pdns-backend-lua-4.1.8-lp151.1.2 >  A \>/=„*F@՚+cB314U.zA932:*[lǰd4X5vFa{["+ߚ0fW \dwijPs|Q3pңVgҎ7>T뚢M\I|)mϼ,TVExHa`XEI:cw]?k2#騏#KTr)L^J%q~rsO^HCrkE aSFu23d55ad2e9a151a9642ec3eabf2ed6bbaa543c6af24cdda6577fa88a7464d1c33b74d3c20bff93a319cdc920bb0a7dc657dea826ꌉ\>/=„Ku+RG8w& Dȉ1YsR,4&Z=/ Dl D/<1Yamh`~9OY&zQC󛾅W+hj&3 ^'w큙?[hAWjQCѾwÄ !e6b/܀._rrsJ9{D]momF+AGFjD pscs,* ;Bύ9@5"A2hoH* :\>p>R?Rd # 8 +Oiox| ~    <(8.9.: ].FPGP,HP0IP4XP8YPD\Ph]Pl^P}bPcQ7dQeQfQlQuQvQwRDxRHyRLzRRRRRCpdns-backend-lua4.1.8lp151.1.2Lua backend for pdnsThe PowerDNS Nameserver is a authoritative-only nameserver. It conforms to contemporary DNS standards documents. This package holds the Lua backend for pdns.\=sheep83PopenSUSE Leap 15.1openSUSEGPL-2.0-onlyhttps://bugs.opensuse.orgProductivity/Networking/DNS/Servershttps://www.powerdns.com/linuxx86_64P\=3faea3b9f3d0f30de640154c1be419dd75e7ad067232d335abf7587eabdc8e85rootrootpdns-4.1.8-lp151.1.2.src.rpmlibluabackend.so()(64bit)pdns-backend-luapdns-backend-lua(x86-64)@@@@@@@@@@@@@@    libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)liblua5.3.so.5()(64bit)libstdc++.so.6()(64bit)libstdc++.so.6(CXXABI_1.3)(64bit)libstdc++.so.6(CXXABI_1.3.9)(64bit)libstdc++.so.6(GLIBCXX_3.4)(64bit)libstdc++.so.6(GLIBCXX_3.4.11)(64bit)libstdc++.so.6(GLIBCXX_3.4.21)(64bit)libstdc++.so.6(GLIBCXX_3.4.9)(64bit)pdnsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)4.1.83.0.4-14.6.0-14.0-15.2-14.14.1\@\@\@\[[[@ZZZЛZZZ@Z@YeYY5Y}@YMYMXDX@X~@Xx@Xx@XN@WW@WJVV8UUv@U>$U8TPTи@Tи@Tи@Tto@Ta@T_W@TR(@TO@TO@TO@Michael Ströder Michael Ströder Michael Ströder Dirk Mueller Michael Ströder amajer@suse.commichael@stroeder.comkbabioch@suse.commrueckert@suse.deadam.majer@suse.demichael@stroeder.comadam.majer@suse.demrueckert@suse.deadam.majer@suse.dejengelh@inai.deadam.majer@suse.devcizek@suse.comwr@rosenauer.orgmichael@stroeder.commichael@stroeder.commrueckert@suse.deadam.majer@suse.demichael@stroeder.comadam.majer@suse.deadam.majer@suse.dedimstar@opensuse.orgmichael@stroeder.commrueckert@suse.demichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commrueckert@suse.demichael@stroeder.commrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demichael@stroeder.comLed michael@stroeder.commrueckert@suse.demrueckert@suse.demrueckert@suse.de- Update to 4.1.8 * #7604: Correctly interpret an empty AXFR response to an IXFR query, * #7610: Fix replying from ANY address for non-standard port, * #7609: Fix rectify for ENT records in narrow zones, * #7607: Do not compress the root, * #7608: Fix dot stripping in `setcontent()`, * #7605: Fix invalid SOA record in MySQL which prevented the authoritative server from starting, * #7603: Prevent leak of file descriptor if running out of ports for incoming AXFR, * #7602: Fix API search failed with “Commands out of sync; you can’t run this command now”, * #7509: Plug `mysql_thread_init` memory leak, * #7567: EL6: fix `CXXFLAGS` to build with compiler optimizations.- Update to 4.1.7 with a security fix: * Insufficient validation in the HTTP remote backend (bsc#1129734, CVE-2019-3871)- Update to 4.1.6 * Prevent more than one CNAME/SOA record in the same RRset- adjust buildrequires for mariadb 10.2.x on SLES- Update to 4.1.5 * Improvements - Apply alias scopemask after chasing - Release memory in case of error in the openssl ecdsa constructor - Switch to devtoolset 7 for el6 * Bug Fixes - Crafted zone record can cause a denial of service (bsc#1114157, CVE-2018-10851) - Packet cache pollution via crafted query (bsc#1114169, CVE-2018-14626) - Fix compilation with libressl 2.7.0+ - Actually truncate truncated responses- Update to 4.1.4 - Improvements * #6590: Fix warnings reported by gcc 8.1.0. * #6632, #6844, #6842, #6848: Make the gmysql backend future-proof * #6685, #6686: Initialize some missed qtypes. - Bug Fixes * #6780: Avoid concurrent records/comments iteration from running out of sync. * #6816: Fix a crash in the API when adding records. * #4457, #6691: pdns_control notify: handle slave without renotify properly. * #6736, #6738: Reset the TSIG state between queries. * #6857: Remove SOA-check backoff on incoming notify and fix lock handling. * #6858: Fix an issue where updating a record via DNS-UPDATE in a child zone that also exists in the parent zone, we would incorrectly apply the update to the parent zone. * #6676, #6677: Geoipbackend: check geoip_id_by_addr_gl and geoip_id_by_addr_v6_gl return value. (Aki Tuomi)- Use HTTPS links in .spec file like mentioned in PowerDNS announcements - removed obsolete 6370.patch - Update to 4.1.3 - Improvements * #6239, #6559: pdnsutil: use new domain in b2bmigrate (Aki Tuomi) * #6130: Update copyright years to 2018 (Matt Nordhoff) * #6312, #6545: Lower ‘packet too short’ loglevel - Bug Fixes * #6441, #6614: Restrict creation of OPT and TSIG RRsets * #6228, #6370: Fix handling of user-defined axfr filters return values * #6584, #6585, #6608: Prevent the GeoIP backend from copying NetMaskTrees around, fixes slow-downs in certain configurations (Aki Tuomi) * #6654, #6659: Ensure alias answers over TCP have correct name- Update to 4.1.2 - Improvements * API: increase serial after dnssec related updates * Auth: lower ‘packet too short’ loglevel * Make check-zone error on rows that have content but shouldn’t * Auth: avoid an isane amount of new backend connections during an axfr * Report unparseable data in stoul invalid_argument exception * Backport: recheck serial when axfr is done * Backport: add tcp support for alias - Bug Fixes * Auth: allocate new statements after reconnecting to postgresql * Auth-bindbackend: only compare ips in ismaster() (Kees Monshouwer) * Rather than crash, sheepishly report no file/linenum * Document undocumented config vars * Backport #6276 (auth 4.1.x): prevent cname + other data with dnsupdate - misc * Move includes around to avoid boost L conflict * Backport: update edns option code list * Auth: link dnspcap2protobuf against librt when needed * Fix a warning on botan >= 2.5.0 * Auth 4.1.x: unbreak build * Dnsreplay: bail out on a too small outgoing buffer (CVE-2018-1046 bsc#1092540)- add patch for upstream issue #6228 https://patch-diff.githubusercontent.com/raw/PowerDNS/pdns/pull/6370.patch- geoip not available on SLE15 but protobuf support is available.- Update to version 4.1.1: bug-fix only release, with fixes to the LDAP and MySQL backends, the pdnsutil tool, and PDNS internals- Update to version 4.1.0: + Recursor passthrough removal. Migration plans for users of recursor passthrough are in documentation and available at, https://doc.powerdns.com/authoritative/guides/recursion.html + Improved performance: 4x speedup in some scenarios + Crypto API: DNSSEC fully configurable via RESTful API + Database: enhanced reconnection logic solving problems associated with idle disonnection from database servers. + Documentation improvements + Support for TCP Fast Open + Removed deprecated SOA-EDIT values: INCEPTION and INCEPTION-WEEK - pkgconfig(krb5) is now always required for building LDAP backend - pdns-4.0.4_mysql-schema-mariadb.patch: removed, upstreamed- package schema files in ldap subpackage- Update to version 4.0.5: + fixes CVE-2017-15091: Missing check on API operations + Bindbackend: do not corrupt data supplied by other backends in getAllDomains + For create-slave-zone, actually add all slaves, and not only first n times + Check return value for all getTSIGKey calls. + Publish inactive KSK/CSK as CDNSKEY/CDS + Treat requestor’s payload size lower than 512 as equal to 512 + Correctly purge entries from the caches after a transfer + LuaWrapper: Allow embedded NULs in strings received from Lua + Stubresolver: Use only recursor setting if given + mydnsbackend: Add getAllDomains + LuaJIT 2.1: Lua fallback functionality no longer uses Lua namespace + gpgsql: make statement names actually unique + API: prevent sending nameservers list and zone-level NS in rrsets- Ensure descriptions are neutral. Remove ineffective --with-pic. - Do not ignore errors from useradd. - Trim idempotent %if..%endif around %package.- Added pdns.keyring linked from https://dnsdist.org/install.html- Don't BuildRequire Botan 1.x which will be dropped (bsc#1055322) * upstream support for Botan was dropped in favor of OpenSSL, see https://blog.powerdns.com/2016/07/11/powerdns-authoritative-server-4-0-0-released- This makes the schema fit storage requirements of various mysql/mariadb versions. pdns-4.0.4_mysql-schema-mariadb.patch - preset uid and gid in configuration- fixed use of pdns_protobuf- update to 4.0.4 - fixes ed25519 signer. This signer hashed the message before signing, resulting in unverifiable signatures. - send a notification to all slave servers after every dnsupdate for complete list of changes, see https://blog.powerdns.com/2017/06/23/powerdns-authoritative-server-4-0-4-released/- added pdns-4.0.3_allow_dacoverride_in_capset.patch: Adding CAP_DAC_OVERRIDE to fix startup problems with sqlite3 backend- use individual libboost-*-devel packages instead of boost-devel- update to 4.0.3 which obsoletes b854d9f.diff- b854d9f.diff: revert upstream change that caused a regression with multiple-backends- update to 4.0.2: The following security issues were fixed: - 2016-02: Crafted queries can cause abnormal CPU usage (CVE-2016-7068, boo#1018326) - 2016-03: Denial of service via the web server (CVE-2016-7072, boo#1018327) - 2016-04: Insufficient validation of TSIG signatures (CVE-2016-7073, CVE-2016-7074, boo#1018328) - 2016-05: Crafted zone record can cause a denial of service (CVE-2016-2120, boo#1018329) For complete changelog, see https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-402- BuildRequire pkgconfig(libsystemd) instead of pkgconfig(libsystemd-daemon): these libs were merged in systemd 209 times. The build system is capable of finding either one.- update to 4.0.1 Bug fixes - #4126 Wait for the connection to the carbon server to be established - #4206 Don't try to deallocate empty PG statements - #4245 Send the correct response when queried for an NSEC directly (Kees Monshouwer) - #4252 Don't include bind files if length <= 2 or > sizeof(filename) - #4255 Catch runtime_error when parsing a broken MNAME Improvements - #4044 Make DNSPacket return a ComboAddress for local and remote (Aki Tuomi) - #4056 OpenSSL 1.1.0 support (Christian Hofstaedtler) - #4169 Fix typos in a logmessage and exception (Christian Hofsteadtler) - #4183 pdnsutil: Remove checking of ctime and always diff the changes (Hannu Ylitalo) - #4192 dnsreplay: Only add Client Subnet stamp when asked - #4250 Use toLogString() for ringAccount (Kees Monshouwer) Additions - #4133 Add limits to the size of received {A,I}XFR (CVE-2016-6172) - #4142 Add used filedescriptor statistic (Kees Monshouwer)- update to 4.0.0 https://blog.powerdns.com/2016/07/11/powerdns-authoritative-server-4-0-0-released/ https://blog.powerdns.com/2016/07/11/welcome-to-powerdns-4-0-0/ - packaging changes: - remotebackend split out now - enabled experimental_gss_tsig support - enabled protobuf based stats support - no more xdb and lmdb backend - added odbc backend where supported - drop pdns-3.4.0-no_date_time.patch: replaced with - -enable-reproducible- update to 3.4.9 * use OpenSSL for ECDSA signing where available * allow common signing key * Add a disable-syslog setting * fix SOA caching with multiple backends * whitespace-related zone parsing fixes [ticket #3568] * bindbackend: fix, set domain in list()- update to 3.4.8 * Use AC_SEARCH_LIBS (Ruben Kerkhof) * Check for inet_aton in libresolv (Ruben Kerkhof) * Remove hardcoded -lresolv, -lnsl and -lsocket (Ruben Kerkhof) * pdnssec: don't check disabled records (Pieter Lexis) * pdnssec: check all records (including disabled ones) only in verbose mode (Kees Monshouwer) * traling dot in DNAME content (Kees Monshouwer) * Fix luabackend compilation on FreeBSD i386 (RvdE) * silence g++ 6.0 warnings and error (Kees Monshouwer) * add gcc 5.3 and 6.0 support to boost.m4 (Kees Monshouwer)- update to 3.4.7 Bug fixes: * Ignore invalid/empty TKEY and TSIG records (Christian Hofstaedtler) * Don't reply to truncated queries (Christian Hofstaedtler) * don't log out-of-zone ents during AXFR in (Kees Monshouwer) * Prevent XSS by escaping user input. Thanks to Pierre Jaury and Damien Cauquil at Sysdream for pointing this out. * Handle NULL and boolean properly in gPGSql (Aki Tuomi) * Improve negative caching (Kees Monshouwer) * Do not divide timeout twice (Aki Tuomi) * Correctly sort records with a priority. Improvements: * Direct query answers and correct zone-rectification in the GeoIP backend (Aki Tuomi) * Use token names to identify PKCS#11 keys (Aki Tuomi) * Fix typo in an error message (Arjen Zonneveld) * limit NSEC3 iterations in bindbackend (Kees Monshouwer) * Initialize minbody (Aki Tuomi) New features: * OPENPGPKEY record-type (James Cloos and Kees Monshouwer) * add global soa-edit settings (Kees Monshouwer)- update to 3.4.6 [boo#943078] CVE-2015-5230 Bug fixes: * Avoid superfluous backend recycling * Removal of dnsdist from the authoritative server distribution * Add EDNS unknown version handling and tests EDNS unknown version handling Improvements: * Update YaHTTP to v0.1.7 * Make trailing/leading spaces stand out in pdnssec check_zone * GCC 5.2 support and sync boost.m4 macro with upstream * Log answer packets only if log-dns-details is enabled- update to 3.4.5 Bug fixes: * be careful reading empty lines in our config parser and prevent integer overflow. * prevent crash after --list-modules (Ruben Kerkhof) * Limit the maximum length of a qname Improvements: * Support /etc/default for our debian/ubuntu packages (Aki Tuomi) * Our Boost check doesn't recognize gcc 5.1 yet (Ruben Kerkhof) * Various PKCS#11 fixes and improvements (Aki Tuomi) * Several fixes for building on OpenBSD (Florian Obser) * Fix several issues found by Coverity (Aki Tuomi) * Look for mbedtls before polarssl (Ruben Kerkhof) * Detect Lua on OpenBSD (Ruben Kerkhof) * Let pkg-config determine botan dependency libs (Ruben Kerkhof) * kill some further mallocs and add note to remind us not to add them back * Move remotebackend-unix test socket to testsdir (Aki Tuomi) * Defer launch of coprocess until first question (Aki Tuomi) * pdnssec: check for glue and delegations in parent zones (Kees Monshouwer)- no longer ship dnsdist here, we will ship a new package based on the snapshots from http://dnsdist.org/- update to 3.4.4 with a fix for CVE-2015-1868 (boo# 927569) Bug fixes: - commit ac3ae09: fix rectify-(all)-zones for mixed case domain names - commit 2dea55e, commit 032d565, commit 55f2dbf: fix CVE-2015-1868 - commit 21cdbe5: Blocking IO in busy-wait for remote backend (Wieger Opmeer) - commit cc7b2ac: fix double dot for root MX/SRV in bind slave zone files (Kees Monshouwer) - commit c40307b: Properly lock lmdb database, fixes ticket #1954 (Aki Tuomi) - commit 662e76d: Fix segfault in zone2lmdb (Ruben Kerkhof) New Features: - commit 5ae212e: pdnssec: warn for insecure wildcards in opt-out zones - commits cd3f21c, 8b582f6, 0b7e766, f743af9, dcde3c8 and f12fcf7: TKEY record type (Aki Tuomi) - commits 0fda1d9, 3dd139d, ba146ce, 25109e2, c011a01, 0600350, fc96b5e, 4414468, c163d41, f52c7f6, 8d56a31, 7821417, ea62bd9, c5ababd, 91c8351 and 073ac49: Many PKCS#11 improvements (Aki Tuomi) - commits 6f0d4f1 and 5eb33cb: Introduce xfrBlobNoSpaces and use them for TSIG (Aki Tuomi) Improvements: - commit e4f48ab: allow "pdnssec set-nsec3 ZONE" for insecure zones; this saves on one rectify when securing a NSEC3 zone - commits cce95b9, e2e9243 and e82da97: Improvements to the config-file parsing (Aki Tuomi) - commit 2180e21: postgresql check should not touch LDFLAGS (Ruben Kerkhof) - commit 0481021: Log error when remote cannot do AXFR (Aki Tuomi) - commit 1ecc3a5: Speed improvements when AXFR is disabled (Christian Hofstaedtler) - commits 1f7334e and b17799a: NSEC3 and related RRSIGS are not part of the dnstree (Kees Monshouwer) - commits dd943dd and 58c4834: Change ifdef to check for __GLIBC__ instead of __linux__ to prevent errors with other libc's (James Taylor) - commit c929d50: Try to raise open files before dropping privileges (Aki Tuomi) - commit 69fd3dc: Add newline to carbon error message on auth (Aki Tuomi) - commit 3064f80: Make sure we send servfail on error (Aki Tuomi) - commit b004529: Ship lmdb-example.pl in tarball (Ruben Kerkhof) - commit 9e6b24f: Allocate TCP buffer dynamically, decreasing stack usage - commit 267fdde: throw if getSOA gets non-SOA record- update to 3.4.3 Bug fixes: - [commit ceb49ce] pdns_control: exit 1 on unknown command (Ruben Kerkhof) - [commit 1406891]: evaluate KSK ZSK pairs per algorithm (Kees Monshouwer) - [commit 3ca050f]: always set di.notified_serial in getAllDomains (Kees Monshouwer) - [commit d9d09e1]: pdns_control: don't open socket in /tmp (Ruben Kerkhof) New features: - [commit 2f67952]: Limit who can send us AXFR notify queries (Ruben Kerkhof) Improvements: - [commit d7bec64]: respond REFUSED instead of NOERROR for "unknown zone" situations - [commit ebeb9d7]: Check for Lua 5.3 (Ruben Kerkhof) - [commit d09931d]: Check compiler for relro support instead of linker (Ruben Kerkhof) - [commit c4b0d0c]: Replace PacketHandler with UeberBackend where possible (Christian Hofstaedtler) - [commit 5a85152]: PacketHandler: Share UeberBackend with DNSSECKeeper (Christian Hofstaedtler) - [commit 97bd444]: fix building with GCC 5 Experimental API changes (Christian Hofstaedtler): - [commit ca44706]: API: move shared DomainInfo reader into it's own function - [commit 102602f]: API: allow writing to domains.account field - [commit d82f632]: API: read and expose domain account field - [commit 2b06977]: API: be more strict when parsing record contents - [commit 2f72b7c]: API: Reject unknown types (TYPE0) - [commit d82f632]: API: read and expose domain account field- set $LD for now. this fixes the configure check for relro,now.- remove custom PIE handling. upstream does it for us now.- update to 3.4.2 This is a performance and bugfix update to 3.4.1 and any earlier version. For high traffic setups, including those using DNSSEC, upgrading to 3.4.2 may show tremendous performance increases. A list of changes since 3.4.1 follows. Please see the full clickable changelog at https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-342 - move man pages to section 1 to follow upstream change- disable botan and geoip on SLE_12 because of missing dependencies.- Fixed broken _localstatedir- fix bashisms in pre script- update to version 3.4.1 Changes since 3.4.0: * commit dcd6524, commit a8750a5, commit 7dc86bf, commit 2fda71f: PowerDNS now polls the security status of a release at startup and periodically. More detail on this feature, and how to turn it off, can be found in Section 2, “Security polling”. * commit 5fe6dc0: API: Replace HTTP Basic auth with static key in custom header (X-API-Key) * commit 4a95ab4: Use transaction for pdnssec increase-serial * commit 6e82a23: Don't empty ordername during pdnssec increase-serial * commit 535f4e3: honor SOA-EDIT while considering "empty IXFR" fallback, fixes ticket 1835. This fixes slaving of signed zones to IXFR-aware slaves like NSD or BIND.- only enable geoip backend on distros newer than 12.3 before the package lacks the pkg-config file and there is no fallback to finding geoip without it.- fix permissions of the home directory- enable some backends that we had forgotten: - pipe (main package) - random (main package) - geoip (new subpackage) - new BR: yaml-cpp-devel and GeoIP-develsheep83 15540710134.1.8-lp151.1.24.1.8-lp151.1.2libluabackend.so/usr/lib64/pdns/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Leap:15.1/standard/11b25228fba60f5563817db73a652e82-pdnscpioxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=8bfa44e0607ae4ec8480485c9020d7187f71360d, strippedPRRRRR RR R R R RRRRV )butf-8cd239de5b26ed951b7773997cfb878845845d43e971a3c0f06e8260180e4008b? 7zXZ !t/[I] crv9u^}}=F tǨPQVWuJoN~$O`N 0\ 2H?K 8'O i炮MTz:a/U*W;}:/[miZ9 AVr-Z }e31 #}'ƭI)i?|OXi[Ÿ?%[=X&f'<`j_*tp>7ʉ %Gb'˗FOnӓ@w{ 04>kDJ!s!&x9:Z2м፸A@] !K׻,sz1k9WKAT,)uw#X1dK`SFz&('T'`~i^oAq&eebȶDw`=Ah 0ȘzދfE }DFaA^jY p~OEIitWH jfps~G'/sAHQX t+3]wS9p(Ť,"#438l+8iNOK"j0ìDl!GPV^$pw!" NP~&S{ڼNlM,Tl.{ XW(HgzLǁG!Bp Xi~TEPnsϣ\8]]>KyE. 9+m͸8Vx@:6MS8}FoOM`ݜ<"=ɓLڢA‰qGb| ?1noBV O :'Ȳ'\P-&ëVvB_A)*Ŭ1a$XML*"2D`Jc~~Jv })i&̲9A{5!=888 ϸGD%NC^wp1Q1ơ \F%4wM)GNcW^5Ϭ^D?tS0 N II))r47P291:}o=$6)w~M!+ $ӹ"l+'nҭB8eYn 7BȽ_ eL ˙!O2z,&$Bbzɷty 3 FwFd !+#pt5UӬ1=NT n;yhK L"0z *@1c641?:jⶏ0GDC s@BGbEN%@xJ a/З׿!tiC\@'Pi9\%GՍ%ft:a Ew S˟5y*9tI?U KDrp/{xWGPwW'23PxyTI&Qy@ XguRt+/R;>Ӡs=(!^lsP efQA`"@ԀL[FxEuHx: RGSSP{V)ȚVGt-yyP wa3=4ЃAhP?kv5pQg",[;fbUvfe\Lq1x(ϯ=gإi$$y"\l9|",Nbx<Ցj,J3-7 fn+/V/Mv5呩: Б6@.V&-$Nk4tΩ.WuB䖟"ysH`>iy !dgM?({6#|.;%}>0(Xo^)!-U#HYsR6O'W0Tx02\,TsO ;,$;Q.3cZ ^c]/[(mp( 1ȓcWÕ#' nA6EU6K-@vXDgAm+ &%6cmjqEdPY5w~cgr\j 俸=̹q- xp&g+KלKLG=Zد= 3z[k㕣C\ͧ fpc% :-fb UWoivIP" 4#r?xEC{ᦐA"L'W_۔cgiҼ޸)H.3T0 ?͗?H9 U=a~Bβj\atJ"WVBtyg2eG2W|M,_Q9j~ޯ# qByء.#G{\wiV) "@HMJ6\d0x[wGdPj;!jnw-%nݦ ҒWU$0\M)Ǯ[܄+NZ Q ??gmDU@ )p4ć#k8jSR=#cR %q4;)OT7"Ì.mfy}Y]~ό`Wڳ0k`a9ԕ<9/͜&zEV#*qy*5[~פ@;jl^8WjP璹+Mf Sڣ&MJzݵ% R$H&JMYn\]^#{*ˌ۠7;-/"2P&GLw++Ҭ{ZCnU t(8݇ bLےxw89O^^eN-YR"%? v) ZӝV%=o x2%|Z8.m̶'[|#3K FZۅmz ^@ój. Ւsvm*ki6ČhwH{7g`JHiZõ5?ӨZ%1"|!KTzW圸3%>jԼcIrOEAYנ=7Q/bD6TK F&i%Jk|cg.fDGRNN5͗0F [a F|[lU,狤36LOUܣNMsV%GLι1a=6 p&9@*m!)^U"bRYCۇ#*:E5 Wڢv('ܫ^#&fP~I9,4(5Ȗz.ָ]gj1@4e1+]\!Z4p,&9s&nŁSo;x' Er_<q~w#'`d^JW"bMРje' DDzُt#<.3Xk+7@:7{(v!jj{IcrnE+~{ai[S(XyX|㉹Dgfَ֏*В wA%:'`-|5}U;7}7ᐈPr')n j~+tlզ}.6E:qߜSiQg`I1a2GPF[V V*~–5.GF-(^^LIZ/O%Nn^J#mERc(@'xbg&A[(ym֔/K^t?m2C㿺A4hh %Y|H2h^e6KطJ^GmkW 8s?ɵ'rZzWJJh-iID}ho Uvd %E63GhPbfx?5@=˛3M`δ KQ Hnx1ucXH 'wNb;-usJ )XfʟϬ ?W? ik7u*լ22ek|FN<7\/oOh'Ϗ15ͭhI_`X]gaN[+?S ̣de´w+NO7f͊fVWJ*t,}搹3.f1@f4sI ivcE]5mڥEih(TW[fZJ1QЗ Iai Э#=n Q_Y؛/jzp0@BFY0No)c#E])o}s4^CE}BRVu_nQг۴DJq0~JT)ia}Um , tviCu8^/]5`gYXm D~ 5ƣ4:sm~m'BfjzoN2ӕnUJr Ǣ*}qc&\6a⡶,YOn[3xr.8ܘtFuvDF)Eĸ,%3`Im:: ʇ% q%e.pGrG|@+CՑ?r*x&qm~ '+rkbʯnT%]vYD_a2#!&YYÍ`}v}t[ |fd7aBf+RJyAW-uT=~IJڂ` c1E j)xuϔ22]JQv eПIuD5XS}1 *?|'*+J0hh!硫{^ft/H}ƋNe.J t~.ힻ(Y $ZwV JCv秶k(a;IR|vHgNeld4AIq݁4t@b?eR,^ž5D6@ק7HQgӀ_R 7rŃ_%#!v|+I,(xKvL^r& S3.>գ|!3<t2i' W<_:Ph9,J8/pavNNЖiZn0P~Kս}aׂsq蜆%PN4EEBSY&!FlYMzƅ灸])hC -=Aqp(!]{ELڇ"3T!чzWO˝m\@w:Ŏe_cWFk.B>-+L-bA;cbf 穾K|9c%d+fWffd~qi`hLZU V S u{eS[eFȱ8 ާp} ,| J/#g-+t@ּ% wg?CⴝD[Zou??uFFuaE!!>tr:#zʛY&AhZw :O8>Tx?L!_~who%ȇ#2Pk5$Bydؤ cw:mԬQrLӊ%uQIj)+l-g.KP@5;~ cv9 6X+qs Om8ީ?쥾wd+qRN(1Y:-@b;"odU9WqWRm|kϋ,8W@(z j }ϤSyNb }cH}B03peD|LU<մOY܄;Fks-ڼ^2tB\ӎHFn4IXrAxA]yyMK\Imr@2ޑV#lܿpE޻gNGDJNᰒijo4r0IOwr.Z19&<;Z;/j9$*`p@?g "I/a^^Hg)E!%7{Qæ\e5 *zgE$H-pcH"dc?–`$J=3 RR8hmyp_cB/吸FeY4r.z 9B_s_qIW.)Gwv 'yJң#r{`-x]^Tqr> Uq<2X֤GD0%BWV3T'9ncN5WңHFy*sM",%/* "|B08N{|9lA ~[c#%e'1IoZV-zmO%GOiF+A8A(E\GRV>qDkdKڄHCQWt_2$Fh&2.X.wٮIߤp$hc}iH&DԾ-f0ޭ'ddhe ,]4H4+$ Iu٬5)nEo\!v2NF\JJ G-!s{&l_ogčrb;vT`q!ɜnF 5['!YR >gcv0y1 bViӗ5{Ld\<'`iͻ^6KR0('q91SD=X6K h_q|2xO zz~/S%i4$A2egRD|` '.Q|zr=vk vI> LuG#Z"@#1]]+i݋ McbPQa9}`ة&g9ֳYѠ֦kFn%wkJ,,Lʒ jV*БT &;fV+6WdGM*ɏ?r Qm# HTgܡjXs5D_R_rx|+W˾nnt:;HtJJ(@S'clS<zӾS38V]0dC.!{5"ʱ RQ+oZcʾa:o*P J A@HdG!,l44vڄkAfEv\Ryٽ΅Aԥ4/ظ=sG*si͍lS?@^bV[P/?U/.8++SQs9I6ۂX8̈́ۆs*x0&o$!;edKW6+ PR/r2ˠ֡&p$#} <sGL]*l)Y9nX-x@b~$ o؍pBQե8μfkq#`][1P^O9W~c@%A \c /XojQ]C#"!HtmK#jo$ 5\忟:-!-5 [xQ,ЁdRoC7aP@+NL ݩcԗ:MXD1w0;FT%,p뻃_%G NbḾ{ۺ?-G 0,EJr5mV5JVT8Ai :MiiHWkǦ'dS 3ek@ NK¤g@!㡳kw6AX,Itsjq!Z07] OS57|р.2UbCb* mEGh^>W`:oG $Q jCL?Q715-KM;dq=Nհ4mrjǔn ;6N^Nn .sNE p7-_󇥠46I^}d֢ϖ"޻!?=eUWͼ iA$EBj}pHKق 1nt)$t+;E-enɦ3d\t5ϸCU ,k?l-#jقH6aq?; W`#UfR{MKrM|(5 a':nL7;/ ĩ‹-) L^&p+z'_^k['v淭i!5A[xU58lkyIW1Ô P# 67wQ)$}:T[uNi+#:Y?@̮z6ܔmma)HNmveu !  zz7躻_i|"mf?]u^m0îFC v9|QE.a];8'ߤ;n}g RNcDDmךC(|([eXK߻>uAQW#OW;@* /z cͦ+>UtE<O3 s`C> ͯrέܶ :!QevG{pgpwCK 2af&OMϔ+zM4=B0Ky'ݽPpi+]]}GjJR[AYh>S9u+]E[/}9Hs^o7$zyv2$$fu]즃B7i]ZmKʲ㑗)$L›;@oc[ )5Vf͹.%ՒL&W 5M8SQh2P࿲Po]:"=q"*ȯv<]ۄX˫` ~ۢSy]|TBj0 iG;ޠ\=WBr $Trrܯ?>esjER3s:չ?2$^Ȳ]睉 _I;l4~ȱjR)ʎS}਑k ʔpBRe3.g[[ѱ@ϲ IEYntk X?+cݒ1;/giUZm>,Xqej#0 E4 }*J@xp^j];q +']I*ʭz/=}X򗝝՛On>V) VNl@6Xlݙq++IEL9Rv7'oeɥҟyg[ SHYq;Zq`D?Q,k% 3[}riPMQذE3htC0EEt[]/j[MrnFD,,Δp5 a9#9VeiRC¬Z'YWD( C\l?%̙ D Gda S.}'Ateis'<ϣ<È/^pF`$ũ%p?TIȜ4I,H15L"o~T8%ؘڰ d$a13}TV<.lYdؼN䍐wR?M}O_f24L 40+qynUqqPj 9>>q0++fsWb 2hIuہ,ci+1$u)ɔx8 hXQ\6t?V֭C/LGߍI^6F&;MGi ҜhYCBnGqr՟#-FcI|M!0fX}3H,Bt#S/tC}aD8z`FLZxpWOOo-B=3TZMaL!l2 #JGi6 ]x>ugX3.7X_wM9IѢKuo-p0-EcpGR&HcTf^K±A?zDyҒj|GG+t)G,2pxGjJ PKQ2ɪ.>٢؝1z{c{`V=7hgI""+kkR2A04jjuVb$q7!Ҧeh#^ܳ2p.T棉$b\//O{hto8zy985g?8ms>64k5[n{:G[!\Dz z$iI2_W?:Qhsʵe*0vJRҊ>!4͙2j Ο׽>1"9b{-Dk?7Kzs4,NRch5U$tV$[OabclGEQl5aԉeJzpK;-ǹ}Yca9^51l U"z"fK⢥|>zj]^XdO "$&{:+GyuueVmAGIźEqU\c&M'!X%|~ꯢ&{q~/us_ٻ9J1bV=УmF(\ttM+zFdh7kJoZʂSfx\G[-ؑ+"qTyв 7z=Lt\׬<7۽,vUp[עZP7<` j>xd/#"Ϫͬ D'%yӛ.a=kq<\m97rl?~50-ZVq<w]o?- llвĩ r۷ #I$TO sx\$gy5"g⮼q~_IUT6+Re ЙpO\˰Q=Ե|$."jzAl *n+khFL".ÁNs\¨9 ܿn~oWummq4~ -; s5O|e%! Ԅ-w_xV_bu\!=<3׉J1n{V6zs Z!j{eY!8u'q7Chm$ `5 Gqzwsչ>kvθ~&urF2v9?y+4B uآ&[%gȥ'˲sP5#NXQf?4{n%L@]Tå٢)(Mrs/?_nmǟ@3\{NӉ(yY!7@D 82R\L8>!=_nDXEi]@ \_dew5cޯXf]E?|-kkS=-f @mnGD9jz `_m&a}>aR2PZL];9+ǟ+߁O5dc߬BXo{Tֱ5,A6׶ևMU{Vx .9}~:ȹ0BrQP#܈Kq tBݷ0OJ8D~QȴjH }#doj]Q+3u^MN_~9q-\st0y&1MwN-yRs+5#fG1j-TbHʼBBI鱢~OD (bT;WJZg"ٴzݑ2[sf=R*vOz:+fh;egr󨆫 5dwl-8HYK; ٦tP.5Qz wN<߷N]bW4@owl3fVW44BA'`ڹd"l2 _4i+$`fSYKVc&8dy.Q/!dER/<3 ʹn$~I36۳1|l Fjv7˔ϹF-0 /[C,*k5hDضؙW/OWm[ΠA%<*&&&JG 5'LM{n)Fԓw.`4rJ;Fi]iq kJTex ;Klvq)/cE}h/PdSq<"V<3w3:H];6nÉY\ BS}?9Z1|6kAQ{7,gӞ|U<GxET^< (SU͌SXƻb!U6sm1ـO8.jKg 7ͨ$Iǭ;Ȁ;>:%zC<ؼ1c@>`DKs\nU)l^O }mbrG$.-/,i#F:Ѻwq]G>Z;z nA,r0*v2u hPS+SOnbrSoXXUX}mV: u>psdcR=:Q:s>'aP{< g6QZ[gK/ `R |y( ōMAiH*6F*Z{^Nk(JHLF.u7P䮅fQ*hTxdb!a[ CAګy6;H4hORުfuQڅJC2@ G8u.pO4JV R(Z/F.ߘ6I&sdɚnLGO9b䆩lWwb\oI>eߓ-us$hcF#^t* V6+4:Dg BNNLUE">u} X+1[?»53r:Y^xS _iV9`pƉ7+~/)}a`wH4-hz1ǟs;(MThݡ~BOSI>MGIoz55h̒". XM:ɣ?ԥڟ18GZ5qHWD.6r##{ڪI'=a#iv<r#̜ZAmږAਓzTXG,uсɜ~UJثY> /Wމ#yHH}gHEYutK`:ðyigD}k5B,DPt+)0뱒@b-?_K92pKBdUБۿ,g><׈ )=ͷ!g%[`4乾Z`2anG&ޔ- iF~sexQAtf68lFah{ o!^[R&UX J$Cb+UW*!9rŖovnO8sp0TZmE[%pf2ƒKKVM{H_L3wfMd]}~E3S\` KV:l"Bn|NbqI׮QgJ"^ JLpF?BH 02#++1_PU;,mY6Ȑ6<6C 89z &JtyьݡIz_8gbo! Z,H~cg5ݙ<8|Čă"v.u%: " bQApAQv4!wX mZWXR4&Xs- ʼn!R Z%k+[bqQBQ,pA"Tׁ$P:T8x͡4e8b4a$!ҭF… UMǚC)Utd47P};~CٲoRL{9nWzސ 3v p&'>ВhQ)G/81Q*׭7PSATaƲ[~Ő[9BaUH`뤷Ur'kl}S qZ:, !1 qr(9S5y*^)"S,'-Kn+t<1&+YWX Q Ud^N +s<\$1ȝӕr#މ{lѨ`JczKH+ȺS& U)V P9?;u/ ^4p׏C23/Pv&1Y"k҅)f!=*,6%Uz8i򝌪s\l7d/$JBM4~/()vPFံ棝 eȺlKmZ__ƾHF%M9b n}}Ok֔~ ]hY21n;g9  }dx\XZpVbP)e%֮vunƜ@ՈUdY&_Is•=Sx!bD2SO1+$ajy޻ r%qdoх4Olfk%2pnr$:s(򯫟9[}^Eq kLY]2] 3=ncXUw:QMRYH#\9% غ ]0Γu3_Dam2mkϗgyFawmby T:|ͲveD[>޼ 'wyݣqQ#K-)]sg76ss!޵멫/갴M."ydF&t'ڹk)1t9g @w$,]ۉts.:LZ9:\ 64{\>0ϛ_wGuILX[F(.&t*x`r̨>Tf]YyU7Hg6=h Uk]B~C0?1kG[jW MJnt!y_9~Z]̀kЀH3ƾOښ w,aa'nQd>MT:xEcEᅮ+)؂:Lũ@q$[%ܶWGxP^D}72Py*2^X**hyI.F%Bio$\Ԇhz~Cґػn}{(NU탓&DD1FtHr^6 ŸMc0p4 XY/*9:ِct(^>'<ѱ/W.>S0]Rˬv):̀;s n KTf|(S#7y׸Cf';#Р3ݺ?]73ASu%RaCΚbʀhʲx[)ȴJsgs0ӅS9e)#гDrN{wF!-ָ\5&s0%M[*#b31fE1[e3wkỲ|-D\e迗qUߺ孉UI>moiTƱi /&W\:9am`NwAS ) +V9a3~voKwD^گoGfϫqijT6`~JKl8U6n'Qe/)!bH J#[H젚2UUǝ6cx*F@ kNx2ҁW=|p uN-J yTEifb~_\K_#?J8 3SrAYmiJBV4"R/C,_*?Xzde ~ӿrTrQU }$pA8D%7O_ +Y L%HkS"O1?h"eO2m=ҧ5#yq2k 0Oqr$|.xYܜ(/9.&QK{_@-m\X~yRMI\&<Քr92BkxZ@XNh1}n@xG9'|!c_YnlCJI]+4gOڍv9[!]yMK 9F+WkDhyZn=0Ƙ43ssl/} _,n9lfujR/euuIIԿtj7YkX MhDRX~#:7e=DVCxF*bh<&$v5DSXDp{;>E=OcRi T"p0j*+0tyH9PePnjCqʔGl8g&YQ2| }‰s/$N7%oMQB;sOK1+ESsO 8t<:.̼_{h2V6(i?>,%k; 5*ΉҾpH͹ ,e`jzE:"Z%S!]z&֤of%\SmlQSaSD&bRqxLLQF {>ד|X 0jE!^;F00R&O8^Pf'ӑ@A׮ynxy9RF—g|ABFpVC~zL{|hZVm6w};Wq*}=+Ua_BՍ.h7T@tf_hCf_'Hv=yfV*yTyO S=){bJ7g5 "h7Yxa-C8*ޚhH>/HQHJn@n ldwj3|@F{ܙs$i]Bh1WY6;oi|ޯڄL&A=2bxIq^|콅bL=b0>zy\] NL|-SMo6R8[kǬ_o/1?_|QC^C;B 1 Oغx'9XN9d7w@8qaW])wdFfnvX,S> I'-m`o#Hi@-_-k(O W@QRyB7AbP]X|? ۬e: O]ٸK s}8y@Y~'HD:Juv?89ӭMMۘ0aebXeS/1eeKi$q.鳁U(LEt^dw\ `7!VWQ N$mEѣ"&i쁼ÙpΙyʺ$;+dQ2򏠿:*Pen_*G0 3bQK÷1(l4[oI":=n!]8_~'mn/~qNWmr'2(&l;uy RÁdשRpU_V'RoH%{:xEqZ MgD1G `YnP*7PFǵ˳n=y!J%?Tqwv#3Iez{[)>uƕ0S(Rv<PE T!|16;˲ x6 Z=AP <)ޥZ F7SS,sF$M_|v 1/|K] *җpUHOhyq#(`0^{Ӛ=v B/ (R<'1##S꣥0-H B{>Zbۗ9@GR`Ж-VU&ZЧ{6m?dT=QtO2WGi_&&jګ[ʆ ^G$OHfY`n6ISa@a"DvH{lz\8~604Q[ %3C([D_X&qHp~lբvfẮH5`O2sf6ֳW!%y-,Zn4bP~ȊiJWwl6&MJ $@lÏ)\@Qė01E0EE2tƾ;q6~T.IV$D|cDsqjh {N{DS8TO DTFA gvSlh(ZZ) c3్Q.W' }-ߥ;VV%TO_\Zg%N6qE94$b;Nd^9wPKJ TR29"J/y8~źJZR5q?6@睙 EP r} aaԢj&0[A|I.vڎ#ͩ0M[J]{,&wy˗Bڈ4n0Ԟ+ҡ&ڊ|C(\)ޏ.-*̹gOFGE{B;siK w=Ƕ +I;Qm/ۺȓ'#ȇOT ̴&t޿ LD'K Ƭmz﵊^rhM:U&(g.ݯ[bQ)>DyH"*_fT乆[=WqO/%V o-Ujѭ03Ϩ/UC"|\z8a2۠cS@ZuԱ蟽'|9mJ|eHcGC|47yLd4ϛG3\lx+b͂e;3B!oX)J)QT\{oy`V7{rLf3D1#;8@66ɣXޮо)k',Ҩ7 VܸBنh;8;rH;D<)5RUh;dW~s]R= ضIzhAWb e*3 QKRKi UEEWi[[Yk"@=kCկҠU~ >.}D9r}W5u뽟'{$bO]ދqUf~=?Q1Bv&mž"%am> J.7L<>׼:}kE>8ґ"]FC@jyKBXp-׆ ۱"1T^"k՘0Ѯ0g>9W$8ـD>{$0"DwyW*b`JNs^ǓM47ڡQGj;]~*ZZoi&IF̸aa3Dqd墩22:S7o;L @;Z;!8hdBnVT6v-0Pƨu`ڌb<]ZlJw^\%\1E6mcU"DSTf|eao W@0/7w B#H?tlT!`7lI5 bs+#*˼ŸRsƢaо?Mdѷh7$z_!#u#2c'R3OYz tY|+l+əB0ACc-"PB8pb!-o#f a$)a܌Z"EhP܎K,aΒl҃%x,~^P!Ѐ<_Fο^u3CLGV0)./!nsEX2=)4ۈOb\1@^'#ECqu*iDŽVb&za7Ul+Jw+mۗ2{*~Yb o̸K&B`L>9lms^Q-t8zۚu*)? /QDF=gS/mcXYˆ7*A{J@%0I Ck._h(4_&֐s AtYQAM[^,V(<&1#SNaD_%,x"ו"MJ[TVuШ%I> 'g=[n@u5"q?2@~E7$:ju@e!TS1X ip aE=  ;@OB辿櫍$`=$t]S499;45_ItSUJ%62 FCXe^(vrjsmV7:+ ȕl@nCƣ.5*9~Sjح`f@* FRC8y1TOI *h<ݦ1}yn]#-3ӆ{eq5۔) @ES#:8uqsu*.M[CɆQsd G&VP%I[bFߩ}t[l$fOrH{lXl.Q#Wmcg2Q:#xcSc6? >y .PJP#rSN]o؆6]7M0ДX}ovvG]- ӹgL3G>(s QWV#gltrL0x/ir 2e?1;Pz'mdQ&/" pK녷+w߅{TI$tj[B2QrNn 0dVr.ƤkkC!{~xi9%='D}khtj\Ses`SjCw5<3r>A\ p~/bf?xr54nTEG I{)ׂ@)JGIFӇ$Oӏ2LGz-+Uwa!KQz8G!:!*F[˶iy4|<m51Ww#U "TߪDUJbk p1 .EuPG. ss 3^PxְzC*LJQSrpzKe ϦeC>:Ǩ5xZ'icOB1۞1ihy$,e~f~|~ J~J4 SN HF+ChƅID6tn m0;Ht "yPQQkEus&) ay TժuyCB ?E\i &JKI1GhP"-<(1VEXjUSu5=! t* ~:u" 5:m/H5t-72Ԉd%"65j=gDQpi#;⿕2:1lWOr#tݖ2q'TZ{dL)Mֿ?~%_j)-I bPO?b ."0g74 /[r=-fseɚ*O PS Snss0"&e$jDonI 'k=x1S6+zP]N=r,K; NW\A#K~ ж#0DB.@91~ m""hj,Hr}":3;Mr&29}0$֤fir4JMI+)̓pǪ_qs-(5DZF9ٮ8Xö7\ICiiL21b[QP4A\n|Q2J ؞ dj8W-.~j98B$V^ex! fWj`|Ǥ>/=c"x^p x)-0`G:lm#u}yg WM# c'xA ],EO)/\ѿr[wTW>"vM;v?5>R5!S%1vm09+8FDP0ݤ/\t&*/GU |c?p=ܞAyF[ۺ9wIyΑWbce"su2K gȒO>z6}`K --"I@:(9y-CF%vaHd~+C(JVF\T8C` 6zoh+|Ҧ ǻ"fAFY zǸF\2 M8S>bWzVYcJ,uT۩z4esآ̆RNA~o7U瞯剱Ut PĎEl:iTag6N~놵J(Ҟ}BrP A W4k\qE+SCۥ+4&sT"+UFJYq͕uѰE+IDRnddd^ȊPh`AfENCK[zXB :҃Y"7\7@&F Opboa=sy8hThkk UY6xfC^~l&%#bxaؤC qR4kPppʁrٛ }Q 2G G:ۓ-ćW"eϣH ^xJi^DM>Ee)?W5s/{T^I="p dUe_dV,p92a!㉄,<6;ؤrt@ѽh<oEuodnI_RQs1KV931v(S>"+|gm>y#)i)r4h(p lҙwc.)+ F%w !Xt*@J$,J)~[^_B.)"%',[|t0[XXнϧ꘬EZ.+/ w*\ yαwis(cT \D&dB}a#?:"@k_-a7e6u! 6U!8>HYn Bog;OCQ$~ߐay["C1!wfOz埆B&cO -6bxͦxj(xe݊c˅MuXIoQ995 _%|ȈK^9)!W!k::U6$h̔WioIZ&!qԋ O֣]30ąy'Jx6)$,|,DgθPmMk44݊Hdo9~1KELVsku_{!at..__ L2 IϚ|BG"B-WKgWNlI}.U&f$9t"V,𾺂7S|pp;*N` GWT{27G}+ çx2ow+>yf'7fxvɔb6Fe(xiE{f"]MDQJb~uS*{~JMX0ikͿyoCTN%C\d#[Dbe JCy[(49^?{6v` PRWr%'OT'Ẕ# :_N6p&(]կ+? e\*xaNuTՋBL;.+,]ބ!̵db3iUt®kh`őrڦDiPI"M(+G[:. 5uS@='pޑk) ϒG0wO8,j>9.0p*F&Ez+Jâ1Ly\rP? fX[7hO#r4J9Xm"c;(b\_ZEQ[ntW~drE7gl z#lb-j\>&sRCt>d<쀠@isl$!, {(wze.#bMseZʡo@fH)/Lp$ 2w4U.v?Wŏƺ[ S귟1/#% qFY#h`mpg(FS˒Yh&AWAFqe~@f=bcSca:݇<q_08kHp$.Y!.t!DG7Y(c 3}b44}lcjW4?ZѼ;謁@qy:EטfO#O~m&o@BM +% 1ކ_SpqFI 7{:62`֌}U[и+AaY= B%?lq48,MAu:R6НT.4 ȄƔ V̜m4ڿ)(SpT Io ֓DSGo+6F& !·}FuZa>MPZ-~C4ٙl,'RlDwev89ʹ(YT80Ii*&Ǵ/"!Q/q C=`[d/sru'ؕ|$CafjnCߑ!ٛS̀OƛG̊#U8uUW[庰&De{GG]ޣG$ĒB3u9Y]ii@S-C`s*iɋw zslkOɐ]0ZTDӊ|#vfid*8kIBQh6fn WOLgqs[$w_)alw (Yҽ_ Y:SPC >i*9>,mc8$tN.8W5nY%C_Kpo7͏c+jFy1m{KFI\4/+ %T!C[hnDˬPѺy/\v9@O&:1jH0yۤg>$ S@􃴽0 g .kw4 V"}J@\ z#,Mm*|_[Gg]@tڨ" s6gIͱA]YɫS'.6m'G0ṲA>,%{QW nd,hh$s)E2p7&sEJbc,AԄ_N/xZ G1=( V7qlso.]$ k&2Dµ(abLۼA.eC]3|n)5 f"ޭ~W@Qu=x0j.;#m`>_3wOT]-]/gMI<`!">^Kz 7hU&"'Ά)$5aQ4%@C r%Mw/u"PǨ~73W!]u89"VjӃIMrRH?+$,`֩_Umpm"AdEv'ٰr(j@9sқ4*=ߙ !1ԧ82q)hfZE9LF5Mm9=+bv )+^0t$%l^X Ic$Y֝Fʾ|km.inwwybCكG#G5hU̴)]1:5c '9!9qUqa=Af@ҿRׁ@(r.Aî y3#јd0lRAfUWkMtL! >Z:p 4S7{%2 `.hZp]SguؙT7Z rk"yL(Ek$ċ#ro3g.}Q}xr| KR1 f9BJ(4 f}~<:OO@L多,J]^2/ dph#`-tښMaui*ޗh$z0\ۉ'*bv7PbNsb7AC3(cy4;h2('mzGɏF9Axܡ&p Щ2\`h[8;hmh$MwGDžM[?;Qw@Ǣpj=F࣊M$UbcZ y" Ms!2qnOL:A飕 X7SӞM!2d䨫m50۾Qĉ͍ZR5Ii$mg[/mQ(szڴ,eⴳ/m b+Ԣ_U촨?\֑F#Љn #H(̮|C&Qv5zlD"?,=̈́x \Y4R?(%aIK2cP^Z8F4X@#9I-1EP+hVx*Bcp@gОk!K$j+rn) $ħ/xVS/svdTXg,DpF?\-CIm:EyreᒹhrZ `1gqf 0O{DA- V˜:~ ;:oT}.s78~>L)#BuOVFCش&c$soMtxT°PZb3NN&x2 k~!BYb9qEY&_h?0b*;!H\ Nh)|u Vaz޽NvfmN _Zqykek䂘?ζװ6\~/7,ӥM}LXYǒ!X[ڇ_`E$X& ܭc+aپBPTuubT`vTPBz050-ga_p\c63B-f?va5Gh#2!rGiԶ4|wm<80NE#R'/LW1HHT"xF=oC%ڇR_\.dvgk(`àB ̠p+$ "d&'^|WBB ճ1 W8Y-(Ckd:Ck auQg;Z..@ ؼش@a*CǠn.x 1P$L{ŐU1@`=| CA]s[B; b(˼$