libdnssec8-3.1.2-bp153.2.3.2 4>$  ApaVޜ!M@eeex:~ Д#^O)!vdcVO1IP)== 0Z2`Eܲأ!aF.V`}i1fp <nĘ >l ;3,ܺwi:NU>>.JרX^8 /O<} ZXzbɠ#0r>EbQavi+#:jA)&g%Z~0O*(n]e&al8Ij;4bbeaa27fef53d9f9b56f277264b530d43b363aa7acbcf896ccee08ea99edd14e0a65e47073201403155d7f46c11e97d75b997d03aVޜ!M@eee S`/l6F?yր.}]Hc s'DG=yՀX hKt˘gz8ٽJC)ʘ8טfZչ8o؈$38,UARz'ԐH0U/^W:+b{YΚ|&C!jO|1K('1ڢb*?80SQ&x ||UbP6fOvH?]>p@f?fpd   EPT`d}     B X`jt(8696: 6>c@c'Fc6GcLHcTIc\Xc`Ycl\c]c^cbccdpdeeefeleue4ve<wexeye zff f$f*flClibdnssec83.1.2bp153.2.3.2DNSSEC support functions for Knot DNSKnot DNS is a DNS server. It implements only the authoritative domain name service. It uses a multi-threaded and mostly lock-free implementation and can operate non-stop during zone addition or removal. This package contains a library for DNSSEC support functions.aV̽obs-arm-8(SUSE Linux Enterprise 15openSUSEGPL-3.0-or-laterhttp://bugs.opensuse.orgSystem/Librarieshttps://www.knot-dns.cz/linuxaarch64(aV̷aV̷114b04d7b704e166653d27aa69926ca9d667cc9f64d87bff668b37eed042f742libdnssec.so.8.0.0rootrootrootrootknot-3.1.2-bp153.2.3.2.src.rpmlibdnssec.so.8()(64bit)libdnssec8libdnssec8(aarch-64)@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.25)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1aD@a @a @`ݮ@`f@`@`q`_@`\{@`@`_@____^@@^@@^@@^@]\HW@\3?@\*[@[@[ݍ[IZ@Z@ZWQYYYXWDB@W1@VwV@V@V@V@VTQ@VCU6@U6@U@U&iU&iTTq@T@T@Tk4Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Jan Engelhardt Michal Hrusecky Jan Engelhardt Michal Hrusecky Michal Hrusecky pgajdos@suse.comMichal Hrusecky Marcus Rueckert Marcus Rueckert Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky pgajdos@suse.comMarcus Rueckert Marcus Rueckert Petr Gajdos Marcus Rueckert Marcus Rueckert Marcus Rueckert mrueckert@suse.dekbabioch@suse.commrueckert@suse.dei@marguerite.sumrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.detchvatal@suse.comondrej@sury.orgondrej@sury.orgpgajdos@suse.com- migrate to user creation via sysuser-tools - run spec-cleaner on spec file - update to version 3.1.2, see: https://www.knot-dns.cz/2021-09-08-version-312.html- update to version 3.1.1, see: https://www.knot-dns.cz/2021-08-10-version-311.html- update to version 3.1.0, see: https://www.knot-dns.cz/2021-08-02-version-310.html- update to version 3.0.7, see: https://www.knot-dns.cz/2021-06-16-version-307.html- make sure we have getent and groupadd/useradd in pre * added dependency on shadow and glibc * might be related to bnc#1186023- update to version 3.0.6, see: https://www.knot-dns.cz/2021-05-12-version-306.html- Make /etc/knot directory owned by knot - fix reload action- Update descriptions, remove unsubstantiated claims.- update to version 3.0.5, see: https://www.knot-dns.cz/2021-03-25-version-305.html - Update description based on homepage- Trim marketing wording from description. - Drop old rpm constructs.- version update to 3.0.4, see: https://www.knot-dns.cz/2021-01-20-version-304.html- add incompatibility warning about 1.6.X version when updateing - rename back to knot- version update to 3.0.3- version update to 2.9.7, see: https://www.knot-dns.cz/2020-08-31-version-296.html https://www.knot-dns.cz/2020-10-09-version-297.html - obsolete only pre-2.0 version- remove rosedb conditional as lmdb is required in general now- replace conflicts with Provides/Obsoletes- fix dependency: python-Sphinx -> python3-Sphinx- use upstream example config file with correct syntax- version update to 2.9.5 - Bugfixes - Old ZSK can be withdrawn too early during a ZSK rollover if maximum zone TTL is computed automatically - Server responds SERVFAIL to ANY queries on empty non-terminal nodes - Improvements - Also module onlinesign returns minimized responses to ANY queries - Linking against libcap-ng can be disabled via a configure option- version update to 2.9.4 see NEWS- version update to 2.9.2 see NEWS- update to 2.7.6 - Improvements - Zone status also shows when the zone load is scheduled - Server workers status also shows background workers utilization - Default control timeout for knotc was increased to 10 seconds - Pkg-config files contain auxiliary variable with library filename - Bugfixes - Configuration commit or server reload can drop some pending zone events - Nonempty zone journal is created even though it's disabled [#635] - Zone is completely re-signed during empty dynamic update processing - Server can crash when storing a big zone difference to the journal - Failed to link on FreeBSD 12 with Clang- update to 2.7.5 - Features: - Keymgr supports NSEC3 salt handling - Improvements: - Zone history in journal is dropped apon AXFR-like zone update - Libdnssec is no longer linked against libm #628 - Libdnssec is explicitly linked against libpthread if PKCS #11 enabled #629 - Better support for libknot packaging in Python - Manually generated KSK is 'ready' by default - Kdig supports '+timeout' as an alias for '+time' - Kdig supports '+nocomments' option - Kdig no longer prints empty lines between retries - Kdig returns failure if operations not successfully resolved [#632] - Fixed repeating of the 'KSK submission, waiting for confirmation' log - Various improvements in documentation, Dockerfile, and tests - Bugfixes: - Knotc fails to unset huge configuration section - Kjournalprint sometimes fails to display zone journal content - Improper timing of ZSK removal during ZSK rollover - Missing UTC time zone indication in the 'iso' keymgr list output - A race condition in the online signing module- update to 2.7.4 Features: - -------- - Added SNI configuration for TLS in kdig (Thanks to Alexander Schultz) Improvements: - ------------ - Added warning log when DNSSEC events not successfully scheduled - New semantic check on timer values in keymgr - DS query no longer asks other addresses if got a negative answer - Reintroduced 'rollover' configuration option for CDS/CDNSKEY publication - Extended logging for zone loading - Various documentation improvements Bugfixes: - -------- - Failed to import module configuration #613 - Improper Cflags value in libknot.pc if built with embedded LMDB #615 - IXFR doesn't fall back to AXFR if malformed reply - DNSSEC events not correctly scheduled for empty zone updates - During algorithm rollover old keys get removed before DS TTL expires #617 - Maximum zone's RRSIG TTL not considered during algorithm rollover #620- seems we no longer need jansson- limit geoip support to opensuse- update to 2.7.3 - Features: - New queryacl module for query access control - Configurable answer rrset rotation #612 - Configurable NSEC bitmap in online signing - Improvements: - Better error logging for KASP DB operations #601 - Some documentation improvements - Bugfixes: - Keymgr "list" output doesn't show key size for ECDSA algorithms #602 - Failed to link statically with embedded LMDB - Configuration commit causes zone reload for all zones - The statistics module overlooks TSIG record in a request - Improper processing of an AXFR-style-IXFR response consisting of one-record messages - Race condition in online signing during key rollover #600 - Server can crash if geoip module is enabled in the geo mode - changes from 2.7.2 - Improvements: - Keymgr list command displays also key size - Kjournalprint displays total occupied size in the debug mode - Server doesn't stop if failed to load a shared module from the module directory - Libraries libcap-ng, pthread, and dl are linked selectively if needed - Bugfixes: - Sometimes incorrect result from dnssec_nsec_bitmap_contains (libdnssec) - Server can crash when loading zone file difference and zone-in-journal is set - Incorrect treatment of specific queries in the module RRL - Failed to link module Cookies as a shared library - changes from 2.7.1 - Improvements: - Added zone wire size information to zone loading log message - Added debug log message for each unsuccessful remote address operation - Various improvements for packaging - Bugfixes: - Incompatible handling of RRSIG TTL value when creating a DNS message - Incorrect RRSIG TTL value in zone differences and knotc zone operation outputs - Default configure prefix is ignored - changes from 2.7.0 - Features: - New DNS Cookies module and related '+cookie' kdig option - New module for response tailoring according to client's subnet or geographic location - General EDNS Client Subnet support in the server - OSS-Fuzz integration (Thanks to Jonathan Foote) - New '+ednsopt' kdig option (Thanks to Jan Včelák) - Online Signing support for automatic key rollover - Non-normal file (e.g. pipe) loading support in zscanner #542 - Automatic SOA serial incrementation if non-empty zone difference - New zone file load option for ignoring zone file's SOA serial - New build-time option for alternative malloc specification - Structured logging for DNSSEC key submission event - Empty QNAME support in kdig - Improvements: - Various library and server optimizations - Reduced memory consumption of outgoing IXFR processing - Linux capabilities use overhaul #546 (Thanks to Robert Edmonds) - Online Signing properly signs delegations and CNAME records - CDS/CDNSKEY rrset is signed with KSK instead of ZSK - DNSSEC-related records are ignored when loading zone difference with signing enabled - Minimum allowed RSA key length was increased to 1024 - Bugfixes: - Possible uninitialized address buffer use in zscanner - Possible index overflow during multiline record parsing in zscanner - kdig +tls sometimes consumes 100 % CPU #561 - Single-Type Signing doesn't work with single ZSK key #566 - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - Compatibility: - Removed obsolete RRL configuration - Removed obsolete module names 'mod-online-sign' and 'mod-synth-record' - Removed obsolete 'ixfr-from-differences' configuration option - Removed old journal migration - Removed module rosedb - changes from 2.6.9 - Improvements: - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation - Bugfixes: - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - packaging changes: - enabled geoip module: new BR: pkgconfig(libmaxminddb) - enabled cookies module - enabled queryacl module- update to 2.6.8 - Features: - New 'import-pkcs11' command in keymgr - Improvements: - Unixtime serial policy mimics Bind – increment if lower #593 - Bugfixes: - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy [#589] - update to 2.6.7 - Features: - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) - Improvements: - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination - Bugfixes: - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback mode- Update to 2.6.6 - Features: - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation - Improvements: - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination - Bugfixes: - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- update to 2.6.5 - Features: - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set - Improvements: - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates - Bugfixes: - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations- update to 2.6.4 see /usr/share/doc/packages/knot2/NEWS- fix tmpfiles scriptlet- package /var/lib/knot - run tmpfiles scriptlet during install- update to 2.5.3 see /usr/share/doc/packages/knot2/NEWS - use libidn2 on TW and 42.3 - following modules stay static: - dnsproxy - onlinesign - moved modules to shared building: - dnstap - noudp - rosedb - rrl - stats - synthrecord - whoami- update to 2.4.1 see /usr/share/doc/packages/knot2/NEWS- update to 2.2.1 - Bugfixes: - Fix separate logging of server and zone events - Fix concurrent zone file flushing with many zones - Fix possible server crash with empty hostname on OpenWRT - Fix control timeout parsing in knotc - Fix "Environment maxreaders limit reached" error in knotc - Don't apply journal changes on modified zone file - Remove broken LTO option from configure script - Enable multiple zone names completion in interactive knotc - Set the TC flag in a response if a glue doesn't fit the response - Disallow server reload when there is an active configuration transaction - Improvements: - Distinguish unavailable zones from zones with zero serial in log messages - Log warning and error messages to standard error output in all utilities - Document tested PKCS #11 devices - Extended Python configuration interface- update to 2.2.0 - Bugfixes: - Fix build dependencies on FreeBSD - Fix query/response message type setting in dnstap module - Fix remote address retrieval from dnstap capture in kdig - Fix global modules execution for queries hitting existing zones - Fix execution of semantic checks after an IXFR transfer - Fix PKCS#11 support detection at build time - Fix kdig failure when the first AXFR message contains just the SOA record - Exclude non-authoritative types from NSEC/NSEC3 bitmap at a delegation - Mark PKCS#11 generated keys as sensitive (required by Luna SA) - Fix error when removing the only zone from the server - Don't abort knotc transaction when some check fails - Features: - URI and CAA resource record types support - RRL client address based white list - knotc interactive mode - Improvements: - Consistent IXFR error messages - Various fixes for better compatibility with PKCS#11 devices - Various keymgr user interface improvements - Better zone event scheduler performance with many zones - New server control interface - kdig uses local resolver if resolv.conf is empty - new BR libedit-devel for the interactive mode- update to 2.1.1 - Bugfixes: - DNSSEC: Allow import of duplicate private key into the KASP - DNSSEC: Avoid duplicate NSEC for Wildcard No Data answer - Fix server crash when an incomming transfer is in progress and reload is issued - Fix socket polling when configured with many interfaces and threads - Fix compilation against Nettle 3.2 - Improvements: - Select correct source address for UDP messages recieved on ANY address - Extend documentation of knotc commands - drop knot-2.1.0_pkcs11_check.patch- enable libcap-ng- fix configure check for pkcs11 support: adds knot-2.1.0_pkcs11_check.patch- fix soversions- update to 2.1.0 - Features: - Per-thread UDP socket binding using SO_REUSEPORT on Linux - Support for dynamic configuration database - DNSSEC: Support for cryptographic tokens via PKCS #11 interface - DNSSEC: Experimental support for online signing - Improvements: - Support for zone file name patterns - Configurable location of zone timer database - Non-blocking network operations and better timeout handling - Caching of Critical configuration values for better performance - Logging of ACL failures - RRL: Add rate-limit-slip zero support to drop all responses - RRL: Document behavior for different rate-limit-slip options - kdig: Warning instead of error on TSIG validation failure - Cleanup of support libraries interfaces (libknot, libzscanner, libdnssec) - Remove possibly insecure server control over a network socket - Remove implementation limit for the number of network interfaces - Bugfixes: - synth-record module: Fix application of default configuration options - TSIG: Allow compressed TSIG name when forwarding DDNS updates - Schedule zone bootstrap after slave zone fails to load from disk - avoid activating the intree copy of lmdb- update to 2.0.2 - Out-of-bound read in packet parser for malformed NAPTR records (LibFuzzer)- split out shared libraries, knot-resolver uses some of them and atm we are forced to install the whole knot2 package.- lmdb seems no longer optional- create a new branch for knot 2.x starting with 2.0.1 - Bugfixes: - Do not reload expired zones on 'knotc reload' and server startup - Fix rare race-condition in event scheduling causing delayed event execution - Fix skipping of non-authoritative nodes in NSEC proofs - Fix TC flag setting in RRL slipped answers - Disable domain name compression for root label - Log via journald only when running under systemd - Fix CNAME following when quering for NSEC RR type - Fix refreshing of DNSSEC signatures for zone keys - Fix binding an unavailable IPv6 address on Linux (IP_FREEBIND) - Fix infinite loop in knotc zonestatus and memstats - Fix memory leak in configuration on server shutdown - Fix broken dnsproxy module - Fix DNSSEC KASP timestamps parsing in strict POSIX environment - fix multi value parsing on big-endian - Adapt to Nettle 3 API break causing base64 decoding failures on big-endian - Features: - Add 'keymgr zone key ds' to show key's DS record - Add 'keymgr tsig generate' to generate TSIG keys - Add query module scoping to process either all queries or zone queries only - Add support for file name globbing in config file includes - Add 'request-edns-option' config option to add custom EDNS0 option into server initiated queries - Improvements: - Send minimal responses (remove NS from Authority section for NOERROR) - Update persistent timers only on shutdown for better performance - Allow change of RR TTL over DDNS - Documentation fixes, updates, and improvements in formatting - Install yparser and zscanner header files - Improve lookup of libsystemd build dependencies - Fix compilation warnings in endian conversion functions on OpenBSD - changes in knot 2.0.0 - Bugfixes: - Fix lost NOTIFY message if received during zone transfer - Disable fast zone parser when compiled in Clang (workaround for Clang bug) - kdig: Record correct dnstap SocketProtocol when retrying over TCP - kdig: Hide TSIG section with +noall - Do not set AA flag for AXFR/IXFR queries - Features: - DNSSEC: separate library, switch to GnuTLS, new utilities - DNSSEC: basic KASP support (generate initial keys, ZSK rollover) - Configuration: New text format in YAML, binary store in LMDB - Zone parser: Split long TXT/SPF strings into multiple strings - kdig: Add generic dump style option (+generic) - Try all master servers in multi-master environment - Improved remotes and ACLs (multiple addresses, multiple keys) - Basic support for zone file patterns (%s to substitute zone name) - Disable zone file synchronization by setting 'zonefile_sync' to '-1' - knsupdate: Add input prompt in interactive mode and 'quit' command - knsupdate: Allow TSIG algorithm specification in interactive prompt - Improvements: - Zone dump: Do not write class for SOA record (unified with other RR types) - Zone dump: Do not write master server address into the zone file - Documentation: Manual pages are included in HTML and PDF - drop patches which are included upstream: 0001-loosen-openssl-dependency.patch 0002-make-configure.ac-compatible-with-old-tools.patch - also drop all buildrequires just needed for autoreconf - new buildrequires: pkgconfig(gnutls) >= 3 pkgconfig(nettle) pkgconfig(jansson) - create devel subpackage - enable rosedb and bash completion- local state dir should be just /var- enable dnstap support for factory and newer: - new BR: protobuf-c and libfstrm-devel - prepared lto support but not enabled yet, still need to find out which distros support it- update to 1.6.3 - Performance drop for NSEC-signed zones - Proper handling of TCP short-writes - Out-of-bound read in zone parser for long domain names in origin (AFL fuzzer) - Out-of-bound read in packet parser for TSIG RR without RDATA (AFL fuzzer) - Out-of-bound read in packet parser for malformed NAPTR RR (AFL fuzzer) - CDS and CDNSKEY support in zone parser - Add defaults for TCP config options into documentation - Detailed error message if zone reload fails - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch- update to 1.6.2 - Limiting number of parallel TCP clients (max-tcp-clients config option) - Ignore refresh and transfer events on non-slave zones - Compilation with Dnstap support on FreeBSD - Possible file descriptor leak when terminating inactive TCP clients - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch - moved autoreconf -fi to %build so it wont be tried in quilt setup or similar tools - move up the %if case for systemd in for the preun scriptlet to avoid warning about empty scripts on non systemd distributions. - used xz tarball: new buildrequires xz- Add deps on the docu packages to regen documentation - Enable systemd integration fully - Add dep on libidn - Cleanup with spec-cleaner- Only require lmdb-devel on (Open)SUSE 13.2 and higher- Updated to 1.6.1 Bugfixes: - Journal file would sometimes outgrow its set limit - Fixed incompatibility with OpenSSL 0.9.8 - Proper handling when machine hostname cannot be retreived Features: - Support for DNSSEC Single Type Signing Scheme - Compile with lmdb-devel to add support for persistent timers- Updated to 1.6.0 Bugfixes: - Fix zone expiration when AXFR/IXFR is being refused by master - Fix forced zone refresh on slave (knotc refresh -f) - Persistent timers database opening after privileges has been dropped - DNSSEC: RFC compliant processing of letter case in RDATA domain names - EDNS: Return minimal error response for queries with unsupported version - EDNS: Fix interpretation of Extended RCODE Improvements: - Maximal size of persistent timers database increased from 10 MB to 100 MB - Added logging of persistent timers database errors Features: - Persistent timers for slave zones (expire, refresh, and flush)/sbin/ldconfig/sbin/ldconfigobs-arm-8 16330784613.1.2-bp153.2.3.23.1.2-bp153.2.3.2libdnssec.so.8libdnssec.so.8.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protectionobs://build.opensuse.org/openSUSE:Maintenance:17006/openSUSE_Backports_SLE-15-SP3_Update/a08d5cf2d25af1f2ab7fa81a995d2fc0-knot.openSUSE_Backports_SLE-15-SP3_Updatecpioxz5aarch64-suse-linuxELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b779347a1b28f42565d7b2022bd1fc91a4fa18c3, not stripped PRR RR RRRR RRX7rutf-811e0ede0562e03b661c0404284cd7ede75ada843b3077bc10c27006f12e37145?7zXZ !t/] cr$x#E}6V\ļL?$HskLZT =/FmnrkϾ>‘j\(/fQ7[u=ZXoG٣>wD >v\ V7S gsWp hO+ ׊6 FmZ\>?tw{9Ť7 hODXhB>TΥLg6dx z+}*JUk1 ˹RΨԯ7RP߁_os3 m7?XSzGWXOkBJγx>о5Fy7'&Ro >8$^#̐73)yӣ#cM&M7fU"  uRRHix*:p͌`xZBG .ut7htJe6(x+LB_yH zFY1 bREZ׫-F_VFc Mj -dSc%n(wq8kr: Oc/fu7"[k|(O~u5/X 鬽YӰ&BI QdG8+*MW5Vjpfk=YnJ5l|ɳ^ eCtj*WušU*^׃z\5>t'["T{Pr "E6|kz㢜ܗ\|ϲۡհgIrK/[uMm8Qw_TPE,]` jCpȦj\^^|l+\'i5ῶ~ɰ^K;gD!D Lx<ן.[]i:IBH{I݃\/yH$;ibjvP\k 8gnv:IdGc#cUG|GD!wQu:< Ǟ%ISo VJ7`u:ZnݴGt O sإb-$;5CwQc`]rlݩZu.>Y#΁xb캴nwe[$j-ۭR,(vS1g !`UՂg+ؠ7$ K:O*n7/Os}+{ MԙTRٱ9;lL&KR lr[>E&;@ⷴ r,]S^AWUV|v B8.L[=ùQ=+Gx{.U+ٗ.a'A/;3,vd[ЛB@(\N!>|_[y(ehBW Ȥ42:e2QO2YuCtH5Z}~uJ?\.rS\摑'*`Wb~  47$Z;kQV޺X°X@ L}lIQZ@ލ֨Sl+P nhw'HE N>j ML D0EyᢜoCc1C$`{童/z_uVNͧM#Aw3uIBx ܫ:3R_ݕbSqHz]+tY#ўßD8/bU@etvT{;ϸ51h2*^8[.b DB@rOrCQoq?M-.Z$@0^E!a"8Tdm9$Sѿr%S Gt1FSNjq= 4t雲>Ia*jťmT3Qƚ% W}6ѲQ%}hqt-~wD]^O’WjoR%niQ{&e"7zV~30w;|uaF2y2k$B~ ZfB%x֭R)Mlج kI:%B^D;f*>sm0 @lyl:XiDd!!})5K$ATldɦ'aϸo0^EK> ޟ=8SS KwWL`kl H5a3 *?CL8)>Aڮ7gZ2&v2ӝ%BF !d> ަ!gib*nD㨞.)_.>*wVz5V 2u.o:aV4mP4g*/Vl-8Yk~5G$n[)P!<fqޒxѥ9?R}U1PdV變Ӡ 2#;3kk&/heV$M zǖ@dzpRyYD"MvBL?$ ]2TU°fu g;ũsĴԦǍ ͻDrOH#;eh!qX—~W3SW;>f[]cTJt* 6m}/ =sI}mɒ6&%@i;cg3)pV{ WCmpLI9rz&n,|W3D C: zGJWQ<yܵe3. =s)n \sWJ9>s0r^M,%.k 2VW=U +Oaw)Y% Q%'xZ["xFxa0fVߒ3ℛsŶ쳻:;55mH9; 0̻mٶ<}(mw{5Q)im|.cUe5KZr$ qp\=d: r8Xd2mT;֨.H". uhvck+;*bFVR;nKF}a bub``+?:;^7koS1pԷ2qs)t%d-kq 5%U>0YCFU*XZtfj\?ܸސ38>b155b|Ì86]冽tqrGhjnq*?.#B,eB%bƄwT5rM phq$fU8к"w@+d#f 20Xr[BቧU/:^06Ɏqe/:h5y˦2_3{rhpM[ZjNeƪk~K{9o9oOkOUl|$.͞alɣ4 Sڿl}DtNR.?9yhS,Ee45G"z,,}/~&v/IrM]))4R'݋34 aË;D7DNkS $v ~dm8P9DVK%yzPuD1+SSd\z[׳8& K[UbF`{3YlTP řY^hIn;7Ǧ2{cV¦ >>b4U(weKKR "]o]QJꨊ`(; }36a`kO 9ir$4Jw%Ʈ0_\w )X~cRDxi(B7 .U{%3[xlM/nWQ{ֶB<-~KnMRRz2q@_` $Bm0_j٢$mɷ}$?n@UF`5WОJa3N-BLk݂~OC+7 X܃\>ᚧ~F兄5q.t748 cVS8'qj-Ж֍ 1%qš<9Gd"D&3ATi>84IzA:=t"vjb@%^TƢ^Ҳ!UZ3s@ n.aJkZ&Rr* ~4f;X"a7/˜ZUi 6#X$\44c'A"a9![`5~,P3PA r̒ EŲy׭%95sCk}OWEzaX;I21O-ʁ'/:&Arbh8AOd _%.Tʻ*&RD5#v:N/d皊dX'n/)7n0P0٪Kڠ8vS^dg1ch?PE42`L\+cBh9-mZȲ)LPꥩ#ƪ@&1&$Y%.߼n꺃yCvb\@xC|hCf%zTsmslTڍIRΚAeH9o  (IƗ:SaFjqtrf,9u&H(qjyXcqoꝂ.H Tyx_sd\? W< bцʄLyy"UWNY|)Ȋy _?2םvFMrkxk-0އE<[ O䷹,Ǻ/ۓOVs8{&flE[S=LIGw)ɞ(譊5O竉S+4<֥SHiaįe(]#foxs6=J2:o}+=I-0I{\HE >pg* "cZ8js0 ט(=EwLAx7>L:-Hi3T(Q~)Ԝcr}lт+(/kgX sn{r8DsPo9h3j#X '-OȢmi܌|Y.Em-ڇ-%SY#OY3PT@ҁ6hYN7v'Auf"25s"sDu/yƾ|ߚH1h]|^0,V܋uӎpNU5ۧ+WW{ZQGr, |6`:Bg,cI@Iyɣd_,EKͥjgP}D"[OdoٌV|T-A *"bq?(#&_T-Sr ϭLUwv<vQ &wP's7=_v L3K^9cRbTewqZ `fٲlX]oZyh2v[KVd]0E,둦pzaǴxmϠG8@\2YW\cˏD[񨕭3dh؂2E@#4cp'"gca*Q(䤾&>Oد(N݃q,T $aWjeM 繪>q0Jh03z L AH^m:㖵uLR !mKnVWQmµ%:Z^oKhlB|ĿY4 }sO Δ#L3m~qvrRa(0(} )[s.ܵ`r@_ Xϔ,/V,ٗv#QݥKDH{#e1jlBۭ+rck%Yv/߾VC~ 6$<(XN_#yn8dC:w{ZrlWy;\.?ya,T).Q׹K>+3i54i\Z'٧heoohk֗fY~sM~.D}`d4"Oᔧl6ba;Q&\:W rnM::yϜ|Ǘ^- YVjl! &ym^A"øɧv_$&A>eR9OVT M۟^|L~E>A2[dWчTSf]hG===|;ׁ6 kLo1PjS;)SoT1xͩ`L; `&n5D0S*QTd^§k&^&,C^*\؎"ou@Pgj›0ueMct2Ģ4.>~Z;==Cd.fj9J/1 P4[N@ A 5T@=iOQV79^Qac([i7Z,A8U!Y"?AҶ_=JfG >pn G& s]n{D2=jG %1qDO&ǿW72p5*Ÿ 9bQ+HW65ݏFI@T#0zvN:qB @V]MH敞 IFgM"PU7X桬wRZO /+(C{>@ \Kg'I@L2h6z 2I.kTncp ѤuR:Op߸ù8=PHŹ=WNQla0."y{f&ki R6&V$}FO93MjiT/z2!IUL/-^>|Dfn>,逞\> G"'Ǔ1O6Z`.e_x\7[l#;9=~sDe)ޡPtosI2gK^^-tw* ď@6`bx~qs@޽S4v~-IfJl*v9葹{z$mZYhXXsO< RSfl>D6[2zj3 %c9>?{|:qr&~ߘ: |P L~;v% ,i&]C,8jJʸcFh-ϒ˄H+{<|FopuyYqix\\ c%]%ORoS@H$+nw!c*r\~n(jp9UM?AFcW Pآ-^w-nMm. ѰORsLp3Ǐ" ߁S2Qͥ2g&,\x\7 O/_q܏&0rO==M *4EZ]f*ϹȜ ԬdE{Jk[FP1a_Ҥ{liZ+'.nuɏ '1ꨒ'~{RƉȲ_fGQ: 3(%CF!C'A^iXf(rn. |/`zބ؄ZF-?huwDG)P^I7Дj_7^Ef|Vn)O z'aC 7+:[7 g,-nhu:3+9{)KURD~LkS^5JsJBDUV!9ܫ#z4gt9񏻎D 18Xнda TE}/b6 ;}e)]uzw jCI;#vX'-Du$}8]ywyO睍]zbq$J#z-1 쬧߱Y ɝ_vzgHD gA[q=ڀoNJ(2\eV!"pB@[~vChcbMrcO>iݷԩ+ĈKX}A*k  ں"r͹SI &a/s3;睺Ё2ׂ`د &YSWCZ>erkP(5 Quj7h0]:TQQm<@|fpBX0c2V,IJb&tB#H2XXЛA ػjKX˴E7F9VOd82U@nBmI멟Bif_ Sb/+r6tj8[=0X#t\/$C%=-= 9PBO<[?v(w ŵ焭z/f0 Mkμ >F1&P|jkS<.l~f*VKKf%kuԫ!]`-7rtOXC?cm=p>Dy@ R(s:% }m.f,=$|iV_fĭӕ?G٨)8Z~bA$a>(AE!A?|hLQ<-'cHˤa֌?:Йtc9zd_ 'TyDoAO@L^EiZ*m0 ;W@ZdObMLl7 ŪJk G0<$x6"MJ̭8UrpNnհ-fB4ݘA ;s6Q\woHwhf~~R8Q\J:42`bo@-Fy9^!G%߿Ož71ڭ׷faY/hCUݓugRZֲkW q`شOPEXyob{6/Jǟc|{{0O٪P#3:Cys^3aYz]07 ͌j=fg۔P4k lQ ~$jwmRüỢf3ץ$WKmzK0ٰRU~szU^}zj0`һ^('ԟ3g[s *# ,$d*t-X?N јK1\J#)t&:}Hk7()v^)yN&D_Nɶ]Q(.Y6W5Qj&dۿ;ے>o/{{O"^T3J5c!h j+8x L6HrbobgɃeϒ%r)$(/pv]ϊLn2a1!,T7T2#J͠xfPcSK [̼=QPTuu^zFCG) !D>PJ4+/}cH ]7.MY]O:nvOj@ٙ"Lž!gK~ xZnɦI/FDL 2z!4Ue=Q%0d[*@:zZ?*_"!Hc.ǰ ME#&R]QY l{fO(KB{S  pZI>|Cb:]b˳+o͡{ &6TZM$XF2|Oޟ ߮xBÕKrҖqofx:v{S^֣ ; _zYWT#r2qab,lg5I\e\~sbRגs,z}?@±r,Zwv#UdKҧl)k qpΧ, 9o2Ź4ؗi1XC$t@-؎ BbQuQZU.vh { π*Oy1ZZI'hQ 5og7Csդ9֊Wtmp&KA#VQ!jN T1VzRt"I̴?S&8! !8ƍ]wiP+5 fu:ͼ=^} a:K6O]zұ-N1Bn&=6BZ~'W|ZLT\D촟fw')ttdU{[FUd 8 PX!Lbr<}ԅ"٤eEwrd`<peuszxΝׁoㅑh+`8Kg a{T-v6rIH>es4Xo"q<<ֆբy2;<4 |iͽNjA ٓs!X|E8n`$l)ohlg^MVSBg)EÀL<Y V!ij׉uzhx _erX<:zLºtw[dj#V4[-m`Pv2c?k{^H p o`(_wӶlsݾ_#9;JHG'`T=96?V'eA xR}1g=1\cU%.KISh tr,1xAYVhy7\=F&ǐzƣG^ UsOe `5aƤ$SDR @gINOz;>!2Hh(r5c@=J*\ M,-rFP&Y3=>!xtm~ hrxХ2$T@(Pճ p92^49Ar 93:Az,#?~exwl=P$yO 9u«;P B-DG.2$'\[̆+}8}}Q#]En5-㺸CF fCȻ?AtG( 1P=GS؆s,}!%&wlSI'[>e%4[kL>ےDj{utX/O856' =kHxs5e~C`w'CfDz.g6h1ǗsHcP`FH*cie1>WwNa\AS B. q4=_f 5 el.6C 4.Vv_(%/ ֒^ oQI_n$-4쁟^o.HUF_rO)֔ _\CCC ɉ6nN<=B.+m>z^a_kȏ؂'Ukjt~ ! 7mq$XɜXO?@H?U!̭-OL:"ւ~r1t7i|Pl8fbJUhEUC֖"33k5fA3:9T@CNC{>[7TxoDWݥޗ9T>j/g 1<6> "@uN$,HU6Jniꈁ$f|cf۽>,^ #QjQ 1lS Ja oAS3Ni#G#\*h24qW5N0Te|i3p?k3Vdv[D,mv6lj\"pm EB^N!SsG~/2]s?iUt9YZoB }k z@w +L oyT5wjTX]|p&[/{oz҈W蛨qbAgXxx"ϖxoǀyQ/6YVfGKfse]?A]_@&)d{6o \k\C'莈(*d;Q{·$u`]7[MǑSEK鴧;1-ܛt"כ]i?CDs7F Y O?T(n.M\QVIӐ*n}MOԵk 6&[: 6E\>w'~TC[FZKh1# ʗ|\w#;=\ZԵ3d}:oS璃q5pckc\桭jÎ4߬HPX1.Z7 |hoPXR,b۔ƹ5p9.nCsm(vVh=+A Ay%xd=b8`9^QP$WL'POFTG ?n^-"!$G[80E"eF}p] ֙{J꽏U9bƳY=|W$:-$'qr5 ]a}/G*23\mnoH\u $),3uEPG_%uCZxXe }Z*َɑi!ų,ei@@ gO;VqNzGL!{61xBOsPY!!܁ Në3nn) %㓴BRIURp+)x8 IV;YnV<KF;d [DLJ:RŦ7+Cs%FT};ڂ!9.|}C\ AY'.`gs4in;C=n\Q&N&1_rtp7I i^kdSc;u~\o>sm%I+[HœAZ! @ Q5Е8d&/pY5&DF"ߩl.+n-_z&tl0yGȝ1ͫHb8ul {KC&)mT0Z; I߃w!*jQF7^׊Y_2SXumWOIʇse ?pV DxB~u1]8w8s|'%Bk!IĎ! +󣀞A_Ւ)Ul& w]@MN[D (-2j1 4ܧR:&oi"#Z՛9,gjAa\sfV'vc*H[\"'!y y&ۅ^4ˌTʾ򌚖帒/~"Q\2 ݠ6,4bOY\ni!""(pH5=bd^ +X!bX:@#.%bzlaVþ>nQ`63#;VaмboK{ѻt@ۦ}Ċ'@}[ _dkJod)Y2S-zY<ާ.\hw2a.M9K \+:ob|>$pn'=XTR+QwK>d_o>:"zk?>so&Eo̠0sQ`RpQh\ ;}QScHקsJHڡT\e_Nvz|] 76 I<:uDBJg3[_DM8})_C[]a$J}%U"eUΟaNh԰s>sß.c~6ͦ$[BYV@xԴc[ExI$N1ТhF.OU˾m]ɢyos+U w{$*T'vȯEa_'i0qm-qC&l}C֤1~W?1>E3{B̒H4>.ǻs}aSZK# vb,Yj/I+JyH|ـ=Ԛ ZMfhɼ(%BOW6aL ]m)ŶV+31*n<]E` /7>cBΗW\Ƶ.( m3:`5li3i5oRlLHLLs~ <[bBmw812~RB4vLy_!J-~v!\)\0guupdg`1ZGOiOglTCO!>+Ny` L+(eEC*CI4 ZDY3꽺.گ bdKZ"S/RDž8nbHGe eP E_^wDP қuXw -,qb|5SIFO"e\<.rMk GlK#4w|hT/jjxH2p9š鹑W{ 4ߘ).qvE<> sɗ\ل$\Zs$wpUX}-t2 W#yIO/uE FlDi/HH j\5P'TBO%$ސ8r:^B{Ӑ^ wyw٢-2)(+jk* KvI)ce\)S˟fL;Sa:(ExC.}|A.:8EdOT i ( TV+Zl𥭛xn!̔[CGFx `F҂gI17؅|D"M:ZE#VVp1Í~`E@'lEAC;>">EFd:b;*y@~'<1TU d.Z-&m Gm=Oj*XDbؚa</H;1K3/-&mIFBÙ@qmӖgX!n1[nTΟ.W< KX|=Z#$#+5 NA 9h("K5q"'oˣ}{F"A qB rXDrpraR(I|ş.C{_݋\W'xǭx>|ēDWWT@3`C)YͲjUHM]Ă?V^m,qNFC]ְa߄\/_bky)#u]E=f&[_ sdzC{IJ 8UqGESFm ]iFcM9xDϵ' Y_oߟnRGhO 3 8|)BzG0x4jf(Ev7EH@߻)n؛~歵R,ǾLj}`a !(;,/J.W~]^xhV׎o-:EX1BQ6j $@WltpHt9?YcUu]Gy9H$:o C䠎| P[гwm(܆jȣ ^4\#ǀGճGJPj:"jOBEX2=;ݵN^pMj,.˳kܛUҽ+W?IzII/B{%Eyl1ه0:g71 Qt+K5W~ƝISCSD'_'E;E`HL;#:Wz+;I~`5MmJRxnF,TҬL XI*绲R*<枲+ @9<S'5#VJP2(H.G-;wdDB/>X'A_͹iTrܟw W[(#'3lrr N5`-h2.كIç>6Ȃqؙ8!,e Us7+٣qLfv@J s귀yqP󍕐N&7b%]CL[j!gx %\Lip*ʹk f{pe+0sV-S˽h43׍f{T独QnP2[ģf EH?pKbz\?w V8 PZ0'C,I٢%γT.C?a_Iɗi3}k.1LJ!{9IbQp>G_&Z"# =,1Sxsi*(ˤuRznOye zܨ~^)td:}dU۬GP?ȄkEu8Ȟ&g-ݮh񘐛_jΗ?Zpӟ~ɻ& VN:;Z T{.u\0"F.lJiZ 7V5H:{d,GX7s=?A͌=JN'P>^*h+`M4M9,|>g."H8p~wȷ.pX_^jlKo|ߝ1AUb\i_ 04n&<:<Ү#IɅO^:KK8fv#?1[zslY_2':e'gq t5!/ئI3;|b1I:k6|+(꺆xIo8ypS$**4`~~5amBِ$JQ0m9 X{⿒ MXzl=v%tl7„İG)l.X*r~Xڜ2j0 7ŒJ;y0P;/C1*_'rW%3=l9 8c.NqQj8^B#%dK^\v2{Sba߳j?/E" Or!T+h#$BtTDl,OtyLT{a !2,I?LJ'@)Rd-P4o[#c4tNl[D&yOCw%=Tν`k}c@VL_P:{ ΏdD H /y#܃Ίc!{EU5ԍbы ;ֶ?]k.9=;Wd]o9"/ L]N.Jp\;TD*t}2ϓ"7=h x`A1}lXkAyVOwmZoD8C]~`(19D]w}bf?<...7BkD pCs2Jw9A%<ͣkX ǼQlk>EoTi4᳨ v}f$\z2.$_3}!V4 DJ/ֲ ƽѬBerQJ? iԼ$E̖Kw& ᓭ3Mg4LlN >(AA>@LU:13Ҿfqp%#\g}9m;q"`+ "2 aR{ZKm-z$|&EzZf?g4#"'&!ϝqgbCZ>cwǙZ 7@l$㯐^)Zo(b3ퟮZwZ0<TD_ f-euVAuE?\ҝpEbGoe3Ͽԋ "71(lDn-|o02ToL7ɴ/{ıys"4D>qPY޼)xL5n`2ߤu6|^K[/Y_ضn=¤ճp&^UԚ%.Y#- 9Rkkf`,Us ۿyE}ron*=|65z !*ܔw'e,V)/[&.Ol8Uz[IX-B yjq @:DtΞ*1_.`E=vF i:dcC O{~~ۻQ YteI~7$ȵmaod 8J'ϸKeL;hu>vQ\_uԞ*Fӓ yFd>#010) S]ڒ!G25~ʯ|a1`V>w.K=aWQej\c9༮|5$1h7d6)my7#طfoss3F9~3_TLCBj׋*3^*w{˂GTѤC,JqqpO)5| 4kF\1>S\ 5̌Q>h # K)Nq^='K.;h5',yQo"hS{i1дȬci<l!PHf3/=y`:`cu-߄aK8ٜ'&"Mir1x) 1 Uf%B =02r,1 #ω?_FS+OQ A.4vJK3-* ܜ]bua+ QNd8 .y:qgryTBcH;5(@yt;d/ g2M?L? y?b,M -dL6/>Ƌ07R=8:Ax7Tӻm (d1'[U걵q*|9sӌX1XiE$xzXWbHմ-3?c1aTVJ[%r܁.q'ct/5)r!Pd 1,m-QXKg;3L^EjܟyM}z^d4~v=՟|/ǵ b~ΟLA71ߞa0PM΀r:bWVo?){g1.9ʹϵiի h!#YyuQ|YN!h^{l?kpB.x7JB:A:q>ON>k<ߙ ; %A?tiO}Ѓ3hk{:ʸh㦔yJ'"ǪD_\"TW?߻Hkz&3QB/ʊE5 F`\bXB,%l%`?D:K;E64oYj/x;ޑ)EP#e9:[jgirKO3VfkqHrQ=-VQ AW0C)+dP"^f-3q?QW>(rLZ h{ y?C(6ss~7LnЋ$cF?,X%jUzsڟלrl!笛xouN<8Y2G ;^Jڑ%|~W W\~b&7AZŧ~gSm 3;=}oI<o(Un֧d9l.'-XC<5pqWE"1:h XKlg'>çOR:~_R4wI͠hy=(_|́iJL X'q{Ue_$bUO AN(a%M"%>vt}O 5Hβ9lK9RץCFrx.>HH0{(`9s *S1Rh(0 k!Cڳ/Y rS&py_=O)䑉\k\ >,ώ,7w%* bb3{Ly:cGCr l(1'5<4׳s!BLD>|ɏ|V$snW%zHm\ߍ21o6.|p8 NUD 5^8$S [kyK7ݤkTI 3ǫp=+RzjZ͢3lu}X"),\խ"g[ýk7@_+r(VaўN~UejYpnH%7ױsldu*L2Ȧ7  B~T&ay-+((xXPCƩb5gi,A?0x3QVL)} Y B ܎+>3<|ulFyYcwpQ#@ŏ+isprM~yeRjzI>i1 j!rW0"0r㺦7<:yi1uֽdRׄu$c?١ d٦yq I8vSU=7׸Q +`϶s^w)Lդ*\![I*XX:` l#)6[<2RF{5#@( -rh< QSysWJ.b6x2tȻh 9oy Z+`vΝkƾ'up\ǯX- wPcݶmSftj;3@YʒI)]]L)Df2ec w-:3s :Q%,T B6 ,GԔQy {A3? $^И7]y5;@(\vCR /iUfNh w}PM]-k5%'Aw'+XAt>_zښL~'-IFvah73fERUIH\w}1IW{ݷpYpxPuM!B^yd̑r,Y$e49n||[`:xN\4E|+ rMABוu?4T]g|:+ahF*ﴂg˷ͳY#PߤXQZjt^R U Tc9eaGP@٘:т.r]ChQb.Y\ ^Mg,q-|鲻$G¢E[o(U`-oz DT?vdqtkEG[t_| X%cB9}2%KyjZ4Xf50C~M rÆ)>AZ#dҢ(wҮWgPb{a~( ]9[μNZ[ B;Ǟq}Xh{E4!.˦HNDcːDJ5,ABi83OcZFhCf vL֯Z౏=42Nm׈n]N٨;FV^iOS"nBp\Z߂q^sjɾ ZX($bНʅ?x>F^[-$V8QjYwzFj&6[FSUF'`gB{ K D.Oj Qۈf4>hg0 ьxnوe,I~~#ru@>cqr&pܣ MVe>dV.{2e*jWeY469mg|{Y, t[kAA>sX*8& r&B*iE fY,}M3E謢Q\olrN#M)6pJSo;.V 5I QۅS[~mKs`7 tKT!` SdZ&*s}L2CYIAwÑ'GjhMBˤJ|v5_f1 d(@sIj5 8'ՂM[F Y(D{xxr5{|+d D [,ω:^rW(~d ZFu)#%!ZG{A<[5'jh9ѢtV}b$oV~ Ow3WnYB{3]6aW HX.+kԱQ(EHqEՏlo NߋvklTY(s C(jyDLHV=D(^X U2.=ࢣ(Ct+pbfa\*@ SGУ@,^wWIpHnoJѽδ"YG#M_'s5Y31;]hNSJr?PEfR$&\-+o粳ВɌ$6LO>+vq[&:R-یtYydYOb3@PYOȌt&@,X3ʰِtUgsHd1ϱ9^63ɔ@/5ayzvP*þK"D=wwjOJyKd=d)7 ɀH`~OR)cٸȚ?F[ "Rʎ=ȰYv:8@WpHc*oŘ݊u~f,膊Jr^D!>gO<鯳o7j9Q5!HZ+ez&J66Q/ ( tnl~Q%jn#eأ&}Zru|z $!x4pdj]/qKϭaDjث@܎֡YYAq 4ՆX@]\ɲoB?^;TF݌%gՇ4D緯G `ĖUߖw*2iMFAoh4:~aHqĶXO LO>5S?cRpaWyjK gn±]t+0x]W=¬*W[xJ2;u yuAЭ"Rx5Ӄam}j%VznfG6h~kb[݅x}/%A ۆl-_nk!ރ;u'3].L,V]4܇IҵX1N,2Q@ 2 5k39Ԅ=f=#M RouTt%M dSyNL߫ªڈRznFH.AÁ 2k)'UP /3"VNB a *ckPhɫ<0-߱}!Dp$H! NJW+@yHzaq ۾0]VQ^7f)|P>$KY+hB_h˵1vSa@.䟺-߈ v/!0+b?vid.HE+߃S@g.Ao]`qnT -GKp[^M48b@9ca:N..:T ]jyG*6mBI1x^ҎnPD U瀭JHsTnnFnPN1RpX3p坲BL}3Itg9C"QJ6]b3Zr"[I%bj=no.7K85/0_مZgGk6Yr7LK/˾5';7B-.ELO2M(Vc6mǂ762{gƒÓd /GB=M G˓qSFAA`93zG&x*ʉ` {mhH\hLp6muQzj~ՋЃ) f0D>Qv3o`I[ͭH<\ǚNۇszR!%4tdسgx RkQ˫Of4` NTn X ~c&%^~NB+>^w+=& [5Z\l$3 uy >xgW+@lm}M |%o嶢_JR=nTZMh_8td  K\΋y'A)]SN‡u*VKs$w5|)ힸ=DUX8'W6=qsy#a8nh$^4[+Ӧ PK[]yx;Vʒh4VT#S,ݵƦ/y0UL)!\wvVynzzx(EaYVG.XLpB:yÞ']_:iړнMj !ѬN)4ԅv[pewd:=a^;ߎ#ߧg7X>X 0!.횂4'sԛ?(` J vW0bL^~%Yʕsn=[BdĞVX#ps_뼢#V *'ZZO nwqp6aNSifv 2n]FZf,bs LzPwzBū^?TM+Rz#"Ք!ţ1Kx^0t,څ Rw e%d!5]G;7_&(SS5ZNdY&15T#~<3?R(=jR={KDGt<*!m1 9aK$OT@!q.L4)*1fCj2lKw[ߤ>TJG}?0(̔OeeN,Eښw9aśfL +Mޭ:nysU')HOS4 r[c.Id̀8! ߃Z?R+C9O1.20mXʐ*\ߴ&53`)Kӳ=\s p'#i5Ko& /4qkpz^ GJD GC/K;9knxm Ta[+,b+E )xO0Aޚ{B)cn> N~O]pG.N~N,;H4Y;取4+'X<~/B"̀$לV1z8f!L޹FˋJVž /qwH"ĉLJJTRWe N0'}}'a:r(.S)w3h-EK wC67=.s͋`!T<*J[@-A:C/rV6~4SmvʲiC&|>-ހGzm5VfmC3'66ک,nj4Tģ~zSnmݝg0Ԡr[ (B[_HV` ϶43tMŭ^8iu0/7;Es-ϴBB\%nӬ_ ؏Od:ݿc9BKTBML8h C>@7+G:*x ߱!NdAR硵 X=^k~ړS t_SٽӘ.#*e' eՒC \t;3@,IL\/6DnDј\iCggZ \ea|-ٻG!"2 D!zʇ 1@t qۆ;iY\8%tjۘt 1MiHҦkpRT+xkNh.@kVܐsk=?uFS7utwX㗱0ֵ_Zw-G<$|Bl59R*bh`Ks^CD,([Z|)9h ^)]85y )>X?*Wz0|mfy V|=)gq.fk[A ygl? )\GO Sd¡r).|z,.J[4ʭU\Gh]4$5QC&=Q`*F8-Wvu?UvAm$TK"&GyiD)24Ä:^Ӏ<2 X?]\ʒ4]|7UEf`:O"JIN#Dh?bsͦh`J hYz )"nSiH(-e>_vJPGj r挑oct,;^1eF }$ҏEXIT_#EN0Y6AvSmj_Ė"䔖|LYt-ہ#.D ?9x;Q=b(oh%H$a39C_D9$TWFoS4QR9n@ R 4F\ )%6^?OgZE2]^Xމ^ :g4<&u_~tQ? 4ck!Ǎ?ؽa 9 bOl͖txH"v!wƯ\RNj+׈p&IE(IE9Fo8B3~+R.s.ޫZzt:0W&i[;AVPUݣәm佾j?mn!C:OЇ{pZeQ8k3^'hP>X4'$>Jw>K #F 34T[$&!1ݪ [GB0n\_5":1~a4b$/+}2_ ҃MK7ITr+mY1=e!@dbٓAs| / `9 j*E1uH tc)I*K <Rs=AZPɒ!!߅UR.em46t1vi@Csz5I=u1H|"?`${L}a7;1@Q(ƶ#\5AR܀)iz3W֡~n ʜPoRP7ϊ}N$vu>+ [,ML Pۯ~ gu4 (yŲxAfn7/K1E勲8yo{_,0DԤ|{r R0T UQBkZM¬Kx6&uFKjqwn N<=-seGZCN|h 7i{=Ol8uUtuuXrɗpJ։)m%ʤieLF_Y~HG 2$8l-X<_xJR݅lHkBAL%a]=hK^ζ%p_.my s2Tv]u>lnQRp4q j`0WD|6gp' jN/ jh 6YڅźvD]i( )F]8esBT0ՐS%U sΟű&mkL tTcFq,^2r*~OqZJE)N)*\=t%&;ô7荏] kCDk(Rl~Bf39T˝ͻwWXp@z?Y~S::L#|^S0~LRy{I{KYHC ~>JRUp;ـ(Ͻ CP 緤0bpgq Sw2i݄Kz5na '~+l֙C+ Ag] {Y@øو\L@PSR ˼Bu,EK'\6|\ڨXߎ>H3X:80F7d86 ˱s-qy O^\ i't(*j?޺&b.hW^^|v[%p{ΠPo%zkQi~v@(vvvl7c=wy_==/ +%#e8;8+ YB m0M)dE±iD3d v+HJ$|ɽg/FP Za U҂>'P* +)h?8Yq\ih-8@OhEk jkj @Ђ,gRal@(W('ʸ37:E,o/^5#C."M b%iH\-eR?E!J]'P7q'U5z _m:kapgق=}h}Xmos$dcv|ң(Wᇥ_2/:R%3fXqMDZ '|IT5߽9x u8Co?ž'1ۤ&4Ĭ۸zq 9!#X)Pe;(sWux"|4νО9l<磚-I@GNS2HI.䓅܏iMzPӉu Wғ̓O+8uD`MDl~"]܈0e98f}6AX8nYF3y`qRfኳh]@y403ʨQ#=~UWt&fywʩgE-UP*L1UlqI~nj1B^og %xKAiSvZnȋ!1zʲso`!dzVJ\öaf]BۺMC٬z*bmH_L ݟ J95Px{ڵ]"QNN0#Vޢ";<#f+MۅWj 0Wq(o0T U+̑MɟJE#y8m/笡^4pJs0gCtWp^DGPIJoxr#?o-7j jJ8h]|6z@6]'#,[+_m}Y,qBjmWX I,X;|yM^Ε"҂.UJS eZ pxְ 5˞)xjOD@ &3\w]\{Wco!tLY7H`Mjlf01ObOG拒eZ4Gy4ho#4 zvLu8nʏ2}w sn ͏ϛ-R?901*ț ͦ_T 9 gHD#ͨ>s]35vk`xqodOww(('{5N& LL@ۤxƇ_XKRFV2޺>hn&a|3Jk?8LZQZDD,ޥp@Ѿ/th]H7 zLd`xD=3Hn`,g-mgXs#f:Th4s¦(gl :[~ \àKZ]ORF;qw Qxs2W V%edqٙϬAƅJ}Lݻx@gbLT[ӲP*Xw|/=ͬl,[Ԉk W?fj.sPzDOT6pH=|G6m+u< 1o>T Ap EN`d"m:ؑa/>p0efL$yĐM;kDV]pQBT\g !S˓?E1/[ E+H.h6{\(Lu3|%iH'{I>}}x0~RY€!dۄ y sK8`i;ճg\e|];'NW]*"b Ŋwiul0A._;X.DpUw!r1`YO*{~ξP1QF1{)7"U~n*u}$ 4; e96XVJ Y\e|[RچRY]=..a ];"RT }Z؎JvBDYӡgcmSZG=Hpj35LءRW-?!bg5V*Abb|\i 3R1O1myCs*xa6oHe燡`||z1!trOlާf/F߿y*krH8%_'_EG+~e3Z}$`:*MR(iWInr\f&L겮~!nr3I&B?eaUPlCJOH_<"b1(K$iPrGK]腾CBT!&&#+C{R/Z}ⶴ,;LVxPAB?5:~Wqd& W@{3TSl[@f]O0a9[boQcB<"mBo]j)o,&~B{U̹H/_jTy@9M\ j(6sMpK-5G{)~As&^MTo$\a574psjp8Md %I!oK>M:qu)>f< ^2OcȑC9ߤozՌwegkB۬d]58tXrA`AoeȔ سܥ1eeVȽ%p i_N#5K6K/]Ä + f"`_).d2P)2 k~l?Qi+h/A f/Ļiji΀Jq=tد/HUS͐BfhHu/uݘ^%CIK##!Ǝ,"^a8qUW0#a[wQl@L;iE300NvIX]&qx\VtZ .| ٘T^jg]mH7B~Fm6kxSjrmզ?{ qo1IG\0(7~e׉|> ṳ] (bL@$y_+mûQqS-Q؇`Lr>/j^ M-٫|hË܏,ҟ[Lg,!+G{o7=uζ [Jb 1ͮgIurf {T_uMqNtP˙f4o=rzp-z~Nڳjb@ *P`'r֌H* !\k/Ҿ@.葶0iLdAyxst8-uԎZu*/ʃ>2@j + ë҂0;ZAhuKߕ\m~d|:-6+Pņ(]@qlZ|jw@ X--xR)"%΄#:KSa@سb95& o=]!*70N4Zupwm Xhϔ}]ci{Ǿ{ܛ/f6 _4 M˯@"Վ` rRT??_y';Kf7vP*ǃ bQ5]j PW?S)n0=O-;e-~?v[3*zyg6cߏc{ߝwx &y.z'.b>QI<_>~v777 _6÷No2D8c]u'ڹ]-E4]Oο~DŽ2HP 6j=l #BT/eiݘ8Xd6m[YC#ӘZdyvk8hw;Ot6)v3rӴk:xgJTnck%L=m-ȃ.Muh9Px_YkE8'NKN8 b\r6S>dfg`A۰>{nZ[AtshKͶO~s9XNfGۘ A᰹DUu`to U"WfPM@W#~-i slF@2 g*̧Qll kiɆz捫mva)XLh䃒ʃΡi*S{kAfx/.ҘtDZQCvX%FaI4PyX RhIoǫ8YPld2VREX* i96{HW`O/sJ>ܧ 6I_3ԃ߮#_#v7!Y#r,Jڂg'6]sO='+gq^a$?q:;, , O6ﴘlw z!Ep"zAo4tz)71' =̟ [~z̘Pf-`72ϟz-&H}L- j@< v$-4Y%[ _ ý5~{ w[B L'lٝ$)+NgC84b2< p@դPv #'+.L_ u[[I#ToG 2}uaG}9Z)\&4xGQXrxB Q%Y!O Ay$`LJ ?͢;[ -N%a-hceqSe"TfY? j+RmcPCqgfQde* '#R5Pnh B ќٵ)TJO_C07^y1-%SOVCvd4K5<;tl-"%MߊҖo%ms뼻ÙXĮݤu _,m#wGԮ_iXUہ埴}4L X8 ]§EL4; [Su ya7Y7M rbj= @ӽNY!sYCGBV( 7`4p}u%)ەr?%.z\{0 pLp%=lv7͙x8*]BCd JV?0q҉O,*3Sjx$ĵ9*ƾ@l0Dhu}lz$yݔlĻBh8%Yq]cAT: U{j:xq Җmj%C&E4mw e-/3JoS ";$9FzlՀ/9G19+3H{lx`d(LJDRaZ15Bo~+%]ڀTb΃M#2dLJRs#R|s S8@m6&R亷Cz{1`Ld3n-:F~rp"i.=B^-P 3ߦu?Y&\gVu6+: 5[ I%fJI lkɿ1W"#/0c?l]r`yRN-TkTф_ GH7RM`YſK\K{U)GSl:J& Iq3)i 1% x k1_ є1\iHuOk#BRU5Ums%ZTva,t1Ǭ"A*뒐QѩBggy.GNq<(TΥPsET'썻kh{rsIg I6Fli.']Y4eD1}v^kNL{Fx&B5ň!8k$a*y 77h ͙\A-u6+yq e3tZP*wC ̷{ݛ:w4%x` or_$Zpzf@.~ ; :B nCfW D)N7"46Z_5~~rsoˆÉrRaZVyCРMM#GRcFHDppDe|WޠR,u28p:g1\юmP ugq,=>(p/cOQ1\n "AزJyi$I+8̑NxNaȬke{{!q%4 ^:-Gg,Ĺ= Xtq)V*f]"$pA_P,i]Hb7A4xc& Q;0PQ2."/JKtJ;Ȇ8[ԏLIrq@t<?(7b&* ;*1kt6q%j8T4M *yY(q/e8FCdL;6Z %0Vu8өB)CSyBWNmJ(\SWH1ZTgF`-Rv ,U%=KT|G|} q$oUBŭS3<;=^|MHP<Au#a] \^@:p}\]L{{6Cd @e f$91r^l\OEg&XPT+J2~bz0;͸V+"bhs<1 .B}TzUu{͌ό_Z2TB(ɧZG5s1rC DӌJ:ת B?M.LpԻٗV&&X V `Yt(\/߼=\S.3y Wf+|0bfv~{ ϘΕU1-=ct)S pr&t\ù."rkzBWzZa+/Z^rc"ع2]W jɁFʚ/Rx jjBK@B&|Y %zR89xc{u`@IO&b :HRoKqPd Yê @9LRbxL^4L h6e LZ gb/h^+Wƣ>WTu׻^V/  5=Z%m),_V ihL.:kXP%j( }\PSU.wHiuyDm_fBPGY3tz0_o4 ։[FT077֝?^ 9Cn`eig"7u5hXx[L*K8)YH ANLHe d]h: AZarشYE1Ԝ/5xk#ibpVi&VSONA诽OI k֐[Zq5M&hW%ΪEvډgǧU2ma>զ#H%CpU$]^CsFPHjZby9sH$"{ [pEVêDN6:c` XWv_Y '&)ygQo&Щ!eAA8^df-! ut.X.-ا!68L׌d"e\=T9nrCuNc +VHP (qҪ(-t^BܞP7itJx bdU2Q5Ki=?NmXȋY>N7`ܯ ޖuy#<'+Xdu#(aA߅Q̟?c/aB!n57[NU%׈e6` R ϑ>g[o.ڨ[ivmHFGWj)Ȥ) ΫY%65T!V[VLOk`J2]tMVGbBM%@aر-$yo*bV [&wy]72{m#/,"IWN爿Ok+Eb'sT ֚r[0?v"`6aqo!Q ZE .Ac7;o0Inܙzu]2u[}"K%LQԺ~Rd8A:9w)Gs1{0JøO9/T7 ҐP aMfv r|.LQ-<ַrbxeaøC6j˵5ʱmλ #Kttt$I(nUȣRn'e X} hf] b!6P`z6i_(Ra6chV[~RQA̮MfB;E*|Cu D0eY qjo8Kj x--}΋@ EXV6khCV]+Ėlrɟ oy.{eWoJ'~8D~Vjֱ GnDk 3* *p/B[%z؄zZMC8 Uk`+{Ι01}j?ON)ïJ rV;-%tUD݅L7׶6f vz]W.j%drõHau6Ԩ۔ ОD{kyPV}L:ى~D'2;*ׂvԐ*3}E 52,xH:hL掣B D֛t,}}ȶ (:ƨ1;M{CY7yY|pH@\VYάFSFJl +uT-7r .b,yGyMk>XH"ff&|PMXsl{/\cLm "sn~Ϥ/cVϛgEuB7eyKP=@ǤɆ)/-P,WJ7՗0kq\;7U{>Q_c؏:.n$puSykt(W)2.܄5 #jѡ:A*Dќ!+_ 7.2<52Mx/ڑ-4⊜ K_ %;'fq/ZTŨyJ.\V |Y:.^~2ei#ޘ0h;QC:rvfk>5և3|Z2 Ysr?}g%P!W+7"RgL/%qw xUs)?]Aдc9l52y7cjpk}djH:Q@Sx GO蟩5­/Аԯ ؔQ YZ