pdns-backend-lua-4.1.8-lp151.2.6.1 4>$  Ap^/=„!5DADãiKr8/ELkWs<:ͪEzGf'ƒ j [p4(%EBBϚIg8ޏ+b m/Qh0Ȑ^3SyK_4FH6[!#dp`G=KM'֜>|G6X[pܙp.) j9O!(A,}Sī ꟭))@~;vt_F^is24dcd6beeae8b3683ddcc94cd2d9cae58f490fd650af2467bafb533d4c9301a29207341e8919e38b70a3a64baa48469358b7759a^/=„qsF6۫#|4s8ڌg2ҵ?!H mެwvSP2whHet#o ]t 0ƛ."0ԙ!$I3/k!+ky:Xa~ՑtdB@tZynK6da[1jcywEN:lĝ. YF벉_iMTt?PsY{I 6nn=$nϥ&[RZAA\>p>Wd?WTd % :  2Vpv     H(8191: 1FTIGT`HTdIThXTlYTx\T]T^TbTcUodUeVfVlVuVvV wVxVyVzVWWWWPCpdns-backend-lua4.1.8lp151.2.6.1Lua backend for pdnsThe PowerDNS Nameserver is a authoritative-only nameserver. It conforms to contemporary DNS standards documents. This package holds the Lua backend for pdns.^~cloud117PopenSUSE Leap 15.1openSUSEGPL-2.0-onlyhttp://bugs.opensuse.orgProductivity/Networking/DNS/Servershttps://www.powerdns.com/linuxx86_64P^~3efbc389b2dfbd82cbf138e6f702ece7333781246e8d208c842430743490844brootrootpdns-4.1.8-lp151.2.6.1.src.rpmlibluabackend.so()(64bit)pdns-backend-luapdns-backend-lua(x86-64)@@@@@@@@@@@@@@    libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)liblua5.3.so.5()(64bit)libstdc++.so.6()(64bit)libstdc++.so.6(CXXABI_1.3)(64bit)libstdc++.so.6(CXXABI_1.3.9)(64bit)libstdc++.so.6(GLIBCXX_3.4)(64bit)libstdc++.so.6(GLIBCXX_3.4.11)(64bit)libstdc++.so.6(GLIBCXX_3.4.21)(64bit)libstdc++.so.6(GLIBCXX_3.4.9)(64bit)pdnsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)4.1.83.0.4-14.6.0-14.0-15.2-14.14.1^%@^`]A\@\@\@\[[[@ZZZЛZZZ@Z@YeYY5Y}@YMYMXDX@X~@Xx@Xx@XN@WW@WJVV8UUv@U>$U8TPTи@Tи@Tи@Tto@Ta@T_W@TR(@TO@TO@TO@Adam Majer Vítězslav Čížek Adam Majer Michael Ströder Michael Ströder Michael Ströder Dirk Mueller Michael Ströder amajer@suse.commichael@stroeder.comkbabioch@suse.commrueckert@suse.deadam.majer@suse.demichael@stroeder.comadam.majer@suse.demrueckert@suse.deadam.majer@suse.dejengelh@inai.deadam.majer@suse.devcizek@suse.comwr@rosenauer.orgmichael@stroeder.commichael@stroeder.commrueckert@suse.deadam.majer@suse.demichael@stroeder.comadam.majer@suse.deadam.majer@suse.dedimstar@opensuse.orgmichael@stroeder.commrueckert@suse.demichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commrueckert@suse.demichael@stroeder.commrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demichael@stroeder.comLed michael@stroeder.commrueckert@suse.demrueckert@suse.demrueckert@suse.de- pdns_maxmind.patch: backport support for MaxMindDB- Build with libmaxminddb instead of the obsolete GeoIP (bsc#1156196)- CVE-2019-10162.patch: fixes a denial of service but when authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. (bsc#1138582, CVE-2019-10162) - CVE-2019-10163.patch: fixes a denial of service of slave server when an authorized master server sends large number of NOTIFY messages (bsc#1138582, CVE-2019-10163) - CVE-2019-10203.patch: update postgresql schema to address a possible denial of service by an authorized user by inserting a crafted record in a MASTER type zone under their control. (bsc#1142810, CVE-2019-10203) To fix the issue, run the following command against your PostgreSQL pdns database: ALTER TABLE domains ALTER notified_serial TYPE bigint USING CASE WHEN notified_serial >= 0 THEN notified_serial::bigint END;- Update to 4.1.8 * #7604: Correctly interpret an empty AXFR response to an IXFR query, * #7610: Fix replying from ANY address for non-standard port, * #7609: Fix rectify for ENT records in narrow zones, * #7607: Do not compress the root, * #7608: Fix dot stripping in `setcontent()`, * #7605: Fix invalid SOA record in MySQL which prevented the authoritative server from starting, * #7603: Prevent leak of file descriptor if running out of ports for incoming AXFR, * #7602: Fix API search failed with “Commands out of sync; you can’t run this command now”, * #7509: Plug `mysql_thread_init` memory leak, * #7567: EL6: fix `CXXFLAGS` to build with compiler optimizations.- Update to 4.1.7 with a security fix: * Insufficient validation in the HTTP remote backend (bsc#1129734, CVE-2019-3871)- Update to 4.1.6 * Prevent more than one CNAME/SOA record in the same RRset- adjust buildrequires for mariadb 10.2.x on SLES- Update to 4.1.5 * Improvements - Apply alias scopemask after chasing - Release memory in case of error in the openssl ecdsa constructor - Switch to devtoolset 7 for el6 * Bug Fixes - Crafted zone record can cause a denial of service (bsc#1114157, CVE-2018-10851) - Packet cache pollution via crafted query (bsc#1114169, CVE-2018-14626) - Fix compilation with libressl 2.7.0+ - Actually truncate truncated responses- Update to 4.1.4 - Improvements * #6590: Fix warnings reported by gcc 8.1.0. * #6632, #6844, #6842, #6848: Make the gmysql backend future-proof * #6685, #6686: Initialize some missed qtypes. - Bug Fixes * #6780: Avoid concurrent records/comments iteration from running out of sync. * #6816: Fix a crash in the API when adding records. * #4457, #6691: pdns_control notify: handle slave without renotify properly. * #6736, #6738: Reset the TSIG state between queries. * #6857: Remove SOA-check backoff on incoming notify and fix lock handling. * #6858: Fix an issue where updating a record via DNS-UPDATE in a child zone that also exists in the parent zone, we would incorrectly apply the update to the parent zone. * #6676, #6677: Geoipbackend: check geoip_id_by_addr_gl and geoip_id_by_addr_v6_gl return value. (Aki Tuomi)- Use HTTPS links in .spec file like mentioned in PowerDNS announcements - removed obsolete 6370.patch - Update to 4.1.3 - Improvements * #6239, #6559: pdnsutil: use new domain in b2bmigrate (Aki Tuomi) * #6130: Update copyright years to 2018 (Matt Nordhoff) * #6312, #6545: Lower ‘packet too short’ loglevel - Bug Fixes * #6441, #6614: Restrict creation of OPT and TSIG RRsets * #6228, #6370: Fix handling of user-defined axfr filters return values * #6584, #6585, #6608: Prevent the GeoIP backend from copying NetMaskTrees around, fixes slow-downs in certain configurations (Aki Tuomi) * #6654, #6659: Ensure alias answers over TCP have correct name- Update to 4.1.2 - Improvements * API: increase serial after dnssec related updates * Auth: lower ‘packet too short’ loglevel * Make check-zone error on rows that have content but shouldn’t * Auth: avoid an isane amount of new backend connections during an axfr * Report unparseable data in stoul invalid_argument exception * Backport: recheck serial when axfr is done * Backport: add tcp support for alias - Bug Fixes * Auth: allocate new statements after reconnecting to postgresql * Auth-bindbackend: only compare ips in ismaster() (Kees Monshouwer) * Rather than crash, sheepishly report no file/linenum * Document undocumented config vars * Backport #6276 (auth 4.1.x): prevent cname + other data with dnsupdate - misc * Move includes around to avoid boost L conflict * Backport: update edns option code list * Auth: link dnspcap2protobuf against librt when needed * Fix a warning on botan >= 2.5.0 * Auth 4.1.x: unbreak build * Dnsreplay: bail out on a too small outgoing buffer (CVE-2018-1046 bsc#1092540)- add patch for upstream issue #6228 https://patch-diff.githubusercontent.com/raw/PowerDNS/pdns/pull/6370.patch- geoip not available on SLE15 but protobuf support is available.- Update to version 4.1.1: bug-fix only release, with fixes to the LDAP and MySQL backends, the pdnsutil tool, and PDNS internals- Update to version 4.1.0: + Recursor passthrough removal. Migration plans for users of recursor passthrough are in documentation and available at, https://doc.powerdns.com/authoritative/guides/recursion.html + Improved performance: 4x speedup in some scenarios + Crypto API: DNSSEC fully configurable via RESTful API + Database: enhanced reconnection logic solving problems associated with idle disonnection from database servers. + Documentation improvements + Support for TCP Fast Open + Removed deprecated SOA-EDIT values: INCEPTION and INCEPTION-WEEK - pkgconfig(krb5) is now always required for building LDAP backend - pdns-4.0.4_mysql-schema-mariadb.patch: removed, upstreamed- package schema files in ldap subpackage- Update to version 4.0.5: + fixes CVE-2017-15091: Missing check on API operations + Bindbackend: do not corrupt data supplied by other backends in getAllDomains + For create-slave-zone, actually add all slaves, and not only first n times + Check return value for all getTSIGKey calls. + Publish inactive KSK/CSK as CDNSKEY/CDS + Treat requestor’s payload size lower than 512 as equal to 512 + Correctly purge entries from the caches after a transfer + LuaWrapper: Allow embedded NULs in strings received from Lua + Stubresolver: Use only recursor setting if given + mydnsbackend: Add getAllDomains + LuaJIT 2.1: Lua fallback functionality no longer uses Lua namespace + gpgsql: make statement names actually unique + API: prevent sending nameservers list and zone-level NS in rrsets- Ensure descriptions are neutral. Remove ineffective --with-pic. - Do not ignore errors from useradd. - Trim idempotent %if..%endif around %package.- Added pdns.keyring linked from https://dnsdist.org/install.html- Don't BuildRequire Botan 1.x which will be dropped (bsc#1055322) * upstream support for Botan was dropped in favor of OpenSSL, see https://blog.powerdns.com/2016/07/11/powerdns-authoritative-server-4-0-0-released- This makes the schema fit storage requirements of various mysql/mariadb versions. pdns-4.0.4_mysql-schema-mariadb.patch - preset uid and gid in configuration- fixed use of pdns_protobuf- update to 4.0.4 - fixes ed25519 signer. This signer hashed the message before signing, resulting in unverifiable signatures. - send a notification to all slave servers after every dnsupdate for complete list of changes, see https://blog.powerdns.com/2017/06/23/powerdns-authoritative-server-4-0-4-released/- added pdns-4.0.3_allow_dacoverride_in_capset.patch: Adding CAP_DAC_OVERRIDE to fix startup problems with sqlite3 backend- use individual libboost-*-devel packages instead of boost-devel- update to 4.0.3 which obsoletes b854d9f.diff- b854d9f.diff: revert upstream change that caused a regression with multiple-backends- update to 4.0.2: The following security issues were fixed: - 2016-02: Crafted queries can cause abnormal CPU usage (CVE-2016-7068, boo#1018326) - 2016-03: Denial of service via the web server (CVE-2016-7072, boo#1018327) - 2016-04: Insufficient validation of TSIG signatures (CVE-2016-7073, CVE-2016-7074, boo#1018328) - 2016-05: Crafted zone record can cause a denial of service (CVE-2016-2120, boo#1018329) For complete changelog, see https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-402- BuildRequire pkgconfig(libsystemd) instead of pkgconfig(libsystemd-daemon): these libs were merged in systemd 209 times. The build system is capable of finding either one.- update to 4.0.1 Bug fixes - #4126 Wait for the connection to the carbon server to be established - #4206 Don't try to deallocate empty PG statements - #4245 Send the correct response when queried for an NSEC directly (Kees Monshouwer) - #4252 Don't include bind files if length <= 2 or > sizeof(filename) - #4255 Catch runtime_error when parsing a broken MNAME Improvements - #4044 Make DNSPacket return a ComboAddress for local and remote (Aki Tuomi) - #4056 OpenSSL 1.1.0 support (Christian Hofstaedtler) - #4169 Fix typos in a logmessage and exception (Christian Hofsteadtler) - #4183 pdnsutil: Remove checking of ctime and always diff the changes (Hannu Ylitalo) - #4192 dnsreplay: Only add Client Subnet stamp when asked - #4250 Use toLogString() for ringAccount (Kees Monshouwer) Additions - #4133 Add limits to the size of received {A,I}XFR (CVE-2016-6172) - #4142 Add used filedescriptor statistic (Kees Monshouwer)- update to 4.0.0 https://blog.powerdns.com/2016/07/11/powerdns-authoritative-server-4-0-0-released/ https://blog.powerdns.com/2016/07/11/welcome-to-powerdns-4-0-0/ - packaging changes: - remotebackend split out now - enabled experimental_gss_tsig support - enabled protobuf based stats support - no more xdb and lmdb backend - added odbc backend where supported - drop pdns-3.4.0-no_date_time.patch: replaced with - -enable-reproducible- update to 3.4.9 * use OpenSSL for ECDSA signing where available * allow common signing key * Add a disable-syslog setting * fix SOA caching with multiple backends * whitespace-related zone parsing fixes [ticket #3568] * bindbackend: fix, set domain in list()- update to 3.4.8 * Use AC_SEARCH_LIBS (Ruben Kerkhof) * Check for inet_aton in libresolv (Ruben Kerkhof) * Remove hardcoded -lresolv, -lnsl and -lsocket (Ruben Kerkhof) * pdnssec: don't check disabled records (Pieter Lexis) * pdnssec: check all records (including disabled ones) only in verbose mode (Kees Monshouwer) * traling dot in DNAME content (Kees Monshouwer) * Fix luabackend compilation on FreeBSD i386 (RvdE) * silence g++ 6.0 warnings and error (Kees Monshouwer) * add gcc 5.3 and 6.0 support to boost.m4 (Kees Monshouwer)- update to 3.4.7 Bug fixes: * Ignore invalid/empty TKEY and TSIG records (Christian Hofstaedtler) * Don't reply to truncated queries (Christian Hofstaedtler) * don't log out-of-zone ents during AXFR in (Kees Monshouwer) * Prevent XSS by escaping user input. Thanks to Pierre Jaury and Damien Cauquil at Sysdream for pointing this out. * Handle NULL and boolean properly in gPGSql (Aki Tuomi) * Improve negative caching (Kees Monshouwer) * Do not divide timeout twice (Aki Tuomi) * Correctly sort records with a priority. Improvements: * Direct query answers and correct zone-rectification in the GeoIP backend (Aki Tuomi) * Use token names to identify PKCS#11 keys (Aki Tuomi) * Fix typo in an error message (Arjen Zonneveld) * limit NSEC3 iterations in bindbackend (Kees Monshouwer) * Initialize minbody (Aki Tuomi) New features: * OPENPGPKEY record-type (James Cloos and Kees Monshouwer) * add global soa-edit settings (Kees Monshouwer)- update to 3.4.6 [boo#943078] CVE-2015-5230 Bug fixes: * Avoid superfluous backend recycling * Removal of dnsdist from the authoritative server distribution * Add EDNS unknown version handling and tests EDNS unknown version handling Improvements: * Update YaHTTP to v0.1.7 * Make trailing/leading spaces stand out in pdnssec check_zone * GCC 5.2 support and sync boost.m4 macro with upstream * Log answer packets only if log-dns-details is enabled- update to 3.4.5 Bug fixes: * be careful reading empty lines in our config parser and prevent integer overflow. * prevent crash after --list-modules (Ruben Kerkhof) * Limit the maximum length of a qname Improvements: * Support /etc/default for our debian/ubuntu packages (Aki Tuomi) * Our Boost check doesn't recognize gcc 5.1 yet (Ruben Kerkhof) * Various PKCS#11 fixes and improvements (Aki Tuomi) * Several fixes for building on OpenBSD (Florian Obser) * Fix several issues found by Coverity (Aki Tuomi) * Look for mbedtls before polarssl (Ruben Kerkhof) * Detect Lua on OpenBSD (Ruben Kerkhof) * Let pkg-config determine botan dependency libs (Ruben Kerkhof) * kill some further mallocs and add note to remind us not to add them back * Move remotebackend-unix test socket to testsdir (Aki Tuomi) * Defer launch of coprocess until first question (Aki Tuomi) * pdnssec: check for glue and delegations in parent zones (Kees Monshouwer)- no longer ship dnsdist here, we will ship a new package based on the snapshots from http://dnsdist.org/- update to 3.4.4 with a fix for CVE-2015-1868 (boo# 927569) Bug fixes: - commit ac3ae09: fix rectify-(all)-zones for mixed case domain names - commit 2dea55e, commit 032d565, commit 55f2dbf: fix CVE-2015-1868 - commit 21cdbe5: Blocking IO in busy-wait for remote backend (Wieger Opmeer) - commit cc7b2ac: fix double dot for root MX/SRV in bind slave zone files (Kees Monshouwer) - commit c40307b: Properly lock lmdb database, fixes ticket #1954 (Aki Tuomi) - commit 662e76d: Fix segfault in zone2lmdb (Ruben Kerkhof) New Features: - commit 5ae212e: pdnssec: warn for insecure wildcards in opt-out zones - commits cd3f21c, 8b582f6, 0b7e766, f743af9, dcde3c8 and f12fcf7: TKEY record type (Aki Tuomi) - commits 0fda1d9, 3dd139d, ba146ce, 25109e2, c011a01, 0600350, fc96b5e, 4414468, c163d41, f52c7f6, 8d56a31, 7821417, ea62bd9, c5ababd, 91c8351 and 073ac49: Many PKCS#11 improvements (Aki Tuomi) - commits 6f0d4f1 and 5eb33cb: Introduce xfrBlobNoSpaces and use them for TSIG (Aki Tuomi) Improvements: - commit e4f48ab: allow "pdnssec set-nsec3 ZONE" for insecure zones; this saves on one rectify when securing a NSEC3 zone - commits cce95b9, e2e9243 and e82da97: Improvements to the config-file parsing (Aki Tuomi) - commit 2180e21: postgresql check should not touch LDFLAGS (Ruben Kerkhof) - commit 0481021: Log error when remote cannot do AXFR (Aki Tuomi) - commit 1ecc3a5: Speed improvements when AXFR is disabled (Christian Hofstaedtler) - commits 1f7334e and b17799a: NSEC3 and related RRSIGS are not part of the dnstree (Kees Monshouwer) - commits dd943dd and 58c4834: Change ifdef to check for __GLIBC__ instead of __linux__ to prevent errors with other libc's (James Taylor) - commit c929d50: Try to raise open files before dropping privileges (Aki Tuomi) - commit 69fd3dc: Add newline to carbon error message on auth (Aki Tuomi) - commit 3064f80: Make sure we send servfail on error (Aki Tuomi) - commit b004529: Ship lmdb-example.pl in tarball (Ruben Kerkhof) - commit 9e6b24f: Allocate TCP buffer dynamically, decreasing stack usage - commit 267fdde: throw if getSOA gets non-SOA record- update to 3.4.3 Bug fixes: - [commit ceb49ce] pdns_control: exit 1 on unknown command (Ruben Kerkhof) - [commit 1406891]: evaluate KSK ZSK pairs per algorithm (Kees Monshouwer) - [commit 3ca050f]: always set di.notified_serial in getAllDomains (Kees Monshouwer) - [commit d9d09e1]: pdns_control: don't open socket in /tmp (Ruben Kerkhof) New features: - [commit 2f67952]: Limit who can send us AXFR notify queries (Ruben Kerkhof) Improvements: - [commit d7bec64]: respond REFUSED instead of NOERROR for "unknown zone" situations - [commit ebeb9d7]: Check for Lua 5.3 (Ruben Kerkhof) - [commit d09931d]: Check compiler for relro support instead of linker (Ruben Kerkhof) - [commit c4b0d0c]: Replace PacketHandler with UeberBackend where possible (Christian Hofstaedtler) - [commit 5a85152]: PacketHandler: Share UeberBackend with DNSSECKeeper (Christian Hofstaedtler) - [commit 97bd444]: fix building with GCC 5 Experimental API changes (Christian Hofstaedtler): - [commit ca44706]: API: move shared DomainInfo reader into it's own function - [commit 102602f]: API: allow writing to domains.account field - [commit d82f632]: API: read and expose domain account field - [commit 2b06977]: API: be more strict when parsing record contents - [commit 2f72b7c]: API: Reject unknown types (TYPE0) - [commit d82f632]: API: read and expose domain account field- set $LD for now. this fixes the configure check for relro,now.- remove custom PIE handling. upstream does it for us now.- update to 3.4.2 This is a performance and bugfix update to 3.4.1 and any earlier version. For high traffic setups, including those using DNSSEC, upgrading to 3.4.2 may show tremendous performance increases. A list of changes since 3.4.1 follows. Please see the full clickable changelog at https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-342 - move man pages to section 1 to follow upstream change- disable botan and geoip on SLE_12 because of missing dependencies.- Fixed broken _localstatedir- fix bashisms in pre script- update to version 3.4.1 Changes since 3.4.0: * commit dcd6524, commit a8750a5, commit 7dc86bf, commit 2fda71f: PowerDNS now polls the security status of a release at startup and periodically. More detail on this feature, and how to turn it off, can be found in Section 2, “Security polling”. * commit 5fe6dc0: API: Replace HTTP Basic auth with static key in custom header (X-API-Key) * commit 4a95ab4: Use transaction for pdnssec increase-serial * commit 6e82a23: Don't empty ordername during pdnssec increase-serial * commit 535f4e3: honor SOA-EDIT while considering "empty IXFR" fallback, fixes ticket 1835. This fixes slaving of signed zones to IXFR-aware slaves like NSD or BIND.- only enable geoip backend on distros newer than 12.3 before the package lacks the pkg-config file and there is no fallback to finding geoip without it.- fix permissions of the home directory- enable some backends that we had forgotten: - pipe (main package) - random (main package) - geoip (new subpackage) - new BR: yaml-cpp-devel and GeoIP-develcloud117 15859381224.1.8-lp151.2.6.14.1.8-lp151.2.6.1libluabackend.so/usr/lib64/pdns/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:12262/openSUSE_Leap_15.1_Update/7a6cdf7879925af089f69ecf80dec0c8-pdns.openSUSE_Leap_15.1_Updatecpioxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=cb795819295f4824ba21c52418b2ff9ebd986ed3, strippedPRRRRR RR R R R RRRRXz^utf-8b874a5fb4b95db3ead26ad6ec7b6974373c341286b566dfc690e76ad1267811e? 7zXZ !t/[P] crv9u,2p1;V}/20YBtCow ڑ"{ w2Z]}cPѯ=Tix5PG:RРeF?J'+r]tWmK lxk?\o׌O_by%W:Gg욻n~_A6ՑpCBd(۠*z`|P:fS~"w$b)nZ[/wCXv{^6PT?0u O{uAeĦaQZd4>\qt,+PZ`g*ģR^x9&@5?%~`KS87 Ϻ욠6"r=جרsÂ5eKUy݆s`StO*R} {k92B [b.摳ނkVSrUqQTOd GLt@\o< Jbr=hb2$ )ޡ3~aLg_qmE"aORhޘ#TdEQl&vqmMf ]T؞ YGbYx&ϭHBwob1""4b .!OTT|u5 rTaK!E%lN•2N1-w:xvo)T(Ѱ0|y_Ō7pC#zՇЮ8܆oN6Ź .}Z+lT),yz솞 uU0uV_`a5VG*ͩŠ?"QmԂ苿2U#͍|>CgC} ٪N(}Kc : mdH@J8NeG~#99R8Քz6(jx=QZ 3u&:UCgCp{m m~*l֙݁3;$x-Y8q )`]vTIR2,o0/,2$)w鰨).Lo|}k^ ?$dECKإij2bUBbY0 @7BQGڱP!{{è6vf <F\@)K`\:.5NՀK0xv?UMy왯`=fuvx ly.= upq1vP%j/CE3O,.üCrlK^$~=p7L]/7B5|єjNxX=#[&*sýA3H5-\~T ڙ<%X期{PNXq 8Fw# &A_&e"AnS_y` O=v?P"ٟ+w7Ly4dŊlj.M `6syڒ!l܏Qb=P._1ȔN/gl!T? 8V~IK7]u%8LC1Y~Hz.+%*;WzF8J/u$7>;15\HDg6!^T-`!PG0Lz50:#ժ چlGHBr0+n1ψa*%-Wdרm!n>jC#!%^\>=ԉ[E̓AҘX~c'Q~ÕvV"k8I'-[uv,76R1ѓGTa //(vn4H)ȥIޢHU2Ԥ0ps!|}ZC H/k1u!GLH7行%_WkkhVhF5@뉽2XgkE&h)ZK&ڢGnEc5Hh->s i 02@>8῍@w#]ǀRЮ(GΧ,m>pUGq) bZe'@Vjv$pIFD~Eѩ{jCYHZ匍?(_WbkׄJ1m.3.h9 ;^Rل0atPi +ŘjIpx'z==V#5z n+@TnRV']c,N-\1E-끊? 9A/|3:l[~ȟ'yB jyhBR%T;cQ;OnѺͶ(.P݋-)N +K }ʕ$kWW.^XtT4~b6^:cQ}֎ ڠQhT^Շ] ,8OoxnDvw1_CKIս1-v O "A"n31{$<$K%;;;z :hixzP>B/:7/Ofg+ ;P9y\+0Ҡ5l96&&ׇ ?wqWaLL3蝐L5s d/CyF.ɣr5g89s SuӷB#b39;©_j[pꚛd^ci̹RZ5~0DB4 SE[)T| zK&"أE޷n {Bm>i%92#M<[qs*>3ڔK~炏,de.>WqgAO,rIUi's*h)! z:c ^)8tZt7åvZDMV C8%!e0lWW يGpy"!})-%i{.V+|KP-7z|ΧyVNҺ9:y@C %[~i7G8" g'xHpaSs aEFSߍOQ-CPɔ 8xd_H`<&Kw` {V<2r)SR1]eϖPv_92W8sڵ<쯈M!ޘS_a:K]A^/!k5X7ݰ-tK!HR'-x\{QotEFy^t斖.j9 Exj1}}mWylP%CrhFYI\ ⚗nfR^.p 0 GsԚyDgI|BKO4[֏IyBSSԒk˧uެ&Khl{XSmju B0 'B}UPܐ\PS=C4=!K-WrcA4[獿jms("_9]I(oI4@CD>Dȁ UI+yyCWmXv˂ )d* Vv;竼+_)_ o8!VKSCԏlg$9Zc!9yOpN[qߏo=(m-ߢQ;1|{ \M;*lcFbϪeӠl HLPߐ*dy5g40206Lk~͗'`C==^4ڮeK%:2˵&-9*BE, ~w_05#zalςzo>vƄ& \ 9Qo @gQNp9>94_Kdw8X.!F" f64 #aNj\mPyV̉-%ǡPøtx3^=tR`m"IslsAi*3VoƠ.j%mUam'RI˪qRx]C*LZ׫!E mpl6q&gTvȖrqT *cA^y[GsLOJQ4W;t-^ϵ`hr&4%?S qk/kjc>U$C"ۿ D'A 5JhPI%(F qOaݙsmr]AcGwd`Wečs7Pw`2H`N_<4Y8`ΏD.6i2.ND21D*VJK=纗mIJaAtyާ%.1g_ׂ]/U}A,8DbîӢ'̻m[݁-Gw/Spu<^IU$_&NzSٲFBwa(שp9@jjI+/ew+8\="Z]gnhW@,Xv*`#U E]?TI;-/ʒ^ 6%A<OG0K2fTB3aG,ƙVgU-4:-m~-QV5zTKW'+a0 ~2t IKՇ_`Qhk(WS)Eqo~h`|~n&r#jA`Dskp mަ0\v"m2bz?G" 3L§8=sd[JH]2}iBQn<$NT~R.k %nn2:7=SP_ܮɩLO_4D_rd^yU ,6Hݢ?,JVq(/K-9_YH+ei s?4NTɻ4 _ZpH:# sn [!^Ȅ-,| _Vr3;V'صfDH%fϥuT 6 3=$nф?ũ[LUE!`p<ݶQU{";1t[@vPCk;28sYݛ$3jMus>VKNP|dYL5 }(pd((Bd3v'%/7WGd.0t.:8V&?fZUǝE=qK^qbKfnT ;)[-뱘t'?" aϨ!NVงΡTx&Sj]lz6tBqI,` V',W1p^AR|UR4EzgNPpޛE14x_=+1pE/n棈uL2N'{R)fR# 1^Y璑e2XR߁eCTo܎^0mSW%A8yv(F,tغaR&TlcgP3mbQ^: {ASv0foFDЯĊ1hvK]Q{rI{._oaGjl3ƥk# }0Si|,An S X)'$X{@DY`$ZeOlBۈ/zr49ǀ=KuJ| 6l#>=^` XϼG t oRm]])|1"yjyLS͜ U NCNyv(}lp,[PJLCurZɋvp/("8mLh(Y/JuF׈"xf#B kX4^U[r[]@y:SƸ ȣCb(p^Q1PPȹwa-73n$/'uLBd;9o C̵&*ߵ1ٲJ:g~ۛ;׹RӧWħ+پc% jyncpTHF+xHɡ!( hwRLAm1鑊ЉoQ`dQ?am)ˍtqLIFcKwQD-ݧҖF8Z>ܵAu_$wjO?ԇ˰Q*@ug #rPm)*'LX|ϭ>L2q/`e.5$4)HySc WQ( ti(j ?6I1Y%qn<qԽR)IU.1.9ߘ(BD.0n!]0cvBQʀY&#e)^o쁁)[`*Rt" boY&MjL)9(KiW6˳`Ҧ?N߼uոQΕ{JۧxdYFI(Pies`nzU<8Cv<ڝA|+*v6!j9ŒcPvԚ4%H=  !v? e&$<L _$UH7 DF s5cNH5HZWHmfCWiih br(%GP6%=} H3RFAa&Lw5vč|/r$P$q-cvȽQzѥ ^#0_dё\Zw}Al8Y TFD R4Pk 9Z2~CUK&karlg&> @"58Fj;kүHtsZH\TsTX D%'<atpE=S/(7^A"eU7Ԛȵ[͈}Z($[z{gWУ[I䫤n#2Y<\ⅈyvv^ mjoΙ]">G!&^V#Հяʅu붏CUh^W=r9 @5f4щAbX؏Z-6c10,I:B#wHv/]4 Xm;c .2d6b %0EB1l`nG ^fi{ ɦ~H ɥ?Y.+#tUn zl.|ndvS1]ɶDXyY!VdF3BSM^ ?xًk45[Z }J|%V,H6\'6~6d솭zy$0NX~L|Gd#N֧1R{렧x'yP敚Ƀ9hNeq+fVYaB:L4 )oh)Gdֻ.Nl堄ǂe'^FFyyA!%kE9zW:g-iXZAܟNJ|ХA}s؂/OE`PC>D RQŞ`{Qa0?{{ Ig0t)?2YJ<^ڇ50_a3z]E.'V"ϱ撩ݢY-v\ loT1o3EcXuŀR߸EÂ;eJf@%j8rY~"9;ՐeÊl{.uchů2t>!'F, ZJl.Zl0n8\m4JgtGް 2(\>:y"{LjЭId")ƙo>U͗GU&޽mި]^O|Ԓ;˜sFeؾҐ&F#>k!S}2.T%jEAV2V BʙR7pĀ}Ē6ݟQ(61doe I%0pApZ҈/rH:4A?/6O9 :S\Hc"d6|^?h``p8#>yx/|2?n-`\e#Pe( alwhVFu: o5Gc8?P+E.EEg6|c`?k*E<1#CZ~$=bmCBUpBlYJ@sv-rj@AQ]s<:!4g:o7lg#@K}p'RwT4&{ZՆI.Vdto 'RG۠G&-$ Qv D  ߰5J4w%9X|yfPQnr:X a0@V‹ЏΙFSW3?Pe?XpN b.!jЈ+o⑩T4-*x_տ>Yef5JHL6;[Ui.-͢=! iYEb#YaST( ^ΌGƅ+ mM01')uM+>JZAl=+2?@ޜO\UYt/X.Ct6c X$RDBjmwwۼ+VJoiqM[?N ʄX(CZ.[w'`5j5nTYYv(S&hG"=q`]f4ՓnWыgz0SMs Ȩr1Nls[BhG/@&$CS9XǢx-2kl`~FQ-;XT6;|Z<)}Esgih{i2"%6(8uuґ2 -Ӷ=h !G<~#}ss[018<R=^?z܍tHw:ݴfj R U*Kg݅%B0[,[ z̓ZrV[xc_-<|~+ ?ԙ/NJҒ}@,4rkXMr7TlN'<CF%{LgcZ+}XajcG!JM0`b&eѴ;ˇ"uT6w '?+j˰ 1z93y s"Ba J2~^՟%_ D>ˊȳexSH'?K/7uCy<^ᏬxXkzVUK kA> z !~69*`*Ƿ@ }3jb'#BkWG }&҅^勦:af^lSPX)f3#E-ي#ՕjLRZ%nQh41B`DŽL,ܻ8[ጎEU]}!h[\ U|JGl'sˎ  a=ǂNlPv`5Q˘UY{21DO9< okj6S9j-B62*VsKzd@[mNY.<Րg%FriV=j,_f.:&Ќ/~aJyvauVvIU8bNŸue\Q_g粹5m &Qi"<29lBRO7M䓶% D?\*Sy9cܻ|OyDԨΕD鐃Q Qc^bm;ij,'cㅭZ*|޿k Cv9tsvuϸJsD~dou>Iž&ڽF?dHJ6x)\𡏞CUpٞF/Wo .v ϒb_nquz 9Gj I23Y&՞2׻PE"qf8CP<pPznCfgE`mxNQ>s>srKɲkNplPxVX-xU s/ KC/@Z/ՉJٔ-~ {J7 S}`Ӎ`tvߜ6QifQ r-C7$ 黼&fS5,NsYbP8D-3ojqlW9_: '*V^\uJIgνCHc#3RKGѲMqf Bdte+i4p]B" c^ˆ ކ4u",536XS6ɵK7 jEm͊qR=I۫*O% S\?!:limL$[Fvt• <76|q A=hNCws fh)Aø|Tm^5׀zyantpQ Y jҲlimes1ͱ@X`C]${{ۘḗZA, `ik͋i wsqvk)$ !F2ùo-0g|/ąMq@'623x9]Jփqד}$muSnߊeaCԼt, ӱ'Q# e뿾ZXk$͢z6;UZ   =}orP+z7䡾nL7C1!%d7G7v`{bT o=he%:ӈ9r) G?)s$74_#ќ43(O#j։ߏb]HMow#T>#J>2&<p1!YG5ZBTZf=Q Ĕ5 Р^ H" /(\Z|b/&]Z.'S?4οܱ)'^u5q֎R?@2rYcp]yF(X`TsY~ԘΜ ;gLӌ3Aj9eOS!>B4U㜮5 |PPj&BwOg<ռ B/BW5*{0aCU;Bգ}"FfIG.$r^@JKpo? qĜe0`*8:/Ƶ"LuPudtbN~o2 _T㔬'8`%ؖNs_[es |XiZC rZ?L4#*J(FK~;ؽxFǮr *9 L4?Zjn~ϋt,{m"n1 \Wa8mpFP9 Eg;{]n1Z ic<@:eZnq\V -Z~e6zJ " K,`\W4醟~c1ήVsp "PJ%.!⬱b&3RQxR3Mo/@Ҩu 2Q ƅB1imv& :™}웃P耙qZ")#6S x5#x$5t=s8lf>(m5Bʊ1PI쀻:0( XA|!0JgT@"Ѱ<]}]Vǎ13uN($WХ"hI:ǭvS?t7uH,GaĜ;2kYFu2}u>>X[`%П8l4QɊ^hi1㻺kN kk6[ʻfrYWRD@#wmPa0|K%`|܊1^fR8E/c C5w@O}dw*Sch As0d)oX.7˳ wUW_641Xݍ*nUbO}vZYTp(QXYgp9 JYKof/ׅ  5eE/‹\[L.?EPaT!qx<&4?ɇF/!qJlE0_A+nn%6B8C~`cؓO'Y2T7}4u| ;!޷JqՁ%!=+6e+a$\_QI&҄Ό+jjpağ+)~)]Zh1yY@wmvOk("YǨUR7> A:*ʵD%Ȓg3+g|cG^CLDU羜n/ /Г˒-DUf"*0:;B'Dd2:JޞaAL!$#sDypD @lC%_oW}.꿚wq.A=mЖ2Tԭ,$"E]8QjŴ [F@To+4Sﴸmw 6]1PVOA Kx#I3)Z.mIzr(Z+&)fNEj/odj9*\&T)i0- yZG$4u'g172I1< H9J>P ٬?ʦt=7 V 0\rmuՊ1,9T\l X8̲vl*:Ʃ3:7uq޻>@k9{7?>h},aY='1rgm }@˜MjJud_3y%'=m,Q/ 5A[\D޴Y\BYwC,$.L^džU±lޭ_lxh͋2R?:t<1z2sڽ:}N̮ J-ȣEzZ*FqFF(ʎcc*qnȝ4ykkR)FQŧ g[ ك w7 ZS./4U} ,SCΑ]뉻v/HT7}&)g\B~^.ՙFe'.ePl9PMm$dg RM6[& Hܔ@)9]vmv2)"xeSz!_0B@\=6e`g&v^q7r*#ꅧ,yovj3 r@*׿*O<݁)|\HȺk yS,uV7X iXqp=bV C.e _li}VM}1xZ z%d0|=h A_R9 ,L&Pc@Yny)Q :;{k*XH 59A߽:/^&2) }]Y!Ɩtkpgq1w%dƦ`xwl:߭zq¸8+x gj[ T `7FO޸S3EՆ-zuVv7OWZOPVypQ&1nԾTTҡ u$y'dPcUT8C#[u+b$ߣ!bk9%2gO 䛠2 7''g#/ ȰܨIJEC]wтoEIP}XnT8d!zok} LgMhrE$sEY/9ߴ8Õ.3 F3/Ndƣ59 QC4`x]rlԛm4ohS=a?=蔌\eW縉C5𤀋o8ރ=Щ/k%Aey<5D8:Fͦql՝cͱ_i#_B0"a@&!trZ#|=m'?нDo;VZ,/,K`<8 [U:25U TV5 -PWwY =E8}ȡ- R/LYA398&&2+SgÏ#RXw]dFuYUط4#\mTՂVsIZOsMuNfpoq\75]~?oSXCh_ XHD4H1zsv'+yHC:y-NRcb@&L&f%GӠI9qZP &0c:x W0H#63 MnfJlB&2f0}l1'?ECfjc7 [6B5Ke l 5C e׌!~bþݲ̊=Ҹ*&K^TnByDv$^q'x{AKg~<5)GL棲;U5=#]Vm#b@Cxt˪ n Xuy,Ig]ap;thlKdOOQXƩ/Zz |h*&ŋl+n]E*a`YZ͸>Ž(A3.1Vi/٨t>$v}P2ϤE: C.E+:Hϫnۘ'բ PkE2o%5Q =,xRÙPIaa@J1GbJ,g0\֤>T.mN!PQ| .@37i4Dg?cg%͸PbA&vD .7Esi`뫺flf>SГ??UD{ >NBM2wbBNγ/kdw\A?Vo:]%wyʳryɖE e+!ï?h1e|/V?n-VG' Q+Яh8|Oȿ;"I'._J%pQڍ%A]u<܉ yv9]GpNO9'ǚܑġzꘇ?9{%.!\GĶHRh L^ܤTѩ5A9"XPNnr{H`EH`R#e (P@E얢J_`( I;yJS"X&%OeX#TG^(f{Bu\srj7n:n3I+@%x I?7C#c%\AӾ,Ҽ V g;Il}旅L wQᯘl+V6e:m@[ (F7Rh]}GMddF1 IGD,Yk>&uz]kCr*QgQz|>fs;Y*vMQdg%m:-Hg%B(D5`gӃ_՝:h:4K|#aZj0, Ruf"; [桰1՗NE›;b\YdY?bi޹kiT{CsԍJ 6Te\OӠ:k`P$*Z,XNbb|_NQ=9a4 xS6l2bW~1ԘFq}x'%nA˝i,NP+9aOX9Hbe5VuLGge혀k0ͺm9x6\c\n[^?ŃV@TcA5@L3}{ֱ,V vz d`RN!ϊE^;X:j&wxW٢\vJMbws4p/lL|h>`{xEL/PvjpCബ|>dDZ;5B+ 6$b*uj(`+{Β$V)g5PÏ~Eɭn?3yT.7m0 ͷ "O}!d$q z$S.vQ{_T(m(bBn{EX7 mrdP>I,"?6_ldte,w ~Y><mble+#Ap4⛴T[M A0~uU"I5Cʶc6mщ^M0O(DX @ӎ/?<'j0ڍPK,R?h&@_V81^p[Ô& A.G}Hu1⡷,(^']`#iQ2%kh=1F3Q+.xPߘyi)Ӽx{;+7!mcjpVnO:6AޖZyfV blUۯY C4㉟Ydb[{Y/p={C *:I'Qb ZW}oe>*0 пYjB^j߁6hryߏFI,R^އPՔV^luߗWAE,S\C\fR&y^i)O6x57n#f~%99W\8\B%M4tJ)VCؘfm7wĈ^4Wz2wR/$Xh.1ڄl嗛Kmu9 ҿg}M,+O ;AKҏM@ۜx*_b}9 'k~]aƉ&|y%1^ VAm_U>-6R,/z@_`>A *˪gؤFj]AZS:={T7OAB=BmFn S("KΞ#1e)6I!4_=feaT Lưd76%=/&dhȴa g ZUXaߪ;yf >]!9R,@!3!B9&n^'֤Hi>ϥO2q@i9 3 •+wl V&F'9 Bݩ∛BxxWfF{e|e+avll [NlV/>_5+A|DC`%Sz3ʏ~Vk2WĭGEKPy1=|I/G/W;_}s:#*&(_;@[,Vܪ'rx V2|8˹鰇!5` Н :}}~@k%7߸]YsҼ>kx2X)SM0Su#a{ ڏ\"$O$UFÅ/pZ?\y~Sk-xV2crݔbiphZCW͹c乣 wOKFKj#(OL\l0lN럚 uxn?EXP`9LmA)UwgA(k݉@Q[5}lG0]م ٕ1K:X#][W_0_y‘z Vz(ck]%~L !1DpSNt/D< Wn?M֩K?KQ\]v!Vz*j`uPtO Oۇς|Ȩ'|Mb.X:2poa_G}.w;o3$Q: 0e WNxSn2$~%LC\C6 8QKڲr!jPsū,q3n@,ĽZkm')3ٺ&t4Ai=wwYcIg$*L9W.#㯛%NUֽ&̒bӌHq(`f:&c.;.(e0awtO`-a+I)y38Cc'2˻5F\XOJŶ{ng  r]Q-p$b_h9/{Ӿ`TR)̣c#x3CTQ}ibIPs9V:7i# le^d8K=])EF @T *x)p=*hjXLXji\Qӆy{C%J+n\n_3o$ZZc^O;,N%$d-.KVِ1c`Wq܊i>B HݣBQ?q.NH%+NN^8XC];XR,B_ԎƔVx͕br Pj7 vM>gOA%x.)Qe$c|/+deɓjB(c'KIIH閯UXDM }cC@sfL|k&hIʯ'{)^`uOo==V5T}BDpJ>\ ~uBd-R/~ 3\?_)³Eh*ʼn ?-?#~񊉟x~NcxDS(6,>]XUƍ18 ¬a@zme7ww'K% 2'HI!*te@{1\ Ry;/|rZuxmHy ; )-uU-jir\}Y-yjn#˃,mw] L%p@FE2iL q0uc@/?ޏզ#rN s~Rv9HEC`3<eM lt; p?p_m{oUL:n+gd:PJ tD0aXeNaTM9rɸa %h|#-I{xp RW{똩jCCr9\u0 e:0 $ 3q!NVvnDXGkF](ޢ''7Qfz؇ui!c lµ̍;nE9q9$>^d9 ~09swAKzE?r V_ ~f2uuM-h{ƎoUپ]kZpGU-H삠jQPWO!Ȱ&\G|2g=PkT9}^$1y*AGӲ M*-L?3ɱ]I盡0= )筭9v+AِܑlLגLD2='aT aWD6@IσCRQ 9mN ?Y'ѩ b;fN_AI <\HLFw:ɸZɓ1r`vamGkċvbXճ\b$z7iȋ ]_#ԅwZePIͧWr1),c!K* exӤ6qPBB*2_|MLJʄ^cx׾akIzIȍItl8kuMOC_pMhSAVD<0>豼 k/2)j.˸qƹPYe֑ʊjkDœ6oW'̛beT×5{H:1Så&d1M=OtjLlkLGI_ S|{_ȋ|iA"jpDz_gP}5 '[̓-w)Ő2UR'UH*Ba|$76J2]v52n#<+Z-[٭oZ[N#CsrZ{n'$ չTsC',Y=$*Blʘsp㫳x?A F`bˀ0R& tq :?E QoڴoZ) G]~?I6?j$^jf2 윛hbͲ-l_T^UnѕkybQ>pq`&6cq&]OK{`ob8'0ˈ8,,\5d Q&9!g*s%VṮ#O-J7$JsOm9$RseqagL ?jfU?~4WU9wL}q-7!I=We8Mvfw#3"ar11s~#|W3ߢJQ +HF~EyD1q\6琁aiViw]q##%V)+kp$\|FTqV GΝ2{+"\uԵ}xAJQi!.zmd}Oi=٬*mp[eΈ[֝ן)gátftpZN__Zx&=#F\`^UuT2Ԗ-9{ylOY$p$k1dЄa?۩҃V?h1ꉥGmMdaoKh go }kr\ %KfrVHjO}!z<ɀ&xB) ;ur'64q0CC0X?JF1csQsQa5L$lT$*?M 5WT|||M%+.LD-7+* cϊ1mև}1oU\`'%3Lg[pri9_9lg'yXvB7q @rp9uY*2=n_M@/ے4`͟_|Lt%<l1 SUːߐ0U04W :5٢ !i79R)ƾ6~lslä u`+ 1ZY娂"wk2m؟o;Kb0|xY) &bkgX2uya`Qk%3%EXѝ9RWj3X@Ob)2ᤪvM94ӝ  >R GVӓ.8`ǴPC䢬J r8G^LhT=StzM6wr3OO mźۜ{04Li~˴JH"}̈.)gAc/p?3`%‡SdtԆq0bu"f'٤gm$ӫ 5Ұ:=8 m~KvdžϙL3'MDM.KQ~0ZEznE0b1 GET ܉.]jͻ%x\Yyʧk_ smїZPE/O<%i{arLI83wEvJcj1JGĢff R{"W{"eܻiR q?5-xUpgs . 4rɲQ)#w~5 ng6FU⃶EL[Ô#foSZkNЭrj,h?Rh]d/qDVB:cb c3Vq;D>|G[Ӵmtk+e範 }(6Q8DTFyny&19LdUb]tɏG;> -1K6v2"e'x@ յ^>Sg 2;@gcsU,\A:9Z6vz7_g19ͧ_% M5/pS h t=XڂB0EW@Xk42 =egt,[GGBq|ML}9c~FN i)/yb1s}`ωC1ZaUga:%gAB6B[k'9?"Yh )\z$.)$KGٙd5B" FpAs̩ͤ{<-QD=7?h*`w{@\aP}919ABZ̀:5 feˈ@RRcV2Z`25OW\bM Kx+5nS+-Jߝd;Q^ >؂;BU2|JC'qa8OPOg>/PbTR*̡0Cyh>b5juRMsQp @NF@zٖ/D[7osa_p@dy_{g&' O6ܬɊƥȐRˠ۔.vvҴdQLšuŁJl:/u6hNWN-Edi 堇Lwyd ^_Y tã@,dH T6F2K\d `B l`iw+<87d! 3%5,#=+<\dy~WK*{ H8b#0^+\xm?1+xFZRY!olq Y͍1&=c(5/n_1$ Or1)8ʌb0PŸw1d*m_<I| ޴;]Hg&G@e~0v蹕k IxBV aB}`* h $=n_ÄDĦ{|eId$axБbМ:gS :g s8*uln=&l_܆Tqa5- jUzTDŽ8Wrb^" &ޝ ճNP~6 +B]m6'"E:Vj똃 O~j#6I0E  m̭Pc# |ӣ<p@n<7A> -ƶ);PDBd~;Rf䝝u~3=u%/2!GUWf^ 6O<.xpSs뉥>Tm;\KMwNfP)ɤPW,?[Q53az>h*./ԙ4i%c7dy{,]uOV!Ŗhuxi9;SGj䴰^Z.'\Zn "zV9OsS/*ͳl_cB~H 5"MQO en"hEqN0'#q .1=Ӫ-yEˈ~,45D Q%gX^2A 5.erZKx\NK/G!.FPDپX˓kJhKTsV ~ML9XX #[3N15YfS2ڟ#;ChAwah`{wJ aGrZ.+nw9 K_ 0G~屣'ЇO{pPh>H2u& |6:( !&+ޑ'9 Ug󎱆!G(9O9pE/X0=0ݜ4˦n}`iZA2l=Mfd'lJw` GWKWUYG pey8lUw1Ϛ˴^GTB+FttAj+A}s)p672S8A.W綾m@ߡ)1lL C_mϭ|94m]&biٝѭa,gͶstðu([I?~pu" a%5!$QHoo.Yڰ`+@y'"i-s1pOhwPӎQ6f7膘?Ss~V.GH┨eVI`U;eˊeRқ)**5mhY'fx : Ϗvs%Fծl6Mw͋cnȷPYX㟽$ TNhמXr,<L8 O<4:jrrWl V=0]l$fjgѿJv^y!+ ~9|Oq o#EАf2 8 cKS0UNPNc),.?(<RCJ[!S=m')l{TLs3NMfwPmYv}F߳#wT{INɘ?4CUz^UeH6L(ǝ>G<(N.Tc,%77RFeaOO.d)h;x1͕BSX.)!flIǑf_riR4 f&U2Z֟{d-nvRp&H\f h?8L}l# Pu3<+;|aiEzm)&! |&&=Sq fu<ZA0;6"X3.2Vyŋq$dy{V'-Ww14T!9ƈ'7v #C=>¾ c%{M!_UUp];7##|:J+,ho\daAj}d)ƶ#$'B~Qڨt! (ۊ\4 zʴ@mۚB&,~OMss3!ƧE k& qrl۹0皅POŚ)dܺ彚XA4t'euQGѢ{ ͉ AE_zs5t;`@N_$O Ѿ/y/ZWL{.k5WXĨL䘝W_I3h c^d%)Ň7^Ho2lG.QJ;ON~4(Hm<Đ/,YB `ͬo{5P?ބA׍(n dJ;"(?DLa|v?8</_IgU׸1mRmUeEGurFjQѱˏ%%ABیLƆ&@Ja(MEO T TZu/lT6z.!;RraJ ¿Λ<\3_%) fM뗋$ZNE\Jy!MLA$i=>pepxnqejOEXJ&"U+y-':BnXLanhAI1Ӊ!jΧm>>A?`7Y+O"Q'=L 4_4[ w]UUKi{@YF&B6S 1FRNp4%f{!c05Isr2ۇ0'Ҟv,?Wx5`)4ͱjPK|[EBcnOUsO氧>']Rʹ$d8ś}AZC$z>!Zf5WD1v_G? P:ބpbb bYe5 -nm orcI.vOe9ed?+g{Tꉑ)fS$DŽf@0, kѲR' 9STbDxMAvWޞ1kY^|l!& pk6@b 8~oTPLk?4Q.F8ɘS h{WZOJ岱1~hIY]'xB[6EBKe2gq::@34q}vV u8[l&_rjtd6Gefo < ! KUW CvYXponCL{xvF>;if%|tt͜sv˭DG ^/_r\g 5r#k̸H:@?3@9ʴv|v(r ! St\*gƣy΃1Ze%(y# s B5z@uTĄ5y'77+HC/ Ucb9]e ZN,\HF,Tט"Sq逜#wn"vixf-=czZ@;n>* dC`rfu WՒ`ZtyѼ(hږYnwWdquZ^A,?'}92+׆ʥYyȺ+oXg%ʈA$nS*&nO] 杇WB i?,F2`񘈿yejj9,۟e0sC/mЪ )vq7 |-ٳ ~>u<Hz$o)di[ GFug-1Q <w8Z1"xý{w\CcMt; KHs,(PNWWoW{#5OT%`nOSQy\*?669Č7^Ze6)@d$K1-/lxP)=#(0[-(!t}1w7 xeC*U@êſU2- }c!wLQA5pNl]EkRPnw|7O 87; \La9fktc&dA4:zn#(tŻr?-Y0w_L|*lra#En(j gpDM.]ƍ9 eT|ۈK!tueqeCG\[ҺzE\Ռxk%FtICϯZiFkEIhAX}V7 x'23["B(rϕ8NkcjkjyrrEdT.ϟ;#Z`[ܓ IdHjx>??G%:lT;+,)=Z2H%%?P Oo#`o;VLҏɲ.641NqPV$z|z "U(0`<-J!=ib0|$klh*[8v M&Mi{6 6Q[yH5JHC{Rno7< x%v (Mkq,* 5ť^m>&Ks ]eCT+ ͦrCTzҹzMOyhuۆ*n:\]/fHbh.i(@Ui9Fa K MlT|T`l OFu?\m0u/bB=h:u9RQNXWa4GǩAEKQqU^D/Z1Z`'vD/@*1vU^vh \֊n-w Yɂ]:xȁBwLW!7^/w܃ FMTYZTRe~ޤ8<'ƫ:LN&zvxAK@VY ʽ 1OV\(ˡQ/=)musBcDG-Z(>/H2"<>B¾%KJcg0 ;.¸c5?&hf)"R1,3J {P3*86*a^ݒʂa4V$!yC@TQ6'V4ӉS R]]s52٥ ?"}<Ɂ!e?ATʥ2_!Ǽƻ>_F_! }pҒL ^i|M'b2!IsZHx/k&Gz&-D'|Pf]gl(Q$X5;*2/Kj6_z):uu0L-OUMƮ 7QִxJp5 7)F/\@.~ .TgAezoXeyF) {~Hb)8?;G<0=gg& e#s UC(Kr$[]|\7 l⫚au׭Dx[t < buauâ^vbD,̬0GKSn;WEO \v X|R ;^R()x@U"X $&,t8w t6XOž$p#C̪ȳC:z0O-ihخUsW:m`Umpi7@rS&뚚ͻf6ƞQ:ڿ鎔:>q?J"%RMp鈸rHJ]h7U5i!ʽJ[5N5g|ܝ4{Sit%ߛ2^HPdX=ع:xѦev2?Pv+1HC 7:o ? 9$eԂM仁Y$yQ2ܦjrޜ8$~mRDK:vqW"fbdHw܌G'N*0 3@hkS3P7 =E)WnoJ+ >picdlx [rGe啵ћ)씂ZZ hcX$dLpMl$$>ES h ;)>og}1$[+GAЀUP0S#]xL;Mjyg"*q:VjY$ KJ/lEg$cba^(wHo VIT1(u 3jᝳ$t3?F4జl[/&M$K1 V1mXb\K@!_-"H=*JX?Ux%..Few142ͱaPlgN@@G&XMNړ !7D g?$[jJ]3:nphS.4 o&Tbj;#bFg 7m1Q:Bx:-iYcHߦVft1NJaH 5[C vQ.Hܒqw YZ