openssh-common-8.4p1-150300.3.22.1 >  A dYp9|I P`eb86ArQ<ꅲfŇk]ɴf 9չaq_vиP4V8 W؋o#3Lq0f[r6!N_'N9ȀY$K9=rʁmڎ 8m>%~ݞ|܆sUA0ȉZC4܆@;cg;EE)Y'))o{e|;Цs[yFb]guu7BnX]4km> ,ǦÔ/SH{}V/KuJJ D~|vѨ5'QF G%`>pA ?d % E .C Yu   \  L@ T   ( 8 ^9 t^:^FG0HpIXY\]H^ bcVdefluv4wx yLzCopenssh-common8.4p1150300.3.22.1SSH (Secure Shell) common filesSSH (Secure Shell) is a program for logging into and executing commands on a remote machine. It replaces rsh (rlogin and rsh) and provides secure encrypted communication between two untrusted hosts over an insecure network. xorg-x11 (X Window System) connections and arbitrary TCP/IP ports can also be forwarded over the secure channel. This package contains common files for the Secure Shell server and clients.dYzgoat23VSUSE Linux Enterprise 15SUSE LLC BSD-2-Clause AND MIThttps://www.suse.com/Productivity/Networking/SSHhttps://www.openssh.com/linuxx86_64*yvFcV   (;X/ A큀A큤A큤$$dYxdYxdYydYz_p>M_pBO_p>M_p>MdYRdYRdYR_p>MdYz_p>MdYxdYx26c7ce984ad1554faa013243ef9b80a3333926157c361f7b338112a128e72fb9b4f0397fa8aa841696089333ebe4fb70f74664e973754086bc7e8e0121cfdd437ce5ace3ef0c9859b1bce11f16b55764918098df7c252fedc0af0ac1cc19cf7a2c0c7a320c31e48e26761ae1e4f85144a94d47efdff025e4bcb77cc71c725233e316829db4e08ef17fc6d3b0c20a992de0f936043a28fbcf8840e28247ab0827310f98f3e5a5369da093f879fc9a6f077c1ecf94040727550cdfa8c030a2d36e175e7c8c2ca49c904598b82c36f255b536b5d2b63999998332e935e478338397c083708e66964338b54096eac464ad4c7f7291c55078129382b4904d05e68f36ee6e37bc6c078178f6ee03ecd5bfb0648d85ae13ea6ae68f8ec2bae112370cec2945b0ca20d85ac65eaae6679c396f49e6bec98b70bc5826ebb60bee0c14b17473d0db766229670c7b4e1ec5e6baed54977a0694a565e7cc878c45ee834045d7cd5e134c51537135f0a4f8ab3e659ab57c787c2d41d78124efb7be5c78c59b02472535860809c60b66bba4f9679622ec00d4da3b190ac86ee3655ab780cf0162rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootopenssh-8.4p1-150300.3.22.1.src.rpmconfig(openssh-common)openssh-commonopenssh-common(x86-64)@@@@@@@@@@@@@@@@@@@@    config(openssh-common)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.17)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.25)(64bit)libc.so.6(GLIBC_2.26)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libcrypto.so.1.1()(64bit)libcrypto.so.1.1(OPENSSL_1_1_0)(64bit)libcrypto.so.1.1(OPENSSL_1_1_1d)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libresolv.so.2()(64bit)libresolv.so.2(GLIBC_2.2.5)(64bit)libselinux.so.1()(64bit)libz.so.1()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)8.4p1-150300.3.22.13.0.4-14.6.0-14.0-15.2-1nonfreesshopenssh-fipsopenssh-fips8.4p1-150300.3.22.18.4p1-150300.3.22.14.14.3ds@dD@d&@b@bbaA@a@` @`` ` @` @` @`x@`x@_I@_@_@_@_@_~@_m_m_cO_Z@^3^Ӝ@^Y^K^B@]|@]X]W]c@]c@]c@]@]Z@]5@\@\@\@\M\w@\v{\j@\eX@\eX@\N\J@\I\I\?\8@\-@\[@[ٙ@[ͻ[@[@[@[$@[$@[@[@[[[0@[Z@Z@Zľ@ZZqZhu@Z]@ZX@ZWQZ@Y|Y@X}@W@WW@WV@WL+@WH6W#LW@VT@T@sflees@suse.demeissner@suse.comvliaskovitis@suse.comvliaskovitis@suse.comvliaskovitis@suse.comhpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comkukuk@suse.comdmueller@suse.comhpj@suse.comkukuk@suse.comhpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comdimstar@opensuse.orgfbui@suse.comjengelh@inai.dehpj@suse.comhpj@suse.comandreas.stieger@gmx.delnussel@suse.defvogt@suse.comhpj@suse.comhpj@suse.comcrrodriguez@opensuse.orghpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comhpj@suse.comkukuk@suse.defabian@ritter-vogt.devcizek@suse.comvcizek@suse.comvcizek@suse.comvcizek@suse.comvcizek@suse.comvcizek@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.comtchvatal@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.compmonrealgonzalez@suse.comvcizek@suse.comcrrodriguez@opensuse.orgpmonrealgonzalez@suse.comtchvatal@suse.comtchvatal@suse.comtchvatal@suse.comtchvatal@suse.comtchvatal@suse.comtchvatal@suse.comtchvatal@suse.comschwab@suse.detchvatal@suse.comastieger@suse.compcerny@suse.comdimstar@opensuse.orgpcerny@suse.comkukuk@suse.depcerny@suse.compcerny@suse.compcerny@suse.comdimstar@opensuse.orgpcerny@suse.compcerny@suse.comrbrown@suse.comjsegitz@suse.compcerny@suse.comcrrodriguez@opensuse.orgpcerny@suse.compcerny@suse.commeissner@suse.compcerny@suse.compcerny@suse.compcerny@suse.compcerny@suse.comkukuk@suse.comastieger@suse.commeissner@suse.comledest@gmail.com- Add openssh-CVE-2023-38408-PKCS11-execution.patch, Abort if requested to load a PKCS#11 provider that isnt a PKCS#11 provider (bsc#1213504,CVE-2023-38408)- openssh-7.7p1-fips_checks.patch: close the right filedescriptor to avoid fd leads, and also close fdh in read_hmac (bsc#1209536)- Revert addition of openssh-dbus.sh, openssh-dbus.csh, openssh-dbus.fish: This caused invalid and irrelevant environment assignments (bsc#1207014).- Add openssh-dbus.sh, openssh-dbus.csh, openssh-dbus.fish: Make ssh connections update their dbus environment (bsc#1179465).- Add openssh-do-not-send-empty-message.patch: Prevent empty messages from being sent. This avoids a superfluous new line (bsc#1192439).- Add openssh-CVE-2021-28041-agent-double-free.patch (bsc#1183137, CVE-2021-28041), from upstream.- Add openssh-bsc1190975-CVE-2021-41617-authorizedkeyscommand.patch (bsc#1190975, CVE-2021-41617), backported from upstream by Ali Abdallah.- Add openssh-mitigate-lingering-secrets.patch (bsc#1186673), which attempts to mitigate instances of secrets lingering in memory after a session exits. (bsc#1213004 bsc#1213008)- Add openssh-7.6p1-audit_race_condition.patch, fixing sshd termination of multichannel sessions with non-root users (error on 'mm_request_receive_expect') (bsc#1115550, bsc#1174162).- Add openssh-fix-ssh-copy-id.patch, which fixes breakage introduced in 8.4p1 (bsc#1181311).- Improve robustness of sshd init detection when upgrading from a pre-systemd distribution.- Add openssh-reenable-dh-group14-sha1-default.patch, which adds diffie-hellman-group14-sha1 key exchange back to the default list (bsc#1180958). This is needed for backwards compatibility with older platforms.- Make sure sshd is enabled correctly when upgrading from a pre-systemd distribution (bsc#1180083).- sysusers-sshd.conf: use sysusers.d configuration file to create sshd user (avoid hard dependency on shadow).- update to 8.4p1: Security ======== * ssh-agent(1): restrict ssh-agent from signing web challenges for FIDO/U2F keys. * ssh-keygen(1): Enable FIDO 2.1 credProtect extension when generating a FIDO resident key. * ssh(1), ssh-keygen(1): support for FIDO keys that require a PIN for each use. These keys may be generated using ssh-keygen using a new "verify-required" option. When a PIN-required key is used, the user will be prompted for a PIN to complete the signature operation. New Features - ----------- * sshd(8): authorized_keys now supports a new "verify-required" option to require FIDO signatures assert that the token verified that the user was present before making the signature. The FIDO protocol supports multiple methods for user-verification, but currently OpenSSH only supports PIN verification. * sshd(8), ssh-keygen(1): add support for verifying FIDO webauthn signatures. Webauthn is a standard for using FIDO keys in web browsers. These signatures are a slightly different format to plain FIDO signatures and thus require explicit support. * ssh(1): allow some keywords to expand shell-style ${ENV} environment variables. The supported keywords are CertificateFile, ControlPath, IdentityAgent and IdentityFile, plus LocalForward and RemoteForward when used for Unix domain socket paths. bz#3140 * ssh(1), ssh-agent(1): allow some additional control over the use of ssh-askpass via a new $SSH_ASKPASS_REQUIRE environment variable, including forcibly enabling and disabling its use. bz#69 * ssh(1): allow ssh_config(5)'s AddKeysToAgent keyword accept a time limit for keys in addition to its current flag options. Time- limited keys will automatically be removed from ssh-agent after their expiry time has passed. * scp(1), sftp(1): allow the -A flag to explicitly enable agent forwarding in scp and sftp. The default remains to not forward an agent, even when ssh_config enables it. * ssh(1): add a '%k' TOKEN that expands to the effective HostKey of the destination. This allows, e.g., keeping host keys in individual files using "UserKnownHostsFile ~/.ssh/known_hosts.d/%k". bz#1654 * ssh(1): add %-TOKEN, environment variable and tilde expansion to the UserKnownHostsFile directive, allowing the path to be completed by the configuration (e.g. bz#1654) * ssh-keygen(1): allow "ssh-add -d -" to read keys to be deleted from stdin. bz#3180 * sshd(8): improve logging for MaxStartups connection throttling. sshd will now log when it starts and stops throttling and periodically while in this state. bz#3055 Bugfixes - ------- * ssh(1), ssh-keygen(1): better support for multiple attached FIDO tokens. In cases where OpenSSH cannot unambiguously determine which token to direct a request to, the user is now required to select a token by touching it. In cases of operations that require a PIN to be verified, this avoids sending the wrong PIN to the wrong token and incrementing the token's PIN failure counter (tokens effectively erase their keys after too many PIN failures). * sshd(8): fix Include before Match in sshd_config; bz#3122 * ssh(1): close stdin/out/error when forking after authentication completes ("ssh -f ...") bz#3137 * ssh(1), sshd(8): limit the amount of channel input data buffered, avoiding peers that advertise large windows but are slow to read from causing high memory consumption. * ssh-agent(1): handle multiple requests sent in a single write() to the agent. * sshd(8): allow sshd_config longer than 256k * sshd(8): avoid spurious "Unable to load host key" message when sshd load a private key but no public counterpart * ssh(1): prefer the default hostkey algorithm list whenever we have a hostkey that matches its best-preference algorithm. * sshd(1): when ordering the hostkey algorithms to request from a server, prefer certificate types if the known_hosts files contain a key marked as a @cert-authority; bz#3157 * ssh(1): perform host key fingerprint comparisons for the "Are you sure you want to continue connecting (yes/no/[fingerprint])?" prompt with case sensitivity. * sshd(8): ensure that address/masklen mismatches in sshd_config yield fatal errors at daemon start time rather than later when they are evaluated. * ssh-keygen(1): ensure that certificate extensions are lexically sorted. Previously if the user specified a custom extension then the everything would be in order except the custom ones. bz#3198 * ssh(1): also compare username when checking for JumpHost loops. bz#3057 * ssh-keygen(1): preserve group/world read permission on known_hosts files across runs of "ssh-keygen -Rf /path". The old behaviour was to remove all rights for group/other. bz#3146 * ssh-keygen(1): Mention the [-a rounds] flag in the ssh-keygen manual page and usage(). * sshd(8): explicitly construct path to ~/.ssh/rc rather than relying on it being relative to the current directory, so that it can still be found if the shell startup changes its directory. bz#3185 * sshd(8): when redirecting sshd's log output to a file, undo this redirection after the session child process is forked(). Fixes missing log messages when using this feature under some circumstances. * sshd(8): start ClientAliveInterval bookkeeping before first pass through select() loop; fixed theoretical case where busy sshd may ignore timeouts from client. * ssh(1): only reset the ServerAliveInterval check when we receive traffic from the server and ignore traffic from a port forwarding client, preventing a client from keeping a connection alive when it should be terminated. bz#2265 * ssh-keygen(1): avoid spurious error message when ssh-keygen creates files outside ~/.ssh * sftp-client(1): fix off-by-one error that caused sftp downloads to make one more concurrent request that desired. This prevented using sftp(1) in unpipelined request/response mode, which is useful when debugging. bz#3054 * ssh(1), sshd(8): handle EINTR in waitfd() and timeout_connect() helpers. bz#3071 * ssh(1), ssh-keygen(1): defer creation of ~/.ssh until we attempt to write to it so we don't leave an empty .ssh directory when it's not needed. bz#3156 * ssh(1), sshd(8): fix multiplier when parsing time specifications when handling seconds after other units. bz#3171- Update openssh-8.1p1-audit.patch (bsc#1180501). This fixes occasional crashes on connection termination caused by accessing freed memory.- Support /usr/etc/pam.d- Fix build breakage caused by missing security key objects: + Modify openssh-7.7p1-cavstest-ctr.patch. + Modify openssh-7.7p1-cavstest-kdf.patch. + Add openssh-link-with-sk.patch.- Add openssh-fips-ensure-approved-moduli.patch (bsc#1177939). This ensures only approved DH parameters are used in FIPS mode.- Add openssh-8.1p1-ed25519-use-openssl-rng.patch (bsc#1173799). This uses OpenSSL's RAND_bytes() directly instead of the internal ChaCha20-based implementation to obtain random bytes for Ed25519 curve computations. This is required for FIPS compliance.- Work around %service_add_post disabling sshd on upgrade with package name change (bsc#1177039).- Fix fillup-template usage: + %post server needs to reference ssh (not sshd), which matches the sysconfig.ssh file name the package ships. + %post client does not need any fillup_ calls, as there is no client-relevant sysconfig file present. The naming of the sysconfig file (ssh instead of sshd) is unfortunate.- Use of DISABLE_RESTART_ON_UPDATE is deprecated. Replace it with %service_del_postun_without_restart- Move some Requires to the right subpackage. - Avoid ">&" bashism in %post. - Upgrade some old specfile constructs/macros and drop unnecessary %{?systemd_*}. - Trim descriptions and straighten out the grammar.- Split openssh package into openssh, openssh-common, openssh-server and openssh-clients. This allows for the ssh clients to be installed without the server component (bsc#1176434).- Version update to 8.3p1: = Potentially-incompatible changes * sftp(1): reject an argument of "-1" in the same way as ssh(1) and scp(1) do instead of accepting and silently ignoring it. = New features * sshd(8): make IgnoreRhosts a tri-state option: "yes" to ignore rhosts/shosts, "no" allow rhosts/shosts or (new) "shosts-only" to allow .shosts files but not .rhosts. * sshd(8): allow the IgnoreRhosts directive to appear anywhere in a sshd_config, not just before any Match blocks. * ssh(1): add %TOKEN percent expansion for the LocalFoward and RemoteForward keywords when used for Unix domain socket forwarding. * all: allow loading public keys from the unencrypted envelope of a private key file if no corresponding public key file is present. * ssh(1), sshd(8): prefer to use chacha20 from libcrypto where possible instead of the (slower) portable C implementation included in OpenSSH. * ssh-keygen(1): add ability to dump the contents of a binary key revocation list via "ssh-keygen -lQf /path". - Additional changes from 8.2p1 release: = Potentially-incompatible changes * ssh(1), sshd(8), ssh-keygen(1): this release removes the "ssh-rsa" (RSA/SHA1) algorithm from those accepted for certificate signatures (i.e. the client and server CASignatureAlgorithms option) and will use the rsa-sha2-512 signature algorithm by default when the ssh-keygen(1) CA signs new certificates. * ssh(1), sshd(8): this release removes diffie-hellman-group14-sha1 from the default key exchange proposal for both the client and server. * ssh-keygen(1): the command-line options related to the generation and screening of safe prime numbers used by the diffie-hellman-group-exchange-* key exchange algorithms have changed. Most options have been folded under the -O flag. * sshd(8): the sshd listener process title visible to ps(1) has changed to include information about the number of connections that are currently attempting authentication and the limits configured by MaxStartups. * ssh-sk-helper(8): this is a new binary. It is used by the FIDO/U2F support to provide address-space isolation for token middleware libraries (including the internal one). It needs to be installed in the expected path, typically under /usr/libexec or similar. = New features * This release adds support for FIDO/U2F hardware authenticators to OpenSSH. U2F/FIDO are open standards for inexpensive two-factor authentication hardware that are widely used for website authentication. In OpenSSH FIDO devices are supported by new public key types "ecdsa-sk" and "ed25519-sk", along with corresponding certificate types. * sshd(8): add an Include sshd_config keyword that allows including additional configuration files via glob(3) patterns. * ssh(1)/sshd(8): make the LE (low effort) DSCP code point available via the IPQoS directive. * ssh(1): when AddKeysToAgent=yes is set and the key contains no comment, add the key to the agent with the key's path as the comment. * ssh-keygen(1), ssh-agent(1): expose PKCS#11 key labels and X.509 subjects as key comments, rather than simply listing the PKCS#11 provider library path. * ssh-keygen(1): allow PEM export of DSA and ECDSA keys. * ssh(1), sshd(8): make zlib compile-time optional, available via the Makefile.inc ZLIB flag on OpenBSD or via the --with-zlib configure option for OpenSSH portable. * sshd(8): when clients get denied by MaxStartups, send a notification prior to the SSH2 protocol banner according to RFC4253 section 4.2. * ssh(1), ssh-agent(1): when invoking the $SSH_ASKPASS prompt program, pass a hint to the program to describe the type of desired prompt. The possible values are "confirm" (indicating that a yes/no confirmation dialog with no text entry should be shown), "none" (to indicate an informational message only), or blank for the original ssh-askpass behaviour of requesting a password/phrase. * ssh(1): allow forwarding a different agent socket to the path specified by $SSH_AUTH_SOCK, by extending the existing ForwardAgent option to accepting an explicit path or the name of an environment variable in addition to yes/no. * ssh-keygen(1): add a new signature operations "find-principals" to look up the principal associated with a signature from an allowed- signers file. * sshd(8): expose the number of currently-authenticating connections along with the MaxStartups limit in the process title visible to "ps". - Rebased patches: * openssh-7.7p1-cavstest-ctr.patch * openssh-7.7p1-cavstest-kdf.patch * openssh-7.7p1-fips.patch * openssh-7.7p1-fips_checks.patch * openssh-7.7p1-ldap.patch * openssh-7.7p1-no_fork-no_pid_file.patch * openssh-7.7p1-sftp_print_diagnostic_messages.patch * openssh-8.0p1-gssapi-keyex.patch * openssh-8.1p1-audit.patch * openssh-8.1p1-seccomp-clock_nanosleep.patch - Removed openssh-7.7p1-seed-prng.patch (bsc#1165158).- add upstream signing key to actually verify source signature- Don't recommend xauth to avoid pulling in X.- Add patches to fix the sandbox blocking glibc on 32bit platforms (boo#1164061): * openssh-8.1p1-seccomp-clock_nanosleep_time64.patch * openssh-8.1p1-seccomp-clock_gettime64.patch- Add openssh-8.1p1-use-openssl-kdf.patch (jsc#SLE-9443). This performs key derivation using OpenSSL's SSHKDF facility, which allows OpenSSH to benefit from the former's FIPS certification status.- Make sure ssh-keygen runs if SSHD_AUTO_KEYGEN variable is unset or contains an unrecognized value (bsc#1157176).- Add openssh-8.1p1-seccomp-clock_nanosleep.patch, allow clock_nanosleep glibc master implements multiple functions using that syscall making the privsep sandbox kill the preauth process.- Update openssh-7.7p1-audit.patch to fix crash (bsc#1152730). Fix by Enzo Matsumiya (ematsumiya@suse.com). This was integrated in a separate code stream merged with the Oct. 10 update; the patch was also rebased and renamed to openssh-8.1p1-audit.patch.- Add openssh-7.9p1-keygen-preserve-perms.patch (bsc#1150574). This attempts to preserve the permissions of any existing known_hosts file when modified by ssh-keygen (for instance, with -R). - Added openssh-7.9p1-revert-new-qos-defaults.patch, which reverts an upstream commit that caused compatibility issues with other software (bsc#1136402).- Run 'ssh-keygen -A' on startup only if SSHD_AUTO_KEYGEN="yes" in /etc/sysconfig/ssh. This is set to "yes" by default, but can be changed by the system administrator (bsc#1139089).- Add openssh-7.9p1-keygen-preserve-perms.patch (bsc#1150574). This attempts to preserve the permissions of any existing known_hosts file when modified by ssh-keygen (for instance, with -R).- Version update to 8.1p1: * ssh-keygen(1): when acting as a CA and signing certificates with an RSA key, default to using the rsa-sha2-512 signature algorithm. Certificates signed by RSA keys will therefore be incompatible with OpenSSH versions prior to 7.2 unless the default is overridden (using "ssh-keygen -t ssh-rsa -s ..."). * ssh(1): Allow %n to be expanded in ProxyCommand strings * ssh(1), sshd(8): Allow prepending a list of algorithms to the default set by starting the list with the '^' character, E.g. "HostKeyAlgorithms ^ssh-ed25519" * ssh-keygen(1): add an experimental lightweight signature and verification ability. Signatures may be made using regular ssh keys held on disk or stored in a ssh-agent and verified against an authorized_keys-like list of allowed keys. Signatures embed a namespace that prevents confusion and attacks between different usage domains (e.g. files vs email). * ssh-keygen(1): print key comment when extracting public key from a private key. * ssh-keygen(1): accept the verbose flag when searching for host keys in known hosts (i.e. "ssh-keygen -vF host") to print the matching host's random-art signature too. * All: support PKCS8 as an optional format for storage of private keys to disk. The OpenSSH native key format remains the default, but PKCS8 is a superior format to PEM if interoperability with non-OpenSSH software is required, as it may use a less insecure key derivation function than PEM's. - Additional changes from 8.0p1 release: * scp(1): Add "-T" flag to disable client-side filtering of server file list. * sshd(8): Remove support for obsolete "host/port" syntax. * ssh(1), ssh-agent(1), ssh-add(1): Add support for ECDSA keys in PKCS#11 tokens. * ssh(1), sshd(8): Add experimental quantum-computing resistant key exchange method, based on a combination of Streamlined NTRU Prime 4591^761 and X25519. * ssh-keygen(1): Increase the default RSA key size to 3072 bits, following NIST Special Publication 800-57's guidance for a 128-bit equivalent symmetric security level. * ssh(1): Allow "PKCS11Provider=none" to override later instances of the PKCS11Provider directive in ssh_config, * sshd(8): Add a log message for situations where a connection is dropped for attempting to run a command but a sshd_config ForceCommand=internal-sftp restriction is in effect. * ssh(1): When prompting whether to record a new host key, accept the key fingerprint as a synonym for "yes". This allows the user to paste a fingerprint obtained out of band at the prompt and have the client do the comparison for you. * ssh-keygen(1): When signing multiple certificates on a single command-line invocation, allow automatically incrementing the certificate serial number. * scp(1), sftp(1): Accept -J option as an alias to ProxyJump on the scp and sftp command-lines. * ssh-agent(1), ssh-pkcs11-helper(8), ssh-add(1): Accept "-v" command-line flags to increase the verbosity of output; pass verbose flags though to subprocesses, such as ssh-pkcs11-helper started from ssh-agent. * ssh-add(1): Add a "-T" option to allowing testing whether keys in an agent are usable by performing a signature and a verification. * sftp-server(8): Add a "lsetstat@openssh.com" protocol extension that replicates the functionality of the existing SSH2_FXP_SETSTAT operation but does not follow symlinks. * sftp(1): Add "-h" flag to chown/chgrp/chmod commands to request they do not follow symlinks. * sshd(8): Expose $SSH_CONNECTION in the PAM environment. This makes the connection 4-tuple available to PAM modules that wish to use it in decision-making. * sshd(8): Add a ssh_config "Match final" predicate Matches in same pass as "Match canonical" but doesn't require hostname canonicalisation be enabled. * sftp(1): Support a prefix of '@' to suppress echo of sftp batch commands. * ssh-keygen(1): When printing certificate contents using "ssh-keygen -Lf /path/certificate", include the algorithm that the CA used to sign the cert. - Rebased patches: * openssh-7.7p1-IPv6_X_forwarding.patch * openssh-7.7p1-X_forward_with_disabled_ipv6.patch * openssh-7.7p1-cavstest-ctr.patch * openssh-7.7p1-cavstest-kdf.patch * openssh-7.7p1-disable_openssl_abi_check.patch * openssh-7.7p1-fips.patch * openssh-7.7p1-fips_checks.patch * openssh-7.7p1-hostname_changes_when_forwarding_X.patch * openssh-7.7p1-ldap.patch * openssh-7.7p1-seed-prng.patch * openssh-7.7p1-sftp_force_permissions.patch * openssh-7.7p1-sftp_print_diagnostic_messages.patch * openssh-8.0p1-gssapi-keyex.patch (formerly openssh-7.7p1-gssapi_key_exchange.patch) * openssh-8.1p1-audit.patch (formerly openssh-7.7p1-audit.patch) - Removed patches (integrated upstream): * 0001-upstream-Fix-two-race-conditions-in-sshd-relating-to.patch * openssh-7.7p1-seccomp_ioctl_s390_EP11.patch * openssh-7.9p1-CVE-2018-20685.patch * openssh-7.9p1-brace-expansion.patch * openssh-CVE-2019-6109-force-progressmeter-update.patch * openssh-CVE-2019-6109-sanitize-scp-filenames.patch * openssh-CVE-2019-6111-scp-client-wildcard.patch - Removed patches (obsolete): * openssh-openssl-1_0_0-compatibility.patch- don't install SuSEfirewall2 service on Factory, since SuSEfirewall2 has been replaced by firewalld, see [1]. [1]: https://lists.opensuse.org/opensuse-factory/2019-01/msg00490.html- ssh-askpass: Try a fallback if the other option is not available- Fix a crash with GSSAPI key exchange (bsc#1136104) * modify openssh-7.7p1-gssapi_key_exchange.patch- Fix a double free() in the KDF CAVS testing tool (bsc#1065237) * modify openssh-7.7p1-cavstest-kdf.patch- Minor clean-up of the fips patches, modified openssh-7.7p1-fips.patch openssh-7.7p1-fips_checks.patch- Fix two race conditions in sshd relating to SIGHUP (bsc#1119183) * 0001-upstream-Fix-two-race-conditions-in-sshd-relating-to.patch- Correctly filter out non-compliant algorithms when in FIPS mode (bsc#1126397) * A hunk was applied to a wrong place due to a patch fuzz when the fips patch was being ported to openssh 7.9p1 - update openssh-7.7p1-fips.patch- Remove the "KexDHMin" config keyword (bsc#1127180) It used to allow lowering of the minimal allowed DH group size, which was increased to 2048 by upstream in the light of the Logjam attack. The code was broken since the upgrade to 7.6p1, but nobody noticed. As apparently no one needs the functionality any more, let's drop the patch. It's still possible to use the fixed 1024-bit diffie-hellman-group1-sha1 key exchange method when working with legacy systems. - drop openssh-7.7p1-disable_short_DH_parameters.patch - updated patches: openssh-7.7p1-fips.patch openssh-7.7p1-fips_checks.patch openssh-7.7p1-gssapi_key_exchange.patch- Handle brace expansion in scp when checking that filenames sent by the server side match what the client requested [bsc#1125687] * openssh-7.9p1-brace-expansion.patch- Updated security fixes: * [bsc#1121816, CVE-2019-6109] Sanitize scp filenames via snmprintf and have progressmeter force an update at the beginning and end of each transfer. Added patches: - openssh-CVE-2019-6109-sanitize-scp-filenames.patch - openssh-CVE-2019-6109-force-progressmeter-update.patch * [bsc#1121821, CVE-2019-6111] Check in scp client that filenames sent during remote->local directory copies satisfy the wildcard specified by the user. Added patch: - openssh-CVE-2019-6111-scp-client-wildcard.patch * Removed openssh-7.9p1-scp-name-validator.patch- Change the askpass wrapper to not use x11 interface: * by default we use the -gnome UI (which is gtk3 only, no gnome dep) * if desktop is KDE/LxQt we use ksshaskpass- Remove old conditionals- Move ssh-ldap* man pages into openssh-helpers [bsc#1051531]- Allow root login by default [bsc#1118114, bsc#1121196] * Added/updated previous patch openssh-7.7p1-allow_root_password_login.patch * Mention the change in README.SUSE- Added SLE conditionals in the spec files: * Keep gtk2-devel in openssh-askpass-gnome in SLE * Keep krb5-mini-devel in SLE - Removed obsolete configure options: * SSH protocol 1 --with-ssh1 * Smart card --with-opensc - Cleaned spec file with spec-cleaner- Security fix: * [bsc#1121816, CVE-2019-6109] scp client spoofing via object name * [bsc#1121818, CVE-2019-6110] scp client spoofing via stderr * [bsc#1121821, CVE-2019-6111] scp client missing received object name validation * Added patch openssh-7.9p1-scp-name-validator.patch- Security fix: [bsc#1121571, CVE-2018-20685] * The scp client allows remote SSH servers to bypass intended access restrictions * Added patch openssh-7.9p1-CVE-2018-20685.patch- Added compatibility with SuSEfirewall2 [bsc#1118044]- Update the firewall rules in Tumbleweed- Fix build with openssl < 1.1.0 * add openssh-openssl-1_0_0-compatibility.patch- openssh-7.7p1-audit.patch: fix sshd fatal error in mm_answer_keyverify: buffer error: incomplete message [bnc#1114008]- Version update to 7.9p1 * ssh(1), sshd(8): the setting of the new CASignatureAlgorithms option (see below) bans the use of DSA keys as certificate authorities. * sshd(8): the authentication success/failure log message has changed format slightly. It now includes the certificate fingerprint (previously it included only key ID and CA key fingerprint). * ssh(1), sshd(8): allow most port numbers to be specified using service names from getservbyname(3) (typically /etc/services). * sshd(8): support signalling sessions via the SSH protocol. A limited subset of signals is supported and only for login or command sessions (i.e. not subsystems) that were not subject to a forced command via authorized_keys or sshd_config. bz#1424 * ssh(1): support "ssh -Q sig" to list supported signature options. Also "ssh -Q help" to show the full set of supported queries. * ssh(1), sshd(8): add a CASignatureAlgorithms option for the client and server configs to allow control over which signature formats are allowed for CAs to sign certificates. For example, this allows banning CAs that sign certificates using the RSA-SHA1 signature algorithm. * sshd(8), ssh-keygen(1): allow key revocation lists (KRLs) to revoke keys specified by SHA256 hash. * ssh-keygen(1): allow creation of key revocation lists directly from base64-encoded SHA256 fingerprints. This supports revoking keys using only the information contained in sshd(8) authentication log messages. - Removed obsolete configuration option --with-tcp-wrappers, and - -with-opensc for s390 and s390x. - Removed patch merged upstream * openssh-7.7p1-openssl_1.1.0.patch - Refreshed patches * openssh-7.7p1-audit.patch * openssh-7.7p1-disable_short_DH_parameters.patch * openssh-7.7p1-fips.patch * openssh-7.7p1-gssapi_key_exchange.patch * openssh-7.7p1-seccomp_ipc_flock.patch * openssh-7.7p1-cavstest-ctr.patch * openssh-7.7p1-ldap.patch- Mention upstream bugs on multiple local patches - Adjust service to not spam restart and reload only on fails- Update openssh-7.7p1-sftp_force_permissions.patch from the upstream bug, and mention the bug in the spec- Drop patch openssh-7.7p1-allow_root_password_login.patch * There is no reason to set less secure default value, if users need the behaviour they can still set it up themselves - Drop patch openssh-7.7p1-blocksigalrm.patch * We had a bug way in past about this but it was never reproduced or even confirmed in the ticket, thus rather drop the patch- Disable ssh1 protocol support as neither RH or Debian enable this protocol by default anymore either.- Remove the mention of the SLE12 in the README.SUSE - Install firewall rules only when really needed ( ::1) before they are matched against known_hosts. bz#2763 * ssh(1): Don't accept junk after "yes" or "no" responses to hostkey prompts. bz#2803 * sftp(1): Have sftp print a warning about shell cleanliness when decoding the first packet fails, which is usually caused by shells polluting stdout of non-interactive startups. bz#2800 * ssh(1)/sshd(8): Switch timers in packet code from using wall-clock time to monotonic time, allowing the packet layer to better function over a clock step and avoiding possible integer overflows during steps. * Numerous manual page fixes and improvements.- Use TIRPC on suse_version >= 1500: sunrpc is deprecated and should be replaced by TIRPC.- additional rebased patches (bsc#1080779) * auditing support * LDAP integration * various distribution tweaks from SLE12 (X forwarding over IPv6, sftp forced permissions and verbose batch mode)- Use %license instead of %doc [bsc#1082318]- add OpenSSL 1.0 to 1.1 shim to remove dependency on old OpenSSL (update tracker: bsc#1080779)- Add missing crypto hardware enablement patches for IBM mainframes (FATE#323902)- add missing part of systemd integration (unit type)- BuildRequire pkgconfig(libsystemd) instead of systemd-devel: allow the scheduler to pick systemd-mini flavors to get build going.- Replace forgotten references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468) - tighten configuration access rights- Update to vanilla 7.6p1 Most important changes (more details below): * complete removal of the ancient SSHv1 protocol * sshd(8) cannot run without privilege separation * removal of suport for arcfourm blowfish and CAST ciphers and RIPE-MD160 HMAC * refuse RSA keys shorter than 1024 bits Distilled upstream log: - OpenSSH 7.3 - --- Security * sshd(8): Mitigate a potential denial-of-service attack against the system's crypt(3) function via sshd(8). An attacker could send very long passwords that would cause excessive CPU use in crypt(3). sshd(8) now refuses to accept password authentication requests of length greater than 1024 characters. Independently reported by Tomas Kuthan (Oracle), Andres Rojas and Javier Nieto. * sshd(8): Mitigate timing differences in password authentication that could be used to discern valid from invalid account names when long passwords were sent and particular password hashing algorithms are in use on the server. CVE-2016-6210, reported by EddieEzra.Harari at verint.com * ssh(1), sshd(8): Fix observable timing weakness in the CBC padding oracle countermeasures. Reported by Jean Paul Degabriele, Kenny Paterson, Torben Hansen and Martin Albrecht. Note that CBC ciphers are disabled by default and only included for legacy compatibility. * ssh(1), sshd(8): Improve operation ordering of MAC verification for Encrypt-then-MAC (EtM) mode transport MAC algorithms to verify the MAC before decrypting any ciphertext. This removes the possibility of timing differences leaking facts about the plaintext, though no such leakage has been observed. Reported by Jean Paul Degabriele, Kenny Paterson, Torben Hansen and Martin Albrecht. * sshd(8): (portable only) Ignore PAM environment vars when UseLogin=yes. If PAM is configured to read user-specified environment variables and UseLogin=yes in sshd_config, then a hostile local user may attack /bin/login via LD_PRELOAD or similar environment variables set via PAM. CVE-2015-8325, found by Shayan Sadigh. - --- New Features * ssh(1): Add a ProxyJump option and corresponding -J command-line flag to allow simplified indirection through a one or more SSH bastions or "jump hosts". * ssh(1): Add an IdentityAgent option to allow specifying specific agent sockets instead of accepting one from the environment. * ssh(1): Allow ExitOnForwardFailure and ClearAllForwardings to be optionally overridden when using ssh -W. bz#2577 * ssh(1), sshd(8): Implement support for the IUTF8 terminal mode as per draft-sgtatham-secsh-iutf8-00. * ssh(1), sshd(8): Add support for additional fixed Diffie-Hellman 2K, 4K and 8K groups from draft-ietf-curdle-ssh-kex-sha2-03. * ssh-keygen(1), ssh(1), sshd(8): support SHA256 and SHA512 RSA signatures in certificates; * ssh(1): Add an Include directive for ssh_config(5) files. * ssh(1): Permit UTF-8 characters in pre-authentication banners sent from the server. bz#2058 - --- Bugfixes * ssh(1), sshd(8): Reduce the syslog level of some relatively common protocol events from LOG_CRIT. bz#2585 * sshd(8): Refuse AuthenticationMethods="" in configurations and accept AuthenticationMethods=any for the default behaviour of not requiring multiple authentication. bz#2398 * sshd(8): Remove obsolete and misleading "POSSIBLE BREAK-IN ATTEMPT!" message when forward and reverse DNS don't match. bz#2585 * ssh(1): Close ControlPersist background process stderr except in debug mode or when logging to syslog. bz#1988 * misc: Make PROTOCOL description for direct-streamlocal@openssh.com channel open messages match deployed code. bz#2529 * ssh(1): Deduplicate LocalForward and RemoteForward entries to fix failures when both ExitOnForwardFailure and hostname canonicalisation are enabled. bz#2562 * sshd(8): Remove fallback from moduli to obsolete "primes" file that was deprecated in 2001. bz#2559. * sshd_config(5): Correct description of UseDNS: it affects ssh hostname processing for authorized_keys, not known_hosts; bz#2554 * ssh(1): Fix authentication using lone certificate keys in an agent without corresponding private keys on the filesystem. bz#2550 * sshd(8): Send ClientAliveInterval pings when a time-based RekeyLimit is set; previously keepalive packets were not being sent. bz#2252 - --- Portability * ssh(1), sshd(8): Fix compilation by automatically disabling ciphers not supported by OpenSSL. bz#2466 * misc: Fix compilation failures on some versions of AIX's compiler related to the definition of the VA_COPY macro. bz#2589 * sshd(8): Whitelist more architectures to enable the seccomp-bpf sandbox. bz#2590 * ssh-agent(1), sftp-server(8): Disable process tracing on Solaris using setpflags(__PROC_PROTECT, ...). bz#2584 * sshd(8): On Solaris, don't call Solaris setproject() with UsePAM=yes it's PAM's responsibility. bz#2425 - OpenSSH 7.4 - --- Potentially-incompatible changes * ssh(1): Remove 3des-cbc from the client's default proposal. 64-bit block ciphers are not safe in 2016 and we don't want to wait until attacks like SWEET32 are extended to SSH. As 3des-cbc was the only mandatory cipher in the SSH RFCs, this may cause problems connecting to older devices using the default configuration, but it's highly likely that such devices already need explicit configuration for key exchange and hostkey algorithms already anyway. * sshd(8): Remove support for pre-authentication compression. Doing compression early in the protocol probably seemed reasonable in the 1990s, but today it's clearly a bad idea in terms of both cryptography (cf. multiple compression oracle attacks in TLS) and attack surface. Pre-auth compression support has been disabled by default for >10 years. Support remains in the client. * ssh-agent will refuse to load PKCS#11 modules outside a whitelist of trusted paths by default. The path whitelist may be specified at run-time. * sshd(8): When a forced-command appears in both a certificate and an authorized keys/principals command= restriction, sshd will now refuse to accept the certificate unless they are identical. The previous (documented) behaviour of having the certificate forced-command override the other could be a bit confusing and error-prone. * sshd(8): Remove the UseLogin configuration directive and support for having /bin/login manage login sessions. - --- Security * ssh-agent(1): Will now refuse to load PKCS#11 modules from paths outside a trusted whitelist (run-time configurable). Requests to load modules could be passed via agent forwarding and an attacker could attempt to load a hostile PKCS#11 module across the forwarded agent channel: PKCS#11 modules are shared libraries, so this would result in code execution on the system running the ssh-agent if the attacker has control of the forwarded agent-socket (on the host running the sshd server) and the ability to write to the filesystem of the host running ssh-agent (usually the host running the ssh client). Reported by Jann Horn of Project Zero. * sshd(8): When privilege separation is disabled, forwarded Unix- domain sockets would be created by sshd(8) with the privileges of 'root' instead of the authenticated user. This release refuses Unix-domain socket forwarding when privilege separation is disabled (Privilege separation has been enabled by default for 14 years). Reported by Jann Horn of Project Zero. * sshd(8): Avoid theoretical leak of host private key material to privilege-separated child processes via realloc() when reading keys. No such leak was observed in practice for normal-sized keys, nor does a leak to the child processes directly expose key material to unprivileged users. Reported by Jann Horn of Project Zero. * sshd(8): The shared memory manager used by pre-authentication compression support had a bounds checks that could be elided by some optimising compilers. Additionally, this memory manager was incorrectly accessible when pre-authentication compression was disabled. This could potentially allow attacks against the privileged monitor process from the sandboxed privilege-separation process (a compromise of the latter would be required first). This release removes support for pre-authentication compression from sshd(8). Reported by Guido Vranken using the Stack unstable optimisation identification tool (http://css.csail.mit.edu/stack/) * sshd(8): Fix denial-of-service condition where an attacker who sends multiple KEXINIT messages may consume up to 128MB per connection. Reported by Shi Lei of Gear Team, Qihoo 360. * sshd(8): Validate address ranges for AllowUser and DenyUsers directives at configuration load time and refuse to accept invalid ones. It was previously possible to specify invalid CIDR address ranges (e.g. user@127.1.2.3/55) and these would always match, possibly resulting in granting access where it was not intended. Reported by Laurence Parry. - --- New Features * ssh(1): Add a proxy multiplexing mode to ssh(1) inspired by the version in PuTTY by Simon Tatham. This allows a multiplexing client to communicate with the master process using a subset of the SSH packet and channels protocol over a Unix-domain socket, with the main process acting as a proxy that translates channel IDs, etc. This allows multiplexing mode to run on systems that lack file- descriptor passing (used by current multiplexing code) and potentially, in conjunction with Unix-domain socket forwarding, with the client and multiplexing master process on different machines. Multiplexing proxy mode may be invoked using "ssh -O proxy ..." * sshd(8): Add a sshd_config DisableForwarding option that disables X11, agent, TCP, tunnel and Unix domain socket forwarding, as well as anything else we might implement in the future. Like the 'restrict' authorized_keys flag, this is intended to be a simple and future-proof way of restricting an account. * sshd(8), ssh(1): Support the "curve25519-sha256" key exchange method. This is identical to the currently-supported method named "curve25519-sha256@libssh.org". * sshd(8): Improve handling of SIGHUP by checking to see if sshd is already daemonised at startup and skipping the call to daemon(3) if it is. This ensures that a SIGHUP restart of sshd(8) will retain the same process-ID as the initial execution. sshd(8) will also now unlink the PidFile prior to SIGHUP restart and re-create it after a successful restart, rather than leaving a stale file in the case of a configuration error. bz#2641 * sshd(8): Allow ClientAliveInterval and ClientAliveCountMax directives to appear in sshd_config Match blocks. * sshd(8): Add %-escapes to AuthorizedPrincipalsCommand to match those supported by AuthorizedKeysCommand (key, key type, fingerprint, etc.) and a few more to provide access to the contents of the certificate being offered. * Added regression tests for string matching, address matching and string sanitisation functions. * Improved the key exchange fuzzer harness. - --- Bugfixes * ssh(1): Allow IdentityFile to successfully load and use certificates that have no corresponding bare public key. bz#2617 certificate id_rsa-cert.pub (and no id_rsa.pub). * ssh(1): Fix public key authentication when multiple authentication is in use and publickey is not just the first method attempted. bz#2642 * regress: Allow the PuTTY interop tests to run unattended. bz#2639 * ssh-agent(1), ssh(1): improve reporting when attempting to load keys from PKCS#11 tokens with fewer useless log messages and more detail in debug messages. bz#2610 * ssh(1): When tearing down ControlMaster connections, don't pollute stderr when LogLevel=quiet. * sftp(1): On ^Z wait for underlying ssh(1) to suspend before suspending sftp(1) to ensure that ssh(1) restores the terminal mode correctly if suspended during a password prompt. * ssh(1): Avoid busy-wait when ssh(1) is suspended during a password prompt. * ssh(1), sshd(8): Correctly report errors during sending of ext- info messages. * sshd(8): fix NULL-deref crash if sshd(8) received an out-of- sequence NEWKEYS message. * sshd(8): Correct list of supported signature algorithms sent in the server-sig-algs extension. bz#2547 * sshd(8): Fix sending ext_info message if privsep is disabled. * sshd(8): more strictly enforce the expected ordering of privilege separation monitor calls used for authentication and allow them only when their respective authentication methods are enabled in the configuration * sshd(8): Fix uninitialised optlen in getsockopt() call; harmless on Unix/BSD but potentially crashy on Cygwin. * Fix false positive reports caused by explicit_bzero(3) not being recognised as a memory initialiser when compiled with - fsanitize-memory. * sshd_config(5): Use 2001:db8::/32, the official IPv6 subnet for configuration examples. - --- Portability * On environments configured with Turkish locales, fall back to the C/POSIX locale to avoid errors in configuration parsing caused by that locale's unique handling of the letters 'i' and 'I'. bz#2643 * sftp-server(8), ssh-agent(1): Deny ptrace on OS X using ptrace(PT_DENY_ATTACH, ..) * ssh(1), sshd(8): Unbreak AES-CTR ciphers on old (~0.9.8) OpenSSL. * Fix compilation for libcrypto compiled without RIPEMD160 support. * contrib: Add a gnome-ssh-askpass3 with GTK+3 support. bz#2640 * sshd(8): Improve PRNG reseeding across privilege separation and force libcrypto to obtain a high-quality seed before chroot or sandboxing. * All: Explicitly test for broken strnvis. NetBSD added an strnvis and unfortunately made it incompatible with the existing one in OpenBSD and Linux's libbsd (the former having existed for over ten years). Try to detect this mess, and assume the only safe option if we're cross compiling. - OpenSSH 7.5 - --- Potentially-incompatible changes * This release deprecates the sshd_config UsePrivilegeSeparation option, thereby making privilege separation mandatory. Privilege separation has been on by default for almost 15 years and sandboxing has been on by default for almost the last five. * The format of several log messages emitted by the packet code has changed to include additional information about the user and their authentication state. Software that monitors ssh/sshd logs may need to account for these changes. For example: Connection closed by user x 1.1.1.1 port 1234 [preauth] Connection closed by authenticating user x 10.1.1.1 port 1234 [preauth] Connection closed by invalid user x 1.1.1.1 port 1234 [preauth] Affected messages include connection closure, timeout, remote disconnection, negotiation failure and some other fatal messages generated by the packet code. * [Portable OpenSSH only] This version removes support for building against OpenSSL versions prior to 1.0.1. OpenSSL stopped supporting versions prior to 1.0.1 over 12 months ago (i.e. they no longer receive fixes for security bugs). - --- Security * ssh(1), sshd(8): Fix weakness in CBC padding oracle countermeasures that allowed a variant of the attack fixed in OpenSSH 7.3 to proceed. Note that the OpenSSH client disables CBC ciphers by default, sshd offers them as lowest-preference options and will remove them by default entriely in the next release. Reported by Jean Paul Degabriele, Kenny Paterson, Martin Albrecht and Torben Hansen of Royal Holloway, University of London. * sftp-client(1): [portable OpenSSH only] On Cygwin, a client making a recursive file transfer could be maniuplated by a hostile server to perform a path-traversal attack. creating or modifying files outside of the intended target directory. Reported by Jann Horn of Google Project Zero. - --- New Features * ssh(1), sshd(8): Support "=-" syntax to easily remove methods from algorithm lists, e.g. Ciphers=-*cbc. bz#2671 - --- Bugfixes * sshd(1): Fix NULL dereference crash when key exchange start messages are sent out of sequence. * ssh(1), sshd(8): Allow form-feed characters to appear in configuration files. * sshd(8): Fix regression in OpenSSH 7.4 support for the server-sig-algs extension, where SHA2 RSA signature methods were not being correctly advertised. bz#2680 * ssh(1), ssh-keygen(1): Fix a number of case-sensitivity bugs in known_hosts processing. bz#2591 bz#2685 * ssh(1): Allow ssh to use certificates accompanied by a private key file but no corresponding plain *.pub public key. bz#2617 * ssh(1): When updating hostkeys using the UpdateHostKeys option, accept RSA keys if HostkeyAlgorithms contains any RSA keytype. Previously, ssh could ignore RSA keys when only the ssh-rsa-sha2-* methods were enabled in HostkeyAlgorithms and not the old ssh-rsa method. bz#2650 * ssh(1): Detect and report excessively long configuration file lines. bz#2651 * Merge a number of fixes found by Coverity and reported via Redhat and FreeBSD. Includes fixes for some memory and file descriptor leaks in error paths. bz#2687 * ssh-keyscan(1): Correctly hash hosts with a port number. bz#2692 * ssh(1), sshd(8): When logging long messages to stderr, don't truncate "\r\n" if the length of the message exceeds the buffer. bz#2688 * ssh(1): Fully quote [host]:port in generated ProxyJump/-J command- line; avoid confusion over IPv6 addresses and shells that treat square bracket characters specially. * ssh-keygen(1): Fix corruption of known_hosts when running "ssh-keygen -H" on a known_hosts containing already-hashed entries. * Fix various fallout and sharp edges caused by removing SSH protocol 1 support from the server, including the server banner string being incorrectly terminated with only \n (instead of \r\n), confusing error messages from ssh-keyscan bz#2583 and a segfault in sshd if protocol v.1 was enabled for the client and sshd_config contained references to legacy keys bz#2686. * ssh(1), sshd(8): Free fd_set on connection timeout. bz#2683 * sshd(8): Fix Unix domain socket forwarding for root (regression in OpenSSH 7.4). * sftp(1): Fix division by zero crash in "df" output when server returns zero total filesystem blocks/inodes. * ssh(1), ssh-add(1), ssh-keygen(1), sshd(8): Translate OpenSSL errors encountered during key loading to more meaningful error codes. bz#2522 bz#2523 * ssh-keygen(1): Sanitise escape sequences in key comments sent to printf but preserve valid UTF-8 when the locale supports it; bz#2520 * ssh(1), sshd(8): Return reason for port forwarding failures where feasible rather than always "administratively prohibited". bz#2674 * sshd(8): Fix deadlock when AuthorizedKeysCommand or AuthorizedPrincipalsCommand produces a lot of output and a key is matched early. bz#2655 * Regression tests: several reliability fixes. bz#2654 bz#2658 bz#2659 * ssh(1): Fix typo in ~C error message for bad port forward cancellation. bz#2672 * ssh(1): Show a useful error message when included config files can't be opened; bz#2653 * sshd(8): Make sshd set GSSAPIStrictAcceptorCheck=yes as the manual page (previously incorrectly) advertised. bz#2637 * sshd_config(5): Repair accidentally-deleted mention of %k token in AuthorizedKeysCommand; bz#2656 * sshd(8): Remove vestiges of previously removed LOGIN_PROGRAM; bz#2665 * ssh-agent(1): Relax PKCS#11 whitelist to include libexec and common 32-bit compatibility library directories. * sftp-client(1): Fix non-exploitable integer overflow in SSH2_FXP_NAME response handling. * ssh-agent(1): Fix regression in 7.4 of deleting PKCS#11-hosted keys. It was not possible to delete them except by specifying their full physical path. bz#2682 - --- Portability * sshd(8): Avoid sandbox errors for Linux S390 systems using an ICA crypto coprocessor. * sshd(8): Fix non-exploitable weakness in seccomp-bpf sandbox arg inspection. * ssh(1): Fix X11 forwarding on OSX where X11 was being started by launchd. bz#2341 * ssh-keygen(1), ssh(1), sftp(1): Fix output truncation for various that contain non-printable characters where the codeset in use is ASCII. * build: Fix builds that attempt to link a kerberised libldns. bz#2603 * build: Fix compilation problems caused by unconditionally defining _XOPEN_SOURCE in wide character detection. * sshd(8): Fix sandbox violations for clock_gettime VSDO syscall fallback on some Linux/X32 kernels. bz#2142 - OpenSSH 7.6 - --- Potentially-incompatible changes This release includes a number of changes that may affect existing configurations: * ssh(1): delete SSH protocol version 1 support, associated configuration options and documentation. * ssh(1)/sshd(8): remove support for the hmac-ripemd160 MAC. * ssh(1)/sshd(8): remove support for the arcfour, blowfish and CAST ciphers. * Refuse RSA keys <1024 bits in length and improve reporting for keys that do not meet this requirement. * ssh(1): do not offer CBC ciphers by default. - --- Security * sftp-server(8): in read-only mode, sftp-server was incorrectly permitting creation of zero-length files. Reported by Michal Zalewski. - --- New Features * ssh(1): add RemoteCommand option to specify a command in the ssh config file instead of giving it on the client's command line. This allows the configuration file to specify the command that will be executed on the remote host. * sshd(8): add ExposeAuthInfo option that enables writing details of the authentication methods used (including public keys where applicable) to a file that is exposed via a $SSH_USER_AUTH environment variable in the subsequent session. * ssh(1): add support for reverse dynamic forwarding. In this mode, ssh will act as a SOCKS4/5 proxy and forward connections to destinations requested by the remote SOCKS client. This mode is requested using extended syntax for the - R and RemoteForward options and, because it is implemented solely at the client, does not require the server be updated to be supported. * sshd(8): allow LogLevel directive in sshd_config Match blocks; bz#2717 * ssh-keygen(1): allow inclusion of arbitrary string or flag certificate extensions and critical options. * ssh-keygen(1): allow ssh-keygen to use a key held in ssh-agent as a CA when signing certificates. bz#2377 * ssh(1)/sshd(8): allow IPQoS=none in ssh/sshd to not set an explicit ToS/DSCP value and just use the operating system default. * ssh-add(1): added -q option to make ssh-add quiet on success. * ssh(1): expand the StrictHostKeyChecking option with two new settings. The first "accept-new" will automatically accept hitherto-unseen keys but will refuse connections for changed or invalid hostkeys. This is a safer subset of the current behaviour of StrictHostKeyChecking=no. The second setting "off", is a synonym for the current behaviour of StrictHostKeyChecking=no: accept new host keys, and continue connection for hosts with incorrect hostkeys. A future release will change the meaning of StrictHostKeyChecking=no to the behaviour of "accept-new". bz#2400 * ssh(1): add SyslogFacility option to ssh(1) matching the equivalent option in sshd(8). bz#2705 - --- Bugfixes * ssh(1): use HostKeyAlias if specified instead of hostname for matching host certificate principal names; bz#2728 * sftp(1): implement sorting for globbed ls; bz#2649 * ssh(1): add a user@host prefix to client's "Permission denied" messages, useful in particular when using "stacked" connections (e.g. ssh -J) where it's not clear which host is denying. bz#2720 * ssh(1): accept unknown EXT_INFO extension values that contain \0 characters. These are legal, but would previously cause fatal connection errors if received. * ssh(1)/sshd(8): repair compression statistics printed at connection exit * sftp(1): print '?' instead of incorrect link count (that the protocol doesn't provide) for remote listings. bz#2710 * ssh(1): return failure rather than fatal() for more cases during session multiplexing negotiations. Causes the session to fall back to a non-mux connection if they occur. bz#2707 * ssh(1): mention that the server may send debug messages to explain public key authentication problems under some circumstances; bz#2709 * Translate OpenSSL error codes to better report incorrect passphrase errors when loading private keys; bz#2699 * sshd(8): adjust compatibility patterns for WinSCP to correctly identify versions that implement only the legacy DH group exchange scheme. bz#2748 * ssh(1): print the "Killed by signal 1" message only at LogLevel verbose so that it is not shown at the default level; prevents it from appearing during ssh -J and equivalent ProxyCommand configs. bz#1906, bz#2744 * ssh-keygen(1): when generating all hostkeys (ssh-keygen -A), clobber existing keys if they exist but are zero length. zero-length keys could previously be made if ssh-keygen failed or was interrupted part way through generating them. bz#2561 * ssh(1): fix pledge(2) violation in the escape sequence "~&" used to place the current session in the background. * ssh-keyscan(1): avoid double-close() on file descriptors; bz#2734 * sshd(8): avoid reliance on shared use of pointers shared between monitor and child sshd processes. bz#2704 * sshd_config(8): document available AuthenticationMethods; bz#2453 * ssh(1): avoid truncation in some login prompts; bz#2768 * sshd(8): Fix various compilations failures, inc bz#2767 * ssh(1): make "--" before the hostname terminate argument processing after the hostname too. * ssh-keygen(1): switch from aes256-cbc to aes256-ctr for encrypting new-style private keys. Fixes problems related to private key handling for no-OpenSSL builds. bz#2754 * ssh(1): warn and do not attempt to use keys when the public and private halves do not match. bz#2737 * sftp(1): don't print verbose error message when ssh disconnects from under sftp. bz#2750 * sshd(8): fix keepalive scheduling problem: activity on a forwarded port from preventing the keepalive from being sent; bz#2756 * sshd(8): when started without root privileges, don't require the privilege separation user or path to exist. Makes running the regression tests easier without touching the filesystem. * Make integrity.sh regression tests more robust against timeouts. bz#2658 * ssh(1)/sshd(8): correctness fix for channels implementation: accept channel IDs greater than 0x7FFFFFFF. - --- Portability * sshd(9): drop two more privileges in the Solaris sandbox: PRIV_DAX_ACCESS and PRIV_SYS_IB_INFO; bz#2723 * sshd(8): expose list of completed authentication methods to PAM via the SSH_AUTH_INFO_0 PAM environment variable. bz#2408 * ssh(1)/sshd(8): fix several problems in the tun/tap forwarding code, mostly to do with host/network byte order confusion. bz#2735 * Add --with-cflags-after and --with-ldflags-after configure flags to allow setting CFLAGS/LDFLAGS after configure has completed. These are useful for setting sanitiser/fuzzing options that may interfere with configure's operation. * sshd(8): avoid Linux seccomp violations on ppc64le over the socketcall syscall. * Fix use of ldns when using ldns-config; bz#2697 * configure: set cache variables when cross-compiling. The cross- compiling fallback message was saying it assumed the test passed, but it wasn't actually set the cache variables and this would cause later tests to fail. * Add clang libFuzzer harnesses for public key parsing and signature verification. - packaging: * moving patches into a separate archive * first round of rebased patches: [-X11_trusted_forwarding] [-allow_root_password_login] [-blocksigalrm] [-cavstest-ctr] [-cavstest-kdf] [-disable_short_DH_parameters] [-eal3] [-enable_PAM_by_default] [-fips] [-fips_checks] [-gssapi_key_exchange] [-hostname_changes_when_forwarding_X] [-lastlog] [-missing_headers] [-pam_check_locks] [-pts_names_formatting] [-remove_xauth_cookies_on_exit] [-seccomp_geteuid] [-seccomp_getuid] [-seccomp_stat] [-seed-prng] [-send_locale] [-systemd-notify] * not rebased (obsoleted) patches (so far): [-additional_seccomp_archs] [-allow_DSS_by_default] [-default_protocol] [-dont_use_pthreads_in_PAM] [-eal3_obsolete] [-gssapimitm] [-saveargv-fix] * obviously removing all standalone patch files: [openssh-7.2p2-allow_root_password_login.patch] [openssh-7.2p2-allow_DSS_by_default.patch] [openssh-7.2p2-X11_trusted_forwarding.patch] [openssh-7.2p2-lastlog.patch] [openssh-7.2p2-enable_PAM_by_default.patch] [openssh-7.2p2-dont_use_pthreads_in_PAM.patch] [openssh-7.2p2-eal3.patch] [openssh-7.2p2-blocksigalrm.patch] [openssh-7.2p2-send_locale.patch] [openssh-7.2p2-hostname_changes_when_forwarding_X.patch] [openssh-7.2p2-remove_xauth_cookies_on_exit.patch] [openssh-7.2p2-pts_names_formatting.patch] [openssh-7.2p2-pam_check_locks.patch] [openssh-7.2p2-disable_short_DH_parameters.patch] [openssh-7.2p2-seccomp_getuid.patch] [openssh-7.2p2-seccomp_geteuid.patch] [openssh-7.2p2-seccomp_stat.patch] [openssh-7.2p2-additional_seccomp_archs.patch] [openssh-7.2p2-fips.patch] [openssh-7.2p2-cavstest-ctr.patch] [openssh-7.2p2-cavstest-kdf.patch] [openssh-7.2p2-seed-prng.patch] [openssh-7.2p2-gssapi_key_exchange.patch] [openssh-7.2p2-audit.patch] [openssh-7.2p2-audit_fixes.patch] [openssh-7.2p2-audit_seed_prng.patch] [openssh-7.2p2-login_options.patch] [openssh-7.2p2-disable_openssl_abi_check.patch] [openssh-7.2p2-no_fork-no_pid_file.patch] [openssh-7.2p2-host_ident.patch] [openssh-7.2p2-sftp_homechroot.patch] [openssh-7.2p2-sftp_force_permissions.patch] [openssh-7.2p2-X_forward_with_disabled_ipv6.patch] [openssh-7.2p2-ldap.patch] [openssh-7.2p2-IPv6_X_forwarding.patch] [openssh-7.2p2-ignore_PAM_with_UseLogin.patch] [openssh-7.2p2-prevent_timing_user_enumeration.patch] [openssh-7.2p2-limit_password_length.patch] [openssh-7.2p2-keep_slogin.patch] [openssh-7.2p2-kex_resource_depletion.patch] [openssh-7.2p2-verify_CIDR_address_ranges.patch] [openssh-7.2p2-restrict_pkcs11-modules.patch] [openssh-7.2p2-prevent_private_key_leakage.patch] [openssh-7.2p2-secure_unix_sockets_forwarding.patch] [openssh-7.2p2-ssh_case_insensitive_host_matching.patch] [openssh-7.2p2-disable_preauth_compression.patch] [openssh-7.2p2-s390_hw_crypto_syscalls.patch] [openssh-7.2p2-s390_OpenSSL-ibmpkcs11_syscalls.patch]- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)- sshd_config is has now permissions 0600 in secure mode- Fix preauth seccomp separation on mainframes (bsc#1016709) [openssh-7.2p2-s390_hw_crypto_syscalls.patch] [openssh-7.2p2-s390_OpenSSL-ibmpkcs11_syscalls.patch] - enable case-insensitive hostname matching (bsc#1017099) [openssh-7.2p2-ssh_case_insensitive_host_matching.patch] - add CAVS tests [openssh-7.2p2-cavstest-ctr.patch] [openssh-7.2p2-cavstest-kdf.patch] - Adding missing pieces for user matching (bsc#1021626) - Properly verify CIDR masks in configuration (bsc#1005893) [openssh-7.2p2-verify_CIDR_address_ranges.patch] - Remove pre-auth compression support from the server to prevent possible cryptographic attacks. (CVE-2016-10012, bsc#1016370) [openssh-7.2p2-disable_preauth_compression.patch] - limit directories for loading PKCS11 modules (CVE-2016-10009, bsc#1016366) [openssh-7.2p2-restrict_pkcs11-modules.patch] - Prevent possible leaks of host private keys to low-privilege process handling authentication (CVE-2016-10011, bsc#1016369) [openssh-7.2p2-prevent_private_key_leakage.patch] - Do not allow unix socket forwarding when running without privilege separation (CVE-2016-10010, bsc#1016368) [openssh-7.2p2-secure_unix_sockets_forwarding.patch] - prevent resource depletion during key exchange (bsc#1005480, CVE-2016-8858) [openssh-7.2p2-kex_resource_depletion.patch] - fix suggested command for removing conflicting server keys from the known_hosts file (bsc#1006221) - enable geteuid{,32} syscalls on mainframes, since it may be called from libica/ibmica on machines with hardware crypto accelerator (bsc#1004258) [openssh-7.2p2-seccomp_geteuid.patch] - fix regression of (bsc#823710) [openssh-7.2p2-audit_fixes.patch] - add slogin (removed upstreams) [openssh-7.2p2-keep_slogin.patch] - require OpenSSL < 1.1 where that one is a default- sshd.service: Set TasksMax=infinity, as there should be no limit on the amount of tasks sshd can run.- remaining patches that were still missing since the update to 7.2p2 (FATE#319675): - allow X forwarding over IPv4 when IPv6 sockets is not available [openssh-7.2p2-X_forward_with_disabled_ipv6.patch] - do not write PID file when not daemonizing [openssh-7.2p2-no_fork-no_pid_file.patch] - use correct options when invoking login [openssh-7.2p2-login_options.patch] - helper application for retrieving users' public keys from an LDAP server [openssh-7.2p2-ldap.patch] - allow forcing permissions over sftp [openssh-7.2p2-sftp_force_permissions.patch] - do not perform run-time checks for OpenSSL API/ABI change [openssh-7.2p2-disable_openssl_abi_check.patch] - suggest commands for cleaning known hosts file [openssh-7.2p2-host_ident.patch] - sftp home chroot patch [openssh-7.2p2-sftp_homechroot.patch] - ssh sessions auditing [openssh-7.2p2-audit.patch] - enable seccomp sandbox on additional architectures [openssh-7.2p2-additional_seccomp_archs.patch] - fix forwarding with IPv6 addresses in DISPLAY (bnc#847710) [openssh-7.2p2-IPv6_X_forwarding.patch] - ignore PAM environment when using login (bsc#975865, CVE-2015-8325) [openssh-7.2p2-ignore_PAM_with_UseLogin.patch] - limit accepted password length (prevents possible DoS) (bsc#992533, CVE-2016-6515) [openssh-7.2p2-limit_password_length.patch] - Prevent user enumeration through the timing of password processing (bsc#989363, CVE-2016-6210) [openssh-7.2p2-prevent_timing_user_enumeration.patch] - Add auditing for PRNG re-seeding [openssh-7.2p2-audit_seed_prng.patch]- FIPS compatibility (no selfchecks, only crypto restrictions) [openssh-7.2p2-fips.patch] - PRNG re-seeding [openssh-7.2p2-seed-prng.patch] - preliminary version of GSSAPI KEX [openssh-7.2p2-gssapi_key_exchange.patch]- added gpg signature- enable support for SSHv1 protocol and discourage its usage (bsc#983307) - enable DSA by default for backward compatibility and discourage its usage (bsc#983784) [openssh-7.2p2-allow_DSS_by_default.patch]- enable trusted X11 forwarding by default [openssh-7.2p2-X11_trusted_forwarding.patch] - set UID for lastlog properly [openssh-7.2p2-lastlog.patch] - enable use of PAM by default [openssh-7.2p2-enable_PAM_by_default.patch] - copy command line arguments properly [openssh-7.2p2-saveargv-fix.patch] - do not use pthreads in PAM code [openssh-7.2p2-dont_use_pthreads_in_PAM.patch] - fix paths in documentation [openssh-7.2p2-eal3.patch] - prevent race consitions triggered by SIGALRM [openssh-7.2p2-blocksigalrm.patch] - do send and accept locale environment variables by default [openssh-7.2p2-send_locale.patch] - handle hostnames changes during X forwarding [openssh-7.2p2-hostname_changes_when_forwarding_X.patch] - try to remove xauth cookies on exit [openssh-7.2p2-remove_xauth_cookies_on_exit.patch] - properly format pts names for ?tmp? log files [openssh-7.2p2-pts_names_formatting.patch] - check locked accounts when using PAM [openssh-7.2p2-pam_check_locks.patch] - chenge default PermitRootLogin to 'yes' to prevent unwanted surprises on updates from older versions. See README.SUSE for details [openssh-7.2p2-allow_root_password_login.patch] - Disable DH parameters under 2048 bits by default and allow lowering the limit back to the RFC 4419 specified minimum through an option (bsc#932483, bsc#948902) [openssh-7.2p2-disable_short_DH_parameters.patch] - Add getuid() and stat() syscalls to the seccomp filter (bsc#912436) [openssh-7.2p2-seccomp_getuid.patch, openssh-7.2p2-seccomp_stat.patch]- upgrade to 7.2p2 upstream package without any SUSE patches Distilled upstream log: - OpenSSH 6.7 Potentially-incompatible changes: * sshd(8): The default set of ciphers and MACs has been altered to remove unsafe algorithms. In particular, CBC ciphers and arcfour* are disabled by default. The full set of algorithms remains available if configured explicitly via the Ciphers and MACs sshd_config options. * sshd(8): Support for tcpwrappers/libwrap has been removed. * OpenSSH 6.5 and 6.6 have a bug that causes ~0.2% of connections using the curve25519-sha256@libssh.org KEX exchange method to fail when connecting with something that implements the specification correctly. OpenSSH 6.7 disables this KEX method when speaking to one of the affected versions. New Features: * ssh(1), sshd(8): Add support for Unix domain socket forwarding. A remote TCP port may be forwarded to a local Unix domain socket and vice versa or both ends may be a Unix domain socket. * ssh(1), ssh-keygen(1): Add support for SSHFP DNS records for ED25519 key types. * sftp(1): Allow resumption of interrupted uploads. * ssh(1): When rekeying, skip file/DNS lookups of the hostkey if it is the same as the one sent during initial key exchange * sshd(8): Allow explicit ::1 and 127.0.0.1 forwarding bind addresses when GatewayPorts=no; allows client to choose address family * sshd(8): Add a sshd_config PermitUserRC option to control whether ~/.ssh/rc is executed, mirroring the no-user-rc authorized_keys option * ssh(1): Add a %C escape sequence for LocalCommand and ControlPath that expands to a unique identifer based on a hash of the tuple of (local host, remote user, hostname, port). Helps avoid exceeding miserly pathname limits for Unix domain sockets in multiplexing control paths * sshd(8): Make the "Too many authentication failures" message include the user, source address, port and protocol in a format similar to the authentication success / failure messages Bugfixes: * sshd(8): Fix remote forwarding with the same listen port but different listen address. * ssh(1): Fix inverted test that caused PKCS#11 keys that were explicitly listed in ssh_config or on the commandline not to be preferred. * ssh-keygen(1): Fix bug in KRL generation: multiple consecutive revoked certificate serial number ranges could be serialised to an invalid format. Readers of a broken KRL caused by this bug will fail closed, so no should-have-been-revoked key will be accepted. * ssh(1): Reflect stdio-forward ("ssh -W host:port ...") failures in exit status. Previously we were always returning 0 * ssh(1), ssh-keygen(1): Make Ed25519 keys' title fit properly in the randomart border * ssh-agent(1): Only cleanup agent socket in the main agent process and not in any subprocesses it may have started (e.g. forked askpass). Fixes agent sockets being zapped when askpass processes fatal() * ssh-add(1): Make stdout line-buffered; saves partial output getting lost when ssh-add fatal()s part-way through (e.g. when listing keys from an agent that supports key types that ssh-add doesn't) * ssh-keygen(1): When hashing or removing hosts, don't choke on @revoked markers and don't remove @cert-authority markers * ssh(1): Don't fatal when hostname canonicalisation fails and a ProxyCommand is in use; continue and allow the ProxyCommand to connect anyway (e.g. to a host with a name outside the DNS behind a bastion) * scp(1): When copying local->remote fails during read, don't send uninitialised heap to the remote end. * sftp(1): Fix fatal "el_insertstr failed" errors when tab-completing filenames with a single quote char somewhere in the string * ssh-keyscan(1): Scan for Ed25519 keys by default. * ssh(1): When using VerifyHostKeyDNS with a DNSSEC resolver, down-convert any certificate keys to plain keys and attempt SSHFP resolution. Prevents a server from skipping SSHFP lookup and forcing a new-hostkey dialog by offering only certificate keys. - OpenSSH 6.8 Potentially-incompatible changes: * sshd(8): UseDNS now defaults to 'no'. Configurations that match against the client host name (via sshd_config or authorized_keys) may need to re-enable it or convert to matching against addresses. New Features: * Add FingerprintHash option to ssh(1) and sshd(8), and equivalent command-line flags to the other tools to control algorithm used for key fingerprints. The default changes from MD5 to SHA256 and format from hex to base64. Fingerprints now have the hash algorithm prepended. An example of the new format: SHA256:mVPwvezndPv/ARoIadVY98vAC0g+P/5633yTC4d/wXE Please note that visual host keys will also be different. * ssh(1), sshd(8): Experimental host key rotation support. Add a protocol extension for a server to inform a client of all its available host keys after authentication has completed. The client may record the keys in known_hosts, allowing it to upgrade to better host key algorithms and a server to gracefully rotate its keys. The client side of this is controlled by a UpdateHostkeys config option (default off). * ssh(1): Add a ssh_config HostbasedKeyType option to control which host public key types are tried during host-based authentication. * ssh(1), sshd(8): fix connection-killing host key mismatch errors when sshd offers multiple ECDSA keys of different lengths. * ssh(1): when host name canonicalisation is enabled, try to parse host names as addresses before looking them up for canonicalisation. fixes bz#2074 and avoiding needless DNS lookups in some cases. * ssh-keygen(1), sshd(8): Key Revocation Lists (KRLs) no longer require OpenSSH to be compiled with OpenSSL support. * ssh(1), ssh-keysign(8): Make ed25519 keys work for host based authentication. * sshd(8): SSH protocol v.1 workaround for the Meyer, et al, Bleichenbacher Side Channel Attack. Fake up a bignum key before RSA decryption. * sshd(8): Remember which public keys have been used for authentication and refuse to accept previously-used keys. This allows AuthenticationMethods=publickey,publickey to require that users authenticate using two _different_ public keys. * sshd(8): add sshd_config HostbasedAcceptedKeyTypes and PubkeyAcceptedKeyTypes options to allow sshd to control what public key types will be accepted. Currently defaults to all. * sshd(8): Don't count partial authentication success as a failure against MaxAuthTries. * ssh(1): Add RevokedHostKeys option for the client to allow text-file or KRL-based revocation of host keys. * ssh-keygen(1), sshd(8): Permit KRLs that revoke certificates by serial number or key ID without scoping to a particular CA. * ssh(1): Add a "Match canonical" criteria that allows ssh_config Match blocks to trigger only in the second config pass. * ssh(1): Add a -G option to ssh that causes it to parse its configuration and dump the result to stdout, similar to "sshd -T". * ssh(1): Allow Match criteria to be negated. E.g. "Match !host". * The regression test suite has been extended to cover more OpenSSH features. The unit tests have been expanded and now cover key exchange. Bugfixes: * ssh-keyscan(1): ssh-keyscan has been made much more robust again servers that hang or violate the SSH protocol. * ssh(1), ssh-keygen(1): Fix regression: Key path names were being lost as comment fields. * ssh(1): Allow ssh_config Port options set in the second config parse phase to be applied (they were being ignored). * ssh(1): Tweak config re-parsing with host canonicalisation - make the second pass through the config files always run when host name canonicalisation is enabled (and not whenever the host name changes) * ssh(1): Fix passing of wildcard forward bind addresses when connection multiplexing is in use * ssh-keygen(1): Fix broken private key conversion from non-OpenSSH formats. * ssh-keygen(1): Fix KRL generation bug when multiple CAs are in use. * Various fixes to manual pages - OpenSSH 6.9 Security: * ssh(1): when forwarding X11 connections with ForwardX11Trusted=no, connections made after ForwardX11Timeout expired could be permitted and no longer subject to XSECURITY restrictions because of an ineffective timeout check in ssh(1) coupled with "fail open" behaviour in the X11 server when clients attempted connections with expired credentials. This problem was reported by Jann Horn. * ssh-agent(1): fix weakness of agent locking (ssh-add -x) to password guessing by implementing an increasing failure delay, storing a salted hash of the password rather than the password itself and using a timing-safe comparison function for verifying unlock attempts. This problem was reported by Ryan Castellucci. New Features: * ssh(1), sshd(8): promote chacha20-poly1305@openssh.com to be the default cipher * sshd(8): support admin-specified arguments to AuthorizedKeysCommand * sshd(8): add AuthorizedPrincipalsCommand that allows retrieving authorized principals information from a subprocess rather than a file. * ssh(1), ssh-add(1): support PKCS#11 devices with external PIN entry devices * sshd(8): allow GSSAPI host credential check to be relaxed for multihomed hosts via GSSAPIStrictAcceptorCheck option * ssh-keygen(1): support "ssh-keygen -lF hostname" to search known_hosts and print key hashes rather than full keys. * ssh-agent(1): add -D flag to leave ssh-agent in foreground without enabling debug mode Bugfixes: * ssh(1), sshd(8): deprecate legacy SSH2_MSG_KEX_DH_GEX_REQUEST_OLD message and do not try to use it against some 3rd-party SSH implementations that use it (older PuTTY, WinSCP). * Many fixes for problems caused by compile-time deactivation of SSH1 support (including bz#2369) * ssh(1), sshd(8): cap DH-GEX group size at 4Kbits for Cisco implementations as some would fail when attempting to use group sizes >4K * ssh(1): fix out-of-bound read in EscapeChar configuration option parsing * sshd(8): fix application of PermitTunnel, LoginGraceTime, AuthenticationMethods and StreamLocalBindMask options in Match blocks * ssh(1), sshd(8): improve disconnection message on TCP reset; bz#2257 * ssh(1): remove failed remote forwards established by muliplexing from the list of active forwards * sshd(8): make parsing of authorized_keys "environment=" options independent of PermitUserEnv being enabled * sshd(8): fix post-auth crash with permitopen=none * ssh(1), ssh-add(1), ssh-keygen(1): allow new-format private keys to be encrypted with AEAD ciphers * ssh(1): allow ListenAddress, Port and AddressFamily configuration options to appear in any order * sshd(8): check for and reject missing arguments for VersionAddendum and ForceCommand * ssh(1), sshd(8): don't treat unknown certificate extensions as fatal * ssh-keygen(1): make stdout and stderr output consistent * ssh(1): mention missing DISPLAY environment in debug log when X11 forwarding requested * sshd(8): correctly record login when UseLogin is set * sshd(8): Add some missing options to sshd -T output and fix output of VersionAddendum and HostCertificate. bz#2346 * Document and improve consistency of options that accept a "none" argument" TrustedUserCAKeys, RevokedKeys (bz#2382), AuthorizedPrincipalsFile (bz#2288) * ssh(1): include remote username in debug output * sshd(8): avoid compatibility problem with some versions of Tera Term, which would crash when they received the hostkeys notification message (hostkeys-00@openssh.com) * sshd(8): mention ssh-keygen -E as useful when comparing legacy MD5 host key fingerprints * ssh(1): clarify pseudo-terminal request behaviour and use make manual language consistent * ssh(1): document that the TERM environment variable is not subject to SendEnv and AcceptEnv - OpenSSH 7.0: This focuses primarily on deprecating weak, legacy and/or unsafe cryptography. Security: * sshd(8): OpenSSH 6.8 and 6.9 incorrectly set TTYs to be world- writable. Local attackers may be able to write arbitrary messages to logged-in users, including terminal escape sequences. Reported by Nikolay Edigaryev. * sshd(8): Portable OpenSSH only: Fixed a privilege separation weakness related to PAM support. Attackers who could successfully compromise the pre-authentication process for remote code execution and who had valid credentials on the host could impersonate other users. Reported by Moritz Jodeit. * sshd(8): Portable OpenSSH only: Fixed a use-after-free bug related to PAM support that was reachable by attackers who could compromise the pre-authentication process for remote code execution. Also reported by Moritz Jodeit. * sshd(8): fix circumvention of MaxAuthTries using keyboard- interactive authentication. By specifying a long, repeating keyboard-interactive "devices" string, an attacker could request the same authentication method be tried thousands of times in a single pass. The LoginGraceTime timeout in sshd(8) and any authentication failure delays implemented by the authentication mechanism itself were still applied. Found by Kingcope. Potentially-incompatible Changes: * Support for the legacy SSH version 1 protocol is disabled by default at compile time. * Support for the 1024-bit diffie-hellman-group1-sha1 key exchange is disabled by default at run-time. It may be re-enabled using the instructions in README.legacy or http://www.openssh.com/legacy.html * Support for ssh-dss, ssh-dss-cert-* host and user keys is disabled by default at run-time. These may be re-enabled using the instructions at http://www.openssh.com/legacy.html * Support for the legacy v00 cert format has been removed. * The default for the sshd_config(5) PermitRootLogin option has changed from "yes" to "prohibit-password". * PermitRootLogin=without-password/prohibit-password now bans all interactive authentication methods, allowing only public-key, hostbased and GSSAPI authentication (previously it permitted keyboard-interactive and password-less authentication if those were enabled). New Features: * ssh_config(5): add PubkeyAcceptedKeyTypes option to control which public key types are available for user authentication. * sshd_config(5): add HostKeyAlgorithms option to control which public key types are offered for host authentications. * ssh(1), sshd(8): extend Ciphers, MACs, KexAlgorithms, HostKeyAlgorithms, PubkeyAcceptedKeyTypes and HostbasedKeyTypes options to allow appending to the default set of algorithms instead of replacing it. Options may now be prefixed with a '+' to append to the default, e.g. "HostKeyAlgorithms=+ssh-dss". * sshd_config(5): PermitRootLogin now accepts an argument of 'prohibit-password' as a less-ambiguous synonym of 'without- password'. Bugfixes: * ssh(1), sshd(8): add compatability workarounds for Cisco and more PuTTY versions. * Fix some omissions and errors in the PROTOCOL and PROTOCOL.mux documentation relating to Unix domain socket forwarding * ssh(1): Improve the ssh(1) manual page to include a better description of Unix domain socket forwarding * ssh(1), ssh-agent(1): skip uninitialised PKCS#11 slots, fixing failures to load keys when they are present. * ssh(1), ssh-agent(1): do not ignore PKCS#11 hosted keys that wth empty CKA_ID * sshd(8): clarify documentation for UseDNS option - OpenSSH 7.1: Security: * sshd(8): OpenSSH 7.0 contained a logic error in PermitRootLogin= prohibit-password/without-password that could, depending on compile-time configuration, permit password authentication to root while preventing other forms of authentication. This problem was reported by Mantas Mikulenas. Bugfixes: * ssh(1), sshd(8): add compatability workarounds for FuTTY * ssh(1), sshd(8): refine compatability workarounds for WinSCP * Fix a number of memory faults (double-free, free of uninitialised memory, etc) in ssh(1) and ssh-keygen(1). Reported by Mateusz Kocielski. - OpenSSH 7.1p2: * SECURITY: ssh(1): The OpenSSH client code between 5.4 and 7.1 contains experimential support for resuming SSH-connections (roaming). The matching server code has never been shipped, but the client code was enabled by default and could be tricked by a malicious server into leaking client memory to the server, including private client user keys. The authentication of the server host key prevents exploitation by a man-in-the-middle, so this information leak is restricted to connections to malicious or compromised servers. MITIGATION: For OpenSSH >= 5.4 the vulnerable code in the client can be completely disabled by adding 'UseRoaming no' to the gobal ssh_config(5) file, or to user configuration in ~/.ssh/config, or by passing -oUseRoaming=no on the command line. PATCH: See below for a patch to disable this feature (Disabling Roaming in the Source Code). This problem was reported by the Qualys Security Advisory team. * SECURITY: Eliminate the fallback from untrusted X11-forwarding to trusted forwarding for cases when the X server disables the SECURITY extension. Reported by Thomas Hoger. * SECURITY: Fix an out of-bound read access in the packet handling code. Reported by Ben Hawkes. * PROTOCOL: Correctly interpret the 'first_kex_follows' option during the intial key exchange. Reported by Matt Johnston. * Further use of explicit_bzero has been added in various buffer handling code paths to guard against compilers aggressively doing dead-store removal. Potentially-incompatible changes: * This release disables a number of legacy cryptographic algorithms by default in ssh: + Several ciphers blowfish-cbc, cast128-cbc, all arcfour variants and the rijndael-cbc aliases for AES. + MD5-based and truncated HMAC algorithms. - OpenSSH 7.2: Security: * ssh(1), sshd(8): remove unfinished and unused roaming code (was already forcibly disabled in OpenSSH 7.1p2). * ssh(1): eliminate fallback from untrusted X11 forwarding to trusted forwarding when the X server disables the SECURITY extension. * ssh(1), sshd(8): increase the minimum modulus size supported for diffie-hellman-group-exchange to 2048 bits. * sshd(8): pre-auth sandboxing is now enabled by default (previous releases enabled it for new installations via sshd_config). New Features: * all: add support for RSA signatures using SHA-256/512 hash algorithms based on draft-rsa-dsa-sha2-256-03.txt and draft-ssh-ext-info-04.txt. * ssh(1): Add an AddKeysToAgent client option which can be set to 'yes', 'no', 'ask', or 'confirm', and defaults to 'no'. When enabled, a private key that is used during authentication will be added to ssh-agent if it is running (with confirmation enabled if set to 'confirm'). * sshd(8): add a new authorized_keys option "restrict" that includes all current and future key restrictions (no-*-forwarding, etc.). Also add permissive versions of the existing restrictions, e.g. "no-pty" -> "pty". This simplifies the task of setting up restricted keys and ensures they are maximally-restricted, regardless of any permissions we might implement in the future. * ssh(1): add ssh_config CertificateFile option to explicitly list certificates. bz#2436 * ssh-keygen(1): allow ssh-keygen to change the key comment for all supported formats. * ssh-keygen(1): allow fingerprinting from standard input, e.g. "ssh-keygen -lf -" * ssh-keygen(1): allow fingerprinting multiple public keys in a file, e.g. "ssh-keygen -lf ~/.ssh/authorized_keys" bz#1319 * sshd(8): support "none" as an argument for sshd_config Foreground and ChrootDirectory. Useful inside Match blocks to override a global default. bz#2486 * ssh-keygen(1): support multiple certificates (one per line) and reading from standard input (using "-f -") for "ssh-keygen -L" * ssh-keyscan(1): add "ssh-keyscan -c ..." flag to allow fetching certificates instead of plain keys. * ssh(1): better handle anchored FQDNs (e.g. 'cvs.openbsd.org') in hostname canonicalisation - treat them as already canonical and remove the trailing '.' before matching ssh_config. Bugfixes: * sftp(1): existing destination directories should not terminate recursive uploads (regression in openssh 6.8) * ssh(1), sshd(8): correctly send back SSH2_MSG_UNIMPLEMENTED replies to unexpected messages during key exchange. * ssh(1): refuse attempts to set ConnectionAttempts=0, which does not make sense and would cause ssh to print an uninitialised stack variable. * ssh(1): fix errors when attempting to connect to scoped IPv6 addresses with hostname canonicalisation enabled. * sshd_config(5): list a couple more options usable in Match blocks. * sshd(8): fix "PubkeyAcceptedKeyTypes +..." inside a Match block. * ssh(1): expand tilde characters in filenames passed to -i options before checking whether or not the identity file exists. Avoids confusion for cases where shell doesn't expand (e.g. "-i ~/file" vs. "-i~/file"). * ssh(1): do not prepend "exec" to the shell command run by "Match exec" in a config file, which could cause some commands to fail in certain environments. * ssh-keyscan(1): fix output for multiple hosts/addrs on one line when host hashing or a non standard port is in use * sshd(8): skip "Could not chdir to home directory" message when ChrootDirectory is active. * ssh(1): include PubkeyAcceptedKeyTypes in ssh -G config dump. * sshd(8): avoid changing TunnelForwarding device flags if they are already what is needed; makes it possible to use tun/tap networking as non-root user if device permissions and interface flags are pre-established * ssh(1), sshd(8): RekeyLimits could be exceeded by one packet. * ssh(1): fix multiplexing master failure to notice client exit. * ssh(1), ssh-agent(1): avoid fatal() for PKCS11 tokens that present empty key IDs. * sshd(8): avoid printf of NULL argument. * ssh(1), sshd(8): allow RekeyLimits larger than 4GB. * ssh-keygen(1): sshd(8): fix several bugs in (unused) KRL signature support. * ssh(1), sshd(8): fix connections with peers that use the key exchange guess feature of the protocol. * sshd(8): include remote port number in log messages. * ssh(1): don't try to load SSHv1 private key when compiled without SSHv1 support. * ssh-agent(1), ssh(1): fix incorrect error messages during key loading and signing errors. * ssh-keygen(1): don't leave empty temporary files when performing known_hosts file edits when known_hosts doesn't exist. * sshd(8): correct packet format for tcpip-forward replies for requests that don't allocate a port * ssh(1), sshd(8): fix possible hang on closed output. * ssh(1): expand %i in ControlPath to UID. * ssh(1), sshd(8): fix return type of openssh_RSA_verify. * ssh(1), sshd(8): fix some option parsing memory leaks. * ssh(1): add a some debug output before DNS resolution; it's a place where ssh could previously silently stall in cases of unresponsive DNS servers. * ssh(1): remove spurious newline in visual hostkey. * ssh(1): fix printing (ssh -G ...) of HostKeyAlgorithms=+... * ssh(1): fix expansion of HostkeyAlgorithms=+... Documentation: * ssh_config(5), sshd_config(5): update default algorithm lists to match current reality. * ssh(1): mention -Q key-plain and -Q key-cert query options. * sshd_config(8): more clearly describe what AuthorizedKeysFile=none does. * ssh_config(5): better document ExitOnForwardFailure. * sshd(5): mention internal DH-GEX fallback groups in manual. * sshd_config(5): better description for MaxSessions option. Portability: * sshd(8): fix multiple authentication using S/Key. - OpenSSH 7.2p2: Security: * sshd(8): sanitise X11 authentication credentials to avoid xauth command injection when X11Forwarding is enabled. (removing patches from previous version: * CVE-2016-0777_CVE-2016-0778.patch * openssh-6.6p1-X11-forwarding.patch * openssh-6.6p1-X_forward_with_disabled_ipv6.patch * openssh-6.6p1-audit1-remove_duplicit_audit.patch * openssh-6.6p1-audit2-better_audit_of_user_actions.patch * openssh-6.6p1-audit3-key_auth_usage-fips.patch * openssh-6.6p1-audit3-key_auth_usage.patch * openssh-6.6p1-audit4-kex_results-fips.patch * openssh-6.6p1-audit4-kex_results.patch * openssh-6.6p1-audit5-session_key_destruction.patch * openssh-6.6p1-audit6-server_key_destruction.patch * openssh-6.6p1-audit7-libaudit_compat.patch * openssh-6.6p1-audit8-libaudit_dns_timeouts.patch * openssh-6.6p1-blocksigalrm.patch * openssh-6.6p1-curve25519-6.6.1p1.patch * openssh-6.6p1-default-protocol.patch * openssh-6.6p1-disable-openssl-abi-check.patch * openssh-6.6p1-eal3.patch * openssh-6.6p1-fingerprint_hash.patch * openssh-6.6p1-fips-checks.patch * openssh-6.6p1-fips.patch * openssh-6.6p1-gssapi_key_exchange.patch * openssh-6.6p1-gssapimitm.patch * openssh-6.6p1-host_ident.patch * openssh-6.6p1-key-converter.patch * openssh-6.6p1-lastlog.patch * openssh-6.6p1-ldap.patch * openssh-6.6p1-login_options.patch * openssh-6.6p1-no_fork-no_pid_file.patch * openssh-6.6p1-pam-check-locks.patch * openssh-6.6p1-pam-fix2.patch * openssh-6.6p1-pam-fix3.patch * openssh-6.6p1-pts.patch * openssh-6.6p1-saveargv-fix.patch * openssh-6.6p1-seccomp_getuid.patch * openssh-6.6p1-seccomp_stat.patch * openssh-6.6p1-seed-prng.patch * openssh-6.6p1-send_locale.patch * openssh-6.6p1-sftp_force_permissions.patch * openssh-6.6p1-sftp_homechroot.patch * openssh-6.6p1-xauth.patch * openssh-6.6p1-xauthlocalhostname.patch)- update seccomp sandbox that broke after OpenSSL update (bsc#912436, bsc#977812) [openssh-6.6p1-seccomp_stat.patch]- openssh-6.6p1-ldap.patch: replace TRUE/FALSE with 1/0, since this defines did come via an indirect header inclusion and are not everywhere defined.- CVE-2016-0777, bsc#961642, CVE-2016-0778, bsc#961645 Add CVE-2016-0777_CVE-2016-0778.patch to disable the roaming code to prevent information leak and buffer overflow- gpg signature and keyring added. pub 3200R/6D920D30 2013-12-10 [expires: 2021-01-01] uid Damien Miller sub 3200R/672A1105 2013-12-10 [expires: 2021-01-01]- fix bashisms in sshd.init scriptgoat23 1689934202 8.4p1-150300.3.22.18.4p1-150300.3.22.18.4p1-150300.3.22.1sshmodulissh-keygenopenssh-commonCREDITSChangeLogOVERVIEWREADMEREADME.FIPSREADME.SUSEREADME.kerberosTODOopenssh-commonLICENCEssh-keygen.1.gzmoduli.5.gz/etc//etc/ssh//usr/bin//usr/share/doc/packages//usr/share/doc/packages/openssh-common//usr/share/licenses//usr/share/licenses/openssh-common//usr/share/man/man1//usr/share/man/man5/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.suse.de/SUSE:Maintenance:29890/SUSE_SLE-15-SP3_Update/2102b9f359ddd3a98ebcb62e2dfc157c-openssh.SUSE_SLE-15-SP3_Updatecpioxz5x86_64-suse-linuxdirectoryASCII text, with very long linesELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, BuildID[sha1]=9ebfe033cafb617652b2b12e7ed24dc70ddd5a4f, for GNU/Linux 3.2.0, strippedUTF-8 Unicode textUTF-8 Unicode text, with very long linesASCII texttroff or preprocessor input, ASCII text (gzip compressed data, max compression, from Unix)RRRR RR RRRRR RRR R RRRRR>Yc8l+кutf-8895217fc95e37fcf7b6f2d29d645729b458b4678c9ea5eda0bb8b749d9ae7e4e?7zXZ !t/V] crt:bLL -%5lrQ>+8~DB od/.Aņ>|gs<^LˆejGV UH*qca6: E{_涨Jw$B?'GhwGƓloBMhO3b0Eru%ҿ'j L@P*b<渦Tv1S"hY&B^`@',farB)-+#sa C l ei{D<qEGU`(YQ0p],Z~iJp4;E&-7<fnEd佑X̚e=N:@JwLg>_plwU`&uÙ*[jdssQLjo\ZP3#rYsX-PB౸be+~f&UyV1䂻AQ>W nтPL ,GŢE4Vul8tAb|O#5Y"?LB>M~c__b)!t2Vgo/\dŠCthP,QJ[2)5ޚ;ϊl>nq6*J3˿ѕ r>J?e5S) 0 S CdWIEF7fECF09 *_Q`Z[Νf~ti^F | }>+OUBҟ`w5u,maeGa!b}NGdfP mUPWZ;Oye맽^]kw>D/5/}O s{2-ilM"xh]Ʀy-] ѝMݲrA?Ǽx+0os실\ DinLuxޞO D$_ 3j>[2"VXTjMIBsv1ݫޑ7- ϕ ̍ r\^~II S1$W((yO-h`%B65){ײqt(sy0TþBBpXtZ=Ret>yz~.wmQ IoY'c 6)0 #Ҕ]5_\6S7Pq˻O1[EsA?#Ku0:HE8k\hل5 D8mDf Kz0 =@b]gZdo,,N@]>(.ǀF0D8@]qO(锖%VJ)mI+Ps??Td0i᪌!r͆˩nf'CFe>H-^udJ5Б t^j璃y0+Wm.6r?C;ז8n]û3j\5>tOҭ}07(L.5YJvf.u[ᅯXY4g+p~$IlPm . J=`f4D^4u,e%eQ&$wg(aYZI ah1=WwD\&ShpQ3A֛DH}ղ܆oK1H++hR^;R'W5UYEm _V"N 9-FߓLFJS}ga;$z[UnpR&l/vB2_[Pp{iK_k)ۯcO:@Z"7o1FG!y*CxW'H~vMm<!~&rW0Sz1ª3ޚ |Ntu|)PaVEwKn2V Xg"$Bd.R})\f7j0 ؁-ʰTlOH:qLdE^dn#0`Y]^J`=L5`2"p',WɩuIEP8<%u?E~; xPFnѰICQ۽2ْcl7G[(!I6ttAĖ, o/h}ơhhx=V`^w%Hdgz5p//'>S1$vY଱#ޮK ƓRSW5tkKJ  cJXy\DEJ:vH\jKt~Qځ!)A6Ё/@#tǾ04Z ĸbm$%s-j ;3ŠYOO68jQ ?DzmWa" ~2BER,/Ues=)CHNDb.ԦgZn0u1>7n匾Rd O9qQT9( Y.5=3PA.Ѵܴ6Δ-;!b{?rYN+@vz#٪#O(8q8ufkvd\ɻxqIř6Ff6!2V&e9H/y8%FG]7Ap23ܶ58UQAmUN-嗂C]c=h9jwMoHy?J'(\lcB'pa< H%!ZeD (ʋo5X!O_i[0Ͷ4vOhQ3M3艪Єgsu2fOԅbTcK /sEHXs,lI2,p >ȴ GoPZnP$3LɓL۹Q 1ps9a/`u:d_N0,&IP|92mv\m9= T]D QZeEju/1KY^NgeJGEHtȳ@)1B󪖖F nr!kEmn}G~ҧF51. AklelB\)+;7 0p]attx7FE CZx~zt;SPl O9$de:6H'yapnvG$   ވk#Dzrʅ<ϩ^1b "h00ΐ R|Pq0mzw::Q 28BF&ݲ^DTS*C˖9 @yޡ֮ﶳqyrWǵPi+ֲ &zAΊ('AMήb[u$pNJ7%K e1(n H+yK. =Gx0F ([jk.yV1ֶu2̉⹁Rx>a>W]jJGtO)$ؾ-\ÛxW+&2w':dsPYM#PyaCgr#}qIQV,tdWTz@GafpgVE.I uV2iHD(+䕙H\mg%n_OT4@lne)yijFgT9~JxZS9Oo&XgZE3% ws(,:piwzJ,v>\p1I/u)DM0}`?-+P t]Xi=3 \{P`?dBopqĜZ L7bW fAP ZhՀq ժ݊pdi-?ot2bɅLsK|mpy5<H(yF8oyss+S@8KJ1{Uؑ.OS_Cp]w&!Ŋ< BhAٴϬd<(wg3gxZv;8 7AQ0<-Y"JꓩE aBdEaUݓ89$3}&F43:bPn;{NAd8/asPS0 pH |7J,]\&ty0$ozzӻ7>򕍤֠CMB35vTbfcf)t.3J|`&D2gR x9'~tI3 hͮԎW'b)ӿ[$"p#֒XE(}ϓ^"@/vw\D .4]HpT:G.R˯Z7nD 8_K$ Y; yǵ틍XUߝrJN8P?]uMw+ƐDk54Äp)&y,Msz8zB"+>X?s,[ku 3V5!8xfw*\B70-; J\0<3F&F+@J;i q7↥~WRfB,tl/T| 1%Ï,bO9-,t@ cOlaYZn ʘx^.ht_FZl P‰}yKhA$|ĠAφ.o/q60'3{`2%+.ZJy(D3RoZ$f 早5;% awĦb(}qz >dcK Bn?R&]oKW Mupb_sA>`xv@t.ԌuhSWu ]΢xe ei@R! /BާnvB]7~Pde XE.|!"Ll͆i)19/xܷ4A%xOCLvρ6r]\Co{)U%q0f(O0녛AGÜD|5=ݎ^z ܗֿ4JvӠ;)i0Oxez/y5=i\^Y_j-=!2 x0|bFYI[ske@}l=.қU4,M*#ȉ!gDD{z TEzmSqM"zP7$%d ҪW&ww-A# %>kLe\k$m%0?+5pC5< sӲцZ' U|>C|O+-7jEk_EO5%K#}I[?oUaCW}@\> `L*qJУ2⼱{ O |yÖ(PT}%| ĢQT$>cֆ@*e[^@6@1,IAnj7IzDE6E3zVk9> +" W:[ ٨O!={D1LcZҨA`=XQMsꬆEm=?Y\D~/sZ0xNˏ``t :g1gqD+~IDh4#ШD֍AJͅoV=\ע6{κԈOQKONwf.r+ ByTF{hm! Oؘ1 abhF Cc߃դ3= -L3"tdK2u1k5^#Һۙrt*W"'4;Ufܮց ShlfJ'U)RoW*% uSU*( *%.ӰӴ%U=ʻz}D{Q@^<,K`lIB|cyW7q8a*3nq4soC-;iB fsdfS7AK%k(btik,JrĤ1f'-lk^V%v}LOIAE9f"VOG㘅oÏD)~&`=պ!AUY{zّ̫:+ϖC| ײַՔ:\l5F&Z:> ӻ3K8H>=ǹj"얆,~}sB]n#FCs${2ԑIX9,eޫH*kW:Jn]:Vsb~dtpu`h~p)A5%|A*&F?$a 53Pώ , 54,d ʷ,*V+4Zҏw2}[lD_.~棳i>\A't^Ei)vBMlp ^N!IZ/oO S22p0S9OPtJ2?vl6Hg>i\?4cbY%?K:qkr+AbΆQ)S㭤j'L IK$GU,Jcu`uG૮}X)fuk~}rU|H?4.V2|{\,L4d<_Ik ̩|('Tv(P vI_ma@w ".BM_)ߨb1d\:pʤǨ H73a-4 me㚛LtUpp':|X#[>Ɔ]h=C>aG_0Β'%Č/6ke"B$BV=YunlK z~C/>Y9S /mMCOtyl,Tl 43D89N!͹Gbei+`[7ML]鸮"hlxRPQڡO/8OtYoHYҏi@4mA5d6)pĶ"yk/20Uͥa]-#7.n*&k%x?I6fY$t K jHXхs8H8|ذhpB ~‹KY8\HqS&auP@w{Ь쪭Țu9nmFVFT,^ٖw&s r@p\4{r^6p Qjyd}]f`so&-ysOF%IM욒_T-PIƫtUs (*>ld=ФU\ꎎF[d4qػ6lʝP5Z<[HDwQF#H%Eocbtp;~F>Iρk7VQCll;JP1/7|?~{|3V~gllLqNqH -#ǚwdl9xQkG6j w8B dde&S_Oy}*}[rC-:Q* !wCxy^U x{J*:x^_wFu}Hb:flch^(/nnM#2,,7P<~I 7 \Fw/?6Q*tv/TRYki~%^ƃտ7ȴZ>eí5'[#d[¶@^\-?!h"ej5q4%VfLmCw.zV+^|y b%wOFf2NT39k6r*[3͂@ȏ;XǘY4TIY!څ)_q^ (u,s ꁸHU̒)N(#gk' nn@(;>? ҆{Z{"Kζ?>0 Ed n-oܫUƐ^ Wj%.W>2@Xo&G\˅O,_Ȱ,;4ЀrP%W=iٙ|̢ i, ,-xM)9{7S@$3Rl (2ћ3 ߃T=_-ݾC4.́٘+i“:ktQ]1, zV"Dv@\Du04;ֽl,D~+GW]U|sᡤI'`Y? We|WL/KǚAY[/ ȶ3HBQ1\$~xp /3kqN;;~m@LW vе=V;vCTTL%p+X-.c9ZZvKa0q9+jٛЙv`5N[2TR_242o-[824հ`]n,I ToqN 4(p)X{U%=FWPzO'Hl𞫸̺?h 0Pn ;Gew\p-Є3.Tk-qUA}a) tڐ~^YR>J8:o/OG%OޯITՇʛۺ=Э$ڸS|Ab[ӊtZR܇ˇ1t 6P+v10[ٱ3Pm0{5K >)9JG$9ȵY,p d.vES}Hv1bPI<`NATQC|ҽh Kbc[<Ԃ#tm[e fdysQi<nBNf3x)GpHǪ4U_? +6{[+BU r,g={CG[7uKw2h?&R-ΝDǽ]N( }Hn߷(QM fCsR3^0St1?b+OZiA4 6gV:kwD*gKY!H҆4N#t>ΏmM%4SPzC>pyc<*j)%['\XQUZǩiDb.yLt=ޒ K3wQK.&mt -80@ŕ&7^z^$<޻A_I)>*9AwyՉi 7[РAD--4H IYFgԚ7i׈Iu`,ZYeVf56R OE4xe}B7ʡ'T7NKJ[Z&L zD z.v]ok>b ܴr6fߨ# ?-a6UgSCjP̴`^/OWTl*FjaǾopb!úOּ"jsh t5X̵WJ{H4jR_c7%QyY $鳛0*Y{U}xrx2 8{v  .]|Ӑc_^iڶ(q?P1ԵaS0NE|(ueύmKg*_yC5_S/x%an(=ԶbMb2,m+Si|)j!˔;焏 \,e N_!{~S+ĝɢ̳zqXc \La^]YN_x'l6~!ˆ 1 nCI]Ǻ`=Ѐm9cCG^H kBteԬ JW {/@emYWO(*dgТti'}@I.@;ljJyns{@)@pb,ˤ(o#av# pdۏ ë+>q:p)t`{h}#q-"7DzBGJw&$[Lkcq3NiH{Ҷ!5$aٚV8Cr .KΗȉgq)o,J; +|,\_Z9 bT(4 5G7LZUT9;N0"q$zpC]ܢ2; /aBޮ[lY;ݩ̻gJXF1N+SSiORTj{f\l ðfLEk1eT[p[.cYC,:׹+)7` Yl;jʽY2i;2u\{~RŻw7F<wd@iM7+Rs[Ȯ|}6(1TQY`$ѹ?l$'Msb3AAnVy= 7р͙cB`FulyS"YLŪ9>LVyrERRh̟Y$z^sKT4ct!V^pLf)Kx(G}@aPPQ?7?؆I]PVLOR KaŜ[}(|$uy{ DpdvMF4>c$lc_"njʄ:n&|+UˠJm]2) OR"CU0_ 6i4wihc^@YX}LVy厰gg;Ҍ ̼=CyjjJdII]ۛ,2'xPP^H ev}oom< 58Nz3'N_~V;B-җ dX$_`]\:`j[-;Fi^Y6[Χr(/%Mt9#,WhLe ޖ b RDcFv* b/.ҝE'Z* 7qU ]b(}4k=It l2Pt4&X)r۵5"$!XmZ/dJ0ziW! 48XiNMIw=4w=@.UA',uBLmv(,XA-E*om )XdSPvc:k,5|zY|`X2F aυHSpydb9L.ě[ _՝_Ԭ\ȾIJ h1q6weW`ƃ$/0{`#ݍMhmY5JL: a' A4Ix| ^ARR)WMp#dVh~W;>-"q@9+x]7oK嘸h5l+2>P^m@U:/`3N"Cص/JJޅ[N)eӜG7CυВL&kt[32龷r|^r?YI'g;_F~gBɥMPQGjVvc1|S\o4n!{Kcܬ\<6@jfdѨ?> t6|8Ew}k˲} ,^ GHnEAFpz(WYMRE-ܰ}$Teh!V#3ץ,E6aRv0O) y |$G@o5Rt]V/뉣uR`qR y ]cd!MPíL!+bwY0gr \v75"F'B=, 0WpRzVvt5;xu@a @GL|מ)\˦s0O%PEsq5B?@WkO9 0Q:D,zъ1j'̇Zuw_ B5*}T#e5tC`DX_ fZV\r XH8Ќٹ-/oo`uI&PzEɿA~;"ERz+2 W̏a<*T=*A2,N!6DZ"{G 02ft'|.pPX\wC"튿 FVj\Ay^;Ƞ艵b]ƃuVjn:l0,l#iURWa@hH([LgZe–s: :F 1SFh݁bhsTۖȋSRʌ( (J)!FųJo3 莦rtGtWLF1KqC^4}a $ ](g;BBl%:m^I$}tso07wpfBg2s@p-5 :gax1z~wqʧ%+3LKND `Ϝ W6>sC&S&^Dϸ>-.>=]oUS6n4f1NfBL2=^|:MZN=3L Md~YuoUfxrjf`ePnOXzv0,$ht"mV!.\<ؐh䓏_s#A&-~8k8؈ g3峽l$+\yX .;(ZKּ'J G0e@>d}Ɇ{p74Qu^ UI[ۦn2}-_?`ĭ v߄5Ww«b@Xc9I DD~`v.dxsDlR9<B\rсߎiQR:ϋjץZd&\Þ8ܥSl/+ٸAP1O]J_scapՑSXq鬯%3 I٤Rs#% AbPpI{6)*pE㑔i Q%Óoj܁RSʏpFřsC,Q9Uh\;S 5Yj8] *1ѡN>T IϢ~]^3^ͽ㣡D&z ]\n|?JwMP ]tmǩO"bi0vQ:&6V.Jߨ.Iۀ恰M 4qh#jշrR('e#R!O;s*k8ts}snQtQ͎!_-\FZ!^ f!6ј 6!hRMCi S.(@:m]E+_ي%/'C+RdƮ1DQD#Y&-@__ "\b3;{|ߣˠ2'% ]C00uƊ>`n r[I#x4L`o`i˻Rt=~P &0h;C/flg,9!ủM%m165'_ɫhB)5d' `^N*Ж5N{S>e@i5vq'@\=հQBQ 4n̷ZX̝8P 2` ဆ<85$G> L^`C=dfIPqJp6Dg:s$ ib8W5X.8-Li@sӁ+ǭ\toKOkz,knxy/2eZّjrLgH#* E,*`jxb~z̄)Z )m?`ݡuDR!?\_ÔżH!B`^y[Kv%KT|9EBP'@R{ro/&b 0EhîbS~Lhxv*!E<3 AÜl"7JW: -v( e3@.nEdZGf7 ,ks,Dn(N0Vge5 !O?";3F+)D@^`Ϡy4RfZ8Qwk~Ň/'4UbȯVX#C|adFO"V!$k?}/*Eҵѣ Xsy-H2P$h-nX#uqPKgSK_)U9^ŝ̢`f6WtBL> l lz,4844bhq=W⓷xy;Pw$5t5+sb\C"L% *ޥ|p?hsgΚ% UrTx݋F[m5tǮM(ǍZ<&8,URtgQ Ct@WZC9"礍2vd"=r Fy(eJG(ˊa\ _*E(.+4דNSrB3SҴn!=bFޱ] +<U4sEd.Gd% {P9mtK3o:n"5WՄou@2 7ipk:| 0sc_UW -d hq#'A3+r4*$frBWc;)fF\5 i|߆)ޥcYHQ=wf`T!w B_25G[oLE#/ 1L?ԫ*Y]w+b!{̰^&_~8{m7azSiQSͪɅr?WG]c>x•C[]BC#,fXPe`%'UBI"ZR *]"]bPl Áfw3BdQg4ם 471g̜'mS tҶodqLIUeDɘ/FV9.ԨY;PGim[WU*T`]j[t5Gʏ%n|_*N9?7ADfCney;\@`{'5醕Rs[Gߵ;޽t#f D`1>g?Cѝ#(:YlSVЀdܢ8gJ]QB5'n܅]`jiƨ-}ztRCOtqn26|hEÁ Lk ؕ@L pN>/e ޔƍ-qo "+,u TWnTk`öQ> `XYyXDzmXJc OLncxr_# *~LiLeRz+5*t*M7&Eb>f8PjAsfA IEk@e5(Td0;-_)70_.PV74j\@iЗPcONoޟ+zGMGNm]?]:J5݀u-Gul;WFgZ08޺ Sfn3>my8A3a_NoAF8a_,M2 %KbraYVq-k@kF2lT%/:87gߖ*(&-WB7oMzpWѿu/l-#[ڲ6{wub_δ T";3*12oPBŸP-[^Z0)U1el(D2qW osf-\)1nry0Tog׮4}4QCyY|c>Y^@=5(8hHa:ڿ$^#Ն'aܚGN G (@5Y7y!< B͡G[.Ak+75<} |5D޷e" U& #VwlN],I?9|>E.dŐ;4J6ƥƍhb+#Q|z X,?bLqoBD˦)G&o011Zu߿S;PC55P(9KG!B޿Y{(!~4*cASͭ8Z"]DZzAXwJM6ӜnJ @ IN@4~d-U$lޖPEV~q[,d^-5GQ 2R5BP#yp`+.MʤYJ( iü >48;Io zW,XadOF¦GtӭG-¦$X &u_ qmg6*5s1Τb6u㢧Q `{g/xLj%4/ LK:p00A< *Dz b>a@g#;4^\Vtf ""2RvxG/$Y~wZژj#H[ԩNzT*w0N!>MyE]@MG 5㣘|LNdlywv|Y Ɉ-?3nc&/ 0ӂ|/$d+GTljeCeԣ&a( G Ts|׵=FEf8ye*88r rapq(UuAyb$LEQGةB*å|g1,8q< )AEyf$%0#FnCVykw_RaF;NH0>ZRB@C\c uƻCgue< k}dQbCK0iK'棅KE45 K%0V̕r1DF[yZ׽1wGq-χwҚ΂|6 ~};%UV~w%iya3(tt?rV'P?p"x3wŃM;n3p3RxLxn[Cʖ}G)/,e?`A4~IYR]JЅ!=.dK ^Et83B*dkj\~zV#An黮SAk'z_+YiqFYMpaM-}S?E:* J&wjB9B} /R0$dOmGTIMtC^u5|lAGPcWD HGXLx_)r>c`s;ښ/zVo~Cl;aEDXM @8ЦM@G.xn۞ O qRh3ENHs!h8h |iW_a݋0C'gTA 0Ԟcqf<6%|9rWpqY?``fo jhG+Q/Y_ޟz aS03C ؅{vжϫ%_"/045.=2SPIJǎJWeMDžglٞi@U)]O۽ !:JJ(r6alѬ4s{K? >@Y).-xols6AOHzHwC:>JK_dP&'zSO;azr]bkxR|@5r:h{S ʲF+lH+yȷ!3$ F0K`HGRe)jX&TdIҘٟtWaqy's|oUCxzcwK6'_U"?\pau7 }8 ׸@d />O, ^RGah._2ܩqtALhzMl@Jy>hIoB'!Z 7vyuˋeDbT마_XOU`W@27 n3BTv āP[WHmwtTl}<׃H+Qe1) /ImNVٓHZ/~> DoTڱ& +f/PO15fbH{Aq*FaqZX[x HƒA}Ĵwtt+~[?rؘTג.tmr<1ߑuʞ>>+3>Z+_^O #ݨ-pc܌亱q;)PS! @rj5مd;@O`))PB3¦rRԻɑa0}R=QAtq*e}*/UF5uS;euyBTA}ܒ_ WC G.X!-i~eo@`/-K2Kq|}UocA(g$,H(X/T2#B0T_?m2 CDkP^ms' XEyB,R I#֑?8P<6ǡ| 3>jfit݄>& b~V1>rج1'/E tE[ wHبCo*Z 5abP*ȓKQygQ+ cF9;Np7ϛ&` ,u;aʓ}v aATC ߲{ ͊=L;sRW9k$,R Lvき5ΰbJ:2_u BX$cٍrp[}J/L^xh yH[)sN9{R@zɲ'3WӠCՑ`n 㺁4N]jG҂mo&Ѷ)[^\gD,▧岝y^+- OLA,ӜBW~A8-|".H"bNa jw/A6αUyjFF4Aon'{,ׅ):1H8QttsyMha7ʓ8ZK-՚|:Rػъ.Y*a_ yUh]q;,p߄cc3^U-1@-튝=_(5p |6"^L2aJ#a9!ACghތ0ÿȓ7Sm6ͽ-aF o8kcτ/ӑ14mhj=:O:EK%H[&ZOr!d̈FM߰4<N 8X~1g9xvKSMq-Q "b p tp=)WnHyQbC8ˉLnxҡLiG{>3_f#uI'}&&U *i\mi?l(7X{Lu[Kiq^ (Hn2̒]"8+%7OT;ni&Rw++OZ2AIÈq`SxM.DMrӘ6|tPtQAvV捇;H~;4{(ُ,FrC$BKňO`G}+c@BJW <ԠDyb}`Q!AvA}FLDh'Wqxy[V|7g6FDfY[Ye 2S[ڲ#OŴ)w!gM"=K݉jUǴN .tHBfj L+! 6a)47de$ .$,Iԍda #$fj_~谘ql6/:`S06AUV_!L`h`VY8;Q}G &a4^/sg`p=u+ȞV*VKy1$zg!S !߂Xzm3eM֦*Jj7-E?yX GHc&]r5.!?Y~tF 3fh(_lRKXo?+p;05za;`T9^ Fb<~xD2#8\I$GU/hr.]YCp z?Ł7M  KLuny45h8W ~tŖF*}XR{)'Ir ՟"QoVڄt/)=lUhS`"q]Sm= YdHzU`"a"^,ISO> xv K;tS)%pXt"VUX5=}Lw.-ԦƑ4zlO ߽,7^CeܺNi_vU@r6D_I',HS%k|(jj?`kRB~a߹zE:E ]\%~&/g?R/z`S MJ~kaOkԯ4YazrU LLn+a&o@v$68ՙyv~U5bLuE&z&fNm*[=7kVh偱~ ^߁ːWn(ɫev׬ -v8+~wB.=Rd~_Sb[Pm"B|s*4H3$+1Ɍ{f%*յp \.%pM_IDVԕ{c:R+7A1/ TF)&-c8 yeb<%k%1a߰e{Lb|)D}T&S”PX6vUGd뜅ϔa(0Ƀ]~n)fD12^L)Ay}`F~0@募~ޜ  M=XZjʤat B<]s[8ۙ+kY* Z2lw  'ͬO"O8ލ=W0϶*A2lCv}1ѹKe~"l7r\ؤI4•!vس]S (?| w sBpUOZi#o|R[1d^Agg##L׼InK,~ 24m0vd5+`2<ܺó;\څm{@Qti0>@5ڄ Ʒ=jI+ "cQR>ێhNV BD 8ڔzxuGM(VAw>KL;Fk(.V<fML5u 4{Y<WI$oQe ڴ:YVg$2HLa|/-UZy0_6 J0蛮0MJ!9P!lbhԬ!|}< ߓ$L VD(*`םKNQIh:\VC+Ÿ>L;?VC {Ȧ,ao^N)wƱv_&"rUXԸ %pVɃqZM*L('^YNĤcSJSH}X =~?eT.wvl:3 Pa.7RgdL/|+7[;85v<@pƀ#ӈsSxaB;E};;\tMHͥ4\LIg] 6)~O#c糚T.(oYgʞ,!_R7eid$`uC Hu5L;Txx+r40g, &EvlnʸU`N>ꢁV"AX7ڊn苴Qܲ5$Kۥh/^M}t>7\3-wGkHBuTW^qG '8Y^ćMa\?4$| oB _-Uξ@SW[  G$*Emtu[%MAK *^xqV%v!(|`uᢧ͌Qa!b5FmtxV\<場{*Z@u‡M{y<= Vߧ@@_Md2gkaʿHꚶ_ؕ5&A}[bww$P M9v: aVX tHMK; B`?N䔕X({^.RbZl)N9i#gID(2#㍭xLrl)Ћo#~8eFNZBO3K }c];Ef +]ֵ!4Qu#TEfNw]ۆXGl?۔qX t 0.6W9&uH@- $]s }MyͤۥBӝ:Z3* Տ2a=A€bIarB7066V_H"1I vHq[<ο-'dyd_gz!4^uX l6z?kLa+)|6cg_RGykxZ{NU ꀘ G68`]ֻDVy_ Fm~r7g FCh1@o&FoV$qARMH3Y' b.D`B8Rcsx1c%Mu{73c2=e FڄZVPVH{}XhnNen&\&5ܭDZ۴†ofn Axe`HxJ@w.wT7׏#1 &T۬iH`667+$˨HbK+ ;.2eA_\h>31hc0- jR 1+HEBƆRں 5S:?9:堌o]ʄ2@껴 \b+tqQCNaa 9XXQ9vWvN>i猎r>H};y;݃LfgU /Ta4 ra{d_,ԅEnن#zwR>62 d|kHyuY9>(etJwWF b)I.RG u<%.?8t|H q|܋&k|bEoS$.w֏{%HP` ,(Xm n<ӋԨb1~/Sq4% ѶK Џ!OTZ#{[CmldժiD,fȃ<- Ҹٶ%|Vv3&v]%p%_9d:+ӖՔԓC!gR=ίk&70_TieBl`Phg @,mER+,ENO%R2wPW )3ROK5vRa;Bd띿^.>0s=ބF( leֵ}}lDB Du+rztS_m+A7"Lu= 2*vG?_fq$%jJj^l.HM_K@a&Z7Gif[Gp0<xLQj (>撈rN%VW7ˢe#k}TiuUF{D;

ՍmC4`?a[_o$ LO}H8Gs*K<Ƹ\ir-A/緙z6̌ D# )N/jjR=(٨U'1DfQ1"pS$* 8*P<ٯy>?}UQփ$)w07Ҕ>7hEԑ_=SY6D6"HpXnPKp O\63Q@? t%ryK$a:7+(^+.<il+>%1p@WUދW)=$7 ﻼ/OE?-yEnj$RM vFem;ٹHCgd'@2DHH5L F#nyC-/.깷0G@*Dե.%j"~Dgw2)DS6g~:o//VȾ0kT]Co(ead1s՞ u#OC wk|)3\#cO$P>t8? )}1V@A}c!>T[w- e ˘hs O]ZVNc$]^RP7D5u hRk%No;pw[tṂ H rik*xMeU5 TH4=)<{7i1$?JFCmիө7 5IbKXq<4HuC'`8‰C86\؜5%B1( uN5[}?ƄB9:T :0cJN%kU.4kEP~{^7pRbUwUtƼpr\iTc] d>֣l+?\|Asm.g#36͋2fn v_<4*̦Lfq 2\I{]]})Ƭy'5>|eR‰UXA_L+E2&"?}_K_U>#<$*J/|(F?WydSD-8z;ޜM&;O>(Z$j aaeӠH濧Oēr6oY Z#6pe[I$bc%,1CM)!|KzmUMD~+2" F8"ۺ4}y(9K$ _onPdޫcQs( Ci&$#B-40X! 'f@fpt2UXF  RnO hV_}OD?Ailٙ&b❟\ƽ>M[ Mo =rWKNǿ?ܿ ]al6po-*| sFe:O9`mg2OŠUac+ \d vd˰a\#ҁg 31>8mibr[bonб]i^}(ȿ=wO^T,{ gD_zI9q%djpFnl9nx{ |2j2Q"NI(OE~~U;!:F`} 2`#K7'4bigR+moD%Ve2BWtE=grl}gXIZ:Psw| 4@ؓ;MB)0)=y2clMhC?GM@"L3y#j D`6ܪ! Yhqg{o9 \\Y@0X.#(.cL)ǡ7CAdƑ~&4a-w+h [McNI̤=$NȞ9dܩnW؆Cė䇒2so Q4ތ>z/Cw8ob|9yo{U% "s`[s EGӒC-\pu _)ssW@Sȃ!i\Tf?Ϯ4GCmTs5#B3Ce~r,~YploB%#5|=hÞ\߽ⵜа*UiqGUIG̊G kΛYx =u@.{ |mݪN5_0FUZI3l}䮉&Khzy!1B=LO4;<0IT\-,hto3JuDK{8oJ|0V(--h 0J%3JvT+*[VN؁8ACȰ>ja~!#J%HTf^cN^/5vv-S#_4r*)nܸMGKEZuWᵧR נbGdR(I 37B>8WմӐJxg(֜:@Lz@Pp.,:[sCT*r~gi*[:uߦ2-@r P.ث^Yz{YU/cՙZw4+{nqr/讂 ]nD/dhO5h-ZDQA VUa3>IWvߓsa7iͻGc9.NVVn>KԼڼVackaIfS_>iAaѶ+/Kg8 M rQJEW8!yaHlN7yj}ʎT/vQT(UtKhmE7Y:N](ShD$wCgJ9_K_3yv=.g dB#`Q>aVLxB0s|nwT _ҀLQ6W㘴TweWGַ#vÎ"'Y`˃sx jv4_sޖθ(mq *S]Gl<W f'nV9îR_Maʎ,<4J*qDy =>`/<)$G L;ZwJxqB?Iw$ovSS򻣍F7da^&1lfEe]E aW( IձH ^7]Xp=s 眀ȶ/%AR%nƽ=jhb2=.c!):INϿ9/:#Fǘg AeΔU9;|.F> 'Yj[Hbح;f~-ԗq*qEmSR*VFS%dKx]0ˣ*0=񀅖_zg%遠vu{'bS?"ab/7q/VfMM}B̘竷܂w wvn< @AOM*Soc:dHj۽Ih0[(C? Y)cL׉اU}fy2wңrJs3{`mL1uR{Т" _ "0y5ǡG `8eIпG k!x5qStG X,r"0$as"V ?peO赛U!rlW֦&c$qIwfF|'[ye&e@Q w0a=nA\s_V-%j&!X"5⚱/5tPN繍BIT2 ^s\͹ =&I)1]Z7Kؖڄh:kl2 B;2,$L/gDi ݅d&ATmv-8 EfUg|)FЈ:qo)* 'aRIdSm4oFF>p|+^ſ5._curQʘ Jf }C >?!~_6"y|Oy\T(İ;fs.&i& a+b7] ZYp"KrSSj`4So+*Þ$o05w+JB,KMz3-`HWޞaDʍ +Kb[)?K6xWPHA7ǚ_*5翧m6S\1wV;z:M-uDP\QV˷!XAöɲZ_rdJWFCv (@7З w>_W#Y<7s\WQLf^j(D̼쇯ly3V λL-B@*4"  :zl᫭?__24tmٲdNh!8ǀOO8w?sJÖ!%EiE!L G&j'ڨ4=?~X$ Mb6 aDZaq\la/u;Ҭ+ J̝|>y;IPh?ڥ{~[=4 l1[* %czaKd-[ wK,-ў%Qw^ yV =ac?Zf8{i2,*/DچIv`аk$8[U`j67W)'7ꡎ0AAWށ?l 7m=4CXy{ŶqdW|,s]ӲP{3 tna Val(!a QCLP)W͇x&ZPe<1!K%̍!FEjŸb-ɟԻpX<gE%_M%.zHw&AcW߼m9X `G@)㫫X`M)i kE-@^)rAզ:jgy0F3C$* Zy!{ m5\g$2FsNkҗ nN+.zJfsT@jh3فY{TyҸļl;&s %](zZCm%_Ȥ*{UY6lh[}{LZf!G bJ-bsԯ1-aAc=[WELG jgzC%^Ok_0`Uh૪Ou?=g!P^ .!eLB:v.zaˉʈ6qO"͙jP՞,/2|B;YcoZ(rZ}-6_Cz(esӿrPp\^C6|h#p"K6$_=f]6%- =Q8aNҹsMX\%%,~ lg:\לp8zRdM:.gʊ &@MC]Woڃy-mqMk6_DP,^XN+HVGP_yETH].t`GЈ#ũ`E^-% 96*:6O ]>2Hgc+tbXu<.8KJncqdS>G/?F;4ֲd W Qw>N]dh jKGJ=%)rUduUhNG1"nz]Q̒^CQF ("h Gͳd (؅ʢRj S jUvo/ "y x!o IoIEP(( v*†zZh{+[{kwMV 2)eNcx)\4s3a]>)/yXХ.0 پ*KAOQٛǎ/Q [q=߂&)e Y5oL|gۗ?9œ냀'Fz;n5''vB:de5]L!,>)Ȩ|_B7S}䥨&a$GMf Ƞu^e',.A ]n~ܸȿcx3M, qaB4GMbY]X0]nvKzOd}֓I6 @Ʈp^ПwzA/<*V`@A Ű8b>mhaYzy8e[ 57GB a9b!ЪnFoBfS!N~AM4 ?>g[ƖoiCMHX]\9 !zvKWSq~kaO 9hYi>a_=u'8 cCtH\DJ.OnlPő1WKՕqd㭅f^4(G:u3>*a#MT"mdKПjR{ڧ 2Cxc #^r&=r߰".T-cޚh1Pս"&9F wM{,ۗZ4{ԩnw;U`xĐ0D#mO1Ϟ3¡ixZ'])P v < "q-wY '&'o=-k8E}fSF{Oaw{rLDb >5}ZjL_e91Iϱ̵)#f_f1=h4?~qVF} S]`ceH$~<ڗ#ևTtd7qSB;0Xv8` !$RJs:݅aOi=!]}mMߦ 926CSpX@tꞰN%;CG4?8v,!S9NDTRxz"FpX> .NON:惆)AR Nnƞhws%]^ *l/?y٦ @˕^EL8{&Yje"DF9򥦤bڜG.%#(Qڧ Le*e4ػ/];j1CkSf"˴>FG/Exj^w(,@)[dLi%hU2l| -V諧i -|}%,9O) pI)~t5p!E o/:'/I/{ʣD!V5>Tm4#)+>|(H&n9HܼW"؝+'󺬠g!g\WjW08LȻwO*x‰HpJ~ 7L:<\9£{6YM| f,jeo"/ dH6lL3[Vt )~+R~| : -iMN*-x)c?筲oOu.3-M6FbgC'|o\vCB4DBq@GMFx5L\ɸLe&)GAh@$'-[Tݵ8MBqAc#|ˬ|~r!9[6\pJu~ y{88hLa)`=@TV}12s"sÖ3j8nڡo} +r}|Fkl1ԨT44OQ1ǬL3(3c]YJb,!~BI?=Of$#:clԆ lXQct5QS߹)kO09z#3j+1_\gtAM__#&kh^w . jeѰ.QO.ɶ~dҐ8ʲ #Q/$pHb~jr98we3KTw o\ü9v y9;)qސRjR@ $ fo-?e!4.]}vx?&F}{o+-l*~ ܘBJH s,vmtJN1z}ةChJ}ZIĵ[h)B'6 =F!EfWDMbEuYY+G_+4o؍M{s_eq]9z0Nꉉ'97׌'c3?29cD纄zAR!7612'{qs> );L%yW9C`D!NoPeF}5 DX O(P?\C3ٽxĺf R [HG1II,*PH eRn j`fKV՟56X]6]P0H<{ocl i(rFH C5Qu4Y8A^NDkm;y'&Y2; j9ښ..MԺbm*5e{- ^ 2=ڋG˫d(xWNZ j92߷^Q *:X2yzW֜h> S+b[s#ÔrSZc=YOkib<{nN%r ̌AWa\Z5{fMj)āU sKnAQb.2Hl\zYk%!lnƺ)6p g"M\⥏v:ZjڄMkj9s.][ <P99TeܬV&K'cޒ 櫟KJu<܎`QgQZ@#?#ȓseO48hDzj_Tm=P:k{6R]C5}FAEW[f/ft|~2Ɏl WM+-.B|;1>c{Q]g3AG4>T] eݏyEmUQqM.FsѐD}~GP 2LYu&^u@8!ɞ.%)Gf =XEf2rZ󋄔*'M1 cm|l[u"9;oBX2)6=^ lT2P8/9sJ95qI{ױts:49a(GDGX,  B;NI.I>:˼\H:V,* ;>wD/*=ʢMd A!.6xuV-N.j)zQ0x2aiQf1-H/ FUtV몂2Q]CDLQ}JYpu^-1bTIAu奰߻ [ŜMc,)Z ep9_0v ea`x>x.a4GpȘBS'M [ڎ!U j5}O4s~NS1dxKLaI(Е& / %eLK9H6){ ilQUMy0j"[̧19mK r1j:6%)NBiSB*)c^`4aC8Ӵ辞ëHaU]m7°3K9?=yPԭPURroEwޭ6!zE+g#`* 3ShAǪzAؔ Vs% ](K HWyT:f=)E<,L^0G+!(!99i9Y}zcql*hJydDɀLdMtxc_7{:.!O5Y=`ߪet/Ny?Audb<)Uagɴ]&UyR]]{opֵgX.o2&pVpkxZĂxV%/)k_5M5/7yq~کf-BQm: AGn raS^2BOURg%KZ{ojof A33YOiz r'_d[{ :ec!~#Ê.KvY )t+h0o^5r~ 02QZud'ҏ; xDarq2@u̎4 ~X>Uu[.M!O9:DL-?oKE ;L,eH|2ićۮ c^9x5cgb| .2ϪL֠_F^ENAw̢X.~<%snFF|5:;}@Cmi+gy=?SXCct`9:7=<΂4I!+ m ȩf%u9N7*VS_ө7Z.F؋Kf=tLn{<8ac_vwYBn|:d;_`LeTMUP2(tZj0G G.d83 Y"+Sڣ«"`IxZ}- 5?5tc'@|j<Ώ|:<=Jx%vY蚑2e\N2RZXjfkKN_cMaWd٥*oO!C?e|&0$׸q\Pu"a,Vp "@JA7@(Nv=py;@0ns"aI 4@9JVEUx}y<U$ ^ wKd7쓩4AIE W9gM 1D4%SG1  GM5z^euG"~,ghډ'Ŷj< ttt++TySUin(igSX[1 _)Q حStaZEd9&V9s3[eb#mhҡ$Y4FUJ6&>6H`IV]̢2qS<\leha0[`Xu::d\vdzhshbsf"ڨJ-+8,PGB:S%Ooce6I_@tKByr4==mK~4'کHܤ|衟e,: %׊a>Z̉>5Z?y]vvY޲>܌~>n"5*\^`=n=d;\cAeR:=s"kiB: AC|#U.kF2T\[[;䋅;L?c5|t ҷY!=i@s9b裳ơXo[lLd-ŜBfσ_^&tH)2,yUj7\}40]*ָ_oS]x8Fky9e\>2BW/Bc`]䩾ś+.WA Ƈ/()W#U@c12I`Cλlg 9!V"0@iA993XeB XAO 2g @Aw) t}8{_%g]  )V9@o;0ױ97 D81lNY 2^2nyϰ<˘L"҂E`Y;cP)n4D7eT1٤땯eZU1k  ڗX!UN#ֱ/J}sOI)b_AA)EzY ,m`WwKPC?i6Č K~`_ TUnzĴlDZ Ss˸)~E ؁ܾfgݶj P?&};B 1Y7!6'ZXU/؉§h9u'4,u~=єX4[NA> hЧs{~o:,V5:pmDM HyWkOTr6RV@eĭ?ۯj,6j ezoge~{sݦ2g(~<͵\>(Ǟ "P|[< PV[`!Ie|f"ϱDPW# em. o|{XMt-`y[2RYRxӟʉMʵ8ϓ}Tmۆsʨe~P ۡ` 'e[hӒ/y+zׅ!?@RlVeř<8|k+cXLϙG:Y`$.VaKbʇ!ƧRfzN?u*~.r乧Y7Ey {/g]_{O,m;CW'Hwj[Z(H_ 2*xC pvUmz%g TxATvK0[mF6'E ezOymz9M l\(Tuz䡅T!?6 vOABfg>J_"I{xxsbv ]aCke |f)7A1K%OIm#T#6RƲQF`d1*JEBZRnsD+lANj9_ڳٴsN+By";8g،鄢*[k$/RH؜8U|4R=Et;(Tߡue\yG{mm8!?~?[yv~UK޵l0],6o I+ܙo 6| Pi˹5G}9L >=MM[O:j_TH639̪˻&]yqMS_v^@"S F݂,%LXYbkV"8dA&7a~$i{i^`x@9,gLEݢ3 ^$m@X4O$K&:u5G*HcIsHa2[Ds{[BoވO;mvH$<]b!f3:2r5Lu21U-NtYPDZ0jr潭~yڝ6(802{}LYNyz 9 D` 0;!M.]m?q<%H.XQI>S,#@5{l6R=NwW#=S 2+^&<ƶޑ!Bz{Jp(8+p>ASci_jqC>(0ĺq(4fy2al]EZtfoa V@IJpQ%rbt *y:A'fM#C.O8CePa5P{lzЛ?sEEвGDAw$ B'{_&K.jKm#D'T6|Itk( .Յm+,;JjJˠ#z=aНQIfewK D&b,Do60=|W:_:Z8GO]uD Z(7lu{<>>0唱wG+SvfӐ}[Za䰮N1qNj%<{iЉ`.6F)e cKs%;l,CFK~~jyt}lCǪuTXį8Pg1Č(hG|>8I>@wX64lyI @@=)J/yeXo9$}vm0L_£rNw~csʰ4>2xVL_8@9U/m1(@Ieq║Q8[[:J1%өӉp+LCVKM2*ޔL騶5mCK`tϱ fSJv*Bߴ:n?f0Sw$rgnf*^MZ1ovp󾲪{]Der`HՊ\Vг*Q kLt{dny"z"IQX8 :S~ O=x@C6df*PiҶHCڞ63s 0&j }ڢ>,4֪ƨccJZ4;Y(|̔1l}ұyO2#\a'6`I97K]W?<F-W=,s|Dud'Tj_BtD= *Y5:1/R7i6 ֭C$Mb\)؎ͭ,%o5"sቼrTߑny W9>1jlԫ2$ikCEKrIglՑS.IuX.Q]$cBΪp+k, túdPK JĠCK4U6V3RI?OS*xUSI%PO٩^ㄭxD !z䡒dB &_nS }T^FdeN]E\GkZƗp29)%YT&3 '7֗5Ywx6ߔye)5_3Hz҇ rG+$iYvyc$)cVc)Nn7Ye||7^Q0\ $nJ$5j{:iQY)&ڶIv[:hyqZݥNLt`3Tbx4HKcoxr$yS~X ^Z݃Ou^"rY["l]uV$ų x_g|jeD$nPDG*l $j.Gr}FKJP/,S[,G ,Mhba̅ӫNeMݩmf"L9H!3Z8$,s?|ќ6×w9ax9:+~̶tP]0 r B{#td->:͐>( k|Uƒ.Gp5Q7=#vuG#5@A"2AiBgUm:_G=jG.f"yՓ0DXo ]yPzo=Bx.*AB~VE%I Ɲ_$I8Y|:!>9z/ìfb€BbNRpƈߩo(/m@yj ^Ymsysic4o;ۯ{Ly:ͱ `fiXTY]б9 )@.}zYKk5=hvj"C%fѷoޓ3{UVEc2;_:!Sܥ$:E]Lp"m=ilAÂDu-aʣ{s9*P{ܹTWݞyȓt ɤբ"M*QBJT8.,c&\W`h~/huͲ? lQ<|nA8,WYMKMDX cyKW ]GFthPU'Ku7p^zE*C7̀u7~V`VHtYM "r1=Ir, 7_̲w"EuPoz<9͹ֈb n>J)RMr*iTa6 n}z]ʼ*^8R70Lԋg%@D) (g2bl!Wbd:43V;XS;d> HA^8lB&,Bt%W7HchmNe+XHRq|f&r/@8`\2fg,} pADׇJ;w!_$F=v?6k]^ZTȉ:nOY64&2^#üP u$ܽc95 rBo~- }BH"gORcoYX$ITcȭPdAUzVZ$SD} ,*"}wRe;InYTs{6'g(6x @qXn! =?+~y\k;NwXf5dS}"_ٓlvTFKW];]QXńtͰ`;be| gBo5r#_o8%!t{=iexXP~Ezmʱw89˔5xqv=k@_ʒL > d J"7fK<glv{Uٺ,~MVq;LĀ"16_C x>TFx,eyRU#TvkX  ' nAZ7úp]Ҕ 1n5{xͨ\񿍓0FOh1x(0"<6ѥK(;#7( 4 6Y7Uv;|AJNj%oFЦo0,4*d V :\zwtW8ߴY=Z*ƥ> W+sNGtܻxG!_Cf?Ze r(ȤH@%R(u&o\t2V +ewe₷iSw>P;?^8nޔwSN+GX-kdl8*p|7]9/Rx?nv8t(bV2eB7vȐzm(ti}p.o:Ō;bWq* <ӏ:!O)g7 X+l[|P|q顾E3[O|xni )8Ӈ #e T;A~a%l |i O||GJdn! 5(ȩ<ށkL4@2Hi9S?LB{C,}A xs2 hYM, SP%7-<`hבgcz09VU{z#߉UeR?1[nKM `~ a:ijKM~ mؽްi'ƦP7$yʑBe9`Pq("vޥ9,>U=Xj[ R=֋iel6 1(o6/!ܯAD 6;[sei,]-;i y>iof |<Ջ7~j?4N991J9clz)^ԛDʳ=Фb!*`,ZM{l\3ӊ\; Sv+&)sĭ`P[+\dsG:ӅvN 'MVl pI !0+on}>'RUſd2mRևy``!3pP1$k%#_׀7*.'HejX %r/b^ }, T ։a+^\j?.8JxM֘*oHc˟zc;G$sA!4Fpd(9 bp36M b'! rO$̨N'2wW-R?D'xy,#S%*m$3ᝉu7\>xMq4n䣿ih[yWjeU}AkcD?IcBF" ad\U|" RfȲ{hFcG,ɔ#_cW3o(};+N?lӾ~C:޶DzV:rFbv(EpȨɦQn>[ 'hRds[<1JH;K`:kd"2@;}f[1(* jЄ[!☃r>#gĤX503] I }XFX(6" d7;|$/Y_F$g=?coaRmvO55m+sw`Ӊ OǑUX4蜔θA O*EI45ޮ!;k0o']J]>o.ZtևZo}rMm+)bl!0ȶSA?; Di7-ZqZ<(Pq"K`V6M [2N ']g*<#H@&V'aJy1 Rc/Iz՚CgQi|<_ʘRKR(y^dGR~&ᕙ#Z8{ľc٧)f,FG`"mR͕d ٱV ~aNeZ- .0jontm :n ?cQ߇ÂH&>t†|jLyлԮ9o7.GfA"Xo ݣ n,C3dպp8"-_^Fx` 4H8FXڵ7{A2:ˡ):' $3$&"g,O쫛 ,x2Ȓ ~țHM-=V&pK+(2^}3; s'3ӛ60;Bid $xQcQCPKv3QEUY^)o'+;VGYi\t9#i Nks :rʓMMkRY "0 ?P;.7zyEApd;%&_jm+}t? zbO,j\-VuJ@9X[h{qe:$!a8(2X-oAiUܙ)CٶIJlO-EýA{t҄ȟɹ㺞U}s(7uYS3=ވpHјk^=5Z8o c#i0bUv)IOv]FY@~6)Oj3Qkx 0 _ypo_k dC|Su:^Ӡ at߭NQڀsy+y[-^]W_Ci]谱Q B3&ky, xoY&b1&8;>3pȵYA/}/Cidq!!y`&*gKog𿷀V؉3m}8ZݎnC_r)@Q+/|o[P`Wpa65K-TT\X`s х"NJ<~[.c03"4F*ǣB9X ?iM鳓}<6UXGD`og~NK+|6 ~,pJP)x.YLC]ۼ/m̗_#[J+ؿkp;ݝZ((7PƟA5]dyf(#̓f2"<\R<'<>63$Ke"SF0l *N̕0N$d {f %oTI6F[:^<@IilTUtaʹ%3#V v eq bRvj{e ݳriت6f㋹G! TD?ߘn$AgSx+=gLRt5[O`Euu 5_Lw/ Mw~Ύ ޲1"wAHh+?"_\W{gA ,Cߦk,_4][ ɞg|7,.\j!H)mh3А2c2-H`d?_dlqECY(Orܭu/ GYϐB]6Pu*[̚@=!NI>u $2~0L=:&.#IѭK3B6Pm*>K-nLD[ϗ.TVEr1Ýa8BE3@F,&,8wKm~i.) Nt.a9ˤX>f_ԝpdc{S˱,J]sxXt% r8@[^īpTO g '5z!=Lubl_֏=/)Ϙdaa[˔Wt(h)ZkiQ!G͢FogñCd`C4~fT`5 ,$S^v3e?e ihEbʹm -DWE}Y|pa\߰'@Tu3@SA{5E ;CVU:9_?W<$61!f # VlYp/2u$\Äf"f1&oB P窋<u,wELAZ8_ :~3H"7 gyWVff0Z)cw *OѰTGiF~azs,fɍ^x$a8~| =589h5|?;nQ9>ДE nCq\`b{BNVl{2̤4H?CYyn*ZΥ~_kK|=]ET~e}Eѫ0/1M>b/}#Oh%EHK+!Woq;'82;0G_eOi@J" 3Rړ1b#n ;=h.ӭk _SϣڒMԛbᑱЃKUg ov֡NӍOaϢ H"߸,qj VUpH2"p[&'ۊVukV#$"y2ЫP+n'mqQwIJIiӤ@y=vRD~W-券>xFד(=?NqqvyoaϜQ%!V݇ uyrŴwѸQ|X%˨ya{Nӗ?H OZPcE֒N='Ӛ:-X U#'v`9'A)ѻ EݴX-jxѭ0;C 9ȉ4Oy j#TL֖h?uTOwFM"jS"ڒQr Gƺ 95N> P %쪱"~^?o ~މĊ Y祽1/%HS.v{;1v4u_6E 8h"Xڼ,{ ZD$!\.(̣XbNNW:/,q+T6@iYHN&9@;~0\0_r#̇ڤv:1/N_Z9ĘB6=wZlU1K%Ѭ{C[ϊt1>B"ٙ"L&Ǒ=%ߞB<Gի+q''1WuQ:9CLjsFפ{zQDvo.˟n+-vzhMšuM)$4 ts113H6)\=,~ iy;7р C,uLÎ'B`sjGjfgk1+) c.r^[g׾u`3oy "ضc7 - or3Jp`y7DvvA s6 S>y} .KȬfnFu$(=ktcaivP qÞk^ա)DX:p7VqFLB~'z ,}10aL8S,`]:LMѾ%_ ]PW frgWCYq[LTX o5kwJ܃)nh$˾7ckVa D?ku{h 9I\lEV/ه!+9t[ƝW0 X_!$_﬊-q:i0qAXYmtu^z00<_Rm#Ԓ "4zJOL˥8Zg F2F!$W/1B7K\)f nhܒ<S@,-Y=,ˀH@vŷ LNe$dD qt~D\I1jH>kJox#$cqd27mXժ"AB1sXtt*pZcbME>Ըcc/ WȼǏtiƫo_ I8۴߿Ʀq琑B@Vd=B;`]2>iQ!G8xmjO 5΂)15;R'Ot坬1oԏ -ws >qMHe8l{lXY|s9 9ãCT$hh:@ n ?C!=Udrȥ`h8_"3Ų&HLUxX(෉ (QʸL,jS9N-d=rnDϔ_z wPnNgO: QՠQѓ8QR;?jVgEݗW\Y Ҟl8 */Ȥ\} mt_/8.& g_i:0ܙJ1 :}oE>ݐq˻R'd~qښKXuy'E/)}5kv-E^Q-g]+՞b0&B8{S%x4x;Ǎ V.vP<: :0[ ֔ "3 <۵'bcO@t1*%b)jL<t%E]13 /x}:]w}v9 BoM0`kղ''ۥ}~ck7h'kWΕaDmݜj!lSȳC*K3.>+ B$G =,TXtr4V Vԇ_&:}&NR^`\v:U-%}")DvWJ H5̚YR ' JGd{W3,}+LVtŶTT841an3v#*/gqN@eϬN"ƺF{~[YʋŔd|ׅ$@T &F{GzFu@;!0/wh8 }J 9yEk rI:D/ |(RTG`UxN>?6F$8qGw\/$9Ko&tyd% Y7|etIqw6fdW89xkDf}M-a''ꗋ#N{ 1?9ks{'R8Z>lPs% e%ѣu%1皞 I^omKI0dz*i@byx%}L4덶6bJ,5H~YsICHs!{$ G&_}L]@+xŵk"pRjáX PdҺIN,b+rHr ;eP5sH"33 ƟݍxGT#dZ)WZk\eM(dS=sp*(w7=wа"ۥ[s#lt (e+7xSJ^}Rη`F5}*\ 5K7jS`ob]Ka"[{{JVthhP:6M0q;,W/ A :i$TYGIjz[ K)wL9}LΦO_jTZ lp: >vn/1MP1} ̧.Asݍ.;,SY@z8 Vx>b$ /A E~V6Q6'ukǖq bcoӝwkxڨPҦb4[O6NZt;"i1%'QQ>dt=ÜQ: u$"NbfYpLaprY礛$H~9>@ͲqW%'\,fxMk?H՝Z%# >x[q:Zg&foGxRg-b5Y&[x[ i"Ҡf6K WL[ablf"3>*#ׅR`6yHso*4xC6[=.(59ۀ<0dUj=%;AZ\v9{W>Htv7M=%T0^S~' 9Yg1AXAsPu8 {>4/wZy:|\1#(ؑzqʥ +b}njɨ..&7#.^/n͉#$S b{ >03Ȍ\l=8[Q$1o3ң10pU"p6égRglDa!VE !A XJuePl`Q.1J2>K 3"\vY=v4GQ=- đc^q#G- '0d̛QuTjn(X wԖkH % *rq,lBvJv<36\]vyvkZe֗0MÃA$EP0b-$uMlz&k &gY)PZ;fkڟdk=o@ԦB"-^S\]'C(٣|*gq?IVI}PSI;:+Y&8)*d:M_ٺ^4e-'>fC"&|[kv𕋃g۽MB4J@wE7BWKͿ[qg1`vLQl]6e'G1߹Oa`.yvLR<F-,D :n6,f ǭ]o YbU\,s.#' R)A.4ѐЌ g}d>VC;gJxiT-уZ+qPγyj\ I.۠캤l'{9W(pN!]VQ_LD7Z֫ӆ3MLb|uךU@^&`zJ>HV&q^i8hD20sY{WQo)Җw? QjUG׻َeRc4r ~Ҩ0(ӻiS V?ȧx&ƘCKF6ţC.FF?RR~`.d87Dř|V͆V7oj Q]BE, e,;nD~_+3ޕquw2+c cpd 97tE&ݮ6Χa$wsrYſwI .߂Hk*S|tzl/fp C%S[JQ} q;'E9tF , cLhaȻ2G|dwP#/ppG7/bwPՍ?p R_Ǎ؀KF,q*5 ˳h%Q?TKX6-z lVܫ #qQuȉ;&$!nM"H`PH)*[8ch^-[)rVz|Udz"icXLoh#}j,*6;A71W*T+ߓ%UA4,,{>dGRJފ#@$Ĕli9#?zLM4듲QH | 5)Zx fPdwgNSp^Pb6NهZc7.幖?"ɒ\H@#C6Z{zV`8naqX6QsG. Ҟi4b"5#XAY(L5}MB K1&%Ȝ=Ot,v,3+pԝd2ucހ\A>$ ~bNnN) ^1)(~ T Z&j:ۉ7nYe'&wIՒfc.HN]A@1$K;f4t)A%սU)^YAa`SyOE}v_`<LWYƌKC`~NQ''P,ç T%CNrpd]]]NT9rd-Z#QgL, Z)[ˆlSq#GW)xzVFѪ'Q}-ݙPhh(}L.R.>5*iFnnQrmQecX~HMJ=&abjiJcݾ+>v@$&#B#DS D,͞V-I^!" s%;T, U5u:p(ߊ}8 ~9k]w*o2-hna*8ProW2T\j] R5P9FWI2\ʜw)}Ԫu*B[ ߫6~qt,&+EDx {rAUC)3_*1P|5}/tG cvz_q=n]hhDZa[?ZV _b5፨~8dT 0DGylŅ$ 3WH)>xgJV8 崁\r>* W [FQ2Mj V5 f_Df=M, Ip9ҎΟLǵ0@}܉A)cku;ĸvD"/"Wٵ:չ>汈YQ,ȳlePF7CWgA]g#ʜ+H_'KL ߼F|8k,À3ٍ| qhOS pّjwo3'{ӆX]mz{]Dp~9' vӦ zvhɦ9Wl &QAM N KSUEMWHT&hawt월=B6HkR(v4%NH)Pj#ܣQ4,҅/7^:<: yE(:bիk=+SU|UBua.FpĖŦRL踭WQ7PQ:w(R?yvr/UQzaR{|md63aj3uX ǸV31Vy9?0DNiok:kN4Vll Z?(K:C)M@N=6L%_tmtNrPH[.V ў=p5&\1J}Zˤ>N|Oų>xY7C;y:Qy3[orwwË )f:$ŦMNQ޷~`hv\-הdB0cWa#OL ̩B5?ʥϾR)u~p]Bϧ E"2uft=)Ɠǜ[ HsGIuS6`m./`–#ZK?w8YlV!B]d*=Lnh98!;k/\@0M^jZ [ns9CPwߋ@9Y7O Ah rO5R^= x-f;a5p@)`ai7ߝ`_+g]4*w<ȶDyg~VTb c=-35kjgWH(7a9DݙS k*'e 4^^:&?coC0rAެz_ o() O/H#4IhNoj?K<_M}kFԫ8 sGy;)nqy?}&J '.PrD=`.H\ܚ!*o1Pݝnwc`(`{{@q;FkU13gQ64~sn4v.6n!k%I(PL3a0's)KO=3@*f@UV-q!~Ww.:;JoTp f, #z.L8-]RZ am0FLO`]Pܲn p624ᇀ$ɂA5Vs ^(Rg4_@,FAoό9ݳ]zBoVu %k9;sxU= Xi r3y@`G8clbjGdፁW:x(\W 1up\=$3fJėX..Q>Mݰw11|}jwSS6eamUmnR3Wv\ZI+ 0{fd]Yԯ ^ _S=r_I~Y6y Nb^ xUMִy~ Iz$7z4xuNzaHbKƉeS٨,lБrw>-/ݭ|jh7/#FkPmW^(GZdvf$> wT_ E/Nhi؁sjUaT.j 3 kKĽRJxg^ɯlbeR.1J̷tvs/Gرvt4]D؄DZ7c8Uj}Z74׽DiSCN?SXc?+ +jpGK#Λ(RW0SL R𡋶Y났Щll[=$(,&>LH 94 2rg6O{ԗ'a.-& T \EP8"G TKxMu˲dnRD?t\bR$n!8g[ {8x "us-Y`(o.&q~nbp[N>?+Z9q×'ݟ_4E/6-\gPS%h5Xq!\_n5Oڗ]jb" %Ho'+R}hEeˆrݬ KNGu{)[i`iUwZ%9V3%q艕^fZ˸_AOIܡ?'K]r#XSxM1MT23?Hi͍Տa׍EoJh& 1xQdTqSp+hJD&Mefi |;:ݔ]% _zS?ƽ0_)5rmہ)W(jD\{Ux6a bqZ"ixX鉮e@攘L>b;Wl9SCM`xqN~+=kO6,[6$V9Kr}13~Ѳm:qy9J^QP_ i{$ݣ_H?|,0~-_Y=$R X9>;Im7q?hR$ն3C-ΌN3|c.GsiUs6z|f*J[GaVhI3!Ll`-!|tZه s4YJu> ,1u$]?L߸7w`q,7R rEj^V?" Oƪ%=^ۢ% iRcB\-^ձ̷jgECLlRz.AbĢUNbbN݀c8Wk]P$ ozj} axn{[أXJ'7.`FSr0F]t咆=ƵSD} 74Qۆ CZ'hCΣo 4p=A_Kέ~ B}57Y!oLNQlY0^ޏkrQҗ l 7i (3H~86JIA̤͐Ä@5d%Dj fgFxW%"I]H1\I:wn¿BJq/j iRfs͆4 i fg넴+[iRn}Jqkp)ZD>:*6x ,Lg+`|.We::M0Yȇ8ӘHHJ ػOEW¤I^ӓKb܎OŢ8 ҕ/uD&2ZpAX X[C)$^; @Q;9 c,wS;^|qdiJ%ve:BXl4]iWKB`EzښT]@ @. )?G*Y8=eܦ :m]m,)3OE)^H ,!vKf^\ge!Cbj0^q_\"mm$XiüJ&(`v]++“,w*UtG}ܴe n6GM/fPk5rUn<;9S&T83,:v LoN.Wh[_u>W;ڴyWRVŻ|Se/ D@yƫIeT|c e{r{v|><ݺ%2$iY 4-䉲fQfP$#bDOΥfOM| ͼJ9wd~oNfw:10'{XZHW,y=aeqj ΁2,^7oԍb8_"GV ҴЛ 8)20 πGїc:OoH<՟^!\^F:kΝ (Cέ~ޏrx@PX(6h)gEQסʩraWwY >}R{+ >?O=J  GJHu_G"7jX{Lwoz,JPON*4e^ 烽]'BA8hP3,1y?pd b_=uW 3u3E(as)SW~YX dχ`9('2 Onc2f$< B&!dXW9=qCeb+0(MW;aS!f~jb5Q90iy{!5^* :rE`Vк-><D]@pI1Ǿ⮬ $W\0av! y C5!XjQp4/m"j#h;13ӸM ҐΒt嶃Zfӎp;VFbBֈE9!ZٮL3uYQSV?]pEi\Eo`T h$* A `q@޳&C]],u*xwFM3E(?Q\>TCt52Aܱ~$n ryV~*q?J!aq@i4^ 0W 9= ;BzwVOWM @jMĠU=j?]xzؖqm Z+S%a4DQX9u RMXV-־ _ AqFE}gwqdsS"(|-Kc~Ou ZVW;e52otb0 UAȍJHj7JN- x+Ebk|a@)TrÿG]4։pg#1Aاԥ%/a?,0HY6?L4-GTksdT>ph{'ia(oN%0rbR19qYC [YzA5hzl)~H)JXA>dY}`3WHcyt|J^نϒBSzTN*`Y0tĿi wo[uJsahjC/G1K6υn) +?UIV%O:q7 H B)F.[jH>D8R2ȿ;gʱ)I^ik_Sg:`ŜpÛoW th̕1D ]8:bNdkBuE9#>mjHZM߉xk`}%j$!^e]g3Յj S F:Nrgr6iD(f_gIS,# jK-/0SOsT,} \پ_`cLY6n 9򖦀 zQ߼ݍߠ,GS, o]E8i}&ՁY,(ۣ,_I@psz̈pYц1'v)ڰ/͇jo MwA'k8bccv. Uȋrq-2'IUT & L_<(6aX#8Z p$v% xCf͡~-@#gFDVcR qY bRE;0t9rij13lc"D +khe-mg77O==Gmb#D| i"/F)zQ=GIY.P ! @E,މiyͺQvPoh^hg88t$DH Fb W A2lIsadcS|.DԂ,"[AB |0Wjܭ*i(e,Wߗc<""%׌u:/xqן|<i{j|` 7n kMrGf#BB=JHWO|9{zKan@y8Tz17eZJ!V_&FGUxX$ 0`=qו6<З;D7Yh5[Yیqp;}60˂@&NA.¿MCܴ?"e^p 7ݒ>M[-5sC,S92@g84 ?|ߵHT,鳭|pT)؃K}n Ằ]KHXzÞKv{kǪ!6`@I[64ZƦ._w3KK-H0VaYb=c?WneQ:0e OlsvY芋uu"= =bDȮF%K%5uKSK%=ToLUqthp+ }^^fuɜ!|cyJ܃܄*MжF2y.0"{V/rA< ,-UR \N'S(- 7Q3!ȺvuZqw(/]ѩ$\HӾ@ 4$= m ^i/J*h#Pp+5'2̿`8:NеtJE wQ L rĔh~ILo7Jbo(Wف)"翕8 `z+pn&uUȧb kŽ+=?]n>"wV#yKiv䏂=و(7S#B:0oHr SWu2Gyט}GaӯJBsБuM:IHn:ulzZG~(-84`H(+ⒿȪG5_WY%ÝmzcVCy{3sT~Wely?8oINKQ05XR x.^x<ˇh()&N@.9ĕDF_Rses"ne<˯(,p0<UU}T p}ra</62B4nۡ6KBdɗpmU ALsAw M×Huy}@Au-jOmgoI2<"]n{Дb`zzZ[CYx {NE#;m wwD{4 )&pUXݮǡd #!38f0ߪ0lHJ1Vs3qȹqrCmwD'rc&':Y'ewIU9|~?sggR,ϼk󐋒+>4y)Mh&0am낏d%v5/,8WQH"/oz! έfJؽ`w !2ۮkٶT)e_먏;5 b~{Ou<(pk, 5 > "B!lsUtc˦r 'p8קԁxtR:W꘩/x>u"/mA]z89s~egyl<|y6Y 53Drq!:UgĹoW (YsqL!8OMnN%@FCA~gGmp< I٬dn=O<ő̻9d;7s~uě!$;We<%1k:3B HFj_}U-SI4#;y[LY .I4$^D 2&i"6u>vȈ$2'Ӿ+txI FN4Mftb 6g: +a!(>LtE$;g:ǣBތ$[5nPqt<:b8z[LPh߾|zt͈0Hk|DʉЋgl^J!\\=R$W{YY푊ZW;A(H'QO{^]2F#DvsٹPX@s6)J8wt|Xӡ*D7$:s&NM~9M=HW'N 9"#m &/mB<F4u&hQO.;?;B3XX8F[~A#rn~谒;g%1ϡ5+.֞E[x~9xMO}7ٖgjf-ѰY3nVЕ{>FzwJ:nߧgy_'Ozi@>v+MoqWS_)^k5 @ }4Q~(El: ~F  ̑#gE&BP^Xz~eSEq=igK]IPb DpΟ=߫ȇg 5\h:k`)v3Yt.{a;45S$Qr$qh2{-PW: R1t+au#%١`o((}.. eiYUL 8Gk=5/&ALQTjۜVaoŠǩE |ʾʮ`:!ji$khmNz[M6X+^̎XFfw$ BauȒܖ{iV;AX醂&|s=Uil1/% """3#?r /cG"Y)~1KfEY*O -g}i~_Eee0 Tck( ae=nF#ɩ~+Miꈍ%t١W~;?( Kne( Қ{P7Gu Yl fįlyWpb)w)NN~[ ;Sbb{orQ#쏀J;x E Jq$o`jlj.= ܙזt1ی w nضzn(8_ԓɃ+ujmLN̪IM4IWSۉ;̶aD'~+{^+bnnj `q@x8ԧmUx(l=]u%3uV ھښwT8̿j"Yi n{RȇMɄ64jQiӪHgjAi,_zqcYa:cͮy)\T{'Sv#6dlTFԈskM|U1RGވ~KC͂péջ}7\ETmŻOFZg{1% _>:JqULCU&NLDx[j.7M_d~X$K7x(°ya#jq9?OC:ܾD]kZNeqtWsj^S$(B &7< \B%L&,#FC3/ɖ6ߕXj%qh~$7Ig̷t7'9j`U\3`QMaXuk;qTイQd'9&ągzλ?_ZW]q$cmڴ Q . )T|v!`WGϲU3<2D_8r#5( 4 (HYH=8DodqJN=8soEe=WDi}8МE%PhԤ-a|H% GxZFYEdvDׂ@},!_}XX45bw:IMQq P2ЩN,FEgn*5FT}0jNBL/fA8|wFۅ77-ΒxA??|-H=*Hi41z݆K5|URGb+0.H_"; AEV&Dէ<Kۥޫ)JjxlYq1}o:^$VM4L FxSD h9,M`H1|v7 vAFjaD~Cq8*ʓ h%(:.w~T)IPRJg K#QiT ߲5G@PO|)o$n-T:hbِknZ$D ?r &'ePaG 3 qh^^G3#&TRV.6:3i‰ݯhlPԠ!Iːɔ}*aJ5?1%1NK;AIx.([[U?Qʻd R'vg/UEz94 j[PS&TuW}?p[9Ě֡tL[}-)@3 LU[sN^57/&+S`5 <]P2Ax!$A,ٲ,)W"iⅎ]$gZ@aM[ *hh0Do#W T}:b21IY# 7MBn׆Dn zQ~ݡt_kⅮQ+_{{t_}_jLnQ.E~J ~ίIc Uԯ4mAh8jDԯ|ՠWK dPӔ}fU~m/ ^IH bQi1?p+A=A 9Saۇff_2'--sQZ%r<V5bDl x"@Jm&dc`:}XwgTlU(9LxuD"=#b8n%' ݔ[f@\zUW(Jb·$}mzYE0p.docc@QdTnJ=%+7:6)m<7K uPHZ|v4i&mӝC2&db`uک_{Ɔ+Ј[ X 3NJuVbD1kܲp }E{vg㿒3l>S+C)mߘ?8ϟc&t O.<:!$pYtKduqj25ꌈ y&7n?ns/tL/a[i'}UG\OG4&)m#T³<G4E=RADSKqýQ;UP1A8>;Vf8ͩ}E{AO7.e{K&;hͭ3qLX,' ˳F%`1,ioǸL7p|ZG0pFhgه /`7M|I9Ɖ!WqLz޵bTk63t6f=9LKD9sOce*߇"l-D긨(s_!}r+r(U;s3?nsvU0aQV= BE/K >KN, o?ѕnc7Ii\ŝ>CN%(o>#l`Ś7\ũ`/oٮiF9 ٠ָe&N 'O(m.cZ`kW2b!k4>b (5@#o\оt*{PE(D ϑO }d Պ`s^gm W 5S̜~P`.k0P 9;8BLuR۷WV`*F˟`nu+Fώ6StPv>͢py.eD39%HJ4y U/Ls; >'}rΊI Qוb5\+ye56 rvD ѽUoag>s o^3t;W Et"a%2Oe`֌ Fủ*8g%`z8=uhPOP[h$ kDr~LouވD)ZچS1.WIIq?hvXqr! OWk)k#1 F^O"N4PP46 aרJbR5RBsFNf&0 |rm.p G@"7K[ۊWTq-bԂ.W!M $k jTdɈ/1&EΣ@0 ĢcW;eԽ'pG^ ?X*$Q8-.?T鰉C8EYI /!Q4No:K1U!']wWD!O4Q!;&(HgZt1SUGMYhԈdz-V bB20cIo6EAt6T-eugjE˾Mb ;=)YKؽs--4D ~GX ߸hsmxKe73Eu`rJf )6E*0KnBz="u( [y?LVJB>;g mn 5wLBMYe=<ٱ2K@G$b/CCG'%wfE(5EBxT c5x?SvB-/A.|{lL>چQѺ{=tԾFLVVk@z>2C匴ޯ! Fis%` X ~\jh`<̡YL۪σg$&soXI8|*aqK9^n5T:Qr. ->СihG)"a91u+Դ@ZL1$ҷBIv^umFa]%Opw n Ֆn'Nf⑻Ns!KID2J[tږW9/w /t~ K!R4X㲢eXpr (2!YU}t:;w̽U;(_w df+)V֛Ec% 9)_=a|>a V禗1vnby&BdݡV=ZeQ%PIf0h)xY`(4q>;2sk T9!Smy XO3BjYQ"jSLCcIQ7UuO Ɣ\̸ETK-pk]骞Kv] X~IsPXE`YGech,RVws/{1 Er`&1R o[gw\0kSRU1Ģd/d {ݯ^F$vP.6ِ*=X4.%n}iOy±`")PqMPuEȓV<}Khb = LF/A (jh7?rYcmO!ɷ~Ӝ?fC_G"'1eP=C?&c_lx6BogD^ETOŴP/fXV^B 9G3x)gy˰;\$0̧[NRU̻BB<6.c?6&[Y#e 3n]|/d7L 腾'jx_#v+4:[Fz (YS{,{HWVmLyѝW^]Q³ dgh<"ORS=b`SُnN%USu3}*>=VhDv##ņb'op0S{.$*u-|\57,6-fق\^{RݻN-uKlN[W ZXXA nɨ>y ne GJvaJ0l%ޫ55 q9و{k~FD-f7<*Hy oUD@I"$6EmevDS߽"L34`o$еoؠKaY$>tUPR|dS˩GTz.Z|&ܒ.Bԫ+h~tdu%z$55jmu ;) -4 $M駲3&L0~5գPZ,[Rw X8:scug#tȏlG5b6X >`6p1%@7څ^ld{7ҽ a )x,2DsVw ۫ \7A:T01zLZ'uª!C9B~`gb$Hx՚(f.}qYɕE~OG75D4cNg \z}0=zďwB%=?U(cVᅐu4ݼ͊E7B.tRw[v8ʫҺ#-pPKjtS sUq.ЏHMb7~/AV=$hy1詀K ֙`w.FkF,,qrvd]6U<-Sz"k \pU0dv:׷YwVn};r0eY̕bj җy:Z]pX-F 8g퐷,7>5΀pиsxT^&'_5dqܝXiܕՙKi5b01I6V;nԜ r%1^j+{2=DN&({]Y+x<}.,*2@CGN 8B';D!% A.CxzToU͟Kፋb3G C5D8Z&e^<~H)fSAʼp2:@ )kkvDVtfr;֞p0[15%n,/,6*^k2Pfq&؛)Q=lFB]/v9}*by"@)QkS[{iyzL1s!_v3Glw2w0e)ܺw wV3#e3?+s 0?/0×-P rqӋ.wzy 7RE'%˭eQ }rO%Uf [pc&*/ŀp bCIy:q?@~٥}9t -ů B{>y Oۇlo1WN?k9Rl팬Y6+y tK l#Rnj+0J*=.-mX iA:|5ar16>[|=Ĉ"fjx|CS*Y4CgK gʃs{m hLelV[:.\wzV\(*i|$-}NHۉ{-ȱqGTU~wWѪ;Cٯ |Ε !g`2)p[Y G"msyİ=xʝw/Ԍ*3FC,o0enMߌRL+~4JvzYCW5*D|̳3 :_ĝnA;V֔?ś$ȵX5 ^`Kk66>G\b:}#I{l vWUVdȑK<T>"eֈ<u/we-:Rq*/Y078oF%~F%0RE3F=I˹O·ϐajOU@p*WP>$+X@җ3[<?Yc5 )hmye'֬i:6-\Q{@s{i%<5> pp!ohQD= yhiFȶ{>+9sN >OI]ahWD"zI OgSJ<Vn )ύ@$SqXаDGT n"Y7[>Ge3u9Bc@!W5>"V<]c:9]o@9yIN,թca:&^ւC݊hא\̍wpD,;'l-%3`85i޺&JZ;4Nk @c]k6Kcr33m9/ڔ>ol+݂Ɣ~$Puf#оӈ4X!`g7L4L >Mp1#F<%{##Wⱎ<9'`S]jl7SW2iΣϳ#q| S4Mg R^o+^`ﺢdh,t NґYdp2gGD$$aR%@19I>:@55 :,%tsw7Qyw'SـaQ ENdة`PY,/vҶlSxuLH{fx{I KH,>ʋov~|v~Gie'IFlv7$4Pk\<v! Zj3&M#Ԝ}{>ƹ6t;'a}EM6i:^;)w혮 csNLEpے!Ƙ3 r ߿E}.| = f~ d8J?n4A}hL#2i4𒧪l2=[:鍑4ER !yݚo.cB,NUK4czl) ǚ2j:K'Zbsw| nɦlf^N)LLD+ |=F_^cef1!ㆫbBw&܃*!хzc슟:& cɥ$r]o2L(H:ky A^)xIX#{T*Aӟy;s8WfqZɶ8u|iXZ,;j^mD?wӢFw&rŁWk8櫁]1kt3I6HĊC'J#~TT^8^v8I܃)|< =eNa-ٶpb}EAL|T\g|DW%&rojȱ_Vr89_c<úd,Ymb(-KaA B5~c9c U޹AA7ikJb,00X~!͛^E4(?7t=eGwmDҎX~4/ҽSn߆츷g0@OY~5?Y{iu5_|فj|*Ld54kփ*g5p= }鏹 w@V8؇]ʹ었Fb9^vٗ[BXIO %L>h9e "J𢫼t%`P/W-zˡ&s*a+!RmvDU?8nT4^9ieY\# m2"eϺ ;Ēb棤buh%_d gP"~pZ1 "|pb5|uK&!6|Q _W9 VBE8uU쇏˴5jWHtQvRX MN.=FB*'5ޟӈtnnbY/OiVxGb/c 9޽w4{kGȅZ*혴|{bInd"rk%-L;Vd7F CRc8J}zO{K쉵 2elyj縉=p&x(CXnSSk\- 3{j1TL eJ81ɿJyp07mS#HM,޴$*E8b =`,_Ԛc.\ 3ځp4Aao3S#VhԳ 6dlخHuMEdRP+l@lr+V% R?1V 0R'X3_{9l'N,^tA| = ȴ&(cf#?t+lOB {1&$ 9f[SL9SLs@9\ Ԕ-TV<UO5)Uq9?k~ <_&W`E Yw;..mZn* m!9bS_ iWp)>IpҗԷ%߯<(kzN*!fwvx0eBn/Mz#,`C=' >oi0jc,*|tXy3mKPh)] ?pЧ>2D%u-p|N+M>E,?.Pjs>X27rG&eЄ7su`R{h=t}S=6pdao](O]!ƿˑbi'-{2 [,?> (mqD\;rE:v Θ >9h=@epo"sgE1h>|)GŽvº +Ry;-pXvݗ/G6h9: M켠ձ_UuмBd6^e`6aT(DrLy{6ǘA6ƥ;? O3ѼVTO^Ϲk;^?Gz%FdZZVh=5R Zg= Zu,z. *qaٳLɇLz**4bہ hM^F]Oڄ:[uty+L!ΉKkި.L=zD-(Џ~E>)bǀ'A2^vR^6ɾ>r[8?UJ1qb sW_ TNW!J/ Lw-{IU%(ٮ $(7 D];! $-iNH]4~NP>leH7\m9qzb6\|P-.1K\hL%7L0-qOzFҀF-Rj<I`v`'2c"x >.LdQV? d4VaD;( z-2 0S SP}#vh=}FmwpD.gDquҒ.GX]WOz3 V?LݔbJ|%𱕢:I& :YwO8eulΙ{X:e玎ɇjtd 1-$+H2V\]2Q|54L'ͬjCKX &BJǯ! 6KL8GG_ 24w1:R'SҳkLdbh;rЋ1 q1<1ZHml)߱/+OD{倠 |k_/sܵfŸ` _T/ZQJ"0<}(.|Q {S$@-9Wi [?q`ez|tnD(悵^6G9ė̋;A,! 7*G3b:L`> Ey3n  պ Ϭa "J%p5;9!r@wH)ޡp62S6h L<AB< ==~mK"Ga5|ѭ"W,R.`&ܛwKKr'^.'*9R3d O^\&%.j?eͽW#_?Kx?0&CDZҊH$hT{GT>/r1ԓ ld U.Zn8bM$*c/%ƣ;N>ÐRPBBgN1q{ydi_zYt#ŹV-M Jwv87a:ȋrvn4, c9BP?9c18&"~ OPYSB3}io^I0?ۙFB*a]e1Ձk4igGwٺ׾\̎~OǬrc 1佯rWVDl5SZ u+`qizSJWbTգ%\h,[t i8bKu~@8?۵FAStgf O{B35ce'"Ek}F+oڔaY"ouS){N4&<ޥst<8r+K g&*pF ,Ѽ/5yꗘ0'4Fu!=Ar$ }|?[&$/Cbt׆S`gjJbn6XX[\K:$$#p(ֿF&(oV`Wn fg6(* f=.z %=pNW@E*oQv*uħs+=zx̙ BKqXB9cT^;UwI|gʐ$ ;O--LTG3YhF\2jKiʀ/OMQ h'g>Jk2MNSB0Re,}kM2v ΐ3GJN0 S:>KQ[jZ%ѻpg׉ꙠDxѣp6Ak6,Ϫ=}AJ\l\UcmxwRnEFw--S E" ?UޙX5@;kcBIg݌<:Wm7U^@-]G-)`CE b뛫;"PnEYTX'/RTȽIܚͯƫQ+&!U^YpgL]>}9U0Ԙ7:tM:hsk䍘?Y)l?!3"#1@>gA*ȑ!4̬<`J&шdӪۑ9N2hlqnr9]ﬣCC?hNBY>cѺ;iɃi}KK3}^>|\=g G>$Pe yk>e)g{XkW°-iVL'A.A8CB:FEL ?,f[="6qi6~[<٦jrĜ^ [.p@z)֒+-[ZByo}8bߢ] ՐFMD)kP냿ڡOkڴeVkTHy-mgga12%ug ή^[G)F᭘nk #{t {8e ЖHPE"+;#{׉γ/y: LD r*jQ0Fʖ|;I*N!4փ!񙕜n2C?+m  ȳI+lRy{< ]=)EW aMJSZd; p 1n(nS_ga=tMKA]7TPm[Zin)ٶ )szX֯|=Iύ~1<X=6O4aeJ|ԝ@X pX J N1Z9R~]ZYfpI?Be 2]coܶT:~BQO0߮Q<غɥpGAEw / 76FvI C-E2Eܚ nsAmy΂frxytcz029b*y1B[׋ :ϱɚssS"dm<šU.! }"j8',SHgs:*>P[ pG>2Y\99/^>=5ۡN?Q NGn&{~>C3.zW# w(H1SFxF(alJD3WqWg[$3ݞ=QAҧ8d]uUM,?99ChOJWd0a+P݄P`&H?%j𭰡AP[K~blmŷJooF%d(q 9S^9潼bz|II<9r 'ΛkϜPR$-ީpFx͹,tdN*Rt#@UlZSeo*B8=T'_EjؚQ4V(9\y %mİ:o$`l))K@M]@UVY{,`i72Bp_'6z)?<'2ZbdqzTp IagvdX_αH0~H>Q &5%\J ![~~bpM$ⰅPUb t-lPCcAE6`'a)VߞFû1>sY?xl_e.+$;<1;C]gN9S`^ŧIs2lˍݙ =Xg3'FRnoVC~!Õ@s{_U\ge߀cI1(UP#AܳpRsv$Pd.8~d yf{#Zs$ ]*"fLhQ  :@R~Ox#frůrx0!=h dT B}F)wZlbUӨ:`. hmgcwPFߺ9 ΐ=nJ2bE4Y$!9{K3\Fܻ8ZW|:SGB3HčH-]cg9(_fq5z:N{~k56(US);"K5}aA㻉y.\\? ;Ng26؎{8iλ wDCBh,S8)n--xS"sw.1#Z4I~>"^()j:2 /;:9t꺲.qT1:Nл.S4-dL\/+C|<Ǒs'3|Hse8i-[kq;>xWF.X9LrbCw)O{לcY#+fo8ZOX#BуLV/^e}V{9wjb?m258a3LqgR&#TXJ_l^"vH ó-ԉ1%9| UG9.Fo̽n|\d he8ɹݑm|cҾ'Ruk 43.'_'' *S rlE])3@FEJOLmYiR9@1בHQMŰ|,5dci_eQB^8:-+݋ôW*i0|%m>jғHڧqAPwuȳgi.txSDN7!|M\ӔlߥG|iQϵTu5f%$D N qc6_ ZWe- Çpvܕ *;~Yև4 9}$ֵKtj5SRFsLltŴ"3'}e|c_O'q%G @ [b5,1mmss>~ضCPvt#&OJ\x؜CmlC&.ڢZs J;̰ ]ʘfִs5:^uTK0%/scD|)BETMC`_HH,J̓Bx,\i!Vg @Fex|3DdJc~-;PNs_!\ǦI-`q`QľS .ɞ/L=oJTV2`ɳQno*ܗ˚T iqe4.< rLy|QǫMz|UV:˟!9 *񲽣q|3%Ej]wgIfg^ Us=h/Ys fxQS*o @HO2;vSFv0U̐OQ}UJ?PyB]j{iS)Md5Q^oNJ.e܀>$ 8Bٖ[T=!qפƥg fwWMs<Eo_[>NunJozx\e ajAݣ QtQ9 "?E\! (,(t L@%[A8Sl)]}T4BDʱpI^%?cLg>Hm} ,)Jf}DGaV0u$.GeQզqb)'jO;q,nACz$3y7. m qk[H&0rx_T>~{$00xQ'gٛ$Uje U)v,T's.N2`$\"6hZJS4H?rr?F\s\D!uf26}̤ãpތ;b^,66"Sctke xCY HۣEPԵAk<ké+k`*F3pB ̶#/?Se=ܢƲ)b{ʞ}l%d~qҴj,v]jנu9+3 !-΄ rILk͛][#mhVoi$Ѩ&jjo5 63(yL_v=ԞEcR/ [oRqBhe{(1{O<^ le:d1=p2=3stCiG+:.x Ao|W)5Gؤj1Nf9Y B 'f|P8̣n:/T_߀E:F0Ѭ2ke8`RsE-{.s0;i~~ @?ojHMl0{[ç03r7)ʩ®vy+sT49ıסl։uͼ/=M%6Xdl>l>|UΣi4W?}On#v"IǝO=:!Z- R*sZ! v&*-c8pmsxUg>e0A 3ɶdςpvc=7÷ (6 Ù; jKvKAu!Z1yȰ\˹<`/ńB0$jE"$'~0.rQ1Tv8KscjBD~S!*m}#̼i VfLߙNIy3!?lhqJL/BIYPuv8"uQ)bA eeaKcHFg&L$V c|۝y'wvfIy*;nM ϲDxSywÚvkcjlꃵCu4a`,:%kB6,H N0mWfjet{ ڈns@cg].TEc鷃Q#>y{qj%S֚3+cۻִ{]+< 6-$}$9SDo5^ IӞ`G7ⲨQ$.8̫(\ OnyȺ@'l 727tF+[x kJFgUiTh9OKfPҋ-?RA2SU,1oגL}*-U8-Mtf(8"VlTßfw/8}Z(Ϩ0,NV^J ѻd$9^`UU&h51g>-Boע~b{u;YD}CϳR|W Y3lvwb hjlF~gG0?E8*/vnjQ^ DC9j%). |pN3.J0vɿDP]AH{e?Ai{O崍tQ)"$VzРoq86{l֐~ _Nt}FvHPeuc39mU ֣vB2@ӭ±}M"ćO<)of\BB+=n+"_&?G}"%Q@+)#$&fvqwm/ u?o~B-}%Թ-OITĥ t/1}n`a!'b<%/XX^\w"*0Y. ϡ\Pe =H"ذq%j!-S녽"3謂['L]859Bi`KhF~-E/5R&CmcBN87wC0'A@8>&9ݻZn 4+IwijծtFT?G`,SEU+=@pqs@V9Wr3vݏoѳ0e y+ l^Yuvk3P %ZKf2@ 3yY%y;{Ϧsu|N{2na| zuYLk&.h zܩ0% %1C寑NG~:VԐD8bm'އ\,x:|f EƺOmmx04i*rp=i.12l2n2Еnr!Q)Bh.21";[3̷%}} 2\G ('t0N93 &n]nv q)ňj&lc^̇ R/)O2"0JC:8 ӐC-^Ղ]_fN&+c? Y?A)HfbN^ӾM3jzAoj z\23"sqOTwҜȝv)Lx HCy ++^iozi#}}xk/K4P5ܶgfY8UBN->bvh02xf,X aP& Ι i8/s]~rgXl'=Q4 ֶJǬg! qd w[.6M3,l~c5TR56BUѿ,K>,;HހBc[SlT|Sh%.!jK:X6k@ZUTq 5U{Yw7jdJR_AN[5`y臀зSX$jYAkƩo?͠vJAE)PC$H͚JNlŋBl0,A1 t^K.r.EE)YbfRB'9 {d0'I²a.H]+MglMb wDق&eӬe/My}GuʍQ,sQ-YF+VhɀU64Ȧ >/Š3WQa*1pX~QS[Ώ 6F -x&\^Bn".3Cr`2ByN_4ؗ2;eNu ^G͡5A<VE~ ' ɂ ESҹk3B7fOi{1&- MAl,7!f}_x-`*  jⷣ4qɌ[SyRZt)ZeEj]sadrXjaQ\A?s0zRD:W92g}3nr26KvO[`c 3IIafxOH;ypÆo9P 4jU1*wrM5kxb*6]b!(W%v%v,KPU(dX|L8a[sURS5{^Gv35oÍQ*05f,cG ?bzUBJָu <4Xx$fCrT,u je>ـ~t#^iL1x˃XmŒr1wJ"E\կb.4NOh]Hj!hl8ˑ8sN+n@y5oPsbm`X`?bJۓsS=a_\p\E%;6.?9zPE)x ~ҸA@5p@\8>dB߻Tl\DP3i‚;*V5LY$>!4ǡf8b>1=EH'+J7c"Lka0B}s5fk-7oMaa?4=SZ+s_~9Ҧ7}RR=wүX.RH%=>qX`BRI8\)@u/?Jfh#VsCJLeIR~Jۇ::&Z 5Z'Zզ/TjnV$\$bkcAB*5#[Mx 'ݔse?\@cV9UcQS ʇzH\փhCd~p賊kóo]s"_tz-Ӌst~fzmȆ00C9P|e8DVbtc#d?z/XIV#c|ݢ 8&G"j@]=r H(nIy,6ػνcC f1mHyېS:Zq?< g#@"#4 hw:wCeZ14|=%RԇNʽc#Kt`-T_;lI ʥ{upD7 day, -!j"n(MqZ,tAKRo Vs$ 9[v^Z:Fm"ZwʅZSNS^ /+0{6$U}n[U@=&%wClxD'_ $S%bYӂ00x7QUKݳQC0 H2OWhN f9s̴FxP<# *LzX_lnTsr.4Qh=b4Oe?VcKKK wֱY8W>l>kUa2tll{ZajOEO(f$  |Rf;^IoSY[gnwIYcF{ŧ$5>.pЕNz|8nMEĊg/_A u̠ҟޝ#E@/o[.[bnxeW5(Z6BL+u=M5:}/`] #!yXrYnɨv_;%o.[4 VS7vAԭ[a[VmY'{ }6>Io^hl[Rr! *v,Zt-9`u$yG8^"/Фs59%['~4 J( sMu_')zJr yGǐG ;5瞛3Ei>a8y#[^ذǏ" €L]2ۤؕqG@R)2?=Lcfo(SmKmv+[e&Jh~eU@%foi3w{挘vdܸWq B~q$F5؄:@vYƑRL"}j/N ʑB9zV@e}NOT_HY1*Bbqa)u}'THOJgRasteΩ-(  `-/)>ˊFi }- ɸi0oXs##٘)Y1)5afUΏWtZ F!0A.U0F=z+\铯ճ\5ZǛYVf+vv~KܗwQ`rykJq 5$8ҜSvD@!śN&zimısq=V8vRgŒ ӯzGQ fo]S@v^l5x5w#}% * L!zQ`}%^$eW!>Th! NOf C+1[q^/NZ$<9e_`AqgUf"M4󙓉UƜ )ϨVOq;W hh+PՑ <$z]RШgkNɾtXֳ.3>ZN]AfPJ$\&vt@ҟ(5!, {r4&" fbg`;Dvď޽JN8FfT]ߛG٭q_͵3?{I'֊\2%4_=qa&/(M8W)*PGTs n abkP&XP^G$5+ o<*|^^DQă&4RIuaI1ڴjIbwlzܽ[*?z)tͶ 3}@cu891Γ2ڕDQ-3( 3TY< 9g>{qC iht6k{}({?т?]& kCƣ5 !i-yxjI] P8mmݷ{l|(.f7k,OY%,UF`/sH{$)t^ǁFG_mKpC>QtBGY }ě<%RpU h&4Y,\=ͅ&w\_U%`XUVos(zkKkk7bxUJo!]g{i$(:U掭mc]/E'AV.ӶNۣX6E"mEPqMx9bfwrAH9@)Tˆ0 bKyrK=\Xb^aqtJg?Ұ#NK0v-31d">l `Z!X\LoZ=A B*Tޫu]ԕjH"$[P;]1̩Gvj`j5BE!2xt[6Wb753ݵzlWsxr|jR!]9R(<$2Џ.SE_9DӘQ4&<\mM,GtR`mLU䧢=[kj7vj; ,,Cw.zD8@gDm[$TNQAG.Cwh}r>+ dX}AǡEM9oP1?ms9&CTf=? @+1)dgә @^ 5|yM{Va-mt/X۫F5BOA*i{ !tֱb LE}*!JcFK3tv8ad"B>(bb)S>Zc0>Y&Yp:ĵh񿖬:铈bu9VQ(YlۀaQc1:Y~DBlj;= Vx<%^8ه#5,">HL 8HhdA+6,%+p N aNnjäZX:rQ;oD"U^6FAI*o#)ku/fN"/͚KD\E]Km\#_MՌ^DR$HkAp3?٧lkK]2R\i.W .6BP ژhۉ1\ҹ:b@evD`LY__5\2 17}FJ_A~y)PzUI| @9~09¥ф $Ӏӑ  PmS CSѵ^P,Z 0D3(I6v7(o)Hn;7Zo8qʿz_w*܇cBNVs f> '*I+C[<2d[9a_ (=R<#Ne@phߺ7pk宔ՇGJ!uyU sEv!ЩBY `etm*wKlyPѷd[ G`Vk@zt8!b V]G0 ݘcȐV $*]V kߜ8 0/sBd .x#臣G;v mj A.4tumoY*4 L3 a'qYj%&Q=$,;V+]A~)߷Y,m L8ɦaekc!x"ùUNM q0URe ݞL ^򼹥7qEs' : z"A)HxDxN_rl8]'5xv^\Uq[Oc|K۷*onva}yCG=nZЄ p{!۪w[aX2c/ B }u1(T3-hMM-"ĨP~mɦ~/vp(g{Rw3lP(Qo9w\L*G@wlJ㮋-0B S ~U{:k@!+0f'L%J7CWuΊu[9Rtr 3sNl;J |aFpFf"3O $lM?$V̀O43C(PΧSvv+w?Ү%Dz% 5]B#ˈ79Ş7(B 鯅ac9K2,#7;DO+b}CA[W@%(ti _=,(욫`&_NJS!=j Z(fhL`@ 4ῃH!t20}^3emd%U&87.{2Ii$JФF)޿-GɅ 0OƊX ҆Y J̹{kHav9MqF+3ddDFvhaqtAUd "sȎ*${ rs])?4o9ew<+p҂/qNoSK0nAWS7cغMNƝs@~G +0FBt\`>\uWTF'o-m"7Jl=TֲmMR6pʼ[G4)7U_FGT_,kO'91whfQf߰jlABw`UH@4e nu+Drjl+ hF2nB?wW9 158ρٍ]8wo@-Mi&9鴇\а9Eeuxˋ;D ng0%CpDФ%j-3WD,7ZBЙW1LYnDZ>8+c~*g? LLOb[YyhT+g(^$R0] .9"7pMNfda_j^ iIѴ(ٔB튔T'z2s-|Ɨw2bBJ~a|rཹX-TԐL&FQ,uԒ GsfsFj˃sێPĒb)dơ y10[OOh&a@ qg3G՚Pckqv̮XV{|ÀtYϢބ)G=d r80D~r%gZWZ f*٦yfmߐodJ`C;f^ z R$̽sD E4ctfˊ}cz<OKi49F o}ؖ PB@)h0z 9,]*d_'/ % J<^v:G9&˙*'ӾHn-UZԕN=|gRBIChcU68p0e䇿 OPJuA0>99B2+DUx*ptZX@qDu\LDU졄d(0{'B{%ERxfyF 60ߒHp[])*)nN OĵTF "zG"pT.Pt\qb4>uفjc}N(S6)n-wʝ+0XPf= ~Щ|g윇gFbOC,f);2b4#H.RAGωAϷCT; !W6jx’/2Chvt4sOט7z:'_CBU>=*dXWtZ"Wc'Hc7cƪspr.UyVx)bPur; 4c<ƢScfyKMmlICCjs(B],?GhbP')4:ŲgxtUzVy"[n?d1Cy~|zua\Rj`ʌ?uALbTi;7!SC:,zW[v]X_.y怽2r!0֦ʖzߙ0D}=XH9A)r %YN;Gej#:rʗCT&fԜ) ;r'u^yӨ 7d,N-1i]Y4 7ZhpW/|~ ,*Ɇ Nt7wOj\K{GÃru?v|A J*JrD4x0eA*3x+E%Vy%3h&,X`W"8q>:2gGI?ܨFyF2y"Q m'@R'>U!z )#,-EW= 0IjЛ[Q1raH]_yh% a\-OFnKT>Y6^T1UPPONTIA6P}4z!$[9$댪è>7[ӓx72Fn9X|rr b .].j٥36Iz˒@rLA6 Hs"3=s)+9!:V~a܌16B/|4Ƭh Vb ʹe+>|#*s 6q9Юs#'T=j"cbsk;ɢߕWC"Ћ=8ǼOaj}CXb_0$R/a!C4J7GN1J 댊GobkI?PBR&4y z#\{%>R<kiq[ Qu@M(;̂Þv} $&q/"t+ K'AGlqUDAX9OD??ͽ@R6@ۜ mxT:DiL>2'k"lVSe:z\q)q/Sx w\m/*fzZOL/Zwj G ڢZ=%b$QJfe)+4w(R{/$ӐhNd6ow]wKk6´j»j/H~rk/^eAjXwӢǍ ɾ<\xj~Klr3rգAJ+7$1-EcޢC RgMj]Zއ5y$u r!sѰ^0[B >YuK ίzR#eڙ2x[\_or9<j%epҬ=fzY\6}Jt#Rf\4H+ PYzmʍsq?f5Ak$uϞ͜krS.9GH ,@o=~k|D1vDt'iZ1p7QPk'wÝfc*ka3U$H1 ;;3 k ^[Us+P`1ZQݣbix`W"{A"j[b#q~Yk L5tSp^χZ&4Ā=!^,Hyv$%RS ybD8@Gv |S%tb\C[w1:V^WW3#Ne i~4&1+h[902&2۷XOD]h y ^OUիIhN0 :red;}6n_T+SfmO;9%a]fݝݏj^.)o?1Tp2UnPC~©2mxv24͊'f ޘHK96a b`Yۿk/`ԡ!ĵӅ+3UYOn(\ivLeHZ56f_0 z X!/ŋl9 6hZ ~P*ڀ@%etGQ;0HpLH7R"u2]oPjpQFz͗TnR}@C(ab-fuAp\`T)f]gH`[Po/ ˵2DtJ)Jg  H{A N[l\'g0UϮ;IJ(u1gLj0 'i=:,Kj_I+Pu/6KcuSA#9Z4XU6#91kɃc=1!V!d`H5v. ID΄q"gH)ӪsnsR[t*= Cԕ2lJ%_i8ưpy ~b);|; Y8URaFD+?Fhpa;j9!'"%.q7&Q8OAʬ!mCAɲr) `u@/}1]TZ[qXBOEO&fy@XOo `"Kƥ]{t3 ܴ8M `wҧ_yG+=mOItKoÚh^[ \;*Np_1UOHTH 7P7)H;u\xקթm]b nLT~w}zo "0 W|ɡy]ڵ*[r}l8lz@ϓV-l9_xt]jZXuZcII0,^a. [V=iaRl{J'ۂ5ɯFlU\"I]nqyDb(Pqdk',dK_y;ϸ'ujur9!ƐLMݔzuczūa#(6<;Z0Faq)PgC8]\VjRyH x1}UUqZ9yc%+ ^1"o (Q&j!1:#hAGƃXmsUj3E{=9XMT[Xقڽ WZBi$՗!]]1^}$ AXE%5Bz}rީ4Kv?$O`7ف ׾m՘xN00QB1Ѹ%cgn0o݀?lQȽ#!愾;t7ZaXo_^:9 ] v#c-~ cC*NA3P͢ ^4ݙY"+[$?c>C^96Z=T·ndOZEJ qXGȞYn,a]9ejon:lh5/"27ФٴцԶT}2Ok-€!{=xsEi@S}oCwӷ'Dr 8.).Ruq|^K/j\ 9/d/F埻{Rqbԭ]0=V4f2uQUXW!rRG>}FAY*8FT2%q1 UB@>3CQ-GKAଌR2T@sVEO@&4<Ut`Foy{}ʎqM9(j(>݉c@S>?%6zCѾ&AM8(+;!$BhZ6"ŤigjDM%i٠ԏ:`E&emhPfk3i#4QR8 W<;n䑽Q2'ӟ؄ B7}hD3>Q C>{|'l bSAvֽfEdPQș'!!L! K:06֤'!ϪJ<O4Xr4 4('& d on=}u)~/!jvV\z5H49sSDEM /,x>B`0ԟ@{5:-]n_PgV$ D4;='jH9Yne\6z^ESW'P ả~9׮FhK$GB"&r䚛|yK7=KiGD'9q5aեK'0.V݃l<#^/Qmg hx"窙WfKkB$S܊qBmMW=ߒPp'mۼ,ҹgZ:7m@u7['EZOTJ3sʙL@A8SE2E]g=Pg%]_])NQp F=Cjs~[Ivwɟ7%I rQ:o81/y]lh#W~BU,a*Ud{r@b6׏5 b~okmkn9ɡ {{s@Up5Bg{t7)(:،^"u=Np QFʟ"Y!;Ù]w郛)wىL 78ͅtk0Ǚr1KNS OoxtMI6U?Ȳߠar#)Ħ WBH 9kAzo*T.#B`AgCBgJ2θElvqE`Z2'PiE?g.W>[3Ĩy.T"sSeL[L6c/Z6=% $gl.ќO];ǒ&<|h{ʯv6 a` D}1#+oeYćH`hsVː?C olk}9D8F 11{5D{RU'@)sUkR1<˱(:#R!w4{3@1Ib߶cdMX~TUFx ^ _Hۦq畜b<1R`k)8N֘5>{;"wK#ӺP(^‰ 咅@N$3ޗɂ=U/JtuuuٕdQm0poa-]r^ߗjQE]\r~05T!_hJ%km4!\[&ҮrBN:|/2Ȃ30&ef/K{qPE9=WLbƚ^N%`՟;4ޕREJ N+( ~PPE90s/pkGN mVi<{+]Srn9?eȒF%&Z\U y&-؛]Nw-gK#bS^gCLc2vF3*KL%>䷵n(&,oƠcǡԔkTek۩X1LJRz;Ǒ_Q&NQ^!Y\fr߿ƀF[%JeO)7{$]#$l?4ep>N]hg޳͈e8]h'c;dzxǝy+4pbf\eDz}a6̈́Qn}s(#^3ȘF'X%"?DC|lsڗt'0k[3zg0(W> 51Q)PkF O@ %,ihi4X5K\,ՕpMW=3wwBo+ll 6]y#(pҳP*1ҾSsPy7s~{%23&u8pՉ7SUdpX%PNq~odU:'0M*,a@vcxg@܉X}'iQh.ޅN i/Tsvh)B.vx[/J^F`DtJX寫WadE?Hv&|G"2mݪ%d.NS>Bl6x 3@krAk&(&B}|GL]Żk0fRq q!3I X̐?rʣvJ!He1 ðN8a1WTo-)eЁG*EGL5P7jE/sOgfɝf>*FrqSŴ1鯹󩙊Cl@<NS\#,9>ʻ jز=̢ SJ |IO`T :?KK7Ώf^"Hy͈pAjE?h*xLds456ԠLag,7oQ6y5Km1T)^/Ryr+}vm5>Wu y/9K2HK ,D1As'..jt>r-^|=3`Z#r)Sk7(bDx׭鵢@K;k[o0шx.GH4XQobrG 5'ͼ57P [0l3^<Ķ/+9ZUwneK0 bCDq>9BKY-}|IA.甇h5dॲ"ZL|FHKULbdɨ3H)\!75@d|Rh9*^Gi׭zL*?r/WS'X \4zBʾD=0O:h{[Z4bFs}AN|P9 @6F ᙥ(g@ YWgvs=uvHcC3Bk]'1y&HPWY^$݆yҎ]xÃB2uKq p'W͔{\ Fmk@ KLUvoa⅔ąA{P$FQ"Ep^"(iBh'7-_ZՓ2VURr[z~mJ/pZ%2uZ%N|x-[B8<麯n9c T Z@\1v-ס_OM9eI{Uf4Pa|yDHxDHSGN.pgʇ'63k6|5O1tmO@ZnP>YK'l$8}2L(Mp[=呹ʔI_1 U ?r FPC=2/*䉕$~a')kSfz}G?W#fxfs雲>nWs=%rzBr_gq/E[S}6;%r ֬&BF= x&-CwoDRjEI^ǖ+i{Gً3 v@Cxyӗ>lFSHl:uET=lև\dB3Er6:ѸU᳓p`{OGp#I?fЦQ,l"<}h]^XmÀH VDyB^./pۤD@+d[Ӈ"rMWep"NN\G&\{VmK1+uqKC3*wqđ&lg`P&3"Ǘ,1B<|9ps- i㶳s?8hVxdۀ! 5܎ޚR$jr}v=7H /Cy,Ź9{qYX95(H`Wi2C.֜t6šCC)ˤK]lpuQ"%mԷ4ہ]FP m-&s[VÏ܉SVv \G.h`̓4#6ggA-q` IB۾qcPv\0vqhۮk=7S~FzH&5jFFy.Wgs"x{"#I q9`~k$ZXOfUJ0ʋ$|wɋ+fH0:2L4z 2`J1b &1ЧZ}]:Lcb&e\8>bvcKU]G,=x>ACL=*5ONNy?TnvKz$&_溑A562 ᷽@Y'Rʆ 62.lt x( u*}Fm#MB(mxrSQK!~a?猆}^Rxfԭ-7 ::P|t<=$ܟϋ*D-HTo,3볏zbw .V, (Ff,KA_+Ou@ Ear|z"\C@!aY^vIVѽC.6XGQΐfmZx^ǀlsp:7^eHp6Q̘Zٍkq!\vB ]p}=`~%zv5 5/[s EuZ;5F} qiE{vhc=d_O$J2㜈6_`ݡ :xG &~)H?5|g(U@6N@jEҝ8NQGht/"=AC(=vǘbBϐ,GbϢ~]q.h5]Bh@m Q e=E璻]w]qFޙuF RYn>v^Si5Sg_eu/aa) ; orEа᫺}&Ӟ]hqQl Am5 e?$g{NtFJL~d~(f\As:#z:A ZH~4Pٺ|͌DM3VQJĽ[f"K?:9 ذ4<;FAФ77L4wO'tjf9Na蠑TPGbL{/2c,WUw5lJL2< nUڄ'f@awS7M\F5gR'XAnݽIܝ= eZ/j%U5R|{1riLPxL|= Evy>"Sǟ wQM zJ:=gڤ"N5vg$B`_1NӮj@b;Ȧ5ǪަoHKh`)/yV*I*":6g.pײë&}K9+")ְNzioMZgg]xxT= 'm KcjuWe-_S\Ae"HQ47C&a'A/6~`gψDEfC-<^, U,l*+ļacaΦx$a~-D˜֯P`x[r2VQ©Ru3(u˜ѯ->? =m6k`vvXN;2J2٣.$j ;cS##[ԛ@K_OKWJ(v*@XD(oۂwXX;yjaU"F/4F3h @TXEln9c hz`l/@; 6SjO3~hW.HN5|8 l0|QౌiH,@!@яj-h7tmul49ޮY(mBN%:ٱory9~s$O.li1 rk);+-ǩ ۴sYg>4j<Pp+(WT}sevW)e~wY‰llN2TgV \y2JB.D 뤶ph r= kLTkO9,[oYڦI$pz(^>^)r.,N.+w'&@"O{r9٧,xa&wnT-QαZuml9 9y&+0A,0Ru u/<èh70zIdO?aupU#.1x[#17>Gre2l.h5eSC r X!p,wܵC@Elͳ CÑ2)wZK]IHuoi>`tFk{m?s̋%P-?A/꥔QO^$.\>J T4:ϓt6%ՁJSj"{:eb͑ zEkRtl펢^E\QϬ|/KmxuRs a5ٲϼJX^6<9=jto '5" mmmAzl:XY#e%vͨA%xHeYj;n+k1,v {]QUGөi)%!;\󓎃h. ݙ{;@k!?uVx b+{WS-C:ˀa~I-qҼ#jw*Bs5<>lس`GwM*[%ftb㕖g_H@4/n+دzJ,MrD5A/{F/BЏ˜ƀ\Z ̄F(9Wq`f(0zzF]L\2[Á>KӰED i*6R샡MCc#:n6,x7|Lh$'57לf^_ѫ6GQԵz΃b詤O_z_Kk]Y}VWb-EuVQ! =ozצ`U xb6h?ifnJ*+}#׷EbxL>de'K+Kk?r@ )q) 9\%0ѱy b9ABb&_X@?TkfqɔE1 N4H•r/M2eVd/瞧yw)- }MdթPS\ҸxN`#fO ϕ%ڽLhr Kcy5(2.3wRj~E 9_݊ VofL)LؓU bSt9Q8[MVyՇ .+Dnyh4 ~άth.J֕WC+rTSdթUQKm@5lDC]j?M:zAΛJ)-hhQf[f)] HiHO_ a*8|`ݝmqH)f<89Y W`|C9TtZ=`\! ߔ;F BE8sDŽ% *"/rFĕ,߉`d8 < ޢG`a>ǂK~~$H1>R9>J0 {AnG2+ Hv$L0ٹJn  l`f]=A$-iqxeU;{ Z``pOsx;Ux=: Yg. S]fw\=9:e2[&&\h]N&J </?ݝo}Rrɚ,ŊCz4} MQUC>d}9g& -ff|Y6>/Va$63=3^0ǡ_ *]Jp %@YUSa 2) 䰝= a7L9G2v^F:O'xg,deW$xΚE8 #H#<+?UϸρB)a&Z [)F%cRV\ZMnXT5;+f$m[RgE T7B Y T,ਃC> "Po kEh>ױgV=B8(\P|MV~qx_aq>n$}PwdemAEQ4"s|O^ʷpy+Z^vIkG2! Sb${sLLPSP4fiC| ԩI˂/L['i@Z"11ImJյٹ*r/m,nC;?{wRoqnv~᷍d̔ϥA.؄a&ʠ_oT9Ph]#)M 5Rۄiat|{%FBKtCY-{@yP#RqE*)~UuYp"Cޥr-S8; t/MR/M7ZlBŁD'#fIz[BZDpUiMa?YĶ3/P;̾c['ACϓHg*O"3XWܚDwNڽ*RdST!_nȨ&O6߹+5űCEqʚ\H<_`gɜde[ (&]S"UKEm:E4%ْ:~T6,s"#~ӘJD!Q-\vM~u.SQ 3D%! 7v;? 6+3kiî D݇55Z+$(HEPnቍS[ 荎RGZpxnc% i0MDrEhlygP]zҫi; DŽCT;Ҥ\VHqZ25`R#n2Jcԣ?D@nm3uvQq8 Y4tUBb4?UЮň_F?y]/~>Jkqi_naL;al!8uJw]Q?,kݍޢ,ANCG}ϛj4c۩lvw~vSPrG"W^/ Q7b`WP:SQM7VS%>]) (0 OO@U ,B6#> r.V kQczKmE/%`TJ4Hyī LF5U\sI>&^h 012UM($q-A"ѣU)au~RhpP+ 'D3]]şz(>o[d3zuY !:=Sc <% ,"W9A]̔fOezN B"UJıִi#)T#Q-̓:7mJs#x<\+ഞ +\s5V> )^q!sj9 o&rV]=$ 1_Ddig4g6-aw\EQ,}w M41F8Ӊ,zOL6ڼv>%D*}jnހDJ:;Rhbd #QMekZpmfB1CsQNG} &^&jTBBkAdoƠD7xIMrk[@V7y>US%x4:[5  Wt&`25e~3/G#K" @NnOGm~5͗lcQÐ<ؙ9r5HX~c/؈cMT*ӧ-2-&x8v mA+t y.DvZm?9-G~(ޕ59Ar]sTb~]kǼ;bigAe(w?bBr@{Q1%!|ibxA1`mleoڌtqmsTZP&xD5hP/)ApZS cڷZ++L]zD7z1eX0*~֤{ME)5~א{Uc_3}qoN՝& jpO'{XWHOn/-):~>ZFƨVv[ӕՊ$|O[}B4)PѲ_^$usIͫDa2 ʋgR^x)P$eF(=Ѓ#T0\>V̓o'o}/Q: j?яՂ0W bSŏciS@Ya %(C`q"ƯIuv܁:e٣HzQ1{~ى2+#ޮcg>'FI2~8inȶWev9tʻ*QG۩\-fJ W6V~`[N(0`}`iׄ#iz&0yN)ٹM9}IsWWM }==%BEf}H7|3yY|8~z;uՔ^=|?Քb͝6TUW){qxOk~ q2j쟛>9nc*6J" _O% b߽D%5sTvM4.}^":$igs2;dR$R,%pK0\gQ7vdf"(=N]6 =TY?h6\\UL Ԡ]"]I}\ך8VoMI 0uQąuXZ9_a7nm%Coͱ}>Dx Ŏ b15%ED6wpP3l@+ %ok-3xNBߦ"VX-o,ōʐ9Zm7EVձ?`[\b+ G ֣OLC7!XW[Uvv/F[#21  pFJIɱwH4rp!<+'+N݂FU0jF84R H̀aDkŪ_6-Z8i9ڸn[QP0˰7{#1:ژWEjQN> 'f$ k{QC%~Z'Q: ~،SV YlO{`B:`d=Uyo)S|yABDꕅPm?@ Z9,r" r\;^_`"QU:`1#d{|@$s?ךxE _YlеG_E,1n/RvA\Kwuaֳ#1ኤ$` ;J[.^|9n}Nܨ1!/"b;/p8JHbF7mDOCIz`GcF<є>1q~B惧tߌ$9* %9#m%- 1mQ7vU:ENR[KW~ ,.ft3ȗglݎ{0Yvl V.MB+{Gi$0.y n!iiM~n͡U K/OC#VPQI;u<|BL<͒,Oպ%41:ED#3A!5F MS[Ix;pT +1A urJ 3A?pU-dk:&`?cgv h;}<%y!3z]w)۝?ˬ)F9N-#bqmT9 3VQvt9|ĪoX1TmY!Jv-f8(FNr}=ox3&VhS;AIEkI [l61]UdrTziڐh3զ8#F`l eJi) ?-nBjuRJ qSɕ{1Q@+V_Af㳯U{qC1.;cFq\^ ؒ:vdfmc}"zcxs7E8R¼h].V*Ow͇D?ZYs6Q# \"Qd]Zgt͐H4$ڇH_Ծ_6.u?G $G Z,ըHo(w6Zq®Zݍ+FBJX%<")N0f /Tu_erd1Fl*HDX6Mtgλ/TRdENgxŸ\zbemhC_Q:[Yq:/THYAX)6h# jrɽ1L9f"C1.. *6ҧ>~I,|Ywٗk'2l&.$[bSY55v!lմ>?7s0!Juk-آzK:;4Vo'E!*ԤDe@ F)qn \ĜCs)'v}ŎĞR$\fY.PŁyaSca9!o=悾$Tk䆿7Y|)H}Y4WiE|O1tj%Eb(~~(\&R-Iw(/I"!cT:hF|+5.ߕE1/ہ`aM.qag͔>LWm η0ȴb@Sa5/Qdn>").M_ſR4 aH8KSH)knBW#PdXDٲ: \ G3nl]LhDMj*.lѯ:>^DTتNpMfMjR7W|Ae |S4gF(cyD`X‰DA=?l~yږE5P.הtо2cN(l-_ޞζQo]"ßx R/_-%Ǐ(эh?Ώ24z*2;xp\ g >n_MY̬9lq Tz-1h&Q"=^X1!!n70෶4ƻ[ of(-}!`mHRg[0R+CHv:ME KN( ֜@TZKPLLL,*NCÀ O< {_\he>3E3:oHy| xءu|?B- ;ғzXА z1˗E9fm4$$}/"͐v)?~+],ـߗnj T2L/%4'AQ㨈3x V[ H(پtYЫaq].qD3BIT㍓0>6Bf&Y3uwOvֳtLCUd8& bbս'㔂j&`+u@`!o_U M"}"x,m,<(I5BԲsd(^ [YW#s̝C(礟8- l^ʼDcTYQæZ C)lb->]gp0OB8:ݽ׷whڳE 5]v0"l<wTzbC-&d$̕rc˧` 2/{~2 rifl3|*$rR-{!rU}%Xׯ5;S&:u '9+ln`g;:y+- 2 @_~?}|QX"[p@aH $K6^]fk@iK?2Ge_uI7YO9T(ڢ07Dɤi?U~ydHje6Y,=FixW8ʝ,o0@Xq.?xmEV z nh:.O;]CG(#Pl=G(@Glƿ;oQTί`M0Frz)PG`1E=r yL}ܗG@g1yM8qUV+SVIpTpbb< e*ڣu qmP.lMR9\٘P k01TqϽ>ߊRdZ#!Ll]14gY v"Q&k|Hz˜d7y4 #M>u;1{*=rנVnmho,;?V`: ~SB@oR7Su~y a;(6-(/!ę60G#1+7e rlN_&٠phcXG)ErI"gʠ74Kg暪CUB= %AP#HI9O;t#C8\>W"FbIR ^H[gLB,|p]b7%Wt1w|he|,,ÿ3֪hɤY;9葉E4 O$_& Y:b8KfGLL%E+ ]}^3w^fU%?Jn07,tŷZ@f^w+i縮 Z03PڠF#|/W^_rjJSlWts W01ek x-"`ᣟ:$4.wur~lm5 SrE<^sACe.6`IVO>=/aJFvxrg21 ՘9fdX/LDadg! 9"4ƙ[fiH-]U<喯<+TĈ:eU{yu/ޯ.##?SivNðt'= .4v~\μ/B ReC]BctNqK-N?- PCJe} %9H"g6eqcjE%)\5SqAP"$C'lg09j!= KWϣFe_3f=Bh`ex?5ʰۜ5:0.fIpOl>>eŁe);[1hpJŪ 2&iTxRc) Fp>WˈG`zO6l2&헅e{' PA~iblLbTT-I"2 t_L1A^hN|ʜ S8dsӅ3iw^kT,/I{q7V[ dH\1 F ۽##{Y5.AΖ$L8ؚppilzd %C(3Vb3قD< ^ƈB]-vָw#?rH27]o|^ntF2*z|>_= ZT5 Os  As.js}UE4&aҶ+4`)' +ˈ$r19&Fp bfvNf%[{O{.y&2ǒ̈́a=w| EI !zyG/W9P ~P2Vw{$MhDy [}(m 9eئl&qgddٙ6cEYA2f̿ I$Hq]Yޭ!.Tb^tH˵M=Hz!e\ܯWeKnB\R9ؔE8LgmUͯUYCꎽɿpgGFz9NǺ6+:oX h+C7- tlIb'lߏiS&MEE#dYx=lY'.).1Rrm 䜹fQn1ԾJ)8xuZXaIZ` ̝@/sȿbEїtcR^%og`$& %/V #HM zfuch-.jt!u6&d{WnhAW{EpTBل ,Geb|5۲IQ Vǵ /6_eQ =G瘹~{9`uHY /1m*9@ec8mq8~)JirE$lhs&@2ܚڜOT+.rt(rM; EQ )bLVK|c #"^G}>ɎVd̪RGR˅)q$f}BX0 1 D.G6[M&$[*OEhPBfl vnO/%zmY$=bCQXF4Tm4*zCD%~{ȥR_)MM <-3hyHgj21 >a 3 _'B6<.z;+**w 5t;1-cPivf("\J>%q@WdO>%DYUq1$'#mT$PS}PK9Q2nv,N.C"u:˞\6[8 FڼbjM(;EɀS:4+6r[ xA_Ύ@- W"PWOOoQI8U`7T'K1saةuʥF,i5huBk Oh){BAJ3P^q+ BZSEAeku7z|@譯*'?e$8&*/xs۵ JNF_trhXjؤNo|MI[Ԧ~ 8ɹ^\\!)ZTAJk4BF^ӋNp\aPvJ?HBc`^*d h^Ei8ָiPe "$NF !M|httZ;K4*:S\g[+r!IkY83ɗj~\H-0P*gGSx̃seBRVSȀF6|eAْR|=迡;<6ݝ* vv$'5$OхUBI|2x#p݋$3] ysmq4jB{+ә=G'ԟqbu1  H u{6P&/eSe^9hM ǕUY:[7 %vl#a,;2~auI~&">7øߦE *3s6"bCU`д?orݶ ivQ'&AH]ǷDP9SshOTzQmgR VJKS}P|?Q(^Xwb`{雿  G 4 0ٱ!P⣘V^G-™ iT.f6WC|;;ؠjzдed_Saxԛ1ٛX(m1Kڧ݈Sozryh V66]*$BCX;YSjObʭ% M ʭǯk[Biu ;L7@-^jSN#=*I .FI]XJ(i^J#j`wc[U3qd쥽7 N_.hS]z4@k3{8[nk!Fk:y7g"FUL{2>ZS?]3 B[9D싈ER<:W$N١!f҅P>V-ߴ}$_2Cj5/GIUmM'phㅹ,`O)3F`3X/ŞΓ^T\-2ͲQ5%"/t l aRju)t\P}oN'Q- *@Ew錭sV ~:ٞfȂ$ ?OJQf r`ۯQ<%QPU 2j)d)}ewv͓4է'W=-ҎsQRZGv.нSwn%ioFw_n8G߈'&D|dMQӑV}N$JWDDw߀k5SojI8A𕈳ޤ@c?aݢ W0=;rWc$|w]&P 5[BmtEƍdB{fj^.F,T@9<8Z2ŮWۻļ+dEGޭ ]-31) nWD^ԣ{Jnլ-xPn1~\:CnNӏVqu_R܄t0Sx4*`%rk5uh4}61hJ!YzĦ QK6 jFzθY4._Tl<@Fh[?>Z )>%Gץ'z.(i_[l3^OHQBc/#e#Bm!'L&1%k8_s2h` Q'Cr ۑmPHL*6;vd@9mxܠJ(U#}nņi1ۼP͊#2 03[G$ϝ;_IلEalw~Q0!<o~}jQ 2AGB.Lūg"eecWvFm YaIal]*4ҝR:j^߆ 7nJ HJ $}y~3k0~{#BR*Aª!"V8*ɶV P;J8O!5qsM„bvЌR[߲$bA 1b 5NTVVcQŐjlY0m*N'd;cm1pHIL[G޻jk_7;lLNM(b(HrA[.]C0enCMStoDZeGq:<%a'0s o@hD47'Er]eM8NpQ/P$Kym7h *%$ݏhDzp PU328 XH&#~&嫿Xn Ҭ s4oO#e<4XѲ [H e6i8YBzԯu_ PMm=g|v/YqV1G!Zw6a :~AV ?ֺ^Al} 3!I>0ݻ'%~:]iLVBD@Io|Vv4BuܛoD {z6163Qd[ڱ b0.CϘQrnP*;<|>?0:=,#w'%fFTl@]6G\ʒE[ r^PҾRПY||)dj3_B-HN:|Pw0H w''5xWUas<9kju|q\L f%ވ2nLmKcO΄rέNS]ȦT2,wp^G;0&&R轡ϥ$l[(*B9ևox hN?fVP uvMVȣƻT9#6';7+9tQmM~3 (_Sl BSeA=W[ȶt-)NƨtZT7$YZGiž@hA$pk(j[(_7ӷQ@!Ź(q,C8҄E+z!wVK LUw(fu:dlCYSt#aI<9w5)x)!DcV6"uFٝUH7] }y 0)=)[I菃3$),iG&jwl;B]9WaBQ\ ~y%_Ɵ8*Q5 2JEAPk;JC̥aa`X /ejPM@є#*٘:??эxzȿo$BQS1"T5ӲUKI7({)UzI -3"”Hզ =im GÄJX׹Dx*h,(Hp=2gл [sS.s5Ir%.6[v[ Y ^7g: Kݻ7xUWEu͋mv3#$IJ7FxDKblH" ޴3&ڕTn%7)[u Uĕ;=oU+czb *mtd$?BR:Yuw"JCie`Od=_S62Yb` o|$meɑ6J`IHM93Tkzz݀1qYŵo1 +8bv~[5oJSEnBI&I`ё#*CT,` .ߚʘ|JpVRZT[LFe6Pof\FN{fE13pTfS IˢpFڻ-U,?Aўg2*pBy)NA4t #nr.;p!yZERg˸Hz; m}K/b c[ޭ`*/]f{^[F,;y&ڵ`7llIEl!+cVeǙu.,elY7Jn@w-!  >)T g!`g;x~4e&Ƹc3`+{މkXS+l!ۻ3`R -Ɨ@Pgg0zҔoGI(2%]G<6@E{ o#ODAymQLN[Ir` ,"eYN;dt;5œe/TU1NV~*e^#|Hhϋס¼xQ EpԢ6 YnEzf99W6+QC^?;E<wG=UW=PJPTmЗ.qfp+mR7NQ>P>Ja,cV~U5X n !_%{ Q=]h_d;2TcE9\hTYC;BȬ9]|J5HƗX%8h̬i$6Aīrz8 PiHupR>t$Nc ˝?ecmNQp,ű Z*' ]?vn{節l/B w6W4aNldj$~^WBB!qw3l%3ɖ{T.s >wF$!ދd7Y |]$@bozȖX$Nt?ub[8ı1͗0`ؿ?ҍn>+ \&t^L^1Z[_۪S(0R,쏮}v4%BQ يSrREhKطHtR UžhLO9.x Hgp ڴ{:^Kf6j\kk{ؠIxkR*KIJ᣾-r7h!4ES,jw_շȄ򷚫>ٗU7Cd`!\Q E'?yLl[$ݍݱcd㥊٤JK õ9ñM7`#E.5`9GإJ[4 _UrTz A4x>xmGC.D#;gUb$Pu: q7@^iZ#+w _V|m"gNTRr R.a>s0Y~<~I"5?,{ 2 Kz~G4u8ou-p VEiNl(ӣ`=׳_pl"\~W9.Tj8?M o-;WN8Swnm1PR{B[bß J##gGQxr\H+nlk{- !J$9 l!aI֡8qVYb.@ȇa3lc'r mϛ;c˹G.o>'( Gm$$4HTݒ1h൯n;` W)ÅOP$ϱ(WĆ R7CkV ďZ&QGTI&.Bz=J]e4P-C,r\5,'CBQ<HZKm9y-q|c;p֔R ct~5jr+4zΛ-CF7*,"_YWxu \e=8 gE]6 HYu-FTFBkۯ4~(|LE>Asd֓b`j&2: (A4vC%ӭe_wD-c{h0H)Ղc{mGpQ %z;c[7`DcSxaYz@"AkŽ*}xɬ-XA _F C7d>Bi_<ԀY yQnsRF1h/QZ&W:*@aR. ^H }1|{ep<嘙MDe 2V <1̔ՅWD)]ʏ4l;QIm\ BI"vD"6[4gʽʓ0l'hlAIM/^N:@] Ҕf25຤x充% i1*d|ܣ9pfl#Ey[-* u =.ޥ[|O (iՄv4-U'U(]2]2F˔$kQB*pr$^TȺ;MP!D}Gb[o.Xl}%ꂫt1rؒw(BIìfG`Ȯj%*lx-fHBlKΧ4K X=VɃTH 2%&>G's/4t8@\t6d~c<~rlLbCa}Urp7:$hp.iQC:SL/w%Nu]ti%&@<[de8hE+gqsB(V`FxJT#77OJ;_A!Q; vf-m +2~\e3_Fg%)`QϴQX¶pz@= Q-ڟDo؂sS@(MOޣ:#J 3tϣjqځaN\8:\3Wo\f埘HJ堷u=4a!Qrܶ$1UaoR@,TS?Zu|b)voy!"T܈]f]/y93ج o9gO6.jEi7B[~zyscַ0V&-zq܌`');X-U B>@%n;11d )OmᩫAGiTMuMVn-:VseJeT(N%j$Etxe]vWT-͢` 6ERԈxH(Z,|h`H箿iMFof-}vatWpF#ƬZ%QjM ;ٯ>4]J5\$ӧ}SEP]v|THG.' TxPe enⓛ\|Hϱ$g4 Bw_l/!rgueOKNLk x51dfz"([imbe݂@I߆~(<"X F (}]SlV:9*"Hƴo{\PI dOuZF'<*Wkw2+ga聕mIi%"i,L6CՈ+֭KM CvL _hv=^¡,bhjl]BU]IzTyQ&{Z¾cۂENK-̙z ҭã.)~Q.B1Wt,lT1fr [%7IAՂ٦GZ%' xsVNkYxQE]8&óFϊ 6[  zxy ڷ2Η(A.%ᄢNMqsN6 YW'-h(^.%82 txÀv8v |H%qkТtf(}G-5DQ&@R]"u69P4Re]`?R!'݌vX+S"J)xf"喷:H@()`фGK=Kv!N[loS;'6f ㋑Ռg,ӎq$v.fl n\b 8A?%)% ꒿g 핵ϋ\LšQDZ h~˺Ξ͢D:S$Q02mv﹁3*W]*LaǸ9lLBm:K03wP㝊U*+}ʏEz$qT]rOxADzj,MC?Zpd&MŨDO\C$n2t.m#JAӦle8mo{z^MƝJ5&Y0G@NPJE~!:[ !/:?ͼve4~(@(e8 >v_ r ry ?3Qxfj';mIugwMWBqØ͏%O$%}kvHCf,k~y@_ugE}LZҔc)<}:j_1(>}i5q@XϞvܜnvrw< (R^MLzt߬ŝ̳'*ʛlzmpU^#۩3)sH:VǷGQ4;/P /(j!}DW!*LМT7DpHF\f9nXoַ:~^1pg[rgsY Qs6o,^3A(67q΢e7Qr8n L#7ݟրLn /0—QQ^΃[ 8I+ {"bo.5.x,gGI%v`Ӻ0"HI%C/FT>W^'7Җ/V\VF9ʡi ])*n%\Ҹظ?-1t&tMs1/qfcq{PjnIC|l'6ZS4ؚ#Mnf5,`}ۿ4@2v0Y)2o}l4|QPLV lQ#py\EPе.iӪ$m+1+_VH^ v?%=xzIq,pr{Nh+J`l rJtFu"C2N6V m@PwE̐tbl&^){ҙ"x3 E7˺lzXHr`Pw#vBUo)܍Mlb(M6'Ϗq,8Z Ԥ"$J2Y_$Q:u$I$%QcН"DfSfȵe0AAէ]FF-ދVy!cqUOtnL4(z! (řZm7؊F>PK%@'0ciH[M}ſcn!> .J `n38JHA(Y~b,qsڕ3^q&Lo jƋ{A:.a35ļ'L)&#HF4{^qo5nN_V@\o:ַb`4Tw1 ^*Xɸ41Mgdx4ЋG*M?P7uK4kpn `x A]R[A3+&6o:Κ_F/w2(CI#&39V՚t0_4uWHH lpT#-fYuHJ6ƒZ _ʆm#E|^nvslю9 gf)YPmTKiԃ\X'xG8No}˃y|$,@ЇB5b&X[;Oo/֜T?jv~VutysڂiR$#xݾ ߌn(Yʛ A69=n1_?Ff,1|P';ѩ4!/&tHLZ M̾cc%^{չg`MHԯɃCkQ=˳ƚ:{}1fa9]3 -DOM~-%y3;_\~Vl,/7"8o|b[;╉C&`H4YަexP7 X\t_JFRzwx1&nIB7D(FOK  ޞERK *o7I̢RNEmňR|Da=yb=.  +/̆o[X'(@>-KVʦ-א .oޣ,9j^Y(KԟuɁ$bi-`/@`8@c='==Wt'i\t%QLK ,[6 lmqk:>$pYݠ&#Jo8?raD2sCɉ[LФWH.._USqS_/O٪ VrЇѯ6e/{1[۪11c:vNfY!U?ko3#&DB*J3Ws7#kYT!uv jhpXu#؍n|0~=4|]kD#ٕ=]xE8Q聇XA/@]LC &DFTӛ+Kg3Yhi=݃?>Q(4ֶ:*ZrK*1!<"Ƅ E?O g"N 0E~7$G#ۘh~g0D;ֺ,u '㎕}הBd[C<'VoÈ(Hև-n8uytt=l\ ԃW'XXB7-_bkD6~t-`r7ӵ{{<H5H4oNTRh5J3SRr G)ZC\DREm8WM(.2ޮkAe%Y#4!`,lfG7)͐ V̝r^E½< A 94ހE#`lddϊ([+qh_5t[= 0'9 L&kt!O'ut`3/,b:0s%'-Mw:+Nq>!0 fL:7ɚ6/|ZI8Xyx$\hhNJ S-W|E=09$WG+}&=  5Ki8=ϻq%sЍb{*8yiUB?A6)Xmc 3{UgU\+|4y8OS/27!XkCj sjϩ|i?#Y$rM`.bGw;,X1ԷND^r/bk4Sh {^ڝE B!nYx``\a2v45֔?JBIϳpqõKy?f˱Vh(cŧخ$8HrYXXY ?$ eX ӹ:@]WM: 5 opYHҦ@Ht`ä'|ΙQU@{ZLQVC{ke .R`ʎJ|;<~!2ib֙r1yHlӌ=<%V̑LXFiq؃W[9@x#(#~%xe1O;.r)K'+&.("τ4D̳*DX[ ;_[7p-[)t 5otK&"Հ)CdUÛp&;$݃WܮPݓ~(-%)])&X3'v1:}(lM}7?h/fTHck@:ϑ!31 dm`)ki_Wȁoc9E7 @m[T"A1ݓ,6Y:|#ԩ*1ñIg3Uv._vԴն,|T-`sɷa{}%nOƪdIWd*1I S]#]~Oٰ@tȅ)^)(9ˆhX2,z~W8q8wvkhc4`q8by+f/_AVȇmʬAXO@=pW2"ˆ^RCSJM=t~[n\6se +PL NMJ>I*8ۏ?d1q͵j"A"!1ߧ +,!3oxW|ʔy6Vv5݁aل  il+Q*+G.̬|ZSdmh+5 U) 4+a3W1({ '8M{( @LɽcB'GvG!͟h0,ɪuӯbKCkk9,dP[RV T#m?*[KX̼W$euĪ&&A_?@,i|V]ƕ4^4p?j^4 - *t- E@! ; {!$OjrQpspKaV^I^qװ%CQߘ`qSM!`O`2n/犥Ȏo|%K ) az8Ua? ҙ"#K"r ʺ!.@%;na&9ǎ]@""[x]''[>\#g3;DYDץeC= <x,z\5!\`spa PJ{`|cw$>E^#10ڧaa8<>Y:cpțVg-PĘZ]OGQ& JF?sE&n&͕*= q{义u/^^*AeU(\xa&B`":Sz7z X1nn ܣUfs^)E4?ۡYѣ]n 0g\ط$7Hs/)` keY|-ߚ9F@w݇Fd#a&}KI-Xwʉޅ½xW J _qEڐDL/t™!4}_ݖƍrEL֠a(~7eq-W^W$# z7(QBUx5~\g:rk{Щg T=*I%-|Wy1 I4u_Aq-_b`8.n /׀QJ|En.+)uX,/pnW*G$ ѱFe22xB#'@95y]rxG &*hr#[]E/d*݋mSGX>Ղ4Sc~Mˀ(6go12wͧDˇ@RWf45yk? x:bżB'6*W!&V9RKf172jӯ}e۝OdWpR9Yq1`(SwͿo~XqUt=1Q{˩ mz` A(RjuOF_fm[U^.$V\re@wDJ@f~Pۄ'- HM0? Ո¥z{[N7$e辠Sw>n׆].H/ A~P*:A%yiu쳻$/*\b]5Iֻ8 Ϟq,K:`Y$rޮ]}\ O v 5ڡP7x,PF$#|ݲ9GQ luOm_< BQP }a>H:rny9K#QYV@VhjXuPNQ֋A$=,;'3smPDɐΐ_`*49jٛ:b+M ce 6(Š:A}92F33ˆHMGG=ty<y_>;o>HCP;!e'϶&K[F9'bF"x-/5քЇ |(o*J7"#^/QH<"kن ӟq^R lQ<@וΤK ++fOS]9󯉞xhc\2smw_ZQ#kf.jVxd .p"+U/Fy 0NL^:.YU. s~  "iV7ۖzS1# 7~?posdev`X9nLJvUo_A{&SjX{b2 = uѱD0he{D(״LI`q`S:Ի~hL97fV wtp)hZڹ~QzX-6V{J렦kB7֣MQcZ(Cae oۗOωBl)Ȕz8]d"b22 x$>ŸJ>EZA[_/xwOkD'f^!$wkJ}zo{T)sOv~nm' תBC5::sd~-uqN6?RL0a.Jd}6 i^Y)hA!? HǙp|GԖVi':ahQl+$yedbǦT"0Z8[pK`5P|3ڽK{}mIT:۩( o=N.NTdyENw3鷗\ů!q /r n| g^ ajh $/'~h}Nٺ5n$MS3 Lڧ!HRN"u7R]Gs`ӵ<0#W)c.,/E76Xޔ73p,`*5@g㐻I6(h},&RD5PE?,OcLpK%%n'kӁJKgHڠ"(ARBV !*҇3\~a\/xE`G]`AoЖ1X_M_yNiS2:ᜭNV9Y{"cDQIQ5CFl+qD7?1OI"9uBs p#`jC>,AŊ[i|1IOUNy %u^ؙKȲf`Jn6VJ}RyNXOG+mNQh!^4/8 Z枲}g~bQ$n.1lQFBܬց\Yt2ǚVX43+#[d;r<Թ[KrMX),7]N!D P*=;ui {G`~\TTp@SXXue!-&3)-_յTČeȤOwMո./Rwiv`g@6!*XQƘ-g1 SJ:'e]d 悂@'hK1>%#@^T|u11D)oAqDݏަUߨ;<:&a6›ħ1zNm83BrOV2Yl?op?n)LD2,C /{tg(P:ebuuIzSL$t H#0OW(,݄jZH]{]Vs⪶rG'$9J =UMr> !o$⻅|՜y518Ls90a: ʛ.A{0ЕI~rm|(nj%zr-J-}!9Σ}ǹ["q6ġ]:RW\X+^LGR#Lާ ;Gd` +>7q o'n|yGV*+9xrC3dz <l$1\m|E(tY_< l׌9AƥE׏AzBff~NZo4C63[+F}k2zlg2K/҂bLzW%n7֛zٌ/[.-@/4Y4޺?nᑵ,8NQ:+D!47$D1Eg> 6 ?lVrGTL0eȌ2[o{54gX2 =/86T1 b(:4Sy*z*S\HʕȻ0sm? =aV.Coc=DOkH-6rzsWo) $?tc6=NP3CwQV\>\.8O}ϟg;IF;ޘ9V tSr-b 5YNkeN]Ԉ/Wz1=FUZpzQ.ԃrFx'mjF!'5׊\x| # ˢzGH_[uIh ħ| ^Ɓ8lOJxGxu zS[nL"!2bĿTUk\Y c}DONQ8ϘFNku)(]WV!e0ZigCDӋQQШ8ANs^p5\#i`;sBf8v;9cWN9X *\ٮ*jh`81Kk.:Q.]־9xա=DGaR1 o4ļ`kFwV_` ù`ų%T.DO FD ir՞#$P ҭL n2UWq =Ka ny_3~Īm)eSaԕ?\kSDT>\ӎ]O͆-[@=qT"\@pЃc<a~CZdZP]hZIڋ$ؖܔݛP xsT}9Rp:&XWX l!~q 8E؄%\FY TUlz#e-i/LszF.}C|R6%n I  {FWqɒCZgf"@mN6L$ ED5zcG:^&-DdQvOmBN^;-".lR'A~UOA"m9uZ51҅e2Vw(` ]+{QidpEk/}&|w#ׁ U=j֎ߖD |b  != m/8}{+~cR %9V7.dr+m-qғR;,ڙQClud] *uZ@A9GÀcO ~V͎q)P? 4GWnmձ"3(+ہ!d|HO2e5<>6N'>*[t# =o /\kU4Dj5σ YFB q %w}xL^:;!nH5So% C:"em4y}5M}0EDzs eiH<Ѝ[Y)1q:k/p# a%“`>ADJ3I M7K)@NynAWu]&E/牅Bc3R\'n9Z. 6Ƿ7 ч!kiS#1SYn٘&Y4k`Ԑd3GyR.PI.H "im"|ޅR`j$KY&b{҉=nd?{6#%":gҵ˚1XZsˠ2=DD+=h,+9mȨF3qcXRZW>_9q\HsÇg@)#!>#U)d}14:ŠV٨Fpm"r~QAif Ϸ=ɀ; 7ޞ:Lb~ xzz=($`aE]c'R< f@ f"[ev[%wpg^< iVI<:^+QG@ !1\#m: ?b%n񧡓+mݤ0K5QjV 8d_""?SDFxk֪ MR{0sYO s0fx׈w+<g ֻV`)%,C{jՅk>kʚ˪Y~\yO3O4 sU*7$1 '^$,K)#:Sfg-=,RXX崪x=,9FO:TPBYobL[LM82y] f{g  b4-HQ[}g 4e8-JSuQN~w&4jFuuMgm"&sh H-Y]t ňZ{j\KXe)j~3U/ X*9&zlGdX>&ԉvߎ꽢f4#҈R>W>ND@ʲ2QL|KPG Hdy1̟eƠaJ6$iѹ)f;_!G9SduCdG^,]1tHDgt@xhqG$5A5&o; >RjJ5߉l[@wv"O5j8VSx0&&WpQ4[xC#`\F?a4qb~'OƐ=F=ZߟRX1Q5~pƺBh.mutߤe1hdo_1-!t\d,'O"jSP,j?z~v 7llq2q6 4 ߽1 u:xZ&?͠d+鰔Q5~An  ^]Pӻ$ BIަlpފ@! ]CJ ,XdV1l YJ`$)  bLuq0:Xd U@uHuл?/>Fӊ?@% Lhv.]xePmM7ܧfbH&:cO_!.prȍIYk;=,>ɪ}PinmAӝ"_Q(a3/5SCeYEO[Fd1GJ`~aNŖj+w* Lևf-]5g}B;2$- i'tj=62B#K uTC 4ƫr,«8}^Ҹʑze3"Va<3+낯{ c's/'q1 X 㝪Ł$&X@[`('^53&`CmjW2g%&잊,0za>F4fr3䂑+wwsaqI> Z'lR %?lr|.shy ñ#PlB@nQ! YЍ|U+{ϊG+&f{5x{' G%Sҍr};X*(WK0={WCX(Rt6^vp7d ?/o9TD"zx\Ja`(qh8AՊNƶJŭeg53iR4zR c^2z;Ck#w4CBVBtVT%ܯhGbRHdTs10j1uu8V h]uHz,]ٜFZp3 !# U]# #ݤq4.Y1eY5A]?UMSQ-w uѥHh#畨-/%#1[gI .=8@L^=OpOrjuk?-* ASz$R.&*#;sRﶟԥ/ZשLksqbE7B˧W\CZva yli澦P mX+*DA0FO3L#pf/@$j>xvr01$"B:9G6MϘ^lE]19BZixTBӽ?VQ Z^ci,#[ywn_2 Jy$QNAiW_Oo +U>p9h cQalKyDXT7?C%]OCUC9XcR-m1ԷieYOIÈsa6v肹3w 4eo'C,mr:Tt$!=A;Tw/y&Ki}_?1/< jl)O踭]bl176WIM~qS}K*|;dorm%SD9%szy6{ Pi8_i],!OvaCht[Z9.5#fuW(c9~+~AG{w1ԕNV'b=VwbT vrfCfծCs.K_W+1{Hr__[}ub/fe"bVALn@u8=^E<晼)K8)-&Q; R*#9!wD2D;mHe  K bB#xKRQC©kqo."Lϕ+C TY|e9.;o|Q~˺k_y'e j֥pW)Q@IF1Ù7 u$ 8V橻e] BilB:9iw²0A->Vd,X6b,XU EV%$?֙#enB'{rƃU|8ߵXW+|TV͐]WCQǶ gE2A. _:( H挌rځƐ:UJ4㇡Pr"_.уk[O|h!J\"R2F,\pecJ2R2>?.0U ĸoޯ  "ݙ5Iҟ'Gbۣx1V[67:dPƁva:XYfzU>yLH$IP|Wuɖ _x.a LݱN}YyOVȨ<6^j$7>ƢAlQ]- کz .S3A S&瞛 )a~+~No 1+$rK (qy4L*P'|. k(.x0}mcm^@fr ;e/p,#| a7flǦC--[FFO$;&>:˄OP}k¡ ~2sR &65k7Ox^q;7M׊-crx&f|doK sܳ =`q"!ޠu6i`%HѠ4e_QXJx3bI: T>~M19I=qoS9Rja-|L`Wrۈ|VړTP<=h$XZFq?rR'6 /mXޖFI[Zu 러>^'|z~b<  {t SdebWѺpU{uΓYȹ@62Mꈧ5 LATW THˮKvT+5u[̸ڲ?bX&u;FarWGDJCzNct˽Į UZjy2)NZ18\Mᢤ8I+ͺ/ <}COqfl .*Cst9p*5\BS'iG9} ; wTR6f/}vmecOTZ=-ڧ>t(PDԨ5$j9%W=ޏ$A\tdG\y-# zZL݈Y@8r[x㊰w68bB.ɥĂ c`φMfd8!"=-r ¦pٺ:˿Q0'0Ȉ2 xlT||T~nLB_co40yHЉu~'R.qAj~LVrGV4(9CLd^;?u=k#K J Cȵ4cΑ9eQj:&? ƿrs! 6bH5NSꏔ,ǝHlM{圯rmSz 1K֯x9yvBVʺRwЁb#a}< 8weφS;DfԩǍwRyd *ΐ|L6$-l8B/D^:~`ItE M;!~ &jӓ.ĕi;t)G_'c7[V#doi!>IbVr{Q5 KkĒBss`DSBʈZKUX r+*B?Z-3ylӝ܂!WY߲d\1M8R;] Qٙvyz$_# ˏnoA{񶈟)Dk VAG`EfIaĝ=dY퀈v-.<2I,tӈLZ :l FZ'  nr]c!_{Qɕ=]69۞F}-"U1l}/H‘r1~j0+PwfS4Vgf19ec*L:]#rrEVt(-ڢ:$yPL'fX#1KxDr7sG7u踍p">^3np㨰vԝ*VC$X,I;Y΋BuTH<(qT4_mۍ$AnHJmlBi糨3:˛RTYTO֑@r19O+u9iƠ0XQÅk!aWɨ[ߗ|Ievn-G^&[68,XޮCuׂwk4K@O]*-+0+'ڜHLdHkS'/`+}#w+=^3>QN1Ju*]3+?U˂DgK}hlD~'cIA:JÕE"SLr_#:V MBp.瓳;@I#?aiӝ 0 3q/WĠB|li+t4g$HP<\t>"?D5q6[_&gWi8Y¾7yy듮עXG$Wj1` }1i1eE&$Ɏ̬C0u!J6jRŜ9zo 6V5),H_I}DL-! js =\ R=VG+f@ߚȂY92_X AM$v]R9|ԭ_p9fEҀ0S3=`~t*\\p5Y8jJ k}u]CZ.BoD{F2 nJB[!|(si~E-*ᯧBR[fKkKB9C3s!髈cl3q:.E*8\d eK)nbH/&r!}ԍ J01xo]ӶOm(x;Zj*N29EC(հ;Y!OQ ~s#ma&,6taSA?,WũND'ǝ=HLM)=ZEqq{Ϯl_%1C[(i >Lմ%xc*],'u:nD=Wng)]nVڿv9n,6Luωg$D>HP0Im< 1[xr`^aM]_f8i~{}Eb޴"5hl7RcUBGT|lO|2Ơ荛]3{Ŵ4[zm/%C]#Fam0mjMOB%{q=g8L d V)Np- ɞv`$䀿nebcÕ5Z[=_+%(Is+]4)ydY L7h0JKNލ(=eM W{"-h?1h[y@6_'}L'rl4q8.a03nż ct%IL3q8{ bd-ԑIE'Z) /ͽ|V<У)kK,Rl\z|f!%*wH +GNWhCg1'}9 ^3DظFRmo"9>;f]i-ś5k`/E*NOdɔ|JdoFS~eh d5WAO=ghc:^ _3!y}Y:`ngލ*(/Ă\̖~xz.YFgZ"=MUbTv$lunK!|ʓ_D]r%R>4\vxgXߔt,!y& G[ʏ+I ¼>MቧUB4rlǜ)$zu{hvi蠃C JOz+c *K\fIe)f =4iUV!}@ pmEkˡ ~c`AzP'N};eե]rm` ,ԃb6QjRqX5g7R0yyWWyl4au+JjnRWu sn=֊&4Ph?mxyx۶Շ?!3?&`/<@vL~0/>pNlWbkKkJDz @cL?=bZIIj`he!k*3ִGkmx= JXӒ<1:aoSO1~;F L)+?;gӴ 31]QWcP'g fv,6>6d2ri y|B;*mf5k"LO !EgICT>ynvS[ULM2hd@KvF=fDUYLy EiU! !ztsԽcSеR,*LPrJܾx i#z}T_iaYc:!XVn#kė}L+1MO !:12;I?RP*sU~V>14!Ge 7K|cdW2WT1u/ilZ *מiɢ( ?v7N7JDjM ;8 Oq^Qa3\t] o)z+t$xP( ?d(ٽ^aiH%Ls&-ӦyS|k^{E VQЕX3t[Y\-V 6`T:5Ӕ l;dKe]#Y\t/yT[/ZToƼ{I;*f=z豲b,C]Pęr$ؽR:} pVvHD"yECe\aꝭaupԞRsrr( ͸G,4z{·|c*fOn>̺zCxR(O N`W*d0Ԓ SK+v%T~ɕQ݀id&!Q }u]JF<)LVL)m 6" ]IuPzjϊ&/U{_ JHӰ5h: It,{ A |ΞӟBeЫGz- ˩'|pDD0\%$l9dLw |5ߍ ٿ '[.!r9WylY1cZ"]0Y4IϜᜂX8AJ$^|BDP(-̾f cD娠8PV-gcswَQg7|JNI=H}l?1Q,Zj?[0a1f=sCH+ YN?O$[6^leWj4=87ǺcB>2[3m q5_=ih1hW Xf҅s6frV@k=7 [c Ѭ#Jf%!4hҭe R7^Gen8LHoUxv,I,U1 mRSǣ#񹭂` )"xo9E:IrܰP.y"WuhrA20fceâYhNBk@ JH5xK`GY$b&Cr'kASC{r jxXaPu䭓/KDzޞ"o3+@xJSptq8fJ 8ZpGeyࠂ1Dzd $O?j]M`;]mÀ9]=~!jN>D%SC*JT9FprBD4`~)E_ȜPM4R5.L(Q*ؽ{Kz sR֚d^W4m$DN w9vp $n@|ژ {Uzg3 \$ #]Ěd4f }Sh'1 ϘUwE -$!:˦C)&me;yT1CN?v 厎2L2F۷ ^=S xNqZef}tPr&a4Idj" w ~S¯끼dZPfsjԃCT)+pѦ Iųɮj:;%EU)kPpQ^{D(~NoX(@zYk3.DW#fp\$»YҜQC"[Q4|ҘsG@nu<"}dn+tdS&.@7nN$3S;95]㻀x .^X(nPBؿF` ky r"p^%]o,3^CPuF^*"X 6 f:ݘouT&m+ލg,;.ذ'v=?f0S-1;0_5 &̭.vg.-ԊP2j,O돰 ~䍞{Gքp6oܖe;vb'O(~ǐ%&A^ [- j;oE]16s=+M~ )r Fzfr[ov3py,Jh?2l $k ul̸]RDzkI=OEɟOTUZ%9kgj}D%v&M]ݴa(~("<5xaVqUHoϧcva}9:1܀ud~0*Gk*ǯIi-s15t:5Ѡc@$p Z05UX=WoLu8aiMm+x;:Ǘj+te}q`.]v9]fYGl: QnHuznPw}qUgnMwSР9sD3QZ:I83HV{{al`BMj\{̼Tq޼~gxh}If/tHщ~R^r+]Y|(:~gi';˰ #QUN+oȮOba~*2"%WM5%<:s &5"hAtoyAHʚcr( py5&du(e}è͓)ԿJ^3}WɍV.532Kp_i‘: ` ŕ"ƃ*|砧9(gNDl]&`Uz7jAh:VQ:G>*ގ! g;5^AF܆<*N+^ <)2:k^691~-&\#;Vf^ۭ9Ja)`iC aL<$,Kꅓ*Q|gF37Jm@nZqK-nNKNGz5BF E*O*>`t2!]8~7LOP)K!yh\0ބMœ4~12<=V~H`JsmNG;Xap\"KDra^Eg=hzZI"##Z ڵ*Z5 jJOj 'rHЀ3ufJxܸPo)HKقsbzG^ncLV*C5`ZG>ax|j3œ@Рyنcgk?`vS/Z˔e{z!xkkukzee1kzU\'h &/EW[84"U{R-hسD7U(J&1%lĻ%2Obԝ{*rV[Gs+ wɇ &GhsTS,N"! ig2d>oN% {'C`H.$lG;B,af(1eT %Z TdҼ0& okCyH|LSmߤs+SV鮢-м0<lkYPڣB4*IjL} Nm$B!d1@_^!|W2JV2'51_ uv5DӒoV3ﯹRM}9hrB&ZLmhCNiV^,|RsPk#6?G?<2:2KDd Xo oގMEKsGY"RrF>I|b< ɧgiϿ=ht% p] :gގް?o[SR7HOy=*< k5:3X8. TBSt2++sPԿիQ܆+n0ȳyz5~1|6pZ,hP ~pޛgݯW1ώ eYWgI`a牗1a`])XHlZU† ʻF 'bq{ȽP $xe̸m^<2¸ܲ;ڙ2K Y[a ]:iMYFV-A28"'gyپ\KI G,tVb뗗$p9+')mOܤ]xjL s'53(gxiߡ; s "[r#,'8-[1tmݧiqK'w@j3cd D* SBIy@=_4iq9s0QRz 7't3\o@w4.WOG܇Q7/uB'l(uz-~ӭ\،A,UJ6ݝ8rTSSI=K|uuPuf/WaSIf+-1^ 0xv8z fo\LRȣ*U]d,~.PьUy9xZ)rˎBt>rvA5]l/6Xr3P]1(O)!Yf)?1~MI0ϚRe`&̫͜RMA@ (Pf ÔX~A*YKQZ R(urai!ENჵ&Qp?, ]*j.zVh<fm(#kJ POLZIalC;kF^"S_:6r>6EfUľTTCua u"ĸe#J6vgt0MYǚ_G%2=c7/ciNV{CdQygC' zȾ9kqb92\ZB |RO6ņ6 w4"F[}? T߷e034i{2ͯ$ u]:kJf o%el ~V) ؛KQ5W$v΍3egoBFOLw>,nH O6龚ݼ]K@4 +.uLLQtOVB52C ]#~=Lp:NJ-\g,^bб-!6{)&Z>oKF(,D3۪%+#XKPk(Sҏ꽢PmFʭ85ݸ4H?nKah p /e=u؁8$Ƅyߠr1?!~&Q]qy>tJw{CQP*NLkFwɞyDm^C)|UXLll |@A#r* c֧颻wnG/eq FriBNaW $RKq<äz&gP%O14j?$1_́w=kKTZYr~8p'Z&[7Z׵h$‼2n;o%ȖMҴ旱^㬝r/ň=Z\/ߴw:[F "Q݂ڏ9TqeIx)*m yamąꀷ՛8ʿ٤JH#)G#`%φyO~!Rĝ&dطTӶ_v//4d2+ZZP$,aRQd\O8 r1(udxSFb2UvkZ:eP\ ':I5 q3n?DxhjF 6HSM,*XP?FmaDC.U}her: .qٽ5V5AS3aq?`n>?pf!L:U,Ԅ|.3MGk."M~oAw b} YjUc$cma^%fUӾ$x5Rҁ>@֑͗57wwp`uMi3`ք|EpRLͺ{2vD>S'U& Obl/m$HW~~"M*<4XTf4 4ECRBm _m=Sp_͌gIEݽmV5no# ;7iv;;ɚZ\|5b`u1F7^K0;ZXBFf쑅dHqv,ngga"=;aU:Ĭ!)AbK).#?T$ #Dki=٣NO$"{bOoqj8"F&.ZFc/n%~,5k **(li^j'ڒ=}怀[z{Z7单K80b-א܊6 uh${*Χ*Y[ ~I܊Znܷ€q{8%'=UʑD6y[4V6CC;M|^2CFx/<Q >'ZY+&Y(G#W~S^ ~/C+x9cvkrDS_=&* ?v6ėc?QC9ϸ:C]o!|nt+Dt:? ޖaj&TpD<+C[YӪ$h>a\]9 ;#g?eJbB$g0Wb_.V;#'C BDx/)uѯx|zdI- q^lZZUdm2Mɠng z±//ׯD=[@R-ݶVvWj5g֓";_BV- RD fNttybo1ڰ~7-BO8Ӣ :a(p]|c$ g"+-ͷ| vMGC {Jqe>?AO_ DHZPu=e1g϶qXbŏ>zS@waA /Õ>brz\jgy6䎑ZřKZ YG{ʘl(o%oJ7m-]{  zFQˤ!B,qC:{ u?ܞ˩vW% 1؆V-(WembNPfɯ`żա?譕ĩ otv[F KH~# \R±^WK߂B\C`N4vj3r< ǫ]s}jgH59B8/t Gy)w}؟qg 91?T]_r.іi]%VpVMVzRgE{ӮuD…eoн̋Gרq;ck{ >iz{{gi 9S1бvԮȿ-1*`,3³z@U)[1bMmRbAw<``@w1bʌ vl%wX!]7mQ^<ÿ%)$E*0gMyк.]WP@7@"(MQnM}8H<%X߹nl^0H5eUkâeЕ1k8Wplݘ}S_ F}AIJ<=E; _8%–H`ҝ: <v:_D7>i}GT6ZQkB^M[xNJE>LۈX2ݛN݁OQ 6F:d6 ݿl/9Fα叠иʮ' Şeݧ2:ͩMp\?nBS4.{~P2c πNLA6>SԞ[(ЗV.86Q7v Xc} b[:QzXK_MM\v:\am[ 3١qİoPDnfO1ehǚP١C]c*I2Lj|7߲ni~Sv)p 0@qϿ-Yb>i̙ j';b0@# [cAa'f`}KQ=1|oq(p)fsҬrpxoGF VQܖ 9 ue7|7ZYH98(ֺ]P=e\}H+0 ѵCXui苑)9r`+){_Ɍ<3Q@vII1%ب˅>KXx:\Dgxk" 醎v+]fc%y3 0ClG=8uRzh{6+^ԓ7ٕYGwʸf:/d*/#,񘹙 ZecCY-M3տ ͉"_k =.}ofqܷ4AE,nq z-Xg&t٧lpNp0 \ށ$|I)œOɟ/D%sy}=#Մhr JN2}Sl]x8ZbDKto1ZKhH/z%zO S\ЅF%e'`q #)g& ټ H,+YǽF𸙠 Hf h[|>Sɖt&յ/ G浪 L! ҤɐW~}}hΨè|A3%>މb(q0S2!jO-LpyAP<ߤJM)ņ:-:+,eKӚ2.3#ꖰj#?EsN'tMd嬐5_Nv~-M:X&JP\UjR xZI>0U Cg笷2}3MK7q|kx=Ď/mx%"-LYU;,kut+Cj/q2̳Q8:)?Cz,[c5qɐ79*V_͋Y1M31wYߑ"( SDnw3쎗gҟ<:nMV B YƳM9|Tե)`Ys&*̘MsC]7ߺ? Z bO6[r:. Cz0(ŋ9;#FgĉQFEkfIdt- =<^Wq YKde~*5oqSu'ɂ%>UVM6 a}p0l)2RPʍPqOb}IpT7|ԕwZ$ W 5ŴhabނAiW:b \2?Gq1+_1&s閊XiJ]f֜9s2mKVY5J`qM 栐!U}|c85ud9M`Ӧ  H"LR#D( Rq"Ί2KmE]jk*+4Z \ I=<(S&!(uyAߎKcܱθr&(^Iі>Rښ<+$EN -_@2v٘ddǿ ZpzQ)Ae^t Z] eFF+QV _պO$st1`+5>[4ixɩG:B' ܀n@\*gqFɸm!s5kEp .m9V2" x%"׺+;Xq(hur!R693U/q5sI].k辱\1j+GqjȹS۔EѩfĶ kCDuNll'H^ +NaV;9',vheܷ(Y;zvw597w>_vMewGSF{)}!lÔ%`!ծtcܨOwf޺x9L 8AGrȌX+'IL yXP\(+;=5ΩWsc9  5B ^Cv DJK)ȴm:y4ɔk+k˅o@*sѐTk_Y)VbMd˫E$3]V!T4MWN(/_k\PgԬgjd}ެ%M#Gfe* #W&{csuq t)+.'"*YN RX(E#is;ZaH¢S&dm'g $^^ Wxΐ}s1Q#P$N3e_?9&a%mY/LKH +u7NPo@@Ӎ{J';/G X^yYAj6|dˤz_1狝8=L}Z&QrMciۨFEL8 eF6mq`.fobGv`/) YȌej5ertu\jtq ^r Q( @^qslpCDo]Bir[ Bj<QۣЅ;*LYKD_%S58@=F+[ iTT`wRl XN+%)($Co!}4eX䪐Z]ɭ13!RC+j0$ $B$Κ6$Pu?*O[eE!t~+YV5H;4|>@} 3ۍ_Ae,*F;s>U\I FVMO;u{]lcxjMg[Ĵ˛5V1"<݄xWhA>ݝC~IXIb.9c]# *|!mZQ.![NRi` 5BŷzTɹ`g>'e\[s NA#?D'[:OTuX)[zݮZ?cLڀ:r#j ޡUc 1o{"Dt!.v)CyLuL#lCvEfbgJx^A~BXmi7@bF3.7T`UeO s!+ EP iMӞfI f3>d:*SV~,RkNo(ږ T?Vd3PxPQ/GY  ùM'd9+2}ɾܾ@*niBҘ,t m O5xե&|D~WV][4A\69YW pᑎ Iou- ˔y>tT2W2"(RRP`Vns{&e^n+[G~/oWJ{J`60Qb$w*HG| U -˘۶tkٳ$`0~dJr܋ I&_ZPe" )G$HKz+k~eL;Mx)vK3-+K.p~uZJ];A3b~Ug"Kp /%{c0 0M Aš'Mr8aJj\Քp:B;ʓ%|q۷ب Ő5}z=[ ifi$k/R#b]*ȿŦ_M N\_hp=1 QR1%?r`Y` *oF_$o[@)΄v޵\"n!/1mS%dpL(ft6JXHhͷ -e!Q𞙴5:91ʅxxn m{@_AN0]"u p,&x:K0qo+dè9Oh4eh֣~/ylǘfgmshfn]@m$y*sPԪJGBD_ WW2fl}10Z-%!.0: Ք~51eKX6?]5VSfA=Xx6lREڃ߶klWܒv0#VUj|e aw1)0v7Qd/O cE#,zllNiI@/ENOSC\n-`T0bP&rF'* z_`[ShuiؙO^LGl&X{) omhD9~m*T͙(^48$86Nr+o2u{oN vK|ˉ̉Hқ?js׃:c;vwEͧʞd,+*lԛÜ2 (,Y{Ȓ]C iu(<&C1\8xb=;dƵhuDGputF:ʞُAzE/ۧ.D,_%)#[hfd:haA`^ g $,ȃZh}2 pvV)uf9\`fv R |1"M؉I# QWznI ay$k Vrk\fb0˨Ǫ^CpJY!axml MR D39 &Dt^w(Z{I=eȖk1xN}k{R ^#8ʱRi7arlTb3ah_ԕzMk&ҫ[sg\]Pf0i[ 5-jh?lӅdbRtUVԬRbqyt5Ex:A0]~콗W%5hgp"plݸFZב;xLvsgQ;ej* '!|40==E@_710Dk. DZ/L۠B_P<3 td/ M~Tyw6zF6_IX:ȉ)ktH(YnurZOM)l 3̍A@ {^ 2ƒĆ 5 *1՟Hri=WOWnEAVV #uf,Os/: ڽD9bif);;9?[/r9Pb\6yRr+ t8~r ~Z㦬J:UC$O&]3wO1B`ï&C0~ǖ,:1+<0u8wU'<ϻ|snt 6̻Г jQa(jSݤ6u>o+-ozr`(9ek9($<.UOGB#P~`iW$*y#v[od瓦NTERmtl -Q XN3J|4F76I4 JQZouVp&gO2R@`tڌ>I PWEb5ENoZTN`ơ)˒\2ns80)lu^lT5溠dd/(e 'Aҥ+ ќqL܈AG s.E+)lo^F;&m^iaE#ȭ Fla635IW n(SL<Z/P>/tԟ1@fPaMHMԃs EŒah*&PEFg22d&QϮӘGa,qJ =;\#RuFW+F/'.Vj]mh+_n-"s?b-6S-&`k9Kn)b7V?5eҦWkuI|`PA:>W8HT>-JqU!M4h 7(K%Fpf6`EХAGЕ?@r{:I8wuƋL:tqW &tC@ |ecWMvtd:hKWGqp?U|PՎo|#!Ko/pP֕tWE~(,πmPT:bkY,g#fTގJKx 1}TJ dJUis:P-mȶ=?2{hsM`JC=iT5G<;1 o`BU'LcrnA(DH(902E)OVhrBh9\Tf%>nh\x eXh[ن>?(t lp|Z>cF{G^a#,TcT#@H]"ﺁ^0@ e){SYRkRnS5}l V đ[ 擡z:UYEǙ̹~;!^q#ٞNE}&Qrj/h NF#^ʞqI16O¾jzL)Y8K@W(BF&ty;K]}">ؤ?2x.o@LqS 㒣L#3ZM=N|JbU;w<8&HcuF^OZFOg,ꓖ7^ohzBl@Fm;6Z*YC1Reyx"@Y,X]lTNԘZ2eĺ''%6o09l"}$PJd=c֘Jkv.Z~ |9H{HSQT+NޫDCcS=7m`=QH럪@+`/~7p;vc.>SuY +85ĤfRԆHگgyyL<QU~%x ;dv "6 M~s}+%S,okv NsKC=h,v|K&h^4˂F6`P/_=x\7QmNZhXyg#e/<ݿ˃y<|~K#8qXO=iH\÷8czsH3q.æmD@DϥISw!@}31}yw|a~ˡI*z/=FuSi`h**2GNj#$BKtUf#v5 ~G+yT'݁Jq3{}Y.=q1/l8 {eJ 7"X{~}`54 ~ި3X4[Q[!3F6A#&Ѵӫ R&vXI MgrBC >j>;yp%<9YcyU9#W*>u}؉ D>P/BS6hH/&:):8No MꓥA;[7%TZ.E#/ՓĎzEf^V%,&[1U,0VSgnroLwy nq-ѫSYYo_F?15h@ ή3C5̲[NYrwGAC7@2-u"lŻ ./~[{OCDhZc^thnbT]~',j|L`KU:8ʵN3 &_J(.Ť{"m],^aIX~83xduU8Ε&e#Ț:~V4\&\qyKzce`@B:tTěD{Ncu,K{z$A:|Xz;Ati{<)^YHsan& QØY+F)Py1*`32D\$JKJw%%oϒZ}"rB.7svwxT/z{j&TpKHy*]KfGKC/u㽛@5ְϻʊ"(D7dwm)UPg@Һ 췦sMv]W Ҝi?(푝ٳY]w<`<*:lwyK'ˉg^PN↭Th`3Kpj)i,$aPi`)|Ms.bC~&ZhbЧt`5H`qz_@WY?gbB]&"F&ܿo.D \|JnpyncO^74cܺ0~bfP <&w6.սh.p<҃|Ag+ѿ[ͺ 1a{XeEVʢ;z;,Ns.ΖaqOY+Ot<ޭ@L@q{;mr$ KJ`ggP8gކe> @)o #Z SRD(]qodFNd@wg?ދՇ YB6`'k-syP7V /9Ac-?\ ׺|0.c*g>8m)܈'%|>A>FS+F3 |,,-<{WT)Ky;Vs^OD--"\M!9䯣H_,-&'?4$`zj4p6ۛ'=(nNW)=g`7f}zbV2Oƛ|ϐpy@/6 p:/'ĘYD15K3jLK@/v$`.8U!f*Cw8ci[Nߥ\j6QzKP:)&f0cr<̛ $D*1fjJj0ꩬ4vewf5pG*k]偓A*iU3BuoKvy(GعxEIdG.xS~Ç dM}ERSAN5sx̒>zϙ<,1dC4\jX ؗI0p@Ɖ{:z RQg܂C4p_. Q;o[5uRo"2㶎]g57!/Јر-4t܃!JQĒct-k[p ҀԎme =X ɣǂ/Lx05QFD +1ZK W96撡( GL}kRm:9.`Uy8 7(9_?+(42pn\iBІ4jjJ l]5cf3ƴK7e=Za/tRNS9'us[E F&Y|TQ_T5?9&aBFh1tQC7U|Tr=SpNJ<6ۼBqt-xP=Ӑ~©PIŌC4E;F>hً$=7Y 8-C)6)"wA_O.;"MVBluue){r(m̆ӯ9)#D8AeWv>3j9 R *xVdžqܙ23׭[yLn qyaU=Ju3Vu^M =6F}j0w]-kRyÇ nV:A ҙj]j_zkb؉LIi@ߛkxa } 46e;1S[\O|)r -ǤR2%P8Q{!~ri[8Je+GýW 7QHU?L=rLcI`%@]x=ҍVG]x0ԙtBQȟ"<My#P%jԗM|sZ--!jHvdA+SE^ pUB<%x1#P\ԁΒ3;Ft2d dӦMa꾟L9 [6nOֻTuf ;xT Oh~sHjWF8I]FBT};;D8\ؠ'+A4۴5()g;lK!/FA$ecj؟X});I{-Ɛ1< ӞL~.R%'K>5FM{_M!~`f/Wޅ֜BOd*$VOf3 +qm0uX Z5塒Ss:8'q2hD[U԰>8f1N&[Ë( &2^eܝ*Zvf ΄jrgSzksHjԈZ6rR /бcY̑_έ24-L?!{ej$ {S1M;oyCX^1?\THy%643}Sf53ͻpAeKc-g'?O7EY6: F )i~yipж}__fIcv8Z'H]V@uЎqG`oiXZ1*>n"t=bcYdJ(;+I ?Akw]0$[Ң .g}؝LWy}6ܪzL Z x"IM59(359'#_gⓀtWZ5AKa$"@V闎ȌZT`7"^+N}Oϋ˃Z׶$DDJc[(7/bjW!N-?{T3@@&j XểC6 ^a?o|E m%!8M4߂;/Psz^Gn}e\P玏3Q訐LU6WG}|ߘ <W=2zIxlU3+zd[؇姧HBWո9†z-_ssjVru[out/lzP6@>0K#ZO4`L 9|~DJ0\3ngH{=Ng`(Wd{}5i,ewY5k]W,>Y]1\-1}."𗒩P1SIx炎$p}SXB~ gmox-7(Q0jeU4oVz>/w4}Ⴆ0{yMbf\_C f}ӏ̧ ;X[0}pȠ,1bRrl苇a r>ON8(( ֈ:DԦ7W/Lִ)Zs N 17Jl^;IRd2P鏝@u߿"/ :-(/I=2b3u؉\7B٠|}UŌZccFh3aʿR|J`ƬrC(da>Ge}\s<ؽsW{)V>ٹl/ܞ IvQК_t|uq{D !w'%.ɄJrP-6Xhpֲ-E u@L_ W6)V&Rv=SnX6vQg/5"bXS ~^ !w'&~؏TJ 3 *^w(6h=WQѮVб掱|!h!KD&kѤSg{rh N\j҂#*}8y'<=ybxK)Ҡq=Zq D P206046|dCHuJ׍Iَ;Ln)`j+:9GTx|irC:JI60ub']4'yذݿ }|©Ewut 1Htkb>cf({͑n1s5'#Vn75ƊE=|LStap0In1 s0>&`jN wlyEFah\!36}9 q35ϵMY`sqK7!!l4y yyJ"WK#uN ғwN uFlz|\R>cТg-.I&'[>-Wv>&MlRBIUIW$CT/<(ů=؈ۧ׈r,(5>味T|>b\l\H@&c lkXAyJ-IAsC/:f vY] ,V  )VcY7}nAV"qմZٲ8iD S/VO/Q@/ NPA{V9Eb™.'l1x:LǪ-uY@ zA.l!o&bcM:2ݒ`H`HJ| [B E%'P],A}3ucϩ׵❙eVșR2d4 h߮=Im.aF8>*n*/?@Fi"yv=cbцLSCU>$Hr?ʬ)"Ae D'D',- s}̟+hCwQO$LR0̔z_&b Zfߙ߈,}{]7>U֮0B7He7}' P;s$X6{9 @OͮAM8-1~<0-RfćSG]nhW齶K&dĜX a?oɨCgڂcIG!!7vN0~NSL|cO"wRLdh GV!C;}ڸ0ӽh^=Tgb["PfJvE-6.vwQT]WtIrB?0nV}9ʽ27#P @Vnx*+*cK"oa @8YQEVU؆\{ɰrNAhOmϣt&F6fS,!"|A+ENhqLvwgA=Q!D=h,d>%'6T@Qs%8L0ފ.3բ7Y {HT  D]1B;qmEi Z'|e]Rˠ+j)0)dH5wV\/q+h=9060-wd0^ś8.VVr-9}2}UP(.xENpm;T+>6hF|H|V 6JRrFgBJ3'Uphx v,]Fb`k.Ug5j w0VϮ@E dM$Ʉ[tKZx眱|';lz?f1f;:@:\X.};Z$V+@Ur6]pQ;r5Ս 3˘[dAƥݮc x.8}$ؾU#Yvtr/A&.ZR}oq#gȷcm_̖ᢽiH,i.(ya8xSܜwJ~;c*}wW8@Hp/QtJ6kNOх3E鹯7e|14 `M.L#߂~M锗TW;dYgP+^˟\-jd@=T.6n*u7t@$UO`ߘu}E .݇[;΄зSCcq㜫h1 bEGb?W٨Wb'Tp.*VMfwQjd Yn=Zej?F6Š*UŬ2nU}W۞E>΢jՎTZhij f?\H^"`X0]x䝌pw հ* ʍ[l2j,ض_SL@DzLSBV*\]HIȰ( tz^ԫ+AU ^F.9AR\6 LRiJ (( @7];Ŗ %P4eAtSW;\ :<VHib MFAb|MgcqOs=D_HryYKaǟkP`^!E0>s92G@knd#ZƨSHB/riO8ah2 ce%0߅ t#X2+Vp3s*KnJ>k*N5ĜQ̧Euܵ,,tVg޴G갤*Ù{ڤV= 7ΨfQJ :hJɮtW*uӤeaC5"\hPp Rwx:Xu١8ӁC7 X'\1l{-\ CuGLvplj)ZL2|f4\74to4vѕh}K.A3 4<4-*Ps.X@a;ڡ4]V!K̨(~5w6%?aR2I$%Se>ȗCIxyJu2`!"Y veT;=I9N (`j$wߌMv ">(b=^)"18X S eobh{eĔlv\_J_74 BZ2ˊgE(#&n<AT!P\`DJYFnE9A|,q B>2\},n1 !rdp*Jiw,ʟXIg%Ǎ[nT$ĘzyDݦ%M6tht012s|oIiqx4e_3`I9ۛ c];:?5g caʜ6$d9,peqcTL 3Bf E$7-^A9 H^.2WAo#fg"!;7f̈Ov\U692Hh}OAOZ-sX 6~ȸF&JROɉGBG#3XV,z~(7}~9A^#'2']JrٿSZH+ϟnƵ/̻2s@A HVkH0@t^\^Z2+(- h,V0Gc\Fa;7Ū.kEVQU;M>)&>PBkAK~C뜎Ã0o^syzf9nJcB\WXy-()䷒HL.->y_@ wCRq".q陠~R:tVtw`RlF;7na@-~5|̡zI?{͉G#Gipݒ|i}"b,b-wb`Q<Չ-hj:6;BK$TS<}ۚb-Q5cXiÍg7ZC!7ygۄhq@X{jsRk_-ם.mDppQf!I Ы;"~|BOXb+]WA"^tܖM56+ {FE.d5w|k0N^4*y;Iz1YpjJ8RK|8DC]bn]*QL?Mv"%я$|+a}{;k_("HǧK='L *{c|g+xXifOndЅ2[+e0]8] zluK-ո}\Iʁ26C͞|[}Oʛ? U m)5ha7FY'[=e0hL ,78Σ6 1LWu1_~h<UTN{TT7SXHJyP QpN:A(3K+&^v%-u.qk ı-nDfO_ۧ:T#`&ŰFbCb1I$;-/T`{Dtnc-TWˮb[8b<XS]8 B%$S4y rf» {## >uT7ݘ*_|5ϳΪK,ϭ!a>rб C2ٗ;IxHm'ʣ i"!1azfunnx+Imb[@n Ώ< O`yx5z'T`_:[~xq7BW,cgw!+ΜQ!dmAgSX!qdc@Df.җA~oixʆ 3^{Ӈdt+/YukVȴ`'nl`K :l v' 4B<#nJ}vW0c{`EHgx% J6 !f6ߦƻ"*TpRg^^5ȶkq+kF9m9>UBo7OI $Kͤq_Wf \5~xp XxҍW]buy]4$$gvVgfb.lS,~ ф+tlr?笓JU) 8]ͺ*iz̧7p-WrnzFgBFL7=(chG%v_?ʻrYT٪]D"5`T Rܓv|u~$+*O"t&]3]'3a:I0 Xf>$㴜jh~Mˌm=h.K+Fks|'tW>l&ojgf\8qt5P`?\Vnd.[<)Efa ʮ> y0(5Ѧs#jonrE[Y_y7T)HRO辰G-FM8wSj9XB$ cBǁ~vّoGÀO6h9#pf׌ʛAGǟwΐןT<ڭia(Œ$D[ ^JmoZb[)` s 4ݺ~u`Vhqz@d GAJ!|>qwz KVՑGfPPg3`wzMd Fyȋԋ֫[k, lY!mbq{SO_cέ_aX;m`1OƟˤjI8/7)'% gb)ur'+[7Z~@@fmuz뫚 Ec[Z-~~W, VwU֟(83S˃@KHBoy{+eBٰ.^+8Ap{d`L)>8UQ6t'nwj2 49gfY%)3DkaElܳ r:F;j0)w%)f"_,[HqS[frKe1-@#/82)qb:GE|2b9פ, q,_-R=Z4_gXGhVeV7Ʊ>h&WZ$o<$sMO9Ig|QJ/]kP4߱:m GXDqEܻ{.(.o\#"ĕ 7dS\}UC9FTU9<(4/5 'eڒ$E[УTIA%6),0"G M@.YpUՔC#[pt(MdnQ-vQ$W"S߬Tn7"+7jM0BG}Z(#%yFB,fkdY@BoI6_݆ >r+ɳLj!w<ތ^9s>QߒnnZ_Yku(|Mks_DK'q8,1|>!UTD?3T KK-TZ|\Ԕf-D5ew5wӍP!xc|_QZk5hE1arƺ Dğ(oxF}b rYAdhr$MCar6BYGld_nHRXtW,e^LDzdP uX`sz5:Zأ5М*BCq>;RxRnَ}F:,cv:=_0 1v)T[33`yK쉛>4Xy{NF~*JtPwjE +P+A-y}Znw}n\>HK-Hc%o:ӺE)sYrOPS o$rm{EҾUeƢQόVU-3ϑfSIT5&2WWbӅdfzm %5-}1^4j8j4t[$=Ԝ3B%sZ]e*Z9 ,\ͻ" oѿsIe1F2z5d7 }5$Ppb K\V잩Bd&uoG,o+g^8o\uuSNv$?y:y <ű6:C?Ըl]E+<;t gHb[1ӉHHgslG |h ڎUm8WUQArRE3VATG e_'*kNy ~ mtN-Kօ*ګOE`XQz'M=B` ۤu0*\K{yKvDY~D?0$ilƓ`z$jrIhL .TY9P(%tDSy÷rUKeeW .*$T6F1Ԥ3Gj|T0_ts=IIh'7I(҃ލ\Q$!9[NTb+\1 N#C|}>S]LƂ%8ZhqB(!7*_Y ȹ,kӌ}qpzd?܀]9 í>v3lz"tjzgO/Եθ`SHe3¾lT#DMj>\Kkj5ߑtQ«^1~W3Yur )ꕑjIz9f#a!ҥ$ǑGf6;R(=4PYʒ1vxh:i},H">BO@D*W*nko=wKcr?/ì:dgSem\B3UrL U2;_H+7uA.X\5^#&Fzט8*a^%=F"mq?Ld~Bsr4:8ի$LDb5p4*_ʮ΋sKaP"}y|uWn]2Q 'cH#Ҏ9x|6}?~V_מ" q&=! KɘZM~D#c'iQ`j_rX7EzZ T 0⋷̸?%,W=9PhJJњH^/$ωC@\I8]HR(7!!'u_-+͒ú>ޓIY'Yx*0߷-F٘t#O^oF$ 3m.%e.9/S BlHK&[M\ 8`uN0w-ٚC 1CtsM ,7VI~;d/:Y7y͌E8*guP(Y,4{7L%75m]'mC7 Vjc47 JbW^ GK~ja.^+G0K;$&tfn;xV~3 7{YLgљ_A0I@NLR Ť/)Vݱ?* $璮ەu|˱mxR: *`7>{$j__a r<]H?ڡg.dS@ALVG]IW2؈OD y$䯊e+д\-0UB&cA ՀNo~Oo`X^)Jw\ D(NwTX9ȹw~ӚLY[i#Z"MSJ'ԳvVt΀т(ЦPHdKgnÞ[œt7O,IQ'7whzjQk6^ߊ}<,e@hd((hT ,$[[}V!j И9,?K~Ýݔf~dNuUwa`=V:͎`aDzNq lfOa*--3fh"VB@^% bCކ1σ!{ĬM~\sT#ńÐg4>sz 8 zBeyY֡C<Vt'vIjUCOY:lF)K.ZJGۏf2 vbxb5TZu=!AEBy_(PO0!@Uk?mM5&J"`IOnVSHdNO?~f@[kok } R@{cjsSǛˉ 4Ÿ1pE'gaTSZt4/OO:tэ׶`$.R[+ M|f8➎͆Ƣou$ qY)V a/Bu#=D xh"85&a%6;LV-^\p< e_ZdN,f MLBEl9m/nGW@'_6b:if:d[{d'Q#0mq sM?d'M !Wywa\9nє" HY`ǿyԦ *C?ND?I ?{ A*aF8z3֋ ;\엨Irg/< @Q}WKaP/-ҿxg0jv[Ҋ"Fc*>JWw(e3Wi̢ƾ8f}q)m,VF6OC4p)#]6[S=5~U5aoяZ KtI`vq2XyZѴz}ftp o] nP /^ ;YWw,y9<CKhK_AϟyGiOAGjj4)CK߉[ }A' Fai7ZB`iv=SV-OJ؋4{[1>#{H`Z/'(Ʃt qB;MD{*h"Iюol*(Rԉu9جo`>zPSG&bB@w}L]Oka QwT+}tAd$@Ė'͓;G_*t l9^;4WAFȨ|L-Vipɉ熅g}`uM`2sBqc03&g& SN~YT.LUyBdIңT^پ0%?1 ]}i2qc8̻*^A㪚 \YۿҫstGVuD@+u'q xd |-Pg=nK4#dqppb.h/MӉS>A%5nvme heN-<)L%u1e;fuM0:9_)& BW'5E~ &h Ny1' 4bһΝY6O%>aKv7CKKo$xRA$z Q֢BiKt;؉TOJ\[ p _x-yq5B{ht|%ӻ֬ecCh3P;Oes40DNM:5L֝<ƋC q0tDhӺ ҔP9 V_-lFх<򩼵Mg]f@/( E =fZ)+HH+:iVi[.m]R> {vJBzN!]Tc0VF(XfhiBdVĎ6XARM1,O9p$WI-40awf@bNOal1k :7#6B05kZvbXRkqS!o(%RT_ǻ _+C3GCc6G-岾יKgK0]<.){UJc>YAOqRɲd+7 <9,_w>083EZ$*]_F|)aMxpXy ߱Af̋! zUDj^z4o %8WwbVu% ji,!W^ 0`T!A 0gw;n' Fθc [_y^Ǹ8jӋ (\(ŢO] @ph3OWف䋦k&O>GWW m,1Fܿ:>9Z ^o͒3kogȔoݓwi'M9_6Xa %}FH)-2;IT(/ʫ=S.rhL (ŸU1ues8 ĴպApPYLG(@g-$45HeزԄɴC=PPvHQoSRBjT,Vns.kU-[eג%M O~)t~[s)tx@!ޏ2Td4r/bA 8Jp ߱8 4o>La#ym/2C2:}H9?1$iS^;+'LGa% gGۛ|AQq HLO:W}=tt0?4Y.[@L-dݛ['РUvz ?<)HBڌt.ՠ~q/Tx\!(gy|(qi͐ęH؎Xǐ{y:SOX@.'ٙJմ?' B͑I| 悂eA笑*ZL=;ͯNLzS֩sa/qŝ1E ϝĆsHffJ0/4)RlBJIކG vu?s͞NX 鞄azBȕl Q+m6mg?i .z&{i6)nڒ &H%uO50LEޑ ɯ[uf]J=x>ۙjA/:[3`=E>C j=T4;m@uȏ(A-s貋 IZ:D@DbN$5h$kYvUgZG_鍯/~.ZrLj4Б/`/o>,׹(@|h^A@iÌ>EFb֌|DYPҫͥ*^"{ eC63\\ַj= TUO_.r/j&?d E}G 6.\]URGg^ri ySoRngsVk->Q<NVN*Ks2>4Vp@vt'Fe[g;e[ۛYEB^5l:@k h R~(&Z5oTqUGx|]\)k u>brf@#M:i$CѫݗЯp$S*I|-iFF6uvo@TF &c>$c]W@零 ` yaVƌEJ5yH45vkng5+HXJaIC{l1pb5a cȻ/48}қ܉EڰZDXb˗'OK3ҭ=ݽij!J+̌5;[9hʎbx֕)f" uDx;尴H鳧R]TzsZ'i ̸ lk/;b1+.=X+L4U#/1jroWIBgʺȤk8r&9ż,<5LgXUYz8HK A0].'p !Amk( ۟YxtLxI&l<9뀩D&Lqˀl'kR.kee/r~(jd YU=Ӛ9}S-0kY`X#$|D;yeiEr}6.wM3?8CB٥8_O UTU^#1d'9ӥPi>GVz㘽Z92L27ļ梥 do&'?0 >jxW%ʟU/3/b@xIa(p?jO=,i;>rmd _J  1SZ{Dc|'4MPl;0;Rӥkl4w؎C؁ ?||X!Xҳ`!+Z͆wBeǮ٥cD)(z4t%t[316*5d!D=C߷XS׫TK z ȿyNhF^.+z]ЋLX O8H8WҲDcom: u$G+ Wlne4-{c=8k[Z8ieڶѿy)I4i:Iυrt!.!TAn +TLLnb̊7+80uorM6999J)_t{/ՑRP F dPH\:#5F8mK#%.GMchpɵ4!b&E Bݧ%8ѿK)2qdf0qZh-dByf|CT`cdؘFW#Dv3#MCe's`H=)QYW1* FŢ\`ۄj P@ _} *ͻ`ÓeʸƾO`t4[7P=#_mzkB SK>TI4DwـS*#q-t76IϋRl`@cu Z0eK F.iV z=ǥ$ ʧ [wbrֻǼ8)L޳,HD~lڽ#U=iH_z;Ln8J$a\5š  d"N Vt]k#~_&8ku`cO 9Q),u?p?AYh4X_Xq:HR@}1 b}+Cj#}bWX 9UNh$;d!YB,@?l #a:&X͚TD:rv -ӽ}<͡gs)i#ZN7&/}țPYRYUyoS; AayLR.fKrg1sLf2=ΊVl~yq!PN0k FȔwBGio6*-^@ٕSRs=Xӻ>=b G}t3aN02`t+Pj'=̦)-xlKt[r-{l$6BeWA9*w|`27=Yew "ѯƧ{l'EyJtG"e<pMX|Nض']2RlmIl "BV#H@z0*y0%upaJ#g4sQhWN]^;:%G/_SB H5EPsuUde|%Q59Ȭ0٤BZ\)CKJC.-FqL-2GKQ~}a)eUMdIѬD9M–`1jp)Ơ喯!*W}n W3h\ Hz1\] 7d>Ue?:"z5Qi '7XRu!e迦cjos6pSiPZj{d:A= VtgeUڊ!%&PZPʊ.[QbVS^ȿJɪ:C\$+ƒ٥u粌*()2q Wvc8lPM4-~pJ)'a8J+')GNv}АTJ%VTe"UFa"Uc?Vd`cbt{S[TUO95qf\t6}M_lj:@TwJ83$B]> pَ5φt6B_ cm^JӜR%2:Hyv;Z1ڎNhՠjB9ky56> N{>O.ZZr@%Zs%8}qw`=kH sKMv&Fp;mi_ w ~D܈@Vt7ʹaFա;n2;]U BFk,c/Rζ8JID9,@]!90;*MЂ87WҲI}A BK SLl7 bnnnl]\ ˯w2 (*YC9oLNI) [ֱCZd$saAcfxg'@ͭBcpi-=tWW 9 ˇ?h'/~J~BйRX.C _0? RrhWt^j=Ġ;C븲h܉{~7/` C1Vj0"cKV'Xr-.sM؇lt870 |ڼ뀊H! a3y>`xq^Xګ='?&_ mQ֥[{}XϺ$vqq#TZUs4[ SU2Q_nfnEE ^g*E Q0mLrIf5M~$"?I*ߧRB0fgr0 oF-mHJs„'ed`La`-pTGoAeʖw¥R^&4IOdI;gelc*g6ե=W(aC*2Rl _QU<'"MttmQa]8gzc`^8 }.ZbqcNx·E"㣤.z3\&~W&| rʊ3?~N py \i.WcʤIZTy0M-R"8)ͷ^x#/k2@6Kpy᭬g>90ުECaf4)L7BYV--LEGY@|>@>0iպWf[Tt௺_'сQ'VRp\3ԯ4\vevlBz TsgZH\oAa @boe0z>*oѮCbRVY%dE6e|i 瓮#ʲp"!GR5AAcJa<Ac1VlרМf6_Vm:8?''m͡:OuFȔ/MrMYxz %<(R#JN,^A)~TB5FcIe8^eKSbl°!}e'vq"'}kqCI]#o>Nr<ZbSs?ǡO'+dV+?Dy$< )怟eak:ť1Bo#ϒa.u4[i3ܾZWT>FX) H+>]j4>{aee(,<29SM"0[ˇȪ6 UeIo&pi<o#5-#T<}QA}*nHRcbw~/ˢ=gd3GX8'x@4P%z>Ser*zyԢ^ȸu@ele?l vf] Ќr l/Ț3VFU &Fqhw@Y`|\ \׸r")wLgu{'_*92}AI.{g$,3*E(ދDy|#|A,4-s-O(njg2K2HF &ʖחW,Xh ;Mw;ZqD^~I:ժ%6ئf}Z`;"҆Hj *C䃃h:_EHLE7-^ ;b+)hiڠY%s7͂cU1TiR+ .W"RyE;E[Jx]ļ$ne'c}tf',IGZE}>|HD>0Tlc!KHDY:$vɒ g d]K--T#֔۵ֲke8WE v'G}G3NL)9ns֌M+k0 e'CXYmM)ie?ۊTe 6sQ:BHΌ>:=6IWG7q ȰˡXoA Mg> 5X@ 2 ]F~s}3aO;VTD@VysYgQ;yVU/t]VT_XMAhGP}#ghhzהíjԻ^Y`1!QU?1KN=ܒ6qupnd{mZ//B@tIUD}(@=k7 cx'<*_X}|3x<.`.MpͣU'|E4w v>Yg眂ve]>Gd$aJ8fMepw}YW#fWq|^9vog'R))BG͠jn&Hx0+yqofi9Uyj5XWT?x9Ϗ-a)W#2gؼ 0I5 PeDq W|ՇWz4]yL9^;,Apʬ~W\|:XY<0.,c')iԘ S 8e&|V:Ec]ʳC/:(r'; 7q[ceR"j Ul&㡜jy? [QUT~5JgVC2<ljs9 [œca-N οKK I! C шȋ #ɛ{R 'PnC>gܢgvPzkA_x rjꛝt%R-1y*cpGcXF*KzQ]kZ;+ Fvsx㻕6ǙI(_ȓI{i-.YE/Pke=a7<ÿǾJPVg[ҭ,q*0dO)w0QIuXM#08 ZAiSUN6LO{B7"Lb$f#Lj/" fR8}Hj1L*ARF7' H$p_4ɀz+A*2P8)8Z: 5 +ylH;h1 v vޭpDApCZ  fC:@c Pf :Qݘҹ2!Qzy\xXB2ik;b9lǶ'w]'Ҿo|~KfX͘ _V"<^%2+@x1~ =Bx'6q:Yz4`3m$_K38|Lo JU g3G % 4'z9޾5*؀k uxZMm,`(54qy[Unk>Þ O( ['D'R`8G:"#B«XܐO7ʑt`B̢Yit%{̺t 끳xRA+4&;tHuye/=QK9̲[F2hJLʺE)]T %|sH$+JRUݾ#N$?t)|48{SnG| 4JTdI*`6걡/j8Tc9 .֎ :"&_`[͚<݂qydK]-l/ ",PS=)KMZ6D㶈P|99ԓgvlZ@/(~ MO_5c;Y/ObGR` >`&YˋҍSrBяJWхJ{U'.UqEC)l"}"!6S!G..zȰo,UJ `jsʪ dy*pFm29 !!tgQNcW#i.꺀--CQr`lɢfx63)i ֑ɵ-+, ǩhr]ˁM6с##=vpc~ l{>"Cquy{Csl bP/QGޓC[݉ q&rc2fW6ٹ/;fp?X\7ӌ (Pݔ_֞Un-i~pE跸+E׻ɼ5(n,)W1#|lNmu7Z& вKmd{jYvKZ0'ԾO:_Kzde8n &>b`@Gj0JD} zk{lK2~5A:'n qS2w LM7hmKG&:ۃ{7uk7gsAI/)BSP+f2:\ yB)ʁ ;Ń7\y`Ʃ띇{=7&3쁣= Tᝢk2dL>NZs2dM."jRJխqu-wGSD2,o|_F"Ԡ\*x K :5îNO .ɪQ |zAZwQhufq91g3 F4תE"w^@A{^pHddҩFħq?A@Sh/Fv/VLeК'4~o(9ND_Bݏ59Xdw48K>bBVRr/%5x"-$Yzu7[0  K85Hqq-T:aX#gюڞDh@4FWEU}N5Q.6U._SDw6 LczUnbDS Uft+k Cam @l;rG=ӏͶDs*nM<_C梄|u wnJ `%&ؘՑXTGXHLts<%p.f!`mM rwri!4TQ8gP\ є^m˸~Y߆'^O& j?/֬Pχ &"z.Hӫ@N6kx@y2E-ܽPGY*aNbr*IL)u#LryG޾O=GtWD>yj-;UUYHCZRk@dS/bk7fE{:?Nr?ۇ8FKU)iϴ |%pc62 5&|[.PJ$Z!#F{?)%FṅIcizt56n W7P߮;onncNDSr w\2ZYS8<ڏNtPckp2xG#̷f]`Ͳ(Mf;֌k'WFLfz;7EKjqHW ]<> U??@'He&}5 9Ft#Ŧr3XDc_C榱ߢ˛~%gZy҆ #ٲ{bQ{qPת(O*E E,2{ƝxxNq3p_EDqǃopM9 ;r{L0G=.R͗7DBLeo]Sp=7Z_^h.r46"ՊcakL PcC.GۖXZi`m7(WE>K+f̎Zn 5[.6bq8z$Zt:Q^cZA c[ \@C 5 u!^ f|^Juܜj.a/= h$j2ٻ }aTR<>[@mFӘ\/' t=Mi +@n-}Ż2]tͦVD_ ܛ"jB4 ex\}Go DXaF8O$L!ay,ZGέ-$!c(1ϞN79nL#OeEuh;V".kO" 9L'"]U?o촬b=ZIR-hs#ބh7}l )2Qhk-R?;)(tFF c('430ߥ21]zYΕ劑].O\TA:NA/'\H>`cbe>{ Rn0-]6Fw5?v^};pV'L۝ #ڙds5oo (yO30oWz5F5 2taJ Z}wa%!]:^Ɏ @IOkT;T1ǘ_dFrBSPqos)߄-Ӫy Fçtػ,;ܙp养6=ll\{Ȳ#~m2NL}ʭSRLizAjRi SiіbFvFQA=F@[,UbbvCz%o}uIj@K-g2כ7vasSNFy[)߾`z`hNC H9k+eˌ5 }} ~D}(Jt3Ti۶II΁IſZ[ jԈܸҲP4 u4yeŁbZnaC`f!(k`P}vɺQqէoI8$ _yŊ?~\/GF';u\f3bc9UF!j#w < !''AUhqAƹ~NCp eTYM~9ct.ٽPYVp$8=j/dZ>bG$ m Lz.vi:0$5E\=F{6] 0Imu0[.RsBaYd 1Tv蟘:KāgDkp Jz,EXpc0x7귐=V : Fٹz5u%LAS4t>=P9ı("0I3i{<\xN5oVg\U&[cXbV)9U̳J';-&4J+C診U>|MmR j_s.pW`\ a%K^Yt} LJT&61 O;X/#$\{*1 *DtW@HPN&꧊!ϭ~eĝ`lJ}f9Wʞbt߳Lo( vBdļES:= P4WD + J 陸+Hi% O2qه%u6"n@TVC-R+9S66pNBy.Dfc^+5'RJ ;b[yu؃}ˏ3%?HLms&}oLY1\bLv=5-OʱN>if#!MDs1gt+b#ݽԁ#1-Vunf-X~(Hh a]( 6q|7]q--d;;ja,FR)1Xd5|fO2F@jƧ8F(q\_5B! ~ S ?.YA,("XykèyT[dCꁈsȘ?s(^AO'M2?d'~l/\;__\emSުzKͺtjl^Qdϔ R8ʹ>Ǣ"mQ+^111@ruќ?A`WN$=.CD $UsONf5)X sJd[A d!̈LEe):aj /xX,ZПԸvRa4Ef~*!mԪJXᙱ6%(Ȯ~">IS]ѣ='NElćv:`G/nND:~1XZ~! V)?zIm\ulMɔ)YH00&n˹bd7uHtbS1jn~p^Gߧ A{D={M&mR4/(!އ_ynT]Na#lNUJI&W{d-ѹ(JWS='j0$"zՆgÖqP< C4Uu1#}󅀚B+=K, ))J΁<%`/J>blܴ7 W8SF^H\^>j-ٍ[Xv{޴H͎!H*BUɥkC!x4'HEg,PVHhXʥ($2RR1a^)(-DzSs_M mDKyb]8}3)|7I;w̯("|>:TnÔ4np%pWQI9%AcJ*WݨGvp]nN' fҾg/Jv3eC.<0tk9OfM-Ǝ;me .z.xNP8.g;gǼR`zwd_di|aZ>0yB}8L J V*3u})b^orx!*59( vǠ2JDo^VbPC`X#WL" (&MUcr?kf C ?k# ŷv&l;cy (>[GBZA[0XoORƤk&kF'i?",;D$@6j ~/ É꺟Gylb$7@kg7HLҌKaG2$xGWɕ6 9Yyp1|ζǖsb@%4)G o~Aw QmRϸ4MCuO\B^=b屗\HTg 8: .RAH*XđЩ!% ;m] w5° BZ_q!,U Xvwo lmxn"HFWGQҏJ1_Ws}~~P%Mg W$ܜ6L(=ۼEA`^Qܪ6G-b&XC&\h3ʺvB6;+٥( Q0 =7>=~[䷅͝>r&impEV7'NdI :)7UTw:<w>` 1=?g4.Lo ;nM{7FޤC ^@d,cnF|w!g *o@pFhn+2\T;|n RUqMN*Ű%.<8t)I.oT< \=yFDD%sg -OI.`T\:neD9ڸSRg]&!9AT0Ȩ@[>\:Ys#Q}I1%yu 2:W˩k,n> 3'6ݡcݫ,DZB&NgyڼpUن\O=A4_sh)&ԍz +2F x J5's9Iu!W<(4 2qcEi1B&#ku!ː ;KMoV`pL6 r~BN".`H!ݲն! Y7 RQ9<%J+(/@HEUouޏԇNQmZe$mb K3vg~R(-Z Z{S{)[fLD01{.sJ:}̋Rm-p<<ܖ/Z/~b9җ>w})Lz!hAU"J-&vPg"ê=Gïw1A ,yk;bXո?9AyO;OG_SOS!IDP%"ؓlD|Lw` ZgtV͌O{LG6sSؙ3粆놭}YK;ՂA!#="VB1[9- kG-]MF=֠׆?$*ϊL@ۻe=8 ~Mlۨ8I.% Q ='&H'`snY2ɦ(|zr*q5wYQ[@8g^)Ƽg0*;6=I>(=h}9RƂr~EeQPu3nX7bb;y r]aGOX^Z$dʪDQpE8r <ȫlHD.mv*u_XqMCM H* Ϟ~u-֖x@tQ,Xj9ȤSUXh|?O.WJ20u²5XY \k{9]^\gS3 R:X2&r *Qۺ򧔻cyRu$-oޒl¹fqK1~[n xmli+.F*~A';! u,>rpM.2g]S3ӌ/8@aӺKHzX?#.L=J@|N2wAJњz@$('x:\1{rCڸ%қ~/580>>fg`2B@$g% f&@TշFR#b̛*1=A\b>y%i)~3fr0S#pvQ4z fҒ*iXoX`iZT#T bH=y߂dBkML/xESx#\UVj^.)gn5@^~/i3 xts[3~KWU.yKe^@ƴ'E%hU-hkǰݠa,48LZF[/' 7wk0M=B,i.ad{ŕϝHM)f3|=˰l3CtlٸuVn<*ya0՘;I/jZgOKZ}ftuAde73^OCp)l=5&f':~vhCxeU9oo1$ꏰ@rnրsSZega͇_ˠ+'zsaTHV# *Jmg,M.߀BC/PG܄8i'OfAgB2}}3K?y d4[);Z]|NDk_:7Cb6?)V‰Ϫ>``R@VpQW&b:EL#сn ɩAd@-u9Q.7Qp6œLP-*)й$me#|ު2ųޭ9Kȳl"xtBJ5'z^ʄJkTi繕' *o% :9)Wˀ:5"vOR0c.xŀ;vnlsIbPO _$Bkf\DJ bmi1JuE :u3KmnVp՝ ]⦍V[LEۍNh& nfHՍ6 c0c }&⾳omuDO?SpNmޜ;3>fiε@MoStgb tmKV@틎0E'N@SSG@RL&?:Z^<~b!'3 Cx2,yR 2&Nxڝm 'Tؤa1~k1n%ͨҖ 7d; QNwUU,mq kAf(HHxUlx <$uBND0 -Nĭ^E}s'QOs^7UĴnoaqu&seϝB4n:q0p(LrT-dɜO1fBKӤ5\ @XSrnHDpM3.OVVAqLM)o5o"MR e޿I-_1gZT7Ug:8 c)FՎbq ^6+·G1u'WU܀3Iȣkw !Oo$bHzhn;҈%VFGxF$`I`~ׄowOtsRQ%W$a#?:N;eIN,Qbd(֙=CꊞSM`:ROF8J#yT7*'ZtYO\?`f [~@o ^wEF|.U 28\UsKw(TXk07Xpo"JXH VM8D X2ձNa`èÕU/@v?ḯ^4ȣ zEֈ;ҡr% ٝ #,8}=毅4˟NyVEFX,Rl̑djvw~wSHc+8׺JbR}TG;,xZ]HIK#}ńAѼ*{Q̭ؖ"/^ G/fם4{Gڤv`Jsl4&E,U]};]QxY/*5pjN@a7q 3դdK4$d2߉tXqkk/%b/fExRZo: v =Av&3Kաoĺ%8cp>J"y8Hz + bLX : U7l!5TuwI?> ;!m,%upk[VxD+,ٕ+<_AZ24x$/O Tn23)Կ {c̐K;za_YP*-}k3x0e9M}\=N`1> Fto\ꞬLV& A$<ŒӸ[8>Qd0ۻ*j$@8INpC# x ix5?R+;r+8RYncH%e6Fi7LCv $Oȶ+=3Fjy![<J E]RױE~50\Mwې1Be#w6;!E&4+*wV6$(R|>2aABZ;oqAd }lRP4OY`_Bΰ29C9Dcz[.+DTgU<.wh=. [h@;;R\6 UoaV (|euj_Êw w^MpZ[R6贾d=<~yi , C=޿7eBq3QV8QT>/1qs/U6@:%[F&?_,lhdWEY28E4zen BW(wb~TY\8z}Y}  ͞bk3WknnxKм.oQ$Dd"^ET_xPF74j8̮,gU|6Ҁb}n4 8}F16[?%ʐ<?O:*LWyb,q-1(H`S_Ш+(]y\4L+&p ]u+nj=*h^ +:fa_ԍj&iG=b1fowal۴XXLt_3G{OiqEy(T9ƫ8r_' ߡ ߣ=. [0O;ifGe.jvx-6D5 {胿Tq>EW,AAz X\'P'K3\>94\ӒZ'>~BA~K6_~g|YSϳv*nSW b /C<׬`'C#2WQ"祥Br/_~B; ֥́ЖIt9,%dḦKmyuתwGcJO)yi :)ͬ\s)KOS͹ju`i.&v#9? ޠo«Tk]<9W:ر{*7ĠfD2p[Y[P*os)Ice7x{FaDwIRhvP$G,K!B^j$Ĭ]S˿&2cd& Mia7]<$yy&.,zxˡhsbL[6Sv lw|/bAh5"C ńfEMTcjS Lm[hLmɁuȣNS5!c4 ĕR6@9 Of/Q?U~F*n[lpN8F|$B|Q,(C&r?ȱ)诔vhzZb&>ƾy> +6E-}{V I臹WFw:*,LR/pq#"5-&7(B}MK?s)g)D";䂽{D[ȱy2] {IɄw,`ADEtE5;bSqtsw|C^.z?>ߐ zJWvmBmX8ƪD2E$T#`o)̳CAOLǞ9L[kE#F!1S_V,؇S{X!]N:%oD_lmE: NǎV~2&N`I~]9P}ͪ6KA֔gG%F9+@pQ4h^Mɇ0sGG~|B.%HIjʚ272]f׵Pxk8[V*k&7-tN==7A,paj8-~YBҵ@;dH}!1~ol(Aiߠ(ix8ˀVwj,@xvPFg5Ѣb$i|S6G 6Id B~%o&vIdl!z xrKXI[=ujڶ1^._DhUa;p%{Azsit{C)tLZ٩qҚ[ 5*;U|Q- @ -dܯ*K_8Gp@/8xHAwZsJN[8@Cj(3m-oO}m:]͌i B51sg jB_D‹Cvdh/Ek-D/Qh7O*OZ?/Ch" ,`bWyz ;?t 7_rN^ҒA8Ǵo߫fcZK&C}|(]I?+n 0PG]l8 MZꞹɕ*(շ5o䷞VA( ZcZ xIUHrIg'FF#`҆9qsj-O(Dd0PcߚԸɷaG׶~;'&1uՉXUuhnHP/pr}[_,i~d!!+XbPA-c9m-D(*:)ӟsKoRs CV=piD!O(Pw'ʰޛ>MA? z+w/X\.֓`;JDCBh!#69hsϭ z` BB7]@s"ۥItAk4^2$"'2DUnZѦfϕ ^# W1$uEy`tK[Ju"qk ;B;kP@%Xic?I7)>v̷S: QBZAM6e"nXWShzӠV[xQ|+"h (|p#U`'=w:~|]s;>27' 析~Ef<9δ=r4T% c~FX|)}PZ8>1B#cDHKX`8W'g:aZׯzV 3ԯS5^TEQr[dŞ1k,u$Sǝh[3wX㕅Vu!%=m8#9Ⱦߔs24wVR{ĤJJA)7t RH)q5ڜ3_lp)KDNeMX|O7/)8D"= m{ygM' O?5PgbLNEu$f_H7,H'x1\̮q "pV,, tՐiDֶ"[m\lcY``K\@j{ua>]0$m50 SQP.Rvkys-RꛉiDZíSACPevh6[=O4¡O"Nk-R"P]D?Im#5ZcҚA[T _sVnH2w橣C2 ]?)E-eXpYAkU/ cu9H*B*ɐR m};+]`Y\6B"M:RD6TYȝA;p,*߶-e&T}e8@6݇y=F N.H o6lU1ίx8< ֿDHv{,^M_fhrd?D5@4"@<3ke$9by(>XWM,t#wN0m`jN`; p7[B ҖcXYZx614=lܖkjE[ sn|I+e܍"t(w]{we5ֳ'ZGnO2DyY{nEW1j|2;j@]t) vfGǩȳ~:ihϛ", _!7.T+휣rOȈ WX))ེ[*Xc2XnoE?g`#ܑ|JˣԚ? %+#L(@Rb,C?'hdNaO 2#mcu)VtY.IV]kCf'?7'.4{Xۑ_7Gwc P YkS+.U Kf)~* >! + 9'N ̀@#ez8_(46Ύ>GcRzei0 "i KܼS5Z*y,O֒>2H⫮;F} :-M{8̥Hkwd)* JzI6zx0խ΁Piguɨ/x>' 0>Q`j: )@Dg}hɍ*X{i.pҚޅ=LY'$V )3PYa |QM<*3/5!ǡ,K(L {j*JrC D`۩>$E]SeS6)iGgodREm.6gURE#_ a+d\1`דH]8tnv_*Yz$,6o&B#Mwe_@&6R=!\5w*;Wfq:7{T' ]]Е6~2sZVLq1 j[ɍӁ5u_3aIt\ d,ƛ$&f?7>sjV:L +a=vc0-,첵`G$};ʍ04'NS P>TJwJ"f h&(+ kޏ{)"-?3`b򾍃ڹ` #p>\b yF5\c֏'=*xfÈF0.@E5R=,B_3J Ԇ ldTu=0 _k`L*`S$魇Qi9Exeo g)O!!%V:έ[[%Ah7)U)'Ɍh]. 5(#@<kPZ+53bz*פN7ʼs^g30)jv *F_ȶB'iοCؐo6Ph\ԁ~D'Ƈ1ш7G؄)@al uwIu \ӭ?EbO ~HמTBF IրnqPR' -ddЂ7i@>j%s]VyG\8.R r&8U\dr #~)8?ކ(Gtzޮ M= ӳ$ "x0ÎvP|FFh/-ӹ*\xDEq'oƽ5 o Za"*էu3=i6_,G@{[EReyuY#4B̝f9dq:v2iÙxleefl>vyt>KʺZϪCz,7࣓Rv>ȗY{|^.R`CH@H w΃6_z@z:+784@|i]/vYեhA!J)F J2zmG05kA5AX^"nJ4,5"Hڻ(]ޛ?(^;A5h1(iX1n͙vm,06>H#,\ꍚc\FLQ^L ` ̲8M'&{RПBnӂw,fVf)H%Ʉ8=Kc:ΠQz/ &-Lȵ1yl n?>KPp .A5sP-V>ڝm'@Wbkh*;'Έ}2!vB$R:c+ ˲$2JYX׆*؄Wo:8 tC.et['<}'.0Wm0g`ݔ~u2kI `ULao158Hh 6E2lD꓾j5oMȴ9:u1x}ga܍j+7|cfk}0qEmA&nc[^C+PF5SM4sToƇ ^lsJq{&buA+%MҨmc>a{5HJC{ZA?%"<l?;|AqpP}(' 0-V9&utRqZ`ʄF 7/ǽ_ŝĬGn[t[U =zѼn؝lx/'Pzz6T ߧ!8g͐v`,|[`v}7~ǩC"so-? uc 9= Ȇ~ykVpqMyHmSC韋fy$|"䇺G?~#X,<3U4)2w5!X5r@=@ yH?I F/ V {t &ל}C7[}rfn4ְu.[;Fo.FLtډt#F;-q] |H_^[yC0cBiĔT/Q^BA(A+W!_k?R(K~M| HTDt)$B!/hD:SIls4gJi,H~0GFt]T&h6)%?smţ v?&ZK5N۴Ls|?ykan  P @UCAoȆxL0vrana ͑ gUDP.f 6:&s} Wj|o(+apK^4jKqь"H_ &@b9<C*qXϳ` /iMvیItdcWIOނD//wrJ=:%d騈=Sk+9:*X'Al:d?@3tsS PmK5oS$ !:"JuCθخ [ϊ(v#LH]N2t_۹׹,{\c11|}Hl=314@{0*YClhAr.%D;ѠE#O$rN{RILs ԱQdec+GJ,]B`ʲl [gTޞE{9 @ɸZjx==GiS{, c&\@Ob,H>|v>*3)8OkPsjs-fT'd5=>RBPvSGC8B~^D jk>ֵZ̝.J9`e߆2Ѓ^ FU!ac'+6e#4tTcb =[e+"p%bvЉ7Df3|[P#!kw/b9s bҎѸB̃P?Ͽ~w?P8Axzo8ud:F\_ +Z o>P`Rj&bfyI`;N"ݗ_SSr6b]I=U<ˢlȨ~':@Lj[^q{tZMPj# E6C88 }xCSK뻢0)8:W*K>;Hˍvg 745n0EJ'LRRȬ&*'R6#HlA1faXl8Wj;$82E6߅3lji'3Ug$w~\B 8?W"֧ϊx>{șCBD0$^?ֲ_N^cزS'ETꂈt9 T޺yG<|~غ2I )><: W3 25<$>u za[epkG Ea.q;fiLRn,%]|f1ΞLޞDYmt "UEWp &TQWk1NͺU1QYJ]ogC3nR."7ʥ!YHmnCoC*ޕY'O?Lz*;_г< &D\YOk;hŦr]֑zL6֕< z,nvO*>['C3#kſ< 0zX_[iA\?t>K v~_;MQt}*(Ub2dq,$]ibnkݸ)P !`iIA 0 E=pť9Z]zrCzPGx@}{˗t{]n \;;N'/6 N@~vY{,e?<1wI8"Fϫ'-P»<Cw 80h隓 7g]5Wzp.tUP<:o针a^@h}TpR@R_o7@aY qfm1 SZ%܇Sx>ipޗ+Jy;J(ǣfHdq\U~?HQL;mK1M4H ҟ zB9c8 z>@bk+%EYI;70Ƀ@Kh1ѕda53\!o6]>gd{!D#oU*5Fc<ˠs;fX__BF^ ?*_EK䪹z&YRljUmB;5_v(ZX»Dy" 2Mx9ˋhТ33(y4Z!쟜w+9dL-yN? }1~R ' 4@8|3-ko*GZ1;ĭ t)Cu̳Nh4Ig-0 E=+.#AS ֻbU4j=m=gH@!J Ko~$9􉣳j>wxq3 pʪ樾^L^N[72Y}G>{6YBETS|E)MiwM3 QF[1hr'muU?|4RQEOgV\-,MXc]iW2ĄXPhQ6ݦA74@DjcUT*~ #:cݹnzJC_q}_d*@ڛ؟f7jh6 H^B^,^w K^ \ykCYpG_/#~UV|n*"Yx*+'/`)ػC[N0 $?UE>6rZ~w/r|{ `3Qhzjry<(]^Iy wݓ!i#: kby5J }c/nP+,FN.yr:!-s^ݞ}(E%׃MR)1Jl7܌C* Q?힞+ ,OW] vCب_Ep\Fb{kL.ebSzRUm晠B^|dg?5IpRuްL^f*Jr%L*NjR<uTGa<;2꾌Oh6$eoM;r R: BQDlփHE\Eh1(nXfqU8Kآ kˑ (3 y:;- xB T 4_Lqij6 ht]YpF6jgǭiH送@SQCm>\`驰1N+Ӹ*,寮{gL |2q֌V={ IBLhk%hJ*$#;#iuoҫ7*!i-!0k韔eiKԡ $kue\ X?]Z|)unM|IRU.:ͩSFk]*0Zi4sC{L-b'箨m,jU_5N!C9;/%`)u:>.TmGcguQ(Dvq{S55;jPx5Ӊsya>?Vړ5O4FU+\Z!܇2/ߙ:X_7⧤2dtnXv*k/5qhdfϸ˦͕:zgER%XU־9rrAdŠJ_AuHpGu4)ɽM cMa xg$QxJagNM+dSr{@Wx|wAʹrҦ|"m^lyP8n_->i=;Ŕ  ֙P S5?)ɚ%<(464W Gjڟ(:ﰁZZKJމ$*U  XZ1TZm4H+ N8Hzzl?29F]G~W0h8 h@Gy6M*;|/p=%M!a+{B nbwħGe}c% 9}[D'$ݞ#י!:5?h1:tXbDƺ,Ä+-'fcPc '/;kռS;[0ȞCDw@:"D?/9KH>!Mz8 +=k >95!5T =\wya/\ ـٛlg{pY ;] ZU-/ŚrbӯRxR/xcliEuQW_G He/<Ϝ`oMҠ7&qRI\ּH0Š׽-@=+V'9z]}!b$FhnR=>-kEÿgh eJ#qXi' (z܌fes9t5+mcGP )e>>ar'ޚ{?YMA|k=1or蘊!x=vg)a&fIHEBuw.MGo:#/fn3.@- t x V $q8_q;k9j@{pE5:{aNEgzߒ X!*`ɅsHU0g 3/h/dSp~ js5?P%ܥI~` U7lL0*BW`%VvU!iB+P )E ) k>0"7}7tO ]]e3OGFꎽhkQe&ƭ&;!s0P3dUT~ȗA;pc;āPvtw!WN uRq B{BÅ/:53rbA܀]X`F/Wϖ,wk%jo!Wv/Ikikrj S`_B1LVZyLmJ{h}A/fCk'eV3\ZK!JX2 n7srL0&L[q}iekbqN#]SBoe KBߺ=I' W$'r\Uu.) F69 0{`^.fă[x)/Bʱy/QI8zfKL»%Ѥϴn3 'd<sQB>VdPJGb$PVez|x߳Vq#oWZOgT2AxuN] ÁZ/r)E+UX ljk~nKLr_)ŧp̸Q+)0g  \WOj `yZq2 =qUX!B0٤gmJlE<mPε(:IRխR>: ۀhǵ䈸[F](k<8)[Y8gX986i{X霍#+Y$Y,R)snW)l~ g!6f)#w7||f3vHr#,'X<|SȮkdgӾE5T-[2H2gOSaw݉.C6`3 g<,--4?&5*7Wg͜ drE˼\hVđnP;ܷ%WU@kq0fKw(jU6]|f[Y=_,N+g3'$d 9;˾໗̂OKKUha]=Kl\"ř);M%cJers6$ZU؂G[ö{t8gm]o{o W>+Mh?I+g.tD@).)MvOy%*F#`Ea9-grn,t@ 2-g|Rq(g[NX[{"|k |%ej~2ae-H_mKfU{YY!pQ? Z uױ=7Sx! zvG f&cV6e3'/zfmJ  :=j4.[1rtsˢZ(`Nlذ#|#HAl|&8}8vBϰVST%T8JgNw> >PѲ;tBZ: n@@&/ĸү uaC`QsU04 =^+t2N!cY"'rndR wuIY33nq`(iUaΔ 3o 2 `P]fؐH-#5;dWEMQ uWMFoAo׃pQ~d?SB73ի3iR8YgG?%S]TMMjhYj"+um3o| f&f3ֶIoY`.uC[] k(XX4;6\e8iy{j Eל{w2t0?Њ'VėNgȊ^|H"uȖt+/lrN+>-ȁ!OmWw?an !X_열S{v\6[&1g*pns7Zi蔨KU jG '90ߓS|m/kIjtYK7 ^vu;o~>$us_pȝ)GW>}=jᗵ쒟-ݱ VKE֟(5SAI,5g8YZ*SlH[&]zc a"f{c$zl{<̷-gqqK%<[sԓa}p[ON,T}|rFsK_i4n% e|]d 6OThJ -y!3vHohP%̍C]bxS7 1x0EYgom>VI(019DvӤ)~$  /'6MF]5 >+eP G۔ډ_j 3\AD4(Dw:eMpkU}?[ZUN''pk)rq(T6b]#ˁb/$z^h KP /m*(T1atۇ۬r ya߽' 9Â3`?~20rŽɃDQ2az TGwO*3|4k<+H,f@9%!ONJ]FE5M, >& 'tj`m&ƨ2~Pc7"ξJ])#Q] xD4sEyl{:[,Y{LY+_pQYWYVp=Ϝcso9yXOVRwEW_33ovHO/}u5oR@ƚa f=:/pH07XLg,RM\ۥq1+OU3&Zݚ.gH/ޑ/ӀmnE kh]E_ӿSBg9N+Div4mN䧦| X5c">ZHJ7zw @:57鴁Ig[]PheVWsMc %v;Ky (=_Sy{ˑ6Ȓ= F1I *j~rߦ)}ݹ|EΘF3vՌK"q;](|uv\&G'\OZb3*QEx2Rf%.:l~ }v_7.9t5}YE7FD])[[ o/9 >L4YQ^}A{n lxR2C"*p"ՈŦ<GWy+DuN@0k`\" l5xf5wKzX>%0 gˬL7 cn2Qe.uĭJStJ)^I)wc@Nʫav"i-V{v5Nʮ~8_gTx@tDzʐ,NLx90ʾ;2AkŵgWӸbQ$G ъ2ĵ(kRO[Y\ e~ 4F #019x̉3ۜ=c\Bǣ\|Et>?P<:rH*/t%"M^4+)O+PA.jDYun۝ c5^L==i8ib@-,Oy/ /xd+2%+WJJ~5!6t v_LLغǷ݌\R($,kaa'&I-v`D݊fd=TJ1am !i5$Qb#̦ .@k$c-Ş 874@>NB62B(h`*2 ƺQ|.63;_-|+W.am";vx0M6t1KЭo5Yg(jSvby=[QbϚ7ж( d *Bc$Ao#e`W EĔ{5O1qQ unȀ򟇮^? Vs{/ ا[?HK19dԷYިxdA] /R;lny0PoV"nJ)EUOGQ$XpT?7&$9 Vtw1_$z%{MkH8j# 'm*7 #>#hF`#MY1xk6]r R"{COl"k=Z=5X7^@`04 +4Pk_CkVEL˹&O&@>KcVu݆OT)*hqT1v4١{1yޠhjQĂ!SH5ϰ&qI j8:_@|Twc (yԳ >icA7%3MƤ>ox攱*Dj"ggnViTTzdO/HpHNA_rp&EqONSIU2#&rnTq^_9;[;^N2YH`HSUMr;n4 woQbt^n>l{ V)fY)PB -,?VQο;V7Qm{;Az%hUOd>3M&9A%\P{8U}TӀsF/S#)GB?e4b.7ipq5O Q߬ѺB4m| sTS(κpY58o/HihVO$"KaķgMݝqH!)eJT0kxRk:ۻ{/>y-RI\不arh-u ֥ NHv} z,?Z3 .vÈ]yـCÀ<󔁃 L"n.IQM6ʺw\Ȇ˙g*Q[tÙILٷg"JIX8}1urE>9#z(q "o\\{svh-'29'ErMM8T3o)C/ &̀*9"C IHW)Tm?RA" t XQy0&otu4"jI}?~k0U.pʌz>U:cI4kg٘k-T adJJrnK$ DG( }ż+!-N,gW1^7ϻߺ~8T;dhѥ*+Lx:+>p=OP="˰/5.ڪKq}z qgAa ~q!XZ^ퟵ%Qo1%쎚Hx_ʯmj޴%c8/r uj!ebmBqi|taZ^ M}Krlxel>ׯ: ZmFV@aF[WޘJQum?HVD~  +$o|< ou^G 4y0W]̎BrhrX\\a%e6>oѹ q 1 ז`ه@_J(r1@fCI;|Gu?KYߜö$;}6B_Mf ߩ/%\Ll]ԕk#9\YW .Un]vIiibLnӂ `XXV'>;pĺ3P$dz4$:#.tx:XAK[vgm?|-mxuFFJJx1b IlSpʥ q#"'3+X>?VDYm%-j-L Z;.-0DfUD h%k+.S`IL<3uy*l2^^m/SBon!( ?#q6W!pޱ![Hk%^znRw"m-HB Bjw]SO3ayTBvcpVpў`}b>bNRQwOC .%,j@7m9z{kT2PKi"S{^eh4(dDX,+pNbzCi $ַ!Rd+bsv\CE^uXil 5oZFZY84 ͮq϶&:cpD;\}W2hLYEd* Dz]6B%$2E`;Q 5p4;kkw$({jeʛT]zvšq~ Y)\U2 )y jR E-碄 w&Q"g z0ij>btV2U#՗2WƓq?5 7dꝳomʳO{qCg\Y?Ec b-;yJvH>yHHfA\9RROU.ޓ2'_D*F>H :[ 굛oriqmN@vXLNZY jG׉=4m][3{6e UT6EgIe,MهxZ0"gP2z:KD̼OJi[7Pݒ!O'$vE;CGD6Ycx$G):'rhq wϨCst6 Mh㈕K hm/_CL,2T`YtpsHqҔJʪq]ĈQʮ^Y2*+f# $>P1 &eIJ]7IN0yuܦdVCG=&JUN+ۇ6ZZb ~3@;1+d'x84b0ȎH,[Hn۰h3(ƛ2DHiLR$Q0sxD$lϻÞRf}^&=d B! U(r+cms81@ULNmC]NyeʸDۅwEJ @ SJ)%HGWVtz#qjJلyl4ƱcHmZ]Q ^8\ +bVc@FAs:] Ji0 HG$4^z93 |l!%gV00>:n}1ڶM:4:2+雄n:IƐg~YYx7:D/N) 9ֺ $Ȋm{v#|eC;Pkn:Flub T1lmgf3ȳCVӆ91LТd ٴu&ӘcnO$Cl* _]j% nɑBU,KXn;0ݻ.w,'Oě>)৙X̻ܱԏ.=> CQA,⪴Sg+>3xLD){^.âs+Vt\dUl[ꮚPa8:/_p`ZE1\+%X3Ls}ʎI?j$N0'V627?Jz*D7 IYJWM\gkn`V(+DC.F0kBphŸ0Hdnyi KUjYLLVcE P s؇1Y̱_c2+uP2r@O׶sc;|pp)dXxEnL"P2);뎲D+BoZj@t\PdYPפn&Wm]_^boFt5J `NVklA _,̽-_qo`o!l+n;EA6v.}D(1^R/bCSG={@ 77-݉]HLR9>EtJ$pʽ,L B;Fԥ rxGFqGiX }o|$"-j{@7#GӃ@]T,h%hٌzm^dAk,:.-, S^EKë[|:o9@X~lHeZI𫭀ZQ.Sˮ+͢Bw)%K==$0Tf\aq_@7N8G43jՌy"$Xܸ6 z SJ>>Cg,y؁V;UJUqAw=w @SoƵn3kk9J"F<)+ 4 Kҟ|HrK-{FAGS"a[ dPL~NCuQ*IYK(P0ٞJ\ОTEX,Lp7W+Y]MnJ bP0: dDuȣtLHh}>  0\0H)PJanH@}f>ˡ,6J淴k0.+zW陯bm葄 MYҘxT|1]TTPjl$noMoK*h\rF=!1xZb0igDiRcdȣ?1ט9t exu$2Ϝ]eӖvCIR_F0 .G7C][XQJe| ЎOTH^xŷ}fa 3#Кze kP-NG ӦCRJ5;=;}D(H3 p4GAőa:sյ7ô#Tɔ}[9SAL!zQ0&N%]"z >&r%ކ58.sY&!⛏@R&ޤFAMѸReWF$)s1ZhŲ ħ BfREů(tA''yBTSQ I4޹_1}CH|vyB yts3MZA0u9Qc K"<׵7r5^QMv TuEW<;WMoJL,O^Fr48T|!A䠆GfEG;"R%IzzGSeKHTM۰2 $.Jz*Jڨb`Jcy\!ϟ{ٸAuLk=*iYLG>@Mk7Nގ5<֦/Aue^ > $UY]-./ IA] >cf0W8/ $]KuHVKirS5p rkO//(̐r} Ֆ$UWԷGͳ#+$տJdM,3[T<K*fWH%\k-33`V[UOWH6zfpcgza(~u$ChŲ*GpPT*6YXN] !C>I15BgɎoJ d|͊=X饲32*E>'p(rZgNDX Le|| 4׃X!F3k>hy'EpΎo!!ݷu} ΐiqTl*3Bm6Y=+1d/܀?ƮȪ|Y#.c#|s=^#cm8zBfzl, 6ǛOYrB09hy -ZocҲY9̲Uy-rkn5xFy3հ-l%PGðRA$0*0P|+@åjWp{!G\ }+d0Bv4A&$a't-,U?>z~OF=F$>*)^h]k~%Sǖi3i:-ےijk!k{0XV4h[OO8GiɢCѓ;gcRIR,klnp'^T) lXw7Ϙpf?ݮsC{TNR l(v?/kk7ofwȚU~(V<zIIm )w!H(ǙN78QKu'e-x/+$wGx^{h'Fe* \t~z ]۲A%z,-?1~,X%KJ~1"ޣ 2'VU,֎M41^$ E54^Sraħ 󢛜}Uo2K " Ǭ O祰I>la@3 {JyY,WRs?fBߵso :IXj*+f@H{ӭiFfo \El۩2V*}YKchߚ2^Ct! t2l1#iOx v@+{hPaI@qò5ȗԤ0 +p {klrQtӭ%KǽI4/ hpRkfܣN?κm?rޡ-bl9d':UƸPPdZ'^Dt|:TO Dye?}M!}H>><1xNd/ "<;W|͛!KZf4Q&O1]j@LX'/酃|4w3k{Bn@6\pf؍G"e͙MHSW\{{:5:|h,#1m! wiv:a4ƣHcO9%U jbݜW=;rd츄;g3LËBYz%J4'>Њ+"<䌴aGXrBP15[g}¯k(R7k!i tvlFYҲ ZcU+y Azq IT -s|i$Yj?׺yθMGSN+y\-NrAyo5ּots2ك5<4gn/!``몒7 "ai#v)f|N=@tJӘCsm4}A<5,˯TK$DZV7~vgZj׎.kyY-IRP]& sQRbАDZe֟x]1svi,uL` ڰU_oH) 8zk].5{b#Әe=aj,.I88tJz?x(vx<Az \cO\Q_(?W'* V}K2 :z~2(pR`1y^"=ކ(KbeYqb _lVts,ƻedr+!S 2L܊[~?#:RU9q z;sbsVل:T)dȧu-qWv#If&>;"*8Ma&R2[JW+2Qi\",ߡT\cBG#4>V#e)\~Ҧr̀\gj erLD7>ѓx|7Yq|i[-+';MZݦXW\ƿ0U=d7b\+ʟ35q7kV<=3~A!걀༹PV=yg<:gM‰E, Ec¾Or )& Z 3+Zp?+ );Il.?Eƞݚx$ %mbfh92VVXл/J75iEAASGܭY{rqm{b<1Sبv~cK&ju#ۧ?J5RkchyKϝٷ;}2(T V>922YJI .E.ADz~_M>hv*ڶ%"NG8 K[o3?E*;bU{Z2)2r*J7᙮b4/M WȎ'&'\pLQpIWbɮOZ:A{]lTc~̦<4m%2ت{CLB9-X~rbuk9ݡͧǘSPv*$J{ϔRĺ&JX+.Si}?flX:EqXj_w3΄UwMB["*}͝9_-Z7<"ma޵TcSRЃ'yb$c`ޥl{~Q+WnP#:gߍP'`䊰cg+nʘ=xMpwGBݑP9y$墩%y&h'XEd۾yjxʹxjrBT+G#xG=Y14Ϋ=)m7y&#!Ħ꿵M~2ka}a |x\K,E |qƗM,j,b픔sjptbT,2-qQs$'_7z!Coȴ_K?zZw<GZԘԳOAn}d.PTim-`9̳5,8 6L 's!UC:CZo2$=>*枓/bĎ;>˴i-s{k+:ΣyZ^y x@qbLolPy:1/$Rbl|֟l2eL SzE{oLåS ΟyNy7"r{jniy|ve= ^'yZy§q9:zC827vF Yxklon\Kzs桔(*{b^.Tػ_͆XjMWh?/aߑK[}&)d&I]kq0En+HuWr E9^OgkݼM5Tt6GZuP'* |"5e;3^EΤˊAw lŕcJ5x 8[ǧleB<}&tV7r%@5!6Ch?Lb8o 3` <] s2'n9ݧ-(~X՛EǠD]+؅SLȈ^+qW]h܅5iN(>rVD‡jI(Ɩ Q7p;HzcYݣS8+֊H^,4Fqbf >=Ad`Ks411~;ͱr /V#8TꝽL/(I>l]RLGO8]}pF"ZNDOQ%s!s%ցu[E5ZSV735839ٕ219him $mek}:hL ¬TwNJ3VJa6ɴզ懆n#&#۲Tx)X&eKC^eo;ؒPRv?zC.BMsv!H?1lt!N>t!dvd=I<PL#x V3*U'})W34QbAi13>;)W(Mܙy+36;c+ܝ%xtF#Dn7K1$ 7F|7&_|WcϚ:`TstvL?Tw;rOt ١yh5:"0^|]ɔAܱ'ѽ 1XcBAwhcS^A>Cܯ3jT9f6YMwEl=%_gqGGNfSJ`։48LqVFbFFi+9*d)x"ҁ  #s4F M"P/]=RmMՔ"?,zHjXh:-UAcZ1]  jO[3GS C0w}ܒA!1=TMFso_kkz$ZGфeK*dPbC9iFZ%e-\'rm hX.N%K BYRAlh4ҷܘ"梇lRYzq6svC;[DŽ%MPaS^o tvhJ)<ʪI٥N*phQUF~TO+1!3,R|ecPt[ZO8W}0m'= 5桂kI!/MzD]\8 w5:@U۸=g y(dPj6Ć潭qOgUQ1Zݝ<#Vz %]@e6AQ&@,Jb4q` J;ՈuU:f71y˼r$Ijn Þ5bF'|g3dX(£aaGgA%[m7bȽXSnȲ^/}g(X\_𖮤vhrVPr^CѶ! bh}w]_s"NZh2$͆4"MT9t@ޱ]ki9WocUGݠVU.BO^+;#( # ߆.rۿ{PFzs>(^ɱ vMQ[+{Fsr=B{4zX3&aC1ɲMdG^rg'os !J0o~U$c::2p$(b.}[& /,2r(IIh2$SxX< nLzs^3U9jr˯J{ ^pkk\Cjއ:[MT* o𴭍!5W #G8KXhG?0 U-C*yN6AT4=:;=tod_K9هh1_,\vgbȶ~xR(8G'-7oW7kbBΑ>b A|) >擠ш? ֆ@r ˶4Y_RQd@!`G>byoX"NT .e؈o'}$WyR'%U_,M5뵣43)-]rsEcNYLd#1uPvcG9>-.ˤe1.f7}i|TY k H]r?u΁w):fT.:Z }ǕG.E < A? &>5%W6GxLώ # b]0sd=.5F_'pk왴 * 2iD3O #{ȐpA1NW$〰)Ƶ4hk/Vb'8 [\rx/_7*{?"*b_eh'kCv+A pM|@Y2t8\=Ī!첁OG(%y YTce ~KKנqaK\`p2'0]q". EG^(gR`)n蟙y9*$>*Ho*a <$jG|6;Qο;ac\-#;DUz%kjb]龎7亂jVW-E˘&uﲠCmg{} N@e~IJxY2'Kc+BeӔI{܃x:b9_SX"pk;,Gz$UqzYƙ]5לRx~E!gZ~s6%AmJ2"`xJ7UV\LLeA]_籟HY*wyH0oAZsnq==Eh?w]Hqv ]3ǎdSa^#jCoG(j&-*~' д h|"ǟuyBD&z#vB[ά ztܾ6hhitڨxo<ż 5T J *"&2Y)Bc{ϥ7LN+J$1f0+B joHrIm;Hl7|CtYKKYc;f1.|YTel.#w;!du[# ŋ}O[YiĨ|3(x(z%=nWԪ6'6&Rww,䚘]1?6 '5h$ ӂ| ~3i8 .ZzZb|t1v 6<'Y.m~b&3(,ڕE~0MUsϰ@5;:upq"HZ8m,h0u 1A*KYދ,p8(a@nv;Pr꩐AfZf{/xC`fhx'dT4DN3\o`\E63|H./^eF%[)|: QoݻmI\F*6Eq/N`{9GwپBH7Dy0l+vtrPN4yS}lp(% e8|kJx2>r'%?f$Wb[mp&)g{G%.esqhj"BsP!Q|Sy kL,q-ڕ,lIە!}cq, ot_B0~=>9gz3>?r^?(9/FQK6Rr lCͺQW4a~xH?H@MM6MӐ2uCO3JfR}jZ^$$a_Yr OJӻXq7hQ1zX{z>g=| uiW9WiQ9mg6Y/E;w QnV14 +t WR=wqxv3bIqQN[( xFڈS[LQM5!>KB3[jF+EpΗ {l#-^ >{ohtkjM\#at!=u8K5_I>Ŀ V{b_|ͲXV#Ь"|*Php+y2[7XViTW^:$plt)-~3mr^LX IKm.lͅJΩ aYBr VInj`p}PyUV%ďnD!Zvj98rBrÎ| p"9_2d.\ib}`9 _;EED\X S`\#UW!k:rJ%R1qh_{UF] /Nj+_"W)/uDs}tY iKAFKـJoh&MNrP[P[m;_?KUe)׵= , ML w24\ )yQ:Z#XS 7P0-Ґ8lKZ+~X9;,"Fn0i*:G-8#ܝWdC?pt03FF0FJx;RBtJ.=;%a KƦi0u:x_Bt:=gI)LUk7^NrRwqX?S6mTAM9t7dhZ+ZmSε=6VAk'UKWy _~;}l՗3}ZZ.>\VCR=礲Ƚ9d?,fNEpqqC%vE Dvo\v6T Tp*C&:K2e(:qo mm2@ԣ?VydJeI]tM_ qZ̄'l͓P!]7v!蘪oGjP;6mMu XeC1vcp 5waQdSySf%k͆V;MLwBsZGҁX׮\dvzj" DόxTwll>̯U;g$Wdli#"\4#p^UHTAo0=fme9jU n MX$^!%st'oZ̀kWEq?Iά!HjΑAiV'|ȉ3׫ɏ,),"뷋M%P KC:  `FTp̂,֟G*U/mBq7aEzk9+K婛1aRq!ߥ @'exZ\ D$hͼQߍA n Gϣb3}anfзkdF c \ŤS<"^f]g=/?&~0%^x0/~pP3*! u,ҢHh VyH4DDH)Oa%i=nH}Qm7BYpķ~v |LlPtXx6|&&ZK~Xwdr+!ݱAdzMFlW}_y znZWax=8|_.֛Okm.8D:w"cFƚ"|utc:6V%k_t 3Z܀4m,S>I m;[ Q1tb2Bqag◐X3D* ږpzs)&%A*hR7>@N;M5cŗ岓I+S+ۨK!MU!1F^6 >H=JޮSKw#'׳pzGx\Gi$Z Tm)j8JH)P9ݦ1zX1!v# D`,m^ZrmiKi.mߏGx+7 L{EDZ%ϖ%rrY>cNKaڿ!R鷜6OdΤSg b"#Zg@Ne4;SM $fLwk?t!e(+EIzz1%`wLhɢs:>VX$3G|fQOYCw"ndjl~=[ȴ5G A4-jFsB~~22GHtzXWŠk?<_*_-? O(0:/9cVfAQ)p<̳ݜa2TlѸ߿Ϊh]J V;{S;m/ZV4 $A7歴Xax#7 cg _NO!\nPS%?XIꃽI:avXET״)m,&Lg&7Ny#v CgF-&^bQ[rIMS"ϾuJ#>@#gLT {.A|?&$ISyxXmٚ4X3hA]!Prv r|6v>/A~Y sV BDMpeʜ-lCLd(Y WyU iZť>kv=" m 5) T=i26j%(ThҕA>A<.a^V]BK=Hx7^!AHqkN1jDz:~{6A%Z5de%%1ws/}WI!t/32Ń&G$m)Um *4XEuMή 1[ $m(vÍC]60+Y3~u^~wCSc(2$Ff {3w޳,ctHva]C:wBP"tn [?;"c5 ;dCmCe*[d/B׵il?MgtҳUƣgYiLpm~上/zeoc;#pI I6"gFpOJܾs&s|ng{Tz0\foK,vb<4:b99xasҩ: S6´=-#sy2'?顼rE\X jk)<`==ংf*d5+ 6aazYީjFi8Xx3CZuNE޸~%lzyQ b8!KKt.kj2 b2yjO,R&]k!nEes3]sTkK5pH-55V \Ŵ YͰ 7' T5Z0"lUKŜf&Ct hJG"wGˡ%늮(&+MCs #)F9]tauN;Y%买*_=CJC/VNf'tx3nc:!u"}DQH Τ3,t-}UZL@P˪b.#M|Dnlpq jJzo鳫c]F fkѱQa\%yx+pȓ#]-v'-7ܹGr4BU.;jňrh|_&iZ1Rz>+խ7ZҌ?.`K5YfM@u|UŨwW% "V+|&KtgLI KM,DFN4^2h͆x{ݥw9 P.1b$Ѫ a|E N]B΄f̥7lBsc24WW3o!ӆ8 %hv;څ`[0媜IT\ìBIg e*?MZ*je=[ªz ߶b8rBJO;-a"ؠ[: M\W1! Ңm1XUT+y VzΑ C)v=CcT{\`na3D`4;EXy&J*ZbޅXكs)5Ƌ[XqHME_BL!*,0 :'fbsZ' ]e kxi'[82pGۗ0G^GUx"z+4{׼>U gMjq@_RymfrO1TU+4U ڈ%x-$ ZqdX8>ޔH̀0'mfcm0,趈^]~&39.6SaE/mP]]w`p`Wj?.h( *``aFT buP<n B{6E`V*Eh$*DMF>Nֈ/30H]JRX",$;GMja,0c_y=  ZAGm@7f_rK}R?VUJ/htrNB?b08Gv> ͬ(dd6iҧ P[cB0\dQ6Uc1m&T`u+D#ax x9'h{ +UY􊭇(N؅QGFw׃}0_N歶>RD$|.pcn'kxu ?Gp!p/ǾIE&sSKE47!/sJI<=vkHCcQ]ʑіɅnGD\y+S1>1Cε0@/<ծg `c/j0 $>7Gi_P1Fe~K0 Xi"d.*J#KP:MZʁ iPOmtKHr xu_UDmh0F7z21y{6R9Xh3ٟ[V xy8gTyrtK:$3רD!nGA^Ӆ^ ? rvs240Q Pa/' b0IF ~9! .h~ѓȢci':cڈQZ)At#MCVe$?TP!X-$) 0nv[ @XRW%%V&3|uq"Ft<$S-94~k}W=KfwXW%Rc*3ƛoV.<&W $F](ViGثi=EbxCcLT~7H}m<`x!=О x&ШHݧafn!p ѝ!>M5茣p:I':?Ka슱z>-{;׽q- xu) ;:7"uiXÈUµ-º(χ"y~moh0KJM5*->xݺC1G cKүz=fuG %L~IJ`%[D5`JfۂhQRco we.WJgeC;?9I+jDhP{ K!avWPi--$/E+Vy519gĮ;+L1nfBW:\mkax_l)+yf)m8ŵ9UjӮaNf۟3CxfZtjz!e%>*`ҙҳeiS͹D憸p]toh~ȇUV]l_}R^2  Z{$.ij3\?kƞ"g3z;D^xW+“K{wbՆ+Em$(0QQ?R8 ~w ϷHr/`RF_:-ylSeȃ^{;jgA ~9qF)*?y*wC EiB410[e '1$"%_Drm-#8_u5.(x$\Mha p*')tRLB}h,sh;MH  9fyu'NkXħ^Th95 v*4ˊAY4y: >NA0PZxqe8^|ǦZOMSvFpe qK>e:%k#;Gp@\MiwIHZS-p.^3ֿ6Bه)DA+ImQmx 1BL-xc' \##iK1(`+CiwDT.N0JmCd֯UJ+gX>?bvj-:>,4h2}?i[!5Tti!p],+8 5mlC>Z5Es ;o`WBO;wy!Mcɋ+_9wokQOց۩ 1s[ EڤFM70R8Y wL܀5qDӾg.w֬hGU]z[yzX=bqFCgV`3um3 ;wuSf%ş9o/z9 < n =w菹gʗF5:B},Db{MGupqjҟW8e_ LZ}nі<I&;Jl XGJ`e1 LŇ,2̌1Y8P;~ RzX3Y%©`F"Et6>ڧ vdIF7[iA (# (t(cof 7i?5:w%yBS'{?qm-I[_~M_;\~ Io>Rc}U?ϙT m0sYDJGʖ)̀Z"zZ_CRz,agޏlUON*oJЖށQfrW_}* %LzL\Utޅ~]We ܔ+:'yrVkvx(YrvO:Sߔ;}jJŜ9X3YP~&j!iY ,r[YcXZď9?<7"qCM۞\rUBq W'(#3#Pt3.7VY_2"Oڝtm|O38ocv@H?-( 0ъ疱 rZY`_%hc{YGV~^**2ן0`yӃ< %lW!ZO=E#dI uI7 qLd;I""Sb21/DuS1_蟥0NS0%J6AZ!U9d [|s#SEď"u4៛aK<7Ց-&Q,x.i$ظœ *4nRPlOTb`m8f?aQ\K&NUXR)8#H+`3@/9w]}pĕHȺ>>M ɰ`Gu!Kzk"S |\Z0R߷V%U9 PB]yBT n8'| CV !Qv6$j9D@ݠh\+iT\l+`.%b>bs0b{{d.E["6B]d렝vGAmdʮZb{hw0a~XC ]:A"*pgRp'wBj. xY̞t2Ppgv3d:i=y] mS䮉͐0hl)AkI;?FEʋDoSY͈xe]6z1u-3,-pL\_;ǢjR[E~*1 .:u.<~lgvQa!Kxɑ_4zR!N%$5skĈŕ|ZxqP>0`\6&LLUS׍?L /yk;bko`v/~M=oˣ si-ƜN8\))3iӭUDsO,1u 1wF> \U;Q#yqRynׄ8y q9v]R.1&$%^1aP;0^#s>Ҫ {bF'rbοS ;;h, 0gF|-;ڝ*H5$60|;K#G !ȏ&k1xÍLn1 wG2I+^91g_I M4ߕV?I)GqAvi_xQk. M7v]Eڠ*,FB#CZzsp'̍:fhΥXB .YAת[2QLv}ٱJ/KUw0NJ83!EvQ!wy^1ʋd#Q3|.Rg5`$lGj)&I~zźŒFyғR+3$uhBD)|ӃцdYd3t4~|EiJctI ,#4M=%R#pS.v!MF4B<,Ed _M7s5> \/sX*L54;62'WOLd} V!AڏM1RFȣQyYA[ sN?mC=36$juϥ-TeW^n,H'Ƙ q2 eNT * MDbg\ͪDբ>I1aO() O:?e?%Y'az.*}acD#"ib3L3g[e,&ݱn@$a-5AOywK xGJ+ȬW,Ny* Q L$^Z&w fNAq[dR 0if›(Uڿ-nţ#w;1X:p(/8JFLs7gQa"U&Pg2="33p4=%jF~g P99)cӶMr Xv1 {L XԦ|l+KJnmuS, hY)dXt$8e]!N<&[ÀP)PP~sۀY ^ZSa0.BkTr8+6k2sk{ Xa+ʇ3DZ9 ;@|D5x.C͹?ºeɊ(]mZ DЀԯo3=a Daȧji|j#چ,g9:Bh(l n"pkD,XY ,_dԈǙB*,8% /^?/W~׶gƏV X]Fʦx#(] MٺR3no8O1΂lI07Qb0+d"Q(VkBQcI-]cAAbÀF x;y-/ j6D*Qc#ԽVSW t'kg[6"異qjs#189[_rW(Lc6t.:-IGL,}qU.[ޒ5f.S͢Dy?fF]lbok'c;|m2fSNBUgm46 RQCcdOLD{/^٦ȼN9DzyteA mv3dZF:PkpܧX=tܼwL/NϠM[24wP$1d E?_#f) Ĕ HU6Z2 ^*}p7Z*{vµ"m֐ :S#3;<o}Ǫ٥Օi (tFӦdoGP^\ Ǘݗr"Q'jS\ ÅDcy,0;YX|q/WT@>3 #P  BHuP\j7wQh,͕74輐?_mu`X%ɽ/X:22cQ {DN #CºDsebb<]AJC,}*%"qT'{QDϙr\ ͂{FρF"\C*m󯮓/r6mj"찟 d%9q%IK#`ɔYU,"5dnӮd>▜@8<ɡYTPЌ%ſײ`3 {qr.F:~;~!kKm7aS% V$|gF*<21nzqr4כ\Έ܍1k`7r xho4iONGԚtȦƧaxl}&8ltjKLh~Pa6!C(*ZMͷAgѝNn]p ORmR{4,k!=>Hsڽ`.|z6c L1lKò|JPu\FV&Vb (hGS:?kn*X- N:ܶٳtwjeٍ@uӓmdעc?75Yߚ8*וΊƙv|PQU>p{w<(IB׳\uS.kx+7.N"WBqf@7Q(зl k(r;5S_C>`, 1ΕڋREz0Ԡ fྣ=zҷ]Iұdu;mQ1ػYp Íˎ䛧<+KPz b@Cɿ)e f\wZ%ou"IuKSs)Z%OU.7C8eP} RYflgCe>(˼f<,fm20D-/DRt<՜dȑ6Mc=kHtZ>|#twyߌj;Wk^H"y6((R7 E* d[!vNmO_ȑLzR4f녕™>UnN?!@-@7kyS )cG>g=dαЬ7x|•$CҋiHO%(jRB&k%i2?Hx<@zbi.&N=KrlHS^V{ubp 9>L[bfj"OY2؝afRE|Jm%ɜ[gLfГC[dH UXM ?M_(hm`~Y~BoiY!Ȳ2\M}x:;^Mve+ "\ ֶ5DC}Ѱ^Ttd`.J%6G責>Y0V좈\sɟ;IJo lC>C}A-wZJeG@ +*aQ$AO=ʍ9Xꤛ)} EZu/Rr >T^jUDJ [v+\.+""`j\,Ĥd@yg ΀?>=EPQ 6Mj>N7a𡬜 |ːyBfpTTg4J^o*@ xZ?br1Fn=Eo8kꗺ*\3#m Ƈ14"Aƀ/wmhrrSZ)79@Xu;r-y9韯ZVmjE?Nt%v]xB 7  dr y0 XY+'n}50p"\i|= lH`5$%(3ejnwNLqyd]rK>`8 Drzä/&6]X̰摪cII*&NxQO#P|-vQ;3jjր˦[;ۯ7SXt|WXοj>5)UAYWb횡q<> (5y#CYp.Od倿ԦcBaNYդu9ZN'\lH![軽jVJ@A>+(KbLT< Q M((14G/yT4j^ _"S$xsO(.iNpR$2 KMBEE<1v;2qU#]:Й&N<8 ]5_9jkE!A)alÉ|,7y w0{[M^ V"H2`ceO0m1cJSɢuV>\`muYa/f^WbrQѵGK[mG9iiCAb;6:n6I.) ,__(":_+)'hUzWY $S'52Ӑ+D`g9o02Nٽ<zvʴaJ\ hR> ,g1!AkO2'- jA}}Y*u HA[oV]f?5F3r^WZ8@ϟ>,D 5=!mEa}e۫ybpe}̍ M V^Ծ3;Fk&ҌM9nX˲V] %iI<^i(+(E=x!XBSڎB#1OXOEI$("gw4ʺCawZ8+ᑮvcO^[j1 S!Inxc&p)'t|<\ɝ1ELτ ~ :2"M-} aKB3Jk=Ӆ^)Mu^BDA)Rn~qB*kp(>áv]$^nb3P%Ln5&nCصBǝ8]eyO-MޢFf05{!ǂN Y tH^Nܼ) $FXxRb0BO? {8eYԋ<3" ~Yg 62ɊeVM9,ԻPpۯg3Ӱ lVv"w?R܅Qv53u2um. qf>R)L @? '~X!f6bޤ"o+O*p9jl1=^5|a6N+^$:y@YS/ O.T/_џOXklv.lԢVY`.tfQІJ6Vڎh.0u8p;R~ ZB xȒtMhcv;EM[4KvaE!kԁ-c0FK2x-35#TZYo ;ŃlAfo]QnM=Hl˦1iOQ!'PR"ĸ{13.Heފֱ ?@TN43OΰSŎvLtrZ|Q u ?xgj^e1< ^AyudL&Z|ypKi)|\bk,'׋:.G[u"ֳAb𸤗el gBEeȋXO %!%>G`JG/WITDŽ ]ro #X8ٍ 85N\5rvFY] e`UckH=`B@m {R/bfx{Fϐ~v9э [",*%~+1[bwAB,pw*afv0~*j)Q~]ެ~;/I$m7 qw6tw:LEϱt\\{9c!?|_]<8<}Q^5wo7nuYרJ16F5遞(jO$^;^A욡L[FFH ԬIاh|4琂^zF qZR+Tt$H<)h0db>AF A~ *탺u&OҐkYaυc S*x1ҹUP6t@.5M+ѹi'b&4+ީX_2g? y4f66cgh e ub?\(jIz9v?\- G5rX :8HlhS.)&QSKɝ^i]Ppwa{,,of%.ΚYk!`BcL, m-3j-ߩuFxx r]\2h:ev{Ҁ[E[A&9@OGܑAh3X@)Y ]0j`SFL B1 R~j},LH7V͠`Oh%[Ĺaᧇ 3>VRv|xoy_'1m8pfȥ#պk7E%7q0jFԊ& O`<l'99oVR,TȚ4QMLN&id#XZ7A^nQg@ v· "){|qr8E2WY@BCW9xNjJXHѿ)]G\@χwmGkvQOopŋO"Z<xdf'`=i䊉G]sF,JĤ|M| MݯB7s2ay$%yx ଜe+J\~Ufx5+J#;tW2>fXGC@fBW٭+z&LB ۦlԹsܬwAb\CnXdxB:JZb7ޮO7^쨓]c^|x cyaRKǵGDdyYDQIx„: mf8U v嬹*_Qlrm;{?[y9]jS"UW/z)ФmQ ܐ) |jJ4%\dYԙ v'7_ONT1T,|!eh )u 9yƐ9i t&6킇4Q?9&YH_~-Jb }Q6@)T290Mrg#]̲3&dDDңpR=> wkWUiG53d*zb1X1i\.h`8D(^DXK^r[(1J2N$;kBU2o#Smou:7yFP$Ġ*< bW)Y4#'э&%U`?7A7q~YYČ:fCD(/k'޸k"_ήEGк}n{I츚`iUvʱ {W$`CY!Bb1ސ/QR%Rg)LsμMK ɸ,8H{M3tpGf{l 5CLHBf,U9&1=v Ŧb㒢^3Ce7;jo`lD`>s5zjj!zZCzCCzmߢ| 1ǟf}POaP@[p9ķg;_ IQuW1YR3k?ZJ +Fb%idF\7\= ~%ThٴgjC|_.0-Yq݆Slh Q=>E>gf}H&fQ;ʧRf;DCcH7wó@&1BN8j%.DcU}uF#x3?vyHǦU+ϰV ʌ`dm-tϗ^ #=?66~@lV F.V2,wp .:\ۨH1l+_XU{nmY5^$B?s,ڍCR3&8kçY6e+?{|[gzĬerzZ=fLW@KH}8 u*JǻLiZ4"K b83"/,E.O>m`B~s)#G;fy^t+#'z8R4_>T Cg?/`\1? esW(E# &zP޵Oѹ1 Mzx݈a!d"8 AJ[,-{lX:B#'yА3@ ҩ)];G]MvI@Tι1[s2J>?N^g]Ĵ%L+aVc#X2P--(> UC>=a784Vn S;pVcJSP%}V2ۄ0@Ҷwy0^g:7p)X'dn,a73SxnĢ݌XvQ`:O~̙ժRw I 08$]6UnMTv`W*>݆ٚ^X%(f*!Spu pTRnKJsos"}5H첯05]R m;h[UvٲY޶WGP NyFv { {L`smQ3q7jϱɱ3Ւ?Sßx K}BZ~LC/a^c€B+Jǀ1wY*cmG!9 B DyGOҠKz/+ ]݁v;ǐ.pܟ}O=IܽǻLZ!_ ih=0Qu?v@bg/N15GN.E̻UK\ }ha?F0,~#Rlt15/ݹd?[mPhH{D9+{6 qIv3F:gOA~<WLyʢjjTڭwri)}J< ; O%$pR*#xNht 8k6*첫 )0^ p1KK? EL[CCG}Xaj3?vdb./U7|ۗ5BMus\`y#PS^G2䟥f1 80`fXƚ_` i!qPx̙d=!dcijQf͟yҪ(1(Zc+ @w1;gcq&ji[Us Fd-& QՍ4Gw 3KQQL#^&T4{jۢDOT>> (f.DH o#nGs8&z>Ă`{UHWFmݱDU1U3S~@\5eņ̀fA!a ]JxA3fȍ~px9EK(35Z]SKʛ8 e#To̭YFgkU_L)'}Ή@充H+犐`7)"noġy% 3&/.3&;(͡`{αDzĵqGsw#쎠xSN-+75q9`q` SJQ:͙3Tc%ܒ)9tsr$<=R^"<PWx8 +(+r/xA>_` ɡR81 pQ/d.mysLr }{w'5ڰ?$;fnīt:?5[Q ̐%"<5 -^S?'SѪ< P0R]˲OZUD J*wQ uPpU {S"!֚v#]fRZ30v!mвX0fu@V|8Vt(įPl@f֣QC=3'ܐ쎸<ϋ@TdYy^/E¾A^abxrrπ&UkkXFpQTXxv̏!Kr4LEhg1,^vaB?hyG<&; &'趙a|{-'& ɞy!i>pk+{i{v;f*C.7䯮z+C/VAtzzaa4bx> 2)IwπBF{栔_igAX]'E-}7޿L#WK%hI S uBXNѨ} EbcaIsu;G |"=xk0a.<4 ,`.rפmiJBypOAnUH6//alaFBߑc2P&{P8܆᫪>=~;Rr~@t>N !`CPtkVf?aj*-9KW7ۚH i#F~їQ(rb. xk1j&eQNo,~0^֤SKWѓji)=nT܊Acyw}ɄWT6,un]#3 {/Rgn-C`0er@'$%/[k \aXL'2u]fԷ ESӘϕ5!z#R6k`_ Vv!5 ´Px_.ELuzR/bcT5zΚ6Yu}g<.UpTfZsIԜvLn9|H|\CZS N}bduVGTc:ya_asH7n+w2;^ p V;cgӳsC+` o5@ ;v@=C9&&[2ɂעk;bBs/.)kt)0 ?S-r_P?-q炓},γOY;30=h`>JN+ #Ů8\߃o!!8A`AH@MM?H\jŗkWwbx-[Qy'еdTe5F7oM x A_wldJϞ(9PGP[0⦴]"\KHSݩ;"{@fb$5e4+A7`/9݈|V& }l5DJ1N;yRRn'O ȕv)'C, {/E'k"=L VcDju1&./Ř]Dh}, Ϊf\4mT<JP$(aYEZpZ0 |c@%GPϝWxQ)wBgd Hks̞^۶Hpfu@T>]!VB#k0> "FoԔ86Ig!+Z`L$8I.lA?=Gi}L|ރ1Bo,w9I/A[+T,c9NjRഀ,Z''jA% I(?r/N3SQo^d3>N)!F׆ ^\5mp1 Y#WzVע1 D Iʔc:x*^_7D8NkS~ U`"\ۆ2Cä%W?}ARTavU P04! V* HDeo:g}ߛ /H$kvۻ6 !w34G6AYCU9z섌M2SΛ@MhxUlPmw  zh$cԆSw!6Dm9 4Χ{[ 7K2gʃJ^#F1I$ ,2q-y ?˕2Sn]47w4$Xɶc>D㚜ͿűS9NYzacwJtyϸh_)Y)({4 i8eURޅJu9rv8rLL%ہP'Vւ Hw^qSkA0RZtL\X2%30 `(v0\EhGm\QǥKI` 5On謴z]} tBo>}}ciѤU=51N+ZG%]ov/%q6*b4?K hݔ*JD"m5 FXx,/pt wԳ| Y,<(>z-7Ɣ_ƨ%Brڊ8< 2RЕ-&wOu/5r6W| ΄kBv5%(la*_DWu;L^f v#ݽ^~Cl`ob.1_2m5CdHq*s)i&0j? ZG-VSOa?`mO+?VI/;.|?O_~>ȞTёoQ /V/I GRpWO/keVD[? 1^zS֔ GքRѢXE*gˎ;CUBCm o̘Yij< %Vz]NF 9x/!ty ,ScABXT{Ӵ,TI ?;aQ1OvAHU.P(I*;<iT@r`т\{ɝpqiV`*dCn?䰅oP ݆+h2.OC|*߾pߟ3y|@EQI " fyGo~Cs4 }rRRKukxZ$) i:w6 *N ر;=)L nuB*\Kfb[ f!}{(4'FjҖ,^'2q O mw gх`(d&'ԭ'XbfVKHIGKQ- xɺ}_P8$2yy8e**4"1TE&ًŒG)D]gtaMqW 9{c!P -- n4eZIث/y;nnP{mv8A /iLOk4BZKS!*W*&=ilE }8 +?{麬5ȄcE<\UgcL7~ɿ(DWȵ f?-qq{t®xu Z'&tujBp%) AwH}GO0Y bIjs1RɄ0.9 T߶-D蠷ҹPKLJ (Puݽ;ٶ*e6 tznԜ&XLT#o.Udq-?բ2%`/Gŧe>ť8 iBHfSWȷf=_Z"zk>t-9q Bm& h-:R~Hbe}u^mx ёjaҌTy;k²jʍ$/ӳ !RT>'Exϭ,I6ǒJ(;oW2ٞfSu_j8j `)2N]/ϒahgȷ̱F}I@6#oCs+AS]ؚ(hlMQm w}|&gHO=q)* z2@_A+||:6.5PVKf Uzˇzk*Q^1w轵Ph|2hX‘\@mvˏl-bEsK7-"".J,̆^e߶ԎCs@ y ϦFlDɠ9@.:7$x#4 R#,Lhy[-kK;F>Q瀺n X"E֛imM9%/Y݅Oii&|]q,Xe)+ ?l(D#^<6x(<I5^1>|{8M}yQ'Ldɜ/8·V}j~@ .v|ЗB4o+4Cg?BEKal:mspM).x;fETMYd.CC6y~Xb0A3{h;lp k"m\~Eǽ)JgXpgLӄPuQ"HpH#/?Q C© +ёqC.Q`wDٺ21|ܫR*Ze/ q/ZW(=f}Rtz(V_TY]2ldRUx-_<ϭ7ޅYĖU,4=4Oeeg У5:i8drZ(S05cHXe^WC&@4{I%FsIuҸh?'D`Z\䣌I_fNq+0[“6C.+ 0KiY RrNG_eC w $5Y^;Ҁ k/YqV\˔5@=P{6MT-gjSB"D16uDwW`Ѐ5(J\u5*Xˌ3lP4JX丵ys0}MP0(P,:#PIPN?;yr#J߃[f#Uu6)t P 얗Pp嬟t̒C{$֠\E3=pz>LĻddG~mGND/RJl1Myo}Y٭ҽSw"&ia&S/Fv Xj5("EMI1j' xrU.ԈYinx;ne}ns:)۞ *>G]Zl$t{ ?5_ͅxC ͭ KQ Uai۸ cb9sn# ` |k;R)ioݽ.)TsǾuI*P`JcSe2i7ꞡ3$!om %:Mhqq8W4hNRڑ,tiE,kUS%_fcYPEG'3z1h)׸T0S% [w7?y e;c/dxEԹ}R،-/X;`#]ʠ 26=zdh-Q*Ʃ2]7wjLKgͣZi#uw3lٕQW!><hD.+v=سR-J xl=ODPfJwy޽obBJv#FKIj>𸔱r)Iu5skܬa#l["YuASqJU4(|.IET+2nfc@]wU!^I9G$VRs:#W}4:_Kn%+?ɌFyGtjH[=q 1l/ExM.{yg b롯G)dؑÙz~8*1QHTgew]7ech2p }SC}0Φ CbIôVI z*ka؅Wb/{!mFq]PvJr&7pnhΒP`%[F+˲cMOe˵ys05ϵ aAj͜ Lа? Pu?LKst\kؼr}+o\[pm[RgQ#Nx׳8s(J8dNW0?8| 5_^}n gխkS}g})6-׾JP/ΫbuZku̖%Ǔ$]ٽq7!k1TNWIr9 pwB$7"1S]S y{ϭ2S\dQ&ػyz#RQ!Pg>ƨ W0iߋMbԞ'͓7t9NL::wBc]:L}C,1MjX}5;F&c-8j W$G&:ڎ }ܕrh,DO.d 3+m ʥ.u3UR'8Yrk74]>߯ϭQ@Kq6\4n~k=PnAzԳ! *8uqq1cݽ%Wؖ,7(S} £mփ1`4Ȏ0Y\^ bLiFVCxK@@hHn+Fo]K>m/\O(>d.xCO6XܯUVM#{"k#:[n2SvB͜~K3`V<3ߕJKҝ$[36 V6@ Z9gk:Ȓ Ijz^8sM "5&@%=_1S`a퀘&]^Va[akHG_8˵p/jlu $Pa *gNYet6їL$64<8tHpkmAw\esOs7I3uۻx=8oR'3s$pNfJ:ŠzLGJeS7#- 7R dI`vM?j0`RF1T-Dց?*+.br  pr祲Z=GtU6>YO߷N iല͢&&ytQГ`QM]e6OiV9/) ?C ֲ۾΅I(LnFͥN*)WWZspC0hVK.愃&us;/0nd#fD3'!OSaHf[:V6kPoYMaώ4ybSg@"pɍU ;%'ۛ+ypZ0c* 12:‰4< p$dmkxqTZ.6$$6&J`lJf2TSR\=hVtQn/Dpqst*vaT :T%xy:-.}f30~I\f2LC'6Rq8TKM,x(@ۭ;u~h)Ec707/s. Ɗzť3LʅJ͍eSsFsf.5g'p~*zuP?AzHڼ?Ƣaf^}$0]gbݕ!iQt1p@O:}"~5(b6 AN_y]D vgv0c P*^.] ݴ5L5:&->M5B=Pdӹ)`Z$L/P)ɯ1v5Jufnn6P3Ӏ)go(9tiQ : :!Sm5 G=?E}NɔIn2٠l_# G %lq3nYu\ T ZkUƸ0-AjytryBzhs!oP%gКk..i$ PY\rj)[O'kqAX1=sыet-e^|_6mj\ ƀʼc >6[* hܓ74zVXr.zrop5+[Qs(4Z9=u!cX@E&.#o%a7TG.\{VJl"zҖ\BGCA :Av ]1\M; cI?pl=d k^8+jȉ| 5͠Z}]6 ,4uߑ V+'c|w'RMDGdPrl%_\+i#ꦷ?7늣U=SFp)p3YGx(nj4St7x@iP7EAHb,7 {;>jSߍ\J[oǜ[#݃7z=BY(%خYWv(!Wj9iV(}jS ?ihۂ@2GGs#ƅ xtHeWi kV7aŖV /-GC/qwզ+6$,-m}"W:mq̟˾^AՑF\}HA†lA-ZI$Ԯ%}ﮎ/ vV~G0m۪q[uI=f]S*3xxJGܩzA2Gl ob=2H@Rkvf_w^MjW}tOO/Q9a^_H~Kr'r1\-w"RşNBۨ!Y-0 .V)p(@_?lٽl~0 n>qayqx&`Eׂհ'puL"QuEu7QwK`וϗU WZ! ^"ݩ%BJxG#WcY^!eYi0c<3jZ?m]͈rYB=]m]BPk5D%]L(xU83tw2")usSbòteƪct Y 8XgSCNZAoo@{9am6^j;'YwR@6bCS5Sq3kkCAMG 1טnP ntJ3xVib7*N+6$7 gbPNM쒰2?ܒ [sƪ 8^:fOJ#TTK'{ S< 0.G۪H ;zU +FNۿED\F-Uٱ SQ`[l BAn LGIys0L:c=ut3SdPp]@Axtc>D? i!Eًih]KA:IQܶ-$ 0 LJj.RYEV(v=6z1X7̻MM4J]0Lkn݋a+Y|L#") ^?ʰ@dڡc79#|#=-H6PC0.^uY0u9 =']NwK5̄(0iz. 7n=C}lujڨ%DP޲!L Gܐ̫P13ȡy1B~)H$i4Z ˒f _N+ܣb>w}!ZBjQ'TSc} Z|jδ;JR(B^?c.07F“v(5J!ƣ.e:e5Xt{L_{Is0Dj!HR "fF}X&/&yV쬞|#Pc{^UCW{i(fRiG l|KV@'s3 |36J)5*"`"`\}Q8p<ŷwr &+4&l(,^)U}IpϘjA0rɭ޹<#O.MX+M N w3 j0< `"41G j-Trlڌķ)}Bgv.;Ȗ}+ ؜Uѳ4Fy e7QW2/D1aBEc^*FPNOÂgG f!C=gVh Bjґ$e<FdzRԪ w0CDb,T5{t;-=EY aD.W Jk]Y bϻxMojSB@t?X33ilg6#(`.l5'Ŕƴ(ĜaOZSŖN^צ"˥٩E {#8UϠ*94a3vNIn7Y,sTvfU#Ue#]'& cßN!g+暜3`:!D};/+˺c~ݴbc Œw3S )Ek2I/58FHyyM0ۀyFrl40"= Oц(gSV,o!eS|R8"K!Sֽ3^J^ܒP9Wq -#$X׆]>3Ul>M16'iq⩔q@CeK-B@ Qz/~IʇDD N Hȧn:_-ʖY sxy#cs}/5gƷO0C=y`8IJn!M; OBir aeoH6Vܮ扃UUtuO^/1C+OYmMRQ${ An%l~%(]h]|! ZJnN BkM)43*<ՕLv >`w"8z{ !4MQvџ?@ # s@&,|ѳ哟bCPh #da we;BƐ>ORڲ 1;$ۨIV_0p7YPuoaڡ]ή N V֐iIżtX0 Q.T_ѫolǒ9z;wN{Dؓ#;35Dfc[˅I,iƬ|(9Vwp?:Hp"3^ uJ%p}l,Ώ|F;vQ-ʴ`ˍ- taIZ-ϴAveN>4~lٿA|:`;UNZW4AVRʿ=jkq$0W=$%و<hOr/Y¦,p*C*n͞ol=:w|ܖud6Dm)^qdܦr"3$m ߷ݝzH[m{vB\vRlҞ:9~)F֒s{| ::9C9q#hKL8=(1dr0"٤]n\l -zV7$N'eB_X!^ۆ0`X+/h$/ccɐ-/R6ǘȵN V[=Jz?@~u&/@亊Y^ނ7Kf!Hyzw c_(E:0} 8㦫ϧ6T@ ؾw)T"lyέq4?v,;[$йo0/w@K.N=a' ߯;FkT)CttƞBT5a'cS jx[O!GBDRل>b[r$u(O(. M_ {SB>zCWcEL\͍)SIu!ݿVz 'FJ^ eO8 ɂO:J2?//'š~> aBD!][}gi3` Wy%iI e!EQa"^H9>էL3HL9CiͫQN!iy=DrFQ?bfd#gWX%N٠ܬ7}v\$S/u.[ǐL5@L\#VeGb_+L\)RT: 1<'#ꓭѯK{0Ϡ۞I%?f^˖I6ӗ͋#*QtknNz?2(U7F(~ >Q0&ԟk䞘Q@.W0^Z(BҮ[o:p2<3Àj".(K0;~< )x9)R 2M$D-f,`nͣt^V >VVkwFݛNxe9M3iX/ BB 'XA~Brg+c%pk4!ɲ(He,:RvZm*“FJ񳜷Wsv7Vo$)ؙ+*/$8Ml k:%E#}/_icى9N#}&QeR֪5Ѕ*u5eY5JM6yFQ0D [C(WR70Dn &oa>`Y(:Yu~]B:tP_tzvXH=K iT@jEzV ]mYrCR"{`'Gi3@M< `]%.j-qMGђ܇Z6rfޖZ.#~gy@Z<` O[!gZi!ߊ<_imo*o vژ yvw9D0 rԩ`*A ovI;k{]d{֖^4m4E&u!QlvRg\4##ty2/Lwa˹1}TIdlI;RG?e[Y a#_Vh/|n`גXkBkVt3Q3IX TW]zR-vЎd3, ';BHC"t ,G-O 0 p SAc&lBhobDq7SOބ|ŞR6P@mo%ಽ[+Jypq OZ]y)'̜KuhMqjDqdd\;#u'v LERSTIMT sT({Q19d(%ѯg<`q]w;2\ꢣk96uU*kWZP_DŽdJ9)[Y*O6cTӺeLnhν v9s72ޭDtX|ymrxY?ݎ>آrD4xx@jqj#2J3=AN$Edsd:kcғ'7_rgq$oq^/6>z%.6f4VD;n˄.(N/ MuC Y[HS@K[R}-PUU7Su;>- [oS_X3˖yP>^YGV_['%Rag/\ʍk4<j_EԆb\cvplXSMt5{ I^ q д\ 0tn; }'9Q7LB׿W t%6m$PUK#0%l=2>ٱb:QC~IЊiL i9GuMi$N@GM$)L}ctL"29X[$lj_Lrl;ЏPPr vW8;O3wb MIc3@'@(ͧVu@g$:?t[eA%XPCxYd]wr_31a.!o52nD”|Sz=$ǻi $,:qmu*U 3JAb((F%*fCͬFL6 hAټ+]}eЊh)XظZfM.m󨺊P S,.Q˯Cq A[g"ՉW6@21`6:KyM-#2űl.5q]\+ؚ-R5|8* Qy(ALN1+ VD=R2 ߍ.댇CmRxj2~FVf!܋p'CJʗN;j5z6E<(nOu$4K326.{lhx~,Ko9bj}Flm҂y jJJM4i<'[Dbي,{?mDdFCHғIwS*:Dp fK 4XT~lic5_s>=KvmW'X&Dw(<h45yZ^DdOrk'AabTKl ϙETO5'WUFgS,׃{z!GeƄx-xB!n'b< @#*=&U5՜ȔN&Ev8~{H+7XwAH9ce>ڒU3 /H5(OHc,lv9M~GӜnPҮ_*S°: ؘ;L@PNM[ põgOFbv՜,$yأ>gh *%2p0nt|"Vka7Wvzt-ג TqvLb꾭1/҃0V<W 8{HHzP|[@gO]E!{ةE|fr!/1xrW)IڍMR N53in0sQQ)k4 >h.33Y#L#yZAhs;jvJC v-y-1 O71w^U_F+ G1:L+2Sӊ.S (9z(kvyb oA-at+(eJ}S`@GV1^fl ]R:JNZ {1L+Ô9mlwIT,QV T;.₅:,@ C"m %zŶMc!t4)〵?w]9|*5rVɭh=`sHPG5ؿ, 6Be5i70= |ON cXu%d"æI%(NtM\tQ_4W1C{ɝ<%ӌaS5NWQ_VLgˮVHH R<q!p6/f.A#zf0NCdTmb* كvoufy_6Hc1xUb*eV=F ;,wI#悕5_%X 4BR3S(b"j:XZrqa0^!Pj ;3ۓY~dN{T`shAx m-5?J=76iϺhLA]L?N S}$HB.yniH9#B>oYY5aMK n0Fogڍaܞ y!ש@`%qz6f?cc{26/u tB2 gF1a<`#i՟ΝTeM#p׌4R;,mrh6_[[SEj!mmT> `Ac PPߺL' )IXe,QƇhme\~m:2~je"ߛ&au6'j-&-k 8U26.ߗ'$~ڠ0:+}bseXEt =(cv͂->[aJF'{\)>dezkWJAp$Uó4VMl?%R1Wa ާޱi6ދ 08;gs`Rcl~z$Oϸ8k>LH"x;po;H4O$7!VPd.Sr:B3Jd){ʵZ}1bD"=,݌Pȭs;ZS}8Z~ V$=z?%n>鄒wjhN/ BT 9|{^n{-ܿ>]:NMXS>a vͼy=>됀hDa}6I ¦P-@'nUx IP.qp2 }ǟ!ЍivK>E]ݞ%+)\99 Vb T&87_eyuBWhSBb :6& V%uxDlOoiü\rgO_&;v[7㉉-7'ڲ{JnaPKKߥ 2 s2Jycc J-m_'] t O,BWad '2" ^h~*UvSށ,B-{'HP 6S X}Ү$z#Q y;vJZ Ѧ4vU8. A铄_C$'Go3lח/a0"'Ce2&ì+8W$C༔,gY4x(=R~\:Rȍe6ͪɤ7<Ӓyie"G?b.͓R a.R"a? YZ