libdnssec8-3.1.4-bp154.1.87 >  A b|sh!M@eee|Jwi1`SHN x^GX+-1|u{>6@3*o&D yG 'Z1|}P0lxW^43i$7e-P=T8Bh(=S",_NOVJ |VD=GCdwTG(SI7Xs] &т$4'mvaFܨFݣUew\;X_!0(iT&V40647a46ef3a814d87fe3d1e9f9e5f6256fbf96997b78d9637abe4d39ccb206973f79a208eac9edf2fd5964e6fe663b150089538Hb|sh!M@eee=RH?Ҧ:q_8YkkqQ4 ì BdN0< v7q0n4ꛝGO)T]O$O!&Q@w!YI,]h#)958e"{%Ep@hP?h@d   DPT`d     F \dnx4(8898: A8>e@e%Fe4GeHHePIeXXe\Yeh\e]e^ebecfkdfeffflfufvfwgxgygzggggh<Clibdnssec83.1.4bp154.1.87DNSSEC support functions for Knot DNSKnot DNS is a DNS server. It implements only the authoritative domain name service. It uses a multi-threaded and mostly lock-free implementation and can operate non-stop during zone addition or removal. This package contains a library for DNSSEC support functions.b|s:cloud120SUSE Linux Enterprise 15 SP4openSUSEGPL-3.0-or-laterhttps://bugs.opensuse.orgSystem/Librarieshttps://www.knot-dns.cz/linuxx86_64b|s*b|s4d3a4f3c78dd5537eaf0ccebd04602fee526809bd1f35b0ef7ddf9810c855a5d5libdnssec.so.8.0.0rootrootrootrootknot-3.1.4-bp154.1.87.src.rpmlibdnssec.so.8()(64bit)libdnssec8libdnssec8(x86-64)@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.10)(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.25)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libpthread.so.0(GLIBC_2.3.2)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3a@an@aD@a @a @`ݮ@`f@`@`q`_@`\{@`@`_@____^@@^@@^@@^@]\HW@\3?@\*[@[@[ݍ[IZ@Z@ZWQYYYXWDB@W1@VwV@V@V@V@VTQ@VCU6@U6@U@U&iU&iTTq@T@T@Tk4Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Jan Engelhardt Michal Hrusecky Jan Engelhardt Michal Hrusecky Michal Hrusecky pgajdos@suse.comMichal Hrusecky Marcus Rueckert Marcus Rueckert Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky pgajdos@suse.comMarcus Rueckert Marcus Rueckert Petr Gajdos Marcus Rueckert Marcus Rueckert Marcus Rueckert mrueckert@suse.dekbabioch@suse.commrueckert@suse.dei@marguerite.sumrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.detchvatal@suse.comondrej@sury.orgondrej@sury.orgpgajdos@suse.com- update to version 3.1.4, see: https://www.knot-dns.cz/2021-11-04-version-314.html- update to version 3.1.3, see: https://www.knot-dns.cz/2021-10-18-version-313.html- migrate to user creation via sysuser-tools - run spec-cleaner on spec file - update to version 3.1.2, see: https://www.knot-dns.cz/2021-09-08-version-312.html- update to version 3.1.1, see: https://www.knot-dns.cz/2021-08-10-version-311.html- update to version 3.1.0, see: https://www.knot-dns.cz/2021-08-02-version-310.html- update to version 3.0.7, see: https://www.knot-dns.cz/2021-06-16-version-307.html- make sure we have getent and groupadd/useradd in pre * added dependency on shadow and glibc * might be related to bnc#1186023- update to version 3.0.6, see: https://www.knot-dns.cz/2021-05-12-version-306.html- Make /etc/knot directory owned by knot - fix reload action- Update descriptions, remove unsubstantiated claims.- update to version 3.0.5, see: https://www.knot-dns.cz/2021-03-25-version-305.html - Update description based on homepage- Trim marketing wording from description. - Drop old rpm constructs.- version update to 3.0.4, see: https://www.knot-dns.cz/2021-01-20-version-304.html- add incompatibility warning about 1.6.X version when updateing - rename back to knot- version update to 3.0.3- version update to 2.9.7, see: https://www.knot-dns.cz/2020-08-31-version-296.html https://www.knot-dns.cz/2020-10-09-version-297.html - obsolete only pre-2.0 version- remove rosedb conditional as lmdb is required in general now- replace conflicts with Provides/Obsoletes- fix dependency: python-Sphinx -> python3-Sphinx- use upstream example config file with correct syntax- version update to 2.9.5 - Bugfixes - Old ZSK can be withdrawn too early during a ZSK rollover if maximum zone TTL is computed automatically - Server responds SERVFAIL to ANY queries on empty non-terminal nodes - Improvements - Also module onlinesign returns minimized responses to ANY queries - Linking against libcap-ng can be disabled via a configure option- version update to 2.9.4 see NEWS- version update to 2.9.2 see NEWS- update to 2.7.6 - Improvements - Zone status also shows when the zone load is scheduled - Server workers status also shows background workers utilization - Default control timeout for knotc was increased to 10 seconds - Pkg-config files contain auxiliary variable with library filename - Bugfixes - Configuration commit or server reload can drop some pending zone events - Nonempty zone journal is created even though it's disabled [#635] - Zone is completely re-signed during empty dynamic update processing - Server can crash when storing a big zone difference to the journal - Failed to link on FreeBSD 12 with Clang- update to 2.7.5 - Features: - Keymgr supports NSEC3 salt handling - Improvements: - Zone history in journal is dropped apon AXFR-like zone update - Libdnssec is no longer linked against libm #628 - Libdnssec is explicitly linked against libpthread if PKCS #11 enabled #629 - Better support for libknot packaging in Python - Manually generated KSK is 'ready' by default - Kdig supports '+timeout' as an alias for '+time' - Kdig supports '+nocomments' option - Kdig no longer prints empty lines between retries - Kdig returns failure if operations not successfully resolved [#632] - Fixed repeating of the 'KSK submission, waiting for confirmation' log - Various improvements in documentation, Dockerfile, and tests - Bugfixes: - Knotc fails to unset huge configuration section - Kjournalprint sometimes fails to display zone journal content - Improper timing of ZSK removal during ZSK rollover - Missing UTC time zone indication in the 'iso' keymgr list output - A race condition in the online signing module- update to 2.7.4 Features: - -------- - Added SNI configuration for TLS in kdig (Thanks to Alexander Schultz) Improvements: - ------------ - Added warning log when DNSSEC events not successfully scheduled - New semantic check on timer values in keymgr - DS query no longer asks other addresses if got a negative answer - Reintroduced 'rollover' configuration option for CDS/CDNSKEY publication - Extended logging for zone loading - Various documentation improvements Bugfixes: - -------- - Failed to import module configuration #613 - Improper Cflags value in libknot.pc if built with embedded LMDB #615 - IXFR doesn't fall back to AXFR if malformed reply - DNSSEC events not correctly scheduled for empty zone updates - During algorithm rollover old keys get removed before DS TTL expires #617 - Maximum zone's RRSIG TTL not considered during algorithm rollover #620- seems we no longer need jansson- limit geoip support to opensuse- update to 2.7.3 - Features: - New queryacl module for query access control - Configurable answer rrset rotation #612 - Configurable NSEC bitmap in online signing - Improvements: - Better error logging for KASP DB operations #601 - Some documentation improvements - Bugfixes: - Keymgr "list" output doesn't show key size for ECDSA algorithms #602 - Failed to link statically with embedded LMDB - Configuration commit causes zone reload for all zones - The statistics module overlooks TSIG record in a request - Improper processing of an AXFR-style-IXFR response consisting of one-record messages - Race condition in online signing during key rollover #600 - Server can crash if geoip module is enabled in the geo mode - changes from 2.7.2 - Improvements: - Keymgr list command displays also key size - Kjournalprint displays total occupied size in the debug mode - Server doesn't stop if failed to load a shared module from the module directory - Libraries libcap-ng, pthread, and dl are linked selectively if needed - Bugfixes: - Sometimes incorrect result from dnssec_nsec_bitmap_contains (libdnssec) - Server can crash when loading zone file difference and zone-in-journal is set - Incorrect treatment of specific queries in the module RRL - Failed to link module Cookies as a shared library - changes from 2.7.1 - Improvements: - Added zone wire size information to zone loading log message - Added debug log message for each unsuccessful remote address operation - Various improvements for packaging - Bugfixes: - Incompatible handling of RRSIG TTL value when creating a DNS message - Incorrect RRSIG TTL value in zone differences and knotc zone operation outputs - Default configure prefix is ignored - changes from 2.7.0 - Features: - New DNS Cookies module and related '+cookie' kdig option - New module for response tailoring according to client's subnet or geographic location - General EDNS Client Subnet support in the server - OSS-Fuzz integration (Thanks to Jonathan Foote) - New '+ednsopt' kdig option (Thanks to Jan Včelák) - Online Signing support for automatic key rollover - Non-normal file (e.g. pipe) loading support in zscanner #542 - Automatic SOA serial incrementation if non-empty zone difference - New zone file load option for ignoring zone file's SOA serial - New build-time option for alternative malloc specification - Structured logging for DNSSEC key submission event - Empty QNAME support in kdig - Improvements: - Various library and server optimizations - Reduced memory consumption of outgoing IXFR processing - Linux capabilities use overhaul #546 (Thanks to Robert Edmonds) - Online Signing properly signs delegations and CNAME records - CDS/CDNSKEY rrset is signed with KSK instead of ZSK - DNSSEC-related records are ignored when loading zone difference with signing enabled - Minimum allowed RSA key length was increased to 1024 - Bugfixes: - Possible uninitialized address buffer use in zscanner - Possible index overflow during multiline record parsing in zscanner - kdig +tls sometimes consumes 100 % CPU #561 - Single-Type Signing doesn't work with single ZSK key #566 - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - Compatibility: - Removed obsolete RRL configuration - Removed obsolete module names 'mod-online-sign' and 'mod-synth-record' - Removed obsolete 'ixfr-from-differences' configuration option - Removed old journal migration - Removed module rosedb - changes from 2.6.9 - Improvements: - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation - Bugfixes: - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - packaging changes: - enabled geoip module: new BR: pkgconfig(libmaxminddb) - enabled cookies module - enabled queryacl module- update to 2.6.8 - Features: - New 'import-pkcs11' command in keymgr - Improvements: - Unixtime serial policy mimics Bind – increment if lower #593 - Bugfixes: - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy [#589] - update to 2.6.7 - Features: - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) - Improvements: - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination - Bugfixes: - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback mode- Update to 2.6.6 - Features: - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation - Improvements: - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination - Bugfixes: - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- update to 2.6.5 - Features: - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set - Improvements: - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates - Bugfixes: - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations- update to 2.6.4 see /usr/share/doc/packages/knot2/NEWS- fix tmpfiles scriptlet- package /var/lib/knot - run tmpfiles scriptlet during install- update to 2.5.3 see /usr/share/doc/packages/knot2/NEWS - use libidn2 on TW and 42.3 - following modules stay static: - dnsproxy - onlinesign - moved modules to shared building: - dnstap - noudp - rosedb - rrl - stats - synthrecord - whoami- update to 2.4.1 see /usr/share/doc/packages/knot2/NEWS- update to 2.2.1 - Bugfixes: - Fix separate logging of server and zone events - Fix concurrent zone file flushing with many zones - Fix possible server crash with empty hostname on OpenWRT - Fix control timeout parsing in knotc - Fix "Environment maxreaders limit reached" error in knotc - Don't apply journal changes on modified zone file - Remove broken LTO option from configure script - Enable multiple zone names completion in interactive knotc - Set the TC flag in a response if a glue doesn't fit the response - Disallow server reload when there is an active configuration transaction - Improvements: - Distinguish unavailable zones from zones with zero serial in log messages - Log warning and error messages to standard error output in all utilities - Document tested PKCS #11 devices - Extended Python configuration interface- update to 2.2.0 - Bugfixes: - Fix build dependencies on FreeBSD - Fix query/response message type setting in dnstap module - Fix remote address retrieval from dnstap capture in kdig - Fix global modules execution for queries hitting existing zones - Fix execution of semantic checks after an IXFR transfer - Fix PKCS#11 support detection at build time - Fix kdig failure when the first AXFR message contains just the SOA record - Exclude non-authoritative types from NSEC/NSEC3 bitmap at a delegation - Mark PKCS#11 generated keys as sensitive (required by Luna SA) - Fix error when removing the only zone from the server - Don't abort knotc transaction when some check fails - Features: - URI and CAA resource record types support - RRL client address based white list - knotc interactive mode - Improvements: - Consistent IXFR error messages - Various fixes for better compatibility with PKCS#11 devices - Various keymgr user interface improvements - Better zone event scheduler performance with many zones - New server control interface - kdig uses local resolver if resolv.conf is empty - new BR libedit-devel for the interactive mode- update to 2.1.1 - Bugfixes: - DNSSEC: Allow import of duplicate private key into the KASP - DNSSEC: Avoid duplicate NSEC for Wildcard No Data answer - Fix server crash when an incomming transfer is in progress and reload is issued - Fix socket polling when configured with many interfaces and threads - Fix compilation against Nettle 3.2 - Improvements: - Select correct source address for UDP messages recieved on ANY address - Extend documentation of knotc commands - drop knot-2.1.0_pkcs11_check.patch- enable libcap-ng- fix configure check for pkcs11 support: adds knot-2.1.0_pkcs11_check.patch- fix soversions- update to 2.1.0 - Features: - Per-thread UDP socket binding using SO_REUSEPORT on Linux - Support for dynamic configuration database - DNSSEC: Support for cryptographic tokens via PKCS #11 interface - DNSSEC: Experimental support for online signing - Improvements: - Support for zone file name patterns - Configurable location of zone timer database - Non-blocking network operations and better timeout handling - Caching of Critical configuration values for better performance - Logging of ACL failures - RRL: Add rate-limit-slip zero support to drop all responses - RRL: Document behavior for different rate-limit-slip options - kdig: Warning instead of error on TSIG validation failure - Cleanup of support libraries interfaces (libknot, libzscanner, libdnssec) - Remove possibly insecure server control over a network socket - Remove implementation limit for the number of network interfaces - Bugfixes: - synth-record module: Fix application of default configuration options - TSIG: Allow compressed TSIG name when forwarding DDNS updates - Schedule zone bootstrap after slave zone fails to load from disk - avoid activating the intree copy of lmdb- update to 2.0.2 - Out-of-bound read in packet parser for malformed NAPTR records (LibFuzzer)- split out shared libraries, knot-resolver uses some of them and atm we are forced to install the whole knot2 package.- lmdb seems no longer optional- create a new branch for knot 2.x starting with 2.0.1 - Bugfixes: - Do not reload expired zones on 'knotc reload' and server startup - Fix rare race-condition in event scheduling causing delayed event execution - Fix skipping of non-authoritative nodes in NSEC proofs - Fix TC flag setting in RRL slipped answers - Disable domain name compression for root label - Log via journald only when running under systemd - Fix CNAME following when quering for NSEC RR type - Fix refreshing of DNSSEC signatures for zone keys - Fix binding an unavailable IPv6 address on Linux (IP_FREEBIND) - Fix infinite loop in knotc zonestatus and memstats - Fix memory leak in configuration on server shutdown - Fix broken dnsproxy module - Fix DNSSEC KASP timestamps parsing in strict POSIX environment - fix multi value parsing on big-endian - Adapt to Nettle 3 API break causing base64 decoding failures on big-endian - Features: - Add 'keymgr zone key ds' to show key's DS record - Add 'keymgr tsig generate' to generate TSIG keys - Add query module scoping to process either all queries or zone queries only - Add support for file name globbing in config file includes - Add 'request-edns-option' config option to add custom EDNS0 option into server initiated queries - Improvements: - Send minimal responses (remove NS from Authority section for NOERROR) - Update persistent timers only on shutdown for better performance - Allow change of RR TTL over DDNS - Documentation fixes, updates, and improvements in formatting - Install yparser and zscanner header files - Improve lookup of libsystemd build dependencies - Fix compilation warnings in endian conversion functions on OpenBSD - changes in knot 2.0.0 - Bugfixes: - Fix lost NOTIFY message if received during zone transfer - Disable fast zone parser when compiled in Clang (workaround for Clang bug) - kdig: Record correct dnstap SocketProtocol when retrying over TCP - kdig: Hide TSIG section with +noall - Do not set AA flag for AXFR/IXFR queries - Features: - DNSSEC: separate library, switch to GnuTLS, new utilities - DNSSEC: basic KASP support (generate initial keys, ZSK rollover) - Configuration: New text format in YAML, binary store in LMDB - Zone parser: Split long TXT/SPF strings into multiple strings - kdig: Add generic dump style option (+generic) - Try all master servers in multi-master environment - Improved remotes and ACLs (multiple addresses, multiple keys) - Basic support for zone file patterns (%s to substitute zone name) - Disable zone file synchronization by setting 'zonefile_sync' to '-1' - knsupdate: Add input prompt in interactive mode and 'quit' command - knsupdate: Allow TSIG algorithm specification in interactive prompt - Improvements: - Zone dump: Do not write class for SOA record (unified with other RR types) - Zone dump: Do not write master server address into the zone file - Documentation: Manual pages are included in HTML and PDF - drop patches which are included upstream: 0001-loosen-openssl-dependency.patch 0002-make-configure.ac-compatible-with-old-tools.patch - also drop all buildrequires just needed for autoreconf - new buildrequires: pkgconfig(gnutls) >= 3 pkgconfig(nettle) pkgconfig(jansson) - create devel subpackage - enable rosedb and bash completion- local state dir should be just /var- enable dnstap support for factory and newer: - new BR: protobuf-c and libfstrm-devel - prepared lto support but not enabled yet, still need to find out which distros support it- update to 1.6.3 - Performance drop for NSEC-signed zones - Proper handling of TCP short-writes - Out-of-bound read in zone parser for long domain names in origin (AFL fuzzer) - Out-of-bound read in packet parser for TSIG RR without RDATA (AFL fuzzer) - Out-of-bound read in packet parser for malformed NAPTR RR (AFL fuzzer) - CDS and CDNSKEY support in zone parser - Add defaults for TCP config options into documentation - Detailed error message if zone reload fails - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch- update to 1.6.2 - Limiting number of parallel TCP clients (max-tcp-clients config option) - Ignore refresh and transfer events on non-slave zones - Compilation with Dnstap support on FreeBSD - Possible file descriptor leak when terminating inactive TCP clients - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch - moved autoreconf -fi to %build so it wont be tried in quilt setup or similar tools - move up the %if case for systemd in for the preun scriptlet to avoid warning about empty scripts on non systemd distributions. - used xz tarball: new buildrequires xz- Add deps on the docu packages to regen documentation - Enable systemd integration fully - Add dep on libidn - Cleanup with spec-cleaner- Only require lmdb-devel on (Open)SUSE 13.2 and higher- Updated to 1.6.1 Bugfixes: - Journal file would sometimes outgrow its set limit - Fixed incompatibility with OpenSSL 0.9.8 - Proper handling when machine hostname cannot be retreived Features: - Support for DNSSEC Single Type Signing Scheme - Compile with lmdb-devel to add support for persistent timers- Updated to 1.6.0 Bugfixes: - Fix zone expiration when AXFR/IXFR is being refused by master - Fix forced zone refresh on slave (knotc refresh -f) - Persistent timers database opening after privileges has been dropped - DNSSEC: RFC compliant processing of letter case in RDATA domain names - EDNS: Return minimal error response for queries with unsupported version - EDNS: Fix interpretation of Extended RCODE Improvements: - Maximal size of persistent timers database increased from 10 MB to 100 MB - Added logging of persistent timers database errors Features: - Persistent timers for slave zones (expire, refresh, and flush)/sbin/ldconfig/sbin/ldconfigcloud120 16523231303.1.4-bp154.1.873.1.4-bp154.1.87libdnssec.so.8libdnssec.so.8.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Backports:SLE-15-SP4/standard/5a02deb01ec9f919b8aa1b90d190b0d0-knotcpioxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=a7bf3bb04e6f8f1b473d66a2faa8a479f3f4b9b8, strippedPRRRRRRR RR RR R RRR RR3ᆰn$_:cnutf-8e1228e41482fa04b4157fd3f8786de92ff8c01fa96281bfb7bbdbb6407321da9?7zXZ !t/ߋ] cr$x#F1t7m,wD=~XOx^\Hpݰ@:*yEt .H2k 3pM[YƥW־g\t&DHe/OP:Uc/\LmN8r.PAtd;,a_j_k ,y4UֽQ䗈SeYYߊa%??s-_l5Ws1-NE>? ,?3l-,Qf]u%!W&b#݌&|vTб=OUEV Ub`Ig؜dk⊌Ed;0R轣,rP Wkoej-Nz+|5c"^Yq¿kE$;3ub~/J͋9uGy%#׹V$qW*YvbYCHh y8j@ĈЕg(ZqdL lx3a=up޹x:A|wRQxm?۹sY:0 I@w-ey&"3ˋ Dl)[)9""G O6L Ч%" 1HS!̛8FOgO>ǷEaC,Dٴ6 {O,0ok?^] ~ahNFQL8$ÍM 3Wȋ^) ُk% qi`VG5c׫xR>%@yYGoi95S~F.} n3BĻc&f=܄kANQlP!(s.!Sqm)I 8=K0xFtѝaa"Yj(qc0ԴK)$rv͒am=r.7v'llplƕ,0viH.CMNPOö$CZ_c0d i4m/:.fhx ˋgAG{M62UUtb>ua[l j=hm5*SkNQ$Ij{ìi6v4gދ0DiYb|`Y3Nc$L"kN X`>-Doct=o7cc|9[v*j(C( [S?'+ȲY CHLAAi^RVE,%[h|sGF>UZ:EHUl%ex cICX/WIϮ)M"zi?\F=V(]E467@ĀnGN_0$zm -Ǽ7-緃o׿3  5~αBMȦڟÇ2x w=Iz /{o3|6e'TphOSEލ[aE|5"Zm:)oė{DCev| ᾑO+f˰^HNL*Ѥr&A\qӡ=REt2[C:(f1~2ApFowVR .\fIZ*Xق<^'\ҋ =tzDQi>s&ԹLŸgv50>NLU1J"-}%5fEqY9v;XfSZ>hsTWW GfkEk(_?}=fqʹ- N2jMoI֩ZF*ueBx$Ag쭌us6).N4.n(! !J>6VI$hZ6D}'$@2hh ab))c ldDNQ.KMB6]FCsBx{?_- I`,E%ZEu uݺ~mUATw tp=g!-2걣U 0kAM(e3e X7"x.ɫ4^u>7h[HfmLh`XWģ |!˭^{YLCCJOtʷ9<OIMB8uUfd U@VJMN3-ZBZsZ "M5R)m3py7Y-U|* C@/>tTB֬s7]*?)wUj8vOpL(P4VY/HJT8#Nޚ \5s3 l}"CU*gPkH5L3Q<Ҫtр۶5M79c ?!ߕzɟ mu$W;+z#wڃO?834w+CcR1#%4U^ii4Ջ|^![o*p~mN! R?~`u$Zs%Ι+&CncW-/-c׼:akE'L[-G`qfdKLeƆ2r$z`gc"J$ij:zHL'2ד /smtX['=d8R$?v#pRPswJ?>2%=i*n2I"KcaVgj[=̈]w{}㨗^qދ*ySb׆Zf[cu1 EB-G8+Dpjd/^!,a÷*;+_bKCy-Hp%=e&`W/egf""7u1>i37/Р! R>ZRƉ+ 2GnݑҠo0@dk[B9] |M\] lwvʩ(?!f]ʑ^!;gfEu ZݣٳIlKf n,Ps6.W(b eJufrqH쨢6.*ruZj ;QJ0Sg*:Igs2.$9.G"4ߛ}!  ^b 7tNZ2gյe35<jɽ5[{K^UH;s _INpuZ]T^Hm``2OEꜧEZ:-YxnAf4`okelڂh(5R0iAf9'0By="cT?zTc;ys\xit9 rZ9[5jDm>VW**펋% 7uͤ.&Js. Pp2"JWaꠤgBrkogM;l䐒,D#1v=XWɬ+ˀal.+Љ;*4b+9;ó._ )g4d~g"z~8 T/enpBGC!bͱDZxڜOx]S#}vs {mڑdOMɳj<&h fm\q_}6q ; I6<qaEf2Ck{X=nyËnŬpR]~3RV+ J_0тu zV wɢT ޴!" PGhH;sg%ß(˥krC$W9Q SZgSș|jO"'f/}<CKeizpIJL!VjcRЗRE> !,+REuhw@^FyMx%Js9YΧ|[SxLμE*&¸#HDx^(7xk8Lr|) ]fasZ4rUhT% *5ޕ#}myg yd{χGե+ :x"""x߅ֈ[fJœZ}k K̉WMѤETl6J)[ qws~E[ v|g!zϑoQŕx{]7#Di g逓cℯb[fAe^hc)BygGϡrRxֹw4 =4e Vh x^`_zFr [uTuJ\ZՖ>L(x'4+oF  c}TW&6)EcCQc\hz!i@h5P V%PB|lsᷓ(C< [0=o\*]~HDBTߧ}sLHS"7oĜ[dkK#>Ɏq-8"rjB󙘁||,uj/%'`?ڱ4,o؄o_:Q^IU$͌=Y޿TD 'oLIl?ؠ#.JdMb±7: fI7cA}cY&D|'OO,~A#EF F^TMrRS%yZiqE E%L(o`}9e+L5y [aSnF%پiv}Ċ XSp4JĎXW0#s"yp*[EH;9բxJ4yOpD8^85li5q6BJG'v\8|(MY| LVr>\L~_[^zpXćoæsGPGL$1eDx|yRS9HY74qd4\%71LLV2xqBXD;CD ú|08R *9y>ou)ɘRF,gPFv }# u*zLK70>090$/Gi >s6Z 3Spܚ U=j"eP peSTkFJ,N ao-?bW*a-场7rp1{Œ<+%"+'<f(,)z@&~M!vK*Pٳ}h'<9ie GдzC7UnέSSoXo5C|gYd8VM}ngw-5E\w}-h$qbS*Hg;бHhv*^(;:S 7{25+\Q X-c?QGGF\}0Ka0x^?4m^<0m׳pl k[ 4K ̲]n<s/8Di}i2VADsu` a $U8PZS)sæT4K]dD;I9 KFٖh#Ua6hLKPW|Sgv?FG=l|򅪛,G!>}~pl-լtu3qU>!* [ЈmYq{z/ӊ;p(KGj]%K,b9C)zεtQ=8 Bie޻x&:r hcMw>;~9I:ahZq@ĭGPBKJ!xM^G|R}.'T.z|&RQV%*q.׃=D5b0|cr e"q?fyh]`|f$RuiuiŷW9d =HPʹP43,*fK J^&m^?{#T̥V{p7{5o)~goX4! >l1[_LV.n-AZ ބd)6D-Y >ź46p SoqJ +ގvMwt`5CrIW[Kgo"9BO&z3$r'0UKC@֞guȔS3tĔܾ\PK7PHUYR@,վcܡxYXQNmK4 /іCMmm7P6j;Rw..!>q;`Y ؿ"fSŹ[fjs;dʒZlK b Nkm۬\DKFhi+N4i.Mn`f A**HՓF{BjEn}",cb>pӒm V!؟[B Vd`@PSlkjDc\>B"cI hn9q l QiM.=J mޭ{*oЀDIu7UL=Et4x k)A8?ks`1̴>ͮ *Z읝-o %:'fo+w#CѺ㥔vP=,:WjmR00D/ 4bBЛƳ) .#o_ U°6vrG ~bf9ȗM+-{P 2W^+ׯ.l,,Fa:L^fZӌ D},,6'#z#-U?5P\ 3kwCa'goo*R>7vYyٌAb3xcr|>(ո}tU ̖oORlP#"_=G*'-c-pnZ^-Ty*"B -11ڪ/E%|h4Jj2lj]i7tb;u(SD1&tdဟ$DJhSO2LLz< 0=jzN\ +?a4 ,{{Pf(U5+]š҆תC:դ+qN%g ŧלjVzV:`W<}TH|Vy +QܽP6UӜ)$f+l9>63@*6Mqb-BS7椡콚<X\yz54"Sn_C)"#bǵuq0 vD&0x95.@T%n+~wLQ5v9*=@Vur>_FcSr8Z'%J³.4^Od=\]Xl3~CݞӮAl-EJlA ?=m 2.0p! 8UHd酇y r\RKBuXEԂ#qeP,硷@m% eOkؤO8[_~zʱ'#u@2MMv !z]Y3bW K>#V^2]r]?E\CU-GrOndcS^|1{[Ȫ SA9$qZHX9|az?[SRX1\ /QpC@vupăIw cNSʺʹIf8z{(Xp@e`ؿ(ZA]֑fqK7ye~RcﮭФTɉd?(\_0i/,7EU׮_LμЏ3@^2IZaد)t|eAP,(ۉVwѸ#u05lwg E {G ;Ք&%Hp拳3@C&u[\XOx }ݛ9{'?4' {݋L3`4ZV3>P>I-!WޛsQ_4GV;Bļ<x}&&%Ϧ$F~0Wu3'ZAX3@E "曆T Ud!y;uj҃WDzQ<5e}q|SHl݋MC)8Lw{ ^BoS{V@+N[7o;+NJeR&B)4ৗD'0ShtۣR7Y IK\~-@3'!;KҺ Oo +G(,,Y9#5gքc7ÅҐb`+C5@s|EHͧHv_jB!mY}>G%?YʔEVY $y>X-v#/A5a n%@v6cX 厭dM+CjS+tTњFe&uˉ|!%|/[hrc.Px+ϧ[6o\7K~e:߽\Ų)۰Y8>#KtMj:lJ1oJ}b{,'Ƭ1%o+;dfa;EhzBD0hf: 5˪JkaOǓ^5-d UJGbN ͻKqo(I$7;Hsm8H0)=`t:@})q5۪׵x2Z칼V K!MA(U/+Je]la R [M^2QHW(!8" Kwl/,Hw FaHhZggt%QG{5|2yW&3R>\X6e&lEq+\}-OFY ;{|.daE@!Inq=@F2ܸw8bI9XYjZߖ+^}(?a0eЈYȍUeb`!Ȕ85qTҧ$槆j?fvY[jSOn#1#8(t 8JCE%k5Ijo5CIvY3@恾AuBtю@)ɜ"2J;pΒ:#v|ը!1@I5P [kw4*(~"mgj'v91d*׃ $kD9]6X~G1q d;#졗[aS䷐^g*v͝p 6|&p-vC]c Q78I߉9ve^QlZ9agC7 ǺfR0]ww;{ts x:-xoU&z&\D7N׹D`ɔ Ȭqx.H JRcil? {)8Ӯ&EDf(|b|Kof`܋V1.a,RCت\cc2{RarMhH] DC;/&wjSH݀W?_Y u߰gUtK_ekQwπ$\rEW9=NYd2*Qbɿ46rR&]Hj⃡Pf"2!"(|aBF7%ݺ,`i51g;O낙sFϹTҧr3neoy iu؅8An[@Rq8 08y9>ǧpXA}Gj‏]L%Ԁ 4^sl4_<=Ğ`&q_&U{i#df`=`a F 7!WkB:hDvqi &K&ҝ[Km:~[1џPo Pba/-ՕBrz}[~-8ޢ=Y\y*e97Zy2.G/x=  ywN7@X< L.`?0ںxtaaS(wJWBq5J22sϿmεE\/#^l޹U]>k /?Wwdy㮪(O3cc(.J,o"Mjߛr2z< r ,(!_@jy2q}?hI(XaVKʣCg7-I4iQQز1D:uϡlб& c4@_۩p2k}}qFJNEAuQzEj9[YP*(|fg$ (uHk.[tǸS=pT; HՐ B{$  [=mz;S,ȂΜ*k^eWNs9CsK$fl>eѥkq GJJ4-5^֜1ɍgc )ډjS>J!\ R13V7A3-ɕ.hob8~qu:<}'vٿ1СQ+&谾H(lrĵE(휤wNjRuGRos| 3Ӣ"~ٞ0ivXI8O֜՜NFQa/:SM@xioēv5! l>a|%%ٕ|܈‡ɾiMFYdK܃bH_p6Rӧ4XY7HkIܫf-ɣ0e- 0ih0ڕ*%*j O1?UV{$P+5̢[Orf%M΋~.cY'/ FVLEZHƶU $e;4^`T}Z;hAxX& 7>F E߈g[h3Hamݻ:jGk#LyL`tk_*dPLlQ XƥzQ\HW9b!vGvXp`mf L.Yn7J3PA:%-Dm6+@b /B'F5o4@RyZxS_M ~@t2 r~ɦgBNd ȥHuV F4J 1خQ(hb(m`l@?ul e/1{oԏ0%xj9F5AQر\hQODB|mpzY2 b`fa ס>} k1ŭ']61`b1ń܎Ϟ׬^ɤ>ZH]DNrل L2 9TqL%2 vMSq' m!$AO%IveuZp[̑wiff@{PBy6/nlr46ՙҡ^]=MAӷXWHƂLȞ6mj L/m-Si}qa5+9W4OӺJ~ɣajG fK^+5y` QTe\ #CqY Eo;*)F E\/Vҁ2߯iCUm5FAOk"?CjH\)?=Q=Fg/mrp1ULV|YVG٢x+Jp#yĆ4};ƷUdj.Czp O͖R2a[ͪ"0G>jӿߞsD<Ճ-[ժfKx9r1Hcl%×Ǩyne {Ӽ`vU*ǟ}58;Lk;W =<]x[ENx/L CTb##Rj jWs&.P.ѹʽJRml4Kċ谢b$GmL+AGݧ+ !O埢AH@W-YEվb>2eX 7<-ۋ,'HKv(3/cC !л&zXY:[j?ڶ_[$fUTr`%Ùl6{JNMhQvc:&}|p܃uY-~q‰#kdO^曗8![!VtqcQihv C{#ˣj=[5H?S_n G[^6V|2r:6uc\#C|#qs-+W(ކOHT虵$00_{B'gE" f$qTClW+=8ᥦ= u.FOHDc+&OCt;sN!Ű ):PD],8şS+pEN݉y)-7:҅pt{;Y.π-%4r jiL \1BbT{(]GDgw͑}yT+,9BEnjX޽g)ϫf8Ĥ}e3Sc33G g+tYY?|Xw(wwLc[aˤ(q%4!J~H=1c 1 =:->XpͬxBpiB3Sdz?!c>́`D0 V֧#(+l6rXFyЅ&;f;Hp'"܎XGsA( q@4ika|^@(S.ukuS]m?=?myD֝u@l0JWbmv|4 ES\Y]FB+crp_KeLݫ>>hG ,_lfg+2>u14:+z5*^B*UN/Ͻ+obTm rGc^"|ndi-KdN@==ػGXWGrG[ ߍ!Uۡ}@ڃ3ĝ9' C\jN&Y:$|$sZFM16lqdIAPZtk@w-" sd⯗6ׅmjly9V B߸)P{(jt $udOXXC'hj|ZD+U>r aK6j[U̒w2LP.gh#[gʙrz8|#vd ߯N#)1݉I1I x^m{˜*_ѹcDIaG<3GMS6*0dd3}RM#?\b%ΝHt~hHb_鏦&d5Z! w8D2 PLsWGۂay(FpLd \s]Fw1B}gtqcbcl]o>n)(. vm,r(Cq<&vT5VFZc~PW]pF]*DAIND)8nq'9f؎'H)<~r:2h!&S!CI{+I] z&[![C#x`A\'ڮ=8nMwSKh1 nCwlQD#@,)Bfx$G wŌ6YGWx ,)2"Upf˓fGMTDF[P'}\,I׮9~w㏐q7,!~\d+ڪS/*n ,?I%@'llm#>CMwSTx䥬8(h(t*3;w'yk)rn*@F_ URnVimO~A]1kzQG$V dL=zcdR;hPG4fXu AhX/OpJ Fj_ׅ(ƞ*~9w0#_.yw0 a璞tG;E1= \w,!."&l)g @bD`6Y]1^N#&9/򘑕. ~VFjM}_ڱrȩ]mv4wJ Bf6 t_AkEʴoǻ S9[X{Z D޴qG#P'Nک8Y⬬.@8$Mr -ݧ56𦿊qOn;^;%O%#Z%(  .Uq%4w:$TJS}. !cV!. =7wHL$oB. 1@㽂R ᢲEQ:9 4\yoEYRO͂@wAޞ ž}N4Z;?ST29(ޓ+&%R˝QǹIvV[%p{hj$W=[y縚8mJnX#j' {hez o\=>{#<(j93CgE,LLɤFE`Wҁ| rڃk csAj]%^فqhԵ޷VRݼDORm`<&,)( :K>pD-.ӆl)GZ1 Q1kN;bb4+o%D%㓃qbXn"L[{b:xmY6cW ΄5%&$Fl5DsHPl.c:zjCBve`r` .]etxcI"h*o[u vZK=ă:-\1? o/g(U}VE9&v$kJC{;B@SEGLqEDÌX^Nk+QzB+k2)Gz؊+Lv"Ve՚a}Gel5 ]#~M؆1oޫ.r=FGL9`{V-d<@4Ĵ6)@_4|*ED-94%Kp迍guY8g.b`dTw5\,lY;E?-JZfIkuƇ84S̀y)G<1^mHDɁ\fVE5Չ+\wXC oOvX]~(qeDhL-UI &|gtSIvA.4_M|O,=B>f^r 8~B$"}^=WsJ5TXf` {X1R_]NJ1H'_n@OyLBU\wtMTfuU D\Zv'NxrXwLw^BL3ބG-C%9]sI4)@ZV5Q>nIg{,\˒g!Tqh1>=/:n|7`⾼F!=^OZ]<13_?@)Ep'ոwhУICq-uk_?R杺}^Ɗ>e (V? p mq . .a#qgjBۭ /IuՔ\^<ÃҴmZg1GхDDP5>9Gt*PRmD#!@Ok '@(!CL6Dt|A$̰)wȠ怋przv$ruzll xE?.$ֱOh<:z7mw|Z@_)[9mU0bux,ZhO:UY&KX/Qƴl$)Jќx`|z A ?GQK~pL9 q$#Ѧ̿h~wnHThGQ}PlqD!?Fd)g4D^jވYMĀ\9kTdb{1J:pFQ$߉!j:t 9kbT'o vuX0';x#wJw"`;h]ɲ7M9# Z*Oݞö%t+kIDY l3fpj0s^єZvM;Wu H6F1䗫2ga-4Wm`:*sof iW"\կ3}CpF6O(v]T^>MͯO#dz Aju@rZmr7 )O7EG"4RTŽg_oۍdv>vEEzzlKkXnȏ94n.~ìM)tdhjЍYy1{BaoP:aM5uKfG2AUdSk h,lrZLß=(d6EJ46]ZtMš Ps vΚ|*4GRgp"o0ϣ/Hu.[RNarC]NDwgCJQnCۿ2 |ԄI@sóuV~'p._B(*"<,QmLMUgku:)J*neґB8 EOQ.@'(KE/2ȴ]PnoSq|%$orwPà|K[,m aE&bwR;٘ߕȍzCDPDnʇۃ?a/*HGӢwbJ /Տu<5|Hm (^~ֺC6DO..7/}i:5U(_vU?ʨ=q3eEzfh g@Yb-EЦ) >F77ZnjnrUM YcN}ޒ4XO82,cQIOtZwEo33 X1iTF|Cgϯ!%*$z%lBݺjnV$mda_՝UOxq)up##+Xt).ZpʨXmxVpڦFLޭj[L;pdTzJƁ;ͼ3lܳ4utƴ+ʟs.~%Z8 )Eso f yBl&#H_*Z%/4jڃA6/Y,^]~r/DSqZ ui9PÙퟸL->K1`N8L/g'bVN"SD_;.B Oj^/yHmxtɻm^yUJ}.,mLUOsLɛa4i iAul< #0U'2(ĒMb#63V^̓u?|ZO,!+-jQ5K#h,xIW_W /vs^#n!Moj=|zt;Mvfй P]n-ӁQpTpTg4MGbq7m2SR@%!p(MDi(m4zT5"FFq&vr@g5US~S*4Isx@O\jaV{*k!n܏0.%DiZMkrZ1g/l*e5S[&k^QFPkb{0nsJ Z%%RW[ZZMPSd8qmfx,8߀;ݬ/,Pf $a_p > Ce w*);$N[#w |n{{s& *z!C[!/K4jŞRP.` ;"]m 1<-_B,<.@W7zBoR™Vؔt;m;W@m7zw8#jB|kbժW[Ǽ[k(^iC%|I8529F!m6c&.Q(`{yfEa7mc X,BVU Шs҆^&GqE/"bLR J0Ž2w1|6˿t'.m-A[yZY <ۦP6:d]@@o_QU\XZR),V6( twJk%[m;ĸrO+E=ҁ5$K{K tkHboT)4`TgwŸPBkC2(\tk+D)^E0?֏C-bdW 4<Ҡȼ2<'71eg*!\D²s'Y8%n"e#ɛ[OsI٭(2 fNoњaԫ3:""Vdnѧ0q\wdhCY(,ޗ>wQ "xxRye2 ۨR0g`Uml-ݐ3Txh\DYmbmNfMp{uўثYbWءEm<`:j%1U)Y_m+[#ag %.xFrȋ_Yg\. 4+V2i9^`ۗ)5evy-R/b$359r`kOg(M [M_H6:ۯWG8͟'=0L O&J1`~bz[\N#uK\tb[Ҥ6[YM1cҊS]0ޝ-\_ HB>q'>aKKv%Rs+j:G>M z7FBE[JFK(<{δ&4ra Iidc!OO._Lz׽9~Xeb%Rj&0axu3 N D(E3{^*U GcJRN#rMoVGsn5v4HVm["0 ( M\DHi>XYExlEis@p!2^BT]==@1q2 qL=Ivd#GwwiNCߖh׌vӡpGD  5+Nv'gYݝ|jMR[}!ޛIgɒUjXm+%#r7@+@K.C4cgI+%hcfuwׂ0K޽;H ."X$߮b+F>ꖁ;ƺ.uGO"@0I1(qFS挴+;MVLd_V@"oq$L։ CwY.̚CQ)XcZq3N{XuîǗS %++)zSkK QbZw,c+4AQ7\wo^ 4:; =` C$ ee( !@wIO^G!['@EPfU+-i'MKv+W5쩴`mme&.O,j5q o}*fa&ߒBC +TZHGaq&H,wZ^|+Sh^ N\%s4ռ*b_$e.,Uآv,a; w{]‘y@Nߍ71:nRXAIQتxdYމ o+NIƆw94<$'wQ" tβS0i/h)1_5^\>Zbq(S)]-AS0]<|}:y_b@"Lc4](lJcZ%@ h:ZРHb5VW*1ɢnU&rbOߙ@ãH/ ' "Y^eA^CojľR 2kFq;b~LW"ZkR:{_]zՅ,y7j &YTG5T„9o`(cȽ1e@j٥D3?. }kFz0G'ԯh$R{ьH=^M&}[@E[Dz[ V Y&M:݅'.jj[_k)qcj]$ ,N ztmLF2^DXx;A)..K28kn8"K{Au%vj.Sw| os`ϼo$TJ= q'o r=x(K9Z/q®yϸtszSwhaʥ}բ y*Y7g!4.vVZ$wș>Hwr`s-pCH]j~Q{b< ã#(<`(wHMgYxd΄_z'XEQq~1tC'N æ 5 zte$C|MLR>=أ;&M0hNM1On=#;Ȥ sTRsmG<)Y/6gIu-Pɂ(sYc r6{ӢýU$W}pWE{}6Yo,zpnM "Q_gb68H9dqX,V\D r?c7KѬ'(x-6̦و\M[d7~X)&e]c8f.?Œ=2$'rT:bxaSY! p2 ߔ%V+$Zl+PԐ^|WfjNn*j[sO 3)Il>U^g@` M@G%gvf>r'Z "ttuqۑ>%@yi ?-).lK{/˧OWhF=/+ '5.E$ћ/Jq5U7 Sb,SJ'"*!F*vu0eBlcSpfOIɌMzX^m=M6 zzM|*BX `QeR-Z߬,l,+\BJd|ԜI;C~3VU,qV6Ӹq$ şg*Dh H`$#Z]#`}'gqXYuоn 4м|xMy^:`bGE[U0>rq9lwID:6(o`E{^wΤTث:~$ h-c"\틵 WHO'%-㔽K= xg[Ʋ9ԽHG ļ[܎p<ע>ΥE Bmfx̥s7]kJO^:oǙs&8Uf4zͥJۻg(ƕTp&+|^9S.wZ<ћr^V/=[j'3͒%=r!Xb$XJ",ak";XQ;%#xs8AUAF<'[>/h^f4=ݔeow,8J?!{3 0^>pIiocfOv&ynMʩG?]NLOCxn6PfڃAkqgNEI͜PEs7,|֦~ h?eYa?淪" &ʬ߬>W73)<jy"AݬzhGNwo^tQ.Au}1Ka\zk h"V}([?agH~ DEii)|T]xbVyԚ q}'=X@T+ɣ_#/N)V:T`g;:#$K'x:c"8sPw{u )\IIZ'L`Y3z o0 #gnr*pAߊDÇDsv,;Lj@Kl䏸?h 4!b1B\bv )Zi7;D_YʨyLA"9UE0Q36V̝w\+I[uj /xK/cySU a0޵|T *PjHuF@7$7L͟+^?ʒNd{JҼ:bF{rA)AH%0ObGPԏ~_yEJWj̊mPmokL أGa5fb)^ͻ?}XEk nOq"<Ā6Hq YL۬a >:~^us^XͪEQ]5o:L?$_p~MA{@`ƍ)@glFi4L9-- '̾M}=fq뉰cffx:?A`7fb;%kݸ K! ]ٯ$qJh"Mc/2Lzgb2ao(*=f&ZFilRdu֜XJ]VZio^8E0}7 bF9-ҕ-_TlVyb!8uÐ+U| p3M ZS֐`?[3`޷ a֩@}R 3RJK`5(TҰT"QA6f߸̀PZ{5{Є-%8\4F4evF{lYLzuADžjp-̍9 5c,EDs#Uhtk)SxxWuDBF䫳 R nE?bA9% V8&0?qi <ؤM4NP M+p&8 Z ؄9RTK_:F@_b:8븁[~z^48v ǭ:S59l0֓Τ؞:1&ż0DwәJG)doHw_^5jrFK&[k}Z>2}q}(}qqe_7M\ sɖr`N"eT^&GAllw';/5MaTL_ t.TW>7/bN!Mk7WOK7&,pQ2~Kd38)|C 4~M|y0S&i LpZ$]c9nD':N1ϬBG'/fcO2L 0W[fi'tq8^ge~%_,d_rCڔ +VGU[DZǡrzZCSbj^0[6RUolq(j%& !K=+݊K/@`o*_+hȸ  ;6o,ϲo#ڡ= m-"Ecr1۬˺G׾Tɭ ld0/?Po뻏vŤ݃tKām{m ]wLHm^*Gm92)dn"UVf(M,ĩN(Oy{FBeؘrB.R ?}4F̶p^V[cv{rw(l3sm8AoT)-Z'ƫ#*7Xإ4Wv;[~:YQսgB΁0(Ē# ,Zɛ 0QT=S' /:W Jʏ\kie ([L4n5Xu]XM'$l*]S !8 jz&0dz`UBw^;#2Bc#jXAjyH@^8}#oL 6TYeLRӠgJY:|E^#6Ŋ kiL^a k !/ȅ 4}̻6: !rsaZ fCH c7A) %|g0zy9MW7$Oœfw5+@YM/IFCe>Snw佺NG5e#J]YOZ\B[lfX0ޏMҘ9y|ZM8eikZ M dbXJH_`ކC7d:Djd[g"YIP,PDTcaxp[;q״tP"J365mQ8gߐ0U<(P&f]z4lhXEt0ܮ+>뙤41]u0c͕l"_ѧjְ7E~R7{;noOe4AߋtdQ!lvP{Tjƚ^A9e0C *Զ‹|l*zuQm+I 2dS9P'-;`%HA$Єh]W/^2]=#8$="O~jL0UѺ>kևc FwTR v& Hϓ?\ V$kWΥ[PĺpEV 8pb3Āżջ8"1&]FE$gh: vgGrbHu7aAxb(huMIH{A֋!A5n-jMc0=i@];iI:7( ~=+E߷@ay=fi€.s6s $uVB5~,fse#D@HbC ?2_e6pihırIT |+8BJl\ۘ"+p#MdrÊhq"kB83 qWRi{x.VbaRzaˣFXv?Ma9`JyA[zƼ`<ܞgjڤFYJw+oMCvP<75!畍B^yG> +(7"v_%9+V:x[d<ҐJ@YHXȳ#{Ɂ6H^ٍQgD L}oۗ 2?1NvgnCr} e z>Q梽00UB5U%}~A!Ы1 ndM˯vX?n.@|$kތ ^QZ-OqB:62PEֺs!&}?]ceK\yNߡ*XIC)~A uԽcz9DO\`<Ŝ8r)=ŴИRgJ:p٬<\?(XG DVNo8cKy 嗱p`2xvg]-t}33?J0}BX;*yh=EADby;PҲF4m ;3c)JG}4\+_&+5sA]# -(_m3U(:<7 8'ٶjao .JgvO%(Q/ti:ʄѝG֑(|4Jw 廙=lm|'H-`sEa͡?:h_**"EӬX~ğ޳@ߐFˡu9+N] ?K.rˇsg4dW vWh,I]8UzԳ!ҭPѥO2QQ;WK횈3B9 PH|hܹjsJ&Y+P<:J>~?ǿ Yͣω}T?5(!:#pr^&= td+v\GP_фM0D7ijnD!f wܴʿAVݾֻ]fu-L(>ngOԟ}tV.W^oͰvst_1= {mpy9BK _5nMKYLK3xA\KE5-CrKa34tT7 a$ a'<8to;wnAj:Ү9h5 16m TBj a7 p '2 %+jUiTyW!PWYsY Yt]1 3=zn>铈Mź<bƋ\n- {Ң5u"0 |w'wv8NmB!b{"Β/[όٹKN;^>8MJƯ~]տX5}vJG;.Ezr7rxJT+0Ɏ%D- )$CiiIl`B PF2[`` MÓ!%s_"⫯G+&Mx<_r^m 7h'gs YȬVtדHU9U{Ӥ΂m{bUOIْZ{LgQ4RV,icy. gE|&S`Y9z/}?*W`j"'9l/,OP5\ߙ"7ɶ@gpX-( wڌU^@h9S3 s9FOb\?A=k3,͜8-0D~]m΄k%SVvf׭^^eK/+YnC^V3(>%oЩ}QU%\*  5(k _I\^0I y#_IA%ޜVj>߉^%:6rRƆWn(L :Xux S~;U$99'Ti)Rrpկd'>4ϔcz ^;{ܗ- Z3il5Џt=O{(:ܕ}bo=ܴ̿.i6 4Tۏw!]+c-B^+{ux R8ˊ#&yOB#htChl>#k0;. x00QK䣾ςmCBbȂHV.~^@$ Zz`JbhJOpwVhY1{up!g0T0:@rU L^4j"b&làuΑ-Q)gIWN9zq?z<6iw]l3 + P\G9/QO-i'_lPy)7J|"% Y; |#qh]}nEjmeKGGTTWWpqPRl=6*H5iVnN8,l J%+>}AJDʴ+K#@'RDl `NO{ ,0t]JS]U . E0fr|$0T n%^+iI,GLW׶bd&ߜչ1wLD8ƋWޗҘ(q&T4&N_|'I}Z\إa4@1 &4v &UzLndPYĥ\c v)>9)p Le `7FyƦ>] cޭ6y%ǀ;0˄HXyID ;$A E%R(#$`8~9&?wN$16 `sp=l6 gt-ͻ9m# m|b@40~GeD{(KzCoVKG k7r-=5V>V$*#i&OŻ̅6.LՈ_0Aw1 fe/*zKnČ'aI}I>g 8WXU(< :) Mm/9b[- g&Xt8I 9']|z0^a=u2 ʎߗ&jjNW=t18]\x=#/`QI8 Qq gq"Qû+|e?j6sW Jw738@G8>MY\Tu <@Vp⇬ݿv:2(з@|zb 0uR}c ϖݺ>g" O*f`cؒy&1"Ŏ5"|'77GKZX/;<\]<\" v1%'qĨr@tkΊEB*{{:WY5%7K;`M8HPmT1 ,&Gl6_3TْGv_ -c#lxg`R7k fTP$0.5K-Z7+7u,[#Ȗf%4K{tVzGb9Xoh5@,M ɜrBuMOj0 AowEh" ̄/PJMF>h6[Sl{wI < 3[tW$B| 04 K{vҴBŐ3v9 W,OgCw.\e978w1BI,qeI#vv2~KS|3U*O *TB7鄬>["C9g3BFn5UU(g&AG3i6S7ۧ[MC4 R:v̨kX,V (5UkMOl+|lrQ`mVNOnb#'H FH%¹o:/+h7t߫_D%zjnJkLdvxE<[2GmWiMǧJG"Cd (>>} Xdl ,=\9JǗp _eR=a,V>  .kfajBVZ:P¯&nlqݝJۼh,h{}*mo},!G:.BxMp -3QX+ Y:di\P ONy'[9XaF5#N%*TcQDcB .*edXH HIըΞkg Ibr9~>IGxIR=vl0}Lu;8&)=Z9S&"_k&QQW6.j[H#ppU  % QVM7W{%܍V355ƂtN{vIj"i1u¿_+Jq 8m.hf9QO8BSL&|?VXqZ:u"Y,#v@}4M&Ar/n`Ø ->*T#u1kG,xaPO%JzR%AK Tڇ'i!D,t[1qU S'6t \GjV8@pq#i= E"";pׂ,hW2<@ ̵+?x[U]6FRDaf0dx=V䀞lsAdp-+WqZ[wXks_ir'ˀ#>3_ - jV!ƣ9ʠLt%޻7(ڼH.f,=BwzA_9&xm@Ib}@,:J!k}!hIhLZs#/hb-OɎܻ<Nٝei_7-I"(·D,VQÁo :߲5x JkFBM]L>pFgn,JnNnrMFݹp OڮNJL&Iƌxy)J :Z$y~L(mL\{iZ9>CrGT)ęZOp'RܭIyEځIXmKV@fo\ IbShzK̩ j )iƓ|ۂ8<4sbWJG%?z\A7m9|P_װ7fV I)N2&tr2"|&Ny:SIF &L V6.-Ѡ0 w'L* ,c:I޽TF_zN,)d   +zs6ˣtF\!0iIkb!xNo r[6/DKnup5>Wl'P\v5O~>dP2zC~d8+>|x㯊:\$3ec^ Nprri šeI]STP!Z2>)Uy_/jI4غxASheGIה 5,lr+m7ad4vzDT$͠ùҽw׮ &"⬕fXw<~?|JSb~}ܡ._4A?)8s$?Gs2;`sH\ߪAf^B*sʐBjJ䣄{>?_f5:[yxt 4WPϠu]<#1om/m.|Hu0.yܯoyҬ}[i=bM ڬ;M<;ob 'Ά?ɬo>̴FH^3d$%ASb2ZrKyy Mo(*7}|"g HWX-=Tg8T?PGy 5'A#MQr蜻ɠH߈X܋aCaUts \v 9xV: k|KZKܲ o,9Bz@\s*yR)y*J-\(vL00 c)k`/, {}`_Lk '3hz^Ll:nznmkEZm# QkF4AZ% g &I DC){X6:g}jzc־HF O$+U7fΝ$F]l̼5dh M~L_ EEa4A"~Sz08 `gd&4-6縠ZϿM'1 E6=XnZ8bw>8(uK!6-DŽ5aˍP˦?u3vW4. Hd h#魿g˙qk}4+F\!6BQH'@s_ZlɫӖD w~ a76](YPgz6S89VQ3)GSf̿0-Vmn8\`ay2S$63c<(4$FMdqGV(ջ=\~%:90(A^흡\&,03_o"Q.Ϟd4v#<B;}R!QJC);K~RIRy7IH@y~HP`|S>9m\| HO"@ d5(4<#f kw '? J Uh|-r j.9gYnKc5L 7# 1A7㚍1IU~'u3ib0/ڄj ݻBҔ V01.if8?Ks:Laq&"3[A4Ыrmr& T\6G;g1ۈ0:hU,mäOQTd]<,lMAG)C WBlЭ۠ͳ.1ckF5MO YZ