libdnssec8-3.1.4-bp153.2.6.1 4>$  Apaߝ!M@eeedLY/F@c)WG1Sz,jK>#qM*(qq<M}q=QFg5]⪮'a~>RQXr\)ph#hpȘPĄ#^cs2/("q!Vac*V}3T(yPJ[ܯln';`%O^ɭF9f-V$2RFT~sc%(e ˖cffa0da1a9b7de6af90322b796d41e5d89561599f297fca398bb6930861a7ebcfa40935587d62ac9e4c605d31d7a896693208dcd3aߝ!M@eeeG=NGr cUb6|TTŗp٤QSe㌪kG($]Wi(1#Ƶ<& =}qlֹ;iDgL< @US^:~ jx"rVLPݶJt;0my Vq*m ܯ\;/67#E_lɦǃFww#34eQ';+ȧz=jl(= yu'JA㈺5C &uE#lJ4 L>p@g?gd   EPT`d}     B X`jt(8898: U8>d*@d9FdHGd`HdhIdpXdtYd\d]d^dbdcedf(ef-ff0lf2ufHvfPwfxfyf zg$g4g8g>gClibdnssec83.1.4bp153.2.6.1DNSSEC support functions for Knot DNSKnot DNS is a DNS server. It implements only the authoritative domain name service. It uses a multi-threaded and mostly lock-free implementation and can operate non-stop during zone addition or removal. This package contains a library for DNSSEC support functions.aߍobs-arm-10SUSE Linux Enterprise 15openSUSEGPL-3.0-or-laterhttp://bugs.opensuse.orgSystem/Librarieshttps://www.knot-dns.cz/linuxaarch64aߋaߋc0e2aa87c348a33a626e5b464960296c62d40b6556ab86e253581a4d8c719d37libdnssec.so.8.0.0rootrootrootrootknot-3.1.4-bp153.2.6.1.src.rpmlibdnssec.so.8()(64bit)libdnssec8libdnssec8(aarch-64)@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfigld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.25)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3a@an@aD@a @a @`ݮ@`f@`@`q`_@`\{@`@`_@____^@@^@@^@@^@]\HW@\3?@\*[@[@[ݍ[IZ@Z@ZWQYYYXWDB@W1@VwV@V@V@V@VTQ@VCU6@U6@U@U&iU&iTTq@T@T@Tk4Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Jan Engelhardt Michal Hrusecky Jan Engelhardt Michal Hrusecky Michal Hrusecky pgajdos@suse.comMichal Hrusecky Marcus Rueckert Marcus Rueckert Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky pgajdos@suse.comMarcus Rueckert Marcus Rueckert Petr Gajdos Marcus Rueckert Marcus Rueckert Marcus Rueckert mrueckert@suse.dekbabioch@suse.commrueckert@suse.dei@marguerite.sumrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.detchvatal@suse.comondrej@sury.orgondrej@sury.orgpgajdos@suse.com- update to version 3.1.4, see: https://www.knot-dns.cz/2021-11-04-version-314.html- update to version 3.1.3, see: https://www.knot-dns.cz/2021-10-18-version-313.html- migrate to user creation via sysuser-tools - run spec-cleaner on spec file - update to version 3.1.2, see: https://www.knot-dns.cz/2021-09-08-version-312.html- update to version 3.1.1, see: https://www.knot-dns.cz/2021-08-10-version-311.html- update to version 3.1.0, see: https://www.knot-dns.cz/2021-08-02-version-310.html- update to version 3.0.7, see: https://www.knot-dns.cz/2021-06-16-version-307.html- make sure we have getent and groupadd/useradd in pre * added dependency on shadow and glibc * might be related to bnc#1186023- update to version 3.0.6, see: https://www.knot-dns.cz/2021-05-12-version-306.html- Make /etc/knot directory owned by knot - fix reload action- Update descriptions, remove unsubstantiated claims.- update to version 3.0.5, see: https://www.knot-dns.cz/2021-03-25-version-305.html - Update description based on homepage- Trim marketing wording from description. - Drop old rpm constructs.- version update to 3.0.4, see: https://www.knot-dns.cz/2021-01-20-version-304.html- add incompatibility warning about 1.6.X version when updateing - rename back to knot- version update to 3.0.3- version update to 2.9.7, see: https://www.knot-dns.cz/2020-08-31-version-296.html https://www.knot-dns.cz/2020-10-09-version-297.html - obsolete only pre-2.0 version- remove rosedb conditional as lmdb is required in general now- replace conflicts with Provides/Obsoletes- fix dependency: python-Sphinx -> python3-Sphinx- use upstream example config file with correct syntax- version update to 2.9.5 - Bugfixes - Old ZSK can be withdrawn too early during a ZSK rollover if maximum zone TTL is computed automatically - Server responds SERVFAIL to ANY queries on empty non-terminal nodes - Improvements - Also module onlinesign returns minimized responses to ANY queries - Linking against libcap-ng can be disabled via a configure option- version update to 2.9.4 see NEWS- version update to 2.9.2 see NEWS- update to 2.7.6 - Improvements - Zone status also shows when the zone load is scheduled - Server workers status also shows background workers utilization - Default control timeout for knotc was increased to 10 seconds - Pkg-config files contain auxiliary variable with library filename - Bugfixes - Configuration commit or server reload can drop some pending zone events - Nonempty zone journal is created even though it's disabled [#635] - Zone is completely re-signed during empty dynamic update processing - Server can crash when storing a big zone difference to the journal - Failed to link on FreeBSD 12 with Clang- update to 2.7.5 - Features: - Keymgr supports NSEC3 salt handling - Improvements: - Zone history in journal is dropped apon AXFR-like zone update - Libdnssec is no longer linked against libm #628 - Libdnssec is explicitly linked against libpthread if PKCS #11 enabled #629 - Better support for libknot packaging in Python - Manually generated KSK is 'ready' by default - Kdig supports '+timeout' as an alias for '+time' - Kdig supports '+nocomments' option - Kdig no longer prints empty lines between retries - Kdig returns failure if operations not successfully resolved [#632] - Fixed repeating of the 'KSK submission, waiting for confirmation' log - Various improvements in documentation, Dockerfile, and tests - Bugfixes: - Knotc fails to unset huge configuration section - Kjournalprint sometimes fails to display zone journal content - Improper timing of ZSK removal during ZSK rollover - Missing UTC time zone indication in the 'iso' keymgr list output - A race condition in the online signing module- update to 2.7.4 Features: - -------- - Added SNI configuration for TLS in kdig (Thanks to Alexander Schultz) Improvements: - ------------ - Added warning log when DNSSEC events not successfully scheduled - New semantic check on timer values in keymgr - DS query no longer asks other addresses if got a negative answer - Reintroduced 'rollover' configuration option for CDS/CDNSKEY publication - Extended logging for zone loading - Various documentation improvements Bugfixes: - -------- - Failed to import module configuration #613 - Improper Cflags value in libknot.pc if built with embedded LMDB #615 - IXFR doesn't fall back to AXFR if malformed reply - DNSSEC events not correctly scheduled for empty zone updates - During algorithm rollover old keys get removed before DS TTL expires #617 - Maximum zone's RRSIG TTL not considered during algorithm rollover #620- seems we no longer need jansson- limit geoip support to opensuse- update to 2.7.3 - Features: - New queryacl module for query access control - Configurable answer rrset rotation #612 - Configurable NSEC bitmap in online signing - Improvements: - Better error logging for KASP DB operations #601 - Some documentation improvements - Bugfixes: - Keymgr "list" output doesn't show key size for ECDSA algorithms #602 - Failed to link statically with embedded LMDB - Configuration commit causes zone reload for all zones - The statistics module overlooks TSIG record in a request - Improper processing of an AXFR-style-IXFR response consisting of one-record messages - Race condition in online signing during key rollover #600 - Server can crash if geoip module is enabled in the geo mode - changes from 2.7.2 - Improvements: - Keymgr list command displays also key size - Kjournalprint displays total occupied size in the debug mode - Server doesn't stop if failed to load a shared module from the module directory - Libraries libcap-ng, pthread, and dl are linked selectively if needed - Bugfixes: - Sometimes incorrect result from dnssec_nsec_bitmap_contains (libdnssec) - Server can crash when loading zone file difference and zone-in-journal is set - Incorrect treatment of specific queries in the module RRL - Failed to link module Cookies as a shared library - changes from 2.7.1 - Improvements: - Added zone wire size information to zone loading log message - Added debug log message for each unsuccessful remote address operation - Various improvements for packaging - Bugfixes: - Incompatible handling of RRSIG TTL value when creating a DNS message - Incorrect RRSIG TTL value in zone differences and knotc zone operation outputs - Default configure prefix is ignored - changes from 2.7.0 - Features: - New DNS Cookies module and related '+cookie' kdig option - New module for response tailoring according to client's subnet or geographic location - General EDNS Client Subnet support in the server - OSS-Fuzz integration (Thanks to Jonathan Foote) - New '+ednsopt' kdig option (Thanks to Jan Včelák) - Online Signing support for automatic key rollover - Non-normal file (e.g. pipe) loading support in zscanner #542 - Automatic SOA serial incrementation if non-empty zone difference - New zone file load option for ignoring zone file's SOA serial - New build-time option for alternative malloc specification - Structured logging for DNSSEC key submission event - Empty QNAME support in kdig - Improvements: - Various library and server optimizations - Reduced memory consumption of outgoing IXFR processing - Linux capabilities use overhaul #546 (Thanks to Robert Edmonds) - Online Signing properly signs delegations and CNAME records - CDS/CDNSKEY rrset is signed with KSK instead of ZSK - DNSSEC-related records are ignored when loading zone difference with signing enabled - Minimum allowed RSA key length was increased to 1024 - Bugfixes: - Possible uninitialized address buffer use in zscanner - Possible index overflow during multiline record parsing in zscanner - kdig +tls sometimes consumes 100 % CPU #561 - Single-Type Signing doesn't work with single ZSK key #566 - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - Compatibility: - Removed obsolete RRL configuration - Removed obsolete module names 'mod-online-sign' and 'mod-synth-record' - Removed obsolete 'ixfr-from-differences' configuration option - Removed old journal migration - Removed module rosedb - changes from 2.6.9 - Improvements: - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation - Bugfixes: - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - packaging changes: - enabled geoip module: new BR: pkgconfig(libmaxminddb) - enabled cookies module - enabled queryacl module- update to 2.6.8 - Features: - New 'import-pkcs11' command in keymgr - Improvements: - Unixtime serial policy mimics Bind – increment if lower #593 - Bugfixes: - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy [#589] - update to 2.6.7 - Features: - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) - Improvements: - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination - Bugfixes: - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback mode- Update to 2.6.6 - Features: - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation - Improvements: - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination - Bugfixes: - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- update to 2.6.5 - Features: - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set - Improvements: - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates - Bugfixes: - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations- update to 2.6.4 see /usr/share/doc/packages/knot2/NEWS- fix tmpfiles scriptlet- package /var/lib/knot - run tmpfiles scriptlet during install- update to 2.5.3 see /usr/share/doc/packages/knot2/NEWS - use libidn2 on TW and 42.3 - following modules stay static: - dnsproxy - onlinesign - moved modules to shared building: - dnstap - noudp - rosedb - rrl - stats - synthrecord - whoami- update to 2.4.1 see /usr/share/doc/packages/knot2/NEWS- update to 2.2.1 - Bugfixes: - Fix separate logging of server and zone events - Fix concurrent zone file flushing with many zones - Fix possible server crash with empty hostname on OpenWRT - Fix control timeout parsing in knotc - Fix "Environment maxreaders limit reached" error in knotc - Don't apply journal changes on modified zone file - Remove broken LTO option from configure script - Enable multiple zone names completion in interactive knotc - Set the TC flag in a response if a glue doesn't fit the response - Disallow server reload when there is an active configuration transaction - Improvements: - Distinguish unavailable zones from zones with zero serial in log messages - Log warning and error messages to standard error output in all utilities - Document tested PKCS #11 devices - Extended Python configuration interface- update to 2.2.0 - Bugfixes: - Fix build dependencies on FreeBSD - Fix query/response message type setting in dnstap module - Fix remote address retrieval from dnstap capture in kdig - Fix global modules execution for queries hitting existing zones - Fix execution of semantic checks after an IXFR transfer - Fix PKCS#11 support detection at build time - Fix kdig failure when the first AXFR message contains just the SOA record - Exclude non-authoritative types from NSEC/NSEC3 bitmap at a delegation - Mark PKCS#11 generated keys as sensitive (required by Luna SA) - Fix error when removing the only zone from the server - Don't abort knotc transaction when some check fails - Features: - URI and CAA resource record types support - RRL client address based white list - knotc interactive mode - Improvements: - Consistent IXFR error messages - Various fixes for better compatibility with PKCS#11 devices - Various keymgr user interface improvements - Better zone event scheduler performance with many zones - New server control interface - kdig uses local resolver if resolv.conf is empty - new BR libedit-devel for the interactive mode- update to 2.1.1 - Bugfixes: - DNSSEC: Allow import of duplicate private key into the KASP - DNSSEC: Avoid duplicate NSEC for Wildcard No Data answer - Fix server crash when an incomming transfer is in progress and reload is issued - Fix socket polling when configured with many interfaces and threads - Fix compilation against Nettle 3.2 - Improvements: - Select correct source address for UDP messages recieved on ANY address - Extend documentation of knotc commands - drop knot-2.1.0_pkcs11_check.patch- enable libcap-ng- fix configure check for pkcs11 support: adds knot-2.1.0_pkcs11_check.patch- fix soversions- update to 2.1.0 - Features: - Per-thread UDP socket binding using SO_REUSEPORT on Linux - Support for dynamic configuration database - DNSSEC: Support for cryptographic tokens via PKCS #11 interface - DNSSEC: Experimental support for online signing - Improvements: - Support for zone file name patterns - Configurable location of zone timer database - Non-blocking network operations and better timeout handling - Caching of Critical configuration values for better performance - Logging of ACL failures - RRL: Add rate-limit-slip zero support to drop all responses - RRL: Document behavior for different rate-limit-slip options - kdig: Warning instead of error on TSIG validation failure - Cleanup of support libraries interfaces (libknot, libzscanner, libdnssec) - Remove possibly insecure server control over a network socket - Remove implementation limit for the number of network interfaces - Bugfixes: - synth-record module: Fix application of default configuration options - TSIG: Allow compressed TSIG name when forwarding DDNS updates - Schedule zone bootstrap after slave zone fails to load from disk - avoid activating the intree copy of lmdb- update to 2.0.2 - Out-of-bound read in packet parser for malformed NAPTR records (LibFuzzer)- split out shared libraries, knot-resolver uses some of them and atm we are forced to install the whole knot2 package.- lmdb seems no longer optional- create a new branch for knot 2.x starting with 2.0.1 - Bugfixes: - Do not reload expired zones on 'knotc reload' and server startup - Fix rare race-condition in event scheduling causing delayed event execution - Fix skipping of non-authoritative nodes in NSEC proofs - Fix TC flag setting in RRL slipped answers - Disable domain name compression for root label - Log via journald only when running under systemd - Fix CNAME following when quering for NSEC RR type - Fix refreshing of DNSSEC signatures for zone keys - Fix binding an unavailable IPv6 address on Linux (IP_FREEBIND) - Fix infinite loop in knotc zonestatus and memstats - Fix memory leak in configuration on server shutdown - Fix broken dnsproxy module - Fix DNSSEC KASP timestamps parsing in strict POSIX environment - fix multi value parsing on big-endian - Adapt to Nettle 3 API break causing base64 decoding failures on big-endian - Features: - Add 'keymgr zone key ds' to show key's DS record - Add 'keymgr tsig generate' to generate TSIG keys - Add query module scoping to process either all queries or zone queries only - Add support for file name globbing in config file includes - Add 'request-edns-option' config option to add custom EDNS0 option into server initiated queries - Improvements: - Send minimal responses (remove NS from Authority section for NOERROR) - Update persistent timers only on shutdown for better performance - Allow change of RR TTL over DDNS - Documentation fixes, updates, and improvements in formatting - Install yparser and zscanner header files - Improve lookup of libsystemd build dependencies - Fix compilation warnings in endian conversion functions on OpenBSD - changes in knot 2.0.0 - Bugfixes: - Fix lost NOTIFY message if received during zone transfer - Disable fast zone parser when compiled in Clang (workaround for Clang bug) - kdig: Record correct dnstap SocketProtocol when retrying over TCP - kdig: Hide TSIG section with +noall - Do not set AA flag for AXFR/IXFR queries - Features: - DNSSEC: separate library, switch to GnuTLS, new utilities - DNSSEC: basic KASP support (generate initial keys, ZSK rollover) - Configuration: New text format in YAML, binary store in LMDB - Zone parser: Split long TXT/SPF strings into multiple strings - kdig: Add generic dump style option (+generic) - Try all master servers in multi-master environment - Improved remotes and ACLs (multiple addresses, multiple keys) - Basic support for zone file patterns (%s to substitute zone name) - Disable zone file synchronization by setting 'zonefile_sync' to '-1' - knsupdate: Add input prompt in interactive mode and 'quit' command - knsupdate: Allow TSIG algorithm specification in interactive prompt - Improvements: - Zone dump: Do not write class for SOA record (unified with other RR types) - Zone dump: Do not write master server address into the zone file - Documentation: Manual pages are included in HTML and PDF - drop patches which are included upstream: 0001-loosen-openssl-dependency.patch 0002-make-configure.ac-compatible-with-old-tools.patch - also drop all buildrequires just needed for autoreconf - new buildrequires: pkgconfig(gnutls) >= 3 pkgconfig(nettle) pkgconfig(jansson) - create devel subpackage - enable rosedb and bash completion- local state dir should be just /var- enable dnstap support for factory and newer: - new BR: protobuf-c and libfstrm-devel - prepared lto support but not enabled yet, still need to find out which distros support it- update to 1.6.3 - Performance drop for NSEC-signed zones - Proper handling of TCP short-writes - Out-of-bound read in zone parser for long domain names in origin (AFL fuzzer) - Out-of-bound read in packet parser for TSIG RR without RDATA (AFL fuzzer) - Out-of-bound read in packet parser for malformed NAPTR RR (AFL fuzzer) - CDS and CDNSKEY support in zone parser - Add defaults for TCP config options into documentation - Detailed error message if zone reload fails - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch- update to 1.6.2 - Limiting number of parallel TCP clients (max-tcp-clients config option) - Ignore refresh and transfer events on non-slave zones - Compilation with Dnstap support on FreeBSD - Possible file descriptor leak when terminating inactive TCP clients - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch - moved autoreconf -fi to %build so it wont be tried in quilt setup or similar tools - move up the %if case for systemd in for the preun scriptlet to avoid warning about empty scripts on non systemd distributions. - used xz tarball: new buildrequires xz- Add deps on the docu packages to regen documentation - Enable systemd integration fully - Add dep on libidn - Cleanup with spec-cleaner- Only require lmdb-devel on (Open)SUSE 13.2 and higher- Updated to 1.6.1 Bugfixes: - Journal file would sometimes outgrow its set limit - Fixed incompatibility with OpenSSL 0.9.8 - Proper handling when machine hostname cannot be retreived Features: - Support for DNSSEC Single Type Signing Scheme - Compile with lmdb-devel to add support for persistent timers- Updated to 1.6.0 Bugfixes: - Fix zone expiration when AXFR/IXFR is being refused by master - Fix forced zone refresh on slave (knotc refresh -f) - Persistent timers database opening after privileges has been dropped - DNSSEC: RFC compliant processing of letter case in RDATA domain names - EDNS: Return minimal error response for queries with unsupported version - EDNS: Fix interpretation of Extended RCODE Improvements: - Maximal size of persistent timers database increased from 10 MB to 100 MB - Added logging of persistent timers database errors Features: - Persistent timers for slave zones (expire, refresh, and flush)/sbin/ldconfig/sbin/ldconfigobs-arm-10 16363600773.1.4-bp153.2.6.13.1.4-bp153.2.6.1libdnssec.so.8libdnssec.so.8.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protectionobs://build.opensuse.org/openSUSE:Maintenance:17150/openSUSE_Backports_SLE-15-SP3_Update/7e783354187725acff3c96b1522f4e9e-knot.openSUSE_Backports_SLE-15-SP3_Updatecpioxz5aarch64-suse-linuxELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=b4be05928450f9de532e0ba47227c855e276d817, not stripped PRR RR RRRR RRǧGq1s-utf-805c3b0b64f1a63dddcec64730f1bb2c6cc25190889b4527fd0ba3aa9ceb360b8?7zXZ !t/K] cr$x#EjkO5}WN1ߗMuc^SX2X-`ݫ6˯jϬ,-zZHMٞ}C0iDJҧɹU(6Kp+K K?4^Kt1<6oOxO.8Ev" 8V[cՅQ9f5V} )hV<ޔRĿ)uWۊD$=;ړ R_0LJK-04-N S-yJ>ŚUAD;Y]k SK+5 Rn`[ W2;$<<.PwQ#bz0<|nr{ӨmC*/ߜ} lwB~Y\]z$9ϔ)iúH+a@0FA#z1_@ho# Aӹ2Z $IDl ͡q-;/$/-ohZq㲲5"DZ3<\UPNYtWg'< V3'6= Gy{&[ʐ(pLR#Cx&}&osj Ж[[B,;fNh]$l+XT[n?V 2GƠ"{HG]t!"-!Xaex"90̯{ 'V:D}̈́(L';?GR<R^䲩݋7+X~.akh>%4=E^ g2xFԙ*s w(4l…̏j&+O2o)rO<ZuFW&߄"Gm (wqu~=#/=ĝӐc6ijcb&^<ӏ\"@?sUH_.,]]aA[ CH]LܐOf 0㧤1P'^9/nt6X^/M{#\Ob7ƈwwb34 /* Pt(as@0ͩp~g@Һڣ͋]L(Dxsmu?m9jfekŸۨ*M+ߜIۡ;k/h 6@HakU @fb< НhR0?DvK"U9ϩ| hQ>k$%h"7pD(O%Ge{s2ԟbFb\+5.N`c7yxjJ!B__8 u^wVdWA4[\j\nM[OG<מӱLTŲ @cxVyfVO+ IP/={f%/IB&)Gh3wEU*W 9R Ez+FnH~Y o4' /M6vִX  ۹<-[@f -*A .4TmHa|ŏK犪jRפ֗DɢSlf15'"n9tmف1;_1dMm|!PHmCƭB# vkl mIV)^niqNE`%n6pПЀ&LWHӒvggՠs vАiֵs\ЊEOH ~j-h==3؆h<4Hb|!ZBt&! Z1M_E7k~Z&!Q|~^^] z9D~`0a@6:MPG-pr %Ȯͱ !4'ʜJd =3j9@.vESFĨIة~,FeoDKOK@-*E~ m9E+Nj<T^Wvf @34Ek4 q~V+=_FUSTov\5S:>vrf#7oB.&7 1/ʵ?jqq(ώwHy}h{*p?0cPV8\B7x}/V&D{icN@D. #I5HWVK v/:i.^_k6;x(z˫$c ;GI/y0FLcrB|^6-C#+큕{O2*b{Ԍ,HggC@iZ\ͯi#4r. ,#JRBΒ?M97bX%y1EKٓU8Zx? !+g1_ƩϤ#3|W)/eyx<  C%8h, c,q/Jj ]+t1ρ0>Du Q>;Fp,٩b|'F)6']*kI"κ9Ⱦ^XQZc}[zb@I`-WsoC"ƤCvkpD g :%1?ts~0!Fl5Ƶ)-;mspkru Rfe A`Z>T̢VifSyrԁIj" yʴ /3X^/S!qaq?[1mu:7hAAq=GB b9hhu-J; !c97%DdT1eҏZv1 b롭Buq%0'4->`ԸJbNoQ᜾1hY\] T ߆`%.fcMY`9mm4<0|(&7D$ TPPu\w=]{LqzsV̰B4@lGj<@-8lt#Y>gWjNԮlkr{` *26{z֦8x)h~[NQO d%2 ,qo_^ѵnrSEN$!:\Tsluk ,؂H ~SV *(9x"DeTImYeh͢zY ip -*)ΤH6%m5G5yl ͦ Ϝv7}_e86g^#]FOh76_b~-W|zA@ՂKeoG7"mARh[FC4Q5JǒBq8J1uEac"{)@1 b: %1"'G-l|cE D44B43;z*bϗVLD Ij$1bGfz Zj9^K@NbD;ڲ\Hd=O LO-˵ӷR+iqA?H Lk yXQR.2POG9SXtdt~+D|ʂ"xnXNuԈ̕ EHT{;ce-4C []#0ͱڞm3F`AlM=Cɲ O[ ˣ^n\h 68̴?j^97ژ9$"#K+oxmכU'Dc$U5X/阶ڝ+iUTR@=͉zꋒtZNql&wEr:ux닖Ų{[fB7r|xj^1Ͱ QGUo98)揨9CMFgGiD-:wǚg @,BBA$(fgt|%βS+E}>K63uZgHƺjO:"„U/RL:)ta"<-PZJn l;&)e_eb;0D@[oˡM@raz#t;бQr6mOdqd79i΀ /$5Vl{'QIbIq56jTb{[Z3jcٗmW  9oTgIX9FooRF:D=}Q;eĶ Y[F4fDA%r8'[ ӅqA;NƛdHHBs^XwRNNjR-PPV::zDߋiqc#t䉜\u?e7H@Y:T,%esER3A_`۴2/.Wg3COLY4R`>ut)fcJMY=BJeHaިU-iy26=Wn\[NMgpB׀#BbweU 9_N'r~dtS,Zv@2+i*ln权OXTQsJ*'Qkɬc8g3L4*ȣcS$yr_3y1H\Q{RGam#T.ݎtףOsjtӉ ta%P3wגdﯡ%-{1)i6](XR7 F[PEd voR1ЕJ[ tR[J)-%dQ[mXO^g&J:% iP~:t2Q|OWCGvg ك[YP/"$4̉D >@Hc$çFdDmZ)y|}x̢4?ʣv? U=ncwxFSM9 g4ұ\Q4j<Ԉ9%~Fp9՛܍cs9k 56ӣj6.YhUS_P,f%d4U\e oj lxÝhLAJiK^::(2?\{0Xo Ԁd _[>wEa0xn@LntX?1LdWH>X*6<apƚ;5ȡK}d&Ii~u͸>H/k۱dFJwyH;H? `%fHۆNE_ vhK Wp'aE5ļy* S=2^-Z,7Ԛͫ Gzxs\CoqdR4^ iO8,Y c r|2a롃U'%W# {C׬ ~ILrx{ŶCu&X b5(=Vm˨!҈HjqgCWa9t+ܫqUQӤt'5o[ Wb;܅*T~l]Y@g>+ @;\<{[O/y&bgW zvp2oEݷlvFkp<*x >1 #L[ V$;x.rȁ>8i*͍L#Q.,MȬKGClw/?2\ H[ ӈA@%F gn#c)XOy6~*u=KOD)hB.T?z~z>d@1B%!ě:X乴Fл/˽C1LUzUaJDVs;diLyc6j]LRhY/E#R.Žu=/IPΤLz"EF[L2x˴Q~c2r^6e0?͹f?Xb׹u18j};xjluъbPO -<렾`w YOljл .iMGPt>)M6&d2Lev8;8yUy+ 5ΏpiG07ShM" \C@f4 c u "%k!mSvKG-F !bSMEyY1IY/g6'" xNq/K8s)V&[u o|bR *kd [[Op>ʡC%&d_7-ßH_/{m]mwQO6J7Oԯcm's"Wky4/5Bq;_$ha~|*r8ݧf;]2? Tf(LnAPA]y_ygW=-}N%ǃ:G`-P:_ha:Hڇd(]zw sE!>2 ~O 5lIۉ SfS<983,ˈ]u%__ Ƚiv K~0 S|Hy hōS!Ia[6.3Mڶyb; CA;S*J>y| ׈+/$yKYV6$/LJ|:XYxhc  |[C$jV{47W_Q+/UJQCNH"& $2[4fhasB3ބqPȹI =n}~eUcfȄI|UvUI= :$گ:$ҊG'dk s/2WdcJ)hvYYPR=評ن'>ܬ~_6PTjE׷+ STdbwn{J3*y uZዤ#Єǃ5seL5i. f8,,?WΎ"$2,e2wt{dXHJ/”\ k/2'pA?d73[U׊?CZ AzGHc0[H5Α=?L7;T=^2n^u$Y >'Q94īZ*H uT+#tĐZZW1 Jw YZ$P=J_~Z&=m#"@Uyaȑi$z*.`S3}e{lI#P6Br^^@r00>Ql0t >yUh~bF_m߄ȅ kE iNj qTr)A4>R!pQ ʪ8H:zIJx!UWO^[,nv8,_fFɏqcIMO'·6&+ O`-+|ᗴyσ_kw+5;cd efTnKS]S٤UQW5kN BDpC aT64I _U\N;VQ#|rX -yiH/m哻~5寤)WgX {NT[.Ep(/=x@8l C CVQλS.(LM ~=<*Z<6P7RyY0`llEnFKuW>bӅ`P ^Tn.wAڲnIKa&[C18Aʝƛk8ؔc ^$J 2°{=@6@IMg/U@+ m^/jUe]gy2d_*JQ]U :m_g >g[QI Yi@a_=}#Z97ɗb9ϗ_k囥X֨:90X>^)IfLY?Vz/28~q|sh>[G>?f\3͹ԝlO!+L T3JK2`+bؐ.سޓZR973/6,tZcJch:h ,Θ5T8Ӓ<@-Sv[bq fg !S:NuJv%]= #*R?Cn caC66I+#Uȭt[EcZAA+$_=UJk:HUhRA3u m錑A˷ NPcܷ^D1'Sq*MjG%e!)~[mNy&Ox:8!|Zr6htܒ L@+ UoIqwCZ)2x $ E-p]=hAV6TDO%X{c;׹ɩZ{l2{\ YŨ^QMO{wF@ =y62_`TQƉ~(A=ŨSCYJ&_C@"Ouœo.Ke敦FV:Ĥ&f+BI3lPHToFE{9A!Y[0-P̝^ μ gE[M ӽ(fb~wEW^{EN6>lj ]NK#`s%`U`FGM\ 8VT҅_R(Lb>?it> ɯ,@2'O-FQu.69K'es-)F5!3< Đh1c {W:aT~{FFeyfi~5tѡ}R>F` ~'%R#8޴o+N-h){)kRsϘXe-)X'M :>.%@eG09u][Zii׋L^jVMPK_gk 9#-Pj'`a#@YVT"Ohh??Wb͋j^Ж;m|s}+v~@nߍZXZއ[a)([xW⟎=7cgT]3PpLkd?gBDer A+#eRj @]0A6+GtX -=5I%U1hP4.6?q*AiJ=&>4I^TqA4=7[Lr22w(DYrDU!|o2{wO$wv{mܡ2'*xpAW/q} S] TUU Z$vLGGc,* RGbkʐ>Ks(5mEw%P ]aC]rf<8`']ʂe:C(Nʦī\67BzN6'dTdnC)D!'otvI2 S;QYnZp<mLGcj10mI5 w$5/_s4`ڿ}ԫ[f[/Xt-kO2Z)8= |HX6^a&xz<3WB&ĈѩYZe@Gmc{#F؂Ċ,Ņ[di`%gu#Z xxX ?e:E/EW0Qo77皲 Il2&̗ihlm6nm@؄aI~r\4F/ө5M@14S"@*HEw~ڊV3W%:߂/ DIXɚ5 x]tn\yDY0Ϗ\䖨oۋh<-2ުI%T1ҪFTZ dӟχ "Xny/߸bG#jGJP)A0+:) ͚%W6 D\Qgߏ>A؜7ud|X2\1"3` 'vJBzhI>Q3򀿔ݡVC:tS{I Cz`g{i0 6'lMzR_Em8:Lv9RӼxfqM!z#;#P*Sݶ{3Դ^wd;&VS$Y湘X,p*>,(Py?v޽ԞɔM㖵sUCyL?,.Y؋+k€6t:vH]= |Lhlx$@`&|eބkZܗELڬ) j@#;HԝfkJfݢ6MY~3gF([0jvI$P;d>zI{憤~?t$G@Y"K- n|nXLkN!֬W{1K"k-YF,(( +RX{P~p""qQF;b/{(^oF iALD5+d{3ekz.[xi%_{ƅR.[^gq9a9Vx-AND#[R'M*ьA* ]$/,%u|4rϼɓeRfqi~0@O,6M9m%d~4RgۉJvn31{dnAsbߤi]dH=9"~J>O]r͐%Fc}eZ.%+p`M+Ɋ;ݶ'x\ W.#=eN\>%\`1bWde1Ah ,穏#ҡF' [NM$6ڞv/耶0$3I U3tݫ)J';7f#\OB) h{zUh9A4WqzP bÖKpiR-B~NP6Թ[8' 2Tt{Ҭ)'÷e KRAģsp~IW>)pwmQH~_Wq.\\:ec18FeK.[I#޿Xn6ELD|1<h>[0CJKV4y!zWp+s@؈0T |eY!ipQ1%S9ڳNټ!(RV`Hbwú΃<F˰׮Gy) `4vzK QmLBUwN ?ə97MпޥFAi#sܕm~T~zؔeX>N IC,Rg.f96U8[ɚUp.~+QU0y>LWAf>$zse5;E*o{b'W|"[ۤnf .LpO`|)aV*kp; MuM*I~1i96K+Sv6撨2{'bKùOI0:H0;%=@&kCJPniR }m[,\.i!@XӞ D_#=m) BV[jywH-Oϥg1Y`C Jh?e&dgS^b3K?-=-٥ڂiRP 9Ėcr1OfL'AH@L0g5Gc?myN.zY@r*O?b%}0>tՎ WKx =%ׂ uWվb28-ʦ-u{5Qh;nE[xOSݷ\G1J9c8Ls ڶ#gݩ TP0Y!})⽄b߯!sNd0hu+ T B p o8m+>hԚFӸʿ}ik mK"F_#a|f8t,, p Vw/ScDvpU=m'%qt NVneG#GzQ[C\1.{W H$d6R~ ˻9[Yèp+bnj -/7^7#W< } {O|c[0A6G*BwC`iFO kyҮnI;fl-V7UIg h ܤD$FV)I/i-r;a}ĵs8oU-ې@qc Uu6Y/)sƑe\ӹQc@qo38,E=;r:٩MYJg`y4jӄ.12j_`ιaJ.I\}?\/8I>~s}eUPCB?-VN^TM 3o2/oLzܟ8Q.$eJsėbM7^561AC^u+}kZS2K8д:^ )Β)s( @ԕkdQܺ_b(ю;*`''*"5gnU4w׵0 mWe x 9w:Ib =;5jmu?a̛Fp@PЕnxk.:׃ YqPA"Q%4P\ڐ+]ɲz*j0^[JFxOcpwi'তC=C R_',xn4+I_ed8'Cr#4:,eqrX>ЗOVU%"%,juZK[30Ǻhw ެ%h?#Rߓ< zE4O[cX7A)Q>LU0NwJ$=l-rfh2N.?PzA`C3R;տmB\B`: !ܻp?DV̧xӼP&Ĝ8>jlB{}:T{Gg27n,mm~ Qq*Պ~6=\&&\4h'zɰGlN7hۗ z#XAf`&*(˓=ۣ$Aκl-3IʦBMZ6<贠K@Ao{X?+N욋Yґ TvϑnNnW tl`˗oOTURpDa'N=h xI'YM7ɢ\DY|k|X5̈́|na~;f9XoOtOq?;JDqBL*=TlU7B{.e="񾕨k=G\n@WK|!:{6TbST+XRf,ì؜^Y1M8H;F[YTmPs9q{]` 4 4w(Oy膺*GJ&f)M0;ml8+.*{+>%s%*QW憬,6sQidf1X%* 'K>wnN!oZfZe?)h,^>P*oDW:27"SB֣%;uҽoƐ|)~vwՐ{خ.]b8Io(Kͳawʾ6)ĻP)טjqtW4DPCdU7x1E.S<]25~ u^-gщ4%*Ts;s0یuإ;L81R7A.>xqѩ"cDTHEoE;jr1Q6Z Nb='|`LYk؛h,ƛ{! T]mjȗX%.uN>P7l { A֜ѱ)&C7x6zCq Y(jcVlҟDxv/EʿxM}u0aM/R_ډ);\t V#xC`\l)k <;tWQ纉qטw;TT ҄m-ҩ|7'0!=EEzPn6D<3xqX*'F?ԢjʽnF~.o^\AKV :z8AR15:94-(hmrREO=TdHjql?{YqQ@ we+'c-Z ߳<%;1T,42hi5Y@}#k(BE>;7Qn:lv[hCgȷT:ɗ#פe7G+b+یd%+_cfsцYrfş,3UlY8@-EV(cfM2WrJ;Q9ϵO .?}+;alR<]eݼ6w037У2H).|]"!REn!RIͽ'>[)ÉR:OqN t RvC{Z E\pkLKh]]: ]Ec|eFMsc;nzzhj/R=["aSl,LI&n)qHZ&.m""jk m):r 3GYrsrS0G{5]\H36&ƏJ[嬏dw"¬wd,+@[ޫ\>pG/E/"4+S%&0(J^!/nZu2$ N5g,("`͔>&FHismc7$9ƞIH4c?iȬK;iE2sl(#ލ,3"~=!LVHUSRcjl)_eLq~p09 1 թBOk>p ~WH1.E RC_EDܲYf-@}Ss]^u)Pۃ<v'[c+vSW&d<6C0fOӲ@sF:u'|z?:|ht;L4KhO]U;w-yH=]wg }?8R~"vՉ@S'7p۔lLhrK]q' ZNEiRyGx6eE8=rWYLVbkL"p 8erB> V<<K 7 >k6cC3~[)y$tF ky?99.~IX$L"z3blg:,7ide|h^\6(Ea)S |k~k+^iStv{&}@Tw1MN@D N}[mR>Ys2^h/ќ]E^G~W)^e%ƴӜljZi96g-O*+;ii^Yc c"=Sr?|i nЩR|7_[CBi  k/M"1V&;ՊAȣX!v- i08P@e/-e#9~PdTMDzu%-MLzդ=H̸Vm<"~Ӛ5?۝uǣڳ4f9J0[Tf\Z紘QL92ft֔lgL9 0S)^`CGNP轥]y>$WE6V?RKxO{>N*Ӟji~4lL ʿҺb%iQ|s{X8c$yL]73Y[„<7zfr%)c䴚f0Z@8-?tZ1/dƤV.my0{TC$tb z,}x?l |dהUmQr/ߺ[N*-=xR3]wΝzT7haO7 rBA"D0oa0SZ\ua;cчɍF\ʯM-KڐUߒn1/>]\>p9+jfT hT+ǧТPB7VB&o Yq`: =!@G~b}0*)ɱLWcu7iS)(͹f8z"MlY^fLVP tmZZ+N{x DK'!éX0MYEU,mO sT_Q@Rp)οm#~{bj} X YΤ-\Iܴwgn#kW=˹{۞'Pbh`#ӥe׀NwYW rCtWK0GطZG.?LCkgI 8bc>XOð`b*4'Vy =iѧ  c}b۩Y*tV:+3E?:s R~%&(qtf&(+BQS/o{G*Q2AvzOg%<(7h Tq[hP ~q+}u_$AR|(.b3hя#Hr0k--ɭH0\xi6} S-ʟ~QPwMa[>fuԈ֧Ҵ`*U'YIqܓVѺ_Q]1}gٷ;ss`̷bX:GH+r7yer#q9Bq?u\3a׷%` XxoM2EfH>ڡуܠ,\jb:+p7\S""tfiW''g" >_i:cshϾg]Ug(_e$~Tu2LAOF,.Pk1G@'NdDI&`;%>=PPzAJM\/=|XA]QG;YRTpRh-8ݾL[~.*G, 3[z V6CNAR,ōGbmp0Gia%]3kc4W#pVoߺL4 m\ʑZDa/ -'~&ڽˑ!%jEW9 $cXb-@#k0bZ_LqaI7W&tbZӴv `xszqMG_AaNc.p|9 + ҿ۲\JDrY~Kn)7J0lEU7;VL-XQ=(fuKBzEj\p(͓h> >u'  ӢJJ\@Jh ЅT^6?jON{>;:.Bس)[qfÈ{DHѻAЈu~剿e? |hrGHi}(Clz U?yPH~e \B[b֔%ASIӻ nYj{/׶ FndK`Մ6S G3l0}QnF+Dvy! >w!+$2O՜ٯe%vC1^"bȧxq7;1 rc^v"odև+Mhg9$ъ̙kd/շ_p›% ^ QH1t6zX S=BI\ QVpd-\/k.[LRe'4ط3ckY2( 0U5ZJM'x?r/X[/&?^--ZC lߚI4400s1s1 xѱC|M㽖[!:U#BL hL 縊rp(axbS{1$1.m.25NCmF޼}vgƨ?UyE"?Xjdu`oӶPxJA1dOn{iWj9$ڗrk<`K. z)l"fR;X=8>LRrno(;^28T밇{۾&Yw9JI[&?Lɋ {1[w1!1P;(݀8$:oE`B\WK~1/_h[h6Ғ*"} ^V|tWtSCc{Y[/!&0M ؉^3b =LLLU#}RR1: RrMȜSU^h];-9ݣ;=l 3o1˳|V0S 9YaR[!J^YVIF4[ :E Q ]ݐTh6~a@:a =XInND_"Ro|DX P]}c2<)pX _|=)ݟzogcr/c9~ރ 6`R8%Fs-Elf#$=_7mJˋ{Qy!|{>[׫xRdmwU##?aNaS#cqp&>jz:l-J®yrZuxD4͜ao/n{ݢ0]%%vCwIW. `1,&dt1|"G)N@d\^=`{O1u5%.Jq Y6}_껷`lhXx~T; DD"V|tB$ž{0"pǤ]_GA\<kDo&e)ƟeO\f\_ВsħdJM/A˚q4~\m` P}ct~")/FJ ,H'(m(k3/[-E]PpؽHnޅWZ)/֦ҏtqBGA=#>dLkO+lYPQ8G6C.j~3|e(=_Z?SC.cΆ D ;q䨟^\82,_=󸿬グH+bO3C&hݓH+&2"z7_SO򞩣{vyLh۪@K`rcq7~8ˍijfnXWj7bFgK}u27k{Y: nwWRX-b؟ zIWަ@T*]\nޢ+O?ȵ+_a SmӨĨԿ#=v/Z.Ǖky0z:!,ǃjĈ2l\h Ȫu1CH6RЇ^:zԊi"m0U|5ss$`oKRȖ$ jQ +Q9FbY8}>ڔ4_Ws2>H8XTe?[/~NJ4kC3`8¦MK~f `*etW*p O~$-&B) 'c Z@hDFdڝzf" o[%=+VoքA:9$g}m FPM~Qpqm Rm5$R E?DZ9rXҞ`8N(=yWyuPX.COPfb ȋ.+3`{[sL lҕC4a9d Jo=z],zhԋҾvCL&Dh˯B7O-I߬hfE}dSQu0WVj)[aWN&yI-LOz%vGDiҘ&v{C6]cQS^$ebw W-<|LGۗV<*u6Yjc0RKAqEFnO٠Qܻ=g V&hu%~z~܄1f{>CB ϊ[}r/bWAScS,IdcaRs* V Q0TYzyQ@5B: ;@k&|еk<9(oΠaUVvDhV:!gebA7%GքdyTz_u#֙U ]֜<2TGZ&nSR 2}K*Nvûk*VaD#\g1$ O %¾B<85נ3y.K:wdg# 4%⠺=FG+Au:î0j{܆v.A89eʉϺ3O!֩KMʇeA˃tߡSx|4Y&dkÔ9Xnlml x8U⾻?~ŕUϳGT~[#XZG\%k2Z"fjZm6YI4"j͝VYrqxg5LQa'tzt^B%71,uؕ(}vmjU1m E8I+~3'qc wU|i: g?=<:nexU~yEQR5KəO&J9gzne΍|B)5Tѷ2D5?(m]!Ux:hU-`Q(S%B+_z ?As$SJҞ"qʨv#,Ç`X,Kw"1ۄgh]2`C#0Y~e٢u"cÀ髣gc/ j&hM*n$jHT)IL-*.5v.lHOZS F[Oޮn#axI0Iza«FXulDaqnk]E}_^GIWa6KΞLp[LRɄ{) Yv)/ZjockL0M~' pv"|xǢ.\\ 61rKOtASfNvc~MT8]zUZ»vAɕp(Z*HΪ5ب*y'y%#Vy*+= j*]"ҫQ |n(Rn@W`k ~6sjсd)|$3tF=sF”PR[RzF$z+l*|aӵ^4M_WŽrWH0׌pɑz{vGB{RU ؿ_I$cA-EAn#_PRف c%7B(trP4OW{(27!:NE$n`vl$qY<)rn<,flnE£j0h0R2SQϮdU &a`dNˤ0[zg[V{#%ps~%E3K}Li?̈JzbjyfDɚ߻Y҂7 2<P̬EEPdYJؿ@:퐈Gz- TMP6B #02h%i gRҩytE^Z:[^,^5N_-\9:vI[r~{NѠ znDw$ 5`h&-mHF-:[d*uۃDaNJ߉PH+ueS2!WXWf[w AӿH=.dL V.<+pU˯qTE#% xGzoxxAv].畨J¦2cȥ#D üme( )z:Sm#h L,er_I+)ņdyn(sWn8˶K'tn3M}8>-] m7ۇkFVsܵp;N~oG3LDYZov> P6,&7Zc^Hda-xw{_ګ"4 6&fq>uUTL G&Z` dO͊ˈZ^GR峣Å \9Ź#&*Ob&Uj3$}${$\G֡n8*|1i6+楁XmA*$w2US,_0s ?恑m Y:Nxz1gSJF_Je枲`sdE1jV{YxkOW<̕=åj7F^Br0^h|xϒH ɀw"'h+?p{TD<&DʯCn[ޣzx6ڟax"pBƼ;^Rǣ|ڕ݆Z3rY-Ëwxq;h3}/1Mb]߲vcOo2)HsQQ^$ooW&qO/ӑ~8Zl:c^^΄bCDfAiyP?c8%2%4Vs&7v=ˌzGzЫڙ;r(M:Tt!@[L&iy c,QzV$"up.s7\و+nC/5֡ )jԲ~V#(<{8\ SV+L1u9B]&pؽZ;:3V8HBkA;K\)(q?3nx8Q\Y5nO,7MΡ!ngB>)w޹1,RhBSAWʎ5؟͹5PNHlIMEҜ Zt Ԧʭu[On^{*/:6+F#&IDjk% 5*vX4$2ePd=+JU3Vk",5b>bK18}10ٲm.L+|l05T.xZ6y`DmʖO8?nn|p#-adǖCflI} ZE"uABEmVJ(5BS}/[]wu4g}|\  \Y, Jϴwi9hH!?7aMa<ՍFnz ,w3[#0w Xr dRw+>Cayޫ{T3dF>zB?DaP (`}TxH$/~n` hSޥY3V(``Tm9M-zAS NISHxjX್keRze U7Ԥb9Ȍfɐ 'ާ'x@!KhZ2Ckwn fNz4`c{`mWr:XrU33AZ"]:#5Yv(ނSbt㾹q#[UmbEP8J} Zϰ)1ɀ7M! J*#!U`X' iU"~# &T.Ukt(Jh%z*@tO;ug_|2׬/)n6T)J#bfd--&*K{VeB-= ݷTa/S]I)M :! JiI_OjkӋ"c!LsI} EH)PBeDAbJ*i?!zRBl2<W%]`\.Rl[=H;X )v3qrD>Drv&0[u8}uI^ʚ\F,GvDOVwx\|6qc6T!mCEr[%k2%D.{OÃV:cd %^!9Kڌr2vSL|ͅ&nkX ɮlwsrA:7i1M݉) :iiuI?qGH;͙-6֒i訒&ݳ0{Wvo6i~Q,>~Kt=KKNneLz74['rxJSu ,ܩ7|WdVFL~L~&ci:BI* x S_~q퐤M^-āeʬ2.%-gS z҂ڧ3 E\,'(+,J}X\RTgK.3#:ۭ묞Dx$ed~=dX(Lrmف=* fʙeZ#הK&Yeֻ<سrXú/C↲ѭuzr]:/&ѻ@܉'hjS#0? "?| BEi耼Nao9瓏MǸPdmSW + +yOeQrP4W[fLrߙ-v]ڙ Jap:$;-kM,U. T|Prp}(h7*d; B_4d6s@&£ޏ! ,=xBzuZ_ YOlDoJ/$TЗ.g5`qd)w|8GJs Ρ3Xe# TF}*-z,ԉn´Om(H~4k1vb̟F2ʸaBq^ È48ͭ>ߛіM6;Ez"l⿕*x1qm!T_DGI +γ|YS֢s&DZq.ʫa!9H OgFPR'¥,'ݕ +N%^E-S[B!qItgvyTeL׏JYvĺ#d"/?_1dn͑zPU-HF -d}N0fQW<[\GAM/1ުz% ~??\8+E> ۻiD|e368ϒyN SSGuPZءO'4:b+2(f2oNWiPKX.{:FB<ʣ2UϛRE{oMGA޵X`\+=~t[9ΧsoNΑ}Jb[;ϋ\R ue?ΩPLɯ#sYedݮU$}0HYXiu6Gu 0gfF}иm, ή;qi3qt=m"I>mp/ '+++̈́XLkqq%r$1l9k}<ǎuGhhJ\OCĈ4{m8=,TDjEvlg]|P\jr@*i8| Wx2iaɜ y58e{^CYk5A"٣ 򴲟\.]gr!q#0khv؍NC}c~X#5ɠ$!mrp*5ZFLCphe9Q 2+KlQ':E'= Wև@=G7 z+=QҬ13o`ں2N89n=vtir\;q2M:ⶤ{a@5ђRv}IK w9@}{eٮjTKQjIrf*mWDWgbeS^* uR[~k֦ScP,_ңli6T.VAGc*ܷI;Ytgβ6\MI@<2MVE`ǀ",K(7Vr hΧ<3"/Guj3dnG]YA_D>m0ݩΊKbt^kn353s4k҄ObϿ|)ŗn͏̇Ә#V}:1]x˛<\ a{vI@ '7p-`**M0O޶TM>sKddθEn~ osfKHcO%&ԍn/v==|P#Ï~m-Pnoőtd\[c-GTxaκbnD}`Q.Y[׽ s#( >ξ;hp˾(F)ً֩J&E?fɉO&a߈8cE&KZo|L^tN+℔Ư cW U- ,n@.ސ%QRD+돨>Z'0!NU'vH.[H;Y;=oXD&}W {ŠY8-V@R2[QtRialq݈OfqZz׳#g H%V @Es"35Ep3YՃ^\.omy!Gw+*Ϗ?]vsdTP-w{{snqFEi#Az_Hлw,<نB8#5qjM#./O⭓ * xTmHM%im;vfjXDq$^O3}H,ܽC2|bl  m!ے7޸qo#v*q.q$cXwYSκCF)-`3{ipBX>5h08 !O–pimV#R ixe,-K6MQ?F1'c7͕ F7WtoD$Eϰ6 G8s-=q9~NqH+(xt\!ctJ8{XvʼnQ$C<CboFBX#?)܇sTֱܟzh)ݣI/EӊH cJ/wՁrNB/~|&I(pr",B{I(sEׂwfE3@M9I %lCdzrKy8P6GSy-Ä<{e 8KFpY5@<8Ҟ\ Z6-8Z,jƕ>0TVZ=]y&Wö&NdjT+S\`@iA]K#qZ/,&2:Jn2$DcD=YhY%.8<-QEj>H# pނk)uI5wnĮЧ#rg(Oz`>aUtBc-ܐxQڗY_T<0^`;e! c9M9 JE;5 5#/a;rA5CͻsRcғ(L*b>6<eM\ʭZݱr^5/zLnpą3R%#AE' @tkWIxzɨs?SYBZ㞕xVVT[\qYή2 7?1yDf =bfd`@X>9_LՉpֽm㛊)j[T,Tkz-WRMͭrF){YӔIlklf=|5PM/2;S/r5+>lM2x~^^cSt{&1e ,[@<-$BO 8X\ᤊjC_i} ֧:x+ |֜Q ]~vI^ͺɢ2XE} 녂rT]EpRf핀 f>ʍ N~wSٰdC0O,mlBN{hXґǎ+56*!( Y`b⩌ @ #BٔM ^A ) ucjވdCPտx/w7V:@^habfMRVh—Ey'%22 hsrOA2J*K7 X7Μن8M'ʙʱ]D`[q#.O />dE- "3S8> d;2ֿALA4@Z?hSm%$h3ioagE+Թ~ aBY}'qK"@ot9|8èk/ X#K[ah^=9oi0.`{1DvWJz%wk̊ͺ">MxC%% ;gh0<i|yQ$lU0&΅矢 .#xvF,vEA o.P)1֑# Z"uԳsYt?GmQ@FFc/p&0e1tDΛ [F&йgs$ 4B gڑ ɤ#EڙM0 Ai{ߦ$]#A/Plrr9zc xjN^kWG@kx*)װzA$ (i9\yH0zFGYA=6tMIn/ACB|zpD/b.s/JK:&q4Dt1 :_quM"h{;vo'C(k_9Kʽ(HNt)/\= ĚC]WmbYPaVj~S>v鱈Ǝ? wUw/SٔI[Q9ϐKA2"#,M[ֱ)_{wlyYog{=8S&'\Z-sC'qQx<`$u2 ҂%ZD`;GKJy)xrw5uc8Gr[*y_F;BgQEU} yܜtIUdbٻٍ3noV+JQf0j&F (:)DaO-kJԅ,H1@xe 6y36%SbR^_m5gJпRպu0- dJ輷Lv Ӯ\ɓpO/nf|yg!;=ELn\Jlyul.9hMfwkrZQ"3"xK.T?I0ZM2=I]%)5g* I4wafҽKE 5V^2B9Y8g=͊.{,ZEyݷLlHӤduzBPWneӡX 150v Ef(dO1Tj$RUAeGJ0~%{>E+ED b9\AEgY/%7^$ q'<͡ ̩sαO>r|J'n M_l5&֔O;EfN%1,3Qj#IB-d 7Z%658>KZ$R}"UTހ\q\$Oo3Ix)o4\Nc!KXwg{ϴ"Ņ U~&,% b7M&fyPDJ':溻‚4ZjpQhAi; !r LI 7ZB6Y, $`zW. ^Ӑ?k> |mX7.T6,iz#o%9fL) |&FhNuZ19hӠS1ʞx!X LUg|φ),85#Ͷ./-"ƏvLjײzf yi.gZhO8 ZV DJ,Ͷޘ CULxX^h"#P; >Ựt&X9V`@;W-lվ.bw=IdǠ]sܕnlZƧ(lqz35v!1oŬޱ)wn̶tZPa!RI 5{Zt>9x;'G6U`2Š5-,yh 3 $* SŅz] Z__Ĩu*ݖ94VAc%B(ICD)|`MиɁf`n{s)Zg;G(C$:JLw* 1% R%(%ҁ6"zgc$OLYu> !߅ͣ5S*:{P-np4l$A1ji'KЩYp,[7 ܪU^P&QxjV"&UXu"Ȅ谪hG%c{ㄲ)B]/J%.£>*ۍz:Vᡅ~ٽA 5MxfƗ cC#|R]%Zl;ʩSb$ ͺ0cnvBR)MURb1;9^K%'_q+̮ [~ YZ