openssh-server-8.4p1-1.30 >  A `׮p9|g@cǑ\߽=PIwrL>.#GE"!#  46ۇ HDgd8eCV 1EmoC'z%-gC.%вZ9"No|oD$$Xho1m~I  Q^׋.衏UXPo'NF@;!xDNZZrqg&{I}oa ,^Hr9|6d7AԂ;8 kCsb28c4634f0fe25a0daf2c7b501a9baae1ed50a9e835e9076c15daf6bdaff0698bd99e489bb22747499d949c1da48f0d54d1cd581옉`׮p9|_۝(%9v" hOOA]z5`D܆GEE%G;uN{XHA/v%E=@v1;ôlp =:VFImZZ^_qGJ bY-oE_2rRYCT=.8¹?  \7,bZXzE2UpK0? d  6>S i*'  $ l   z89|9#9(#7#8$@U9%U:+fU=p>x?@CFGHI<XPYd\]^bcYdefluvwLxy6zCopenssh-server8.4p11.30SSH (Secure Shell) serverSSH (Secure Shell) is a program for logging into and executing commands on a remote machine. It replaces rsh (rlogin and rsh) and provides secure encrypted communication between two untrusted hosts over an insecure network. xorg-x11 (X Window System) connections and arbitrary TCP/IP ports can also be forwarded over the secure channel. This package contains the Secure Shell daemon, which allows clients to securely connect to your server.`׃goat16SUSE Linux Enterprise 15SUSE LLC BSD-2-Clause AND MIThttps://www.suse.com/Productivity/Networking/SSHhttps://www.openssh.com/linuxx86_64 # See %pre. mkdir -p /var/lib/sshd || : if [ -x /usr/bin/systemctl ]; then /usr/bin/systemctl is-enabled sshd > /var/lib/sshd/is-enabled.rpmtmp || : else if find /etc/init.d/rc[35].d -type l -regex '.*/S[0-9]+sshd' \ -exec readlink -f {} \; | grep '/etc/init.d/sshd$' >/dev/null 2>&1 then echo "enabled" > /var/lib/sshd/is-enabled.rpmtmp || :; fi fi if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : for service in sshd.service ; do sysv_service=${service%.*} if [ ! -e /usr/lib/systemd/system/$service ] && [ ! -e /etc/init.d/$sysv_service ]; then mkdir -p /run/systemd/rpm/needs-preset touch /run/systemd/rpm/needs-preset/$service elif [ -e /etc/init.d/$sysv_service ] && [ ! -e /var/lib/systemd/migrated/$sysv_service ]; then /usr/sbin/systemd-sysv-convert --save $sysv_service || : mkdir -p /run/systemd/rpm/needs-sysv-convert touch /run/systemd/rpm/needs-sysv-convert/$service fi done fi #!/bin/bash tail -n 1 $0 | /usr/sbin/sysusers2shadow RET=$? test -f /.buildenv && exit 0 exit $RET ######## data below ######## u sshd - "SSH daemon" /var/lib/sshd PNAME=ssh SUBPNAME= SYSC_TEMPLATE=/usr/share/fillup-templates/sysconfig.$PNAME$SUBPNAME # If template not in new /usr/share/fillup-templates, fallback to old TEMPLATE_DIR if [ ! -f $SYSC_TEMPLATE ] ; then TEMPLATE_DIR=/var/adm/fillup-templates SYSC_TEMPLATE=$TEMPLATE_DIR/sysconfig.$PNAME$SUBPNAME fi SD_NAME="" if [ -x /bin/fillup ] ; then if [ -f $SYSC_TEMPLATE ] ; then echo "Updating /etc/sysconfig/$SD_NAME$PNAME ..." mkdir -p /etc/sysconfig/$SD_NAME touch /etc/sysconfig/$SD_NAME$PNAME /bin/fillup -q /etc/sysconfig/$SD_NAME$PNAME $SYSC_TEMPLATE fi else echo "ERROR: fillup not found. This should not happen. Please compare" echo "/etc/sysconfig/$PNAME and $TEMPLATE_DIR/sysconfig.$PNAME and" echo "update by hand." fi if [ -x /usr/bin/systemctl ]; then test -n "$FIRST_ARG" || FIRST_ARG="$1" [ -d /var/lib/systemd/migrated ] || mkdir -p /var/lib/systemd/migrated || : if [ "$YAST_IS_RUNNING" != "instsys" ]; then /usr/bin/systemctl daemon-reload || : fi for service in sshd.service ; do sysv_service=${service%.*} if [ -e /run/systemd/rpm/needs-preset/$service ]; then /usr/bin/systemctl preset $service || : rm "/run/systemd/rpm/needs-preset/$service" || : elif [ -e /run/systemd/rpm/needs-sysv-convert/$service ]; then /usr/sbin/systemd-sysv-convert --apply $sysv_service || : rm "/run/systemd/rpm/needs-sysv-convert/$service" || : touch /var/lib/systemd/migrated/$sysv_service || : fi done fi if [ -x /usr/bin/chkstat ]; then /usr/bin/chkstat -n --set --system /etc/ssh/sshd_config fi # Work around %service_add_post disabling the service on upgrades where # the package name changed. if [ -x /usr/bin/systemctl ] && [ -f /var/lib/sshd/is-enabled.rpmtmp ] \ && [ x$(cat /var/lib/sshd/is-enabled.rpmtmp || :) == "xenabled" ]; then systemctl enable sshd || : fi rm -f /var/lib/sshd/is-enabled.rpmtmp test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ "$FIRST_ARG" -eq 0 -a -x /usr/bin/systemctl ]; then # Package removal, not upgrade /usr/bin/systemctl --no-reload disable sshd.service || : ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_STOP_ON_REMOVAL" && . /etc/sysconfig/services test "$DISABLE_STOP_ON_REMOVAL" = yes -o \ "$DISABLE_STOP_ON_REMOVAL" = 1 && exit 0 /usr/bin/systemctl stop sshd.service ) || : fi# The openssh-fips trigger script for openssh will normally restart sshd once # it gets installed, so only restart the service here if openssh-fips is not # present. if rpm -q openssh-fips >/dev/null 2>/dev/null; then if [ $1 -eq 0 ]; then # Package removal for service in sshd.service ; do sysv_service="${service%.*}" rm "/var/lib/systemd/migrated/$sysv_service" || : done fi if [ -x /usr/bin/systemctl ]; then /usr/bin/systemctl daemon-reload || : fi else test -n "$FIRST_ARG" || FIRST_ARG="$1" if [ $1 -eq 0 ]; then # Package removal for service in sshd.service ; do sysv_service="${service%.*}" rm "/var/lib/systemd/migrated/$sysv_service" || : done fi if [ -x /usr/bin/systemctl ]; then /usr/bin/systemctl daemon-reload || : fi if [ "$FIRST_ARG" -ge 1 ]; then # Package upgrade, not uninstall if [ -x /usr/bin/systemctl ]; then ( test "$YAST_IS_RUNNING" = instsys && exit 0 test -f /etc/sysconfig/services -a \ -z "$DISABLE_RESTART_ON_UPDATE" && . /etc/sysconfig/services test "$DISABLE_RESTART_ON_UPDATE" = yes -o \ "$DISABLE_RESTART_ON_UPDATE" = 1 && exit 0 /usr/bin/systemctl try-restart sshd.service ) || : fi fi fi \@ X=& +A큤AA큤큤큤$$$A`׀`׀`׀`׀`׀`׀`׀`ׁ`׀`׀`׀`ׁ`׀`׀`׀`׀`׀`׀28d19d7f20fa597be7904cdf6d4999afb4e80e3e6d0a25af8237ab2c4fec84da05faafbe214f8e098ea66307a1cbe747f8796e3c62eba9df1ec4233ca1195bf36610510ac772c25ac58ed5f9c2e7bd04e6141b4e424305ba01ab43dd68a5eba0387af7c493f6e151cd3af375328e1f5da7d9c05f6bf09128d443a40314cad885d7cfee39eaf3c7cc14fd26b0d5bdc87002632842e916d53934b52c29e2571b4c39d26d57e62906f0613d9cb1840d249aab64eadc894b387088c688e0a5983c262bc82fb62af9360d862e14e16d89dd69bccb326fa0f886ccec58adf0969fcac0a8774e8f9ae403debf7e4d1807ddc051776552178de9cc27b3b59f02d1c4efdbedf1a33679966c18e28cd84cd671f8589059a8fae45374449ba5cb6471ca18f4238433b63d6a5b548acde065f164b6773b3e1c44b3b959608bb9db74e93ed56db3543263048fc358b3715765cc590975f077b8d08c5ea224495e6945f2d3e16f3fd24d9ed04464b0496fbd7f64ffcfc6005fdcb81752ff6aceabaeaaaebb99ae1343b3f840e3c7d4db7cc76d10d60f28af167a56421bfb2e04245d911001128fservicerootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootopenssh-8.4p1-1.30.src.rpmconfig(openssh-server)openssh-serveropenssh-server(x86-64)openssh:/usr/sbin/sshduser(sshd) !@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    /bin/sh/bin/sh/bin/sh/bin/sh/bin/sh/bin/shconfig(openssh-server)coreutilsdiffutilsfillupfindutilsgrepgreplibaudit.so.1()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.16)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.25)(64bit)libc.so.6(GLIBC_2.26)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.6)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcom_err.so.2()(64bit)libcrypt.so.1()(64bit)libcrypt.so.1(XCRYPT_2.0)(64bit)libcrypto.so.1.1()(64bit)libcrypto.so.1.1(OPENSSL_1_1_0)(64bit)libcrypto.so.1.1(OPENSSL_1_1_0d)(64bit)libcrypto.so.1.1(OPENSSL_1_1_1d)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libfido2.so.1()(64bit)libgssapi_krb5.so.2()(64bit)libgssapi_krb5.so.2(gssapi_krb5_2_MIT)(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libpam.so.0()(64bit)libpam.so.0(LIBPAM_1.0)(64bit)libselinux.so.1()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libutil.so.1()(64bit)libutil.so.1(GLIBC_2.2.5)(64bit)libz.so.1()(64bit)openssh-commonpermissionsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)shadowsysuser-shadow8.4p1-1.308.4p1-1.303.0.4-14.6.0-14.0-15.2-14.14.1 /usr/bin/chkstat -n --warn --system -e /etc/ssh/sshd_config 1>&2` ` @` @` @`x@`x@_I@_@_@_@_@_~@_m_m_cO_Z@^3^Ӝ@^Y^K^B@]|@]X]W]c@]c@]c@]@]Z@]5@\@\@\@\M\w@\v{\j@\eX@\eX@\N\J@\I\I\?\8@\-@\[@[ٙ@[ͻ[@[@[@[$@[$@[@[@[[[0@[Z@Z@Zľ@ZZqZhu@Z]@ZX@ZWQZ@Y|Y@X}@W@WW@WV@WL+@WH6W#LW@VT@T@hpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comkukuk@suse.comdmueller@suse.comhpj@suse.comkukuk@suse.comhpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comdimstar@opensuse.orgfbui@suse.comjengelh@inai.dehpj@suse.comhpj@suse.comandreas.stieger@gmx.delnussel@suse.defvogt@suse.comhpj@suse.comhpj@suse.comcrrodriguez@opensuse.orghpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comkukuk@suse.defabian@ritter-vogt.devcizek@suse.comvcizek@suse.comvcizek@suse.comvcizek@suse.comvcizek@suse.comvcizek@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.comtchvatal@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.comvcizek@suse.comcrrodriguez@opensuse.orgpmonrealgonzalez@suse.comtchvatal@suse.comtchvatal@suse.comtchvatal@suse.comtchvatal@suse.comtchvatal@suse.comtchvatal@suse.comtchvatal@suse.comschwab@suse.detchvatal@suse.comastieger@suse.compcerny@suse.comdimstar@opensuse.orgpcerny@suse.comkukuk@suse.depcerny@suse.compcerny@suse.compcerny@suse.comdimstar@opensuse.orgpcerny@suse.compcerny@suse.comrbrown@suse.comjsegitz@suse.compcerny@suse.comcrrodriguez@opensuse.orgpcerny@suse.compcerny@suse.commeissner@suse.compcerny@suse.compcerny@suse.compcerny@suse.compcerny@suse.comkukuk@suse.comastieger@suse.commeissner@suse.comledest@gmail.com- Add openssh-fix-ssh-copy-id.patch, which fixes breakage introduced in 8.4p1 (bsc#1181311).- Improve robustness of sshd init detection when upgrading from a pre-systemd distribution.- Add openssh-reenable-dh-group14-sha1-default.patch, which adds diffie-hellman-group14-sha1 key exchange back to the default list (bsc#1180958). This is needed for backwards compatibility with older platforms.- Make sure sshd is enabled correctly when upgrading from a pre-systemd distribution (bsc#1180083).- sysusers-sshd.conf: use sysusers.d configuration file to create sshd user (avoid hard dependency on shadow).- update to 8.4p1: Security ======== * ssh-agent(1): restrict ssh-agent from signing web challenges for FIDO/U2F keys. * ssh-keygen(1): Enable FIDO 2.1 credProtect extension when generating a FIDO resident key. * ssh(1), ssh-keygen(1): support for FIDO keys that require a PIN for each use. These keys may be generated using ssh-keygen using a new "verify-required" option. When a PIN-required key is used, the user will be prompted for a PIN to complete the signature operation. New Features - ----------- * sshd(8): authorized_keys now supports a new "verify-required" option to require FIDO signatures assert that the token verified that the user was present before making the signature. The FIDO protocol supports multiple methods for user-verification, but currently OpenSSH only supports PIN verification. * sshd(8), ssh-keygen(1): add support for verifying FIDO webauthn signatures. Webauthn is a standard for using FIDO keys in web browsers. These signatures are a slightly different format to plain FIDO signatures and thus require explicit support. * ssh(1): allow some keywords to expand shell-style ${ENV} environment variables. The supported keywords are CertificateFile, ControlPath, IdentityAgent and IdentityFile, plus LocalForward and RemoteForward when used for Unix domain socket paths. bz#3140 * ssh(1), ssh-agent(1): allow some additional control over the use of ssh-askpass via a new $SSH_ASKPASS_REQUIRE environment variable, including forcibly enabling and disabling its use. bz#69 * ssh(1): allow ssh_config(5)'s AddKeysToAgent keyword accept a time limit for keys in addition to its current flag options. Time- limited keys will automatically be removed from ssh-agent after their expiry time has passed. * scp(1), sftp(1): allow the -A flag to explicitly enable agent forwarding in scp and sftp. The default remains to not forward an agent, even when ssh_config enables it. * ssh(1): add a '%k' TOKEN that expands to the effective HostKey of the destination. This allows, e.g., keeping host keys in individual files using "UserKnownHostsFile ~/.ssh/known_hosts.d/%k". bz#1654 * ssh(1): add %-TOKEN, environment variable and tilde expansion to the UserKnownHostsFile directive, allowing the path to be completed by the configuration (e.g. bz#1654) * ssh-keygen(1): allow "ssh-add -d -" to read keys to be deleted from stdin. bz#3180 * sshd(8): improve logging for MaxStartups connection throttling. sshd will now log when it starts and stops throttling and periodically while in this state. bz#3055 Bugfixes - ------- * ssh(1), ssh-keygen(1): better support for multiple attached FIDO tokens. In cases where OpenSSH cannot unambiguously determine which token to direct a request to, the user is now required to select a token by touching it. In cases of operations that require a PIN to be verified, this avoids sending the wrong PIN to the wrong token and incrementing the token's PIN failure counter (tokens effectively erase their keys after too many PIN failures). * sshd(8): fix Include before Match in sshd_config; bz#3122 * ssh(1): close stdin/out/error when forking after authentication completes ("ssh -f ...") bz#3137 * ssh(1), sshd(8): limit the amount of channel input data buffered, avoiding peers that advertise large windows but are slow to read from causing high memory consumption. * ssh-agent(1): handle multiple requests sent in a single write() to the agent. * sshd(8): allow sshd_config longer than 256k * sshd(8): avoid spurious "Unable to load host key" message when sshd load a private key but no public counterpart * ssh(1): prefer the default hostkey algorithm list whenever we have a hostkey that matches its best-preference algorithm. * sshd(1): when ordering the hostkey algorithms to request from a server, prefer certificate types if the known_hosts files contain a key marked as a @cert-authority; bz#3157 * ssh(1): perform host key fingerprint comparisons for the "Are you sure you want to continue connecting (yes/no/[fingerprint])?" prompt with case sensitivity. * sshd(8): ensure that address/masklen mismatches in sshd_config yield fatal errors at daemon start time rather than later when they are evaluated. * ssh-keygen(1): ensure that certificate extensions are lexically sorted. Previously if the user specified a custom extension then the everything would be in order except the custom ones. bz#3198 * ssh(1): also compare username when checking for JumpHost loops. bz#3057 * ssh-keygen(1): preserve group/world read permission on known_hosts files across runs of "ssh-keygen -Rf /path". The old behaviour was to remove all rights for group/other. bz#3146 * ssh-keygen(1): Mention the [-a rounds] flag in the ssh-keygen manual page and usage(). * sshd(8): explicitly construct path to ~/.ssh/rc rather than relying on it being relative to the current directory, so that it can still be found if the shell startup changes its directory. bz#3185 * sshd(8): when redirecting sshd's log output to a file, undo this redirection after the session child process is forked(). Fixes missing log messages when using this feature under some circumstances. * sshd(8): start ClientAliveInterval bookkeeping before first pass through select() loop; fixed theoretical case where busy sshd may ignore timeouts from client. * ssh(1): only reset the ServerAliveInterval check when we receive traffic from the server and ignore traffic from a port forwarding client, preventing a client from keeping a connection alive when it should be terminated. bz#2265 * ssh-keygen(1): avoid spurious error message when ssh-keygen creates files outside ~/.ssh * sftp-client(1): fix off-by-one error that caused sftp downloads to make one more concurrent request that desired. This prevented using sftp(1) in unpipelined request/response mode, which is useful when debugging. bz#3054 * ssh(1), sshd(8): handle EINTR in waitfd() and timeout_connect() helpers. bz#3071 * ssh(1), ssh-keygen(1): defer creation of ~/.ssh until we attempt to write to it so we don't leave an empty .ssh directory when it's not needed. bz#3156 * ssh(1), sshd(8): fix multiplier when parsing time specifications when handling seconds after other units. bz#3171- Update openssh-8.1p1-audit.patch (bsc#1180501). This fixes occasional crashes on connection termination caused by accessing freed memory.- Support /usr/etc/pam.d- Fix build breakage caused by missing security key objects: + Modify openssh-7.7p1-cavstest-ctr.patch. + Modify openssh-7.7p1-cavstest-kdf.patch. + Add openssh-link-with-sk.patch.- Add openssh-fips-ensure-approved-moduli.patch (bsc#1177939). This ensures only approved DH parameters are used in FIPS mode.- Add openssh-8.1p1-ed25519-use-openssl-rng.patch (bsc#1173799). This uses OpenSSL's RAND_bytes() directly instead of the internal ChaCha20-based implementation to obtain random bytes for Ed25519 curve computations. This is required for FIPS compliance.- Work around %service_add_post disabling sshd on upgrade with package name change (bsc#1177039).- Fix fillup-template usage: + %post server needs to reference ssh (not sshd), which matches the sysconfig.ssh file name the package ships. + %post client does not need any fillup_ calls, as there is no client-relevant sysconfig file present. The naming of the sysconfig file (ssh instead of sshd) is unfortunate.- Use of DISABLE_RESTART_ON_UPDATE is deprecated. Replace it with %service_del_postun_without_restart- Move some Requires to the right subpackage. - Avoid ">&" bashism in %post. - Upgrade some old specfile constructs/macros and drop unnecessary %{?systemd_*}. - Trim descriptions and straighten out the grammar.- Split openssh package into openssh, openssh-common, openssh-server and openssh-clients. This allows for the ssh clients to be installed without the server component (bsc#1176434).- Version update to 8.3p1: = Potentially-incompatible changes * sftp(1): reject an argument of "-1" in the same way as ssh(1) and scp(1) do instead of accepting and silently ignoring it. = New features * sshd(8): make IgnoreRhosts a tri-state option: "yes" to ignore rhosts/shosts, "no" allow rhosts/shosts or (new) "shosts-only" to allow .shosts files but not .rhosts. * sshd(8): allow the IgnoreRhosts directive to appear anywhere in a sshd_config, not just before any Match blocks. * ssh(1): add %TOKEN percent expansion for the LocalFoward and RemoteForward keywords when used for Unix domain socket forwarding. * all: allow loading public keys from the unencrypted envelope of a private key file if no corresponding public key file is present. * ssh(1), sshd(8): prefer to use chacha20 from libcrypto where possible instead of the (slower) portable C implementation included in OpenSSH. * ssh-keygen(1): add ability to dump the contents of a binary key revocation list via "ssh-keygen -lQf /path". - Additional changes from 8.2p1 release: = Potentially-incompatible changes * ssh(1), sshd(8), ssh-keygen(1): this release removes the "ssh-rsa" (RSA/SHA1) algorithm from those accepted for certificate signatures (i.e. the client and server CASignatureAlgorithms option) and will use the rsa-sha2-512 signature algorithm by default when the ssh-keygen(1) CA signs new certificates. * ssh(1), sshd(8): this release removes diffie-hellman-group14-sha1 from the default key exchange proposal for both the client and server. * ssh-keygen(1): the command-line options related to the generation and screening of safe prime numbers used by the diffie-hellman-group-exchange-* key exchange algorithms have changed. Most options have been folded under the -O flag. * sshd(8): the sshd listener process title visible to ps(1) has changed to include information about the number of connections that are currently attempting authentication and the limits configured by MaxStartups. * ssh-sk-helper(8): this is a new binary. It is used by the FIDO/U2F support to provide address-space isolation for token middleware libraries (including the internal one). It needs to be installed in the expected path, typically under /usr/libexec or similar. = New features * This release adds support for FIDO/U2F hardware authenticators to OpenSSH. U2F/FIDO are open standards for inexpensive two-factor authentication hardware that are widely used for website authentication. In OpenSSH FIDO devices are supported by new public key types "ecdsa-sk" and "ed25519-sk", along with corresponding certificate types. * sshd(8): add an Include sshd_config keyword that allows including additional configuration files via glob(3) patterns. * ssh(1)/sshd(8): make the LE (low effort) DSCP code point available via the IPQoS directive. * ssh(1): when AddKeysToAgent=yes is set and the key contains no comment, add the key to the agent with the key's path as the comment. * ssh-keygen(1), ssh-agent(1): expose PKCS#11 key labels and X.509 subjects as key comments, rather than simply listing the PKCS#11 provider library path. * ssh-keygen(1): allow PEM export of DSA and ECDSA keys. * ssh(1), sshd(8): make zlib compile-time optional, available via the Makefile.inc ZLIB flag on OpenBSD or via the --with-zlib configure option for OpenSSH portable. * sshd(8): when clients get denied by MaxStartups, send a notification prior to the SSH2 protocol banner according to RFC4253 section 4.2. * ssh(1), ssh-agent(1): when invoking the $SSH_ASKPASS prompt program, pass a hint to the program to describe the type of desired prompt. The possible values are "confirm" (indicating that a yes/no confirmation dialog with no text entry should be shown), "none" (to indicate an informational message only), or blank for the original ssh-askpass behaviour of requesting a password/phrase. * ssh(1): allow forwarding a different agent socket to the path specified by $SSH_AUTH_SOCK, by extending the existing ForwardAgent option to accepting an explicit path or the name of an environment variable in addition to yes/no. * ssh-keygen(1): add a new signature operations "find-principals" to look up the principal associated with a signature from an allowed- signers file. * sshd(8): expose the number of currently-authenticating connections along with the MaxStartups limit in the process title visible to "ps". - Rebased patches: * openssh-7.7p1-cavstest-ctr.patch * openssh-7.7p1-cavstest-kdf.patch * openssh-7.7p1-fips.patch * openssh-7.7p1-fips_checks.patch * openssh-7.7p1-ldap.patch * openssh-7.7p1-no_fork-no_pid_file.patch * openssh-7.7p1-sftp_print_diagnostic_messages.patch * openssh-8.0p1-gssapi-keyex.patch * openssh-8.1p1-audit.patch * openssh-8.1p1-seccomp-clock_nanosleep.patch - Removed openssh-7.7p1-seed-prng.patch (bsc#1165158).- add upstream signing key to actually verify source signature- Don't recommend xauth to avoid pulling in X.- Add patches to fix the sandbox blocking glibc on 32bit platforms (boo#1164061): * openssh-8.1p1-seccomp-clock_nanosleep_time64.patch * openssh-8.1p1-seccomp-clock_gettime64.patch- Add openssh-8.1p1-use-openssl-kdf.patch (jsc#SLE-9443). This performs key derivation using OpenSSL's SSHKDF facility, which allows OpenSSH to benefit from the former's FIPS certification status.- Make sure ssh-keygen runs if SSHD_AUTO_KEYGEN variable is unset or contains an unrecognized value (bsc#1157176).- Add openssh-8.1p1-seccomp-clock_nanosleep.patch, allow clock_nanosleep glibc master implements multiple functions using that syscall making the privsep sandbox kill the preauth process.- Update openssh-7.7p1-audit.patch to fix crash (bsc#1152730). Fix by Enzo Matsumiya (ematsumiya@suse.com). This was integrated in a separate code stream merged with the Oct. 10 update; the patch was also rebased and renamed to openssh-8.1p1-audit.patch.- Add openssh-7.9p1-keygen-preserve-perms.patch (bsc#1150574). This attempts to preserve the permissions of any existing known_hosts file when modified by ssh-keygen (for instance, with -R). - Added openssh-7.9p1-revert-new-qos-defaults.patch, which reverts an upstream commit that caused compatibility issues with other software (bsc#1136402).- Run 'ssh-keygen -A' on startup only if SSHD_AUTO_KEYGEN="yes" in /etc/sysconfig/ssh. This is set to "yes" by default, but can be changed by the system administrator (bsc#1139089).- Add openssh-7.9p1-keygen-preserve-perms.patch (bsc#1150574). This attempts to preserve the permissions of any existing known_hosts file when modified by ssh-keygen (for instance, with -R).- Version update to 8.1p1: * ssh-keygen(1): when acting as a CA and signing certificates with an RSA key, default to using the rsa-sha2-512 signature algorithm. Certificates signed by RSA keys will therefore be incompatible with OpenSSH versions prior to 7.2 unless the default is overridden (using "ssh-keygen -t ssh-rsa -s ..."). * ssh(1): Allow %n to be expanded in ProxyCommand strings * ssh(1), sshd(8): Allow prepending a list of algorithms to the default set by starting the list with the '^' character, E.g. "HostKeyAlgorithms ^ssh-ed25519" * ssh-keygen(1): add an experimental lightweight signature and verification ability. Signatures may be made using regular ssh keys held on disk or stored in a ssh-agent and verified against an authorized_keys-like list of allowed keys. Signatures embed a namespace that prevents confusion and attacks between different usage domains (e.g. files vs email). * ssh-keygen(1): print key comment when extracting public key from a private key. * ssh-keygen(1): accept the verbose flag when searching for host keys in known hosts (i.e. "ssh-keygen -vF host") to print the matching host's random-art signature too. * All: support PKCS8 as an optional format for storage of private keys to disk. The OpenSSH native key format remains the default, but PKCS8 is a superior format to PEM if interoperability with non-OpenSSH software is required, as it may use a less insecure key derivation function than PEM's. - Additional changes from 8.0p1 release: * scp(1): Add "-T" flag to disable client-side filtering of server file list. * sshd(8): Remove support for obsolete "host/port" syntax. * ssh(1), ssh-agent(1), ssh-add(1): Add support for ECDSA keys in PKCS#11 tokens. * ssh(1), sshd(8): Add experimental quantum-computing resistant key exchange method, based on a combination of Streamlined NTRU Prime 4591^761 and X25519. * ssh-keygen(1): Increase the default RSA key size to 3072 bits, following NIST Special Publication 800-57's guidance for a 128-bit equivalent symmetric security level. * ssh(1): Allow "PKCS11Provider=none" to override later instances of the PKCS11Provider directive in ssh_config, * sshd(8): Add a log message for situations where a connection is dropped for attempting to run a command but a sshd_config ForceCommand=internal-sftp restriction is in effect. * ssh(1): When prompting whether to record a new host key, accept the key fingerprint as a synonym for "yes". This allows the user to paste a fingerprint obtained out of band at the prompt and have the client do the comparison for you. * ssh-keygen(1): When signing multiple certificates on a single command-line invocation, allow automatically incrementing the certificate serial number. * scp(1), sftp(1): Accept -J option as an alias to ProxyJump on the scp and sftp command-lines. * ssh-agent(1), ssh-pkcs11-helper(8), ssh-add(1): Accept "-v" command-line flags to increase the verbosity of output; pass verbose flags though to subprocesses, such as ssh-pkcs11-helper started from ssh-agent. * ssh-add(1): Add a "-T" option to allowing testing whether keys in an agent are usable by performing a signature and a verification. * sftp-server(8): Add a "lsetstat@openssh.com" protocol extension that replicates the functionality of the existing SSH2_FXP_SETSTAT operation but does not follow symlinks. * sftp(1): Add "-h" flag to chown/chgrp/chmod commands to request they do not follow symlinks. * sshd(8): Expose $SSH_CONNECTION in the PAM environment. This makes the connection 4-tuple available to PAM modules that wish to use it in decision-making. * sshd(8): Add a ssh_config "Match final" predicate Matches in same pass as "Match canonical" but doesn't require hostname canonicalisation be enabled. * sftp(1): Support a prefix of '@' to suppress echo of sftp batch commands. * ssh-keygen(1): When printing certificate contents using "ssh-keygen -Lf /path/certificate", include the algorithm that the CA used to sign the cert. - Rebased patches: * openssh-7.7p1-IPv6_X_forwarding.patch * openssh-7.7p1-X_forward_with_disabled_ipv6.patch * openssh-7.7p1-cavstest-ctr.patch * openssh-7.7p1-cavstest-kdf.patch * openssh-7.7p1-disable_openssl_abi_check.patch * openssh-7.7p1-fips.patch * openssh-7.7p1-fips_checks.patch * openssh-7.7p1-hostname_changes_when_forwarding_X.patch * openssh-7.7p1-ldap.patch * openssh-7.7p1-seed-prng.patch * openssh-7.7p1-sftp_force_permissions.patch * openssh-7.7p1-sftp_print_diagnostic_messages.patch * openssh-8.0p1-gssapi-keyex.patch (formerly openssh-7.7p1-gssapi_key_exchange.patch) * openssh-8.1p1-audit.patch (formerly openssh-7.7p1-audit.patch) - Removed patches (integrated upstream): * 0001-upstream-Fix-two-race-conditions-in-sshd-relating-to.patch * openssh-7.7p1-seccomp_ioctl_s390_EP11.patch * openssh-7.9p1-CVE-2018-20685.patch * openssh-7.9p1-brace-expansion.patch * openssh-CVE-2019-6109-force-progressmeter-update.patch * openssh-CVE-2019-6109-sanitize-scp-filenames.patch * openssh-CVE-2019-6111-scp-client-wildcard.patch - Removed patches (obsolete): * openssh-openssl-1_0_0-compatibility.patch- don't install SuSEfirewall2 service on Factory, since SuSEfirewall2 has been replaced by firewalld, see [1]. [1]: https://lists.opensuse.org/opensuse-factory/2019-01/msg00490.html- ssh-askpass: Try a fallback if the other option is not available- Fix a crash with GSSAPI key exchange (bsc#1136104) * modify openssh-7.7p1-gssapi_key_exchange.patch- Fix a double free() in the KDF CAVS testing tool (bsc#1065237) * modify openssh-7.7p1-cavstest-kdf.patch- Minor clean-up of the fips patches, modified openssh-7.7p1-fips.patch openssh-7.7p1-fips_checks.patch- Fix two race conditions in sshd relating to SIGHUP (bsc#1119183) * 0001-upstream-Fix-two-race-conditions-in-sshd-relating-to.patch- Correctly filter out non-compliant algorithms when in FIPS mode (bsc#1126397) * A hunk was applied to a wrong place due to a patch fuzz when the fips patch was being ported to openssh 7.9p1 - update openssh-7.7p1-fips.patch- Remove the "KexDHMin" config keyword (bsc#1127180) It used to allow lowering of the minimal allowed DH group size, which was increased to 2048 by upstream in the light of the Logjam attack. The code was broken since the upgrade to 7.6p1, but nobody noticed. As apparently no one needs the functionality any more, let's drop the patch. It's still possible to use the fixed 1024-bit diffie-hellman-group1-sha1 key exchange method when working with legacy systems. - drop openssh-7.7p1-disable_short_DH_parameters.patch - updated patches: openssh-7.7p1-fips.patch openssh-7.7p1-fips_checks.patch openssh-7.7p1-gssapi_key_exchange.patch- Handle brace expansion in scp when checking that filenames sent by the server side match what the client requested [bsc#1125687] * openssh-7.9p1-brace-expansion.patch- Updated security fixes: * [bsc#1121816, CVE-2019-6109] Sanitize scp filenames via snmprintf and have progressmeter force an update at the beginning and end of each transfer. Added patches: - openssh-CVE-2019-6109-sanitize-scp-filenames.patch - openssh-CVE-2019-6109-force-progressmeter-update.patch * [bsc#1121821, CVE-2019-6111] Check in scp client that filenames sent during remote->local directory copies satisfy the wildcard specified by the user. Added patch: - openssh-CVE-2019-6111-scp-client-wildcard.patch * Removed openssh-7.9p1-scp-name-validator.patch- Change the askpass wrapper to not use x11 interface: * by default we use the -gnome UI (which is gtk3 only, no gnome dep) * if desktop is KDE/LxQt we use ksshaskpass- Remove old conditionals- Move ssh-ldap* man pages into openssh-helpers [bsc#1051531]- Allow root login by default [bsc#1118114, bsc#1121196] * Added/updated previous patch openssh-7.7p1-allow_root_password_login.patch * Mention the change in README.SUSE- Added SLE conditionals in the spec files: * Keep gtk2-devel in openssh-askpass-gnome in SLE * Keep krb5-mini-devel in SLE - Removed obsolete configure options: * SSH protocol 1 --with-ssh1 * Smart card --with-opensc - Cleaned spec file with spec-cleaner- Security fix: * [bsc#1121816, CVE-2019-6109] scp client spoofing via object name * [bsc#1121818, CVE-2019-6110] scp client spoofing via stderr * [bsc#1121821, CVE-2019-6111] scp client missing received object name validation * Added patch openssh-7.9p1-scp-name-validator.patch- Security fix: [bsc#1121571, CVE-2018-20685] * The scp client allows remote SSH servers to bypass intended access restrictions * Added patch openssh-7.9p1-CVE-2018-20685.patch- Added compatibility with SuSEfirewall2 [bsc#1118044]- Update the firewall rules in Tumbleweed- Fix build with openssl < 1.1.0 * add openssh-openssl-1_0_0-compatibility.patch- openssh-7.7p1-audit.patch: fix sshd fatal error in mm_answer_keyverify: buffer error: incomplete message [bnc#1114008]- Version update to 7.9p1 * ssh(1), sshd(8): the setting of the new CASignatureAlgorithms option (see below) bans the use of DSA keys as certificate authorities. * sshd(8): the authentication success/failure log message has changed format slightly. It now includes the certificate fingerprint (previously it included only key ID and CA key fingerprint). * ssh(1), sshd(8): allow most port numbers to be specified using service names from getservbyname(3) (typically /etc/services). * sshd(8): support signalling sessions via the SSH protocol. A limited subset of signals is supported and only for login or command sessions (i.e. not subsystems) that were not subject to a forced command via authorized_keys or sshd_config. bz#1424 * ssh(1): support "ssh -Q sig" to list supported signature options. Also "ssh -Q help" to show the full set of supported queries. * ssh(1), sshd(8): add a CASignatureAlgorithms option for the client and server configs to allow control over which signature formats are allowed for CAs to sign certificates. For example, this allows banning CAs that sign certificates using the RSA-SHA1 signature algorithm. * sshd(8), ssh-keygen(1): allow key revocation lists (KRLs) to revoke keys specified by SHA256 hash. * ssh-keygen(1): allow creation of key revocation lists directly from base64-encoded SHA256 fingerprints. This supports revoking keys using only the information contained in sshd(8) authentication log messages. - Removed obsolete configuration option --with-tcp-wrappers, and - -with-opensc for s390 and s390x. - Removed patch merged upstream * openssh-7.7p1-openssl_1.1.0.patch - Refreshed patches * openssh-7.7p1-audit.patch * openssh-7.7p1-disable_short_DH_parameters.patch * openssh-7.7p1-fips.patch * openssh-7.7p1-gssapi_key_exchange.patch * openssh-7.7p1-seccomp_ipc_flock.patch * openssh-7.7p1-cavstest-ctr.patch * openssh-7.7p1-ldap.patch- Mention upstream bugs on multiple local patches - Adjust service to not spam restart and reload only on fails- Update openssh-7.7p1-sftp_force_permissions.patch from the upstream bug, and mention the bug in the spec- Drop patch openssh-7.7p1-allow_root_password_login.patch * There is no reason to set less secure default value, if users need the behaviour they can still set it up themselves - Drop patch openssh-7.7p1-blocksigalrm.patch * We had a bug way in past about this but it was never reproduced or even confirmed in the ticket, thus rather drop the patch- Disable ssh1 protocol support as neither RH or Debian enable this protocol by default anymore either.- Remove the mention of the SLE12 in the README.SUSE - Install firewall rules only when really needed ( ::1) before they are matched against known_hosts. bz#2763 * ssh(1): Don't accept junk after "yes" or "no" responses to hostkey prompts. bz#2803 * sftp(1): Have sftp print a warning about shell cleanliness when decoding the first packet fails, which is usually caused by shells polluting stdout of non-interactive startups. bz#2800 * ssh(1)/sshd(8): Switch timers in packet code from using wall-clock time to monotonic time, allowing the packet layer to better function over a clock step and avoiding possible integer overflows during steps. * Numerous manual page fixes and improvements.- Use TIRPC on suse_version >= 1500: sunrpc is deprecated and should be replaced by TIRPC.- additional rebased patches (bsc#1080779) * auditing support * LDAP integration * various distribution tweaks from SLE12 (X forwarding over IPv6, sftp forced permissions and verbose batch mode)- Use %license instead of %doc [bsc#1082318]- add OpenSSL 1.0 to 1.1 shim to remove dependency on old OpenSSL (update tracker: bsc#1080779)- Add missing crypto hardware enablement patches for IBM mainframes (FATE#323902)- add missing part of systemd integration (unit type)- BuildRequire pkgconfig(libsystemd) instead of systemd-devel: allow the scheduler to pick systemd-mini flavors to get build going.- Replace forgotten references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468) - tighten configuration access rights- Update to vanilla 7.6p1 Most important changes (more details below): * complete removal of the ancient SSHv1 protocol * sshd(8) cannot run without privilege separation * removal of suport for arcfourm blowfish and CAST ciphers and RIPE-MD160 HMAC * refuse RSA keys shorter than 1024 bits Distilled upstream log: - OpenSSH 7.3 - --- Security * sshd(8): Mitigate a potential denial-of-service attack against the system's crypt(3) function via sshd(8). An attacker could send very long passwords that would cause excessive CPU use in crypt(3). sshd(8) now refuses to accept password authentication requests of length greater than 1024 characters. Independently reported by Tomas Kuthan (Oracle), Andres Rojas and Javier Nieto. * sshd(8): Mitigate timing differences in password authentication that could be used to discern valid from invalid account names when long passwords were sent and particular password hashing algorithms are in use on the server. CVE-2016-6210, reported by EddieEzra.Harari at verint.com * ssh(1), sshd(8): Fix observable timing weakness in the CBC padding oracle countermeasures. Reported by Jean Paul Degabriele, Kenny Paterson, Torben Hansen and Martin Albrecht. Note that CBC ciphers are disabled by default and only included for legacy compatibility. * ssh(1), sshd(8): Improve operation ordering of MAC verification for Encrypt-then-MAC (EtM) mode transport MAC algorithms to verify the MAC before decrypting any ciphertext. This removes the possibility of timing differences leaking facts about the plaintext, though no such leakage has been observed. Reported by Jean Paul Degabriele, Kenny Paterson, Torben Hansen and Martin Albrecht. * sshd(8): (portable only) Ignore PAM environment vars when UseLogin=yes. If PAM is configured to read user-specified environment variables and UseLogin=yes in sshd_config, then a hostile local user may attack /bin/login via LD_PRELOAD or similar environment variables set via PAM. CVE-2015-8325, found by Shayan Sadigh. - --- New Features * ssh(1): Add a ProxyJump option and corresponding -J command-line flag to allow simplified indirection through a one or more SSH bastions or "jump hosts". * ssh(1): Add an IdentityAgent option to allow specifying specific agent sockets instead of accepting one from the environment. * ssh(1): Allow ExitOnForwardFailure and ClearAllForwardings to be optionally overridden when using ssh -W. bz#2577 * ssh(1), sshd(8): Implement support for the IUTF8 terminal mode as per draft-sgtatham-secsh-iutf8-00. * ssh(1), sshd(8): Add support for additional fixed Diffie-Hellman 2K, 4K and 8K groups from draft-ietf-curdle-ssh-kex-sha2-03. * ssh-keygen(1), ssh(1), sshd(8): support SHA256 and SHA512 RSA signatures in certificates; * ssh(1): Add an Include directive for ssh_config(5) files. * ssh(1): Permit UTF-8 characters in pre-authentication banners sent from the server. bz#2058 - --- Bugfixes * ssh(1), sshd(8): Reduce the syslog level of some relatively common protocol events from LOG_CRIT. bz#2585 * sshd(8): Refuse AuthenticationMethods="" in configurations and accept AuthenticationMethods=any for the default behaviour of not requiring multiple authentication. bz#2398 * sshd(8): Remove obsolete and misleading "POSSIBLE BREAK-IN ATTEMPT!" message when forward and reverse DNS don't match. bz#2585 * ssh(1): Close ControlPersist background process stderr except in debug mode or when logging to syslog. bz#1988 * misc: Make PROTOCOL description for direct-streamlocal@openssh.com channel open messages match deployed code. bz#2529 * ssh(1): Deduplicate LocalForward and RemoteForward entries to fix failures when both ExitOnForwardFailure and hostname canonicalisation are enabled. bz#2562 * sshd(8): Remove fallback from moduli to obsolete "primes" file that was deprecated in 2001. bz#2559. * sshd_config(5): Correct description of UseDNS: it affects ssh hostname processing for authorized_keys, not known_hosts; bz#2554 * ssh(1): Fix authentication using lone certificate keys in an agent without corresponding private keys on the filesystem. bz#2550 * sshd(8): Send ClientAliveInterval pings when a time-based RekeyLimit is set; previously keepalive packets were not being sent. bz#2252 - --- Portability * ssh(1), sshd(8): Fix compilation by automatically disabling ciphers not supported by OpenSSL. bz#2466 * misc: Fix compilation failures on some versions of AIX's compiler related to the definition of the VA_COPY macro. bz#2589 * sshd(8): Whitelist more architectures to enable the seccomp-bpf sandbox. bz#2590 * ssh-agent(1), sftp-server(8): Disable process tracing on Solaris using setpflags(__PROC_PROTECT, ...). bz#2584 * sshd(8): On Solaris, don't call Solaris setproject() with UsePAM=yes it's PAM's responsibility. bz#2425 - OpenSSH 7.4 - --- Potentially-incompatible changes * ssh(1): Remove 3des-cbc from the client's default proposal. 64-bit block ciphers are not safe in 2016 and we don't want to wait until attacks like SWEET32 are extended to SSH. As 3des-cbc was the only mandatory cipher in the SSH RFCs, this may cause problems connecting to older devices using the default configuration, but it's highly likely that such devices already need explicit configuration for key exchange and hostkey algorithms already anyway. * sshd(8): Remove support for pre-authentication compression. Doing compression early in the protocol probably seemed reasonable in the 1990s, but today it's clearly a bad idea in terms of both cryptography (cf. multiple compression oracle attacks in TLS) and attack surface. Pre-auth compression support has been disabled by default for >10 years. Support remains in the client. * ssh-agent will refuse to load PKCS#11 modules outside a whitelist of trusted paths by default. The path whitelist may be specified at run-time. * sshd(8): When a forced-command appears in both a certificate and an authorized keys/principals command= restriction, sshd will now refuse to accept the certificate unless they are identical. The previous (documented) behaviour of having the certificate forced-command override the other could be a bit confusing and error-prone. * sshd(8): Remove the UseLogin configuration directive and support for having /bin/login manage login sessions. - --- Security * ssh-agent(1): Will now refuse to load PKCS#11 modules from paths outside a trusted whitelist (run-time configurable). Requests to load modules could be passed via agent forwarding and an attacker could attempt to load a hostile PKCS#11 module across the forwarded agent channel: PKCS#11 modules are shared libraries, so this would result in code execution on the system running the ssh-agent if the attacker has control of the forwarded agent-socket (on the host running the sshd server) and the ability to write to the filesystem of the host running ssh-agent (usually the host running the ssh client). Reported by Jann Horn of Project Zero. * sshd(8): When privilege separation is disabled, forwarded Unix- domain sockets would be created by sshd(8) with the privileges of 'root' instead of the authenticated user. This release refuses Unix-domain socket forwarding when privilege separation is disabled (Privilege separation has been enabled by default for 14 years). Reported by Jann Horn of Project Zero. * sshd(8): Avoid theoretical leak of host private key material to privilege-separated child processes via realloc() when reading keys. No such leak was observed in practice for normal-sized keys, nor does a leak to the child processes directly expose key material to unprivileged users. Reported by Jann Horn of Project Zero. * sshd(8): The shared memory manager used by pre-authentication compression support had a bounds checks that could be elided by some optimising compilers. Additionally, this memory manager was incorrectly accessible when pre-authentication compression was disabled. This could potentially allow attacks against the privileged monitor process from the sandboxed privilege-separation process (a compromise of the latter would be required first). This release removes support for pre-authentication compression from sshd(8). Reported by Guido Vranken using the Stack unstable optimisation identification tool (http://css.csail.mit.edu/stack/) * sshd(8): Fix denial-of-service condition where an attacker who sends multiple KEXINIT messages may consume up to 128MB per connection. Reported by Shi Lei of Gear Team, Qihoo 360. * sshd(8): Validate address ranges for AllowUser and DenyUsers directives at configuration load time and refuse to accept invalid ones. It was previously possible to specify invalid CIDR address ranges (e.g. user@127.1.2.3/55) and these would always match, possibly resulting in granting access where it was not intended. Reported by Laurence Parry. - --- New Features * ssh(1): Add a proxy multiplexing mode to ssh(1) inspired by the version in PuTTY by Simon Tatham. This allows a multiplexing client to communicate with the master process using a subset of the SSH packet and channels protocol over a Unix-domain socket, with the main process acting as a proxy that translates channel IDs, etc. This allows multiplexing mode to run on systems that lack file- descriptor passing (used by current multiplexing code) and potentially, in conjunction with Unix-domain socket forwarding, with the client and multiplexing master process on different machines. Multiplexing proxy mode may be invoked using "ssh -O proxy ..." * sshd(8): Add a sshd_config DisableForwarding option that disables X11, agent, TCP, tunnel and Unix domain socket forwarding, as well as anything else we might implement in the future. Like the 'restrict' authorized_keys flag, this is intended to be a simple and future-proof way of restricting an account. * sshd(8), ssh(1): Support the "curve25519-sha256" key exchange method. This is identical to the currently-supported method named "curve25519-sha256@libssh.org". * sshd(8): Improve handling of SIGHUP by checking to see if sshd is already daemonised at startup and skipping the call to daemon(3) if it is. This ensures that a SIGHUP restart of sshd(8) will retain the same process-ID as the initial execution. sshd(8) will also now unlink the PidFile prior to SIGHUP restart and re-create it after a successful restart, rather than leaving a stale file in the case of a configuration error. bz#2641 * sshd(8): Allow ClientAliveInterval and ClientAliveCountMax directives to appear in sshd_config Match blocks. * sshd(8): Add %-escapes to AuthorizedPrincipalsCommand to match those supported by AuthorizedKeysCommand (key, key type, fingerprint, etc.) and a few more to provide access to the contents of the certificate being offered. * Added regression tests for string matching, address matching and string sanitisation functions. * Improved the key exchange fuzzer harness. - --- Bugfixes * ssh(1): Allow IdentityFile to successfully load and use certificates that have no corresponding bare public key. bz#2617 certificate id_rsa-cert.pub (and no id_rsa.pub). * ssh(1): Fix public key authentication when multiple authentication is in use and publickey is not just the first method attempted. bz#2642 * regress: Allow the PuTTY interop tests to run unattended. bz#2639 * ssh-agent(1), ssh(1): improve reporting when attempting to load keys from PKCS#11 tokens with fewer useless log messages and more detail in debug messages. bz#2610 * ssh(1): When tearing down ControlMaster connections, don't pollute stderr when LogLevel=quiet. * sftp(1): On ^Z wait for underlying ssh(1) to suspend before suspending sftp(1) to ensure that ssh(1) restores the terminal mode correctly if suspended during a password prompt. * ssh(1): Avoid busy-wait when ssh(1) is suspended during a password prompt. * ssh(1), sshd(8): Correctly report errors during sending of ext- info messages. * sshd(8): fix NULL-deref crash if sshd(8) received an out-of- sequence NEWKEYS message. * sshd(8): Correct list of supported signature algorithms sent in the server-sig-algs extension. bz#2547 * sshd(8): Fix sending ext_info message if privsep is disabled. * sshd(8): more strictly enforce the expected ordering of privilege separation monitor calls used for authentication and allow them only when their respective authentication methods are enabled in the configuration * sshd(8): Fix uninitialised optlen in getsockopt() call; harmless on Unix/BSD but potentially crashy on Cygwin. * Fix false positive reports caused by explicit_bzero(3) not being recognised as a memory initialiser when compiled with - fsanitize-memory. * sshd_config(5): Use 2001:db8::/32, the official IPv6 subnet for configuration examples. - --- Portability * On environments configured with Turkish locales, fall back to the C/POSIX locale to avoid errors in configuration parsing caused by that locale's unique handling of the letters 'i' and 'I'. bz#2643 * sftp-server(8), ssh-agent(1): Deny ptrace on OS X using ptrace(PT_DENY_ATTACH, ..) * ssh(1), sshd(8): Unbreak AES-CTR ciphers on old (~0.9.8) OpenSSL. * Fix compilation for libcrypto compiled without RIPEMD160 support. * contrib: Add a gnome-ssh-askpass3 with GTK+3 support. bz#2640 * sshd(8): Improve PRNG reseeding across privilege separation and force libcrypto to obtain a high-quality seed before chroot or sandboxing. * All: Explicitly test for broken strnvis. NetBSD added an strnvis and unfortunately made it incompatible with the existing one in OpenBSD and Linux's libbsd (the former having existed for over ten years). Try to detect this mess, and assume the only safe option if we're cross compiling. - OpenSSH 7.5 - --- Potentially-incompatible changes * This release deprecates the sshd_config UsePrivilegeSeparation option, thereby making privilege separation mandatory. Privilege separation has been on by default for almost 15 years and sandboxing has been on by default for almost the last five. * The format of several log messages emitted by the packet code has changed to include additional information about the user and their authentication state. Software that monitors ssh/sshd logs may need to account for these changes. For example: Connection closed by user x 1.1.1.1 port 1234 [preauth] Connection closed by authenticating user x 10.1.1.1 port 1234 [preauth] Connection closed by invalid user x 1.1.1.1 port 1234 [preauth] Affected messages include connection closure, timeout, remote disconnection, negotiation failure and some other fatal messages generated by the packet code. * [Portable OpenSSH only] This version removes support for building against OpenSSL versions prior to 1.0.1. OpenSSL stopped supporting versions prior to 1.0.1 over 12 months ago (i.e. they no longer receive fixes for security bugs). - --- Security * ssh(1), sshd(8): Fix weakness in CBC padding oracle countermeasures that allowed a variant of the attack fixed in OpenSSH 7.3 to proceed. Note that the OpenSSH client disables CBC ciphers by default, sshd offers them as lowest-preference options and will remove them by default entriely in the next release. Reported by Jean Paul Degabriele, Kenny Paterson, Martin Albrecht and Torben Hansen of Royal Holloway, University of London. * sftp-client(1): [portable OpenSSH only] On Cygwin, a client making a recursive file transfer could be maniuplated by a hostile server to perform a path-traversal attack. creating or modifying files outside of the intended target directory. Reported by Jann Horn of Google Project Zero. - --- New Features * ssh(1), sshd(8): Support "=-" syntax to easily remove methods from algorithm lists, e.g. Ciphers=-*cbc. bz#2671 - --- Bugfixes * sshd(1): Fix NULL dereference crash when key exchange start messages are sent out of sequence. * ssh(1), sshd(8): Allow form-feed characters to appear in configuration files. * sshd(8): Fix regression in OpenSSH 7.4 support for the server-sig-algs extension, where SHA2 RSA signature methods were not being correctly advertised. bz#2680 * ssh(1), ssh-keygen(1): Fix a number of case-sensitivity bugs in known_hosts processing. bz#2591 bz#2685 * ssh(1): Allow ssh to use certificates accompanied by a private key file but no corresponding plain *.pub public key. bz#2617 * ssh(1): When updating hostkeys using the UpdateHostKeys option, accept RSA keys if HostkeyAlgorithms contains any RSA keytype. Previously, ssh could ignore RSA keys when only the ssh-rsa-sha2-* methods were enabled in HostkeyAlgorithms and not the old ssh-rsa method. bz#2650 * ssh(1): Detect and report excessively long configuration file lines. bz#2651 * Merge a number of fixes found by Coverity and reported via Redhat and FreeBSD. Includes fixes for some memory and file descriptor leaks in error paths. bz#2687 * ssh-keyscan(1): Correctly hash hosts with a port number. bz#2692 * ssh(1), sshd(8): When logging long messages to stderr, don't truncate "\r\n" if the length of the message exceeds the buffer. bz#2688 * ssh(1): Fully quote [host]:port in generated ProxyJump/-J command- line; avoid confusion over IPv6 addresses and shells that treat square bracket characters specially. * ssh-keygen(1): Fix corruption of known_hosts when running "ssh-keygen -H" on a known_hosts containing already-hashed entries. * Fix various fallout and sharp edges caused by removing SSH protocol 1 support from the server, including the server banner string being incorrectly terminated with only \n (instead of \r\n), confusing error messages from ssh-keyscan bz#2583 and a segfault in sshd if protocol v.1 was enabled for the client and sshd_config contained references to legacy keys bz#2686. * ssh(1), sshd(8): Free fd_set on connection timeout. bz#2683 * sshd(8): Fix Unix domain socket forwarding for root (regression in OpenSSH 7.4). * sftp(1): Fix division by zero crash in "df" output when server returns zero total filesystem blocks/inodes. * ssh(1), ssh-add(1), ssh-keygen(1), sshd(8): Translate OpenSSL errors encountered during key loading to more meaningful error codes. bz#2522 bz#2523 * ssh-keygen(1): Sanitise escape sequences in key comments sent to printf but preserve valid UTF-8 when the locale supports it; bz#2520 * ssh(1), sshd(8): Return reason for port forwarding failures where feasible rather than always "administratively prohibited". bz#2674 * sshd(8): Fix deadlock when AuthorizedKeysCommand or AuthorizedPrincipalsCommand produces a lot of output and a key is matched early. bz#2655 * Regression tests: several reliability fixes. bz#2654 bz#2658 bz#2659 * ssh(1): Fix typo in ~C error message for bad port forward cancellation. bz#2672 * ssh(1): Show a useful error message when included config files can't be opened; bz#2653 * sshd(8): Make sshd set GSSAPIStrictAcceptorCheck=yes as the manual page (previously incorrectly) advertised. bz#2637 * sshd_config(5): Repair accidentally-deleted mention of %k token in AuthorizedKeysCommand; bz#2656 * sshd(8): Remove vestiges of previously removed LOGIN_PROGRAM; bz#2665 * ssh-agent(1): Relax PKCS#11 whitelist to include libexec and common 32-bit compatibility library directories. * sftp-client(1): Fix non-exploitable integer overflow in SSH2_FXP_NAME response handling. * ssh-agent(1): Fix regression in 7.4 of deleting PKCS#11-hosted keys. It was not possible to delete them except by specifying their full physical path. bz#2682 - --- Portability * sshd(8): Avoid sandbox errors for Linux S390 systems using an ICA crypto coprocessor. * sshd(8): Fix non-exploitable weakness in seccomp-bpf sandbox arg inspection. * ssh(1): Fix X11 forwarding on OSX where X11 was being started by launchd. bz#2341 * ssh-keygen(1), ssh(1), sftp(1): Fix output truncation for various that contain non-printable characters where the codeset in use is ASCII. * build: Fix builds that attempt to link a kerberised libldns. bz#2603 * build: Fix compilation problems caused by unconditionally defining _XOPEN_SOURCE in wide character detection. * sshd(8): Fix sandbox violations for clock_gettime VSDO syscall fallback on some Linux/X32 kernels. bz#2142 - OpenSSH 7.6 - --- Potentially-incompatible changes This release includes a number of changes that may affect existing configurations: * ssh(1): delete SSH protocol version 1 support, associated configuration options and documentation. * ssh(1)/sshd(8): remove support for the hmac-ripemd160 MAC. * ssh(1)/sshd(8): remove support for the arcfour, blowfish and CAST ciphers. * Refuse RSA keys <1024 bits in length and improve reporting for keys that do not meet this requirement. * ssh(1): do not offer CBC ciphers by default. - --- Security * sftp-server(8): in read-only mode, sftp-server was incorrectly permitting creation of zero-length files. Reported by Michal Zalewski. - --- New Features * ssh(1): add RemoteCommand option to specify a command in the ssh config file instead of giving it on the client's command line. This allows the configuration file to specify the command that will be executed on the remote host. * sshd(8): add ExposeAuthInfo option that enables writing details of the authentication methods used (including public keys where applicable) to a file that is exposed via a $SSH_USER_AUTH environment variable in the subsequent session. * ssh(1): add support for reverse dynamic forwarding. In this mode, ssh will act as a SOCKS4/5 proxy and forward connections to destinations requested by the remote SOCKS client. This mode is requested using extended syntax for the - R and RemoteForward options and, because it is implemented solely at the client, does not require the server be updated to be supported. * sshd(8): allow LogLevel directive in sshd_config Match blocks; bz#2717 * ssh-keygen(1): allow inclusion of arbitrary string or flag certificate extensions and critical options. * ssh-keygen(1): allow ssh-keygen to use a key held in ssh-agent as a CA when signing certificates. bz#2377 * ssh(1)/sshd(8): allow IPQoS=none in ssh/sshd to not set an explicit ToS/DSCP value and just use the operating system default. * ssh-add(1): added -q option to make ssh-add quiet on success. * ssh(1): expand the StrictHostKeyChecking option with two new settings. The first "accept-new" will automatically accept hitherto-unseen keys but will refuse connections for changed or invalid hostkeys. This is a safer subset of the current behaviour of StrictHostKeyChecking=no. The second setting "off", is a synonym for the current behaviour of StrictHostKeyChecking=no: accept new host keys, and continue connection for hosts with incorrect hostkeys. A future release will change the meaning of StrictHostKeyChecking=no to the behaviour of "accept-new". bz#2400 * ssh(1): add SyslogFacility option to ssh(1) matching the equivalent option in sshd(8). bz#2705 - --- Bugfixes * ssh(1): use HostKeyAlias if specified instead of hostname for matching host certificate principal names; bz#2728 * sftp(1): implement sorting for globbed ls; bz#2649 * ssh(1): add a user@host prefix to client's "Permission denied" messages, useful in particular when using "stacked" connections (e.g. ssh -J) where it's not clear which host is denying. bz#2720 * ssh(1): accept unknown EXT_INFO extension values that contain \0 characters. These are legal, but would previously cause fatal connection errors if received. * ssh(1)/sshd(8): repair compression statistics printed at connection exit * sftp(1): print '?' instead of incorrect link count (that the protocol doesn't provide) for remote listings. bz#2710 * ssh(1): return failure rather than fatal() for more cases during session multiplexing negotiations. Causes the session to fall back to a non-mux connection if they occur. bz#2707 * ssh(1): mention that the server may send debug messages to explain public key authentication problems under some circumstances; bz#2709 * Translate OpenSSL error codes to better report incorrect passphrase errors when loading private keys; bz#2699 * sshd(8): adjust compatibility patterns for WinSCP to correctly identify versions that implement only the legacy DH group exchange scheme. bz#2748 * ssh(1): print the "Killed by signal 1" message only at LogLevel verbose so that it is not shown at the default level; prevents it from appearing during ssh -J and equivalent ProxyCommand configs. bz#1906, bz#2744 * ssh-keygen(1): when generating all hostkeys (ssh-keygen -A), clobber existing keys if they exist but are zero length. zero-length keys could previously be made if ssh-keygen failed or was interrupted part way through generating them. bz#2561 * ssh(1): fix pledge(2) violation in the escape sequence "~&" used to place the current session in the background. * ssh-keyscan(1): avoid double-close() on file descriptors; bz#2734 * sshd(8): avoid reliance on shared use of pointers shared between monitor and child sshd processes. bz#2704 * sshd_config(8): document available AuthenticationMethods; bz#2453 * ssh(1): avoid truncation in some login prompts; bz#2768 * sshd(8): Fix various compilations failures, inc bz#2767 * ssh(1): make "--" before the hostname terminate argument processing after the hostname too. * ssh-keygen(1): switch from aes256-cbc to aes256-ctr for encrypting new-style private keys. Fixes problems related to private key handling for no-OpenSSL builds. bz#2754 * ssh(1): warn and do not attempt to use keys when the public and private halves do not match. bz#2737 * sftp(1): don't print verbose error message when ssh disconnects from under sftp. bz#2750 * sshd(8): fix keepalive scheduling problem: activity on a forwarded port from preventing the keepalive from being sent; bz#2756 * sshd(8): when started without root privileges, don't require the privilege separation user or path to exist. Makes running the regression tests easier without touching the filesystem. * Make integrity.sh regression tests more robust against timeouts. bz#2658 * ssh(1)/sshd(8): correctness fix for channels implementation: accept channel IDs greater than 0x7FFFFFFF. - --- Portability * sshd(9): drop two more privileges in the Solaris sandbox: PRIV_DAX_ACCESS and PRIV_SYS_IB_INFO; bz#2723 * sshd(8): expose list of completed authentication methods to PAM via the SSH_AUTH_INFO_0 PAM environment variable. bz#2408 * ssh(1)/sshd(8): fix several problems in the tun/tap forwarding code, mostly to do with host/network byte order confusion. bz#2735 * Add --with-cflags-after and --with-ldflags-after configure flags to allow setting CFLAGS/LDFLAGS after configure has completed. These are useful for setting sanitiser/fuzzing options that may interfere with configure's operation. * sshd(8): avoid Linux seccomp violations on ppc64le over the socketcall syscall. * Fix use of ldns when using ldns-config; bz#2697 * configure: set cache variables when cross-compiling. The cross- compiling fallback message was saying it assumed the test passed, but it wasn't actually set the cache variables and this would cause later tests to fail. * Add clang libFuzzer harnesses for public key parsing and signature verification. - packaging: * moving patches into a separate archive * first round of rebased patches: [-X11_trusted_forwarding] [-allow_root_password_login] [-blocksigalrm] [-cavstest-ctr] [-cavstest-kdf] [-disable_short_DH_parameters] [-eal3] [-enable_PAM_by_default] [-fips] [-fips_checks] [-gssapi_key_exchange] [-hostname_changes_when_forwarding_X] [-lastlog] [-missing_headers] [-pam_check_locks] [-pts_names_formatting] [-remove_xauth_cookies_on_exit] [-seccomp_geteuid] [-seccomp_getuid] [-seccomp_stat] [-seed-prng] [-send_locale] [-systemd-notify] * not rebased (obsoleted) patches (so far): [-additional_seccomp_archs] [-allow_DSS_by_default] [-default_protocol] [-dont_use_pthreads_in_PAM] [-eal3_obsolete] [-gssapimitm] [-saveargv-fix] * obviously removing all standalone patch files: [openssh-7.2p2-allow_root_password_login.patch] [openssh-7.2p2-allow_DSS_by_default.patch] [openssh-7.2p2-X11_trusted_forwarding.patch] [openssh-7.2p2-lastlog.patch] [openssh-7.2p2-enable_PAM_by_default.patch] [openssh-7.2p2-dont_use_pthreads_in_PAM.patch] [openssh-7.2p2-eal3.patch] [openssh-7.2p2-blocksigalrm.patch] [openssh-7.2p2-send_locale.patch] [openssh-7.2p2-hostname_changes_when_forwarding_X.patch] [openssh-7.2p2-remove_xauth_cookies_on_exit.patch] [openssh-7.2p2-pts_names_formatting.patch] [openssh-7.2p2-pam_check_locks.patch] [openssh-7.2p2-disable_short_DH_parameters.patch] [openssh-7.2p2-seccomp_getuid.patch] [openssh-7.2p2-seccomp_geteuid.patch] [openssh-7.2p2-seccomp_stat.patch] [openssh-7.2p2-additional_seccomp_archs.patch] [openssh-7.2p2-fips.patch] [openssh-7.2p2-cavstest-ctr.patch] [openssh-7.2p2-cavstest-kdf.patch] [openssh-7.2p2-seed-prng.patch] [openssh-7.2p2-gssapi_key_exchange.patch] [openssh-7.2p2-audit.patch] [openssh-7.2p2-audit_fixes.patch] [openssh-7.2p2-audit_seed_prng.patch] [openssh-7.2p2-login_options.patch] [openssh-7.2p2-disable_openssl_abi_check.patch] [openssh-7.2p2-no_fork-no_pid_file.patch] [openssh-7.2p2-host_ident.patch] [openssh-7.2p2-sftp_homechroot.patch] [openssh-7.2p2-sftp_force_permissions.patch] [openssh-7.2p2-X_forward_with_disabled_ipv6.patch] [openssh-7.2p2-ldap.patch] [openssh-7.2p2-IPv6_X_forwarding.patch] [openssh-7.2p2-ignore_PAM_with_UseLogin.patch] [openssh-7.2p2-prevent_timing_user_enumeration.patch] [openssh-7.2p2-limit_password_length.patch] [openssh-7.2p2-keep_slogin.patch] [openssh-7.2p2-kex_resource_depletion.patch] [openssh-7.2p2-verify_CIDR_address_ranges.patch] [openssh-7.2p2-restrict_pkcs11-modules.patch] [openssh-7.2p2-prevent_private_key_leakage.patch] [openssh-7.2p2-secure_unix_sockets_forwarding.patch] [openssh-7.2p2-ssh_case_insensitive_host_matching.patch] [openssh-7.2p2-disable_preauth_compression.patch] [openssh-7.2p2-s390_hw_crypto_syscalls.patch] [openssh-7.2p2-s390_OpenSSL-ibmpkcs11_syscalls.patch]- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- sshd_config is has now permissions 0600 in secure mode- Fix preauth seccomp separation on mainframes (bsc#1016709) [openssh-7.2p2-s390_hw_crypto_syscalls.patch] [openssh-7.2p2-s390_OpenSSL-ibmpkcs11_syscalls.patch] - enable case-insensitive hostname matching (bsc#1017099) [openssh-7.2p2-ssh_case_insensitive_host_matching.patch] - add CAVS tests [openssh-7.2p2-cavstest-ctr.patch] [openssh-7.2p2-cavstest-kdf.patch] - Adding missing pieces for user matching (bsc#1021626) - Properly verify CIDR masks in configuration (bsc#1005893) [openssh-7.2p2-verify_CIDR_address_ranges.patch] - Remove pre-auth compression support from the server to prevent possible cryptographic attacks. (CVE-2016-10012, bsc#1016370) [openssh-7.2p2-disable_preauth_compression.patch] - limit directories for loading PKCS11 modules (CVE-2016-10009, bsc#1016366) [openssh-7.2p2-restrict_pkcs11-modules.patch] - Prevent possible leaks of host private keys to low-privilege process handling authentication (CVE-2016-10011, bsc#1016369) [openssh-7.2p2-prevent_private_key_leakage.patch] - Do not allow unix socket forwarding when running without privilege separation (CVE-2016-10010, bsc#1016368) [openssh-7.2p2-secure_unix_sockets_forwarding.patch] - prevent resource depletion during key exchange (bsc#1005480, CVE-2016-8858) [openssh-7.2p2-kex_resource_depletion.patch] - fix suggested command for removing conflicting server keys from the known_hosts file (bsc#1006221) - enable geteuid{,32} syscalls on mainframes, since it may be called from libica/ibmica on machines with hardware crypto accelerator (bsc#1004258) [openssh-7.2p2-seccomp_geteuid.patch] - fix regression of (bsc#823710) [openssh-7.2p2-audit_fixes.patch] - add slogin (removed upstreams) [openssh-7.2p2-keep_slogin.patch] - require OpenSSL < 1.1 where that one is a default- sshd.service: Set TasksMax=infinity, as there should be no limit on the amount of tasks sshd can run.- remaining patches that were still missing since the update to 7.2p2 (FATE#319675): - allow X forwarding over IPv4 when IPv6 sockets is not available [openssh-7.2p2-X_forward_with_disabled_ipv6.patch] - do not write PID file when not daemonizing [openssh-7.2p2-no_fork-no_pid_file.patch] - use correct options when invoking login [openssh-7.2p2-login_options.patch] - helper application for retrieving users' public keys from an LDAP server [openssh-7.2p2-ldap.patch] - allow forcing permissions over sftp [openssh-7.2p2-sftp_force_permissions.patch] - do not perform run-time checks for OpenSSL API/ABI change [openssh-7.2p2-disable_openssl_abi_check.patch] - suggest commands for cleaning known hosts file [openssh-7.2p2-host_ident.patch] - sftp home chroot patch [openssh-7.2p2-sftp_homechroot.patch] - ssh sessions auditing [openssh-7.2p2-audit.patch] - enable seccomp sandbox on additional architectures [openssh-7.2p2-additional_seccomp_archs.patch] - fix forwarding with IPv6 addresses in DISPLAY (bnc#847710) [openssh-7.2p2-IPv6_X_forwarding.patch] - ignore PAM environment when using login (bsc#975865, CVE-2015-8325) [openssh-7.2p2-ignore_PAM_with_UseLogin.patch] - limit accepted password length (prevents possible DoS) (bsc#992533, CVE-2016-6515) [openssh-7.2p2-limit_password_length.patch] - Prevent user enumeration through the timing of password processing (bsc#989363, CVE-2016-6210) [openssh-7.2p2-prevent_timing_user_enumeration.patch] - Add auditing for PRNG re-seeding [openssh-7.2p2-audit_seed_prng.patch]- FIPS compatibility (no selfchecks, only crypto restrictions) [openssh-7.2p2-fips.patch] - PRNG re-seeding [openssh-7.2p2-seed-prng.patch] - preliminary version of GSSAPI KEX [openssh-7.2p2-gssapi_key_exchange.patch]- added gpg signature- enable support for SSHv1 protocol and discourage its usage (bsc#983307) - enable DSA by default for backward compatibility and discourage its usage (bsc#983784) [openssh-7.2p2-allow_DSS_by_default.patch]- enable trusted X11 forwarding by default [openssh-7.2p2-X11_trusted_forwarding.patch] - set UID for lastlog properly [openssh-7.2p2-lastlog.patch] - enable use of PAM by default [openssh-7.2p2-enable_PAM_by_default.patch] - copy command line arguments properly [openssh-7.2p2-saveargv-fix.patch] - do not use pthreads in PAM code [openssh-7.2p2-dont_use_pthreads_in_PAM.patch] - fix paths in documentation [openssh-7.2p2-eal3.patch] - prevent race consitions triggered by SIGALRM [openssh-7.2p2-blocksigalrm.patch] - do send and accept locale environment variables by default [openssh-7.2p2-send_locale.patch] - handle hostnames changes during X forwarding [openssh-7.2p2-hostname_changes_when_forwarding_X.patch] - try to remove xauth cookies on exit [openssh-7.2p2-remove_xauth_cookies_on_exit.patch] - properly format pts names for ?tmp? log files [openssh-7.2p2-pts_names_formatting.patch] - check locked accounts when using PAM [openssh-7.2p2-pam_check_locks.patch] - chenge default PermitRootLogin to 'yes' to prevent unwanted surprises on updates from older versions. See README.SUSE for details [openssh-7.2p2-allow_root_password_login.patch] - Disable DH parameters under 2048 bits by default and allow lowering the limit back to the RFC 4419 specified minimum through an option (bsc#932483, bsc#948902) [openssh-7.2p2-disable_short_DH_parameters.patch] - Add getuid() and stat() syscalls to the seccomp filter (bsc#912436) [openssh-7.2p2-seccomp_getuid.patch, openssh-7.2p2-seccomp_stat.patch]- upgrade to 7.2p2 upstream package without any SUSE patches Distilled upstream log: - OpenSSH 6.7 Potentially-incompatible changes: * sshd(8): The default set of ciphers and MACs has been altered to remove unsafe algorithms. In particular, CBC ciphers and arcfour* are disabled by default. The full set of algorithms remains available if configured explicitly via the Ciphers and MACs sshd_config options. * sshd(8): Support for tcpwrappers/libwrap has been removed. * OpenSSH 6.5 and 6.6 have a bug that causes ~0.2% of connections using the curve25519-sha256@libssh.org KEX exchange method to fail when connecting with something that implements the specification correctly. OpenSSH 6.7 disables this KEX method when speaking to one of the affected versions. New Features: * ssh(1), sshd(8): Add support for Unix domain socket forwarding. A remote TCP port may be forwarded to a local Unix domain socket and vice versa or both ends may be a Unix domain socket. * ssh(1), ssh-keygen(1): Add support for SSHFP DNS records for ED25519 key types. * sftp(1): Allow resumption of interrupted uploads. * ssh(1): When rekeying, skip file/DNS lookups of the hostkey if it is the same as the one sent during initial key exchange * sshd(8): Allow explicit ::1 and 127.0.0.1 forwarding bind addresses when GatewayPorts=no; allows client to choose address family * sshd(8): Add a sshd_config PermitUserRC option to control whether ~/.ssh/rc is executed, mirroring the no-user-rc authorized_keys option * ssh(1): Add a %C escape sequence for LocalCommand and ControlPath that expands to a unique identifer based on a hash of the tuple of (local host, remote user, hostname, port). Helps avoid exceeding miserly pathname limits for Unix domain sockets in multiplexing control paths * sshd(8): Make the "Too many authentication failures" message include the user, source address, port and protocol in a format similar to the authentication success / failure messages Bugfixes: * sshd(8): Fix remote forwarding with the same listen port but different listen address. * ssh(1): Fix inverted test that caused PKCS#11 keys that were explicitly listed in ssh_config or on the commandline not to be preferred. * ssh-keygen(1): Fix bug in KRL generation: multiple consecutive revoked certificate serial number ranges could be serialised to an invalid format. Readers of a broken KRL caused by this bug will fail closed, so no should-have-been-revoked key will be accepted. * ssh(1): Reflect stdio-forward ("ssh -W host:port ...") failures in exit status. Previously we were always returning 0 * ssh(1), ssh-keygen(1): Make Ed25519 keys' title fit properly in the randomart border * ssh-agent(1): Only cleanup agent socket in the main agent process and not in any subprocesses it may have started (e.g. forked askpass). Fixes agent sockets being zapped when askpass processes fatal() * ssh-add(1): Make stdout line-buffered; saves partial output getting lost when ssh-add fatal()s part-way through (e.g. when listing keys from an agent that supports key types that ssh-add doesn't) * ssh-keygen(1): When hashing or removing hosts, don't choke on @revoked markers and don't remove @cert-authority markers * ssh(1): Don't fatal when hostname canonicalisation fails and a ProxyCommand is in use; continue and allow the ProxyCommand to connect anyway (e.g. to a host with a name outside the DNS behind a bastion) * scp(1): When copying local->remote fails during read, don't send uninitialised heap to the remote end. * sftp(1): Fix fatal "el_insertstr failed" errors when tab-completing filenames with a single quote char somewhere in the string * ssh-keyscan(1): Scan for Ed25519 keys by default. * ssh(1): When using VerifyHostKeyDNS with a DNSSEC resolver, down-convert any certificate keys to plain keys and attempt SSHFP resolution. Prevents a server from skipping SSHFP lookup and forcing a new-hostkey dialog by offering only certificate keys. - OpenSSH 6.8 Potentially-incompatible changes: * sshd(8): UseDNS now defaults to 'no'. Configurations that match against the client host name (via sshd_config or authorized_keys) may need to re-enable it or convert to matching against addresses. New Features: * Add FingerprintHash option to ssh(1) and sshd(8), and equivalent command-line flags to the other tools to control algorithm used for key fingerprints. The default changes from MD5 to SHA256 and format from hex to base64. Fingerprints now have the hash algorithm prepended. An example of the new format: SHA256:mVPwvezndPv/ARoIadVY98vAC0g+P/5633yTC4d/wXE Please note that visual host keys will also be different. * ssh(1), sshd(8): Experimental host key rotation support. Add a protocol extension for a server to inform a client of all its available host keys after authentication has completed. The client may record the keys in known_hosts, allowing it to upgrade to better host key algorithms and a server to gracefully rotate its keys. The client side of this is controlled by a UpdateHostkeys config option (default off). * ssh(1): Add a ssh_config HostbasedKeyType option to control which host public key types are tried during host-based authentication. * ssh(1), sshd(8): fix connection-killing host key mismatch errors when sshd offers multiple ECDSA keys of different lengths. * ssh(1): when host name canonicalisation is enabled, try to parse host names as addresses before looking them up for canonicalisation. fixes bz#2074 and avoiding needless DNS lookups in some cases. * ssh-keygen(1), sshd(8): Key Revocation Lists (KRLs) no longer require OpenSSH to be compiled with OpenSSL support. * ssh(1), ssh-keysign(8): Make ed25519 keys work for host based authentication. * sshd(8): SSH protocol v.1 workaround for the Meyer, et al, Bleichenbacher Side Channel Attack. Fake up a bignum key before RSA decryption. * sshd(8): Remember which public keys have been used for authentication and refuse to accept previously-used keys. This allows AuthenticationMethods=publickey,publickey to require that users authenticate using two _different_ public keys. * sshd(8): add sshd_config HostbasedAcceptedKeyTypes and PubkeyAcceptedKeyTypes options to allow sshd to control what public key types will be accepted. Currently defaults to all. * sshd(8): Don't count partial authentication success as a failure against MaxAuthTries. * ssh(1): Add RevokedHostKeys option for the client to allow text-file or KRL-based revocation of host keys. * ssh-keygen(1), sshd(8): Permit KRLs that revoke certificates by serial number or key ID without scoping to a particular CA. * ssh(1): Add a "Match canonical" criteria that allows ssh_config Match blocks to trigger only in the second config pass. * ssh(1): Add a -G option to ssh that causes it to parse its configuration and dump the result to stdout, similar to "sshd -T". * ssh(1): Allow Match criteria to be negated. E.g. "Match !host". * The regression test suite has been extended to cover more OpenSSH features. The unit tests have been expanded and now cover key exchange. Bugfixes: * ssh-keyscan(1): ssh-keyscan has been made much more robust again servers that hang or violate the SSH protocol. * ssh(1), ssh-keygen(1): Fix regression: Key path names were being lost as comment fields. * ssh(1): Allow ssh_config Port options set in the second config parse phase to be applied (they were being ignored). * ssh(1): Tweak config re-parsing with host canonicalisation - make the second pass through the config files always run when host name canonicalisation is enabled (and not whenever the host name changes) * ssh(1): Fix passing of wildcard forward bind addresses when connection multiplexing is in use * ssh-keygen(1): Fix broken private key conversion from non-OpenSSH formats. * ssh-keygen(1): Fix KRL generation bug when multiple CAs are in use. * Various fixes to manual pages - OpenSSH 6.9 Security: * ssh(1): when forwarding X11 connections with ForwardX11Trusted=no, connections made after ForwardX11Timeout expired could be permitted and no longer subject to XSECURITY restrictions because of an ineffective timeout check in ssh(1) coupled with "fail open" behaviour in the X11 server when clients attempted connections with expired credentials. This problem was reported by Jann Horn. * ssh-agent(1): fix weakness of agent locking (ssh-add -x) to password guessing by implementing an increasing failure delay, storing a salted hash of the password rather than the password itself and using a timing-safe comparison function for verifying unlock attempts. This problem was reported by Ryan Castellucci. New Features: * ssh(1), sshd(8): promote chacha20-poly1305@openssh.com to be the default cipher * sshd(8): support admin-specified arguments to AuthorizedKeysCommand * sshd(8): add AuthorizedPrincipalsCommand that allows retrieving authorized principals information from a subprocess rather than a file. * ssh(1), ssh-add(1): support PKCS#11 devices with external PIN entry devices * sshd(8): allow GSSAPI host credential check to be relaxed for multihomed hosts via GSSAPIStrictAcceptorCheck option * ssh-keygen(1): support "ssh-keygen -lF hostname" to search known_hosts and print key hashes rather than full keys. * ssh-agent(1): add -D flag to leave ssh-agent in foreground without enabling debug mode Bugfixes: * ssh(1), sshd(8): deprecate legacy SSH2_MSG_KEX_DH_GEX_REQUEST_OLD message and do not try to use it against some 3rd-party SSH implementations that use it (older PuTTY, WinSCP). * Many fixes for problems caused by compile-time deactivation of SSH1 support (including bz#2369) * ssh(1), sshd(8): cap DH-GEX group size at 4Kbits for Cisco implementations as some would fail when attempting to use group sizes >4K * ssh(1): fix out-of-bound read in EscapeChar configuration option parsing * sshd(8): fix application of PermitTunnel, LoginGraceTime, AuthenticationMethods and StreamLocalBindMask options in Match blocks * ssh(1), sshd(8): improve disconnection message on TCP reset; bz#2257 * ssh(1): remove failed remote forwards established by muliplexing from the list of active forwards * sshd(8): make parsing of authorized_keys "environment=" options independent of PermitUserEnv being enabled * sshd(8): fix post-auth crash with permitopen=none * ssh(1), ssh-add(1), ssh-keygen(1): allow new-format private keys to be encrypted with AEAD ciphers * ssh(1): allow ListenAddress, Port and AddressFamily configuration options to appear in any order * sshd(8): check for and reject missing arguments for VersionAddendum and ForceCommand * ssh(1), sshd(8): don't treat unknown certificate extensions as fatal * ssh-keygen(1): make stdout and stderr output consistent * ssh(1): mention missing DISPLAY environment in debug log when X11 forwarding requested * sshd(8): correctly record login when UseLogin is set * sshd(8): Add some missing options to sshd -T output and fix output of VersionAddendum and HostCertificate. bz#2346 * Document and improve consistency of options that accept a "none" argument" TrustedUserCAKeys, RevokedKeys (bz#2382), AuthorizedPrincipalsFile (bz#2288) * ssh(1): include remote username in debug output * sshd(8): avoid compatibility problem with some versions of Tera Term, which would crash when they received the hostkeys notification message (hostkeys-00@openssh.com) * sshd(8): mention ssh-keygen -E as useful when comparing legacy MD5 host key fingerprints * ssh(1): clarify pseudo-terminal request behaviour and use make manual language consistent * ssh(1): document that the TERM environment variable is not subject to SendEnv and AcceptEnv - OpenSSH 7.0: This focuses primarily on deprecating weak, legacy and/or unsafe cryptography. Security: * sshd(8): OpenSSH 6.8 and 6.9 incorrectly set TTYs to be world- writable. Local attackers may be able to write arbitrary messages to logged-in users, including terminal escape sequences. Reported by Nikolay Edigaryev. * sshd(8): Portable OpenSSH only: Fixed a privilege separation weakness related to PAM support. Attackers who could successfully compromise the pre-authentication process for remote code execution and who had valid credentials on the host could impersonate other users. Reported by Moritz Jodeit. * sshd(8): Portable OpenSSH only: Fixed a use-after-free bug related to PAM support that was reachable by attackers who could compromise the pre-authentication process for remote code execution. Also reported by Moritz Jodeit. * sshd(8): fix circumvention of MaxAuthTries using keyboard- interactive authentication. By specifying a long, repeating keyboard-interactive "devices" string, an attacker could request the same authentication method be tried thousands of times in a single pass. The LoginGraceTime timeout in sshd(8) and any authentication failure delays implemented by the authentication mechanism itself were still applied. Found by Kingcope. Potentially-incompatible Changes: * Support for the legacy SSH version 1 protocol is disabled by default at compile time. * Support for the 1024-bit diffie-hellman-group1-sha1 key exchange is disabled by default at run-time. It may be re-enabled using the instructions in README.legacy or http://www.openssh.com/legacy.html * Support for ssh-dss, ssh-dss-cert-* host and user keys is disabled by default at run-time. These may be re-enabled using the instructions at http://www.openssh.com/legacy.html * Support for the legacy v00 cert format has been removed. * The default for the sshd_config(5) PermitRootLogin option has changed from "yes" to "prohibit-password". * PermitRootLogin=without-password/prohibit-password now bans all interactive authentication methods, allowing only public-key, hostbased and GSSAPI authentication (previously it permitted keyboard-interactive and password-less authentication if those were enabled). New Features: * ssh_config(5): add PubkeyAcceptedKeyTypes option to control which public key types are available for user authentication. * sshd_config(5): add HostKeyAlgorithms option to control which public key types are offered for host authentications. * ssh(1), sshd(8): extend Ciphers, MACs, KexAlgorithms, HostKeyAlgorithms, PubkeyAcceptedKeyTypes and HostbasedKeyTypes options to allow appending to the default set of algorithms instead of replacing it. Options may now be prefixed with a '+' to append to the default, e.g. "HostKeyAlgorithms=+ssh-dss". * sshd_config(5): PermitRootLogin now accepts an argument of 'prohibit-password' as a less-ambiguous synonym of 'without- password'. Bugfixes: * ssh(1), sshd(8): add compatability workarounds for Cisco and more PuTTY versions. * Fix some omissions and errors in the PROTOCOL and PROTOCOL.mux documentation relating to Unix domain socket forwarding * ssh(1): Improve the ssh(1) manual page to include a better description of Unix domain socket forwarding * ssh(1), ssh-agent(1): skip uninitialised PKCS#11 slots, fixing failures to load keys when they are present. * ssh(1), ssh-agent(1): do not ignore PKCS#11 hosted keys that wth empty CKA_ID * sshd(8): clarify documentation for UseDNS option - OpenSSH 7.1: Security: * sshd(8): OpenSSH 7.0 contained a logic error in PermitRootLogin= prohibit-password/without-password that could, depending on compile-time configuration, permit password authentication to root while preventing other forms of authentication. This problem was reported by Mantas Mikulenas. Bugfixes: * ssh(1), sshd(8): add compatability workarounds for FuTTY * ssh(1), sshd(8): refine compatability workarounds for WinSCP * Fix a number of memory faults (double-free, free of uninitialised memory, etc) in ssh(1) and ssh-keygen(1). Reported by Mateusz Kocielski. - OpenSSH 7.1p2: * SECURITY: ssh(1): The OpenSSH client code between 5.4 and 7.1 contains experimential support for resuming SSH-connections (roaming). The matching server code has never been shipped, but the client code was enabled by default and could be tricked by a malicious server into leaking client memory to the server, including private client user keys. The authentication of the server host key prevents exploitation by a man-in-the-middle, so this information leak is restricted to connections to malicious or compromised servers. MITIGATION: For OpenSSH >= 5.4 the vulnerable code in the client can be completely disabled by adding 'UseRoaming no' to the gobal ssh_config(5) file, or to user configuration in ~/.ssh/config, or by passing -oUseRoaming=no on the command line. PATCH: See below for a patch to disable this feature (Disabling Roaming in the Source Code). This problem was reported by the Qualys Security Advisory team. * SECURITY: Eliminate the fallback from untrusted X11-forwarding to trusted forwarding for cases when the X server disables the SECURITY extension. Reported by Thomas Hoger. * SECURITY: Fix an out of-bound read access in the packet handling code. Reported by Ben Hawkes. * PROTOCOL: Correctly interpret the 'first_kex_follows' option during the intial key exchange. Reported by Matt Johnston. * Further use of explicit_bzero has been added in various buffer handling code paths to guard against compilers aggressively doing dead-store removal. Potentially-incompatible changes: * This release disables a number of legacy cryptographic algorithms by default in ssh: + Several ciphers blowfish-cbc, cast128-cbc, all arcfour variants and the rijndael-cbc aliases for AES. + MD5-based and truncated HMAC algorithms. - OpenSSH 7.2: Security: * ssh(1), sshd(8): remove unfinished and unused roaming code (was already forcibly disabled in OpenSSH 7.1p2). * ssh(1): eliminate fallback from untrusted X11 forwarding to trusted forwarding when the X server disables the SECURITY extension. * ssh(1), sshd(8): increase the minimum modulus size supported for diffie-hellman-group-exchange to 2048 bits. * sshd(8): pre-auth sandboxing is now enabled by default (previous releases enabled it for new installations via sshd_config). New Features: * all: add support for RSA signatures using SHA-256/512 hash algorithms based on draft-rsa-dsa-sha2-256-03.txt and draft-ssh-ext-info-04.txt. * ssh(1): Add an AddKeysToAgent client option which can be set to 'yes', 'no', 'ask', or 'confirm', and defaults to 'no'. When enabled, a private key that is used during authentication will be added to ssh-agent if it is running (with confirmation enabled if set to 'confirm'). * sshd(8): add a new authorized_keys option "restrict" that includes all current and future key restrictions (no-*-forwarding, etc.). Also add permissive versions of the existing restrictions, e.g. "no-pty" -> "pty". This simplifies the task of setting up restricted keys and ensures they are maximally-restricted, regardless of any permissions we might implement in the future. * ssh(1): add ssh_config CertificateFile option to explicitly list certificates. bz#2436 * ssh-keygen(1): allow ssh-keygen to change the key comment for all supported formats. * ssh-keygen(1): allow fingerprinting from standard input, e.g. "ssh-keygen -lf -" * ssh-keygen(1): allow fingerprinting multiple public keys in a file, e.g. "ssh-keygen -lf ~/.ssh/authorized_keys" bz#1319 * sshd(8): support "none" as an argument for sshd_config Foreground and ChrootDirectory. Useful inside Match blocks to override a global default. bz#2486 * ssh-keygen(1): support multiple certificates (one per line) and reading from standard input (using "-f -") for "ssh-keygen -L" * ssh-keyscan(1): add "ssh-keyscan -c ..." flag to allow fetching certificates instead of plain keys. * ssh(1): better handle anchored FQDNs (e.g. 'cvs.openbsd.org') in hostname canonicalisation - treat them as already canonical and remove the trailing '.' before matching ssh_config. Bugfixes: * sftp(1): existing destination directories should not terminate recursive uploads (regression in openssh 6.8) * ssh(1), sshd(8): correctly send back SSH2_MSG_UNIMPLEMENTED replies to unexpected messages during key exchange. * ssh(1): refuse attempts to set ConnectionAttempts=0, which does not make sense and would cause ssh to print an uninitialised stack variable. * ssh(1): fix errors when attempting to connect to scoped IPv6 addresses with hostname canonicalisation enabled. * sshd_config(5): list a couple more options usable in Match blocks. * sshd(8): fix "PubkeyAcceptedKeyTypes +..." inside a Match block. * ssh(1): expand tilde characters in filenames passed to -i options before checking whether or not the identity file exists. Avoids confusion for cases where shell doesn't expand (e.g. "-i ~/file" vs. "-i~/file"). * ssh(1): do not prepend "exec" to the shell command run by "Match exec" in a config file, which could cause some commands to fail in certain environments. * ssh-keyscan(1): fix output for multiple hosts/addrs on one line when host hashing or a non standard port is in use * sshd(8): skip "Could not chdir to home directory" message when ChrootDirectory is active. * ssh(1): include PubkeyAcceptedKeyTypes in ssh -G config dump. * sshd(8): avoid changing TunnelForwarding device flags if they are already what is needed; makes it possible to use tun/tap networking as non-root user if device permissions and interface flags are pre-established * ssh(1), sshd(8): RekeyLimits could be exceeded by one packet. * ssh(1): fix multiplexing master failure to notice client exit. * ssh(1), ssh-agent(1): avoid fatal() for PKCS11 tokens that present empty key IDs. * sshd(8): avoid printf of NULL argument. * ssh(1), sshd(8): allow RekeyLimits larger than 4GB. * ssh-keygen(1): sshd(8): fix several bugs in (unused) KRL signature support. * ssh(1), sshd(8): fix connections with peers that use the key exchange guess feature of the protocol. * sshd(8): include remote port number in log messages. * ssh(1): don't try to load SSHv1 private key when compiled without SSHv1 support. * ssh-agent(1), ssh(1): fix incorrect error messages during key loading and signing errors. * ssh-keygen(1): don't leave empty temporary files when performing known_hosts file edits when known_hosts doesn't exist. * sshd(8): correct packet format for tcpip-forward replies for requests that don't allocate a port * ssh(1), sshd(8): fix possible hang on closed output. * ssh(1): expand %i in ControlPath to UID. * ssh(1), sshd(8): fix return type of openssh_RSA_verify. * ssh(1), sshd(8): fix some option parsing memory leaks. * ssh(1): add a some debug output before DNS resolution; it's a place where ssh could previously silently stall in cases of unresponsive DNS servers. * ssh(1): remove spurious newline in visual hostkey. * ssh(1): fix printing (ssh -G ...) of HostKeyAlgorithms=+... * ssh(1): fix expansion of HostkeyAlgorithms=+... Documentation: * ssh_config(5), sshd_config(5): update default algorithm lists to match current reality. * ssh(1): mention -Q key-plain and -Q key-cert query options. * sshd_config(8): more clearly describe what AuthorizedKeysFile=none does. * ssh_config(5): better document ExitOnForwardFailure. * sshd(5): mention internal DH-GEX fallback groups in manual. * sshd_config(5): better description for MaxSessions option. Portability: * sshd(8): fix multiple authentication using S/Key. - OpenSSH 7.2p2: Security: * sshd(8): sanitise X11 authentication credentials to avoid xauth command injection when X11Forwarding is enabled. (removing patches from previous version: * CVE-2016-0777_CVE-2016-0778.patch * openssh-6.6p1-X11-forwarding.patch * openssh-6.6p1-X_forward_with_disabled_ipv6.patch * openssh-6.6p1-audit1-remove_duplicit_audit.patch * openssh-6.6p1-audit2-better_audit_of_user_actions.patch * openssh-6.6p1-audit3-key_auth_usage-fips.patch * openssh-6.6p1-audit3-key_auth_usage.patch * openssh-6.6p1-audit4-kex_results-fips.patch * openssh-6.6p1-audit4-kex_results.patch * openssh-6.6p1-audit5-session_key_destruction.patch * openssh-6.6p1-audit6-server_key_destruction.patch * openssh-6.6p1-audit7-libaudit_compat.patch * openssh-6.6p1-audit8-libaudit_dns_timeouts.patch * openssh-6.6p1-blocksigalrm.patch * openssh-6.6p1-curve25519-6.6.1p1.patch * openssh-6.6p1-default-protocol.patch * openssh-6.6p1-disable-openssl-abi-check.patch * openssh-6.6p1-eal3.patch * openssh-6.6p1-fingerprint_hash.patch * openssh-6.6p1-fips-checks.patch * openssh-6.6p1-fips.patch * openssh-6.6p1-gssapi_key_exchange.patch * openssh-6.6p1-gssapimitm.patch * openssh-6.6p1-host_ident.patch * openssh-6.6p1-key-converter.patch * openssh-6.6p1-lastlog.patch * openssh-6.6p1-ldap.patch * openssh-6.6p1-login_options.patch * openssh-6.6p1-no_fork-no_pid_file.patch * openssh-6.6p1-pam-check-locks.patch * openssh-6.6p1-pam-fix2.patch * openssh-6.6p1-pam-fix3.patch * openssh-6.6p1-pts.patch * openssh-6.6p1-saveargv-fix.patch * openssh-6.6p1-seccomp_getuid.patch * openssh-6.6p1-seccomp_stat.patch * openssh-6.6p1-seed-prng.patch * openssh-6.6p1-send_locale.patch * openssh-6.6p1-sftp_force_permissions.patch * openssh-6.6p1-sftp_homechroot.patch * openssh-6.6p1-xauth.patch * openssh-6.6p1-xauthlocalhostname.patch)- update seccomp sandbox that broke after OpenSSL update (bsc#912436, bsc#977812) [openssh-6.6p1-seccomp_stat.patch]- openssh-6.6p1-ldap.patch: replace TRUE/FALSE with 1/0, since this defines did come via an indirect header inclusion and are not everywhere defined.- CVE-2016-0777, bsc#961642, CVE-2016-0778, bsc#961645 Add CVE-2016-0777_CVE-2016-0778.patch to disable the roaming code to prevent information leak and buffer overflow- gpg signature and keyring added. pub 3200R/6D920D30 2013-12-10 [expires: 2021-01-01] uid Damien Miller sub 3200R/672A1105 2013-12-10 [expires: 2021-01-01]- fix bashisms in sshd.init script/bin/sh/bin/sh/bin/sh/bin/sh/bin/shgoat16 1620301699 8.4p1-1.308.4p1-1.308.4p1-1.30 sshdslp.reg.dssh.regsshd_configSuSEfirewall2.dservicessshdsftp-serversshd.servicesshd.confrcsshdsshdsshd-gen-keys-startsysconfig.sshsshd_config.5.gzsftp-server.8.gzsshd.8.gzsshd/etc/pam.d//etc//etc/slp.reg.d//etc/ssh//etc/sysconfig//etc/sysconfig/SuSEfirewall2.d//etc/sysconfig/SuSEfirewall2.d/services//usr/lib/ssh//usr/lib/systemd/system//usr/lib/sysusers.d//usr/sbin//usr/share/fillup-templates//usr/share/man/man5//usr/share/man/man8//var/lib/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:SLE-15-SP3:GA/standard/1a8ad500f0e39fca0b93e69ee51732b0-opensshcpioxz5x86_64-suse-linuxASCII textdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=61b57ab616fbfecf569afba664e01fb534662349, for GNU/Linux 3.2.0, strippedELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=ed06716184f77cc71206ed2c41e00262f6270382, for GNU/Linux 3.2.0, strippedPOSIX shell script, ASCII text executabletroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)5!R#RRRRRRRRRRRR!RRR"R0R$RPRR-R/R(R*R!R RR&RRRRRRRRRRRRR R)R,RR.R0RR+R%R'RRRJP.[auditutf-8fdeb5ef605439dfc5eca90dc6f1db155dce552657460ed2c92f5ace0750c38c2?P7zXZ !t/rw] crv(vX0χxRy\uNV "a}5WZQXiὗx`&7,no>+bet20-jT:W]uO1|JrwB%5_0NN)+|m7aRA#ɟ}%^Ȼȃ!* 1Ԩ՗Q pxy!۷&0@ [B3҇3Sgz!G W6aiE.fjMOh8-lcZ0T)ln)E9i0J+,UW #OM&X/ XOE59ɮ" sX(k=6{sw*4Ѡ1R)[;f<z5r1!R 9􂋲J.vث%OBC {pfNR*;vǚPٯ^Phu!E*hUgffJüO*bQ#P{>$ŮֹW ?b$C'C Ekg< VQ^17saFTECw0)X3cyjh]ħ[8re͕%G>U7 t6|@ZFR4*ĐVb:Uum ZПI,vEY鷽q, DzIdwkX0M{[ɩO3yM5gmokv>b )Ӝ`fzo)MY(lM87"N1u9h/eVqD9=4{"SepxxuR1eF̜Y\7resB4fzt5_%'< :}>ܜQ$cT_{A Irx"{ӥřZ1CAÂ_g'3 C?;-І` :_V)bQ Ig"+{![ a>ŃC7z6x"&HyVo%:SDq\ `9jl{r0ө#Wn&F'S AnR(i Ԥo<8,\98#]©:lPw+n_Fcd؋QpNV B /I6e%;XL|S1ֱb}9`P(C1J(MfU%aC=v>O2۰-4k ɿdkD/?؝(]3K K,\~YFLi!̄>HqrQA6N$i[g|xb9ILMEwnP ^8 \tLE|D[%~4]m|S~5dfӶsR7|A0H )5!-ǝt~42hDK7 u%&+SID3vra4-JƶQotaq`BVĴ^g б< NiOy&~e_g$|qX( H jZkL P[&8G> {v}9"BT+ʏ?m&(.zpE2:~ʚaC沆|61}v>2|=QH9i}Xa$viF̱q7vW ϥ;$Gfi?ʚG>8O~S/5J,<8i:MQ7xFZXVă'A(ʲiWijy; vЊ$hd=D~`ߢQ1\|r, ~;y.F2oy7eCk [[)e]yBT'U|7%֮~ ',Fk}cU2Ho9Gh} @vct dR*U€3|fßǍF3A:m]&nQ2fb{CmРGm1lșGð^cvhK9*.ůöò1d$/Tu!'<99[9(l.q ydaZi԰q?\י אQb,t {mOԿ|ń$5Z߱:G߸_)ɒض>xׄw̓6B`se)gj`m$qDD]@"SC&ɞ x6ݑ)΂frMO{g(~S_g!puONaLg" 6NhhST"πIqSyeVy ^!:xrY}늑 ΋|Ɂ!HτlDf@K%R ChnOF[ac:ݷZ@I}'1pī\Iy$V v6/yۅg;C*an;fϨSOU{LԣpU($F厨{|E ,-2B:H2".j{ܠot) D_I|!t֦R:FIN>~KK;l$ a: դ*7Asc ~v|SPr.kL< Kzd,X*BN۟mtE)`+^lMS| x(Epz?p`s2mCJ*G&ti ɊP҄[~ZЯ>'ů!ԍXlEHF5t&^۷jhZg7crC\㢹6SB>O,8R3ΣDo/Ȑ< 'z)1%ڬo$ĖR+ FϙwILlS5eKƄw&?ϯP^oo&0n诇Im߭V y.zQd ֪mk˥;ۛY `\,%5a|C~%cP8mf_$cA؊x%M.;a2Z}JbT`RB @HNWtҍhNz'[V@Hz2WxA0"T 6L>oW.>Tnܞ`ŝjyRAē 04l,e78=k>labW$WS&AtD)֍6 Nf X3྿s~gnĆ$* wKf>^u,'Bc@$/[$fQ)@Yo5ؐ9^ r U wyAТ,H~\SaQ0?WDXuu~65 Rbʕ~KԵ-uye ʅ_*:$#Leȶ?ИðƢLWC m v]4 #^.Nxs'&AOD>c }aU/{iFZϵi`(E'vďkkꘪ|D}~/r-+A9ȅ+$iHdOtF(([ܑ(U\5 LpW3N".caB`l[A?/qMmqMŧl7'ߋ^l o s%*x2d~N,Gz˪|NI?:}j&кƯFmɻ9M`]*!щhVdԿӥ,'\OݻoPxH5i}G۬0ukkYpbq21m l1;u^Buk.S %`+d@&5Vj4nɭ^3er]O%pّ##gPUY'<eB}6O` _~"}Xhi/Cº?|IR4׫^?Wn>) [TF>rk+ '˰}Bo_W4φ\hB`C[{ߪbCuiA2,k頹d>^5FxC[o,ʔ2֚K3. 2eb$KFb﫟KI|IJyr,P+q`ȐX*ΐs@`LuʇAtan*0T\z_twE@gdt2C%n1]oB\#i@joD1ޤݠ%B@VQB:"'g(̍f2 ƔU#&KTYLJ}A_)~|P{,~Qv3oLmc}&&~ }u+KEڍe,- zXoPpې.vYbz%mߗ_h$Z,UW2 ٘r}d@^ƒ'>IG_WT(e:$Lpjκ-"AFɬ\Awc<3h%H"#+X9X'SV"J/\x;iWoS_*#O eBu z5-@6!J8=U;VٱHGNp DzM(g(08W0 S g/1I7-ă#Ce Lb/ nX}9 sSr \QsZt Zy vkEKֽKNp+gǗΓ_lϼ$f9Ajđg=C!y=Z'8nq 4FUzs w̒Íb}ުoS1X|E<1,p}$w)7;$oWOl'lD//#Z1Onz4S΁0db7z~<񪙒YK2, ȳsDM sTʆ2^^Ҹ y{O:PhIlZb]Bjy_3 ?nMFR\Hax7xOrZ2; וgq:rAslO_<ݧp K֜oA:P` svvG )@5# .c!̊'"QuC%˒q _2\4ND6|1\r4#@8sÝ7~n.qm ++I { gp' `K5 ^ OJq /iIM{33bcD=Q)LCu`~979AZFoe^ӫgQh=(Y*pluB/hQdAb(R%F w/V31=+9YlϬPġ2 boTc~pq%õgZ$jBpz9 ]TTNM/:(٨kWU6bjXD'݌BC`SpNhMwZ;( e@*1ٔ9;Y:N4As˳X+-?‡h\5LN4Bki<[טȉGӔi@r)/I&}x; kK+2O7iX7-3P{+!%`"V׎/C 1X42Uh˟p-E+ ffJj.W~F,V^h)? T&ʞUޫZ(> ta*箷D࡭N${9# Vz/]Awu6AP@>p;;^HuywCkr[I;~ ќUо,FA{.9YPA#LjgɀVpVQ\aNH~G6cQ}Z0HS N0d:Oi(YYN01WΘ6U>40BǛYOwS(HZPS9j ђ`7[]:h4y`s psI@Lt;&_(`6sDB! yn=7 #1='YsB)| iбޡՍK-RQ߽6c]܎gq0(\Tr+e>¨(ML瀱-2UQU,,j]z|digz*\rӏtF ORZDIΔ& 4%hټѵ{CKm2w&V טQ8FGHmt`(D|xډv@D_2#;h0@?>-(qϥgәw| 0[DtB;c~:(6ǿP k$֑8|*tro=*@1qhuY8hC)^9mbYl5눵<n,yBED!5Pc9-~ݮY:*s@ORh[e nP[~ꋺ'WWI4Vl j0&}CQG2԰ V #R$ M!-< x/!!Lȯf~^a 2A/=k h| &DB 崌%~"̖yuzqG7g3cTzmx1 7#>^MĘeq9'j`oQ6학hȔ 74e89\7v?Ηr[:d=rMT{]%^:z ~y7ZeTJ+\)U9|7x{DC! f#•p1 RfL>E9IɦBGwCoi=H-8N XWK@w+џ0лaZzTHjB78q-^'89 w[7qpk#0jJd}H_M*YRt~  OG+8.ߨ;yD0“'SnWC gLo#,@!p"o%hu@M(g.PYio:X? Lc%Ti(W_g@!ces}PѳS!5aA\b]@˽F"/,N Pmewi209/p5o$vʝKd_وy+uT-8qzY"ͦ}"tyՃM k>ߑW~Rh/qH6˼uo@i_堚;#)1BbliV41/Zc  v N/َs6 ,q38TQv( ȧJ!$/1S3Op|%[U_6L"ޥ?$u*@LѝPx{< Y# g{4Kxy#U"z27 xYb!$T5\)~ߞwmnW=R-DH&h:/c'u\Ƈ7V`gj%" Լ-*11@/g3dQ>eut_hkZ+ 1-u\w`ē6TRA`HsN+L!c\kRy5`LC?|ɬ}Z0ϊn @#BWGiKWςKgДNc 'Q@XE>;j Cp\oWl|:r[jsnxvur:%x콬4O dW}׶U}ȭoFXsFL,]47RGFUq,6)U4x0i' cNQƕn)uyU/܂aVB]e()((W (gXl]ʄfp<@2u2Bbu$HQsE5\0hLds =.11){ ͘7 ^L):K30-Ho,Zeׄ{Y ?r|ևTBavEQ)n)$Z^BJ$Ks`(g#MO-7yM}}a8%+W!m 5q{G9s O(}e[(_w$keeNc}|b#SUi {<޺)ڕ:rt3;YLLk7ɫJuKU7ޛo#kr~3}BW"q=΍TAӸ痙硤7Db64P׭G-xgڧxӂ< 9L4ىg Az s( Qn܄owˌ9 Z+~g=b7`4tl5l_<{hص,pp}l@{m'5D*4T4/S& 1:>\2ڶiv 8BP 8D-P[ȋU"]\ p6\ Om ]`GdCWG}I,m>ܡdapU"Kau [6=%U<7|s)vc`j1B7bt*LE5nSeWz><=!paFz$ȶdv}bXs\l+nn,f)-dzr'y ȉGzŦRY8`)sȤlà(JJ*ȲSX6QyWK0j7i'F}Vgupj>+l^ oH/Z{SΙ:'rSYd_\d&;GnRp]6`)qskx1 *hQ.[k"r0}қY2Z{P7U#*xhVncrefHǸ4YJO$3(Lj80Pwk_*b#Ø{ii1c[I5ɡ?ZuSBwh lz׈2}ЗB n`ޝ0a)nȢw[FnjQGYɐmc\Q2[,ܜhzͱ = |\co]"4=o:uvRr):`:3-ۍ^3282oZ-AxցE7&-N_ɸZ.]Lv!{ЭM]j‹(l rÈi\@D{0…?)ֿfh푰sI&}: QIJaj`d1v?~\MJ^VFƊ(oK1@fgc}V8X .P䗛գ{p(n۴5 M0'gO͞t5* q㦐, TӁ}?A2L~\oqۍQr(yST9%' -!С19ӡǶipfcco賡:reS4@ Y? p^\bD嶋/}&FL\(ErB5ʞ"Вw-uIeyh,E%LEݠ- w7%\b4Dze1Ò-|I31lAh e9rH=:QIk! cCQdz A%=ÙmaұteYs>:"%M&x`-Ӑ܆}/x1{!ЭfNG-Hu o;oP.0E,c TvRSQtF9{/!Ex.J}qaq2Q7*:'ۗ;+BgO%̌\uMiV `GyQ"V!6`Kb]̵-x_2̈5KO)I3L*E"5W#;@} 06F(  )DZHg ʭ05ӚpMQYc 8 4̕i^͏6v F e|*ӺUD/`̟߇ l^U}Mk-~f{~>XcBWUm?nI4VIMF4&璸*m?XW})&ƻ#+;(c.[C\R`ڶ~̬8NK0 (K))UA & zS z5uol23>v t?Iΰ?igeq0+ _t\~[̷&UlڒvNRLTpH.9t!*VyU.qG6SZO M~ ܒ;~t+K fU4sxLJLgk+fH--SGdYSr瀮a"jn de$)T[1"Jp:E+e YdN68HAxO CL逺߉:C&14wHYPM\y %-,8Яܥ8_fDux6}$1˅~pm8 _ f Ln΃CaΫe`E[ΥuͬՓecv_GG WvsB4:JEnu$ NAmdcTEǂ$.IF4k["MrF k>ӪN y+]ou"|^1B?"d+=yۘ2{|K9Zl(I#8wb致 r!Ø0p R_r)9ѼM\pn)Q9ى́pCKۚ r0g2xroZۍNyώM5QTu iP WDC6vq0c;uf8ޭZ+,W93]Q Cy:yR[aR|9'K:pӽp!jTZ'3}r7Y5kfۻGX_R^Dey| L5EoOS2tIҎop- $$퐦:jg#˒n%`_U;nɑXo#0nCUV:'2$2Uf.:#5H!P?NwڜM_J>9wfr^")^luxzK-a}V5ўY>&5 }S 4>X/0T%0*yK"o.uK5# eCΪVf>;r}@,^$A}+r[;e0?NgMދ.o $r}qZ⋱j [ לNfaNiϻF=VD9lO*VF渱 b$pP:]kþpx)F`U^b`_DY ϵ<>\|.Zߓv!"eNX顭USmƧW𘡛Cv?BM"<F~GA ٤)bPݣ;כ@H<:)Y7$w>ԡB(1&R1Aќ` șXu£ϣ$ 49i^K:{NO "9vOHMH#(LҦƦRiO?>.Z9ü{$[]bn{,]aʗHWU+,gx Zj+[Lv;>߮8Q۠cMësJO7iN[m0f;zjT='ea]*G-T#yM@Xs]'K1{ lG˴U+VR]!iZpC㤉ԷNT#vS4cX0^Znx,X ?*~9C1QT|/be-fe5(+NW̵-Քw2VgU(U'eOl(;]: :/# XA3're&>([7E,M>Z@[-|vVzbڷ(܈k=<(Z񿌐x pd_7k\/ ao5ɔ%i&39_]=OjXgC_< wmxᬊeMp$NR*.%鬉#<tz-wGsXZ6srrwR}~V/7T<.Nl0ץ!e ^^ Yy.-=<2zKcl ݌;*p`f_3 {)Y*{_TL kMx-B%qk qeq6@ebcG*Kl 6;KiB]J Ӱq>㣻 sW*zRc<ԏׅr x& GvU .{}z TCakxw).{)>UC)L&h$ha9.1":( bR"`eޔ;|ZRCDJ QC牪ARtE6EvOy\kvP[Ja#Wz6 ɍFS&y#̽ t(L=_n9`lw F/,wXW1{rO6|lƣK/QX;C9T8Xy(+N ^dざ^s:niI EQANEU,~ iUAʍ@{본 )Wزzu'YQ}Y-vfJ٬;7Zxjj@𵘻' DA= +-h*[yB܇}'7ziWH֚MNJC]B=|2i, zb T҉ ;gH?Yht9k3/Bj(ᯟg@ہB/l;l膄?ȉdJ}L@&bΉX19YB V4] -`Q/bs9s%n4Y[Sd7ul[M.fJß㖣&B9Xh{$ 1C\O@%O"#)u <'a[>`^4:Yc&Q8vH.&%e+v )"X/ƿ{4)7lr5Q˝!r}gw,b9,xt|9K^Զ}vSj괓}R?l[q9PehAƂÅQ`2pKxZZ %EXRbЃiҪd]YkGhBmmޫ!ě-j3gچN M 22֝9T}ݶ_@{wr1S7NiUZ]KuBUJ鳜fSns^&=[_JhD;fu>u'V)!^}l+c67U=:Z)B:(0ưkhCTG!2)O=:H1錃r-jI:!)p[rar̢~MIE'ࠛ ٯri:`м[f%u/ɫN#b52&,El{g.1=8z (돉=!|27 4"~ƃx8`8?xY:d\W,rDt./ y7dgxz[XcJryI&c 3MürqvZ,,B!Ω0PT;AyRxacb'U,Ϭ>]liuKuRC-N"au}Vu&*F?wfUN*V z6"qQܑC·C HZAc @$?K^ݻќ#=Jf`qG Si!Fp!omH_=юwn9&zjd/7.aI77_F`*a~ds cԹ~k6O/GX!]F.׃qm.= U3 xmŜ$Bj)?md< 0]W L_Bq`QQxkNIw*tyו7N ?"ɬ k/'7~aZ? 0\bu_Aeo(\lPboa TXNG>Hz4$R.0Ru#a iKO6. ql.9"KEm"=,r6A>x/j i;R|pְEǗ7Eߍ0&Ņ^:. (K –P&7Ԧc_sRyϾ5D, L#!HH˱`f alp+y8U=vEEth, mH51`K`vMWE¥9$dyu8nt BoJm|)%t8gہ&BEN-YHy~~`B=\6'?վ&OK9'EavX_}ͦ@X?\]!|aewa=(NY$j8kE8q%»AVtV-,IJH|A~TV۴a)MCgӎF4Sȩd66ijtPV<=DBH]!XɤUI*)BSBi0t{/| $` n-V^\V;Yz1K4ּUr(1}hzX4!-º xAP8q&2"EII]PW)ț4xi)Iktƽ,@U3:&"Q9R6p#^oZ.d?dž҅ &}J cg{|`p8ԬЍ``2P~̔U2U0eHtd/h0L5o>$P6R@>!a!h+Ǡvl݃\[8Cu&~s tfZЬ8s&m_t .yzG`5Hx(mEAr8f$%M^&iy5Ւ"X9}?Dee*e<s ='Z% brT8L Jg^t3aIXE-_AB抬57^ IM Qhxmǣ*=:T.b3{+oFȞB4)IP@9 °ڪ&h*&'m`}vqyDRf林3U" o9^;ٝLȀ`;?o7 z8^tu.ΉN Ӵ!ٍBA(YUКIqO%lV-GY1̇V$H?FI>J󼀪{eL!D8rj|e"`I "eJy7m ׿BxU<`귵\竱?]O;Z]0Kyƭ538qVMumRNSEʅwҐq{WY}BeY ӳJ1CL vjL'Œ5fCMGtǤ_u,yvD*@!RQ/?Xk*DrhWo:fV[}knJ`';# 3*֎S@G Zn :]ⵟW_lJmMg4)j艷7'yysof~N"R34'^^QZ>6MC! {(ɛǪ/+}?#rJqaZ|._1W3fqgyԚ5}Qt߈/ DfA$I= pSt{? m orM,tkvWL9eŦV*F+D\HFT*үTT"(9^ Uw# rH12-{9'QOOffP􎐟QQc³z_hZt{xcf]^|K{M}Hԇ'!|&+ Am`ܹ ӿU1w1'N`*b-(@]ʚd=(+6Ohs@1P՝-fFD>~刐O'DVgD{mZHmD#̦.ň!nPbH$zjE|ߙoɷFq^%.<7͟(]c֪]'N/b9Ou#H5c/ ;bR"wH:FLmPS'u0N$yxIw 1'ww6!nbV{ eg%b?rZp[Hs_ʗAF:{'pxOeG1fK4KOW3Q KyH1Qо8:)`bWf2~k9_ʹ#ȣ[=U&=Ѥ$~EKWl7 BJ 5b듣!Dej6s7R**@kp]/hBF&..=/N# \LjNH~ c5VmuҊ@DCHq1|#{5^}5njxt'' 9Uﱑњ&Ϙ(@#3cd9RL#;FRJa>1%Pkިדaaz&x=rpʝ:!C3I䡅?bYs]-@{REJL:^sCýS?j{8.MrpnɘPq3hbix[At0#JM! қpe!?Uǃp\`(v2ﷺdΖFrR@ VW59[s!WuT3ߞ:O񕶙*KL O߱:.[͊|+u dw7f,|\W@ŅAKV|BE% t+x&E_kkwB:lփ^:πJ3bJ'.N8 餢_s\JZSË)#\<8MaU_ C^qʙFN:W"LIٓ#CxYʾ9)ٔn]k-GA%"5%:g%>g'Jdv;2{~='.2{ad$eK|^DfCDUA/EgC"V$0oЂޟ_ “sLJ6RLL,Kl^@0|HVq[T2yB_$ض< 2I x Gi#s:c !"m/.׻<=<,eڷ 혘 ^Qci _L<`,w `YH3VÕtKA C8̸?=o\15}#-b MQ͉iD(|QS-Wٍ7YJbїx61V6O\}@|Ok@7U^>$`#}#z @#ta}qkum>Zn)?k0o$>i_yaoDwjQ~/iO|SXI5 q@[j CG]1bX2mjb!"zI5}KRZGNȤ#ՕdŁaf!Rwj,t䀸-Uzu$O-?$A>VZ(D/S`ҁY4Q$os_`k.~,Xcoum؍iILjf< &rb㾰fv5>"UUK~zcS3~w"lf&@>+\{ۮ[]oƃI9i $7;1c 'TLVEoQ Bg; i"wڽxP! QQFԪW&I~*/gwo9/:󇡌=vMkY #b?+\+`@iJEA6G`_XFDyH m`FYhE]F#ssT״ khE[݀G3Y?0ʐǭ4LiwlQSYkc~ŵ{ZV;E [% ݟK"? Y4!$t}\A]MkU#&T>hf Y{͇D%k籉|1^@ď=>Ҁ9\6Iœ*th&dr^hm1y3⡻uEs$u!J7p# |@ydoʸ|1U#R-t?"~V| 7e_-**gbgOP:˰pt+IFFG"24' ?Z*i_!SuWZ @+K5БQe7tnjrP$ϖS[P$oLI d ڸ~7F, L?2&amS!);DB o g* JpĞ[TNlrs汿3:,e"2sisO.c uz*!D2#AGX͔/lh+V5ESbbiKzU|{ `LC::ѯkd;0_/h|ZJ_[| XGW|n-K_ހS?2'/ +z-4oJgqe|q5F*-iLWPKm&e l*I]'?WW<كIf*I"~Jx3Xk-erG;]9o=D cMIq#@N1[<=9̯!OOTܧc%lF6D <>߰ҏ.g4["^+\oMc|z6W^S %40`؝TOJ~u{gKD!V1;fd$>E=d$4N&Œz͕Mwat>5Vn2׾.{W"[j.|;L =y(UrE8x'(G啄Gڼ)Z@[5z |+J,%2| 0Yxvi.t@f>*S%@03,4u#f4\am`v4{&Ӝ]W#̘Ԫ΍)hіjڽbF5i4o1LGCekqS$2Qm$z)NlHF\RZc `|4M>kA9i=aO S.zZ>&Kvښm~S~0YEY*uhwSEk R0GɩYGN:E}I%w݄[v ʱg}xL N=0G'Ux3.nW[p6 t,ܔo;+20l@op[FD#ْ-UH$t= À Nmbo;U[CZ3:|6J W)IpJb3ll׮FL)6pfU*dxvqQNV,Sub(XjYIb}c A̕aF[.d![j%9IMѧ÷U"%wR7-Vh3X04ĉ  ^F+QOp.ZIM.*h o#9#dpcCe4xmK;9Mb@h`ftHQb*w4 Z'0pʦ5ǥ[sg>"-Լɡ e-ؑ>8MbGQ[:_AtO$"E `bbr5;r$6mOmpsO ڇhyD1-I EMX{k%9{5 ]㐃y?a t?C](ҨjG3O.@{!ێRɢ3 'U5C>Cbzp'S,ﳓٛ1ӿԠ/tTfwNT4砉 `Gt5:\M8˂d"RE/Ɉ`\R\>}n!vDtT?J BSKJAE9AT :gruZ?\OȆt~5`>G=)Xrhr4 [[&5`cڴ~vOr)k ~?i=g3#ޏ9FݸJY~zZ 37%EMgYI p`,f;e|bE$bٕ 6 j/#5y;P'ϨĬ;#`(Vd$tVA\JlD~Ê_?ZTtX]j4gǶ|:(PX&wk YY }wuy*~^d~\p,< Ґ)A3=P9B7:5,C;-ƖwT0H}^xf&l2nIDŔ]v/*.*7rX?;gN am\6R̠%a6FBgrڠA@iLBDM7A}z+=ǀ+iΗ]@\ZSU`8(׎&?/T,V߂M-N\ME JP0>yQyjyn}Erit. !?K8=˄ڊH`@IfAˣxJjGXPq˺pkyw&Z\A 5ĝdg=c˓o\ %pkÐ@OQ,Gu992Kj*R=&/Rv?Xc碲֏R;(U6 ˣZ_?iͧ <>xѣՐ }&hB.\vH[oc1^ I~-sSѻTF٪yZH%mo>z%oh ܭ$s78~:*p߹l[?#V.MOl [o`].jtkf'5Þl*JBL7v!`x( HgR_\%?3J0s4/ǎ 9T Emcҙmqv vaemѠѼ_t)b1 R5kS78^F ݔfyS:|kk~yWu'q׻[2_̵i<(VNJmp!bOvUۼBহ5q3_b##3@S;[&PDC18cϓ߃&D LBſ~FF8(HX~ۨ` 2\Äo#՞ٗ"Ռ^T*ӭ>_1o@d}\l+k~Kdo8ʺS5(j; Lq|=Yk#6iQ2#")B4oǦIOI0qYg!"@%Rv;2gfdCXa6A3_[~iT=^vB;c |s cB~z*Z)!j ?h?V HF~-T'`ʄ|9?i=T@T=5 Wl1AUP3CӺ˜/l JWv~ m0!cPW2YUsZ`KDBڭ\Kdꕉדf鳫O.Cp&P'mW{>] X3m 4j$u ĬS8*%_\75 f&%X?>CY'GBN? bf{d4 TƐ#U$ս&|x+e] g$fwKe]MQ%֍9E\d'p䮣[UGL3۸媘 C8Ql)|Su?[#x8FX`0:6?3]c;S;5cay֦rkCN0 O_-=D-=? mHUny-T*J{֒82AGO]_ɥ%kJӣ\DWlXZ)n׆+NnR"[vm@õj/ R8A0b{WTK Ezp% ǤrjE%X Hr6̶R+f.U7$'ͅ/-:dK%fY8*4 kܓ('Ն?%7xl342Xي#~סLQ?0$S{{ӫE] g⑬IRz/L-eޏ"Ǘ4}8 wB&ps;X^Eu~&jN`hCU"+~5Rw5iО-~=AX`9 #M!y[o%:%eЧSyzk^SFhꜱr1 & }2 n10sxuqϗ<4RA𶪔hLٴcgP-ǦT7cQwςe"PrP9 )Yd!27iVw,,EqXF<ei<9w)|sU -xCXwk_ᜰ@'ea|LTUtXsO8E7{Q;/[ɉZk>e)^2Mv;3f}[7D ΆUuرs:;D߈7 F}Qx0"E8X+(᩠7Il=Ckr&𘥼<zXꋬϡ~bY5y! da:5`Zc6(8 *.Zq#Hƒa`~|Kk-:FH/_+1C%ʓYU?eU@VǠ} %}~TmH, I9KUn %@wfxzZ5ukUƾ;eN|η߁k'^i-VUe>;#kjZ(_VµxjuŠF0V% 5YI\,Srl6Vw ˨J$չEN6{ѫ5\p,]2:Hg݊sVAa1CY;Y9ںz`m$F5{b.M zt4oErѝ2Z#@Z{߫]PTa{jƃ %Dc H~( a%,w$3ؤ‹٪)² 3+..44z1VcVBocuܶOPk7o}W)\r$SC$beH*K v̥-l5NsF`зy[r{krFzHsk$q@tlz=W OFt|& 03yם900gOdl]ww5ȡ֪:E7Xff_U#-%FO5 p. ¶0>f\$ }Cn+agE 9h;jP(3(MP杓=dA;%6L#DA=ՂTDyHpঽ Dw!O`)'it$ n%xp/ hBZvCAV 6aYAu&W+K rTbw}I~9VsM"45ڝ"\BoA9 ؠQ,Y~դ7"iHx)Ic8{L{#El #\K&A畂ވW$dqJԓcO"(jH-$  KϏ9T~nvi2%үJgU7⿍pmW ~i|f@u`1FwT$mOr8n ׆*iim4__4돛!Ջ+IhuU_)(yoS&gPpYi}M eJY_iۆyF ,VP'EV7J8؞Wl6pޟȡ`Iy72G_-.s."1@Ek5gsPOɋf #O'* Pp 1Hm#&Zd΀\1%ԮlU/#Q`Fwra-ZGBLkKa͜h\\FcT)ċXΒĺqԼJs`oVu:]3Ffտ$")x6b!jÜsNqjFQ ,Y5>ϗ;SS 'Itu:c*8Lp3;\'d6/,4GwpF鉮d!8L- (^+ݤYh~S ?`-ƯNʼnL:kG 2g/w($aD*v($pԘ|!K5𦎮L|RKط[[#pWkgCCA,h599A|7Cl5.-~/=I"]ֽ߭H{J]fD*6$WiaBU&k]Q)pT?< mᄺO#_;>(QېH+ƕ TDlKDjsaK{O/)-v{?@%vhK}}S<o'0(u+(D )c"m:)TX~WZ4P)QD <,wG?iD IcrTC]O {GH xyOUo'Q(1f^ RHg=Сfϴ6h+̌TVrgq'e{h*A o?,7'e .J%jv1\Y0r 8H |9N$!UT?A.Ǵ{$!}eXmSK\(rXE0^YI]$]=:T]N4ᡐD>N[c"nP0Bֻ`8GnX_Ihpm+\:wqsݎVr1 < Gl>bL :,[IV7Kj#{u6#fd~喒26&e3(+Ӊ8sCۯЖ+qH >"δV.گLVO^dݱ]R[dpfس\:8+-dv<`OrCuH!ҼMإAl"| zEejWqi S֐/Vw7l;67.ݒ<"0%OK5Ʀ9죀|myY@&5 N%fTH‘QGsh:CլݵF 3ex[ǫ(R d>,6jlǥ_ _8(&6)ELd2f_l#YR GA7fֲ@m"YW5d[T!'WOfQz kDجBy ҐK _|?4y$7clr!]ԍY+HGcV{( c5znCeGǬߘ5öV}ݦ}5R#i|ދ=C9:̜ #_#6ivh KL<}( r i> KYh[@Q[-^ ZA#QuH7 vAjaV@nY"C1*g>s/ :⏬rgaj >[|pE.v)^(R\SgҭdÈ6y&&8*B2o$unА(z[a!H^n6.3Tao):p>2*|9JY+ˌ*\+]n S܄fO@ݰA5 V {|AN+(-{^ht^ϊWy:h;W)B@2Zm.6kc9Xk]xc+ٹ*UZI=A s~+[vTXqQU0+ߵЋumo1aS ?eR-1dNyGPï\7ۑ~3XߘZ{Yͽ8.*f{L` 5} ~[mJznzޙ 9TtD?:OԔP"":w=:ϲlmNSF{O]Y"Pe\Cu/xPqrkLbc7t  ƤsŤՙ{.g.5Vtl npM@S30ixXK3m)_:]eW,~_2i]ஐ%H, 5m߹:.Xg'cPx.Y6="Ց˄5C3Y|}S3C%>l<E}bjm{\/RƷdq4l$-H}Vas'Ьezkr}3s"ٸiM>3U`t SԸ )0DF|A+|]̧iQz2Ǡ),^6Ob-UZAQ!6tud*DAxmP0{p|WkN#g$tO-צR~`qS$~4Ͼ~̚vc x1BwyQWQCA~LF[ŽI:=3 w|F # x2M?&+,Uj{. +Q+\{$7PW-a^4ϩ3 wnK^FҠtǮ9>.W b/-M, M')Ys܀3-R#h&E[&eaFGdzr_BAN \@SݸZŌ 4וZ8ufJ0ͽcC]+Lau/B\#y>o̶v~hq{Xt sıw7 Ӎflڕ[,zG-ub3Λq~cjA 큮ږP )OH%x.0hhV$t@rrZZD](?gZ~`}YR0nUדSD 9K3ث4KRL$?CU~AԢ hJ#Hף' M,Sk6`) AC52;Jߌpr/Jk&M٧e&kh$X|oa ,U{l6NqVekgʭ_/xB ͙ü 7"AJV}ߎ,5Qf/эD"JT !%  ƛKW^ Z"n5PqNKSzYN`,OXrnhd|9j碃k@Kؚl|խ0DU<׬KꖌwhQ9o:4 q9xCG& ~< ²UlQG$OR>!G(DOE BZD}UE3 hzuy zg )4ЅMt @`\} WvxPaQnv&́~]D˄18.qi9V8s#x= XZy|*z6bSn]?-BȀHtLk!)pr~slx'N*q(=l{&1Af 8}`>]`AxG2ln0~x%D?C{[>s=2 & nIcFMS|#>6OzGUjپwœ`x+l^ Y &@Q=R)B9(K:Oi^(kZ4 X~T Nv:]AXF&.G!^ռef8ic3[O%vCn0֣͵姭 {SSf'Ql=@p9>J#}VHbvtȟ(+bδ-@Oc@_r*bnoM%mv.]9`R!"8?}S2J!Jx>*>3*$eM-eYо> 7wmNr،X[ڦ,4rSh!ͱ&wu#jtbK4K3]x"" =c=42= 5V]sD)QOCs@D'cy|{ M?CV.UMcm"{H)BHdД W+ W$pi36jur;`t+mHqr Ϡ]kL>;me~)YpFd;a:'@45\s.D.NQE?^ң&SDqFSYRgԤs#]0zO M\E  r{<5ނh,%::(:QCՂqH|P3H;Ȃ>т..: ӨRt|hnj5⦇Wbos `j}5͡UEcTa(aWCq$1XEe`.r>k]kW]{ɸ>79r MiLb!x|w)agFyI{Bu2Px-!4g:qd~n\3;aJ y& 2j⦘R\;,)!ٗI(s9_$Ǐ|>lygZ ]]uV/Jq{  `f؍H0=)0zxFWweꢏ ރ|:]ua KHU u0Xj)%]j7It~74 ^ &Sļ1>>#VI쓇=xu-[:7>Gc> RQ?Vz K АZieB6OUm.ބlk) 5jDeA,H5f%coH"<_?9 I\NW*gKh \^|Z ڇŲADUp` w`jMCjb0]Ӟȵ'F]{e!C\ߘr!+c#؀!SpSGTg5MqggPn 3 *BZZX)Q|~p'&S(*`cc%]2Yݢe{_Vs7e2.>\>[oR=D#]=류8D,bq9ȶD$BbM.26ZYBΝ$K}x㑗! BG:q'kD. bW}lYvӿO2d'iJیsmȹߖN.&KE<ؤ2$vq}P:߅\Q-TS~-T-K[ ,0wOE&ʫ~EUHgtbr\d,@P|Mulnˠ{09^i۽э!$xLDZ$*6M"E't$iYs+ ]{#A%9H"m etj*zͭߝx\ڠ.vb.8DDܠA^$Owg~iBJwv\%~ MƞBZ7(aʼn{oUY]EFc Y{=꾐t𣃪U7a߶P&+zu$.$Փ V{M(0~$bb;Bٔa,dWx^nIpk,RL"X O3ގJ#>"K1=s͞[ϔa;?^e^=N Q)?#U퇰/8&$E.!RXEIN\=ECX!"||[9#s}e!uU4㲶TjUL@FT@z J>ub, 6cت-Q#s`Yp(N稇vB2kRXVAz!rj+Pꏢ: Ռ[Vd`P;jhYfsA+gm@ةKVz_T0lS*OۿAvw_\Wp+2k 4NSBH&ˀ֢r.BU: 1e]H ðui5poG-s w-/"T/:QW /8$g b,[wAXDk &e23,=QSrV5=>3( 9{Γa p|D\b B)?3Ζti2ejr-#,_N\az[i]\uOC?׈CpXEp|)N;r>;BX| \VT7)sD@\wgGcZD[K1 }\eh΃ ,4Q{yxX.F P\WtG󍛷3dgUS`'c Gducϔ h38 Xї,Oi}HMeD fE4QkxFBoawS7dr7u6L$v$gSJQV jiÅ ۊO:˅bMPLb*R96C V7,LчKP1(Tcwu\PD$BZwCL`妌aDb)KEe:;gd\]9j(L&ٖ+u~n<ЗPgpƬ>lǟ=H6?Ro)O/O*&#JF; %2&b#0e.<._Ռ$Tи Rm81:?[J[8U! E9is7h'''WzzǔnAK}\'&Fi,qI#q.+ ]6@!S-WO]D6M>h1vwg G7FY ҕih UwINWև"gqN˭ĎW"dfj5-2V΍fly֤֐ut'{`_MEZ*ŅXqPa bxn:^V{H:Q̓kI{)1v]G,TVl7s3#ؑ-aH;ݏ N?CI ۢ d5x1Nw(:R.ŚNyHɠLS\z}bfa75zqh@LPϖwQ̏Wkc:*?@ UMp,7^`uyt`0 [N .7~|)i?t h鸩~!n)ߌ֯hM'1/޴PT%4 uݻOOHE.Ѿ( &`D<%0J ٔ4ب9s|4^j:[jj!(Sِ)4|0:twlLܠ~zw2*𾿿%ݫjgN[5eqӮ+2k˓~IJKT ^r=1* %\}5E¨g рbp ."l2Z  (1\S\'r4{hZiPɍ!_4CXE 4?D"3aG(S;5_?ȔB԰k7:ƴgVNKlYŋow;>nh| |}o?×ܥF:ς-## Fc(!uPKtf1YJj{~^Ȧ \SvT٤Xԩx6s(C%DBP.ڬ |%_O^[RWw5h]hLfzL@exOPMȫb$ '@"aWf4{W *Ƌ;"'Cocmެ n0Wx%vp z(@۷^띬>۹ Ӵ 󄪂>.^|aeNuȼpzش0da >VW5z pL@BC o|̍C߶MycVV& g},`](:,8zHu % M,<ߐY42Ҧ_jޡ~`DߓqqU„#[ !:  j հ?YySו#+,  ŜfW ּX?vJ.4N)e&+BLw{O:)]n)WNg&*K̇!)Ţ3 ʛn37YTCON?-lG6{>|#mN^7 dYj%"viEjD 2qw" 5hg8& \n#kiB 1S9.YCqhNc}  'ϰ@nd|$IA4?%>FUKWH0p3YFEh7R$=vt3fq]<:y̓^8%:.GXDW LXo53%9=190ƋT4mhӜ$!A+J iՕj-6V/K˨~@6;@>ezϛ ȆekLnB2^xuNp$j]" KoW Pv!Ȟ:9-&MFm;bu=;M LϿnOJvOgO fR7HTmX*-KQK>et5y9 # -nJvB[~/HV{1PpCشu3LELrGݣӊ.O:Z89u:4o{-O}U}Fr~r%ejrZ!_[v'8!\rc #MImN]S:i}u7SSP ̝;ˬj,t%Ŭ+~H6tըѧwH&Dl45=wTD@v`$% WtI.[wFg\[.9'GGe<.{)嵕XokL|#4m'2Fd^ҠXkQnBk4OؕhM)Fko4DMwRuB ,͓>YY%A̴FQvY2iŶn-.9!U_{fiҹ +BV D#[hSIaHBkll`F1="٥q.'Q~) uG)@B){ QW.dֳ2Xѯ*a^ )%pe&nnK#3f95{}p`靖oՕM Wo`</V*POH8ߒVu_1cb{e jW[ -%@i{fh^~. }jh91M:x]n༂ Bj4̡U1v:)\Gj; ;ɹQaoǥ蛰G"šEz:묿wRzrXr=$²n`r yk ǚ*ՐoN+|됷cQ w+ڐHAٓՉ(w%ˋj] Buis.&ޟ5MH0U,钖:m#? "Kc頂ߒ ?YD7]8\,xF'`5 IW&T䔵\Ÿp`ڎl}]hݮn !bȟNG-Tݩ&?..ցx%ЊQF|:Ll83o/k&k* 6 5/ֶuIAm̉~7\ڳyyޜͿ(=s PPFaWw[H֛i x/Sr$`썜3NRIU%?Xq>H['mW0e:,Ҽi ҝݾk i)aY/1=QZkM6^zÒȒ`ty6 o νh0E5&gʡFDt8DyÐ̳,eק~[EK:K[-c!  s\gc3, L:8gYYҞN%ѫ!GtV^Kx"*Y$ }%'Ie$̠v3y 2:E#)>4ό~^$CPvʮ [Dyt֡$@$.N$l?[c&|W#Zσߋe܈Dҳ.?ZK(ҩ$u4eф)O(uQqe"41hLWFK̒Q% E[17 Rw pF#Kr`…k(o^֌C[= Io$k5CLUj<ͺ\( (ߞT'{+HJ(va7&S)ɕBmZ9,XhxEzػ12;6^-+ <̶ݍVz:wIMyLW1FĴjr:#l bsUԳ#<-[Ÿ0647lrB2rPqO!ˆbꡃ%<]0 ;şx}H* G#u w?]4Z\L le1Se!kE |^MC6&XO }9^ü@n+SOEJ@Ik'ÐfkMA)zg=ޔD,P&w@FAo3鿄 f  B@ELe@?U-hIrXt]ʩ[|(Thi9zWC"(zn}&y=BjeVmK(Avð2 }iy̟J+6YDap KHep3BRkSطL+fcD[ Gxu , ZVJI{Xg@Cn25 tk!"MaU"ԻJ\e;l3UqQћOOǀ,s%rtP/$61D ,?vgVw0h1:s<[cZ?? p+ͼV~InBO+fH]$'sC wZ!ob,wQh{P./0 X,b>au w2?Ha!Ix(c#Xrmeǖe@sOkh4Ó8N0`&/G |:ʌBwD;*8^[F Y.橹wpSE 6J0Svn&ރr,J6(T?uvU)sSv-pA \Z(asB۰y?A6K5 6\P꛺z_)`jiC6!uOD`V]ׇltȼ:?C9!}+p<_En)OR{س#!اq_k2\kw3 iQqLj7n݄2LN$f2?@zʥC֮i{ط~FE{qtɼ8¬ %Ϊms'SmAj !%ޑ?[<&OYϓX&V +t~%_a6:IDs"N$V2RƟwC"MkKi;!5 lybǻvSώnrJ`∟mE}ex :?~0[u8o]O*-h ^hK/q /%PϿ[\wWtSGw[|z 2 D{'dϬry]j6,SNw!tM ٕAݕ!kp%$mH$( ;5t{WϜ]6fT&(S@mU`y)L>9[m{kKu-(yj褿"*`"W. `,4v3co jׁ~Υ[@r>MbJufH5p2"ͧNTD\~p BKlTFoqx)ձmLd|Y3Y{j~zF"_OEP a2qzDQDs'$d?r(0$싐H*F0^?D`\%_XifD*c^mGނY8 ZN~0[sKBnw LRlҩƼiswݚʲ\ #ow TCzY9<9`7Y ֍<@ou3);5yE+xtk m$#3y)m4,;ٓcMbt}/3Ex.G@0W-: CJSaDKL@"O4ϒ@Ź!9-#x0<́8u[@x>ӌ AI~%n?s|-9Wu353k x\AHY P]IB"5*C8nнqXh1ibG?4}#:X+cdWɆOEv?ٍ v3V pC.,q.Ipr2PNź[{t/!S@ː 4Zx(X>0;hpy,V!FK0Ĺ L}G!cA5 A 0Ɔ%?2(]؂tezv qqkr8Tζ(yƐ7 $z-Gz] ;]Y "%T!WQejt-1#kaڽM/hmQxck+GG vǒT=d.]!;ᳯ|r\Ix@ du&LȅDD7~ "_ZUߔlJ7N5w(>D+'Ii [40T}_БLG ج،|\;Y 9DΪ5W ۣ7N=Hn8:&F ޫIET% +?TȴدC"C Caّ{:U>CYmkRfWTL Loywqa@ͭ3XҟPgAѪ@ZUJivCPɩ ̬y~!H:q$*ͮk0fsLXp Eϳܶy}W>O@WjqNvg.oCLLY~1 7(K PgKf:N(cŅaxɝE MƬ4DI4g_pP !(B選\ӉE=΁xYȇ56O*VQ7DEJ;/b1]>.q"~v> 8|ؽӸ>エl"Ǽ4P^coE9 ^?f:Yꌼm\]GCAoPZ}ܒv_l˰I8׼oe C/*%fOWjƍe`, gZ$8pGzy&%}!U Jw}ǝ=ث@Oh:5F.־,{p蟼N.?H?ptc6(1]'[Ysz+.UnJܡQ5XZ(o Bق^sNm @%;C5*'ϭ , $ФŸ*)Hq(8P:)[UkHagju.f>A9 굉l!hڋ3K$EI 9{j!|( !ׯ,1+ .³YUE"ѝOQi6gtE9|\ӐЧ  BK{)nYJ6T4uQ݅1V>[_\IBsP:$Q0-O$؀iD6ԹkM8FBʼ8T NI2lI~VVRtO[Iwk )'9an96DZ* \ G-HK>I^%o${镦;5qs377(ŁEK39r/1ս^&Ds2PQ▇kw4Ier15·p [1開t~<4`)G+kUx>A!m^Ȫj3,qb?aq7dFwy:ЩX|JSH|J"-%z "P_qި2nӀTKRy Q@*]5 D`2QlnyTC\PfǑM?9"(X(..5}{F Xc4jVv_7>NpwR>Ƒd eF.= olTnR ?] 4#vQT1KEUY |CZOjsnk-p'T e(LI yRw4ǭR@0_% A'Y*%sWgB9cB :L>$y.][@j:":j ZmSD$S]qkɫR#PCNqr+i`~ 8s5 FhH֣YQx'm A9sW9 kNCZ}o&g%SHGKt mCÅ؇Bd2O#OBaD75MuQa}^`lCb„aiAptk-.=(/I7(y 5O^|(o˽N5zIjvI~wW@B=Ov= ގt]U5Jbs9Q(Z* O";[BG/F,պ3~k B! 54M@<_(s'ت`[\w>KAr3ךG~kR: ("X?]-k02TEG>/3IOvRMA, EKFɁ hbr?ޚK>z3D R1[|md:4Kr4y2{8BIԻ.-Y `3TJk4f8U|5Dj{: T3)t`v􀂻FG.XDg&vj:-{\d-0եZ >UOoф:}&~soL{;t+5 AЎ^S `EwmG(hIaô%vJFȍg3Oj_Oz y O''{N=d=ok*MXvKH6GƣA'MN0sB63g\Bܺaݠh(* s 9|9q€6(,(`Ejbj`>,ʡ߂ ص5oy "!FX9I4RNȪJr9.}ZVb xJOۅP0MH^} oAg`XѤM >Ț27(@y,"pq9hH5$Dyzp%(bVCQJbjsCUouYU|,2 g,ꦶT2KOj8Jjd޾UwKq5TEL3߸w!J5Ӷ.*ldsDSH-b|).&&*xƾщ1Aju6wFybz'p[t[oջ~ Bw#hGůcWVx< 4-f%9sa~/7Ńޕp/qhVfgna~ˁvqe9ncU./.2,f1(᷁hD<5`ﱾ%ng M15,&$4[ضr%A3+uK7ql2m1vsn)/]ĵcyɋΩ 9GֆH yx0*rzbGbD@ Q{_k! ߈+⃼k%au͏*8RwߟT%~MvTl?AȷfH +-_ESL )oLcvF+\Փ8#ofx>i=tc7&n,VjLqz+Cd~1lY%dR4m Qji~3ο{β[ ޢ )/V<D1[3$plAHj$1NhltQNBزSޏ4A3 sK4ض)!\N{ksg1,ɷ">eO!ѥOg&F m>6WZDRDi`#f f=_톂 - UƐz9M6DY\:+YhH`bǰ֋Dt1݌ـ:֒ })rȘYL 08AGu$:8C؁ %mJiL4$FPgXj/&A#iK=8l`Bg ;/শ2Yy>t~" Z܅u:q* e7=aX3~BX33,I \Ys:{8?ti\ʁo ;Zh q}WU+Ce,G=%hg]-tV#9GuoxV+\f}uFayڰ۳R)/'Fͻ! Dna*h`Fcž{ Pw5Ry `^5[, 57UpN;xbK-k*b6~4Qcuz't:-ts!s( ghK?ZD"k#wCRc&m[nk _u\Xf Mnkuwedz$Qqj>W9vPUȏ{L_ jۤs9r׃wȺ2T3w! +6seN@LF2R>]jC1C )" ,r,:ؘxݤ40qFuLōQʵ%S@z딥B &Z nw9Om(zTی֮W{Ҍ_oeL}7fܷgҘP/ ϏeCDËcdiA,jfr%гeN_c5cNWhFۆ"bK<](u;,S 5Ҝs2l(P ?l f_ʥv`TZvVaSєN`zO{ p᰹2\Ϸ0b}^s}*@т{RhUے}2@(hGNىVZfHK,#29Roꯞũ3Cj:?p)Q6 :Ÿ2RJp0'Cѵ~OV?oZO2ݙ@uRK]6E:j\=`r+^zB| ydGGhp\\xtDu._nAVшfl23ߕ^࡞_!mI+Y*=G^snSBzdHlIstK"n~`f\t].5*0bhaB+RHōy޹o-ow^o3<9Q(Xd"hҮ3ɬgQ%qr#IGGpe/Y{h\fi6$t:\N78IDSXJ:)\"J9+OYARlZ%p~%w 3:qO':5VT$ck0lxR#؛Lć$]@! (m+! }߶j^0YӽW:*/b=wǮ 50 .PʫH%~j.d`Ui2J~NZ"V7 pJ"dۭ}d9蚃 b?ʼzud**."84'LJw(x<;?uI8n>rS ZBAR!ػ (k :گ4m1U7@o oy{ H%oe~z梚Q)KqtX>C̋8\ ghQyƳ YF{G+6>FR/DcXMj6z泖&⃔| VPi +GAFװGS&lrȦƙBrM@p|iAN wQPP;*H> ;պg<0:' S$" g.rx"۠`00>d^ssD4Z'Md3ƍ in^! L#雏Wot(u̟d)MըQYnNDIj;1IO-cwK=#h}EmrX#;J  "RU0w%*x`+ٗ㽑5Gf\'#:O\EU":Đ? gn6Xױ?.,usKļ r`Òԣi{ѷ;P !0?sjYY k\Wl* 2[`v$QsV;ہ 8V36`uʣ&!HXg))زpㆣW= %IO_}$sB^'){ lRZ66+SS h1sF1fl4ꑫ|ĂoUTBy YsxHT7d0}l)&BN vmEv3+Xfğ ."79 k3Ld NYɱ`+-i3aɵXL.#}FU)57؊g{39Jԝ>Kg3q|<tpLp jVgxir|'}*J=詧N{kznl 4,;DFA0جDŽ|A=Ƥܚ/zugZ?N3s/R 8륯$4c)7sgOFfnÛ# RLbSU0y;pA.,J |u~ŚFiZ,}#3_E 5h~r;(fLi/ &= FUԅݨBc6vKLߍ${Ep;LǶ~MY`P?dZ^H븢iSWm;8J)׫EٴBefJ :~6M jjԐ;rs) db,xir@^P+!τ9&ֶfAx}y;Sm&t2BVRiUh'r9-H ؟,le,%ԅp )dUb gR&3YFmd5kàS_LL#&m+3BhDKGٟBNN =B5}tq{=H TDʹI:[@q|bHįclk1$;>az$; j d~(X%f/Cc.WX-njWYf|P̠ ~786R.&yKD5GBxL0WDP% xE ,ŋ 3|d*H;.~FNUREc}7)axy.]xhw3~kդ:QԺBɯܲ-_'M ҝ2=&5VPPcЀ-~S{U-.ǫX-&s\{6 濐lNAgaӡJ+r VD! Þ%7 ~m]":XF_+>##'Zaaȕ_O)eN^2 myZ·քU#;lgA`ݮ핎\ vQT+>ܪPQgXbO05ftOAVĽ/qg%oon#qRBt}r4x\D tF*N4$3450k!+w"gF>ϙ}+ 1wx]C9 O@3ѿ>Y~ ˻>ʐtXlF;A)\ 1 P7e%cYtY-ޯK)"an( nK)XΊr=kՎkMU?}qaNŵ^j̘ե6R Jz]%3xj..wBZI]ffb'(! Vc"ėڔ!DnuLYmV*TT Q M$ݖ)FS-8r7ɞy%we{0='N8vQCJeh)=YکS ފ@Aw q&g\-l^f۱Hҏ0%A Y.kGR4_芐 VEk{9\5% (w=} "d!uر2sfϩhI/gи+H)B=pdp |yQe RQ\Nhq0fx:)q(hRN0 P"k"f.e6khonʫe|$۝ 5G%E`G;4tĎ NjT*a*snD48TJt-:ǠBT4aZ0ɜ!@W7lO=ĉI?%UV//.ti/N_Z~ I$$V$6d]8a"/8n5r Ҕ?vR'2GfBt0~#EQ֤(1Hj{HȰYSC`t1Ajt+߃T>Q޷y 2ȳ-m?# qAa .c(HfE V-?2諒?Q{EͪNrޖGZz I@ۉ$tֳ2 AMwD:_IR7əDD/\c.yr vov)Rze*I!mP-T)虮 ._Z}nI(e_37 8]GGN (Z~ό9=@#KghUJ$p?d\;&h3'*p5SLX&TU,SY C)d_Q&.ݡpoX ZT^|őS5)IQE)PژcUtHijI?"ߴ4ZgϒçgnHd;0Jr25$ffiV;LUL"bE@kH1I"ߍ"m[\T8Xlhds*+d G$0 A؏rW qrF4_m1a"zױQdž쥵AqÓװV9w%%bN7U)aA䓦z;Kf FV>Sx lu׍Y8͇c^L3va !ܒ+q +6HW [!mʋwYBG:Á@Ʉ5 vS%Qp!r \cn vK!EQsqgU1gbgLy.#ZS a:ނNn}i'M 4܃4Ś0EwBIp 6 l\.GvFHsl~HZ~:/k}X@?i,l/Y$^$Lil_Drw8@ V 4"Gw# _ l3D>n(k,f˳z`w FJ6zp>c bt̅&~xaħB^zBy[\59X_M1! #\8Cż\¡'C@s&$9:u~qi6imj06֋H(?hsioqФ0]=@vk 8W3X\'$V5v"ÍW) /$ȃiVLAeK!bjmB+Rd/V u^͙m"Xh%_өN |!dϽ6w`;VjWN8! *6^.֮cA?ݟ`QZvے`7a ~K3.x VRc#?'; I}-47r9@i$d'% ao U)wD<9lgxtCzuBVʫ0r&Y;c60ņ;b.~Mc󒉛m둚^3zXHz@Bx>̿ eJ~Ø,[A񧾇>nxYs_+ŘًCqt8f%UYDTyZ0G\}ʘ1UFrM妮z Ћlq_Iߓ9߯+^xl7OUF Oe*-.?_#3Ti{=O0pd&-o4%QIJ3H: m*&}W43bp <Áw1`cn1@#b x ɓ2M `ڗ5†;? "_vS5 vi箏t7$\σ.CyN¥nZ`: }-jgE>j~" ;$ cЅg Ӯ_}cMm EϯskD͋Fp J9\& =WyAzJ0E T'PWxi-xZtk m"t~ r@,](z x}yqƦ)Kl $?`pVt}HBFPXg,z#P]cG?wF}Rv9=>r}j^H[ &H2:?'mHSYu)@\YЙ?a굠нK!Х@K;Χ@]mٳBښ&7 *xb"-/7 ?D=p4\rKRb8'Nd,Rl(X.ÇgmFyJʫ$e9yxV Û8pfjvuTKw[ ѸKqoXg? 8|lcSv0ϐ⏧sIWbfiUGMoA`&Μx32Rsg*!avJuގ?}5q˗cYQ8>ǥSVun1tPpF@|xpOAY-?@QJH&08r d| GZ#@eמ߹yx j~O4nMHu֕< A=} @^w;+X}skp/( fڼC4%> EOpLZvj0!7roT ̊}ǨC>U5dOt SHR4Ȳ.y W;~Dhu:XÆWhdN#WIൠYkW3PgF^M:A Azh;R jà&19npU^@IIƁ Yz_*jh_dl8%ZhS WVW 4l ڹwӶOԲt\aBH3[ިwiO]@uQv>B-Z(ˇtIx1(W?yM8O4}Ӎvn_{(5][SB Ko@I;_&d8agd3VSᏟ5T+OV|[^G*Ǖvݕc:а I4=?w֨^Yĺ]eI^/nV&UhItZMh{Wֈ3q[+r6LyykuO3Bdмd,Sw܃L{)q\;7($4PJr3̦vNIPDZ{BN.`{G ćВcRm[Ρ洊m0Rwн`z94/{6f;}u82S5JO"pcSQJjsKR[v^AeH<1Aᱷ3 B}1|_KD+Ԑi jM O,$F *X>Ct><,Y˘S\?Eh6kFJvgmu0Msix_DM6Oq&]LtTPn:ؒR"yoT,S %גULIW,O[bF]̐E@;~Dw[37`^ptcuYyӛv=%WqvΦVQ}:vGIM5B(+}(E"4q|J<"?޴*E qiXP5z 8y@e„Fʇ,s!kŕ0 JLׄ7 V#N'7=SPyrtܪ-0[k7#|f ~"PǸ^׬FPm I3g –£ssCL h3hN g gE B՘m^[a=jaYAQ~`K;(ìeGwt j:۵GjxŰIb@*43tDϛeON" LPG3@`nQ58iѵU} 4Y_*LDY,M'`hg!AR<łhə5\[V_DǗxS}^+HJ!3WgH=|b ͑c"Ў a|P,n FO)DZypr;+K8+g> 4V(w?t4vӸQv}$֑I8*ҋT+K0GӭRJ9 [_p%]) W!B͹bg=T%Q&jxӇM wWWte^!d 3<@Im*.^ijj[]*4o?}/mKWy˹T,uE9l=}`n塅ʁG]YdѯيE= ^ApjWl,@0* sh`rnLCxtšuEB4&d)MS^070>HǙmo£wLҝΩk빢$~iޠ  xU l1OEzԵ-c_k$Z\5 -/eBϺx&O#b}bQg|@\U{g%TV%]UB{΄\@?xT"@ne,go$VuRl0QxwVU\#^R%"%\ cT]8 9}(w)M#vMVXMb&Hl@Nѫ9*L{ųm73 .3S[sӉJA9Oѩ=ێZf" XQ%z.wGҵhЎkd9sH@>}~wLbAQ_ۏh>':G'[5Tst@f rfpVCଘoF&vYY8)t2\_A!2j Lf.4Ǫ\ SJAjQM!1{Wǭ0/a]i+3}#PZDb>DN!ctNA|:{ {i4H=ݣ8_0y(*OԦZ1h=Hu b5/pc领GevD:S P]3n0_3ixQArE>Vy"7ѽ| =>)=ԋ)a靿oe”I ?Yl*^-2UH8ߋ@i7ʗC:gd <^MӰѐaްP[ѣSG 3mȰҐ!8ʳ˙>h“a]ή7S'(]G_! %G}^=3/^z.(`Z7X%nZ#{^46`\|MXk dbBk'mt#s=zE[RK6Rzt㓱\y^9R+JcǕ䄢dи+^\'w}ӢO1R΁34A=@ r yBf8_]\wYVWe=;/ zE|u_rζ#g?bme0M t̶r6̻[՚S!)JWAR7SC,怌XXI'9_pw:1 +Mڔ08c8βbMeOGI5q>61~3A[egxroEMw vN~v/&itԙBuw'Os pQR;jCqRMya/ToX#帎<5ðS!)(J7da@w!,ڽpGo $φ%cP IM{Sd'''MyHߜBSz_mȟ#HCNye(a smW䝵KL'LPX_|,%z1f7=T? kg䩽f:r< 㷬Z 2mfN.esjHY/7g++@‡+Z;:[8"QҠrpe 6KX$7݂9?Wd_3J-)fawc%BI_`#-]f9"@O-fKCs%刟+6afYqKp_'}HkoϯȚ4|/4T` )'rCw͌@XA|]fXy % bUv@ń$vL PBlR:5I^_24P.|,ei~X3ve~[~*AA,_#"R&GM,\KSg5a0 ^1W#k|RK/$žyFM/*`G{B v,tq4IM2E4EľhƌtLV*2stPYۼʳQ T K٪ƶ<ʡ:zPEN$#`???:g [ٰg/Dl%xsoᕅ}?mr-a9K b1|ATDbq{]ng:?E$>"djQv/V̖Xle Wkv &.R:IKe 9(I8m1'թ-4@a4Dk"K3 (WIrћ#T?#Ft,9vIH(DQxzjnV4CB{tO8o^Vŋ"eYEZҁ%\5Q=$=*&E"xȁgX x%K;,#> j/TdJp. Qv,_ Laҧ=f^FM8ObH(kֳTI/ Xh?L7}b^6&_ v N^yڼE^)yz&]?땪+$a:)K\!u-(!FLp-'fW['@at!Ya 5j{͕p#Z¬i >&-.S]deYݪU8OFu-4ek9ДpxYT;S4COtt^~Y7*o>QOdh&QNMik@1zȁԱk FKsOlv\&x5L>;ui\?D}oTD ZjY*6Wp&qև. ^!K|Rq5gC 0Hb$.ӧlߌPvu5+vv":>36&HutUST=RX.?d /Un]vi0^#h<] h~^nrM74\v>Gdchb=d,EIL-YeifŚzqDU8$wV*JMvkE])%+I1G)Z@̡ m*Cʑ }{ZQSޚ#-کq[y6 u%'B??cv6;^́+2NO36` l"2tZq(n4KTH *p[=vs_^2a@#m ɡ2߅q?esR5堗2cHlß 18_Q.ď-紐O9p YA' % R2й|m1|8k\8r,RM| #D)O#V2k;{x*Sx͖["Om顼d{nߕs=Ϛph}*xeU*z E\\4űծBڲlFQy~7M酢@L0-4$+!qdAeAױr/o4nI#l( fSK/{Td E\&K|r\Z0d\FJ˼y]H+RxPB4Kk#|8/ǪsI~H AƙIu`>7!R [19T$y@ !CM+@LߏԸ rnꤝ[Y;@ >kǏ."# @/إE/y 2`W&>w $f?A+Ԕߛ0r[^m>{Pm)._-`lcadRu#I)]|sŷ1Mw4t; Aql#<1#dN?X}A|EV9 Lɍ=ROO,`S#/'3eBѰv ʽmT>.6g>EMP(O:K.X@c nJV 5~HX=TkNj>VE'p]*3鳢;K6 зHG3*gx~-2+l֛ :XՒsB_-9v-}4ጡbgXu34lGGC<{Wuyei17zJK2Ԓ8N&_* `"ySYY~]~diqڗ0 cP)%c={޼SPpfyhMP c4Z0#hd K\t@x'ge*Gae EmVASXi )WZj;ς0g{‚7nFc4B2B>zMd{]L)?"PG q_+Q# %Q,{HnE,d^eb~ܙ_NTE) e0u.ŚJ+B zf&Gc jQ`қ$5Zۃx$-:궣jM]&%%cg >UmR0ѓ,E=,{F/3FW(z/"z`fE?sߋ, |N{j H:_m\rUKHhaJj7Yapo@&H?{-gk\ _')Qj&f>V<5Wn0nVS$ԶLV@~}UA\N'*+[@gtW;;&I~dމb<"s A%Jӽ(\&4!łUHw"~Y d|oLl9 H?Y)¬Yy8RtKǺX>4{$QAC+$aU0}+_s\ ZHNQ\榏H]r}yA  Ww_IYi7_ŢΨ+a5Yn tpnqD(aY x񉾒Z~\T @ER9jq2!Qt2- | c!, T$$`ÀŮfYsu /oLjDH9vvڛ2$8k_rd0ZۈtK^7['v]B8Z?rgemo vH]119ÿq $![pE1C*$#OY-y~FF~P)r~^ً`?;%a^xm߿W`:<%uc <]ޚJ1qAQt(Ϗ '`FBiysanW>/ x.i]\k^h%΂ ltqtvϙ^m ܖ/wODPykݧ:P Z+' SC*aH CpDg k֙^h8ߋ]p@ZDB.MU,Q qiZƜѦ0-$͢Bn@q*"s2׊+GcWFDN/!$ z"y}"fWZ&lOUd](} >-y !PK{ӹsK<򥥡>rš`+iqlb,7#1t4"W(N|IjV,-^+ Ui0w/ Gc#W [v?wEa*wxώDzšAnGx $3._17a9B-FԶK'hZ'i$UDz74uVFSBa5QX(KhHMR#oT@O@L;14@ql*y=|6Wƕlpb Bz-H4,R,b0BBlcͬ' r;|k7 0chl e?ܢ>f^\"/4WP@wLw'mLW,XF6a\}H%Wغu6D ISI`ߡn V[` eӤgU,P@:vgy |@ k=xrPb84VLC Y#|-yUmSrnnOU50HLkMm+sDmhKm%e˳@R5w#GI)SnUaVʦϔL(SdD.W@QLihi_*ub~krZ$cM0f-&2ʝ-/Ȩy'K]xmKu-ɐ+]5t+k!,-H#Cf{d]UO>lyo LEUEHXTtN>PAY!H)!Al̚Do:P˔S/EV N#j>si4~G(kɇ0\e.$baZ-+"0RzW`q`igL;etU:uOu;(5-Ie[\t(mOAe.:#{ x<hz+kFPZ uԾlvܓ%.m ^|~XuQ*{`ŕ/s{sdpYBSܳtV,U_;(uboģ2z0C@#Z|JO?֒ $V¨v ݡhߙ#Z'm32{-\hּx+jn97oin ] L`9Kk1R͡]"]3al c`B y6>rG|z= @}}oah2DU$ؾ?Dȣ-`bEV&*?u}I 40mj&ogoqF;3P:p5簱/Ѷ%11[k<ágl(1S|J90tY#"dIGO +yәSCH’zҡc:?F3sT,h ! xQ7-xAiU\iEgl3`.*^b3pjt;--Q_Z/lGY18$]ȅւsaߡjE D xթIW57ÄRu<pw7F"I+٧`|B3WcN\5+~*!RFO'@-# ό?,lB2aaMrά7؉ [ 0^.5+&\ ISiXš Fަ_)ҵB/؛?ąrĠH7 Ţ&"r<띫D\֌8!|O2X+L$BN<r) >ʹtA!Ψ&.ae_rcQ,ϐUVƺЭ;hn |/o1_+pMoBY\S x" i~)&)iY"ϵ!xvn6evdzO{Gjc6cpbD}:şחj<*/mo,Q4JвuΞ`NغfBZg;l UVlen)aǚڢReI<#R)7shd:Âlщ0Z>=? ("s+,#,QeHY+wj8[`mm9 eGW#kJ1ٱCZ9n󒈽2[h x07<LC@.;"$;Q,zMQz,KH겒6I5,z^K7b'P6=I6󃷙- ©KaF!dSi)[Y8퇣DJ5M Oo!#99y{Ȇ)KWkiخJCӥsmxl_YXfKFQd K#Y{\m:[{z_Lhy>&"Kh$@9N:gu]8-я9d6  @:&mBJ~# ^#t@<1d|Q#o_1,O uyD~D9ⅉdx˩%O)Bh"- 3j1S\]JS2m Q?OLL1&CqBpxX OЃTꮟ™XofXCUSCe0GdB/0{US;-v9"q(:!/ݳxp;5I.fѨ kU vXc9T{w1u[89wg| TO蓷~9uX8DX=Ri@&~]MAŕq e][+Ԑk(ï/?s/r[ fXE8Uh JKZ y+ͩ.̅#Jڋ抛@Y>걹I;g=qZp=GAדxĎ#ifM>pLTд^ mNu *e!-#L؂?c0~Z`A #ݨO P И/G$x;ѥWPKP/5ze'@G 6x\ŭԞE%@h|fQqǏ;h6#='/F[jd~Jp9Uk{ϸIFMlc#7t?GK yC|*[ցe);Rc{q$BSx堆,T?Ǥ_S5VE|۔=jkrot(%OHe{d2H?3ta1Tuukd6!֪ڔLe K [`TtwFD(i钼@bl;YoJ)r$6`șut#)A^2*ەl#ӈ.2 #"\0sAe&/O4Gk!U+1~ |l=w7}wa4"atfL>ьUԧ83 ryjR^V"!ϰA-* _ZXPX4}E>BC|KL宲h+`GQ yeV 'G?'.K,,9?"PYĴAAZZKrӨP?oHf5+)(@iQ*DۮN7fQ W,I Gf<ɛf+^+t/=r_og^(98 }j"f2aJ6;1n :L "*{ y ,.U1ٓ&/&3!8,k*Gs${}NM`F|bQT# n\8[H5x 8W2ѡpEMbb1l' -nPXa; m~#ru'EVoCcܧh/+Z؇H*@[r0S+FcNGNىn;[5`h6T1aޭ&l-T396rYczy[N5$- 7p}}|Їl"BfP&->+}znnUXD[ SǨZu 3*ΩաiDrrm0>YwuJӻԊAGOc? -w_̌'+~N 220sK ~RGg+qPfyYf6g2QzI`L4&Ah2-@ٹ{޳kb= 'ѯו7@Y!.нKȖz Zear-NӱwoQFgJ,-J]_WfguCK}oLYۢ eWx@F/PC5Z0"0'$Ʒ9{w7Üd/+/5FJZxJ)OY+ڑ$>`$Ѫe2Bl[)~x=DmVM}NzTwK B9-#a=k=ἱZT"\)Ls+b)5{ Jf^̃yWpy Ϣdxȕ2L#R@sI7wǯ8XՋҋ4W@w0&Vˮu3^0*Eq܆?'ڊmǟ@P Hhy=1&%$/d*1vT9h3e\v1KR{-tT-}jUA&1v9+(M Aj;%G'm%[`q$*/'stӍ=O]XzOrdN>ٛ,b-kCT`69KI(]" @݋+kA᠍J/r9%"UQWfa?t: q́dV>/-(f6 :gHл2@W]F,%]0]՛.QzAe&y_jP9lU3ˑt :=M s]7z*CDX(>lM7kVkA3$4G$=VCmN)ftb-1y)+m@BPPa<: U#74f: gxKX!iNͣoqq>l[6NWgs@JXfY0xqtp]Wb% MRvm^j[γkEs[}VRGFEQCիFN^`w nNJ[0LZb~K9C%|o(fmlh>IZ҂@*{bؑ_~水&mu֊ `K܏2wFmGxbEL'QM=qHs1y}Ak*]':aё09! >*JĻ捔Qrg|ۈ( Mj(<<:$[ |h҄`ɤ2;D|k/* =:끻,O^GbD[#n&qV]CbUarɺ_KH5  .T{]ШXLetԏ 5)o֑QRLLq +#LWx+]`yB¬Cq99=n>_e}4`?l R9[r,oRzDJ4+5Ns񐡴kR&ӶP]Mw`ۙG[;͑*Y FgkJdH VXVY"bYtP,Ƴ*ڏ?WܯF*}369S P_ d&JЗȃT,jcH{i9UHקY5ŞpZmWKE2 oXb 9VtRyIVl:6}+f#a_6׫lqIi(\};7Cv Wd@ gVr{ F@}-g4 SJ%U˫t>\J8 ֫.F!&`7U'@:ќG͒5A#5)P0"?TQϔلplqL[,)i&\:$V55j U;LTI%{p>Ԫx{4+&Apqc7+y6vЬtaQ!<++,3 gFBfTqK333_:~5s@"hbP쏗yC}3V4BҔ޵pտRCo,b8Y`ݗe}0;dn:X%z_mWeig}-~ގhaP X#ݐ~ !-F%Q2DݵrvBsaaA}#TkϪ?MyU30_s"u:"[ b )XY:N$ _^pEm0XB qG4 DL=لzf 1;ww>b9d qxQ-!>1/ON+hM# q2F$,͟;00TUa@~>ք6bNMN:tE)}[Hӈ@6 ze)2EqNF~cIm m_@K#7&!WNKΛǰa)N;naZsR˞ab `oF7S+)Jk4OU19-i՗fO`X< bho(ɟ*ED.u)`.L5WjNf51 Ar͆sc#P0"WAN?Q!szUU@B8E)6@@& kU@=A'CP!6z ?" IbtK~cڏ% Ŷ;znAke:h7UTAT2pIRxvF'ʣh"W3&丁,PHɼn`Nömv` ZBSSӠI4(' T8@f9ۍH>n*1 ,F+6uaՐ "qÀ"N$]/6[6{XجYE?˥QNIlG%GڨQ sH`[B#P vns(E30 X#UL|=O7(PTgMi}WaPxP&og1_JKlԥ>/*σ.+#~Q9djD:o^0<͟ra+bI(+N荶Ag o=3σD{l@1a]0\d1Al2m՝)9}EGi /u kfe 쪻SISӪp]p5LćP,zkFRl݁x#UtP^L77X!D7OcaF8 ^St[d7G7 >ڴp/q'J`j)B:kU(n/^O흮LwL׭yN`bɠ|{~2VEÝ^t<=2c[*(c0w"<[NZKV= u:T܁bw.թ!a:2|PcÃc5~63)}N+u2ٶ):Puh5W!{Í+0N2 Ne:c Sx{T F0~ 0ě_>@Rk{:*K7 )kKX\ݮPיeIHm=y):/w5vmPU0X#> D9tڍ N$bt}婅 PW;V# wK0A(pj4 L?F(^7WvCST%LwwP_6 8) 2'ɻ&Ɩ"kBH<(Z8oم|2`TW+Deaj;<ƸFZ_Ccgȝ!uLVa_@b@]VomX򁳻, FS#%n+tlQă\.IKj-Q=%*:ŕOŢ D_XIН+iH:Yf6xܒY类ZXSRy(3d&(j9N X}}6%z`RWrq=ux{N*xWj+d BD}\iv./ P^!EVo 8M;RFG<1-+B28;沁xPYoܩxh8!@+a]N|n^]/a:°%zGwI3{c`w 9ҧlPFJz|"8{QVqk9CI1FnˏGMhi6\DDa'fP4Jpv9^n4j͟8d{؈Ucjńڗ{<>M-yAjYj!|KUhx'K>Q)!E_'y@|cQh}k.-jZ|a{çUT| Ehh(4A+%4A(S^s9(jBZ-SWjx3I )|@m\t̫+ E*gԒKi~Y'1.&cyJRbf0nijIjnnWOV2OY O)(bl>LjSOǟHK[>WX].B+i'?2_#Lju@wouw8Z[$ P}P*%|q5h41|) MGZϾ_q@.N\_J:ik& ̨rvgs n?:xmkWIPBx:]&wւq@j괊;sԱo1`sa=oSn3\l0FEw;?K]cA7<]J4pa@.;WRz\N(:]A{)Vq'wVAvOiɻjf7[%GE w"ܭ6;Gr*mօh=]b]m B\‘|K/^{_[U! wowӥ/R/5tI9@ݦՔ6/CZ34qn\[. +[/&Zlj-_ѭH|їR)nF+rIt-ztk X-F;/J^U\5I^q\w['fZ1+)[^X'7uB,2X!SvL\3rW]9:W-CYCQ&(Y_ /1+2a[\k˳%(x~Kosԝu;NݎX)u6׼pR꠴c` ;*4ke'Z4$ӛtyM$Hap)Ļ}SU<ںiV>c\!o[6%Vk~x?Xɟ;$A*:cv:FOՓuEn4z7K6A 0H8sFEzVXhCD.*V f6;GVI,1QDs\< ?q-AɚC&b2B ).#tLR65[ wJ/dWx\BzsTG+Ã9YTܗ"{DFJ_{|W[E;FDv(N03d>g G?A_Ys/%Bj8_idq,ϓc;~IK]04tb)=_}L|C96"O(}=% 3Wb+ZF9 ɿ9f2S6 >i<"!ʫ.t~ӎs!^NveJUqC$lrNG rdš?0'%h?}FPڹ>jbFy Tǜ&ԼG6He͏ֳΡvMV W@n8ՙnKo+ڏm{**fa]U9!\08b$is & Z):fUkn[AFsCv _=|Bl mxA+::K|ycik[g kݬr-΍J`e]!VG ^Vjk׌2a@P&0yAʛK6HO +>ُ)CԌ !E|t=G' H :t"]A_E-kЏ DOzy'nlAO(V# dg(+Rx 3hXdgУ /0{H- b˭G\@G PUp<3eѷEtQhԖ&^3oWcxQjCbT/ϻdq'8ܢQ>?3[Gwi.Jb[;;+p$1;"/PψWe$JFb`v\b{1 U2Y;> бۅQ Ohv }s8VXˉ[S]$q)!)7k)J"D?<=fc=,ʺl,F7i [4|y:~k>Q9d坓GU}޷$c2 kG|-XܴN-nⷧ?h}_̢zk5w?}O& M\Xuto)5~T ?u8m&Pf+ U2i0LLam~=mWM,_!|Ft8L5ŠLIe^C" ʈQ8-a26A^}/!Ww 7ɘz_"jY&Dˁ8ZLw1/lq\ *]NG9X%YqSl=йJ :5c?r7wD۱\RZIV%?"͟֌_c}H0/Ȼ ل 0'xzkݎZfA'pk70Yܦrp/sɥLw" <̀N"0& K.:,-*+{lsp)Mh'5552xtH-ީ)ȅ5uq&kF7Z NeNjU Qq]`ibuFaeqz)ԳD& %13%<^ 6}+^iWـ~kAX$]Ii|u 5 έ='@ Rhw"<+YׁcFgBa9 ߪ_6V0$1`GML)rO."|c`Ds0ƾ(!0-42fX6w|t"`lp[U0]J|iAV0/}gN-1ݬlGD@AAd*GLYJ1i.ӆJd+q32cl1L*VXnkIA9+B$XGz~^rȢDV:=sl(5 8VdLނ 3A=SܺPn+ A  >Y$ix@R"Bh6pCŀpbgU/9WXn%DUVeRpނBj"OHq8rX0kڋ #UbZ'Z)O$':!s-Yh V;BWr0#+Ny(:)5ԝyYo`\kJ++G -j_Mqx /}'H$~WF梃HOӅ4&K&2[&[Me[]L_Tά<5 OcD~#cK BCr5$\ȒrT]Rvޫ=~/u%~ ·}m:&mPk0rOh M֎ٰmDWή nFڑ#pDW4i z$!]$f\&@tZi N(0jj 2R0jsV{]ad׍Mi2 gk 3k]uL+-tRs#_(;lLt}d"XP U725* O]: FiBМ2w 3{Lp'r qlА"Tw 9iTPO8U=t3q)qg&cc_vR};'Ѱ+vsnG6JG"$19ղm-]+,Z: hMw1;SXWSXI9VxA_ɞoq栞[JYٖ !hE|Fw?\>JCү^;ښf@`~=(u NPwֹݶcVjXa>,"Z(7Wo#RGgP8Tmϯ`H-QABЇ4! dvt2jʲI\?_Ock/t&V=, 79XkD9{t o͠wKPV7 ]s-Kg=.CeiWA[Y).Ww>l(~Ak O 6Q?٭hSi}4V;:ju*L<-w,i-xH# :T |RF|G 'Tyc)f`?3^+mUݮ$|Ź:q귵U`C/tMB;Ǚv<*C&<v9oJnEfG}̱9r~Hy 7#8#Rǟ@ȞR,]l)S { &u2nEÛ1q$I~bҲ XmT!h+a-%ҎY}'*qW<}v4JtzqM*arQljH3;eizwR >romNsQL\Źu*I( >׍Q_vAPFˏ'dbrp9&s#/sw + }O(wQdtb ̬ T[,o}ǩ5{RV\֗(I٫k4,Om2܈y*a,tg9eK>i+N-W)_l:OKK2 ȱ4/thm M9Li3 49PWg~4a,|23݃V|u P n9]ώV-HMu2$=Sw9A ,}')U@$B+[bȞH\uw,+/"&C% A, ,)ӣEByA:b2 oj:s>炌w,)tTJ´% MDvф3Z* -$KtOxb{i~O&Eբp'Lr r"EiNqݧ,NKNp]oHN #+fBi17Drh kጕgu3|T=ұ+911 '{g]Bj Slfj{ R@ZΑdjsb Դ);UK--*ޖ?e uuRNjDakx7B_'軌mY*m wn= xX>fz\T83?wR4N|9+ GBPs;jSR#> !9u2Du luJ+f_gc+ 33ݔ2TIm&u%CYΝc%١&Gҕ #J0eCJz|_h+  لolHc3_Έ^4ݯ  I^ڷա,tdrVOo K HܔXP9SX%hl݀9j=NgR]1F"%,7}d{@:/S9:MR ɦ#?s.5:V6T 6:+GLb9Tor> =e(M* 1ّQr=!3Eܰq)^0%|z4ҁYYc!@5cmC(Wț' VA9Χ~wKDn^%a}eb*A¹]`^RaۻCm&ƤxYH'w'gK@@+1K"[uN[e:K&lNl2Q'^*yriGUdL!3ଢ଼J 8T⊌wj4/K|u>Qnl&F:{{`34?i `& cn(m<ȿ%jqCX8Sv q") a&copd \)%IMh-!e^Whapr0,ݟfN"L,ކ^I*R*~uuɳ}*OeG^ ΡMNrŤk;C|%$ߞz89hGGz*G[aeE.VkLrPŕd2LbikY**tGPť?(rx$z`XOK_M׽g_;G0d ^޷DqYS- v[q) z6U$ZMpa%zFni.}аf miH7S2,pj_F|%=@ZC]jCYz IcpDR'Տ'8<:"W7kHVNlsV,/!<Շ3{4ivNtot?,d#fѲޏ ҽY^&lL~8| K7Zk4mH&Q'&pQGT{W|}qyRri[1eQOHknOg/ņ( j(r"r-G6ȼGckKEZ7|eJE ђX_&vT+YS)S~S{SVFʌ uΰv޻ՅBS]G *-Oʤ2| P}w'Uީ^*8/:_wi1&٥$;V څ<:P{&(:(?OT7%~YXck$t s78{̤[y?87;k[^ӳ) pfBhL3x@51A3mO L.5W`yWU* CƲJւgXtntF'o;ytQaq*uDQ' 4پIM=wC>bztGz ͓Sκl1BӜZH$h!! ̍,a@EanD*O# &4ee"(E3wl=266eŤ"a;̈́X4//],}ES 烆f:pG Jj@[h r<}:C3)0_[#Gɓo8 ӷw"+evUqAUcdKR+7T$G z& nQP [˯_5ت h'9$*(H@PzX-\$Kc49̰Gg!vPqC(8)أhtX`_uIÙ[ zl* zf.A#1{\_zջ0 M-7:LA1\]k2B\z0h|e?lTg(V;B*]탙hʱVQszk9T;ZV;^<_bNi n{d)ltOT[L)X4vp_/xv!+W|5gp]t| &DǿZuޓ8NyAQNLw]#XJ"'7-o>O9!&\tP?2zmg3+gY挢~߿H^,qRD{2tc&՜WqHύkf)n)pn#w ]_ɸYtd #CDdq_\y'A6a%qMWW>15nm+?<@y$iqIn 1g`@:Aq"w LT)aIa3`Ī|@k(gi..OSԈeJ0҃E{|GPt } CbhL֤YU @rKEOKOaRk؂[3 ʪC-6ZSIS8o>s={[m\R2ikQ桇hۘHi I|jV]PsTqhSӊ{$?2y;/+A$Q &C:I"2dNowcz1;_#h]$g~uK[wVNPWORɹWu JwiY/\X# 42ɣ#H]VOY&alf(dרXp@&EW;B1;D/VBV6͚%7(We'EGYG}{4Qu\wY0gA;lbf9 ~+7w7ޑhOg.1ܧxQrz`,u~xsd?ߖx}}߇ě ?ڠrPCkg:G{}":1`EV耔_p/b4.^L-GLtƘLBฆ:2ј,!]?lW&ToTXSt8`OB`tbc徑B(xM )Nó)*vT\n^Ѻ{2ew@Il8KF'jVHm 1 FqH >D )X_c!f-5Η'zT7s ps%-e<2pۻIx"2kT|.MB  ry3RBG[U6 fZ{ezOۋoԲUsx0}o0O~Pf1.OI2/@QţcHG% .jH Ʌ"z[ s 9]NkOw\~e]HzYո-K~*ITQ uIL%@+jfV$omSz -]9aګt*to\oj:P9,8qψg/j6mpH;p~N,2m>U׈qnlbhVٕ8v5Š)h^(G$4K>[Hv&B{}q/"I5}kt%ZP=ʌo/ tց~.hzZ> hY>:+{"Kd N4Zۙ+ATtfTɋp{6{ >2z$)[/Qw}Y;2eǦߥFq|0k|W5V>qq8F~N̆@/#5Jflݛ@ж)-u04Û~f߂j_D2"E-00y/Jg"p\6E* )򯒗pAr xEj"?<ưj\DRHN!n>(" \]A4ІP`.Л}HXt,|* =RMU`x,%Vw7${sY1NW(/Wx`afEhʚQ#*da(M=KzV`vk]w\ h#Y΃J#F1kC *y"'^Dp倛 VvLl{_Ty7Yo濔J-z "Iʸ +]̥jO4eހ[*TW(6Z{}{R:De?9>Gj!PvNg+U4n'9 ?r :Sށ4ֽ>wf<) 7pS;tḁGlRvV#wI>)V.L'= d]t6U]|DvB@vt|EZ4<06]( 㸩YFr_\={ *R膼5XD,Z:g~\tv̳Y_ HW:pN_6}J$=c'a%Y|#P@^_p"3,q3Œ=#I<1209p\I]*[Ѐ$O4/`53d7 zD⫕̫+hy)a6-gfjgب˞4sɖ&r7-yY3^σH?q qLCtM;f =Q}GsM Jy"Vukd| skd*띱]2+("F6vPѼ'@h FVg` MUyqfO&bmy{nGLlZS0KnemeۧUBII.tO7wB/LPޤGƧrޜW $);9}?jI77+QZ=ˍG%f jĐףCaŧ56 tS~?n7Ds>J@Oؗe=DR:A_}P*>`0?Vz8*»AB-pk,X/8+`˯?६d5AlJvR%{~(ZSr]`_(~ULTLe@5~iv[gh*a5O94#j2J v{@N@'+=V٧x5m(A3Jx"0>aFv~KFR_sC\THtt(4ʀ klDQ 0UI_=+0 ߀V?XC? MQKCTm-o>1lD bbD%2o4痄{gߧ2%i9פj8 4@Q6 30r:8S kQ7l%.ʃr*7H>^wo?˫Q[Ysby`qJ0@@oʘ/z$ڕqi;N@ +>D>  x\j,^9KI]%DāE;eQ3seN+ᆹ$H*馰P"A$,"TN}^FXj##Lk37`M@R˧:N\{eN?"ӣ7żHT f}Δ@*s5H^|ֈ^LBS[߄ ߼eW(HqTm;x2mG$ʎ"҄ oݔ#' "ω!v%Ż&E~dcF0tíUt3F]I+{*֐ӬFKM( xg!OF-=d\ך'ܗ,ξ=W?Nع.tdGجtou ]66>gh ž;DU#PM#D>k++ش#x@۞+FW2uqK/yۥWr%r#&>HbQ2qsxmؓ3¬tԀ9?HiBWVI@f8+R2Y[З]HqN#RI߿߆ݥӭ1&NmtHu#DR97v3ژ0@鐪@,ѥ:+at'oL9[13ZmBR޸?sX1OCg#o߬i늳#~>Q(,58@2kA^iN$Eݔ_ZOkQ8֝b+W-\-/FGA7oEGH>se3J6ް[ jkE~g"J6E)NϔRip’i~ J~ȓ`:Q6#6>fUSѾ\㓻-IO ipRpOĵ|SXUe_D 7@ƚ`(=3I<3"f\TlQj ˸Q\p[,*r#gft!q0 ̱@^?qni!u}9M>Oy{wwe_3M ꗸ,4L ~8U&/[ώƴ92j,==_w~7qd3$IVP'XK l>ռq/nzl%)'cξ'Ct mQ" P~Tk[.WG; DyC%N*]B;#lL,_βvn5AID 1ĝ r0Ԧx~9 S/7$M(&{šmpڲQG#7f[ui-ñ?:~Q%Gl@X[MO 6j|$/FSnj)ӛ$r#g1n642ڔ.ɺRXt 5Evt[wf8J<3 $UlkVJhi] FLn!y "T-v9%iN8lݿ-?RV1L}1"9G![ե8Az "){ ӦV{#D-;bw:yÕ,՗3}}V'6FLF}0 }p1[;!|K܀2zsHX؇KwCq,o@ ADuʘiI=eJ @Xp3cׅ4%>,ƎYZ&N6EV_㑏c`m'$ nrQ>E_3KSKwVNR6,g* RZ 7Q  kxx\ WE΄e>4UyB u\mH^*r%uJ dA+x~:g}#Q۔਺i=6Q(j|1VD,$8{S]}cmK,oڄE۲䐻l` ~0V+Tu=oh>sop H}9()SxHB̐RD‡_.S3h" g[+-VG]$7G#..JhYD5tbND+͇'i$bsƋ}rk`|$i ȣ e{dg0u3AK:)%Bղau+֙kT|''jbHuoIP @ƺqMmsW+ƖFwaCu[&ƂBkU kqQ01pened.`@a/v;s?Xm[*_6h bS3Z46Mm=!*>3%)A.P02l_ =És ࠭S7' j!V6l $d}g7=qe+eemk(%dy ŎEi+A5"zdq3|C6H-n8im8D83$7q *j1OO#'t :ArabGSEoїYi'q(śܓv!ֳ~m܇X>&i ې~uԔ&ZI4ºЎ{k$WVز֝"v̓URY[obE)a)fT-k^ndyCi s1:hNKF5 pmM }m&Ȫ9$ ڽ|KBrl+E9ӆ:Nk!%u<ã&Gļ éL*JbWywTN0>^-8$‰‰ƏQAO 8z΂ݼ(eVx4jȳ1&ͩeaȉFؗm: ex﬷! `)4yQHyZ7/kffwL8B }SG+M\c?"@jw*tg Uɧ0UlJŇf]R: lP3̩LևUGqq mJ: %@=+_c޲2o.yL Eeyb@;L.ҭ#=FOF|ʹ^vJ!2#]۱d72*6R{# G~KOGhPXed;+pXm{7z~.ٓ9x@gV<cH4 ZC?RQ#RS>Պ^PwhDMiߪ,c^71()F~3{Idy2@Ok6Z$R4fj w e1eh,>'v,Yq1msdJkW9͓́C渁| fͲ7LZLbF;!6&d7/(xfT,B*<;yRm۠Z%;ӄF{:+H=0{>_R)Ƴy4gW~wUFˊt=)~FB`КP05< (E4LGܰ sh K1J-5w5N?x[ DNI#/+B ~ko8" j<<lBpH(Mq$>c~Ԗf\ rtFO$`N֐]W DH<>dccOL@4R?ឬSbA*mgV}T0!H0Vgqp2,r߶6-F Úחm#e֔<"sK6#c0(^og(~Y@t_Ewg^/6"͘ Qj~~rsA.QaG+?)o s EmmtBdGXxn!;"%m_]GvDmos ,LV1p38]+"TwM!:<;aEͮpO30C f*u_5\q; M`>txMz ʻ ﲊ=wUp'TJ/ }nXzy'k&%fJ]e sDq*u680cEDXq(@~Y|Mo$[&ـf@X\k1Ò]BGxqa6KJJi$O**|rs+&O&O&׈ܜqU|'ݰjG;b}VTчc}Q%v]s=t_p?V|aހAq92y_*-}ӖwxODPcQ0ڼL, x^Pq(j"C4DHD4: E<4qÈ.HlE3Hܷ/=bjHD%(Qv1?<\nq/!wo2~7NRnɵryC63E2(hFހT P=<%ax.1Pp=e 3+Sۮ@$"b[N-rW1%L^C~1n:)18գno.Xg4$?%SC8%!7_{D|_I~n?`Г#jSpR@Ioŗ?BۆCCl7FȜ"0DyHC=)s,(HX12NesB9QJmEl' B M).`cJ+ 7h.'{[yѕ 9ij2 SYܫ:eRq&넀Eե7nUSv2E\g nd{sYG k[M0ê N݃ݚM^iDZbE+09Œe`r\ 8|3[uO˞sX”`Mv(xfc_8vQ131^%YF|LtA4GT?t JzÆV7)ܕH0a&9kSPb8!pM q+>Ne<2ixGhVŁJy&糽oɅHgXŖdb|пaZ7Qnrc#2,;x7Djepe' :!%Mޣեh6؛*5c $3ۄ8 0p-%lLEi9 xwtv(y`HK_flONљaG|^)1b#W1.!Rn [bέM"~xȱ5%5JCG@krc~mElR[MаB !c>t!5tXGp#MY0ƌ߁ NhsaA R=/"!9lz.yz֙9#-R5[?,] ,'D^^C]ϒ=GfĄ!ZYk;@x2ST<& ;ɼg/7di |;K , '>(x-盨q@(Lb-|l52j5 ^a+ZW?Rj!e f'};UjE}(tȂ3jӛRNrWѱ09":1@k:Eaݕ&$fLp0h[\ $D?Z` vaܦ?s02ݬ0V廧uPlhb/̧״:]hOx,O@.ÿ?4w!/bUEȠU|@:m orTTv&Gb/G-cSI׼^&V8%18!9C; [X׵GX"Ce"ZWh09>l5#[/[q{oGڊi8 bc'r<%пk{e,"qwLOUQQF8 d܊qPB:)wٖ)+JnqBy (pñg54#,FQpЦ7Gzi@liň |vzD"!o}%J|=]"8E| Nq 6(n6Wɘ0pf c^˴ XT @T/Zs9/~EA6wNxbDJ='3_iēo)? z#ݪ*F0;jr F`&8n)sKh52c!+,Z+&K+LM>! pmqp&}$kIuKT9Q*Io% 困~YK?Q^nE2ށ!bB-9GvF:"vEF@J 93dp;q$% Ǥ gm:X3aa@$L@Xgdً.5,UEhY6LK~,89FE'Wl)!CE㼞\|@txOmeCDDߓ %D-B_q:9S&-Q70]ΚZcPo0Kde5I^VT.ST\ '8V t6y Z}+iB |Cb ؁ۏ/l\6^@o/;"1j]}SFy([ w(c]c-;BCC=uj2-T~(t0i13?k縚Or |8d#D58N>8[V.1꽚DdJ:'rt6!)ʞ{I[jĨKY _X.Bj5w7Ie; %q=+HsΞYmjJiZ)* f dXHzpK(a{݅SǼ$xpcG~Rѯpm501).I!oO;l a /&stk<׫{`qI"%\Cu:)eE Or;§¤VɌƳWWs;n);ˈX'$ yPaCU}#~=p,.@l"uᏨ&WB3x"`еNG|L5 bǃ"v_!C)zʲZ_6Bi .NCT:Y&FXT`cW E/ =9UC*?s1^ps`Ysm䅮|kǁ ]a~ NXI:q"12# b3^~Ɯ*\"H+ϲ>Py8|\* |#D,D2[שI?|IiQ'e}8Z-Ὂ7WWxd<ٱ9$hmsS࠭;Qnox8~E ^q9a_A۞q g#,tk:]/o< hMO&`zz+d{@= 6±|p#4z`y_fJG)c[3CTcBφbv5ʻd=52:Zb?P(1pQz#/㒡\ JTeϦ=a@vgPÅj.0g yq [;ѯXhɁ'yEJNRٖ/qtPyW- rq5LΗ Ejb+X7/sߥD#ۼOjBM$S _#B'u\V g%K`NWWԝ#_cjm͔>u*?8 pXZ6ht8_tS@'y)K.] KJ+\c:ͥED3,[Ef5!C֍[ cU,ΠT|/ܴ4kF@.%$mVA78+LZs$S/aGg Vi%+\o ΅hzA ET2[jƦ6U, t[$Nf6wF!xw`q.Uk@DGO&pZP1H{DsPը@3AA](?d|wF()ȤbL ]xc'Z8pEi@Rm{$q`IvW.j)yۼufϨڸ9`TY`X,* <%%T" QF˅biЅOPo-_>#ɫPa }bK^1HY[LW$;/zݯ/QGVb+/fI$b$<ϊ{ o̺>56XT!sŢ⌣Ϭ18S|$RݟN&gh(:W'bi*O"`iH~ E{X+3mп}.&z@VjP\wj5F[>i Զ `oڧIavi>z7 y '}AuTN1*ӵ||>Ei@$ZOpOY-|Mg2+5;S=$$ !bڍ@3`BɽzF4S7N=Tt@YS&֓ox,e<ŔRxYC{cT ufd.4%B=N.TS{+~#8 owf .?2ZfSz MOq`Bbs--ue'lb xb = lġ"JlK|5C3^bl' nߏq: Qr|J/ Cxщ< G^Ղ\+t'a%=KJ 3t|sU닊RJDQ -< AbI\7$[ǡ絝/GГ'΄ >s! JW6VsFoc1sIT ؋h5 L_ qM9L.{vm](svQ6He8/=pyZV]ؗ֋bgvjț0!eVesܵV⠒( ;\mNۃZ 4!c Ci%3HWF(^A(Q{a>1_.ZOMùqLP(Y=ϛF8J ΜuPjlm6V-;6b:bcv侨 *PyY*\JWF6U6`po!UQjڅ[*L $;yciq w$=|^ӌ!K"|=Y57:oJ%;p_tX?th *t5sVc.nZ5 wCqmz]ЙOz /h T02q5Ԫқ;sQQMgif^=!5t=k0,SEj6-;7 cU5iVz"V/ZT>>Mځ}Xl3pz7QY \Rݑ?P3 @;hԌouw^Ũ';|Ėsަ/Kts¹F'(uUL2|BI:-wrPV蕤 On!kVKJw ,C*{DaHqnq `Q4-Wȏiž8E'U>:!m) bv'yL4>/P(͘LTޮe6[;GڲGc.M(|QQ͐]S7s6%ݱ>0>k>ngLQjg,҄c+)D~u,FቓF`(>wX7*LkgHoV湚vA}ˀ!Ɓْq,XINOqe6dP? PZ+>;& /X*"~>eMk1a^en'8I &SJ!@Ո #5Pϡ^nإ6 %oW/\>?13Gk}y͙.å,cb N hXZ=|7ՏE$XRQ!G&>|Lam#KD1y.s6YK`2.ly`l}'b`A. :||ҩs Kj+o$5 ׯ5<szU^~CFlD6Kt%dX`C"KჺzhܯKK|ɤr>uFzuj37:/)rrr /:W,M-hFO{Q.$jI5ǘ8AaSȢT.Vo(x%Oe䌪.IgR#ɋ!uRNl0J*ojh"1hpp`0[z7>+}sgDdJމhZz)+Ah Z`HMf8tZu=BUc5qOڀ l՜ M\[8hӏUtT#WWyCb=do&/LOTx_%~"`ΆrLAt9X|DoՕux 0Z% PgM!S_PJyG1cݐFb:S-QRaute72 eHնDdqmbD c묍*O4'2I24Ύq8 h4dx#2f9[?ĉ>DVwr\nYʀ<-RL.#J  vCQ#aw> X WÄorsPcF֨!Yn%K*}玠=%ZndwGޘ:Mx _~F = D\r'*cNRSȌUm%gڂo8ׅ"e^Q e>nc\=u[4B.{O'Y}qU7RG?$J/\?jwã\@v]n,/(sX8_P=#rjvEvIJP.6=(K /r-V|y{D@ SrLe%=}4z,-[Jm?}WU9)šǶ p;j 'Wӧ JM!qI n(ѿ*U?gxa]L-KI8՚M?8ΞɓC3dhiKƍG6{efQ+)Yc^G Na[5!9Űi VG'@YQY Y`όY<}V=\Ƈ󧛨;f+\,CxͰPq9{2A!] rDpJ>kcKBbอt4ftie=F >^RUSypu6=ɿ^dQ@3X}|Y:\"-8r2eK͛r${Gr/pke95j~!pY|j8#4ϣ&)o1Q3hQR,Ӧ?zE߻`[(X%iD#Ӱ T;|)hJw4fK`VZz/#HLFUf~^& +F",) b85| V=< >x=M0x./l}ޢ@2vEa܉6PgzP5+Cü Bŭ`CAg_/Q64oq਀Y%뎄RIU,c^.˻{-xH*Ŋ(y~D2*L B dW^_:_Aixt_O&j 2:!ӛK5@u:rX.(WIqe"Vlt 9.!fQEnj?X8fo`2#Bѿ$"U:Zxas_&JբOQTUǑ7 "V%ZB g"- L ={w9h?39t(%DBYmpTh8¾}R: &Ac-'H:Ϙ4鞆9j!h8\EK28lԍsuaYMl6j>|8*5c%b4$1u^xsd?_k ?jYvBGS:8ݘ{ ,#/Ӝhz#[w u/a`;WnKs-s)sVFd^u 7ߝ5GDc*}T2-G5Ôk/(E7b.XZbH)Rxn˟A22皼M+ossP@HOw<@+'2馋rlAteOl|5Q}z`<_})eb)_]u13|y:?TxE}  z7ʇЙ<HZWX|V  W[|VUj,Dy}y R I>f)Zr7O:Hb◘ ⓍXꓪ*ϧֹF)dg>y; \jV$B]ӎ(GA%-r_%]dhZ#ϴtPKUTFwσ?+A⍧zݎ zȦ KF- h5}Xf#\S4g [Zš(at9YPR?ζ5h\˶j' #cAx;KxQoUswJlk B/wDI)C ØHɪF#^Fd?t*r(%eheÌܳPpC 3` o bUgYE/WvaܱU=8 kr+A0-='h+Ö "IWN[0M!YhYfXt۸ty~>xǿ-!1Tv^6 #/Zr.Z2p^ ?Q#)2[8PdE5[^r?{s,OBZÝf;eF-ⱘo\@klY!zS/СՏ(8Pkvy 3z]knϻQ:)Ca8^^ K4ͰMܠ{ʉ?o! r#Y-oʃ*nJQB4䘿/JxG7FezH߈cX ֈ`Xv(%>+/k!|)_\ے-W҅(IxLT :e2^$~(tuf[ԣ O!@f!7}:r "iY4T֫ iF.RWLq fB>N2^hYg;iGf(~iz2ȸBl,z#40 ݂}-q<ˎBbc288Su[ ~7/3r8Cp{sFE}y*S;\z<)'R^즀f L(.t8l6 { 6mmmz\3}K@#B:Z,ߎۋm w_;4hJb=eaqb &(cQr*3ofqꇑ–aj 'Euif@#ˋ 8ݚlj>&%a'(~#J jK6U" \f/I>&&Z=KOxLOׁ?geʶT 0ctÐ1y5. >coJh;+Z*8I4E8,`3X.22dZध k,j X\ y.ӄJlx<5_ Cr75rQhS)&7UDC\ߗۺ?]tfP4Kf[攈!m`p0pʛ4 ̕]Wtqhl|)CNM@$B?.Z }3sK`'9l N펞y Ε,Dz ŁzC#݈yߟd :#!m@׀h.i fZGK+pyۈnMdbMrPE!,ADꝢᛚσ̛ǯ0F"cM<5l eJ3iUkB#L]jeB /O5ƚm x@ȝ tMMw~WѮRfH#g·+!kqk-$ǿquȨh/zҒK?@hGI5=k!҇S6 y\gKpы'H] lw+Lw9eC}LP{!B#6uKt:C,CGNu޶D61L"[QT-`)S*:` $o0n;<=+FLqyuIc-Ը~@g&9Y>fOA/!l52o>'\cQssCkɑ1jqΖuإhTrNFP!qk0u7o%agZ\_FE*RKot}_B7VN1FeOy!gZt]"8];*ߐg>Rt BC4Tf';$~XqᄿH'(*=8IN(sX$:_MW6Nw_n."X !퀡NCcBiH^0?!tQAZYTyǵ88JUAɦP9l9;Lhml`Tťj5ےڳ&WjEV;CCb/i  A/#AUY_ ^PfiFh24tKfS5mVXЀƿX@|G)7Ԁmu7 KƂu T7i2 Ǝ C9C|E^,{e,ޮH@!S>̇FKGu8ψC\ukspk_d12@꣸E~NNAYo' l_c# O9bdk>^QB+-.2|7rP.MͽI%sRĉo! &((VpXwɶtJ<hӂVEPVUDCI' 7TF(s^TAH]Dr?5f) E;$iR1ˤ5*q+ ]v^t׎=rљs`ۮ'+eaE!:Qx0ܦW)+ǚpd)ٻ3s[qa8OLd ;AV?MS3$Iᢵr93%l՛UN 4F'Exk e/8s[}3riXrk:H^՟"3W7 miW_Qhm7"ʺN>l7iPְrOSc؋UC/5X`0v8Р$y`|sJO'h"yOyYX_qfۃMĹ aY߈&;jWe!| xN 2L׈!TVDy}]S'(̺ۅD})̗4?ǎ}SC<}/Mݥ(*"|i E(me@)D3#m8eX# g8\fpKYa_̀pƻyآE~O>KE/)~?DdjOۍ zm8 J8.*/~yԾ% (%침_$)Yn.fTOt *B¾XC̈́VƠyM *Y`nN?:~ɫ1nߔ1#zW=Н|WR~92PK5{M/U>: f85u'N!LlÂWVY_ॠsJfר\䵶 mlVyh~%k/hjc )Fm.Xh<׆.rPo-5v*^P;~pŤdPD8}C {p0f@=*WU#湜jm lvC"k{0H"34C(dvB2 r/BُȢHHKFFU`J%84%+wOigy^OhtaQr~f# hʥ[U.y3PВO?pC7a `o.^cMNB$'/gƃ$}oKOf{J\*7b@"v"-K ~qA9$sˏQ= mㅰ[%uI5>bI :6I(|[Q!H2¹j!Dٚlc"ۄݗ^d"p? .[6gūMEh"8 .h7vcF65sY{VӿžHdgI13 ^S}_lsrR< O;NHHxJڿq!b)eACJVn,,rϳ +\]s?F+ WSGo\t}2RC{qNI}#ٳùJW,xɯbRY7sȭ2ݟ0ήvZtQ=
js #UKþC%mK,t"gL#t>0)ʙS^ړT$6T4qqg1ЙXÍJZc($[wxo@aҕg] =UE-Ò3al9!p;C:o~s|bٷZPx__KDֶkJWmA#qŐ=e_n  ?Mxc-{q~f b}+,аX͒nk~.S.+֛B%˖d]]JE+Yd+䚘Ikl,&:2LE*L\m+3\Rf㯈ik:i-Nhh4t*:{FڭS9j_K>+HGE61ݝ-'gk éF"͞*A)q8f2OuUMzvWmʌJp6M yv%(^G貯_{YfSϝl 51v_}I7f$r&hπFD0#U($|vB.x5SHpM#Ǩ'Hp{=:ǟm>#~ ,l)26WWO :89uƈGpv,TܙgHM蹡uGlͯ929ų8T^ȕQ WWd%3;Up9:CMOh^NKoOkd%2T탗ZHd[aqK?D’Ɋd\(m M(%STQCL7 %SdtRЗ)砲fKXs幬G(9L>lSp/W`Z4e29'˕=6#ۋ)f=::obXg;a -ck=FFu>N) U}f^wOa51<x4֋J<‡APT]4Ϙu#PW\"Еq`l6qHߡT{qpBgq>(xXjrum,dYkvt-6ܣa~8ּIٹzu*?eَYC\d'YIl_%6bI̠E:PSC1X>Aw3`erK2JFnyc#`7q߶6/-y BV/!}.G#|<4Еqe jэG%0a81fUa0 'M/^\L!h;f!D3E yՎ08Q1C[CvOXk' LIhM ԠcA^pMOGxt:37vWG un OM'v '˧ ܊삀C|̨,x wwBq.!/y[ ƈVж+sNRWjCs]03~t2֖ ]OE[ ZO}{oSRkY< ubUaos7څ>ᔜj^Fx-a.{jjx:$glxIl/#FR@tMf EZy$1M cTVf=[fn\/a'*-2e-S&{JuU kk[^E~tY*`Pl#C :|pv os ?)H<- 윝X7/V^hRoB@~f&;s>2?>2F! Ұzbiv%{/rUZ\zd&dwy״ sdբstB@08RȱzΈ)yGD>h jT2.HW20'֤҆W+Kxq,NU^8A2WM`$@!}b3n"[:~ UggE*z簚ntpPcF+Vu"qJx @oz l7ZT~0q;jN7R.6id39PF,~+Lv`B["C/0ߕ!.8ڧ/}skPˡ Y5HaYhwtx 5Űl kOsxg1^u=~WeTDw8-3}TRL|Ӏ-$?E䃿Lqlo ͢j1f-ҡ(Nba0 sG[FJF/fx"@3 "if.hNO2:2Bjkڊ" [eJȵlN8bG"vrK };]UC>7](}OI(34(w<H~Bl G՟Z~Jbhۚx.0rkItr)kIPˢcQ gE^=/^v7ugj+ȕLXdp+JJFO=3$ yÃ*Z%6[[}&"2*WhzqeO-? ܓUoP;Y읿=DfVRO,q =T7@_:xXV"٤cuHSj+5fc!09E[ƍF̊39gKn# +^+]P-7HDptvP⣠򐗑)> wbgaޚhm-Ke \(C f& BO9P<%}TR%43Ɛ?3QeX)ǟ]OHOHNyf,8w{k`S Ml5U3/Fucd!_72]ӾtrBC2|[JFZ +;)uk -@f먽uF>7؈[[Rok\"# w2Ok g7dޯ)i K07]dfu#JK1jh,VT'=~IS+ef$E ;t1zлf1r~ =0 \e&N+f çlCK-uˁ{SS) 4ֺ^Y/;thD3nф3[ɘq'<@L&"W Jb[WO+) flOs~O%gˎُ\ 8i\SxusiSzӐq:M8\UԀ%h܁UCg,Wg ~Ԙ%ا*" #<b+CCOx ! /FRzXkUCFM+7ĥ]`I%n~Ǐւ z$iPQjRB<x] wyl]};5[ڵ V%@1(9ZMг`.X(f"%ͅ\VZc= 4K@E8;Wʂ 1@sJn`ƎMS3.d'CQhy2=T W=,'y%8{F4˟oP26 /Wkw`.46GKكFVY!BX:lliQ>aj`s9{ 3jS%㛜a fYNsv<~&XcsfL(6M( n),6P_el̙߫ϸ_~k>C8sH-!च 0}ܐkyqP?6c~JJXi,vK)W8&:fne~d75TT%)e55 4o`o$Mz Z*9% qbLa"*Axͪz [ǿ4;;L:wڑiލA^ldcmUWρl`q_Q$x^!bNܲ_ NOv]o۰d]LjOnU]JXLH)ѴPՀSm &z}c  E0-Āp3VJR6 }d2bmBF5}'bn8E%\Z[NKK\0v|T2D <|LPi)je7B/#B ~ˋF~>QbߙN JƼܴx )Z)[kD?]zQ-Wh$q)XGzp`, jvt\TcGt6(0ڬBRLWd kL^&4i̎(yRb?\Pg܃DCr *#$&G!znq{ȣybֱ) Q]^y7rl6XjM-mkj.f"`’Ž`hC?-di0ʒdaR6&&q'- uZ^01S2\ԩ׀^G аyʏ6Sb͖D9.O ͜*3*H=N/`-Ya}4YV4HIj\[8Ƽ^4I~tƌ:h|i~T :}%hqntb W@k9_~qŲZ1 нn-?``{3u?'nu?Vo9NyV1}2'"sa~ k|^]#TXgO劕#2&j؉04syl1j.b\qr8ޙBX!D3`H{U9)}tle!ʙ]ԍ}Wܺ" Pj28*YR~oLS7]H \kOCԱuNDCL\Mk<~x8 :`#t!,.swD"NZM6)!Bc ưh\LGF`݁FE|qaWH ->$@sb*F4փp$|j Y[MyˊTrNDtmBs!#DQ̱G+qvQZ \wu ",+Ӑk%Ѧ;)p Z_ÔVFD޻A͛L~s6oc?:3۫V0CC VΟye[5)U}S hNt2w(/Q u@)7Oza&D= TL͉oj %ZҘaT؇v@ ]Lj0%CmV C5*,-TD raT{Í,p@sGT,ńa)Bp=x43Xgp׺# 5=[77]uѳUZؼLܼXuvOɞ} By3Wܙ͍fg8'#lqaWas@9G7AaZMzybS-LC˘6h8BV ы)hYI.8ԗz $z0HZ[(CiOlSWשk[<BSeU^X_[8*G,<EyLq(SF!hqgD:yWޝג -a$׍2=Vr-KW*z$Ig[{,輪ڟBF Ep,H/cg݋ gZ;aYeZY(}.somUR.MU[IsEI RMo)(U/B<5UTcxZQx:SQm6w~' vk1DbPy6": li<̞TO?vՅTuƵ F='5#:=GѶ9zx;])F^oH+[*ƅ+FPGR=@'fμ\`e)D,13k>4ZQ:)-6 ?_v$ c/ Sxp^2yc"\fbƺ-{1q=Ȩ(f4> 򱙡8Mٍ4[hx+Ր+ηtU%_CE_\h7OdQq9pM0y _Ƴ>NDۍx6(X9Rq~H #gH)Ԭ:#NpKN*/HpH(/I=icZ X`1h Xoۃl6ʞN Avid+:M}%21v1ld"_cNPmF>mt,vS.OJO#k~QH[5 0) bjnC}@X> Y6pRfh:[897ydZ{7gߟƸ:1 sf `Z^>:Rd=2z Ѯ0W{yiUѿ;FCLop-'\{!S= :RcGIK\X݄4ܲx:A4Uouu#S^霽e=8Y(V.V֖Y;\m'┍iD͇*∲z\}=}^Ps@B)ƪHc6QkEᡙ -S0IB~O\!z龸ai1Tr- ,MkفL s J1o[K b# z/,Q-}m5R$`_DQJXL YSd4%@%Q~?˨٪s29mSyXAȾYt <0/ 1OxFT؃-Gx/S '7pݼ9Kg3KWd([^jaEX+kr1 '9oa_vJx .7E1V\|qѩPTѮ*w6efL|@O)M{a=NӠL1Yw?#ڄl#%@W5c0UMM9X(F}r&&r[WIH+%c *t2cPK4{WuSI14V39kDy5^z)n--v.3qG~ϔr3  _ENijND vxG=ڷ}>\<ņ1QJQSW9oR%+vT1B=Y(L) 'W=PV@K.qnkWn0C  )BX!0E4Tǵ7řU4Qo$Dվv]z MmsEU| ΢M+쿳J׀r `vqu,YetP|PElF=%] ĐFkȳ|_ANp-=e\=*33do]'j@ ~!{uE?j>Jx}.]Cn)[z3aqPUL>j ھLuP"=ˍAgU hL6$$\y;jCGhψsc9r{R2~dLvkK({XQ6-ԬqL#b`h2NALȁw\tHQNƒ>]Y(`rZ{|p h[s #M>ynmKSfCޗ)`wSHp㝩!1ҫ:a6E2:DQ=$51ђ=u @n%XstWXxJTyN;JP` w;,;|_QT"%3e?@׿xE4.6 o^6l\F PV*ap-E~sgey|x(2]hvWgNv'ʹ75SGfDd1S8mPM~ib0~|$ )%]a֍dJ4uN9>?b_dH2dM]5Mk{iE׽=ʈ!V^w)0Pp3SŢt#)Zd ;sL1EdWwX*s4-ZtjN1<;ِ~„Lmi-\]'1)-l;[N>HíHf)d܆^}ւX>0}lL3ӴI*x 8y*ۊg|!*C]!9Z>G=Tz͏kdӘ[Bd< @B 8;*ǝ:F~NvkD/ \ȕ;4Zfl| ]#t4B5uDMqM%+RGjYm,N5f7lъMf-.j@RsJkDi+2OW 08ьLLw""ZˇK܃?N$t?6c7i؊S]$_kq,w'%;iU1.C__+l^*sm#^]K|[xNγL&5d7B]Y |"ކHB!4ƪ >O>^Vu:JEVtƻ6i_ rƘ2f$ /lg9j5c,USlE)jn0qIilݟ9PfTBA*-j6u%g̘͂+}74 N> f+,8գLTG䤂?N̈G.k5&7$q5쭌\!ݳډ]To_4һS[65=2>7H-ooQ[[~HuI 8ֱvu!m#`f0D֥3ƣ~fN)7- 3ڝ4Otk'j8ݮY_\.kơ1 /1l,-9)7/~ʴ|U9d8݃<~UP[_uEm'i>\̚e.÷zc1h Me<ŽK 78Jmu5opwP |~W,h~T-D퇮v0,15Kiݥl~kdn0aYm=]Cp+!n,Y'%O6{> [닏zڣ4HY_7LRLG+>p2|Y-*@9M8ńz̉V#[@0Q^n6ٗ2U_'~}ULon>߁X)Q@IT3ñwp 44 .| ayɊIʸ>Y,@ ~ϳN.nsL.R+kV[=\~lG,.]Wt\_l+gRaE!sƢ|asNаW^c}c]0ۙ^@wDJ3  ll|T#pG^rCЁ,)k9wc;3,iX{2㻛<VڏqTsw,!ŏfx{'-M?MR)ދvhN߀,(F%/Yva=WD;X $H?/IatLD\2K>ds8NsRZeƸa.AS0qw*Wڗ4*>uWr܄ #K?uԾ/{{P!H`@Aؽ#GP+`;PTSEڻagyj*`tL7!Zq~YSZ70mP {cpƏb4 lV'0 )VČ0ЍfP6BE"~82`pְqFaiܕ[߼`!HB4 {VЧwosLfPݻF3Ix,hNpy%+{^6NSB7 )"vVS?PI{`BLH Urzj]-33^v<2'@nk@J*nW&U4ą^G=W3;e屹6`w$0VCJG3:~ !:;9fS}!(u3xx UXѮ+Z\;,ti]{٠Z-4(,(T(ak9o )(Bqww]lwJ_"lf5 JF\~>wYxd?Hz)kp;+h6wI,H涋"u;J-ڵ~R//sCwAE)$1O*\ j`W?"Q y(ysy >HD-PŤdlv '7!ਮqV඀fsE.щf i7LK?$9IY8 t P*'ߛ;)EbJWkD5+a]aN;6U5˽7)Gŋkxt-B.[1d ]?_0暺HM\W3ӺŰ Focڕh>U9ͩM}!|ayPC4~dit8\L7Z475$l|4CRvAy!뇵x'%]U։Qɪp!4(%MGҪ[b9bC0b9g_a_8,2N&n:p@[h۵ {nfY˚ΓYq^v7tl0NWkɷٌCkf-0+嶻Yxv63UFY)?;eO}r:Bgn7RTx `C<9/2F>?su)neasf'pC{?_mϺ4/hEd,Uzn 4ȯ67Q 3+kU\*nDi?[hfE꩜9)|)sxmn/R'INc$399 }1b ]DI5$qp* (wT`~S9X|}(9)TuiXaԜ:6lv%M)"^@n8̘`|u İGNȌYg_9t="e-y9;W󮦗b~&l#Uz~gxsm,£p_.n' }G݊iz̜L1X2a'Kjy%sz?7>sڡa T☵Jhk|zu)kx'Az[OЇK;gTW(<wN ɞU]59/Z/ը{4KB.6zjS.oq`{IxX JX6T,A gWo?1ˀ !2,=b~k#_?U3ײOka3i@QTE-4…"aHw7K* :DQ0Δv?$V^*M/&f5`)€p'/jPan<HiTD(o d JY[eXuY# _$׹hwr&(50b[gEk(3Wgx$%o2l3DrFOؐ!yh4y 6@3ֆi:2 Zc&vYHۀX,vЉQ^אz]DStaV"r;?.Hy?AS`F+R̃\lIzYփe}Y%:3otDe!og6(i.최65lyi 1|A͡r[, Z^gWh:6RiچBS Qa(AtF@]AQr`cr- ڂ*`4쩫xK%qY[*z5zN}Tά6~ڝ=.H`hS0Ss"`I0kHɓBw Rp|vuŀぷɟ?cCӻ5-α[+CZ wv2wރ0HAEr|Ni WWrjchKLx R\%!6{[*w,zT7a'!f>ֺ,-ϴlۭTo}ՆMV *OKaګ ㅌ(GdS#^z&^[S8xsţ'xͭMlIը2YfU0<jJ?@F~'j9,4iQYuos1xJW濑y;+׉q/F;I> YzknAdTi/%ȵ"85y%S <@q%]X~HHϛ<8P͂Wطqks0,8Bip8( BIЫ%ĢuRZ 'Et@dsu:uMG"Fɮc/5iD 멽l_e؍CLϾO/ken,pG/5^lByP(hP$\P^Otol{MCpQѪ׌h/+vع5gO# NkcF5x=Я2Gq4kt1Ϩ$AC3>{'nuNBwr-Z%+yit2fhܵ`.x ;As}H;/V==X$O*4Kŏjt|C { & P~Es&R2{D.۫&#lRvQm 0G5HOI=*:е,Cj.|daf1/ґ!Ua>S9;GyV#UM~c} PY` )|reN_8$(üHãLJNK6H?R6Jf @8kaF奙tl!V;'$By@%b5MXg J=+;afVg^3|6<[vw ި Th]M\'x(",aNi@Oڂ sw[#XIƬd=yH9q+)]!A#57[^Ob㍫ƴ& 쁲9, W \oCZ  w s.oیyEcYkṳ x+i&{Y,*窣D)唌ZgcPSTT p UJN^{b:dSD2_' mco>$rFZ|4=q)VY25G_Eg ̼XKLuFɢ2™Et=hG֤V0[eC99B#bI,ʛLY) ZFx,x/iîadz:\25vD"~%LC3ըW+y"T/=laD|@IzMt!UIė՟ud4z w8!$W^5QrNWY~e l/ Q.98s_ WD沨W,5>Q2V$o<-2/.<&e"U\h⬳;)ARU1zՓG"`ezrK3%9$ Hy0~t9g5^| z'(g=,(Wb)ӚfZ$qZ#34?7oLK4`xv}"i,_urEOt&xa%5y]hŊ" 4q'Gj<$YչwooHe8hH2BM%py_!EO<$@Ӏ3ĸ(3H:=xGD6ʼnMjm:mt46*hte?w9R )^:>rT9qZzcy\?XW%.%S?ᡘۅ/ZgY҈8qξ$BSmn}ٟdID[yo1/r" f>Y3qI%Y[Jg_fWxvy//ֆ:|ȔM5yc!:x:NT<%1]i ߴęG{dr; #VxAGJɣIÂC p$||?|o;îJDu'+>R\c1-圲 T.-\(|]#t LV ;6qU7r{h)$t眀[7#K[ mI#we"W=A|cggD1e1D+%GzjY2,ۺ%&@Nԅ E@NKȮx~5I2=tQ;)0Rt@& `KjK֐IUJ1dv\jީ`]zhav}%y5긡Uv&BPt$$cubnqʕ3)sգ5WƄsaO0]nX{XGJ+e}sl+9@s !~L!i{ [kke6Zɛk!f;`sH"@j1řܥ%f+mo٧tQհLR۪Q :Uu"?sQЮ8d`*qn[2?EIfRZL"W#s{5Fݠ^nӱ5)L.`ҺA6YR@ʂ)4p4qZ_|,k(,m9ޤb7e-]0|U&GQ#31x;kk!ۺ:B#NTBs 4d^NOy DWODꡣY`+zCG؄M(᩹kȜ̭PA ^1D$:LlR˵>)oFg OU\"4:3_evd0UUXbS)6ԦI$amÄƨ A{Qw>F'*T!H4t\z'/;FdʂŔoDCY\^Okw>6/sU)ݞЖ, 3cD4z}"*Hergiˌ$}2[ /RAG‰KԿ^,_p}cy"`ǚKL)߰g/]+|(W{L}p raM}$`Z)xDenlhϵWOYj9Mdk,2.vIL.cr()BT#AT AϲkY ó1gc ٖVr 915=y c>7bs>f??9|XBncTPpM\ڿ$ej5aQ2eL̅_GEf1>?t"=kflfio)&e+Ot0nhx8D9g-&)VyQ0sf^8(ns2~{$: &8HDnEQ)cUQ\<]8;MdU`.ka/hEPa\/FB5Ȧޓ-e=6s\k$umtaФ XXT"E|oŃ{eSB0&ܟ =>~L)R-'3nD.ˈGQLh06ǜ 'uCIbĵt}$>XG}۞`]Uߛ|1 /10J4M#:c ܉򱱒lc{xllxb[bVBK+潴]U~h$u 5c wVNˈԩKLZcKխ}\KZ˚{[0`y S(en3 SL>E9w/Ժ) _Ш4'$s7p7:؁-gԦqdKNgm^8k Aq/} ]IXsOvo%Pnwm]#IYd!s%OQݔQvRq-DAXn޻%c"7B(éÁ,7Jks9b+bAng>yrOuո zUI 0W֗/&o߄ Z(!ȿ 6pF1gҵ4l]$ް yPNvƼMBq^?̵& ;YVӍ-+"Qd[,ߗΣ(2AC,pTmІET*l&-i&1)$욵`$oHP8DRuew__יezhDR2Ae2l)ЛPn3<"kH[pO"tr~ wĶ'5*Dʕ!_l|o,>H\!pT_kQ}._BlJWg>zn^ĕIUu@ls;2ZnG.UkrhWw;޸ fl SAم@NcL͊vțs$9 aft%j#ha4NJR00v9ZW_ WMlVaE(' 65ATr j9FĢ1;T̢FP芟>?SA__1[O&%7>#4{,n-L-\wGd4jrol` 'De PN2f˻-ػ?$~KXRs+SanUśGj ^s`ުJ˝!iwr2w4y ŚNið|`J8t?O/+Af}_'1R8$dN[d eJtqW24:1RJC0jD#V&:1?SDr+- %#Fsy"pE18rEʕߎHAݙ| UN)9Z1DvЫRiC/Pc8^8b'C'im[:g"xA,l\ˌb]@\(_ӳ$ٶoNXHi;&02)6v&AVxcd-i[w[-K >ɻ*SqV{Mt?2Hc#;ɟ Re|x&h l1" !O]֍JWYSĴTT8Ti6*8Z=*ċ+Wj'`iYOQ`~_]MR,<"0\,Js)rpKm["!>;e@8#4>M mPY@cV}3.RhksyMVbƄN,h鼞"XbZXwo坵R QAYM{fNHA" CaכY T&v:%2POS~Ow M&)c'6\K䠠bWA N-R]t{2Q1-GfJ#W,G/Me=+}xWF|D 9E JqMبqƘJIV.U:٤7*\ 5({`I@<0QmXFG?`+}Q.%avst1Sf>X>V 6MɲC|c(j=řt㺰>K|kPnW ܽ91)ZxN-oPo=2ܞ?͆U;rQ>0M;KW!s8Qܖpd)Wja05/rʹ z7\;ĸ 7=ofs0q9+"Ac;ҏG`B~vH#Kw X+#dWK:`<\4䓱5l\:g5̤OAۇKԪYմ5(A`'W(fM VNˑ2 \O_Ja[xɠ&Fq=o@b ąZ@v/~ %G~*Z`l 2p3tN~/vnS.C.CXyՄKqOĒst) wzPu(_ͣ3cNt]AȦc)M}ቱį"])fPb~7q87'!ц:88l* yD/p\֕?KW 8^i=Lyo r 6݅}zJFgw/~Z6¢m> רX $d<{ٮ|3<ج]C2k#ƀz$v'# ӈߠ.$UUo7x鏁# cYAkXu"C>W~JɘV0M~v b)78m&X/HگTGSl |c>EˠՃUО@Y4sʍ :u<8@:S3T8 C\UӴSG PaWDW+ ?2$\B'1Jt_r[gԹ}'(#o>e(h|j}ńM[3|q*Ƈ''.*Na$vs$}[rxFkl6|V[wjz ԓ + }U:s~›;?=/hG3W\ bd[1sG,.CRBgmwMݳ L iGهTZ>DPż8on kF,+2HQ:,$7:XZ,Ψ1 险0w")-p\!! lOMc|"Ȉ k)He a`7+o ; <|0TiJG;&>t6@]i}m DgV$zliw6bQ1ĔK c ~g"@d7$ŭ8_N-Mx |-mOh t/"w 1M<N4bVyK1߇1[fA六+<is-nmen72+4J rhO;cX'8 i/%_*'VZmo1kʗT`(헄f: _ c*sg8V&o>vE ' xrD5NϩϬ#B/d0K8 R _19In]͒o.V$o?ؙW U NV~h׃靯\A= >W$W*V?g›8EcP7;X76CgF (1C&mHڞYu1g3aR}eу o3-=ym}K.U[=jf=զc 8䌗8㤱_L\-(: [,pxvv]K"Z*޷Q!Sdyҝ_2BSy<#_cLn>>,SH7YGٕm,X!$3$ƈ01YOTJ|חVK)-w'A*r#/5B>*-&kܛ"/4|3~Vj==H'NO })Qko_F[4-/j._ @5r?Bb15G=LvBC4a@GiA*\Zɹ,;ɻp=Y8/ҒpMӪ_>IFDrX:ƖZ鯋e4w4p(|p>➍-;~6sZM {/oN* 51^=*s0Ȇj` j)%;вROiLSJb#|I| (+lwNR$%]=#|K}=WRG_Vzno3B~"kRxy{F[(A[R.dw.W&4޹*mǎ~Wfƚ`2e$s%:vyecr+Q=ݨubrf){Ƀ 3N,grI+>»Ū(jRw+۰(u_ UbhQw<.C҂͈?;2cN旇Q}WPژi_AXAR?z^XIRd?Ȓ2Vߏ9A<Z)fa(i=]"ںjלkg2٠QGK}/ -BeuX]>WD`])ނBϮ)AZ~>ϗK3+M v( Y{c0ng0♘E/ tMlHMl0O9# V)$=ҭ{&I]X&+;k-|' @ŶP%-DzSӰdҫQSUJXcLygs4"m?'Y5[4SU^$KG6Z|KRw +1 -8Ȁhr^?1\OA x۲A[A1sRk5gY6A y"QZ˟(>_u@g ҫu,YпǢhp+R=>|cO5r*(;ƔWR-|#S3B\(޸?Jؔ4&wAd¥ү9~@ց }Qka wu-fDFSq۟2\{VW $y6:Sp{q;jbZ"*Ԋ:)Gg[՞ѱ0 (Z{(m[CGBtsXq#/'*;4גubMUP $6![oJ}Q gl?:[CAgg Hr2ؠab]Lb|bWO@߱gթN 4T2(^q ~ IЕQ+V[P[W]'D<+ ޶ؕޮ0M^}ژc֕W~֞_&5H`P)ey& e$B5ɦ2~]:2ڋ9: |n_/e,I\> @=h2j >Ap"i|Hj;<7;s{\d; '18N vaQgKF qi5 |l2*cQ]t+!Ph᧋7T@ctpP)Jk=KzXI<>k "DhƢ׆ʥ87;Y4Q`&+]U>b-JhDxA!K'MAmr㠺]ugnO۟)u; 'dh{B!]")kzL썠s^s"L @fZeG-+V^&`Xd&$#V… 6Wtopȑ̀)~cB'dAS]ĴH1?&,$*6)*GYI{ɦ% /)Q?Jy},/'f4 uYEǙYKbT^heG[w\2uiirϐWs*@Cz;L}B%Y(\Y M3SZ Ku6`+#r*7۾i:w?M-R۔S8$M^5bo^W|sj AbdيZCC 6CKjԐ9ȑV=}Ы{A>ܭ3\4Է/hᇢAJK:z ;gUJf3{b\XDFD1E4' 몥~Hy:CvчSFD>jgulM_sx׸Ngp'f ?-D+=1S_+oWıjAwE-Ñ8h41axw%w|^zZ\tK\*28xr5\Z2伂voS@j"?i=cj[@7M8UGP!rMiýyYZA -gI+f /&U}{u V^JS 2+TG.> 9ܿ%:}m~F{*V>5Y[/fIEu*iА!Y]=MQibU!^ aZ~4ڨޢPeRŧmʋڂtvEa9 Qxɧ{R Sݕc ڄg5tyJ`[@3n/*,82=L i5@աȟKDsL>, vԯprrަ;x4(Ӗ(tPR^t>FqVvշBp0û&!;Rח*̦hsNGF Z3VW)ɓXړ\z1 }L>x&zO"%JætGGKq&='YΌKּ#_ޘ46M'ycI&DY̻;*3b^wD11C[eԦV01rVbay?Œ 2FxFz|};F{]1rzkI4 t { KϒSwUh. ou.{> Dp2ejb؋K SQ_agCzc1;cU ;TOoJ5"gd-!GTwӭd\* i'1|  5& a]vϬ+_qh9)jT&@<^4?gq%P σ\zZ @u^ dTZϐARR:Tf[H`hl?a[WnB&yx:$uNXS!ׯ>h? ohxzt% 2+ؼ3N|]M1&A2mQ90vgנnYhVЛypbI@,IGj \{!ۜF^HI\% -갲}7"*,Uo^Wyk-lw=)W,xQǜY 6UWw7hs.OFjᒠzWb'R^O@?YPGk:Hv7ࢎC h|5rs2ioeÐ_/"w~ ~c.n@ T2:-fjs;w&x]jP'_}>zg*wmN4ܷ]*G6Ak+*6kLEHƥh18 6!=fO#wVS2oV߬ D@1.MԱlcW>mܬ yܭJD›7 }w3ژ\cD#K:nn'qrP*̮Pd3>k: 9o 9mL/i#Ď)&Aгo϶5}V>~qz9ڜ<ِ,σb@MfLw,rgxq Is $OtL.u8mƎvɪ!o!x2%V'6nB\A Fw.WK\OIM/M?9pԗq6xPNJF)gUf>k8tȈG]6 %ߍ 7B֞ZвM`Ÿ"#_ LCΓ]H_Z~C,H'`О'EGt럪\`&.Ÿ,Q `#+5탊ޅ<8;pܰ!<$ 7Q_|Z@A1 01pOOyH"zAm~tx+OBէ(sTו;Sk\H,WIzk:<_t_M XX 6 J]XDPy)#BH̑$5>'*&N܊H.^{ΆHt5-7r۶5?gDجW?<:i4.F.uV/KxdGJCCR27XIJUVE_F.y/ 5# M [ʈN˔7ONkN V~UzNcl# 9;n/J\5j|d<*cjF?WiR.?T!Y\**K-_ xmo:X;[4+)ʏ'5CVF`B,͹Sq>^YRtIR}>&@rmA|\^1D)F={DE-Cݪ6.I֍ژ,zajr'y;A7@Tl2XCH6dC9ȡ nngTv Çct-ucv>uHMV@fSxy d@ cܞ Bʿ oGBr?Ws̵2Ʋ:؈¼ q_{^o~\.àWݜFw=o[CoI?>yLrVV1Vңb J}E4&0j`EV z m)-/pF Mhs_fEbmZcl v"uYQ5é)]2 o* ?q!q`u<߀\*`!FTx Y={;[ݭ˺_աeuD 4QJ9R$• ̹sYYjgI31K;+Ne: N%{xIDkl0U\jg9mm=իwǚ|7vK{c7;pZH(ڭ{O|#敵闹E!֎C>YjΰqE䁑'**gɯ+%dB/!~=*ᘢi"Zp;V3<$.ĊdJHG cO bv^z$Zk|K~zS<=tuR m#Nz,x 7GQ)+Ao6E*iקxB }ުHCfীe01HkO gni=VV i'AZVdOo_BoMZHDdB]Yէý1A=L1F --Z;htx|$E2OVariYG[yq/8PFo8@;M2Ez@Y{cG,JqؤJuTR#3K/(~UYx-;Do]6w& >I[ ) 3Vҋg %s[l/-cݰp dLk~Vr~ 9p A6N?߁ė A^r˖ aXh"Y>>(:; #̢HVZާB>C풳4)E A|03:*A!Hcm|"cHAEDFCKpcҐKdZjJJ[ -+J'R7>I;8xbŨ[ᛕ44Q4԰BnsȿbUw,dQF|3_\Ạ0p& iдۜ5Yngň)ߠ$Q͜.;XQHӺyUDNľbn) hTۥ9>rQzȹ6 ŝkAv9 =(N[+!EGIJ"vYSGչ(@ғ1Pi{3rǕwp7^,AKEW,bW`؋xvRs+kɕ4>)][D-w"CMqWR[&ׇTRoNߣ&5qULDKF,aʆPX;MJeth\/$Lw2[ck ܑNRѻQN?v"v׶+XE>`\E<j7e{J^70縖6yn~X]sJ/_L ɪo8oSXf w;mֹ/ I2ߨ60UM$ \tC1׏~FfIa``]t'CHJYq3[-o$b=UGgEhzSי`_XЭ]FB|萢EZXgb^VztqKu>Uwʻ`J+ r:'?`My&<9UY8X3ņ~%Yh!1ャe% |{Hr)<{f-߿ d/z8Y)BiIЏX4޻xb"s޶?zR5DUG4ZlqGMc+ [R8Y-?~^$iDGX J2] $xi3;IJ{:-Tbfj(8}c Vq$I2hl@Qۄ"Y\N TI0 }\ψaqFݙzohV Fb;XZclYt\7IuX2K8x esbHΈNە|ZN誔|*dxyHXJIr8]X^2#LH!HtAp5i{)IZDݏdf، t!o-OJxfQ8;o%ur(Ď%W]}^Jseկ¬oG%[DTo+9tX| x] &;4_X l3&,ܶQP _VwO=bK.5p3 4ʤO}"n3岽dc¥vNY,xY!JjطTt-QnE"l)T`hdfoneũ`BL[WR] .x&py.Eԝ\|I܀d0XL70m4B\%#AE]OV\WnhC .(9F )spj9&CL;2+yۍpJ] o 6UHʶ't u N 88V g\fȠw"$ڲNdyWvL~K"*D(}5O$9t#"(B?Tf֕$²~QgaO.g`Jǫ\횹:#^EN'fB G4t/VHx0#hٿ7ڳ=(䌣õqN5k:ĨGG x* k8JHLb1X!09*Hh,D:U.¾s6==n~egcX6 &6xZrգC/b$VfHc$n3@x)B'U݉bON/~;2F6!)i>͔|Z9_9`a)qFU|X6N$jTyX[KDlu- 4~n{p/Z}\Nb e2"dWkVko'2gf FYہ! &ՏٟNKP2C!i,$;v-Ab&2mI~`jQဟS@% %*%ccSGLmvƏYʠ\=϶u~u>&l" i6?wh-4*䚐FI m)QɓRv2Lxio}F%YPXJě.몰h$ ET˦YR ;oC} L~vh2y9l}+T|.O"DT,7rqŽhcfD%G\d8Ymp!=V^KȵIf1jzmQ9N<'B?#^[Nd''M⚮ɈѲe. zvm L  \nwh@ o` ZX}x*Nv]4.0> f<~K0HS~ݪםDV`?(q+p8fIЦtFz1ij]h 0_Vw3=~/13c*T!Ckqn4 s:ope (pUYA?b[+h]5:t,3E6N̓ldK 5o#&^˃lkG< Pǫ<^5+k`JwE?X Un_h:S/{,M;3/_TgS[E<=C98Qs}0jcCgn~ [_2 {I}cma'LWnweƘ3*.tD'upBqS:Tac_~;p2`m Y#:Z5{S%<0ch35c]wM+A?#@{!AƦ0\PW*;YL(v.ro5}wf$ IB+uUb^^@*Үg:+CVb]1hdˋ肱6>MQ7U]kmcdA߳C(ڻgx^rK uZqV|Su-o ʱRZg/`'ΊM(7n:]GFd6Cj%cJK'e ֆXq<Lnu(HO\l/Tx2CLЍRk+JWu?~)(=HJ"#E] 9R*w%YE{5g 4Q)}U}5>\]]Z=W8؅) *QYTۻ^e;}[ BI4)[&jy[;+q?vJ~4OXoYREQҸF*('=}9Bl!@uK;0s%$js`4[`nIQЮjSp;kv!&Ƽf&PQfB&)8?DWX]HnH:hhqn",^ju3;zFD!xGX aPypş~kH5Љh=b (ڱ0?bmD4i`㐡7Sje-P_+WĬO<' jڵm2zJ$}+#Vq> L*Ԩ(`cFA'a}Vࡏ""Q+c th5S)^ꉜ„E2&v}@m4cg9Ix$10q4!}s |! V7;HD^n 3}G^'xJ0l*2ƥ#zސt2[N@^$JZRY9 <-%X}^9r>N_:J 128y.@Єvrafvi.9g,dRk76GW+?`md&I1Cg!lJ6N{/?4 %zr%&jՁy aa0N Qr+e:<z}+M%jʼnWT٧Ke} 0q*HbXJ-]~,w^ڥ,Z7W҅iyTTЂ;o;8 vVҥ 2l"<_,k+erG$QTvso )wK 4~0 7L,};C` 7.b}SO)?3&-o ~c\i*l;T"(>BOKNml?Fp18֏Zs١T)V 2o *$i@I} qͺ2S)d ;2d}IN #pnTÂYv\Np$:QܚmvdQ$~KM߅X8`^{` ߙNh= 4Ʌw˰bLXUk<y!hIn4 VѨv E|Ċ9z &,r79j^m)Ͳis% l1kDtVzAQ܌';< P(_:ΠƁo88%ځ } {FJ7$"6e)^EE >n7&I~ČILj0`8JI>t]爂%ltixwemLזsv)<[%8,(άM. x {+fJarLYF mxS&P VBzkn2 T,V&H"'+fi*kfF'E ~JIDdEVH ;Ĺ4 'ߛ ت_ 'OY;+LMri/r#Pi[7q[U W5)R2r2dKgו4L?mSq5}ĜF폸$ɏ4Z <9| C^JgW_ 8Ή}@a_|,;S-A{+"鞚+799<0Bl{q %x7IG0~6L5߆ऀ"?i+/ Nk W).ńwjEvӄdE.u1iض"QC}N R`]Sprt&~Ff#?2\ 4Om,D~-"{q@+rbE!!RbX%_mU! (ZUV IE*V8ẘK^;!hl풁TH?KZ0b%P {Cp:vK4?Sc҂ةC>εS ;)%vDB2*d @I[%_ BO2P(?KPXD;Bٷf*/v`8w!YYr oMbtB4_x-'v=]o0i.I>DU3zDqƕ6ekSYP\v7DE-tanj*q  mA~2HEѓz!>vޖHꅷRDG ʤǰBhLB]b= ,lgwѯ2gϺ(_ r8|gK0x]gT 5l!`|@)Pa -F 7X^eVJh.3qb͉ocMz{<(~lābQο:?F* M{p >#V}HbƁ}ɤ2*5;Zl> >2g|G82`W,DDCdod7#jێ[H7YtwI@- #71loCGk?,㧌J Qvx5f27-c LqN54l} Srs\XҶXh &u{iO.úo*2H ր4d}LRݛk+4O g(&9Z﷣x>*=]љs=-Z K8#K.lNmWOc F$vZ/v RFkrğ>WNNqK~z; L4[0 [/y?>W]|fKK $ި( +ue;_t Ujz/;b#4eHPo.yBInZ T[Rs"b_[ӐW }CK֯=Ɇ .&!<ׇfBgsP]zRbO4& 'N؜+µE :b|y1.|vlѱP#3F5 ǘ({1i]LMkKQݾu' 5M/@"!4W8溡>3 (K&K}:ĩOr,snjG~?*DˤW`bVtJgWmzpd@|,{VLXSC9P>!xc%N {qڃgG8]pxxʢPC:)@|}J$L/D+kium$+vwDw!UUlwsH*xӍmPOGVrhA\WP=St\G.x*E-ϒgpϬGJr[hrqVI(oG`k@07tA!8|}|u[^gQ~M,bfG(㏓%bAYHG"|D5L=G aQ;GK7@CJ,x*ޣ[,qo[>ZZֹ}9x"$9Oc;K* $dcxB*X/ɻMDp|VWH>kx&,5t۞hHV_@jo?~!5Y86hVeT{jfܗ֑ ,Nph(G=#s[?JG+y.n;tE_p)YC䉆ԁW eIJuz}e 45 vU H@쟕=Ky-Y,6뢞DIF#\3dY5اvH'!]2 2?ŠgEksFV,Rځc"`R.?wkSz_: deEYԠ)X5s ڢƤS>ҥ{_ f]p4B"6[ m_9y ^ `MߊxUZL_gTzaLj.O+`'RKa頊~@? ʋjch´ޤ -ֿƴmTuYURtlU3c\~CӚ϶(V>ˌ ,20sTanP;r-IR I/0f[J˯pu;)fkoUլX΁[$_uɵ zO:gS1#,̖y4琈{C+xV5!H.#\jV3 44Rigu+WB/ʀӅF` 4LQ5haȿP8wA=J;P&:Yc0`Fo}4j@٪NfL7Q<A'3u>LF҄ lr^s- >RIqFFwCX\̝^2IWx6jџ 7'6w): P G=WNF4iDءVjzvreŖU}ݫ Jh$I(~5̈́?]7-ܺ|aMEK{nb+_F5Gq ]p~zBe:nW~ت̩:s{)CksRo8Tqtf(:if_tzLPۥ2xέX̏X?l> |C A' Sl`t,c,u &.UzJhWjfP:V-h*pC_[2oFWDsg8k8M@O4z1]o7:<Xjs#@58a= MF ]ID-r8ֵN'eEQ*c}T@uYboxـt%}]"͙PJt38Gq#&RVC|)wq">6o\@l-DgDr2to+[3u,p0$~%"o˗oE6ErVY pAfKAk=u'쀢H̹_zu!yg[m31ZlC(K}`!2w;39%ן>Hei=#]ͥ$ K1ND5>EPt ϰE@[2F74|v"~zIl1mA@@fۮ5Bg37SZ ?6UmlXؐLtnߪQ@Bƶxn(Ǥ6LMvWx=^  UBdmG -<8R\d%Z6.m #ݢFx%V*vC<;~$!;y0P< ԰f3LBnꄺU(F%VXaKNi&R h]ƤtZygLP+Hf,q D>٫Q_@I;sX%ztr,ÆҺ*C KNV"1>Q' oK yKjOV}oUAA#*[TIzw¸Gm[e5v,?h-U9??U3ؓH!0UX⩷]ϞDx>zSKG'􁦌r a_ ኾo 8?>ЍѠb\"{j0tJ aهҖ&ipӀ2UG*`FF/V"tbY$i^voH#9Y&yJB'pC޲oiQt·wzfE( HȗY< K[,e=ix^YaEWC 4'5)B+ ,/[ˀy(x֍شRcYMx I$G#Jut({*{7ã27!@VRś!_&ԖՃ}fHjik&ُTU8.`ڣEM@{C4M:H>9n'&Wv̂!cXS_YpXռáШ)}8Drd&pk.YK/E1 Glk231$kf֣^hAy0FH9婱t% 5 F=mZIp W҄D^CKB# w}uRbt&_)i_ Ӣoa*{c+j.6@N=ZoM3fL#/5ԤlČ}%eNv+3Yylxmœo\fWICvD<$HE~PE {s@ZAXd+q 5y~;69U?9axۣWx}۵ &3ϝ'c\fR$]I9ie"=4-ŻsEȪmf=.6/dzeig禊6SskF╊XKD2?~yڟ0a: 齯4U O1G繸j| ^mA7pܮ~m̞ztSWND卿9\=n%t݂Z s/Y`/IOʧ)2YSPmt_WTncV9sS>R |}eA~+GYtzT@KZ{v.3H}|E0-ψ\_-Al%gPZkJV~[ qvq9=;6hcQv@+y!|䩰uSEn{rwB,q3elu %a۴͆d1ʇ2l4-t[C{C1͙<ޚ_Ȁu(Dt{YF{ظjd{qy`yVP5BoՄ+ b.Pqe UW+A BQpq.D/mGVkҹsvXu*:Eu6bEEV'\ưf@+U( d7O8xUZy=3C3dwE Y ʦi&?iFQt"qꡗťppPHLņuߜVv@q$ .}l֓^TV= 3q=żiDQb<,3Z-yY:1=" X71ˈIlޱ/Z?xD,|.E3SI%.M}+iWS&K0{cߙpym-PX>.Q5py$P%3id#,oAk^}zDo4$t͑;30h.X,8쬃o/%QF<g9Y& F|+bW{)U @yԑڃG:qڟ.3148fXKԽ"`ƫ.='KRcn&@ok~u\֠w[4oo*[)7>4Y-h9"e%2&H4P ֐q|tNNr3^=rl졬M *40k̿3~?0YR.Y1gm"5q.3xQ I6bԘ#>ryQ0ݼBȲЊjSSLw=3X 5seHjC=M7L"ruÚQk޿`fdGk< rNʫavq~KGu3[L]a??@hYK*xʩd@ɍ"bG0:_Ħ򐡏7wm^sd˖{@m4ڡv1UslXJ2=8nE4-AO>eHS ~M\Foʆu;(Ӆ q$PE4~HY.!hNV7r0=%\TC;~ylg6+5ͼVN4nE3{RBL5 M/ 2K'-.T-enpvopeֺfKByсveXo8mGe&BOq?ww_Op%-[>?LR /)Ɵ LlgWb[NY -!Ť9WQhߊhMu-*Iȝd#WIPb=ǂP\1EpO>] % Z O{IPkH ECۨpʟ mؕ0!~I\.[L+3jRtpB[ʽitpwpդn]́l䌃%gacs5z./~-a8 RJłp2-N2*u/o`H#;x&钞a6@3mۭz2M @x⼪8I#Z5}y5W$uko[EepGUSyTntҚdYW;ϧWp%4BߦRa":͏c^1粕t77tG5T? 1ΌE(3sD!OwC>WێZ7.š'L}ľa1&4#|=1F1jsfAnp7B~aJ  S|5QӕAoC%H!\ͭqq,_F'&&X{wmYJ4fHvT7B,E$7 O/t =Ѓ>fnjZSǤI2 +:Ω;I5 ?KBuXa,-*sʖ4zJQq-ͪ gC d/|,,+!MMFBtļP5l=ZpBhxkdUF!RP,0qOuz|C&26P-F=ߓgVP:)ܭ ate'з6qa-΃K+yU%2U%{eȓ%aFׄ*^7\*/Juq|10eD_) -6 j{t{Jf&]t RYsB E&!D?u$VwCs8A Z~'ZqB dd8,G?kM^l~h:ثS݌HÓ.NQLnIfh7=`\С-c%Yfs7Vnq觤C?O?쓔&߿,%'szS3pBC*glA=T`)x5R5X,W իr1C G,\⌴|fOU * ӈuDg8uK*%{E=T W$Ӑ?+ NTV8kçX ] MWYˡ%4XQ sY-aN_/-?) V4*< w: )!/Yc?&#.{Fn*&mBvADe˙ 69 sє8 -HM?XU3Bp WKKKa(x㇌sm_=XDUx7A^f<,ÑU/je@r u>wI(Q;J8%ߝ9]s8~uc*Yۍ[b0IxxDktkй ?Վ@4u)/nMH%l2k!ܡ鲂70:;x, |Z7H:hH_;H%Pв}Ö `|]4f3yqBVv4{j.HN;-jh;l0^Y:*ဌ`I@8M6% $Q],bma>"'9aoދ~2oP}5C8@,nX@t3ckNVN DRUtUyY/Ժf|U5jbA00}U87v+ɑ`iېGW2jloR${`ɞpf/J(r  +uۘc;]Ttece9J&ƫ)aQg%SAS('L8E-I=3<  1j`{(t-T+ݏ[(R.Qf&]oGݮ :Gu 7ljnQ,#x;AdP/K[:|0+}N/KB&~{&0uwt͒AX&G$-J =p"aqjcǐj_c!ݾR'X8B #kjnګqTz ]-D$ض4x%'ր'_kL~|\`$ZQ#ZyDZx+VGJ ]csqT:yztCSE]"ʥN3D\?j̓Y R>5]QÕDsVRڌnC{79K4'.x+mPX-R6U&k4պSw@8`nBr~*y*k\r6mpnU푥߭>iVMS \ T +˯;+Wn(6篫E#cPQ3XݭȼfH'&+o옆|&"UyZ"_ɕWt^Wϥj찢*[ yigҾt#7`X2J]ut\ ߦOm ՒdJTl' @π8+J <VW9'(ymjA&gf\*%[tQ!0J:ʹ^Z97B;BpC9<X9d4D_϶ >" K b~|qS\vYT4ntL|TqJR>*eJ$+yTE8ȃܦˇh2li_DayM[LTJuiNnHЍ*ZJÛ,U%{1tRz~ jr&sWt@4hԚ3]@9:nL: Sr@S;P䰙Sp~ ὿F@"k 37_Q$!Kdmly ƮiZ5qJ#A1Y0.'IƫEzt&'Q7/LX'oМC8前rWRzl5D,].S+ƻcFV}?=w/!&,UDWpė>k~B i}&~DU~X;_W.nozd}#XSB=| eH'aߛ{h BfGzEA "f%BZE툔&w\8՜Lˋk[VlP;yt gO<q8 I ߰*Q4ZTM)mޜ|ZWT찘m@Ikyp#waώ<7N3,IX!TxmMbF00BE*AvP0-;UR_d~SaoM֤Ja_y?tD֛Vlm-زi1 >ԈQQ7kyrBS !4#O`x vI*ȷE6/?*6Amn<(GK~Т!6G:^&^'vưoӃN+my,HlCPdH' ,Of>Qc&r ,ލvO3/CJFǪ/<΂B4 *E#iwMM-ob4DAly۶"T;D- &8Q{`34Pq:7lh?*gPw|W&K]NML+4#h]G^wr|}6u'GuR#W LW: \廿X_@k(\p#g}4^!<ӘK.,߇]ԛ; <r Wϴ€'Qؗ*i@M M'۝ZonAy#h^uڍbxFR胁>1HtЅ~.ߡMCHETGqu0,G('N vݎE FzWxΑnnsi0kJї[fOM}a_۫7=k4'e~h!N9.>EVԠp{L*MCq[N(b@s;Ѧ,x(1xԘ>4)*vX Tr)U}״y'!O.͋ #j)S/M>& !W.lvG>?81|;ZCPk,c3 aո(ϗ, NjЈ)'BϗArѸRYi#uS`q.#dz#N6e d&Uy54G490ѩWۣs5B IovΗ|-V]{PxdQ&/Z6m| >mTݙ;j ?N*73Yv;diFDmzq `5DH_s5EttdpeW $ $ dyJATJuŝ M|Pi'w(aYLdiz ÇkFoY1ïtY"_0^5x_[.d]Lt18`b-r^ǺP8ɨ|~)_hvykj:4؂ pF[k-IAus'|}tܙ|z⁷/Y^`r7 Wշ"Ôӈ5>i7(r" '|IvW FAd @_x{@pܽz٪L|{`E#M|] ZbLDHZ1`K3:NM]eЙ5jU6TP0M OwSN6p1Lj0gO;1(q&H`!lb_ ,@?WgܮðqfC?OKFa7o BM޻zu׊o}r|4_iw"|Y*FcYwHw(1H$Ġa3oghD#UP֮)s6ķ*$AHJ}+_p]Ӎ$n܈"?)旎LHh\Cf"xoG4XkD|ܢ)ItWRJN"0#~SJʛlQ!WwG4([〾7>I:3 y\VF8ŞTYߟ0i3ζ(]gcV:|޲4 xP9DM!EϒK KSRehH,Q1ڧ S;U,H\|0n 7LZ2YF$}m>'c#X#:lrDYia #G ]I2WP8Ug#հxCs(A3sŘ2JĪc6&Ig @Omݶ~Ҹ胎c1Ԭ#X[{>a,ğѻ @$ iR=aPCܼV)G.%Lb0zp HM FȸKFVyI(q;S죫"YAYNx[__[@!b_MP[]}- .|j } h +a!-B,ZV:ιe"ݟʀж(&Qd7K}ۧܶZ \Dh*@j)q8R/J+d3vy=j067x^} ?R&B\`~ }KGbqd^ Crky6S88 `d#OyNW_>0a`+w]unTqD-U rT}->QZK뉧PZkNe'e,>,l^VOұjJ@9)>(@莢V׃=7($FPsBl] m(wo5Onά0)A8X#eAVbcIbaw8UFvH41Ouj*/I.c]k\3s@ u6ǀZ8 I$HNG*n]GOf #'nq*y_-sN{Ve-gN/ J<|}:'a+X^a20)_IF4%氶IDCZV5•L6teL9V Boɸ5X֓HKL{Hd]lWvW3>e rz# (c4bM%f| Mb?Ekh%&|Ltn]cЭ;6M}朠 lڹIi hֲ!|.&*+I':0SyKhud'T\T~WL&8|Kzmu oz9y uG6sr8Gˍb':_b >g^w/)w"#z/$!4k͙)3})k}Z*#A$sQXup Y ]R7Jڲtm]׶?\m#h3oYTb<ɉ ;N T(L21Dh_,8 y/S8mG}-Sj`t9qM/(G8KQj&ߖDt! ST}B/&a @ԯ>Iq" ϖkUn|qq` ykuo(Iw>$KIPġ?FTU&]8ܷ֙&sڣ(Fto9PZ&R&&.[XI3m&$Mr>dW.mMY/$p\^Tcu{խ8YSYSVE9=\aϧ?UJWѺgofNjyUggauV) Cc+ Yݬ6#8:noM 4)Ʀ{@0OyQŝY%^Ph=9E.`OzNƾ>mXЧZTgx1N&X`=cq+d)+U3;HKhCq$_G(Tq`sm~!H]ؤ|ѽǡm'ԯ_LcO׊'R0 UK2@Nd@j.ˆԳc@x^NGsa7 }knn׫=x#`4\S$?+y)HP^m`\ SH?^ҕ"mh ҄gV"KZ-*نsBC9 #{@DZA2M&a^T2@2wU|mvo!jZR>1ɶ gCcN=:i=-At^bq\^ ӥ!Յ mQ4[*)oYgfrb$tΉs_Ѭb* yM .2OF&%A=eauRh*$$2S! St>%2iZ݋8$(VjMtʠ?xWsqQ+Gnۗ>~WH?s[ǾVP$%Fn  >0x_ X*EfO`dPajaDSZe05M!^Ro8ZoEquV3 !?qWTkDsK(Б?pz=@`}p107/8hYr9o8J0 :YyU6?d$)KafuL]i{&?\+6)iOqbQwvlqX`: KZSLlpyQ|.ˢeC%t~&]>:yz+Z%] ^j[TbVXommj;jVah~Vxo2>pPֈ^,&I7֔IG {C,+՘#kw3뮛>ʏ#H`>}/ jF2L !e0]&*w @;'T' '[`W'?ߪ?#AG<X2P"6S.iItyuaJj d9ې^`cU2YrsC$#q{Rpҕ(4+==3@QA|C7#qft;f:(g#W]~OE<ԫ#fc=Vh v ihڍ?j~_|08=\x̧lk3œh.|]m6bZƓsPz!~#{ c|غV䈧._Sn|=U@Hjd*lgD!J?&3n˃QU\x^2t6P7]ez(%*4ab} #д i$Ͷ,-L/6  J$.pDԮw\pn'y,yСl-j&#B[2;ғ24N D촔m EANJ3 x*{ȋN7E]y>d@~G6/ +>ON5Q_h)`A"0 &iF\Bܳmr9[դ,Kp)]%9}BQTb11? ]O Y}(%\XݤuMmoo7\ⓉbI!,)@q2cڪd<h@ޒ,Qʔd-F6n5'9m>1y[`&ʍ}9=-$? 84]1y=*$PU%;.mQ,eag)4,06GD侌:')\a#8b=Ү,]~]5B=MxEZl]0#^AiL-So 2 h|?u頡C,S0!R-u)WD zAQ"҃fh=؄֥ K.1Och|J@ʣ]\vTHn $V2<.Šdʻ/j!D)(Ӓ`oUbB *^zJ5>CioRo/#_:,)jp_) !l\3g6~=V}|}x!U^g_ 87fFGPɺٶ7{kt ZD2胻2Q$mg ̻Yu'9U ~@+Ha"ÙYƕ0Y"8!mo .fDK"{6ˢ?tBWݭ/ً׾Z7BOedz͛;s" ~ 9!VkŇM+jD.-:i?R+[/ES!vIUTbQ=m-5h5 ftlE/蟁"T'iy>2?kRZRMs 7i) vE$5ߕUBQEow;thI{ ?2w>@ /~KT8IOX'@)V^BEI|jauS훎|2Ք0?8 ; ?!J%j7n"Þ̍b[MÈ-= #Yće i ~bBsE`Coy5t&O/Qt57cfGh{dZ|0hCy zBhAqM>K֏u9)!̕<аL Ӿozq7*m!zh8ۧ x @k҉zVj$Eu v+~!+" a1K'" _F=Y]'v5ehDaĎWC -aH"9s[^ê/(&U;C2)O2cMC\!`~3ַFQukJCA"GjAqHvmaGʼnzP:,ͼ9B=R==[ˡԘג3,?(Ja6ΖyV2Zx}Mnaek55=P:Rj#Zг̫(K:Qx,0uk! Pl F8xX) 䛐௬"oVRrl|lYw;<|5|xsŌ(j9솞Ye[mo~ݰ*QTv[WlcWZ$ KOELfNU՜InC4ڌU6]r<*\I<!)Aj;(DeGgE`I{WhKWߥʷhj.`ҿo\#V2i'o=k# #`kZ[zHJp%2};U=:rhπ=Tڱz"1(6JԓB3ʧtbPv?SFU6 ~ {k@p &GgY^Tjq^-SiO0]\P1W:7`\C5}]ndNԈjI>3p(iGgbmj;1Ciy, {E I>{k0CCQ Xʕ$ma0sΥ.c* ;e1ߓ0@jۧ~A/X4`x߫9)*tw)cƳ[ epֲ)*Fg$KF_d5]}![dbmÝ79Ʃ zFgHj2&?LQzxb]ir 7ј쐭U}h\~a="Z܏utm]\u=K8&h񤼔H X}ۨ>9}? T>XPR_4 /ϙw;H`%Q5IZ>\l5Giᴍ!jc'*nd鑭U:83?ܤH'I׏MKUx1PVU] U#")J𫵝,q}b4߾.,N%MⅳNza`32}P}IF|Nےڗ1T$nD<- mq3@>+2$]SkDMY`ۆߵH|O2L✚бeE goL"Tr)mbv6kJj~҂sbĴle8?:jrNz 8ۅCN|C~BT 1 @:WBb-0F-U`!^q7My#y,$C[[^@Ya-ՙY޹L2w#SA)kQnD MVR6Z5*qqREP*$Z_Tgn&\MT%sc#U{OyuLcOҡЪ75@kiV>F*O-UH.BV"_XdEA8EvG_"!UR.s1@w&wN*ubtr[mIy %.ۏ_H q|;hτWn%V@T!)BmfX:v.`/9ݹ˒@̒znG [TA~]w/Z66 JyG*X8L2=P9m\P)9ֵ1ޜ4l۱G]b{~4/#2$9Z^K?G(]l3uI W $-nxk 6ɦ)OH~z}-jD51t3@{Ldf̗d/X@[uԉEqXz{gr80@ PspcgqpE" X1WF\ M=I48Se]Ó4Ehr8h+7%7qN0{ Q\-DKMʳhU42;e;mJ$R\H;Ҡtus|xvS%4 i֋6ˣ^7ڬ`Sک`@.xd_[/ ( ,edOL_['v/Uڷ op⿿'q:OF hR*QqԔwx!{t͎mG*"ՠqjXs/I< Z-.߮пiTϡ#ْ0 Ch@ c#j>1yq2Awna?guFg7ZX!5'C[< ɤlCn{3.IR w=iYZ* GT&$̈́Љp 3s|w TJL bTa nT,&ŁxqHaY. ziin-rSs{ٚRO[#첊>Hʳ< z%s0cyWo[TvmdXC ƾ`Y!ʜoAX p!QNg 'VnG)EvDR/>qs| 6`qчdtK:yy nËv s4}uیEa^YG.&X%X`aߵڅmbti`p2ǹNCWWhoŒd:>fi%H'g(vd:ܫ/$Y i:x.z$>Q4o^D iҜW(JO5B)DJM}`&1n_fw,boܡu䱢D܊Sۆ]Nw*-#L$)qnνH tkeE+ G]'.)_xW tP($rX&m!ս*FIn=:ud V}B" 2n Zy7Ѐ(4 jjA,f[{iyR/L' KCRo "eѽ8@'X.4LK׾Kex/ v3z]5c_QbGXe9`p'Ǜ'6Qb?15KY\=+MV&pj9 - (ѥ/ 2?H8+T+G]ɉ2:ѹf;,tguzS{yT 5Z%-Fj;rrAaqs_:k%>7Px:ݘ zULۭ]!u>3p)/ :1|1fC_n `璌a  >MJ/_f({I3BJVe4?bճ*u 9)޻;ޕj~=OR R ㎹FZ3j*Ԭ.jy\rA!(?2raB=(Nv{[ՒPޚtg;L($wtb - J#l 1UJF:]`N nYG7+3<׎2=a) ڟ'gTU]~B21.묾ͱ,^S[IqxouENzJ^Ep4䃼f,gφ٩y4tN@J6[)_WP6]qk^ZdNAUsVè9S$ɮR'xm;e2T$6\Gԕݒ"(8T^!YM؎DP*!߫#3o sf:8C5ܜ!#A31oDYdbYTrݗw_Rb;lv17d5'^A܏bzuU:9~&!ڋݺ ~ &`03赁Y(Li0|<%>?іb>cqTԻe' eYICu$HΠmA o߰(/c.O5tI.l[DF)[\)䇵@F٢E^f .{3)bhq kkv52Q6A%.]ht*L8'0Og'KE*v+J)S--)$k/e9@*7IClv&8FYk6rQ=]m-M3 {Pqv M,9ڇW 7:..dRd,*dL&I旐4rf jL=6KcJw9cyh(5Б~+Щ/"-.KyYRtS\lOUkA+Q0lK/CP"ÝHcB (o,C_f;G+94 (S:eedt˜Ы7E~ڡ\ C c dž ԓb¦DXZc"%z˝t~af+UZl Sjww96Q.(qK{ZRJqYWף@%6y(ʣWYd $!]պբ.qjKSouQP_glņxK6daBH^>ުT Ǻ`")Dk92G94m@6QM"%+99a -/b-A_2jX3@UAa(H6H%NCSȺ֤o3FT݅ gu k9m(ro7SJ!|Pl;d`3Œ=eL[`$sFQ 䛚Kmά,&d3dž̑@VՁf>:hH_V@d;QȻ *tmE%0P'EpY i{HHʒ,?.&۞'s:v  uȳLSnq=U7d]ݔv "<Oa@ !Ls]Dt*E6R>2o.*.Lf#ϼ,^W$T_L9JJ3PΡ ipBB43dn"̍iHZ7 )aX%nIȨ_{9V P(pBBWaFA:DMiMæZ`[C=[Xa36Me &[xc[36=\ۮH0^|'C3aV2 W!3$ݻ9*b/)?S'I]I [77HLDuIqh%kh7B,@1-;z !- p(dWtxp=;4G@K>XcXxWrϕGM&^ uakRiFJN[-,] -c|N0I43'oDuU wZPI&c!C׆vy);kyxl>b8<2- wBͤ?j,,URO~t/QW*{Y|Ҕ ]~ XCxhrѠ|{vav|fΘm: m mY@-xr%4aT+F`D3̄CD2ț0Eo *Yㄟ/d*@JA0>=` Qcc^shڱmyp3AD L*dᤕ\+/Oߗۿké4xK5 p9קEoV0};OlwL%=0-e<~$o%>hR:g*[Gدum L^j;|@"aF, ʞ@"(ˆ!2fLf0!uA&,Վ^F_1ץ˺g A2A>- +1/ڡݼ~ˍe g(16NX#  >}WQ{4->X^vnri$I_a1\nzӴ#}kV|+K,ڏpه@ JO^&9%LpNu 8v8@1ݻg"?@4FWIҁU 瑴S&:=SS%nU lOZ0KNv Q1v{2*̯&nua++RޠΈC79Nxor pW?B;:m?2i2ٴ>''6KCElJ;8&'fa)E|u'lj%j&FQYϨ Ԫx_eRƕK50i+-6퍄Ov' \^Zg[8ڞAjD~sb[]'twH *m-C| -V af ! \[`IY?]@`P]yK(9.a:_s؆PJ}#ux}V #gp:,u.8Ƚ>\A+{J."μ-R:ȴnR+]:?8H ״a?4ߧt44?'ni+)Ex]H-2 b[((q$_<#LZ3O\Yb.5hld Fڨ!PH>/&AJxt?'`X@)&cJgoY(;;Y\UU@ұSY`Tl1wC8|zr532;:d;1 2~b(Ń3n!  j.?BZ&+JG?%+0TI"W,M8[L=JMN!<-Ɲ A eF,NF5&M<ĎNa277в| bjQ%jCpgow2T |#`8p(hawxan<\ (Cd^*S/ lV4w]<-{b?ekLv٩T3Pgx~kμ.(0_ ZN*V_%$w (Y8 )zM!likȚ+rh }*?}_KEHܴo+`mV#- "(8Hwܜ7~\< p\p#gK]{]=}=R^dqWS2=v\`%RXJUq}C۽AuOKFI(By /9Qՙ`;^pRβ-Ҁ6h_i\2keguu&Nzwg?wOp=L0ѷ5fpnV]p:M8)Moq,I?m6:pNFE\[sa֣4=Q7B*RL7hD%튬d_\f6& S'%= ~pu*23thmŖzA@HGicmTNcKb,kfVAd#lǕW۪i\Qh$م"(G/3 Dmc !Q$xXIM6۶ 'Gg]0Edrڟj*ZFҲc]9qB̅uS昧+bG=I˿/ 0Dnf$.:>[<_n 9_ 3iطXW?x{?ϸ+&"OjXb ;8?.q ^~(qFZWwQ| !vU)`F KAdјg^GkXBKIOg gY"&9P%F]E!t62ݺ>-i('z6w<<%? B8g$?pD@H2%Z`>LC5E~v64C/b!俖2<ǰYzu+ܑȩ'PU5;$B%2_NquM^ %ַJ%4+X .z\q"y"*vqG2F_c<'—bCuq999akdoO{L*(;Be00S~P2v, 'N#SeOԶ\\=$~ 6E*`+MX0Ok)gM^3/$#<)(HkSLjoxz~+y?Jܙ8oۓkxOk5VŒ3nKtqHLzŝiUy#ʴ {ġdH`Q;h bJ,J`oUvL̠j1 j|h=X1=~F=uN/*Kf," -c* 0 FW հ}RodxDê^4SOh~]g7Cv_TAޕ,$ el oqN1a*`t#S9k-"Lju8wۙ٨Žbe?N}zF:Txer`Ӆ=K T{_ɍQp_Ynd>"\KÁ(Ӷwc=@Qf5[)_A$Vة_kp0To[fb+G1 bpj֙ELn!9k)Eze^'RU RjVq~Fb*iz}.ih(Q?A.#z?#mɅܬ 5qI'kڒON~b`,(]xU{oe3!m@"-«ݮyO3-ZjˀIzȀ8%jc1mX;#+L/!L)*nu6)ŨT/P~G8s"} x%lbY/BQ GssTډFn++gINd$&=W P p[N߹%yPz"zOD.`8I7DΖ8T~6;3b2+GfG,)ʋm$';INQ?n\,/jm++ z00`ܖăw)_8 ]'gTYPhiLdAVGPRt;-Yq ٩fpێ%`pM]zPÁNg\4zr4[mZ7(*J7L%# B|ZOڜaaJqk!/sTz܈c,DOHyw\srUSs:`=4GfH##U M{͂Z5jw PTry[J/|*f'H VzP< GNR;B[0- W4'ë,eb^Ih|jSO>+{5Sw{&C5bV_?c'6V{l)N[|$|M|c١79pR) 贾EƋAz&x9R25Hx0P$ ;]hhiqB-zLVF˓&]Nj=G\V%||:$Tq)AN<涺rbD-)|.(C`0 O+fTH*egFk:=EhPQR1*JFmOH#2Lf S 5O&ΆI#UXFi|]6:._U$R {BEUSc3Tt?MDpA okQ|c{C:8Y=9 G!\{\o*BǗq@;FO)AOw<Z#8GPA:n ?l;=v{b^VJ^mt#`nX@$69 c+dRon'Fs >݈"ӭ0ph`LWwE=z޷Rs#Z b 4e?Cb]KL.ogD1Z<6x[bG0휜Z>9B0ʗAY W2)\]85RGBypAme0Nv;Tqh.S9 {pEǍ,R n,7$k}}2 {elr4d}q?y#sY8c74x`f9d@fi׎DoiK1ts/ZD7MgIfujGu(hu-(3&\0ms4C̃be !`..62^L` xh([iW&˯uZCb7uX#,۱0VWt(#奇&AQ j/͟(o]{\k2!5jhP򏔣m!e.ӯ8*ӗTYH#צ!}{S?8G4gã6L:P7C؄YUn;{wc {FȸիMM!%ҹgC{VXFC{gu(oҋϺcE/GI !+@nꬥ=lTVSn 8n$Ȍe&W 8t+2?Eu2L ,4+JK,- U? ~rE|ڷi&j&򓷇 6󖊇EB/c!kjAP e ^x4kfipZ)~>Pf< DZnPau[3|%)կM" (rhhb/9SCפFMv[aoWa{rb_5"/5QR `G|J:!c/=l`H=ӹPOAAE\x]Uf`Yw]^x@;D*f8ik^D\SՏ&!8l1ыfɃ򔆚zztkn^R295;=~ċj2>'sg2PD#ـ}8kjb6P5 b$ml^@z2eަp.]j}^zD'.Q/ϊ-aĶ(mWis^y<@bZh^ہ c[PpJl̞&LÞ%Kj *[ma?!jՊtΘkE_'"4H>+L o~0$u\X/FYbސwDV29Jh\HN F)  ж4ihSY I|?*!Е^>iRM&O)EmAxwS@q[_qvN_OQ8˳T>{J: ќftT|s O觻|]9IoLjZ[~oC푃QaC"Z-t 8ënM`w}d٭AWbLe鯷_ްZZn\i`iT7x~Zx2uΏDI콈joUmw_ xO<#XA2PPY6TwKDFJui]$ ZylOX,X0}cO9C$H"U.Y=@T@qﻐ:!S69hLg>`^Q"kPnj>B1Map{X,o`fNZω`;OVT.2b{Zm7bCemx#c"F־ AȲc\>>7?ܢ8m쀶Wt}ULA-DS&/vOS\^`z "Τ[Y=/6A}v3&HN9 ]K؍$!NƜ}OSr7g$pg`]_8P&~]jMZ^DUwو?*Ԟq9NJ1F=(R %[kzΊ,/Gԛ鱦4ۇ"dIX4XRŻrB:$v#tz0;1\vƵaS@% Hf>DM\ m&S NH潫٣l+0"h# X҈ՀzlaRnp>b d(X&' ϰ߳@D*}T_} R@0epb46u5ӕIX bQ4` Y@H ^ aq?P$P ~_44spMsugmxNKsCdW=pGv+tT2΁"*j<ʇ=F:Ã_AMFuGP_9 Y)7_(庬LjH+ײ?ظF 0tɊC7@fП a_8PWZ$ԆoÇxxI)Y.t !$e%HG%CΕeǞ]=7'o;*Oy}b\9}%ˆu1hD{cEB$KK۴ 3{ jh+p4/TsLA>TGy"m6-1w/wӲn!e'͌,;pQGvhZ׈XuWaitM`Hxl|̸MytBX>ajKeCzԖ{4†S"''/ϬvҌ>r[Y}HPqHG6S!Pn,O}o EjKю^,,]W>[s6t^+N5| +TD!;a/_0"YV~$ˁxl/mT"RU׾€A9V=IzOW̓#2=f?6=3Z^KLك'L&̛,-B.V Y(F`bԴHj$BxE.R?d)pQVb8XkKl@]ne6Qvc5%#܇#ܪ 4|!,<۷>R>݊3ߕpI,Yc$6pvŨu 2x*-0Z!=,gϱl6F‚*N@8Ҳ<=̱dl`QDj(*Djۄ}ų[nj GR "ѵ$ 箔HjFHNV@\-o{0S^m00k9:h|r e?w,џZ\2XVDeO\~lNW;n5^4|L'>ZK`Q} b.rD/>ڸ|$`smSE- ?w$ ot8!^uux~Wn\x>)7gۺfiFՀT:R1rG$3~=WKn}ƜuU֥C"z\L}ө7ب"7Ub/grUJ )bi^0%YwJM2/ӓ E< 4nj.]gIVJUCTwQ|wJ]dn^<8I ?" A#J9IJZ~Dva!v'x`Y`0SJ-UKQϫu /!3⓼*ks5V:w׹q%t dq+_A\KwX9%gC"Il'`Rv ɿXf=k'~dEAZ5PIQ] WFS\߱z!댳WZH@ĸWFKH~ͷt(%z|9$ ~R 74fEt>1"S<{RB\Yi'cg"kr?.:-}υHTNfEh=S{5/fzpO{ m|B3ϴiKZ>r |>(!*Imα&u6duMّ5}aeOJc,7D(e!~;P y\źˉ]mmGKi%@ r>SH"@+5 ??`ʤ=(:ôl}?"3K"lTntF@4Ns@)Qe'fLk=)Dp[W^r(PYi 4la/ MbmuHִG Lx1Q TJSM单0^ңnuȕt^d %]ZKIZ#x+@d{[~ ዯyZ)fӁa ѕKű#"Be̯QdE!D2"KVs OBQDh*m#mZpZA$8;i\$Eb As@ BB8'F ~8ڶtK@Ml0:s)C/a_skPA͊$q ssDenƒ+xm41,eyưR%Iw-S*+D|dDrUq"´ARdaq:q㚶FԵy86K$hI٬eLiQj^P\Qn@,!w<_.(eh1Zo뻮֤P?,؁5|q;տRSaRt[*4_:N~2:SFO ơ-UQ  L?T{~ Ӝmv0H^!s[dFQ׆C-d2fbiFX6 s"YZʍX1N&Hzh64?Dɋq2G s5e3NҢpGipI2>vTuq3˰^Ή.c TTʁL LaS ЎeBa39By$%3pI&{nFdhh q<oJ&?qGοz;q0rwÿR m,VeD:8PXAm:Hߡgώ#)\) '2MR5fxVt4 l@Ah(@* nkԾw)D~@c)ǹ"&{9S{9Fs{)*&l[MvҲG®BlCyգO~7tB1mRvc˴Jȗ Sg y5 Uے#-ŠP4cz$q a$L ,^HTas*%Y=~uL$g#R:^tPvG[:\] (SfJxG(ogܔ[6{?'&l^Q8 ʖ0bJ* rcmK>:Rۢ`6pl,+̄>VMTZ-DK 34+r^& #GE&z3lbü3'MĔtO|׆uapvGK$)ښSM^뽢6y闧^zAQ:Ӑ>^!'rA%2}a+ǀƘaˆ J/u\kZ1ڮǃ]I E=xx$WqvxB׵Ftrum Vcal~9o^ v(CS>GUqz:RMdCMQ TY6HLNd}_8Gs3 Eu&_P۬&}-`5&k*T 09Vءr*>}]aH6)O^Y(V eD @B$G4soAܿ1ۿ#6{V)ZũpRQkdg֘*Ruvײ5A* /껠Gh |͜6G9"Y(gc$RدXðn7BxbO&5v[r'h .nj{*ͩˀMXføă=/3vQ`-pT Op+vj&k$0k.e[_hVt; '4SZᠤ謹{%yjg9٣p 2)ޡ(7΂w)Lbc.En-BA;] TZaGIܲq48TB89‹fT} fhRo^ap )r" r7/c>"و6ѳ:o3Lj/SР援۫ᨈa֦ `>+/ 9yk ӭ܆ͱVe wtdOtfz `Z*8I ӐhZXrLJ%esveVs/ ?O2xeXflBj~*t^CynS!7Y:aҧ`$)m = QL4o6\6EmtfEa"S?_Dm@/7k 4s;:5ڍη&ղL9[j(ަvW fʒEl$jry#yRU2yŘ3+ 0IVai0$e v05J /]nM ,^sCC0fOd]<}쳺Qz<?B:R:6rI=88n~m#p#},~3オARe_"PL JT;Npd^FeeqoI]MsL6dVP_:+ IjheÕ0_ɸ%YBB̅Y3`տD`JE7D p,5Kdo4w tsέ ,^,L'S$Ⱦ!xchg{M6l-Y8Iw3IJGi>XAY nE/1ct6Up!)#9vۆc)iT['9&tu,Z}XwIF~ TQ\RG3Z9UwUQB^?m[蹮~5/qQAY H4s9^Df,iA*VyMDt̙3v֦&y5D*F\A"i˒ o߇WJf8bfʪ?  P'nS4 c{|}?.u!\{qs2Swx$n;) m^D^V|,Odu/sr[fꋸP ^zJ)γkB􀊃j :v7Ր~j% *Ӊ&aI~ %@2'qxJMXrQ]Z9B++ld!9aL>pӁO ngn|;gt3{UHrNfKxxn ɦ஁ۻo,kWVͦ*LCڷbR}݀xʔFPxc(B\シ|ǚp@j~s?xY3p'GPBb0VY$3T̢,ݒA*j$? >6Q)f:0T3mT( C@8w_gOM5}kY" 2K~Pg?#cV~0j}$Oh#K4KoAZvZ<NZee\]@\fvk I"fex5G]KtًoTPaɷB.eHSKe"Xʏ|(ǗHt p~<՝e|iM|=lo'dajL,uIJM[{-y[BNڻ5\r:ՕkbgN`Xj9WGhk䆜sq r㉖=,l}ɎT@H¦;=~{@TaoH.Ǿ&PoxA5L}LD|̞6^j~ȧ.) pt HAI7(]~K&nǑxk98CfZx }Gt+ wޢ0Hz]} >1m۞}\~>۟K2ԅ\_S Z 5&vpS3ܮpОH@i3W +I65^H = $ 1ށ?ȥv Tg/]oCfg}K4~Ui9A=S몺?=-* da9246)8N>Z/͞&nWlw6:߭7ϐ&/ӗ}ʦ&fyN] xm4.I=8 `)BޖP1x!Ue>hey%df<~Mlf`bs\ZF:Rx SWUzSӸ)k9;L ϶:k.̼]nc&oOHO6B.R3bРs/k'l4DM]Ęgp@ yDN>z屙xIkɞ31gfpk.s6:a呆${h5G/Edٝxzܪ?=ؿS x`vB+1:/r%Q|Nd|2vgRS1*߈DǃgՏ86#HOndϘ NoIgY$mW}$kTEH5mNN+5(z]PF ~ɮGIA*1c?Mܪ^T%(>+}ݱL㦽 G/.wpu%keF3 i;̆t+ǔoa=oIS%xJC;w FkG:).&uK%;&dEّLSvAez뿖VdXͿXn^U|KU2?<#.zpvTS!qyh ʁf+,]qQdo5KwEwϴ[) û& 8Ԇx)ڢdiDzV6EF)âϾ ЦX1sF T2žHR8I38{UWrB‰`CE;Pxh:,fɡp {˘Y>lEIc)7L,e3R>!̽DB|ȭ2ْ\XA-рB+Ҕ{?--Y;u#y?qrhcIa%'&q'wvt’<]J[f-L3fY3Rt늏.8JȈ%l)@NKQ6qyG-Φʏ7w$鹻7/ ~z}4 lLtβZCk|/a(J8>Y ƔczI`J}Ff1̊5ΐk Q³@bνI.VukCY(n.eqڶ@w?3GU& TzA#$: F`i6 :/NBX<5 r39Z)'Ї &kLihG3;( S8lc꠫[HUp耝`=cSA4AdB>AH?=C#I6p4Ūd'GDDT]]Bwיd?00շ icJ 9M>@(s4{IN]" i,TR"ՍZl=?~KPSb}V=_6Fy Q<۱A(n?WM߹zA"CX"'A:h{^e/(%R9yj4 Yk6`䨍M rvc{1(TEnmR,ʌֵDvlڲ9t`;YRT,4q-,T:>ӂcEx 2]ḔJum(8l_{x!'x$s*n5Դİ"> ##"_*w3.;("h@M&?xQR{mvYs *B5svAu:h*-Y{#;N;^+POQ˨$\D^ 4/oJY 6o#"(m lRg Z&#4 Zw^^uh΁޽ iA12Ufm SQO'fpoH}Bo&G”9ޯ& ] >ι>q f6k^$Rß #=xVͺD}=02L Rx0jJ ɺ5 2^m(=se].D|mc.z!T7hRYd_?# ^yǰmu(, \xj| o9,&l0M[|6Uv:>El)-=IDטR8*JW :K`0{Po~SG&3#ҞU):꧚],to sYˆ'=jt1L۴#LjTVwK/;\9I::vIv^ \7oy:W&}l-]6Faw?v9%ʡ]5R\Ӵ`KE<G,u҈;? :JmXD0s2?G]ˎł(}ɦ)fE֥s8 +(*^-axNW9o ZvcouSHHV ɶ^5^ghv(hR^$ ؍J/T FFsXz O@# j8.8bY*V9ucz }k~@c;(5p@"ޮؼwk BZxl(\<~}) XW;,cUIT4k} x"c+zgoLS"&-XpQ{-!{-t5MS) O-ŵ 7w!^aKK*v-BXlI-n;-)%Aڀ=1/1Yi9_M\$iB'd%$ - c JU⍎8+o4426ML,̢yvĀIhU ɫCU8*w͎Leïu;|Y>^IKԬ~xIH0;^f6;MT } 8E@4ƕ*T=[W_SSH:A8!6 {/@y_iI*k_#IMgUwOԔTNR 㖻ys-FAvudSOAϰ<|_ϮFGod/R-.8 3GQ oV-3?F\a?7/ueٷKV䢜<-%7Zd.Ec=@ry+I}Xc$|r lA\f43PP|5:jf1tO<:j ̽RiFI|M}3x4bcKwQĹ4&$t%ƠwuKO!xF?֬g畜$< H)8+sꄅX?gGl{UFXmЧ`~ f]=uӮ4ly =&4to/Ag=h%13(cL&Y2u|*cGB;Mה+P-#§x:@3bՃe"\Q%r & SGݙNMZyۺ >^6G['S5^N Lg2 mGx8Dz|vW+b :\v5lݰK~ؕ$5O9&K֪_"v .ܷW."u-] %VV;-!MPnXh!x`8.g|Y0$怕-!BӺ4G!3r߈`<=^Y`:o<7e Ըc̑+&]0_7-2Yx/ٮ 07v\@¤zQb|!$»GfGw=^Ip&\'FVSuVW.Q:^uC;T\2NӞH:tCkא)XsXv> 폔q>~WVsfc.`%#GCޗ\lF<TE0=RorJD} i3ժ"-bd#1fǾ~E2 X/ʦBo* ])Shq9"Jd$hzU=ӟ/ӆ?Wf9=(ߠ]B9'z"@LUgl "fȗp~ܠw\I-6cZjWQQ^y<"Oؼ* ͭQd-xC|sG? /m{,]3:*B6 eWǺ]DO|pa&k!.nf ђ (&ոۛѴb-KV\Ϊ,zzH#F܉v" 152}8^5\c4pRta6zCulF͟~2dm@H40ՎeΫj6231; Ɲ'e]>2h}_6I Ch2#Y(Kc+_XYKqد4!#6+|찖I$U}fˎhՇcy :cJ &f<]=˜XgO 5o90"  ::)E3\$Dn~}O\a8&VY>xe2`N輽7t`⬜uL~`* KyQeg_g?"?~'Ul/(@4aDGE@؆0bn}dWfߎp kxKW?.@wK)J}%rt8qBDW*) A_{i&tÜKxhܘz'RqJV `}dq)N\|?z񸰳ӏՉrkss9F]8LW jz)䄸xJXݖna\8vP$l]04եH;cŊ2=W (sr ='3\})4{02ͦ>0ٝɵm |?GnA2N a'P k\Y\0/tNss%>'wV |ᤧVVs-?Ň}1Aݝv)3]pr9R@ХPva ^13^3'I٘j))ףWpf;K`kF>LQѼJ):׺-(ӡWR;Q'k,Gjet2tg;נ˚q|K|GclيF @M=gEh{[bi{i/ʄGï]Y`e15L2sWjO&4H~|5ky^0\ Z؂ 1D}T'h \YRHf3] [AfWaդpo‘҉֍ 8H]9KkFelGL@5V9>?A/(w;Z9`-@*6'. `_ȽC^;#wV_ƶV˹mNsxCnfK _Yt! 9II[aH_0ƍ5a)'%} ][e *XM4;dk@-8ߎKdu)6~Ye@ ƵqmfJXc8!~zJ\i4y)z @IOaJMnވX *ɠ-zG9<ę{dn,făv)a%@lO WYЭ􌦼vUNb?|U/}Dj~p}.*U) v%$yѵ4w|ml]5ui`(f0[CSf{i{3~$+MF\}ȉ7-(Q=?:fJbb_N!~w=v~?C;9L:<&B|, djˌP~8:C5E16jͼ23$(9ucmӗkw:r6й?N(ItKOb?p iq#"ǎa*iDvZ > EѨHD^Z* ,Lqў„%g>=>ӍJ20'BH8D&0QePAJP2=Yi3%8C6Wp{hGw=?ZZu{^9نc 4l;Ttc؂%-pNw>%uLkt# b&hDo9Y#tЇ= #VS'ܛȧ=#V @nU]D ~H̡pVA1Ȃ+rSVOFZ"nq61آgEN *nZ #)\^lGRF8G-97 r3YMv{@Z@ .(;؜,Vul~{^_j0PuV(VWJ' HlT;I%cZܹWQ,޸oEyrރIs1ax\"O5S9E3@‘;$%+LDa@OcVTFCP]:\lr \Krk1g"my9x^}(lM$y6A_ հPjߘ[yĔmp 4 8[Mwg`?N I7QK >4ؽ*?[øe5d񯹾Y1J u SahZ9>'JӀ|ǰ{;զĊ*0IZpZbAg)+BCԩP >TȢ#W®JH2J?RONaħHG(` 7^$2vO‡oP wN!=U62x>.TL|h=qkdNTfFkLT&N sR<_l>5<α` I/2앙O 8M rq!zUg"\w)@K'(oD^yqesca;:UF>tO5f,] {dD&.[^i&]Ļ b:mIȄc1u b/N=+Yb '=EH(e,AdƿWLHx,un9kzg]Y=RN)E,@7E!%9/ "7dOh=Tm5?X l\9D\gW%Sknz>帱|CAۉȨBRf+!@obfi %]$n6`C=Z%=]P\ NG3=T|DtEIdfCBF+AQ$NK^*D1Ond)30*y-yH~gtt̂A0)v AMF1^ ̞M!$fSPg+ D/zI+m]?z j!-5dY*aUm 1|lP_FIp.*&X4+d,1^_2> I$?,*S݅B>PXIdSܡ$TU9<Pp8pMQ}탌)N.ZbRTN4[4[V=#>^'ğD7 l|8 gjlpu8U,apD$"[ww}uihyh yI)oݢ cBu[{df$i7դLvNqGY.NLy@,SV= 0eyGObN|Tk4 1p\S 黲e/=<B9ܡ^R={7f; *pOj ̥LguM_Zs*\ $/3G|0QHr$u|i49ֶ}&l$V:I'U!k 27b1)5vIz>2(B5gEX<"MuC/Qє6,?h!,LJ8aaʎ\22 1'}uԪ7 K;`G]LQ+h*,πA urҺ[[ڿ{xACS&Ҳ> h7t-UĴ6G!^ZQdPKGQ&A`F"P>s8/lXLf)B67ܹ_!BFܤx'Ri0x\PjsV`*{}c8WqiVrRcMGY{A[@ 2=LҔU W0\h1z4G\6Y`#!v< P?Þ~O%qӘί> /糘dp7m.HB#Z,]X?"U7D^ ل?ڋm3H ZFJ* B(u3p26}Yf˒3GA#'xryx"ZexaGݭFXӵɡ,1b#0O$ط+=pK>bE]*ֺ~m|M֐x Eg|e(5R K-ex ps!IXZ𶋄i&r?Ü6;5YS֋?Wur{Qva<8Nl2]oFryp<=DA2R`Jy`d_m]HpYj1MlwOTt,@ HqY'1k68+וּd HDNxZ[ŻLr&W\bS/hguڰpM[fc KDIlժŻ1~[wDc^o.QM G5)+\%f}31- -Q-De. nڕ)qi}-o ; 1JFq%;9rx8G艫ZFL[k`52mNlgߍRM9{b͈9:JA矍N-Ih[־_ωyjXDﯾ+p?+ .ё,GWD ]/l`d<aAM"CBcprYQeQ[!d?(d# 07B bAW Igϰ[)ޱJisIop&Mxd^`Kx6`QQ=lyR1FQ4As ުX=?6}`|P^ʊ2ZImd= m_uk V)e'fK[(:wޫv iیکdTx}߰KYIqxԁN MN#+pw})'{,Or@Uĭ4_.!Myiv>FwOJ舱eێ!~*>8#v7H:ocam V5vMҚ~9x{sdžhX" ! \>`xI8ʯ\'BoM -1)]zW}@v*-dp -=S_dDvxRlt4dدZ@s|r)t{6"h!ש43pۭ)+:\Нm=旬z2U`\(1dhCDMU|YXzvY bą3TKOQ<> M7B.jF*Y#r^U&'t)f*x $ fUh`Yi;۝d)Oa/[y63iT(v9]II~V.0mvt%ߝ*q5A[ōƮz痘u* +SV 1旆CH;x#f^)OWH0럊b#)o!P(\w3iXG6*=[k`?-dM\ܷ.]~R0ҖՆd xY3+"nWQL~{x[9sUJz*-%m'{m VA`|`e$B'>Hmuͺ d\89S$3d\W4@mg,;KFcdupArZ6j9`ҾҜQ5#QņSd!ѭG;ʄZzZXZI,,#&jO3-Ni}`i0?OX\7MF L^U" 2`9dz}%=DZ .`:K&wA 򾯃 _25|!:S17&*C:Opd&QH5/xKE n xd=Ż)ј)•%aė97s׳G/GD5@D SLJA ũ3zv@RL/4:?`Wm\TQ{ڈc3ʅmZ :,$9Ƨa>l̤jVW]z?yQle4FXd6 hRe+@ahkbI} ƨZsڍNa˚>ۅU!薻|z!-BazՕ^3.m+e؄KD!Yǧ Gۆ+/y5O]I<sHF=⿇,#3tW8G$~h;ogẇ N!?\) 6]mŃd.96|sUn 8Z3:)=GzS0gMx%cQ -gp ;Ž0@̳%qh4.[d!Q+씗$?z\1QاS?ĎuȄ ` 8^PuB-!NnzIҫV$QcC3e*PvZ|Fl}=8ukFbN'oA&r8 "呈 pHЛ@)S.TJ7h ^RVɭFtUow+.fbz Ķ3~lt`}zMj$ 89o|ɈKH֯OE{ݧ4h~]21=Wq}[\m k(>U+HeCO4{vfٵ߶fbYϗIHHm)!޲/}`3'1j/},y3^W رٺt-ǢG1umL *\mZe\6h}>_># W:w(] HOm |{C&8<TPnT[@}Q72cg68 b)hGOCvsK-7Dn³I6k#y6%|V|buAR:5n[c_ەgUtn2U#f/.͢s,/ (-v|u+X3[*n)1VZ ,r4OVq#Bp VE{ppY,=Gtj"h= g?!5{{d؛uAJi9{Iٔ@qP%Z_7}Q ?ʵ.qp4Ta kbvsDhF*"g; Z8bx}iFD‡tAb@݀ z+3ɖDﯾa1-WCLOmb.t:\|Vj̡?ݼإ/So5ht`ݘ%ǰg{nD~O[u $=B)bl3G.*a&9 eMl,TM28[쾳o .U{HtV+!,;XC"&eR\0I*Eo৓v3|; pn.Jm!LYA+v**<'=Nw_ttux#FG)\N4!}q"P8McZeB4j)Z)USJ *ۨ3:/`X D.if6`3^h!$qRvLL΀ctu!)7׏}6bWJfPܛ}LMU#D*L8 خ"]]98!T/ڎR t r\2⇥ȓK$lyͼX;䰪@]LWr8=E%Ѥ Hc)k(k\e/dL"1;ס^k +Bp_uw 5:|Vbquz$XVe>:Bw+W{$BYorrrA.cTQ'>| ||=еA Q6 oA;ř 3L1Kb1$&o.۾C/gvHUwDSg|FДODgPU|w[&[P?-=]a1&!]NsM-v'QRwW&=tC٨Z\ zSחތǹ\R0!zDL/ЬFGn(R@0Y\k!#iXOs@ak:=C|z1 em7Czi;,Ieg '>TDٶq1hNty%>dq7ύWbhƀ,;d8l$ŭ]:O7wN _BVRV(,9φsj\\rb=9}3V9(LtPgE igQAއdd1[I6T c}"4"@337eU~ d^ lOƆ\iɨTM8;fj55v=ղS-|c| yuOIU>%O¡!V:k,xښX1EL< Wcu-4Oix-cBj0dmOc,3`_\[Ni=1ӄx$Lǟ64\iڑ;l)U/!J=^ w@[Y, re:LrVtO)jHgxK0ے&SE|<^ }6 F}+xpH +% zljLFBbx\և>(*4`Lvex/)^걹cS22m=x͆#LZ%Kybl4 ٽ2Cg=7I÷LftBuHz|^ ;&a"/̥3HFBs*D[G3:MoYz϶r:xt[v8^ᦚbEa6@u-آ.!t=H 㾥Bh9tۄ쇇(NF+6;tc~9|yߏqTAb3sR;Vx4'"/3D^=Cc"IsC*.K>Q]uDR'+g^[(( &# >ǸE}LF~,سe;I rεOFBxofQ|;́0A{"ʁm2@&Py vyZ+ffx#fX%rpJȓ%frInyߜIϓŻInQ9`8+Z 2O)lrAoڢM.q\A/B}.xEZZW"Q>طlfb56.^@Χk: BNf?D5ld>١b 8iTÎ +FC1# =jcKbYLn*5K+: < I+H'",F֒sd7e +)ER܅!GeJFmfJRۗEִ#9 K0xMޱUg]CXLOFN'Mb[@@Z i0 v8z Eɠ>FWnUhy14[T8\\O{M0IK m1&d .1//-&lC6 g#Po= ZOi'~"l^3[]HjD 96l(pZ{ނiǸZar`0;;a m=%qtEGJ决6{Xe˺N䲛Xr'/Nj j"8/+V dy鷎Y(ٜң*!boY|Yu+]& g Ӌ-堾6L(vކYj>'3ӟ|&곸{jRT7"H[V&ej[2vb^Ԃ̂Hpji^7ǔ6$ƨ;ݬ+&ȰL0b~**=޲&;$Ef:. BF8~ߎt_5c\+U,SjA\X$. 7[K`cj7~Mj/ ck nN8̝hwmɥR$m],u$HIF~P6_ܞ1quu1ztd%O PNY$u.Nq8?GB34 8L0fer&QuUx^'r;W4;(!iAVO93ϤhԘĎihbO}@'56tf,2SIXNV:zSuY "QZvYrNUQTD(luzkY:d%ZuxF䓩ܮz({=_F8P{4a֙EzՉ /\;|.sixߞ h9sjM{ZqGj'Vd9M/PF95EZw^HVl@INW,|p8V\8qizCklx.{,"`CL=EM|ٌιǪ~ݏ(:XNV=×ʁnb L5aLbr=wC[ 6k x߻ь A^2_Q?jnϒU79PzHV|aijϲ833?'blPr36n O"i"]7 0+.8 XjMGtgZɽ4 2\}2HR29u&ܮ#w8:+ }~ C#aGsQb˜h{9}|ił)0ƌ^@6: ٱjK&\W.Y M2!T8ACwLU0v;m,>mo=!]qJ`:Ś.TFJD:( R #>V, eIx߅3FiɵL~S9[?~MC*4yy[O7GS48•T\w m(C%\|&խ"'j=tBKӄiD^܍bDfȩnY^s=XS\fF#Om9(jvud5mBg'ewC<C=p8pD xԫaļ9 ua4D[4x*ՎW(U76G7B2]3_V*#"V>o+aV ,sF-/_#7'\/Ӣ[EY,FA1F /3Ńؽ҂5:Ze&"z$*˕:oMj-s7ɍsr&\j-!<ł?Tfo?$ULdc*{ ty}k \uQ^?V2.0y;n,ak";ǣ$s{O; Cg>Ya=4 6kDE {B%c\(okѤ̷/.X x' 9\y-qT`H Fwab<O'V y7"_0FEP^ $Ѭ)) o124 ~G؁:9 (+j.!eq W`*(Z7jpA|Tm7YP6ΰ3FѾ~R1&VZT𚱁$P0&]qOwg ``Ox 4p,ǔ TI$f78\rbu:u$V:5"w Vi7tb| &;A".W&T%0GPCu}2,SIHt=4꣞t) jɱ^H{V%_ZRe+/j(E ĢnXw6?8/6lX?fx$<%  ˭ /:ɏ'Yو9^ٓ}9}e9zϓ*<3]@P3S濚{ u ik8'*f!z<Ë77?| nS1D.(8L$Z^m;Ѡo dP-9F%q{7q:;B s҄ZA-v d2"NohB˰nי؍8+#NddÎG \ھ*a2Ja5C -ug~WNFōܗ"Eg5B]-CRb8RB'˦aXodxX*JkͽLq-V{Q S!*+Fo>n_ S^z]Jd0:raFS,F<,Y\lQMp=|AW= 1iNBإ^ Ǟ? ҚNR\K ء*9A5;lϳW2oZ5")8ӽ9_k[ѝ)0Goo,&XEFi';Ry]VrD%O^nq:dfU]~9RzH_qJ^KĠ<5Ѝ"qKQsk^ FN6Zh\޻T9cb0FRgM قOsyɗ85ٺWح~-0#ɱhT2fv}2L<1#c*4%0B#S].*ő1bsTs_䀰W,#S`/EFX茹q\:޳+6NBLLg*c5fYV'h"^lSn*%U< &̚s+ 遻)A};dx I,D{ 'ϡN ԉ[UõDP!VBxS~ iɷz$e1 DńqiIM^,c2>R ZAtLr ((D]䞉 EH{y+wn?D-/PTtVPXE`N!G2q,e V^~"dG:mf 6,8\B\X: ?t8{0BW-> ^R&` Z 4|ַM=-]?!?жuqg,R$uA"Y=ͳ>rYai Nx:ΐbz]ƴ~JjnwJ6N [vr;V5aeo>Dc[6ia?Bc4 "bK(o^V2RQy=:s|jGꪍH^AxDJ}1V[ژ\ @M4v+UFw6Đ5JMY]zYN^)dK"hb 4pq6As٘Q8҈&r 0Ĝ[yh|+J FXOSy._PqͱW6n_9s7H.0Ivc@Rq!|pTxrXL@**lwXlb gQ 8 -O.'*$dl\ZhKPFe 䶭\])J8ks~gҷ {ޜg:Z8M?x_U,YT2dI7P}? RK]SEyh 3Ф+n9DI ]G&Xl$i yRb&?`u4X!V3PPߏDCG&+K]JY0h ԚC8zv6>-%s -38ƓM D$)Chq,&P;cQAvNyk$"rSjt /$TK".f6)V hbl=.*hC|eB VXd(eن u(E]laK@wd&bQJdfc1>" 4("rD)}xpp>(ugڬS[56ɉEL!  XOX ۧ쏥jh(XNhDСQ U%XkET U*>1KE+/mu$D$\|Ӫ upľi%p 3+0 hDqQw/}q^lyJuerẄ!KEA9uG\ B7Hf{Aj;[vQ3ޝLawbN/H ƜN]zOT*߯=Dk8|!QL .Byaޏ^D|Ўk>GE/]\ٵF>{OzcZg mt?OCfN G>ro=>+HwbQ8KMT0unqkyjRvSݿHQ2HBI a=aZj'Vv3V3qXn$y]!ϽeZW?c1Jv:WBhkh.!~qaq^mSkCN|~XEiW'|~.waKP|vdW {A(BWmoeFbD@/k UoF*P*DPd0 G|4u^x~\ި-{!;$kd]n:OW0C|qsus n0ZdR a;<8Ho={f7KZl {ՆEnuc.LIuR+LԑrRr7 NKTURWTWQ?Nq Q n:,tf/Sm%@W߷?N;KVuWd Z٠z1N!ySb F@ |PЧVLߩr ݓYIl*S՗ZicM٧DMW N?lEս~i ,"{ k)Ln,F.#Y*$8dOFڊ˜ 8#["9Z峲PS`M3$>iIX0ۣB^լxreBt'o{(DUhti2aPU^d*djD/n&βsiY$ YL>cc;aQKmJՒe%{cƣϭYL Dw?et~fY\-DrD/y CwK]N' } p%moRa:ĶEQsȔΠ#ߍJ% [s"R J *}V]\n׹F;菤59yc}g=I&\ Nǀ OH'XTpWWޓ(H7ܿ%:1Y=W,BMvwd1 nԏ .ġ 5}e󻅻FNkۗgSU(JdPȭ$ ~-%f:ldl;Rш*Θ0n#BͶhTo>jT5>%?փRg %`˧k3[[2= !o [^ Q =GkVFYS5xB P>X~K9Wxvэ]Xj ^)?~v B%SWDƥ;9%ÝF"f\ ʑU>l\ Pcf.(lKV"Ol5̔.nI)=HKmDw#Q"v[E=},G /@&C75ZI ڸ)lϗ\ph(Qw賱z zwʭj5RjIi'.b3?gYTMu%uk2\/3sw;Y7z+ȸ5XC3llC T0Ϻ@JE S{Lqcl򳵆%Q (8irvKɬ~fF|&Z'i o8l7'ւ٩Xi4QmD_IAR1(r,N(™=lI Q:vy,AЁ՛1 !m1r C2dH5 }QQAzˆωjƗMe?2 a.VW[Fגصut0'1 :QDr3 tS?H[ 77pU 8ӫ?($X2oШmTJIZ\~8 }#. ˈAH,by"FYه#޺CGhQįE FfH= z2NA1HE(i0D9ה{p,(] *S>DKh۲5ηVFgr?gãد r&V@9qaRI=hI=xְ%d.;f ~kk#Dt(# $)8B(2kkY0]ࢌ Q<қ a'ō_1A>DE*?2c*f=vQiIA{lᅏJg9Zqx Å &,|In]P]kaJ{Zx"ꉡyxO>;8xhݔǨ}4;?YnE]n]U:c\`FPbv1xYs2`HؤuKv/W=!Jhah1K.#K&"[0kd'7\j`Y5G&DO9]͑Pj-oa" Yqr.n vÈ-`9_P=p!e[L'3dbړ'w%0h냅?z7z) UZH'!pȋ݂MpP jɂw8 Luԥ_ ~x,ҒKI^_8uNj:T0șLZY]Tsr6f$FAYҍLIc<׈2lpGĎ~%Sx9$G6s `68]V +1=նCݣD5LS$dJ|o受`*4mҥCKR +s}~ D[|_m_!g?Lҫ5ئ;u48@DƘBBga5  F~8XjJ1I>lc.VN>d+D/ߗt{PݲH0<:P8lZKdfoKVW鲾o"&J-P+;aC7(oSyAjݏIi}Vcp.fЋ<9FCE&&Q-5/Y|z@lINR[.jyF5M[Tla:崠 TwUuo9@xiz cbR+3' rC%gSDl"7"K ZiQ>l4SGϻ n7L5JS}s)E+8_0h,2r2ke׹PG]#kA)INaTa1#dNȌ$'/翱x%fNuW>W>&Z&  -~,Na_ޏt uv^\[6yP֕ݻ/IWBgZeN:6@,Yv @߯"(!75Zp i]L}_ +>.y1<0U! P:02AҌ=3 h) U]4sZT.$I72 sWEîA ډ_i4ƛ0}.ޙAH\!N7O蜙쯮Z.ş yNY &0jnl,QNA}5u`RԘs ڊ HVˇ%d|R蘳MȦ N~~w#b\r{)+/nK@t 1q*^ s au$MM7{omƼzWh9DxB_h|ks,~/eCq7VMicX\%5*~mE' ٠yJs[pEDw^Ŷ|T5i_퉱%GyWDk03+zjuuU5^L bt_.ԻsLL]poh#b|one\hρ u+ԺێE,4߽=+S9#ӫ@"W#&; 5$;9(,@d|,YB5nN4۾a [LpFsmH/wWAb\&˂Eh@KMoZm:\6YatΧR!SA!#z=\ uZ"iIODLZ8k=Y`&a“ {^;5" 7zPi;E-Ȝd0QG-[QUvVEt@C2MKir ):bV@taGmn ,2;fn*R0 }*%i%%HNY46~]zi/ˠ+e mt/u,XUU&P?jFr<82ؠUKv/Dd騁-& tIr譫h ?yXl;AJmgac)ȅQ0/W@8{SڝFMD,g\HY 2l~PCYWTa8Xu*h)^o#+E,>'T+ՁXIz4LVsb! }'q"K@4pT?"N@dd#cJn@䊡7 ҺNck8D'0J4.[k- ja+8Q؉4J)I#F0wtr  Ws^'Y3/{02vf:}`+;`/(xzmj$ҳSa"% :y&[UQR /re2耱 (؝wIP@5Ss5l4s.W }):,:K y=njQ9Lb^[qȑ ӷeςr N8Cj]- FlO&]MZ6FF%Ľ#xJ!4drP̕4y5׉'ZeRVHzJ@}/H7рw>47&ӣigQ!ܭ )ab۪os,y,v1b#^-5ͫ#yrr=%dQ>J ,=TڭY4+16ϫt oDuTE+L&ҞBq$ҭ/TI64x:vu9: Ihe(Wc4ܠ?|ɆBQ_lɆd{ -yhd'^3Rw/ݳ_GZ5|Ů/q1Şcբ ,G?G˕tejDŰCO?r;/mzZ'61hҳ(zT9$f됼AI#,ٷDLd[9WVQuJ66N:/3R9Ihi- "Qͯ\QyT$/qKy@rsp޸f ÛXhXpT2F9ڽP eNW)~ ^\KB~6U{:kLKB+zW />ԵtcW%5nh 5J30-KINMi~xV8.{]aFw.> t&o TL [[zSg Ayǁvo\jno6nh} "TԖI³dDF)ܷc6Q( 'PaZܿ\?8,C$,(QXSR aÜ*Xu8f x$H[3?1. FI4>z`vAn|o.F%f @2$t9"x>o ږaC" BeK+tX:aO=:q +e.+[ƺLHb=숟^0oOJm$*qA|c 7>iHTC_a|!'ձ*qKב|6{Xky˷L&1CM;; \ԴM/"!u"qLG(;V+K^/oN5-f&!E3ԘlLi$ 3+ʼnQ'7;)U\wGN0cgA`tGF!NkA,)/(nㅹ0Sn 'Ա[$أ$z6I,(^iv]øQi)l{DC Gd.t$=B~C5 7Xu6P+4IYNJ6 Y,ML\@J:3+V 5YcQk' !&p c%o M+[=ukD nwZtX]J9U~6xdjۤמ("g%>Zzz&7de#Wpd-˯}36XRmTV1E'Λ!^cBUko-vK\Dd`ָ ֿT=Je{J} ʳ爜 CvTά/}[Ihc_?4ri_ɁBg+҃}JҾn?o. J mק^c>6wλwUoKܗ7l5 F0IX JA;P;Uf+%_¹!m;SHTg.e&Ydyn?Y|X>0~ ":pY֕PVbcO^eWvv>}+~u{\$ 3YDiX T9֋3y>`= L7+r@æ#Yt儥kM7{'vzY|0D@sM^,W릜]!? kZ*O2݃Ĩgm3% ?'&ۊn/d wҝRRw1N15VgKعrŵ{dнTq ,Ee ;p&epm)^?S`Zf;[\P*F7UiKr\ GdQ5>'1't_OR!M`-r-nVpza`Û)z&̌;B :xZeΕ5^be}uL/j,P+zm=H T\r׮/~SibgoUEo;{&HmvS)-,f4b9}'A6Pov az= +sү[j_#˿\5ه,m@/VGFz/U{|阵{g0 OE}ﲺ)O;I1Г[.:_YqyM(x'ʰ׼rڀ&a<@BZie/%U![ M|/%as6PIF_dQٽ-G@jƣƝ!NuRC8>;{9EK(dହJxXp/!w$nX* `CQ"rHjDXXD*tFMfcR5 8r!ѐX))[UZQliՇ ϗ6Kunw {ݵVpņ8C,fP`]6mS T6Dj݀}rA2{ Q {M; f͠l eOMLBiMNajn'V8ZXڪ/8"[MAp>MIG\LxҿVkGL]iMszv,##ib tۦNzۺ׮ t72;nYtXM9VOOk*Aϗ{wDTl~"c=Mr] O4rğVe{&=df6rDBeV"Z @kWQ,vp>0ci:x3e}9+#.-/r2:m .]:|+)/:=So W`..jc:x {b$5s&# OcMb0\?Z"]~!L EB">{ab vh;I3pII~N=IŜj|$ ŐjDYt rṘB}r@0Uؐ{ #w ǽ2{؃{j2yZc Ӈknp>MBB }}eP4L338H/#wS ?~O@˝O EqsU#I5-$t 920-ѝWǛ;z|\7͙3+Ypl n'͞I+&pezeC = 6\ .fz1D |" _e,IV5*Fr׆[j%F{NaFT?H>&Bm9jGa̼6hxE?-,ʐgi bX1{?Ő~>F}]jpa=XzU"J,*t(!Ti3_>A\B .o4^CQ!E|YS&I̋TVˆ`TCloPiy6z}ctR5"؆RՄ&07R[8&cJW4L\:쟼 R vSr"+\yJ 7=Xg*5}~BKF&ɄrmYa8 Lo0&&ze -C˂2k~JwbQ*('062 [~5ʇqb4ga$Ú4c0?]lGcœYU1,aa(.ځV@kfZ*˶T/}TxRsP2[BJ/۩'(I+ ֫,Bs'4a4`*j.B@^2\yd KHFź(2bڦ d/jcϵdD/%AySrP$@M-"_'3/q`=J_\W8Rϱ@D[ vEhO@)F@LX1$NT3j/Ne`>,vR0RCs FL,^\k*d :bVT` ,ZdKRZ؁uBg=ǵ!z˨i/NۘCވMJٖt|Q:v˦`}<Y|2Y_ "7I ý]<lC*n<ڑx+Ih]Q[YoOts).ba*hs&2fAU*& q@uadRS8k\ңL54cvS2>Иz\( <;8 2FH1OF*XVV< ـvS0-g4 -JH=n{0(}ʑc~UzT3…WK-]kcobjx9It<a+$ ^2ZE=CT\6[P.@ETlHC6*FUu_cAiXcV+T+7ۛ:Qy7:x$(z;nm$6.K+ˌ]& #Yp1B[ޟ?#C9Ğ8Dq*x6D[m5 ? ckgi[ .$}iU>O4he!8$4CX`+A j_A'AϬ|uЦ̝îQ- pSSO,kDZM dLb_S$@MBek~g mޗSuI+5AR v\'3oR3`AQb}5HKr,@"Mlc߭d>G;G/…GeHa4~i+.b+'=k bb5\3H~(,Ұ$eזns%V[͒qG *1YI)Q$rwފ<ĻPJWGkF\4Es} @hfs$VB\=%] ɏzI9S?C5ZK&Uj)!dK#ܖ@0d#q:6+k #LB&"?mx*k^OG' ͙n.Gk r \+{ AiZ RU "P1/VWfWH1EAx,BiL*<:WFA]@ԅ:m5Fz { 5qp1$=5n/v3hD4PKsRISǍևv0Y6K]ZmؙFnKoFdl@u[&K2*W?CX\Q?Ck 7xN4+XVn,Wn j"z . #84H/كRlxvcLq pdQC; r lWѰW;ڌ#peQjuoS1:D9oeCǖ6Mj:shʯmE GAVx ̹f7gf!19GL7Zҗ|1u29(uJq w;(̈J7oﭲfOG0#~]Rukѥ߽הsЈQ(kUL%X]B%Erc  /m+ô];Pa4J AF/N_ ՙ & K6.H].wn5LqWĘ ӞZړi`f' P`Wil}CEs+ިxG5|KT0LZE~o|m87KKCaS%f@yp˫(}dIZV\Ɣ]w٨@џjD$ .ԏɂSg~UWQӅq/זNwasD-ݢ|GXd\;e̤E 'm\]mʖݯG$D\+OR< .2F7V<.BHTŠ^:'<߃K#LN*,`27&u?^eOb|NnL2z~"@Ga,oLٍ iϩܫ`o<_m_;ߑt_"b 9x RuhDG h)=.4eLֱӖ!v7ұ>!xEwqC /\>l uQmLoՑq:Dns=(:2F7ЍW| A}(q$d,&6A%ĵBWij7&źM+7EG"kMV_#Z :v#ju P1{@(zu94_7r< /*Ԭ0ݲw 9.̚2sV 䈷5Çl(1W|Oz sPaގ-ݑQFe8Z_ Wΐxi)0KLF@#,UZ/iZbߌ7/bG|x>?(V&7cYO=zu]u'(m+^K;`߬JFkq`MVO Q BB([M)+ӝg;sUs[BUW9ir3[r--̧4KH[\"%fLЍP-3z柢^y qOMge8Q/ecӔ)10ro]o"V(?F1KA3q&A UOAaXߒ%wA9~yܞ  ;j4!a@~rϋFx]5M6-h*ɥе\xc2ƿ"R7 vؼ:5v|6$찄fi^wdһ eh"I1 4oοqr/T5zOD:%]ImUhӺ:Eaŝs8$u{\u|_, H9=־+-'kA󯶥G*pmKs1F3X'D{ܠ;nF,67+tʩcMХ .vtS*(+COfqfIɋ$(UH7vD޺7Smbdsn(*ZwWYgE+"2ئAN||}P/+%8iSx CXް ;zxOp Šv./ޡoKlgN虪$69"}B7]#eEie7aSD?,f;Z T޶Xۣ݁=K_щ :Q}٭7T)u"&4:e߶*tѦ]_jԀCQtK5&iuג@Qj> BN\oPS~ jw;E. րĥL)TPCBhYac5M?u,Ĩ *dg45ogL }>rW!f/9~e[(O>R&ѰR@ΚRA U?Tb^L9kwbqO .V ȣv4M;A˷|p/7ܧj>35zQmy/GV"t쾥_9Z$yMB*$UU辢;5U,nRd<rFgR/rY綪ټ~{"h(/ϗvf<$Њ:1bMήqff^x1-=ETWQg#  OL< y54M e'ƇŐgg=T hS0r@pl/G mE8ˍ*1Wŷ6pA|(AC3=| YpK>!kiTL;h,?cթYJՕr鈁UAlOr_iI>^ o8u6;ڌz8XkR<5 PϾ 8svw A+Gv)<>uioœ5?6sК~k/g{,ui?`g_&\>a:YɅ me;>$H,;>30c> >VX+Qsh"7AKgL&sz1,=BRnQ*|G$e֑([% e.8ݏ(Ƃ2>fIB.̴rd6Fb  ?=ݐhuI_n;#^v; 6J""{mΕ~j!s9GmO^X'yn恆g -b觹0`c-ZջbD}^1dJ ҇/fyD*+ ^bso`h>.Il})ܪHq&}sUǤ aXJ>"Ԭ>d AP)3|D-?k tE֪e1$G|X@}~pL5'/rrΉϦK#u&a%<ѿY7oKg9NbY5b19 X׽yRA41"hUQd$ ^6tU섩s-ֶn ڴih2~nV|M ůB)6X!C~դ!:ԇ0H; N^@ڦ9J,31XI{ngz5s%zz&nb4ϸ[- kPJ>: pcOm >9'j+9''h.- ]UڑZ,.7mKU׋8kc4u(Bc ~>}I%Yce`f#yk|CJHRĵ:ڋPA!m 1mb2dV{g,z4A\-5&`Heby34VK:20bGJJnq\64!Qdoef2?Ǵ*vvd?Lmy`yHSJhF7ˆ<_; V{✹/]I2TDVriSB<ٙG2{s#\)wd 0u2#M! 攁Qrd e6|R7ǕհsU_3gNB[c,7Wz_B 9yrПmL&R5=Z6@-JGj?XXJB`ޢ_n);Ǧee=Gjh-zcOe5џ"TRecAtxd\ZF0S'HK~& 1ͪS.B]L\IY=c*ƀ^jGSӬkhr2A1-K?Y`gh}4[D O!kHzXy?keݕĕ(xIƥ_-(55)\hw\6yȺ!X|3i tȗ*b?֮9egw&,ϒsĆ97 o}a5.QxRk_dc?%r[@VzyxZhp7kKκʙ(ٞ&j~Sh*2$B\^oLe"Dan?~`CyNv7O)\"ѱ XaAA^uP}Yu1xsTI/mdm@ʗx=jS!rHUFak\@|f}؉5ӻ`~K0QGRaMlt/C{G.~po0Sc:*z8oܰ>8Xt+Vgݼ-5SJ)( Y&I1fM{kYtjR!f)V) !u3f5+Oi"0"Kh]W 9Ȕ|QZ:7݁l AW\(U WCd[5&v62ĵEw:@CSz̽U 3b^17W{-W)>D]v?)dY6Lǣ3ĕIO؛e:b'Q,pV~xBR X q {,9kcv)ͳ pOF'A}Xĥ}.H.iQmdoт0 ]@0tÌdxv*gw̉BJ$kk$cd;M*t  灰k?nKjBoWˀzncrNDlg2hcw~7"d9D0 m9QcCͰ:7h*O$`c䓨@o@N"Қ$JDžKthk/nh}(X=_p5R/8UX} 9o*fzL*;+3~|wHFޛ~V3(gC:h ̀C 虜 7vX2*b-UhU 6ʖ/nvB.ښql*^ GD\&Vs'hP+!-IKoT뚀 Z_%r^/.HЗD6ʕVAzLi*SK1P5.5!0x4ݖhWAk (bcRe+㻆9vggr2=H'[^Y5lj)LR&hg}>ҝ')Vr9# u76 QҡZ-(P`p+LRܼmH+Q˩*օM{= "ff3Bp(F}/ޯo? a s|Z (4nP%^@|]ҾI8KU՛ ae%at2?Oh2|ndLe| Apuq-Vy(]n%`5 _=?aHD0]j@M`#y~ϙ"G'@\dN:*+井dB^:ה5{^r "D;'zH\m OϓκT\#_W岖ʬ$aCSx@m )7PF6Le}eآׄjpv w@QۯᇂtS)Jj78DͶ`uX)N,'9^pp? NRl 1'XWȨ=*BrD6߯fߖ&RFkuڪ5S`fVox1Oʘx^DU,}Xe盃ks2!W kJ;?vSǝ 4Qu~xI#Fa 8x D8"8@N}7q; Jv /SktZc` hIC/_pOc23ȥbw{>8Ƀ` +N!b"!Q?(7DpaP'rUf; $a ĹL;efΎQK#OxNфhN&Ʋ&.kDzxXA; #7],HLTɞ\t />1`$Ka"#hcC۱z_}dpL,Q8%H^^|eRfQYcя/ k4 •>ʵŸY FvͽNHVbw$~ĿG2kn!;!y3(}G!01zt6İO;űae atY<&z V"Y}v7E@q^sU?+>\ZJOt-Pyht8` hW =D@>S0Hrait]r󹲫lcE`ӝ=wXpM:)veAAņc^vh,4`Ug~4}u_XX妞ʓ:fK--JɕH_l_TP 9dL}ExjџE4 h'p.#غܿx tX>Fֻ$a"HʅBF<,\D!vb !v'gIcQWMsfB~/SD&*0[M?g"t֕OoelBXS@0,IVk ~^1_aC4׊(--\)5w+'QH- ?+'u.z\\k7oOazWxʡ68˻ΡP#ZL=E#Ui`# / ̃ 3sp!AD ,*>]"QĞ:T$8p*aMglUv 'OB?iWFGf0* `m`xH-x|*%7WE^oÔR#O5 p(K/=甹EiSx)v Ua]?߈auOClP xte* '_43a˒_>^.$~H= %:;Nh$Ql sYWmvl#0OM[{ElZUQ| R*;K[&yMHF&_U`xk`͇׏*G@g>=y7O{7Ł1&;x l[3,8MJCc(Y+eHķ&3{Wik]#7æ=[ŭTAkߣ5!S¥ {G3B |޵Fs7D%+2T*{# {QF?kIj_TEfsJσchB Iq\ b|еPHQñ Մq6X/]B{N$[ׇV;XDzmUu:9--MInӄ#f(r}`r%J*̮BwJb Q3e.r+ iaa|[ Gy73"E6yJɵATpR̔'q\V=u!` ầ2 IǬeAy'vP(zFqPӜfp98$C#A;>tFLqsIJ̉}&Rko`As5Mqs#gE/]}G"F 7z<$i1wAKG%Q SB`+P2Yzc|J&^PF뽔Ƒ'(jXV\ ]=+CR<B c吘()y@c!tؒMD)#l=p'NBb.8s:Weɥy[t{Xʽ;LOE/eLAͩ'fq Xqb !pr8ff]~D+2fi˪b 3U ^^VzjP1lߋ[K'M U$;LZxhAy۸ (}-I2'~憜DgɌ Nl/lyciq([B!+kpGxK3}걱/_FËrVlmLFt~@-ul‹xTr.Ptj,>z[qj7W3l?֯; _t f8ܱ[';/=B=O|BZjq4s*Mպ{Y^+32GV VϨǷk/6G7 6E,HY`Ey@D⸚8zC]*]# Bܒ 06 yZCqiv02=x,r[I'mLX ~A\+0fcg)6p,Z.\HQ{tԓ?뻧&MY(lGSu4C &'jV0f K =Zpy$Zj`kҖ"EMͲ*B߯9ob?~E߆0US (Pƚf3Ue)+eU [ˇ5JFvUk>΃MKP8 BLWa)]#τ2gP]GE>HDycLiPJ}S6.WG=ymXv2;ʩ/d.NMꄶnVj<11r wsIx^KZF`mn::)}w7q\hLC7XV+8Q0-;"{EsAa&c٤dȆ1*DG0n.^y&nXA,PE8`P83=94iy/GAy٘M[ˈڹRc4ge+}۱G雸[hcɼoZKjȥ 1\!4Mc`o7)~},S ̹ ,5:W6Üz7c:B]!  gKvZ85ܞ:Q zK۫1H}JՄ]r>۞CY|5| A$Ա\z\ pTȏ:ƍil/KpH3+YWHcAy<\}/MKy谵q@ڨKˇwGWR`f (/@œ(ש6@7 [EcWt8R%0sNYH-{!n"K{#%3ԚVtcK?qȆ[3)_%Ha{HP\2:֎1Ҭ>VOni3'ʷA`#=]ŁBz'$G5D6͚ 5Lmz7vCJ#JJ7jf(8KQ&ON첔aɘf,؍qrc`]ӧnJ \Ωʿ)7/RZJ `Gat{cTqfǭo " @<_C<'~ـHU M_߫o%-[z_u0m^ Dk*"B9 JZgΔ P/Mǯ4C"2=TLL⹁4sì _Ul}*ȚX=ljOM|3Cs˛}`"l4]eo?R #-\"8jŢ'q˦ߕ+S|W53P hzӧeMF 8SZk jHKH- HM$X~DɁbexCe7 vM7&uv1|-2;ΫަXK#tc=יIH*G;rB(qJ5/$|yD$Ķ9i"g%gZؕNr󔫒I=AwR`#)?}dU9xFlӳiQӬ,6g8 `z=6S+?sܷagcd ^~;*_+k@=.8 j<$_hIXy\/^>9kP,uOp~pɂqۡA3 Ƨo]*co@*}Ơ % uD`l >Dߚal|8L܎Kql)W|xh;L(jߙ3H 7}YG' l&f U \DlQZ]jRz|.&c-3~1ll 9_q+gfYb$stɊ?ap&;pk|o hNX23fon1p̩YRu62Ӳ8EWv&8Q.R!Q.©^JmNڒEZnf"8c"DKt!$oUh=DAͻvs ۈN oVHYQAd4VT~(˜IݕNMupTޓ8kkaV'Uv7c9p_d etݯ߰`i]m^k:?,!#C*C*xeC/YMQl9u7`3( 8SmToZ)mSX4[[3xqͱչS^MWVA*oTޟn9\=[zH_ϡs[$N s\Ġ[eҡmB 7f<vb12GO$ ʱcO6*NY#{ y0=g\MkkI8r6p?/=ИNE9 m,4Y@]_r5O3/ ?DXBwmxߌyd`~Mvuzu0]ORsbc ت@?.p1~, zI->D3Ъ&TvKbELW6aB" Ƕ0+{mcq]ߏ6&HW,x`:Bo~Xӣ.Za~1璐ӊ駞f*79xRڠ(vӣ0(zr0Q{z$/̟}$wL2 +RP|0vz}5ȇX[Lq9ʡ(s29ν<=)h&9itnJ XZK‹Xoק7Ť=$=+ ^I6X|C;k1\}@4(숞.|dPH5/;Xq xa )`W|YkqNGץ(86<9qvY޺/wہSMc+}&$B(} ~rRWK>l\i  {}4%'V0~}͐:o1U:j_.+ft]L*IT o#̧Y_vLʧLVw'C'3}d\~dr"s3BtV[](֯'SUgy{0@Hca8:̦ mщרϑL4F`%{|*pOyȯ+c8gňؽ^4\$2~#fo]pQ^~SFw lQhK|{j=Vu*kӏ4ǃY-rLh$5^&=x 4>QJۈƼ̍,Ʉ  k5buAo//wΤ%sF&2񝹘SԠX G#wiqr7ߌ37'wX7>7^bߦ藕]g_/R-An eOb/{^'_H.-d Nvnk0XAt42: (s LT-l홴d(#5+3@$okp.1H@Y;z Up/oRP>I٨^ 0b<,2Z([]cs=&b&1G@h@ϰ\?N(f>l_uxh^Kx7XL; ̀p<-hM֎wUDt~*TqKge>F( i91$ϖ&\N%to6SVs6Bygkt* @-p`AdN|̖e"] _xz䣲8xŀN=13 ' _Pޥt &<h)  ̩ܺC˹"IKpI\Mh0o>[m2SbRuy7p$[}et_%B 4R!!,z V7_m2PI* \6x[*M1%&b[*थE{%CoAY:â]cQ et:I א,#H 9* %(9'T$&a mX{vѭoH8Ę}$~,u9^)Ϡ,23/n( ~;ڨ󂴈JO_K?ubGu <?=2=*\9k1 RZVUzoxI7iKSxIy2c"ءMgn`Q;/ QKW<XԂǹ1/„ x HM*jO;ŜHp!sHrŌԠpprգ^S\K $+J%7LoF'fJb} }Wn/C?wiʿg"cꅣ{~"LqE-'#cmv (3E'&[ V ~چ.p[3 QKڧ79}kuն\z8,(7|Nf4cM79fi<4!XypnD-[MQ@'~ȞʞC(D@ZDt &-m©Mҧ5 o bfivvV.++˘K`"lPԮQŰ~}r^W@A {4!US +9z҆XɌˍ;+7ղSP?!}zT+BT@ /7=Oɏҋr7D7:24dn \&؍)FtDo}F9I~cy $t-LM"|q ifŲVe2<]Nڧ3]?]Ml p"5=9GdݠaKD3ݬ04_0?hH=clx3BHR3`K;Wo!ACVs3HU^Ȉuf­$aNvv߾*.$vOP zqG_!ל'Xp%TDnL7{n6rT/L5 ܽ6QzXKZ 2ȼ"-2-+|. Ҥ'A:J,K-XU˧w1i ;dRjܓRD!W=-0H;Wؖ7|=JŊp`CKT{u4n XP9+ߡJW@' C8 +$~D!Έp9֘ԫDg9(Qb#e1N|Go졊W8 UՂ9O#E Pm$d{1\ \)XEv{54>NT+uP|96pEyU`I=|2y_uayI=.CJ+2. a>6,mz]fnʼi84lgWgcĝ{ۡ_ ]af},cg 0bZQF8~eś4BzAK~?C#~#Z:SO-AKwU}}]یbl>Zh"CZuD7B[(-8Yq`HSa?_S$쉆 .& +UMvAigcBU{7^2["$R5ǘPU,Iy269Yrv*VNv9Iκy]BGܹ[tft~k>^hP" PQpL!>AI'a ?ׁ-&7h :|ƶ)h6>}9GȃFL YmBjwaUvK`\aeTTH{Jb84~B?1Pib"N#Du{)kbAF' O{DO( Z -=eg,{1\Nd.J7R9­bPѕfa1UmĖEĽ N=bxi\2|܋n4jBS+K4&?SS 9!5_SMfNWCw7&Ҷk^jZ!xl"wc|znf~$_hDeܡ<Z\ ,q_b<8P'!픶;tsaF\: GHj&(~֕TyZR5GF˓~!9|_Yܼժ+rEt_pŐW~!E ~71WFpsiO*2. ³&HOo,c<5|/wC qAeg@d"Cp V@$O'~i7*i[ %׾v%{m 6M]e;As<4U M\Պ3[D dN}| .2_2G]jB!Z@q(Ie&Y/) Z6FTԒJIZ Ngkcxzê4YXI0oe.{b]zm C $.t&\׽XzWw@ø)‘Fs{/*R`4g=~"=s7F(d?.`zߺQxjKNb!KO Ny_Zqú}FՋKsߌ⊅Q+$}/,(=MDI!(Ҋ=`=߹01bz:[ZZ 0t@6V":1_%x$0>?Bm*Q]-a UFHr~8G7e9]:&YG?QXE 9  VH 6j''^[bTGˮwc?Pՙ Nj7&/"DR^B" ӒLm MS[ӏ6 /헞+ϝ_D1qr*9ed/Z2+T4&٪=j!ԈT䩈JQZWyo52IAMn_ooЏH$ qYŞ3Fkntxȩ[gm.!}_JJlLɃm'!;kGlq w5x]8@ޥ_ʚȮ3[Q?nK_efuyU]&qr/whI49C$emEHb >7x:0*o`B"UZK:FꠂXl C+~ xy-6 [ ^Xpd6iЎ*.ϯUw*WyOt1kʕyZnp2ggk &:|UbG3&m7deYYDl^~nC}'_r(C`(f1(ZL(#%^āJT“dc; yXGf(s]b-*YX7Rvo c}k7B)P.upEdy:Gw'!G;+Biȳrud+xG;Aٱaq&_˻n1 ,sxOsb逑4hE-֘mѷƥk~tQxCMKhZ&W]m+XⵒߛT^49UQag %1mG#Mb 1i6e;^ GؕRmAsUZScjI-U'(@nIrZ ̡]b%|33+ƘroA*iZ4 >);籌˦94Hbrp,nϲ&HF σ2޿(@ŧ*P)m}j*ݰOgm큠TF,Gys_ic {?7S%TE=qnz2ITB.p0/TbsD{B#tW,.Q|IX,(q*T<:ӥխzWLjӫ}z!z1ZU4r{K 7zzy{h `zpy ˈ_roIiNcizR77/5hU"IrCwBŴ`5 yۦhɐgO#l-Zi^7Y7e<3Mq73|떦Rؽs;Йu7|?ڙv3.]qꪵGJ^jrzH*_U8snn(_Go-<͍"+H)o:1g2&H?$cXY>dddf^EJ!?% f? ؛u|Ybܶ!C%cz.U.#>${hRŗm4bV}p~}F}_h$}KCX+Ⱥ}-ydE%ΑFR}A$ݱbhpJDG@\Kw!ILoD8U`!:fUQz7y-uwpE=Ec#BЯ I#4Rb،%96̰K6YI?J. AM]$8 fJ rH,P`˖8Ar9hbW#ONMpW3 u>2l"[.wGǭ=]MaQp[9oFxaVI%5;Dz4/_Rd9֒ȹ`*ȬN>P,>VQ+UF9,B onmxРJ WsZ< H/gR.m$*L3Ih$((]9ܨA⋯h HZzhR1iv6Ԋ{fPMl zӢ^^ѯ66؅ҚAxiL*J'NE-N_**r0>@F]/5~ii 6ny>aB5AX/m`Ҟ3t!ug)'Q0ԜEo y/BOm6Xqn0FfpOj}+ي_uԍRbMRؚ@w 0'/Y#>NWA LpOɞ71vrlEaERJC t\5uK[52ZqcVR\:iR@,ͺg#w=PciڱM2GbՅ^[U7]kj8ٹ͍[`E ,@?b +Y[_0udPe5K%.!5Q:MwD~;-Ly+.U J nXRT ,D* aAB.}J}ϤS\O/{ytF`cOLx AqHv=tCoDj#[ xњW(!P\0q`&^>DjQ3=_t,rʼ8'S 'IH¦Wef kKi UE-ʀ.TB{,Sm7Hj\GB N= %2d E::;[k [' !laT86>y]E!}$g_8GSirR13%F(]W7pc{K{ݼs{L0z@+ٍT8n@0$T/bb+pf|,>ilV2)I6/7SWl髚 $5(x꾿[Pfp#GJg167Q8 0rAJ.)t_J2Dw+Tg[|}PPJVQ@,#H.XsNu.|zPbPDN@<ά{6)v͖\y^2턍SQD҆|V&gX\\dE?~.׵3)^9 ~ho(%8JH"=Hg_q]tMza?]lŶ:7:5/}ꄞ FQ@kCx)Iَ^aHHDܮ$@|GFMWp$Phv)N 1T+Qp#+-QHUkW_h }7/PP>)=Vn48e-` }t){x(9\e lb} WIIʛ)Sud[qHnDVOIksAl4QUr.mB'؁4j[XjXWS6Ϥ[(wS\cq Gʳt¼&͆9B$%ŌuY#-b(u2{Ez^T8m4eKcj-v\yPJˆpc $pɦ6oͳ`sr?e7^mFvfR7 wGkYKhEaVg#~VyInYQ crKWe,ؚ>NZϏS>.Yb7kogq@,X>G-L:Ǘ$1%bNu#A19ᇌW-o% q7 a3el~*e TOw /^9M) Xe峦sO 64NI;]GN ېJu Gj"IbӓEE_1:lL6rb3 T9kK,}!~-Bh* SzCNvǼ#$ލvN<j]6 gMzf٨Hh|U {j"geFKx ؅LJ?֛NEYMsͰls*uϬ *5.wyg6e9O' =YWMj$:QzQV#bh"Bg -,;z~339w@-uYG^@α\\$M9h ܑ}tDuhoe@W{"`1UafJ>6Glj="#c=rJyKoAt2{ Pzw(nI{vzD)r*7+AqL[V=k^K_T.93nÛ0A)Toz)|oqT-/d[83, G"~V:Ob"35x ݯOLh)w"7Bj{ f&wƅӾ/Byi^D!B6)|:[feFsyf;DzNYL |' {ϱ 6Xb-;w/:(qx^"NĐ*xJE~>*%"7Tl,PaE =wg?IxwH~FrP*lݛW,fhA].!U?Ջ@}W\t(3E|c*q T)3#l>ĆeToaF#~aOďs_]ҹѡPn~`)5(N^Ovv*zOA_  9es2R K&`X̥ӳ0!x]^wI ~u|j3- r$nS{Si['d>7wK:]JCd@jji/05[ })>-pKٍ0LR3ž*yzܱe&|-K)Trqܩd*UzFp(ʲ`a߫f(`BH]gCZ:߉nL:]Tw/KvQhrȭKm75 Liܦ| llzeim [adX ;$(ಚtj Bf/qW~PqpuE|iC@XǘLN|;8 %d誂 W±'"4H)Ϧ։S-V2;ﲮ%)XNE$r*10/&biRW3=# ;QHM&jAwsS]&?<(7< To:^pHQϛ^Вi9dgQCmv:XD3KAn}EVz$/A 웩|ˢ$8  TXJY*^'M+xV7?V߬i02PJ2i3?ZO$'m_Q>%K T$%|Jt :0HDktqٛslg•T fO-42#U[{>} @ 5@f_2*BZ" D_o|oq88$SlfT30Y %;0qᮄK2s,80Pq,ˬjۼ̣тR]VCt"?>5e/!$҈o Gl'-M/5:6L))2`_]@Lؾ=XWꦰW_5,zq :n' :]Aӆ1HxsƉb:)>i2 L;UNM~9?4RƟ+aB6}%`asvTem\T+E&C_K4g#HoZ<ۖHiɂkH@15K3 }ݥcA)Eu$@Tݦ K} 'W/KnM& S8+ӅCS'Y7!?*{ c"a-aEsXg5.2@#_iMdZ#[i$ͪeU%r TvtkD^uƂW!'w9"D:7`|]̶˧T'L6M4Ot_honhl`Yк?z7JZ߇u^+8;Xl"YR)N Cԙδ2D 7(wYUܗ\j*x\d5D?*UFPKbD[#Acb"_vJkm)A[͒ÃRt+!q;* w(thSDY,@ <9yS=6,,UIA)"RLH#)^ '?/=;CE~2zvu|٫FF9Gɴfuټ"$ּoJr<3ˊ6;lZXĻfH/$J @Wt-VJQ).[E@k7)Z =vmoxA|LJ!)N&ZVjTDA3he+q rD Tn\j9#_+:~ e&clkpAΕΏ'n;+Apg=H"ȮfŴqY~-A~WqaswB0~DtKYoמ}CvX͓˛{>n}#JVi߭ݫB2XحeA_ouX}b+>f#)YhZ; vI n5'{hI3%Zo/j-@5~bNޟکE,EI2Fbj*bƩN 9lx!D8KFZ#D4-7,ǸQ@Kq@%ҟK@ʺ,(sۀ.V ͟+\C -^@s"elcT`^ҷگ#*r?@TĴ⺠*LI܍ZAȜ|Qw4N>T_To#Z86t xUK:9Lmސr9o|'=*j.CEޟa&+_"W- SZO?%m4ΐwh ,_=%=##'b Iѷnΰ! 0|f\n2xXhJLز !ؘ*|S5 GR@3C.7I|tNJH :2^ s$wȞ!0Ќ;G3T# |jt_rUgnݵF %Tik"kZ5/jXF fvqziBĉ& 3|y|p,֜5ţׂD \Oqv';1pro4~t;̩#-RŢwüI6W9u;ˬnN=B9d:`GÊ9D3}\g+Kl,ulN_X5r `u*xt0:͝uiIO"Ƥ[^DJٯjcxmy"7 |dDk*чlېr"hSXYl&D\|7Nv,fw do##kj=et&̭16=1N ,WFj#@uNʩIND; @ni@z;Hz_(*Gn$c+s*+.K.d)u6SAF JF72hwi-nϣ_ܢ,vt10bX￲=hA}EO%ƈ#)ØnC_FSD?lxQWIMXGBD'>O,)@?2LL{!h(.|܎;a?oqYٯ[i][5 v5"]f6+ȼw{ciNzUO?~ejehSumM|6qHXy*k9^ITBVG`.X3D#|d+t`3aJ@lDrc`h)KXNj\=3jAw9rݶ+VC}O;B~|XG/1S9O[G|!ۨ&6MgT871QF2uNe&+fg8I6T C˱2-=5GWDrUͻ~VTXFiGZ)PÈmz{ NCr~g.#d xc-rXXi,_L7Q'H;3B"q0'ہfk's+Wx/=߉K~Fʢܚ~mՀk JAD0nIaAGyQ[ITx~fQ(3(n2o]bICIF^'Zw5  wW1Z-kݨ8b,@8o曶q|A2nѨaJ$BnXUycwIQ[V-^z5?ӓswo1USQ~>E_3MEټNW+8it`@N)¶NI Y[vu?&0ݨ])x,ޞkkA#=!:(.%@0|b@Mobu"" y?"eueKt#zᘥI7u+v:ֳpnAPs<ҖkWJ5<hѶ OҸxKJ[KVDCG ذŤ"иأlV\^Pw0 %a[_!屢KKp=!76zƩrخc T|" Jo$R7GWպ$l}U#MDƘ݁QIWdM1e2`┺Adg X$բZw^) +_5It'_|u9b1LUzH+PKi}碂ԔY4ojՇP* RUe3x`5/ G{{ tGt)+̪J5u>wc_[0߷cJ H~㶕KHۄ&9HC?L z&}qI+ oB7}D#' 2I 5B2LlwBaʳdJEHn[cUu VT|G U^A|{[>|J0>6 %N2X~'oVìO=L*TS i ^1~c$1X-oCX3B^ҘD*!ţuX(SCC UYth jحO-ѠtCZ%"B6?g;=4dA:1dPi6)j;n%P,|TuCk_w"$C+d)H*ChR$#2oFǠ:TVզ)-As7:$*w LvZL{͏`Q{FZ2S XC"s؀_{N B)|wݲu@,7B~dZH88G JNǪ0f+={넠3`.sEϥ">Izl#iTԑ.GR1Fa -\(%HV~w>=,s23G":`nFlO[e|nn鋬 ^_^$J)rl]w^F ͣ=&Rݜ=}ϴ3yrw9Z X;,%iK4$)v*lWSUQ"}~*hlbWv Ɓd +}p}6\$ѵlفS黩\Oިʡ=Bo]SM_bt&1?yQ d4CCKl;!O{ uIn*P~p1J';ћj6!de*ŜӠ`Y2O >(=U.a o恻O#*b(q o9ESC(0oK|IlJQ# ZBN{] C>"vQX^) ѩDwѹ UZ;-|ex"vް ACH]EßDPi4 x;2fQ"'2XeQZRb<`o`$Y|& /Nu QyO ?wh 0#fYg,!GJP:1G[ir0[7q?0mTרЩ%س3H"i{#!E0ME\D%'nTU|[5VLje^,˸hdH6D4yv :m$X(egV/` ;guJn9,Q +m<9xFras)WxEICp5Ba;M x*aU&IEfp-/BG( Sf̾+'1NTx)N
  • iJ4O uD*Z=oYt]u}]LMD zjWxRWƕB3͐i$6!Rߕ51H).$hFl!ꆇ("hlIW#J+"U*@cqGbCɔ1 j½:狻Yx\_9?zCTnmAB 됔ǸLZkd/(z]epD7=3|HcdMrr-gB7!ոO -;Of;G镋˭;rbԩC \rsm0?iןm}1KlXCdcڂ `7&m"DJ^KFZU(f?Gke,%;Y͓tj1xfSm#-3r "&)nH#3I7 C?ɞeA|l5:sgkDs#&:1` ls)?~{%b=2Y 9ՇXGIqO~1&8P˦Ve3܉ '(ʀ~n-]fYCscYQODyq>⩊d}oVdV^4p"mƾ;՗g dMtBT>!V/|z{ħz 8d4dBb @'խ$],A^ٿ=( ;.iviJaG!ḙȽŅGd0=7~N xl{[<`0:w†~:-uSʜ);EDղv+Q+z.m%K=^Se+5}oa$7u9oS yxDukePx~w>}X" =-XT)O2X{,q_J>gv>$U:͇R5|"NFru_T@jܲƦqran~2JEvYE9? #~Z,,Ej[w ս"-*yU-[5*"6~8V*hcsbjE@?ZTԹWFĮг⌑Ql\5Bl Ja۠G"ojZ8nj 1 1't rza#1zS戂}+v(& >8 ˪T+7i.LJ_S}^+;g H{HT{<47ʙ%oX/7|CW ]<"ŝpvV%\s jT=Mj Xflo>2lk$8^t@ Z?y\h~ꝛ ڗ=1۔lCHOV؄m;68:YiKb>͒uݷoOQ5@1w@/1GL Ug !l7*R>,*;rH\v4vAqFB|F!Q%FciIUmt@ciDSc26~u__O1Ng"M5<o82Ovt}aQr, >ALN |C'nT$}L:)iFQWnÑLrH<U5TtޭgKHgWC+,w6:Ҷ77HȨ[.%ǯ#| a0AzOWGhؔ/:}rxIiMYs}j~JGV}kf/)]j[0="`1ſ>,Y=*CPL̔5` h_HFJbv,i?Cg%s67 .%G8;Gڳ¸"nvWHx;?%a\/)c󉝰AxWozd6je&~jbm23 ~;}+o%,mTɺX#]hƨ߯?> -C,Z&]*u ͖*<K5vO8jȐLEY .J$!4=|(yQ6}b s$V)Yw08} $VQ퇂od@8Mrmw$ӫ]rdX?kOp`[D`a9h1'{F?3hny S 9I &@CG?(tYaGG[=GwFU螦'^h' b.^lzX"@lEz<(p)A"|%eгDE* /P?PWnǎ*?mC2B"!~ȅj:dq%MMޒJ %.Mfg_0N0}~K\`-MSqD%pqu#GVh;9DVw $h!އ:{B~^ft= ZºCXL3V6?EyX@ !VI90u|d= Lܤ='&? @9ś䂉g hI #M%ѡ|vU6z&30sw( 7+ST: +Z򓨣(",."K] $B! (nb,pٜAQIBݞ;&GFY0jbNAs7x(ȿMx9:=mZD[݈4פ͐L:74J}j 3 =˜ Mid罘m?q:fO?{u(\s+Uvmv,7A4.AaۆHM!Ilp6 R؎bAuYebIXaKH9/|T!R2BåIC35C(=[4pEaޖ:`bh&cFSn9N'r =>l8gY x%tXrd((* ]Mp)F$aPG|1;ⱊG@ORr)hW)8vԯ؍-RՉLIB o[]x^7=aO~=wp hXGS9lV k ], B~vG{0 Ѵ4W |*҉n4A30I8lɬ׷GֵIr,oFC&P)/=p/,2TٵA8z`}(972'>~=:·+ /!v$}]?}|L2)D}A.g{%>ʵOI0>^ªmRXñ4F_?c푁? eamWhϰM5E"wep7fel[D+] OnE*4X;sp|Hhf&s0GESZc͊#~ɯ'Z" f0FZ2v-4 -`DTY] l .8ne fd-S mJ5D23z4Ֆlfd-rf6^࡛wGsE9ؽi)OA e`5IAJOc ОLx}:y޲ |=y'EVV3u(|z/W% φ,8mPo-9@Q(̈́+mPgsEn,hSo[9wBGZ2zZkN0z{]yND3@N)zA'Q9u/_C1=!/RN{ǂ?ݡ3QW60%),W\B& Vj_zt u6rWUHb#>TI--Kwq@Q4g90ՈFP/e#O{$g_ͅa\olbW;,LQ^I>G.U;$,r>Wxgp;ƤTK)!^V# @j>RBÈZ)Gd_VITiAEJ ɶޟbl |:oJ K 7NFnoAP)r0v-:]EN.v"6%΀k|i-@OYlrshgS5|=MaWsXiL.S-y~)n>(@ vDlyg B%vb1VͶ"]y{iܡfc_'C]) qE&MYMޮm G;SCчz[,zlKGcD̔h•]dv:n؛kg`$ӽ{듡[N{aFBv5 j]W[*qAP6 m"g =~wr Sm>"Xcz 9;Xv dZ+y4Qta_P h8qʹLᲪaeyT(l#>>!딿=lZJg;ݗTdl2%?`-2l" ms4)qm?:n~{8Eb!+qS(ͷؐha] r/92q舻{[;}CVr1qXYH/G> ()ڠzuӥ knl/Dh[_0\<}#ˆR%ۮQ_\sHoq/s *0TһEi݁YIm!0ޞZBuJ-Y@dJ9hpx weOj/dU@ڵĘtubd;*ڼʈwb!#H $]Yu{^)٪o4~3l9D+APih9nIE8D?3'-Zj^U/u3%>+za΄+*3μ#XC ,/{E&M-d> Zu&˿P.!3ץwwMFzس>6&xݝjMԏ6 FQA>v>Pl^wDW`=#-L&́3E^STN;iWKK$CŏΚ| 3cȰ^)Us{l'Ѽs[ip *i9'Bd?[8cs|۩"WbhEܺծb6H~`:, FZdy۴ot-rd p?[%`C))Z +PVn' a9Ok$ep4̞n.V"Ł:)縇rq1^`ʀOی /TK(mrc2֡ bl+w_'3|lG ׌T]MxC39[ 6㾐ѥ+}T"$\S!h:cΓC!=~Quo!"pLT|pWs~RB=.4eXډ`>ɹ8jSB=-W͖͵!mQA`̇H`=а )ٻ+3w[[$RTHnNPݲUwa%YjP;,bG;˗k*D|#q}OprNǶ<d#,=zJA9џT}r7);q~dӚŪ **X. 01Mks-[A"5]+Nטṭ/fLVѯٚd´?+)_3AO~4┚$1 o0oPLAܵ@3bK#Kg@,uKJ <*U@]l/@C[gL# ; ZlV祹uTuyeh0_gֽMG148@a =C8a()FoPn6@[Qw{f!*d8¤uQƜ%QmVXJuQʹb`oLlpk9ܕ -Ͽ{즛Na\L%Q=]۱$AДҒE:S$ w>AѶ V`l̿SUyuQ- ,mg_@2^ӈ!Ej&%"; >p L钉KK2Olb|RȃtۤJ. QͳnFD̄\iYs 'gÖNJR~˱L{lVdQEb?*<߉ ٴIUl[NH|ଖ:R9}gHb eteSۦVQk:c 䵲"!ymZ¦ЯzKe|ۺKn[2cWDP`c˚e(&5o;Z}նN_KP"sV53!\x7[tr_?EWrauI!Ia['h;9f`Uч"-_~e=(ɇމ{ۅ͏yK1,HUu/I= gܞs;MY|Va}&}X}"#U~*L /Q zQZ 5/95)/"(!0/pt-F)i`g3"_5hAE( Rĸn.g; i3òzZ%i~)_ GljO"JY_j9>V+GkOFԜ7Q ZhD}_<7&RRY)XV(:$^ğ|S`Iȧ21p9gs<#A `CUc z3HĽ@$IBK]Vqyxf7&өF8hV+b@8:uo,pkձ+QPKqR˴^*rE}U .B9}1f,4HEu(z/Ȏv 52sµAh]`<d.l({˩ Jz|aAuK`Ր7Ft|Jb&4S)hhGp|TGVYv׏󬨻5/ƀD8 l{ bUh`v T,ru8¾RЭ4O3_ _MMG,ާal&-.OCu' B?"ю QGOR>);6AB@a1#o81^}2&eLk{O h"j}E4!⍿E!_n^ڒ R.q撬oV""h\LfаMm*L02q!KANyjyf?r'Ew:{z ^!!xiV>M&W9,}[{"列<蝞w2uL6>9FVl+Fe _Dm I#o ]1~7AA$r3Ѵs*ױ*I&xHe9r$W,:z$]|&Jڬ" Q`;ݻgɓYy,n Z2IE7XAZh| Ә}ۋH3Jx_U_$df cЂծ;1Lrh'u"> Ec|qnܤzQQ9C/>Au$U(pma Ǥ ˡ@M/Tb E=4+nK6u L2M!yz1omZQr_GuSIO{PKyA};?@5͍a8@u7,suFiYWָ"Q/)L;mU"/]>4ћW89!~sp@ LU \ӣ ɏ^.:/sk'ېJ`mck6̻@ s[t:$Ё+PS0m"]獲w'j^ƟEUthqu#WG#ge>ũ1ߛF^!UDnQԪsAig'V$^!e[8+:?/OP);ֵ Y j=Q)♾3 R}8[05JLH4{2A}r* |ZZELd"H|dP~ŎܹAKD/5[c ;p[̠!.Y+a o[uK*YD-) f,7v7v *4G`>vÇreȊRJ?\LZ5v(5*h`mא"ZGg ~c9g"ߍ$]< v"BWUK?=N㩴D8^Jo5Pzͳ Wn99O?\| v铗L/(/ⴛUCٵMJWy't?] S#5Lz馻z6n \gg\P?G<5+ƋKbD%Q>9MM D.Mg]ln7oŘ!/ ?5(_/`#*551Z}d/ә{껽[=YKoվL} U+4+]>f4/| S'"(BL3Zn.^:[⎧E=cn‰O_/DeP=>*An#ҿoL菉LXco*3Ή_0D &9]l /*7N[EzV>C5;2-̠S}1PϷ&%xwRWڥ E7) ߏ5Nkr|IfC!=RB˓ƒbz}_UUPZ@L):/ǹ Z@yrqR d [>}ks_NA"wUOjL_-*ʏca]ZHMZ#^hst{94-W:knFuQ/75๶yA6Y%wQx01T#+}d\ څ8!l%w{2ilyePtLm2plb•5.}'"-d WL'ȥm 0.dBPzgs Fʠǽ=oˏ>P9d @뛯O1^G ZBLz8MxaVHbGDAch P6Sc9ƭĵMt!ռN uEWbղD3iySĀt<[l%_kJZlfD&!Z˷Iƕ^wK_P_|OP[g28c+#kQt(r\l(t 99Z蹈A{<>.w޲ 2%fg_^kN>єQ $RkZN5z؈v21qѻ&##&sSM!&17%rC\TidUS\Y)z8Z< wRR&4ySjcG=r榖zw{ nϝEVC!`FN?o1xa)FP_v7YYq)ir:}ͼ7H' )aF˅F$2pQ|$1d]`Q {Pz|"OaZu S9rj݌r26 5ۙωӧu8h+uTVH\QHO5b9)8MdzoC|plݷDVyT7.32b>oUmEP"iϰDgpx/Uz~|+r{`NezcEr)tU8@ ,7wlQB޳ n=Q˃ ߶vUTVk*kgzފǃ ei\{SsKחatyKa`V@S).jle^ίHvi]Dh+rigRHVFL7 rjҚ,bcQ܅L4Ae \#+ gz=E =T]P );( -O]Še.PdPU ]'[Kws{r\mO;lx+g=\/Gp Bv4=G/ZgߑQLXg$#Xt|#RuIFO) # =7?q8f'â=DB";?`L񟧑~4'%ZW] 8zah/V1ieTFEHfK]%_F/HbW%,:8m֞<%%D?Pfx:cpPZ75oS8 Mɳ.65;Mcڼ\Oq$VM`1EoL9!2E/5'P߼ Dʬn7YPͶG{psĈ|L#!<2`1 ]s[&T&O}`(+}uű.-V-#]γ9mKX)\,:Ő Lq<Nw|N=qԤ2"SvwN+'[(KGT<`@R9 &HGzE!2Pͭd@3B7GJ+n+x=مB \DQ^7_#DBx$L,Imnͬi`5cbhdptq$a M*Fyz=m&Ab"X8Rx} -^mGS0`;g1ry2ҤmEK2*Dwke09pF0+gNo; kx`A![,B[M2r[+0uZj+3TA*^ <ʴ}Fx >+}}?Zu @..7`v+1XxB\Co␩%޶AW>fktAY^ueU,3d(]`c^hV;va㨖6K3?U֍I,~ܼZ{O3 X$7U@SvZŐG_r9|'Ax]Jc׸4gA#3dфugtqM6pf2D;}&vHvc:iumLrvބ]["܅ui".gTR,Ph3'%mWNLb ]ViRaA( L[6KVOOJ¨HȦ98i^vKG̍ "N"wti6%AÌ%4r{E%m=M) ZANuiI`ю h?6na'R_~HKMIH{S ˉ'H*3]Ä́`|/=qȜqt}\v-wԯH_% 0\ "pQ?mF.+Ԑ2957tM8` l,YOPUHⶰĠ.8b`*ENJn\^䜣IO%*$99Ec" u|jpa2 SxbОdNg7";[$pk!t%y<eR69Exq4|R!zM{p*6PȬ^Jqdx;js0,D<\%Y u s ct:NN M՗zI 5{7jvn~Hp(T/@21{( >eir<4TD9HL 0t3§ <)<$aG#N$ϻ'.[6 Qݗg?Bj1"υ@uVDIf\h6@|Pnb5qlfU1r7ѫB9ʂ-bUZFckk#2[٢%@CJn6^ȸ[Aڍ34yBJSb :Xh,7p9T ɑA'a3jEobtBڜ+ iHb7gM\;Xo<9D!w9E*adG~{Tw2i5J6yl%\vhK^#])isҎ7G5Nk|99AӔU |h\ (ǹl\>+0v> +"{fؒx7{ST!4^> 8Pl(t6X L|]Ie TPy[_:ѠF"$pCMƖA?!岗D45iqM~t&K9)JNϰke9yDH4r|;mqZ%N ci&^<6Rެ?w5K@E/-ΓY5~CӲǔy~bB,0%"em[. ԏICsE}LR_5Cݢs&R]n]1fLOs M%,ԷRcܺ xJ&n]J?l!٤ ^^+6}.cdRcNwNf{NHS)))tXW~O.FKZ;CÌ!OOWkIxW(?%*vg(klh!!pyUa0al[~\2(*V_+@ T%i) 'L9dl]WHEƯTIvu/*h@F!cFj"v K]7vX0Lw]kB 1S˲f4w3 `g06ԕY}>Ya V,Q3y1]~\s!k5%JUIxIЉzq̰{)$ްug2U#\T=Wwx7Cq9 5EG8 ⾫$GdR-sJ:|l=lHuL*x<ӊ}Ud^@η!uaPR@;?씸>ZO&*=J{6|>L)TÄ1 KG\SoٗDD%vd@g N^yA8@{Nn٬v ~y<+,JfxCh"rTd1*dq jW7_XYJq?I$1]je jq"sӜ±SAʤ^ uB~7P  \ANPsĺg|fѱ^c̷؈=lX_izӗϼ :y)[`/qd+}?2P4JZ%RХn#Ul(;ܼͧIs6[%_og"cIIt=ݍi:wp'hB:hzD8e[C}P@XF3mmj&#y_gR[GT ϦrdJmwya%S={ruhW.HPЂB#g';g3;߱XY,L㪍ɘ;ZJU;@@ޓ>/5T kL'3\X]=|w-vR%[K'|\ZL@,]L >P5ġ&!k} rS\CQ} s9BUn,x(hrPu-6oبY-fZÔ7*:gZ 薠~h[6 M K6Dºn¹ҫ}hI?xU]|~tIlAdв5Kc~e%4%<[]S;3츥Oo͂KJr>M&*`Jn C_}c0c҂^n&0gbPhh֌?d>SG5a-3`TXN?;u}7jo)7ksP!w!# s eJoaؠ-QϑWw#EveA / hom{|,Y9yc J͑T^`inǧ`) 8?Q ]؃%cw0*D&f!{1 +Q<^Y~W.r?X˻ԲM}w&,kt`t`jDUDPCGjuUC %6!k y5azn9 W!#U <({ 顎5dx-VđTL̚us(:~<9~SxehYEnd|V:\?_tt^hߴ,|3q=7Rxjejn^C 0 hPAAضc3d9'&C7W\'ߞW|'IifG2x+*>uuW~=2d+ hǿĀ*P2UV1k>Džد\ =i (6YbaerS?;2PyxƵ*ԢBYt|,z(}}1u!m`D^ǪȢS1O#zxO%~̨` <8b^ANˣK[ɕϜd. Hv*]8Q/p.y/:,Xz{}!!żDJSZUmװD!ۄdmma:x>OF5\VI1+օ ǓEyH(ߴx&O/aD^PxX2#u06`Y]zBD_' XdҨ;Tr_))X tyδ]`sJ)m =Zʥ(^j@$/kBRX۞ag)SNq2Cbl?<:`W:._-Ua -SZPb(i8 nE"k{/OYߐS (ȗ K ΍O>,Z2ӝJ[\h<]|YS&\A]ih nc4`kR4Ntg'L !~ڧK )"wj[gU3 Z?>Ί+żS0=S[п9D4Z0zm^y\Ǹ(FUwC٘5zۛs$sB4Q1~I"8ߔ)8(N(¼U/EFōQ@O<=N}/m-W5tY,bkdzz;6El謞u^ T9ЏnǼlxZh#HϨwV2܂}Or6B"`_W@f}Gf]1pzR~UbEu4Xn]겝Pg)ȖqlL4z3jʼn.FՀMiyY2;w!f'X^Z% (/0xRD:2ۓ} - y~BNQ7",t.*UۅxLδ:+]%Bo_7|ǧ{TZuO->VF ]}=7Xo-+ogٓv`22{_w/ ~Љ#婈Ew2gq+6Ti14̂t28Zx7$~'v);Nyy0-VfXg.m8.\L,ic'2g((C2-h%^q~f#\l #99QH`/;3.eV3HILiXrO.m^*VXie$Z6!o-Ҧ&PLJ9]Zc? ;QC|vPPl(0X-7B.Ggu$ʦ؜H,JH) &51D[aLxB<=FpInJe{Z3L*-˱ Ar jcY"۪wCR7vsΰ0n|XZ_? 5Ta?wabJz~ 'ۻ*G{=+RP9n6nsJE.ƛ43B'$7dk9?髷F<%$ziulHt b!WLp3(mJb}(1ĬTl6rE .)m<F%gV#?[ZHfZ?WiN@,b섪:-;9iޠ.>s~@E N:\9UɕϞFvc՛[z yz PhZj!7.:Bg!w_LW,_5>8e6! ph QO4L1N=?I-}\q߳oP7f"=(-hSw7ZYjry0<\\z#lO œ1ܥ! QRbgAw}ulY}c+`ã,M&5(7E9]4H4|Nb5Kd|_ǷR/Tmy&{ .ܬ=ΝuAS$ni-&1穂]K.j+uN{-a45 0,"_W8wӳ#ՃT+'Ąn#=)V}*ENo"&oSgЈ #ۧo@Auo;TtY_o:CYc|h{[DuVW ef-Wp^9ʘ Kq1"[V4 iH(inUOHZFz梩YI?N/ΨDJ`ThwIH^{ x9).NX ބe X֭f6/tʻPO{~o6G[C`ds"z.7*PNOG:P,=۲yV3I_|:5¿? @.GF' MSmKU׭/k'4P{tm A<ɭ'7Q5\Sc-馫7Pƅ(\9. :ɤؚQ6QzPGĩlx)2ex!Erj <7RVq/M4e\nODkѷ֎KfTly]KQR"3"dk)T+AUc`hi+iT QGUd{jD @bG,Ө{Te *mjTo|3p4A?rZ,){Ua2z%%FIጪ:|Iloj ަ3U~-âQ2 '?탁deK_Dԃ N2C$/Ŀ9腦?]N.Wgݠ2Ys/ '>>qhcοziTlI @]ԄɄ)=O\@kzN \(7~f֯KЫoڧ X`/5ºAV pMMn+S-ОSd*q۰n'A)TyƊիńJtC\XF6GO3mINOm,"c0"ʏFduJM@VWyNP>$ `-agkS22f ˴N']K4w&$+ܶqsJh '8xw %.0 {gc l_\xD:z*[.5P?!dVU%n-ZxҒC,jv 2P!K+ Δ$za.3o2xuwEbC NގR]e82xʱ> nb } {çj752k_&5@{&n60'Lљ,U,JS)ߍes9ֹ\e\zߜ:9Z(V QnI m\@}dM[3)K'lɊ`頃H[f1_ԍjƳO|-`S `@pcr&涨MbtK4곃bvA[` `(ɻ o?ܺ#!=gA6xW,zS{r,<ѦL&SXp4?Aޥ'ЕPzn>PdTa=n1fE\^闵-sVԪ'}YJp)ǁf,ͷeݍ ]FΗ6<~GUF){_iR.wJJp;d F:c3QS"V kL{B0uMs1ퟏ|ja>~nO eB0;1 9fr_Wx<y֍h mi8o+m+-Jjh2#1'-drö^_obx&IRv528\7 [uw +G C Y X.X,FE]#Cd0XOZ'ݳ҆Cၿ/vޟC<̾Ao]Z4[lE{:PL* -{ii0!Fqo`=H;,^]F~?AG"O<\bBXtcz:5di$<}ؘ*1K^(81ŗ# w@@f$F:YχN_Cb{Zp9"`qO/LvjFh!imfh:S>zO̟]Fx?iŲ<$?*'g56&R`H氧FPaO{ i[rĮ/XKfz^cd2-nHQX9|x\vB ?M^ A׷3CexlG^~`+0Ĭ،M\ޜh!_7oXT)Dyb(zs= %d %_ۄQ`i2!]YϧǣK4nmNl>u8rnk>'f {-F H{w#Y++dX#ȱ^cVR,PxlW ƍ(2G(QG襔*HfŊ_gה>G]7[U VY*Ҥzυ:父/,iklfBLQy5}Z7mW!<$;Q e#k8ReL՜{q{lOa ^' 1ʕVѼQ[3>D=5"zeA~ bvFot%d~e?T:V}Pp\!iWW-b |SHo!؆Qey;8/6T.AK ޼@Wr - 1]$ QUux/՘{)`m97X9XO;ˠv{_[~5մb"H5mC#:B+/v\uaa_:`=M?#U ;BP8ғ] X9"kZ]ޡv\/BNRjC72ҾeW~e}LFD/~r?IMlרO xӐ&K_?Y̷_ŒG 1jjC3He# ڬ,8pMI`:rlD,)ˮ[{s꿡6NkI%7,M44;e;G"`ΈS8}BxCJ_['(̻yy3hNJ"U%H#$s$e)%x=ڊw7c!n i\/uj6 \D'ќ۱XDAK#4Y*5՚jc:k?bwq.up+G-Vx6AkPy'sY_ɲ\|R1\r4A7=i5xuO5g7P_bekqC3&yUt\B&'g=nbfXu0(˥-*h6&WKYݗh=0jiCel*B|FtUj>+] vg 'R'`&>#$`zs#+ gT 1 -zj4]@c}AOrNл+F 'gHqCӹ&q7659"o#}S!8f\t}*Dk^yAfSQ^BA\h#`!"Dx.M$/%ɸL2yi$&-.O ~6GGDXż'O9vϛvČiDJ5PMTJ[^lt Zl"i 뉊,\0nksXĈ8@\ƫ6"ЖEAk(׌ = nMࢶԁk,TCo6z{| 5/Mrr>M)j|e3⥽V8IN6E 6>knhp9T(-y"x1kn~YbLgh$k:"!WT}P }i!|+Y nI-3ݰYVadjӐW.;.:cS+[iTܤ  *6,NJ-6%"&f V nd3DŽʵ<=㑍AM+_Zg.7V ?ˠ`VL<֍H19?b?U7Rhuib S#*~GfzZ?O!^Ypa{G%cf:BCOqF} Bp#eno-v>2H]Gm|(4Qeo3 GhF`~1SMގ#'7|| I7Atбf?eJh8 =Ķ*Ʀ.Fw;ӳqC=iIW {d`ۦ'\J_!;^bI7rxZMk޽l]%$Ma1Ɠ9Kƻ2<- )$E:&缔ఔ4B OlWtN?'UP#JKv KY6Ո[p9U'ehǻij?Qʒ^'nϞrPMOMǓkg>=쪚<4S{:݂β\7Жs"gԪquG+ܪjb_m{P2&6H)n+t)-#ٗs>K(PGoN~tąP$sxxx}KYx5"0ڏq=x$ 'PPe@B9M ) vx;5{vU=N0JjE?RxqI< ]O3ӽjΊ"43uƻzIo')\X/Imͱ]sVh( nx`ipZ[*qjrɗ\GmUKY"N=Pc?%bqüZz>J:F*;~ 0 j6/AwsR{R?8=4uf5/u48ʀYA[dW-4nԾt",!LoUw 8ꖦ:u23"v `ekqi"FeNӰ# 㐼,cI{+smBQtXۈ"tҞf2o-hm*#i~* IʁBErö Iq(3&:ڊLuuoLWyr8N(P!t=24&Y_KU8!۵P1@& Юk% v)X5*N'xr2^&!׹ן1Xh"X O "N VY$VұpG`ޡZk1ԇp;)0q]uwf]IVrX3(imWяkU{n@Ũ|E恝Qum'/??ۘ"l <-ZXE0NiJɵh9ڻuTV^XT-:]rH7TBf+FJ; s Eъ6;:Ɵ8 R{v}}w\8 HHE j@K@x=͌+hs%UX4p)4.;VEևb}/ a1!&$79["nhQP:]SiF$B(ا# [?jhj2E JNREg=CúqST]G@5'ޙPݪQ+8~3aN6 skw?W "ߨWwH(k ëTljU"8QBYNG1i?fbD`j\0G7/!&?zySH.7E 9&/xؕQ Z'nG@BF 0ش>Q&VZa0uNP c[؟h6 }}wH +<v+Mj6G~IS3 g1g<Kjw7ܩm ^[AGa. )A?D#x9DIq>L =-3 rⵓn+lѷĠ.J5],2 F%]o.}ðĐD᚝9sYWG(;q׵ykw geHsaQįUWfZo#rBzEg7w % MG_2رD*+f788?(bcju-J$7zL\a Np! No:"{8 `3%W{ԮJR否hiؙ rqkxaI-) FO_ԟ^qWK=yC>lqDkf?Qu$PG?IMI/ \0:n4V<J/"Q5҈)k ]08 z $ث}^{tMP0qzz)0\sj/%! ZZjo<"S_*"׿_ޯ5t-NiR i=vgS$&1c`xm |a`#Ic1CJkrQP /HK6ӡ+ƒaBP_5ɸn4S"Z'7d "بS) ep"m~pvD3- ~37~iI6:׳?%;~;'Əۋga}A{up߾}㑊d (@ѝ5G,3[*4QnOԑ`dj r"ܷPfg.$pP`Nz|~o6TTLlf8M"cֿІc@_`rZm*YuĭO?SGIū=4&ac_=@0G_jLZCן ,S!s}#o7D'OHY,zϕCx'o:FLpx[3X%I 4'aODYkv6! ֦0Os$RS_&,~Ej kSkEm%QuB>.:%|RunJR!Bw'?)&/QT/l?1V4]saܤ :6G$x`D}Xvk9Z* ,i&sQs< q/ O\جvެ|$CKeQ;/1cz_=u&׻v7`uxOF wPYQoNF=o78%.tyI&LxǏ@'=؈Yʅݺo;X3 Б*4#FjzU`>rjV@:݃f1߶84=nIPT|OU`S/-:)VX_`| B-_ @Pbŏ9Ȯ^yJ=3EYHDM<,@r5rXXgo","lʎ;}RB9Ңf$sW!d$90+'_TWߨkG*YUO^fˀmP=5)p &9t6 F[[1-#H3WbɜϞ(ĿzRu uN^vl*%966ɯķ%=CzLf u 6Ph( 2E_nՁevj *d+A]qTYA#}k '+UzAc ?;WǎDjYƏ6Tfsv?ޗך ߂X'R</DWR\NMO%gYΕ֕8|)0w+z1\#c9f3a&5JGԔ,8Nso}|&&t9ErI[E0Fr@FXw &أ86Tv06 $Klu J{eKLxL1y|uז`f2ye'Vj$TE*GO4c ,)`cEAN1 j~y]dߵKൽ6$L\6}K߼LVx_ mg=˝7t-˃G܃`4.d!uP {od3H>㲾'bɅ\ɕDIzA]Kq-#d.7\W1~.3> =~:gBcɨ#w 8Kw̔ \7s1 UXY89wO*)gɣ;JހǩQ}E Ä[2к@!Hdp$q\{ kTDVw YIܔZD{*rxc7.MQCje^2kw0~ɻ0~".PomTUE?4O*<ryY}: *dW @f¿cNpP0Ydhtp6r 󏾿@a`P q<`Wp$ Q=|bmfq ֱv6>s%P(eo5NA?{̌O lݨN" xОa h/qq2^;Խ}3vnQ,pELqq*Bb`@#w7čCTCœ[Ηo&{>?~:ѲtٟП4dXE7vR6˛8XlkS"Y-W<%H<,ӹӔԋF 0g\M!7s?=rvs?K Y]\L] hT|{u]abH兝HQ6dbv簥uGʙ@2}kܟt-bA)FfI*J8%Dm>9B :mpNDI.93Wd;H;^J Zz K#'fT})S)9a.Lּ~RVg!$|8QW49$hXi! U('^Xq`\".UhZ5~SƂ濿"oO4?BؓƝd)T}k>OUëiNB}6>,t5Hn}NdέN$Ł3@,S)1@ZWB6\Hy}HH<fI&ҙtsjEo=nGRw 1KݮiCJ"Xp➄q:؛}X1ޖ4OBKĢ}X``Yjb̳ZDyR}j!̷YAer:}:'Ւb ])!%Uaqpgӧz,PxiY͇s7-J$a~;Q$*z[Fg*H&ӴFg( @s\+Y'vmp FeMr`/ɯPe-$GחlboG%GI4)`'t#غlμYɢgBY !r_1CgkZs.Lvq޸m%ϼOøs7\C Mk/&d|$:IYdm!l%tE~t% uz/(`xŠ:\QG&fbbe7Fۀ&;$ZN"A ks< yG_Ԟ$B;c WiE&^HWp ! Hlq(~3+|7r"agټ2xE>kPQz žlJB7#"cO mCB 0Ebؓwh5Pjr+ J|K[Kf8!W)EV)D,B5ä/VDe3 Zt]od5S_l8@TJ)Lr  _ٓn@?{!thT;!;c(clG-m ʝZ*'mVC 7,|xS~):9:8Y?rA2hsx׍!BK@ ~3]2hD&\ڟ j򐀠- "hIfw2'ڎ:Xv0G2{juɹTt9#h/B6(A](RR6%DRGV47ԢL[N?F3‰FX]0i-ψ"TBnemZ' Z| ›B. w%qO4XY5W|wAf6T×6^~-tR7ֆSፒPԔc@095u[m}Q$/xR;ɯrn="`}%_ewLA!1:P&d. bu@=r S(4\_өJkON Bq$߃i?]ۙ#D'JZh8fJj,5Bpay. Lx`$ EE j"R~RB ټ )d#R/S+M_N\FްfjaW-0Zwy8H-mۭUdz1ylt_`|օGq\l-gҞEqqN.@-8.u]$ 3yR 7V`QccrXn?4%dE%J5k2Z}+ 5q} VBVlY#ON5:n3@hu@DPg|2[$7?9[|9Pٝd|]R!Lꔁ5n < -=vA:ϺK̹vLܮ[q5L x3hIɾPr`@~uƣBzRv> #W3ހ<彇 pOѕPDZx e ѥ1Y6 p_qx9»;٨/Ό*{x6SmWG5~䀋]),BuýG=ItA2k}WuHCt-#(CѤoA{/qBn511qrAHWd\gvIPC%~!ѷdNOt7Xlce$q4 U?S$~ 4e|UXoT5 O ܘ2"J[kjܵլvKredV*eO}?NtX>gj_m–/{@&E1M.q<_- ˥?4n箧qp3L.'.U-]blc5<$+3K#{W o/ "g4"yM$Vc3x1VS\H y@ꥮk' kVC20I r4>\[Y^ry{suӽ1[Â}`pJF$b$c7j-}g1j9dlD=-AUd=7=H:eh۩^-˗3ivFoR&x_vPKސɕR2w:WMlլxzY7kTAm{ŽH#vuE2+o[PV `9R5V6% POb mCiq'.{5eCD~ʤ 7l%=`گe,ljw8,bH#h E;#7Vj*$}n"o d3RsR+A>苠Ӱ>gq \| <ԙIHY*p:f2 8&w}%-Pog0yWV~4B Yg4_٣= fG!tfJ|(G#T+hj/ @}@Y#2=^=I dSu -58,;yJ+ѷHІu0zĎٝ؎I ,* aI`7!̽W޲yIU zALY7.:B gZ,,5ׄO*vSxμ^Vo_K`i\G#&a"hCqG9e[wv>=cЬ_;xU,6S{Mmd-o& O 9%JX$JrC24 y-2xI*G U'y0k)] < -UIv(}{kHE"gKPt.CK+챻v9Վͽ,?23Wը?N̜$'o}%V>?]ԫ6kԑbflbl@a'"tJLqwKr$#Ԁ5iG0@Vd`sKX GTuO8Ca[GD~{f| qacDR%bd:[Z R~z;,ƍ9D:.Y?`lP:7Z `HC %20:. i}p:*dp_qspq nBG+;uRmfcG,BQ%in[EG_t^a+ߪ+`=YlOj Ԧ/?E2]gk(Y2:TgUh!=@ x\ Y-N_8 q^/29ⳤO:$h3xp3V,isA%s:rx{5@ ?P4oOM Įտ:Ȣ ZTP`d#2F ruJGN,eRO bfIǽq|FqB\l.MPFǘ `#$iV9[ i8fLm6s6:Ô¼Ut8rDMǺpjLW3WǎO rܺNcE2+?1GZF/i9#5™:Fl'4ڠnIauΞ{[,}=@>ED~FԸ$uyCDB0|(G[,LDŽ:VesJeTB0ȫ;2kWz=ψCQ<*fi7$̔[hdb}B~gYּځ? dN%|ڞ ,px0ب92xp< N{mt,'k+g(~ sϣ ˨ _ZY;J{Np8%E)CN//D99+YJTzK^v!X E㹒Q^l9"2Uѿ (ҵb&UUn(MhXSdgkʻjss VKԡfqO|ޫ )9@hzFk" }k~+:"b?c gd6z &:ۊmm'F0C9([[B2tv-s˛sY_/SrPeDެi<?5☔#u0P-ҦRQkALٿ馚N [c!h{n*b )5:CWvF,-|ZQ]̎";쫕ba8_IcvOߓGL_ aҜ{Ys& #߇)^5^ϸ^ubN𾣚\b{ 6Nq 1gU} 7y9d+@ ÚZg]L-z`=BЍ9;Ts~.LPߪC%13a7sjFzPSMvaS[Σ2=rq]3p LZzޱ'#W;鑸օVMfa㐵Rnj{в U5IC _ٖߖ]I"^!)6iӯ+o6z-q94,7čf g3gV~}a'z8Rˤvi ޅ?]4ccCB= KoFbj :O|w- k_UƨG_2~)(/~xx# fg5[*NbX0?ss:1 Zc.3 V뭫~/PQ#B q=t Ļ=90B6;'zߘl[(2nМw|[Pv7"X%6̃d-}KsZڐ#v62?$b5ӛh\;\gQ\v_[id r &0.f6ĊT=PSPycwNz 2RrFXJ5YZ\Hz?}3OE(7L]wb]Gt%Č2UGg8fdz Ze{;9UzvMѥM(xZPu t l(&RW@>Wj&&gxUU+&jzf M ':~o(R‘JoĂ,Z2I)W[W"条5w;C³S6D'y6_5t2Gޖq̈WuϘgՁ|qdd!| _"+_"%U.G I7b=JHlWÏ5 .Ae-G韺Ŀ;4#Ψ/$sDV+~)\'5ᰗ(>-RCTajf.zdk,%̯J?/=W8RAȪ\_,T "&E};\I̜qpA2uTюٚA'_܁ *7l!kHuw+׎ps'H@iu E~1)&UׂcG{N0,yuJ9q#V#8"6)z !_7ICp44Nu~dɏQJ^<*}f22{WɄ}sfFHagZ$5@CTewή1g4QzLDQN,5|Ιaz¦ 0ft&e+= &;~zs)7AY*ϒ<֓{Q1}"Ĝz N=uA"uیw=؇  hhek:? StxaЪyO [#-- u6»/&:7B|[Ub4tp9[EQ1~ ŢBKMwBtjA_LչƿJyP SL2HbSއF)s&+&Z$> ndiN,|v\cSh?zQ2JQK(AҢLΞ0t,.f Cdeô gc_JGW?,P4ӫD>̨sI ~1y`o*\2:t;'V|i ;f~7 X j2>!LѾrv֊5UɱBN$e2*noc!kdUȲvNX3DGQGߏ5¶֭.|YRz:PomP;,'Cw0VA,;j$Xe BÛ˫>S4F^ 0ib J{V~s7i&Wo &. OλBy_I5h-欄\~'!78#ڮbw[Y@]wD,Þ3|Dv`/.@>WY2kȿ#\9'vvrG49q.be=KN*2&ǺX]$U@ ¿.DB)%R@ħ-ߖ,_@Ytk{C܂`q'ۻ]h^&ʱltd[U@*7ڏ֒a jg,.dQȉFsw~lL&&?m {yn'8"h:iZy8r)v cO:2M/`'YKSm|e. +- PB%4imHqy{5[ml׮fшӒDו( [YZY>wBނeS>Ӓ_,&xy$OQgX0( ,:9.)B&+՗*1+^jgj#H\L9ַZ`͂圎(}AVM-`!*T֐878;Z)C+2cק2_N JFJ'ڶ} D=s+&A6YX 7f#8ڤDj,qb|Cjyp6o _™80NBwFbU3ץ an?:TW&~ {e}5ѤO%L#gq^&x޼8&NްyҺK^d(Cϵ-lnuIFCF0 J(Fע`#R愍0F9`jVO2 ԸL5jI,)2.3x*YKW l XŜh!j8Ք6|/>:MA=W,SO[ܲ3 G6.q@lPB̐PZ][mЕ*׎"g&"-xӛQY W;{вXޒhPk`Oi9cJt f}wz\7}$[e^W^;|q !d >d< 4T \kГ.PrFRkS6͵Dފ>igXvD!xZw":'74IsLĚ\:y->1ybTH@lh`CNqM-fujy=/AZJgD~čCFG)*W\U{H~ֆ j a"!Vz:[fWYSJϩ&p!=e֌&[I 40&m\@$X'pszbu}d}WĨ|Elfg?Q{W&d2}QtY##e't}wU&?^{;P۴TI!d4})0eȈDӆ QU?Կ*"3$d- K/jEO*F8B_ޏM ʱlO]#G%o(1,A{k*ƳVg$4VDͯE Զ&` gO XFf+r+\ ~ ^ìy7`(<à sC{91f/ bxؼCdZ^$Jy?rI溿ͣ%ޔ\v4g ʽmwhEaE ~(h [wM_;#zd$0Pxg] dvwB R3EkS!rT_4Esrj. >:CS%䗁{lr X[ i{.wW۪į::tKبsP{HOf}l>ZNÒ^.  4ٻ>}n4/ʑrR3>6C;^_x,3# *69N_d`Qs{]=!ŤϋܧuYi;J&G}v,PZbmwcmx?Ra]YRRNBbyocr?䱥%wxtj%K[YK㏋TңD,'c}ζBsܪM,N$߉mRM;$;H]tvLsIHBDfQ[eWGמ@ nDQSMX¶.XJN=0D!12cD\ɈOC{ e̸ [DS8eo=ǙW~,krC 4cړ19dO!uAɼpA,j/k#sӜ 3i|#-|`Ѳcݎe'ӆWGOa\Ň?/:h:SY}f ۦef` FE  `'_zB0Ǎ7K[޴5cL)LqkL%}L^Qu0 x/&C`nPIƐ TH(C^wV7r]U"g[Øpl5ޚXWΛ̜ܹ #$u3^sEJh -5: 9U #fD1T"⥶1t|ѽo#de!5Ģr(ȧzv29%4hW("s hu?Sk= >h5Bvئ f4PiwAR*y'W^"]CįճF#%&N'N]*k0ځ-FgI5X =b$Ǖ!L~P!0E8fv XY308]\tOi4zIPmľagn=P2VE]U,yج+hY'j3LlPFT1J ,VgU5Ż\)4%?csY]Ux:}n]g/bl)AD)hФhi-H C95U32&6'FV{ݥI9vmP#U":,"/0C9(3:]0 l HʝB{!Nb6 {x̂D}ӏ!z ޾5Hny%{N:W" G~&cDidHq >CE/k/ vKHXE?jYĠ (FyIY`_W;~~3x;b FÇ}]Fo.V%> hX<&{]# ]TcK2iopt JOC[5pۺGcS%IE$?x OQIq<y†7H,}u %K4Snf0(sviMY䣺!(1q$*Lr߃d{܂[ۄu]MݾiK;'[J,te>w294[ L~?4аɥtP6օkEmCFiIMr\S·{Uaɧ03FS(|wYRO"?ZU|uu?$K,bbdeA)tuvF۪Yhd!XWF@"MWZ.Zbwr׌L0^=U{,eGÜ޼A}'x*)b0F40{V+>*~7 8meκM9QJi~u+ ͯi"gbtoa1]|LFLt*U2dQe1LQӕ Au{G}6Uf@I+mBk,@l%4X_$}Q꟟(?"ڶB˕<{˜=G.yB2 Llp~(6Ltm3Q0-X-wUMD:ȵ Jt|Hu&cEdnWBŅ 2AT< ד& Vr2%%yuttW`3@14X+Z[z,Uӫ?JQ!N 24#"h8jW\nʐї}ca1\ fJ{v('4$[+QlGDwfX]Ɠ}FgINi]|RRk^f9ސ|PTHT9(֛vx͠Ϩ1 YsVHAj1ph2TQQ1+7Ak^1"1 ^KAK^[=>FW~b!fSe/O#퇆;wtJ|0R~8l\#:Lf R) \/C+?PDɢC@Y2PWT)4ɏ]w>٦.|3̅bCPG^Xޯ`7NR~H)JSbSP4UR )"3Rzr8˳KSV/imK6>;!­PJ\%}8GhG/1٣SJkvGUo >JLC4">w GIsc>^1{LSgHX*3 \LEFEF(*0vxkVzҟ.9`0anJgj"xBRJ8[V/1t̸A\#k(J?ON֪_-+ Apb jQVTKYr|clt9jXRr\YCpxfj*iӤD߄İp#5X(tC|*1ǻTYy!Zw S"-2VZ& wdwsENpbin2,1[Ǜ<;;]V._`Z8il4 ]i(aАnPw95?U]EkJk1HAуex)ަcGf}pJn4`2[ɟ&/6yB6I9j(pK `rynaGDݤ;,i*MV{O,܅FX6忹`*))'ϱ I%Q8{F,t n&8:HRĝSr.hyy͖CG³V uUVpu]7F^v,xvHZW3*B4afø4 jg'F!5pP^'[lirId4{hIO؛d(`]6q}PoD ^ Iܲ/Zs<GbsbnHÕx庍{\joPP*%g0Tj+rb] X R'Mh liXxƭz)~H-\5/DјׇSʱ /w)sIHgVLQ aD-!',}x/~Q76t6.5-w|IykHvEoԑK+YԯиVG{߻if(#|vWm3/Z~Ն)D{;7I}b;LE..{L`ҍIsmA`xpHS50\ CFꈨPT8;ݡn8$7ίQ6ę?g[ǂ5ܮmۼaEiwmrYO;{#_ H1LF F)/O1zJ𒳗GųTA]wVJ6[MfF/IVB)zh,AƑ}m4cr#7vɾcYe%']įECZNev/ L{_INv4%]5>r^/ ,LI{aF|4([SQj*Q =5qrDۆ^T mK X gXs0U?bKEG| .4D8QpBzgCDeh\X='X{1i,{2; * fʅB_YU.)N_  ~o 9@z&WM)ɿlm0Tͷ$Սٱ B|c$@V](]ʵ˴(:, r6~n:#e-eM̦0 Mf_J4S1dyiBz|.2O%S*[.1zAƻߍ(b.6؃NRDkӴq; ,7y"Zt/٠[=luW w'jDfef p|1ӂ0AH9-YAlnD11N(E~Pr4kK]2+Z!mv. wQ?]ᮐ!D_}M({W_A o׿<%6생Y@Æ_u6ew f=_TKF] w|3`c9\7ލUw,q9? z`Y_zʾx.%;-Ն5Bk-ub>nʉ\KTFٜ>VДzG镃pѸz)W3?"R ~N-;JKxm[0<3/eL^tz,)`Rm4O{4lk=MV׉~aV(hyY*גmלz,ܽ,sa-S.zLN+owe42ÑcbfCzZ; {LRfʮ PpwЀ X 7lKr=o,q5,%td$" ~AB ^Ht~J,^k_.o?WΎPR쥌ތOjLBxrCC]*zj1 oC"-%8liCBJhXI-ַhFI g%Zn_@2 U&'te w,V}? hEk!Pc"禲R!=rq< ٫yH"kTdIn%?kt"XLO-ʑ/@]q8lR0[T7%suu p]TI-KU9ξвJr=NU 2\!һ̸-~#s܌qaoJ>ERjzڧ+I'n1YE+;clHZ< 鞨9IPP)qJFaE*Nણqchܵ+i&%vPz<uS?0rV^8du/rڰK _: u^A+1h.VɔJ1MQA n{9H rEvjs;LѲy Ԡ@3}7IK* ߒA i͡lm\{?!Ù+].9zSEFޓwMnF)b;q+<3CՉ1App=pWf2Gwr5i--]˹_ڲ@ s0wB-Lԯ=xtm}`X`7!+;_* b; N>䧒̐W; J&_Vwt2MA֟ $:d_jm>w]_ji,xҒ`sfO0a=60mdN_mhߜ~BtH"6qWL̹&L#0Jd7:qUi3(ƅ"[~?U,ۤe9YMg 멤r p#("Kv ߦ,ĄT$\2 `%n YP<*02p#U*-ҡbx`:fXŎ[0@}?N0YAN>_ejpQ&d 7I(/4Y֔2 PsT L~gW XEpJӺ9WYo Bxăq3 <-Ɔ/l͡B\.ʾ6.syL B1Y^'\2 %6T,/@Ggf-B2Z14m`pdL Y)(>G3EA`<*Mf1T*Xфܹnn= Dw{b+0Dm)78l_'w+|i!}SqJDFUdtwWio#Wݧm;z!&Wj2u8cޮP#žn->QuDɨ%<LV^Al3ܠ @7ͯˇ)scK5"WaѝRAxޫ&K닇hɅ)`uK5lۦӨGUG=sR9 'ݞ˟?RQa/o'P--'!5=tÖ|shȗ"JLz,LSAg l8Y WEh&`S`{pqpP{|ld$.>.wr n -cl>cޯQZI uz䚝ԃfV_SgyvާWD)^h8צ37XZH*rjI;[Ps)y7(M%[~URwm<;_ (նZ:&/?T#$L:74-b X2+YޘǶ'fs(oYH8'*& )<5c@ii"YP v#soNPfP&P+ |J7OvF-.˄c#Bëlz Œ3 XLTϊM7Sc ?fCO]uh00_.6WPGS칤RVE( #Q ^l 5ҲZW#1Iw˳]vߪu%%jK/i\=TvmacnT|bGCpU)x e0q)0/eZR/}3F|B;1퀶`3ZbWSB,~`l>ͯ@SG|y&CT-]S8֤m@4>J?N[ޛ6z,c} RG }f<|d$'S/A8LOa&}#-]z#^#{:J_RV JFrGUU8](L-&KT6ţYOW\m6z\mВ:Ḭ'\w]jߢg;Mq3fx1š)^Xz YNM5@8@p^}8ѣKSp/~[AWjv ^Wm U d^+;l+ e+D7gF,#a8En Fq4XhfnnI`nTMu+:S八Q^MT@γѫ{1&ӣm9[y?݌ ɦu rBy[vhc'v3gvĊnn_^{ܵcjI큳O Ke! /`c3R%.w#)>A\ER#SDX0Z^5%ph JǔɗHU ֜Fw<ȶX묜dvyꭜMy 3oiBPqO .뀙 hȍ(o󞑧4<hvO72_fV1@ѽ됹=۪ٓUs p|\3 ۋT:i.GS(q T/Y0}ߺagbwM>TL9V1J%J?ww˥|޺j_O*N\}K=CnME\D}V "죆"AKua.V,jnRdUY¯L$S0pؽ`Loܹڡ?t[] U`KSMm%bPGK"R sd̺O犼ȸ ^K cJhgW(k2SbqҘMȕ64 3i˟o  `/{ @w[|=PEa!lgO ;ס%a`{/zKw<ꃁ3Fdp {У2Pعr1gV?MysS$7so'fy0g1Pf:z܇b0'$>ȇ!ڐ T[ zdSd.y8dѧWyTe)Ғz'#RaxeU( s/D6@RIOיIM~do:P{Lח>4GhLfej .^F)J2~5ڊt}rPbn6Ng2:H͏i2ࡠ'y8]`!G {~->KւQkګOIIk1٤Vy?ά6?kwBP 6ۣ9A8Op2Dʜ}bItp\-#Ȱ^ǣG'\DKkD)L0&zSZ.H\SƘgQ1 x mC ^vG>EkQ"HVǖCe^$eGa3vMeVlu?C>z'V?1t+!Xt1JD)` ]. U]~@=Q,b<o`2뭘Zwz.^HmmwrUu8zF$]Ի_̭}oU㻋t9sʗ-}$BD*gۜJR|7Kѣ64UnRu ojmۀ { n[7n$L4 %u,Y[SC{JgLأTCCx^WwW\/a*'rr5*QNjHX|ԧxLC;G/9S.8sf'ŷ}c7X=1,c(Q yӂK#́d,h^ji>k2H9M8/'ah:M6y]ܥ;hUB{a}ecRi)~mHzOQsvsY8U6 kLE1TL!6{,~uλnu S]Cj?h+#נ43/Ӂ8O{yP\qyzb(u#2-MB;&h.:и>fI/FR 7тy˱kPOr`C[wK@J"`iSSrΥLJT*d?ɣwbe($>^`gA8^JAQ|~P(}v>}I( %-ն\jgCpG^K6zN1m?_QN™oBt?#U0ɰlI\0<ݯRiMrдA/Fyuog<3U u}_S iX\PU"9Ѝb,aȽ`ii|5D |+?,h5MNnު~=ĵՁΤ6B/#xw}uzd˕EՂυ0u ⮭ ash3(,(CF4mU Ll%q87tZ`L7O #+l|kZ ]"h?pd=|ox/Jd-S|Tٴ!OY/dTi0  #ɝbvRo OFll"ݩcWjJҪ)y5<$@MUR k1RoN`V"D#~E[>88v~su)qm4| aJDtؒU<ϝ?wrtVf@ˬE>p.H'[PގM}PgUψiTV {{.QX-IKlhx6a%@LQ2'̏q5+[qk3erwoϫ `·U_]Ğ1^dn94h/]aVNݸe&NִY $dQX?j~! *!>`h#i_wӆ$:U>,헠-hZy5Qޤ5_ثsWP{-<cjFkovpz563|M[5v8El=љ|1ܛqW͏dޑB6YˁbsmǛIbTx M nҸ2m$s$S_X Յx1֊ ~UTpìIXPּگ?~H%"_߫Dj+":FܚD/{ձ)^?a91R ŒNS:+U@{I1ŹiYEB1$7IH-+HWQXi T Ėw b~]'u>0ePV$aј#K7!=I?|#.up0EsғM:MLŶͼu)U*#VM5*qb9S~OޘlҐ3Vn10Ðg-krKe#ht/_ss4uajZMǚSNýe`Ҧh BJ3x02F0k^b L!L K((<IN̷N^i7&pg:z\z~vIt;$zr, ĽO(Ĭ)f |p~3ɚV ;E hEqrfID- 7WWO7$}U4E[(;8pAS]<I~-z2@(OWf/3#Y@=NhW^v;?%@_SlM]y!|FGK+C{&gJj2kvkU%[ yD8Or7Nut]T~J NѮ%Fςj!,Z!+}0REV,%?DnK>uۭFH_ZC**S('xXO ]FBV\HgUCͩB0Ug D&˝Oݹ >#春V-n}I5b,% ;BiϣL y׊:)bF8,:q$ \hU wX]#&` Dq?x!pa++,k?^M Y jpjd8ď xپ nUkֶQ Ak 3r_ē(MN$xH >'#dã<00Gu5m3Ti;Qvs t֊܄̡baHЁ\*PV_ Nnno#|[:п{tK)ǘ8&6n.fPiDrBxXl:L1n@(j:m1Evotkn!c "nH@lC)'P8 b%R]ugJ9mП6ꚛ>h). p|pu:ڇGXIw}{YoH.b4ɠlzZi$SqM;yp>q馬#c٦N{bCmTEz8ܿU1! ifѲPc2e|%_|uhg-H:g鷗(^YYmM8)"Z~ΝB9NBi*vO@_ƶ6ƇnVjZ( Pjrs0CՅtvwcAH2x|4ܼ.N:^;=T{7 ů$W56$cZ1\]GÁ QK<> 䡲JÄ(,@&xl.X`)x&7J.Ci/B):B+!`A}"m(Qg1kt@5JV'.`dG1q6FrY}ʧ9ZPQƺB#h4,*.u>- < o(Q^QA)Gd9w"@PJ$pΚfeȰ4{ѱ >L.}[01`KBsxg%v=cA qqAn9`;vFt!49Tr8 ])'j?+RdAɴEC/H zDPt+c$=IM']MP sRn: ( -4%FHhCx@꟞ByyjrH޹$RZ_!DIv!N1-v ¢4}[23 F r2 燂L˳#)2Q#;#2 qyc;{ vz>$h9xxS{r9&8:R)`i-K+HP9U’Yi|UwmZ?W Xj }e71y*k S"YM*~( ظ9a6Z٦`(gsUfN@9kw+,sɰ$8yڟ1 @Ke/Sh_R<- YsҲһOΜ_pHF!Q[>#2K!+s@͉sF*ZjKX[rJ JQy@JG%v#2w0[ʓW37Krz (!rV+T@p]!FmEA 7:?x;EJs3yЀόYz3l x,[_ݻ)N6Д\+]Â)P4dU 25nx@}+ PeMQYz[fU.>Qt6o9&-ԈX%<k^ɷjb sc.` ɸ͋y@mً㗉$ϗ5b/$ľ5ptY(xKL۳ɗ4ӝ5_W!3'ԣYo$d#Q o%8r{qh!x$0a A[#vp+,'i.:NG{Z,n *"Mщ;8~ԘnV~0ɝY?ݓ-((85M>m`tqGo!4o"s"\۠м=Ѳ0AZr{_L!IŇ#A>o#7y܂| T5m/=郢*)zρ