container-selinux-2:2.66-1.el7$>P`~}FQ+>?+?+d  $ L ")z( 8 H h  0  8 X     (  X  > ( 8 99 t9:9>(r@(zB(G(H(I(X(Y(Z) [)(\)@])`^)b*d+%e+*f+-l+/t+Hu+hv+w+x++Ccontainer-selinux2.661.el7SELinux policies for container runtimesSELinux policy modules for use with container runtimes.[Lx86-01.bsys.centos.orgCentOSGPLv2CentOS BuildSystem Unspecifiedhttps://github.com/projectatomic/container-selinuxlinuxnoarch# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null /usr/sbin/semodule -n -X 200 -s targeted -i $MODULES > /dev/null if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : if [ $1 -eq 1 ]; then restorecon -R /var/lib/docker &> /dev/null || : fi fiif [ $1 -eq 0 ]; then /usr/sbin/semodule -n -r container docker &> /dev/null || : if /usr/sbin/selinuxenabled ; then /usr/sbin/load_policy /usr/sbin/restorecon -R /usr/bin/*podman* /usr/bin/*runc* /usr/bin/*crio /usr/bin/docker* /var/run/containerd.sock /var/run/docker.sock /var/run/docker.pid /etc/docker /etc/crio /var/log/docker /var/log/lxc /var/lock/lxc /usr/lib/systemd/system/docker.service /usr/lib/systemd/system/docker-containerd.service /usr/lib/systemd/system/docker-latest.service /usr/lib/systemd/system/docker-latest-containerd.service /etc/docker /usr/libexec/docker* &> /dev/null || : fi fi #define license tag if not already defined&>QA큤AAA큤A큤[L["T[L[L[L["T[L[L093be781f9916163b4f01d3f7edd672d735d3d8347b5aa643cfa3c58057c6d5d97d35871d6dcbbeddc0e5d72140fac6e392d5576c1c630518591023309742ba4bce007968a1dcbdf298e23d31891aa8cf7f8c8ac3db92be4206acc5e8f1a699brootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootcontainer-selinux-2.66-1.el7.src.rpmcontainer-selinuxdocker-engine-selinuxdocker-selinux       /bin/sh/bin/shlibselinux-utilspolicycoreutilspolicycoreutils-pythonrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)selinux-policyselinux-policy-baseselinux-policy-targetedrpmlib(PayloadIsXz)2.5-113.0.4-14.6.0-14.0-13.13.1-1923.13.1-1923.13.1-1925.2-14.11.3["X[@[@[[[Z@Z?ZZZ%Z%Z@Z - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/shcontainer-selinuxdocker-selinux2:2.66-1.el72:2.66-1.el72:2.66-1.el7 2:1.12.5-142:1.12.4-28container-selinux-2.66README.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2/usr/share/doc//usr/share/doc/container-selinux-2.66//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericdrpmxz2noarch-redhat-linux-gnudirectoryASCII text?7zXZ !#,WcZL psWahl.vҜ)AlN|MtGHc˘(^L#Y@KYO6}iyߝAb.AwP~Vz!#0}3?wA6V,lǎP2yd.׬:EU6Kkű0⭤$ѥR\Zxo 1ݚ 1˾AL# ^-r <|X^Ma7WʻN9UI` gI![J"̎5?C!f޸\66?ؑt }C8Ip+\*ICE/7GpM]i( ɨZ󯜞njpődp F'q FAZyY$~M,۶HƾY:6?Y@R3o"UK3Rk8yϠw[z0ͶHgoP@u8hcie6d r lZzFq]to4hy9 oEuHg&cM* ~w 9wGM׏b V ﲞoe7Ą9!CvgP[l8c^ug~H4IbW2!ZPi8> Mŷ$dcպ鐏 -;ņސR"6N捍JKSdߡ HZ1f!QX8xQrVs|,]%4i ϗ/xw0 C]3+w0vL_*zͼ+#ЃNf h%cĘ/2y'5|f vg4@/b]STuK*j?ypɑ|Aʔ6GPlBDapWk aH ]ʧxn2I|rύdT7D t0Y{ӆπDn1gh_\Mw,nLZp @mL$~<뻆I~r_1YQt7 2 :ePTm(%*\ Q01-d(+ |,uVo\r3'thuƇ8-\U?%L*s%>n#f*h@Dԛ6TR͸˿3>vɶia[oo@v31,;Cs]k픷Es' ġ4`Q&wROݷ*'\N !Rja'S xNٸPs21J d8(dܵCh6"Ì bqv])mglP|YO#X>IvlOpv忦 +O0g\t<ƋsA8kjk;#@FV)uu`,'16,_ΈmIWqx3O(צ,޴ʈִO!~LoNRY#0bAA)GeXBH!GeF\ zƠ"(6*+oo3}oFCS EeXIn`OrӘ~k,$By%ӅU(%ezדNGT/|xxE:VJѰȪc^Ϭ^PGa/ YR,)hox uۚ;wu ׍YP,{bs BrM ʸ IP ͈([9äKb=*74AT|XQ07+0$\,wԢS/LTfcG lң Р$sA[{d0u)7T+ ?Yw?Zޏe-F,\)wpNd ~r}SEznԊ`!7Hό?̘[@ٓ﻽L/,o42”;Ỷo׼[/ xHNz=[S],NGD*V Wp*IK!towiިᩥf)M8'nq'noh]vψ[P!:'? y/D%*yJ N5o,I&L>a}Bf}B>,7mvE{ė8M/g R4ӭKp(ːؼӚlvEY6VjB7YUs%pIn'V`vXZ. K8?27ئut 7/3@s6Mbs?o3>ܚ+<|0PPCQߧ3Fw 6JZɉ#;2'|T ZpBzUXiHUF2Ж$}a |Qߔy%$OW%Ey7!Mxl@a{eY'L`9CU- @ 4:HeVxc;VrADn]>W[&g+B0`X9 4FqH*U5 /X~lQ *_%V|e<" |8__7Ckav{C87SV6m`;&`Oc%E_%H 4W0Nr%lBp#c.wgXnYY1o)o=$He?yu2Q:]fsԈKG^ةqskzŘ!GmΑ4jr^S3` Vb[ Ml[u&r2Q'5Z-"|'>&,Ӫͮj.]k22&ꗱ4~ /t :Ofoƣ_2K`aUf%sϲ mq:_{dQɨN2[%uam ɔ׆svI >/Gl(ns=JC+YwO<}< kcb$c}vcY^>\E!:f]^l|bBuVgGb͕^c#?VQ>v ?AU 7WZXV3չ-8|:ݣyrqr($K^΢ GلtdBq̰Oh` ܷB?/(M|4I꣨Si|*ӶFKq0QF=Ȏa?Ǎ jhS:GKIC3>E[B~ТiCvrQ52.+ҍiF90-s3iqߘ6EX&vmȌ'f3I3fi͉gY\[dY DnBꔄύie`PZ]"s=YU)z>cv9JMD9j/_'ɳ~>@^fO* AJG{[+33!vaøs|GOG`f8m;xKN*I 4}j d,C 9VW]5;G˳`hmZvt@Ja@q'gbٷ֖|RQ5 B{ lЭ{ÒL4ӹg{sjpiuv\S]&n :SLLk^ATț@>?*z(~X[J408Vj'*ܜ,ىevu+hmU(a{/_[}h pA8ILTn_BT8+ xL%+_x2$p})ԿAHTJT+6Sr+en78!L MTp4k>X{8{w{}<'"ġGM@m`*f\7*8?vdPyQOF*v*(iHOWl\Hڱ5KO/?^[^}aq?]VAyO{'yѿ%5;$)2 IӆݕЯ1tOmvjehJu193B4 ̝Z婺8FVNƔ%@*OXskaN#E8 vM3HкN3qf!)NQ~ytu/'+pK> ?uaxZÚsI f?ݷ"x(\ۊαP>yHP ljqζ1xa 37{YfFz|N]:FeV5Dyqm?d^uZ^yDW))r$ nX(ňfi|a3\au2j̽w`'āʏhY$QvuQEJda{IPWwBwf α(/OU)g9S-Ew2_LT izmTp?{g \Ȩv-;L$A" -DxI'Vv<iУjas_Xkc"γcbS<9k3<`ϧ#ė'e ,P+4!,.C x0ϟ->[3:T+;.$1 as̬g\hU,R|8*hF6ɲ bwKi ٓ4D;3 =t~lC=sx>E'`C7 yI]oe!Μ+.%m31mFxYeOhWrG(*eRvHRFI{agmd.oԭ:%0?Cj $w]#WD#R\Lpk0@-dT}vx_?}f,e\u-:|[\/BMQଓ.- =7Zb,Y/BEG3 [T=jR4"wH$z dF2,q$2=:;N-HP.h</alIAUG{ͣPkgk'!K8,&}KpLsUaQGwL\/kd.WYrCCoC( X8Hr6 tIJ7ڛ{+Ǔc9 FH wa]97߲~feXu;(g!*_^t78T Q=p5ŨDs{P{B- 6WY?x%!>P!aԶB%mh[@!~v}$arPkBSAhD2ϱuQ0:FlDDw@ wr}U"_&ܗę~]NsKY$ziD45%MKqN +=Lq6qjcR:Q_qdU5Έ(#|powpGlQV|AŐ!u|1-+mVy3#xYⴟ9bRӛU@2.S56r@\~44e+^&RaRjKVVi2gK A=(gݶondBu,3y8T: o*1e,jkW(r&Kz{{-YY-҂zLTW+64,tfMCUĕh' m9ܬo>`dr8N_@9dAC2>lhP4ga0p?~zmqЉOŅXrV]?EYm ,k"5ƙ%5k6w4"ho\.E"B(:y pb޸,ٱ߫jiTKʒNp-<\~a: ]q=ɴE0mVѓ̩L~ІŦpҜWesЎ,^qdyla;Zz2,Rw[(>[|[n&{xͫNsy_G Ԗj] P:CeC/azt\9fܬE6-*@8yK1ꝣt ު%6+ 4~p.C.xnzϳ+4-赙`ۼћA֢R#}MPhq!X/nG4()Nи4 @vcnrԬ/@-; P<]|pfO 4kGG>V,5K =x\~D,G~f>>u>yȕ6Ls'iv,ZNÎj)57q3ĸغ f]F!>ٌ_0E ç>Dָz+"1˘ã(p}j˲w3=o1õ /C;H]mHr%Tyc܌h.f(Duxٰ|;âIgn '܊xx'fDu8Tx)=Yaڿ9=n7m*%M7K(z* @TPUrK}Ԗ JS +S[fmaԉ]*5v:\ٟ^ ukO;M$tlD^`lCV$P{֒>_X]u K~:iwv jUVׁw)]4!!i"Z󙿤d%]guW#h㇯Č@+UET^&~R~0f'U[; rl.l {/SݥLE;{VsI|ɯUYj9\. vM%s;Of^FܨcqU0FQ"84CT{nA}TMtT-s1ف2_7 Mdbq-ăFs4-ݝWCk3U}?^!2@! !b Q6Nz26eı?\]P@zJk - 9l*J{v:cޘw?wj`{*t98j$#h_&A?rQ*[Iޱzk;0k?(%kK[wzX)M]X6wЯ9 6y$L2з<"bbǗ$^"0<%[_n3'+eCMV,>'Λ~yгr{Oլ6xH(UPcSp9<-HEvs``m:fv6റu` .#e0u}b)FQkm:oܶи0'-] R$ LȋM}ՂRFP=%KoyBz='e!vut9FWu`6+¸ecfD+yTzQZOC12fnJ1ԼN:BZU7NdZ[HEb Lg0+:أB3W:Xonzg|4'%J;@Lkی[G2iz@R-qH9_hlObJR$|rﬗцXUul@Ll1@B»zk|VR1 s4Oo9d1f1W#\N V[D*OZx.fAcyPJJ } +4[}?!""UxgzdSd-p7]UY>/|'tu<RPV>2+LZ}#l=BlK!Mٚ/#οUBbb׍Vm_l%pmAR +b5^ElÖrݟC XgKM ve$u$9 ƸD9f=XK;7Кج ~)a V|*MNi0Ŧ"ݺsD%)_~Kܪ03|P^"V4MZIl ,~%hB*㈭d1,E;h9k4pgD&LϞ0N/orX$L{h_Oft<w3ajJ x5Zݥâێ~k1ųu'~a /CKQ:`Ӏ!Ĺg)Yh~)m̺R6j?ro# IÜ)(+*G{z踎45$)aTxi$ǏzlU13}KpCA#YvrDaGL!ģ-+Eŭ*=Xe;?Z1M*Kh(=( Qxs?qj0L ŴIb2wuNEM&\u ٵ(_OKM?PGjy Il-6 ' `UZ0)P=J#W+G:rUq^4擱tğ xPhǨW9i~^v|N#iS,P=遗 1:yn{n"LH:,T^yis56= (|G*Dq5sc/i/wg}Ŀ߽WS4`~xJLDI ?!YW&v q$ࡾ%\WRvq:z+|I{.IXbէ`v/Rf U6!aAS+$psę!uOon%_;~T=ܦsgEЌc}@&&^|K16vm\;=,VLc|0ܭ@[ ?V; NmPX|(9Њqu=C̐7YznpNo0DyX<kraMS-venߡZ=mEL-=DS=g"NJ” N;qQ<|3Jy4Wp"+Ds,/0KjtD4T}nXI/D^3@KtPB:P 7&n)@oF0}+@yJFNe8ohwjEIO(r=* 1WFQxb8C=@,œ]V.vE6eGP.{VDg:'✆UK}w$a p|M Bߧbu*}y艚>^Eq8PbP[}EO^10M4eBMuBE,v Kyy@hro2+߻J盒&=+gqƑH1ۮ͇:,m(,#ba2_l"y`fGI;JASiJ`b*2-DYӖ7'~ܸ"yFW:s {N{R_B=C,k 7 %u}!IMG3 l=4reh$/d~|iˤ)f'8v$-4{e[N>кѶ1Doa Y`LΎ8 *CڇOnqnQ.!2Y@Ggd.yI&6&vZH:L?> M #tdT4gSP$y7Ay, @ J2+cU7sIW;Hmqat{nYvKYJ fAh2Jp4 ?{Hrܥ/3ohlRU+Ny!"N(Yf0"\1ľ?.uN vt- =#W H.j2lp!JNt($Zu7 oc̟N 5t릵x%>L8 -Etړo2-u (,N@g(|bQh~*/EltObӖAa@5\c oJ6hܞg*RDwUzpK }OP0%ǀns7zⱌ㝨wp$S1 g2cÉ6~]l 0/$ 4]1q9F)/5JbHC3R,,%+_r 39^z3uc? ,C,x7ӭ6Fm=Sd)M2'4qIj7ue=`2!! mR |v Ǹ?F.$y J0b=5ȀcX\q8 I)}#*AlHeO(9Ř#|9 ˑuu/ <>o2*~ Uyp~MdiO I> ېY /x6`0l朥Eqc%˖c91]mZ/hU$?HFMεSas4$?r#5br|!8#-GIEdF{eoMt|%+@V6뫥]槹X]}PdA.jT0PGKsUVuadwGNX2 ?6a8VgLB5seމm!Iۍщvd?L7tݶ/ҥ,-Ckmy G)x64jsP̮4bHbR b+!Cre˾fYթT;SCo+->g^;+?n+}H^5dU n '',j=ЌFDŪ6E7B}zm"E7&eFR]fB0ߟ5h` /c ^h_,DA3*= Y Ȥw~"Ou."ECO&JWu{*<3^hQxbr:Y 6XAѳrSYDX␼W@iŽ %wZ;vJN-_U I=XhM0sqAb_Z;coƉyx-/):d*՗ 0zfS@>Ow7*H8"s..bovɐ5!x%s^JZwK3iZjSmןCJZS85Iej)~|oeP|^"*Usi-Nc$.&x+iIN=ʿWQ]קK~W1 B^"=+s(0x˃sERb$|;O/e% 4 oX**3eN9d«y 9zE-vӻPcA3-'-uZ81ۡ/HoQL*vbPfMC7bֵ4s +ُk6ƥ\8 G>`I,3]\EkRTV'& ?SX?-V޻jW Z-M; >,ONJU yFݢGt.K:9/ C+Fk֭1XUٖ({ 1K7<8^a XbOFZ% a Wɒ'~GpE+R`54,\{XNƁPYl>$hc@߼V:>YVQ;lMM /wBOLV_7\}fv`i]ɛ:k1&GfO A O~}!HL᥷# \zjV! *ʡe NZd:8Urz' t;2R_\}k=ysmĺޗ]$+m2Q`k֑&/]53&k}b^J6KL!) icvܦ62M$_@9J HZ ; 96uHt*Lr ,:Y`"]|7k- I_qfR{`슕΃ΐlGJfR.;v⪞qALp/әc*)5١Q[9қ =4"-o%v=XQרS*x`5hj-,m=&PQN0H×-Qz7#ūfA1Uy ϶`b)yzY]:8_0$cT/kO(pCO}`c?<b)l&*jcT~dS aR8}Ü[ R|,G)]K1vķJ1UC^T@î~I er2‘]TPh(ـۃbZDTÄzm\mAQ4 I@}CWI ܦɾ> kPQ]ᗽi?2-/o߈x|l63 1OLx wEb*Ql.y+Nuor]zWW]䗵M/}du#0qT^t>cmz _OeӹJÇr:[-dC:e㖏PhT1HJm-R9qwp}HQBK4G#V&Kj9\aؑ_rɀM.8I_s/:" ]Z)SKR~;"訍οf~'?NBː@L\]/Nz2_h|U TBOKM+V)K+-{G?@Jb㥺SrV/Ub]ݙ O:<#iwC5Ee,ZGOГ;E- ΃ߜ%~%k۷} ֵ4`wW:@_ /) RJo' յy~ ЬLܒcw4UWpLhAK9l׾&דTpCx ~2"a "II7/̻^E OퟎjW#þ#xjeyv$Jt2TBeK\ajK(UDHu7;{RݞD"f\6GEʦEt0?SsuVm3-$`r2nP3f@Zu.=ɝn2-X{ qccm߆a;:]2).UG>xsGݷX:>Nf? 4؋CRbs/Kg3j4d&|8ƼzE=6LGAI츤=b[BqR;߳tgJ+dbEֻY+5>W r= $chYj7cXz+)J$ ^'uxOvmS&IE 2~&h9ig7|M*RyB#p4np3N9A/E{CRE$jمZ&t`OHBu1]u (dΞ8E ~Gv7*sD D# V `atϸ AhP*b:[Uv^9c~ Y,s}dФ (3;(0*43>fe $ g<4pƂaB羨ڪ*/!~ ˳C݂8b55O[(;{Ro9m<`[OhzB10;C23{ԂJ[d̵~<=x8'TG ZيLuC"Bϑ_E^N3Jp%