libdnssec8-3.1.4-bp153.2.6.1 4>$  Apaຜ!M@eeeFtaK GZ{8\iWY}k=Fe ϧn*AcveZ_jLe{4PNZfz O$,]`XT?8έi\sY@튻"5.BRUa{u3A AO+7h)w`F8 C ]>zK|k֖f@~!?+khK}$A&AI M:KMsRi=qk}d97a2fcb6ca5cb9d4f236576e350b6a5243c6cb05569949bec401b2059ff1f67a2ff0dbb9b1e5505d4c3c044c994b5b7f390f64b.aຜ!M@eeeBX&ʆc'UjɈ/7*ra`RE=G F`G ϪĽUju}K)kk1Ojz }ڲgB"L"d()s*1*t mp`ʐY]HGb7 '')4?%GU{&A;u5ƚ bz5 t-2,6I Apfk*=O..ύNvl' o׫v刭V“ZkjB}3O;pQ\>p@h@?h0d   EPT`d}     B X`jt(a(889x8: 8>d@dFdGdHeIe XeYe\eD]eL^enbezcf dfeffflfufvfwgxgygzggggh,Clibdnssec83.1.4bp153.2.6.1DNSSEC support functions for Knot DNSKnot DNS is a DNS server. It implements only the authoritative domain name service. It uses a multi-threaded and mostly lock-free implementation and can operate non-stop during zone addition or removal. This package contains a library for DNSSEC support functions.ays390zp2aSUSE Linux Enterprise 15openSUSEGPL-3.0-or-laterhttp://bugs.opensuse.orgSystem/Librarieshttps://www.knot-dns.cz/linuxs390xawaw028577de4e58c86c010241c84f98714b32c2b928baa68c90b9ed45609a5126aflibdnssec.so.8.0.0rootrootrootrootknot-3.1.4-bp153.2.6.1.src.rpmlibdnssec.so.8()(64bit)libdnssec8libdnssec8(s390-64)@@@@@@@@@@@@@@@    /sbin/ldconfig/sbin/ldconfiglibc.so.6()(64bit)libc.so.6(GLIBC_2.10)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2)(64bit)libc.so.6(GLIBC_2.25)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.8)(64bit)libgnutls.so.30()(64bit)libgnutls.so.30(GNUTLS_3_4)(64bit)libgnutls.so.30(GNUTLS_3_6_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.2)(64bit)libpthread.so.0(GLIBC_2.3.2)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)3.0.4-14.6.0-14.0-15.2-14.14.3a@an@aD@a @a @`ݮ@`f@`@`q`_@`\{@`@`_@____^@@^@@^@@^@]\HW@\3?@\*[@[@[ݍ[IZ@Z@ZWQYYYXWDB@W1@VwV@V@V@V@VTQ@VCU6@U6@U@U&iU&iTTq@T@T@Tk4Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky Jan Engelhardt Michal Hrusecky Jan Engelhardt Michal Hrusecky Michal Hrusecky pgajdos@suse.comMichal Hrusecky Marcus Rueckert Marcus Rueckert Michal Hrusecky Michal Hrusecky Michal Hrusecky Michal Hrusecky pgajdos@suse.comMarcus Rueckert Marcus Rueckert Petr Gajdos Marcus Rueckert Marcus Rueckert Marcus Rueckert mrueckert@suse.dekbabioch@suse.commrueckert@suse.dei@marguerite.sumrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.demrueckert@suse.detchvatal@suse.comondrej@sury.orgondrej@sury.orgpgajdos@suse.com- update to version 3.1.4, see: https://www.knot-dns.cz/2021-11-04-version-314.html- update to version 3.1.3, see: https://www.knot-dns.cz/2021-10-18-version-313.html- migrate to user creation via sysuser-tools - run spec-cleaner on spec file - update to version 3.1.2, see: https://www.knot-dns.cz/2021-09-08-version-312.html- update to version 3.1.1, see: https://www.knot-dns.cz/2021-08-10-version-311.html- update to version 3.1.0, see: https://www.knot-dns.cz/2021-08-02-version-310.html- update to version 3.0.7, see: https://www.knot-dns.cz/2021-06-16-version-307.html- make sure we have getent and groupadd/useradd in pre * added dependency on shadow and glibc * might be related to bnc#1186023- update to version 3.0.6, see: https://www.knot-dns.cz/2021-05-12-version-306.html- Make /etc/knot directory owned by knot - fix reload action- Update descriptions, remove unsubstantiated claims.- update to version 3.0.5, see: https://www.knot-dns.cz/2021-03-25-version-305.html - Update description based on homepage- Trim marketing wording from description. - Drop old rpm constructs.- version update to 3.0.4, see: https://www.knot-dns.cz/2021-01-20-version-304.html- add incompatibility warning about 1.6.X version when updateing - rename back to knot- version update to 3.0.3- version update to 2.9.7, see: https://www.knot-dns.cz/2020-08-31-version-296.html https://www.knot-dns.cz/2020-10-09-version-297.html - obsolete only pre-2.0 version- remove rosedb conditional as lmdb is required in general now- replace conflicts with Provides/Obsoletes- fix dependency: python-Sphinx -> python3-Sphinx- use upstream example config file with correct syntax- version update to 2.9.5 - Bugfixes - Old ZSK can be withdrawn too early during a ZSK rollover if maximum zone TTL is computed automatically - Server responds SERVFAIL to ANY queries on empty non-terminal nodes - Improvements - Also module onlinesign returns minimized responses to ANY queries - Linking against libcap-ng can be disabled via a configure option- version update to 2.9.4 see NEWS- version update to 2.9.2 see NEWS- update to 2.7.6 - Improvements - Zone status also shows when the zone load is scheduled - Server workers status also shows background workers utilization - Default control timeout for knotc was increased to 10 seconds - Pkg-config files contain auxiliary variable with library filename - Bugfixes - Configuration commit or server reload can drop some pending zone events - Nonempty zone journal is created even though it's disabled [#635] - Zone is completely re-signed during empty dynamic update processing - Server can crash when storing a big zone difference to the journal - Failed to link on FreeBSD 12 with Clang- update to 2.7.5 - Features: - Keymgr supports NSEC3 salt handling - Improvements: - Zone history in journal is dropped apon AXFR-like zone update - Libdnssec is no longer linked against libm #628 - Libdnssec is explicitly linked against libpthread if PKCS #11 enabled #629 - Better support for libknot packaging in Python - Manually generated KSK is 'ready' by default - Kdig supports '+timeout' as an alias for '+time' - Kdig supports '+nocomments' option - Kdig no longer prints empty lines between retries - Kdig returns failure if operations not successfully resolved [#632] - Fixed repeating of the 'KSK submission, waiting for confirmation' log - Various improvements in documentation, Dockerfile, and tests - Bugfixes: - Knotc fails to unset huge configuration section - Kjournalprint sometimes fails to display zone journal content - Improper timing of ZSK removal during ZSK rollover - Missing UTC time zone indication in the 'iso' keymgr list output - A race condition in the online signing module- update to 2.7.4 Features: - -------- - Added SNI configuration for TLS in kdig (Thanks to Alexander Schultz) Improvements: - ------------ - Added warning log when DNSSEC events not successfully scheduled - New semantic check on timer values in keymgr - DS query no longer asks other addresses if got a negative answer - Reintroduced 'rollover' configuration option for CDS/CDNSKEY publication - Extended logging for zone loading - Various documentation improvements Bugfixes: - -------- - Failed to import module configuration #613 - Improper Cflags value in libknot.pc if built with embedded LMDB #615 - IXFR doesn't fall back to AXFR if malformed reply - DNSSEC events not correctly scheduled for empty zone updates - During algorithm rollover old keys get removed before DS TTL expires #617 - Maximum zone's RRSIG TTL not considered during algorithm rollover #620- seems we no longer need jansson- limit geoip support to opensuse- update to 2.7.3 - Features: - New queryacl module for query access control - Configurable answer rrset rotation #612 - Configurable NSEC bitmap in online signing - Improvements: - Better error logging for KASP DB operations #601 - Some documentation improvements - Bugfixes: - Keymgr "list" output doesn't show key size for ECDSA algorithms #602 - Failed to link statically with embedded LMDB - Configuration commit causes zone reload for all zones - The statistics module overlooks TSIG record in a request - Improper processing of an AXFR-style-IXFR response consisting of one-record messages - Race condition in online signing during key rollover #600 - Server can crash if geoip module is enabled in the geo mode - changes from 2.7.2 - Improvements: - Keymgr list command displays also key size - Kjournalprint displays total occupied size in the debug mode - Server doesn't stop if failed to load a shared module from the module directory - Libraries libcap-ng, pthread, and dl are linked selectively if needed - Bugfixes: - Sometimes incorrect result from dnssec_nsec_bitmap_contains (libdnssec) - Server can crash when loading zone file difference and zone-in-journal is set - Incorrect treatment of specific queries in the module RRL - Failed to link module Cookies as a shared library - changes from 2.7.1 - Improvements: - Added zone wire size information to zone loading log message - Added debug log message for each unsuccessful remote address operation - Various improvements for packaging - Bugfixes: - Incompatible handling of RRSIG TTL value when creating a DNS message - Incorrect RRSIG TTL value in zone differences and knotc zone operation outputs - Default configure prefix is ignored - changes from 2.7.0 - Features: - New DNS Cookies module and related '+cookie' kdig option - New module for response tailoring according to client's subnet or geographic location - General EDNS Client Subnet support in the server - OSS-Fuzz integration (Thanks to Jonathan Foote) - New '+ednsopt' kdig option (Thanks to Jan Včelák) - Online Signing support for automatic key rollover - Non-normal file (e.g. pipe) loading support in zscanner #542 - Automatic SOA serial incrementation if non-empty zone difference - New zone file load option for ignoring zone file's SOA serial - New build-time option for alternative malloc specification - Structured logging for DNSSEC key submission event - Empty QNAME support in kdig - Improvements: - Various library and server optimizations - Reduced memory consumption of outgoing IXFR processing - Linux capabilities use overhaul #546 (Thanks to Robert Edmonds) - Online Signing properly signs delegations and CNAME records - CDS/CDNSKEY rrset is signed with KSK instead of ZSK - DNSSEC-related records are ignored when loading zone difference with signing enabled - Minimum allowed RSA key length was increased to 1024 - Bugfixes: - Possible uninitialized address buffer use in zscanner - Possible index overflow during multiline record parsing in zscanner - kdig +tls sometimes consumes 100 % CPU #561 - Single-Type Signing doesn't work with single ZSK key #566 - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - Compatibility: - Removed obsolete RRL configuration - Removed obsolete module names 'mod-online-sign' and 'mod-synth-record' - Removed obsolete 'ixfr-from-differences' configuration option - Removed old journal migration - Removed module rosedb - changes from 2.6.9 - Improvements: - Added zone wire size to zone loading log message - Added debug log message for each unsuccessful remote address operation - Bugfixes: - Zone not flushed after re-signing during zone load #594 - Server crashes when committing empty zone transaction - Incoming IXFR with on-slave signing sometimes leads to memory corruption #595 - packaging changes: - enabled geoip module: new BR: pkgconfig(libmaxminddb) - enabled cookies module - enabled queryacl module- update to 2.6.8 - Features: - New 'import-pkcs11' command in keymgr - Improvements: - Unixtime serial policy mimics Bind – increment if lower #593 - Bugfixes: - Creeping memory consuption upon server reload #584 - Kdig incorrectly detects QNAME if 'notify' is a prefix - Server crashes when zone sign fails #587 - CSK->KZSK rollover retires CSK early #588 - Server crashes when zone expires during outgoing multi-message transfer - Kjournalprint doesn't convert zone name argument to lower-case - Cannot switch to a previously used ksk-shared dnssec policy [#589] - update to 2.6.7 - Features: - Added 'dateserial' (YYYYMMDDnn) serial policy configuration (Thanks to Wolfgang Jung) - Improvements: - Trailing data indication from the packet parser (libknot) - Better configuration check for a problematical option combination - Bugfixes: - Incomplete configuration option item name check - Possible buffer overflow in 'knot_dname_to_str' (libknot) - Module dnsproxy doesn't preserve letter case of QNAME - Module dnsproxy duplicates OPT and TSIG in the non-fallback mode- Update to 2.6.6 - Features: - New EDNS option counters in the statistics module - New '+orphan' filter for the 'zone-purge' operation - Improvements: - Reduced memory consuption of disabled statistics metrics - Some spelling fixes (Thanks to Daniel Kahn Gillmor) - Server no longer fails to start if MODULE_DIR doesn't exist - Configuration include doesn't fail if empty wildcard match - Added a configuration check for a problematical option combination - Bugfixes: - NSEC3 chain not re-created when SOA minimum TTL changed - Failed to start server if no template is configured - Possibly incorrect SOA serial upon changed zone reload with DNSSEC signing - Inaccurate outgoing zone transfer size in the log message - Invalid dname compression if empty question section - Missing EDNS in EMALF responses- update to 2.6.5 - Features: - New 'zone-notify' command in knotc - Kdig uses '@server' as a hostname for TLS authenticaion if '+tls-ca' is set - Improvements: - Better heap memory trimming for zone operations - Added proper polling for TLS operations in kdig - Configuration export uses stdout as a default output - Simplified detection of atomic operations - Added '--disable-modules' configure option - Small documentation updates - Bugfixes: - Zone retransfer doesn't work well if more masters configured - Kdig can leak or double free memory in corner cases - Inconsistent error outputs from dynamic configuration operations- update to 2.6.4 see /usr/share/doc/packages/knot2/NEWS- fix tmpfiles scriptlet- package /var/lib/knot - run tmpfiles scriptlet during install- update to 2.5.3 see /usr/share/doc/packages/knot2/NEWS - use libidn2 on TW and 42.3 - following modules stay static: - dnsproxy - onlinesign - moved modules to shared building: - dnstap - noudp - rosedb - rrl - stats - synthrecord - whoami- update to 2.4.1 see /usr/share/doc/packages/knot2/NEWS- update to 2.2.1 - Bugfixes: - Fix separate logging of server and zone events - Fix concurrent zone file flushing with many zones - Fix possible server crash with empty hostname on OpenWRT - Fix control timeout parsing in knotc - Fix "Environment maxreaders limit reached" error in knotc - Don't apply journal changes on modified zone file - Remove broken LTO option from configure script - Enable multiple zone names completion in interactive knotc - Set the TC flag in a response if a glue doesn't fit the response - Disallow server reload when there is an active configuration transaction - Improvements: - Distinguish unavailable zones from zones with zero serial in log messages - Log warning and error messages to standard error output in all utilities - Document tested PKCS #11 devices - Extended Python configuration interface- update to 2.2.0 - Bugfixes: - Fix build dependencies on FreeBSD - Fix query/response message type setting in dnstap module - Fix remote address retrieval from dnstap capture in kdig - Fix global modules execution for queries hitting existing zones - Fix execution of semantic checks after an IXFR transfer - Fix PKCS#11 support detection at build time - Fix kdig failure when the first AXFR message contains just the SOA record - Exclude non-authoritative types from NSEC/NSEC3 bitmap at a delegation - Mark PKCS#11 generated keys as sensitive (required by Luna SA) - Fix error when removing the only zone from the server - Don't abort knotc transaction when some check fails - Features: - URI and CAA resource record types support - RRL client address based white list - knotc interactive mode - Improvements: - Consistent IXFR error messages - Various fixes for better compatibility with PKCS#11 devices - Various keymgr user interface improvements - Better zone event scheduler performance with many zones - New server control interface - kdig uses local resolver if resolv.conf is empty - new BR libedit-devel for the interactive mode- update to 2.1.1 - Bugfixes: - DNSSEC: Allow import of duplicate private key into the KASP - DNSSEC: Avoid duplicate NSEC for Wildcard No Data answer - Fix server crash when an incomming transfer is in progress and reload is issued - Fix socket polling when configured with many interfaces and threads - Fix compilation against Nettle 3.2 - Improvements: - Select correct source address for UDP messages recieved on ANY address - Extend documentation of knotc commands - drop knot-2.1.0_pkcs11_check.patch- enable libcap-ng- fix configure check for pkcs11 support: adds knot-2.1.0_pkcs11_check.patch- fix soversions- update to 2.1.0 - Features: - Per-thread UDP socket binding using SO_REUSEPORT on Linux - Support for dynamic configuration database - DNSSEC: Support for cryptographic tokens via PKCS #11 interface - DNSSEC: Experimental support for online signing - Improvements: - Support for zone file name patterns - Configurable location of zone timer database - Non-blocking network operations and better timeout handling - Caching of Critical configuration values for better performance - Logging of ACL failures - RRL: Add rate-limit-slip zero support to drop all responses - RRL: Document behavior for different rate-limit-slip options - kdig: Warning instead of error on TSIG validation failure - Cleanup of support libraries interfaces (libknot, libzscanner, libdnssec) - Remove possibly insecure server control over a network socket - Remove implementation limit for the number of network interfaces - Bugfixes: - synth-record module: Fix application of default configuration options - TSIG: Allow compressed TSIG name when forwarding DDNS updates - Schedule zone bootstrap after slave zone fails to load from disk - avoid activating the intree copy of lmdb- update to 2.0.2 - Out-of-bound read in packet parser for malformed NAPTR records (LibFuzzer)- split out shared libraries, knot-resolver uses some of them and atm we are forced to install the whole knot2 package.- lmdb seems no longer optional- create a new branch for knot 2.x starting with 2.0.1 - Bugfixes: - Do not reload expired zones on 'knotc reload' and server startup - Fix rare race-condition in event scheduling causing delayed event execution - Fix skipping of non-authoritative nodes in NSEC proofs - Fix TC flag setting in RRL slipped answers - Disable domain name compression for root label - Log via journald only when running under systemd - Fix CNAME following when quering for NSEC RR type - Fix refreshing of DNSSEC signatures for zone keys - Fix binding an unavailable IPv6 address on Linux (IP_FREEBIND) - Fix infinite loop in knotc zonestatus and memstats - Fix memory leak in configuration on server shutdown - Fix broken dnsproxy module - Fix DNSSEC KASP timestamps parsing in strict POSIX environment - fix multi value parsing on big-endian - Adapt to Nettle 3 API break causing base64 decoding failures on big-endian - Features: - Add 'keymgr zone key ds' to show key's DS record - Add 'keymgr tsig generate' to generate TSIG keys - Add query module scoping to process either all queries or zone queries only - Add support for file name globbing in config file includes - Add 'request-edns-option' config option to add custom EDNS0 option into server initiated queries - Improvements: - Send minimal responses (remove NS from Authority section for NOERROR) - Update persistent timers only on shutdown for better performance - Allow change of RR TTL over DDNS - Documentation fixes, updates, and improvements in formatting - Install yparser and zscanner header files - Improve lookup of libsystemd build dependencies - Fix compilation warnings in endian conversion functions on OpenBSD - changes in knot 2.0.0 - Bugfixes: - Fix lost NOTIFY message if received during zone transfer - Disable fast zone parser when compiled in Clang (workaround for Clang bug) - kdig: Record correct dnstap SocketProtocol when retrying over TCP - kdig: Hide TSIG section with +noall - Do not set AA flag for AXFR/IXFR queries - Features: - DNSSEC: separate library, switch to GnuTLS, new utilities - DNSSEC: basic KASP support (generate initial keys, ZSK rollover) - Configuration: New text format in YAML, binary store in LMDB - Zone parser: Split long TXT/SPF strings into multiple strings - kdig: Add generic dump style option (+generic) - Try all master servers in multi-master environment - Improved remotes and ACLs (multiple addresses, multiple keys) - Basic support for zone file patterns (%s to substitute zone name) - Disable zone file synchronization by setting 'zonefile_sync' to '-1' - knsupdate: Add input prompt in interactive mode and 'quit' command - knsupdate: Allow TSIG algorithm specification in interactive prompt - Improvements: - Zone dump: Do not write class for SOA record (unified with other RR types) - Zone dump: Do not write master server address into the zone file - Documentation: Manual pages are included in HTML and PDF - drop patches which are included upstream: 0001-loosen-openssl-dependency.patch 0002-make-configure.ac-compatible-with-old-tools.patch - also drop all buildrequires just needed for autoreconf - new buildrequires: pkgconfig(gnutls) >= 3 pkgconfig(nettle) pkgconfig(jansson) - create devel subpackage - enable rosedb and bash completion- local state dir should be just /var- enable dnstap support for factory and newer: - new BR: protobuf-c and libfstrm-devel - prepared lto support but not enabled yet, still need to find out which distros support it- update to 1.6.3 - Performance drop for NSEC-signed zones - Proper handling of TCP short-writes - Out-of-bound read in zone parser for long domain names in origin (AFL fuzzer) - Out-of-bound read in packet parser for TSIG RR without RDATA (AFL fuzzer) - Out-of-bound read in packet parser for malformed NAPTR RR (AFL fuzzer) - CDS and CDNSKEY support in zone parser - Add defaults for TCP config options into documentation - Detailed error message if zone reload fails - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch- update to 1.6.2 - Limiting number of parallel TCP clients (max-tcp-clients config option) - Ignore refresh and transfer events on non-slave zones - Compilation with Dnstap support on FreeBSD - Possible file descriptor leak when terminating inactive TCP clients - refreshed patches to apply cleanly again: 0002-make-configure.ac-compatible-with-old-tools.patch - moved autoreconf -fi to %build so it wont be tried in quilt setup or similar tools - move up the %if case for systemd in for the preun scriptlet to avoid warning about empty scripts on non systemd distributions. - used xz tarball: new buildrequires xz- Add deps on the docu packages to regen documentation - Enable systemd integration fully - Add dep on libidn - Cleanup with spec-cleaner- Only require lmdb-devel on (Open)SUSE 13.2 and higher- Updated to 1.6.1 Bugfixes: - Journal file would sometimes outgrow its set limit - Fixed incompatibility with OpenSSL 0.9.8 - Proper handling when machine hostname cannot be retreived Features: - Support for DNSSEC Single Type Signing Scheme - Compile with lmdb-devel to add support for persistent timers- Updated to 1.6.0 Bugfixes: - Fix zone expiration when AXFR/IXFR is being refused by master - Fix forced zone refresh on slave (knotc refresh -f) - Persistent timers database opening after privileges has been dropped - DNSSEC: RFC compliant processing of letter case in RDATA domain names - EDNS: Return minimal error response for queries with unsupported version - EDNS: Fix interpretation of Extended RCODE Improvements: - Maximal size of persistent timers database increased from 10 MB to 100 MB - Added logging of persistent timers database errors Features: - Persistent timers for slave zones (expire, refresh, and flush)/sbin/ldconfig/sbin/ldconfigs390zp2a 16363605693.1.4-bp153.2.6.13.1.4-bp153.2.6.1libdnssec.so.8libdnssec.so.8.0.0/usr/lib64/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protectionobs://build.opensuse.org/openSUSE:Maintenance:17150/openSUSE_Backports_SLE-15-SP3_Update/7e783354187725acff3c96b1522f4e9e-knot.openSUSE_Backports_SLE-15-SP3_Updatecpioxz5s390x-suse-linuxELF 64-bit MSB shared object, IBM S/390, version 1 (SYSV), dynamically linked, BuildID[sha1]=6e84459f8707c56695b3dc0ff8860d8c22d4e34e, not strippedPR R RR RR RRRRRRR RRZ]FZ8a $&utf-84839e832d497804b98c5d5f78cd661e9e26f58e230d9383abc40894d9baf0f7e?7zXZ !t/[n] cr$x#Ejq酕]RNZb8V<{&HwNHb, (U`.BnEc6~Vfs~Ԙ6=E@0b/y%uv{ }T0g>݂KM04iUk^é_ZOsbrO^@(oTBJW&qՅ-Ghx ,hQeldp$pC7WFV\h?;Ow)T-^nR-0 Mq ; kTeu/M!7[n?&qd(e/KNۓu vs p p!@T*V7%:D3υ-ϕ8,ϴ~,}LJ;CΡBz4a$3^LއRE^J'"QT\#kjp>f?fn $1˪@UnV)h-c 6 *Zt5DYQ-IxKlYu, _;M*,HKS;f=iy^] r 7"NXF] 1cZ9|~iE#Թw6;M)Ym~'ht6Z[xB[: WR~,g24/k&%Cǀn_PeRԼUHubBQ1]&[X_ )`"_c%ꫳwE]1y ݂e?Iڐ<;W{$ՊUkWmO%X6Rۺn6?__XjUe^ԘͼYTuaѼ4]N0tBrAoe)ge aM&? d8=xA]$d%mH"ur =Nd|qrA;>,i΃G-4LO-UA]ͣfƴ騑OG'TCUxɻT0Q(dJ 𠚦&h*_p1 U' kdCPj"8扛5=#eseǷ's| زV+Z!rBRI],+wk/h8N \Ft @6׵`thj[q8yi,ۊ\j_ZC1;{v{1}x 8 Q햂VrxM/YMI,y,9_.IyX(+s`!!£* wTj؇Z5^ʹr\srto%qqt&%\TVyKLl|P2s-'lA05TKWdH SDwQUZ5>N#x7 >+>Z[i`# Me5]{cE$MJ:tsBX94 J?߇eH;N5f5j3'sbm RiFnhNGA/ O4x=<\īX-zzBUi43R*+<ؖձ%` k j%)(Q%8G?[¥1Sc@YP,q:WdwQ6 ,@\ėm*J̍${Q]={ qyT>ˏn=҂;e e-z_ =2"$ &!e]2O]]BUcsyDl(U1$+\t7@%O-:dJ\%u;_8Ϣ~Fv !Exa]>ͧYɆ#3@D<ԑ S$ g'G&ތL`RS@uP;f"?u_uu&d_œB[~To öb )I6"U6&F75V5!9CV/` dXRއ#|k^4<2IA"#cŰz]"#C;,Z&QFQ"1ywu;RaQ5* FJrfΣ[Q_ <,#M Tn&f GOA3ros*!@EGXEa3:8zE&=I3$OR~:ǐ/MA4dpowtYRZt4RԵl0|]o*4Eqr9P;s]߄)iכj]3s׃op qX5nʾ꤈bCQ}\KC$o:lE# bk6S'ջ|c#*ںm{R}1Pq[2D4EC5BNB\M:X\lESPZ?a8*phl ]͜ށ7_&οf׫ZK \| `7 g>F#R[/zqMk-˟sA$.+qU߀jy{2u?]8?|v7N ,ܲ4zg]o%Ki |I:`^I%'B7`2|iH"X ,aQHG(Lh֮ Lɵ Q 5ldJr7߀|mwN_wa UFŪ؋'5MH-%Rf3 ŸQ$RtAmػHrHmhZw yWX+.5孟 5%aٺz5{AP$N0$p{`; P~@_PV%(u K(T{󋛷BȃbȤadfJa1p+C4ah(L=$wy snnr/ F.2Ǒ_p 6?lrg1w*r=2agC>8 u#Rǒ >^fZsFV A8:5%fHpX{KHOq<Wi6T4FdkI{NHfr !rb]tw idtOӠ/МĴ1qM*qԫULl.&I+0Im9UepG<[tSQ!ZՒYL1Yu@lLlH.c4iB% I^gkO )np5ֺ5GS_B@: fpInxAsN\ۗyDpйhM)(:*P*$hKFzO)Z"}K-j#߹mN7:Lb4%Fy:{->]$&a poSFfE3]SNA"A {mL'Oe*ldzc!a}}F[R^O'Wb,`)v΄xbZUK  hB~o~Yg=h5& QWwWfp י y{ׅ(VT i Lȓę0ݧcm^=َNRJ8iYr!ՆkV1ݕ` 2F86y6]CȢ7ʫfREoVoՄ͓诈dR(>A a!0aC1b͆33h~\,8g9n4)P N9?p&y_J^ୣ@+E~}+2V?$ D#o*rj Nyb $}Vy=>hYIa#k϶NXFl_AzcYzOH0[+y6GW&,QԀ7E,L)cwK[?E[ZcgX:e1BTjEʴ(& v\],o6䓨5hgb24I;nׅ֞5Mҙ\>mG^e\E'[cԀӌkJuO'aǘvԜR((jN]@?7ΥunN +#-[궎T/jgڂT.}@_d#D_[g9t,f'!!lVP]y9)%ʨ!DR:֎\y;ZvĐ! J&6Ic>GhLh&3 mr3Vt[m(AFdG2umC;tq2x _͓3`@kt̴Us)TЎL <ӱ n^F71|J".i@'pqNݝf;/@vbЗ0bU*`$[6۩NeE&N(%DB2 HWײ1.Naǧ:Ǜ#?u8JbZ'tϫ6 ^0O5jLO` xI:a g ?elϡ˔_ۙ7[ςjʺVGn İ#ZGvѽ&MzHp)8lbΚ@ %|ɒþ=zxQ~ Ŕfݿbͤp\bpѐ՘1m0)pj4\ $˃/f$X砕qJH$lo *_đ#m ږO2_ֳxKٌTSc%ACV -WtSQݾYi1:\DoEkiAJjx  MƮCw |>8P@e;χ|`X5#ͺ.]m%ś>vP7TcP CO\v_qw.*SK0 > n~3+%Td.=$#wI 浵Ǿ\JSorxރ唫m$ /-Il(Pݨ31rfIOrX̰Rd3uf %j_Mz)p@TI~?on-vNJ$Gj|rc]` Iv[p+=:*A͸G]lFU_\É3"G?[I&f.-YwAVYv5CBߙ,Gӳr-(i*Oq *mnv[Ƌ&yj)N{xѾrg˔]Ku Ji=[KKBUlz(&4[G*⵸j#mOT ΊU B ƛk ´>02L\/ha ܬdwe1:VOﯢ6-Z}m^@bl[() {'i vEIQſcx6#I\7f?n|Ȟ6P6<'\7}L]ͪn],-x啈u`w%k"^0V.Ve{V чH#9ӹ 2f0⯳f^L3 Į$£a[vs5=`D[taCBbtO;SH Uˆ }f2~=.8tl6WKBFy5f$m4gbտ.ix^=%| WE|$u9+w"=x3Y} by!טz92C?jW(9GNX6ukm˦xѯ &’GqT';Ns#W50550iugse^.s^&;WXo!_r WuߏRkWhRJz (@г/&oװ`03t'V_೘Kin\E'Xk5$/Sa1^WB *2B;aX[Mànnvy1(x *ydw cS,ҤAZf4r B.0(bs036T3ŭJ6Bv}ֳ I3nU4^2LKc0ȸUKNzuw~aǹb o-XtSrE]Ϋ]e[,P^*Sy"rkM0k[nx.S[o7E;֦Y@ȶz}MB3D\/ۃ6bẊIPP,B56,7٪LX|/ǔ Ct` i̶LBv4cG8:i[ҙ>oiH/{̜37pLA.Kf2xU{bIqo'Ƶ\q"8,;W{`/Ś`^-2̃l^SnG,/4AF\ avI*sELxƴ◂ wxK2FAˏ@=7gFξYd+"s3OJ PIJBaH{5n"&-;GDF_"MD&K @ KLK{]  ;ָ'-3h摱ƕ;a3%XsMPM)+tP: kU sVc#,tŏ'JDjnɰEH]k۞x`:v0o}qc0f!iv?;^QƁ54|x:g|BMWoIg2x?Dz+HP[Q4MyU)Z=Ӷ׊?_M{TqZBɐ(w$;E>#4XdVWƖq*{sb ۡƢj>L] hpɐ2%10p1&7 $"'b-?T%s6>55w{ L{9._cٰn=EAXj@s [. E K{)K\ G6%by*B0leL݂X[:t>j7kOSQHm)" ]줊-6OD<1.l3 䲏~GRW"9mɨWG7u=>?m.HIգ|jȐ>NgfZ ~U>bd nR& A5e2vߛ?%xZc(_Ct]X b:-Naf|#Y:?EkE-9r;GY獗X3\?nl[\;$ h Jɟi%\8Ptp䑩5[EzAEr&M1@aNW&ZRg9 %u#3sN'[?;@٪׼ )a*EYwy K9=PEalu]Ie&|=.,L~CBzmY+ D7NLN8 S=b\TVU{\D|YQ'9Zm!JgVG)j7T~Rqݹ=*Jb09NmOϻq  pŘ,Gi1YX%ܐBnv'TbFrsFSiҜTo()\-2?/z?&2&q)7%n -"f{X\wVgzlwXlWlWZO)z2.?3p|c e7 |?3$ZS'-{~Hdm8@~8erK 4iu%я cT&}LNuEwԽ*jTs;VzCk;>rqh4"h>7n C1$_z~)(sfF n!̌S%r1z+I;J+E9> Ci'eO@c.9$)^ޛݑb!U]YJ$%Tm6}!]3?P3@b549, ,\N!wcԮ2pSv)o^f@WJ'NPBXO;qO;#%Hf'N:H,B.^] 5xNY-"8P+uZ+; K|mUEωt9`=&|,(οfI&W[@.a<{w" %YCrse"Xo_4V.^co!ؗK317JN];m+r؈觱(+ۇBswXQC3y5\Ȯ~Mo_Pe1w>%7LZ憣)_)9:yq;q} ۔miJח؇AO ߙ 3'uxfM1yV̵z `YWԷڿ!>p3,{$ oMjj'2}#v6+a0SԧH=e8d'Gt\g$bd#{׼gt_$UgV}}jY )\v,}6#4H,@˵%Nz993"վ);FIbgt)\.;k64=rF)5u8E1ŞImMOL|*4=-rk\HnEr(%9y1c4NT{(=uWFDi/5`BR%.2$ͥօK |jp:S} vﴀs,i{7AKo6RXOZv]4 ?-J&v 'EoZ1l%x#Sr(`4dXB];Ytһ ~DsEG?w2@1_>|i.Ҍ&BTgQRU2Y wt^Tu&_$qYIO!9jKbyFr}lc+ACD$$80}T춗BpNw<&7N/vXO'qà̦x1eh5͡9G zցfԥ%i/;nO U9b9VC vV>!Jj5ސ;#Ww'+@0E|Ju;W$Aϕ=9+w!oml;, V}>WGI8X5BA\nI=*fW.%!}ftEnm,}5۬Vnppݿ"dZdR!uS@LwЯ[8vx[HLt%nUk3p_\E~KOY8X);8bKR ks_c}ٿ>Ղ77vؗY|ZUqb/>sFC<wHan_G>1g-=(|!k(u`SUV#nP qgRz0VviCMENq UZƣFPC".rL]_Q [US$"SkT֕_|7azlf.ǗTud8wVEۣ?L8o&Gdr6ъC T_=^[sC\GNpL"N7x=u=.'&.]p+: K-HMY=0 0|&JDʾf]% R1`{ʇ(yb @V3=T#jx,yBqP/=ȹ&c)awfIf{. , 8!lQ2B?TptQӒ"$"}S19?x5*65y}*릜mx8~TNAjفlӜkRD}E.\4{ԘA7&DcDf\Ҳ{;Z`a"F}. Xqa|痯= ăxL;i,) Aa*ݰFQz "(fGNY=4; bg2rSרm?=-, ӟdĖn]Buz X_ rϵ'SCÓ [MAr|+6 ÒV NOZl>EQ( F 27i"knG 6AR7 U=PYUFX;X #]V)QLv*(>*>TJIGTDVp2|t ;-DU9AC]4luZ:͜^.WTZ }Ի. ; ~(@,\h-jH^ $wYrɧSĿ?{rGGxoپcĮ%q `^=_&\Z@2Ү 3ִ -dk_odT@F?akQPxϑA[)*n];)P w>13}OM+ t1;b=EpʙT hҠq6`]F~y~b"Y H~ai_;=rEea.f߆2 b"\np8ճbK1ؘ"r"L~F}WArKsa6,ź$y|+=p+YGiұ;i Aq ;+  $Δ'Ivh~T.DP\HFPeP@_ɦsPbM :?eT a'DpO/&`F95]ؔ23DۡI9HJu%A@x[߳f %F}%০p Q2l;eijs:p!)S ֹ@OH>+YJd*!>ei%t4ɬm򃩄ϟFsOunZʟ<]q/HI'w뉜;CO}4_cFۍ%3~@ky*>4&)1vXЃ-d:⪫ʯGwv37 e W}.vX^zv.'O\P_s<~$ύ&Vkq2;YjEm:Єr,"*4?u8$;q!6ho\(%4Nʥis\%auV DAp?HUf FլxؾoE<@p%€S;S},@Ƨ \ PdHgvSjJzQ$Pzj$ 3#95E$w?2f&]7^6k` 7W PNZ?&^6`?֌!"k&;{{@>:goo{CA1(8q4X}MoWǕF/)g*ZWpaKՏWLn mM`1gtls &W2:EDŽVG-/K0Y\_P>e[K]lFC\z1+@i9xm>.cTZca]{cm-S6ͻR#T?1hD-YBsF}븢9?m/ĮfހxN|v(jD`PgRck,)Oh'F,pcљu54*e%|y!3M76HX{>ut\Fo##9AS1"J hTPE5\3%*ss,3tJ0Z7t~9M/ lXHZoi9åp$yw@{ TbAPWa30^ل$Vpch()DȲ*Oߧn'`a{hf1qŠh ;l;5#+#6ׇ/ &13JḋD$Ch$kfꔡvpG.:/!8ms+hcFC1mi>V~X <ΰ _mn%E Eb&F$B^8%hd:܌ Ȩiu3쫋H,%ҩ&' Unc-Hl@렭rZE4.nzL&i>ƊcQ)q8wy ۣ/@BOD^ CL,iy ZmA^;6}7#jMО-բ0[eYi#! s2 --Mv3̰V1#dBi&*IT+Lh[p2qnƪv?E]9A^QO>[{ƿ$4YX &>se6Ũs- `'ٹ}Z'OcT׿9^bL) +1`U!V LwFlbq2 Q)ʩ k^R,戸ϘFa7iCu6Q*QQ{C#KQ/e^Jlj]WZnY^ og[j MC 3ABb]7O0GF:]ԞjΉ:wT.Qz Z/ ƣu"p:,vݶ$hzI(C^muz($*+?;9VĿCNl [$Hfm&AI+@ (j`\TOIq0٧VE.`%k}S\?dk戶f,lQ(L1Z H0^{ +=>9e.c#6.mPACI舲ѳcE@"mWYtc鈉ڔIFFKI0lA_|_cb{ ,=|}J =ZgphB]j0 $dw]4~DL~J\)>ތz?,27;[@[7]6ٌp."qCh~/QJɮ%4(s~e9l|:~j?`S,з!3K'?i2 wRX5տf+P6%iV_pl9OԀVM ">'x\ha" HȩG׼! n-=g$ ^[Stnpr?*}ܫ-0Iϱo Ň{ԧ{ҕe rLK_C}X:M߬I$1ӗjueyXQ>J]$h09TD-;zW-P x&Z=5,ǐAz{soj Lp%B}VBti}IT1dU!3dyrOE@d|5}u?L(bwώlZlC:d:J|b{*)g6?tO%aC~ &DJ/'MrVP<~7m. s}KYÌ#}Y3<cp!r{nj@<"|ٟk}( ̊˻mOշI6^{{ۂ@V/^VBLN T A<ܴΗ?5;YpKrKqO79 !šj ϗr%y*$ֲ}5ɇDJ-Z2\̒ ¶oB1y+WWcB.!]f"V+m=\+-xթBuFr^2+敯oGH{t'K>╧c]oRJ.;&2C/t ;q?L^05# 9ϒsΠfJ rT$#"1馆Q] uy[DsjEvw68F_h^\of"Y0\x/ƱK1g]Pfy cpNxsl1cX%:3>з`&`$LA g۬asDX`GìZCg MU9zuj E_d;r4%y.K!%;CŀQ<<q0,RxjIͼa̤Dex|C5Tq%tf c.~O4]O] Se(tdoZU}0k1L֮G+GRR.0k㿵=F MTx]0ަwUPkVtZV'k1:d7>ڀ@Gk++AC(%I 4%XcrK^k ̓v: Z$O!Ejm%֡k7Ht,^ 9h^ ;uʪ#⎺r\ՄhRf>)prڜ})+$Y8˳ X( "\e0@&N->s\v酅!I`^1`5(. W$"lLvhR՗OvQ$"H,J1ę? n2|'޵% ePڛ;@eX5%}'}C2 iH켎JKBH5ckkMT5#ߕPyJxg 0?yq~@K $jV^b&|^ ۼ2ڭS7a3 YAYf^F .<jeZEU XXK8WVOwIbXEн%3MY9 1?‚jyoab>{hX֝rs%D_wd-? `GX&]EDyjqte.Hkm@=- &c1{|8t"hKVqT;]=|0KiDLQ 75¢Ed(ZNOG"(‰.yC. C \~ۅZhi3OwL(ɏv,$6'2$T] r!$CkR41^ ڻRU 5#=9ut(Brnɻ{ ՘"(U+Vokq.aOunLJ/0k9n1@!8ŭ  J7cUx|R(TMm5j n߀ K7%66CKQ/AP';=pd*#o Bh|QaCD]*3.#w Զ zh—Xz}ՙZy ˅z4aE n qѺek&d]0X5l`CcN|/ >dH"h*M,.)E4~fz9Ʈw>YDU@f50+򐈿Sbj(vEu(L.@5F`E5󨢿Yβu LTnpMu}˒llPh'Phjq6F#{{uv$Qn<@5Hm5 |3)khB1V3kUE I&&8]jHyP+􏋭fApAhxH.iW]gavS<%5_7tM0σGZ0 |f 90Kۧn5$2rræ1w˳A@[%8?Z'% ̔J_,BCyl0JEiZ0?R|"p?T1Y[+E+iY?ˌ8+[ 48ZŖ/ǖ怗p#MS*o'w°3.3ˏPj\):=P @Z5Gk+9cQو`%mV_3aAQj`@R2BJ+їat`"}rr498ĭAIp =-7 o|hybp<ݿB^`GFx9\! 3tMQUۉ@B EZVOthX#FanKn7( 1_%P3'\5h}v|&iNƸF071їqmbcl. V[^a` zQ}U%WWJ" /&gۆ{+JIb14c, k]ZA)W|``пvnzdxkaePC#̿faXք@q21BvMQU#9N|Re_u\wחA7F~jٝ\TU1gRL)EoQiN45VBt2y)7tѥ ݅ȟNwbPmqoP|u$lD0 TLP迒\pT|tqk!*3٬EGأ^n^l+ 1B4&螳=3t;{0(r^0&h*$-cz:LL@m#ϗ14(C˧lB^_N0A 6MY# B;`$f5C.$B:0pwO&6+)3`E7 8ݿ! iZK0z$ hm}y2ޱBgҏ 3ǽ5i{s@D.8m\?~NnEX 5'vTq3<*ylW8^]E)nT5^֛aaǏxuŸq9r"B\4_D( ZvK-$ONkG"16@nx6ƟMEE!۴2=F+p9M6(/JgR##Z; h ؗ_x]T("?r>WaԸ%#rt  5 1ױ^1#3@L?w ϞCMh_6z包T.'k XpLJS0޻ݢ @5q!U^-Δwp@u W!ׁARݧ;CD 2J64c~t[_Urp}ѥ'OR q <VWynyF[i|ņj.fϊwqXE46n Igѕf SwkdsK7`y`X2T̯alcE@[ ι:!@mt=3aPmꠅ;ߋJ,ʐ"@ G[x"V)*ֵ0e719T 625%9D[s)Bn*&fW\B8>d&iz+%(rڢ |_amA[ң(B-JhqxHOp!jln6j56:]N1 H(Fy)Ebd:+{e ~zsr\UMӏ E2Sޭ&(`c>O;B;C.t!4 ;@.4?ĺp36E= iuukkHU\h j0Ču6)Ѽ JOOÛzCnB=i g 8?P6,\T@Eҹ|/.<"3NIvn5Z,Vqsеݷ-Cm~6vʫwflcPEQ=fQxf{x( q(`Ԏ^,D d#C[kw+ҡ٨ } 1`2Y&MMx19zWFL<]Жz$ˠW_zz0At;]LW/aYZh{*i8ەq%opyp T%^}t )L5Me;8iz/W4WPBPbLvS'.xLdn"w}ܑ+xF|'G̭?7|p$G2{ޡL_'+Mӛ ^#~HF;^l}G(RJu2XO/8q?JtHYLԖ"7qr޲T~:-Pm>G*Hq-Jvb LYK;gT:*'kV227`M3@0=/h(MTvĠw BGŨ֫q@r󢯄ݧc'O-KߏkfFr VT֖ $$ (%+A2]!y1}*4ú:\F:w췸}IC4?uM)6uұ&"w.Mc3 :hYrwLcšB<9ύDJƠa8˘fp,s'oV788!MBes{g Қ9<#QE؅Ex"zODXъ:/a*GI8%ڵ\plf_vtV:l&Id0 źm\KWt&IQDO$߲BA2:3և}^d!؂e-}wR}i2pEB$$+> e׃4mdHxܯ:/BT$*+c^RǨ9.N֩wI&GiT\E5mN 1U; !I4F=$le33S*S_&^DUuj_^,A_a][XV;_(?(O4F)/5t*"x4 lw\nJv,-E/x͡@giJFޢϞ/#[*1IIQ4]bg59rQ9O;"=@h4*R+$";>vL{s:6z=:FVF H75QR"]/4 _Dlˮ ؍zhPpz &yMW*Asj=VZprHm0D#2/a!w;#aKNO?Q V\q''*@wy\f$*pU85,X}+D;iI1YȟG[}bn[6eŚqBa{$F-o^CsGe\3]t`2d&sRS# *; ʰ"De-if@*Pwux>P+'!k/6'@ɬ?YLb$$ĮiBӜbZq6*q0Iwjs;C3Ylh"eܝ%]92ݶPԡ/I@ ?PFn+ZL69(&XYg 7jͯh_6ikТ(N' 9L0כ9Eone73G6+-PܒyS?3BHc</6ixB8@t}2fLUiXܓ?n;XdlՖ^dUe{Z[zزT OQHEps?ks+I0bg-/M~2ěW!XR'kWjqP ..K`Ҏ 5õ鞐`Uq#qO3aŜ<~O2}d+7+zO`?%K3['!xa(׊SwqlIW2Kf|-fu%J9~i& s_bvFn^Q],̛O?iCT_i#"kU >32KQ]MX~;vM6(D)ʰx06i`bmVEDY`~ᄠ~i84mI\KhNV,wH%V/I$l {9d/J'f`AfvzK|G`]\QL;h'GQbLo4 jXvQ|;vmNmZG+SE|nG太_o=@rRgNw&Oj$-b}&4u 4r*1WſF % AtdJQT.dXF^Df)c()֮:9_ Dqz7/" ^m-ƀ&6X>Ph$\&#@ ct4,J)S6 )8՚r(d{E8eh>BW||W_p!oɬkx`R$zЁԴܑC eZpJO"/tBO'[Q*]lDO(˅/=TR6G׌FNURcg9p1W6U#W/,8öx{<@Q>))s\1vc՜lPe۾4Ǜ,QBu h5Ϭl 1$;L3qEeE\ʢ)둩vA !͗ SG({M;tOa"u/*jWNǡqZ ԣU|{(B%rpmJ)O2-+šRBo$\K7OW2)޼xM|ƸI?+6fpu~R0P2ބHCiGfSӽy>cb5-(OI4Ǩ`5y|{xUD_r58aΏ)H r6'J;wDNѤ+-s~B Ec \@*DLIdF[:`w g?:v 竖FCJț6nK|TMn@cu+gU*\*W=_҆㝕vM^5~ ʉ̉ʬ % ۑD盶?>]VE`!]ƣ8ncٞAW XX+ CŢyvhacN1&D{|'!AlId\(fJpJy yI}y q0lʻ緩0Pn.ߏ6X"i+̓b쀷%,٣e65!-P9j!wB'N^*?N5+cNU jV.F`9;KәTӔM$}q/nP5a1~$aۣ͒? &MCc΂R4]NE^ 1j_PԞ\Vp59LGZ#OC WL_uuvQcH!ܸaЕ9e%iVĖ!tY_Ut04Au]qθZ̨gf7 2mbYe9xľq :~-|- 1ޞkUR$` ߢ=*Xa /7[궻`fa:|42{ !luN`<3 ^{>u}5pu3Zn=f9r0PL1vuRKE0j4n1RȲv.̿"wJǭe\HAqCC ݚ?/]N#bX^`G9s(hۊʒ:'m΁~(QF|8G(u9+'^%< =\9Mu @2n_J,v=:T1nj 2af,O8Pd㇝P9HwWbKI}rn;H}! `W|>t-nTCkNlYOԣ413z0+VȼT&B^&I᦬;*biylmMMo^o>LBߥVw46dLvWϦ%Bbua{F#DPh@,@N5cӘX6chIZ^:ˍ3Q#gtq-^멷;v&Ɨg&6;)aUW$ ڨ;Oʋz+LJ:zSn: 侢,X[WZ)k0fvetJʜG$tWf:IY2bQ fcC"WS L&KMvn0TEI ym`$˼C;Bm{'; 3P=0ˣ\\ :SF4Ui)"_.;2_~ 1vN4< Qτ:49ura3 }RM1G8 F ga4)::&9D[9l`~+h<ӌP =%ӒA$ 7s3iQ &NcZ n>ZʫA4_ifۼkFosi}I4Y7qJSJ6n0cͯ3U u g EGh5e >;Tܺ;πa`Qi69^|@/*>n6C^gc6B"rAho` yA_dw^&Z[g:dD,0~IK]0$5l.,xEb}$ (k(L/z5ErFU=4u}C&O!S%⛟R`㚟R> LE"?kmeIۖ⯆IWsS`8bԝXyǧ$') R-?sqeufcTCj0b0o|02=.;nJ[NJC 9HG]X(uhfB/5 TVj\)wĜ{jdyJƭ;V6%U\Kؑz]RVgPFI{ўVC(㥖,' 𓾍$|iti?5jԚY dխu;F'i=jP:PLOZ3Ǩ-9}~ton 밇ThAP.tkP8AWӗ 56GEOM3K /QjIՌn{qm[t7u%ŋM?e/vl|#`752K?\rl3i?of -ّ4=o4xbMff?ll&|.>Ǘc-.~hl>?\\^V9-}zHpNL(>! , ~g%.qr#Ö0oVXFxY8юgy @Lia< -D$S8MHmɴ6N;n_2T6T+ïP[u֋8wdZv7'PѥQp%0`*6[aU 9V&'8τ/Z1G|,?gIDga_AtqZPCE@:SdySAzTk<^0E emV(lo$  (8lN@ZhP̣nRClX|+}+JxFx1ǴLUjϖaAgnNZkK.Wm@o%$ĠA[ɟr.DQr?VTy{Ml^-Kvlyد{@H7 F^>vU_S>@4G\4 5qV+"T˧"IM'Kt?kz6:ߕ(x EnO\Ɉv҇/͇arfluZ+zmu%E|fQrQtm簙􄶵S ^rf֯nU@c3͟6i?]%6lYMB{bJ!nɚ9NꖨB6P 0xP9dz1++h+{y-o$لk78 f?[…2,ZJ`3;Vfڌ3VشǛђ#Va~bWw!rĝ@M[Kl|"^ R}A"r\_S c~fm-Ζbv' v *UwLTSXKǪ\haR {Od4+QW]njlGT)Ml lV4˫ul9R0lRlLZ0_zd9x]c4. eneP/| ` §O+*?s}^0S(F~BۙƱ^u#E>\.ws?}\@*\8M LE/me Ļ$l$Ew(Ƃ{i Nvv_.gCZL%zI8..y|կc: 8W/5_O{Or H"c4M+Rnn٭,M] cY7àՍꎥC^D:MEC~;>ñ^G/K2[mKY3+:Q͇NXsRlql||k@Yinj|3>,o@^0t]BZAA88q9iM\N aDFH9E5a!PMƛcwjK RX1ԥhyk'P 5@{v2Z SS}_~9Y.!#riyɋYizf֐g E5_A "6툢휒=),ijƉ{ҭ;OGF =ϤXEst 5?x,?aQXDzOjo1yV^s!ZUyrMʔpP +׷LWBxj))׸1TRsh$j7[Iub3L1+}e&iL{*.> -‰&I| I?o]pfY O]y֕H=Ƅ'k[&cq: vz5XU{'2*PD԰,ZP<&[M k/}RدU?6H@SI` `IB6._PA$xsf <}1/Ȱ'vHE167omrƅ?!Cw0Nwшy*Yz* |qiqMd!i,2n"8mgݑQzt00ej07CYxJ.]A{8Z}4hUX> A(Z?XuËyb& v1큒 {17[vUxxO#T |UvAkGPD:0Âm6@` PoW1[hı@e1htcMGHinFPSk[Q5V/t/Oa!`|4M8\~9[ W 6,'ˋ@úM2‘ϙ5+u,9kR'-ح&q%ijfLiaoi0ԽxNfT|˥42 D:G]ם,hC//&"\ezmÿC."U=Q'gʮE+d 0{l= G׿Qpe4r ֕hHV8qnl]˩- W8UkNG;4}f.N]C[5"0xX3n(HGn/JYOv徑v ي 3+ҞB'W~&*vŕdJqr'ާ?έw^]_1k+q]}['5ZcX6ߝ(Wq?3~`>EԡZ;b-*PqW~| cýK<2ɮ ⚳,`  N_8vyh9^ΓH+gGQ)iG$P3kٮ Dn=B{|>y~m7[ SPZK+U Pj^Fj>j_o1~]i/`z5ӆST*8Qmd x0<*d5,G?a]HEI%V6J~Ѧ +J#'T*z-DViL{VZПU&xyBMQ" LDzjq}xjæ,G_0x3AqZ,X@GEOЍj)rbH`pd0[9}>5 4BYԎ覺TZSIR< (Y<ӥšHioCzx2q̋JU(z^otdVD '$fhC} bí!!K1?0,0v.N OoT7vMO.ݟ8e\5 wҴ~ޒ$`BD˱M2Pzpkk٤ A'qm6,GFY VBFgYwO#7Vr't+/CR˪~c̟~"o&/6V1Ȅ!F^|cAkfA]Ļ]y`й}2)PJ&iCՒqS;j>X~TxkHjpf${ft|h Ƴ]] F eSk ŹNI+M^ S`%i6m^zAÀ-ZÛUɓ O/"s߾kQ~`+k^{3m݀۩ ؾs߳sJ f'M 3u7y>w>vK0\Zk0;n2_` ?v~8U!`2hn??A3;WOhf$7ͤ.@&'0Z=vLL\Xgm͕5p݂  ȥ׶5)4yҢLLvF=^^~KKd>h/mPyʼnWSBÒ=Hpm+{lP#Ƃ_&2?kT\#VrssT lV 0Y\BTK/$`(]Z+ko`e0ߧ`f*#L;7Fv,ucsi]Ń+/!8Z:)@CM`x tf'<ǚ/=#*3)figa^Hoi&X!.kzV') -#u_9H}# WN:ܔƊ炑@ڨװ<eS饳) } A=uU20BFxMhS\D^nA/-=f5ęV"VOz!A3>.2tV>;}%ڏ% }aX&`R}=pUN'ʖY9hF_ D;d?x+ ~vkW^ ʽ_er~h= k.4?KD2'97!wDj%=|yx/?WAwұ*:GnfaGaLUH;PnHeݙ|G\DWέ\EvHX615gT1qw_e=n:J+أm/%\zָu(qi6.x㭿n#w L5AR~A „]L#`(qY<(#yE&sOnȅG"Ȣ3Fbک!|N3a#UgoG_-j6s{7L#n 0)J#@AAf'LO "I3p !FW+44%mp큔֏tm)WzDJكHjq>e r 4O%M*d@6O8y6>wp4a< ҡN4w^?9h0 !Z+Cw<>7j5uhٿ0j=-ݦ@XhU%IfZ Z,q{ ~sVMחU+=hx£^Oލ#ߏmFdńvǍPlnW5reGr(vxJH  AǍ#y-0jT%J|P4A/6ˮ2åy/d;]u<ewQ—'Bk6[|bݓS ٍ05k#AWg/>=R&.]9yqbo!m] _@qYy(H1kbY1]IxRUAH$9U+؊^`k%fX߮SSJr1}u}`∼9 S6r2]46,;f|n3bEEG 銈CxeЗ'?۞Orm ~< ãefؤO^ri -s_WE0E3LxMeb@LwSrgȹbk2S isDOeFV  􌩥4l"bAwk`eu;f=IjLGZU{# 0J†N0nxXM IgUՓXryN3|UgǍ6n.F[`m؂GajߓOBx74h: q*D>b5pl#\\$sQ"a'CCElwAY',Rǁ4mG#J7Rf;Rāc&T~KÑ9`] M d[(2 AO>J%N (i^\yBj8#3͞ Ve(y57a Fnx' ÊW7b Z35meb߀G'9>re3bdXG&'\+/p^c @N.[%ȋ Mm)[)4AJؕbT0o%3/s*%yp\*K圭{QF]fN˦SuZ?@tC,_}Y*8j#>t&bݳղ|# |\[3)e?i|h}X/ޠ==?c&# x [$Ue)R$=94^ !@Ea=Nf/|RH<i֩{΍m'M0!u/7d?H9r Zcz"Sh__e:)gmgzTF"-O, !Z>OAxMK bhǔCcΪWLX1W9"Cjra9X. hOMFbҖ#&ĉ>eR8GIgnDv{e2FEh,\ђ^` KBB<%]`3z=r_<@L?e_$yl5B ._hS|0KxYW<b 5g <]`QacAWvMPܥ}{b[.b̿-^Cv3֊|'3L118qemߑ6 xo +%Xpd7r̟:h<)*ljSMw)Amý ]> u^=F+!:FO#2HmkS%jiE6H +#7?ZM0ٺ2#[>9(g]'),B |g.jTe7I_dɇ{x\;4 ˓+ $T(ziS'_IʴdFF:$$ow*N?n})|2R4|w%juLSz*=|_a0A5E_'Wtax~f[/EC /W[1 VlMé.K+;|2cmϤ%5 7|8?lVQv6̛L?PdÈBh.R`[ 9c֧;۰u: В c^&AoL!2eXLr"j7rOE3ZkLHQT_Y Z^NRjQ dr(jN4ʀ ?$bLٶb~:ZI /m6F(=0Zqp֥{6EpM@;pInڰ1dvtjIeI]((Ud"zD;V$' MqLKNbnC;3 )UT[>1xݐs;mf@BLk~O˰U{7@m9k.\^bz?]ț_CiDc| .%9#v/a&Q}mOKz6ɽcՇ1gy-U̜,TŴ2A]:t]Z$ngρ=2>* -@G6[#"#-`ybFhMZ7ۓب{X \V.TND-#c_g p&sxk:jϰ {3#e_اCb&n5U:*E$y!Qkmm <ekRh2s~gz)qib@)t-|LB(v%*Y(v/HiP֌p#s7ήqSUm;gp׀hfG5T3ѬC!o{A=0WM6PK+K"s^=>; QC騒_|㙬9[Ge 2 '& y0;$lBE'_*Ĉu $h;i6C 9!Ʒ .@D9kD?0;?PyT4 Hd'.P 9kǥy.䕬>c=KH=$$/ii)R$fu%C8hw\sQQ3IvxQwQ ; ꪘ*n@P&.@] 0Zgv aф~ ;?=ZѼE6%w{)RHIE"Q`KS2j"` \.d{SJ愙$MͮGS4$!Nrja rnzƠGt$'oP% NGTUw_`3t'o;9KKUo(>p!5g9zѭƥcDT^HZ@ %v̥ygA$?$vigȩ ^ե,14 N@e]z޳ Y*Ă++1|a )ثLY +S!hs 1r;ќOp5 @#i>=0ne*^O}+UHqk:nYaW1d {1䊢BC1$VDkMQD(wJ'A' }i#PGud ?L|u4r5>nX3%4Y vRSW]Dbor Wv :dx]+UXPâ)'82atOX6{r-QL!< Le-H8kYO4z:`#b.Sn\Cє9LBNu֫2HsE%Jv['8(4t+ % 1QgE,` Lgf˕eה*K/Z[G4FEUQӦ{a5@R^U@O0fsd `0/AgB?1ڐBýT9.7P[D0nȧrl;"4|Svwнg+g/*d`L?:8ĐZFX~Ud3S,`󜐏kxy | f?Ig]LRaQe̵ A~, h!)tB>|׾xNfhzp;s}'|5stLKytcWixP/; C6 h}fSM( j +xuG5>UzGWcxh%n>R0/t/M:;KDv%̀# ❏jG )q1gEh7?ȑ/lpYaؽLC4Fh1߭_?!ӗKUnWj?z]@B}x?qN>x37($A.!ւ_uL1߷pU48q-s&8L)&E11r%+z0d |*KW-R1 A;tM[z觜`a!bzrjՀ7?I.LZSpiw|"/E;Iƕ՘ة;#zCros/;O_ BF)p{C BGL~2R5wU/M'W0] /̧t`klfĖjL'r/x#vCtczK,6\䅻vJ"^Sv >QDESQe5Gfةo]A¤ 7v-K.񟢦,y9.gF4cG\Xڙ)Z.yZ%1AuUHFJXT{R!BrJ,ۥ_tk' wSI Toev ,3Kqܗ< MZPtEw*yl 4 M$'8Lٯ{S6͎G]-IN!Yb6wvc27-ԥwLm2IT1ʭ_PV cs:wzI@C1 ksU]?y: Jѹ]D)b+BP K Y>s}]IKӡڟ|{q^jܖ|nX 3Lyc^C^Hb&"r?,?KR{@=tG-m8̫B п0i"Ϝ{!8hiVb[9|Xk]PG]Xeφ|D4Y*iK ]ezܥ(cvY8;D@wOӮti`0LS[p&rhIlZIDaزvN30"9&!!{6Q{R('>:khC$p9D @<40`V6!R]*'f(ۜ\єHk m]P)2 "ihn>q6Z5(RJ\Y:Ȇ7*Dƞ]IX㦥[4]`#u1݈R ih/#svcEonj26krAZ<"##䦟cX$cnL-׼$ YXΏPG`G1)d@W ږxL gр@k#ԷtGݹ@1.v:S~xT[b"eRea\0]s~"Âl`9^RԥyLVfg PǾ\֥5:X4id{/Ő`Ѝb:T@X&ҘGD,؄ d65 )`Grs?t5};aF;k% ў]ګ)\n-|O_C֖1ad"ܨ ?q YZ