libdnssec8-3.1.4-bp154.1.87 >  A b|q !M@eee?[zw;L0[fk N|JObHؙJ=[`4A$(b"3+|-X,]s,,\]h6a475687828b7a11baf152190fa19f6f24b23a3d71ba8cae91fa6c36c8758daf9c4cb3877d8d1f60dd014c470f6a4be1135755e8db|q !M@eee$l+.UF͊ǣ@ sBvPZ~;аӺ뙒L7AX,,Dtğ.9W^Ck7L]1T.lj\?,صnW0jj颾*yPg. ݚM~8ghlg \ݏ@g7HGLmvct ?ɭ1t׷1U4|(uo&~`\~q7h]jXXOP%3Fra>p@gX?gHd   DPT`d     J `hr|(8898: ]8>d2@dAFdPGdhHdpIdxXd|Yd\d]d^dbdcedeeefeleufvfwfxfyf zfffggDClibdnssec83.1.4bp154.1.87DNSSEC support functions for Knot DNSKnot DNS is a DNS server. It implements only the authoritative domain name service. It uses a multi-threaded and mostly lock-free implementation and can operate non-stop during zone addition or removal. This package contains a library for DNSSEC support functions.b|pobs-arm-10 pSUSE Linux Enterprise 15 SP4openSUSEGPL-3.0-or-laterhttps://bugs.opensuse.orgSystem/Librarieshttps://www.knot-dns.cz/linuxaarch64 pb|pb|p4a4f495bd92998b518500623e5616ff5c3c9f2f3e4400a3ded4a1435b342a650libdnssec.so.8.0.0rootrootrootrootknot-3.1.4-bp154.1.87.src.rpmlibdnssec.so.8()(64bit)libdnssec8libdnssec8(aarch-64)@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.25)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3a@an@aD@a @a @`ݮ@`f@`@`q`_@`\{@`@`_@____^@@^@@^@@^@]\HW@\3?@\*[@[@[ݍ[IZ@Z@ZWQYYYXWDB@W1@VwV@V@V@V@VTQ@VCU6@U6@U@U&iU&iTTq@T@T@Tk4Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Jan Engelhardt Michal Hrusecky Jan Engelhardt Michal Hrusecky Michal Hrusecky pgajdos@suse.comMichal Hrusecky Marcus Rueckert Marcus Rueckert Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky pgajdos@suse.comMarcus Rueckert Marcus Rueckert Petr Gajdos Marcus Rueckert Marcus Rueckert Marcus Rueckert mrueckert@suse.dekbabioch@suse.commrueckert@suse.dei@marguerite.sumrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.detchvatal@suse.comondrej@sury.orgondrej@sury.orgpgajdos@suse.com- update to version 3.1.4, see: https://www.knot-dns.cz/2021-11-04-version-314.html- update to version 3.1.3, see: https://www.knot-dns.cz/2021-10-18-version-313.html- migrate to user creation via sysuser-tools - run spec-cleaner on spec file - update to version 3.1.2, see: https://www.knot-dns.cz/2021-09-08-version-312.html- update to version 3.1.1, see: https://www.knot-dns.cz/2021-08-10-version-311.html- update to version 3.1.0, see: https://www.knot-dns.cz/2021-08-02-version-310.html- update to version 3.0.7, see: https://www.knot-dns.cz/2021-06-16-version-307.html- make sure we have getent and groupadd/useradd in pre * added dependency on shadow and glibc * might be related to bnc#1186023- update to version 3.0.6, see: https://www.knot-dns.cz/2021-05-12-version-306.html- Make /etc/knot directory owned by knot - fix reload action- Update descriptions, remove unsubstantiated claims.- update to version 3.0.5, see: https://www.knot-dns.cz/2021-03-25-version-305.html - Update description based on homepage- Trim marketing wording from description. - Drop old rpm constructs.- version update to 3.0.4, see: https://www.knot-dns.cz/2021-01-20-version-304.html- add incompatibility warning about 1.6.X version when updateing - rename back to knot- version update to 3.0.3- version update to 2.9.7, see: https://www.knot-dns.cz/2020-08-31-version-296.html https://www.knot-dns.cz/2020-10-09-version-297.html - obsolete only pre-2.0 version- remove rosedb conditional as lmdb is required in general now- replace conflicts with Provides/Obsoletes- fix dependency: python-Sphinx -> python3-Sphinx- use upstream example config file with correct syntax- version update to 2.9.5 - Bugfixes - Old ZSK can be withdrawn too early during a ZSK rollover if maximum zone TTL is computed automatically - Server responds SERVFAIL to ANY queries on empty non-terminal nodes - Improvements - Also module onlinesign returns minimized responses to ANY queries - Linking against libcap-ng can be disabled via a configure option- version update to 2.9.4 see NEWS- version update to 2.9.2 see NEWS- update to 2.7.6 - Improvements - Zone status also shows when the zone load is scheduled - Server workers status also shows background workers utilization - Default control timeout for knotc was increased to 10 seconds - Pkg-config files contain auxiliary variable with library filename - Bugfixes - Configuration commit or server reload can drop some pending zone events - Nonempty zone journal is created even though it's disabled [#635] - Zone is completely re-signed during empty dynamic update processing - Server can crash when storing a big zone difference to the journal - Failed to link on FreeBSD 12 with Clang- update to 2.7.5 - Features: - Keymgr supports NSEC3 salt handling - Improvements: - Zone history in journal is dropped apon AXFR-like zone update - Libdnssec is no longer linked against libm #628 - Libdnssec is explicitly linked against libpthread if PKCS #11 enabled #629 - Better support for libknot packaging in Python - Manually generated KSK is 'ready' by default - Kdig supports '+timeout' as an alias for '+time' - Kdig supports '+nocomments' option - Kdig no longer prints empty lines between retries - Kdig returns failure if operations not successfully resolved [#632] - Fixed repeating of the 'KSK submission, waiting for confirmation' log - Various improvements in documentation, Dockerfile, and tests - Bugfixes: - Knotc fails to unset huge configuration section - Kjournalprint sometimes fails to display zone journal content - Improper timing of ZSK removal during ZSK rollover - Missing UTC time zone indication in the 'iso' keymgr list output - A race condition in the online signing module- update to 2.7.4 Features: - -------- - Added SNI configuration for TLS in kdig (Thanks to Alexander Schultz) Improvements: - ------------ - Added warning log when DNSSEC events not successfully scheduled - New semantic check on timer values in keymgr - DS query no longer asks other addresses if got a negative answer - Reintroduced 'rollover' configuration option for CDS/CDNSKEY publication - Extended logging for zone loading - Various documentation improvements Bugfixes: - -------- - Failed to import module configuration #613 - Improper Cflags value in libknot.pc if built with embedded LMDB #615 - IXFR doesn't fall back to AXFR if malformed reply - DNSSEC events not correctly scheduled for empty zone updates - During algorithm rollover old keys get removed before DS TTL expires #617 - Maximum zone's RRSIG TTL not considered during algorithm rollover #620- seems we no longer need jansson- limit geoip support to opensuse- update to 2.7.3 - Features: - New queryacl module for query access control - Configurable answer rrset rotation #612 - Configurable NSEC bitmap in online signing - Improvements: - Better error logging for KASP DB operations #601 - Some documentation improvements - Bugfixes: - Keymgr "list" output doesn't show key size for ECDSA algorithms #602 - Failed to link statically with embedded LMDB - Configuration commit causes zone reload for all zones - The statistics module overlooks TSIG record in a request - Improper processing of an AXFR-style-IXFR response consisting of one-record messages - Race condition in online signing during key rollover #600 - Server can crash if geoip module is enabled in the geo mode - changes from 2.7.2 - Improvements: - Keymgr list command displays also key size - Kjournalprint displays total occupied size in the debug mode - Server doesn't stop if failed to load a shared module from the module directory - Libraries libcap-ng, pthread, and dl are linked selectively if needed - Bugfixes: - Sometimes incorrect result from dnssec_nsec_bitmap_contains (libdnssec) - Server can crash when loading zone file difference and zone-in-journal is set - Incorrect treatment of specific queries in the module RRL - Failed to link module Cookies as a shared library - changes from 2.7.1 - Improvements: - Added zone wire size information to zone loading log message - Added debug log message for each unsuccessful remote address operation - Various improvements for packaging - Bugfixes: - Incompatible handling of RRSIG TTL value when creating a DNS message - Incorrect RRSIG TTL value in zone differences and knotc zone operation outputs - Default configure prefix is ignored - changes from 2.7.0 - Features: - New DNS Cookies module and related '+cookie' kdig option - New module for response tailoring according to client's subnet or geographic location - General EDNS Client Subnet support in the server - OSS-Fuzz integration (Thanks to Jonathan Foote) - New '+ednsopt' kdig option (Thanks to Jan Včelák) - Online Signing support for automatic key rollover - Non-normal file (e.g. pipe) loading support in zscanner #542 - Automatic SOA serial incrementation if non-empty zone difference - New zone file load option for ignoring zone file's SOA serial - New build-time option for alternative malloc specification - Structured logging for DNSSEC key submission event - Empty QNAME support in kdig - Improvements: - Various library and server optimizations - Reduced memory consumption of outgoing IXFR processing - Linux capabilities use overhaul #546 (Thanks to Robert Edmonds) - Online Signing properly signs delegations and CNAME records - CDS/CDNSKEY rrset is signed with KSK instead of ZSK - DNSSEC-related records are ignored when loading zone difference with signing enabled - Minimum allowed RSA key length was increased to 1024 - Bugfixes: - Possible uninitialized address buffer use in zscanner - Possible index overflow during multiline record parsing in zscanner - kdig +tls sometimes consumes 100 % CPU #561 - Single-Type Signing doesn't work with single ZSK key #566 - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - Compatibility: - Removed obsolete RRL configuration - Removed obsolete module names 'mod-online-sign' and 'mod-synth-record' - Removed obsolete 'ixfr-from-differences' configuration option - Removed old journal migration - Removed module rosedb - changes from 2.6.9 - Improvements: - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation - Bugfixes: - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - packaging changes: - enabled geoip module: new BR: pkgconfig(libmaxminddb) - enabled cookies module - enabled queryacl module- update to 2.6.8 - Features: - New 'import-pkcs11' command in keymgr - Improvements: - Unixtime serial policy mimics Bind – increment if lower #593 - Bugfixes: - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy [#589] - update to 2.6.7 - Features: - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) - Improvements: - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination - Bugfixes: - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback mode- Update to 2.6.6 - Features: - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation - Improvements: - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination - Bugfixes: - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- update to 2.6.5 - Features: - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set - Improvements: - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates - Bugfixes: - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations- update to 2.6.4 see /usr/share/doc/packages/knot2/NEWS- fix tmpfiles scriptlet- package /var/lib/knot - run tmpfiles scriptlet during install- update to 2.5.3 see /usr/share/doc/packages/knot2/NEWS - use libidn2 on TW and 42.3 - following modules stay static: - dnsproxy - onlinesign - moved modules to shared building: - dnstap - noudp - rosedb - rrl - stats - synthrecord - whoami- update to 2.4.1 see /usr/share/doc/packages/knot2/NEWS- update to 2.2.1 - Bugfixes: - Fix separate logging of server and zone events - Fix concurrent zone file flushing with many zones - Fix possible server crash with empty hostname on OpenWRT - Fix control timeout parsing in knotc - Fix "Environment maxreaders limit reached" error in knotc - Don't apply journal changes on modified zone file - Remove broken LTO option from configure script - Enable multiple zone names completion in interactive knotc - Set the TC flag in a response if a glue doesn't fit the response - Disallow server reload when there is an active configuration transaction - Improvements: - Distinguish unavailable zones from zones with zero serial in log messages - Log warning and error messages to standard error output in all utilities - Document tested PKCS #11 devices - Extended Python configuration interface- update to 2.2.0 - Bugfixes: - Fix build dependencies on FreeBSD - Fix query/response message type setting in dnstap module - Fix remote address retrieval from dnstap capture in kdig - Fix global modules execution for queries hitting existing zones - Fix execution of semantic checks after an IXFR transfer - Fix PKCS#11 support detection at build time - Fix kdig failure when the first AXFR message contains just the SOA record - Exclude non-authoritative types from NSEC/NSEC3 bitmap at a delegation - Mark PKCS#11 generated keys as sensitive (required by Luna SA) - Fix error when removing the only zone from the server - Don't abort knotc transaction when some check fails - Features: - URI and CAA resource record types support - RRL client address based white list - knotc interactive mode - Improvements: - Consistent IXFR error messages - Various fixes for better compatibility with PKCS#11 devices - Various keymgr user interface improvements - Better zone event scheduler performance with many zones - New server control interface - kdig uses local resolver if resolv.conf is empty - new BR libedit-devel for the interactive mode- update to 2.1.1 - Bugfixes: - DNSSEC: Allow import of duplicate private key into the KASP - DNSSEC: Avoid duplicate NSEC for Wildcard No Data answer - Fix server crash when an incomming transfer is in progress and reload is issued - Fix socket polling when configured with many interfaces and threads - Fix compilation against Nettle 3.2 - Improvements: - Select correct source address for UDP messages recieved on ANY address - Extend documentation of knotc commands - drop knot-2.1.0_pkcs11_check.patch- enable libcap-ng- fix configure check for pkcs11 support: adds knot-2.1.0_pkcs11_check.patch- fix soversions- update to 2.1.0 - Features: - Per-thread UDP socket binding using SO_REUSEPORT on Linux - Support for dynamic configuration database - DNSSEC: Support for cryptographic tokens via PKCS #11 interface - DNSSEC: Experimental support for online signing - Improvements: - Support for zone file name patterns - Configurable location of zone timer database - Non-blocking network operations and better timeout handling - Caching of Critical configuration values for better performance - Logging of ACL failures - RRL: Add rate-limit-slip zero support to drop all responses - RRL: Document behavior for different rate-limit-slip options - kdig: Warning instead of error on TSIG validation failure - Cleanup of support libraries interfaces (libknot, libzscanner, libdnssec) - Remove possibly insecure server control over a network socket - Remove implementation limit for the number of network interfaces - Bugfixes: - synth-record module: Fix application of default configuration options - TSIG: Allow compressed TSIG name when forwarding DDNS updates - Schedule zone bootstrap after slave zone fails to load from disk - avoid activating the intree copy of lmdb- update to 2.0.2 - Out-of-bound read in packet parser for malformed NAPTR records (LibFuzzer)- split out shared libraries, knot-resolver uses some of them and atm we are forced to install the whole knot2 package.- lmdb seems no longer optional- create a new branch for knot 2.x starting with 2.0.1 - Bugfixes: - Do not reload expired zones on 'knotc reload' and server startup - Fix rare race-condition in event scheduling causing delayed event execution - Fix skipping of non-authoritative nodes in NSEC proofs - Fix TC flag setting in RRL slipped answers - Disable domain name compression for root label - Log via journald only when running under systemd - Fix CNAME following when quering for NSEC RR type - Fix refreshing of DNSSEC signatures for zone keys - Fix binding an unavailable IPv6 address on Linux (IP_FREEBIND) - Fix infinite loop in knotc zonestatus and memstats - Fix memory leak in configuration on server shutdown - Fix broken dnsproxy module - Fix DNSSEC KASP timestamps parsing in strict POSIX environment - fix multi value parsing on big-endian - Adapt to Nettle 3 API break causing base64 decoding failures on big-endian - Features: - Add 'keymgr zone key ds' to show key's DS record - Add 'keymgr tsig generate' to generate TSIG keys - Add query module scoping to process either all queries or zone queries only - Add support for file name globbing in config file includes - Add 'request-edns-option' config option to add custom EDNS0 option into server initiated queries - Improvements: - Send minimal responses (remove NS from Authority section for NOERROR) - Update persistent timers only on shutdown for better performance - Allow change of RR TTL over DDNS - Documentation fixes, updates, and improvements in formatting - Install yparser and zscanner header files - Improve lookup of libsystemd build dependencies - Fix compilation warnings in endian conversion functions on OpenBSD - changes in knot 2.0.0 - Bugfixes: - Fix lost NOTIFY message if received during zone transfer - Disable fast zone parser when compiled in Clang (workaround for Clang bug) - kdig: Record correct dnstap SocketProtocol when retrying over TCP - kdig: Hide TSIG section with +noall - Do not set AA flag for AXFR/IXFR queries - Features: - DNSSEC: separate library, switch to GnuTLS, new utilities - DNSSEC: basic KASP support (generate initial keys, ZSK rollover) - Configuration: New text format in YAML, binary store in LMDB - Zone parser: Split long TXT/SPF strings into multiple strings - kdig: Add generic dump style option (+generic) - Try all master servers in multi-master environment - Improved remotes and ACLs (multiple addresses, multiple keys) - Basic support for zone file patterns (%s to substitute zone name) - Disable zone file synchronization by setting 'zonefile_sync' to '-1' - knsupdate: Add input prompt in interactive mode and 'quit' command - knsupdate: Allow TSIG algorithm specification in interactive prompt - Improvements: - Zone dump: Do not write class for SOA record (unified with other RR types) - Zone dump: Do not write master server address into the zone file - Documentation: Manual pages are included in HTML and PDF - drop patches which are included upstream: 0001-loosen-openssl-dependency.patch 0002-make-configure.ac-compatible-with-old-tools.patch - also drop all buildrequires just needed for autoreconf - new buildrequires: pkgconfig(gnutls) >= 3 pkgconfig(nettle) pkgconfig(jansson) - create devel subpackage - enable rosedb and bash completion- local state dir should be just /var- enable dnstap support for factory and newer: - new BR: protobuf-c and libfstrm-devel - prepared lto support but not enabled yet, still need to find out which distros support it- update to 1.6.3 - Performance drop for NSEC-signed zones - Proper handling of TCP short-writes - Out-of-bound read in zone parser for long domain names in origin (AFL fuzzer) - Out-of-bound read in packet parser for TSIG RR without RDATA (AFL fuzzer) - Out-of-bound read in packet parser for malformed NAPTR RR (AFL fuzzer) - CDS and CDNSKEY support in zone parser - Add defaults for TCP config options into documentation - Detailed error message if zone reload fails - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch- update to 1.6.2 - Limiting number of parallel TCP clients (max-tcp-clients config option) - Ignore refresh and transfer events on non-slave zones - Compilation with Dnstap support on FreeBSD - Possible file descriptor leak when terminating inactive TCP clients - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch - moved autoreconf -fi to %build so it wont be tried in quilt setup or similar tools - move up the %if case for systemd in for the preun scriptlet to avoid warning about empty scripts on non systemd distributions. - used xz tarball: new buildrequires xz- Add deps on the docu packages to regen documentation - Enable systemd integration fully - Add dep on libidn - Cleanup with spec-cleaner- Only require lmdb-devel on (Open)SUSE 13.2 and higher- Updated to 1.6.1 Bugfixes: - Journal file would sometimes outgrow its set limit - Fixed incompatibility with OpenSSL 0.9.8 - Proper handling when machine hostname cannot be retreived Features: - Support for DNSSEC Single Type Signing Scheme - Compile with lmdb-devel to add support for persistent timers- Updated to 1.6.0 Bugfixes: - Fix zone expiration when AXFR/IXFR is being refused by master - Fix forced zone refresh on slave (knotc refresh -f) - Persistent timers database opening after privileges has been dropped - DNSSEC: RFC compliant processing of letter case in RDATA domain names - EDNS: Return minimal error response for queries with unsupported version - EDNS: Fix interpretation of Extended RCODE Improvements: - Maximal size of persistent timers database increased from 10 MB to 100 MB - Added logging of persistent timers database errors Features: - Persistent timers for slave zones (expire, refresh, and flush)/sbin/ldconfig/sbin/ldconfigobs-arm-10 16523225443.1.4-bp154.1.873.1.4-bp154.1.87libdnssec.so.8libdnssec.so.8.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Backports:SLE-15-SP4/standard/5a02deb01ec9f919b8aa1b90d190b0d0-knotcpioxz5aarch64-suse-linuxELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=306be8d685753c83256808bc35297ff02ac54da9, stripped PRR RR RRRR RRmQ >Z#utf-8fd0f55c938a1e883e73b82121ece7484a4b6ca56042311b24519e89fc3147c6b?7zXZ !t/] cr$x#F N,9z„h\<ۺfocI[ao#;]?UlOquwTaިȂ#ق N-$+(T;sy-Wha"$ FLT4DIL*S~2tUjK,U Um2{څj;Ӈ2㻅3O`%#ɇ!Ҧ)JƆvR:^$)a)9_NV[ śCg>9x#ʀI3k AWF%y05P; w=u ~ĸ96u#HcM0SNgKuBE.s~}`3׉ֵ&Q.;ˆΖٝ|0Lu<^?}FFJc~B.y౺oWM&{ (z-^eXij_ Kw8H^swIbT_+z°Qx*rq$\ivle ̝4d  ti8u{ ʧGrxnˎ2BjR / i47a_%֫ޡY4o[ DRٯ@ KM\Oolj[##+ަ\qtn p <_N`\v\bd?<>zdجmit4h%%sȰj.7ՄFK^8FWfi1at‹yH+)f^ެ#!}}. X+ҝ\H&CWTp8~(dfr(p~Nc,Gc *#pPcfvc Axcw'Aq}Y7D CTOr4#L@\8o!1|NaБ]vBR( y ghVo!JAV>@r}CCZ] 㧝 =D11K#@kk1k]x\!6[?HAlCpimG@uTyZbE:ؚ]m9rb\ y-ϲ֧ ⽉Cd\FWtb(-EHC1 4%ÓrmR$E)Nx-̬֍x}< 'eΉQBq"g~ .~@TFjGՍX$`C_MHZibE>* (RXoIr &Q0?9jw3JoQ倧("}4 qa=P, m.9 Λ7u48°AW"%Y""ʛƗ^n}& =,[tm=O\1}VwK?g9ZQjJCdw=ԉ# { Kɟ'$[tM'^a]> LH 6tGβVʶ+wk̹3isTwg-7Xz(dswmB$n# F/ w|s"m{ 5/ kNuZ^b[F$#ڃQ֣SəP0o' WZҌL%;-90č\pې(arQz߽0d>FYR!1'bqBjfxaDIZkw`Ů@$XIJV@P9$@BO:W ԫ̻UIs \ԏ}󀰊n3I@( \rK=.zuN-&]x㣦 k|vBL=YMBc͍ga1b* 8@a `^S(g #.{!r5 %كJ~7Á;ԁڔDf N3B>n, ܃0HdTERW3,'s.*;AuBt'M"+&p7neVl!%<|\%7 4+ūwz0pY 4m~DEZVg)ȋ:b1| BQ`뙨iP n=g;!q0{fz\iВ Mu/%@-GvQV?曑JOM%\ u3[އPXjB:Z_euАQ=:!"Kjli`O̠b}L-ϮPfhQ^ ʎ AhlV[8D}ET"7[9-l?Lt&߄a>C&s`; ZfC^/@.V1#inP+s f܌ɴh6#FS?D=;IEt# {)ڧ-{p٘*n1e:ݷ~fML\F!p5ݸ>7 "cݮߠ-9әxoKڣ+7hߘ.e}^/d!9 !'"*_Ev&3U ޑc]/ḁ.WK,Pҽ8x2by-|>._Q:kMb̻ k j欋<Á3C|K٭Gjg $hDLoH(mMoI"{i ))H0}bP80U6ʔ3t=a9M*N}Ϲ9 G &Vߍ?lkOD9Ȕ`̶ު{ndqY&}}O6WBA.N~P!pQ h#֐]qjtRbbHj.Hc>Cr=v!G~ >܊em4Cj+8ZJv"}1`ncƒ+8! :>-L&s(h7j(;ZۑIAĄ pϕA \3g\}2ʤEq-"rjJAHҤF!-4UMſӍ?(r~ghGHϻ]v+9-P̈ rtp c kaL8u pPD Kò^9J ~R/kBKiw1|6%DٿXuѶzňes}Mֺ|L7s]'gZr uBk>u\r["ڃ\]m>،mA.#W8];ÚˏBYz'}z0,rj tIſN=2$4a!gƴt֚~Þ-DP=`\] AJ\ Z39;ݐ(*Y]y>J9JU!ɳ`==U/M&! +G%@m ;sgc--Mܸ JIPL}Oyh% \j`/bY&mo{Jd5^Ͻ ` ].B0E8 Im,L]*Pd M0abʧfwZxVT+-[J ?@$2H $~m`+֘Θ4P 4I:3d'7 O | j软%<NI*ph,2v'0H'L d4_'U/qv,1bs06 fV0bn 188P[6ʖP`C1~=2V:Ҭ0gC#(8.όPQF' 4Qz)b7T ֔^݃GEb; <}j_(G7w)r* sMi,#T/(>z8% c>=o1x,ad̽/,x2py㼕ѐVG&Pz){uEƫmCK_@xeXI[)xDgb9.I_GPūkst KY#!D8^FfEpqK_"fh)i\ɟ n)>M*VВKmci&uVx__Z44&&p)[#:4'#{}pSjةf0Ƨɷ"LDr>#׭$:^ꑮr7W`\N/hD[sh!$7W$7HK0ABAED (ƶ: ͍m4;Rʻ O5fG/zqc@# x<򒸐z¬Y4t-M}N1SX^g5c}U#YVtN3 RD!NCiC`$bWEf>dpn";I# a1%Byc(=GU7rֆ*Λ*k <²Yʔ5D=vYqXg>˽@&BWA$T/ s(ߓJV*E" 0RG٩D%=± _q7/=ޠYmDG*#w/x,"[_<π=AH:Ptc#\{Tʲc6m`t,0% D炟s\CGKmg/"+`1)?`6EaȪӕJ濙bqnC.:#Y-`7< W˿D'HiuR? @1广tV \ *kHgԬ4åL65,: Ђ8THMƋH42g-$&eZ 86dEsRtы$ig_[l@oˎÜGV B=|O~Y3p CsǸ3KfdhPWn{=gPq8U8r*'p"?NAȇ} W TʏSp!UV**f5SdXnki'PoCf@[IR԰PoNN0F2Bs]JHrQFP UQC(_o]R_SFn Tظk#F-sOFOBlaN&|Ý>;29UTh&a\ǯMH LN#Z./l._-D"\Ng¡^jTk*t_Իz\5mtz [`P, P̟C# ⹨ {$V^] p:ޗ3,Ep-P:&3YWuA1V@l#5֊D/VA%2$doE-Lh If%YGИ{Q\z.#hfK^vrap>Oݾh7\yH=9vYITf[نyK9*^T~R}%Ջ{UOlj ϜMi|"݊Tsi^uQߝ+s".{یYHSPk^(qԓz90r}Uٸi{IQ_L7o[^m"f VԺF/*bU&,81Q(ܤh\L\@JFfg. rWd\3 =7gyM0? :c[MTmۨz ?s A~nNJv`&;E z⃾԰Byݡ ӱwu0 OlP. VnV1oSGU}cp* Sbܢ@z@c1-V3SM0mQbɎʇr<<5bvnj ~]5xڪJ{qEَ!So«; p%8 :7w.4꤅}o&T %k>2HO-_*핊&0,"FmOkFd 0^ &5y)YI&?9@WxE#cG)=R q|{! Z@a| O'HxMIYD^"_1v[` k[':oG&ϘT>[;}ᗬ썔WՆL>;$/`N}:tu_V-XNsut{䰳6Qz2w |Ř[Ll!<6Gxy O|7=XVyq< *ZNyИ@B/L+޻qfMW2.үqITt1\r ZH0Ü׿,Gg5I_ 'YdhLB4Wձh1]#\ܨB6*zT[c^HD?h>Z$tYƒz)̣ZLW>ŮɕVҲ| `~%%5C7~}l (i޸}6q$L"9񭔯D 31x:}_g^~wMoӦ.A`/THq- ,ɷyGS[%"1n !/LQS983N1-tQTZ>%ߟw*P{q*Z0(d9=Sc=7FFA23}*l ,`\NvkD._|8/-q!Anm#6çDG>ڽb cRr<<`lTwMjiB1?JY'dڷƧ$MϲG>q=K±%->-"J!PBSZ;L_s_ߵy' Lȋo`}ײKÁ`5@y%wMX J6Ay5䩓TeIѿ #]WMF>k tz%+rܾ/&P%Ϯm1MPj4?w%7Nŗdg'[x\o#Z](RTj_6ʃ@C֎%KkJ9؅\#8>lc 7@'y;/>c#E<.v_ҟϿ O2qLpaqt*Fmه eR 4,-V58 BhŖRqg=_WPs6tV;dŞ闌aN<->}1%(7㿜c46Bݏ0b?쿧&g0e7?DgdC5eXU*i/ pn@u6PR>%7 ?Q`پ*!υ_ZbCm/Z/ q^Z{*(wLwKxش-9ESYF ><zDH.]v.%~T+.xH f]mAzMgbǏP[f 17|N,Dd' NH}wCr߆v@H֛iU?]A& ޭا2V)S^>x{->Oh;_~`QRDnj[ ɦʛ EtNaWSvm+ .ur9^7RL!5~'xGy]/1X?f`)pةYZ>k{Aviu({~٤;a l)3NΔ:,F U=N'0pۤFur4,*;ەgGrڷ{[3IwIW`@̾Z<wކkxכPrz+-=%VܾP 2oN34'gEsLnCS=>ʲ 1@Tl2, K*(c5ocfjJ!ȅcTtqF?^OUCT%xi̥:0Y+0Ad5o_c[cd=aAu=!*m]i-AjiH#  %eJ&*RHR.TqE(``9sPlO4ׅycIpH'O3XhNu+|q X:%?z.i J%2>ր32畭ϺPDBWc|k=$ (|G8)U PAcW߮:jpF)fےI|bEv/ZЃM㷚ս{f!Fe׀TH悋XѰVB3)g5>VC]YncY(c6 hynnu(|Co Ѣ +q67k.|RY)_RuCfwCa4?MIXi‰|kצ,%3RX_;鱙N3݌/wy5VYK B&+jV4$ J6Zj ~D섗;*yQuBt$-hB16GƟ[Qp~T|Y[{I.P-:ģp^ 쬥^n,H(F[Z.DԄ)֯黆 e)=b|`rn$nVTϾF\YǍ؛ȺF;).m,J iN~/:ؖ;&a3b\00 %kzb/C~;ji.>$)aZCNʇ7ebW5[Ȕix: kDkƸߏ55Eh;$o#r_T񣾘7hBWan1vϳMJ8'MJޙ_#چ< YL |!d)?S =N0D$M$c1E袊q\C}!ofmbb0ȯHY9#BOL9D&I,,Ӌ12%4sw0 \, !)ɳy2hނ!#g"]yP0Z`{]^'0- szre '. U- 7 'Tss f' 힧\d[  ;b4}Y *j"$֔eF3.UWOXNt DҧX"o׾h/T䂎u˓+9@+g~I2ulxDzuOSj1W2JwDH~uϨ3xߑCۀ2 щ⻘{l<"/^_~HeɖV7ԯ[2mR'ƞAfg((r3*uo(umeb)kάT,ަF,g7e\lReV`E7$؟$6_0U$ W: 16jUx k^x%m8b=Mbq×IBHzL$O-dz-nM3(3#EyA`BS:d5qqӋnM<N !~=MQT0jϞ|zIH;AǥG1nP<)B]VSMyϙSčÅIaвI>ZPLkYơiyNE.kTpE(|V,hy[3r<c6dy)G.o/U(uc}]z a#hwONI]*|GR]EN H^neM>[z8ZݒDR YTh.pU<P7';/<cydMk /暬bV{<-eFm':EZ"滁VԇZǥKneQy̫ D>^ȱlq.ދG^UwO%pp1ƸJқ|QF*K֤c2wf֥bsnX9Lfc8<2D)C',gTd:U.#ti{n\Ra'Ѳnevpuk};$3Qz8U,$N׶ve W@=\ .P[a׸(u@gX7VXo)>Ovg9,q s ՄE{Ho*m޶~&OTC?^@ *>~w,ft8U} .Wh 791<(7 ?d@z0zugѳtkj7SXy&&L<;U~LMoݖE_>׼'ZyC !}ם"E.kFby;se6\h7*gP?X{>9р R+,gh/ 5ߔ/0_SCx@A7.ފtp)׉[j92? p{Wjowbm֫O'a骛$V̉ZFz ]T%FaqDBq#9`rGgRķE3ф}2M2H`Ϗd.p8KQgPE;G'rO"d0q̻QߒB,!ūQ'XzN`rexTXLILgo -ǖNh0ItUl!x:jBI;\P@=RP}SL#PjQ@-0E( G{~OB%B%')@B%kԚv4RD麟xqSz'j2kR)sE;Dԃ{SFp$FX^( J? P}8dšhR>QWDt(=tUjZGǢ3CoD;kp߫iaoLkӖq㋢y?щ/(1{~0zdߝ2S_V~50ш+35r 1'%-f)w݃+n$Jn$^g=;0R Ȳˈ.ԠQʰcMLWpoa~3"Xs6wIF\<'ީ+W=61N\펰;Á$K;/rLH͹)g)W芠_{ !ZY2";2KeGIZ*1 k?߁5\GohhJrb\)532٨dW&r;hPk`}\Fv۪/JwA:4$ :A};Z7#K33U SV4^1-%K$`ՔZ0 i\wn]4S IfUIАշ G*#CWEqqQ5wۣ8 tUTWf<ƭc C?PJtwv,Oe^5FܫƝ$cF Çpb8+\ 1w.⦫@y)*EȏE9l&ٞA+ qvtQ6= yT;.mwPwO@՚ H6%PAGUsk!"%@4 *X_7JKfbr@g0p<q0 xT?4n0'"-\Hׄ-iYJ&O"/ e;,W΋KɗX sEWE]<{ДdfdH&•/@jۡ)B8pg*|Fjm lU leژ<\mj&PB#K<|ռm(L%3FLOlU(FaG7 M=Ptᩣ63&@J__!c+2U1md !שq>&; 3 傮Jh73#&9.4I~]a뇕Iyk]g Ώ6˴>0 G,vo(CP=l!6^7ރr46Ms&2rw.TWUH@+]ǏnLbG0VQɥKqk0vUʝ5wYˊm&tP:C TLSR56|Dħ? ]0/ ,T _A=˭H1ݿoiX@ε `h~fEo7:!O@SE3?ac@(F7~3Y5:ǵ7(^Y"udkyfMm^sZQ z/lwl *[AxC兟"q+̱,AMr)Qi mw8-+^gȊE}-&PA<@MU0д=a.0S@_t^7Bbaaz],$G Ѯ* ΋|B@Xs'3 ;GabGV$/a!2 Kmxq+nt T;xTsf!Ni&F3 P+u{ɸoYB񥄿Z&CW'C0Ѯߤ ׉]: {YFg{ ӧ:"wZ֔VۅrfXȄ3Uq%sy{vT1p2 0~/sG*Wٞ\\|B"-\Wr}ȠjTܣ2BCSYHzzAvMmex%8[J5dbD0Ui9N" To{{euͦ񪝀 Bg3ԩHwV+'s=gGI4p5}&4o3@ǓettFMN"᾵w?{s+-Q7t•U rK(erRa&Er]ghUOi)Y /$c .1ꬊ % KӷpgB1P ©̩ND3"1 WE*ƅJ :I=^-'q%}^g Z\@-38pk_߽kN^ACM#ћװ1}ݤn$ 7`CRy~C+qH7(F64W+VhX*-ZD#sJkV&8'3Mƅ~i}u+EN%Vc8* T/X*j E ~Ey Z:Xh9X9JQ]t7̒RVwp= H&$UXU|RPB@+ g0e O^5(T8+4n E2Q|J'n~kSK'6>1B"zYQAQ͞td_Nt1Ӣ!>A\y&A?3liϥ)޿>A]=Gzg`oBѭҪA_yϨHNgQ C92U7dDtE|fr :P*xrHFG$i~FP'*Q+vr _i1qQd(2)4p'}LoC^Hv ct<: ir.^ }]MұhTODd TL*wf''%p75} R e,(]AZI8Y4,KIu "$+DGsH=TDXuK͵4,gh Zg}͖Bn{F"\r1b18WMzn3)\d".ӄt(4;^]k]V>a&l \Y}ui7UB͢[7Q'ҍ'mI2ZPD6Bd%oo e 7Ì8O\Yy-!, Ap_0 ((ڛMSk)#v P3>DK8 ,=)kț6_Bo&b-Fr%m*_f U~+yD01ŹwPgQ]mTk jtgNȈNG{\GNtAw3\cPy9hZNB Tia, OіO"s feo3e}N^D^W:o pq` vT>1Em$귥cӺ0J~CEu"K#ҧ|UĿ3T9vvC V\.re@BjrZ-Q;|PgiƗ(MbT(i߼% ǙkqG#ap}v@6k_/> `Kvm`KË }.F+1|$ԗ<@ !hucSܼA j _-AfXOc^Vrٷly9v(J1්i`C, L=LV0ɪk wÒSRP30̃JP&_Q:CihX JK:j(ר֤TI2aa0|}kijnW\ ǧMxk֔0wx5>9P ݟVy6@D9HFJWZbc:n%qvn+%ʸ+ī.=8^bfMIZ9,iP?yq[M&QCb BwJH^Y>"&O8Ьԃ*fRIwj'QfK0eˆu(oqi,sXPq %EtR6G Qa nZyo:kxqC_CVڜͭ Hy^)╭o5\C|iLFt6k !iZ(*C}8ׁs83ᚚ _r>}ń{ c {B[ >lD01l?_}˓4R͚ aLΏROԶXa95<G%~ixK{* Tphb|t͓V:A0&SGmZC^I?e+=Qx0a Q(eGIPwxͰ*&q Zo?հ9pNȭn u(zU1E,|o[ox?P̆V+\V^fD3tkzl%{{f=b1eʞ ^i&qyU;T Ɏ+  <  #t-ʰIe_@*"zd#G{;DQS.E(4N6 :ɹ]f h[y˅d9;k @ pQXleWI0-LrӋY]}/8qA}~U@?Ng̖4v^<ᕊk3 6>3b-Ja+j%^1-Z$| QXV#4eLjǤ%_ظSϻ4̀@C]z)VHU%W$a\XpT,c]D&-aJեCW\PZmptgB[%X~ځH5*YzAx ]8}XLVZv׵ ~[}$2~WƠr/;ϸ˺0v8w b \:O4tt[ʭBA+a*#dnH_N٫HhF4s|ǿTFF=KK[fmj׬Iqgΐ.Þ-_vX,4tz%<҂ u_=jas-Ϸ”_Uhs!igļpmI]$=q@ uk?D'Fڐ3=3g?[Y@VZ댲t P2PL`&)8Sx]EAƇTCBsC Vͻׯcݷ~0^{شXiVhjȱMGE,y57!XrZI׌u-n16CuPn-U!@7B G⽯nv^m p)F! |s@:}.UW juy&^Vc(yUO늝~{R޹`yΓAu' H@OPA5uB+]k']\$7CG5D{|?o83B3* =2p9tXٵt4n86)@`+lD`I bvg.uoj YqVbG &sbtc=|p0!A0 %'sLQ=Y >cHPxڨ6Cg+ޚ>qn&|L݌UIJ0!NM*c6.\6v3eղ,N}H |OBuwzD^%l.I.=ɴ[Irx{sM`?<|3'#c#L_BNJ >k ),do(z'DQHcxkKX:(ɋFb~H}2ULGTVeƶLU>[a]nIHY˫ +vX,e%66*Z.ju׏WwFӑ#k-&mJB֝ Gmwt(vNyT̍^Utس-TkH4}T`Cnh!MkqA.z%Zz|;!%zS)mYce.$؅GQf(6}C̟=q"iw@8 wfP W)4{NIMq mBlѩ7MId< 3$U_}PH!8&Q]`UZ:ZNt:/]41˹h{*l=O p>aXa<|uUY:|MPw$ބ8M„ັZ5vwu6BX|vHb }} @#Wt8%{Blp塀NW;Zh]x HK]&b:9n'zZP#*+`J5 ch 1dޖ)x%6?U}=`p]ލ$rz֓sQƼM4fƣKḷPU@a\r8QeO]VK!} dr󗣪CaNdey %`@We &tpMp//Va4^@'b4ΰF'Ll*: L)clxtn ja^8W*p(ш+>iNl\*¶C˫:\T?-Y/50D~j!8|M!TϠWi2dA轹BJSiFT_ق@y#=MARl У.X=h0 ߥKS¯5)83v&87&&3 rr\A>/뮼 Fy+w&h,:iYn l3N$)+Udfm%%?q so(0ó*BT`;y1bk5Ϲ( v/(*5+6 $Zu,ȖX;ްAI X-_ aN +cB%b_S< l/F9ks[ t2]?VZϵ}#(KF𖖌ScMn*ұܜNusG\H8 ֡0 F.v"(njq}=CwPb=iؚX5XN1ۚ)YpȪˢĿO7i܌늋ZݚݮQS?m$Կh=X눀&{ሴzǸ*]G|9PW ~ gۖ&NTUnr;Z|i\h2 i.&*A-SOU.'!{}/6](3?L##X35bbl<^7;WJ@@A^yDqd܄/+5R̢{vפ|]S 18G +4JS6îxR&`DCd` Л~`wf[{FwήZX\شwC[PCa^BYȵR->vvSEqJ&AR_ibSxJx{J&J7V ]!{/*:h9V:q$ƁFtu1^(Nxl& >葸.<pߗ |֙?ϭg-TvSI CrppI~iOf7)/F T.@/*kaS5u[\j0 ]@ur;}h5M2̻B rU!qݯ"#P͖JѪ[LШc",.U%*Q[^p +emR5cɇmA*vv[r@o$X̭]w[5(Sϧ*U:rf-,\ y%4Pb'{"cݱ2? 81-+&0z-o7'(< H5"'oVH Y_[!cj8 =b!r21_ NO:Yb~`5Da7A?,!NAdKYs,iO6-zT6B\`;k\l껻7HsYW0 "00Q*OQ=Ka*D99j?R%@9:V 6|{0I0 ij {ۭ:R-Uʶ@5~~3܍VV3v~x%=/ΣL/F]PW;y˻,`6"VlCD1+H]vuPo*J0F0Qy 6bp!#'YU^}Sz"PmZ0ғ7n$MFIz%;X5k2 Y2Od7*S`Vr) Fc,z"!?G^x"˾+C:! K4ַ,.iCD<;f`xUV՚,LA.LֆȃRyѮmeq.+7{g7,ALsޤ%P ՑU5O5AT{:*`UZIBC :w MN֐:1㗚"?!J h\NL6 ~I 3C!pa0xX!񀣩 u5]!=3 o;%F`H| W!7K+Z-\$uM)UD[oMX;tKs]V27%|$ 6m:^d4yB/2Zps/@5oTBfk 6A͸Ukz~_7gnY:s th&βaݺ=@h eNz= QE]r2-9t+iMgLVF&pkRŴ>y 8>%c o hʠ@ʗ jR}E]ɴ(\)*OKd*((nTc܋Ut%2}K>C0]SXeeNPCM+Qsi/)Wf["73 ۟q6p##`̠-S nA[~iZdJ7.5Z(:P4IEdP?PvN7V` ԇ\Nmwi 7K=(qͦ!L6;{{PX㽬7Ou%Yֶ6l4Xϣ1{ORG[TolF ^`:ȑ"mtfV̳s -92 egtÚ ~M͙,ް 0!!Z ~.7uL@u!3R!Rk;uȇ;(>0!Q`>=go$}?ѝι@r4e#=1x ˗o4y/\{( דV FJ'0[0P5U1‚+Tuz'[˂&YmyD8kFpͤh&Z*+Noi?ۚA:5zic?@qcu5p=<39?eH́Y~@[eG?79Ч)nmI]9fi beT'4N4AHrU^p6kƓ {#釫J(D }ns3lJT33W9^oɟ9aϋ4dz~(9j,!R+MƳOjnZ8,y1Ņ71WRxMۆhlÂˁ-1E24EVSr|U+ IoE%;Ŏڋȃ|O_RD[5֠_ؙlx!|`=;\%:!t'q8)N1 %q6G% 5jUsO#>kH* KߏoOaĕ*1}ONz`JM}龇!I*A%yҍP\b<ᇝiL"; :[$zr; n/wj2w>N[eö<*X=9JGQJy78~0`C1K)"I[IևZGVd"Vi7-#u>t{/81z/>dp;}CWZ8'ң贊MP"+FMYYw<No֔FÅ4fyX}Ӷ~dO?;m(NFV×OdDRTaU.,^p}EWe.܋pay<><^Xm|ei5iLʴ{cbހ-Z%>saG`ݥtr.GyG6kH|R轲_6\jˆ\}*ŒQ" a^'(@ 9 %S8n  |$CЀŮYb'!U =Tk.^m I㭃f&:APw["k8w 2 ${ȰsCN6'$/ kk?q(R$M9u{lڊ4 "}$jRsBj6S*M@ Nk`hlf`"Ʋ0D:1;joeyiKL1AW 6n{KoAϭ3>Qb= q>JD^G UA: ҙ#NT# Idbַ CF8D {Btn~?:yz?(^t[@x򊺗p(? 9~n.5Ү#ODh=:.2:͌_`PҌzg>O&S>I$][pGq;eKca'nL,eS$1W_ PM(dT-er &w;`k&~KD+D/դ\3~bt `'CE 336M' *.M.Sd9;7waЏJ,50oϬh?#[Ah\]LJund.LT%Df|}ж'rƺsjni'm`r612F[G#6F[3$ն;hBKHʁPkۗ9q^l;rhVº-F5͝bgaA&pfVy 1`q) wk->w N~dz!2YE-͢j'e-~z̞7*͞ s㷄{lX(|Ab ۦ' Dw醥%7;:Azэl?Ued wG>/"}5,w_;hJ$^;;c ͗Mp5wߛRE-um0Ί`ff}YncjL3u %e2{gģkڦ&I{ .]]3TԳ,ys~Qmso->߉ei:6ӂ5+)8N8u"LKғ4|y%ϘѭuY]ASdc>!*EonF/g ^t-39GVl}=2 ܒ0 DĄoFӾa'1 1>-<*aD:R9} ]Owj7$ihϊ KgIfrħ<z]D8uٽFՍH!ejPX/Jl;žLVEGN2*+e'EHܪO?ߺz1UVJ~[,;usTaJ8C}<8ʚ\p&ᢚ4Zj"QG^H\+/^WNI{e;{S*Wv:T;^^!fppmsc4m(eR* O4@ՅH5>ZK !?n3$60>(H* =7cnq :YD-s|eaOVH*U> $\iF_stz.,Bn4j)3n[<U-i@1S0sv/T*lv1ߖW"Yqײ!k 64~88]T9-yn*tjl{4)Q E,AyҳLBò9EOQy]zXÊSVb&$]B*=&rE$ :@`=⇬IZW׌P抉nz(YtDK`GkpP6b@Q/+5xҺ(r؝_nQh$ a8vV: DPcIz/lAG$igà S"f>륌:zդ_Y9AA8!X_Pfw3L6Plc_,+g^IM Yr6qKythR,leDzw$oQ׿]=)_ >{<7PѪydC.GrvjBԌD>|W3uӆnY~U:0%\VXm l/菐G z qe?iy{!헄ݥ >/@HvQ褸@5L Ȅ&16I#qH:krmDyE`-J{n$gYT ;?1j視T+Œ:i')'_r&~xFe2tΡ4(tp=UM]ogȸ~K*R@[ugl]}u ~2Qm4AI)q6*z,7mgJ赗4?%\%'K۝S i∑oyt4p7;p>00wq ;+1&;2Sx%A&Tg/i:O; P;< oXz.l5LC+͞yLtf?jg?ҹnGM*C/sq{v f/Q)ɴꑀ!iޑ=0)+vJl_l>̎4$̌aEct,3U~q|Dv eaӿ>8C2K v(`}<5Kzj |j+VhemO >/^ ޥ-\%.hWm <|*| @Ds۞ QZ@^\xK[;+}v}`+d^,A%)if{NZÒgTd?tR% jf#/K(4" j4{%Tz`E;b:k^h`I ;%@3m?X(Kw;jU 9fcJq>^$2+"+O_J&&HzXɰk^Ș_3Z7tzBn޷K7hOHWS* xqmٗ%_cXy365:|&Бl=ڇ}=$  2](_Py.t-XۧBW&*<84౴;V )(Ls|Ŕ(,ymT;wi  Db̳/5h73x /p4a i-#r yWB?7)n2ה**"X2y^,xqRy)YN؄obccÔuH E3m2۵MqM8rL7cV!yh_F3ڔŪ66h݇+n&?H5Ws%Ԡtk'4Vdf3}Rf혿)eM EEL\.:f *(m>O0/6,K@(t:1R=H304jf8t -lHT Fvi.Cop77Z5W<^nM[ LZz1U"q+d{wN٤bd$(L>+r.P{x=3"B,x &_?t4pN_V |Y'~vVDGYTb0)4X $FrAPF~6g1JwsCpPDOVrEɻJe zʪQp]_`f0!mac0h3ո:wlI h 4u"燝# l;:TGڴm}Z$2ge#,JuF3IM'a-a),q G{<-5_5+f?rCY[ wDnZQ3~ q(VduBb*TUMX&zzZj K ,~m1q}TJ;ln8ZeY-,ҍJsFʃ#$dk8a{V'w܉#ZEp?P)"ܗoH1kޔ;IXSj.ZX &z3*$BC+$#':&gڰY.rk+BAa]aMTe/;qnoPBrT&h-&Ԣ WFڹ{.3Gr)[Vנփbk>e su59L.[r|&Y} 1K{3'yc%!E=^~Y90cGwr5]D5rsyD>ȧ:eŔ=D0IڑaM31r߄`f?8+꾅Tl&LOjf'σܛRtO jX|X1C#MҢDA0>EZIHRֺ Ǹ+"ǫ&FmXAB=Nߥ:iiH;Qᛲ3.Ej1R J_sua+nG:#J͘cm1'/J_G=`$ 04'ǿ K{|],wINw袐I-Dl.%DyB¬Rݳ}XQG2 ' Jn'arɆ/r*H-~wΖq#ȷ[2(!PKU 5L&$Bz, q XjRqJUL0=QÛ93i$H;~o>^B3JeN)?EaU N3X K0*XAsR-V6Ǩ`%ƻ W̖ _Ǫ a1  NEBֺ] €lKm)i \@068^_b |uU>q(? ԅeIVX6-~jLf-NosVOE$;8B Q(\)o>!f~BG ; M e}Ub+m~9I$7CR{\|7N4DX݈'RmkCb7zaTXşPF@>P~H(PWBLwU5DˌŖQҸovL*Ҍy ~#pOٔB!f1zb=Qc]U,kI[|!xu-e<*T T>" xJi5轼X]iL5q#"],ۏOq8Zx]IR}W t `1ʼt$w`-+ҨC':T{ygB]s:\v mm|h38+00?, /gŢW>y$ +ZAr͊tfP k0EI9{  R_`oa$*zYѶ0RR~邲WqPG.%ezw=`m .rmau2H=8"ChLjPȎ! p> 'u3N/? ?z6")+5cۘ$Y5 yeYY LdP]tIJ  j7r/ǯ5L .5" ~&mp^@i~e^0bԾNزk?L0+ϭ!hm !4_Te9'㯣}+!L:gnuC4і`MM9XY5y"P~=+5  霃du%J賖ȜW_b!҂^f΃dMdPR ^l2tsWh#`s(ᕋǁ?3sAo3s>"‹ٝȝM?V P[{o uUTbwɹYEhWyO~؛+V`8}[;*Sd%Sؑ8Y YR?$`ysW$S4 iƖ-bK?Y^BdoM3iGl}ĵ>4&wbN7ߐQW)I-.M$U7oKΦxf^JjtѫmR㒕? T~xFҥÊu1QE;Khfb(G2*X˯D=qrN!t޶Hz 7gEJƖG&rp^{=i] zx%d ԜO҆ۙ{I-&\x.i\%}޽]#Y XPgCY߄mNv1JI3{zxf܏cLqqXFLn<H/JǻL07ʴ"xuiG[u)tݱuZ0 B.gC@[X}6y= jGG"ɠKrhu YoS@-GM,2֑ yC:SJ'nw5!wǢh Kky?ɺsKqE]XaT;[NDnHhS+0X qY'피絵 pê`=AsQ㕓.p^%㚐uʔS @}L`\U|I󂗦lI;שbi*3oqG~XsܮqD12O͕_!ƀ;JT6C^іlTRJ|j,b![Y DArk$"f`땍dn|;= ?wǟN%Ek=̵4ޗRM#e9/̺v5C)W ).vR(ji?$79_ۥreRY]NjqD@cxw =ENP@B pax]q#<&f愑C6}SMu~5HRx)F4͕9e_/Cãy{8KG8 0d|)~Gh+2Wmރw*aK^rku'i7r,'sJeNbfn(- vW;q/ڨp_7IG^RC,sl!Җ ~}`;X0A~`T_@Sp[f0j~|3OpxG?JdN a#U 5"F{`7I뮸!fEpd-it3DՋ&C}N0PTjɽ}&s 3[hlek d2pJS̔Jf(,ei1{].I>it/)@ t,V0~mN}[Fm-p $V¿fX{n2Qs9eDB5|hݦ'ڪMH6 fSǘRqr'*6*y"-'R[`Lv&ˎ{w(\+Iܺ~*%9cK$]wWEwk'x\*Rq&Z ÷Ü5c<DhcYD;Ø|tHNûqP.BIS.C制iC<UlhsJFm*%eH~DhX{BgyƜү-'s٫T9I^e;@"m(ILMmwW'=ab UnޮT m+xtFN !* +仓R;0\ИxJg}sq;Ezo[ ~Z#(GdT<ʪu@S<)}sU:4n!YX"YpCI{&*/"ϰdV ź( |?1TЭ os5 |R6A38Zm^8V"mȀztS|* w@*VPЮ+$@U0d,(2⃛`JM5e{oȩeXA;x?/`粯@5a,K3U 3i.BP@m}-M Hb|h#|0B)6$CՋC3lMuܻ],Aig/aiK>9~j~y`J?27ɔ5}4 J8H$-i^71de=Y$`[^י5>$Ik̐p]4 " [{/(."x"Lmwɹ%jA!bPF<ėEݳ7O$*%wWG̗d?2rH(@tVuNa+"o)xAwfC,o_u;C&gGV)05 O @4OF)@ \yv0 Gy;6Ï˗ӜG?$o eDoʃ#BCO5Ն>z=z*Q7*GUH ",K%Ʈ9WK(p='dzCӎod+?=S Tc(34)5~Ly~!忶e0*T|3fw+AYBRF?cC@Zf$5{d\b Pe{EdRrM#W0YtsZ2\NeXKP'+TNwsU9}?@&m*6UFHU8yJiHMy7rL;N%j|TVg&rtISgF@=<'W)48h=n`R'*wT34j7E@mpH4Ϛ;\>ΦamG}i 65>axΛ{0pQ1=z'o'$OL-⊝lw-{,ccmuZ' q$6a @9D=ܺl M^!|xa1IXSǍh|cv?Ptr`KܭV%&*hK K %((J'``Vn:̄jJV1崩AP%ym~9cF"Acʿ]L lg4E%h/v rvEI0T` zͼ1 k%BY?3*SQndNw.s!˲&:p#& !'`}وR Q &)#<9esƌiX2:f= U==qDdSNze YZ