libdnssec8-3.1.2-bp153.2.3.2 4>$  ApaV̜!M@eeetLlʹY 'u_6 &ܛXSdn7E Ӡ4r!P^WW掜֌Г5WEh k!H&PzaEvb q+h{ݷ҂Lt`]rȤ$m>q ёP*0>!aSG0%m=# ᎍ)maKH=/">p@f<?f,d   EPTdh     F \dnx{(8696: 6>b@bFbGcHcIcXcYc \cH]cP^crbc~cd$ddedfdldudvdwexeye zeeeef(Clibdnssec83.1.2bp153.2.3.2DNSSEC support functions for Knot DNSKnot DNS is a DNS server. It implements only the authoritative domain name service. It uses a multi-threaded and mostly lock-free implementation and can operate non-stop during zone addition or removal. This package contains a library for DNSSEC support functions.aV̘obs-power8-03pSUSE Linux Enterprise 15openSUSEGPL-3.0-or-laterhttp://bugs.opensuse.orgSystem/Librarieshttps://www.knot-dns.cz/linuxppc64lepaV̐aV̐92cbdf6fd4e09e6cbf6504a3c1585fc546122b44f561ba7d5ed9672bd6a176a2libdnssec.so.8.0.0rootrootrootrootknot-3.1.2-bp153.2.3.2.src.rpmlibdnssec.so.8()(64bit)libdnssec8libdnssec8(ppc-64)@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.25)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1aD@a @a @`ݮ@`f@`@`q`_@`\{@`@`_@____^@@^@@^@@^@]\HW@\3?@\*[@[@[ݍ[IZ@Z@ZWQYYYXWDB@W1@VwV@V@V@V@VTQ@VCU6@U6@U@U&iU&iTTq@T@T@Tk4Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Jan Engelhardt Michal Hrusecky Jan Engelhardt Michal Hrusecky Michal Hrusecky pgajdos@suse.comMichal Hrusecky Marcus Rueckert Marcus Rueckert Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky pgajdos@suse.comMarcus Rueckert Marcus Rueckert Petr Gajdos Marcus Rueckert Marcus Rueckert Marcus Rueckert mrueckert@suse.dekbabioch@suse.commrueckert@suse.dei@marguerite.sumrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.detchvatal@suse.comondrej@sury.orgondrej@sury.orgpgajdos@suse.com- migrate to user creation via sysuser-tools - run spec-cleaner on spec file - update to version 3.1.2, see: https://www.knot-dns.cz/2021-09-08-version-312.html- update to version 3.1.1, see: https://www.knot-dns.cz/2021-08-10-version-311.html- update to version 3.1.0, see: https://www.knot-dns.cz/2021-08-02-version-310.html- update to version 3.0.7, see: https://www.knot-dns.cz/2021-06-16-version-307.html- make sure we have getent and groupadd/useradd in pre * added dependency on shadow and glibc * might be related to bnc#1186023- update to version 3.0.6, see: https://www.knot-dns.cz/2021-05-12-version-306.html- Make /etc/knot directory owned by knot - fix reload action- Update descriptions, remove unsubstantiated claims.- update to version 3.0.5, see: https://www.knot-dns.cz/2021-03-25-version-305.html - Update description based on homepage- Trim marketing wording from description. - Drop old rpm constructs.- version update to 3.0.4, see: https://www.knot-dns.cz/2021-01-20-version-304.html- add incompatibility warning about 1.6.X version when updateing - rename back to knot- version update to 3.0.3- version update to 2.9.7, see: https://www.knot-dns.cz/2020-08-31-version-296.html https://www.knot-dns.cz/2020-10-09-version-297.html - obsolete only pre-2.0 version- remove rosedb conditional as lmdb is required in general now- replace conflicts with Provides/Obsoletes- fix dependency: python-Sphinx -> python3-Sphinx- use upstream example config file with correct syntax- version update to 2.9.5 - Bugfixes - Old ZSK can be withdrawn too early during a ZSK rollover if maximum zone TTL is computed automatically - Server responds SERVFAIL to ANY queries on empty non-terminal nodes - Improvements - Also module onlinesign returns minimized responses to ANY queries - Linking against libcap-ng can be disabled via a configure option- version update to 2.9.4 see NEWS- version update to 2.9.2 see NEWS- update to 2.7.6 - Improvements - Zone status also shows when the zone load is scheduled - Server workers status also shows background workers utilization - Default control timeout for knotc was increased to 10 seconds - Pkg-config files contain auxiliary variable with library filename - Bugfixes - Configuration commit or server reload can drop some pending zone events - Nonempty zone journal is created even though it's disabled [#635] - Zone is completely re-signed during empty dynamic update processing - Server can crash when storing a big zone difference to the journal - Failed to link on FreeBSD 12 with Clang- update to 2.7.5 - Features: - Keymgr supports NSEC3 salt handling - Improvements: - Zone history in journal is dropped apon AXFR-like zone update - Libdnssec is no longer linked against libm #628 - Libdnssec is explicitly linked against libpthread if PKCS #11 enabled #629 - Better support for libknot packaging in Python - Manually generated KSK is 'ready' by default - Kdig supports '+timeout' as an alias for '+time' - Kdig supports '+nocomments' option - Kdig no longer prints empty lines between retries - Kdig returns failure if operations not successfully resolved [#632] - Fixed repeating of the 'KSK submission, waiting for confirmation' log - Various improvements in documentation, Dockerfile, and tests - Bugfixes: - Knotc fails to unset huge configuration section - Kjournalprint sometimes fails to display zone journal content - Improper timing of ZSK removal during ZSK rollover - Missing UTC time zone indication in the 'iso' keymgr list output - A race condition in the online signing module- update to 2.7.4 Features: - -------- - Added SNI configuration for TLS in kdig (Thanks to Alexander Schultz) Improvements: - ------------ - Added warning log when DNSSEC events not successfully scheduled - New semantic check on timer values in keymgr - DS query no longer asks other addresses if got a negative answer - Reintroduced 'rollover' configuration option for CDS/CDNSKEY publication - Extended logging for zone loading - Various documentation improvements Bugfixes: - -------- - Failed to import module configuration #613 - Improper Cflags value in libknot.pc if built with embedded LMDB #615 - IXFR doesn't fall back to AXFR if malformed reply - DNSSEC events not correctly scheduled for empty zone updates - During algorithm rollover old keys get removed before DS TTL expires #617 - Maximum zone's RRSIG TTL not considered during algorithm rollover #620- seems we no longer need jansson- limit geoip support to opensuse- update to 2.7.3 - Features: - New queryacl module for query access control - Configurable answer rrset rotation #612 - Configurable NSEC bitmap in online signing - Improvements: - Better error logging for KASP DB operations #601 - Some documentation improvements - Bugfixes: - Keymgr "list" output doesn't show key size for ECDSA algorithms #602 - Failed to link statically with embedded LMDB - Configuration commit causes zone reload for all zones - The statistics module overlooks TSIG record in a request - Improper processing of an AXFR-style-IXFR response consisting of one-record messages - Race condition in online signing during key rollover #600 - Server can crash if geoip module is enabled in the geo mode - changes from 2.7.2 - Improvements: - Keymgr list command displays also key size - Kjournalprint displays total occupied size in the debug mode - Server doesn't stop if failed to load a shared module from the module directory - Libraries libcap-ng, pthread, and dl are linked selectively if needed - Bugfixes: - Sometimes incorrect result from dnssec_nsec_bitmap_contains (libdnssec) - Server can crash when loading zone file difference and zone-in-journal is set - Incorrect treatment of specific queries in the module RRL - Failed to link module Cookies as a shared library - changes from 2.7.1 - Improvements: - Added zone wire size information to zone loading log message - Added debug log message for each unsuccessful remote address operation - Various improvements for packaging - Bugfixes: - Incompatible handling of RRSIG TTL value when creating a DNS message - Incorrect RRSIG TTL value in zone differences and knotc zone operation outputs - Default configure prefix is ignored - changes from 2.7.0 - Features: - New DNS Cookies module and related '+cookie' kdig option - New module for response tailoring according to client's subnet or geographic location - General EDNS Client Subnet support in the server - OSS-Fuzz integration (Thanks to Jonathan Foote) - New '+ednsopt' kdig option (Thanks to Jan Včelák) - Online Signing support for automatic key rollover - Non-normal file (e.g. pipe) loading support in zscanner #542 - Automatic SOA serial incrementation if non-empty zone difference - New zone file load option for ignoring zone file's SOA serial - New build-time option for alternative malloc specification - Structured logging for DNSSEC key submission event - Empty QNAME support in kdig - Improvements: - Various library and server optimizations - Reduced memory consumption of outgoing IXFR processing - Linux capabilities use overhaul #546 (Thanks to Robert Edmonds) - Online Signing properly signs delegations and CNAME records - CDS/CDNSKEY rrset is signed with KSK instead of ZSK - DNSSEC-related records are ignored when loading zone difference with signing enabled - Minimum allowed RSA key length was increased to 1024 - Bugfixes: - Possible uninitialized address buffer use in zscanner - Possible index overflow during multiline record parsing in zscanner - kdig +tls sometimes consumes 100 % CPU #561 - Single-Type Signing doesn't work with single ZSK key #566 - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - Compatibility: - Removed obsolete RRL configuration - Removed obsolete module names 'mod-online-sign' and 'mod-synth-record' - Removed obsolete 'ixfr-from-differences' configuration option - Removed old journal migration - Removed module rosedb - changes from 2.6.9 - Improvements: - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation - Bugfixes: - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - packaging changes: - enabled geoip module: new BR: pkgconfig(libmaxminddb) - enabled cookies module - enabled queryacl module- update to 2.6.8 - Features: - New 'import-pkcs11' command in keymgr - Improvements: - Unixtime serial policy mimics Bind – increment if lower #593 - Bugfixes: - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy [#589] - update to 2.6.7 - Features: - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) - Improvements: - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination - Bugfixes: - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback mode- Update to 2.6.6 - Features: - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation - Improvements: - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination - Bugfixes: - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- update to 2.6.5 - Features: - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set - Improvements: - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates - Bugfixes: - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations- update to 2.6.4 see /usr/share/doc/packages/knot2/NEWS- fix tmpfiles scriptlet- package /var/lib/knot - run tmpfiles scriptlet during install- update to 2.5.3 see /usr/share/doc/packages/knot2/NEWS - use libidn2 on TW and 42.3 - following modules stay static: - dnsproxy - onlinesign - moved modules to shared building: - dnstap - noudp - rosedb - rrl - stats - synthrecord - whoami- update to 2.4.1 see /usr/share/doc/packages/knot2/NEWS- update to 2.2.1 - Bugfixes: - Fix separate logging of server and zone events - Fix concurrent zone file flushing with many zones - Fix possible server crash with empty hostname on OpenWRT - Fix control timeout parsing in knotc - Fix "Environment maxreaders limit reached" error in knotc - Don't apply journal changes on modified zone file - Remove broken LTO option from configure script - Enable multiple zone names completion in interactive knotc - Set the TC flag in a response if a glue doesn't fit the response - Disallow server reload when there is an active configuration transaction - Improvements: - Distinguish unavailable zones from zones with zero serial in log messages - Log warning and error messages to standard error output in all utilities - Document tested PKCS #11 devices - Extended Python configuration interface- update to 2.2.0 - Bugfixes: - Fix build dependencies on FreeBSD - Fix query/response message type setting in dnstap module - Fix remote address retrieval from dnstap capture in kdig - Fix global modules execution for queries hitting existing zones - Fix execution of semantic checks after an IXFR transfer - Fix PKCS#11 support detection at build time - Fix kdig failure when the first AXFR message contains just the SOA record - Exclude non-authoritative types from NSEC/NSEC3 bitmap at a delegation - Mark PKCS#11 generated keys as sensitive (required by Luna SA) - Fix error when removing the only zone from the server - Don't abort knotc transaction when some check fails - Features: - URI and CAA resource record types support - RRL client address based white list - knotc interactive mode - Improvements: - Consistent IXFR error messages - Various fixes for better compatibility with PKCS#11 devices - Various keymgr user interface improvements - Better zone event scheduler performance with many zones - New server control interface - kdig uses local resolver if resolv.conf is empty - new BR libedit-devel for the interactive mode- update to 2.1.1 - Bugfixes: - DNSSEC: Allow import of duplicate private key into the KASP - DNSSEC: Avoid duplicate NSEC for Wildcard No Data answer - Fix server crash when an incomming transfer is in progress and reload is issued - Fix socket polling when configured with many interfaces and threads - Fix compilation against Nettle 3.2 - Improvements: - Select correct source address for UDP messages recieved on ANY address - Extend documentation of knotc commands - drop knot-2.1.0_pkcs11_check.patch- enable libcap-ng- fix configure check for pkcs11 support: adds knot-2.1.0_pkcs11_check.patch- fix soversions- update to 2.1.0 - Features: - Per-thread UDP socket binding using SO_REUSEPORT on Linux - Support for dynamic configuration database - DNSSEC: Support for cryptographic tokens via PKCS #11 interface - DNSSEC: Experimental support for online signing - Improvements: - Support for zone file name patterns - Configurable location of zone timer database - Non-blocking network operations and better timeout handling - Caching of Critical configuration values for better performance - Logging of ACL failures - RRL: Add rate-limit-slip zero support to drop all responses - RRL: Document behavior for different rate-limit-slip options - kdig: Warning instead of error on TSIG validation failure - Cleanup of support libraries interfaces (libknot, libzscanner, libdnssec) - Remove possibly insecure server control over a network socket - Remove implementation limit for the number of network interfaces - Bugfixes: - synth-record module: Fix application of default configuration options - TSIG: Allow compressed TSIG name when forwarding DDNS updates - Schedule zone bootstrap after slave zone fails to load from disk - avoid activating the intree copy of lmdb- update to 2.0.2 - Out-of-bound read in packet parser for malformed NAPTR records (LibFuzzer)- split out shared libraries, knot-resolver uses some of them and atm we are forced to install the whole knot2 package.- lmdb seems no longer optional- create a new branch for knot 2.x starting with 2.0.1 - Bugfixes: - Do not reload expired zones on 'knotc reload' and server startup - Fix rare race-condition in event scheduling causing delayed event execution - Fix skipping of non-authoritative nodes in NSEC proofs - Fix TC flag setting in RRL slipped answers - Disable domain name compression for root label - Log via journald only when running under systemd - Fix CNAME following when quering for NSEC RR type - Fix refreshing of DNSSEC signatures for zone keys - Fix binding an unavailable IPv6 address on Linux (IP_FREEBIND) - Fix infinite loop in knotc zonestatus and memstats - Fix memory leak in configuration on server shutdown - Fix broken dnsproxy module - Fix DNSSEC KASP timestamps parsing in strict POSIX environment - fix multi value parsing on big-endian - Adapt to Nettle 3 API break causing base64 decoding failures on big-endian - Features: - Add 'keymgr zone key ds' to show key's DS record - Add 'keymgr tsig generate' to generate TSIG keys - Add query module scoping to process either all queries or zone queries only - Add support for file name globbing in config file includes - Add 'request-edns-option' config option to add custom EDNS0 option into server initiated queries - Improvements: - Send minimal responses (remove NS from Authority section for NOERROR) - Update persistent timers only on shutdown for better performance - Allow change of RR TTL over DDNS - Documentation fixes, updates, and improvements in formatting - Install yparser and zscanner header files - Improve lookup of libsystemd build dependencies - Fix compilation warnings in endian conversion functions on OpenBSD - changes in knot 2.0.0 - Bugfixes: - Fix lost NOTIFY message if received during zone transfer - Disable fast zone parser when compiled in Clang (workaround for Clang bug) - kdig: Record correct dnstap SocketProtocol when retrying over TCP - kdig: Hide TSIG section with +noall - Do not set AA flag for AXFR/IXFR queries - Features: - DNSSEC: separate library, switch to GnuTLS, new utilities - DNSSEC: basic KASP support (generate initial keys, ZSK rollover) - Configuration: New text format in YAML, binary store in LMDB - Zone parser: Split long TXT/SPF strings into multiple strings - kdig: Add generic dump style option (+generic) - Try all master servers in multi-master environment - Improved remotes and ACLs (multiple addresses, multiple keys) - Basic support for zone file patterns (%s to substitute zone name) - Disable zone file synchronization by setting 'zonefile_sync' to '-1' - knsupdate: Add input prompt in interactive mode and 'quit' command - knsupdate: Allow TSIG algorithm specification in interactive prompt - Improvements: - Zone dump: Do not write class for SOA record (unified with other RR types) - Zone dump: Do not write master server address into the zone file - Documentation: Manual pages are included in HTML and PDF - drop patches which are included upstream: 0001-loosen-openssl-dependency.patch 0002-make-configure.ac-compatible-with-old-tools.patch - also drop all buildrequires just needed for autoreconf - new buildrequires: pkgconfig(gnutls) >= 3 pkgconfig(nettle) pkgconfig(jansson) - create devel subpackage - enable rosedb and bash completion- local state dir should be just /var- enable dnstap support for factory and newer: - new BR: protobuf-c and libfstrm-devel - prepared lto support but not enabled yet, still need to find out which distros support it- update to 1.6.3 - Performance drop for NSEC-signed zones - Proper handling of TCP short-writes - Out-of-bound read in zone parser for long domain names in origin (AFL fuzzer) - Out-of-bound read in packet parser for TSIG RR without RDATA (AFL fuzzer) - Out-of-bound read in packet parser for malformed NAPTR RR (AFL fuzzer) - CDS and CDNSKEY support in zone parser - Add defaults for TCP config options into documentation - Detailed error message if zone reload fails - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch- update to 1.6.2 - Limiting number of parallel TCP clients (max-tcp-clients config option) - Ignore refresh and transfer events on non-slave zones - Compilation with Dnstap support on FreeBSD - Possible file descriptor leak when terminating inactive TCP clients - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch - moved autoreconf -fi to %build so it wont be tried in quilt setup or similar tools - move up the %if case for systemd in for the preun scriptlet to avoid warning about empty scripts on non systemd distributions. - used xz tarball: new buildrequires xz- Add deps on the docu packages to regen documentation - Enable systemd integration fully - Add dep on libidn - Cleanup with spec-cleaner- Only require lmdb-devel on (Open)SUSE 13.2 and higher- Updated to 1.6.1 Bugfixes: - Journal file would sometimes outgrow its set limit - Fixed incompatibility with OpenSSL 0.9.8 - Proper handling when machine hostname cannot be retreived Features: - Support for DNSSEC Single Type Signing Scheme - Compile with lmdb-devel to add support for persistent timers- Updated to 1.6.0 Bugfixes: - Fix zone expiration when AXFR/IXFR is being refused by master - Fix forced zone refresh on slave (knotc refresh -f) - Persistent timers database opening after privileges has been dropped - DNSSEC: RFC compliant processing of letter case in RDATA domain names - EDNS: Return minimal error response for queries with unsupported version - EDNS: Fix interpretation of Extended RCODE Improvements: - Maximal size of persistent timers database increased from 10 MB to 100 MB - Added logging of persistent timers database errors Features: - Persistent timers for slave zones (expire, refresh, and flush)/sbin/ldconfig/sbin/ldconfigobs-power8-03 16330784243.1.2-bp153.2.3.23.1.2-bp153.2.3.2libdnssec.so.8libdnssec.so.8.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protectionobs://build.opensuse.org/openSUSE:Maintenance:17006/openSUSE_Backports_SLE-15-SP3_Update/a08d5cf2d25af1f2ab7fa81a995d2fc0-knot.openSUSE_Backports_SLE-15-SP3_Updatecpioxz5ppc64le-suse-linuxELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=c5ade133f947300c3c5fe31a97c45dfcb9fd4d94, not stripped PRRR RRRRRQF0 eN,utf-876b24db23c6e52979d9812902482d891e430154033fc5797f9e50f26a790c7a6?7zXZ !t/e] cr$x#E}_q16|i#_h?fm 86lq0G4(!<<˃W_8x}W 2;<jEGBκeRYOKy ZG..Tt!Ʊ68]Vk::=WYBe?s+:PMձ˧7}܂܋/J;H_觢3sń|P7:-\I#)f;H-&uTLWz|0U$L^_U.T*wH(}G&3{B{y=~V;MO^3Ԁ B.i_ƁW}6zEK5޾eigl=o&2IƩ&$ߒPW}'&xC(}\T`A[<rG1%B+>C*$W\r-4!KuOö30'Iu% zҩOMIrh,G_ bwQ컓߭8qv . FQĈ5&0(ca#T--QE;05+㯎v%Ɂh|Tx_F1 IPfR >&wO.Rڨwܿ$zV9Iӈ>u<vGwϧ|`_3}:%ғ`z;=tQ ,g`&Ǵ&TŖf&-b-p֥r( PZ=T :6ci@piKrXt4F֏5!z${e ?X50rg Ud_:6zKoK d-> aF3ha>5ȐV#4tbcYR.x;~ ¬#ts_ +Elё؅ԧ01;4HƮz̺M)TM x& R[aJdgxN,̕0^L :y+/[Hw릅= gj}anuDS;3).K[$fA DPj$ jII]uI<7s82W {D8^v|m{6/7b<۳rdlEOf̴1{-X]]2ot2I>h\-ʭ]#]NI3 $ොwFHR-3u2C!b;?¬ۓN?9"=U6PPMwwM9cHbg,;M[DXJaW;}* $TtR,菫E:^4n2Kv,OlbQ`âgON|Ծx Ι0, = m|;IeE I+1!Y[:29P@"G0P(6]@9k{,^etuq?;7o jF/>U-Fm pCf H@p#_~t%^zD ]bq1@Jehǘ1Ilqe/HfRVo9͠ l݊)wWh&wOE@xJ+(Uc˚pQ&<4lep|^.ɂڢ9MEvֺ@WI u]$(ujgxaDC=lUlt@M_:WdPt54LeCH׍BG؃7v3^`bHl1jz氺>5/eur_zíʿ`T К'z5~ R+.lJ?k t$wdzwiA !wD,ɐ}l` yƘύH-գ8Q Yiø1|?„TefO{9108ݱ,oKixɖ/5dkB±FoYSrWL@;P%+y?(Q$SKN'b#/J;6zEŅKE)KEș3r 0 c/R8RN$+[kAb \x ΛԄ-m5}b ٴT-n#A1'5<{ʻ;fdQ=hGzO\5d<^EfklkX &HnCPJ{ ?H=@PŸxf{Pg n3(y*[ODԻu?ij323Ʊ}$8Kjq &@`gg}6}]cNӃ*wna*朐:L|zף!R{\*|k@s8|OMTRBv!BH$R3fAv nЗLބL~FN}ꪰ/$jn F'%o͛Bvj, x 27I6bզLNuT; mrR yP4wA ̫$aԃ{Gv{%X*Ng29zTt`ToѮ?s(t]yu`vV 9gSH|O9Qq/5"v wnMv0 çyMո_CW aopD?kt쫍Bi0+=wwbC.s4{D}RB;{xeC4}5 gsr!Kz(<@Iksb[$NNry߮Rֈ}iP.9̦ojr>n- BP`Vd_o-p< uZ'f 1W{vJ9pSKz@Sb4zJ[, N^)ex'UmgR)xP\ϯGo5NϏev)Ѓ]s:cc\I+3?lAQ;o`e_ﵧ]#7c_둦TxFm (e7ƒ3KE_Qo68aE/<{m*s-Rw) =oǰ'P&֜|q&T4]tGbJpH9yψo%_⺝1ի]B44uWX0%7S(l/rVP,RƬvpx_H)TOD=9UԀqvv[" C(0RpMF~NnִFV!.afMMlSu2Wԡ9d2b Kq5Q#M > RR韲d>wbzKK~n'|bz1PJxS˰Ι$+_7:Į  ӧqi 3͠j/t>KSy7_>~ț\ f%]&1N&!O4fXT:wm줒bIP&AeL< V'B75i.dC֢Cp3wa*NʗiY2D%.Jj2S}TZr .|mO{])lǫHNj2|#kLG\g˳̹Zfd8k 8hgyx86*\i6߷[ A|NRa9ǬNSR-?k-680ߜDžUL12c^R9Fitw7Y1߹AS#M,d n>!'0@|0U ͞+IIѓڥSpTOtyb&鑗h:0.@/L`v{I_xRgpc u/9d8 qyi]7=q; X3kvU֪<;n)8VX5,!$y?Tt &Pםݲ3M̦mAÁ$1Tˋ޿0N6^\(Ώ1DwnT,z)_% yu ~~t#A j7y1LҕCOө2giه:W{kVXf[ & 5WF7)s0vFotŊ!0D1H:9!q 6^Z>azZ|>rBŴW|DtcqJd;q~w#(wi$^WΔREyB #􍈦T uG';Ey̋:1yȅD!tZO= \M+*~sguX?b+a5B&\~y 3 Gil#>)Z9116W"t\g_*尪A2eI/P>k>5>\Z:yDJ*rV<#Bja~͗#,1inȹCpmWR 2\rk0o̓lJ*8(OdB:֠ME`ӭ,8|!(w$punBny (.ev5u\KdR\$hf&'3 V0wɫH$ `*I˅s򞩲Oig$|脪zwXIyh4qV\b!1wJ` I1hdQbX|CToHT`-KR+%7V3dVSD!ZJWic dypX/񈐡Wժtԫ;H^h*nML|`oȡq jؒ{i%תruS=DWv5!0>cL~0"ڒ}5ܢ^ct+Bo37Q@c=BfG]F%?WΡw}.ʡAUAD# {˪+4;ԇⶎhg_<=n9 ]yMƮٙI5[žmBl{I ^a#{K4m~HBi0A2vNޭx/gL(Β$;m"ln~{:Z`-7͠v G+e񚮞'9U@BUL<^L aB`A~* lG9OD'*j-o iK_| 1=Pe;sw !i"&Zz-ۺх7WA Ȣ/ Y!3 }>9,wqSV 4TnOT,,.>hkd'"$Z|kj .#[D΍֫P/,u<8!Ay^WhtKkj#Av^˰MՔ_Ju4{`.v4^O^rQGt$nLp-/j8 gJkH>v`\-]<pu8Y%*aǙcMjZ)X}u |B @< !ド@REO4!z#!}N qO[zex2{?D!-0kzX~rp s8 6MU෋g zr")W $d7&y YL,Ok߉Ǩw}窦zEаbcq#뀈9O~NXF| .|< 0Ϝ(Gˌǎ$ZZժg vXx?=qV9im)I%*Y<eM!]Myܱ |l b_[(/xmhX7^' ?QQ9-w&^JlOFތ@MV.iڐ9es1K;8LE _79' H$ljeC̀kc aۤp:~ )$ F#!NgB+Qvp;xwTY8\9[ףK7YsAJUh"W .K;IG̘!HX[1v}_~Y,Pxj{d8RE+dd-kC&iKCYP0zc Fx s@@]m\+a0 ;8Zz1֌㶵xQ^9B'h*}S'Y's-ϋhk+AEU+ȃF*>-1I=~N.-؄{Yn]5%bQ3&!]-edV-8߅5̮`3.ŋk׋OӶvb$`Wo~?g> z(yhC& dclsr/ `77n/؍/6?..6e+gt)_JdSڹ=G6B PON?ȍgڎE,4۲m^j^|oAL06vTJeV YpJ}2Ak]!US %m^ɥݩ6(̴eLz\ŰC <.x`R'efh/(խey@\|x v]'AFٔ /ڶ0RӏY}1'쌍'^SU%w|@{,pb0IT\N%YK \ U=Iv͖ۤeTSny &:`'eא2]̥k 㪐u.u^o\p I[85XAQԀ&!rl%!^,oc9Cq<>eY6y-85|^1M-L~0ۙ "hr8x 6_Hi ,<-C 㞠TS>2'/MoMKnඬ툸kSY6H˥++ǛɓG*':i׷?3El+V?ߊ үTrkH0W!N7(4L@)Gs~kdHG/GZȵM-GdԟJS7 SfȂ߼hl9VG+|YHo4o0+FնU%LWk5UmDS%[w\UAŊi;wlP*\hb 08oi:WX5.=(B7A4}.(-/7kBvG2ќ) w6l ބb)Pq`/MyJ Rp#NP#P"6bh½(0f^!gŕW nQTU守74Xs5oDum?.t2mdbЃ@Rn9P2S~Svg7DS]S6e̿٦2AU Iό,%vz#DBA]4-(X}tW$WMtI" `G?] M3f)𴳻E!@w?޿B3|<"OP@_wM)+AM/bnqd=>j+2'T;V41sS=n;U B(r m߇S&T1a1?pTMȸ ZѠrj3GPx044݁(XM~rj+Y<~wrpK!`r1nK u2԰y򧈒a N)" 1UθcWWk ')]-y z{19c&P$yb '[V],6xDUcs24yt ΡxzR(DhniVcyEs\ƻ>N4>uFobRY~W;X1@K@^<݂4ΖNrYP/h/C]8)Z;3(P}WEӀK"|Bg A,ˈg ͮ[q뛁8e"ʖ3*!pU8 k<"e h-(kFMLg8L}Mw'CBg=V1Y. Á7鳨+1V9l#I#h.8s4-`V U>|Kjn87sU(=>卯*hNl~Zobnmmo"bK<0XFSٚQP1q6poAY5.#0?&Uic/CQ{pj:Y$elaFpiaO >$$?qj_o~0o? TIP$N+| W=[HhBh= 6%osv:/GۨJz +=mg؜NS|s<弮D񋾏&LH/'c\Dg #\nΊ ~1ګךA^mGѮaA";nE؍=\<=Ǐ17djnTP\ʃN\n44fR(uBTU >^琱5 jF׾X mBB_)-Jho$K+]dp;ƊVĻyP}=<i=IuQaXQzIqoz{8D b@k*cS =`VR$Ò c;2ˢ$&F|23GjhLF}1)㋩5Mmk9,0ܘ>]nL3(8`ѕ!m1R"}'͸5;=Gsrաlm?0^/!(l5O?l|Jw9/OgIV7s°AyKcP zr5*H:bT4E, +p[Dȝe8'l?-#\qSUn-?4=׃΍!i\ ,3U)Z IHk( ݸF etD1'gP8{ ◠| s3<' ' D  r:)AvIG\"_zjnu)lgjBn1h]>2Aӹz2&+jݢ&(CgkX#I`bQ!'Mya+/ ƨUm&qómP!N:5.6H2 #Vpt- vz5Ɯ{̗ ȴuճ <}15f]wM?ݦc`є(T܇..bq gٺSg,!mEnrqEV+ޗ4 /][ 'v~0zE?]ˈVEXVAʨ9Wey;dJT8ؾۍ /b3$Ns=EW'هtSQ$? 0< ym!^0F|- < UssXjGcLOkfq$gQ;+E}"DG`fb5|g|y&z9@=i\cŕ`jt2 pu(I2MN2'Z3y aD}J*.dN+kd43L)G g٩%@V*lG2Dͅ.¾D2`|9U/aj[{J%:i_t{&o޺S3j(Cӏص`_Yj[~zwϥWr=lM7~qx<Or=g;4iEXsLiiw`/VM]Ùbga/}-G^ϷQW=ƨg7P> ۾6q*c *ۘz?Ԣ5:evmEpT2m5ms1/>-W9ٔHV4=!WVa@ t.ܧn X(ED㧹f+=77Q !,@V< t# r,'bcidElI(^Z|*+V=P /yphtWP6QX⪦E+- K%X5C-GdV:h-O/@:$4~ޞ˗;8y1N{#(3=Ef]4T["CUMGZa~B@J 9RiC: ֏'`c}W~M^PC^w|[^Lˌ84Ljc#;S ULVnxU`Uq רn sxK.WYo$Cp>cڛ"g`o _\neFZ+%!KMu9SiK(J_$R) 0i!08bIh]w8a%gFD{^V؍rD/GGp+J\d@T'*gB62_؆Z Z1˥| PhQ>ɝ?er"'‰hr1(r-봏v>xh Z[>+j`S_m|l짪 \DA 7[DRWPUeM )yV|5A>^].Ey#6CSz +#?LK{qfԤ\&*:ǫc)F*NUi_})ךeݔplIduPl\GxY͞cν1UOa`!Y0^ǂaSa.^  E ҉:dUKLĔ߲kvT{eQSb,pߋP)V8 G6\|gƵ\J}8d%U\άv0FG}Y֬}}e 3Ul0@Z~;HOfcO-[lZNz(gQXh<]O%ꆛmResc!8Kk]^$  yun~6#S kmčXd/[/ּ=rZ! e}:Hρ>J^`vT7|[2*O:l XL,iMŵ~Y]}aT<>ӡ]_/sJ{~)@">*.0՞apc9Iqɴ W6.BPs؋n|@Ie9(Vp+O(9Wηu#_DYɗ8[{2fp> ݼP,Rg%= gˀ$J8M>}duGj}IowlS3Qt l|y6|i&1*]Y< V]6MCYP]"jEZFbl9-M؅*S;GvDPiM͒,~Dh Q:Ig]ɍ#&_:Gnh9X2ۊ4ryYHGjg؊vf)\mt@8a}D0etd8[lX+SXrJ*uʵä@@v_|TC)hY% ?:k(`uŤyR2${FlA]MʝGdDC$%}wa̴ e |+&MQYz^LѤvGkuČ%'P8(z-uR30ش~tte2Oj-ހ3xRmzPO:o҃Os)6'J4ދo\Djn6`0&Xԉ)-S/!bۑO,5cq'_Hdy=wD.Dq, NyRcU&ǟ,MN!&)Xf ;/JecOeY;X;Ólڏ|0r"=XŅ0$-ra>pcX5`B2^*n+-7\AU:k EvndhFC.Ae%4Rf#9@iW؟)w[9YМ.Öz DMF4gȎ1d6uh^U)C+#~[@t<--)nE8⿑j5gxi&<{0CP]U8W6?i|lxwZTaƓ~ +&tjW'e׀_2=hD17,/|)pmͱC͡۾STh"nLhun:^?i9^C?&ْ2|rݾ`g Y.4eXWT|45w(kmZ# -kqy鐜`qIwM7qXB+ÐPIz15 w{D xe;.s%_(<oAţANJQ;7n >otVU{`Gt~mwU6OomMp$P11W> SSrܳ@=}WO[W'yg,2a݄Zp,O #/)}8ĮoJ͒ܳ*qx&~V-;k1 edl~]93yqרl9L莁r=:UϏs"㡘ިXXs!Y[3}NfFzԓ#= Frkgڿ !`֐.,I0A0'}IeFe*)?''c\MGg4x[X[g[ʄ}Q#҈4q3qBf~Pˣ>k C -,!XB_mi̯;y򛨁xFDfS=q#\7Eˀ잣ۮ# yPy$e,_8 y}K?b6Op3Y5:fBSe+B}`l>]=>l= ߤn)<.)ZVK7V%Ph4cւg+A: bAMZLI%VBG|BLB3fM$ɱ ߲tzd`&VgzCi]˻uwuዒ9ǿc=Pڧ;}@Z`8 (w`Dԁ󷭴r'՗#,'UOoUeS[ȇDNS†xXJ˗l4U +V330ޅv&-˙ %'# gz 5rRG-ڞ)'- {cy#Opa[z4VJT߻C4U)@>+N)ƗMz;2<iNMI_$O,PHĶ9bRrRe?DꊚxlQLsZh'Zq5s$5q@y⚟9\uv$K,5>E<xsW(K 4F۫`?[(ptJI5j1װ W$58j.f-:vRHTt H `G0y3^Ҫudpxd1R,ZaHylW˥:pZCכ[Q;MuQ4+g 8^ChlU-K5{PL3I]-_k['}=zD||G xkbk+Os`v 6J?UywSߋM )ӝTrݒslik> ֔HE"H7\y7yzo(_=bdg8^ԇϝ~Ί#ebftuJwsED N8KtfbF 349C嬸1]Q1j\T #\+F Sm-z҇[6TJpY6J&~?E =ygxɀ M:,;O+5_\sx@:TA6zB׸rF ū"{.Soh|o+ۻ 6~Th#@/\/vsR~tӏ=@Lx87,<_ʒ܃}Iܕ>*^Nd:ߏTM=ʃ _uSvwL!pZQo} -|":v ,|u0®nqcds:VXWAԙ0= xd"92xKk~=z ӀH.9t@|Z.x!<j5 JOȬHaT5:ʝ8W4ٚ?fK8ރ&Iׄ]^C` bуʭWw%sT57L9>l#U=|ø}G8.C<,e"6Enm?QT'JPMˎ-'QBjL8P͔A}3x93!Ot)q1b"8"i;4Op>S$Yw3-|Q|VNmtUPK[8]b7]%8B^z5[ksh9Lo)^2USQq!0"Əa${[Z/*-V uwM^ā_ТZ>,*ֿOVTݡ((k;Úvݳ Ač ä2=:I>1R4KNn>(aG/ }Ȑq2Lg'x-Rn6 ̫%i~u3PK){'|KOMsB\qU'52Tڊvh||Se"f37IvaϡZR Pt;n d$.i)֊{3)^N!r]MwHReM9ni'Mӎc1>:uo->0 M>le \ZTw*,iSS^=QFw~~A `Af"3]bHo|4G;#;ɏbduC!w,oW+P&i1²x{$nnl~{ O4W3_R:h0?c zڝx/I$uzuʺi]Q,P:PP[Č'>N2,y*7қ!7z@"dhCCmhE[eg$pxGdrʉ\$I]6S73t[#j+$ݡS,a hv0n/Es3ժ{Rzb5\ˁt!G6rmR>8:#EM8]ʇ'&5qz  n6d;NAtjWfoVSu7{*5S0Y6w1xYR~x [l|wn&& ֱhwD)`6i4n0Unz`C06W+$i6xodYLڷ~1_~F㧁<"C,m͢9K]E ^,bpaQy Oz|:QM<>I^x+rB!^tdL]&EypLn<0?l +ģ,n7' # hߤ 9l9@1â/XTV@j.&AacQB4`SU(0S&[? fSKE h'0p/ڦTk޼8+Vz^{*]RD-;?} !ɧ Etpl,6zew3} 7Vmvf%\3%CJ9JH>3 z Z*Qݻl'(Y;/M9u]bta*t]b<^Ԯ &@F S|9y[w&n %Ctد4]zz0Ncdӵ6SnB.M{cJ0f"q͉sdoVH||UeFe'Qv%\ +OS\b-&w)LC|h4?Q3FpcxȾDAMVϧm(Y M4ŕ'"a̖oLG39GD* FWb~ r( Th|;* F߾^g%9P,Q;<#M:|kU dQ%D0. ;sO\mZ 'xjEP߻T,XPn2ڕ,B߁\辥Ǐ%[eXi%ƕ?- jIlA5~Pn=t]W!Eaos50*I~1+]H,&2`#?xЦHJ͗CtCb >{ I`!]glڈ*^DNJ!S*~:J"a<ҷ*g:d`FAH[mVre'GPA L# gf?83gMAt,TqE/DG"nj4 #G/#XPkbޞPSnbΦgVS' _/@k>"8޳mRjx/ tbwfyS]P~W4K4"ڵA:;炦=&5y]F(L~eeBau5)lE䱓4%v#0crC3%LӸa<.Ҋ%|x?&Rs `E.[K< k|K?G$< &aI E}; cy KRk"A4SZ1=T@&?eXlsLP?ƗN Fg=氝6jLY^{I]OR%qN[){u,#f}c ?#9!j!*4zTz5yd~OOdPs̜Jr}C:Vu>f3~S/Te[eOpC<4EDr^o1"dU+o:k%Ő#T} wcȕONQM&%TheUzn.x@ua;l̢O|_Xe+ HjԦu`+nIVG NK{T|Žl A9ᶴPmQ=솋uϐŽ'#]glBa cZbcϲ.pݡbnVǔ>Gk>8@8Tf&aLL{>W)d֝S dz+=7>72F+W ~1t]DH[WPRge >=Ef>-&JWE@kg/ьE[TYNXd A j@3{nˑ"tQc,FI"#]иv^la՝(єzT S~ Ʈai E$u Cf&( 'Y2rl7fZ~wsP M cܞmĎ60` KE98qX8yː- 7xJ"eoF6ȴҢ8@DS'oe [֦ 5/ۂ~v泝)-~@jٮ;d3d":0a[c{ EPu*r׻fѨ! $cCrjM :9=ga!dm "4:K=) ?aL-7s.tkES%*{ N7 yy`dYis:$2J3pV`<߬$rI_􎬧;1I%Q %P)qG&S*9:cc 2S`Y^Za;ïrZ_]1l\\s!mq=DS 5r->90Ŭ~0蝮 |]Q޶lۍ34dͦ*njt|@d8@MMwW7f1j&>UbXAcWm** *Jo d:g"(% FߴLjt|!fBDzMTV|kELj1mYC&bIX O"H:Tprws /h.Ue]\yLFQ^_/]UhŔLRhnQIdԓ_־*W y h(\ %u0)E54)bw:ǩv:OwVrz By= 31 &L5<>=ҖKIR1DaTwio}ƨg#T?8_?1J`IM?Ћw"-3 .^f%id)_^Jp #ix-A&=րpMLJz],p nc!:Q€wm^qov@1nj: ITE4q}ۈ.Ԕ o `-*7m*mi"ԉ)w'G '=3?p-u'3G@hĺ%Z-Iݷ}hV5%~tY7!~_|QEjP~^Y[ c`}*DYSaٸ\,Ŭ4QJo8,'>٦ -iV3퉭tm/t|gjqHG~+iv "y"Fy -d=9@pbHY tOcӾp"07yoƥ2@m[*"`/9鷂tp 3m^ںxu[Q+t 2VA)D:6>$OZ;ʿ1Y(UrHT.ܲ9HbTT0'Ϙxxb,N<\9!ʏqw=>JxgUXx s̄?!5<\omY~S=([ƌW%FIߗ >v]fGޡ!l8( d:h1`bįtdX/ #/ FOgG_:DaGݯCr~Wߍx\R&=."9v;`+?JPU.}T7 ;8xN-M샞roW4#K +/*&@iBK:UeWI8H(ҟ`p<9dNfo;X2>Qf ]1py̺^ý)\|۱pVz݊bmP{T>عXt|GEvn6@v&y%2 =ĶU_Q76hD`rpز09W$a,Vud9UHww'QFzL!TR7E-ꖜ붯 ٍ9 ’MjhElm*NV;چ]a^aաDoblvwy5<}լq"i&bz>Sg[Ϳ&ML3N8dd7aZ:O2{+K>;h?/_mY5_%֍zӌ=[] w.CTrC8K4_!(X\h8ntKJSf쟨'JI9"whE5.y@-HG[ç/ NA:M.W0ȑe$s846jQ%}x9Sem)/HMĴ;0|cKcE-*aB4pQwtnaJ+VعJSǧ1mҏeNhC')o|zq\ !RChkb`t{͜h _+C.Oy%)i6t//M bEf& a4ZԻ@Q2aS~N`TL81}{%Q tařT""kcpJX#K,B:HQprG ҂Qϔ,yM=21 <&S{"q,Ha~zź1|ZT"T0Ulp,BrtcD-yJNQ$hp}x-; +iel<*̠]c"m.)<4s[ jEcnD :+JFr5`U.IXՙ0 S JI qMgg*Hþh!:ܸ=  FC/6/:ބTBgÇl#{)7QqM: ̺&"~;tB {H6U\=R'+_jl_@`MGy!>{ut6yϻ*|af1O<% 6/S;2tBAXʡ75|R@U@͇tem!*CUܳaڱ}S:e3j`K%}OxdNW} RޫՎºI=zs 8!~he$xffd ^1r9`ЉEzHZt347l6s Yx&zrl!L'7|D" Sg mPD8c;P;Lui.~ cV/P\uڽx +A|\rt.NN6d0e=n&plBN-޺$!49}g8Lo].靼7>%Z Ў#t Y?~c̰@`|g;G.~-a{򩴽A(R"Iqqeʃ 4*%lDk{I锠BM@5m1ΗQQŁ8>\t%$4o wh1dVWvf7[5"< ku#hU6ujlrH{IwJi/`(ɎY9yRQg]]}Ȯ6:t~P~<쨼kahe~<ũ;]k+ۯNo$Dnoc>D~HPoor·2|X*'!jԷ?p rR5ŎO4zd%-93|J;ov6N6,-L^v]2n_-01hktlroI{0Pk)[~g FQ݂xNR^ ,O…`Glw\%3 8{ppx34u52l' ua/>p몁Eɝ.bpIP< (qW#K,-f5CċJO2 yLhόȉ7L1LMq9#O_Z=Q^K-oBme3N_0]UXsCtfq?X"^ء !yl&`Oj-B0NQU[@]Mۢ"85|l=!4H5Uo$˕^,y0`W0=E;(2J^\\]72Om% b}L%^\;1>=_V cy ǹRtȷZf8qGdgkumÓ%(y͛nv2r4 |Йzl%A}/Y>N{+?V Z#*@6FVj= Fj9g!KK_qRcB·-x>qlc>g!Ơ@v6kJR=0Q,&@e0ִ7HE$P3/-DԆ[kpU%i5/XPqBozܭ"ϴ~zr:`CDEgLS]Q"CbJBE㝴)1mpY]V,r5bܺv!'Dn NlLE o!vhOI,WՖ% qn[ɍ|+1X#q,S1ݪKYN|G`3sݷwY,e O;\3! 6b^ JftA#©qϳQRb:NPZoǯ 5KHet(ϓU--_;Npb7Ìw(Px0fP)Zq+\'h W"z.P6~o Qv;XQ8oz,FO{`)wޢ(TIu*O`W#boZ]<~@rD֏Q,HNd&LJ( (ΌCEwjN>a{&gnOѧ@ܟ }Vt`-%)+8}๑ZĝbwE_:{ CSPҊذs_VwsQ1hL}T="U DJt W$F`VӔ6;ŇnԔν%yaXp,3vAd=2_[YfTȬvxlR`X_⭹`f91;M,ӐRIk˄"\ԦXŢ aiU*!kzO}0ڗbnUAlV`8;x rјXچ\KP3ifQGPzPcsk|k-70cb[ga"㒃W['dW `;qP"(Z+FdE66*$)ާKϓXn| #y{=]|pTLd;%O6_oͻBY>\9pڝSfΤGK.W^lrt֝@y f^r$S/s yc$쟳Rܭ4ATnPivBsKy+dfK]w~})gYOn~Xy)xۛw mwu~w/jAq\h[ @o1~gHmXLp+sFcK6hYLlx]PO+FB:eP: TF*1vD·7=д1v{Rd𗗍|"33gJ T mr*j ,b(ν yXCv C_t4cO@{!T .dC I59ţ D͋}>fAtP'O9q(V@JG^KP*׎*c$;ecsI8/)ϡhڄѹ ~~G7]Ro7'OƛM4T>U}us#TxC Tx)],=b*A#L6h JнL(k@5 /b]!ϗyrC$Z4qcR8DJD .$jjų`fsAYʊOm#9L2z+@ztvC\Gݾh3+#wm"_ѴDi|ŏ}eﹽmV$i0)%0: 2#V?ɮIU~wodŌ6cd5sGӄp6vL6fF\Y{xk0Lwi<:lB9_5 5]~ZK柼,;VVkkP\:"P:8՘pv=!fga_`X?%7 "=P5S2nv p1|1pj#]ŌO8/O=2:m]3AE[d5VD7Jܘyz]fE))6%t68>!c'V\='y>FIMt @6PT2|[l"{C,F.auFvròEY2$S Vbͺj"L͌ GL:\⬲4|]JC*RIgd-ap1XE9jsG4,USj7p}aՙ=hGn!r-'c,UH;֛wl7- Pk &r7h@yi^&00 /ڿ"tv.p4WPinN XIN!s_֖帼ge*tk%& fEy ;y@Z_KM62H>~RDn]pom-\"Z]ϫBqb_G W.v bCtɼ=}\A fޡ a9LTWaD݄bnR[qX:zB\fZٕglGrN5=Ac!=%CoQ^V+ua:k.7lG.P#PDӪ1,KC޺|V1Yeec0նT,8!'R[0W(PVC#)W*!!XWBukĎlGA0J YY{M2]W3B&1nZs:`/?uɮ^#L q_+3PSi5W6&F:#}\ ?"ͨr֌8ʭ:8$#nܩ5Le0ONpE!Ն$d Y , G{ŽCx;fZtv q+X'"/S{:C;L!k%ISWƩc%&g6@ϬۤS2'KV=gql*K$ {W^#\/ r&l}ô'go"O'JWZ?j|m[dYݶUVT r8W_ էMkD+K@ Tэ2PᰆjP[K#߉^J e(Wl+ꃪCT[u\hDIu< e*9lx}>.iQ?B"~"zu}>tc5xv, !*k$!wGv3(q oA47O 1y(|sX>C1%u=|:N[R\uxs XJݗ7%-VI5YpC*N*f}aEUc!DIGz _[Ȓ5sQD})UVSɪQl-,`(mX~&%% O __ w*}br V`0`A TQ8ۖSYU8l[ڮD1({7 ҆u8M@ߨcEUY@j~D78glU1)o"j'j[Q&w|!\0%n0Q) C^S(7֠ Ioۅ޼#_W|lZeCk};"QZ\ܳ'."lY /OJEU@RWck>V] TN!)eoCғY|F2n\g) XdO fxXX%ۃWA.\l\'1P|*55sg|o&ǨQ:@ұ]x ;#%RZ_ߵ@w}IC YnV^ƠV}iF\TO X-uG]'; }l`6"鉣nA!Os|1Fv\)A%v5 /3"c]/b߄Rie 52.||D)肒8V)G*g ;aH@ >];^{_rZҩ9\Y ^Z]ؐ!#na\fk=ӲgAwJgiVm};ZD ){betiivc) )ۮLNQX<+aH0Ƈ)m;2],g?e Zg=&p!l=&HJntQfCSs$cT3*WP0:{PW'M<!A\Bn'F9+ 1n|GtMj\okA7)VtʸU94b8[俟5*B6V]x1x2f52YBѨ9ݴb4H*{zŬ`ńwQY;&.p~ 2$s&Q 1c:uc DPʘBi[6]P-2XBo/2HJ~I2ߊR~GUly"7ynڡt `a*xCu-Y%XĸeUSּk…$)15YL0EkGebըB qQ((j~oa\ӾB)62ZxHsk|2/d< UҼ&'*1%G:p+$`9bj/\Z Q3ʼϰa3+? ä_GLnG'mǑqCĩa^.VSgu9uQ@A$9mi({']nHu*b?:cg~z`)+v:KUɪ2X9WŀHM2eN9sqEpu=1t8^/'HM`Ag^wcYgik}gP2rp_7V?%ܝ8"DqC+2 _QSbYRz>֬3q~Wm2=]+V(|bP6wr{} ,fa5j\E~2at-ʑp |-żp̕ԴLJ*1/Bdވ{oۍ2;fI6;'dV9~o=k+z^z=f S;ZZbc=I-?l℣]x;!pĊxo'܉Q9iR @ <^WCuY+ܻU~ڜg;?G"˛n=A3|j!ȇn9*jU7>I>WX+C䈿M%b@,)/0fL]lAؕU\)s;ߟ3 k4KD0iFfZZCT#oJ!dlpM~tk.Wn.-hg!uH֦RgIϕ8s Td6'/)Ҏ9B6ObCN6(J(;H0n<%b+x'V|~I=6~TSKt?qk|XM5oCƏ9)0>\`~pvX͡ YAs%ivPN>#o̼=X;}û(<߱MjmLAHAfN׫.y|LJT}ܺ\YE6 Lv+ޖ.? wn+:2+@lq@!c|ΦD-ewC3VSq S<۔'dX^_EWJ3Gc|dԋzYߝ7ѪYtuh1FSLͮbsd}G&E a5! cyO0ʹA2SwLt0r߇_/MFA'x JP$Hn t E-֫e6BMs與GcQmh ^pZwm:byc* b>/6^']&\=sX&pHJ^B<&g>"ܔOK-Պ@QKܙ("-[0nkǣh Bz<%Q;i ,Tv: ʗR0Ƶ%o?&wHKmz ˴O\I{|5/ac\;y"ylz*_.Ap\Dwt:RIl 'm޴E z>* X%2hs'1P%/m6\0+Ys;,ٲgF( 6z9C 4NqA "orÍED-$XOƻݾ_LưabZ N* qɩh35Si"Sp[y-NwM_<)Nʪg1/ئ17v-7ul9t8 # !~!tRok4d.eB }dtܨp.`}z DSGV_,v/SP8`]WhL S{6Zw0p)5q7RuRC"9ۂ0]2SnUjA#g9+ Lؐ fAiN^1RlfT}9hk>- ;c=H :#hDCW, rS)W) v0bg&L*[Q^MU#cĄZRJ|.˹,=9כ$CHpT\]o@EDљ  m4—/3H^ZV9Sif=VeGSoINWh,D9JDz_5R ʲ˯j;=넔ѐZD N3>u(: {bScA*ҧ^780Ō<<1iE,6w04SeZ$zWJ lm+A>(1 d֫a 41B&ԶV;~eurvhN+iWgem |yV9K;G%GLݝ릐6@VX.u5s6  F9Q:zCq(0|<;*M݌y >Zа}y+(/hM&:DwvU XfF3˯?; )-|bpk|[ 璄I/LN:AQxU^ZtX1ˉ=rwF!jS[~z4V) Pm5lәlɼ Q>,Ы;s'y,3ċc[ИW2@5+ (J@n$- ԩ/o|} /bm-̔!Qx2ZPmC>%%YƏoلҞīN#VүDzj괏j}:́lmL颮(6CZ6R15"irA?#6t;yjߦ<#_/ymvf<7δ2q8sNG b; l+b^`EcG-5>y,G(yro]GW@JoSR%-i:Ҧ^|'O&\1oj-'QK\x^SO({ ]|R+QZO{l4+xi Y,+]-b7j'`-NRS?fߙOyx(u- 1`0_ʂ) S) ?w ARdiJTvz-=7=%fہ`Dsw dswr%/ӔT,c"`9qVɝ^\4h7x a ӎb̦=i h=Ru`G"#p"uM;T !B|^j=$=~ۄOaq(U gEy/6P<$12RIzw9 !%U.9j!HnLsvLmhn=82P4S E5Q>F]pֶzޓݾԉTU4a/4*7h+=k]a4+;Pi8>}jX1EШ #kWk BebR0 ;]׵UY0> 1nۂdB\2-nzyU}K [fZtV 8T$yJN{Vb# |٩`.>]t[;ZKEoor`ٮ` `V}h)/ $.gk>}9`<Kc2U=UV4MX7eV/()[!϶9g]~'}KJFL Y mdݔQ##<Q6A.mq)_kb A$칟E+LJ$3[ýNC sEr׎SctbE~M0f)ڪ1G4on6-j<srMFu@,g%~oj)6wnJKӰ"HgM'܀0hqRu 6Hb)rMtqWxf]qqZ3*[e|ŘY7RV8errGe_أ>P؝3NRށCf<9A.ebgH;UeHDʝK^c|c+ S  Ja] < [`ay yaެdG>TCw,=!4BFRTI~4S{iTgE7peK[`rhX24ֆd[Wq%'"Zəĝ?o~"rm֤ȩJsb!Y9͜y L޶a4󙐩- %?hXAcQ2Ɗ!̉m>/s1?:,kPN|rv±{,9bzm9"h[d99?Ǡ(/wdp Xu} I2'D60 .Ikn,ޤƵo =Ga~ .ȴ(~$ l+5v)鶀eA O:rԟ=b[ُC䄘*^Uw┣S( MKP;M|$SlnG] eFb)O;FqƐ,X{Z>c xNqR,gl"3%@ P~ s[(ĶǧST-\!|7m ).'H]̄+VPx\JG$05[mSLG|:1X}ҡ;`U#7o-23YP*)ʕ IӯRnJV}xLt@/B ;*V"É(e@ӕbIs=Wx$$sn^̉GCυ]0^J*ȍXF|aFpEp z"}ɞ^eZD)+ d"fz""Y4Dta.(.Re@Y|l|Ue&&ޥcuQ 316L+3Zie 9QfL˻eiI)""noR,ulO@*P)lT4TpƿMIßM[ N0>¢sqZc%abZ5J/ԦcS Qb0uǮsd׏#i.ʼn zjǒ@@S ;2T1"6Ƙ90 5pg|@ U [eV x)65"'wEV\rZ;^N`ia7mftw*T?oNeVP*A(H^)rtl04lUhs6G(jE5w1c!M}P%gr`]x8g>1:#MT6}qoKUK]@?V6PeD^! A?1ZKߤEK4j̤igٽi_bSɻ1<`~uz˥?\H:*SޚTPՀxqp(õ]hR/,@:3(\5_0Q "n]^ N^X&axm&. fHz!qig||~'ֱl"\͞'٫fDI!0dhjzF7FJ1͞O&8' 팲s":EZL13 V Y]j0zgZ;V 3;D PGy麿Mf :^;PߋLs 91'&,DJdf +0E=]((d2  nuah!׮)ȇ4fcyڦ`s'I 2% u6[$!x{Q S" jv k:yvmݖ`B ֣zn6z6$Ʋ]9LWsI./?phbЏh{5Xb Sn3 @hI0cFWe$FD-tdjKlX_<;~ .UN?s8bO \c |G|Gj;۟B.4rI+LQN)GEZ`y? oy\THD Kcy3KZSA11tJ2syLmbQO-mmh IҬ\}tgж!Tb O3ɠ> IF(aVpu'X$%OTF 讧k>7kC~鋂9/-ZhXSR*zܦmRHSQ+{=d/$G],ьvş@d~5S,w^"WG\ Ne^Buң'z~LN@PfrD7? րy9%j%-d"V!8̿+Lwky *8Ǎ<5QXj(5YGєTs$ 1UxjE=|2aAf(: !KSnMvێ)!%@N}x&BCw _iσZ(nh_IZv5Pc~ p~< !GXj,f?C\:U7$6 U yx7$5[пNK#2?0ྮ՞ s3W,emݥ ܌BNxWDɲV]I= ,E@mxϬ Db=#x?)q>⦽.#.EtCw݁(%rCd=f,곛yp>9EE?5d}gPH-K?x Y XmǧLy g;s_çuNV* tfisq}T]IiKdAU?< tQhٝ'|مk?#Soar lg ýʚdB>Jˑ|Q=a4Nf3tĤXes]oT[+gH;>l]$@)~ΩN^sZ@ S?0DscGAfvS#[? @\n1Gs-Lr qk"" 7Ń<(8vN8Z"?E" (gOkX/U!Y63/i-4Fs4bi,5Ad7m[zT-Z]锆>#k<_il,~I[vbJZb!x PxdKzBRl?= >τ1Zy Д qSuW_p.4ACZ.ld$&hj'ndBߜw0x,R+c6b8q#a\F aaώ̖2F„soBͼr:T=qve $U%~=c2X\+s6"ܘ[NJ%(OҾǹ0M/En}Nj4*:@Zم2`R^u#/04 ɒcxОfW|ARI,~~_^{mעOf;nJ3؃ɯt];ȍ;ʧ%RNCmKګ^iecY-EV P2*[lqCI%tBFH>hM2]^:hO =!n ?S) ;\VǢ]uҬz6_u>>C\u/tV:ߊk;RV(5O n4SmԶ&VeycfPsPz{%=j+Y!1\?U,觭U߷tx3V>JCSQMKRg?~zYD ;G 4XprҲ/9Gf=1r ) ǐN(©_& Ȥ_^kqgr5ZAK%h@ k>NbN"Un+gFV[ F\] Eh/ {iA׈O2ª8V6r*#Ъ&Q)Bjr0ŷ3mҮܴ.81%[;TFsex$GhY0GzZ|Sbio^7ڈyRʘ"`=+/pO$;=G["ʅ HA?tN:~D*ص%\k6gCg ${5 !R>{;9(P.h_d7a7K'(r wEIBw\7dlwjC9 Drf2 @CDJvrI4F}&ƂD`YJ}wV_ߓ^Mܿa"-g%B E.5FRþuoi #ް*JJVhX"A @g{W'ui9c2GHkαecy ܖF0ܼvUD,bT8ygfZ^3{ku ]^rD6@Ц>: rNFC!X 6%`|f<˽OUZ8hΒ!j-T 6r)J/ruǩ$oxFnj:Mb0s r[rΧ xjXRL~Ra=\COAt˗>JwjyI?!i.ZאpVBأIcW=07oz:^h XG H?[Lںy<,ODqga_Q-eZy`cئܫ!]>' 0sm VXS3/-# %lZ "f6[weel:"ibo~M)!)G7&7~& '6͂L:/K]) Ktu1d Isc&xkhձgݴͰht'8R&I$̾]hY不+HAxɄ$vY6<'B%Zw{*OR1ݿ i:J^b?.O]LI$UE`M= #R,WqQ"C! ak*uMEV>.vmx s%r.$;GXt^K6讌MwuPhn`Ðɀ)ɐBE).]9XVј+ήnGKk[E+tJ%j#ތ&>'<,OHw%iomF#ں {w&NF]-$Ih˵Ks;ް4NПZ1J^J~DzLnfQVfƮ~ѿdq ̯=-Օ@ZX5gY^f"p}idjǞ$ 2W!|g_%UjQbǮ\,iUD9džfD\!5_!я," wfxпRpo, bzV'h̻:&CF?|ѕjLTjyTkQ{/r.K*IQj9`>ǵjE W.m,TUT|@RĐJ_:5MVma1*TPb"8lE~׋Q+v`e 9}!_XM808-ͭʩCfWGM^8 #Tb $~h/I)FH|}쁳ڤ>43RS>pټ ȂuxIm$bȖz6c^yY,*XnJoԨd *%yCfޏC*?𡎫I&E[vɵy6 ^5$7@qᩳsOZ$&,"VL4w1GQثKD%mzimm_fݾxv%&o] Z띭y\e?F+ - 0 JF翠殝4ċNzɷMr(kTXK:4d ͮ2t7~τv&̓p րEJ?wui ]*Bd+̉2dEx2$x.$g\t헍wqc k<(Iժ$`!v aنte!XCabRmk_~G;l"~eQ3!BpI}@F]"rpF:͠u ގ;vLGaf9+ |X42nUqBN_&8Ya"O(N>_мy-Hi w`.Ty~r&;$ETh X"c\)CS:Qܨai{ J 1-N18 m wЎaHU/m& JPxˮlT;#}.!߾ ]<oc[:1*d'\E+C.wsMB̃ ]bQϪPO!Z;g;S(zZ }qݡv F;d>p87{Ei\S[mV3¹р$*?Bs49hHk1.4JQρ'!VAL "J',jUO:DHW^^9! F3CC.15 $?Dir\^6$D ɋ5~+t,+ﰖ3C`VKT I#XNkMr|I &Tg o3&YpBջ  8e6h6CF 2*Ɋ&/qvăF.a+ Soe6N_ʸ3*_s5\D@Dg7z{l,ua@8k1P}| ܧċrD2I)15%2j//a8r/P?F)IXw,*>&s͊&k*}~Z͓d?[h iٲn>w^јauvte~_YVS|nL8AU~.N=% ?<4oӆ| #p*#Ǐgo-\>JL8Y[^a7n#bl$ shذ%2̈)· ЖATm=E"* ?$g+Pe߮Un /kkz,5-Xfn_ )gSTu:,ӠsKnռe /[ޚS~`Bi3KvN.!]tJrq?1| L 'CL_'məXg9% 8>z +VgG0؊H78٬tsw|r`h,kOnjWY^zk8߶ΐudk`JuOPS(h,pBQ@\QeiWUx7%]UB.ڠS#&';t{-08yf#DvA:'EJGWu2qXcգ+dMhPaZ'9_tSG\ ֽxbrZ^UxT)Lz~o Z<+X\Sb<x$5u#M!`[an O10ڛ"a[ǫ3V,,Rfp{7Y!M,ZW$@e^'L"ӛ"Hk 9)bXh= CϾ3viVS⾌Te3\JNFid2fLg&e2Ӌh IbG?o׶H V)JC7)Vù;xCniTZ O ` [y&r B"<ʲB$?4:$ &Co9k;Wc`?26;0WܤBr?Q6}dMdd:w q +ہ?=/;N*k[Ui9ϳw|n5fvly/_ T:"4gι\#~E/q[ 0Nk7r'Gr85hKk3<ݒ&?~:GTY)K0F˥6YL:5.}6\PX`_84ffۚyp? ZG{aslzBؔ+,`I&K)N8]vn!m=. ~8w*3Ur1  2@uj$n?+wxcjq$qP~lO )K!34 _JJJHFnƙR=<k}v=U ?f8 Qa˸O[iKK:@sP BI06,YK]ƠآY 0~&`@=JMd]>'L SUc \>=x,Rb}T"vF]mASn٩35U.4=)qz7y Pq<ǍlW{4.S4$`儤P)t? k [,[Jyq1?ɖHv}#=2$쁵yɳRJ4Lܱ6+W`ޑ#"1 Wr06>m(ΞwyYSYTőVs蹜cyƑ_DF^^11_>,fXY> `a#O)Ƀm\ѭCb!׶/u&zN9Ql ’^JSjejZءQF$n0+d$k$!n9'uɃ0gRX BC^E2c?G-1Y"m|vҮ@ U0)ݰf{BLmkB8ԨwӖe{GDvA;_ɧSTX Uj΍G_99R {xtjt,$[NQ1P.[5&.T7^Сbǟ^[[ ~VY6<4N`MW'Bi/sf-TVA.3ņ1%^ 7/i9t$# X3Gty&;>B]ǰiE'ǏUrBW/wbaO'+mhvntdt[HADQ]S ⏞b+GF!: YZ