libselinux-2.9-8.el8 > 6 6_6 3!pQp)Tξ7]mtZ`c\E ]mtZ`^q@Gh&%9lO)X2 VDO h yw3l@afΒlψm=q;ČvygqĪztdp"@فwVkgf@Nw}. ʨAŲ#'^"uz\סc8r|IݻyIOn'/=lN[@ ͡gϧ)B# mδEkp?dh?dXd   <<@pty  $ 4 T  Hh( ( 8 (N9`N:qNG_lH_I_X_Y_\_]_^`gb`dbfebkfbnlbptbubvbwcpxcycdd ddTClibselinux2.98.el8SELinux library and simple utilitiesSecurity-enhanced Linux is a feature of the Linux® kernel and a number of utilities with enhanced security functionality designed to add mandatory access controls to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement®, Role-based Access Control, and Multi-level Security. libselinux provides an API for SELinux applications to get and set process and file security contexts and to obtain security policy decisions. Required for any applications that use the SELinux API.c"ord1-prod-x86build002.svc.aws.rockylinux.orgKojiRockyPublic Domaininfrastructure@rockylinux.orgUnspecifiedhttps://github.com/SELinuxProject/selinux/wikilinuxi686# AAA큤A큤c"c"c"c"c"c"c"\>382d2fc6ccf45d07996f467b08722a73c0f0f59b1d6efaae44467d7869372e5eafe23890fb2e12e6756e5d81bad3c3da33f38a95d072731c0422fbeb0b1fa1fc86657b4c0fe868d7cbd977cb04c63b6c667e08fa51595a7bc846ad4bed8fc364../../../../usr/lib/libselinux.so.1rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootlibselinux-2.9-8.el8.src.rpmlibselinuxlibselinux(x86-32)libselinux.so.1@@@@@@@@@@@@@@@@@@@@     @ld-linux.so.2ld-linux.so.2(GLIBC_2.3)libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.2)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.2.3)libc.so.6(GLIBC_2.2.4)libc.so.6(GLIBC_2.28)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.7)libc.so.6(GLIBC_2.8)libdl.so.2libdl.so.2(GLIBC_2.0)libdl.so.2(GLIBC_2.1)libpcre2-8.so.0libsepol(x86-32)pcre2rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)2.9-13.0.4-14.6.0-14.0-15.2-1filesystemselinux-policy-base33.13.1-1384.14.3c@c.b_@_l@]X]@\@[@[ā@[ @[,[@[Zz@ZK@ZZZI@Z@Z}@Zz@Zu@ZTZOhZfY@Y˒Y(@YJYV@Y@Y|xY{'@Yx@Y.X-Xg@X@X @XN@X@XXx@Xv@XJX43@WH@W9W@Wq@Wm Wk@W,@W'A@W#LW@VяVIVɦV=@VVii@V@V UU@U4@Ua@UQ@U8U6;UTS@S@SSShShSXS 4@S@R@RUR&RʚRkR%R@RMUM@M@M@M@MlMQ0@MGM5ML@L-@L@L*@LLq@LN@LF@L$@KKKrK@KKqK}+KTM@KA@K@JJJJG@JG@JG@JjJS8JS8JB@J@JMIܑI@IԨIbI̿I@IV@III@I@I2I@IcGIcGIcGIG@IG@IBR@I1.I!\I!\I-HHHe@He@He@He@H@HHH@Ht@HsVHgy@H^>H^>H-w@H!H @H@G@GG#GF@G@GGƢ@GƢ@G­G@GGD@G@G@G@G,@G,@G@GG@GZ@GZ@GeGeG|@G|@GO@GO@G<4G<4G0W@G'@FF@FIFFFFF&@FF@FvFFS@FF@FF]F@FtFFzh@Fw@Fm9@F` @F; @F-@F,F@F@FF*FF @F @FoE@EE@E4@EE?Eɿ@EEEEElEx@E&E=E=E@Ex@EvEnEYEK/@E>@E4EE EgEgEDfDDDDq@D@DB@DB@DB@DB@D{DDX@D4D4D4DD@D@D~D~D|3DvDu@Dr@Dr@DlaDk@DiD`@D_2D_2DX@DWID?D;@D'Dj@C@CCC-Cǖ@Cǖ@C[CCC8@C@CC @CCqC @CCCC@CBC@C@C|pC|pC{@CyCp@Cp@CoACkM@CiCf@C_oC_oC^@C^@CX@CWCS@COCFc@CFc@CECECBnCA@C;@C:C*C&@C&@C%mCC@CC C a@C a@C&B=BۙB@B@Br!Br!Br!Bn-@BgB] B] BZfBS@BQ,@BIC@BAZ@B9q@B9q@B06B-B$Y@B#BB@B@B LB LBBAA)@A@A@AA@A@A@AyAҜ@AJA@A`A`AA@AA@Ak@AAA@AvA@AAoA]FA]FAQi@AN@AI@AF@AF@AA@A>@A>@A7 @A7 @A5A4h@A3A3A/"@A-A+-A(A$@A!@A A A@A@@@q@7@@@@6@@@A@)@@@@@@@@@~y@@~y@@~y@@}'@s@@s@@s@@l@@ia@@b@b@b@O@@O@@Dw@@9@@,@@ @/@@???E@?E@?٭???q@??@?@?@?}d?z?a@?M?D@>S@Vit Mojzis - 2.9-8Vit Mojzis - 2.9-7Vit Mojzis - 2.9-6Vit Mojzis - 2.9-5Vit Mojzis - 2.9-4Vit Mojzis - 2.9-3Petr Lautrbach - 2.9-2.1Petr Lautrbach - 2.9-1Petr Lautrbach - 2.8-6Petr Lautrbach - 2.8-5Petr Lautrbach - 2.8-4Petr Lautrbach - 2.8-3Petr Lautrbach - 2.8-2Petr Lautrbach - 2.8-1Petr Lautrbach - 2.8-0.rc3.1Petr Lautrbach - 2.8-0.rc2.1Petr Lautrbach - 2.8-0.rc1.1Petr Lautrbach - 2.7-14Petr Lautrbach - 2.7-13Petr Lautrbach - 2.7-12Igor Gnatenko - 2.7-11Fedora Release Engineering - 2.7-10Igor Gnatenko - 2.7-9Iryna Shcherbina - 2.7-8Mamoru TASAKA - 2.7-7Petr Lautrbach - 2.7-6Petr Lautrbach - 2.7-5Petr Šabata - 2.7-4Zbigniew Jędrzejewski-Szmek - 2.7-3Zbigniew Jędrzejewski-Szmek - 2.7-2Petr Lautrbach - 2.7-1Fedora Release Engineering - 2.6-10Florian Weimer - 2.6-9Petr Lautrbach - 2.6-8Fedora Release Engineering - 2.6-7Petr Lautrbach - 2.6-6Petr Lautrbach - 2.6-5Petr Lautrbach - 2.6-4Petr Lautrbach - 2.6-3Petr Lautrbach - 2.6-2Petr Lautrbach - 2.6-1Fedora Release Engineering - 2.5-18Stephen Gallagher - 2.5-17Vít Ondruch - 2.5-16Petr Lautrbach - 2.5-15Charalampos Stratakis - 2.5-14Petr Lautrbach - 2.5-13Petr Lautrbach 2.5-12Petr Lautrbach 2.5-11Fedora Release Engineering - 2.5-10Petr Lautrbach - 2.5-9Petr Lautrbach - 2.5-8Petr Lautrbach - 2.5-7Petr Lautrbach - 2.5-6Petr Lautrbach - 2.5-5Petr Lautrbach - 2.5-4Petr Lautrbach - 2.5-3Petr Lautrbach 2.5-2Petr Lautrbach 2.5-1Petr Lautrbach 2.5-0.1.rc1Fedora Release Engineering - 2.4-8Vít Ondruch - 2.4-7Petr Lautrbach - 2.4-6Robert Kuska - 2.4-5Petr Lautrbach 2.4-4Petr Lautrbach 2.4-3Adam Jackson 2.4-2Petr Lautrbach 2.4-1.1Fedora Release Engineering - 2.3-11Petr Lautrbach 2.3-10Petr Lautrbach 2.3-9Petr Lautrbach 2.3-8Than Ngo - 2.3-7Vít Ondruch - 2.3-6Miroslav Grepl - 2.3-5Fedora Release Engineering - 2.3-4Fedora Release Engineering - 2.3-3Kalev Lember - 2.3-2Dan Walsh - 2.3-1Miroslav Grepl - 2.2.2-8Vít Ondruch - 2.2.2-7Dan Walsh - 2.2.2-6Dan Walsh - 2.2.2-5Dan Walsh - 2.2.2-4Dan Walsh - 2.2.2-3Dan Walsh - 2.2.2-2Dan Walsh - 2.2.2-1Adam Williamson - 2.2.1-6Dan Walsh - 2.2.1-5Dan Walsh - 2.2.1-4Dan Walsh - 2.2.1-3Dan Walsh - 2.2.1-2Dan Walsh - 2.2.1-1Dan Walsh - 2.2-1Dan Walsh - 2.1.13-21Dan Walsh - 2.1.13-20Dan Walsh - 2.1.13-19Dan Walsh - 2.1.13-17Fedora Release Engineering - 2.1.13-17Dan Walsh - 2.1.13-16Dan Walsh - 2.1.13-15Dan Walsh - 2.1.13-14Dan Walsh - 2.1.13-13Dan Walsh - 2.1.13-12Dan Walsh - 2.1.13-11Dan Walsh - 2.1.13-10Dan Walsh - 2.1.13-9Dan Walsh - 2.1.13-8Dan Walsh - 2.1.13-7Dan Walsh - 2.1.13-6Dan Walsh - 2.1.13-5Dan Walsh - 2.1.13-4Dan Walsh - 2.1.13-3Dan Walsh - 2.1.13-2Dan Walsh - 2.1.13-1Dan Walsh - 2.1.12-20Dan Walsh - 2.1.12-19Dan Walsh - 2.1.12-18Dan Walsh - 2.1.12-17Dan Walsh - 2.1.12-16Dan Walsh - 2.1.12-15Dan Walsh - 2.1.12-14Dan Walsh - 2.1.12-13Dan Walsh - 2.1.12-12Dan Walsh - 2.1.12-11Dan Walsh - 2.1.12-10Dan Walsh - 2.1.12-9Dan Walsh - 2.1.12-8Dan Walsh - 2.1.12-7Dan Walsh - 2.1.12-6Dan Walsh - 2.1.12-5Dan Walsh - 2.1.12-4Dan Walsh - 2.1.12-3Dan Walsh - 2.1.12-2Dan Walsh - 2.1.12-1David Malcolm - 2.1.11-6David Malcolm - 2.1.11-5Fedora Release Engineering - 2.1.11-4Dan Walsh - 2.1.11-3Dan Walsh - 2.1.11-2Dan Walsh - 2.1.11-1Dan Walsh - 2.1.10-5Dan Walsh - 2.1.10-4Dan Walsh - 2.1.10-3Dan Walsh - 2.1.10-2Dan Walsh - 2.1.10-1Dan Walsh - 2.1.9-9Dan Walsh - 2.1.9-8Dan Walsh - 2.1.9-7Kay Sievers - 2.1.9-6Dan Walsh - 2.1.9-5Harald Hoyer 2.1.9-4Dan Walsh - 2.1.9-3Dan Walsh - 2.1.9-2Dan Walsh - 2.1.9-1Dan Walsh - 2.1.8-5Dan Walsh - 2.1.8-4Dan Walsh - 2.1.8-2Dan Walsh - 2.1.8-1Dan Walsh - 2.1.7-2Dan Walsh - 2.1.7-1Dan Walsh - 2.1.6-4Dan Walsh - 2.1.6-3Dan Walsh - 2.1.6-2Dan Walsh - 2.1.6-1Dan Walsh - 2.1.5-5Ville Skyttä - 2.1.5-4Dan Walsh - 2.1.5-3Dan Walsh - 2.1.5-2Dan Walsh - 2.1.5-1Dan Walsh - 2.1.4-2Dan Walsh - 2.1.4-1Dan Walsh - 2.1.0-1Dan Walsh - 2.0.102-6Dan Walsh - 2.0.102-5Dan Walsh - 2.0.102-4Dan Walsh - 2.0.102-3Dan Walsh - 2.0.102-2Dan Walsh - 2.0.102-1Dan Walsh - 2.0.101-1Dan Walsh - 2.0.99-5Dan Walsh - 2.0.99-4Dan Walsh - 2.0.99-3Dan Walsh - 2.0.99-2Dan Walsh - 2.0.99-1Fedora Release Engineering Dan Walsh - 2.0.98-3Dan Walsh - 2.0.98-2Dan Walsh - 2.0.98-1Dan Walsh - 2.0.97-1Dan Walsh - 2.0.96-9Dan Walsh - 2.0.96-8jkeating - 2.0.96-7Adam Tkac - 2.0.96-6Dan Walsh - 2.0.96-5Dan Walsh - 2.0.96-4David Malcolm - 2.0.96-3Dan Walsh - 2.0.96-2Dan Walsh - 2.0.96-1Dan Walsh - 2.0.94-1Dan Walsh - 2.0.93-1Dan Walsh - 2.0.92-1Dan Walsh - 2.0.91-1Dan Walsh - 2.0.90-5Dan Walsh - 2.0.90-4Dan Walsh - 2.0.90-3Dan Walsh - 2.0.90-2Dan Walsh - 2.0.90-1Dan Walsh - 2.0.89-2Dan Walsh - 2.0.89-1Dan Walsh - 2.0.88-1Dan Walsh - 2.0.87-1Dan Walsh - 2.0.86-2Dan Walsh - 2.0.86-1Fedora Release Engineering - 2.0.85-2Dan Walsh - 2.0.85-1Dan Walsh - 2.0.84-1Dan Walsh - 2.0.82-2Dan Walsh - 2.0.82-1Dan Walsh - 2.0.81-1Dan Walsh - 2.0.80-1Dan Walsh - 2.0.79-6Dan Walsh - 2.0.79-5Dan Walsh - 2.0.79-4Dan Walsh - 2.0.79-3Dan Walsh - 2.0.79-1Dan Walsh - 2.0.78-5Dan Walsh - 2.0.78-4Dan Walsh - 2.0.78-3Dan Walsh - 2.0.78-2Dan Walsh - 2.0.78-1Fedora Release Engineering - 2.0.77-6Dan Walsh - 2.0.77-5Dan Walsh - 2.0.77-3Dan Walsh - 2.0.77-2Dan Walsh - 2.0.77-1Dan Walsh - 2.0.76-6Dan Walsh l - 2.0.76-5Dan Walsh - 2.0.76-4Ignacio Vazquez-Abrams - 2.0.76-2Dan Walsh - 2.0.76-1Dan Walsh - 2.0.75-2Dan Walsh - 2.0.75-1Dan Walsh - 2.0.73-1Dan Walsh - 2.0.71-6Dan Walsh - 2.0.71-5Dan Walsh - 2.0.71-4Dan Walsh - 2.0.71-3Dan Walsh - 2.0.71-2Dan Walsh - 2.0.71-1Dan Walsh - 2.0.70-1Dan Walsh - 2.0.69-2Dan Walsh - 2.0.69-1Dan Walsh - 2.0.67-4Dan Walsh - 2.0.67-3Dan Walsh - 2.0.67-2Dan Walsh - 2.0.67-1Dan Walsh - 2.0.65-1Dan Walsh - 2.0.64-3Dan Walsh - 2.0.64-2Dan Walsh - 2.0.64-1Dan Walsh - 2.0.61-4Dan Walsh - 2.0.61-3Dan Walsh - 2.0.61-2Dan Walsh - 2.0.61-1Dan Walsh - 2.0.60-1Dan Walsh - 2.0.59-2Dan Walsh - 2.0.59-1Dan Walsh - 2.0.58-1Dan Walsh - 2.0.57-2Dan Walsh - 2.0.57-1Dan Walsh - 2.0.56-1Dan Walsh - 2.0.55-1Dan Walsh - 2.0.53-1Dan Walsh - 2.0.52-1Dan Walsh - 2.0.50-1Dan Walsh - 2.0.49-2Dan Walsh - 2.0.49-1Dan Walsh - 2.0.48-1Dan Walsh - 2.0.47-4Adel Gadllah - 2.0.47-3Dan Walsh - 2.0.47-2Dan Walsh - 2.0.47-1Dan Walsh - 2.0.46-6Dan Walsh - 2.0.46-5Dan Walsh - 2.0.46-4Dan Walsh - 2.0.46-3Dan Walsh - 2.0.46-2Dan Walsh - 2.0.46-1Dan Walsh - 2.0.45-1Dan Walsh - 2.0.43-1Dan Walsh - 2.0.42-1Dan Walsh - 2.0.40-1Dan Walsh - 2.0.37-1Dan Walsh - 2.0.36-1Dan Walsh - 2.0.35-2Dan Walsh - 2.0.35-1Dan Walsh - 2.0.34-3Dan Walsh - 2.0.34-2Dan Walsh - 2.0.34-1Dan Walsh - 2.0.33-2Dan Walsh - 2.0.33-1Dan Walsh - 2.0.31-4Dan Walsh - 2.0.31-3Dan Walsh - 2.0.31-2Dan Walsh - 2.0.30-2Dan Walsh - 2.0.30-1Dan Walsh - 2.0.29-1Dan Walsh - 2.0.24-3Dan Walsh - 2.0.24-2Dan Walsh - 2.0.24-1Dan Walsh - 2.0.23-3Dan Walsh - 2.0.23-2Dan Walsh - 2.0.23-1Dan Walsh - 2.0.22-1Dan Walsh - 2.0.21-2Dan Walsh - 2.0.21-1Dan Walsh - 2.0.18-1Dan Walsh - 2.0.16-1Dan Walsh - 2.0.14-1Dan Walsh - 2.0.13-2Dan Walsh - 2.0.13-1Dan Walsh - 2.0.12-2Dan Walsh - 2.0.12-1Dan Walsh - 2.0.11-1Dan Walsh - 2.0.9-2Dan Walsh - 2.0.9-1Dan Walsh - 2.0.8-1Dan Walsh - 2.0.7-2Dan Walsh - 2.0.7-1Dan Walsh - 2.0.5-2Dan Walsh - 2.0.5-1Dan Walsh - 2.0.4-1Dan Walsh - 2.0.2-1Dan Walsh - 2.0.1-1Dan Walsh - 2.0.0-1Dan Walsh - 1.34.0-2Dan Walsh - 1.34.0-1Dan Walsh - 1.33.6-1Dan Walsh - 1.33.5-1Dan Walsh - 1.33.4-3Dan Walsh - 1.33.4-2Dan Walsh - 1.33.4-1Dan Walsh - 1.33.3-3Dan Walsh - 1.33.3-2Dan Walsh - 1.33.3-1Jeremy Katz - 1.33.2-4Dan Walsh - 1.33.2-3Dan Walsh - 1.33.2-2Dan Walsh - 1.33.2-1Dan Walsh - 1.33.1-2Dan Walsh - 1.33.1-1Dan Walsh - 1.32-1Jesse Keating - 1.30.29-2Dan Walsh - 1.30.29-1Jeremy Katz - 1.30.28-3Dan Walsh - 1.30.28-2Dan Walsh - 1.30.28-1Jeremy Katz - 1.30.27-2Dan Walsh - 1.30.27-1Jesse Keating - 1.20.26-2Dan Walsh - 1.30.25-1Dan Walsh - 1.30.24-1Dan Walsh - 1.30.22-2Dan Walsh - 1.30.22-1Dan Walsh - 1.30.20-1Jeremy Katz - 1.30.19-5Jeremy Katz - 1.30.19-4Dan Walsh 1.30.19-3Dan Walsh 1.30.19-2Dan Walsh 1.30.19-1Dan Walsh 1.30.15-5Dan Walsh 1.30.15-4Dan Walsh 1.30.15-3Dan Walsh 1.30.15-2Dan Walsh 1.30.15-1Dan Walsh 1.30.12-2Dan Walsh 1.30.12-1Dan Walsh 1.30.11-2Dan Walsh 1.30.11-1Dan Walsh 1.30.10-4Dan Walsh 1.30.10-3Dan Walsh 1.30.10-2Dan Walsh 1.30.10-1Dan Walsh 1.30.8-1Dan Walsh 1.30.7-2Dan Walsh 1.30.7-1Dan Walsh 1.30.6-2Dan Walsh 1.30.6-1Dan Walsh 1.30.5-1Dan Walsh 1.30.3-3Dan Walsh 1.30.3-2Dan Walsh 1.30.3-1Dan Walsh 1.30.1-2Dan Walsh 1.30.1-1Dan Walsh 1.30-1Jesse Keating - 1.29.7-1.2Jesse Keating - 1.29.7-1.1Dan Walsh 1.29.7-1Dan Walsh 1.29.6-1Dan Walsh 1.29.5-2Dan Walsh 1.29.5-1Dan Walsh 1.29.4-1Dan Walsh 1.29.3-2Dan Walsh 1.29.3-1Dan Walsh 1.29.2-4Dan Walsh 1.29.2-3Dan Walsh 1.29.2-2Dan Walsh 1.29.2-1Dan Walsh 1.29.1-3Jesse Keating Dan Walsh 1.29.1-1Dan Walsh 1.28-1Dan Walsh 1.27.28-2Dan Walsh 1.27.28-1Dan Walsh 1.27.26-1Dan Walsh 1.27.25-1Dan Walsh 1.27.23-1Dan Walsh 1.27.22-4Dan Walsh 1.27.22-3Dan Walsh 1.27.22-2Dan Walsh 1.27.22-1Dan Walsh 1.27.21-2Dan Walsh 1.27.21-1Dan Walsh 1.27.20-1Dan Walsh 1.27.19-1Dan Walsh 1.27.18-1Dan Walsh 1.27.17-4Dan Walsh 1.27.17-2Dan Walsh 1.27.17-1Dan Walsh 1.27.14-3Dan Walsh 1.27.14-2Dan Walsh 1.27.14-1Dan Walsh 1.27.13-2Dan Walsh 1.27.13-1Dan Walsh 1.27.12-1Dan Walsh 1.27.9-2Dan Walsh 1.27.9-1Dan Walsh 1.27.7-1Dan Walsh 1.27.6-1Dan Walsh 1.27.4-1Dan Walsh 1.27.3-1Dan Walsh 1.27.2-1Dan Walsh 1.27.1-3Dan Walsh 1.27.1-2Dan Walsh 1.26-6Dan Walsh 1.26-5Dan Walsh 1.26-3Dan Walsh 1.26-2Dan Walsh 1.25.7-1Dan Walsh 1.25.6-1Dan Walsh 1.25.5-1Dan Walsh 1.25.4-1Dan Walsh 1.25.3-2Dan Walsh 1.25.3-1Dan Walsh 1.25.2-2Dan Walsh 1.25.2-1Dan Walsh 1.24.2-1Dan Walsh 1.24.1-1Dan Walsh 1.23.11-1Dan Walsh 1.23.10-3Dan Walsh 1.23.10-2Dan Walsh 1.23.10-1Dan Walsh 1.23.8-1Dan Walsh 1.23.7-3Dan Walsh 1.23.7-2Dan Walsh 1.23.7-1Dan Walsh 1.23.6-1Dan Walsh 1.23.5-1Dan Walsh 1.23.4-1Dan Walsh 1.23.2-3Dan Walsh 1.23.2-2Dan Walsh 1.23.2-1Dan Walsh 1.23.1-1Dan Walsh 1.22-1Dan Walsh 1.21.13-1Dan Walsh 1.21.12-1Dan Walsh 1.21.11-2Dan Walsh 1.21.11-1Dan Walsh 1.21.10-3Dan Walsh 1.21.10-1Dan Walsh 1.21.9-2Dan Walsh 1.21.9-1Dan Walsh 1.21.8-1Dan Walsh 1.21.7-1Dan Walsh 1.21.5-1Dan Walsh 1.21.4-1Dan Walsh 1.21.2-1Dan Walsh 1.21.1-3Dan Walsh 1.21.1-2Dan Walsh 1.21.1-1Dan Walsh 1.20.1-3Dan Walsh 1.20.1-2Dan Walsh 1.20.1-1Dan Walsh 1.19.4-1Dan Walsh 1.19.3-3Dan Walsh 1.19.3-2Dan Walsh 1.19.3-1Dan Walsh 1.19.2-1Dan Walsh 1.19.1-6Dan Walsh 1.19.1-4Dan Walsh 1.19.1-2Dan Walsh 1.19.1-1Steve Grubb 1.18.1-5Dan Walsh 1.18.1-4Dan Walsh 1.18.1-3Steve Grubb 1.18.1-2Dan Walsh 1.18.1-1Steve Grubb 1.17.15-2Steve Grubb 1.17.15-2Dan Walsh 1.17.15-1Dan Walsh 1.17.14-1Dan Walsh 1.17.13-3Dan Walsh 1.17.13-2Dan Walsh 1.17.13-1Dan Walsh 1.17.12-2Dan Walsh 1.17.12-1Dan Walsh 1.17.11-1Dan Walsh 1.17.10-1Dan Walsh 1.17.9-2Dan Walsh 1.17.9-1Dan Walsh 1.17.8-2Dan Walsh 1.17.8-1Dan Walsh 1.17.7-1Dan Walsh 1.17.6-1Dan Walsh 1.17.5-1Dan Walsh 1.17.4-1Dan Walsh 1.17.3-1Dan Walsh 1.17.2-1Dan Walsh 1.17.1-1Dan Walsh 1.16.1-1Colin Walters 1.16-1Dan Walsh 1.15.7-1Dan Walsh 1.15.6-1Dan Walsh 1.15.5-1Dan Walsh 1.15.4-1Dan Walsh 1.15.3-2Dan Walsh 1.15.3-1Dan Walsh 1.15.2-1Dan Walsh 1.15.1-3Dan Walsh 1.15.1-2Dan Walsh 1.15.1-1Dan Walsh 1.14.1-1Dan Walsh 1.13.4-1Elliot Lee Dan Walsh 1.13.3-2Dan Walsh 1.13.2-1Dan Walsh 1.13.1-1Dan Walsh 1.12-2Dan Walsh 1.12-1Dan Walsh 1.11.4-1Dan Walsh 1.11.3-1Dan Walsh 1.11.2-1Dan Walsh 1.11-4Dan Walsh 1.11-3Dan Walsh 1.11-2Dan Walsh 1.11-1Dan Walsh 1.10-2Dan Walsh 1.10-1Dan Walsh 1.9-1Dan Walsh 1.8-1Dan Walsh 1.6-6Dan Walsh 1.6-5Dan Walsh 1.6-4Dan Walsh 1.6-3Dan Walsh 1.6-2Elliot Lee Dan Walsh 1.4-11Elliot Lee Dan Walsh 1.4-9Dan Walsh 1.4-8Dan Walsh 1.4-7Dan Walsh 1.4-6Dan Walsh 1.4-5Dan Walsh 1.4-4Dan Walsh 1.4-3Dan Walsh 1.4-2Dan Walsh 1.4-1Dan Walsh 1.3-2Dan Walsh 1.3-1Dan Walsh 1.2-9Dan Walsh 1.2-8Dan Walsh 1.2-7Dan Walsh 1.2-6Dan Walsh 1.2-5Dan Walsh 1.2-4Dan Walsh 1.2-3Dan Walsh 1.2-2Dan Walsh 1.2-1Dan Walsh 1.0-1- restorecon: Fix memory leak - xattr_value (#2137965)- Restorecon: Ignore missing directories when -i is used (#2137965)- Describe fcontext regular expressions (#1904059) - Strip spaces before values in config (#2012145)- Deprecate security_compute_user(), update man pages (#1879368)- Eliminate use of security_compute_user() (#1879368)- Fix mcstrans secolor examples in secolor.conf man page (#1770270)- Use Python distutils to install SELinux python bindings (#1719771) - Move sefcontext_compile to -utils package (#1612518)- SELinux userspace 2.9 release- Fix RESOURCE_LEAK coverity scan defects- selinux_restorecon: Skip customized files also without -v - man pages fixes- Build libselinux-python when %with_python2 macro is set to non-zero value- Build libselinux-ruby (#1581322)- Don't build the Python 2 subpackage (#1567358)- SELinux userspace 2.8 release- SELinux userspace 2.8-rc3 release candidate- SELinux userspace 2.8-rc2 release candidate- SELinux userspace 2.8-rc1 release candidate- Do not build libselinux-ruby- build: Replace PYSITEDIR with PYTHONLIBDIR- Correct manpages regarding removable_context - build: follow standard semantics for DESTDIR and PREFIX- Escape macros in %changelog- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild- Switch to %ldconfig_scriptlets- Update Python 2 dependency declarations to new packaging standards (See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)- F-28: rebuild for ruby25- Rebuild with libsepol-2.7-3- Drop golang bindings - Add support for pcre2 to pkgconfig definition- Enable the python3 subpackages on EL- Also add Provides for the old name without %_isa- Python 2 binary package renamed to python2-libselinux See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3 - Python 3 binary package renamed to python3-libselinux- Update to upstream release 2017-08-04- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild- Rebuild with binutils fix for ppc64le (#1475636)- Always unmount selinuxfs for SELINUX=disabled- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- Don't finalize mount state in selinux_set_policy_root() - Follow upstream and rename _selinux.so to _selinux.cpython-36m-x86_64-linux-gnu.so- Fix setfiles progress indicator- Fix segfault in selinux_restorecon_sb() (#1433577) - Change matchpathcon usage to match with matchpathcon manpage - Fix a corner case getsebool return value- Fix 'semanage boolean -m' to modify active value- Fix FTBFS - fatal error (#1427902)- Update to upstream release 2016-10-14- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Changes/Ruby_2.4- Rewrite restorecon() python method- Rebuild for Python 3.6- Fix pointer handling in realpath_not_final (#1376598)- Fix -Wsign-compare warnings - Drop unused stdio_ext.h header file - Kill logging check for selinux_enabled() - Drop usage of _D_ALLOC_NAMLEN - Add openrc_contexts functions - Fix redefinition of XATTR_NAME_SELINUX - Correct error path to always try text - Clean up process_file() - Handle NULL pcre study data - Fix in tree compilation of utils that depend on libsepol- Rebuilt with libsepol-2.5-9- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- Clarify is_selinux_mls_enabled() description - Explain how to free policy type from selinux_getpolicytype() - Compare absolute pathname in matchpathcon -V - Add selinux_snapperd_contexts_path()- Move _selinux.so to /usr/lib64/python*/site-packages- Modify audit2why analyze function to use loaded policy - Sort object files for deterministic linking order - Respect CC and PKG_CONFIG environment variable - Avoid mounting /proc outside of selinux_init_load_policy()- Fix multiple spelling errors- Rebuilt with libsepol-2.5-5- Fix typo in sefcontext_compile.8- Fix location of selinuxfs mount point - Only mount /proc if necessary - procattr: return einval for <= 0 pid args - procattr: return error on invalid pid_t input- Use fully versioned arch-specific requires- Update to upstream release 2016-02-23- Update to upstream rc1 release 2016-01-07- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Changes/Ruby_2.3- Build libselinux without rpm_execcon() (#1284019)- Rebuilt for Python3.5 rebuild- Flush the class/perm string mapping cache on policy reload (#1264051) - Fix restorecon when path has no context- Simplify procattr cache (#1257157,#1232371)- Export ldflags into the build so hardening works- Update to 2.4 release- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- is_selinux_enabled: Add /etc/selinux/config test (#1219045) - matchpathcon/selabel_file: Fix man pages (#1219718)- revert support for policy compressed with xv (#1185266)- selinux.py - use os.walk() instead of os.path.walk() (#1195004) - is_selinux_enabled(): drop no-policy-loaded test (#1195074) - fix -Wformat errors and remove deprecated mudflap option- bump release and rebuild so that koji-shadow can rebuild it against new gcc on secondary arch- Rebuilt for https://fedoraproject.org/wiki/Changes/Ruby_2.2- Compiled file context files and the original should have the same permissions from dwalsh@redhat.com - Add selinux_openssh_contexts_path() to get a path to /contexts/openssh_contexts- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- Rebuilt for https://fedoraproject.org/wiki/Changes/Python_3.4- Update to upstream * Get rid of security_context_t and fix const declarations. * Refactor rpm_execcon() into a new setexecfilecon() from Guillem Jover.- Add selinux_openssh_contexts_path()- Rebuilt for https://fedoraproject.org/wiki/Changes/Ruby_2.1- Fix spelling mistake in man page- More go bindings - restorecon, getpidcon, setexeccon- Add additional go bindings for get*con calls - Add go bindings test command - Modify man pages of set*con calls to mention that they are thread specific- Move selinux.go to /usr/lib64/golang/src/pkg/github.com/selinux/selinux.go - Add Int_to_mcs function to generate MCS labels from integers.- Add ghost flag for /var/run/setrans- Update to upstream * Fix userspace AVC handling of per-domain permissive mode. - Verify context is not null when passed into *setfilecon_raw- revert unexplained change to rhat.patch which broke SELinux disablement- Verify context is not null when passed into lsetfilecon_raw- Mv selinux.go to /usr/share/gocode/src/selinux- Add golang support to selinux.- Remove togglesebool man page- Update to upstream * Remove -lpthread from pkg-config file; it is not required. - Add support for policy compressed with xv- Update to upstream * Fix avc_has_perm() returns -1 even when SELinux is in permissive mode. * Support overriding Makefile RANLIB from Sven Vermeulen. * Update pkgconfig definition from Sven Vermeulen. * Mount sysfs before trying to mount selinuxfs from Sven Vermeulen. * Fix man pages from Laurent Bigonville. * Support overriding PATH and LIBBASE in Makefiles from Laurent Bigonville. * Fix LDFLAGS usage from Laurent Bigonville * Avoid shadowing stat in load_mmap from Joe MacDonald. * Support building on older PCRE libraries from Joe MacDonald. * Fix handling of temporary file in sefcontext_compile from Dan Walsh. * Fix procattr cache from Dan Walsh. * Define python constants for getenforce result from Dan Walsh. * Fix label substitution handling of / from Dan Walsh. * Add selinux_current_policy_path from Dan Walsh. * Change get_context_list to only return good matches from Dan Walsh. * Support udev-197 and higher from Sven Vermeulen and Dan Walsh. * Add support for local substitutions from Dan Walsh. * Change setfilecon to not return ENOSUP if context is already correct from Dan Walsh. * Python wrapper leak fixes from Dan Walsh. * Export SELINUX_TRANS_DIR definition in selinux.h from Dan Walsh. * Add selinux_systemd_contexts_path from Dan Walsh. * Add selinux_set_policy_root from Dan Walsh. * Add man page for sefcontext_compile from Dan Walsh.- Add systemd_contexts support - Do substitutions on a local sub followed by a dist sub- Eliminate requirement on pthread library, by applying patch for Jakub Jelinek Resolves #1013801- Fix handling of libselinux getconlist with only one entry- Add Python constants for SELinux enforcing modes- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Add sefcontext_compile.8 man page - Add Russell Coker patch to fix man pages - Add patches from Laurent Bigonville to fix Makefiles for debian. - modify spec file to use %{_prefix}/lib- Fix patch that Handles substitutions for /- Handle substitutions for / - semanage fcontext -a -e / /opt/rh/devtoolset-2/root- Add Eric Paris patch to fix procattr calls after a fork.- Move secolor.conf.5 into mcstrans package and out of libselinux- Fix python bindings for selinux_check_access- Fix reseting the policy root in matchpathcon- Cleanup setfcontext_compile atomic patch - Add matchpathcon -P /etc/selinux/mls support by allowing users to set alternate root - Make sure we set exit codes from selinux_label calls to ENOENT or SUCCESS- Make setfcontext_compile atomic- Fix memory leak in set*con calls.- Move matchpathcon to -utils package - Remove togglesebool- Fix selinux man page to reflect what current selinux policy is.- Add new constant SETRANS_DIR which points to the directory where mstransd can find the socket and libvirt can write its translations files.- Bring back selinux_current_policy_path- Revert some changes which are causing the wrong policy version file to be created- Update to upstream * audit2why: make sure path is nul terminated * utils: new file context regex compiler * label_file: use precompiled filecontext when possible * do not leak mmapfd * sefcontontext_compile: Add error handling to help debug problems in libsemanage. * man: make selinux.8 mention service man pages * audit2why: Fix segfault if finish() called twice * audit2why: do not leak on multiple init() calls * mode_to_security_class: interface to translate a mode_t in to a security class * audit2why: Cleanup audit2why analysys function * man: Fix program synopsis and function prototypes in man pages * man: Fix man pages formatting * man: Fix typo in man page * man: Add references and man page links to _raw function variants * Use ENOTSUP instead of EOPNOTSUPP for getfilecon functions * man: context_new(3): fix the return value description * selinux_status_open: handle error from sysconf * selinux_status_open: do not leak statusfd on exec * Fix errors found by coverity * Change boooleans.subs to booleans.subs_dist. * optimize set*con functions * pkg-config do not specifc ruby version * unmap file contexts on selabel_close() * do not leak file contexts with mmap'd backend * sefcontext_compile: do not leak fd on error * matchmediacon: do not leak fd * src/label_android_property: do not leak fd on error- Update to latest patches from eparis/Upstream- Update to latest patches from eparis/Upstream- Try procatt speedup patch again- Roll back procattr speedups since it seems to be screwing up systemd labeling.- Fix tid handling for setfscreatecon, old patch still broken in libvirt- Fix tid handling for setfscreatecon, old patch still broken in libvirt- setfscreatecon after fork was broken by the Set*con patch. - We needed to reset the thread variables after a fork.- Fix setfscreatecon call to handle failure mode, which was breaking udev- Ondrej Oprala patch to optimize set*con functions - Set*con now caches the security context and only re-sets it if it changes.- Rebuild against latest libsepol- Update to latest patches from eparis/Upstream - Fix errors found by coverity - set the sepol_compute_av_reason_buffer flag to 0. This means calculate denials only? - audit2why: remove a useless policy vers variable - audit2why: use the new constraint information- Rebuild with latest libsepol- Return EPERM if login program can not reach default label for user - Attempt to return container info from audit2why- Apply patch from eparis to fix leaked file descriptor in new labeling code- Add new function mode_to_security_class which takes mode instead of a string. - Possibly will be used with coreutils.- Add back selinuxconlist and selinuxdefcon man pages- Fix segfault from calling audit2why.finish() multiple times- Fix up selinux man page to reference service man pages- Rebuild with fixed libsepol- Update to upstream * Add support for lxc_contexts_path * utils: add service to getdefaultcon * libsemanage: do not set soname needlessly * libsemanage: remove PYTHONLIBDIR and ruby equivalent * boolean name equivalency * getsebool: support boolean name substitution * Add man page for new selinux_boolean_sub function. * expose selinux_boolean_sub * matchpathcon: add -m option to force file type check * utils: avcstat: clear sa_mask set * seusers: Check for strchr failure * booleans: initialize pointer to silence coveriety * stop messages when SELinux disabled * label_file: use PCRE instead of glibc regex functions * label_file: remove all typedefs * label_file: move definitions to include file * label_file: do string to mode_t conversion in a helper function * label_file: move error reporting back into caller * label_file: move stem/spec handling to header * label_file: drop useless ncomp field from label_file data * label_file: move spec_hasMetaChars to header * label_file: fix potential read past buffer in spec_hasMetaChars * label_file: move regex sorting to the header * label_file: add accessors for the pcre extra data * label_file: only run regex files one time * label_file: new process_file function * label_file: break up find_stem_from_spec * label_file: struct reorg * label_file: only run array once when sorting * Ensure that we only close the selinux netlink socket once. * improve the file_contexts.5 manual page- rebuild for https://fedoraproject.org/wiki/Features/Python_3.3- make with_python3 be conditional on fedora- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Move the tmpfiles.d content from /etc/tmpfiles.d to /usr/lib/tmpfiles.d- Revert Eric Paris Patch for selinux_binary_policy_path- Update to upstream * Fortify source now requires all code to be compiled with -O flag * asprintf return code must be checked * avc_netlink_recieve handle EINTR * audit2why: silence -Wmissing-prototypes warning * libsemanage: remove build warning when build swig c files * matchpathcon: bad handling of symlinks in / * seusers: remove unused lineno * seusers: getseuser: gracefully handle NULL service * New Android property labeling backend * label_android_property whitespace cleanups * additional makefile support for rubywrap- Fix booleans.subs name, change function name to selinux_boolean_sub, add man page, minor fixes to the function- Fix to compile with Fortify source * Add -O compiler flag * Check return code from asprintf - Fix handling of symbolic links in / by realpath_not_final- Add support for lxc contexts file- Add support fot boolean subs file- Update to upstream * Fix dead links to www.nsa.gov/selinux * Remove jump over variable declaration * Fix old style function definitions * Fix const-correctness * Remove unused flush_class_cache method * Add prototype decl for destructor * Add more printf format annotations * Add printf format attribute annotation to die() method * Fix const-ness of parameters & make usage() methods static * Enable many more gcc warnings for libselinux/src/ builds * utils: Enable many more gcc warnings for libselinux/utils builds * Change annotation on include/selinux/avc.h to avoid upsetting SWIG * Ensure there is a prototype for 'matchpathcon_lib_destructor' * Update Makefiles to handle /usrmove * utils: Stop separating out matchpathcon as something special * pkg-config to figure out where ruby include files are located * build with either ruby 1.9 or ruby 1.8 * assert if avc_init() not called * take security_deny_unknown into account * security_compute_create_name(3) * Do not link against python library, this is considered * bad practice in debian * Hide unnecessarily-exported library destructors- Add selinux_current_policy_path to return /sys/fs/selinux/policy if it exists - Otherwise search for policy on disk- Change selinux_binary_policy_path to return /sys/fs/selinux/policy - Add selinux_installed_policy_path to return what selinux_binary_policy_path used to return - avc_has_perm will now return yes if the machine is in permissive mode - Make work with ruby-1.9- avc_netlink_recieve should continue to poll if it receinves an EINTR rather- use /sbin/ldconfig, glibc does not provide /usr/sbin/ldconfig in the RPM database for now- Rebuild with cleaned up upstream to work in /usr- install everything in /usr https://fedoraproject.org/wiki/Features/UsrMove- Add Dan Berrange code cleanup patches.- Fix selabal_open man page to refer to proper selinux_opt structure-Update to upstream * Fix setenforce man page to refer to selinux man page * Cleanup Man pages * merge freecon with getcon man page- Add patch from Richard Haines When selabel_lookup found an invalid context with validation enabled, it always stated it was 'file_contexts' whether media, x, db or file. The fix is to store the spec file name in the selabel_lookup_rec on selabel_open and use this as output for logs. Also a minor fix if key is NULL to stop seg faults. - Fix setenforce manage page.- Rebuild with new libsepol- Fix setenforce man page, from Miroslav Grepl- Upgrade to upstream * selinuxswig_python.i: don't make syscall if it won't change anything * Remove assert in security_get_boolean_names(3) * Mapped compute functions now obey deny_unknown flag * get_default_type now sets EINVAL if no entry. * return EINVAL if invalid role selected * Updated selabel_file(5) man page * Updated selabel_db(5) man page * Updated selabel_media(5) man page * Updated selabel_x(5) man page * Add man/man5 man pages * Add man/man5 man pages * Add man/man5 man pages * use -W and -Werror in utils- Change python binding for restorecon to check if the context matches. - If it does do not reset- Upgrade to upstream * Makefiles: syntax, convert all ${VAR} to $(VAR) * load_policy: handle selinux=0 and /sys/fs/selinux not exist * regenerate .pc on VERSION change * label: cosmetic cleanups * simple interface for access checks * Don't reinitialize avc_init if it has been called previously * seusers: fix to handle large sets of groups * audit2why: close fd on enomem * rename and export symlink_realpath * label_file: style changes to make Eric happy.- Apply libselinux patch to handle large groups in seusers.- Add selinux_check_access function. Needed for passwd, chfn, chsh- Handle situation where selinux=0 passed to the kernel and both /selinux and-Update to upstream * utils: matchpathcon: remove duplicate declaration * src: matchpathcon: use myprintf not fprintf * src: matchpathcon: make sure resolved path starts * put libselinux.so.1 in /lib not /usr/lib * tree: default make target to all not- Switch to use ":" as prefix separator rather then ";"- Avoid unnecessary shell invocation in %post.- Fix handling of subset labeling that is causing segfault in restorecon- Change matchpathcon_init_prefix and selabel_open to allow multiple initial prefixes. Now you can specify a ";" separated list of prefixes and the labeling system will only load regular expressions that match these prefixes.- Change matchpatcon to use proper myprintf - Fix symlink_realpath to always include "/" - Update to upstream * selinux_file_context_verify function returns wrong value. * move realpath helper to matchpathcon library * python wrapper makefile changes- Move to new Makefile that can build with or without PYTHON being set-Update to upstream 2.1.4 2011-0817 * mapping fix for invalid class/perms after selinux_set_mapping * audit2why: work around python bug not defining * resolv symlinks and dot directories before matching 2.1.2 2011-0803 * audit2allow: do not print statistics * make python bindings for restorecon work on relative path * fix python audit2why binding error * support new python3 functions * do not check fcontext duplicates on use * Patch for python3 for libselinux 2.1.1 2011-08-02 * move .gitignore into utils * new setexecon utility * selabel_open fix processing of substitution files * mountpoint changing patch. * simplify SRCS in Makefile 2.1.1 2011-08-01 * Remove generated files, introduce more .gitignore-Update to upstream * Release, minor version bump * Give correct names to mount points in load_policy by Dan Walsh. * Make sure selinux state is reported correctly if selinux is disabled or fails to load by Dan Walsh. * Fix crash if selinux_key_create was never called by Dan Walsh. * Add new file_context.subs_dist for distro specific filecon substitutions by Dan Walsh. * Update man pages for selinux_color_* functions by Richard Haines.- Only call dups check within selabel/matchpathcon if you are validating the context - This seems to speed the loading of labels by 4 times.- Move /selinux to /sys/fs/selinux - Add selinuxexeccon - Add realpath to matchpathcon to handle matchpathcon * type queries.- Update for latest libsepol- Update for latest libsepol- Fix restorecon python binding to accept relative paths-Update to upstream * Give correct names to mount points in load_policy by Dan Walsh. * Make sure selinux state is reported correctly if selinux is disabled or fails to load by Dan Walsh. * Fix crash if selinux_key_create was never called by Dan Walsh. * Add new file_context.subs_dist for distro specific filecon substitutions by Dan Walsh. * Update man pages for selinux_color_* functions by Richard Haines.- Clean up patch to make handling of constructor cleanup more portable * db_language object class support for selabel_lookup from KaiGai Kohei. * Library destructors for thread local storage keys from Eamon Walsh.- Add distribution subs pathAdd patch from dbhole@redhat.com to initialize thread keys to -1 Errors were being seen in libpthread/libdl that were related to corrupt thread specific keys. Global destructors that are called on dl unload. During destruction delete a thread specific key without checking if it has been initialized. Since the constructor is not called each time (i.e. key is not initialized with pthread_key_create each time), and the default is 0, there is a possibility that key 0 for an active thread gets deleted. This is exactly what is happening in case of OpenJDK. Workaround patch that initializes the key to -1. Thus if the constructor is not called, the destructor tries to delete key -1 which is deemed invalid by pthread_key_delete, and is ignored.- Call fini_selinuxmnt if selinux is disabled, to cause is_selinux_disabled() to report correct data- Change mount source options to use "proc" and "selinuxfs"- Update to upstream * Turn off default user handling when computing user contexts by Dan Walsh- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fixup selinux man page- Fix Makefile to use pkg-config --cflags python3 to discover include paths- Update to upstream - Turn off fallback in to SELINUX_DEFAULTUSER in get_context_list- Update to upstream * Thread local storage fixes from Eamon Walsh.- Add /etc/tmpfiles.d support for /var/run/setrans- Ghost /var/run/setrans- Rebuilt for gcc bug 634757- rebuild via updated swig (#624674)- Update for python 3.2a1- Turn off fallback in to SELINUX_DEFAULTUSER in get_context_list- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- Turn off messages in audit2why- Update to upstream * Add const qualifiers to public API where appropriate by KaiGai Kohei. 2.0.95 2010-06-10 * Remove duplicate slashes in paths in selabel_lookup from Chad Sellers * Adds a chcon method to the libselinux python bindings from Steve Lawrence - add python3 subpackage from David Malcolm* Set errno=EINVAL for invalid contexts from Dan Walsh.- Update to upstream * Show strerror for security_getenforce() by Colin Waters. * Merged selabel database support by KaiGai Kohei. * Modify netlink socket blocking code by KaiGai Kohei.- Update to upstream * Fix from Eric Paris to fix leak on non-selinux systems. * regenerate swig wrappers * pkgconfig fix to respect LIBDIR from Dan Walsh.- Update to upstream * Change the AVC to only audit the permissions specified by the policy, excluding any permissions specified via dontaudit or not specified via auditallow. * Fix compilation of label_file.c with latest glibc headers.- Fix potential doublefree on init- Fix libselinux.pc- Fix man page for selinuxdefcon- Free memory on disabled selinux boxes- Update to upstream * add/reformat man pages by Guido Trentalancia . * Change exception.sh to be called with bash by Manoj Srivastava - Fix selinuxdefcon man page- Update to upstream * Add pkgconfig file from Eamon Walsh.- Update to upstream * Rename and export selinux_reset_config()- Update to upstream * Add exception handling in libselinux from Dan Walsh. This uses a shell script called exception.sh to generate a swig interface file. * make swigify * Make matchpathcon print <> if path not found in fcontext file.- Eliminate -pthread switch in Makefile- Update to upstream * Removal of reference counting on userspace AVC SID's.- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Update to upstream * Reverted Tomas Mraz's fix for freeing thread local storage to avoid pthread dependency. * Removed fini_context_translations() altogether. * Merged lazy init patch from Stephen Smalley based on original patch by Steve Grubb.- Update to upstream * Add per-service seuser support from Dan Walsh. * Let load_policy gracefully handle selinuxfs being mounted from Stephen Smalley. * Check /proc/filesystems before /proc/mounts for selinuxfs from Eric Paris.- Add provices ruby(selinux)- Update to upstream * Fix improper use of thread local storage from Tomas Mraz . * Label substitution support from Dan Walsh. * Support for labeling virtual machine images from Dan Walsh.- Update to upstream * Trim / from the end of input paths to matchpathcon from Dan Walsh. * Fix leak in process_line in label_file.c from Hiroshi Shinji. * Move matchpathcon to /sbin, add matchpathcon to clean target from Dan Walsh. * getdefaultcon to print just the correct match and add verbose option from Dan Walsh.- Update to upstream * deny_unknown wrapper function from KaiGai Kohei. * security_compute_av_flags API from KaiGai Kohei. * Netlink socket management and callbacks from KaiGai Kohei.- Fix Memory Leak- Fix crash in python- Add back in additional interfaces- Add back in av_decision to python swig- Update to upstream * Netlink socket handoff patch from Adam Jackson. * AVC caching of compute_create results by Eric Paris.- Add patch from ajax to accellerate X SELinux - Update eparis patch- Add eparis patch to accellerate Xwindows performance- Fix URL- Add substitute pattern - matchpathcon output <> on ENOENT- Update to upstream * Fix incorrect conversion in discover_class code.- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- Add - selinux_virtual_domain_context_path - selinux_virtual_image_context_path- Throw exeptions in python swig bindings on failures- Fix restorecon python code- Update to upstream- Strip trailing / for matchpathcon- Fix segfault if seusers file does not work- Add new function getseuser which will take username and service and return - seuser and level. ipa will populate file in future. - Change selinuxdefcon to return just the context by default- Rebuild for Python 2.6- Update to Upstream * Allow shell-style wildcards in x_contexts file.- Eamon Walsh Patch - libselinux: allow shell-style wildcarding in X names - Add Restorecon/Install python functions from Luke Macken- Update to Upstream * Correct message types in AVC log messages. * Make matchpathcon -V pass mode from Dan Walsh. * Add man page for selinux_file_context_cmp from Dan Walsh.- Update to Upstream * New man pages from Dan Walsh. * Update flask headers from refpolicy trunk from Dan Walsh.- Fix matchpathcon -V call- Add flask definitions for open, X and nlmsg_tty_audit- Add missing get/setkeycreatecon man pages- Split out utilities- Add missing man page links for [lf]getfilecon- Update to Upstream * Add group support to seusers using %groupname syntax from Dan Walsh. * Mark setrans socket close-on-exec from Stephen Smalley. * Only apply nodups checking to base file contexts from Stephen Smalley.- Update to Upstream * Merge ruby bindings from Dan Walsh. - Add support for Linux groups to getseuserbyname- Allow group handling in getseuser call- Update to Upstream * Handle duplicate file context regexes as a fatal error from Stephen Smalley. This prevents adding them via semanage. * Fix audit2why shadowed variables from Stephen Smalley. * Note that freecon NULL is legal in man page from Karel Zak.- Add ruby support for puppet- Rebuild for new libsepol- Add Karel Zak patch for freecon man page- Update to Upstream * New and revised AVC, label, and mapping man pages from Eamon Walsh. * Add swig python bindings for avc interfaces from Dan Walsh.- Update to Upstream * Fix selinux_file_context_verify() and selinux_lsetfilecon_default() to call matchpathcon_init_prefix if not already initialized. * Add -q qualifier for -V option of matchpathcon and change it to indicate whether verification succeeded or failed via exit status.- libselinux no longer neets to telnet -u in post install- Add sedefaultcon and setconlist commands to dump login context- Update to Upstream * Fixed selinux_set_callback man page. * Try loading the max of the kernel-supported version and the libsepol-supported version when no manipulation of the binary policy is needed from Stephen Smalley. * Fix memory leaks in matchpathcon from Eamon Walsh.- Add Xavior Toth patch for security_id_t in swig- Add avc.h to swig code- Grab the latest policy for the kernel- Update to Upstream * Man page typo fix from Jim Meyering.- Update to Upstream * Changed selinux_init_load_policy() to not warn about a failed mount of selinuxfs if selinux was disabled in the kernel.- Fix matchpathcon memory leak- Update to Upstream * Merged new X label "poly_selection" namespace from Eamon Walsh.- Update to Upstream * Merged reset_selinux_config() for load policy from Dan Walsh.- Reload library on loading of policy to handle chroot- Update to Upstream * Merged avc_has_perm() errno fix from Eamon Walsh.- Update to Upstream * Regenerated Flask headers from refpolicy flask definitions.- Update to Upstream * Merged compute_member AVC function and manpages from Eamon Walsh. * Provide more error reporting on load policy failures from Stephen Smalley.- Update to Upstream * Merged new X label "poly_prop" namespace from Eamon Walsh.- Update to Upstream * Disable setlocaldefs if no local boolean or users files are present from Stephen Smalley. * Skip userspace preservebools processing for Linux >= 2.6.22 from Stephen Smalley.- Update to Upstream * Merged fix for audit2why from Dan Walsh.- Fix audit2why to grab latest policy versus the one selected by the kernel* Merged audit2why python binding from Dan Walsh.* Merged updated swig bindings from Dan Walsh, including typemap for pid_t.- Update to use libsepol-static library- Move libselinux.a to -static package - Spec cleanups- Put back libselinux.a- Fix memory references in audit2why and change to use tuples - Update to Upstream * Fix for the avc: granted null message bug from Stephen Smalley.- Fix __init__.py specification- Add audit2why python bindings- Add pid_t typemap for swig bindings- smp_mflag- Fix spec file caused by spec review- Upgrade to upstream * matchpathcon(8) man page update from Dan Walsh.- Upgrade to upstream * dlopen libsepol.so.1 rather than libsepol.so from Stephen Smalley. * Based on a suggestion from Ulrich Drepper, defer regex compilation until we have a stem match, by Stephen Smalley. * A further optimization would be to defer regex compilation until we have a complete match of the constant prefix of the regex - TBD.- Upgrade to upstream * Regenerated Flask headers from policy.- Upgrade to upstream * AVC enforcing mode override patch from Eamon Walsh. * Aligned attributes in AVC netlink code from Eamon Walsh. - Move libselinux.so back into devel package, procps has been fixed- Upgrade to upstream * Merged refactored AVC netlink code from Eamon Walsh. * Merged new X label namespaces from Eamon Walsh. * Bux fix and minor refactoring in string representation code.- Upgrade to upstream * Merged selinux_get_callback, avc_open, empty string mapping from Eamon Walsh.- Upgrade to upstream * Fix segfault resulting from missing file_contexts file.- Fix segfault on missing file_context file- Upgrade to upstream * Make netlink socket close-on-exec to avoid descriptor leakage from Dan Walsh. * Pass CFLAGS when using gcc for linking from Dennis Gilmore.- Add sparc patch to from Dennis Gilmore to build on Sparc platform- Remove leaked file descriptor- Upgrade to latest from NSA * Fix selabel option flag setting for 64-bit from Stephen Smalley.- Change matchpatcon to use syslog instead of syserror- Upgrade to latest from NSA * Re-map a getxattr return value of 0 to a getfilecon return value of -1 with errno EOPNOTSUPP from Stephen Smalley. * Fall back to the compat code for security_class_to_string and security_av_perm_to_string from Stephen Smalley. * Fix swig binding for rpm_execcon from James Athey.- Apply James Athway patch to fix rpm_execcon python binding- Move libselinux.so back into main package, breaks procps- Upgrade to upstream * Fix file_contexts.homedirs path from Todd Miller.- Remove requirement on setransd, Moved to selinux-policy-mls- Move libselinux.so into devel package - Upgrade to upstream * Fix segfault resulting from uninitialized print-callback pointer. * Added x_contexts path function patch from Eamon Walsh. * Fix build for EMBEDDED=y from Yuichi Nakamura. * Fix markup problems in selinux man pages from Dan Walsh.- Upgrade to upstream * Updated version for stable branch. * Added x_contexts path function patch from Eamon Walsh. * Fix build for EMBEDDED=y from Yuichi Nakamura. * Fix markup problems in selinux man pages from Dan Walsh. * Updated av_permissions.h and flask.h to include new nscd permissions from Dan Walsh. * Added swigify to top-level Makefile from Dan Walsh. * Fix for string_to_security_class segfault on x86_64 from Stephen Smalley.- Apply Steven Smalley patch to fix segfault in string_to_security_class- Fix matchpathcon to set default myprintf- Upgrade to upstream * Fix for getfilecon() for zero-length contexts from Stephen Smalley.- Update to match flask/access_vectors in policy- Fix man page markup lanquage for translations- Fix semanage segfault on x86 platform- Upgrade to upstream * Labeling and callback interface patches from Eamon Walsh.- Refactored swig- Upgrade to upstream * Class and permission mapping support patches from Eamon Walsh. * Object class discovery support patches from Chris PeBenito. * Refactoring and errno support in string representation code.- Upgrade to upstream - Merged patch to reduce size of libselinux and remove need for libsepol for embedded systems from Yuichi Nakamura. This patch also turns the link-time dependency on libsepol into a runtime (dlopen) dependency even in the non-embedded case. 2.0.17 2007-05-31 * Updated Lindent script and reindented two header files.- Upgrade to upstream * Merged additional swig python bindings from Dan Walsh. * Merged helpful message when selinuxfs mount fails patch from Dax Kelson.- Upgrade to upstream * Merged build fix for avc_internal.c from Joshua Brindle.- Add get_context_list funcitions to swig file- Upgrade to upstream * Merged rpm_execcon python binding fix, matchpathcon man page fix, and getsebool -a handling for EACCES from Dan Walsh.- Add missing interface- Upgrade to upstream * Merged support for getting initial contexts from James Carter.- Upgrade to upstream * Merged userspace AVC patch to follow kernel's behavior for permissive mode in caching previous denials from Eamon Walsh. * Merged sidput(NULL) patch from Eamon Walsh.- Make rpm_exec swig work- Upgrade to upstream * Merged class/av string conversion and avc_compute_create patch from Eamon Walsh.- Upgrade to upstream * Merged fix for avc.h #include's from Eamon Walsh.- Add stdint.h to avc.h- Merged patch to drop support for CACHETRANS=0 config option from Steve Grubb. - Merged patch to drop support for old /etc/sysconfig/selinux and - /etc/security policy file layout from Steve Grubb.- Do not fail on permission denied in getsebool- Upgrade to upstream * Merged init_selinuxmnt() and is_selinux_enabled() improvements from Steve Grubb.- Upgrade to upstream * Removed sending of setrans init message. * Merged matchpathcon memory leak fix from Steve Grubb.- Upgrade to upstream * Merged more swig initializers from Dan Walsh.- Upgrade to upstream * Merged patch from Todd Miller to convert int types over to C99 style.- Merged patch from Todd Miller to remove sscanf in matchpathcon.c because of the use of the non-standard format (original patch changed for style). - Merged patch from Todd Miller to fix memory leak in matchpathcon.c.- Add context function to python to split context into 4 parts- Upgrade to upstream * Updated version for stable branch.- Upgrade to upstream * Merged man page updates to make "apropos selinux" work from Dan Walsh.- Upgrade to upstream * Merged getdefaultcon utility from Dan Walsh.- Add Ulrich NSCD__GETSERV and NSCD__SHMEMGRP for Uli- Add reference to selinux man page in all man pages to make apropos work Resolves: # 217881- Upstream wanted some minor changes, upgrading to keep api the same - Upgrade to upstream * Merged selinux_check_securetty_context() and support from Dan Walsh. Resolves: #200110- Cleanup patch- Add securetty handling Resolves: #200110- Upgrade to upstream * Merged patch for matchpathcon utility to use file mode information when available from Dan Walsh.- rebuild against python 2.5- Fix matchpathcon to lstat files- Update man page- Upgrade to upstream- Add James Antill patch for login verification of MLS Levels - MLS ragnes need to be checked, Eg. login/cron. This patch adds infrastructure.- Upgrade to latest from NSA * Merged updated flask definitions from Darrel Goeddel. This adds the context security class, and also adds the string definitions for setsockcreate and polmatch.- Upgrade to latest from NSA * Updated version for release.- rebuilt for unwind info generation, broken in gcc-4.1.1-21- Upgrade to latest from NSA * Merged av_permissions.h update from Steve Grubb, adding setsockcreate and polmatch definitions.- really make -devel depend on libsepol-devel- Add sgrubb patch for polmatch- Upgrade to latest from NSA * Merged patch from Steve Smalley to fix SIGPIPE in setrans_client- have -devel require libsepol-devel- Upgrade to latest from NSA * Merged patch to not log avc stats upon a reset from Steve Grubb. * Applied patch to revert compat_net setting upon policy load. * Merged file context homedir and local path functions from Chris PeBenito.- rebuilt with latest binutils to pick up 64K -z commonpagesize on ppc* (#203001)- Upgrade to latest from NSA * Merged file context homedir and local path functions from Chris PeBenito. * Rework functions that access /proc/pid/attr to access the per-thread nodes, and unify the code to simplify maintenance.- Upgrade to latest from NSA * Merged return value fix for *getfilecon() from Dan Walsh. * Merged sockcreate interfaces from Eric Paris.- Fix translation return codes to return size of buffer- Upgrade to latest from NSA * Merged no-tls-direct-seg-refs patch from Jeremy Katz. * Merged netfilter_contexts support patch from Chris PeBenito.- Upgrade to latest from NSA * Merged context_*_set errno patch from Jim Meyering.- only build non-fpic objects with -mno-tls-direct-seg-refs- build with -mno-tls-direct-seg-refs on x86 to avoid triggering segfaults with xen (#200783)- Rebuild for new gcc- Fix libselinux to not telinit during installs- Upgrade to latest from NSA * Lindent. * Merged {get,set}procattrcon patch set from Eric Paris. * Merged re-base of keycreate patch originally by Michael LeMay from Eric Paris. * Regenerated Flask headers from refpolicy. * Merged patch from Dan Walsh with: - Added selinux_file_context_{cmp,verify}. - Added selinux_lsetfilecon_default. - Delay translation of contexts in matchpathcon.- Yet another change to matchpathcon- Turn off error printing in library. Need to compile with DEBUG to get it back- Fix error reporting of matchpathcon- Add function to compare file context on disk versus contexts in file_contexts file.- Upgrade to latest from NSA * Merged patch from Dan Walsh with: * Added selinux_getpolicytype() function. * Modified setrans code to skip processing if !mls_enabled. * Set errno in the !selinux_mnt case. * Allocate large buffers from the heap, not on stack. Affects is_context_customizable, selinux_init_load_policy, and selinux_getenforcemode.- Add selinux_getpolicytype()- Upgrade to latest from NSA * Merged !selinux_mnt checks from Ian Kent.- Check for selinux_mnt == NULL- Merged matchmediacon and trans_to_raw_context fixes from Serge Hallyn.- Remove getseuser- Bump requires to grab latest libsepol- Add BuildRequires for swig- Upgrade to latest from NSA * Merged simple setrans client cache from Dan Walsh. Merged avcstat patch from Russell Coker. * Modified selinux_mkload_policy() to also set /selinux/compat_net appropriately for the loaded policy.- More fixes for translation cache - Upgrade to latest from NSA * Added matchpathcon_fini() function to free memory allocated by matchpathcon_init().- Add simple cache to improve translation speed- Upgrade to latest from NSA * Merged setrans client cleanup patch from Steve Grubb.- Add Russell's AVC patch to handle large numbers- Upgrade to latest from NSA * Merged getfscreatecon man page fix from Dan Walsh. * Updated booleans(8) man page to drop references to the old booleans file and to note that setsebool can be used to set the boot-time defaults via -P.- Upgrade to latest from NSA * Merged fix warnings patch from Karl MacMillan. * Merged setrans client support from Dan Walsh. This removes use of libsetrans. * Merged patch to eliminate use of PAGE_SIZE constant from Dan Walsh. * Merged swig typemap fixes from Glauber de Oliveira Costa.- Change the way translations work, Use setransd/remove libsetrans- Add selinuxswig fixes - Stop using PAGE_SIZE and start using sysconf(_SC_PAGE_SIZE)- Upgrade to latest from NSA * Added distclean target to Makefile. * Regenerated swig files. * Changed matchpathcon_init to verify that the spec file is a regular file. * Merged python binding t_output_helper removal patch from Dan Walsh.- Fix python bindings for matchpathcon - Fix booleans man page- Merged Makefile PYLIBVER definition patch from Dan Walsh.- Make some fixes so it will build on RHEL4 - Upgrade to latest from NSA * Updated version for release. * Altered rpm_execcon fallback logic for permissive mode to also handle case where /selinux/enforce is not available.- bump again for double-long bug on ppc(64)- rebuilt for new gcc4.1 snapshot and glibc changes- Upgrade to latest from NSA * Merged install-pywrap Makefile patch from Joshua Brindle.- Upgrade to latest from NSA * Merged pywrap Makefile patch from Dan Walsh.- Split out pywrap in Makefile- Upgrade to latest from NSA * Added getseuser test program.- Upgrade to latest from NSA * Added format attribute to myprintf in matchpathcon.c and removed obsoleted rootlen variable in init_selinux_config().- Build with new libsepol- Upgrade to latest from NSA * Merged several fixes and improvements from Ulrich Drepper (Red Hat), including: - corrected use of getline - further calls to __fsetlocking for local files - use of strdupa and asprintf - proper handling of dirent in booleans code - use of -z relro - several other optimizations * Merged getpidcon python wrapper from Dan Walsh (Red Hat).- Add build requires line for libsepol-devel- Fix swig call for getpidcon- Move libselinux.so to base package- Upgrade to latest from NSA * Merged call to finish_context_translations from Dan Walsh. This eliminates a memory leak from failing to release memory allocated by libsetrans.- update to latest libsetrans - Fix potential memory leak- rebuilt- Update to never version * Merged patch for swig interfaces from Dan Walsh.- Update to never version- Fix some of the python swig objects- Update to latest from NSA * Added MATCHPATHCON_VALIDATE flag for set_matchpathcon_flags() and modified matchpathcon implementation to make context validation/ canonicalization optional at matchpathcon_init time, deferring it to a successful matchpathcon by default unless the new flag is set by the caller. * Added matchpathcon_init_prefix() interface, and reworked matchpathcon implementation to support selective loading of file contexts entries based on prefix matching between the pathname regex stems and the specified path prefix (stem must be a prefix of the specified path prefix).- Update to latest from NSA * Change getsebool to return on/off instead of active/inactive- Update to latest from NSA * Added -f file_contexts option to matchpathcon util. Fixed warning message in matchpathcon_init(). * Merged Makefile python definitions patch from Dan Walsh.- Update to latest from NSA * Merged swigify patch from Dan Walsh.- Separate out libselinux-python bindings into separate rpm- Read libsetrans requirement- Add python bindings- Update to latest from NSA * Merged make failure in rpm_execcon non-fatal in permissive mode patch from Ivan Gyurdiev.- Remove requirement for libsetrans- Update to latest from NSA * Added MATCHPATHCON_NOTRANS flag for set_matchpathcon_flags() and modified matchpathcon_init() to skip context translation if it is set by the caller.- Update to latest from NSA * Added security_canonicalize_context() interface and set_matchpathcon_canoncon() interface for obtaining canonical contexts. Changed matchpathcon internals to obtain canonical contexts by default. Provided fallback for kernels that lack extended selinuxfs context interface. - Patch to not translate mls when calling setfiles- Update to latest from NSA * Merged seusers parser changes from Ivan Gyurdiev. * Merged setsebool to libsemanage patch from Ivan Gyurdiev. * Changed seusers parser to reject empty fields.- Update to latest from NSA * Merged seusers empty level handling patch from Jonathan Kim (TCS).- Rebuild for latest libsepol- Rebuild for latest libsepol- Change default to __default__- Change default to __default__- Add selinux_translations_path- Update to latest from NSA * Merged selinux_path() and selinux_homedir_context_path() functions from Joshua Brindle.- Need to check for /sbin/telinit- Update to latest from NSA * Merged fixes for make DESTDIR= builds from Joshua Brindle.- Update to latest from NSA * Merged get_default_context_with_rolelevel and man pages from Dan Walsh (Red Hat). * Updated call to sepol_policydb_to_image for sepol changes. * Changed getseuserbyname to ignore empty lines and to handle no matching entry in the same manner as no seusers file.- Tell init to reexec itself in post script- Update to latest from NSA * Changed selinux_mkload_policy to try downgrading the latest policy version available to the kernel-supported version. * Changed selinux_mkload_policy to fall back to the maximum policy version supported by libsepol if the kernel policy version falls outside of the supported range.- Update to latest from NSA * Changed getseuserbyname to fall back to the Linux username and NULL level if seusers config file doesn't exist unless REQUIRESEUSERS=1 is set in /etc/selinux/config. * Moved seusers.conf under $SELINUXTYPE and renamed to seusers.- Update to latest from NSA * Added selinux_init_load_policy() function as an even higher level interface for the initial policy load by /sbin/init. This obsoletes the load_policy() function in the sysvinit-selinux.patch. * Added selinux_mkload_policy() function as a higher level interface for loading policy than the security_load_policy() interface.- Update to latest from NSA * Merged fix for matchpathcon (regcomp error checking) from Johan Fischer. Also added use of regerror to obtain the error string for inclusion in the error message.- Update to latest from NSA * Changed getseuserbyname to not require (and ignore if present) the MLS level in seusers.conf if MLS is disabled, setting *level to NULL in this case.- Update to latest from NSA * Merged getseuserbyname patch from Dan Walsh.- Fix patch to satisfy upstream- Update to latest from NSA - Add getseuserbyname- Fix patch call- Fix strip_con call- Go back to original libsetrans code- Eliminate forth param from mls context when mls is not enabled.- Update from NSA * Merged modified form of patch to avoid dlopen/dlclose by the static libselinux from Dan Walsh. Users of the static libselinux will not have any context translation by default.- Update from NSA * Added public functions to export context translation to users of libselinux (selinux_trans_to_raw_context, selinux_raw_to_trans_context).- Update from NSA * Remove special definition for context_range_set; use common code.- Update from NSA * Hid translation-related symbols entirely and ensured that raw functions have hidden definitions for internal use. * Allowed setting NULL via context_set* functions. * Allowed whitespace in MLS component of context. * Changed rpm_execcon to use translated functions to workaround lack of MLS level on upgraded systems.- Allow set_comp on unset ranges- Merged context translation patch, originally by TCS, with modifications by Dan Walsh (Red Hat).- Apply translation patch- Update from NSA * Merged several fixes for error handling paths in the AVC sidtab, matchpathcon, booleans, context, and get_context_list code from Serge Hallyn (IBM). Bugs found by Coverity. * Removed setupns; migrated to pam. * Merged patches to rename checkPasswdAccess() from Joshua Brindle. Original symbol is temporarily retained for compatibility until all callers are updated.- Update makefiles- Update from NSA * Merged security_setupns() from Chad Sellers. - fix selinuxenabled man page- Update from NSA * Merged avcstat and selinux man page from Dan Walsh. * Changed security_load_booleans to process booleans.local even if booleans file doesn't exist.- Fix avcstat to clear totals- Add info to man page- Update from NSA * Merged set_selinuxmnt patch from Bill Nottingham (Red Hat). * Rewrote get_ordered_context_list and helpers, including changing logic to allow variable MLS fields.- Update from NSA- Add backin matchpathcon- Fix selinux_policy_root man page- Change assert(selinux_mnt) to if (!selinux_mnt) return -1;- Update from NSA * Fixed bug in matchpathcon_filespec_destroy.- Update from NSA * Fixed bug in rpm_execcon error handling path.- Update from NSA * Merged fix for set_matchpathcon* functions from Andreas Steinmetz. * Merged fix for getconlist utility from Andreas Steinmetz.- Update from NSA- Better handling of booleans- Update from NSA * Merged destructors patch from Tomas Mraz.- Update from NSA * Added set_matchpathcon_flags() function for setting flags controlling operation of matchpathcon. MATCHPATHCON_BASEONLY means only process the base file_contexts file, not file_contexts.homedirs or file_contexts.local, and is for use by setfiles -c. * Updated matchpathcon.3 man page.- Update from NSA- Update from NSA * Fixed bug in matchpathcon_filespec_add() - failure to clear fl_head.- Update from NSA * Changed matchpathcon_common to ignore any non-format bits in the mode.- Default matchpathcon to regular files if the user specifies a mode- Update from NSA * Merged several fixes from Ulrich Drepper.- Fix matchpathcon on eof.- Update from NSA * Merged matchpathcon patch for file_contexts.homedir from Dan Walsh. * Added selinux_users_path() for path to directory containing system.users and local.users.- Process file_context.homedir- Update from NSA * Changed relabel Makefile target to use restorecon.- Update from NSA * Regenerated av_permissions.h.- Update from NSA * Modified avc_dump_av to explicitly check for any permissions that cannot be mapped to string names and display them as a hex value. * Regenerated av_permissions.h.- Update from NSA * Generalized matchpathcon internals, exported more interfaces, and moved additional code from setfiles into libselinux so that setfiles can directly use matchpathcon.- Update from NSA * Prevent overflow of spec array in matchpathcon. * Fixed several uses of internal functions to avoid relocations. * Changed rpm_execcon to check is_selinux_enabled() and fallback to a regular execve if not enabled (or unable to determine due to a lack of /proc, e.g. chroot'd environment).- Update from NSA * Merged minor fix for avcstat from Dan Walsh.- rpmexeccon should not fail in permissive mode.- fix printf in avcstat- Update from NSA- Modify matchpathcon to also process file_contexts.local if it exists- Add is_customizable_types function call- Update to latest from upstream * Just changing version number to match upstream- Update to latest from upstream * Changed matchpathcon to return -1 with errno ENOENT for <> entries, and also for an empty file_contexts configuration.- Fix link devel libraries- Fix unitialized variable in avcstat.c- Upgrade to upstream * Removed some trivial utils that were not useful or redundant. * Changed BINDIR default to /usr/sbin to match change in Fedora. * Added security_compute_member. * Added man page for setcon.- Upgrade to upstream- Add avcstat program- Add lots of missing man pages- Fix output of getsebool.- Update from upstream, fix setsebool -P segfault- Add a patch from upstream. Fixes signed/unsigned issues, and incomplete structure copy.- More fixes from sgrubb, better syslog- Have setsebool and togglesebool log changes to syslog- Add patch to make setsebool update bool on disk - Make togglesebool have a rollback capability in case it blows up inflight- Upgrade to latest from NSA- Changed the location of the utilities to /usr/sbin since normal users can't use them anyways.- Updated various utilities, removed utilities that are for testing, added man pages.- Add -g flag to make - Upgrade to latest from NSA * Added rpm_execcon.- Upgrade to latest from NSA * Merged setenforce and removable context patch from Dan Walsh. * Merged build fix for alpha from Ulrich Drepper. * Removed copyright/license from selinux_netlink.h - definitions only.- Change setenforce to accept Enforcing and Permissive- Add alpha patch- Upgrade to latest from NSA- Add selinux_removable_context_path- Update from NSA * Add matchmediacon- Update from NSA * Merged in matchmediacon changes.- Update from NSA * Regenerated headers for new nscd permissions.- Add matchmediacon- Update from NSA * Added get_default_context_with_role.- Clean up spec file * Patch from Matthias Saou- Update from NSA * Added set_matchpathcon_printf.- Update from NSA * Reworked av_inherit.h to allow easier re-use by kernel.- Add strcasecmp in selinux_config - Update from NSA * Changed avc_has_perm_noaudit to not fail on netlink errors. * Changed avc netlink code to check pid based on patch by Steve Grubb. * Merged second optimization patch from Ulrich Drepper. * Changed matchpathcon to skip invalid file_contexts entries. * Made string tables private to libselinux. * Merged strcat->stpcpy patch from Ulrich Drepper. * Merged matchpathcon man page from Dan Walsh. * Merged patch to eliminate PLTs for local syms from Ulrich Drepper. * Autobind netlink socket. * Dropped compatibility code from security_compute_user. * Merged fix for context_range_set from Chad Hanson. * Merged allocation failure checking patch from Chad Hanson. * Merged avc netlink error message patch from Colin Walters.- Update from NSA * Merged second optimization patch from Ulrich Drepper. * Changed matchpathcon to skip invalid file_contexts entries. * Made string tables private to libselinux. * Merged strcat->stpcpy patch from Ulrich Drepper. * Merged matchpathcon man page from Dan Walsh. * Merged patch to eliminate PLTs for local syms from Ulrich Drepper. * Autobind netlink socket. * Dropped compatibility code from security_compute_user. * Merged fix for context_range_set from Chad Hanson. * Merged allocation failure checking patch from Chad Hanson. * Merged avc netlink error message patch from Colin Walters.- Update from NSA - Add optflags- Update from NSA- Add matchpathcon man page - Latest from NSA * Merged patch to eliminate PLTs for local syms from Ulrich Drepper. * Autobind netlink socket. * Dropped compatibility code from security_compute_user. * Merged fix for context_range_set from Chad Hanson. * Merged allocation failure checking patch from Chad Hanson. * Merged avc netlink error message patch from Colin Walters.- Latest from NSA * Autobind netlink socket. * Dropped compatibility code from security_compute_user. * Merged fix for context_range_set from Chad Hanson. * Merged allocation failure checking patch from Chad Hanson. * Merged avc netlink error message patch from Colin Walters.- Latest from NSA- New upstream version- Latest from Upstream- Fix man pages- Latest from Upstream- Latest from Upstream- Add man page for boolean functions and SELinux- Latest from NSA- Latest from NSA- uppercase getenforce returns, to make them match system-config-securitylevel- Remove old path patch- Update to latest from NSA - Add fix to only get old path if file_context file exists in old location- Update to latest from NSA- add nlclass patch - Update to latest from NSA- rebuilt- Fix selinux_config to break once it finds SELINUXTYPE.-Update with latest from NSA- Change to use new policy mechanism- add man patch- Update with latest from NSA- Update with latest from NSA- Add changes for relaxed policy - Update to match NSA- Add relaxed policy changes- Sync with NSA- Remove requires glibc>2.3.4- Fix selinuxenabled man page.- Upgrade to 1.11- Add memleaks patch- Upgrade to latest from NSA and add more man pages- Update to match NSA - Cleanup some man pages- Upgrade to latest from NSA- Add Russell's Man pages- Change getenforce to also check is_selinux_enabled- Add ownership to /usr/include/selinux- fix location of file_contexts file.- Fix matchpathcon to use BUFSIZ- rebuilt- add matchpathcon- rebuilt- Add rootok patch- Updated getpeernam patch- Add getpeernam patch- Add getpeercon patch- Put mntpoint patch, because found fix for SysVinit- Add remove mntpoint patch, because it breaks SysVinit- Add mntpoint patch for SysVinit- Add -r -u -t to getcon- Upgrade to latest from NSA- Fix x86_64 build- Latest tarball from NSA.- Update with latest changes from NSA- Change location of .so file- Break out into development library- Move location of libselinux.so to /lib- Add selinuxenabled patch- Update with final NSA 1.2 sources.- Update with latest from NSA.- Fix to build on x86_64- update for version 1.2- Initial version2.9-8.el82.9-8.el8setrans.build-idaf5fd2b2eb04d6fbcaa41139149b8720d432bb49libselinux.so.1libselinux.conflibselinuxLICENSE/run//usr/lib//usr/lib/.build-id//usr/lib/.build-id/af//usr/lib/tmpfiles.d//usr/share/licenses//usr/share/licenses/libselinux/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m32 -march=x86-64 -mtune=generic -mfpmath=sse -mstackrealign -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2i686-redhat-linux-gnudirectoryELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=af5fd2b2eb04d6fbcaa41139149b8720d432bb49, strippedASCII textPRRRRR RRRR R RRRR R RRRRRRutf-8bc82e21b2ae9addc7d0df20b336c8e5d6c273bb9639a20554efac0d5c0ceac1e?7zXZ !#,+] b2u jӫ`(y.U\tVY#;Gv44F5| 8zyh-c,Ͻ-x"HC.SuᾭmCCЪOlW_aKΠ[~1lՠH<'FKf7avH;Q%bJ\OnK?ȫ? Pq.ujL6I{ŃSkΗ^B3]ei|Kt7{_st9`MjnZK7bTekvdBB^Yql3#oڃC-+NEbp#lWpS֣ 8 -9)!6OD qX5kb3U/mD~a-w8SoI8;ׁ45YĚ(8_OicE k |LUNԻ͚xz\8<6@GI"?h&"H&: qDU(G-ŮELTZx=vPl_xD*p_@&2| g6Zua-!'@<ԹW=0}nu_ˤ wa^#dwRvS uiP >Zx}A]O%<2i,䓏 ⪻\j=M1^$\>nNTN"-P /©sWLhIsa(U w+P[w}ެ b ѭTB BI-w:pd} k8!Wm2kyFMݿ j 辸UսdYznّ(4XfLD)843K9sx/s(_ m{CX=;%;ܞ{  qjO5>,3埻<|B72Vkry%ъ#T8X;;lޘn3rBjV˼ّhYSRN꟨ 0ij}3 i0m0/9!*{9vvI5Sk+â_P~dۏzR=lf!nU J[ǥ(Yiqja2R [6H-z63ch3_ "#?32{ Ir*m;_ORvEi{DFMveŒQx:|` $qȁ4ɡiEni \(ՙq NJ7N7G7\eXo8Rr;SjyU/ شt':zxybwToٗj27K>:LlGO, <NV%F9v1?ʽQNuk:[? B!n "ًůR^NS~Ax[y,J͍TZ&'}_*]X|S[6rh5n4M3wC?j*M|'p*f Ӎ8[6}=| B ܣLg;* ^;Y^\Ztߢ§Qt i*E(1pZ̵鳡#PJ-Sd>q -eLFf,X Fd+Sk=Yend.]s6'7FۇpwnF'A8|+g?Wrk5b qװv=W*mW1@eq;HX,vdm܏~HŃ΀\ox8Z8@,DChJdӕD뼒GzTݛydC$w8)it"?pGC1k% 3R#|cA-ƹǧA" J ъNF2DN&d1Ɛ,6@EAPxX8܊m 54/v`d4^N V?? ,XKz0cOԜ\U+hVC,Vy>R!5 #eAg3_J拣qr`DrqK:BgEq0Ey!aXNezt[38I*2tf5~ep{dw#*sRaFU=޿)Ô\~O<&m.nz~bƒsZV 1PizGj֘enD>nQSh2@Ź"Hn:JXl US[na z9/+Rx>BEA"_hcy^5='܋qFq "rYc,w/Mf1mKxX=\fItr8oIenp=XǢbۋ v7UpgahAnӘD0k÷oul s`o(%K58cJҹKeh@q8mwÉL`VR:z'k-**9m߽ǸۨD|UK%]I1ԩDH/ǁA;v8eiCV =ubAeA2w*:1C`E&8+ wh;_?u%oGɉr Uٟ=E\sl7^o#=<41FEV̀퟽,(}"QK e}o(k?fWQ%؁96إLqmSrO`3dBFwVuX8#Hɵ߻̜G^-:@o,xJs^4:䒔o sks{/{>EzJՉUwJ3L/sՆpukek^49q51Y8m@~/2QfuZ4:R qTHJϊ\lQ'yA 3DPcW2 0)K*B0cScCY>m1݄ץțwtk'k9D+rNd:g{ ȩAB;Տ(!JpR{U V]#VqQ - Yq$ I[O7w$??PB }r!q|?Nu0feM.HW` WBuMn27;(PKIN}>s0)8]$VyV-VM{CGA<DT; 6`=Ҫ<#%NU~̍R: mӕnè*W_[DB8\\)Hw| *;4ˇ+Idۗ_VWC7[SY%EܘA[}T) kJWB4=;dᙺ@xvu 2E }s % ``cyS}{J$Qb>?"[B6UokbsW3(g4"{OS+kpx{{̧\QFm6:O֏T-~Zx J{ V"E`8U4+}wƩݪ;3<0 ' ʻsJV}|=݇Y^3)#Bbخ E,"2q܎?tX 0pm`M$-c,m6oM.#tؚE}xmmO0z51D 'EQZR]r6_48uV<ȸ.](?!ퟻF"[,࣠MgeJ_{XQ5YE (HdсJߒ% Rx/xZM+Wa&狔B&1߈(5gFчIxڎ"3f仞0[8*cDt= mzo2wy^Y, sQμ0BW~ap0̆]֚Anbҽi6<-"sS//fÊq7fgi9{y>#ۋ7V /zRxP,Xo$y݂q p]G49c9ʙWk ʵD$1&Pgsb] -Zv$8¾*97^.:"B$)fNݷQݩ$Ad[b<9U}q'+7Aחow LY ʀ;{#lO+=Uy`phl+*yh&kT,;Pd2J>%L*%Zu%Xs l>ȼPq"9Ӯ{ҴuX?q(:qޚV_16wɥ!+afnzI/.W.PkAq<bة }[¤x"mR\_Xȝ'Xi퀧h ۈ'(á(ֺٰ"NZwO#^g$ O*YSxfD 4eٍ*.o}ɎĀ4d չ;Vc>uR>nvYœ08Of~2 o2K90喹6fOL?oQ9ѳA/`{Fu\Sl12F7e%3C{%s55r}x+ ?F*CRe'0y$!]?[{L^9H11}}7yonCؾQ2.%dדECK Jex䀣lv@7 fY41GkxO&XN&טL,L(Ҵt-dզ9_(Hې$ Û`7'% #:m#ZK%3I{ ):$8cECx v0]{`'`rYiI09``Z1 C9|\PRoك~NټRnVj.]1hҽJ=%r}e+){NJU+*aCU5CvYgv.Cx[?~T]r ϢV=0M_ʊ/9i^\BA2*>cB#@.̚*]]9 '"Y[z&]*~RNbeЛ wĨ7>mR 9[`Py'#w /.UM笣h!`2*S0cvJԗD??2_;c͸[1Ň@'ž7{S6=JdzX'3 'Vf0` IBSj27tu?r Mw S!.h0HX ,.cGiF)spiCyXNNoG@OưF)ރGJUѽhjwyYKQ | d [7*_؜55gQrX3Iv*&i®z%.Zվ|4uMHsz4t~,'uKdHHdloƖ'ԝ$ZvpQ |O N6 WE:((i)ʜW֍Yoha ͧ_S}I]Rb$:.x\pɶ9qcE.IY̓x\8ɗ 1uOT L?gu6B#WO\¤ɽZ^'nxζoMTʐ.V zyXF(R0jn_D^&m*[@?1XJ: }zܤcJE4Αwĥ{'Jg)CHUٕ6úWe]v9[Mqo\?o 2,G?1NYFݨ~QRa~aCPQ%MI7Hݬl[EIzI P1-t![)ڗ9p` Y 8 ooM\ BusϴNhj$ %1!<[D~YEf{O0v~ Jzbt׮MoY Iĉz . jxfT߀Kl#Y?w(_QJ Iuy+Wx'|)v{Tu:3+ `_clz5XL`r포`T-> ŕok#2Gv*!z#)"bjXRFw xկՑlm?Ȗ9ILq8ǺIWa}mz3-' wߗDq%Vכcz: A`,7-u*~xe©tJX @tD{rl,ǸUeyK@y0B%-C~Wd&xqv"=gȄtCX! &CU.JQE=qUS[;r F@E}:T$5w/R+$I:!'-q_(4)˩ȇ;}=='fLܒ__uU&>Mx7T/I2b3LDJfLZJ 9ijPFT[朮07Xes+(ޯܒvǎW<Wz u9yZ>4O\M#C2׎5z[E֨YjYR|}(| ќ UސR?1Dc([J1Gk;FkHQΣ3]̚ba# QϠmf RCZŤ # CPoPA.`~D 湈%/|w Ώ`JԲY3{YTHi홤r砀uD.> ,+š10&QYCn78 Sf˖iCVY8uS ")¬wc=JaYt..n-m ȵ씨@ Qt-Ew0T5=3: 4fwi"!8@ xUGH|n1S-*J ܫnD~0Ɨ&87$jC2IZZjk}]},Z-M nvC̓򲄁2 :GWZs]ij Zco$̑T"8۳6J j(/6 =V=$8P69&ƕU7Hba]N!+{UCSYwtKC//R}v};w"Lb&,]OBb˃Gr4= VFR. IA7Zϋ޼y_m ܋{GP!෎DspqN$.2K4y{ <Ϝ>뙏1$$.ialK Ɵcf5&Q'`td{KcnECR{%h{yoɲ`)=Ql6A+>j㞑g0۠oHHixTSBwlVpsVT &$ ҄yI8J`Su@/TW@ )kJY[ga ym *vd96.#v E!X3Ok8;5pAOp~e#x"aA*s$m_2Q?sѲ%]dbvC/}QH KE(0F Mvnrql劔na۠AIBZI/{vq]6*R2"dKh?0z!L "-cj5N6*/ pJWP#(1;~yy08 FlsCHpn//'>Ծ$xO"f lz>b`lm\}0IHWYu`55KKhdYX&&n{-PExetXWgva `sMOp&3/? /Jc5#j$ Cz(͋AYQIƵ#I4b6OQ%ø?eL{9&~2F2Fz4ޛ_{)kA(} d=ow-uP?#ǂ&mzp~Y{YxWHyoY@·-!"#o5԰Fx yڟ[DV Ƿ\h>{Y'oWaYT\59HZ͌)Ӭl4wseng"4؀`dU,S~IlD | uG-:]aU{uP!1;#dIv9v. u)<+;ð%{`}([_zu57/=Umڗ^?-ۓ~iƉfleԅySkYsm%?trCmI.n8eeu.m1ʪXTLH:(T"<Gʎץ%ϸ@Y^h:5HͯJAfْ 4 mV*z!U,^d<{0x "B@ʾSfJiTL$ h/f|<Ha:xbBHN Fփ7sMe O[ 33*;a?V6U_16&m /#pJn|.-a Z{jKF[{#J3ɑmo7_Y_8†I9usNyOn_Y.;\t(B4{qQh fٟy=cpit"lp鞛cDJCKep?c~)TgokyvZjH4(ϓq\û.A]n"|]s:cOW.ZRiv7Cs@|-_du@;1N2V@b߂cY.MN>iQ7 6mxU^ Y?;ޘ3~Xױ{%1KPVi|Wu"bͱQb 2VE!$o>40QfsߡKməQ޳6֨x2P㳦JZ߃)k +E3,%zMvJ==` nwҀM&֦^x⇶boA j]"@B{lF1^5A fLR5OFNA~(¨)$҇sM4)l%"2f;oUj %'䒳p9ADo:'}_}mǫXF`2768R 覎 ?}v\ގb&o6^?vHmv)4<‘oE+\W] HAiI$P iˌϥBn%-l {*D,BԘv H5po+<3!˔] .̽[΄)k!  3h"2m3g]}R/h7[/S1ؽkmRJj/B_ Мê R XY$f RDz .} MPLHY A |4 Gp%k${IC{/o aQ#;N!T% PVi Yй :>W'{6HTP';>6/~ C 6Jjhr֣"_ԃcO+F17<_ΛL D{bH9ogA6<41U4 X%{}F-,[M2#/d:8ɛtI0ӷW@0[.ʚv!xm$7_XI+:P8| '$v?)lu7ēv*;ktGʶӄ1$R2MwK'NF c:YM#dN{4tTcޔA8אcL. hoi#I- k#p'na@x3|Ѫ.d]lmvGyNO+E=7;zPqxz4֙J3W,[q/ ݁cwFX;Fm*- nEB5g\w>g1O oud\,Z9~Ž+'B?Llx j"SAs!ܙ"XO?xVIC~,ydg[0 ;n> V_;ЬSD Lis$%#ks6JKвm,8oVhWHxs s"DyZ.|Ux_^0E U~hhIBkc>Qx ǞV*ϔ<Τ P]LYc%X7/zq;@@2G,KO'*w\(-q9pt'h{dL8u,Jy9)YO"b@#vԋN/1%6 gʉ{76,֛@TbbFUgj 8y3TDc=ʧ-.5I0S 5CT^ҳ0/&EcVvT/G7R ٌoeCCF.7IKaYR֮4@]hzR uǬ) V^;e #ÂGf5ir&)e&J1{cH:gy -Iqj>D`i:7Do$cDv`7 DB6 I(;h=rso TyK2$&5[{]b46BO9>W%__=s8 4}H?N.ݓ<na,U| ϵ֌o>RTd!h-g#HQN3qۃ@ ?Ͷ6l,kelʙ0fo^ S)&jWŐ;a4}_`HQ/B ЪP`?ҍ=enN< .*kÚ\W+sB6\zJnM~VGZi_O46,,ը3)"~p9AʚpJ =_RA&ws.Yƞ_X?ekv%Q[H9cwOy$WzMsյG06~b@es B7J\{ubG;V_M{`0&y^3N߫1Bz㕩-wg3kgc%=jQ5NȊujumyd %5xuqJ!Nҹ@v[J>JSm$G)4;_ 3o{IvCBCj}*(Tf7 id ;Kcpb B45IS߈8Z ~z{CWz40n}iO ̌D # Cڋ9 ?떹'x/_YeXN>w-퀬*W|W-Qz1zɇl|J4څEYڼ|DuU5ј+uΠ^D;z;#?B\2dc1u ͷuA%);2 B|E3ޡ@kȺ]䉋qN=-.MS AJw oG"Mi?dx^ JkSv8$7S"NZ Tz P"Ng$:'ۋ·|yl2 B<.>Fbs_+wk8ƣ}%BAzk37 Ͳ*f-=+I8`&yƕl(C?Rwb . g7षIuv58%G1V\}kk~@28+AP_-RW+0Ti]wn"i v/˸8.{"`p(vk7k>HiӜٌ[\_WNʺ@T+~ʰ&ҡ{[/6txz >=!vJ; M*˕F9O.=]b?&v!`oߞd[`#XaNuBβ*i1&D2;A;sݒ?K~2;C߂+΁0ZЇ!T7X@8 *3*}< hJ"U\Gr'WL8vR3oΐyN;{U5)6~i,l쬞"7]#O>U9l67iW~YWwH~azPgB&%D?~'5ab/+CG(EEO-: z{1o{yαp Gbp~C]dh3h|#ll)[6K * 3`I׫"a *.Y(Kp%K0t; 6Z==t<zDμJDӻ|i &% 1̓Mkf0r\RMQ>ZKkF5QQmI `ؽN5[, 7r!A ,DnI?T׿UhuI߱ir0-  6ٯ[}O:ck{xHί+?jp9̹-X6='cGfptzk<P9A2A8_ҝdeG:t2~% (d` C QV53bia6i7FlÝ~4`>$ oCÐy-dr̸+k%cS'U)ڥŜ9\Wbnd"EEDk9ozX5 {)ڬeSYu% Yn˽uA fw߉ʝNX2rRD|L 5?=>TIώYTG$+ۨKչD{ WU6ZEKHnf 8uբb򲺽x~^fJ= C7NKouOVQʖX毦o7 \[82JĻJzDAYR\fϭۉj䗗ݦ{߻\y6ٿ}a>3f|J*@ v6IY;iKiO@'06f$|?V0+'b"; qCC'6l8W*ܰ3O5rjj$"ٺ\gS'w=b8@vmFQE@ؠFB>2M6W$_үM] |^s^Gd`&7!N|_r2&ch?=/}B}- S @.GD=pc 3jpqXiLBg /_e\zIl) m:r#%ߔ_ 2O.PE 5hC]cOuyvL8]$Zj20K;r7X jD'!¸=o۟Ru9Phڸ7ǜ+GR@]מ[wKB ?yȉ/.;RRMmjcaFڢ!й.&WzƬ:;6rkLw#/lTʖ# {Yk"cmGk(.Vox@{Xt|.x7EK U$}!O{dԞ1h.JE8'@ϘxKO+|AbL)vެ9@bY0m9g2Q@oe/rcyPJ5|=vJXҕ=iI^F{w24E.{n} ;*;pm5=@Q.LC@"}MV? >5.4; %3 &aG wmPb ɣ;qW( ƒrPMq6:BeoX.͙㭨 vmU !#/s:-`RTVus*:3Wt{JhIÎE;4 D"_Knp`V%-=FcFc|Cp rQceLwڝ^~,* !,]N1j qQˢ-'`e-t>8B Zݭ{YD-}'=="1:"4>ߪ(Ńk:"B:pE!jY +CTvN6ۜfȚz 8[/;Xor!~e -mJ~y03;m,~](#GHC#Dw ,C߿:UZ3wRfT޶DFGYƵtjaxJ~8f= Ƿ}E(2^lwqٷ MVb@i>싟8Q4# p]rUT*kuU_&L7IgSJ1S2ܙOp_89>>yV=v罇Wj3 ><rq'ӐSoiz~ j' O,e;Q-|٠DõyWR-՝G !E?:nOOlQvB PJK灱Bwj\AGݰjU0}-*GtHj!duwfl"auzytlv oJInџƼg %'HTrthNh`)eb}1g]>1B}|oiMRɄd<"#D ~ ^vbjΈrK/Zܰu A[}~l^ 8f=+AEur~͉#zBZTZc O\= A2Sه* =<ˆM-sJ>Bj/ EF$Kw!5m;^_bȪ?8uFnH_L,9`=*H {+\k6q:\  Po٥("|F>)B]IXNpNLD;R!!J.HCSF7 EyDɊ7nxG&+)(C #*7/ȼ (Ydx=|QJ:*kSqF?豠=xZql.O @XČ1OpFvۚq'T%r߱㑶OM2hNc+M]_cW$,,(畲 d!"uE9BX- m[D&*_0 -AJ! x w4V^k$z1 +S㪤bVM9 z4:aP&0s~#zZKd-q1'xB=d_mA4fQs!f1b9nrN/{xUUj Lɧ=4o!8Ni)$VrgRE΅/^91le ZIvUF¦\:2[8GGZ|a4->]wt>El]z,aKRZ?ڗ@zGYHSfԍgĈgDBF8  yo2=jSRK_B!gK~n,Iҁů9y4`E Yw+ر;}J[gK :"0Fo'w/SZ^_=ģUn$^2^G1"=Da>0fWDe^Զ!~egjaDBqh\.-Jl e7laU2$cްiҥ!A&bOT+xnS(+aP_wpڙ;K \T3J3XnDa^P{qūB+E\B굿NTu<Q![?g_^˘sɀm&ݸ >z#F2.ug9 V۳עhAqLB^t@72".aGbm- pV^\tALَTY?e%qJH0-})FxUP 5|*M"/Hn'ҭ+]O|?1V]<~je'{0M b~*v}nb+NToyLZ2,Eqa? K[{3P kaVifm3VDEet |ā0/A-&WzQѐHkDyWPTb_&-td6Z}=u Ipc_ @»s4yCM-qDÖ%+ۍ \񶟡̄27=,a"\1DWagYd…p!pIW-j+QEB:2S^RZn#>y ,,AO1\i<1'p CzsA REPN,6mkxS jHpǡe4K 8uYI,lz "BT'\Erl6;Db}a\Ot2eV5XK"?s; CzᎥd~HyTwm ]lpbT\(Hy!м*FԩYvTTHlBH걲̋-iK8 }~~>N Qyq^\ҩO7JGd'_ q%Kv% Wlza|EtcQML/6p,؁& -JA x!\\ zw:0dFBZLC*p.")>3C%>$i:A/ON (>(/SH-bW.:^' Ku1rk5'CkW"qhTZqِB&>-e?Na N+?v%0k}4B Dk rm(F]2mv?@5"4ƥ6qsPHkکN(;D82@|VE dYɢx@4f2ԋEϠ$Z%p-վ睍R;`I_- $Dq@CB%V<&CWФ@&Qdڅ$*pҎPK}rpǰҚ@9L~OeN :`';bT{p5,*m3F́ ~7(VN 7YܖU.Y%hf<ҖMpE`F"gzG%+?J~y~ 'bgT\#1/Ni!m]e.`ή DLSb/==F$e+ݣS$0> !!}h w|M /1I;>V F&?)(h1<%7J:TYD  a3EOI>mJCsbK)/M9U[`"3#Je[8F r?Pynw Yp?Q_QZ|<@ k)ʝザVM5Ύ1g't"GVmE! `717Q?S*!N#A Slϫ16XgE89Mޅ0axV0 | Eo[Gj7&@؆TT:5Pae˓2`D+f,,1`.TPʁ=Uuˌn DkQO:LXnTᙹW|7<Ԍ6VԞ ^|RxE 6W:vNJ&pq4ejU+=RݨO1^MڻNӁBEk£ANnP+oT̅l CU?o/Z}jע`!OEV= K',񋉞^C0$lJȒ=68j2}kk?1"ՀAy yHȬ?@˜ꮇF1r,l*04k1'1 kDfM3Y^b^Fj887_9mݝP& -Yg:*x#4@ ֈ"bW!.Yn$eH/ X,( ³wPpUr7{ {q5t +3)Q9,O)o6^L`&% Ϟ}K"CAZMx}{O>Qڭaq*@W(dnlyD+shn 4P2ee"DX ABG4I}L*_`pUd 8 L6ߗFůvOT+qUP)kiC\V3e䚹V@(yX7rSLk[v $"-3o4{ N Aq +._yaQgNiNgs_'Ek7yM7v$ؚ:,|4!p YS`c^wY!mhH}يgH_ 39N۶KU< ю xOPY76[(6O*V=kX&U"žѹC8Wǰcߟ4>DDVPAz:v{Ȏd/ieؒas4FrnHNIxk!N+@+a{2w 00;KIڏ#|8SEr.f]yC+Ff%yPc]ۂx1p"'/8ɚAY]̗Gi-?g@)#Xp},\T]g*LDyY?(ElPL0FT]0w4Q_5ŝd⺰p8i;IG6&&?#B#7 MSvG:[vCyq|oɆ0R2ןxw9PzBd9^Z-7Z؉w0R6/C/T9иHHt-dn)`bs$Ћ}C`b{aP:geo>pLcGqJpr*q\~PӚS |_x3ұ(`-X^Ԇ,%G#c2.̝7µרx(-4^]c%9rGk0~#me?CxB3s|[T G0ȳlFjJQ AMw .-%za nuFWXRilnbSaΡTXB 6=7σ59K'>cs9f |QLj 3lM$ʤ o˧T$?)O{$$\5SGmeRq`|Xݣ뽒Y*6vBZ޸0HKn)aƵ0*kgP!f@,օ 3 \Ĩj>/?zo#O,Nji<[e?[ 6$TMJhטNZDp63s!ј`ݦxHkLJMg5AGډ 9ZL]|y*P3ͣsdl$*RiHu /->_V2>rJqTHN` Qr@4w_xN#Sl^8:%&xJM8 k6bo6~Flr ~"x 0I`.C#_X̡ܾp;aA ޡxj6Barw޿,x~#"TLF} 9h8D]sDy[Fi9>kAB6h6zbZl~EFf;̈|75ٕ 01;v};[f{bķ[ZV tqz(*H@ ̖HhgJE5[Sʈ0z N:{lM>} 갽#2_k. ( 0{"Ea}wڜÑIu=Wi\Jh aC%~aLItJf}KWkVHܛs_zMq)lk8L߅7SLoş#Ҹoqȕ=-iv@y4m1vS' ^Y:"J"}Ukz9O;OxA+3#ܽoRZzd>޷?3̄Z 4Xn<ƌ]WlZ ]_ho0g _o6Z5åvVrԘt/=<Sk}vrͳ[^FNFi}&-\#jhK %NG“t@=NJЮn-eq5^ۊD pJ(j.biAcaK1;q(;VjvP'%o{۸".#->s#ǰgFD * =`?k͑nG~c8ZLg#ߏ쏻MfO.~_cƖkHVZsMov:G8(C1[;(lKN@qflU M>J-L@j2L?;{y oj(t7nmh8QKK *`oւEjr}Kߗ<|#Ü?qC?5,dnRݬ{rpbP&=IbhbsDpӸPXoВIjqƤN-:&p#y<12L6tKlf茁˜eMkwUUOG|L|yxݏyd,r]3UԂ=SG6ɝ*9rq0B1IxUc| giZP6!>s}ۚd*evKvDwB{SӃ~0[0C=~öٍҖi,-Ue=}aoD{dيК $5U׭CtDmˮVtpICܾe.`bȳFj5vtI.&L8x8C9̦};dl`)oٳI&U'R +L]%kMrq_oD(hpλ~2a%n—m;֘~#t}+vgͳ T̜y%IN UUk-X}7 XD*)Ynr]72 RQ%t@G'H~~5 #آ߷zи߬!Ǔ~Xb¨eiԈN&PE4jtr,4>!9! n]>]z *D;65 )P94Vf/Iyh' 6&Ũ5B 0Fd?~ ܍U8qI3Nʁ_Se9_n/ 04lCOc7~|(֗ܒnR+CUrZMJh~EY%\n߸'={#/g,\ɆTG͑dXGhDW#(c-+ sױ7 +DedY+Y8 91~z}?# a/}{08$6:ާ媇t2+11^G H,3iIY |d_t6s1x$$>j6+}$H=7qJ"vc2}q3\PCq6~+N|.DJ\8 l;C[x]5'"f'[p/`F,8`Uuwt#I!sV+sh)l/.^ِvSq1YN{G(Q>VM/i.qԠc%9@T>BIZ1)}癜:*aR[%SSfxpDWw/LMpV9ڧ\m4UZN$FYdZ:並 Pa~* F>͸7#s\ĚZqww{f1bWhZe]a跍S-&ڒgk(3_Hr샊J _ЕCLJL)v7t-v㤈l cNMR}ezb;Яw$T4n~YTV,ȶfTg8%ؠ?X%g "´Z kYSǭ-Dx>)D /?u>e ԵUM_m;4F7m8sUysQgٽyΞpcYLY>CS`:<\=kX&rUB˻Aj("nA|)iat8-N14a|V.FjjcB*6T;)MUE?7,)f߇勚*PBB\m^Rp5'(;OfqD vxK +Ϙa prbHU=wOK| kfx:,YͿc09j_~g-\oJXHZzL:apgtb%R馦m$gv-_0hQw?`@!9&)nmϗ̫S@ |J\VwJM)}7h͐ v"º| qzvčM.1s-d(mJ7'%9_Ao{xgX_gcuwPM0Nu"\,T5|1iacqг= pxl$ߖ~mRyFtVK+\L\Y}xY[ JLjf*Ntx!1(ɷl!1hcʓbrs4A8kaŴGs Mv2 T® ɮT)Z֪gZ[0aY+)Мp3MgSOJWfm5-#w(jЬ S{Z*;/O$~Sϔ893++쀉 ^h@MEpJހ&xQ1 hۣcLpykqWybƂ׫L_0RWEk? |Tvv\:`'8K2"/^1KA{$B#-l}iHB{Wmk/l96<@ď+|Q]3#,sl$zٿ=L]n? h/Vc:Y~0rG[0 q]:;V gE"zC1 (M5nE1F7+tNt*-L¼g \}czohh! т22oc~3++,bpj +sGƜ(t2CYfz H#xuXwIK8i B3<Heӌ9UYV\Eviv1{k%%\+H96"䍿n.7PNllCo}턢2X+j!C, U$d#*[zb9=+?\]=DF)=qsGv} ƸgR(rd9.?hA`b)^ksm,At,생ˠ7iEǤrC"HIuIǹB\#h*+MЮbRvnBA m.qIL%uL4EΡMԭvY{Oc_YF+nћ/M(;,6+Ezeﯳ z U_F #Kx[2i9*!^֮2kѬJ´{IĀ&FC[//! =Ѹ EJD(1•ZvfjpZvjh'؂,ר!P#剽=W#,{p);C:6/hO ;'LQdBSޗ|[l0FwAK5)Zꜳ_+Im;xnSsiadt E ^h?L7ng^ը`aDMO*{kGcC >*wV5؇2t: =qVԳDϸk:RLR- H\KFno*oy㎞Y5kw$'|\Vt4{K'ȳpHF˼#hrZ-ˬh௱ЅV2/j[yk^Qj1$除Q+`&RwuI &A_Zmz -;%Rvkj,'uΡF*qC?L0nQ"ov0dN%U.CyuS#NkJSknUKG0Hlm~]4֫󑼎OM%`eS}>B.a`)DB]e{d%mwqKF^'5#Ox(;CB[t=p-$p` ʢ_=XB(q.412I^o TO(SX[v$tB5e"4"[)c7^OHoK>3~B]ym,pw- !20 $+>rr\´Ju.`?qRg>!SJҴaޘf19%}=L* |llv $v\TrLbƲϼpľu$K lKJGݾ_jE 4d{!sʓ)ͨJDz8l{~ l= n҃5$Oδ!jOT΀s3o$D +|f_`Ʃ,Uέ~tFR_Fs׷;)dLhH|Us&X[ b"A\J4yA@@[ nrԫeQ4Y۝ 8bTNtX7QMMaxxx8H\⅖i0nrO8jM֟#`vD/B`ͫ}34GƑ|;=,~%Dcܬ k"Np#lV0d.V0 @*ƣ3TmuUlAy+:_Iάz>Y d hLj J{نcWNYČԧս e64 EѰ=Y_RTF25|;;=  ؟ʌB-D&5 xM,pq%*RK=Xigֈ}ݬΑf c5{'&BM!-qĪ@gL|fMb6@(-eFJ5:UIǼ[o _(=N큲2ęY]LQ C|oi2X5I/  Ka0y;~%kS>2ASQ ="Y)ѝNoNf4,xd9\-s3{'-/n$ݶI%\'XۉE8 )OĈ]^u"Ԉ᭟ш(tk}&>#c]?ߨkW"i.yViK:\aն˅d ·p>4֋ڿkn#zy:_p݇' $z0M w~ÂNrC,)W*tC. OTnZof3ܶ$}n6Y|qRMM>ٷ*xG-g'1\_ґ:t+DzٽA„E|l6}r3:* AӮd](g?wY-"|( *WO5,}wo=yHǯ;06}DHA``; ٿ-.B_2 Yx{-yuP C:XR"wY^ 1tE=-7WL~]`mcV$=cY*^oo>zJYR[}FgXmy@Ήfy:8p 7p8O!a_gG̢E,PJ/ek8+Z>e4enC=蹍D+N|Źn3߭)`; hha,5Uʳa~mڡҍ\%s ٖ1+Ha řhC1,_f$"ԈhKL4$Cr231Ll n{L+n }5khcs\.{2<_3F+}AiJR"D0i^-2h HhhW ` e\X$Pmn&3 yc/vY:Lp4ܗ#ZϙmlZ!,L.['C=ixs 2'}?1[F?JzϏ7}ԅdǍPL-1k/lMh)o Uڠ5֧B+g~ Hw$ xԞCI$)*'!Lǰ%$l9HoF푼42$TاM.-ˆ;'O^!#yD_5f֧MpdWd -< W !i))emykyЮ `{Uzq E-U (j-! rbE]V BS?P0=ngOcy<.Hn7Iֈ^ FF훺atUqC97mC(ZA*1_<:w\c7c`F=@ ++!(s r':5S#y7.~>K45*sOG I`[ 84[k&ܷ}$'ORn H, Ӕtj9xKsU[?SB<;$@HNs%ΣRU۹C9A[4z7]G;)DA[>t %.$U{ ,yfh>oL~>Qӯ­i_fVYi)yM8,CkƲz&l?g bSdꑊ%#.L='c26mG⧭sɜs ӤN֋_n*})d(1:hp!(ǵS!'Su/?|Ͼiw.B\Y8>mi1xB\4daijѼYeKȳ( dWz}ۣ+0G6ǖn|Vfik}BM^{*?$ sВx0a4#< +.m|m W7fT6Kw{@QFOx6Ys-+wz8HXmi1hPꍱ]tQU(kڤr0mb( _:iwkwV'XyIv߉|2y潭l(; 邛+-bO|UGsS+6Ŧ_&"T$V4Wml}d`9,Œ',f'4}V]jf p. ĄI?$Rv(ri98=;V$~ORQeam>je}}w@.LSV[&b.5M/wD듰JkG!|ɇ-pLs.2s84bj_͢xwN7\"ji"_5wK3/3ut,MQ F X=8vk4^ zuHˣ? R=R_V?됟+8l(3Aϱ&cZ;~.P;1N%;Ee3Ғ9AXygzi%׫ҮWa~s}dX^ T5]')4"( =zl2,ҋ"'C' n&:#^g%׭'ؕ3cJ!KWEyN[a8HMBR.b,~5gTK'3#Hz%txtwr/ V"`*8cߧ=-R~4 'G+: Cqd}0l}eXof~)>r~􇱗7A;c2"$t Ny ųC# Hq-NcI⦭]O2vE9j]u3[ʼ0\_Bo4ٖ{_tnY/RRoIsFg_ƼwEb &fl\|uɔb3Y[ڷ8DтߤM"du1 iq KNɹ5bA؆ ]e ] n ,6a-2?ˏ ?3b#{.O*,Ŵ1HMBnn#满|.2FDV>&PFs|"x)*Uia{->;؄{fP1qpriX4jX6A ՝ss3Yf?}JAv oA\fǏ@/mW*֯1+2.މJ#l8kwsFp ڧtAwbwX{Tr5̈́>GAs̺c< +_A2T}kcOTJ8?uǻthT<_ZVuT["@{iMrН/m OkE7=S:%m So9WqgS[D5xmj>׳T* hCtvgfjgwj@Q杽UTN s- EM+Psk M9.ɃWV'YgNmTvXcxHYmLoqjVWp:dj]ʋ@@ot6_)бI"O;pZ5~0gL{qc8R`[O^s<(bR?5d7ej#go018`#D\qh5"Jc <_vcW&p>#PDF[]Y]|-vJ*<{m[9#מ)rzx;VN4kS.bpa^߿O;݇"9*%ݠׁ=1̂ݡY Tt^6u_F_.1$㲦L)^ZNH~1<&/ U|e#LBZ hy|_,1 iϾտGTӥy8!'P<3lFObI3oTal"+^.)7'hc_WD枿K&dT?DrU@W2rAZwu:ޥQ RX׽U!TO#X{76`X5Di eyf^xûY%8+'N2vԁڤs34,5F#mzΏtrFP[ hѭK4 }Zl%qIG<6pR[H٬֛Ÿzn&ܢ Lh Ģ|9;=MR&5 8w{7 k9H[JSE0cfV| d׊8NM:&IkGnKP6AÕD"OD*`$ZGz6J.ȍ˰P7muESUmgt @~h췂{! X`cYQi5A=90ĒLR/%zp N \Kzpu Wt@Ћ)󪷳ƘC1꧓_ШU.Du ,-arsX F@ Ф2QU8 0|z1OL&Mwnq ׄ@+8ﴣohoۓ6f-5MT@v~\1u_(9+ҊbO,ve7/Ҏ8vDy#aS07?Fwbgry6@r=aM{ڎ!gDŽ$wUR=따:hSXD;+FQ7A&zjf|`whYd{~<0 4m uȞ E7>FX9XFfPCجb#Blڂ^-D0oۧSH2L aFGUZ n8#oO'dI$$Uw,_r$z!`+_%]pxYmO? LyhFŚn2yCn D!Smߍi lݒ*'b:C{5,uS8 6!#UuuPwJbSܩ*ϐOP#DiP*Dr.(a8ڽ Gfoolih=6]'1f'NEd,PP9˧xQS7A~v:ʄЍڬ0]n4,ZzjH<9`fBGL~R.>}m-=͊)RHXP=y]3E?δ3HZ} Ğс=}^cZhaPuP \QZk~z}fG|a7s-ܓp ,7u~+s?Ob):qIs8`$E h a"jvb|/+=8ºgЮ?>0 n>KWdl{[d/wF.$';?m5hM}\K.ug{%ɯZ:!\ pmd]S7>wi)Nq}TD&F(jC(Z^xd2{iϳ)TE~)^ Q`ߎCeĘJjB=l?r?K,#i!vT Ac2c֭ZzX-bٞ(Z?W 6_NbzoqѓP)WM+[J/ dBYB6H; 2?Ӈ#qNMeUK.GyI@mf ~J9$`s?.+ v{A|)C\})ԡ\D=r[$8T\dBiD<0ޒ$D6`пy)ݝ3~kƼ* YwUM=ĥAkΑl>u.~^8/q!K0q_4Rgٛ"(>AX%D1xMPnLar=TnhiZN1 *Zs#=[3)G~P͛?Khj*&o D]m]̍d}uFu[GI7@mlɷ];X[+c3yܪ~`3Ûi8i@aSH9i)6 +r5*YeJ'?E͸ Np?k)a:- Bn_J$K1 Rb/=!9jCq0pIZƾVw5%8GEm|skrJ-m|5դ!O9yA.AlGJZ7Bm;R% 3k4, Uq`OuF K`yo 0jVZfZ8VHKYDÉ[RY|˿N$&ѿ^ 9k}?@ J%ꚦM$d kI 9r4وQ%I8j7|2O6TIUB 1зlmʨ?H8 | \0'x#5J{n {3 ~DNRWn,J>3)}ZR664*zO=8% jԯo$'] 8oPE9svI"/9z~<|:[Pp驅A4 JY=er19 LhTJ?Q0("?vI9Lzh$Gh,Oh3Ǩ} sK@RwE-ZnɮM|םر40t܂1/ oK% V]D%PX2;=X^$b|nLv\c t~3|%zFGPr:9'+7m B;/^eu~o%{s +՝茵]D.Y97&)ra ']px<н{4%+$.T'Z:tBz9@#rBxDWOwd؉zPqS;9$<_rԏ.Yv.fdt` ӭφ5vn j }o #VPĊVtl ?j#Xh+o%Kf)wMϽyΫblWRO".>.4'&}7l^}ݯ矄4)A鉤%6QSQtp-1#+D SXn00d&jĄڕ;y։Γ=+zv*@b` 'FRT ._V.^^PkW|'s4(후,*lQ6"cT?; rgӤ: w5U2jZ>S`mM"d%h78,VШAj`8WJSF ¦d=l^bw07?WTUcT 'BѬ^p>h48 ʏlf*T8X(jJvI*խ30IE"*&<>5 JG|1Kln|%&"G_ `(b(D,vP C#x*dzI;囖4C=~$X64ar*Y_,àAB č=־8jb\y"O~o`CI (_YRj쏱ti .B<MjD &U=En[f^G|9i\WjhZn({6hW^=V@//M5+#_,x-riv _B8 "e&ѮTzN;Z0N>[q汯l̉b21b{2¼^xd:w%M8A+L<)H.STuI>cjPI)BJb\N*u}=ͤp3X_$͟v*lS V:;jю)n ℙhiuR"X).O׺N2GPq}7]OpRcY BNm|=ŷ1``tt:l. .ͦǽ6ZS?x ]icʾLT;-ۅ*,ܳJ2>[N)4Ddž 4\$^խhZJ0F{Wj_yٛ۩ɳ d;:~rpa5%o7!;`ِj.z~_{7 2((H7 CwD6B[v5xG8O })D S+87vH+7OX[]v(E0CV]ڎ哤a^ Q7Xp$NDs<Xit\S4?X{p2>aPe/Yݫfa[)|5xvz, Q2߼>=[Ss4هe0'wd&ΜAq~δa))ՌHw1]sc3TTBy-BR- 7NV6?TZ8a*2իٹ,OѮG~̑9+%bz}|<fW&?AkD65kOx.Ao 'c'FbpYSEAdBOqi/˨G1Fz}#k9ToW嘾[sRU!AJ}ԥ-|=,BV~IMqMNnʋ/밐xA6\+LګîYsy& K`aO{G Jz?@v΁L#8dY7moNa @1īJ+ǡ;CΊ|L9w&I_PKgP}TR i2As`tׂ lD*ج᷹Z7``"BaN? >SsEM@ J ؽ^0 kC_[)B6:4QTXݪ2ѝu~M6l9vC_l ͌ )/b2 ҀE\Bt@.lM7jKn gu]f,!J7u (<2fT+4f&s-G@w![ :Nj\hYli=IGjOWCut` `u$\sqfBpK7Jvp:kN Uz7OD,>!6^R'7"?du;YjWnCq4e~7RxwVk ~MwH/}Noy|( р^ C\ƌo5V0U ^Tk:S%A)}<+P'/,cB7iݍ>.0b%SEI3Td*}c?SJ8{|dVb<`ƧCHuJI!&1l lՉ/r{7 Ԁbw8”MmzRLR1;DtoyH(S< 2N֐nE "9k&D?Ew< 2iiŃ]Xxۂ{de)&CػR:`S"W3snKBJw_+;Wx;^;Jɻi srӁ+&cdlHR@G!ډ*iuRSDΌ"=cCkz9Fܲ)d%2!ZI$yaRn wpcW]G^(Q޸Wi[>RhFT mRyB\.niyun)0QmX<ۉ!t^S|􅻭O7rҘ85rE2Fb aۈ|I{}P&.q{@oPܒHƥ " AeOZKcUB=2vC5E' Lr*'exjtt.9g&kyI<\A[/x}!g}z#R f= -ٵ_z/4у h03yKHtW$ 42w^74yof7x /QΒdAnf7b]YrHt2/@w@3bS̀z3#m׶oIMAG^F.:Ջ_鸨 @ȁ Bs(Ib fuxv2}|OwUNgIk+D b-AC2ǵ0 + 4 꼺D!XdEI3kffAnT& ekV~}F{>! #sOh h磬mXk[Dx* SX,4L[BX^M 絸:hGft2;T"b/ZYҚlrԎp۟͢kF,[p =S&tCˮF>Xo$̋TNfL ΙSTj܀ mypJ ?UvE Xax xFl# A2{FiH!#逡{8 P㧫_&P[Qof>kAl$(/Q7~,s5l6# cufys?@"?4M_FZdq| a7TY7ƛ+p?|1ZR9(CO_uG}‘ xqV/8C wg1x8pr@HT*1_e+ؙQ>\@;o:We Yo hY)2I4& KDr+ Pɉ&[A&ԬQ9-u= 'hJFǷ / K:c.|xS݋ں k|2TlP!2;Jkf rQcNtm0&3'w ~})Xqt23SYƻmVgb0^Zkt-z sBsc&ȩYۏA [Yem"!L#{ *f lo1z+w#iHl&bi ~ 6b}k.6;ӄlKٍb%w'{>L;ߍz? cTϖ;܌ϟ>z,lo=PIF>{A+2m pC"Mdh\$x QQAC}tQzש6ohXR=;' v~Ejl{PCTgENƚO)_]JC\b [c̯̲ 5ۘ9|W*|T6yU=2Nc8;/:NsJ|ƒ%Ixs"0l[2 jĥ  ng?4͍:?4Wf3'Z8])NT\$H[CF6?HOjjqRu}wN1w]Hk M9wxՖ˹ 1v;"=#(U@Z^wUTZ`!麐oo5c8%Mr{Y* KЪtK8dap&>vZ WKތJ;,:A,I>PYt_*by|~ uЯ!n|D LZce@m䔏SZ-ۧ:Oݶ.O*/<nu#Nipܵ*v+w-ޟVے? ߛhp4=2K:ο+odq0ZRyr3=j=5 {1U|" o,~[{ʹ惼TIBfvZU>83(f@|ȴQ!j46Uⅺ&>lVAkĤN2J 磲Z{}iJ%QSFS#hG Jd?uUgE.)( EfBff:%&¿ :qkWr±k/ęgqlg [*=U6AKGZ]~F>N47so3TrPU֋ ',&<2Tߘn)}*]vw|;Ƶ M]-[A08N];)![ȓy޺Eƚaψy vTW S҈W{pWˋmq&L}7ڙ/J67i;Z!dI Dq>.3Mu~Nς'kPgtΥgOG0+ȒA)Gݮ{kfX0@eڹuT|0 Mσ7?I`llVW76X?&* Z%C9y2;nC5FY-,#"ځTȒpYrR8_FT'ogC+)(FQ@7_)iB7VI?7]odA;Q99Iumc!Em'ė}ET^K8m~%[b6nw<:%)х#޷9VLK4C#} pH |_nT FIvYr5co8Q'&kkIZrT,){ODqcdbᢣpp47C)) l5=E9O">un jy w*'nK\,&<%laBkd(<:Ӗ^ڌB˾uйG_ֽc>=w(5dzȬ굋 B!0y5j5ݼV rzJ.MDs%9:Pk'r=~\ htp|>-O,g 9k>~q7Nuy9Z,}e66鹂tV83D=.;UNG7F~a絡 KfD2S~oi0۱8Ǹѝ#}[h.BS92s\5)΍alHGeAq&}'?ļĕ=+QZX/1_ek+[ZU7,ڀ͹Z9477饡KU;<yVNQa#U[0u_GS P_cqyP׵n‚ ~D͌XߵJy=WܴPm̞vmc>mwN&=jOG~po_U޻nHxg:2kP6;c曦ucI,D\~dįBf%}VrZ:ؙ3&s9]e^6.QV z150;X, C¶r|mW3NTGe]\|>?ͪZKRTmU yDگ hGM\[ JFz2!DU~NXK n˼FVob!y7Nvo~$l !W;dV|D'E}=}IJcj*7.-6_Vɑeť{d:H˛-k hGotM cZ->x ;Q/gW -(?7w%uu-'k] [Pz1gLrsʆC"U;m! ۆf#y!(6 }[9h-1>Wc= BdC:ΉL+qd˟?B!Xۄ{HDK_׾Γ9A@9`hXFkIy9F T*"|D"o\xk%cxXk~pmpLӸ )cΐO`Þ_n( G3S;OJ(W!11Yj,¨2Ql}*j?F]$( w/3Qp>B\ d~rĵh5I1FNs njzMKYDrkMg(CNPq+31>]&"3s)%teǽrJ'jW}i-^Cq48Ʌ7Nȗҥ^%\ڙD)QpZY&}Aa1BEFtwg!t%|<`e@gR| :`p=!ShBO?YI',f3>c:30>opЕ1l]U.d >{4 q`П/ΥDʎc!Nzd cRDILzTt"9;OO izq^?zIÍ.$] L.+xzB/DaF,ȏ@?҅d[ tUdWgHܶ^„fkս^؀zvnr5}K;O @u1r}݂:`[*x96obAcI$~7y*Rs̓Ay˶/;1dE}E kb6)ʹ! §**sfIl"}~qoz+!8Ѧ>ϳI!tΈj;g1y{c"=J8s1չeN2g{^2K7'&S[,`ş\?>3:1+O1A[_' J`x}XxE! Ŭyrea8䶀vƵXsR9D!*Z)_6I zXY(@?c5#'H\Ŗ|^aYZ}T`R~UʨeY񱶙6PbD<Oeo~VɨbX& 8 I&E*AyT2FK/s!"Ay94BB'@3Q;ʘq>T=)dKd24!l$UmY\G#^ |\R?\j;e/~ws 0PX\d1a2'MMV 8 ֱOߩ3E4G%{\bfj!,س&G ?2ij;vi 1 ͙y8;hS`t@A*>4Xt  z6/FK]0놉-ZC^A:)aԻ)C 4'U4T!zKSF}LͱE!g汧bCErD)|Xm^l0bsBNs}MV6aQnQcul&8%zB(8GTUA9f]PE[]yS"Zh~+J?sQ;95]rw^^q@b 2>BTMn7&i.3f _/PQxQsp@Jj}*'O]=חkmJj[q پԗvw BrS0AG!x0A5ρk{xzxPyߋ:}><ō g-^Qc֣F{Eh:Hrq}$#$:nI'?0pp9BqaEq=Y;4N䗆i߽ImG&i ooJ/GcmVbGnpIr;JtDcr_4ūDNyبeޜqAl`b`6d¸,Ts >:sƯ?}J`y>U5k l3lKP I^bA}B+,y Nk;I2҉uR$8%0Ԋ[_2:IPVw?u9c<57:b<]'BbB sXQA<#m'h;+ӂ Sd"1bMShy)d\wfs(%|HtN?IYI%e~H?(NVw .XzxDzmm=*젯mDxŷ1y}|$yY) RƘF-ǗEϰO߷ nˑ>L_JN6!cI9>&Qpֿ;n#)IulS⩲n8@KšUGzxW:nyC[~fQɮS/p.~. sG/8qw>{~s }JwUMQß ;付3)!a7ͩZ J_8#;9oV'>{{ ųDESn&S.eT߶zZxe)2/3崀J``:8$+ożu}h7[  ki:^F^spIh=3߫ت{0ZJuF0r%R XZ|i|Bsz&> ~dEW)3`GZl뒳(gkR`I w)j:>`%2w5RS;}FbojaEvلFmUFf{4!_v"tN٬}{.Þ옾j֡onz\񲆘9OF%WPu\Jtc-L %%D\ az|;%O}_GAӾĨYPG?tasmr3HpDagah |(ZL|Q1qC^*I `Y1z҅? +.QOX(SjcVW=HϛJ^Xs ?*T׶`;!4DDJRmvL%- MImjlǵ;7 vf^Io2r-GXˢT0ZngGt>as_"z=Ń %7o]1UƜьxq>Ż5hލgWF7;J)" ly"n3B뎯0^32ּR͙L)]jaJٰZ.dkN%@}m[r:93lQMQ^td^heGbR>'yx ɕ\T'ÿ raFV_Lq|? 4+,_Y1:;Eg6~N"߹׭]M9E_PYtL7RkaھB,l_9*هw6VÊ u6֧€֨1޽IwfRJq_XKt l {Mwzzt2[4䀲k$<NɽH6T)roV6.Ԏ?*}~?]Gv$$xgؠfYpH0/ЉUviR`׈ N&'h!`uSyglI|3vaE8Voc"D>$$h/I %Eo]65s6 Xk C3ȗ4b! wo X5=AOVVi D*'dWb-h TD aFZoS)=74ߜ-¬|~} \Umte'*SX?7(#Lnov̚8MRjCR"gtA"Q)`+TL5Կϑ-h3fH2-ѳK.PYxۻ<3xF7\qɘ%p]YDO%nVY2o `'EDz0ܞ{(KTo/:2ud$ùÊdCA<8G@,Ա_klBLg^ix~E}=O9WR#",l`WghK+! Gy1x58=?OȇPHM ]g \7/926x6ECglԃJci9BK{ ﳯOgbmf:D'𹥖? Knw@4=Aލ]$ Qyb8H hI%v _ Rڬb,3Ne$131ĹVY;6dn Yghf![r/c@b@uUj)x[~߫isCH uzCG 7:ϙ4Q_/;&jt=/2a> @%6yO;gKٕ*6JTrjG\/QY%p|X5y) ?"yXCE`crࣺKtngMu+ fx55>pYN1C>0P:Ce<2pFɝDZNje7a׸oZ8]`G+@%07Z ;lHzԄdY)|BY7hiFG;v'Z6sL*=uye/m#iߍIfCB;a-[;9UlVCxl'dX02>[$%abpbC5A,ңa컁No&a$eUb o3;1w)AZHm_@/KGH"]4^4 i$|iƩK2]]Һl]1Q/uX}pE ۤP4WU/:$if:W/lF̟/7"zyRNTnc)7y4s8k׀)Ha5L:~cҹ sl&cx' Z6:\rՒ?tgY-pzDŃSe+Z*]ԅ 4rU0tEΟ!.AL i޲>/|=',\ P27,I׍%apۆ j㥦pVWBg̘QYFqpPQ\7 "AU[o!$ąefXC[Nd4$uԮAC`{Xwk9f+m zH@g=Dxuy%EVN#_<)Y@c gWaf[ǺݤeY1a(Gl]~/#ljz #̘qɺm&YYߩrkd2Υ.&f_YB5Q|즱Evw:B[XcGe agqeNgb8qR;ß>·T,%%I;ؼ`Q , Z5')ޔ߷Yp$vcE/í49/$xusÀ%2ba0UO~ɽ !ZX~_R閝Uh+D7ɵgIQk]\Ѯ l떶 ga]BF¤ ֍݀ #V?cЁrѦD14Yۯmv'aKpJv<@ 2!_'F7\ Wݕ|g1u1e>u2 God52J ew {'2E.di?7)JdeĒ;ɒ%qe_6:Nqi3?.FNZZBA;bXxC`ũsi$]'γ+}nԒ#\7a駳ÛqC聏yU1 xMOSӁ*1Z:6WDL{Z ^5: %X8 =D&1q}e® vK0h%MrWn+LŽjz~fk_ۓʢu9 VrLg7H8$~ c ?(#+#g8}oMIx\Dtq3=$svQ*Ғ -{'*P|5B#Pt-/h973JҔtgl,t$vB <%Ub}G 8p$ $B׺{v;7h6sEDڎ)?Ō-vϰ3yFsCY*I8K- ~:jD+ ` ro.3l.?9+W+eIm^wuKxȷ/qIop -¹1B}#2QܑnwEf*0iBm͝TiUԌ ꇏU5˥ϕ`U0CxX֗}@E#;!" >^ -lW>mDk)ly,=zvv"+) Ax"璒ʅlGS_Uq=-q[ 6rrX{Nߦ6-p]hZ/c'T1w+Sḧsbloyt+Į^)o=+Cwj"\酓41jndHn@Ju~}v WE-<#o7APRq,f>ͼ_vp_kt>$Q 4|'c Z,pI7kMt za4X/"vx * ' 6:o#myވ`\"qKbB?l,nkw)QlMXi7;2>o\=z&.Crl%.NUftE>~S;tt):dod oWΨϐ@(HMv/C@C6yAF! ~|r[CT#Mȧƕ[N<̈́X| .$Oրw"D{>P #R[uC(8Ѵm|B @W7*M$>_NKtX6XfvZ,M7^Wdǟ5ߨ0+5x4I{9xz'SqKTu &%'g`Z/ ז Fg)4vֺ V fkAuՕϣ)Rh3GDk-qԷc=v.rm f͞[:0[w,V _-&ʜ7+(7Y[|z$N3DD8@.J_]̸;Wmj|9'uȄd h2y"$kgݬːqf6X\ @/jHXWX2 _"6MCࣖIlgV*B:(]VI2+J]ءYGrY&=CG"5^9:\1QQ"]{#+5%dR%^w7-ŗamaByfLk>6!n:aAPM@?tUD4]% f)br$`2N]K7Cʍj B@b,ᵑT:8i%%u+>I({QfjFϤbNŚ_ZUUL;ð '+( tZK{9pR7j]!)eS zU>h9 ѠFL`|*g#n9oK"usɦ5Dr>#&>Ƽm$ܮg9J{s0xtҍa [ Dۉq7 xßm0zo+Lص2U#n/RO95hFd'8 4zrVYcG !Wީ1!lGrw:o]y{}Ka?2K \n7g__i[2y nQ%bS&q%8qRvHPKLg(U0neo\:kv_ABxb ** |/;FBVY^;e#PDĥVv)GA8# ~v8,hP܍<,VQLc\̗0P5ǨAO᷈= Dq) WΜu 4 _e'bZx2*;O1 |'Otu_X͝#O-vq Uݻ$fGGhO 8D\sY}ƆTH LJ3aq*ψ*Pv2A; ^X€ܢa'q/0_}< ] _hlGkJ1W-Y~9N1;2û=.*Hq*_pMbdv(=XV dzs1$Vzdk=%Û3i7j+ 06[&͙bI ^' ple~-DV8R-a+iFSї\S|YmLHX|GS¾XR:o2b9D{W̦Qp jo#񯎣\6w_JqXؽiVeRr/?b^!mL@S^Q]FR`ܵm?l"LMZ"<(5='2yPuo#b05;/ l4?kHU `q8 nˊuM.YZ~0ω=jyc=})ep 6g% vqpC dc=_{Bry0鿪Y ːtDk\]/(_eujfE ev X2V7.1~\%DTai%Ј9lͤAmtōȫ\n k?9;ķJ3Jfgq.\N B4OwZMly ګHL~Ojv"-~'VE 6lRUՏo =Taq#2I<~?ZbDsFY/c7Q@.{w>$(ĈBC1` E?kO3w|{[V. LBxE%6*sa5WIw 5[yli|PWIB6CeSEeX{+5W1Yv~rIbeRu8MѐA;^(Qu !ޡtkLZ6zB I~?Uf ~tY?Zd鿿,S;Ʌ\qn; $n1 'ǟjcSI=n!Y-SYmtS4dĈIY]'Vhu'݇OhV7lFF {sqd Db&ORsƪ<% G;T垶|$j@Ù'*,~M%V Ѳ![ҋ/W]x_[lO5&"S=.ќpfϡSpN;ӲC f &汁UJsij+S1Czqˇ:g!lo91*N: Ka"j%ed@8(kTp#b~`ABq (_᭙BEo{F:%TzM|wc,u% d$\܀C|Fs괲!yYkx3@rI$:<#a$$(]_{>*qZyG.k x2~%muqVʹf עP_gAzHH~yI7|5u ޑ2mi>Թ(x1zƟI/4@]d~~z&HDubue&1HR.)J}C439JkF2 <n%6qfJzr|{Euլҹa7(TV]k ,|6FS y$c$u0oN>[:2G`L_l=<67Vip4g|PFAS HW|Z4F γ1C ?7$onGZ !%}m5~zk  04Bj58AͫJӀ9/k+Ͼ_Cp;|D)3k0jY[|K䚃)my haUYGmGZiLH5íxc<9 Ax ^kQ[+ol†c( KIO;'{/A6zIqHLVB,.m /F^>b[F]OdhN\^b=T%3h~ݏ?G/#^C|P#}(*vGyyPEbVr_>(&`O^54هY ]>K犬iQ<Φ3N.XZ^Wv=4iea}|CgB~Ϊ=pٲg6euy5MnG?hy5tHk6~Gj2+CY3KS@HfaF ]g┠R9@;5#+y;ZQ:4kx_GI%փ;[瀏\Ih?sQo^F?r?) ]<8Y{ BK*N/DT}>ޠ)?^D|Ź_.72fL{2|[WW/8'vS%qc5jFQZM ?u%'^S0z?k0ZJ3zJFo&3bFkBp~X K<~/Qn9cmE\s\}J/ͩzgAQւK0 y0VmH:Cq! z: O_a1D3b'R&wbxTHg36,;K brZ-ÌVb кzcFr6Ա1)Ps*L)q;SbrX_Cƀ*ԆU|CDj' ۿ%<7+/w0CKd9j Xrug.|J875?q'x>GVڍ}pJ#W#M \id٨L)M֍iވ}P68w먽CzHW.Bt̎T)m!me,rmś։L?V6\t\HV7!KUNS^pBU ܖ{sTh~)%vdyKަZhUcUK^P_犐=j9+/b=pPec߂ç7AMpOj+`-o  X:L:pT'DD4+/3״{g2bmPUTfΆ;O5JSK%eHeڣ2>5)4k veшiObjڋtԉ z"]3;*ZOP_!1:8[L7d9aB\vE,"^Ь5~I?%S[訮K[9q@1!nTEN1ws1D+F%VKprq+'tBE7k#ֿgb'e'5LR7,QثY6Ր!.I"rKD$rLTH_vUl)~b3fKmFik XF&7^" ژ7t>S`r =A+ʒxR+DnrNN.>~I/ {tU" 1!pfh2qw:I j9n6B[/QKP ~|ON&G@.E2Z)Uh͐N!eƢg\5͞Xk~XM/꒞H2^ 1 ~kvaRp&E!ɒs, N(Eg. l&ܭtug'm^*^P1'_UvwfՍQwm a2!ωMưkhć6 5x >Faw(\(d3B8N}2W+9O0J=% tG1e4j4"p@ʑ}ݭn0vh# u'Y(n_~ 3?lm_PQy`6D?$~!!x*a;iK XoW| k8W<6k78CRί{6 &C5qm$z C!L?ތo:A>2No $'o\O-m$Ⱪs&{ѩ0bM'|vBCtloNFcX, ky^=]TDbөx3QZL`_`"iٽ BR|Dz,iv2٪@(hX}]Ig/FbC`6qBU$XöǙ_0YAT\ ㈉fX󅶈% i=#<|Q~I[D;`I%i8'KAA+FAC30LQeE9fq8 Ct5;,n?8>2Aꀐ:[;T `" fvg_8~ s``EYxsz:/#ɘR0¡d˳۴#2/.΁4xD.J#SIF%VHռϤ*Q:onOvwK[²%t8<, g }gwxw?xծCljV3e ^m!.H1ي:%^ח]3{Mo dwz*H /X$pM><Wlr;@Z~.I2}FjNJfg݌=L" 0Ƹj00nJQ&eE\ Ήt-le;<w-aAr#03X]BӃ&5[cGCyxlxڞ-azˀB\lN&kR*1%Hu*۳3%b-ҧ8ZLͮ;Nc $i} D؟ j )8Ya򗕨kXߏ؉G“>Gżrg7 fۆŢ6.Taиҿs1‰x;,#qє\ 8Gik1dZ UTD2v"U% IB2zz,N͎ &g7 UۂZ<9c$ ?aDiʆ8\lS!1l- bɭlS{ GĴXE'jl/`A``lDb(Wh  O䨼\*!p|VKc? QY1vzĞ!{+=UD,GholМe!. 7zkk6XaoDGPbtB2y[C< ᦟF/9 0d'O+ Vwrs@l:rERY:xE]'zZpcsǢHI,iՌ7xmnuA!.D(K>=lLbOАh~,Pk=Ir\nU=# }=Zjٹd ܬy s}32 ӿ/.^[Ƃn)k AISʉ13sB•C6⼸F@6(?X]s-LV<x"|o e0(DӰ C`x^#;(qQLYū5qjKnEBR5 `WSkۜ1qZ/Φ3/RT$ kAKG,3kW@ :XG;(HwG>N\?yH5e%:t0\ ‰OQWWas}~YJW9]|\_QʐE=:ᙟr4 dH\ntLeRrUZJ&ogY&j ߕ%j8t#1F-7N'R-j1ƍjs$[QUxnNxvkKLfm5lԓ'^Vb }fBmj Zk㖑\3_|I2y[OP VPg+m4D~' )1>ev3jM劼1y+MECҷD_\2wT3t~$f{ <Nj@B3(Ae 0!'G&麰}È|K4vUZ Ԥ Ƹ(;G;D6 t~al7:_0$l't5\,# _HcT,1ORmPB2đz4[h!'ԓMKsՔFOeGᘑZxA^r~Q>y+o%4 BQ&` h8**}E; _h+[1[~JjJ7Zo$4XRPCvV.L߅*mƮvKȄAt;V["EV DQ~Y7x\'1ԝ6_JtwC$i3 NQ DuHv.B=%Ъ,${+|I$9ZF^B@vd2)+ꍧ Diem]A}Q YiG˰.F,dž?8i.Ak Cj-1?fԖ^5%kϾ =$\6g)8]R׽5Ɔֲ^m^ w(rx+א22V3!Z;s)dg,o Ŧ])?jȵ^鍎v봀BC9!͊HOf!3hmvKN96U>s\fpTz"9ӕZrjG 0Pzg l3>Nb(GS#kgHz#*(x0IlHh[I Y̢dՒb PҹȱZTkyw׆:'gn kKV"]A'q!:q΍ .w YZ