pdns-backend-mydns-4.1.8-lp151.2.9.1 4>$  @p_kR/=„Wʃ dTsQ|CU-FC : ikFH `l cA0͌;mߞa1ai¹p$r'@obqi2XQЖ.pT8V/ 6Bo1t#"%uJjpqR,;u]Ou}+̢l,.lb.<#ͱC,I~E/&07ipNgrezrjDo؂m#2d8ba709cc02aa99ebdecd048395671320011781cff58c84a7ac279739e271f84f7162e9633f960dca0f1c1b8c95429a53796564T_kR/=„4~'QGYEx֒iwVD.EZzP<4%Dޝ( 󤶒rlξvƈ׏Ɔ,ơuU hcY|E0JΤ9E`DǍ1t?Y3vn3Ja2vxo,7S3klhFw"t`6eK:}'I{)AEv)S!tC*9G[8P!n̂~P2jTEj_?U >p>Y ?Xd ' >  2Vpv     Py(8292: 2FUGUHUIUXVYV \V4]V8^VKbV\cWdWeWfWlWuWvWwXDxXHyXLzXXXXXCpdns-backend-mydns4.1.8lp151.2.9.1MyDNS backend for pdnsThe PowerDNS Nameserver is a authoritative-only nameserver. It conforms to contemporary DNS standards documents. This package holds the MyDNS backend for pdns._kQtlamb58openSUSE Leap 15.1openSUSEGPL-2.0-onlyhttp://bugs.opensuse.orgProductivity/Networking/DNS/Servershttps://www.powerdns.com/linuxx86_64_kQm266ed89142f24f638584627c8be597ecd09cac4debe6bb8baba8e7eb73276e1erootrootpdns-4.1.8-lp151.2.9.1.src.rpmlibmydnsbackend.so()(64bit)pdns-backend-mydnspdns-backend-mydns(x86-64)@@@@@@@@@@@@@@@@@@@    ld-linux-x86-64.so.2()(64bit)ld-linux-x86-64.so.2(GLIBC_2.3)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)libmariadb.so.3()(64bit)libmariadb.so.3(libmysqlclient_18)(64bit)libstdc++.so.6()(64bit)libstdc++.so.6(CXXABI_1.3)(64bit)libstdc++.so.6(CXXABI_1.3.7)(64bit)libstdc++.so.6(CXXABI_1.3.8)(64bit)libstdc++.so.6(CXXABI_1.3.9)(64bit)libstdc++.so.6(GLIBCXX_3.4)(64bit)libstdc++.so.6(GLIBCXX_3.4.20)(64bit)libstdc++.so.6(GLIBCXX_3.4.21)(64bit)libstdc++.so.6(GLIBCXX_3.4.9)(64bit)pdnsrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)4.1.83.0.4-14.6.0-14.0-15.2-14.14.1_k8^%@^`]A\@\@\@\[[[@ZZZЛZZZ@Z@YeYY5Y}@YMYMXDX@X~@Xx@Xx@XN@WW@WJVV8UUv@U>$U8TPTи@Tи@Tи@Tto@Ta@T_W@TR(@TO@TO@TO@Adam Majer Adam Majer Vítězslav Čížek Adam Majer Michael Ströder Michael Ströder Michael Ströder Dirk Mueller Michael Ströder amajer@suse.commichael@stroeder.comkbabioch@suse.commrueckert@suse.deadam.majer@suse.demichael@stroeder.comadam.majer@suse.demrueckert@suse.deadam.majer@suse.dejengelh@inai.deadam.majer@suse.devcizek@suse.comwr@rosenauer.orgmichael@stroeder.commichael@stroeder.commrueckert@suse.deadam.majer@suse.demichael@stroeder.comadam.majer@suse.deadam.majer@suse.dedimstar@opensuse.orgmichael@stroeder.commrueckert@suse.demichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commichael@stroeder.commrueckert@suse.demichael@stroeder.commrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demichael@stroeder.comLed michael@stroeder.commrueckert@suse.demrueckert@suse.demrueckert@suse.de- CVE-2020-17482.patch: fixed an error that can result in leaking of uninitialised memory through crafted zone records (CVE-2020-17482, bsc#1176535)- pdns_maxmind.patch: backport support for MaxMindDB- Build with libmaxminddb instead of the obsolete GeoIP (bsc#1156196)- CVE-2019-10162.patch: fixes a denial of service but when authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. (bsc#1138582, CVE-2019-10162) - CVE-2019-10163.patch: fixes a denial of service of slave server when an authorized master server sends large number of NOTIFY messages (bsc#1138582, CVE-2019-10163) - CVE-2019-10203.patch: update postgresql schema to address a possible denial of service by an authorized user by inserting a crafted record in a MASTER type zone under their control. (bsc#1142810, CVE-2019-10203) To fix the issue, run the following command against your PostgreSQL pdns database: ALTER TABLE domains ALTER notified_serial TYPE bigint USING CASE WHEN notified_serial >= 0 THEN notified_serial::bigint END;- Update to 4.1.8 * #7604: Correctly interpret an empty AXFR response to an IXFR query, * #7610: Fix replying from ANY address for non-standard port, * #7609: Fix rectify for ENT records in narrow zones, * #7607: Do not compress the root, * #7608: Fix dot stripping in `setcontent()`, * #7605: Fix invalid SOA record in MySQL which prevented the authoritative server from starting, * #7603: Prevent leak of file descriptor if running out of ports for incoming AXFR, * #7602: Fix API search failed with “Commands out of sync; you can’t run this command now”, * #7509: Plug `mysql_thread_init` memory leak, * #7567: EL6: fix `CXXFLAGS` to build with compiler optimizations.- Update to 4.1.7 with a security fix: * Insufficient validation in the HTTP remote backend (bsc#1129734, CVE-2019-3871)- Update to 4.1.6 * Prevent more than one CNAME/SOA record in the same RRset- adjust buildrequires for mariadb 10.2.x on SLES- Update to 4.1.5 * Improvements - Apply alias scopemask after chasing - Release memory in case of error in the openssl ecdsa constructor - Switch to devtoolset 7 for el6 * Bug Fixes - Crafted zone record can cause a denial of service (bsc#1114157, CVE-2018-10851) - Packet cache pollution via crafted query (bsc#1114169, CVE-2018-14626) - Fix compilation with libressl 2.7.0+ - Actually truncate truncated responses- Update to 4.1.4 - Improvements * #6590: Fix warnings reported by gcc 8.1.0. * #6632, #6844, #6842, #6848: Make the gmysql backend future-proof * #6685, #6686: Initialize some missed qtypes. - Bug Fixes * #6780: Avoid concurrent records/comments iteration from running out of sync. * #6816: Fix a crash in the API when adding records. * #4457, #6691: pdns_control notify: handle slave without renotify properly. * #6736, #6738: Reset the TSIG state between queries. * #6857: Remove SOA-check backoff on incoming notify and fix lock handling. * #6858: Fix an issue where updating a record via DNS-UPDATE in a child zone that also exists in the parent zone, we would incorrectly apply the update to the parent zone. * #6676, #6677: Geoipbackend: check geoip_id_by_addr_gl and geoip_id_by_addr_v6_gl return value. (Aki Tuomi)- Use HTTPS links in .spec file like mentioned in PowerDNS announcements - removed obsolete 6370.patch - Update to 4.1.3 - Improvements * #6239, #6559: pdnsutil: use new domain in b2bmigrate (Aki Tuomi) * #6130: Update copyright years to 2018 (Matt Nordhoff) * #6312, #6545: Lower ‘packet too short’ loglevel - Bug Fixes * #6441, #6614: Restrict creation of OPT and TSIG RRsets * #6228, #6370: Fix handling of user-defined axfr filters return values * #6584, #6585, #6608: Prevent the GeoIP backend from copying NetMaskTrees around, fixes slow-downs in certain configurations (Aki Tuomi) * #6654, #6659: Ensure alias answers over TCP have correct name- Update to 4.1.2 - Improvements * API: increase serial after dnssec related updates * Auth: lower ‘packet too short’ loglevel * Make check-zone error on rows that have content but shouldn’t * Auth: avoid an isane amount of new backend connections during an axfr * Report unparseable data in stoul invalid_argument exception * Backport: recheck serial when axfr is done * Backport: add tcp support for alias - Bug Fixes * Auth: allocate new statements after reconnecting to postgresql * Auth-bindbackend: only compare ips in ismaster() (Kees Monshouwer) * Rather than crash, sheepishly report no file/linenum * Document undocumented config vars * Backport #6276 (auth 4.1.x): prevent cname + other data with dnsupdate - misc * Move includes around to avoid boost L conflict * Backport: update edns option code list * Auth: link dnspcap2protobuf against librt when needed * Fix a warning on botan >= 2.5.0 * Auth 4.1.x: unbreak build * Dnsreplay: bail out on a too small outgoing buffer (CVE-2018-1046 bsc#1092540)- add patch for upstream issue #6228 https://patch-diff.githubusercontent.com/raw/PowerDNS/pdns/pull/6370.patch- geoip not available on SLE15 but protobuf support is available.- Update to version 4.1.1: bug-fix only release, with fixes to the LDAP and MySQL backends, the pdnsutil tool, and PDNS internals- Update to version 4.1.0: + Recursor passthrough removal. Migration plans for users of recursor passthrough are in documentation and available at, https://doc.powerdns.com/authoritative/guides/recursion.html + Improved performance: 4x speedup in some scenarios + Crypto API: DNSSEC fully configurable via RESTful API + Database: enhanced reconnection logic solving problems associated with idle disonnection from database servers. + Documentation improvements + Support for TCP Fast Open + Removed deprecated SOA-EDIT values: INCEPTION and INCEPTION-WEEK - pkgconfig(krb5) is now always required for building LDAP backend - pdns-4.0.4_mysql-schema-mariadb.patch: removed, upstreamed- package schema files in ldap subpackage- Update to version 4.0.5: + fixes CVE-2017-15091: Missing check on API operations + Bindbackend: do not corrupt data supplied by other backends in getAllDomains + For create-slave-zone, actually add all slaves, and not only first n times + Check return value for all getTSIGKey calls. + Publish inactive KSK/CSK as CDNSKEY/CDS + Treat requestor’s payload size lower than 512 as equal to 512 + Correctly purge entries from the caches after a transfer + LuaWrapper: Allow embedded NULs in strings received from Lua + Stubresolver: Use only recursor setting if given + mydnsbackend: Add getAllDomains + LuaJIT 2.1: Lua fallback functionality no longer uses Lua namespace + gpgsql: make statement names actually unique + API: prevent sending nameservers list and zone-level NS in rrsets- Ensure descriptions are neutral. Remove ineffective --with-pic. - Do not ignore errors from useradd. - Trim idempotent %if..%endif around %package.- Added pdns.keyring linked from https://dnsdist.org/install.html- Don't BuildRequire Botan 1.x which will be dropped (bsc#1055322) * upstream support for Botan was dropped in favor of OpenSSL, see https://blog.powerdns.com/2016/07/11/powerdns-authoritative-server-4-0-0-released- This makes the schema fit storage requirements of various mysql/mariadb versions. pdns-4.0.4_mysql-schema-mariadb.patch - preset uid and gid in configuration- fixed use of pdns_protobuf- update to 4.0.4 - fixes ed25519 signer. This signer hashed the message before signing, resulting in unverifiable signatures. - send a notification to all slave servers after every dnsupdate for complete list of changes, see https://blog.powerdns.com/2017/06/23/powerdns-authoritative-server-4-0-4-released/- added pdns-4.0.3_allow_dacoverride_in_capset.patch: Adding CAP_DAC_OVERRIDE to fix startup problems with sqlite3 backend- use individual libboost-*-devel packages instead of boost-devel- update to 4.0.3 which obsoletes b854d9f.diff- b854d9f.diff: revert upstream change that caused a regression with multiple-backends- update to 4.0.2: The following security issues were fixed: - 2016-02: Crafted queries can cause abnormal CPU usage (CVE-2016-7068, boo#1018326) - 2016-03: Denial of service via the web server (CVE-2016-7072, boo#1018327) - 2016-04: Insufficient validation of TSIG signatures (CVE-2016-7073, CVE-2016-7074, boo#1018328) - 2016-05: Crafted zone record can cause a denial of service (CVE-2016-2120, boo#1018329) For complete changelog, see https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-402- BuildRequire pkgconfig(libsystemd) instead of pkgconfig(libsystemd-daemon): these libs were merged in systemd 209 times. The build system is capable of finding either one.- update to 4.0.1 Bug fixes - #4126 Wait for the connection to the carbon server to be established - #4206 Don't try to deallocate empty PG statements - #4245 Send the correct response when queried for an NSEC directly (Kees Monshouwer) - #4252 Don't include bind files if length <= 2 or > sizeof(filename) - #4255 Catch runtime_error when parsing a broken MNAME Improvements - #4044 Make DNSPacket return a ComboAddress for local and remote (Aki Tuomi) - #4056 OpenSSL 1.1.0 support (Christian Hofstaedtler) - #4169 Fix typos in a logmessage and exception (Christian Hofsteadtler) - #4183 pdnsutil: Remove checking of ctime and always diff the changes (Hannu Ylitalo) - #4192 dnsreplay: Only add Client Subnet stamp when asked - #4250 Use toLogString() for ringAccount (Kees Monshouwer) Additions - #4133 Add limits to the size of received {A,I}XFR (CVE-2016-6172) - #4142 Add used filedescriptor statistic (Kees Monshouwer)- update to 4.0.0 https://blog.powerdns.com/2016/07/11/powerdns-authoritative-server-4-0-0-released/ https://blog.powerdns.com/2016/07/11/welcome-to-powerdns-4-0-0/ - packaging changes: - remotebackend split out now - enabled experimental_gss_tsig support - enabled protobuf based stats support - no more xdb and lmdb backend - added odbc backend where supported - drop pdns-3.4.0-no_date_time.patch: replaced with - -enable-reproducible- update to 3.4.9 * use OpenSSL for ECDSA signing where available * allow common signing key * Add a disable-syslog setting * fix SOA caching with multiple backends * whitespace-related zone parsing fixes [ticket #3568] * bindbackend: fix, set domain in list()- update to 3.4.8 * Use AC_SEARCH_LIBS (Ruben Kerkhof) * Check for inet_aton in libresolv (Ruben Kerkhof) * Remove hardcoded -lresolv, -lnsl and -lsocket (Ruben Kerkhof) * pdnssec: don't check disabled records (Pieter Lexis) * pdnssec: check all records (including disabled ones) only in verbose mode (Kees Monshouwer) * traling dot in DNAME content (Kees Monshouwer) * Fix luabackend compilation on FreeBSD i386 (RvdE) * silence g++ 6.0 warnings and error (Kees Monshouwer) * add gcc 5.3 and 6.0 support to boost.m4 (Kees Monshouwer)- update to 3.4.7 Bug fixes: * Ignore invalid/empty TKEY and TSIG records (Christian Hofstaedtler) * Don't reply to truncated queries (Christian Hofstaedtler) * don't log out-of-zone ents during AXFR in (Kees Monshouwer) * Prevent XSS by escaping user input. Thanks to Pierre Jaury and Damien Cauquil at Sysdream for pointing this out. * Handle NULL and boolean properly in gPGSql (Aki Tuomi) * Improve negative caching (Kees Monshouwer) * Do not divide timeout twice (Aki Tuomi) * Correctly sort records with a priority. Improvements: * Direct query answers and correct zone-rectification in the GeoIP backend (Aki Tuomi) * Use token names to identify PKCS#11 keys (Aki Tuomi) * Fix typo in an error message (Arjen Zonneveld) * limit NSEC3 iterations in bindbackend (Kees Monshouwer) * Initialize minbody (Aki Tuomi) New features: * OPENPGPKEY record-type (James Cloos and Kees Monshouwer) * add global soa-edit settings (Kees Monshouwer)- update to 3.4.6 [boo#943078] CVE-2015-5230 Bug fixes: * Avoid superfluous backend recycling * Removal of dnsdist from the authoritative server distribution * Add EDNS unknown version handling and tests EDNS unknown version handling Improvements: * Update YaHTTP to v0.1.7 * Make trailing/leading spaces stand out in pdnssec check_zone * GCC 5.2 support and sync boost.m4 macro with upstream * Log answer packets only if log-dns-details is enabled- update to 3.4.5 Bug fixes: * be careful reading empty lines in our config parser and prevent integer overflow. * prevent crash after --list-modules (Ruben Kerkhof) * Limit the maximum length of a qname Improvements: * Support /etc/default for our debian/ubuntu packages (Aki Tuomi) * Our Boost check doesn't recognize gcc 5.1 yet (Ruben Kerkhof) * Various PKCS#11 fixes and improvements (Aki Tuomi) * Several fixes for building on OpenBSD (Florian Obser) * Fix several issues found by Coverity (Aki Tuomi) * Look for mbedtls before polarssl (Ruben Kerkhof) * Detect Lua on OpenBSD (Ruben Kerkhof) * Let pkg-config determine botan dependency libs (Ruben Kerkhof) * kill some further mallocs and add note to remind us not to add them back * Move remotebackend-unix test socket to testsdir (Aki Tuomi) * Defer launch of coprocess until first question (Aki Tuomi) * pdnssec: check for glue and delegations in parent zones (Kees Monshouwer)- no longer ship dnsdist here, we will ship a new package based on the snapshots from http://dnsdist.org/- update to 3.4.4 with a fix for CVE-2015-1868 (boo# 927569) Bug fixes: - commit ac3ae09: fix rectify-(all)-zones for mixed case domain names - commit 2dea55e, commit 032d565, commit 55f2dbf: fix CVE-2015-1868 - commit 21cdbe5: Blocking IO in busy-wait for remote backend (Wieger Opmeer) - commit cc7b2ac: fix double dot for root MX/SRV in bind slave zone files (Kees Monshouwer) - commit c40307b: Properly lock lmdb database, fixes ticket #1954 (Aki Tuomi) - commit 662e76d: Fix segfault in zone2lmdb (Ruben Kerkhof) New Features: - commit 5ae212e: pdnssec: warn for insecure wildcards in opt-out zones - commits cd3f21c, 8b582f6, 0b7e766, f743af9, dcde3c8 and f12fcf7: TKEY record type (Aki Tuomi) - commits 0fda1d9, 3dd139d, ba146ce, 25109e2, c011a01, 0600350, fc96b5e, 4414468, c163d41, f52c7f6, 8d56a31, 7821417, ea62bd9, c5ababd, 91c8351 and 073ac49: Many PKCS#11 improvements (Aki Tuomi) - commits 6f0d4f1 and 5eb33cb: Introduce xfrBlobNoSpaces and use them for TSIG (Aki Tuomi) Improvements: - commit e4f48ab: allow "pdnssec set-nsec3 ZONE" for insecure zones; this saves on one rectify when securing a NSEC3 zone - commits cce95b9, e2e9243 and e82da97: Improvements to the config-file parsing (Aki Tuomi) - commit 2180e21: postgresql check should not touch LDFLAGS (Ruben Kerkhof) - commit 0481021: Log error when remote cannot do AXFR (Aki Tuomi) - commit 1ecc3a5: Speed improvements when AXFR is disabled (Christian Hofstaedtler) - commits 1f7334e and b17799a: NSEC3 and related RRSIGS are not part of the dnstree (Kees Monshouwer) - commits dd943dd and 58c4834: Change ifdef to check for __GLIBC__ instead of __linux__ to prevent errors with other libc's (James Taylor) - commit c929d50: Try to raise open files before dropping privileges (Aki Tuomi) - commit 69fd3dc: Add newline to carbon error message on auth (Aki Tuomi) - commit 3064f80: Make sure we send servfail on error (Aki Tuomi) - commit b004529: Ship lmdb-example.pl in tarball (Ruben Kerkhof) - commit 9e6b24f: Allocate TCP buffer dynamically, decreasing stack usage - commit 267fdde: throw if getSOA gets non-SOA record- update to 3.4.3 Bug fixes: - [commit ceb49ce] pdns_control: exit 1 on unknown command (Ruben Kerkhof) - [commit 1406891]: evaluate KSK ZSK pairs per algorithm (Kees Monshouwer) - [commit 3ca050f]: always set di.notified_serial in getAllDomains (Kees Monshouwer) - [commit d9d09e1]: pdns_control: don't open socket in /tmp (Ruben Kerkhof) New features: - [commit 2f67952]: Limit who can send us AXFR notify queries (Ruben Kerkhof) Improvements: - [commit d7bec64]: respond REFUSED instead of NOERROR for "unknown zone" situations - [commit ebeb9d7]: Check for Lua 5.3 (Ruben Kerkhof) - [commit d09931d]: Check compiler for relro support instead of linker (Ruben Kerkhof) - [commit c4b0d0c]: Replace PacketHandler with UeberBackend where possible (Christian Hofstaedtler) - [commit 5a85152]: PacketHandler: Share UeberBackend with DNSSECKeeper (Christian Hofstaedtler) - [commit 97bd444]: fix building with GCC 5 Experimental API changes (Christian Hofstaedtler): - [commit ca44706]: API: move shared DomainInfo reader into it's own function - [commit 102602f]: API: allow writing to domains.account field - [commit d82f632]: API: read and expose domain account field - [commit 2b06977]: API: be more strict when parsing record contents - [commit 2f72b7c]: API: Reject unknown types (TYPE0) - [commit d82f632]: API: read and expose domain account field- set $LD for now. this fixes the configure check for relro,now.- remove custom PIE handling. upstream does it for us now.- update to 3.4.2 This is a performance and bugfix update to 3.4.1 and any earlier version. For high traffic setups, including those using DNSSEC, upgrading to 3.4.2 may show tremendous performance increases. A list of changes since 3.4.1 follows. Please see the full clickable changelog at https://doc.powerdns.com/md/changelog/#powerdns-authoritative-server-342 - move man pages to section 1 to follow upstream change- disable botan and geoip on SLE_12 because of missing dependencies.- Fixed broken _localstatedir- fix bashisms in pre script- update to version 3.4.1 Changes since 3.4.0: * commit dcd6524, commit a8750a5, commit 7dc86bf, commit 2fda71f: PowerDNS now polls the security status of a release at startup and periodically. More detail on this feature, and how to turn it off, can be found in Section 2, “Security polling”. * commit 5fe6dc0: API: Replace HTTP Basic auth with static key in custom header (X-API-Key) * commit 4a95ab4: Use transaction for pdnssec increase-serial * commit 6e82a23: Don't empty ordername during pdnssec increase-serial * commit 535f4e3: honor SOA-EDIT while considering "empty IXFR" fallback, fixes ticket 1835. This fixes slaving of signed zones to IXFR-aware slaves like NSD or BIND.- only enable geoip backend on distros newer than 12.3 before the package lacks the pkg-config file and there is no fallback to finding geoip without it.- fix permissions of the home directory- enable some backends that we had forgotten: - pipe (main package) - random (main package) - geoip (new subpackage) - new BR: yaml-cpp-devel and GeoIP-devellamb58 16008687244.1.8-lp151.2.9.14.1.8-lp151.2.9.1libmydnsbackend.so/usr/lib64/pdns/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:13121/openSUSE_Leap_15.1_Update/09357eebd4b440097887cd3db35b8206-pdns.openSUSE_Leap_15.1_Updatecpioxz5x86_64-suse-linuxELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=143eb4e978ecbc315f8068d3ec0a36e630cfe510, strippedPRRR RRRR RR RRR RRRR RRRMBEJQdt0utf-8c980afc7d1dd0265f065ae364adc983c6688dcf2dae4ac8d517ed11d7adbc71a? 7zXZ !t/ṧ] crv9u+ԄB^aAT:/jN},m08VJN*l*7܋D0~:uѮīy4) v ֥"6۾Ak{%Sq}HP~WL]<@сɦ|vMZIAߣW3;y,Rx-TEmF@rrtƐjj|Fu`w "n!>"E/>hC $^ /(M%[]J߈ԗ}zYwm'qj@DUxYm6+æΦ8MٗH*Y =D`jRt@n ? Gտ8}\INu`fJay dOo2\='KYV"ll nr#^MwװA 60.5ڒ^ALl/P*J{M%l}.M}laIU,Gn<ܙ# iR5;u=c`}HB/dXѩTZ8hAC'xxxf4h>y|).CCt*H8DDr!-}%?32nZ(Iz4-i{Pje*vz:儈K%مE7A[P yU!YJeoݟLߝG0 OtyL6kh|v ;,=Ѿ);\D00ޓ-vx4YR`,h4 3l5NԦ/n S9A!rUdKe>(qnh $Xn6#{LqOwzk"#Qa z8L≣ҕqr]ҳc cgd86L=/^%}-3Wa6su/{?dՆMD/pnrUVCy4,&gB*<)NQ=ӉiĆlv M"q?<v[!8 e L/QF0"'M-.oNvR8AlЈm/FBkPԼ< /UNSvڢij/ǻqijH4FEy9qyA8%!*v H-@/&?-<.x tY⨲IusqY쮰>L8bҌ*p?! SjLj~`(yƁ]O EKwRBkvKcFdÀxSJ^j ;^ǖ7f2]8 b/ +0ס$T 2S^)}߆}Tƪ2o f4L*W2z |'HS`39ԭW!s\֔zVCc%=f DgP9io \s/`X4%8h {#3a)}VzEBɿ̒|׈}]NI,|k$u/IH=/=\PPq$;1뎦L6QV_Tg,̊=}Պ%[ڿFڰdYG6-Lk)=BX28D,7\qM60{q *84m]r|2nla('3[s5_eFvP"J}ԗ*ƭƆ%0vaդw ɶٗw?M^IFV-gdT:V  Dx~/oaM Bu:$ByF?<n0u~>oٽ;&OQY}r 3DCdCйXx$765wm5L{*ߍׄBjh8O4DP+|Q  wDsspU\qTV~9{:"#_,`V7@q#xp HBM T=&;&KL\Y{֩sQ x JO(g?WV0B||X qLF:#.mXzѯrD_VS<tBt4R:3[N㋽+ʂϡ$@x^wqۙ=]3O*m/0FbA 1Z۠X.82v)Tb- (bPBOE[4A3@ V+'ddCWYti1UNm8B-S'q|Sb jeu7$ =LueM.F|&U="@b[cOP>ʨ+O.P1Bφ&"lӇ#%bp)`Q#+FiP% sߢK[wr-\}4MLFUn4G{iblu(9` &#^O`7Uzr7DCqKG\=aC(ٜG샀F6-ugQw?& m ?C1;VOJa{.n/Je:3/!DS7 $NBX|4d2&b%Mm1W5ESPqyEj؄J 8a_:+br`FnbqqM]w}Mf~:if9͎T;ȋ6ebm=Ƈ_Ħ nWj>ѡ~n43vvt_y+/T0uwN(6c$ƪt95~n3-fN6FǜԉhYDóOK,ɥ߱k:\n/8nвà:։FIx@~OlyxIQ L _c}z*@4,`Ѳq٢-Z/mCƸ=R\ M!Y{Vmh^L:4-m%FUs’h 6PsfhY?8~XҹbRZ+ewBU1~>&YeOXBrBz\p[H3u<748D\_1' Sj[>f93Z2"2KJ]Lۮ̽ˑ"}7Q B.?9,tj0* mOsKO _Dc-zke둓wڶ+܄`R[S?H?8rj^.?0fX CrL)"Vw0vk}=J/YNhQbg.Dabܱ2erq-X.|Q?tra-#׳? d01A;c6zUX.m~ ^_.EYgjC`8TDfo,{cLt0H>K "ԉJO#hX1YHmeW}gAR5ߤ 8Xލ_Y Th[K?$$Bcf+p@qd@\MR@~]j}6p"3Uؕ6 y]%oݴt0[Opf?|-PT/]Dѧ j}\&9@ z(dy xihxda z5EM^aS]FVҰ& 3 '-yO"[x+by BOsdSmJ.ivMGEsћa+TragUՙu$f@|J.n3֥SS?ԥ9\UR h WM+Hk4=bVêмO H4:.KBNNo?*?V>MgHk@'5_̎ i_#G~8 '4y!] ݃R2qqgK6O,=8]@@7[bqQXĔ!4dI +;uЁY!ڇpۜ WHCɁrt<L*}C|,fD< $x22>B];0C?J1? "{6 4>d eu~Oa&>,l͊/ Hzŗ9ĪhgQ2EؖhΦ3"foL%m![cti^N@zbk-QeK|>92cqVwcc -)dΫLu#QXip|Q}|J@'4Vۊ>p~aVxpVHU_(RPEӢ#u[g2*"Ho^uCO2'rMӗ N~`ƗY.uG<mUل,{Ԩ-)㕮$F 24lІrIwg} ^ EwT61L 48j6 {*ЛzPDkX}<7 B Mk4w|C&xDAPcz 0ygLgbn\LgͪJioŀ{k¡~5U:0@z(%ZԮXTڀȚl9E hFʹ>brj ">MsT'4±qZ.Q\p54i\e)+z5).A܍i;,ЭJM3'1hr+Z0]\xi~ QaК^R1?@lVVzA[5O+s]0R0[+4rs0ّ6.&*Һ~8P:ӭ䒦 ;2ZXSd4 |:wwE"]T6tvR%L'tS4OЅak7{,虈Fj u}gسfEzf˵N xucg%<%u~ (3Ó_kۓYÇd0 U`6"^,1Wԡ0 `w_>Ͱ7 +!IeBɞ9ն+UUᙽԪT)} tJGhχlv<"ͪKa mK>La1h9f6x.ij\YMʣv. >FSOQ梴(^DM#LJ`C)hb|;JGuOy&ps*v2B[~ 6, /?WDk*t)ut2Aܐ7 ҿ3VM@$Ŕ$Mɡ"TpQ>WJyc]z˫Rg[wd15=}K¶btI BPh|'*APc񕕤a㽺vRwi Ҳ`"V[FK3¾{wv \:-l.|72/ym:FsD~.2fv2Gbޒ<1Qs'9/O$Wy?bu|Xuj;[-AXZ}ʍ㘑!BY, R;hF$E*M|][2'v 甥әY0&/!`b- p3ZU[`?`GU%Ky`$3Kj54Sh{ #y wew5w;nϯ[U B.r @B<ʟ,jNx"ܬt_4DK9:SwOX(/+y}f28<:d>_pN`:k F 5P0᩷qjf aeGc@^a 9ZVe5E~Z jX i|~"7v _ ꤍrPGNYA"ӴWa<ɔ*O>0z5ؑ8%h ^>4/i+P.cہ*-smbN~gY `lr-cMfsH`5Xs ArP6I` Wĭs`_ZBmC _-R;O"w8+1J^5r\OdZc ~u@x6w$a2T޲ݽ>!ߠwVG= 7N*j"_+bvOȋ % 0ߴK${9%od/G|=[PL:p0cj;s7d)xyݾ&Hފ,fPTXȠ @ NuR[iFQ a ^g(!k4d^xٞ5lқElE‚eP>fxuӣlmz%tvCéphXu\g;pJ^Iaș7"aWtD:Jqy(1z>*[Զj V1+ {M"^<|y_G]} Qb}љ@rVf4Q{q]piG,6i0b^Cd} ,"wpPco =Gƞ$R!BiR,@H:$?ȇsKQ͗BI%|F(d<; :]O)D{Z8`6BCk&-r*@R*%M__SZK[)~r+28x= Esh+ fa\pbWӝ8]4{^X"m8T̺80>QҠl@]Bt'-ےfSqk?"F`Ѹ^wAcEhB*Io: Wx0R) CfXi5@$vt HR}8XK}?7JTF{cHLK3G{&> ; 3N$^# T% D oH#ld %fͿܣ3"iOX:V2s'M.*~"#?csY o>,6{[ zxm,NՇlH\3zh}{NpSG;E .5 3܂9MjFl܉)teh̀r&oV-]kU~0Z \'O`%"It!H;y,g,VKQQ~EvlafS(Z?-X\+ >5ks%|(ƛa#oxZShRſ(w.igO?moOPaaItD #]#c,-"#ZN`׹$LV+vɗ۳*1 +m..ݘХ |rۨP@ؽAXı@hv׳U;1TO Ƿ'RnG/ruD=<\_['SvI'뗪.)n_a:4' ݳ]=-ЧGZYTGovO24Fp? uS76l{fN!`-v%W ^.J8z ~wWIQmmNC@hz鞣o"jO9;]rZc&¥c%zU'E`;n:CN*2rC,6H%0<˄WE T[LG:y[Nvv5A\Y?Is*S߭8w /uL^p7X;;/p,䩲[I)7=[Cԓ2& g~ Xiേٝ+iceȺ)cziP=q20c:Ž}[1h;?hPzف\$  bLQgw~j*<(LX?ade-.{>[vS߼|^ ڇ,&i*F&™11"+hhxFNćGQV#x, &V_1Ʌ]-C(jJ*36qKǠ'Yb&#TJ0re$Oe3vB?vCvy f#}ev\؟YnG dvԐmTi=4*wp20oK %SCwAٶЖn/ZQ|KyVaZ8H*0S(p|H::~u#3 MK`PLU뻅f  75mz,H܅h  vmdXȻ-M5}$^ q ͡Ce8&&s~,rOq!\Ls#XWDPjYM,ݏ`3(ITv57_ _gd{Hʤ́#=nBgѡ'y+EFDNT1#3OxzSe2s@rtjCi>N!Uwaы>Y4? @fCY(+|5-t䂶Iu-:ڌ6<50-]nVug^}U3$p= e=!m@WevP:2ËZJ^Rȩ+x} p1B&PYAs ֊+膽rTߎڽ$!Ъ9eW8Mqg8TWZjaIO+=i,#!{-6Ӎ4l-c"EW,K\wNon~dƤjh)X!3ӷ:,ׂ[N!xY4{g*tBx<^^LA5u}i[wPy,y2ږuš?,&VAd(Q3HyE;b]9U!ĺQNI{!11dwE`GtٙhԻ.r'v@YITʲtRY plKଈpt Qޝ8'Xsu}VU\?XW&VQ 8ܯS~o D5=OF-ū@td6ȡciF_`GQ[,M:D -]A:"!a4 @ >)$Mgo7 67Wg3$ʄ|qS rUAQ@ x[ܦ`orF5SJ *S"$^.HzGѓfB|IeʣACzD?qqnDu4r cTMDCŭө#3a\]$bƵI #Kn= :%ּ*y>nN!eeHH [`nR TaA5y @ bsshGD,^{( JQHg1EcvDL-\|xZƍ1{*dpџ#~84vO Ƨ- AmQ8}G?G&:)0$ѳm QcĹ LL?¸JĈ1oXa<ۡ ծ|[4h>G1sU3g<]i{ivJ"QhJJ[XCLOdDMDqogrr/gC叩e3 Y'Waf_JehM<4uC/YIckq=~°yicbaޥ½6.RJ?t GyoF hOcj K6OP: 3 ,@;5!G@Lʃ!& *?9|PRnSVq(Q".AQ^=箫 64$R&@vyhA`ZMmO +nIl`Ktvf6#F^w/fzvRI;/vB~1è]&:zܪ$+iq_Q&lv ]-o0y/Q ׈T[X(S|/}rOtwr;*cqyܨGL k1ljG { `r}D,,e >oEvݩ.].v{0O`hMrY/wf U=Ӣ卫aT/TTϹr<8NBC\zLAV^r 7qCDŽ80e=*\ rHb]"{Q%N+~RJ1p6rD|\^PZTґB KSk:N)Q ]M-,_7+Vl>Xy/|v{O0gc2\LQؠeO?$a61D;`+Pk0 N]pg<,#\^~`H=h8 Ҁ=.6սæ@!á*Jo11逸ӡ8fo W'OC((\5+i1AbE2ehq|X#D:RHu)t4r,B!gԊ{:rJ+|m Ž{aJ HmfI@|j¸Nmח?JlF8ٽ4gU5.5k=cftʦլ~ a^C)> cEIȀx;1^ldRf{ yl#܎͵.~vDFmuVǒ]7^о`&]ϴ$l3~$^ *1&9 |Wݢߴ7rg!-N gC81G @oZh_GE"1(S '79L[` 20#_R22bmͱg$Vw*k4~9JxpU5gTβ~)-sd>n&k #@ep#e~R,Uzxnr%XiJBEl7JM ` Up#;e=t?o4\4L+TIwD州|Cھ7g )GMڎ*, kV253'Q#)2,Tj $R FUa{5zQZZ*Mn:G8&۶݀Poxer$zB7Ie:5Wyé7a򄙥JmD1 h%UkOb1%DكaqAɠ:"3S_( e_`aqdA5WRhmCP،ݗ3#Ln')KHusĮ%5-Yn:3vxa2=h#DG^j7k=r{ ^Κ_MmMq>|~Ea!•}BOqb⎐4|G&8S4("T˘tːI mmC\T1>D2+/Jt_< w"F~؝`mX޲$&݌Y_Dž $C p-i&<+*[3ϩ]qFn ?+FM}\y^< M^=t ʮ7\M(:5YSHH;qБxg=#-LwĎ2|sI {%U8[{5X,o[݁?+>V{)*&dNi,k8H>T,͹LAZ0o4#[ZodL %_~ b-1OSӲG* By+4_S"\MKӤ".A~$K3Mޝ|x5,@BQG) 4FoHͳ-Z26b vlIQP 0 |aޮ\.ݤU;9i!36Yk *I qżKùti~1,z{etjqءVy2QrЀQ-hPa,9f؈ʁ% 3rB}p3YW|E8_NM/-D8pf7c%$@<9`+B11@;QKФThIf۝SRF`MY2 .1=/i´cPsx1 ؊>sBed(60)7|2(L"GS;r$1`,"zvd;2vu5GͬW Cnf| sOW)$ղ-59?N}>tUMJ;e6BK(E TBy;ȸ`J0+/6v?pÐGnX|0H$֩< #g-/`^}6A7H&JlQ Hgbs&Y<@,}m9ɤG4o*t^;zQ|8vz"y-*!8>@!X扼.ij.JL ҩ;xD;a|ҭK:fJ_@n 8ՀLxнDTef~3mbfq:>Nxa h_G(BfƔk!gxPbC*e sg+]ؔ5hŻW4l%<i{Em|&̮xʷԿt,O*k魥W/\O03ȌJ i yeXۛ"F9(_.uӀdwGncg*'['nѧ·&Yz,!9[>:2b ()r#GoW%?Ȼgb$?:jUy~ʞGiq!u,u'ןi0YY\M#BN8 =|ѱm s뮛_lA2[ƀ^"cǿ(1,uxZa2H:tZBy*mԩ[hRetd݉ (yY_]ūLR .œ_8% ȓ7[$ #OXq 9jk(LG PR$N T8Qw"ܠ9.eRMC2>̒BB"l(s'wY HEsY8p=3][0n dғA(6D|6+`Zr\258I-;w 3L@4ݼk S? eWINdnrK0xMc,aU,1h4]r?3JZ qnCl .עan[87 ƢW@tәk@FmB8+F֝D1-⎴_1V&uA91z57q @JV6с$~Jq7r 5ҪqSޱRu`G?v~rTpxLLclGR)Ndbۤ+F\X Y.A͑(~赙GAdVYwd@qNWΖ,Jgpǿ asJQ <#w1%?ɂ3==!4R,sz;/חa] l6?տ-˩0 \Fx$(Ea;Y8kCW&G 1|Џ\$>ݵ$./ 1U@Cn5Cc3:]RЂ- 2W@ pNIOx _:22`p#qt}*q5*CYjF zTOwr]jX+3;lD*|L8} 3Bn2vn2F] b%nϽW=tNYzot::Kx 3=0S L^0%O;e>yΰ!wxi!*zl,,hأ,S܉{>uq\A:f!qo4/~!-ɧ]ŞIB`T|\~=~hTQ`Ms\oZolPC m7rŹ tmt])|@9R13G4}M>/M_5[i=anH8vG`MSDX6+ %E? s$FcM 3!/?'9'$5ay:7őWݝDa n6,$8GQÚVz|xR) 2k2uPu}fiCeٗM$Y^JF. Rs3 9HKKY"\j>AT&b.#<CA)ӔhCG: kpk`Άϩ4%mNƨ\ .<4Zⵌ^|$QgFgi<pe@{2T+]5at `IȜ-"so:͹':3ML wՉIsTy>Ec(.ˑSQnM"|{@Dɸ᭸jrGBo1LB'b!Zr{;"fq \=W:mԖy>Qa6 `&r s{2Bn!kގt"z3XWPv)D :} O1lè E$͈c29sZCX@Za9ʣGBm#W@P0Uvo pWդGLZ}Zkt5ۉ׬70/(m^/..-*qd{ן\PS1gaH"it pnno,2?fOJ)F)Cx׌tه_u凋&јѨz^mm_@YstNsPvxJ4U-}BB0L $h`&+{cr)}f0Maox[ 0fHGiGDi6}IHQpdł"DZݯwوڠ\J )m&㿊WWoL:vwYVv ^~r{NSfm3|s6(˓ U #M,ّlL01/V*XۢTC>Śt3?xLWR*P<+ #4 #4{t޻ъ{#lus_hrk>lB& G$&<䔞2d JPoD:*e`96D/|Bz6:S>3#"}aōK"r1zneI;5!M(V*zu۰u!92_}?qH*&$-~SVtSIhNH,O f%4FAv-0G9#ڭ9F"W3!N19~ޭ۸#3 @Zu~IzqrT m5 Ak8n}[*]ŗCu^!g_x/zT/U~wU9iO||swSQtA˵DE=JE!/d_YE&OYFb 0zbfb+xcr%6Hg,\{Xk+<`I.F{@HBoNu՟m5CL՟%L޿UE` W?tʶ&WBn2^UP?Hw(U|1kc^Q&s{g/cҒNLIH&BDBQܾa Zwp8V"OZVCp®yҪ=aQՕ;Hк1 `&fx]P'N%}s';TSH|YĖLBKWfzLZo!|]Hf_ eJ؏ u;?`; qQ }RTu7Kd#{(6\qnj~6Jߑ7\ py^֗~tӧeҦ#K?TK]KnT7jO9f*HEZ0]4nDZIBmiH.M6> 9]3o\=BΊDm:d{\s8iih\7i=Xhq$ [kcR>֥L[*lՆ@[q q tU4m=zP C YnO_=t撉1NC̠2ž@Uo[ >atW6h48o9Hóڷ(30 Mro/#dזSәneGn袉U;*uΚzp E5t$56@{w ̱H˱&*Nˬm6s}:iؓb/Py9>o05#J[gZ,&1Xσeqؤt-yE 0IZ@|͍}{vr{|/JѽOYxu'ŝ毄l)Y˃#k=ԵZ/IG1}{4k9W\3Nzu [gx?ڸ3&*RF?_5 Qr$Yq.>deA 9>)dJn“Qⷦ:RW3y` ?RA3fD8߄|$7WO4(,5&m9@S fpO9AеX%?+zlӰo*g/(KMcRxS3n')+=eOa{CgH!* `S Y'-3٭,:l #XH;@| p| /ᆢbz-p5¢- k jAt|/WQ ,?F/檶ΗۘH5TSeS@N-e ~EUiOJҜ"i>g)w-w<1[,1Hth^v==yeϪH噎J< @($hY$/Qqf:j$-k%aGW5}_i$w]X&P0vyBFzEfeQ_%P8JuXdX6{~䙾~΄"i_vJMM79%jVcC+ !]JCvpRf?ң ƻ 0nHHŪkܩ]XZ70;9:.m܉e*H-u;|㌍꾬3K0R}⋠)Tz}a˽LewIkq[C՚X(Jm9m& nv9aҒWǙ5~;7\h]gr-p%Lre5[ܩqݻ1"\˝=bͥg;6@pkS[j逓ƚ8G|ypϚ$10K,8) z^zczdO_pP(u;= "P?{^APeN9>Rz`kHӠ'2? ty Mv 7?]a+^RkS BzKE{#Dg\kk1n0pg+ L@Mr:|lMJ;F,ᭉjFjZqf~O †57fw4hE6s4/2A.YiL'W8l&`{BE !o-'VB=̂nKs~IRB nGJ*a.#aJ:L$/m+yF}rMˊ_5XUExv)Jװ95 qbz"kÝ 5!Ejċ9@:C,(G--'+99:N#B?#` 7PM\}tyUMe'[Xy'x4x|z|:q/%I_Q3e߇lC`Cnqv #Y% "/!Ҫ-Wl3;dA Y (* HZ$v1+)(R$m4^ZW΢#Px.Kpup|zÆu[T*>Cnkx54{MM\4pk $pyډTSlCߗc4;yءZ~/]fq]4íW0T'^0+OoBjBfpa*C*gh̝̕iTQ-KSƮQ! -[J;a] eu1 [6fƗ$j/us po'NeeTv7hשB:ha).)wvQb KUYd(nƧq<Ӗ6u)K9ػׅ{Gp:kP #N~֦7,iޤ+p_tE0!Voxh΅ 'Wԕ_Ғj JlB4JIcViY=)'e'kj}zv=Jxc~a U]=۱ p]cߦ|xeN.XOdi*y?bf.mRG'μ)-3T*>OOiIZ3Rڣh`q[֦N13 Ǔ_5]H >JC9?362ui n.IF~Poփ^y Ϫ^CP8 /~)q@=lG8"7i@LX'΁J+%?#%Le j^;D[ yRDDBj% T-DaF'g5W\t4n`pGO')+*EIӔ&W.& +I񳚑X-<8WN7j bHS4 ܋!;e*h=?Cp 0Kڰ]=qxğv2eJ W"x1%_?>[lnI$%h&gQMZ}Eǁg½jWoqAMX ?}|K݈7BeG@O'}IrmHaqO"4ccZ`8H@+n56 @+l7OL=t{jn9s!թ*k>yಂmFSF\szoy "@IpnǗC'D6!GN][_@jvX tɁ8)$?mJ+Q')ʮ @iVJp0yi~]έid< @Tp0)B.єμ48:)Ow+>(M86BDro11q(S6ݣˁj[`C]1cn s`W9 {\6f!;DFKD#)3*6fmn=>Pap?,&[_pZ4e)\bD) Z' 绉~_m; j9'РznmwKVw(֪yokfvۍ ݈_t5=@+|Wf!ޠwhOwL2(c 2=ƕ:3y&]#5/9!o0>sF?:D'bڡSKp`ui;ܖVk6Y}h+#,!ɕTyPqD옸C \vsj0@!֬ j:Q(ijĽ՞f IEz9nc=vV) Ya3$ӆ/? nSF7.< "jH{O-ΰ4yYr(RKuf@i%рE3Ƈxۿ;j4ky7~fTj*4lÓ Qn.uB#aOp#E Ǣxe8) ~:Lwٽf$w$J=rhbJ{z¿ҺМvY,yb<Ӹz4~5@,8c۞$w8j j6(cMa^HYITS]N!oIQ$yY"9hv\I-aјU“7lj"z[r!lǡwz|7aXDlb|3qư?^5|t hӀ3'*ƨJ3m9tƀsC+o'8qhaOTU]9C r!ߺ+*7[yP!NÃ: ?yr϶Ts{)m? _ee3N Kh}|WC#Bv;hb\^EJ-e16-X`hl<`/O| ,WJ""A u=@,ǫ s;֎$vS%OqȞ,~}3B%逧qٜˮضR$(2>#l2uCL%c _ [;0,zDۀJq6V |qěe^DT0|IoJ @mz7攮j Ƕ3^GV貫}q q]+:d|Eb5L wJ3ZUH+AueJ;fN_vERHc}!MikplPdfLN֞5}~:ρ/L&g z JX)̘k5L]8; !+p;Wo>ebߕm3 K|$)z(k|^ix@uHYRHD1NoŠOA+FV¢-0cx(6'K;{&8A;Ҽ$G'i2#W]@{C1vjo 15jc~g0XG͞MYu!ƺAnI5MrP@V~凝%)Č3Z.ђVN+44׈H%^q#d]l;S20puͨ[L{% e5ߢuSCNAjtxy}w^+({ww:`seM$B&K^Oݢ-c d]S'/4% @~9GKX{3yvu}Xr86H ٶ%0݊9sO`yQ!$TCikttn)d^?#RO| %w; V?* D:h:fx;m %~ܟ]9P[L,ʺwU;6bUJZfUȡ=f騝TO:;Dw^pQxsT4B?'JrBʧ'dJE4n _:R>Ur> ij2-{n3@zTP]@dsD=Hp$2Bq_ˣ*{T& ߮}EF9ݧ Rȗo(f9KQD.*%Om*H}"' ߸$7ef :eHV=eW[E4a5`@^Lcg+.dt4dF.rZ>l8-?{| <7[4 7g Q?&l俱n.M%S Z&Ж4JIWTWʇbzJ/'X]w:jRP%)e$=jFPf&7{su???^=UDv[!!ݘiFuM$6t2}bqu w]WUb?v.EB3(g[w"zetKh 8H͙N|!fg+J)Խch(E12T?*]RLS׹l.[gZ~/8ͦ!V}d3+&߱ :د,B|_<$C>/H,ELd^r|{ԫD?-u>~-DŽNmI ou.8]y+xuV.o'wQW;'ӆ*K vM?)ހ [MtVj6Sz<8f񔌧l)e䚐{KŌ-(:%c=Wi5P φ ك\zu}qTHN i%Y pM|jFQkH,AÂPɕUW݋)AyS'GOөX;wM̂&'݄oRqBr5;1CU#iU(feZx<=7)1V~X+oj51=7b<ҞlU*#iiTRk8ǥ1y0و1 v~ќ_~wBPKR:E;RNH=qeB1w 6|#M]sdXWyČrˌhwv|vꫤנnʋ1y /'Cf ǝ * <] jhu)[^qԺiu*c@D)܃Z'9[0^ާJUR1p<.@%t#ȟ7E#ő*<$%mgicB/جG=u@c^{.N>=bS;\/FmkUpNI&QY u6DZ|-ZI5V*E,7az@n~?x;o{M47%E$9jw F@1ט3q0pOU*r۠y9KQU䖏;xMlfԾ+LZ*twv*a60+4S\W2Fv'Ў`csPSy3?U<3̢95jZgPx%/w9$.яMW;J=S_2@oK13VW@7 s(lΌi= ӤۈG -oIFj4*r]+ՂM= I^Ws إЭ=_ZCpLLDoǼ級Y6@_sT.Q1fqXv\H܏kHiR4t"Z{sj[ƫPuC!> B\ra.>oq)y-+i~2e6XxqdR־s6 <@H~֞3`fݱe5 #p|d1EX~׬aD@O2wčГ?V`)DfI 48ؿyԠ!ܶc LD FjHlZoиU7-*BzTN?! eɬw٥Ǫ)&_F@OH[r: <+1^Xӿ_fUòmI9"x-fǡ^^N5c@ȂX+Myُ<s>{).&?3=9/Bs{~f1%Cohx ވξyNk!?5\r!?a)˰;C:&.E4Ai  pyu3,Jea#^!;DZϙqf &UfLd #6uG{L@CP+sH6$1 @t@Yl}wC8 ͭ v-TcD9@APϵfJ&T?!>.(r@k)Up}Z:AEBJtd_dZC{s>۔݃ӇfCc$͔A '2C[WMs6$fc /PVP3厈@E'J|G?.%替!溽p 0{iZ@C+t,AƏVbҦ˜-/'/ >'*E[K@͍;ّD“ u"h ÍC]A|}{z>4X ]Z|Nq.$|4^?F? Q3I$Bwq^Ԟ1(>=&*@%-k;CMJW!ZנǶvd`*[ʼ@4Lu1/Sw ;\ m/o.}'vceŐ.咤dL#/lh4$QCPclBO7< > `+z.*5jܹ֘R鿧p?HM7v ⟋e3ʗݒCܻש 0^y!1 _A[}m^'й؊ Ғ{*9̳Z.Ê Rѱ?Ho <4p| I7!ЭfF 4镔ExEzop8Wߜe8؆Ók҅R%B9+URzT?tdpي;͍|tQѭ\8cN!BNHTX{8,j[ _!*!y2DbLӭ]SJU<<5W/Ema@*& 9x눺r^Cٛ4Ѯb )vZ ty:L,9%]}7*NҝIP hRg棊%Up.T:N" 9|Bj05s^-d#Q;dp*h\RQ M6b'nY^I<" ˡDzd`A5 GƮm.cQ9/OޠؤT9>u33lb> W>lkvk^ t,CYoҩH"ܲz19F ͠FI(ض+."aHUM_Ř FOb=rjQOyg[xB Z9Џ6Q}Ydp_( ^ P 4 BY *RsTf&,)6+*> !_Is:eW">6c?F#s | 'Y}cVNj*P_ 2ݵh~pt3=}]=e~!^Ij X2! .KⳄTj 3 .iXvbOz ҟf2>^髳.aKOFRn-wDPhQ5gUǶ SZ:ц=fEW#P/ fJYp%F9L¤ffmU>B&ohiݎH?n#PhL1!Bq$k8V1lw3gTc0; AۧIg;=sE^b`wlЗѾgB RdZ$aW½D]l78:df">'hpY~(ζR );nsekIh#ח8H;KB4s$H&T, kL/@##>|jB=MFI`}U m-١^=#skKhNdu%0 T.q)Ǽ}m49(<:3fqǰ{Um \䟙,+ _y3Tc?8K4,סeYK< MS)WL ";6>2qNUPKP.:1c15#u`[/p"XDҦh}:ɮ#e#@ fr_gtrXЅH@[cҘDP\mb@R9+G?Hd#$4$T~O0v\CL()NALU HX˥rt2C· 6}wx (E)\>WQGG×Xe 4Z>4FUfBMж YZ