uJ g4&]OИ<2{%}3,37hFpJ.~VkF8e+TzN1-pV}~̈ri/J [GZ rNI0;t~ B:~dc< {%@Q,a[>^lpVAQZn6^#i vf0"Q`om7 yXN-cKa dlC,n5f|`H|l=Qp,I!ndee ]Frx|V.t_we@@6:8Xp!MDdmwrTq$U末;7cBvgx^\.(P?[l/_vqE83br],eK#Y3>%aiݶLJs0Wu9Gk v,4 "hu;ϑ:4B8Vj&GO!5C%1/!kgAk{S^j [)3p0Ulsz+gm2cB'ݜY1wmVnqzjsTT^(9c*FTT 0b̚G^YD%D2 ګ+03pXt#[TaÉpWSK>5Qt*_> ]vz,vs"Nx5h$ۋ}dY\284T$yȔoaTH]2t͆ w I'ټPU~=eű{ XzY$תdgK(YFnV:Y]mR}y K#4 bNo}gj= Y>3qhV' v2:bkLJ %r|idd# RW][Ct%~:A 4<=gAlPsJWRnV+ORVyOr˴$27Gӫ|gY(g1-:DZ#`fFԿ.g0m Hw,@R w8<$^Fv xYjyW',΀ǐj'6AȇTuh 52m6Gp8 gF,^N8Yy?PTO*v,Őz=Vrs_E9v4imRBzNT$gjۛ3,}kr6~ r|,stKgJZAꑁ^;e~M/@M$j{n,#>CoT&ͣs.ΘVimΐ, 1oSݝ_QVOUɟ,vB/<9$~W;k-8?X w9qI )@]xSig{q2)X x$#pq:Ud *0fqjAI<#Ku OJNԹky< q]m#Um2߃||G0IĢG٩bUf;}>u>f,,#!ޟ`vF\%{OWJqH8R}-Xڽ7ɚ額6S9p\]sowTȏw1K1c] @}T3 &4锔"]{PxX*FY&qiD%:@xS{ 8,"<̨4WcRvE TNB4B]{KOMn 55l% |-nU ?ozY'r NR蝲DE',GZSbR)?l!6eB?aܟB,8 '0]C ,K-Ƞc-Z F8Z.X)ug !f.4 /sstd'<{"}d^DTr'KOD5"Kk|L#h @!yYtQš%}xuTz-bx0wq-#9ʝC`ٱbǞ-H 9;혋B"o_68x}ovG)Y+T~@+PJ-\J0nUF+m5pkX-^SmaS<)Raq*F#j+i Lo?ZN,y@싁n0>įû 2$|YG>Ͳ,ybɭ8pI?aD!>Gi$пAbI+'jM۳ ֠MLw/ jTp]Gh?ОspEL&aؠީK[Cx} g.^"#28668h=׻g |+9O3*|UkyA!stF9K'`AV<䇲Bq~z%qs7/׻Uo  Ϙa0gKUBChk~_[TɵFB$4zv,1t6!#@_)HO#8M@XaS As`X2K)b0ܵ2~n>/[!wʏ 9zDd>Jo;cgkNUv\0%V므Ǎ1mSqq=Mv `&@{=r!WeT/zqk &7 ] $x^rAKp{\ߞ7s;|4rbpC/$0[%]d*ra. ~2~!hr+0@U݁ XtQxAt~{.!$&gFˮDG WGܧn/APr߷$ku`6k Rdz\GS:Rn FOD~JROXAsI:MqI? CmOy؍1yAΓOCJF[7eIսe$xAjOEN^<'PP=,)-+WVWA ӓA%7CWa,l߭d,5e}Ln13ؙUbhnԒ9UxI'jp'3!8&h_k ȝb6MԔ}T!.F?'$vpB8ZޑꞔctU(f2\O .h(:t cjUDS9@jgMEBƱS,7W[KJ ya))-g;R~ؖo3Lq͹'04m+1mSc_×T)%VW[I*>%iqVg;Me`>I"GV|ξ#G$TXכ< or!:#~$eb>hF{h_O[D(w ym^df99@}E1@jpD1sBYUa3.YpEtemMQ{bޠwP-[&W尺J#+?CJBM K[~A$E=z'I]aa Oو zձEBXP5ǹ{ c;Tise3 oM fao}}cy K?|" _+v0L#ŐMmf?WI!S&m(L^#O?m_GJ%"z()fS"Oaړ9B~2\w?ނ fU'v;wjoOdotW,v\54E^q;]K(l'">=<7ur7'oXJ'nZe+x6w #M^XD[aGN=¤w#v 2mJ1_t2_;e= OEr^1%%ӽΨ6he (pH(R3x`o.6£7N̵[sp0&@kq/gJ_Z)وݑB_/jiG§3:!n̲<f)5?StHuJ'wz`cH֣Rl]9?{7Mծ zәJN^!Ty 2Mh'1\iWXOɵ{rY- jsհ*%L̵]-huepϽdmpAt~*+u:!W.  FI]'<jm7R CB '5V٥e } 3> 7nr/iIɕ$Gfkդ)+l4 ­f`3`0n H{x$F|iO_&DD.x\Nب:]@:k7 f ЙAۼz-C}QLe4]ltݽgQd$n󴃝֐?#|sy1 +ְ#z?ʰK6eE6m~5&v<)_D@$Rd`:@NEs{`I mj!5P0 }- wcEff<pU! xfG^Z!U/ `#9VujvVk)rq(/S^xV?^:.$Bnk SBt݈;Ť`{{㍵6(s\ǝ˞UVn8pZ e35Fb}$arO9YOkp<3rI^@"2ـIf`I )y8 mbnALUtI\e>q+6`۰=atA _,Ή9j%aS1G7-̜=|A^=4 ogm0̀.ypzU\M.)~zr($\eK$zHwY-_ *kgwk6&JGZBa;$J~d" 8A(_GFal$B 9\e B8#t¾iu?PJeiAW۹DzBqZwhmmSNT {)&h}3Ud\.zf˼EQEüآOMO}־I!6v(m!r"C+/VGLW2@(P(襠S c?  xK@yp}&LFjdcJO6}7^Xf5a! Maҡw͹w~xV3XIG&ZN1{U,Q 3NbiDv/RkMQ7'u,hb N_G%do  ٰa]h"a`IҽKZ_ڠP]DžFLyR($5/gܖґgE1[u|N؇IWe(6BoCd(9 &n[qOZ]`^;xOԄn`:Z,B2/{={뀱5SXqX(rHF˥M!sbO4! zJtQAYc'+nGnL47Jú˟N7Yv׳:*FvиU3EUDtlꕟzY>ZHE hd ],?3I'8IULeEoYNyvgh[g?JokAw  QF?EQ:AbyMrel/IŘ}@ z_yU/qI!QU8*RåTU=p]U  1sj%%+ʜ2bVfᜭ6|AGF _GWLBTL 9+z1XX@u~U}熍*mI!B2 EYW}e62U(6m@6l8hK~6/ ZЎgqTvMI@9x10xf‰ýBݾW+}1EΧԺ'pz<;".Di~`CgeS^|>x۶+ޗAx[-7T  rNu VTJyYɗE[zDL>ol#!@%h`8b}}3Ld1QB^\m`-RAg@6=毯1 Z%Fm0V\@7 /HzL|nY3kgs?Áʊ Mb#a#a͗q`_֕rdb&b|s*<!gwQrpT$dhP,vtav!N ,ӯ%t9dVO'X( b8~+i7 dR0yh$7zkOorg甁9}gsmEi$9>?! ˮj[筈Mwu @'9UȮٙN/ ƭW4uJӟ_rBr`rIq>v)[W?yQT9R0.?Bxe3#e-mxϺIX>EEDި .Wǩy~' @1ݼ'bfNo`-m4|KuϨ7 ,X#)#1-b/-$2BYe{f^|26LLUgdiئ~Lܙn)# UjZXP4 kz"F#3PTyͲ;Jў?ά&:FUïU[&YFKW[XήP()n-|yX]28]%xe,Vcߊv+nO\|qZ^ROZ-16Ir 2o/je04TrѥvC,wC(mYOB=+< SW%B4][(pVJwoK%?-G~rJLk*WuJibړĆĭJ@+\J1U˕Ephi neM5AG8o֎E3QgB_vraFo":ccox8ҳ 9EYAuۚM0qv߁zM]Ŀ}M hل\ {wDicz]O|1!BիSP?6vzg0b:.~,^xoHRG˭0H^G!*;H>ԁ!3UhiuDK#9'Ql;Vb(k /7`M9IkozTh̩؄EUѐxmx=ȌGlB Ȁ7-%ɮymO1zu'64;v//SJTIl%Aͅfvƣ"u\8} +|VFKT<+nAJtdf ELσH^o>1LY4nMQqAݹ)زwéy׮YͯF~WpW )%0U W_?j(*P? m.ƫ 2m)0R=O‚@ C`蒠Yd)m'H_~25Tqm-ε =v=A9 h!] ӳ4P)S)A4t67ȃh_W[Y:Ơɜ:%V]rh"1g[֤*YMT+:3l7Wo'uR|$^P?_D.:Kyjw m/kV_'`- 3_\k^$^ 4@ Z P|YuWaNAG>}Ѹ?zQ" H-",ET!DvϳzAlc\ؒ׬ڠw66aa@,Dr>kB  3UQt= My:ⷃ4jU2oZTAK j˘4Hy9 x|1*'*3#ZY?hhDsWz'c' UѬLq56aW cl%e)߇getd2YɽZ sj`h;ݥ)TPe'!-YaŽNo ZmQ$+Old:xSHv|Am4|/,f+ޒ9RMư#)0Kq ~tnj!J:.*ў/K/)!ARi4ɣ f; ;R<^&slQ&*6t,v @B묻+膆tyi; 6PNF90^кs#Z @ ڥ3H6J$깆 z}rq ]}O>AmZG$ _rpK{_RHp*p++YP6r2)>Jw.}H?W+ed ։G%>Oåub}FSv=Qcr. ղkTHwoY:Omc\i,׳6C9kHyŃ4搛gɟ^E%-T\DZPܡD;| A5d⟠dbGdĥU@5# >T!lsak{[rsgexmɣܾgb>UVfTjl;K 3+#a<}2,[M!3<!B< Ȳ7ʤq%>E }#;O/-j`/GbUʢ-Q9+rBl'P_<@D[;BJiHR.=v玝@Vj Y̦AT <ϤӚvx+d@\$a&mbXeȾ]3Ydۿ^[ EL) rF&B.v3. <^p#JmhgvYKBc==F_8X(L/g;Y<;Wt> zaˋ]3Xr+pvƚ''fSt :JK{ClU^HΦrFi_9s;M'Up nRϓC5Aߐ{ཪCŅ<$Ǟ+6\jqT@8fVE0N_ XAfn߱!'N<9^+\,(#F: _R@3$8L M,/0WL-įl=)D`Qx,xX ?CX/Άf !&ςBeBgQRTH&6-MbyJ%GtëȀ_׌lɞyC fw9óQ>tz۾Lk"1s#J8I@x.Y啡"3*̺6?^W;A:wJ_-ZBٷ䅍5]Qeo| νD@\܊c! D۪~l\FhcdTM} mE =\G}<-zi Mso#Q$XIqU c 4\ 'Ek F,wLHr&&@OV^RoT5?X~*Э;oEN<#$h/3 QՋD(׮ X.2E!DUϛ*Ҥou:9!h8&($}md lu#/,BHtvP]HTB](GRH'Z4tf*b#[*De/mAy-7G7=ȕ7ủR0i8EjߴIEYwVuj,%Pe͊`jlOor2.j2"fUoP+-T dpnz'FծXxׄJ*B.Tj 2 .)~\48Ry][ L0MZZ@ pﶿ K&;fUk,DͳAIyџJڂ KaBm+,#=Օk2@" b6"1iKK^^W23Kv"z%2\X47iB?%"}~g~5hWUrAg"YAs5n3<*nd7~(A o|7@ɭWf[@\9璑aJ[(+{ ߘ^>HKvMF߇9NQbKM/R >i'3 "A[ J NnL(1I%H?QP`QoфsxbLDbZ Wi7R-QkL .&9az -aY-1P6p 6ҥdcP8F=^ԪijĀB :\* ,oX/[Mt;47  YorT1pz7Hxs)\ ?CB9w.X_DqpEA3qYcc@T۰px-]JUz>;IhIA^#B%}EؿljC,Qo-_k4B4?tJ Gj*O^CTMć$?b爇YWB%1?/1e)H~_i]=/Xj`-#f@hь ^^v,oX(r(_)dB3,(3t,Ow7 bPkaU3kSv CĘmRCalJDn^KELOtftn~(pɷIuҽo/jCFCr4g|p8P4*?=1D.ň ">@L&wd`rz6~\h ;r *}pk6P xɯ{f?y -}gzɖu}η kz_ ?dug P*t]DLv$}c}$FJC@m:߾z V6pq  o/B) n=é%E\߳}^ڗtl|܇ qأL3 Բ[,TK{MQ'v OOb,GSdM$>~onG7(xcGs&rs =ݦK(` hO$Yq6p<ڧfT;}1)mh˴U,"UM'Y:~K2'593\,x܁"[fgJ@ivevco3,# .w"2iI\Zg>Kgp7xDPROQv1C2XuZ1[Íb8yG\&qc< ~fl&i-[uon6 aÀYOiMn[{OEq_[ȭ&~IJ2B .`Qؾ|4~>3$U?-5P?(3U/+YĽ(<.X9u/1)8 ` hOI%yC`6CVAy]xs9e>k#)j@9oT=iφ|bDr@vl4bWBsIUk)KI|8%}R6ŞڕWG2< PmզʌlICSdF6ɛp9KUM4Ɵ2MzpP}"Z h ?ǚyN*y7Z 0K]Lҏ{+djG4K+9aܜh{᫟%ҥRhV|ZA->d\FY{ u/Y-&-@kڦX*Ś^[ !K2hh[OAv~ u uR FKߦXtF<ڱzdznx>cW?Qme׏ Jπ;CFx655b:怋q y >Yju10TUcKu݈#ƘhT-lr_ǝ!R80v~2lĂj)Vy/\x9w{VrJBʧԁx;ue:ZB`cTX Fo:$C{V&ewU]C5жSQk}fqδK[;ЙaNuUmy@]ͥZb]r$ >;S^jT69ޑUɪBoZJhe@@[%yJbchEjeዡ~p osQq7`EVQ=w;fw1mxmvvsQ1czh zt<~L^BJ:0RX>=US1"[%/W-aj_.rReQrӮ9'W;_*=fXTc ՀCƻdXNd* s]Uۨ]B {VQQ6UE/.ϩ&3e$@q Ɩ*߱`+O*p3X7O㱉|CK[$UNA#O@R! xPB =J=wcZ 4*eU,܍(o\'pP#2 cX$^p]6 \o( R8"{3nYS?5_ll?q AEa]ת%$/ ^.D: ùo܂]>WI`?"t`ml%83+C̦8.˨Of^^U] lwUS!\;K--s" zRؗ~|j|~ yzXr 2D統_u>=[d;Q6˚ñ167.5(ޏIxXE,EA'WpZ*GtEʑG%j:.!MۖX \ěq0&1ւ4fF۹ ʻ jtC.DfJgnʊr$~:,ΥDD1RD.NC@wLH>/3iB_ֈjٜkJJrV52l5ϼY~. VA8J>||B6Jxj58Y `[+Vw cY.[M.-QW*h-Jm)+PƹelC6a Iv`-*GȮj8_S2~TGs2*H+7ǻ3fO@RB.Ms1^ky!>@<;,4ĭ-.7 C}R+_~n衜wuF0'ZS)罴]f?Dh>@%~.ldһEvD1{r9$3evȸ^zv}f)4F6C*S27t\;Ly3S>?< E ߱V3a"Oe,CWXĘRl;ȈE@:aF] qi2V.yTFk Ju7%xJ:>XV662h4 F4҂bkTR`M8;a}}],?GھS䣏7)4Bm _nS4#A[0*Hf<@nRlM;w{(*0Qty{E34c-_ BKj\ =?p :PܑbRiS(# &BΥqu:{ۏ|8"\[PҵyG|vpw)t )r'a/]'|jƁ$ꯛYg+@A {]N + [ī{: g8{%zޱX9Ym2qEH0wy ]s8q#0v§kR'Ie#֜j^rEU' nˤpNd Fo%dj~7A ML? @Ж_Gx?G *fMGk>p?(bC~=*ڟr֞nRu`je~2D,dX\ذ[,EM6js qvsYjPXE y k%1_ YZ