libdnssec8-3.1.2-bp153.2.3.2 4>$  ApaV8!M@eeeh?p&˴+Yd85L‘R|Eтf Fv/GbD9y^.H<9"5TPڝUf$vZ=.B zȞ99[r,]!?mL5) PNsEPM8g6ؿ k?4k Wn7>ϾRՈŠ>( 7cRwIhϢ$VՈau؞ԅZc ue$P3da6672fd713efe7a472713d5383fe9f9f6af92c3ea7dd5036e3c6f9c1d9242571a40a9404b7983ca3be66af3b8f2e43b757122cMaV8!M@eeem̼:;Ly,[s; 6?sK+IïJei|X JiqЮ Y 9nlx݌{tBLQ4ng,ԷR=a2#vK@ր@w+fsd.X-}ۛ$Qv= $8ӳ5l>p@gl?g\d   EPT`d}     B X`jt4q(8696: 6>c@cFcGdHdIdXdYd \dH]dP^drbd|ce7deeefeleuevfwfxfyfzfg gggXClibdnssec83.1.2bp153.2.3.2DNSSEC support functions for Knot DNSKnot DNS is a DNS server. It implements only the authoritative domain name service. It uses a multi-threaded and mostly lock-free implementation and can operate non-stop during zone addition or removal. This package contains a library for DNSSEC support functions.aV#cloud105jpSUSE Linux Enterprise 15openSUSEGPL-3.0-or-laterhttp://bugs.opensuse.orgSystem/Librarieshttps://www.knot-dns.cz/linuxi586jpaVaV98f92046cff586177e26355b0a49e8e3a5b9dc7e285a74f3c4369bfef042b8bflibdnssec.so.8.0.0rootrootrootrootknot-3.1.2-bp153.2.3.2.src.rpmlibdnssec.so.8libdnssec8libdnssec8(x86-32)@@@@@@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.1.3)libc.so.6(GLIBC_2.10)libc.so.6(GLIBC_2.17)libc.so.6(GLIBC_2.25)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.7)libc.so.6(GLIBC_2.8)libgnutls.so.30libgnutls.so.30(GNUTLS_3_4)libgnutls.so.30(GNUTLS_3_6_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.1)libpthread.so.0(GLIBC_2.3.2)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1aD@a @a @`ݮ@`f@`@`q`_@`\{@`@`_@____^@@^@@^@@^@]\HW@\3?@\*[@[@[ݍ[IZ@Z@ZWQYYYXWDB@W1@VwV@V@V@V@VTQ@VCU6@U6@U@U&iU&iTTq@T@T@Tk4Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Jan Engelhardt Michal Hrusecky Jan Engelhardt Michal Hrusecky Michal Hrusecky pgajdos@suse.comMichal Hrusecky Marcus Rueckert Marcus Rueckert Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky pgajdos@suse.comMarcus Rueckert Marcus Rueckert Petr Gajdos Marcus Rueckert Marcus Rueckert Marcus Rueckert mrueckert@suse.dekbabioch@suse.commrueckert@suse.dei@marguerite.sumrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.detchvatal@suse.comondrej@sury.orgondrej@sury.orgpgajdos@suse.com- migrate to user creation via sysuser-tools - run spec-cleaner on spec file - update to version 3.1.2, see: https://www.knot-dns.cz/2021-09-08-version-312.html- update to version 3.1.1, see: https://www.knot-dns.cz/2021-08-10-version-311.html- update to version 3.1.0, see: https://www.knot-dns.cz/2021-08-02-version-310.html- update to version 3.0.7, see: https://www.knot-dns.cz/2021-06-16-version-307.html- make sure we have getent and groupadd/useradd in pre * added dependency on shadow and glibc * might be related to bnc#1186023- update to version 3.0.6, see: https://www.knot-dns.cz/2021-05-12-version-306.html- Make /etc/knot directory owned by knot - fix reload action- Update descriptions, remove unsubstantiated claims.- update to version 3.0.5, see: https://www.knot-dns.cz/2021-03-25-version-305.html - Update description based on homepage- Trim marketing wording from description. - Drop old rpm constructs.- version update to 3.0.4, see: https://www.knot-dns.cz/2021-01-20-version-304.html- add incompatibility warning about 1.6.X version when updateing - rename back to knot- version update to 3.0.3- version update to 2.9.7, see: https://www.knot-dns.cz/2020-08-31-version-296.html https://www.knot-dns.cz/2020-10-09-version-297.html - obsolete only pre-2.0 version- remove rosedb conditional as lmdb is required in general now- replace conflicts with Provides/Obsoletes- fix dependency: python-Sphinx -> python3-Sphinx- use upstream example config file with correct syntax- version update to 2.9.5 - Bugfixes - Old ZSK can be withdrawn too early during a ZSK rollover if maximum zone TTL is computed automatically - Server responds SERVFAIL to ANY queries on empty non-terminal nodes - Improvements - Also module onlinesign returns minimized responses to ANY queries - Linking against libcap-ng can be disabled via a configure option- version update to 2.9.4 see NEWS- version update to 2.9.2 see NEWS- update to 2.7.6 - Improvements - Zone status also shows when the zone load is scheduled - Server workers status also shows background workers utilization - Default control timeout for knotc was increased to 10 seconds - Pkg-config files contain auxiliary variable with library filename - Bugfixes - Configuration commit or server reload can drop some pending zone events - Nonempty zone journal is created even though it's disabled [#635] - Zone is completely re-signed during empty dynamic update processing - Server can crash when storing a big zone difference to the journal - Failed to link on FreeBSD 12 with Clang- update to 2.7.5 - Features: - Keymgr supports NSEC3 salt handling - Improvements: - Zone history in journal is dropped apon AXFR-like zone update - Libdnssec is no longer linked against libm #628 - Libdnssec is explicitly linked against libpthread if PKCS #11 enabled #629 - Better support for libknot packaging in Python - Manually generated KSK is 'ready' by default - Kdig supports '+timeout' as an alias for '+time' - Kdig supports '+nocomments' option - Kdig no longer prints empty lines between retries - Kdig returns failure if operations not successfully resolved [#632] - Fixed repeating of the 'KSK submission, waiting for confirmation' log - Various improvements in documentation, Dockerfile, and tests - Bugfixes: - Knotc fails to unset huge configuration section - Kjournalprint sometimes fails to display zone journal content - Improper timing of ZSK removal during ZSK rollover - Missing UTC time zone indication in the 'iso' keymgr list output - A race condition in the online signing module- update to 2.7.4 Features: - -------- - Added SNI configuration for TLS in kdig (Thanks to Alexander Schultz) Improvements: - ------------ - Added warning log when DNSSEC events not successfully scheduled - New semantic check on timer values in keymgr - DS query no longer asks other addresses if got a negative answer - Reintroduced 'rollover' configuration option for CDS/CDNSKEY publication - Extended logging for zone loading - Various documentation improvements Bugfixes: - -------- - Failed to import module configuration #613 - Improper Cflags value in libknot.pc if built with embedded LMDB #615 - IXFR doesn't fall back to AXFR if malformed reply - DNSSEC events not correctly scheduled for empty zone updates - During algorithm rollover old keys get removed before DS TTL expires #617 - Maximum zone's RRSIG TTL not considered during algorithm rollover #620- seems we no longer need jansson- limit geoip support to opensuse- update to 2.7.3 - Features: - New queryacl module for query access control - Configurable answer rrset rotation #612 - Configurable NSEC bitmap in online signing - Improvements: - Better error logging for KASP DB operations #601 - Some documentation improvements - Bugfixes: - Keymgr "list" output doesn't show key size for ECDSA algorithms #602 - Failed to link statically with embedded LMDB - Configuration commit causes zone reload for all zones - The statistics module overlooks TSIG record in a request - Improper processing of an AXFR-style-IXFR response consisting of one-record messages - Race condition in online signing during key rollover #600 - Server can crash if geoip module is enabled in the geo mode - changes from 2.7.2 - Improvements: - Keymgr list command displays also key size - Kjournalprint displays total occupied size in the debug mode - Server doesn't stop if failed to load a shared module from the module directory - Libraries libcap-ng, pthread, and dl are linked selectively if needed - Bugfixes: - Sometimes incorrect result from dnssec_nsec_bitmap_contains (libdnssec) - Server can crash when loading zone file difference and zone-in-journal is set - Incorrect treatment of specific queries in the module RRL - Failed to link module Cookies as a shared library - changes from 2.7.1 - Improvements: - Added zone wire size information to zone loading log message - Added debug log message for each unsuccessful remote address operation - Various improvements for packaging - Bugfixes: - Incompatible handling of RRSIG TTL value when creating a DNS message - Incorrect RRSIG TTL value in zone differences and knotc zone operation outputs - Default configure prefix is ignored - changes from 2.7.0 - Features: - New DNS Cookies module and related '+cookie' kdig option - New module for response tailoring according to client's subnet or geographic location - General EDNS Client Subnet support in the server - OSS-Fuzz integration (Thanks to Jonathan Foote) - New '+ednsopt' kdig option (Thanks to Jan Včelák) - Online Signing support for automatic key rollover - Non-normal file (e.g. pipe) loading support in zscanner #542 - Automatic SOA serial incrementation if non-empty zone difference - New zone file load option for ignoring zone file's SOA serial - New build-time option for alternative malloc specification - Structured logging for DNSSEC key submission event - Empty QNAME support in kdig - Improvements: - Various library and server optimizations - Reduced memory consumption of outgoing IXFR processing - Linux capabilities use overhaul #546 (Thanks to Robert Edmonds) - Online Signing properly signs delegations and CNAME records - CDS/CDNSKEY rrset is signed with KSK instead of ZSK - DNSSEC-related records are ignored when loading zone difference with signing enabled - Minimum allowed RSA key length was increased to 1024 - Bugfixes: - Possible uninitialized address buffer use in zscanner - Possible index overflow during multiline record parsing in zscanner - kdig +tls sometimes consumes 100 % CPU #561 - Single-Type Signing doesn't work with single ZSK key #566 - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - Compatibility: - Removed obsolete RRL configuration - Removed obsolete module names 'mod-online-sign' and 'mod-synth-record' - Removed obsolete 'ixfr-from-differences' configuration option - Removed old journal migration - Removed module rosedb - changes from 2.6.9 - Improvements: - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation - Bugfixes: - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - packaging changes: - enabled geoip module: new BR: pkgconfig(libmaxminddb) - enabled cookies module - enabled queryacl module- update to 2.6.8 - Features: - New 'import-pkcs11' command in keymgr - Improvements: - Unixtime serial policy mimics Bind – increment if lower #593 - Bugfixes: - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy [#589] - update to 2.6.7 - Features: - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) - Improvements: - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination - Bugfixes: - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback mode- Update to 2.6.6 - Features: - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation - Improvements: - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination - Bugfixes: - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- update to 2.6.5 - Features: - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set - Improvements: - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates - Bugfixes: - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations- update to 2.6.4 see /usr/share/doc/packages/knot2/NEWS- fix tmpfiles scriptlet- package /var/lib/knot - run tmpfiles scriptlet during install- update to 2.5.3 see /usr/share/doc/packages/knot2/NEWS - use libidn2 on TW and 42.3 - following modules stay static: - dnsproxy - onlinesign - moved modules to shared building: - dnstap - noudp - rosedb - rrl - stats - synthrecord - whoami- update to 2.4.1 see /usr/share/doc/packages/knot2/NEWS- update to 2.2.1 - Bugfixes: - Fix separate logging of server and zone events - Fix concurrent zone file flushing with many zones - Fix possible server crash with empty hostname on OpenWRT - Fix control timeout parsing in knotc - Fix "Environment maxreaders limit reached" error in knotc - Don't apply journal changes on modified zone file - Remove broken LTO option from configure script - Enable multiple zone names completion in interactive knotc - Set the TC flag in a response if a glue doesn't fit the response - Disallow server reload when there is an active configuration transaction - Improvements: - Distinguish unavailable zones from zones with zero serial in log messages - Log warning and error messages to standard error output in all utilities - Document tested PKCS #11 devices - Extended Python configuration interface- update to 2.2.0 - Bugfixes: - Fix build dependencies on FreeBSD - Fix query/response message type setting in dnstap module - Fix remote address retrieval from dnstap capture in kdig - Fix global modules execution for queries hitting existing zones - Fix execution of semantic checks after an IXFR transfer - Fix PKCS#11 support detection at build time - Fix kdig failure when the first AXFR message contains just the SOA record - Exclude non-authoritative types from NSEC/NSEC3 bitmap at a delegation - Mark PKCS#11 generated keys as sensitive (required by Luna SA) - Fix error when removing the only zone from the server - Don't abort knotc transaction when some check fails - Features: - URI and CAA resource record types support - RRL client address based white list - knotc interactive mode - Improvements: - Consistent IXFR error messages - Various fixes for better compatibility with PKCS#11 devices - Various keymgr user interface improvements - Better zone event scheduler performance with many zones - New server control interface - kdig uses local resolver if resolv.conf is empty - new BR libedit-devel for the interactive mode- update to 2.1.1 - Bugfixes: - DNSSEC: Allow import of duplicate private key into the KASP - DNSSEC: Avoid duplicate NSEC for Wildcard No Data answer - Fix server crash when an incomming transfer is in progress and reload is issued - Fix socket polling when configured with many interfaces and threads - Fix compilation against Nettle 3.2 - Improvements: - Select correct source address for UDP messages recieved on ANY address - Extend documentation of knotc commands - drop knot-2.1.0_pkcs11_check.patch- enable libcap-ng- fix configure check for pkcs11 support: adds knot-2.1.0_pkcs11_check.patch- fix soversions- update to 2.1.0 - Features: - Per-thread UDP socket binding using SO_REUSEPORT on Linux - Support for dynamic configuration database - DNSSEC: Support for cryptographic tokens via PKCS #11 interface - DNSSEC: Experimental support for online signing - Improvements: - Support for zone file name patterns - Configurable location of zone timer database - Non-blocking network operations and better timeout handling - Caching of Critical configuration values for better performance - Logging of ACL failures - RRL: Add rate-limit-slip zero support to drop all responses - RRL: Document behavior for different rate-limit-slip options - kdig: Warning instead of error on TSIG validation failure - Cleanup of support libraries interfaces (libknot, libzscanner, libdnssec) - Remove possibly insecure server control over a network socket - Remove implementation limit for the number of network interfaces - Bugfixes: - synth-record module: Fix application of default configuration options - TSIG: Allow compressed TSIG name when forwarding DDNS updates - Schedule zone bootstrap after slave zone fails to load from disk - avoid activating the intree copy of lmdb- update to 2.0.2 - Out-of-bound read in packet parser for malformed NAPTR records (LibFuzzer)- split out shared libraries, knot-resolver uses some of them and atm we are forced to install the whole knot2 package.- lmdb seems no longer optional- create a new branch for knot 2.x starting with 2.0.1 - Bugfixes: - Do not reload expired zones on 'knotc reload' and server startup - Fix rare race-condition in event scheduling causing delayed event execution - Fix skipping of non-authoritative nodes in NSEC proofs - Fix TC flag setting in RRL slipped answers - Disable domain name compression for root label - Log via journald only when running under systemd - Fix CNAME following when quering for NSEC RR type - Fix refreshing of DNSSEC signatures for zone keys - Fix binding an unavailable IPv6 address on Linux (IP_FREEBIND) - Fix infinite loop in knotc zonestatus and memstats - Fix memory leak in configuration on server shutdown - Fix broken dnsproxy module - Fix DNSSEC KASP timestamps parsing in strict POSIX environment - fix multi value parsing on big-endian - Adapt to Nettle 3 API break causing base64 decoding failures on big-endian - Features: - Add 'keymgr zone key ds' to show key's DS record - Add 'keymgr tsig generate' to generate TSIG keys - Add query module scoping to process either all queries or zone queries only - Add support for file name globbing in config file includes - Add 'request-edns-option' config option to add custom EDNS0 option into server initiated queries - Improvements: - Send minimal responses (remove NS from Authority section for NOERROR) - Update persistent timers only on shutdown for better performance - Allow change of RR TTL over DDNS - Documentation fixes, updates, and improvements in formatting - Install yparser and zscanner header files - Improve lookup of libsystemd build dependencies - Fix compilation warnings in endian conversion functions on OpenBSD - changes in knot 2.0.0 - Bugfixes: - Fix lost NOTIFY message if received during zone transfer - Disable fast zone parser when compiled in Clang (workaround for Clang bug) - kdig: Record correct dnstap SocketProtocol when retrying over TCP - kdig: Hide TSIG section with +noall - Do not set AA flag for AXFR/IXFR queries - Features: - DNSSEC: separate library, switch to GnuTLS, new utilities - DNSSEC: basic KASP support (generate initial keys, ZSK rollover) - Configuration: New text format in YAML, binary store in LMDB - Zone parser: Split long TXT/SPF strings into multiple strings - kdig: Add generic dump style option (+generic) - Try all master servers in multi-master environment - Improved remotes and ACLs (multiple addresses, multiple keys) - Basic support for zone file patterns (%s to substitute zone name) - Disable zone file synchronization by setting 'zonefile_sync' to '-1' - knsupdate: Add input prompt in interactive mode and 'quit' command - knsupdate: Allow TSIG algorithm specification in interactive prompt - Improvements: - Zone dump: Do not write class for SOA record (unified with other RR types) - Zone dump: Do not write master server address into the zone file - Documentation: Manual pages are included in HTML and PDF - drop patches which are included upstream: 0001-loosen-openssl-dependency.patch 0002-make-configure.ac-compatible-with-old-tools.patch - also drop all buildrequires just needed for autoreconf - new buildrequires: pkgconfig(gnutls) >= 3 pkgconfig(nettle) pkgconfig(jansson) - create devel subpackage - enable rosedb and bash completion- local state dir should be just /var- enable dnstap support for factory and newer: - new BR: protobuf-c and libfstrm-devel - prepared lto support but not enabled yet, still need to find out which distros support it- update to 1.6.3 - Performance drop for NSEC-signed zones - Proper handling of TCP short-writes - Out-of-bound read in zone parser for long domain names in origin (AFL fuzzer) - Out-of-bound read in packet parser for TSIG RR without RDATA (AFL fuzzer) - Out-of-bound read in packet parser for malformed NAPTR RR (AFL fuzzer) - CDS and CDNSKEY support in zone parser - Add defaults for TCP config options into documentation - Detailed error message if zone reload fails - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch- update to 1.6.2 - Limiting number of parallel TCP clients (max-tcp-clients config option) - Ignore refresh and transfer events on non-slave zones - Compilation with Dnstap support on FreeBSD - Possible file descriptor leak when terminating inactive TCP clients - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch - moved autoreconf -fi to %build so it wont be tried in quilt setup or similar tools - move up the %if case for systemd in for the preun scriptlet to avoid warning about empty scripts on non systemd distributions. - used xz tarball: new buildrequires xz- Add deps on the docu packages to regen documentation - Enable systemd integration fully - Add dep on libidn - Cleanup with spec-cleaner- Only require lmdb-devel on (Open)SUSE 13.2 and higher- Updated to 1.6.1 Bugfixes: - Journal file would sometimes outgrow its set limit - Fixed incompatibility with OpenSSL 0.9.8 - Proper handling when machine hostname cannot be retreived Features: - Support for DNSSEC Single Type Signing Scheme - Compile with lmdb-devel to add support for persistent timers- Updated to 1.6.0 Bugfixes: - Fix zone expiration when AXFR/IXFR is being refused by master - Fix forced zone refresh on slave (knotc refresh -f) - Persistent timers database opening after privileges has been dropped - DNSSEC: RFC compliant processing of letter case in RDATA domain names - EDNS: Return minimal error response for queries with unsupported version - EDNS: Fix interpretation of Extended RCODE Improvements: - Maximal size of persistent timers database increased from 10 MB to 100 MB - Added logging of persistent timers database errors Features: - Persistent timers for slave zones (expire, refresh, and flush)/sbin/ldconfig/sbin/ldconfigcloud105 16330777953.1.2-bp153.2.3.23.1.2-bp153.2.3.2libdnssec.so.8libdnssec.so.8.0.0/usr/lib/-fomit-frame-pointer -fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protectionobs://build.opensuse.org/openSUSE:Maintenance:17006/openSUSE_Backports_SLE-15-SP3_Update/a08d5cf2d25af1f2ab7fa81a995d2fc0-knot.openSUSE_Backports_SLE-15-SP3_Updatecpioxz5i586-suse-linuxELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), dynamically linked, BuildID[sha1]=dff02c3df6533205a2fad3c59681a43695df9a0d, not strippedPRRRRRRR RRRR RRR R R RRRR>NZ`Xutf-824f1e75e1867c258c90f7c2935b1a4cd01c3bf2c2839e34f2dfb167416cd9853?7zXZ !t/l] cr$x#E}ӈ wI] wu?RK$}DPkL\K̺ľ]MxM&Vlse1NqCHNFO!>~bζW05we2 ڇ SQvo*5\;iN, ~%{r^%HW .9rܦioո'r0 @oy\ߴ h $w*xSڊt7pxs¨P`쁇NwD)wҀh@LCw;QSe'Y.~Ckg&7JRoxC] y0 (ҨcSbE̾jz9^<0"DHKIĠsid\R ͟O~-mciS"S츄{#~+#F{ߗE9j,#/* L 3ء,n ۡ(6IX.摞xj `9N: heo2.ڋoxg~@$⾶@AM(2/1?t {18 (F_!bM3:2ܝlZLv ⌵RQL+3$ȨC`SE<^!5ŭpBrtQZ⯔ozVddg6\2;\0q6 <1)cN#z.Q'*[H5N^=t 4cD:CG }Wa_k=n-f'<ly5ɰe]9ewճqwԕ.XO8 5Y|Gvr]nh,vߐ&Cņx-*JsqPqd]p&]gzS?*t+œ= H\Sqjx=?C% !(n3)֒mdr D-kn%[SďcAxړlL\}2Rʋz\<$ƮQd0l -=8RM+ÚThD$O/!ό ۗM?t tm,`In.fI.N#5Jxo'M %/Q" dA)'&~wou ¶ YK6Ug Ӭ^ߕ4ax^FQK aI7ui_]O/cݦ:"t@k#i@x4 Tr*BY0~W;+աd&$[I Gx}Fx(#N!Bve&˛~<Ӱ~e$@\8UK둿yߗ㹚z5a~0esQ̽j%- KIjgpۦxu&1'4 e(!M$`dvfTP妟X:kzV2%lA4N4y2aQWɃH<>јEi?k+t^ E[ rCz/@-r 'h5WywɳB_.7$}18ls?+~#Rç8ioaRRzh5>E:+[k$30G>?wqԷT?^k^~ \jI Fjl@ʛCfDw } BJLdStY ; >e`vKU8Q"ƳUfs~yT+>:CB??*gK(+-1bboo: v콗[~F=dKJpw~uJk ;5@L=GU$@ \X֪{bQgE'8b(="n1g8$5J'; }Dv@Q IqP`#KA-\i5CDa@ȥ`0'D|&UC>GOa,P4]&rr^ ާPJy 'gG;E{7, _O_VJzhBUPRuq[k Ŕ;wVKawA/8O_S?E?{[zXi<[)Оs}/D-*uَAwqq ]; uS ̣awJzi8C7!XaYn}lG~(FWt$ DO;~Zf84>ķ_9Iau=C3rZ`@Xi[WS"^|3fG盬)鉶{`.qclx>ʐ#~y"D@fo(Zrx. (|iD(8;٪M,,r k/f]ro%Y_rNG>W4:YW$v~h4m>_/ \4$: ^ڧ+ZfL 僩QWA9'02#ɽ_u (=jhcKDǕt%i)1m=r(`i/N#74Q=3dzR#ztmxGjݖ# et?u ,Mr:*Vrn Փ6yiJ0C0mS'CF4I喁'J Nbdm($ :7\kAr4ĚE|W>\BnE}<*\*1v`B֖́#zA Qc~>=Sǡ%Grx acV+ lqg+2G񶅙gk}R攛!uXWzγơhڕ5 /ĬuA4wOSuHM+$yql/l2yqIc'[x$*k@ܣRvcܘ1-"g()F&O`p`$ȩɖ%Ӗ9н ܃& B'c" ?K ֖zCH}Z-Dhz,f[Ҩzzq7c.RD.ZQb 3uVOQC֩~o^$T1>5=xN4T>H ]8MJшC1Fsx1N e#ĕRTJwU#iof|54yfPm" {@|{>΋&?߳V:copثSS+ V,5"DկBaɅf7K%Dj .dX(;- +;',Rg+ {ι#"H0Q{ 07&i+IAʭ 41x\ܚrV3YJ-A$EKFİIc.tg鵳jǽWo*1xQ [ݍş- fU&@h|n  N&}T8aZ ?=\fKawqŌcpm+Ac-ej؂IzSwti^=Zw[5آ0, =X):6ȜETv"e}XfeĂ(xkrqiYTB_<ݬ@l~oߨVq4{c"K$-!q zJg-ԓXUaX=/5(B8 "SCZEze>G$835i [KX (5Lw5!}>SՇ}Į-A.o?׵qt[əHʛ.G݉,6bB0W@$0.`s0ݪG~Ԓߵ%v0JKz+ݖTDbi.Gޠ_gR(j*^ƣ.Cjc1&bsdG Ǫ-kάW3\b1^+-Z1N[VUB47QiD)'Hreqnolp:Ԓ bq]XPm)Rmx=(gAY:6Tp~GjVϒQ8h8F97Β#(\6w|+PJxr%L" f'}d~f\>7eEW->ͽ| aqB]b⿺O搰˧_R'H݉kw5Nkvb5/VVО'keQQn lX}] K+%g3^rxk2{Gd}wՍ#׏u@=%:ah>y#*67&l2`xHֲPy__i:eǶ~ĭ[ O%grIrpf[dٌk\Vf4P)dKn]ޖ$"Nǰ1ܕ65cYK( ƴqK;t"s qdRcM;^[uzFS>{QvK7nWˤ_b3:i3 }\2ꢼP)V#@B#_d)a5y|D*XLB:R$U:`G|[R/h=|G1 Yա~iBL,G[tO@]Dyen8r0Kr65FR?4"-!<X(zY> G0?> :Gއry/B_+<'ܜx@=-RL-9(_bxXtq8K򊨬g"y˖QATu_N6=cmA[˃aA̪Z#B])^[3unBU}ֿy)8c ̭Q 6W%[[iI$ a{9(џ]ɬ;279515!w;vKF?&`k<ѩ4p/oʞ1Xr[򏎧ë\,)#nk6zl[H߳]aGML>>avm-Vہ$@WsI /Q˲P \殙S7?Riوl8#['5F0bWnm۽4z珲2;\c`q.S7wUK ጮ`>(y+N)mOlbNjD[ID?Uh(;./oRt &I\L"^̹͑B~W7d@ B A<ԫOFieW|̴r^i|ǷpVjs3j.#vXQf3#jRcȾæ1!]KguNX#19Bs!\QLkFj2YLoF.a>ݵuF={tIMg_DjgRTxz^vsNh'f J aıxqR8+1GnO'a'Lb;**e^ ȷ|88sXި{uڪFX5@_񢿰5b $f.ܜDʖܢe.ɷdД3(2E?¢ IJx9eT'rEUƒ&buh8-A*s{|V{{S{1l#hn}嚍@\ 7yc -S971&͇j /~d{Y2喀\\bnbi[jlNFސjDڟG%,B_W ;j֗AfttSU1A6VN;B_<7px|,Ht?YI|$:#>7GMedI͡Pk k?<))!U6^ŚNc;>k윿76m&E7 4^RFP&< c 7 (axjO;l7Ftï|cmx4ˈnXER!D IB:s9=TC .ޖѬܹL.&hMQeQI#W,ITu~}0?i|9dlcrT=%|S#N| rz /ʜ ?>:ʙEi(C#C0{JO“w?sb Z wfѵN粄_it]y_{Q-I7򨉚UtV$sy@a \.FzS5]mkem(g@1p NC@nRZ/c0RC]p4ߌ ͖#uS6;GabV3.4LL1qQxy("W(?  t/n2(ctY@ 3r {#}ǽHk B%Ҧ_[ƦD E LC2s4݄)nES;ٴi׆jU}2Or>Fko7 qDj~Zؐe9EK8/T dXU2?]i:N/X$2(.J2iJj)F.rYb* fD&g\]l,aOѠ,x@=7 MMG0cw|MCo-Qdʎ [aS';S/ڶR8ڬAԷj̻;*>Y8;˴}b{pixF^ #3xX"#UdtSkHBrUs+lrh<`J} `?][*̕Xtݹ&LҘDT}Kd֖x\KY+q31@֚KR)_3I7p)\fw^>KL¸+/glϫVpT B# i@n|]00sg2$W{%\gHy>ؗDSY- 8຃>tLF1dIX=wj}%g=/D/M`H%D1vh_q"m*ē,P&҅Jg1ңοA._7+aiY&w:( |*@uB_'KV:U_mz| 5BP)T#OR3lt/U ,,?$ &\ɓlAְ\E\ϧ:[80f[f_ѹBb&eRwͶhaʫxDZ74ТFoq*.M3Ro緷Q'rllc1[孺3{hm!췜G R av Qy!4,NG!vBȼd۾EH pk׿&?]6v$Ilm:鰾&jwi+Ъ-[x'6~_ f;:TWJSM<3}r\#&]Bz~ kp[ާ;FB xZi1K/ `֗ ^̳EIۭఐsRʼN 8Qj/Kto t|BJM_LnH+S..f%bR][tǕGk*^N$*  ޷k֡Lj9?[l fy,= *G8tRG0{e-IgK!L4dH$eP)uHUt##  ubC"y#:sP:믞h5~M^R& fM"2Anxv<XBE]S|c9#hqAt)gCD4ṷ0_M o'WHF.J9~`V)PYn|5f+c&[aGא]?>h1 +17KpRNWRrgYglj(f9 TX_1_8H qA T|,BN Ԟ0=erF/&L !U&j46l`9>w".V i1 A_|0eBqeSD@G0#'i' &;uvWN+:4RVC <=};xҌǠFHlE% BLBM'z |5b$O]̐5iHQv @?  QPv"=>ex+6t2SѨYrc몥%h3, $ӫ_aƑ?l 5*+l'Fg)n!.dh$|V"0D}!]v[`ĜF0]( .vOw5N~JqOaTlpriภoaa2%'(^tƨ؆'wyy hwE&"؉/^̀@kJ,8 o_m a=# SOl%8'&&?}|B{3.{P|^91"` z:ZiZ:M_PzL!rV\_POp͛4I`ihl"~ɳֈY gas*$?u޵ꯨ#K]M=n :- KoԡNiXe 9*pRи:L2(Ci0x;9Y V Bq@OfPuwsnT'K*l:<ƾdkKא'A]u$= L;D@gE{1zMW$5C' ÍBU+G4Bpd{^mE*[rt-5a'MaҼ]Es ADsNJ[oQ8 <b`Awz_עѯm}e^{Ӓu&1?Ŝ_ ǩ) E/t 2zv(yь[=`Xĩ{=/  tQۥ y_ҡQV`,ƔYۿ+`HOHn (v",M}Dsyodžc+6 c\@A^L2?0^yj[oL `i۹ =Rr_CyU|68uxɕ!@"q)??&/|Q9룪xyS=obRraR:57Y%TpB$i3؉,r|@?2$QDraY]\a^˥,zv4 J鉙 9m#9 謹RݕVjJ[?Ҩn\dw7aPHz?lz<-ZM4C0Ma2M 4| Ӯk MO>n e7w ~˔L]Ύ7: tӖFjt^`^rk>` *։DW+cMriw_cLz`œ=}@Cx%`h?f V)׼w4ȺHbFX׾&ӰKiOT5K {kGmV(+IO19-zuַSMȣ`Qn 둺44o'YȤ`q#3_p m @e`db9R/ᬳ/d?*&>c QjNRX ̃`:`Zd3Q;ISriDF\g9],_rč&HLR3358ʪцukqt~pNCv;[DbH fM b2m]3Z n\A;H?U /rSЖm[C!ŗkC9A˳.҅MJ]|[2Γ ijR6՟i%,56u]Ǭ',`$ȕOsM6@!jǧ#^#w*q3)芩ge6]h&5{ߒ 锞 V~-AG/&ػo]{7%cUDQ۲& "Wem<}yxg?,c`g;$!aN $}C5>i#HT>@uEƃΊwsn̫3;#5lrj@w K&,TMp3A$2ߩ..plm79r8}4v3Vݫ?j{| uhK%؝Ο-.q&K^WB$z9f}2MLyGyڝ˿8ʽ0t&Gg'\QepaL9!^o:=C3N^Vaw?j"+n42J#L0gl[mRLG 6Ы+3VZ5?HOs)&]Zw<vcb/$;yc^ڲS9IV@iEimҨ2J̧B ځ,%wcE>XyDotF8l4x3Gϰyso}腰F>bò4wc2>?2Qhx0yilgw7Mm;])Ke"G=~!yK3o%"Єf\>Z'2̆B`TQ>G5WL g?gZ=nFbDg p)gqѓ'E*geAE1[/f+fk-5D;XS_djcVY!D6 tԛx+b$ӎg5:ʃި^y Ў|a=%5;;hϲLdL4Ȑ#ҷ$.ogCbJ9c*i ۭvmCS_cν*ko0OkXe!e6gC =& 17:+'ҭvƯ9dٍTB'=&&n<yu`?^btoKa 2_ը%ォ֋\ixy 38=?ۍ`GZE Xy#I5(2kzaDS(NQh`jϲ,Κr"0H2~!t<-r$ *7myU-/0c$8}T/I$hե+2UhpGh+`{,ŕߖ_gg_vCqhs2W"!'ll/d$!!xxi2LH[5+񕚍GchL)U%wPcMާ%YOaUH [U?N%-C6JN]=P4OtW{>_&yK58sK%ym;% oM ZEüMMN):ڟDQ#iε-'{ތ{s|2;F?G}#)+Tz$(<|sen[v=c- "6(Z XB'xh Pl4 {J90cFv"|HRm_6=TIڪ@stw/G(m)wAћ2HIa^m:|eq n 2faɋoMF+oh-b@Q&&y7 :AN,pqVjz;ޢ2:W9=6`Wy=F5QZ2hvzxaH q0 LyAUӍB.@JtgOuqyJ7ʻ2.٩~uF0u~(?ޓ7COU l0IyAy:m^zHuv0k /f7Uh${ e%{Kc zf]P}a`=>GMLf"#h9};fk$ $|ݸ}@ .sO- tN\:hy9tJ6 _ ddq*6n " έ/N垦ϯSB06m)j~?idL3 D^5JK4+>O1)s !7ô>@DB$Q]irR>ke*1 &PAϲ | rޙAd9?ѵs7 L^d LcVi.9F> ;%P?uİo@z^Z`2Fh[9y{s!5U S+).[F L;eXnK5{p_Mx=ϔ0p'<XRvXڦCx؋bIv t[>e# R̭: Rӣs_b4iLa@v6}.]$%(MrB ;իuئ]|J3荎̌zu ~WEŎ29z,ĨW+B %P&{W=a8i/ՠdÐ_ߨ1֯uI= +![aWFMD= j[2kg}ް7kZGِ{E_g=ɲĤ[e0(hŰWt(S '$*^<@U*=jb^kӼ(OtT_G(A~gNʯ @MwYR(]Z׌e(IG(,pa~g"մUKm+C^Ͷe<8;2f'R|,\җu^d ZUw#=AjNYeђK"*kSV?pkVMb\d=j3v!ճ\MScu:B޳etD2i.܆ _+/U];9#SfԂTTjb>+A_P[Hpv& sZ;.po?ݝ/Ww"2:}<”5H>uˆ1"( r 'UL,a@*jjh~76&ڣ[S>ٸ7Ԅb x9bdV?SJV%`n:{b+v%} 6PAb<'r%q! ys!8 ]H/#;+,ʓr2 Uon24< 's.5[{Yj3uW Qn'6]O-M)fYNonH+ P`]3iȱ# RaqXw~EJkdB5Dֈч Erш{_fnDYVwQCv#ĊGX*, k>^%;* Sh.Tޜ0̔&m<͡ =9>ۊIIP^+~YOBVt^]606;N"Dxxz.Z2C lfFYliBs3wta"C)\s~ >%r@<[椚+}}NRq5fPŻ{_Fa7p'yũ~5/+&DG׼ ;͝Sq"m^oI{;;>DO`;&KvT]I:k\ ED2#etL[?ۥǑ$oJ5W,f:0xJZä˸]f+A܇9#GᡰrJu6p+dC'͠wnDazu-@Zzc{ɡ W~s-cl<O Q*ĜMfMFK_ (5 %;2sD n=}y$u@wU8)A>` /OO5fVtpJ3gl5u+3=ـ2:`%&>MTH|h+xѤ0g)#xh%ۓc^kqLb3J]:)LSI/UJ;_VD Tzq )_C='Gp'#׶m&BT4%hJQs%m$ð xO:}6p RظX D Z G XI)B!J1Gդ;n =1Þ} {*4̵Dr)Hʬ6\tSnaT/ˏy=PdZՄ_X)ǧ<@Xi^"GC'q>NH&ցEil}EN>2 FX znB'*w:RAqɆ~an}c|j)Z?XP`uhNϟ.GINg:RxćP1gxٱFnOJb=&%ky@y ׌G vmP/9KcmbI)'{4w˟T\ȶ_dm ,?n˾v5×کY/3y)3A E"|([9%h,PF>ޖl59Qcy}|k>JwEOʋA~ Li3{HbtfJmÍ}Sؓc]3.\zNծj%qA۪v#"R^`ױ0NP.}qӃɹY:sE*|;C!tEjȉRt0_[CF:Ӭ/81(dNCtX䥤=<$JJ>gHnO}ѕW>V ;qA s&h7xq`[vYu! tͿfsm݁7MqNl`^ D$*8҈}ƃ]p S`OeIJ@0QD3X|Ghl== $ˉN .|,զKٺd\E**EÉكǥ\% CAKD n+b( B5߰_M@ NێR *V;`pW!s45wg"χ^;i,e4o% jtv fDhx5ᷤn"4mlLg94ir9q! V;JL@[*M}+[EMWvNvr0gRAWf$IlZnR&3zrwYqLt u`̄Ecrsqػ]E-Ý6JJVBIVH_~ gMPQFB ˣN0(qww (d e]”-]3Z@?2UtOC"No}l8#"R hCN2?.Ԭ~%#F!3mΥEgr͝l}h|dbFJS}`p=ZiTm&+ e5i3uϥ9Z?2o`ִRm?,j>Zr Ccj޾֛a)GjW֩U藬mO1>_NAߘ&rg>`)ei=k[rũ3k4ٿ~@y\ ĆlcJ}{_  | wl8_&O b,_'!=g#Ab9z$BMtث4fLƶޕ٩MAƈD j3H*([mDxTg' AȖ!#~>yWW[n6!MWf zRU}<*CX+a#YL 2fM2my!y>lUIA=Ax/ݶY7+~KJz¼?Qżd>d鎒Jy/q (CX3,pdij MXc~mDUM)Y٪|` T.ZQ,$Y;E::2]#sTaR6Vh/%xb3wH#8LOA]O͞Y$Rm;I@F0n[@E=[2-"_6}(:Zb̲m$]R5Wh7C}Qb18si/@-*\smH˹k&Jp)=Xa͝",M ,/Q?~Jp 6``A!HEa8F-V34fGiHPv{K)*W#jxb:ʹl@2 t郈ýPPS3"Ry4:ђ". V]$ P8S|{۽לPcY޶'lZv&u~֤͡p{WUf ui 'W/NcATbl XBVnQs.VHմB&-#_5jTږՉ7^,cLlb@cgcbB6zRv%em z.3m[YJKZt*QOtmեXܮc9 MV-G#r yHi"y›ضއtpkZÓ{U7/(>p _S6:eE8El5Q3BST)|2gR6w^u-R~kH'GCCXUnUT~[{ӜWfdI:IWt Or%sX ^Vǁ@<׎q I !!' vrVWOO, 68-b 8|ȸUP M@;yfL :_ifV{"KzR)}qKkn s  8 ,/R:VϹ>{Kp>agZ% &Rt%Mh p ǃ !(,i}E+l王I\LjsS3\A3kMTZ,;Jj|]>kѪR4 H_2`tㆢAX9p7 (T8,DEy5^C|R$;AbP0=1,nD}ݾY[*ih9Z:xVƄNQ҃C1Rsu/*rE~RY5OsN Ym&*GH|ecWku䈵q G8J{^{)1b `9Iu1!vޓP`{)VW +& ~A3g;W_FZ'E &< bD$R?;Kouݣ6KO63,|"458e~U>5s>J6ݢ|5 >&bQN#nkO5<$ΈFV%0= {AL?ȢJ Pqg-˞7?gfgWHDEA%lO'@spRl^Pz#PS'e:V _r6ut5uw<hwbZLmY?afzCg$:XsyFSIZw?@I]YPM흼ȣ,3+8o(4ʚ!f.1Js4qUB#BWW">bHfPx#]0?Az~ ewol= CW0^JUVZ3(諾T57YQRNj#$ (P:mÃ0'->(CF:tFv;~?Ol+@:/*tۣP {:hVߏVEO=D(L0M\c _Vцj@W.ɸ UaCdw^ CղӰoYԥ884{0 &U*ql=G5`e@j<­WWYp .'} jI}q%fOQA"%u|'>=N"af.|`=7;2յQB5.kU嬐gdzT/^cQ&AjR}G?0ɸ`Ѽr}Y㙕% % PN7qWJ~/^N{dTf%4]OV71՗'Cku{yPUP:RkgdY<{|ygz4wgƭF$oP7OXEke,Z", ~r޸w\;%W1T;{8\Jj]jH:1VAAJq;&b4Y v+V8 IMq͵˧X@p8^Gorqs|8*Ƚ)Lhn?+n6@W䊔HP"O6fs,!Eu|#'uV?|p~fP"Wb#Ζd&'S%ɞ:vB?ֹcWWs܊5Qw] )[<@T*@S\33sޤGp?AN_zk5$үMV[0X)fݨ!{aƁI7c.?SIf6"Q%/\NJƄ8w!Ȥ:/ՕOl`?/(- Ex 6((҂=|Tɇ󎓣̫ Nn[Ƒr1 /fb3sp;/k6:1î'Hk3[5yVAM8*.w B*ZVmϗ(IJ@O՗vCX#iANܑ蠝)7s EPaOԢ UM>ï1-C5ΠR.¦@B Ղ &VEvT"P?hK`C`g˗ >e.N>c0SaW/+_|3%L:/zu!O&28hF{Es' {1J|!B`g\aH9%Q]&d"-4uIJhu61|Y@췭F= ETny0;&/m}LvblBc~]3ה&\y0LqgzO(;.0aFAq{Δ?j0c\b3P0bTJtK 3ߘ5sXƖ A0 %;i~$W'T !^% &ڙw6<4~׸ .dpސ>M?K-S1z-iv i諶duS:rP 1%7ߧ*Npyy|#oN#d̥cgX"QP` ) eatMGX6X% ҉6*gk/Uyg˴% g+I%T1nlmC!7fPzPy:?]@VH1Re=PY2uFϢ$e0Tܞ9l& }cӝzh(hj I&I?Hp Dr TD`{ro+`XVct#X-Mauh%Y _'%@9jgS|u\Q%X!:kk!HJ|k`ÄT00R1Ԃ3E\@@=KjX& ~@DBB7@@EBxb A (u>5.ÙƖ0"3oܳ[M7 R00n0FfZ5 M_,e (Z=eJ<[C ڶfXrF@U>m%,>T3m>(-Fؐ~.8۪x3#Kz"hy%ōd<߿$KZEU qp\oϘ_+٪癩p}婍WD6=g t MH1IJŜ`78 p8@T_(|mYeOaM/ՅQÆ(=&Fp[gf?= keo/H-[A s;6|~a ɚ&OcTjsD_{eІ6%h* r!"n}]KG6W4QcTYM:{Viє:)X(<s=K&jCWƩ>}>GIƘ\for5bV~j#\f W0a ĽRn Vx2B )zUWkrHGr{ɤ=V `̾J8u'e¿$m"2%;a3H¢4[WU3⑒Ϝ[}4o@FU/ZXE3Ů *a1Za -I34S87b`d#A2cL:'8T*[ R[MB1w,\m7;[#t>nx şSNsXUK(]%n6ȗG85~U3_V!/; 4hFs.ULj:pM.8ӭ Hޒ]DK8Nۍ"Mՠ^¨yua,7t^vYF&: 5>i  Wt'fbᾕҤ k8;ϱ<{^1?Z"^9Oq1|Q H$?Ϡ\¥[\<`&`}W3⽂&hB/蛤s9 $A8ցrg蕠gN2`ߜH/#Y">*Yt (sMM͔3'$&޲1 EBW% _EM~vs.7DY͆qNaz yC, PML~'B6Jk P~1fbG\jQ1W7!TW}Yr%+M!kEtk^x PE1D"{'&;Ʈ8_ȓ1$_+΄llv]Pt^lX 7f t&ze8e\ƘIBoY?Z!h ՙz* h\B Mɝ-*&:H}`' t{ 2$ py St8e+1¤<Cùz;!.:TC '< .8r nMƒ:ԣg [(_m.-0 wT*am'=ˣ8C>=,)ރ[ɮ[Aaa$(5ȲFY8"'hv}ч7I1,QjRܙ[3&H Uib,v6 6@qJ՜֮%ZdQgD&; :ԉ|k$4jE2?gQ R5~ Xw}ykM~MF1 ( Nyq4ŪV~ d*#nCmz.3/]050rGgI,,i lB%;¦iRޗt2F;)a(F{RhQ!` ujգRj'od`/ ζ7aFZ⇨NIY7ZumiO6xۥRْzaq&hdӑjr\bBw!| hƩkBL٠#*jk\Drb bz`{ЌeHW2 _-h ϵ8ev;W^1e} 4Y_12P>igM )fP0J:7&S9&emU^TsPExBD9B&;ÓbB ;׬ s2\8nn YEyىo)JsHJ_RQT.Ę96NnDmQqk0F5Ơǔ ^kT Y>P)CGam7sn"on[sh1G&9 "dyW-,,-K_}5\T > 컀0K>z6>0G`״-2gQgkʂJ5Qq; J .c"?*J=5a k-!`C@0܍=Ʈmn0^0mdeuBN6)rǟK/'H^U9XX]V*`3hoUBzPR.LYdWdfLJBH)TbA\{ҁupaL軂p ң5[q$: -2ז52uf!~G5C5tMDZ]2Q8~X#W5cg&mjp8 VjJP߂zo_ܽ]~, 81׵>8BHǨ$:8 ~.'@#Щ)'Moyu*-UI}J)"K²6t$ =H<) @Qq!껁6H~6]Mvq 6 #L,I)2n 9ǃoE)/W#)(|˙|B/U |oh=`tV,!m΢wWC|5"\%sV mM"Q+H@SF;n*k /0>qS8!:y0ܚ$@xjt] /Ѥ&iM5f|E2I;? 5&Thu: [AgSτN{c7*dG9uVc$/aI\Fz 01*Nt 7 wɜD;VuG{H˜f_|rH¡.۽q?+ 1vԎ!A#ۅ F: D{LDqUA(naIlȎd&iѓ#iX|,)8?c{\m_FWBBM|eNJW Af)[Id"F9#> ,7X&OQX(&ץib~^u.TR5<kYTT|yjhռ2qUytE҂̯ doWebp#-eCd&KAq)+9cu_ 4&>Qc;fsR4|mS/j?F:9q j@{I/~ aZJrP SD|MȠR"X>(ǛlZ03D9f)>Q#ļP/Հ^N}HS}~`B@3VIា{S1Eӯx9xd81/.'yxegkbhQr]Cx5,"!\i7K-b.WxALmK?W$g(tլH9Ƌ2vX}"  jSC fFUw0c X 3)K|[l(iEBUhcC ]( |Av.7KvZHak 3efplY´xiCRq$@[+LCX\a[]mX">NWÓ\ν^C-y>rf3}3=]\[A jg jNzܽv Aܽa'<|%ue;9ڤe պRO$MJh{0}uE uךkwLZ3MOUL-=0FqƎ" 3*}L3Ձ8s:y<}g=.w޼g~M!T*DLU}rН;aھTGfB eL{w[51/HʽkRG6P)," b*Umq!Zذ$$2C |ƖHU@i|T^0ւr6<:a`HKИ_ PK40؆ жݛ 5Vv4~d==.F|DgZN39#Qӱխ%y:^:ybF5Da$"+7\9G΀KyY?䋗pK"|K ::D5 BF<6óD mDV'"^_*#SCnjT'OEEǼ'k*\|<3S;gJqK ԥ(g H&+U] b< - x>&sCOjthe]u^qS{dCZDIxF݌Eg3; c.ɵ(s(KTwF= } mG@6BA7SpzcijJхZ@F8aTDeˌ9fT bYTJ`DV~:JwJT%)an&Sq[R!{o% P+,\*PN- {js%t@VSrG@BH{BݯbPA5=~J ~ 4{yGG" BI(^՛=+)5@jrƙctY_L)`0lxr01tHEpo2LR@zF$_U+|t}t=HD3EB*%"z>뭣Wi=`Ӻ3F4s?~MU; l{zZ`I*]>'EmU ? 3];禞 fP^Zដb5hFý^%a5?`l"HĒ'Pi+{bX3`rSbٖK.5gb̶en!9 ^,]<1;Q4xD0|E 0 5M|k][1=hՋ a NP4KVK}ey}W\_N==䯍eXry{`dXěR(^(x ^>_OƩ$Xџ[`C9jlr^|p\O{b$Pk"*f@9CxFkLqqu}},J#]~>9j;l`AeN)C;Jj9 7LAj˲ uh vb4KK+˗Q@fj}9Mz5r8fPY7Zh8a'nܣ%z2XH+1_Je E`Fr?aaB#s}h~h=.eE\+ H8Q̞M@|=.ePЪ o {QՙPO(3kW17$ Sal-ԓ +CMI"N:kl۠EHTl#,CrC?WV@-cHiĿya!1@1j8}M N~f-ܙ Q}=Q`J5׭:UX~;߮(J|&Vgܱ2тZ~Ac*a/2% f13 B'}p~Wz#o\J8) rrzE4 $\:ItjF:#F5|8RS=['tоHW#DH o֔z) c"h/]זz5202cJSmq[Q5W=fL lc7o I4<VKHV…fHn)_\(.KZUk$_Po#`:QIw`_J̫Wpۯsw-hE2C*\/ GnHC3PCcMC㤦4"%,Sڷ9Gፄ8SR]4-{/s%}IQxHYifO'3D&f#R@7YOS^e {WE9W'? Yh?cIxE)gFmmg+&'#DC*Cj,#)]lF0~vBD|y} $K1:m^ R"ߜ$.,wSE0K*;$?vj":%x4gQp fy.HݧU(ej1Ĵ=NlG!T=- f3I$إLת7UՂ>45U ! w6.YvkJJ9cLJ-NUFԆ u') hao=5UǠ `^N$&WI惲}e\j4Ƚ},RhTx$lF [};YheAykYGSSFufI?efA)rp!W6(rfٌtҠwl/)^\X{C)(9uZ"  -nxksp Kf.&?4WRH}|}|8K4y]k)ǒR|I~ʯʸw[05df3\MnYG0wiY]UJ &6pvJѯEG9KХ1Ua,!N Enww=Zq}UQHI;end!l.@vjѶ+9$FC܏8#Gtߐ숄xs|Ec+QmMqE#̋ي흔P*0,Vu$虠|xoك1 19Vno~] VwpKpCR!.\fepՂ< ͒%Ep=pX" I}:L[jTju;ՑNd9< ^bRV$ |e1&" HQ[O:Hib '8aTS^v~#+PEy8m0z!\> [_/ FxTzJi9>;]Ÿcs@j%r (oJj݃P;ѿ jw9[ݐ?mٲ1~Bj 蹣4M)wF"j ŝ~lB*1LKeM%eh> -d[\+ nPbu!i9/oZb@+%uuU)+:(Zѥ4ALͥy\qR([m10ma!dmw~*~9XOK_4A*RQz.< ;Ms,hXV SP-2Qư,eW+ʈUeG@kRǜɑWL XhOTOmh'=:OC?oHY'|Ś[NGYzEio";gRkqj҅rl\E$*[_bA{nl=ɞ(tZ=h)XKPׅ_m:* ꨃKg?њ?G7"Oj=3{6!ObF"\枃z^Z/P Xk8 tJPnp2 D&u]֐Q Y!*,ୁhӆ;*b4m(חW8]mfV<ۧRo9篎oSZ C,NR>KpxWhڡK *X4!=r f C)3<{{d?CVX:ބ~t"k(D= '\fJC0^l.؉?"7kծ8:q teEt2{2b+wtWvQV09$\~64҅L).2_73x~aP0E$ RZgQ~8V~)?DK>^9vFpRK;3VG1 9`d01+r_tctD|v/-`up%K@>+(q?,zҀg>ViiYضށ7DsV`]p!7R,< 5}J9X&-S8R_&OQO'%ĀTD+%q-N(zH](kmp*ya[k(@ cE1Z.֐g.-)/EK4XѲI)a>_ zXY f=,4I-9LחmUg^?Yp,@Pw#a "Gi\ә2$*j< VR NБgM z/WwI{kyL㻞s (0Ibڷ 41IA8nd C&^`7%h3] 3 ]J*q^yI7I՘M3FĥG(PErƳSMHFwf/>Iv GXuHVҗK5QV. K#4C"RUŏqowެ1z>vl> V) %8LV"PTl-v4'HqэbN6y9fȾA!LX7L~tI7ZQ~7SjdG+1蚉"\KyyCDZq.f~Y2 trB TS Tfx9ER,s| BB?؁DM_#W'+v39VwbpϟDŽM 1tߟ\jg/[i_6CU'l:e E& !\i@sFIV`ri-JfNhQj0 8J}k'Ti6:#%߱.CMǯ 6K=b1}Ԥdm#e21ک4mhYҿw o@ s1σR+\FH#[5|V>ڰk Ag\ L;:v#_D/ P^) Ж{2f$fia% 󝧡|ȋ%Y([8ժQ#@ J7bH&, + :f@nss C3Uu=4y܅A&QEY=YL)NMU [DeU? =܏BIm|K>"H"`#5z뺳\!"j(Ǣs+t)Mo#p^wS#-58bm+|K8BjY25_8%ag%55K$f-u#2?)kf>m˄,Ӕt&*No3f?޺`5sAA%8d ы7Ԧt}7iL osu<</aNejFAnca!ˌevTԄK=͸Q$xery֠M;-D CSqH2 ( 33ay ;`Go@rK0*H:IԾ¬I4Mr{jLvkGWwM9~i:(*g/9z;a9 J>Ep[' ;;˽f1Lp;wv5.j2dGuFle,F2(6w {z9J f.Nӫ[5$Wʥ1&8g15 :d>n}ATW$zA1;&=]h6ňXƥH0SmLF +$J )d3Hi: w NH2@*(G2lX7_/A0 Wׅa}/j_[Zg6*qjplTiA<fDLr=d's+h_g Žc!0DԨ!QLn #GQBDiS@nl@h1$P-a=#BZbD)1I*8垴ɱT+̝_C Q+ #ak{?O m$Z# +5;z+d7177ƥGH{Ldž *}Q\pUBYSl\TxJxI7!ȃ؈\jaSbCYI%TҖm>"r?ڪPs嫩諅I2iF"X B7FIϋ?y݊-STf `ͳ\ۃZGc)lJZ˾<\ox[\@d:g@Dۈs)vJO Uz< F >F.K4DVG,LtjΤV#z%-#S"5uc@Eߦ@Ȳ+;e#;qB$ȳw{4ov5fujbpu>y#j! `L^]K?F> EwS»՗edTÀ Ea1^a޵2#*T\BkiO,wشstz\Ͱ6EӋx%4o WF ^kQ=0I*pCFtl;kr(Vp9_]"M0ACIٝ~.o)t?4q%eo)jj퍹1YYvPQ+8jkEr2b y 5 HJ`nK/XmiLg4ZmuN@%y~VtZ+Z_?p _h+1FR{,LSלj"2[hw+>7gO5S{34U7l7o`C)"t}lWwmY?8Q .ix |/"i\;R'؍(`NqQc#HOjyb[±Y~, S@v% 2Wf$:B/Qzڴ$v WC=iؘg!h,Ax!m1Avǧ^R?#ݷi7#hl8Š L7R d|RFy_jBSQT6#8ӹ(_@CLT tr7ac3AtFCO @__#2xF 5}Zp!3f,o2Fc&OH"xiP ZP}By|xI[s9iֆ<_>Ee"@Pj8j I9ߚl5niLiJG -jvMO* Ys=IR7d#~ j.RJY\qtnPPJ]7֑A0Ϯqp=Jb^U0 T_XTf-ƿQ"j8qCwnͳ\>-2Ũqei\wbJ+j/rȥm'SrdUgxhp>qhTFČ$J4~-qEo4 Vz.{A 4!?h> _BS9T>+@ҫրŎݿĵ`TZF2kBz:R%rnOѰn^PvWܔr0E~ {>ʩ,'{]Ͱu)T/MZ S'Dp'$̓c|A 3Y2CJ'ޗX: ,]@;Ե.VvTL ZXz |E%=gr~7)7Ff06ڨ dxAWtɰ?A˴'"_n9<cG(T;1-NM6jxmC!68#r/O$CMˡ䪼b.;'\`0{L Dy%_EHDd(V*PW,KV:L.pȼD:syH氎ǿٸ4!tܺdT{N=Ac2o9M:؅ Ӡ.HS7ކ핎p &WVc:_N<`LDK7TƸ Hi2L(A:y} ͗>ɴ|Ih$G/SgKEh9[ϯ%9ki ;7Y ")e!/qXf%A1Ș]~~2gc"C$p. ~>^AB5r3.>"0k0C[%E/ca)ңGĔ>"ODAol@q 6r][V@՗87_m<=Tb.vzݕ:yA:N*lzp/}ۤ)kIw nL%O 7s2s!UWf/!1ɣ/lD0Ȇ Դu$nU&-9X쒊X)sdWIM^8RƱ| G[G x0OraRO8(U$2],38:0s"ޯ9g@`MDQȫ@ +}E%z(8A4pPU 90W0(j4B*0Hf 5!SE!6h":}D-}ޠs Y". &U tPF[ߺ;ru dMG|pg=zyr0T l:cadՋQ$.)oam 3ܴ T

x[hbتjN*5fE˓U6SwVo}GPAЗʒ*+#CugQ*j=&O>",\ԍ^Uw4"ashB`r sxA^k`ġph\(MVï_f&0Gݎng9 N:-Q@'tO[VR,Ȑ}PbQ{&k}oM]Y6fPQ=f\?}>`zpH3ݗC߁x]lH:EՇvwf(iY3k(t ̱ELYHђOqN+~ $wHݤ]Ѿj~U[OqK)%f]OMF.A#y{/4c+ۋ~O47t*ۃh2R wLj5s!I%y;TB B[I6oQ𥂌v>U5@\Kl8S!'ra^1gqp4[UA9c6PZ YQx,e,LeH=G)^9t(aC{(a+KY'.i =ֲ[Yl]o5Z#K9#6n#-5 OQAGN{j ;jN"-+D)jhCߥC ګ>Hˡ]"qe0Ek3w*(vμ|eqž%3&i{թjI"Ia*&Y;@ Ou/+@eB,aTKulS2+t5ktg92ߨNo$1B&z׬ld՛Evg)cPZߜ<ζrNг6dđ}:Cz+zB_JjHsA p գ"[kS2-c-̀VaG?G(Nkl'1jY|+q|QݯebpsmҀa4깳eaFGA篦 `ykz xLU܍T84#h2e&{^-?q Ms S}kh9'WCh\i J-}Y+mW]HLd:("UǿE|0r%Ϧ6Wi69ѯvm1A|YhƏ~c,3N~khm 0#VhI !$ wN`s1HU . WiU]1T;,s{qHͽ +}.~rvj%Úb+A6r{oX^υ|M&] u\zgeUH۽s2#V;`6:T9-·Mu-\Tu$7;l|q$CR1ȱMRuW H_N@~ ɥePDfH~iM xS%3jr˻*0$ܼ 4OW"{1+t caHK4&uK_i=9/CLK߽o6\(mT"4OSGhqKx)@͋u jd-BJ?$h .l-2IEf}ƭ*Rm=# ںjyb$ |G̔]~ev<:>49Iڻv+6gQ P7cn]ݛv=JT;ù1P-@4ZzU{M@:$,C-0Q?9 IǛTGI_!~0$T]N; wZD[ZD?*8\7[Mx],rdDuVvmZ2E?+iN \**S o3y!9F9LͤkX3ɉ KR֜?I-WC)Ll[(Tr/Wr㊅sͦ '](wT|:"S| ޲FyqdBlWJ{IxhZj#aĨ#T:Z*7P1#wGRhk5*\Tzsc& s?e\<:|JVUsӿS!!a;icTו2q4 OڥNy[b%pRUϾ֠K|wY}CH~Kd[cqLlz-ij ~C-~V?sg<ε[ Kױ_zj cۃj|Ϳ}句0*t@z[Hp3 8,2fZ^]/emcjJ$%sf{[;~zN.&;ŞyʗbԛgOxU ҙ1~J=|QR ȭ[4 @M-ن^ ȹc{8i`4L7qm 5.q5Q(ӅtʽRu2U:UFItq#g|ɇlfusKxbtw/A=odq'ddQ5m, a"2F4T 6slK\pzq/e hVʪQ%PoK!Lbf0mbKPHh c8xef`P6I=#jL&g94qIV!UQyg?)k^r3u``~D s yӨedC]"A9)J0YQ@1:vRXb]A8FrP[N.I"&viq.t\ACaM ʑ6CŪHCO_!Z7OSgL6"Ѷ{\Wp%f$+xyfiSGv/ƼhܼߴutЭḥ*eā ^T2:Ds鐑.׏&D|6!F٧2WCB?J;A:[N?c".pn _MDAkr zxcGR 5g$+TAIQZ\Jo=t?d1XIw*Nӣ6a+q j"J׆-.JꡰPuwޟ}-ũT-,IW(KӣFe}X|rO(MY|z/I_uq{6 ɣݡns!4` Hv ,Jzl h a2^O>"T=SbQϥaنu"-wЈCl3EW ?J]Wۺ>4T2K5z{R"M R Ǭ<fuI\2*TxT0?L9ky4/cf7RfFC&b'zksyCT,".mO&Wh?(%5=o> jGéA>xYIʭځt%W@}v} %¥^ :mZu.KJX QWN+ƽ1˦I~R^ġta J6 4(8.kIݘ t&@CZ"# M9-ʈv/"M F{7Wxu߮_ۢ-7L:7"&D/+5z[|+5bφ Ty;2Ņ7 |HXLC."F:*&KPglC=ϯEhF–Wcqh(Ӥ BOt=]矑V "d5͜#{NYCg l h\fvFڹN{)%hl..:,w_x;I OtjoZ ljR5| j*+gڌZ%Ta1o\5X+eYw=lEξƒ{]5 PTR†u=iy%ĞaitbZucW=?,AX 1DgC%l &fK{u z@n|!PBRWJ(EgWIgZ=dJ/;kpoA_E1A9'*OٵwD)Ʒ"{ /j6&&)BJb@DRt K&(oՆ /5X;[~3HI.z\-T՚zfEEH`5.>A0) 0rRY7|]XiiѾ4Ao`XT9^9+ǁNpI̵eBYR[jf:pY@;b, ܤ%;$jx5x}V,)Աjz{Xt;{!2z6ϩ^;;p$ X(g[nP/ /Wݥ0Ip&/JIL )ӵx<0 Z,NWqidV3wB5eN I܊Qu=6,iL/L^Uc!$5JY9ؤ-6{d l]yx۵ᬖ~a[AvN}IUvPow2!qh[|Dʨ(r%y+4eI,Ќ"?n:ZS?-PBkW! Qi甋[TȔDnjehZP_$򚢇  YB nӟ N"Eu<HXH$`C|-@CVBϏQSԒ =DLzAǖ@ 6%s YZ