libdnssec8-3.1.4-bp153.2.6.1 4>$  Apaᶜ!M@eeeRV4e`viGbfdv?Fbh @[?K~>dEoLv ז|Uv {'EY~K|In gcC\৕}Bo`<4hγm5ÉdXP,)>F;\w[ ~FaꃇU9x:i#9VD"lZwxQ=E3f,ibDRRP84XMy,b6f1cb7a1746ff7d83a0053f2a482f202192b41297ba1399279c70f2ea7a4212ae23da31dbbfb7fac952e5e48eda0aff9851d0db2XЉaᶜ!M@eeep>юS8B[9GҞ٪EP4ahv:]vqLa]cc$Kv &`}P|mkYҲn]"wmN龜 ψ+ܸsoeǻ8v{~hp87!w u7sKjA 7XNG7s?% gtW6%zy-t6ٱjN'h0gJgR5 LeE4R.[!>p@gP?g@d   EPTdh     F \dnx{(8898: 8>c@cFcGdHdId$Xd(Yd4\d\]dd^dbdce8deeefeleuevfwfxfyf zffffg<Clibdnssec83.1.4bp153.2.6.1DNSSEC support functions for Knot DNSKnot DNS is a DNS server. It implements only the authoritative domain name service. It uses a multi-threaded and mostly lock-free implementation and can operate non-stop during zone addition or removal. This package contains a library for DNSSEC support functions.aZobs-power9-07SUSE Linux Enterprise 15openSUSEGPL-3.0-or-laterhttp://bugs.opensuse.orgSystem/Librarieshttps://www.knot-dns.cz/linuxppc64leaRaR63eb4b8a98b483e1cca65e61359afa95940ff320afa2f6ed55bab91a56f37ec2libdnssec.so.8.0.0rootrootrootrootknot-3.1.4-bp153.2.6.1.src.rpmlibdnssec.so.8()(64bit)libdnssec8libdnssec8(ppc-64)@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.25)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.17)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3a@an@aD@a @a @`ݮ@`f@`@`q`_@`\{@`@`_@____^@@^@@^@@^@]\HW@\3?@\*[@[@[ݍ[IZ@Z@ZWQYYYXWDB@W1@VwV@V@V@V@VTQ@VCU6@U6@U@U&iU&iTTq@T@T@Tk4Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Jan Engelhardt Michal Hrusecky Jan Engelhardt Michal Hrusecky Michal Hrusecky pgajdos@suse.comMichal Hrusecky Marcus Rueckert Marcus Rueckert Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky pgajdos@suse.comMarcus Rueckert Marcus Rueckert Petr Gajdos Marcus Rueckert Marcus Rueckert Marcus Rueckert mrueckert@suse.dekbabioch@suse.commrueckert@suse.dei@marguerite.sumrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.detchvatal@suse.comondrej@sury.orgondrej@sury.orgpgajdos@suse.com- update to version 3.1.4, see: https://www.knot-dns.cz/2021-11-04-version-314.html- update to version 3.1.3, see: https://www.knot-dns.cz/2021-10-18-version-313.html- migrate to user creation via sysuser-tools - run spec-cleaner on spec file - update to version 3.1.2, see: https://www.knot-dns.cz/2021-09-08-version-312.html- update to version 3.1.1, see: https://www.knot-dns.cz/2021-08-10-version-311.html- update to version 3.1.0, see: https://www.knot-dns.cz/2021-08-02-version-310.html- update to version 3.0.7, see: https://www.knot-dns.cz/2021-06-16-version-307.html- make sure we have getent and groupadd/useradd in pre * added dependency on shadow and glibc * might be related to bnc#1186023- update to version 3.0.6, see: https://www.knot-dns.cz/2021-05-12-version-306.html- Make /etc/knot directory owned by knot - fix reload action- Update descriptions, remove unsubstantiated claims.- update to version 3.0.5, see: https://www.knot-dns.cz/2021-03-25-version-305.html - Update description based on homepage- Trim marketing wording from description. - Drop old rpm constructs.- version update to 3.0.4, see: https://www.knot-dns.cz/2021-01-20-version-304.html- add incompatibility warning about 1.6.X version when updateing - rename back to knot- version update to 3.0.3- version update to 2.9.7, see: https://www.knot-dns.cz/2020-08-31-version-296.html https://www.knot-dns.cz/2020-10-09-version-297.html - obsolete only pre-2.0 version- remove rosedb conditional as lmdb is required in general now- replace conflicts with Provides/Obsoletes- fix dependency: python-Sphinx -> python3-Sphinx- use upstream example config file with correct syntax- version update to 2.9.5 - Bugfixes - Old ZSK can be withdrawn too early during a ZSK rollover if maximum zone TTL is computed automatically - Server responds SERVFAIL to ANY queries on empty non-terminal nodes - Improvements - Also module onlinesign returns minimized responses to ANY queries - Linking against libcap-ng can be disabled via a configure option- version update to 2.9.4 see NEWS- version update to 2.9.2 see NEWS- update to 2.7.6 - Improvements - Zone status also shows when the zone load is scheduled - Server workers status also shows background workers utilization - Default control timeout for knotc was increased to 10 seconds - Pkg-config files contain auxiliary variable with library filename - Bugfixes - Configuration commit or server reload can drop some pending zone events - Nonempty zone journal is created even though it's disabled [#635] - Zone is completely re-signed during empty dynamic update processing - Server can crash when storing a big zone difference to the journal - Failed to link on FreeBSD 12 with Clang- update to 2.7.5 - Features: - Keymgr supports NSEC3 salt handling - Improvements: - Zone history in journal is dropped apon AXFR-like zone update - Libdnssec is no longer linked against libm #628 - Libdnssec is explicitly linked against libpthread if PKCS #11 enabled #629 - Better support for libknot packaging in Python - Manually generated KSK is 'ready' by default - Kdig supports '+timeout' as an alias for '+time' - Kdig supports '+nocomments' option - Kdig no longer prints empty lines between retries - Kdig returns failure if operations not successfully resolved [#632] - Fixed repeating of the 'KSK submission, waiting for confirmation' log - Various improvements in documentation, Dockerfile, and tests - Bugfixes: - Knotc fails to unset huge configuration section - Kjournalprint sometimes fails to display zone journal content - Improper timing of ZSK removal during ZSK rollover - Missing UTC time zone indication in the 'iso' keymgr list output - A race condition in the online signing module- update to 2.7.4 Features: - -------- - Added SNI configuration for TLS in kdig (Thanks to Alexander Schultz) Improvements: - ------------ - Added warning log when DNSSEC events not successfully scheduled - New semantic check on timer values in keymgr - DS query no longer asks other addresses if got a negative answer - Reintroduced 'rollover' configuration option for CDS/CDNSKEY publication - Extended logging for zone loading - Various documentation improvements Bugfixes: - -------- - Failed to import module configuration #613 - Improper Cflags value in libknot.pc if built with embedded LMDB #615 - IXFR doesn't fall back to AXFR if malformed reply - DNSSEC events not correctly scheduled for empty zone updates - During algorithm rollover old keys get removed before DS TTL expires #617 - Maximum zone's RRSIG TTL not considered during algorithm rollover #620- seems we no longer need jansson- limit geoip support to opensuse- update to 2.7.3 - Features: - New queryacl module for query access control - Configurable answer rrset rotation #612 - Configurable NSEC bitmap in online signing - Improvements: - Better error logging for KASP DB operations #601 - Some documentation improvements - Bugfixes: - Keymgr "list" output doesn't show key size for ECDSA algorithms #602 - Failed to link statically with embedded LMDB - Configuration commit causes zone reload for all zones - The statistics module overlooks TSIG record in a request - Improper processing of an AXFR-style-IXFR response consisting of one-record messages - Race condition in online signing during key rollover #600 - Server can crash if geoip module is enabled in the geo mode - changes from 2.7.2 - Improvements: - Keymgr list command displays also key size - Kjournalprint displays total occupied size in the debug mode - Server doesn't stop if failed to load a shared module from the module directory - Libraries libcap-ng, pthread, and dl are linked selectively if needed - Bugfixes: - Sometimes incorrect result from dnssec_nsec_bitmap_contains (libdnssec) - Server can crash when loading zone file difference and zone-in-journal is set - Incorrect treatment of specific queries in the module RRL - Failed to link module Cookies as a shared library - changes from 2.7.1 - Improvements: - Added zone wire size information to zone loading log message - Added debug log message for each unsuccessful remote address operation - Various improvements for packaging - Bugfixes: - Incompatible handling of RRSIG TTL value when creating a DNS message - Incorrect RRSIG TTL value in zone differences and knotc zone operation outputs - Default configure prefix is ignored - changes from 2.7.0 - Features: - New DNS Cookies module and related '+cookie' kdig option - New module for response tailoring according to client's subnet or geographic location - General EDNS Client Subnet support in the server - OSS-Fuzz integration (Thanks to Jonathan Foote) - New '+ednsopt' kdig option (Thanks to Jan Včelák) - Online Signing support for automatic key rollover - Non-normal file (e.g. pipe) loading support in zscanner #542 - Automatic SOA serial incrementation if non-empty zone difference - New zone file load option for ignoring zone file's SOA serial - New build-time option for alternative malloc specification - Structured logging for DNSSEC key submission event - Empty QNAME support in kdig - Improvements: - Various library and server optimizations - Reduced memory consumption of outgoing IXFR processing - Linux capabilities use overhaul #546 (Thanks to Robert Edmonds) - Online Signing properly signs delegations and CNAME records - CDS/CDNSKEY rrset is signed with KSK instead of ZSK - DNSSEC-related records are ignored when loading zone difference with signing enabled - Minimum allowed RSA key length was increased to 1024 - Bugfixes: - Possible uninitialized address buffer use in zscanner - Possible index overflow during multiline record parsing in zscanner - kdig +tls sometimes consumes 100 % CPU #561 - Single-Type Signing doesn't work with single ZSK key #566 - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - Compatibility: - Removed obsolete RRL configuration - Removed obsolete module names 'mod-online-sign' and 'mod-synth-record' - Removed obsolete 'ixfr-from-differences' configuration option - Removed old journal migration - Removed module rosedb - changes from 2.6.9 - Improvements: - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation - Bugfixes: - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - packaging changes: - enabled geoip module: new BR: pkgconfig(libmaxminddb) - enabled cookies module - enabled queryacl module- update to 2.6.8 - Features: - New 'import-pkcs11' command in keymgr - Improvements: - Unixtime serial policy mimics Bind – increment if lower #593 - Bugfixes: - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy [#589] - update to 2.6.7 - Features: - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) - Improvements: - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination - Bugfixes: - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback mode- Update to 2.6.6 - Features: - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation - Improvements: - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination - Bugfixes: - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- update to 2.6.5 - Features: - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set - Improvements: - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates - Bugfixes: - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations- update to 2.6.4 see /usr/share/doc/packages/knot2/NEWS- fix tmpfiles scriptlet- package /var/lib/knot - run tmpfiles scriptlet during install- update to 2.5.3 see /usr/share/doc/packages/knot2/NEWS - use libidn2 on TW and 42.3 - following modules stay static: - dnsproxy - onlinesign - moved modules to shared building: - dnstap - noudp - rosedb - rrl - stats - synthrecord - whoami- update to 2.4.1 see /usr/share/doc/packages/knot2/NEWS- update to 2.2.1 - Bugfixes: - Fix separate logging of server and zone events - Fix concurrent zone file flushing with many zones - Fix possible server crash with empty hostname on OpenWRT - Fix control timeout parsing in knotc - Fix "Environment maxreaders limit reached" error in knotc - Don't apply journal changes on modified zone file - Remove broken LTO option from configure script - Enable multiple zone names completion in interactive knotc - Set the TC flag in a response if a glue doesn't fit the response - Disallow server reload when there is an active configuration transaction - Improvements: - Distinguish unavailable zones from zones with zero serial in log messages - Log warning and error messages to standard error output in all utilities - Document tested PKCS #11 devices - Extended Python configuration interface- update to 2.2.0 - Bugfixes: - Fix build dependencies on FreeBSD - Fix query/response message type setting in dnstap module - Fix remote address retrieval from dnstap capture in kdig - Fix global modules execution for queries hitting existing zones - Fix execution of semantic checks after an IXFR transfer - Fix PKCS#11 support detection at build time - Fix kdig failure when the first AXFR message contains just the SOA record - Exclude non-authoritative types from NSEC/NSEC3 bitmap at a delegation - Mark PKCS#11 generated keys as sensitive (required by Luna SA) - Fix error when removing the only zone from the server - Don't abort knotc transaction when some check fails - Features: - URI and CAA resource record types support - RRL client address based white list - knotc interactive mode - Improvements: - Consistent IXFR error messages - Various fixes for better compatibility with PKCS#11 devices - Various keymgr user interface improvements - Better zone event scheduler performance with many zones - New server control interface - kdig uses local resolver if resolv.conf is empty - new BR libedit-devel for the interactive mode- update to 2.1.1 - Bugfixes: - DNSSEC: Allow import of duplicate private key into the KASP - DNSSEC: Avoid duplicate NSEC for Wildcard No Data answer - Fix server crash when an incomming transfer is in progress and reload is issued - Fix socket polling when configured with many interfaces and threads - Fix compilation against Nettle 3.2 - Improvements: - Select correct source address for UDP messages recieved on ANY address - Extend documentation of knotc commands - drop knot-2.1.0_pkcs11_check.patch- enable libcap-ng- fix configure check for pkcs11 support: adds knot-2.1.0_pkcs11_check.patch- fix soversions- update to 2.1.0 - Features: - Per-thread UDP socket binding using SO_REUSEPORT on Linux - Support for dynamic configuration database - DNSSEC: Support for cryptographic tokens via PKCS #11 interface - DNSSEC: Experimental support for online signing - Improvements: - Support for zone file name patterns - Configurable location of zone timer database - Non-blocking network operations and better timeout handling - Caching of Critical configuration values for better performance - Logging of ACL failures - RRL: Add rate-limit-slip zero support to drop all responses - RRL: Document behavior for different rate-limit-slip options - kdig: Warning instead of error on TSIG validation failure - Cleanup of support libraries interfaces (libknot, libzscanner, libdnssec) - Remove possibly insecure server control over a network socket - Remove implementation limit for the number of network interfaces - Bugfixes: - synth-record module: Fix application of default configuration options - TSIG: Allow compressed TSIG name when forwarding DDNS updates - Schedule zone bootstrap after slave zone fails to load from disk - avoid activating the intree copy of lmdb- update to 2.0.2 - Out-of-bound read in packet parser for malformed NAPTR records (LibFuzzer)- split out shared libraries, knot-resolver uses some of them and atm we are forced to install the whole knot2 package.- lmdb seems no longer optional- create a new branch for knot 2.x starting with 2.0.1 - Bugfixes: - Do not reload expired zones on 'knotc reload' and server startup - Fix rare race-condition in event scheduling causing delayed event execution - Fix skipping of non-authoritative nodes in NSEC proofs - Fix TC flag setting in RRL slipped answers - Disable domain name compression for root label - Log via journald only when running under systemd - Fix CNAME following when quering for NSEC RR type - Fix refreshing of DNSSEC signatures for zone keys - Fix binding an unavailable IPv6 address on Linux (IP_FREEBIND) - Fix infinite loop in knotc zonestatus and memstats - Fix memory leak in configuration on server shutdown - Fix broken dnsproxy module - Fix DNSSEC KASP timestamps parsing in strict POSIX environment - fix multi value parsing on big-endian - Adapt to Nettle 3 API break causing base64 decoding failures on big-endian - Features: - Add 'keymgr zone key ds' to show key's DS record - Add 'keymgr tsig generate' to generate TSIG keys - Add query module scoping to process either all queries or zone queries only - Add support for file name globbing in config file includes - Add 'request-edns-option' config option to add custom EDNS0 option into server initiated queries - Improvements: - Send minimal responses (remove NS from Authority section for NOERROR) - Update persistent timers only on shutdown for better performance - Allow change of RR TTL over DDNS - Documentation fixes, updates, and improvements in formatting - Install yparser and zscanner header files - Improve lookup of libsystemd build dependencies - Fix compilation warnings in endian conversion functions on OpenBSD - changes in knot 2.0.0 - Bugfixes: - Fix lost NOTIFY message if received during zone transfer - Disable fast zone parser when compiled in Clang (workaround for Clang bug) - kdig: Record correct dnstap SocketProtocol when retrying over TCP - kdig: Hide TSIG section with +noall - Do not set AA flag for AXFR/IXFR queries - Features: - DNSSEC: separate library, switch to GnuTLS, new utilities - DNSSEC: basic KASP support (generate initial keys, ZSK rollover) - Configuration: New text format in YAML, binary store in LMDB - Zone parser: Split long TXT/SPF strings into multiple strings - kdig: Add generic dump style option (+generic) - Try all master servers in multi-master environment - Improved remotes and ACLs (multiple addresses, multiple keys) - Basic support for zone file patterns (%s to substitute zone name) - Disable zone file synchronization by setting 'zonefile_sync' to '-1' - knsupdate: Add input prompt in interactive mode and 'quit' command - knsupdate: Allow TSIG algorithm specification in interactive prompt - Improvements: - Zone dump: Do not write class for SOA record (unified with other RR types) - Zone dump: Do not write master server address into the zone file - Documentation: Manual pages are included in HTML and PDF - drop patches which are included upstream: 0001-loosen-openssl-dependency.patch 0002-make-configure.ac-compatible-with-old-tools.patch - also drop all buildrequires just needed for autoreconf - new buildrequires: pkgconfig(gnutls) >= 3 pkgconfig(nettle) pkgconfig(jansson) - create devel subpackage - enable rosedb and bash completion- local state dir should be just /var- enable dnstap support for factory and newer: - new BR: protobuf-c and libfstrm-devel - prepared lto support but not enabled yet, still need to find out which distros support it- update to 1.6.3 - Performance drop for NSEC-signed zones - Proper handling of TCP short-writes - Out-of-bound read in zone parser for long domain names in origin (AFL fuzzer) - Out-of-bound read in packet parser for TSIG RR without RDATA (AFL fuzzer) - Out-of-bound read in packet parser for malformed NAPTR RR (AFL fuzzer) - CDS and CDNSKEY support in zone parser - Add defaults for TCP config options into documentation - Detailed error message if zone reload fails - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch- update to 1.6.2 - Limiting number of parallel TCP clients (max-tcp-clients config option) - Ignore refresh and transfer events on non-slave zones - Compilation with Dnstap support on FreeBSD - Possible file descriptor leak when terminating inactive TCP clients - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch - moved autoreconf -fi to %build so it wont be tried in quilt setup or similar tools - move up the %if case for systemd in for the preun scriptlet to avoid warning about empty scripts on non systemd distributions. - used xz tarball: new buildrequires xz- Add deps on the docu packages to regen documentation - Enable systemd integration fully - Add dep on libidn - Cleanup with spec-cleaner- Only require lmdb-devel on (Open)SUSE 13.2 and higher- Updated to 1.6.1 Bugfixes: - Journal file would sometimes outgrow its set limit - Fixed incompatibility with OpenSSL 0.9.8 - Proper handling when machine hostname cannot be retreived Features: - Support for DNSSEC Single Type Signing Scheme - Compile with lmdb-devel to add support for persistent timers- Updated to 1.6.0 Bugfixes: - Fix zone expiration when AXFR/IXFR is being refused by master - Fix forced zone refresh on slave (knotc refresh -f) - Persistent timers database opening after privileges has been dropped - DNSSEC: RFC compliant processing of letter case in RDATA domain names - EDNS: Return minimal error response for queries with unsupported version - EDNS: Fix interpretation of Extended RCODE Improvements: - Maximal size of persistent timers database increased from 10 MB to 100 MB - Added logging of persistent timers database errors Features: - Persistent timers for slave zones (expire, refresh, and flush)/sbin/ldconfig/sbin/ldconfigobs-power9-07 16363605383.1.4-bp153.2.6.13.1.4-bp153.2.6.1libdnssec.so.8libdnssec.so.8.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protectionobs://build.opensuse.org/openSUSE:Maintenance:17150/openSUSE_Backports_SLE-15-SP3_Update/7e783354187725acff3c96b1522f4e9e-knot.openSUSE_Backports_SLE-15-SP3_Updatecpioxz5ppc64le-suse-linuxELF 64-bit LSB shared object, 64-bit PowerPC or cisco 7500, version 1 (SYSV), dynamically linked, BuildID[sha1]=eb78d138e2e63f76f7a8fa657e7ffdf9e63778ef, not stripped PRRR RRRRR` ʾzxn,IZutf-863818b37749ff8409da03e3d1a4bc08baca31f3c4b98c614840500b4b666395a?7zXZ !t/㮻] cr$x#Ejqȿklq}``L1P|q8@-O&8uf5.޺cՈ^'YU¦ <#$PΓқ]9Oh0h4⍔RvӈY'ʣ*NӶcEi2DN8LtJ֝R2 A+^BYtө.g#ک]ۍ)<2',NkKKl?h]Z7Ttp Sq3 Hȱ(c "2x91v g{6jUL\1J q!#\4 _[zlRmOON]`qp6svGZG+S{ҚP'AEOS:bɫ 1uVB' `P5m8V8/v(B+~0RcJd8Dk?Cv?T 8J3s<پv^ݹN`%bΌ@$j!Y( -zi3FHM#!)(-21QܴN3Quof@kD9jbz-X1=Lnsa,x:~3jd7RsyR='DoB:+&dqq+oMw.wt)`I"N0`J&pa{ ZGmBSB59%vuTnɅ³E( /Hvr,ˏ|\?yh6{`Qt`2/X8%sv#/:}pXd3f_@M aQMQ< Nwg T J0s=Fepu\Ʉ<{j0 m.Ab/:Z!/ѳ׫UkoN w~o= ׏am,3nĠ*sAԫyY6fm;\6Yp5|( Cv<{qpG& B:P >k5ȰBŅLJ.~O}-v%spOF5jlΕ*  vgO"?sFAק`j@a 'т L7Ik]iN!;@0q0A< Qa+[UD'yAyn66 ì2 ,h&;QA$U ?bY$~@oaEdf65L89v0(iiq49l#%_@2>螈VSocDg۸&~Zb)]֌dcK/03.oЪ]=0VA!BGf $tLn6X6ĉ/mZ9t]X攻 C 6帧4 ‘t ^jNh}&_ؤ+ez fo Vu;^ly?K:z5N( |)z?݈zRzS #koO&l^kG2NCUF-Z,v%dK TT|2L!q)!Ei;6D~siê8.>,㭃#Y{4tZW&zw#cRҾ:ZA"OFBśgOqǠg$/Nta/Gjln^veOF_ 2ߑJ87 0)>uD'^H ZQCO.p2nP #oW H49YL7tecB;nfx'zhu57DTLF9l>Ae4kɹ%GK y)2~>3[)Ѕ#8*}a!&AqsbOu_\z z\k9`G8%_̜TH.JՔ/VϜ3-39<́K"/Isd%, S>ʴй%H~TQ~yVRA *#:7WҲPGD s6/ `A*EԽБKSIajC~jcr;.}+: =aBI_0YSyvB`fIs-{HZTQ#o_Ʌg:+ f= ad˖ L#\E{WрӺ AQVFA3YwW81f5 $LW|&rAƐfgs/1! IoS Ɔ'nYđ;Y9W;i6Hj5o+kԒM![OK4B 'FpWy\yưBWw\ 7O04s`NBj;܍w8?W^1>]̖*GxK)Tvjnw=?ݨu2zJF*{?Gds+ 4`LN_7־f/|+w{\`M\jpqx@xJr.y>ͳx"ܺBC5Db@ZѾa4caQ}fn!c] HD+!iifG!N6r?Lb#goxBE݈l6gڞ+pJZHi\JEZ^"pӃBVs]zc&/~OJQOU9vxpxT)+;m/gvF@ycƀɻdi$"pcsi\TstYюQ2e>xܘa"g#ƽSv̡`QD<`(rd+ox[*.3Z@GZ6DU }s8$}bMo%hܩР9f(?Ǣ,YSI-9mONvL-$yƘP R+k^ɦ3^{P&8|uX8 ׳_~Mє#f9ȯ;F뎲lƒu,z*OQ8_.&ػ *A2Q70Ў z*l\K__ݑD}̰d/pO5IuV/9(!&r?}#*OImoF[0@li gOz1ղ5_~U^bA lKð4:^h>|M=D]6Zsgn'+<8ͷQ/Ezz7if u5*:l2ꖔو@-n5lN1Y*,0ef3S`E\P:]-12 MvvƠf߈ 0X$DEc_LTZa7rt,d]{oG$/Hz+D oϙg}Egј(cqvHFYԶWʆ"SJ 2!]=&]XU``!\cxIiF}_5DRL#6 nS֍V_h=;(^2G mWsݸ[[:rȭ1,O{^] {Cvzl0HkiZSLb&Jvڮ 5-|L2m;Et1E@/ }Jɸ<w{_L>ۥ< oS356A~=7ExkTz@ Fy/Z Ӱ@{J?hpJ`1IUU<4=YO]VRiߩvDrϔIZB%udܶv1.fmY c&V4ulp?qD96ŵ7M12@\}&afK!yj]ZWh5 Zi_a_hڔs5`M>ͽ֮oAn^4yXiSF7G_z-(Z #"jƨDoQرII&Ĭf$xM*Z HAD[LH2@Я6IHIav:Gyd})|n+ A$@D!508_.}(UGW+@x~΋q +6&D'n *z;͔!y,ERURރ6@B5ZkLiCAMS0kp9GJ 0XleL1-%l_ :1)x !2uFC ~vvjhĬ]&HtMzQ_VXPGp ƺo[1d/ќ~$-+eSx{rbi.C+&[Uܴ)"WB4c]at-mt<Lz"!MKDOB5, \Db$bH*3( ꘐ8`MӤ$.²w <E46CѿY)E$?WOw>ZL8yR_I!:ʽy!xf2 Ljfͽ󶥞 %taZ&p׶g*/hn y`[stAo=P[*w[7+$0q,99z5lzQH"BHBIlŶUEk!$JjlցJz0 Piy;&נ:鮋 g%vk7;(lYZ]s; fRզ]˿m%iXD,7Ys>ħ dI~m |Iš 6=KA0 ]yv0x % QӼX4fJE-ɹ tF s=SAHzVVP7#7?mVaء:]_#'=W5E)˾mX(Ɨ nl\!vL֧SFט)e˲cf?=uFݒYTS#f׍׆^62v}*$0>=YprO_.S@ܥ5}nxzon 6yƒis;o &31,uSRĚpcMA-jLĺ/!bA@YM$#x̫Y.-Y()ЙAm6Z' S."y(ﻌÚ#A&:l-Wm/EqLe89M9I!>R''::bwΉFq6i[Pʀ#OqDM(k:35>6V{auTTĥBW`ݱSObZYl^Q2zC.^l;w+3>v 2,T扊#Gτчtڲ1xע+P曁vfÛpŝO|-1֊I|+$ YeAQzx[ y,:6ڹ`9F|UZM&*<?4-I;Zt :@w቟0agmidNp}4(,o̗$c64;c0x K}1STDk+![C>$[ Bfx#qj{wBrt2Ł'E_ޥ Bze4 W6P單!sx P,9z=bMTl4?wUCSC>ކDv4-y{; V7=JɆ 5wdNyeF&Xu$=jA>vUCh'}6QލX0bjI$0x\ ;r$"[2qaKԲx~4kuR}2aHSv| &7{ h؆HҘmbGg2悎 T1_?FXcG(;?.9!?~ qG)@\yp>-!7J%ܝNt Wsk3{YL< ‚"ḏƂqDvS Fjp"Dmy%F$4peok^<) ^)]KgexISe-e@Ō+[\)t'(cݬvsyu0BݟhIfSRK4 x8MIp0XSJ.Є) <2bG$4>EFzBQpF_EP De@aWFv֨nzlx.!T;|+3 5(4U\i-Cf,x .Tvl[g+ZTfɦ]Ch,)致mUN L*6ź<|P]|\Nh@Wki߱(1,$PG)})$}SSm#,2CcCѨL*˹L e_|흶 TɅaI|2"k9W<:J^Mer`:a,?:t٫Xt%#||Vׯ^(+5K5exP&S|1n6u$)i㝿`# e|-< Q`me_SV-*3&,=xϚ0as遦} ^ACFhC\(璯hMF6vN}"P*?.l?]L5 ]&zF"iM%6+rix\ϳp4܏~ IiJ|?,S EY _Gn?u {nbFɉƅ.|A:RQ#ThX yrϙF4ez; F,+R9n;\O"|QT`pfqv;l!bb+G]4k:J4$#d?ͺ*wc}8z2 R-s~wDg҆ͬ0 }7 =n7gzFŒB'! h:voRG%Qf,x}A۹A@V?(K,9<^Ȃ]/WS05f'EåYE|Fcr";,o쮠3]छ!Wpc<:JcI$W}v t36nk/eDioaesvoa$@"IkX@"Ɗl;i䖉“%iZ@=fNBkmrpcH gt;d]҂7J42LM BO=X661=$e }m?h˨0_S E0 4=A=*4Fcd{1Dֹ1x%Aоh CŪUg?e;kb 4bT/*;P&v3;Ҳ?SIw F; 3zޑgM.ֿݼƳ=N+앏Wt'ACXDب},NU _Clc>^$eǣOl'j0Pp4H2W )f-{Ÿ>%&0il0M?ސh}ߟrPuK֏ʱ@)nLD<b@QK4+!lve9p cs?KozO M*?y(m^);dTr-+4HER{DB`T*]7-P-Ho B4C]ji 4tU$(n\:='Y6S'O"}Pu.v%NZVͨtLiH mLZ0Λ g#dYI`ٸE=T61EӶi\\ =*VgxFU-KzmGzɆY1y4GQ{_(l5g0PTF;ÂP&e<KCJ PCI/WmLi%EěǒҧU^3 ȳauLl>_xф:/c1 -Rg(L>XB ZC8GF–#+χ*nˑ t>hmM=&:H1ZOתu?u A2o!Q牣S9#kmߏ$#gu4Zm\$pCya]J2q3U钾榭ا`ݢU^cIyǨFjWe#a\nTׁ!o/w;yR ]tw+j5:Z!"Kώ/V9Kv.s{+8YK0d;b) c ۽uUo95#G̕|.% vtijxOB؛>O9G `VG,5t008I+xRo38s@#+8 $z@Sb(E&WUc Jڣ+eX,oNVVti?yNV, O8F~[/ڟy]v);V/p \bǀaɈxƀ>p80 Qb|Vڜ̘$iLt??Jè8>>R!L~fkuiCd _gqٷZjhyiEd~l{6- (B!|:!^;jvfMuqdRTԘKq@H7i>-dNQ`@ @n(U$lC>\>}I-!ߥy{' ]L^e P5]+37f2B>XآW-zGR--^iqmx* [W}e .ɉr4oj3=,p@0cwa j5OOOCqu8@aZ7uAb֊GNkAw9D-[ o8HB|=U9f((:XQ|ặ<3z밮 d hViwH9XOݤ,\24eCryU'kI;] lM$lVQM+\HƵßyas0O$tIv/~y?v?M&L ]KZ,}Q3{21_CI-M fA獱Y{Dҡ\1Y|t֗S-&-,}j :"qYb韫VJ~׈a50_,vQ1~9nc=R~g˸M#*Q]8sf'Xҧ |3=Q(UىL檢C.GqE %m]7.Hqc1`~i;+{N6ayp(lԗ^@+|O@a{Gna!62k>PnqiҦ9bIZ׼*љgk-\]iV( =CLlz摱)T6ay|GJį(>M(`xAH!/Z͘jM$DZ| cQ,_`He-akɺ$B!C!B2mDT(> 3`p_l5N9 zƚDxAB` #[33漠gn<[=|{gW Ewrk(348.Yg-QaOby8h+s%SsN[`>ᴺ-wpS=#X.oDq^pOć҉[ zݑ" oVpRX:mf.SIn,V7*|E+澹0Jt-+s#l3xHs1| (Uo{O|y:}VGٯToIU9$\|_Iի]jٞۖ&-L/0_6-Z~\!ߨ hgzi w*uZLY lCc2$i_Yl[I3a@~guڀuwc(dk/ ^&e&rQrLҼ}ܯtv_M&ނ=\12Ⱥ:D9uaƇjҢo8xG8ޅOU7ٸӤ=00jnݗ!6RjC$ܦՁr !]> Ռ3ӸP[P~L h^alT`AV/l}!==&ETR2z"nB Go< h14BB.bZE1nsr[wf㑉a`4EI}I;lːJz1~%d4Zv9j8e(%UNèe K̵msQ$ In6>шitR{A6 h#8Sݘ _C$9pv?!|<+m[q6qxrruaXC&a ͺM/ysdtl1~^㬋I .NGg\=cV'ˮuhH-|~dQ@s[sѳLj؉$\"1܀2!H"row* %Yx/X?|&Y9HKR ga;ř <{IGV܁:D{b:OJ8,MO=)΢͢yy|@)/pI\{%F#-xǟ Mh&``:GX6&zpe6wl/)|, +N Bm-.F6n2P$ha_W^.A9/^]fsŒeXgG9ml${W*">c4 vSPnsFR]d* $;ܴ2/l{n|(q/ &xF+}HuV˖;g?kZI8RP:(4 yY冟9xH Z0t)pSPX1g)Jod18}7Y=VI2ޠ_i![}_fDWkSs؋AZUaWiԅsAf1e7KM,ьa㡮DXQYoc7+7;ǿKQl$E(fgx>;i 2iˮ M"p7h<ͧ5~,mR8d9J򍒭ji~ݭ*uͭۨ^-v MٛGyM_Sj{`NoS&8J‘`͒+3!^8 \Q 5,avA!C/ZsޠfٷC#p^)-E83`Rl>SaiVYP4*9bT~ f"ZHx~vus.h;3a~ ^o17 3kH+vPx[GSׁA-lhR&tv EΚNCU]xӵ&Ru\,IsQ:о] Ñ'p-6@85gi?^ygI(v7%qAHM]°)~6 cMdI8 2jR4]MCdOYNajY ac ڏ^DnL>_$} IDF!c=1Yk*(1頠YJ^6?*fϞ.:%̮W1%PT&Fc.5 b<'"R,WslbkN;GЍH7 Vἢʚgdm\UqiA叞{-4 rA=i kQgЭEvIP%J…ɋ&5V݆ei9>-fs7Xv3DE@렊`S$_{v, {~o?RLBTJl1,N3ch>˾W`,fN3-;9'mY2ԣVl!R|%HPg$aXՃy;hɄʤ09g (%4z$qDO6{KrGW|x 3?i h U h9nUK !3FAh41[܋ BGr_D.Q އ+#҆1_PtEiCjEK-Ƅ~f*}!Yބn4Nԏxyi^=>bڟŞmNifs|7(J~Z^BØ ωzԖv+H֬:zKt7ӓHQEj`yu'zd&%=<f)?%cy?LQPxrk'ܫ|`A#{ʗ4^j TMIeFތ8ߪ.{2I#EC<)_-o^1 ܽ Gڜ17\ralPAx 'D~ND1X.7&s8!`/>7 :z?ƥ sT%6 ?]7*(E "EzDZaނpF͍H= XPDKGFb=z]4#'m5_m2_>P&y`.<O.#_(I` 輳QSs~SO.Mz22 F _?.#cA!4r#u6Ů-f}[ .,?fh ,M;#3!/r~}>Ǐ'Hf8>qP9Iɦ)-! $+Xo)ˠN-"HdRAB";;B2X))B:fY2Y%EL'cj}4[#x?=܈):2JQkoפ,>Ǝ=Zqʎ[OgP d.o{ڲeOV= /wSH7+;K.ْwFU>{u =4\C3k#a^ KYTM9 !IY,ԅA,d)!*Z;X#4(~/E^kB[q<}rӱ7 HR|2c= d.鶱k3׋Aa'0mR7P&9_#3욞'uZ`"gM%8כ}bjH*i(3.0c#?vMá}z\FV[ ɸ¦zv^"WL36ݔ(2Y3Xfp},ЈndQ,ҘΌ:̝sCr90fLxCN;%dAD#ϣ cyPkd>{jISl~OzdLLT-3@mqw xkuz\g}llLózz5,N=f@fPyI]\y)B*r}z3@GT8 g0D|i~6L'䁈ٸVR`R*h h)I6MuV+`c^b*ţBrD/E sؚ+4IbQ! #ziR{ĵ8[}U6q\5@=V#`a ˫5N{1<xĎg%8'm:{glr䫇fi\IL"dMNjz &yCc,_)$4`u|N41.P5%`l_>T 4~_4I(( .MRw"&h$Ap$Ci%xgqw2"]}2qށԵTȽ)Q V&*3Jx6Zʽ(nѱWƪ]'mptgYh~?F jȨCӎ=Y'ȓ CdaZW Hy)i{Cx YМl,:#тm]!@bp~gQJTpI9Mv!g3c'V &""wKPϙ2uB5$|\_wwKk1FBF5RxbCbh/T3E`Y[D&V"-o"z@{kb`lEX`iH~G NF<4 Vt{Phµ;bcʬ.嘒ve>ءI[XGԨ.F(QS`)J%$6I]E QF'n%w5}r B,VcY.Wk1b[MF o&=c8F'0(lm{؈w#EW;sqAd0EeY-u1q= `~p:R$ ɖnBS` ڱ;T+3Eq f'Ѥɛl,e(}^Fuc2M_>n`mB^pJFʸ1#(v\61╊*& T;~0a/ Ǭ?Ǝbm3a9$DZ_ i]1W5*/kfP3 {`pGm(o Mg|꒝AS7}mQdTZ? g#:sAi5U3 _kWoffS.vIr^^[>!1EZ6aOZ{2ʧF^ٞ\1o+8`?alxiߠtzHꢙRY&1Éna/jIGw:yI9ɑOD_G~|D;x2((cU]ۿqyc5ԷvCEDD_Q`ۓ~ūǁƁW1Oǵe܁w-3xvoɟuv\j2}7 @>>s*(Gl>8"gU!Dd[暈-cY޾QΓ>W3G7f+X8 H #ȄYLΐuL/T㋌Ʌ>t[K!{ 0D-_?v>IIa/=ߤp#?$ѓ,+N2@daV3ilZ +@1@[%!?Q3 sv-L[vtr(7!׉" RU}4=ö́u{;ʻ@ݐ$G#_F3%u9=/o-eet&Fac:b6LPH}KH T\O:BtK5Fs`-{%SOl񄃡5(cśVԧwԄ~ [%ZO XC ]T1S-ŚM=;k;@3&0M0z\鲵j9DQ[*s@jtp>N/\ !Eu2ipߕ WińÃir@ CA?&5%ȀHG~ avY>N^MбcF|'h_o15 e?N&kE k݇,$ 3Qb %{: IP뺼}F4z'sqB. &UOtrRW GgHZIwjRI%73cOb/zxN/kV]]X59vWXJ '´ ϞvDa+ -pf39ٓNlI$`[*+aID=*Ϝ/ , /z e2?ruMm.%IkZ9Zܠ?To~_x*ZpgV%B#eO3 *'W䀹;־ޒNH qK2wd3 J:)E^B#zgj@2{N춖ˁdKu3 Hjf_5 eɊQ["āMYN+fzljpt]̕. EjSWE=XAVnkw؟ԃeU;z0"("\Bʽp6R Г,㗗OckIEY$ޑmfP3 = -XtFʿ@؁Kjut} {ש,xm\ N {> c@#{##RkL]`iR M ~Tr+RvAD(x'^i ٓHCANB^ПɺL[K6,p "൦7OHky>/yHcHgۈ D<~v><_%-xl>θħb'Ml=maA G/q]UzqğhuKZQЍ7dB.ܴYL=Ņu{@ܒd3di=^1D"!#2r1:4̩!M#ƳBJ:K̯gQBhbR{bgf 벏W dϐZ<ұ I22RC2Sh;_S-sZj424C>5Z(b ]k sҕ<5OგɃvӥ)/hdyߏ)2=F oYZE O2^ǟϲ5xF7bWÄrCW_ؗ=HjN+8wxNʡZȍ&~ٓ˘j?xm7j˺"W3tnd$KeG7Uȶ"lp_bn\\ -٭V3;4);~q3T;BX$=`3y4GZS|>c"("q1R-5*':A?NvL5H TQwvob>^XbY\vj6}"En@Ր[)/R̾4w=E Sdvξgon\İwc{ڮ#(2OΒk~P^EYtI B̿XZ7ܨm5SZqv?+K 5BmhLPVy}lh`ZecRY%~L%KgL}Y>9B9h+,k\' P~ xԁOnE&uX (KNoWcyU# mjW4 Kj c3)rY<64S:Oupt4> h']NZ{K% Een.\VEMo,M5Xud'7D/Ρ3:bO14x\*)CwbU,vx8Fgmq@v TF :€ؔMCD~&h `M(ޘ#F:Mjv!PBDsk HƠd&H_9xgzb)uAh] ӳs'd;mo>rC% 'gua8dHo@ScPT%NӅAL_H$%9qRm>(1&L(4LBrX89Lin2-s@`/rbXQ8+s31L*kKTʠO=m<(wji _5RD͎ ' ؟%Z!?,7ayh+1&&ݒꦹV(Pq$]cHlٴ0E򤂽j sbׯ{Ad@&4ud`ih%Fe]IZ$p媄-q7-oI7vPPlЋA#5V~t>LcBS-]%xH1&}ex"9Z{\ iV+&>uOb=(J[Nw!88XoÛ *> TX3ryrY,1"(y(mBċ1桬WV>-pť:Iz 3O%l%kWsTHJI湉UȔs{(az+ t6༏!u'WlG}7Ӫbt0AV_bWσ%^tN``ʊbZ7PsoŇo_Hr.F| q9R KfrITbT,+0X]M~8eGWdR! ՚v Ad\82v. ^d/+$宇NZ+F"=! BzBnx3'ٶֆ0;<)BmXXǕueSe b޹Qh Ce$3WZe$ՎlQ^tf$ HΚ O(KrA}7\M}FЧ0]tSK[_8ӹwuk[-om  }qE(Hz؈^eywuO3 !-Eړ$r^&&lͯ95jFU73bDzK=PGՋsatq PN|n?MH_&AWD$ 5Y7\`W}j@Da0Υ1". +I0޴Tobqs0N@#V<9>`8&ny⯇ơ}"ۜ - .3SgDTWPZ!JmyN& T).iBD]J/W?:a&qp 7ӜRjD`MpmTlnO*}SJnP+s4`,.3 Etg@H"鯘 Q&xxEb҃;/2ޏim~<m0xG"K"oT:Wû<>A [jj̓0 ͣAGˁAѾaV|AR7[,δ{jS/"_[ X&U%t%ڲdoI#xCRkZr0#ꅬNCˢ 1ow8;kT?i튍?OU- D%dJ]E" n-o8[L u~ C\gA;5cIy BZ 1ıu &L~aŏE0U@>Dk c "(+А<9=ϔZ/]U7hws+n \7OZe5(?捿?#Hޗp_WALN M9q>#sY a qAQ$#l A"9\KpvYkbx$#'W8?*bz3Zvsg՝R{4rB VW[R4b@~Pp nc<$b%$ /vQAj^`@А,/8OABnMapyiW7RmgzSO%PwKM xDh,{+*YX=Gl">m%N`*hؑ0+'jl ^7Gz/j(&*/^Km:49}cNd$czˢAh@j &V;,Y sRzmb" vi^T;-'p #6"SnګvvnjVwt ̽%,Id)I8v}ۗȖU2I]t`>bDi 7<b ^Ӹe}k#xզen+.%Ο+sRr `@Ic)VіXl>vR)IlE Ym}$ }PncjGn\/;YZ Fc(QpkߛTjcTǘnl_“[봵J{I\Q4D5gD( Lk|v &;(М_C۫lվ:⑥E&?TO5خQ𔹪m( % Jg#‹=F݌ =gkhBCm'tϛ݊Nv 8 f=~C-M <'Z}PޢѧA`ٜa[8+gн/s; vB)`j'4&rniމ3 N^0N}ajΛX :)Zxeph"⿩"M~,P"0:E C^?<2|kC璂qO1xT&FWӿ}?%hß(8Sp6CrR௻PlIqc &GNm-<2(V8~PTjŲ~ 0KI)ی89..pyk?,rϐnmilH4 (wS{¨1mz'|E3qaFiLHO|SW>BF6d?me"i.GfwxR7[X-&y8Ycy4?NtQYh!Ҁ0“1 4^;IBFU"d˃VbU0e@Ȗ=Bb4([fJ 3Tu=X)dضu5+Uäk{? X)ĦDƆbHM0xmuy/9F!py{=2T10 "iɥ$ f]XlJ4r˕nz[J[ti7Rq|izߞƭWw쫍aeP>" ?Z|񺹫²[B1Pv1 1VId,\ z87]`ux:(23RZqG1 .JS9&/}_q h>Y玱uwak6ȠY#U2wH[&4$x|Iޓc#Bổa6Nhs=O#6/  mxS@O8.xğ/;ٱX]s=CL`5h'I#Z!R۸mH>1P q_*O6x#&VzCHi|ZɰA3-0_ NE #l; GbL^3n`;1w5mS^mL~m`lpd |?c8R!ok..g3a u&PGC@]5M *‹$=>q,>9X[ >ϭ]Ep_pϦʒy-'owQs͇{_+< .Ãʍř9ϗ1Ĝh=!-Bj#_2Pj_F碖n|*A&rd<y%zepj~j_ ֨ GWD4^* e|ǽBOO©þ^kH+DbnBC^wF笠_Rw|ɸ|dF1yQvJ3~ 'QGvA܅n9@!d8 j%J.'ؔҝy wf5_"4ӭMa{3тл!lhCsm:TJ _26?4PTLΤO*znN]ƧBDe/@ԻI'%xd H:1wn}9rɡv%շMK0}'m Z- >5!&ߝB]a (AB'yeDarNߚʜ،/^U]sSE s&aNC@Fk i^%"A׼8.p\vs+ld=`@^=ᅉ볥Lõ՝?a%kZ<+ Cf3*|_%7E5_X1xgI$C92F,GΦňB !tÓng[,YYQ~0O/_OP HaG3qW 8 `Q0' 繱_pXlekNV1v2KJ~j0'GƫbB'mZoP1xNw| x12KZmb)o P6(bm+rSnՂQc+^ Xߐ@@RoRy4ѓ?zeW&;϶WW,H?3,kQ O4NJj%FVw捿;)>z~hzKZ?o=lLU&U .ѫ_@i1R(a0?WE`%QA \~*iQ¡B #~.-gl,] /;vVv9Z(891RΧP~ǿ ǒd6^ @rإmy NSo :%00SxqA,ԯrnD)e0Y]q,sÏQ81WJA|>\5VBXEP/2dKNCVQR"k~y0JN8u°#_37(V ,pb.,LHSڨLG J o4>gP_RiF[_pZOƉߥEQEe;;863 fM 4rt9YXC} |&#Sς};}24lu.a۵Mp(BhP5om%WAXhdO{NϷX]ey`}E\F=Zt2G1ɛƣEl^O bڛC 8.4k?U4cfyH۲QLlZW;{8wfC ?8 =UĞ>dsCL {+{YuSo;i~?a6 * <9!<5)f:qԣ6hM>V1;?f-7Z#t>jTLçG jU崬җ ("e(lM4,=n8M_x(ff_2?tyD] r7Ѹ#_cH2a[Blv/)yWݜ{h^KFDQFO PΆVݲ;FK(XV1w?J*D\)W8'"PQ.,̐#66Vb8ʜ(oiT|Vޅ UB+`HXX%[B^ Rv[$0Ρz^S?sŏ#ǖ9\QIa?qӽ@IQ:'P u /:7g%egnȓ(jpLYAsEze|a磀 \CkO_NYc | xwmK-ͬ@S)zk?Qmթ] ?]jr,oFDDN :v^,i7{q͍FU%t`c+ȵӖjT Tf☬ńtRcp2ڱ,1lc"`?Fh <$&H;4dH4n+4}a%輋d/8Q䎌3pZ LcI PP+7P@F'nYb<>^6㫈"pNTٽy 1&_S#lyQ<$|71>̨cJ`j33$ػ3swD ?-%Nm\~ā+G)0j͓ʮ4FQՑ[p*<@,0JSʮX1kȂ%A6 e8<F:{Y"1ԃRmV>w/:|޳KB]yviCEmh(!qf')8?;Ɂ9EIKn=/KE) {vvc5B̋$.`7%>U\908& wKP';{àIf>jya|hQMow2pB!d921~9b};k,_O80SȍݹPr(g".'#LR\^0Rmo!9rC;DW~7ZI?Fk}tx^6"4e65)OsqCi~~l7DϦ 6 ݀"7\^Ȼt w;̠2{V2ü<ȃ ^DZ6:tt#QQ8淕.UC'VJ';VE^hm,x(QEn"Ϋ#5}Y}"Q .h4zO,N6Fӧw6FpͶBZ|?u=ઐh`Mo:QqbY%H̟[됂[/LI7ڵ2 aO mY]I`RcJ|U*j` GjBԬuib0atI ̄9^ؼup 3!? kẀSb ]f~q:= fL̍9[\NAmqk}iA,C[)ӿ.3\b=Tگߗʚliv0|9kfZID(#a5 _0U [kmBlN)u|ؤn)0(3V i/;&R#Vӳ_ v(y}tKG'r5 "oo[҉sbHGՖR9U7 5yRMpn'C~_I6 tfr@Yh:j>?T-2 Bڒ,6x-U[- }e!K'S v7Q Dwٍ yn2]b>jSЖ>a1ia$ Bߦ&#%InBnqHa>%&_|#~'K:;'@5nU,Rl= )̳%ouG؛ւ! coIDhL+o?ZgS+acXiSjg33`c$jCB.(d$6qtP4Q"=0cmb!O&9heؾ;tl6\ 8[8v8m|z$2RP|[t}[Qr >s`@VRi.ƶowزl]By((̓_= p%QF[ f d0?4B QAKp?z ̺pum ѵhLq@zw@GvRL _IIssy `QQN0lˏaC*E|=iqcL\5`+K&#`dZs[maXmNj)aܾ<7Ty>ZQ~t#/7QƷXm06(ɩ;L T$Įz .^!6=@'k̩uLJ`DI1*' _لGozh,s)%OYgS֩UÊ{U.3S0w+Jg&FX{̂5*M^aV-o0U;BҼ5 &$3K1Ä]`iaqP*fU;Fۂk['Y7+nڬBOQ ,f? ܋xnKme H.!i!nk<6)3Q1ˮ=4tS΋K.W _|=Cy\}-dnKg1r^e׃Pi_jQ9Y Mf Ƣ P=lcAhpe%jɟQd8 qwZ΍Aⴚash˳Jv,%K`ha%d=Gφ^MSZ r7 Ojp2^â<ϒ<@ lD~?P%"#?/w6jtѨnujh*OXRnF cYP :*rt aH5)M5#t9Җu7CЩ,3L fQP䫳Q@4EQUUnB߮RxO+MVmt5\mle1-t 㰷EWFN556Q$iVs{e4moPBC{sEc R)H+!3,26t+v[T&/L'0)AO ]{:(H9IF?co큿eOiJl := sN >w9@H` $t9KʕsIP:T;1J"hxCL'LӨuUd G78&5hL .9έUfDk^xδF+lo7 u#cy"wɊJ+ǜL '߂Fj= AR$v|uG(%s06s{DJM15u>>𽗃ל8_!}].̂(61$8d-[{?CޠDz"ԢVE,lfc-S "R=&ݽ>xNG|kaz GA? &ŠĊeSELws6I T&_􍎲ЧL`{쌸N1}^ Λ¨8m+܎;La4i bhjWhB~</w1AB0^nFZf@  NǰZg͠o~kZUIp}4}1'UgP> 5LI]i`~˛ۍ')Cޫ50q?DtDl*cвJ< \5]N.ZmMg7H+%~~葓T4W8̴@cBPKSGէ<#ȧG#yj#I7 C&p  dnqAIޢwҹͽy+:\ɚـCoIwE-M.'џ仠։يo);P2/,d_e@m&4ԚJy[<:("/v}V/nC"23f? $[;4l\aM|SD9}1`0PQ3y?zE^/ѬO;O"ߌ*ȍ21[U섖 S>-{ncz >PE9490V~dYͺl'5bG_"VnsD, 6 ^=ڝřjŝ i QeËtLX\ l(eYN_5sMt$z=VzVqmgIc2|K\2w>jא[r`‹Xī`xڰB}&V2 Q ho~H6^@Ev9NJq] IKNc6ʩ **mNJU؈TI}̰:DIo˹+& T@T i)J&;QGSe`R@ܜTIs!5"Q=EgUMZ nOaAXƯ4JzP>`'qj;Ids:Wc *vVjLa6^s ;[;|%epu^ܛع&rr:cRdW*s=GNP.SF_G/N"ngVJ!B oȒMʥXyo@Y;%Z # 7(AkWޑk 7F|63hZ梗alyU2q6}E%4ٙ~'F<YE3Ypsv 3F̠ny 1#= V[?!hy~ۃ9vэ%ZNFͿBtRPSQx*s$N^U@;TfQzy& DHA\ule \t=?ZTn 6nlщ2MP[wʿ1a쁬vKζl`:=:!DRX(kWG)`(vYh6àg)xuSi\1ʸQwJُU 0ὄ'"h2D0zE Y@U6f#` 3ҦGg)ҡcQߌT(d@,V]''trr<du ;I AW-]l(PAЃ7C+oŁMgz|Kf{N*18˕x-lµe0F% yoS 8n}Wk}$Lǘ!O{o+~CK>K⇭R ٮ *vUrUarfwͅqU\S,) 2lW7~ޣ0`PAҘ9 D1,k 03 *ށb >4V8Cׯ)Lg%ӑ@K&vD`z…ui L h|+c]~H k?_@`p%ppMdb ÿR K  I~z2zozpeA,i_o0hI n`=[wB_oXɼ*6uS7 =+l;lBd*o_S:߫6N6'4玨R^(l ZM`+I++C*)j:ET#̚R}#Gfq'pSlɵ\H̏,ŲF}gxr>J=`}!9^K]F y}6~ γ1hwxPko5^-um=L' \8/& inA$Jb]aޭ h5P=W={$rhIs:v%6:{)MqȭD/^͉w붖ω)1PI;ٰ12*wdX_W85ux4~,# bܿ{qM*0zo9-* z@O{oxʄ%Ols W9 Ăg1_m™aٌ-HY6 s{n"#"LQBLZPtY8qϨD&tou٠"o Opc""t{;~Y{ɰ){m/$c*HBy#~l.t !zҗ)XhR^` tW2wEc\)?Ρ_@ &" qV`puZU%"3A_CDj!#؆ǀXz $LyA`_qy,pe:v0eyUorXm6=Wu}myG^UVc`C$^X~Xj>U>@#,4٨xkVmg dE)ioaTh6N~Q}o1R '&tL,+B*}ƄC ~6eXGmR# źې)薓t NdWNd_h~+]U^y?D!g2BLčg iœ2+hFVs:G?df C@ʟNU|7- ;)zx$Yu6S*?|32FVw¤0RbhZ2&ƿ~ .HҦ/:}HH;w8p* (-u:)J) ױԪ[*1Ρɾθ$0uoI"wTA^^|վy/l߱f$iTxx~ :`Z/-q,?1*L *ߢ} ##y8H'dZF^YOTD+Mlef԰if[CC?/2ؖ5ar*rP<~OM&'V`B4A5#0ŠazׯsfCQzTxm`!nO6Gِ6 הT`< wW_b2)|T~wNЩŧf pڦi#xen7@Hф4AtA@^+8}SL`D*EmOW3ko-'~ͨ,1/Zz@;qșRuR7<۔"QG>4LZ@̧Ʈ}[aoLbFẗ́'oJ$RՔˈ0VXJ-n<0let)[-\Q-(IvH= %5W0m-$a=e5V{6qvwAS}Ah@rB~JWogB үhkʙ0 OEr29pL$W  ͨ`]XKTdMHZ+rF()J 8ck/x0>~]W^sC]M!s  L<P \"֦gv(qK\(%FtfAlev0+2r]!Ul'SPĹQ='>IyQ.$#1a-\V}Qa2sި77ҽfɋ<'\NAAFn3տ8RU.\?q/b (dEaKJƳi>t):Ha7ސaҮ4/q X@N{U:HiA[ҥ[S(X@ϗzW6T΄~7\s=j B,DMlεG,laV.ZgJ* 3dpesd~2Ԑnu^s:Jb(c|ѦX/y-6PLn aÀ"NA!ZR҉uĦ _qk߶09A]c.@U=oNR?4k:7%7۪Yך|ߤ'WMH u"s,P`Fذ)ZA_]nrL/+dko34nPN-s b1LS/p.eb}r-IJK(K\N\Zm$3`fl@ྀdg'?Oߝ6;gsNƿ]r;2Kܮ~n}'@M`iu-侔V+b1ǜ. 5G=^oPqPfYqg;r_ &5U =  276*'^ʖ+}tݓ= +U7ed EkOdK$LC[7޲e&%AvDY2v}shb|nҎtk=f{p>gV<ݵF ]?{ g3:>XfC@ڂy4>O4jU*GHU]b PAy| _cO6E0_Ē(XmH]k))m: Uf%lx[LgzZ';kfpo`Z N?=vl-ULCn)*ӤM #;5 2X2t4BJ-/ayFА= g! G6ՙ1h`.>,H8?0|jDqwf183=ygMV@4sp{gSC,]='zAyTWȭdy?/T2@m؀O]9/0ET}|?OŒuBEVDXb:x/!d;Ù5' {!}x3zmG y<U"2CLgAŬFyژn67Ąh[j SȉLzS.\<[9!zi52f oG>ޔPmvGP/+N4v *g#a~̀CXINJZ'E˲j+'O$62jjB/el+ %!V=lXɦRە)LFeQ?GVW$Q^O:ĘP|2?_RVLN|^܂k+sϭH nlR/܆L͆C8x܈Z+]vbN5-o1DvQ%jZ3R@>7H!a\Z@InzL߻ ^sVf7[VNbrul7L6t֐c֬oaA&YrS dhҦ8'}(đCIqQ+ͩR1&d/KJySkW;K=maPIoӦHɆS uDqv=$ut,sZ<}De4X.z^VU6SrJf2Q -6(AZ@n!ƿ*##:JM\4;&ζydHL)<is}Dta'+_*($+ҤgD@!z'_&#4E|b[Ҵ}ܖEEBO-y|)MaK^CxW@W.h %#9g1>l&)GbGMXvKECKtEkS:@whK+ Zp}* SPG+3I)G:@Laak8􃈩VB 3SG͸5kѪw$*#TGx@h'iL-2Bf4&ҩݶݧǜXӪl ) }q"-{Ue'cr_5*m_4V!xfJQ$Y-\/-ybnl1^8|]XQ#Vuڊ<xL"$c `.o4ehz^]Mrj6%umKy>FUI'=t&&ơR% P-#ul$ߊZ(j'!Cۜ߈.yT2WS Gx2PZ(bl6цG[ahX,E{àb{W;/'x7'W)@SI{F#^j ՒB*dW]!&c~eK}`ニ&˫9զ6{OF@Ll Fh浅 8GzF8rXuT]9x$I!g7 ۛ9ǰP=# 8ukC悱?U!n==-rOۇ7F-C@p-k=pGGKTn RofԌ8uϚz8QCAj K!T҆qx b"?'zݕ^6 ǒ!W[Z|ht7~r`KީmϏ59HU|ϵjjдS7=4k 0h}6D6.WkR2ĝl Gt ^.Ʃg>@w;>`*֔ 42{7b?pi/!Ց^uNm%P59 zq5yw"K*w2Zz䤐VNXk4xHE6f hH;X2x4rH>ۧc=>6Ig8pMhl3 I1 ([iU 93iU=腹¾ml> >RCUuM^&RF|r8DY>Y#j}v*!}wrz雒wpHdXmbR&0ۅ])~s;ַ2xt4i{*I`{vBVi z%CJ̖·,!:Df$$*Qϸ1j܎P_"~7ZVh>0y=*{/`yV^[oa<ȸMPr}*_mbcCiSgyM~ N!A?NC~kl}w*P*{%u9f6[Y(b*QJE<+ԌmNV7%wf " bdќ9dA|QZUu-)!䓜ÈX_a2%+́ 5'p+mVy凝U:8~[S8Vf[J9v`1qD]1ħh:4G: /oߜ /:dit>yȕZ2EvQxGX7yAك4>qZZ2(.m\&ࢢEZ ."W;TS/(- F|x*4A SΡmf>ov!G /:QlMQS(/j.%&*+.ǀ3]RW'z89zb[q錧כ ?Ş;3~ ܝN)xVCR_$<}0ɸ/Ojn莈_.0W-MQ}:ҫ*q>MJ(g KH/ȋXq p2k*%qiG]f{!Ϥ~&K$tnB(Quaq޲`"qYsf-nS]Ks+#ڽГ383\!a! N '@o,=6LJjR{vK*ۧZ#X󑹃9j_.‰Y5&/=rgE뿫ټ@[W4Nd$vqD7),"4M+HI חp2a7_{Yb~DQC|4nw7I-]^e/z]DnPFcᢡ?[ AQ3ٖyض`hPc#X"w wSjN^LBPLH8»6R KC/\+2K904 L阊 1Gf? <"0\S{g爊v0ϦaVz)ڌhjO:x܎IaJˋBvs?DH9)P3KG,?OxUen Txm ihy Fc*|3SX z bհM6=K&b­e[m(Th~o5? /έ 5f&#z0xYB vP42޲m?Xt,n-[l *CuCfEbC4qm37D[ J+C֊^xͬkhEZCg&XY>Eπ}P*Ի<[X-3|vcH%Tk:1a9jWFlUqjk&*~Q Cp7!Ii8#2=f;%Q:{v_LJrd1> 9S~_ZB.i|jw gQmQJvSWi>E܏oRvbӔ}Xu.lz??$@ x,EW>C]#ݧcp$;^AJ^r]eO֍%/DNt,g|E BɓeaKA?,UKweP1it)JHh<\T 53Yі*.j!9avxջ-pNw}V艮4!r(jN޾Zw?YxVxyT 8 җ(Iz$K.v bnA = IraA' n) ºɿGjeFhz$֘ꑶ*E;#~S>Mi6c>iti{yZF$m9M7#9!,rRM6 =?wlTGcs$1,D~O>+?LPp_'e&=:יx5'bUdSL!bĥH". ~3+Æ94Fi҇Uc zӇU=KWǰI;Z[PK{愈>;Q3ML6Uf.P45ID~`6K:,wq#2 W"}ijy"n LK, '%a 3]!I;Ngzc,3-@7,;/=Ƀf'lYZh&Gޚ!_O멩}j,rZr#:<ZXW{:'W޶V@pzQ.8 32xO13pF|<Z9xm&2pۗΑtqۧWpc=uGWLy dMvyѮW!VGh& C[ Dt[pͳ0q-):ΣP%1i k:Dz]Ś-KK#CPtaMA .1~>?\.M֨u GjD-oߠ_cy9윴qjܒޔ{˹%o# z