From ef8c062d9f5b12d660aab92c28177e716d4721eb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E6=9C=89=E5=AE=89=E7=A7=91=E6=8A=80?= Date: Mon, 4 Nov 2024 21:49:09 +0800 Subject: [PATCH] update --- docker/install-docker.sh | 751 +++++++++++++++++++++++++++++++++++++++ docker/uuwaf.sh | 14 +- docs/waf.tgz | Bin 3549 -> 10020 bytes 3 files changed, 760 insertions(+), 5 deletions(-) create mode 100644 docker/install-docker.sh diff --git a/docker/install-docker.sh b/docker/install-docker.sh new file mode 100644 index 0000000..24389b0 --- /dev/null +++ b/docker/install-docker.sh @@ -0,0 +1,751 @@ +#!/bin/sh +set -e +# Docker Engine for Linux installation script. +# +# This script is intended as a convenient way to configure docker's package +# repositories and to install Docker Engine, This script is not recommended +# for production environments. Before running this script, make yourself familiar +# with potential risks and limitations, and refer to the installation manual +# at https://docs.docker.com/engine/install/ for alternative installation methods. +# +# The script: +# +# - Requires `root` or `sudo` privileges to run. +# - Attempts to detect your Linux distribution and version and configure your +# package management system for you. +# - Doesn't allow you to customize most installation parameters. +# - Installs dependencies and recommendations without asking for confirmation. +# - Installs the latest stable release (by default) of Docker CLI, Docker Engine, +# Docker Buildx, Docker Compose, containerd, and runc. When using this script +# to provision a machine, this may result in unexpected major version upgrades +# of these packages. Always test upgrades in a test environment before +# deploying to your production systems. +# - Isn't designed to upgrade an existing Docker installation. When using the +# script to update an existing installation, dependencies may not be updated +# to the expected version, resulting in outdated versions. +# +# Source code is available at https://github.com/docker/docker-install/ +# +# Usage +# ============================================================================== +# +# To install the latest stable versions of Docker CLI, Docker Engine, and their +# dependencies: +# +# 1. download the script +# +# $ curl -fsSL https://get.docker.com -o install-docker.sh +# +# 2. verify the script's content +# +# $ cat install-docker.sh +# +# 3. run the script with --dry-run to verify the steps it executes +# +# $ sh install-docker.sh --dry-run +# +# 4. run the script either as root, or using sudo to perform the installation. +# +# $ sudo sh install-docker.sh +# +# Command-line options +# ============================================================================== +# +# --version +# Use the --version option to install a specific version, for example: +# +# $ sudo sh install-docker.sh --version 23.0 +# +# --channel +# +# Use the --channel option to install from an alternative installation channel. +# The following example installs the latest versions from the "test" channel, +# which includes pre-releases (alpha, beta, rc): +# +# $ sudo sh install-docker.sh --channel test +# +# Alternatively, use the script at https://test.docker.com, which uses the test +# channel as default. +# +# --mirror +# +# Use the --mirror option to install from a mirror supported by this script. +# Available mirrors are "Aliyun" (https://mirrors.aliyun.com/docker-ce), and +# "AzureChinaCloud" (https://mirror.azure.cn/docker-ce), for example: +# +# $ sudo sh install-docker.sh --mirror AzureChinaCloud +# +# ============================================================================== + + +# Git commit from https://github.com/docker/docker-install when +# the script was uploaded (Should only be modified by upload job): +SCRIPT_COMMIT_SHA="6d51e2cd8c04b38e1c2237820245f4fc262aca6c" + +# strip "v" prefix if present +VERSION="${VERSION#v}" + +# The channel to install from: +# * stable +# * test +DEFAULT_CHANNEL_VALUE="stable" +if [ -z "$CHANNEL" ]; then + CHANNEL=$DEFAULT_CHANNEL_VALUE +fi + +DEFAULT_DOWNLOAD_URL="https://download.docker.com" +if [ -z "$DOWNLOAD_URL" ]; then + DOWNLOAD_URL=$DEFAULT_DOWNLOAD_URL +fi + +DEFAULT_REPO_FILE="docker-ce.repo" +if [ -z "$REPO_FILE" ]; then + REPO_FILE="$DEFAULT_REPO_FILE" +fi + +mirror='' +DRY_RUN=${DRY_RUN:-} +while [ $# -gt 0 ]; do + case "$1" in + --channel) + CHANNEL="$2" + shift + ;; + --dry-run) + DRY_RUN=1 + ;; + --mirror) + mirror="$2" + shift + ;; + --version) + VERSION="${2#v}" + shift + ;; + --*) + echo "Illegal option $1" + ;; + esac + shift $(( $# > 0 ? 1 : 0 )) +done + +case "$mirror" in + Aliyun) + DOWNLOAD_URL="https://mirrors.aliyun.com/docker-ce" + ;; + AzureChinaCloud) + DOWNLOAD_URL="https://mirror.azure.cn/docker-ce" + ;; + "") + ;; + *) + >&2 echo "unknown mirror '$mirror': use either 'Aliyun', or 'AzureChinaCloud'." + exit 1 + ;; +esac + +case "$CHANNEL" in + stable|test) + ;; + *) + >&2 echo "unknown CHANNEL '$CHANNEL': use either stable or test." + exit 1 + ;; +esac + +command_exists() { + command -v "$@" > /dev/null 2>&1 +} + +# version_gte checks if the version specified in $VERSION is at least the given +# SemVer (Maj.Minor[.Patch]), or CalVer (YY.MM) version.It returns 0 (success) +# if $VERSION is either unset (=latest) or newer or equal than the specified +# version, or returns 1 (fail) otherwise. +# +# examples: +# +# VERSION=23.0 +# version_gte 23.0 // 0 (success) +# version_gte 20.10 // 0 (success) +# version_gte 19.03 // 0 (success) +# version_gte 26.1 // 1 (fail) +version_gte() { + if [ -z "$VERSION" ]; then + return 0 + fi + version_compare "$VERSION" "$1" +} + +# version_compare compares two version strings (either SemVer (Major.Minor.Path), +# or CalVer (YY.MM) version strings. It returns 0 (success) if version A is newer +# or equal than version B, or 1 (fail) otherwise. Patch releases and pre-release +# (-alpha/-beta) are not taken into account +# +# examples: +# +# version_compare 23.0.0 20.10 // 0 (success) +# version_compare 23.0 20.10 // 0 (success) +# version_compare 20.10 19.03 // 0 (success) +# version_compare 20.10 20.10 // 0 (success) +# version_compare 19.03 20.10 // 1 (fail) +version_compare() ( + set +x + + yy_a="$(echo "$1" | cut -d'.' -f1)" + yy_b="$(echo "$2" | cut -d'.' -f1)" + if [ "$yy_a" -lt "$yy_b" ]; then + return 1 + fi + if [ "$yy_a" -gt "$yy_b" ]; then + return 0 + fi + mm_a="$(echo "$1" | cut -d'.' -f2)" + mm_b="$(echo "$2" | cut -d'.' -f2)" + + # trim leading zeros to accommodate CalVer + mm_a="${mm_a#0}" + mm_b="${mm_b#0}" + + if [ "${mm_a:-0}" -lt "${mm_b:-0}" ]; then + return 1 + fi + + return 0 +) + +is_dry_run() { + if [ -z "$DRY_RUN" ]; then + return 1 + else + return 0 + fi +} + +is_wsl() { + case "$(uname -r)" in + *microsoft* ) true ;; # WSL 2 + *Microsoft* ) true ;; # WSL 1 + * ) false;; + esac +} + +is_darwin() { + case "$(uname -s)" in + *darwin* ) true ;; + *Darwin* ) true ;; + * ) false;; + esac +} + +deprecation_notice() { + distro=$1 + distro_version=$2 + echo + printf "\033[91;1mDEPRECATION WARNING\033[0m\n" + printf " This Linux distribution (\033[1m%s %s\033[0m) reached end-of-life and is no longer supported by this script.\n" "$distro" "$distro_version" + echo " No updates or security fixes will be released for this distribution, and users are recommended" + echo " to upgrade to a currently maintained version of $distro." + echo + printf "Press \033[1mCtrl+C\033[0m now to abort this script, or wait for the installation to continue." + echo + sleep 10 +} + +get_distribution() { + lsb_dist="" + # Every system that we officially support has /etc/os-release + if [ -r /etc/os-release ]; then + lsb_dist="$(. /etc/os-release && echo "$ID")" + fi + # Returning an empty string here should be alright since the + # case statements don't act unless you provide an actual value + echo "$lsb_dist" +} + +echo_docker_as_nonroot() { + if is_dry_run; then + return + fi + if command_exists docker && [ -e /var/run/docker.sock ]; then + ( + set -x + $sh_c 'docker version' + ) || true + fi + + # intentionally mixed spaces and tabs here -- tabs are stripped by "<<-EOF", spaces are kept in the output + echo + echo "================================================================================" + echo + if version_gte "20.10"; then + echo "To run Docker as a non-privileged user, consider setting up the" + echo "Docker daemon in rootless mode for your user:" + echo + echo " dockerd-rootless-setuptool.sh install" + echo + echo "Visit https://docs.docker.com/go/rootless/ to learn about rootless mode." + echo + fi + echo + echo "To run the Docker daemon as a fully privileged service, but granting non-root" + echo "users access, refer to https://docs.docker.com/go/daemon-access/" + echo + echo "WARNING: Access to the remote API on a privileged Docker daemon is equivalent" + echo " to root access on the host. Refer to the 'Docker daemon attack surface'" + echo " documentation for details: https://docs.docker.com/go/attack-surface/" + echo + echo "================================================================================" + echo +} + +# Check if this is a forked Linux distro +check_forked() { + + # Check for lsb_release command existence, it usually exists in forked distros + if command_exists lsb_release; then + # Check if the `-u` option is supported + set +e + lsb_release -a -u > /dev/null 2>&1 + lsb_release_exit_code=$? + set -e + + # Check if the command has exited successfully, it means we're in a forked distro + if [ "$lsb_release_exit_code" = "0" ]; then + # Print info about current distro + cat <<-EOF + You're using '$lsb_dist' version '$dist_version'. + EOF + + # Get the upstream release info + lsb_dist=$(lsb_release -a -u 2>&1 | tr '[:upper:]' '[:lower:]' | grep -E 'id' | cut -d ':' -f 2 | tr -d '[:space:]') + dist_version=$(lsb_release -a -u 2>&1 | tr '[:upper:]' '[:lower:]' | grep -E 'codename' | cut -d ':' -f 2 | tr -d '[:space:]') + + # Print info about upstream distro + cat <<-EOF + Upstream release is '$lsb_dist' version '$dist_version'. + EOF + else + if [ -r /etc/debian_version ] && [ "$lsb_dist" != "ubuntu" ] && [ "$lsb_dist" != "raspbian" ]; then + if [ "$lsb_dist" = "osmc" ]; then + # OSMC runs Raspbian + lsb_dist=raspbian + else + # We're Debian and don't even know it! + lsb_dist=debian + fi + dist_version="$(sed 's/\/.*//' /etc/debian_version | sed 's/\..*//')" + case "$dist_version" in + 12) + dist_version="bookworm" + ;; + 11) + dist_version="bullseye" + ;; + 10) + dist_version="buster" + ;; + 9) + dist_version="stretch" + ;; + 8) + dist_version="jessie" + ;; + esac + fi + fi + fi +} + +do_install() { + echo "# Executing docker install script, commit: $SCRIPT_COMMIT_SHA" + + if command_exists docker; then + cat >&2 <<-'EOF' + Warning: the "docker" command appears to already exist on this system. + + If you already have Docker installed, this script can cause trouble, which is + why we're displaying this warning and provide the opportunity to cancel the + installation. + + If you installed the current Docker package using this script and are using it + again to update Docker, you can safely ignore this message. + + You may press Ctrl+C now to abort this script. + EOF + ( set -x; sleep 20 ) + fi + + user="$(id -un 2>/dev/null || true)" + + sh_c='sh -c' + if [ "$user" != 'root' ]; then + if command_exists sudo; then + sh_c='sudo -E sh -c' + elif command_exists su; then + sh_c='su -c' + else + cat >&2 <<-'EOF' + Error: this installer needs the ability to run commands as root. + We are unable to find either "sudo" or "su" available to make this happen. + EOF + exit 1 + fi + fi + + if is_dry_run; then + sh_c="echo" + fi + + # perform some very rudimentary platform detection + lsb_dist=$( get_distribution ) + lsb_dist="$(echo "$lsb_dist" | tr '[:upper:]' '[:lower:]')" + + if is_wsl; then + echo + echo "WSL DETECTED: We recommend using Docker Desktop for Windows." + echo "Please get Docker Desktop from https://www.docker.com/products/docker-desktop/" + echo + cat >&2 <<-'EOF' + + You may press Ctrl+C now to abort this script. + EOF + ( set -x; sleep 20 ) + fi + + case "$lsb_dist" in + + ubuntu) + if command_exists lsb_release; then + dist_version="$(lsb_release --codename | cut -f2)" + fi + if [ -z "$dist_version" ] && [ -r /etc/lsb-release ]; then + dist_version="$(. /etc/lsb-release && echo "$DISTRIB_CODENAME")" + fi + ;; + + debian|raspbian) + dist_version="$(sed 's/\/.*//' /etc/debian_version | sed 's/\..*//')" + case "$dist_version" in + 12) + dist_version="bookworm" + ;; + 11) + dist_version="bullseye" + ;; + 10) + dist_version="buster" + ;; + 9) + dist_version="stretch" + ;; + 8) + dist_version="jessie" + ;; + esac + ;; + + centos|rhel) + if [ -z "$dist_version" ] && [ -r /etc/os-release ]; then + dist_version="$(. /etc/os-release && echo "$VERSION_ID")" + fi + ;; + + *) + if command_exists lsb_release; then + dist_version="$(lsb_release --release | cut -f2)" + fi + if [ -z "$dist_version" ] && [ -r /etc/os-release ]; then + dist_version="$(. /etc/os-release && echo "$VERSION_ID")" + fi + ;; + + esac + + # Check if this is a forked Linux distro + check_forked + + # Print deprecation warnings for distro versions that recently reached EOL, + # but may still be commonly used (especially LTS versions). + case "$lsb_dist.$dist_version" in + centos.8|centos.7|rhel.7) + deprecation_notice "$lsb_dist" "$dist_version" + ;; + debian.buster|debian.stretch|debian.jessie) + deprecation_notice "$lsb_dist" "$dist_version" + ;; + raspbian.buster|raspbian.stretch|raspbian.jessie) + deprecation_notice "$lsb_dist" "$dist_version" + ;; + ubuntu.bionic|ubuntu.xenial|ubuntu.trusty) + deprecation_notice "$lsb_dist" "$dist_version" + ;; + ubuntu.mantic|ubuntu.lunar|ubuntu.kinetic|ubuntu.impish|ubuntu.hirsute|ubuntu.groovy|ubuntu.eoan|ubuntu.disco|ubuntu.cosmic) + deprecation_notice "$lsb_dist" "$dist_version" + ;; + fedora.*) + if [ "$dist_version" -lt 39 ]; then + deprecation_notice "$lsb_dist" "$dist_version" + fi + ;; + esac + + # Run setup for each distro accordingly + case "$lsb_dist" in + ubuntu|debian|raspbian) + pre_reqs="ca-certificates curl" + apt_repo="deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] $DOWNLOAD_URL/linux/$lsb_dist $dist_version $CHANNEL" + ( + if ! is_dry_run; then + set -x + fi + $sh_c 'apt-get -qq update >/dev/null' + $sh_c "DEBIAN_FRONTEND=noninteractive apt-get -y -qq install $pre_reqs >/dev/null" + $sh_c 'install -m 0755 -d /etc/apt/keyrings' + $sh_c "curl -fsSL \"$DOWNLOAD_URL/linux/$lsb_dist/gpg\" -o /etc/apt/keyrings/docker.asc" + $sh_c "chmod a+r /etc/apt/keyrings/docker.asc" + $sh_c "echo \"$apt_repo\" > /etc/apt/sources.list.d/docker.list" + $sh_c 'apt-get -qq update >/dev/null' + ) + pkg_version="" + if [ -n "$VERSION" ]; then + if is_dry_run; then + echo "# WARNING: VERSION pinning is not supported in DRY_RUN" + else + # Will work for incomplete versions IE (17.12), but may not actually grab the "latest" if in the test channel + pkg_pattern="$(echo "$VERSION" | sed 's/-ce-/~ce~.*/g' | sed 's/-/.*/g')" + search_command="apt-cache madison docker-ce | grep '$pkg_pattern' | head -1 | awk '{\$1=\$1};1' | cut -d' ' -f 3" + pkg_version="$($sh_c "$search_command")" + echo "INFO: Searching repository for VERSION '$VERSION'" + echo "INFO: $search_command" + if [ -z "$pkg_version" ]; then + echo + echo "ERROR: '$VERSION' not found amongst apt-cache madison results" + echo + exit 1 + fi + if version_gte "18.09"; then + search_command="apt-cache madison docker-ce-cli | grep '$pkg_pattern' | head -1 | awk '{\$1=\$1};1' | cut -d' ' -f 3" + echo "INFO: $search_command" + cli_pkg_version="=$($sh_c "$search_command")" + fi + pkg_version="=$pkg_version" + fi + fi + ( + pkgs="docker-ce${pkg_version%=}" + if version_gte "18.09"; then + # older versions didn't ship the cli and containerd as separate packages + pkgs="$pkgs docker-ce-cli${cli_pkg_version%=} containerd.io" + fi + if version_gte "20.10"; then + pkgs="$pkgs docker-compose-plugin docker-ce-rootless-extras$pkg_version" + fi + if version_gte "23.0"; then + pkgs="$pkgs docker-buildx-plugin" + fi + if ! is_dry_run; then + set -x + fi + $sh_c "DEBIAN_FRONTEND=noninteractive apt-get -y -qq install $pkgs >/dev/null" + ) + echo_docker_as_nonroot + exit 0 + ;; + centos|fedora|rhel) + repo_file_url="$DOWNLOAD_URL/linux/$lsb_dist/$REPO_FILE" + ( + if ! is_dry_run; then + set -x + fi + if command_exists dnf5; then + # $sh_c "dnf -y -q --setopt=install_weak_deps=False install dnf-plugins-core" + # $sh_c "dnf5 config-manager addrepo --save-filename=docker-ce.repo --from-repofile='$repo_file_url'" + + $sh_c "dnf -y -q --setopt=install_weak_deps=False install curl dnf-plugins-core" + # FIXME(thaJeztah); strip empty lines as workaround for https://github.com/rpm-software-management/dnf5/issues/1603 + TMP_REPO_FILE="$(mktemp --dry-run)" + $sh_c "curl -fsSL '$repo_file_url' | tr -s '\n' > '${TMP_REPO_FILE}'" + $sh_c "dnf5 config-manager addrepo --save-filename=docker-ce.repo --overwrite --from-repofile='${TMP_REPO_FILE}'" + $sh_c "rm -f '${TMP_REPO_FILE}'" + + if [ "$CHANNEL" != "stable" ]; then + $sh_c "dnf5 config-manager setopt \"docker-ce-*.enabled=0\"" + $sh_c "dnf5 config-manager setopt \"docker-ce-$CHANNEL.enabled=1\"" + fi + $sh_c "dnf makecache" + elif command_exists dnf; then + $sh_c "dnf -y -q --setopt=install_weak_deps=False install dnf-plugins-core" + $sh_c "dnf config-manager --add-repo $repo_file_url" + + if [ "$CHANNEL" != "stable" ]; then + $sh_c "dnf config-manager --set-disabled \"docker-ce-*\"" + $sh_c "dnf config-manager --set-enabled \"docker-ce-$CHANNEL\"" + fi + $sh_c "dnf makecache" + else + $sh_c "yum -y -q install yum-utils" + $sh_c "yum-config-manager --add-repo $repo_file_url" + + if [ "$CHANNEL" != "stable" ]; then + $sh_c "yum-config-manager --disable \"docker-ce-*\"" + $sh_c "yum-config-manager --enable \"docker-ce-$CHANNEL\"" + fi + $sh_c "yum makecache" + fi + ) + pkg_version="" + if command_exists dnf; then + pkg_manager="dnf" + pkg_manager_flags="-y -q --best" + else + pkg_manager="yum" + pkg_manager_flags="-y -q" + fi + if [ -n "$VERSION" ]; then + if is_dry_run; then + echo "# WARNING: VERSION pinning is not supported in DRY_RUN" + else + if [ "$lsb_dist" = "fedora" ]; then + pkg_suffix="fc$dist_version" + else + pkg_suffix="el" + fi + pkg_pattern="$(echo "$VERSION" | sed 's/-ce-/\\\\.ce.*/g' | sed 's/-/.*/g').*$pkg_suffix" + search_command="$pkg_manager list --showduplicates docker-ce | grep '$pkg_pattern' | tail -1 | awk '{print \$2}'" + pkg_version="$($sh_c "$search_command")" + echo "INFO: Searching repository for VERSION '$VERSION'" + echo "INFO: $search_command" + if [ -z "$pkg_version" ]; then + echo + echo "ERROR: '$VERSION' not found amongst $pkg_manager list results" + echo + exit 1 + fi + if version_gte "18.09"; then + # older versions don't support a cli package + search_command="$pkg_manager list --showduplicates docker-ce-cli | grep '$pkg_pattern' | tail -1 | awk '{print \$2}'" + cli_pkg_version="$($sh_c "$search_command" | cut -d':' -f 2)" + fi + # Cut out the epoch and prefix with a '-' + pkg_version="-$(echo "$pkg_version" | cut -d':' -f 2)" + fi + fi + ( + pkgs="docker-ce$pkg_version" + if version_gte "18.09"; then + # older versions didn't ship the cli and containerd as separate packages + if [ -n "$cli_pkg_version" ]; then + pkgs="$pkgs docker-ce-cli-$cli_pkg_version containerd.io" + else + pkgs="$pkgs docker-ce-cli containerd.io" + fi + fi + if version_gte "20.10"; then + pkgs="$pkgs docker-compose-plugin docker-ce-rootless-extras$pkg_version" + fi + if version_gte "23.0"; then + pkgs="$pkgs docker-buildx-plugin" + fi + if ! is_dry_run; then + set -x + fi + $sh_c "$pkg_manager $pkg_manager_flags install $pkgs" + ) + echo_docker_as_nonroot + exit 0 + ;; + sles) + if [ "$(uname -m)" != "s390x" ]; then + echo "Packages for SLES are currently only available for s390x" + exit 1 + fi + repo_file_url="$DOWNLOAD_URL/linux/$lsb_dist/$REPO_FILE" + pre_reqs="ca-certificates curl libseccomp2 awk" + ( + if ! is_dry_run; then + set -x + fi + $sh_c "zypper install -y $pre_reqs" + $sh_c "zypper addrepo $repo_file_url" + if ! is_dry_run; then + cat >&2 <<-'EOF' + WARNING!! + openSUSE repository (https://download.opensuse.org/repositories/security:/SELinux) will be enabled now. + Do you wish to continue? + You may press Ctrl+C now to abort this script. + EOF + ( set -x; sleep 30 ) + fi + opensuse_repo="https://download.opensuse.org/repositories/security:/SELinux/openSUSE_Factory/security:SELinux.repo" + $sh_c "zypper addrepo $opensuse_repo" + $sh_c "zypper --gpg-auto-import-keys refresh" + $sh_c "zypper lr -d" + ) + pkg_version="" + if [ -n "$VERSION" ]; then + if is_dry_run; then + echo "# WARNING: VERSION pinning is not supported in DRY_RUN" + else + pkg_pattern="$(echo "$VERSION" | sed 's/-ce-/\\\\.ce.*/g' | sed 's/-/.*/g')" + search_command="zypper search -s --match-exact 'docker-ce' | grep '$pkg_pattern' | tail -1 | awk '{print \$6}'" + pkg_version="$($sh_c "$search_command")" + echo "INFO: Searching repository for VERSION '$VERSION'" + echo "INFO: $search_command" + if [ -z "$pkg_version" ]; then + echo + echo "ERROR: '$VERSION' not found amongst zypper list results" + echo + exit 1 + fi + search_command="zypper search -s --match-exact 'docker-ce-cli' | grep '$pkg_pattern' | tail -1 | awk '{print \$6}'" + # It's okay for cli_pkg_version to be blank, since older versions don't support a cli package + cli_pkg_version="$($sh_c "$search_command")" + pkg_version="-$pkg_version" + fi + fi + ( + pkgs="docker-ce$pkg_version" + if version_gte "18.09"; then + if [ -n "$cli_pkg_version" ]; then + # older versions didn't ship the cli and containerd as separate packages + pkgs="$pkgs docker-ce-cli-$cli_pkg_version containerd.io" + else + pkgs="$pkgs docker-ce-cli containerd.io" + fi + fi + if version_gte "20.10"; then + pkgs="$pkgs docker-compose-plugin docker-ce-rootless-extras$pkg_version" + fi + if version_gte "23.0"; then + pkgs="$pkgs docker-buildx-plugin" + fi + if ! is_dry_run; then + set -x + fi + $sh_c "zypper -q install -y $pkgs" + ) + echo_docker_as_nonroot + exit 0 + ;; + *) + if [ -z "$lsb_dist" ]; then + if is_darwin; then + echo + echo "ERROR: Unsupported operating system 'macOS'" + echo "Please get Docker Desktop from https://www.docker.com/products/docker-desktop" + echo + exit 1 + fi + fi + echo + echo "ERROR: Unsupported distribution '$lsb_dist'" + echo + exit 1 + ;; + esac + exit 1 +} + +# wrapped up in a function so that we have some protection against only getting +# half the file during "curl | sh" +do_install diff --git a/docker/uuwaf.sh b/docker/uuwaf.sh index 3a9e385..73b9a54 100644 --- a/docker/uuwaf.sh +++ b/docker/uuwaf.sh @@ -1,5 +1,9 @@ #!/bin/bash +warning() { + echo -e "\033[33m[南墙] $*\033[0m" +} + abort() { echo -e "\033[31m[南墙] $*\033[0m" exit 1 @@ -13,8 +17,12 @@ if [ "$EUID" -ne "0" ]; then abort "请以 root 权限运行" fi +SCRIPT_PATH="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )" +cd "$SCRIPT_PATH" + if [ ! $(command -v docker) ]; then - curl -sSL https://get.docker.com/ | sh + warning "未检测到Docker Engine,接下来帮您自动安装,过程较慢请耐心等待..." + sh install-docker.sh --mirror Aliyun if [ $? -ne "0" ]; then abort "自动安装Docker Engine失败,请参考 https://help.aliyun.com/zh/ecs/use-cases/install-and-use-docker-on-a-linux-ecs-instance 手工安装后再执行本脚本" fi @@ -27,10 +35,6 @@ if [ $? -ne "0" ]; then abort "你的Docker版本过低,缺少docker compose命令,请卸载后安装最新版本" fi -SCRIPT_PATH="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )" -cd "$SCRIPT_PATH" - - stop_uuwaf(){ $DC_CMD down } diff --git a/docs/waf.tgz b/docs/waf.tgz index 1c57f4f53e6eb4237369c6f32b4897d3192e0478..64a37c274db3a5df2e58c45086eb22987f82c18e 100644 GIT binary patch literal 10020 zcmV+Y2& z%lk?9OKd1vm8Bz+q?H`k-*ic8(py`toE;Y+!A5jhwx%<_j>DOhl|7GG=s4aCd zoJ3w@jnIJUlUys@;ExyitUkCw zQ1_(q+40AhFRnkj2yAc^)5B9^yZ01#5AAuqAb0l?-5~g3n69l=0b%#MxUJ&!_ z(S6DNM`Y3`lNVnkwRr>XB!CB?7#3Nu^#bYc1x~A)Z4hOS7>+(m-M$ugLQh0)EPdU$ zzR>v3v*D@RBMgd++B2q2K|GD~H&*YSZG3hkyt~{uc60sY*WsC);qvMA>nC7#{n5#_ zn`hU5I^H;O4R*P{a4~#zeC^ih@TU{1s)Ck48N~jZt6{qXkt?G(fJAFe+5LI`y6?)t-rxL3Am z;Uf$OH(k$nYDE_Jd;7p~BVG+>-bTj^Y$4(pOlyhMB`CX9qLc|6Bkn zOO$ht6@W)t0xNLPjxgPcP%PjZ+<^873J@$LCLONKxYxoS0mzTJZC4HSTExM?D;yB> zpnl8eY$>CpC*Qk0c{rQR!2fKf?@wOO;dz}X)&W?}NyKmvWyUAT82(rQ_Q~2eE8&If z+mnA=I0~rP-)v^}?k%vX)w>I;cfW3&x)gr#Dcr1I`zBnx3XxVA&x!9Ie|#%kxfkC5 zu(7llp7|UgS061mKD-y6_<^I988sfryO{If|HzC2*o(pJsAgzBeXwfJC0C67-o0&sjVtCGfF zzK5t3AI!mW7P;bs0|0sVLg|mFjEPSeFnJ+hDkSu5s!jSp3T`OI_){c0CI~w&^$^Lz@BM zHZzIfxjfnsX8|_uE)gh~QX6OvLE9sAlMx>HD9W%csUMABv$icp5amK#CBv!i7 znwC&+U0?frnTxiyU+QT(yYVavZkO@+m!`?K8?f|0UHblhJ;(b$bebwv{e#b_!NDeP zVC()bHJIc5e=0SQ%?)O;|H}aQ@BQCzaIKwR39lVr|MF<#ug8A=@l#3E=;@@If`3`U zi$-XIR_~sH@<2=v^OBRK)uftigOQ~5udavZ&+-f-YVLC<5H-qKIdqVfimE?z2n%ay zfiNaX>t}E9QX{;4Gkotvc~2*Gpcevm9{BFO<2ynQl(YLtt-{Ks@vs!g8F)b zElBVYN!pkyVLk63IN`^iU2B%!jjQ(>i_47*7uUYHFOmma&iUp$lvq0(ow)#kN8dbN zxB@}-@yCp{6qIUfmmh==Kf?O`!fhPf z{43x0`h}%%@gqcc>|S{CK^(qu?)2jimQeubPV?QzXTvL3fcEO$^J@>^hmja>Ql?3G zdU||)<>>0YFF^*JHvjqr+8m%s8?0~j$E$1Ke!F`AT;tXavt)F+v0magiALC$y2u*OIO0viyX_^gIn-b%EH#e+wXB6M|MpEn`W(X?qqoJ zeWA`d^nSuD9863?09{+!f>*oiLL~HKlpND#lH|Ok@5In}piy=N@ zxaJ&n^Q7dO#th|SW=*S#1uX!BmbJk0qhZ~#%jQfIN+B~)=+0~PJV_0v)l5oF=W=Q) znuek=C?Om1*<>P}jWbbnYQC3m5vZ!-oJ#CR)25L`z;iE{=G2dnOb7H0s^gQW^-ci-ZzI{D^9#M{jcN2-9yvUZ%$5)6sEN@&8RSe z$^3e_yXQs<~+@W0GBYSabX znu1ut8FK32rh05K`-}DXBsGX|4kCus8XIlOavt zOmBLH>a!6W=$2@J!xJNNKam;dtp34oN`Ud4-PM|y@N3PqXV`EB|3XH>3Rg|BA;kmd zwS8gAQD+OvHXShaj3orFuv5cU%g?-JBb@aU)T)E~GSMp{MG1)f^* ztCl3~V+f4>(l)?51vWTG36L`I>DD%aC+WZfGUQh%(W*{h`@|`esi6r{2EK8$>UciH zXUuFG%%ZmdE?t9Q0IoJU3rGR>aoXg(QC{sA%gj;~owJO(vP9TK@gIMe-vTCm+z z@((KDGHu&2O2tx8E<^0DIgVBI%tMqENGiR3VsqA!<-oO3q#8Z~s&}x+qQs1A`gHv^78g^P~hxfl`~4G<`OxdB`0M7Xe~RHc)_^gh#57eyloy zBvlS9wsV&vR|w2^&QR{DQ1LaY<2(WpiIg=DLK~O7tJ$8WbF`=@oFmht;}E|Yjv?c1 za4mv@0ss%v83ieWU=L!z#C(Cwl}%WRdqfVapb?0h0c8l@hSU|wyiMFtH9^>IpGo65 zo?{hV+t@hg&6+i(0*0b6yWrn32`i9!9czwCs1w6<3+)+E@-UbB9i#lOigQp+>VZoY zEbEjS)TJGuY{HX3;BJ9q1U^ShPb*nW=JjgHu}ocIMGP@L*aOy1P`Q9Df_!Q&okLMU zrw*HD_6hXRYFyKs^`v$Lg`^~bIVcpL(F#tS8P18J!mU&@4aO3mgwjk*Mldih0gG^< z5qLr`C`aaMEJ>jGpbIh2;;+=l3#5f+9{O+Yqn_GV6^R2 zlTxQs7QiJXs7j+TsE=m+3gQqV*}(Zgb|;9UnOOV^#AKIZ7qv;a>ov>biM!D!!8j^D zCR;!y20g#(cg%3hEW1v%`C>s;b4?8jVV19G0vM!;+~7Y+pah6%ReV{X=mCzZ24TY~ zm!<#v&nU3|+wh*puT0~~^fml;U@e*W{DT;lyNuOeZcpkR5|_L>e$_T%_Y zP4qgD2v@pm)_j#!9eXN}xcC63Fsy7?{(`KpVbcp4%)}%Htu3o9MKXxqqUnM15@H=R z*er+F9MAL}Y>rr60Sg4-cEr35=epURVu%Q ztRKpxSxV|o;Cj?5LuFGnEmLy=!$`6d)AEC(|#*~t%+jMvWwpcKYn&m&r! zXIfn$HFe>O=BmvJh5am>zVlrGSyf zoks6B;eAWBxB{?|NVT|a_+WLPcXUJXpkIM{>`Pty8ZheL)ipupBu@@55!{lM$6 zP==3Hht8bIg%9%8E6gnzToqgmbPlXx4;0u~b?aC^R<*Zbzmd*@+Kj6iP@p10?21^; zCsYPbGQ^If*ilLo77=QEDCSYnnV>&0M4$o7sWYA(ZaOh9hY|yWlQyTB7PFq1*Ux|<2BoNbhAl=%cah&SOnW^Z8Mk~Z=O4Ow zuxQ2Bjb36yfHd8JvO;(2QypVGqz?q6Y+$u5f6OJESq}ExiB2lgIcv_(frf5 z8bhDXs7b*Oo}bv%BCl{$K8$9)LpW2!RRptN!h`ig}M`bN6>A_ zqv=izJx<6tE=SlfNz7MF9XF|40R~!V{uPmIJkqOKwTjk{CqVGm)%*TF=|tN^T5Q2k zYgbmipY`%Fvy4S2ToLoce!*RU%-{-+F=8JrStLVMXhFOx{tACr{P55rs0)T6M`^?O zxTI4b0(vWT5HarswHiMODb?dCksUcTgDeN;hgLGDFO%M88^~wlub4-Vz-b?gXn;)a z;CI7%RYL$(x7!x~V)Kn&sBfpnmj24ViYE~N0s#!GA^2$PjGvZ@K=~9xSzELOjR!T1 z?4XR^X(*{IgE)A+Si*YE0Jr8^;y~nWrvx@De(f+kIWaM|r#SukP(dCraw(eDjqQ3e zTgq&wDLtLe3~o;+)7e}(Th`M9X-(G#bQw2*#b=Gkb255I*@Uj7jCUT!d=Y&La`(I9 zcH7($whG;}=?U$om1jD7Nn}0oh1vGV=xalJ$AQ<^hj#569WTByG`@GVAag)D_Tv=+ z5PO4Pj1;;z#le3zAZA7;-`q7mIW$t-J2hUATMYqEnlT5AQ;aW)k!{1(y%~iz(o>_m zCyTF*jgLk@UH}tTu>p&dY68XR#1?jMK*oPyz|FeQ(<6;cy;YpryQ|RsuDHu9MqjagNi+0!QQFZDIwzL&==XsNVjVu8Ixfb9KPzLs?N_TuJuz}Ejr zQX~(beSMPQ*i@2)5IB!q5mCfztNg)mCBl(UH^E70e#J32OEcb~!w(%V=rp0U7 zfjw)3^|&+?3@d3yL}dRWoZ)4^2_{`RQ#%L1Umq!!7f>1rsHSayF3KVlg$ zB<|Wd5*05#*1)8<1qZyKDzc8k<3D(d{oF(D{%3j9Uy5vtQh#yA$0$T~Jn3h>RvkJ|OfAf2 z`mMLriHW|5hB}7FBlt|p16%9$0$rz`*N2a{%55ZtOadDZgnA3SeCb2PHl4>KYe;bK z1loVKcdX56TiMU>D-@YlCW*i}(>8II?W8g3cqef(cDmV}xI+a9&{`lOp*n7y{`Nhu zdv)~yKeO9u(M%f<=f2K8_q@+Fnhc((v}*R*T4^F`xQ?|w2FVP4V9#ek;>@ zBn1WfjC^XiNa#QATC@L?&j$T?W@J`)@o2{SgE=~i0*3K1y>NU_k<6x#k+rRm7L>@|{lNqR+=Yrg;d^z@DaIKN> zs3Q-~?!0o~L=DU^Mz`>8zv5lh5F;Nrz>o~+J{zM=Q(rb zN1ze#)LV9851_j@Ae<6Qu=ji!hYy|$`T#|gJ;VjfxsVFX{>($GQ?hn)4iydxEn$!R zY(Op|>+B%$O#EfvTsMF3uqnnM^*lv~JzW!QN&c?yM-IRiIOvu6GjSLHY(X$2YFUw#HWF=@$Y&F9^ zdtn?*rkF2-73=8Hu5EFtBG&p++yv`XDMT_{f_4_-CSaU|f&lC>hhI{aL!)Z;8fxC8 zZs5B<>+^jtfrB_l_oHT9880hvEY1J(TCh$O!2YzW<7Z=1%gxzj&Oc8gUc5((sWCUubH&j7FZ;&uXU6;S$X&_(0f={Xa zx4*f)*O=m|ngPJ6zo7UCB_O5CMY>ePcS#}a4IfS0nVv;zr%g(Lt?|U8zonR*^0!kk z752;3Q9C~P6gf(O0AiIwg5}rHk*zzD9!8!&i%`2Fmow4N48s!=hl{DZJ=ILNM()8| zG;&o#7luj~%P0z4nOm#W@}EHxtd4O`qPFU;jT`_AP3OouK=kJ(*vdLaA~ZKhP=x!J zUnF5`oFcIp_>wH|hZb-V3z*@Y(1l2)Y+%)^@KaLU9%hl;H4EWUU2f90^OF?$v}Zk| zpH*Bbh9OqFo$e>$!Lcvw9TS*Zz6u5Kg&cSYnENhj}!oNrIpVlf8AQ;BH;%wup-_b)v|UdXBa=o7Mp((|I`S zQ$VO8{-ZjX;C=puI3F??Zi|aVeyO;+vhRu8`Ew*4py)J7i46%44CZPW9w4b=lt!=m znCE8fTfeyJFUo6#l2a)eb>^85d=Wxwa(F2~T5(T-353Hh`xu4nHoljRT)$o(T&)y^ zBeucQ!lnzIB3k#%_b`0!JF(9};M}s+4HYbLO5@vBw{SxYOyLdP#1PEKksN$cOR_F& z7{FuRjoQ=(8s!T|oD~H`B3voC1PqA>Y_8 zqZ-j`pv)-Jck7w`8-4nZSw9h#HA z{n&_aRNb#UgB81>(X?tiek$QHxz?`Klo^!QzefHb@a78K`kD0$LzS`a0Wqb6biPdO zRX@jGvcPU~BxjN+g92of%!YX=K*sCiSI<$nB-W91#J^|?iOtt)8QAh29guxm18FC$ zwqYW#h3-f=O7{wV@q+0kint;{fX0a?fRnUO+O7NTwo{3w3rhjD2&hSpXJyQp9g24y zp3ZKQKNJQWMA7M46wkN|c5@?mX9YO$h{Qkli{Lw}z%h@!0Q{sH771)QoECr|R|EeC z_*GDt1$*5Ev2s%l+M`il^cLgpG8?Q23hyI(QTNkGut-@l96sB#8l_N{coiyDWKCRn zfY3n=hsc2=fa-4T9pC4*$6;Y^U~87_!D;tmc6NlA-Yb%aMLkLiGI?5biVwzQ6ez%{ z_p4vXpTQ)2!!!dUV-EjO95{~BLFlVUZ;)VzXVY_G`GD$0=$-3aBy|fJd-vD~;Z%N< zTj?B)S+wjhtu|zn2F_nDmBE;?o*j!LkpnVyl|)v`grdPcEfE3=%6Jnmm>X$8+{r^4 z23MPSV;{tKFqvZpAm>W~;lKbqBM>r_6SN>hmo40trY-U^W@XzJn>J77{*&Dut0@Ky z<^RJe4o1Ms=fKP}nJtzM`MA&?>N*$}9y;1Vg>8wWIjH722A?X^8U~s(HYVL+@EN3n z>K1raRl{;K4bH5sig0@v-Psd;OExg3QV-4%@CHFBWPp0Q44SC47m@?-eBMC5SWVT0 zh@acW+1uznfKRrOMg?$`rAb3i@rcX~sZzR{YL#_MYqjz0+uGJtnKwx^^SN{_cs3ph|_I6OaEOAdtm4@s# zSAl}w>z5C)Gju5-OG}pGxu>v{R9lX$ZJ(m#^o!e%#q7Q{fS1AW zLcV?U=YV(h4V0~9d430j%+P(P2MIxciPe|WVD1~g1+ztvOx3q(5GU!p7l zzWEU_Z21hM4q@4^U7&9-eTFujJB=~ z9a!(ZcsK(FlJI-kxWu>BsyS8qZ>1!khC;)F7`RO^IFHj-9|Jb0w~2q|=S zt!-f9Je_1h&d#Lfd`0Ha3InB9)1C<(M^MRHi-2p_r1&k1N`v*Qau3)AVtS`gJkeFm zco>5@CYgj_%4Blxpl5A&zH5OJ_fSidoE&DO@Rcwc<+@AKCJ%{- zSa?g!IydYejRLJ*!U=ZUzYqQ2LCKsr#``wC5N{S74?M7aQE|F9ZUB4`XpLQ~jDcE7?Fnwfat1xsHA*e=vHny6iWP%>P zc)e#G6A12;u5COg+^cPL6f&HO*2NJRB2&POc@>VAwKH4+Jqir2WDf&=A zSDC=pmC?!7PKjO7t1_}PR#l2@b{@BOp4hp0U1tm3VHn)yHeLm}plpRfKeyrCOLttY zztGIw9)qRx|5+3ONMa;lH$E9{zUp$m@m0{eWkumAi=$(r$O!$;$uwB7PYqBhMVeA+ zh<=#F$4bg&R`n;{@w9LONq##Tp9<)KNg92&g2-IyWufj>LvdN8y9m=sVA6w*K>Ht; zpbV@+aCz8At;Y~=mlP;061gwMy{mDMxm>^cZhB8X*pF5bsyMvjtr_-F)!_{ERLy7eCWgDNZAY zImfQ^ST~aW{~n|6>Ssh_kv-|jr(f#1G*V^)MTwr8hU2cA_jDpprk?uriQZuzb;f6_g=mjhX|DDoXWFLDa5U2a^P7 zof!|i-;z5`x;rPfeWNbaq;yXm-IJ0;26>{VoCK^=2P@B}xuQEim_~<%)wwQgHEo)e zC!^bJLwOLGzB{6emq4w|?MBreRJRvoSMJ2M@UPTyfjLiSf@Xz9c;lwaAWZBcp!>zq zS2>8F?h?#ZHkCh_a~-51LJCM@h}EXmT6)G7GNCT+h+TZ!ABP^Q1B%!OzF2*FuX0_$ z{ML6-a+dyo&AzIv2UZV?G=K|A((yR>*tN&QvU|tuH3#g66`Jss?YwWj3d8(%gGSMGjhd`i+)(Ma5~p2P2$VMP~=ETZ95)ktAUGu=bs zS&r*e(44D}Qf|vv40*Y^Su&t5-?_WBG&BBKz;Fd?s3_M>2(->!gD_Eb?x zykz*wv>$jxE4e3`jJ0Ut&yRmP?wP`EyL6iYLM3V9x1xB`Hm`bXtMaG4_HmEGwoP3E zrL^vObk>s5_UT?JfJmlh@zD43^R?4U@R7`+S~<<+5v7@A8=zJpk)_+LvaRsef8h-g zX&Hz>$b}4RHZ(V#DoEFzEGDj(E+dyOA$CvwbG&MH4EUK=wFogqI6K3C%vi=9Dwr#D zO2G!dMt_D2X3cUq1#XQ+SdQl7&b1YbZ~t-{r6R5C>ykI#78L2X*_tiu0PhrwPCdqJ zQOy8$0{m$Zdh^qVQn`0smGQn^m%)H_2<2>`b(?nOhG`Ea> zndeXeteko-W7w#mv2(3;=hhmLRpPGt^V7ORxA<=CV`aV~<&?h;BF zX2919ru~GaJsYH^*KN^ioQd|PMXiSPpn~?OX z6bi!sdHgrODdto|%*l3%O4K8m2j?;)pz4X%swM3Kh)lltX{h{!>;v)?xE zOw^{oZ+v+JK7V;O;axo07(G>+9<5znsNeX~oBO(Ub*Xl4v^G6oyEE3>D$6y5U1}H7PP=V_53?gAfwVS6_uTM3ePk|Z%7H^{N zt-w{64F&PTNHOz6*y?F>%Da|^cssMJrA-k#0wbg9pkoN!*hQIj|8>18EnUXH^Ugi= z=FT?mjSbT6XuDBV4eZ_jq4CoUI0Uq1K52<6VXZ94np$xUD(h%T#Ccl;SMYh+##8faAwiha>SxaoZJ&=d&5f3zs@2dY4wJ%lCbUPA)c9 zR*0?CXg}L150(U(f&Dx79mwwMKk!jsq?U>~(t*~2r;9NBwpqL{DIXAB1$1On9-okbH=2$x7 z3y9(n{8w`8J=Y{Purp#>Lu3n3!rR8AsxB9?eXMBVGBRZ2b5%Bq$K;VAwB?Jkr5Xd@RjCs1r0hG#?~_QH!uU&u{};42x%Aa4$F|>K?NIu z$O)X(t}-M`mLOfb?^Ayra!PZUTKsmjCB1cCE3Et9}0R`Amqe03$M+ApmA%6^BR_o0I4sL6)RM>TqrEO406}n5L{}d zosJEcut5NXvqhh1@FRU2K_o!Lx~5;R=I+#|PDg$#i>QFSsd;D^L1YY&C#Gw&cZ0~d zfL6yRfjEdv2&neWPf+TD$Rup15N#H?1 zJ|Q(aNJ!bnfw&`0n)J*c9gGt|8$2#eQs$)&(j+16tk5k*ST_k$_X2ew{aSpfPdg}6 zJ+0Y^zQ5z|w3>U`PMy71zca^N+qM_ma-Kfe8ir#Rx7kZ8Wjhm?d&&Gq=6@1O9ShEp zS2W;~A-{Ly`9GRUN^Jg*_9l`kI{(LkJe>bu1Jp0fdv{MY9-OHCaPpUDH#mPBjY&cj z{v{Bbk6?1HE}ny?kza$=0ICVu9R9-#w_;1rLN z$q7a#a#Fa)`5D##z3UIX(_`N3*R|=hFr(AE!91|`E?%uYKI6}{{%|K$bPd|9_uyo8 z@qF#ahpXe~Sl8X`U3>yNSFcaPWT;o{&o#!g*?Vtrn|UONnmNMjSU0T-uUCY;QAmr} z$%}M@$S@qYzJSAiHYzj0t2ghqrp(&yrP}0N?c!AZ{!_oC(d|rcW+6xKK+QWh2zdTz zb@Ub-_0?-swI~b__3O*t$`vxIUR)rf!rb%KYjc4skXlZY83UH+OLg(7?`bLxJkWBc zS|*e6<%hL1PrRu~IOnQCd^&%+e*45e*|tX{OL>!vfy~;IW$)bW`lIXhlS@SA^KU>W z_R8#TT%7hMuMl=8m%Q=iAboA(?CMu@!~qj$nf1X{@767lU0u9TU%3RBfNos8B{-AW z)tEm~U3vgMV6xfkOJp;GmTbtr>a*MR@4v4;ov6*ukj$Wh!5!3fjNJQbqW~9IHc&=+}Tp*DTXJ3Gm^)R$-Bl}mu>-ok079O{2Ol}d*7|8>AG%g_A_qn&;OrU-Urq>l)ZYj4^|F^poVaCJ|koTVy7 z%y4R1*8L4_0tFXjS96-^ylE8FVvCALMHs(EYm~vIfqyDXt@&1cD(YciPqpk0RTo^foEd zeut(4oh9CZp{OQ~U6ukYT35cb*w)LxoTt&DhzQpz=yQ?7bO9T~s%085l{#$}2maaD zZ>zGHDS<;vvf5fWc<|%?53{@fk@?%M?7sd?=HtEl2m3N|0mlVcAi)GOO*NXv^6a}2 z`mEqGHWWK+8bL=Wxwi9(Ulr9+fdctSku70ab4nG)Iza#1lB0|*;4SlnD;$QTka}Sp z+sgjtIKC_lemMshLu)eO0?w<3>L@uu2~xxTM^1~wvL$M2j?Fy&@_#!U{f>a{*t6q6 zcK_aioteQ8T1Xb(-Ti;h4(#2tXZyf`9eej=`jXMu8jAgU_a1m*8jv$X6IDT=q@@EVSv%FX*0 z1Y0#B)#J9029HDBWi5@8O_ZbR7;+{+WMRirA%G}FaxECnb|jlQNFw#d%Pw($07(B| z7wbP+#;^4Mcp{!!bN`EzKVkoW4X_z~Xj({CNcBUeflB5Ga!iybCl^CmbR0MkHY#hF ze3@fo%x$JWNx(fs!NUSQRkZR!)e$XRfU++_y%Vt^vg*gP*6&&}skFR57uZ6{(KU`c zL>VZDxy`_LKjh#rMj%Q7p=dKA-|vD7L?Neyk*u4p;UKes_V@2b1<;#db<=jBK9kNS z!zwu~z$-69F@U3pc2}Tw2q;5;ypSD~lHMX59Mh4t79RyGY91Q7f|%0pBCLVAQRyuK zc&UbAD!FXVEfk=3mrYa4+Uik^`cO2sZTE{+Cn~#^L0l@6Upp#mRHRj+XsJ#G!5l+- zkY*N(u$d@Ny>B<|&Z&kB3}7AQpebN%pq!i^a?3W+4$xVk*ia4PKqkUQI^5mGQozaYvLRM<*vBpT`v5vZFkrVKuV*46ZRhr3~Fg0kDW5+iu> zJyzB-l=W-&kXq(TkSILO3-(T$Fb|#A)P^xfVxp*4UuQ?;Y|=}eHCXm3kTsYl^R9(? zGS=~Bm`m4?(gm9Xhg*G&Bj`D(+Hy{#KCkFGQ&aOi9b%AbgAHVMg2@GP5&ToO@Gx-| z+|Sp&dkp83Tw>5r7q zj!D@4_QQ(82FI;0xx2YUQ@$PJzF4w%C-=Dvrz}h3%dirs%SW;x+Q2MN2^}|tD;;~c zaZZUQPRCA?E1ei$bfE(s?WG+out@7lkR%>sU5*4EG9NK%2#yeWGvR|4##X6qssn8) zKhzhEN2OGZTbuE~btgy3I!pmk+=~tYTOrtjs~V8B zol+%k?V;?0Bgw&3+Qh+pRCG#&hwqYgn)fDlf-72$#VJ8ewlKLxy`bD}RSW))%SsOi zcoO)4Z-JGMv>n}9v%)g7V3~UBH*{ULR2c?g+OMz(3Su#t`U?j^fSRV0-^H^w@X%!_ z8)l)vy`rHjgb+dqA%qY@2qA