pdns-backend-postgresql-4.1.8-lp151.1.2 >  A \>/=„ݲ~fJ*p&fčn~lښ ;ڝn/^CC*bMq.8%A-IuXK휛,APQÃER,A*/Fvh+7:$\>*vDEžGh~{W4JE) hKE^JPffTq!_ɄfL`?-)۩YCeVfn7BR=Cgjm ?u/>59bbbcd1c90c4d5d8f0a0893cc10507fe3e5958d11077776cb30301062de3fb6c1e35e9dcd038c1a2455bc62e9ee74992f52dce9\\>/=„eZDEmy:t}[ce<)D $6%-L_ZͳLvxuٚBk\hn$~}Iza!pWcJmω/T]04d-#\FEJџyT bN,OӾ sJ&J5[=eSC'>)Iz1p _6B̸d&{N M5(Pμnu\@aTY X& 7_jX0>p>Ut?Udd  * F% ?c}      (AZx,(A8H.9.: .FQGQHQIQXQYQ\R]R^RbRcSdSeSfSlSuSvT wTxTyTzUUUUU`Cpdns-backend-postgresql4.1.8lp151.1.2PostgreSQL backend for pdnsThe PowerDNS Nameserver is a authoritative-only nameserver. It conforms to contemporary DNS standards documents. This package holds the PostgreSQL backend for pdns.\=sheep83iopenSUSE Leap 15.1openSUSEGPL-2.0-onlyhttps://bugs.opensuse.orgProductivity/Networking/DNS/Servershttps://www.powerdns.com/linuxx86_64P*p  o큤\=\=\=\=\=61a21087946ca4b54ffd336855c7bad7f1f990b31658102a20c9c1e47e0b91335eb4236fac7b4d5e681d84a890267e1c7d643e87734a6dd251d9760fab49bb98adaf2a23450290c86027a2d2b7ec2c6b7cb97c4653fe0e9a5c0a9da68a0b0a3b0bf6189a5675c9465d2296434a462f1d980c0f684484c0051fd82d4a7d0f08619124a2926c5380d8f9fdb030c8b449579a2c5cce2701afff455af34045e37eadrootrootrootrootrootrootrootrootrootrootpdns-4.1.8-lp151.1.2.src.rpmlibgpgsqlbackend.so()(64bit)pdns-backend-postgresqlpdns-backend-postgresql(x86-64)@@@@@@@@@@@@@    libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)libpq.so.5()(64bit)libstdc++.so.6()(64bit)libstdc++.so.6(CXXABI_1.3)(64bit)libstdc++.so.6(CXXABI_1.3.8)(64bit)libstdc++.so.6(CXXABI_1.3.9)(64bit)libstdc++.so.6(GLIBCXX_3.4)(64bit)libstdc++.so.6(GLIBCXX_3.4.21)(64bit)pdnsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)4.1.83.0.4-14.6.0-14.0-15.2-14.14.1\@\@\@\[[[@ZZZЛZZZ@Z@YeYY5Y}@YMYMXDX@X~@Xx@Xx@XN@WW@WJVV8UUv@U>$U8TPTи@Tи@Tи@Tto@Ta@T_W@TR(@TO@TO@TO@Michael Ströder Michael Ströder Michael Ströder Dirk Mueller Michael Ströder amajer@suse.commichael@stroeder.comkbabioch@suse.commrueckert@suse.deadam.majer@suse.demichael@stroeder.comadam.majer@suse.demrueckert@suse.deadam.majer@suse.dejengelh@inai.deadam.majer@suse.devcizek@suse.comwr@rosenauer.orgmichael@stroeder.commichael@stroeder.commrueckert@suse.deadam.majer@suse.demichael@stroeder.comadam.majer@suse.deadam.majer@suse.dedimstar@opensuse.orgmichael@stroeder.commrueckert@suse.demichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commrueckert@suse.demichael@stroeder.commrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demichael@stroeder.comLed michael@stroeder.commrueckert@suse.demrueckert@suse.demrueckert@suse.de- Update to 4.1.8 * #7604: Correctly interpret an empty AXFR response to an IXFR query, * #7610: Fix replying from ANY address for non-standard port, * #7609: Fix rectify for ENT records in narrow zones, * #7607: Do not compress the root, * #7608: Fix dot stripping in `setcontent()`, * #7605: Fix invalid SOA record in MySQL which prevented the authoritative server from starting, * #7603: Prevent leak of file descriptor if running out of ports for incoming AXFR, * #7602: Fix API search failed with “Commands out of sync; you can’t run this command now”, * #7509: Plug `mysql_thread_init` memory leak, * #7567: EL6: fix `CXXFLAGS` to build with compiler optimizations.- Update to 4.1.7 with a security fix: * Insufficient validation in the HTTP remote backend (bsc#1129734, CVE-2019-3871)- Update to 4.1.6 * Prevent more than one CNAME/SOA record in the same RRset- adjust buildrequires for mariadb 10.2.x on SLES- Update to 4.1.5 * Improvements - Apply alias scopemask after chasing - Release memory in case of error in the openssl ecdsa constructor - Switch to devtoolset 7 for el6 * Bug Fixes - Crafted zone record can cause a denial of service (bsc#1114157, CVE-2018-10851) - Packet cache pollution via crafted query (bsc#1114169, CVE-2018-14626) - Fix compilation with libressl 2.7.0+ - Actually truncate truncated responses- Update to 4.1.4 - Improvements * #6590: Fix warnings reported by gcc 8.1.0. * #6632, #6844, #6842, #6848: Make the gmysql backend future-proof * #6685, #6686: Initialize some missed qtypes. - Bug Fixes * #6780: Avoid concurrent records/comments iteration from running out of sync. * #6816: Fix a crash in the API when adding records. * #4457, #6691: pdns_control notify: handle slave without renotify properly. * #6736, #6738: Reset the TSIG state between queries. * #6857: Remove SOA-check backoff on incoming notify and fix lock handling. * #6858: Fix an issue where updating a record via DNS-UPDATE in a child zone that also exists in the parent zone, we would incorrectly apply the update to the parent zone. * #6676, #6677: Geoipbackend: check geoip_id_by_addr_gl and geoip_id_by_addr_v6_gl return value. (Aki Tuomi)- Use HTTPS links in .spec file like mentioned in PowerDNS announcements - removed obsolete 6370.patch - Update to 4.1.3 - Improvements * #6239, #6559: pdnsutil: use new domain in b2bmigrate (Aki Tuomi) * #6130: Update copyright years to 2018 (Matt Nordhoff) * #6312, #6545: Lower ‘packet too short’ loglevel - Bug Fixes * #6441, #6614: Restrict creation of OPT and TSIG RRsets * #6228, #6370: Fix handling of user-defined axfr filters return values * #6584, #6585, #6608: Prevent the GeoIP backend from copying NetMaskTrees around, fixes slow-downs in certain configurations (Aki Tuomi) * #6654, #6659: Ensure alias answers over TCP have correct name- Update to 4.1.2 - Improvements * API: increase serial after dnssec related updates * Auth: lower ‘packet too short’ loglevel * Make check-zone error on rows that have content but shouldn’t * Auth: avoid an isane amount of new backend connections during an axfr * Report unparseable data in stoul invalid_argument exception * Backport: recheck serial when axfr is done * Backport: add tcp support for alias - Bug Fixes * Auth: allocate new statements after reconnecting to postgresql * Auth-bindbackend: only compare ips in ismaster() (Kees Monshouwer) * Rather than crash, sheepishly report no file/linenum * Document undocumented config vars * Backport #6276 (auth 4.1.x): prevent cname + other data with dnsupdate - misc * Move includes around to avoid boost L conflict * Backport: update edns option code list * Auth: link dnspcap2protobuf against librt when needed * Fix a warning on botan >= 2.5.0 * Auth 4.1.x: unbreak build * Dnsreplay: bail out on a too small outgoing buffer (CVE-2018-1046 bsc#1092540)- add patch for upstream issue #6228 https://patch-diff.githubusercontent.com/raw/PowerDNS/pdns/pull/6370.patch- geoip not available on SLE15 but protobuf support is available.- Update to version 4.1.1: bug-fix only release, with fixes to the LDAP and MySQL backends, the pdnsutil tool, and PDNS internals- Update to version 4.1.0: + Recursor passthrough removal. Migration plans for users of recursor passthrough are in documentation and available at, https://doc.powerdns.com/authoritative/guides/recursion.html + Improved performance: 4x speedup in some scenarios + Crypto API: DNSSEC fully configurable via RESTful API + Database: enhanced reconnection logic solving problems associated with idle disonnection from database servers. + Documentation improvements + Support for TCP Fast Open + Removed deprecated SOA-EDIT values: INCEPTION and INCEPTION-WEEK - pkgconfig(krb5) is now always required for building LDAP backend - pdns-4.0.4_mysql-schema-mariadb.patch: removed, upstreamed- package schema files in ldap subpackage- Update to version 4.0.5: + fixes CVE-2017-15091: Missing check on API operations + Bindbackend: do not corrupt data supplied by other backends in getAllDomains + For create-slave-zone, actually add all slaves, and not only first n times + Check return value for all getTSIGKey calls. + Publish inactive KSK/CSK as CDNSKEY/CDS + Treat requestor’s payload size lower than 512 as equal to 512 + Correctly purge entries from the caches after a transfer + LuaWrapper: Allow embedded NULs in strings received from Lua + Stubresolver: Use only recursor setting if given + mydnsbackend: Add getAllDomains + LuaJIT 2.1: Lua fallback functionality no longer uses Lua namespace + gpgsql: make statement names actually unique + API: prevent sending nameservers list and zone-level NS in rrsets- Ensure descriptions are neutral. Remove ineffective --with-pic. - Do not ignore errors from useradd. - Trim idempotent %if..%endif around %package.- Added pdns.keyring linked from https://dnsdist.org/install.html- Don't BuildRequire Botan 1.x which will be dropped (bsc#1055322) * upstream support for Botan was dropped in favor of OpenSSL, see https://blog.powerdns.com/2016/07/11/powerdns-authoritative-server-4-0-0-released- This makes the schema fit storage requirements of various mysql/mariadb versions. pdns-4.0.4_mysql-schema-mariadb.patch - preset uid and gid in configuration- fixed use of pdns_protobuf- update to 4.0.4 - fixes ed25519 signer. This signer hashed the message before signing, resulting in unverifiable signatures. - send a notification to all slave servers after every dnsupdate for complete list of changes, see https://blog.powerdns.com/2017/06/23/powerdns-authoritative-server-4-0-4-released/- added pdns-4.0.3_allow_dacoverride_in_capset.patch: Adding CAP_DAC_OVERRIDE to fix startup problems with sqlite3 backend- use individual libboost-*-devel packages instead of boost-devel- update to 4.0.3 which obsoletes b854d9f.diff- b854d9f.diff: revert upstream change that caused a regression with multiple-backends- update to 4.0.2: The following security issues were fixed: - 2016-02: Crafted queries can cause abnormal CPU usage (CVE-2016-7068, boo#1018326) - 2016-03: Denial of service via the web server (CVE-2016-7072, boo#1018327) - 2016-04: Insufficient validation of TSIG signatures (CVE-2016-7073, CVE-2016-7074, boo#1018328) - 2016-05: Crafted zone record can cause a denial of service (CVE-2016-2120, boo#1018329) For complete changelog, see https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-402- BuildRequire pkgconfig(libsystemd) instead of pkgconfig(libsystemd-daemon): these libs were merged in systemd 209 times. The build system is capable of finding either one.- update to 4.0.1 Bug fixes - #4126 Wait for the connection to the carbon server to be established - #4206 Don't try to deallocate empty PG statements - #4245 Send the correct response when queried for an NSEC directly (Kees Monshouwer) - #4252 Don't include bind files if length <= 2 or > sizeof(filename) - #4255 Catch runtime_error when parsing a broken MNAME Improvements - #4044 Make DNSPacket return a ComboAddress for local and remote (Aki Tuomi) - #4056 OpenSSL 1.1.0 support (Christian Hofstaedtler) - #4169 Fix typos in a logmessage and exception (Christian Hofsteadtler) - #4183 pdnsutil: Remove checking of ctime and always diff the changes (Hannu Ylitalo) - #4192 dnsreplay: Only add Client Subnet stamp when asked - #4250 Use toLogString() for ringAccount (Kees Monshouwer) Additions - #4133 Add limits to the size of received {A,I}XFR (CVE-2016-6172) - #4142 Add used filedescriptor statistic (Kees Monshouwer)- update to 4.0.0 https://blog.powerdns.com/2016/07/11/powerdns-authoritative-server-4-0-0-released/ https://blog.powerdns.com/2016/07/11/welcome-to-powerdns-4-0-0/ - packaging changes: - remotebackend split out now - enabled experimental_gss_tsig support - enabled protobuf based stats support - no more xdb and lmdb backend - added odbc backend where supported - drop pdns-3.4.0-no_date_time.patch: replaced with - -enable-reproducible- update to 3.4.9 * use OpenSSL for ECDSA signing where available * allow common signing key * Add a disable-syslog setting * fix SOA caching with multiple backends * whitespace-related zone parsing fixes [ticket #3568] * bindbackend: fix, set domain in list()- update to 3.4.8 * Use AC_SEARCH_LIBS (Ruben Kerkhof) * Check for inet_aton in libresolv (Ruben Kerkhof) * Remove hardcoded -lresolv, -lnsl and -lsocket (Ruben Kerkhof) * pdnssec: don't check disabled records (Pieter Lexis) * pdnssec: check all records (including disabled ones) only in verbose mode (Kees Monshouwer) * traling dot in DNAME content (Kees Monshouwer) * Fix luabackend compilation on FreeBSD i386 (RvdE) * silence g++ 6.0 warnings and error (Kees Monshouwer) * add gcc 5.3 and 6.0 support to boost.m4 (Kees Monshouwer)- update to 3.4.7 Bug fixes: * Ignore invalid/empty TKEY and TSIG records (Christian Hofstaedtler) * Don't reply to truncated queries (Christian Hofstaedtler) * don't log out-of-zone ents during AXFR in (Kees Monshouwer) * Prevent XSS by escaping user input. Thanks to Pierre Jaury and Damien Cauquil at Sysdream for pointing this out. * Handle NULL and boolean properly in gPGSql (Aki Tuomi) * Improve negative caching (Kees Monshouwer) * Do not divide timeout twice (Aki Tuomi) * Correctly sort records with a priority. Improvements: * Direct query answers and correct zone-rectification in the GeoIP backend (Aki Tuomi) * Use token names to identify PKCS#11 keys (Aki Tuomi) * Fix typo in an error message (Arjen Zonneveld) * limit NSEC3 iterations in bindbackend (Kees Monshouwer) * Initialize minbody (Aki Tuomi) New features: * OPENPGPKEY record-type (James Cloos and Kees Monshouwer) * add global soa-edit settings (Kees Monshouwer)- update to 3.4.6 [boo#943078] CVE-2015-5230 Bug fixes: * Avoid superfluous backend recycling * Removal of dnsdist from the authoritative server distribution * Add EDNS unknown version handling and tests EDNS unknown version handling Improvements: * Update YaHTTP to v0.1.7 * Make trailing/leading spaces stand out in pdnssec check_zone * GCC 5.2 support and sync boost.m4 macro with upstream * Log answer packets only if log-dns-details is enabled- update to 3.4.5 Bug fixes: * be careful reading empty lines in our config parser and prevent integer overflow. * prevent crash after --list-modules (Ruben Kerkhof) * Limit the maximum length of a qname Improvements: * Support /etc/default for our debian/ubuntu packages (Aki Tuomi) * Our Boost check doesn't recognize gcc 5.1 yet (Ruben Kerkhof) * Various PKCS#11 fixes and improvements (Aki Tuomi) * Several fixes for building on OpenBSD (Florian Obser) * Fix several issues found by Coverity (Aki Tuomi) * Look for mbedtls before polarssl (Ruben Kerkhof) * Detect Lua on OpenBSD (Ruben Kerkhof) * Let pkg-config determine botan dependency libs (Ruben Kerkhof) * kill some further mallocs and add note to remind us not to add them back * Move remotebackend-unix test socket to testsdir (Aki Tuomi) * Defer launch of coprocess until first question (Aki Tuomi) * pdnssec: check for glue and delegations in parent zones (Kees Monshouwer)- no longer ship dnsdist here, we will ship a new package based on the snapshots from http://dnsdist.org/- update to 3.4.4 with a fix for CVE-2015-1868 (boo# 927569) Bug fixes: - commit ac3ae09: fix rectify-(all)-zones for mixed case domain names - commit 2dea55e, commit 032d565, commit 55f2dbf: fix CVE-2015-1868 - commit 21cdbe5: Blocking IO in busy-wait for remote backend (Wieger Opmeer) - commit cc7b2ac: fix double dot for root MX/SRV in bind slave zone files (Kees Monshouwer) - commit c40307b: Properly lock lmdb database, fixes ticket #1954 (Aki Tuomi) - commit 662e76d: Fix segfault in zone2lmdb (Ruben Kerkhof) New Features: - commit 5ae212e: pdnssec: warn for insecure wildcards in opt-out zones - commits cd3f21c, 8b582f6, 0b7e766, f743af9, dcde3c8 and f12fcf7: TKEY record type (Aki Tuomi) - commits 0fda1d9, 3dd139d, ba146ce, 25109e2, c011a01, 0600350, fc96b5e, 4414468, c163d41, f52c7f6, 8d56a31, 7821417, ea62bd9, c5ababd, 91c8351 and 073ac49: Many PKCS#11 improvements (Aki Tuomi) - commits 6f0d4f1 and 5eb33cb: Introduce xfrBlobNoSpaces and use them for TSIG (Aki Tuomi) Improvements: - commit e4f48ab: allow "pdnssec set-nsec3 ZONE" for insecure zones; this saves on one rectify when securing a NSEC3 zone - commits cce95b9, e2e9243 and e82da97: Improvements to the config-file parsing (Aki Tuomi) - commit 2180e21: postgresql check should not touch LDFLAGS (Ruben Kerkhof) - commit 0481021: Log error when remote cannot do AXFR (Aki Tuomi) - commit 1ecc3a5: Speed improvements when AXFR is disabled (Christian Hofstaedtler) - commits 1f7334e and b17799a: NSEC3 and related RRSIGS are not part of the dnstree (Kees Monshouwer) - commits dd943dd and 58c4834: Change ifdef to check for __GLIBC__ instead of __linux__ to prevent errors with other libc's (James Taylor) - commit c929d50: Try to raise open files before dropping privileges (Aki Tuomi) - commit 69fd3dc: Add newline to carbon error message on auth (Aki Tuomi) - commit 3064f80: Make sure we send servfail on error (Aki Tuomi) - commit b004529: Ship lmdb-example.pl in tarball (Ruben Kerkhof) - commit 9e6b24f: Allocate TCP buffer dynamically, decreasing stack usage - commit 267fdde: throw if getSOA gets non-SOA record- update to 3.4.3 Bug fixes: - [commit ceb49ce] pdns_control: exit 1 on unknown command (Ruben Kerkhof) - [commit 1406891]: evaluate KSK ZSK pairs per algorithm (Kees Monshouwer) - [commit 3ca050f]: always set di.notified_serial in getAllDomains (Kees Monshouwer) - [commit d9d09e1]: pdns_control: don't open socket in /tmp (Ruben Kerkhof) New features: - [commit 2f67952]: Limit who can send us AXFR notify queries (Ruben Kerkhof) Improvements: - [commit d7bec64]: respond REFUSED instead of NOERROR for "unknown zone" situations - [commit ebeb9d7]: Check for Lua 5.3 (Ruben Kerkhof) - [commit d09931d]: Check compiler for relro support instead of linker (Ruben Kerkhof) - [commit c4b0d0c]: Replace PacketHandler with UeberBackend where possible (Christian Hofstaedtler) - [commit 5a85152]: PacketHandler: Share UeberBackend with DNSSECKeeper (Christian Hofstaedtler) - [commit 97bd444]: fix building with GCC 5 Experimental API changes (Christian Hofstaedtler): - [commit ca44706]: API: move shared DomainInfo reader into it's own function - [commit 102602f]: API: allow writing to domains.account field - [commit d82f632]: API: read and expose domain account field - [commit 2b06977]: API: be more strict when parsing record contents - [commit 2f72b7c]: API: Reject unknown types (TYPE0) - [commit d82f632]: API: read and expose domain account field- set $LD for now. this fixes the configure check for relro,now.- remove custom PIE handling. upstream does it for us now.- update to 3.4.2 This is a performance and bugfix update to 3.4.1 and any earlier version. For high traffic setups, including those using DNSSEC, upgrading to 3.4.2 may show tremendous performance increases. A list of changes since 3.4.1 follows. Please see the full clickable changelog at https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-342 - move man pages to section 1 to follow upstream change- disable botan and geoip on SLE_12 because of missing dependencies.- Fixed broken _localstatedir- fix bashisms in pre script- update to version 3.4.1 Changes since 3.4.0: * commit dcd6524, commit a8750a5, commit 7dc86bf, commit 2fda71f: PowerDNS now polls the security status of a release at startup and periodically. More detail on this feature, and how to turn it off, can be found in Section 2, “Security polling”. * commit 5fe6dc0: API: Replace HTTP Basic auth with static key in custom header (X-API-Key) * commit 4a95ab4: Use transaction for pdnssec increase-serial * commit 6e82a23: Don't empty ordername during pdnssec increase-serial * commit 535f4e3: honor SOA-EDIT while considering "empty IXFR" fallback, fixes ticket 1835. This fixes slaving of signed zones to IXFR-aware slaves like NSD or BIND.- only enable geoip backend on distros newer than 12.3 before the package lacks the pkg-config file and there is no fallback to finding geoip without it.- fix permissions of the home directory- enable some backends that we had forgotten: - pipe (main package) - random (main package) - geoip (new subpackage) - new BR: yaml-cpp-devel and GeoIP-develsheep83 15540710134.1.8-lp151.1.24.1.8-lp151.1.2libgpgsqlbackend.so3.4.0_to_4.1.0_schema.pgsql.sqldnssec-3.x_to_3.4.0_schema.pgsql.sqlnodnssec-3.x_to_3.4.0_schema.pgsql.sqlschema.pgsql.sql/usr/lib64/pdns//usr/share/doc/packages/pdns/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Leap:15.1/standard/11b25228fba60f5563817db73a652e82-pdnscpioxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=c29c1107705289837680841186c256d65540810f, strippedASCII textPRRRRR RR R R RRRRV )butf-86433b81897c5b54dbbee2dfb753177d550fd4db60fe8bbb6707c85e21724b6bb? 7zXZ !t//q] crv9u^}}=F t`\]piq+B!7Buُ\5JW'E7$&eto({BX鷷HvNB;Leo,["Z| &+ `$頌\ғgu{ K72^ 7YVt7;qt|m66EC":3-Cp8\xAdMm f##D+̗?Ů{Bdq(-,0hv&b3YB8Q` Q |?LfGq,F_CآhDR$Zq@v/e}wo\7rKj"iM[{F{LD | Η. 5xHIJOP;ys1ذ"IG<Ԝ#Mtj^^/hAeZ.&BO' RQڑUٛ8.,jp?YV1b7ڶM 3Y} d47P+,gj TP55w*E3~b(FTI Xg u8n"#Nݯ 1@PubڡPxG-} ڠ{ eSu b=?ڕ1V3\zN{g +оcu#w4Á@Z+v/zh0`뼧 #xf{tc9>Ǐk.\+nr讼-.3e@{2M2fWvoq./ .^O\4{B*3|| ']_*W-f#Al8X?P託Kg {z:?83ґLw_-RpOմU$e6g1OKTtdo9 Hg&~A}IUԄKLTPc91R$hUrkփP,[f ؘ 8؋J,G[u*MTIj4; y$йCx^GC7+ot^eޏ/4w{Uݞgv\/*qNrҌY*\!Y_s> V"r;L'<93X%W]P?#VPC{|n^-~ @?u*?z4[$ٽ>42^ْ 0H_)DwHr\N-s(n8ԯ`kbXfhP0voPl)h+H_JzsʚGyAP7m+ncȵ& $F0eߟ#v )ij׸ @Ļg޴ʳ:fƠo]U޷iim姧T= Jo<[/S6{ظBl扽Ɵ(0cT>G[l~"]VV|[3q R(9aͱ2R;s+-\"n[dRsa*&w'(:EcG+d<T(/&<,ɰI j :4CS@y UtHp~2ƌ)IfYhMo5:7÷~65Z/i:Wb$=rdT,6T=YH;A1K|@E樈ѝ-(Z*&CH;yfLͭrZ F̃drm#n9Yofdwǂ~TNf\ \<|y Zҭ4rϹ o%|3bX5C yMّiPJ9;(ytc4 >B )y f᧨!"$` D/2È! WJK =J̪nZѴdֳv3ϖCs_wi>Ԅa.qPK JwGCid%x1:h4=?E.>xI B] d"gpr.=dqlaZ<7l'캌 9@@ncwˆ괦!cPwZ(L`2njVb20ȞRO-RmF ͷu@ 7:٧o}d9S4#]s DƁiˋpD&Q&NAEU[$,P +\/a7% 1{\*.](GT,z2dhm{S@FP5yPe:=Ee=i, M%g?J({'OWb$H}ZZ.C2)%;7Pw+ '@?˨2W %7CЏ`vUƈtGšzJP~+2dX3+CٙUKtyYKTw=^b,e[jn^߈z:Mt evqsQJr9STeQwNu5Dx;ys:f*AxV(V~xe+-ɢ›WnwOm67m}GFP{Taj{,zJx_YQ~xvH. b:8M`j5|&rY~A0úehM~r(H8coݙ-UY`d:rB(FwUfMd۽{wUEKgCPFG^i 77"E"ɖsۘPWyes LE[EF?)D>ӈۖ6R2it@fc![ћ 2"i\$0F\Lx#H2T+vߒsJ dV~L61^ɺ5s].} 4 t4O;V/)#h$X/CQw:f|z"әu\ܑ5_e7%P XGjaͥL-:Zc,"KQs2y -s!}VcLX̥y)/b-?Bהؽre݆rξ D9%YM CzB!Oll,_(S87e`|՞v-˾Zh NzDÐ3XםD ,q9g2H;"\ \)'꽛o_sَFzVu6'-(e/rdNݼ13DŽȃzJtrS.;` |%cҍ Xa{{дm`M>\YFjݠ+oV"f͊h F6bܯjItzC̓VhE22Br҉w+z zм,^*_B`Sy"KFՙ"P7F)~8*b]IB2ﲜ}ğ6s3/yV@ˍk~P~$j/Jhrgg(R`C4֑}+ӂxŹ#.21u_IIChG&@W@;TBbfҿ<款POAg5{lRqhbc sI2jHu$J-W<%5US`&,VՠxBgR30.E!od&uA=oeiPna&A>*ov}qHrVd*sTc WT檂, # @cӦQs"T}-HtWQ6]~+qaS9tgO$Wܱ9%2kr'!&h96P?kL 3C -+CH$KZ^2_UVg},45_ ;Րrsw(g!BX?r )e$ftH1 V+3PYXwUv!pwz upe $ MJq8WӺ+q\EjQTWOXw>ۅq~;N|l:9,#Atrvbrt!f!jl N`~մZfEix)gkN {\-3^cDcVשL\=#]t6C}Fob4MچSz l޵zonQx`r'bEsTOK!Ilڡ35ݲ=' [96"HFc~Oj%lJzx.}uI %!]lavƕب{^VծEgJ#\ݿ2Ѥ6s C`D07 P! (kV<$Y  ѱ`\M^Flc,܈0-/Ty'|pۻ ?fp Z&[<` ?N>vwr#ƛ ҷye: <)뱦5Vj* (siT_n絥ц;uEV3MPCjϵE&WL5uq:VѨ1 p6,E-9"6xZLuNp!%^CԶqfߠ!GF\eeV8UkpA\\ƅLv_Ty̫(ϖ68Ѝ k.;C 8][Ⱦ,BLTan1BKMva8fS-i1MACgn4j"66psr} cW.UKŻ' ݶơ ̀1or" 0LJqKR,^u,-ek߃Z軐}B* N6 3?AAX2ļIlV4ViFEJKxE*gȪ*-X*CŅJ=*wNqcu[JJV?mn(q=j4qY9Wx)Zs ~`[:Aiݡa'F4 ,JCx+M2O{Ojr'\<-^9g@~|a@y $5ouѷm1ךz$M]6``z)Y4?A_5Oqi}eDC-d^Mp/;X+ &Kɒ Ll=Qumk7$X$ v?!/LOgAaHs2 ;]f"LrBI ;,u6VPtC()y;QBݺN{<-?t^ZW@xTumA#+.޼v7gYǮu3NWlb]o;JU) ruͲTT9˶T..(c}jb)uIn&{oX(D4VKH=,;7pc_tu(5rk]< gQT}ߨ gy> S؂Vl79k6*`Dx+GH!2Bt5!CzʑX4ȭs Mi~ߩfVune׻] O)zt,< ?2xJĖc눱=+ :sJziʣj˪A|kuLOzq 1LѤVi cY@h ZQЫ6LrPt*lwzbI {S j K㷚=-mNKD#0W_,IìvcmV07ut]GɲΔNu]:b;K~t#dVO0_u[{Sn?>E[""h{t',F.rs` g ['ؐ@aA7->fNDoBk굍sĠ؄x!/ljH1V;mcľjn)@;d9P/[FɮYrM 9r: ݳ2O>^[XBds Ѡ@Rn( ? Z<dg#ZCәFʤ o<`M?7| r["":~{PB}iuJ>X"]]!DtѴ%V]Э14a Lw·B[&sG$VP+NTGe!4̖6\fOSPc0׭+G1 E\nQ d7(ಝTO4}K}.&u8S,piH5=*6"gچZb]@/rJ T巘ӇM _/œxkba[]x| ^O# vj`?n7-f^3`U/)g4hilz:jj^sѹWeT{At~nj7f]z J]: U9en^<Ҽۯ#haI-t4gLK G~G!ezAyH哬Tc7Zn}e}nkXT^Ʀ 6 %V*_d®k}3cs+s77~uByIFx;;P.05jd(~Ǒ2 AzqFӫaYZ}@G [҆ґ k\X]4]-F\0 yQ kqNHxx<e@\SYJpnb&+7$<2td\J5=rĶlHd=&9id j9pH見sll 0q_z)̰~hʓP9 сUUjˁ nm ș>D߄ɆǴ׮91kk{v߼7B(3WxKt$\ylc<m#6 I hר8a N8Z:jufMo.VO+ hXM"?n|sz^Mc4U~ ݳp w| hXMAkQ90S A{eKतog"(Nμ? D"X% ;hDmmQ wש D=߇t'͍|!Æ4w&5}7Z1Ɵ !u,[͓&s=<dTkS` ~0A&B5YdF<]MYCd(OmY(TyX|(ҾHF֜lav7 g~Hʁr5u[^IYV'yMd#!!hA4L߱m*SŒCLnm+IT H kS wo,ԝZgD qP=9YHXڮcf$x5 ݏ;>n mɀHR t~ApT [o@dvGٰjja33:s،;ĭT84"wo } @ Z[5:6('YylvW/l~d{ _K¼截'low3DO-e$T̿qԽh~4ymŝŒDF\:n;cF}i7QE0yŦۅ~/L\d M^aa`/H8 'eF@eDb  .Q)PZ30>/Wc<Gu"׾o1524b\G}V/7f+tibXf:iJ{7rm}n?䕁Y;7ӽH5{/c8 03TQ]?oe e-AlEChP?Fw㭪"vRœ0"ZyR@m9zgثߤ~Ҏ+hH°ra,XrӾw| mM]&˾l3d.-n{<]8уL98^p'WqEMcgtnmyJ}蜄ĺR{De= oZh9+UnD!D'B D᥉Q>8EH/' nXuðT;"a$+,eegSv[>Æب(0 1xN(etX{*U]TqKt\S(;wV>f3崻/X<78,J0 vedvzϲxfRgL# ஀ң4кʣq9 /1wcL!Iw1*#ZVgZ~{,xol&n̡\F W篁رXwc\+wd$E:2ۥ`UVgެ[ڒuTfn;GJFJ2(⦞U *eyj3xA[wO@)d*Ãd-:+'~: -X کWe!DP ap{UئoLx|tg=q #J^QjIǟ2^V!WxoY mG20undjQĜ"z+CEz"T*2u6>-9dlϓM\$Pj^kېΟSn$` sИax !\V}Rtث)HeH8U7%e-`}ֆb_S+1T:B,>>x:9+*[45iا#t˥Ac|75z6*JmLfD|pl?zȠx ܇1毲Jbù6cAp~oDQ)꓋'38[{ҠZ` bH\r\Vm2]V7AFd0O;A5U  ǡGqXwSc05y= 0o:jsDEmdb'4깒m[vj9;OI*sϾ!v*kقM}[KB ׭7XҘe) {fRZRp K)'2Ӭ#qI 6&7=T섓9ޠdh-rS'~sj+bF,۸Yݰd|":7j|6r)jK@< مfzvIogdTԑt_?-$?:ǁcS&KӧcM|ӧGBl MI&C[ܶO咬gbiյTjTv,:_xGȸL" ,:Ky櫽UяC~,nM0yp->q;<]Ri4f=H]k}^+QJmb@(! dJ>lu@p*6\98.-d{ikG~)1?'}O<@А^:6F=Q.l5BMt" X3?,5vpU1%nT_ʟq{.mQGsܷ7c ez f3L#g8#Kޚ#C{K#s%s&^?&ҦJ|«|'Tk2Z[!T޵En XM}CSd]W*b, wH`kyHHu"ǡe1y|mԩ&FOq\PS 5.b^t2aGb %D%م&\]{OOK|wI0G/j1g}gǂB)%94oL91BGGTa {$Qd.&_y?6.' kf40:YK8 G*'ԷPbKU V:}#zj ekndQQ;鄶8"qQtS}]"q]{c=s~5?-N,Wa*\S! mh@AS@Ցo+7Ggxcxߜl h?cTmߦyZ2rVfXI-b/L\MX ˴zD~2/vN)p xlL1k $]?'b@fPj&\ lfPPbTlZyTe4.HCq! Fꪕ?O"UߓЗ`i]wU!^I<@{Rnf}\J!OӋH1XO` NҼx61&jc):~wT#֞Lj@c[қk42 KKҩ?tY4SP ?&C5"ssH`5/#c2i壛.@UJr*քq`[93i`ٓ欒~R`eZSL|"@s} S3J1N#]{QeKj9pB.{1Op:!>(9kn)HWw*<P*M%>4BGm7.T_"tBĄ5YWLhoаl7̐NW00TlЁe2:anj/m#AH9G֫,ZPS vmBKT# C,d)S LgkSۀIN{2UpȦ􄠒\R )d!ZFC|"7pDY[$Abɚ8㰏)Z\(%eUu*7#Dq$>+[_q~ %EVd$l`ħI=?%ZjMFSoF u_;嫿е&|ϩMbq1znMU+fZ|B# =<ul&RbcCH޿')ub UP⌫TɌ.\g!2EA C:it"W1%8Ҍp3@%'ft3K%;ЄWT~eMHப`v raf#;0W0*AKEA H)K`{%~VteuMXk_it *@-VPǑoe!hảt 7FM U+@gY]såʑ6k>{=s|#hYC³&߉/P'mNBۮNu=IH) 6pg4pUZ)0zY]YvLh7l&h˳KGEu}s{PkQΑcۄujRQ/v mFخ!PQЭ1Ӊ_+:j{Ԩn7Ƿ ʜU@,)>?iZ#˔o=b0=\P_/5i[ܖ` =bz Z,%.&nd7ĕ֝hD_JD 1 ^@%^o{]w9 yl3^TLݢ`[ x4W19ȏh v$$eZٸqQmKxlb̭sgmGkcNEg0~g}2V-"5ţ^a!0G~"]6xsP½Nw> ފ%Aꦟ6}rƛ&ƥmNJ&|kٓw+ô6ޞCͯC800]Yp&6Rnq/f p@r($e]6*8iͧ78oyDzqu <У-[`.s7ˆ'R "r|Ub ӡsӀA`HT ?bg\#nzFyUj;qpzVV V=b 2QZ(|&*|THW/SX+^58+CVJtYcRNRH` l ;=dQ'{ >&s^Y?ض/[P*rC(juQ%2Kvgz]0L}a^c-@Č7U$²O[j;k4~2Btހ~@*evE%!eΨsG?(]PnSLg)iaa!ޛlqv]mzPn4x*Lrίf!P2@_I]TZ_!47n3t*z%bUt9m]Q, K( y!cW^e#H'41GuHgЋ_ji}%.=rC `؈cHV'dӻ6EvEuLq5کolk:`~V"}]ۛW5\$i,[<}J H JRf@[׍dPI|xȴ;M`a\icTF!`Ģc@[/Uzgʉ%f1opBhFS֞Б6l?25M*0Ӷ\(*pflL'l_v)pȷnupM; |FwhJN  [䉂*Lg},fƯV@Iq1f lZi>ŕō;ΒλDZFk *@ MKR ޼Y:gၕ@\YOLwC<K1g!JgcX}C58X|ϡ=_|&x@8ƃ_,Wq{9 -`,){Pq<+^ R.#1j鴣FnO #dfGCV^(d/,*kA:L^#3\ ]qy -K0iW &P%qGçT`jx*NeNb8)9F2FbkAci*CN+" ɤ,x'ZYtɐƉU~sw:d A{{+*gg eTV47|BҮo ]RLe~;r7q|49i>=fsEXg}4x^lӃᦾPz]`9-ˌq]CLKRЋ"SF{ GS$k7} AmpƑषtpß0ޛ(:QJM.΁qJKt0XiA_6eA3ǂivaOէIΛ=#hQE&J.e*'g,=ދd:9.#0?9W≏R%~Hj@gc?\D[m„_ UYʷg ׆ktgHdRR 4`MM! >\Bq\I=}PED`2GJUM *>r|j^wi*.0  U?abi@2{B阦$,h$ q;܆Ƭ͒k܎Pg H>axB -:8oXŒ4Au1StGvK:#[Fղ {q+A%_ $5V} \txI{U{Aקɕ2VЪ]p i/LTď:5y4 Fw9kO&ƇҜC7GW(UY d]~YwTXmADu2cL8m;' K<*L'/n-o՛#8$ه!@ jsH$+#Frb%м:eX%# ]X:<>]ذC~~\EIuMHQVT\g9FIX(ң%[ { Z3xE:UW Ⱗ{yod9ܤX{Ygṟ-)BH@Ѥ;@Wq{P%^k~I9?'j]rbԱH"$ϵevkCL <E( ~orTB#-C?5k76cXWS<ŝrk-Zs(ݴ֙ DI#e+R5r!WNwLyhN7.5gvw5|L ~Ӄy&nX4:t`M*nG̏!똎 CP7-!QOq +`qL `WH46@mT5ZBI|V}ćKx["F?B ӗЎCQ2_B3C DpOiy3 4R bR8/t҃k=1ʢ\7$ܦa}U1Ff({8>G"p+yUmPU_ZOÇ~ll]VJV T״r(&+s#5+} o[?/,TeC˽Ȅ%5ܤyzB2j IPn}=ZxD !GL/ KԢWIęXzL%i[Ӆ`FvsQфf]C h[i$6 6յM"V9q NSdTYH;𽬺} .* O*s\P0[#`S0 }(lb Z:U"1KC;h$}G!u֎"{j ǯPn-ZB2A[N5ؓrEP碅M(fo9?d&UE,N2#SSgIۀN7AbD!P7.^^#2P5#Se*}wY1t]/gߐ!1Lz \0Irnʱ\&ݳ"Lz+e"dzܺIF}elwQ+_Ok%oPʧOd'B2䥔\̂OFA$ |' G7WxFTvt-%qTdw2 F$p~3xc.FZ*h_R1&o AtvV&TxUЩLֽĆrcpxy3#aM :?3t: EM3xo_b%r ȒSGG V+vLb:zeu_5}jv0nԑRca ;?𮚈tɜnC~;3wߣjḰjJ'N:DͿuh^g!Rޛ`v*.laz1Dm,l[2Ý'+Z)$\@hLciޔ- } [Y!tEq*_b'4:푃DY-QKh`ƟT́9Zn-0Z#BE૶D ɯ#|;(ǟ~gΗL{&+_գp [oTe1Θo1LahI)Ji Uh3.6BsO*I=Yu?jYqBzgMҟ${.\ˍH*˫`4BR*Xm^7zm9)_}u/sLC=}_W#Ӯ1EhR,&P?Z" EFVFw(^.b Fd`INqc69s$BfapEmm^ٷiJ_xj3|gA {8HQ"1&<&50|EvH:wjQ}Vh e"4mi7I9<+3Rg{e4vjlN`eBDίԤny.,61;Hq;Fy!+*M:^$09r6H><3^UpN-|P fӆDiBͰ4,S8 wF?IU>'m+>:/Z+.R+ߘẒBAX݆;lFrglđ<(L (,y2Q L #k${4JuMk*Hmz3 \wby33]u.S|_5_c:]ࣟu0}d]U|\fp H{1nm+W`N9+DEfAAx,c]Q%Poeϊ'lZHDe}aEhmc'Tb=j gmn81.V9݈N2 }}6eL~9K-J=rZ蜕q*䎃R)͖ -e!4Q@ě>ZYNеd4mw٢f8p W7@ {=R;o4%=&ŠJYoQ RDU%!.De¯"dJj@'ck{z 2zL.+KFE!*:{w1vQg `n'c7Ν%{UOa ұFЫKWfSkƼ(+sml8gVf|X*c:[ԡRGx~.]Ɂ+ % ,~R#Ӎݼ!y'$QE˴ Vsċzh+sR8e1pt( 1|b]loA 4E-!P~zU @atiKАǍ? xAXds&oHLg]!#/e㕖= 6u#Twr> GPbY>OD0z| fl>Zvߣ$7 8١DPH]rwMqQ2)%wxv?QBZPQs>b|<*]qBJ3Ki YX8geɖXol%m5`JM<ύW|1QqCIIV iΡnJT@so9RP3ZRS΢?%C]vPs|S,;_M;{|C*/n^{&P!VyM#뷋V`!6 PD5<"rAK-%y.j!= :m &S++&E[ֹSOx emOxt۪ >z_g"GY ܽ'p??[BJhZ9@FJɆiuGa`@튧׳CrwԵ]#~UxF({{*ؼץ/^Bg|0EL?.;DzoBn:yHvDVuOs Ah=]})NLKe)*2oR4c]~~~g$e6ąuu@c=ָ@MW4}7PC"iY'HUrpwEL%Z&wv+&Eϙ[X&1uX_QT=Ai}D0450ED@.Y^ag.h g؜ &6L,Jxlzf4Ѫ>3&9kOE4~1dFm?գHsi5BۜR( /K.3OV"_65AhsjP3; U'uyQGqn> 1+\PS}5h,ܝ{-r*ܰ;cӤׂ-dZRuq(YO\H1D,ANrQig3: z1ё=svA>C^Ouf5,^rh`R4_)0EzN,lYTk% XWDuEyN dNw'Yk©5Z8w?*WRϢm'b#O)BO\Dd_9اAu'`5(~e'$ 8 n Ĩm+gI rr+~ ڳG \33+77@.OsqFϔ̚`TǀcTmNxoz/Od!Kl&QU7:G9aƦƱ3xꥰk`߱{wH/{ R, vkJocl5tCx'qr_Y[ؘV6tH@bb0VEG+Wt]6U%HAe!@Y]6_ىr obtnwߊ;K[wÊfʣ~ TNxc.a'aalOD?7glG¹$qMl-<@-@km5x^1ȳ? IĘV>.>gV NB A%ea)&bI 31k&^nH{BI~pAn\94lj{+9vj2Nw4)ULa8ïf,D^pg8ne\ ~ 5 E;cOw'*}$'Xf%˧M$cr/]p E=6Yr+:V n F\bÍS`kڪ$ͻet U08:A45&[GqiV+ъrg7 f^Sv[ryi{Y3mF[g] n6ԺxQFAfΖ8`T^1$d NRphL O0`t| .TuS4ݽk_ ܹ-ۀ,h|ڵſ:.g1fxNR]@V ]m['iBt*Z9m%@`'iKʗKwX9Ye!/>o٤j,"9Pdw铭`,Oz.O=dcnkCh9*,C;Q@m \<|`AgV&gWP^h@znz?txz)UVPqv]\}D9X+|{xؒe8z^A'o,`tp\,"D![ʖsP5VnMpN L투:+4[ h"\k$&YGl"0G YZ