libdnssec8-3.1.2-bp153.2.3.2 4>$  ApaV&!M@eeeo&"~a(|Ta}԰!.ws9Z֥`̨ޗ-^^SzҌ-15MQXKT\#Yţ'wwT]*r^,,LU҃Xd GscnPk0d,j1 Ţ8WG@ Þ*$-!ӆ{^疻 c'X%) PJ./%*'z]*;7 W:eS:640961d7610cc1a54e886cc08287f153f4dde9052bc9fec5013755099e3c72800db107727439b85474b4db68efcb1cae4987d156,aV&!M@eeeq}x+N^6c L8v veZFz`z5/+ E*, hu`ܢHZy)#U6UpZǞL1\9!힩p7yh,F4fBj|4VrխpҹO)7TQ!ÿ́F:>D<m3ő]h[FvjY3Y:\xb.EImb[kV>0("n#QW_ߊ4=4?g>p@g0?g d   EPT`d}     B X`jt(a(869p6: 6>c@cFcGcHcIcXdYd \d4]d<^d^bdjcedeeefeleuevewfpxfxyfzffffgClibdnssec83.1.2bp153.2.3.2DNSSEC support functions for Knot DNSKnot DNS is a DNS server. It implements only the authoritative domain name service. It uses a multi-threaded and mostly lock-free implementation and can operate non-stop during zone addition or removal. This package contains a library for DNSSEC support functions.aVs390zl270SUSE Linux Enterprise 15openSUSEGPL-3.0-or-laterhttp://bugs.opensuse.orgSystem/Librarieshttps://www.knot-dns.cz/linuxs390x0aVaV90f929f7784d803be6cd4884aeafe1ce612646d9082c51422f861bbf8bf2a63clibdnssec.so.8.0.0rootrootrootrootknot-3.1.2-bp153.2.3.2.src.rpmlibdnssec.so.8()(64bit)libdnssec8libdnssec8(s390-64)@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.10)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.25)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2)(64bit)libpthread.so.0(GLIBC_2.3.2)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.1aD@a @a @`ݮ@`f@`@`q`_@`\{@`@`_@____^@@^@@^@@^@]\HW@\3?@\*[@[@[ݍ[IZ@Z@ZWQYYYXWDB@W1@VwV@V@V@V@VTQ@VCU6@U6@U@U&iU&iTTq@T@T@Tk4Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Jan Engelhardt Michal Hrusecky Jan Engelhardt Michal Hrusecky Michal Hrusecky pgajdos@suse.comMichal Hrusecky Marcus Rueckert Marcus Rueckert Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky pgajdos@suse.comMarcus Rueckert Marcus Rueckert Petr Gajdos Marcus Rueckert Marcus Rueckert Marcus Rueckert mrueckert@suse.dekbabioch@suse.commrueckert@suse.dei@marguerite.sumrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.detchvatal@suse.comondrej@sury.orgondrej@sury.orgpgajdos@suse.com- migrate to user creation via sysuser-tools - run spec-cleaner on spec file - update to version 3.1.2, see: https://www.knot-dns.cz/2021-09-08-version-312.html- update to version 3.1.1, see: https://www.knot-dns.cz/2021-08-10-version-311.html- update to version 3.1.0, see: https://www.knot-dns.cz/2021-08-02-version-310.html- update to version 3.0.7, see: https://www.knot-dns.cz/2021-06-16-version-307.html- make sure we have getent and groupadd/useradd in pre * added dependency on shadow and glibc * might be related to bnc#1186023- update to version 3.0.6, see: https://www.knot-dns.cz/2021-05-12-version-306.html- Make /etc/knot directory owned by knot - fix reload action- Update descriptions, remove unsubstantiated claims.- update to version 3.0.5, see: https://www.knot-dns.cz/2021-03-25-version-305.html - Update description based on homepage- Trim marketing wording from description. - Drop old rpm constructs.- version update to 3.0.4, see: https://www.knot-dns.cz/2021-01-20-version-304.html- add incompatibility warning about 1.6.X version when updateing - rename back to knot- version update to 3.0.3- version update to 2.9.7, see: https://www.knot-dns.cz/2020-08-31-version-296.html https://www.knot-dns.cz/2020-10-09-version-297.html - obsolete only pre-2.0 version- remove rosedb conditional as lmdb is required in general now- replace conflicts with Provides/Obsoletes- fix dependency: python-Sphinx -> python3-Sphinx- use upstream example config file with correct syntax- version update to 2.9.5 - Bugfixes - Old ZSK can be withdrawn too early during a ZSK rollover if maximum zone TTL is computed automatically - Server responds SERVFAIL to ANY queries on empty non-terminal nodes - Improvements - Also module onlinesign returns minimized responses to ANY queries - Linking against libcap-ng can be disabled via a configure option- version update to 2.9.4 see NEWS- version update to 2.9.2 see NEWS- update to 2.7.6 - Improvements - Zone status also shows when the zone load is scheduled - Server workers status also shows background workers utilization - Default control timeout for knotc was increased to 10 seconds - Pkg-config files contain auxiliary variable with library filename - Bugfixes - Configuration commit or server reload can drop some pending zone events - Nonempty zone journal is created even though it's disabled [#635] - Zone is completely re-signed during empty dynamic update processing - Server can crash when storing a big zone difference to the journal - Failed to link on FreeBSD 12 with Clang- update to 2.7.5 - Features: - Keymgr supports NSEC3 salt handling - Improvements: - Zone history in journal is dropped apon AXFR-like zone update - Libdnssec is no longer linked against libm #628 - Libdnssec is explicitly linked against libpthread if PKCS #11 enabled #629 - Better support for libknot packaging in Python - Manually generated KSK is 'ready' by default - Kdig supports '+timeout' as an alias for '+time' - Kdig supports '+nocomments' option - Kdig no longer prints empty lines between retries - Kdig returns failure if operations not successfully resolved [#632] - Fixed repeating of the 'KSK submission, waiting for confirmation' log - Various improvements in documentation, Dockerfile, and tests - Bugfixes: - Knotc fails to unset huge configuration section - Kjournalprint sometimes fails to display zone journal content - Improper timing of ZSK removal during ZSK rollover - Missing UTC time zone indication in the 'iso' keymgr list output - A race condition in the online signing module- update to 2.7.4 Features: - -------- - Added SNI configuration for TLS in kdig (Thanks to Alexander Schultz) Improvements: - ------------ - Added warning log when DNSSEC events not successfully scheduled - New semantic check on timer values in keymgr - DS query no longer asks other addresses if got a negative answer - Reintroduced 'rollover' configuration option for CDS/CDNSKEY publication - Extended logging for zone loading - Various documentation improvements Bugfixes: - -------- - Failed to import module configuration #613 - Improper Cflags value in libknot.pc if built with embedded LMDB #615 - IXFR doesn't fall back to AXFR if malformed reply - DNSSEC events not correctly scheduled for empty zone updates - During algorithm rollover old keys get removed before DS TTL expires #617 - Maximum zone's RRSIG TTL not considered during algorithm rollover #620- seems we no longer need jansson- limit geoip support to opensuse- update to 2.7.3 - Features: - New queryacl module for query access control - Configurable answer rrset rotation #612 - Configurable NSEC bitmap in online signing - Improvements: - Better error logging for KASP DB operations #601 - Some documentation improvements - Bugfixes: - Keymgr "list" output doesn't show key size for ECDSA algorithms #602 - Failed to link statically with embedded LMDB - Configuration commit causes zone reload for all zones - The statistics module overlooks TSIG record in a request - Improper processing of an AXFR-style-IXFR response consisting of one-record messages - Race condition in online signing during key rollover #600 - Server can crash if geoip module is enabled in the geo mode - changes from 2.7.2 - Improvements: - Keymgr list command displays also key size - Kjournalprint displays total occupied size in the debug mode - Server doesn't stop if failed to load a shared module from the module directory - Libraries libcap-ng, pthread, and dl are linked selectively if needed - Bugfixes: - Sometimes incorrect result from dnssec_nsec_bitmap_contains (libdnssec) - Server can crash when loading zone file difference and zone-in-journal is set - Incorrect treatment of specific queries in the module RRL - Failed to link module Cookies as a shared library - changes from 2.7.1 - Improvements: - Added zone wire size information to zone loading log message - Added debug log message for each unsuccessful remote address operation - Various improvements for packaging - Bugfixes: - Incompatible handling of RRSIG TTL value when creating a DNS message - Incorrect RRSIG TTL value in zone differences and knotc zone operation outputs - Default configure prefix is ignored - changes from 2.7.0 - Features: - New DNS Cookies module and related '+cookie' kdig option - New module for response tailoring according to client's subnet or geographic location - General EDNS Client Subnet support in the server - OSS-Fuzz integration (Thanks to Jonathan Foote) - New '+ednsopt' kdig option (Thanks to Jan Včelák) - Online Signing support for automatic key rollover - Non-normal file (e.g. pipe) loading support in zscanner #542 - Automatic SOA serial incrementation if non-empty zone difference - New zone file load option for ignoring zone file's SOA serial - New build-time option for alternative malloc specification - Structured logging for DNSSEC key submission event - Empty QNAME support in kdig - Improvements: - Various library and server optimizations - Reduced memory consumption of outgoing IXFR processing - Linux capabilities use overhaul #546 (Thanks to Robert Edmonds) - Online Signing properly signs delegations and CNAME records - CDS/CDNSKEY rrset is signed with KSK instead of ZSK - DNSSEC-related records are ignored when loading zone difference with signing enabled - Minimum allowed RSA key length was increased to 1024 - Bugfixes: - Possible uninitialized address buffer use in zscanner - Possible index overflow during multiline record parsing in zscanner - kdig +tls sometimes consumes 100 % CPU #561 - Single-Type Signing doesn't work with single ZSK key #566 - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - Compatibility: - Removed obsolete RRL configuration - Removed obsolete module names 'mod-online-sign' and 'mod-synth-record' - Removed obsolete 'ixfr-from-differences' configuration option - Removed old journal migration - Removed module rosedb - changes from 2.6.9 - Improvements: - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation - Bugfixes: - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - packaging changes: - enabled geoip module: new BR: pkgconfig(libmaxminddb) - enabled cookies module - enabled queryacl module- update to 2.6.8 - Features: - New 'import-pkcs11' command in keymgr - Improvements: - Unixtime serial policy mimics Bind – increment if lower #593 - Bugfixes: - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy [#589] - update to 2.6.7 - Features: - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) - Improvements: - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination - Bugfixes: - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback mode- Update to 2.6.6 - Features: - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation - Improvements: - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination - Bugfixes: - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- update to 2.6.5 - Features: - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set - Improvements: - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates - Bugfixes: - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations- update to 2.6.4 see /usr/share/doc/packages/knot2/NEWS- fix tmpfiles scriptlet- package /var/lib/knot - run tmpfiles scriptlet during install- update to 2.5.3 see /usr/share/doc/packages/knot2/NEWS - use libidn2 on TW and 42.3 - following modules stay static: - dnsproxy - onlinesign - moved modules to shared building: - dnstap - noudp - rosedb - rrl - stats - synthrecord - whoami- update to 2.4.1 see /usr/share/doc/packages/knot2/NEWS- update to 2.2.1 - Bugfixes: - Fix separate logging of server and zone events - Fix concurrent zone file flushing with many zones - Fix possible server crash with empty hostname on OpenWRT - Fix control timeout parsing in knotc - Fix "Environment maxreaders limit reached" error in knotc - Don't apply journal changes on modified zone file - Remove broken LTO option from configure script - Enable multiple zone names completion in interactive knotc - Set the TC flag in a response if a glue doesn't fit the response - Disallow server reload when there is an active configuration transaction - Improvements: - Distinguish unavailable zones from zones with zero serial in log messages - Log warning and error messages to standard error output in all utilities - Document tested PKCS #11 devices - Extended Python configuration interface- update to 2.2.0 - Bugfixes: - Fix build dependencies on FreeBSD - Fix query/response message type setting in dnstap module - Fix remote address retrieval from dnstap capture in kdig - Fix global modules execution for queries hitting existing zones - Fix execution of semantic checks after an IXFR transfer - Fix PKCS#11 support detection at build time - Fix kdig failure when the first AXFR message contains just the SOA record - Exclude non-authoritative types from NSEC/NSEC3 bitmap at a delegation - Mark PKCS#11 generated keys as sensitive (required by Luna SA) - Fix error when removing the only zone from the server - Don't abort knotc transaction when some check fails - Features: - URI and CAA resource record types support - RRL client address based white list - knotc interactive mode - Improvements: - Consistent IXFR error messages - Various fixes for better compatibility with PKCS#11 devices - Various keymgr user interface improvements - Better zone event scheduler performance with many zones - New server control interface - kdig uses local resolver if resolv.conf is empty - new BR libedit-devel for the interactive mode- update to 2.1.1 - Bugfixes: - DNSSEC: Allow import of duplicate private key into the KASP - DNSSEC: Avoid duplicate NSEC for Wildcard No Data answer - Fix server crash when an incomming transfer is in progress and reload is issued - Fix socket polling when configured with many interfaces and threads - Fix compilation against Nettle 3.2 - Improvements: - Select correct source address for UDP messages recieved on ANY address - Extend documentation of knotc commands - drop knot-2.1.0_pkcs11_check.patch- enable libcap-ng- fix configure check for pkcs11 support: adds knot-2.1.0_pkcs11_check.patch- fix soversions- update to 2.1.0 - Features: - Per-thread UDP socket binding using SO_REUSEPORT on Linux - Support for dynamic configuration database - DNSSEC: Support for cryptographic tokens via PKCS #11 interface - DNSSEC: Experimental support for online signing - Improvements: - Support for zone file name patterns - Configurable location of zone timer database - Non-blocking network operations and better timeout handling - Caching of Critical configuration values for better performance - Logging of ACL failures - RRL: Add rate-limit-slip zero support to drop all responses - RRL: Document behavior for different rate-limit-slip options - kdig: Warning instead of error on TSIG validation failure - Cleanup of support libraries interfaces (libknot, libzscanner, libdnssec) - Remove possibly insecure server control over a network socket - Remove implementation limit for the number of network interfaces - Bugfixes: - synth-record module: Fix application of default configuration options - TSIG: Allow compressed TSIG name when forwarding DDNS updates - Schedule zone bootstrap after slave zone fails to load from disk - avoid activating the intree copy of lmdb- update to 2.0.2 - Out-of-bound read in packet parser for malformed NAPTR records (LibFuzzer)- split out shared libraries, knot-resolver uses some of them and atm we are forced to install the whole knot2 package.- lmdb seems no longer optional- create a new branch for knot 2.x starting with 2.0.1 - Bugfixes: - Do not reload expired zones on 'knotc reload' and server startup - Fix rare race-condition in event scheduling causing delayed event execution - Fix skipping of non-authoritative nodes in NSEC proofs - Fix TC flag setting in RRL slipped answers - Disable domain name compression for root label - Log via journald only when running under systemd - Fix CNAME following when quering for NSEC RR type - Fix refreshing of DNSSEC signatures for zone keys - Fix binding an unavailable IPv6 address on Linux (IP_FREEBIND) - Fix infinite loop in knotc zonestatus and memstats - Fix memory leak in configuration on server shutdown - Fix broken dnsproxy module - Fix DNSSEC KASP timestamps parsing in strict POSIX environment - fix multi value parsing on big-endian - Adapt to Nettle 3 API break causing base64 decoding failures on big-endian - Features: - Add 'keymgr zone key ds' to show key's DS record - Add 'keymgr tsig generate' to generate TSIG keys - Add query module scoping to process either all queries or zone queries only - Add support for file name globbing in config file includes - Add 'request-edns-option' config option to add custom EDNS0 option into server initiated queries - Improvements: - Send minimal responses (remove NS from Authority section for NOERROR) - Update persistent timers only on shutdown for better performance - Allow change of RR TTL over DDNS - Documentation fixes, updates, and improvements in formatting - Install yparser and zscanner header files - Improve lookup of libsystemd build dependencies - Fix compilation warnings in endian conversion functions on OpenBSD - changes in knot 2.0.0 - Bugfixes: - Fix lost NOTIFY message if received during zone transfer - Disable fast zone parser when compiled in Clang (workaround for Clang bug) - kdig: Record correct dnstap SocketProtocol when retrying over TCP - kdig: Hide TSIG section with +noall - Do not set AA flag for AXFR/IXFR queries - Features: - DNSSEC: separate library, switch to GnuTLS, new utilities - DNSSEC: basic KASP support (generate initial keys, ZSK rollover) - Configuration: New text format in YAML, binary store in LMDB - Zone parser: Split long TXT/SPF strings into multiple strings - kdig: Add generic dump style option (+generic) - Try all master servers in multi-master environment - Improved remotes and ACLs (multiple addresses, multiple keys) - Basic support for zone file patterns (%s to substitute zone name) - Disable zone file synchronization by setting 'zonefile_sync' to '-1' - knsupdate: Add input prompt in interactive mode and 'quit' command - knsupdate: Allow TSIG algorithm specification in interactive prompt - Improvements: - Zone dump: Do not write class for SOA record (unified with other RR types) - Zone dump: Do not write master server address into the zone file - Documentation: Manual pages are included in HTML and PDF - drop patches which are included upstream: 0001-loosen-openssl-dependency.patch 0002-make-configure.ac-compatible-with-old-tools.patch - also drop all buildrequires just needed for autoreconf - new buildrequires: pkgconfig(gnutls) >= 3 pkgconfig(nettle) pkgconfig(jansson) - create devel subpackage - enable rosedb and bash completion- local state dir should be just /var- enable dnstap support for factory and newer: - new BR: protobuf-c and libfstrm-devel - prepared lto support but not enabled yet, still need to find out which distros support it- update to 1.6.3 - Performance drop for NSEC-signed zones - Proper handling of TCP short-writes - Out-of-bound read in zone parser for long domain names in origin (AFL fuzzer) - Out-of-bound read in packet parser for TSIG RR without RDATA (AFL fuzzer) - Out-of-bound read in packet parser for malformed NAPTR RR (AFL fuzzer) - CDS and CDNSKEY support in zone parser - Add defaults for TCP config options into documentation - Detailed error message if zone reload fails - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch- update to 1.6.2 - Limiting number of parallel TCP clients (max-tcp-clients config option) - Ignore refresh and transfer events on non-slave zones - Compilation with Dnstap support on FreeBSD - Possible file descriptor leak when terminating inactive TCP clients - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch - moved autoreconf -fi to %build so it wont be tried in quilt setup or similar tools - move up the %if case for systemd in for the preun scriptlet to avoid warning about empty scripts on non systemd distributions. - used xz tarball: new buildrequires xz- Add deps on the docu packages to regen documentation - Enable systemd integration fully - Add dep on libidn - Cleanup with spec-cleaner- Only require lmdb-devel on (Open)SUSE 13.2 and higher- Updated to 1.6.1 Bugfixes: - Journal file would sometimes outgrow its set limit - Fixed incompatibility with OpenSSL 0.9.8 - Proper handling when machine hostname cannot be retreived Features: - Support for DNSSEC Single Type Signing Scheme - Compile with lmdb-devel to add support for persistent timers- Updated to 1.6.0 Bugfixes: - Fix zone expiration when AXFR/IXFR is being refused by master - Fix forced zone refresh on slave (knotc refresh -f) - Persistent timers database opening after privileges has been dropped - DNSSEC: RFC compliant processing of letter case in RDATA domain names - EDNS: Return minimal error response for queries with unsupported version - EDNS: Fix interpretation of Extended RCODE Improvements: - Maximal size of persistent timers database increased from 10 MB to 100 MB - Added logging of persistent timers database errors Features: - Persistent timers for slave zones (expire, refresh, and flush)/sbin/ldconfig/sbin/ldconfigs390zl27 16330795433.1.2-bp153.2.3.23.1.2-bp153.2.3.2libdnssec.so.8libdnssec.so.8.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protectionobs://build.opensuse.org/openSUSE:Maintenance:17006/openSUSE_Backports_SLE-15-SP3_Update/a08d5cf2d25af1f2ab7fa81a995d2fc0-knot.openSUSE_Backports_SLE-15-SP3_Updatecpioxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6db75a4f9ff2b1bcbb95ea17ce796a09f5dd5a50, not strippedPR R RR RR RRRRRRR RRjFNjjYl9ѕ׃;1EAI$I.ys01{j-#@_b7`WnMzX_ʕrY7T13=HK&ɅFlhf l|e0o7l y)rvhK"ݔ|B=oK=eݶ8  kM)#W-u8rq DYYArS{͛'/玱pl.tQ4.F`r?Ƕ6 JЅG(*9$_ٔRӔ7V w?^ObiƧX5r8P*V:_ W)r3BUX[ wT9Z{b` \kDn_T)‴m88M>_ϋsQ?(SuFoPU,0ܽ.Zts:zwuvꌾ( w,\Oz)O;}r{%Q1s1(tKJPV̀}\oHu| @4~z0Ղ)fr_l#fY@Eƌ b"߼ے=W=ϫ}0bZ`;veN&H-' w9q/Q!E%;}t5YwB:ު^" 09ޣB#3IFbtoLq?>t"!1D%ᵆf kC#?QoWdoD>|Xj؆:^kh}]iv$DcBu*bLZϺ^~!HmV\1[v4:}& ^f Lm||<<[^AAʫNe|ޘ7t"3]P9qx3$U\ov\[p۽&0g(~,\{]~K9odF K?,h ,|Sѓ 4,!@]ƥ8K:xiF("0+EU{xdn'lW.> 8ᥱd+ف3>k?o!1^4:_]z#:N{i'dqv5}$yD P5@\C*_r8MZwH/qt^J3,\b_sH;9j>W-JZ6oQYF.IJ:w{{m+iȕ((@*lA\{!"Vº(o3Oas~Nmd=l(LrbZ\tH]A ٻ3Hj \$ DoDŔbwxQ%8'$ Z)JP7VJ/i~D 8bp0dAuo Rzܢ|`w3-=Y}y`WGMA{vb,zWP%6,bygeP6!5-!n A|HAT2BHbtjݣS/֬۸'XD7zC: Y(K4+Mr#dc߄3%W񓰓:Lv +K@#wD0&MΟM0`D`8 7bJW;8x)lhM=^>$O ь׎\PR4Yd0M W]//X}(tVµ~z0Z1 ׭pn2t3 -/id~)Јп0mQ2)MU/nv$g%@`&OqWV;OHqL9qqk=Q_+tFFѬ`6KcZΤ@$ 7i?át϶cOhatP(ϱvj)p 'N+2PA枠ؿn -: V*?bzN- ]v#a^y ,ņt!gߓCi$JQ:ju,+/Kq$.CřZ/SA2=\v6mNvqEAA8h $ fWW N!0|P҈0|gخ\lIlx>>hc5@.-]X]U1i~J޺"ҿk㎞x !v7f.7At@ C;-6k:M\J36$QoV N(n.K3]t} Ej&{5Y.qAMĥ,G a;]:=j[C[K u?M(Ժ 6.MV*T(c^Ou j\bZ};s~M3N4}%h;gўX$JdsA&\~BmdP4"ƲD*$7aOvfi8=kB]G 3|롭&wD 5)$5)r |QFb\Vg=OsyiL7Q6Ɏ=l[(־A﹇vR(>l5nq\.vwmQIBU'N I]b|vPqFdܰ sJ' $Z{ɰf۱MD5qEƅӛf~Jr6͊G0&r WYm/=[E`kˈ[$H+|k-447E'' إ:$[B-}%z7I|GKgtÉ7m=zN Q(|FK5+R HOǖdM&!;./_@@#^B1V rgFd?,ׂ*I8E=8 >vnW}ym46UG?ŷ]}MM y٣;Uޯ^d{ ZCqU̚fk_$غ 0Q;D-Ѥ,e|νT p];&P* iPOdtK:]ۮF,$iY@}(m*Y&GնD Є߮0(d@ {j9Au4[&AΌ Ve7p_6"-titOc(M﷞ cta,)xJc-\Jp6tdbۉwLPѳ ~1{'~1!~|Yˡ m0vP%LV p OmdB-!l!Kf˚-;36K|XJPjkL!3aCLI;Cm %ִZx)C)<- qC=>v֕r?]c5q-ڏPݜǮLӲgcd²7UWTt䣴ʛkj_!ۑ@*({_SS?X<ʊل\TeLIvP+i U\v*yK^Vl\oDk}<+RZu B)t7K Ŀ/pWI ߎV~v`t]-} U p"FdZHQl%SԈ OD^;8*a7AG;#)+m >Ct4XA}Zm~ETH7 Oݭ2ޭ*9QWf~P]y(2uHHf`\f5毱u)y {nA}υn|\2Bo6`&Öac?㢓'  p65dj I?kMjxsnIh2ڪjMPol~UxV` gן/W Z6H~`3_*X%@a;޵pNм._Mfr;#8EA/ҷ]l1L mE ڷO^Q+\?z'zwU~u\@@;VM O~s /ޖj#nJyrPpg>ae3j^OD֦i3GwI# s,t7=YxsKޣ'Wi }=6TscHLcĔh`wT(Θs+S EN6%m#fcIPʮ+8\߆s̷ÿL%vaŠdyHرƢaL-ݭn:R T9Qoo?XC=z&RLٿԻսB7Lcis)$<X8HF jgo3Xm. y ZMIY夁4+N--z s@lVt9}d cKMHuKf{MVc][C6lK判X#^'CSt!'bbmXWoz3^d@EtU,u 5 쭥v^$ʽ> H,{n` 4g1ݍҸ:{TIDTZ}Y*\tU|EÖP ,Dgm { uh/vSqvk " ο3i!#M`'MηRwkp3q)pfJ#E`>>vB莀6cNȖgt#f]k#:0W~B3ya8EQ.KZ-y p@w]}eEO Z8X@jZNn-=/m;Pʌ] A3 $YPJot`cZY۽C[8qhl& ?g)rcdCJkp/c7S:]I#`^%YCMa@4-2W.EɫN-Ge^oe0 Pwðx$E O;HQ̋}3V/ho[F}CO̻{J=-JTzs*Wfb3VgТ[0'#6^Ѩ)v Aq>k7.n|rS":ETz˥y")' /ɣ"u5Oo/5il)H*L\*S6՚ц2&2n !>A^q 11WW_Tۧ %m0*n[::ӊsbI-A0]C-d=5=L^rgkCz'Ǘ{z9>7ՉLxVL'pmF(ZzX`R,V̢E71ϙNLE~xE19ihDL.n%oѺ B|tl&lPx L'4w=lXz( ñj H@Ed:0Ǔ$/n>7M1g\ں )sYo~dJ`țF +xjU !#I_3(nj뛥|Wb^&|Fsk[KKg^Z)dg\X$Hj֡5N$mWxbX!Le-F6C~5g Ö2foQ 8Q*Ϫ[ƜLːVEB\k"<E ށĝmJ Sմ)95Q1s}7ςT~n#_y3{A-׽v4uZF zWaH_v׉*Ş\!k3PI"\SFܕ+qW5gqVh[>+i3G 1ϩ-]jGf9XfMԕpm0jbIftXwWmSOwvdui ڻ'}Ed ()ˆjtGQ"Yu*ͮ&{|f}74a? ~F3 C Tm|vSL]F_P^@ڟ 3)}MྜD0/IV;(/}%Z~] e:uUƷy^&)1uy^ioZs7偻@7xl#֮z<*AJtk^gPmpL xOBm C<-<+!v6]}-s粤 JgIiXkadrSUUR7 JOEiUc0mnTдdăw;$-+T"(Y#sʠk&5@AB:X ռp/- |scdWt Ƃwi˝m|,ty5G_Fu{{Q3hOK v񩗩n#|^_uSY'\LJ$\<^e83G"VI,llEo#PD}-x̩xB<2"9Z:"^5'E]87[%Vw@lI%#LNuE B gfU?8Yl1=&ňoMuG#MG9m^C an Q=G B,hNKU?#q~3R^N!ДrN{s^]1w.>,o4<:lR9*"sp9l*}v}o#jsU0ɽp[ubv\$ T:lkr ~X^~+CwJ&pE=D>: 0~<hE)ȡt9ћɉ<Zlh n̍liqIDF*+{W5mKr hʄ˲CԞ kXnLn6qÂeA*ӷCc^zѡ. lP(bBA%E3T*R_Dl>^bK%Roq(,ఔ-MONg4z4oEi\)'} SSnn-,-htʬX^]o^زf.rf\w׏NA`|@2I1W|v|kYF=ZOx7ERg9ӢCf oy^ٳKFgd80Ak"x]6;70⦅s_74Rpǰ߂2^S*13=AS-{؞~A==Lcz>)R@:Ǝ1;+~jNFFHX`9 ɯ|<j¬~؂RtȔzc6-jΔ_¹` PI ,VnVUPoƬzjY 9H`nI1d>Yy+7`|+yk*v$vV(Ξa+kR_u$ v 󿄵9N峄$Έ22ܩUؘL `0-jwLV}ő nh/|>JyZ'X+\WߚSvF0 Ug0,3[7x"|p%5d}С2e +0NÆIuJ \_7Oۓ8>!&~V cQDJʖ<5>1^JG_6zj꒯* Xt#^2e'lx0ӯ*Ë"QNmTa b~ 7 ul A=%x\u2^a_WkjO|TN* 4K2@JMիpT+!2~D͗ hgiOH{ߴcEUQHؕ:f_bI`<"Op0D.{d ^× `pu <'?Q,ssGr/閇M,QsтoGZpsiY*)^SO<5`lzLFMZVFwNbk{[r {/ҟ]0;KCR9[4m?{e Ϲ#ᥓ2_TuAh %چ}#TC,\Uw ̣ۢ.YMuIDV5}u{[ $gFV?pҪ@-qAȰO26A@.0*J&^.n5#>?]NrFܿ(q&oMe&Bc6Kchb[?K5M;>V+eJ+O&%p"[.MHA/ «2oI|t]?5\3$hus(Pxi4RcuS=5BN+aEKʢ|/%CI\gpɜ,]88ңAsNqd( Vh+Gpw o^WOgcI{y,V*'J1zs擬g.ȣ!Xqtr&4AVZ;YO3"UfxN C۬XtGȾ^X?4~MLK/,^PrL02*'+OIJFY*yPNg/&+꾣XuWV``CW4P(I1;慪¥Poz 0)k*HLq9 ˭q8^iNC%sÌc3 dM7RiIREo @0z DR˫ץʑY'nPaȑ(8('VZ^WJ@ 7~~ 3Mn~LR'XBGZ2_Cvwr(n[^=vdMA75ΒҸ/`e2L9k4?W!ড[«Q䟝r8ScE *hBGuͨ4uk]J'r;9k]rL@n](D8:"ʝ)fGG0wDt:|*ϮڜLϛ%U;!H1Ns[; >r 83u5[A(,ܗ7A y-q^F/!{RRGL pVu7fG9h#g9t" t@N?Cl'4m8@UŏFw-4 3Z9ȍJo Bd[puP W'D@wE@C P~GSSO-; EMBlyEL^V~"߬"A@\0}to3!JF('ΙG\H -CQʛWh~{_K fg;@8LD4M#_pY9Gaf&AH+I?Bt 9G*M "sxMVݜlǛ@Vی `Əu)"Sۥ!ύSqVEڰoLXrń7:> *Y^R`Yà m_o6~P$"`d=EDR  NewoZMx%YAwM[hOF\O@4'ZOj2-U=Δ@WґuA;U] \%CHG",~Ve`'(\h'c6;uFt""'Bhx$Kc(3X,6ˢ]7$NfVR_F\NE|iS# gݠ紤EM_\ :dvFHJ{fe'ʅ'5y1I=e+RO?c=k""魠xmݯ,Ȩ x2?٫BEwaȃnOQT(~?mRI!uE~rk0tΕ4`z((K'h$s3&PqO[ Y2ClǷ1R]okғM7 >VvSPG/m7_HU:RF/^1HOu>EUpJrЂub%RF=uI17V?vƪ)t'A#죣9QRs^/ 4@@掼=.NKO+=dR*UȊC"*cf7Gjh7 o+'%5tD9Mˣ!SG*dyyEv˛u<ﴇTbG * X-9Efy+gӮ nD[ A"Vkz4oܞt -߉N2Lh8 ھ܍|Q53jguƮEk|{oYͼ|ܨ'] R,9_)#=Ð`VM,bn,}H>ŝf^gH[AaVgs)cڅ0_CYb`P cpp1&` ~Ic))J䴉) BNEF*(+Fk|ڽPouݗ?ð\̥1o,Rnc6Q8۔u?mfJ +4`\>Q)mXW|zPZؓSJh/N;_G"+s]_f[DDdezug$+_P*N`]]9Mf XX\C|hTj:g1{Bޝ6\Pׄ(ktMgt'䲪,FW똄hp(gUN_;ApqB&cQ\ C:QD>F#9>h })wKYSc@Qw15={EXw*$"}F WuPz[?ڐ'v(lQ*%<.RTn$?ń%&u6IT6^ӑS>@JRlzbxq |s&A(Hhx5 tM3ګ+i Uo!pǜ!w5d+UKroȆt/8q<'̀ ͱ!PƔ$LJ&VKRDV22s+) `itY%F}Jw#燐MmK!l;Egi+e ILcz:k6ԟ_HS`|$7ڱrcp=́k<&!ˣls'ScM6o{H|ԫB?]jf*6-Q %*?|+ǎ 9q9H K6pr>mӷ`I}D۫ha ->SUZ*ƬQ3_,:6;m#}Pty13/RE?_jzYwpBwEta9݉ʪHCeIM\5[,GMLgۂӞ"pI~Ǟ_nS,;g-aqh?YZ BúS&p 󖧚Bk@k%6JRRX^UJW@*d_2&t{`!sZ*">kNZɾ[։&XDz5hu6om<~Jn |a{BB&2| 5EyV_`-WMpo`-p1Ph%I_i}<J]PBCG` 8:_HIg67WԠlWn;jJ (I:'g](95/t?1[y]V]"Sk}0!(t4ʵQv !wVJ]O!`j8w212К #8+:.뿷 3D7O]hf@fJ@17$ѓC@8Rov$ ?DA"c .3M0 07p l"}rЩWz'Q99x6y?洿lϊm򮬈T^0 dv^a{VaDa;Chq]3PFE4 ZӿW@:I2]kBz 5Y2`=MRy"+2 ~s^Xn"!*B$j3V䈱L6]ε***+Z78gٚz[,z4LQ!}" 8 <܀"fo>~Jo_O&d9w!OrbS( 3 a5M݋Q%NʉPy/kӮ L}E<3yl4{]"6yh>3X{̜7DBphu"LvhG@2 -?GT9SWx+/e(Ie} sKϩJXuS\e%˓r4G#5zѹ- /:Ö)[3p~df}1)Ge#T,f{Ry,novJxQ\voo q{{ Pj%;7 яZ;{2gb*/䳋5買W1ͭnr |ZO3h +TW- @],ĽN_."gdKs=޳i qؐh M7CyW 7pFbєY(yniLƱs, s1z4y* /zU.uo"Q>5b"6Mx/5#~@EFUsYtz-vAaJn7¤aadDuv:ُ~GlDIb9;YޣT7t3l 2OCV.ֆXhbN/bϭ&t\1"H-̤X}pMk) 1,o"tt*/ vUyA jI6|ExYTbsp،3/x/ Ǚ?[XXBeNx?6Mt-H\$iۆQ[5GǸ!sϰ$܍r*5o@\ce/_RJ7p =LjJ0Iwf?;BrI{ٗ{CD#xOe A9}5oDѷL\IP$ilw&/ 9ʴ՝Pi'*aD>A`RNbgBN[.X?}bTS7D$\sq#F:ZgA<2"`מӎ `nԌ6!Nc*: ×:G!Bp"|uWf9"yLfQ]d9WeF?Ē˨O7i [WOTj1G^q@]cs3ߍ(rXdꀎbg sjb:D MlrsaO'7M[tWAH>DfD}<{ @zb#ɳbLlZcTf ߙuQҭt̂[| PYUM#եnK1zP MKd9x=1 0%4 >5FK*k g F2SWM1}7{L '|gS;ndӰvH@LPe?^ ٔ˷!;|J(5dɏ>IX˔a*#hYr}FIIKfk5+{Ia-wE¹\Ɖ$,J\AuJ5$/o+;ݝ7PjY~2Nڍї>֏I%fc-_9$)giS̓wbGWTV=D_5x6RP>s#{o! N3 .G*>VATGH>,N$iաOуʄ]vV='y! " d(2_"rk}Bi- xf (CjEs}xBnivGF&@`6^t<*T=JG&W*[#.Z VL]<IBt mB7w@ֱTҿNoNNЮ V?.Y&2wn.;"ݤ;yyUKc_ME"fB a4m6rRض,OvHN6Oa U<@hBTڟU?)L2h+nZ%~ !FcDXJ 2;zsYQ~4Ċ6oP{5qo{%å0;G+ yCyk鹞So!lnEgm_Oi@M2xdL]SRↄEB\}T0"?wQ X D8iMMJ$(ZHX%{n'*ߐF!}?E,EdEv|JxnJG~BL 6OM05 /`oŠz[#ZMS#!ԼQ[բI*<1ca:8V#j*?xGbL2rB>љ7E6Dj.Ch.}iEZHDMKf'.0}J@y©b thY'lԟd=]V-I\ ne'7*މYy#y!&8;u 38K.dpTCwVu֎Z)0o{'~ۜ&,ʏyuA/CdkևTQZVH3 "ne Lrxt>oq!P@[m]`6q;MIxW,@긜ag 'øj/l᚝c!gFϏBݶɆ)&Ehf}%ǓEhzEk lg%U>Z*)4CҥXY&{AwƧAl Jr'_e*6Y%Zns̼7sea+Uc})S>93a]aÊbe^Y'' ⵌ@kihcI7^t1@;d,QbkT9e4qt)g- #uU;Lsk4U1ԙ`Tt%&ՀJlk aɞPl'LХo r #fC+Rnjǂ)J U F ?ԩQr?,ܻo ^G?Nay4F:WO;x,,nD.X%oމjn`:qwD½O7,uJ#MV^wKeebV=CŃMsF?#~9+20PopQK _FݔBȖw&r[y H^k_Z뇘fID&BA?ͪ>]4gxKmHqQaeo|k;Q<Ϛ}I:M:@l(s8걯m<.i(q6`aC6X64G̈́+|/h1-9֤a//۞%&f"5>l0/mUV%J^V ڮ=xbmkMlzTីC. w>lTͮA\$Ik\ڪ{dh}2:F VpqCS{S؍E42;X$*\)Vw: pF]wGSy"Aŝ=! Q6;5!ԝ-fJ#&|%\BNg_gB~Bj _!H.RȚ]cR_]αE@<b\ NT#jIp7SO{t"ં{Nw`뤷5H%/-OZE@YEFsg^0[Nf?}IwL//#l]z]N2\l'f~n?U肾!}3}yZ8BS0 i0@w5%[] SLY oŐi-;"KO7eѿ#(0yg U2OِQ=n{f؞S3, Bv!gyGoV6'8oIގ1iԟ/q4$)RZQN$B]/7l֧ ivLE ]M?F 2I!PL7vMLh ;8c#%g޺ٴ626G*ȤO*tey}C6¸&q]2AU劀oBdt* eo-تc}u_]S a.{'] \Xs z#!hL"U9Fq#sݢAhzݷ >LEZր ްxPf0W~+Usy mYdn*BS6puWS %RWslC@:?&8 (m@;pfl lⓇJZw9*ch[g[FF kH1L"\%>?;%&6]2.zBd0qV`˙CFJ#%-)+-#.oE:$jHB[߮VqcxfGbX'x{-0S "ƒ#EݐB!M3Jr4e ؒ8:($)C2]D%[$%?QZ2 )|,zP ƒb+=#U$ۤ )/u>}+$]o]@I$xHhA, ?i܇QEm(YvoaTzB[dx&uZyF`(>A\qvp獑7NJ(u|;$ wHdCrizf3s+Wy m.npe $19zWс(٢A>*:s V.UX$.g7ŇkcYP͗ WkOZ4!FK#{R!(JGc0`rX^^}z4p,,Cl!=_WŘg/ǍrZoHԣeǰ&j:;oCE՟$;bYbQa8;ƨÊ鞖`9rtbtvf.eX`֗liV j}vUWcMj[p[{Hu$g-FWAn%`ؐa*?@¡, ea-I5ua"Nkqh^ ERhҡ9+<*8Ŕ"q %7O>gW T@Y__m';(g:ЎizfQ~[qAL9CM݂aa 8qywvX" YRKS&HM " @vCo_RQ4 Řh)v<fl" 5!*s~PXژ>ǥ*B-HL\1vKH^$~xQGzgBr^u6=.+=t"xHAPnE%+. ƽMb*#Ѐa$;{P#h'I^(8V F:)mܭ1(5>)Tm{o^)jLj60mi}ŽG܆v6:Ȱ~f3%OFvGeuޡ7 Ee4n`0f\({%d=[LZ7dH~IJ&yE>͕?3 UWGq厷>%={ߐ~OAJ,F`Ip F^3I*oCĦ0 Ҡ]‚OˍՃ8;ΙvR6aC;c=I CEjh~2vomcRT% me 9o; DpmMU-c3>J΃MPƍWD2z0wxb6xGұ˚)K\x{I?OpܹD3H4KGwilB W'@Ee_v Nʨd{ Mx?\os~X)sߗ_HZS~G R}?.ٔlyzݫM|+bJ*膾BtI2>X~ c=̥3 e3CQvs"3LRʨ )@S"c3ZdMv4)(bAJ;3vb0Qg <\ybĥۏuFhKty>UgIko7qT}V ХO=Y  is0ZkF,c*ӠÌxJe#;X=ݶZQS="cYFϕǩQ] OOJZ =w3HYpV8c}ʶ~-S]6xt7rp nD*fPW0)&.rM'0EX Q袸&qT̴B.Z "K =0ONEUw 6! :Ɠm!:" F*) @0 Zd=z7rʜŴBPɒSvh6d{`/l%^24C }}Ygg Ϗac#4φYuU[Ο+^SstU uY3ul`cl$ w} l+\M2w1 ֔!&k`_B_) Mw YEhVy*ˠ >+քxa?ogrP{^ԃd+e{~ۼ稤MƷSZjLS_YeÅӂ}D2$VbZ CM4fK}է?2BS$y{)?S) sChC=/S?X`9 9y%R+![MuP9Bqev oG: 0'- (Sf鳨pe蘅%Z 7!7=b;&嵊Gvp3/ޘ]:\Q3k҈Dn6ś@LFwKgvg6/Gm "722֯=NN@QV hPF3@ ikUɸ\ sDH\ K5E7Xi@Rޡ#_HjS-@܎*ljn$]d||x?J@V]֭9 iJ˴iY"+'|aGbp>:IQn8<1 b$)bd1OWvncz{؏W<]`.H V ]p6* U =*i`q73sL5 =43S/lR)\AΊG|1<7ڃ8C7x5ߟrnTطuRXqQ p\NCE7\D1MƆ jY_>89%tbjl[s;<Ռ (T11BNzzagҧ09=kQa.SxAn@JPN!+b مDiЏ}9#7^;6dx{~<Ž4|))Fxo߳:R,Z.-֋\%E KΡnI!:tϭt {W9_E/lup_k" ˺Yskp8e5htnmaPNt?47S<3Vyf!<rI$ՖAqK":_f 3u^2,5%b sO]gdw>.BBن[ȓq<)1/z_L"Ga%ĤSkopP gW~XU~0M Cx)8d\WڤJSVS /!pe,{ZH:L4tf. : {m,-Y~S2RbE\ܿBwBSW@)gkW@^!|ΰȝԝʗpcY#PT`l-~b 6%{9 y]1_\l SY}}(J>PsfGsdhC##߶XBl홙 X~TxHAz֘(Dյѡd9VJ~<2EtQ3C.*/RUOt~QC|3"٢j3kzXdt_61:Ȍ^W2GwE!%(wjO%%NtXwh'|DSyXZ *ļEmp 2htNު[䭏$Co:BF"Gu wƧ۩/nO8N/5c{!5Y$hDQ>/kˣ[JK^ 6Sib"UGQSgE{q ӨW̥=c G vq)Yfmų"E(/$Q]* cPvdnD9+"BpROq-T$qIMA!Js?vSXos*Xi=1:sm3+v#,9wLg]43oO 9l@t~)ޤ̝[Y!roI_\õ D0Fa~Oַ4XTؙ4GvZsy/TĔqZw_wAs1w}hngY Yέ b&t˧]Q@ cnNHjAXإT~X71cN<žsIR>[qՄw؝>){@N@ ;?^.%UNCE/٢{v$QtƺUi+`^,yyNӃ_c. ,kJC}&-+(XFg9t7e*oFX&-?,^,_ "H}{NmH/xzP.$sy߉+E7-9Q4yR01/+X^w佷H߂ .oTNhI 5)kOLPsἡc jxy"iKb]Vc@-q)8| ,^IlIGhO*Bj= +W̱+]3)ObK`<@w%'D *_D7_a0iuPs19@"!>s'Umn^ZeA !(ae`r ђɈv ÝI M:mA6+o槔Ȯ充$uy326-'խ5[X#ԸaB5̈vh%_{).׆: PsaAރiE5T({$wĬM2B 11bk?WdAߦFE|2Z/BiGg:#iKN @*)鹁M[*qqNxqaؽoQuw(ܽt9@7kaj6Wf/1J!ҍcSED`N\k+.Ι"ˆK5w&)~|'wgy?AjφMс5u|Z_sЕO!%?h+죮˥ɫ;_52ا- W }4CXFԷxJT޵˻LډW!>ط\^6dY0٘ PR뺐&FWm.n&ToH/K]!#l% 1p4* ?[0=-#fjF>u$ ~x9&hQݏv)4kf=K`;$=tuamI>R9*c'<ɫ"Ypq>9LV&}cy5rыng"YR'ߞ]:(JaX6u6uideF+T; F(}(i^6Dg}U"/l7A${uP0"l9K@Yk|@$e#Zl,~&"&݆N ޡ];!Z:ԏT(QMQ͈HM#WnT w1OH50^b[F$2/{BV>]vĉu-Ycٹ=mf7IR[ QfxPP_U@`Z7QA^fY>YM+KÈcKuxuMz͒F!m|SuE͉HQ% 4Y* ~PQ+ˣ_T^4HSw3< ` ;Ű0OVu(GFIB'PC@䄆 M ,g~{`Z9CUz^:Ǡ"T ?tn(iUh} G$Ld܇+;YblͲ_pOtR%i%%xg[ +N·MI`uK5xhJHA^E6-ɋOq%-u~;!j#i6BA,NC̈́ ?%$ ޞ0QV}(i}tAoӓqP17+pvY7GMc{~Bhg}AVty[B92Q{Ec3W!~(f-)jӡ9%HmGyn_ϋmAGI.( @=+ LΞw~M{gMe8)^%(J5؊E8W74н~a!c:0?~Yȡr*wd2y/y;8twrB Go[3ڙcR\P m!I ,5 }r Q; "©Y7 L-\ݤLŨ,+ݚd٪F \1=9\'HTb)nW5MuSaSv,%J9,p U'L5kŰokv.OVU% }ONx!%6-_$\o0 y@*8Nm]ZZ!-'(ZQȟjpxlҾWe@*ULM  H8lKahӂa6S0}n$[W svFͯύLcbgw+k A7\6(^wA5I(%PHxcv oY=rnPx˦j*=оPni 8j~bK{TZ%%>FtMq f *:b\pCW.l<лYL/ ^\imAGb}}Kla (aDKr)HK 6%kGZ{Dd՝$B-1M,b51D`{ e2f̱8Vѹ`xH(%F$U.[UF_"UJMYA˶C Fj0Lw7@YK]A*ԳPs{A}.KVg 2 #0} ngî @͢RK?pZYG[Ѓe;#] hPƷ2]Q.%\쁰(JF,8ę\֌i<BO"JwPצwY^ !* -6o35ҷ47#fkf!ܼXrgy'QsG|mH3ucD, ~هk^FvLI5Xi\'VK8\_=.7',rW:wξ ExamY:_N2ڌ+c޼VؔlJP MnQl[0t7&9Uf)nJ2^\*:%TgI!x~~BmIX/js،{bv-f [&ЊXWvMm7ԍ Et<S= 0n\HZIWP·oL Ӗ4Qdw+@DσjFD@ĈF/un4nw3>\BT,vCvH_+ڋwy-4IPTP_xOs%m~B$2N,Qۼ&|N3TzVE8V4iU x:A,w R"ݝ8ż6 R97z}|]H,0ԣ&w? ?\PrK bP…%4TgȒ'2,`³@눐O<W{ \iTf$F+ icޠmrJZb@{͢HܯZa4Mk\h$OhX,u(ǍM#44 JY߶ EbBZ#&'owi:-m6ǺZ KdM\؉"OQ|R)%~*S[&6||Z%i $1pw8aǵQ[Q-_1#\Vo߰|*9IC=?1aޖ"9{NH싟.=cy\'p?om#6js,TӹwW٩n w:&c| ͣ~2HǢt5Mx4,yh p߰µiJ NBb40,m|LX/O -.s4`~ag蚲qp_7;d1%i% >I#>nWwcjÁX%)o[,yω.TE5iBpG>xPt>2OL ^P֖< ^eVftvۢ-J{Cݞ+ (F'ijXJ*)7IY~2zF2*)zedY*?D cOE? Q_͖Et< nC71}qPQqOx҉VSSmw~wiy:wh,NO-qrj5I)3A6 K2 Zr+y[('ɇ49R,m$ZNjE/W7l[ϪRa زzUx|K1)32FUɃ\vluڱa#`(m4]423d$ѕdBG>˯C|}3Q䐄}8MZc$تreǤuZRS"Y^]n]BQOOkmzDiBlQO!6~8$Js DnOnugOʚ\4# 3hýGigӔ;NVG`䃜h6LJAAlcVjDe^/txIPLz4"m7hARZSx[p|i޵d̕ )G{dƳ 7q}hVHg=ϟBMIM` E/gl`ys# o im8>eV~xwwU5?AAFakT%@JM{o/$z+3'3):)R3"yMPg-r!HT@8aqfdE&[9'Cclf%4AʶƆ6`vޜzB)cF--= 3b]𴴱,~UD?n׼K7Ŋ;j|FA_S6D&[Y0WFpFJAJ n Z;N}QSә z8D34٭Seå0 rOƑ.e$_]q/SB2ٕj| ]=㴷j?ꀺ,D&tT "l{189kDtIds>~Um./ GV\hsIͻu7;g .hQᖕ| %BE#5t:nHYn=ZWl:C^ 6]F55 s&SZIPS `P<]EJ6 5|m?RWI m) `YIM"n[R= A=Jid$wDQO(Z` 38|7+wGVBBGq_?ȴZ뺎N>X~# 4\|@M+G=<ߴ_uS6;:B(h 8bD',؄ɔ%b gsOY->Qa\k})u_-2u>X@Eݑsme6,a k|tQgaNBm]HCG*OUY\حȣ X82BV{LD0f9#)}qJ_fOkV gsQm h '&:pPp/s)'m1$;~2%x_i`I d5؎|] %P5p TCՐn Q@ z, u鿲 M稜M' (\a!Mp 3ٱ? =.gY{P_h>Z* UM0b@zWA}˞Bs"EH^Up+_;k'h Af_ \\,K Oj%\DSN9ŨLUWˌaSnQpiI~V3ءnB68D9;u ^j Ngj3y,}^8s;Tqssf[rnx}%X=á$&NRowzfCXŜ +rŷ 3B*!"nݭC6)Ƅ KhN( *_s&~`'Rs&?MD| G*ACGd7~+Aq&>L4hg܎GkUT |2x}QeT~d9, E5ӇG1d(uP*&t4)CeĴu}U40Iq:Ld3}bʫnW0}21f`'4 50Se[\=CUFix_k 6@ :#86D.3t-?]L!;4+19-W>س䂍LSz}&X굪`DI7 XI\ϙT1*;;ǠQ<YSd~$lμ66e7XLtFr]U hGCq^8M~>u﹖ )7QԴɠmHסٕz LVs.3պgZ4 ñQb(t&Z=8䲖4{wb-gAD8h+xCC>\LfV=6zbxkU?;cޱXdmIe͐^pSA-#N^౳V eE~w&zsWwI>wG%Q~X †ІWrqrynmX0S͟s/ig4hAS>$B?2oLSxdpL'|p=|+8itQcDx*pp@yNpbg2P,nd7X\ϵ pWdb}e_Nuʙ7/vFY<xvPA% B>lt3+&EAw*$[/毴"; 9#d=T~ڰ1 r>#8o8  bG zp{# >ޡoj)`_ jc6[8`*;HB2[FDC*P E-P\elu:q\V֟<v&&#\L{k/q7r"czt[3 ymFWVR9li=FS@`R/if"we(ŏĽQPVrjZI a'z\EW~D Wz1c/m wDu&# -2D[_XZfm5 紓:@Ԩ /z*J|0y53"[l,'U㶰<8+#޸{H-:V_xEK~e d*5 KSV<x.tu%c!P9)k=46uvGnl~7)9b nyl@rSpILAuH+*(ϵ Y[PA~`mX5z WjEA-|*). wG&Ťq^-RdyFE<0A1Ha|[,V * qVck yZq"IL1KPeɪUK0"8ԓ{1pvrXT3v:&ݵݢ$DftE)v"XzF.#[ys"C̫d5V^O>HH¦RqRFAGZŠNH6snxGxMjũYŘ8.5R@/ãtΤ0zy瘭Y.ҪXP%f\uSWH07XV㋢F}s6.&Ξ4 Q!2~^ɋ6K|{^ $p é$pIWܘΞjq6yrdv+mU)tb y`FSED荓:7d|`$`9m8Gq"PQ8p;9ŃHܝ&F#7C^.0 R ƢH4/@&׈N|bX%X$I1?] OUSsH u`p`wab#wm .;_VT.m I{!3A۩D4Vކ bLvaNGV؇_GSfw7|iDT62U2oH۬Ͳc27K>dOlpY.A7+,\=Ǧ>KQfͩi_LX>"Obuh48I O1צNV8Cf,Tߍ|2$!x׉d9Y@xXROi\/2r%%5KcGC:dzq BAy##kT<z{ّtG?E]$PRuW/5d;#1]*lP|qRTcYw_͉M#^˕!튦@\55#1bhd EqShW`6P^5B'IҢ١!bt[L{Ufq؎L^"c9VfX6+엣UrjvexOV0bpv&5MDCxXeO0I@&"hWgÌa1u%4n3MD*i؏Ē"zUx4/=oO*٨HutoJCpXqb}Ʌ ;* ԨWʽwF]$9f2l%2QߝqmkL ,G?h2Ken?TooNė8-? @%Y ȎC8qxxwRWrvSb/]إ2\ܤ 7 O<<^4خx@k^"dd/J"4AC鸄djrVyB"UbMXK#L)61e7ܳ(Fm`CW4&;VLe ^lfZNNc–;nY &< MTR fFٽ!ZG D(.NjZ l:;~}A0ʎ劣',O pLd?y H ,//5Lzyߊ*E0j3gҴ֭}+MVfOލh-A˜M(ڧ\ݙua #"+뎟ؓwx&c1p{hPӮzI# ^|8;1)?!tYN;UR5"wBI-NpMKrEQYYF+aW[IU2:%n98ʰەSPM|SH]!@g@[S!|h*~2K H p}zW$C/ղ2D&[z/im-A9m߃jAE_)r{F#ZBz3}T{_2n;͔N t- 2g%0j9T t )YX`7DW[*Buk6lblB3\fH@A2fU(qa fh A!PM)BU&ʂfSnP`ـ/_tUr@#G>샑lDrZ9)țEyIm.QTѪMs7} _ t mAqBxWYw&W>!i 9Jٕ I"i,GDM 頀ܩ B. YZ