container-selinux-2:2.229.0-2.module+el8.10.0+1815+5fe7415e > 6 6_6 3!pQp)Tξ7]mtZ`fO+ ]mtZ`\~k?P_aʝѡtזhʨ҄M>ϰt0`yD=ƀxRF*\/ȎKAg ֫|{Hnpo\jgT74 %%ew@S|о*GDF$FԳ)h +[Gl.n#ۚhk3WXr*=V NeÂ$ސW*0hX)fq/so io`5SbVۤ  )G[>D!,UbtS]#cN7Uʦa2D YaP]]GA~r͐jX3ʶ"UED|[s~?yg]Acz79Bofq}J6Y FøNme$PoIxs&9¼W-Ⱦ&  ÏӸdD#3 u;N nuteec09337231667a602e23567afe0495db864d99e289654962cdae702f5c3204786417edb606abfa5e9b66f3203ca25e5e6e2b21bˉ3!pQp)Tξ7]mtZ`fO+ ]mtZ`mR՞G(+14 .3Ɯ ^'N6O3Q[gyRՖ@+^*>3a"612tb ؛O(g皯 fJDWnYckDdN=%gW9tD8l~3KFž9]VH ߈ߊ`ӅY>@,m,lret}_tAP=a|J{~j0Xk]'X,QX/CW`"*nq}8G[ZqCFh[,ڛZ(Wt -^욓LʜeNѿ԰NRdsM6s zN@"|qF@_3>pIpK?p;d< @ h CIPL t    @  T   l 8pS(894:/=gR>gZ@gbBgjGgHgIh,Xh@YhLZh[h\h]i<^jW bkdlemfmlm tm$umtvmmooooppCcontainer-selinux2.229.02.module+el8.10.0+1815+5fe7415eSELinux policies for container runtimesSELinux policy modules for use with container runtimes.fO(=ord1-prod-x86build002.svc.aws.rockylinux.org KojiRockyGPLv2infrastructure@rockylinux.orgUnspecifiedhttps://github.com/containers/container-selinuxlinuxnoarch . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then [ -f /var/lib/rpm-state/file_contexts.pre ] || cp -f /etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts /var/lib/rpm-state/file_contexts.pre fi# Install all modules in a single transaction if [ $1 -eq 1 ]; then /usr/sbin/setsebool -P -N virt_use_nfs=1 virt_sandbox_use_all_caps=1 fi export MODULES=""; for x in container; do MODULES+=/usr/share/selinux/packages/$x.pp.bz2; MODULES+=" "; done; /usr/sbin/semodule -n -s targeted -r container 2> /dev/null /usr/sbin/semodule -n -s targeted -d docker 2> /dev/null /usr/sbin/semodule -n -s targeted -d gear 2> /dev/null . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -s ${_policytype} -X 200 -i $MODULES /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi . /etc/selinux/config sed -e "\|container_file_t|h; \${x;s|container_file_t||;{g;t};a\\" -e "container_file_t" -e "}" -i /etc/selinux/${SELINUXTYPE}/contexts/customizable_types > /dev/null 2>&1 matchpathcon -qV /var/lib/containers || restorecon -R /var/lib/containers &> /dev/null || :if [ $1 -eq 0 ]; then . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if [ $1 -eq 0 ]; then if [ "${SELINUXTYPE}" = "${_policytype}" ]; then /usr/sbin/semodule -n -X 200 -s ${_policytype} -r container docker &> /dev/null || : /usr/sbin/selinuxenabled && /usr/sbin/load_policy || : fi fi fi6f{b0(: BA큤A큤AAA큤A큤A큤fO(=fO(=fO(=edfO(=fO(=fO(=fO( - 2:2.229.0-2Jindrich Novy - 2:2.229.0-1Jindrich Novy - 2:2.228.1-1Jindrich Novy - 2:2.228.0-1Jindrich Novy - 2:2.227.0-1Jindrich Novy - 2:2.226.0-1Jindrich Novy - 2:2.224.0-1Jindrich Novy - 2:2.222.0-1Jindrich Novy - 2:2.221.1-1Jindrich Novy - 2:2.221.0-1Jindrich Novy - 2:2.219.0-1Jindrich Novy - 2:2.218.0-1Jindrich Novy - 2:2.215.0-1Jindrich Novy - 2:2.213.0-2Jindrich Novy - 2:2.213.0-1Jindrich Novy - 2:2.211.1-1Jindrich Novy - 2:2.205.0-2Jindrich Novy - 2:2.205.0-1Jindrich Novy - 2:2.199.0-1Jindrich Novy - 2:2.195.1-1Jindrich Novy - 2:2.193.0-1Jindrich Novy - 2:2.191.0-1Jindrich Novy - 2:2.190.0-1Jindrich Novy - 2:2.189.0-1Jindrich Novy - 2:2.188.0-1Jindrich Novy - 2:2.187.0-1Jindrich Novy - 2:2.183.0-1Jindrich Novy - 2:2.181.0-1Jindrich Novy - 2:2.180.0-1Jindrich Novy - 2:2.179.1-1Jindrich Novy - 2:2.178.0-1Jindrich Novy - 2:2.177.0-1Jindrich Novy - 2:2.176.0-1Jindrich Novy - 2:2.174.0-1Jindrich Novy - 2:2.173.2-1Jindrich Novy - 2:2.173.1-2Jindrich Novy - 2:2.173.1-1Jindrich Novy - 2:2.173.0-2Jindrich Novy - 2:2.173.0-1Jindrich Novy - 2:2.172.1-1Jindrich Novy - 2:2.172.0-1Jindrich Novy - 2:2.171.0-1Jindrich Novy - 2:2.170.0-1Jindrich Novy - 2:2.169.0-1Vit Mojzis - 2:2.168.0-2Jindrich Novy - 2:2.168.0-1Jindrich Novy - 2:2.167.0-1Jindrich Novy - 2:2.165.1-2Jindrich Novy - 2:2.164.2-1Jindrich Novy - 2:2.164.1-1Jindrich Novy - 2:2.163.0-2Jindrich Novy - 2:2.163.0-1Jindrich Novy - 2:2.162.2-1Jindrich Novy - 2:2.162.1-1Jindrich Novy - 2:2.162.0-1Jindrich Novy - 2:2.161.1-2Jindrich Novy - 2:2.161.1-1Jindrich Novy - 2:2.160.2-1Jindrich Novy - 2:2.160.1-1Jindrich Novy - 2:2.160.0-1Jindrich Novy - 2:2.159.0-1Jindrich Novy - 2:2.158.0-1Jindrich Novy - 2:2.156.0-1Jindrich Novy - 2:2.155.0-1Jindrich Novy - 2:2.154.0-1Jindrich Novy - 2:2.153.0-1Jindrich Novy - 2:2.152.0-1Jindrich Novy - 2:2.151.0-1Jindrich Novy - 2:2.150.0-1Jindrich Novy - 2:2.145.0-1Jindrich Novy - 2:2.144.0-1Jindrich Novy - 2:2.143.0-1Jindrich Novy - 2:2.142.0-1Jindrich Novy - 2:2.139.0-1Jindrich Novy - 2:2.138.0-1Jindrich Novy - 2:2.137.0-1Jindrich Novy - 2:2.135.0-1Jindrich Novy - 2:2.134.0-1Jindrich Novy - 2:2.132.0-1Jindrich Novy - 2:2.130.0-1Jindrich Novy - 2:2.124.0-1Jindrich Novy - 2:2.123.0-2Jindrich Novy - 2:2.123.0-1Jindrich Novy - 2:2.122.0-1Jindrich Novy - 2:2.119.0-3.gita233788Jindrich Novy - 2:2.119.0-2Jindrich Novy - 2:2.119.0-1Jindrich Novy - 2:2.116-1Jindrich Novy - 2:2.107-2Lokesh Mandvekar - 2:2.107-1Lokesh Mandvekar - 2:2.89-1.git2521d0dLokesh Mandvekar - 2:2.75-1.git99e2cfdLokesh Mandvekar - 2:2.74-1Frantisek Kluknavsky - 2:2.73-3Frantisek Kluknavsky - 2:2.73-2Dan Walsh - 2.69-3Dan Walsh - 2.69-2Dan Walsh - 2.68-1Dan Walsh - 2.67-1Dan Walsh - 2.66-1Dan Walsh - 2.64-1Dan Walsh - 2.62-1Dan Walsh - 2.61-1Dan Walsh - 2.60-1Dan Walsh - 2.58-2Dan Walsh - 2.58-1Dan Walsh - 2.57-1Dan Walsh - 2.56-1Dan Walsh - 2.55-1Dan Walsh - 2.52-1Dan Walsh - 2.51-1Dan Walsh - 2.50-1Dan Walsh - 2.49-1Dan Walsh - 2.48-1Dan Walsh - 2.41-1Dan Walsh - 2.40-1Dan Walsh - 2.39-1Dan Walsh - 2.38-1Dan Walsh - 2.37-1Dan Walsh - 2.36-1Dan Walsh - 2.35-1Dan Walsh - 2.34-1Dan Walsh - 2.33-1Dan Walsh - 2.32-1Dan Walsh - 2.31-1Dan Walsh - 2.29-1Dan Walsh - 2.28-1Dan Walsh - 2.27-1Dan Walsh - 2.24-1Dan Walsh - 2.23-1Dan Walsh - 2.22-1Troy Dawson - 2.21-3Fedora Release Engineering - 2:2.21-2Dan Walsh - 2.21-1Dan Walsh - 2.20-2Dan Walsh - 2.20-1Lokesh Mandvekar - 2:2.19-2.1Dan Walsh - 2:2.19-1Lokesh Mandvekar - 2:2.15-1.1Dan Walsh - 2:2.10-2.1Dan Walsh - 2:2.10-1Lokesh Mandvekar - 2:2.9-4Lokesh Mandvekar - 2:2.9-3Lokesh Mandvekar - 2:2.9-2Lokesh Mandvekar - 2:2.8-2Lokesh Mandvekar - 2:2.7-1Lokesh Mandvekar - 2:2.4-2Dan Walsh - 2:2.4-1Dan Walsh - 2:2.3-1Lokesh Mandvekar - 2:2.2-4Jonathan Lebon - 2:2.2-3Lokesh Mandvekar - 2:2.2-2Lokesh Mandvekar - 2:2.2-1Lokesh Mandvekar - 2:2.0-2Lokesh Mandvekar - 2:2.0-1Lokesh Mandvekar - 2:1.12.4-29- remove watch statements properly for RHEL8 and lower - Related: Jira:RHEL-2110- update to https://github.com/containers/container-selinux/releases/tag/v2.229.0 - Related: Jira:RHEL-2110- update to https://github.com/containers/container-selinux/releases/tag/v2.228.1 - Related: Jira:RHEL-2110- update to https://github.com/containers/container-selinux/releases/tag/v2.228.0 - Related: Jira:RHEL-2110- update to https://github.com/containers/container-selinux/releases/tag/v2.227.0 - Related: Jira:RHEL-2110- update to https://github.com/containers/container-selinux/releases/tag/v2.226.0 - remove dependency on policycoreutils-python-utils as it pulls in python - Related: Jira:RHEL-2110- update to https://github.com/containers/container-selinux/releases/tag/v2.224.0 - Related: Jira:RHEL-2110- update to https://github.com/containers/container-selinux/releases/tag/v2.222.0 - Related: Jira:RHEL-2110- update to https://github.com/containers/container-selinux/releases/tag/v2.221.1 - Related: Jira:RHEL-2110- update to https://github.com/containers/container-selinux/releases/tag/v2.221.0 - Related: #2176055- update to https://github.com/containers/container-selinux/releases/tag/v2.219.0 - Related: #2176055- update to https://github.com/containers/container-selinux/releases/tag/v2.218.0 - Related: #2176055- update to https://github.com/containers/container-selinux/releases/tag/v2.215.0 - Related: #2176055- add watch statement removal from container.te - Related: #2176055- update to https://github.com/containers/container-selinux/releases/tag/v2.213.0 - Related: #2176055- update to https://github.com/containers/container-selinux/releases/tag/v2.211.1 - Related: #2176055- use conditionals from https://github.com/containers/container-selinux/blob/main/container-selinux.spec.rpkg - Related: #2176055- update to https://github.com/containers/container-selinux/releases/tag/v2.205.0 - remove user_namespace class, thanks to Lokesh Mandvekar - Related: #2176055- revert back to https://github.com/containers/container-selinux/releases/tag/v2.199.0 (2.200.0 fails to build as it relies on the new selinux-policy which is not there yet) - Related: #2176055- update to https://github.com/containers/container-selinux/releases/tag/v2.195.1 - Related: #2123641- update to https://github.com/containers/container-selinux/releases/tag/v2.193.0 - Related: #2123641- update to https://github.com/containers/container-selinux/releases/tag/v2.191.0 - Related: #2123641- update to https://github.com/containers/container-selinux/releases/tag/v2.190.0 - Related: #2123641- update to https://github.com/containers/container-selinux/releases/tag/v2.189.0 - Related: #2061390- update to https://github.com/containers/container-selinux/releases/tag/v2.188.0 - Related: #2061390- update to https://github.com/containers/container-selinux/releases/tag/v2.187.0 - Related: #2061390- update to https://github.com/containers/container-selinux/releases/tag/v2.183.0 - Related: #2061390- update to https://github.com/containers/container-selinux/releases/tag/v2.181.0 - Related: #2061390- update to https://github.com/containers/container-selinux/releases/tag/v2.180.0 - Related: #2061390- update to https://github.com/containers/container-selinux/releases/tag/v2.179.1 - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.178.0 - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.177.0 - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.176.0 - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.174.0 - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.173.2 - Related: #2001445- update minimal selinux_policy dependency - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.173.1 - Related: #2001445- lockdown allow rule was removed - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.173.0 - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.172.1 - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.172.0 - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.171.0 - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.170.0 - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.169.0 - Related: #2001445- Start shipping udica templates - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.168.0 - Related: #2001445- update to https://github.com/containers/container-selinux/releases/tag/v2.167.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.165.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.164.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.164.1 - Related: #1934415- fix the build of 2.163.0 - Resolves: #1957904- update to https://github.com/containers/container-selinux/releases/tag/v2.163.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.162.0 - Related: #1934415- do not use lockdown class yet - it is not available in RHEL - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.161.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.2 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.1 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.160.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.159.0 - Related: #1934415- update to https://github.com/containers/container-selinux/releases/tag/v2.158.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.156.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.155.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.154.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.153.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.152.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.151.0 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.150.0 - Related: #1883490- synchronize with stream-container-tools-rhel8 - Related: #1883490- update to https://github.com/containers/container-selinux/releases/tag/v2.144.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.143.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.142.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.139.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.138.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.137.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.135.0 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.134.0 - Related: #1821193- synchronize containter-tools 8.3.0 with 8.2.1 - Related: #1821193- update to https://github.com/containers/container-selinux/releases/tag/v2.130.0 - don't use macros in changelog - Related: #1821193- update to 2.124.0 - Related: RHELPLAN-25139- implement spec file refactoring by Zdenek Pytela, namely: Change the uninstall command in the %postun section of the specfile to use the %selinux_modules_uninstall macro which uses priority 200. Change the install command in the %post section if the specfile to use the %selinux_modules_install macro. Replace relabel commands with using the %selinux_relabel_pre and %selinux_relabel_post macros. Change formatting so that the lines are vertically aligned in the %postun section. (https://github.com/containers/container-selinux/pull/85) - Related: RHELPLAN-25139- update to 2.123.0 - Related: RHELPLAN-25139- update to 2.122.0 - Related: RHELPLAN-25139- update to master container-selinux - bug 1769469 - Related: RHELPLAN-25139- fix post scriptlet - fail if semodule fails - bug 1729272 - Related: RHELPLAN-25139- update to 2.119.0 - Related: RHELPLAN-25139- update to 2.116 Resolves: #1748519- Use at least selinux policy 3.14.3-9.el8, Resolves: #1728700- Resolves: #1720654 - rebase to v2.107- bump to v2.89- bump to v2.75 - built commit 99e2cfd- Resolves: #1641655 - bump to v2.74 - built commit a62c2db- tweak macro for fedora - applies to rhel8 as well- moved changelog entries: - Define spc_t as a container_domain, so that container_runtime will transition to spc_t even when setup with nosuid. - Allow container_runtimes to setattr on callers fifo_files - Fix restorecon to not error on missing directory- Make sure we pull in the latest selinux-policy- Add map support to container-selinux for RHEL 7.5 - Dontudit attempts to write to kernel_sysctl_t- Add label for /var/lib/origin - Add customizable_file_t to customizable_types- Add policy for container_logreader_t- Allow dnsmasq to dbus chat with spc_t- Allow containers to create all socket classes- Label overlay directories under /var/lib/containers/ correctly- Allow spc_t to load kernel modules from inside of container- Allow containers to list cgroup directories - Transition for unconfined_service_t to container_runtime_t when executing container_runtime_exec_t.- Run restorecon /usr/bin/podman in postinstall- Add labels to allow podman to be run from a systemd unit file- Set the version of SELinux policy required to the latest to fix build issues.- Allow container_runtime_t to transition to spc_t over unlabeled filesAllow iptables to read container state Dontaudit attempts from containers to write to /proc/self Allow spc_t to change attributes on container_runtime_t fifo files- Add better support for writing custom selinux policy for customer container domains.- Allow shell_exec_t as a container_runtime_t entrypoint- Allow bin_t as a container_runtime_t entrypoint- Add support for MLS running container runtimes - Add missing allow rules for running systemd in a container- Update policy to match master branch - Remove typebounds and replace with nnp_transition and nosuid_transition calls- Add support to nnp_transition for container domains - Eliminates need for typebounds.- Allow container_runtime_t to use user ttys - Fixes bounds check for container_t- Allow container runtimes to use interited terminals. This helps satisfy the bounds check of container_t versus container_runtime_t.- Allow container runtimes to mmap container_file_t devices - Add labeling for rhel push plugin- Allow containers to use inherited ttys - Allow ostree to handle labels under /var/lib/containers/ostree- Allow containers to relabelto/from all file types to container_file_t- Allow container to map chr_files labeled container_file_t- Dontaudit container processes getattr on kernel file systems- Allow containers to read /etc/resolv.conf and /etc/hosts if volume - mounted into container.- Make sure users creating content in /var/lib with right labels- Allow the container runtime to dbus chat with dnsmasq - add dontaudit rules for container trying to write to /proc- Add support for lxcd - Add support for labeling of tmpfs storage created within a container.- Allow a container to umount a container_file_t filesystem- Allow container runtimes to work with the netfilter sockets - Allow container_file_t to be an entrypoint for VM's - Allow spc_t domains to transition to svirt_t- Make sure container_runtime_t has all access of container_t- Allow container runtimes to create sockets in tmp dirs- Add additonal support for crio labeling.- Fixup spec file conditionals- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Allow containers to execmod on container_share_t files.- Relabel runc and crio executables- Allow container processes to getsession- update release tag to isolate from 7.3- Fix mcs transition problem on stdin/stdout/stderr - Add labels for CRI-O - Allow containers to use tunnel sockets- Resolves: #1451289 - rebase to v2.15 - built @origin/RHEL-1.12 commit 583ca40- Make sure we have a late enough version of policycoreutils- Update to the latest container-selinux patch from upstream - Label files under /usr/libexec/lxc as container_runtime_exec_t - Give container_t access to XFRM sockets - Allow spc_t to dbus chat with init system - Allow containers to read cgroup configuration mounted into a container- Resolves: #1425574 - built commit 79a6d70- Resolves: #1420591 - built @origin/RHEL-1.12 commit 8f876c4- built @origin/RHEL-1.12 commit 33cb78b-- built origin/RHEL-1.12 commit 21dd37b- correct version-release in changelog entries- Add typebounds statement for container_t from container_runtime_t - We should only label runc not runc*- Fix labeling on /usr/bin/runc.* - Add sandbox_net_domain access to container.te - Remove containers ability to look at /etc content- use upstream's RHEL-1.12 branch, commit 56c32da for CentOS 7- properly disable docker module in %post- depend on selinux-policy-targeted - relabel docker-latest* files as well- bump to v2.2 - additional labeling for ocid- install policy at level 200 - From: Dan Walsh - Resolves: #1406517 - bump to v2.0 (first upload to Fedora as a standalone package) - include projectatomic/RHEL-1.12 branch commit for building on centos/rhel- new package (separated from docker)/bin/sh/bin/sh/bin/shcontainer-selinuxdocker-selinux 2:2.229.0-2.module+el8.10.0+1815+5fe7415e2:2.229.0-2.module+el8.10.0+1815+5fe7415e2:2.229.0-2.module+el8.10.0+1815+5fe7415e 2:1.12.5-142:1.12.4-28 selinuxcontextscontainer-selinuxREADME.mddevelincludeservicescontainer.ifpackagescontainer.pp.bz2templatesbase_container.cilconfig_container.cilhome_container.cillog_container.cilnet_container.ciltmp_container.ciltty_container.cilvirt_container.cilx_container.cil/usr/share/containers//usr/share/containers/selinux//usr/share/doc//usr/share/doc/container-selinux//usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/include//usr/share/selinux/devel/include/services//usr/share/selinux/packages//usr/share/udica//usr/share/udica/templates/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2noarch-redhat-linux-gnudirectoryASCII textSE Linux policy interface source . /etc/selinux/config _policytype=targeted if [ -z "${_policytype}" ]; then _policytype="targeted" fi if /usr/sbin/selinuxenabled && [ "${SELINUXTYPE}" = "${_policytype}" ]; then if [ -f /var/lib/rpm-state/file_contexts.pre ]; then /usr/sbin/fixfiles -C /var/lib/rpm-state/file_contexts.pre restore &> /dev/null rm -f /var/lib/rpm-state/file_contexts.pre fi fi #define license tag if not already defined/bin/shutf-822acb24374d280555142ae66e4073057115e597f98a20e1ec97fbd7d14c879a9container-tools:rhel8:8100020240523110049:82888897?p7zXZ !#,] b2u jӫ`(y0aT578C8JU!y!'GN}}Ԓଃ3m(o~=Xܼ#NӉ3L&H rOur\X'3l"v_̺iN~[x s5pM641kϘotdЧ]H7 O0x@%%_Ǧx=:W5h,!:5'_ϒ^38KU4(xAVHj0l,Dj:lasEC܆ߝ{oCX׸sE EЊě95֮,-.bnjcnWU !˪v!g:>< oSI|S$␿3&=JWlەI'Q޲xXP><_3CIlt~~p6&cvkXO?es[tqA?l+;\McRؠ]$ n09f֛wZJ( &a})w&x]4rB3yq5=p&hZluͬ&¼ugIx}n.L+=}>y'dK 5l6[`4 za$f$U|γ.+1^RZc%ֲtE36LiRֈSlddO<"Eny ȶw=}:`Mq9%%'^& l"5CJ 3.0Q?j>?6S @u(YΞlL|bV(wtCh:YhrEr}@?8 ڋ˄p3l2$û$h2_qhv;<vC@̊Y;< &W}3Z8)Q[uf{tTSK-e5p`m-##A _vg/FG_a9RQE"V"#2nv[WT^;5:!5?L?klhVU唕u x䵡|ißld/\oAˡn'<[v$3 EcsZTnX>ev:<[k,Ҟ䨭@U!A.$߉,oQu*ߴ!RER_}t8Zu7Qƀ]F+5rxljZ"G2bt Kn^ECPNrd6VJN5Ws3pTQYlfE'vyoEOTۃW5f8XQڪGvD SlʮT]iDr9d4spB{G'DV#5ͅ68MGܴ[OX nn@P*ʥ|ӯהDX+KDHUpv;WO [eEZYx@*"ըrjFkZ03VENZ e?PO8 U$O|/6gcp~45̕e^w: Jf*y?3缊*n0eƔ2+W4xl UTҔXo|ffDgP6xFsh:7SFf~"\m8)GIbGk9 Yp˶*E(B z 0A$b<h:<݊dvƦ+'D*8n*'Bky]h&q1 ʒ[Yt%/1<:ݏiX%Nh6|٨D'2GxtfKt/$ufq{]Ru9͕[v}P(a2P5!%iI):QRq)iNqg '۔.0,/9Sk?:= ֺŴhf'+ۻA QwzbkBIh0os2mePNnҳt' *džD>a,@6*ECbr}#(&9ctgyr(ɂ| y-vB\:#XmȏMGm|NS?ӳĵή> 0X˄|v0vETIίIx5iׂ8CNb"o ;O ;Ii8&IP]X؉Zv3J\Nu#T ^kԷZܴwd{6I:\_7 {'@hy[:UʢQj1hQ_cGzcoaMg4&@;KZŚvSj 蛃,gwZg۠aJ ?ݙw?K= s~M9^/gkOdW2r87Q5W'Rq^&X Ha{u2{ò"o`Wn_-gv`12\/CGɗ8le})C^vIk"Q5F(*AU`_/T]~gf4ȡoPcp adX1p"N]Ը{b%EzB,eG[70w]CJ+8z~(wwH-v:7 _8-W;\dO}_ N 1F͔XraB y{c@ AO8C<+#-YeVqJ-gݣD1r^S KrJNO{NY既T-%ٱ! s@%vctm@%n&bΟK.YMxg [\h>.RB',>s@`_UV8:]OupK p?-e{<w05ζk8,Ϝwys珓mvavrٞbDdz44o5& Yi]bl!lR~0a2 GkX,;Es|CIAࣳ7#\>R%z*U z=1:o\:#B(V g+iX% $u$@S=&akXÞWկG[Џq@nxZvJ7ڡ˒to@pE&scAfu6Ί c(: N=u@$OUj+[x9̍2U},J%1ۀ8o-"#路}X-'ILj  G;F]ڬ{vT/N J7%ˏf6]IWМ7y[((ҾYXv`"7躲qg\rY)ż gTpxrw ,#7Wc3ur'Sk7<~{V<&Ug)Dd^_^! 4kHOBPE#$MɝRqb韴=-[9A-3A`uu2ىwrݝ=z4^0cD t]Gy  j{1t9m&L֩2ZEôiYϹ= Xqz^ i`?\ .wc m`ج s# 3yif0uȐQ]Bw~)̮_c3r>gsQ}F~ Qd|6cG4,'ǥ3tB9S$w?=a-\YR# `l,yaN5?6hڗPU,PO'v[V)%HJ.yhmkĕ #3Awv0nDH;84:•*@ʰ>~>7,u̔vv} &\Y-fX%\khisa*\ ʆX %gzO+-\>_~$ xgM͙6<|gN"-d$d?T i3P!~ދ/6_ռ7t/xn.)ɶyqdi,MKVY3p^!%S]8&RN+5x+ޣZCֈw7xǨ`q&b!Qì{6-'Y)a~gL9IMmT۞zc[1&= \&(HOy;rydD2~[sADl 2 w[g_a@<$OV@䣅VL٣倚Ӫ-MH*R#zHHDL[H\7OJ Z#EU_;eŊSNUՈOkG8F_gn7h&'_<+Q@yw S[bWa%(jAQ@ځdNnPI0ކDdYch'mG;§UcF1Cy Hc҅k=<:.z؛tdҐ6H3Waȹ]Bœ'y'k/9!t;ӕpeRӊTP+֝l!FR\G""<$SR LLCN/qL >9bG)Oys)}l]0?*Snst+Up!eu7WiX*ETL<j02bDZEG+ zG'c5EXtaW_ɬ[XW9.5#qf,SFq5r.UPIz#iPFK 7+5T^ 7_yL4B4f`o&0şiO,m+e&(PKjW1x+z! i#`y鐎w5C4_iⶡv/ SVWP#yVN=M-n_UXaR,96q4!K_G!@Fѓ SZfN}TG{Vy "2;YlfvO5W5lC.~ ?w@TzB%T-ZJ4r_vT\ C@|k˱2,MtPR!&2,5BEP[_@n=ev9~Rn}41yosZ:µiK^P"RR.Rl?E~n#{/u7&l@ Ecڤ3q7j{PR7fg"y" ([8PyV(Ջ- lɋeaH>E ԎT(8+>Wopoas i"1Mn?lL~l556I#Prs @p(ISg`@JknUHn%6fŽ`\-yGd"ow@_ \Q-쏉g;p/K0pfVjJm"0v|*>qiJ^d<w9ݮYH?`QнsןDZ^Ǻ+W/W/ OOab: l(h`HZVs %xh& 2\Ua~U}Q0dۻShO_f8.5p lda'lT~姰OXV!..aQ@13 ,j  Ů߽JXF]+*53!|azؑ Hi' ֣[A$3۷:‹k5S#K /_sRG~iVja;SDI"C#&' 1RpRa6'pab-dDMpacNRU.b%^ AXu*s,R{Ē@ a` lQW15P`=ӁHne eҫj&ixO:qܫ?sl~xŅaK)5 jcRD^PT9Cw nj޺6$ ٜ;ymd~Ѯ}L©U!U?Ռ AWYQ@|a&(bJwU-I ΕÅcW'.wLd VcFfRڂ VXEe ͊9GޡuݫCX)q3Y<&:<1;V`aí=.qקTlI+%fݚHUzi*xFLVTH~i>u }E5S?m:Q ,T^V=`Vrzro>SߘXuuR}OKM:dg`ʺǑ"Kk .)KʬWh^80`A3<*x# f,\B:K.W;qFNpg䜹?+c}@.<8QboZ)v,B*C3 ,(ViX*N|9i:Cm?udPmp#bԾ[dj%t_ ޞTB2>\nj #do]BF_S?c>7ޖɀ53gy7~ލCUEq)b~{A0e [=ťQ 8Yw!rsYONglmѭ 'EdZY݈dsO]w<៌ ^s&k3锔 #iw&_״f\Q7uWu$gz I}JebJ_~('ުj=k1U@b)aL6DeX1PnNzb/EU֔6OỂ],mKzN4yUN-+og5|1 W_m+pkĕmZ5CrJ cF-T ՚Ŕ5퀿H  58` UI^OQM%~Ѐq8c/U#\7;%R1:M'V.yK({igFFs[IN%ȥ f]aVs2NjDNx5X#GƷ"1l ؜*}PZ}$P# RQQ' q`@*p->&)u 6o+(J0j .E6ѰEcY nN%տ̭͏u_t3.M쀅+>T]H3ط3b `OAu,͹ [W_k +Uӎ˾cDN(;iV󺈕#[.'S"skN6ͿI&X3@9VW3AS>?:C5RA vзb25 \>=B"fގ_$-z&1VDiXff:NM^IHVFg_"W6MrGo$*p ߑYǃj`[S^Uf z J"Ʋ>]]65E>m,7a@LXi)nWzRj,ԱJ3uȜ8hsiR?OJ-=.̿ᆩWIiFW2RejpԱahB)(\PcLڒhOhy5u\འdsA4' &,#怶z6beo..=?wϖ>hP]C,Nt*'p"C( ]*e]_ZE+Y]äN} em¹ A% G.Kۊj E(A@lM/<@l4ke@Cg8L +NĺU=*sSժ:l#斃hC FF)L .Rԍ.3!/YFw.nR;x2nSn0 N^r!_B),Sh$U~⇹@X V2a@9X apo> 7OPA}sa`2v]w̼ Ɏ%pĪߗ`3uicL  r ~m!؄i30M$vLZ {ǐ'N!_} ]T 1#}b#UjُzVJFHNfbu+q7g ҧNV"` [yJm緟2uw31w=s-Ǫ s&֫S!ܤ*'1LZvy1 [g,\f#H\Z`Y[ʰZiPTEʢLaot1p[qG1rks7bdX<ʯa9ʐXg4hKanYA\lUO3>0#h`orvE掤'rg?[hg58cF@UjZ6&(FA#DCJxO}P <MƯl/?+&>]ܔ^hg7$:jѷ^bp+R- ϯ Rcs+tt=gyUJ׸~W{,2YR*kXO(/pzLgGDöFp詷OwNa%\Os}?ShMő-aFpPz Ff R} =ʂ9ԩ Fޠ7t )PH-t޴k`_>p+78^H$Yv^`dI SZ歶鵔vLn.eJw*Ī L޴9׸[M(濢j4z};z7膷PXw*†R@iؓ/un+]L z}@d{ ,m}،mGC,5p¹<p|j`3NZlGLK2fΧ,HAtPMؐ: fඡ~[V"pOIتg@8 ji |G.4gg1F'qH!Bh7{#۠Y[^rX`:^hwwe3쾨& SE̮p0us5yX@H1'5CH @[woln&R2X^sGȞ}&tcokC|ͽKʷR2G<$Fl{_] >Rh As6]&F^݂4`UD{/f;0OU^ S, "Lnc2`Eg˨ JIɋ@̑JsHJ) n_MLfz0,jU>8WZqaq7H@)qЃe)ȨqQɝ iҮs0?ccڬ<{8Np©"zEђ(L捎!K^|ˑY߯dV) ٮq w4o" zY= IRumAs3Hmx\UTݍǡV(m50r}Tjota1`wp{gDH{$2GdH >n>&qeuyB<nxy7R:9A>'+/ ,;G%i#5#¦'c!_7lYq/ׁ$Rիc+wnK1N(fQ^rX%kks3 ls@oq@8e⏑#Gm8iWنf JZFeBIkḶWRn=дZ#R }16"O  !23г~8 +[G.]{2i0@ $_D/ʭ;qcօz6"IB|s.hE³;J,6Ϻ?j٢J@Q"6f5XPc᥺]6 +7p&VKH2I(/n320 ~Q7%,X +Ԥ:ǨOEoR'ݳUIBBD8o .ADmP N1Q:ڎ$PLaV`pxBųN R^U %Uܳ4qDL+ܓ"pTw~,'QӫfsK*x+1 ` »}nt欕?lt^:ʿ&^/'\Ku)1xn2b!N3Hp\1][//S7"1?A3QV\/LW#|"jdyլ\Oe"7PH jrNLE` :f"EgM3#l -j<[pqbb7{Rl´$N,$OG6{U:XbkJ~C/5{La{*VMՍk\*bc'ktfՅ@ج(6)33t+"m\nmS 2AR>.PVw ׁip~!/$^Q|.p ;hA"qXU,k;pq8Ɖ]h/!nR{[Vٰ<>}e0&gbIU9{܎״p=v":5qj^ޜ:4K U~ ~&h…a(Kq>9WXb˱<&͋Hdb#(\~p[t|oP.o2&y dDM9/3SJ.8|"/Y+68X @A?'k)4$Fgz+ (ZL|`^.Ϋ:z݂ )ͥ{vtU|6vQ (FYȠ>ڣ $`$\ӞBajzuSi)\:/^RQ77'FQ0F="pv1 ::)+h&)n4mm4A>eStjkHІJq C"Fvd0>3rQaV:LFY8(ӆN%MMy I~Wm)*q A8_@R/+A/;mBUTx!"59_"Ȯ1G4y|cIJ3pLޟ$ōyiĒٗhU׿ XHS[EGL!*O^qd/p+ ԜJ'Fm s b>m}M"f6E;^)͖3WBF]~rCjlJ(tk)a'Ȉޢ}.aΒuLO WJl]D k+\Dw wx|()c7-hӮsz)4h6NۘΌN*Tf}55cJ;rY[G+Bý(-He)!(¿CPZ. HGiꕌԔcZ imT X`}삆ku"ڷ ǣc  o(,bb9ɏqWME3}i"/쐙K[6=Mlw0m1qqމAqK$4~݇(ykxyX_"n27syBJM_nsϣ`8ޙ.k&@W<ܽ4.CAT;φF"l6f[;1%|ءz3r|$ ɠ@-5Ym\V'NVGgg]1U :MwJ"kan?Xڢ9y:Om?Zb ĶCw eQrz0$nx-ƈlϼL{ naquuz%>l%U ;ԽD:KAw6*;z7 0 1Y|?r\0"Q{MnۑHt1ï$i ya5hv\YSӥA8@X] .OW44W6> ÚV깢(WV$r | ؒ&Ck+ui8_d~=FO5&5 K?@׎jG`Mv(:1]Xf96R3c=u Woĸo8}>6Z*P8[/.]mpG^rN/Pof”p -$d1F]f7Ҍ9a)H/H)(nbcfGTXϋa:V\<|CIXuV-:9p ,M}qJ&)RJЬ!M穸 H$egEvN&Zf"ncRQŦ9'|{cnPEXSD`h9Sao h ^$'w.EJf8@e͚G׋|2 uG&I4̌QΑWX}h}|v;0aĎ'-bM׍& ~Vl!z5 [K(,ԑz-%U3uGlJ xi2$wtʷ{8hiBT&ءq/BVN-z +qE)OC[M>a 4YCf;tNxȧ#Ҷ0gåyZB^1Hh+Dօ·,}NM/EN }X!s)}Z\eyS'~ /Ե4 ʵwd#WqYF)ߤD#fi:qydܮN|EHkN+) [*gT!la,C1+?@/m<́ Т _x %#| R~85 ѣYS6Yiؗv7iloBkG_:5kM=68ZHט,մI=ǛP-[971bՎB i 9_LIF]9= & քbx.:#JtWԹfׂ`,mVs 1$=yWCA$@pOMDxnCƶf"ᵊz`W`5wKfqQgq\vXJY{QO6׌ ̰Y $#+H@ L ^“3u|Ը֦wBb)/VG/lIᜎVlf$FS&,e>X>s L5a  sm;S&asQYzn ķ,c8@wr0/k^RKQe"w}LKGE('jėBUNP \ fy:Bfqƚo,_^]8Ȗ}p4OUݵGqEqFuGKlX6@B%=IZ4x}7v@K@*uC}т4jK&G)'!LWP'4*ԋ'MtFߕ)%=՚x &ۏG9Kq)fQ$8L/,R<44*/\tvr6v`7w%UpgpZba&KSCHhR6&*GG9)-`o2h2qŏ(7c֦ʛN&p(b㸺a286\h_B4=O jIp^/@kJ{Tx׀r! 3D ̽%6A B\HDX(xH4þrx;4:S f@K^O?K:c}ai9zze5k__ηQVĦOJq@Sx!5`3j@_ @yUEZOjS9A"O$`ވBs/ZN;Yn~~ձSvкdդ\jFUSx]d VN>N.^@k٢58J+RH8v<,m.tGuZg~Jk[5<ڭqV^d el"@cVy|Yoc2Lfg,NuȠ|ێhD$7)Q:¼Ͽ{Ix8MC汈f|Mf>*QI+Dj%[ M&D|/~PDnpAٿp1bOanK)`_7%;R<~rsK[f~LYE }|#g!]ǎװXz,nѼSWhXOEs_Okq'~,/{i20,$M dX5iv?kk 838aXJX 7":r邪4\ؙq]e`8A`(&Va>Q`P(01(SJ5`!Aag]IZ.̺LU_,U`*R°>`~(O;rr~Z<̑(x  @PC(:ڻevc p?WVu-zE.mVJ:`6H"j*(WȄ );v`ݭ} 7rq9'vŕ.H'htoӷDfZ!:-!GQWI-P}`ğ_ǷD-l)7}wQ'H8ۊ#{q7B0!ri/^WN'ͪnf]T?nSuREUB)ߟ@XƞjE A![XQ50 `׌tպD:`&@UU"+)ȷ+cTjV\·P3 (MHnX|V=Xrc\Pv1F D9s0?dm&{#cU!)u^H ͧzԠG294ZW'ɮA6NDεnEY M :?g}?1 ZIIv!q˔"%R?c+˖z֭QQeo*Llw /Nrhý]>^-iU][uOn&RzļKH,zܞ^0~R+1;|^,`dF84-X4꓅!c/X4G.Yه ÅkX0ӧ"&a#;>%ݚ+I>kֱ8#~ڒJ5k.0Ps Y52&Q=9.u S5d#Uω~\u= +MN{JQ-;ɴܖAN;O V561rU86 Uۙ9+xD"SM#^EE1{LfrJB[g?eBut<E=+ēwk EDFU{o[ jh=Dᬨ 4[A;1P-E0oFj'>&ׅJHv OOz>\ꤚ?5 WVr]ca`Z#_4!}0Fv&Y$ֺ 8xo;U2 p'yS@)Ct>hҘk&U/8@lXhl9vűOXMnսM64/z艤`Ms)4bjVrF.fݫW/eӅzNzisb}ZÉ%JP#/Ac'"<^ͧCOr[k(z34YJ2eL<`7ڂ= 4tPcܧcuK6}s/!}^?n/EAߗR|{؟W -'{I)&H)ŏ{DƖyz:|2ٴg^hUvxzAa qj{.F|;!@_|2"{Q~VE8UpGx  8QGA<,p[^]!X?aul^t V)6GΌ(!`0 "# GIP.Ɍe̤ }}5YwOq!@0 ղ 0Gv&c>%}qplNyR69[Tr8C/A9 *[rEkr82Ҁ#k"0o+Z_d& Dc0A3p"Z-_e򅜠anwJ|7o\W4`(AP;ma,]h7-l.ch5SG汁DH/;z9z2M1g#0mlD@Qv  k'mnjT*HY y$fUOvHB Y@B̟R3a:찶3E&Hʝ7UWeśRZґ O;5>?K܃ Yy+UynTH6#9w*F&|z1aLJp|djBp;@/v)=_&N mOF>#ZR$jfIƺRБpעn'ZC?-LwD4'xEp醲lz8;1*e &=Q[W2>TQ=sI͝!ka\Ք*''~hi'"AɮurTM0UP[Q[Z[ˬ }`%}Yڡ+M6⠏g(eh픬%fti2/g?yGVGe;=J5AB`yF3Av z]gKf|MY:S.I3WCʼn={O O(W-/>r/{KlAR,L;4LX dz#N= lԩ[2:`ycd >3 B̦B~z#b B^a:w֝"vKoDN<|ꤩ/E5B/GuvsD*'Jd]b{ܧX֌it .FGfs6I0s'ao.e"bh ]zRϹ>gjpǼP Ks QbTtv8::i$4S/-nzZS΂;ƦY.QKF rD/ v{%ۧntoGFGa cQî4;vċZDץV},tgLs#M^P3u#ÞY߬Xj4׸ԉ("2W|FW$FPg}]|xj9*I)<F6Kp8@qlTS ŷ. c'I\ LrkXt(Z`l$s-ta3N{3.RFMǹHf G 2DNL_U>nLo"q/ff#8١7 e5i]F.ҒeA,DN4Ȕ:| =j ;HҌKC/',W UWΫU {7,3w٘WAc#;?7n<ˉC/^Bb(+(Y/vl~Ex5G]8iB2ط߱H H>v3C&:*GԊ=PhIbpAlPǴmv({ ċRzGGy3c>v cE FEdO$Xe:Υ&^x`%5'Ax;UJ;iWCذ'XNYO'XYacGb aj#;n RSIw" ^x҇@:Eڋ0Q;ϱ1!cx{ug!@o;ˑ'WP#2S>}'_UT7/|>kyjnJaiaS_(΁lL_ eFYǶSX UrW:Ns@bK&J}cR0ނ"[U M}c({kfL8JؑzHe J m }[1fdrK'3R X0>@MNTE^ΗEf@.8wԠD?Yζ@In%iK%x"O恷~9QHxg*s:2\AjhBsS5\|N} nw^:Y]Ԥ>eq6,Θ{`FiַZ[= 4ʍj ^BB8iؕq }t=_C6=|lt %iPf$`S<#"IE^O5xi=3`]]^ @Nrg4< % ù%] 4Zj-E@wg5MGHz&WP䟏k+tQ\t0\TW|av%7 k̑]Nګ!0p nWB*<1^[usΣƀpMM7c9K6晙œzbe$S*U/ؚ}qB x|U/`Mi2Y 8y bdI!`Tm \i +C24ޝN'Y/XOUC xa|5޴rCr29L@Ql+w )B蓩%Ꮌ倉mݓ)Y롔Q]y{kؙR|yݩXS&#Ol߀6vMA52pA:2aPPcNòZAJ;IoK&&޵:CLUZu' DeS5]wBenmmT e<,2#|טXLczDSHX?J|mQk'"=L&G~- Q|hwܜ;4t9ݥ|M~bW$&6dS}IҐ'k&6RSu@YC) Ͳ#wCg G\eVIwk{we9 KG"O cNP$ g1N-Stk"l/@K63m});Uz拓rbݛ*nJp& o""n=ܽ@=B^IF;|;#t96CU[Wz Z~Ƣ̔;͉(19[Aђ"! ;pE!CКpO65{|&juq!:o- J[Kl*l<_ٱE1;Hv$!W%gŇ3OW\[l^Y˾ ["Ea%GUP՘4Pa8ޫjb1P[v@++xA)QH 1.!J[audۨ_["}yf:qŰ#P Ic!'h6@[ʸe"߃Chuр8NX\Zswϩ)uX1~oTIGC !?3 l}mK]MÇ%o<1iR#;&Ʉ\+"O⎦韁x?l tdB9]5lbB>zХ>JXg AVZaNâ]@42EbWLAدn8:3gpAmt<'sG6d89R ߬=KG]~/-A dĠ2t|O6qq3n?9PKmn⢼1M쇲PqypfU*~=\x}EK25D) YfH"{ErY4݃04Aq/r0ΦWހ rO)Ot #yu-V6QJ<}|2>&i<./; { f$}E}2<]0TMR.@}Crsv"kP!IVɅ q~efv"X=o˃&NSX9 DO{ XaP,D*Cìw|EjH^v&잆JD2޹lɯaV ymH[\/(׳5G5'/b+Ti>h[X:Y(4w#w*-JFzpnԐ18z&}Q۪Q#]d%uoMը4E ^8nPd"O_Yj%Ÿ~Pp>Q%#Bԃ0~Q|X7| Zװ.t A_{KvmU;aTuBѹ.D&oka63FQ`eW{i)6ۍl5H'=Xא}o1r+QPOt 9Qh;r'*y\i˕2aqno&AxHEF)rCp4lb}M(!['8 vMp8egl=yN(#G| 7c5ʠ0ɇaZ+XI.0i1q fcy-p-C7V"GӿkZ_QRWPsB7zVm tTS!SmЃx42 "GR5ȗ5etqY矱:eMM)fmt,йHVg>c'_UFp,uY6- XXxcj[<_?V}a83rYq! vR@jw()OД724 Vfӄr 7$OhuKs\&)i"s $==wAuͣrAGcG"1f^qn L$PfiA f魿eQITQ$"ˢO1_XeK?dv-GOi`wQ6l_L~-VihY_L=Onw*0ޕ^-y\ IGUl' rЭBEaYD2- Jwm`,}ܱ>rwu̘fUD<@xEO#I/qM$YG0㎃dDžsCtQ:O'ek&yfDHAH11Kݠ­G~$],6 kh+R2+P,^ 롊:gƢڀL0b%I»b[Vxw9ٜgwjmG0 DNũF]E>ZWo~3; Z|~y>V~@tCt`'Vfy }h1hW}fNK_p9=cCf:)X`%[Vu}xL vMM~), nb=QsY0׵4  $tdTY ѕ ד__W\־Ih!O],:Hfhà ((o6gS?i5yrG Ft}(v?6Q4N) O$oŗSZ֢ 1/@"':]M]!n"CbفL\*^NKy叱)VS ?Zu8SRԬ% UNX I(4H_xt}$oF"z,)-ٱ!niyF7G#A=c׺x* aYb[2XK5-eJP/M(擵o)VIAt`#YxZw*ľ1A[ljz}>q6AֱKui"$x+3]rԣޣ:ƭLr3&Nr  8j_Zd,< E|5*fIZ(;'F* <:li6٠? Х0p&_ "^q腑 e՚ op?P #d*,[ܝ-Uߏ1.uP.:pw 2*3xJU,Yo ]>ϓ~m[R#kR/g~Z:.91x '8zy4B7u haybX]&Us2B&61Yt+ Sߐx%/v)-/^8fsB tiKQc9*j#s*Kp@h@)?dKA@J&-|t<d$o q=dũ"#f]+NM|*J Lk~_g\!Nup2xU?@y=Jėd/Ѩ׆KUvT** Oiԕ0S+Pdc_C:[`T>dU `|)ROϠQtսÁ-Ak3BdI7v 1Yܞ ƞUlE_2umꮋ6k7\x'aͲ]d^ Y3:ԇ%NuLm^V}V(N~ŗsƿ3pØh.W_slv_ =BgM}cv+;<ϯ@Y`͏ YZ