123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989199019911992199319941995199619971998199920002001200220032004200520062007200820092010201120122013201420152016201720182019202020212022202320242025202620272028202920302031203220332034203520362037203820392040204120422043204420452046204720482049205020512052205320542055205620572058205920602061206220632064206520662067206820692070207120722073207420752076207720782079208020812082208320842085208620872088208920902091209220932094209520962097209820992100210121022103210421052106210721082109211021112112211321142115211621172118211921202121212221232124212521262127212821292130213121322133213421352136213721382139214021412142214321442145214621472148214921502151215221532154215521562157215821592160216121622163216421652166216721682169217021712172217321742175217621772178217921802181218221832184218521862187218821892190219121922193219421952196219721982199220022012202220322042205220622072208220922102211221222132214221522162217221822192220222122222223222422252226222722282229223022312232223322342235223622372238223922402241224222432244224522462247224822492250225122522253225422552256225722582259226022612262226322642265226622672268226922702271227222732274227522762277227822792280228122822283228422852286228722882289229022912292229322942295229622972298229923002301230223032304230523062307230823092310231123122313231423152316231723182319232023212322232323242325232623272328232923302331233223332334233523362337233823392340234123422343234423452346234723482349235023512352235323542355235623572358235923602361236223632364236523662367236823692370237123722373237423752376237723782379238023812382238323842385238623872388238923902391239223932394239523962397239823992400240124022403240424052406240724082409241024112412241324142415241624172418241924202421242224232424242524262427242824292430243124322433243424352436243724382439244024412442244324442445244624472448244924502451245224532454245524562457245824592460246124622463246424652466246724682469247024712472247324742475247624772478247924802481248224832484248524862487248824892490249124922493249424952496249724982499250025012502250325042505250625072508250925102511251225132514251525162517251825192520252125222523252425252526252725282529253025312532253325342535253625372538253925402541254225432544254525462547254825492550255125522553255425552556255725582559256025612562256325642565256625672568256925702571257225732574257525762577257825792580258125822583258425852586258725882589259025912592259325942595259625972598259926002601260226032604260526062607260826092610261126122613261426152616261726182619262026212622262326242625262626272628262926302631263226332634263526362637263826392640264126422643264426452646264726482649265026512652265326542655265626572658265926602661266226632664266526662667266826692670267126722673267426752676267726782679268026812682268326842685268626872688268926902691269226932694269526962697269826992700270127022703270427052706270727082709271027112712271327142715271627172718271927202721272227232724272527262727272827292730273127322733273427352736273727382739274027412742274327442745274627472748274927502751275227532754275527562757275827592760276127622763276427652766276727682769277027712772277327742775277627772778277927802781278227832784278527862787278827892790279127922793279427952796279727982799280028012802280328042805280628072808280928102811281228132814281528162817281828192820282128222823282428252826282728282829283028312832283328342835283628372838283928402841284228432844284528462847284828492850285128522853285428552856285728582859286028612862286328642865286628672868286928702871287228732874287528762877287828792880288128822883288428852886288728882889289028912892289328942895289628972898289929002901290229032904290529062907290829092910291129122913291429152916291729182919292029212922292329242925292629272928292929302931293229332934293529362937293829392940294129422943294429452946294729482949295029512952295329542955295629572958295929602961296229632964296529662967296829692970297129722973297429752976297729782979298029812982298329842985298629872988298929902991299229932994299529962997299829993000300130023003300430053006300730083009301030113012301330143015301630173018301930203021302230233024302530263027302830293030303130323033303430353036303730383039304030413042304330443045304630473048304930503051305230533054305530563057305830593060306130623063306430653066306730683069307030713072307330743075307630773078307930803081308230833084308530863087308830893090309130923093309430953096309730983099310031013102310331043105310631073108310931103111311231133114311531163117311831193120312131223123312431253126312731283129313031313132313331343135313631373138313931403141314231433144314531463147314831493150315131523153315431553156315731583159316031613162316331643165316631673168316931703171317231733174317531763177317831793180318131823183318431853186318731883189319031913192319331943195319631973198319932003201320232033204320532063207320832093210321132123213321432153216321732183219322032213222322332243225322632273228322932303231323232333234323532363237323832393240324132423243324432453246324732483249325032513252325332543255325632573258325932603261326232633264326532663267326832693270327132723273327432753276327732783279328032813282328332843285328632873288328932903291329232933294329532963297329832993300330133023303330433053306330733083309331033113312331333143315331633173318331933203321332233233324332533263327332833293330333133323333333433353336333733383339334033413342334333443345334633473348334933503351335233533354335533563357335833593360336133623363336433653366336733683369337033713372337333743375337633773378337933803381338233833384338533863387338833893390339133923393339433953396339733983399340034013402340334043405340634073408340934103411341234133414341534163417341834193420342134223423342434253426342734283429343034313432343334343435343634373438343934403441344234433444344534463447344834493450345134523453345434553456345734583459346034613462346334643465346634673468346934703471347234733474347534763477347834793480348134823483348434853486348734883489349034913492349334943495349634973498349935003501350235033504350535063507350835093510351135123513351435153516351735183519352035213522352335243525352635273528352935303531353235333534353535363537353835393540354135423543354435453546354735483549355035513552355335543555355635573558355935603561356235633564356535663567356835693570357135723573357435753576357735783579358035813582358335843585358635873588358935903591359235933594359535963597359835993600360136023603360436053606360736083609361036113612361336143615361636173618361936203621362236233624362536263627362836293630363136323633363436353636363736383639364036413642364336443645364636473648364936503651365236533654365536563657365836593660366136623663366436653666366736683669367036713672367336743675367636773678367936803681368236833684368536863687368836893690369136923693369436953696369736983699370037013702370337043705370637073708370937103711371237133714371537163717371837193720372137223723372437253726372737283729373037313732373337343735373637373738373937403741374237433744374537463747374837493750375137523753375437553756375737583759376037613762376337643765376637673768376937703771377237733774377537763777377837793780378137823783378437853786378737883789379037913792379337943795379637973798379938003801380238033804380538063807380838093810381138123813381438153816381738183819382038213822382338243825382638273828382938303831383238333834383538363837383838393840384138423843384438453846384738483849385038513852385338543855385638573858385938603861386238633864386538663867386838693870387138723873387438753876387738783879388038813882388338843885388638873888388938903891389238933894389538963897389838993900390139023903390439053906390739083909391039113912391339143915391639173918391939203921392239233924392539263927392839293930393139323933393439353936393739383939394039413942394339443945394639473948394939503951395239533954395539563957395839593960396139623963396439653966396739683969397039713972397339743975397639773978397939803981398239833984398539863987398839893990399139923993399439953996399739983999400040014002400340044005400640074008400940104011401240134014401540164017401840194020402140224023402440254026402740284029403040314032403340344035403640374038403940404041404240434044404540464047404840494050405140524053405440554056405740584059406040614062406340644065406640674068406940704071407240734074407540764077407840794080408140824083408440854086408740884089409040914092409340944095409640974098409941004101410241034104410541064107410841094110411141124113411441154116411741184119412041214122412341244125412641274128412941304131413241334134413541364137413841394140414141424143414441454146414741484149415041514152415341544155415641574158415941604161416241634164416541664167416841694170417141724173417441754176417741784179418041814182418341844185418641874188418941904191419241934194419541964197419841994200420142024203420442054206420742084209421042114212421342144215421642174218421942204221422242234224422542264227422842294230423142324233423442354236423742384239424042414242424342444245424642474248424942504251425242534254425542564257425842594260426142624263426442654266426742684269427042714272427342744275427642774278427942804281428242834284428542864287428842894290429142924293429442954296429742984299430043014302430343044305430643074308430943104311431243134314431543164317431843194320432143224323432443254326432743284329433043314332433343344335433643374338433943404341434243434344434543464347434843494350435143524353435443554356435743584359436043614362436343644365436643674368436943704371437243734374437543764377437843794380438143824383438443854386438743884389439043914392439343944395439643974398439944004401440244034404440544064407440844094410441144124413441444154416441744184419442044214422442344244425442644274428442944304431443244334434443544364437443844394440444144424443444444454446444744484449445044514452445344544455445644574458445944604461446244634464446544664467446844694470447144724473447444754476447744784479448044814482448344844485448644874488448944904491449244934494449544964497449844994500450145024503450445054506450745084509451045114512451345144515451645174518451945204521452245234524452545264527452845294530453145324533453445354536453745384539454045414542454345444545454645474548454945504551455245534554455545564557455845594560456145624563456445654566456745684569457045714572457345744575457645774578457945804581458245834584458545864587458845894590459145924593459445954596459745984599460046014602460346044605460646074608460946104611461246134614461546164617461846194620462146224623462446254626462746284629463046314632463346344635463646374638463946404641464246434644464546464647464846494650465146524653465446554656465746584659466046614662466346644665466646674668466946704671467246734674467546764677467846794680468146824683468446854686468746884689469046914692469346944695469646974698469947004701470247034704470547064707470847094710471147124713471447154716471747184719472047214722472347244725472647274728472947304731473247334734473547364737473847394740474147424743474447454746474747484749475047514752475347544755475647574758475947604761476247634764476547664767476847694770477147724773477447754776477747784779478047814782478347844785478647874788478947904791479247934794479547964797479847994800480148024803480448054806480748084809481048114812481348144815481648174818481948204821482248234824482548264827482848294830483148324833483448354836483748384839484048414842484348444845484648474848484948504851485248534854485548564857485848594860486148624863486448654866486748684869487048714872487348744875487648774878487948804881488248834884488548864887488848894890489148924893489448954896489748984899490049014902490349044905490649074908490949104911491249134914491549164917491849194920492149224923492449254926492749284929493049314932493349344935493649374938493949404941494249434944494549464947494849494950495149524953495449554956495749584959496049614962496349644965496649674968496949704971497249734974497549764977497849794980498149824983498449854986498749884989499049914992499349944995499649974998499950005001500250035004500550065007500850095010501150125013501450155016501750185019502050215022502350245025502650275028502950305031503250335034503550365037503850395040504150425043504450455046504750485049505050515052505350545055505650575058505950605061506250635064506550665067506850695070507150725073507450755076507750785079508050815082508350845085508650875088508950905091509250935094509550965097509850995100510151025103510451055106510751085109511051115112511351145115511651175118511951205121512251235124512551265127512851295130513151325133513451355136513751385139514051415142514351445145514651475148514951505151515251535154515551565157515851595160516151625163516451655166516751685169517051715172517351745175517651775178517951805181518251835184518551865187518851895190519151925193519451955196519751985199520052015202520352045205520652075208520952105211521252135214521552165217521852195220522152225223522452255226522752285229523052315232523352345235523652375238523952405241524252435244524552465247524852495250525152525253525452555256525752585259526052615262526352645265526652675268526952705271527252735274527552765277527852795280528152825283528452855286528752885289529052915292529352945295529652975298529953005301530253035304530553065307530853095310531153125313531453155316531753185319532053215322532353245325532653275328532953305331533253335334533553365337533853395340534153425343534453455346534753485349535053515352535353545355535653575358535953605361536253635364536553665367536853695370537153725373537453755376537753785379538053815382538353845385538653875388538953905391539253935394539553965397539853995400540154025403540454055406540754085409541054115412541354145415541654175418541954205421542254235424542554265427542854295430543154325433543454355436543754385439544054415442544354445445544654475448544954505451545254535454545554565457545854595460546154625463546454655466546754685469547054715472547354745475547654775478547954805481548254835484548554865487548854895490549154925493549454955496549754985499550055015502550355045505550655075508550955105511551255135514551555165517551855195520552155225523552455255526552755285529553055315532553355345535553655375538553955405541554255435544554555465547554855495550555155525553555455555556555755585559556055615562556355645565556655675568556955705571557255735574557555765577557855795580558155825583558455855586558755885589559055915592559355945595559655975598559956005601560256035604560556065607560856095610561156125613561456155616561756185619562056215622562356245625562656275628562956305631563256335634563556365637563856395640564156425643564456455646564756485649565056515652565356545655565656575658565956605661566256635664566556665667566856695670567156725673567456755676567756785679568056815682568356845685568656875688568956905691569256935694569556965697569856995700570157025703570457055706570757085709571057115712571357145715571657175718571957205721572257235724572557265727572857295730573157325733573457355736573757385739574057415742574357445745574657475748574957505751575257535754575557565757575857595760576157625763576457655766576757685769577057715772577357745775577657775778577957805781578257835784578557865787578857895790579157925793579457955796579757985799580058015802580358045805580658075808580958105811581258135814581558165817581858195820582158225823582458255826582758285829583058315832583358345835583658375838583958405841584258435844584558465847584858495850585158525853585458555856585758585859586058615862586358645865586658675868586958705871587258735874587558765877587858795880588158825883588458855886588758885889589058915892589358945895589658975898589959005901590259035904590559065907590859095910591159125913591459155916591759185919592059215922592359245925592659275928592959305931593259335934593559365937593859395940594159425943594459455946594759485949595059515952595359545955595659575958595959605961596259635964596559665967596859695970597159725973597459755976597759785979598059815982598359845985598659875988598959905991599259935994599559965997599859996000600160026003600460056006600760086009601060116012601360146015601660176018601960206021602260236024602560266027602860296030603160326033603460356036603760386039604060416042604360446045604660476048604960506051605260536054605560566057605860596060606160626063606460656066606760686069607060716072607360746075607660776078607960806081608260836084608560866087608860896090609160926093609460956096609760986099610061016102610361046105610661076108610961106111611261136114611561166117611861196120612161226123612461256126612761286129613061316132613361346135613661376138613961406141614261436144614561466147614861496150615161526153615461556156615761586159616061616162616361646165616661676168616961706171617261736174617561766177617861796180618161826183618461856186618761886189619061916192619361946195619661976198619962006201620262036204620562066207620862096210621162126213621462156216621762186219622062216222622362246225622662276228622962306231623262336234623562366237623862396240624162426243624462456246624762486249625062516252625362546255625662576258625962606261626262636264626562666267626862696270627162726273627462756276627762786279628062816282628362846285628662876288628962906291629262936294629562966297629862996300630163026303630463056306630763086309631063116312631363146315631663176318631963206321632263236324632563266327632863296330633163326333633463356336633763386339634063416342634363446345634663476348634963506351635263536354635563566357635863596360636163626363636463656366636763686369637063716372637363746375637663776378637963806381638263836384638563866387638863896390639163926393639463956396639763986399640064016402640364046405640664076408640964106411641264136414641564166417641864196420642164226423642464256426642764286429643064316432643364346435643664376438643964406441644264436444644564466447644864496450645164526453645464556456645764586459646064616462646364646465646664676468646964706471647264736474647564766477647864796480648164826483648464856486648764886489649064916492649364946495649664976498649965006501650265036504650565066507650865096510651165126513651465156516651765186519652065216522652365246525652665276528652965306531653265336534653565366537653865396540654165426543654465456546654765486549655065516552655365546555655665576558655965606561656265636564656565666567656865696570657165726573657465756576657765786579658065816582658365846585658665876588658965906591659265936594659565966597659865996600660166026603660466056606660766086609661066116612661366146615661666176618661966206621662266236624662566266627662866296630663166326633663466356636663766386639664066416642664366446645664666476648664966506651665266536654665566566657665866596660666166626663666466656666666766686669667066716672667366746675667666776678667966806681668266836684668566866687668866896690669166926693669466956696669766986699670067016702670367046705670667076708670967106711671267136714671567166717671867196720672167226723672467256726672767286729673067316732673367346735673667376738673967406741674267436744674567466747674867496750675167526753675467556756675767586759676067616762676367646765676667676768676967706771677267736774677567766777677867796780678167826783678467856786678767886789679067916792679367946795679667976798679968006801680268036804680568066807680868096810681168126813681468156816681768186819682068216822682368246825682668276828682968306831683268336834683568366837683868396840684168426843684468456846684768486849685068516852685368546855685668576858685968606861686268636864686568666867686868696870687168726873687468756876687768786879688068816882688368846885688668876888688968906891689268936894689568966897689868996900690169026903690469056906690769086909691069116912691369146915691669176918691969206921692269236924692569266927692869296930693169326933693469356936693769386939694069416942694369446945694669476948694969506951695269536954695569566957695869596960696169626963696469656966696769686969697069716972697369746975697669776978697969806981698269836984698569866987698869896990699169926993699469956996699769986999700070017002700370047005700670077008700970107011701270137014701570167017701870197020702170227023702470257026702770287029703070317032703370347035703670377038703970407041704270437044704570467047704870497050705170527053705470557056705770587059706070617062706370647065706670677068706970707071707270737074707570767077707870797080708170827083708470857086708770887089709070917092709370947095709670977098709971007101710271037104710571067107710871097110711171127113711471157116711771187119712071217122712371247125712671277128712971307131713271337134713571367137713871397140714171427143714471457146714771487149715071517152715371547155715671577158715971607161716271637164716571667167716871697170717171727173717471757176717771787179718071817182718371847185718671877188718971907191719271937194719571967197719871997200720172027203720472057206720772087209721072117212721372147215721672177218721972207221722272237224722572267227722872297230723172327233723472357236723772387239724072417242724372447245724672477248724972507251725272537254725572567257725872597260726172627263726472657266726772687269727072717272727372747275727672777278727972807281728272837284728572867287728872897290729172927293729472957296729772987299730073017302730373047305730673077308730973107311731273137314731573167317731873197320732173227323732473257326732773287329733073317332733373347335733673377338733973407341734273437344734573467347734873497350735173527353735473557356735773587359736073617362736373647365736673677368736973707371737273737374737573767377737873797380738173827383738473857386738773887389739073917392739373947395739673977398739974007401740274037404740574067407740874097410741174127413741474157416741774187419742074217422742374247425742674277428742974307431743274337434743574367437743874397440744174427443744474457446744774487449745074517452745374547455745674577458745974607461746274637464746574667467746874697470747174727473747474757476747774787479748074817482748374847485748674877488748974907491749274937494749574967497749874997500750175027503750475057506750775087509751075117512751375147515751675177518751975207521752275237524752575267527752875297530753175327533753475357536753775387539754075417542754375447545754675477548754975507551755275537554755575567557755875597560756175627563756475657566756775687569757075717572757375747575757675777578757975807581758275837584758575867587758875897590759175927593759475957596759775987599760076017602760376047605760676077608760976107611761276137614761576167617761876197620762176227623762476257626762776287629763076317632763376347635763676377638763976407641764276437644764576467647764876497650765176527653765476557656765776587659766076617662766376647665766676677668766976707671767276737674767576767677767876797680768176827683768476857686768776887689769076917692769376947695769676977698769977007701770277037704770577067707770877097710771177127713771477157716771777187719772077217722772377247725772677277728772977307731773277337734773577367737773877397740774177427743774477457746774777487749775077517752775377547755775677577758775977607761776277637764776577667767776877697770777177727773777477757776777777787779778077817782778377847785778677877788778977907791779277937794779577967797779877997800780178027803780478057806780778087809781078117812781378147815781678177818781978207821782278237824782578267827782878297830783178327833783478357836783778387839784078417842784378447845784678477848784978507851785278537854785578567857785878597860786178627863786478657866786778687869787078717872787378747875787678777878787978807881788278837884788578867887788878897890789178927893789478957896789778987899790079017902790379047905790679077908790979107911791279137914791579167917791879197920792179227923792479257926792779287929793079317932793379347935793679377938793979407941794279437944794579467947794879497950795179527953795479557956795779587959796079617962796379647965796679677968796979707971797279737974797579767977797879797980798179827983798479857986798779887989799079917992799379947995799679977998799980008001800280038004800580068007800880098010801180128013801480158016801780188019802080218022802380248025802680278028802980308031803280338034803580368037803880398040804180428043804480458046804780488049805080518052805380548055805680578058805980608061806280638064806580668067806880698070807180728073807480758076807780788079808080818082808380848085808680878088808980908091809280938094809580968097809880998100810181028103810481058106810781088109811081118112811381148115811681178118811981208121812281238124812581268127812881298130813181328133813481358136813781388139814081418142814381448145814681478148814981508151815281538154815581568157815881598160816181628163816481658166816781688169817081718172817381748175817681778178817981808181818281838184818581868187818881898190819181928193819481958196819781988199820082018202820382048205820682078208820982108211821282138214821582168217821882198220822182228223822482258226822782288229823082318232823382348235823682378238823982408241824282438244824582468247824882498250825182528253825482558256825782588259826082618262826382648265826682678268826982708271827282738274827582768277827882798280828182828283828482858286828782888289829082918292829382948295829682978298829983008301830283038304830583068307830883098310831183128313831483158316831783188319832083218322832383248325832683278328832983308331833283338334833583368337833883398340834183428343834483458346834783488349835083518352835383548355835683578358835983608361836283638364836583668367836883698370837183728373837483758376837783788379838083818382838383848385838683878388838983908391839283938394839583968397839883998400840184028403840484058406840784088409841084118412841384148415841684178418841984208421842284238424842584268427842884298430843184328433843484358436843784388439844084418442844384448445844684478448844984508451845284538454845584568457845884598460846184628463846484658466846784688469847084718472847384748475847684778478847984808481848284838484848584868487848884898490849184928493849484958496849784988499850085018502850385048505850685078508850985108511851285138514851585168517851885198520852185228523852485258526852785288529853085318532853385348535853685378538853985408541854285438544854585468547854885498550855185528553855485558556855785588559856085618562856385648565856685678568856985708571857285738574857585768577857885798580858185828583858485858586858785888589859085918592859385948595859685978598859986008601860286038604860586068607860886098610861186128613861486158616861786188619862086218622862386248625862686278628862986308631863286338634863586368637863886398640864186428643864486458646864786488649865086518652865386548655865686578658865986608661866286638664866586668667866886698670867186728673867486758676867786788679868086818682868386848685868686878688868986908691869286938694869586968697869886998700870187028703870487058706870787088709871087118712871387148715871687178718871987208721872287238724872587268727872887298730873187328733873487358736873787388739874087418742874387448745874687478748874987508751875287538754875587568757875887598760876187628763876487658766876787688769877087718772877387748775877687778778877987808781878287838784878587868787878887898790879187928793879487958796879787988799880088018802880388048805880688078808880988108811881288138814881588168817881888198820882188228823882488258826882788288829883088318832883388348835883688378838883988408841884288438844884588468847884888498850885188528853885488558856885788588859886088618862886388648865886688678868886988708871887288738874887588768877887888798880888188828883888488858886888788888889889088918892889388948895889688978898889989008901890289038904890589068907890889098910891189128913891489158916891789188919892089218922892389248925892689278928892989308931893289338934893589368937893889398940894189428943894489458946894789488949895089518952895389548955895689578958895989608961896289638964896589668967896889698970897189728973897489758976897789788979898089818982898389848985898689878988898989908991899289938994899589968997899889999000900190029003900490059006900790089009901090119012901390149015901690179018901990209021902290239024902590269027902890299030903190329033903490359036903790389039904090419042904390449045904690479048904990509051905290539054905590569057905890599060906190629063906490659066906790689069907090719072907390749075907690779078907990809081908290839084908590869087908890899090909190929093909490959096909790989099910091019102910391049105910691079108910991109111911291139114911591169117911891199120912191229123912491259126912791289129913091319132913391349135913691379138913991409141914291439144914591469147914891499150915191529153915491559156915791589159916091619162916391649165916691679168916991709171917291739174917591769177917891799180918191829183918491859186918791889189919091919192919391949195919691979198919992009201920292039204920592069207920892099210921192129213921492159216921792189219922092219222922392249225922692279228922992309231923292339234923592369237923892399240924192429243924492459246924792489249925092519252925392549255925692579258925992609261926292639264926592669267926892699270927192729273927492759276927792789279928092819282928392849285928692879288928992909291929292939294929592969297929892999300930193029303930493059306930793089309931093119312931393149315931693179318931993209321932293239324932593269327932893299330933193329333933493359336933793389339934093419342934393449345934693479348934993509351935293539354935593569357935893599360936193629363936493659366936793689369937093719372937393749375937693779378937993809381938293839384938593869387938893899390939193929393939493959396939793989399940094019402940394049405940694079408940994109411941294139414941594169417941894199420942194229423942494259426942794289429943094319432943394349435943694379438943994409441944294439444944594469447944894499450945194529453945494559456945794589459946094619462946394649465946694679468946994709471947294739474947594769477947894799480948194829483948494859486948794889489949094919492949394949495949694979498949995009501950295039504950595069507950895099510951195129513951495159516951795189519952095219522952395249525952695279528952995309531953295339534953595369537953895399540954195429543954495459546954795489549955095519552955395549555955695579558955995609561956295639564956595669567956895699570957195729573957495759576957795789579958095819582958395849585958695879588958995909591959295939594959595969597959895999600960196029603960496059606960796089609961096119612961396149615961696179618961996209621962296239624962596269627962896299630963196329633963496359636963796389639964096419642964396449645964696479648964996509651965296539654965596569657965896599660966196629663966496659666966796689669967096719672967396749675967696779678967996809681968296839684968596869687968896899690969196929693969496959696969796989699970097019702970397049705970697079708970997109711971297139714971597169717971897199720972197229723972497259726972797289729973097319732973397349735973697379738973997409741974297439744974597469747974897499750975197529753975497559756975797589759976097619762976397649765976697679768976997709771977297739774977597769777977897799780978197829783978497859786978797889789979097919792979397949795979697979798979998009801980298039804980598069807980898099810981198129813981498159816981798189819982098219822982398249825982698279828982998309831983298339834983598369837983898399840984198429843984498459846984798489849985098519852985398549855985698579858985998609861986298639864986598669867986898699870987198729873987498759876987798789879988098819882988398849885988698879888988998909891989298939894989598969897989898999900990199029903990499059906990799089909991099119912991399149915991699179918991999209921992299239924992599269927992899299930993199329933993499359936993799389939994099419942994399449945994699479948994999509951995299539954995599569957995899599960996199629963996499659966996799689969997099719972997399749975997699779978997999809981998299839984998599869987998899899990999199929993999499959996999799989999100001000110002100031000410005100061000710008100091001010011100121001310014100151001610017100181001910020100211002210023100241002510026100271002810029100301003110032100331003410035100361003710038100391004010041100421004310044100451004610047100481004910050100511005210053100541005510056100571005810059100601006110062100631006410065100661006710068100691007010071100721007310074100751007610077100781007910080100811008210083100841008510086100871008810089100901009110092100931009410095100961009710098100991010010101101021010310104101051010610107101081010910110101111011210113101141011510116101171011810119101201012110122101231012410125101261012710128101291013010131101321013310134101351013610137101381013910140101411014210143101441014510146101471014810149101501015110152101531015410155101561015710158101591016010161101621016310164101651016610167101681016910170101711017210173101741017510176101771017810179101801018110182101831018410185101861018710188101891019010191101921019310194101951019610197101981019910200102011020210203102041020510206102071020810209102101021110212102131021410215102161021710218102191022010221102221022310224102251022610227102281022910230102311023210233102341023510236102371023810239102401024110242102431024410245102461024710248102491025010251102521025310254102551025610257102581025910260102611026210263102641026510266102671026810269102701027110272102731027410275102761027710278102791028010281102821028310284102851028610287102881028910290102911029210293102941029510296102971029810299103001030110302103031030410305103061030710308103091031010311103121031310314103151031610317103181031910320103211032210323103241032510326103271032810329103301033110332103331033410335103361033710338103391034010341103421034310344103451034610347103481034910350103511035210353103541035510356103571035810359103601036110362103631036410365103661036710368103691037010371103721037310374103751037610377103781037910380103811038210383103841038510386103871038810389103901039110392103931039410395103961039710398103991040010401104021040310404104051040610407104081040910410104111041210413104141041510416104171041810419104201042110422104231042410425104261042710428104291043010431104321043310434104351043610437104381043910440104411044210443104441044510446104471044810449104501045110452104531045410455104561045710458104591046010461104621046310464104651046610467104681046910470104711047210473104741047510476104771047810479104801048110482104831048410485104861048710488104891049010491104921049310494104951049610497104981049910500105011050210503105041050510506105071050810509105101051110512105131051410515105161051710518105191052010521105221052310524105251052610527105281052910530105311053210533105341053510536105371053810539105401054110542105431054410545105461054710548105491055010551105521055310554105551055610557105581055910560105611056210563105641056510566105671056810569105701057110572105731057410575105761057710578105791058010581105821058310584105851058610587105881058910590105911059210593105941059510596105971059810599106001060110602106031060410605106061060710608106091061010611106121061310614106151061610617106181061910620106211062210623106241062510626106271062810629106301063110632106331063410635106361063710638106391064010641106421064310644106451064610647106481064910650106511065210653106541065510656106571065810659106601066110662106631066410665106661066710668106691067010671106721067310674106751067610677106781067910680106811068210683106841068510686106871068810689106901069110692106931069410695106961069710698106991070010701107021070310704107051070610707107081070910710107111071210713107141071510716107171071810719107201072110722107231072410725107261072710728107291073010731107321073310734107351073610737107381073910740107411074210743107441074510746107471074810749107501075110752107531075410755107561075710758107591076010761107621076310764107651076610767107681076910770107711077210773107741077510776107771077810779107801078110782107831078410785107861078710788107891079010791107921079310794107951079610797107981079910800108011080210803108041080510806108071080810809108101081110812108131081410815108161081710818108191082010821108221082310824108251082610827108281082910830108311083210833108341083510836108371083810839108401084110842108431084410845108461084710848108491085010851108521085310854108551085610857108581085910860108611086210863108641086510866108671086810869108701087110872108731087410875108761087710878108791088010881108821088310884108851088610887108881088910890108911089210893108941089510896108971089810899109001090110902109031090410905109061090710908109091091010911109121091310914109151091610917109181091910920109211092210923109241092510926109271092810929109301093110932109331093410935109361093710938109391094010941109421094310944109451094610947109481094910950109511095210953109541095510956109571095810959109601096110962109631096410965109661096710968109691097010971109721097310974109751097610977109781097910980109811098210983109841098510986109871098810989109901099110992109931099410995109961099710998109991100011001110021100311004110051100611007110081100911010110111101211013110141101511016110171101811019110201102111022110231102411025110261102711028110291103011031110321103311034110351103611037110381103911040110411104211043110441104511046110471104811049110501105111052110531105411055110561105711058110591106011061110621106311064110651106611067110681106911070110711107211073110741107511076110771107811079110801108111082110831108411085110861108711088110891109011091110921109311094110951109611097110981109911100111011110211103111041110511106111071110811109111101111111112111131111411115111161111711118111191112011121111221112311124111251112611127111281112911130111311113211133111341113511136111371113811139111401114111142111431114411145111461114711148111491115011151111521115311154111551115611157111581115911160111611116211163111641116511166111671116811169111701117111172111731117411175111761117711178111791118011181111821118311184111851118611187111881118911190111911119211193111941119511196111971119811199112001120111202112031120411205112061120711208112091121011211112121121311214112151121611217112181121911220112211122211223112241122511226112271122811229112301123111232112331123411235112361123711238112391124011241112421124311244112451124611247112481124911250112511125211253112541125511256112571125811259112601126111262112631126411265112661126711268112691127011271112721127311274112751127611277112781127911280112811128211283112841128511286112871128811289112901129111292112931129411295112961129711298112991130011301113021130311304113051130611307113081130911310113111131211313113141131511316113171131811319113201132111322113231132411325113261132711328113291133011331113321133311334113351133611337113381133911340113411134211343113441134511346113471134811349113501135111352113531135411355113561135711358113591136011361113621136311364113651136611367113681136911370113711137211373113741137511376113771137811379113801138111382113831138411385113861138711388113891139011391113921139311394113951139611397113981139911400114011140211403114041140511406114071140811409114101141111412114131141411415114161141711418114191142011421114221142311424114251142611427114281142911430114311143211433114341143511436114371143811439114401144111442114431144411445114461144711448114491145011451114521145311454114551145611457114581145911460114611146211463114641146511466114671146811469114701147111472114731147411475114761147711478114791148011481114821148311484114851148611487114881148911490114911149211493114941149511496114971149811499115001150111502115031150411505115061150711508115091151011511115121151311514115151151611517115181151911520115211152211523115241152511526115271152811529115301153111532115331153411535115361153711538115391154011541115421154311544115451154611547115481154911550115511155211553115541155511556115571155811559115601156111562115631156411565115661156711568115691157011571115721157311574115751157611577115781157911580115811158211583115841158511586115871158811589115901159111592115931159411595115961159711598115991160011601116021160311604116051160611607116081160911610116111161211613116141161511616116171161811619116201162111622116231162411625116261162711628116291163011631116321163311634116351163611637116381163911640116411164211643116441164511646116471164811649116501165111652116531165411655116561165711658116591166011661116621166311664116651166611667116681166911670116711167211673116741167511676116771167811679116801168111682116831168411685116861168711688116891169011691116921169311694116951169611697116981169911700117011170211703117041170511706117071170811709117101171111712117131171411715117161171711718117191172011721117221172311724117251172611727117281172911730117311173211733117341173511736117371173811739117401174111742117431174411745117461174711748117491175011751117521175311754117551175611757117581175911760117611176211763117641176511766117671176811769117701177111772117731177411775117761177711778117791178011781117821178311784117851178611787117881178911790117911179211793117941179511796117971179811799118001180111802118031180411805118061180711808118091181011811118121181311814118151181611817118181181911820118211182211823118241182511826118271182811829118301183111832118331183411835118361183711838118391184011841118421184311844118451184611847118481184911850118511185211853118541185511856118571185811859118601186111862118631186411865118661186711868118691187011871118721187311874118751187611877118781187911880118811188211883118841188511886118871188811889118901189111892118931189411895118961189711898118991190011901119021190311904119051190611907119081190911910119111191211913119141191511916119171191811919119201192111922119231192411925119261192711928119291193011931119321193311934119351193611937119381193911940119411194211943119441194511946119471194811949119501195111952119531195411955119561195711958119591196011961119621196311964119651196611967119681196911970119711197211973119741197511976119771197811979119801198111982119831198411985119861198711988119891199011991119921199311994119951199611997119981199912000120011200212003120041200512006120071200812009120101201112012120131201412015120161201712018120191202012021120221202312024120251202612027120281202912030120311203212033120341203512036120371203812039120401204112042120431204412045120461204712048120491205012051120521205312054120551205612057120581205912060120611206212063120641206512066120671206812069120701207112072120731207412075120761207712078120791208012081120821208312084120851208612087120881208912090120911209212093120941209512096120971209812099121001210112102121031210412105121061210712108121091211012111121121211312114121151211612117121181211912120121211212212123121241212512126121271212812129121301213112132121331213412135121361213712138121391214012141121421214312144121451214612147121481214912150121511215212153121541215512156121571215812159121601216112162121631216412165121661216712168121691217012171121721217312174121751217612177121781217912180121811218212183121841218512186121871218812189121901219112192121931219412195121961219712198121991220012201122021220312204122051220612207122081220912210122111221212213122141221512216122171221812219122201222112222122231222412225122261222712228122291223012231122321223312234122351223612237122381223912240122411224212243122441224512246122471224812249122501225112252122531225412255122561225712258122591226012261122621226312264122651226612267122681226912270122711227212273122741227512276122771227812279122801228112282122831228412285122861228712288122891229012291122921229312294122951229612297122981229912300123011230212303123041230512306123071230812309123101231112312123131231412315123161231712318123191232012321123221232312324123251232612327123281232912330123311233212333123341233512336123371233812339123401234112342123431234412345123461234712348123491235012351123521235312354123551235612357123581235912360123611236212363123641236512366123671236812369123701237112372123731237412375123761237712378123791238012381123821238312384123851238612387123881238912390123911239212393123941239512396123971239812399124001240112402124031240412405124061240712408124091241012411124121241312414124151241612417124181241912420124211242212423124241242512426124271242812429124301243112432124331243412435124361243712438124391244012441124421244312444124451244612447124481244912450124511245212453124541245512456124571245812459124601246112462124631246412465124661246712468124691247012471124721247312474124751247612477124781247912480124811248212483124841248512486124871248812489124901249112492124931249412495124961249712498124991250012501125021250312504125051250612507125081250912510125111251212513125141251512516125171251812519125201252112522125231252412525125261252712528125291253012531125321253312534125351253612537125381253912540125411254212543125441254512546125471254812549125501255112552125531255412555125561255712558125591256012561125621256312564125651256612567125681256912570125711257212573125741257512576125771257812579125801258112582125831258412585125861258712588125891259012591125921259312594125951259612597125981259912600126011260212603126041260512606126071260812609126101261112612126131261412615126161261712618126191262012621126221262312624126251262612627126281262912630126311263212633126341263512636126371263812639126401264112642126431264412645126461264712648126491265012651126521265312654126551265612657126581265912660126611266212663126641266512666126671266812669126701267112672126731267412675126761267712678126791268012681126821268312684126851268612687126881268912690126911269212693126941269512696126971269812699127001270112702127031270412705127061270712708127091271012711127121271312714127151271612717127181271912720127211272212723127241272512726127271272812729127301273112732127331273412735127361273712738127391274012741127421274312744127451274612747127481274912750127511275212753127541275512756127571275812759127601276112762127631276412765127661276712768127691277012771127721277312774127751277612777127781277912780127811278212783127841278512786127871278812789127901279112792127931279412795127961279712798127991280012801128021280312804128051280612807128081280912810128111281212813128141281512816128171281812819128201282112822128231282412825128261282712828128291283012831128321283312834128351283612837128381283912840128411284212843128441284512846128471284812849128501285112852128531285412855128561285712858128591286012861128621286312864128651286612867128681286912870128711287212873128741287512876128771287812879128801288112882128831288412885128861288712888128891289012891128921289312894128951289612897128981289912900129011290212903129041290512906129071290812909129101291112912129131291412915129161291712918129191292012921129221292312924129251292612927129281292912930129311293212933129341293512936129371293812939129401294112942129431294412945129461294712948129491295012951129521295312954129551295612957129581295912960129611296212963129641296512966129671296812969129701297112972129731297412975129761297712978129791298012981129821298312984129851298612987129881298912990129911299212993129941299512996129971299812999130001300113002130031300413005130061300713008130091301013011130121301313014130151301613017130181301913020130211302213023130241302513026130271302813029130301303113032130331303413035130361303713038130391304013041130421304313044130451304613047130481304913050130511305213053130541305513056130571305813059130601306113062130631306413065130661306713068130691307013071130721307313074130751307613077130781307913080130811308213083130841308513086130871308813089130901309113092130931309413095130961309713098130991310013101131021310313104131051310613107131081310913110131111311213113131141311513116131171311813119131201312113122131231312413125131261312713128131291313013131131321313313134131351313613137131381313913140131411314213143131441314513146131471314813149131501315113152131531315413155131561315713158131591316013161131621316313164131651316613167131681316913170131711317213173131741317513176131771317813179131801318113182131831318413185131861318713188131891319013191131921319313194131951319613197131981319913200132011320213203132041320513206132071320813209132101321113212132131321413215132161321713218132191322013221132221322313224132251322613227132281322913230132311323213233132341323513236132371323813239132401324113242132431324413245132461324713248132491325013251132521325313254132551325613257132581325913260132611326213263132641326513266132671326813269132701327113272132731327413275132761327713278132791328013281132821328313284132851328613287132881328913290132911329213293132941329513296132971329813299133001330113302133031330413305133061330713308133091331013311133121331313314133151331613317133181331913320133211332213323133241332513326133271332813329133301333113332133331333413335133361333713338133391334013341133421334313344133451334613347133481334913350133511335213353133541335513356133571335813359133601336113362133631336413365133661336713368133691337013371133721337313374133751337613377133781337913380133811338213383133841338513386133871338813389133901339113392133931339413395133961339713398133991340013401134021340313404134051340613407134081340913410134111341213413134141341513416134171341813419134201342113422134231342413425134261342713428134291343013431134321343313434134351343613437134381343913440134411344213443134441344513446134471344813449134501345113452134531345413455134561345713458134591346013461134621346313464134651346613467134681346913470134711347213473134741347513476134771347813479134801348113482134831348413485134861348713488134891349013491134921349313494134951349613497134981349913500135011350213503135041350513506135071350813509135101351113512135131351413515135161351713518135191352013521135221352313524135251352613527135281352913530135311353213533135341353513536 |
- diff -Nuar flatpak-1.0.0.orig/bubblewrap/autogen.sh flatpak-1.0.0/bubblewrap/autogen.sh
- --- flatpak-1.0.0.orig/bubblewrap/autogen.sh 1970-01-01 02:00:00.000000000 +0200
- +++ flatpak-1.0.0/bubblewrap/autogen.sh 2018-02-03 21:26:06.272233339 +0300
- @@ -0,0 +1,19 @@
- +#!/bin/sh
- +
- +test -n "$srcdir" || srcdir=`dirname "$0"`
- +test -n "$srcdir" || srcdir=.
- +
- +olddir=`pwd`
- +cd $srcdir
- +
- +if ! (autoreconf --version >/dev/null 2>&1); then
- + echo "*** No autoreconf found, please install it ***"
- + exit 1
- +fi
- +
- +mkdir -p m4
- +
- +autoreconf --force --install --verbose
- +
- +cd $olddir
- +test -n "$NOCONFIGURE" || "$srcdir/configure" "$@"
- diff -Nuar flatpak-1.0.0.orig/bubblewrap/bind-mount.c flatpak-1.0.0/bubblewrap/bind-mount.c
- --- flatpak-1.0.0.orig/bubblewrap/bind-mount.c 1970-01-01 02:00:00.000000000 +0200
- +++ flatpak-1.0.0/bubblewrap/bind-mount.c 2018-02-03 21:26:06.272233339 +0300
- @@ -0,0 +1,440 @@
- +/* bubblewrap
- + * Copyright (C) 2016 Alexander Larsson
- + *
- + * This program is free software; you can redistribute it and/or
- + * modify it under the terms of the GNU Lesser General Public
- + * License as published by the Free Software Foundation; either
- + * version 2 of the License, or (at your option) any later version.
- + *
- + * This library is distributed in the hope that it will be useful,
- + * but WITHOUT ANY WARRANTY; without even the implied warranty of
- + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
- + * Lesser General Public License for more details.
- + *
- + * You should have received a copy of the GNU Lesser General Public
- + * License along with this library. If not, see <http://www.gnu.org/licenses/>.
- + *
- + */
- +
- +#include "config.h"
- +
- +#include <sys/mount.h>
- +
- +#include "utils.h"
- +#include "bind-mount.h"
- +
- +static char *
- +skip_token (char *line, bool eat_whitespace)
- +{
- + while (*line != ' ' && *line != '\n')
- + line++;
- +
- + if (eat_whitespace && *line == ' ')
- + line++;
- +
- + return line;
- +}
- +
- +static char *
- +unescape_inline (char *escaped)
- +{
- + char *unescaped, *res;
- + const char *end;
- +
- + res = escaped;
- + end = escaped + strlen (escaped);
- +
- + unescaped = escaped;
- + while (escaped < end)
- + {
- + if (*escaped == '\\')
- + {
- + *unescaped++ =
- + ((escaped[1] - '0') << 6) |
- + ((escaped[2] - '0') << 3) |
- + ((escaped[3] - '0') << 0);
- + escaped += 4;
- + }
- + else
- + {
- + *unescaped++ = *escaped++;
- + }
- + }
- + *unescaped = 0;
- + return res;
- +}
- +
- +static bool
- +match_token (const char *token, const char *token_end, const char *str)
- +{
- + while (token != token_end && *token == *str)
- + {
- + token++;
- + str++;
- + }
- + if (token == token_end)
- + return *str == 0;
- +
- + return FALSE;
- +}
- +
- +static unsigned long
- +decode_mountoptions (const char *options)
- +{
- + const char *token, *end_token;
- + int i;
- + unsigned long flags = 0;
- + static const struct { int flag;
- + char *name;
- + } flags_data[] = {
- + { 0, "rw" },
- + { MS_RDONLY, "ro" },
- + { MS_NOSUID, "nosuid" },
- + { MS_NODEV, "nodev" },
- + { MS_NOEXEC, "noexec" },
- + { MS_NOATIME, "noatime" },
- + { MS_NODIRATIME, "nodiratime" },
- + { MS_RELATIME, "relatime" },
- + { 0, NULL }
- + };
- +
- + token = options;
- + do
- + {
- + end_token = strchr (token, ',');
- + if (end_token == NULL)
- + end_token = token + strlen (token);
- +
- + for (i = 0; flags_data[i].name != NULL; i++)
- + {
- + if (match_token (token, end_token, flags_data[i].name))
- + {
- + flags |= flags_data[i].flag;
- + break;
- + }
- + }
- +
- + if (*end_token != 0)
- + token = end_token + 1;
- + else
- + token = NULL;
- + }
- + while (token != NULL);
- +
- + return flags;
- +}
- +
- +typedef struct MountInfo MountInfo;
- +struct MountInfo {
- + char *mountpoint;
- + unsigned long options;
- +};
- +
- +typedef MountInfo *MountTab;
- +
- +static void
- +mount_tab_free (MountTab tab)
- +{
- + int i;
- +
- + for (i = 0; tab[i].mountpoint != NULL; i++)
- + free (tab[i].mountpoint);
- + free (tab);
- +}
- +
- +static inline void
- +cleanup_mount_tabp (void *p)
- +{
- + void **pp = (void **) p;
- +
- + if (*pp)
- + mount_tab_free ((MountTab)*pp);
- +}
- +
- +#define cleanup_mount_tab __attribute__((cleanup (cleanup_mount_tabp)))
- +
- +typedef struct MountInfoLine MountInfoLine;
- +struct MountInfoLine {
- + const char *mountpoint;
- + const char *options;
- + bool covered;
- + int id;
- + int parent_id;
- + MountInfoLine *first_child;
- + MountInfoLine *next_sibling;
- +};
- +
- +static unsigned int
- +count_lines (const char *data)
- +{
- + unsigned int count = 0;
- + const char *p = data;
- +
- + while (*p != 0)
- + {
- + if (*p == '\n')
- + count++;
- + p++;
- + }
- +
- + /* If missing final newline, add one */
- + if (p > data && *(p-1) != '\n')
- + count++;
- +
- + return count;
- +}
- +
- +static int
- +count_mounts (MountInfoLine *line)
- +{
- + MountInfoLine *child;
- + int res = 0;
- +
- + if (!line->covered)
- + res += 1;
- +
- + child = line->first_child;
- + while (child != NULL)
- + {
- + res += count_mounts (child);
- + child = child->next_sibling;
- + }
- +
- + return res;
- +}
- +
- +static MountInfo *
- +collect_mounts (MountInfo *info, MountInfoLine *line)
- +{
- + MountInfoLine *child;
- +
- + if (!line->covered)
- + {
- + info->mountpoint = xstrdup (line->mountpoint);
- + info->options = decode_mountoptions (line->options);
- + info ++;
- + }
- +
- + child = line->first_child;
- + while (child != NULL)
- + {
- + info = collect_mounts (info, child);
- + child = child->next_sibling;
- + }
- +
- + return info;
- +}
- +
- +static MountTab
- +parse_mountinfo (int proc_fd,
- + const char *root_mount)
- +{
- + cleanup_free char *mountinfo = NULL;
- + cleanup_free MountInfoLine *lines = NULL;
- + cleanup_free MountInfoLine **by_id = NULL;
- + cleanup_mount_tab MountTab mount_tab = NULL;
- + MountInfo *end_tab;
- + int n_mounts;
- + char *line;
- + int i;
- + int max_id;
- + unsigned int n_lines;
- + int root;
- +
- + mountinfo = load_file_at (proc_fd, "self/mountinfo");
- + if (mountinfo == NULL)
- + die_with_error ("Can't open /proc/self/mountinfo");
- +
- + n_lines = count_lines (mountinfo);
- + lines = xcalloc (n_lines * sizeof (MountInfoLine));
- +
- + max_id = 0;
- + line = mountinfo;
- + i = 0;
- + root = -1;
- + while (*line != 0)
- + {
- + int rc, consumed = 0;
- + unsigned int maj, min;
- + char *end;
- + char *rest;
- + char *mountpoint;
- + char *mountpoint_end;
- + char *options;
- + char *options_end;
- + char *next_line;
- +
- + assert (i < n_lines);
- +
- + end = strchr (line, '\n');
- + if (end != NULL)
- + {
- + *end = 0;
- + next_line = end + 1;
- + }
- + else
- + next_line = line + strlen (line);
- +
- + rc = sscanf (line, "%d %d %u:%u %n", &lines[i].id, &lines[i].parent_id, &maj, &min, &consumed);
- + if (rc != 4)
- + die ("Can't parse mountinfo line");
- + rest = line + consumed;
- +
- + rest = skip_token (rest, TRUE); /* mountroot */
- + mountpoint = rest;
- + rest = skip_token (rest, FALSE); /* mountpoint */
- + mountpoint_end = rest++;
- + options = rest;
- + rest = skip_token (rest, FALSE); /* vfs options */
- + options_end = rest;
- +
- + *mountpoint_end = 0;
- + lines[i].mountpoint = unescape_inline (mountpoint);
- +
- + *options_end = 0;
- + lines[i].options = options;
- +
- + if (lines[i].id > max_id)
- + max_id = lines[i].id;
- + if (lines[i].parent_id > max_id)
- + max_id = lines[i].parent_id;
- +
- + if (path_equal (lines[i].mountpoint, root_mount))
- + root = i;
- +
- + i++;
- + line = next_line;
- + }
- + assert (i == n_lines);
- +
- + if (root == -1)
- + {
- + mount_tab = xcalloc (sizeof (MountInfo) * (1));
- + return steal_pointer (&mount_tab);
- + }
- +
- + by_id = xcalloc ((max_id + 1) * sizeof (MountInfoLine*));
- + for (i = 0; i < n_lines; i++)
- + by_id[lines[i].id] = &lines[i];
- +
- + for (i = 0; i < n_lines; i++)
- + {
- + MountInfoLine *this = &lines[i];
- + MountInfoLine *parent = by_id[this->parent_id];
- + MountInfoLine **to_sibling;
- + MountInfoLine *sibling;
- + bool covered = FALSE;
- +
- + if (!has_path_prefix (this->mountpoint, root_mount))
- + continue;
- +
- + if (parent == NULL)
- + continue;
- +
- + if (strcmp (parent->mountpoint, this->mountpoint) == 0)
- + parent->covered = TRUE;
- +
- + to_sibling = &parent->first_child;
- + sibling = parent->first_child;
- + while (sibling != NULL)
- + {
- + /* If this mountpoint is a path prefix of the sibling,
- + * say this->mp=/foo/bar and sibling->mp=/foo, then it is
- + * covered by the sibling, and we drop it. */
- + if (has_path_prefix (this->mountpoint, sibling->mountpoint))
- + {
- + covered = TRUE;
- + break;
- + }
- +
- + /* If the sibling is a path prefix of this mount point,
- + * say this->mp=/foo and sibling->mp=/foo/bar, then the sibling
- + * is covered, and we drop it.
- + */
- + if (has_path_prefix (sibling->mountpoint, this->mountpoint))
- + *to_sibling = sibling->next_sibling;
- + else
- + to_sibling = &sibling->next_sibling;
- + sibling = sibling->next_sibling;
- + }
- +
- + if (covered)
- + continue;
- +
- + *to_sibling = this;
- + }
- +
- + n_mounts = count_mounts (&lines[root]);
- + mount_tab = xcalloc (sizeof (MountInfo) * (n_mounts + 1));
- +
- + end_tab = collect_mounts (&mount_tab[0], &lines[root]);
- + assert (end_tab == &mount_tab[n_mounts]);
- +
- + return steal_pointer (&mount_tab);
- +}
- +
- +int
- +bind_mount (int proc_fd,
- + const char *src,
- + const char *dest,
- + bind_option_t options)
- +{
- + bool readonly = (options & BIND_READONLY) != 0;
- + bool devices = (options & BIND_DEVICES) != 0;
- + bool recursive = (options & BIND_RECURSIVE) != 0;
- + unsigned long current_flags, new_flags;
- + cleanup_mount_tab MountTab mount_tab = NULL;
- + cleanup_free char *resolved_dest = NULL;
- + int i;
- +
- + if (src)
- + {
- + if (mount (src, dest, NULL, MS_MGC_VAL | MS_BIND | (recursive ? MS_REC : 0), NULL) != 0)
- + return 1;
- + }
- +
- + /* The mount operation will resolve any symlinks in the destination
- + path, so to find it in the mount table we need to do that too. */
- + resolved_dest = realpath (dest, NULL);
- + if (resolved_dest == NULL)
- + return 2;
- +
- + mount_tab = parse_mountinfo (proc_fd, resolved_dest);
- + if (mount_tab[0].mountpoint == NULL)
- + {
- + errno = EINVAL;
- + return 2; /* No mountpoint at dest */
- + }
- +
- + assert (path_equal (mount_tab[0].mountpoint, resolved_dest));
- + current_flags = mount_tab[0].options;
- + new_flags = current_flags | (devices ? 0 : MS_NODEV) | MS_NOSUID | (readonly ? MS_RDONLY : 0);
- + if (new_flags != current_flags &&
- + mount ("none", resolved_dest,
- + NULL, MS_MGC_VAL | MS_BIND | MS_REMOUNT | new_flags, NULL) != 0)
- + return 3;
- +
- + /* We need to work around the fact that a bind mount does not apply the flags, so we need to manually
- + * apply the flags to all submounts in the recursive case.
- + * Note: This does not apply the flags to mounts which are later propagated into this namespace.
- + */
- + if (recursive)
- + {
- + for (i = 1; mount_tab[i].mountpoint != NULL; i++)
- + {
- + current_flags = mount_tab[i].options;
- + new_flags = current_flags | (devices ? 0 : MS_NODEV) | MS_NOSUID | (readonly ? MS_RDONLY : 0);
- + if (new_flags != current_flags &&
- + mount ("none", mount_tab[i].mountpoint,
- + NULL, MS_MGC_VAL | MS_BIND | MS_REMOUNT | new_flags, NULL) != 0)
- + {
- + /* If we can't read the mountpoint we can't remount it, but that should
- + be safe to ignore because its not something the user can access. */
- + if (errno != EACCES)
- + return 5;
- + }
- + }
- + }
- +
- + return 0;
- +}
- diff -Nuar flatpak-1.0.0.orig/bubblewrap/bind-mount.h flatpak-1.0.0/bubblewrap/bind-mount.h
- --- flatpak-1.0.0.orig/bubblewrap/bind-mount.h 1970-01-01 02:00:00.000000000 +0200
- +++ flatpak-1.0.0/bubblewrap/bind-mount.h 2018-02-03 21:26:06.272233339 +0300
- @@ -0,0 +1,30 @@
- +/* bubblewrap
- + * Copyright (C) 2016 Alexander Larsson
- + *
- + * This program is free software; you can redistribute it and/or
- + * modify it under the terms of the GNU Lesser General Public
- + * License as published by the Free Software Foundation; either
- + * version 2 of the License, or (at your option) any later version.
- + *
- + * This library is distributed in the hope that it will be useful,
- + * but WITHOUT ANY WARRANTY; without even the implied warranty of
- + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
- + * Lesser General Public License for more details.
- + *
- + * You should have received a copy of the GNU Lesser General Public
- + * License along with this library. If not, see <http://www.gnu.org/licenses/>.
- + *
- + */
- +
- +#pragma once
- +
- +typedef enum {
- + BIND_READONLY = (1 << 0),
- + BIND_DEVICES = (1 << 2),
- + BIND_RECURSIVE = (1 << 3),
- +} bind_option_t;
- +
- +int bind_mount (int proc_fd,
- + const char *src,
- + const char *dest,
- + bind_option_t options);
- diff -Nuar flatpak-1.0.0.orig/bubblewrap/bubblewrap.c flatpak-1.0.0/bubblewrap/bubblewrap.c
- --- flatpak-1.0.0.orig/bubblewrap/bubblewrap.c 1970-01-01 02:00:00.000000000 +0200
- +++ flatpak-1.0.0/bubblewrap/bubblewrap.c 2018-02-03 21:26:06.272233339 +0300
- @@ -0,0 +1,2223 @@
- +/* bubblewrap
- + * Copyright (C) 2016 Alexander Larsson
- + *
- + * This program is free software; you can redistribute it and/or
- + * modify it under the terms of the GNU Lesser General Public
- + * License as published by the Free Software Foundation; either
- + * version 2 of the License, or (at your option) any later version.
- + *
- + * This library is distributed in the hope that it will be useful,
- + * but WITHOUT ANY WARRANTY; without even the implied warranty of
- + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
- + * Lesser General Public License for more details.
- + *
- + * You should have received a copy of the GNU Lesser General Public
- + * License along with this library. If not, see <http://www.gnu.org/licenses/>.
- + *
- + */
- +
- +#include "config.h"
- +
- +#include <poll.h>
- +#include <sched.h>
- +#include <pwd.h>
- +#include <grp.h>
- +#include <sys/mount.h>
- +#include <sys/socket.h>
- +#include <sys/wait.h>
- +#include <sys/eventfd.h>
- +#include <sys/fsuid.h>
- +#include <sys/signalfd.h>
- +#include <sys/capability.h>
- +#include <sys/prctl.h>
- +#include <linux/sched.h>
- +#include <linux/seccomp.h>
- +#include <linux/filter.h>
- +
- +#include "utils.h"
- +#include "network.h"
- +#include "bind-mount.h"
- +
- +#ifndef CLONE_NEWCGROUP
- +#define CLONE_NEWCGROUP 0x02000000 /* New cgroup namespace */
- +#endif
- +
- +/* Globals to avoid having to use getuid(), since the uid/gid changes during runtime */
- +static uid_t real_uid;
- +static gid_t real_gid;
- +static uid_t overflow_uid;
- +static gid_t overflow_gid;
- +static bool is_privileged;
- +static const char *argv0;
- +static const char *host_tty_dev;
- +static int proc_fd = -1;
- +static char *opt_exec_label = NULL;
- +static char *opt_file_label = NULL;
- +
- +char *opt_chdir_path = NULL;
- +bool opt_unshare_user = FALSE;
- +bool opt_unshare_user_try = FALSE;
- +bool opt_unshare_pid = FALSE;
- +bool opt_unshare_ipc = FALSE;
- +bool opt_unshare_net = FALSE;
- +bool opt_unshare_uts = FALSE;
- +bool opt_unshare_cgroup = FALSE;
- +bool opt_unshare_cgroup_try = FALSE;
- +bool opt_needs_devpts = FALSE;
- +bool opt_new_session = FALSE;
- +bool opt_die_with_parent = FALSE;
- +uid_t opt_sandbox_uid = -1;
- +gid_t opt_sandbox_gid = -1;
- +int opt_sync_fd = -1;
- +int opt_block_fd = -1;
- +int opt_info_fd = -1;
- +int opt_seccomp_fd = -1;
- +char *opt_sandbox_hostname = NULL;
- +
- +typedef enum {
- + SETUP_BIND_MOUNT,
- + SETUP_RO_BIND_MOUNT,
- + SETUP_DEV_BIND_MOUNT,
- + SETUP_MOUNT_PROC,
- + SETUP_MOUNT_DEV,
- + SETUP_MOUNT_TMPFS,
- + SETUP_MOUNT_MQUEUE,
- + SETUP_MAKE_DIR,
- + SETUP_MAKE_FILE,
- + SETUP_MAKE_BIND_FILE,
- + SETUP_MAKE_RO_BIND_FILE,
- + SETUP_MAKE_SYMLINK,
- + SETUP_REMOUNT_RO_NO_RECURSIVE,
- + SETUP_SET_HOSTNAME,
- +} SetupOpType;
- +
- +typedef enum {
- + NO_CREATE_DEST = (1 << 0),
- +} SetupOpFlag;
- +
- +typedef struct _SetupOp SetupOp;
- +
- +struct _SetupOp
- +{
- + SetupOpType type;
- + const char *source;
- + const char *dest;
- + int fd;
- + SetupOpFlag flags;
- + SetupOp *next;
- +};
- +
- +typedef struct _LockFile LockFile;
- +
- +struct _LockFile
- +{
- + const char *path;
- + LockFile *next;
- +};
- +
- +static SetupOp *ops = NULL;
- +static SetupOp *last_op = NULL;
- +static LockFile *lock_files = NULL;
- +static LockFile *last_lock_file = NULL;
- +
- +enum {
- + PRIV_SEP_OP_DONE,
- + PRIV_SEP_OP_BIND_MOUNT,
- + PRIV_SEP_OP_PROC_MOUNT,
- + PRIV_SEP_OP_TMPFS_MOUNT,
- + PRIV_SEP_OP_DEVPTS_MOUNT,
- + PRIV_SEP_OP_MQUEUE_MOUNT,
- + PRIV_SEP_OP_REMOUNT_RO_NO_RECURSIVE,
- + PRIV_SEP_OP_SET_HOSTNAME,
- +};
- +
- +typedef struct
- +{
- + uint32_t op;
- + uint32_t flags;
- + uint32_t arg1_offset;
- + uint32_t arg2_offset;
- +} PrivSepOp;
- +
- +static SetupOp *
- +setup_op_new (SetupOpType type)
- +{
- + SetupOp *op = xcalloc (sizeof (SetupOp));
- +
- + op->type = type;
- + op->fd = -1;
- + op->flags = 0;
- + if (last_op != NULL)
- + last_op->next = op;
- + else
- + ops = op;
- +
- + last_op = op;
- + return op;
- +}
- +
- +static LockFile *
- +lock_file_new (const char *path)
- +{
- + LockFile *lock = xcalloc (sizeof (LockFile));
- +
- + lock->path = path;
- + if (last_lock_file != NULL)
- + last_lock_file->next = lock;
- + else
- + lock_files = lock;
- +
- + last_lock_file = lock;
- + return lock;
- +}
- +
- +
- +static void
- +usage (int ecode, FILE *out)
- +{
- + fprintf (out, "usage: %s [OPTIONS...] COMMAND [ARGS...]\n\n", argv0);
- +
- + fprintf (out,
- + " --help Print this help\n"
- + " --version Print version\n"
- + " --args FD Parse nul-separated args from FD\n"
- + " --unshare-all Unshare every namespace we support by default\n"
- + " --share-net Retain the network namespace (can only combine with --unshare-all)\n"
- + " --unshare-user Create new user namespace (may be automatically implied if not setuid)\n"
- + " --unshare-user-try Create new user namespace if possible else continue by skipping it\n"
- + " --unshare-ipc Create new ipc namespace\n"
- + " --unshare-pid Create new pid namespace\n"
- + " --unshare-net Create new network namespace\n"
- + " --unshare-uts Create new uts namespace\n"
- + " --unshare-cgroup Create new cgroup namespace\n"
- + " --unshare-cgroup-try Create new cgroup namespace if possible else continue by skipping it\n"
- + " --uid UID Custom uid in the sandbox (requires --unshare-user)\n"
- + " --gid GID Custon gid in the sandbox (requires --unshare-user)\n"
- + " --hostname NAME Custom hostname in the sandbox (requires --unshare-uts)\n"
- + " --chdir DIR Change directory to DIR\n"
- + " --setenv VAR VALUE Set an environment variable\n"
- + " --unsetenv VAR Unset an environment variable\n"
- + " --lock-file DEST Take a lock on DEST while sandbox is running\n"
- + " --sync-fd FD Keep this fd open while sandbox is running\n"
- + " --bind SRC DEST Bind mount the host path SRC on DEST\n"
- + " --dev-bind SRC DEST Bind mount the host path SRC on DEST, allowing device access\n"
- + " --ro-bind SRC DEST Bind mount the host path SRC readonly on DEST\n"
- + " --remount-ro DEST Remount DEST as readonly, it doesn't recursively remount\n"
- + " --exec-label LABEL Exec Label for the sandbox\n"
- + " --file-label LABEL File label for temporary sandbox content\n"
- + " --proc DEST Mount procfs on DEST\n"
- + " --dev DEST Mount new dev on DEST\n"
- + " --tmpfs DEST Mount new tmpfs on DEST\n"
- + " --mqueue DEST Mount new mqueue on DEST\n"
- + " --dir DEST Create dir at DEST\n"
- + " --file FD DEST Copy from FD to dest DEST\n"
- + " --bind-data FD DEST Copy from FD to file which is bind-mounted on DEST\n"
- + " --ro-bind-data FD DEST Copy from FD to file which is readonly bind-mounted on DEST\n"
- + " --symlink SRC DEST Create symlink at DEST with target SRC\n"
- + " --seccomp FD Load and use seccomp rules from FD\n"
- + " --block-fd FD Block on FD until some data to read is available\n"
- + " --info-fd FD Write information about the running container to FD\n"
- + " --new-session Create a new terminal session\n"
- + " --die-with-parent Kills with SIGKILL child process (COMMAND) when bwrap or bwrap's parent dies.\n"
- + );
- + exit (ecode);
- +}
- +
- +/* If --die-with-parent was specified, use PDEATHSIG to ensure SIGKILL
- + * is sent to the current process when our parent dies.
- + */
- +static void
- +handle_die_with_parent (void)
- +{
- + if (opt_die_with_parent && prctl (PR_SET_PDEATHSIG, SIGKILL, 0, 0, 0) != 0)
- + die_with_error ("prctl");
- +}
- +
- +static void
- +block_sigchild (void)
- +{
- + sigset_t mask;
- + int status;
- +
- + sigemptyset (&mask);
- + sigaddset (&mask, SIGCHLD);
- +
- + if (sigprocmask (SIG_BLOCK, &mask, NULL) == -1)
- + die_with_error ("sigprocmask");
- +
- + /* Reap any outstanding zombies that we may have inherited */
- + while (waitpid (-1, &status, WNOHANG) > 0)
- + ;
- +}
- +
- +static void
- +unblock_sigchild (void)
- +{
- + sigset_t mask;
- +
- + sigemptyset (&mask);
- + sigaddset (&mask, SIGCHLD);
- +
- + if (sigprocmask (SIG_UNBLOCK, &mask, NULL) == -1)
- + die_with_error ("sigprocmask");
- +}
- +
- +/* Closes all fd:s except 0,1,2 and the passed in array of extra fds */
- +static int
- +close_extra_fds (void *data, int fd)
- +{
- + int *extra_fds = (int *) data;
- + int i;
- +
- + for (i = 0; extra_fds[i] != -1; i++)
- + if (fd == extra_fds[i])
- + return 0;
- +
- + if (fd <= 2)
- + return 0;
- +
- + close (fd);
- + return 0;
- +}
- +
- +static int
- +propagate_exit_status (int status)
- +{
- + if (WIFEXITED (status))
- + return WEXITSTATUS (status);
- +
- + /* The process died of a signal, we can't really report that, but we
- + * can at least be bash-compatible. The bash manpage says:
- + * The return value of a simple command is its
- + * exit status, or 128+n if the command is
- + * terminated by signal n.
- + */
- + if (WIFSIGNALED (status))
- + return 128 + WTERMSIG (status);
- +
- + /* Weird? */
- + return 255;
- +}
- +
- +/* This stays around for as long as the initial process in the app does
- + * and when that exits it exits, propagating the exit status. We do this
- + * by having pid 1 in the sandbox detect this exit and tell the monitor
- + * the exit status via a eventfd. We also track the exit of the sandbox
- + * pid 1 via a signalfd for SIGCHLD, and exit with an error in this case.
- + * This is to catch e.g. problems during setup. */
- +static void
- +monitor_child (int event_fd, pid_t child_pid)
- +{
- + int res;
- + uint64_t val;
- + ssize_t s;
- + int signal_fd;
- + sigset_t mask;
- + struct pollfd fds[2];
- + int num_fds;
- + struct signalfd_siginfo fdsi;
- + int dont_close[] = { event_fd, -1 };
- + pid_t died_pid;
- + int died_status;
- +
- + /* Close all extra fds in the monitoring process.
- + Any passed in fds have been passed on to the child anyway. */
- + fdwalk (proc_fd, close_extra_fds, dont_close);
- +
- + sigemptyset (&mask);
- + sigaddset (&mask, SIGCHLD);
- +
- + signal_fd = signalfd (-1, &mask, SFD_CLOEXEC | SFD_NONBLOCK);
- + if (signal_fd == -1)
- + die_with_error ("Can't create signalfd");
- +
- + num_fds = 1;
- + fds[0].fd = signal_fd;
- + fds[0].events = POLLIN;
- + if (event_fd != -1)
- + {
- + fds[1].fd = event_fd;
- + fds[1].events = POLLIN;
- + num_fds++;
- + }
- +
- + while (1)
- + {
- + fds[0].revents = fds[1].revents = 0;
- + res = poll (fds, num_fds, -1);
- + if (res == -1 && errno != EINTR)
- + die_with_error ("poll");
- +
- + /* Always read from the eventfd first, if pid 2 died then pid 1 often
- + * dies too, and we could race, reporting that first and we'd lose
- + * the real exit status. */
- + if (event_fd != -1)
- + {
- + s = read (event_fd, &val, 8);
- + if (s == -1 && errno != EINTR && errno != EAGAIN)
- + die_with_error ("read eventfd");
- + else if (s == 8)
- + exit ((int) val - 1);
- + }
- +
- + /* We need to read the signal_fd, or it will keep polling as read,
- + * however we ignore the details as we get them from waitpid
- + * below anway */
- + s = read (signal_fd, &fdsi, sizeof (struct signalfd_siginfo));
- + if (s == -1 && errno != EINTR && errno != EAGAIN)
- + die_with_error ("read signalfd");
- +
- + /* We may actually get several sigchld compressed into one
- + SIGCHLD, so we have to handle all of them. */
- + while ((died_pid = waitpid (-1, &died_status, WNOHANG)) > 0)
- + {
- + /* We may be getting sigchild from other children too. For instance if
- + someone created a child process, and then exec:ed bubblewrap. Ignore them */
- + if (died_pid == child_pid)
- + exit (propagate_exit_status (died_status));
- + }
- + }
- +}
- +
- +/* This is pid 1 in the app sandbox. It is needed because we're using
- + * pid namespaces, and someone has to reap zombies in it. We also detect
- + * when the initial process (pid 2) dies and report its exit status to
- + * the monitor so that it can return it to the original spawner.
- + *
- + * When there are no other processes in the sandbox the wait will return
- + * ECHILD, and we then exit pid 1 to clean up the sandbox. */
- +static int
- +do_init (int event_fd, pid_t initial_pid, struct sock_fprog *seccomp_prog)
- +{
- + int initial_exit_status = 1;
- + LockFile *lock;
- +
- + for (lock = lock_files; lock != NULL; lock = lock->next)
- + {
- + int fd = open (lock->path, O_RDONLY | O_CLOEXEC);
- + if (fd == -1)
- + die_with_error ("Unable to open lock file %s", lock->path);
- +
- + struct flock l = {
- + .l_type = F_RDLCK,
- + .l_whence = SEEK_SET,
- + .l_start = 0,
- + .l_len = 0
- + };
- +
- + if (fcntl (fd, F_SETLK, &l) < 0)
- + die_with_error ("Unable to lock file %s", lock->path);
- +
- + /* Keep fd open to hang on to lock */
- + }
- +
- + /* Optionally bind our lifecycle to that of the caller */
- + handle_die_with_parent ();
- +
- + if (seccomp_prog != NULL &&
- + prctl (PR_SET_SECCOMP, SECCOMP_MODE_FILTER, seccomp_prog) != 0)
- + die_with_error ("prctl(PR_SET_SECCOMP)");
- +
- + while (TRUE)
- + {
- + pid_t child;
- + int status;
- +
- + child = wait (&status);
- + if (child == initial_pid && event_fd != -1)
- + {
- + uint64_t val;
- + int res UNUSED;
- +
- + initial_exit_status = propagate_exit_status (status);
- +
- + val = initial_exit_status + 1;
- + res = write (event_fd, &val, 8);
- + /* Ignore res, if e.g. the parent died and closed event_fd
- + we don't want to error out here */
- + }
- +
- + if (child == -1 && errno != EINTR)
- + {
- + if (errno != ECHILD)
- + die_with_error ("init wait()");
- + break;
- + }
- + }
- +
- + return initial_exit_status;
- +}
- +
- +/* low 32bit caps needed */
- +#define REQUIRED_CAPS_0 (CAP_TO_MASK (CAP_SYS_ADMIN) | CAP_TO_MASK (CAP_SYS_CHROOT) | CAP_TO_MASK (CAP_NET_ADMIN) | CAP_TO_MASK (CAP_SETUID) | CAP_TO_MASK (CAP_SETGID))
- +/* high 32bit caps needed */
- +#define REQUIRED_CAPS_1 0
- +
- +static void
- +set_required_caps (void)
- +{
- + struct __user_cap_header_struct hdr = { _LINUX_CAPABILITY_VERSION_3, 0 };
- + struct __user_cap_data_struct data[2] = { { 0 } };
- +
- + /* Drop all non-require capabilities */
- + data[0].effective = REQUIRED_CAPS_0;
- + data[0].permitted = REQUIRED_CAPS_0;
- + data[0].inheritable = 0;
- + data[1].effective = REQUIRED_CAPS_1;
- + data[1].permitted = REQUIRED_CAPS_1;
- + data[1].inheritable = 0;
- + if (capset (&hdr, data) < 0)
- + die_with_error ("capset failed");
- +}
- +
- +static void
- +drop_all_caps (void)
- +{
- + struct __user_cap_header_struct hdr = { _LINUX_CAPABILITY_VERSION_3, 0 };
- + struct __user_cap_data_struct data[2] = { { 0 } };
- +
- + if (capset (&hdr, data) < 0)
- + die_with_error ("capset failed");
- +}
- +
- +static bool
- +has_caps (void)
- +{
- + struct __user_cap_header_struct hdr = { _LINUX_CAPABILITY_VERSION_3, 0 };
- + struct __user_cap_data_struct data[2] = { { 0 } };
- +
- + if (capget (&hdr, data) < 0)
- + die_with_error ("capget failed");
- +
- + return data[0].permitted != 0 || data[1].permitted != 0;
- +}
- +
- +static void
- +drop_cap_bounding_set (void)
- +{
- + unsigned long cap;
- +
- + /* We ignore both EINVAL and EPERM, as we are actually relying
- + * on PR_SET_NO_NEW_PRIVS to ensure the right capabilities are
- + * available. EPERM in particular can happen with old, buggy
- + * kernels. See:
- + * https://github.com/projectatomic/bubblewrap/pull/175#issuecomment-278051373
- + * https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/security/commoncap.c?id=160da84dbb39443fdade7151bc63a88f8e953077
- + */
- + for (cap = 0; cap <= 63; cap++)
- + {
- + int res = prctl (PR_CAPBSET_DROP, cap, 0, 0, 0);
- + if (res == -1 && !(errno == EINVAL || errno == EPERM))
- + die_with_error ("Dropping capability %ld from bounds", cap);
- + }
- +}
- +
- +/* This acquires the privileges that the bwrap will need it to work.
- + * If bwrap is not setuid, then this does nothing, and it relies on
- + * unprivileged user namespaces to be used. This case is
- + * "is_privileged = FALSE".
- + *
- + * If bwrap is setuid, then we do things in phases.
- + * The first part is run as euid 0, but with with fsuid as the real user.
- + * The second part, inside the child, is run as the real user but with
- + * capabilities.
- + * And finally we drop all capabilities.
- + * The reason for the above dance is to avoid having the setup phase
- + * being able to read files the user can't, while at the same time
- + * working around various kernel issues. See below for details.
- + */
- +static void
- +acquire_privs (void)
- +{
- + uid_t euid, new_fsuid;
- +
- + euid = geteuid ();
- +
- + /* Are we setuid ? */
- + if (real_uid != euid)
- + {
- + if (euid == 0)
- + is_privileged = TRUE;
- + else
- + die ("Unexpected setuid user %d, should be 0", euid);
- +
- + /* We want to keep running as euid=0 until at the clone()
- + * operation because doing so will make the user namespace be
- + * owned by root, which makes it not ptrace:able by the user as
- + * it otherwise would be. After that we will run fully as the
- + * user, which is necessary e.g. to be able to read from a fuse
- + * mount from the user.
- + *
- + * However, we don't want to accidentally mis-use euid=0 for
- + * escalated filesystem access before the clone(), so we set
- + * fsuid to the uid.
- + */
- + if (setfsuid (real_uid) < 0)
- + die_with_error ("Unable to set fsuid");
- +
- + /* setfsuid can't properly report errors, check that it worked (as per manpage) */
- + new_fsuid = setfsuid (-1);
- + if (new_fsuid != real_uid)
- + die ("Unable to set fsuid (was %d)", (int)new_fsuid);
- +
- + /* We never need capabilies after execve(), so lets drop everything from the bounding set */
- + drop_cap_bounding_set ();
- +
- + /* Keep only the required capabilities for setup */
- + set_required_caps ();
- + }
- + else if (real_uid != 0 && has_caps ())
- + {
- + /* We have some capabilities in the non-setuid case, which should not happen.
- + Probably caused by the binary being setcap instead of setuid which we
- + don't support anymore */
- + die ("Unexpected capabilities but not setuid, old file caps config?");
- + }
- +
- + /* Else, we try unprivileged user namespaces */
- +}
- +
- +/* This is called once we're inside the namespace */
- +static void
- +switch_to_user_with_privs (void)
- +{
- + /* If we're in a new user namespace, we got back the bounding set, clear it again */
- + if (opt_unshare_user)
- + drop_cap_bounding_set ();
- +
- + if (!is_privileged)
- + return;
- +
- + /* Tell kernel not clear capabilities when later dropping root uid */
- + if (prctl (PR_SET_KEEPCAPS, 1, 0, 0, 0) < 0)
- + die_with_error ("prctl(PR_SET_KEEPCAPS) failed");
- +
- + if (setuid (opt_sandbox_uid) < 0)
- + die_with_error ("unable to drop root uid");
- +
- + /* Regain effective required capabilities from permitted */
- + set_required_caps ();
- +}
- +
- +static void
- +drop_privs (void)
- +{
- + if (!is_privileged)
- + return;
- +
- + /* Drop root uid */
- + if (setuid (opt_sandbox_uid) < 0)
- + die_with_error ("unable to drop root uid");
- +
- + drop_all_caps ();
- +}
- +
- +static char *
- +get_newroot_path (const char *path)
- +{
- + while (*path == '/')
- + path++;
- + return strconcat ("/newroot/", path);
- +}
- +
- +static char *
- +get_oldroot_path (const char *path)
- +{
- + while (*path == '/')
- + path++;
- + return strconcat ("/oldroot/", path);
- +}
- +
- +static void
- +write_uid_gid_map (uid_t sandbox_uid,
- + uid_t parent_uid,
- + uid_t sandbox_gid,
- + uid_t parent_gid,
- + pid_t pid,
- + bool deny_groups,
- + bool map_root)
- +{
- + cleanup_free char *uid_map = NULL;
- + cleanup_free char *gid_map = NULL;
- + cleanup_free char *dir = NULL;
- + cleanup_fd int dir_fd = -1;
- + uid_t old_fsuid = -1;
- +
- + if (pid == -1)
- + dir = xstrdup ("self");
- + else
- + dir = xasprintf ("%d", pid);
- +
- + dir_fd = openat (proc_fd, dir, O_RDONLY | O_PATH);
- + if (dir_fd < 0)
- + die_with_error ("open /proc/%s failed", dir);
- +
- + if (map_root && parent_uid != 0 && sandbox_uid != 0)
- + uid_map = xasprintf ("0 %d 1\n"
- + "%d %d 1\n", overflow_uid, sandbox_uid, parent_uid);
- + else
- + uid_map = xasprintf ("%d %d 1\n", sandbox_uid, parent_uid);
- +
- + if (map_root && parent_gid != 0 && sandbox_gid != 0)
- + gid_map = xasprintf ("0 %d 1\n"
- + "%d %d 1\n", overflow_gid, sandbox_gid, parent_gid);
- + else
- + gid_map = xasprintf ("%d %d 1\n", sandbox_gid, parent_gid);
- +
- + /* We have to be root to be allowed to write to the uid map
- + * for setuid apps, so temporary set fsuid to 0 */
- + if (is_privileged)
- + old_fsuid = setfsuid (0);
- +
- + if (write_file_at (dir_fd, "uid_map", uid_map) != 0)
- + die_with_error ("setting up uid map");
- +
- + if (deny_groups &&
- + write_file_at (dir_fd, "setgroups", "deny\n") != 0)
- + {
- + /* If /proc/[pid]/setgroups does not exist, assume we are
- + * running a linux kernel < 3.19, i.e. we live with the
- + * vulnerability known as CVE-2014-8989 in older kernels
- + * where setgroups does not exist.
- + */
- + if (errno != ENOENT)
- + die_with_error ("error writing to setgroups");
- + }
- +
- + if (write_file_at (dir_fd, "gid_map", gid_map) != 0)
- + die_with_error ("setting up gid map");
- +
- + if (is_privileged)
- + {
- + setfsuid (old_fsuid);
- + if (setfsuid (-1) != real_uid)
- + die ("Unable to re-set fsuid");
- + }
- +}
- +
- +static void
- +privileged_op (int privileged_op_socket,
- + uint32_t op,
- + uint32_t flags,
- + const char *arg1,
- + const char *arg2)
- +{
- + if (privileged_op_socket != -1)
- + {
- + uint32_t buffer[2048]; /* 8k, but is int32 to guarantee nice alignment */
- + PrivSepOp *op_buffer = (PrivSepOp *) buffer;
- + size_t buffer_size = sizeof (PrivSepOp);
- + uint32_t arg1_offset = 0, arg2_offset = 0;
- +
- + /* We're unprivileged, send this request to the privileged part */
- +
- + if (arg1 != NULL)
- + {
- + arg1_offset = buffer_size;
- + buffer_size += strlen (arg1) + 1;
- + }
- + if (arg2 != NULL)
- + {
- + arg2_offset = buffer_size;
- + buffer_size += strlen (arg2) + 1;
- + }
- +
- + if (buffer_size >= sizeof (buffer))
- + die ("privilege separation operation to large");
- +
- + op_buffer->op = op;
- + op_buffer->flags = flags;
- + op_buffer->arg1_offset = arg1_offset;
- + op_buffer->arg2_offset = arg2_offset;
- + if (arg1 != NULL)
- + strcpy ((char *) buffer + arg1_offset, arg1);
- + if (arg2 != NULL)
- + strcpy ((char *) buffer + arg2_offset, arg2);
- +
- + if (write (privileged_op_socket, buffer, buffer_size) != buffer_size)
- + die ("Can't write to privileged_op_socket");
- +
- + if (read (privileged_op_socket, buffer, 1) != 1)
- + die ("Can't read from privileged_op_socket");
- +
- + return;
- + }
- +
- + /*
- + * This runs a privileged request for the unprivileged setup
- + * code. Note that since the setup code is unprivileged it is not as
- + * trusted, so we need to verify that all requests only affect the
- + * child namespace as set up by the privileged parts of the setup,
- + * and that all the code is very careful about handling input.
- + *
- + * This means:
- + * * Bind mounts are safe, since we always use filesystem namespace. They
- + * must be recursive though, as otherwise you can use a non-recursive bind
- + * mount to access an otherwise over-mounted mountpoint.
- + * * Mounting proc, tmpfs, mqueue, devpts in the child namespace is assumed to
- + * be safe.
- + * * Remounting RO (even non-recursive) is safe because it decreases privileges.
- + * * sethostname() is safe only if we set up a UTS namespace
- + */
- + switch (op)
- + {
- + case PRIV_SEP_OP_DONE:
- + break;
- +
- + case PRIV_SEP_OP_REMOUNT_RO_NO_RECURSIVE:
- + if (bind_mount (proc_fd, NULL, arg2, BIND_READONLY) != 0)
- + die_with_error ("Can't remount readonly on %s", arg2);
- + break;
- +
- + case PRIV_SEP_OP_BIND_MOUNT:
- + /* We always bind directories recursively, otherwise this would let us
- + access files that are otherwise covered on the host */
- + if (bind_mount (proc_fd, arg1, arg2, BIND_RECURSIVE | flags) != 0)
- + die_with_error ("Can't bind mount %s on %s", arg1, arg2);
- + break;
- +
- + case PRIV_SEP_OP_PROC_MOUNT:
- + if (mount ("proc", arg1, "proc", MS_MGC_VAL | MS_NOSUID | MS_NOEXEC | MS_NODEV, NULL) != 0)
- + die_with_error ("Can't mount proc on %s", arg1);
- + break;
- +
- + case PRIV_SEP_OP_TMPFS_MOUNT:
- + {
- + cleanup_free char *opt = label_mount ("mode=0755", opt_file_label);
- + if (mount ("tmpfs", arg1, "tmpfs", MS_MGC_VAL | MS_NOSUID | MS_NODEV, opt) != 0)
- + die_with_error ("Can't mount tmpfs on %s", arg1);
- + break;
- + }
- +
- + case PRIV_SEP_OP_DEVPTS_MOUNT:
- + if (mount ("devpts", arg1, "devpts", MS_MGC_VAL | MS_NOSUID | MS_NOEXEC,
- + "newinstance,ptmxmode=0666,mode=620") != 0)
- + die_with_error ("Can't mount devpts on %s", arg1);
- + break;
- +
- + case PRIV_SEP_OP_MQUEUE_MOUNT:
- + if (mount ("mqueue", arg1, "mqueue", 0, NULL) != 0)
- + die_with_error ("Can't mount mqueue on %s", arg1);
- + break;
- +
- + case PRIV_SEP_OP_SET_HOSTNAME:
- + /* This is checked at the start, but lets verify it here in case
- + something manages to send hacked priv-sep operation requests. */
- + if (!opt_unshare_uts)
- + die ("Refusing to set hostname in original namespace");
- + if (sethostname (arg1, strlen(arg1)) != 0)
- + die_with_error ("Can't set hostname to %s", arg1);
- + break;
- +
- + default:
- + die ("Unexpected privileged op %d", op);
- + }
- +}
- +
- +/* This is run unprivileged in the child namespace but can request
- + * some privileged operations (also in the child namespace) via the
- + * privileged_op_socket.
- + */
- +static void
- +setup_newroot (bool unshare_pid,
- + int privileged_op_socket)
- +{
- + SetupOp *op;
- +
- + for (op = ops; op != NULL; op = op->next)
- + {
- + cleanup_free char *source = NULL;
- + cleanup_free char *dest = NULL;
- + int source_mode = 0;
- + int i;
- +
- + if (op->source &&
- + op->type != SETUP_MAKE_SYMLINK)
- + {
- + source = get_oldroot_path (op->source);
- + source_mode = get_file_mode (source);
- + if (source_mode < 0)
- + die_with_error ("Can't get type of source %s", op->source);
- + }
- +
- + if (op->dest &&
- + (op->flags & NO_CREATE_DEST) == 0)
- + {
- + dest = get_newroot_path (op->dest);
- + if (mkdir_with_parents (dest, 0755, FALSE) != 0)
- + die_with_error ("Can't mkdir parents for %s", op->dest);
- + }
- +
- + switch (op->type)
- + {
- + case SETUP_RO_BIND_MOUNT:
- + case SETUP_DEV_BIND_MOUNT:
- + case SETUP_BIND_MOUNT:
- + if (source_mode == S_IFDIR)
- + {
- + if (mkdir (dest, 0755) != 0 && errno != EEXIST)
- + die_with_error ("Can't mkdir %s", op->dest);
- + }
- + else if (ensure_file (dest, 0666) != 0)
- + die_with_error ("Can't create file at %s", op->dest);
- +
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_BIND_MOUNT,
- + (op->type == SETUP_RO_BIND_MOUNT ? BIND_READONLY : 0) |
- + (op->type == SETUP_DEV_BIND_MOUNT ? BIND_DEVICES : 0),
- + source, dest);
- + break;
- +
- + case SETUP_REMOUNT_RO_NO_RECURSIVE:
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_REMOUNT_RO_NO_RECURSIVE, 0, NULL, dest);
- + break;
- +
- + case SETUP_MOUNT_PROC:
- + if (mkdir (dest, 0755) != 0 && errno != EEXIST)
- + die_with_error ("Can't mkdir %s", op->dest);
- +
- + if (unshare_pid)
- + {
- + /* Our own procfs */
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_PROC_MOUNT, 0,
- + dest, NULL);
- + }
- + else
- + {
- + /* Use system procfs, as we share pid namespace anyway */
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_BIND_MOUNT, 0,
- + "oldroot/proc", dest);
- + }
- +
- + /* There are a bunch of weird old subdirs of /proc that could potentially be
- + problematic (for instance /proc/sysrq-trigger lets you shut down the machine
- + if you have write access). We should not have access to these as a non-privileged
- + user, but lets cover them anyway just to make sure */
- + const char *cover_proc_dirs[] = { "sys", "sysrq-trigger", "irq", "bus" };
- + for (i = 0; i < N_ELEMENTS (cover_proc_dirs); i++)
- + {
- + cleanup_free char *subdir = strconcat3 (dest, "/", cover_proc_dirs[i]);
- + /* Some of these may not exist */
- + if (get_file_mode (subdir) == -1)
- + continue;
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_BIND_MOUNT, BIND_READONLY,
- + subdir, subdir);
- + }
- +
- + break;
- +
- + case SETUP_MOUNT_DEV:
- + if (mkdir (dest, 0755) != 0 && errno != EEXIST)
- + die_with_error ("Can't mkdir %s", op->dest);
- +
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_TMPFS_MOUNT, 0,
- + dest, NULL);
- +
- + static const char *const devnodes[] = { "null", "zero", "full", "random", "urandom", "tty" };
- + for (i = 0; i < N_ELEMENTS (devnodes); i++)
- + {
- + cleanup_free char *node_dest = strconcat3 (dest, "/", devnodes[i]);
- + cleanup_free char *node_src = strconcat ("/oldroot/dev/", devnodes[i]);
- + if (create_file (node_dest, 0666, NULL) != 0)
- + die_with_error ("Can't create file %s/%s", op->dest, devnodes[i]);
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_BIND_MOUNT, BIND_DEVICES,
- + node_src, node_dest);
- + }
- +
- + static const char *const stdionodes[] = { "stdin", "stdout", "stderr" };
- + for (i = 0; i < N_ELEMENTS (stdionodes); i++)
- + {
- + cleanup_free char *target = xasprintf ("/proc/self/fd/%d", i);
- + cleanup_free char *node_dest = strconcat3 (dest, "/", stdionodes[i]);
- + if (symlink (target, node_dest) < 0)
- + die_with_error ("Can't create symlink %s/%s", op->dest, stdionodes[i]);
- + }
- +
- + {
- + cleanup_free char *pts = strconcat (dest, "/pts");
- + cleanup_free char *ptmx = strconcat (dest, "/ptmx");
- + cleanup_free char *shm = strconcat (dest, "/shm");
- +
- + if (mkdir (shm, 0755) == -1)
- + die_with_error ("Can't create %s/shm", op->dest);
- +
- + if (mkdir (pts, 0755) == -1)
- + die_with_error ("Can't create %s/devpts", op->dest);
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_DEVPTS_MOUNT, 0, pts, NULL);
- +
- + if (symlink ("pts/ptmx", ptmx) != 0)
- + die_with_error ("Can't make symlink at %s/ptmx", op->dest);
- + }
- +
- + /* If stdout is a tty, that means the sandbox can write to the
- + outside-sandbox tty. In that case we also create a /dev/console
- + that points to this tty device. This should not cause any more
- + access than we already have, and it makes ttyname() work in the
- + sandbox. */
- + if (host_tty_dev != NULL && *host_tty_dev != 0)
- + {
- + cleanup_free char *src_tty_dev = strconcat ("/oldroot", host_tty_dev);
- + cleanup_free char *dest_console = strconcat (dest, "/console");
- +
- + if (create_file (dest_console, 0666, NULL) != 0)
- + die_with_error ("creating %s/console", op->dest);
- +
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_BIND_MOUNT, BIND_DEVICES,
- + src_tty_dev, dest_console);
- + }
- +
- + break;
- +
- + case SETUP_MOUNT_TMPFS:
- + if (mkdir (dest, 0755) != 0 && errno != EEXIST)
- + die_with_error ("Can't mkdir %s", op->dest);
- +
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_TMPFS_MOUNT, 0,
- + dest, NULL);
- + break;
- +
- + case SETUP_MOUNT_MQUEUE:
- + if (mkdir (dest, 0755) != 0 && errno != EEXIST)
- + die_with_error ("Can't mkdir %s", op->dest);
- +
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_MQUEUE_MOUNT, 0,
- + dest, NULL);
- + break;
- +
- + case SETUP_MAKE_DIR:
- + if (mkdir (dest, 0755) != 0 && errno != EEXIST)
- + die_with_error ("Can't mkdir %s", op->dest);
- +
- + break;
- +
- + case SETUP_MAKE_FILE:
- + {
- + cleanup_fd int dest_fd = -1;
- +
- + dest_fd = creat (dest, 0666);
- + if (dest_fd == -1)
- + die_with_error ("Can't create file %s", op->dest);
- +
- + if (copy_file_data (op->fd, dest_fd) != 0)
- + die_with_error ("Can't write data to file %s", op->dest);
- +
- + close (op->fd);
- + }
- + break;
- +
- + case SETUP_MAKE_BIND_FILE:
- + case SETUP_MAKE_RO_BIND_FILE:
- + {
- + cleanup_fd int dest_fd = -1;
- + char tempfile[] = "/bindfileXXXXXX";
- +
- + dest_fd = mkstemp (tempfile);
- + if (dest_fd == -1)
- + die_with_error ("Can't create tmpfile for %s", op->dest);
- +
- + if (copy_file_data (op->fd, dest_fd) != 0)
- + die_with_error ("Can't write data to file %s", op->dest);
- +
- + close (op->fd);
- +
- + if (ensure_file (dest, 0666) != 0)
- + die_with_error ("Can't create file at %s", op->dest);
- +
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_BIND_MOUNT,
- + (op->type == SETUP_MAKE_RO_BIND_FILE ? BIND_READONLY : 0),
- + tempfile, dest);
- +
- + /* Remove the file so we're sure the app can't get to it in any other way.
- + Its outside the container chroot, so it shouldn't be possible, but lets
- + make it really sure. */
- + unlink (tempfile);
- + }
- + break;
- +
- + case SETUP_MAKE_SYMLINK:
- + if (symlink (op->source, dest) != 0)
- + die_with_error ("Can't make symlink at %s", op->dest);
- + break;
- +
- + case SETUP_SET_HOSTNAME:
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_SET_HOSTNAME, 0,
- + op->dest, NULL);
- + break;
- +
- + default:
- + die ("Unexpected type %d", op->type);
- + }
- + }
- + privileged_op (privileged_op_socket,
- + PRIV_SEP_OP_DONE, 0, NULL, NULL);
- +}
- +
- +/* We need to resolve relative symlinks in the sandbox before we
- + chroot so that absolute symlinks are handled correctly. We also
- + need to do this after we've switched to the real uid so that
- + e.g. paths on fuse mounts work */
- +static void
- +resolve_symlinks_in_ops (void)
- +{
- + SetupOp *op;
- +
- + for (op = ops; op != NULL; op = op->next)
- + {
- + const char *old_source;
- +
- + switch (op->type)
- + {
- + case SETUP_RO_BIND_MOUNT:
- + case SETUP_DEV_BIND_MOUNT:
- + case SETUP_BIND_MOUNT:
- + old_source = op->source;
- + op->source = realpath (old_source, NULL);
- + if (op->source == NULL)
- + die_with_error ("Can't find source path %s", old_source);
- + break;
- + default:
- + break;
- + }
- + }
- +}
- +
- +
- +static const char *
- +resolve_string_offset (void *buffer,
- + size_t buffer_size,
- + uint32_t offset)
- +{
- + if (offset == 0)
- + return NULL;
- +
- + if (offset > buffer_size)
- + die ("Invalid string offset %d (buffer size %zd)", offset, buffer_size);
- +
- + return (const char *) buffer + offset;
- +}
- +
- +static uint32_t
- +read_priv_sec_op (int read_socket,
- + void *buffer,
- + size_t buffer_size,
- + uint32_t *flags,
- + const char **arg1,
- + const char **arg2)
- +{
- + const PrivSepOp *op = (const PrivSepOp *) buffer;
- + ssize_t rec_len;
- +
- + do
- + rec_len = read (read_socket, buffer, buffer_size - 1);
- + while (rec_len == -1 && errno == EINTR);
- +
- + if (rec_len < 0)
- + die_with_error ("Can't read from unprivileged helper");
- +
- + if (rec_len == 0)
- + exit (1); /* Privileged helper died and printed error, so exit silently */
- +
- + if (rec_len < sizeof (PrivSepOp))
- + die ("Invalid size %zd from unprivileged helper", rec_len);
- +
- + /* Guarantee zero termination of any strings */
- + ((char *) buffer)[rec_len] = 0;
- +
- + *flags = op->flags;
- + *arg1 = resolve_string_offset (buffer, rec_len, op->arg1_offset);
- + *arg2 = resolve_string_offset (buffer, rec_len, op->arg2_offset);
- +
- + return op->op;
- +}
- +
- +static void __attribute__ ((noreturn))
- +print_version_and_exit (void)
- +{
- + printf ("%s\n", PACKAGE_STRING);
- + exit (0);
- +}
- +
- +static void
- +parse_args_recurse (int *argcp,
- + char ***argvp,
- + bool in_file,
- + int *total_parsed_argc_p)
- +{
- + SetupOp *op;
- + int argc = *argcp;
- + char **argv = *argvp;
- + /* I can't imagine a case where someone wants more than this.
- + * If you do...you should be able to pass multiple files
- + * via a single tmpfs and linking them there, etc.
- + *
- + * We're adding this hardening due to precedent from
- + * http://googleprojectzero.blogspot.com/2014/08/the-poisoned-nul-byte-2014-edition.html
- + *
- + * I picked 9000 because the Internet told me to and it was hard to
- + * resist.
- + */
- + static const uint32_t MAX_ARGS = 9000;
- +
- + if (*total_parsed_argc_p > MAX_ARGS)
- + die ("Exceeded maximum number of arguments %u", MAX_ARGS);
- +
- + while (argc > 0)
- + {
- + const char *arg = argv[0];
- +
- + if (strcmp (arg, "--help") == 0)
- + {
- + usage (EXIT_SUCCESS, stdout);
- + }
- + else if (strcmp (arg, "--version") == 0)
- + {
- + print_version_and_exit ();
- + }
- + else if (strcmp (arg, "--args") == 0)
- + {
- + int the_fd;
- + char *endptr;
- + char *data, *p;
- + char *data_end;
- + size_t data_len;
- + cleanup_free char **data_argv = NULL;
- + char **data_argv_copy;
- + int data_argc;
- + int i;
- +
- + if (in_file)
- + die ("--args not supported in arguments file");
- +
- + if (argc < 2)
- + die ("--args takes an argument");
- +
- + the_fd = strtol (argv[1], &endptr, 10);
- + if (argv[1][0] == 0 || endptr[0] != 0 || the_fd < 0)
- + die ("Invalid fd: %s", argv[1]);
- +
- + data = load_file_data (the_fd, &data_len);
- + if (data == NULL)
- + die_with_error ("Can't read --args data");
- +
- + data_end = data + data_len;
- + data_argc = 0;
- +
- + p = data;
- + while (p != NULL && p < data_end)
- + {
- + data_argc++;
- + (*total_parsed_argc_p)++;
- + if (*total_parsed_argc_p > MAX_ARGS)
- + die ("Exceeded maximum number of arguments %u", MAX_ARGS);
- + p = memchr (p, 0, data_end - p);
- + if (p != NULL)
- + p++;
- + }
- +
- + data_argv = xcalloc (sizeof (char *) * (data_argc + 1));
- +
- + i = 0;
- + p = data;
- + while (p != NULL && p < data_end)
- + {
- + /* Note: load_file_data always adds a nul terminator, so this is safe
- + * even for the last string. */
- + data_argv[i++] = p;
- + p = memchr (p, 0, data_end - p);
- + if (p != NULL)
- + p++;
- + }
- +
- + data_argv_copy = data_argv; /* Don't change data_argv, we need to free it */
- + parse_args_recurse (&data_argc, &data_argv_copy, TRUE, total_parsed_argc_p);
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--unshare-all") == 0)
- + {
- + /* Keep this in order with the older (legacy) --unshare arguments,
- + * we use the --try variants of user and cgroup, since we want
- + * to support systems/kernels without support for those.
- + */
- + opt_unshare_user_try = opt_unshare_ipc = opt_unshare_pid =
- + opt_unshare_uts = opt_unshare_cgroup_try =
- + opt_unshare_net = TRUE;
- + }
- + /* Begin here the older individual --unshare variants */
- + else if (strcmp (arg, "--unshare-user") == 0)
- + {
- + opt_unshare_user = TRUE;
- + }
- + else if (strcmp (arg, "--unshare-user-try") == 0)
- + {
- + opt_unshare_user_try = TRUE;
- + }
- + else if (strcmp (arg, "--unshare-ipc") == 0)
- + {
- + opt_unshare_ipc = TRUE;
- + }
- + else if (strcmp (arg, "--unshare-pid") == 0)
- + {
- + opt_unshare_pid = TRUE;
- + }
- + else if (strcmp (arg, "--unshare-net") == 0)
- + {
- + opt_unshare_net = TRUE;
- + }
- + else if (strcmp (arg, "--unshare-uts") == 0)
- + {
- + opt_unshare_uts = TRUE;
- + }
- + else if (strcmp (arg, "--unshare-cgroup") == 0)
- + {
- + opt_unshare_cgroup = TRUE;
- + }
- + else if (strcmp (arg, "--unshare-cgroup-try") == 0)
- + {
- + opt_unshare_cgroup_try = TRUE;
- + }
- + /* Begin here the newer --share variants */
- + else if (strcmp (arg, "--share-net") == 0)
- + {
- + opt_unshare_net = FALSE;
- + }
- + /* End --share variants, other arguments begin */
- + else if (strcmp (arg, "--chdir") == 0)
- + {
- + if (argc < 2)
- + die ("--chdir takes one argument");
- +
- + opt_chdir_path = argv[1];
- + argv++;
- + argc--;
- + }
- + else if (strcmp (arg, "--remount-ro") == 0)
- + {
- + if (argc < 2)
- + die ("--remount-ro takes one argument");
- +
- + SetupOp *op = setup_op_new (SETUP_REMOUNT_RO_NO_RECURSIVE);
- + op->dest = argv[1];
- +
- + argv++;
- + argc--;
- + }
- + else if (strcmp (arg, "--bind") == 0)
- + {
- + if (argc < 3)
- + die ("--bind takes two arguments");
- +
- + op = setup_op_new (SETUP_BIND_MOUNT);
- + op->source = argv[1];
- + op->dest = argv[2];
- +
- + argv += 2;
- + argc -= 2;
- + }
- + else if (strcmp (arg, "--ro-bind") == 0)
- + {
- + if (argc < 3)
- + die ("--ro-bind takes two arguments");
- +
- + op = setup_op_new (SETUP_RO_BIND_MOUNT);
- + op->source = argv[1];
- + op->dest = argv[2];
- +
- + argv += 2;
- + argc -= 2;
- + }
- + else if (strcmp (arg, "--dev-bind") == 0)
- + {
- + if (argc < 3)
- + die ("--dev-bind takes two arguments");
- +
- + op = setup_op_new (SETUP_DEV_BIND_MOUNT);
- + op->source = argv[1];
- + op->dest = argv[2];
- +
- + argv += 2;
- + argc -= 2;
- + }
- + else if (strcmp (arg, "--proc") == 0)
- + {
- + if (argc < 2)
- + die ("--proc takes an argument");
- +
- + op = setup_op_new (SETUP_MOUNT_PROC);
- + op->dest = argv[1];
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--exec-label") == 0)
- + {
- + if (argc < 2)
- + die ("--exec-label takes an argument");
- + opt_exec_label = argv[1];
- + die_unless_label_valid (opt_exec_label);
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--file-label") == 0)
- + {
- + if (argc < 2)
- + die ("--file-label takes an argument");
- + opt_file_label = argv[1];
- + die_unless_label_valid (opt_file_label);
- + if (label_create_file (opt_file_label))
- + die_with_error ("--file-label setup failed");
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--dev") == 0)
- + {
- + if (argc < 2)
- + die ("--dev takes an argument");
- +
- + op = setup_op_new (SETUP_MOUNT_DEV);
- + op->dest = argv[1];
- + opt_needs_devpts = TRUE;
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--tmpfs") == 0)
- + {
- + if (argc < 2)
- + die ("--tmpfs takes an argument");
- +
- + op = setup_op_new (SETUP_MOUNT_TMPFS);
- + op->dest = argv[1];
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--mqueue") == 0)
- + {
- + if (argc < 2)
- + die ("--mqueue takes an argument");
- +
- + op = setup_op_new (SETUP_MOUNT_MQUEUE);
- + op->dest = argv[1];
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--dir") == 0)
- + {
- + if (argc < 2)
- + die ("--dir takes an argument");
- +
- + op = setup_op_new (SETUP_MAKE_DIR);
- + op->dest = argv[1];
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--file") == 0)
- + {
- + int file_fd;
- + char *endptr;
- +
- + if (argc < 3)
- + die ("--file takes two arguments");
- +
- + file_fd = strtol (argv[1], &endptr, 10);
- + if (argv[1][0] == 0 || endptr[0] != 0 || file_fd < 0)
- + die ("Invalid fd: %s", argv[1]);
- +
- + op = setup_op_new (SETUP_MAKE_FILE);
- + op->fd = file_fd;
- + op->dest = argv[2];
- +
- + argv += 2;
- + argc -= 2;
- + }
- + else if (strcmp (arg, "--bind-data") == 0)
- + {
- + int file_fd;
- + char *endptr;
- +
- + if (argc < 3)
- + die ("--bind-data takes two arguments");
- +
- + file_fd = strtol (argv[1], &endptr, 10);
- + if (argv[1][0] == 0 || endptr[0] != 0 || file_fd < 0)
- + die ("Invalid fd: %s", argv[1]);
- +
- + op = setup_op_new (SETUP_MAKE_BIND_FILE);
- + op->fd = file_fd;
- + op->dest = argv[2];
- +
- + argv += 2;
- + argc -= 2;
- + }
- + else if (strcmp (arg, "--ro-bind-data") == 0)
- + {
- + int file_fd;
- + char *endptr;
- +
- + if (argc < 3)
- + die ("--ro-bind-data takes two arguments");
- +
- + file_fd = strtol (argv[1], &endptr, 10);
- + if (argv[1][0] == 0 || endptr[0] != 0 || file_fd < 0)
- + die ("Invalid fd: %s", argv[1]);
- +
- + op = setup_op_new (SETUP_MAKE_RO_BIND_FILE);
- + op->fd = file_fd;
- + op->dest = argv[2];
- +
- + argv += 2;
- + argc -= 2;
- + }
- + else if (strcmp (arg, "--symlink") == 0)
- + {
- + if (argc < 3)
- + die ("--symlink takes two arguments");
- +
- + op = setup_op_new (SETUP_MAKE_SYMLINK);
- + op->source = argv[1];
- + op->dest = argv[2];
- +
- + argv += 2;
- + argc -= 2;
- + }
- + else if (strcmp (arg, "--lock-file") == 0)
- + {
- + if (argc < 2)
- + die ("--lock-file takes an argument");
- +
- + (void) lock_file_new (argv[1]);
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--sync-fd") == 0)
- + {
- + int the_fd;
- + char *endptr;
- +
- + if (argc < 2)
- + die ("--sync-fd takes an argument");
- +
- + the_fd = strtol (argv[1], &endptr, 10);
- + if (argv[1][0] == 0 || endptr[0] != 0 || the_fd < 0)
- + die ("Invalid fd: %s", argv[1]);
- +
- + opt_sync_fd = the_fd;
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--block-fd") == 0)
- + {
- + int the_fd;
- + char *endptr;
- +
- + if (argc < 2)
- + die ("--block-fd takes an argument");
- +
- + the_fd = strtol (argv[1], &endptr, 10);
- + if (argv[1][0] == 0 || endptr[0] != 0 || the_fd < 0)
- + die ("Invalid fd: %s", argv[1]);
- +
- + opt_block_fd = the_fd;
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--info-fd") == 0)
- + {
- + int the_fd;
- + char *endptr;
- +
- + if (argc < 2)
- + die ("--info-fd takes an argument");
- +
- + the_fd = strtol (argv[1], &endptr, 10);
- + if (argv[1][0] == 0 || endptr[0] != 0 || the_fd < 0)
- + die ("Invalid fd: %s", argv[1]);
- +
- + opt_info_fd = the_fd;
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--seccomp") == 0)
- + {
- + int the_fd;
- + char *endptr;
- +
- + if (argc < 2)
- + die ("--seccomp takes an argument");
- +
- + the_fd = strtol (argv[1], &endptr, 10);
- + if (argv[1][0] == 0 || endptr[0] != 0 || the_fd < 0)
- + die ("Invalid fd: %s", argv[1]);
- +
- + opt_seccomp_fd = the_fd;
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--setenv") == 0)
- + {
- + if (argc < 3)
- + die ("--setenv takes two arguments");
- +
- + xsetenv (argv[1], argv[2], 1);
- +
- + argv += 2;
- + argc -= 2;
- + }
- + else if (strcmp (arg, "--unsetenv") == 0)
- + {
- + if (argc < 2)
- + die ("--unsetenv takes an argument");
- +
- + xunsetenv (argv[1]);
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--uid") == 0)
- + {
- + int the_uid;
- + char *endptr;
- +
- + if (argc < 2)
- + die ("--uid takes an argument");
- +
- + the_uid = strtol (argv[1], &endptr, 10);
- + if (argv[1][0] == 0 || endptr[0] != 0 || the_uid < 0)
- + die ("Invalid uid: %s", argv[1]);
- +
- + opt_sandbox_uid = the_uid;
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--gid") == 0)
- + {
- + int the_gid;
- + char *endptr;
- +
- + if (argc < 2)
- + die ("--gid takes an argument");
- +
- + the_gid = strtol (argv[1], &endptr, 10);
- + if (argv[1][0] == 0 || endptr[0] != 0 || the_gid < 0)
- + die ("Invalid gid: %s", argv[1]);
- +
- + opt_sandbox_gid = the_gid;
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--hostname") == 0)
- + {
- + if (argc < 2)
- + die ("--hostname takes an argument");
- +
- + op = setup_op_new (SETUP_SET_HOSTNAME);
- + op->dest = argv[1];
- + op->flags = NO_CREATE_DEST;
- +
- + opt_sandbox_hostname = argv[1];
- +
- + argv += 1;
- + argc -= 1;
- + }
- + else if (strcmp (arg, "--new-session") == 0)
- + {
- + opt_new_session = TRUE;
- + }
- + else if (strcmp (arg, "--die-with-parent") == 0)
- + {
- + opt_die_with_parent = TRUE;
- + }
- + else if (*arg == '-')
- + {
- + die ("Unknown option %s", arg);
- + }
- + else
- + {
- + break;
- + }
- +
- + argv++;
- + argc--;
- + }
- +
- + *argcp = argc;
- + *argvp = argv;
- +}
- +
- +static void
- +parse_args (int *argcp,
- + char ***argvp)
- +{
- + int total_parsed_argc = *argcp;
- +
- + parse_args_recurse (argcp, argvp, FALSE, &total_parsed_argc);
- +}
- +
- +static void
- +read_overflowids (void)
- +{
- + cleanup_free char *uid_data = NULL;
- + cleanup_free char *gid_data = NULL;
- +
- + uid_data = load_file_at (AT_FDCWD, "/proc/sys/kernel/overflowuid");
- + if (uid_data == NULL)
- + die_with_error ("Can't read /proc/sys/kernel/overflowuid");
- +
- + overflow_uid = strtol (uid_data, NULL, 10);
- + if (overflow_uid == 0)
- + die ("Can't parse /proc/sys/kernel/overflowuid");
- +
- + gid_data = load_file_at (AT_FDCWD, "/proc/sys/kernel/overflowgid");
- + if (gid_data == NULL)
- + die_with_error ("Can't read /proc/sys/kernel/overflowgid");
- +
- + overflow_gid = strtol (gid_data, NULL, 10);
- + if (overflow_gid == 0)
- + die ("Can't parse /proc/sys/kernel/overflowgid");
- +}
- +
- +int
- +main (int argc,
- + char **argv)
- +{
- + mode_t old_umask;
- + cleanup_free char *base_path = NULL;
- + int clone_flags;
- + char *old_cwd = NULL;
- + pid_t pid;
- + int event_fd = -1;
- + int child_wait_fd = -1;
- + const char *new_cwd;
- + uid_t ns_uid;
- + gid_t ns_gid;
- + struct stat sbuf;
- + uint64_t val;
- + int res UNUSED;
- + cleanup_free char *seccomp_data = NULL;
- + size_t seccomp_len;
- + struct sock_fprog seccomp_prog;
- +
- + /* Handle --version early on before we try to acquire/drop
- + * any capabilities so it works in a build environment;
- + * right now flatpak's build runs bubblewrap --version.
- + * https://github.com/projectatomic/bubblewrap/issues/185
- + */
- + if (argc == 2 && (strcmp (argv[1], "--version") == 0))
- + print_version_and_exit ();
- +
- + real_uid = getuid ();
- + real_gid = getgid ();
- +
- + /* Get the (optional) privileges we need */
- + acquire_privs ();
- +
- + /* Never gain any more privs during exec */
- + if (prctl (PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0) < 0)
- + die_with_error ("prctl(PR_SET_NO_NEW_CAPS) failed");
- +
- + /* The initial code is run with high permissions
- + (i.e. CAP_SYS_ADMIN), so take lots of care. */
- +
- + read_overflowids ();
- +
- + argv0 = argv[0];
- +
- + if (isatty (1))
- + host_tty_dev = ttyname (1);
- +
- + argv++;
- + argc--;
- +
- + if (argc == 0)
- + usage (EXIT_FAILURE, stderr);
- +
- + parse_args (&argc, &argv);
- +
- + /* We have to do this if we weren't installed setuid (and we're not
- + * root), so let's just DWIM */
- + if (!is_privileged && getuid () != 0)
- + opt_unshare_user = TRUE;
- +
- +#ifdef ENABLE_REQUIRE_USERNS
- + /* In this build option, we require userns. */
- + if (is_privileged && getuid () != 0)
- + opt_unshare_user = TRUE;
- +#endif
- +
- + if (opt_unshare_user_try &&
- + stat ("/proc/self/ns/user", &sbuf) == 0)
- + {
- + bool disabled = FALSE;
- +
- + /* RHEL7 has a kernel module parameter that lets you enable user namespaces */
- + if (stat ("/sys/module/user_namespace/parameters/enable", &sbuf) == 0)
- + {
- + cleanup_free char *enable = NULL;
- + enable = load_file_at (AT_FDCWD, "/sys/module/user_namespace/parameters/enable");
- + if (enable != NULL && enable[0] == 'N')
- + disabled = TRUE;
- + }
- +
- + /* Debian lets you disable *unprivileged* user namespaces. However this is not
- + a problem if we're privileged, and if we're not opt_unshare_user is TRUE
- + already, and there is not much we can do, its just a non-working setup. */
- +
- + if (!disabled)
- + opt_unshare_user = TRUE;
- + }
- +
- + if (argc == 0)
- + usage (EXIT_FAILURE, stderr);
- +
- + __debug__ (("Creating root mount point\n"));
- +
- + if (opt_sandbox_uid == -1)
- + opt_sandbox_uid = real_uid;
- + if (opt_sandbox_gid == -1)
- + opt_sandbox_gid = real_gid;
- +
- + if (!opt_unshare_user && opt_sandbox_uid != real_uid)
- + die ("Specifying --uid requires --unshare-user");
- +
- + if (!opt_unshare_user && opt_sandbox_gid != real_gid)
- + die ("Specifying --gid requires --unshare-user");
- +
- + if (!opt_unshare_uts && opt_sandbox_hostname != NULL)
- + die ("Specifying --hostname requires --unshare-uts");
- +
- + /* We need to read stuff from proc during the pivot_root dance, etc.
- + Lets keep a fd to it open */
- + proc_fd = open ("/proc", O_RDONLY | O_PATH);
- + if (proc_fd == -1)
- + die_with_error ("Can't open /proc");
- +
- + /* We need *some* mountpoint where we can mount the root tmpfs.
- + We first try in /run, and if that fails, try in /tmp. */
- + base_path = xasprintf ("/run/user/%d/.bubblewrap", real_uid);
- + if (mkdir (base_path, 0755) && errno != EEXIST)
- + {
- + free (base_path);
- + base_path = xasprintf ("/tmp/.bubblewrap-%d", real_uid);
- + if (mkdir (base_path, 0755) && errno != EEXIST)
- + die_with_error ("Creating root mountpoint failed");
- + }
- +
- + __debug__ (("creating new namespace\n"));
- +
- + if (opt_unshare_pid)
- + {
- + event_fd = eventfd (0, EFD_CLOEXEC | EFD_NONBLOCK);
- + if (event_fd == -1)
- + die_with_error ("eventfd()");
- + }
- +
- + /* We block sigchild here so that we can use signalfd in the monitor. */
- + block_sigchild ();
- +
- + clone_flags = SIGCHLD | CLONE_NEWNS;
- + if (opt_unshare_user)
- + clone_flags |= CLONE_NEWUSER;
- + if (opt_unshare_pid)
- + clone_flags |= CLONE_NEWPID;
- + if (opt_unshare_net)
- + clone_flags |= CLONE_NEWNET;
- + if (opt_unshare_ipc)
- + clone_flags |= CLONE_NEWIPC;
- + if (opt_unshare_uts)
- + clone_flags |= CLONE_NEWUTS;
- + if (opt_unshare_cgroup)
- + {
- + if (stat ("/proc/self/ns/cgroup", &sbuf))
- + {
- + if (errno == ENOENT)
- + die ("Cannot create new cgroup namespace because the kernel does not support it");
- + else
- + die_with_error ("stat on /proc/self/ns/cgroup failed");
- + }
- + clone_flags |= CLONE_NEWCGROUP;
- + }
- + if (opt_unshare_cgroup_try)
- + if (!stat ("/proc/self/ns/cgroup", &sbuf))
- + clone_flags |= CLONE_NEWCGROUP;
- +
- + child_wait_fd = eventfd (0, EFD_CLOEXEC);
- + if (child_wait_fd == -1)
- + die_with_error ("eventfd()");
- +
- + pid = raw_clone (clone_flags, NULL);
- + if (pid == -1)
- + {
- + if (opt_unshare_user)
- + {
- + if (errno == EINVAL)
- + die ("Creating new namespace failed, likely because the kernel does not support user namespaces. bwrap must be installed setuid on such systems.");
- + else if (errno == EPERM && !is_privileged)
- + die ("No permissions to creating new namespace, likely because the kernel does not allow non-privileged user namespaces. On e.g. debian this can be enabled with 'sysctl kernel.unprivileged_userns_clone=1'.");
- + }
- +
- + die_with_error ("Creating new namespace failed");
- + }
- +
- + ns_uid = opt_sandbox_uid;
- + ns_gid = opt_sandbox_gid;
- +
- + if (pid != 0)
- + {
- + /* Parent, outside sandbox, privileged (initially) */
- +
- + if (is_privileged && opt_unshare_user)
- + {
- + /* We're running as euid 0, but the uid we want to map is
- + * not 0. This means we're not allowed to write this from
- + * the child user namespace, so we do it from the parent.
- + *
- + * Also, we map uid/gid 0 in the namespace (to overflowuid)
- + * if opt_needs_devpts is true, because otherwise the mount
- + * of devpts fails due to root not being mapped.
- + */
- + write_uid_gid_map (ns_uid, real_uid,
- + ns_gid, real_gid,
- + pid, TRUE, opt_needs_devpts);
- + }
- +
- + /* Initial launched process, wait for exec:ed command to exit */
- +
- + /* We don't need any privileges in the launcher, drop them immediately. */
- + drop_privs ();
- +
- + /* Optionally bind our lifecycle to that of the parent */
- + handle_die_with_parent ();
- +
- + /* Let child run now that the uid maps are set up */
- + val = 1;
- + res = write (child_wait_fd, &val, 8);
- + /* Ignore res, if e.g. the child died and closed child_wait_fd we don't want to error out here */
- + close (child_wait_fd);
- +
- + if (opt_info_fd != -1)
- + {
- + cleanup_free char *output = xasprintf ("{\n \"child-pid\": %i\n}\n", pid);
- + size_t len = strlen (output);
- + if (write (opt_info_fd, output, len) != len)
- + die_with_error ("Write to info_fd");
- + close (opt_info_fd);
- + }
- +
- + monitor_child (event_fd, pid);
- + exit (0); /* Should not be reached, but better safe... */
- + }
- +
- + /* Child, in sandbox, privileged in the parent or in the user namespace (if --unshare-user).
- + *
- + * Note that for user namespaces we run as euid 0 during clone(), so
- + * the child user namespace is owned by euid 0., This means that the
- + * regular user namespace parent (with uid != 0) doesn't have any
- + * capabilities in it, which is nice as we can't exploit those. In
- + * particular the parent user namespace doesn't have CAP_PTRACE
- + * which would otherwise allow the parent to hijack of the child
- + * after this point.
- + *
- + * Unfortunately this also means you can't ptrace the final
- + * sandboxed process from outside the sandbox either.
- + */
- +
- + if (opt_info_fd != -1)
- + close (opt_info_fd);
- +
- + /* Wait for the parent to init uid/gid maps and drop caps */
- + res = read (child_wait_fd, &val, 8);
- + close (child_wait_fd);
- +
- + /* At this point we can completely drop root uid, but retain the
- + * required permitted caps. This allow us to do full setup as
- + * the user uid, which makes e.g. fuse access work.
- + */
- + switch_to_user_with_privs ();
- +
- + if (opt_unshare_net)
- + loopback_setup (); /* Will exit if unsuccessful */
- +
- + ns_uid = opt_sandbox_uid;
- + ns_gid = opt_sandbox_gid;
- + if (!is_privileged && opt_unshare_user)
- + {
- + /* In the unprivileged case we have to write the uid/gid maps in
- + * the child, because we have no caps in the parent */
- +
- + if (opt_needs_devpts)
- + {
- + /* This is a bit hacky, but we need to first map the real uid/gid to
- + 0, otherwise we can't mount the devpts filesystem because root is
- + not mapped. Later we will create another child user namespace and
- + map back to the real uid */
- + ns_uid = 0;
- + ns_gid = 0;
- + }
- +
- + write_uid_gid_map (ns_uid, real_uid,
- + ns_gid, real_gid,
- + -1, TRUE, FALSE);
- + }
- +
- + old_umask = umask (0);
- +
- + /* Need to do this before the chroot, but after we're the real uid */
- + resolve_symlinks_in_ops ();
- +
- + /* Mark everything as slave, so that we still
- + * receive mounts from the real root, but don't
- + * propagate mounts to the real root. */
- + if (mount (NULL, "/", NULL, MS_SLAVE | MS_REC, NULL) < 0)
- + die_with_error ("Failed to make / slave");
- +
- + /* Create a tmpfs which we will use as / in the namespace */
- + if (mount ("", base_path, "tmpfs", MS_NODEV | MS_NOSUID, NULL) != 0)
- + die_with_error ("Failed to mount tmpfs");
- +
- + old_cwd = get_current_dir_name ();
- +
- + /* Chdir to the new root tmpfs mount. This will be the CWD during
- + the entire setup. Access old or new root via "oldroot" and "newroot". */
- + if (chdir (base_path) != 0)
- + die_with_error ("chdir base_path");
- +
- + /* We create a subdir "$base_path/newroot" for the new root, that
- + * way we can pivot_root to base_path, and put the old root at
- + * "$base_path/oldroot". This avoids problems accessing the oldroot
- + * dir if the user requested to bind mount something over / */
- +
- + if (mkdir ("newroot", 0755))
- + die_with_error ("Creating newroot failed");
- +
- + if (mkdir ("oldroot", 0755))
- + die_with_error ("Creating oldroot failed");
- +
- + if (pivot_root (base_path, "oldroot"))
- + die_with_error ("pivot_root");
- +
- + if (chdir ("/") != 0)
- + die_with_error ("chdir / (base path)");
- +
- + if (is_privileged)
- + {
- + pid_t child;
- + int privsep_sockets[2];
- +
- + if (socketpair (AF_UNIX, SOCK_SEQPACKET | SOCK_CLOEXEC, 0, privsep_sockets) != 0)
- + die_with_error ("Can't create privsep socket");
- +
- + child = fork ();
- + if (child == -1)
- + die_with_error ("Can't fork unprivileged helper");
- +
- + if (child == 0)
- + {
- + /* Unprivileged setup process */
- + drop_privs ();
- + close (privsep_sockets[0]);
- + setup_newroot (opt_unshare_pid, privsep_sockets[1]);
- + exit (0);
- + }
- + else
- + {
- + int status;
- + uint32_t buffer[2048]; /* 8k, but is int32 to guarantee nice alignment */
- + uint32_t op, flags;
- + const char *arg1, *arg2;
- + cleanup_fd int unpriv_socket = -1;
- +
- + unpriv_socket = privsep_sockets[0];
- + close (privsep_sockets[1]);
- +
- + do
- + {
- + op = read_priv_sec_op (unpriv_socket, buffer, sizeof (buffer),
- + &flags, &arg1, &arg2);
- + privileged_op (-1, op, flags, arg1, arg2);
- + if (write (unpriv_socket, buffer, 1) != 1)
- + die ("Can't write to op_socket");
- + }
- + while (op != PRIV_SEP_OP_DONE);
- +
- + waitpid (child, &status, 0);
- + /* Continue post setup */
- + }
- + }
- + else
- + {
- + setup_newroot (opt_unshare_pid, -1);
- + }
- +
- + /* The old root better be rprivate or we will send unmount events to the parent namespace */
- + if (mount ("oldroot", "oldroot", NULL, MS_REC | MS_PRIVATE, NULL) != 0)
- + die_with_error ("Failed to make old root rprivate");
- +
- + if (umount2 ("oldroot", MNT_DETACH))
- + die_with_error ("unmount old root");
- +
- + if (opt_unshare_user &&
- + (ns_uid != opt_sandbox_uid || ns_gid != opt_sandbox_gid))
- + {
- + /* Now that devpts is mounted and we've no need for mount
- + permissions we can create a new userspace and map our uid
- + 1:1 */
- +
- + if (unshare (CLONE_NEWUSER))
- + die_with_error ("unshare user ns");
- +
- + write_uid_gid_map (opt_sandbox_uid, ns_uid,
- + opt_sandbox_gid, ns_gid,
- + -1, FALSE, FALSE);
- + }
- +
- + /* Now make /newroot the real root */
- + if (chdir ("/newroot") != 0)
- + die_with_error ("chdir newroot");
- + if (chroot ("/newroot") != 0)
- + die_with_error ("chroot /newroot");
- + if (chdir ("/") != 0)
- + die_with_error ("chdir /");
- +
- + /* All privileged ops are done now, so drop it */
- + drop_privs ();
- +
- + if (opt_block_fd != -1)
- + {
- + char b[1];
- + read (opt_block_fd, b, 1);
- + close (opt_block_fd);
- + }
- +
- + if (opt_seccomp_fd != -1)
- + {
- + seccomp_data = load_file_data (opt_seccomp_fd, &seccomp_len);
- + if (seccomp_data == NULL)
- + die_with_error ("Can't read seccomp data");
- +
- + if (seccomp_len % 8 != 0)
- + die ("Invalid seccomp data, must be multiple of 8");
- +
- + seccomp_prog.len = seccomp_len / 8;
- + seccomp_prog.filter = (struct sock_filter *) seccomp_data;
- +
- + close (opt_seccomp_fd);
- + }
- +
- + umask (old_umask);
- +
- + new_cwd = "/";
- + if (opt_chdir_path)
- + {
- + if (chdir (opt_chdir_path))
- + die_with_error ("Can't chdir to %s", opt_chdir_path);
- + new_cwd = opt_chdir_path;
- + }
- + else if (chdir (old_cwd) == 0)
- + {
- + /* If the old cwd is mapped in the sandbox, go there */
- + new_cwd = old_cwd;
- + }
- + else
- + {
- + /* If the old cwd is not mapped, go to home */
- + const char *home = getenv ("HOME");
- + if (home != NULL &&
- + chdir (home) == 0)
- + new_cwd = home;
- + }
- + xsetenv ("PWD", new_cwd, 1);
- + free (old_cwd);
- +
- + if (opt_new_session &&
- + setsid () == (pid_t) -1)
- + die_with_error ("setsid");
- +
- + if (label_exec (opt_exec_label) == -1)
- + die_with_error ("label_exec %s", argv[0]);
- +
- + __debug__ (("forking for child\n"));
- +
- + if (opt_unshare_pid || lock_files != NULL || opt_sync_fd != -1)
- + {
- + /* We have to have a pid 1 in the pid namespace, because
- + * otherwise we'll get a bunch of zombies as nothing reaps
- + * them. Alternatively if we're using sync_fd or lock_files we
- + * need some process to own these.
- + */
- +
- + pid = fork ();
- + if (pid == -1)
- + die_with_error ("Can't fork for pid 1");
- +
- + if (pid != 0)
- + {
- + /* Close fds in pid 1, except stdio and optionally event_fd
- + (for syncing pid 2 lifetime with monitor_child) and
- + opt_sync_fd (for syncing sandbox lifetime with outside
- + process).
- + Any other fds will been passed on to the child though. */
- + {
- + int dont_close[3];
- + int j = 0;
- + if (event_fd != -1)
- + dont_close[j++] = event_fd;
- + if (opt_sync_fd != -1)
- + dont_close[j++] = opt_sync_fd;
- + dont_close[j++] = -1;
- + fdwalk (proc_fd, close_extra_fds, dont_close);
- + }
- +
- + return do_init (event_fd, pid, seccomp_data != NULL ? &seccomp_prog : NULL);
- + }
- + }
- +
- + __debug__ (("launch executable %s\n", argv[0]));
- +
- + if (proc_fd != -1)
- + close (proc_fd);
- +
- + if (opt_sync_fd != -1)
- + close (opt_sync_fd);
- +
- + /* We want sigchild in the child */
- + unblock_sigchild ();
- +
- + /* Optionally bind our lifecycle */
- + handle_die_with_parent ();
- +
- + /* Should be the last thing before execve() so that filters don't
- + * need to handle anything above */
- + if (seccomp_data != NULL &&
- + prctl (PR_SET_SECCOMP, SECCOMP_MODE_FILTER, &seccomp_prog) != 0)
- + die_with_error ("prctl(PR_SET_SECCOMP)");
- +
- + if (execvp (argv[0], argv) == -1)
- + die_with_error ("execvp %s", argv[0]);
- +
- + return 0;
- +}
- diff -Nuar flatpak-1.0.0.orig/bubblewrap/bubblewrap.jpg flatpak-1.0.0/bubblewrap/bubblewrap.jpg
- --- flatpak-1.0.0.orig/bubblewrap/bubblewrap.jpg 1970-01-01 02:00:00.000000000 +0200
- +++ flatpak-1.0.0/bubblewrap/bubblewrap.jpg 2018-02-03 21:26:06.273233339 +0300
- @@ -0,0 +1,143 @@
- +ÿØÿà JFIF H H ÿÛ C ÿÛ CÿÂ ´ ð ÿÄ
- +ÿÄ ÿÚ õc6Mø‹5G?¢orŽ¹y-ã=:I.lÖ¯ Õv+Ü�jŒÛóJ¾¤ÇÒçNØí„�1%†=õ¬UÉ®ñ·¡P|5q6÷š`:Ýy/M=.qðÀ$ÀÇ l_‘ŒÓ›g7ù}° <
- +DoMœ€Á�‘sÌÿ _‘ê�ÚVsf5Döj—÷s¬ñˆ2¥`w5^.Ÿv¶b'Ódÿ IžóȯH”m†XŠ3!‚”e7aß%½QY«š:x)¯ÑÁ3ÿ ›ÞÏrah_×±ÂÊRZ™¯*ÒP·)E˦à á•Û¦Àý7È.¦K6 q'qÂçäÛóÓÊoÒ‹¬jØ9ª»°¬Ì㱞õ˹Ná9SjR¥r®UÅT/вa:îBiÓeãß{.ùÞ¥ý+ÇõÏ[5DœE<«<Ï‹s0y�Åæeð®}õFË¥a|áfëæ¡,WA[HI†Ïž€×¦u]ÙR–Èóú²ÐÆNÎÒd&Ôî)4+}½‡é¹Áêi÷3W7ÜW"Y“Ïèf?7¶?›¢•«
- +6hôªë=Œ¡Jyô‚÷f;iBéÓÑ©©é´V9gÙbŠÐéÖV©`Ñ�_læï[3ÖãÂ6<V7ÃÝ�énNóÚXKËo¬ÖãÐ-äêí: ¨f@ÊÑÐÃ3ëXÍâjkÔÐ>³`z,R5± —£`…gÚÂaÆÐÒë6D�/ªÉaD2dg«‰ ŽGŠRYWGÏ1ºÃ¡k[èÐrÜC:õK"%üöÖãÔø÷³Å[ºBþ~gßÈØÛÌ|dƒãM†ªl˜™Ia„�é
tp¥Î!•µøG¡nuX&!ìKµÛ˜ü®ó¤GNhÒ-°™ŒŽ:jç—p5R>{mG£Añv¶T²“�açß zìRe[xÉW¥öO0!牮�P-d,Ñþ½ww~��Q¸æu_º´˜vSdcB<·T¥Õžgbï2÷vÖr>ß”oŸKþƒãœ
êÊæ!AÍ™
- +àlF!áf%hQ¼‚¡žd¾žº]~•µÏŠôO½œææ¥H‰ ð°™�Ãk;<»—xšLKô¬k1YNÎ֩蟵óÎåšZ‹�+2|ÄŽëA&à.\�Éa �pÁ¾Ò%BÇÈïôe_Õ>¯Sy[OEIOO>¹¨:3,a¼M�TŽ¢³CE±hÊ·~�äœÖœ%/•p˜9˜qpõ:
- +vpi);y˜$¡ÆC´¾Ì9!ó¿Xݲ— Êϲx1Ë�³¦V—etâLM,œ\¿0ôƒ4ÔzÔº'Ûy–‹"dpA+‡ÄÝ‘‚ܵd/îVá'aÁ·sÁ¡Ÿ;õ6ý>7+gÛq1VR‘k>”oeTóÛÉúO5uóïå/:vJ
.
ŒíƒêðÙ�ÖEÔµ�Á Ë ©105ÊÈý¡\ž8‚8Û¤ÌOš]Ýã7´ã+.ÀémÅ€•Ýʾy¨…;)fGÞÃ"?«s”ëjŸK‹¦ö¨<¤*Ë»‡è8\âI÷-ZΊ’¶ž|l8A–ÊÜ»óº'Íß1}>Qzˆ\An¾IòßK¬§¥ƒ=ÏÊ™SÐÿ ;§ .T�¡–}í°ô6�kžÒ •ÉÊÉ„Î6!²º‚RèQ6°H‚¬/r7ƒ|퉲.VžµÁ5o(ô¥!.ö[+Ó•Øñ¿[>zßM4©½™¨8gÀ&sÍuM¤6}jpHeñ3CŸ
- +5à¯Ò§qö�”ñÓ4ß–xÁk[ͺÕýÎÇnFÒÊÈ®=y·›}Qå„=Þ}Üû£9$*j€Á¢¦RO1b\7ðJ 7¥ƒ*9º³™ÝŸ|÷©ÌتÑó œ{9º�šr–3ѵsí[jçÖz¼]!¥VG2æJ‹¡ƒú²§’!€„¶€Œ-T:¼éî–E¯OÃ?A0ÞèšúöÔ^kÖw¼©!×»ÎrÛ\yÕÞÞ‡5¿¯@åë¿™ïàè'˜‚Á6¦ô«†‹„ƒ¸ÍG ÂCBxÏ—†ÆÔ©]ÀÂì4O!>5n#Ûn®Ñr:0µDµ)2l(rÕi€t.÷_
˜³òb`’Ô�sÃÁm3bï��ƹ€^+Y†‘Ë!ä&ØLœ¬ƒæ%Œ† ˜ô›wE0ƒ1v]Xä÷Yw\Y÷�w,ÁŠ£üJf¤drAm53ZÎò",kNèVkº:4Y0üH»Ñ�š-¶,]QAvm´ýÅ>™·Øj«a]¤dIŸ��Ç5\ˆ$P§»dGD�¦?ÿÄ % !"#$ÿÚ ö¾k¡í
- +L†¼ôXZÃVÿ {6ŸÒkïžËR‰çlÃ@g¶Îþ.ˆT r³Ð¶nöõJ²ÎgÕ�2.dGÐt÷œª�%󚩆¬kÊ-AùTA`LO„^’3ö»úÃL¹ÓëyŸÎDP9Ÿ\üùòor‰Šv ¨ ¨EÃý·Þ )ö"?W¯å%¯ü„ÑÉק}ÂY‡O¹Çy™°žÍuò¯£œŠ¬³„ÐÍz:[7¥šêìçÜ×8‹S�;AwWû�·¬B'à[ûË ÿ 5™')óòƒ6P&IÈBTmO4¶HžÓHÒgé‹ãºˆ(ýªÈt„1ý«@oòü€½Úçò73s¡Þ«^Z‡C;Ãaê3T,¿�€Ð“í*³ŒsK@Ö>©Öhoár]{vz5ÉXz è•ûƒ -Iš0i«C^Ò]ª‚£íVåMƒš%4®“¢Õ¦¢z#?7âà:¶!Y¢Ã ª8¥|ü±ªUó,Ÿ©HéF1/ù5:®^뛆ƒ£k˜zÖ‹f???*)Ó][dÂÝö3òŠD2‘þpÖÛؼöÂiW)´ý‹UJ#–%ç9Üïb�s|ØXJãÅYMqu›M1Gú
Bð\�gÝßôÙÒ—>µB_Ø&½âÁ¥ÌÅjdò'y~)Š×ŽæóÇ}|Ä«êiöËé1FømU�9û¹Ì5G¯F²Ž®ŠV±²³«¸zBßO>ªQ/}ÒNíHTXô»ŒØk[b¬YTÝ|úŽ!â
áÔ‹�+-ªQ^¡ =G´H? A^´“Ck”¥•è¼5¬b.®Qžó#8ÙÀéìü!Úésy¬×K‡¥ÆN²'ÓtºØZˆoÛ<@GOIá1k;jßeÊ;ŸöäÈïçhh:øã˜gV0±CžŠçÑçüçMA¸o_] $¹ÓÖ)‹Ÿ“òœÐ._×±ÖÛr3ð#KÄ°¨ªÝSÓö|ÙÚªkŠÔ${üë÷œ²/¿¡è=?(K˜ÐðŠ² ›©ÎlÜ=‰U7³øÚ‡>grFO;TÁŸ˜W”}=Šå¨ãd8=hߺ´XvD1� ý-oÉŒú78lŸ>_ž<ÍÇ¢
ƒ/å%ç�ú½¯/½žö.–•æÒà1ÓÀ&‰Õä �gŸ[Qÿ nuÒ{5£ÎŽ«—…˧|ÁdbÃåÖù)€* ¬6›²ŠØ¤NP(Ø"(U;¥˜é˜«%dË@¬{
- +µ¢•%üêò×Ø[;•²�/ðó5&¸Òÿ H«Áÿ Ò�æ¨ÀâðU�^M°‘Á-S5ó¥Ó>²‰s,LÍ™_¢…ÖÇϵÕÌ猉NѤÙì£Vv5Aig10Û%ÿ αˆ’ g’ŠÐn‡aZ]"°YÍêë
- +ÙlöPûK"éDºtŸ¨�*A|é‘t;¥C0Óz6¢Ôz«g!—^�wJ"9Üæ¿«¥‹ž|ÝKÒ§=¹÷u1[Ñ3¿ìª÷Σ·û“h"£®Z
sË4_ç †¡uŽˆ˜
-å¸Yvþ¨ùÜ$”V#üž¿Ðµcw£¦vx�·`é<[°ieó{ª.thláݤ_ãv“gšQ¬ôî’ÆyQU—ÒÍÔ–M_Eiâ)2Ùº$WGÆÍoÙÚ÷¹
- +jÑK‹Aì0ûB™
`øëš�>§Û"óAÐ�
- +�ÞœÉ[Ø ¼ßz}š~;cûöÁË{Mo ÉzWö2¸Df2ŒA¤µtÇ®†O¸¹”^ˇF÷µ~‹uiÈX,[Ï׺¼ýJ8Ûõ‡Gbß}ª›AôËOàùI¬èAá�œ³ÓêÞ.jÍInQkˆ70ׯO¡íT=¶¥¯ÐölÌò*\YÔôë¡ù7²yßbˆØk¬ÚÎèE’Ÿ]Þyª¾o½žŒ!÷þÚ,
h/ÿ ]LÌP¹z£aX,Z}·=©k¯ìNk¬éVÁ8FEû…ŠñKMb�vçÆA'µôÑSQ70ãöGÂ¥¢§ù3˜*¥{'G/òζ¢…«Üdüµ5vÌájò×O€UfßJµQ…é26DÔk$ÛDÈX–¦Ó†+cy¥p;ziÂãLd‹5E¯¨Š“«þÏ9�,¥%Ê ¡ä9˜e6ÊqðŽ©êª,}}V*jäXGO;—åPxm¥ÚâtÝŽ‹9{ZÚmNcaŽb‰œ®{·Ýˆ$¼MPºˆRôÀ‡(ç ˆ«¦P�ÁÄ–ßr.si>(‚E")�¦ÖGÚ£(«FQ̹jä&0Gôo{iìŸgŸÓé»[;Fß‘5�£øø÷ü�ùëó<Ç.n'Íž²—[BgXÜþz×71Éó†>þß)ÅÇÿ g…¸†6xA\tÖ™2&¹ÖûŠ�&·¡öØt¸)šd’/îù�»@|’OŒf
- +yt%Íe+åÇÚaŒ–“íWasY•·þ”EÞ}>Ç—&‚íb‹Í^¡R^Ý3$ð™zÛ¶_›m3g§ðó·^��—Ùfc~¾{ù©Àü3S3š1C2‘$ï#gý2†�âšÒÇ°xŒs|=âà¤lè±òì_åäÈ^5Âôr(ÉwQKUXTK{H}`´Ÿm¦\7%•MþÒ3v{e¸™ÄÑËN€ÖSW=žC�éÝ=qÚ)Ï.~ŸXUŸ±í÷_êü¥¡¬Q‘_�hþß1R_ïÜÂþ%V¢¯’³aS#ÿ }Çÿ �—q[8
- +ýjšz5_Í~Y¾³øäÜèt´ïªVl6w–Çü=øÊsžßü›~wYÛ+²L~q™ÍÉÍô®t$ø›¥&
X½©X³W™Ï›O›—‚.Ø^o¡ïòV%"� "°Ü5ÓÚÏÃ%ƒwŽf©¯�Çi,¨M»×pvª
2ëk4ÖvgÛ\¼ÑBã…‚Öét!+¹r\ö,+h™1=�㿵Âö%¿p:þͧˆ½FÉ®+‘Ù±mðýßBì
- +´½åafŠÛOÖùßý-s3d^È:-²�¦ªÝkrTurô»éÒaÕ¥ F¢j«k8‚dŠfÿ ŒÜl8 aØL-}V%y¹/XÌf‘H•o@±R²ãeñô¯Oÿ �‚!?a¼ÌÜß*T³{þàX®°.Ht+˜�5›¦h+}ªÊËF(Ãáq]µGp¨¤^I#½tXø¬bÖ ócÄ’¹˜2õ†…Ÿ[ø+QBc)Zb³JÚ”º.*qj\‘Wìùê°f—ýŦóá‰òðÆýPûKbr9+/øï‚Äó“ð;ƒªî£i¨ÍXƒjGKù”8®k4†²Âe½Üô•Ïí2¢ã¼Ôuý²€Ó?SüÚz’Óû²ZØ •9Ù7ÆŸâ¬
- +„ò¢¥|'ù¡«6gõçÿÄ F
"2#3BCð!1QRSabr$Aqs„4T‘¤ÁñDcdtƒ“”£±´ÄáÿÚ ?ùÆV±$–Xª|íbÖX×Õ9cÙoK�ŠÔéñHÖÆÛ++*Ù†[m•ª’I•TÓÇ��£b½UJµªÂv̘ðñQµjI$³b¤=ZÕÝ”Ôib’-£Q°Ë‘Z�kTµJãs&ìü¦�¶ç�˜fʬ$vâ4mJG2ÈÕbHÕ’Œ,6‹÷'»øl2äC%”üÄŠì²3%—#qm(Ø‘¶ðјòõ†eû2-Ž$Òy
b«Em¾ô³¶CV±‹‹btq,Ìrä~5V–5bLr!³q#Y|]±– ¼Qcò¬�жÞ,‘UF�¤cNµË}aYº%5‹#L¾¦ù¤9rîFeò–kÍ·“
ªY<!ê•ú§K7#۸ѫHV¯Uõ�<ŒÃ~#æ8š´ö-€ª¬ùðËê™XÜi=>è÷V›&ð�shÚIb8ËoHfUÉHdÜܱVR¶$måñd‰p!åâ®DklFŽÆÊ3Uˆt꫉7á$jÅ#1“mŒÊËá�Ýæ£bÒ_²ß°åÄеe©
- +µª3*‘íIÄ÷{zgº·F-áXqRMd²K´¾4m'Hç�jž“2µ˜÷ˆ¤\HÙ·HÕcÜ$�[QÝ÷|�µ‘î7È·L¬ZÍb9µ$™cÉ�V©¦jŒÎÍû‘j±TÅw²òñL~=‚ž_� Ñ«r ·%4nRሲ3q$ÖWÎôišIj{½r6\Š³F¬Õ$ÓÕ¬4’éÚË ½ao¹X·d7ª¾ ºå^B͸˜•i
¹U~Ä“PÑâÒjLZ2?Än2Å"©U]»xC2³X¯ìû»“ôˆcªU�Æâ±›’·2I<”ÜfÉ�?+fÄÜUä,ˆËs£NµÝ&ÒÕlu„xX»}"Éõ�Ë1V®Bê[Ä7¤®RvÃs²¹dtdÛEV=º•fËìJÿ Ññk~¡rìêö¬¤väÒqRi*ÃMeÈ’[`n7ÐCªY"¦á³+)§‡m£$«dÄš‹KS^«±oXq?«‘ff²–vÏlå‰í*»Q³µakYnVÌyj¥U±¼Íëv0¤-V°º…=ꤒ3
!íì�š6²�ê'f#Ö2Åá÷¦¢iÙ«¸4Þ„ô¥=ËK½)æ®àÄ+fV5‘½SrØ‘ªùIW,I*»e±²‘Tl·P’±â§š¤ym‹ýåk�¹dC3UEÒÖ+2«U{=‡ØG§f4ñí®^°Ì±®$�çÒéU“ìbþÔj½ßbMƒ/dy¹FŠ2ÕŽ<EZíÊc3dLÑ
�ØÅE$o1_.çùйmª™)ȇNÎC»”ÔLìÕìU°°ýsgÊ,m‘²r±6R÷#iZL½#¡ªÝéï
- +ØÄI,R¶™ŠÍk1_¸µ·o(ÜlÅkˆ¾›±Ç½8î:úÚ¢<V3óvulmÈÖHÑFçÙ§U¥�•e:¯úR6–64ñË!kÝË?¢I2É—ÂŽ"ó5*ÅRÖi;8ŠØÇṞd*³ÞQlÄ‹æl±¨Ùm¯Çó¡[Ãk‹xPê…\¤+e•M{kÖR+6#.XŠµb6Š¶R=Bƹx§æ<�tŽ=µ¿«ý’5m¹ç”’míºÆIÉ�¶V’%5KpIRF©Ç—dmæQ¸ÆŸÅfÅdÍñôžZ©ÄeUÛ=,|Q½O�¤ã,Š2ù…å‘£‘|Ʊ‘˜�‰'.‚9–<wšË‘Þ³wB´«-¥!šY£’¾)6ž]ÙY7…‘¬I2ÔVò�dÊ£s8‹ZØÜEÄVo1oªt–ô”VQ²â-[oø¢µi,te�¹ekȶ&�U·¥‘VBi7
:«c¶I§Q#�rŠ>è[<±«Éþ§ƒT±Ï�ì'Yõ¾´ªé¿D›ù®«ãï:ËKþGÖi Y5SoiMD›‘I´i¦Ñ²íj»’NŽ�%Öÿ ef\bŒÕHò5MÆV¨¹
nñEË—e�-X“§ÉÙo¼k,G©VîêGÞ
- +µ.GU²÷‹/„LµÇÒ7e©½±Œn5ÜÙ«V<˜þJõku\ú–i;©Î´ëí,+"ÁßJk$—]ª“U,›Är"Ë]ÃôZÙc¢U·‚MVÉd5
f•…ùZæ<�³FÝžZ‹““
‘_¸ö¹H¥·6a[�¿ø¢Ù¹õ�ê|šE&�Ýå£[wìHÙ™|Nè¬Jѱº.7ð£u†©[ksUµýô£PÎËY{ŸõQ¦~ñTU¤^2B×i�xUå&X�#
- +«[
‘ȯÜG Í�”UfåÙo¼è¬†iîIŠ¹b[ë
- +ßTê5IšEnäÕCh²“½ÿ Ê5‘c¿r$‹UdU“”gVª´²1׬Ž(»éö�d–QVÏbI6ÖÛ†£¬•–±
&%ª*³-˜l±? ÖcìÕK5…Uâ5‹7ÇøË#ÚtòU¸•À_R§âc£'PÍî+Gã‰b¾8³7-®è†e“ˆÓ-q#Õ6•d—þWý¤ÒÚ9}ê›QÅ1&ª%ïV]âmSI‹HU¤j½ŠÍZöqDZY•†QZ«RK©_Ú5~>?úL¢µXµxŠÙfâ+yXÑêK=”ÖY`¶žMý$ÅqÄfÛ–ÊG®•š5–1—ñ6¢(VOXšF‘r-V±#YˆÛlÊÖaW¿Tö„’5U-÷žZŒYXµFȪÖª®å½kññÿ a–Ì~/�¤²ù{“sãã¤VNì�U¨…j²�"È7/ê!ffZ¹4ÊØ–·)kb{;Žƒ%Ä^?xÕKb5”UõöYªVÅ•x˜ÆÕcËÝŒ«f?/Çõ†¯5,,Œ¸©¹åa›‰#[+a”n_qÒ[ë±ì8¶Cb¥WãüO`͈§!±-cËñôv7Ïì%éötéº :q™ô�/G°^‘xÈ7�»±°o�O�bFéö{ùý§GO°èééúO×/AÓÓœcr—ÇÜt|�ÞßggGÈÿÄ G
- + "#23ðB!ACQRq$1DSabr�‘Á4Tc±Ñáñdst¡¤ƒ„”´ÔÿÚ ?/<–ïn…–ÂwϯÖÉm²©ÝÝ(»XLiJr¹L1æʆ F;R—HÜÅuäòÄ»jJbbÅ)iñâd®p“m>ÑKqïE.!Œca2Þv&$ñuë‚» ÐãDÑÐQïZÌfÊÍp7ZÊe>°!jÚ2†¡N¾zeël·è–ä¶pöý‰¬–L¥hŒ¶
V*ªË‰½Ž¥js*%˜-[Ub5�)Ðj‡†*ÑVYP’ÜRÜÖÅ’±V1É%¶è+"S¢×‰‡¼°J eËŠ/s#ææ”éB¶¬—„ÍÔ(7Ý8†ÐóuÖÏß,´¶Þ=uñùeÖÿ ¿?$heQZ†A""Žô±–ðª¦.²©!hÌB,Øx-Œ^ ó#„’û‹•43
K•ŒÄ.\ÄÅëúù=Ó…«·}*†áUª”+Æ&%÷r²k—.´¿Î‚$\QcìÇSâdÏîÒYo÷*‹î«äo§x!(0Wib͉£Fž´BáügÙëðìâšØ„Ql¸„£ ü8¸Ð¨KŠ
Èr³{
- +—›SK‹
- +¡iG|ØUʨÝ6òŽÎvI·e*)û¹,áo�drâ¶ÙJ=ݬý´ªI!ʬÃxV)|˜Â®¶aÀ«Ò¡¼üŽVU5Å�’”JSÓ©…lBc¯Ú·÷~�Çë÷M–ðyü½uûû-¸{5Ðî”Ò•†/�—Ê¥ñ/²·/y�ðœX°VlÌØšT«·Í‰¨J]F»ÒÊ…‹•„0i^²Ì¹P¼1YbJ†4‰vźê]ïïü¾>¾ˆÂÆᘄ‘b‡ÓAŠÈ+¸e¹mô°“›4MY†!)hÆŒkÞ!™ÈôY÷û¶iüö}Ûfž°,¾ŸÕï÷u·Í>´ÖÌÃPJ)Þ8‚+ÝG\?¤Â§±"õ~!báî¡,AWNð\K†sDÔ„]`—tV
¥*5;V7)˜Ø1Ô$*ÝÌ2"¶«ña§óW½‚B¾%Æ
²žŒ\W]8¬n…l!Í×^ùw³JØ]¥5ÂùlŽ¨ù¥A§+Ù0P¾TR…Û²„Ÿ
- +¥PøfñNîF9cÑÉè °‰¶ân¢ê-+f§`Žèa$Œ$Œñu댧S¸—*¸sG6ðÛ..´A³Î#°fQ„CÅ>§Çü¿9wÓ§i–LTpˆåRçZqtZ+F&žÜЩիÉ$ÂÄå/›Í•UÂËY‰{¥D¤Dqf©&ãåÜ«åQv—ÊYcŠÕ2Ø"š¶ådËÅ×õ…š_DH¡
дۈsëB,·M>ÈÌÝlì(åÜ-Êr"´—;Ÿ]h‰HˆÛ˜K¶[tr„†Ò•H§Ž£UÜÉON�S\_OU¹W_ø°I®îØKÁ¤ëôZ_Ö
¢¨?”ª"·,!k°Ô[•KÕM±|7EæÍΉJhXÛtn‹³NPÏÛ§‡¯Tª¨U8ÜP«�Ë)ÖÒ›8fÙÅ.´£2¹Ø¥—ÐŬœÛš¿ô´±"+ÌÝõ_ÉieUa]óÍÿ ‹Mÿ ÕþªR�AUSw�ü^a—G³Ì¬&ÁeÃÒË.æØÝ)ïg¶ØYJ}™õúüa]nnºóvi•UƒN7ª¬ï�ÍÊ”t¢#wc
- +Ù‰î˜�u¦0‡L¨&ŽQæËLK
l¡¥,/•º3x,%A§%’È¢êO¦(²´rÁö¡Ç
ÅlÊ$±šfÈšqæ”Xæ—v\§>kîŒÍü:õ~z~��²Í|å]…éfJœW"ømì9ˆBPK4q4¬p¬r®T8·ˆ¥ï[ïÒ¿ZªªƒJ)mß7þ,ÅšâiGNEU mO^¹Åp•ÅD›’0¼1kå”;ͦ™Ã›²ït,¡6³[;ì)ªVKVh²´n˜—pBÖ“'w(ÂŒÞ)–Âgxm¥¹WëQnnòŽ‰|ï•A¥U›s7±l%·
- +/EolÕ¤ÖV\ßMn™K±ÃpÚPG{`ÌØ}¿[¯_`–{
- +£ëÕ6˽¨$<0¸Yl®§nó
- +Q-ºÜ8ˆ'(¯wn+à�¥•‘‹Ê1bJ´c–¤µbÖ|&©XKR‚¤J„Ü,!‰¥+®(î+æ£Y0ŠháëÕ4K³Z0—tòØ9 ˆñBƒæ–Ý4ÓÍØSXQâU\K‰M¼1ÄK,Õ1uP�KÂLÞË”µ0ÂktT¤ÊR_:jíqAU«t5ìøZ~?ãù}ÒŽÝeJÇ•5./zø4£§Á~õ“XR׎þƒZÙƒ…U«iQþ+½KQâf;f©N˜ßž‚#l,£–hŒ¼x{-ú%°xoáÍ×ò–û»OÒuç…äK®á„3^R“¶£›-/óa-¸!dï·3* Ýu¸½d×7kêåk%Q(U½L£ÕdD¼]ÌI
�^¨¸•—ÓF:°JÜ]ÔJjª
- +Ñ^4ZÚ9Ir�d´,
- +ŒŠ ›Å2°gÇ-ÑÍ,á›g»FŸ÷ÑøiÙ¦eÒáõÿ ¿òìÛŽkL¸e¼LÃʃ¤p¹xÒáIfæÎðNqpq¡jöÛwÁSÿ uŒIX£ÝqSò¯‚ÅÚ¢Üo¿ÅL¤+&ócû8ÁAz9«èê…¸ªÜª:�®ád^X+â2; ‰/ÒcNwºî#á(D=‚7/j]Ë—f믢3†éÅ}©®†+!ßJv
Ùy?ú±ÄIkwГޢémö¦kfÑh²gVÔêê—¿r¯’ÊQkHyP‹-²œEÅ…‡)u5[Z¸)öå·"ð†
Â,)ãûàå7Ž!!¸rÍ°m)m°†[./—]…oû]zæº[K…œ™N³Çº:„\_µ•%O˜·Ê‚›‹{ÊŒ¥UsÖ¢å|ªk*Œew*]Å"e
ECX*ô2ŸU½ÅkW‚©GB„æïeÖŽi·°–7,ŠZ=YmÝ„"CD0†ìñeâ—{ûV^ÔËš[ï„0Š}a•I¢ÙKi>ÒÜÕ¦b]‰z÷°WŒ¬&¯Ÿ©T"ÂS!$„ZRŽ…µ¼V`Ê:USµ˜PV$6”¶1b̧>Ì"—{ûRãaÚPFRŸÃ!–Ü0FуÅ-Ï
- +îºýðnõf‘Í-ñM‡×õŒ§S3ææœ8b0áP�•Ø{™OK†L/K-?·Šm–ç¿°¯¿½ž.½PG,´G†
¥ó‚ElÎYö&»%Ý–�°†ØB"3?ý)âë×n„» Œ¶è±·1K˜ƒÃØRÛ¡e‚WÓÃsB/f×AÓL·²ÑÝ:vM»¯¢/dfˆP´M�²i^�‚4èòÀ9£4Ú:KGdzNŸÂ,ÈÏ6�±c¢è:;<=z£4fš|“Å׫°²6@ò†ØSÅ׫³L)çÛ4OÿÄ O "#3!2BC1RSbc$Ars4‚ƒ“DQa’³Tq¢£²ÂÓdt�‘±Ãâðó%5ÁÒòÿÚ ?Ćb7DF•ŽæLÆó�f™D|Ù)$
æ>1¿ßðê( Æ™L:W˜qîæð�ðàKÈÏKQGS¼êÅ¢šR„‚+š?âsuO³œ™M`FŠ“¾\ÌüY}ίSði6IW(‡~óÞuv Yã]„Æè³:�쮸'´ÙÚš!äôÿ ¿èétJÏlMba+tTTó…ª#‡…mbئñâår´;6ª÷
- +QK¹þ¬^ 6â+88ÛêeËõt�£²œX+N2&ø$�,̽–ó}&ðhYeôÕ
¨2Äúz‘½Eo¿}¼ÌžNJ½-lÍ¥Urêãh»*ǵ*M5l¥Ç‘`dV?¯Ío5Jؤ™†®êG,'Ÿ
°I]J~X³57ò´šIìaÏÙà5vw*J˜0Tö•Ó=tÚjúM±'/]‚Œf´�)¸n푇c*€ÆÃ÷TdÉ•M?K¤«�a�sªÈ™€qS«ø~–>«yºªE0‹]U… hH»1Ôûæ´]‰},§Î䱪ҒV_TÂlÍÓ,Fæ¨[bÙ‚œé¾_U_&»5(fT0ò²/Î<ã+•û9ä2&*Ÿ&ÙÎnmv*cT”®TF
¸mª§ñösQ2Ÿ:š—-KÖ¨K«*‹yE“+J³T�ØòkΓ~//P)1¨9ÉD—|¼@xGð,-Å¡tÏŠ)ãzŽi‹(JuYÇá*ŒŒÿ #?‰«ß \(v‰S®ÝÆàyÚ-¼9<e“³äæúÍø¡˜ÖØ””Žâ)ˆÃyŠ®1¸õ��Bs¹RÙÝT´ HiÃλ²+'ü]&YuMDÉKªê&ù›ü£ò/‹ó[Í×k™5Ú1=Ö€øm÷4Îß&´¶–¢Cæ+-û?î_¬Â²˜‰ßã»Åª`/Ú›’_6ï€òë·©¢$°€�ñ,Ή£ø.gåéÕáR°©§š‰:@‹7 f%N>p²æ5>—¸Vªèm¢akp—çè2ÝMYM%Zb‘¼Gâ²Þ¢ý[5 QZ“ 5ZA/%x|~®V3JÚITŠUP™ÚHÇNe„‹ð.í% ª|ôpìªió¡¯4~ušº‹õ}Ujj“¦�%“PËÞš€@;M^p²Ü«ÄÜV°Õµ›5“ÀqXשl>Z§DøzzìGSKLÑš�Eç5¼;/ dp0ý?KÒn«(kdÑ´j lBØ<«€\ï²Lö£7Oà³TDÖèÙUcNð ˜rJÂn^˜øªÖÔ7Höz½œAS¸2 …¼]@<öóÒ°þ´ê’’}cC¿¾ç2öþå÷búZK©…°š}œ¤¸72Ðáåùñ1¬ô¯Òª‰'L��Æ&k#oTE'Á“(±Y1r¿êÍÕ]D
:€aŽÙÝ¡·ÔM:[Ù›Ê cª¢�Wƒ�Î^]!+$¦¢º3 R6Jä
- +Æ“ZgŒÈ¥óq|,ËÕ=d©åµ”ÊXR^/:œÂ ËNÐ袞ªœj�ü›UÌÕS1TÊ
- +–Ò(‚6(íCG™ÔÅÚ9|ÖÞöú™t‚¤Î§7[¾]Àd_!ú�Zý.V�„f°OêùáœJ£ªÓM%žùÓ›r+êÔ‡ÃÒ£´ŠÐHYÂSãcŒ¸²‡Põ>ž€Ø±3[„ndwE�+Hÿ Êu“ ‚>ÐPG¸ŒŽáW¾lâãü
- +Ò‚Ø&˜.à‰Þ`&7⟈VÖ|P= ‘Í�D ŸôtÈ@�2oÞ@VA]¬$#lˆî‚÷ŠýI¹Éí•”7HÆáx<ÄÕr6€ÕÒ±ñI0ó†
- +Zià³–Nw/íWåbÕCR袨U]³ßŸ€R&ⵦ°?£ªŸóuOFä&Š¥|SR@ÈÈ6€ÛÌãg3–9sÊNóÚ�@Kß>P/#Ý)OXª¹2–ü{K„HO—¨ß«ùšÚtÕ#U@ s1íq�x½Í&˜»]D¡BѲž~Ô ÑkC#ûZù¸¾ª¥öj>S`„^“CQR°¿…·Ÿ;ú‹åb5æj�©-µ@ª‘6¥*íw{Ö¹X"ήJìJøº©Út2ƒ§«¤Ú5$ª{ný©BxéÌÖÅ1uÕYZ’–Ý'aS¶‘¤”¬‚*Œj«Þ>:v·h.Š†œ´*9jR¼²öfµµôiMIÓT Ô]ªó§kÄLf;IjcÍU˜[‡¤ÅÅ�rÀ§0jŒêDìâÈÙÛöe5^³U꜕¡íí¨ºÐËâËgKº˜Õù^“héÆ»)ª
- +"Š¢¥Õ=&ÓæìÕ/°rcæüW*—7d&¤Xt§Xš�]DªNjœªœ¨*ÛFŸ·²äíMjœjN.ÚÖé§SP;6º¢‰Û:¼6Š›BÚÊÌWÝOOÙv–dYËV5)JìƤÒvÎmu}5hÊ›N«Mz9æØMmŸMPgâZ™“²Òÿ 7[ÔÁrj–ä¢�öò5uk[ûbi|X¹ªnS6ª¯-%½’"í’5Š¨••DÍ=ß²Ò
VÓ¸þb«ÆµªÏV•aÊÕ:pŠR5¬›Þ8X<BÞ<†û.ËO“ü6én¤rùn#LÖ ‚è+ëÖŠ€Øê`U�E"ê‰\Õ;+h#!*¦–åÒd£³Á%],½GUgQ/%?jU-(bþ�ªÉ5�Ä8¡¤BÙ„ÙæµÀº‡yzkS~–nŒx–Ô‚Dd*¬€rÝP«N�X|J–·˜U›.Œ6vwVH¦b”@²šmå(¸ØÀã/雋Kínœ›‡•³å¦øÿ ¬4Ãå³V¸
ì´yÕ²Úƒ–|ÅÌ°ô'L—NŒÏ&ÏYâºÿ ú˜õE±©e4rÊÊYË$©£´üO""îþ”ÊZ�©&Õþª¹d/ËTc˜»9YÁJΧ1~�«�Nl‡R©Hgp-i¥ kÚ>C¨1ɪqÚ@ÐYBþ׼Õh‰{á`äÇóè à*inà©_Ueoþ>jþ.·Ë’*ý§o�ÿ |gñ40€ÅÌj¡ª'„øío {çÍÐí€U=Qºœj¨ÚR3Ú} r¥ëÍÆ=:Žo¥•º:”ìÙ tÚRH’42ÃÑD`¾bbùX�Õs2è£hì“1µÕ4‰|!‹òŠ@~@ý!koæ¯Gƒcצ]Æo 6¾²KÈBÛ×P�âê3µ~R´aIú7·›/æŠê*šÇÇÕ¦Gkæpe§§©V.–Ucj´eWII±×´VH$*~Ôk1¿ˆ¹Œ¿„XÖT1_”ÝTJ�î½�ʪ,Ä*WPÑœi×ÌË—â«–…$kG-ˆ,°‚p¥ÍÊß"v6¯'Hy9]Ôýj�·v� À¶ü¦’¦Q€ŽSûEë)læñò[ªÂà‰ }>$NO”ÒOf[¸lÉŽ—Lþ«u^›ñv�cΤpTm6R˜ØÞUiÖ®ÿ MLê©^“Rµ7TÛ@©×)X8*Í’ÖÖ\Ÿk³ÎÃÑËg+ÑR±ê™�؉ÔÇ•mV9–R˜Ÿ!U9*fšÙöU‡+³v�/gd¼¢œ‘K'_Yú¹iÄj¨ë°ùCËbòòqbÍ—)@®Ÿ³µØRkÎhÐB è…ýVTeªmüæúZXm:ªsu}ACª*ž÷ðòC�jòdo+')\Ü©0ŠÂìt´ô´•.‘³“ûCU˜Ö¿äÏÙ»SZf×7˜D4\¨4¹á*q®>i
œ“úy—âë*ªö�8¢ž±«'•5(,8úŠKülø�U+›ª8]2×l±Õ{�'yYh�ž;:\̸µ5ŒËYZ¡Ü>÷Ä¿øzQ•JR'¹�1qÚ#g�ÃÔǪ…Q6ñ¼„˜”Ӧ ¸¬8W“çúše Ó˜VE%Fz¦þuÆj W¢ÛÁÕÕÑ
- +äVv4»n¥vS§UJ…D£?Úª …˜ßÕ+¶õ+Tº ¥†$DYÉiüätèhâü zä[YNmà¦2Ë+]Ü$WøFt²tÛ‰’HlŒÅÀ<_¿~\_¹ ÂV“.¹Q7…Þï÷?ÛÕ%[ŒÂ`šw'ýÌ—cѧ³¤Ó)¸R^(Y‘Ü«L³qeü-�}¤ fµ˜¦šÎÙÌ0°�¹ÔÕû&¾§wc¬&´þRRr3øŒÊ ÔQÓ,Öã5ƒU) T‡ær¸5;9ù‡©¡ñðÔŒïšýý ®–¢B¥«™ÞÒïH˜oàù|µé.®œ5´c†;ÁhÖ\ÖôúhÊ¿ñ–*ª›•JªH5·Keu"ìD]?;T¼ zËnš—2J¬8„ÍóL˾Îßœéú™>áÒjJ©U]9M‰uBJËnôM†B¿¥ÚC›éhë6D�V$YQNÛ”Ú2ó*¡_RÜ|ΓoWômmjÓHQW\ü°"‡¡™Nåü³ñþªº-Ò“S
- +�ªÚI=ž�.rM'IkLØ´›TôêìëÊ¥«•é*:À]+œ.¨`oŽ*˨2 üj^ªšlÊ®fŸÚ;&v=S×Po¥jù\¬U}3ãôñónüEfÑOhìp³¤T€¶$±XD®�˜Àš¾búF|ßWS%%†fœUO‰G N–ªî�œ¥ÕïÕh¦4�?(Ô&7Õuøz�æåê\ÚÅšê-‚U-ªnàj§ü6r²é8Ø]Ò%Ed°m¯åÞÀµ|ί·»ríº&Tñæ
ÞÇü )©ˆ¦J¿w‚â"?=š§ý4)ų…$.T�JÖxk õ
Hcwh´jºŽ’ŒÛÍK~�m®–EYLå
- +f´í
- +Œ¢ZïeÝ5ú§ÒÓMEML
- +£TÒ8ŠMìr�µ½B`ËÑz±µ~—ñ¡©¬\Vö‰ÏJ·H·1Tˆ\ò >O!CùJX¾^Â÷•õRŠU‘x¹?áþ
~Ð$à1šp$øüFOiÏo=ýè˜(2bã|]qÜÒù<+S4¤"Mu‰>¤H/Çrª,gúÌZSjjGzÊã¦c›Jùð
�Rº�`]û;y¿K¥¬4»5U�â§D�6GŒ8„ò‰‹ƒ@(ýÚËiÖ¤®òå°ñ‡‡Ógòµgd²
¥¸jMS3gÉ>0õ1ó|ÿ K\(U*%ePp¨|ú'oĸ˜¥ò¼x¾.¢¥©9‚´f,˜Yñ� ãóý=U–È(‰
dÛç>f!§æ/¤y~.��ðS~â’�…€¤x†Åùÿ •ð•“N’Ld¶ð™�¸
- +ËJÌ™�læÙª—%ez•Q¹ŠBŽ©îàµT”ày)‘OÅPÚ†sZÐÄœ¹;*Ž¼RÊv0*éÎÖþ°§2û]m:r,Á‡Š¡Y9ªÌjÊÜjÄ 3\Ü#JáËOƒB€ùÁg-µf^¹}%K¨hB¥íi*´ù-WgÌ3°Ô<űªÊžsp±]«ô“iU,‰Õ•®z[Ð8æý�”N6^æ-§WùR€;cTìUJO,Ù–-¨©B·TK¯mÖ¬Ï#VÆ7øºu*ÜÊ.ÓNå*n‚ÇZVrÀê•Š[;.V‚žw+TµêªU©k¦0™p%Å~*…81Õ!|¥©x»W·Â\%î˜$Þk6–ëL¬ÏPË1ÿ ÒUŠýOfZ¶…NY]g(æñ°n¨X̺Œ].^>’tCN†0J™%�ë+‚á¨+;9£„¹”üÞ>vÏ¥w)¢÷X‘T°‡tԽ‡éò¼LD² Œ˜1|Ü^oÁïÒ#llöÜ…¥¡QPtÌ«¡¦rŠÓ �«')]§òõIÛ.¥Ú
c«ÀsÎà5“²1&°SW�|¬¶aÕ=”ͤÙô‡TázDZö ”/8p9Œêéõ4µF§6 F‰"DL“\‚÷Á–“9~ùæÓRÊŠrršÇpˆÉ¼¼rùÃËK†äžénþèáðÿ åê
ªE(èÝ>�—ÎËzšS�'†«‚GÀòßä
;hm=¡Q�†6Ó2¨Z¨¯·¨Ïê7ëi”;€BÛ�»ÚjÜ~%¯ù�-3·¸2œÐ4`$Sg‹ÆÌ>.‚�"dîÎ25o�ò_³Tþb*Õü½X¥Áö¡¡U»·Ì&�É»ñدýäÕ:¼Ô@.MY.=Œ´øD¾™Ž«®#³mµÃƒ2Zi¸<Ó'«~],™l÷'tqÌØ w‡GfáÅ¿ºÌ\Eý=΢#6„ªf{ÍŽ ÊG~KòzY9\ Þn<ZÆÖ!pÀBƒ
Çp“~¡�¦µåàêc°œÆ¶´ÄŠ– R@á@´9‰BíæÔur�ÓÑU.?k’ª§‚ïE5?'ž||ìfCN¬œ¦ÕzMJÛ¦T̨ÍÓk˜ÂÍy \¡õ�œ,åâR¿‡Êêäz£){ ¢i{üB¼kÿ [£äqDn´${Ø~êyÿ ÛÑ2˜\¥TÇ3ÚJCëÄm3ãÆ|Ìk_𰱪ХéwiäšîÅ"cÒ·©gÂøWèˆéÅ�L‘…³)†hS\ÒòqÔ)y=.W/Aɱ ,t©xD”>ÿ åêõ¨Œ6Èîg˜Uûžž«Ýt+õeh”�°d¼éM£ù`Y?pêi{oiißSµ�XMtec*[³]€E Æ-;È©û;èÒ|6ꎂŸ²0¨(“Vu´v€Æg™ÚÛ9†k·šÆ+” Äí*€i©ÌÙMæ¹(
- +¥óªm¨mžZYz^
6¦vhÓd}?g2‰¦§;ÎÑQó ]O„
- +�ÖwŒ;ÖvxGßÕƒN ݦYÇkÙÓiŒ›’$Vô˜Aˆ¾™Ž�µÆE¸˜V*Hýæù4ªª�¤é
- +–ç
›•¯ ââ·ƒ%Ÿ—éuµ¸áê"€-Åaá°È~îøšˆDŒTADEÁŒÇŠßÌ»@€§ß
- +¡‚;÷ Žf‘~úƒQ9"ÍìNðû–/ß¿XÁ+´d¢ †è›üWÄÕqÓR0ö~R*wÂ
- +eʹ®Î5
:™QÊì
å'›¢EŒ,$â‚%@_…*, ö_Çk?|>&�’cM27>�¾ñ
- +†ÀÆ>M~³«§¨šra5"Ñ)ÎAÒk};8ºÉS]¢7A0[¥b-2ÅeÃÁ釧ÍR¹�õ)U£ £-�CVµTmŠ¦ÒÒ•Ö`à5³hmV-Kg+�¤¬jSCcѤ{-eQKšl¦Q€öŠ�"<_ý?¥Á™Üæ5J†²™i¦¨Y4Â¥Ø× «�ï]¢ÎÏO—Çñ²âª¨k�ÃTæ®ÌÁ:öôˆ�™bíøtW£¬ÕXé©ë›Q)
Í’¦¥>ÈM¨æV)ëª9¬Ç•½˜ðôôêdËûÛPT·Ê ×Í0SêÚ|Ã5ò©ñãæ·ýjêŽc* ¥P 1 6˜\ߟáh{±6V!Ä凕£fO3©ÕÊÔ…;%�:•Y/à»ÀŽÎ|zž}S$Œ²àsq�«ð‰øóú�_¥ÒÐÊïšÇ½‘#ÀŠP¶ïŒuwåX½l��²ª«ëjN©ÙíkègfT%Êìù²S¹EÚéÖÆóhÍN«õu_Lš‚V×ÚU¦P”S›.�UYû?Ôo¥ñ´ÍžU˦eEΪ¾¬eS„{6%ìçØÒ寕ñ´ÚãÚLjh:Œ†E\Ê4´ÆžºÓ GùÀ¯OKe.FƒÈ¡BÙã1?6Î_�F’)Š‰nöDz1Ÿ„„½ÍCfq‘Ü£Ž§´Ï-Þþ�ARg¨ï()ÞAáÒIÐJ�OVQÄx†¢Ÿ`ËzŸ�ê«W°[iU-öLï0K¼#ø<Ÿ V|Z Ý2ÍÃó{¿ƒM8á3.ã˜ûƒÂVßéñ~n¢cƒw²&îû?þKûç«{íßß3í‘Óèß™É;†Ou¾KÖΘ+ƒùšßJœFD†½¦‘¸Ì„s0ƒºtø¹·µ==ÔœTFì½�ÐÓPˆšÈéôÚ¦·Òo5ºÌo0luPÅyòi„Ò<<»8í§mb×J¦´Þ›ÎË_Juuà•pÞÓsWFbf4¢×5:]XÍc)›T¥áÊîÕUKO²¨;6Ì(s•H•“èP²q}£±lð
Q¶¶�@:½©Ùªª©Tx�´(2UUU #g”Ê÷•HÕBR!žêí¥gÕÉ]^®<©ì½%f©"xn€)¬xð™ð÷bÈÆ·ºKR”çÓ‚ÎoLÂÃÞ1>!§�Óô´´›¶ˆ¡cv
- +Õ
ƒœ«ê¥Ø³¥¼‹íêõ\¥äj”ldŽJi¨ˆ�œÅ„aÂÐÇÔ´X¬kú¿WR–î˜ï"ºT^‡ü®f]
- +ê’I‚-éZÛžaŠÅÙæg3›ª—BVÅœˆÉAŠŽHî·Ó4/‡êå¿I92°§ÅÞR/P?/O{¦&•bªT�Òü 7›Gä¾í;öm¥Hº&º’£Ú†Êj|¶xéois2slÅéé;IÕƒ´ªj¤Zt�NTê>U‚Ñôüü¥ü¡ëijX8œÉÙé¯Dps
‡XjWð)˘ÍUÓS¦FZ£ìåÌ >}Êsi/«‰¶eøZ$Àæ$n·¼#7¤?¹ÕÓœmˆ l.g¼ÇåÓ/q\3ræ#¾Dá»ÜX= ÜåÜSa}üVyôåÓ šì¤2‹g�Ó»Îô™ÍÒ„�jââ(û‡ƒ^ñûÅß:ÿ ³tF�Ó÷Ïùö–݉‚$¼æg€/ðè#![€‹ÍÖ{£îk+ÔÄ-pRÝþÞ23%¿ÆMÄÏWƒáé ðÜ&"0¡"Uéóx<áÐÂiË9»z‚•*Ëjlâò,1‚…jc9JWEMȬUãkPLËVº‡gÔ�ÅI›'m®¼lnШˋ«Íé*¿mïlUÓÓ¶µÅÚ^ÁñT;™‚œ±SÓôµ³ë[=¦ñe>ÏAÎpMÖ&˜Z!ÓÀÇ·>—;ùEšBÈÅ#Q/Ä’·‡…'ã_Qmñég%eAH3qFò2‡Èzy×C+¡RàªÍ7¶lPbâ>e÷Ž?‹ãøzc³IBfNÑ“´ Uòc—àЄӆ!+÷o9³Þýþfª©Ð„¹»B–¢�qÅ°¬éYà>Ú=+4–ÈCØ-\•(– Ço†àðdÿ U©É¿¶^kJ,£¥O¤¡.£žÎ&h"'*Ø‘�Ó~]m¡WÛ)k*áŠ5"»
- +J⬢ALFKËgU·æSrr¡³³QR�™KKOKybl8Æò"PxþÒ¿Ut� i*'iRÀÑT$�ì*‘ìd%Pî`v~Ö]O�£ ’¾j–DÕT^„ßKLm�l€#Ìæøâis!'N&D1÷0CÍóðh
[»�{¦{£(îÿ w[åk+aœd[¼cïÿ îý§/~ñ™.ù/ÊÒ™
o¶]iEä)þ×Ý«§tD{g~í(ÈQi G¶|ÿ îãýý:¦ Bšr´ÊLb.>;néßyt×—Áõ5ZépSläÜB]ªÃá¸ê¾D.ÜjåôƒT{F®ŒÞÒkƒblú+N£i9$�'“\}ž™Cj*YPÅÒÐR¸êÜÜ4ÍĬŠ“gæ«°PTMC“L?ýÆG�‰EEe%9½”èå)ÕR¯H*ÑÍ´êDyŒ>
- +ð=‡wÙÙÍW¬¬Ëj•Ù6{ÛJæ[Ú*•sj �ÒQ®Ã!_lý‚—ƒíjv,GE^ëJIH@ddvª �:Qļ�o�©kS¡AØï[
uH3³¤L¬Z¾_ÓcUˆšÝl„Ôƒ(û
:DJؼœ v_‡g±L_+�.‰-ÞÄPfb[—ópdóê¡]¥€¬pmqr¤L¸Dˆüÿ £•§šþÐk–˜Nè’IYuÁäáÉýý&�@IδŒà`.ÔÒ+ý@,|¾“Rjë-ºag¨· CÞkð ƒ#1,Y1eôu8Æ.îÜ;æü:HE9Éå(!!�!+jïã|Y~˜uKGNy_שàƒòÚ]CÐC‚níÍŽÿ ¤©$ËcÐm—!Ô�hàvkªÃ'ÙÌšµdÊߪÖê£hÐáNΧ\ãÙðªdäM†¡¤³¸þÞ¶í{ê\Êêz½ž
- +¦”µ¹„Ä—´tó¬ÊöäêÙõ9N‚¶jÆÆ© 嚯¨J{,J3�3ÒĤâO'•¬g¸€`¤ÜYÿ ¿¥…4îfá-ýì³Åþ–»5ûœrE;Çx·Æø�âSr¢}ï c>?§«#¾ØÝ3¼n›=Šßí!-ßÞÓUq n\Ä�Ê_ñ1i¥7H -bR;±‰øZÒòø™és}^–“°i¯ì”ÕUdÅ™q°ï6¼Ë™gr–¾o|F©HvάvyÂ$µŠŒ ä6ð÷2³#9ªø¸u²AÉENÞ©QÒÒn5,ScˆJ’—³f¥Î#YVŒ™jššÚ�M@¥3o~”ÖÓRíê÷UJ—2ªç®�$aÙmÏØÒö«>U5¦
¬íõ�—õYmJŠ£Øû"4”®Ù^à=«+¹w°”¼mj•cyNÒtˆ>ùdFã©><¤Ñ]Br-µ‹[køò¥´[tê�ꦤJI£P4…ü�CUcòÙêcêÞ×v§iûAµ-blJdT4ÇŒ?¥\úšƒòâe=5+~®€ëf¡cJS%¾`ÿ ?0òzŸ&† Üa�Â=ü>eú<ÏáhIå>G2-Vñò—ó±üFt¸ôüÒ
- +¦‘Z1*iãI®+Á‹½™[—"¹WâæãÕ*¨²5§ŽHfî�—¦ºlœß³ÑT´ªèè» »t»yI°�å3bÃøkWÖË >à…Û
- +hÉK^À.§WþgKÇùZk”£E7AÌ} ˜~Sy�øzƒS¡„f-Q$²€ÀxD›gßðùZíeP2Àþ¶[ÄCªm™F;6v�VШªA€¡¦ÇUåkzfwÓ•:²tš§æÒ†Ö™¯hÒÕ4)^/”¥$i¨B‡¦`Ãåþþ¶…= $SÕHÔ[î >+ŒÙ”V¥üøµ´@ù‚\B7všª“!´<–ý/åè©�…‰�Ûþó/qÄHÀÎýþÍÑ#påƒ?Nÿ ›êzº»‹ˆFfxe@>[}ýKOˆKÅo~ï›ðj¤�m§^¸ÊÀ•€ßß]ž²š±´ÐâÀÕ©¡½`>" ÆËÙ¤QÓSÕÖS:¶œe, E„ ûCO&l†Ñ[r-¼«3ruÚ7Ý_ i˜3tBNÀüx—æ´Ï«“[Xvs³ÉÙN±ˆÅ,¨M†XˆüaÂ+ÉøõWCú=F¥ô»(aÕ�$uT´çgkU!uöAsö¬½v-lßÒÏÒݨM¬¤ þ§9TžàR•H`¾ÍŒÅ¼¼x”ÞŽ%bV¶ivX£ÙT"²£¡3²¿Uü~3`|=RdrSNó\EAÈ´Íw$®3ãE�êuy'£Ø; ª^…@ª¿j, Të`^d"^ã:ŸKýn¶?èÞ˨I
eH™6RÃS>0õ5²©é\NmA˜ÉsÒä� Ü^@gÅÿ åèU;·(X_}Îmä%ó¬î^O“WîBØÄð‡þ½<,[¢ž0\»/>Êçú¿ƒE6+gˆ„®Ll©qˆsmg�+ô±éÕ5J¦§Úɹ²d~àߧ=zé컺ŸeRÛeÖ‡,ßg¦½9ËOi£À“¨�Á6WNöu?@MX$6E¾ö®’›§û{µKúBÑýaµ[J€|nÉGRTÛHEVCEõü^W+›¯ÒG:�¬"CVBŠ®îZ![� ò—“/ëhW¿´_]±�” ��¡R¦âês._¹ªs§§«Ulú7›I\ÓåkÊ!ÑFv’Õ“àêjI .ËÄ2ÕDcòþþ©ÔÈä�Ä©Þ£¼@½Ûøÿ ôhœXǾؙ ÊÌ<}>_ú¯P ÀÇpŽòhâk‹ÌÜ^@ÕFЫySR •,ÞV@ø:@¿'ƒ–¶7óriÿ «¦¹¢òY%àÁI�Ó�s0TZš±^mådŤ_²Âžf”L š2 Ï2î±lñý5j¡x—5”–à,GÄMÆϤÆtšµúŸôª¹»6²�E³ëÚÙ*Z62˜€²§ÁÎWMŸ\Ën±ìº´2�ô»…”ÍÂ'À-igã;9xýVž'rXÝK?F;üäh,cj0‘$¹Râ¸\ügT¾.c9Y@ÚîÊ•©Úµ•Œ
- +ý¡TâXe »ï>%z<cÓÈÜM¿H‰uA’. Ä¢8uE¾/M†ø™1+ELÃ*€‚LÒR®”šã.kH¬[ ×Ôêò¯Äï‹®ÌU'7‘Õ«s÷<É-i5I{œ–ãÆÌJðakSÊÑvI¥Q9¬I:¥£N¨o·´N?%ú·‡ÄÓәļ¶ˆ–êdÝ`¼‹êqS©~ÿ ¯Ü\É»Ûw—›VÞÓ¨™Ý!ÃŽ."Êá¯U«mFðãƒhîIØÒùgÁÒø\8*Q«qÚ.†Æø¸ ¦üæ°åþùêT+¢§Q“
•¡Xÿ ëv;é÷åœ=êuãÄF^}1@„¨.Rwþf–»5?9“׫tnÜ?
- +ŸäÕì(˜Þ1¤Ùµ)«e›f«-rœ_c]¬S¨
‹Oh0V&/ìÝ.f¨i(Ðᣨ¤MU*ï&½lñµcìézÀI�^<¸ƒT�‰…Ó²U%|K^*Ž§J�KébH}]S9ÓÁ]²v|Ø&ØS)jFõ ¯øx‰môšÐ=5Óà3²Õ�ÅŒ>>—PÃêjlµÂÀ[£ðñãg3G_Z†Çe§!DÕq“®!+øÍw—¥çäëîíçÞgîÛÇÀ¦#LUGhJJ�µ\¢ƒ:wuÊSM}.®•3N{9
§©£¶¢À[ûUNpäÈÌãØúº:m±´iëj$…äDb¦‚òÞ«¸òYð›gK[Nª’œ!¥@ãŒIk°£‡ÇŽðôþåj‹o©¶¢›U]GµèÕlBj�õ=[ù—¬ÉLÇQÕ wkõªí›±Ûµiÿ E_P;8h–™ìW,‹:×Jú~&)•ªÅè«—¨¥VÜÛ{FŠP%*Ú5jhAæËh%ËgS"Ö®o7+SÊÑ06�µ?lÅ·‘S�ˆ6ÏWQC´]N`ú+”Ûƒ�Cˆ‹?åÿ Y(6†ÞÚ��ˆ£¦Øµ�–~+šœü_•%¸r«EnÍ©Ø›0¹¯nÚhªªDÄJ¤¢æ@ý²¹¾ V,<ØÊÌ�“lûJšþqZA˜‹ø¼§j¢‘Î3¥2´—2ÙÞË\ÚŒÂöäÆŵYO�—š¦‚
‡ÍIDÆøÍ”í·äX®U16a»ÛR0V Ûáø~=Ÿ5Ü7´Žw—”TAÌÕÔéh-—@›G½Ÿ6—%î(�ñ:,K:@ eƒ¾e�áU¿ŽÞ¦�/©•ÓÁ°]1#(hñ4Væ8ð¼#äÔ
÷[¿¶w[siQº¨2«h(ê1+
j©¶® ÏÇNWËêµ:¢©rÙ8ÇŠœå°ªÆ-—OÆx>§W[9<Ì6‹ëÆ”‚ º”¤5*§!÷1ƒEy>)ý=QQ¿Ž(؉g;æ˜C ¨¾|aÌWãÓ$Ü
- +��òüš™ÊÔ²ÝO�ûçǪgº_T¹D¤wnáÊCçž‚½,#Î0„ÍløEîhÉN\W)‘ÏÀ÷•îñeÓhÞñÙ”° ª¦pÓÊ*©ˆÂáë@s9�%jŠ£km`ý!ý!HáªM-`žqÊœjÕgû?§Ê³.�€eYµ½ŸJ«·Bj+ù"U,ÈXÖ|-mÈuZ_OXtnÁT›j±Fn5|UiýŒÆqT2观ðx¼ç£�dºK‰Î(6xßsÁ�ZOn ¹`7Žø q–Póü=AÑÓµ«=àÁßàáéM¬§¥Kæ1 $EU 2â ÉàÄÏ‹gK‹²í4¥ÖÀƒPw8x®hrïYüLªþ2è-ö¦-�áóX>û4ç�1Šˆç»pä? 4µ
- +BæÈ�Ê-ñiñ“n
9J¶"ÂÆð1·‹‡Bƒ\(†V3;ç�Ê:(¨%2)nÝ`ÿ û³EP}ÐŽð\ÇŒ´ú�˼Ó0"7Á ê£xD±ÎºïÔÆñ’˜ï·¾.ÔÌFâŸêÒv}R¿V>·gš¦‹{e/é=¡¾§*Ì]e·[+eש�‘P4ʬ§‚„›@1áÆághêµ^–¶ƒŽê]™\‚ššfpÔ4Š�wX¼Ùrc^_ŸÚfÝ¢êXMR°vP"o©�ŠÆÎU�›W&¥i’¨Ž?t‹¨¿©eÀºNÏ8eêò|]Rññꎨ
- +:B-ž`Q? ~gü-SW©m:q}¯]3qS€™uUÚ_EF�¼¹¬_jþ+±eßNäìê6ˆÄ²œs×0Oʼnµ¡ŽÆ#�#(TÞOS*¤(öÎÓu@ÍP;j‰›9$_iƳðämECÍR²¹˜•½ÁDlQ^«—¿i€™qª™ì3ÈŸ«Áè¯.±í
- +² ]к6¢Ï„†Å²ö#—�&%^ÜËÓ)
§ ¾5SVB¸Ë„»;�|´}&øúJô‘&ö.ÕSoX”S�Žòê3›¦ ‹âøX˜0w>
0'� s,áhs=^¶-ÈŽúp"wpÄË�ç‰V»˜gÅÙòcn/Ù2©ÔMV‹fI¤êÆœ©‰Êkp(*q+ƒ!›1_K€Õ—WTºUX˜¶“hMͬüØ�ù:m^EsloF›U=]Ý
- +ÆSšÝµt�PdâjŒÅ‡\KbÛãêèoݤJ HO‡Ý¸
Ÿâhe ¶#S;…‚ÛþÑhXÃaŽù‚!‰ò«äÔÍÊYŒù¼Žá²Ûµ3›Õá“ÝÀðñk>øß%Ç»ï ð–²H.ßi@÷L�áÔTìù5®¢á8 Ý¿Þ>°œIE“uóÃâÕ·O·tF¤
}Öïù´�u5OgLf²;.%^xÀ×o+-~•JkÌE%_@ª‘%h[yP5Øké�]2Ð�§Úe+©q‡¿p¨üôçsÏJÀßMWEƒf¦`éÇ�ÊÃZ@Fߨ
- +SÏÁ¦&¢ ÁJ„JþoºßB‰”–èËÞ©gåïiU5�{bm¥IZÚs�/´ SòÖ&ux=]†B"6�‹Ô…™xóŸò´¦T!õ„Û&);Ík¨õ/eÄϪÓç+)¥NÎÚ©tU—e(Q@ÍAˆ\ÛO–«;±Jä›}EkuFÌMh2 %=¨"«„À•PN?µÔÇ‹ƒøºŠš¤¦H�¦R•8|v— .�8Ìš¼|ÜJ<>ž“²ö’XU”hcé°ß`�ýa‹–¿|þ©ÒéZë”�_mB�¹<D¬ùy¸ýóæ꺞¼šŠUölEßN$ŠàÇNxÎ ™Ì_5NSRÆå ¦:º˜¯�*TѪ•¦§ ¨•~LÜcùM±IºYíäRª‘QÚ��‘š®rˆs��–ÏÎÒÁÍ !™jä¦V>ò‡Ï�RrR×2F …?5�®ÒŠƒ�ýãÇýÏ•yÈa‹®�“Fs?~øÕóºï˜ÒFšØX DÈǵ–ðÝ¡'oÛ¾D£ß×%,kâ¹R6øˆ¼š:wH 2FfFwØÏ-¥¬M2°d·ÀÎègͦ1POvC�æõ¾æˆ[_;¦cÛ6“[Ù§ ÷ç üVx?‰§% ;˜¢›£¾Â÷„~ž�LÕÖ•¥twÅ…å/!è&t×�³¾JB*ûZ^à3§�zMjÃ3X«"&Eóà!·ð[‹IZ„Pâ¸ÍÇvï?É�JŒ 6740»ÌçÁhÿ ÃÕZè9ìà f¡‰q‹HƒÉ£FžÌçÔERäÅ´òäßq*ÏMEÕ‘³!™"pÒ¨äǃ”¢>fåsÛ—WlÔÖTÁ‚@*j¡ðy8Ô®˜d»â}]T�*Zÿ Ò«,M=wÈ0Äù¤!ýgÌæupëþr~”Ä:±aúÀÈ)²¢¥íJ‰¼;S1TT) tµI²?RÖmU °6�YÎWæµA“ÎÒfFr¸4SR/�`
- +á
—›*Dѳ'Ú I•gÃÔ쪓¬¥‘T®¬Z§'ÇØ88”ÏÁ¢©¤]ffð…G<ïuR�Dñ=æ3»wÊC¬¶Í¡nòþÁÐ7ÆélGàÔDÌqwÁD÷ê ÙÞÚZÝQ¿Ë»EÌ1ïÆSÜb[ÖCéÿ ØA¤'†ó·ŽîV�$~(Í'íü:Ýlîû£åÔ#Kwï6ßòŽ¤Ò™gpï‹cIÝ|(’à‰äU'Ò"#×êü_åjN¶^G»†ï
¾@ÔÕî…‚àÁcd\g‡C" Ÿí.ïשּׁÚAÈfTóMVøn ƬÈmáì$²w©ƒø¼žMIe²" x.Wð‡áÕ:¡ôÕŠ¹N`¤ž ý�…W—°ý=WÖΧ¢©Åˆi† ŠÀ ª%y
‡Ìo¥£©¨¦(p´e…©ˆa—„G¨ ψ¿“Pã�“XÐîÊÙéÞ~5õ2hkE5T53{DjËù7
ü»ü+RòvZ^_UÌkTºJJ¤QT¹î«-øHßy4K©eS«#9V#¥�š¸Ýb€l å„…€*ýÍ-àp$ e°&6¿¹êiµn6Ú;÷‘M 6žCÑÂ7s·°Âù_»itÃM†œ5“75°Wñûú5Ÿp8,ˆˆ÷5þiï�{>í
Ñ211òë´Son
ýÇó|‡©ˆßìÝ Nþ ¶f'C)9�Þ(Ÿ&’âL[íÞ6êmÝ£Íîê]U½Œ`Œi«é™&ÈÝ,îOïûúE.)¨¥[âbwBï÷µßP31lÚtƃ#¬I ÃMA¼×xØ¢·ÏÇn]ã-˶ýÑÜuœZæ )ä‘N(î–'€‹äíÕÔwðGywo¿ñikÜKT3Û+/ÜòhØjKfn1¬D‹cŒ¸ZMN:€5ŸÄfªrd¶VÚmëY‘€‘œõ@´LY*¬\fp—çÆ|9?Lõ‘Ó�w ¯ê¨zfOXr€|%m‘6x.tÇ|�O
¡Á©'î;Á‰
ö¡¢“ò—tÏ·\th©ŒæÉ∈ï’üZ�${möè÷ŒÅZ\$“Žýð~_ö¿ÐÐ
- +fd?í- œÌ™wnþrb&B7ÌLûuaË÷L{5~ù öß:»wG·ú‡^9Ý¿¿¿Û¡ˆûß3÷ëï»ÿ d¬2!ßÞ€öÎŽ�*SOr c¾,ÓkÂ’¤Á¤µ“EE*¦_¤ƒoL2}M>¢h$Õu;H²«%¾ÙàÈ|¾f«o†;²¡ÕFÉ5¤¸…ZƒYœƒ`fÑ’�Ý-Z°ˆ°x¤½²:aVö¢'wŽèH_h�÷«·G÷É{§á:xf�Ê1Ü3x‡ °œCx‘ªd Âó{áŤӂg’;à¢Ð÷GðZÌš’dù`N7n·Ë¦\æ;†}ÍNèÕñº7Gtÿ VŠíòS=óýz ݺCEï]¦,w¬º=šï˜�ê�Ú0Ç»»Ýáº7wÍÞÍc‚¶x‹úõw|wwnÕ�†Dn†ÏŸX . žâ�ßéa›S埻CoŠ;çv¤ÏÛûæíx¦wV�4õLJj’ŽÐ¥Îàn7Å·ýšý Û!-*ç¡wL`f "Ð8Gû5¶Šùåìæ[t^˜‚ÿ ÇTÔÑ�“¿»ˆ¸¾ùÓ�;ÀEò13ºÙÝÝíþÝ2?®G~þÿ 6·Gtj¶±’rÊb]ƒwß;Šÿ P¿™ª‚Ý»
¶÷G~èÿ óŸ´"K´Â˜[ûŠù^ëYMa’ÿ FéÕ-;bq™³ºf-öoÕÔôëQ¬Ö0ÀÆP}Å�½OßßÛûµÅ¿þÿ ›X½ƒþ—ýú\,|^ÝýûôÂ�lF‹üúî-Dÿ ^–!6ZQ?xÛì×ÙÂ<#áÿ »CΤãÅv·—·]Ñÿ $Oß¿þOÿÄ ' !1Aa0q�ðQ¡‘±ÁáñÿÚ ?!5à€ŠyB>
- +F&tÄZ
8€�[€x^„MCµ„±j‘6ŽHCØ/%XÒqe߀3Kô�Þu€J(<ä(©[‰Ð’õa92R ò`ˆq‰G(L¸4ÀŠÖ�ÍŽ:Öa_`§ƒæŸÉ Ï}ŒÈ°ÒÝ�ÅÞH®_£o@8z Géqà‘ üì#4�°AÏG ±Ñã¡Bᾇpwv Ž,â:ÖûpPO.¾† q-‰$BÁÛÔ#ìã4 ð-:�H‘|©‘C,¡’¡$¾È&¿@Ô'ÃÍÈ„á±€ñÈO¯N++ Bµ-#ÁÃè9£C�EøiÀ 14«8œˆÝÅèG.¼³
- +ŒOG@(1
·¥ñÝŽœCáÈ€°—�BDí¡+“ê^Íæþ¡�Þ$g-eDbQ“ãÐÂnqÈfðÒ”#Fj@«J€fp gÃ�ÃH‡³IM”ÛIÔð*åNI,TùI¬8~¸(Á@ª�3…Ã\Ì”
àà凥¡! pÈI“ÇhñG�l¨ÌxŒ-“RÖÏ´»Í1‘;µ* ƒŸ
�R¡Èpwæʉ‘ÞP£Õ?‡aiP'T pzÚŽ{�ªÁèGVìÍ$€Zkd‘Ó½h£!±[€”‰†€ ã6DûˆxHf–hHwZkT¥á-î„VN*Ž´é
- +�ÃŽ‚m sˆB–‰f–ÐQÆ D¨÷Ë-ä§|ðBÊœÉ�PL�ê(zZáç"i€{q±áäúGóíF`•Ð<¿ß¾Ã®ˆs–ÄÙäÚ<$&›ñòi§ìúæœ÷Æ£ió(žøD·�X‘Ï骘h²Ê">Ä«-4˜”qÀ,Ö±òdZI¡ôg‘ÁŒt=’l§«8—1ˆL/â‘èC#¹`^ãÓ.PÚ£LŠ2½ØÌFÙgìÑçå´†IÖ*Ò±Øó“7Öb+«6£îI€$5¦ze‹\L{(Ø3…�
Þ£'‘Kkº=ì8qf±!b½±„s;¯@§þÊb·G¬icWMvÚ>(p¥7xÉ�í#4£ê`\ú.·òh�¨G“2J)¬‘?#Kõú¼òÑ›ˆ+�gEQËm¡Ñ$L°½&R˜…K‚…p Çï‰]nvÕ$C¨paÐ0€š4¸gŒ³0Ã@%…’šÉW!0sP¦c;Ørû;œJU$·ùO$PÔ‡
g]2‹Ë€z×e¦0"IOp¨•Æ"™Š¶422§pda�Ý«!Éð×Ò+°XÅØ9…¥w�€Û�„YcA±ØM^ZÛiO&}m˜$-Ù’ØðG'ÐOƒ
'ðL7Àó�Ò45¬`&1ƒ¨Æ%�Ôå\P3^ÅôÙÓ‡cƒòb[I&¦,JÂx»�¬Kx9ð.j€ñÕE3•Ì�½dŠm¸ÐÒa–ÆR¬n_#Å9ƒX ¶ç>ºìkH‡yÝ›¨¨Kæ VG Cƒ Õ0Š5áB�”3!Ö!+ ö%2ÁM€
ŠD!†ŠBà'1qê)cqrAO‰[H9µ�dõâ0:<¼C`#SÌ"$fBûº€�×3û«³€#ÇåQ e‰Qž’
- +ǃZfÑf½ÿ H6„z aGî;]ùmð{v‚êÅûM&!âUa'i& ¨å‚KÏÊ!(-ž,ª«(Z �ŒÀ‡Ã_—ˆã€:ËO
- +Ý@m=¬`ÍË6�ž‡ã²Âqâ;Žûˆ´Zrb4OLJBp¥‹d „«†/࿹þ _r1ØÞa‚ ‚üL%�3tk�â
‡Þ w ¢N-àFyd+Ïí ÆüˆhèT8È!¥3ÒÀ‰=>‡j”¥ ÏÔ<6äç^HŠ3›ËàY'<‚í¬DÂx„®eÕ¥¦¾C–ÊA�¼zTŽIx*
- +F—J`�Ì
q£’ÙI-¤0Ó>�´ƒ3;°X� ËÉÐF\ñ¸S@ï‚ÈÄýRý¡N@ñªá”Œ…8b &%Œsƒzd‚•I†§&.Åœ’ 2„Ÿå
- +D§Î2ăËé¸0åf
WzÞ]K9ççéÓ¬Ö¥1¼qF Â@„+½LÊDB}äÀH+–
‚r h„"IDÆUÌNÙ´„ºaû\Ž@ò‚3Øe å¸��LpÃå2õ¸-[!¡ÆÍ 7P ‘?Iƒ¢�5ÑÃi^Õj“âà†ñÌhpÛMÃ%AƒÀ…jPÛ U*›\)Ï}êØ (G”!Þ‰€Ñ¥öa‚
- +^¿óטÅ
- +¸ÀÂHS¹�LšŒO€4G)¹@8•iä•„;ÓEú vrJT:Ø�Æga{ç G•"â®Eú“xTÞ)Ë”¥‡¹( ´†a b�Ô@×Yné´�IÓSA°¸0š:»A$'t“¡U¡ì
- +eE�(F´ÂÂŽ$Ð`X¡‰ne„Õ:¡á ëH!dè‰Ã,‹fÒ QBPƒÓD††„B‘ãÐ%ÁU½¤å–B�&�=ÄF9ö{Rш�Ò{9D#‹0KK¸
- +8(1T‡ÇÑïs’H‚Ø"”²ŒÕ ˜PF©£\¨åèȈ‡§ øHK–1q¼RK¦’Deât¶|=J1mp!ep
nÀ 2^¼Fð‰ ñu/íJ—0&'p“ðOF®É1}!Ç@}Bn •4_ÐbÂÉTŠ$˜‹1Æ¢ÆqK•¾ÀF±_J�
Ì`Ãþ3Ìdšk ¾1‹<9¡`@E6¾EÃ
8€}€wØ@fþaÛhbÍò¸È>‘˜¤òêJTÒ„ÁÅíX¨�ƒ\0�Ê“ ÓYÂáq�+ÚÖ1ÀcQ—Ý Æ‹làƒËX€³ëv±äïZCÂÜœP’OèÊÜâ•Jˆ— Û©ŒÈSÎ0š&¼¤ žyÂe“*Ú—Ñ}‘ñ+X8±Šè�#zÒiIHö(ƒÈd–Þ Ã¼Ço¾R—% *ÏÇÑè·Ü¾�LzreP1zy ¬¥ò,‡µôqB :�W <yZä'¸ƒÖJù
- +HýÑ3ïb2›‰B3AdžöSẨ�E�—:ŒA)‡ Dì¾ñÛ�‹š8ú©ä7,&W sCmZo‰ÓahÇðÅŸq¥ÍÔÄaC¥ÔÄ{µ–ÃÀH;ýeAIÝE(
|!ETDUa‚;�§ŸmÁµ‚-ˆ•9çÑé#É”3Š‚mp‘Y-cL¤6iŒ�¡áVTó�¹ž¸" ädB·YK $аI m2°•ä �ˆ÷ê€Û° À P''¿G�Ó(a�°Fψq¡ÊN@k[“´•B0bâ%cŒ~‹ ‰¨©Q�êH“†ï沄ûÌDwSU†°>rN49‡(=N#kƒ±8€C0‰jMä01Jx¦|ëc¹Ö IÄ:YÔ¤åœwÒHH¯¤”U˜ŠÉI �©È2Zª„ç�U€Øª•�3\Fñ¤Åor™šÍc�
.Dxe)hÃÃ5ÜZRFM+`]AêÐwŽÆ =ìe(›À5ÆpsBkÚXy %ˆ‡P1 øƒ×q®˜’Udf7ðïªÊú¥1¼«ödG%ín-cm#lˆ×š¤"°
ÿ Q§²G³°€ ƽîBHG~ÝnqYŒa�£Vã !Ôþ�Mc�î,½Àm˜èS1 n&G1µÌ%�0ºC3ŽÀF:á³@6¨`*ä°ÝŽnæAž>f‡¦â¦¿¾V2<‘^8à*ýƒ:]ï²0P)wwˆER™…"À%ž
¿Ukm†™ k©t”3v#ð Ô7δ‹�nI
^�ætïÄÏ‘{ƒe¨ßoòv=—ëéÚ;?˜+1ØkDqúßø�Ú0GÚƒÒÙº>]ž’6ôkWów�lï¿toÄàÉ—½BKüè.÷%ËûM��ìÖÇþÛ\õæC®ÝƒÛî72�~S}gæâÓ´5âßúÞ<µ«ÓžØ�êÐõG¥]}â�ÛÊnƒÕÿÚ ±¶÷jw¼ýÂÉLÏï—^°b65"Ó–‡"wI"Á$hðH¡7KZ“ã¨âá÷ž±:ö“s –5mÙðâÈåïÊNlÎ<µÀÊP�«fz
- +}þš)ˆ"E’Sæ)Î%<zßÓå×D¡Tyá> g°Þjo” 7Fƒ œtÌ£†—vˆûý'&ƒ
- + DŽ˜U2Ý%¥%Ý$½®9/ð Ƀ�{N¶§3Î÷®G!�Œï¼ é�#%�¶¤Ò·©Ö�´µF4Çfu€qB^Ÿ!
- +M‚†ÍSíÝ0´Ï“˜Ö &UÈ¥§@Ã{N±<cüÕ‘Œ–ªÿÄ & !1AQaqð�‘¡Á±ÑáñÿÚ ?Úš¿i2–/j ò¤ò|O*»*2¸ùœÉ*Öu®ŠC^øýr\w÷�y¹ìnÙ†„¥á}F/ àÎÏ�±í‰™/ëO�†5&¾
](‹\¹×Øð§Î0í²£wàSéØ�7¥ƒdÜý‚)nÍmØ7>ø؇
½¦{ bøºƒBk÷œŠŒ#“cŠÊ¸<|7ìGƒx¦oSYÄÛwÑ„M°ìZ±7ƒä+Ì©°“Å¥QÇôA“ír’n¯IJº=¢âlNð{ò÷^Ÿè<}¨Ýaú ‡òÌæl9íß)狉Ba:cÉ~V:5Å$ÒLo¶\ƒÔ–\ö3Q�œSHÄ(wÇꬼEF9ô×q¥Ú=ŽìyNmMŽÛÉUDÞŽ¥]V`ŠU2ÂܨrƒìâœGáéìÞ̳GT6ëÔæ—€y£8$>VŽ\ۤÌJÜ#þ•iNE†ížoõæÇ&Žj‡˜ÖGȘpj4?¿d¹"?¶uæßz.�i¼0µó�rx¤ñç"�Ÿ¿Çƒ6·_MÞa ÏóeåwdLÓ192þü³¼>)Mµc�š”?FÈÆB_6+uàx�ÆF0™9ü™=’ûHoŽ�úˆðpgˆV4†
e˜¤Á–ä7vŽåçÛŽÜÅ £s»ÃDcš">PÚ£ê<�£Ý_ä;£�tÑ`;Sô¶33¸õ~ÙìcêEXÉnCœ¾m'0~¹³Å,ÑÚ‰÷„ª
룷˜ÔFGC5>Š[s{á¯4;�'.K#Ðò|êýNQ5·ã_T U$¢^Ñè{Ét7LÙ?š-3ÁHž'Ÿž‰á¥¿!G»¬–È ÓIäZe]ƒNøÀŸF2
- +Rh€�msCFÝóffÆ)o?‚
踂cÙç o>}1É�лtIDìXΗ`s*ÙšQ£)›ëÙ{kω{«…FÍyùa’d
=V6í4Š/Ýôcæx¡A³™âiÐÓ-v„Í=
- +½=r""ê"dAn`õõè3§s`Ô͇òãn{ê\¾*ѺG½d&[,Ê®�‡ë§vYI$v+3ÂøŠ0pÔ�7*�¨¡¨ˆw~´J†ŠÏUŸ:"‹øsxAôvKÔn–ë9WЉ¾š�SûzN;øSM©oû„Ë–á•G!î´Kú
N‡sv�v¤)a‡®·DÛ+É—EÒ(´ïùü·òŸ”úv¹V?„ò{Vóñ¹“
'ƌ>�
tüк„ÜKtn„e�ø÷~#¤&VÒdA˜â@âî–üaÕ¢á¾åA¨{}ßpnÂÃc”½%åìä\ú$ä�z04§ëÅèåh«Öƒ_ÙÕÕx¾„H·×ô0»$yÅÃå�·`«a/ÎœÐ�ˆý�.öÃ{Ã}Ù~˜·îïød›6(›5X¢Èè7(08LË5wç‡ï¸æ~1úܹÁLýPؼ©ÀÖ¼ ¼íIí!Ò›yg–*ƒšÀ±æ�¬¼Ž‚Ö{�ï§F¶5Rå·«ÿ 6-gù 㧼ÒcþşDK¾=Ñ؉Fï^´ç�0–> éÊ¿Ä_뺼:‹JXþ�CT§µ'éÜ0WÆ÷Š~Våæ!ãn*š}xÍŠö:¢kd¬šºßÆч'ï®þz±�»F?Ÿ¤r"Ù�ÑŠ<¨×Vé2/{²‹à©Ÿ�0ñÛn§V�ZO« Åõ àîÅÖxnPWóf s—Nâ4º®s†"ÁŽnå¡;t]4Õ¢gUÄÜDWB1–†žÂd|{
- +êú~ÀƒŠx‰@¼�$²Q™4
3g.ùøc:»‡oa‹�A¤Ãï”c_äô"Ó°c:öôýM7ß²fÅpãöž^Oú*SË�¬Ò-Bä\ûþ8¹×ÕW+_&©:Y1B~H«\‡%Õ4apjàFy±VKÆÛrNñ.Ÿ§'Î × ²çÆërôcîM¡ß%�8áоÕêZ�ñ¥Kj&¼¾yʈ5uUöV"¹£ú¦oj¶aÁõ䬖ê</EÆ~1ûg…ÏÑSòisYˆlè"ŒŽ/5G…¼Žý§àyuùLU6‰}KJIª_OœØÿ âf|z™VÎ𛯠™ñèU:ýè¢8kœÜÔsy¡ÈÒÿ JŒ_8LÙ]R択ÂÕ:‚�¼Wµòf¿È¿Nb&ää0gèñç1ul:µ N
- +)0Ÿ‘èmtiÃç„Žt †R!žÅS˜ý¿[â*3OÌÌè‹Þ÷ò[j¯[fî{·Q™�Ô¸v(¡ªk�>ÈLv)zäD5Õ˜�þUÝêr‡‚Z�*+'å+ª†—µLo &�4×"ÈÍâ•ç>rAÅ·dáiÈ”£«Ó¶…OŸVd®¨œ}m¸Ôeæp7‡Úø1©ãÍ%
- +‰žK¬Ùº(Ó]H¼Fä¼d¿BxQ³%ñ‹JEÕ�$àÓ?ÔlOÝIã`´{ 1ndJœ‘ŽË&»<î
Z¦±·TÝ~Iæ¿�&2µuF—hö;¿æë“p"÷TŽ?`û_ü�tÝÕl¸/Œ†àÉ>>j*–¹«I°
- ++ÔÓäJ7y¨]yŸê�ÈÖ]û¸RÙÅWE~@:ÓÁƒºï[YA±Þ÷œçïøÓAÎð›tGÞØžíR@ˆ—jýrAÄͽ_g7ÁJ�ƒH†«Jj¾„DÚ¶6z¸³6Ñ,S’¿*ÍÈato*0ˆƒÆY± z0Ù®©§aÅgÇî8c�þ$ý‘´“ê>—”>ÌMÎœR6Ð]caèÛ°8ÿ žÛvTLžõCŽ¢÷NÝìlÝ'�v+DæÁÅÌ9Ó
- +ÍÙ_¿ÁBWlönå5‡0 Ô?—p (çxÔcw9+ü±îâ›x>FÌ}0¼¯“·ˆ‰¬’¶jëÿ )
9D›èj}}01v“‘Q»™±Àža½U½÷üW4?+´ž¢&,Ëwaú²j©¨qnLÞâéU”\Ó3ª’ÈyV)#j®:DʾBå߇}880VÛuì‚u†@2›øŸ“챧 ý
y„¥%{šluQ7j&xE$”ƒë
áLÓeÔópû_6'>×××
6hx¾-×ñ›_ú{ù1�Oñ+ôcbMeÚ—°›™édúËáîÉȺռ_ùQ3í˜kŸ�¸Þâ(’ôS*tt|ºªû+\Ñ@ýÉäB›eK»¦)`fÆ™ÁP‰¬!ÙТÞëA•jo8Å÷:‡ó{
²£ »©¼·þ”Ý¥AØñš¨0ˆˆ‰žf£6
†hÉ‹¶vêÏÛÏMT:¦Ô=~jc3�µ`¥mÝ–xhp?ˆ„SLb+íŽ"!h`ÈD#ÃØêS~± Ëœq¯ŠIŽþYÏÁ/á‡(=‰©÷�±2O�Èí£g¶é�¶ýâZ:•ÐÖ~Ϻg¼dš8�xi;Y‹›ŸáÓŽXÃ7+=Q�d
ãRЛíMq›É^:²>9�‡½Ø2X¡œÓãäÿ ö²FžÑü(@L³XOq`}k=ÜjAHß»1ááß»/æJwÜqÒ=´û-†5.ö@ùëf:£…/XÍ”ÚäL$LA—’ª²a…b©Lh2‘ð¶*œÆKô&gÇ ‰÷¼Ÿ»vB<�v›K<[«É°3‡q‘¬¯kÓ¸`jÏ›G‚×%uY-‡1,0€×¯»ˆ*[«´aVcð»'v+—AÐúC=49¿�ÿ ÚžjQµ´z<(ËãÆáâŸIƒiÝûÄ<Ûs@¤¥®KÈ3_&òÏHcbº–A¦Ñ‡¤ZÍä E$œ�ËǤÅQ’ý{{2ÞÖ�Ö—;¨ò_×Äç2Oƒ½?•ØU7B5á¾JPÔðßk†Ö�ƒLM¤ö‘ù¢Daó7ì?Övdƒ†~Ú›°2ÑãînüZóœ¥sÔÔÊ�¨®7
- +BÑ�ýW¼l»70ãŽ#uö¯`|è¶Æ™�`νý´_rÞjõ€ÂÃðSctbä;È鸙yèŒrß°à®úIìÕîö4ÐBÂF9^Ûyè·”šéÊ>õW5Í
/¿4òƒkª°Uä7fØ»¦üx\‹Ÿaݺ1à¿®‰N·F"=¡žÙþI(�ºÆœÞ¨Ó…+i©£ò Â_´„ª<.žC3ÝÙ5~Äd›Lîdz~{¨øY—±(Bèá�¢Ö#æÃVï€Ø¤¨Õ9‚'|~ée
^.¥jÔ>ÜݲþLìFšâëùÝFZ’øRþ{+løº-°BˆŠJï3È8gši†:qº?Ðô{�kú-ÙðlÑ*àÜá¾Û»˜,|‘ìÆ\Lø8žà‘Û^E–{›¡šÞ¸`‹º‘©×àŧj' «ýc×W†é¢#nè>ä˜Ì1‡rüM «5y�iožju7SSk´Ú/ ñ<× oí7ˆŸšy*–Ïd±‘}2çÐfþo˽.E“
- +sÉ>
- +íz.¦ ƒ^‚¨d+?@É ˆ�x¹Ûؙα×&�¯öqÆ™HIÓ•oï"á‚ÇbOÞkvW�ÁÏ3‘©6;‘µn&üÂGõdž–�ùòÙk‹ô¢ ¿K2„ƒêoWaD.eϯåÃSßçÆÎÝ�óXü›žaÎ��u‹ÕZ)&«ª"�i[™#L E"fsÕ×ñï0å€.C¼Î›ˆª6”HR[¼²DǼy›½uv õ]œB�294Çë¿ ÓAïò»vôٟϯsð5²�Ä®ï!á»FºçÍDÍ|KmDdt3SáØ¡£÷Ò>Áð¦UØX5-þüh{¨>VìÙ?—ö€¹ó:n2çÐðÛÔz¹ B1W\’œÅ3>=1T‹^Í�X´ì2e[¿Êî¼ÌçXiŽÏq=±”†t¤„FÄߢ1øPB4O´8JË0��SˆÁÆ•UÑG°÷_à¨,èÌ…B͈A¯AîbJþ½
R?_„pf‡%ð"Ó°ù[³M†Nì�²Ñf2OK¢ð‰ä=ÔÀô3Ù©™ñëøHÿÄ & ! 1AQaq�‘ð¡±ÁÑáñÿÚ ?ñx‰Š:õ³Â(ËT’ð-% ¥R87@ctDë@à4Ê9‰)ˆ¤’P IP2—©8E0È�²f‰êÓé
- +µI²H�EÌoáv|z‹oÝ#D•¸%tÊBf@$I8G2 ¨_@:‹ªí(§}™Ü¤0÷½xd�É¿~Gí~¦Ò�AåÏ%iÉ�ƒrW=lýFê|ÐYsa3_3þD›°(yÂP.ë$é#ÖÅì÷B§¢Eî¹Ýôh±nùÖNša+Ì×Sü9/ܹ+–¾7TY49Q)vM¼AÉy�X§EäÚe¥c"=ù¢àÓU-d¢Þ(!×�“ò4òÒY'rÐés�÷CÀº¡%
- +œŠ>T·=P®.€åƒ«´w3‚ª×˜Æ�I#8bn®¤«¬*z{_‡ætULþÆaó+±G8BÅÈ�1Ò*Oælzv0Ãø«]>Åc÷N<u3šþgç©J`º+dy¢S䢇Nuv¬}
šiO�åVnøtHèü¥E+t5šÈJ’@E>&f§Êó:"Ñg¬ T@X�„@UP èÔ”„ŸA“ÂdRAD‚èÀ—r�‚05Е( )]�bHÄ8S!ÈU ŠŒˆ ¨U&6<ÒSÖñ�wᣤ%*K>3yë(ÕŸZBR0¬Ê8¬•S%p$¡jÜ^äiB™Uc¸Á´Ô~ï[Ÿ÷’'˜JPÔ±"„€JP� ¤¤ Ò³ñ\1l NY� A$„(p@\AV ²n,”y›¦lðK¨¦”Û€¹é<ȦŽ»ÂùNDd„\!fx˜ú×–O¹³»Sö;—öu7¢Û�3Ñ.—©[Q[„Ô¾0õ%ë
- +k7§¬!73Óç�jÓÌj+_oò‚„ TЀÅ*¢Ök®$Á˜ HU&Ix@%I“™*Nb„ã?ãÈ’P^Jà˜‰‰ÇrÏ8éx2_ÚkÚ‘ÐÜ¿“‚_t÷¼öh-çÂÈæÝ¡C
- +Í8w…/Ûá”jé™=cžôJ
]é¡xq£ Âöç‰â6rë³]^*ýdÖPáp±Ñ’Sá2ZJjÏßÒÄ‹«œ}‘2[ùùJF—ñoYcŠ‡¾Å¡‚•ÔPÈDÈ 9B�_¾K~Ç“÷èÚP¡¢û=ÇN~ÏÂð´ ¡ÏŠ[X#©@*X °"« ,Ä„Á8K�•%Èÿ d&W¬–’ƒŸ°Ër‘Âéµ³&6I·Œôé ïwo+†ô˜ìܺMžRtòØŠÅBç::¤dëÄÎ t×+³ã…aTÅx6Ÿ2‰ÀKiò‘"ë\xåiŒr8áøŠ#Ð|pʾáÆâ$T 0dÖ2Ñ ËróÓÖZ]Ö0t¶+¼ýFg‹"ë�3…S®G{O¹üòœ&¨ŠÁ\É}C”W…çÌo
÷Öºñ€Š\« VB ÄH•—ƒ
- +R `%0 @Ht
- +ÂAq0P ’( S€T
- +d�r(�G �€w”Hš�2ÆR”}-E{vXÀ=Ç)˜…SúçÏT‹…Ýe×!8™?Ì(}˜Uù9î.c†ÌáIû�2ϲJ©m¡,¾XãI>V‡)[èÜÂ%I%OÏô\¼ñ –_ÒÇY+^ѩ¬p.k;§ |J¥—ÌýA%—_Xž<ÉäO#Eòc…Ó×ÕHú_]ðñ[÷f\g8CëïoSTÖ«$V´/k‚�X‚‡BC$CA"8à?Q¢fm€Å”¤¥K“ÇEHG]&Q–’«™–Yá…!B’HA2“ 1xBYÇËL,p—(+W»Vç´–PC5O׺Æ�ü—l]zõD´t)OÆ«IQ�è·<;i~Ä4
¶@óºÃ�¯°éŽB1'|iAŽH¦ÁB˽ùF'M9^4bÚ÷éüˆvø�˜0ƒû¯4ÊEóÖ �?aŒ•Ò0áp~ÕöÒÊj&%ŠI‰ hP¦U�ÍÌüt‰²÷ûÐ,PMÔ…@@‚ "#’|„0DR’ï~Q·@ºå2’hNúôf”P©ÏÇí/pêõ�°t©œj\ñxîšM=rq!ÐHO‹hy¸Âù.ÒÒEùkË�IÁ°¶8?�î÷‹„±â‰íЬ£qð¶ë>,(ÛŒÈÂ<ÕYá�Ðjb�Øœ7 @ØÐFJì}»ÇãôW–RKˆçÍÆ&róÍL¥u‡U¥/ÃUCŽgsC8ÅG÷DžfoLºOÜ,Úþ¡ñ•«Kv–äI*ƒÿ J5ñ%Z¼’Åðå0F-aRìzneŽñ�(<šmÀŸGªioLtyÈÃç•hâüðb lí&¸�eé`ï¹0«ôÍ9#·[>QNOÝûKì8Wüa×Y·óù·/ÅŽ4¢yLÖ®ý9–´/W�Ewx{ÚÈžJè\Ø¡$´h™}öÆz+´4a,¨ZIIhÌ쬼£‘ú™œm&õÃÊÒ3EÞÕ§Ô�@ƒ�*zK‹ ±éî4K/w�OÌç¼»sN+pþØ;3Æ…Fùü¼d~x4Wéà UŠB À)d€}p—4Œ�~DÌü´Ž‡?{‰Ù=JiËÞSŽ‹Z`�r¡-éøëß(Ìð§)$ñ1ëÌç4èõAÍ!ˆœÝQ@®ìèÎÕ—Æ>'ê8<`6i<S³ù8ËÉŠ7F³mã¬xïÌç
- +U|+V_‹üUËcÖ2n…cÖ¼æQ‡‹dåŠKŠ¦â¬üFÖŒŠyKm8s—3Æ\.¸h_~ªxàñ%âõ´P|¢al翾LÅ:yŒ|o×JR?N�.}D£?sÓÔ1(ìT{·¨2è팟³»�~ ÊŒ¦¤ R€X6d€ € (Ò@€
- +4&%¨"QÉ!U�0ü.uÖšrQØZÜK�
- +TÂÒ�åèüùiÿ )ÓÌ"ï~Q
- +à
c3-LôYä7ÅžuÂïxƸtGx™Â<éÞ<’x=]¯àÎ¥¼])žšñüF%¦á7æ2·[>_ÃTðUôðW¹æìþ£„R©N4Qò…“ Þ£‡j,ÛH`f¤]ÐLÓŠ˜Ôã"á”Ä£?8ä´—àþgÝöÕI’9$’¡I$“¬.︹^åú/¨aùÅ#$[bKvM©… ˜®ÜÝ!Æ’kí’8~Ý+„[k½}`zêví…éŒp{OIÓòQÅ})FÏ¿…š…�€~-ò‡)ùa:Mûà9©ÖüxâkgóqHÈ]Œû�Ïó¸ü±×7Y'Täî{È¢9̤èe´º7ñB¢¼Ò©xàqçø°!(IÉy‘а“cÓÜ)ù©›LB,¦f‡iRxp!SKº«¢ªvUžµ€)N\}c“ù-ÃǽÕa_¯�ÚÐÃ
- +„Ÿdv§q ÅÈráo1úV}±FÎ*M¹+{yÇ`htà¨)ǺûÇ‚#øØØž$%ÓçZËG´{áF@»F÷ž3Ƴ²ð‰N~vv¯ŸhÉ ˜Ø0*TŠ¯A@°]hâÊpyXŸ0«†+3b<ˤH奚‰Ê&hòV¢æ ²ÅJ[ŒÇ«N<ÞcÑî‡_Ø/l¢QŸƒ4%0(…ÇåøŠÃkÕ»Òo{‰§ª"E�îŠ$»ã8¾ýlc÷¹7ž;»GÐyìc©oöxÉõO0K‰*A&À T‰!R¹{9©+šH5&¿·mwXÎg:f!ÊäǺJ¶‹‡9¡ZKH¨\2ôJÚÈmoy¹ÉSèoã*uõËìé7º@TyÕ$±É~¹‡^Îý²åSýì•gv|þ�% rL€C˜ç+i´õׇ¿LLÔŸc¯l ’”~äòŒC:]ù,Œs1šèC<7ÁÌ©}Ž¼¬ ÔRFe.jË)³´ U{îØZq‰o752Þ*_þ¨zÞ‘TÒ5’Šþ+@.¯¦\vÜ>šÛ3'�ƒÏŠ¿‘ZÕW·}³Å6wª�$¬
- +nT,J+§^
c;lå£hEÕ¶¦«ÚO¼bþ~R:‹\g‹I_¤jž
- +¾šcÓÜ9Q9÷]¼�)"¤èAGzóå§#¢‚@B�JP-”_ø»¾âv½Œpr7ëGœpvçfùŠ!µvŽ/Îìö‹½�óÌy¿…ë3Y:ô‡yé“Ø«G{¶µrÍp…9ûç×bÓåtµ€þ^‹ÆH�lžy`/2-Ë¡¤gf\ªªö´ ÑÊ…iÍÓ¸ÚG†‹*´Ûƒ·V'yÆ}ßcÁÑšY‘SßB¾Éõ
- +ô/b(j
@ Èÿ .omfz}Dê÷šV¹¦±ÆÀw á(üz[‡…6ÿ K£fŒ…(5N ¨é.,9/ªa” ü!y,’–ŒÎá/�óHá-| jLã ºÏ(ì2ý]0¢Æ%þµ³ÀËrË;Õ²’Ù‰=0ÀñZÑj³Û—qI?ƒò$uW±—�cÉÔÙtáXJT›³'SjÊ‚<®Ù–�Øá¤Tó;¢+Z*=—µ="C×Ͷ„Øô÷ eÚ�$íÂÑîƒ_ØáB*~tÍÓìfûŒ-û¿
- +Bó
@€�r9ú�@ûˆ±¬cƒcG¥ÅPÇ?�1ø_öNm*‰ó˜Íj°çüj§žåâ�Û Ç±çŠN7©=—ó ŽëêðÀØÐ'|r\`—®'¡Æ5/ËÕèÐå»Óci©„Øô÷üCýë|{FHz=PóOåJ :%Zõ G Í,¼f‘8;µ'”쑱Ð?ŠF}ß¹žÓºšm™‡2ÒSŸ;—gÈ™©>Ç^ØFaR Sº0™«2ÔóنȆ5~jêè¥ZØ4qz=
- +6-·5óʧ9ŽÚG¤"cv|à•Â£ìÚ¯µåÒ‘PÒZnµâN<—’ûh d�µl;G¶Ž;äs!£L´›Ï‹¬f;üøÑŸwßíEµÛ½âFãÙéÛ‘™¥(“ìoHÚšÏkGU +v:ŒVàW9uxÄU·ëXRÔšAGc¤×5tY4]×¢Cñ)çya
¿®}eꞪ$®THKª ®ñ²ˆ¼í=#;cÃO:í\°Š-%Ž‹H»”™cØ`Ö)„R˜yÎ8\¬’ÞgYƒoßèá)¡œÕä“/ŠJQ1}§4nn�»¾ã ²¥•Rxÿ *I5Õ]•BrQGô©ù§qˆÛÂþjy/ă�¥„W›Ìt:-zÏ["œž"ÇOZrQI¼øÂtÒª…Qå;a:ciÙÿ ’xôYe‚M¦Ñ p4Ž·¥ZT�MÒ_˜.?ËQÌîhgÑÓNý"bž�,ÑÐêºC
¾•SQê=žê5ý�ZNˆ»üá T%(”F¤ÒPçs†ñs®´Ó’‹ÛYŽ¿%çäÅOÝ;Œòÿ Ó§Š22m1ºÑ(‘S÷Nã¼ã/&3tûü«^H'ô€¢kî 3jà=–%H-°€*b�ý 4$hþ {¶P›žž Ë04�5]+›@
- +eZ¥•`Ò Ep ¡|Å°>B3O¦V€*R}¿°4Ê �Ó§v¯ô´Ü‹´1)ýûŠ·úN2ò`‰Lg¤ ÅUÁxÑ9ËÈ�ÿÄ & !1AQaqð�‘¡±ÑáñÁÿÚ ?`Ìžé4²�4/�OܼW«9$Ê r‡¾jà+
- +‹ìÐ=©ÂI7šêJóu±sŠ úh�Š8ÁD€^a,)`@„É�ÅRàßF!˜ìPBè ©]B8Q˜B€+2CÑ=.A„‰P1
I¥#’ÿ >Ò‚’Úû„X‚Kš™Ä>Áä8 »2ËQ¿ÆÓ"†¢EÂ,´€Ä.¥ µ]ŧøÔg/À9A"Oa,JÛR¡ê€I½§¬í„JHq}rðîL8FàÄ¡µWãGl3qMæÉmgƪ®–u!a¡ÏRe P†éÏŽÑÂ*å,'oØP¥‡`_ø
HPÚ2¦! Y0¾ƒƒE ]V%D�2¹TÕØ)‚«¡W8ÎF*—²À!ŒÁÑ–ÔLFÂy g:�AÔÔ
‹´Àg�-Â
j¼‚Šä pÊX F…�D0U”š€Æ‘"Jrê
- + ’ZR7ì¶!RàĪA@ë‚$ûY
- +Ó�Üš2 Xù *ÿ `zKAöÄXeii¸èœ`ð»¤Ó� r5Â?Ø|›=xÇm´µÁj™àÀãiDcJš™’¸¢Ruî/À"Š¤/Ó.‹©òAÊ=-sœ€‡Ö…àÖA¾u%lx!*!+ô
pœ oñ¤|•Q!dåSìôÇi$`D.Ä‚ Ž<ÐaL r˜C$á��sÅU/ [DH�9- N§c1ð„O>`Â�¢](jã ×
- +E\û âa¸À @VÊC «SÂКÁÜÅ>Ë A‰:ÈhNPˆP&ÿ '
|