selinux-policy-devel-3.13.1-229.el7>t  DH`p[$ƨoxqX8r"cV7Ġtd`!b :O7&Z]Y&#&/uRdci~_Snڃ^vUy[Z'{NT14jP+x4G#5<ܯ<Ҝ|fpP#| rw軆- 9@܋"# r0j-‹+wOՇzb낦ftcA+{$3xݖ՘ԧ( EEB~Nb@G,`6?9XSQƿ*7[- GN-|Q%Ex,؉򏠟_CypשX4]tdjx'/SӬ=\2sPK%s|i"CDSRWuvhm%l "֯YEk,r!U x!F˒H`ziUWјP;UicL'T&29879819a2da705be60520d23d2f5784358d7b10C[$ƨiO3\emPZ ;ҝ3ϟD|OU8 5+ gaŦ?8?ѰtGwҸǎD-yS`\, *ً&NJT63֮7Gâs;WPA*tfCYDž;(L ')?Js#l @E@yV丈E6j2!xLre0}6+{* #'8މ{1hqf;} 1[*ֿ8Lx]g*lL ܃ød<1IEEUe8}XYށ\J_Z8J^g9AپE So >C9 K? Kd & ;lp  PLL !L +L @L ,L xLL$LL <  (H8Px90x:"Rx> deG dpLH yLI LX Y \ 0L] `L^  b d xe }f l t Lu Lv  w !hLx 6L KCselinux-policy-devel3.13.1229.el7SELinux policy develSELinux policy development and man page package[ܣx86-01.bsys.centos.orgoCentOSGPLv2+CentOS BuildSystem System Environment/Basehttp://oss.tresys.com/repos/refpolicy/linuxnoarchselinuxenabled && /usr/bin/sepolgen-ifgen 2>/dev/null exit 0p R^q'"-%$#5-3z+*I[+b$"""/H(7?#3J2*G"&'KH>()O63>)j&0h&H// =/:*8"-%FX n'4$7-#3jMw0>w09!B4%48*K66m3-4('<W -* .&.z.^-2.&3&l!*%Q$$FA":4955K*)-:pP9o/UG6.@)>-(252115<$?R.@C.;E&7e+4 7Fl%4^1a.OH$.>6 7=b,t2615w5O4 ?;5RQ#/@~!$q06(4N6j4 "-&h7%=$6zO,I,g#1/(076E+~47,8JC95F%3 Q%!-S;Q5'-&5%8,+7.aA;HBjHS6,1o"40)/`5Q 9?i6./&95754,!1}'$4.38A-()+CG%0./-4>679,C:p/#0r" J> +w$2; E{*yF`*c/0v>7l)4QQ+01 0)-y8.' 0Y8e>g'<6(:60+(yBG".K')\.k=6@,6_a).I947Gn*I}/2'*q!{2 &&.*.LN(C$#-3U)I*FP1996V9<7 28BF/<260'(#@_-.K:`6&SW.&,9! &3XP0@z;1E31d$)00313|01(12RV'&6^.'0'22D"2D)f2D)f2!(+J-=C7..*h0xI!& ./.'[EE>h0(-&'W/.U;0AG0J,$/b=8Ez2 M)B'(7$6<=677\6S6SS''g37K)&0hN3!Y1I_ /(()4& $p%/BQ58f'$#!r#BZ--I0;;0TBM)H#0& $%./KJ+6J2r.- 4.2-03-@V55.1.5-7.]/7j$S5i6,549q,,X-J*,+=F0="274:..BCs>*A25G?//-18O%0i'2u(-*(})+!+y() +%$\%B=BW#-'8?9.$:04490#"M.^(Fy27.'q)IIK S =s + *U/V("3^w-:q6A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ3[ܣ3[ܣ3[ܣ3[ܣ3[ܣ4[ܣ4[ܣ4[ܣ4[ܣ4[ܣ4[ܣ4[ܣ4[ܣ4[ܣ4[ܣ5[ܣ5[ܣ5[ܣ5[ܣ5[ܣ5[ܣ5[ܣ5[ܣ5[ܣ5[ܣ5[ܣ6[ܣ6[ܣ6[ܣ6[ܣ6[ܣ6[ܣ6[ܣ6[ܣ6[ܣ7[ܣ7[ܣ[ܣ7[ܣ7[ܣ7[ܣ7[ܣ7[ܣ7[ܣ7[ܣ7[ܣ8[ܣ8[ܣ@[ܣ@[ܣ@[ܣ@[ܣ@[ܣ@[ܣA[ܣA[ܣA[ܣA[ܣA[ܣA[ܣA[ܣA[ܣA[ܣA[ܣB[ܣ8[ܣ8[ܣ8[ܣ8[ܣ8[ܣ8[ܣ8[ܣ8[ܣ8[ܣ9[ܣ9[ܣ9[ܣ9[ܣ9[ܣ9[ܣ9[ܣ9[ܣ9[ܣ9[ܣ:[ܣ:[ܣ:[ܣ:[ܣ:[ܣ:[ܣ:[ܣ:[ܣ:[ܣ:[ܣ;[ܣ;[ܣ;[ܣ;[ܣ;[ܣ;[ܣ;[ܣ;[ܣ;[ܣ;[ܣ<[ܣ<[ܣ<[ܣ<[ܣ<[ܣ<[ܣ<[ܣ<[ܣ<[ܣ=[ܣ=[ܣ=[ܣ=[ܣ=[ܣ=[ܣ=[ܣ=[ܣ=[ܣ=[ܣ>[ܣ>[ܣ>[ܣ>[ܣ>[ܣ>[ܣ>[ܣ>[ܣ>[ܣ>[ܣ?[ܣ?[ܣ?[ܣ?[ܣ?[ܣ?[ܣ?[ܣ?[ܣ?[ܣ?[ܣ@[ܣ@[ܣ@[ܣ@[ܣ[ܣB[ܣB[ܣB[ܣB[ܣB[ܣC[ܣC[ܣC[ܣC[ܣC[ܣC[ܣC[ܣC[ܣC[ܣC[ܣD[ܣD[ܣD[ܣD[ܣD[ܣD[ܣD[ܣD[ܣD[ܣE[ܣE[ܣE[ܣE[ܣE[ܣE[ܣE[ܣE[ܣE[ܣE[ܣF[ܣF[ܣB[ܣB[ܣB[ܣB[ܣI[ܣI[ܣI[ܣI[ܣI[ܣI[ܣI[ܣI[ܣJ[ܣJ[ܣJ[ܣJ[ܣJ[ܣJ[ܣJ[ܣJ[ܣJ[ܣK[ܣK[ܣF[ܣF[ܣF[ܣF[ܣF[ܣF[ܣF[ܣF[ܣG[ܣG[ܣG[ܣG[ܣG[ܣG[ܣG[ܣG[ܣG[ܣH[ܣH[ܣH[ܣH[ܣH[ܣH[ܣH[ܣH[ܣH[ܣH[ܣI[ܣI[ܣ[ܣM[ܣM[ܣN[ܣN[ܣN[ܣN[ܣN[ܣN[ܣN[ܣN[ܣO[ܣO[ܣO[ܣO[ܣO[ܣO[ܣO[ܣK[ܣK[ܣK[ܣ[ܣK[ܣK[ܣK[ܣK[ܣL[ܣL[ܣL[ܣL[ܣL[ܣL[ܣL[ܣL[ܣL[ܣL[ܣM[ܣM[ܣM[ܣM[ܣM[ܣM[ܣM[ܣM[ܣQ[ܣQ[ܣQ[ܣQ[ܣO[ܣO[ܣO[ܣP[ܣP[ܣP[ܣP[ܣP[ܣP[ܣP[ܣP[ܣP[ܣP[ܣQ[ܣQ[ܣQ[ܣQ[ܣU[ܣU[ܣU[ܣV[ܣV[ܣV[ܣV[ܣV[ܣV[ܣV[ܣ[ܣV[ܣV[ܣV[ܣW[ܣW[ܣW[ܣW[ܣW[ܣW[ܣW[ܣW[ܣW[ܣW[ܣX[ܣQ[ܣQ[ܣR[ܣR[ܣR[ܣR[ܣR[ܣR[ܣR[ܣR[ܣR[ܣR[ܣS[ܣS[ܣS[ܣS[ܣS[ܣS[ܣS[ܣS[ܣS[ܣS[ܣS[ܣT[ܣT[ܣT[ܣT[ܣT[ܣT[ܣT[ܣT[ܣU[ܣU[ܣU[ܣU[ܣU[ܣU[ܣU[ܣZ[ܣZ[ܣZ[ܣZ[ܣZ[ܣZ[ܣZ[ܣZ[ܣ[[ܣ[[ܣ[[ܣ[[ܣ[[ܣ[[ܣ[[ܣ[[ܣ[[ܣ[[ܣ\[ܣ\[ܣ\[ܣ\[ܣ\[ܣ\[ܣ\[ܣ\[ܣ\[ܣ\[ܣ][ܣ][ܣ][ܣ][ܣ][ܣ][ܣ][ܣ[ܣ][ܣX[ܣX[ܣX[ܣX[ܣX[ܣX[ܣX[ܣX[ܣX[ܣY[ܣY[ܣY[ܣY[ܣY[ܣY[ܣY[ܣY[ܣY[ܣZ[ܣZ[ܣ_[ܣ_[ܣ_[ܣ_[ܣ_[ܣ_[ܣ`[ܣ`[ܣ`[ܣ`[ܣ`[ܣ`[ܣ`[ܣ`[ܣ`[ܣ`[ܣa[ܣa[ܣa[ܣa[ܣa[ܣa[ܣa[ܣa[ܣa[ܣa[ܣb[ܣb[ܣb[ܣb[ܣb[ܣb[ܣb[ܣb[ܣb[ܣc[ܣc[ܣc[ܣc[ܣc[ܣc[ܣc[ܣc[ܣc[ܣc[ܣd[ܣd[ܣd[ܣd[ܣd[ܣd[ܣd[ܣd[ܣd[ܣd[ܣd[ܣe[ܣe[ܣe[ܣe[ܣe[ܣe[ܣe[ܣe[ܣe[ܣf[ܣf[ܣf[ܣf[ܣf[ܣf[ܣf[ܣf[ܣf[ܣf[ܣg[ܣg[ܣg[ܣg[ܣg[ܣg[ܣg[ܣg[ܣg[ܣg[ܣ][ܣ][ܣ^[ܣ^[ܣ^[ܣ^[ܣ^[ܣ^[ܣ^[ܣ^[ܣ^[ܣ^[ܣ^[ܣ_[ܣ_[ܣ_[ܣ_[ܣt[ܣt[ܣu[ܣu[ܣu[ܣu[ܣu[ܣu[ܣu[ܣu[ܣu[ܣu[ܣv[ܣv[ܣv[ܣv[ܣv[ܣv[ܣv[ܣv[ܣv[ܣv[ܣw[ܣw[ܣw[ܣw[ܣw[ܣw[ܣw[ܣw[ܣw[ܣx[ܣx[ܣx[ܣx[ܣx[ܣx[ܣx[ܣx[ܣx[ܣh[ܣh[ܣh[ܣh[ܣh[ܣh[ܣh[ܣh[ܣh[ܣh[ܣi[ܣi[ܣi[ܣi[ܣi[ܣi[ܣi[ܣi[ܣi[ܣi[ܣj[ܣ[ܣj[ܣj[ܣj[ܣj[ܣj[ܣj[ܣj[ܣj[ܣj[ܣj[ܣk[ܣk[ܣk[ܣk[ܣk[ܣk[ܣk[ܣk[ܣk[ܣk[ܣl[ܣl[ܣl[ܣl[ܣl[ܣl[ܣl[ܣl[ܣl[ܣl[ܣm[ܣm[ܣm[ܣm[ܣm[ܣm[ܣm[ܣm[ܣm[ܣm[ܣn[ܣn[ܣn[ܣn[ܣn[ܣn[ܣn[ܣn[ܣn[ܣn[ܣo[ܣo[ܣo[ܣo[ܣo[ܣo[ܣo[ܣo[ܣ[ܣo[ܣo[ܣp[ܣp[ܣp[ܣp[ܣp[ܣp[ܣp[ܣp[ܣ[ܣp[ܣp[ܣq[ܣq[ܣq[ܣq[ܣq[ܣq[ܣq[ܣq[ܣq[ܣq[ܣ[ܣq[ܣr[ܣr[ܣr[ܣr[ܣr[ܣr[ܣr[ܣr[ܣr[ܣr[ܣs[ܣs[ܣs[ܣs[ܣs[ܣs[ܣs[ܣs[ܣs[ܣs[ܣt[ܣt[ܣt[ܣt[ܣt[ܣt[ܣt[ܣ{[ܣ{[ܣ{[ܣ{[ܣ|[ܣ|[ܣ|[ܣ|[ܣ|[ܣ|[ܣ|[ܣ|[ܣ|[ܣ|[ܣ}[ܣ}[ܣ}[ܣ}[ܣ}[ܣ}[ܣ}[ܣ}[ܣ}[ܣ}[ܣ~[ܣ~[ܣ~[ܣx[ܣy[ܣy[ܣy[ܣ[ܣy[ܣy[ܣy[ܣy[ܣy[ܣy[ܣy[ܣy[ܣz[ܣz[ܣz[ܣ[ܣz[ܣz[ܣz[ܣz[ܣz[ܣz[ܣz[ܣ{[ܣ{[ܣ{[ܣ{[ܣ{[ܣ{[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ~[ܣ~[ܣ~[ܣ~[ܣ[ܣ~[ܣ~[ܣ~[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣ[ܣcd065e896d7eb11e238a05b9102359ea370ec75b27785a81935c985899ed2df6846bbdba1149ef9edd39c6f18d37f29e5ed9cb3670521f142ed6d7d2bf9f2b8342d2c3aa4d008aad3243fd00e4723033e27e253289356cdf2cf9ec46135a8327bceb4f36b0f077b7a232a94e214b3b0a5a85152e4d89c193f92ddaba3ede1ad6915c7f0c40a42fcee66915b7919b7fae619955cd17057621da5c0f19f0ee9d7c65c48928f5604bdd11775bf81abaf0b290e2fdf432e32566536267f193c8ebb59ae6e76cc7a5666b1b93ebb2ccb79acdb617da95b341c710a44a57fa17dae2554e42e537c7ed16eb8266f0fd30d9431df7ae9448ceca366380b79a309e4f8cc916a80c6600d621875d1e77969107addccf67caafb898f570f2f3acc0d592d6acf3fbe4b6421c388361ca2548f73beae836eacd46bf701b743aaee22dcc014ccd30fa3d24f35cf1178eb518b3b86697061b3dc1b11446ab5d4cf42a88e182eb36eb63fdc15b61e40edfb0b642312a4ac5055172d1ac368cd355f6226b2ac9b30aed36231f704a8fc43b491b52994ca63f2420e959a7e7b68c16b5949def7be1a03d1459e04beb93eb7ee8027d810066004a48befe6eb1a6363db87f65c8d5689fbc7d877df480ce102a1bfd7692aafd1735af81bcc30a531b08c7c4d0c6e59c607e878e6755349714cd96635168a5891fdc1927dcf41ade440aaf86129294512fdc6c81bff5a32bf2f53acaf23436d8a00b6d0aa719fe4aac12f7207cb0cf1de3cf26828fba61b4997521ada45cc63505ae859eb1ab8b2bd7cff5eda31467b10041e6303483b23e554a5d023b8377ef4cd4ea18264e7ebe83d10edc3af0e4c96b5b0f845ae53539e8b0f0d9144133c40f88197be4087ede536e918538c8d0f11674a789de4efdc5ff1925b79b82862906836ebddaafe1eb76ed2c2ba4755fe170fa5a257cf160d3783b71ed8a95fb5a7321dd5c51b87e10736c82b24900f1f8e55b71bddb79abef8761376ceed7f00f390d53439a43cdecb26cb4a58ef37a9d84b2bfd401494ee4d31e37b03f625b18b0ecd0947c00ebfe86f552e42af0fbdd53a45070c82b528d05c56a2b10f21dda3b5568a87aee2388f1374849a37b6466a607dfa67093af12922ccd5bdf8765a9851c8f89a6aba033f46031a036c6d304822c34e6c0f1f59d06c55cf2c3ce628c0abcae4e0018fe306211674e3050ffdff0f5b3d5c0ed3f0af78b740b86077e97dfb4422a6a690418d8159199c2f2adbbc1a1092bbcd083e0d13a276fa0ed4a00a90f811d5d99c9bb23c82e2613234bcc5b069925559a9803de69b75eabc51cc8a0e25e468d9ec016527cf4f6b3d0b856dc965fb93b67857dbebfb4d7f8ab0f6939ea31183c94d91149023a737b59b9ffa6c8e2fc06ea8a7a72e674173f8dcef90363308fa8751ca52ddec1b50ecfdca0a324cdbdfd4f6920453997f0d6843a2bed7a1494152cc7368b60dbd4446df29e6988597034e735ec2ec9febc9f4570dbf7b7a342dd3aaf490ba496a97f6e4da61846934093bd1d7e5da9fc0f3885d838dc212f38de163f9718b9d6f3af2466cce51d0f9456c0a68dde2eff024c5bd24885e59ca444294d5e51936636dbd68f7f41d7608cf64db98293643c0843379264114fce171744a1c868cf2811793e256b093db59376c908c9e4fad3e00d0cc485d310aa213c722490b589717ad67600840712845583760612651eb1eb4bf356910153ac18d51f8b66780a9d0c0f1304a0c41c1b37f93150dc087c34515b72f27ad0500605e170de215ececa3c3345555fe8e7eea3bd9f1228c90b16c6aa8e8c75675ac4bae01f35df1063f7ab70e2e453bf4531404aaddc92e38b775651d3b08a27020b3b0953c94bb865edbbe014205afe1035bfefb9dfa1dea526cb8b1ad6754b2f161b5185b3957633aec2449d58c9b78a5e20ed829ed8b4e9c656168314b4c7613a0748dae70c37745adfc09e2e4219ad5b59ac87ec91973da7de40eb0d0f756d6ddb8c470f5cfa7b1e1758faf811e2bdb0f88ae6caee22d944e7319050a9f94a11b21c5d60cd3a12d6210f80300a4322a782aac2eba68c677df511924e8d61c02dd6d11888ea876f6eab042507c63cf6c6c99970ba85e5f02effdf44a1029b1ee84586849c79b0bed5437c51ee84d9aa7510c7eecc08e4c2344e129abadd4bedde2819ff543cf7c61d827a1c645928573b8713bdb080fee05950ebcfc43edc478c817b58ca2d4cd981e30c43e5ab592f621560e6fb2092a289af474e6073377b418b6021892c2e360e4bcc0827e44106e4bdc30bd65c0bc172d600997ea5ff4e55a980dd4facfda875c5bc37d78a4e1532a731be8c10257ed9e9744cf786a99fafa055bbf0e88fb342736b6af37d45f5c22d84101af564ac20e1702a03605ea31fe821857266661a3477295b76b89206d1a332c67c1a0f427d3fef73b64f37e78189906bb90090eab9e5c6d42c82c20caedc48708a8b187498cff767ee003edb29c385c28d61680a165867101e254eb0ff1def59d3bf618fce5d0c862d499c8838840606e35514481db6c201b99f3280b48b54cfcb7a046f369aedf0809b495ab26564b6c08021eb05fd69639200c316d5b6e7493b5235a89fd8fb821aa0da1b91ddf4cb2aa54fcdf0f50eb524f10825480ae7e6c82b90bba208fa1af9b4d565d3fd6fcfb6df826d7b5ff247ff943c2b6c488c67bf7d8c26f0d9aaf219d6b8c3a4488c53f9ba44e39f3d4eacd7d3dfcd076eed2bf6cfb48a89b76866c7def61cf3c8731d8967e1726b257025544ae9fe8c369ea929b2381cd458015f83ce5d87458ed4d198ee28e97c5fca3811ce9a3e7d2bfd29a572df29696de906b87b0dc6cb86f3b5a54ef99516a32c4e10ccdded98676eeb37ffe95af6d38244532f45896e3471b58f8469d4866e4eff042a4741d5d6801ca82e11724b92fa6fb13e43ab6d8598664922150ef551aa24262ef616a1c00f96baeccb0e1f86300d30255eff469ee7908dd2cc15f3a7678c6d06631ae8d43f2127f6fb5aafa4288fe3de0b841f7e3035125aae9e2efb2e01f3ce328878a0b18b5aedf82409a1ef4caec53ed81cb03f93c2689ecb025e1745ba5810323b01220f34724b00e406f40b52bd363fbee20535ab47cb80a9a22e8afe67eff6a72d7935487e173b00f17df91bb6e196790ed6123d5d84df4d6678c7178b6b88c4bd9dddfe217a89a2d6a506db3b8f430f9fa51d202f9b669d1bf6144582bbba5d38b22dbf66729eda222a01f3bf09053d5402a92afe4ffd751b074805c71402cdb751fd07bafb14285b6cb42b605c9e90ef51a2ba6b1dabff8627223d6ead5c78a1469e8573ca0d2bb071b3c9b418b389c1865d3e95d5fbe96cbc2806286c20fd7657faf3ae478a31b2d06e9826d7b4b9ab0565195510686eae270cbc0c779a86ed9dd82f30e24fe515069d2be1f5cff425adbfcfbc709f97de62ade00eec1235563f9b18b20bb37a938a96f78a5948b54b52d79f81766611fbe2af5fd5cc6aa0207735954c644e5cbced346b0f44b61f9c14227cdef6b4e5a500cb20e483fec2da8bd106ba6f54d0b5c012c0fd7511bf0fc5c551716683a734e7de5f6c21028d6cb3ad24739dcad4a726c284d2c35dfdbb787679be2935d18635f2a58618a8b4f647f63317d2d13a97edb3302694d51aac07699d7013877929b35ad65d00095463df7379802490bb846b7fd0a916065924e3ce228ba9f65986294f867217ebc1886a997fd36047d540200ab8a4fde7c9bb8d563bf6547b8456bb1e1e6d00b7790fdee17986d3ceb621b14ed87aef6ec65bd6987119ecea4c7fbfdeb0547f80690720bfce435fa500a19bacc7549ce5e80a0f35fbe946246ccce3dd6cd564e0c1dba2b1b003dd66f3d3e24364de0db9bc28a8523aab933c4b1efe2270b3262394f6aeb4d61dafee19f95209efd191709c6070e6c0b386aaf239aa25f0a7b2e3f7aa991a54ef9f49488ddf90f9b8d202d1ccdc72c35f9e516e951531bff4ca347b74067735b269f1e30e10c176634076e62c8794d66256333b2a575d895d27f4cd8c2ff00250791e4837ab87a207a8c47a17b2c239a9f57185ba25f280e5a57cbae67082e0f69f5bb6d5b54ff03b087e9c278df4f41bf8a9bd65ea12fb0ff01438348b2154eb236f9eff3c0503eb130c9a28798b7a86eb0831b6ed682b95e4747ca13842e857f95c123645cbf4b6e9c5afe494f1bf7e1ae5f6f0488a3ffc3348232d47fa8a2d26d9321a34c895ca9415092d146e517d6fb6c6c1944aa36733a98a8752d5488b14ccb4813208b8a7fe495e396d2a78714cca270e8f9c5b792f05303420798a8bbe7c4da40acf92f16c7bd2c33fc1fe7be909b388e80afb64aa317bbc37cd94beea3a78ce037a174f40ccc116263600ab8fa5eb15b180463a46d09281145c05c1e492cab49dec5f07e9ea0a406ce44e404ef9086414317a9d2fc48d304c89e89fa2caa747649315180881de15e1478a01ad816f35c5c9015bade8f00b6a775adba3018bf6bfd35c28d393becb959d9d6a63d42bb84ab4f618ef920e5115506ef8df91a08f70c93050600a24e2a63e681cc9c338f6f3a75ff279f7a6c08eebccff14f1a5b6b9de902f5eeede66f3e86dfa1635fe0fd1b19c8fd3e3ce14bc01f09d28d54a48b04f7e0257ee038826c58b37dc83dd2795ade0f7eecf1f6473bc395eec726e5babec9c77ca39fb12c6867d940b4f8e77da935558a59f3498105a649b7cb0975a2008a7650abbd01aa42136ad70b69b44858d6c08e5ae40b1bcb94c7faa00ef305f3826b35f185110c3f8054720a6afc6cf9150643678c0a962f4d94b86ddd9b658843a4039e1c0aac5c0a8285db228f2bf56ad9df7576014c2575eb72bee11104922f29466fdec3c60368695aae70873f374af612b4e4a8857174cc81c78a77fc34d5e215da6d1b9e9d9caa862ef58600a7ac9909bf0e6dcdb8516d21b8a42fd7dbb43fce68b9121824ad60bff3f6252cb491aa525f2cd327c44a1ddbb47af9ba565f59fca4aebf8634b2e20a22fc27c2d052d8b9214e033bf9f282b26ad76ca9481b71ffbaedd0e5fcffc1e542df47f4dc2ccf8be9f900394a640b852663c6eadd767164defab71bfcc9ad0c8ecde219c33acf470df0cd268caf068e9a2a7c2443266fd8d0ec9d3c68597d19f1300e96bb6a4ae5efeb51bb7640fb46b5b1e969c599f3e56e0f83bd0dbe6f3d5047c968c5421e2756c0d198e55d4f03a1eaac82710ca1c0cbd4538cf6c211d318386213aa339d17dbe429f4e6744c1ec366c393633ff700b57a42f07b1079ce93d777841812cb34b2fc260d7d9e23037aafd45b378163eda06d5e0f000cdb82071261a74e61abfed4871b4b34bcac8fabc559a88f899bf2b9f65536de3f85e6f4d4ec32f3d25240e7de3d5f0edf1e50ad07fc0848951b6c47de495be9f25afe5168505052d3a5b4f2760174f4a559fb17633f906c14aa7ce9317d32bf1ed202e36e367754e3ba0a2fcaed0cb8e047396f9d4d88b5c7c7f5c4d32e2383eaabafd4789b4950145d2efa4f85405c8ac4610da8af68dc2f141cc21542ecffbb9f49cca5973c54d93e9d5dfa1bfd1ebea0f67a50127a7247903344f28636c754bea7f36280aaf191d45039598da92ce031f6b35a64a20f9b2061d54f514259b424e51eaeecd6df55cc94159cebbbaf9fd8a04e98d2d87a778c9572181cbcfe7d2a1fa6aff0e5894b5f3fe5cc6fbdb2a6ff900ccc73ceb58d3fe8b8ad2f8392d86cedd77b3177a61e58e2cb002a59bc6f60794c026f0911136318f8d92929b742bbec5dd02e9736bdbb4b5a73ddc1593b0020f3349746c10ac8bef306e4984a75aec0f82455c1b88f7cfd64b6f25d676f5ee541d010008fb37de69e3b4871c164bca20eae44428fbdd70d64aaf5ccffdb61ebd342e895147f7b80ac5e0946bf8ce3eaeb7a45b081e0c752f6299fe1e871d6465c10181832aebef81d3c98708520a441968f01e686ad5af213d6a53ac2a3facaede4b2e3d9aa7d3231e71378452c0627a5ceef29f8602917e8b0aae0e109f932cbff7ea1f69b4af4486547a4b17086d9a2013d02f0a6e1c0ca572dbd74c1089cd320d1ba1c2c3d4ef007d7702b61282e0c11c2f7572c7246b85b20315a239014fa7a62d0b74ec594df49b9a413723b1983ee42afdfd87d6cb735ca6aff20e12cddcbfd315451497c0051db66987db63f77926d0698920b429990995ff588573cb0d9f8b485d9c754e365fa875ce354f5616fcd62d58ac44c3211c2936b8f49d6b26ba3a02a23d13cc9dbb0fd2bf927cbe5b5c3931253d74d1e67497ea505c46f9aa6b8deb869d813b0e460fdc60908a5cfae2ff9f7155ace8b9f3f4206445f77e2bd3a6ee661b62fe211a754bff3de93493e9d4fb4f9bb98892f4f34fd418abb1e8cab50f7998d12d8465560182d0e8eeb64843952ec46b6104bd95edaa6613d829ff23c7169dc454a8863ed22acdc5fefdc37d83cd97271bd93bdd9dc4c947f27a9590fdaae3af7056433c11d0c4e9dc2f08b932f102805bf6bcfc2dd0e3ce4f3232a78e5554334d41d24402410b84fd946cf2c7be6f4ba61474b859c4e8b79f438011ce9be3cfc829c48b46da72cb6e2fc990a827ff8fecd107f77856e66899a9606ed4dd64c634a1577182c935049c04dfefbbe18271bfd3cf4efbc8218e804f1d4edbdbde8b88ba5a0e1e223d15dbefd756b390825d13af35fdbed371830a46c4a85bd772bd7485b454a14ad65e0711931509d323d3c5703bad083bac63ab3eda34f76af528a0bd466eb71a7e3c0492830dd6662a1026603b3847f1a845da1c53041dcbadbda8caf916a698271cb6418492b1360927f30466a17135d70d9ff586f9e5829358c9b78028c15d8f7ae1007ca8205e9646e1cef9b585cafb42b1bbcf251932a3ddd9c812e84b210c111b38f53661745c77af7f86ca584566478e22d2a2032d18dbef41af6309ab26265233bf6e561dcba0906af32a7f64a551d5113fc92b33fa99a16e790951a27af67bf7781dc94a220dc35e649a156c5ffd7c55ae7bab08bd792da7cdf23b978def5a71c0af5d12d16787956b7710390c67349d49d76f71720b578caa97734c7816a0160b92e65dbe302926751d4a2ca19a138b1a8509842e4fe695e924a6b69333d1c02327bbb80386069f0d279d17a155dbf48d306e12295a4cebbd6af27919c398b06ed94d9e8a3b285d8bc2dffc020038b0cc01704506cd73776e03f60f24c3ae619ef9b6441a4eec3c1f27df426ebdb5b6304e217228fd418cb68cf0b51174a56715b59984e6e2d0589378223ae72d07c4b4fcabf92661c69f08b7731e4e26bf8dd790ddf185527d327e9c2579742afd5ae94365e36e49ec04eeec88d3a3ec1b9bbfd6c819005c42dbdff157923ab7a725989f87b61c37321c9389d647f3c5a843e6d0ea167a7a8f6a79cdac03e10b18b5bb5778d597395eaf791d3c3dd9a1c3a8414bb6d84a2ef0feaea0cc8318dbc4a6ca9435fcb66c367853fa3fc4c05625efd09db7274b8c62dea915b4a24bac4b777f25ffb5e6a3e79c184cae11bd53d5f528f7b9c97282754e15c52d1b3f73814d315f984ffa6218ba3e16b5a946521934232da2ccc340a59d64c119a67de4f35176f6c97cc7fed93ac95ea1a7b7f49ad20791a16730f698ef5907e4a2c028ceeedfc33f8fbb1c64ca7e1303632ff130cf6687cfdc7f4b384e4f862c374013e5ab6f638d2875f3fe5943744bbcfca84f5087ab63317f041e350dd285a71d27b03d78525f4164000246911723efe2aa35f62323ed325053ae7869bc326d4ef3eecd6b9e1403c24bf5e44b6105a0ab59c50ea95db13d1a78b23019883b993cf130dbb22164dab4a8c649a2cdee8890c42acc046051025f14fe586aa236116d2921066f410a140edcd5df100e9091e62a10d35a8581a5cccec188bbccfdb204b9eaf3b8937b12e26b0108f6a3a2dd7a15cc079f3db7cff0330e2e85412e64d4b95a7bb77c66bba8ba85ec0a969168e099b44801c134f1b26101f329413b9e2c94cd4bea16c663026120afad4964749a77ea2a41656776f2023750f12691c3a4fd94c9282e4bb0f19e66e71fddd0aeae086f9c90174ec07568c1543bff431486ff6e7b73c9325b47ef008794c46e59b1809692db83ef397feb57884b6543c670d728b7c72fd9aa9c95eb147c3f4c4b2f91f39eb4d503f9efc48f70a145ca044a6fb89f0b397837450fc1e4433139d4db8d97a12012d2ea57d2cdaf399804c770c25b339f16cbe8463ef247e61e4deac8f5277fd5b17236ed7b74bfb6db8aa97b6c465a98bb2c394443135740d7017e1005c92f3ddd72bbab51af5247c8f6fa90cbb23841d5d2cc184569a4e872ad1dda5b8dae4596c49595911117bb506a72c46a187191e4da2de55ed743dd3faaad5dedb18fffe47f00c8a0ad0e5c2e53b17363bfa2cca3663466c465e9b7410fa747b8703ac60bb96ca7a68d42d704115b9951ee06c8a906d18e972102c7f1d9e9fd49fd3bbd5b5c7804e470a7bcfc9183cdbea1e67daba961f61c0325fd59363e2146a3f306812f2b156a264f7fd96ba230e5806c91dcd951943c46ebea8d2aa5e947f79a993a9023536e4b8bff128bba0248545b4c3a165ed46ef3951cc2a23e7225599ad8535f2837c42bcdb03a047a19a96bc2093ce74d8a9690e7466670a2b543aec31ab20acdb4bd6cabbb38520ba4368afe6f98cfbdfb9f9ff2a2c110a1d98568722fa7a631f7eae4c05e7ced8a2fe2b7774f50dfaa532aac808dfd0dfc51b79a8414e72212c4a545e5666514d0fb62775abc3e0f8595e66f647d520651592a6d10e1df15ac531626091231ed9d7fe0ae66cf9a4ac4485788f83cea1f3f6a883049e9a288d46f08b47c45bf76c5fb0a0219cd27f79417902bc9be2a2e8ddbfc7868505fe43283753ed4210cacd65255ffb5881b5de015dce175ae8de380ceb4f662d5fff049679b28c32a6d9b4b0d2f6e4054a5dd164116b3a30a5c63f70c12481b7786754056e89be0bad6493e36a566d6f0e1a2c9ee1ef548c6928faf146664174151c70c90e05f97c70d2c29d04d6e136b6e91bbd03eab81f77a513f9c823ffaf894fcc7e6b304661393bde16c38808f590899acab69da4ba9081955e6218e557c6682f6eb3c57f210de07c5860116752a4641ce872dbbe0900434883e91622df4a28b32193e1247005e1e29f50625b1be3f83dc00dcd7a95469ec3523e0b27c1455d773555f4339502354e54212b7c8da3ca175b68b8c95320c2a51f3ebac160788911534befffb4210f366563c8f5f8c54100d925676680580cf5ae262898b84139348ed6648487a39bf0ac53c05f081ebd0ecef4a7e96d1711ff2fbbdce37f0831a3d7db7f55e839b26bde6fcf6068287f4b0144984dc0ecc9453d1d20339e294ed46a3e321102bb257554a069483a412403e811686f3d06feb61bd00eb5376fc30f97f7342bd2ece61034f808239f5d767408c4be2115c1a5300d0506dad754040206887b3a08f0dc06da8cd09441e25a99e633dde302d24dd70ab9b6f96ef8599ee8f4ad3875a67648d0a21981b5f5a9ced41e70557efb1c5dc1969b01527bcb84c16675e084bd27f9be40623eda2096794c4b02cc5f2ec2bdd7443bfa4a9a71e44288cc26b4d4b1275dfc04274a32752e40a8217ba7bc09bb61f5ccb2fe1871be04ab574e31f1ace95a2880b2588a4090bc1335b70186385ea2e23378a17cb2ff9565b254c4797a2e7ddf24202513d16efe8dfd86f6ff76781900f1d602d1d054305c130336b0bbf0a9f4e3ab7468fe037fd7ded4df3a44b967de14eccf7aad0f3f90ab8751eba73f36b3608237cbb7020bc8fbc99244f37fcfc8dfad5c0f5f9793eaee604b75e0ddf698fe12f8d851aaeea0aed3502b46bd2279a3084cf512ca635317d84f6679bebf300bb05f7c8594d328b55f161a2934a51276bea596efecbb149e8901bfaf4a7a27ac25896a5a21d6530be133a464316cc7701fa89e517dd7102cf9680878c669d1c967f3fffde5d5a0e0760c72cb3b362cc0e82902b843ad50984bc6f91526db8bfdad172d9478138ef02f5184fb96416fb383d1604cf25f499cea5ea4be1569829205cf6c181db14b4867a0b372255a3ea880e2a5eb81ed561bafe583aa8cc83e58fb19b261099c734135067744161aa50ab282951389901296a551288e486f38d8c662db1184e9d976a03a72e288d031d1be858d038fda0bb6bc43b466e089e0cc8b3cb1b549bcecea44723eec0d1cbd947b9be7d6faa86434c7f3130422b37f33c0cf323e1f0db6308e0bdfa96c6121ee3046359acb3bfe68c84ea3648cf4fd99f91a3e5dd916b7307e8be63b41dfe7d1ac5e0da27143e696c2c90a54217069768111d455c227e95867d237b56ebf2bba985b8a7aa0352d51504ef84c4629a65a07a3a03d5f52d063e4607fdf0a8c73e9221862d675ebdd05117685e0f1976e80dbf421149508d9ab98afa7980ea9d61c53bf53114935fd74ffdca54f497120f7ca52360de73f27bb222141cd493c5d3bfe8c098111186a796bf95daa982c897cc5f0edb902f3f40053b440ad3d4fd8ddc7febb9ac4322f6036c21bfc768e320dfe6f86fad5c0f9e03b64d62c0ce4d0ad95f9d2d896f159db2107bd159d897e299d82f54ecb73cfc17ed003a014e167a29170b34dc1f7d2dee7feec038b6db7aef552ee530568c24fc03fc0a6c5a6316d66331eb696391106b2807bd46d92c7831a4f5be940d178e0c1367c7990932d9d299504f4324bb7d9ca1763bb5d41a1acac371bb0e4da33baa57125756d31fc9118b7df581fcac23614cf1a5b48fe6d61a29b06d1a16494a1578c2a1a2856793fe7cdc788c717211f375d6158cdaa80a8e3838e1394a991f36b1ae94f1b87f93a0d813cde62544cef427a8b95c504e0a4c0866eff0a8757dfecc3af62cdb1c7d9c4943bd16d8661545429460b32918f79fd4e67d8664e2e1831ffc85289520e6fd535a4e9088e67e1bbca869e096f23f60cdb83fcbff21c986533fd6bcb9e8716b62bc5e4a72de987751dc8b521ec6df5c12660e9bd79dcfc661ab2f34e31818756b9223d92a904ae9458927d6ab067d5abc0ff19b1271d7d9afd5d8fffb48bde82d94b1f7b3406bc25c0fb79d1e2c7e05689ab518e861f026420f25a3f28e902aeb4fae7762b5f00eb7e1a0096daa320af3bfd3fc2c5a85687326e1a68b59f1c75b6416ab1cdc266368bdd45397fcb97e6668c6e6da0e957cfa7ff7f98c1ec38c7ddc2837bd0ad52c6b0e38186b89f995ce44c6cb5601e99ac17865dbd42ad2da696db5ad82daf95dd6f40cb6d5763d435650541b60031bcd5612462eea3bbc81cc8715b3511f7dba841f93acda33cb844300675ab7b43bd7e6d44f105dc10deff6d1073f282b5fef07ef16255029baa1f5b2d3279f010ea11082bca767c16890cec823d833a26504bbfa1f420e6e9e518e37cdc4563ae62321f2135178d0352a8ae55deedb8436a5b0d834ecddd19344c2abd9a32c85794e5120c2399d392f80842ebb6e31d9c89b6cc7683f2ef43de153758cb323efad371209de72ba2428f2c10b1e7ba846319d2484a51e0e812d733a579e395e43d84ef21ae7bc33405592fe5979c9d679b8f804ba8981aff44e44bac4d6a198adf92a9f087cae0b8e7104eae0121869e4713308205db79724ba9a638ea4de48e974932f2078dd77fcb885739c1a1cd82c07c31ab342219440727394a0d4f4841c27014967108c70f877204005e798d9a7de1512c9c69f4513f9d36288af9daca5cca6a409ba044cd2b2e9a0ad904f588feea7c635299b2c340b440b4e8ab71fc332da9b8cccc2a036faf31cfce1c51004c08bc59e965ec70ce1834ab3acf134cda3af3e60fc18f956e0ef86539ea9feeb72d4c86c673732dc339dafc0eac55af1c2482dcad76b3e4edeb892654d30cd8bb5920c7a58110e93631beb40da7139d434ee84f0aaa0aebd14d1ddc40ae4f6fea86defa05d274c9213ce14902a7ed17ff3dece4ca93bb1557500840b765fc86dfad1b3c1b33a9367b8bfef621fdedbd2fea85ff03508776a58c28b5a027b05a4b29f5a71cb454459daf2105b4204133c01ff4e7d6d37b722c66cbe73dcdba98ed01f5742311588baed094dbfff24b450d68637207936ff68a04555e94fc46c91422d60abd6b35cbce6dc9cf1262678c1751159d4b435a92cb35ee13d4842c642ff01b10b5006e582436e6018b8d3de56df28fd0e2ab21d4c3d9ffd746bf9ec38c43e752117e1549aed2dbe61d306b901855510f28a8be5382cc27cc6eb3a1027358d189e32044276c6e6c36b2c29e2504f4461af8284f718305848347b741704c7328998a76198300ec3efaa920f5a4fb27a0c068b5317d766f490377ec3b3a2cf1563ddd4faa232c5fc7dc8a4e998166a51a9a517367ce1185124405cbaaf1cc47f589b0287a2a9bcadef6493b1beb44df0806ec7ca09e5e2bc2663495f8d63fd09a5451aa8fc831e7ca0adfe582079d2a5a886113c09435efdab47fa27a0e73248a54f21e7686021cf15e7fe1788f774d8a3a9959a0b6d8ada2c10ce9a0c33e7e14646c55fa0aa1ab9895f21082f87b2b0f32bf946152e0616a6fb91f5faed7d337eb9547979d4c631f5b05ba51f3e1f94db5652c51b7aafc9d3264ff17705990d4b0af5c1e68de73ff01955a38b913adb6003fb575a406f63a85cc3308956a7b0ea0211824f8b6802bea4be17dd9084baab228f247d1e57b8ae9b52c97ff08ddbb7bca67cff7f60c90d7d60df9448e0cc071440521882536d3a61070591cf0b9c4eb6b5c0cc69259bbd0af51696ce356aa0c139874fa09f68e553743f6047cd215884cd0951c379f845e16b476dc082fb60dc828a0008190432138c41aedc4c627a5889a957b513d1922b42ab6d6423b8cd38e04e74f90a2b7d170127b174c225964698da1a7beb5459135d3708c3d355b4f82dc09ce33e2b7820173eba99da7c0a15dc8b372055d712f618cc77ec78a3a0fbe52fa04419fa60644d12ae1fe05d30600f9db447243fe5291532273fdab93cee3b9564900489750de010668dcdac0df57c7618eee918ff508e348eb71aa1211eb047ebc47bba9f14194c17aefecc2cbe17adf17fe71afd0a66261f6324725774c7207af62dc34b9cc88a70a8054b9faa1c4b6d21fd133ea2d668c6183d02c5fb87a805c2ea6824cc6a18f5975cc6c57f51ab17e031a4d9c87fba55f33ed2505c595743e8e578a6424d198bd7780c6b8335d976ee84283d3fbcf5fa9ac09b5b3dd475705aade6b4a06169c36361667dd369646339ba0883286cb76637273af49fc2d69e8dd222f00f5e13ef6c4b7b283aec59982f18a4f502a03320cf6af5244dd3e3dc5e9639f920b38d896e3c0136562c093b38c9963f672b0c66500d9fbf745ffbf960f06a520b0d54b0154992cf223d2e8e1898b3a8d568fd28fb6c8b3e3e8fb7b0ae6697743bd3c5c80a77efd22eed2c52f0a832dd4b15a37c1ccdc4268d7438e95d717b454f3e10c9d2e16549efaadbe925d2ad84c3e3191b45ca897d4994e4703f98996c740dca7d96a434e177b6002ceb4d790c02481cb5283014ab18b2dc9957af921ae2bcb46ae277134aebed250cdcc45165df1e3d6abda3c3fb7862779384d2d91702d86360d1273133dfe358b5041e68501eed374c93ea14cab8d6e01fc960198ec64c2763e79eb46a4822ab9761f2601d54982be5cbcd1d5b094cce888ccc5c8ecfcf5cdcfb4419d648eedbe7036a7131f089d6aa8ec31891f428025d1066cbcf3776a863e9b1b256cfa593f972cd2e301b7774a6fe61bbff3a4c2f6151175c740ae77f5d337f6596922f0c933bde6e35acbcd072511d0528901bd0dd6e640e07ca75630fc2f58d003a2c41ad47866d17af1205ddb5e7d89a00a41f08d9fdfa3d6d88feff8363dade8335eb321bb5b15c1960652edef1c60ae50f1b7ea7c660062c23791a2a54734a32aed74efcf5f2c7415f4b5f452205f853b7ffa110865e4e5b4c852338c82b5d05dca52b2f29045eac6966a274cd92bc1866c7818dfd7588b084501cba66cba192e072ea875e7eba44ed64f2ad3943bdd7143378cbf7d42afb12f56aebef9cd37c27976257eaa803e7fa21e97ab7c3b41b3bbfac29a38ca541746e542ba4a7be4af4175fccb1d3aab7ad7f54d80998551d10c553a80fe200415595e793e6d6b686d5dbe1506769b425aa1e0d16d0a73edb1a0645d900df4bf11738bdd9f6b06d101ed1b48fb818cd5d7243a2118e29c214d6c23297ae792ae0b335f7ac5e67ec98d5691b839911bb648cff80b8dfe930f6bfc6df27bafd14af914ba4471da5def7b91216a738f3c7b675304d33eda470c21824f5a4a3b3bf9dbcf5c5da5598d7ec77f7cb800b387213efe6a78643d18dc054b6e8261f9c14dc02be1227054ceebb73979fe7ed3436fc83a55e8211c3b15bdc3b2749e562def68eae42613171a1ef302bd9da3139ce1cd043515db2fec8dc635bb035f380751c578954487eba60787e8a7b5efb52afd67fec6f889bb775b844b8a0b5e69acc9d074e33016a756c9c0f5aad6c7b72edca0782b08982b8c0c0c6c009953a1e50fd0ab01fa4e2f809ce791684b64f5217f57ce239090dd218b82828b6d50a990d4b103d63117b0d6a8bf03b53728645090bef1f8b29076a11d0a2f9c5f9a0e10de23e65cd11fb48bb35a2e91950dc2a5b4b8a863d033d769cd96f6fb9707b8e746825dc6afdd36024dd0166b8287ec44b1d8c7c27eeb5c98a1f72a7a05e2bf08e01b6054d681b27573a697af495ffe8427895f3efb20beeac196819b4670b9907564dfc39ef5c77e5db2c8f23f88eeccbc0ac1fbf3579fe1d261053a6774f2bc5c942568c897aedbe0f4ebcf55ef8fc03bdce1aa932555b23f88abf167503598ac8fcb45d7bcca06bc942bd40be6590def73184389aab5c485f277cc4aa88481d842c8fc03ca0af4b48e1d8c2095925726965d186205a7d1b01f137a2e6382e6d534eda652d279ef8146310c4dba8750845ae4d3ba0d0d778093583682f8619005a3416bbcde5f5673fb8556f94b19494a3454e5d31f99ca73500dccbff3bb215a949a4cfa6bd86f820eb26a855632d62919495cf98557317f8dd3a086bc4975dc7e6dd339344a373a43dd2c0f2e63d48344f800bedbfbcf8d43fc228253dad2cfb758780b505b57bab4fb4462f33b00789bc61e429073230b6015dab6496a623174e3d99f45b32a54a800c7612cdfc708dcb626547b919124033b13477b0e297b1e3e9e8f2720f35755dac20529f00c6a4bc0e5e276e54b637fd44e511f54d939f795c53d19c4e6bdaf15d74a7183fab72812ff5b363a79ac36e0615ae2c1daccf27e3161d8fa289656b24a23271f193815f9e2c73a5969ea42e242478ecfbd14ddb6e532e6d9b818a71c5e20be56075cb04a579e9add6b4b5e036a78d1e1f6b99fd84e1bc830c1374055f6d05123718f0b108198561c2816ff7d39bbd826b2c94e7e63f1cf5396c483c36a2558b17026646ab2465715ba7b358f86beb6ebec9ff2a657910ebf3afbdbf6854a69dff58785546f274ae5929d21d83e7da5e0f16bcc20f7e51b27542223c7155d64468538291535e7ee029ed56a5359a02c64d03061bc8ae204e7700647285bc4cc2ac6f23e9494497df26571fba19a045939f7626979d7ed2eedb025b0fe2e73abb10435d695fdb5ee0021d4bfcb98d86d74036ab20600e633c76eea65d1c9e1be9428ac159a77398f146f3f9f2a5a2f5675088c83d1545d32fedf062d287fffaebf1f6b9e8a84539ad9767ddc566398f235efabccbe7d1ae181b127acb771de2214382c6b53068575a53e77352896e7484b2084fbdb312d0490d774224149250dd45af95c2803305b4ba7cd15821e078a9e99b6bd0578d7c4b8d2f894d8fbcd5ebaf4c47327276478e1314afa8944c85fd98bda964f39465b1eddc42e836a530f57f904cc2ad8239dd996161ef5cd4da752425a08481991e41761c679795cba32fa3031a02b2c7891d671f6390b370cb49bd6b0784baaa62d0b46ff3018f646d71cc72e9d4cb1b869c52c9ea02308d3d8e6fd352b8641c0c1937bb1aba08da5afa240ba020d20252cfe0b9acc9a423946c039f79d4a7840ec96955186e8526bc85826c2e4ecf9ea8638238561ec1f66956240623d656da25343842fe21ed6624149774058808d82f59ad320b087e2015a1130f33786b7014c97800684004ce31a6f0c3bd598d94a1046a033faea405ddc1b8590e0deaa0eda849d32ed2dc0f7091b45f1f2e5c8d7d526915069229d52b53453d90f0a2aba1dfe62f08da7b119cb84d8f026d20dd1cd21e90368a496835dd5ddd5a2b2c243e2a549c1a5387bfdc980caef7c7563dc05144794211a11fecde7b52981a1e7ad1a2f7f0d06af5942166490c3d946265f2e7838ccb8b0c804593ebb927bbf633870dcd31af15a49905f3bdc2f68aa12478de968668880d574a325419ddfb737b97913c996e1711e837084c937ff4cb8da87b92b5aa4b9c85df8af1ac5ca6a71e05a0591f99fc3a196471a239aaca9c9b69349fee3cc3b4b60ce0f47a533020871e525641153e72ba0942f361e763f8d5e40b5144b0ccec1fb33f2dd5dd93c8cf334c86fcf6d24e69ee51ad26c336dd700e6e981f46e598bcfece414648fae70c47294df6480ef95e7674e330e1f58e8a38db495b1ac5303daaf29ce0786b96f6c3eda717b134148fa2622830b6bbfe19e7f09bcac0170b92c6c5b983981b77e198db095b9e854f6a79065d021cf9d7c222e4b029f448f0c49f5df9d95be384a2331ad7d45dece4e329ff7273e921ef986b15b39c3d5882d9063604803ed2a9573475face5ed4015e416938699be095f6eed4ec208edad17fb3c7d513025e6caff92f8369800857faecdebbe3800f3fe645e61bcfdaf3760df020a6828a4194926bb8af9606e24a1dd5d97319fc3ecb8354f67d96d51011e7db1c3cb6c8a7ab3d41eb39add48e46e40c2220ac7e001b52a7db32323d088be6307c52814b033f0d8548b562cacbd737bdb76e5c1914678f593280ddddfdf11e981f814595ec2ab64f6aff1a554edf953151fa64dcd4fecf426d958d8eca2b0ad0511534dd86efc37d3cf866e78e784f2927aa3e59346ed4f7de713a8dc448b92ebde5f8be94b3456f5182f57eecf4b8cd654d1548136e867757ad31cb4c96fed57181640ae7a1beed48fde0b053c5bf95679df6f937269d2001f4f6cb6e21b5d394a28b36bf9d2a8bf3597a13c6adc8880ac37d27ac88c4d5f257ceaaafa56e86d8e52ea14c6b6d2cf0538558d9949a4b5b8fb3ead0e6f01fb66e9ce80abb6ae5588bf9ad52353e60053ae6a1de5c8eab1b551cfd8c2af67d371cd9b67b7b1a4aff28d407ba7bbbe3c32ab8427d89b32b602a2d97bdbcec4c159435e4e88eb71bd48f9e7329be13e1715c359dc4f08de27b62e44f35c69535742c6b0c560f20ca02351f115ca688ea540be107211f32017de0712782f3679c618eef6f39663529108eff73ad06d5f3aa5b5fbd5781c827387257e6d051f6d6de1b3ed5c2a911b3c4be74e1e10e0dba682aee9639ea6515ff8e36b33bdbeee64302eeb358b8abf0183f3fe6fa1170760537b03f4349c53b9857e101e9433e89b2fe8a57b9e45c9402763f96744add09b8abef37cdeacd31ddb247627f8443065e2782cbe232cb93447a9ad88b4e673f76c1d9c562e199f6249e49d85d2daec32420a258f8b2d71c005f5fab54999a0930c8fe9c95afd66192cc83fcf690f307455bd8f8470db77499840cc4507a415f3e2263949a453f4c571745d9047f1d10e7a082ecf85ac896e149a9b3f2d07a13778d1f7dd4d76434c804fe7856903023e8bd14a836c5dbddbcd1a9ab6520e166aca838cbf4335600231f559d63a205262ea6478bd158eb310c05d6763f4a6a4a75436f8d296199216044ef0e2d260fb7a274494f01201ec951e05d5537eeb5c0beb38e70ba2ab4aab8a053b24e56d059c8cd1f417818ea32233db70c12de7099ec4b3efe7d0718e8e0e417a8014e95b0d08f07e98408bd3373d9ed327497891ceb853202a8c637c5bd373f80b9cc0f3cec811ae80e72f23e3e9caf99b178f5c1336712a43dc37d92830b694c8c1920b4d68fc25ea896893138c4b499202e2028a80ea88501bfa2c6eca8bb55bbe11cce1d16b8d3cb4c75e844080ed3447cd98d027c566111fa6a720e9258b0731bf4805664102fa1958a493986f73bc948a496e05c5c5a86bac1510139d5ab0eb07fea779e1a0b6f816685cf170f970418c534a6fe7ccdeadb6ab8fae1b500d34b17913547fdb5187916154248e8c6541e59afaa0fba43bf7b763b9eb2ac1c1d84e5f8636d5cc8134ef65c59a34bcaedbc241467ed267d0f69606466d24ef01c430c3bcfedc56bce4e5d3ddb3653b5f608d736ed70212781ae7a1181bc8f137c1fbb2cc2d09738dbee1ad635d17310dcc342d07e8fb7e9baaeca656e11bd65b8c2f15381acff30b7fe5b705af3fbbade9bdb50fd3fbb4c184e8c9bb12097221ffdfbf5758cddd8cdffd0ce8a1b01c93634058169c312de5bcfd9cce8aae94f70e73e81db9d4b4e5b4bf9aa90c5669fbf8730671c21b28e2f60393d7dadfd0a5836f559664ea65c3e2799a2aee248db0deb4015d897a515431782cea7337ba6e101e228e241bf86a69826d8a9c9e3220cb493fd287768a390806a80f14edbcc2e7a77b7241b14141f2a2edf4773424901ba77645ef08eaffe3ab2ace8eb9c126a3304051167fca1cc5084925f7f9e6fba42ba900f67224d7d1583458f53f581b74fd06c4e2c911b795b48c9c6d430ba882c11dc24e7bfefe28fd3cf9bad53ad95890b5baa69407ee94267132a16ba1ee25ca47cf1a54717f08b51b5cd42c5e0b9947f498091d7272c1a1e8c10c5a7d7c872fa5217c16f1dfa860c3b1d998d48f14370f7ec14b286cbc209e93e0fe5775e5c2f09c0e69794b5ee89ca4b0a089edc9212132b12ddb6d2e21e14c2ed626a67ed483a818fc9a5667420e95f80b390b9708c03529ebdd0bef2883772611795cf68920817cea83307f64d978e3800645732941179dd7cef365c48636391ca73618a98f95f43274e31189bd10dd742e1675f2fb5ea3383b7ffd7d3c88d40e93dc009ec5303a93ae670866857b8eb1b32f06fe3d7ebb96c327a5bae8d60ea3f831333ed3e30c9828d4a2342004ff42cfb2bba9748a6883c66bb1dbb7db6e6cbb2e30cbbd8719cbfbca115c5d4ee609899725a241309412261e7837236b8b077396a841903e3d47be705265f22f06a41bf0b23bf9ac33e05535750860b25b74595b78db123b8436014dbcb89815b986fc636fa6194c5c17131637d8164b8d3ee56aaed297b63da098d7778c87d7ddbe99d0a70b1f314a3ad78110f27a621e23d1ec3e0a95860792605ae3c00c77192bcff3f8131c070629e569abc6af3e25ee6734c1ed599bf37b926ad4db202cacd026546d64baabf5bb53491252f9ebc61d73386cde2f7fc44fc058b33b1d576f4c34be565f32da5068c4adad3fa29a74f9895b0efc67cc5f03ca0b301af42848643c146f427ee16621648ca131e9805478454ba78d2ac59dce315cb49cf407a04724ad9f48b6ddd2278f2910797a1ca7c33db00b90f13662eb067f45cd32e6acff72ab987b186840922f645810c043cb17e5a54e04c8d0ec3b6d158cdb9502d171acf5f19a578113edb35bdf385a24707185a6f9428c01a1112ce3a75f2b662be62a7db97a4754bf50d2391a444625b713f1e841f9071393d882675ef124555b1840e370a1f7d6a7ba5e53417d13eec5de9e74da2ef53ba049760f73eaa0335ae7ea4bdd2551e56b6b6a7afe703335c5afd2fe5d0fdf91420baef0ee9581661f158f34abfb05facb7d82cc96891f1bfc5bd3ce0ab5aa2321418b9450fe88c3e12c93caefadbb4f2d8d40ce9ab899829e6142eff892804b3d21c678d5589a768b6d68e03bd45b4e4a8c427f33065787a1e1d2c3f367c851860d5743cea38b0ed0fff2cab6f0f1738d1b03374101cb54d1e91cbc9dfc4c7864974c6b79e4cf80fd74b059e3ca346f35158a820ddbb9f50fbe54ce5c34a2935562ea03a99d1ee674bf1f65b0ca85a2cb8d874081551be6f9c5649f010d659ec6da24b67ebf2ed83d75f9d2ccfee9ad67f32e7b196e43115ed7cb81c58571289fedfe753e223ed6b5ef0d4300eba2851596d60593205f5a88e2ad603bcee4b49dff8f21042ff8c96b25fac2c88fd5c79583503a09c34376490bbfb26509105e243765910a1870e726f8d994cf1da671d9bad3cbe8af43738a1917e98c700a2916ce395bb9653a6c2ac5313f09d83f868126f0981c7b1734af8bb3106c4a08d5c492ee999c8f6e0108d02982951f130caf508af61f5b55f98bca51e96119cb2561ee4c1525f63adba0b19b24f6d290ec7652f8e9da3c122d61c7433443f25bd6fcb841c1c9e6cd0ff2e24a377d71eae2623180ea9b4cbd73c376b9d593ff7c4b21a4292e83bf8aed8af45a37b896471b5f87e57ad5a4cb663e5d0a181976b413df1063563486202da11d6a433f72a6fd9a49c49d35d245927b73055fe8119850a917f98322cba49ac6cf1068a7d73f18dd1bf813d6192931fb2dd684df9d2440898ae02e3be1fed1dc883447206f3cf78cbe5cd009fa75cc95a6ce931f8e9d76d450d08c6a40d9088ec2fa93209d31bb62394997bcc31dce1db6fc770d0b49b2ea57bcb67054df6aeffef048bb3eeba69a18065c6fb7c7359e3cbba78ae82ceada88ccb7968d2ce506c130347c6e0f2a8b4439c6d5bf84fc57e1996e03358f6bac8ff19a093192ea2fd87d5b8fda90255266a187d6ac4acb6f6c5fa6a1ecd06ab40b1ce02e5b24bf2ca0aa80e7de3cf32ab336e71f8cbfc4543286a807a35f53d47e6bddd2128f46c69ff64da1300eb7310a824eb5f0cc9a1f67d5142240aa8f0e832967b1a267685b93207161d6d62eb5bb54cc5ee6ac52f6652787c2fc51623d37bc24872279b853fe0f2ae594177a12e85d13888f0bbd93e548626f75fd0d6cb435d2975c98ce698f13ca99408b24a3f142347139eb12af7178d0fed25afbbac26ed280e821d224d60c03d2613281d3f77b00e6e2cb1f54a51513438f724745795100d7234dd8326c05adc970e0ee5ed197e9b09321d0a58a8804e236898f73072ed657973d550d4ebcbc15fa61bcda47ef743a6a707b2806f08d5f6f277f5802537d79ebd70e2972b27e56efa87df7df1ae4b9ad19dc0b6f7a7a29ec856ca8bee902600abedf17970ede9f9ef318cf2ae1c8aa5f2d003871a2022de3f109f90f2917425de718c0f8449a2a497f95cf75a3edeb3b430f165b451c6df2707ca744176f8835b8265185bddff559b3bbc3526db1c1abdac7198725ffa70b1b39d57d976b002ff14281a84d27d318e59ff901452383a7cd02d4cb5e0e1e7b86a496592ab441eb3807a6bb732c38c8cd0aedf246c8267f520ee9b22c41c928659b782755e8336f34e0a3a58bbcd630f84daaf2ea411599b24b8cc5890d5e0ac50242f455e2bf05e0e3354819d38c14aa67af1dc19b7011b1ea068c05368719f5356c2dac644a2999fdfb4a33ccdabdfa6a724c71d9d019e4fa56492e5730deef886fefe3f56a71bc261dfa51b0c6d2539431b84ba8be09da83e64b0a79541cbcf603f6e97c2553409b688201504e41ecf336205b5eb3ea9583d8a7b95ffb111681636135320af6dcef32bb6c32106282ee2681308f76eb3c8064c9b082c356055d301347839207a1ab4674b003288aec662e0fa262a3bab606655af6771f710204c049b85fee33d6670c7734d9a90790c84b3e3f18707b7b0308a48540c0c109d8bba89635f1cd6026e669523ad77456c96efba5400360fc227821bf0393c1b0ba99f7ca501f7204178087bb958449a6d3afcfd4aca84d5681638da2fee6fda804a2422fbb9a4268bcf890cc9fb74f98464bacc7d2623512cc009a1f918de13f9422398142ddb6040f0879214fcbcc1937eb81e11c9f4389a8c9b2b19817eab43657f9aec91095ef0cb08c8508af77300fed00b6f21952ae3b6be3024cfa30dc71ef1fe467e77d2b394483fcc916150ef9581835db763132b2dabbf2d480e588dfb10d61aaa562866c99b5b79a178028f82569250e52dce60833a3d875abff0e20777256e7e030d93e27336a6fe68bd44eeb1c4da1d703f0bce141321e29fc7a44b29744f8692d09e052b8ac693dc23bcbc2405727f29321e89f27f89bf82e8d2c9d24557f22e7ec5c6bdb0f2a0733e643de5fb8373d027b849928b69eeca1c1000c13e228b20f767d46a3a63598b95fbd05fc63540d7dfffd32930fb24a20bf16f8c06065edbd9be61ca778d528ea8b6d282ed88586cc09fa8595c89402db1040c6e3eb49cdaca0aac5c6719f3ae3b35508b1ed93e0f87c2790d80c30a6519101d8e513bb0d4d67709e928f8cdb3b37925fb1062cda8a6986778064cca1c2f99850cbf3a250435e64bfe4462521f52c973a78f671e66db84cc6fa775a7b1b0474186f6438c834163dc1b389081d1a63411340bc1526c8d68c349f48c4e65ddb2c1e8caed46af820c5307450fdf52334de3fe38c440444fad3c86a8781f89a740697a859555ecf143f4a0ad98a1936e7ea2d64b59e3bec510b364d272c983aeae4239fbfced327997f6487d1e74680305f8c6f8172aa11ab3bb49345277600720bc04eda8a63bd583be0107085b25e4d46c370093c6882a92747d2c9a47acfa293150643df43fb00fa68f4d7ae7f8f1b233b74ee672936adfb8430fce7161135defae7e2f9fb942bddcb33af840a2a2a770ba03a0d3222887ac958f709ce2f788d61e221c925742f4c04f70fa03fff4fdeae934b5f16e59368672d16a2e847ca5f8f5703e601c7d893e1aee529a7107b601213b72087fbb1ba99147352e3d5332571c0e3466eb9bffc504e6d0ebae9f323e348eb04860bb453aa26c9d007670e90c6c49c296d91691ad1fb25ff31ce4f8322a3ddc26c7f00d0a6a8c424364ba9a6f3a647582bc5415cbc4464ea07abfd49fd6b4e9c164c3b9ae20b8c1bc2cadd825b46988f695a77ff09ec51fe389e1c23fdc8227ea30631a5da79d306c29de6179d1cda7853344bdca96edc74155d7fa13504692f7731ebc7d2853204259858de8e86133ab21454f5097f72177da5d3a0b99409ff9cedccc138668b48eabf0aefff650baee43fbefe184a2dcafeb2ffe4035c30d0bdc9ed9fba2bc77c43e42afa79815e13f8de36b64622301e686977df89ac90bf0303e235b0fd69f4b4c7e2513dc7fb7950606dab7e142f97e490a09c4d59d614d9e65b86833203500ff6bd97ec0c88c876898150a6a4a86f40c6ea512a14493e37ad8af5ead9ad5a851992c4b314dc71456c78090e75e63aa7ee0942ee4857fe71c9b6f9197a7fed6eeb15aa0694b58f1840e7859765d946ac5ba2a5cbafeffa2e3f8423dd1ee72aae3633079daa987d5246ace04aaa55ac45375da65c88e8638a92296423df5c3df17ceda370636623d303f829690d3035f15551b55a73c00f802767617e39b83eedf03c1670c0da9f5f4de16441dec0712679dabce491cad833f5a509b39a5e1ed3460ed38be7c18423c760bfe575f9fc3c3e2a5a73ac5534982370ef0ac463604134524c0dd7ef727897632741472896491e39beb6dc202b837bb98ec63013abfd96435b44dd510b26bde936cbed75efe4f48f5aac5cb3979f4ed14bfbb5971610d6ec53e3e977d948ae5ab1d239a899ef860f94fdb69a6203989aae5a9d38f89ed59d05aaa232086dd14fe1b4e6205eaefa0a2a2de94b4b291abc5e37a794a50133adefdaf84b638e6cffd37faa50cb154979756a0e39c0c91da5aa05c4b7c32f188d57b9b12b60f9211dffcac82e1a49aa84e6eb0c8e8d256fb7ef768a0dd11c27b45a3ad1e854f1ba07aa69ae141796847f55ae6f14a03f0276af89026556b1cdd04c6f495c072720c89ba3416464ac2eadc499131620ce9a21e8d158be0c4cd1498333e12671751bce4c269d2c7eea918fbc622d26ddf98c9ba0fcf2ff1771d4d4596d930da70c19686c8faeb113d02c05d987156cbe7a37315fe7e927abaff018af711d403b67394df9188c006174c7d09202dbb012201616f08f5e351f09ad8a92e41da334cac6715d4f290910008b25bbd62e9033113cb78ece2ce3066d26082d2dd4e3284d593d7e89ecee973dab8afb9212f07f3cda55c154a4c7bc32aa5295d3f4d063b1c31ca26b89e2da735aae92ce00a6f9e90c9038a86985aa5baada92e73141f598e85dde66434bd63816752566b429cf35998989b288ea5d0dc910f322fd2c25e1939092d460960bdc21d604a8fb1c86c5ed2c0d2afa9ed89e86d0f3cf798d6624e9e1cea3c05125464c594135dc9bad5566ae74f0ca3dbb838bf200ac551225e2bca5cb5377ea5f7158aedd6c3b09c5d486476716416d4052c55ddacaeadbdc7ac439be6746c2ca4259f402ec763319626c0c71c1d61e0db4c76d28fcd789fd2f129b2a892b32fa5a42df1030ddc86e42d60491e1b7d8a6ec57df91688a9320da4f8e81f999bb4e0812f32f23900b72d37b57ac69a40d2c7980e119e22d6ba183d96e8621fb324a94c6999200d06fca954e2438c124835707346d75aef1813da8f3367295c8294f528cb7943e2036d7ddfa09a75ee0a54ed4f18951b0bb456603821ebd09d536feeea8b8112862e59356d18406754706ee017c7aa1b44063aa92dc029489f9fb5ff0c0fe34ce17b7f180c42b88c62e7925c444149353874e0fd4f3e8280ad85a57a9ff1fefb11ec1503c132f87fa5375eb1d849f3a6a6f4c0c036afe99889e9d312099e29037d4145234960ce074841153f283ee5ed4c9b2d61033130b71570517bc33e9c8187d4c0c5a64261a65df5bf4f5141474f2d09350eea780c781eb423a301bbe9a0f77a94ed6a436a24c1a67f5a3ec38e0e7040940111a4f20b4c05b68818b93acdfa4a041f532c3a40bf32075217be5750683dfd9c0ded0c3595b1dd1fc55bf14d9d0f44e2a3c43cdf9ed15445c43c2860ba327e85caa6a26641b709249020cc42f3455c7be0126eeb9a5ebf47df792d3b843d789fc6f4a0e04dc7791dfa7475142d1b753ef3bf5758f645aa1a9bdd3b61b4872f1b827502aa39b51162ea92061985a0c091c10bbd4f0cf1d6c4a05e17761eab1d65deca49a1d38bcc0771c8e91f25f68c42319d9db6a7ad65a06444b9caa89973ba3467f5242885fe1f67569ea225ba2954e6a137979177f06440ad58d837e13ad23c4ff95a291ac2505fa7490134e01ba9e01ae6874b59bd600b59ec676d87ffddd8d8e64ee516473407e16c0dcf3d332df28ed7d7275a82993d6db7f32cd7df810b4bda123c776401aba642d46efdda60b1b2d1ddd20c281cb3b9b5050bb1b67ee9d11a8b374199cd53b42e54358a4582b0be7892f3fa542875e3ab3b1b19ecaa69451d2f7d3197269ceffa03906f3699037ca7fdc13b2241b7eaa8ba4ebc64aa12c616d9ece76184c526527cf980b8f9b76d4d1f5cd1cc4d88aff35ef84914ba63a68fcf9be4b1f5e78a53be31f33ab0115ccd9313f18c8d733d11097d386e8d33ff194af35c3de718379aeb248dc679e6a01f9d423aab6a08bf4b9c5a70ddbfe0bc1203adc5bc4da3b760d24e1831bc587a0c3c6f8833b0b4f5fa8477fde8e076b762191fc5507f6b16ff5cda79e7f5d8e5e26e0ab06bca01a540723093eb78d3f8c9aa1850b21c1692d8686d5c49ca16829e82c2c72262c52ac6d19aada2d574ec1e76930474c9321e4a353c79054e6758dd0dc89993772c1dcda73cfaab526e5488beaeea90b9f9a5a418911083ccf1c8efd6d378bfd7ac9c904f3e3ec70d920c4a267155fbf2cf6adb9856a6d63a58c356e2c0fe92696958f11d7260d3bc3499c6b7e326dc7e3f57e308d6653ec8206a96962a609b6088772d25b9bed51bb31ba632d5b9d784d54946780e0d8e6e4556cf722831ade11af9d58d09657ad95e8368a2d1e65a99f95a741b296f19e32115c696fb5cac2899d8e2d0b8c07dd4a9e5fa7c147d48180f21ed2d95e1c51d7438d7f708a34b50522e6bdeb631cc8c590742899d496647e903f129f87afcca0e6c8f60bfb3febf781d3899be8296c586594d292d601e541a3e6f34ef521bfdbd985272cc8c130570c67437ca3a3db288ed2f0e3a3545dc97748f68e50f4e7560b2a04b12e4daa96455cce578ebf31283f7b7f564f5c354f9d47ca2b9c8fbc476251be45ca69f610a3461046ce1fc1b582680ca8609027191a9893e4eb9e80528139ec28f149c5a10eb5434cbb1543723fd2a327b857ed26cd3867969ebf0adfbdf921881572b8a72d9ea39291f7cff1f758a77705913bc55856a45455346bb2d2bf0951ba90f31ee11d9083be74a86a37ec95a3489e272cd0868825386e4ff1695c48ade6f22a4e22397f0e4ffc5afdc2cf77e0f261bcb0d9c0da7409eed6bf74c3d9ad451aa57c681e603eb0e970e5aa57b19b46771e82b016e094f4a54239ce293af652ed772441fe3c9bca3bc1a824360cdbc04f2b85c993698baa354878654f390ed08d5e88a266b3f7dd0631b575d2f103b393347d9056abdea5b7edeb4ab7a4c87a5e6bde65c1b17317b77802409559433a7daf4d2bf03ef3a00ad8ae801166e649c2705d4d1dde2ce09945bf370259809469899f52093ec8f87f51197190c8afa88848a283a63330e0c1ab25e7b226705b6c5dcef050b43db4c297b0cb6ff8af210d272be75085b3429910de49336369a8f96da018787284697d93053c05c96ecb3c38b8a867218c6845b01876884a514d9b232be430cbe0e77d470524e161630c917ae69b4df27c9b27bfc7a232481e9bd885e7fc8b944bd5ff8b66e48f735e1c3ecd84c0e3b4deb61925b92c494efaa1fba50d6ab39525ca5a1a6c608fc5493729034a8345f2938c0e549f1e6288b74758268617ab447012981e386986743a09f228274e4363a42714e715e7bb87edf0e909d6ea40a03d36e47250599a9ff2a7c58159f83cec0723254d757154d92a14806ebad401d10282de61bc236f485346f4b0c3b300cf47cbe4447044f539df8e7bc18afd3a79f2527a84d2c1132af9dbcd01ebe67fe7dde913acdfc63b867efbe3da655b57348a428536342cb28dfc9753019f9801c71c5391b921482bee854cb04539e9ac701fdab55edbc7287a0570b3bfe15812069ee9ecc4f3b4ebac60e71406068be491eee814d3e03451f58f746da3d42ea8512b24284564f7563f618a597aca6d98d8864af565f877b035291c2129e409cf299f9ef142a2fd4e5d017668043926ed4488bfde4f3113e0bb5d205051882ee3846b5e82dcc09c14d6a7e61ad2104db679ef950335c10be273095c22d79ba0d0dfd7bd986389f05fbb03edba994d86de2e9c928194f2c486d6a0ff172b3794efe083bf113002de2730c9a399b82441dd58819d4f8401b0f4865eb8ff10718a57ef241db45ecd2730a0cf3d9b89c1655ad1ef48e9cb572683e1b0c376ace86193ea98c38cc0fd233592190006a907be003fbb3ba79bd385432964aadf238edd99a4db4f8b9fe8c89143bc5a7ad3a5a498b8059280a5e54a2e3272d0949c7a2d8c45dc8b2e9a27018f1109fa148155e8e519ed244052cba422106894386db24a670e78a3037ffbdfcf4a0411fd649ec8fb5848ebcb552a7a01f6aec0b53d51be9237c7cddffcb21f79473812c5ece3eb30e1c5c1666da4f22bde45741c36bc92dcf52bd75b92b9a7a2e883b7b36fd5bc269a8bdd4d7a9eb6b66fd6788f8e00ccab4d09f52886d0a4d80e11c1ef256679baa43deac458e1a2a0063d653bbaf00a484c6f1c6422d574922b731a20ee81275475302c9ae81a90c55d8f2f570d10ee7bbce64872c21deefb92229ed371ea871e1599ba524f8f13dc419ad1572be9c83b9d12c3ea871402004f39a5052cfb758d1273b7ff58ac58af3554647fb05cf493c8723a497e8d3ee579004072dac5ecb4c294c3c6a7aff9d3f6a73534292b52df645f06dd96c7a917b8e387c61e05b3038e69e5f8a21c4c086d41ce49d400ab0e96b71fcadc7ec2d372a80f24e5b83e67f91c48c630093f1de9c7c2d4d0ad5c1b44788d491f7babc25ae173ace84b4467d1e13d728bc8a3a841cf76c74fcfe2bd975ffc2e5466acf315ecbdf50e1d425b9494468ea2c7302cf333640bcc308cad7a1fa6e8af52624ec088a71784611267534d87085eaaea5f8dd5e1acc09d0aaffdbfdc8a93177a171570c81b5434d9e965a6a0de2c4ecaf7aeaf5002604e4a053bdedd5234f15e4f3280bf109dab5e3b24852238d9cfad19e1f5fc87d126677bd22000d3563980ed927c55f7544ce2dd3f3fcd7eaeef2926fbc6850ef22195aee8a614aaafc164416bcb69781835b8b6da4f194d813e00d62bb2f7c9668fc5cf359641e6fffa56ed01b9ab900b05bb64e1555ec2f01295a51c25a0852e9a9832393825f8834e6161f339bab95b7f0054cd297b6036aa5a066f41d007ec2662a5544c40be6143de552cca1cb5d0eeda28ebc2edef2d8d39149f4be8e8e07375bb10c8f8fd0a2825dbd81075af3d466848997a9581780cfc0cc3593c461de2ce0a2044a77f2b23e17d6ba6195113eb4810679def1be4ce38327305123a78c9b297de40970ffd62b1929cc105163cc19669480b25bfb142810d6cf7485b34e514dcab822a31d66a1dc96e865b3785446323117f55145387171ca7e8c065d9f9d6feee00b05bde3e2e193cc573e686c9f91a1a2ebae7a91fd8255d7086887d16f3c28faa8de39abd2986691474c5f20719190c3a105953c49bc70da06ce5290148ace35dac65a39534cee8eed967448ddf124069d45d7e2aa3ed4d88b1e2ffaefcf023268c209946255b60b11a9246617008120a62ea34da5302a028cf8c535a4598d90a6379754cb7a961e1aad4b0ff6aaedf404378fcb6a801528775bf7c6cab9d1b4d8bb7fe0c565ce4d9c276d8013bd876216c1fcb483b2ca73ab0f2bfb82b39725001243ab52483060297e9ac78cb9a8a62d8a4b05e0a9e366391ce67f31fd0f846d786927e4de28caa2bd5d798939846796c31450e689aaae2d3045df41e2d62b02009f06590dee0c0ae5ad6762167246915f313d039f9b641f5aa3e31eea9e4d7c5fbe92e377dd265d10ac505cffbf723f3162ddaac0f76f91fda2c8ec9e09a33da23c77cd98e1669f3d8132f893b5563f275f9ed50b2c812f32515f50698a2097ab44355018c058f4b363a59121fa93c61c7c21cec278358f96ebc39b604bf20cc8b5c05fc4d07124ab80acc748956698971f2a822ffec85d0452b98fb92b99ec7ddc22deafdf70874ffb0f5ce002c71bdd8a69bfcc6aa6570749af22d63903acf9c8b9d21872ddf31c72404c9fe3ba3acbac06d245259e2a1735842101008f8651e6d32a9ff6c8701f5299a8d43a42532f4720b31fc0d7d8fc4b1f6ee30bb44bddcaae5160c3e2f71136fda9e51ea143a0ec4c28dcee4743ab347c74e2237e0a68e955e12d858229c73a89de5e0be0b0230eba8eb701e5a684a509ed7df06c8dd4534b2d7bd14ee2deb3cbd95e258d15f585aa08c52192405f784f3aaf80ef566ea95feef80f60828114957496c737ad2592f4278b2ee9e9adee4e9c82b718185d7d14c471c088755363ad5350ee1dc9b645577dc727ce60a470175841bdbae6e7b8664f15a0b376744c5da71b9fad030eface47e621faa7d59558cdf8e49aed4616e9b71579b75bae828a96c00675e15d5116fceab1e0eb8ad7f276b2d211735cff3b487a381a8aa25d119f87774264a637b536230fd7b56ff7f232e679e98aa319137e50c002f6639eb35c934fd4780c414f47e07c806573bc55751026c3d1020d603f1dc1223fc51d609e00d836a27d75ca3b795e7e7e6850c5b229335c30f56d5ea4a4159afc8f0eee096c2465166b9070c13441f8c9c1ab79ccd576c1995e6ae3aad61c68c3f1a01b6be38e58097826cfd2b3ddc8e1831aa3a35260ad450d5e99bd34685c5a93e6baadef8cfba7ec86d2118e18cb48d0c88b724243364181c2a7e4c88216ad843f770f5c60d26a694c38177d6eea038af5d0de1cff17c2e3d469541cef0340bea7274f25ec3d85a94684e628b9ab5d9ef01e6a62b9dcb14f55e1af9cdcbb34703a81b3b301d539aaf7306319edc63b1e6ee8e9bd0b406b9695566f06c8acbbcd0b91514b2cf01e91c825f21030f5445e3c695221389a7b1d0e4813ffcba9b83b889cc8eb174182b2a37ee013f83f8ec98ad32afdf6fc52a7ec4f0145cb574712463ef45ee2b52a4b6d6e04c62acca725e2bb84e73f48351587a8e7207ba6285343f8b55e50e9fb530cc3a7f21bb173350ba33a3dd424697d05dc8375fb27ee565bbb8e6fff1d8a38dadf63b2a7413a62c162652e42a32921070c44f0a280fd5fb1c70e4cb89d51b85ee3ed9fd8042bc62d9ee8393b92bcfe6c4a38b1f06ea4594a20d5e9464f2eead2d3f3c6a7fd191ccc377ec98513c85b8d2f871f5f83a8c04d12d422a048780f2a3a2706b236ffb2ef120b988783c900bc83257b3ff12408d44ad73c786ea1e747c4e2aba1b42bdb45dba9b5587083cdea9cd2a13c6835d7dd2461e0112f8afb39ece9a659b8b20197e2463b4108c980deea556ad036fde53916d2c6ddde7211b28b0985b61d091d7112aa86d1a8aa0ec39482a850b2b69afff86c0de9928798f4d1afaa8da7539d7643f7393bc51b26c52f48248cd255c37d2c6b014c8f728f96b4a0756fe0f15c98142fa58df94a8837e28b0e0f14e40e414dd59ddd36f9da8baa6d23356ce83c2654c28a32b2994dca638977cd1dd5d7a3089403c5209b4c5dfa8d7ca036348ad0b65bbc88a031fb4bb70e6311484e2443020253b779696298ac82a5dd4fe5515a4b7616b4767e721673105e2b802bdba6480bd5347c6bac326c56279bf9422e00010ba3ee2c4b5546078c689b0200b650beb1f4df9a74f9a924acf2addf5f6a452667a17b8d005d324dee74cf40c62e021371581a3682f6e061aea2eb183ba4dc0438e0c8a52e98e9d5050e948f497a141338bc1fd3b8960ba2513722c705a183a7bd1ebe56bb6c0d4fae495fd2359c4776eea064541178ae17dce31661be4d96268ab34e1f12df23c47fb9dddcd3b87bc30f48de708e1d2c70f90001ca808d6a7b8a1f1d0712f8d73be084c713152fdffd15db15b89a909b4993ab88944caa6147003c5ddd21ceab57c9b6c3c73191eab4a4e570d0e40e1cf66470ca9789e45bf45e3298116b87826753aac5a2ba6f3259701c4c87729ae99149b25acaa53ad07fe349a3953fb59f25f471621c9a538c588bda8c09524537354dca6954bdf03a9e6a595bea8c3b79bb8ddf5bd586c541b353308b47b47038bf2deeed9188450944c80790c6c91cc0e61cd50d017e8fbedebe30cb504d810cb630a4a25d9fc925da6ac0b2adcdee31a3c6f6d67a18e186d3eabfc4b0ce06c664ab388d810a7d754e761e719d2958640f9b3ffc6596d2254f0cb87890ec0ce4bb9e651134ca0ddbdd74e8903e8caff8070e1a23164741335371d36f1b86471ede8d1c28f0530218f1ce756e8028f95f482c76d193adf579a06f102f2e30e7f4d317f17fc075404c5b9e1fa6c99a65667f6d140f1c6243ca98a8719c45c0e2e4f069e494003c77c3e2104ebbc171bc849d886618690e50cc203578feff362a5063de1faf18c5dd67b43a43b3d301043a6c7d1e5d2f4046f94940e4637d29fedabc6b33d05aa00b116b14d90887fb2a294134bf08d2b7405f1ca3d6245d319d24acaa173d04670c2a4ad7d756ac5e562b7dc439a94f94169d810d212463cbb689070025804c98340730a4f9922c76a2ea6cc22b071b2c3d84cbbfac7c7a735665188207fb6f0163644e44d287c125a8da97bc79ced190e1d5e0f69f26547b5521400ff6ef99b8f5a9a0c60b78aac09d58501e163a2449ef0e575aeb4e6efe1a3111bd0cf91bbddebce521e28f216cfb95755c88d73c28ba8409fbc79d8b62a9f8ea50b1d03918437231d96b1a7afe2adfead5c0d6376f768d732bdbce2648556b02aabbf3aec23c7f47c8502c4f48be0fc76053bb2ec687a04ead4ab458fd8c4e59ea00fc23b837eeaaade6db7a7ab26afea14d63184b6d3b8f9450122c436f477bc2bd55929900998fb8a3b2ee8582e116d622da2f6b9ff0ff0e622d1d1b3d2b83e992f2dbf8254b5717a392e975d695dc0830be53d0c4f4694a19535692b7d39eacc25fd72305e2ee88c69431dfc27ad4ad7ab00696e6b2b0de616bae9476b65c815dccaaa298ce8656797d466d243fde36ca639985f9b145ae283ebefa42dc62cb4b47a76b1599096cc7e607ee558bfaafe9b493ec98a0df7525e024cb4964017a61e3d8d22cfbb899f8cfd0a4153555495bf28266a9befffcff035592ea2a4db4aa589e61423c1deb0c1df1fe19e3fed52584ad2906c65aacce82188444d464660a8fc18ae980ac199b804b02dd2efdac733cb6fbffe612066c97c9ba4518c7d036ca9214b9609218e443ac05794d192790a039f9bcdcfe1cdb8d639b478d8aceeb6e7fa34d59777ce5c7b9cbf6713e458c7ff18b27a6ce7051076e96bf82670e587ee21a675b538525da87ec3287e1b3c2ed26b02e20771eb04bb6e5e68a2d40894e5a0f790fba7c31c21be1dad7bc460d3a3a1ab9821084fd37c3d5c2a763decb2bcb815beaad56159bfdd0b1d4760b5a3900c467bfa8b80f43a67eb4c67b7dc79119efc067e69cfac3eb459961e45a1b826b5f492cf1e8f9575594e7257372f2e502fc932898df7dc987428fb2b08796f99bfdd1b36cfb4759efde6a724a97753135b8518189d3c22f4a33f2a92ed247a227a13bb9b752f7cca23e727498b3a7a88c0fd19693ae5705245390a68d21250c7ac82dd44b95a995f74ff84d24330b5274fdfeb908e2af15d116245c593a62a176878c2ddd15b16d2f3f2b20824071e678cb846bfd101a7fa9376d92958c792a87d1ae1c62c5ea4ee7467315d42dc5c52c60d52eeccab6e98f4560543273f9edbbad6349cb5f2f49debdab4dd357ba73474de823f98a73f201e445c9f6697ff9a57dad6114a3d1180caf2d73abdfc02d7e548c1fffd0764811985730e3147ff20e1ca4e31c48de1c40251093fb5125ca9a41144a58526e9949b902b87fe55212cca5975d3550dad0f3d94b44bcddf188abf517b9099e198eeab2c063fa582fa9d35e0bce019ca349bb00c224069e4567ccbd69a4ddbc70491b9315273a6e5117da32047899b04ecb39c670c931786c1227802ee7c7cf34923fb37defd0e459993b22c8d1da224d806ff5cc1450f203baa3377520bfdcad14ecdcf64eb6e26ad978ffef251f4d58c68c7b1fbaf802bd20ccfb00463c8a2d0c964a31c2535361f900a138572bad3ea1a6ed430fa7146954d899e5291948c4b7a7426ded2e537ff6a83de7300c2027dfbf8bf0b00b51a7ee1bedec395988eb07cc27a0e1e2209d7f732180dbd605ec0e27a294d6aa6e464110b9691328731e2acfee6556aeca08794cd04d67f3d4ab9fa23c95b29ade519ef08b0ebcb3775ef725d8c8bcfd3e27964035760a8cf318e3dafc752c846c4583807424ff7127269344e4d93992d57d07e4f1312f29f4f0626a562fab0e07d45cc45d495f0c1ceb343d77c0c05ccaf7d94084342f4b77249a9ca79934346dfd35a5dd01d28cba20a995583329abc54f0510f7e40f1f8667f2c96fb2429c1ef87ec6e8f7f6f4d6f7e947856ddb3d9f869e5b7ee0725c5de60a197cb4136235e52a2a7c2c59ac236fcf164877cdde0c5eea64b277373462fa57a6fbb94d8502536ec9238d06d01ca8af0a5b18af4b823d0349eada953aa05a26ef7a17e96f36cbc46027bed96850653f373d797aa7e4d73d12e2e901ab9ca108d444ed9a53dce57ce6c38121792f5ea476b73d87e4034bd2dfe911841a9b981010558c210192985113b61e568d91c7de51e9e05a4ce1617fb9b9e40e711f861c1ee0c30785509b1f63fb3e61a87d3edf622ed17d2e4d0907b809470e0452690ff71684b9778d081fddb764fea61ac717f701f058026232b99d1a9c67670e55d4a605717ae38a1025440b43c083d802ee8948ec9d87656279cfd7b9fe300f0ec6ba24f29a8655b2aafcb51c9b7228d0843fe29841c7291a0b9027e998e7016deb637c100ecfdb36ec131b9a35fdd3901c8a6bf5d4d310a8e7fd92822356151d82832c9dda0a700bfc77a930f932bc4e6b0919139b1b00db9221a3cf15eeae2169a1ddd9a96c0b33ddb738e2a0242409a2cbf538b1efd33daf609b9788a526e389ee72e6407ea57767404a290b0716face155adaeb712f21d6154475705f0ab45b63df430bb8cba6a3b1f44780922688b650c470c27a19a3645861a8988ab52c7d92240690262ae6b814a7bb40b90f3ec2e45003def71c17727668fa9b352b85ed73ebbb8332c3235cebdb8f72b3e5689dbf0eda38f688ffb5276f4f04edff70134b07deac43847bcbe5ed38a565bebd4440de90d589b2eee7f70635604b01da31e4874e43da7de78967e2dd084ac057eb99fbebeb241fb509e6c91fd34c846ca57a74e7e2fcf871bc69bf9883e96639fdbcc9fca04b3dab7a577cb002aed0039918786de514d7d9adaf3554399ded8667508d28c291d26de9e7e6e023c55842c9a1c7393873eda0f0e5c8c6fddf879b4143bb0f7cd963fa873b1c84c809a36f427ae0ce656fd7449e923d3b19ff4555a235528544e6c5465543eb893b3c8db285c63030ae3afdcf4c42298b789313ca3b7fe1af4a1367571c5f63b7edd33f25d9b515d01b20a65441142df4d6a142bac73e3c62c7b7f8082f897996ed3fdeaee6ab6e3d18475121efa7ab9ad9be656e3002f5a1b87b5ca9a6dad69887a66c6839cbfbc3eab144dca78c1055cba3d8542c680808a3a564f0d473b9cbff9d3c1b28cb9441ab02a3a3442f8d60999b06de1e7b3d42ec871c267ae51cad4b55d6500628ef3c48fda5c78b373099d444ab52ce3b2d762ca22dc6129c1c2cf56eaa01012ed18b4628e5dc3c1598860d3182e1df8bc8fbefdb94d305814811091e576639906bea697f8da2a4de8d91540a710879bfbae37031dae8d9da691e977bf076717b1772a1dc35b95dc0e1658fdc5f1ee8c89c33df6145bfa8987b1b62a6942b42f66e8512331cde0e43d88cf72bd432631583599336ff99744b6f821fbbee462c25eea079136d29f73e82298af8ccd5fb09a06bc5e14a6915820f4371516b9cfff351941197392530d6e2a58dfe9c91261743db4f27b6506b1c7bb40cc564b38897a053e61b17582ab1afd3d45b6f65f5e8023d103f2beaaad510119b3b30b455aed277cd1dcc51ee2a14dcd01674978490a077f12a08f87f0141747952f9265289c39dcd27ed7c0b6d68bc13daa72ccd0af9287dac44ad592c940e29e8f9b940de80b4bf5087094c09dd50eade72266123a05ba6d3069d3743dd249ab7a5b7b474eca1de0fb96650eadad966eb6a7c9a70c90331d94e9afda7cf67de2cf392d7284c8e31cd4395a9a8f2d5f544b98985264009a2ca392a9078943e8aaa30f3bd9e9fe9d50d0098916b317fbd583823e1f392f8a6ceda4ef7171510b87f8b6e114f1aeb6e20a796c24c23a2d8d15e82381142ab8527e788a4279cc6ec07daeffcdee83ce53567f47a97c417556207f94558fc441ab5d375ce3713569d16cccec48a9b3b79c2ac78329cf3f4e688f1dfa324afa293d81d8b025d46a6777761c282334907990c11a09eb2d6ef197af86ab235597caa646b62dc1625f0a1b8f4fe170a3bddf4a3e51a11203c10d847a91a79c38a92f7001169d728891ffabb74eefb69323743429e0c25e0e106150b4b26b046cc7f8bf8d1b1fa92fec4d220d582799daa825ce05239270b7badc03da6d888cffe11e8d2cff63ae7d828f6dc9368c4f158f9aff0a24db77615f9d5171e7ec2a0a34dfdeeef31dc3a081fc1ac35db35d2a6a3a4f0adf8ffb9b87ab5a0e5ffae6b4150cdd82df8c72b7041c5f52f3b6e7b3d34e1de8c9a285da76705a97a449d82401d56d1ad28ac8f0776db89d78cb5e21254272692a8b791d27a598969ff37a19f87305228a4a00ea33c96353f62403c7d74ad43bea8620b3babf90cad8b245d9671e2b2c1cc205991d6dabda7d69afd8fa00a4e6ad739bfc3f41b06655ff08714f37d29b990edb8703155d4668327fb793e9b7887cfc415d9010cc5a6e60a7a45a59266bfbbf535bd40245b5a67b4735da1c0196540dc75772d26bf7f30158c5a13e08290f884205214801ea111af740d78a96ae8ca08b7cf140f1b191f3b18e113caed749f028fba134ad73cf2bdcb04daae205a4dde467db8bfa9b303dd6665cc8383a2169fd6f00294d84d97894d8cc7a07fc7dc73064d4acaa673b779a7131f7d6c807f3f22778f32506ba4c2a033398f5e48b498355e1cdc1ebcca02e38d70d92ff073b6f04f259a67ec1a31f995ec2d496c4e72ad956319a9c1642ef49d50841a406bde0d97ed844839926509c72af3a56edb402b65f1b2cb083ce906f3f375dd4077ce4a3ca8473e9f5142509a6ab0895ae1cbfe9cc35d68b001f5363335fbf7b6e445961e6075bafdc35f3d1fe6bc4e16b2fee7eb4769c7d173936a79dd94f9e7b456a02066013d59da2cea0c1f8d84150fbdf88851c3fad4aa37be00e60f41bac80accd90526b784c272a4688a0107796d57490437f7de82ba719219dccf0a34cafe30ee5890edaa68abca37af7817d31a96cbabe9ed658414d1a6fc4617b85e936bdab54adef67a7c0d3337a3c010010df3690d1214dc275c702f794f80bb47d1aae6754e58d5eb689579ec8e47549cd88033e474ff48eb15b1cd5addbc6e50ac54c56e4bfcbda3a8a0381a8762336519a4d6f787cb464d0182ef803f5c70eff5a69f3ef5c173c749f502e29a863228a03ad49afa84a7bad6b818d7d25c0419f544f42ec2d5f56930b6fe3820a82518945ed9d03c99a3ec9383542f6ada9d114df5adbd67a24bd25d42ddb8e6b21c820786b6a3e836c8e11880096c88a76e6b3465b2d61fb111456da58dcbccf7b19b300c88db34699a9ca265599305c22a780e0e1bed18fec6aa777cbd0e9969533401615f79cacfe402f11629b8122175a8367c1d105de7f6a1cb88225f778cb322e41f990c6409fe24b6ef4b37780c99d8068089bb3a4b778ec63c80f6f8d03343ef3770f288c724cbb375f1262bcf9def4c6cf0f1b44438ba89a2e02cd44f22143e05e69a393c69eadde7cf16d49be3af9d557b0be1597fcb7a681dd73bafa132de4a34ca6486127234bd0ab6c050df98cf6b0f111f7500652ca14cab4a41fa2d18f1c664626ba70f874a8365ea64d1e1e8a257a1d313a6b652cf6db617dcd22d74378159ef1ce25258c76e1e676aad0722a01e30db706e67788d558e44bd0fb600b177d88096f96dacfd78b5105fab1d3a7aaf3821f9b6c39569a4ebc38fb30d472f257823c495e9417539f0cdef91c7a5b0091ee7c195e0268af5ef300a5c9fe1406579ecdcb0915397d14f82ed2bc55f8de4e5abcecdfbc41f9e80a83a072d01418a2a544f718ec3d4f6332d1bb2aebb00c6ca66b9999e6bd2bc490523859f0db1dea63779b9f1f84d52cbf3e7dcede8214080c6b54916f512426bc9447266897ad4078118867e0d6746cd99378ff539066b246ecd123bcb3597c4acc172ea13c1e260468fe12b1696ba737e1984e9b593f774c3db1696be6964319b9f9388707bae3ee0858528e3658741dc271e80974045f3ccdcf5c271fa4458e81023f42761c5eb37375dea4e4d4d8b1de0b4724631cb35b0043e7ac67c4edf767115670eaf50370af4cd2637de6c760e5750b8bda3c5351c16a9a5ebc02e2ea24cd10e9fe31deaf0e250d869f933642bcb9da2dd7ae6d92e3c3242c2ca4908bb60f19d68897616973b67dd1f1b037c460f7181782191858f2003a4146daa41901058972d7baf5088dd5f89f294ddf5d0b6af191f36df14250213469c2735942e825ae6d36406817d2ec872e739cc1cb9f0bee817e95e37bb38c24b9bab958654afa1a38dc4c3155c37d1310f014a5860de0637d0a48d23331bf8afc9f5cef164c130ca4a472b360b92d4552f083d6ffc381f8b033bcc0550c42ea706ca15026f0d4171c06e6e3ed636e2d7cfa92856ef967342076d612e419457b0667c8087f01ebfea10184cb54e7c6df803d8878fc04ec7e45e1705072d1a554a5ead50980fc7dc0443a2f51f64bb73fa10f183be1e8c4368441ddb9cc5c47845c02ab67194a7f27a109036ef7c44c33ea236f799350705cf63fa5a8ed6d8075b8d483c41a589c4ef7efb716cf495f839a1f22ae433f35d4c5abbe7bbcec3a78ad021babf3e0b9ff84130557125622e93b0795670617a426fa536430d1dc22c79ef99b0474f5fc4a7812efe5c9e2e9f1a23edfed2340ce460b118525836600127c410d977d7f2e9a89a6b571289479ee50ec969a026d8054077f783ac7038fc45f1d7972c01d4ff6811fb44dbad8a5de90b39b8a8c055e25ba81b4839725ae5f33875d468fa381a5866ebfa41f21cf2bcd32c0a3e171ca4cd5ee36fda6a7de9f0c630430e796fcae444eddb481d8c61f7c1c1a6b6b6df269eb1c69ddb5d6e2c4bde345e22546ca393c69f48b4d52019f1cd025393fb97d193b53654aa6bf784c660040145a5d5da90092751a9294b526d087323a04313b76cbe6447ab73707f48abe7628a2d8e2b0a5de8dc8e7d4baf10cf6fb714170a8d0e808f9b00d1e3796967ea69bbf899bb84605751b423872250ad5e61d0162613a0876f1c0aa27c7c9dc629bc9ef8fdbcd6abcd26fcdf55e0bb080028cb3de1e3785a3320ee1652bc1a553fde8f73da96ace4c55e5d140bc4211918ed8694dcc5d974ff47276c8c157260e9099cb8042fc9f9a258a6a107023ad1f91a1cef61a74521564bee71c2c055606b183fb3e5f02c21d21f45d8c3dceb63edb8779d4e54668ea48b3d283b141db2e76e2cd4f4f609d47125519bb969771a27a129d82b326cce960126a21be34bcc01bbbda81dbdfc70e2cf40f79d3c7da6f29603a5e52e7f968c8bfc4709adfad10b5d2901740c54625168f306997e9ff6a4dd6b3089030fea08c28cf13a58a35e43883a9feaa5b6552041142f20a916a2b4bb0c0892a4ccf1a8707b3bd537b359cd86f831c655102f69601746ba8a29cd9a089cc3796df03360f77c6727dfe70cf7bd1ee97bd070a1b8ff7798ba8dc2e1ca6f09c1ac987da350d1929136cd346b5347b4aa00aa08b1707ffd7ed550b167233ae883db4791025d4d3f0893cae53d0ee29569290f29b0f73b691f05895c9a2c40357ea89b2fdebe78c41e14f014919d17cbe67b0fe6fa854d65c7a2fa0804dd88d8638caa595e49d2bcb1eb6bb45aa447c4f6ff29d308b7785fa01213a796bf7f61237c38b7d6fa76cb760315659cb37e2c88a9cfa7d48353a5e160709aa599f17ab5076cf9010a1aff139e7d908e73c96c1eeda61568730981f77f749455f6d4efa787d9fd40630cae5ce4d302f7cb502afb8a092b1a0447db8c42d95be45ad25ca5db36cd0f24768173e21b968e7f38503c70bfe56101b8152b3e1a32d922a58fe48f8fa01802d578ffce70178b29fcd877d58d2062a166933fc33d52c611c44d98beefc7a2ddfab7b17a455cabf8acab61554a4c1e649c4d228fea931d30314849cb63eea6684d5410dc66d24fa96739949aa615777b13a0849df0f9b95023bfb065c29379f515d4eb24965f0da79ebfa7af2b3852ee22611953769bc08b0df17def102abf69d9e9d2ab0854760e6ee324c6d35d804f0069d65636227f3004c20e2b74a1666b877e0701f933590c14a0693251fb7588d16d011de7e13d98b07a9935ef81774938d1f8dfb137ef0804e32d54efb3566ef86664a6b8d78d19ff938ca4e067e6c9bd56a635ba2884c97a074fd7e5d32a98c6ac2563323e1d7b40da5cc1f7a66385ef4badc4fb28ea729d6a406b13db81f59251659084f059081828fbc0a287f21a7481d8dbacdb4cd8714741779ce7f0b10d23bffed168fe6f15298797240be1ab25efd139f8f6663e275121659798aa25963f01fb9366b0eea86b68b02f48c74ddfd8f7d326a5bcdd419a78d76dc27507ab0aa42971abb2fb8f1b624d62e13980139cfdec46acd5a48fcfc5b86a5e940a9849b14c16368fbd87c5fb40b8f410d515fd63ddfc55c529e5871a4988f6b1478222f54769ccbe8ee2f3b735fa774ab209ee535a968e7f5c73ae0b5de7c384522f475b368931a1de116ed780a373343da60ddf436d33d075b54dc44383d1b526a931061cebb55f946b2b415547f11343fb2be1233678bcf7d349560ff71b11f5ea8eef27435e40088394228db93f8063dea3693be95fa1569f3b3c91b8b67f0b77d4a7523cf67d842d97ff491ac1842f40f10eacde168aec22d2d14732daa332ab4a4c30248538e83dd7afd1ee5d712876feaf7825829e2e7eedfa51679ab1d7c340f9d40420378b49fc3fc42f72a9a0ef50bf647469bdcf7149a89c14818c0ea9b5fee05682c065ca8a9032bb556e10a0a2e7d508f1d60276b6a8186759960374cfed62f261cbbe8b3e77cb01b01c412d961c16cbbff5ec6c655a18f3d99b0b8ba2b4aa9480d626d4534cf488116b5b194add0074a593366f9f4c8ab554393017f7dbcff227adc4f71578342e2d84814a1c949f6d51703ab19ba4460a1548b29a5b52b5214a1bed29e9cc43e8b0590aa3070424a755fbeff2c6ce21c722042d196d7192681845c6f898923b56e5f3a7370eaa6dde6d978e89f788d512a80fc498c33ff338ec7f0c3c600de2bb10c1afe00f096a9ae8df2b5e49cab7828c8b23e925e8b46f8ae63e024d51c5cce6b972e070373aad3419669fce258a3be7b3bbeee648a0c7caae41e311bdc63f25a49691a192ed222014d0071e3d7c64e3592feb0806efb75f5e4af2e6fed4d7d0bd43c4a7c60c815cd80ea50fcf42c7e4f1db51cf0abc3e13f4bf91a41a4fc3dc846fd52471628de83030a44e40e76462c6e3bc2cc3561cfc80134e7d03d955e9d64080cb8010b54d350db79d3f32b95068a570ea03232c72c60631d150f317724b11b487dc910d98e2cb9460ddd235a8dc716278e888689c0d5f78ab3b58c904794b17c4bb64d3d6f28dac34b8a9ee8a1dc6f6bfd1c2e413e4b24ccd3543f6eb8e1b962cf0657bead354f86f08fb83acf0f2d15cdb76cebfbe9efddee249045cc81f0360110d2c9c77265cacf1808e1c01c426620d8e9353ff01078bb31d4e49983b38764b57ede033442be57fe2e7eddbafccba9c67435feef3aa6476bb9f59c22a7186659791f24ea5aa27ff0350e301a756fec499d85eb9faf9d230b40f3982dce8192896f6fae40e80b9e7ea12c5f4d0a31070bfca4ab36898d33f2d5f351ce8cf7e17db47b09b29b6646db4334883c7dead3bc7d0ee01dcae538c3d49b1714f3c113d06102aef49d645173306c4f207ec6eac2475bc8fa26926eaab8daa466e6c34ab10668fa741b86b382e92b2214397f748cd625ba2b58e697d0180c69fda71d034cc0670d4abb988426bd872fd41b642ecbfb6be68dfa4f340707a6b6409871faa6e3067219f101d3cb77ddfff917e482730104661cceb733c1c8990e16b5508a890bb1f9e8d2487295eee1701bcac5abc493de597d5d9cba5cd5af580949919869f4f652c32fabbfa516fd7e11158d2757bcdf0f755df173d3f8a550f91664ee1fbfd1fe2e59ae2715ff9aeea4f6e5041aa73aea79be007519d9e80f3fc68f329869d7f478fe0119f2111f54df2cf7b560fb1b47165ffc114f5cbe2c2859c07c3564d638cf9c85c5b84afdc9e5adc2978b62752b13878a63ee99c68d6b79db08bcbe71bd7d43beac5e3096a2c6a472c0df4bce2087fe04ae6fc39eff4ea505292100fa2e449a20358a447dac2e932e04d7d18ffdbd3f64116e120f3aae0392e635702f6ab8282c7bedeee6904bc2880bd57531f848c8fa136e125585af4a7a7f206ae99a126a67330b01e99d67b16e0f0f06f556418d3eaebac9ecaf854ac4e450620e22a388b25ae4efdcae411eda11fb962a74e49e12de23e88b8e6e8c72121502ca28ab80ec0a5022692b0cc5062a8d2bf2cfc2be101cb922d31a3bb9f5171d85a0a03cc4c51d0a2ce10fea4c1355bb710ada6ec0f11b69a74187f2b1c63f9ba776ee670eedb92f052f1e90992332cd3d3da29b248ecc997d73887e3ff12e12feb5b1939f61c73c0709582ba97883728722837edd1db6f102788d29df604047d15a1852a5dd7fc7c74f30d392c0a8534255713cca7653257ce25fdeced943975bb6ba8593235be0f4f199d174f7843c720ccc6baf0215e17be990c8d2c9236224392020c2760c7d5610f539f02f2d083e892d69f78c18e755a0f356d6c90a8306674d83c32907c66a654183ed03d261ae20ddc26354f38aa3bdf0760380fc09bd7f12b225901dcc213c71318e05bbebd80f524cf5061ec623cf5bc895b4a6077976a7ddfb9c0cd3fa783259354b6a2d9f284552ed221b78d0b55e8eae65c02003e58fb60c50bff4d44d5bbf786a3f5cbd49c3cc914fc3c602d082d7557c3f7ab7ace38536e001bcf52eb0ef80154322b310e2ea795fe7333d0ba333dc1a7a853d0b9825e34ff5cc055917311b257cf36bf141a2decab2f2adcb50466bd0432e09ff47d854ff60e1443cc6d6dacc027bc112c705ab3b6d6c3de3ef5ce27d4d129fdb066237160be102dc61a8690c459a52b319c974404180caf42f8620ff20f9681d46a8953f4291f3de9ff279d00cb82789f9f3390a83d0f9d38050aec674c5c92bff62cf37d43b50905fbfac7db15ec9b8771850627e1f9e770c312d2138fe017e607b8c1642c6193e31f193b69ffac55c595da60862d4d14c2cfe9a6558b3398ed59bc10b4a1822dd6fb02884f6d44ccefd2acae2137921c5c0e61af9b6845095b45d27820b326e1306ee3ae43d05624e3e2bb39362187700f383b59c51594cb7ae9af7a6e004d2ae29e9ed089968a55efcaa2f352623448f5c54666a6b57111956291dcd7f5a4d181bca27e3145020dc777335c526de9ec2d3451247e2f3f3002408fb776a822a58c313e8616d49869e70d2e7926ab78c4f2c95e286db19b74770a15064005f43ccac5d10198033f1a16ef1b73e2fd166acebec28a489847a9ec8537747b5c83997872a38527282e648560e37180d3acab42a72ecac8dc39a281f1c19b64c8c71eb8535c29c8f8b60a4aaad677de1e20a0f21a524e0bb3e1e91926c4021f3070eb5de9d98a8df57c41452f66e5ce73d7900307c01ee5e45201abbbf8f49bfeafe78720bb61856e7752389ff5d32b760488343be6f700a1c9e55fd535ec4584387630c08a2a48f89f1e7efab7c9de516fa1771def7e4dbac84f8db1de0015aafbd1f2d74e64e65fe58fc43a3615066166868d9ced78ed3b6fe08ffc3b415fd98b5ce70858187beba7852b7dc6579163cf9c1121397fb5abb17febc0e3c0acb838d464681e2ffd6d72819fba2d563207621ce08ee5421e74da75fed5eb0c36720ac7bf257418746f2b2c0c9be338ced8a733833fbeee05906259c4d26b6769ed477ba6133cee26d58d44738fbdaeb8df99a70d00195f6aa67023b00fa611d4d09cabe9af0010edd6aab27dc4e4815cdd63292e5edb1a572dbf1c307cc0127d6ae1a2edfd548dfbcf3360079f6cb5de7778ead94d8ea779f40a51468df59c9f68f9b642929d27db1b62b28faa2f28889ef015c1b547c2a7fa8b98ceff4c4e721b8d7caac45aec0866c1e62eda03a822517e99d42a6a679d36aea470b4ae2a2f97fef10c28943ea9861b09ba728bb660b6bbe5b2f052c88b744bf24caaae05561feb1a5735f213b9bd71892f0188050dd475e72c9740ae547d17dba345b4fafa7aa952bd9e0639a2d3566ee4e9ad19515d523d2e4f36d26ff1e7ef1b609eb3b126823314ba667be6d09e7c435b4d6e68e5a8f1345e55f2a71d50b8b8b105b87c9be2458431d77b36ccd6f89235c8512dbb2d57f8c59f560879332543b473d0d19165422d731c2350156be4658e3d17ab99a5e2816e0bfeb8868a7cb38627522e5d2d86b7307a41f3ad81341c03ca0d7e571b4dbebf47d47a90638207314b6b00686d4427b56330750f0121d400e9d590df382d206d0d812187260693fd726374ab708767b3ff731a9774e56647d00e850b4e31e47f422588d47691d26fae2c91a9cec647376c3061b1a41f12ad3ea960b18424e474d5462a6b43b3b083d7b8eb3cd3e3fb8ad176138ee32c53af44e90cf24ac6d1b3f3a0fc446c2b2d7211c2136b646c59ef7a8ac5a4faf92f201651879cab5905e6c5ad9b39ee8b357259ac5051ca342f48cb3b5f641e6cd4b740095645d8343e36752b1b57a0f6e303a6a7cf32fc24a3870bc0e3897e96712d82a1225701f8be67aac7299b091e2048947f23a93c985b761fb16454f89dd5cc893f1fa3aa7bd95015c9da68d57bcc35ea31bf25d69551683c6931093b2aadd0f37ed9acf6a408ed91f11101f562a2e2c5f16fdecc66dda489676775b1a2d62b09fe66ff297ccccf99f5aaf8488601f66f11b9cfdd0d91241fed97d3c0088963cfbe070f039e5fcac771780e6b2b245be54f17cfe37e425c0de47acc34e25519300a8afff1f835d63680fd56064190b99b6b0c723e7411d0b183ec38d0aae036bab9785586d3d50a0d062a3038681769da5820da23528c36df7f3c9a828fb0adb085adbe1892570135b9fcb61d795502f612507a641afe9b2b2b93310408eab6a1a581f107de5cf9998413d3c68d6243afa58f2dff4bbb6a97c5c6cfb5f9dc23aa7393ff18ceadaf4bbc3deb8791ab6744ce12d16f90fff60c7d88ad8a30b82042edb1fb6c6411d873e295d3e86ff5ccb94ca3ae8bd5f6b6f6baef56ff9d9f00356a9eaabc41f2f05d94fb7ec0f69329e3ec74e0900a2d326d76e99ea7707e1ce2b7c9e6a3f47ee0d8ab2d7f8cc651eb5cbaa2c6b617062a51b3ac075fadbea8b53d0b781e9091901c608a42fa6a2fb46fa13663a7273defe1808c6027a20202a7fecf228e09b6dc2cc97221bfd0ac131d90c33861c5b993c7248555c7a15c9d90fe9a3214a0d3d43efaf8cff196df2dd4d116b18330f422f44364c29c0198437378bdc402c079cf7f67027fa945b4782c2a06ec557cc466964d2bf2cf0ec14ebdfe615cfb1133491ccc415e202f1ab98e3c738ea119238f3ccc569ff46181e0b82c4db4e1d997566979b1005abebc940acb548ae12b96ad19af931e1cad7869c80dd8228e000126b3b93d629afb1aa9f487a25701d6ee99e4cf2f5b9f207f73e11763352830ec4e195996180fc56c5d84d0615352894cf5b67f2b1e91974da5e501a8b09f090edde5e77c5366c947b3a2746ce229b5754f6427e403fcb271e487fccf3d74e0fe67009ce4d32c4fc1808882f1d4b65436887c30ac2a06f8c8c8f48d1dc75e1446f6e02f13305f0ac1c859912dab3370f14e7959902351550bd14b3d5b84eacd3998c630db20e49958f0d8366044fc900284d5e8db58504fbd6975535a2ee1ead79b6cc88bc6831f661b1fee9d97dcd7f598338c12befa546a75c7bc86c784b367da4df13f70a59c5bf9933e95654b7701b41963d33993a9e0f46e7281411e4e7a3b97906fca7bb82652c94025930124c911c6dd1333e8f7340448aa6fbaa75ba9380a049b41bb86262d4921453133dcce9bd98da9878ff74c6a6ae2b40dd06c1d8a963ad52aef1b26f73e9c57fd52286f2bc6ce8df8781d3c4c68912a05deaf4ef510089374b5a3ea63672190ae97c9a0c79dbd339b36ca5abfece9fbcffc1a6564735f8e5b7ea9ee50b7aa3feee252816e206a7ce1ba545a90f74a20711c831a4554a7c53288733fecbbbf9f48d272d6b65926e6491c7204b34f76048735d6256dc1a9ed16a62193ef707a785456133801b11691fdd576103235c6ba2978ab05ae19878ccadc36f9574c97ce3a5bc3aab4ed3070dbb7ebfae002d7ea4c48794deab0502b6dbe03c1a49ee52728fd3ec92389993e7464e8d8040e60b211d75bcec5adb4a19ca20af1f2232c652fc25159e12e858f3d07f08910093953401a8f70c11236df7992bc2e113e51b20b22a2296639fa6133b6015f802d66852bb2b4b698f1e8a81a76e67687d0b8508a371a3cfb18254265d57413dd9aaae3742eaa265f3456bf9dbdfb08fdf6b477a6a10fdad90e7a3355697aec35bf22a8f84b655ed7fb307d0489142c045faaa914e81c608e59c6f88b82749d9567c46aca74b4e1978b741a44795d277cf7243127e1597f2e5a3ae676b42c162909e2acf12f010fb756d886355f41a24888a64d5dd10af3515f3001e6911908bc84e293c988afbdabb7d440a2ec3de96ec06b56b4b9701e95e5ca10b6589c2733c81269da2cfc17b3d47fa89dd30503200099ee675147c9e6f97da5e3a7856a4decc4b8c165c4ef804f41c533835ac27e46741496675a2431086b71971f0d40370dbbb119242adaf4e729ddf8d1e04b69a669486aff6a0ee039a66c9961c66e0d6d5f78f3a1fff5432c41265936aea1995776862f892861c937f5904d376a339dbf99a02cc9cff84c27f206c5afe488c953a574c797e99f22b5c917e5fd1a90f3c17a4868d0688696a13dc911ff02f1ad4b6203e9d92f77bbe78470dca7c72009d61b3df1e7871b60921a0d54a6ebcaa148260672a3aedff2f9764f8197d9a0b6c934cceb6820a41476eb1b6a9110af53bb182dbf95046145f6bdf102b1cfa86a5afa8b08e603fc927f0460fa9563545c88d7ca5916dfdb5c9b6c767d520679e66bf673ec64502185615b13d9a131fa4651e5c8b40eaa278c771c4fef3acc35ef76d167f79eb68279911984ac9da9e54eb431dd2340ca6c72e04c2da65412db02aaa3246250c507eb8ff42c1d25b629f9340317ce8b71eee0aa0c015b2b905cfa739bcb9db63c6779cbf2a576a132b4028bf070686f89adfaa5ca91fade9b6f6b4df65a63848c502d2d24b94201e4713ecd2aafce1b7eb28ae4f96ab46476eefc5392d6ba2fe7220eb3458363b121c138d122a188c3dc60454f7ef6fbe7479cf56d1a20347d7960a7330ee392fbb02e0d5b59f7881035d8439568b8f438c0d91f38b1467eb4194f28f7a1558882f831aa7bf0679b0059c10180c66abaff9d238887a05ff23493cb18235efb163adc0a06a2c8099bbda391161ad30f52ab2c7627ab44e1ec88fcbfa08277e4418a7a2286601e56877d6269595c4885c64ea809e9c121caa5532d4aaeadb9e9e6651be49f25470bb0dee83448cd59ad75f4cdcdf2d6c3346d6065ca27b286622eb28fee3ce4399894dfbd1846725fad67fa2b818870e0aad72f9499e1fc776431e6fa6a6858f5c6f1f0b56126e8f912a126053d445f27429a596842da82b1c3b8308ffab9ca5d5c88a2d39b0f44968b0ab67222c6b93f8cafda69183c62918e96bd5d949173c140d1f7d0d256ab50c9fcdc61c725a4a1e1f4639c8363ea53abc87a8b8696a1b8dfd51814f19a6bbc18f5c567ee8d89e0a85879c50fc1ac149cba1e9453d5d262d272c3a76a0e254872e1f54e8fa6da6c8d2220605305dc398214609f1e31edd55c8185c46fc00880f28beba2b50b042b26b20d8fd7f26fd662142b0440addcbd3a64e6ee99bb583676f96927d779481a0647ae6a8cc059d35daea794868326bdb485de1940b2a0c5b90489666a5ad85e2a4c336c730d0cc6280111fd237f90c67e4f6815889ffd803bd9cce441ac59e2aadd6e546f9ac17507798d056b2a421d381866b954c30d33a932a629b67e2745913efa188f9bbce163bb69ed44d12c9167c406883793d6e073e31f74637aa4a17c5c1e67bc663294b8f573ebade9b593b1f720c74cc001f07f29d1168caf61ed84f913f70cfa5c6ebbade99e2d4a5a9b2a872a1b1fc75c65337ddb01ea09c027bb0ab8c5bb00cfe363edbbcaaccd3b997cf926dd2ccdc64d98cdaa4389d8e3c46a789810929302c1e8d10c233932e1144928018bde47eaef06a82746533c7a4b9f1b8253c9bdc89e63f7feb3bc7ccc9aee795df2fafc139fc21ea9013ba3a3c248747fa68bb7210b8557073f3fd7cfbcb3a57eab551aead27af9f716c1d528efcf4723c5755ddd767ba5543f9a7b1c112d10174ee53670c3efa51b94b73a0922dd298c2ae4bc7585bafc8404413f0042165cdf82fc68e9466646ef85d2a9b52bf523fe8094b7dd275c84288aa10f6fe14c5dd5f3e8b2e30e2f182083b5a1f4b0072bb58e0004fb9868578a1e1fcb8be370bfec6c5b2d0318eef1e9bb50ab89fd834ab0e625af5527a5e6f82f8a3a405eff949692ed2338cb902ca715293b77dadec10b53bf024f432daa9e080dd7f2810c25b850e8c2e0b405d1375275fa5e832390fdc7373e6977f682b358897fdf88ccd4f323356b80cc556eba9346d54c0472b377c06d453348058467141f388a523f6ee723496005e37bbb98d321df49a1884bc3561c19198cc35f2ff429ea6efe3161f569f92e1da035ff641f28c04a0a8052136df82f8b0447529ae3e27f8a58912e545514146409666760f5425a3225a4c26c143794808a9cba3f10821c3a9a6a419e06c57f5a6dff47370620808ab3cfdb8f2aeaa4c2eeb90405d1ac832bcc1a55bbffa814c3471d27765a5ed6edb3566edd96e20e6f108402df41b49faf48b75484ce9d37936b2f26672e80731901740049f18de88bd5eb2f58dc4afdd7a8f9198992edbed64c2602373c57e2c06bfddc03177ac292e562cbab5e054acd21318a4a10a4805330476c9099e3d7660d79a3b2b8be3c14d05fe246eb1c9964761289d097f71472a6beaa0127023697956632f8ba77250559a15ce9e7f270e6eb1edb62586cfc31cd4fcbed345891201cb9f2834761f84bd88f6ab147e6b3f1ff90139f9c6c4fcca9dca67f6f4474b102eb1d4765f13ddda3746d54e44bdd32806a9a8a179baf0f8d75593777e79ad9eb9a370db4ce21cf5fc496d6e521ddd7f2e86d2fce6bcd92f1dd8028592154f1a8734fedac7795d4c039d5ebd66d4ac8475a137ed935f20c7fad6ec11db1f86058949a36165489f84d9cda1b1bc1d4e247187d32e953e61716bb585c1d0454f7b965292fae8b22536dd70cab60356d1dbd744f7011c840ea57f5b80a17340138bbef39b38a34631fcb4ae8d262656ab1557b3d74e09da980adc68b54c5eb56ba9716374b1522367425691f578ca5d4cfdf22220b7694610d9eff4fad493158fdef22d1c936252b49153004e8c5ae8b53fc55dfc7aee6769d559dc6d0a439d4d709b116e3abb4ead94bc8cda7b0bd12c0a96a151ff242377453f06983beb82d144028101cfc7cb7b12abe9a1ce9de7f714f1c7c24357c98d11145b5a768f01b6e6f2bfa3da6a825728ec4d1186fb56378be287c83bb728ac1f2e844241a0d5cc98b9aab6996b7ecc14b7b499624b294b767111b76681e3bd0002113c7e3206caed1bbaadf9f536c32c97ba20607bd2711ce7fad2a83149529b060620ac3c8be317fcc60c721d23665f16c9e7eb87b8e591da318ca5d60a8cd6c7acc1d3c2d7a06e4483f0186f62e2ba305649189c5e53605892ca44ea79e249bc821f3e82e1c1583e7aadb19f0c574c2e138adaa6efbd425980613fbab36ff49733b6179e15246bc89971830913c0c225e6fd33bab45f351768e60d9016b5dbe6c9f4cce77d160878dc2a27e19edca99840bc821a66df08234e37b482e1cae6644af512098d2495c11ecb228a57c43ec86768f732eaa843d810a0faa286e1fbe63bdc46bf9e852e349d15c0a170c8fffabd3dc7839f6a8190b7184ec66bf453b4eb894885d61e9e21438073e1729f784790935607c7cfded186c2a6b134916d591421f72aef18288cd68f97f0998c659a81d73526766309ac0300415da7b642dfe8ba7e3c9c37af67b4893f119f69985e1e16f4bfc24a1dbb04462575658584d7a752252839e0787f818f41901f5080e1d52f35e165003d5c0f8281cca9a45dc44769f5665d33df75ff7ed753aecec1308e456ddfee4dfb559bb6fb36cfa647b5777228cee24821962f8350ed090a538f12a50724188e273c645315f4da6267f040104edf9029bbb4da1884407f8437f5d1665d870885f1bfcc6b28d3f367465ef32dae8fdb43ffbdeaee77e4193482563fcd3d841e2003850e5a4adfab4a1dab93d42a9d707cc91f5b78382bd068555baee3664a461831989b94c420c1bfc0b53e8e4a1b26a67764ff9d721bd676265bfd2d76548d3ee2aff5fa8c6f28673111195dd8108568c5baeb5928123cc3c1b07c07cfdfb5d1b71a90bc96b083b75ada40678238949c508ba6ce3af28e601b3ff5c087f63876b575fd2eb7323053775f5487a6dabf336946eda37230d3afe6a75e16af37a9193bf5ed51d5efbe577c4527d4cf0d0b8fa8a5f15c3a0c86b2984c2fa556522afdc5cf3989be38b3f1489a775cc80126f4d1a8441834285954db30d2035e886940aa2254c6a7fa3587c874574b47e8979ae0986eb3088e01a1a670b2d7b5f7f042960fea80d5a4b7db00cdcb715765d11897aac6584687657e883a35e36f6bb2e461ef2ffbb4694e11a41c08e8059b623f10c48f63c62fb5a371680dbcbaefc2f43d32e52de3db301729a1b604cf905eaf28e369efd2b04c8a6bb11d60be37de8897e2fd350db4d073e1e0ecdc8d430eadbcce1c2f9483546647d3dbd75abeb905506182853505c63ed3e3fc8bb6c544a55ec2358f987e91434db7b3b17e514d2f48f7319c7ef30eff72cab9a0852645eadbe45f34bd141f5de7b6dd367854ba7fd6658e0ab2ee66dd20f2bbf921f3cc5a0563ec062df41b6c9a4aadd81c262a9683ed1f5beed2cb04acb8ed18581103daeee290630e04d67226f6ac86d5c680cd7cf4c79256d383aad62adb72a01eec6d9f098d5ce17185b645b64c52293358623fcb8c77479dceacd1f35821b2e43b825223eadade6c6fb97aa9226edb450e9c188133f2b5ab21b3600f488f34a18db510c4fb0c894345fc280833c53bb2bcc559bc70effc2b5eca18b6d2a609fba4f8f44f77c93b8ef7d642011a633d790ec454d67642a944ad1d2aa5e96bc51819452dbfd7177f3dd9e1579be6ac226caa88435614d0c29b519def4c5f36f85425bdaf8dbf6e858cd02aca16c6c9d82a0f18c5090080164047f2e975e9ffeac708d3a2b8be97695b2736897676ed49b9dfda9c890da00b0cb6da8a832264cdb48d8779e719246a6a830fd4033094135fd6b9e636240a4e0349526f4536b5bd4b736cdfcd46a88de2344fa8db7a39fceb5b724a9376f7e51aa417f1a10baf63cf530a4e759c4be80b251ee82cb392bbd7183039d952a0d4d1ed64f506d9efe23b37f970187481518b39553343e89b89c2f6dcce66804b8d45e1d55ec1dc36cc679e462ef0170344a83a53bc23044a873d608da8320ac65e235db368ec238efc73a0203508252577fec225b42f66ed7935d065051184cc0371494b774893d57f30bcfbd03c7ab000091123fb60fa23dc7977917000d8e9ddab549cbf957485e17c342807ad67edd3919d1d5c4c847c8eb7c6fb1b6b756bbcaac63bd1cdc9f8d96cc9f91fdca6af5f66e6ddb2355d6387d4229529bedffda6fe0a77c0907cdfcf445c8c720eff421ee021081d34d0b73b54b3d84781a1ada9dc628a4b59f6253f1a3cff7e82c31014abdfb9015711302df5363c688e3232679cfe23c0b273f68c0e161f6548b405e8177ccef5ee92b215d98cc128ec7997bc8f7197c143accb3c720c1f4ed2e331130e4a70df1d89d4ac6bfc50c642cc8cc1b05040cae31594015470b104163e85a9f519ec28427b47a3a8a0b92dac1276436acbb54bac573e9b83af6955baa5e254871e2e681ac5f42219834da9a5411d59f497c6df3a89b46399e8060121f44b73ac189060dcfdc7e66f426462aeb94eb0d7a16135d140ece4e04fab9f317cd83c2da92777bb26d75957c8d170caff2d1572dee417551be25c2b0446cb6bbccead36a25e3a2f523bc9b6fe3537b3fe0aa0918ff2e90d41ab5d8203c9701bc04cc8b426fbb2b25601df442b472e6b5d3c2dde368e1329c36b3915b82af2137dbe48a5ab8cf13af4b255dbd31ea11473575a63c08ff3d36ed69a0982b7e2faf71b27cc091d7944b25c30144c6f1e98e0ff646ca67f3c1eab89ff4d3cfbdcf15e475bdc50b64f802fd83ffc56f99177e399c256d93b6fe616073e922ccea2b52f01db24cf9a25027550a18797dd34c98ab8b8392c4552de764709256efaf78ad4b8bfc02b1a584fd52817f2c16f6d26828f8fe32f5863cd938c5d2c7cab425f6c614225dbc671e97634e210c017fa39c3f630c22a6c1ac6673903e55c2f09c09aad4dabb76072ce6ae8beaf03e48c627465dda54afd436d47f007c5b1c7b52cf55830d6a3dbcd561bac52be9e131182f46854ba40f55c86c7935413f3c9ebaed553f9b9fafb964f0c5a03ee454b8a21bcef78881b1dcd9e4f0944f5e0dee6770f7d32e058739d6a63eb6e264ada03dc9a30d0b1db52bb8d96dc1f7c6265fd93ec0da79c5898fbf9ebb3dc1bb2ffe8ad5eb8ab90e70f448d5fe3fad48c56d1bfcd93dd5b11f413eaeb15c0056ce58e6652cffa6da783774a82e27db165d9d836346f72747d8c8d85f9487e22f9fdd22afb05e33f35a5cf7168954bcfb11617d30de40fa8ad3c2f8f52d1728c2fcf55f6d1ebbd74086b553b14dd513b6350e3a768b8678ca52b18189a5b85564134db150477a016b7824e73e59449451b33fddc3fca5183dc7d9a198d69544c402d09a96e837c02247e4a6130d6eed2a9f2b30c3f738c35d70c85248c3b057359ed5ea1cd52b3d75eb9d54174e6a28ee2c6111a86baa9775f96a245abd0122b84590b748d11e36778668804478853cc95a6b177be3e89ad0d4dd55cf07353cb8977d3bd98060e117840d167f0db84d406970401cb2938b18074c16b36f9fd560d2658a28f3aee83ffb01f39fd96972dbcddd32018d34891143f8288664e979993eba480034fdab02115f30ad476c5814c52236c0351dce3f0dadbe16ad102d558e58e46f4de316d601f1eb8559fd6e7fa0da2edaa56f5a01fe1666e4700cbc5dc1ef9f7674f1fa53a82de533f9084a762ef55562b17634c10f12f1430c0c7be8aa9798546cd20c5eff8408a3cb350afaddd7ee636cd8ec151e393db773f5bbd9e176a34373d86ef942dd0d79b9e271371ed04fc6bee281bbcbc2cb0964bfde1e396a4c18625e8e24c29951cbdc14718e6d5109b0c08565d7735b9bca70a223539dda13c5e09eedc6ac0cfbf99a4807070785cf8dcebbab95d7a05ef72583571f7cf3444111c2d7cf6631862d9975944aad75d7121705fae35559fcc29c10be0ef7945100115b9f3c54195f6ba9878e79c64132a7fe77767413faf8cbbecf2ff69e85ec340b5692343cbd35c12b18aabc308b5d49214f95c8abe9237658b6f43919438f0789c7154d639c21103181eb034aea16574d9b6b961ebaa798d75ac2904f37e5a683dbb687f10e0818620bbadd332c64b26e0a1f4c6f64cfe00b35e9c5c8265032b1bb6ba5b13d924d0d200a10249cf5b69919d56f2f8ee7d0400c4ebf7153181646511f2519b3bca740aec21d724ced7aa4b820ab901cdfea9c89112d9e50021c63c6707ad027f5ca0be19cb4de574ebbafd938b3e9570d8be400d97da0ee86ba610153c7075ffa8b175ef3946454d98d904b82ce7ca96ff4cbac78721ac8c31f05fbb8e42c55b32556888450385e3540e73d58af2f6078582f2e941d213a237de856139ef5954f8af94fa85a9ece6f4b649d63fb0284a9c4fd576ad72a86371c8e8b2f43c27ce93027d0c7593926a6d69e87ea5795b61888c1aa80f605d1ba68fb1af27697f8a409f800b9405fc44a2b70c283d640d237b73b444da8326e7171c2f699e87c63a02d79cc10e62da48ed2f97597ab3c57c2944b11186e1df36974cc03a7c87606755b499406d36a35de4966e5a983e8cf04168af815d21fe1af84864fdbc6fc0b1a881b7f266d8cf96c7b67bd124bb3c785236d119466f2ff51edef931037f4fda1951cc8518579c4fd97d9e6e43c8848d5ec133e47a9aa5bc6f49295e63884fcb22e77fc54e4941241b888a31aa59e107b714f37d474deb8b9a62bd3a6e3867e6b8a972ffcbdd03d0c48345a50b025da83de2dd8136643c674915030edcdde1db0742a3f69d8dcbe5f87362de6cad7bb3b395799a1c98d7ab4b909d19699256f2e028fa054ce49aa8645a150c2dcf0ebbabd87f87c14285b7475ea9fb1a2b772092d94e4a2332122b14c958c48dc2d147d4f797e5cbb1ade04c953f37555803900b7091ad9c274db66dba1ad056534beb09ff8030ec81d88848d7089d787aaaf897a74f9f91692557e5b306cbc359b986356bdfe5682a624c554dc42f3e521c76711beaa01733ba252670a55910720d4e62e0d294f49c7a5be941ab31619b07f28784a8196105c38585c29fbdfdf32b29c9dff18edb10cd5d176199bbec3d9c4b2eb6a5ee2867b255ad92ba3774d2356ce55e4ffee3c5cf8fceed59dda03fa9cda4bd1fc8f7005e2d9b67b2b729af552856a2d69a43380d8e3582bf5a0844ad15b75115a79b3c343c898164ca54480b7c4111b33949585bd30e2e660344012ad27a9e85fdf6ce509e07ea1ad1d81816db8e485d029101155c57641e2839a65c77e5eb43ccd16f81f626bd74c084bacde9e7716266b39a463ab4a1f2055fbdc00c20ea10db76139a5b90e106bfa4a51f41d475c303d094b6aa0303775b834388fee4d6677e18deecb5eaf8c3d591d3cb4c956ae34c7c60fe071f5d3f19cab9a59dd9423c6e88af1fa1223501da07cc214b18724ec1c587951ba0b1dc970bda7dc0ef804fdefebadee0965e023312ab274d01ff551753dc0b7afc85e10b68a9f56428cc2267fab541213b3fbf509cab4daefa4c984e8b1480724e2e399e42086c67fecda7789d5c380e0f257e6e475c63c832aa4b17c31f83ba5d7ca5db9fdc57d4dbc9e8affaad3b65d1b3c4bf0b75df9f602ac32d1ea696219afb6952a294f4b540cce84a33242e065c609afa4e97d83aed8fbc70e410bb4ac1e64656c713f72378bfbae088c13d3e8e1fadbd2f5cfa1718d26c9376cb66449aecd642d476cdd411ab79511ea6608cfc1686b83d4ea4a0f8f197a759b62753860ab0c47b8caa719338d29ee89c6953ed4beebf5685b8b2ba9eb59fcefa66329670c5fe2ca4435c41b5ec4bddd9a69aa5727f8c7026cc337e7f5ea2b85d3e6eadf65d1da59921e9601684cbd6db98176793a8a778e4f97171b0a271463c772de46a0436964b32a57a00ff7e9b78ca13c743767b460bedf3a1d701196e2a87424a7fcdfaf115afcf9476b7992addc11bf5dd4485153818ddfe711c3fc14fb30aa9336100044e5a37d30d6d246459a6c6c38a28b0ee36c5f4ded811a115f23d4853e71cfbc48617fc8d469baeafc65234b2284f93d2a41953de6549f9c41b571867bbb6ff418332d3cbcc109f85d59203bc4d222a70ef70373f65e9cf0780289af7a3d8d168265f3864c5d2e933bacfa2424be11948b89596109584ca6e8ee0144c3d99a82cfab8846844f118601ab906b0b44730d79c9169db3822060b3fe635b51c060ba336c774dd1a5612319c004cd5a626743a468607a7cce9fd29ece8b85e868444b17ce733e80d2eae2e43585ed707a50ce1b2a2173dceff5f35b4dfeb79a69e18ae83d3f8445f0dd7f896096bd7e10383a59f95db4cd85ed6e54ca1cf899e13cd8fcf8d894fdde52f8598fb1581db8f2da9bd57d644127db11aec8803135259c6cad21a3a8cb51b86f5832f74d2d7da4c00ad6e04975e7986d4d7f5182ad6ac51225ea5bf595012f4da7a714ff27a654cbc5614843c848aaa8d1e71be240742e0225408d964430303d332924cf588f4c0bfb75f32c2907095476f00465ce5377a0864ea08f2916a2194b915e61d9829ba0af574d7d8d4fc61be6557c49d9b1893796a674dcd4a2d0ab1540da21721f9ba2889d40d11d15a03f47fb9b4758fb5d396fc3ef09dd2eb17340651bbd4d4d302171b64a5d134a14c2f5761d69baf6e087645f1569ae3c9430bd62569a771c3c9d386357852630d14d59bccaae73e88e79fd335da885dbc26e317a560e886b46237a9bf974c90f17e8d1a3193eb8f6a8a4085fe6afcfc6625155f230cf95e28b02b2aa25a07dd2b9402a7e11a026050b95f200b7f559706d39de6ea5c6a3290939e06c2dca3293634d1380cbea8776653dcd705517ec2d729f81f6402d57a065a801fad2f4c318f858e12657835c6477ac3168ca4094abd3e684a49eecb3f72361e2950d32c7279a81d3d6a36479bb03f1ac6bfca0e129b096f3fc11b1a31322a3603bdbcf5f25ef6983aabfde61dbbfb31aebf6a6438c0de64b0fb58146993c8339ed1575816a6db7850ad758ee3d1b493442e12deb80ae936380c081a69dfbe7b86cbb28d5c225733e9c7e7674418cc7696f6bc482688210a51cea3c76ba11c21c21d75191c1f92f2834c1a9f9c6d1be9ad98508e7b4876621c126d0a3b9432e15f6aef3241bebfc3cb8f2dab4b96f97a61ee2e7312845d3614d817793f6c40190d7b17ef2b7bfc8ce665fc927dfd178722fa98d37e58d5c3ea763893f1f46390b9e412bb7b986e6f26e6b4998a7b7252bee2a919d92a4f63bcbccf52f7a4236cac4964dce74ba8572e8481de412bb53a0ec1667d3f64526bce5b1d39b5a49449f20a6d274d55e60b0c722a8c3606a1aed9a73738d634bd51a4b4be81283351fabfe38d8bc07b96495b56be9c69adf49958224936770455c97be2e895476df55af2d69e308a5b1f898d2d60896055b8f95f99cda6c961be77245025b3aae7411644fea5d5ed7c0f9fb6a9d48af4287b4be060236cee349ec67d4e94f6da473e30d4d406d95c62c1e7814aafe12b62e4ebfa9b4421b156a67e6743bb98d4bd17da6eec1e5a6591e5b6215675d6704257ca0cd1f71717e12fb61f365c8309df3e3e7646cf2ca5bf8fbb0e602e769c5510b11bbf114744ee38b80e0200a059a64daa7b699ea04851f976a7ac131cc0e2da1375524def3476375b4c4fc0e8e9e114f8873394b2ae418d4bff3bb202b523d2b7c897bbbac4f2af74dd5887ca6f5bfdc6a379332dd8f0a6a3b5792c1f1921642c1498dc23802f39f4e43e8f51f3415daa93f1985ad00c9e8768cad571d2016f57b05337882a38ad9f4470d205b1eb895de995fe90369bf0b6c0d73c5923465938cf6750d0a46ef63875d8eb0958c48459bae7ed3d0e6f1a4ff0c876e86f23f199e98d6fc6810cc76de5161e8c5d2e502ef34cdae2115a05ce7760248fbf9d29f89d80de97a7c4ce37d6999ed4c65057c55aa5b6295e0897474a4abd86b58a630b5519e24a96a9c36481adf71efc31aec6227002d4c5671641c259859e515e84034740a8fa2decd0cf594aca7cde73ea9f6beecbfbdac88cac419f91c685e36f599e7419d1b68ee540daf765f2281a336d8d5994334420ccf21ac60cde19a49d0df073a40445ecdd194aecde7a0c42d2d896a031477712bf49b2967b5d1a24f133bb7553be28f71887bbc6f8b53795a1b06c323fab7840c85c24e06f6df3f449c39f7f4cfbc5e74ab0b6f54dd85d46be27789f44508d7a4e0294ddb7a972022adef1feb4bbf80b6acb41388b29f99d86196551e89be73d3fda6fbd1cca14dcc0044a97c9e1430600238a4ed27cb144440da1d6273ec8750b8d8035c7924a123c47777a396502a8ab6b7b98c93fe28a08d8377a606e099c8ad9f42dcac63554b356a129a9e9573fcfb207b27baa436c6d4ddb4f8580d914a1263461e304db5e0815f7dd9b755db529032597b77050aa6c653afe3f7d7eac9e3df2d52b926639aa3f51d8cd5471da36ecf408bd859ce900e439901bd20c3c1bf000f6e62cd234e5fa295118a5b5f55100702fdafd43a7398894f4a3dd4f74889d27294143d5f3609d97ac3323c6f3d6ecbe990dcb5d975358f54153f286e78c8cfbc76cf3e2540614252d267ac9327d13fde8abc4b282014be61a11450aa26626c478ccab01c380f39cea9dc5d67501ab68b06bdcd6440d7ece6f784539530afbb27edb7b1a83bf6576ec304ad3538edd4a02e1fe9ff821eda6d9c8f6eb4ebad0d80fc45576ab4426f0b390ce9fb42312c23430d040d85efa8cde8e1a3c47a082d33cbea897edf90b00820032156816c8cc1218b9cbc41108f910a9a072afb6d94c20b5daa083a8c6f1e49570a82b779b06e91e01eeec67ad5fcc586401c91030a8300014a92973e2b4653816cfd1866ebe6a07b7b9050176f3f0fd7deb7094b96dca67a7fab85f80275b5616414ba3d11bed295420cb62860d5a01fe557eba85cab0dfbdd4ed1d7f30cdc0540690d7bfc99ff1e5915e91fd99a5b94d2d26eaabe72c2e727cb88748e83899ee6f2f6efac8eb7d66b7578fa17671b4b70ebdf40a36ec697ece2a6d2b170bd083c0efd515b81acdf56c750064571d635ad50165f1e98519b12655820ef9393b33d71e037d8ae46f6e9ac84b732b21008111b16796ea62181f264aaa19c362b426516c97bbdbbf0b0da0e47f805847067261b62d7d699124645c6a6a983565815e6de4fbc31263380b6dc811fa9d4c1ed15690b2dc7c1afa5a4a810ee69bb8759c898287630273ba24ee35f314790e09d865d2e82dcacb1ed2ef7614e2bd9aaaf2c7b1fd1cac6b3b56058d33a13e5d998b5cec54b5968271a32ce79f80118678f2978011bbaa86de2c5579e966ae17c6dd435279303fcb2d1cfdffafded27c921d1feea042f83e96f01bff7fc98215044eff87f28e65559c9b030a0676eac25552b5961084f162e8bb638d52c81b091ddbdaaf684c6f1cce30ff4c8c60f55148aed8bc5894c22114a2f37c483bd9d9eb809a483f918cd901f9c48251f8dcb19f35d61bf1105ec96e66f22601575a5abeedfd08dc5ec6669790c3b47e557d391adfb259ee0c86566ea1c4a93ad18003cb35a752e91df73a688cd65b92b754071ce3f6328f76c6d6f455eae1c4cd80e2b05cc183e1dadcd83deab48dcf62d191e0f69e1ea30f050b80640b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c645236986f1affba9e034017145436f7519e5681fa5b9940890979fb54be43bbf05d958cdf22beffeb2bb7ecfb3dcaf8a0ae07601a0fc97d4d7bc9a7dc9c8221005d958cdf22beffeb2bb7ecfb3dcaf8a0ae07601a0fc97d4d7bc9a7dc9c822103edab1ff7eb6bf33f108e9ac1a08eb16c954b88a844e3119adf5950b44014eb611cb6f5cf19bc18ac0560bff08c21e5a715d9e488ed7b90715ddbb518fd57060e234489f88176e66bd858291d9de7054c6bdcedbb9f19ebedfab02d238b3dad79ac6a853e324ff7c5e92f5e9bbbfcda63466ec3e8a17fd9b3247f183465e93ca372fd5afc77f0d7f38658bb86153e8c7472376a5d735412237aea47881eb714ad1ffba188101427d74509d8786310f1e0793a251f31819283664626cbb6286bcdd109bc3de5bef59a8492c6f849e7cf1c2a665d6b5844e749d36a714fc4eb8f652fe79b889ef808d2d515a143bd50327674d18780056158238e627e37eaf784b4505976a7c3561f4c11d3d6507b4c18b802110be70e1266ecd65aa25fca9510137f5d6822f4308c7525d307bc5aa18c4a8cd6450e22a5d3ff8ec4fd0e0db96029b188fe909be6889a961ab6d53b11520bc8ef965b7387b554bd7c482b02b0f4f80d00110a008aff7aed1c6d66dfb2edfa2605d155c2d97a1c2877fd1bf4d770e6708988dc83ba66d6a40a20293dfee564ed40c41d5e541c2997e512019841b0b19fb878199014dea84874d11e319609135d4251944a93718a1549871f86355fe0d12397a1e4e4db62d46514798e653a11b107fa6d6cbd7c1d4a8795f849809cbf723c6b3654d1ff2ac20fe4e91db0ffb8387d06864cabae9e45d13b197ef3dcccc6b0296da09999c1156c66710e48fad121d7a7eb3f20a9281c83c7715e7f759dd2b11d8da24b078973a81d23f56a3cd370391c47ad7ea923f5233254b2c62a41ea39a3c45f364074338dbc792fc2c11e46cd8506f84eec2d00b8b7cd076d84a54a4e74dfb2af63dad0b61ff21f4f95994201c284fe8f586948c544ff57e966e81d01c4e3d56cb060111b09771b67ad0ce7c76f75907623f84b05a05d45611f5bc55eab02c151e601843afc2885ab9824b294c7d32e6352066793e8ccf6663071d70e16fed8696139a12f8dc737261cc47235f1f6043d92c85ee5f87b03e8429e9657bb9f64a21db6c7e0cca7c1f3ff6a65af73bbecb35b1a93de7ddc539df9a5eb5dc9143c8d61b9b80d5cf522b829938f539a301cd22e79e52f6213df15534953e17076aff00521a5402e73915fd843905ff5a92e6db5564e3ddd38febf2dc5e8b6c7840d556c9d7eed953dea0cf43b01fecc45edfa2a8e9b2cfb89d9914c4b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c6df6010f421b495d8f08d34e5855353addd29d9dfce3d14618ababcf1211fb906@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootselinux-policy-3.13.1-229.el7.src.rpmselinux-policy-devel       /bin/sh/usr/bin/makecheckpolicym4policycoreutils-develrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)selinux-policyrpmlib(PayloadIsXz)2.5-82.5-243.0.4-14.6.0-14.0.4-14.0-13.13.1-229.el75.2-14.11.3[t[#@[@[@[[h@[[[9@[@[}P@[{[{[z@[m~@[i[i[i[dC[`O@[]@[Y[6@[3|@[2*["X[d@[[ [ L@[[[@[ZmZȲZZH@Z@ZZz@Zz@ZyZ_:ZWQZV@Z.s@Z)-@Z%8ZZ @ZZNZNYYA@YYW@YW@YYY@Y@Ycl@YP@YJ_YI@YBvY9<@Y6@Y5GY1S@Y0Y.@Y-^Y, @Y, @Y%uYYY@Y@Y@Y.YXQ@XXX@X@X@XXX@XۡXP@XXg@Xg@X~@X@XƉXCXCXX @XXXBXXXs{@XY@XWXRXRXOXJXAb@X@X)@X#X!@XWWSW_@W_@Wv@W;W@WίWW:WQW@WW@W@WW~W@WW~D@W{@Ws@WrfWj}WbW^@WYZ@WYZ@WUeWM|WBW9@W9@W1@W(W V@V@V@V޾V2V@V_VVCV@VZV @VqV }@V }@VBUUU@U@UpUUUUoUoU5@UUȒ@UĝUUWUU@UUK@UUU'Ua@U~@UzUv@UT@U@Tr@T@T@T7TTTC@T@TTT}Tto@TsTk4T`T[bTWn@T?@T>aT6xT6xT@S@SSDSg}@SB@S>S;S:@S9XS5d@S4S2@S0@S,)S*@S)S)S&S&S"@S!S L@SSS@SSc@SSnS @S SK@RRR@RRJ@Ra@RRR&R&RRR=RʚRR@R@R@Rv@Rv@R@RR@R R@R@R|@Rz/@Rz/@RsRpRnQRi RfhR_@R_@R[R[RSRNRNRL RIgRB@RB@R:@R1R-@R-@R(r@R' R%@R7RRNRR@Q@QQdQQ@QQޞ@Q@QکQکQ@QzQQ4Q@@Q@QKQQ@Q@Q@Q@QQ@QQQQ@Q@QQQ@Qzl@Qw@QvwQo@Qo@QnQm=@QkQfQb@Q`@Q^QZ@QQQIQGQ@j@Q9Q8@Q4Q0@Q-@Q& @Q$QQ@QQ@Q @Qh@QsPP@P@PP@P[PP!@P8@PO@P @Pf@PPqP @PP7@P@PPPYP@P@PPPM@PPd@P@PoP{@P{@P@PP5@P@P~P}L@Px@PvPvPuc@Puc@Pr@Pmz@Pmz@Pmz@Pj@Pd?Pd?Pb@PaPaP[@PXb@PWPS@PQPO'PM@PIP@@P>@P8@P7lP2&P2&P,P,P*=P(@P#@P#@P!@P!@P@PkPw@Pw@PP

@NNU@NNl@N@N@NåN@NNNN@NNN@N@NGNGNGN@N@NNS@NS@N^N^N @N @NNj@Nj@NN$@NN@N/N@N@NFNFN@NNN@N@N@N]Ni@Ni@Ni@N|tNyNx@Ns:@NoENoENiNf @N^"@N\N[@NTNS@NS@NC@NBrN:N98@N7N6@N2N.@N*N)f@N(N%qN$ @N@N7@N e@NpNpM@M@Md@Md@MM{@M@M۝M@M@M‘@M@M@M@My@My@M3@M@M@MMM@MMMMTMx@Mx@Mv@MlMbSM[@MRMQ0@MQ0@MJMGMGMA^@M>@M9u@M6@M5M4/@M4/@M0:M,F@M$]@M@M9MMMMM\@M M M@L!L!L@LL@L@L@LOLOL[@L@L@Lr@L L,@L,@Lډ@L7LLLNL@LΫLeL|L@LB@LB@LB@L@LMLL@LdLL{L*@L@L5LLA@LLLL@LcL@L@L@LzL)@L|L|L|L{@LvW@LvW@Ls@Ls@LrbLrbLmLk@LjyLe3Lc@La?@LZLYV@LXLN@LN@LMxLMxLI@LH2LF@LEL=L=L=L;L7@L LT@L@LL@L@L0LLGL@K^K^KKKj@K$@KKK@K@KK@K]K޺K@KtK#@KKՀ@K:@KK͗@KŮ@K\K\K @KKKKK9@KK@KK@K@KKKKrKK~@K,K,K,K@KK8@KKK@KK@KqKqK}+K{@K{@KuBKs@KqN@KjKie@Kf@Ka|@K`*K]KXAKTM@KPXKEKEKEKD{@KC)KA@K;@K2@K0K/c@K+nK*@K(K"4@KK>K>K>JJęJH@JH@JJJ_@J@JjJjJ@Jv@Jv@Jv@Jv@J$J@JJ0@J@J@JG@JG@J@JJ@J@J@JJJ#J@JJJ@J:J@JJQJ@J J J|@JzJyt@Jyt@Jx"JrJrJq@Jn@Jn@JmJhPJeJ\s@JW-@JT@JS8JKOJI@JCfJCfJB@J@J@J?r@J<@J;}J:,@J7@J67J2C@J0J/@J,@J%@JJB@JJMJ J dJ@J@JJ@J*@J*@II@IIA@IIII@I@IIIX@IX@IX@II@I@IcIIo@Io@IzI)@I@IܑI@@II@I@I@IԨIд@I̿In@I3I3I@II@I@IV@IIaIIm@I@I'@II2III@IIIIIIII@III@I1I@III~@I}Iy@Ix_Iw@IuItk@Itk@Io%@Ik0IeIcGIa@I`IVIO@IJ;@IHIAI>]I= @I7@I6tI3I-I@III9@I9@II IP@I@IIg@Ig@HHH@HrH~@H,H@HCHHH @H @Hf@Hf@H@H+H@H׈H׈H7@HBH@HǶH@HH|@HHH@H{@H)HHL@H@H@H@HnH}H|@Ht@HsVHr@Hl@HkmHgy@HcH`H_@H^>HRa@HQHQHO@HFHFH$@DX@DU@DN@DN@DLDH@DGwDGwDDD@@D?D?D;@D;@D:HD:HD2_D1@D1@D-D+@D+@D'D!<@D!<@D!<@DDD@D@D@DDDDDD@D@D@D@D uD $@D D @D @DDDFC@C@C@C@CCCCCR@CCCCC@Ci@CC@C@CtC@C@CC:@CECCC @C @CعCعCعCعCC@C-C-C-C@C@CCǖ@C@CáCáCP@CP@C[C @C @CCg@Cg@CCC!@C~@C,C@CCCCC@CC@C@C@CZCZC @C @CCCf@Cf@Cf@CC@CqCqC @C @C @CCC}@C7@C7@C7@CBCBCYC@C@CC}@CqCqLukas Vrabec - 3.13.1-229Lukas Vrabec - 3.13.1-228Lukas Vrabec - 3.13.1-227Lukas Vrabec - 3.13.1-226Lukas Vrabec - 3.13.1-225Lukas Vrabec - 3.13.1-224Lukas Vrabec - 3.13.1-223Lukas Vrabec - 3.13.1-222Lukas Vrabec - 3.13.1-221Lukas Vrabec - 3.13.1-220Lukas Vrabec - 3.13.1-219Lukas Vrabec - 3.13.1-218Lukas Vrabec - 3.13.1-217Lukas Vrabec - 3.13.1-216Lukas Vrabec - 3.13.1-215Lukas Vrabec - 3.13.1-214Lukas Vrabec - 3.13.1-213Lukas Vrabec - 3.13.1-212Lukas Vrabec - 3.13.1-211Lukas Vrabec - 3.13.1-210Lukas Vrabec - 3.13.1-209Lukas Vrabec - 3.13.1-208Lukas Vrabec - 3.13.1-207Lukas Vrabec - 3.13.1-206Lukas Vrabec - 3.13.1-205Lukas Vrabec - 3.13.1-204Lukas Vrabec - 3.13.1-203Lukas Vrabec - 3.13.1-202Lukas Vrabec - 3.13.1-201Lukas Vrabec - 3.13.1-200Lukas Vrabec - 3.13.1-199Lukas Vrabec - 3.13.1-198Lukas Vrabec - 3.13.1-197Lukas Vrabec - 3.13.1-196Lukas Vrabec - 3.13.1-195Lukas Vrabec - 3.13.1-194Lukas Vrabec - 3.13.1-193Lukas Vrabec - 3.13.1-192Lukas Vrabec - 3.13.1-191Lukas Vrabec - 3.13.1-190Lukas Vrabec - 3.13.1-189Lukas Vrabec - 3.13.1-188Lukas Vrabec - 3.13.1-187Lukas Vrabec - 3.13.1-186Lukas Vrabec - 3.13.1-185Lukas Vrabec - 3.13.1-184Lukas Vrabec - 3.13.1-183Lukas Vrabec - 3.13.1-182Lukas Vrabec - 3.13.1-181Lukas Vrabec - 3.13.1-180Lukas Vrabec - 3.13.1-179Lukas Vrabec - 3.13.1-178Lukas Vrabec - 3.13.1-177Lukas Vrabec - 3.13.1-176Lukas Vrabec - 3.13.1-175Lukas Vrabec - 3.13.1-174Lukas Vrabec - 3.13.1-173Lukas Vrabec - 3.13.1-172Lukas Vrabec - 3.13.1-171Lukas Vrabec - 3.13.1-170Lukas Vrabec - 3.13.1-169Lukas Vrabec - 3.13.1-168Lukas Vrabec - 3.13.1-167Lukas Vrabec - 3.13.1-166Lukas Vrabec - 3.13.1-165Lukas Vrabec - 3.13.1-164Lukas Vrabec - 3.13.1-163Lukas Vrabec - 3.13.1-162Lukas Vrabec - 3.13.1-161Lukas Vrabec - 3.13.1-160Lukas Vrabec - 3.13.1-159Lukas Vrabec - 3.13.1-158Lukas Vrabec - 3.13.1-157Lukas Vrabec - 3.13.1-156Lukas Vrabec - 3.13.1-155Lukas Vrabec - 3.13.1-154Lukas Vrabec - 3.13.1-153Lukas Vrabec - 3.13.1-152Lukas Vrabec - 3.13.1-151Lukas Vrabec - 3.13.1-150Lukas Vrabec - 3.13.1-149Lukas Vrabec - 3.13.1-148Lukas Vrabec - 3.13.1-147Lukas Vrabec - 3.13.1-146Lukas Vrabec - 3.13.1-145Lukas Vrabec - 3.13.1-144Lukas Vrabec - 3.13.1-143Lukas Vrabec - 3.13.1-142Lukas Vrabec - 3.13.1-141Lukas Vrabec - 3.13.1-140Lukas Vrabec - 3.13.1-139Lukas Vrabec - 3.13.1-138Lukas Vrabec - 3.13.1-137Lukas Vrabec - 3.13.1-136Lukas Vrabec - 3.13.1-135Lukas Vrabec - 3.13.1-134Lukas Vrabec - 3.13.1-133Lukas Vrabec - 3.13.1-132Lukas Vrabec - 3.13.1-131Lukas Vrabec - 3.13.1-130Lukas Vrabec - 3.13.1-129Lukas Vrabec - 3.13.1-128Lukas Vrabec - 3.13.1-127Lukas Vrabec - 3.13.1-126Lukas Vrabec - 3.13.1-125Lukas Vrabec - 3.13.1-124Lukas Vrabec - 3.13.1-123Lukas Vrabec - 3.13.1-122Lukas Vrabec - 3.13.1-120Lukas Vrabec - 3.13.1-119Lukas Vrabec - 3.13.1-118Lukas Vrabec - 3.13.1-117Lukas Vrabec - 3.13.1-116Lukas Vrabec - 3.13.1-115Lukas Vrabec - 3.13.1-114Lukas Vrabec - 3.13.1-113Lukas Vrabec - 3.13.1-112Lukas Vrabec - 3.13.1-111Lukas Vrabec - 3.13.1-110Lukas Vrabec - 3.13.1-109Lukas Vrabec - 3.13.1-108Lukas Vrabec - 3.13.1-107Lukas Vrabec - 3.13.1-106Miroslav Grepl - 3.13.1-105Lukas Vrabec - 3.13.1-104Lukas Vrabec - 3.13.1-103Dan Walsh - 3.13.1-102Lukas Vrabec - 3.13.1-101Lukas Vrabec - 3.13.1-100Lukas Vrabec - 3.13.1-99Lukas Vrabec - 3.13.1-98Lukas Vrabec - 3.13.1-97Lukas Vrabec - 3.13.1-96Lukas Vrabec - 3.13.1-95Lukas Vrabec - 3.13.1-94Lukas Vrabec - 3.13.1-93Lukas Vrabec - 3.13.1-92Lukas Vrabec - 3.13.1-91Lukas Vrabec - 3.13.1-90Lukas Vrabec - 3.13.1-89Lukas Vrabec - 3.13.1-88Lukas Vrabec - 3.13.1-87Lukas Vrabec - 3.13.1-86Lukas Vrabec - 3.13.1-85Lukas Vrabec - 3.13.1-84Lukas Vrabec - 3.13.1-83Lukas Vrabec - 3.13.1-82Lukas Vrabec - 3.13.1-81Lukas Vrabec - 3.13.1-80Petr Lautrbach - 3.13.1-79Lukas Vrabec - 3.13.1-78Lukas Vrabec - 3.13.1-77Lukas Vrabec - 3.13.1-76Lukas Vrabec - 3.13.1-75Lukas Vrabec - 3.13.1-74Lukas Vrabec - 3.13.1-73Lukas Vrabec - 3.13.1-72Lukas Vrabec - 3.13.1-71Lukas Vrabec - 3.13.1-70Lukas Vrabec - 3.13.1-69Lukas Vrabec - 3.13.1-68Lukas Vrabec - 3.13.1-67Petr Lautrbach - 3.13.1-66Lukas Vrabec 3.13.1-65Lukas Vrabec 3.13.1-64Lukas Vrabec 3.13.1-63Lukas Vrabec 3.13.1-62Lukas Vrabec 3.13.1-61Miroslav Grepl 3.13.1-60Miroslav Grepl 3.13.1-59Lukas Vrabec 3.13.1-58Lukas Vrabec 3.13.1-57Miroslav Grepl 3.13.1-56Lukas Vrabec 3.13.1-55Lukas Vrabec 3.13.1-54Lukas Vrabec 3.13.1-53Lukas Vrabec 3.13.1-52Miroslav Grepl 3.13.1-51Lukas Vrabec 3.13.1-50Lukas Vrabec 3.13.1-49Lukas Vrabec 3.13.1-48Lukas Vrabec 3.13.1-47Lukas Vrabec 3.13.1-46Lukas Vrabec 3.13.1-45Lukas Vrabec 3.13.1-44Lukas Vrabec 3.13.1-43Lukas Vrabec 3.13.1-42Lukas Vrabec 3.13.1-41Lukas Vrabec 3.13.1-40Miroslav Grepl 3.13.1-39Lukas Vrabec 3.13.1-38Lukas Vrabec 3.13.1-37Lukas Vrabec 3.13.1-36Lukas Vrabec 3.13.1-35Lukas Vrabec 3.13.1-34Lukas Vrabec 3.13.1-33Lukas Vrabec 3.13.1-32Miroslav Grepl 3.13.1-31Miroslav Grepl 3.13.1-30Miroslav Grepl 3.13.1-29Miroslav Grepl 3.13.1-28Miroslav Grepl 3.13.1-27Miroslav Grepl 3.13.1-26Miroslav Grepl 3.13.1-25Miroslav Grepl 3.13.1-24Miroslav Grepl 3.13.1-23Miroslav Grepl 3.13.1-22Miroslav Grepl 3.13.1-21Miroslav Grepl 3.13.1-20Miroslav Grepl 3.13.1-19Miroslav Grepl 3.13.1-18Miroslav Grepl 3.13.1-17Miroslav Grepl 3.13.1-16Miroslav Grepl 3.13.1-15Miroslav Grepl 3.13.1-14Miroslav Grepl 3.13.1-13Miroslav Grepl 3.13.1-12Miroslav Grepl 3.13.1-11Miroslav Grepl 3.13.1-10Miroslav Grepl 3.13.1-9Miroslav Grepl 3.13.1-8Miroslav Grepl 3.13.1-7Miroslav Grepl 3.13.1-6Miroslav Grepl 3.13.1-5Miroslav Grepl 3.13.1-4Miroslav Grepl 3.13.1-3Miroslav Grepl 3.13.1-2Miroslav Grepl 3.13.1-1Miroslav Grepl 3.12.1-156Miroslav Grepl 3.12.1-155Miroslav Grepl 3.12.1-154Miroslav Grepl 3.12.1-153Miroslav Grepl 3.12.1-152Miroslav Grepl 3.12.1-151Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-148Miroslav Grepl 3.12.1-147Miroslav Grepl 3.12.1-146Miroslav Grepl 3.12.1-145Miroslav Grepl 3.12.1-144Lukas Vrabec 3.12.1-143Miroslav Grepl 3.12.1-142Miroslav Grepl 3.12.1-141Miroslav Grepl 3.12.1-140Miroslav Grepl 3.12.1-139Lukas Vrabec 3.12.1-138Miroslav Grepl 3.12.1-137Miroslav Grepl 3.12.1-136Miroslav Grepl 3.12.1-135Miroslav Grepl 3.12.1-134Miroslav Grepl 3.12.1-133Miroslav Grepl 3.12.1-132Miroslav Grepl 3.12.1-131Miroslav Grepl 3.12.1-130Miroslav Grepl 3.12.1-129Miroslav Grepl 3.12.1-128Miroslav Grepl 3.12.1-127Miroslav Grepl 3.12.1-126Miroslav Grepl 3.12.1-125Miroslav Grepl 3.12.1-124Miroslav Grepl 3.12.1-123Miroslav Grepl 3.12.1-122Miroslav Grepl 3.12.1-121Miroslav Grepl 3.12.1-120Miroslav Grepl 3.12.1-119Miroslav Grepl 3.12.1-118Miroslav Grepl 3.12.1-117Miroslav Grepl 3.12.1-116Miroslav Grepl 3.12.1-115Miroslav Grepl 3.12.1-114Miroslav Grepl 3.12.1-113Miroslav Grepl 3.12.1-112Miroslav Grepl 3.12.1-111Miroslav Grepl 3.12.1-110Miroslav Grepl 3.12.1-109Miroslav Grepl 3.12.1-108Miroslav Grepl 3.12.1-107Dan Walsh 3.12.1-106Miroslav Grepl 3.12.1-105Miroslav Grepl 3.12.1-104Miroslav Grepl 3.12.1-103Miroslav Grepl 3.12.1-102Miroslav Grepl 3.12.1-101Miroslav Grepl 3.12.1-100Miroslav Grepl 3.12.1-99Miroslav Grepl 3.12.1-98Miroslav Grepl 3.12.1-97Miroslav Grepl 3.12.1-96Miroslav Grepl 3.12.1-95Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-93Miroslav Grepl 3.12.1-92Miroslav Grepl 3.12.1-91Miroslav Grepl 3.12.1-90Miroslav Grepl 3.12.1-89Miroslav Grepl 3.12.1-88Miroslav Grepl 3.12.1-87Miroslav Grepl 3.12.1-86Miroslav Grepl 3.12.1-85Miroslav Grepl 3.12.1-84Miroslav Grepl 3.12.1-83Miroslav Grepl 3.12.1-82Miroslav Grepl 3.12.1-81Miroslav Grepl 3.12.1-80Miroslav Grepl 3.12.1-79Miroslav Grepl 3.12.1-78Miroslav Grepl 3.12.1-77Miroslav Grepl 3.12.1-76Miroslav Grepl 3.12.1-75Miroslav Grepl 3.12.1-74Miroslav Grepl 3.12.1-73Miroslav Grepl 3.12.1-72Miroslav Grepl 3.12.1-71Miroslav Grepl 3.12.1-70Miroslav Grepl 3.12.1-69Miroslav Grepl 3.12.1-68Miroslav Grepl 3.12.1-67Miroslav Grepl 3.12.1-66Miroslav Grepl 3.12.1-65Miroslav Grepl 3.12.1-64Miroslav Grepl 3.12.1-63Miroslav Grepl 3.12.1-62Miroslav Grepl 3.12.1-61Miroslav Grepl 3.12.1-60Miroslav Grepl 3.12.1-59Miroslav Grepl 3.12.1-58Miroslav Grepl 3.12.1-57Miroslav Grepl 3.12.1-56Miroslav Grepl 3.12.1-55Miroslav Grepl 3.12.1-54Miroslav Grepl 3.12.1-53Miroslav Grepl 3.12.1-52Miroslav Grepl 3.12.1-51Miroslav Grepl 3.12.1-50Miroslav Grepl 3.12.1-49Miroslav Grepl 3.12.1-48Miroslav Grepl 3.12.1-47Miroslav Grepl 3.12.1-46Miroslav Grepl 3.12.1-45Miroslav Grepl 3.12.1-44Miroslav Grepl 3.12.1-43Miroslav Grepl 3.12.1-42Miroslav Grepl 3.12.1-41Miroslav Grepl 3.12.1-40Miroslav Grepl 3.12.1-39Miroslav Grepl 3.12.1-38Miroslav Grepl 3.12.1-37Miroslav Grepl 3.12.1-36Miroslav Grepl 3.12.1-35Miroslav Grepl 3.12.1-34Miroslav Grepl 3.12.1-33Miroslav Grepl 3.12.1-32Miroslav Grepl 3.12.1-31Miroslav Grepl 3.12.1-30Miroslav Grepl 3.12.1-29Dan Walsh 3.12.1-28Dan Walsh 3.12.1-27Miroslav Grepl 3.12.1-26Miroslav Grepl 3.12.1-25Miroslav Grepl 3.12.1-24Miroslav Grepl 3.12.1-23Miroslav Grepl 3.12.1-22Miroslav Grepl 3.12.1-21Miroslav Grepl 3.12.1-20Miroslav Grepl 3.12.1-19Miroslav Grepl 3.12.1-18Miroslav Grepl 3.12.1-17Miroslav Grepl 3.12.1-16Miroslav Grepl 3.12.1-15Miroslav Grepl 3.12.1-14Miroslav Grepl 3.12.1-13Miroslav Grepl 3.12.1-12Miroslav Grepl 3.12.1-11Miroslav Grepl 3.12.1-10Miroslav Grepl 3.12.1-9Miroslav Grepl 3.12.1-8Miroslav Grepl 3.12.1-7Miroslav Grepl 3.12.1-6Miroslav Grepl 3.12.1-5Miroslav Grepl 3.12.1-4Miroslav Grepl 3.12.1-3Miroslav Grepl 3.12.1-2Miroslav Grepl 3.12.1-1Dan Walsh 3.11.1-69.1Miroslav Grepl 3.11.1-69Miroslav Grepl 3.11.1-68Miroslav Grepl 3.11.1-67Miroslav Grepl 3.11.1-66Miroslav Grepl 3.11.1-65Miroslav Grepl 3.11.1-64Miroslav Grepl 3.11.1-63Miroslav Grepl 3.11.1-62Miroslav Grepl 3.11.1-61Miroslav Grepl 3.11.1-60Miroslav Grepl 3.11.1-59Miroslav Grepl 3.11.1-58Miroslav Grepl 3.11.1-57Miroslav Grepl 3.11.1-56Miroslav Grepl 3.11.1-55Miroslav Grepl 3.11.1-54Miroslav Grepl 3.11.1-53Miroslav Grepl 3.11.1-52Miroslav Grepl 3.11.1-51Miroslav Grepl 3.11.1-50Miroslav Grepl 3.11.1-49Miroslav Grepl 3.11.1-48Miroslav Grepl 3.11.1-47Miroslav Grepl 3.11.1-46Miroslav Grepl 3.11.1-45Miroslav Grepl 3.11.1-44Miroslav Grepl 3.11.1-43Miroslav Grepl 3.11.1-42Miroslav Grepl 3.11.1-41Miroslav Grepl 3.11.1-40Miroslav Grepl 3.11.1-39Miroslav Grepl 3.11.1-38Miroslav Grepl 3.11.1-37Miroslav Grepl 3.11.1-36Miroslav Grepl 3.11.1-35Miroslav Grepl 3.11.1-34Miroslav Grepl 3.11.1-33Miroslav Grepl 3.11.1-32Miroslav Grepl 3.11.1-31Miroslav Grepl 3.11.1-30Miroslav Grepl 3.11.1-29Miroslav Grepl 3.11.1-28Miroslav Grepl 3.11.1-27Miroslav Grepl 3.11.1-26Miroslav Grepl 3.11.1-25Miroslav Grepl 3.11.1-24Miroslav Grepl 3.11.1-23Miroslav Grepl 3.11.1-22Miroslav Grepl 3.11.1-21Miroslav Grepl 3.11.1-20Miroslav Grepl 3.11.1-19Miroslav Grepl 3.11.1-18Miroslav Grepl 3.11.1-17Miroslav Grepl 3.11.1-16Dan Walsh 3.11.1-15Miroslav Grepl 3.11.1-14Dan Walsh 3.11.1-13Miroslav Grepl 3.11.1-12Miroslav Grepl 3.11.1-11Miroslav Grepl 3.11.1-10Dan Walsh 3.11.1-9Dan Walsh 3.11.1-8Dan Walsh 3.11.1-7Dan Walsh 3.11.1-6Miroslav Grepl 3.11.1-5Miroslav Grepl 3.11.1-4Miroslav Grepl 3.11.1-3Miroslav Grepl 3.11.1-2Miroslav Grepl 3.11.1-1Miroslav Grepl 3.11.1-0Miroslav Grepl 3.11.0-15Miroslav Grepl 3.11.0-14Miroslav Grepl 3.11.0-13Miroslav Grepl 3.11.0-12Fedora Release Engineering - 3.11.0-11Miroslav Grepl 3.11.0-10Miroslav Grepl 3.11.0-9Miroslav Grepl 3.11.0-8Miroslav Grepl 3.11.0-7Miroslav Grepl 3.11.0-6Miroslav Grepl 3.11.0-5Miroslav Grepl 3.11.0-4Miroslav Grepl 3.11.0-3Miroslav Grepl 3.11.0-2Miroslav Grepl 3.11.0-1Miroslav Grepl 3.10.0-128Miroslav Grepl 3.10.0-127Miroslav Grepl 3.10.0-126Miroslav Grepl 3.10.0-125Miroslav Grepl 3.10.0-124Miroslav Grepl 3.10.0-123Miroslav Grepl 3.10.0-122Miroslav Grepl 3.10.0-121Miroslav Grepl 3.10.0-120Miroslav Grepl 3.10.0-119Miroslav Grepl 3.10.0-118Miroslav Grepl 3.10.0-117Miroslav Grepl 3.10.0-116Miroslav Grepl 3.10.0-115Miroslav Grepl 3.10.0-114Miroslav Grepl 3.10.0-113Miroslav Grepl 3.10.0-112Miroslav Grepl 3.10.0-111Miroslav Grepl 3.10.0-110Miroslav Grepl 3.10.0-109Miroslav Grepl 3.10.0-108Miroslav Grepl 3.10.0-107Miroslav Grepl 3.10.0-106Miroslav Grepl 3.10.0-105Miroslav Grepl 3.10.0-104Miroslav Grepl 3.10.0-103Miroslav Grepl 3.10.0-102Miroslav Grepl 3.10.0-101Miroslav Grepl 3.10.0-100Miroslav Grepl 3.10.0-99Miroslav Grepl 3.10.0-98Miroslav Grepl 3.10.0-97Miroslav Grepl 3.10.0-96Miroslav Grepl 3.10.0-95Miroslav Grepl 3.10.0-94Miroslav Grepl 3.10.0-93Miroslav Grepl 3.10.0-92Miroslav Grepl 3.10.0-91Miroslav Grepl 3.10.0-90Miroslav Grepl 3.10.0-89Miroslav Grepl 3.10.0-88Miroslav Grepl 3.10.0-87Miroslav Grepl 3.10.0-86Miroslav Grepl 3.10.0-85Miroslav Grepl 3.10.0-84Miroslav Grepl 3.10.0-83Miroslav Grepl 3.10.0-82Dan Walsh 3.10.0-81.2Miroslav Grepl 3.10.0-81Miroslav Grepl 3.10.0-80Miroslav Grepl 3.10.0-79Miroslav Grepl 3.10.0-78Miroslav Grepl 3.10.0-77Miroslav Grepl 3.10.0-76Miroslav Grepl 3.10.0-75Dan Walsh 3.10.0-74.2Miroslav Grepl 3.10.0-74Miroslav Grepl 3.10.0-73Miroslav Grepl 3.10.0-72Miroslav Grepl 3.10.0-71Miroslav Grepl 3.10.0-70Miroslav Grepl 3.10.0-69Miroslav Grepl 3.10.0-68Miroslav Grepl 3.10.0-67Miroslav Grepl 3.10.0-66Miroslav Grepl 3.10.0-65Miroslav Grepl 3.10.0-64Miroslav Grepl 3.10.0-63Miroslav Grepl 3.10.0-59Miroslav Grepl 3.10.0-58Dan Walsh 3.10.0-57Dan Walsh 3.10.0-56Dan Walsh 3.10.0-55.2Dan Walsh 3.10.0-55.1Miroslav Grepl 3.10.0-55Dan Walsh 3.10.0-54.1Miroslav Grepl 3.10.0-54Dan Walsh 3.10.0-53.1Miroslav Grepl 3.10.0-53Miroslav Grepl 3.10.0-52Miroslav Grepl 3.10.0-51Dan Walsh 3.10.0-50.2Dan Walsh 3.10.0-50.1Miroslav Grepl 3.10.0-50Miroslav Grepl 3.10.0-49Miroslav Grepl 3.10.0-48Miroslav Grepl 3.10.0-47Dan Walsh 3.10.0-46.1Miroslav Grepl 3.10.0-46Dan Walsh 3.10.0-45.1Miroslav Grepl 3.10.0-45Miroslav Grepl 3.10.0-43Miroslav Grepl 3.10.0-42Miroslav Grepl 3.10.0-41Dan Walsh 3.10.0-40.2Miroslav Grepl 3.10.0-40Dan Walsh 3.10.0-39.3Dan Walsh 3.10.0-39.2Dan Walsh 3.10.0-39.1Miroslav Grepl 3.10.0-39Dan Walsh 3.10.0-38.1Miroslav Grepl 3.10.0-38Miroslav Grepl 3.10.0-37Dan Walsh 3.10.0-36.1Miroslav Grepl 3.10.0-36Dan Walsh 3.10.0-35Dan Walsh 3.10.0-34.7Dan Walsh 3.10.0-34.6Dan Walsh 3.10.0-34.4Miroslav Grepl 3.10.0-34.3Dan Walsh 3.10.0-34.2Dan Walsh 3.10.0-34.1Miroslav Grepl 3.10.0-34Miroslav Grepl 3.10.0-33Dan Walsh 3.10.0-31.1Miroslav Grepl 3.10.0-31Miroslav Grepl 3.10.0-29Miroslav Grepl 3.10.0-28Miroslav Grepl 3.10.0-27Miroslav Grepl 3.10.0-26Miroslav Grepl 3.10.0-25Miroslav Grepl 3.10.0-24Miroslav Grepl 3.10.0-23Miroslav Grepl 3.10.0-22Miroslav Grepl 3.10.0-21Dan Walsh 3.10.0-20Miroslav Grepl 3.10.0-19Miroslav Grepl 3.10.0-18Miroslav Grepl 3.10.0-17Miroslav Grepl 3.10.0-16Miroslav Grepl 3.10.0-14Miroslav Grepl 3.10.0-13Miroslav Grepl 3.10.0-12Miroslav Grepl 3.10.0-11Miroslav Grepl 3.10.0-10Miroslav Grepl 3.10.0-9Miroslav Grepl 3.10.0-8Miroslav Grepl 3.10.0-7Miroslav Grepl 3.10.0-6Miroslav Grepl 3.10.0-5Miroslav Grepl 3.10.0-4Miroslav Grepl 3.10.0-3Miroslav Grepl 3.10.0-2Miroslav Grepl 3.10.0-1Miroslav Grepl 3.9.16-30Dan Walsh 3.9.16-29.1Miroslav Grepl 3.9.16-29Dan Walsh 3.9.16-28.1Miroslav Grepl 3.9.16-27Miroslav Grepl 3.9.16-26Miroslav Grepl 3.9.16-25Miroslav Grepl 3.9.16-24Miroslav Grepl 3.9.16-23Miroslav Grepl 3.9.16-22Miroslav Grepl 3.9.16-21Miroslav Grepl 3.9.16-20Miroslav Grepl 3.9.16-19Miroslav Grepl 3.9.16-18Miroslav Grepl 3.9.16-17Dan Walsh 3.9.16-16.1Miroslav Grepl 3.9.16-16Miroslav Grepl 3.9.16-15Miroslav Grepl 3.9.16-14Miroslav Grepl 3.9.16-13Miroslav Grepl 3.9.16-12Miroslav Grepl 3.9.16-11Miroslav Grepl 3.9.16-10Miroslav Grepl 3.9.16-7Miroslav Grepl 3.9.16-6Miroslav Grepl 3.9.16-5Miroslav Grepl 3.9.16-4Miroslav Grepl 3.9.16-3Miroslav Grepl 3.9.16-2Miroslav Grepl 3.9.16-1Miroslav Grepl 3.9.15-5Miroslav Grepl 3.9.15-2Miroslav Grepl 3.9.15-1Fedora Release Engineering - 3.9.14-2Dan Walsh 3.9.14-1Miroslav Grepl 3.9.13-10Miroslav Grepl 3.9.13-9Dan Walsh 3.9.13-8Miroslav Grepl 3.9.13-7Miroslav Grepl 3.9.13-6Miroslav Grepl 3.9.13-5Miroslav Grepl 3.9.13-4Miroslav Grepl 3.9.13-3Miroslav Grepl 3.9.13-2Miroslav Grepl 3.9.13-1Miroslav Grepl 3.9.12-8Miroslav Grepl 3.9.12-7Miroslav Grepl 3.9.12-6Miroslav Grepl 3.9.12-5Dan Walsh 3.9.12-4Dan Walsh 3.9.12-3Dan Walsh 3.9.12-2Miroslav Grepl 3.9.12-1Dan Walsh 3.9.11-2Miroslav Grepl 3.9.11-1Miroslav Grepl 3.9.10-13Dan Walsh 3.9.10-12Miroslav Grepl 3.9.10-11Miroslav Grepl 3.9.10-10Miroslav Grepl 3.9.10-9Miroslav Grepl 3.9.10-8Miroslav Grepl 3.9.10-7Miroslav Grepl 3.9.10-6Miroslav Grepl 3.9.10-5Dan Walsh 3.9.10-4Miroslav Grepl 3.9.10-3Miroslav Grepl 3.9.10-2Miroslav Grepl 3.9.10-1Miroslav Grepl 3.9.9-4Dan Walsh 3.9.9-3Miroslav Grepl 3.9.9-2Miroslav Grepl 3.9.9-1Miroslav Grepl 3.9.8-7Dan Walsh 3.9.8-6Miroslav Grepl 3.9.8-5Miroslav Grepl 3.9.8-4Dan Walsh 3.9.8-3Dan Walsh 3.9.8-2Dan Walsh 3.9.8-1Dan Walsh 3.9.7-10Dan Walsh 3.9.7-9Dan Walsh 3.9.7-8Dan Walsh 3.9.7-7Dan Walsh 3.9.7-6Dan Walsh 3.9.7-5Dan Walsh 3.9.7-4Dan Walsh 3.9.7-3Dan Walsh 3.9.7-2Dan Walsh 3.9.7-1Dan Walsh 3.9.6-3Dan Walsh 3.9.6-2Dan Walsh 3.9.6-1Dan Walsh 3.9.5-11Dan Walsh 3.9.5-10Dan Walsh 3.9.5-9Dan Walsh 3.9.5-8Dan Walsh 3.9.5-7Dan Walsh 3.9.5-6Dan Walsh 3.9.5-5Dan Walsh 3.9.5-4Dan Walsh 3.9.5-3Dan Walsh 3.9.5-2Dan Walsh 3.9.5-1Dan Walsh 3.9.4-3Dan Walsh 3.9.4-2Dan Walsh 3.9.4-1Dan Walsh 3.9.3-4Dan Walsh 3.9.3-3Dan Walsh 3.9.3-2Dan Walsh 3.9.3-1Dan Walsh 3.9.2-1Dan Walsh 3.9.1-3Dan Walsh 3.9.1-2Dan Walsh 3.9.1-1Dan Walsh 3.9.0-2Dan Walsh 3.9.0-1Dan Walsh 3.8.8-21Dan Walsh 3.8.8-20Dan Walsh 3.8.8-19Dan Walsh 3.8.8-18Dan Walsh 3.8.8-17Dan Walsh 3.8.8-16Dan Walsh 3.8.8-15Dan Walsh 3.8.8-14Dan Walsh 3.8.8-13Dan Walsh 3.8.8-12Dan Walsh 3.8.8-11Dan Walsh 3.8.8-10Dan Walsh 3.8.8-9Dan Walsh 3.8.8-8Dan Walsh 3.8.8-7Dan Walsh 3.8.8-6Dan Walsh 3.8.8-5Dan Walsh 3.8.8-4Dan Walsh 3.8.8-3Dan Walsh 3.8.8-2Dan Walsh 3.8.8-1Dan Walsh 3.8.7-3Dan Walsh 3.8.7-2Dan Walsh 3.8.7-1Dan Walsh 3.8.6-3Miroslav Grepl 3.8.6-2Dan Walsh 3.8.6-1Dan Walsh 3.8.5-1Dan Walsh 3.8.4-1Dan Walsh 3.8.3-4Dan Walsh 3.8.3-3Dan Walsh 3.8.3-2Dan Walsh 3.8.3-1Dan Walsh 3.8.2-1Dan Walsh 3.8.1-5Dan Walsh 3.8.1-4Dan Walsh 3.8.1-3Dan Walsh 3.8.1-2Dan Walsh 3.8.1-1Dan Walsh 3.7.19-22Dan Walsh 3.7.19-21Dan Walsh 3.7.19-20Dan Walsh 3.7.19-19Dan Walsh 3.7.19-17Dan Walsh 3.7.19-16Dan Walsh 3.7.19-15Dan Walsh 3.7.19-14Dan Walsh 3.7.19-13Dan Walsh 3.7.19-12Dan Walsh 3.7.19-11Dan Walsh 3.7.19-10Dan Walsh 3.7.19-9Dan Walsh 3.7.19-8Dan Walsh 3.7.19-7Dan Walsh 3.7.19-6Dan Walsh 3.7.19-5Dan Walsh 3.7.19-4Dan Walsh 3.7.19-3Dan Walsh 3.7.19-2Dan Walsh 3.7.19-1Dan Walsh 3.7.18-3Dan Walsh 3.7.18-2Dan Walsh 3.7.18-1Dan Walsh 3.7.17-6Dan Walsh 3.7.17-5Dan Walsh 3.7.17-4Dan Walsh 3.7.17-3Dan Walsh 3.7.17-2Dan Walsh 3.7.17-1Dan Walsh 3.7.16-2Dan Walsh 3.7.16-1Dan Walsh 3.7.15-4Dan Walsh 3.7.15-3Dan Walsh 3.7.15-2Dan Walsh 3.7.15-1Dan Walsh 3.7.14-5Dan Walsh 3.7.14-4Dan Walsh 3.7.14-3Dan Walsh 3.7.14-2Dan Walsh 3.7.14-1Dan Walsh 3.7.13-4Dan Walsh 3.7.13-3Dan Walsh 3.7.13-2Dan Walsh 3.7.13-1Dan Walsh 3.7.12-1Dan Walsh 3.7.11-1Dan Walsh 3.7.10-5Dan Walsh 3.7.10-4Dan Walsh 3.7.10-3Dan Walsh 3.7.10-2Dan Walsh 3.7.10-1Dan Walsh 3.7.9-4Dan Walsh 3.7.9-3Dan Walsh 3.7.9-2Dan Walsh 3.7.9-1Dan Walsh 3.7.8-11Dan Walsh 3.7.8-9Dan Walsh 3.7.8-8Dan Walsh 3.7.8-7Dan Walsh 3.7.8-6Dan Walsh 3.7.8-5Dan Walsh 3.7.8-4Dan Walsh 3.7.8-3Dan Walsh 3.7.8-2Dan Walsh 3.7.8-1Dan Walsh 3.7.7-3Dan Walsh 3.7.7-2Dan Walsh 3.7.7-1Dan Walsh 3.7.6-1Dan Walsh 3.7.5-8Dan Walsh 3.7.5-7Dan Walsh 3.7.5-6Dan Walsh 3.7.5-5Dan Walsh 3.7.5-4Dan Walsh 3.7.5-3Dan Walsh 3.7.5-2Dan Walsh 3.7.5-1Dan Walsh 3.7.4-4Dan Walsh 3.7.4-3Dan Walsh 3.7.4-2Dan Walsh 3.7.4-1Dan Walsh 3.7.3-1Dan Walsh 3.7.1-1Dan Walsh 3.6.33-2Dan Walsh 3.6.33-1Dan Walsh 3.6.32-17Dan Walsh 3.6.32-16Dan Walsh 3.6.32-15Dan Walsh 3.6.32-13Dan Walsh 3.6.32-12Dan Walsh 3.6.32-11Dan Walsh 3.6.32-10Dan Walsh 3.6.32-9Dan Walsh 3.6.32-8Dan Walsh 3.6.32-7Dan Walsh 3.6.32-6Dan Walsh 3.6.32-5Dan Walsh 3.6.32-4Dan Walsh 3.6.32-3Dan Walsh 3.6.32-2Dan Walsh 3.6.32-1Dan Walsh 3.6.31-5Dan Walsh 3.6.31-4Dan Walsh 3.6.31-3Dan Walsh 3.6.31-2Dan Walsh 3.6.30-6Dan Walsh 3.6.30-5Dan Walsh 3.6.30-4Dan Walsh 3.6.30-3Dan Walsh 3.6.30-2Dan Walsh 3.6.30-1Dan Walsh 3.6.29-2Dan Walsh 3.6.29-1Dan Walsh 3.6.28-9Dan Walsh 3.6.28-8Dan Walsh 3.6.28-7Dan Walsh 3.6.28-6Dan Walsh 3.6.28-5Dan Walsh 3.6.28-4Dan Walsh 3.6.28-3Dan Walsh 3.6.28-2Dan Walsh 3.6.28-1Dan Walsh 3.6.27-1Dan Walsh 3.6.26-11Dan Walsh 3.6.26-10Dan Walsh 3.6.26-9Bill Nottingham 3.6.26-8Dan Walsh 3.6.26-7Dan Walsh 3.6.26-6Dan Walsh 3.6.26-5Dan Walsh 3.6.26-4Dan Walsh 3.6.26-3Dan Walsh 3.6.26-2Dan Walsh 3.6.26-1Dan Walsh 3.6.25-1Dan Walsh 3.6.24-1Dan Walsh 3.6.23-2Dan Walsh 3.6.23-1Dan Walsh 3.6.22-3Dan Walsh 3.6.22-1Dan Walsh 3.6.21-4Dan Walsh 3.6.21-3Tom "spot" Callaway 3.6.21-2Dan Walsh 3.6.21-1Dan Walsh 3.6.20-2Dan Walsh 3.6.20-1Dan Walsh 3.6.19-5Dan Walsh 3.6.19-4Dan Walsh 3.6.19-3Dan Walsh 3.6.19-2Dan Walsh 3.6.19-1Dan Walsh 3.6.18-1Dan Walsh 3.6.17-1Dan Walsh 3.6.16-4Dan Walsh 3.6.16-3Dan Walsh 3.6.16-2Dan Walsh 3.6.16-1Dan Walsh 3.6.14-3Dan Walsh 3.6.14-2Dan Walsh 3.6.14-1Dan Walsh 3.6.13-3Dan Walsh 3.6.13-2Dan Walsh 3.6.13-1Dan Walsh 3.6.12-39Dan Walsh 3.6.12-38Dan Walsh 3.6.12-37Dan Walsh 3.6.12-36Dan Walsh 3.6.12-35Dan Walsh 3.6.12-34Dan Walsh 3.6.12-33Dan Walsh 3.6.12-31Dan Walsh 3.6.12-30Dan Walsh 3.6.12-29Dan Walsh 3.6.12-28Dan Walsh 3.6.12-27Dan Walsh 3.6.12-26Dan Walsh 3.6.12-25Dan Walsh 3.6.12-24Dan Walsh 3.6.12-23Dan Walsh 3.6.12-22Dan Walsh 3.6.12-21Dan Walsh 3.6.12-20Dan Walsh 3.6.12-19Dan Walsh 3.6.12-16Dan Walsh 3.6.12-15Dan Walsh 3.6.12-14Dan Walsh 3.6.12-13Dan Walsh 3.6.12-12Dan Walsh 3.6.12-11Dan Walsh 3.6.12-10Dan Walsh 3.6.12-9Dan Walsh 3.6.12-8Dan Walsh 3.6.12-7Dan Walsh 3.6.12-6Dan Walsh 3.6.12-5Dan Walsh 3.6.12-4Dan Walsh 3.6.12-3Dan Walsh 3.6.12-2Dan Walsh 3.6.12-1Dan Walsh 3.6.11-1Dan Walsh 3.6.10-9Dan Walsh 3.6.10-8Dan Walsh 3.6.10-7Dan Walsh 3.6.10-6Dan Walsh 3.6.10-5Dan Walsh 3.6.10-4Dan Walsh 3.6.10-3Dan Walsh 3.6.10-2Dan Walsh 3.6.10-1Dan Walsh 3.6.9-4Dan Walsh 3.6.9-3Dan Walsh 3.6.9-2Dan Walsh 3.6.9-1Dan Walsh 3.6.8-4Dan Walsh 3.6.8-3Dan Walsh 3.6.8-2Dan Walsh 3.6.8-1Dan Walsh 3.6.7-2Dan Walsh 3.6.7-1Dan Walsh 3.6.6-9Dan Walsh 3.6.6-8Fedora Release Engineering - 3.6.6-7Dan Walsh 3.6.6-6Dan Walsh 3.6.6-5Dan Walsh 3.6.6-4Dan Walsh 3.6.6-3Dan Walsh 3.6.6-2Dan Walsh 3.6.6-1Dan Walsh 3.6.5-3Dan Walsh 3.6.5-1Dan Walsh 3.6.4-6Dan Walsh 3.6.4-5Dan Walsh 3.6.4-4Dan Walsh 3.6.4-3Dan Walsh 3.6.4-2Dan Walsh 3.6.4-1Dan Walsh 3.6.3-13Dan Walsh 3.6.3-12Dan Walsh 3.6.3-11Dan Walsh 3.6.3-10Dan Walsh 3.6.3-9Dan Walsh 3.6.3-8Dan Walsh 3.6.3-7Dan Walsh 3.6.3-6Dan Walsh 3.6.3-3Dan Walsh 3.6.3-2Dan Walsh 3.6.3-1Dan Walsh 3.6.2-5Dan Walsh 3.6.2-4Dan Walsh 3.6.2-3Dan Walsh 3.6.2-2Dan Walsh 3.6.2-1Dan Walsh 3.6.1-15Dan Walsh 3.6.1-14Dan Walsh 3.6.1-13Dan Walsh 3.6.1-12Dan Walsh 3.6.1-11Dan Walsh 3.6.1-10Dan Walsh 3.6.1-9Dan Walsh 3.6.1-8Dan Walsh 3.6.1-7Dan Walsh 3.6.1-4Ignacio Vazquez-Abrams - 3.6.1-2Dan Walsh 3.5.13-19Dan Walsh 3.5.13-18Dan Walsh 3.5.13-17Dan Walsh 3.5.13-16Dan Walsh 3.5.13-15Dan Walsh 3.5.13-14Dan Walsh 3.5.13-13Dan Walsh 3.5.13-12Dan Walsh 3.5.13-11Dan Walsh 3.5.13-9Dan Walsh 3.5.13-8Dan Walsh 3.5.13-7Dan Walsh 3.5.13-6Dan Walsh 3.5.13-5Dan Walsh 3.5.13-4Dan Walsh 3.5.13-3Dan Walsh 3.5.13-2Dan Walsh 3.5.13-1Dan Walsh 3.5.12-3Dan Walsh 3.5.12-2Dan Walsh 3.5.12-1Dan Walsh 3.5.11-1Dan Walsh 3.5.10-3Dan Walsh 3.5.10-2Dan Walsh 3.5.10-1Dan Walsh 3.5.9-4Dan Walsh 3.5.9-3Dan Walsh 3.5.9-2Dan Walsh 3.5.9-1Dan Walsh 3.5.8-7Dan Walsh 3.5.8-6Dan Walsh 3.5.8-5Dan Walsh 3.5.8-4Dan Walsh 3.5.8-3Dan Walsh 3.5.8-1Dan Walsh 3.5.7-2Dan Walsh 3.5.7-1Dan Walsh 3.5.6-2Dan Walsh 3.5.6-1Dan Walsh 3.5.5-4Dan Walsh 3.5.5-3Dan Walsh 3.5.5-2Dan Walsh 3.5.4-2Dan Walsh 3.5.4-1Dan Walsh 3.5.3-1Dan Walsh 3.5.2-2Dan Walsh 3.5.1-5Dan Walsh 3.5.1-4Dan Walsh 3.5.1-3Dan Walsh 3.5.1-2Dan Walsh 3.5.1-1Dan Walsh 3.5.0-1Dan Walsh 3.4.2-14Dan Walsh 3.4.2-13Dan Walsh 3.4.2-12Dan Walsh 3.4.2-11Dan Walsh 3.4.2-10Dan Walsh 3.4.2-9Dan Walsh 3.4.2-8Dan Walsh 3.4.2-7Dan Walsh 3.4.2-6Dan Walsh 3.4.2-5Dan Walsh 3.4.2-4Dan Walsh 3.4.2-3Dan Walsh 3.4.2-2Dan Walsh 3.4.2-1Dan Walsh 3.4.1-5Dan Walsh 3.4.1-3Dan Walsh 3.4.1-2Dan Walsh 3.4.1-1Dan Walsh 3.3.1-48Dan Walsh 3.3.1-47Dan Walsh 3.3.1-46Dan Walsh 3.3.1-45Dan Walsh 3.3.1-44Dan Walsh 3.3.1-43Dan Walsh 3.3.1-42Dan Walsh 3.3.1-41Dan Walsh 3.3.1-39Dan Walsh 3.3.1-37Dan Walsh 3.3.1-36Dan Walsh 3.3.1-33Dan Walsh 3.3.1-32Dan Walsh 3.3.1-31Dan Walsh 3.3.1-30Dan Walsh 3.3.1-29Dan Walsh 3.3.1-28Dan Walsh 3.3.1-27Dan Walsh 3.3.1-26Dan Walsh 3.3.1-25Dan Walsh 3.3.1-24Dan Walsh 3.3.1-23Dan Walsh 3.3.1-22Dan Walsh 3.3.1-21Dan Walsh 3.3.1-20Dan Walsh 3.3.1-19Dan Walsh 3.3.1-18Dan Walsh 3.3.1-17Dan Walsh 3.3.1-16Dan Walsh 3.3.1-15Bill Nottingham 3.3.1-14Dan Walsh 3.3.1-13Dan Walsh 3.3.1-12Dan Walsh 3.3.1-11Dan Walsh 3.3.1-10Dan Walsh 3.3.1-9Dan Walsh 3.3.1-8Dan Walsh 3.3.1-6Dan Walsh 3.3.1-5Dan Walsh 3.3.1-4Dan Walsh 3.3.1-2Dan Walsh 3.3.1-1Dan Walsh 3.3.0-2Dan Walsh 3.3.0-1Dan Walsh 3.2.9-2Dan Walsh 3.2.9-1Dan Walsh 3.2.8-2Dan Walsh 3.2.8-1Dan Walsh 3.2.7-6Dan Walsh 3.2.7-5Dan Walsh 3.2.7-3Dan Walsh 3.2.7-2Dan Walsh 3.2.7-1Dan Walsh 3.2.6-7Dan Walsh 3.2.6-6Dan Walsh 3.2.6-5Dan Walsh 3.2.6-4Dan Walsh 3.2.6-3Dan Walsh 3.2.6-2Dan Walsh 3.2.6-1Dan Walsh 3.2.5-25Dan Walsh 3.2.5-24Dan Walsh 3.2.5-22Dan Walsh 3.2.5-21Dan Walsh 3.2.5-20Dan Walsh 3.2.5-19Dan Walsh 3.2.5-18Dan Walsh 3.2.5-17Dan Walsh 3.2.5-16Dan Walsh 3.2.5-15Dan Walsh 3.2.5-14Dan Walsh 3.2.5-13Dan Walsh 3.2.5-12Dan Walsh 3.2.5-11Dan Walsh 3.2.5-10Dan Walsh 3.2.5-9Dan Walsh 3.2.5-8Dan Walsh 3.2.5-7Dan Walsh 3.2.5-6Dan Walsh 3.2.5-5Dan Walsh 3.2.5-4Dan Walsh 3.2.5-3Dan Walsh 3.2.5-2Dan Walsh 3.2.5-1Dan Walsh 3.2.4-5Dan Walsh 3.2.4-4Dan Walsh 3.2.4-3Dan Walsh 3.2.4-1Dan Walsh 3.2.4-1Dan Walsh 3.2.3-2Dan Walsh 3.2.3-1Dan Walsh 3.2.2-1Dan Walsh 3.2.1-3Dan Walsh 3.2.1-1Dan Walsh 3.1.2-2Dan Walsh 3.1.2-1Dan Walsh 3.1.1-1Dan Walsh 3.1.0-1Dan Walsh 3.0.8-30Dan Walsh 3.0.8-28Dan Walsh 3.0.8-27Dan Walsh 3.0.8-26Dan Walsh 3.0.8-25Dan Walsh 3.0.8-24Dan Walsh 3.0.8-23Dan Walsh 3.0.8-22Dan Walsh 3.0.8-21Dan Walsh 3.0.8-20Dan Walsh 3.0.8-19Dan Walsh 3.0.8-18Dan Walsh 3.0.8-17Dan Walsh 3.0.8-16Dan Walsh 3.0.8-15Dan Walsh 3.0.8-14Dan Walsh 3.0.8-13Dan Walsh 3.0.8-12Dan Walsh 3.0.8-11Dan Walsh 3.0.8-10Dan Walsh 3.0.8-9Dan Walsh 3.0.8-8Dan Walsh 3.0.8-7Dan Walsh 3.0.8-5Dan Walsh 3.0.8-4Dan Walsh 3.0.8-3Dan Walsh 3.0.8-2Dan Walsh 3.0.8-1Dan Walsh 3.0.7-10Dan Walsh 3.0.7-9Dan Walsh 3.0.7-8Dan Walsh 3.0.7-7Dan Walsh 3.0.7-6Dan Walsh 3.0.7-5Dan Walsh 3.0.7-4Dan Walsh 3.0.7-3Dan Walsh 3.0.7-2Dan Walsh 3.0.7-1Dan Walsh 3.0.6-3Dan Walsh 3.0.6-2Dan Walsh 3.0.6-1Dan Walsh 3.0.5-11Dan Walsh 3.0.5-10Dan Walsh 3.0.5-9Dan Walsh 3.0.5-8Dan Walsh 3.0.5-7Dan Walsh 3.0.5-6Dan Walsh 3.0.5-5Dan Walsh 3.0.5-4Dan Walsh 3.0.5-3Dan Walsh 3.0.5-2Dan Walsh 3.0.5-1Dan Walsh 3.0.4-6Dan Walsh 3.0.4-5Dan Walsh 3.0.4-4Dan Walsh 3.0.4-3Dan Walsh 3.0.4-2Dan Walsh 3.0.4-1Dan Walsh 3.0.3-6Dan Walsh 3.0.3-5Dan Walsh 3.0.3-4Dan Walsh 3.0.3-3Dan Walsh 3.0.3-2Dan Walsh 3.0.3-1Dan Walsh 3.0.2-9Dan Walsh 3.0.2-8Dan Walsh 3.0.2-7Dan Walsh 3.0.2-5Dan Walsh 3.0.2-4Dan Walsh 3.0.2-3Dan Walsh 3.0.2-2Dan Walsh 3.0.1-5Dan Walsh 3.0.1-4Dan Walsh 3.0.1-3Dan Walsh 3.0.1-2Dan Walsh 3.0.1-1Dan Walsh 2.6.5-3Dan Walsh 2.6.5-2Dan Walsh 2.6.4-7Dan Walsh 2.6.4-6Dan Walsh 2.6.4-5Dan Walsh 2.6.4-2Dan Walsh 2.6.4-1Dan Walsh 2.6.3-1Dan Walsh 2.6.2-1Dan Walsh 2.6.1-4Dan Walsh 2.6.1-2Dan Walsh 2.6.1-1Dan Walsh 2.5.12-12Dan Walsh 2.5.12-11Dan Walsh 2.5.12-10Dan Walsh 2.5.12-8Dan Walsh 2.5.12-5Dan Walsh 2.5.12-4Dan Walsh 2.5.12-3Dan Walsh 2.5.12-2Dan Walsh 2.5.12-1Dan Walsh 2.5.11-8Dan Walsh 2.5.11-7Dan Walsh 2.5.11-6Dan Walsh 2.5.11-5Dan Walsh 2.5.11-4Dan Walsh 2.5.11-3Dan Walsh 2.5.11-2Dan Walsh 2.5.11-1Dan Walsh 2.5.10-2Dan Walsh 2.5.10-1Dan Walsh 2.5.9-6Dan Walsh 2.5.9-5Dan Walsh 2.5.9-4Dan Walsh 2.5.9-3Dan Walsh 2.5.9-2Dan Walsh 2.5.8-8Dan Walsh 2.5.8-7Dan Walsh 2.5.8-6Dan Walsh 2.5.8-5Dan Walsh 2.5.8-4Dan Walsh 2.5.8-3Dan Walsh 2.5.8-2Dan Walsh 2.5.8-1Dan Walsh 2.5.7-1Dan Walsh 2.5.6-1Dan Walsh 2.5.5-2Dan Walsh 2.5.5-1Dan Walsh 2.5.4-2Dan Walsh 2.5.4-1Dan Walsh 2.5.3-3Dan Walsh 2.5.3-2Dan Walsh 2.5.3-1Dan Walsh 2.5.2-6Dan Walsh 2.5.2-5Dan Walsh 2.5.2-4Dan Walsh 2.5.2-3Dan Walsh 2.5.2-2Dan Walsh 2.5.2-1Dan Walsh 2.5.1-5Dan Walsh 2.5.1-4Dan Walsh 2.5.1-2Dan Walsh 2.5.1-1Dan Walsh 2.4.6-20Dan Walsh 2.4.6-19Dan Walsh 2.4.6-18Dan Walsh 2.4.6-17Dan Walsh 2.4.6-16Dan Walsh 2.4.6-15Dan Walsh 2.4.6-14Dan Walsh 2.4.6-13Dan Walsh 2.4.6-12Dan Walsh 2.4.6-11Dan Walsh 2.4.6-10Dan Walsh 2.4.6-9Dan Walsh 2.4.6-8Dan Walsh 2.4.6-7Dan Walsh 2.4.6-6Dan Walsh 2.4.6-5Dan Walsh 2.4.6-4Dan Walsh 2.4.6-3Dan Walsh 2.4.6-1Dan Walsh 2.4.5-4Dan Walsh 2.4.5-3Dan Walsh 2.4.5-2Dan Walsh 2.4.5-1Dan Walsh 2.4.4-2Dan Walsh 2.4.4-2Dan Walsh 2.4.4-1Dan Walsh 2.4.3-13Dan Walsh 2.4.3-12Dan Walsh 2.4.3-11Dan Walsh 2.4.3-10Dan Walsh 2.4.3-9Dan Walsh 2.4.3-8Dan Walsh 2.4.3-7Dan Walsh 2.4.3-6Dan Walsh 2.4.3-5Dan Walsh 2.4.3-4Dan Walsh 2.4.3-3Dan Walsh 2.4.3-2Dan Walsh 2.4.3-1Dan Walsh 2.4.2-8Dan Walsh 2.4.2-7James Antill 2.4.2-6Dan Walsh 2.4.2-5Dan Walsh 2.4.2-4Dan Walsh 2.4.2-3Dan Walsh 2.4.2-2Dan Walsh 2.4.2-1Dan Walsh 2.4.1-5Dan Walsh 2.4.1-4Dan Walsh 2.4.1-3Dan Walsh 2.4.1-2Dan Walsh 2.4-4Dan Walsh 2.4-3Dan Walsh 2.4-2Dan Walsh 2.4-1Dan Walsh 2.3.19-4Dan Walsh 2.3.19-3Dan Walsh 2.3.19-2Dan Walsh 2.3.19-1James Antill 2.3.18-10James Antill 2.3.18-9Dan Walsh 2.3.18-8Dan Walsh 2.3.18-7Dan Walsh 2.3.18-6Dan Walsh 2.3.18-5Dan Walsh 2.3.18-4Dan Walsh 2.3.18-3Dan Walsh 2.3.18-2Dan Walsh 2.3.18-1Dan Walsh 2.3.17-2Dan Walsh 2.3.17-1Dan Walsh 2.3.16-9Dan Walsh 2.3.16-8Dan Walsh 2.3.16-7Dan Walsh 2.3.16-6Dan Walsh 2.3.16-5Dan Walsh 2.3.16-4Dan Walsh 2.3.16-2Dan Walsh 2.3.16-1Dan Walsh 2.3.15-2Dan Walsh 2.3.15-1Dan Walsh 2.3.14-8Dan Walsh 2.3.14-7Dan Walsh 2.3.14-6Dan Walsh 2.3.14-4Dan Walsh 2.3.14-3Dan Walsh 2.3.14-2Dan Walsh 2.3.14-1Dan Walsh 2.3.13-6Dan Walsh 2.3.13-5Dan Walsh 2.3.13-4Dan Walsh 2.3.13-3Dan Walsh 2.3.13-2Dan Walsh 2.3.13-1Dan Walsh 2.3.12-2Dan Walsh 2.3.12-1Dan Walsh 2.3.11-1Dan Walsh 2.3.10-7Dan Walsh 2.3.10-6Dan Walsh 2.3.10-3Dan Walsh 2.3.10-1Dan Walsh 2.3.9-6Dan Walsh 2.3.9-5Dan Walsh 2.3.9-4Dan Walsh 2.3.9-3Dan Walsh 2.3.9-2Dan Walsh 2.3.9-1Dan Walsh 2.3.8-2Dan Walsh 2.3.7-1Dan Walsh 2.3.6-4Dan Walsh 2.3.6-3Dan Walsh 2.3.6-2Dan Walsh 2.3.6-1Dan Walsh 2.3.5-1Dan Walsh 2.3.4-1Dan Walsh 2.3.3-20Dan Walsh 2.3.3-19Dan Walsh 2.3.3-18Dan Walsh 2.3.3-17Dan Walsh 2.3.3-16Dan Walsh 2.3.3-15Dan Walsh 2.3.3-14Dan Walsh 2.3.3-13Dan Walsh 2.3.3-12Dan Walsh 2.3.3-11Dan Walsh 2.3.3-10Dan Walsh 2.3.3-9Dan Walsh 2.3.3-8Dan Walsh 2.3.3-7Dan Walsh 2.3.3-6Dan Walsh 2.3.3-5Dan Walsh 2.3.3-4Dan Walsh 2.3.3-3Dan Walsh 2.3.3-2Dan Walsh 2.3.3-1Dan Walsh 2.3.2-4Dan Walsh 2.3.2-3Dan Walsh 2.3.2-2Dan Walsh 2.3.2-1Dan Walsh 2.3.1-1Dan Walsh 2.2.49-1Dan Walsh 2.2.48-1Dan Walsh 2.2.47-5Dan Walsh 2.2.47-4Dan Walsh 2.2.47-3Dan Walsh 2.2.47-1Dan Walsh 2.2.46-2Dan Walsh 2.2.46-1Dan Walsh 2.2.45-3Dan Walsh 2.2.45-2Dan Walsh 2.2.45-1Dan Walsh 2.2.44-1Dan Walsh 2.2.43-4Dan Walsh 2.2.43-3Dan Walsh 2.2.43-2Dan Walsh 2.2.43-1Dan Walsh 2.2.42-4Dan Walsh 2.2.42-3Dan Walsh 2.2.42-2Dan Walsh 2.2.42-1Dan Walsh 2.2.41-1Dan Walsh 2.2.40-2Dan Walsh 2.2.40-1Dan Walsh 2.2.39-2Dan Walsh 2.2.39-1Dan Walsh 2.2.38-6Dan Walsh 2.2.38-5Dan Walsh 2.2.38-4Dan Walsh 2.2.38-3Dan Walsh 2.2.38-2Dan Walsh 2.2.38-1Dan Walsh 2.2.37-1Dan Walsh 2.2.36-2Dan Walsh 2.2.36-1James Antill 2.2.35-2Dan Walsh 2.2.35-1Dan Walsh 2.2.34-3Dan Walsh 2.2.34-2Dan Walsh 2.2.34-1Dan Walsh 2.2.33-1Dan Walsh 2.2.32-2Dan Walsh 2.2.32-1Dan Walsh 2.2.31-1Dan Walsh 2.2.30-2Dan Walsh 2.2.30-1Dan Walsh 2.2.29-6Russell Coker 2.2.29-5Dan Walsh 2.2.29-4Dan Walsh 2.2.29-3Dan Walsh 2.2.29-2Dan Walsh 2.2.29-1Dan Walsh 2.2.28-3Dan Walsh 2.2.28-2Dan Walsh 2.2.28-1Dan Walsh 2.2.27-1Dan Walsh 2.2.25-3Dan Walsh 2.2.25-2Dan Walsh 2.2.24-1Dan Walsh 2.2.23-19Dan Walsh 2.2.23-18Dan Walsh 2.2.23-17Karsten Hopp 2.2.23-16Dan Walsh 2.2.23-15Dan Walsh 2.2.23-14Dan Walsh 2.2.23-13Dan Walsh 2.2.23-12Jeremy Katz - 2.2.23-11Jeremy Katz - 2.2.23-10Dan Walsh 2.2.23-9Dan Walsh 2.2.23-8Dan Walsh 2.2.23-7Dan Walsh 2.2.23-5Dan Walsh 2.2.23-4Dan Walsh 2.2.23-3Dan Walsh 2.2.23-2Dan Walsh 2.2.23-1Dan Walsh 2.2.22-2Dan Walsh 2.2.22-1Dan Walsh 2.2.21-9Dan Walsh 2.2.21-8Dan Walsh 2.2.21-7Dan Walsh 2.2.21-6Dan Walsh 2.2.21-5Dan Walsh 2.2.21-4Dan Walsh 2.2.21-3Dan Walsh 2.2.21-2Dan Walsh 2.2.21-1Dan Walsh 2.2.20-1Dan Walsh 2.2.19-2Dan Walsh 2.2.19-1Dan Walsh 2.2.18-2Dan Walsh 2.2.18-1Dan Walsh 2.2.17-2Dan Walsh 2.2.16-1Dan Walsh 2.2.15-4Dan Walsh 2.2.15-3Dan Walsh 2.2.15-1Dan Walsh 2.2.14-2Dan Walsh 2.2.14-1Dan Walsh 2.2.13-1Dan Walsh 2.2.12-1Dan Walsh 2.2.11-2Dan Walsh 2.2.11-1Dan Walsh 2.2.10-1Dan Walsh 2.2.9-2Dan Walsh 2.2.9-1Dan Walsh 2.2.8-2Dan Walsh 2.2.7-1Dan Walsh 2.2.6-3Dan Walsh 2.2.6-2Dan Walsh 2.2.6-1Dan Walsh 2.2.5-1Dan Walsh 2.2.4-1Dan Walsh 2.2.3-1Dan Walsh 2.2.2-1Dan Walsh 2.2.1-1Dan Walsh 2.1.13-1Dan Walsh 2.1.12-3Dan Walsh 2.1.11-1Dan Walsh 2.1.10-1Jeremy Katz - 2.1.9-2Dan Walsh 2.1.9-1Dan Walsh 2.1.8-3Dan Walsh 2.1.8-2Dan Walsh 2.1.8-1Dan Walsh 2.1.7-4Dan Walsh 2.1.7-3Dan Walsh 2.1.7-2Dan Walsh 2.1.7-1Dan Walsh 2.1.6-24Dan Walsh 2.1.6-23Dan Walsh 2.1.6-22Dan Walsh 2.1.6-21Dan Walsh 2.1.6-20Dan Walsh 2.1.6-18Dan Walsh 2.1.6-17Dan Walsh 2.1.6-16Dan Walsh 2.1.6-15Dan Walsh 2.1.6-14Dan Walsh 2.1.6-13Dan Walsh 2.1.6-11Dan Walsh 2.1.6-10Dan Walsh 2.1.6-9Dan Walsh 2.1.6-8Dan Walsh 2.1.6-5Dan Walsh 2.1.6-4Dan Walsh 2.1.6-3Dan Walsh 2.1.6-2Dan Walsh 2.1.6-1Dan Walsh 2.1.4-2Dan Walsh 2.1.4-1Dan Walsh 2.1.3-1Jeremy Katz - 2.1.2-3Dan Walsh 2.1.2-2Dan Walsh 2.1.2-1Dan Walsh 2.1.1-3Dan Walsh 2.1.1-2Dan Walsh 2.1.1-1Dan Walsh 2.1.0-3Dan Walsh 2.1.0-2.Dan Walsh 2.1.0-1.Dan Walsh 2.0.11-2.Dan Walsh 2.0.11-1.Dan Walsh 2.0.9-1.Dan Walsh 2.0.8-1.Dan Walsh 2.0.7-3Dan Walsh 2.0.7-2Dan Walsh 2.0.6-2Dan Walsh 2.0.5-4Dan Walsh 2.0.5-1Dan Walsh 2.0.4-1Dan Walsh 2.0.2-2Dan Walsh 2.0.2-1Dan Walsh 2.0.1-2Dan Walsh 2.0.1-1- Allow neutron domain to read/write /var/run/utmp Resolves: rhbz#1630318- Allow tomcat_domain to read /dev/random Resolves: rhbz#1631666 - Allow neutron_t domain to use pam Resolves: rhbz#1630318- Add interface apache_read_tmp_dirs() - Allow dirsrvadmin_script_t domain to list httpd_tmp_t dirs Resolves: rhbz#1622602- Allow tomcat servers to manage usr_t files Resolves: rhbz#1625678 - Dontaudit tomcat serves to append to /dev/random device Resolves: rhbz#1625678 - Allow sys_nice capability to mysqld_t domain - Allow dirsrvadmin_script_t domain to read httpd tmp files Resolves: rhbz#1622602 - Allow syslogd_t domain to manage cert_t files Resolves: rhbz#1615995- Allow sbd_t domain to getattr of all char files in /dev and read sysfs_t files and dirs Resolves: rhbz#1627114 - Expand virt_read_lib_files() interface to allow list dirs with label virt_var_lib_t Resolves: rhbz#1567753- Allow tomcat Tomcat to delete a temporary file used when compiling class files for JSPs. Resolves: rhbz#1625678 - Allow chronyd_t domain to read virt_var_lib_t files - Allow virtual machines to use dri devices. This allows use openCL GPU calculations. BZ(1337333) Resolves: rhbz#1625613 - Allow tomcat services create link file in /tmp Resolves: rhbz#1624289 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322- Make working SELinux sandbox with Wayland. Resolves: rhbz#1624308 - Allow svirt_t domain to mmap svirt_image_t block files Resolves: rhbz#1624224 - Add caps dac_read_search and dav_override to pesign_t domain - Allow iscsid_t domain to mmap userio chr files Resolves: rhbz#1623589 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322 - Add execute_no_trans permission to mmap_exec_file_perms pattern - Allow sudodomain to search caller domain proc info - Allow xdm_t domain to mmap and read cert_t files - Replace optional policy blocks to make dbus interfaces effective Resolves: rhbz#1624414 - Add interface dev_map_userio_dev()- Allow readhead_t domain to mmap own pid files Resolves: rhbz#1614169- Allow ovs-vswitchd labeled as openvswitch_t domain communicate with qemu-kvm via UNIX stream socket - Allow httpd_t domain to mmap tmp files Resolves: rhbz#1608355 - Update dirsrv_read_share() interface to allow caller domain to mmap dirsrv_share_t files - Update dirsrvadmin_script_t policy to allow read httpd_tmp_t symlinks - Label /dev/tpmrm[0-9]* as tpm_device_t - Allow semanage_t domain mmap usr_t files Resolves: rhbz#1622607 - Update dev_filetrans_all_named_dev() to allow create event22-30 character files with label event_device_t- Allow nagios_script_t domain to mmap nagios_log_t files Resolves: rhbz#1620013 - Allow nagios_script_t domain to mmap nagios_spool_t files Resolves: rhbz#1620013 - Update userdom_security_admin() and userdom_security_admin_template() to allow use auditctl Resolves: rhbz#1622197 - Update selinux_validate_context() interface to allow caller domain to mmap security_t files Resolves: rhbz#1622061- Allow virtd_t domain to create netlink_socket - Allow rpm_t domain to write to audit - Allow rpm domain to mmap rpm_var_lib_t files Resolves: rhbz#1619785 - Allow nagios_script_t domain to mmap nagios_etc_t files Resolves: rhbz#1620013 - Update nscd_socket_use() to allow caller domain to stream connect to nscd_t Resolves: rhbz#1460715 - Allow secadm_t domain to mmap audit config and log files - Allow insmod_t domain to read iptables pid files - Allow systemd to mounton /etc Resolves: rhbz#1619785- Allow kdumpctl_t domain to getattr fixed disk device in mls Resolves: rhbz#1615342 - Allow initrc_domain to mmap all binaries labeled as systemprocess_entry Resolves: rhbz#1615342- Allow virtlogd to execute itself Resolves: rhbz#1598392- Allow kdumpctl_t domain to manage kdumpctl_tmp_t fifo files Resolves: rhbz#1615342 - Allow kdumpctl to write to files on all levels Resolves: rhbz#1615342 - Fix typo in radius policy Resolves: rhbz#1619197 - Allow httpd_t domain to mmap httpd_config_t files Resolves: rhbz#1615894 - Add interface dbus_acquire_svc_system_dbusd() - Allow sanlock_t domain to connectto to unix_stream_socket Resolves: rhbz#1614965 - Update nfsd_t policy because of ganesha features Resolves: rhbz#1511489 - Allow conman to getattr devpts_t Resolves: rhbz#1377915 - Allow tomcat_domain to connect to smtp ports Resolves: rhbz#1253502 - Allow tomcat_t domain to mmap tomcat_var_lib_t files Resolves: rhbz#1618519 - Allow slapd_t domain to mmap slapd_var_run_t files Resolves: rhbz#1615319 - Allow nagios_t domain to mmap nagios_log_t files Resolves: rhbz#1618675 - Allow nagios to exec itself and mmap nagios spool files BZ(1559683) - Allow nagios to mmap nagios config files BZ(1559683) - Allow kpropd_t domain to mmap krb5kdc_principal_t files Resolves: rhbz#1619252 - Update syslogd policy to make working elasticsearch - Label tcp and udp ports 9200 as wap_wsp_port - Allow few domains to rw inherited kdumpctl tmp pipes Resolves: rhbz#1615342- Allow systemd_dbusd_t domain read/write to nvme devices Resolves: rhbz#1614236 - Allow mysqld_safe_t do execute itself - Allow smbd_t domain to chat via dbus with avahi daemon Resolves: rhbz#1600157 - cupsd_t domain will create /etc/cupsd/ppd as cupsd_etc_rw_t Resolves: rhbz#1452595 - Allow amanda_t domain to getattr on tmpfs filesystem BZ(1527645) Resolves: rhbz#1452444 - Update screen_role_template to allow caller domain to have screen_exec_t as entrypoint do new domain Resolves: rhbz#1384769 - Add alias httpd__script_t to _script_t to make sepolicy generate working Resolves: rhbz#1271324 - Allow kprop_t domain to read network state Resolves: rhbz#1600705 - Allow sysadm_t domain to accept socket Resolves: rhbz#1557299 - Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow kprop_t domain to read network state Resolves: rhbz#1600705- Allow kpropd domain to exec itself Resolves: rhbz#1600705 - Allow ipmievd_t to mmap kernel modules BZ(1552535) - Allow hsqldb_t domain to mmap own temp files Resolves: rhbz#1612143 - Allow hsqldb_t domain to read cgroup files Resolves: rhbz#1612143 - Allow rngd_t domain to read generic certs Resolves: rhbz#1612456 - Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow virtlogd_t domain to chat via dbus with systemd_logind Resolves: rhbz#1593740- Allow sblim_sfcbd_t domain to mmap own tmpfs files Resolves: rhbz#1609384 - Update logging_manage_all_logs() interface to allow caller domain map all logfiles Resolves: rhbz#1592028- Dontaudit oracleasm_t domain to request sys_admin capability - Allow iscsid_t domain to load kernel module Resolves: rhbz#1589295 - Update rhcs contexts to reflects the latest fenced changes - Allow httpd_t domain to rw user_tmp_t files Resolves: rhbz#1608355 - /usr/libexec/udisks2/udisksd should be labeled as devicekit_disk_exec_t Resolves: rhbz#1521063 - Allow tangd_t dac_read_search Resolves: rhbz#1607810 - Allow glusterd_t domain to mmap user_tmp_t files - Allow mongodb_t domain to mmap own var_lib_t files Resolves: rhbz#1607729 - Allow iscsid_t domain to mmap sysfs_t files Resolves: rhbz#1602508 - Allow tomcat_domain to search cgroup dirs Resolves: rhbz#1600188 - Allow httpd_t domain to mmap own cache files Resolves: rhbz#1603505 - Allow cupsd_t domain to mmap cupsd_etc_t files Resolves: rhbz#1599694 - Allow kadmind_t domain to mmap krb5kdc_principal_t Resolves: rhbz#1601004 - Allow virtlogd_t domain to read virt_etc_t link files Resolves: rhbz#1598593 - Allow dirsrv_t domain to read crack db Resolves: rhbz#1599726 - Dontaudit pegasus_t to require sys_admin capability Resolves: rhbz#1374570 - Allow mysqld_t domain to exec mysqld_exec_t binary files - Allow abrt_t odmain to read rhsmcertd lib files Resolves: rhbz#1601389 - Allow winbind_t domain to request kernel module loads Resolves: rhbz#1599236 - Allow gpsd_t domain to getsession and mmap own tmpfs files Resolves: rhbz#1598388 - Allow smbd_t send to nmbd_t via dgram sockets BZ(1563791) Resolves: rhbz#1600157 - Allow tomcat_domain to read cgroup_t files Resolves: rhbz#1601151 - Allow varnishlog_t domain to mmap varnishd_var_lib_t files Resolves: rhbz#1600704 - Allow dovecot_auth_t domain to manage also dovecot_var_run_t fifo files. BZ(1320415) Resolves: rhbz#1600692 - Fix ntp SELinux module - Allow innd_t domain to mmap news_spool_t files Resolves: rhbz#1600591 - Allow haproxy daemon to reexec itself. BZ(1447800) Resolves: rhbz#1600578 - Label HOME_DIR/mozilla.pdf file as mozilla_home_t instead of user_home_t Resolves: rhbz#1559859 - Allow pkcs_slotd_t domain to mmap own tmpfs files Resolves: rhbz#1600434 - Allow fenced_t domain to reboot Resolves: rhbz#1293384 - Allow bluetooth_t domain listen on bluetooth sockets BZ(1549247) Resolves: rhbz#1557299 - Allow lircd to use nsswitch. BZ(1401375) - Allow targetd_t domain mmap lvm config files Resolves: rhbz#1546671 - Allow amanda_t domain to read network system state Resolves: rhbz#1452444 - Allow abrt_t domain to read rhsmcertd logs Resolves: rhbz#1492059 - Allow application_domain_type also mmap inherited user temp files BZ(1552765) Resolves: rhbz#1608421 - Allow ipsec_t domain to read l2tpd pid files Resolves: rhbz#1607994 - Allow systemd_tmpfiles_t do mmap system db files - Improve domain_transition_pattern to allow mmap entrypoint bin file. Resolves: rhbz#1460322 - Allow nsswitch_domain to mmap passwd_file_t files BZ(1518655) Resolves: rhbz#1600528 - Dontaudit syslogd to watching top llevel dirs when imfile module is enabled Resolves: rhbz#1601928 - Allow ipsec_t can exec ipsec_exec_t Resolves: rhbz#1600684 - Allow netutils_t domain to mmap usmmon device Resolves: rhbz#1600586 - Allow netlabel_mgmt_t domain to read sssd public files, stream connect to sssd_t BZ(1483655) - Allow userdomain sudo domains to use generic ptys Resolves: rhbz#1564470 - Allow traceroute to create icmp packets Resolves: rhbz#1548350 - Allow systemd domain to mmap lvm config files BZ(1594584) - Add new interface lvm_map_config - refpolicy: Update for kernel sctp support Resolves: rhbz#1597111 Add additional entries to support the kernel SCTP implementation introduced in kernel 4.16- Update oddjob_domtrans_mkhomedir() interface to allow caller domain also mmap oddjob_mkhomedir_exec_t files Resolves: rhbz#1596306 - Update rhcs_rw_cluster_tmpfs() interface to allow caller domain to mmap cluster_tmpfs_t files Resolves: rhbz#1589257 - Allow radiusd_t domain to read network sysctls Resolves: rhbz#1516233 - Allow chronyc_t domain to use nscd shm Resolves: rhbz#1596563 - Label /var/lib/tomcats dir as tomcat_var_lib_t Resolves: rhbz#1596367 - Allow lsmd_t domain to mmap lsmd_plugin_exec_t files Resolves: rhbz#bea0c8174 - Label /usr/sbin/rhn_check-[0-9]+.[0-9]+ as rpm_exec_t Resolves: rhbz#1596509 - Update seutil_exec_loadpolicy() interface to allow caller domain to mmap load_policy_exec_t files Resolves: rhbz#1596072 - Allow xdm_t to read systemd hwdb Resolves: rhbz#1596720 - Allow dhcpc_t domain to mmap files labeled as ping_exec_t Resolves: rhbz#1596065- Allow tangd_t domain to create tcp sockets Resolves: rhbz#1595775 - Update postfix policy to allow postfix_master_t domain to mmap all postfix* binaries Resolves: rhbz#1595328 - Allow amanda_t domain to have setgid capability Resolves: rhbz#1452444 - Update usermanage_domtrans_useradd() to allow caller domain to mmap useradd_exec_t files Resolves: rhbz#1595667- Allow abrt_watch_log_t domain to mmap binaries with label abrt_dump_oops_exec_t Resolves: rhbz#1591191 - Update cups_filetrans_named_content() to allow caller domain create ppd directory with cupsd_etc_rw_t label Resolves: rhbz#1452595 - Allow abrt_t domain to write to rhsmcertd pid files Resolves: rhbz#1492059 - Allow pegasus_t domain to eexec lvm binaries and allow read/write access to lvm control Resolves: rhbz#1463470 - Add vhostmd_t domain to read/write to svirt images Resolves: rhbz#1465276 - Dontaudit action when abrt-hook-ccpp is writing to nscd sockets Resolves: rhbz#1460715 - Update openvswitch policy Resolves: rhbz#1594729 - Update kdump_manage_kdumpctl_tmp_files() interface to allow caller domain also mmap kdumpctl_tmp_t files Resolves: rhbz#1583084 - Allow sssd_t and slpad_t domains to mmap generic certs Resolves: rhbz#1592016 Resolves: rhbz#1592019 - Allow oddjob_t domain to mmap binary files as oddjob_mkhomedir_exec_t files Resolves: rhbz#1592022 - Update dbus_system_domain() interface to allow system_dbusd_t domain to mmap binary file from second parameter Resolves: rhbz#1583080 - Allow chronyc_t domain use inherited user ttys Resolves: rhbz#1593267 - Allow stapserver_t domain to mmap own tmp files Resolves: rhbz#1593122 - Allow sssd_t domain to mmap files labeled as sssd_selinux_manager_exec_t Resolves: rhbz#1592026 - Update policy for ypserv_t domain Resolves: rhbz#1592032 - Allow abrt_dump_oops_t domain to mmap all non security files Resolves: rhbz#1593728 - Allow svirt_t domain mmap svirt_image_t files Resolves: rhbz#1592688 - Allow virtlogd_t domain to write inhibit systemd pipes. Resolves: rhbz#1593740 - Allow sysadm_t and staff_t domains to use sudo io logging Resolves: rhbz#1564470 - Allow sysadm_t domain create sctp sockets Resolves: rhbz#1571591 - Update mount_domtrans() interface to allow caller domain mmap mount_exec_t Resolves: rhbz#1592025 - Allow dhcpc_t to mmap all binaries with label hostname_exec_t, ifconfig_exec_t and netutils_exec_t Resolves: rhbz#1594661- Fix typo in logwatch interface file - Allow spamd_t to manage logwatch_cache_t files/dirs - Allow dnsmasw_t domain to create own tmp files and manage mnt files - Allow fail2ban_client_t to inherit rlimit information from parent process Resolves: rhbz#1513100 - Allow nscd_t to read kernel sysctls Resolves: rhbz#1512852 - Label /var/log/conman.d as conman_log_t Resolves: rhbz#1538363 - Add dac_override capability to tor_t domain Resolves: rhbz#1540711 - Allow certmonger_t to readwrite to user_tmp_t dirs Resolves: rhbz#1543382 - Allow abrt_upload_watch_t domain to read general certs Resolves: rhbz#1545098 - Update postfix_domtrans_master() interface to allow caller domain also mmap postfix_master_exec_t binary Resolves: rhbz#1583087 - Allow postfix_domain to mmap postfix_qmgr_exec_t binaries Resolves: rhbz#1583088 - Allow postfix_domain to mmap postfix_pickup_exec_t binaries Resolves: rhbz#1583091 - Allow chornyd_t read phc2sys_t shared memory Resolves: rhbz#1578883 - Allow virt_qemu_ga_t read utmp Resolves: rhbz#1571202 - Add several allow rules for pesign policy: Resolves: rhbz#1468744 - Allow pesign domain to read /dev/random - Allow pesign domain to create netlink_kobject_uevent_t sockets - Allow pesign domain create own tmp files - Add setgid and setuid capabilities to mysqlfd_safe_t domain Resolves: rhbz#1474440 - Add tomcat_can_network_connect_db boolean Resolves: rhbz#1477948 - Update virt_use_sanlock() boolean to read sanlock state Resolves: rhbz#1448799 - Add sanlock_read_state() interface - Allow postfix_cleanup_t domain to stream connect to all milter sockets BZ(1436026) Resolves: rhbz#1563423 - Update abrt_domtrans and abrt_exec() interfaces to allow caller domain to mmap binary file Resolves:rhbz#1583080 - Update nscd_domtrans and nscd_exec interfaces to allow caller domain also mmap nscd binaries Resolves: rhbz#1583086 - Update snapperd_domtrans() interface to allow caller domain to mmap snapperd_exec_t file Resolves: rhbz#1583802 - Allow zoneminder_t to getattr of fs_t Resolves: rhbz#1585328 - Fix denials during ipa-server-install process on F27+ Resolves: rhbz#1586029 - Allow ipa_dnskey_t to exec ipa_dnskey_exec_t files Resolves: rhbz#1586033 - Allow rhsmcertd_t domain to send signull to postgresql_t domain Resolves: rhbz#1588119 - Allow policykit_t domain to dbus chat with dhcpc_t Resolves: rhbz#1364513 - Adding new boolean keepalived_connect_any() Resolves: rhbz#1443473 - Allow amanda to create own amanda_tmpfs_t files Resolves: rhbz#1452444 - Add amanda_tmpfs_t label. BZ(1243752) - Allow gdomap_t domain to connect to qdomap_port_t Resolves: rhbz#1551944 - Fix typos in sge - Fix typo in openvswitch policy - /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow sshd_keygen_t to execute plymouthd Resolves: rhbz#1583531 - Update seutil_domtrans_setfiles() interface to allow caller domain to do mmap on setfiles_exec_t binary Resolves: rhbz#1583090 - Allow systemd_networkd_t create and relabel tun sockets Resolves: rhbz#1583830 - Allow map audisp_exec_t files fordomains executing this binary Resolves: rhbz#1586042 - Add new interface postgresql_signull() - Add fs_read_xenfs_files() interface.- /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow dac override capability to mandb_t domain BZ(1529399) Resolves: rhbz#1423361 - Allow inetd_child process to chat via dbus with abrt Resolves: rhbz#1428805 - Allow zabbix_agent_t domain to connect to redis_port_t Resolves: rhbz#1418860 - Allow rhsmcertd_t domain to read xenfs_t files Resolves: rhbz#1405870 - Allow zabbix_agent_t to run zabbix scripts Resolves: rhbz#1380697 - Allow rabbitmq_t domain to create own tmp files/dirs Resolves: rhbz#1546897 - Allow policykit_t mmap policykit_auth_exec_t files Resolves: rhbz#1583082 - Allow ipmievd_t domain to read general certs Resolves: rhbz#1514591 - Add sys_ptrace capability to pcp_pmie_t domain - Allow squid domain to exec ldconfig Resolves: rhbz#1532017 - Make working gpg agent in gpg_agent_t domain Resolves: rhbz#1535109 - Update gpg SELinux policy module - Allow kexec to read kernel module files in /usr/lib/modules. Resolves: rhbz#1536690 - Allow mailman_domain to read system network state Resolves: rhbz#1413510 - Allow mailman_mail_t domain to search for apache configs Resolves: rhbz#1413510 - Allow openvswitch_t domain to read neutron state and read/write fixed disk devices Resolves: rhbz#1499208 - Allow antivirus_domain to read all domain system state Resolves: rhbz#1560986 - Allow targetd_t domain to red gconf_home_t files/dirs Resolves: rhbz#1546671 - Allow freeipmi domain to map sysfs_t files Resolves: rhbz#1575918 - Label /usr/libexec/bluetooth/obexd as obexd_exec_t Resolves: rhbz#1351750 - Update rhcs SELinux module Resolves: rhbz#1589257 - Allow iscsid_t domain mmap kernel modules Resolves: rhbz#1589295 - Allow iscsid_t domain mmap own tmp files Resolves: rhbz#1589295 - Update iscsid_domtrans() interface to allow mmap iscsid_exec_t binary Resolves: rhbz#1589295 - Update nscd_socket_use interface to allow caller domain also mmap nscd_var_run_t files. Resolves: rhbz#1589271 - Allow nscd_t domain to mmap system_db_t files Resolves: rhbz#1589271 - Add interface nagios_unconfined_signull() - Allow lircd_t domain read sssd public files Add setgid capability to lircd_t domain Resolves: rhbz#1550700 - Add missing requires - Allow tomcat domain sends email Resolves: rhbz#1585184 - Allow memcached_t domain nnp_transition becuase of systemd security features BZ(1514867) Resolves: rhbz#1585714 - Allow kdump_t domain to map /boot files Resolves: rhbz#1588884 - Fix typo in netutils policy - Allow confined users get AFS tokens Resolves: rhbz#1417671 - Allow sysadm_t domain to chat via dbus Resolves: rhbz#1582146 - Associate sysctl_kernel_t type with filesystem attribute - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Add interface dev_map_sysfs - Allow xdm_t domain to execute xdm_var_lib_t files Resolves: rhbz#1589139 - Allow syslogd_t domain to send signull to nagios_unconfined_plugin_t Resolves: rhbz#1569344 - Label /dev/vhost-vsock char device as vhost_device_t - Add files_map_boot_files() interface Resolves: rhbz#1588884 - Update traceroute_t domain to allow create dccp sockets Resolves: rhbz#1548350- Update ctdb domain to support gNFS setup Resolves: rhbz#1576818 - Allow authconfig_t dbus chat with policykit Resolves: rhbz#1551241 - Allow lircd_t domain to read passwd_file_t Resolves: rhbz:#1550700 - Allow lircd_t domain to read system state Resolves: rhbz#1550700 - Allow smbcontrol_t to mmap samba_var_t files and allow winbind create sockets BZ(1559795) Resolves: rhbz#1574521 - Allow tangd_t domain read certs Resolves: rhbz#1509055 - Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow ctdb_t domain modify ctdb_exec_t files Resolves: rhbz#1572584 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Allow SELinux users (except guest and xguest) to using bluetooth sockets Resolves: rhbz#1557299 - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Fix broken sysadm SELinux module Resolves: rhbz#1557311 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Update ssh_domtrans_keygen interface to allow mmap ssh_keygen_exec_t binary file Resolves: rhbz#1583089 - Allow systemd_networkd_t to read/write tun tap devices Resolves: rhbz#1583830 - Add bridge_socket, dccp_socket, ib_socket and mpls_socket to socket_class_set Resolves: rhbz#1583771 - Allow audisp_t domain to mmap audisp_exec_t binary Resolves: rhbz#1583551 - Fix duplicates in sysadm.te file Resolves: rhbz#1307183 - Allow sysadm_u use xdm Resolves: rhbz#1307183 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix duplicates in sysadm.te file Resolves: rhbz#1307183- Allow sysadm_u use xdm Resolves: rhbz#1307183- Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Improve procmail_domtrans() to allow mmaping procmail_exec_t - Allow hypervvssd_t domain to read fixed disk devices Resolves: rhbz#1581225 - Improve modutils_domtrans_insmod() interface to mmap insmod_exec_t binaries Resolves: rhbz#1581551 - Improve iptables_domtrans() interface to allow mmaping iptables_exec_t binary Resolves: rhbz#1581551 - Improve auth_domtrans_login_programinterface to allow also mmap login_exec_t binaries Resolves: rhbz#1581551 - Improve auth_domtrans_chk_passwd() interface to allow also mmaping chkpwd_exec_t binaries. Resolves: rhbz#1581551 - Allow mmap dhcpc_exec_t binaries in sysnet_domtrans_dhcpc interface- Add dbus_stream_connect_system_dbusd() interface. - Allow pegasus_t domain to mount tracefs_t filesystem Resolves:rhbz#1374570 - Allow psad_t domain to read all domains state Resolves: rhbz#1558439 - Add net_raw capability to named_t domain BZ(1545586) - Allow tomcat_t domain to connect to mongod_t tcp port Resolves:rhbz#1539748 - Allow dovecot and postfix to connect to systemd stream sockets Resolves: rhbz#1368642 - Label /usr/libexec/bluetooth/obexd as bluetoothd_exec_t to run process as bluetooth_t Resolves:rhbz#1351750 - Rename tang policy to tangd - Add interface systemd_rfkill_domtrans() - Allow users staff and sysadm to run wireshark on own domain Resolves:rhbz#1546362 - Allow systemd-bootchart to create own tmpfs files Resolves:rhbz#1510412- Rename tang policy to tangd - Allow virtd_t domain to relabel virt_var_lib_t files Resolves: rhbz#1558121 - Allow logrotate_t domain to stop services via systemd Resolves: rhbz#1527522 - Add tang policy Resolves: rhbz#1509055 - Allow mozilla_plugin_t to create mozilla.pdf file in user homedir with label mozilla_home_t Resolves: rhbz#1559859 - Improve snapperd SELinux policy Resolves: rhbz#1365555 - Allow snapperd_t daemon to create unlabeled dirs. Resolves: rhbz#1365555 - We have inconsistency in cgi templates with upstream, we use _content_t, but refpolicy use httpd__content_t. Created aliasses to make it consistence Resolves: rhbz#1271324 - Allow Openvswitch adding netdev bridge ovs 2.7.2.10 FDP Resolves: rhbz#1503835 - Add new Boolean tomcat_use_execmem Resolves: rhbz#1565226 - Allow domain transition from logrotate_t to chronyc_t Resolves: rhbz#1568281 - Allow nfsd_t domain to read/write sysctl fs files Resolves: rhbz#1516593 - Allow conman to read system state Resolves: rhbz#1377915 - Allow lircd_t to exec shell and add capabilities dac_read_search and dac_override Resolves: rhbz#1550700 - Allow usbmuxd to access /run/udev/data/+usb:*. Resolves: rhbz#1521054 - Allow abrt_t domain to manage kdump crash files Resolves: rhbz#1491585 - Allow systemd to use virtio console Resolves: rhbz#1558121 - Allow transition from sysadm role into mdadm_t domain. Resolves: rhbz#1551568 - Label /dev/op_panel and /dev/opal-prd as opal_device_t Resolves: rhbz#1537618 - Label /run/ebtables.lock as iptables_var_run_t Resolves: rhbz#1511437 - Allow udev_t domain to manage udev_rules_t char files. Resolves: rhbz#1545094 - Allow nsswitch_domain to read virt_var_lib_t files, because of libvirt NSS plugin. Resolves: rhbz#1567753 - Fix filesystem inteface file, we don't have nsfs_fs_t type, just nsfs_t Resolves: rhbz#1547700 - Allow iptables_t domain to create dirs in etc_t with system_conf_t labels- Add new boolean redis_enable_notify() Resolves: rhbz#1421326 - Label /var/log/shibboleth-www(/.*) as httpd_sys_rw_content_t Resolves: rhbz#1549514 - Add new label for vmtools scripts and label it as vmtools_unconfined_t stored in /etc/vmware-tools/ Resolves: rbhz#1463593 - Remove labeling for /etc/vmware-tools to bin_t it should be vmtools_unconfined_exec_t Resolves: rbhz#1463593- Backport several changes for snapperdfrom Fedora Rawhide Resolves: rhbz#1556798 - Allow snapperd_t to set priority for kernel processes Resolves: rhbz#1556798 - Make ganesha nfs server. Resolves: rhbz#1511489 - Allow vxfs filesystem to use SELinux labels Resolves: rhbz#1482880 - Add map permission to selinux-policy Resolves: rhbz#1460322- Label /usr/libexec/dbus-1/dbus-daemon-launch-helper as dbusd_exec_t to have systemd dbus services running in the correct domain instead of unconfined_service_t if unconfined.pp module is enabled. Resolves: rhbz#1546721- Allow openvswitch_t stream connect svirt_t Resolves: rhbz#1540702- Allow openvswitch domain to manage svirt_tmp_t sock files Resolves: rhbz#1540702 - Fix broken systemd_tmpfiles_run() interface- Allow dirsrv_t domain to create tmp link files Resolves: rhbz#1536011 - Label /usr/sbin/ldap-agent as dirsrv_snmp_exec_t Resolves: rhbz#1428568 - Allow ipsec_mgmt_t execute ifconfig_exec_t binaries - Allow ipsec_mgmt_t nnp domain transition to ifconfig_t Resolves: rhbz#1539416- Allow svirt_domain to create socket files in /tmp with label svirt_tmp_t Resolves: rhbz#1540702 - Allow keepalived_t domain getattr proc filesystem Resolves: rhbz#1477542 - Rename svirt_sandbox_file_t to container_file_t and svirt_lxc_net_t to container_t Resolves: rhbz#1538544 - Allow ipsec_t nnp transistions to domains ipsec_mgmt_t and ifconfig_t Resolves: rhbz:#1539416 - Allow systemd_logind_t domain to bind on dhcpd_port_t,pki_ca_port_t,flash_port_t Resolves: rhbz#1479350- Allow openvswitch_t domain to read cpuid, write to sysfs files and creating openvswitch_tmp_t sockets Resolves: rhbz#1535196 - Add new interface ppp_filetrans_named_content() Resolves: rhbz#1530601 - Allow keepalived_t read sysctl_net_t files Resolves: rhbz#1477542 - Allow puppetmaster_t domtran to puppetagent_t Resolves: rhbz#1376893 - Allow kdump_t domain to read kernel ring buffer Resolves: rhbz#1540004 - Allow ipsec_t domain to exec ifconfig_exec_t binaries. Resolves: rhbz#1539416 - Allow unconfined_domain_typ to create pppd_lock_t directory in /var/lock Resolves: rhbz#1530601 - Allow updpwd_t domain to create files in /etc with shadow_t label Resolves: rhbz#1412838 - Allow iptables sysctl load list support with SELinux enforced Resolves: rhbz#1535572- Allow virt_domains to acces infiniband pkeys. Resolves: rhbz#1533183 - Label /usr/libexec/ipsec/addconn as ipsec_exec_t to run this script as ipsec_t instead of init_t Resolves: rhbz#1535133 - Allow audisp_remote_t domain write to files on all levels Resolves: rhbz#1534924- Allow vmtools_t domain creating vmware_log_t files Resolves: rhbz#1507048 - Allow openvswitch_t domain to acces infiniband devices Resolves: rhbz#1532705- Allow chronyc_t domain to manage chronyd_keys_t files. Resolves: rhbz#1530525 - Make virtlog_t domain system dbus client Resolves: rhbz#1481109 - Update openvswitch SELinux module Resolves: rhbz#1482682 - Allow virtd_t to create also sock_files with label virt_var_run_t Resolves: rhbz#1484075- Allow domains that manage logfiles to man logdirs Resolves: rhbz#1523811- Label /dev/drm_dp_aux* as xserver_misc_device_t Resolves: rhbz#1520897 - Allow sysadm_t to run puppet_exec_t binaries as puppet_t Resolves: rhbz#1255745- Allow tomcat_t to manage pki_tomcat pid files Resolves: rhbz#1478371 - networkmanager: allow talking to openvswitch Resolves: rhbz#1517247 - Allow networkmanager_t and opensm_t to manage subned endports for IPoIB VLANs Resolves: rhbz#1517895 - Allow domains networkmanager_t and opensm_t to control IPoIB VLANs Resolves: rhbz#1517744 - Fix typo in guest interface file Resolves: rhbz#1468254 - Allow isnsd_t domain to accept tcp connections. Resolves: rhbz#1390208- Allow getty to use usbttys Resolves: rhbz#1514235- Allow ldap_t domain to manage also slapd_tmp_t lnk files Resolves: rhbz#1510883 - Allow cluster_t domain creating bundles directory with label var_log_t instead of cluster_var_log_t Resolves: rhbz:#1508360 - Add dac_read_search and dac_override capabilities to ganesha Resolves: rhbz#1483451- Add dependency for policycoreutils-2.5.18 becuase of new cgroup_seclabel policy capability Resolves: rhbz#1510145- Allow jabber domains to connect to postgresql ports Resolves: rhbz#1438489 - Dontaudit accountsd domain creating dirs in /root Resolves: rhbz#1456760 - Dontaudit slapd_t to block suspend system Resolves: rhbz: #1479759 - Allow spamc_t to stream connect to cyrus. Resolves: rhbz#1382955 - allow imapd to read /proc/net/unix file Resolves: rhbz#1393030 - Allow passenger to connect to mysqld_port_t Resolves: rhbz#1433464- Allow chronyc_t domain to use user_ptys Resolves: rhbz#1470150 - allow ptp4l to read /proc/net/unix file - Allow conmand to use usb ttys. Resolves: rhbz#1505121 - Label all files /var/log/opensm.* as opensm_log_t because opensm creating new log files with name opensm-subnet.lst Resolves: rhbz#1505845 - Allow chronyd daemon to execute chronyc. Resolves: rhbz#1508486 - Allow firewalld exec ldconfig. Resolves: rhbz#1375576 - Allow mozilla_plugin_t domain to dbus chat with devicekit Resolves: rhbz#1460477 - Dontaudit leaked logwatch pipes Resolves: rhbz#1450119 - Label /usr/bin/VGAuthService as vmtools_exec_t to confine this daemon. Resolves: rhbz#1507048 - Allow httpd_t domain to execute hugetlbfs_t files Resolves: rhbz#1507682 - Allow nfsd_t domain to read configfs_t files/dirs Resolves: rhbz#1439442 - Hide all allow rules with ptrace inside deny_ptrace boolean Resolves: rhbz#1421075 - Allow tgtd_t domain to read generic certs Resolves: rhbz#1438532 - Allow ptp4l to send msgs via dgram socket to unprivileged user domains Resolves: rhbz#1429853 - Allow dirsrv_snmp_t to use inherited user ptys and read system state Resolves: rhbz#1428568 - Allow glusterd_t domain to create own tmpfs dirs/files Resolves: rhbz#1411310 - Allow keepalived stream connect to snmp Resolves: rhbz#1401556 - After fix in kernel where LSM hooks for dac_override and dac_search_read capability was swaped we need to fix it also in policy Resolves: rhbz#1507089- Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow chronyd_t do request kernel module and block_suspend capability Resolves: rhbz#1350765 - Allow system_cronjob_t to create /var/lib/letsencrypt dir with right label Resolves: rhbz#1447278 - Allow httpd_t also read httpd_user_content_type dirs when httpd_enable_homedirs is enables Resolves: rhbz#1491994 - Allow svnserve to use kerberos Resolves: rhbz#1475271 - Allow conman to use ptmx. Add conman_use_nfs boolean Resolves: rhbz#1377915 - Add nnp transition for services using: NoNewPrivileges systemd security feature Resolves: rhbz#1311430 - Add SELinux support for chronyc Resolves: rhbz#1470150 - Add dac_read_search capability to openvswitch_t domain Resolves: rhbz#1501336 - Allow svnserve to manage own svnserve_log_t files/dirs Resolves: rhbz#1480741 - Allow keepalived_t to search network sysctls Resolves: rhbz#1477542 - Allow puppetagent_t domain dbus chat with rhsmcertd_t domain Resolves: rhbz#1446777 - Add dccp_socket into socker_class_set subset Resolves: rhbz#1459941 - Allow iptables_t to run setfiles to restore context on system Resolves: rhbz#1489118 - Label 20514 tcp/udp ports as syslogd_port_t Label 10514 tcp/udp portas as syslog_tls_port_t Resolves: rhbz:#1411400 - Make nnp transition Active Resolves: rhbz#1480518 - Label tcp 51954 as isns_port_t Resolves: rhbz#1390208 - Add dac_read_search capability chkpwd_t Resolves: rhbz#1376991 - Add support for running certbot(letsencrypt) in crontab Resolves: rhbz#1447278 - Add init_nnp_daemon_domain interface - Allow xdm_t to gettattr /dev/loop-control device Resolves: rhbz#1462925 - Allow nnp trasintion for unconfined_service_t Resolves: rhbz#1311430 - Allow unpriv user domains and unconfined_service_t to use chronyc Resolves: rhbz#1470150 - Allow iptables to exec plymouth. Resolves: rhbz#1480374 - Fix typo in fs_unmount_tracefs interface. Resolves: rhbz#1371057 - Label postgresql-check-db-dir as postgresql_exec_t Resolves: rhbz#1490956- We should not ship selinux-policy with permissivedomains enabled. Resolves: rhbz#1494172 - Fix order of installing selinux-policy-sandbox, because of depedencied in sandbox module, selinux-policy-targeted needs to be installed before selinux-policy-sandbox Resolves: rhbz#1492606- Allow tomcat to setsched Resolves: rhbz#1492730 - Fix rules blocking ipa-server upgrade process Resolves: rhbz#1478371 - Add new boolean tomcat_read_rpm_db() Resolves: rhbz#1477887 - Allow tomcat to connect on mysqld tcp ports - Add ctdbd_t domain sys_source capability and allow setrlimit Resolves: rhbz#1491235 - Fix keepalived SELinux module - Allow automount domain to manage mount pid files Resolves: rhbz#1482381 - Allow stunnel_t domain setsched Resolves: rhbz#1479383 - Add keepalived domain setpgid capability Resolves: rhbz#1486638 - Allow tomcat domain to connect to mssql port Resolves: rhbz#1484572 - Remove snapperd_t from unconfined domaines Resolves: rhbz#1365555 - Fix typo bug in apache module Resolves: rhbz#1397311 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Add interface systemd_tmpfiles_run - End of file cannot be in comment - Allow systemd-logind to use ypbind Resolves: rhbz#1479350 - Add creating opasswd file with shadow_t SELinux label in auth_manage_shadow() interface Resolves: rhbz#1412838 - Allow sysctl_irq_t assciate with proc_t Resolves: rhbz#1485909 - Enable cgourp sec labeling Resolves: rhbz#1485947 - Add cgroup_seclabel policycap. Resolves: rhbz#1485947 - Allow sshd_t domain to send signull to xdm_t processes Resolves: rhbz#1448959 - Allow updpwd_t domain auth file name trans Resolves: rhbz#1412838 - Allow sysadm user to run systemd-tmpfiles Resolves: rbhz#1325364 - Add support labeling for vmci and vsock device Resolves: rhbz#1451358 - Add userdom_dontaudit_manage_admin_files() interface Resolves: rhbz#1323792 - Allow iptables_t domain to read files with modules_conf_t label Resolves: rhbz#1373220 - init: Add NoNewPerms support for systemd. Resolves: rhbz#1480518 - Add nnp_nosuid_transition policycap and related class/perm definitions. Resolves: rhbz#1480518 - refpolicy: Infiniband pkeys and endports Resolves: rhbz#1464484- Allow certmonger using systemctl on pki_tomcat unit files Resolves: rhbz#1481388- Allow targetd_t to create own tmp files. - Dontaudit targetd_t to exec rpm binary file. Resolves: rhbz#1373860 Resolves: rhbz#1424621- Add few rules to make working targetd daemon with SELinux Resolves: rhbz#1373860 - Allow ipmievd_t domain to load kernel modules Resolves: rhbz#1441081 - Allow logrotate to reload transient systemd unit Resolves: rhbz#1440515 - Add certwatch_t domain dac_override and dac_read_search capabilities Resolves: rhbz#1422000 - Allow postgrey to execute bin_t files and add postgrey into nsswitch_domain Resolves: rhbz#1412072 - Allow nscd_t domain to search network sysctls Resolves: rhbz#1432361 - Allow iscsid_t domain to read mount pid files Resolves: rhbz#1482097 - Allow ksmtuned_t domain manage sysfs_t files/dirs Resolves: rhbz#1413865 - Allow keepalived_t domain domtrans into iptables_t Resolves: rhbz#1477719 - Allow rshd_t domain reads net sysctls Resolves: rhbz#1477908 - Add interface seutil_dontaudit_read_module_store() - Update interface lvm_rw_pipes() by adding also open permission - Label /dev/clp device as vfio_device_t Resolves: rhbz#1477624 - Allow ifconfig_t domain unmount fs_t Resolves: rhbz#1477445 - Label /dev/gpiochip* devices as gpio_device_t Resolves: rhbz#1477618 - Add interface dev_manage_sysfs() Resolves: rhbz#1474989- Label /usr/libexec/sudo/sesh as shell_exec_t Resolves: rhbz#1480791- Allow tomcat_t domain couple capabilities to make working tomcat-jsvc Resolves: rhbz#1470735- Allow llpdad send dgram to libvirt Resolves: rhbz#1472722- Add new boolean gluster_use_execmem Resolves: rhbz#1469027 - Allow cluster_t and glusterd_t domains to dbus chat with ganesha service Resolves: rhbz#1468581- Dontaudit staff_t user read admin_home_t files. Resolves: rhbz#1290633- Allow couple rules needed to start targetd daemon with SELinux in enforcing mode Resolves: rhbz#1424621 - Add interface lvm_manage_metadata Resolves: rhbz#1424621- Allow sssd_t to read realmd lib files. Resolves: rhbz#1436689 - Add permission open to files_read_inherited_tmp_files() interface Resolves: rhbz#1290633 Resolves: rhbz#1457106- Allow unconfined_t user all user namespace capabilties. Resolves: rhbz#1461488- Allow httpd_t to read realmd_var_lib_t files Resolves: rhbz#1436689- Allow named_t to bind on udp 4321 port Resolves: rhbz#1312972 - Allow systemd-sysctl cap. sys_ptrace Resolves: rhbz#1458999- Allow pki_tomcat_t execute ldconfig. Resolves: rhbz#1436689- Allow iscsi domain load kernel module. Resolves: rhbz#1457874 - Allow keepalived domain connect to squid tcp port Resolves: rhbz#1457455 - Allow krb5kdc_t domain read realmd lib files. Resolves: rhbz#1436689 - xdm_t should view kernel keys Resolves: rhbz#1432645- Allow tomcat to connect on all unreserved ports - Allow ganesha to connect to all rpc ports Resolves: rhbz#1448090 - Update ganesha with another fixes. Resolves: rhbz#1448090 - Update rpc_read_nfs_state_data() interface to allow read also lnk_files. Resolves: rhbz#1448090 - virt_use_glusterd boolean should be in optional block Update ganesha module to allow create tmp files Resolves: rhbz#1448090 - Hide broken symptoms when machine is configured with network bounding.- Add new boolean virt_use_glusterd Resolves: rhbz#1455994 - Add capability sys_boot for sbd_t domain - Allow sbd_t domain to create rpc sysctls. Resolves: rhbz#1455631 - Allow ganesha_t domain to manage glusterd_var_run_t pid files. Resolves: rhbz#1448090- Create new interface: glusterd_read_lib_files() - Allow ganesha read glusterd lib files. - Allow ganesha read network sysctls Resolves: rhbz#1448090- Add few allow rules to ganesha module Resolves: rhbz#1448090 - Allow condor_master_t to read sysctls. Resolves: rhbz#1277506 - Add dac_override cap to ctdbd_t domain Resolves: rhbz#1435708 - Label 8750 tcp/udp port as dey_keyneg_port_t Resolves: rhbz#1448090- Add ganesha_use_fusefs boolean. Resolves: rhbz#1448090- Allow httpd_t reading kerberos kdc config files Resolves: rhbz#1452215 - Allow tomcat_t domain connect to ibm_dt_2 tcp port. Resolves: rhbz#1447436 - Allow stream connect to initrc_t domains Resolves: rhbz#1447436 - Allow dnsmasq_t domain to read systemd-resolved pid files. Resolves: rhbz#1453114 - Allow tomcat domain name_bind on tcp bctp_port_t Resolves: rhbz#1451757 - Allow smbd_t domain generate debugging files under /var/run/gluster. These files are created through the libgfapi.so library that provides integration of a GlusterFS client in the Samba (vfs_glusterfs) process. Resolves: rhbz#1447669 - Allow condor_master_t write to sysctl_net_t Resolves: rhbz#1277506 - Allow nagios check disk plugin read /sys/kernel/config/ Resolves: rhbz#1277718 - Allow pcp_pmie_t domain execute systemctl binary Resolves: rhbz#1271998 - Allow nagios to connect to stream sockets. Allow nagios start httpd via systemctl Resolves: rhbz#1247635 - Label tcp/udp port 1792 as ibm_dt_2_port_t Resolves: rhbz#1447436 - Add interface fs_read_configfs_dirs() - Add interface fs_read_configfs_files() - Fix systemd_resolved_read_pid interface - Add interface systemd_resolved_read_pid() Resolves: rhbz#1453114 - Allow sshd_net_t domain read/write into crypto devices Resolves: rhbz#1452759 - Label 8999 tcp/udp as bctp_port_t Resolves: rhbz#1451757- nmbd_t needs net_admin capability like smbd Resolves: rhbz#1431859 - Dontaudit net_admin capability for domains postfix_master_t and postfix_qmgr_t Resolves: rhbz#1431859 - Allow rngd domain read sysfs_t Resolves: rhbz#1451735 - Add interface pki_manage_common_files() Resolves: rhbz#1447436 - Allow tomcat_t domain to manage pki_common_t files and dirs Resolves: rhbz#1447436 - Use stricter fc rules for sssd sockets in /var/run Resolves: rhbz#1448060 - Allow certmonger reads httpd_config_t files Resolves: rhbz#1436689 - Allow keepalived_t domain creating netlink_netfilter_socket. Resolves: rhbz#1451684 - Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321- Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Allow sssd_t domain creating sock files labeled as sssd_var_run_t in /var/run/ Resolves: rhbz#1448056 Resolves: rhbz#1448060 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321 - Allow netutils setpcap capability Resolves:1444438- Update targetd policy to accommodate changes in the service Resolves: rhbz#1424621 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Update virt_rw_stream_sockets_svirt() interface to allow confined users set socket options. Resolves: rhbz#1415841 - Allow radius domain stream connec to postgresql Resolves: rhbz#1446145 - Allow virt_domain to read raw fixed_disk_device_t to make working blockcommit Resolves: rhbz#1449977 - Allow glusterd_t domain start ganesha service Resolves: rhbz#1448090 - Made few cosmetic changes in sssd SELinux module Resolves: rhbz#1448060 - sssd-kcm should not run as unconfined_service_t BZ(1447411) Resolves: rhbz#1448060 - Add sssd_secrets labeling Also add named_filetrans interface to make sure all labels are correct Resolves: rhbz#1448056 - Allow keepalived_t domain read usermodehelper_t Resolves: rhbz#1449769 - Allow tomcat_t domain read pki_common_t files Resolves: rhbz#1447436 - Add interface pki_read_common_files() Resolves: rhbz#1447436- Allow hypervkvp_t domain execute hostname Resolves: rhbz#1449064 - Dontaudit sssd_selinux_manager_t use of net_admin capability Resolves: rhbz#1444955 - Allow tomcat_t stream connect to pki_common_t Resolves: rhbz#1447436 - Dontaudit xguest_t's attempts to listen to its tcp_socket - Allow sssd_selinux_manager_t to ioctl init_t sockets Resolves: rhbz#1436689 - Allow _su_t to create netlink_selinux_socket Resolves rhbz#1146987 - Allow unconfined_t to module_load any file Resolves rhbz#1442994- Improve ipa_cert_filetrans_named_content() interface to also allow caller domain manage ipa_cert_t type. Resolves: rhbz#1436689- Allow pki_tomcat_t domain read /etc/passwd. Resolves: rhbz#1436689 - Allow tomcat_t domain read ipa_tmp_t files Resolves: rhbz#1436689 - Label new path for ipa-otpd Resolves: rhbz#1446353 - Allow radiusd_t domain stream connect to postgresql_t Resolves: rhbz#1446145 - Allow rhsmcertd_t to execute hostname_exec_t binaries. Resolves: rhbz#1445494 - Allow virtlogd to append nfs_t files when virt_use_nfs=1 Resolves: rhbz#1402561- Update tomcat policy to adjust for removing unconfined_domain attr. Resolves: rhbz#1432083 - Allow httpd_t domain read also httpd_user_content_type lnk_files. Resolves: rhbz#1383621 - Allow httpd_t domain create /etc/httpd/alias/ipaseesion.key with label ipa_cert_t Resolves: rhbz#1436689 - Dontaudit _gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Label /var/www/html/nextcloud/data as httpd_sys_rw_content_t Resolves: rhbz#1425530 - Add interface ipa_filetrans_named_content() Resolves: rhbz#1432115 - Allow tomcat use nsswitch Resolves: rhbz#1436689 - Allow certmonger_t start/status generic services Resolves: rhbz#1436689 - Allow dirsrv read cgroup files. Resolves: rhbz#1436689 - Allow ganesha_t domain read/write infiniband devices. Resolves: rhbz#1383784 - Allow sendmail_t domain sysctl_net_t files Resolves: rhbz#1369376 - Allow targetd_t domain read network state and getattr on loop_control_device_t Resolves: rhbz#1373860 - Allow condor_schedd_t domain send mails. Resolves: rhbz#1277506 - Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689 - Allow staff to systemctl virt server when staff_use_svirt=1 Resolves: rhbz#1415841 - Allow unconfined_t create /tmp/ca.p12 file with ipa_tmp_t context Resolves: rhbz#1432115 - Label /sysroot/ostree/deploy/rhel-atomic-host/* as root_t Resolves: rhbz#1428112- Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689- Hide broken symptoms when using kernel 3.10.0-514+ with network bonding. Postfix_picup_t domain requires NET_ADMIN capability which is not really needed. Resolves: rhbz#1431859 - Fix policy to reflect all changes in new IPA release Resolves: rhbz#1432115 Resolves: rhbz#1436689- Allow sbd_t to read/write fixed disk devices Resolves: rhbz#1440165 - Add sys_ptrace capability to radiusd_t domain Resolves: rhbz#1426641 - Allow cockpit_session_t domain connects to ssh tcp ports. Resolves: rhbz#1413509- Update tomcat policy to make working ipa install process Resolves: rhbz#1436689- Allow pcp_pmcd_t net_admin capability. - Allow pcp_pmcd_t read net sysctls - Allow system_cronjob_t create /var/run/pcp with pcp_var_run_t Resolves: rhbz#1336211- Fix all AVC denials during pkispawn of CA Resolves: rhbz#1436383 - Update pki interfaces and tomcat module Resolves: rhbz#1436689- Update pki interfaces and tomcat module Resolves: rhbz#1436689- Dontaudit firewalld wants write to /root Resolves: rhbz#1438708 - Dontaudit firewalld to create dirs in /root/ Resolves: rhbz#1438708 - Allow sendmail to search network sysctls Resolves: rhbz#1369376 - Add interface gssd_noatsecure() Resolves: rhbz#1438036 - Add interface gssproxy_noatsecure() Resolves: rhbz#1438036 - Dontaudit pcp_pmlogger_t search for xserver logs. Allow pcp_pmlogger_t to send signals to unconfined doamins Allow pcp_pmlogger_t to send logs to journals Resolves: rhbz#1379371 - Allow chronyd_t net_admin capability to allow support HW timestamping. Resolves: rhbz#1416015 - Update tomcat policy Resolves: rhbz#1436689 Resolves: rhbz#1436383 - Allow certmonger to start haproxy service Resolves: rhbz#1349394 - Allow init noatsecure for gssd and gssproxy Resolves: rhbz#1438036- geoclue wants to dbus chat with avahi Resolves: rhbz#1434286 - Allow iptables get list of kernel modules Resolves: rhbz#1367520 - Allow unconfined_domain_type to enable/disable transient unit Resolves: rhbz#1337041 - Add interfaces init_enable_transient_unit() and init_disable_transient_unit - Revert "Allow sshd setcap capability. This is needed due to latest changes in sshd" Resolves: rhbz#1435264 - Label sysroot dir under ostree as root_t Resolves: rhbz#1428112- Remove ganesha_t domain from permissive domains. Resolves: rhbz#1436988- Allow named_t domain bind on several udp ports Resolves: rhbz#1312972 - Update nscd_use() interface Resolves: rhbz#1281716 - Allow radius_t domain ptrace Resolves: rhbz#1426641 - Update nagios to allos exec systemctl Resolves: rhbz#1247635 - Update pcp SELinux module to reflect all pcp changes Resolves: rhbz#1271998 - Label /var/lib/ssl_db as squid_cache_t Label /etc/squid/ssl_db as squid_cache_t Resolves: rhbz#1325527 - Allow pcp_pmcd_t domain search for network sysctl Allow pcp_pmcd_t domain sys_ptrace capability Resolves: rhbz#1336211- Allow drbd load modules Resolves: rhbz#1134883 - Revert "Add sys_module capability for drbd Resolves: rhbz#1134883" - Allow stapserver list kernel modules Resolves: rhbz#1325976 - Update targetd policy Resolves: rhbz#1373860 - Add sys_admin capability to amanda Resolves: rhbz#1371561 - Allow hypervvssd_t to read all dirs. Resolves: rhbz#1331309 - Label /run/haproxy.sock socket as haproxy_var_run_t Resolves: rhbz#1386233 - Allow oddjob_mkhomedir_t to mamange autofs_t dirs. Resolves: rhbz#1408819 - Allow tomcat to connect on http_cache_port_t Resolves: rhbz#1432083 - Allow geoclue to send msgs to syslog. Resolves: rhbz#1434286 - Allow condor_master_t domain capability chown. Resolves: rhbz#1277506 - Update mta_filetrans_named_content() interface to allow calling domain create files labeled as etc_aliases_t in dir labeled as etc_mail_t. Resolves: rhbz#1167468 - Allow nova domain search for httpd configuration. Resolves: rhbz#1190761 - Add sys_module capability for drbd Resolves: rhbz#1134883 - Allow user_u users stream connect to dirsrv, Allow sysadm_u and staff_u users to manage dirsrv files Resolves: rhbz#1286474 - Allow systemd_networkd_t communicate with systemd_networkd_t via dbus Resolves: rhbz#1278010- Add haproxy_t domain fowner capability Resolves: rhbz#1386233 - Allow domain transition from ntpd_t to hwclock_t domains Resolves: rhbz#1375624 - Allow cockpit_session_t setrlimit and sys_resource Resolves: rhbz#1402316 - Dontaudit svirt_t read state of libvirtd domain Resolves: rhbz#1426106 - Update httpd and gssproxy modules to reflects latest changes in freeipa Resolves: rhbz#1432115 - Allow iptables read modules_conf_t Resolves: rhbz#1367520- Remove tomcat_t domain from unconfined domains Resolves: rhbz#1432083 - Create new boolean: sanlock_enable_home_dirs() Resolves: rhbz#1432783 - Allow mdadm_t domain to read/write nvme_device_t Resolves: rhbz#1431617 - Remove httpd_user_*_content_t domains from user_home_type attribute. This tighten httpd policy and acces to user data will be more strinct, and also fix mutual influente between httpd_enable_homedirs and httpd_read_user_content Resolves: rhbz#1383621 - Dontaudit domain to create any file in /proc. This is kernel bug. Resolves: rhbz#1412679 - Add interface dev_rw_nvme Resolves: rhbz#1431617- Allow gssproxy to get attributes on all filesystem object types. Resolves: rhbz#1430295 - Allow ganesha to chat with unconfined domains via dbus Resolves: rhbz#1426554 - add the policy required for nextcloud Resolves: rhbz#1425530 - Add nmbd_t capability2 block_suspend Resolves: rhbz#1425357 - Label /var/run/chrony as chronyd_var_run_t Resolves: rhbz#1416015 - Add domain transition from sosreport_t to iptables_t Resolves: rhbz#1359789 - Fix path to /usr/lib64/erlang/erts-5.10.4/bin/epmd Resolves: rhbz:#1332803- Update rpm macros Resolves: rhbz#1380854- Add handling booleans via selinux-policy macros in custom policy spec files. Resolves: rhbz#1380854- Allow openvswitch to load kernel modules Resolves: rhbz#1405479- Allow openvswitch read script state. Resolves: rhbz#1405479- Update ganesha policy Resolves: rhbz#1426554 Resolves: rhbz#1383784 - Allow chronyd to read adjtime Resolves: rhbz#1416015 - Fixes for chrony version 2.2 Resolves: rhbz#1416015 - Add interface virt_rw_stream_sockets_svirt() Resolves: rhbz#1415841 - Label /dev/ss0 as gpfs_device_t Resolves: rhbz#1383784 - Allow staff to rw svirt unix stream sockets. Resolves: rhbz#1415841 - Label /rhev/data-center/mnt as mnt_t Resolves: rhbz#1408275 - Associate sysctl_rpc_t with proc filesystems Resolves: rhbz#1350927 - Add new boolean: domain_can_write_kmsg Resolves: rhbz#1415715- Allow rhsmcertd_t dbus chat with system_cronjob_t Resolves: rhbz#1405341 - Allow openvswitch exec hostname and readinitrc_t files Resolves: rhbz#1405479 - Improve SELinux context for mysql_db_t objects. Resolves: rhbz#1391521 - Allow postfix_postdrop to communicate with postfix_master via pipe. Resolves: rhbz#1379736 - Add radius_use_jit boolean Resolves: rhbz#1426205 - Label /var/lock/subsys/iptables as iptables_lock_t Resolves: rhbz#1405441 - Label /usr/lib64/erlang/erts-5.10.4/bin/epmd as lib_t Resolves: rhbz#1332803 - Allow can_load_kernmodule to load kernel modules. Resolves: rhbz#1423427 Resolves: rhbz#1424621- Allow nfsd_t domain to create sysctls_rpc_t files Resolves: rhbz#1405304 - Allow openvswitch to create netlink generic sockets. Resolves: rhbz#1397974 - Create kernel_create_rpc_sysctls() interface Resolves: rhbz#1405304- Allow nfsd_t domain rw sysctl_rpc_t dirs Resolves: rhbz#1405304 - Allow cgdcbxd_t to manage cgroup files. Resolves: rhbz#1358493 - Allow cmirrord_t domain to create netlink_connector sockets Resolves: rhbz#1412670 - Allow fcoemon to create netlink scsitransport sockets Resolves: rhbz#1362496 - Allow quota_nld_t create netlink_generic sockets Resolves: rhbz#1358679 - Allow cgred_t create netlink_connector sockets Resolves: rhbz#1376357 - Add dhcpd_t domain fowner capability Resolves: rhbz#1358485 - Allow acpid to attempt to connect to the Linux kernel via generic netlink socket. Resolves: rhbz#1358478 - Rename docker module to container module Resolves: rhbz#1386916 - Allow setflies to mount tracefs Resolves: rhbz#1376357 - Allow iptables to read nsfs files. Resolves: rhbz#1411316 - Allow systemd_bootchart_t domain create dgram sockets. Resolves: rhbz#1365953 - Rename docker interfaces to container Resolves: rhbz#1386916- Allow initrc_t domain to run rhel-autorelabel script properly during boot process Resolves: rhbz#1379722 - Allow systemd_initctl_t to create and connect unix_dgram sockets Resolves: rhbz#1365947 - Allow ifconfig_t to mount/unmount nsfs_t filesystem Resolves: rhbz#1349814 - Add interfaces allowing mount/unmount nsfs_t filesystem Resolves: rhbz#1349814- Add interface init_stream_connectto() Resolves:rhbz#1365947 - Allow rhsmcertd domain signull kernel. Resolves: rhbz#1379781 - Allow kdumpgui domain to read nvme device - Allow insmod_t to load kernel modules Resolves: rhbz#1421598 - Add interface files_load_kernel_modules() Resolves: rhbz#1421598 - Add SELinux support for systemd-initctl daemon Resolves:rhbz#1365947 - Add SELinux support for systemd-bootchart Resolves: rhbz#1365953- Allow firewalld to getattr open search read modules_object_t:dir Resolves: rhbz#1418391 - Fix label for nagios plugins in nagios file conxtext file Resolves: rhbz#1277718 - Add sys_ptrace capability to pegasus domain Resolves: rhbz#1381238 - Allow sssd_t domain setpgid Resolves:rhbz#1416780 - After the latest changes in nfsd. We should allow nfsd_t to read raw fixed disk. Resolves: rhbz#1350927 - Allow kdumpgui domain to read nvme device Resolves: rhbz#1415084 - su using libselinux and creating netlink_selinux socket is needed to allow libselinux initialization. Resolves: rhbz#1146987 - Add user namespace capability object classes. Resolves: rhbz#1368057 - Add module_load permission to class system Resolves:rhbz#1368057 - Add the validate_trans access vector to the security class Resolves: rhbz#1368057 - Add "binder" security class and access vectors Resolves: rhbz#1368057 - Allow ifconfig_t domain read nsfs_t Resolves: rhbz#1349814 - Allow ping_t domain to load kernel modules. Resolves: rhbz#1388363- Allow systemd container to read/write usermodehelperstate Resolves: rhbz#1403254 - Label udp ports in range 24007-24027 as gluster_port_t Resolves: rhbz#1404152- Allow glusterd_t to bind on glusterd_port_t udp ports. Resolves: rhbz#1404152 - Revert: Allow glusterd_t to bind on med_tlp port.- Allow glusterd_t to bind on med_tlp port. Resolves: rhbz#1404152 - Update ctdbd_t policy to reflect all changes. Resolves: rhbz#1402451 - Label tcp port 24009 as med_tlp_port_t Resolves: rhbz#1404152 - Issue appears during update directly from RHEL-7.0 to RHEL-7.3 or above. Modules pkcsslotd and vbetools missing in selinux-policy package for RHEL-7.3 which causing warnings during SELinux policy store migration process. Following patch fixes issue by skipping pkcsslotd and vbetools modules migration.- Allow ctdbd_t domain transition to rpcd_t Resolves:rhbz#1402451- Fixes for containers Allow containers to attempt to write to unix_sysctls. Allow cotainers to use the FD's leaked to them from parent processes. Resolves: rhbz#1403254- Allow glusterd_t send signals to userdomain. Label new glusterd binaries as glusterd_exec_t Resolves: rhbz#1404152 - Allow systemd to stop glusterd_t domains. Resolves: rhbz#1400493- Make working CTDB:NFS: CTDB failover from selinux-policy POV Resolves: rhbz#1402451- Add kdump_t domain sys_admin capability Resolves: rhbz#1375963- Allow puppetagent_t to access timedated dbus. Use the systemd_dbus_chat_timedated interface to allow puppetagent_t the access. Resolves: rhbz#1399250- Update systemd on RHEL-7.2 box to version from RHEL-7.3 and then as a separate yum command update the selinux policy systemd will start generating USER_AVC denials and will start returning "Access Denied" errors to DBus clients Resolves: rhbz#1393505- Allow cluster_t communicate to fprintd_t via dbus Resolves: rhbz#1349798- Fix error message during update from RHEL-7.2 to RHEL-7.3, when /usr/sbin/semanage command is not installed and selinux-policy-migrate-local-changes.sh script is executed in %post install phase of selinux-policy package Resolves: rhbz#1392010- Allow GlusterFS with RDMA transport to be started correctly. It requires ipc_lock capability together with rw permission on rdma_cm device. Resolves: rhbz#1384488 - Allow glusterd to get attributes on /sys/kernel/config directory. Resolves: rhbz#1384483- Use selinux-policy-migrate-local-changes.sh instead of migrateStore* macros - Add selinux-policy-migrate-local-changes service Resolves: rhbz#1381588- Allow sssd_selinux_manager_t to manage also dir class. Resolves: rhbz#1368097 - Add interface seutil_manage_default_contexts_dirs() Resolves: rhbz#1368097- Add virt_sandbox_use_nfs -> virt_use_nfs boolean substitution. Resolves: rhbz#1355783- Allow pcp_pmcd_t domain transition to lvm_t Add capability kill and sys_ptrace to pcp_pmlogger_t Resolves: rhbz#1309883- Allow ftp daemon to manage apache_user_content Resolves: rhbz#1097775 - Label /etc/sysconfig/oracleasm as oracleasm_conf_t Resolves: rhbz#1331383 - Allow oracleasm to rw inherited fixed disk device Resolves: rhbz#1331383 - Allow collectd to connect on unix_stream_socket Resolves: rhbz#1377259- Allow iscsid create netlink iscsid sockets. Resolves: rhbz#1358266 - Improve regexp for power_unit_file_t files. To catch just systemd power unit files. Resolves: rhbz#1375462- Update oracleasm SELinux module that can manage oracleasmfs_t blk files. Add dac_override cap to oracleasm_t domain. Resolves: rhbz#1331383 - Add few rules to pcp SELinux module to make ti able to start pcp_pmlogger service Resolves: rhbz#1206525- Add oracleasm_conf_t type and allow oracleasm_t to create /dev/oracleasm Resolves: rhbz#1331383 - Label /usr/share/pcp/lib/pmie as pmie_exec_t and /usr/share/pcp/lib/pmlogger as pmlogger_exec_t Resolves: rhbz#1206525 - Allow mdadm_t to getattr all device nodes Resolves: rhbz#1365171 - Add interface dbus_dontaudit_stream_connect_system_dbusd() Resolves:rhbz#1052880 - Add virt_stub_* interfaces for docker policy which is no longer a part of our base policy. Resolves: rhbz#1372705 - Allow guest-set-user-passwd to set users password. Resolves: rhbz#1369693 - Allow samdbox domains to use msg class Resolves: rhbz#1372677 - Allow domains using kerberos to read also kerberos config dirs Resolves: rhbz#1368492 - Allow svirt_sandbox_domains to r/w onload sockets Resolves: rhbz#1342930 - Add interface fs_manage_oracleasm() Resolves: rhbz#1331383 - Label /dev/kfd as hsa_device_t Resolves: rhbz#1373488 - Update seutil_manage_file_contexts() interface that caller domain can also manage file_context_t dirs Resolves: rhbz#1368097 - Add interface to write to nsfs inodes Resolves: rhbz#1372705 - Allow systemd services to use PrivateNetwork feature Resolves: rhbz#1372705 - Add a type and genfscon for nsfs. Resolves: rhbz#1372705 - Allow run sulogin_t in range mls_systemlow-mls_systemhigh. Resolves: rhbz#1290400- Allow arpwatch to create netlink netfilter sockets. Resolves: rhbz#1358261 - Fix file context for /etc/pki/pki-tomcat/ca/ - new interface oddjob_mkhomedir_entrypoint() - Move label for /var/lib/docker/vfs/ to proper SELinux module - Allow mdadm to get attributes from all devices. - Label /etc/puppetlabs as puppet_etc_t. - Allow systemd-machined to communicate to lxc container using dbus - Allow systemd_resolved to send dbus msgs to userdomains Resolves: rhbz#1236579 - Allow systemd-resolved to read network sysctls Resolves: rhbz#1236579 - Allow systemd_resolved to connect on system bus. Resolves: rhbz#1236579 - Make entrypoint oddjob_mkhomedir_exec_t for unconfined_t - Label all files in /dev/oracleasmfs/ as oracleasmfs_t Resolves: rhbz#1331383- Label /etc/pki/pki-tomcat/ca/ as pki_tomcat_cert_t Resolves:rhbz#1366915 - Allow certmonger to manage all systemd unit files Resolves:rhbz#1366915 - Grant certmonger "chown" capability Resolves:rhbz#1366915 - Allow ipa_helper_t stream connect to dirsrv_t domain Resolves: rhbz#1368418 - Update oracleasm SELinux module Resolves: rhbz#1331383 - label /var/lib/kubelet as svirt_sandbox_file_t Resolves: rhbz#1369159 - Add few interfaces to cloudform.if file Resolves: rhbz#1367834 - Label /var/run/corosync-qnetd and /var/run/corosync-qdevice as cluster_var_run_t. Note: corosync policy is now par of rhcs module Resolves: rhbz#1347514 - Allow krb5kdc_t to read krb4kdc_conf_t dirs. Resolves: rhbz#1368492 - Update networkmanager_filetrans_named_content() interface to allow source domain to create also temad dir in /var/run. Resolves: rhbz#1365653 - Allow teamd running as NetworkManager_t to access netlink_generic_socket to allow multiple network interfaces to be teamed together. Resolves: rhbz#1365653 - Label /dev/oracleasmfs as oracleasmfs_t. Add few interfaces related to oracleasmfs_t type Resolves: rhbz#1331383 - A new version of cloud-init that supports the effort to provision RHEL Atomic on Microsoft Azure requires some a new rules that allows dhclient/dhclient hooks to call cloud-init. Resolves: rhbz#1367834 - Allow iptables to creating netlink generic sockets. Resolves: rhbz#1364359- Allow ipmievd domain to create lock files in /var/lock/subsys/ Resolves:rhbz#1349058 - Update policy for ipmievd daemon. Resolves:rhbz#1349058 - Dontaudit hyperkvp to getattr on non security files. Resolves: rhbz#1349356 - Label /run/corosync-qdevice and /run/corosync-qnetd as corosync_var_run_t Resolves: rhbz#1347514 - Fixed lsm SELinux module - Add sys_admin capability to sbd domain Resolves: rhbz#1322725 - Allow vdagent to comunnicate with systemd-logind via dbus Resolves: rhbz#1366731 - Allow lsmd_plugin_t domain to create fixed_disk device. Resolves: rhbz#1238066 - Allow opendnssec domain to create and manage own tmp dirs/files Resolves: rhbz#1366649 - Allow opendnssec domain to read system state Resolves: rhbz#1366649 - Update opendnssec_manage_config() interface to allow caller domain also manage opendnssec_conf_t dirs Resolves: rhbz#1366649 - Allow rasdaemon to mount/unmount tracefs filesystem. Resolves: rhbz#1364380 - Label /usr/libexec/iptables/iptables.init as iptables_exec_t Allow iptables creating lock file in /var/lock/subsys/ Resolves: rhbz#1367520 - Modify interface den_read_nvme() to allow also read nvme_device_t block files. Resolves: rhbz#1362564 - Label /var/run/storaged as lvm_var_run_t. Resolves: rhbz#1264390 - Allow unconfineduser to run ipa_helper_t. Resolves: rhbz#1361636- Dontaudit mock to write to generic certs. Resolves: rhbz#1271209 - Add labeling for corosync-qdevice and corosync-qnetd daemons, to run as cluster_t Resolves: rhbz#1347514 - Revert "Label corosync-qnetd and corosync-qdevice as corosync_t domain" - Allow modemmanager to write to systemd inhibit pipes Resolves: rhbz#1365214 - Label corosync-qnetd and corosync-qdevice as corosync_t domain Resolves: rhbz#1347514 - Allow ipa_helper to read network state Resolves: rhbz#1361636 - Label oddjob_reqiest as oddjob_exec_t Resolves: rhbz#1361636 - Add interface oddjob_run() Resolves: rhbz#1361636 - Allow modemmanager chat with systemd_logind via dbus Resolves: rhbz#1362273 - Allow NetworkManager chat with puppetagent via dbus Resolves: rhbz#1363989 - Allow NetworkManager chat with kdumpctl via dbus Resolves: rhbz#1363977 - Allow sbd send msgs to syslog Allow sbd create dgram sockets. Allow sbd to communicate with kernel via dgram socket Allow sbd r/w kernel sysctls. Resolves: rhbz#1322725 - Allow ipmievd_t domain to re-create ipmi devices Label /usr/libexec/openipmi-helper as ipmievd_exec_t Resolves: rhbz#1349058 - Allow rasdaemon to use tracefs filesystem. Resolves: rhbz#1364380 - Fix typo bug in dirsrv policy - Some logrotate scripts run su and then su runs unix_chkpwd. Allow logrotate_t domain to check passwd. Resolves: rhbz#1283134 - Add ipc_lock capability to sssd domain. Allow sssd connect to http_cache_t Resolves: rhbz#1362688 - Allow dirsrv to read dirsrv_share_t content Resolves: rhbz#1363662 - Allow virtlogd_t to append svirt_image_t files. Resolves: rhbz#1358140 - Allow hypervkvp domain to read hugetlbfs dir/files. Resolves: rhbz#1349356 - Allow mdadm daemon to read nvme_device_t blk files Resolves: rhbz#1362564 - Allow selinuxusers and unconfineduser to run oddjob_request Resolves: rhbz#1361636 - Allow sshd server to acces to Crypto Express 4 (CEX4) devices. Resolves: rhbz#1362539 - Fix labeling issue in init.fc file. Path /usr/lib/systemd/fedora-* changed to /usr/lib/systemd/rhel-*. Resolves: rhbz#1363769 - Fix typo in device interfaces Resolves: rhbz#1349058 - Add interfaces for managing ipmi devices Resolves: rhbz#1349058 - Add interfaces to allow mounting/umounting tracefs filesystem Resolves: rhbz#1364380 - Add interfaces to allow rw tracefs filesystem Resolves: rhbz#1364380 - Add interface dev_read_nvme() to allow reading Non-Volatile Memory Host Controller devices. Resolves: rhbz#1362564 - Label /sys/kernel/debug/tracing filesystem Resolves: rhbz#1364380 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857- Dontaudit mock_build_t can list all ptys. Resolves: rhbz#1271209 - Allow ftpd_t to mamange userhome data without any boolean. Resolves: rhbz#1097775 - Add logrotate permissions for creating netlink selinux sockets. Resolves: rhbz#1283134 - Allow lsmd_plugin_t to exec ldconfig. Resolves: rhbz#1238066 - Allow vnstatd domain to read /sys/class/net/ files Resolves: rhbz#1358243 - Remove duplicate allow rules in spamassassin SELinux module Resolves:rhbz#1358175 - Allow spamc_t and spamd_t domains create .spamassassin file in user homedirs Resolves:rhbz#1358175 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857 - Add new MLS attribute to allow relabeling objects higher than system low. This exception is needed for package managers when processing sensitive data. Resolves: rhbz#1330464 - Allow gnome-keyring also manage user_tmp_t sockets. Resolves: rhbz#1257057 - corecmd: Remove fcontext for /etc/sysconfig/libvirtd Resolves:rhbz#1351382- Allow ipa_dnskey domain to search cache dirs Resolves: rhbz#1350957- Allow ipa-dnskey read system state. Reasolves: rhbz#1350957 - Allow dogtag-ipa-ca-renew-agent-submit labeled as certmonger_t to create /var/log/ipa/renew.log file Resolves: rhbz#1350957- Allow firewalld to manage net_conf_t files. Resolves:rhbz#1304723 - Allow logrotate read logs inside containers. Resolves: rhbz#1303514 - Allow sssd to getattr on fs_t Resolves: rhbz#1356082 - Allow opendnssec domain to manage bind chace files Resolves: rhbz#1350957 - Fix typo in rhsmcertd policy module Resolves: rhbz#1329475 - Allow systemd to get status of systemd-logind daemon Resolves: rhbz#1356141 - Label more ndctl devices not just ndctl0 Resolves: rhbz#1355809- Allow rhsmcertd to copy certs into /etc/docker/cert.d - Add interface docker_rw_config() Resolves: rhbz#1344500 - Fix logrotate fc file to label also /var/lib/logrotate/ dir as logrotate_var_lib_t Resolves: rhbz#1355632 - Allow rhsmcertd to read network sysctls Resolves: rhbz#1329475 - Label /var/log/graphite-web dir as httpd_log_t Resolves: rhbz#1310898 - Allow mock to use generic ptys Resolves: rhbz#1271209 - Allow adcli running as sssd_t to write krb5.keytab file. Resolves: rhbz#1356082 - Allow openvswitch connect to openvswitch_port_t type. Resolves: rhbz#1335024 - Add SELinux policy for opendnssec service. Resolves: rhbz#1350957 - Create new SELinux type for /usr/libexec/ipa/ipa-dnskeysyncd Resolves: rhbz#1350957 - label /dev/ndctl0 device as nvram_device_t Resolves: rhbz#1355809- Allow lttng tools to block suspending Resolves: rhbz#1256374 - Allow creation of vpnaas in openstack Resolves: rhbz#1352710 - virt: add strict policy for virtlogd daemon Resolves:rhbz#1311606 - Update makefile to support snapperd_contexts file Resolves: rhbz#1352681- Allow udev to manage systemd-hwdb files - Add interface systemd_hwdb_manage_config() Resolves: rhbz#1350756 - Fix paths to infiniband devices. This allows use more then two infiniband interfaces. Resolves: rhbz#1210263- Allow virtual machines to rw infiniband devices. Resolves: rhbz#1210263 - Allow opensm daemon to rw infiniband_mgmt_device_t Resolves: rhbz#1210263 - Allow systemd_hwdb_t to relabel /etc/udev/hwdb.bin file. Resolves: rhbz#1350756 - Make label for new infiniband_mgmt deivices Resolves: rhbz#1210263- Fix typo in brltty SELinux module - Add new SELinux module sbd Resolves: rhbz#1322725 - Allow pcp dmcache metrics collection Resolves: rhbz#1309883 - Allow pkcs_slotd_t to create dir in /var/lock Add label pkcs_slotd_log_t Resolves: rhbz#1350782 - Allow openvpn to create sock files labeled as openvpn_var_run_t Resolves: rhbz#1328246 - Allow hypervkvp daemon to getattr on all filesystem types. Resolves: rhbz#1349356 - Allow firewalld to create net_conf_t files Resolves: rhbz#1304723 - Allow mock to use lvm Resolves: rhbz#1271209 - Allow keepalived to create netlink generic sockets. Resolves: rhbz#1349809 - Allow mirromanager creating log files in /tmp Resolves:rhbz#1328818 - Rename few modules to make it consistent with source files Resolves: rhbz#1351445 - Allow vmtools_t to transition to rpm_script domain Resolves: rhbz#1342119 - Allow nsd daemon to manage nsd_conf_t dirs and files Resolves: rhbz#1349791 - Allow cluster to create dirs in /var/run labeled as cluster_var_run_t Resolves: rhbz#1346900 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535 - Dontaudit su_role_template interface to getattr /proc/kcore Dontaudit su_role_template interface to getattr /dev/initctl Resolves: rhbz#1086240 - Add interface lvm_getattr_exec_files() Resolves: rhbz#1271209 - Fix typo Compliling vs. Compiling Resolves: rhbz#1351445- Allow krb5kdc_t to communicate with sssd Resolves: rhbz#1319933 - Allow prosody to bind on prosody ports Resolves: rhbz#1304664 - Add dac_override caps for fail2ban-client Resolves: rhbz#1316678 - dontaudit read access for svirt_t on the file /var/db/nscd/group Resolves: rhbz#1301637 - Allow inetd child process to communicate via dbus with systemd-logind Resolves: rhbz#1333726 - Add label for brltty log file Resolves: rhbz#1328818 - Allow dspam to read the passwd file Resolves: rhbz#1286020 - Allow snort_t to communicate with sssd Resolves: rhbz#1284908 - svirt_sandbox_domains need to be able to execmod for badly built libraries. Resolves: rhbz#1206339 - Add policy for lttng-tools package. Resolves: rhbz#1256374 - Make mirrormanager as application domain. Resolves: rhbz#1328234 - Add support for the default lttng-sessiond port - tcp/5345. This port is used by LTTng 2.x central tracing registry session daemon. - Add prosody ports Resolves: rhbz#1304664 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535- Label /var/lib/softhsm as named_cache_t. Allow named_t to manage named_cache_t dirs. Resolves:rhbz#1331315 - Label named-pkcs11 binary as named_exec_t. Resolves: rhbz#1331315 - Allow glusterd daemon to get systemd status Resolves: rhbz#1321785 - Allow logrotate dbus-chat with system_logind daemon Resolves: rhbz#1283134 - Allow pcp_pmlogger to read kernel network state Allow pcp_pmcd to read cron pid files Resolves: rhbz#1336211 - Add interface cron_read_pid_files() Resolves: rhbz#1336211 - Allow pcp_pmlogger to create unix dgram sockets Resolves: rhbz#1336211 - Add hwloc-dump-hwdata SELinux policy Resolves: rhbz#1344054 - Remove non-existing jabberd_spool_t() interface and add new jabbertd_var_spool_t. Resolves: rhbz#1121171 - Remove non-existing interface salk_resetd_systemctl() and replace it with sanlock_systemctl_sanlk_resetd() Resolves: rhbz#1259764 - Create label for openhpid log files. esolves: rhbz#1259764 - Label /var/lib/ganglia as httpd_var_lib_t Resolves: rhbz#1260536 - Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Include patch from distgit repo: policy-RHEL-7.1-flask.patch. Resolves: rhbz#1329560 - Update refpolicy to handle hwloc Resolves: rhbz#1344054 - Label /etc/dhcp/scripts dir as bin_t - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255- Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Allow mongod log to syslog. Resolves: rhbz#1306995 - Allow rhsmcertd connect to port tcp 9090 Resolves: rhbz#1337319 - Label for /bin/mail(x) was removed but /usr/bin/mail(x) not. This path is also needed to remove. Resolves: rhbz#1262483 Resolves: rhbz#1277506 - Label /usr/libexec/mimedefang-wrapper as spamd_exec_t. Resolves: rhbz#1301516 - Add new boolean spamd_update_can_network. Resolves: rhbz#1305469 - Allow rhsmcertd connect to tcp netport_port_t Resolves: rhbz#1329475 - Fix SELinux context for /usr/share/mirrormanager/server/mirrormanager to Label all binaries under dir as mirrormanager_exec_t. Resolves: rhbz#1328234 - Allow prosody to bind to fac_restore tcp port. Resolves: rhbz#1321787 - Allow ninfod to read raw packets Resolves: rhbz#1317964 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1260835 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1271159 - Allow tuned to use policykit. This change is required by cockpit. Resolves: rhbz#1346464 - Allow conman_t to read dir with conman_unconfined_script_t binary files. Resolves: rhbz#1297323 - Allow pegasus to read /proc/sysinfo. Resolves: rhbz#1265883 - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255 - Label tcp ports:16379, 26379 as redis_port_t Resolves: rhbz#1348471 - Allow systemd to relabel /var and /var/lib directories during boot. - Add files_relabel_var_dirs() and files_relabel_var_dirs() interfaces. - Add files_relabelto_var_lib_dirs() interface. - Label tcp port 2004 as mailbox_port_t. Resolves: rhbz#1332843 - Label tcp and udp port 5582 as fac_restore_port_t Resolves: rhbz#1321787 - Allow sysadm_t user to run postgresql-setup. Resolves: rhbz#1282543 - Allow sysadm_t user to dbus chat with oddjob_t. This allows confined admin run oddjob mkhomedirfor script. Resolves: rhbz#1297480 - Update netlink socket classes.- Allow conman to kill conman_unconfined_script. Resolves: rhbz#1297323 - Make conman_unconfined_script_t as init_system_domain. Resolves:rhbz#1297323 - Allow init dbus chat with apmd. Resolves:rhbz#995898 - Patch /var/lib/rpm is symlink to /usr/share/rpm on Atomic, due to this change we need to label also /usr/share/rpm as rpm_var_lib_t. Resolves: rhbz#1233252 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Add mediawiki rules to proper scope Resolves: rhbz#1301186 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Allow mysqld_safe to inherit rlimit information from mysqld Resolves: rhbz#1323673 - Allow collectd_t to stream connect to postgresql. Resolves: rhbz#1344056 - Allow mediawiki-script to read /etc/passwd file. Resolves: rhbz#1301186 - Add filetrans rule that NetworkManager_t can create net_conf_t files in /etc. Resolves: rhbz#1344505 - Add labels for mediawiki123 Resolves: rhbz#1293872 - Fix label for all fence_scsi_check scripts - Allow ip netns to mounton root fs and unmount proc_t fs. Resolves: rhbz#1343776 Resolves: rhbz#1286851 - Allow sysadm_t to run newaliases command. Resolves: rhbz#1344828 - Add interface sysnet_filetrans_named_net_conf() Resolves: rhbz#1344505- Fix several issues related to the SELinux Userspace changes- Allow glusterd domain read krb5_keytab_t files. Resolves: rhbz#1343929 - Fix typo in files_setattr_non_security_dirs. Resolves: rhbz#1115987- Allow tmpreaper_t to read/setattr all non_security_file_type dirs Resolves: rhbz#1115987 - Allow firewalld to create firewalld_var_run_t directory. Resolves: rhbz#1304723 - Add interface firewalld_read_pid_files() Resolves: rhbz#1304723 - Label /usr/libexec/rpm-ostreed as rpm_exec_t. Resolves: rhbz#1340542 - Allow sanlock service to read/write cephfs_t files. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - Add interface files_setattr_non_security_dirs() Resolves: rhbz#1115987 - Add support for onloadfs - Allow iptables to read firewalld pid files. Resolves: rhbz#1304723 - Add SELinux support for ceph filesystem. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) Resolves: rhbz#1236580- Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - New interfaces needed for systemd-machinectl Resolves: rhbz#1236580 - New interfaces needed by systemd-machine Resolves: rhbz#1236580 - Add interface allowing sending and receiving messages from virt over dbus. Resolves: rhbz#1236580 - Backport docker policy from Fedora. Related: #1303123 Resolves: #1341257 - Allow NetworkManager_t and policykit_t read access to systemd-machined pid files. Resolves: rhbz#1236580 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added interfaces needed by new docker policy. Related: rhbz#1303123 - Add support for systemd-machined daemon Resolves: rhbz#1236580 - Allow rpm-ostree domain transition to install_t domain from init_t. Resolves: rhbz#1340542- dnsmasq: allow NetworkManager to control dnsmasq via D-Bus Resolves: rhbz#1336722 - Directory Server (389-ds-base) has been updated to use systemd-ask-password. In order to function correctly we need the following added to dirsrv.te Resolves: rhbz#1333198 - sftpd_* booleans are functionless these days. Resolves: rhbz#1335656 - Label /var/log/ganesha.log as gluster_log_t Allow glusterd_t domain to create glusterd_log_t files. Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737 - Label /usr/libexec/storaged/storaged as lvm_exec_t to run storaged daemon in lvm_t SELinux domain. Resolves: rhbz#1264390 - Allow systemd_hostanmed_t to read /proc/sysinfo labeled as sysctl_t. Resolves: rhbz#1337061 - Revert "Allow all domains some process flags." Resolves: rhbz#1303644 - Revert "Remove setrlimit to all domains." Resolves: rhbz#1303644 - Label /usr/sbin/xrdp* files as bin_t Resolves: rhbz#1276777 - Add mls support for some db classes Resolves: rhbz#1303651 - Allow systemd_resolved_t to check if ipv6 is disabled. Resolves: rhbz#1236579 - Allow systemd_resolved to read systemd_networkd run files. Resolves: rhbz#1236579- Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737- Allow logwatch to domtrans to postqueue Resolves: rhbz#1331542 - Label /var/log/ganesha.log as gluster_log_t - Allow glusterd_t domain to create glusterd_log_t files. - Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow zabbix to connect to postgresql port Resolves: rhbz#1330479 - Add userdom_destroy_unpriv_user_shared_mem() interface. Related: rhbz#1306403 - systemd-logind remove all IPC objects owned by a user on a logout. This covers also SysV memory. This change allows to destroy unpriviledged user SysV shared memory segments. Resolves: rhbz#1306403- We need to restore contexts on /etc/passwd*,/etc/group*,/etc/*shadow* during install phase to get proper labeling for these files until selinux-policy pkgs are installed. Resolves: rhbz#1333952- Add interface glusterd_dontaudit_read_lib_dirs() Resolves: rhbz#1295680 - Dontaudit Occasionally observing AVC's while running geo-rep automation Resolves: rhbz#1295680 - Allow glusterd to manage socket files labeled as glusterd_brick_t. Resolves: rhbz#1331561 - Create new apache content template for files stored in user homedir. This change is needed to make working booleans: - httpd_enable_homedirs - httpd_read_user_content Resolves: rhbz#1246522 - Allow stunnel create log files. Resolves: rhbz#1296851 - Label tcp port 8181 as intermapper_port_t. Resolves: rhbz#1334783 - Label tcp/udp port 2024 as xinuexpansion4_port_t Resolves: rhbz#1334783 - Label tcp port 7002 as afs_pt_port_t Label tcp/udp port 2023 as xinuexpansion3_port_t Resolves: rhbz#1334783 - Dontaudit ldconfig read gluster lib files. Resolves: rhbz#1295680 - Add interface auth_use_nsswitch() to systemd_domain_template. Resolves: rhbz#1236579- Label /usr/bin/ganesha.nfsd as glusterd_exec_t to run ganesha as glusterd_t. Allow glusterd_t stream connect to rpbind_t. Allow cluster_t to create symlink /var/lib/nfs labeled as var_lib_nfs_t. Add interface rpc_filetrans_var_lib_nfs_content() Add new boolean: rpcd_use_fusefs to allow rpcd daemon use fusefs. Resolves: rhbz#1312809 Resolves: rhbz#1323947 - Allow dbus chat between httpd_t and oddjob_t. Resolves: rhbz#1324144 - Label /usr/libexec/ipa/oddjob/org.freeipa.server.conncheck as ipa_helper_exec_t. Resolves: rhbz#1324144 - Label /var/log/ipareplica-conncheck.log file as ipa_log_t Allow ipa_helper_t domain to manage logs labeledas ipa_log_t Allow ipa_helper_t to connect on http and kerberos_passwd ports. Resolves: rhbz#1324144 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow pcp_pmcd_t domain to manage docker lib files. This rule is needed to allow pcp to collect container information when SELinux is enabled. Resolves: rhbz#1309454- Allow runnig php7 in fpm mode. From selinux-policy side, we need to allow httpd to read/write hugetlbfs. Resolves: rhbz#1319442 - Allow openvswitch daemons to run under openvswitch Linux user instead of root. This change needs allow set capabilities: chwon, setgid, setuid, setpcap. Resolves: rhbz#1296640 - Remove ftpd_home_dir() boolean from distro policy. Reason is that we cannot make this working due to m4 macro language limits. Resolves: rhbz#1097775 - /bin/mailx is labeled sendmail_exec_t, and enters the sendmail_t domain on execution. If /usr/sbin/sendmail does not have its own domain to transition to, and is not one of several products whose behavior is allowed by the sendmail_t policy, execution will fail. In this case we need to label /bin/mailx as bin_t. Resolves: rhbz#1262483 - Allow nsd daemon to create log file in /var/log as nsd_log_t Resolves: rhbz#1293140 - Sanlock policy update. - New sub-domain for sanlk-reset daemon Resolves: rhbz#1212324 - Label all run tgtd files, not just socket files Resolves: rhbz#1280280 - Label all run tgtd files, not just socket files. Resolves: rhbz#1280280 - Allow prosody to stream connect to sasl. This will allow using cyrus authentication in prosody. Resolves: rhbz#1321049 - unbound wants to use ephemeral ports as a default configuration. Allow to use also udp sockets. Resolves: rhbz#1318224 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow targetd to read/write to /dev/mapper/control device. Resolves: rhbz#1063714 - Allow KDM to get status about power services. This change allow kdm to be able do shutdown. Resolves: rhbz#1316724 - Allow systemd-resolved daemon creating netlink_route sockets. Resolves:rhbz#1236579 - Allow systemd_resolved_t to read /etc/passwd file. Allow systemd_resolved_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used Resolves: rhbz#1065362 - Label /etc/selinux/(minimum|mls|targeted)/active/ as semanage_store_t Resolves: rhbz#1321943 - Label all nvidia binaries as xserver_exec_t Resolves: rhbz#1322283- Create new permissivedomains CIL module and make it active. Resolves: rhbz#1320451 - Add support for new mock location - /usr/libexec/mock/mock. Resolves: rhbz#1271209 - Allow bitlee to create bitlee_var_t dirs. Resolves: rhbz#1268651 - Allow CIM provider to read sssd public files. Resolves: rhbz#1263339 - Fix some broken interfaces in distro policy. Resolves: rhbz#1121171 - Allow power button to shutdown the laptop. Resolves: rhbz#995898 - Allow lsm plugins to create named fixed disks. Resolves: rhbz#1238066 - Add default labeling for /etc/Pegasus/cimserver_current.conf. It is a correct patch instead of the current /etc/Pegasus/pegasus_current.confResolves: rhbz#1278777 - Allow hyperv domains to rw hyperv devices. Resolves: rhbz#1309361 - Label /var/www/html(/.*)?/wp_backups(/.*)? as httpd_sys_rw_content_t.Resolves: rhbz#1246780 - Create conman_unconfined_script_t type for conman script stored in /use/share/conman/exec/ Resolves: rhbz#1297323 - Fix rule definitions for httpd_can_sendmail boolean. We need to distinguish between base and contrib. - Add support for /dev/mptctl device used to check RAID status. Resolves: rhbz#1258029 - Create hyperv* devices and create rw interfaces for this devices. Resolves: rhbz#1309361 - Add fixes for selinux userspace moving the policy store to /var/lib/selinux. - Remove optional else block for dhcp ping- Allow rsync_export_all_ro boolean to read also non_auth_dirs/files/symlinks. Resolves: rhbz#1263770 - Fix context of "/usr/share/nginx/html". Resolves: rhbz#1261857 - Allow pmdaapache labeled as pcp_pmcd_t access to port 80 for apache diagnostics Resolves: rhbz#1270344 - Allow pmlogger to create pmlogger.primary.socket link file. Resolves: rhbz#1270344 - Label nagios scripts as httpd_sys_script_exec_t. Resolves: rhbz#1260306 - Add dontaudit interface for kdumpctl_tmp_t Resolves: rhbz#1156442 - Allow mdadm read files in EFI partition. Resolves: rhbz#1291801 - Allow nsd_t to bind on nsf_control tcp port. Allow nsd_crond_t to read nsd pid. Resolves: rhbz#1293140 - Label some new nsd binaries as nsd_exec_t Allow nsd domain net_admin cap. Create label nsd_tmp_t for nsd tmp files/dirs Resolves: rhbz#1293140 - Add filename transition that /etc/princap will be created with cupsd_rw_etc_t label in cups_filetrans_named_content() interface. Resolves: rhbz#1265102 - Add missing labeling for /usr/libexec/abrt-hook-ccpp. Resolves: rhbz#1213409 - Allow pcp_pmie and pcp_pmlogger to read all domains state. Resolves: rhbz#1206525 - Label /etc/redis-sentinel.conf as redis_conf_t. Allow redis_t write to redis_conf_t. Allow redis_t to connect on redis tcp port. Resolves: rhbz#1275246 - cockpit has grown content in /var/run directory Resolves: rhbz#1279429 - Allow collectd setgid capability Resolves:#1310898 - Remove declaration of empty booleans in virt policy. Resolves: rhbz#1103153 - Fix typo in drbd policy - Add new drbd file type: drbd_var_run_t. Allow drbd_t to manage drbd_var_run_t files/dirs. Allow drbd_t create drbd_tmp_t files in /tmp. Resolves: rhbz#1134883 - Label /etc/ctdb/events.d/* as ctdb_exec_t. Allow ctdbd_t to setattr on ctdbd_exec_t files. Resolves: rhbz#1293788 - Allow abrt-hook-ccpp to get attributes of all processes because of core_pattern. Resolves: rhbz#1254188 - Allow abrt_t to read sysctl_net_t files. Resolves: rhbz#1254188 - The ABRT coredump handler has code to emulate default core file creation The handler runs in a separate process with abrt_dump_oops_t SELinux process type. abrt-hook-ccpp also saves the core dump file in the very same way as kernel does and a user can specify CWD location for a coredump. abrt-hook-ccpp has been made as a SELinux aware apps to create this coredumps with correct labeling and with this commit the policy rules have been updated to allow access all non security files on a system. - Allow abrt-hook-ccpp to getattr on all executables. - Allow setuid/setgid capabilities for abrt-hook-ccpp. Resolves: rhbz#1254188 - abrt-hook-ccpp needs to have setfscreate access because it is SELinux aware and compute a target labeling. Resolves: rhbz#1254188 - Allow abrt-hook-ccpp to change SELinux user identity for created objects. Resolves: rhbz#1254188 - Dontaudit write access to inherited kdumpctl tmp files. Resolves: rbhz#1156442 - Add interface to allow reading files in efivarfs - contains Linux Kernel configuration options for UEFI systems (UEFI Runtime Variables) Resolves: rhbz#1291801 - Label 8952 tcp port as nsd_control. Resolves: rhbz#1293140 - Allow ipsec to use pam. Resolves: rhbz#1315700 - Allow to log out to gdm after screen was resized in session via vdagent. Resolves: rhbz#1249020 - Allow setrans daemon to read /proc/meminfo. Resolves: rhbz#1316804 - Allow systemd_networkd_t to write kmsg, when kernel was started with following params: systemd.debug systemd.log_level=debug systemd.log_target=kmsg Resolves: rhbz#1298151 - Label tcp port 5355 as llmnr-> Link-Local Multicast Name Resolution Resolves: rhbz#1236579 - Add new selinux policy for systemd-resolved dawmon. Resolves: rhbz#1236579 - Add interface ssh_getattr_server_keys() interface. Resolves: rhbz#1306197 - Allow run sshd-keygen on second boot if first boot fails after some reason and content is not syncedon the disk. These changes are reflecting this commit in sshd. http://pkgs.fedoraproject.org/cgit/rpms/openssh.git/commit/?id=af94f46861844cbd6ba4162115039bebcc8f78ba rhbz#1299106 Resolves: rhbz#1306197 - Allow systemd_notify_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used. Resolves: rhbz#1309417 - Remove bin_t label for /etc/ctdb/events.d/. We need to label this scripts as ctdb_exec_t. Resolves: rhbz#1293788- Prepare selinux-policy package for userspace release 2016-02-23. Resolves: rhbz#1305982- Allow sending dbus msgs between firewalld and system_cronjob domains. Resolves: rhbz#1284902 - Allow zabbix-agentd to connect to following tcp sockets. One of zabbix-agentd functions is get service status of ftp,http,innd,pop,smtp protocols. Resolves: rhbz#1242506 - Add new boolean tmpreaper_use_cifs() to allow tmpreaper to run on local directories being shared with Samba. Resolves: rhbz#1284972 - Add support for systemd-hwdb daemon. Resolves: rhbz#1257940 - Add interface fs_setattr_cifs_dirs(). Resolves: rhbz#1284972- Add new SELinux policy fo targetd daemon. Resolves: rhbz#1063714 - Add new SELinux policy fo ipmievd daemon. Resolves: rhbz#1083031 - Add new SELinux policy fo hsqldb daemon. Resolves: rhbz#1083171 - Add new SELinux policy for blkmapd daemon. Resolves: rhbz#1072997 - Allow p11-child to connect to apache ports. - Label /usr/sbin/lvmlockd binary file as lvm_exec_t. Resolves: rhbz#1278028 - Add interface "lvm_manage_lock" to lvm policy. Resolves: rhbz#1063714- Allow openvswitch domain capability sys_rawio. Resolves: rhbz#1278495- Allow openvswitch to manage hugetlfs files and dirs. Resolves: rhbz#1278495 - Add fs_manage_hugetlbfs_files() interface. Resolves: rhbz#1278495- Allow smbcontrol domain to send sigchld to ctdbd domain. Resolves: #1293784 - Allow openvswitch read/write hugetlb filesystem. Resolves: #1278495Allow hypervvssd to list all mountpoints to have VSS live backup working correctly. Resolves:#1247880- Revert Add missing labeling for /usr/libexec/abrt-hook-ccpp patch Resolves: #1254188- Allow search dirs in sysfs types in kernel_read_security_state. Resolves: #1254188 - Fix kernel_read_security_state interface that source domain of this interface can search sysctl_fs_t dirs. Resolves: #1254188- Add missing labeling for /usr/libexec/abrt-hook-ccpp as a part of #1245477 and #1242467 bugs Resolves: #1254188 - We need allow connect to xserver for all sandbox_x domain because we have one type for all sandbox processes. Resolves:#1261938- Remove labeling for modules_dep_t file contexts to have labeled them as modules_object_t. - Update files_read_kernel_modules() to contain modutils_read_module_deps_files() calling because module deps labeling could remain and it allows to avoid regressions. Resolves:#1266928- We need to require sandbox_web_type attribute in sandbox_x_domain_template(). Resolves: #1261938 - ipsec: The NM helper needs to read the SAs Resolves: #1259786 - ipsec: Allow ipsec management to create ptys Resolves: #1259786- Add temporary fixes for sandbox related to #1103622. It allows to run everything under one sandbox type. Resolves:#1261938 - Allow abrt_t domain to write to kernel msg device. Resolves: #1257828 - Allow rpcbind_t domain to change file owner and group Resolves: #1265266- Allow smbcontrol to create a socket in /var/samba which uses for a communication with smbd, nmbd and winbind. Resolves: #1256459- Allow dirsrv-admin script to read passwd file. Allow dirsrv-admin script to read httpd pid files. Label dirsrv-admin unit file and allow dirsrv-admin domains to use it. Resolves: #1230300 - Allow qpid daemon to connect on amqp tcp port. Resolves: #1261805- Label /etc/ipa/nssdb dir as cert_t Resolves:#1262718 - Do not provide docker policy files which is shipped by docker-selinux.rpm Resolves:#1262812- Add labels for afs binaries: dafileserver, davolserver, salvageserver, dasalvager Resolves: #1192338 - Add lsmd_plugin_t sys_admin capability, Allow lsmd_plugin_t getattr from sysfs filesystem. Resolves: #1238079 - Allow rhsmcertd_t send signull to unconfined_service_t domains. Resolves: #1176078 - Remove file transition from snmp_manage_var_lib_dirs() interface which created snmp_var_lib_t dirs in var_lib_t. - Allow openhpid_t daemon to manage snmp files and dirs. Resolves: #1243902 - Allow mdadm_t domain read/write to general ptys and unallocated ttys. Resolves: #1073314 - Add interface unconfined_server_signull() to allow domains send signull to unconfined_service_t Resolves: #1176078- Allow systemd-udevd to access netlink_route_socket to change names for network interfaces without unconfined.pp module. It affects also MLS. Resolves:#1250456- Fix labeling for fence_scsi_check script Resolves: #1255020 - Allow openhpid to read system state Allow openhpid to connect to tcp http port. Resolves: #1244248 - Allow openhpid to read snmp var lib files. Resolves: #1243902 - Allow openvswitch_t domains read kernel dependencies due to openvswitch run modprobe - Allow unconfined_t domains to create /var/run/xtables.lock with iptables_var_run_t Resolves: #1243403 - Remove bin_t label for /usr/share/cluster/fence_scsi_check\.pl Resolves: #1255020- Fix regexp in chronyd.fc file Resolves: #1243764 - Allow passenger to getattr filesystem xattr Resolves: #1196555 - Label mdadm.conf.anackbak as mdadm_conf_t file. Resolves: #1088904 - Revert "Allow pegasus_openlmi_storage_t create mdadm.conf.anacbak file in /etc." - Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Remove labeling for /var/db/.*\.db as etc_t to label db files as system_db_t. Resolves: #1230877- Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Label /var/run/chrony-helper dir as chronyd_var_run_t. Resolves: #1243764 - Allow dhcpc_t domain transition to chronyd_t Resolves: #1243764- Fix postfix_spool_maildrop_t,postfix_spool_flush_t contexts in postfix.fc file. Resolves: #1252442- Allow exec pidof under hypervkvp domain. Resolves: #1254870 - Allow hypervkvp daemon create connection to the system DBUS Resolves: #1254870- Allow openhpid_t to read system state. Resolves: #1244248 - Added labels for files provided by rh-nginx18 collection Resolves: #1249945 - Dontaudit block_suspend capability for ipa_helper_t, this is kernel bug. Allow ipa_helper_t capability net_admin. Allow ipa_helper_t to list /tmp. Allow ipa_helper_t to read rpm db. Resolves: #1252968 - Allow rhsmcertd exec rhsmcertd_var_run_t files and rhsmcerd_tmp_t files. This rules are in hide_broken_sympthons until we find better solution. Resolves: #1243431 - Allow abrt_dump_oops_t to read proc_security_t files. - Allow abrt_dump_oops to signull all domains Allow abrt_dump_oops to read all domains state Allow abrt_dump_oops to ptrace all domains - Add interface abrt_dump_oops_domtrans() - Add mountpoint dontaudit access check in rhsmcertd policy. Resolves: #1243431 - Allow samba_net_t to manage samba_var_t sock files. Resolves: #1252937 - Allow chrome setcap to itself. Resolves: #1251996 - Allow httpd daemon to manage httpd_var_lib_t lnk_files. Resolves: #1253706 - Allow chronyd exec systemctl Resolves: #1243764 - Add inteface chronyd_signal Allow timemaster_t send generic signals to chronyd_t. Resolves: #1243764 - Added interface fs_dontaudit_write_configfs_dirs - Add label for kernel module dep files in /usr/lib/modules Resolves:#916635 - Allow kernel_t domtrans to abrt_dump_oops_t - Added to files_dontaudit_write_all_mountpoints intefface new dontaudit rule, that domain included this interface dontaudit capability dac_override. - Allow systemd-networkd to send logs to systemd-journald. Resolves: #1236616- Fix label on /var/tmp/kiprop_0 Resolves:#1220763 - Allow lldpad_t to getattr tmpfs_t. Resolves: #1246220 - Label /dev/shm/lldpad.* as lldapd_tmpfs_t Resolves: #1246220 - Allow audisp client to read system state.- Allow pcp_domain to manage pcp_var_lib_t lnk_files. Resolves: #1252341 - Label /var/run/xtables.* as iptables_var_run_t Resolves: #1243403- Add interface to read/write watchdog device - Add labels for /dev/memory_bandwith and /dev/vhci. Thanks ssekidde Resolves:#1210237 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow logrotate to reload services. Resolves: #1242453 - Allow openhpid use libwatchdog plugin. (Allow openhpid_t rw watchdog device) Resolves: #1244260 - Allow openhpid liboa_soap plugin to read generic certs. Resolves: #1244248 - Allow openhpid liboa_soap plugin to read resolv.conf file. Resolves: #1244248 - Label /usr/libexec/chrony-helper as chronyd_exec_t - Allow chronyd_t to read dhcpc state. - Allow chronyd to execute mkdir command.- Allow mdadm to access /dev/random and add support to create own files/dirs as mdadm_tmpfs_t. Resolves:#1073314 - Allow udev, lvm and fsadm to access systemd-cat in /var/tmp/dracut if 'dracut -fv' is executed in MLS. - Allow admin SELinu users to communicate with kernel_t. It is needed to access /run/systemd/journal/stdout if 'dracut -vf' is executed. We allow it for other SELinux users. - Allow sysadm to execute systemd-sysctl in the sysadm_t domain. It is needed for ifup command in MLS mode. - Add fstools_filetrans_named_content_fsadm() and call it for named_filetrans_domain domains. We need to be sure that /run/blkid is created with correct labeling. Resolves:#1183503 - Add support for /etc/sanlock which is writable by sanlock daemon. Resolves:#1231377 - Allow useradd add homedir located in /var/lib/kdcproxy in ipa-server RPM scriplet. Resolves:#1243775 - Allow snapperd to pass data (one way only) via pipe negotiated over dbus Resolves:#1250550 - Allow lsmd also setuid capability. Some commands need to executed under root privs. Other commands are executed under unprivileged user.- Allow openhpid to use libsnmp_bc plugin (allow read snmp lib files). Resolves: #1243902 - Allow lsm_plugin_t to read sysfs, read hwdata, rw to scsi_generic_device Resolves: #1238079 - Allow lsm_plugin_t to rw raw_fixed_disk. Resolves:#1238079 - Allow rhsmcertd to send signull to unconfined_service.- Allow httpd_suexec_t to read and write Apache stream sockets Resolves: #1243569 - Allow qpid to create lnk_files in qpid_var_lib_t Resolves: #1247279- Allow drbd to get attributes from filesystems. - Allow redis to read kernel parameters. Resolves: #1209518 - Allow virt_qemu_ga_t domtrans to passwd_t - Allow audisp_remote_t to start power unit files domain to allow halt system. Resolves: #1186780 - Allow audisp_remote_t to read/write user domain pty. Resolves: #1186780 - Label /usr/sbin/chpasswd as passwd_exec_t. - Allow sysadm to administrate ldap environment and allow to bind ldap port to allow to setup an LDAP server (389ds). Resolves:#1221121- gnome_dontaudit_search_config() needs to be a part of optinal_policy in pegasus.te - Allow pcp_pmcd daemon to read postfix config files. - Allow pcp_pmcd daemon to search postfix spool dirs. Resolves: #1213740 - Added Booleans: pcp_read_generic_logs. Resolves: #1213740 - Allow drbd to read configuration options used when loading modules. Resolves: #1134883 - Allow glusterd to manage nfsd and rpcd services. - Allow glusterd to communicate with cluster domains over stream socket. - glusterd call pcs utility which calls find for cib.* files and runs pstree under glusterd. Dontaudit access to security files and update gluster boolean to reflect these changes.- Allow glusterd to manage nfsd and rpcd services. - Allow networkmanager to communicate via dbus with systemd_hostanmed. Resolves: #1234954 - Allow stream connect logrotate to prosody. - Add prosody_stream_connect() interface. - httpd should be able to send signal/signull to httpd_suexec_t, instead of httpd_suexec_exec_t. - Allow prosody to create own tmp files/dirs. Resolves:#1212498- Allow networkmanager read rfcomm port. Resolves:#1212498 - Remove non exists label. - Fix *_admin intefaces where body is not consistent with header. - Label /usr/afs/ as afs_files_t, Allow afs_bosserver_t create afs_config_t and afs_dbdir_t dirs under afs_files_t, Allow afs_bosserver_t read kerberos config - Remove non exits nfsd_ro_t label. - Make all interfaces related to openshift_cache_t as deprecated. - Add rpm_var_run_t label to rpm_admin header - Add jabberd_lock_t label to jabberd_admin header. - Add samba_unconfined_script_exec_t to samba_admin header. - inn daemon should create innd_log_t objects in var_log_t instead of innd_var_run_t - Fix ctdb policy - Add samba_signull_winbind() - Add samba_signull_unconfined_net() - Allow ctdbd_t send signull to samba_unconfined_net_t. - Allow openshift_initrc_t to communicate with firewalld over dbus Resolves:#1221326- Allow gluster to connect to all ports. It is required by random services executed by gluster. - Add interfaces winbind_signull(), samba_unconfined_net_signull(). - Dontaudit smbd_t block_suspend capability. This is kernel bug. - Allow ctdbd sending signull to process winbind, samba_unconfined_net, to checking if processes exists. - Add tmpreaper booleans to use nfs_t and samba_share_t. - Fix path from /usr/sbin/redis-server to /usr/bin/redis-server - Allow connect ypserv to portmap_port_t - Fix paths in inn policy, Allow innd read innd_log_t dirs, Allow innd execute innd_etc_t files - Add support for openstack-nova-* packages - Allow NetworkManager_t send signull to dnssec_trigger_t. - Allow glusterd to execute showmount in the showmount domain. - Label swift-container-reconciler binary as swift_t. - Allow dnssec_trigger_t relabelfrom dnssec_trigger_var_run_t files. - Add cobbler_var_lib_t to "/var/lib/tftpboot/boot(/.*)?" Resolves:#1213540 - Merge all nova_* labels under one nova_t.- Add logging_syslogd_run_nagios_plugins boolean for rsyslog to allow transition to nagios unconfined plugins Resolves:#1233550 - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/ - Add support for oddjob based helper in FreeIPA. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add nagios_domtrans_unconfined_plugins() interface. - Update mta_filetrans_named_content() interface to cover more db files. Resolves:#1167468 - Add back ftpd_use_passive_mode boolean with fixed description. - Allow pmcd daemon stream connect to mysqld. - Allow pcp domains to connect to own process using unix_stream_socket. Resolves:#1213709 - Allow abrt-upload-watch service to dbus chat with ABRT daemon and fsetid capability to allow run reporter-upload correctly. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add support for oddjob based helper in FreeIPA. - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/- Allow iptables to read ctdbd lib files. Resolves:#1224879 - Add systemd_networkd_t to nsswitch domains. - Allow drbd_t write to fixed_disk_device. Reason: drbdmeta needs write to fixed_disk_device during initialization. Resolves:#1130675 - Allow NetworkManager write to sysfs. - Fix cron_system_cronjob_use_shares boolean to call fs interfaces which contain only entrypoint permission. - Add cron_system_cronjob_use_shares boolean to allow system cronjob to be executed from shares - NFS, CIFS, FUSE. It requires "entrypoint" permissios on nfs_t, cifs_t and fusefs_t SELinux types. - Allow NetworkManager write to sysfs. - Allow ctdb_t sending signull to smbd_t, for checking if smbd process exists. - Dontaudit apache to manage snmpd_var_lib_t files/dirs. - Add interface snmp_dontaudit_manage_snmp_var_lib_files(). - Dontaudit mozilla_plugin_t cap. sys_ptrace. - Rename xodbc-connect port to xodbc_connect - Allow ovsdb-server to connect on xodbc-connect and ovsdb tcp ports. - Allow iscsid write to fifo file kdumpctl_tmp_t. Appears when kdump generates the initramfs during the kernel boot. - Dontaudit chrome to read passwd file. - nrpe needs kill capability to make gluster moniterd nodes working. Resolves:#1235587- We allow can_exec() on ssh_keygen on gluster. But there is a transition defined by init_initrc_domain() because we need to allow execute unconfined services by glusterd. So ssh-keygen ends up with ssh_keygen_t and we need to allow to manage /var/lib/glusterd/geo-replication/secret.pem. - Allow sshd to execute gnome-keyring if there is configured pam_gnome_keyring.so. - Allow gnome-keyring executed by passwd to access /run/user/UID/keyring to change a password. - Label gluster python hooks also as bin_t. - Allow glusterd to interact with gluster tools running in a user domain - Add glusterd_manage_lib_files() interface. - ntop reads /var/lib/ntop/macPrefix.db and it needs dac_override. It has setuid/setgid. - Allow samba_t net_admin capability to make CIFS mount working. - S30samba-start gluster hooks wants to search audit logs. Dontaudit it. Resolves:#1224879- Allow glusterd to send generic signals to systemd_passwd_agent processes. - Allow glusterd to access init scripts/units without defined policy - Allow glusterd to run init scripts. - Allow glusterd to execute /usr/sbin/xfs_dbin glusterd_t domain. Resolves:#1224879- Calling cron_system_entry() in pcp_domain_template needs to be a part of optional_policy block. - Allow samba-net to access /var/lib/ctdbd dirs/files. - Allow glusterd to send a signal to smbd. - Make ctdbd as home manager to access also FUSE. - Allow glusterd to use geo-replication gluster tool. - Allow glusterd to execute ssh-keygen. - Allow glusterd to interact with cluster services. - Allow glusterd to connect to the system DBUS for service (acquire_svc). - Label /dev/log correctly. Resolves:#1230932- Back port the latest F22 changes to RHEL7. It should fix most of RHEL7.2 bugs - Add cgdcbxd policy Resolves:#1072493 - Fix ftp_homedir boolean Resolve:#1097775 - Dontaudit ifconfig writing inhertited /var/log/pluto.log. - Allow cluster domain to dbus chat with systemd-logind. Resolves:#1145215 - Dontaudit write access to inherited kdumpctl tmp files Resolves:#1156442 - Allow isnsd_t to communicate with sssd Resolves:#1167702 - Allow rwho_t to communicate with sssd Resolves:#1167718 - Allow sblim_gatherd_t to communicate with sssd Resolves:#1167732 - Allow pkcs_slotd_t to communicate with sssd Resolves:#1167737 - Allow openvswitch_t to communicate with sssd Resolves:#1167816 - Allow mysqld_safe_t to communicate with sssd Resolves:#1167832 - Allow sshd_keygen_t to communicate with sssd Resolves:#1167840 - Add support for iprdbg logging files in /var/log. Resolves:#1174363 - Allow tmpreaper_t to manage ntp log content Resolves:#1176965 - Allow gssd_t to manage ssh keyring Resolves:#1184791 - Allow httpd_sys_script_t to send system log messages Resolves:#1185231 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow dovecot_t sys_resource capability Resolves:#1191143 - Add support for mongod/mongos systemd unit files. Resolves:#1197038 - Add bacula fixes - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. Resolves:#1203991- Label /usr/libexec/postgresql-ctl as postgresql_exec_t. - Add more restriction on entrypoint for unconfined domains. - Only allow semanage_t to be able to setenforce 0, no all domains that use selinux_semanage interface - Allow all domains to read /dev/urandom. It is needed by all apps/services linked to libgcrypt. There is no harm to allow it by default. - Update policy/mls for sockets related to access perm. Rules were contradictory. - Add nagios_run_pnp4nagios and nagios_run_sudo booleans to allow r un sudo from NRPE utils scripts and allow run nagios in conjunction w ith PNP4Nagios. Resolves:#1201054 - Don't use deprecated userdom_manage_tmpfs_role() interface calliing and use userdom_manage_tmp_role() instead. - Update virt_read_pid_files() interface to allow read also symlinks with virt_var_run_t type - Label /var/lib/tftpboot/aarch64(/.*)? and /var/lib/tftpboot/images2(/.*)? - Add support for iprdbg logging files in /var/log. - Add fixes to rhsmcertd_t - Allow puppetagent_t to transfer firewalld messages over dbus - Add support for /usr/libexec/mongodb-scl-helper RHSCL helper script. - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. - Add support for mongod/mongos systemd unit files. - cloudinit and rhsmcertd need to communicate with dbus - Allow dovecot_t sys_resource capability- ALlow mongod execmem by default. - Update policy/mls for sockets. Rules were contradictory. Resolves:#1207133 - Allow a user to login with different security level via ssh.- Update seutil_manage_config() interface. Resolves:#1185962 - Allow pki-tomcat relabel pki_tomcat_etc_rw_t. - Turn on docker_transition_unconfined by default- Allow virtd to list all mountpoints. Resolves:#1180713- pkcsslotd_lock_t should be an alias for pkcs_slotd_lock_t. - Allow fowner capability for sssd because of selinux_child handling. - ALlow bind to read/write inherited ipsec pipes - Allow hypervkvp to read /dev/urandom and read addition states/config files. - Allow gluster rpm scripletto create glusterd socket with correct labeling. This is a workaround until we get fix in glusterd. - Add glusterd_filetrans_named_pid() interface - Allow radiusd to connect to radsec ports. - Allow setuid/setgid for selinux_child - Allow lsmd plugin to connect to tcp/5988 by default. - Allow lsmd plugin to connect to tcp/5989 by default. - Update ipsec_manage_pid() interface. Resolves:#1184978- Update ipsec_manage_pid() interface. Resolves:#1184978- Allow ntlm_auth running in winbind_helper_t to access /dev/urandom.- Add auditing support for ipsec. Resolves:#1182524 - Label /ostree/deploy/rhel-atomic-host/deploy directory as system_conf_t - Allow netutils chown capability to make tcpdump working with -w- Allow ipsec to execute _updown.netkey script to run unbound-control. - Allow neutron to read rpm DB. - Add additional fixes for hyperkvp * creates new ifcfg-{name} file * Runs hv_set_ifconfig.sh, which does the following * Copies ifcfg-{name} to /etc/sysconfig/network-scripts - Allow svirt to read symbolic links in /sys/fs/cgroups labeled as tmpfs_t - Add labeling for pacemaker.log. - Allow radius to connect/bind radsec ports. - Allow pm-suspend running as virt_qemu_ga to read /var/log/pm-suspend.log - Allow virt_qemu_ga to dbus chat with rpm. - Update virt_read_content() interface to allow read also char devices. - Allow glance-registry to connect to keystone port. Resolves:#1181818- Allow sssd to send dbus all user domains. Resolves:#1172291 - Allow lsm plugin to read certificates. - Fix labeling for keystone CGI scripts. - Make snapperd back as unconfined domain.- Fix bugs in interfaces discovered by sepolicy. - Allow slapd to read /usr/share/cracklib/pw_dict.hwm. - Allow lsm plugins to connect to tcp/18700 by default. - Allow brltty mknod capability to allow create /var/run/brltty/vcsa. - Fix pcp_domain_template() interface. - Fix conman.te. - Allow mon_fsstatd to read /proc/sys/fs/binfmt_misc - Allow glance-scrubber to connect tcp/9191. - Add missing setuid capability for sblim-sfcbd. - Allow pegasus ioctl() on providers. - Add conman_can_network. - Allow chronyd to read chrony conf files located in /run/timemaster/. - Allow radius to bind on tcp/1813 port. - dontaudit block suspend access for openvpn_t - Allow conman to create files/dirs in /tmp. - Update xserver_rw_xdm_keys() interface to have 'setattr'. Resolves:#1172291 - Allow sulogin to read /dev/urandom and /dev/random. - Update radius port definition to have also tcp/18121 - Label prandom as random_device_t. - Allow charon to manage files in /etc/strongimcv labeled as ipsec_conf_t.- Allow virt_qemu_ga_t to execute kmod. - Add missing files_dontaudit_list_security_dirs() for smbd_t in samba_export_all_ro boolean. - Add additionnal MLS attribute for oddjob_mkhomedir to create homedirs. Resolves:#1113725 - Enable OpenStack cinder policy - Add support for /usr/share/vdsm/daemonAdapter - Add support for /var/run/gluster- Remove old pkcsslotd.pp from minimum package - Allow rlogind to use also rlogin ports. - Add support for /usr/libexec/ntpdate-wrapper. Label it as ntpdate_exec_t. - Allow bacula to connect also to postgresql. - Label /usr/libexec/tomcat/server as tomcat_exec_t - Add support for /usr/sbin/ctdbd_wrapper - Add support for /usr/libexec/ppc64-diag/rtas_errd - Allow rpm_script_roles to access system_mail_t - Allow brltty to create /var/run/brltty - Allow lsmd plugin to access netlink_route_socket - Allow smbcontrol to read passwd - Add support for /usr/libexec/sssd/selinux_child and create sssd_selinux_manager_t domain for it Resolves:#1140106 - Allow osad to execute rhn_check - Allow load_policy to rw inherited sssd pipes because of selinux_child - Allow admin SELinux users mounting / as private within a new mount namespace as root in MLS - Add additional fixes for su_restricted_domain_template to make moving to sysadm_r and trying to su working correctly - Add additional booleans substitions- Add seutil_dontaudit_access_check_semanage_module_store() interface Resolves:#1140106 - Update to have all _systemctl() interface also init_reload_services(). - Dontaudit access check on SELinux module store for sssd. - Add labeling for /sbin/iw. - Allow named_filetrans_domain to create ibus directory with correct labeling.- Allow radius to bind tcp/1812 radius port. - Dontaudit list user_tmp files for system_mail_t. - Label virt-who as virtd_exec_t. - Allow rhsmcertd to send a null signal to virt-who running as virtd_t. - Add missing alias for _content_rw_t. Resolves:#1089177 - Allow spamd to access razor-agent.log. - Add fixes for sfcb from libvirt-cim TestOnly bug. - Allow NetworkManager stream connect on openvpn. - Make /usr/bin/vncserver running as unconfined_service_t. - getty_t should be ranged in MLS. Then also local_login_t runs as ranged domain. - Label /etc/docker/certs.d as cert_t.- Label /etc/strongimcv as ipsec_conf_file_t. - Add support for /usr/bin/start-puppet-ca helper script Resolves:#1160727 - Allow rpm scripts to enable/disable transient systemd units. Resolves:#1154613 - Make kpropdas nsswitch domain Resolves:#1153561 - Make all glance domain as nsswitch domains Resolves:#1113281 - Allow selinux_child running as sssd access check on /etc/selinux/targeted/modules/active - Allow access checks on setfiles/load_policy/semanage_lock for selinux_child running as sssd_t Resolves:#1140106- Dontaudit access check on setfiles/load_policy for sssd_t. Resolves:#1140106 - Add kdump_rw_inherited_kdumpctl_tmp_pipes() Resolves:#1156442 - Make linuxptp services as unconfined. - Added new policy linuxptp. Resolves:#1149693 - Label keystone cgi files as keystone_cgi_script_exec_t. Resolves:#1138424 - Make tuned as unconfined domain- Allow guest to connect to libvirt using unix_stream_socket. - Allow all bus client domains to dbus chat with unconfined_service_t. - Allow inetd service without own policy to run in inetd_child_t which is unconfined domain. - Make opensm as nsswitch domain to make it working with sssd. - Allow brctl to read meminfo. - Allow winbind-helper to execute ntlm_auth in the caller domain. Resolves:#1160339 - Make plymouthd as nsswitch domain to make it working with sssd. Resolves:#1160196 - Make drbd as nsswitch domain to make it working with sssd. - Make conman as nsswitch domain to make ipmitool.exp runing as conman_t working. - Add support for /var/lib/sntp directory. - Add fixes to allow docker to create more content in tmpfs ,and donaudit reading /proc - Allow winbind to read usermodehelper - Allow telepathy domains to execute shells and bin_t - Allow gpgdomains to create netlink_kobject_uevent_sockets - Allow mongodb to bind to the mongo port and mongos to run as mongod_t - Allow abrt to read software raid state. - Allow nslcd to execute netstat. - Allow dovecot to create user's home directory when they log into IMAP. - Allow login domains to create kernel keyring with different level.- Allow modemmanger to connectto itself Resolves:#1120152 - Allow pki_tomcat to create link files in /var/lib/pki-ca. Resolves:#1121744 - varnishd needs to have fsetid capability Resolves:#1125165 - Allow snapperd to dbus chat with system cron jobs. Resolves:#1152447 - Allow dovecot to create user's home directory when they log into IMAP Resolves:#1152773 - Add labeling for /usr/sbin/haproxy-systemd-wrapper wrapper to make haproxy running haproxy_t. - ALlow listen and accept on tcp socket for init_t in MLS. Previously it was for xinetd_t. - Allow nslcd to execute netstat. - Add suppor for keepalived unconfined scripts and allow keepalived to read all domain state and kill capability. - Allow nslcd to read /dev/urandom.- Add back kill permisiion for system class Resolves:#1150011- Add back kill permisiion for service class Resolves:#1150011 - Make rhsmcertd_t also as dbus domain. - Allow named to create DNS_25 with correct labeling. - Add cloudform_dontaudit_write_cloud_log() - Call auth_use_nsswitch to apache to read/write cloud-init keys. - Allow cloud-init to dbus chat with certmonger. - Fix path to mon_statd_initrc_t script. - Allow all RHCS services to read system state. - Allow dnssec_trigger_t to execute unbound-control in own domain. - kernel_read_system_state needs to be called with type. Moved it to antivirus.if. - Added policy for mon_statd and mon_procd services. BZ (1077821) - Allow opensm_t to read/write /dev/infiniband/umad1. - Allow mongodb to manage own log files. - Allow neutron connections to system dbus. - Add support for /var/lib/swiftdirectory. - Allow nova-scheduler to read certs. - Allow openvpn to access /sys/fs/cgroup dir. - Allow openvpn to execute systemd-passwd-agent in systemd_passwd_agent_t to make openvpn working with systemd. - Fix samba_export_all_ro/samba_export_all_rw booleans to dontaudit search/read security files. - Add auth_use_nsswitch for portreserve to make it working with sssd. - automount policy is non-base module so it needs to be called in optional block. - ALlow sensord to getattr on sysfs. - Label /usr/share/corosync/corosync as cluster_exec_t. - Allow lmsd_plugin to read passwd file. BZ(1093733) - Allow read antivirus domain all kernel sysctls. - Allow mandb to getattr on file systems - Allow nova-console to connect to mem_cache port. - Make sosreport as unconfined domain. - Allow mondogdb to 'accept' accesses on the tcp_socket port. - ALlow sanlock to send a signal to virtd_t.- Build also MLS policy Resolves:#1138424- Add back kill permisiion for system class - Allow iptables read fail2ban logs. - Fix radius labeled ports - Add userdom_manage_user_tmpfs_files interface - Allow libreswan to connect to VPN via NM-libreswan. - Label 4101 tcp port as brlp port - fix dev_getattr_generic_usb_dev interface - Allow all domains to read fonts - Make sure /run/systemd/generator and system is labeled correctly on creation. - Dontaudit aicuu to search home config dir. - Make keystone_cgi_script_t domain. Resolves:#1138424 - Fix bug in drbd policy, - Added support for cpuplug. - ALlow sanlock_t to read sysfs_t. - Added sendmail_domtrans_unconfined interface - Fix broken interfaces - radiusd wants to write own log files. - Label /usr/libexec/rhsmd as rhsmcertd_exec_t - Allow rhsmcertd send signull to setroubleshoot. - Allow rhsmcertd manage rpm db. - Added policy for blrtty. - Fix keepalived policy - Allow rhev-agentd dbus chat with systemd-logind. - Allow keepalived manage snmp var lib sock files. - Add support for /var/lib/graphite-web - Allow NetworkManager to create Bluetooth SDP sockets - It's going to do the the discovery for DUN service for modems with Bluez 5. - Allow swift to connect to all ephemeral ports by default. - Allow sssd to read selinux config to add SELinux user mapping. - Allow lsmd to search own plguins. - Allow abrt to read /dev/memto generate an unique machine_id and uses sosuploader's algorithm based off dmidecode[1] fields. - ALlow zebra for user/group look-ups. - Allow nova domains to getattr on all filesystems. - Allow collectd sys_ptrace and dac_override caps because of reading of /proc/%i/io for several processes. - Allow pppd to connect to /run/sstpc/sstpc-nm-sstp-service-28025 over unix stream socket. - Allow rhnsd_t to manage also rhnsd config symlinks. - ALlow user mail domains to create dead.letter. - Allow rabbitmq_t read rabbitmq_var_lib_t lnk files. - Allow pki-tomcat to change SELinux object identity. - Allow radious to connect to apache ports to do OCSP check - Allow git cgi scripts to create content in /tmp - Allow cockpit-session to do GSSAPI logins. - Allow sensord read in /proc - Additional access required by usbmuxd- Allow locate to look at files/directories without labels, and chr_file and blk_file on non dev file systems - Label /usr/lib/erlang/erts.*/bin files as bin_t - Add files_dontaudit_access_check_home_dir() inteface. - Allow udev_t mounton udev_var_run_t dirs #(1128618) - Add systemd_networkd_var_run_t labeling for /var/run/systemd/netif and allow systemd-networkd to manage it. - Add init_dontaudit_read_state() interface. - Add label for ~/.local/share/fonts - Allow unconfined_r to access unconfined_service_t. - Allow init to read all config files - Add new interface to allow creation of file with lib_t type - Assign rabbitmq port. - Allow unconfined_service_t to dbus chat with all dbus domains - Add new interfaces to access users keys. - Allow domains to are allowed to mounton proc to mount on files as well as dirs - Fix labeling for HOME_DIR/tmp and HOME_DIR/.tmp directories. - Add a port definition for shellinaboxd - Label ~/tmp and ~/.tmp directories in user tmp dirs as user_tmp_t - Allow userdomains to stream connect to pcscd for smart cards - Allow programs to use pam to search through user_tmp_t dires (/tmp/.X11-unix) - Update to rawhide-contrib changes Resolves:#1123844- Rebase to 3.13.1 which we have in Fedora21 Resolves:#1128284- Back port fixes from Fedora. Mainly OpenStack and Docker fixes- Add policy-rhel-7.1-{base,contrib} patches- Add support for us_cli ports - Fix labeling for /var/run/user//gvfs - add support for tcp/9697 - Additional rules required by openstack, needs backport to F20 and RHEL7 - Additional access required by docker - ALlow motion to use tcp/8082 port - Allow init_t to setattr/relabelfrom dhcp state files - Dontaudit antivirus domains read access on all security files by default - Add missing alias for old amavis_etc_t type - Allow block_suspend cap for haproxy - Additional fixes for instack overcloud - Allow OpenStack to read mysqld_db links and connect to MySQL - Remove dup filename rules in gnome.te - Allow sys_chroot cap for httpd_t and setattr on httpd_log_t - Allow iscsid to handle own unit files - Add iscsi_systemctl() - Allow mongod to create also sock_files in /run with correct labeling - Allow httpd to send signull to apache script domains and don't audit leaks - Allow rabbitmq_beam to connect to httpd port - Allow aiccu stream connect to pcscd - Allow dmesg to read hwdata and memory dev - Allow all freeipmi domains to read/write ipmi devices - Allow sblim_sfcbd to use also pegasus-https port - Allow rabbitmq_epmd to manage rabbit_var_log_t files - Allow chronyd to read /sys/class/hwmon/hwmon1/device/temp2_input - Allow docker to status any unit file and allow it to start generic unit files- Change hsperfdata_root to have as user_tmp_t Resolves:#1076523- Fix Multiple same specifications for /var/named/chroot/dev/zero - Add labels for /var/named/chroot_sdb/dev devices - Add support for strongimcv - Use kerberos_keytab_domains in auth_use_nsswitch - Update auth_use_nsswitch to make all these types as kerberos_keytab_domain to - Allow net_raw cap for neutron_t and send sigkill to dnsmasq - Fix ntp_filetrans_named_content for sntp-kod file - Add httpd_dbus_sssd boolean - Dontaudit exec insmod in boinc policy - Rename kerberos_keytab_domain to kerberos_keytab_domains - Add kerberos_keytab_domain() - Fix kerberos_keytab_template() - Make all domains which use kerberos as kerberos_keytab_domain Resolves:#1083670 - Allow kill capability to winbind_t- varnishd wants chown capability - update ntp_filetrans_named_content() interface - Add additional fixes for neutron_t. #1083335 - Dontaudit getattr on proc_kcore_t - Allow pki_tomcat_t to read ipa lib files - Allow named_filetrans_domain to create /var/cache/ibus with correct labelign - Allow init_t run /sbin/augenrules - Add dev_unmount_sysfs_fs and sysnet_manage_ifconfig_run interfaces - Allow unpriv SELinux user to use sandbox - Add default label for /tmp/hsperfdata_root- Add file subs also for /var/home- Allow xauth_t to read user_home_dir_t lnk_file - Add labeling for lightdm-data - Allow certmonger to manage ipa lib files - Add support for /var/lib/ipa - Allow pegasus to getattr virt_content - Added some new rules to pcp policy - Allow chrome_sandbox to execute config_home_t - Add support for ABRT FAF- Allow kdm to send signull to remote_login_t process - Add gear policy - Turn on gear_port_t - Allow cgit to read gitosis lib files by default - Allow vdagent to read xdm state - Allow NM and fcoeadm to talk together over unix_dgram_socket- Back port fixes for pegasus_openlmi_admin_t from rawhide Resolves:#1080973 - Add labels for ostree - Add SELinux awareness for NM - Label /usr/sbin/pwhistory_helper as updpwd_exec_t- add gnome_append_home_config() - Allow thumb to append GNOME config home files - Allow rasdaemon to rw /dev/cpu//msr - fix /var/log/pki file spec - make bacula_t as auth_nsswitch domain - Identify pki_tomcat_cert_t as a cert_type - Define speech-dispater_exec_t as an application executable - Add a new file context for /var/named/chroot/run directory - update storage_filetrans_all_named_dev for sg* devices - Allow auditctl_t to getattr on all removeable devices - Allow nsswitch_domains to stream connect to nmbd - Allow unprivusers to connect to memcached - label /var/lib/dirsrv/scripts-INSTANCE as bin_t- Allow also unpriv user to run vmtools - Allow secadm to read /dev/urandom and meminfo Resolves:#1079250 - Add booleans to allow docker processes to use nfs and samba - Add mdadm_tmpfs support - Dontaudit net_amdin for /usr/lib/jvm/java-1.7.0-openjdk-1.7.0.51-2.4.5.1.el7.x86_64/jre-abrt/bin/java running as pki_tomcat_t - Allow vmware-user-sui to use user ttys - Allow talk 2 users logged via console too - Allow ftp services to manage xferlog_t - Make all pcp domanis as unconfined for RHEL7.0 beucause of new policies - allow anaconda to dbus chat with systemd-localed- allow anaconda to dbus chat with systemd-localed - Add fixes for haproxy based on bperkins@redhat.com - Allow cmirrord to make dmsetup working - Allow NM to execute arping - Allow users to send messages through talk - Add userdom_tmp_role for secadm_t- Add additional fixes for rtas_errd - Fix transitions for tmp/tmpfs in rtas.te - Allow rtas_errd to readl all sysctls- Add support for /var/spool/rhsm/debug - Make virt_sandbox_use_audit as True by default - Allow svirt_sandbox_domains to ptrace themselves- Allow docker containers to manage /var/lib/docker content- Allow docker to read tmpfs_t symlinks - Allow sandbox svirt_lxc_net_t to talk to syslog and to sssd over stream sockets- Allow collectd to talk to libvirt - Allow chrome_sandbox to use leaked unix_stream_sockets - Dontaudit leaks of sockets into chrome_sandbox_t - If you create a cups directory in /var/cache then it should be labeled cups_rw_etc_t - Run vmtools as unconfined domains - Allow snort to manage its log files - Allow systemd_cronjob_t to be entered via bin_t - Allow procman to list doveconf_etc_t - allow keyring daemon to create content in tmpfs directories - Add proper labelling for icedtea-web - vpnc is creating content in networkmanager var run directory - Label sddm as xdm_exec_t to make KDE working again - Allow postgresql to read network state - Allow java running as pki_tomcat to read network sysctls - Fix cgroup.te to allow cgred to read cgconfig_etc_t - Allow beam.smp to use ephemeral ports - Allow winbind to use the nis to authenticate passwords- Make rtas_errd_t as unconfined domain for F20.It needs additional fixes. It runs rpm at least. - Allow net_admin cap for fence_virtd running as fenced_t - Make abrt-java-connector working - Make cimtest script 03_defineVS.py of ComputerSystem group working - Fix git_system_enable_homedirs boolean - Allow munin mail plugins to read network systcl- Allow vmtools_helper_t to execute bin_t - Add support for /usr/share/joomla - /var/lib/containers should be labeled as openshift content for now - Allow docker domains to talk to the login programs, to allow a process to login into the container - Allow install_t do dbus chat with NM - Fix interface names in anaconda.if - Add install_t for anaconda. A new type is a part of anaconda policy - sshd to read network sysctls- Allow zabbix to send system log msgs - Allow init_t to stream connect to ipsec Resolves:#1060775- Add docker_connect_any boolean- Allow unpriv SELinux users to dbus chat with firewalld - Add lvm_write_metadata() - Label /etc/yum.reposd dir as system_conf_t. Should be safe because system_conf_t is base_ro_file_type - Allow pegasus_openlmi_storage_t to write lvm metadata - Add hide_broken_symptoms for kdumpgui because of systemd bug - Make kdumpgui_t as unconfined domain Resolves:#1044299 - Allow docker to connect to tcp/5000- Allow numad to write scan_sleep_millisecs - Turn on entropyd_use_audio boolean by default - Allow cgred to read /etc/cgconfig.conf because it contains templates used together with rules from /etc/cgrules.conf. - Allow lscpu running as rhsmcertd_t to read /proc/sysinfo - Fix label on irclogs in the homedir - Allow kerberos_keytab_domain domains to manage keys until we get sssd fix - Allow postgresql to use ldap - Add missing syslog-conn port - Add support for /dev/vmcp and /dev/sclp Resolves:#1069310- Modify xdm_write_home to allow create files/links in /root with xdm_home_ - Allow virt domains to read network state Resolves:#1072019- Added pcp rules - dontaudit openshift_cron_t searching random directories, should be back ported to RHEL6 - clean up ctdb.te - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow certmonger to list home dirs- Change userdom_use_user_inherited_ttys to userdom_use_user_ttys for systemd-tty-ask - Add sysnet_filetrans_named_content_ifconfig() interface - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow kerberos keytab domains to manage sssd/userdomain keys" - Allow to run ip cmd in neutron_t domain- Allow block_suspend cap2 for systemd-logind and rw dri device - Add labeling for /usr/libexec/nm-libreswan-service - Allow locallogin to rw xdm key to make Virtual Terminal login providing smartcard pin working - Add xserver_rw_xdm_keys() - Allow rpm_script_t to dbus chat also with systemd-located - Fix ipa_stream_connect_otpd() - update lpd_manage_spool() interface - Allow krb5kdc to stream connect to ipa-otpd - Add ipa_stream_connect_otpd() interface - Allow vpnc to unlink NM pids - Add networkmanager_delete_pid_files() - Allow munin plugins to access unconfined plugins - update abrt_filetrans_named_content to cover /var/spool/debug - Label /var/spool/debug as abrt_var_cache_t - Allow rhsmcertd to connect to squid port - Make docker_transition_unconfined as optional boolean - Allow certmonger to list home dirs- Make snapperd as unconfined domain and add additional fixes for it - Remove nsplugin.pp module on upgrade- Add snapperd_home_t for HOME_DIR/.snapshots directory - Make sosreport as unconfined domain - Allow sosreport to execute grub2-probe - Allow NM to manage hostname config file - Allow systemd_timedated_t to dbus chat with rpm_script_t - Allow lsmd plugins to connect to http/ssh/http_cache ports by default - Add lsmd_plugin_connect_any boolean - Allow mozilla_plugin to attempt to set capabilities - Allow lsdm_plugins to use tcp_socket - Dontaudit mozilla plugin from getattr on /proc or /sys - Dontaudit use of the keyring by the services in a sandbox - Dontaudit attempts to sys_ptrace caused by running ps for mysqld_safe_t - Allow rabbitmq_beam to connect to jabber_interserver_port - Allow logwatch_mail_t to transition to qmail_inject and queueu - Added new rules to pcp policy - Allow vmtools_helper_t to change role to system_r - Allow NM to dbus chat with vmtools - Fix couchdb_manage_files() to allow manage couchdb conf files - Add support for /var/run/redis.sock - dontaudit gpg trying to use audit - Allow consolekit to create log directories and files - Fix vmtools policy to allow user roles to access vmtools_helper_t - Allow block_suspend cap2 for ipa-otpd - Allow pkcsslotd to read users state - Add ioctl to init_dontaudit_rw_stream_socket - Add systemd_hostnamed_manage_config() interface - Remove transition for temp dirs created by init_t - gdm-simple-slave uses use setsockopt - sddm-greater is a xdm type program- Add lvm_read_metadata() - Allow auditadm to search /var/log/audit dir - Add lvm_read_metadata() interface - Allow confined users to run vmtools helpers - Fix userdom_common_user_template() - Generic systemd unit scripts do write check on / - Allow init_t to create init_tmp_t in /tmp.This is for temporary content created by generic unit files - Add additional fixes needed for init_t and setup script running in generic unit files - Allow general users to create packet_sockets - added connlcli port - Add init_manage_transient_unit() interface - Allow init_t (generic unit files) to manage rpc state date as we had it for initrc_t - Fix userdomain.te to require passwd class - devicekit_power sends out a signal to all processes on the message bus when power is going down - Dontaudit rendom domains listing /proc and hittping system_map_t - Dontauit leaks of var_t into ifconfig_t - Allow domains that transition to ssh_t to manipulate its keyring - Define oracleasm_t as a device node - Change to handle /root as a symbolic link for os-tree - Allow sysadm_t to create packet_socket, also move some rules to attributes - Add label for openvswitch port - Remove general transition for files/dirs created in /etc/mail which got etc_aliases_t label. - Allow postfix_local to read .forward in pcp lib files - Allow pegasus_openlmi_storage_t to read lvm metadata - Add additional fixes for pegasus_openlmi_storage_t - Allow bumblebee to manage debugfs - Make bumblebee as unconfined domain - Allow snmp to read etc_aliases_t - Allow lscpu running in pegasus_openlmi_storage_t to read /dev/mem - Allow pegasus_openlmi_storage_t to read /proc/1/environ - Dontaudit read gconf files for cupsd_config_t - make vmtools as unconfined domain - Add vmtools_helper_t for helper scripts. Allow vmtools shutdonw a host and run ifconfig. - Allow collectd_t to use a mysql database - Allow ipa-otpd to perform DNS name resolution - Added new policy for keepalived - Allow openlmi-service provider to manage transitient units and allow stream connect to sssd - Add additional fixes new pscs-lite+polkit support - Add labeling for /run/krb5kdc - Change w3c_validator_tmp_t to httpd_w3c_validator_tmp_t in F20 - Allow pcscd to read users proc info - Dontaudit smbd_t sending out random signuls - Add boolean to allow openshift domains to use nfs - Allow w3c_validator to create content in /tmp - zabbix_agent uses nsswitch - Allow procmail and dovecot to work together to deliver mail - Allow spamd to execute files in homedir if boolean turned on - Allow openvswitch to listen on port 6634 - Add net_admin capability in collectd policy - Fixed snapperd policy - Fixed bugsfor pcp policy - Allow dbus_system_domains to be started by init - Fixed some interfaces - Add kerberos_keytab_domain attribute - Fix snapperd_conf_t def- Addopt corenet rules for unbound-anchor to rpm_script_t - Allow runuser to send send audit messages. - Allow postfix-local to search .forward in munin lib dirs - Allow udisks to connect to D-Bus - Allow spamd to connect to spamd port - Fix syntax error in snapper.te - Dontaudit osad to search gconf home files - Allow rhsmcertd to manage /etc/sysconf/rhn director - Fix pcp labeling to accept /usr/bin for all daemon binaries - Fix mcelog_read_log() interface - Allow iscsid to manage iscsi lib files - Allow snapper domtrans to lvm_t. Add support for /etc/snapper and allow snapperd to manage it. - Make tuned_t as unconfined domain for RHEL7.0 - Allow ABRT to read puppet certs - Add sys_time capability for virt-ga - Allow gemu-ga to domtrans to hwclock_t - Allow additional access for virt_qemu_ga_t processes to read system clock and send audit messages - Fix some AVCs in pcp policy - Add to bacula capability setgid and setuid and allow to bind to bacula ports - Changed label from rhnsd_rw_conf_t to rhnsd_conf_t - Add access rhnsd and osad to /etc/sysconfig/rhn - drbdadm executes drbdmeta - Fixes needed for docker - Allow epmd to manage /var/log/rabbitmq/startup_err file - Allow beam.smp connect to amqp port - Modify xdm_write_home to allow create also links as xdm_home_t if the boolean is on true - Allow init_t to manage pluto.ctl because of init_t instead of initrc_t - Allow systemd_tmpfiles_t to manage all non security files on the system - Added labels for bacula ports - Fix label on /dev/vfio/vfio - Add kernel_mounton_messages() interface - init wants to manage lock files for iscsi- Added osad policy - Allow postfix to deliver to procmail - Allow bumblebee to seng kill signal to xserver - Allow vmtools to execute /usr/bin/lsb_release - Allow docker to write system net ctrls - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix pcp.te - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl- Turn on bacula, rhnsd policy - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl - Fixes for *_admin interfaces - Add pegasus_openlmi_storage_var_run_t type def - Add support for /var/run/openlmi-storage - Allow tuned to create syslog.conf with correct labeling - Add httpd_dontaudit_search_dirs boolean - Add support for winbind.service - ALlow also fail2ban-client to read apache logs - Allow vmtools to getattr on all fs - Add support for dey_sapi port - Add logging_filetrans_named_conf() - Allow passwd_t to use ipc_lock, so that it can change the password in gnome-keyring- Update snapper policy - Allow domains to append rkhunter lib files - Allow snapperd to getattr on all fs - Allow xdm to create /var/gdm with correct labeling - Add label for snapper.log - Allow fail2ban-client to read apache log files - Allow thumb_t to execute dbus-daemon in thumb_t- Allow gdm to create /var/gdm with correct labeling - Allow domains to append rkhunterl lib files. #1057982 - Allow systemd_tmpfiles_t net_admin to communicate with journald - Add interface to getattr on an isid_type for any type of file - Update libs_filetrans_named_content() to have support for /usr/lib/debug directory - Allow initrc_t domtrans to authconfig if unconfined is enabled - Allow docker and mount on devpts chr_file - Allow docker to transition to unconfined_t if boolean set - init calling needs to be optional in domain.te - Allow uncofined domain types to handle transient unit files - Fix labeling for vfio devices - Allow net_admin capability and send system log msgs - Allow lldpad send dgram to NM - Add networkmanager_dgram_send() - rkhunter_var_lib_t is correct type - Back port pcp policy from rawhide - Allow openlmi-storage to read removable devices - Allow system cron jobs to manage rkhunter lib files - Add rkhunter_manage_lib_files() - Fix ftpd_use_fusefs boolean to allow manage also symlinks - Allow smbcontrob block_suspend cap2 - Allow slpd to read network and system state info - Allow NM domtrans to iscsid_t if iscsiadm is executed - Allow slapd to send a signal itself - Allow sslget running as pki_ra_t to contact port 8443, the secure port of the CA. - Fix plymouthd_create_log() interface - Add rkhunter policy with files type definition for /var/lib/rkhunter until it is fixed in rkhunter package - Add mozilla_plugin_exec_t for /usr/lib/firefox/plugin-container - Allow postfix and cyrus-imapd to work out of box - Allow fcoemon to talk with unpriv user domain using unix_stream_socket - Dontaudit domains that are calling into journald to net_admin - Add rules to allow vmtools to do what it does - snapperd is D-Bus service - Allow OpenLMI PowerManagement to call 'systemctl --force reboot' - Add haproxy_connect_any boolean - Allow haproxy also to use http cache port by default Resolves:#1058248- Allow apache to write to the owncloud data directory in /var/www/html... - Allow consolekit to create log dir - Add support for icinga CGI scripts - Add support for icinga - Allow kdumpctl_t to create kdump lock file Resolves:#1055634 - Allow kdump to create lnk lock file - Allow nscd_t block_suspen capability - Allow unconfined domain types to manage own transient unit file - Allow systemd domains to handle transient init unit files - Add interfaces to handle transient- Add cron unconfined role support for uncofined SELinux user - Call corenet_udp_bind_all_ports() in milter.te - Allow fence_virtd to connect to zented port - Fix header for mirrormanager_admin() - Allow dkim-milter to bind udp ports - Allow milter domains to send signull itself - Allow block_suspend for yum running as mock_t - Allow beam.smp to manage couchdb files - Add couchdb_manage_files() - Add labeling for /var/log/php_errors.log - Allow bumblebee to stream connect to xserver - Allow bumblebee to send a signal to xserver - gnome-thumbnail to stream connect to bumblebee - Allow xkbcomp running as bumblebee_t to execute bin_t - Allow logrotate to read squid.conf - Additional rules to get docker and lxc to play well with SELinux - Allow bumbleed to connect to xserver port - Allow pegasus_openlmi_storage_t to read hwdata- Allow init_t to work on transitient and snapshot unit files - Add logging_manage_syslog_config() - Update sysnet_dns_name_resolve() to allow connect to dnssec por - Allow pegasus_openlmi_storage_t to read hwdata Resolves:#1031721 - Fix rhcs_rw_cluster_tmpfs() - Allow fenced_t to bind on zented udp port - Added policy for vmtools - Fix mirrormanager_read_lib_files() - Allow mirromanager scripts running as httpd_t to manage mirrormanager pid files - Allow ctdb to create sock files in /var/run/ctdb - Add sblim_filetrans_named_content() interface - Allow rpm scritplets to create /run/gather with correct labeling - Allow gnome keyring domains to create gnome config dirs - Dontaudit read/write to init stream socket for lsmd_plugin_t - Allow automount to read nfs link files - Allow lsm plugins to read/write lsmd stream socket - Allow certmonger to connect ldap port to make IPA CA certificate renewal working. - Add also labeling for /var/run/ctdb - Add missing labeling for /var/lib/ctdb - ALlow tuned to manage syslog.conf. Should be fixed in tuned. #1030446 - Dontaudit hypervkvp to search homedirs - Dontaudit hypervkvp to search admin homedirs - Allow hypervkvp to execute bin_t and ifconfig in the caller domain - Dontaudit xguest_t to read ABRT conf files - Add abrt_dontaudit_read_config() - Allow namespace-init to getattr on fs - Add thumb_role() also for xguest - Add filename transitions to create .spamassassin with correct labeling - Allow apache domain to read mirrormanager pid files - Allow domains to read/write shm and sem owned by mozilla_plugin_t - Allow alsactl to send a generic signal to kernel_t- Add back rpm_run() for unconfined user- Add missing files_create_var_lib_dirs() - Fix typo in ipsec.te - Allow passwd to create directory in /var/lib - Add filename trans also for event21 - Allow iptables command to read /dev/rand - Add sigkill capabilityfor ipsec_t - Add filename transitions for bcache devices - Add additional rules to create /var/log/cron by syslogd_t with correct labeling - Add give everyone full access to all key rings - Add default lvm_var_run_t label for /var/run/multipathd - Fix log labeling to have correct default label for them after logrotate - Labeled ~/.nv/GLCache as being gstreamer output - Allow nagios_system_plugin to read mrtg lib files - Add mrtg_read_lib_files() - Call rhcs_rw_cluster_tmpfs for dlm_controld - Make authconfing as named_filetrans domain - Allow virsh to connect to user process using stream socket - Allow rtas_errd to read rand/urand devices and add chown capability - Fix labeling from /var/run/net-snmpd to correct /var/run/net-snmp Resolves:#1051497 - Add also chown cap for abrt_upload_watch_t. It already has dac_override - Allow sosreport to manage rhsmcertd pid files - Add rhsmcertd_manage_pid_files() - Allow also setgid cap for rpc.gssd - Dontaudit access check for abrt on cert_t - Allow pegasus_openlmi_system providers to dbus chat with systemd-logind- Fix semanage import handling in spec file- Add default lvm_var_run_t label for /var/run/multipathd Resolves:#1051430 - Fix log labeling to have correct default label for them after logrotate - Add files_write_root_dirs - Add new openflow port label for 6653/tcp and 6633/tcp - Add xserver_manage_xkb_libs() - Label tcp/8891 as milter por - Allow gnome_manage_generic_cache_files also create cache_home_t files - Fix aide.log labeling - Fix log labeling to have correct default label for them after logrotate - Allow mysqld-safe write access on /root to make mysqld working - Allow sosreport domtrans to prelikn - Allow OpenvSwitch to connec to openflow ports - Allow NM send dgram to lldpad - Allow hyperv domains to execute shell - Allow lsmd plugins stream connect to lsmd/init - Allow sblim domains to create /run/gather with correct labeling - Allow httpd to read ldap certs - Allow cupsd to send dbus msgs to process with different MLS level - Allow bumblebee to stream connect to apmd - Allow bumblebee to run xkbcomp - Additional allow rules to get libvirt-lxc containers working with docker - Additional allow rules to get libvirt-lxc containers working with docker - Allow docker to getattr on itself - Additional rules needed for sandbox apps - Allow mozilla_plugin to set attributes on usb device if use_spice boolean enabled - httpd should be able to send signal/signull to httpd_suexec_t - Add more fixes for neturon. Domtrans to dnsmasq, iptables. Make neutron as filenamtrans domain.- Add neutron fixes- Allow sshd to write to all process levels in order to change passwd when running at a level - Allow updpwd_t to downgrade /etc/passwd file to s0, if it is not running with this range - Allow apcuspd_t to status and start the power unit file - Allow udev to manage kdump unit file - Added new interface modutils_dontaudit_exec_insmod - Allow cobbler to search dhcp_etc_t directory - systemd_systemctl needs sys_admin capability - Allow sytemd_tmpfiles_t to delete all directories - passwd to create gnome-keyring passwd socket - Add missing zabbix_var_lib_t type - Fix filename trans for zabbixsrv in zabbix.te - Allow fprintd_t to send syslog messages - Add zabbix_var_lib_t for /var/lib/zabbixsrv, also allow zabix to connect to smtp port - Allow mozilla plugin to chat with policykit, needed for spice - Allow gssprozy to change user and gid, as well as read user keyrings - Label upgrades directory under /var/www as httpd_sys_rw_content_t, add other filetrans rules to label content correctly - Allow polipo to connect to http_cache_ports - Allow cron jobs to manage apache var lib content - Allow yppassword to manage the passwd_file_t - Allow showall_t to send itself signals - Allow cobbler to restart dhcpc, dnsmasq and bind services - Allow certmonger to manage home cert files - Add userdom filename trans for user mail domains - Allow apcuspd_t to status and start the power unit file - Allow cgroupdrulesengd to create content in cgoups directories - Allow smbd_t to signull cluster - Allow gluster daemon to create fifo files in glusterd_brick_t and sock_file in glusterd_var_lib_t - Add label for /var/spool/cron.aquota.user - Allow sandbox_x domains to use work with the mozilla plugin semaphore - Added new policy for speech-dispatcher - Added dontaudit rule for insmod_exec_t in rasdaemon policy - Updated rasdaemon policy - Allow system_mail_t to transition to postfix_postdrop_t - Clean up mirrormanager policy - Allow virt_domains to read cert files, needs backport to RHEL7 - Allow sssd to read systemd_login_var_run_t - Allow irc_t to execute shell and bin-t files: - Add new access for mythtv - Allow rsync_t to manage all non auth files - allow modemmanger to read /dev/urand - Allow sandbox apps to attempt to set and get capabilties- Add labeling for /var/lib/servicelog/servicelog.db-journal - Add support for freeipmi port - Add sysadm_u_default_contexts - Make new type to texlive files in homedir - Allow subscription-manager running as sosreport_t to manage rhsmcertd - Additional fixes for docker.te - Remove ability to do mount/sys_admin by default in virt_sandbox domains - New rules required to run docker images within libivrt - Add label for ~/.cvsignore - Change mirrormanager to be run by cron - Add mirrormanager policy - Fixed bumblebee_admin() and mip6d_admin() - Add log support for sensord - Fix typo in docker.te - Allow amanda to do backups over UDP - Allow bumblebee to read /etc/group and clean up bumblebee.te - type transitions with a filename not allowed inside conditionals - Don't allow virt-sandbox tools to use netlink out of the box, needs back port to RHEL7 - Make new type to texlive files in homedir- Allow freeipmi_ipmidetectd_t to use freeipmi port - Update freeipmi_domain_template() - Allow journalctl running as ABRT to read /run/log/journal - Allow NM to read dispatcher.d directory - Update freeipmi policy - Type transitions with a filename not allowed inside conditionals - Allow tor to bind to hplip port - Make new type to texlive files in homedir - Allow zabbix_agent to transition to dmidecode - Add rules for docker - Allow sosreport to send signull to unconfined_t - Add virt_noatsecure and virt_rlimitinh interfaces - Fix labeling in thumb.fc to add support for /usr/lib64/tumbler-1/tumblerddd support for freeipmi port - Add sysadm_u_default_contexts - Add logging_read_syslog_pid() - Fix userdom_manage_home_texlive() interface - Make new type to texlive files in homedir - Add filename transitions for /run and /lock links - Allow virtd to inherit rlimit information Resolves:#975358- Change labeling for /usr/libexec/nm-dispatcher.action to NetworkManager_exec_t Resolves:#1039879 - Add labeling for /usr/lib/systemd/system/mariadb.service - Allow hyperv_domain to read sysfs - Fix ldap_read_certs() interface to allow acess also link files - Add support for /usr/libexec/pegasus/cmpiLMI_Journald-cimprovagt - Allow tuned to run modprobe - Allow portreserve to search /var/lib/sss dir - Add SELinux support for the teamd package contains team network device control daemon. - Dontaudit access check on /proc for bumblebee - Bumblebee wants to load nvidia modules - Fix rpm_named_filetrans_log_files and wine.te - Add conman policy for rawhide - DRM master and input event devices are used by the TakeDevice API - Clean up bumblebee policy - Update pegasus_openlmi_storage_t policy - Add freeipmi_stream_connect() interface - Allow logwatch read madm.conf to support RAID setup - Add raid_read_conf_files() interface - Allow up2date running as rpm_t create up2date log file with rpm_log_t labeling - add rpm_named_filetrans_log_files() interface - Allow dkim-milter to create files/dirs in /tmp - update freeipmi policy - Add policy for freeipmi services - Added rdisc_admin and rdisc_systemctl interfaces - opensm policy clean up - openwsman policy clean up - ninfod policy clean up - Added new policy for ninfod - Added new policy for openwsman - Added rdisc_admin and rdisc_systemctl interfaces - Fix kernel_dontaudit_access_check_proc() - Add support for /dev/uhid - Allow sulogin to get the attributes of initctl and sys_admin cap - Add kernel_dontaudit_access_check_proc() - Fix dev_rw_ipmi_dev() - Fix new interface in devices.if - DRM master and input event devices are used by the TakeDevice API - add dev_rw_inherited_dri() and dev_rw_inherited_input_dev() - Added support for default conman port - Add interfaces for ipmi devices- Allow sosreport to send a signal to ABRT - Add proper aliases for pegasus_openlmi_service_exec_t and pegasus_openlmi_service_t - Label /usr/sbin/htcacheclean as httpd_exec_t Resolves:#1037529 - Added support for rdisc unit file - Add antivirus_db_t labeling for /var/lib/clamav-unofficial-sigs - Allow runuser running as logrotate connections to system DBUS - Label bcache devices as fixed_disk_device_t - Allow systemctl running in ipsec_mgmt_t to access /usr/lib/systemd/system/ipsec.service - Label /usr/lib/systemd/system/ipsec.service as ipsec_mgmt_unit_file_t- Add back setpgid/setsched for sosreport_t- Added fix for clout_init to transition to rpm_script_t (dwalsh@redhat.com)- Dontaudit openshift domains trying to use rawip_sockets, this is caused by a bad check in the kernel. - Allow git_system_t to read git_user_content if the git_system_enable_homedirs boolean is turned on - Add lsmd_plugin_t for lsm plugins - Allow dovecot-deliver to search mountpoints - Add labeling for /etc/mdadm.conf - Allow opelmi admin providers to dbus chat with init_t - Allow sblim domain to read /dev/urandom and /dev/random - Allow apmd to request the kernel load modules - Add glusterd_brick_t type - label mate-keyring-daemon with gkeyringd_exec_t - Add plymouthd_create_log() - Dontaudit leaks from openshift domains into mail domains, needs back port to RHEL6 - Allow sssd to request the kernel loads modules - Allow gpg_agent to use ssh-add - Allow gpg_agent to use ssh-add - Dontaudit access check on /root for myslqd_safe_t - Allow ctdb to getattr on al filesystems - Allow abrt to stream connect to syslog - Allow dnsmasq to list dnsmasq.d directory - Watchdog opens the raw socket - Allow watchdog to read network state info - Dontaudit access check on lvm lock dir - Allow sosreport to send signull to setroubleshootd - Add setroubleshoot_signull() interface - Fix ldap_read_certs() interface - Allow sosreport all signal perms - Allow sosreport to run systemctl - Allow sosreport to dbus chat with rpm - Add glusterd_brick_t files type - Allow zabbix_agentd to read all domain state - Clean up rtas.if - Allow smoltclient to execute ldconfig - Allow sosreport to request the kernel to load a module - Fix userdom_confined_admin_template() - Add back exec_content boolean for secadm, logadm, auditadm - Fix files_filetrans_system_db_named_files() interface - Allow sulogin to getattr on /proc/kcore - Add filename transition also for servicelog.db-journal - Add files_dontaudit_access_check_root() - Add lvm_dontaudit_access_check_lock() interface- Allow watchdog to read /etc/passwd - Allow browser plugins to connect to bumblebee - New policy for bumblebee and freqset - Add new policy for mip6d daemon - Add new policy for opensm daemon - Allow condor domains to read/write condor_master udp_socket - Allow openshift_cron_t to append to openshift log files, label /var/log/openshift - Add back file_pid_filetrans for /var/run/dlm_controld - Allow smbd_t to use inherited tmpfs content - Allow mcelog to use the /dev/cpu device - sosreport runs rpcinfo - sosreport runs subscription-manager - Allow staff_t to run frequency command - Allow systemd_tmpfiles to relabel log directories - Allow staff_t to read xserver_log file - Label hsperfdata_root as tmp_t- More sosreport fixes to make ABRT working- Fix files_dontaudit_unmount_all_mountpoints() - Add support for 2608-2609 tcp/udp ports - Should allow domains to lock the terminal device - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - We need to require passwd rootok - Fix zebra.fc - Fix dnsmasq_filetrans_named_content() interface - Allow all sandbox domains create content in svirt_home_t - Allow zebra domains also create zebra_tmp_t files in /tmp - Add support for new zebra services:isisd,babeld. Add systemd support for zebra services. - Fix labeling on neutron and remove transition to iconfig_t - abrt needs to read mcelog log file - Fix labeling on dnsmasq content - Fix labeling on /etc/dnsmasq.d - Allow glusterd to relabel own lib files - Allow sandbox domains to use pam_rootok, and dontaudit attempts to unmount file systems, this is caused by a bug in systemd - Allow ipc_lock for abrt to run journalctl- Fix config.tgz- Fix passenger_stream_connect interface - setroubleshoot_fixit wants to read network state - Allow procmail_t to connect to dovecot stream sockets - Allow cimprovagt service providers to read network states - Add labeling for /var/run/mariadb - pwauth uses lastlog() to update system's lastlog - Allow account provider to read login records - Add support for texlive2013 - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - Allow passwd_t to connect to gnome keyring to change password - Update mls config files to have cronjobs in the user domains - Remove access checks that systemd does not actually do- Add support for yubikey in homedir - Add support for upd/3052 port - Allow apcupsd to use PowerChute Network Shutdown - Allow lsmd to execute various lsmplugins - Add labeling also for /etc/watchdog\.d where are watchdog scripts located too - Update gluster_export_all_rw boolean to allow relabel all base file types - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling- Add files_relabel_base_file_types() interface - Allow netlabel-config to read passwd - update gluster_export_all_rw boolean to allow relabel all base file types caused by lsetxattr() - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling - Allow pegasus to domtrans to mount_t - Add labeling for unconfined scripts in /usr/libexec/watchdog/scripts - Add support for unconfined watchdog scripts - Allow watchdog to manage own log files- Add label only for redhat.repo instead of /etc/yum.repos.d. But probably we will need to switch for the directory. - Label /etc/yum.repos.d as system_conf_t - Use sysnet_filetrans_named_content in udev.te instead of generic transition for net_conf_t - Allow dac_override for sysadm_screen_t - Allow init_t to read ipsec_conf_t as we had it for initrc_t. Needed by ipsec unit file. - Allow netlabel-config to read meminfo - Add interface to allow docker to mounton file_t - Add new interface to exec unlabeled files - Allow lvm to use docker semaphores - Setup transitons for .xsessions-errors.old - Change labels of files in /var/lib/*/.ssh to transition properly - Allow staff_t and user_t to look at logs using journalctl - pluto wants to manage own log file - Allow pluto running as ipsec_t to create pluto.log - Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Allow dmidecode to read/write /run/lock/subsys/rhsmcertd - Allow rhsmcertd to manage redhat.repo which is now labeled as system.conf. Allow rhsmcertd to manage all log files. - Additional access for docker - Added more rules to sblim policy - Fix kdumpgui_run_bootloader boolean - Allow dspam to connect to lmtp port - Included sfcbd service into sblim policy - rhsmcertd wants to manaage /etc/pki/consumer dir - Add kdumpgui_run_bootloader boolean - Add support for /var/cache/watchdog - Remove virt_domain attribute for virt_qemu_ga_unconfined_t - Fixes for handling libvirt containes - Dontaudit attempts by mysql_safe to write content into / - Dontaudit attempts by system_mail to modify network config - Allow dspam to bind to lmtp ports - Add new policy to allow staff_t and user_t to look at logs using journalctl - Allow apache cgi scripts to list sysfs - Dontaudit attempts to write/delete user_tmp_t files - Allow all antivirus domains to manage also own log dirs - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Add missing permission checks for nscd- Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Add file transition rules for content created by f5link - Rename quantum_port information to neutron - Allow all antivirus domains to manage also own log dirs - Rename quantum_port information to neutron - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Allow sysadm_t to read login information - Allow systemd_tmpfiles to setattr on var_log_t directories - Udpdate Makefile to include systemd_contexts - Add systemd_contexts - Add fs_exec_hugetlbfs_files() interface - Add daemons_enable_cluster_mode boolean - Fix rsync_filetrans_named_content() - Add rhcs_read_cluster_pid_files() interface - Update rhcs.if with additional interfaces from RHEL6 - Fix rhcs_domain_template() to not create run dirs with cluster_var_run_t - Allow glusterd_t to mounton glusterd_tmp_t - Allow glusterd to unmout al filesystems - Allow xenstored to read virt config - Add label for swift_server.lock and make add filetrans_named_content to make sure content gets created with the correct label - Allow mozilla_plugin_t to mmap hugepages as an executable- Add back userdom_security_admin_template() interface and use it for sysadm_t if sysadm_secadm.pp- Allow sshd_t to read openshift content, needs backport to RHEL6.5 - Label /usr/lib64/sasl2/libsasldb.so.3.0.0 as textrel_shlib_t - Make sur kdump lock is created with correct label if kdumpctl is executed - gnome interface calls should always be made within an optional_block - Allow syslogd_t to connect to the syslog_tls port - Add labeling for /var/run/charon.ctl socket - Add kdump_filetrans_named_content() - Allo setpgid for fenced_t - Allow setpgid and r/w cluster tmpfs for fenced_t - gnome calls should always be within optional blocks - wicd.pid should be labeled as networkmanager_var_run_t - Allow sys_resource for lldpad- Add rtas policy- Allow mailserver_domains to manage and transition to mailman data - Dontaudit attempts by mozilla plugin to relabel content, caused by using mv and cp commands - Allow mailserver_domains to manage and transition to mailman data - Allow svirt_domains to read sysctl_net_t - Allow thumb_t to use tmpfs inherited from the user - Allow mozilla_plugin to bind to the vnc port if running with spice - Add new attribute to discover confined_admins and assign confined admin to it - Fix zabbix to handle attributes in interfaces - Fix zabbix to read system states for all zabbix domains - Fix piranha_domain_template() - Allow ctdbd to create udp_socket. Allow ndmbd to access ctdbd var files. - Allow lldpad sys_rouserce cap due to #986870 - Allow dovecot-auth to read nologin - Allow openlmi-networking to read /proc/net/dev - Allow smsd_t to execute scripts created on the fly labeled as smsd_spool_t - Add zabbix_domain attribute for zabbix domains to treat them together - Add labels for zabbix-poxy-* (#1018221) - Update openlmi-storage policy to reflect #1015067 - Back port piranha tmpfs fixes from RHEL6 - Update httpd_can_sendmail boolean to allow read/write postfix spool maildrop - Add postfix_rw_spool_maildrop_files interface - Call new userdom_admin_user_templat() also for sysadm_secadm.pp - Fix typo in userdom_admin_user_template() - Allow SELinux users to create coolkeypk11sE-Gate in /var/cache/coolkey - Add new attribute to discover confined_admins - Fix labeling for /etc/strongswan/ipsec.d - systemd_logind seems to pass fd to anyone who dbus communicates with it - Dontaudit leaked write descriptor to dmesg- Activate motion policy- Fix gnome_read_generic_data_home_files() - allow openshift_cgroup_t to read/write inherited openshift file types - Remove httpd_cobbler_content * from cobbler_admin interface - Allow svirt sandbox domains to setattr on chr_file and blk_file svirt_sandbox_file_t, so sshd will work within a container - Allow httpd_t to read also git sys content symlinks - Allow init_t to read gnome home data - Dontaudit setroubleshoot_fixit_t execmem, since it does not seem to really need it. - Allow virsh to execute systemctl - Fix for nagios_services plugins - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - Fix hypervkvp.te - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Fix logging policy - Allow syslog to bind to tls ports - Update labeling for /dev/cdc-wdm - Allow to su_domain to read init states - Allow init_t to read gnome home data - Make sure if systemd_logind creates nologin file with the correct label - Clean up ipsec.te- Add auth_exec_chkpwd interface - Fix port definition for ctdb ports - Allow systemd domains to read /dev/urand - Dontaudit attempts for mozilla_plugin to append to /dev/random - Add label for /var/run/charon.* - Add labeling for /usr/lib/systemd/system/lvm2.*dd policy for motion service - Fix for nagios_services plugins - Fix some bugs in zoneminder policy - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - glusterd binds to random unreserved ports - Additional allow rules found by testing glusterfs - apcupsd needs to send a message to all users on the system so needs to look them up - Fix the label on ~/.juniper_networks - Dontaudit attempts for mozilla_plugin to append to /dev/random - Allow polipo_daemon to connect to flash ports - Allow gssproxy_t to create replay caches - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type- init reload from systemd_localed_t - Allow domains that communicate with systemd_logind_sessions to use systemd_logind_t fd - Allow systemd_localed_t to ask systemd to reload the locale. - Add systemd_runtime_unit_file_t type for unit files that systemd creates in memory - Allow readahead to read /dev/urand - Fix lots of avcs about tuned - Any file names xenstored in /var/log should be treated as xenstored_var_log_t - Allow tuned to inderact with hugepages - Allow condor domains to list etc rw dirs- Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Add additional fixes forpegasus_openlmi_account_t - Allow mdadm to read /dev/urand - Allow pegasus_openlmi_storage_t to create mdadm.conf and write it - Add label/rules for /etc/mdadm.conf - Allow pegasus_openlmi_storage_t to transition to fsadm_t - Fixes for interface definition problems - Dontaudit dovecot-deliver to gettatr on all fs dirs - Allow domains to search data_home_t directories - Allow cobblerd to connect to mysql - Allow mdadm to r/w kdump lock files - Add support for kdump lock files - Label zarafa-search as zarafa-indexer - Openshift cgroup wants to read /etc/passwd - Add new sandbox domains for kvm - Allow mpd to interact with pulseaudio if mpd_enable_homedirs is turned on - Fix labeling for /usr/lib/systemd/system/lvm2.* - Add labeling for /usr/lib/systemd/system/lvm2.* - Fix typos to get a new build. We should not cover filename trans rules to prevent duplicate rules - Add sshd_keygen_t policy for sshd-keygen - Fix alsa_home_filetrans interface name and definition - Allow chown for ssh_keygen_t - Add fs_dontaudit_getattr_all_dirs() - Allow init_t to manage etc_aliases_t and read xserver_var_lib_t and chrony keys - Fix up patch to allow systemd to manage home content - Allow domains to send/recv unlabeled traffic if unlabelednet.pp is enabled - Allow getty to exec hostname to get info - Add systemd_home_t for ~/.local/share/systemd directory- Fix lxc labels in config.tgz- Fix labeling for /usr/libexec/kde4/kcmdatetimehelper - Allow tuned to search all file system directories - Allow alsa_t to sys_nice, to get top performance for sound management - Add support for MySQL/PostgreSQL for amavis - Allow openvpn_t to manage openvpn_var_log_t files. - Allow dirsrv_t to create tmpfs_t directories - Allow dirsrv to create dirs in /dev/shm with dirsrv_tmpfs label - Dontaudit leaked unix_stream_sockets into gnome keyring - Allow telepathy domains to inhibit pipes on telepathy domains - Allow cloud-init to domtrans to rpm - Allow abrt daemon to manage abrt-watch tmp files - Allow abrt-upload-watcher to search /var/spool directory - Allow nsswitch domains to manage own process key - Fix labeling for mgetty.* logs - Allow systemd to dbus chat with upower - Allow ipsec to send signull to itself - Allow setgid cap for ipsec_t - Match upstream labeling- Do not build sanbox pkg on MLS- wine_tmp is no longer needed - Allow setroubleshoot to look at /proc - Allow telepathy domains to dbus with systemd logind - Fix handling of fifo files of rpm - Allow mozilla_plugin to transition to itself - Allow certwatch to write to cert_t directories - New abrt application - Allow NetworkManager to set the kernel scheduler - Make wine_domain shared by all wine domains - Allow mdadm_t to read images labeled svirt_image_t - Allow amanda to read /dev/urand - ALlow my_print_default to read /dev/urand - Allow mdadm to write to kdumpctl fifo files - Allow nslcd to send signull to itself - Allow yppasswd to read /dev/urandom - Fix zarafa_setrlimit - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add additional alias for user_tmp_t because wine_tmp_t is no longer used - More handling of ther kernel keyring required by kerberos - New privs needed for init_t when running without transition to initrc_t over bin_t, and without unconfined domain installed- Dontaudit attempts by sosreport to read shadow_t - Allow browser sandbox plugins to connect to cups to print - Add new label mpd_home_t - Label /srv/www/logs as httpd_log_t - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add labels for apache logs under miq package - Allow irc_t to use tcp sockets - fix labels in puppet.if - Allow tcsd to read utmp file - Allow openshift_cron_t to run ssh-keygen in ssh_keygen_t to access host keys - Define svirt_socket_t as a domain_type - Take away transition from init_t to initrc_t when executing bin_t, allow init_t to run chk_passwd_t - Fix label on pam_krb5 helper apps- Allow ldconfig to write to kdumpctl fifo files - allow neutron to connect to amqp ports - Allow kdump_manage_crash to list the kdump_crash_t directory - Allow glance-api to connect to amqp port - Allow virt_qemu_ga_t to read meminfo - Add antivirus_home_t type for antivirus date in HOMEDIRS - Allow mpd setcap which is needed by pulseaudio - Allow smbcontrol to create content in /var/lib/samba - Allow mozilla_exec_t to be used as a entrypoint to mozilla_domtrans_spec - Add additional labeling for qemu-ga/fsfreeze-hook.d scripts - amanda_exec_t needs to be executable file - Allow block_suspend cap for samba-net - Allow apps that read ipsec_mgmt_var_run_t to search ipsec_var_run_t - Allow init_t to run crash utility - Treat usr_t just like bin_t for transitions and executions - Add port definition of pka_ca to port 829 for openshift - Allow selinux_store to use symlinks- Allow block_suspend cap for samba-net - Allow t-mission-control to manage gabble cache files - Allow nslcd to read /sys/devices/system/cpu - Allow selinux_store to use symlinks- Allow xdm_t to transition to itself - Call neutron interfaces instead of quantum - Allow init to change targed role to make uncofined services (xrdp which now has own systemd unit file) working. We want them to have in unconfined_t - Make sure directories in /run get created with the correct label - Make sure /root/.pki gets created with the right label - try to remove labeling for motion from zoneminder_exec_t to bin_t - Allow inetd_t to execute shell scripts - Allow cloud-init to read all domainstate - Fix to use quantum port - Add interface netowrkmanager_initrc_domtrans - Fix boinc_execmem - Allow t-mission-control to read gabble cache home - Add labeling for ~/.cache/telepathy/avatars/gabble - Allow memcache to read sysfs data - Cleanup antivirus policy and add additional fixes - Add boolean boinc_enable_execstack - Add support for couchdb in rabbitmq policy - Add interface couchdb_search_pid_dirs - Allow firewalld to read NM state - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files()- Split out rlogin ports from inetd - Treat files labeld as usr_t like bin_t when it comes to transitions - Allow staff_t to read login config - Allow ipsec_t to read .google authenticator data - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files() - Call the correct interface - corenet_udp_bind_ktalkd_port() - Allow all domains that can read gnome_config to read kde config - Allow sandbox domain to read/write mozilla_plugin_tmpfs_t so pulseaudio will work - Allow mdadm to getattr any file system - Allow a confined domain to executes mozilla_exec_t via dbus - Allow cupsd_lpd_t to bind to the printer port - Dontaudit attempts to bind to ports < 1024 when nis is turned on - Allow apache domain to connect to gssproxy socket - Allow rlogind to bind to the rlogin_port - Allow telnetd to bind to the telnetd_port - Allow ktalkd to bind to the ktalkd_port - Allow cvs to bind to the cvs_port- Cleanup related to init_domain()+inetd_domain fixes - Use just init_domain instead of init_daemon_domain in inetd_core_service_domain - svirt domains neeed to create kobject_uevint_sockets - Lots of new access required for sosreport - Allow tgtd_t to connect to isns ports - Allow init_t to transition to all inetd domains: - openct needs to be able to create netlink_object_uevent_sockets - Dontaudit leaks into ldconfig_t - Dontaudit su domains getattr on /dev devices, move su domains to attribute based calls - Move kernel_stream_connect into all Xwindow using users - Dontaudit inherited lock files in ifconfig o dhcpc_t- Also sock_file trans rule is needed in lsm - Fix labeling for fetchmail pid files/dirs - Add additional fixes for abrt-upload-watch - Fix polipo.te - Fix transition rules in asterisk policy - Add fowner capability to networkmanager policy - Allow polipo to connect to tor ports - Cleanup lsmd.if - Cleanup openhpid policy - Fix kdump_read_crash() interface - Make more domains as init domain - Fix cupsd.te - Fix requires in rpm_rw_script_inherited_pipes - Fix interfaces in lsm.if - Allow munin service plugins to manage own tmpfs files/dirs - Allow virtd_t also relabel unix stream sockets for virt_image_type - Make ktalk as init domain - Fix to define ktalkd_unit_file_t correctly - Fix ktalk.fc - Add systemd support for talk-server - Allow glusterd to create sock_file in /run - Allow xdm_t to delete gkeyringd_tmp_t files on logout - Add fixes for hypervkvp policy - Add logwatch_can_sendmail boolean - Allow mysqld_safe_t to handle also symlinks in /var/log/mariadb - Allow xdm_t to delete gkeyringd_tmp_t files on logout- Add selinux-policy-sandbox pkg0 - Allow rhsmcertd to read init state - Allow fsetid for pkcsslotd - Fix labeling for /usr/lib/systemd/system/pkcsslotd.service - Allow fetchmail to create own pid with correct labeling - Fix rhcs_domain_template() - Allow roles which can run mock to read mock lib files to view results - Allow rpcbind to use nsswitch - Fix lsm.if summary - Fix collectd_t can read /etc/passwd file - Label systemd unit files under dracut correctly - Add support for pam_mount to mount user's encrypted home When a user logs in and logs out using ssh - Add support for .Xauthority-n - Label umount.crypt as lvm_exec_t - Allow syslogd to search psad lib files - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files- Add policy for lsmd - Add support for /var/log/mariadb dir and allow mysqld_safe to list this directory - Update condor_master rules to allow read system state info and allow logging - Add labeling for /etc/condor and allow condor domain to write it (bug) - Allow condor domains to manage own logs - Allow glusterd to read domains state - Fix initial hypervkvp policy - Add policy for hypervkvpd - Fix redis.if summary- Allow boinc to connect to @/tmp/.X11-unix/X0 - Allow beam.smp to connect to tcp/5984 - Allow named to manage own log files - Add label for /usr/libexec/dcc/start-dccifd and domtrans to dccifd_t - Add virt_transition_userdomain boolean decl - Allow httpd_t to sendto unix_dgram sockets on its children - Allow nova domains to execute ifconfig - bluetooth wants to create fifo_files in /tmp - exim needs to be able to manage mailman data - Allow sysstat to getattr on all file systems - Looks like bluetoothd has moved - Allow collectd to send ping packets - Allow svirt_lxc domains to getpgid - Remove virt-sandbox-service labeling as virsh_exec_t, since it no longer does virsh_t stuff - Allow frpintd_t to read /dev/urandom - Allow asterisk_t to create sock_file in /var/run - Allow usbmuxd to use netlink_kobject - sosreport needs to getattr on lots of devices, and needs access to netlink_kobject_uevent_socket - More cleanup of svirt_lxc policy - virtd_lxc_t now talks to dbus - Dontaudit leaked ptmx_t - Allow processes to use inherited fifo files - Allow openvpn_t to connect to squid ports - Allow prelink_cron_system_t to ask systemd to reloaddd miscfiles_dontaudit_access_check_cert() - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files - Allow user roles to connect to the journal socket- selinux_set_enforce_mode needs to be used with type - Add append to the dontaudit for unix_stream_socket of xdm_t leak - Allow xdm_t to create symlinks in log direcotries - Allow login programs to read afs config - Label 10933 as a pop port, for dovecot - New policy to allow selinux_server.py to run as semanage_t as a dbus service - Add fixes to make netlabelctl working on MLS - AVCs required for running sepolicy gui as staff_t - Dontaudit attempts to read symlinks, sepolicy gui is likely to cause this type of AVC - New dbus server to be used with new gui - After modifying some files in /etc/mail, I saw this needed on the next boot - Loading a vm from /usr/tmp with virt-manager - Clean up oracleasm policy for Fedora - Add oracleasm policy written by rlopez@redhat.com - Make postfix_postdrop_t as mta_agent to allow domtrans to system mail if it is executed by apache - Add label for /var/crash - Allow fenced to domtrans to sanclok_t - Allow nagios to manage nagios spool files - Make tfptd as home_manager - Allow kdump to read kcore on MLS system - Allow mysqld-safe sys_nice/sys_resource caps - Allow apache to search automount tmp dirs if http_use_nfs is enabled - Allow crond to transition to named_t, for use with unbound - Allow crond to look at named_conf_t, for unbound - Allow mozilla_plugin_t to transition its home content - Allow dovecot_domain to read all system and network state - Allow httpd_user_script_t to call getpw - Allow semanage to read pid files - Dontaudit leaked file descriptors from user domain into thumb - Make PAM authentication working if it is enabled in ejabberd - Add fixes for rabbit to fix ##992920,#992931 - Allow glusterd to mount filesystems - Loading a vm from /usr/tmp with virt-manager - Trying to load a VM I got an AVC from devicekit_disk for loopcontrol device - Add fix for pand service - shorewall touches own log - Allow nrpe to list /var - Mozilla_plugin_roles can not be passed into lpd_run_lpr - Allow afs domains to read afs_config files - Allow login programs to read afs config - Allow virt_domain to read virt_var_run_t symlinks - Allow smokeping to send its process signals - Allow fetchmail to setuid - Add kdump_manage_crash() interface - Allow abrt domain to write abrt.socket- Add more aliases in pegasus.te - Add more fixes for *_admin interfaces - Add interface fixes - Allow nscd to stream connect to nmbd - Allow gnupg apps to write to pcscd socket - Add more fixes for openlmi provides. Fix naming and support for additionals - Allow fetchmail to resolve host names - Allow firewalld to interact also with lnk files labeled as firewalld_etc_rw_t - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te - Fix corecmd_exec_chroot() - Fix logging_relabel_syslog_pid_socket interface - Fix typo in unconfineduser.te - Allow system_r to access unconfined_dbusd_t to run hp_chec- Allow xdm_t to act as a dbus client to itsel - Allow fetchmail to resolve host names - Allow gnupg apps to write to pcscd socket - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te -httpd_t does access_check on certs- Add support for cmpiLMI_Service-cimprovagt - Allow pegasus domtrans to rpm_t to make pycmpiLMI_Software-cimprovagt running as rpm_t - Label pycmpiLMI_Software-cimprovagt as rpm_exec_t - Add support for pycmpiLMI_Storage-cimprovagt - Add support for cmpiLMI_Networking-cimprovagt - Allow system_cronjob_t to create user_tmpfs_t to make pulseaudio working - Allow virtual machines and containers to run as user doains, needed for virt-sandbox - Allow buglist.cgi to read cpu info- Allow systemd-tmpfile to handle tmp content in print spool dir - Allow systemd-sysctl to send system log messages - Add support for RTP media ports and fmpro-internal - Make auditd working if audit is configured to perform SINGLE action on disk error - Add interfaces to handle systemd units - Make systemd-notify working if pcsd is used - Add support for netlabel and label /usr/sbin/netlabelctl as iptables_exec_t - Instead of having all unconfined domains get all of the named transition rules, - Only allow unconfined_t, init_t, initrc_t and rpm_script_t by default. - Add definition for the salt ports - Allow xdm_t to create link files in xdm_var_run_t - Dontaudit reads of blk files or chr files leaked into ldconfig_t - Allow sys_chroot for useradd_t - Allow net_raw cap for ipsec_t - Allow sysadm_t to reload services - Add additional fixes to make strongswan working with a simple conf - Allow sysadm_t to enable/disable init_t services - Add additional glusterd perms - Allow apache to read lnk files in the /mnt directory - Allow glusterd to ask the kernel to load a module - Fix description of ftpd_use_fusefs boolean - Allow svirt_lxc_net_t to sys_chroot, modify policy to tighten up svirt_lxc_domain capabilties and process controls, but add them to svirt_lxc_net_t - Allow glusterds to request load a kernel module - Allow boinc to stream connect to xserver_t - Allow sblim domains to read /etc/passwd - Allow mdadm to read usb devices - Allow collectd to use ping plugin - Make foghorn working with SNMP - Allow sssd to read ldap certs - Allow haproxy to connect to RTP media ports - Add additional trans rules for aide_db - Add labeling for /usr/lib/pcsd/pcsd - Add labeling for /var/log/pcsd - Add support for pcs which is a corosync and pacemaker configuration tool- Label /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t - Add labeling for /usr/libexec/kde4/polkit-kde-authentication-agent-1 - Allow all domains that can domtrans to shutdown, to start the power services script to shutdown - consolekit needs to be able to shut down system - Move around interfaces - Remove nfsd_rw_t and nfsd_ro_t, they don't do anything - Add additional fixes for rabbitmq_beam to allow getattr on mountpoints - Allow gconf-defaults-m to read /etc/passwd - Fix pki_rw_tomcat_cert() interface to support lnk_files- Add support for gluster ports - Make sure that all keys located in /etc/ssh/ are labeled correctly - Make sure apcuspd lock files get created with the correct label - Use getcap in gluster.te - Fix gluster policy - add additional fixes to allow beam.smp to interact with couchdb files - Additional fix for #974149 - Allow gluster to user gluster ports - Allow glusterd to transition to rpcd_t and add additional fixes for #980683 - Allow tgtd working when accessing to the passthrough device - Fix labeling for mdadm unit files- Add mdadm fixes- Fix definition of sandbox.disabled to sandbox.pp.disabled- Allow mdamd to execute systemctl - Allow mdadm to read /dev/kvm - Allow ipsec_mgmt_t to read l2tpd pid content- Allow nsd_t to read /dev/urand - Allow mdadm_t to read framebuffer - Allow rabbitmq_beam_t to read process info on rabbitmq_epmd_t - Allow mozilla_plugin_config_t to create tmp files - Cleanup openvswitch policy - Allow mozilla plugin to getattr on all executables - Allow l2tpd_t to create fifo_files in /var/run - Allow samba to touch/manage fifo_files or sock_files in a samba_share_t directory - Allow mdadm to connecto its own unix_stream_socket - FIXME: nagios changed locations to /log/nagios which is wrong. But we need to have this workaround for now. - Allow apache to access smokeping pid files - Allow rabbitmq_beam_t to getattr on all filesystems - Add systemd support for iodined - Allow nup_upsdrvctl_t to execute its entrypoint - Allow fail2ban_client to write to fail2ban_var_run_t, Also allow it to use nsswitch - add labeling for ~/.cache/libvirt-sandbox - Add interface to allow domains transitioned to by confined users to send sigchld to screen program - Allow sysadm_t to check the system status of files labeled etc_t, /etc/fstab - Allow systemd_localed to start /usr/lib/systemd/system/systemd-vconsole-setup.service - Allow an domain that has an entrypoint from a type to be allowed to execute the entrypoint without a transition, I can see no case where this is a bad thing, and elminiates a whole class of AVCs. - Allow staff to getsched all domains, required to run htop - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Add prosody policy written by Michael Scherer - Allow nagios plugins to read /sys info - ntpd needs to manage own log files - Add support for HOME_DIR/.IBMERS - Allow iptables commands to read firewalld config - Allow consolekit_t to read utmp - Fix filename transitions on .razor directory - Add additional fixes to make DSPAM with LDA working - Allow snort to read /etc/passwd - Allow fail2ban to communicate with firewalld over dbus - Dontaudit openshift_cgreoup_file_t read/write leaked dev - Allow nfsd to use mountd port - Call th proper interface - Allow openvswitch to read sys and execute plymouth - Allow tmpwatch to read /var/spool/cups/tmp - Add support for /usr/libexec/telepathy-rakia - Add systemd support for zoneminder - Allow mysql to create files/directories under /var/log/mysql - Allow zoneminder apache scripts to rw zoneminder tmpfs - Allow httpd to manage zoneminder lib files - Add zoneminder_run_sudo boolean to allow to start zoneminder - Allow zoneminder to send mails - gssproxy_t sock_file can be under /var/lib - Allow web domains to connect to whois port. - Allow sandbox_web_type to connect to the same ports as mozilla_plugin_t. - We really need to add an interface to corenet to define what a web_client_domain is and - then define chrome_sandbox_t, mozilla_plugin_t and sandbox_web_type to that domain. - Add labeling for cmpiLMI_LogicalFile-cimprovagt - Also make pegasus_openlmi_logicalfile_t as unconfined to have unconfined_domain attribute for filename trans rules - Update policy rules for pegasus_openlmi_logicalfile_t - Add initial types for logicalfile/unconfined OpenLMI providers - mailmanctl needs to read own log - Allow logwatch manage own lock files - Allow nrpe to read meminfo - Allow httpd to read certs located in pki-ca - Add pki_read_tomcat_cert() interface - Add support for nagios openshift plugins - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Shrink the size of policy by moving to attributes, also add dridomain so that mozilla_plugin can follow selinuxuse_dri boolean. - Allow bootloader to manage generic log files - Allow ftp to bind to port 989 - Fix label of new gear directory - Add support for new directory /var/lib/openshift/gears/ - Add openshift_manage_lib_dirs() - allow virtd domains to manage setrans_var_run_t - Allow useradd to manage all openshift content - Add support so that mozilla_plugin_t can use dri devices - Allow chronyd to change the scheduler - Allow apmd to shut downthe system - Devicekit_disk_t needs to manage /etc/fstab- Make DSPAM to act as a LDA working - Allow ntop to create netlink socket - Allow policykit to send a signal to policykit-auth - Allow stapserver to dbus chat with avahi/systemd-logind - Fix labeling on haproxy unit file - Clean up haproxy policy - A new policy for haproxy and placed it to rhcs.te - Add support for ldirectord and treat it with cluster_t - Make sure anaconda log dir is created with var_log_t- Allow lvm_t to create default targets for filesystem handling - Fix labeling for razor-lightdm binaries - Allow insmod_t to read any file labeled var_lib_t - Add policy for pesign - Activate policy for cmpiLMI_Account-cimprovagt - Allow isnsd syscall=listen - /usr/libexec/pegasus/cimprovagt needs setsched caused by sched_setscheduler - Allow ctdbd to use udp/4379 - gatherd wants sys_nice and setsched - Add support for texlive2012 - Allow NM to read file_t (usb stick with no labels used to transfer keys for example) - Allow cobbler to execute apache with domain transition- condor_collector uses tcp/9000 - Label /usr/sbin/virtlockd as virtd_exec_t for now - Allow cobbler to execute ldconfig - Allow NM to execute ssh - Allow mdadm to read /dev/crash - Allow antivirus domains to connect to snmp port - Make amavisd-snmp working correctly - Allow nfsd_t to mounton nfsd_fs_t - Add initial snapper policy - We still need to have consolekit policy - Dontaudit firefox attempting to connect to the xserver_port_t if run within sandbox_web_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow dirsrv to read network state - Fix pki_read_tomcat_lib_files - Add labeling for /usr/libexec/nm-ssh-service - Add label cert_t for /var/lib/ipa/pki-ca/publish - Lets label /sys/fs/cgroup as cgroup_t for now, to keep labels consistant - Allow nfsd_t to mounton nfsd_fs_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow passwd_t to change role to system_r from unconfined_r- Don't audit access checks by sandbox xserver on xdb var_lib - Allow ntop to read usbmon devices - Add labeling for new polcykit authorizor - Dontaudit access checks from fail2ban_client - Don't audit access checks by sandbox xserver on xdb var_lib - Allow apps that connect to xdm stream to conenct to xdm_dbusd_t stream - Fix labeling for all /usr/bim/razor-lightdm-* binaries - Add filename trans for /dev/md126p1- Make vdagent able to request loading kernel module - Add support for cloud-init make it as unconfined domain - Allow snmpd to run smartctl in fsadm_t domain - remove duplicate openshift_search_lib() interface - Allow mysqld to search openshift lib files - Allow openshift cgroup to interact with passedin file descriptors - Allow colord to list directories inthe users homedir - aide executes prelink to check files - Make sure cupsd_t creates content in /etc/cups with the correct label - Lest dontaudit apache read all domains, so passenger will not cause this avc - Allow gssd to connect to gssproxy - systemd-tmpfiles needs to be able to raise the level to fix labeling on /run/setrans in MLS - Allow systemd-tmpfiles to relabel also lock files - Allow useradd to add homdir in /var/lib/openshift - Allow setfiles and semanage to write output to /run/files- Add labeling for /dev/tgt - Dontaudit leak fd from firewalld for modprobe - Allow runuser running as rpm_script_t to create netlink_audit socket - Allow mdadm to read BIOS non-volatile RAM- accountservice watches when accounts come and go in wtmp - /usr/java/jre1.7.0_21/bin/java needs to create netlink socket - Add httpd_use_sasl boolean - Allow net_admin for tuned_t - iscsid needs sys_module to auto-load kernel modules - Allow blueman to read bluetooth conf - Add nova_manage_lib_files() interface - Fix mplayer_filetrans_home_content() - Add mplayer_filetrans_home_content() - mozilla_plugin_config_roles need to be able to access mozilla_plugin_config_t - Revert "Allow thumb_t to append inherited xdm stream socket" - Add iscsi_filetrans_named_content() interface - Allow to create .mplayer with the correct labeling for unconfined - Allow iscsiadmin to create lock file with the correct labeling- Allow wine to manage wine home content - Make amanda working with socket actiovation - Add labeling for /usr/sbin/iscsiadm - Add support for /var/run/gssproxy.sock - dnsmasq_t needs to read sysctl_net_t- Fix courier_domain_template() interface - Allow blueman to write ip_forward - Allow mongodb to connect to mongodb port - Allow mongodb to connect to mongodb port - Allow java to bind jobss_debug port - Fixes for *_admin interfaces - Allow iscsid auto-load kernel modules needed for proper iSCSI functionality - Need to assign attribute for courier_domain to all courier_domains - Fail2ban reads /etc/passwd - postfix_virtual will create new files in postfix_spool_t - abrt triggers sys_ptrace by running pidof - Label ~/abc as mozilla_home_t, since java apps as plugin want to create it - Add passenger fixes needed by foreman - Remove dup interfaces - Add additional interfaces for quantum - Add new interfaces for dnsmasq - Allow passenger to read localization and send signull to itself - Allow dnsmasq to stream connect to quantum - Add quantum_stream_connect() - Make sure that mcollective starts the service with the correct labeling - Add labels for ~/.manpath - Dontaudit attempts by svirt_t to getpw* calls - sandbox domains are trying to look at parent process data - Allow courior auth to create its pid file in /var/spool/courier subdir - Add fixes for beam to have it working with couchdb - Add labeling for /run/nm-xl2tpd.con - Allow apache to stream connect to thin - Add systemd support for amand - Make public types usable for fs mount points - Call correct mandb interface in domain.te - Allow iptables to r/w quantum inherited pipes and send sigchld - Allow ifconfig domtrans to iptables and execute ldconfig - Add labels for ~/.manpath - Allow systemd to read iscsi lib files - seunshare is trying to look at parent process data- Fix openshift_search_lib - Add support for abrt-uefioops-oops - Allow colord to getattr any file system - Allow chrome processes to look at each other - Allow sys_ptrace for abrt_t - Add new policy for gssproxy - Dontaudit leaked file descriptor writes from firewalld - openshift_net_type is interface not template - Dontaudit pppd to search gnome config - Update openshift_search_lib() interface - Add fs_list_pstorefs() - Fix label on libbcm_host.so since it is built incorrectly on raspberry pi, needs back port to F18 - Better labels for raspberry pi devices - Allow init to create devpts_t directory - Temporarily label rasbery pi devices as memory_device_t, needs back port to f18 - Allow sysadm_t to build kernels - Make sure mount creates /var/run/blkid with the correct label, needs back port to F18 - Allow userdomains to stream connect to gssproxy - Dontaudit leaked file descriptor writes from firewalld - Allow xserver to read /dev/urandom - Add additional fixes for ipsec-mgmt - Make SSHing into an Openshift Enterprise Node working- Add transition rules to unconfined domains and to sysadm_t to create /etc/adjtime - with the proper label. - Update files_filetrans_named_content() interface to get right labeling for pam.d conf files - Allow systemd-timedated to create adjtime - Add clock_create_adjtime() - Additional fix ifconfing for #966106 - Allow kernel_t to create boot.log with correct labeling - Remove unconfined_mplayer for which we don't have rules - Rename interfaces - Add userdom_manage_user_home_files/dirs interfaces - Fix files_dontaudit_read_all_non_security_files - Fix ipsec_manage_key_file() - Fix ipsec_filetrans_key_file() - Label /usr/bin/razor-lightdm-greeter as xdm_exec_t instead of spamc_exec_t - Fix labeling for ipse.secrets - Add interfaces for ipsec and labeling for ipsec.info and ipsec_setup.pid - Add files_dontaudit_read_all_non_security_files() interface - /var/log/syslog-ng should be labeled var_log_t - Make ifconfig_var_run_t a mountpoint - Add transition from ifconfig to dnsmasq - Allow ifconfig to execute bin_t/shell_exec_t - We want to have hwdb.bin labeled as etc_t - update logging_filetrans_named_content() interface - Allow systemd_timedate_t to manage /etc/adjtime - Allow NM to send signals to l2tpd - Update antivirus_can_scan_system boolean - Allow devicekit_disk_t to sys_config_tty - Run abrt-harvest programs as abrt_t, and allow abrt_t to list all filesystem directories - Make printing from vmware working - Allow php-cgi from php54 collection to access /var/lib/net-snmp/mib_indexes - Add virt_qemu_ga_data_t for qemu-ga - Make chrome and mozilla able to connect to same ports, add jboss_management_port_t to both - Fix typo in virt.te - Add virt_qemu_ga_unconfined_t for hook scripts - Make sure NetworkManager files get created with the correct label - Add mozilla_plugin_use_gps boolean - Fix cyrus to have support for net-snmp - Additional fixes for dnsmasq and quantum for #966106 - Add plymouthd_create_log() - remove httpd_use_oddjob for which we don't have rules - Add missing rules for httpd_can_network_connect_cobbler - Add missing cluster_use_execmem boolean - Call userdom_manage_all_user_home_type_files/dirs - Additional fix for ftp_home_dir - Fix ftp_home_dir boolean - Allow squit to recv/send client squid packet - Fix nut.te to have nut_domain attribute - Add support for ejabberd; TODO: revisit jabberd and rabbit policy - Fix amanda policy - Add more fixes for domains which use libusb - Make domains which use libusb working correctly - Allow l2tpd to create ipsec key files with correct labeling and manage them - Fix cobbler_manage_lib_files/cobbler_read_lib_files to cover also lnk files - Allow rabbitmq-beam to bind generic node - Allow l2tpd to read ipse-mgmt pid files - more fixes for l2tpd, NM and pppd from #967072- Dontaudit to getattr on dirs for dovecot-deliver - Allow raiudusd server connect to postgresql socket - Add kerberos support for radiusd - Allow saslauthd to connect to ldap port - Allow postfix to manage postfix_private_t files - Add chronyd support for #965457 - Fix labeling for HOME_DIR/\.icedtea - CHange squid and snmpd to be allowed also write own logs - Fix labeling for /usr/libexec/qemu-ga - Allow virtd_t to use virt_lock_t - Allow also sealert to read the policy from the kernel - qemu-ga needs to execute scripts in /usr/libexec/qemu-ga and to use /tmp content - Dontaudit listing of users homedir by sendmail Seems like a leak - Allow passenger to transition to puppet master - Allow apache to connect to mythtv - Add definition for mythtv ports- Add additional fixes for #948073 bug - Allow sge_execd_t to also connect to sge ports - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow sge_execd to bind sge ports. Allow kill capability and reads cgroup files - Remove pulseaudio filetrans pulseaudio_manage_home_dirs which is a part of pulseaudio_manage_home_files - Add networkmanager_stream_connect() - Make gnome-abrt wokring with staff_t - Fix openshift_manage_lib_files() interface - mdadm runs ps command which seems to getattr on random log files - Allow mozilla_plugin_t to create pulseaudit_home_t directories - Allow qemu-ga to shutdown virtual hosts - Add labelling for cupsd-browsed - Add web browser plugins to connect to aol ports - Allow nm-dhcp-helper to stream connect to NM - Add port definition for sge ports- Make sure users and unconfined domains create .hushlogin with the correct label - Allow pegaus to chat with realmd over DBus - Allow cobblerd to read network state - Allow boicn-client to stat on /dev/input/mice - Allow certwatch to read net_config_t when it executes apache - Allow readahead to create /run/systemd and then create its own directory with the correct label- Transition directories and files when in a user_tmp_t directory - Change certwatch to domtrans to apache instead of just execute - Allow virsh_t to read xen lib files - update policy rules for pegasus_openlmi_account_t - Add support for svnserve_tmp_t - Activate account openlmi policy - pegasus_openlmi_domain_template needs also require pegasus_t - One more fix for policykit.te - Call fs_list_cgroups_dirs() in policykit.te - Allow nagios service plugin to read mysql config files - Add labeling for /var/svn - Fix chrome.te - Fix pegasus_openlmi_domain_template() interfaces - Fix dev_rw_vfio_dev definiton, allow virtd_t to read tmpfs_t symlinks - Fix location of google-chrome data - Add support for chome_sandbox to store content in the homedir - Allow policykit to watch for changes in cgroups file system - Add boolean to allow mozilla_plugin_t to use spice - Allow collectd to bind to udp port - Allow collected_t to read all of /proc - Should use netlink socket_perms - Should use netlink socket_perms - Allow glance domains to connect to apache ports - Allow apcupsd_t to manage its log files - Allow chrome objects to rw_inherited unix_stream_socket from callers - Allow staff_t to execute virtd_exec_t for running vms - nfsd_t needs to bind mountd port to make nfs-mountd.service working - Allow unbound net_admin capability because of setsockopt syscall - Fix fs_list_cgroup_dirs() - Label /usr/lib/nagios/plugins/utils.pm as bin_t - Remove uplicate definition of fs_read_cgroup_files() - Remove duplicate definition of fs_read_cgroup_files() - Add files_mountpoint_filetrans interface to be used by quotadb_t and snapperd - Additional interfaces needed to list and read cgroups config - Add port definition for collectd port - Add labels for /dev/ptp* - Allow staff_t to execute virtd_exec_t for running vms- Allow samba-net to also read realmd tmp files - Allow NUT to use serial ports - realmd can be started by systemctl now- Remove userdom_home_manager for xdm_t and move all rules to xserver.te directly - Add new xdm_write_home boolean to allow xdm_t to create files in HOME dirs with xdm_home_t - Allow postfix-showq to read/write unix.showq in /var/spool/postfix/pid - Allow virsh to read xen lock file - Allow qemu-ga to create files in /run with proper labeling - Allow glusterd to connect to own socket in /tmp - Allow glance-api to connect to http port to make glance image-create working - Allow keystonte_t to execute rpm- Fix realmd cache interfaces- Allow tcpd to execute leafnode - Allow samba-net to read realmd cache files - Dontaudit sys_tty_config for alsactl - Fix allow rules for postfix_var_run - Allow cobblerd to read /etc/passwd - Allow pegasus to read exports - Allow systemd-timedate to read xdm state - Allow mout to stream connect to rpcbind - Add labeling just for /usr/share/pki/ca-trust-source instead of /usr/share/pki- Allow thumbnails to share memory with apps which run thumbnails - Allow postfix-postqueue block_suspend - Add lib interfaces for smsd - Add support for nginx - Allow s2s running as jabberd_t to connect to jabber_interserver_port_t - Allow pki apache domain to create own tmp files and execute httpd_suexec - Allow procmail to manger user tmp files/dirs/lnk_files - Add virt_stream_connect_svirt() interface - Allow dovecot-auth to execute bin_t - Allow iscsid to request that kernel load a kernel module - Add labeling support for /var/lib/mod_security - Allow iw running as tuned_t to create netlink socket - Dontaudit sys_tty_config for thumb_t - Add labeling for nm-l2tp-service - Allow httpd running as certwatch_t to open tcp socket - Allow useradd to manager smsd lib files - Allow useradd_t to add homedirs in /var/lib - Fix typo in userdomain.te - Cleanup userdom_read_home_certs - Implement userdom_home_reader_certs_type to allow read certs also on encrypt /home with ecryptfs_t - Allow staff to stream connect to svirt_t to make gnome-boxes working- Allow lvm to create its own unit files - Label /var/lib/sepolgen as selinux_config_t - Add filetrans rules for tw devices - Add transition from cupsd_config_t to cupsd_t- Add filetrans rules for tw devices - Cleanup bad transition lines- Fix lockdev_manage_files() - Allow setroubleshootd to read var_lib_t to make email_alert working - Add lockdev_manage_files() - Call proper interface in virt.te - Allow gkeyring_domain to create /var/run/UID/config/dbus file - system dbus seems to be blocking suspend - Dontaudit attemps to sys_ptrace, which I believe gpsd does not need - When you enter a container from root, you generate avcs with a leaked file descriptor - Allow mpd getattr on file system directories - Make sure realmd creates content with the correct label - Allow systemd-tty-ask to write kmsg - Allow mgetty to use lockdev library for device locking - Fix selinuxuser_user_share_music boolean name to selinuxuser_share_music - When you enter a container from root, you generate avcs with a leaked file descriptor - Make sure init.fc files are labeled correctly at creation - File name trans vconsole.conf - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow certmonger to dbus communicate with realmd - Make realmd working- Fix mozilla specification of homedir content - Allow certmonger to read network state - Allow tmpwatch to read tmp in /var/spool/{cups,lpd} - Label all nagios plugin as unconfined by default - Add httpd_serve_cobbler_files() - Allow mdadm to read /dev/sr0 and create tmp files - Allow certwatch to send mails - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow realmd to run ipa, really needs to be an unconfined_domain - Allow sandbox domains to use inherted terminals - Allow pscd to use devices labeled svirt_image_t in order to use cat cards. - Add label for new alsa pid - Alsa now uses a pid file and needs to setsched - Fix oracleasmfs_t definition - Add support for sshd_unit_file_t - Add oracleasmfs_t - Allow unlabeled_t files to be stored on unlabeled_t filesystems- Fix description of deny_ptrace boolean - Remove allow for execmod lib_t for now - Allow quantum to connect to keystone port - Allow nova-console to talk with mysql over unix stream socket - Allow dirsrv to stream connect to uuidd - thumb_t needs to be able to create ~/.cache if it does not exist - virtd needs to be able to sys_ptrace when starting and stoping containers- Allow alsa_t signal_perms, we probaly should search for any app that can execute something without transition and give it signal_perms... - Add dontaudit for mozilla_plugin_t looking at the xdm_t sockets - Fix deny_ptrace boolean, certain ptrace leaked into the system - Allow winbind to manage kerberos_rcache_host - Allow spamd to create spamd_var_lib_t directories - Remove transition to mozilla_tmp_t by mozilla_t, to allow it to manage the users tmp dirs - Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Call snmp_manage_var_lib_files(fogorn_t) instead of snmp_manage_var_dirs - Fix vmware_role() interface - Fix cobbler_manage_lib_files() interface - Allow nagios check disk plugins to execute bin_t - Allow quantum to transition to openvswitch_t - Allow postdrop to stream connect to postfix-master - Allow quantum to stream connect to openvswitch - Add xserver_dontaudit_xdm_rw_stream_sockets() interface - Allow daemon to send dgrams to initrc_t - Allow kdm to start the power service to initiate a reboot or poweroff- Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Don't audit attempts to write to stream socket of nscld by thumbnailers - Allow git_system_t to read network state - Allow pegasas to execute mount command - Fix desc for drdb_admin - Fix condor_amin() - Interface fixes for uptime, vdagent, vnstatd - Fix labeling for moodle in /var/www/moodle/data - Add interface fixes - Allow bugzilla to read certs - /var/www/moodle needs to be writable by apache - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Fix namespace_init_t to create content with proper labels, and allow it to manage all user content - Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Fix sys_nice for cups_domain - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Kernel_t needs mac_admin in order to support labeled NFS - Fix systemd_dontaudit_dbus_chat() interface - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Allow consolehelper domain to write Xauth files in /root - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Allow consolehelper more access discovered by Tom London - Allow fsdaemon to send signull to all domain - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Fix file_contexts.subs to label /run/lock correctly- Try to label on controlC devices up to 30 correctly - Add mount_rw_pid_files() interface - Add additional mount/umount interfaces needed by mock - fsadm_t sends audit messages in reads kernel_ipc_info when doing livecd-iso-to-disk - Fix tabs - Allow initrc_domain to search rgmanager lib files - Add more fixes which make mock working together with confined users * Allow mock_t to manage rpm files * Allow mock_t to read rpm log files * Allow mock to setattr on tmpfs, devpts * Allow mount/umount filesystems - Add rpm_read_log() interface - yum-cron runs rpm from within it. - Allow tuned to transition to dmidecode - Allow firewalld to do net_admin - Allow mock to unmont tmpfs_t - Fix virt_sigkill() interface - Add additional fixes for mock. Mainly caused by mount running in mock_t - Allow mock to write sysfs_t and mount pid files - Add mailman_domain to mailman_template() - Allow openvswitch to execute shell - Allow qpidd to use kerberos - Allow mailman to use fusefs, needs back port to RHEL6 - Allow apache and its scripts to use anon_inodefs - Add alias for git_user_content_t and git_sys_content_t so that RHEL6 will update to RHEL7 - Realmd needs to connect to samba ports, needs back port to F18 also - Allow colord to read /run/initial-setup- - Allow sanlock-helper to send sigkill to virtd which is registred to sanlock - Add virt_kill() interface - Add rgmanager_search_lib() interface - Allow wdmd to getattr on all filesystems. Back ported from RHEL6- Allow realmd to create tmp files - FIx ircssi_home_t type to irssi_home_t - Allow adcli running as realmd_t to connect to ldap port - Allow NetworkManager to transition to ipsec_t, for running strongswan - Make openshift_initrc_t an lxc_domain - Allow gssd to manage user_tmp_t files - Fix handling of irclogs in users homedir - Fix labeling for drupal an wp-content in subdirs of /var/www/html - Allow abrt to read utmp_t file - Fix openshift policy to transition lnk_file, sock-file an fifo_file when created in a tmpfs_t, needs back port to RHEL6 - fix labeling for (oo|rhc)-restorer-wrapper.sh - firewalld needs to be able to write to network sysctls - Fix mozilla_plugin_dontaudit_rw_sem() interface - Dontaudit generic ipc read/write to a mozilla_plugin for sandbox_x domains - Add mozilla_plugin_dontaudit_rw_sem() interface - Allow svirt_lxc_t to transition to openshift domains - Allow condor domains block_suspend and dac_override caps - Allow condor_master to read passd - Allow condor_master to read system state - Allow NetworkManager to transition to ipsec_t, for running strongswan - Lots of access required by lvm_t to created encrypted usb device - Allow xdm_t to dbus communicate with systemd_localed_t - Label strongswan content as ipsec_exec_mgmt_t for now - Allow users to dbus chat with systemd_localed - Fix handling of .xsession-errors in xserver.if, so kde will work - Might be a bug but we are seeing avc's about people status on init_t:service - Make sure we label content under /var/run/lock as <> - Allow daemon and systemprocesses to search init_var_run_t directory - Add boolean to allow xdm to write xauth data to the home directory - Allow mount to write keys for the unconfined domain - Add unconfined_write_keys() interface- Add labeling for /usr/share/pki - Allow programs that read var_run_t symlinks also read var_t symlinks - Add additional ports as mongod_port_t for 27018, 27019, 28017, 28018 and 28019 ports - Fix labeling for /etc/dhcp directory - add missing systemd_stub_unit_file() interface - Add files_stub_var() interface - Add lables for cert_t directories - Make localectl set-x11-keymap working at all - Allow abrt to manage mock build environments to catch build problems. - Allow virt_domains to setsched for running gdb on itself - Allow thumb_t to execute user home content - Allow pulseaudio running as mozilla_plugin_t to read /run/systemd/users/1000 - Allow certwatch to execut /usr/bin/httpd - Allow cgred to send signal perms to itself, needs back port to RHEL6 - Allow openshift_cron_t to look at quota - Allow cups_t to read inhered tmpfs_t from the kernel - Allow yppasswdd to use NIS - Tuned wants sys_rawio capability - Add ftpd_use_fusefs boolean - Allow dirsrvadmin_t to signal itself- Allow localectl to read /etc/X11/xorg.conf.d directory - Revert "Revert "Fix filetrans rules for kdm creates .xsession-errors"" - Allow mount to transition to systemd_passwd_agent - Make sure abrt directories are labeled correctly - Allow commands that are going to read mount pid files to search mount_var_run_t - label /usr/bin/repoquery as rpm_exec_t - Allow automount to block suspend - Add abrt_filetrans_named_content so that abrt directories get labeled correctly - Allow virt domains to setrlimit and read file_context- Allow nagios to manage nagios spool files - /var/spool/snmptt is a directory which snmdp needs to write to, needs back port to RHEL6 - Add swift_alias.* policy files which contain typealiases for swift types - Add support for /run/lock/opencryptoki - Allow pkcsslotd chown capability - Allow pkcsslotd to read passwd - Add rsync_stub() interface - Allow systemd_timedate also manage gnome config homedirs - Label /usr/lib64/security/pam_krb5/pam_krb5_cchelper as bin_t - Fix filetrans rules for kdm creates .xsession-errors - Allow sytemd_tmpfiles to create wtmp file - Really should not label content under /var/lock, since it could have labels on it different from var_lock_t - Allow systemd to list all file system directories - Add some basic stub interfaces which will be used in PRODUCT policies- Fix log transition rule for cluster domains - Start to group all cluster log together - Dont use filename transition for POkemon Advanced Adventure until a new checkpolicy update - cups uses usbtty_device_t devices - These fixes were all required to build a MLS virtual Machine with single level desktops - Allow domains to transiton using httpd_exec_t - Allow svirt domains to manage kernel key rings - Allow setroubleshoot to execute ldconfig - Allow firewalld to read generate gnome data - Allow bluetooth to read machine-info - Allow boinc domain to send signal to itself - Fix gnome_filetrans_home_content() interface - Allow mozilla_plugins to list apache modules, for use with gxine - Fix labels for POkemon in the users homedir - Allow xguest to read mdstat - Dontaudit virt_domains getattr on /dev/* - These fixes were all required to build a MLS virtual Machine with single level desktops - Need to back port this to RHEL6 for openshift - Add tcp/8891 as milter port - Allow nsswitch domains to read sssd_var_lib_t files - Allow ping to read network state. - Fix typo - Add labels to /etc/X11/xorg.d and allow systemd-timestampd_t to manage them- Adopt swift changes from lhh@redhat.com - Add rhcs_manage_cluster_pid_files() interface - Allow screen domains to configure tty and setup sock_file in ~/.screen directory - ALlow setroubleshoot to read default_context_t, needed to backport to F18 - Label /etc/owncloud as being an apache writable directory - Allow sshd to stream connect to an lxc domain- Allow postgresql to manage rgmanager pid files - Allow postgresql to read ccs data - Allow systemd_domain to send dbus messages to policykit - Add labels for /etc/hostname and /etc/machine-info and allow systemd-hostnamed to create them - All systemd domains that create content are reading the file_context file and setfscreate - Systemd domains need to search through init_var_run_t - Allow sshd to communicate with libvirt to set containers labels - Add interface to manage pid files - Allow NetworkManger_t to read /etc/hostname - Dontaudit leaked locked files into openshift_domains - Add fixes for oo-cgroup-read - it nows creates tmp files - Allow gluster to manage all directories as well as files - Dontaudit chrome_sandbox_nacl_t using user terminals - Allow sysstat to manage its own log files - Allow virtual machines to setrlimit and send itself signals. - Add labeling for /var/run/hplip- Fix POSTIN scriptlet- Merge rgmanger, corosync,pacemaker,aisexec policies to cluster_t in rhcs.pp- Fix authconfig.py labeling - Make any domains that write homedir content do it correctly - Allow glusterd to read/write anyhwere on the file system by default - Be a little more liberal with the rsync log files - Fix iscsi_admin interface - Allow iscsid_t to read /dev/urand - Fix up iscsi domain for use with unit files - Add filename transition support for spamassassin policy - Allow web plugins to use badly formated libraries - Allow nmbd_t to create samba_var_t directories - Add filename transition support for spamassassin policy - Add filename transition support for tvtime - Fix alsa_home_filetrans_alsa_home() interface - Move all userdom_filetrans_home_content() calling out of booleans - Allow logrotote to getattr on all file sytems - Remove duplicate userdom_filetrans_home_content() calling - Allow kadmind to read /etc/passwd - Dontaudit append .xsession-errors file on ecryptfs for policykit-auth - Allow antivirus domain to manage antivirus db links - Allow logrotate to read /sys - Allow mandb to setattr on man dirs - Remove mozilla_plugin_enable_homedirs boolean - Fix ftp_home_dir boolean - homedir mozilla filetrans has been moved to userdom_home_manager - homedir telepathy filetrans has been moved to userdom_home_manager - Remove gnome_home_dir_filetrans() from gnome_role_gkeyringd() - Might want to eventually write a daemon on fusefsd. - Add policy fixes for sshd [net] child from plautrba@redhat.com - Tor uses a new port - Remove bin_t for authconfig.py - Fix so only one call to userdom_home_file_trans - Allow home_manager_types to create content with the correctl label - Fix all domains that write data into the homedir to do it with the correct label - Change the postgresql to use proper boolean names, which is causing httpd_t to - not get access to postgresql_var_run_t - Hostname needs to send syslog messages - Localectl needs to be able to send dbus signals to users - Make sure userdom_filetrans_type will create files/dirs with user_home_t labeling by default - Allow user_home_manger domains to create spam* homedir content with correct labeling - Allow user_home_manger domains to create HOMEDIR/.tvtime with correct labeling - Add missing miscfiles_setattr_man_pages() interface and for now comment some rules for userdom_filetrans_type to make build process working - Declare userdom_filetrans_type attribute - userdom_manage_home_role() needs to be called withoout usertype attribute because of userdom_filetrans_type attribute - fusefsd is mounding a fuse file system on /run/user/UID/gvfs- Man pages are now generated in the build process - Allow cgred to list inotifyfs filesystem- Allow gluster to get attrs on all fs - New access required for virt-sandbox - Allow dnsmasq to execute bin_t - Allow dnsmasq to create content in /var/run/NetworkManager - Fix openshift_initrc_signal() interface - Dontaudit openshift domains doing getattr on other domains - Allow consolehelper domain to communicate with session bus - Mock should not be transitioning to any other domains, we should keep mock_t as mock_t - Update virt_qemu_ga_t policy - Allow authconfig running from realmd to restart oddjob service - Add systemd support for oddjob - Add initial policy for realmd_consolehelper_t which if for authconfig executed by realmd - Add labeling for gnashpluginrc - Allow chrome_nacl to execute /dev/zero - Allow condor domains to read /proc - mozilla_plugin_t will getattr on /core if firefox crashes - Allow condor domains to read /etc/passwd - Allow dnsmasq to execute shell scripts, openstack requires this access - Fix glusterd labeling - Allow virtd_t to interact with the socket type - Allow nmbd_t to override dac if you turned on sharing all files - Allow tuned to created kobject_uevent socket - Allow guest user to run fusermount - Allow openshift to read /proc and locale - Allow realmd to dbus chat with rpm - Add new interface for virt - Remove depracated interfaces - Allow systemd_domains read access on etc, etc_runtime and usr files, also allow them to connect stream to syslog socket - /usr/share/munin/plugins/plugin.sh should be labeled as bin_t - Remove some more unconfined_t process transitions, that I don't believe are necessary - Stop transitioning uncofnined_t to checkpc - dmraid creates /var/lock/dmraid - Allow systemd_localed to creatre unix_dgram_sockets - Allow systemd_localed to write kernel messages. - Also cleanup systemd definition a little. - Fix userdom_restricted_xwindows_user_template() interface - Label any block devices or char devices under /dev/infiniband as fixed_disk_device_t - User accounts need to dbus chat with accountsd daemon - Gnome requires all users to be able to read /proc/1/- virsh now does a setexeccon call - Additional rules required by openshift domains - Allow svirt_lxc_domains to use inherited terminals, needed to make virt-sandbox-service execute work - Allow spamd_update_t to search spamc_home_t - Avcs discovered by mounting an isci device under /mnt - Allow lspci running as logrotate to read pci.ids - Additional fix for networkmanager_read_pid_files() - Fix networkmanager_read_pid_files() interface - Allow all svirt domains to connect to svirt_socket_t - Allow virsh to set SELinux context for a process. - Allow tuned to create netlink_kobject_uevent_socket - Allow systemd-timestamp to set SELinux context - Add support for /var/lib/systemd/linger - Fix ssh_sysadm_login to be working on MLS as expected- Rename files_rw_inherited_tmp_files to files_rw_inherited_tmp_file - Add missing files_rw_inherited_tmp_files interface - Add additional interface for ecryptfs - ALlow nova-cert to connect to postgresql - Allow keystone to connect to postgresql - Allow all cups domains to getattr on filesystems - Allow pppd to send signull - Allow tuned to execute ldconfig - Allow gpg to read fips_enabled - Add additional fixes for ecryptfs - Allow httpd to work with posgresql - Allow keystone getsched and setsched- Allow gpg to read fips_enabled - Add support for /var/cache/realmd - Add support for /usr/sbin/blazer_usb and systemd support for nut - Add labeling for fenced_sanlock and allow sanclok transition to fenced_t - bitlbee wants to read own log file - Allow glance domain to send a signal itself - Allow xend_t to request that the kernel load a kernel module - Allow pacemaker to execute heartbeat lib files - cleanup new swift policy- Fix smartmontools - Fix userdom_restricted_xwindows_user_template() interface - Add xserver_xdm_ioctl_log() interface - Allow Xusers to ioctl lxdm.log to make lxdm working - Add MLS fixes to make MLS boot/log-in working - Add mls_socket_write_all_levels() also for syslogd - fsck.xfs needs to read passwd - Fix ntp_filetrans_named_content calling in init.te - Allow postgresql to create pg_log dir - Allow sshd to read rsync_data_t to make rsync working - Change ntp.conf to be labeled net_conf_t - Allow useradd to create homedirs in /run. ircd-ratbox does this and we should just allow it - Allow xdm_t to execute gstreamer home content - Allod initrc_t and unconfined domains, and sysadm_t to manage ntp - New policy for openstack swift domains - More access required for openshift_cron_t - Use cupsd_log_t instead of cupsd_var_log_t - rpm_script_roles should be used in rpm_run - Fix rpm_run() interface - Fix openshift_initrc_run() - Fix sssd_dontaudit_stream_connect() interface - Fix sssd_dontaudit_stream_connect() interface - Allow LDA's job to deliver mail to the mailbox - dontaudit block_suspend for mozilla_plugin_t - Allow l2tpd_t to all signal perms - Allow uuidgen to read /dev/random - Allow mozilla-plugin-config to read power_supply info - Implement cups_domain attribute for cups domains - We now need access to user terminals since we start by executing a command outside the tty - We now need access to user terminals since we start by executing a command outside the tty - svirt lxc containers want to execute userhelper apps, need these changes to allow this to happen - Add containment of openshift cron jobs - Allow system cron jobs to create tmp directories - Make userhelp_conf_t a config file - Change rpm to use rpm_script_roles - More fixes for rsync to make rsync wokring - Allow logwatch to domtrans to mdadm - Allow pacemaker to domtrans to ifconfig - Allow pacemaker to setattr on corosync.log - Add pacemaker_use_execmem for memcheck-amd64 command - Allow block_suspend capability - Allow create fifo_file in /tmp with pacemaker_tmp_t - Allow systat to getattr on fixed disk - Relabel /etc/ntp.conf to be net_conf_t - ntp_admin should create files in /etc with the correct label - Add interface to create ntp_conf_t files in /etc - Add additional labeling for quantum - Allow quantum to execute dnsmasq with transition- boinc_cliean wants also execmem as boinc projecs have - Allow sa-update to search admin home for /root/.spamassassin - Allow sa-update to search admin home for /root/.spamassassin - Allow antivirus domain to read net sysctl - Dontaudit attempts from thumb_t to connect to ssd - Dontaudit attempts by readahead to read sock_files - Dontaudit attempts by readahead to read sock_files - Create tmpfs file while running as wine as user_tmpfs_t - Dontaudit attempts by readahead to read sock_files - libmpg ships badly created librarie- Change ssh_use_pts to use macro and only inherited sshd_devpts_t - Allow confined users to read systemd_logind seat information - libmpg ships badly created libraries - Add support for strongswan.service - Add labeling for strongswan - Allow l2tpd_t to read network manager content in /run directory - Allow rsync to getattr any file in rsync_data_t - Add labeling and filename transition for .grl-podcasts- mount.glusterfs executes glusterfsd binary - Allow systemd_hostnamed_t to stream connect to systemd - Dontaudit any user doing a access check - Allow obex-data-server to request the kernel to load a module - Allow gpg-agent to manage gnome content (~/.cache/gpg-agent-info) - Allow gpg-agent to read /proc/sys/crypto/fips_enabled - Add new types for antivirus.pp policy module - Allow gnomesystemmm_t caps because of ioprio_set - Make sure if mozilla_plugin creates files while in permissive mode, they get created with the correct label, user_home_t - Allow gnomesystemmm_t caps because of ioprio_set - Allow NM rawip socket - files_relabel_non_security_files can not be used with boolean - Add interface to thumb_t dbus_chat to allow it to read remote process state - ALlow logrotate to domtrans to mdadm_t - kde gnomeclock wants to write content to /tmp- kde gnomeclock wants to write content to /tmp - /usr/libexec/kde4/kcmdatetimehelper attempts to create /root/.kde - Allow blueman_t to rwx zero_device_t, for some kind of jre - Allow mozilla_plugin_t to rwx zero_device_t, for some kind of jre - Ftp full access should be allowed to create directories as well as files - Add boolean to allow rsync_full_acces, so that an rsync server can write all - over the local machine - logrotate needs to rotate logs in openshift directories, needs back port to RHEL6 - Add missing vpnc_roles type line - Allow stapserver to write content in /tmp - Allow gnome keyring to create keyrings dir in ~/.local/share - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Add interface to colord_t dbus_chat to allow it to read remote process state - Allow colord_t to read cupsd_t state - Add mate-thumbnail-font as thumnailer - Allow sectoolm to sys_ptrace since it is looking at other proceses /proc data. - Allow qpidd to list /tmp. Needed by ssl - Only allow init_t to transition to rsync_t domain, not initrc_t. This should be back ported to F17, F18 - - Added systemd support for ksmtuned - Added booleans ksmtuned_use_nfs ksmtuned_use_cifs - firewalld seems to be creating mmap files which it needs to execute in /run /tmp and /dev/shm. Would like to clean this up but for now we will allow - Looks like qpidd_t needs to read /dev/random - Lots of probing avc's caused by execugting gpg from staff_t - Dontaudit senmail triggering a net_admin avc - Change thumb_role to use thumb_run, not sure why we have a thumb_role, needs back port - Logwatch does access check on mdadm binary - Add raid_access_check_mdadm() iterface- Fix systemd_manage_unit_symlinks() interface - Call systemd_manage_unit_symlinks(() which is correct interface - Add filename transition for opasswd - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow sytstemd-timedated to get status of init_t - Add new systemd policies for hostnamed and rename gnomeclock_t to systemd_timedate_t - colord needs to communicate with systemd and systemd_logind, also remove duplicate rules - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow gpg_t to manage all gnome files - Stop using pcscd_read_pub_files - New rules for xguest, dontaudit attempts to dbus chat - Allow firewalld to create its mmap files in tmpfs and tmp directories - Allow firewalld to create its mmap files in tmpfs and tmp directories - run unbound-chkconf as named_t, so it can read dnssec - Colord is reading xdm process state, probably reads state of any apps that sends dbus message - Allow mdadm_t to change the kernel scheduler - mythtv policy - Update mandb_admin() interface - Allow dsspam to listen on own tpc_socket - seutil_filetrans_named_content needs to be optional - Allow sysadm_t to execute content in his homedir - Add attach_queue to tun_socket, new patch from Paul Moore - Change most of selinux configuration types to security_file_type. - Add filename transition rules for selinux configuration - ssh into a box with -X -Y requires ssh_use_ptys - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Allow all unpriv userdomains to send dbus messages to hostnamed and timedated - New allow rules found by Tom London for systemd_hostnamed- Allow systemd-tmpfiles to relabel lpd spool files - Ad labeling for texlive bash scripts - Add xserver_filetrans_fonts_cache_home_content() interface - Remove duplicate rules from *.te - Add support for /var/lock/man-db.lock - Add support for /var/tmp/abrt(/.*)? - Add additional labeling for munin cgi scripts - Allow httpd_t to read munin conf files - Allow certwatch to read meminfo - Fix nscd_dontaudit_write_sock_file() interfac - Fix gnome_filetrans_home_content() to include also "fontconfig" dir as cache_home_t - llow mozilla_plugin_t to create HOMEDIR/.fontconfig with the proper labeling- Allow gnomeclock to talk to puppet over dbus - Allow numad access discovered by Dominic - Add support for HOME_DIR/.maildir - Fix attribute_role for mozilla_plugin_t domain to allow staff_r to access this domain - Allow udev to relabel udev_var_run_t lnk_files - New bin_t file in mcelog- Remove all mcs overrides and replace with t1 != mcs_constrained_types - Add attribute_role for iptables - mcs_process_set_categories needs to be called for type - Implement additional role_attribute statements - Sodo domain is attempting to get the additributes of proc_kcore_t - Unbound uses port 8953 - Allow svirt_t images to compromise_kernel when using pci-passthrough - Add label for dns lib files - Bluetooth aquires a dbus name - Remove redundant files_read_usr_file calling - Remove redundant files_read_etc_file calling - Fix mozilla_run_plugin() - Add role_attribute support for more domains- Mass merge with upstream- Bump the policy version to 28 to match selinux userspace - Rebuild versus latest libsepol- Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Add labeling for /var/named/chroot/etc/localtim- Allow setroubleshoot_fixit to execute rpm - zoneminder needs to connect to httpd ports where remote cameras are listening - Allow firewalld to execute content created in /run directory - Allow svirt_t to read generic certs - Dontaudit leaked ps content to mozilla plugin - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - init scripts are creating systemd_unit_file_t directories- systemd_logind_t is looking at all files under /run/user/apache - Allow systemd to manage all user tmp files - Add labeling for /var/named/chroot/etc/localtime - Allow netlabel_peer_t type to flow over netif_t and node_t, and only be hindered by MLS, need back port to RHEL6 - Keystone is now using a differnt port - Allow xdm_t to use usbmuxd daemon to control sound - Allow passwd daemon to execute gnome_exec_keyringd - Fix chrome_sandbox policy - Add labeling for /var/run/checkquorum-timer - More fixes for the dspam domain, needs back port to RHEL6 - More fixes for the dspam domain, needs back port to RHEL6 - sssd needs to connect to kerberos password port if a user changes his password - Lots of fixes from RHEL testing of dspam web - Allow chrome and mozilla_plugin to create msgq and semaphores - Fixes for dspam cgi scripts - Fixes for dspam cgi scripts - Allow confine users to ptrace screen - Backport virt_qemu_ga_t changes from RHEL - Fix labeling for dspam.cgi needed for RHEL6 - We need to back port this policy to RHEL6, for lxc domains - Dontaudit attempts to set sys_resource of logrotate - Allow corosync to read/write wdmd's tmpfs files - I see a ptrace of mozilla_plugin_t by staff_t, will allow without deny_ptrace being set - Allow cron jobs to read bind config for unbound - libvirt needs to inhibit systemd - kdumpctl needs to delete boot_t files - Fix duplicate gnome_config_filetrans - virtd_lxc_t is using /dev/fuse - Passenger needs to create a directory in /var/log, needs a backport to RHEL6 for openshift - apcupsd can be setup to listen to snmp trafic - Allow transition from kdumpgui to kdumpctl - Add fixes for munin CGI scripts - Allow deltacloud to connect to openstack at the keystone port - Allow domains that transition to svirt domains to be able to signal them - Fix file context of gstreamer in .cache directory - libvirt is communicating with logind - NetworkManager writes to the systemd inhibit pipe- Allow munin disk plugins to get attributes of all directories - Allow munin disk plugins to get attributes of all directorie - Allow logwatch to get attributes of all directories - Fix networkmanager_manage_lib() interface - Fix gnome_manage_config() to allow to manage sock_file - Fix virtual_domain_context - Add support for dynamic DNS for DHCPv6- Allow svirt to use netlink_route_socket which was a part of auth_use_nsswitch - Add additional labeling for /var/www/openshift/broker - Fix rhev policy - Allow openshift_initrc domain to dbus chat with systemd_logind - Allow httpd to getattr passenger log file if run_stickshift - Allow consolehelper-gtk to connect to xserver - Add labeling for the tmp-inst directory defined in pam_namespace.conf - Add lvm_metadata_t labeling for /etc/multipath- consoletype is no longer used- Add label for efivarfs - Allow certmonger to send signal to itself - Allow plugin-config to read own process status - Add more fixes for pacemaker - apache/drupal can run clamscan on uploaded content - Allow chrome_sandbox_nacl_t to read pid 1 content- Fix MCS Constraints to control ingres and egres controls on the network. - Change name of svirt_nokvm_t to svirt_tcg_t - Allow tuned to request the kernel to load kernel modules- Label /var/lib/pgsql/.ssh as ssh_home_t - Add labeling for /usr/bin/pg_ctl - Allow systemd-logind to manage keyring user tmp dirs - Add support for 7389/tcp port - gems seems to be placed in lots of places - Since xdm is running a full session, it seems to be trying to execute lots of executables via dbus - Add back tcp/8123 port as http_cache port - Add ovirt-guest-agent\.pid labeling - Allow xend to run scsi_id - Allow rhsmcertd-worker to read "physical_package_id" - Allow pki_tomcat to connect to ldap port - Allow lpr to read /usr/share/fonts - Allow open file from CD/DVD drive on domU - Allow munin services plugins to talk to SSSD - Allow all samba domains to create samba directory in var_t directories - Take away svirt_t ability to use nsswitch - Dontaudit attempts by openshift to read apache logs - Allow apache to create as well as append _ra_content_t - Dontaudit sendmail_t reading a leaked file descriptor - Add interface to have admin transition /etc/prelink.cache to the proper label - Add sntp support to ntp policy - Allow firewalld to dbus chat with devicekit_power - Allow tuned to call lsblk - Allow tor to read /proc/sys/kernel/random/uuid - Add tor_can_network_relay boolean- Add openshift_initrc_signal() interface - Fix typos - dspam port is treat as spamd_port_t - Allow setroubleshoot to getattr on all executables - Allow tuned to execute profiles scripts in /etc/tuned - Allow apache to create directories to store its log files - Allow all directories/files in /var/log starting with passenger to be labeled passenger_log_t - Looks like apache is sending sinal to openshift_initrc_t now,needs back port to RHEL6 - Allow Postfix to be configured to listen on TCP port 10026 for email from DSPAM - Add filename transition for /etc/tuned/active_profile - Allow condor_master to send mails - Allow condor_master to read submit.cf - Allow condor_master to create /tmp files/dirs - Allow condor_mater to send sigkill to other condor domains - Allow condor_procd sigkill capability - tuned-adm wants to talk with tuned daemon - Allow kadmind and krb5kdc to also list sssd_public_t - Allow accountsd to dbus chat with init - Fix git_read_generic_system_content_files() interface - pppd wants sys_nice by nmcli because of "syscall=sched_setscheduler" - Fix mozilla_plugin_can_network_connect to allow to connect to all ports - Label all munin plugins which are not covered by munin plugins policy as unconfined_munin_plugin_exec_t - dspam wants to search /var/spool for opendkim data - Revert "Add support for tcp/10026 port as dspam_port_t" - Turning on labeled networking requires additional access for netlabel_peer_t; these allow rules need to be back ported to RHEL6 - Allow all application domains to use fifo_files passed in from userdomains, also allow them to write to tmp_files inherited from userdomain - Allow systemd_tmpfiles_t to setattr on mandb_cache_t- consolekit.pp was not removed from the postinstall script- Add back consolekit policy - Silence bootloader trying to use inherited tty - Silence xdm_dbusd_t trying to execute telepathy apps - Fix shutdown avcs when machine has unconfined.pp disabled - The host and a virtual machine can share the same printer on a usb device - Change oddjob to transition to a ranged openshift_initr_exec_t when run from oddjob - Allow abrt_watch_log_t to execute bin_t - Allow chrome sandbox to write content in ~/.config/chromium - Dontaudit setattr on fontconfig dir for thumb_t - Allow lircd to request the kernel to load module - Make rsync as userdom_home_manager - Allow rsync to search automount filesystem - Add fixes for pacemaker- Add support for 4567/tcp port - Random fixes from Tuomo Soini - xdm wants to get init status - Allow programs to run in fips_mode - Add interface to allow the reading of all blk device nodes - Allow init to relabel rpcbind sock_file - Fix labeling for lastlog and faillog related to logrotate - ALlow aeolus_configserver to use TRAM port - Add fixes for aeolus_configserver - Allow snmpd to connect to snmp port - Allow spamd_update to create spamd_var_lib_t directories - Allow domains that can read sssd_public_t files to also list the directory - Remove miscfiles_read_localization, this is defined for all domains- Allow syslogd to request the kernel to load a module - Allow syslogd_t to read the network state information - Allow xdm_dbusd_t connect to the system DBUS - Add support for 7389/tcp port - Allow domains to read/write all inherited sockets - Allow staff_t to read kmsg - Add awstats_purge_apache_log boolean - Allow ksysguardproces to read /.config/Trolltech.conf - Allow passenger to create and append puppet log files - Add puppet_append_log and puppet_create_log interfaces - Add puppet_manage_log() interface - Allow tomcat domain to search tomcat_var_lib_t - Allow pki_tomcat_t to connect to pki_ca ports - Allow pegasus_t to have net_admin capability - Allow pegasus_t to write /sys/class/net//flags - Allow mailserver_delivery to manage mail_home_rw_t lnk_files - Allow fetchmail to create log files - Allow gnomeclock to manage home config in .kde - Allow bittlebee to read kernel sysctls - Allow logrotate to list /root- Fix userhelper_console_role_template() - Allow enabling Network Access Point service using blueman - Make vmware_host_t as unconfined domain - Allow authenticate users in webaccess via squid, using mysql as backend - Allow gathers to get various metrics on mounted file systems - Allow firewalld to read /etc/hosts - Fix cron_admin_role() to make sysadm cronjobs running in the sysadm_t instead of cronjob_t - Allow kdumpgui to read/write to zipl.conf - Commands needed to get mock to build from staff_t in enforcing mode - Allow mdadm_t to manage cgroup files - Allow all daemons and systemprocesses to use inherited initrc_tmp_t files - dontaudit ifconfig_t looking at fifo_files that are leaked to it - Add lableing for Quest Authentication System- Fix filetrans interface definitions - Dontaudit xdm_t to getattr on BOINC lib files - Add systemd_reload_all_services() interface - Dontaudit write access on /var/lib/net-snmp/mib_indexes - Only stop mcsuntrustedproc from relableing files - Allow accountsd to dbus chat with gdm - Allow realmd to getattr on all fs - Allow logrotate to reload all services - Add systemd unit file for radiusd - Allow winbind to create samba pid dir - Add labeling for /var/nmbd/unexpected - Allow chrome and mozilla plugin to connect to msnp ports- Fix storage_rw_inherited_fixed_disk_dev() to cover also blk_file - Dontaudit setfiles reading /dev/random - On initial boot gnomeclock is going to need to be set buy gdm - Fix tftp_read_content() interface - Random apps looking at kernel file systems - Testing virt with lxc requiers additional access for virsh_t - New allow rules requied for latest libvirt, libvirt talks directly to journald,lxc setup tool needs compromize_kernel,and we need ipc_lock in the container - Allow MPD to read /dev/radnom - Allow sandbox_web_type to read logind files which needs to read pulseaudio - Allow mozilla plugins to read /dev/hpet - Add labeling for /var/lib/zarafa-webap - Allow BOINC client to use an HTTP proxy for all connections - Allow rhsmertd to domain transition to dmidecod - Allow setroubleshootd to send D-Bus msg to ABRT- Define usbtty_device_t as a term_tty - Allow svnserve to accept a connection - Allow xend manage default virt_image_t type - Allow prelink_cron_system_t to overide user componant when executing cp - Add labeling for z-push - Gnomeclock sets the realtime clock - Openshift seems to be storing apache logs in /var/lib/openshift/.log/httpd - Allow lxc domains to use /dev/random and /dev/urandom- Add port defintion for tcp/9000 - Fix labeling for /usr/share/cluster/checkquorum to label also checkquorum.wdmd - Add rules and labeling for $HOME/cache/\.gstreamer-.* directory - Add support for CIM provider openlmi-networking which uses NetworkManager dbus API - Allow shorewall_t to create netlink_socket - Allow krb5admind to block suspend - Fix labels on /var/run/dlm_controld /var/log/dlm_controld - Allow krb5kdc to block suspend - gnomessytemmm_t needs to read /etc/passwd - Allow cgred to read all sysctls- Allow all domains to read /proc/sys/vm/overcommit_memory - Make proc_numa_t an MLS Trusted Object - Add /proc/numactl support for confined users - Allow ssh_t to connect to any port > 1023 - Add openvswitch domain - Pulseaudio tries to create directories in gnome_home_t directories - New ypbind pkg wants to search /var/run which is caused by sd_notify - Allow NM to read certs on NFS/CIFS using use_nfs_*, use_samba_* booleans - Allow sanlock to read /dev/random - Treat php-fpm with httpd_t - Allow domains that can read named_conf_t to be able to list the directories - Allow winbind to create sock files in /var/run/samba- Add smsd policy - Add support for OpenShift sbin labelin - Add boolean to allow virt to use rawip - Allow mozilla_plugin to read all file systems with noxattrs support - Allow kerberos to write on anon_inodefs fs - Additional access required by fenced - Add filename transitions for passwd.lock/group.lock - UPdate man pages - Create coolkey directory in /var/cache with the correct label- Fix label on /etc/group.lock - Allow gnomeclock to create lnk_file in /etc - label /root/.pki as a home_cert_t - Add interface to make sure rpcbind.sock is created with the correct label - Add definition for new directory /var/lib/os-probe and bootloader wants to read udev rules - opendkim should be a part of milter - Allow libvirt to set the kernel sched algorythm - Allow mongod to read sysfs_t - Add authconfig policy - Remove calls to miscfiles_read_localization all domains get this - Allow virsh_t to read /root/.pki/ content - Add label for log directory under /var/www/stickshift- Allow getty to setattr on usb ttys - Allow sshd to search all directories for sshd_home_t content - Allow staff domains to send dbus messages to kdumpgui - Fix labels on /etc/.pwd.lock and friends to be passwd_file_t - Dontaudit setfiles reading urand - Add files_dontaudit_list_tmp() for domains to which we added sys_nice/setsched - Allow staff_gkeyringd_t to read /home/$USER/.local/share/keyrings dir - Allow systemd-timedated to read /dev/urandom - Allow entropyd_t to read proc_t (meminfo) - Add unconfined munin plugin - Fix networkmanager_read_conf() interface - Allow blueman to list /tmp which is needed by sys_nic/setsched - Fix label of /etc/mail/aliasesdb-stamp - numad is searching cgroups - realmd is communicating with networkmanager using dbus - Lots of fixes to try to get kdump to work- Allow loging programs to dbus chat with realmd - Make apache_content_template calling as optional - realmd is using policy kit- Add new selinuxuser_use_ssh_chroot boolean - dbus needs to be able to read/write inherited fixed disk device_t passed through it - Cleanup netutils process allow rule - Dontaudit leaked fifo files from openshift to ping - sanlock needs to read mnt_t lnk files - Fail2ban needs to setsched and sys_nice- Change default label of all files in /var/run/rpcbind - Allow sandbox domains (java) to read hugetlbfs_t - Allow awstats cgi content to create tmp files and read apache log files - Allow setuid/setgid for cupsd-config - Allow setsched/sys_nice pro cupsd-config - Fix /etc/localtime sym link to be labeled locale_t - Allow sshd to search postgresql db t since this is a homedir - Allow xwindows users to chat with realmd - Allow unconfined domains to configure all files and null_device_t service- Adopt pki-selinux policy- pki is leaking which we dontaudit until a pki code fix - Allow setcap for arping - Update man pages - Add labeling for /usr/sbin/mcollectived - pki fixes - Allow smokeping to execute fping in the netutils_t domain- Allow mount to relabelfrom unlabeled file systems - systemd_logind wants to send and receive messages from devicekit disk over dbus to make connected mouse working - Add label to get bin files under libreoffice labeled correctly - Fix interface to allow executing of base_ro_file_type - Add fixes for realmd - Update pki policy - Add tftp_homedir boolean - Allow blueman sched_setscheduler - openshift user domains wants to r/w ssh tcp sockets- Additional requirements for disable unconfined module when booting - Fix label of systemd script files - semanage can use -F /dev/stdin to get input - syslog now uses kerberos keytabs - Allow xserver to compromise_kernel access - Allow nfsd to write to mount_var_run_t when running the mount command - Add filename transition rule for bin_t directories - Allow files to read usr_t lnk_files - dhcpc wants chown - Add support for new openshift labeling - Clean up for tunable+optional statements - Add labeling for /usr/sbin/mkhomedir_helper - Allow antivirus domain to managa amavis spool files - Allow rpcbind_t to read passwd - Allow pyzor running as spamc to manage amavis spool- Add interfaces to read kernel_t proc info - Missed this version of exec_all - Allow anyone who can load a kernel module to compromise kernel - Add oddjob_dbus_chat to openshift apache policy - Allow chrome_sandbox_nacl_t to send signals to itself - Add unit file support to usbmuxd_t - Allow all openshift domains to read sysfs info - Allow openshift domains to getattr on all domains- MLS fixes from Dan - Fix name of capability2 secure_firmware->compromise_kerne- Allow xdm to search all file systems - Add interface to allow the config of all files - Add rngd policy - Remove kgpg as a gpg_exec_t type - Allow plymouthd to block suspend - Allow systemd_dbus to config any file - Allow system_dbus_t to configure all services - Allow freshclam_t to read usr_files - varnishd requires execmem to load modules- Allow semanage to verify types - Allow sudo domain to execute user home files - Allow session_bus_type to transition to user_tmpfs_t - Add dontaudit caused by yum updates - Implement pki policy but not activated- tuned wants to getattr on all filesystems - tuned needs also setsched. The build is needed for test day- Add policy for qemu-qa - Allow razor to write own config files - Add an initial antivirus policy to collect all antivirus program - Allow qdisk to read usr_t - Add additional caps for vmware_host - Allow tmpfiles_t to setattr on mandb_cache_t - Dontaudit leaked files into mozilla_plugin_config_t - Allow wdmd to getattr on tmpfs - Allow realmd to use /dev/random - allow containers to send audit messages - Allow root mount any file via loop device with enforcing mls policy - Allow tmpfiles_t to setattr on mandb_cache_t - Allow tmpfiles_t to setattr on mandb_cache_t - Make userdom_dontaudit_write_all_ not allow open - Allow init scripts to read all unit files - Add support for saphostctrl ports- Add kernel_read_system_state to sandbox_client_t - Add some of the missing access to kdumpgui - Allow systemd_dbusd_t to status the init system - Allow vmnet-natd to request the kernel to load a module - Allow gsf-office-thum to append .cache/gdm/session.log - realmd wants to read .config/dconf/user - Firewalld wants sys_nice/setsched - Allow tmpreaper to delete mandb cache files - Firewalld wants sys_nice/setsched - Allow firewalld to perform a DNS name resolution - Allown winbind to read /usr/share/samba/codepages/lowcase.dat - Add support for HTTPProxy* in /etc/freshclam.conf - Fix authlogin_yubike boolean - Extend smbd_selinux man page to include samba booleans - Allow dhcpc to execute consoletype - Allow ping to use inherited tmp files created in init scripts - On full relabel with unconfined domain disabled, initrc was running some chcon's - Allow people who delete man pages to delete mandb cache files- Add missing permissive domains- Add new mandb policy - ALlow systemd-tmpfiles_t to relabel mandb_cache_t - Allow logrotate to start all unit files- Add fixes for ctbd - Allow nmbd to stream connect to ctbd - Make cglear_t as nsswitch_domain - Fix bogus in interfaces - Allow openshift to read/write postfix public pipe - Add postfix_manage_spool_maildrop_files() interface - stickshift paths have been renamed to openshift - gnome-settings-daemon wants to write to /run/systemd/inhibit/ pipes - Update man pages, adding ENTRYPOINTS- Add mei_device_t - Make sure gpg content in homedir created with correct label - Allow dmesg to write to abrt cache files - automount wants to search virtual memory sysctls - Add support for hplip logs stored in /var/log/hp/tmp - Add labeling for /etc/owncloud/config.php - Allow setroubleshoot to send analysys to syslogd-journal - Allow virsh_t to interact with new fenced daemon - Allow gpg to write to /etc/mail/spamassassiin directories - Make dovecot_deliver_t a mail server delivery type - Add label for /var/tmp/DNS25- Fixes for tomcat_domain template interface- Remove init_systemd and init_upstart boolean, Move init_daemon_domain and init_system_domain to use attributes - Add attribute to all base os types. Allow all domains to read all ro base OS types- Additional unit files to be defined as power unit files - Fix more boolean names- Fix boolean name so subs will continue to work- dbus needs to start getty unit files - Add interface to allow system_dbusd_t to start the poweroff service - xdm wants to exec telepathy apps - Allow users to send messages to systemdlogind - Additional rules needed for systemd and other boot apps - systemd wants to list /home and /boot - Allow gkeyringd to write dbus/conf file - realmd needs to read /dev/urand - Allow readahead to delete /.readahead if labeled root_t, might get created before policy is loaded- Fixes to safe more rules - Re-write tomcat_domain_template() - Fix passenger labeling - Allow all domains to read man pages - Add ephemeral_port_t to the 'generic' port interfaces - Fix the names of postgresql booleans- Stop using attributes form netlabel_peer and syslog, auth_use_nsswitch setsup netlabel_peer - Move netlable_peer check out of booleans - Remove call to recvfrom_netlabel for kerberos call - Remove use of attributes when calling syslog call - Move -miscfiles_read_localization to domain.te to save hundreds of allow rules - Allow all domains to read locale files. This eliminates around 1500 allow rules- Cleanup nis_use_ypbind_uncond interface - Allow rndc to block suspend - tuned needs to modify the schedule of the kernel - Allow svirt_t domains to read alsa configuration files - ighten security on irc domains and make sure they label content in homedir correctly - Add filetrans_home_content for irc files - Dontaudit all getattr access for devices and filesystems for sandbox domains - Allow stapserver to search cgroups directories - Allow all postfix domains to talk to spamd- Add interfaces to ignore setattr until kernel fixes this to be checked after the DAC check - Change pam_t to pam_timestamp_t - Add dovecot_domain attribute and allow this attribute block_suspend capability2 - Add sanlock_use_fusefs boolean - numad wants send/recieve msg - Allow rhnsd to send syslog msgs - Make piranha-pulse as initrc domain - Update openshift instances to dontaudit setattr until the kernel is fixed.- Fix auth_login_pgm_domain() interface to allow domains also managed user tmp dirs because of #856880 related to pam_systemd - Remove pam_selinux.8 which conflicts with man page owned by the pam package - Allow glance-api to talk to mysql - ABRT wants to read Xorg.0.log if if it detects problem with Xorg - Fix gstreamer filename trans. interface- Man page fixes by Dan Walsh- Allow postalias to read postfix config files - Allow man2html to read man pages - Allow rhev-agentd to search all mountpoints - Allow rhsmcertd to read /dev/random - Add tgtd_stream_connect() interface - Add cyrus_write_data() interface - Dontaudit attempts by sandboxX clients connectiing to the xserver_port_t - Add port definition for tcp/81 as http_port_t - Fix /dev/twa labeling - Allow systemd to read modules config- Merge openshift policy - Allow xauth to read /dev/urandom - systemd needs to relabel content in /run/systemd directories - Files unconfined should be able to perform all services on all files - Puppet tmp file can be leaked to all domains - Dontaudit rhsmcertd-worker to search /root/.local - Allow chown capability for zarafa domains - Allow system cronjobs to runcon into openshift domains - Allow virt_bridgehelper_t to manage content in the svirt_home_t labeled directories- nmbd wants to create /var/nmbd - Stop transitioning out of anaconda and firstboot, just causes AVC messages - Allow clamscan to read /etc files - Allow bcfg2 to bind cyphesis port - heartbeat should be run as rgmanager_t instead of corosync_t - Add labeling for /etc/openldap/certs - Add labeling for /opt/sartest directory - Make crontab_t as userdom home reader - Allow tmpreaper to list admin_home dir - Add defition for imap_0 replay cache file - Add support for gitolite3 - Allow virsh_t to send syslog messages - allow domains that can read samba content to be able to list the directories also - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd - Separate out sandbox from sandboxX policy so we can disable it by default - Run dmeventd as lvm_t - Mounting on any directory requires setattr and write permissions - Fix use_nfs_home_dirs() boolean - New labels for pam_krb5 - Allow init and initrc domains to sys_ptrace since this is needed to look at processes not owned by uid 0 - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd- Separate sandbox policy into sandbox and sandboxX, and disable sandbox by default on fresh installs - Allow domains that can read etc_t to read etc_runtime_t - Allow all domains to use inherited tmpfiles- Allow realmd to read resolv.conf - Add pegasus_cache_t type - Label /usr/sbin/fence_virtd as virsh_exec_t - Add policy for pkcsslotd - Add support for cpglockd - Allow polkit-agent-helper to read system-auth-ac - telepathy-idle wants to read gschemas.compiled - Allow plymouthd to getattr on fs_t - Add slpd policy - Allow ksysguardproces to read/write config_usr_t- Fix labeling substitution so rpm will label /lib/systemd content correctly- Add file name transitions for ttyACM0 - spice-vdagent(d)'s are going to log over to syslog - Add sensord policy - Add more fixes for passenger policy related to puppet - Allow wdmd to create wdmd_tmpfs_t - Fix labeling for /var/run/cachefilesd\.pid - Add thumb_tmpfs_t files type- Allow svirt domains to manage the network since this is containerized - Allow svirt_lxc_net_t to send audit messages- Make "snmpwalk -mREDHAT-CLUSTER-MIB ...." working - Allow dlm_controld to execute dlm_stonith labeled as bin_t - Allow GFS2 working on F17 - Abrt needs to execute dmesg - Allow jockey to list the contents of modeprobe.d - Add policy for lightsquid as squid_cron_t - Mailscanner is creating files and directories in /tmp - dmesg is now reading /dev/kmsg - Allow xserver to communicate with secure_firmware - Allow fsadm tools (fsck) to read /run/mount contnet - Allow sysadm types to read /dev/kmsg -- Allow postfix, sssd, rpcd to block_suspend - udev seems to need secure_firmware capability - Allow virtd to send dbus messages to firewalld so it can configure the firewall- Fix labeling of content in /run created by virsh_t - Allow condor domains to read kernel sysctls - Allow condor_master to connect to amqp - Allow thumb drives to create shared memory and semaphores - Allow abrt to read mozilla_plugin config files - Add labels for lightsquid - Default files in /opt and /usr that end in .cgi as httpd_sys_script_t, allow - dovecot_auth_t uses ldap for user auth - Allow domains that can read dhcp_etc_t to read lnk_files - Add more then one watchdog device - Allow useradd_t to manage etc_t files so it can rename it and edit them - Fix invalid class dir should be fifo_file - Move /run/blkid to fsadm and make sure labeling is correct- Fix bogus regex found by eparis - Fix manage run interface since lvm needs more access - syslogd is searching cgroups directory - Fixes to allow virt-sandbox-service to manage lxc var run content- Fix Boolean settings - Add new libjavascriptcoregtk as textrel_shlib_t - Allow xdm_t to create xdm_home_t directories - Additional access required for systemd - Dontaudit mozilla_plugin attempts to ipc_lock - Allow tmpreaper to delete unlabeled files - Eliminate screen_tmp_t and allow it to manage user_tmp_t - Dontaudit mozilla_plugin_config_t to append to leaked file descriptors - Allow web plugins to connect to the asterisk ports - Condor will recreate the lock directory if it does not exist - Oddjob mkhomedir needs to connectto user processes - Make oddjob_mkhomedir_t a userdom home manager- Put placeholder back in place for proper numbering of capabilities - Systemd also configures init scripts- Fix ecryptfs interfaces - Bootloader seems to be trolling around /dev/shm and /dev - init wants to create /etc/systemd/system-update.target.wants - Fix systemd_filetrans call to move it out of tunable - Fix up policy to work with systemd userspace manager - Add secure_firmware capability and remove bogus epolwakeup - Call seutil_*_login_config interfaces where should be needed - Allow rhsmcertd to send signal to itself - Allow thin domains to send signal to itself - Allow Chrome_ChildIO to read dosfs_t- Add role rules for realmd, sambagui- Add new type selinux_login_config_t for /etc/selinux//logins/ - Additional fixes for seutil_manage_module_store() - dbus_system_domain() should be used with optional_policy - Fix svirt to be allowed to use fusefs file system - Allow login programs to read /run/ data created by systemd_login - sssd wants to write /etc/selinux//logins/ for SELinux PAM module - Fix svirt to be allowed to use fusefs file system - Allow piranha domain to use nsswitch - Sanlock needs to send Kill Signals to non root processes - Pulseaudio wants to execute /run/user/PID/.orc- Fix saslauthd when it tries to read /etc/shadow - Label gnome-boxes as a virt homedir - Need to allow svirt_t ability to getattr on nfs_t file systems - Update sanlock policy to solve all AVC's - Change confined users can optionally manage virt content - Handle new directories under ~/.cache - Add block suspend to appropriate domains - More rules required for containers - Allow login programs to read /run/ data created by systemd_logind - Allow staff users to run svirt_t processes- Update to upstream- More fixes for systemd to make rawhide booting from Dan Walsh- Add systemd fixes to make rawhide booting- Add systemd_logind_inhibit_var_run_t attribute - Remove corenet_all_recvfrom_unlabeled() for non-contrib policies because we moved it to domain.if for all domain_type - Add interface for mysqld to dontaudit signull to all processes - Label new /var/run/journal directory correctly - Allow users to inhibit suspend via systemd - Add new type for the /var/run/inhibit directory - Add interface to send signull to systemd_login so avahi can send them - Allow systemd_passwd to send syslog messages - Remove corenet_all_recvfrom_unlabeled() calling fro policy files - Allow editparams.cgi running as httpd_bugzilla_script_t to read /etc/group - Allow smbd to read cluster config - Add additional labeling for passenger - Allow dbus to inhibit suspend via systemd - Allow avahi to send signull to systemd_login- Add interface to dontaudit getattr access on sysctls - Allow sshd to execute /bin/login - Looks like xdm is recreating the xdm directory in ~/.cache/ on login - Allow syslog to use the leaked kernel_t unix_dgram_socket from system-jounald - Fix semanage to work with unconfined domain disabled on F18 - Dontaudit attempts by mozilla plugins to getattr on all kernel sysctls - Virt seems to be using lock files - Dovecot seems to be searching directories of every mountpoint - Allow jockey to read random/urandom, execute shell and install third-party drivers - Add aditional params to allow cachedfiles to manage its content - gpg agent needs to read /dev/random - The kernel hands an svirt domains /SYSxxxxx which is a tmpfs that httpd wants to read and write - Add a bunch of dontaudit rules to quiet svirt_lxc domains - Additional perms needed to run svirt_lxc domains - Allow cgclear to read cgconfig - Allow sys_ptrace capability for snmp - Allow freshclam to read /proc - Allow procmail to manage /home/user/Maildir content - Allow NM to execute wpa_cli - Allow amavis to read clamd system state - Regenerate man pages- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Add realmd and stapserver policies - Allow useradd to manage stap-server lib files - Tighten up capabilities for confined users - Label /etc/security/opasswd as shadow_t - Add label for /dev/ecryptfs - Allow condor_startd_t to start sshd with the ranged - Allow lpstat.cups to read fips_enabled file - Allow pyzor running as spamc_t to create /root/.pyzor directory - Add labelinf for amavisd-snmp init script - Add support for amavisd-snmp - Allow fprintd sigkill self - Allow xend (w/o libvirt) to start virtual machines - Allow aiccu to read /etc/passwd - Allow condor_startd to Make specified domain MCS trusted for setting any category set for the processes it executes - Add condor_startd_ranged_domtrans_to() interface - Add ssd_conf_t for /etc/sssd - accountsd needs to fchown some files/directories - Add ICACLient and zibrauserdata as mozilla_filetrans_home_content - SELinux reports afs_t needs dac_override to read /etc/mtab, even though everything works, adding dontaudit - Allow xend_t to read the /etc/passwd file- Until we figure out how to fix systemd issues, allow all apps that send syslog messages to send them to kernel_t - Add init_access_check() interface - Fix label on /usr/bin/pingus to not be labeled as ping_exec_t - Allow tcpdump to create a netlink_socket - Label newusers like useradd - Change xdm log files to be labeled xdm_log_t - Allow sshd_t with privsep to work in MLS - Allow freshclam to update databases thru HTTP proxy - Allow s-m-config to access check on systemd - Allow abrt to read public files by default - Fix amavis_create_pid_files() interface - Add labeling and filename transition for dbomatic.log - Allow system_dbusd_t to stream connect to bluetooth, and use its socket - Allow amavisd to execute fsav - Allow tuned to use sys_admin and sys_nice capabilities - Add php-fpm policy from Bryan - Add labeling for aeolus-configserver-thinwrapper - Allow thin domains to execute shell - Fix gnome_role_gkeyringd() interface description - Lot of interface fixes - Allow OpenMPI job running as condor_startd_ssh_t to manage condor lib files - Allow OpenMPI job to use kerberos - Make deltacloudd_t as nsswitch_domain - Allow xend_t to run lsscsi - Allow qemu-dm running as xend_t to create tun_socket - Add labeling for /opt/brother/Printers(.*/)?inf - Allow jockey-backend to read pyconfig-64.h labeled as usr_t - Fix clamscan_can_scan_system boolean - Allow lpr to connectto to /run/user/$USER/keyring-22uREb/pkcs11- initrc is calling exportfs which is not confined so it attempts to read nfsd_files - Fixes for passenger running within openshift. - Add labeling for all tomcat6 dirs - Add support for tomcat6 - Allow cobblerd to read /etc/passwd - Allow jockey to read sysfs and and execute binaries with bin_t - Allow thum to use user terminals - Allow cgclear to read cgconfig config files - Fix bcf2g.fc - Remove sysnet_dns_name_resolve() from policies where auth_use_nsswitch() is used for other domains - Allow dbomatic to execute ruby - abrt_watch_log should be abrt_domain - Allow mozilla_plugin to connect to gatekeeper port- add ptrace_child access to process - remove files_read_etc_files() calling from all policies which have auth_use_nsswith() - Allow boinc domains to manage boinc_lib_t lnk_files - Add support for boinc-client.service unit file - Add support for boinc.log - Allow mozilla_plugin execmod on mozilla home files if allow_ex - Allow dovecot_deliver_t to read dovecot_var_run_t - Allow ldconfig and insmod to manage kdumpctl tmp files - Move thin policy out from cloudform.pp and add a new thin poli - pacemaker needs to communicate with corosync streams - abrt is now started on demand by dbus - Allow certmonger to talk directly to Dogtag servers - Change labeling for /var/lib/cobbler/webui_sessions to httpd_c - Allow mozila_plugin to execute gstreamer home files - Allow useradd to delete all file types stored in the users hom - rhsmcertd reads the rpm database - Add support for lightdm- Add tomcat policy - Remove pyzor/razor policy - rhsmcertd reads the rpm database - Dontaudit thumb to setattr on xdm_tmp dir - Allow wicd to execute ldconfig in the networkmanager_t domain - Add /var/run/cherokee\.pid labeling - Allow mozilla_plugin to create mozilla_plugin_tmp_t lnk files too - Allow postfix-master to r/w pipes other postfix domains - Allow snort to create netlink_socket - Add kdumpctl policy - Allow firstboot to create tmp_t files/directories - /usr/bin/paster should not be labeled as piranha_exec_t - remove initrc_domain from tomcat - Allow ddclient to read /etc/passwd - Allow useradd to delete all file types stored in the users homedir - Allow ldconfig and insmod to manage kdumpctl tmp files - Firstboot should be just creating tmp_t dirs and xauth should be allowed to write to those - Transition xauth files within firstboot_tmp_t - Fix labeling of /run/media to match /media - Label all lxdm.log as xserver_log_t - Add port definition for mxi port - Allow local_login_t to execute tmux- apcupsd needs to read /etc/passwd - Sanlock allso sends sigkill - Allow glance_registry to connect to the mysqld port - Dontaudit mozilla_plugin trying to getattr on /dev/gpmctl - Allow firefox plugins/flash to connect to port 1234 - Allow mozilla plugins to delete user_tmp_t files - Add transition name rule for printers.conf.O - Allow virt_lxc_t to read urand - Allow systemd_loigind to list gstreamer_home_dirs - Fix labeling for /usr/bin - Fixes for cloudform services * support FIPS - Allow polipo to work as web caching - Allow chfn to execute tmux- Add support for ecryptfs * ecryptfs does not support xattr * we need labeling for HOMEDIR - Add policy for (u)mount.ecryptfs* - Fix labeling of kerbero host cache files, allow rpc.svcgssd to manage host cache - Allow dovecot to manage Maildir content, fix transitions to Maildir - Allow postfix_local to transition to dovecot_deliver - Dontaudit attempts to setattr on xdm_tmp_t, looks like bogus code - Cleanup interface definitions - Allow apmd to change with the logind daemon - Changes required for sanlock in rhel6 - Label /run/user/apache as httpd_tmp_t - Allow thumb to use lib_t as execmod if boolean turned on - Allow squid to create the squid directory in /var with the correct labe - Add a new policy for glusterd from Bryan Bickford (bbickfor@redhat.com) - Allow virtd to exec xend_exec_t without transition - Allow virtd_lxc_t to unmount all file systems- PolicyKit path has changed - Allow httpd connect to dirsrv socket - Allow tuned to write generic kernel sysctls - Dontaudit logwatch to gettr on /dev/dm-2 - Allow policykit-auth to manage kerberos files - Make condor_startd and rgmanager as initrc domain - Allow virsh to read /etc/passwd - Allow mount to mount on user_tmp_t for /run/user/dwalsh/gvfs - xdm now needs to execute xsession_exec_t - Need labels for /var/lib/gdm - Fix files_filetrans_named_content() interface - Add new attribute - initrc_domain - Allow systemd_logind_t to signal, signull, sigkill all processes - Add filetrans rules for etc_runtime files- Rename boolean names to remove allow_- Mass merge with upstream * new policy topology to include contrib policy modules * we have now two base policy patches- Fix description of authlogin_nsswitch_use_ldap - Fix transition rule for rhsmcertd_t needed for RHEL7 - Allow useradd to list nfs state data - Allow openvpn to manage its log file and directory - We want vdsm to transition to mount_t when executing mount command to make sure /etc/mtab remains labeled correctly - Allow thumb to use nvidia devices - Allow local_login to create user_tmp_t files for kerberos - Pulseaudio needs to read systemd_login /var/run content - virt should only transition named system_conf_t config files - Allow munin to execute its plugins - Allow nagios system plugin to read /etc/passwd - Allow plugin to connect to soundd port - Fix httpd_passwd to be able to ask passwords - Radius servers can use ldap for backing store - Seems to need to mount on /var/lib for xguest polyinstatiation to work. - Allow systemd_logind to list the contents of gnome keyring - VirtualGL need xdm to be able to manage content in /etc/opt/VirtualGL - Add policy for isns-utils- Add policy for subversion daemon - Allow boinc to read passwd - Allow pads to read kernel network state - Fix man2html interface for sepolgen-ifgen - Remove extra /usr/lib/systemd/system/smb - Remove all /lib/systemd and replace with /usr/lib/systemd - Add policy for man2html - Fix the label of kerberos_home_t to krb5_home_t - Allow mozilla plugins to use Citrix - Allow tuned to read /proc/sys/kernel/nmi_watchdog - Allow tune /sys options via systemd's tmpfiles.d "w" type- Dontaudit lpr_t to read/write leaked mozilla tmp files - Add file name transition for .grl-podcasts directory - Allow corosync to read user tmp files - Allow fenced to create snmp lib dirs/files - More fixes for sge policy - Allow mozilla_plugin_t to execute any application - Allow dbus to read/write any open file descriptors to any non security file on the system that it inherits to that it can pass them to another domain - Allow mongod to read system state information - Fix wrong type, we should dontaudit sys_admin for xdm_t not xserver_t - Allow polipo to manage polipo_cache dirs - Add jabbar_client port to mozilla_plugin_t - Cleanup procmail policy - system bus will pass around open file descriptors on files that do not have labels on them - Allow l2tpd_t to read system state - Allow tuned to run ls /dev - Allow sudo domains to read usr_t files - Add label to machine-id - Fix corecmd_read_bin_symlinks cut and paste error- Fix pulseaudio port definition - Add labeling for condor_starter - Allow chfn_t to creat user_tmp_files - Allow chfn_t to execute bin_t - Allow prelink_cron_system_t to getpw calls - Allow sudo domains to manage kerberos rcache files - Allow user_mail_domains to work with courie - Port definitions necessary for running jboss apps within openshift - Add support for openstack-nova-metadata-api - Add support for nova-console* - Add support for openstack-nova-xvpvncproxy - Fixes to make privsep+SELinux working if we try to use chage to change passwd - Fix auth_role() interface - Allow numad to read sysfs - Allow matahari-rpcd to execute shell - Add label for ~/.spicec - xdm is executing lspci as root which is requesting a sys_admin priv but seems to succeed without it - Devicekit_disk wants to read the logind sessions file when writing a cd - Add fixes for condor to make condor jobs working correctly - Change label of /var/log/rpmpkgs to cron_log_t - Access requires to allow systemd-tmpfiles --create to work. - Fix obex to be a user application started by the session bus. - Add additional filename trans rules for kerberos - Fix /var/run/heartbeat labeling - Allow apps that are managing rcache to file trans correctly - Allow openvpn to authenticate against ldap server - Containers need to listen to network starting and stopping events- Make systemd unit files less specific- Fix zarafa labeling - Allow guest_t to fix labeling - corenet_tcp_bind_all_unreserved_ports(ssh_t) should be called with the user_tcp_server boolean - add lxc_contexts - Allow accountsd to read /proc - Allow restorecond to getattr on all file sytems - tmpwatch now calls getpw - Allow apache daemon to transition to pwauth domain - Label content under /var/run/user/NAME/keyring* as gkeyringd_tmp_t - The obex socket seems to be a stream socket - dd label for /var/run/nologin- Allow jetty running as httpd_t to read hugetlbfs files - Allow sys_nice and setsched for rhsmcertd - Dontaudit attempts by mozilla_plugin_t to bind to ssdp ports - Allow setfiles to append to xdm_tmp_t - Add labeling for /export as a usr_t directory - Add labels for .grl files created by gstreamer- Add labeling for /usr/share/jetty/bin/jetty.sh - Add jetty policy which contains file type definitios - Allow jockey to use its own fifo_file and make this the default for all domains - Allow mozilla_plugins to use spice (vnc_port/couchdb) - asterisk wants to read the network state - Blueman now uses /var/lib/blueman- Add label for nodejs_debug - Allow mozilla_plugin_t to create ~/.pki directory and content- Add clamscan_can_scan_system boolean - Allow mysqld to read kernel network state - Allow sshd to read/write condor lib files - Allow sshd to read/write condor-startd tcp socket - Fix description on httpd_graceful_shutdown - Allow glance_registry to communicate with mysql - dbus_system_domain is using systemd to lauch applications - add interfaces to allow domains to send kill signals to user mail agents - Remove unnessary access for svirt_lxc domains, add privs for virtd_lxc_t - Lots of new access required for secure containers - Corosync needs sys_admin capability - ALlow colord to create shm - .orc should be allowed to be created by any app that can create gstream home content, thumb_t to be specific - Add boolean to control whether or not mozilla plugins can create random content in the users homedir - Add new interface to allow domains to list msyql_db directories, needed for libra - shutdown has to be allowed to delete etc_runtime_t - Fail2ban needs to read /etc/passwd - Allow ldconfig to create /var/cache/ldconfig - Allow tgtd to read hardware state information - Allow collectd to create packet socket - Allow chronyd to send signal to itself - Allow collectd to read /dev/random - Allow collectd to send signal to itself - firewalld needs to execute restorecon - Allow restorecon and other login domains to execute restorecon- Allow logrotate to getattr on systemd unit files - Add support for tor systemd unit file - Allow apmd to create /var/run/pm-utils with the correct label - Allow l2tpd to send sigkill to pppd - Allow pppd to stream connect to l2tpd - Add label for scripts in /etc/gdm/ - Allow systemd_logind_t to ignore mcs constraints on sigkill - Fix files_filetrans_system_conf_named_files() interface - Add labels for /usr/share/wordpress/wp-includes/*.php - Allow cobbler to get SELinux mode and booleans- Add unconfined_execmem_exec_t as an alias to bin_t - Allow fenced to read snmp var lib files, also allow it to read usr_t - ontaudit access checks on all executables from mozilla_plugin - Allow all user domains to setexec, so that sshd will work properly if it call setexec(NULL) while running withing a user mode - Allow systemd_tmpfiles_t to getattr all pipes and sockets - Allow glance-registry to send system log messages - semanage needs to manage mock lib files/dirs- Add policy for abrt-watch-log - Add definitions for jboss_messaging ports - Allow systemd_tmpfiles to manage printer devices - Allow oddjob to use nsswitch - Fix labeling of log files for postgresql - Allow mozilla_plugin_t to execmem and execstack by default - Allow firewalld to execute shell - Fix /etc/wicd content files to get created with the correct label - Allow mcelog to exec shell - Add ~/.orc as a gstreamer_home_t - /var/spool/postfix/lib64 should be labeled lib_t - mpreaper should be able to list all file system labeled directories - Add support for apache to use openstack - Add labeling for /etc/zipl.conf and zipl binary - Turn on allow_execstack and turn off telepathy transition for final release- More access required for virt_qmf_t - Additional assess required for systemd-logind to support multi-seat - Allow mozilla_plugin to setrlimit - Revert changes to fuse file system to stop deadlock- Allow condor domains to connect to ephemeral ports - More fixes for condor policy - Allow keystone to stream connect to mysqld - Allow mozilla_plugin_t to read generic USB device to support GPS devices - Allow thum to file name transition gstreamer home content - Allow thum to read all non security files - Allow glance_api_t to connect to ephemeral ports - Allow nagios plugins to read /dev/urandom - Allow syslogd to search postfix spool to support postfix chroot env - Fix labeling for /var/spool/postfix/dev - Allow wdmd chown - Label .esd_auth as pulseaudio_home_t - Have no idea why keyring tries to write to /run/user/dwalsh/dconf/user, but we can dontaudit for now- Add support for clamd+systemd - Allow fresclam to execute systemctl to handle clamd - Change labeling for /usr/sbin/rpc.ypasswd.env - Allow yppaswd_t to execute yppaswd_exec_t - Allow yppaswd_t to read /etc/passwd - Gnomekeyring socket has been moved to /run/user/USER/ - Allow samba-net to connect to ldap port - Allow signal for vhostmd - allow mozilla_plugin_t to read user_home_t socket - New access required for secure Linux Containers - zfs now supports xattrs - Allow quantum to execute sudo and list sysfs - Allow init to dbus chat with the firewalld - Allow zebra to read /etc/passwd- Allow svirt_t to create content in the users homedir under ~/.libvirt - Fix label on /var/lib/heartbeat - Allow systemd_logind_t to send kill signals to all processes started by a user - Fuse now supports Xattr Support- upowered needs to setsched on the kernel - Allow mpd_t to manage log files - Allow xdm_t to create /var/run/systemd/multi-session-x - Add rules for missedfont.log to be used by thumb.fc - Additional access required for virt_qmf_t - Allow dhclient to dbus chat with the firewalld - Add label for lvmetad - Allow systemd_logind_t to remove userdomain sock_files - Allow cups to execute usr_t files - Fix labeling on nvidia shared libraries - wdmd_t needs access to sssd and /etc/passwd - Add boolean to allow ftp servers to run in passive mode - Allow namepspace_init_t to relabelto/from a different user system_u from the user the namespace_init running with - Fix using httpd_use_fusefs - Allow chrome_sandbox_nacl to write inherited user tmp files as we allow it for chrome_sandbox- Rename rdate port to time port, and allow gnomeclock to connect to it - We no longer need to transition to ldconfig from rpm, rpm_script, or anaconda - /etc/auto.* should be labeled bin_t - Add httpd_use_fusefs boolean - Add fixes for heartbeat - Allow sshd_t to signal processes that it transitions to - Add condor policy - Allow svirt to create monitors in ~/.libvirt - Allow dovecot to domtrans sendmail to handle sieve scripts - Lot of fixes for cfengine- /var/run/postmaster.* labeling is no longer needed - Alllow drbdadmin to read /dev/urandom - l2tpd_t seems to use ptmx - group+ and passwd+ should be labeled as /etc/passwd - Zarafa-indexer is a socket- Ensure lastlog is labeled correctly - Allow accountsd to read /proc data about gdm - Add fixes for tuned - Add bcfg2 fixes which were discovered during RHEL6 testing - More fixes for gnome-keyring socket being moved - Run semanage as a unconfined domain, and allow initrc_t to create tmpfs_t sym links on shutdown - Fix description for files_dontaudit_read_security_files() interface- Add new policy and man page for bcfg2 - cgconfig needs to use getpw calls - Allow domains that communicate with the keyring to use cache_home_t instead of gkeyringd_tmpt - gnome-keyring wants to create a directory in cache_home_t - sanlock calls getpw- Add numad policy and numad man page - Add fixes for interface bugs discovered by SEWatch - Add /tmp support for squid - Add fix for #799102 * change default labeling for /var/run/slapd.* sockets - Make thumb_t as userdom_home_reader - label /var/lib/sss/mc same as pubconf, so getpw domains can read it - Allow smbspool running as cups_t to stream connect to nmbd - accounts needs to be able to execute passwd on behalf of users - Allow systemd_tmpfiles_t to delete boot flags - Allow dnssec_trigger to connect to apache ports - Allow gnome keyring to create sock_files in ~/.cache - google_authenticator is using .google_authenticator - sandbox running from within firefox is exposing more leaks - Dontaudit thumb to read/write /dev/card0 - Dontaudit getattr on init_exec_t for gnomeclock_t - Allow certmonger to do a transition to certmonger_unconfined_t - Allow dhcpc setsched which is caused by nmcli - Add rpm_exec_t for /usr/sbin/bcfg2 - system cronjobs are sending dbus messages to systemd_logind - Thumnailers read /dev/urand- Allow auditctl getcap - Allow vdagent to use libsystemd-login - Allow abrt-dump-oops to search /etc/abrt - Got these avc's while trying to print a boarding pass from firefox - Devicekit is now putting the media directory under /run/media - Allow thumbnailers to create content in ~/.thumbails directory - Add support for proL2TPd by Dominick Grift - Allow all domains to call getcap - wdmd seems to get a random chown capability check that it does not need - Allow vhostmd to read kernel sysctls- Allow chronyd to read unix - Allow hpfax to read /etc/passwd - Add support matahari vios-proxy-* apps and add virtd_exec_t label for them - Allow rpcd to read quota_db_t - Update to man pages to match latest policy - Fix bug in jockey interface for sepolgen-ifgen - Add initial svirt_prot_exec_t policy- More fixes for systemd from Dan Walsh- Add a new type for /etc/firewalld and allow firewalld to write to this directory - Add definition for ~/Maildir, and allow mail deliver domains to write there - Allow polipo to run from a cron job - Allow rtkit to schedule wine processes - Allow mozilla_plugin_t to acquire a bug, and allow it to transition gnome content in the home dir to the proper label - Allow users domains to send signals to consolehelper domains- More fixes for boinc policy - Allow polipo domain to create its own cache dir and pid file - Add systemctl support to httpd domain - Add systemctl support to polipo, allow NetworkManager to manage the service - Add policy for jockey-backend - Add support for motion daemon which is now covered by zoneminder policy - Allow colord to read/write motion tmpfs - Allow vnstat to search through var_lib_t directories - Stop transitioning to quota_t, from init an sysadm_t- Add svirt_lxc_file_t as a customizable type- Add additional fixes for icmp nagios plugin - Allow cron jobs to open fifo_files from cron, since service script opens /dev/stdin - Add certmonger_unconfined_exec_t - Make sure tap22 device is created with the correct label - Allow staff users to read systemd unit files - Merge in previously built policy - Arpwatch needs to be able to start netlink sockets in order to start - Allow cgred_t to sys_ptrace to look at other DAC Processes- Back port some of the access that was allowed in nsplugin_t - Add definitiona for couchdb ports - Allow nagios to use inherited users ttys - Add git support for mock - Allow inetd to use rdate port - Add own type for rdate port - Allow samba to act as a portmapper - Dontaudit chrome_sandbox attempts to getattr on chr_files in /dev - New fixes needed for samba4 - Allow apps that use lib_t to read lib_t symlinks- Add policy for nove-cert - Add labeling for nova-openstack systemd unit files - Add policy for keystoke- Fix man pages fro domains - Add man pages for SELinux users and roles - Add storage_dev_filetrans_named_fixed_disk() and use it for smartmon - Add policy for matahari-rpcd - nfsd executes mount command on restart - Matahari domains execute renice and setsched - Dontaudit leaked tty in mozilla_plugin_config - mailman is changing to a per instance naming - Add 7600 and 4447 as jboss_management ports - Add fixes for nagios event handlers - Label httpd.event as httpd_exec_t, it is an apache daemon- Add labeling for /var/spool/postfix/dev/log - NM reads sysctl.conf - Iscsi log file context specification fix - Allow mozilla plugins to send dbus messages to user domains that transition to it - Allow mysql to read the passwd file - Allow mozilla_plugin_t to create mozilla home dirs in user homedir - Allow deltacloud to read kernel sysctl - Allow postgresql_t to connectto itselfAllow postgresql_t to connectto itself - Allow postgresql_t to connectto itself - Add login_userdomain attribute for users which can log in using terminal- Allow sysadm_u to reach system_r by default #784011 - Allow nagios plugins to use inherited user terminals - Razor labeling is not used no longer - Add systemd support for matahari - Add port_types to man page, move booleans to the top, fix some english - Add support for matahari-sysconfig-console - Clean up matahari.fc - Fix matahari_admin() interfac - Add labels for/etc/ssh/ssh_host_*.pub keys- Allow ksysguardproces to send system log msgs - Allow boinc setpgid and signull - Allow xdm_t to sys_ptrace to run pidof command - Allow smtpd_t to manage spool files/directories and symbolic links - Add labeling for jetty - Needed changes to get unbound/dnssec to work with openswan- Add user_fonts_t alias xfs_tmp_t - Since depmod now runs as insmod_t we need to write to kernel_object_t - Allow firewalld to dbus chat with networkmanager - Allow qpidd to connect to matahari ports - policykit needs to read /proc for uses not owned by it - Allow systemctl apps to connecto the init stream- Turn on deny_ptrace boolean- Remove pam_selinux.8 man page. There was a conflict.- Add proxy class and read access for gssd_proxy - Separate out the sharing public content booleans - Allow certmonger to execute a script and send signals to apache and dirsrv to reload the certificate - Add label transition for gstream-0.10 and 12 - Add booleans to allow rsync to share nfs and cifs file sytems - chrome_sandbox wants to read the /proc/PID/exe file of the program that executed it - Fix filename transitions for cups files - Allow denyhosts to read "unix" - Add file name transition for locale.conf.new - Allow boinc projects to gconf config files - sssd needs to be able to increase the socket limit under certain loads - sge_execd needs to read /etc/passwd - Allow denyhost to check network state - NetworkManager needs to read sessions data - Allow denyhost to check network state - Allow xen to search virt images directories - Add label for /dev/megaraid_sas_ioctl_node - Add autogenerated man pages- Allow boinc project to getattr on fs - Allow init to execute initrc_state_t - rhev-agent package was rename to ovirt-guest-agent - If initrc_t creates /etc/local.conf then we need to make sure it is labeled correctly - sytemd writes content to /run/initramfs and executes it on shutdown - kdump_t needs to read /etc/mtab, should be back ported to F16 - udev needs to load kernel modules in early system boot- Need to add sys_ptrace back in since reading any content in /proc can cause these accesses - Add additional systemd interfaces which are needed fro *_admin interfaces - Fix bind_admin() interface- Allow firewalld to read urand - Alias java, execmem_mono to bin_t to allow third parties - Add label for kmod - /etc/redhat-lsb contains binaries - Add boolean to allow gitosis to send mail - Add filename transition also for "event20" - Allow systemd_tmpfiles_t to delete all file types - Allow collectd to ipc_lock- make consoletype_exec optional, so we can remove consoletype policy - remove unconfined_permisive.patch - Allow openvpn_t to inherit user home content and tmp content - Fix dnssec-trigger labeling - Turn on obex policy for staff_t - Pem files should not be secret - Add lots of rules to fix AVC's when playing with containers - Fix policy for dnssec - Label ask-passwd directories correctly for systemd- sshd fixes seem to be causing unconfined domains to dyntrans to themselves - fuse file system is now being mounted in /run/user - systemd_logind is sending signals to processes that are dbus messaging with it - Add support for winshadow port and allow iscsid to connect to this port - httpd should be allowed to bind to the http_port_t udp socket - zarafa_var_lib_t can be a lnk_file - A couple of new .xsession-errors files - Seems like user space and login programs need to read logind_sessions_files - Devicekit disk seems to be being launched by systemd - Cleanup handling of setfiles so most of rules in te file - Correct port number for dnssec - logcheck has the home dir set to its cache- Add policy for grindengine MPI jobs- Add new sysadm_secadm.pp module * contains secadm definition for sysadm_t - Move user_mail_domain access out of the interface into the te file - Allow httpd_t to create httpd_var_lib_t directories as well as files - Allow snmpd to connect to the ricci_modcluster stream - Allow firewalld to read /etc/passwd - Add auth_use_nsswitch for colord - Allow smartd to read network state - smartdnotify needs to read /etc/group- Allow gpg and gpg_agent to store sock_file in gpg_secret_t directory - lxdm startup scripts should be labeled bin_t, so confined users will work - mcstransd now creates a pid, needs back port to F16 - qpidd should be allowed to connect to the amqp port - Label devices 010-029 as usb devices - ypserv packager says ypserv does not use tmp_t so removing selinux policy types - Remove all ptrace commands that I believe are caused by the kernel/ps avcs - Add initial Obex policy - Add logging_syslogd_use_tty boolean - Add polipo_connect_all_unreserved bolean - Allow zabbix to connect to ftp port - Allow systemd-logind to be able to switch VTs - Allow apache to communicate with memcached through a sock_file- Fix file_context.subs_dist for now to work with pre usrmove- More /usr move fixes- Add zabbix_can_network boolean - Add httpd_can_connect_zabbix boolean - Prepare file context labeling for usrmove functions - Allow system cronjobs to read kernel network state - Add support for selinux_avcstat munin plugin - Treat hearbeat with corosync policy - Allow corosync to read and write to qpidd shared mem - mozilla_plugin is trying to run pulseaudio - Fixes for new sshd patch for running priv sep domains as the users context - Turn off dontaudit rules when turning on allow_ypbind - udev now reads /etc/modules.d directory- Turn on deny_ptrace boolean for the Rawhide run, so we can test this out - Cups exchanges dbus messages with init - udisk2 needs to send syslog messages - certwatch needs to read /etc/passwd- Add labeling for udisks2 - Allow fsadmin to communicate with the systemd process- Treat Bip with bitlbee policy * Bip is an IRC proxy - Add port definition for interwise port - Add support for ipa_memcached socket - systemd_jounald needs to getattr on all processes - mdadmin fixes * uses getpw - amavisd calls getpwnam() - denyhosts calls getpwall()- Setup labeling of /var/rsa and /var/lib/rsa to allow login programs to write there - bluetooth says they do not use /tmp and want to remove the type - Allow init to transition to colord - Mongod needs to read /proc/sys/vm/zone_reclaim_mode - Allow postfix_smtpd_t to connect to spamd - Add boolean to allow ftp to connect to all ports > 1023 - Allow sendmain to write to inherited dovecot tmp files - setroubleshoot needs to be able to execute rpm to see what version of packages- Merge systemd patch - systemd-tmpfiles wants to relabel /sys/devices/system/cpu/online - Allow deltacloudd dac_override, setuid, setgid caps - Allow aisexec to execute shell - Add use_nfs_home_dirs boolean for ssh-keygen- Fixes to make rawhide boot in enforcing mode with latest systemd changes- Add labeling for /var/run/systemd/journal/syslog - libvirt sends signals to ifconfig - Allow domains that read logind session files to list them- Fixed destined form libvirt-sandbox - Allow apps that list sysfs to also read sympolicy links in this filesystem - Add ubac_constrained rules for chrome_sandbox - Need interface to allow domains to use tmpfs_t files created by the kernel, used by libra - Allow postgresql to be executed by the caller - Standardize interfaces of daemons - Add new labeling for mm-handler - Allow all matahari domains to read network state and etc_runtime_t files- New fix for seunshare, requires seunshare_domains to be able to mounton / - Allow systemctl running as logrotate_t to connect to private systemd socket - Allow tmpwatch to read meminfo - Allow rpc.svcgssd to read supported_krb5_enctype - Allow zarafa domains to read /dev/random and /dev/urandom - Allow snmpd to read dev_snmp6 - Allow procmail to talk with cyrus - Add fixes for check_disk and check_nagios plugins- default trans rules for Rawhide policy - Make sure sound_devices controlC* are labeled correctly on creation - sssd now needs sys_admin - Allow snmp to read all proc_type - Allow to setup users homedir with quota.group- Add httpd_can_connect_ldap() interface - apcupsd_t needs to use seriel ports connected to usb devices - Kde puts procmail mail directory under ~/.local/share - nfsd_t can trigger sys_rawio on tests that involve too many mountpoints, dontaudit for now - Add labeling for /sbin/iscsiuio- Add label for /var/lib/iscan/interpreter - Dont audit writes to leaked file descriptors or redirected output for nacl - NetworkManager needs to write to /sys/class/net/ib*/mode- Allow abrt to request the kernel to load a module - Make sure mozilla content is labeled correctly - Allow tgtd to read system state - More fixes for boinc * allow to resolve dns name * re-write boinc policy to use boinc_domain attribute - Allow munin services plugins to use NSCD services- Allow mozilla_plugin_t to manage mozilla_home_t - Allow ssh derived domain to execute ssh-keygen in the ssh_keygen_t domain - Add label for tumblerd- Fixes for xguest package- Fixes related to /bin, /sbin - Allow abrt to getattr on blk files - Add type for rhev-agent log file - Fix labeling for /dev/dmfm - Dontaudit wicd leaking - Allow systemd_logind_t to look at process info of apps that exchange dbus messages with it - Label /etc/locale.conf correctly - Allow user_mail_t to read /dev/random - Allow postfix-smtpd to read MIMEDefang - Add label for /var/log/suphp.log - Allow swat_t to connect and read/write nmbd_t sock_file - Allow systemd-tmpfiles to setattr for /run/user/gdm/dconf - Allow systemd-tmpfiles to change user identity in object contexts - More fixes for rhev_agentd_t consolehelper policy- Use fs_use_xattr for squashf - Fix procs_type interface - Dovecot has a new fifo_file /var/run/dovecot/stats-mail - Dovecot has a new fifo_file /var/run/stats-mail - Colord does not need to connect to network - Allow system_cronjob to dbus chat with NetworkManager - Puppet manages content, want to make sure it labels everything correctly- Change port 9050 to tor_socks_port_t and then allow openvpn to connect to it - Allow all postfix domains to use the fifo_file - Allow sshd_t to getattr on all file systems in order to generate avc on nfs_t - Allow apmd_t to read grub.cfg - Let firewallgui read the selinux config - Allow systemd-tmpfiles to delete content in /root that has been moved to /tmp - Fix devicekit_manage_pid_files() interface - Allow squid to check the network state - Dontaudit colord getattr on file systems - Allow ping domains to read zabbix_tmp_t files- Allow mcelog_t to create dir and file in /var/run and label it correctly - Allow dbus to manage fusefs - Mount needs to read process state when mounting gluster file systems - Allow collectd-web to read collectd lib files - Allow daemons and system processes started by init to read/write the unix_stream_socket passed in from as stdin/stdout/stderr - Allow colord to get the attributes of tmpfs filesystem - Add sanlock_use_nfs and sanlock_use_samba booleans - Add bin_t label for /usr/lib/virtualbox/VBoxManage- Add ssh_dontaudit_search_home_dir - Changes to allow namespace_init_t to work - Add interface to allow exec of mongod, add port definition for mongod port, 27017 - Label .kde/share/apps/networkmanagement/certificates/ as home_cert_t - Allow spamd and clamd to steam connect to each other - Add policy label for passwd.OLD - More fixes for postfix and postfix maildro - Add ftp support for mozilla plugins - Useradd now needs to manage policy since it calls libsemanage - Fix devicekit_manage_log_files() interface - Allow colord to execute ifconfig - Allow accountsd to read /sys - Allow mysqld-safe to execute shell - Allow openct to stream connect to pcscd - Add label for /var/run/nm-dns-dnsmasq\.conf - Allow networkmanager to chat with virtd_t- Pulseaudio changes - Merge patches- Merge patches back into git repository.- Remove allow_execmem boolean and replace with deny_execmem boolean- Turn back on allow_execmem boolean- Add more MCS fixes to make sandbox working - Make faillog MLS trusted to make sudo_$1_t working - Allow sandbox_web_client_t to read passwd_file_t - Add .mailrc file context - Remove execheap from openoffice domain - Allow chrome_sandbox_nacl_t to read cpu_info - Allow virtd to relabel generic usb which is need if USB device - Fixes for virt.if interfaces to consider chr_file as image file type- Remove Open Office policy - Remove execmem policy- MCS fixes - quota fixes- Remove transitions to consoletype- Make nvidia* to be labeled correctly - Fix abrt_manage_cache() interface - Make filetrans rules optional so base policy will build - Dontaudit chkpwd_t access to inherited TTYS - Make sure postfix content gets created with the correct label - Allow gnomeclock to read cgroup - Fixes for cloudform policy- Check in fixed for Chrome nacl support- Begin removing qemu_t domain, we really no longer need this domain. - systemd_passwd needs dac_overide to communicate with users TTY's - Allow svirt_lxc domains to send kill signals within their container- Remove qemu.pp again without causing a crash- Remove qemu.pp, everything should use svirt_t or stay in its current domain- Allow policykit to talk to the systemd via dbus - Move chrome_sandbox_nacl_t to permissive domains - Additional rules for chrome_sandbox_nacl- Change bootstrap name to nacl - Chrome still needs execmem - Missing role for chrome_sandbox_bootstrap - Add boolean to remove execmem and execstack from virtual machines - Dontaudit xdm_t doing an access_check on etc_t directories- Allow named to connect to dirsrv by default - add ldapmap1_0 as a krb5_host_rcache_t file - Google chrome developers asked me to add bootstrap policy for nacl stuff - Allow rhev_agentd_t to getattr on mountpoints - Postfix_smtpd_t needs access to milters and cleanup seems to read/write postfix_smtpd_t unix_stream_sockets- Fixes for cloudform policies which need to connect to random ports - Make sure if an admin creates modules content it creates them with the correct label - Add port 8953 as a dns port used by unbound - Fix file name transition for alsa and confined users- Turn on mock_t and thumb_t for unconfined domains- Policy update should not modify local contexts- Remove ada policy- Remove tzdata policy - Add labeling for udev - Add cloudform policy - Fixes for bootloader policy- Add policies for nova openstack- Add fixes for nova-stack policy- Allow svirt_lxc_domain to chr_file and blk_file devices if they are in the domain - Allow init process to setrlimit on itself - Take away transition rules for users executing ssh-keygen - Allow setroubleshoot_fixit_t to read /dev/urand - Allow sshd to relbale tunnel sockets - Allow fail2ban domtrans to shorewall in the same way as with iptables - Add support for lnk files in the /var/lib/sssd directory - Allow system mail to connect to courier-authdaemon over an unix stream socket- Add passwd_file_t for /etc/ptmptmp- Dontaudit access checks for all executables, gnome-shell is doing access(EXEC, X_OK) - Make corosync to be able to relabelto cluster lib fies - Allow samba domains to search /var/run/nmbd - Allow dirsrv to use pam - Allow thumb to call getuid - chrome less likely to get mmap_zero bug so removing dontaudit - gimp help-browser has built in javascript - Best guess is that devices named /dev/bsr4096 should be labeled as cpu_device_t - Re-write glance policy- Move dontaudit sys_ptrace line from permissive.te to domain.te - Remove policy for hal, it no longer exists- Don't check md5 size or mtime on certain config files- Remove allow_ptrace and replace it with deny_ptrace, which will remove all ptrace from the system - Remove 2000 dontaudit rules between confined domains on transition and replace with single dontaudit domain domain:process { noatsecure siginh rlimitinh } ;- Fixes for bootloader policy - $1_gkeyringd_t needs to read $HOME/%USER/.local/share/keystore - Allow nsplugin to read /usr/share/config - Allow sa-update to update rules - Add use_fusefs_home_dirs for chroot ssh option - Fixes for grub2 - Update systemd_exec_systemctl() interface - Allow gpg to read the mail spool - More fixes for sa-update running out of cron job - Allow ipsec_mgmt_t to read hardware state information - Allow pptp_t to connect to unreserved_port_t - Dontaudit getattr on initctl in /dev from chfn - Dontaudit getattr on kernel_core from chfn - Add systemd_list_unit_dirs to systemd_exec_systemctl call - Fixes for collectd policy - CHange sysadm_t to create content as user_tmp_t under /tmp- Shrink size of policy through use of attributes for userdomain and apache- Allow virsh to read xenstored pid file - Backport corenetwork fixes from upstream - Do not audit attempts by thumb to search config_home_t dirs (~/.config) - label ~/.cache/telepathy/logger telepathy_logger_cache_home_t - allow thumb to read generic data home files (mime.type)- Allow nmbd to manage sock file in /var/run/nmbd - ricci_modservice send syslog msgs - Stop transitioning from unconfined_t to ldconfig_t, but make sure /etc/ld.so.cache is labeled correctly - Allow systemd_logind_t to manage /run/USER/dconf/user- Fix missing patch from F16- Allow logrotate setuid and setgid since logrotate is supposed to do it - Fixes for thumb policy by grift - Add new nfsd ports - Added fix to allow confined apps to execmod on chrome - Add labeling for additional vdsm directories - Allow Exim and Dovecot SASL - Add label for /var/run/nmbd - Add fixes to make virsh and xen working together - Colord executes ls - /var/spool/cron is now labeled as user_cron_spool_t- Stop complaining about leaked file descriptors during install- Remove java and mono module and merge into execmem- Fixes for thumb policy and passwd_file_t- Fixes caused by the labeling of /etc/passwd - Add thumb.patch to transition unconfined_t to thumb_t for Rawhide- Add support for Clustered Samba commands - Allow ricci_modrpm_t to send log msgs - move permissive virt_qmf_t from virt.te to permissivedomains.te - Allow ssh_t to use kernel keyrings - Add policy for libvirt-qmf and more fixes for linux containers - Initial Polipo - Sanlock needs to run ranged in order to kill svirt processes - Allow smbcontrol to stream connect to ctdbd- Add label for /etc/passwd- Change unconfined_domains to permissive for Rawhide - Add definition for the ephemeral_ports- Make mta_role() active - Allow asterisk to connect to jabber client port - Allow procmail to read utmp - Add NIS support for systemd_logind_t - Allow systemd_logind_t to manage /run/user/$USER/dconf dir which is labeled as config_home_t - Fix systemd_manage_unit_dirs() interface - Allow ssh_t to manage directories passed into it - init needs to be able to create and delete unit file directories - Fix typo in apache_exec_sys_script - Add ability for logrotate to transition to awstat domain- Change screen to use screen_domain attribute and allow screen_domains to read all process domain state - Add SELinux support for ssh pre-auth net process in F17 - Add logging_syslogd_can_sendmail boolean- Add definition for ephemeral ports - Define user_tty_device_t as a customizable_type- Needs to require a new version of checkpolicy - Interface fixes- Allow sanlock to manage virt lib files - Add virt_use_sanlock booelan - ksmtuned is trying to resolve uids - Make sure .gvfs is labeled user_home_t in the users home directory - Sanlock sends kill signals and needs the kill capability - Allow mockbuild to work on nfs homedirs - Fix kerberos_manage_host_rcache() interface - Allow exim to read system state- Allow systemd-tmpfiles to set the correct labels on /var/run, /tmp and other files - We want any file type that is created in /tmp by a process running as initrc_t to be labeled initrc_tmp_t- Allow collectd to read hardware state information - Add loop_control_device_t - Allow mdadm to request kernel to load module - Allow domains that start other domains via systemctl to search unit dir - systemd_tmpfilses, needs to list any file systems mounted on /tmp - No one can explain why radius is listing the contents of /tmp, so we will dontaudit - If I can manage etc_runtime files, I should be able to read the links - Dontaudit hostname writing to mock library chr_files - Have gdm_t setup labeling correctly in users home dir - Label content unde /var/run/user/NAME/dconf as config_home_t - Allow sa-update to execute shell - Make ssh-keygen working with fips_enabled - Make mock work for staff_t user - Tighten security on mock_t- removing unconfined_notrans_t no longer necessary - Clean up handling of secure_mode_insmod and secure_mode_policyload - Remove unconfined_mount_t- Add exim_exec_t label for /usr/sbin/exim_tidydb - Call init_dontaudit_rw_stream_socket() interface in mta policy - sssd need to search /var/cache/krb5rcache directory - Allow corosync to relabel own tmp files - Allow zarafa domains to send system log messages - Allow ssh to do tunneling - Allow initrc scripts to sendto init_t unix_stream_socket - Changes to make sure dmsmasq and virt directories are labeled correctly - Changes needed to allow sysadm_t to manage systemd unit files - init is passing file descriptors to dbus and on to system daemons - Allow sulogin additional access Reported by dgrift and Jeremy Miller - Steve Grubb believes that wireshark does not need this access - Fix /var/run/initramfs to stop restorecon from looking at - pki needs another port - Add more labels for cluster scripts - Allow apps that manage cgroup_files to manage cgroup link files - Fix label on nfs-utils scripts directories - Allow gatherd to read /dev/rand and /dev/urand- pki needs another port - Add more labels for cluster scripts - Fix label on nfs-utils scripts directories - Fixes for cluster - Allow gatherd to read /dev/rand and /dev/urand - abrt leaks fifo files- Add glance policy - Allow mdadm setsched - /var/run/initramfs should not be relabeled with a restorecon run - memcache can be setup to override sys_resource - Allow httpd_t to read tetex data - Allow systemd_tmpfiles to delete kernel modules left in /tmp directory.- Allow Postfix to deliver to Dovecot LMTP socket - Ignore bogus sys_module for lldpad - Allow chrony and gpsd to send dgrams, gpsd needs to write to the real time clock - systemd_logind_t sets the attributes on usb devices - Allow hddtemp_t to read etc_t files - Add permissivedomains module - Move all permissive domains calls to permissivedomain.te - Allow pegasis to send kill signals to other UIDs- Allow insmod_t to use fds leaked from devicekit - dontaudit getattr between insmod_t and init_t unix_stream_sockets - Change sysctl unit file interfaces to use systemctl - Add support for chronyd unit file - Allow mozilla_plugin to read gnome_usr_config - Add policy for new gpsd - Allow cups to create kerberos rhost cache files - Add authlogin_filetrans_named_content, to unconfined_t to make sure shadow and other log files get labeled correctly- Make users_extra and seusers.final into config(noreplace) so semanage users and login does not get overwritten- Add policy for sa-update being run out of cron jobs - Add create perms to postgresql_manage_db - ntpd using a gps has to be able to read/write generic tty_device_t - If you disable unconfined and unconfineduser, rpm needs more privs to manage /dev - fix spec file - Remove qemu_domtrans_unconfined() interface - Make passenger working together with puppet - Add init_dontaudit_rw_stream_socket interface - Fixes for wordpress- Turn on allow_domain_fd_use boolean on F16 - Allow syslog to manage all log files - Add use_fusefs_home_dirs boolean for chrome - Make vdagent working with confined users - Add abrt_handle_event_t domain for ABRT event scripts - Labeled /usr/sbin/rhnreg_ks as rpm_exec_t and added changes related to this change - Allow httpd_git_script_t to read passwd data - Allow openvpn to set its process priority when the nice parameter is used- livecd fixes - spec file fixes- fetchmail can use kerberos - ksmtuned reads in shell programs - gnome_systemctl_t reads the process state of ntp - dnsmasq_t asks the kernel to load multiple kernel modules - Add rules for domains executing systemctl - Bogus text within fc file- Add cfengine policy- Add abrt_domain attribute - Allow corosync to manage cluster lib files - Allow corosync to connect to the system DBUS- Add sblim, uuidd policies - Allow kernel_t dyntrasition to init_t- init_t need setexec - More fixes of rules which cause an explosion in rules by Dan Walsh- Allow rcsmcertd to perform DNS name resolution - Add dirsrvadmin_unconfined_script_t domain type for 389-ds admin scripts - Allow tmux to run as screen - New policy for collectd - Allow gkeyring_t to interact with all user apps - Add rules to allow firstboot to run on machines with the unconfined.pp module removed- Allow systemd_logind to send dbus messages with users - allow accountsd to read wtmp file - Allow dhcpd to get and set capabilities- Fix oracledb_port definition - Allow mount to mounton the selinux file system - Allow users to list /var directories- systemd fixes- Add initial policy for abrt_dump_oops_t - xtables-multi wants to getattr of the proc fs - Smoltclient is connecting to abrt - Dontaudit leaked file descriptors to postdrop - Allow abrt_dump_oops to look at kernel sysctls - Abrt_dump_oops_t reads kernel ring buffer - Allow mysqld to request the kernel to load modules - systemd-login needs fowner - Allow postfix_cleanup_t to searh maildrop- Initial systemd_logind policy - Add policy for systemd_logger and additional proivs for systemd_logind - More fixes for systemd policies- Allow setsched for virsh - Systemd needs to impersonate cups, which means it needs to create tcp_sockets in cups_t domain, as well as manage spool directories - iptables: the various /sbin/ip6?tables.* are now symlinks for /sbin/xtables-multi- A lot of users are running yum -y update while in /root which is causing ldconfig to list the contents, adding dontaudit - Allow colord to interact with the users through the tmpfs file system - Since we changed the label on deferred, we need to allow postfix_qmgr_t to be able to create maildrop_t files - Add label for /var/log/mcelog - Allow asterisk to read /dev/random if it uses TLS - Allow colord to read ini files which are labeled as bin_t - Allow dirsrvadmin sys_resource and setrlimit to use ulimit - Systemd needs to be able to create sock_files for every label in /var/run directory, cupsd being the first. - Also lists /var and /var/spool directories - Add openl2tpd to l2tpd policy - qpidd is reading the sysfs file- Change usbmuxd_t to dontaudit attempts to read chr_file - Add mysld_safe_exec_t for libra domains to be able to start private mysql domains - Allow pppd to search /var/lock dir - Add rhsmcertd policy- Update to upstream- More fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git- Fix spec file to not report Verify errors- Add dspam policy - Add lldpad policy - dovecot auth wants to search statfs #713555 - Allow systemd passwd apps to read init fifo_file - Allow prelink to use inherited terminals - Run cherokee in the httpd_t domain - Allow mcs constraints on node connections - Implement pyicqt policy - Fixes for zarafa policy - Allow cobblerd to send syslog messages- Add policy.26 to the payload - Remove olpc stuff - Remove policygentool- Fixes for zabbix - init script needs to be able to manage sanlock_var_run_... - Allow sandlock and wdmd to create /var/run directories... - mixclip.so has been compiled correctly - Fix passenger policy module name- Add mailscanner policy from dgrift - Allow chrome to optionally be transitioned to - Zabbix needs these rules when starting the zabbix_server_mysql - Implement a type for freedesktop openicc standard (~/.local/share/icc) - Allow system_dbusd_t to read inherited icc_data_home_t files. - Allow colord_t to read icc_data_home_t content. #706975 - Label stuff under /usr/lib/debug as if it was labeled under /- Fixes for sanlock policy - Fixes for colord policy - Other fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Add rhev policy module to modules-targeted.conf- Lot of fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Allow logrotate to execute systemctl - Allow nsplugin_t to getattr on gpmctl - Fix dev_getattr_all_chr_files() interface - Allow shorewall to use inherited terms - Allow userhelper to getattr all chr_file devices - sandbox domains should be able to getattr and dontaudit search of sysctl_kernel_t - Fix labeling for ABRT Retrace Server- Dontaudit sys_module for ifconfig - Make telepathy and gkeyringd daemon working with confined users - colord wants to read files in users homedir - Remote login should be creating user_tmp_t not its own tmp files- Fix label for /usr/share/munin/plugins/munin_* plugins - Add support for zarafa-indexer - Fix boolean description - Allow colord to getattr on /proc/scsi/scsi - Add label for /lib/upstart/init - Colord needs to list /mnt- Forard port changes from F15 for telepathy - NetworkManager should be allowed to use /dev/rfkill - Fix dontaudit messages to say Domain to not audit - Allow telepathy domains to read/write gnome_cache files - Allow telepathy domains to call getpw - Fixes for colord and vnstatd policy- Allow init_t getcap and setcap - Allow namespace_init_t to use nsswitch - aisexec will execute corosync - colord tries to read files off noxattr file systems - Allow init_t getcap and setcap- Add support for ABRT retrace server - Allow user_t and staff_t access to generic scsi to handle locally plugged in scanners - Allow telepath_msn_t to read /proc/PARENT/cmdline - ftpd needs kill capability - Allow telepath_msn_t to connect to sip port - keyring daemon does not work on nfs homedirs - Allow $1_sudo_t to read default SELinux context - Add label for tgtd sock file in /var/run/ - Add apache_exec_rotatelogs interface - allow all zaraha domains to signal themselves, server writes to /tmp - Allow syslog to read the process state - Add label for /usr/lib/chromium-browser/chrome - Remove the telepathy transition from unconfined_t - Dontaudit sandbox domains trying to mounton sandbox_file_t, this is caused by fuse mounts - Allow initrc_t domain to manage abrt pid files - Add support for AEOLUS project - Virt_admin should be allowed to manage images and processes - Allow plymountd to send signals to init - Change labeling of fping6- Add filename transitions- Fixes for zarafa policy - Add support for AEOLUS project - Change labeling of fping6 - Allow plymountd to send signals to init - Allow initrc_t domain to manage abrt pid files - Virt_admin should be allowed to manage images and processes- xdm_t needs getsession for switch user - Every app that used to exec init is now execing systemdctl - Allow squid to manage krb5_host_rcache_t files - Allow foghorn to connect to agentx port - Fixes for colord policy- Add Dan's patch to remove 64 bit variants - Allow colord to use unix_dgram_socket - Allow apps that search pids to read /var/run if it is a lnk_file - iscsid_t creates its own directory - Allow init to list var_lock_t dir - apm needs to verify user accounts auth_use_nsswitch - Add labeling for systemd unit files - Allow gnomeclok to enable ntpd service using systemctl - systemd_systemctl_t domain was added - Add label for matahari-broker.pid file - We want to remove untrustedmcsprocess from ability to read /proc/pid - Fixes for matahari policy - Allow system_tmpfiles_t to delete user_home_t files in the /tmp dir - Allow sshd to transition to sysadm_t if ssh_sysadm_login is turned on- Fix typo- Add /var/run/lock /var/lock definition to file_contexts.subs - nslcd_t is looking for kerberos cc files - SSH_USE_STRONG_RNG is 1 which requires /dev/random - Fix auth_rw_faillog definition - Allow sysadm_t to set attributes on fixed disks - allow user domains to execute lsof and look at application sockets - prelink_cron job calls telinit -u if init is rewritten - Fixes to run qemu_t from staff_t- Fix label for /var/run/udev to udev_var_run_t - Mock needs to be able to read network state- Add file_contexts.subs to handle /run and /run/lock - Add other fixes relating to /run changes from F15 policy- Allow $1_sudo_t and $1_su_t open access to user terminals - Allow initrc_t to use generic terminals - Make Makefile/Rules.modular run sepolgen-ifgen during build to check if files for bugs -systemd is going to be useing /run and /run/lock for early bootup files. - Fix some comments in rlogin.if - Add policy for KDE backlighthelper - sssd needs to read ~/.k5login in nfs, cifs or fusefs file systems - sssd wants to read .k5login file in users homedir - setroubleshoot reads executables to see if they have TEXTREL - Add /var/spool/audit support for new version of audit - Remove kerberos_connect_524() interface calling - Combine kerberos_master_port_t and kerberos_port_t - systemd has setup /dev/kmsg as stderr for apps it executes - Need these access so that init can impersonate sockets on unix_dgram_socket- Remove some unconfined domains - Remove permissive domains - Add policy-term.patch from Dan- Fix multiple specification for boot.log - devicekit leaks file descriptors to setfiles_t - Change all all_nodes to generic_node and all_if to generic_if - Should not use deprecated interface - Switch from using all_nodes to generic_node and from all_if to generic_if - Add support for xfce4-notifyd - Fix file context to show several labels as SystemHigh - seunshare needs to be able to mounton nfs/cifs/fusefs homedirs - Add etc_runtime_t label for /etc/securetty - Fixes to allow xdm_t to start gkeyringd_USERTYPE_t directly - login.krb needs to be able to write user_tmp_t - dirsrv needs to bind to port 7390 for dogtag - Fix a bug in gpg policy - gpg sends audit messages - Allow qpid to manage matahari files- Initial policy for matahari - Add dev_read_watchdog - Allow clamd to connect clamd port - Add support for kcmdatetimehelper - Allow shutdown to setrlimit and sys_nice - Allow systemd_passwd to talk to /dev/log before udev or syslog is running - Purge chr_file and blk files on /tmp - Fixes for pads - Fixes for piranha-pulse - gpg_t needs to be able to encyprt anything owned by the user- mozilla_plugin_tmp_t needs to be treated as user tmp files - More dontaudits of writes from readahead - Dontaudit readahead_t file_type:dir write, to cover up kernel bug - systemd_tmpfiles needs to relabel faillog directory as well as the file - Allow hostname and consoletype to r/w inherited initrc_tmp_t files handline hostname >> /tmp/myhost- Add policykit fixes from Tim Waugh - dontaudit sandbox domains sandbox_file_t:dir mounton - Add new dontaudit rules for sysadm_dbusd_t - Change label for /var/run/faillock * other fixes which relate with this change- Update to upstream - Fixes for telepathy - Add port defition for ssdp port - add policy for /bin/systemd-notify from Dan - Mount command requires users read mount_var_run_t - colord needs to read konject_uevent_socket - User domains connect to the gkeyring socket - Add colord policy and allow user_t and staff_t to dbus chat with it - Add lvm_exec_t label for kpartx - Dontaudit reading the mail_spool_t link from sandbox -X - systemd is creating sockets in avahi_var_run and system_dbusd_var_run- gpg_t needs to talk to gnome-keyring - nscd wants to read /usr/tmp->/var/tmp to generate randomziation in unixchkpwd - enforce MCS labeling on nodes - Allow arpwatch to read meminfo - Allow gnomeclock to send itself signals - init relabels /dev/.udev files on boot - gkeyringd has to transition back to staff_t when it runs commands in bin_t or shell_exec_t - nautilus checks access on /media directory before mounting usb sticks, dontaudit access_check on mnt_t - dnsmasq can run as a dbus service, needs acquire service - mysql_admin should be allowed to connect to mysql service - virt creates monitor sockets in the users home dir- Allow usbhid-ups to read hardware state information - systemd-tmpfiles has moved - Allo cgroup to sys_tty_config - For some reason prelink is attempting to read gconf settings - Add allow_daemons_use_tcp_wrapper boolean - Add label for ~/.cache/wocky to make telepathy work in enforcing mode - Add label for char devices /dev/dasd* - Fix for apache_role - Allow amavis to talk to nslcd - allow all sandbox to read selinux poilcy config files - Allow cluster domains to use the system bus and send each other dbus messages- Update to upstream- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Update to ref policy - cgred needs chown capability - Add /dev/crash crash_dev_t - systemd-readahead wants to use fanotify which means readahead_t needs sys_admin capability- New labeling for postfmulti #675654 - dontaudit xdm_t listing noxattr file systems - dovecot-auth needs to be able to connect to mysqld via the network as well as locally - shutdown is passed stdout to a xdm_log_t file - smartd creates a fixed disk device - dovecot_etc_t contains a lnk_file that domains need to read - mount needs to be able to read etc_runtim_t:lnk_file since in rawhide this is a link created at boot- syslog_t needs syslog capability - dirsrv needs to be able to create /var/lib/snmp - Fix labeling for dirsrv - Fix for dirsrv policy missing manage_dirs_pattern - corosync needs to delete clvm_tmpfs_t files - qdiskd needs to list hugetlbfs - Move setsched to sandbox_x_domain, so firefox can run without network access - Allow hddtemp to read removable devices - Adding syslog and read_policy permissions to policy * syslog Allow unconfined, sysadm_t, secadm_t, logadm_t * read_policy allow unconfined, sysadm_t, secadm_t, staff_t on Targeted allow sysadm_t (optionally), secadm_t on MLS - mdadm application will write into /sys/.../uevent whenever arrays are assembled or disassembled.- Add tcsd policy- ricci_modclusterd_t needs to bind to rpc ports 500-1023 - Allow dbus to use setrlimit to increase resoueces - Mozilla_plugin is leaking to sandbox - Allow confined users to connect to lircd over unix domain stream socket which allow to use remote control - Allow awstats to read squid logs - seunshare needs to manage tmp_t - apcupsd cgi scripts have a new directory- Fix xserver_dontaudit_read_xdm_pid - Change oracle_port_t to oracledb_port_t to prevent conflict with satellite - Allow dovecot_deliver_t to read/write postfix_master_t:fifo_file. * These fifo_file is passed from postfix_master_t to postfix_local_t to dovecot_deliver_t - Allow readahead to manage readahead pid dirs - Allow readahead to read all mcs levels - Allow mozilla_plugin_t to use nfs or samba homedirs- Allow nagios plugin to read /proc/meminfo - Fix for mozilla_plugin - Allow samba_net_t to create /etc/keytab - pppd_t setting up vpns needs to run unix_chkpwd, setsched its process and write wtmp_t - nslcd can read user credentials - Allow nsplugin to delete mozilla_plugin_tmpfs_t - abrt tries to create dir in rpm_var_lib_t - virt relabels fifo_files - sshd needs to manage content in fusefs homedir - mock manages link files in cache dir- nslcd needs setsched and to read /usr/tmp - Invalid call in likewise policy ends up creating a bogus role - Cannon puts content into /var/lib/bjlib that cups needs to be able to write - Allow screen to create screen_home_t in /root - dirsrv sends syslog messages - pinentry reads stuff in .kde directory - Add labels for .kde directory in homedir - Treat irpinit, iprupdate, iprdump services with raid policy- NetworkManager wants to read consolekit_var_run_t - Allow readahead to create /dev/.systemd/readahead - Remove permissive domains - Allow newrole to run namespace_init- Add sepgsql_contexts file- Update to upstream- Add oracle ports and allow apache to connect to them if the connect_db boolean is turned on - Add puppetmaster_use_db boolean - Fixes for zarafa policy - Fixes for gnomeclock poliy - Fix systemd-tmpfiles to use auth_use_nsswitch- gnomeclock executes a shell - Update for screen policy to handle pipe in homedir - Fixes for polyinstatiated homedir - Fixes for namespace policy and other fixes related to polyinstantiation - Add namespace policy - Allow dovecot-deliver transition to sendmail which is needed by sieve scripts - Fixes for init, psad policy which relate with confined users - Do not audit bootloader attempts to read devicekit pid files - Allow nagios service plugins to read /proc- Add firewalld policy - Allow vmware_host to read samba config - Kernel wants to read /proc Fix duplicate grub def in cobbler - Chrony sends mail, executes shell, uses fifo_file and reads /proc - devicekitdisk getattr all file systems - sambd daemon writes wtmp file - libvirt transitions to dmidecode- Add initial policy for system-setup-keyboard which is now daemon - Label /var/lock/subsys/shorewall as shorewall_lock_t - Allow users to communicate with the gpg_agent_t - Dontaudit mozilla_plugin_t using the inherited terminal - Allow sambagui to read files in /usr - webalizer manages squid log files - Allow unconfined domains to bind ports to raw_ip_sockets - Allow abrt to manage rpm logs when running yum - Need labels for /var/run/bittlebee - Label .ssh under amanda - Remove unused genrequires for virt_domain_template - Allow virt_domain to use fd inherited from virtd_t - Allow iptables to read shorewall config- Gnome apps list config_home_t - mpd creates lnk files in homedir - apache leaks write to mail apps on tmp files - /var/stockmaniac/templates_cache contains log files - Abrt list the connects of mount_tmp_t dirs - passwd agent reads files under /dev and reads utmp file - squid apache script connects to the squid port - fix name of plymouth log file - teamviewer is a wine app - allow dmesg to read system state - Stop labeling files under /var/lib/mock so restorecon will not go into this - nsplugin needs to read network state for google talk- Allow xdm and syslog to use /var/log/boot.log - Allow users to communicate with mozilla_plugin and kill it - Add labeling for ipv6 and dhcp- New labels for ghc http content - nsplugin_config needs to read urand, lvm now calls setfscreate to create dev - pm-suspend now creates log file for append access so we remove devicekit_wri - Change authlogin_use_sssd to authlogin_nsswitch_use_ldap - Fixes for greylist_milter policy- Update to upstream - Fixes for systemd policy - Fixes for passenger policy - Allow staff users to run mysqld in the staff_t domain, akonadi needs this - Add bin_t label for /usr/share/kde4/apps/kajongg/kajongg.py - auth_use_nsswitch does not need avahi to read passwords,needed for resolving data - Dontaudit (xdm_t) gok attempting to list contents of /var/account - Telepathy domains need to read urand - Need interface to getattr all file classes in a mock library for setroubleshoot- Update selinux policy to handle new /usr/share/sandbox/start script- Update to upstream - Fix version of policy in spec file- Allow sandbox to run on nfs partitions, fixes for systemd_tmpfs - remove per sandbox domains devpts types - Allow dkim-milter sending signal to itself- Allow domains that transition to ping or traceroute, kill them - Allow user_t to conditionally transition to ping_t and traceroute_t - Add fixes to systemd- tools, including new labeling for systemd-fsck, systemd-cryptsetup- Turn on systemd policy - mozilla_plugin needs to read certs in the homedir. - Dontaudit leaked file descriptors from devicekit - Fix ircssi to use auth_use_nsswitch - Change to use interface without param in corenet to disable unlabelednet packets - Allow init to relabel sockets and fifo files in /dev - certmonger needs dac* capabilities to manage cert files not owned by root - dovecot needs fsetid to change group membership on mail - plymouthd removes /var/log/boot.log - systemd is creating symlinks in /dev - Change label on /etc/httpd/alias to be all cert_t- Fixes for clamscan and boinc policy - Add boinc_project_t setpgid - Allow alsa to create tmp files in /tmp- Push fixes to allow disabling of unlabeled_t packet access - Enable unlabelednet policy- Fixes for lvm to work with systemd- Fix the label for wicd log - plymouthd creates force-display-on-active-vt file - Allow avahi to request the kernel to load a module - Dontaudit hal leaks - Fix gnome_manage_data interface - Add new interface corenet_packet to define a type as being an packet_type. - Removed general access to packet_type from icecast and squid. - Allow mpd to read alsa config - Fix the label for wicd log - Add systemd policy- Fix gnome_manage_data interface - Dontaudit sys_ptrace capability for iscsid - Fixes for nagios plugin policy- Fix cron to run ranged when started by init - Fix devicekit to use log files - Dontaudit use of devicekit_var_run_t for fstools - Allow init to setattr on logfile directories - Allow hald to manage files in /var/run/pm-utils/ dir which is now labeled as devicekit_var_run_t- Fix up handling of dnsmasq_t creating /var/run/libvirt/network - Turn on sshd_forward_ports boolean by default - Allow sysadmin to dbus chat with rpm - Add interface for rw_tpm_dev - Allow cron to execute bin - fsadm needs to write sysfs - Dontaudit consoletype reading /var/run/pm-utils - Lots of new privs fro mozilla_plugin_t running java app, make mozilla_plugin - certmonger needs to manage dirsrv data - /var/run/pm-utils should be labeled as devicekit_var_run_t- fixes to allow /var/run and /var/lock as tmpfs - Allow chrome sandbox to connect to web ports - Allow dovecot to listem on lmtp and sieve ports - Allov ddclient to search sysctl_net_t - Transition back to original domain if you execute the shell- Remove duplicate declaration- Update to upstream - Cleanup for sandbox - Add attribute to be able to select sandbox types- Allow ddclient to fix file mode bits of ddclient conf file - init leaks file descriptors to daemons - Add labels for /etc/lirc/ and - Allow amavis_t to exec shell - Add label for gssd_tmp_t for /var/tmp/nfs_0- Put back in lircd_etc_t so policy will install- Turn on allow_postfix_local_write_mail_spool - Allow initrc_t to transition to shutdown_t - Allow logwatch and cron to mls_read_to_clearance for MLS boxes - Allow wm to send signull to all applications and receive them from users - lircd patch from field - Login programs have to read /etc/samba - New programs under /lib/systemd - Abrt needs to read config files- Update to upstream - Dontaudit leaked sockets from userdomains to user domains - Fixes for mcelog to handle scripts - Apply patch from Ruben Kerkhof - Allow syslog to search spool dirs- Allow nagios plugins to read usr files - Allow mysqld-safe to send system log messages - Fixes fpr ddclient policy - Fix sasl_admin interface - Allow apache to search zarafa config - Allow munin plugins to search /var/lib directory - Allow gpsd to read sysfs_t - Fix labels on /etc/mcelog/triggers to bin_t- Remove saslauthd_tmp_t and transition tmp files to krb5_host_rcache_t - Allow saslauthd_t to create krb5_host_rcache_t files in /tmp - Fix xserver interface - Fix definition of /var/run/lxdm- Turn on mediawiki policy - kdump leaks kdump_etc_t to ifconfig, add dontaudit - uux needs to transition to uucpd_t - More init fixes relabels man,faillog - Remove maxima defs in libraries.fc - insmod needs to be able to create tmpfs_t files - ping needs setcap- Allow groupd transition to fenced domain when executes fence_node - Fixes for rchs policy - Allow mpd to be able to read samba/nfs files- Fix up corecommands.fc to match upstream - Make sure /lib/systemd/* is labeled init_exec_t - mount wants to setattr on all mountpoints - dovecot auth wants to read dovecot etc files - nscd daemon looks at the exe file of the comunicating daemon - openvpn wants to read utmp file - postfix apps now set sys_nice and lower limits - remote_login (telnetd/login) wants to use telnetd_devpts_t and user_devpts_t to work correctly - Also resolves nsswitch - Fix labels on /etc/hosts.* - Cleanup to make upsteam patch work - allow abrt to read etc_runtime_t- Add conflicts for dirsrv package- Update to upstream - Add vlock policy- Fix sandbox to work on nfs homedirs - Allow cdrecord to setrlimit - Allow mozilla_plugin to read xauth - Change label on systemd-logger to syslogd_exec_t - Install dirsrv policy from dirsrv package- Add virt_home_t, allow init to setattr on xserver_tmp_t and relabel it - Udev needs to stream connect to init and kernel - Add xdm_exec_bootloader boolean, which allows xdm to execute /sbin/grub and read files in /boot directory- Allow NetworkManager to read openvpn_etc_t - Dontaudit hplip to write of /usr dirs - Allow system_mail_t to create /root/dead.letter as mail_home_t - Add vdagent policy for spice agent daemon- Dontaudit sandbox sending sigkill to all user domains - Add policy for rssh_chroot_helper - Add missing flask definitions - Allow udev to relabelto removable_t - Fix label on /var/log/wicd.log - Transition to initrc_t from init when executing bin_t - Add audit_access permissions to file - Make removable_t a device_node - Fix label on /lib/systemd/*- Fixes for systemd to manage /var/run - Dontaudit leaks by firstboot- Allow chome to create netlink_route_socket - Add additional MATHLAB file context - Define nsplugin as an application_domain - Dontaudit sending signals from sandboxed domains to other domains - systemd requires init to build /tmp /var/auth and /var/lock dirs - mount wants to read devicekit_power /proc/ entries - mpd wants to connect to soundd port - Openoffice causes a setattr on a lib_t file for normal users, add dontaudit - Treat lib_t and textrel_shlib_t directories the same - Allow mount read access on virtual images- Allow sandbox_x_domains to work with nfs/cifs/fusefs home dirs. - Allow devicekit_power to domtrans to mount - Allow dhcp to bind to udp ports > 1024 to do named stuff - Allow ssh_t to exec ssh_exec_t - Remove telepathy_butterfly_rw_tmp_files(), dev_read_printk() interfaces which are nolonger used - Fix clamav_append_log() intefaces - Fix 'psad_rw_fifo_file' interface- Allow cobblerd to list cobler appache content- Fixup for the latest version of upowed - Dontaudit sandbox sending SIGNULL to desktop apps- Update to upstream-Mount command from a confined user generates setattr on /etc/mtab file, need to dontaudit this access - dovecot-auth_t needs ipc_lock - gpm needs to use the user terminal - Allow system_mail_t to append ~/dead.letter - Allow NetworkManager to edit /etc/NetworkManager/NetworkManager.conf - Add pid file to vnstatd - Allow mount to communicate with gfs_controld - Dontaudit hal leaks in setfiles- Lots of fixes for systemd - systemd now executes readahead and tmpwatch type scripts - Needs to manage random seed- Allow smbd to use sys_admin - Remove duplicate file context for tcfmgr - Update to upstream- Fix fusefs handling - Do not allow sandbox to manage nsplugin_rw_t - Allow mozilla_plugin_t to connecto its parent - Allow init_t to connect to plymouthd running as kernel_t - Add mediawiki policy - dontaudit sandbox sending signals to itself. This can happen when they are running at different mcs. - Disable transition from dbus_session_domain to telepathy for F14 - Allow boinc_project to use shm - Allow certmonger to search through directories that contain certs - Allow fail2ban the DAC Override so it can read log files owned by non root users- Start adding support for use_fusefs_home_dirs - Add /var/lib/syslog directory file context - Add /etc/localtime as locale file context- Turn off default transition to mozilla_plugin and telepathy domains from unconfined user - Turn off iptables from unconfined user - Allow sudo to send signals to any domains the user could have transitioned to. - Passwd in single user mode needs to talk to console_device_t - Mozilla_plugin_t needs to connect to web ports, needs to write to video device, and read alsa_home_t alsa setsup pulseaudio - locate tried to read a symbolic link, will dontaudit - New labels for telepathy-sunshine content in homedir - Google is storing other binaries under /opt/google/talkplugin - bluetooth/kernel is creating unlabeled_t socket that I will allow it to use until kernel fixes bug - Add boolean for unconfined_t transition to mozilla_plugin_t and telepathy domains, turned off in F14 on in F15 - modemmanger and bluetooth send dbus messages to devicekit_power - Samba needs to getquota on filesystems labeld samba_share_t- Dontaudit attempts by xdm_t to write to bin_t for kdm - Allow initrc_t to manage system_conf_t- Fixes to allow mozilla_plugin_t to create nsplugin_home_t directory. - Allow mozilla_plugin_t to create tcp/udp/netlink_route sockets - Allow confined users to read xdm_etc_t files - Allow xdm_t to transition to xauth_t for lxdm program- Rearrange firewallgui policy to be more easily updated to upstream, dontaudit search of /home - Allow clamd to send signals to itself - Allow mozilla_plugin_t to read user home content. And unlink pulseaudio shm. - Allow haze to connect to yahoo chat and messenger port tcp:5050. Bz #637339 - Allow guest to run ps command on its processes by allowing it to read /proc - Allow firewallgui to sys_rawio which seems to be required to setup masqerading - Allow all domains to search through default_t directories, in order to find differnet labels. For example people serring up /foo/bar to be share via samba. - Add label for /var/log/slim.log- Pull in cleanups from dgrift - Allow mozilla_plugin_t to execute mozilla_home_t - Allow rpc.quota to do quotamod- Cleanup policy via dgrift - Allow dovecot_deliver to append to inherited log files - Lots of fixes for consolehelper- Fix up Xguest policy- Add vnstat policy - allow libvirt to send audit messages - Allow chrome-sandbox to search nfs_t- Update to upstream- Add the ability to send audit messages to confined admin policies - Remove permissive domain from cmirrord and dontaudit sys_tty_config - Split out unconfined_domain() calls from other unconfined_ calls so we can d - virt needs to be able to read processes to clearance for MLS- Allow all domains that can use cgroups to search tmpfs_t directory - Allow init to send audit messages- Update to upstream- Allow mdadm_t to create files and sock files in /dev/md/- Add policy for ajaxterm- Handle /var/db/sudo - Allow pulseaudio to read alsa config - Allow init to send initrc_t dbus messagesAllow iptables to read shorewall tmp files Change chfn and passwd to use auth_use_pam so they can send dbus messages to fpr intd label vlc as an execmem_exec_t Lots of fixes for mozilla_plugin to run google vidio chat Allow telepath_msn to execute ldconfig and its own tmp files Fix labels on hugepages Allow mdadm to read files on /dev Remove permissive domains and change back to unconfined Allow freshclam to execute shell and bin_t Allow devicekit_power to transition to dhcpc Add boolean to allow icecast to connect to any port- Merge upstream fix of mmap_zero - Allow mount to write files in debugfs_t - Allow corosync to communicate with clvmd via tmpfs - Allow certmaster to read usr_t files - Allow dbus system services to search cgroup_t - Define rlogind_t as a login pgm- Allow mdadm_t to read/write hugetlbfs- Dominic Grift Cleanup - Miroslav Grepl policy for jabberd - Various fixes for mount/livecd and prelink- Merge with upstream- More access needed for devicekit - Add dbadm policy- Merge with upstream- Allow seunshare to fowner- Allow cron to look at user_cron_spool links - Lots of fixes for mozilla_plugin_t - Add sysv file system - Turn unconfined domains to permissive to find additional avcs- Update policy for mozilla_plugin_t- Allow clamscan to read proc_t - Allow mount_t to write to debufs_t dir - Dontaudit mount_t trying to write to security_t dir- Allow clamscan_t execmem if clamd_use_jit set - Add policy for firefox plugin-container- Fix /root/.forward definition- label dead.letter as mail_home_t- Allow login programs to search /cgroups- Fix cert handling- Fix devicekit_power bug - Allow policykit_auth_t more access.- Fix nis calls to allow bind to ports 512-1024 - Fix smartmon- Allow pcscd to read sysfs - systemd fixes - Fix wine_mmap_zero_ignore boolean- Apply Miroslav munin patch - Turn back on allow_execmem and allow_execmod booleans- Merge in fixes from dgrift repository- Update boinc policy - Fix sysstat policy to allow sys_admin - Change failsafe_context to unconfined_r:unconfined_t:s0- New paths for upstart- New permissions for syslog - New labels for /lib/upstart- Add mojomojo policy- Allow systemd to setsockcon on sockets to immitate other services- Remove debugfs label- Update to latest policy- Fix eclipse labeling from IBMSupportAssasstant packageing- Make boot with systemd in enforcing mode- Update to upstream- Add boolean to turn off port forwarding in sshd.- Add support for ebtables - Fixes for rhcs and corosync policy-Update to upstream-Update to upstream-Update to upstream- Add Zarafa policy- Cleanup of aiccu policy - initial mock policy- Lots of random fixes- Update to upstream- Update to upstream - Allow prelink script to signal itself - Cobbler fixes- Add xdm_var_run_t to xserver_stream_connect_xdm - Add cmorrord and mpd policy from Miroslav Grepl- Fix sshd creation of krb cc files for users to be user_tmp_t- Fixes for accountsdialog - Fixes for boinc- Fix label on /var/lib/dokwiki - Change permissive domains to enforcing - Fix libvirt policy to allow it to run on mls- Update to upstream- Allow procmail to execute scripts in the users home dir that are labeled home_bin_t - Fix /var/run/abrtd.lock label- Allow login programs to read krb5_home_t Resolves: 594833 - Add obsoletes for cachefilesfd-selinux package Resolves: #575084- Allow mount to r/w abrt fifo file - Allow svirt_t to getattr on hugetlbfs - Allow abrt to create a directory under /var/spool- Add labels for /sys - Allow sshd to getattr on shutdown - Fixes for munin - Allow sssd to use the kernel key ring - Allow tor to send syslog messages - Allow iptabels to read usr files - allow policykit to read all domains state- Fix path for /var/spool/abrt - Allow nfs_t as an entrypoint for http_sys_script_t - Add policy for piranha - Lots of fixes for sosreport- Allow xm_t to read network state and get and set capabilities - Allow policykit to getattr all processes - Allow denyhosts to connect to tcp port 9911 - Allow pyranha to use raw ip sockets and ptrace itself - Allow unconfined_execmem_t and gconfsd mechanism to dbus - Allow staff to kill ping process - Add additional MLS rules- Allow gdm to edit ~/.gconf dir Resolves: #590677 - Allow dovecot to create directories in /var/lib/dovecot Partially resolves 590224 - Allow avahi to dbus chat with NetworkManager - Fix cobbler labels - Dontaudit iceauth_t leaks - fix /var/lib/lxdm file context - Allow aiccu to use tun tap devices - Dontaudit shutdown using xserver.log- Fixes for sandbox_x_net_t to match access for sandbox_web_t ++ - Add xdm_etc_t for /etc/gdm directory, allow accountsd to manage this directory - Add dontaudit interface for bluetooth dbus - Add chronyd_read_keys, append_keys for initrc_t - Add log support for ksmtuned Resolves: #586663- Allow boinc to send mail- Allow initrc_t to remove dhcpc_state_t - Fix label on sa-update.cron - Allow dhcpc to restart chrony initrc - Don't allow sandbox to send signals to its parent processes - Fix transition from unconfined_t -> unconfined_mount_t -> rpcd_t Resolves: #589136- Fix location of oddjob_mkhomedir Resolves: #587385 - fix labeling on /root/.shosts and ~/.shosts - Allow ipsec_mgmt_t to manage net_conf_t Resolves: #586760- Dontaudit sandbox trying to connect to netlink sockets Resolves: #587609 - Add policy for piranha- Fixups for xguest policy - Fixes for running sandbox firefox- Allow ksmtuned to use terminals Resolves: #586663 - Allow lircd to write to generic usb devices- Allow sandbox_xserver to connectto unconfined stream Resolves: #585171- Allow initrc_t to read slapd_db_t Resolves: #585476 - Allow ipsec_mgmt to use unallocated devpts and to create /etc/resolv.conf Resolves: #585963- Allow rlogind_t to search /root for .rhosts Resolves: #582760 - Fix path for cached_var_t - Fix prelink paths /var/lib/prelink - Allow confined users to direct_dri - Allow mls lvm/cryptosetup to work- Allow virtd_t to manage firewall/iptables config Resolves: #573585- Fix label on /root/.rhosts Resolves: #582760 - Add labels for Picasa - Allow openvpn to read home certs - Allow plymouthd_t to use tty_device_t - Run ncftool as iptables_t - Allow mount to unmount unlabeled_t - Dontaudit hal leaks- Allow livecd to transition to mount- Update to upstream - Allow abrt to delete sosreport Resolves: #579998 - Allow snmp to setuid and gid Resolves: #582155 - Allow smartd to use generic scsi devices Resolves: #582145- Allow ipsec_t to create /etc/resolv.conf with the correct label - Fix reserved port destination - Allow autofs to transition to showmount - Stop crashing tuned- Add telepathysofiasip policy- Update to upstream - Fix label for /opt/google/chrome/chrome-sandbox - Allow modemmanager to dbus with policykit- Fix allow_httpd_mod_auth_pam to use auth_use_pam(httpd_t) - Allow accountsd to read shadow file - Allow apache to send audit messages when using pam - Allow asterisk to bind and connect to sip tcp ports - Fixes for dovecot 2.0 - Allow initrc_t to setattr on milter directories - Add procmail_home_t for .procmailrc file- Fixes for labels during install from livecd- Fix /cgroup file context - Fix broken afs use of unlabled_t - Allow getty to use the console for s390- Fix cgroup handling adding policy for /cgroup - Allow confined users to write to generic usb devices, if user_rw_noexattrfile boolean set- Merge patches from dgrift- Update upstream - Allow abrt to write to the /proc under any process- Fix ~/.fontconfig label - Add /root/.cert label - Allow reading of the fixed_file_disk_t:lnk_file if you can read file - Allow qemu_exec_t as an entrypoint to svirt_t- Update to upstream - Allow tmpreaper to delete sandbox sock files - Allow chrome-sandbox_t to use /dev/zero, and dontaudit getattr file systems - Fixes for gitosis - No transition on livecd to passwd or chfn - Fixes for denyhosts- Add label for /var/lib/upower - Allow logrotate to run sssd - dontaudit readahead on tmpfs blk files - Allow tmpreaper to setattr on sandbox files - Allow confined users to execute dos files - Allow sysadm_t to kill processes running within its clearance - Add accountsd policy - Fixes for corosync policy - Fixes from crontab policy - Allow svirt to manage svirt_image_t chr files - Fixes for qdisk policy - Fixes for sssd policy - Fixes for newrole policy- make libvirt work on an MLS platform- Add qpidd policy- Update to upstream- Allow boinc to read kernel sysctl - Fix snmp port definitions - Allow apache to read anon_inodefs- Allow shutdown dac_override- Add device_t as a file system - Fix sysfs association- Dontaudit ipsec_mgmt sys_ptrace - Allow at to mail its spool files - Allow nsplugin to search in .pulse directory- Update to upstream- Allow users to dbus chat with xdm - Allow users to r/w wireless_device_t - Dontaudit reading of process states by ipsec_mgmt- Fix openoffice from unconfined_t- Add shutdown policy so consolekit can shutdown system- Update to upstream- Update to upstream- Update to upstream - These are merges of my patches - Remove 389 labeling conflicts - Add MLS fixes found in RHEL6 testing - Allow pulseaudio to run as a service - Add label for mssql and allow apache to connect to this database port if boolean set - Dontaudit searches of debugfs mount point - Allow policykit_auth to send signals to itself - Allow modcluster to call getpwnam - Allow swat to signal winbind - Allow usbmux to run as a system role - Allow svirt to create and use devpts- Add MLS fixes found in RHEL6 testing - Allow domains to append to rpm_tmp_t - Add cachefilesfd policy - Dontaudit leaks when transitioning- Change allow_execstack and allow_execmem booleans to on - dontaudit acct using console - Add label for fping - Allow tmpreaper to delete sandbox_file_t - Fix wine dontaudit mmap_zero - Allow abrt to read var_t symlinks- Additional policy for rgmanager- Allow sshd to setattr on pseudo terms- Update to upstream- Allow policykit to send itself signals- Fix duplicate cobbler definition- Fix file context of /var/lib/avahi-autoipd- Merge with upstream- Allow sandbox to work with MLS- Make Chrome work with staff user- Add icecast policy - Cleanup spec file- Add mcelog policy- Lots of fixes found in F12- Fix rpm_dontaudit_leaks- Add getsched to hald_t - Add file context for Fedora/Redhat Directory Server- Allow abrt_helper to getattr on all filesystems - Add label for /opt/real/RealPlayer/plugins/oggfformat\.so- Add gstreamer_home_t for ~/.gstreamer- Update to upstream- Fix git- Turn on puppet policy - Update to dgrift git policy- Move users file to selection by spec file. - Allow vncserver to run as unconfined_u:unconfined_r:unconfined_t- Update to upstream- Remove most of the permissive domains from F12.- Add cobbler policy from dgrift- add usbmon device - Add allow rulse for devicekit_disk- Lots of fixes found in F12, fixes from Tom London- Cleanups from dgrift- Add back xserver_manage_home_fonts- Dontaudit sandbox trying to read nscd and sssd- Update to upstream- Rename udisks-daemon back to devicekit_disk_t policy- Fixes for abrt calls- Add tgtd policy- Update to upstream release- Add asterisk policy back in - Update to upstream release 2.20091117- Update to upstream release 2.20091117- Fixup nut policy- Update to upstream- Allow vpnc request the kernel to load modules- Fix minimum policy installs - Allow udev and rpcbind to request the kernel to load modules- Add plymouth policy - Allow local_login to sys_admin- Allow cupsd_config to read user tmp - Allow snmpd_t to signal itself - Allow sysstat_t to makedir in sysstat_log_t- Update rhcs policy- Allow users to exec restorecond- Allow sendmail to request kernel modules load- Fix all kernel_request_load_module domains- Fix all kernel_request_load_module domains- Remove allow_exec* booleans for confined users. Only available for unconfined_t- More fixes for sandbox_web_t- Allow sshd to create .ssh directory and content- Fix request_module line to module_request- Fix sandbox policy to allow it to run under firefox. - Dont audit leaks.- Fixes for sandbox- Update to upstream - Dontaudit nsplugin search /root - Dontaudit nsplugin sys_nice- Fix label on /usr/bin/notepad, /usr/sbin/vboxadd-service - Remove policycoreutils-python requirement except for minimum- Fix devicekit_disk_t to getattr on all domains sockets and fifo_files - Conflicts seedit (You can not use selinux-policy-targeted and seedit at the same time.)- Add wordpress/wp-content/uploads label - Fixes for sandbox when run from staff_t- Update to upstream - Fixes for devicekit_disk- More fixes- Lots of fixes for initrc and other unconfined domains- Allow xserver to use netlink_kobject_uevent_socket- Fixes for sandbox- Dontaudit setroubleshootfix looking at /root directory- Update to upsteam- Allow gssd to send signals to users - Fix duplicate label for apache content- Update to upstream- Remove polkit_auth on upgrades- Add back in unconfined.pp and unconfineduser.pp - Add Sandbox unshare- Fixes for cdrecord, mdadm, and others- Add capability setting to dhcpc and gpm- Allow cronjobs to read exim_spool_t- Add ABRT policy- Fix system-config-services policy- Allow libvirt to change user componant of virt_domain- Allow cupsd_config_t to be started by dbus - Add smoltclient policy- Add policycoreutils-python to pre install- Make all unconfined_domains permissive so we can see what AVC's happen- Add pt_chown policy- Add kdump policy for Miroslav Grepl - Turn off execstack boolean- Turn on execstack on a temporary basis (#512845)- Allow nsplugin to connecto the session bus - Allow samba_net to write to coolkey data- Allow devicekit_disk to list inotify- Allow svirt images to create sock_file in svirt_var_run_t- Allow exim to getattr on mountpoints - Fixes for pulseaudio- Allow svirt_t to stream_connect to virtd_t- Allod hald_dccm_t to create sock_files in /tmp- More fixes from upstream- Fix polkit label - Remove hidebrokensymptoms for nss_ldap fix - Add modemmanager policy - Lots of merges from upstream - Begin removing textrel_shlib_t labels, from fixed libraries- Update to upstream- Allow certmaster to override dac permissions- Update to upstream- Fix context for VirtualBox- Update to upstream- Allow clamscan read amavis spool files- Fixes for xguest- fix multiple directory ownership of mandirs- Update to upstream- Add rules for rtkit-daemon- Update to upstream - Fix nlscd_stream_connect- Add rtkit policy- Allow rpcd_t to stream connect to rpcbind- Allow kpropd to create tmp files- Fix last duplicate /var/log/rpmpkgs- Update to upstream * add sssd- Update to upstream * cleanup- Update to upstream - Additional mail ports - Add virt_use_usb boolean for svirt- Fix mcs rules to include chr_file and blk_file- Add label for udev-acl- Additional rules for consolekit/udev, privoxy and various other fixes- New version for upstream- Allow NetworkManager to read inotifyfs- Allow setroubleshoot to run mlocate- Update to upstream- Add fish as a shell - Allow fprintd to list usbfs_t - Allow consolekit to search mountpoints - Add proper labeling for shorewall- New log file for vmware - Allow xdm to setattr on user_tmp_t- Upgrade to upstream- Allow fprintd to access sys_ptrace - Add sandbox policy- Add varnishd policy- Fixes for kpropd- Allow brctl to r/w tun_tap_device_t- Add /usr/share/selinux/packages- Allow rpcd_t to send signals to kernel threads- Fix upgrade for F10 to F11- Add policy for /var/lib/fprint-Remove duplicate line- Allow svirt to manage pci and other sysfs device data- Fix package selection handling- Fix /sbin/ip6tables-save context - Allod udev to transition to mount - Fix loading of mls policy file- Add shorewall policy- Additional rules for fprintd and sssd- Allow nsplugin to unix_read unix_write sem for unconfined_java- Fix uml files to be owned by users- Fix Upgrade path to install unconfineduser.pp when unocnfined package is 3.0.0 or less- Allow confined users to manage virt_content_t, since this is home dir content - Allow all domains to read rpm_script_tmp_t which is what shell creates on redirection- Fix labeling on /var/lib/misc/prelink* - Allow xserver to rw_shm_perms with all x_clients - Allow prelink to execute files in the users home directory- Allow initrc_t to delete dev_null - Allow readahead to configure auditing - Fix milter policy - Add /var/lib/readahead- Update to latest milter code from Paul Howarth- Additional perms for readahead- Allow pulseaudio to acquire_svc on session bus - Fix readahead labeling- Allow sysadm_t to run rpm directly - libvirt needs fowner- Allow sshd to read var_lib symlinks for freenx- Allow nsplugin unix_read and write on users shm and sem - Allow sysadm_t to execute su- Dontaudit attempts to getattr user_tmpfs_t by lvm - Allow nfs to share removable media- Add ability to run postdrop from confined users- Fixes for podsleuth- Turn off nsplugin transition - Remove Konsole leaked file descriptors for release- Allow cupsd_t to create link files in print_spool_t - Fix iscsi_stream_connect typo - Fix labeling on /etc/acpi/actions - Don't reinstall unconfine and unconfineuser on upgrade if they are not installed- Allow audioentroy to read etc files- Add fail2ban_var_lib_t - Fixes for devicekit_power_t- Separate out the ucnonfined user from the unconfined.pp package- Make sure unconfined_java_t and unconfined_mono_t create user_tmpfs_t.- Upgrade to latest upstream - Allow devicekit_disk sys_rawio- Dontaudit binds to ports < 1024 for named - Upgrade to latest upstream- Allow podsleuth to use tmpfs files- Add customizable_types for svirt- Allow setroubelshoot exec* privs to prevent crash from bad libraries - add cpufreqselector- Dontaudit listing of /root directory for cron system jobs- Fix missing ld.so.cache label- Add label for ~/.forward and /root/.forward- Fixes for svirt- Fixes to allow svirt read iso files in homedir- Add xenner and wine fixes from mgrepl- Allow mdadm to read/write mls override- Change to svirt to only access svirt_image_t- Fix libvirt policy- Upgrade to latest upstream- Fixes for iscsid and sssd - More cleanups for upgrade from F10 to Rawhide.- Add pulseaudio, sssd policy - Allow networkmanager to exec udevadm- Add pulseaudio context- Upgrade to latest patches- Fixes for libvirt- Update to Latest upstream- Fix setrans.conf to show SystemLow for s0- Further confinement of qemu images via svirt- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- Allow NetworkManager to manage /etc/NetworkManager/system-connections- add virtual_image_context and virtual_domain_context files- Allow rpcd_t to send signal to mount_t - Allow libvirtd to run ranged- Fix sysnet/net_conf_t- Fix squidGuard labeling- Re-add corenet_in_generic_if(unlabeled_t)* Tue Feb 10 2009 Dan Walsh 3.6.5-2 - Add git web policy- Add setrans contains from upstream- Do transitions outside of the booleans- Allow xdm to create user_tmp_t sockets for switch user to work- Fix staff_t domain- Grab remainder of network_peer_controls patch- More fixes for devicekit- Upgrade to latest upstream- Add boolean to disallow unconfined_t login- Add back transition from xguest to mozilla- Add virt_content_ro_t and labeling for isos directory- Fixes for wicd daemon- More mls/rpm fixes- Add policy to make dbus/nm-applet work- Remove polgen-ifgen from post and add trigger to policycoreutils-python- Add wm policy - Make mls work in graphics mode- Fixed for DeviceKit- Add devicekit policy- Update to upstream- Define openoffice as an x_domain- Fixes for reading xserver_tmp_t- Allow cups_pdf_t write to nfs_t- Remove audio_entropy policy- Update to upstream- Allow hal_acl_t to getattr/setattr fixed_disk- Change userdom_read_all_users_state to include reading symbolic links in /proc- Fix dbus reading /proc information- Add missing alias for home directory content- Fixes for IBM java location- Allow unconfined_r unconfined_java_t- Add cron_role back to user domains- Fix sudo setting of user keys- Allow iptables to talk to terminals - Fixes for policy kit - lots of fixes for booting.- Cleanup policy- Rebuild for Python 2.6- Fix labeling on /var/spool/rsyslog- Allow postgresl to bind to udp nodes- Allow lvm to dbus chat with hal - Allow rlogind to read nfs_t- Fix cyphesis file context- Allow hal/pm-utils to look at /var/run/video.rom - Add ulogd policy- Additional fixes for cyphesis - Fix certmaster file context - Add policy for system-config-samba - Allow hal to read /var/run/video.rom- Allow dhcpc to restart ypbind - Fixup labeling in /var/run- Add certmaster policy- Fix confined users - Allow xguest to read/write xguest_dbusd_t- Allow openoffice execstack/execmem privs- Allow mozilla to run with unconfined_execmem_t- Dontaudit domains trying to write to .xsession-errors- Allow nsplugin to look at autofs_t directory- Allow kerneloops to create tmp files- More alias for fastcgi- Remove mod_fcgid-selinux package- Fix dovecot access- Policy cleanup- Remove Multiple spec - Add include - Fix makefile to not call per_role_expansion- Fix labeling of libGL- Update to upstream- Update to upstream policy- Fixes for confined xwindows and xdm_t- Allow confined users and xdm to exec wm - Allow nsplugin to talk to fifo files on nfs- Allow NetworkManager to transition to avahi and iptables - Allow domains to search other domains keys, coverup kernel bug- Fix labeling for oracle- Allow nsplugin to comminicate with xdm_tmp_t sock_file- Change all user tmpfs_t files to be labeled user_tmpfs_t - Allow radiusd to create sock_files- Upgrade to upstream- Allow confined users to login with dbus- Fix transition to nsplugin- Add file context for /dev/mspblk.*- Fix transition to nsplugin '- Fix labeling on new pm*log - Allow ssh to bind to all nodes- Merge upstream changes - Add Xavier Toth patches- Add qemu_cache_t for /var/cache/libvirt- Remove gamin policy- Add tinyxs-max file system support- Update to upstream - New handling of init scripts- Allow pcsd to dbus - Add memcache policy- Allow audit dispatcher to kill his children- Update to upstream - Fix crontab use by unconfined user- Allow ifconfig_t to read dhcpc_state_t- Update to upstream- Update to upstream- Allow system-config-selinux to work with policykit- Fix novel labeling- Consolodate pyzor,spamassassin, razor into one security domain - Fix xdm requiring additional perms.- Fixes for logrotate, alsa- Eliminate vbetool duplicate entry- Fix xguest -> xguest_mozilla_t -> xguest_openiffice_t - Change dhclient to be able to red networkmanager_var_run- Update to latest refpolicy - Fix libsemanage initial install bug- Add inotify support to nscd- Allow unconfined_t to setfcap- Allow amanda to read tape - Allow prewikka cgi to use syslog, allow audisp_t to signal cgi - Add support for netware file systems- Allow ypbind apps to net_bind_service- Allow all system domains and application domains to append to any log file- Allow gdm to read rpm database - Allow nsplugin to read mplayer config files- Allow vpnc to run ifconfig- Allow confined users to use postgres - Allow system_mail_t to exec other mail clients - Label mogrel_rails as an apache server- Apply unconfined_execmem_exec_t to haskell programs- Fix prelude file context- allow hplip to talk dbus - Fix context on ~/.local dir- Prevent applications from reading x_device- Add /var/lib/selinux context- Update to upstream- Add livecd policy- Dontaudit search of admin_home for init_system_domain - Rewrite of xace interfaces - Lots of new fs_list_inotify - Allow livecd to transition to setfiles_mac- Begin XAce integration- Merge Upstream- Allow amanada to create data files- Fix initial install, semanage setup- Allow system_r for httpd_unconfined_script_t- Remove dmesg boolean - Allow user domains to read/write game data- Change unconfined_t to transition to unconfined_mono_t when running mono - Change XXX_mono_t to transition to XXX_t when executing bin_t files, so gnome-do will work- Remove old booleans from targeted-booleans.conf file- Add boolean to mmap_zero - allow tor setgid - Allow gnomeclock to set clock- Don't run crontab from unconfined_t- Change etc files to config files to allow users to read them- Lots of fixes for confined domains on NFS_t homedir- dontaudit mrtg reading /proc - Allow iscsi to signal itself - Allow gnomeclock sys_ptrace- Allow dhcpd to read kernel network state- Label /var/run/gdm correctly - Fix unconfined_u user creation- Allow transition from initrc_t to getty_t- Allow passwd to communicate with user sockets to change gnome-keyring- Fix initial install- Allow radvd to use fifo_file - dontaudit setfiles reading links - allow semanage sys_resource - add allow_httpd_mod_auth_ntlm_winbind boolean - Allow privhome apps including dovecot read on nfs and cifs home dirs if the boolean is set- Allow nsplugin to read /etc/mozpluggerrc, user_fonts - Allow syslog to manage innd logs. - Allow procmail to ioctl spamd_exec_t- Allow initrc_t to dbus chat with consolekit.- Additional access for nsplugin - Allow xdm setcap/getcap until pulseaudio is fixed- Allow mount to mkdir on tmpfs - Allow ifconfig to search debugfs- Fix file context for MATLAB - Fixes for xace- Allow stunnel to transition to inetd children domains - Make unconfined_dbusd_t an unconfined domain- Fixes for qemu/virtd- Fix bug in mozilla policy to allow xguest transition - This will fix the libsemanage.dbase_llist_query: could not find record value libsemanage.dbase_llist_query: could not query record value (No such file or directory) bug in xguest- Allow nsplugin to run acroread- Add cups_pdf policy - Add openoffice policy to run in xguest- prewika needs to contact mysql - Allow syslog to read system_map files- Change init_t to an unconfined_domain- Allow init to transition to initrc_t on shell exec. - Fix init to be able to sendto init_t. - Allow syslog to connect to mysql - Allow lvm to manage its own fifo_files - Allow bugzilla to use ldap - More mls fixes- fixes for init policy (#436988) - fix build- Additional changes for MLS policy- Fix initrc_context generation for MLS- Fixes for libvirt- Allow bitlebee to read locale_t- More xselinux rules- Change httpd_$1_script_r*_t to httpd_$1_content_r*_t- Prepare policy for beta release - Change some of the system domains back to unconfined - Turn on some of the booleans- Allow nsplugin_config execstack/execmem - Allow nsplugin_t to read alsa config - Change apache to use user content- Add cyphesis policy- Fix Makefile.devel to build mls modules - Fix qemu to be more specific on labeling- Update to upstream fixes- Allow staff to mounton user_home_t- Add xace support- Add fusectl file system- Fixes from yum-cron - Update to latest upstream- Fix userdom_list_user_files- Merge with upstream- Allow udev to send audit messages- Add additional login users interfaces - userdom_admin_login_user_template(staff)- More fixes for polkit- Eliminate transition from unconfined_t to qemu by default - Fixes for gpg- Update to upstream- Fixes for staff_t- Add policy for kerneloops - Add policy for gnomeclock- Fixes for libvirt- Fixes for nsplugin- More fixes for qemu- Additional ports for vnc and allow qemu and libvirt to search all directories- Update to upstream - Add libvirt policy - add qemu policy- Allow fail2ban to create a socket in /var/run- Allow allow_httpd_mod_auth_pam to work- Add audisp policy and prelude- Allow all user roles to executae samba net command- Allow usertypes to read/write noxattr file systems- Fix nsplugin to allow flashplugin to work in enforcing mode- Allow pam_selinux_permit to kill all processes- Allow ptrace or user processes by users of same type - Add boolean for transition to nsplugin- Allow nsplugin sys_nice, getsched, setsched- Allow login programs to talk dbus to oddjob- Add procmail_log support - Lots of fixes for munin- Allow setroubleshoot to read policy config and send audit messages- Allow users to execute all files in homedir, if boolean set - Allow mount to read samba config- Fixes for xguest to run java plugin- dontaudit pam_t and dbusd writing to user_home_t- Update gpg to allow reading of inotify- Change user and staff roles to work correctly with varied perms- Fix munin log, - Eliminate duplicate mozilla file context - fix wpa_supplicant spec- Fix role transition from unconfined_r to system_r when running rpm - Allow unconfined_domains to communicate with user dbus instances- Fixes for xguest- Let all uncofined domains communicate with dbus unconfined- Run rpm in system_r- Zero out customizable types- Fix definiton of admin_home_t- Fix munin file context- Allow cron to run unconfined apps- Modify default login to unconfined_u- Dontaudit dbus user client search of /root- Update to upstream- Fixes for polkit - Allow xserver to ptrace- Add polkit policy - Symplify userdom context, remove automatic per_role changes- Update to upstream - Allow httpd_sys_script_t to search users homedirs- Allow rpm_script to transition to unconfined_execmem_t- Remove user based home directory separation- Remove user specific crond_t- Merge with upstream - Allow xsever to read hwdata_t - Allow login programs to setkeycreate- Update to upstream- Update to upstream- Allow XServer to read /proc/self/cmdline - Fix unconfined cron jobs - Allow fetchmail to transition to procmail - Fixes for hald_mac - Allow system_mail to transition to exim - Allow tftpd to upload files - Allow xdm to manage unconfined_tmp - Allow udef to read alsa config - Fix xguest to be able to connect to sound port- Fixes for hald_mac - Treat unconfined_home_dir_t as a home dir - dontaudit rhgb writes to fonts and root- Fix dnsmasq - Allow rshd full login privs- Allow rshd to connect to ports > 1023- Fix vpn to bind to port 4500 - Allow ssh to create shm - Add Kismet policy- Allow rpm to chat with networkmanager- Fixes for ipsec and exim mail - Change default to unconfined user- Pass the UNK_PERMS param to makefile - Fix gdm location- Make alsa work- Fixes for consolekit and startx sessions- Dontaudit consoletype talking to unconfined_t- Remove homedir_template- Check asound.state- Fix exim policy- Allow tmpreadper to read man_t - Allow racoon to bind to all nodes - Fixes for finger print reader- Allow xdm to talk to input device (fingerprint reader) - Allow octave to run as java- Allow login programs to set ioctl on /proc- Allow nsswitch apps to read samba_var_t- Fix maxima- Eliminate rpm_t:fifo_file avcs - Fix dbus path for helper app- Fix service start stop terminal avc's- Allow also to search var_lib - New context for dbus launcher- Allow cupsd_config_t to read/write usb_device_t - Support for finger print reader, - Many fixes for clvmd - dbus starting networkmanager- Fix java and mono to run in xguest account- Fix to add xguest account when inititial install - Allow mono, java, wine to run in userdomains- Allow xserver to search devpts_t - Dontaudit ldconfig output to homedir- Remove hplip_etc_t change back to etc_t.- Allow cron to search nfs and samba homedirs- Allow NetworkManager to dbus chat with yum-updated- Allow xfs to bind to port 7100- Allow newalias/sendmail dac_override - Allow bind to bind to all udp ports- Turn off direct transition- Allow wine to run in system role- Fix java labeling- Define user_home_type as home_type- Allow sendmail to create etc_aliases_t- Allow login programs to read symlinks on homedirs- Update an readd modules- Cleanup spec file- Allow xserver to be started by unconfined process and talk to tty- Upgrade to upstream to grab postgressql changes- Add setransd for mls policy- Add ldconfig_cache_t- Allow sshd to write to proc_t for afs login- Allow xserver access to urand- allow dovecot to search mountpoints- Fix Makefile for building policy modules- Fix dhcpc startup of service- Fix dbus chat to not happen for xguest and guest users- Fix nagios cgi - allow squid to communicate with winbind- Fixes for ldconfig- Update from upstream- Add nasd support- Fix new usb devices and dmfm- Eliminate mount_ntfs_t policy, merge into mount_t- Allow xserver to write to ramfs mounted by rhgb- Add context for dbus machine id- Update with latest changes from upstream- Fix prelink to handle execmod- Add ntpd_key_t to handle secret data- Add anon_inodefs - Allow unpriv user exec pam_exec_t - Fix trigger- Allow cups to use generic usb - fix inetd to be able to run random apps (git)- Add proper contexts for rsyslogd- Fixes for xguest policy- Allow execution of gconf- Fix moilscanner update problem- Begin adding policy to separate setsebool from semanage - Fix xserver.if definition to not break sepolgen.if- Add new devices- Add brctl policy- Fix root login to include system_r- Allow prelink to read kernel sysctls- Default to user_u:system_r:unconfined_t- fix squid - Fix rpm running as uid- Fix syslog declaration- Allow avahi to access inotify - Remove a lot of bogus security_t:filesystem avcs- Remove ifdef strict policy from upstream- Remove ifdef strict to allow user_u to login- Fix for amands - Allow semanage to read pp files - Allow rhgb to read xdm_xserver_tmp- Allow kerberos servers to use ldap for backing store- allow alsactl to read kernel state- More fixes for alsactl - Transition from hal and modutils - Fixes for suspend resume. - insmod domtrans to alsactl - insmod writes to hal log- Allow unconfined_t to transition to NetworkManager_t - Fix netlabel policy- Update to latest from upstream- Update to latest from upstream- Update to latest from upstream- Allow pcscd_t to send itself signals- Fixes for unix_update - Fix logwatch to be able to search all dirs- Upstream bumped the version- Allow consolekit to syslog - Allow ntfs to work with hal- Allow iptables to read etc_runtime_t- MLS Fixes- Fix path of /etc/lvm/cache directory - Fixes for alsactl and pppd_t - Fixes for consolekit- Allow insmod_t to mount kvmfs_t filesystems- Rwho policy - Fixes for consolekit- fixes for fusefs- Fix samba_net to allow it to view samba_var_t- Update to upstream- Fix Sonypic backlight - Allow snmp to look at squid_conf_t- Fixes for pyzor, cyrus, consoletype on everything installs- Fix hald_acl_t to be able to getattr/setattr on usb devices - Dontaudit write to unconfined_pipes for load_policy- Allow bluetooth to read inotifyfs- Fixes for samba domain controller. - Allow ConsoleKit to look at ttys- Fix interface call- Allow syslog-ng to read /var - Allow locate to getattr on all filesystems - nscd needs setcap- Update to upstream- Allow samba to run groupadd- Update to upstream- Allow mdadm to access generic scsi devices- Fix labeling on udev.tbl dirs- Fixes for logwatch- Add fusermount and mount_ntfs policy- Update to upstream - Allow saslauthd to use kerberos keytabs- Fixes for samba_var_t- Allow networkmanager to setpgid - Fixes for hal_acl_t- Remove disable_trans booleans - hald_acl_t needs to talk to nscd- Fix prelink to be able to manage usr dirs.- Allow insmod to launch init scripts- Remove setsebool policy- Fix handling of unlabled_t packets- More of my patches from upstream- Update to latest from upstream - Add fail2ban policy- Update to remove security_t:filesystem getattr problems- Policy for consolekit- Update to latest from upstream- Revert Nemiver change - Set sudo as a corecmd so prelink will work, remove sudoedit mapping, since this will not work, it does not transition. - Allow samba to execute useradd- Upgrade to the latest from upstream- Add sepolgen support - Add bugzilla policy- Fix file context for nemiver- Remove include sym link- Allow mozilla, evolution and thunderbird to read dev_random. Resolves: #227002 - Allow spamd to connect to smtp port Resolves: #227184 - Fixes to make ypxfr work Resolves: #227237- Fix ssh_agent to be marked as an executable - Allow Hal to rw sound device- Fix spamassisin so crond can update spam files - Fixes to allow kpasswd to work - Fixes for bluetooth- Remove some targeted diffs in file context file- Fix squid cachemgr labeling- Add ability to generate webadm_t policy - Lots of new interfaces for httpd - Allow sshd to login as unconfined_t- Continue fixing, additional user domains- Begin adding user confinement to targeted policy- Fixes for prelink, ktalkd, netlabel- Allow prelink when run from rpm to create tmp files Resolves: #221865 - Remove file_context for exportfs Resolves: #221181 - Allow spamassassin to create ~/.spamassissin Resolves: #203290 - Allow ssh access to the krb tickets - Allow sshd to change passwd - Stop newrole -l from working on non securetty Resolves: #200110 - Fixes to run prelink in MLS machine Resolves: #221233 - Allow spamassassin to read var_lib_t dir Resolves: #219234- fix mplayer to work under strict policy - Allow iptables to use nscd Resolves: #220794- Add gconf policy and make it work with strict- Many fixes for strict policy and by extension mls.- Fix to allow ftp to bind to ports > 1024 Resolves: #219349- Allow semanage to exec it self. Label genhomedircon as semanage_exec_t Resolves: #219421 - Allow sysadm_lpr_t to manage other print spool jobs Resolves: #220080- allow automount to setgid Resolves: #219999- Allow cron to polyinstatiate - Fix creation of boot flags Resolves: #207433- Fixes for irqbalance Resolves: #219606- Fix vixie-cron to work on mls Resolves: #207433Resolves: #218978- Allow initrc to create files in /var directories Resolves: #219227- More fixes for MLS Resolves: #181566- More Fixes polyinstatiation Resolves: #216184- More Fixes polyinstatiation - Fix handling of keyrings Resolves: #216184- Fix polyinstatiation - Fix pcscd handling of terminal Resolves: #218149 Resolves: #218350- More fixes for quota Resolves: #212957- ncsd needs to use avahi sockets Resolves: #217640 Resolves: #218014- Allow login programs to polyinstatiate homedirs Resolves: #216184 - Allow quotacheck to create database files Resolves: #212957- Dontaudit appending hal_var_lib files Resolves: #217452 Resolves: #217571 Resolves: #217611 Resolves: #217640 Resolves: #217725- Fix context for helix players file_context #216942- Fix load_policy to be able to mls_write_down so it can talk to the terminal- Fixes for hwclock, clamav, ftp- Move to upstream version which accepted my patches- Fixes for nvidia driver- Allow semanage to signal mcstrans- Update to upstream- Allow modstorage to edit /etc/fstab file- Fix for qemu, /dev/- Fix path to realplayer.bin- Allow xen to connect to xen port- Allow cups to search samba_etc_t directory - Allow xend_t to list auto_mountpoints- Allow xen to search automount- Fix spec of jre files- Fix unconfined access to shadow file- Allow xend to create files in xen_image_t directories- Fixes for /var/lib/hal- Remove ability for sysadm_t to look at audit.log- Fix rpc_port_types - Add aide policy for mls- Merge with upstream- Lots of fixes for ricci- Allow xen to read/write fixed devices with a boolean - Allow apache to search /var/log- Fix policygentool specfile problem. - Allow apache to send signals to it's logging helpers. - Resolves: rhbz#212731- Add perms for swat- Add perms for swat- Allow daemons to dump core files to /- Fixes for ricci- Allow mount.nfs to work- Allow ricci-modstorage to look at lvm_etc_t- Fixes for ricci using saslauthd- Allow mountpoint on home_dir_t and home_t- Update xen to read nfs files- Allow noxattrfs to associate with other noxattrfs- Allow hal to use power_device_t- Allow procemail to look at autofs_t - Allow xen_image_t to work as a fixed device- Refupdate from upstream- Add lots of fixes for mls cups- Lots of fixes for ricci- Fix number of cats- Update to upstream- More iSCSI changes for #209854- Test ISCSI fixes for #209854- allow semodule to rmdir selinux_config_t dir- Fix boot_runtime_t problem on ppc. Should not be creating these files.- Fix context mounts on reboot - Fix ccs creation of directory in /var/log- Update for tallylog- Allow xend to rewrite dhcp conf files - Allow mgetty sys_admin capability- Make xentapctrl work- Don't transition unconfined_t to bootloader_t - Fix label in /dev/xen/blktap- Patch for labeled networking- Fix crond handling for mls- Update to upstream- Remove bluetooth-helper transition - Add selinux_validate for semanage - Require new version of libsemanage- Fix prelink- Fix rhgb- Fix setrans handling on MLS and useradd- Support for fuse - fix vigr- Fix dovecot, amanda - Fix mls- Allow java execheap for itanium- Update with upstream- mls fixes- Update from upstream- More fixes for mls - Revert change on automount transition to mount- Fix cron jobs to run under the correct context- Fixes to make pppd work- Multiple policy fixes - Change max categories to 1023- Fix transition on mcstransd- Add /dev/em8300 defs- Upgrade to upstream- Fix ppp connections from network manager- Add tty access to all domains boolean - Fix gnome-pty-helper context for ia64- Fixed typealias of firstboot_rw_t- Fix location of xel log files - Fix handling of sysadm_r -> rpm_exec_t- Fixes for autofs, lp- Update from upstream- Fixup for test6- Update to upstream- Update to upstream- Fix suspend to disk problems- Lots of fixes for restarting daemons at the console.- Fix audit line - Fix requires line- Upgrade to upstream- Fix install problems- Allow setroubleshoot to getattr on all dirs to gather RPM data- Set /usr/lib/ia32el/ia32x_loader to unconfined_execmem_exec_t for ia32 platform - Fix spec for /dev/adsp- Fix xen tty devices- Fixes for setroubleshoot- Update to upstream- Fixes for stunnel and postgresql - Update from upstream- Update from upstream - More java fixes- Change allow_execstack to default to on, for RHEL5 Beta. This is required because of a Java compiler problem. Hope to turn off for next beta- Misc fixes- More fixes for strict policy- Quiet down anaconda audit messages- Fix setroubleshootd- Update to the latest from upstream- More fixes for xen- Fix anaconda transitions- yet more xen rules- more xen rules- Fixes for Samba- Fixes for xen- Allow setroubleshootd to send mail- Add nagios policy- fixes for setroubleshoot- Added Paul Howarth patch to only load policy packages shipped with this package - Allow pidof from initrc to ptrace higher level domains - Allow firstboot to communicate with hal via dbus- Add policy for /var/run/ldapi- Fix setroubleshoot policy- Fixes for mls use of ssh - named has a new conf file- Fixes to make setroubleshoot work- Cups needs to be able to read domain state off of printer client- add boolean to allow zebra to write config files- setroubleshootd fixes- Allow prelink to read bin_t symlink - allow xfs to read random devices - Change gfs to support xattr- Remove spamassassin_can_network boolean- Update to upstream - Fix lpr domain for mls- Add setroubleshoot policy- Turn off auditallow on setting booleans- Multiple fixes- Update to upstream- Update to upstream - Add new class for kernel key ring- Update to upstream- Update to upstream- Break out selinux-devel package- Add ibmasmfs- Fix policygentool gen_requires- Update from Upstream- Fix spec of realplay- Update to upstream- Fix semanage- Allow useradd to create_home_dir in MLS environment- Update from upstream- Update from upstream- Add oprofilefs- Fix for hplip and Picasus- Update to upstream- Update to upstream- fixes for spamd- fixes for java, openldap and webalizer- Xen fixes- Upgrade to upstream- allow hal to read boot_t files - Upgrade to upstream- allow hal to read boot_t files- Update from upstream- Fixes for amavis- Update from upstream- Allow auditctl to search all directories- Add acquire service for mono.- Turn off allow_execmem boolean - Allow ftp dac_override when allowed to access users homedirs- Clean up spec file - Transition from unconfined_t to prelink_t- Allow execution of cvs command- Update to upstream- Update to upstream- Fix libjvm spec- Update to upstream- Add xm policy - Fix policygentool- Update to upstream - Fix postun to only disable selinux on full removal of the packages- Allow mono to chat with unconfined- Allow procmail to sendmail - Allow nfs to share dosfs- Update to latest from upstream - Allow selinux-policy to be removed and kernel not to crash- Update to latest from upstream - Add James Antill patch for xen - Many fixes for pegasus- Add unconfined_mount_t - Allow privoxy to connect to httpd_cache - fix cups labeleing on /var/cache/cups- Update to latest from upstream- Update to latest from upstream - Allow mono and unconfined to talk to initrc_t dbus objects- Change libraries.fc to stop shlib_t form overriding texrel_shlib_t- Fix samba creating dirs in homedir - Fix NFS so its booleans would work- Allow secadm_t ability to relabel all files - Allow ftp to search xferlog_t directories - Allow mysql to communicate with ldap - Allow rsync to bind to rsync_port_t- Fixed mailman with Postfix #183928 - Allowed semanage to create file_context files. - Allowed amanda_t to access inetd_t TCP sockets and allowed amanda_recover_t to bind to reserved ports. #149030 - Don't allow devpts_t to be associated with tmp_t. - Allow hald_t to stat all mountpoints. - Added boolean samba_share_nfs to allow smbd_t full access to NFS mounts. - Make mount run in mount_t domain from unconfined_t to prevent mislabeling of /etc/mtab. - Changed the file_contexts to not have a regex before the first ^/[a-z]/ whenever possible, makes restorecon slightly faster. - Correct the label of /etc/named.caching-nameserver.conf - Now label /usr/src/kernels/.+/lib(/.*)? as usr_t instead of /usr/src(/.*)?/lib(/.*)? - I don't think we need anything else under /usr/src hit by this. - Granted xen access to /boot, allowed mounting on xend_var_lib_t, and allowed xenstored_t rw access to the xen device node.- More textrel_shlib_t file path fixes - Add ada support- Get auditctl working in MLS policy- Add mono dbus support - Lots of file_context fixes for textrel_shlib_t in FC5 - Turn off execmem auditallow since they are filling log files- Update to upstream- Allow automount and dbus to read cert files- Fix ftp policy - Fix secadm running of auditctl- Update to upstream- Update to upstream- Fix policyhelp- Fix pam_console handling of usb_device - dontaudit logwatch reading /mnt dir- Update to upstream- Get transition rules to create policy.20 at SystemHigh- Allow secadmin to shutdown system - Allow sendmail to exec newalias- MLS Fixes dmidecode needs mls_file_read_up - add ypxfr_t - run init needs access to nscd - udev needs setuid - another xen log file - Dontaudit mount getattr proc_kcore_t- fix buildroot usage (#185391)- Get rid of mount/fsdisk scan of /dev messages - Additional fixes for suspend/resume- Fake make to rebuild enableaudit.pp- Get xen networking running.- Fixes for Xen - enableaudit should not be the same as base.pp - Allow ps to work for all process- more xen policy fixups- more xen fixage (#184393)- Fix blkid specification - Allow postfix to execute mailman_que- Blkid changes - Allow udev access to usb_device_t - Fix post script to create targeted policy config file- Allow lvm tools to create drevice dir- Add Xen support- Fixes for cups - Make cryptosetup work with hal- Load Policy needs translock- Fix cups html interface- Add hal changes suggested by Jeremy - add policyhelp to point at policy html pages- Additional fixes for nvidia and cups- Update to upstream - Merged my latest fixes - Fix cups policy to handle unix domain sockets- NSCD socket is in nscd_var_run_t needs to be able to search dir- Fixes Apache interface file- Fixes for new version of cups- Turn off polyinstatiate util after FC5- Fix problem with privoxy talking to Tor- Turn on polyinstatiation- Don't transition from unconfined_t to fsadm_t- Fix policy update model.- Update to upstream- Fix load_policy to work on MLS - Fix cron_rw_system_pipes for postfix_postdrop_t - Allow audotmount to run showmount- Fix swapon - allow httpd_sys_script_t to be entered via a shell - Allow httpd_sys_script_t to read eventpolfs- Update from upstream- allow cron to read apache files- Fix vpnc policy to work from NetworkManager- Update to upstream - Fix semoudle polcy- Update to upstream - fix sysconfig/selinux link- Add router port for zebra - Add imaze port for spamd - Fixes for amanda and java- Fix bluetooth handling of usb devices - Fix spamd reading of ~/ - fix nvidia spec- Update to upsteam- Add users_extra files- Update to upstream- Add semodule policy- Update from upstream- Fix for spamd to use razor port- Fixes for mcs - Turn on mount and fsadm for unconfined_t- Fixes for the -devel package- Fix for spamd to use ldap- Update to upstream- Update to upstream - Fix rhgb, and other Xorg startups- Update to upstream- Separate out role of secadm for mls- Add inotifyfs handling- Update to upstream - Put back in changes for pup/zen- Many changes for MLS - Turn on strict policy- Update to upstream- Update to upstream - Fixes for booting and logging in on MLS machine- Update to upstream - Turn off execheap execstack for unconfined users - Add mono/wine policy to allow execheap and execstack for them - Add execheap for Xdm policy- Update to upstream - Fixes to fetchmail,- Update to upstream- Fix for procmail/spamassasin - Update to upstream - Add rules to allow rpcd to work with unlabeled_networks.- Update to upstream - Fix ftp Man page- Update to upstream- fix pup transitions (#177262) - fix xen disks (#177599)- Update to upstream- More Fixes for hal and readahead- Fixes for hal and readahead- Update to upstream - Apply- Add wine and fix hal problems- Handle new location of hal scripts- Allow su to read /etc/mtab- Update to upstream- Fix "libsemanage.parse_module_headers: Data did not represent a module." problem- Allow load_policy to read /etc/mtab- Fix dovecot to allow dovecot_auth to look at /tmp- Allow restorecon to read unlabeled_t directories in order to fix labeling.- Add Logwatch policy- Fix /dev/ub[a-z] file context- Fix library specification - Give kudzu execmem privs- Fix hostname in targeted policy- Fix passwd command on mls- Lots of fixes to make mls policy work- Add dri libs to textrel_shlib_t - Add system_r role for java - Add unconfined_exec_t for vncserver - Allow slapd to use kerberos- Add man pages- Add enableaudit.pp- Fix mls policy- Update mls file from old version- Add sids back in - Rebuild with update checkpolicy- Fixes to allow automount to use portmap - Fixes to start kernel in s0-s15:c0.c255- Add java unconfined/execmem policy- Add file context for /var/cvs - Dontaudit webalizer search of homedir- Update from upstream- Clean up spec - range_transition crond to SystemHigh- Fixes for hal - Update to upstream- Turn back on execmem since we need it for java, firefox, ooffice - Allow gpm to stream socket to itself- fix requirements to be on the actual packages so that policy can get created properly at install time- Allow unconfined_t to execmod texrel_shlib_t- Update to upstream - Turn off allow_execmem and allow_execmod booleans - Add tcpd and automount policies- Add two new httpd booleans, turned off by default * httpd_can_network_relay * httpd_can_network_connect_db- Add ghost for policy.20- Update to upstream - Turn off boolean allow_execstack- Change setrans-mls to use new libsetrans - Add default_context rule for xdm- Change Requires to PreReg for requiring of policycoreutils on install- New upstream releaseAdd xdm policyUpdate from upstreamUpdate from upstreamUpdate from upstream- Also trigger to rebuild policy for versions up to 2.0.7.- No longer installing policy.20 file, anaconda handles the building of the app.- Fixes for dovecot and saslauthd- Cleanup pegasus and named - Fix spec file - Fix up passwd changing applications-Update to latest from upstream- Add rules for pegasus and avahi- Start building MLS Policy- Update to upstream- Turn on bash- Initial version/bin/sh  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,,./0123456789:;<=>?@ABCDEFGHIJKL3.13.1-229.el7    develMakefileexample.fcexample.ifexample.tehtmlNetworkManager.htmlabrt.htmlabrt_dump_oops.htmlabrt_handle_event.htmlabrt_helper.htmlabrt_retrace_coredump.htmlabrt_retrace_worker.htmlabrt_upload_watch.htmlabrt_watch_log.htmlaccountsd.htmlacct.htmladmin_crontab.htmlafs.htmlafs_bosserver.htmlafs_fsserver.htmlafs_kaserver.htmlafs_ptserver.htmlafs_vlserver.htmlaiccu.htmlaide.htmlajaxterm.htmlajaxterm_ssh.htmlalsa.htmlamanda.htmlamanda_recover.htmlamtu.htmlanaconda.htmlanon_sftpd.htmlantivirus.htmlapcupsd.htmlapcupsd_cgi_script.htmlapm.htmlapmd.htmlarpwatch.htmlasterisk.htmlaudisp.htmlaudisp_remote.htmlauditadm.htmlauditadm_screen.htmlauditadm_su.htmlauditadm_sudo.htmlauditctl.htmlauditd.htmlauthconfig.htmlautomount.htmlavahi.htmlawstats.htmlawstats_script.htmlbacula.htmlbacula_admin.htmlbacula_unconfined_script.htmlbcfg2.htmlbitlbee.htmlblkmapd.htmlblktap.htmlblueman.htmlbluetooth.htmlbluetooth_helper.htmlboinc.htmlboinc_project.htmlbootloader.htmlbrctl.htmlbrltty.htmlbugzilla_script.htmlbumblebee.htmlcachefiles_kernel.htmlcachefilesd.htmlcalamaris.htmlcallweaver.htmlcanna.htmlcardmgr.htmlccs.htmlcdcc.htmlcdrecord.htmlcertmaster.htmlcertmonger.htmlcertmonger_unconfined.htmlcertwatch.htmlcfengine_execd.htmlcfengine_monitord.htmlcfengine_serverd.htmlcgclear.htmlcgconfig.htmlcgdcbxd.htmlcgred.htmlcheckpc.htmlcheckpolicy.htmlchfn.htmlchkpwd.htmlchrome_sandbox.htmlchrome_sandbox_nacl.htmlchronyc.htmlchronyd.htmlchroot_user.htmlcinder_api.htmlcinder_backup.htmlcinder_scheduler.htmlcinder_volume.htmlciped.htmlclogd.htmlcloud_init.htmlcluster.htmlclvmd.htmlcmirrord.htmlcobblerd.htmlcockpit_session.htmlcockpit_ws.htmlcollectd.htmlcollectd_script.htmlcolord.htmlcomsat.htmlcondor_collector.htmlcondor_master.htmlcondor_negotiator.htmlcondor_procd.htmlcondor_schedd.htmlcondor_startd.htmlcondor_startd_ssh.htmlconman.htmlconman_unconfined_script.htmlconsolekit.htmlcontainer.htmlcontainer_auth.htmlcontainer_runtime.htmlcouchdb.htmlcourier_authdaemon.htmlcourier_pcp.htmlcourier_pop.htmlcourier_sqwebmail.htmlcourier_tcpd.htmlcpucontrol.htmlcpufreqselector.htmlcpuplug.htmlcpuspeed.htmlcrack.htmlcrond.htmlcronjob.htmlcrontab.htmlctdbd.htmlcups_pdf.htmlcupsd.htmlcupsd_config.htmlcupsd_lpd.htmlcvs.htmlcvs_script.htmlcyphesis.htmlcyrus.htmldbadm.htmldbadm_sudo.htmldbskkd.htmldcc_client.htmldcc_dbclean.htmldccd.htmldccifd.htmldccm.htmldcerpcd.htmlddclient.htmldeltacloudd.htmldenyhosts.htmldepmod.htmldevicekit.htmldevicekit_disk.htmldevicekit_power.htmldhcpc.htmldhcpd.htmldictd.htmldirsrv.htmldirsrv_snmp.htmldirsrvadmin.htmldirsrvadmin_script.htmldirsrvadmin_unconfined_script.htmldisk_munin_plugin.htmldkim_milter.htmldlm_controld.htmldmesg.htmldmidecode.htmldnsmasq.htmldnssec_trigger.htmldovecot.htmldovecot_auth.htmldovecot_deliver.htmldrbd.htmldspam.htmldspam_script.htmlentropyd.htmleventlogd.htmlevtchnd.htmlexim.htmlfail2ban.htmlfail2ban_client.htmlfcoemon.htmlfenced.htmlfetchmail.htmlfingerd.htmlfirewalld.htmlfirewallgui.htmlfirstboot.htmlfoghorn.htmlfprintd.htmlfreeipmi_bmc_watchdog.htmlfreeipmi_ipmidetectd.htmlfreeipmi_ipmiseld.htmlfreqset.htmlfsadm.htmlfsdaemon.htmlftpd.htmlftpdctl.htmlgames.htmlgames_srv.htmlgconfd.htmlgconfdefaultsm.htmlgdomap.htmlgeoclue.htmlgetty.htmlgfs_controld.htmlgit_script.htmlgit_session.htmlgit_system.htmlgitosis.htmlglance_api.htmlglance_registry.htmlglance_scrubber.htmlglusterd.htmlgnomesystemmm.htmlgpg.htmlgpg_agent.htmlgpg_helper.htmlgpg_pinentry.htmlgpg_web.htmlgpm.htmlgpsd.htmlgreylist_milter.htmlgroupadd.htmlgroupd.htmlgssd.htmlgssproxy.htmlguest.htmlhaproxy.htmlhddtemp.htmlhostname.htmlhsqldb.htmlhttpd.htmlhttpd_helper.htmlhttpd_passwd.htmlhttpd_php.htmlhttpd_rotatelogs.htmlhttpd_suexec.htmlhttpd_sys_script.htmlhttpd_unconfined_script.htmlhttpd_user_script.htmlhwclock.htmlhwloc_dhwd.htmlhypervkvp.htmlhypervvssd.htmliceauth.htmlicecast.htmlifconfig.htmlindex.htmlinetd.htmlinetd_child.htmlinit.htmlinitrc.htmlinnd.htmlinsmod.htmlinstall.htmliodined.htmliotop.htmlipa_dnskey.htmlipa_helper.htmlipa_otpd.htmlipmievd.htmlipsec.htmlipsec_mgmt.htmliptables.htmlirc.htmlirqbalance.htmlirssi.htmliscsid.htmlisnsd.htmliwhd.htmljabberd.htmljabberd_router.htmljockey.htmljournalctl.htmlkadmind.htmlkdump.htmlkdumpctl.htmlkdumpgui.htmlkeepalived.htmlkeepalived_unconfined_script.htmlkernel.htmlkeyboardd.htmlkeystone.htmlkeystone_cgi_script.htmlkismet.htmlklogd.htmlkmscon.htmlkpropd.htmlkrb5kdc.htmlksmtuned.htmlktalkd.htmll2tpd.htmlldconfig.htmllircd.htmllivecd.htmllldpad.htmlload_policy.htmlloadkeys.htmllocal_login.htmllocate.htmllockdev.htmllogadm.htmllogrotate.htmllogrotate_mail.htmllogwatch.htmllogwatch_mail.htmllpd.htmllpr.htmllsassd.htmllsmd.htmllsmd_plugin.htmllttng_sessiond.htmllvm.htmllwiod.htmllwregd.htmllwsmd.htmlmail_munin_plugin.htmlmailman_cgi.htmlmailman_mail.htmlmailman_queue.htmlman2html_script.htmlmandb.htmlmcelog.htmlmdadm.htmlmediawiki_script.htmlmemcached.htmlmencoder.htmlminidlna.htmlminissdpd.htmlmip6d.htmlmirrormanager.htmlmock.htmlmock_build.htmlmodemmanager.htmlmojomojo_script.htmlmon_procd.htmlmon_statd.htmlmongod.htmlmotion.htmlmount.htmlmount_ecryptfs.htmlmozilla.htmlmozilla_plugin.htmlmozilla_plugin_config.htmlmpd.htmlmplayer.htmlmrtg.htmlmscan.htmlmunin.htmlmunin_script.htmlmysqld.htmlmysqld_safe.htmlmysqlmanagerd.htmlmythtv_script.htmlnagios.htmlnagios_admin_plugin.htmlnagios_checkdisk_plugin.htmlnagios_eventhandler_plugin.htmlnagios_mail_plugin.htmlnagios_openshift_plugin.htmlnagios_script.htmlnagios_services_plugin.htmlnagios_system_plugin.htmlnagios_unconfined_plugin.htmlnamed.htmlnamespace_init.htmlncftool.htmlndc.htmlnetlabel_mgmt.htmlnetlogond.htmlnetutils.htmlneutron.htmlnewrole.htmlnfsd.htmlninfod.htmlnmbd.htmlnova.htmlnrpe.htmlnscd.htmlnsd.htmlnsd_crond.htmlnslcd.htmlntop.htmlntpd.htmlnumad.htmlnut_upsd.htmlnut_upsdrvctl.htmlnut_upsmon.htmlnutups_cgi_script.htmlnx_server.htmlnx_server_ssh.htmlobex.htmloddjob.htmloddjob_mkhomedir.htmlopenct.htmlopendnssec.htmlopenhpid.htmlopenshift.htmlopenshift_app.htmlopenshift_cgroup_read.htmlopenshift_cron.htmlopenshift_initrc.htmlopenshift_net_read.htmlopenshift_script.htmlopensm.htmlopenvpn.htmlopenvpn_unconfined_script.htmlopenvswitch.htmlopenwsman.htmloracleasm.htmlosad.htmlpads.htmlpam_console.htmlpam_timestamp.htmlpassenger.htmlpasswd.htmlpcp_pmcd.htmlpcp_pmie.htmlpcp_pmlogger.htmlpcp_pmmgr.htmlpcp_pmproxy.htmlpcp_pmwebd.htmlpcscd.htmlpegasus.htmlpegasus_openlmi_account.htmlpegasus_openlmi_admin.htmlpegasus_openlmi_logicalfile.htmlpegasus_openlmi_services.htmlpegasus_openlmi_storage.htmlpegasus_openlmi_system.htmlpegasus_openlmi_unconfined.htmlpesign.htmlphc2sys.htmlping.htmlpingd.htmlpiranha_fos.htmlpiranha_lvs.htmlpiranha_pulse.htmlpiranha_web.htmlpkcs_slotd.htmlpki_ra.htmlpki_tomcat.htmlpki_tomcat_script.htmlpki_tps.htmlplymouth.htmlplymouthd.htmlpodsleuth.htmlpolicykit.htmlpolicykit_auth.htmlpolicykit_grant.htmlpolicykit_resolve.htmlpolipo.htmlpolipo_session.htmlportmap.htmlportmap_helper.htmlportreserve.htmlpostfix_bounce.htmlpostfix_cleanup.htmlpostfix_local.htmlpostfix_map.htmlpostfix_master.htmlpostfix_pickup.htmlpostfix_pipe.htmlpostfix_postdrop.htmlpostfix_postqueue.htmlpostfix_qmgr.htmlpostfix_showq.htmlpostfix_smtp.htmlpostfix_smtpd.htmlpostfix_virtual.htmlpostgresql.htmlpostgrey.htmlpppd.htmlpptp.htmlprelink.htmlprelink_cron_system.htmlprelude.htmlprelude_audisp.htmlprelude_correlator.htmlprelude_lml.htmlpreupgrade.htmlprewikka_script.htmlprivoxy.htmlprocmail.htmlprosody.htmlpsad.htmlptal.htmlptchown.htmlptp4l.htmlpublicfile.htmlpulseaudio.htmlpuppetagent.htmlpuppetca.htmlpuppetmaster.htmlpwauth.htmlpyicqt.htmlqdiskd.htmlqemu_dm.htmlqmail_clean.htmlqmail_inject.htmlqmail_local.htmlqmail_lspawn.htmlqmail_queue.htmlqmail_remote.htmlqmail_rspawn.htmlqmail_send.htmlqmail_smtpd.htmlqmail_splogger.htmlqmail_start.htmlqmail_tcp_env.htmlqpidd.htmlquota.htmlquota_nld.htmlrabbitmq.htmlracoon.htmlradiusd.htmlradvd.htmlrasdaemon.htmlrdisc.htmlreadahead.htmlrealmd.htmlrealmd_consolehelper.htmlredis.htmlregex_milter.htmlremote_login.htmlrestorecond.htmlrhev_agentd.htmlrhev_agentd_consolehelper.htmlrhgb.htmlrhnsd.htmlrhsmcertd.htmlricci.htmlricci_modcluster.htmlricci_modclusterd.htmlricci_modlog.htmlricci_modrpm.htmlricci_modservice.htmlricci_modstorage.htmlrlogind.htmlrngd.htmlroundup.htmlrpcbind.htmlrpcd.htmlrpm.htmlrpm_script.htmlrshd.htmlrssh.htmlrssh_chroot_helper.htmlrsync.htmlrtas_errd.htmlrtkit_daemon.htmlrun_init.htmlrwho.htmlsamba_net.htmlsamba_unconfined_net.htmlsamba_unconfined_script.htmlsambagui.htmlsandbox.htmlsandbox_min.htmlsandbox_min_client.htmlsandbox_net.htmlsandbox_net_client.htmlsandbox_web.htmlsandbox_web_client.htmlsandbox_x.htmlsandbox_x_client.htmlsandbox_xserver.htmlsanlk_resetd.htmlsanlock.htmlsaslauthd.htmlsbd.htmlsblim_gatherd.htmlsblim_reposd.htmlsblim_sfcbd.htmlsecadm.htmlsecadm_screen.htmlsecadm_su.htmlsecadm_sudo.htmlsectoolm.htmlselinux_munin_plugin.htmlsemanage.htmlsendmail.htmlsensord.htmlsepgsql_ranged_proc.htmlsepgsql_trusted_proc.htmlservices_munin_plugin.htmlsetfiles.htmlsetfiles_mac.htmlsetkey.htmlsetrans.htmlsetroubleshoot_fixit.htmlsetroubleshootd.htmlsetsebool.htmlsftpd.htmlsge_execd.htmlsge_job.htmlsge_job_ssh.htmlsge_shepherd.htmlshorewall.htmlshowmount.htmlslapd.htmlslpd.htmlsmbcontrol.htmlsmbd.htmlsmbmount.htmlsmokeping.htmlsmokeping_cgi_script.htmlsmoltclient.htmlsmsd.htmlsnapperd.htmlsnmpd.htmlsnort.htmlsosreport.htmlsoundd.htmlspamass_milter.htmlspamc.htmlspamd.htmlspamd_update.htmlspc.htmlspeech-dispatcher.htmlsquid.htmlsquid_cron.htmlsquid_script.htmlsrvsvcd.htmlssh.htmlssh_keygen.htmlssh_keysign.htmlsshd.htmlsshd_keygen.htmlsshd_net.htmlsshd_sandbox.htmlsssd.htmlsssd_selinux_manager.htmlstaff.htmlstaff_consolehelper.htmlstaff_dbusd.htmlstaff_gkeyringd.htmlstaff_screen.htmlstaff_seunshare.htmlstaff_ssh_agent.htmlstaff_sudo.htmlstaff_wine.htmlstapserver.htmlstunnel.htmlstyle.csssulogin.htmlsvc_multilog.htmlsvc_run.htmlsvc_start.htmlsvirt.htmlsvirt_kvm_net.htmlsvirt_qemu_net.htmlsvirt_socket.htmlsvirt_tcg.htmlsvnserve.htmlswat.htmlswift.htmlsysadm.htmlsysadm_gkeyringd.htmlsysadm_passwd.htmlsysadm_screen.htmlsysadm_seunshare.htmlsysadm_ssh_agent.htmlsysadm_su.htmlsysadm_sudo.htmlsyslogd.htmlsysstat.htmlsystem_cronjob.htmlsystem_dbusd.htmlsystem_mail.htmlsystem_munin_plugin.htmlsystemd_bootchart.htmlsystemd_hostnamed.htmlsystemd_hwdb.htmlsystemd_initctl.htmlsystemd_localed.htmlsystemd_logger.htmlsystemd_logind.htmlsystemd_machined.htmlsystemd_networkd.htmlsystemd_notify.htmlsystemd_passwd_agent.htmlsystemd_resolved.htmlsystemd_sysctl.htmlsystemd_timedated.htmlsystemd_tmpfiles.htmltangd.htmltargetd.htmltcpd.htmltcsd.htmltelepathy_gabble.htmltelepathy_idle.htmltelepathy_logger.htmltelepathy_mission_control.htmltelepathy_msn.htmltelepathy_salut.htmltelepathy_sofiasip.htmltelepathy_stream_engine.htmltelepathy_sunshine.htmltelnetd.htmltftpd.htmltgtd.htmlthin.htmlthin_aeolus_configserver.htmlthumb.htmltimemaster.htmltlp.htmltmpreaper.htmltomcat.htmltor.htmltraceroute.htmltuned.htmltvtime.htmludev.htmlulogd.htmluml.htmluml_switch.htmlunconfined.htmlunconfined_cronjob.htmlunconfined_dbusd.htmlunconfined_mount.htmlunconfined_munin_plugin.htmlunconfined_sendmail.htmlunconfined_service.htmlupdate_modules.htmlupdfstab.htmlupdpwd.htmlusbmodules.htmlusbmuxd.htmluser.htmluser_dbusd.htmluser_gkeyringd.htmluser_mail.htmluser_screen.htmluser_seunshare.htmluser_ssh_agent.htmluser_wine.htmluseradd.htmlusernetctl.htmlutempter.htmluucpd.htmluuidd.htmluux.htmlvarnishd.htmlvarnishlog.htmlvdagent.htmlvhostmd.htmlvirsh.htmlvirsh_ssh.htmlvirt_bridgehelper.htmlvirt_qemu_ga.htmlvirt_qemu_ga_unconfined.htmlvirt_qmf.htmlvirtd.htmlvirtd_lxc.htmlvirtlogd.htmlvlock.htmlvmtools.htmlvmtools_helper.htmlvmtools_unconfined.htmlvmware.htmlvmware_host.htmlvnstat.htmlvnstatd.htmlvpnc.htmlw3c_validator_script.htmlwatchdog.htmlwatchdog_unconfined.htmlwdmd.htmlwebadm.htmlwebalizer.htmlwebalizer_script.htmlwinbind.htmlwinbind_helper.htmlwine.htmlwireshark.htmlwpa_cli.htmlxauth.htmlxdm.htmlxdm_unconfined.htmlxenconsoled.htmlxend.htmlxenstored.htmlxguest.htmlxguest_dbusd.htmlxguest_gkeyringd.htmlxserver.htmlypbind.htmlyppasswdd.htmlypserv.htmlypxfr.htmlzabbix.htmlzabbix_agent.htmlzabbix_script.htmlzarafa_deliver.htmlzarafa_gateway.htmlzarafa_ical.htmlzarafa_indexer.htmlzarafa_monitor.htmlzarafa_server.htmlzarafa_spooler.htmlzebra.htmlzoneminder.htmlzoneminder_script.htmlzos_remote.htmlincludeMakefileadminadmin.xmlbootloader.ifconsoletype.ifdmesg.ifnetutils.ifsu.ifsudo.ifusermanage.ifappsapps.xmlseunshare.ifbuild.confcontribcontrib.xmlabrt.ifaccountsd.ifacct.ifada.ifafs.ifaiccu.ifaide.ifaisexec.ifajaxterm.ifalsa.ifamanda.ifamavis.ifamtu.ifanaconda.ifantivirus.ifapache.ifapcupsd.ifapm.ifapt.ifarpwatch.ifasterisk.ifauthbind.ifauthconfig.ifautomount.ifavahi.ifawstats.ifbackup.ifbacula.ifbcfg2.ifbind.ifbird.ifbitlbee.ifblkmapd.ifblueman.ifbluetooth.ifboinc.ifbrctl.ifbrltty.ifbugzilla.ifbumblebee.ifcachefilesd.ifcalamaris.ifcallweaver.ifcanna.ifccs.ifcdrecord.ifcertmaster.ifcertmonger.ifcertwatch.ifcfengine.ifcgdcbxd.ifcgroup.ifchrome.ifchronyd.ifcinder.ifcipe.ifclamav.ifclockspeed.ifclogd.ifcloudform.ifcmirrord.ifcobbler.ifcockpit.ifcollectd.ifcolord.ifcomsat.ifcondor.ifconman.ifconsolekit.ifcontainer.ifcorosync.ifcouchdb.ifcourier.ifcpucontrol.ifcpufreqselector.ifcpuplug.ifcron.ifctdb.ifcups.ifcvs.ifcyphesis.ifcyrus.ifdaemontools.ifdante.ifdbadm.ifdbskk.ifdbus.ifdcc.ifddclient.ifddcprobe.ifdenyhosts.ifdevicekit.ifdhcp.ifdictd.ifdirmngr.ifdirsrv-admin.ifdirsrv.ifdistcc.ifdjbdns.ifdkim.ifdmidecode.ifdnsmasq.ifdnssec.ifdnssectrigger.ifdovecot.ifdpkg.ifdrbd.ifdspam.ifentropyd.ifetcd.ifevolution.ifexim.iffail2ban.iffcoe.iffetchmail.iffinger.iffirewalld.iffirewallgui.iffirstboot.iffprintd.iffreeipmi.iffreqset.ifftp.ifgames.ifgatekeeper.ifgdomap.ifgear.ifgeoclue.ifgift.ifgit.ifgitosis.ifglance.ifglusterd.ifgnome.ifgnomeclock.ifgpg.ifgpm.ifgpsd.ifgssproxy.ifguest.ifhadoop.ifhal.ifhddtemp.ifhostapd.ifhowl.ifhsqldb.ifhwloc.ifhypervkvp.ifi18n_input.ificecast.ififplugd.ifimaze.ifinetd.ifinn.ifiodine.ifiotop.ifipa.ifipmievd.ifirc.ifircd.ifirqbalance.ifiscsi.ifisns.ifjabber.ifjava.ifjetty.ifjockey.ifjournalctl.ifkde.ifkdump.ifkdumpgui.ifkeepalived.ifkerberos.ifkerneloops.ifkeyboardd.ifkeystone.ifkismet.ifkmscon.ifksmtuned.ifktalk.ifkudzu.ifl2tp.ifldap.iflightsquid.iflikewise.iflinuxptp.iflircd.iflivecd.iflldpad.ifloadkeys.iflockdev.iflogrotate.iflogwatch.iflpd.iflsm.iflttng-tools.ifmailman.ifmailscanner.ifman2html.ifmandb.ifmcelog.ifmcollective.ifmediawiki.ifmemcached.ifmilter.ifminidlna.ifminissdpd.ifmip6d.ifmirrormanager.ifmock.ifmodemmanager.ifmojomojo.ifmon_statd.ifmongodb.ifmono.ifmonop.ifmotion.ifmozilla.ifmpd.ifmplayer.ifmrtg.ifmta.ifmunin.ifmysql.ifmythtv.ifnaemon.ifnagios.ifnamespace.ifncftool.ifnessus.ifnetworkmanager.ifninfod.ifnis.ifnova.ifnscd.ifnsd.ifnslcd.ifnsplugin.ifntop.ifntp.ifnumad.ifnut.ifnx.ifoav.ifobex.ifoddjob.ifoident.ifopenca.ifopenct.ifopendnssec.ifopenhpi.ifopenhpid.ifopenshift-origin.ifopenshift.ifopensm.ifopenvpn.ifopenvswitch.ifopenwsman.iforacleasm.ifosad.ifpacemaker.ifpads.ifpassenger.ifpcmcia.ifpcp.ifpcscd.ifpegasus.ifperdition.ifpesign.ifpingd.ifpiranha.ifpkcs.ifpki.ifplymouthd.ifpodsleuth.ifpolicykit.ifpolipo.ifportage.ifportmap.ifportreserve.ifportslave.ifpostfix.ifpostfixpolicyd.ifpostgrey.ifppp.ifprelink.ifprelude.ifprivoxy.ifprocmail.ifprosody.ifpsad.ifptchown.ifpublicfile.ifpulseaudio.ifpuppet.ifpwauth.ifpxe.ifpyzor.ifqemu.ifqmail.ifqpid.ifquantum.ifquota.ifrabbitmq.ifradius.ifradvd.ifraid.ifrasdaemon.ifrazor.ifrdisc.ifreadahead.ifrealmd.ifredis.ifremotelogin.ifresmgr.ifrgmanager.ifrhcs.ifrhev.ifrhgb.ifrhnsd.ifrhsmcertd.ifricci.ifrkhunter.ifrlogin.ifrngd.ifrolekit.ifroundup.ifrpc.ifrpcbind.ifrpm.ifrshd.ifrssh.ifrsync.ifrtas.ifrtkit.ifrwho.ifsamba.ifsambagui.ifsamhain.ifsandbox.ifsandboxX.ifsanlock.ifsasl.ifsbd.ifsblim.ifscreen.ifsectoolm.ifsendmail.ifsensord.ifsetroubleshoot.ifsge.ifshorewall.ifshutdown.ifslocate.ifslpd.ifslrnpull.ifsmartmon.ifsmokeping.ifsmoltclient.ifsmsd.ifsmstools.ifsnapper.ifsnmp.ifsnort.ifsosreport.ifsoundserver.ifspamassassin.ifspeech-dispatcher.ifspeedtouch.ifsquid.ifsssd.ifstapserver.ifstunnel.ifsvnserve.ifswift.ifswift_alias.ifsxid.ifsysstat.iftangd.iftargetd.iftcpd.iftcsd.iftelepathy.iftelnet.iftftp.iftgtd.ifthin.ifthumb.ifthunderbird.iftimidity.iftlp.iftmpreaper.iftomcat.iftor.iftransproxy.iftripwire.iftuned.iftvtime.iftzdata.ifucspitcp.ifulogd.ifuml.ifupdfstab.ifuptime.ifusbmodules.ifusbmuxd.ifuserhelper.ifusernetctl.ifuucp.ifuuidd.ifuwimap.ifvarnishd.ifvbetool.ifvdagent.ifvhostmd.ifvirt.ifvlock.ifvmtools.ifvmware.ifvnstatd.ifvpn.ifw3c.ifwatchdog.ifwdmd.ifwebadm.ifwebalizer.ifwine.ifwireshark.ifwm.ifxen.ifxfs.ifxguest.ifxprint.ifxscreensaver.ifyam.ifzabbix.ifzarafa.ifzebra.ifzoneminder.ifzosremote.ifglobal_booleans.xmlglobal_tunables.xmlkernelkernel.xmlcorecommands.ifcorenetwork.ifdevices.ifdomain.iffiles.iffilesystem.ifkernel.ifmcs.ifmls.ifselinux.ifstorage.ifterminal.ifubac.ifunlabelednet.ifrolesroles.xmlauditadm.iflogadm.ifsecadm.ifstaff.ifsysadm.ifsysadm_secadm.ifunconfineduser.ifunprivuser.ifservicesservices.xmlpostgresql.ifssh.ifxserver.ifsupportall_perms.sptdivert.m4file_patterns.sptipc_patterns.sptloadable_module.sptmisc_macros.sptmisc_patterns.sptmls_mcs_macros.sptobj_perm_sets.sptpolicy.dtdsegenxml.pysegenxml.pycsegenxml.pyoundivert.m4systemsystem.xmlapplication.ifauthlogin.ifclock.iffstools.ifgetty.ifhostname.ifhotplug.ifinit.ifipsec.ifiptables.iflibraries.iflocallogin.iflogging.iflvm.ifmiscfiles.ifmodutils.ifmount.ifnetlabel.ifselinuxutil.ifsetrans.ifsysnetwork.ifsystemd.ifudev.ifunconfined.ifuserdomain.ifpolicy.dtdpolicy.xmlinterface_info/usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/html//usr/share/selinux/devel/include//usr/share/selinux/devel/include/admin//usr/share/selinux/devel/include/apps//usr/share/selinux/devel/include/contrib//usr/share/selinux/devel/include/kernel//usr/share/selinux/devel/include/roles//usr/share/selinux/devel/include/services//usr/share/selinux/devel/include/support//usr/share/selinux/devel/include/system//var/lib/sepolgen/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2noarch-redhat-linux-gnu  directoryASCII textSE Linux policy interface sourceSE Linux policy module sourceHTML document, ASCII textmakefile script, ASCII textC++ source, ASCII textASCII text, with very long linesASCII text, with no line terminatorsPython script, ASCII text executablepython 2.7 byte-compiledXML 1.0 document, ASCII textcannot open (No such file or directory)?p7zXZ !#,] b2u jӫ`(q7eVhB0F`%DDg͗QxA9=ny✲ 6 dd \\F|"Da3vb^52o ){(.\@J.R6'm"aۅ\/y׮);jITMe,=5t TZo(gjEy}(lZw&Oc=]V+9u}qo>4C7+筱UTl1 ܺ囃 -.Ɖ֘M=P9Aɯ9W'bLMu3k ~qy}zQwΐ,)@ƪ.-g!7;G-tTE@ XGܟfΨ8~8ޖ/7%c"J*6 oc1pͿCWqj]ba!Ȳ5ވ\b)e;e>0%KCLd$-Jx,o{Մ>& 3vohJCA-E o}Ǖ1aQ)X鮭hL7;"PdB"֒j~왨 rzE)3M 3\humH4A8C;y{KذAfˑtܜ2^Ĭj!k#. B[|x?S7Y P;jkW]߿ ݒh9#\ ǸA+&24D"[|E7~PX8wsԞ#$Z10H:@ĤĜENO,(9'n&J«?USֻG%\3ڇF;ew$d`v1(V >KJoz1 ^p!#:LMEVY՜$M6' IO5@p }|@UUە-hxu)/c/_-FjW!ܶDHBba݅cذ*Em_,:ܰe/ >[/N2i8qB!DF;c*=ep*^ _u;6R+>r 5ń3_hQ+L]{os] CGShy}ʚ2}^ DYH; tv"͇̞M b?OUpՏXjʄtm>tu3 ,mǀ>Fqtc.2vMLK7QIɕdڠ :KI'oxo0g  .ڀb!YOoR|2)v.5DZk 6{AϥDŠ$'^15q3=󕏀ƔFI%G,B8糍n鸹@3g<=mJpOj7Ƹn,wuj2!Zx,ue';ozV+|]Nv<;v` I~g2+E|!f( V7++l-Īk$QfxfVn.c~ y4>z9+yTۈW^"&G#oGIEmЀѲt~ v=N7ȿr(/PPm@I"!a7[j†/]00bo1@7j-YnB8lF*|FUKX-zZ2D:"U.mw9:)Ga2߉$)ٸpsWJ5UBuS;z 44h$_6:m[=onV =Qв썶ug "Ң4ÌyO-pfOvS4dfHv$y˪5؄p*LPh&i Ry_ϖ%kŶ{y>rȮ5TXૄQFYr 4,!e0"=!ퟯEάTAhYЋ!R:hm=1 ]8֥>L C ,mȸLqoD/eB϶0 5 uaʔHKGT! źv?G&\< WZ$3cʪy-6ڊز1W9~4!ӄCAUR'*l{yrn LSi9gzF葦#sl"ѡ BM0:FQetOwg8v#j"rr\Щ"gP Ʀ=X[RAH1@ @GfJ!ciVf)OƝ8 /N\ hj&~ *e%(CQ'&ݶ(`g~Gf ;nc9Vx;:0~}wbDdL+( 0{I`nê -kufϔNޗP¢ %4֤_5èVnb]T׭K)D 1PvIay=p(;{gcPq3?.)"춭9%/؉}u$(J<6 n*y68>2- j-b/} NjX ?n,c0,s.pHK%b]hPLv &.5I8G} C4qanwzt_$V9)B_34 st[=Q#\Ã%|OyMM<6e(=7Ze(dS.1Q f- ؼ!n0vLԎIksPӌU`*Dmx/81}5WŢcoa-EUp$޽"C U\Nfg+w|+#>cBs0"=};;< _Ċ'n ;yػ 6>v[:2eDrr8ܞ9)C61۠vQ;urBF|Y_WG[Hnre^n#*T*rk7eyE.gj7Dza?E" H4Z䔐t2gzS!g^/e~]f6\|%Vh˹2ǂbKW.Pvv٧,CA>ıZ⫆@R=GlV!Xh}\tIW|c`[o 2\:+->9Jx͗9sYM*sm_[rwRԤixqDq:Dy' |!|#`T[*3a6O61‹eAιJ[b`$߄;S=wEH+X[^[(Үʄu$e-GbQ{ޢK_LŦ&~ 4c ZA`0ب š{x$_)RQJgS$i>a2n`Nb[ݮtWǂ!N)sS`vNLEeJUT)DJsCGntASn Hz 8hS S*>]u;l|jpNxԣ:x& L3AN~Qٱ-a3Y"ǀ {>fySǩ8gH.%;ȫ(lCϗSw윁"?Jʃ WdŷF6&I$5ax%5;ֵЖp5 RVs=ukhUm*o'kq3/$Dj<^))#V|Og?v LJ3{{P_UAŽ(g@9-:QK Z^ X6  o&UalH θKZW[tz'/ġIOc-*05Ѕ)y;wÊJtb;I[v`ALtȃ;^bX?Naq&1!yԸ0EAh鰪0ӢOG:7iщ@f3&{F4ۻZcNjfNr7#[V#PZ1q N2 d_f[,Z[!rv2M̈́E{ b7^ Nu,<*gu]@T*K[!hD"|kC:U97+ }ӚiUT$WdZ/S!Z@ϳuҖ>7@&VG27D+hG"J^h=P\GFDc~.<Wc&Z$"z%sDr]OԊ:@&"l8{-ayJ4vӭVkѶR/M" [76ga?ˤ&㢬[G}ar7odu&jқjENMme mO p:R-+{ki^iP#=G&&-lmKk/rTAjMN&:8jؕF[7$tc0HA8& @#[7NF#d鷖 78ïlGo[MLTrm7mLt4M?Fʛ5  pv8v7ث,Q}+S~65gc Jn'Hl{p'.^8Ҝ=aG&[2L8H:vdߔx:4{f?CE df*$48OGE{gocbNdP6;\K!(@(r{B؂$c(Z3z{8Q6brxMNQ4$SGrd&_"}؁x)z9 ?ԑa XD0&kAT$aqQ6,$EMNTUlBG?v a )3z!NBSAJk"T3^Nհ^8!tC"xH;8 hG&38Lش)is p R9]!\9ʊzG8^X/Qxf *f\p,( r;BlG;L*KQ3ϙw<Ҝu9 9ũȝv5rV'NL42&3˄ +k0-G.mՍO>zQ0_B8`,8@5pi`yp :i#唝5½q47~><;jG^| ŵ-?;ڠO&]ŜM᛼ ѕץ^PGHtR5'J2 ֺK$>;M +w^Z¦97Gd?oP Ym%!{ĚDɥ x'_yFrg»M4~p?(Ġͽ 51JAG'5zBB%a=[u`bT#ĭDu5h ڤ5x|3*tbMޔ߄ QdIRu[v3AsٕXhQNX?vG]^ d9[,<ƥu#1k8Oĩ`-x8R b(a`!;ۍ.8C>Eb#5Vh.dv'Vp f7Cab0v%yѢLY +݆;cdlTUרGo[ɏ5̞:{T@G>9?O vulGFH7e%EJX~3q"5X-y$3I"+MGTޜh?ׯ%̺o?lP+%=*r}K|. 7GK9+_/ct!}M5:q 6{F#\MSIƹn6`c{xok:9kF$c)I = Hފ4H#=O)J'Fd;'z&4TLt27itouX#ӧʒB%_RܙVWxqD͛y':'I[)r Me~9e*e=߿N% fdR\I'L([oQ"@8` TY6~3>z@+\6+ѣk}H~1x\A2MQi-~f[oP?Mlg 'Yĺ̩$7,(2' I,6Й:(-hQKm SdV&ImGQ,M;~Qʯ :hpliȹVp.j^5ZMIVÏa'y bfHm 4L3Q/z:XA0Mu 0x ak=ج ۢ`рXo/+)?GdRP*0 ]{b4/υRҩE^a/ bn DjrZ319>E:e_ e5i{J"'SW5 2CN/U7|Rc4M ;1zc&$* -Z(IFs 6i0GnForXosnYX}qJ| BgoҏM FLt\jgaNrY%"]7މsq`шfS pGͶ)2v/`{r֓.ksQ(J_?^ۆ{׳$_iFerf A]ctqeܰc') BN-ݢ-FlaH2h[5|5Vyif~Im52?=Hv63)WٷqZL⥍$0,4g 1!׭?.Vt[H[gkJe{o8S:d_4l [1!`LhV M+1I(_-\2Mqg Dv#d*Sx?ʋJ;5 <\ X`Bf<JYJY;ALxH-ꕅΣg\aز_lpOˆ#b37QӺdÜ>d&?˟ UJzάY3fB o1ߜ  ai4TWr=Gy'1=i5iQq#9yM#Թ^MhJ]vj,5 bD7/ ,W]T~!=D ipKY) xC/L }u6MWZ Z\5'Ju^9`*ux 9?gf0TMhUz>yh}虆4< pb=rO\+ ۃZHLjA&$5|&Y&j`{Җ f d\ŗ Yd!Lr.ol?M^HU|fX Ҭg|;݆P,zUٸN̲C3T]{X 'dQs4۶.b= aE%q|>˚5-/N`:ڂ% B@w b]u2Pw$Atn7Z6+^MG\d' x U- ZWi2ɏ3z諪qu?8zΚQ3knА5=%q0J gj{txzWgT )]/R=$N|6k /B3AAWxc8 l$osFl' %}`8"x/ ":3ht{.=1RTR.xAGZn0fqHstUsK|"/ DdEi=zm|ծPYSخݩ9,--u \RV)#3O^ icG%;ٌ AkѫHX0<!Xݘ'|tck^ Ǩn=3edx2=>3&FX^ \: )ܿ&1`ծCK>i*0T99^xY;jC{u3@Zr]j:?mL6n Ÿ_P_b<=m տXLL y4"2OY>Ee\Fd ye*Dg9 ptIo6ȝp\[5Nbٳ}wvpV\4 ߮3_XJʧ\0+ԬH ^y K3K'6tm@!0oy3ݨ?>hk6 0g8?\wp:m^j9ﶹ)U/aN:k2Cfmt^uF'Gd?%[ ^A!#MnݬsjH/IY~3,R+}V; S$0p mkk젗uC R<ѐOumP0#݈?]a֟V iӇ]Y8 }UPUc٥DMV6aaq%eFp+"@G:T6 Eb|7tդzXnX@?*İm bRxwC&UYq{w98v-9fW) =OFPI)6"R"gJ8Es4tTߪ}N 3҆u\KG'w>Frtf$E[ k%4q4d.LaI><E%`z lSz50Z'OO I(EPDB㪩[rUePNlq9cQŕBpMǏ^Bbt㗫m*E_)Ol~\y-6XnTO*VgU"AȠn{7r]1Axԁ'(iª&ygZՕjdKE)'9T}Ê 6~I3Bӊ0>˄'턔,ĄpMzJɴ5s5.vVMP|*͍ou ?~c1#i)%iŔ(;%NZ @>~.Ae܊ Ȏߨٖx!볣Ympczmvo vMkK.A+C.QhK>)R۲c滙 kv~ĜJerDIN- 括 !ַefIumMɢ3Y:$>L AIYvf,va^ ;>Fg :,`"_!z2pNft{*-檋v~E3K "v|Z` wW)!nmKm+葛ev/ A_Fi--Aw Q:Mܚ9k!iI$=^s< h$w_SIz):U|.<)yMQ}/qGU֊cځ=?KqVrluaŕe@vեO¶O7{aEp^shӨL\X>@i r92[YT=?ǹNGII鸓&uCbՒpmȳZI{db%q5R艆 bC"}M=~5QVllr V.ǣ:!*COڿNiK-+>jצиDX=ZD??iZ$=($_ N5p΢IcpcvIxxElESa G/ ;^;{B5)GQ#l;Yۥ`|3wqvhFc)uxM i-p>&$1DF(NV(mM5Q)]y.XW>?uWWrIybl&m5.Q7p2cP7L+Uy@H%)g\+9,1-]Ν#qXyLupwKFCmXY+#-&9uނGG1='xK}J6L~6_c :"$0+L]_zKiR}KT93߾ Äq/6/? bM@ک>DWʟ*Y.DM-FWx1Z&\c_h(ǃnZ!pB$;O|^,U}O69'Rm2C "+ߓdNL!8*.Vu3L7atYfIzqgU8DI3nÊKn'*(^[`BVI38'ĖHN!;b8d߼ѡ#7 /"Xބ&:Oue_g@uOP(Aҏb uEw2hS'?@BQ31+l98F&N욣DO_CwDu'O0z|/?{m?0X^}Կ#@Ĕ{?GX#_ޥn*߿gC=ّ hԕ`hĠL͇NT 6PԋC,XLIaoÔrtx).nf=6fol"=-!Kn [.r4$,ח& F˄K6u!(0s}O9-Z:"EhLT=$uLX˱TJBgbumpy ):4$eDPT\Lkb:wY𢭰U@hQ ^Х:##p9;MamiY5_7#F%L\rbUYZ{)Oh@qFg3Gڧf}PZyn'ٛ|%]^nJ"Gڐ^m-> TIטy yE w2^`46i,A{oHnsb=sR}pj t. "yE wD].Z}á61XtzwSe2X,;[fS>m](]Lhw08 hn$E/"@`ڄ0%(;CO+F81, _:o r.tg /2\I߯k/Q#w+KHfc|I)[$)K$PN^^ܘ/uléLN𡄖 ARbΧQT6lO%lr yV`qBQr=y.= cm=҃ѰeEi1-Kl:GmGӆɾ,'*gcHzp97HXӶ.z %4 =-.go_NsbK!e9ҜA/ 4ScC^fɼlMEStd:V95_C: t'w@ז 7(@n>`$8"N%Y?Q~@ xDr)ڀmc6bخնJ adI6p,1#_j_b>o`ua+ױ8 cu R`w J;8At؏Ǖb6i&@$c[r嚔}[eݾ-Lx0\wWBESXDmwЎ҆ybu D: `:)4; j|z5]#~A.&w#Xk;W4G.{Ao8z?Kb4zJJl>\&Pl7 il\xf jtƟνx>?~g"=L/ڕ3ձXe_jՏk< 1*r sR0 ӾD~c^YD,Rv(5ig`}-"NAP}'',LC q3Ŭ#~^bQ֒az"."j"5B޾WrVۧlL|8h?jETպ殿j4|P=L|[h&Tڰ~6a#ܱPI,r"[ZaUD96~T5",kJ\5<%1+%Ar̹ѥͳx iR}OoKMJsMH*8\X;k=.8?Mddؿp;G?فT`Msurh ts.qpg;^a:hul<"Iq!;ŏ'mJHV˛̵R&Bj@@q"o^N%{}^m-_S ZM} ) 3Kk6~Pi}S@m_gKXSǠ3RGыYGR<\qڤ;4j9R6a7E2T_jC~ =JC$Rlz4hԂC`&Ѱ)PҜS`/uμ6o!@ 8kjDcU?{%ZZm0̿u(Uclq0GeU#ШJ?qڀםR.#أN]O3 NQ U ԡrN4lޢ~RTO7*?!iw봕#EԵ!*C֊5[L9ʉoD: F"sQ&[Nq9w]((!Q[QGbo@dx=hS)Nѓ/tc//vDE-VЀcZ$օdG:!乭&,#PTKcEv0cjt㩚m|'9e#(t: ǓNPa?R xeJl,nrcv."^fy0'z<*y;cvVXG??GldvQ *#yK˝\g6p!{i7^{+,&RE@6^y=O sYZe<9ڙ4r7\+'ر@phӽ,`]ev)~FuƵ9Ж^6\M$z,ka4mq> T.e5'[.`ٸamHu<- 4BYXMyqz$AB1ڐOeK| {&MΫ٨FBI]uWwX#F#7GzDGta͇0h"]C+e&lDM߭]~#[=dSI^!oqa"NaomH 4c|fp c#)ib;zk%y>.?ҩ0  9f^K-w(Gd/hkVO=R;Q9)_iPƋ~A0K=kK*E$~ׁ X+erJ hʜhxjS &!64xAlP &BԹfMmɢA}o䰭z8*zR rTd!g1L=4#UVCdV]G0 N7ǁ|6DA?mw"(:nj݆5j< '_lʍCϢεL#z~0_^ց;BZFxy VYڶP{͹ fB Uxy:,:y0n}DWxqm:#,%GS-ޅJեS)g)ϘCmF_~L-Kqwr,7΍H9~py.W*,ajȺ)eAg5*+R.|=a$}h|Td?Wsa埁4=.O^#~?aXY:̲E1WM=T"aswR ^/ǣUW>Up%gIUZDoi82=m5Q0#q (?HeC]b>%vz ,8ltHR$WCkLڨrg-cNW}1qr&{ٜ`8eˁ۷52rB}bBjJH@ 64:uZ*ߤ‘yqwV Hӱ(+2w"^7U,US"B> |lZ55q|C6X>_䘪| 1mFl{; :U."Bh$l9Ov~3k,O{8v؈WڞH_y<bE.DRZww!-v~֒jcم%mEQ.IY{TyI. .x>$M 3ZU*OesJ2" x^͗`@`S_w)*.gx^lCrљ,Wm >=|k%^ijMXoki۹Tp\0W5CVY a3dڦ?d@fCntWH;|[ܭ+8e<g:;׷,R1uJ9^QMZu'oD{b`a@nn YRf6{zN&F]+󦽫ғ#z=|60@bUd%%4m &> ,VIK7PCʨZBl 1 'kzs>.*4 x'. C!q i%ސ wt2~1 O``[g ~j0,(\W1pw)6t>`?p7l(^v6F5Kn0qLBBYR!û=2>pTP=2~;"8KwwR<>z/8NzB?H\&RV~X ?Sd>*₊sɔlp5N>i,y&A95*R+i-KNFJu1gЕ*qHbQ5@jl4q{g}|ew8/ܢX!?P>0Y斡w?7$)tO,>TC?($g"loI\΀Bqe_vb۠aL4Z"s<06mu8j0qj{G vj,ع=&n62/W#EU{غo4SWeY &;j$Fљe{ޞw3Ja'[ʘ/BPLݑsBW7~SDr Qw;7ZYТI$Dk*+s2 +oȼ8ɚWs&vbs2?\g qӱ5/9ob08g𛄂PҖm\ Yw׷\o6S/k8 䚼c^sW8Ny\K>hN`r._a)#J߼\uJOр>Ċk(}ƕWCD%LnNAԓL-7쑘+;R~+|q-?f^UA:9eu8` 4s#&0iL$)%I⻾hV)a6/*}ݥMl_Բbyq"w vNZs:*1KH!UV85RtKzɀv&l46NjH a-؈G!N֒Q)ҹu)߅Շ?l;O˩CC䜼rݢq4r>.ĤVvwu.E5Il8 Qoy|x*_nFknw΍RZ5c~kXfS8/={UN806O8v!ČI5E+>-$H~u %{~s=/d`us#lBF-⃆9|y2!|(7܉,ɷ5̀q 4l~FB"%0b XPfUA*ΕA]S82awx}e>JҰIN ޡl0!B~a}wC>Ӿ;so4nCZ {[Q1wZ!UW=rxA!mj[[Н ĥqaY[%ڄTPUzҦETu첼EF##̜w]$ f6%ExQ(uWM=` bkz95b3$ҵ @{ CAyM7}9sR~@xA@sl4%tNUO9!es^L'hS^%(dcNK=//A#qz>p Vm/p“Ps9^I3-'{ҀZ@+X4oZXejՎR}y! 5MuW4j<} b+[!4 W]W=p|Bo^/64̭YYPN'ӈy@nnwJyl|:Sv؃d1k0(;@m?$2K bpIL6D>{9S`%;zTZ-*,Y$8֜xֵrw_q Z"tgoQq2R\ĊB% 98DpBj_PY-> sy4]s.,黧>ɜ-^P GyUXVq ^YCxyQ\yW%RK\0n`ɧpel:t3Ww"''bcmd3#]`cxƳc7yh_T{44RL(^d QlP%kj0:ҼGGrܹܸz>7vPٮsv6 +\rXI &t8f)qR|ɴE*]ረ Z"AѾjcZFeqE-R_q 5\?ab˙O?| 6L5ˍC@OKd.rYSp \}:uApPG_OX LQL|)bسaakp5p2?ZM'C삪BJ *9:0o(~ܴm}MPG =\ƺ!◮OBlzj$I7nɆ#ZtJ_x^8I6,W<(0029AZ~o?} HC9Rxa*O=mx O_JaeajKeo`Ido9H^V=%^(5y~PrQNY%;AԠ?Apա(`~5ʶ/a}bP}hk|LP q̼PBwD05'Np3$)6ڿ?Q_5ܠu2wY-v_Lzje#ܵ:7<z $xd:+$Ty@/c;(σ`3K)F hݜr @U)l%E`KOTSRQ)ۢLaX< )Xml\<| :뱵KO0b{BڅA4l{'cֈF?DIfJS08{е_.`6bUOkk7^ÙgT2P_G7~l\&+>Edʶ`3 `2gzT"5a?廍>uuXK R_-fͶ~ ÙwGJ 7Z(`)<"K/J. Be+MJSbT %Vg)q Žc29H@(946G}OHPwh .c}`^J9̬Dґ7y^jc,HbwQjLe&}xL$TH:8|!lAmr?kl=d!!B J)`C{d<,͡8۰7 e7HrL|"S |څ_. PLu5)>A|!n= E%D!Z(T5eUIQtI|DOX"N=mym=Ps/gg݁mӓ!X9R| bAACBd]li[kއb/FtI8DH-0WbUṀV>t*Jsi\נY:)N3.$_og,|s |Ʌ$$Ͼ$|k#o{M-Be<6߃"}N dl鴾G_ 1>ψ>4aX)4sOgA֝V#2rdp#d{0@+Z||"*A1^'5N".Հ%ԄG6-tt Xp'źq>ζ:X}nnq$E}+C6;HW0(@CJ@;tr@~% m>S8Ś^PUy.Nw./S!k%1 >8@wˊJu` Ԡ:5%R7D$[9 rL[T USZ|7.=w>̟$pNncvF5T[G!;%W$֏(品3ɵ3?'#2( )jO^)Iw*Ӏy-i+ɌQ^1\y[RPR,[3 ,XX3\E4mRZE7 \  *JCاẗ́@%Ebbk[}G2E }EZ4?R1&8E: >'Eo-/ zBPO (ORE Z!xGhJ[X<߮Q3P96.0jWEvwbVFlhcflVrNz浪v븦7i ! e{u)sK@2cP쨟jH|/VEp-=)N"6Uq4Z}9[p w|.ワEr9z(0c'޿DηʢkpBtB$"2+iR,G]hX6,BJV=]_rƉL:gwZ載uȔY I>Fw(u77QZU^5y` ʎJ$Sab[H@۩eN_K^) a^2,T^q CQuh"p][ҬL k|zIgW~i0vwh E1)J[־'mƔȭx@*6Ѭ_i\h:8d)XF v`ЉNo#}ù* ,[H u Ę[E3ҒnKS>X`% I Ihyld3 -i͆V1!g>YS_T9G&K$ ($ Mr<#_WIqj6R(sEr~0tA;:lIq r@_B{x6)K8-C`&+I DI2~VAUсЧׄb ;%ת*K/L/ܨ}֨ CY)&R$"^m^%ow_Y5Ze[eW}] z9VP%Z\"ICr:Znc;SsPF9gp lb 75Tc$_:q?PH{$>80' Ie>%]/fN(b!뽛ENq[#MX:B")}v$WT{T><l b?452ɺ?E"l{[V3 {5weJwU[Rw{9*Fà[#01b1@-])jIV~vIbKRgi% mt[ oE# ٦ǩT_i۱Ӄ}kV-%G2}ÁLK4ǍHͻg̬oZ(#og5trP0d17aAԲSmc8~ڞ ZqZըV &ѿh"/n3Opz[~Q0/'k6O LUhf!suR1Mp[0&A 8%ta{Х}^^smqOLgl*QsPoVFwڀ@Hc ݛ?(XȂ5#{Z N)SBq.l_Dg)VT zɨbj)0^K yW}R8~GCh>>HV9^8(L\T{]br"@dIXU.&_|}WrxOԺ,IC";=8о“+2ҁb9iG\{;`p~c!IYmmNu 7w6dN tgg 4zt2=~93 'gB %AU#άޕ.AzR0Iʳ-b4BX#P[ψc9:"^U. -p"E;n ahCkx*}<\giN_u9]8%pϨlͿ#h+yNVC&Z].*7 I6w!nd3Ј8,|^=H/_ˇ0_Dw;#dUdRΗxF7IǤ~ Ίg "yʘ ;.8Շ" xW}=Jg6qDj,;J[X!7T6/Rda\;,h:='I\6]Tt❇RqӦyT]hدpj*+(G.q|bXK:gV 0ǪF-''686a52}>5$r*?Ֆg4O U.8 t5! b2D0Rq\@6+#i#&nHK@ ̙C>&CWWbWg4=L. (-<Ǽ_y>r5(Bl{ғ)*tɼr̝7gHX &Z\+JSb./lAf##WbR X4lS_?͝f'ŻOWRnvMLv̀gp'eA wWn)ԣ({khW![Lov܊l_ҡ趓zHs\ T|H>A#'R,e/4oӯgj fD \ 쯑`~M1'QLS0v55I h%-^ICh4%畴u >Q@uŘM8Mw^<=҂J/]Ow0Q }.zd8mrTԜ`\hQ9LQ Difb:<(G~G;.X7A;{ain*ї$R ,eƴȼ YcLӰppGN_!l,z#RvZ,[*97q-[ngEJg<>ݼd€O;N@SA{/ՙҰ6hذ!p->4Qg'(`[t7Kt uZ7%obd> {U`) &6, 6tr1lYMG'(6LYj,vKnkњ0zn=Pd S'()yDoa9=N?0$EÝ<(N8 /NrJU4gڪ{~)3/Ͷ?qD3'n# sţp}Lk92g h_݌'}m;n;6NRn # \ _CTj#GgRR0`ew#ϗ}75?wo8s5TUQF'vXyUN+{fNJ*C2_`J,T\!,I w`0@+ m~>$FT?7GңDOCiMS = #' eN_g&F XI٪LiiZa\gkTL Kh}?\Д 2tm0w::Fd$ </M&U678,ޠivݥ47#V׻ z Aҩ4Fٯ]nȫ%_HltJH7(M=gtt)taVs8 {|s@J>1D JUq䷘hvYzW^ffmپu־5+fA1,D QvdBܫ@x"r~7C%iXf9đ0VgO4TZ9n>9?\I̓]"cR+)B B'tKAa0eU|6{I+of$ T)I<09տ!G+Vvgt@]j"\e]6~6UW:Ug\ox{~6MZo9XXmk<|O'HQ|{®=kz o{Ҋ?qpy0g=ZmDN|*dEX~e \fr25TN/Z8%Nh=3l?"۔nHԦn.BAxt.6)L8{Oh1dM2o/UNX%}_uS;datp%"k:#pxh}^D@@nytL(b꛳UV>aԦA LFC R ŦESȖ2;=G I`UvsP12b ʣs:'d\Ej Vs#ji%ӱNW?&KM Gm=slykq&‚$bW|$Eku!Q!f]i Cu󊏏⦼ n5|M5#q[NPF˶N?fbh93%0HEsECAۦ>;k̔gn_M{ I)9Q2-p fG1iSV[ C|S8IdZLF!2ːc p 1o[^\TIY nX:?@ς:>Nn؉ʳ)}-jЀC>d[#|qs=kSvQ@"1! twp}2{UodK{i{86v:GҵwueB,/N]VO“ 4#rK{TЭ7'l0FIV^{o?w@O)T''H^8SUzm #b̍?${*!q{0 q))3c^bd9'?a:yY3[`3aq(:ޔ i<ӠNd_U_s V^Ng %[k;]"B\a O:^~7GlӇvPJRbk/UB_7/wmRj|1 30KZ1(nTPɦZvk9nN3`pVTz* Mrd``nDB 1@'j9j  ƣ$0}|$ c5i-&72;8XFoQ=ƱP< є3 f|DŲB*9_Otͼ:x(З֔`c@Xz('o%wA_^Ly3 Eb9n睗ԕ¶ԾlIH Sre,:}`uu<m"zK7z~o'ShI eZ%MC jRxpᣧ!/Ln5ͣ/fݗ'K)R6;>YWҌjç V#h>.]}>!"j\|%t$H@!H='1~VPg+U;_jqHxA9Pg kпBrVB,"ihxpr{9`q#Z 1\7MD&&O^ָUSu\k!&{{!!_K򺛸` 2ItWDF7&齆xq$)PgǺ x>>Ww _G/=;vKSY[' tvɢ0/nZNޒLrDu| EǖXǬoA|M\qO Sbķ*kV%%RE^b[:o2 *w X=2ВY4̳om3Ru\n3Zǘk]['p-cW/n `E\T(!.ï(4R0ojQָju[3IbN4|IeG3@5?[0Q0\!yd yk.&DA/o;(|cOW`~O١W+v#Ibρ{v|ZBjj8ݓ:RIˮޅcdNeH8]uZt(K؀޵YyӈM1jw4[c`4:CrWgNO9(ϢɼK :?V;ר>`w@9.^8"6%Nc"u[& lt~mO`lkv/5y3.D0#jm88!`I&yWxGY9Wlb"fȄ Qڷ0HXp& N_;bBngX>_W/JkL7Yٮyf ۄo74 !?n q $bpIl=P)C#pKd/ ܅MhuV8ƄBp(cvMU4[UH op+ j]آt,¿cO`%*H)cX|Y8|;0mٍ=x`jxே c*E,dLhg:P d}N5M*S6}J&(#<~1-%Y\646܍{b0G~:\ZNa$ B֋瑛x@2C_U_b#C FTY<>Nw1{U!%vygw9fTiz;#Mo5kT.7VE>axD uQtǑ^GvľSL!U :e)R|`F`zw)Y,u+gQ.we, ,Ag0K R 2"@:! ;#,J2T]ӳ82P  (@QDŽN6=qm۪طb| v7EH꫻Qq[BCTcxm? &;On3\ZE*w}VZv6#W7e73jƬ;=Nј qOvGc߳@k n9 ˴gYف/!ԮNgVOW87;[a 3II@Y|4JƩ"<ȡ)rO nI3'@K1tb@)#" Չ A4+t)=8t@]n&ѴnU]X7p ޵?lKHFw7۵wQ9Y"Ŧv62` 7Ga֎vԪ}AˆcmE^%nD}zc'#%fYk\uGQ(05+^I sC[_| |tg.uw!^91N}yɢpmfERDq>+d&@ 0.Ia@eM6(WkfYx2:G{p#305zt)&Q^&O/Z ?YűLF q2\8ْ?T["/ZRxL[rH*کW PѠPJ:$1z=BR]() =|؃bfodgwDs@Z4|Ǹ1YB@,%̒d_#I;|Y+T1լ-ZkgdpM\jR2s bӺg <j-b\`j>;"D(e[+B\P~_Z+.(Rwiչ@4:qP)fkc(9ULjAy-sbx25>{<^+:Dj&jxkYDS~6S_ #!hI~"o~g zyA}:} V?݇P|h+}%.Q+퐟ePY1O@$C^_}6: NIK#PD*MH8aQ#n:I ]m8E6.D4ː35%LObB1Hsv 3ntm&,// TI;Y(U #`3W*uP%$hxj0ݿUf+CPCQvur~Eߧ K8<]O @+"wu!j"}&˭ /Q$7I{(ߙgE$# (5KbGh(*U].q"O# tk dCfd+׸IX$*  pl;pMBEN#Y;nX3t}`H[kqhU>k_,Rd֢v72%^q{H $ȗl_ɣ; Jb{J6I{DrY1 w^^lqs`CHD(Dkݫ;qfՉVdq@zc\ݴ kf";Z%?g FYQcr*^WnWb^ő1|e1C-tW.agkp4D Ua>>u.mqtWbJ~Ry%զOD4>)_Eu86bռhUgf{<Y& ,5V|OEj[Zk..bn')F4 ]2U5?ԗ{-~^+aϑ`]f}kjkg+/ <7=4f9D5{+IjG|5."EWK*xZi_~*5Hӄ]Ό)^Q 1Jbq^C lb\[=>:^졆RA݌ފÀbmP\ !WjD,h-{Y| $HlWLNqEKargSIogC *ȅux{L:DUgܔu[k5&dNhb{f!xAqF C ܿ3m^ICȮl.L5(Nx4*4~&yA+\eo‰]nsσ9v+ my^ -xdwX@?LoE>U 1Al$lZ*d{?/6"t+n̮:sܐ0 Ie4D@-ѻtرRʣ,b0| xLЃIESUTb*Z3:~ %aX(4ZSR?x xeYZM0(/;tcxEtYRW/Cpl= 7Q"Wې%f.dQgU;QcB\ j[j=+Ipʘ1 ]}+.t_\pp32 hX|H):]HH -+n%/Es\s,iLУ7Y6v5r b `'oơM2U:ѻ7S0 Rte8&[$<ֆ`zo,䒞 튨|qwN9S&w,Uz!!i2sIu /%M(\v>^YJi>,3`/E 2U$Lځԁ?ES W6O1=ԾlKYslqUegu:0aFO8{}d.eM-Jf5myYk P=uJ~L.-f̢ +)d9 jzb .`d dKtԍ"N!,zR&3p,=Cw$03M86AP@dnoyFN0aTz_QV9AhQ,Kp?п)DbzINHv zF/Ec@OYIaoɸYFVG 7(ɹcu+t ;;]LN~pMuI{:x*:$ebؼR_B8X>30Đ`=K1|x` .7;)A֫˚i;]Hl^-Y"dxk> tՋT4 c mlצsQw^/idBm,o3me|0{U%1Mw*hH^OڅPRv0p̀y1}.' WLxDXqc̎jBK÷sܳM3AQ(ˍh'#JK2\`1#oiHD r^HC6H"OIQc LZ"mx^;21ζo9z_H/P(/1c>Tڊ֧.)+ܸXjSup+ {w=ŔbEaSH;<95& E}Te>FC %Qgeڣp|zcKN优ۨM&mk@ .h1mHd=;94@Kz$~ikubΘjT/v/_3X9&1Sp F[Fz9;#*.hnȥJJObIGGhAqCap;(n.Qxx4> P NOT!uSϺA-(ŮBPo~DنA8#2D@.-5hXd6Q/ChqH 5Ϩ/Y9y'[/`քPD4+ GcG@#[ ,7'03>]C=<$F`HK_o?lA#ib,0ɣRà@!:u= r#)w8-62ז?X(]ȵد`pbfaO(r,NWhQvMN2ر4KiG"@T9 RQIjgcF,|>랗 T? &ңr4|l*3_mppܿ c\C kD=q<묬X*7JO}H~ 9Ծe 0 2P 3xKH}f)oD8?607>ч[&lOGlelx ?f&G嚖rb[  `pŽF 08:baurG7PY·;='EFJ~9Ex\8Bޕ;Pp-)'rt*(^ZK7hLneٯJO^,Gv뵆WE,1F@ oV/U"53j\@ĭg`5G`EqETh5n5?4'Tϥ6O]jxD #{L ,jp|G ڨ8y 0 _nsypb0VeP* de]v9\65rgncș[#b|⟣e󧀆\jI$;SX|lcQVAcw+͋|:Y+<֔JK@di¦-"&AK 5jQ LT7`1𻠚(d7{[4 H&Z;.]3YaGCBxbhMOF6w!\ifҷk(Ͳ|X볃X݂r l[՞%ⓏjDVB64s[^;Pr7cJow*BFwO ѪCt|5+/H4{e%t{8⼫Fp.:7&i~lrcf7DĘO5z F}f38I-j #|:{ NLv0wχe+Y /X@rLIm"i1#cuYܐPFSŨ?$ч>UjYÓZ.!E|1DA: 4ziW7 |J萢 /c@HC8vzEhѫIr}#! B󗐗2mdʀSlEL?Oյ0q U/J\u^z,=Kz7}=BdE:0.jTͤP<8*Aڽǐs۾Ub=•Q-34 BEXR(nXi.Yַʷn٣TwXJ7:H7dj lFzuE(tD)ۭI8eoД( _xZO `D$< q;Aa4짲śOd{&/"SwIU <~`l葊4mwB6Mw"C fY+dΫKVZ,.jᦙ2@1%BqCe~F1eD.S0tpF+Aw Hw #ƵYz J&{VIy_M{?Ĵ5%a/︵'I_i2ɿiK[p@L"HiԈG;m!ݿx'!m7h)MH.OȡE=6,BHW n-ˇk֩QPA/g ߨڗ 5x߼ZB%\& '?? r9H"~4Uf<9%ClxgTQ2%:J<"GmvrI,gOޑ| QW',*Bv~ݗ9}WD2 <<ֶ%@-mp(onB4'ٸQD׃v"1%ypuQ)`0_-*Uϲ(mOOO,k# ]{^А|OX4MfGWwfQt3'+psC ^7LJpS"U"6lz`CZm؍CKTFgr>9A55 )LVgs*Q)Lc+9Z9OåR5~V E_(rch2~.}Y.r_-v^C{Tܳh|`SDl]R#Q_2柢gaX?x+-lO(^,G4D[ddMS- / t] $뇛.muCQsYJoVb5%gRԁSPԨepo[ڨzm7V\3=~j= v\j4gP~5G/9-jeDSo9IaɎF 3Kן:c?K_A`3K3`bc) PI|7'VtG߱rqo`@e<)Ds^Ԁd{D}BMB禑60Q2 8-ꦺ}QhxDvn""֡%kT0 %c#'wQGuEʉSIM!4_R;۔qèX#2cƩ ADpKAH =Glc(BיlPri]CF0/x7?m;WeC=ZqU:Rq|֩&74ܢYC#6Ȟ Ɖ0-bNu-otM)Cs{n%N rzhmU0[֭ZO/RU}Z{\ I5bj='^F1JV3̛pA0&8038 f]] #d4.b!"y+p8$(<}~c3sU) aT-`T~l9Cow`?}V+=L\ ;=| -D_ 5 cm0`#l??歹!nƊ# uZ@w}iAM&ZnHP $C%ޖ=har(f <ymaӻ0K^lCݩK.gw*67,Iۥ+\NbWtmAiF S`Cи}GvXu~q.(Sn){z<)LcXpfD|ae6Y7WƇ ;:0C~#*b׊(EM2t!%73.1!VҗwYgV5}G k*:@;y*goD"6h:w>dKcMI2M?Bg Г4!_^\I? _?'Kz%21`|1iJ]-_HzAFu]m: Z˴u'0ZYi#S٠?#G޽-V6)wM@0Bs, O ;pv0aXjSq^4Ma ]DGEeΘ,b@S}1k7D!Z2%ډ:AR|B 1518?R glxe[Rv%wk}֍A.3Os 4tccK3–z\4Ag%\] fݧaCupε#ϵL @lX~zfKOS'h<(ɛjZ;<`NuSJu;WFVMY%iTL\VԘiUox5GE=Ks"KIݫ:}\,Y{?IT R7}Vbq,<{Sϕlj`$Wl:q;Idj+]VJ w;7NKWVCe/]IC@_CAGݩsC|K ,@JuV>۞;}"ϻԓk o$fiBAM|wdA0)JqVf4Sx>-tZ^%Q#T +WCzަ8%U1oWra}qZ5R"a1BY:/^>\~m}< ,M Bq@ysFd_`Ɯ~zjV)1m+#*kXeRA{?r/o-h8#MT ^Ț 7y:/u^v' lR4WOE;YQCu1P2f]wgZ2Xa_xRn oBSQu E/"n7ZfL| f5OpŶ)n{eXVrA ~ I}JfmVʓBD,!c78N̚NK^k8نYY)@zE@2x }Y\U$gV@KGsiIapj|vV_|}Łz!eOgh}I E^氿;U d蓤[T j4vcEX kkWV>fC佷^3gmW86hrUvqc`ā<%qvu7t <0R:8CoJw մ}Dk-2d-VV}SuM* tBTF`?\rhx^O#Tɩ+^G%D{F/Xrctr1agIɽ:=S5ɲv.]":GuժrD÷\> ]S#mCgG)-r/Ey?ɶ''8nI޲Y*GNÕ!qx!'z5i'\nZ*-֗# EU\M T֯t 0t8帥wbOQa 4 5+!BA3 mBDg+SfNnӤ S@g 8[An8 UiG-ak{J^o4R# FQD)%I:,O%Hf^nAʝ7g]b Gq(au4ufոѕ&m/puo %V'c'jA2_!6sfFuq;̬2Z׌p#f8f|kܸ38w R?ͧ+&R8VZ.gkē: .lίNyl4 ņy>(ᰪ3\w)n[j=XtvOǒT<Q3{?K~( i~ٔ,DH!lnD9fl ʁ7G#h/njjQ'~GNqOTvq$gs,ƥ梁f)P>Udx$/&C2j ּ9Bc AݘD@E+@gK{UB Rh/Ky,M:S G9"X6eElGFqJ䍀ʗ+G4 9u@:auD?kXxS'C 8>"cݚ)WhM(sw}x;fx2*ELpϗ^-lo;p9y6DCkռaT10֍q&:@@93'& !$yWoJml{8m$!mҼ;z&&G%"Y_]5=t @}P`!>m4>n24_ :Wж;lv58!oXTFs?"h'ш!deˡ,Tq ~Ҏ#4ejt\ .uw8]kAU3G"J&ǡXkT 70pbWJX#"Q ݐ>oCUː6/squwM\4)Ef"ۃ &;I>(5af 7<H 4HM!]L8"f"s˿x]]=B!9֭;~k`'tf A({n [x =piɱSꆙgngf+q_U]2@4 ҟ/ uũ5 ~yҝVu7uPxLzw\}dѳO9Aq t\]s6#yZh @ 0DޑJ&x^Ɏ&7Cr PJcj V4!C:,=[^Կ.`gB^{5pڈ:0||pMRt-VC*`"niO0V>+m~98|j縌;Kh33X8lh݌q|{4w Jd.ɜwTF]MJ{tea0ᔇM V:>.%Phh;,C3 ҍatcVH"i]!`U"R'5l޵w+ W YEm&OR#y]`kK^ziJ=Zu~"q rEGe8V)#m̖s)\N;A(pV˭,s_-Y U54:G,S43ň*]b ~$h}4R)(Է";h-ȟs!ݛ5t;?BdgtAs9tc/(OϰD''}MtkSY{E40#"*spXoÔ4D;~ fxu(вS?J+<[#]h8x~5bP|qɻɟ!Ͱ)WJ𞰩zկ.Lex&ɬxLF>QUj:b/SP[jfnRSECɾ`)IwqvtJt@&Nj֜og&o8@KQi6 $GxiMٯ,<cu@(d c "uW"ͺ2U?)Nojs_}zBԦd50D|l+ޙE%߬%w%%3F5 mlT-`KϳçB}q[g^&IMyV^Au#'9Sb@!_^ $2"&J$8D ={ Ppft瓉iv*6)$pH8}t}qR4|gc[4E}D$pvؚUպMꬬX;e(ø&Ղ>~>]aT1@\{S܋kla\h_Lr2erNuL,⢕᫜7qBSw/h ʸGuٙǺ ?nrUF%_YRI/E'~aMt!'wtXisQrM>w 8T;VC-\`n9oŋe^ܬO/]{xI޶?|*]*վP !Vtw{_#79C`q=48Hotllz= vYU3:Ü>X/G/{ Ve c/0\Ӓ/R1H~'sG Ƅ~'U c޺): "0qkNYbp"ª_&OxhF\jO"4k0m|ܩ@JCPՔ (c>sgK@ .3hvIJA>hwQx?98OU9A4Ge 70$dA5:^ٺ.jӥ/LҠYmF!Y&.StZ"vH5޼GYˉ7t0I\t;{3]!YG˺"oo ]lzVQJUW׸`-/Y{B:' W&5~07#Jc؅Flr!=@}cRC0 uNrYy31 1בp&a'- E[|$ 1A$"VX iSD|֪@ɩst$|5D9*1ʴ)2ɾHEE%~]h]=0%$LPV9N|% Y+bk Ok;jٖ3Wqҧ:G$` QľO(@jM,JRƈԂ&.rϨ_+IwIE^Y;J gK#Ŭ"iiԎY%N/^+ hJ1c%/ϔł&碏tyCS[=L@|^0+׉Kw%܎%EQ9j, 9\L25. ^ ~X$)1A䉶6'jMuՁ-Īfx7hx3PSi=DQV`{gnvI=0zӗYJw{(P~I;tҰFKzoIʋ/#${=a%kjk^Ek9KbPLLmK{3ěA O:&DQ祴?z"6j.$zm(IY9xc4+%p̐j _5% ZM!NyIiIq`%=w-wN^`.g;aV-qv~5fljX=Md"++uآgJIG]6 t% *EY~ Z\Z}II}? 򁐞}Ϗ`,F׽HwJbE[c_s "TG=Gym"\HxA: :jt9j48܁4 gkd<\Ώɨ>9YIhgC4,rQZڎaiRԀ.Lى_fGx]x'D*pZM"-R~1buAY -|٫:Hp&5v⎦mB p(]6[m\C O`%AHI^te~@ ~R^{ \< w&7/1[g1ڤuJӏ]a?38gG2H8z}wC\2yΟGᚒ6yM4~/WCzs0¢TNIe4\/]yHktzT5ATƜj>g8ņ*&@P.T4"MPfػ<`[lU&+hƋP.PDŽ+NͧZKBp.=J1g5aR BeJe68P`MsFӖro͞OYZ)b bFN?Pܧ& ܫ΍BjHKIf$M5&+<$ P-,g2d.|f^,7J\GU "c]>CU7Bf81qʟjD"TT#):Zuj1n[A ?lO_ 9{_?U ea=Z DZC==%k^h^Q AEsSXl̩|NX nߐ˂w]K{:84L,[j#iZ IÏ-6oJAiG.=Ea }W|wWzǥJ0EP^^Q]klЃ⧺Iz6uM'W .IOH` ΫKWːpZ7g0kepaŮqpE2GLe TQBBBlӉE7qjX7(0QΚ}?,Bl땣pP5uږci ,B%oؑN s=iec))lDU%ͣ[֩⭙8㊦eXSPhw׉n S?yF \Q;X~Rw*ײa? C }U^e3+#ۦ3{|65*Bޒ+r\s[A!W\mWJێ@C=o+܍*k)꠾L2`Y0fBjc᭴žmd љ[[EHL 3n:6Xm2_P<FL4cWς*,Δ&wr_;a)ଯyk#BhXZoQea0*C` ,3wXi-n\h93sء[S1mDr~`[\)y j̉Q >QpJ3"1S$cFb?Vq%]m-cwwiE ALJ੟ zhQbL[vM\sd?Qq1=GNE`RLkV3'""^ }~RWdd-`w#m=r2jOJO$P~?Owl/0aFrvSzk ligT.X}ȪCRKm;ٞ$q97i?T'y7$)x-"z]a1-(2T7D.":(-Q}YMmy!d?Yr(b(I%}|XNf ѡ09Ia^ձPU?Ϡ⻭!KK@`~5eIi2-gzN?oG`襤8IQKl`‰掓$s=1ףM>)Syw^'uD*<.ޕlsgq UrTsc+Zհ8Gּ &i-F$625kyS3] )# Wu f] TV.:Y#aAZ: P_Q#b+Z# Ԅ 7Z5XCRH}/ TFz/| K.Iu\Y` 6UF-*Qy&\0ɻŁNnZRtPsOHU#^s&i9Ɨy·`&iD''2ӄ) JٓjK|1?ݢ'Nl(縐9G ,ZrTBG~h Xԡ^-bgtV+Atʆ^qyB2{tGnSw֫F{̙^$+~ Pm&VK0Ml`LNjHɂ0oR4 4\~|;?L {b#N ^kFr7I yP$sC4KpuIsŃ&l ;6$cNubc-*U;ze ѹMF06Nտ e^9 3AGȠu/Xc׬‰O&vxI[٘?Rt 4\fm&5^i ñuϭah2Ӵ(le.#tzp4Buj63yva6BZ0x)P̦.i2p7+ɤJsk>%CvW rTWfNZL\04P\d`?#K9@L甘_s/]wK-P'hn{%ˏ0Pgaà(3h„J8IH$N9i q25{Bpx@_jj~ ;|K0,nuY$gPy[Co?-Z=ogPʑ<0zo tihq!&ޢD(8\)T: )O`i^-v_(>l `;Z1\$pOD_jyyZ:z'ڂTFNzi ≯S"@q} kUn%oR N<ŹMFuO[?xqzļ߄A6*dmp} n;Xv &@K$r<^ZTjK.OYytO68*@ ztR 7J|=cEj+aՓF ֩*AQR}n8j"((tI1N㲣V |%`6 cc+v+/]_:6pHcOϭ1v\}D=F#%6DdX6V $j W?p^%TF|cFD e) wPǢ 6A:4;$H6I.=)uz۪Iy茊ZI;}%-꾮{B%kLCV%P{ҋ,%]IH&21ꪽy*|X'¸VZo hzd7 cy~FnbB?u b-^_BgG1z-m闸K߄Qm.¤%94-MImtP"MH ;Y/(./`.#(F/B@>Hhz੦&|&Be2 Kt=S~lx:!P9|0GH +8ߎg19SW/x㋟wk#&KMk8j*typ_/cضbKR8aU/kcpe>Ľm"U< ӤV(GRDn<x%GE(<,=mRhpN9]YCW!_>+1L H@#8<&D*ӹ.w+@Dlxh^d$FBl.)l} * P#E;=@g?ckXΓP7`An6Qo?A 1j|!!f>G61[nz@.g:\ ` 7HʉHvwx5-A5q"n=˰޵ ,j~ն͹_ jz#># 2^EңَelD#D$lV3IlhZyĦjhpcVqjUȅi×]gW #U/= xLh-,S׾*0 \OXI~-50a;5db'_;xAY'G톼}zF~W&΅rOl~Cݍ"TN .VV:,vA`MHYop&=b-g<`/hv4L>P,&#tE&%-~\=S SS&b67ݏͱ-cje}⍿k~Af<'kC k$^%|ĢR>]84% }3 `[+BtJZ{YowB O2_#/ @;7^:JGя w#^F-'-?97]>p\oe)7ᑎi$,M 1(>Ex Ý Iڧ]3ׯռnSЬNH\T.TK3Oll{*7!o7ot(у,'x(J B*PEv `gXnd*:U Eȓz0_рBGt$ MΜ۹_?şSpHV\ @bX`M67aN3*]+-nTw7:(Z}&oVn_58M.k_2ήGtn5s+ڒc)5un–7ơ+#(Ay} K%YlI<%E)DIX) iјGeD3HR$U90n/rb-3Ag~$x.>}aR/^ Ԍ`zqP棿 f8 T@<وB*hk+9$+\@ O`&- r-`6R|`F*Y5O+:O_$ c'vVS%ZG/,܍QvoA/Y=]S/[qWVQ ΐ_GCT <ٿ0K@^imw)"u4\K9J}Rr'l-`/ V;] @lp ȶRZt9<Tx M֝Хmꞅ$߶>VMŭ Ka=oi19AycDF p2`XLK"?x=-{%E*nIMB 嚂feFnqp iu/.D '%#5c`cB>3vDNzE֝im-Gf LP8@Uoчp\YҸZtc!RmĴ!*&LxP!sYm$' 4E^n M~F\rm"&57A,.UOB[1e.8?w66?Ά/\2 ݹfݻއ|)Z_H=*ė\OF2^lPdufԅOg}\MO,עn{Ŵ@֯H+ Y懤$2}ktt?T8ћn9"Src oX4ucNp߁.Gpp$?1l-g5C$z0o1z$9\&S#;:Gh3&/e, :w$O w3PwvFRC*m(mmhp9/"^">5OOR솫qHb]vM7rHC&ȃT@1< a g-{)X"Ê>CʪR|Ln۔6s.[m^yoFg#suυ\lV߯EьǹDrv016VP!(H̸hJ>qS+x3Ns.~#f9 Ma Yqk5Ix>6 "Rz$ulnqok~QɬpS.RȨR)9ȐVf>/ۓ_yȔ*ذŸ j(+2N|cD|>j111Ɓ1fCĤ}Pil!mmp:+*Z "\4*I!nB*Zaؐ$/u-[}$;~(v)·]"vxRQ\`&ﱻW/G%mΞ~\ t jmɍK.Gp}@ hAGo2_{/vɚ@)2# 9qE`$:@,kJ3J9fpyQv4 U1Jd?ss$2npc.w;iR "9{boOmJ" ]j@m,g:^w%ou*KW$mPBew>, BG 7dk_nO0@z F $ gSMd*z`m«Lϛ4#Q<.k@HBf4M!8(1!z;yZzKꛖOB]}_ks`fjMf8oEHUqAKl[zLH N$pt@|$q]-bK{5=.L g@[.@u+h4[D1 ?ݦATjG)^j1,@'x̀CByMTu5I< ~`24g1dGiΞY. }An\÷ʩ? B:iP܌/SEaFKbD>І}?C\3^:SfدS!CpSz% Yb逊%qȀH2buB9j-˴8܇}\kL.nY~7Zqj*Hμh Sc9Q&!8FzFrN*$qg9HK]Kr0͠g QrXM*Y_ O!Hg)@ .$J69CjWXC1s:)yBe ۊ :g3WKp'ӹo9^T%/F+h"qߘ 3o]HSy/'GZ utiykg6/&B7]JXWDB)_mL~,*0'{ #ha.$qfK**xIk(@fLFpCy>;K6JG32':גW#aja;3ȡo0E59.芬5KE('x%FR`WTƋʄ[ex򽮮f)a /ά($X=|q4!(=V K ]2ngc。%Eͷ$=IZݚϑp'QUey06}~ M@5@q:[ k鳳a]DDDT{hM;p|)iٵj4pY qb#mT?9@9 o*٩~5Nvv`ezehc{~DU ě .Fnzub"YB P?"3}GCLk#35BQ/R}U%ct"3g[^t/Eta8#`"Rv 2/;Zbd_%GgtȚJr?>4 ,qdT *1 kSrߐ<+Ix2_4 H.`hUMAgv4$J2y7Mq>s@],Յ2F!Kub~1n2EÍdQ>1t+\ʭ֟ yY*2]5dSLbx1Qo["ĶN//n,P~I + gblc&>F.8D,N%o;0^ uwoiP T\@{VJ+E.Rz}&j!Ҝ0u童Yn`6(ܣl\Z;P, Hlߺ nu'6?+~GT4!C߈l798C,:.L9SD)DN_nH"p*NQ$ r7ʗt&;g4}:R/5P_o\2&#ϸ2EG;.BwD$w݉Ƨdߺ! fFtxˎ-[ew66ʫO`υ1| Ro tvSSc _yF֨Ε2nfU@b=E[ |hmIKC)nk dޑe/%ؠۃep_B֖%؁?Αan\fB4P'@Ox#6YUf7SQ\?*PњηV+N|O|U]TkZr߽JEKύpY#4wZGwd1w%uY濊 0\TMV&0T<*3$լ#jT[Rm&0<hMVc+gn6?*ޑl}l KfT.XA,͔ǹnx޲OO)VMpbnJ;Ć6wg =#NQN6!VBA >mFM\QN/=$ѯz!hcjN 5Ik4'l~zGh״Rx?Q];@ْ݇hNžrs9ZeÌ2޺8dۙ:c3oU{S_[3<GD^(~] R:PDhA`dbɧgrն7 vw6g>pcV" i`6WcAS&kQŷu25b="71F)@~l>^{lN"B4SJڮ!<-Ziܮ T.o~ +tU (>i)_-B;WPIFAu]ܪl$Cu;lM$ҌsQ@^%{]?]eܒak y󠏐ͲRF"ZGv,sL1I}JS_{ri>.O NQB:LV-|֍wT T!N%3 lU&8j ΗQȋr GxLxXY@Tԭ? Дg¿x[SfOXf-.P$ mQs.uh|' ʆX<l©ڽ,hpg$5ƛ"~ i[eL&kz3X8ʺ1=/B>2sR2i5`JOӑ|UY [֊[,z+#%wZ/+.$T9'aGaUހa-rwҸkg#`ŲKŚµ 2EnD&ǼSO"N=Oe:԰ I&VDؐ;;NCD 60򙿠ϴ!Rg=:R4pJMt1 Σ#& OSF^-(&nЙelvm/HDS$#99!R.AI&uQ5?hŴ;[:ۅm"! 5j1.G vZc9mFꖆ' F5òs.)2lv+6fx6sWe$Pj3a\ I~ b v-KxQqTUwU9sӴR(@sApGɪ](:Xd,2i R ǹu.Wv5\ |P3%RXu.9C cS僂ixAH^eޒꁮdX}E D7QN>~\V%?!.V@6߅Ǚðr+Ø<+/"״u@>"B^vv1(-T&R⍈d=nl D>"w \W>WwwffVԂ+$#ę'?> %S8TLdRt$X Z? SVe2$)j+\ no L|q?@7`p`}Jpћttw*WK-}qsǍ 3Sa9=-m,vԒ:ѻ+уJ`1F}.8Fg DtdZ)γ'k0{ﰣt^8+u'lWD'qďskf"%n̶xKw6ӔS 'M`*"Xd|:zYyZG,JԼS}%t`2B-t4 bP&E0z; e܁-d8)W#/REX?uw<8O? O@:fôyyYO (|$TDb6bR0n*pYZ.IS3`C4+y6 XK:riT=a<cf1af(@0rX  _tĘNU-1bëԈ/P-9.0K=HV)>fYiAASg*j~ٖk:{a=}\H&<+8uK/U0qkU~_-"d ΗP|7jFFłO@-EO !f1]"3FK—T ײ@hLκ 3Ɖ4/ "wkHZ1#usJ%bɭT0 _z/_`S;:ib/Si8@gR@Iun5x0J?^( ̓D\:ZK{M?GDW)ӗ$Z޼TEFwBbsy<,o)äzEo fHu?R;_UӊCZtukw#AUښvhQ_r;X9E6Jё'hDB8"ƐѧˑKL@,ߛ MRǯbzf88#S usOh2זM_{8|1ʊ YksD5 QFnK)`eJao@=jwWBe 3g*bilZ\ޫS5죸&.1[bW+Jf֠g  [)'goɰ.}ng iՃ?aN¾XZKP:gɡk/3p`AӾY\|xw'[Yh"wBnR?'/.l֚]sw;30 L9ĖJqy c dVDTop4uλ)(SUi,q/AԥpTWsmݜbj2>K3b[ #4͏pahP_'RrO1~>i%`LmciGr(:@3^N6s3O5tde1>wدV~ɱi{wF~ ߌ=F1:lZn e,uW Blc$d$±ڮo+NEvF>=ag5fS; NQ +fD,grnKq$C(c ѣ@~L2I/MӈA9z2U筗'mNP=κ=7RR[MLr'5@R}`arCD4TLƊ1od27H.C廓E#rΫGHztkO}l: I6jp=%CwZ)$1ןX%Eƶ |`l_mnR1<&[1p$g~;~_]&Mrl$&ŏpw FEcDÏf$g)Vo߄w_>NSyeL[hA#$2( { TٶǍdoB鐮l -*Sɇsb'ǁ>u!iK.ѳl|?*䬋m9Uhlpn +MZkG ięrb&~i S- ,nhXa[M5;#Y˛f.M1V ꢃwTX!@,>f6fͩA| u^fUm4 o@Bz,"W:a'ئ3T4!snA9!=S4j{M)Ɋk93z;9w.Zآ胂AKDf4^m] È>hpVAmLv^W }axJN:Z'T SdzQW;VȉO-0Z5H^l߹ٍ/W=[p#uC-񩃃fT.l}Px!(dX:7 W"n&+a9<2 G8q042fO]Pt-kR^/5(Y# Y`$gR.*bJI(̼W@v O9s|͒8q2bi4͆SwA$xz^KtjAtd[ӠxYWapiXZ A@hXF:yif1>!ۉ_ט|~}sVTs6A "Nar!޿MC}>/ɓ.mDHbɥjoG=CVԈ1^' Ϛ'na)pF!T%>dpo df_ )pph8q;[ &*1&l^o$ RcTI/b=KF= 7\[k -:btd1o? G6Qo7N+(Wԫ-RĦS,qS=pĐlhLC/8 vlD+;QMs.h-EDM_uLL?ZPЌ_ k5[!J$_1Łΰj1MrX*GrU5|}pJzSzl'nw&t:,v%? smiʪ׷ΰ~v]//s"GD吐ۇ#,UJE1ej-6sV>L%d+ C@؆tS ل$#3.ރL̹]"% مk`G<Χ*xϮ?"4p,ce!z0lK2Ml$Z5u=X3zWV[eQҳ99=;iV=/s(f,2!ow #PBt#yUǚf,5CL qu~昛`:@XA3oL5'-b۬7BBdI2 d/HЁꖁ5?x$m3k8$oB:448mJ1[Юҹh'XEr{(VlM_̚aM Ϊ▶°\B-JsYQ rlE$AtDM!v|:3ƗNnI1V# [5F[C㵯[m.`A\ԁ%(!yފl;T|,5Pbh5 *EKYƺn_<+d]h!` Xj~&1I7fߠ5d%^"vQ5:y9ҲoƎM)K`Y?X#GssHI$j ~@ύ OD.6h|߈+LH!o#~و}m^1I#f~ R4Y+6TWŝ#=*Bܪc|[yfwYlyٰHn DX1GDqC\/5[δuy|wst H>\3̅==vZz-u.7<e%9)$ P|yp?ũRV h)nVV͔ rf0ISdvpW,;&䟒\JgW r( j; [1|=6LY:b|'?|]i7LNPû{fXekĭ c/$ _v#iߊjYe65ۢc[,4ۊfsݮ.;4,b:k9OSS yuS,{6X)xRnV}J½ nf(}-EIӦX&`QA? }ܼ0+pkBZ%`Rפ?њ7}jUrBߞ:Rҩ2dk/Eɓ#Vg u8ok+rF㹆Z N/Ҁׄc;KCלGƌ׻Ab)Ɲf?(cp,(:w= 7\˾'F' %sNѡTu `ЮI[AC>\&6f38XKs:G㿏WaYG};c@<+T[|YfNsڡi 19Ӵw dkbdGqU[[$ WpH.%-@3vP2WŎ%s8$z7#s[S{wBMw2v73-n7V[ԙooTlF.H!r˜zSB&# bCsF,އ܌M3=s/)Aym93Fer96pR6 .=drվ?=Ɓ0!iqRJJ\_Mfu |XJj~w2 f%q~I?Wo!b.>Q`1ۊh fr=m8J~8riz%JZsk/j)!ˬ<8ny̻f6XG8 Pk^ҷ3u52PO#Z'[4DjbZK_]a ZB `P8:},TMr6K~YBqhMD}g5kp^J#* `k\Zaw=G 4&Ew rnJoJB7˥b@-(:T6QiӨ?)95`om|0UÎ」m9zH@3 rBW_N Ă5DjX =|h`)g*!u I;0@whU5=&3jn@5R_cmW&X[@VЗ ͋K~/Εp| rܴ!$dzlIka%a ꌢRI+F%zY+e:μ`z<5!A6}{#MɃι|G렮)ÊwגO` yt~㷡2IWhKibH%d$Qw QXwsk.W6~<}EG/ 0s 5}wZ762lu, Rr#fyOfO̾xb+ :b|n_.-*'Θ*Ɍ<^DZs`&_)][k8gީa!M%M "u'Kz tº}OK$>PWVnZ?v!z[֯6#0iNP[ CijZ͜lU|C {n@;+<ޟgZj3A~D&r@><,M{ҕ,vteN˨pb0wpYW[W+61KpB[Œ|^{V`0 xV,O 35};y漘ߧї crsQ\ISu۠AW_>Vнiu֖uyJ28Ag"4H=IEJ}ĻH.Еmo s3NbA?Cռ^?Uva9"ҞtR-C[DME3arE}~(]bҬ8*)< u0U nOEVq;/Nb:4=u˵}Q3' VP枊2x7P{qc&i2i`aK@SN,PXXˈFk'P I]&4RTG r؟,*ľ' fLXQd֭3O ;^iq[6 XXϓ+ȋpGL)L"^vH_mbz@sl$قouM4&W)XWWmrD˝/\Pajajb\J~'mBo$>7wYGPp(K( @܊^%8Cۉ[8"wTyΩ#ȪW44? 3 1Vi %25ktq<ܶF+yq!rkxZmeyƉ[؇x>Lb!7: ߿( [٪{9 >n]V,[ZLdl\H͗"\i@}>u(ҦIi!YIw0,LJ:,z"e$:]e"'T92A'6 q;t+ }M@<8 a.pp$ڋ(VE8.ZQPqL,OC[|vAn]!r}3#ʡx*.V/kE|x<yl.Hz@S }@a XX2e;qt-5J+ k#)ȧBdQIv:\wnJvwڻNMD47ti^īK@nS'ί]6vF&W/;Р† DO dkNؼV8B62OJ(O?~Rr⠕!d&{a6Fs3`WRb8d[*Gqy?sI΃:8xKS"@-ZNp [kO%2Ec!"9MQM_6-_d,nc:Jľ>BUA~;TBcTHF=uH//@2 =ag _+oy?a]\Gr'Px0QyE|3cz\o =a3+`u}`4DnFKe.J,E:" ad>p2o,&'MXj%Q&t:ǝNg־?_6^=0r\,_3+2elp.O{!T6RwA|fx,ɿ@xՉ4m^ѾSA]Ԣ"0 FpnPĶt\Qo$: |}5+SnK]XyH#p?iɋG&NސBQpDmgN#ℏ&4BL8¤x\BHi{ѿXm,~VW2CչA3HZ9^dޣꏷUӎ

iG5U++LLY Hb"`>V`k^SA. Ƣ\BS&8l 7υygyU nNo&"XAv<'w/P'G nz}<]nܘQ{Yb/T?A /^9p.o4ܗT BHbL4=q8ӠނH3 | hVdD 7?Aw *]xQ#"`4ĸKӱE;S;ٰPn: /"￐9dqj/5`x#R@$AψEBv(꓊ڣz34B˟zd=7 ܺ,ta3yxOyUrתf7-` 2~ھ;~Xm1b!a;5֒T\q * MwEEcsW ~YZs)@])NMN4eȏÍRHiv4,@ i`m֠Q xt]Yի+sXb ~"QP=,dTmRF6c 3iDAc]V9oKYicN,&[W={xNFbЊw~T ARs(ՒC*⡚I@Tss9 /IX֔Cf"p_&#%,BTlw(;4^eʥe(շBs};d;AE~%A}>Q9<,.cGfώj2vNdxF̀dS.f娦at?7 r7s0rld}Kek# GZ Y+FW0L !H`6<}ZGП^f. n4|AJ򚷛Yߦ#o$͂Fޝ47_d` إ*}W6K%p=]ػlg-.~|5$"O}z JNfHrp˂6bM;6 *k0  9DJWq gRphEY*s|::қ2_P ͵Xcx."an!| ělj]Zf`xA|\=eYPEVt1:Ő:>*HW\d"0C¿i%l]%*5=)%^n.|PY;nT]2Xҫ7%s QFFo",@T4ga4'>| K^ :"҆~_ٌrXμVн"|kmgcCo6숺U t'ssY9*eSE/:TB5 bݸ1!&E&+ǵ oWiy=uvt~%,!Cxg~kcx;w.g͆D '߰޻.I  L]Y֠|Cˉ6mR;3+E_X_l@Q@\(mN <ͱ+P\Elo"ǢpWV|t惦$,$v튔z ʀװdP  Ѩ%} U1+} >V䐠89^ydE %Ď J+1j&VY27(Mzbz-9ȧ);ڝpcgu S"RJ Mn{{@}Exo+Bg b;X2{d$˱ʓZW"N|y|W ñLz99DR\DA,)BBJUg2ap7,څoF?_UxQVa_ `:admourQqVbysGUC$kTyr9R[(e$Hc-,:IsD6Oٹ'dY`bYݔfxa Ǔt ,8nM l"sf.jN 6 k)1jWHƲEqe{WaPG"g0Ky:@M뺭>Rzȶrҕ&aɹAns-iT]؁%$w}د|?(ww{jĝԋxPdB01AR}bȦ5++M0ZǤӦSc˜j6ʕ?9^w2~]= &7HNCA+]?4Uݤf-%=co\\BW_*M"MsV?np._%C #.[8!RTw6X!ȜvnF1IYneu(.@4&P b+*'!'^Ykv>g/KR9x ߸L!ANV{ZJC<+ WpZ_m] T좉c+A4Am+ӮjvG]nph܁E|4!]5 dD zٳنo@b3 #} a޺܂/(k Z:տγ6Ho59e Z|>řπJsPV\@0azGzlu֭"#T^>21TZ't+#d fyr3G|M3>᚛qA`MJx\WJj㈰݄s]gdONzl(4%EaciҌr+2ʙ]?jcVac‰ER`L`Dr1 2Ҁx:GKߴNd[0#Q ql L#^:[ZpJ؇U}4I>C2 ׶^^9i2vx[3,%/xyKd(JOW\NI7hQqXW>H)$lgnr#[kXZ'_ȵ7 L-Է)l˚GmVF [hVG\4B0%ȥux P60qgHh.FJC{>Q"}"o3,.E,f>m{e+ _Gt;)Z)wtkwQg/f*9+86T .`EBe!fǯ4տ3R! _vbGv j4\%آt+mmK\x (ӈNXA{?~<}{ vH<_5HYQv%|/ΠMnLĹ$- ~Ism_?g?&]K D㗯z|QjIa;,+ #MBfѹEMTM^ύVc> ,VF赗Ʀf|g#~F@TJ Hq Xj\āV ;oe!RF4kȵog%{Oi|N#Hw~s!W;eO˷ҥb(ogLLڕ6y=#1vDL$MQ8 [?ph4+"tV͠кye[8Jr.<] @p[ҼRb98)cʵbvjX7C|EaU"+J 8Q.X8pVZvㅚYW[iXJXDZ& hxl)4S] *Oբ}yQ.Xm}%eo&[]L2̜ _26Hjk+a!3zbTd%y8Y0Yʃ/zcM Lz+m71'+/N:IZEbEF*.k g<+_n)+.@ljN5C0vnz `"C=Nf E[שn:n5ZF/cN`à-R6kxY /+DCFgY νa0bvƕ0ܵw/ww'4GzlC3O`?n$Tιk뒤 QY<#TP.aeL)p &Cqru^ǻ ~A׷i5V#$0"yaL[.6ffTPUMҨ+lu%*Op)}jݙu"j"L0yya 3tj0Fbft90o&J?^R cpA XEd5. xӠzqrfTG3Hn1TYp!cUװE]X''} F&A hQ4 }U햦V ^Qcj@`vm^5r>d Lt8q;5.Ot:<4@5bI\Pٔ*GpC fm#o:.6(JK黏F VPKS\IrXDsh˕H{30Ԋ>9E^]8د$tMg7CQQFur6ڎ:-)KN;|ߪqZPےrYIڑ xnu.T 𰶱sx'>,Z"أi!1Ac&T"1Gnuz2j]%# AHAӈK7M ƝRyT=a_w{5RWX<1vLCX ,+Uc>Bs,eݗn.N;eΫ(;7Te@Ϯ;䛆P|ep/xmDR7ׂ'!U(][-rMJlf&CV9u Y9SgXIJVk^ht ( 0+ bC E#jd8gh#Nrt~E?{-`'5ΕFD'Z`C>kQ.K~>7B^k=mژcɕJ66e :dO~܉Vz66BS dU= B-vWJfdr!Xw+[AtTPWc.f_i]5H%Pڴ~Bh^[ 䦼&;i9<[X:3lE hʼ{0-KN5-K\K;G.'D SН=<+M=E& *r65-0յJdtrQz{3:96QO#4f5(.޸ӗHrQa3騵~L/H&;(ʀ$8cWXS >]c/Qү:(^TFj+d{i#Wct]PCZxt㡮˾'&,o^|R[U#DH1DԱ<^m 'Q*icTE.P(qJv!|9JWSA9cSqV:_H)i8b6 /nI҇65mgJ.'Yҭ'fRm %8P" ȁ~!62 Xj2/I |mU 6 RAY6nLE.0F?I^12s|"7v|G!}?yb r_ ǂM#OE)cRU`="cȚj8u]|A3ﭾ!'"09q !a)h~3Og0D./Ss\x8wT?-P2ں.B7Cx8Tk82_xV3Sr}$"iZe(YS}, s{ۢ)P8P0ކ\Zڊ# 3۸~"3/aAo+-:C+.{цJ52CѓHckY@=:j9dwFl i|9 <;4YJ6 n)"PL܀:<8C9(8 CsSJ9n?pDr-2ӔgnGݥa ̈́LzR: F*>x9 Oz‚~܌DE \v!GW}m[(*rjGH<\;:e1GZ@HQ&P>E:YkTT0TR`aD?'!;#-K&y\\|r&4G?+$ʓ}D'w~SLX ;ܴEctl{7[]yA>_hBŒV} g ~Ix&FQf%+&3W:S\69iX^y3qHՐc#֟B;Aݠ7Ñ ,cN'AxzD%"lNl,{X/b+1#mU7ı:2cR|.Ӻh0E&yI F/xt-YZIA37 J(j  nvK-I_ۑ1 ֆ@#z->kf#x |f|tby(s]@x$y &x)-ݳ=5L{FU'Z+0"OΤ|T⸚ԓwR w;M[.l"u5]L20O-JT<-a5|l-:|ݶO[޶*S WL #Q4=|J"NjjcOŮ&p;mXDKRD8WrAL{čZ]uCXcȤsb I FfWصKx.WT2>\op&|ʙsh6{]q>|K}2[XRcr^郀+pow T2}Z6B̾d `zW2ُѣbfvSf$s | Pf2ӻ:Rُs;T5v%Dzeߗ]Sn$ж[j9)MVfE'W+l9OCk-4'oJ[PHT{r mFC%\Ğ\[7繺v:R!/"#ë&\㷃ِ>^[ Ubtv0Fɥe PWnmw0qg<ɡW3SaqS{'+DZUj4ɉ9֒)XHy\ą6 x͙#eƻV89|nXo+xo"7LwUkyV|֙Pbh7ENp|q"暣L1J~iaˤYX0!g 6 .b#&Q4{wEkd9⮾LjƸr"jaW%\4ꍰ)>vfNEE; BN]ǿZPUGxr:sw8C8U?A9 BRS]>IE\$켧H[mǠ Tc5-YDꚖC)7c+&J 5ۊ%i,: V(uUι0K\V'VrU/!KUiznҙUx(6&nfZĀBuA@a}IBq Vvre~1iR'{\'!q/vܧT& cvsE*z+&.57=Xl=3#DML୺Eh1 SFyZws-.͸~P90ۭ#I9@H N3P#4Wu77tJw #!%~W赻Ă3%s!j' [s0bq˪q ܴEkl(+:˱ADBc/k+nCQ7=JgˀӖ;N~H2北Lݥ S"R=GJ/:9pu(y Ӏ)@†@3 ,^ f DQtFYKm q \iZiT <OȳDo½gY҅MGdW4F0\[ xs5] ԷHD3-aRH < yy)r~Йz@>։㲾X= 5~ϥA$sqG`mǻ\?\(k{(kJs'#3ѐb-גnPkt`'  2حo? ̠"Ugk,ld~N%г\~s8.{ߩR6ZN-:O8|`2oIQ@b;+Tן?[%o2 b3iXR0'9BE-'<@UFBBG}S;k!ѫ<- ~G*CܼJckntazHPR,,Bozۊi{!BBnL펨?8X`2 8D0ΐ#6Bу2n>a4#G&A+:DgP9R@XE*/?k@(+"(kUqP2n۠  'Jh~o|N$ʏVl-J\xLNj`?j(},6#V]!pĒ- Z= +h%8B9 ZURTSu wMkʖW`TҘ4 J OY8K̈O%kx 珔D62x5Jٽx[=S6Fdz:xuei/#Br^ V^#p|C[*?[7u>=2,B&5qR: a 4ɓڱ 8Ǖׅ x'6=dS2mD13V .h!%0ڱޭHPƻOnW)v"BP "*{ <+:3~c-,EJ-Wx!.d߲/5ܐ Bda[FJ4Yyi)I렐Qvj5q;,"ețҵ~=A@*UۑPi[%Of֕ӜQAt~; (ҳ~F愎~}0OdJk0k>6RᕺI8(O5S 3F .Y<%}Tr^4J*zp9zJ$s(iP֝M#@ZlݳF$h X.R 5Mz_N9Rɝ[f+d3l)󗤥Hh< FOUE]FyE&aXOI݈[ޫ޻kHgl#`x UZjZE fN|B]*]He?6A0:fL87vT*8 - Pr9nG4,-Hwk"O)3@d<_3kb?✡ÜvR@"g]:D !G!k||}}&| rn϶@a To/ʪ>Xp@pUe5eS,ᙳN]"9KǮڀ%䩅d1yz޹UqfatEay ^:ArVI2ݰv>J.xU"G]vyBz8z)._f󄐒5#(NDɐq/pt"D`hLo Ll R=mwx؛`졄͕cc{$((,pP36YAӁ)E}ޟ_Pp+Dr側f4o2pX*Ĺ[*1P1G‡Q9sgCvu Tۤ9,E;p"eDC$nIu񶢝vZFaj>4dV*j9eNd+ >>ujes g e1 VܡȓBtm,2=ZuI| ]J\%x-JarV,4(O^ϙם<۵&ieiZ;dU:lzbXAzit*{Zp;yʳ%IKacƛ1Z~-S237wV &Ĺd뗖(#Hl@ڟ䱧Ѿ}SF;E,=L/OmvlɬgR QxCm,_/sA/~R2x4mw ǧ?TYr7e><?z?9I cE_I~ 0|wWE#Ym3 _޲`,[#:5 )o1A#& $T!k0fl2G@]dFIqFcAh<JEgNUYA1a]PFdTg? Wzb Kvf9EI+)Bs?4ױaj!ߘqij™e[ӭq?" w 4p6kK˱'E)$Q_Dc^@T4$D-?I냏4pR갏O#m*<2RuD_aӖi{&D,ToGh1yķg_E|xzm"&]7PLj>c+IY?1?w-uh[g^jCJ}`Ȇ2׆ȖV#4zsC036DYPd[e0(D`M# N.߃\}0 T8 "l-?Z%VVH;XF͟DH7ߊͱd:')Ь֓쨜Tu=.IgHM6LW!DS|Gw0su1Η4 ly8&Ӊ xzT:oF/[]LKA}>hH DT=;t_1 8VU3{0S;qkw8qM,^hkDdxnx-F9bsJyߤ^C3˽ft8p4"`:$cU#mKrhZx +N'b?[>sݪpX :ߢmN S_]aRVړaچ / I8 z/0u::ГNCw{ d䖁F!;trD`(! c֌pFRNH2Oݻ;0G,ZNT3A2& tM^y;`GGُJ%H=T:r ]{<zͺ4T҇~+kfMDT~:/u-: !K?ý w톌|Xe< %!M?kD~94g,Bt Øk߆8d*96%wwVJoQ J`:]ϡljk<Fei~䃓(lJ?6`FIz49NיY7{z+kܷ0d 71 Ϙ:*(ӕbs6 -Ēq z=eW\+cxpi]W,{,"-F_MrPS|"$+B,;'M,4flzz݈ҦaK q[GuMeK]OǼ0X]qɈAEf 1ZvO )o5BPga+_૭LK^I~Ĥ +A݋PoVaHf~Jaq=@$<(w )qmRb,ޱ#J{7]Q}rdweZ3A0>{"N32^4dJP('7NZw+ESķIW+QWmk[+Xm]|77Π5 r`)3׮bڬORe^3_}WpY{g>Ink%i4^,tt$&|e3>2.)َ\5EVDQ='CT⑍H E҄*|w؋VcWnɽL Lub /0 o ]XUW;jpzME2CusÙjEɨuSxTG=T sYwz42Q}%loťG]j2S!? x@VگE5k+[y#p[:]\Xld:koۆҡhlxodQcPzL.jPZ\տi:P6Sop#@Rby~yoKm[w|pBN|HCrZFjʽ7k^2"@QfA*qY voOoDBԼ;9[Ć2HZ)Bmi &P7iy;vou[8Udn JluuJh fϰaqUفHH$Y>tIuꅶ>qIS׌ 'rnZwl+s0&F0`BTP\Jc*Qb|EU[G8)݀ng81䡂w7wWܨN:בtL-y_j5/頁[U)n0]T$ijF)+Cs(Dp>woќP,9$aC$.'(v#]:evB^+#_CE dcXcc:a3\ ̢҅DFUcVfEpK,` AF ȑr έS5#6=PS;7vܨ/h%:(Bz>N fM5iӑ)?5d^oW"I\t+g?8'D(߬ku`vrOZ\3!42 q3ZCG}\A:6ûד ja`kKnlve~R_M H3J(%ɓbu8LMp/NuOb m -IieLWIW1Sý2\GM{rl"4.}f=^GW_~ވmoqY`<]~Fna!B""'.gr-%+⣨D-! ̹&ɠ+)raE=Tܑk{n L[E羢^CƂLbgm܇%0Y^/Ja'1@|/lh_Id2 "`z LFXbvxK΍aR""S+(0g%Us4bU'j(Mr89רa_rKQ0c_W1-m|^g¾^- i'HZdd?Bn[CW߬rt=Gݪx3*aQv4 Qg ihUoavBE\ݹV[9v=apr pHڊtȀ!K$Np4XTŎ/_-byӠZh~Gh:X{D hĄ\]8Z#k 6ݺ3a!T"!%zs P!OF^/ A =\f[-+@0P%1+냯uWD!-67jqDuay@oP!baCOԏf"px2Wv{#q|m_ Z5ӿn 6ؙSאney̪P Td@r\Ԍq>jKf?⟗)Us=x;o/wpcǸ8[/8%-T)t/zh)sRveX^4gKB0m}썪3<<|z"U7s6a@egm0;F숊 SIQE6MHZ8{o_m:hӿjhe iZQEC6^LBF ކHui`4B{xZJ 1vIF^3vv)1e}@>{(2%0$ZGIph!i@2<֟uYJf='j$"4&REJ||H< Wn$>MMRj&|/ss6[bL90 .!& 6: BQ'֥C蔻M\d4}4`t8M /׌i#R[笖 % }1cY54)[-=ʮ9ꮲm4v/0VgY>Cl~51Vt7>U'Z؃bo|Mo\;:\: (KKԠ)F<& Sx{JZV%mKL uWS Jpd~KQQkrC`H`=(Ggnrؕo/+Rr~ٚ&Gvb>W}_|ǘPlF;O<7bS. ҲE{q͸kv#I|=tl}He\_iQܜx=\s7! H@}\21EX.ڦ h‡kSS 1N;p0·D8C-_N4h<&Lm6y۟L(hJa\Nc6ʝ@? H%OO=?tG^ I =~|($62P?.ɐtνRFfO~1; B瑋Һy@mm SzHkYk??W^Vΰw󎠨^E,c۞™rjUfKY,-S?(%PMx-~% @6<i,EZÃi<TG7J QY38]Bv̨Ơ^Y8`o@xg~g0+mKXYdv_q٤ n& *ULܐL}m>QZZsRTO`ЂS"νMKY2 zhM 58jzHi Cr3JMdvIN9#uxۓxaozþۯ8\݋cU+7>62[pY_i3ѽG!׾X5Dʖ^9FpR@\\ʚQM&q{y6FqM,Owi:)en)NܢHyJhTQ7@#aI8 j]/  z~`TbD<%ؿZ|~`  mTEzma3̥@AvPBuVw{r{{,[\$ⰕC~^ QX*Ọn3&1&wBfJ 0@>T|p9DBwg6!|"1N&RsK}2|O<gyDO@Cto`~k4_11{O B%>i'Lb"z+a~A-'mZNܿl9Y&6:;$M^?Ķg +w-YqBN`ʘ3N$ 5ÿ/@ĄQsLIcX^ /g&MJ ^bG Q"mƲj7˃dcZThv SIe:YpGM?@^^;4?S?JJm E~TM^gʘ}fOƜ%KXRi?I8ga^}jj!{}Y`lǐ"c8J"!a${k{BB?~' NDm4w=Ǝ W"bv]g [ݫJD4W28m N&Si< : ȑw$a^BSG  l됊6VwbfAz 6ZD#ۅL.yi3V3NBTRbW YE".d7<ޡk!0ym.X/vReVћ=lap[7r.wb:v:SQMّuVҎ NNQ~%i2?(URao /=X "=Ōz\_~ds< rʨwJ 2O'˧Z*}L@]VKδT_cW{stkDi"Kޢ0' T]ŁE"vaTo[u23p}KVFk"@HS i 15pL0jC S"cMN-I]]ԩ\JX/Bh{XψHUUˍa~]q0Y+*O}f4M$k|kQSJF5.2:S!927 (o؛9W1G,@@ݺ25kqVp fV)o#di)j\qvpE(eFÔuAɨ9>,ibvFf\ZU@}꾥#6`R^j>Cv(fLw5ʭJIM'D^psaV?jʼnQZ_I1${z @g vb*nncկtOt 9D$ ǿڈs}z|=3\!S0Ǧ1 B7ay~ bzp^!d.Ubrv%T|cIиE@4i4_`o(L^y3C)v X|?m(0d(LܜDŢgW]?A"Xͨ 3X~/Hu8t7LѦ'Syp/_)%, [hGJ*{1H5 DɏTr0ЬR0dttSm.]jֻf| We52o__{Wc}ҴypxQKE--BB9}Ϩ =u#LUB3ڽ-P;yf(pՉ|T]杇~VR N 8ӳ^svduN\UŸ,-R[3[l)[rkւx V6" rb> Gf@c %Cih+V{' e:#}Cxنg͇ڛ osE+Nfr<\YlʟVGdx0\C)RTfxuuJ`'Od<)/+F߾#4iUl8F֘Ns$^F1ߤ Po* HP8 ';G>n' k^!UVdTϳ&f祫ǏWy:f&yvOy5׹%n$t]MI^Z>bx¤=:f mivRaAQd"!YI0IY˰a+IGy3 'ف9ʿ=\L|]R{n(U b{F9"4U^ JR|a;{k\lY!-zN!Pgɮ۟obrGWLR-/eq%ݱNrRo;1^M!p^@Ncr2g[G~ͤ~S_?""=о׎ Y`<8pAfU|}*x0Ay p#d?{jV/BUp[(x% IGQs-uQ3=y!͖>4х? "DQkU11[Tx୍2<ސT#_G~ .qVQAYM6PFX۩/&S?a S~yXShCu,<M_O-4FX7oӚ}ATehv{|nfKw'E;saWVtOMU5@@y*S%$OR-b2lŘO~||?Kxs6!x]ΞD㘄JKE$vl[;_灎b˫8A8("J^J(󆹥&| [0bԳFkX(;'{.Da@OkBzι^l8_i_W2j/ <=n>'D2l/L|JyRJVJ-MD֋CLV2=I3h#c}{dm@CUU59ͤ-"D0}8!2 W=3/fXxM;s so=}7 H[dQᷪrxMc}*o4ݏVc[uZ4ˍIơT^vGLE&?H զh v61.j}80$L Ʌdfwxfv! *"4 ;~XRb%e}iL!K>?EB3^ϜHWDo*U}JówyM;T^8hnߑ8W4 .s WհDx F[?Ebr<7]tȑV,i!j/#5Cjlŭu& C{ewWvC~HX¼RjE)}V~"ÿ:" d!ku 7Eeo*@|?/ 9Nv/H21Ei0ZVS7VW wdƘJkV+hx!dESHT;+X,;؝8EuՕ`VP]I} ijIP$ͅcosbDW/Y?n)Wx)}?e%0k&Q|@z~)i. Nsiu[cQ)T,KZP.QNO{ }k>Dg2hiW0:Q#eX->Wg)v+ )Lo۹_٪ e"6G,B`޴pY7 u(PeW|Ji V uc]HV ,H-NPxQ.^6D=Y@mRj`(4X' ,*::ԕK Gf:qS,|9x@"39*X4n(CBoaÁGxb!ʒ@o1zO8mpi1ɡZࡰ! 7 M2粝>름o\@ˇW! &ȶg@1:[Ću/i+\Ly$kTbԜ ޘNeR0)T4ũ~l B(҄Yk <+Aiґ;[%r['LF$ÇbJV5k頨;U&rΓyNoҡ(|d1Y'd˩5 -rMѳiMp .lU\9u2h-]ίُeeO"IIŚ'Aux@@ 9S*ąL_RAڏjLy/NƒQ8lmڒ ḧ́Cȑ4n΄cW Ez8(MصЪ}%Qg&F&O:ըHXF%> x?A҄A˂JKZ^4{.&ׁH6ZYvLj]hZ`EXcSQ'ʜG(e8ܙ6[Ԃeg"IL1Nj\(i>a(IF cx o-"#-Z/ E|MenSz2r7ė6NjR$7B z/`tv׭ ‘$Ti_e꥖SҲf_o!c$ɿ0v#cc4ImLTIG"\ޖ MMêJ|D*Dd5?4 K DTR=ȉZ5,>DK܃qln\ي`jiS,k%9U3@έHbcPso~Sb%S.Q=5b3WopB`ot9.X{%Tc(;DKVbT39Ca,UWl1-.VQ TTp|ƀl ʹCд.((YbyzUB]Ϟ'UQu!5~ShXjk4?QV*L& ΄ˏ5ENwpxf;+b3r"z -s)'֍ʀbzx@9ڭ{Vz7ed:1lإDdMd?هgt>\! BcFVo?AT_5dN ըyI~̜+!~"T(;wd(饚TW?t'%v!)О#\џ]qP#X4|>CE|L>OyXG2iV4s1uǾZ%$lKKGdRJlKA?9]g=ϻ݇BP'QcrA7FoWIP˯%IJΈVYV:P)cV7j.ƃH,Oa{xO%B@W-5.`}Y@z |djԟ@3n.p,RIN.g>lWE>_K_i~zLڇq ]mH_PٶNO:.BVKy݇iJ_;8 NoV7Is·0n_΀Uΰ\P) 񘇛d{)9^LgaUxpUi%/zvy{<`yg=V>~tk. h-݋l*'CV C ԴQ a&/=1+ʽ(x]Jr,uw8Y9D^L+>`ձzWSqtwo8MqK$ΙD?:]1&v䆰}&.ɿ,Zaj̥1> GⱤ%3*!$'|7;8! fǥVW UYdq a䩻Hp{w"lW@/829@M=Eh-I6v([cBKZ.{)yBPQPrn]BB]p!Q}*Nzx|Nsk]2>M~3t8o,dsJS?SJ:Wifz_͋r[}7rԌgĴ~?]-9u)6[:Ll1%dV :s& ƃH_kC7XًsLݔ̽!?h LWcPtYR͒L_ ǎޠ!#wyO*{_EjS#MvMY!NU'UL4K7hz b|  ]~~1GcveahV#_-ږquH xyMiS+}zbS5ݼ5t%MlImP=ZG/l- *צ[G< mv=wt6]ٚR>X_yE: 3Ӌw$IQAMUԅn5834Ns7y#|ɀdj{9  ]O];RC~S-kKtԹJ!]%j!d/ 4{ u%~2VT8ot繈 Oys{N̵ 5j* J ay{4< r O 5eb>SaC սfmtkG(S3~ Sk-kߤ&EEmWie&S &J 2kCt_E``8w\Pk'* {ԿˆRӵv0yIToAn K$GKܕ#/ h2 ]_E)pv)[5:ѲVɼaۤV悈$D$eF%u-',ߚxQW~t'hC Tz&J+2 ƳT!8X\uzA ey@5=Pt 84/P,mMoxe \Ja1'eif4{-q eԪ<+eEփ?V֒aw邶:yP 5KR^9!Ns@qekT@H7wDԥUPix!XL()/s)m-% C*B w*ԉ,Ϩ3X*e+ǰDD@_Tϰcp/ RbA1{VbQBП!5q_A7@9w1nogހ0091ւOpa`iCQ~heFL]\?tv-';*:z^rC-s&As7|_k|6{z zhNz:4uX |PB ;T4 7-tH^_d)mBX>@EXcIʉs muuF֎Od52qWwRl*Ei SchͱFTcYt:`FҎ.[~+&{6VJ%2ٚJD[H cU0FcB8( H \ 7%9X9^\Q1[XoxcqG=+ kч2x NX7NjlSՀ$쒈'ӋzF^72KX{>y@~DanW|"[$>Y)3e_BM+/Te*A!%ϥǬwv+ B"ik3+R0]hf1v3V]XܠI$b&HB|6:;; 3Un3/;@-qeg *%Ì{%$[8y{MlEX-; N}/LMoOpɶCM82?~)<Di時X&R +qWMc{PQJKXqnx۰p\-PfWʜ  xh q=U'][̀8zڼrCTm۳r$vޯZZv2G xd]mlDQ tiLub_|*N\ӥ#W 9 .$Q)u*'rotDDAƷУ3Y:ldlv -7pKJv!t|rG|f>ZH {Ujvpz 4GV+^ ]eod^;a"Nȭfd}W57C$@JAԝ' XY5畁޸Q o3a_t$+0Bd<0Hg ܺgɮ_ݍw8il5\γ4;öQ+9}TPF n+?x1hZKqntVH}VJޔD^(b"+OE‰.`^7Ǵ,u|9}%K>H(x|ͣlF.; lt5-}]*!rXdb3\+f_|5n*#:9[mJZBNA PL-+Y&«RnZbk0HlD綵F;x`r7yܙ"^)WB,;'UeqRcpu>dT9gHzxoZ\G5gM <>✃[j8*A,z$/(Q;" uKR}зQAcl4yEs/ w#)T`"< 儂mI9S!6gfz@Ώ<` 7}΁ VUz2wޓ"*mk42CKn؅и? \ ' -WA$|&d3>!ehò7#9G#J ӝA&>iΜ,{("}Sq;:}^ÄFMmu 2q^0>+]T$ھELoSq2qv(IOVŸ\F<7*[@ =,wUKLE`Lx9@V s*LE=ԿE;kddh_bjE1i'z32U8Kv- TTOf,UQIt%Ϫs?X&V$\#IZT&+iQW^9S<߬q]YQ|=54bNG14jVy_6ϫԯP]@ ;:3yMT}F\f|"79B-N9tst^k4[Z\(xvr\3UE&͐ANoQ V`JA~?N݉'2Bl6c ޳l)T`cG)Prֲ+c9U*5h1 >z%103uxn1B4mJyh~ a'< (7r ?1DXތḬpj5x[B{ۡFJϭfSi PAgaall[}dJ9#9,@_yWΒϚ71Hr "}Ьy CH,uhދRFY"#uyPQ㝮HA_k@^`<9l {,(lv}ܛew3k8.6k0}e 1t⑈荮6[t&f[)K9؎ qQ(G@AxdLt \E^I>=H$(`APkq[ MSsIϬEcxP@ ;ژ0!še/]sL:&FOV\8&@ mBhἝ-TH?S9gf)yy6C|Λ{0QVPrNGآkk^N)jH)AI#(LPrùRz >H6m9Lh#g֋SeGcs02_.iHi~Xz+/u~ir{r!NGHQpv[*I dN᳸Oat#r!sRߺ.ᵎDs̵U4ѭ]b@ zT¼`YO0EQ3HblfU^wjJa.k m aoQO +pyD/<}BÄS RKub ޓ*_k!ƿS)+-=ʓd m"}U䬇{^{ߑ MX5pU8ʋ ~}q^۸'bW>}C2uQ*̀6-+jzOz0uzHiB Rf*R$u/32l0m_5vM$[b,K#/Tʄi#dœk(U%,c0]n[L{Be ©.Pj2~7; Jt<~]7KlAbvj<ܼ$-g ~8 7;Qhc/r2w#Ը=#r]^ Un}d+S`ؔ&YYK2.ʐ+ɫaHGjH&hܟ}Gbިo5v>U-)&u{ r[sjLL/l]G3~dF}ODƃfu1NE;0:~OӱK8@\l .1VR嬨RC-aaӣ >Q\iž;ppS U9UNLbZ;DiW\5>yQi^R/fDF~Kko}"iiax9KMС1r3WwO<9pV{y oP6އcG"\%_ͯSr6څ"5ߞm rϰ@5)`{@ם֔Km,nQΓPS}*H24mDZF򨇟UdsV.#qs20DYA@X}k{wC>ks$sp,]8?9xB O,m]kVr`Tek:㺉6\-X.Qe4 N~_ ,1*i~9q^1Oi0yINE$»F1#&Dx>GJN;|S ]]IzRZ =zyMI`gzr0|rRY.9%#EmrO4FqBmYôfpҪ >EcX0?7tq᥹s[Ktmi).{3XjkTr-Wlc0Vh !rw9x䊿AD hߞB0)/|7VFu27m^Mg['i1V*2NkHn%%qe._N6&YnWA Rf[ |/~RE%5=7q ھ$U&猨 *Y̓(Dv~ g>U *"5ykܿ,j(cWc2_T9h֙G0*K϶dYzzݮGBh![er kEky!&0'Xݎp\+&NpJ\X:?RQ? `s^SWeI&EQ_5hbwD"&.#}-dUd8s53֝FiMfOHܜeI~e.5k$ G ʛO&^£S?u iy΅sӵ[ N ?QkG]=@+<6C;Gu2%ؼEE"] >zE7Yx&O/3)]NCZT9>1R0"o?ZLgi9T M 洂pڽ̐7,uC^ &RAelpr! r% UWRbPVjx՜!IdN'Jw2=@-ѫ3)B `#D`=AW7p4n\m QCeTj \v7j-cOKn~ vNGa[\Cxw^Ӳ[@l$}rZ gdr`=7`s;jk_\W9:dmUǡnĒACUjK%sYnsH" eF/H<;ͱ z:2+ |YD:#q%&D: -A/#v?ğ߱m.֐5%6` 74 co K py{AN=uΔ3SL\>m98aңn*oZ /a  @REܰt%(d1j1+KR2fyYBTւX;рaN@P HY?ZoNҴRRj E_SJE;[2hpLQ9j|Ϙ!Ic:$"Gd)NU%>}o#&h}nB1^v%G~xM |."7H՗}ea\ h{duK3kwÑiE".(; /-4_X5W+m`=pt"W4`ыQYS6T8Wr|8[uyPPN~C߆b,ǫS}6LR~K:W 䤡3j!Z4)ʙAB:e;s`*^|3ecc?YȞV []S#8; wFK#3[p,E6\ʖA(f֓8Vm20l>tU*:G(0H4{_ ;Š'H[ (LS:(8&y_Fݰ\=PjkJo2eN 04C$yf!C%Al&b6YpofK Fo8f-_ĩNu#Sf`o\*'.kz /o? )i"7~wG>^% Yl g[-Ly<+Yn١@sǘfJ$ R8jl1#1\`ĩw 5>,:2DT\NMu02::;QgMπ/J) jެ*$>HG}WaG.aΉH@ RFZFeA լ.L_p_ݵӆo>'8,z0,]v)V ,t*>yF+ v/Yz9,¸ DOrj2K(2+cZNKDz,;kQ3W_\[ rd[y\InRKЗ1#tfJjgwvRo妵P*VA`KܜZ1υ^z|n/+,kL E,#hl^vڜRJ<U0v/MK"ri_Ake즗e9fjصHOHU`5cKD7ߛ*_OpEB O:n^nD);y4|Zj, Ѓ8 WF}􉫥6=u"7`g2qELWS!5Uynbg.+,"ƼMʉJw*^Fba:Ȑw]!498Wom=\ 97^Kd(IbĬaCH -+QqMDM;!s/3l~a_VwCnn…=U}7v4N) [d|&܂tBIvR8hune[1 ۆ; WP6B"r+R=}Z8΁v8JAGNkK'0n-OD}w2pd=([S-`Fxgg|Hp'Pʎm(/vpk@$!Y*[$~&,P3fraOuXqЖ"OX9CLUxФ7)0Y[ mN<xZa~Sme% B>NgX+Zvbߎ>⭁^6/u.:v`5gBh)1ɱmx d L@RRaIJǐ80ง c$Wֱ~8R@ǥZXDBK_vyF)Gъ5U?WZ;}VJzҸK@ٕ0mvhS8i=Z6qK?8 X0xen@-DJ6?%MiV ZGNキ92I\rC*!i&K`ԻMkS6 i-Lp%U/ye%bS= Bc¶CNu4gI,Q`RsT^M&ةH}1w0e֠=3qGP;9^v4၈P歷IIQ{dǸķb9)&ZBnӗ(IkHm]/~|6fuR^cly7r]`[0=Z(bU;={WN b>YhU@7$J٣%Q|UpAOܷ%X͸~͡~u1/須Q5MEց\Cho'xP_H u|x( Qڛ&@G ӋMOCmРv~wNF4Sl^"t3!9hQlAlwVBgx$M α0Ebp dp2F'7x^,'ȃ]J#1^D6bt\[+ü-zK>PsMGD⛯*8hy+ꜹ PsF q=4u5KTu~ VJ~4?ؠ5R b5\D2UЮ|5C8Sb0B%C7fn,F RD( eamQUA4`b.g-_d/`B ^n߫ooL!0YI. bdqDv$id<`WSP|FZm&{s{ 823o,ljf])Q#'u_~`Plqdmc9#x7_W zj6pZ=.+6$0@9ԯFǁbTjC1L*l5/weUBB"=TdYba#%hE]WtQk TveP7]~%dB_HK<45rzkdu*߷*$rj5`Zr&\/%L{o$))X("ɘ%ݵJPP f+n_ PΏ[HkWe\Ғ԰D"/VeJ?u|&`] Ab+OOԝdu:C0_+rmW{" ΁G^X&)hH_RL4EO1xSfb5c"rӨOYQxޝڝU6R4r1*jY8BTpSiTccZQSۚe dSu eâ(f$׆<_wo~t`fmڀ[7c{?"Gj-F~ho!HtB9ef?>1,f0 '). c)#R#M~H 9dste}fy h4MTc nʦ%Z!/u^*/uo1Q-Lv5+QaW3lmé8!m5Xu8ZL*rCʴՀ7 0Nt{O|a"Ɨ?aܤze P׸i0Q#_yx8ܳCgXMy{jrFo0_8k&ì.إvXY҃oxhDNilܤ+im.@fW2X,[ȑ=țgEG|Ԃ܂q#G:bi? })CNׯAۿJj=V7q„L2rw/ׁH.Y%ɁiYRŁZ8?RG2-וC5^!WJ0zpyd>s^\5In6ksb{ $.lawEL R 2.3āW[ɔ̟\&e%|[Bz7[v$W%b.ď v2aRXP'oUv$ }|OߣQj(!> Cc믟%Sb.`p}R=Ł tk< řo$1?WOx!NF?QNQLwA4T%, Ձdl i®{2JElRN.[G33ht U F MR-r8>TRP.egF| TXvC(|8snn2spw_=kV`7ARFE8ɃmBh20`ESг;\1x%if)$cgtf.+R4Ky9Bcs^0qpAcB[{ۺgewGQVA᯽RV/FNl <K1.|/xK\~7<E>Ր%]Kѓ-YX`_G; Fގ&oSKTN`b<݂jș%_DPwIYtsO+#^w#͎%%^Pҕ1^g#ufӾ.$n\|(ŒOSh15ӣ(iߋzK em&j;mh| }Bz/[#>K]09zpNupc6.I7sxNd1ZXoR']v)ThC"$e3w߹8"ǣ<yv-Tb+'b,8/h ހ52?6eOݰM tוVO=x5DfqŨgr23ݿUHɇLZ>Ʌ?۝2>[^Wt}VK:w_0!^򲁳w%ֺ l1ZH+oYb:*Îalzv1_(։0JZcuX8YO_<_jdf<ex3NfFk.&e]}ʷ+Z}R WikgCB0NB+zl =of?ŷBMѐ $}A.h&NX@$nQAKK$.w!YD Pr>/|6񲑛;Q"d\Ο:k;gE_X~w#>τ5;C@aSJF]ZE.DT'*vLF @K3Éx%,.! 58(ZbfN"l7bc!~>z 6vˀHwyvaÓ6=2|0/L5|/g4Zg>w׊~{jTf`yxn]2=9U\1:^}WS%0x;PPE ~M}ČTP`>\XCZƬaT|P}1l:뱠p}ŕ>mu[pMP\KKþHzcXgJW ϞCV,qi_A5,VbyDT2`Dm";LLKZyfz`̷R^h nar/k̤> Tb{|u8WK|O A%C2h*wHPbŧMQSIUz{OC 횸bwpkC2RaMDؗd$*6!2 ZdSSr ӃV@`~eh=}t#.t9afn=z5ta] K?OlL4^INa/,h5$22lnCϡ #H,/%.BhDtS^Qh/HqFQ#4c+VYVaMR%\ vU=Y}^~)ĵ894Fn31ȶL`s0.TgnL*J)_d cٝcW͉eL=udlMY$S%%86Ќ@aكzE+juI7cO~^B5qH}duxBF#|ew`1/E'?tlY V^so'-i'%_Q=+cTR6X\Ij㺆 ; ! uIZ-a/0iϨ;MOqSw  &!9Ѹ->1`>‚soΠX|Ѐli8~&j}ɩ L6C}'5%ߞ=j `0"R{N4ӛ ǂjgE$Hl4)j IVG Nɳ᪇(J|"A<*ẋ١[?г 3)s*i0[~irLiܔix;Jf{$*0 |ǃ:S]",V2Rz{ @ o h]R kyIk)19hMÃ@/v&WnlB-c8u=%~q`)+Z:?眘zm@RgGPda3o6xzQ5 =XEg)2< HNPje$ӆS)ݩ֠;q,7\VZ>A=` n)ᵕVwy3͇Or{vȼF0[ U7uqE QK=Kj oZ9WapԼEx027gǴs CnZY-,aX__k-A|= 1ߐv4&~P'a]msUBNAkm)gZ1):T2!|u,riWJl)UВVsuEͥSC '/-AR+3%R!|00"8"7Нgc1oߣR~%b~+Ԯ챳M~I(¾s-ʵ6/ԜtfOΛX}eZעBpSTyKnPV̲Vq8mVx)t>RyOX|G ፾j3 ٭/WLmgVݱRg7+Bh٩O +t{|]uܒCd4( 1^,.K 3ٕP޴d}a IݏcIG8U1pX&ƿZ%F,ki7s{zoѮU *VVf#hHiu4aM`qX)ʔ;K _b߬~S`L鞢"tή 5L4&'n^XB= Oi'23~v,-d"M钻4Q<) 1u^NƌriEe@Ǻ@I扁,D>i! ^3Tuge?x|QS 5.q}Te*oPGed+J+x {Q.#EZB}O6a,ݙlZtBI 虙b;7gLjv>H(`\=Ɖ "-au ҾgGG!㎹1ܤA0ȩ *tbAA6f|@9'ǿ":Yzu\cAsv`RXͰrld"(M@f=.dw'i VmTE HbgyưRraᛦkXY)ǗB濓u b{l0^Hm1.͍鳳5n}O \MyhK+ V6cMH* _Ϡ7{P_/{&Jus**sl> + }s[E@,uw3`h8[8ai|ۖj@ݗaY:Z֘ WQkψn} Dmqԫ[l:DL%խ05:ПLlUh||1#1B9VA-XiKQIw}jb8-o!̲$cG2@OߝF^xI(6PylqNڸE:$6*; $Ž@Έ殁&ݬn46%d+ˉdU$I;hFfQ/@ sJi:Vđmr(-N _Vg8ٱ:Ǽlp:{G}]b+ΛwI2']lb ;4 c@,#ɭ7@S5;D a|kJ[ioeV0~Sȴt@Cd*~~+ʍ߉0NN{~ɡ,B`0M"VA԰vJo  q6 3"[\sd( ocɧPDfڎz~Par6!%џPrRmzĬUvMsΤ6VXu?Sf'RX0_ |,9D3rj&-?(%[Ļ|tHp@QN" Ԍ)2-C VkUem~z|%R[aoMz!NbȣL!&S{/x5^,/Aa 5wL)arF/<[QnWC Zx߼*A WGV:5p&<5g'\Ύ;OhƗ9;~7] RHOjF}M"3zw8!TF>_3֩BFI&ԥ))$Bll߿4O`)D@>qoM+L:R(ٍl(vejEh|Ɖph` T~CDxzx?j0o 4߆}I' 8멼gts͚PϮHuZ~K%y$\k^jn5Ϩ1Ǘ:m~Af עJOaKN; Q7yxjxNg&C~~G u 2 } 8S`N ph#Yy:ʋ8?Mx)j>~"@I'֠uڧ >(";_`-PZNXM53zp(@GoўTwYE˭|IZa[FyL;L{jT}iZz;GeC5#6('#à VG1P#e5UQЏ)nlB]QקoAU)oML^o_Riu Z Hm(Nf|dh״hK9 La ںj,x HX Aa,׼s MwE͖م?R bvi(q-6>"8n*B3UxgчF0;]*ilIe;$pnZY2ۂKCa<`r֐PqlߊV|UϨr` gH4*z{ՙo02'V (鎺^$m*ٷb;=AP+ 'Lv|U>y! ]b( 8yҔOd& QzڲL {cnw:J/U V Bv@8l=ɥ |JCy!\L(E#zڼE0׏qC^tYN̲.lQg|0rtȟY$mä#T 5r$1~tV?dڟ Z/۲ջ?qu4nN~}ҡnÔ۾ 4L]z×@" k_!{UNp;8d)753"#HSZ $2k1N?Z/D3ErדϋR>-PWڊJu/+ϪAohXѲ"9^g"א T/^v/emtd.>}U p9>`(M_]hlR:ѡ/. }pUo<6튘8';M'=yGROaNEJQW3Pް렿`tAdo<P9 }O$|Ơ|6%nZ=%#[v nA b&;{fgFm$"+ԋN &dzlZYm#:tM?6^5(ЗCC֭8īԄV4U5}1Srr dڴ-ն:S{@22Xb rѱ{c)GE'όEJ ӬX<)<,ˤ@W GÍ*~%!lVN+q}zd:mmVhnIKlۦ/V:$2mG 76!T;LBg}뽤Wh(v({Kt8Э.>e}P @,[賲@e;F3 R_7klL͑q!6CZ#XH_& 'H\ZUQݙM8K|$!}(+M0y3Fc?#fR8q}ayMNU0,DةgO)d@E̱[!z]̹&k$0l%„KYip\UXQjbŠKF}Vwx{ ¶WAy3w}um/c@Cuշ]V.\ՠPsLFHv-C?.`,|꼀HYR0I:w_A(,S 6F餳2|e4ጔwyY18 wvWr1Q:zJJ,I|$JΌEѨ fON!oDѶ!PHd(|cljkƪT 6Sʹ]QغAOϓnY/AW[?u[Y-Ԟ?!46^@3Tf-ָboG%Dd;nb!6P0|^u"Z00l@o(7JDdO(y[ Ӡ@oB_V$|3V*cNPv(uBKR̩X7%`!Wc5۹]g-҈?~_J!ֺHx68aj3MOS'; q'q&Rp؎D6 ڋ═oIuLC plfxd>g^BהzmYZ5֌3!DzE}OǤ0֦<" b!g2g=1T_BZy'AŊY*~3 쌽{Z~B["~n+#N$mV¥Dz\Cw|Z{O "'(;@+L6)NcoݹٴUX!tAρ.="hΚ^/yɋ/p}:s] >/j ncv7r ‹%ho 8gj٬OWzQ[ڼb zm)@3hdLO"1L3]N =rf|pF:SG.7 -N~&e{Eir/٭QCxh莗 PU˞8$}mw1iۿU>SX%n*5dD(O׋zfĊ%#"_HW`9j .97J 7Ʉs>Bo=zcN4QA>bJ/̤S hu & ͈oSBC[&6cP@F,ʶȂiusvܠj##y8X|xY1{HxZ/DlbQ}m-s)-m7:;8tgo$M4 8ON^^yvɞu]V!5gʒ'U"fG6u`*zˈCdG￴HFL>еL8;I6 Y2ʍ[3)"|m5DrCnE!*deZ:lG?twuծm(:ގCMZER;O- BnE,HaQOH9#%Ii#;K-|53+iU.-wWY016>K^3[b)-/Cñ}s]I9A:;w"+:' BӅ9A-8&˺BS&(<- n!NFn ]*X*n_@B; u6  J/Zߋp@?O#="?f~^"Vsm tc 4u *gMG5:e8<ōX Uq4-/B7NdYj@^wΞX5Y~]VA9KP:Y~C1a̬ 0>@9e^c(Qb`@/{=E,!"}q{3;lBi%ަk\yE $5`/UV%rf+zyNE\dU`A"ĵ074+f͘}bcCoKNd i07^A]B;[Syj|۶jάN" c$9NР廲.>]>ׂL@_`t6 s,\ڽQ _4w| OX=[z_5i Yו3K' P$ցV`d 3'9vNȞyjd_[i>(:uvӟT%|C -U'/}J@ۂ{$ZHrJ1)LDu{~G JB|_;(`d}3rtq$"@8M"H̅WF;`b5~3vj?lXGrKqnavL!h>C ::>n=*AçʒHz]F=4c;2@뵉_4^6ft6f%=^/u_`-B7YRR9ZFO= '7רXQvK<c9hUHv":8Wxs`(.k?!>FfjT;k&eӄ4RO7Q)C< eyD_/եb #߼Q3& I-Q'ݮu~2r-DZ09dv 邝Rı{WPjY9;9 x"D/LW,w;~7`tenhۿYa{ʫhAEM O/cAM(/ ciSVk ; v[.vac;D[seZ,2M 0sg4ygʩs! NH3_y7h9QO+Pk7a=ӻ,BM  DNXhʎi\g #=Hl9+$4i W_2e6>R2950q'<@v;dY\(ƒ6⏸ Fs/Na.s&&1kvP% v3f Ӭ!Lq b3P&l@mg%?왍d8 NO]oRu 5Z5UHQu#/ ID\>ۋ5v|3ONlFe Sy9(l24F𲴾4Tu%;6YyYc517s;?M\aZq; 2c_ ^FfZ$*;PB h:@6`Z8g0cI;]jd)SeJgz/4ʣ\:[@eԕ0ٷF ᨜"^'KXur*˳S!=Ngx$?{@Df}D c$ن@iQ}W{TeF/l0l&y\&)_@LFhIT:BO+&y,UceQp ([E”,ȸ{oUcH&v 1Vml` 5ǤNee<VngkL0g$'O$˹C d;Wc?9yB85|CKݕsӶM5^wiSws. 6"'2Z$XY lQ0 f+Sj6SX;xYr&s) Ʈl2n"+R`;`_p$Xv6PߋVMa+ a'岺 O˝lص ̔3E/d@R?`0)#e?yF云5ACa; 07 Z2[I+mEoc1[K*sRAC!ETvZbVFSW=4O ?t劅1'#X]yQ$&^ t )T"0~RXjEk+17w)fgvjD6 ܡ&e7ݖGV{֖@_259YdcϪЎwXFqT{8n~j6b!TlAxCCKQ[+ li5mشdĮ`W^fUN}ڸr,sqE{4TOCJqq]kNPoC=,;~;wf#wg֬MԒ0q{iV; h5CŞ{/JoEpM_p";_}Bwٚ5J\V  3/˰c;= *aG/$=o%-|sr] ty]oY"tXJ G: 5K= 0u{Ȗ|&#sjНCdX@4(EHd7㑆dYB^@"M_#.zuF\zQ GYIG[:L /jչuo`Lھ-'rB]p IB qBa3?}GOVʹ.# sꚈZHlLdl._q(n}4j(+hTC[̇T]m뱹'wz5SYFhc_;DGbuH6jh=kdg..ۤ5sbíLQeE@9\tʰ}71@Q1tiiZ-pLոi/[s7q 7ͲD/ >PT@D!ֻ*9-%OWڧTO/Q+dy_;2d4hBVQ4kACvŠu( VeW|Z*7;w ۞7TohY"Ӷje5wD_m+8gVҽ fUUr ]9K&=۩nc12i=Titwu\SP"nv eI/ FYH }2r{g!hwlB:=/ʺqqiAri6Y0{6N.Ug%'Pn<4 iOZTI|=z2FmO&uA֟B[MIKxxB 1ְ PczuMơ*2w{ޅۯ'NVQB/S5$q`5xVgmgC"Ok71$| p0z$EnJ<*! ${,޶)K4RiJx%>b ANC_rd1<8٣|4KMmgZ:ekҧ ۹6UI *&%am' ،g{7nÐ d*[.Hx~mi BV4g VzeO" i ]j3xbw>  ?b?ɏ댳p\ߪYb]ij tE"Q_.xƈyne?m1rd۔xHzt,w%ZAZt(j>-c0sFq4-E! Hlu@,U[S(u dњլfK#O`xEv=!'w  ;y0J J y5yҶґ2k{v mo. 1( N x~? 1=FS +JjE!(ۀ;S/:$k18=\A\Dk`c 9BOy&iM*Ed_ޠ,?Q*P@ĤT*us=r"%g>:= e{Da3 &4pM(? 0g0׹]l {.Rx7ǃ ql.O5+C/!PlcRlvGY FFV9H 5ͨ]aJoU_ZNVwRyG }lѡS/wLá9/i"}gFr~ c367ʁT+\Vz}^ &e? (uwE0\̒ǁ^[F$5ZL 7(p:r_fNeі>i$O'>W 4l*Y Pqx\ X =K}eOM#+IK-H߸E^/f]DhاK `ci0r68 VێIfDg Mм6JJn\c g-][9VJIR+Px2߶n]fOc"ʳYx3[C:TlN@4 uḉ]U& !mzZȊ!7_MI^p>'s[#;7143\y&*ױ']LSw99͊~Na‚7$B<:o+WY @z(B܌-z09 cc|ֳ>8skJ-қF9>[{׊ RsUC pkA5:n-/@J :6D [Ä {n|i GB]z-UzLZFּaSIKZY5ݲ7SzpA8nHw3@<˃ܝ6vjv\w,r涉EWZbviXph/ƚz_1&~['j&=99 f7̦rRVŊ,(1L7MHRPB.~' nSOcl@B? ĕWI8>yUeneQ|-_ g"R;eH_Y(3ԱOڃD02A?r tn P4/#<)b+ W.MPWEλ5`J81d ފ<0|=ґ fEQah/F ;:I+N\Y?iٜIrg[4S<ԣp噡/$PP “xpr3qs7W^ej#֬= Zz/Сqp3NoAY1uqjFRAdQ:ȼW oJj__&H_=پbG=sвt~gAE<&e1.#~}M"BbY|WٝL]q4vpp*D#A)>qrv/%a\cz/qrhずϏhuļGxhe㇍6$ґs%oqJJdӳ酏B0+Pphn|{ki&qf]Zpl@A\=n ?H fhۍgN̾/!ʲ^&P놬j\#AB]\EGr/%Q>>9"}P?@avT|SiOWҭxuSŧnw:<%җ7f?''>σ"KrFj~P5DOEx#ƆK!ǸcWkru><6;h'Z,^Ox Hf:*!uWѪ vM#/EOaT\/ʳ;DaÄW!!&^D_H9 ?}TgRUb~נ4d/]>o7Ae,ǝB+z=]vpLϖ^dE$<9086u"'$ckܬqE5}rN׈Q$N K,+-VIV?RQ4"]yU[eireAXXyK:ɰ8Ω48st=9e.iu5bs(%l^cՇPm3!k1W)S%COQa q-:$昀rCyӐѧ{~W}wOK(^;Bxk^uETo!'t;ٷLb޺"FUneQ5UT_p~w-D;z`ғoM/KK^D''wd{=ss6ueݬ>x= *'d" pYH}fH *ՕYز [* HW7a촠рma{ұ3cV"]Bk?-~o>PG2VOп4LQ@ȄoCkz7#H+%~>&Q9Xv%GEOhM# '3e-y^_-(k@T$)}vw_6{jY Y/&A=ZlPЭCVDCqFm;WFa!Zl3mֳZ6'"`bCnbښ%]´|< p\}1e<;kSmt߶*I,Olu0HX l?D/. vbgLJlܞ'Y"mWoTBNbߗl 6fYN NZm{,ǖ֊0!.U\8B}YrYsr e$YKKLQ|&6\F/=C6U_]*Iv`4J$UtTf/ڨerLS>a8[%n6(h@Tu fLCjBVuFbg@Rs",6տ{%zO 0Lv)7Bb3sE1y.̛ cx0j~`\·7 o³qEK7xpUQi`ݫcxDR sK+"Y,''K4D \5l\'t9WK"T͢\1bt7+ G $6߻S],b-ZR )N,{osf̃a'އ/~ܚC%=JSzB^j9.r94a9]jP7 Y9;_f>В=IohsWQ-49.KW&23Պ3/n-?u7SJHt&7.B3SnԴsC SPFcY958CqXi.'f* {)w,l9ԭkrEGU+EqٮP5CG#M{&z.2x`n@?Ym"!e ܅}wi4k@eYUMJ  5}~Z*V둏TK/35`/y,֣.,>Aa#Y >S&vA~ؿĝ%} (!XS)VHk > g˗ \; BF)~]=v}OfI*E Ln333N (6*ʭ::mjp]vZ'l*ሪ{B*hgl?/=<f{%wV{8reQ\g՘M5%zJ̤Tud8Ze6"&SԿ:w~ak?kDBem=A1zZA5lR!cdHq P܋՜aID=|SzWn}}*]B3ϼ|'Zu52^9ȸB4N~3U +֙t,CNAk±Dڐ3\ 4v,]-ҹDYܶfG4GSpa' 4$UЫ)}_}ݵc@ C2fǢWugTևԀjdxt v̈́5 +кz:{}p` e4{~stN'~CmQ0DqyQ5(;ػ9v%izJUU[i9lӍ52r5*"&15"&Z!nd.\@8S Y؜]GXl"dHy Mxڈ}_)^:c>hHH.9!^(H!߆Y^mMcXիbS&i8|ؖE:I%d܍<p5XX%$oM~طQ12ϧFum1ƵU`9C;-,.w*`!۬MRfD/7v>:ڶ,3ágjCaB/KI {~@kN\]3" V嚧lp̗ui d*&dlǼ*ܘ&q.eqeMD_qL\ 9m|' endqZ6cP~~?uEz]ui;*ZU87OH70`.'JI =ϠLz~u6zbV2svk;|I%50;H 𰜛O֊y{ЍkQ|}p5U*G[MN]ϭro _RLϟYs&Wnh5?$PF;hKݡS(=ů;QAٮu[7ym+BCBl- DPx̥S lLCG`Ab2D' ;8>i DAx𷁃2Cv0n/-"TYur#ca1ۮX,-YO, X޵)u$P.37d%lLWx*A7 %mo4*w U ]mu#sM1;S)R/J8k4d#wZocsdH-=y@|U8h թ ݕ9>P'Lto?WEÃq`yXXtSe1m@2k%V5O%|֨yz_[jup>Oi Hsq# d =L6Ek m!>EQYڶbGoܴS"@N>G$?brY%Q-AVr%d3A%RyF7F`{H>~m˓@HWO&=$7[zSN k{IdQ8bs*aJ;s}LEڥS~L`1?Ezcigͨ~y оn0,J'X lojK:nrSn`Ԍ9Svuɦ8MdV yW"m8)!g_ ,E\Hpf~. WTWB=TVb՜Zi-U7 V;~-Kz$7`?i󀃕|63eQ9Iύ x6폌:0%YLt~)Q]S2)r*vǓn S6NK{Ior0)6A3i0\i`lQm*\s)ߤbYV^#Bcyn1y~i2Xl_)e &|X:3nM-x@03tD%4V!;L0nB0]YL3 DZ^vƑ^=nҨxEe>5܄=P;nCp1fD}l u>yCB1u9L%s5;W! T0@+7 X,bJI>2 y@vlU i@:'|T7Ho\,@Y֪P˄v/T~P܅JrCι\PlʺUc Pc "$&PL*eNXe肍͉ߦ6=`E! [wG=0NR$}(8RBKzbmD[-C<(KUȵ&68x,>6TډpiMofݳsܗv5ơ'u<5/)LߋR!Y0 aR>AU6sf-d9`6oCxec@YQ 2நe%0 z@<[;K* [sEo1f~wW-Nђ:53 3a/8݇l'` rB#)VOe c`^i*8ܨ3O$6*//nLqiiLqӜ5U$݆MCIsxh+i%)EL$9!dTj0a~;>|hFWyirKZq(xFVR)$mS&X!۲X:Nh'ZJroIXdnF*C"ONXAc4%Oc"Oƣ߼U 1qz @_|؎A_Q ꛁ'Iߢ!&s۠bwḺl#l]GY?kzPYH= JSX/8dKWr_Sfꛪ Bw eYAعgOXA smU h32~9U x}ʄFs󭈆3i+5:'B<󂪀0X_ ]SFR19>8zn9Իe "_j%˖X6_qϹKusiL}5W,:L*3p4ܫ]k}}Ă %P*}qһzL-턧rQgh6dj=/ _g2Ġ(iCr|BhW;5nvi欿m/Al^Wj\2 I g~x̚)zͩ=Lk<6A6>@=ԫ 'Hݣ;vl)?aAc #$heP`mZK ȮR<%4#JnO໒",)$YIK&|oAP Lՙ)TxTVR獡$8.sz3&;yPbC/\ 2f%۞opf 髒jJ"%_ƴk4dpyIZ}˄R,\͝z%4םkr7k0tٚ??@*\s1$?;  ۵NnUۄ uЕ:QSێy轵3mZm[d)Q/mzkcMlPA d>!e n!nzWmmˢ`gKqaRH>9VC[BH:Ib敖,ְsԎyXrFg?(FVсF[[%ёZY$E]F<*1ҀIh2Spw6^Xv ݽF(W{lp5@`"]E 'd/%(C S+\+f 8أr Tmԫ\95 |_\2ηSO*.LBIS25ӅMk@6(ɻ'>Rº/l^hbxӛ %T (˲#PZky4"5!C=`>ujcIM]:J>8*7{A[krKv*Z^b UvQzAQ>hG@ZKi5^ MnG\g$5C_dWq׌;S_/a4ާ'S6M4Ȏ|nG9 ^,eO[‘}* C˪8c}ƅϽ TB ]:{^cH3'A )'k ߡf g. ҵ(&G@V1buթ4xe`NÖi'Mf)VjWkz lǪ)O%ؖdwK{b|oA6h;!̓H<*k"#̃;%hWw7Nogo[Dd;FIwy9,uJ]Rs"UCQ^Za^ ib4ATsΪJ@eF^L/`ߙ`c-֨uqrI5BJC*$qњ=9n`*4rK~G+bEK0-3sqѧH>aybП\yX q*,0d-X?U$:f)J7bY:j{2IN֤#`|xd?<O L7#x|IuH>,ƤC9:$"W=0tXoR7iYrC"N`/"Qbv˒Jf/|} YxfU^=o1ɫ]x.fZR%P6K)Λўm dXl6J?>=߇!JkGŹd739YWsdk78k6H敼L=qBv[e|r6դΊdUvfL{b@Dѫ}RStH e6;$cyV"ei1Yr1;H#bΛؤ3Tlfgpm!j:O57wY8ב`vd/:}iBSY+R+vVh(׊ft}WKֿAO )e~D_Xt:NβWA[AJ(?v ( E*֓ko5@Lmj2S&tg}ty6z5[S@S/Eٸ]BK\>GiιHי`Z4;]4 O=[hCoDYBVbϬ, B!.=p)}751D_> V:E'"Fۊ\K3OQ0 >Oq7 97~T,:eOTI&-b2^=24a`,uf)#z۶Jt$ٓ}}2v} sm),9! &aAr j,fs3"V~ya٫L )X,(]ߝ&xk@9kB X{3C #mnٿ1 ;R8+i7(&g,u+3r~i l T wy0r9oYwZHq'OT,q^f?HfG(cN ;/斮;U&-fjMg,4 4)"26WݧgOjp0[G= ADXFF Z)q/iu 晡@NA"F]GP"w0 T~04ueH/7LWû0uӓ>Z!GqR4 .,,=jcۘ9G&ǭy?ފmJ flI$N.cZd]U7y^ظ,X\狷ZSj=v-2rz#>xRAt|=|&hDBV^~w*ɝ8`/}Vmօ&%$M t*Qk|+zХ9^S epK HNz>AwD*,k ;cBKc_&6eդ?#8ct\c?Cv}~# UL1yD6g>҉Vy5ij;T<"H@$1MWuOt)sRQ  ͯdNj"3B ElU3y1ŸD[Yؾ< 4휭NL~C:;LiޥHqo!X+!>|lraO>xF"[e}e"`08)<,ʮj/@؅RFԃ} zhe `XئuWU8I9to#?1U0RH @#]6A~֚k _Ƥx W5e<k d49z+b /π5LR@dӿh a0,e9;5Z:V_*DWnaLU[k.+w1@y>o9(8Sv(\}s8˂CEC"uZ ._^mF^\2RZ[x3o-yY.JPekKphoX\Ǎ' L=}5~xށwa=Ɉ1/W>D@\,w!|M qͧ}Ԙrz&c4%LDuTC, &Sx?87zX Uo /C)]<#072W2>{L%Q|gGIY("6ika8jhV' Ȇ5o(rKeiyɅysP]nSe45S0? [:ב=0`̹Y>^D°n85ߨ"$zz=%RP^*G`ebo J"y9v&{9(CO85s57+}^oh++FqņXɣf5{R'MEuV4"!s;.Y]! ( q!kF_c#ZXDDLȣ*FHFLUٶyX^Yn,zDO x}qy? 27#JW]DxvIA0GdEb :@ 2-(Z"7ɟ } _W=~eD$·ܬ#bſW{k$ꡂު C%[Bw[1L[:En,ݒTG&(rCmV!y#&;*٢ l$ U GN+N:$]r:N kBM&u sJ~a9ۙїCt89E'NMA ܁J9g &TKS=1%PDZ,iu5p)f4Y!~b=\5A;FU2hAbİ\-M_g7L߈'CYh/r?1I۶je,CxiZ,911($J2cU ǧɄ}&fUֆ8dLL%@0CQ410_Q`Ύ"qGXu+(21]!ie{cwrHRb{YeOG_]|*Ė&f%OMWbJ"#L+qjd]XEXҋzzrYK A)KL_TW!t̀LL" 6M6.?gHx1NM+٦BCn?s(—1{~v3]-em2B92E94_A­5{T7Bgl)h{O~/ia 63TVnWQ^ƻKLYW  #lۣ첱kRN~ \*(-œ&QIH#^-{oYp7y~":Ѧ#xyDӌn,`WC"o'=x=0~u&-]aUL璖4 !1;at{r)<!yQ%F%ؚ'Fb$!KF_/2[O~>3cHg_ WFElOEqg!zeG6\ B1pNfN?0҄?$0X2J?BNjU=-P)/Nhu\~d`wVK{ֱQ[򽦫kc )\0k,wG[5ہW$}G 7xXdO@7Sw$VH"T1{̕9 h<t:`2DNTHהgyw_m![Ԁ: g}(Rݑ||BD=UF rB?Du]=`'lO2{nO&a2!vegת 4:1Rw=Y ng7,o,.Ywd)SsO!ԣB d"U{\ݔΏBol+1 9ıKĆI;7^yeWS/6zp"^~BwaDs ߅Lfo T[Ȍᐝ2/Yx xER!ur9YSz\|/{'jl$cC`H4%>( lN׷"eb7>i%\ ,@c;\W%M_BO,G)fJ-pn^G :CfНE=_CmD@X`~)FTG7::A뽎n؄\18]Nž`బOǨ Y*:tY}9,I=(H  'JJ{?V'9sB=s?COI%Pc*u5Y4C~LWX(y.LQVxG%͎VM?܉NB 7VRz<ͅj岱 4v~t9jw:7'^ 0nwu#Q)V" b ~/b3$pF7U p9/e+C/st4:CpyΤZjL0%ac{0W~خQb!CtHkuT` zf<)?#7@j=71)!ޢ08d+>[Ec!/8ܣ Ls>qXv uk骈qaGs3{ ^d\b J{7l~QC}M3,ܼn` d(ȩtC9 #mv AX@ОH&Gd.EuW|pT_߸Ah3&.yS bUljoe0rsA'IgYz[}L3m/SMjk+0ysXِHeզuHp=6P)Jn-q-`UYgAC}l`eì&E,eW񪭰k -mmb!~:-n N[{(q֬ؤ,U,w4_yŬ}qm, o"ikU\7#7pmP!<4C'#RK>4W~=Xwn0ir "D`2`KUxMys%ÍFMJA1LsJ #ܡ6wNļ xkplVtc 䰟QYg^w]լK(~ aH!/9~Zڍa4.?)2I~i*p(g:th\Ȯ;)'2&2ifEaOf[Looe]%\b)Pبaȱ##/ ׳HkSL KJaꪜgKYuꩤؚ=ȓy >x7k~Y3kGN5cRf6UčU ;}b(!&p :p/?No-R՝7T G 01X֤[Ddߒ>p1Yd:IQ7荤9v8ZFk6ƦȄx sQ _;IJ_))jt3+\BHIvluz]7(eޢq}ӄҜD+|4NL,YMJm|:R#"-OzM <4O,lZxO!aWNAsc !!a蕏/Rq~y%;қ Dô/b ^}f'q6&~FRr#~9HOF/(/t퐃pp\Ka?$& EjwL9؞dBr2,~6jN}CuL.F"›6ptFXCA|ž_,;TɃ PXv_/$(ʬ5F>9pԟnyٲpF /G'bLkg>,C^v0xL$M;ەUBT'O?̦|rw/z E*# m^뜗WcǞoaf>!Pw+W[)mw(i5eV݊)MXKu{G _2}a'`%ԠTߟ LwF0==0Z6(?Ha3g ƺUʻQN]kOd|7\7CKY[ߏ-؊HNEoz6>J/Ʋ-;o 'Bdm1\Q.b!jK4=w*'{PRy#.pb*zTg6~g8iw؈ߺ"`@wl"^VAcd9?s uWyFON$rܱ=jyk:zV#*JrP>`sa/Șf+Ep 6-rM`I gec7}_L WHdXU;zuקQx©U`ޖ!1%3= ;]@8_گ$4đBI.p??3)Iv}M #Z\RB9 |I 84QΔuH6 vl{\8=d؞)y/\ӊM&;ZޓSY!-m3kb($IApiwLCjh2VO%&ZFkhnѺO,Q#xzK[Lx*f5?99 ~ah a SN"/'+He)֝kM \R]Zt+_r}w͋NҎaC'ϳ[ڽ:㿌w^ &Gܰ6+Q, * I@נC?@&+*Roa8|:f#,*(!0Ls?iUtE5%-miڋӧ @a8t&#ʜ)wa9k/Z316"AsnЎ14 @E3}Y].+&,ͭ#FyR?? I%xxo]l4B2B0hDPwjP8^ %KF}7'r0o? /fϣem )ٚlPUȯRC!m?P 1o8] 7/l(/ʹF(_uɦ\(Nux4D5ƜS_@=0Z!&}'VP2^Q۔2=1 Fl%i]Yn/iTHOЗ)[Tq|<Ōc& E>0\?)߭Nx.ްqj ? 6̉̐cQ6P0_eW`)`A>Em%?!?"'#(b~4wגOݾ>+POxuEY!*Yxn] qBZ{CH*Y9bۏx?-zR|g4=LTj~鞬U c+v]̵I 4uZZp#tvFʼܝlg ;mbmzȧa۹b,'ď~U1ߗV{GItLqs FWi"st)]ƫ ]UTܐXh2vŵ(6 THBu;elwvOCjv>ՙ}Ƴ.M_<^3˱lV³Ѡ6|({jL/B[{2`%[3f2nzߏD6!D } S^L6ܒ:;ҲKX DBl^'A#CͪkhrfiqLuA(<$) 4iivf_`" &K8h<)_F~$c|P#*]Q쵴_(&d=Fyo(󗅗y7}C[ S֊vZx]Dêe ,9]N靎#!Q!dJ9eH2>*KḶ@};>JcX귢;1jy+Ht yiugebt yIپӜ3m(h)q 1Ӳ2iu%LFA~Yw!}o2U@ɢ(|]=K%"Zef5?!B|[?*WHS5ٜ׳;\kN<|{?hi;cE@X(B:@+xA h 5x=4ʶjźq5O͘k%dAFbt kS0Rn6]&DTc:e ,3Vg/+VkqYDl) UA*+izM(h]l/j&]hHH&sMmiB #T5I\jىU@V!x#C`KKk?YW,Vf2P_6 ]Fh9iɕ9C$H,jCfGG?>crL%crr fO~=t@9G1A'(}we(Ffv /. XL Ӣ8Ü8ƘT/˧6 {(0Q `|&nvV0ńj7r.?,O18̋`T`Ra]v"0GW u8`4i4޵Fb\ {"| Ӌz)"U;"2 iKEVtOw$*6L[(.jKT2ydeN+%7fHLw7,Gn(s\s)݉ ڋV`7w``9T< GCG8s>Pm<-z0u6N:j. !r J/0ti2V=JNw9SS$˓qOЊvnc]7*>h WN]~毉U[kGٵD-8=V3mC*AI*^5n;H)lvPb@ PRTuKR^ҾG^`vVu9& P&b45AH/>iNIRsxC0ǕE+{_rlƯyDvTF&@/rMioO/N ~b.?͡fǧXh<ΛOPr*mlmg`[-C/n5Dd.Xg9kM">n ^!{hmwdԬ4v& CCB68yy$1paZw QJPhf&5<3~N2 =ʁ qU%/ѷu^[kp;k|b"R{D<5]D [\RAjL{8mכ6PGp+۲$%W~X%;}i킺) W~!g41}Ou}nʚ~#ƕ$S/yuKù<4RkܔV89V感9X6 X;<-H#zEC~ܳoPҖ؛B 6"m(JK35$%!Zp Iۯ5Z7͖3%Yv8ork9X3|bT:&MM,`CbLI֮6%s."}7ӶVOW\p`bv ᕚG;.}MLp9U{ ,\v??b1Q6X]/"[XXR}3vt!fr|OT5 W C{E%q3h2ɎFe.gHDfbqi}Vn/?KjŪ|53Ys?5*ЉɏK/UKIO'C:r e NKB倯Rd1@xZxTwhhkم:Ė`z RjLS7!h[c- HuG?\&r i5]Ӱ{7S ABT؜{XTmlz8-'e>{<;ܤ}oAsV8c H163dynMpN;]{HF7D{ JrwT7bg%WMM~3[pԗ>KЯӞwşRoݨ&U['yKMb&!FmL˞ ,WrI|uy^\9.|凜.rYɧ}atiZ<5 ˉ@&\.ܕh=`π=L0gWCs;lIh PsPa72 ?:LJdmƈ&QNMrMiP$Z[K|0E$RX],&'$0 iaΣY"mC ؑWjAlM|P_8/t2n&<1C8E30oYQ-C\L]r4W,x&&?N\ J+%u֫}_0_\ y+΢qMabqj@*xN)Em]JEEj ׿fG9RWh']=x$\SRtjwY#|Ufǹzxzhylv $8 Z>pJ"U.k°jnSH1Q It [1SsuEٶ"b KSfVi+( Og׃$:9Mf\vԻ\!P 0d ddq@ IDZGjx7=j -rd@+^~"*BjzzR?mWT;mK@C{tsg\Ky?)l'aҢ Ad5ȏAYߥTk o/U|z9EG ^f-7~]HB{}I--yRn9du" KFWF~t4?Hr!ӦuGuRxƒ|37=rϲ 6Ֆ4-,92t2`T\[ {zB/l+T?"BpC&*}q-}aDwXsIy qf/X3.]`_3;^^HK!n:hr9x#7MR%!4`HtGگ'&_$FnK5ŧVݯ("U8Çuf[]m4|6ך\!@ͪm CAISA~k|Vƥ<~Fz3 |tƁ m0 AJ}ɳo+~S=CV ?f+*NIs% 1ſ|p$'fSo_bŠJ#RE]aҪߋ:0i9# n[nXq>P{5z~ '/$L=W#0JSGNi }kT/.>fdn bUC.g\د%q$656ghi!%ݑ$bEB2#t0 mHɉ\p1cΟD:"'THH1O^B4mb m,\ , _<^i^qDm9ch5)z|lxbkF?u vs92Rb kVV&7=(X2EKPA \8Mw%]}?B[y~읳BF併(y,ϰb~m66Pi4;4Nvɜ)#09>ҜOF`xJl cr +~һ(HΒp2&%gaRˏ.=ݾ s9{ G̅u]:[ͩo x!LKʡ9bLA ״W%# m%ʣSB.7>ܝAlt?Atn&LUP@vΔ- eO Rl*|s-a:ю!8[ C34t/.6ۆU`LWȘŸ5[vOtrP4!-%O-7'dND$!4}ԟ /Q  KM }J n4_)z -å~:4"or_SZw04b m?$a(]-1\C{(BlxԾP8d.G0Rd+#H±ZWT\U'*D_xG-g}g:K϶>Ε%R,ܞ^qB$ \eٝHmO{^txb];ٓU8,+Ъa߿eלYo/yc-F@#!?_EzTeq )k C]<ʮ\?R!*uo17Uþ[QeH$ՙ,'+L9g9ȴ}ζTA,.Ac`C~'wMv [AcFުe>NP;K!a, X.M=*z`9 ׽CگjI}*@۟|GvܿS s'8Im$8e* gqӺcAfHy/1$q5Dk|z𜢪qjPβmp= tGJUpIZ@o]u [g}jE9@nN\rϬS20vT+a(EwGGaz+X x&S} p^h)N׭$5$T?r15E3ɏu KUN 0Ħ6w3 Eh>EBzr`$UʒFp7x<QAjq9-6$\hdV#wIˮ@sxs# &S\)Wqh2kcƠËjd ܞ+;Ok+: vxCU`9+Z\ }7u%p;PiΊ]#@i)sQ\3` lm4olTIż1/Phw-1T5v{唴bGG2ǫzzu XZrƴf%`EE@cЖb;GCL(+lefwދ*H}S>gؕ()]K*>Q;*/΀@*t@5NƞJPZ6̺{!.\ S+HoZIUbQJL'pSG&,\3q(ivF /ny"E [r7ʪdOi1IC4YIp"[b&6m7@km9 k95yg' H}x~3:!.ړ;*bJ vea%LؤnreG7; na8A9(fґD!swlP:,m8^^DHYO:rs(CB\gF^mް]CUuO `!u`3erDS{QwPrGA9eCvoHn@ GTu{i$f'm,i#l8"X<ޯ]h{T;u@2yVv Fk'y<~ƠbGy<IMXXf/ώC97A]|!  ReǷ=s }HcX?;q%Dc2gWϽ== +$(dgo.nI*;|qoRCG n ;߈y Jd'E鴹B\V~46>g%]{J?n^= f * 3ű k>C r~wd~LWVX3清M2%ZSh4G.:]O08"J J@SbڡPKx`I2.Y+遘?_cYͅU V`Im=` ʃccS-,6dNr0֊[ Q#MKjxR&d B:sja;8D膥 prxް0Y YYﱂf;T>͹o 8JNk6.X=\PϳxWHLl֧+ifC6̈́ҲDČ~%ic&M Y}Tl/lKOÅT>q 9t#lvd; y`n7e s%Wa/.'R_I"bs{<,G)MszPM#,u(&slpU[d"kI k1O]Ғ|ې#7 mQ7]O+ ԣ=?Xax&CG?_N^%O6}$|u W2,]dĵ.~ЫFK C73v1>hR/<+j=7"4_^Q4QmYp`_uជebT ,@Ǟr9qJtwmI%ğqw}&#>ZGcQ)4^>.'l l4̟S0NhQhpid#(Q })ٹ8+ǿwE}-ǿC`Pyi8\܎6Ku1HK~~(|<(؝itG׽?iɜC_Rd PPZhf5SJBЄQ0D~KdP.28-{؄k^7e!";k@-y'HT1kjW͢cv@)FC\𔃏?v+|5֛svok37> қC򴭠zx3'}J$\B3I<,X;1'hfY5X%-ʛ}h+FN=/t54^ZSoxb+bΰ׾}QCq\fkʆEՈ(^6W)x$Y=E8G`DRh$C/ DU'aqnj&.)Lru,:U_)VKaBOUϜ2YEo܊κXE5Pצ5.C>aa Zw gfJQ(放"wS}y0$jD_v<#\ڭӡR鞘z+ypKTu/f?wlj}h5>bN[yyap`]jjV2h(cP!KB*Bc=5vwz)%q<8ЀÀhOZ@n(Fgࢡ/!|5RRו% nyw8!_+;yWRt"̓it?D@2HG,)uE"ZEo{6D0w!7hZ!㞟.Pk'.x’Koso60yo~fx`!l L5Sĩ= zGXssQVZMoDa XZSzsN$챰}TU r)M(.Xp{=ZdS<<+6zl7>z+:y}[e v]eec`U5 ݍ@aѬ %qx:''{ sEޏh3X FhNO-CЌ1A.:1 .gAgy}M;{\4ED=[M1H2ă / 6">h(Rgxd[%݆ExDRіX|jN 7h_%E<+=XjΝ JW ΢x3DCLC Y2 x!>4IU:t! `ܥ.A`Smף@;?dVl5+EX\%e<'& sQ1yjc2 [Ƈ,QR$0n!cZ ;֮Gq=2[G]6$c/ś-+r$x*3;}hlUm8i DAz(sڷtޙM#1KbcmtWEC.ӤC<,@RHNV-b=,3Tdb*TCmsPZ^LY!>ZLB!VH/WI'tGkn}>;v2jBBa&(oiLVѤʃUw{ B.@6b hz hǵU}gxdfnxS*ݧv|,@sZQ3m۹Bk̆S;䁐K|[J*1R @X6ɫYe)7e);GsȖIݿ&jLhbI$H?On,G y7&kl*(@!FEARu֥ކ}eE9͟9\AR#+'Ѓ=nin,.0"9ddC2^-كКbr*g]Pts4+vVƘg)~:E7+lzfOkSRŐ6|*Ȕh6hЖ{ǁ ΉB\'vXhDTooɌS^ %bZIhG*O-]alz?;Bhxv)'aw!:FSK3zDHM}eZx 1啴{ Bw=L͛ t]؛@3~|K7%@r.`Ul3ld UA $cIkꭹH&O_S.X(9NZHeAٽ npM¬rO S3PA.<_.,P#_IWN+"*1_R!J1{\IMd(!JŲBT0u |ؒTpKXAxt0wtGoSE#;B}/xơN}0 qЍ9xLVHw "xYY1DtcvXELnɗ*WZ0_V]+mY:/l@h<90PM/|7SeSVRuνTI沶MXq!@W1e?Z&9dϴ’*5l2)xi ] x{4]g"*q,Ϊ5:lB G<؆QS뉈38 v^mc;8ǺKf^9P8'ĥi;N'uk<(h$Kl$<;f9N, YKjc ")2M6Ŕ3U1-?-"eG&C(at\{,+ Kn961OHtϣ#?_j#k#Ln,{5@wN 鿨 jbzC\9_ưք)qwEbHT85B|cot u9 ZU=:BXlW2I?u?zs9M姴=LW̒U~.>DOZUpg ֨bbO,Pm {i<}ו utpRۄZia@DžrA>-/P'3 F]IQ]׋Web5.\FӲ} 䥎I:JY~Sa5Dͱ,\詩[[4utWY Wt[oW@q Vx]™R-2<0g.m\?f%{l޺x(E2$@v2YYVE$FI;4$?4nf9$>}2__BNO%O8LQHm|jͦN^[㉻PNbI1:!xбGoǚzakHwq=U]''B BDЃ>7XR a4jz@)L>>+fj]?6En]= h.!a悌ֳ:Lo-Z@^ _j8nWZHAbȺC.W\J%#Ldh2^䪾BC2QN1/Jf90vs`_y ]=@{@F[0 RR#_C:,{AdʣY:B, X:tVA#E!/+q&6ƆhIae<1]4 {ĻdqIC( cyrbΘ]u1[1 HgZ8 b9sʟ7IᯑĕKZ J"^IbUN@r #$ƼfsI:Ǥ6k7FpqHDz1UU$]FЍ Zd9K5dv6wSLlD؁V^-]30~ra{LEӃ~ iКm!DN!LCM>:R1- PD3F\ٮTXcZ_Sk T$ cnއzL1MgMNWcH8vsb).wOD&%sN{{Uɯvk pNjL cA>YK7} [=SeDZ;Ѿ){XXhgbm>X^[ւ2}G\ӆ#S9˞v5ڭi=~iB> Zʽ`'s4h}MM7(V'd=oӍ,Vr)w:nJÔ I{i?vZDm;A$iK",PM\p7X:@|}HhNE_{zkZF>~k{o+$<_F|W>ٽs(]` <,.'P,/(AQYfbY?S^dxfy_|Tؿ)^I)=(fƟPbttMZM_օ ٪,*%]:^e5fs-g!lYpdė6 )#Qe#TЕ,x3dŪPt} bugZemܮk@ d;nuiycvp\W('G"sK ɖfw߄@;Mr!c,>$Hc,놖P=I䲄&Ȱ'"7lGA6 ]$u H?zh<ľO:hNh kfV[t"MeD +L\.޻^rQRѻnbƒ9o U™-RRzzFθv岣OEv O5sRE'} |RP[y gFb>nJ.RgrюyTRDђ[:$ḧJǙkO S[#L D#kawLs<,E"_>T5NV&DL0tHZŵJTQ(!GBC #wZOOIBTUٺrb<,o QEGٯ4ƞSa1!5mFTߤt>>ҿ2+,lpudfc: Aخ4ǺYw3&+t &M@f-w)hS45s.K$wv Ѽm)4 m{pw({3c' Smʪ0;>U;RZ&bRm4;T#e`D]6}=Olʀ\ӓeG-cT\9,/Q\]BZ߻ʧ9#@ SM 9~~>2"rY)>eHeؽ ȠՄTRuB&fL^=?2BWdx mMZ-ESjM\!<I؟x̏vߦFC 0kc/'쑭)VZ6[H6ZvT]ILڟpt~Ѡ|r7CAD6,% <(yӓ"tf9VosorXhʈfQf'fJ4nX<1go`d6P&5Ǹt ZWJ7FuFԜ6(xY>7esZnsR]v"o>,L0$?T|švM^q"j&D?YòF9\vBnX z)ٚA̴$RJ tmGZ G9ؗTDh;:FEpe.^I)f{ni;k`m>Ff}!CD,^(VI/Ĉ a֪`<*}(xmrnC72i*!BӞ\_x;5CGtc Ԛv%Q1U*]\9C 0KOL B OБT]uɐ+o5~Kq]:8ea>b\Qq <(xB_}êÕ"jf8wtk0.LB7|D`]<>ZWāQ$̚+)1YaK4]DzV2"IΠ軆lk tԧ j )+eB̌e!̈́g"qFt&9qXR ?E=K0n@Y\bAL<ΩL70)~=o91.DmY:woDAXg9 {n^C鲵AnX$/>tGSYssGR0nq)O?mڙ5PT:; ݴRB!7VlqDP]7Mdy3d?OfoL8@Qr(až]S6g1/QDCd?]dPs+{NV쏍AK<}jhk DtOc1U r#2!p $&l~o`_d8x#}K-!MF28v!*{D~vӲt6:/iЭ`C/ 5Y, ݏR爡xҚ.:r3E"5tXc tLp6V;+MAY䥎lm98XZ!Ɂ}ARCOGCCMc;C cs}lMh)UhcW#:y zyz~I0[+g%9? h AM[+nco >Vw 7:eby{̙Aq78$~6wii DCd'v(CCԄBr! %?WujW;,Gci\V_ߤXG~k@U\:m({Ur H/CZ:=07gXfBX-ve>JYۿS*Lv-tfc_ V"ϼ;=x$/+Y}]`R< K(ebr]Rsgx%e{qŏ%UI@zE5LގMiƭ|EVEt\9 E)1w9T+6#q8Jd@lFtfyk ܛ%F|4 ;`Eg豾1U|,oخ[Tba" k 醔/AF;)hڂl)m{Dۭl)_~$1̱,eU}~R1? ͝m'gsp!'!_HOpkNkД8gՙ[ǭ_[8f! =@[61vrmu~^*ҭl}p=nږ 㛬G_3oV6$ۢb9Sw1{L(=9p~%1mNYOKzD@ކDב])3d&zW⵿nNKn&- U㱅wҪ %`лX2tTKN2W5[a.[i7ml`xVͼd EьY ,f(YW ӂsǫbiU p:mh!=jy#Ǹ{`,ڲE=Otz y+yGLuZTq,56ci5x; dZEzukjpEXY (xRֆ]y>(; iCI__"AsgԢz@cw5a {6dhx* Z}]`D[\e {>J.Gh޵Ni}$-4zΚumo2]ɀ&‘JfQ2jO~˻{8a8ՠw)~gtrpE)HcKeԑ]30>>;l/Vݘ6ϴ-_Zif2+U`Dv3E==W+c-i6GbȬÂwi>1_N:g8$(j\BP)={L͙`7Ht|b1S/nO£LƦnjaͭFoybr9t=;۠ ]j;T)Go!*&!u dj}1)֚1+:$ضP_=9X맠EO5IsMg[S'Tb8`W\XfsVmV[ I,~!↲|Xck9ڃY >Ч3}p d5ߕ1}d&ˌla )"G,hлXvhRGK}q8JIuTlgj/[T rΘ5Ov~$e<}`j)LǶO2ǗO%}1'p FwuWreUq^iulh!Í;[>Za3MZP@#/v' WBpTimqf1 g\tR5i58i)3&3ū+@w}vA1yj"gxzwË`)Qm&'T fzyc8Upd§^0i?_KF5^qt:^Pa 8 k%bzϯSb{?#v-MXI4I-'А!r$ W5}N;BVgv;Xo&WjQ":ùDd:e(* :bHvp?Rz 8V:S1 #7D@ޚe5{~5ъWw /]`>1]+%Z@hF}ǝ EOxf\uΨPSꅼw]4d<|Q(@{iĐB;݂"8m@[NAP)QqT-nWKbXH(=R}QpZOti>p5-:Lt'Gp Z>kcɣRTz}O,1؅"ʼ7h3q4A}I/8w7Ti)˯gR 2Zǎb*=s%zż^辰53vҵF}$Y=5>(%WNbL6Ľ-8Gop#;TڳF7V#sӳg5.ӐL"B \/㩕4⣯9eRp񚧝>EN8ƪjC3 kITKUI[^8_}=@qlAR*#=Ԓ;X}zDγ {uKLH/83Em8A H`$lǽfb s`rۍUq.^0 ƫ \C.R:zC/p2rS\ܟ(fMmI]Ծň6zJ( }&#aFez'~@7I{xR7z.i02|AgڠzN$Zsvs-(-ZR_9to x3rؠ u󽦰{lb0FcV\9-2e3\x}<`(tIZ05$ ]̛j0iM5%ME_3x6lUJeXRIو? /<=#yF[HzPCfgyf<Q>zZjTAt 6QPHPY^yY@"?DoR'yxq5qؙEi I0P${oF.&&ڥx$ !TcY!$%o v<8C{ċ0\n'ghX`kry/m15G6Sۨtr"m;y{C}cG!t^b0lHXKKv T_5/MWŭ>pSm7US0|]/|- lu[e[VdbkG%8>Z43ײH_,NΊgK¯$m-չrieP5fb8{暊 CƺXxmp}h~Σޯ$w'\U12(gO7YCOdaُP[ڃtll6qf̓;!r=Ӯu' Y.f8B $Q?+K0hsFnxʹ̆3&p,xF0]Ds&y%jru7»̂\X }^9Lr/4,hހ@$R ]4]0*. _+Θs8=Д0懙g v@12KB]xOW!NJC򄄬al22ñ ׎whqż&8Lf8"<ܕj} C-?J|J,l_*ʑ:7'>nw)kgRBQāj+fr!|z uPk+v>A-hBy,k<xaίٽ*k\}luBQT#uMT:>nELA9fߏUW~3Bee`ˀω.?Vb(Z/s}bw_Ba,] #[@?C|Y_@Tƍ0زr s OKNYgi'hn_uխnx$T5o.Q[KEEpCG.^Q)d?8KUma8c6k=̯W},\! ' /3bO€0J..78Q>i[tzr7vVPe2ujQH=d+;:G@j Y mS珁)%:GqR'PG).1n{aj-/k1&%k(ke g/`b/"Y=@rUR;u%Fxm?#gk4 )ԉ:f0@'3֚4ޓm#\`pUK 21EvAY:ciݮCWz$|7ka@DYV4œ6WKU4/q=X>).>FWJ|vdAvV*_'ȔYXCVP_:CJ7 ˄z ݷG׌Q_K$y^ƵX}6\5|oL1 IX=_KMdIN?1C Z,ln0he5ZnQY= +M#6T`8/䇷/sV^J<8Qʄ𫹬^Dj֜VjWV`gs/z[PzJF8 3 సkm.Ơ,|A9cs}gxRomLaըC=OIQ<&h)hKl )Y;ҴѮkIvQ5{9-HY-d!7MMgi(`ߟ\2kX'BGΧ6'I.MwX*ᖎ-!d\yHC4 /TEsUM?7(YLp"RmktD1sPb7`\}ȕxůȝJ1,Cߖ#r. T!W'MBHG)qXj_3hj|6Nzk\yO.s4b瀡sd] g"lH3$;DbvV'׭;=kt2L(ۜ71Xuv^IAU:d_4NnخKZ~ť9;զ Pͷm3V~Y Q8pE G4Dn"WqZ Վ @.kW+2*rN-:ݎ??u@u3Ώ 4oDzllz|\AؗU(^}>G^.8.?Vg5=--ڝ|3a*  ({,@ZFPjlD=CjTrU#p;%8Q YϗcJe}D@Sq#YX|C qkU!PE>D@zH{Y!@x(sӽ ]82%҈HNJ8$̓pṄO.Zq_2aewG~08r 5-OmJ&ԢfthE,JJJ|{ Xwm@g? b:lѤwPªCD?uJv@vm3DlaĉO"DWN&3S|W%>uK$/>z'=|F$WnYC"~es 2_ t5$F8̕z5xPF[g E1;n͊ yx `0&k}S|'w=G3F)BSt /St >ǖ"%QcD*xIWdJ m4bRy8*-ȭIïtVVfw ^m6فDSBk=ﰙ>aњ z-?J54igZ)P*'2ZߜT{5,]l?)g1d`؏tS)cΌ!(gf {_pa="|& R+թ(߂pƍ41bwPH4%mYjp6 S5j> $naۡxf2 &&B[7{A6Q*<57Sۇ!z 2#>t\;>Rh<#%TddLHtx_i4}"bRNQM씁pTѾJe3.R`n<5omۏgxv]0:nD_4/D<\j'~UaRwЛ+`Aŧ; XT+f@HeځN6)X%Mk~.ׁ帪$Omt 1V'}=% w~ݗ$kT:\b w_:tRW߶hDObJ@h]wџw-iWXZq'"BmM XhakU#sEWgN͊yR-p"(FHq? )nxۺB*3Ƒ|^\oh#S)/$t py74,Y>~ti*~qp^{n<~N,_Δ# Х2+\ꌒuHhRir9>ʳf92*f.̿p,"Ʋ] ѽDaN-2訃;>x" AI0zޥZEB5got{IU.u8!R\H9 g~rhhY݈T yUai=/PEciW @OPȹd@٘Avډv3Eawd@:\3pċ=?amvM)KjM/YbƽPV}"֐!\AW3"TeL^_|>X$'D e؄O]j閯=ObGk鴦! o3ʠqANTvvOP6 X-MJSpF|NH :* {9mh5CCAƞP |{kf,JaDZڭf 广;"P7; <.'c}~fځ!r_u\ ,ё5m/5g9䇠`(\$V2`;%Na_W̜!cn?,E4Þ+dy X ~$&j&@ JyXsTQV~>&>´Sx7f|ߥIGe…!T O?^j; ^F{_95ubN<g#*\CTꞡ/`X~f4/ib? ^Ϝ| &5%QfU,+zAM.*m*k3Gi/][K#Eǁ/ģx8v^_Kcf [(Cz dHԝa@,*k[ǜvuB-R߾@¡[AGBr3"ͻ ^R.!2ڴO|N `Q/7YHcV|l< F@,˶oQyDhPl{0 K֐~1 r 9L"edO9vM}+W~kڴ=6-{U!T:+~#T0iu1.c.xg0"zOn!LF`SH',1c}9cq ;%Bk3ă(hnorxy9n* Z1؟Nx ?&< '4T$37lx¬?aMJ=/ogZo+^WB4Qw4{K 3 cUoXWi1j>I/[c#`qn16dZ sK̭Lc(L}uF7a/z(vr# Oo"n\lܟy,qܘ,Y^'Fr@סٓIpרk| _E92=oq}3|GA`&g)b/ԱW;sfZk.I'@/ 틩h|ÂU6{^bG{$]q?&6o 3`8>gź!r? "!8kq &ʫ A^da(1'%jC1l?m MvZDah΄6N,dˠXoumf2%`uHԙ<Ou#}UeݸBBe?ĿrhHfBgA,S;s 7=G'CjD%zԜ[_ox4GF* R?HrJaПt! 6()'0X ʼn7JvB_!0 fz< Ś2=_om -$l}-,>uϛx'Rk!Awp}.c%(7bNBa .Hfs6RF uH }?Q`lQ?GkrIcZ I_iweց qÂM%Ncx[dSº ιx  uҡrM'єYj Y/+Eм0ie569&S$ %HX) guwؖ1B[¥އN4;?kmehpMfXPu|t'nXCAٖ>x]Oo'APt %s 7s d |Қ6"L%D_P#f^JxödڐCi xo^BHC.J%.EuqN-vq8߲h3GJs5Tnf8u/EdX,Oj3lL[+Hj´|e>'dx@n:fJf"(SPNA|9'Bң?g?$-aÁ VXPwYH뷦GDGFuF#d>M0C}vb{\ۉ|,VVй iUSnf%BwGCE xxqދ}F0Bi<]ͅL'.c Ef,GiCCɺ# ٭7} P?<4m9&aFq }{lMe@oU/Fv@:fc:#ml`v~q*W,K&f#oTRS .H-mڤkɁ\rzfh:zr'21)vqyXv}S:'U˄B? dT?v;;M:M8%a/(-vMf*h?M[]cE ,6@:VΑ)3 &g]1xj#➛߳=lu~k،g}ȯt|յnf#:X>נgPIj;JD!4>4]5C}ֈ/ p3V\epSGE}΅0jRtå;qvnse#u*4$6wBu!G1}Kt7炱A;p|2Y7kk"XkHV9u+2ۑ7Pζ6vK]y nJ՜_d-NCuf< mMRR_,`KӬLBז9MY_t XSsY`a'@s8:V߅O#0]]Ft Y^f[Q#߂0q9hNiؒ3m'V  N)ͶESBVHѐe>s8i0=xao&zUM/&hh,M{z.cXHe 78$i}^Ѹ-tG~wm(86>V,2!O^[hBIAW:tq2g $eL2%@z΀䟔rB .?Tܽ{~Rm[굻6n~>.TG?OJfZ.sҮGDaQ)JVt`™@ǩiQQp`;/ws ׂ!v=q~"'D,}Z@5G3k$Yt Z ej;A䫔̽Q6oC<{lǭXhhY4>\K.4{zR `>-jHYjrh5,Ž1ܹaq;кrgKa./4ѯLtETk0a|">Syxd:_'/:fv:">@P:r'w?jdTwD5hqѰe 8'N4oVE 4'Ћv=.UAU/.oa6gWzځK$ra%::J5l4+\J l˖Cv(s2;&-'eDaXyb 0SÒ6٥C;1 ,. ]L >rOGU[eץoO{+Ǐ}b+*6:P [cBG{62hlVU>>uA7w޲n? DYl6`OVm\;M2XP"-y֤j;Ԗ>>?*9BYdYF?B7莅 cAqH4v?' 2WҢ;O*"ȭ)E]2oOrvjԂ}ւZgagϏDץ(S@]@;D,[Siyj_¾mAJZ/~ a EnUqQ/W} TI#{]5nAUٟo<o67"ŌAM7kӣ3JNnX+Y*s6H0HFu߇jL` Vj + ; 1~MJw ƛ?CEp}&V0ԙMm?isx =B˧ 7-u~8t(Xy0v&~v%klsobLe>W8J#o<χ]rtrw#9=:EW_‰dKW5# F^ͥ =ꎁs+ }T,v(e%hl湗+[ts &N,3vLO^~+#3~jţ_tDVdA& h'L|켽=:y{H:n'=ȍ)ւ59ހĈqUC6te>e=TKP%$|2av#z>6c=b:ՔLWgOBn痆 pW7ql4l%#㸷ՠG?@2řSRSeAa,/8Fe5Gzu#-(,CGգVn^NNbjw v1Oj5]wHIJĵ\TQо[''fr $!>kє |{μP{ڕ!,-; Cd'5MԂ?+N#\sOaI};Q܉ =*]̥m-@`ݫO变g%؃BwݾGm::צQ>\,~Nj1u١=e (െ YCcӌ>r43 ! EՐvH1gi}e=8 !>2vSMWC令)}y>QKDUfPv!Q@r=5Hw:~+*ra::kG%¢m~4$dKݵ>ӓ8p į6"ҸbE[s]괍`nD/U@_\FW_E]2̑z>QKN>.">FO oǚ`},ٰ#&[ќ\îqqxDWHQ@$J%t8S)ziJmu5 ^RۡG鄞3$ٟS?UjVH3ЖK^ &GuHI ]'uc'aFM@۔ O2S[%:*۸Q4&TQ29Hbr*=\6҃W(] ]0%f AsORjÈ^GW~E+XKCb@@I8]?<Ԩ.N42#$_ДjmH#ry8wp6ڣ~K~3`˄Agi}ܭ)\.|$ŚHӳg1R0|3URGxYNU ('07@5+td"٥ϫI'rzX vv*KW6tnb3_6ey{Df"f9jȤema^/H 7laYj@0nNkj=%'[dٮ"wAZۓSh--H9Jp"l^:ԙN!X_[1+dS 1T9Q%V$n ӇB=^Y~"8|t kp*K֏2/u,dW˹{zWkp~2?4Ⱦ_?RjǻlH;]5w::XQQRhyVuJ/9yM˩|K[N! e,W(ȣ 'u+\OOCzQ)2Ts&CUJ~+7}pwTW;٘(鷦#395S5vKY|:%sQO^|4#so #gL/f өfm |KPT bN_G#A)4ч}#%1/H%NQX9.b}VY%2bOO@5_` 7,;+'klϋFlex`z=4C($nMwI (H x4jKkLjY_2;Z ۻrk{dB6SKY5z;tNmn4s-OT2/1:M']c7hR2:A?0I3~egx@`-Ԏ.[V*c&yȕzj@7 r3/żH? k5n/UK]Uߐ#@88i&`sj,7t]v qLBSM=bͷbFҊNi8`g}cvq8J[oFz4Q$HYȁF o@D8R*\׈P<,:D%e ZΫ0q«'֮DDӒLBʤG Vu]JnvΟ 62W㛢{ܞpҡ^EK(>)73xIRDGmHpUlliwolՉ[ :Gގ/t[J́h *\JS ;:Y"%纉#1-aխV# Zb~1JV912VzR4暕LDq>QW;c(ɍ*K& Ӓ$KĭCCmMT_]>6wOD䩭Wʪ1Y1TO40| t*o ËͧzD60^`|&/}*21)2V&\*h+ XsvMHP +!ٔﶿ;wj ~,: W<Cp@6%fMZ!X;oɊΎnu?PuVnrmxEDlt]q}W7FL f.oS Jyp>789yt9/t5ڷ*o˅Ȃ[D/N"&V1cgAS7;BW/0w䋀 ຕdB `MXM;@_w=57L ^"$U!M!̰2k-I(aKT iڔHVBr3+vsCw~rds|MϻFF4?@*jn~QD =$LעX/4WUx0ʚ\ /(d"k@sx n\GΓrK3Ȗ>~ `+Nd/ ΟMFW:Au 툲aw /! FhW(#W|Ϝ:"P|g=+[m PlQܙ,<-\{xƜi/iIJa|jIb S傾J=?L`"mugTm {DQ޲G=}M2lKvɊi>6גϖlΕ[T~]gS:LEU8ʻt tCd@I#UZ|~';iNL,HžtM0g QL'&q)0ӭljGvfv6 "?QvB#E!ީt{ZGmؖ k.uV-*q't艿?.UJ|.qU3`"zUtYs72M]i_x-E UŜ7- 7w0ai3w`~hwu5j AU5('o]dӐ,$-\nv7]ߞM#iiR"آıiP9lD-PvTBy`X]OHVyj*&. n@x=M$AI5?k?Dg=n?" ~ xcV`r Gp%67^ڿ@zGyDiCrOT]#t) OȳM4R!wbWHJ%^5(Yu-f9I:+šGK.{ΎC(9`?T'$r/p ar-:lu V@iީ@f1[#i@D6ɻ#evu'$q9M[sY$r}WDVb>?`y=ÁxQڞk5Jដ%qr=X6B~ W/i+BC*ה%9lJ6>^O5aw}R0 EmPLV!(DeZKW ̣P^rdagdhCcg7=x7[r{tTr9{Vr12UJ*wAP4$Ũ~5"_b]AQre h\RY*^x+kV&31kr@s\$A$>Qj簬WM a3 a,QLM) 5pTV iS\95N1FMff_޼\JK6cwad"<*/Px!"a9wOL\[F ]㮬ϯ,2$8ʆwI,P=FD8o:$9&ŴJ.l&tj5\~m>P"9s9v*ɵrzژ,3,mT`woh*EadZDRT!^:'yk)H\dRFE5e:!]^L!yjV=0hK(q?Kwi!F׶A-ws)uN6U1Bb WRN/\~ /2O"68$,"d3w̋m6HbQY!`*O6C)48\&_eTCީx|T.^roz"겊`zˋytM9fXr/%7=O)L E,dpp~e>U,jؖ&xa rOF漡 n4&Z$`>6MMlv_KxNK=+KOK$ .% [$GgW`k'{N:,X B)ُP`$%#*HAgkl{8iW%7@_>cQXp1m锳PUkLhΣ8*])9--ćҤA?X v{`^;Քw8KXQKp0Y9rrv]͉ZyS`)L1= s⟶ HL!hbHreztgȂ3TO|ju>T0)V1;Н@߉R:xP:pݢaH{?H2hrjx.Om.p7)_GRVڍU罵vj)*;┭19̴&P~1cgr}}z?xv e (#_uF3Uԭ(Mf#aV }M[+$z))xJZ#Ia~kܴ'?v-k2*ov ^ hS 0:i`h@Ov=ay^7-'CEcʩL$49[W%0‘._w!r7+v3x (n^X_IOu|}vP 71ǤL9#-Pg؍nMRU$mL*A.&2z_=P+v ĻYi!6?Ҿ-˃o2(tqڛ^D}KdᲾ,[xM M8!x=1<0LՃ7!ͣmf wHpNoP3qYt: BJLF9F4b0gf)J|& z ݴD2,X- e0 pK{(Tz. }{ -AWZ֝D"H{gL!d56Q~w^9%N,=X&hÊäYj~blSB46ƯuK/ސǒîFtnDuOsqlDb0H.$g`o(uƞ-C'cy"a`+tHȍ||&8ںwlOc^.Π&BNccS㝵9Fr9Rb;gU  kU 4UzV`R׊BcfYRx- `a6xm8OXUvxyLVLRc@%ΜlqxwbS/|>!Ȯ<{5,Kblg-ܧ̄fC`lcu=Է_'lRbERm=W%l*Ћ5uFu^X_e ae/ X  BenqJp$+ɚ %!+`U:%ʊ_JH!xο'8U/(|YdiFCz>)AcU1v&l/DIp\uMTw/2G _cYꉩ8p7 -|3ANwgj‹T.ڤ/u9,De(d1VMSBF!j XCWOLpTNK[s9g?^Y6ɫ6Ր))~a㱎62|-&D5d"(<(kVgk7rF}|b|_x,5w(, Sx[VgkMƦ Ƈ3BLaGTr P6%В5UbGN ?~8aݥG:1. vi[4'+b; vGx[7b" K{0pj=<Ҥ O1_xh!$H*LP[ Bx{K,5@|abAH[M$H'˘-ei0|%l}à>ƞ-n|¨X]&M@?T)j{>q8Oc$`!CC,((n 7Θ;W\ж 3y԰˨\6VK69`h3˅^oI}C\<9[\9^%a8w`e֫mӰ?`)'ecL=p֮XV7C[ 7LeE^v_N8ƅjJ#QĝM?һ1VbZ8>)R&WJmtX-\e= ,ש?s9 i3.;"*C`p6힎wϳEJ0^${ ~j 6}W@cOF*Tl6tNWCbF^s6Ș-?Hޔ{R*:xjtgI{ۋ-ܙzOĨ)yL!"wfGv,iɊM$PYpGGqa@`ZrVK-Z%L\Nuڇ<-$5 e\S' ͗vWr׆-5n` C)++m6-"]Y0ߘ=If qw~p~*Xb`$HKk) :MZgv_yR'&R,tsPR! l@{ Y6Tz@P4|tڢUc@pGpP',*&`쪺ݭґ~*ZNg0yxt:Ed:0p6@V*&8~qɯUYcWN$gN y%UXPMT_[[{X}P$ڈ@NMY.'kNtXZKDb!~m`QhdRϞh" _y[jmc6z^#xu~@TZ6K&$a[}C_ M[lAףc`JKbaA-] EwsܗARKWxwjc!du,;&SD7Wn?=Z ai׽:H佘GjsxhU ` S;9z\ Xi%!-Ti93Hj+v!80Vm+ӫ 6i>?!r:.VhphqL}TT ŭjtPz8}AvW~|IBf}#E25GcNu-èG{J\GP֬!Nˑ> 2"F+oȺk0m/eԅN}t_jj%J7}}!V+aO5[`\JjN~esvzuIC\ 10ux>UrkzF:=SV0y 8:EqaSs>Opw^2I EeW'D#|̴$'V .gGr󬖙 Φ-^,9%v8e-%# C& Hm&֟WL}'xb qF3_ʭ ,y+/ ѱ<VtM+WKy]Bxw ?y8=SmOs1'[x``}R hp+=6*pULZyX.vT,(sc {~% 6`h8*WwKֵWQsAiUy5>Ke `7{fqƛy?fHWw6-1ZI ȭ`,:B BᤞXOSl+gO<4bHYl/Ӟ}V iz\[׏f E |xIK m6U.>#4>H ѱ„`Ϸ2,vJVȡf#?@+ݶeR¿[R, l>=ڿ_9NJlT' SX"_Ѣ1p.8

q]`b5D('f샲+c dh8$Mq.)u=N#& 4D\7J3'>^ք8&FoauL# QVDSq"!|gI01$5 ;S1[,@Ͼ6bvQɑt JB0F"=qVFw{~o#9sW3uJЪ6/Sc?P#x=l]|УNoR'(Jrp"D |l!΍,~k6cT qV|ڲi^;WQժWM*9h[Nw塥a6%Lp#,R΁~/s N?lvR][-Qt`].(9]xDs:t*Z58<*MxM}͐5uNWMR=NR 4#N'7k|?az CXyqzcZ=t ~CpmnҽЧ?c\.ؾ"ZZ/D ͜*)WK,UѺG 8Fʀ}\~Vh@!oU91..6T=]p{qC^Qƈ {ic!zaCx!\l^X8<E=> čzLGR04b-֨ E Q^.Г3ZX4֠E@[XKwC\=S7PΙ1 D/˰Z)d>?j؋sш-roS 63Nş[*'W@b yvPɴ&cPэƽܹnYh~]i6KUs eu#Fj#pX`\S+^p`J%:f;Ê`2,0\z:+$Jjkȕ;-e#l:`<4+mbO9\|h4)d a$Z]sc1crhPgevQGGPQչ5wGQ~F9nC <+0'ƋWj[. NG݉6 .PF#+,/_bwwʼۯNױ/"X~qf {o;ay\#2 Πe : ;Gs:ǁ$H#7DkY={t{OW/~!KLJ 㶴68/Ge[`MNNT(I/΄cV` g3{6CuJ -&(ZZl @V$ޫdUۼphOu֜;@Zҋˉwʙq֞z-=$h料v0>&bg,Id *9NJWcQ^U4۠>;X=;L HfL9M?8~n"wsN▹,!DC `D{< |K,I0 9cs4BwsRz^!axݖKHsC=9laREʨ3'EvBWnP+g҃ԌNSsUY^e;]i~O׆ORǩ9k.њwҿ*^z|4nj G_ɑdm1d̃.le ϷVΌJ*Q>w+sȅ>-P;E:%0>.f5rԟ H.xM/@4Rvۓ/ YӇxK[]In FdSH9haݴ+4 W}ryvb<gznAc2՝K:yo? uWiA9?(Vԟ^}-B /`z'1LE~Ⱥofp|(:"^t'^F G+'u4c](KU@: ?6 Ϊ1рt*r22J0 sse~{;T(}g࠮b7b2C,qu* a\=2y)@_>qS`cܷ#Ȏëi6^'B Tޙ, <Dx u^YL;y YH6z^_w&B[D>:Yk&ݹzbܘL!:%S*>wސ᪮a+b]+]#ErDV:F͝ZGmHM}.l}g`0]P`vS:>I.Q쎽qHJ#+6 Gcfgؾ*հR "h,ku)L?ȗ9z}H_egta j\<x G,a6Т p'tWcNC|(il6g!j|iYRR3._Sa ͔™ Lͯ(- Ⱥ|?kep솧xz<4?YwI ݒʑ5dzvW9_YBpf km솟>1'sXMGkQ"TWXg<0{r`Ub~ z_0=!Ś>GO[%Ďޭ{쎴&r'>I$x[ tW\vQ~9H2U_9I8Tc{r]@sfG_<b(.*u)VeY[v*~CE47 075G 3x?Z)p=`귘10(1J WQgzH}v҈Z|j6ƧɭwmF|W˟(K!4~[NC;b grY·]qo?;k4G%=9͡ Dz>޸u?nCKU [q*Tq ?׫;Yq"|tVjRumq1|Y^Ti5InTFhiʠ&.4X#/ZkJhJ8YXz-KMqy&۟„/م7' u"+n>6KF\=3UURl0 _.`>FS537mb kgP,3n}nGQߙLti >lQBC1D`*[x%C-'ܭ+j ;^wDԓjF,G GYAO#7T6i/y@E$oM\sā0sq6:`Px#&ij*`gg¦^{wGx)o5+\>x93]yT'ܒ=wS89KJM8H>~wO-&RCf4?tCdRvC+B-͆h-+Gqw$Jx!sa)7Jc DI؈!>T cjtaTqԸB/1Cgtka̾]A[L$qU%YƩچ 0^[Tc8aD^Vt:";6R#^c,`AV5 q|aUBrgH͒s@*бs1͢yKvoRXeԊ$; ut&}i_,ĻbP#$8^_Ĩ&o)}d 1z;D8Ga!NQLzA=9zٜHCN(u"_6 -TyR.s{DNM0;QDqic'XlpP Cutc0T hM o3ld5(cRd,ԙğ'lf+#z̼aeeazķvu20Uxh@*q0 WKȡBQ>;QB&_B:kj+)'5)C^#1<(DeTk̯s6rgqECgZhVزŽrK(*aa5eR:t̩c.3>9*`pѲ@Á1_݁(F S"DI8@֬xr6}2\cD[B  +q@! F4[T3s{)҈Ӻ_k'ʜ.fL@~$d\{ Mr O uRrWIpVr5bVy7V@!,2AEq~ TL]VҎM]taƞ+ N_R(6B;?Z͜_kVoD﨨vevvk=M14˵Gb7T˨"@kb\ )hHNpHǏD&HhJy;7W kX1@48­é" U b>:r |*|̽ՙhm7 ot]Sk$we玹8sZAp*NCcفN" ,*7YQvS3ȁEo(ړ|V~IS.@r#MhcBg҈؎s36.*_ ?It$d*~L'[a`߫Il suKkWw+nu(Gv)Xku$)ǒFp6H_R: 9^Z*SH5j#S{qHx ^o1dQZuz^f9f؄jCO+#-E@)|<'*'+7;>gu 9t58PsQQD/=;*V$398}Ϭ5U^eWcgKIӧQ^#4F4K.|fމ,mӘ 0}l$+hI֊3mG2 HjI"$ hX0vt5GW$lY^N;)w#9+ro^J$g{BVEŸ0C1 ʴ6A2q8c^0ugC&~jC}<2mIWKMgPYha8WM7nXZ#Ϣg#\^P!fLi[5³:~ !I LZBHf~F&ze-+mYynP7 ^Rr\.@ygzv; K%1lږ**R[*Ǧm'UTQkv68ZyM UC՚/Y]oQW>xW v&2{{ 5N |}:9PH|x΢8L:ovE,%%^+p?Q%\[ho|@>7C7MסO~\7)O><}[#EZT1+Qs)"D]'ۙdsIf1nV*\~7n>at0NW!d(3riIk-ל@Dmc=5ŦB1X}0CR`4SLQq"QEQKl m% TsM:p"/* =Ixn*8Gj].mJDgFEqm?W6Q"*R[ …4ɗi3 9vѡ>i|<S4A5E;8\Vyo݆q/ek]1 {9Ă?`O5ˬ}>XMlke M ' K2 (W5n|wQZ+&ah)pXX+}C*# )6)ySrʢ@ļ(1C;1I(0ռ\J`ѢM5?a֞׋xqtrj q-A;JAVm=Un<UgRű͞G*6Ԝ-^ILpR(YFMgL?3&bI8R?og]md=h򞛯@ΝuDC#95|+:L+𴤼 >y{3Hj6s-oM$/lRFõ^ 9}OtTf̻Lbś !ԋxL=e詻|yHz0w <فJ[(-sJK& \-P,RϨ"x(GF}c>H$K4l9Oyp*6dc(f0/lD q<a +^ %L*rT R#hl@AtX!Ra s@d?|Gؓ\KQHu~5&Lv[l8RaF@=I=o? /p=W+AԘs!"AA<|cUyꪴP=Χ̼͊X>U"V{٘NԦ>:~UxYjI[[\o Qe5siT) CM\B.݁*5mxr]#<;%i-3Lϱv3q{@贕;TYX`ׅЊA>"^wձK$]#C(紾B9/|CD(>A14roFϼҀ<ڵl<`6O"rieX8gi:P,;s_\] f%a t2KqH1a{eo=moB4 (qLo*r>fonmjz;;;(2 Oh(X>MuթOCu{rqD0CL.:wv]ZdtݕRQwPD_VhM31Z:.CBH'S?yB>)Q>&@7,?$}Nމ] ofF2_d%s"l`/?( ~Rol`YFVl _`oĆm9TGMl.ҋImhT_H&UmD,Ċ$6θh*kEUo7'h#Ls/[y 3v1l eB}Sj8u@2Nsf|2,Τ@o$ ndQqjJH(ٞYا]Abκ_bHʭ.K^]k ,=/z傞PfISgX1a29-م ˷Q`^KMMak)N\롆E~+'7~ׯxڨR$h-jk.I|~yz2鶡_OgRVH ?krkr;p E?#qSFR@W2D҈RY> d"ʿy`"]Y5bu%x)l' 9lX2kszAZ#@K< 郔;HѦ PgL) 1QzomL0;,|s VI?]BmHH$]{5sJI\[;TT6$;%K ity]D?Nu.qQ&Ё')=֟+ >bm^v1?T3/(Ti*}[6lzޮ3l|%}u:bF,x"BO]ȓOAʽfo&F nۢvIcuv1[W@p0b6䡷KC\"z MnhH#C=.*Bk S:ec0Xn{"WHufx4vDS-;%%N~Ag&P-'ݯH8o7]1na<Z$ߖĘ*F~0= C>0=erA#Ze]#l=P? cDFcߚoqG[/0h+2Fߏ=a_PO3TKY_OmtPvA&v'@qi2}f+,Ë//ՁrG,}mMw͞\1sJ!Ez4Fek {G xYaV®o3Tq ෤V@f,oߊK4aD;avH[_p>>$;.,nEE` CU]vf}8c'Otg3yG,i 75 hoP8R!mYPNL;NGhHNf}6oȐЯlLk4WOzGȄb,㳈 ۳tQ?BɈJ[tSJ}\xK5|ʪ+BF_ܟFFq`f| ZԻ}Plg\ ʅDd`mt0=oo7y*{H([`XPK 2 ᒣ`ߏRGr6X(X'q 1}TRp¥ f$;CCh;qGmOF0k8rn N͊.J7Eܴg׊ޠp4#V95m5Dީ?ηI[od ikGĦ s/M8n׈{$gFP`~Rvnٔ.P5-^8ǁ $7OD 8d\4W3I(><>\K);0$K@[\:XN T*b h ˅ Npq;VΊ<740VO*NUsd5 Y_0MLJqbY|gȎΉ$vקحd ϒbN udMcUp% (&I:8 mٱ~o"̮Kx?R96(~|CSk=yee_>uZZZYQf)ˢ~@>* % Ⱦsh{ɵio: Y)ax]m[]g'0+쭣L[ ?708@²<$(5dC ڏiR?té!a~; ¨"iZ9dz=FwYCC[CWf +wu8HVRF?ʴ߇:gyRyiāsMy!pPQ&1H!+rKZ%Bn&G5Q΂@(^i,I@?1/-ڑJIsM0[ޘcCqUH)[KA}7N).>o M;36Ζ}02mP\U D1ģoX_rF"`Iʂ)x܆P,W/Org>Сv]پиmh~ %k;vX;HE5PCtW)2_E NFtV+1ǸNmj~m_#)FȺ[" xJ1&OCVJu Mp4yzlJ¾cK n%Ƭgd}՞þm8o%G^2<2wii&Kmx8`mc3ӨMO#\-\YKRXȈ^C ?m$|35vlj(?M]eP2-Ū@>ʃfC*Uj #q4ESezG/47akx eM"XVݕy0I}vIMo^bysA9rF& iCmsiR]響|"~RބwVyrM -Sy ʾ0ByaQT(6X%D5ga|u)U0f9=ĉ6EgW5/ǧQ3/`=\BduL%fg|=:er; '}X#,w8[^P΁0@_s%_U`IôM>ndb/>^ֳQHV~+省t^qX =KQo|7uvBǵ%$h9zyhjn yQy vP;z IQ1d>bMi9JgI^ i͵?WsU27m-DځKb }C!`;J ؼ,> j9T`1Us~V g5Kh#1ZTiaTNSzW,I}?^ mǀ cpe ɁdCbQ^1HL,]w)z] HYr! ķ>Vm$F"n@rF*:~-V4/Bu^̐zёfxDZ<z3 uG.5[virAi#XGŅcڛpVA@x ֛!FtLy4^]-ήQKAuA'JN:ӚJD1>[q (n%?(ytI$Y{F&(!,"X,Z(WBe'g 8; ٽb\Ɋ^>O8)?i\Ȟ310K|3|4s );j1k(2]sJs^>"ȟ~=)-QZmx7|h8M ϋMrD@Qz10'p, jL5MT`@ \* +  ]V 3٭#@ĥ뫶Ӊl8LR#7@42<ΛRL0 _yr7rLA{r qLBa0s[h0]Ӧ(= uy>gc +﬊I49\a" cpӾńlt8^,tM||7aaqn8ݕW$Qgu3,(8I7<`YSCD bj4}Q#|5Eriu$ j_" {61"2'r_QwN1hKU;j57Z6EgN^Ȳ`R60xm+H̅AN(^@nulHzupHzkWn!K)AC!UW= (m;*iB֟~-fcLZqiVNo4S^{6vQ4K@tB成v*XEBeGk tZ4ʱ3yK$s-6 0Yp*Ks?_%| ^r:oLT9!*(dB(2q/fdH3HJJC=G;Mu,jZ6&̜Qg%{Sbe$K4|):E͚NRmf5ņ"{^Pxqd2$FMU>Ch&bg% Lb=CukRc%{L BV 7E]tW"ƖS1y葅@-sPBXV C-tF1E]D&L&z~&߈U(%NbKV*r;DST `:j@"G:snuE|ۘg' Î!woLQA Nm麰0i*jhˌVYR!wWG [j4} A]F}TȺrL 7Yhc\!g(' dS9; Ä Z@w`lw5 I3+<[ khP.zIVbM٬M00ZyfYLlKwHI f 묦=u0tޠPWUC\eĜW 5`:H;c?-RڀҢx@C+E.:㹲|X89~BߓuUIǨYc6DR| H$U70) %TF#Gћ28bہRND+ ))ՙVlxl2Qu.}8ǓRG)N1$4`Zܩݦߕ5Cx^WHDk>__ ȹ-pl.(<;3!9jGKT$zd~')$+;/$T%&% tOlv+[?"c'i?"qs..If!/Ry.]ϠUniwfs|jj[s,CZ Qqbh6B$=/lkbl+#Bc%Rs4/kL4~2!j8 (^aU/7 2Yu%Xyf~ }C\E3lE̎=k=R,н7sC1sF>Y2+O=9k8WjMKa Qlv9>H poᄂMKHn@3*ej t^d~)mK: `|'󸻑>z̆_2" &jż7kSܗ(_,mw[m7=ݱ|b;H`~y7rK6 &]`ooUl*/f^fc*꼃|ΫZ+712IOhUH?MXtE F:Gha6&<"i^D8_ݖ1Ļ-|A WYH)b"AfO`S51{M?Y#썓uw ySuWT྘Ze܀՚J(]{@ jHҚq,PI`,9ЛkyDja/  Qo"[V43ѺW/ rʘU=z]*]:>3] B|zGA%Wr 8dW#Ems?eŬ܍Shqc)v&ټN,nW 4עn#Dj pp BB_i BSG,^k[(ڢKV!CPrNߜ l{lW-ΰF'2_]z\OJ!07a۱qۤ :XWd!,c19\{/pᅩ>bk/ DϰLW(B"7s8ڱg3+xR6DSHh'* H89n A.-75gΝWz 6V?1Dܒ6x8޽GD@pY7 wUڏcF'WCP?<;g:D##F9n<->֘Qgli"p4&-JV/jˁ!;._ɹCS{ IAZnF 橗 * l4=ד(xLzD Aa|'=,W|ud |{/QAz`bo-%B]?hFDhIn$~t?D \8dW1bÙ4c*HEW[*": v:`oqK_%eASgS~ qHCq1۲)g3#uZև(EDY$һM7(ւWޝJ?{Ie4٧{ :>RdVz}! C]Nf kJ Oq0}UuY׼ (ɀ?0Cn{fխR 0 AT'\[lZu+8 Tk ;ꂜѶ8bQ,us.E g~:J/080X\-$Q#) ԟ䘃{o)>i$U^ ϙ5 ^Ȧ(= ml<#7Ȱ-{n‘ Ҟw1#%3nlAHⴶc5:J-XGZ~ϲBAbFH 'W£v !R.f.Fx,^]5>bDǁGŁ0U5Z}r]r588;F/xW( 'g*E*fxgev5äѳH/zfb+ןx8%>r1 Q{+I&0MT{`WR$g/|azx'3b5|WD|QDB.*<8hc o-gO۶Zdۏpk-ޙȟ^跡A ֹ|(Ӻ>Al/\?`ِ/I|&2e vIl2fϟ 򯞷2&o,,G7{nD/MwoVd`͔4z_e"]O>r:\QR)-KePɥҭDžΨ;IMv1E,XϮ'ep6 O^O; Z}NCM* XHǵ\o8+ xSKnCEM(}>[fߡC0q&c" C`j'_s:EHQAC m[.lџQw2F#12 (V%'A0Bi$;/8#?hZܖ4"3%VHO C,,6 8Q2&N?cxxd 8 alWnoGxi2-eA)6/~r#"R3,0gtL\#B{f5 Vðkmur qG˴w 6&^8$c &N"gVVzFN,:R;ՐKWDq?9gtqG^ PJ[=zsykL:6DֆouAj(XkA2jG3cE;_)/_/$]e!D8Ǽ!51 Yhgbd5]GIX吜OL f^Ou+auq`]Q-#wzWS5_ u=ismf%m`_:ZQX&fț%y9װ!X*d "tO^PçЉFgbױ+UCwV1e=[~F@CNnHzi嬍}e1! !6yN`lEIi+]sǂjrEKOr/Sr u!B :قֵPV2/cIm b"v1QhuˑDetRWgY{;Xu)JϊzJiV`d:!`f" gٌ0^m5$i @`aT;!~Aa.@YMK/ԔpvQ tʾJ~ ی_HCuf'ꧻVES3y革[BGg4WҔq2b RY+- >v)ٱ#2[L`󒺹&E9+~Be/T`jU!@Zl~ " 6j Mq$0y%oAser:v] rN #]wHHE$aE@$25(Qak%xeh-4xжک ‰m3 (sEH83L:MrO 0|'hүSZ~gW[!xcȽ^y[Θq;p麤3{GX`W%9J5B=cjlX 85^]649yG0R#'RhCC~X ^Ȯ=Q0ҺskV^ߵ/"Բ-w51?KF^C^Y2 Ѻ³ ]W%ًCA|H*n@r1xV!s9{_p0bYU8X-t8ϵHStM^_Qα;+m?䃆04/z\ߟT ܡ~pNOMI9@]XZHЅwr'h$I>J6#jm(xQ{Y!A'U^ۯf@ _S/&7ܰś<[so%s=D\l pCۏxsť; LN9CHt 9!{(mW{GpDFa{dy'WyCeXof-KzagQKz÷j,8 ;CH3֦_W?g Av ܍Γ;aVno}/LKXYwV@ @;zdc-RDXVBX=b"Z?dezvc`nTD#d6-||ps3,%dCf\C0vB!VyxpA =BP  ]qt>pl܎+37Gν#z cC$z2 Cd}ҟ/.֋U5,}{2|>SiZ}9~ƙ]9֘Z>B+H lcT4Bڗinqd{:OFwtɆΣOLp@*4nd JA'Nsy?JYy}ΰ]+4=c]\1댹 [c,ץ `2B:,O9Pĉ.^Wb( 0ma @ց)#v7hMi7}1͔S\) 9\'fjcmJ>΢X.>r+~3,v22t|PR9pr'f{ |m{yիʄ@,9T 'sv|<;$ ߰$ &ݲ?eDzaQZةH(@=C NҰK4Հ^ǩجؾ+ʊ_yJU-dW+z 69T/\oH?NHe(;My-kbI ϟŬaJ C拱'dra6Vd–;Y E/R˓~> nZ/3oyMR4}bgWӘ.CW5eT9۫fv 97Pu^ %@xsf/ f.ׇ?R*7CHt Jzd̖v=Udl!Og ϕ<\ H\if~  0k,>JnCoN,&3{ [- R&ުEIˑ7 =Ϭ1uD1!IeNXNǁUveAD #4'ϩLpu&Z[]8qTשi)+OkTem8vF~{O%>7D?Ĥֶ6]Z~fw5lc{+%|1HEVߤ,:O6j#JɆy> {oSJVI,si.'=\ںXTCٻ=U5n17 Qj l+(b8Є玛5&[5Fv?G RiN oU{Loũ -C3]&_/ >p!w]>/<!ai,33=^JXCO'm~;iZ2'iMG^ ߰y͐)@ h|R.5i̴Oe1:Q_ɀخox6a`_f4L%)>oP8q9#r&m$Zkb^i,]Y?+upR>^~RfQA,U2F,eI'y]m[?g#Uo;h7_%[~0 YS.r lAwoXl$?bڮըbh"F ?t]˘N}{9#Geqϔ6bɲ.Msɺ@w6ᙹ^oqN{X>'r21Լ~;8fjEPis~vXNZhӱfB]Sx%^8l}pC~5E ȜNPI=`sAi B;Ms=tH? }y1 ~{H+cQI9Sq|;Ps_9Ȧ>5+^Q*_foO@&0`#.TJ `fX+M")PogSaNX l$Lj%-Uܙ6r%7sW0n0ꀞDŽmпFjXl*RDoڄ6M^|30 C%VĽ[aY:}(*m3{& tnፔBiDbt@qjnI"/.ю=s tIETI)ݪ. NiY*6M(=- =4( `o|]QS;:,EtY20v?I1J+½'<;hv06ogxUk2q5x.|D"ao0v#Oo0ЈS$j-,r. Nfrg1gOVcM#(ON,TpQMXk#.EŒN}gb%;)!& l62e%] $5GYD dS:vJ3Ѝ4Ŏ58l@]xm0F7oE{M1<\$"`Y ޗ$p XXn}$ Pu I8"uDҒQ\'"&`*ٟ&"xSvfU}l*c;הQV"f/jbe q>*3f M(ZcA80M"DFQHZ4xu\ %=R:e0F']˟j} 5e̱PJ 1EC r"KxVqݱC.Q=f뱽65Fڮg?lhm 25CZunogI$Y@ ^@NU D=^,:U0k4XQи)-?n ^껵z2~23]?уCD-}-@[0'(\dsw . V姗uhAmy{X(?EGZEwdFUqĊ%Ǐ/,.Y^1ptfwh3s/Ν-u.*&@kqU"6 )#5QbQr+Tb'^~(fHmC᪲R';JVxZa.3 8qctY7 L6}].4qi? /BDX<+ VUO'|4:qZS35)J$Q>L<;.$ \+?_n.1(ZQ5Bwoд9nL)G28yW#Zⶽm }޾M[&*R|!d+~QHtu6E2ͯt1j!Ʈۜ#;꘲ >Uz2v)i'hLӂGxANv 1x}wz \,΀p1E6@,wf{M H0X/Vu˝r~>D=ԱWSh6Z% QUYCBci4z.XBܥ.: cN]Y8agěrDN!ڹ G(6a]oo+OU 1hGgU/rGTj˼B[fB31Ufti ;(O홓R.#yk?ޡݴVʂ}*]qVv[4ky _DbP "FmMjScmb6o'N {:ˍOl_ssQ7e(מ¤%'H(KCyFx2mcX6l]\< G˻E!rR%3 _TAuB}m5:#t qk}lL {#x'ӟd|ā?ģUn 6O&_VG\>(w e]rh''-/$!0̹kb(pӚ!jAsGMx'CrITw#SI`%sFH,ՎJ.q{ui@Un=( _Šqs;јHQ h'p>wo63R=7$:#ό\1 %)EW6<|qRAz "h5)[A_.P־}w͸znV'm_7"++bxMPM6Ţ2e2 '.Pr#?Q|7Vx{iQx"&^5{濪g=MN4 0 (ʭM&6Gc="qɴmG_*< {؅G)S qՓ5a_ӫP!hɋͿPp}2XqhͶgp\}O1\G\$hycf+GWAB~*P^ JwyLٹەV!gv(ޡ1<MZʪZb}^}v@jt\Ge [qek S#" S[jȈ*ꤳD=oЯieQGJT{sdra(^NVo܊:bBnPMoɉ9~}yQEw3L =x* FM%_?4\Glt@i>cbi^0׺0Y>0(ϜJ}#-uA숂dCu#4lM.I n&t{p1'-,qތ& K8J--[ڧ`$A"_dEX"Ҿ,,W'ъwȄkg=ۻwP?4/\v. MQ?!鄱vGYȦo^->POgޫ}:sP}рn ouD<OYNE38z!I>nXH *lbDdknԳx!=Z*E7 ~ ':,垻D @{>`RR>2(7cIlJS~?6[ /zZ= I.Ykԓ/ FgCJ؁`"ohhYQͭX{zުw Ձdǫ ^6U~.:,fр*]A$\SJyK0nJħ|ŀ* n\w@+<o 5'"h2x8Mw]$N];mlH?}\?gʾa&'kmA0Mn'/=Ϛ`Ь; M{>Y'$5cB'0)>@Q2R"參`OjCo[)#!m3M !ﲽjrnlH<ճ  G-BG(Q#u&Gu0&2. tg'˗MFt9 WhI2Ӑ(Z WQ)͑+P%7pPx@ ARڑ.ƏXm<7AK@CPS/@M=-Gz-j`2 ;&=ܠYԿ\ A6TˑSr#e钆(vl鐏LpD|~^|scK><^yX;4Pil8F7˻Rǔ|wF9]J;̈́,j1c׃ЏE 7dGD|b^n[2#Z)6Eea&5uo+@CK"D Nެp2| ߛ x[6؅CO_A^&|{Qu^ 6-C>'A4MSNS?5VZ+b]lh/HF$V*I̸6:KE4cgq,b;i(+JaGcVG̻ev, ]1_(ӔQª, bRO:p6dSn&\¡+,O XcE%r,"TGK{&~Q3r+&xSw鮨j4Wlx>#V=8о&#Sũ)},5#u-X2ȏ@WH< >)}}O5e܈ -6ZC@N( J5v6Yeq}dbw^ Yrҿ`9ܽhVma_0}SaILhtW/<4nsF"R:mr^*C5 16<ۿ[ڟQ,13ԣ?"Z^C?$ի.kt<&wY>re8pLF> /غAJn#tc<*K,'%RHWq~oٌTǐ4 24pV.2AThc\m?l@`&Ԛ!T.u3>kˑMIt)Bܣ# 'ϱtZIw~7ǻΩA8Rⅻf_8O! Ud+q qPUU~sA>3/Jj.C)_dk9h_ZV7J3k1}"'g[ՙsc"ɏ$.@?/]ft?.tf}}W|v!X HZo_4pC谒OCDxad`1ysFsM%Gmnj xdGgg ޝOW)ծ`ntf9쐾cQς%1*rbCHS]xK%C6R'E_!'.Ƚdo@xwH4-{l[(wfP["يҿ\9v0d-(T Ʉa%0law#ͲB./bVN~3Ξ=}f &p:QyN}u̍jSX+)AR ׆8ْ &|>Pjv#OB_ae<){:L]ዪ('$1ц9yM T}ny?pFr4SI?1{S> L7\19"7h9u0Ik^Iӝg/d=Էǎ oM粬SJA>0Kb)(Y댦0 jT3(݉*EY?KU"5|H{K8:F,NCw_ksX5>vՐp~Ya19> ZL:-sHE<GuO*2Oo:)P 7Q!Y58alrJ!=xapF[S1b.]PFxPɕfeG1! 0vßj{tH ËpsDm~ǂQ@QA8_wJfzW2߆ 丅M13ܼ9b+{ܪܙhɢ0IԲtpL!Zmm߰:}+ELe,x2wHCw"r_5!U,< %B%'(Z|/!WE/v0⿗]v*w,cϠ_N8 O>b51yh2'+ebE=cJge+L2wR=09F9>VB#`:V1m%[Y67AIgAsM:d&m2ۛakKg;62q),xHkry{2%F-q $>a(#t,g AO-i]djhz"Zz9_ NK{:a'x.g9+J< )N*:b;sf>|NVnms,W)xq"`!z͒Ȯrh|^1طRWHċ[51NWa A6D=ud[n؆0iiԹ- V&ٹ{HYwԟ\E$,#Vv=CJFMڶme;LHBOҸll,2CC-_@y K P6> '{7(Uw˄9,U({9q,} (*0T/WpC!V ʅ =YTy _wMwo͖J'M.^cY$炗89ߡeH5eѴzVaڝ߫\:%L:֕v !]WX}M&MV7*O y1rۡ@FP}~\L`,Kן8jBzot GuM)_b=r^Nʵ5hp\KӍF 6{&pEN;;Hy~G(s[1}Y3\`Pa+-I&o8$mhNKo_BK]#T MXAjN6H~nA4JZu^mܞrhw06 2.]>^EkoL~GųcQ]+Bt$)l̴ 7.,ܻ۟KF:&S|=w$*=sI{bz<_9sFXqB&g@ C[l'Ps7mʚqww8h.OgOYUT)+ح~#:T7w쒢 brnFt} vߵnB gw# =Ġӽ ]'J.jWU X"&U'sw+EIH~qҦlTatztcwS^1QLte!%ahNE&;")5Mk熈 ⷢzBv%Whԣ"_C}V?qTs Ps;8og3WA;)N+;dAHHW8Ň{[&߫Q^([b{ VxEٕ\р E[x1pxYbKCJ\sɚ@x ILMs>ReN0 6T0FSpK ^X-9n8k;FȜ&?Vݑ7䕊|&$9ӠЫ`PEl5ѹNQFgK|c>N^@Y!@d6~?eYv  2ҩ]Xjh`N\K %ƭ=)i !q2"&do)}qY޸Vִ6q/  5 x+@m^ PҩQ+Y'$WqM(%@?OW,S'ƯUiXRX@羴 /jʤv}Wɷ#T8s KK\v'`A/4Z-cjmJеoKG[v>fctP82ܿSMQ= Eâ~ U?nwQ^ÿTB ҵt锑fđ[&Ռn3 MǡZ׉ihvm+>l I'`ƻa5aC!LZ!ˀ!)Oq=J=o[~PEL<9bMGi%^VK!Z+by =~OI]H1%5;vG}pIpۖ3% &/T ,) 2AJGwW#|Z bOk.U_kqi8.[IQ1BԔզłWE.w͔ȩh6P <P7Q͊p#W;Xt4F?w[\n荁tN`7m5|LsJ*LG K*mƊ3ZRUC뤪vb_$xqp{0?a`t{n$_(*b;"cNtHJ}iqMdt0RY o'nЮ3"E<򝮁Hpp@YI|Eq[v񼋾/*x*s<_NugԂZ3k - 8Ji%Z\2Xepkb%"\;g!)G"ځsLQ2p澻JX˧y&OѠ ؝i,MflՆ5;w7 ϭjr&j/۵XS mGCO'ַYX5 K`!gGfHdQqȴ'/gFǓ^} w C"2 g|x9nY 4T/k-3{u+$8xA:B!|IxCˢh˴5<'u ݭi0"դ#g)3^HrDthsKCjKp/G.r%6!8n겝7eYxFsWmOu^E㕹JX>cb>JsViϫcӕŁo#_")n{Jm}7ea=~t0r7TJ ;*XUqZRS prM'M7I dF6۶ykC]ZY~waA1zdT=Ub%[;fSKuMJֵONMdrySD;B{ÅEUM-bKO( ԀPն_X!yb+kG_u}O.@|Ά|z`L1u81]L%!*7xL>Df7*۠FoĪG5:HboLW/ Q|ޔD>$c..كCn-AO[9 ~,_J0ZѤC祷7-4~J/BϹ8 /d aNO9Z磈}nEmsY滆'FK7Uќ - )Mc6(BEOJ{[_jm]F CRFX#71#2|.e)l쥌^vfT:kp~fՕTAf ïC.ps*sjY]ey_/NĠeyG{F7s))6zڽuk/QB% #+new,QCΙ7tGu@uÈ&$s||KhƳ[o_1)c}B+}W:B7a?QNJc 8{jhK"~Ag#>RKKiu;n_f=< "&.u\h4ބdcU˧|x/(MPD~pZ-L)Sΐ ; yj]ig7^@:&'QA#q%"XSC=@ 7L(5["NX1N24޲Q[i/kBЍSvVS 2ŐKьgѪ}|# 3?6"lY/ݔ%EIy *?\VOUOxie&$e%K:9S(`Ѩ/*a(_TR_d71pxjR3 e_chp8$C$i'ImPb~%0.Q2=S bWF :дXyp5 FTwͻg?e7Yt]w} R> >DeokZ4S‰tj~w/:~H#}͏aHCuے!q&N-0Z w,7g)*9>b {/T."y9}<ʮkgS4vLWc9U7[I%Uf3Y}fTfv{cP^12;[<[}eg+AM/;(7+p}Uka@5vk֣Fxv/$cu;;Y鸤Jz}ɐU5 8vPt,.ʭ&k8!Y|v}ɦsm+gInD?hFpF/v# T~d+ӬظUd  ArP_dXv#|-j U" xC \)b*lpy72@ϚDAM?آM1r</A1g@h1d$BT.g5 AQwzqNI2?u CPB-^(ؓ `?+'kt+m]U,Q9v2" + MY GjN*ѐX+LֿF%%yw41ëJkNDPꅫDB+WYSͳq"õG:8&voW.L OW@դ"\s:&tUVaHWW|M{R,+5(ESkU+tnDN5O?O)\{D ;c.pr׊y.^E;Ѝ!#6ecL{JztpL3PpSͮ'-ltr?MOuڟ(LpO7вW N@~f_UMgwc!f  L@?ʼn9?? ϐ7u~de 6T~=FAN`+|_[,5(Vjܩ?Yc"h6QH=-'шe3|&Uw *PZZefC̆.%^#%G(m$LyƄZ ,Qb\8Cn?Oppx$?Kp ^[h(08˄T~R)j -e<|PD;aiD*Nzct$JJydsU'72-C!0 uN^u)?Ť=M%~w-yhT-łQO q>cD!F0+kJmAϤ8[bAJ<:ɽ Ƶ@nxyJD!X&ROjƀ1}9VfT8~C}7aBf8/[Q O@."d&> )B ejQKb5'O!ʨ2Žq]m0.u.iDRp x8de+XB?$tF Ra4Y#ozL$j PKJ(4i5:J}jNf !.aOvA-KŌQG]K&WY3.b8 vRwP0_lLޮ#XآaOy^us]f TWn|m ~ Un9(X!-=֙)Déέ$1칆,3`]g.,ޜP\샳zkbh>X1ul.rR1*jbԀN+BZi(g:M7~FJb@ ^˜qmd;GY+MuYCCW`J+BDoiM3S|:"IkЊ$y\Y)׵O|ן;y+۔ǩm4?뷲fjud-c]>0|-JNC.Ҳ[¹=. YC|PU}|"/Dݛac&%wIe5/*^"}S~zr=@5B0lpq_EuSb v;;o{QJ өb@+OeR[16^W*jemg%diM8O[ƒc>+}8}$@8,DXCnoO1McHqi#j#)/g\!)ջ Sq&<;##q/$O$bMߊg9( z")H:RU=y4chu'DO(:@`d<2Q,Ii^_3ܹKU`*f7gWKUJ* . Ib$V rʸ 7t*fr%T%qVFe+nu #fV1y瞝_9wD8nDۗ"4kr+eG MձDވvIdBi]d?݄d_C:vnP VOF^n5-Y&j= ]%Kϥ_>=<3Y8 ;(|UfɊq?o!Fw^zlg?&KZz0C Ȓ|xm{C܂rl0/:GAEw$#5"wd36Zf(0{=B<BЃj qu9r*βl5: o|jܠ$[E<+:؊a#j Đf7N+1TL+ FPOz ^Q g {MQq 4rx^\DH(|2C/?bv-ܮy9OѮ`@]L9L55{s?x FTG`Ѡ>oAT"m@w "U;`՚3_À+/jX5]Ǭ#ev13H0qٙcYXq>\ׁ/92 >CBB9_HjO*ty U%o;E6hBX;6BRS8pZ|=0\׵_*dGhT&q L;x2nz$6}[Hp٭6 0;@/dfτ*gwI5>eRs'%Fjq*5okNX`|C|nhlSdۑITQѱ`M! ^-\.)k߃(Qxj_-I3_<}M+C)7igt`2;Nd(EgU2Ftׂ5V,و!B"cr(,IO-$*̭. DO)7L-ߐFqbh3$Ru-XjhY& @=دBQVv]zij]7xz@3l(^htzI$۱@],=Z@g%cnQvӪt&ѮLkgp(*bͭ7wnFՊ>SFGA2?u$;ByL|n3227E" Q*sĨW03}@;H/؇ {lVv@ftzx byjZuͬ(t[?{[2v|"1qr 0Ap=Ew!xyI$u2}\<° 2c3y?kJ5m|t lMz=:jжjp-RO?w#fMa z=DImokÐ%ʀܤÙ,*LMśMm$ IpB!kL"Te GJA0a[hGhĚgȦzy7cwg,nd]$_1$AssJ ئѸ `oRdۥq-n&NXP[E?(d0utm  Dz|WĥĕHÿ ztN7aWy•mDk{?/}hbڱVr%g8i4e(]6bQEtiͶMYxAlRIDQW[7X :9Mq`AA6|ٿA۶XȣSjew͂c 9% oF׿DKp~:՗` ^bwuD W`'$E-6Dm܊#KR1-9*^juY`sE#IsC}YqZL~V04r/Eζߺ(U\[1/>lrtiveRhShAۇ^;p4 6z&Ex 6)F'?OjDgjS9`1+- Mܝ_l@],JLR !2ix&v.uf#6NJH5"[%O|U~ysZF)1 fnמpeXx%$CٕÞm>A[;چ?^YMgVи qHze)59h;՚8 xHv[^f=MBC~~vɀ^+-9ꗈƇDo o5 < z(ި;֧5ײJ)ѱ,Mb)bzll,P*'fi d ?DrŠ{Y%`vYmBϪnkGR$#H}? P):BᰲcX;yq.Diݲ J?=2efԎ:El˶l ~#zޏ(Sa Sʉ|Qf"# ;}#Re"KX=K!0;>lk~z_AJ>=ͼEH$6;lOchkRfK?r?} l7,Ftn!lUeǡDi߈#m>nE]$(hl1)7C>qrG* `upYr\ ^5gsuD@3.uve +z6JPXHm Ӥ%Hw**YOb0À5aP&fNu&R4`pX4wgMï3pZnG9%\{^Ɣ!IBE5|q "gA:>B/Kf%)Nzd*y 16H9AEp^/έwUc7\b{xnK[ ΀CXL(XEtA NZ(28`U(KMOw?#xfX;NZ/vνӿai귋m tmݩ( BN*ߔ:C* LR+ |qooNK z&!1(X .LVWei߶AKK>8u-s0Wz|WˡI+/ϵĪIj'm%B0nfdngzf@:i h{~vV$Lq~p3-CÁ8|,Q>DW,^t>8)3Uu `B9Zl%>ٸ>)Znޱֵ֨1" 삂cX#'Zg$#&K[ɥCe E(}~ lG ,%_ ,+ %< R*c&ӛ[KRKQ*̛ G_95-B-/{ XX)/ G|a[,-Px-@$25QFlEY>lD5έ8v2^ 1Br /lG KGIc}%`WS/NR:UmK 5ex:؜]uKU})VUFuVOW?Ձ#A\AR*GFʑ7=a()*m@ӳL zH9I\f`n_:՛=N* w#mEtP0ᮉ7BW&=΍XJPm9vZyr$>J:XN8uzĆ}dw@"sTǮJ=ymAaj3s[ηB"|6XN< bߤjMClQٸ҄F.;XP0T() 3k1yYX "wQ[`N tw!;YQͤ*AOKGq6I.L5 Cd FA:Ji^L%wGCqɪ%"s, @&TGIHۺ>#eu.&? 609j" 2ЦH-%5x,:g["eݿ4Նf!yC7#+!%PG|4Ѽ0I|})<CEӟo_֝kΆVXDޣ<ʺFT@wד㽻e6mYR8yj܉B!6 :ʫc Kj6FY)<J(%?ֺN'j#xo]4nrD#=[FXmɥk>ͰM6H*ĺJY a#Ho ~ I.#C#|\d2AP51P Y"8.yBL){d:ʧa'jqmɖ.6wtv{@䙄Լm UyΠx$/"3swU*c#;?D]ek5E %㳸zn)75WXh6P1eS{ ]b?Ba\=dFzJ]n|QAi3c缦!D=k;\\|K*m+ Oe^%$an62 6qJr!efolkYCB4Wm)M?cknnpznZI*J-VzMכ:E1RUzc4oUH|.jA'#C tT)ff&pD#I:„U.~[ܺi'A S-J~r(җoU>h! s0ʧ`8Jbo:EM T IW8@ݽ_%R(SmUa?WpONKX}%cD&p  ,pE_Q5]fC0lѱZ_U+o7jID7o4|NNU3V`7 REo`2d,f2NjU MaX b W:]?uNƜewS-@\ﳰ?\8O]/K>TG G?o]0y"MEEc  I)8I.F‰CD~p\kWQzF/j;gkwIRH jYn9ii&b[ileR) ;E*m7QвٍKUZ"{mI_YfT4LSCV pgQr2Ǽ:9 [8ǁ/%̩آ1O:'!B +Bn0ZzJO&r$Od=.CH4맡\,OBp38&/qG>M\YZܬ93xv֤J%;a.E3,~$@ce䑔Bۆ}p-B" ψ EP;#%S: qyBX67Ha5.MP8R;Is$s]99$f #|Anb@rN>ʞI~q9 |4LT\SHr˪N-VT#Xq; ղ|oEBw*GfZdIrCChOQ&9Tn`:we$g@!4X(휯E!?$q"%6kbEoج-)v:&Iv %p5csBxٙ-IsmDԐT:43l#3pgO<^aqټTuc߀` 蜐ozz+{trb[8&,g`S!DyfR&%qmSH f]¹ע*8H0pW.HN.Yvpv!+\e5k=YFG T  [`~@b̼vڞd{Quѽ1u_F+[w쭲a R}nSA:(̏b'?&/]vYVW@eȪW֝Y*=Ս{]_@'̢Ϗm$7T1?L+ͣR,C:ضyS4?QӘTJΌ8mD^QD Ɯn=ա]L@y5]ZyKjfG9g_hb ھIźX4@;Nv-VwtPm$Ƃߛ(=ePO$faN$UXfyEƶGAGR#q7 )C;-_f(}}?:epM$1|7S̨7=3zhו\f{wuHC+ ܉`nHi`ۜ,VBg*ڙ&1L蔢WoDl88GQ 7G`Gǚ&2A(c褏X35A(q@z4;_71Kav&N M+9<}:uoM;$s~N=;Tmye:ʄ{6S{G* I9L,3Wi|P\>I ֱnuƋ'7D@%c{ *Vj\^r ka&vzYIv\.̰ I*aI/gN݊-[ɁqZǴg ] ek%z_ު{): qD z =I U=>,xܔKTtW61!G[(pyr,W?nF,WjhPo649w5aeI8ϛ(BsT2hFt6en&d~8})ZPU\~(VfNzN> "xi}N:[7mzWM[T}MZ$S; IC@|'s>.8 ܄@̳^V~Y۶i,lync1}V]xZ(xhT~=߇ h1v_(w]‚CIPt~!ivchm_[# GCC5[V5,Wa:ZayWN7he })n5>q]pץY> Fh4(qH*ap7LxV^<9+֊`Nɓ 7ƽ^Ebg 6:\=|HO >y|y~ %}9s+ $h pR])NވVڏVAqy\Y$q fd^k3 zgکbMˆ [EGOc/-ƪjmt\ZW%r7p1Ʀ?+~F$*>b! E<|--C"G⭣ ^3F|h#NnGBKpfcKվevoj=oNEskKg}m"}];kM/~~y:N$WrV}򆲜Wsh2#* ` # fMJV(5MYgɩ KuYx't[l. T=e=1;ŕ,7*u#gA?S] Y$aG8np:+RBIl ɓVIm\EYC(Oy-`7q~VFDY|VOf6gTMH]m bT%$,uVpTP~`Y3k* MU!!w4KElD;z tKc Uk{67{ .wЩFbÎ)@?u: `k1}:32|yIL`6W ; 6J\ ϒXE\i,%<iڒXq,9@Ay np\ ILL̿CO>^[6LD]y8Ax=>ZHb`s|C4-sLb/b[q6b^.QUĄƀgSdֺY>Ȕ ]nV2*qn _ȔŸSwm~K\A;z0)pRc]z;#{8U$6Pm61<ja wZrz*Mݖv%>ҳn8X8=mg[/5&xty\,b{p=}ARڎ%jK S_H]p.KzGxzA_|%\;Cxxg$dĪޖ>&G7~/lpҥOmU2X^X8敍QĮ8%ڤ}n7nJv0IM-q܃j!蜏C #as:0R a_SowR9}y) <X:5PwarY9Tg'o$Q)CeH=,f^.gÂX+}@WXb2w-(p*^ Xנ!1R|`xzkh hSJۑPX *f3nWK?2yL'9𽧚ᛗl`A!;=`h_zUJ]862}7mQ5J<=#puP&>5sػնwWng*G1lvy0ȹ#xv˩/ôc{TAuQ-G<1= )9oSJ8 dd5ax%Ԁ!Is:{SlAhxDhRfhQՃ4kfSź'+.L`:湲RŇuO 0hU@/s?C(-"ɂ(q+ĔߝAą20ݥx2t4"k}rv/fpu, 'r{NM%)ϱT bl!f! e;5:am(9KwG7;+e$Ku6X\K=f"EDa8t? \bp*VjJ*ݻJoԢk%cx. eJ<ΦɒռHi6,I/[ )/0~t?fi71 IfbgVu2^dTִ3.Zw2bLdB5z |%^S) A>p,@ʎ߰0]#^)J%h-'(Re8%R~Bue8VEZӎtkݒ\,؁8f>,UEĝh<E Z sy<1f0z1l9p#+Z9.y"*W@ԨQ YWDEųY_FKOVŧm$EfG[JwV+ &iDN|Wx]TZ&&ّ's^kz FۤH]Bb,Xkt|v~"/62{[{a{Pa/E[c-oSR- .81#Uds0?֙Zh/8 m &Vk) ΀+P5=KmP>-_F NKhM˹L#Ӳi*skk͑ՄcNj7,ǜgշh리rO)dޘ Qր[|-= P_F SUfooB}UHVAV4U]E?[ɾgt.(N&k{+j% {Wܜ@41L2bNheb( wz@=hroJetYPcQE<,Kyѱy3|@V?Z['VI>6&d sEtH_-F*<_Y kh[aŸŨ*^^<\5 sZ]H4C/h@OK{hVՀ0pLY.ӰQz̊#]S{؄{x)(!&y}]R?ZX8H?[-뚌~io3'[r8ot7]YPakvM]jU/0´o a ! I 8ݲ$s?~j~{G [r;} 'V[Rq'<[xu:U0 -k2}Q$&˲Z$CObȇjeHZ^>£;0]Dӝ"%FLങ u5a0' ,L?UYnjTӯ(]oP/Hn`(mm-]~juYL3k~|a0۽@I$d /Ō3 HGEcYƛ1"!zN̚$>HMܚSunp祉O A|U͂A괩9]&W:eϏbC5$1,k~=ӄ6BKLew/H̑F?KQvm69eN[4BlPx$zzA# p#3@G8UYzRغ5Fr>igSIb%⟫O.Tڼ;"T 9 FrϑRsR4)[ͮ%8b S7pv8pvCTuh>lZ8:#侐$ VxE|i@=m2BJUrx:z93 :sTD4m^--P0lS0 xJXk{/Icg$&/U ajMvi@u3LZMւ#`K)0NS*5(s^m\]nnjԕ`7Q?L,)nCHB SYcJRƿW2vޅUXe %ߊG )C>^}^og7$b;VC_-@p/s/<$;."䋄7\J\,&1^ܙH^bR?Hi3Uꚋ}ܶ?Fa8< ;.j8s .f ܪ}ui^Z\5V?.&)_em 5XV=lfP(L|BNg6خ8z j02viHF5&]cP*_o4#&⠖jlP>MPEB/vE}: !OzMuV0@Jf)rA0Yiġ,4Lb"hLZJ*UWk F/yҠTs"Q%_+1DNm:gLnydD)6%9DԪIݍ͞@[%m?Tt^'y`x&+ka)NBJ]f=,l<sߙW\v|ufR&z=+& J١Sɀf nY@Jx$-8kEZXu[_߾#!(,'MA[@7@Afé1ʨ=G~͏mHE{s176C%tClTa;KDr.k|c#P_ \d޲O;) d1U\TYPh1DJ>D<`lj>|Ⱦ0xӴKxE5V3tjS[5>?%hS)To,;JjVg&$R4=YCfۏjkU/E.6&qĎD7@k K9q6EJE7=r&d:85ea%.8kE4kBpdz~0;x.L'vmKjOA1FG%Z,~ml>yZG-O^],E4$5V0iQL f ߘXsl`$Vp94KV2$Ne9%_ o n*{HΉKV{τufLDDs,2⚙꾪{4"R^R1?:3OhӤDd!]ӧYRgv<}[mG%| |g(a=yƿuNji`ClH3Lh& ]aٱnyyAM'38'@ q䛍LV,>pI({VBjq^dD߲X 8;M9Z-_䲅b~ 1$abYʂ-x''u/^trV#I+/3;jha,,*^l9R˕5Q_ \1r7|g9eGDr퓖!;(Un*΄&tp6*`m" &/ ][wk~؊nashqxS '+15 U^oyv/VA^?G*) t>+zH2evdM(RzmEAˣ94n5wp=uPPvjQ2~9Q075"0[im;R_EF } )5}͹*B^NCuR2$`uU*:CW$ ͧӱ09lP4IDy&@pElU2s-@*v_fѐԮǼomݟ֐CN-S3sa\Ǻ3!UTF6ib ÌJzrdŽY`V1.ya|i!l|U #U'rKL_Ne`Tv2rYm9'h#K1?>3Jv (i T׮nlrR~+фŰ*U/-9 ,\{1Ȳp?tt VE @*-}g5|܈g:xܠӰ?nm"Vzczݍw{Cr:9)rD͕DVʂu{3N2ԃKŦ,E l|K[ŢfP\>u':R!t0ωjȊI@HV[mV'(#J 07<΢ *7Ji+_Pޏ$R|9myڥ"?|QhFވ5.J͈sFthj 3c@o%˅R [s+.~Pul6&epB5'u0<0bHt}1V.:Fjk`]@^=/} |ᒛpoSGvg*=m `!qo7^2jŠ ',VO 2qDSs6 $ tzsw*/w*͸S{^U|I8o74\c{D6aJ`Diڡ> ٙ%/Ž:97{۫[0Z vu L'MW20x^ifq*Q]٫)KߨC#B#o̧_'nU=t=l{SL ި%6r7gO%[DNP_#|NGlffMItϖ@1mb7|0aur.m)n uIpF@@+5i'qm9NYƝv6e\xksYg[;ALqyp0c/~]?\ 8v?A TܩQcޥjq4@DH+3~nF6HEFKC6VK#8w`"FSAN؊&H qh.?{sNB=E+էX:=J$(]\8im5R'z2z %_C P?-1$iH'Wxv74!#u3{IZ#;p?c_6 ZD"J*!^VRي\h('xK7hf]LcM]5`\s] ][P|+Q'Y~:sЇ'`I^k\U+]MEN< [ˆrk"0"zB1ŤRFߥ%'V&!׍sɅjWsvaN\FpF[5&`$\"-.J-w "}?}ՎJ=EOE>M!֔:/}6:C<A e߰nky"s4ؾ0Q61Sn&u wVW(>\Z oxuV[L.eb촾 dE ~|\zn=kޭoׯWGo0#MZ!CBzѦ3)^7NüY0 z 09o@@68Ďc_^v*_[ gP ڪAI,.s/5Nh]Av& te#=~oR*,yFDPl{ ɧܢA1'ԍS D6, [>չ9pm5D~^t(qrY?2ȕ[IOD(/M9H5GA<J4\,8BqW[vn[+'14KmQ QNYic37xWa%FkK^v{|1s H?NTI؅T٢cfW0cuqe{IиӔm[GK#ʤv/]}7Ԃ_θtFg4 ~mJ˦t6yޞN|}`8# w|ȦabUzIEUDPO_o'zEew !XP>U{FNy [GhpF6vy%F70%R4a8 vj3WXluTnM;b88ntCiu8ZڝDH2<oG8n.CzrklCrdž[Nхw$jx)4Bz*)ܸ T`?,.D-TSD(9՘cFNc 7pKWvK pWTVaO3D_n3Lƀa3-٦ZBr/!tЩB1LhWNDUf!ă iJ̋p4ӡy ETx3;r?( ϖh83"^yNEĤmDHb bxMC1ۂఖʢ~KTMPȰS!/sӤxSTKЇ݅Ćub$Aʬ_1|mc1q Fe5!|K x~>T j|mN.R*zHbîEL r3xLHb!f_An4FE:.(sN\ષM?$`*BKu;j9n6ϒv+{:/zrj")kl/b#E6W%$K 0 g6sPxR/"1+$M K]nwr:L C_jA "zo=ŭ=V~}w\|[6g9>Qs9pA ?fk]$;=fA Q^<ڱ$jCB! ʞ//Fy4%u5rѱ|F^,W|3/loSX81eH1٘]mA5ڟ&,ax# #I`xr5|NP~K[A ^\ z>hr!xn$O^Ld02S\ugO_I'=_wZN8j=uMg|>P͚k5GwJ K ,tiJ i9ob5nZNCOfUGɤ16u6-t c2lNdds n7~?zBпla*:lt0~ՆnB;:_Fk w't ))A[UT럫HxܟrŖ.0UFlG"R ,fhɬ+ _hm5Sl?d /:οdƴ6=rS84>&iʝ{=GmZs9]lf =tb :9GQ&U@ q;Bg%GFCE4:ril^',dґ`ɑByW&5=?;p:)9aJ2ay8䋡P |E.ől5*oG`I*z_Du#c}uq5⃤c$lgh POm}BYaJG2UtdV.Zo{Jt@F(  y[p9e[s`N١C n.ZjSq 薢dt$.(QOx̌.Y鰧 ^%9*qqɮ:z_N, #;>+^mϒf7mY+BD"59󆞎NJ<v^\@GP)Qm bԀ+E5J/@g>Os&"zÖi}lđmɊmg !FTlJIM DD_5z2}%Ȝuquj,2qOiJFuY򉞙@ڍ3p`v4,!Ox+$ﳡfdޖ>"brH:RgٍNT}HTrzx0YsO~YL{DAOM[wkPߜSPW!Dׯ(hH,f}xgP # sW2Ě9Hwzm`bMF)w Lo2 }M. U7sPX )o_GO5]xNM; 5 LṡȪQ=}9!N&+ἋV@*n\{h:,}OS Pѽ?{Tl]k-/C}'Qjκ`:Yщf쌼cJ!?v% 7?Ol )^tѲ%Cݓsoa:Mh S;ܿiTԒvSCEuUki>a3O%W%I;bA29VH0ⅹPe,m<_kC1 >iq~"{`ΗՔ7?euHB0LFG%G{;9@/S{KXMp P/gfz`M KsY©n'INf dpɳ 2)B|D): `Ǵv .jz%fUJ) 9rXk5 hNznv`zNuwB` VC{>ib|c:GZ{b:ʁ13RԋD6?`haX|̈́!Γa%̔0w[>'yҠRytYH6; |®X foK?hV\6ڣo@5Wޛpȏ\KRMEq<ijf.}Ha}qt^cM.%sYi&n;{t'z)MW'$ߤ<4~Cc <[Ib6T$MnlYm+ɐA4|7AI$(q@]LwLŘXDkXA"0 p;bX;l@H=l83SBFI]va'#jm5W2j|Cbqm?k'Ƽmr ]X1B˦ӯ1(HVcYObDayq(^g8Ǭϑ#f@Zd@5v!9FɱAf쒁ުybL|Â׮Wx,,<~юB==(&V%9iN_ ւ:'\װsO0,B˚}Omˎ4 R_]GiqJ5~ncRQvc΀{pk۵i˹cłE~erVGjIm|I|9y0gLgrd0MA\c xm@lKlsK6R: Щ.( cUH@ޝ09b@vN,HT؄zgC|TR]݄ٷҟȊy3&X=@iAϢF *$ÉE{watkq~A㉊ Ǿ<+Lɴ+~1|/~J^qʂIKz6IP$]9!9=`+$(x?FP}?3|a۷VWN$l[aFG*hDQBZBCE@4}=!Lֲ{ !'x#0C& %5jn~ --ReƔ͋ZfÄg2Q0pdw/~MSqf?3IԗRΔ$ ΛCfq{ӹ0qV7Uvuw Lhq̆[ڮzb>[C4!v,-R# @Wއ`+BЙXWۘRUt \bcb37U(pX^06^h}HCD1?įAd lDXxJ5od;UٳX!O%4j +Fv19mGaOf#Ⱦ-QnQvSqt*19xɣ=lc,l/ҒV˞[; iW+X =ֶq{ lpN;R܊ko>fO\yLgPZoO<~ BL|:Dج+L~qm?mDRh>j1䟀kcu[0|o Adu/^@|_05D,H%-jv噿2M"Gv+Xd4ŷ+g -dMF2i1 \-2,BdV1HilKNN:^lh4W\RCYфi*_?5dp$~;ó('6OB.+OQʭ=\W:-N)U3p؋)Wu<_#~HXybwutI5(Nlqq'-ZIwk:UR!|ɜ[ ;osikD4El FAbbireDE)#/c|1qHFA q{$B`o:Bh5Ӈ6` XPƪf.BEg6 +Z=g }Yk@ 61O݀ O3}Bca(dz{!9(rmTEN$(Mg\P;QfHUi${B׼oU~(;XaKDL?-kfAHF3!_ʃ%%0?ݭ{XdwޘDG,2I3+a5csy\}-f-H1z'ssX-rmox2X5Z?wj2 /\a?O9/"A\ .Mg{\)EyEB`Hq?7PQn z0A1[/>= 啄6夬j le@Mt>(* D.VĿx+=hyj 7 (;Ve+VoXM(بP%"ۯX$ؽV/~ׅM-"s~2W4@sG$b~IT2 E\TU.Ƹf8]8mO'_A*/v*xؗG>w^VR065Š uBvH@gviWl4r{q9_8v^#s/@ejIm&¦K]'+)KIĠ7?`ewD)Hz8z{9o7hiE9VkP}!ka$wv}Q:90 f pޕā=İL:g,!sEş,scƾ'?N vO^fĝ!hy:3jYqymYG1R+4cKxim#h[ !O]"ᅠW5lUNОk/J/ʛzjtUzybIfLnӾL>7N.귽 T׿$T,ͣH*D<@J(5A*A6wl BM&2LAk!Ȧ֧giw+8ߪ=x(5 zYqGZl V;2 S%! x.p@ژi^hnU",Ľ*YH#󁣚vHPB>7:Gb߃s)U).P. IRks<#q_鬔SʹUV-o2YP7$ i h7K$!Tv0C6DDf=L5/FewL ]^pT[@lu]U;EWו!h i*"Vn5D:mهJNs1G9SpGP;ţ%RY3"SRWGd@[8 =k߸uHRkg~fvLC /g˜Eؘ|!Y=ٙ/ipX ko;8~?)KFpn{_y$5\ IY<8=V;ǎPX3~"Y@3.3֟ozi^mcNZ-ܪ%vђ`3*hϴ5/3_ Ȃ.ƋuuhXc?!-g#HиX$VHRӅ^i }g[pMFP;Z' E "z3XM*9a8&*^ȞJ_vU@v;=@5_{`bځ Ks' #%F?q gHVMAZ4wS͈@SZ@H~֦JIc9Y-yRVxj1#I'YH*CJšjm23Ǜߑ~"d( U1 )P}r*\XIB?}wNQ٠]f>c7}1K]w*ΙG<=IuExLBNPKvY %;߻Sd.u[@^Y.fvrZiPU{TFYN) v*;XݥŔPC,\^NV^YV֌}>s ::Abs2k}1/ʣ"Kߨը;,5yP&?Ά1%*zr}$H]Tx2?7/U?H&xmS:^9{09]ʀcEicGFag@^'VRAW\ (VmSWVse`4]-[EKۖԺ ġ#y8'J‟gJ@*4Szkv*<~mGP|DWbqGмsͲ2 Z'rxĂJ$$ -fQ ת]=a|L zgh nUGX9X:&HאD##"޸ *M.|^.֭vmL,H!ByP@c>ޔ 5hϨK%Tjw#=W %Tz)}IpǷ֛ic 4X /`T%vskmE@I&huy`\\4c~^$|D+gD2]{~捾Nrtu:7k/煫./߷2sDV.ґ~^8%0hf=oD`a,qޡ1qr4jDȭ. ]5JSꥡ&X\ʇ ~7vE"i&wT7oҠA͒? %a.q: X}#5Ѭ=ae}ax5dR; z 6u7ERLrgt1\ qT|UgV6paӤ5Q u"gyKuiv(| \4 9mҏNiazUQᣌZQF˨Tz~AQ##҈/.mLT'Ym0 ?u²yM!sT,PC1QQ!4hre{J[p0{=GAՋE2)cK1UoeOzZ-jb+}>+Z08t(<s8E@Η] [05X `LREHQ^XPUQEd4NxHjўILօq:K7VGo/xk26%Ḕwo3StO?nee !k0~αE4d/g g Er <+/ . h&g- ( 0;L5p#ʏ>GީJ-dK$~z;҂-̥pm{߉<#k. ld `M lq<1P$zRARLinuTd Ȭ]R{-3zBm:|yd\Xb:Z\Tч.dْ<B('wAΰg4[In!~7M-z4G{'Co\0=ViB*Iƹb!ݺnE4A2OsS}㯟g%yܠY:#-$ 3c-8ʟ(T&<_op0fB f=M$ !M4&?ks*7+ŹHiYSSjϭ~@ԑdq c#[\ok>0r_yȟu7Hbhhp>BG^ȠWb-9`}]wB>S| %\Wlx=jS*Fi ̟<[@J-{?OkI{x#􇔧-7, J8hDBDIx!cǣލC–jES7$[Dž`q$96}T/.}<W*vXDacR-%[EB+|yosd26%YfAbaN *RÇgD;L!9Xs%`۷v/ ?"oᕶdΘ8?E]tAWTr)%3 5_󹀳x- s.&sH r~`8mp1u?&_6izɒ3@RjS^HG `nR[]h dPb lœ8,%umy |r't'EGV@[@.:7hO""0f~haS|W-k9t30?y$sT@ 8볽5l]h(eW%uN'*}lQ֜9dlmk{&$I*Th*ۀf`Tu?cmVnQˊHpze̍7 K%YKF|,K^} |K% {.1+.]8to(ttԈ8k31OVXl8r23o7T(mIlTL)+~%dƤ{0rù2~zR=ű%@tsfI7+myA n=US<ɾ0$c2*n]h@`ex pO^ݓ8=A1B9aDCnA5<_1鈁mO%ٟ0{bT=O0%z`D2vB͚<-@aqh9&!* C˞`2 HqG/Uc `Į 3,k-*Ew@` \csy™Qreůbț:f+DUKGSZ(v~*fꋽVK1{^ j̧rh<{`шeH+5B861!|ѾH_}8ltUzz_NYC2C\EAB2^>i]RTB5&B`3'q4F4*^x wSTܘ"PH mCNmL/'`-# KXf[׳" m@ƇZbp@mtS\ ik>^0ub~`d*m3Z"SquEBHo7)$ "+|7$ݥfU]s11s>< 'Osk ԯUA`ǧ}m"ӃqT˥Jli9 -F$eUH#Bu8ԡ?"?M+,Nbfk/xV4>g!y[k{Qf:.:a)NnΝv|u?퀰f ^>6AOSCtw籙DxFѬOqg?}.BQ " C])f//=žpG3vlu 2* Զ#W;+0F1cW6gx>FqMI( f*:Z`h/_|-#$ۭVPvU:*NpZI9G@s٪}e?*u縱0+ܱz:砇{] CLKJ7Nmce0z^!/P0L/߃ժ/"]דk'wP ^dIH߸ٕk=,W54^TuW2chx嗩k)R\דbG0o]~~I;x?4ʟqHclp"v?dQH}M3-}dgH "OթbxN>WgGܣdTrEa5j{u%zPIߐQK]lO`!IoiE1KCO{&K6bt@UٯCʣ@:m(w`D>Tt&,~إ]hͦO}Dm5TU8-+^UL݃)<6&iTvvQC>՚ ̾Q??&T%CMAG/ln8Tnnk%GDϪ2"X'yhF\.U|RJFb|7O%c|S_KOTik2̣1|#D0 YAr!V|C6=;j߉(8C2s$}ƖcR Z"Vn_$4A.Zc}#z`Yj_8ք'C3ۦB߲`Fl$R%OP%$຦RH\*z+?[簴j!/\]7i->šMu@ܟ&0 gGkw[ Ef%40#މqyHORv{I@o~Q65ؼJgnDYU Z2I׽+_s`\\Rf(R[4o"mZF`v=KX[0[?"fHC*캟@u-3_%%ùq ics 6rWՅP=lsjzlm-k8gW9lHs8콠i4JsyWFqW!oN gfvnZ+|F:2v@bT rH {lK3Y& ۂ:#{n,wCSX5T+6D\0d"`)UXF3_|25HqЉǁ^%ώ53|5mj7O\'( @yr)ht)(O"V> p=5+SEURl&LKzЅh_;#*Zn_NwM"=>l=TO= ue'LdDb;1׳Z2Nd;W+h4EG/zT6ՉR-@XnIBsJ>͓Z#`BZ;(*=`"|N㻭U5EquHwA_A$N/- v8{kH)hy_HKciaͲ$18XQYZ_р\ȶb DxcAǨ@8v_He }iђSjq&OrS\pI,,:h>%836/u7.HtH>4dn8G[c`6s=m=Yow@X[1&eS%Q7A=7G*¶A7p[hVRJƄ-aD]7߅WxB7KaJqDaL_[V蒰g(CeȄk_܌$n 4 ̈́Wfh&jWFǕ lX>ͯ*-J'5Ѱրpפ?QXM6j=PS^`"KrG12@NL-vppb.v .5GJd>a 5N`[88çu]u?J x.l/eyjR#ĦC*R#60+4d-̊lbli?[%3OFX]e9fzq6q 7՞ I   CP *ș##+9ļ%޶p۪S}h^ӣ}Y-'SFZK퐗 i/4W+ͬ<{]Yd"#1K?Xllkʖ>? qPu[fZ?>)}'v2ޛL6-ہ|){S>-7PG9Vśd`")vI A*ퟒإ]e RvW['CnX[|eS;:CfMyô^]gL!/@ġPSOB3e|< mz1 1^C,@׫$]gay:J+M9 PR8Kh8 Z#y K;\-3Y1ui7(lU_4VޜGN"ܾH%o׫0YPOv5 nR3x"v3.@h9ydf6?#H:'X ?p=:BkJ -F\tpTB8^ ]~Q .״ji VD+B\Xp?Z7J pw Ked`mPwż[0@S3w!ocmP$Lٴ&応!P/XK{jF8Ȧ9E$3zȩC$$ ~췍Ȭ: W.;  /ee=)L\ku@D|%ØOjlӌ*?R[aCqicϜ)mCtN>i|7&~Kމ8n1Ki  ԦFϝQ=[O";vn<q>@R#g3E#7}udirD_?twx”pZ+E iv/']A [U3#<<*ɼwPU4pG cU֝[UCw#Quf'Y1 |2ʰLm'wԄAX/g!()B2dF6tQf;ގb>(F1]_^F/ҡ(C;rKo:@wdWNeEf&}+AXٿQ8 #Mp%M6'𩝗+=`'F¢{X$mu&VMM99@2f#M`/vAUtdtd+*Ct]]{ ? xValp%Cz"Y.!E,.k ZYu-O薳^utMZSwOKC3hVڳϷ~rbL  _$3ҷ5ӏmal:hw=2Z|h'ƘF+W]FYoPj'>BX.f{eM3A|CnebC1Fp65E6j1bذsI_+-q"\[^]ܷDuۛlq $ف-:p NbG8c!4<9d`$M]Y\ OTݼQMI3*]̈́b7@S.%,0g=ȓu LlgY~vqRkPGZ&+~c)4o+-gc9xXkY[G6JV,C׷?_Y-$XPPv1WK|Sx>nr=뚛) ,4o;17v'OZT1D3Mi:C.\1ȝش4HL^ Ƿ̊0jJWzW^w0 ZU 5H#Gh ԉ[+u{ޒShzEYٓ4\->;kBPLB 7}5xW-rDO۟v7ykZKhNNȿs,ᐿ&߳@ ̯QZ=$=|kEc-nYc~ԛ :ɊokP+/ ىxQȟ8T;fR y P=`՛[Jb;''.5'o-.-XDGo_ a5-JRѺMec]E;;NQv[6CrxA :-UNU;_cB8 0:1(Y|vӿXtKglylu4PUz4bgEɔV˝E` tzP3qz(K}/{0>ɖ ?).H]qU#'zuWGd v9{R{'Nkn(o eMY±팿vy~xWY֪"n7%AgFn#ר_1bbWUW6A㽅W"?ii0\{Y#D.\kjQ ]fI\{ g䠠u>A@fDZ4Nh=d[&^ 5m>HwE+eqэuYWh3/-ZС$W|bJ$}(mtiz#iFaX1gO R`<ѯ)! .ϝ|f­'!RGT&tbcTSX;4 K`_A2[1Ԟ xxp몢-0EQYDzEƂqD@屻Sɺckk⭪ezo )|DH|;^P3J<_.Bлwh^fBXZj'#0^݈#'BEkxY6?–YzI\rt2@bֱ}ֹ~nRzhSR.<'z}Ci7e5k)eﺪ ._@.v ~w;np'y"KpO v8DF_r1zاWQ=@wzM(μlohuyBO{V `iyz3(SzXjCh:lSaLpO)_u٣V9VAwAM"S27$EؑrӱKfmp$GИ~ lvcH-| u eˤф+٨n=/#:Z-?ea(3t].yT+A_fQeI/'$t @ cY,s7h>t]\#Vu+x{^o+ _fDڷLU@7\M8ovKm!mZ&|F=ϭCSOK;̰?;E kNG+^4? 6hkInafo/Ce8 }&DO*%tḑ,Y6`__QՈ dria\H@Z\]/i2ΑX@ >3xf%h2L>;V!0IK7XWUO%fp} 퉂"ojյ$/ÿ?4bI=~+% Aʇ}ᶌ)zkG0/3ҷ1؂-(NlL۞Qȟ_I.㦹x݆07K} *NW,dk-n3KxfrV/wi2Z5+,kMCU^})XQ$@::!=MIGI(돘d_[LxW]"8gxTK41Ӄul.iֳ/0]9{)f$?%92"U`\Mی\clT 9*-ew#֬8Cr' k>%M(UB&go3n^ f5h-&j0Qkdq*/gX e*TV߉U/_]})ި1Otj0WgnC'ͭLfGWxk} X鎙H!04+ &9߀yukP t? RaE6㑄CՌ_Z0pe$ ^vﰝ@DƎ4K0%XVHs~sPGHTZab3>bJ"8\qx$G WFPruU 1 qO{CU$뀰(`}:K0S^d 98-{+=gev@ ~bcCTh:q\uSJ N9=KvZVI+)gw&nF؁ yeG\&:[A':;Pv QU:"TD<9QLO3[گ͚CI:w[t.cǰ"jKeU4iR7;:_+ rt 4)+@.'䚬 ;ژT6&O{`img"Nj o˚\,b D635_܊jMo!r4فDVdWӑJ=q?q,F&Day NAG d CICBPm"aK}Hp}ת-q+^`znh^ndI3˾1_+J7L&;bPك`4pbkX}#&`,]sӫ |dv@ViG":q}&{BiBk_Cavv='XNTMZ+}$mdwv[xr\ m6*_!>C\KbU/8m0ZGϘ,@:7<0 RV>T51n 68k'j9t=wJ ~ϗ}b:sBS-)OT*#i81?BG%ޮ|}Ycar"Ϩ_M:!pW( Ӌ<Ase@ ,r *tIz^tFZ J:L|w^Rulߖ5K!ȑ-nhpW2)܃2V^G u} ;9!#‘t$ 7[Fڎc铧Zr$yǔ'Dd9bSWަsJ0*k٘$UUzLYdc]ꆿ7;s=?!h$<" a_[93MLjo@Ѕ(iH:-0a-"N&, ʍcprOahz]9[ P]8Q =ާjEq&vri5F r($ɺ4)LYνz#$t'$}B޷L  9Y튍`qTc\`Nrc?'QEpa2B2mE֓CQ 6OB di5*$pԷT0< b&9'EX;O|S"~k,xE$TVau:[RJĦ(?>* j [bXoSL D#Uӹ>DSR7ӨcJٮr;,d>_{ǺBz((/rH-^@1`(֊rOKA="'Jm?ܣjVRdH[ & q+9N1Mkl\j_=(iv(ǕrJx#:MϜ,[iSD5:|WQ0$K~,~ ҲvG gԕ洇bZ=X$ؕnvErt45uv9gB ZT 5Ł;=zb5}< (p>@0Eо`|;oN\ҰNI`;%(~«WM7`١rT_K40u3V)̏R!ejUNhE#6ȧg6gh{#ˇKwg)ش6!Į͘N}RU݌Ԩ _lP×cHbG=pbBAhlSS.)#G;F&E 1fvN9o@t\L_)_谓Zh/CɤrLXG}8v|*C u3g/QFdUYanTx~O2׷X &K!:|y"U1 -w>{{f"/q =\rÿA"W{[c%adN{e!}NlZGCr&㒙b!͟#0uoZRۯ>O:ݘo"3Eq+g|-~eMuaPw}E2_ VMh`aIp@3Y8X$|!x0 ;WrĀYz]{]`S5歞Ga֥2^6Ko(@6ӧp UEhq=;.6٩\֖/.Q̈́&5L' kS/1MaԈ0=FStnlhuЯqp~&݃Bx8\vOx.E+O􁛉6% ]OjݨˣkE=JuؽI`vmRTvx6nHVNo2-h_bQp5BOi.oh[(}/_tR4t+>v$8vMF;K4 T٥Lkxq_Bp3/o\ FRu4_Wz,/cMskZ9AiטzAD8M}oɫ$/xHVFxE?F2)VfaQb n'g镸mMG ]Ė)Gw'!CMːuG^؇qȸd^?e`000aE|5Sįc@w&uǭ_ҟlX}OqXIPD;x?t}sw!D"Ɍzq'0BspÇ[(-*aWs)\f톙*SI*)mز޳a-~hH}*NŃc>}\^#.z'9xm"T?p7H)!KXwn![*"b |c;K9JܣE@FeZtiUZVD[;dƾYr'B(Uv6d5҅_MCh`ˊCW3lh{Rˏr 0=𑚒}AJlU1H_1\Ay ҅60ELgNLk0:[RC`?F9DdS*(`~6sNdDN6ѭ=aФW̅nPm Ԡ,88P{ 4] Uh7Pl2crEM^ϩ^,*iWhT ԑǷDLE4;#1B͜"ZHf-87Rp+9vR7m)7u,;nR(£`ԗY2sw+kB- li#vZq%Na TV og ~3E#Q0Q>D] 5cB󲏸Yip|2X7Bj"A<ʺn’b3!(D/숚<2YܜG6ZKX\oF =ENzB`n(-k.K_Mnb<@}޸83՗XmC._.?GhSG ?UE=N+bmh]E  o2 JRDe//dSQŹnp_gO8R@j#wRIqjʸįlCQ ;,P'&kVՖ -)Tb, tgzh8| Z͈'À ;zCj#Ӿ-3rzJUL &8ɓw0%3K&qob(M%htX7\>26A̵`ݽo [c}#Ώv ?਌w)91_whUg0EۮueܳS{rrXbKv[lya1egH7x#>@5[4K|boj.ʄV5w;IJћ"(8x'wNF8rO|JtުQỦ>XfELY ã-}3Jz__GFDϗi^MAGS̉c^Lu ` t4?UgĭAR٥ï9WovÛaJDrB[gc: V/>c-Ȋs +x+0xj?qRÚp_.!ȁcB8ҾA؜r F,f@ iiɡb 6Iq`0"3 ىD`ɋrC4%4Z N6` ',4vPa?1wSM.ͫYN@u'Vݮ``idFdNL\MKwiRiWwZ^0EG˕T܆p$‚H,ݱ {W1SoH)n&/B ؠ,A6pcf`)z asE8k١Oę=ZH& ssKլ^%n.Y& Q#&aQ7]/&(/ s]pr=? 1,nhJez"E-dž;'<Ŵ9>H񽣘:_z\CDb% Dd,PXozIHG%~ ܷn;PgGX̬q:gB9qV"?]Kl;d` |gh/bP.MIJiG&lk\őjVj:sC/{ܵAi3iDu^15ELxiW{p gm~5`˼@.Lnl~ ow+9uiz_ԅ'3'.cd.o\dԛ]׳eDSJ'9yӋM6AV_Kxń_ ˆ /W",^Ph4Ѱ` &)_2эhgIo+u)c尦Kn.JGԡ 0Oy]H=Σ6-ni ~r!b|Z: 崦NRWp1y먖@7Y(U6n¤7 "Pg7 f~jkٔBǽ_'N3qw\t4k~,D_iOGtf. 9r bC% >v#yN^3l],h/Эe){Z!Z}GjO?ժ:L'vVT^R&0BΤKZ^?o&{lrNHRSo*{iq6M)E5`+j^K$n4ӞG}%Vm۵om*rK"Iг>6͘s`,#+/ȀEHƨ1$ؽtձ 7y0C21)+R; [?Ek<2r/Reߏ+Ys'CEM:NWi7Hĉ٭\NRmԷ֮arEL$p\vu3(\*K/yqg0H?]F^ !;S(L +'+,(#Y"y&Aw=vXmW$OTcb(0:. ma5ɍqǛڛQVIː[3\, n16ƶ-ߙi90?~|%ݎg8lKS+F9eI7~7:`% Q̡8ELg ("RdLׂU桷5P3e<WKf]guej.3ұ c/=7ǎٻf$12/ޑC臙̏9uo:gҪøj~8ƒL8OAX9V"05J@vԔj)[3X1 i!JwLh!jiJ7jgI]>/.Mw4 <$Aϼ$[(%8OZKkcνX/T:Snǂ#aVi`}òkMES@0vw [_@0x_iN8] 7Wvix2a$Q̼~wnbfXv)SnIX/ܻ|cl|/:W ɸ\W%*.WD_ E:-ሳWGlXBvP;/wbY怊RcJ nßJ ;@Fyf+ւKV ! FMWwRgVvC}YvVlsJx &hN;)K{d>XQ7O!XfNo]򹚦pmn1Gy ˿c" 7N? ҡ?B_)KH@K30?/z(QFS3"2yA$^Wd^,*W\ F3=v|V'A0v$0J&eLb8;({[}?8^S\2Y\u\L<oj\pjA-\!ʬG_a~ZGߘ}t8,(dV]gn`Ӛɖ&%GY5hS.8"j^^(inqLM1ýyWCvk'!yybGps ) R?s5r1,'܎)/tm=IAYc^G8'L3(!b7ڬU3G=[FQDNjKRe01xsty{ܟϑ_@F kOzhK|\":<7r-H\i}ȫ-wN~0/7FQB( $;eS]kʀo湌_Io\`)PpaMSp;tZwoX@62;MȺck ` x,s,3{/F40†-"RX183| e2Qu܇m#Pҟ]2}G%PKj5c q^:Dd2+'(_I8~rxRF?|/GռpyJPE[JاJRƌ:ځ#UyBDyn|zinٓ ?d3g_" !qv##O u4Am:b-0x5|s&_bWG,G؎=_ތc GKS6ťI"zٌ<+-O,H نl#]Ypޗ4:ͷ)QP\ّN-ryh uGז[.؇4-Ge@qj_*?@xpGGKSD1umFOG1/ϯM3ʟ^MwIc1|x:ىRꔜ!x~D=롤E_lFy_~lPK^, DiD۬ŰDh#~4?_hfe$q%7wBJeagw~~ 9T=`#:!r( 3Ǭ 8> yI{5E3i,$ =,'lnc۬c+#sgI*a2H M?hi]$ۑ XhU3od\3ׄk(p g_B~!' = H¼ R~eL(ɏASvCnE Ƙ`| %/>%xIlD<F;̬eCHp캏@{F#MU]ĥX!Jו׼|Hts@TU}:[_H\,J('h:|1:r]lչs#A>iν5HϦ?Y]>J㭪RP6"s1N>P ^U[YZx(u5٦6$C*NTl"$t X+YZ\n"yqd.dp`gaF#؍*wµ "^ڂܼyw(2̸eOu$f1*o9.pV:yH!M`+-sjTR뺅b8DlbRHEȫvQtߥ :ę"U?8ڼ 9k_#V7^0APL {(P,SGEuc )#T'SݚYc*7 cVɬ" H2-*D . g3uixOMEF)e j?Kz3 'ϰɼ2"hO;J[Gf1x%p O#bR~{" 1Ч W,]f7qY4qN;EF9% h:($1 j[OrU 6%!i:6um9f곲[ݑ?]ZW6i,{a-1='_K:_p陱ApF)u7şR*oB%6Ĺ75T"vwoBF0xg ۄH9F,oFeR[Hjuz ՆmPgSv;ps!*|vv0(qAlpfy}[FQ[Etk@Jͦ1;* Lмc+w&OoF|)NoDPOI]~,cy\Gmhވ^-EF  \0O1!E[-qޖ_W-L&WEc M ( 0l5& np(Aږtc?DjOc+ƤFZkJsy\#霌A[?8DNRF.Pgܥ`% 1{sbd-!<1kYÕM%Yd164(X' c hfD9rl]Tvg-AI7+uwCr[ƣt_$A"ZxOm̚yG8ڬ~ܘ 0bq/3ےĩ8$dzt,ǂ ~Pr ÿ eAcّt7ԜeU?߸NUx.9۵iiUZ=V>Ed5Tu =m_m2RT ̐Dx?kȖy_, ,6+QftY*Â((F>އ T_ P㑥ķ.ۗO!.fƷoxB[W: hlMo Z>o(oH{!{:>q3YהYSиb>'U![@8};95+̺D㹍(n}LK͠o_W1PLᦙuR+HFOi"J܎z`I;ȫwZKզLȻm?dƺ{%Z7B~ǏZl0d>ղMЛ.B$,L 5f3w_܌[J,1k> !,MPۛgɄg9 Nl.b☭Z4t0N *B7R /FZKoO Z>m|uy+Na GbpK5]Ã>KıtpoEa_RMTR,ՔBؙwȇ@YU&^//0C.W+&3o]5O-6xV=^a4[WHq(Bּʒ7E(KKB,r>H.@{Zp3ȮԂם"H N: lܯRAï[Ċx \!. &+䠻aK&:*P$1sA"]JBzƍ: b7O$eS6E*^kţ5VxHyx/:{ EvVd߀7[4ӗZ,Rrl) 6 E]uAf8.U zK 1o"8i& ƵjT;KGU2q*x<&9G12 hvvR{3..[+v'm& pZ 8PQc;,d8U?9Q=P*_Ш!f iuz[wp[.J৭cOQ0~ZC5'I0S xbYX٢,BjKQcקǴ\|9@fKc J.( %l [E}jps J3ϤjPdpq\@f١rvL tf)=eti`Y3En"Ё%";Qݜ$MY³e)>1KŽ{ -G1ch&0[]UϛAUW7mCg$i"T_el[7^yf0W/:Xp3[i 9M o2,,׍Q2* r9RP\r]0˙cGh4`}䵡!-&B< YlA0M J[Q6{I*Kv'wS هKCq9X;\g{VOMq-0LF /H0Oe@P $|H,{޳+R%ǏutKw>!~E_75yߧ{794E'Sb('gR«Ώ+㓁U9g_p,l &<мoB7naէ#b h_%T347sd|Jd< }i(F{뒲 !wnXŽu} rfpC`_ DݫQ,wo9P,E/dkAuJļj(y2=-p tOmP|u)436&c)Ħ) o||Ma {ZkvDՀ JΛtTg2*[FY_z/)s'B'? 9k&ЩL<0N.K|q$ߎS̱h%M 1OH^$bש:IF%teޯjȴk3~i1g_S$уҷH]i3DXܚ)!~DosaŘF~Ʉ-wkY0k7vU\>qG,]Cd% *Z7-T (uр5cȩ tʥW ύ7f2ʬ5>!=<,>0N1AӼx#o4`B`Rdt$> :)ʙT2B8㹹H6{0J0GI25C}=޹:'Dº~AĪP8r1s(hET-s(:ٯ 6uYENW YvGH.vRZ,ÂN:^hӨ1g斈ٺCsqvChDHE#"#IpPY3~#LTZB{j gAB ~0( # ~*[BZWe^ISV_*'"_f-r@!㸃ۖ2-xAqLSRe*ʎ^G"Û^՜ Ui>")+]CfsW;.{}c=_>.#S3m~i&ҨaJmD1ʧlpM?[ cm&]0x1^FOEK}#/< _a@^ռ qlʡn/Z--jϴVw >m P`½unrr[;nk$sFz~SKX|7-\&h^SGSfo"46a#HH),dOzE*v]-4S#,o*'7&'⻶%Vg6G*2zLz)tPSl{rRd\3[%ڈ6/~0 /q6ٻ)ĄyN~ĊH!XAn,zy!t)~]7(~N!/U68K>gC:Ln4J˲8])ařT@{.j|k*Z^2e漈vfJ;})weok&BەN7CѷrF~T CmYiBMҘJ^U1' wK7A4j4*N{ӎÔ-_[E"V-"vQnΈ({'4:: w]0Qn&MV&廙4HxD$Z4нg3sVWtpAR0uv)zڄq8˂5 ؚ)k bkK>s],g8J鴟1כs/pDǓj}mfA<9n(kW? щoލO k\öePt$JEfn0Od%:`&Dt(cL$8N^&_љ>Ϙᯰ!.p_ΙMq~_wd ]|?.?9~aQ(ܢ#;huw9ޙocs244 NT:}>-icgdlOODK2}{^>d)Y_˛?Xu}o*Ȋ\ {_  :?z í3yÒ?F _6t7Yk?b u(7;沴ed!F+x?F+aZP1Bs } = \ҡѪ)'EFQ 0X8(AVsZg>Fteu[4(o[$̜u]7b6P!7 14^gjpth#wN.ۂ7R5t}r F!V?0̧qē)fRԎTtbYԐ\O Um.vߖT'%pztGqT\ѻ$D^ٳ_IVu8u.rSXQ5L@fsI;[ GA⺻?j|7Rge[}zw>~r9?vqǫ\`57%?U#A}R2=D8.qLIe[vY?x6~hs ^|VP iғ 9uF^oHoJ엊Lt7nw#6}0aI[ÖJ7g̗6T&b~2*zw]E?C̷O+U%2Ӻ4n,S\z~#+xdtY@Bt?Q"~Ku@[Lܹ2ȶC3O[r+UԋMqR ^BE$V0*Dno<Me ~t ue^cjsh4kTԙ@pxo:mAq7 ɒ)[qnnEeZَƞ]=eN)]i "Ӧz Ui\gfH|b@OwtImݖ+}ߌ y=,g!JFr%F< ;G{5zrիGb[M7n1{"<9lH8cZ2NOe9CwBx*-|gQ'XZ"C-#sէCkE*WEUgix f=Ti!itdf-* FR 93Ձ36Av%I[7^ &<𡩹_=[[fOWDxDdG莻CbvPn؉qj~im3߃JQ!7FnZme'5G cE޹"nj,[[8}-PHSMN.ô[Z/s9|Z" 20 \2SӀ:x ZwɄ"l"SeL%)xewٚD_7cLhFWa_w/ K-Ґ?0íր)@e\剁Jrv^(ۺ, `pZ8Ҝ(ƲΪh p6@kOVN%&;-g%')S$us4%0/N8% uY(ĨҬ|\5%܈d]:hd6[T/xgS_WMJvڛӸ(x6(2C3h)")M@zsc%M:(Sx(K,zsU=1 f@!J'+~|AlNf`4M&V82.ŢU4o[$Ɲ`MjS`Hx(VSٞ} l_:fvz&h)<‘\+Ls|Y66~,RQCvWeD(FN21G4δPlΊWE~BRZ*s//!n?؃|jmKnɹFi(<;0O .OdžVJP8*˂8#@Dvx]GA7#n\*C h%ȣ7kuvr{.v =Dت_hOZQ=?lP˙דvbmN*~ ʳ]ɛ|a~Sv_J58axyڬs(Mɖݴ'L f|*[r?_ul#,Bl]Sm  E|xc"("ⶉ&q1'vRL?qk[ho\Tf:[Xl[ıEVEi^n wJp~ȧd֪9JGu,{qۍ|. ǵÿ0r7f-lS<5qggs)6hl8agCȄr#OZxYpb{K8`9\a2?.WG( v+ӻ6׊ >oߖ/>~RSK$8USPr7<-r0*CWC1 !rF6%H1NYb|Qa1OS&ݼԸriDp ]&Fo8VIOo"}?¶RcsˏRM8Ԟ?߻Cuxj^e$+dT[}F.cxBj_ewKCB(`UCd(p|rR)rb㝇!u4'L0[,W.W˳%TMscgh!&3I(գ9Bshh?䌶&o3 o89tMj\"$7ŎgeCed1QlIq̰0ٺd3b0"E5VҡY&+)B.JV6}vg`DQûO䫕~ tqw̯5nZ9 \ýS 1RZbvbaO-L1AjfẒ!RKWS& ޅ/+졀:yMY/,dZ*p8Yj%]aY6ݞmI_/嬍'ww(d]WKoF0cWұpƴVY>B'Bm1bhETIMƔ%mgE'B2GN$cKGSxa9U(*/gT|8XtZ*'/})c%?2ܔ8{:M:4В0'hۊ^*/|JnE#79`uixwĠ*-sXSدpME^;I 6p#Lt!HR˾,]~-_|yڭ!*MV :}iDa<'=K'O Jxӌ3&>U-_z0&gHD{HpQeLhä8@Ȕ;G%EKg[kq>,xl`ZY>a!my:)툁y0|i{d#xywt ZlvVxrE7% ;xo$?qWh<~ /)5JÎ45Kϲ>C12JGTqqgJS \ulʖc$h" |-y+{F$NghBR,RE$<7X2%Hs&rpZ-(G'*[ iOǨ)44%xعEY_L,&<3g'\%4qN 7/qR`* VA} x(3h@;ONA[NxeCLv]^SlnpVt&85M 4Xđ#GXd~j3QX?cRĿ5l U-y᛽ )naU$sx[%Ŕ@$VW@ٸg gS]V;5E .R*tN6P)깊bNs@E,yP"ޟvm\ng.i޾'@>ʢf\@1 ޴)p:# XG Z^X`ӯ.0ڹxU__ pVFg׃gz_?{+:-nvb`K_'B7H74UGPY (mOoN3%6A黗&"hzܿo,5*  Tmg3FS[`scYіhVivD;*"<._ Cy5zTaxMV *j~l Đ;j1"r#T%8VV$ս$.$d SA6,D%o޼nS2ob]zWJ9Kdsc"=`yĵ 3eH( sA:9}t(la+IT6Q \܆i~@Q"AԷSu#>1#E8rWmJb@wTwJB)js/C^= EOHqOԧR<@揞'3פ=듰rI@Cѐ À 1,RB\Λ`%{f._HGN0հ|x~gF$G04YQī$Vfې99MNYDeo8s+y}p2 7 ]ZA]SY]B L0栂+%< A;BBm*n8F?KQGX;]e)'4{@EFEѼ?t,;L(ͩ$B 1կW H\yYI9Xm I,zMvȓ!؊; {_Г0gRݮ"̫|r]ZWG@^^Fn4ڤC$7][#Aަ'd*7x*B$⛗E>^HDJ+ʦfI`8ot?A jj|tXV[̢񃛞~4]&&M(z[t-f9őUn:7b$" 4LJ,h*;TѕX2ryXqoRBˈaeP[D%;tϒ=wME5aJc'wyOm;Tրk,U9u-Kmz;=GwhwǑGQ]v !3ONӾB.yBd& Ў wVFP3)j̚^qq((V[X`- r4>̯*ra9o>~!jaMTd ;7AH'jw?p"IOvd=*<'uÖY!P<3 al W\4x2+1镐xZ24p|'m R(7iw@9#h#lk졿g9ZEe<"4OȮN# PYFbnli,nП~HȤ[F VȮ'Uƾʊ<^EmGO8A.}?d375ׄ#Z *g EWa< D`>*BB=fG)Ԑ73Ed;R Wҭ]f(҆Sx>w\õHVN2@7d=,,Ӏ~1Oo 0o5fGhjw s:R'`娙<jQ[~[:;SE *3u\ư-5sg(Vݶ.,+MBCzp,ԇI'/T&LB(5kOT}V ڱ-%- gY5_. X7 y&^::H40][^2aڂ?է.1 XWI^M9=NjQ\JȾ1vcu0"2FXcL;/@F[p0UU@-ӢHLQK΋θId;sZ"g7/7k55`fd 﫺Qa+ºh`(?ji@ܷ]|EV:l3˷ 9yVË0,.rB]ZZ&ʆQx2)Y,Xi;?vJv2ص,%Þd(g0չ$w0 3 xgӰssgpE6g1T5E pQE,͇ <.a(%r4R-|G(pHzDo8Mc"oTt $v:֠]1 mя30O&,qB>/OňR o F=yʟ" ?(tFBF#*6NH PH7&ays`wͻLF;CV #7 vNQn?C)f;+uC"O'r-]Z'X& ''p -}6m/rCkgV=L媣j2AZx&9=O^/](ɇgnf`;6NF72ir΄`+:9{ 4)DӼ4)f8S _DNgw{>mT?![/luY?FU|.{DӴ9]samfxN445*2vU*~lh2ȭ=R3| # LL&aȺۇG[Uo#yjr`k\cWEχҮx4N4~Xl^j) =BU }F2N$dD 08*9}{ '2/I}?b&][T[wO$p>QPyҐ[f LZ E~YV鉆g\RFyy6[QiwvfH`(8jg ax κq.]\.wfODQ)X߅;; ϋHkybP9 |1>hV,"hܟM$tb_xc}uׂJ<Ӿ=Ǻ%-j&q.yKDC(c8y3pB\зr*lPu.7a*nFsvT=̷lrbZvz!<2h Rpl|OEo5-|z `\WQ_l%'F|Ik>G0_e ;Dȼ]O#|}41\{ Kd cvѷFgx?nuXRgI+@"X,6Iӏa.^K8Ն㻚L-^&@.s.mąRق(]bE+A-a.([#:Gx`40Q<D-չ8r]UmHY#=aDp2Po?=m)V Q:FՂn  3ս@jvs&% P XᴨaWON[$veR(vKk5N-ֺUT_iiqQ~8⹭vFV8G;5.ZOA4%m= A›|*,g#u( X\т6~{>,S 8uDL"+oX IA)56 X?FMZTVls0zj=Teed+ W+>7z.e㛫#"Lڲ79Z`YM9gRois‚LE%7Aܒֺio?j<½w!Ncȳt)rԯ,6x޽qg˘obHq)†7Iz$1`G*!2O_.i> '3=QWff{abp+mX1AYlՊpsg!&{Iڰ^Trja#c)z-JN{WohN;t“Y+7LR5+$jxRu>tc8>y@0.TesczK2ˀS$B5za/3YQR<#$rQB$M>׍emaPgCe‹pT>*#$})}_[ H;j-H=8ZM7U،f 7}+g?v@ z#MJGN E)H<8=oQaE}|)]cHhW\fv2tĻ#\ƌ 8) =  k\ :Y zkP 6C񚰳(tW -j3b?I,gZ8ߟnP3.35%΀}v m2~d3*O 14`Y$+m{q(@t 7^SlvuY>Ox@vvvդ+h,7M߆.EV+*+tN̠/0)e*wŗG[I`} H3՝DrĻ1c4=]äiMAc e R֨Wj\hW 8_u!uZWPIthj8ޠ veޝ1HqCT#O^EaVn.pPA)F$dk=%ݩ% #ҭ;$D gKM_Z2پeLBrs;($S  sD^P``ڍݡ~_mN"T%&%of˷|Ȃ+ @yt,]=YOQ{KSƹAѿn(@FPJ!X'2x3T'so SAұ^H<,|u!Jı޴D"_u /LJnL'h zj}e#h3 2Ed vjY Y/Zn sg"Y$}s%1+z,ю7cFr0ڨat|FJ-s?|(HF~; ѫN띤, Q^Y#ϥWhYV#oѽ[;~ ?>`*uP&=qH:5+`#Ct^V{1`b "ςh>,Y1%/ 3{,9m]ߚzj(:%SB@>h]Ay.ON "P}F=d ű S:|%xm (z .`݀fp=8,mn&QN.&W +bQPiChPV[;ҙٟqJqM0fo礫qft cPDa%~LO¿ݣ;*PO2Gv qif^ aa]g k9En=hC\ ?Sn ['|IbQ4(dԅ@:NSQC:7˴G6-TwX(NdvvGlatC_ƑHFX 6my"J~U]hIKq C~q/?PZ[r\B]WU>F ϓ D٪"y"ig>iR_8B9+Miv*jae!}&i51 '|+G[sot\pWݓPj:UQ;fECw'3{ddB<"vl(=xSxW(iFGu = ö =$EoȠfEEnQm9gYx e!VS.p?\WjS!L5-Y2RkF'Ѩņ%Y9ӥw!4;CYP[}o{ޕ?ed)"qtRD>΅-g{#ejHDRDcBz)>Q#WTzɌk(L\L5JOu BlMjQ^ KmQ`:QIk諭Pep 6\(֋Qry~|yqj}" urnQ{a^dx<R/ZZ닛`,HӋ +#y(ܓD,-ItV&)^,$ F9mUs|u,|KpIlބX?ᢑ6\W 1:Q$&;K1'E-i]f-BF`o`54Wm+~sZ? '40NI4kHܱ.ӄg'*B.\X\dnB'7[^Ņڻ_?IȍkE1A1=Kkʠ؜Vo$]1QI轚?NBh^qMOY["Ni膕*av:ptDc6,O#VroכH!A%l/& Y3R;L]RfG뙛ƊĻyCqA$\W==vϿ\/YNVruCc `壿&႞9>9{saJGV u :=B6uRD@3J#3v磼tŦ1ǡ9z ਫ਼+[sv3 j9s_:۫7z'SZ|K+OL@5iy T[һE,2PkhA]r[^R/"Jx;`=*TmA7DOH+B.Z\TM7j`k~V;~@vTF1 6T/x {cX?IĂS>RT!"F=A+`$GY|3窤 ŗ- @E4n,W:C@ii7ug#h⧩OzGg©z˚.cP l1UM1*0517WAjT J;AIyr}J^bFwm/n_xuejXnxvGecu+P*B|,i8)CP: V8Ol!£E8kx%hxƌoȱ IF1*^HPh]$$oiP1wHRȗ{h-qc<%6LϪtY|Ud-d B7CL@] +ޱmJJ0VH6&.30t7vXx&.7A\[̀;m ZMsp~ ہQtY$4 ~n_~exo'ƪš{ѭ\"vt`׈u@8kDAN.њ̦>\^?szKP@-LW NjD-`0߶{21Jҽ3 GIFS1;P,|MQT+X`#俜!JXҊfp3h=B E`QńvMFz{TS=-BNԁ Yԣk7D樂axDt6:J3W]̎loK5/*.wetkxH}\`iTͷ?sԼ=K4R@ B)MiIU#jc-owGaUbEj/L!=v04T]L.u])3iTOL-gWųƹrz.޻ QQT9\ ''"z{rx3Ӳ` b .7(ietsq2K/tL{k{CBX3vHTin*ΐ!O K!!A/وB`^Ǜr;46}'ÄhzPN\YnՕoݍ|~f{#z"p@3!GrSNvhvAN]3 VgZrw<$?Slic"J=T6J ;nfj5Zu_㌈h8Ij=,L84"|52AGomOTK ^yPZ8jH96?3\ / &4ch@L'.^iIv)wLm9þL8=/#QNՍ@߱81-k ҟy9'di %6v ʵuô?/d?pRʭNmw?cmw㨩>hФfZUv]5>TrnN:$OC9} "i0m>@G-W~ht3 E.%M{.b<5R%YGUK(.$z+JA*V7WLqRe.|ߌe̡׺"81I/*2YZKFrON aGN*'x3Αf$0Xjff]o0l9ُ*Z ?oo&wZx7~8py3>T_e@Xm/gh?.fÌ A@3m۾e<>ڸCC%ͺʀ3Bm9 i\QljeW4ɴ`!yg#Y?[ŝ jG%*Vΰ V"dDj)BXܣ?Z-oӟeQ-#?Ȱ) Y; /Ҋ x@E0C_'TOZ6FV> T[p!bzh܍]Я[p;, ,v YSz]J..xkh2L;5Mp}TO4=ňsy0u괳d(]m\Kc:3>ৢe  3DJbRtr/m3B@U$BdIxVjXe?h\hHV/TRi` <,6OU!!/(޷<[ Acq+aYI%vx,`{Pսmc˧31u=ܚa\IsJ ?/Y*G̷ +զJ!/'|8?M71p8 AbNjo{AMZYObJՈUUNiT3Z ρbU:~.ļ⋫صjwS4&1'(رV& ~%ұC!VegOg׍b }Dñu1q<˅X+k:沲M= /xkq1]v(.ҫܵ6"˜OG];V%%,X!BiHBZd=[a'X $L{aDꆶN #*L0tEMtf)aY ."픟 xG%4lC {ЫCЦ:J;[Nt-h#6ҕx^.Մd*_Q6{>찅!il)DkQ"QRu:t`88cAqYT4TKy:~AEh<4v hݪ/Q`jGcF$^|kʲ[tnCӡAjK~ScԼWi?_WY+L5Ximm}+ͅ#bDb:c# 'BwM"nhlWXۖwj~ki!>^wB,kpmL* ڞIMaLxI3Ɔ?J2fSz]NUQ6cXxLo RW ps+L>sq: &F UHMsʗGWдqYK{p!h؁a(haګInҴqm1 E!93߂֙Eӈ"`41 U4},#֠Y]VlÊTP%L4:90+H {L3䱤Tɜ 9]jC8cf=>h=6"ԉWbRͦT8ng|汍`>\>ƃB=<͘J4+ᠧ5 O?slڶUc6^nIžŻ1Jn"љ j/P)#ơކ ѡn(Mߖ/^v#TCvzF-Ԍͮ`B6 6U~DE۝BTcZ#++{W6ԮR-1 &lD{9{E.~%@hUd[>0BKBSbMº}Onϴk1xx-фo%㮬깕B"/\`9LͲm :0擃c%{ft{!($~"ľ ֩@ׂSTUMx0k0R9jq; p'۬Ԝ``$IA#8 H/P\81\z6;~º8}1w,=R|7S%|즃vhUUI+ kHd/w GhI䮿 3NZ\BڟzxU'`L,[.3VnqHkj[=7R  s"ZplȽ/5{o۵{lwfl΍V[Lwmšp"Q\Kq80x bzs8|=[Z.@ =ylTzd\؄H{+e'@VjeH؟\:22A<}KnBݹjQ5+`1A+S1讈`hf(K^ E#Iʩ=^\NBÂ>ϭ&MG5IO#r✧G,vj,kjC !YCޫ`^*#_EoFٮp1- LۈE Þe=UKd+뚋XIϙ'OK B>ُ*/p`Vm}^$2U!-ziox#hSpwͬ'ڎ="_hU5NE;(RBu6ŰQBuPb1 sN aG7ڞKz+KrRIvbs4+0 \ bçܽ:j?@ '또:A"ՖM;W^^Y`&њ7r~.g7+>h`H(^k }r@+^2+Y .rF ]DxH0tC<{lr|aSR|6 $ 97LiU]5WI ͐u/oSs֦=w9H*o-|;c7[՝}}'_l]p_"NЫBM€ֲ?Hķb?Β4XҔ2k4;@WZۥ绕"$2|72s?*;'` \ܯjiY⼁4۬Mh_3q^3Kw u?.b,}45M'ֹJs^KY~{I-;6pAY:5?ƥD!VC-%aeИ~R,I0ğ;e"%r 'IMߪ uʐ\(S b]ggDibRݪKrFD3YZ3~¿^/ns|hj>([OU+оޜ'#TYaHjϝe 7e;m,+$-g ,MQ)8;:`4^?CT >E!r -$uT=k ;+ɿ+d+ s+K5/A zSbe݋@=Z((lOњ\(lx<%`½H8Ҙӷis5 eC7˄7;oΑk( Ǝ{fKK YJJ ;kS4){5r wY_$9bAd;hst1w71OHBBsE uC'ȸb*V Ap(`c5١V]⋋tYAr˫{g_'UIie# 6޺m@8->9FrIjkw*+}Zn߾+PRף (׈z֙DMPcBNGS7.xNS W '=4d(6_;y@T:l_(Q-ӟD%#h9{N j:< WNUd 2܉EU1,>Pye=> }E͙'c!"e?RL҆beQ AH-!9[ދ|!KO?nx {co俋ĔDn6GX7msuV-wŞ>d5[Xs#&hH2eV# jBh"_e8)ÙޓaAIh.vϝSo%A$%zBGɱ#߳YzTNhgN; iR" wTO-6TѸasL #ް0`#X8=@Wd[ǒq=cvΣV1nk*Hf 1kR @k8 *B rV?GoG)0-3!fh@d=^MY2W Oq'B4mm`K:ՅdQL| &]hZ aBIBf Ƭ|3Q'O-9ݹn׊H9WeD$rBiLSͅ4j;=X5Z%ix }{ooh{JBG#Z쥖 !9顤)]E)t7)gbYG WShZBDSoӣFwCJHG2#x^ CɯvB G%M4B̛+ Z-'O3w/'Ptݵt %f\o=ǻ3yhJu_I5`A⦿#tH"#̀D!<'_<= w(IiQ5CMsE,\$):-Dș?Jc|$X3rQ7\P'LJ^/txiAz)I$-^^E|jdň@# u_8ݽŵ(w]b jKN+L,; .LEZ.h@~6 BT܈s蛰1;Q7{C<.AaOT`ztŦRc&HHE*RfA[нs/ǝNRB€ .mG"C$c۝ + UQWjyݒM6#.[45VQu`&qiKd P/H SZ—dB[fmψ#XqnD} $3jb5%&e -1Mviv^c( KUi]R#*S!% HY}|)C>? >MѳO՝WT >c `oKg^LG}sUԲI+DH|_M"wf)" 'X:43kB0_R`U}T DK=?(}u`xYc/9eyG~QtoA>ٰv̆JA"HsV#N;y5ӏ`\fcdeI{8/蘆2nyA׶E$%ؘ1~vl_ _݆:6[ ƀ#g+Z3뾩 Ɯ+ťjy& _Z%q,RA _10hani?k@viI i*7E ɭSd(g`P:.2 5h:.x* M];16}F]n)ísBh+[]ZG[LC-u`LZV")VlAL 3A7 ϩ.G'US*vKr *ASZ7t aJk26Y7j]Tv5k  xI| }_e@ mp ݂vT[7x_Bf?zYnܣJLMw{.k1T~kݘS a.ᶎh踢l>p:U,AF3*WPr"jwOiQ6lCj:6fɿPT+XĜ!Jq\Xڅ I"w-ߓ]_tc b&n,"u0:+ݼM]xYHko]a}fq p`i QDIU[W)ܘ,UӽL SI4c${R>&tn44 hQT3r)D 1"zb"iIpLbHХ>—&>p2oz @Y b 3cFgcG8O9+b+ZY$Ǣ{䷭F1w}CmI# 頯 S L*׼B)V9=_HcEUXWzqUFruS^垯ྤc"SdB=<.0A"`n,$#ѓ 7i*2gM פ~ޣ_}ϽHəxc'&Cso~iĬ@qFI;'{hYo. di>) pF D%ϰ 3_0n[(\xIIxbB ٙcu cNeSy]zIo?jt}Ę}(TJ d}q]'`l)JõF6F6MΚD$_ZyqO.{_E`%ruJM¥ ːjN?qK7ބ/nL`Ϛ'Jn>X nN*B +/xxN&"PfrSl\u;*T Cn.ҿ7+>f})𜟍j:%{_7t\#{,XKCc)ԫ84|G&u5no ~b]J/C~y'Ͱ b5CD/7RpF x,SY\EVn38 [qBH6P1ZM4Qzw;WO;F]Ě(0hCO6U=y~%)gpJ`j>H'rZBS5MDD3;e-@j4LoM96`[Z1ݰ_b[ )Ǹ>wcMKF <^a4p}]ͮ4JK{ʻFLû;cqH޷q5X;* ?#N+GR&2?'|ccy8 ,\[D 9bgYѐ*76p5V8/^.Qko!1jItzb/(2W>o;dˀ"/#-efEQ$Jt{H`aKB`6O/D?LƉR*%_%p8[.ך惌ʀ+&FtkP/`Tla2/Pjt܌̰q4+1 kwS>fcp!ɔj_| d?][K~L`F0L]ߞfߓ`]ow0o8q SŨp{z Ial%&jòK%X)Ii.`^t:$Nn7F2.`oqFּI FLeYzB+-Џw Qd˔74ڿKMWeyAZ?>Aڨm< j0q+V_pK٧ќL, % 1c6s"nsM>AױIJ[^J]yća_eelUH&ԱźBP=k|XU3Νo`GASG*MNl=cHZ{h.8Sণ3٤)c X?#Tᤫ8'֮**xmOxK`gi{*RVwJ Aaf݃3g)I$XvE @ =J&=j$Xc6j?Y[ ԭeWKmr|Mn[vH[=M߲q}YdnO)%C M1[fdge3̄(f'1CۊP[x \qIa|x.wۡNa1U5S=di03Y"|Rʾ>4,ٲɊcJ:z:05vcL3bF̹֓%8ijV>ÍKL~ e̯Qs3@DyԆ}tgwE卪HZPO.kZq7N~˝˨ç\qͯ=(~_ּv7 eaA9Cr=L*E(PonC/z5-X$do8I撎>o `̛v1vX qM!zE%4[U ~4?q3FdkLDH {9Ka9Xy -) &(>/X|P?8e FX.{NclYjl a/u*jw<$Z3\VU2ʘ[iz4.&&*dJLXU #Kby,/ye+&-9 pH13JɁ .XZ֦j< >U@}oI-޼VF ZPy?`JqJwYs'i]IhgfzzIA=$8q;zPjJFKwD4lйbK(H^]b2U0.A;@v,҆M߾hOQq)ٮ*uhU%q2W.yZڃ[ L)+R )OS&|=^&+լ 3W_?Gl~lÝ{mRi6#53#+{ g\EZ}BBKg62\W3yYAp˜na7?|\!|js F+^/n}#Q>n~p2"ùĉ{ZiL2ZnD\goW}_ sG(jO]˧G@¾&zkxk>mWc: BIꅊlgโb9t_̖aÎ;D%0Hs vTg0k=}}s9u&'϶NZ_3aK@rj `zpf2CD 8bBb-4 {ewux7.L|>`6j3O:C>Qr}9{r\/@ΧؐwzUm W<Eq!\8"Z(z2 +JmK0y*n̴'i, (zS?$Ћh1>A. vPt`E?.WUk`<ۑ.)1.h;w"6ϣV<!-#s:gnvh|ӰC+JaC5F6݂$-8.UeQ} vKTKRO;N Sxy [BN~V,g?^me^?m@1yG{+2! ƛV5SyY\GtĆ7]ko%gɿ׷O;̢[Qz2TQw洬(EWGsusŹFԘ0 _t1? }pĻ6 зzr6yŌfj:#W.5Cߓg_t xB>rLom v3 o>=e(bY}ՒH+Մ Ocʖq)Eɗc(IEŴl%2IF4$h|_%'#D1ߛ [ p˷Z,e*u]j|r蝓'cQR9w(;s M˲2.6AԮ\ 4C`u؊@-B&͟?NmeX4Š@X C)/<]A d L4ْ8=)<-'`W[lw*f(X2E$xPCNRl;[tg𐅂ij$y޽R.dH&̋ \v:ۖIkKi궹N vN$UJ#`  v±Xh>fyRY-WK)a"ftš/eZ_f?{7vބUkM^|2'rfc}G1KCtɪ~pa@}NB6H*3Xmd2]|y=QqFK&ٙb.ie7=(%`bD9=+FU@E *t(.5RF '2 74X_x.9135\LiQ7rn 7ӻ⵹56Qma#URk-1^#q9EP&ORKD*Rg?t'UwR0}&wN!ɼuK}6!'F; ʖ jnS:f^.5`VXx9Ţvd>YTlB> x+x^2NV5`@-ى4HGBpTNMX|$nzxOEKU"6Fv(mS IehpлQkصbYU)X](S5E{2~Ҷ[G 4jVGaEǍ#\,jYB)**T;<& t(NA`\-H|}YxBT S#n7s's];g\]33"ץ29k[/Vh t%B;>M)=7~0H9|`dϛTQg<9Z!1S#)ﮩPUwu- CaWHk"EJ+j-!M[oXhP!2y, Jc' _h ӱ2Ò|IxM !̱jEWK٭PouA;}n}qVy)6 W0g[s&;7:Z$.WRB6{i)-O]%YEw-mxTMOHc#Qsq PubBp"0yyA|-]h&pJ(닗>ɗ)W8< >80f_8Yr?IID4{4VJ'>$҃ƑvySӨF-uOhJeo+?M^wIfH$ctYT]&>h 8VٰDǰ[AnD%!+!NTF*(,"kc)|0p+g)^!rÓ9CV,Olt( OA"b'>~0TS(+"3 S_dvIK*fWilwx/ 9hR 1PQiL)"Qjt7sH&dX>wTZJޅV_\sڐ R AH롑JZGv]qxcCFkbުA}D!k<&Q ?b)C4Yﺏ-\% mGم\k-n˱x\/R2+ bWdFHwZ?H>g8K\qh Y=@&Wܓ>/\2RO.,?6hRi s{]ׅKywg(,ժj҈o~]`B5_aFTۄ@ hBj`i tOm339tr-BA[05h| ϑ ?R+;Rcȝ#/k kh.4KSVLם\Ȯw7 cw=)++ߊ^W7umc'dȱ6n,w%՜CrŋV;J~,AkM*"'"opĬY7b[$I>4e, V[^0Ҁh>FGזI#Urș#3zpR臝qݝFAG L<$[@l0Rl]P)r#VfAc!ڷ2\bw|@CPo@{_!?'?G'`(^׳0hƲy:/cf;fr- ژ./~K!G I>Ay{娑ʤ$K[o3KI`8mc.2&XG|t8\dyO2fo^T@@A1`W ӧ_hGc=ŃX-xܯ>tXZj՚EE=ԑ7"Ο8?JVi隚GYUQ@2{`NNa᠌ PsAgĶ0x{2d%Q$#PpwDza`y@LJւ3'%A0MŮ)2"f}af}̟;RZҵfGs[Q}I`&bʭ4}J==z|McrÝӫ%3JYy)KJ0|bs o4!Ҁ;p!8T 5/kEf[v[7m!\.mU; :szȼSa0}C}_Es(4R%J@OIu_;b-k(e8DFh uswp,0}rqGj=2QZ!q(?Tf`:--{/g_BN{3-߭]iT2Q sNn~lu]P)<L[ X`:nV.F $ϻz73l@.mK߮+Ѷ?SE)0Ci\ ,<`N [3\ _]ZеFulEc†Wd&Q 3ܧ59_,6 b#<zRz[LO ri:'S& u-;.K}4j/fkteZQۜ n %7|uayOr!D5z—8VTx%mͷbSvLz;utR;jބ4i ,-,昺?S[c~'Mm\[]%Q6q[WA&4MM&L,Ifօ9cyeSL7t;ZŢߝZ6GWK1̏tݜ$i3s%)2{sPL]ouDf~'"4 ZrvU'!S?Y< čk4H=l`ҮWa3-|9"#$v4X!QtDƣdv$'3W}yi@ءC9=8(zbqvcN~fofI=?[}Wzse:6t1pIRbɽ鏨NyE9¨ru7UVn6-#r1vЂ;EA{я#'Sp8H-9w9qK((ё|Ƽиz8LoktmtD*3T=܅B{.&ZlͲ~aeFªҘ4/DTӵ#)PB N n2¾V}(u(*fsCD\-Vg1> C$[}'.a+9vЩ|"$z![f[sPe[n]JDx1;oeW> 2=pwٽ\b4+M)x_KٽW򲍊&ՈEL=cfH_::Xtǔw%hۉ:jNN>G=[v  ҒT$C1Y><j!?ՄrWe$d^#8Hĉ (Mam-_j4,'Or̤]:̺'km&=& RY; _X!XM{ ݯ 4.\MBnG[ ƒeO+ =ҘP&f}1mŧR.f%=r2hɪ#Wa g *{ܣw}뵉D[]h\oRKv*I;ejQ  ByuR^@HSb:.YlE( bvZB@m)|.6gMg|IEz`!!h{<T!q{:vnlʝ*jCvZlPJw€#8+sc5GŰ؊ f! %[ f?h07EGix/)Et[Z!IĜMĎ˟򨥥ʜt1lW'cTsM)QR.g'F`FkYh $i׺Z]!AHqݪ<_}!=@Y5xy0ve|/lQݧRD7x8*;!ہ` d]1rOf[^IvntuLmO*.éKo} *g7$} wb rgBC¤~S^2&U͞zۑ\>%j,+N~h\ VIG=' x=[:]/r Aۏ>ʣ}4(6l楇m(+̊$|aNhXY>Hȩ]w{VS"SjMMïz)< >u_H.%@-ȝ |ƚvMEs`w(unϮB限^:O33*YjKsbMw`@',v晊jM'ɩdL"!;f"+3Yǟsd&'rzsX陟7dS3q훺 .ot  MjtONc}Ik[p(~F"4YMDK[TT7j1ؘ4iJyX9Ж-!ڥ&F5ɟ; x'@Z9Wd.{b>},ր\D&ҳm VG~3rTNhbj-4^[:uo {zC>]xm 9 ㇊bVFؐ;;16b#5gTֵm_ zi` *ICϏVWc'هwvxԱHzw8E}f^j<mʴrB+ϞG*gPV?g*ym?zU-dn35_JJ(wp /!:]!0?/dd,p] X. GCfLM<4S\kh&r) Z xt ћ7֎<~-fHvP?6ruþ5NH]ȝi 2}Sc.TbP7= ·T4Xh:I^,s)f J!zTiw9VTE[%!Q[Vfvcp/wP@|ܹ̅ ½WJ="((n';1abꮓXB+^'6c _Y"WΤ"+t]gg !U]uפC'"#BpX%W$j߾E\~;ڜ.[2LȁsZ7$S ¯Cndn& z.upشI>I.7Za¤<76]T6 ߸h|S:q<(NIH !EEDŽdDϿtL`eGz~؍aDdh9FX!мOS P~\b ODޱcC+9o%l"zfv;{̘0()$c6A X OI&v0:9,c5l[/ t> c0H!zQI9f)yPAth+:!;YGU$p$ZJ5l(^7E1poہu;΂n5%iG\ S?>$Ar5n~i"f<P,/!r';\fMpS@MzQiؔ=za> wP3kE1؛g,x.ȟ6x g*Û(};H ͝ D,[G=*:'CemvJ f,Οv![ O~aFGm>ci&2ƁF.?[6Ӎ[ȼ6\(m MZ!V>%,#okŮ.U,e;t4 _>$ Nܟ$*a+Ų"\q0dQkPc,[ctY%$"IvY*CgJAy0vBua5T|U+fvvmvJnr~xFD9jHE8ҷKdm]~&zN]ufB4&tF .wMiMBXN a)AL=F,^Ct*مUw{ ٱ\#YSgTC1Ucd6IWG`L5!)_"{,^9-6{}<-٥?1'?{*@^Sc9.) T*;:k;e#rqFu*e$cQZK@MV/;Wr>C Td\3霭G[֝|w=*I`Cj.|DΦ }?hln] FE,c@j7iV_%zAؤͫ{w葛ĽH0!:ц>&el pZ))2Q ku,b -c-uNkDGA9^1l#*}zl܏ym>"w@h3,t V@; 3]Hߘp< je_@ahۑ)5_f(cүkt,vT.Oo:Jx+/@-Ls-AUc*&╗sS7\Em= ؂5l8̮ _wA->q:'$3'$`IKaѕc(:ܵ 둾+٪oZ֝S{9)Ɉo+hTRV_y4V҄ Eӵt` M0D;=/EP|V cw_WGtSpkJ탽j<;# =? I\Fp+Ӧkjp8hS70zDL7 ̮e*`,?X8qΌ#IR],@>hFB+Q)ӔWCZ_3ISJIr3mn}XSr맍.Or> b9;<p|}QaѩѣX@$B-*)=A~vvBIVD`MEXX?#_,/-kFqvėlOW^J)M_E+\Q(e`ñG啢d pT؋:{iH6LT>hJ(V_ؕD8Tu}Tj).K_T%@ճF- 9ᜓW  gpD"D ,L=`ϴ==e?ID]bd5-Xo2,J KD G"Eg[x@»u"2&/ADGKR7B}~0mNm/(-MH$2޺בgC(@}קFSSf/ufp\<ݶp\ 3~3kT@NjEIeM&+{I:Ew4myɭT!=^z IjK0ŷ|e+>y۴!v=@Q,Q\e# N\bGO `YNp]U#o4Dlp|'uܩW0k7ZRvш>H:ؕ_ZD ~Ą1i ߈SAR~A}li_ŬS6gtI6_lyo b so6]QT}*8:zA/A-yK7IFuOGjy(Z6 3N~K[%#7o/moXM>k>%87p:Ϳ4%JQd? ¼XCdrRZl|Y6݄|ۉd -]i-P SSR rmv G1et()@Ggs&E^*Yf`j5Vf i(?^V($%ZKcX![΂{$+'Y6BV:Տɺum: yAMTds/An{S 0ץ*tFp SdC,&џ2\96Jvu'6_0 |aQ*ۂOg X89@u;fiF䙁j+$ +t ry# tԷ{!8o(w"|xu^%#7j#/o1FÚE('=>2 ٰmbr(LR?M'<5:ug=>7&?F dm vIAvy˪Zj"GR=wϷ>% zlA/#NԘ`R )8߉]k6)Ђzu̲Ҭܨ3kl&)ˆڷ-O't-٢`nCd*N _.oSv4!x91}>-Gad ?/_{71]:_Nƥw]zvX"<3]Z R 0 hz:3ߝ{ն0Un!ݖPc!h %x ysQ3t;ҩX?]w]g*Su@+ mԑi%+6ǷvFi`$uӼ!@KhI)TMӋY*UzHN,e.iE}Iz ո 0J6DP8A{;߾AqkTb &߾NzqN*hLN D&t-F"GQ4s]rQzPK^R %G»iV4[ձ3s `)8hֳ"PWOL7Yڟ PdFtYCbp=E+46OgbhS`S ~}fꫯ {N'4A4vՂThW"cZ6Z_ jnbC/g׏LH$ھux0'Y(uR#;sBNE̫XC\5.Y о;ū-FA;2j7}7X8}܇7و 2LbJDDڑɩtvG+R`-Qa)0n+$/oA *,h06-wzАKJsH*ѐ Moh_ )0)ʛ{#ʘB0~뛖j[pߵjI͎M\PGO7Uu}$1Hk|F yix]dQcRQ+p/%>2~򡲰]9@C _|1rh|Q )KAN^۾ez>V[g&ѵmҬԚE `祜a;9r }3, #i7Dy _ |X1ߥv!ω TO:Q{f.p'fY l%EY |!a(VS}ׄ{pSr| z!|cLXuv>{#U g a_# ю5ȪtJU^8/`W:*gkNnW h. PțoM~-2K iV;MV` G;C-7DtGR/1>X߽4E6 8d3]5O>,i+mIXQ&*'{s*w lGRHG|̸f$~(V;䰂 6H>IZy2|ݚG/ݶHk_joMUӵ$^%=p /F{"B=f$R#-~OhD8M<=.:*A-LJ/K_Cwțf~{0i tjGXw1fx|ݡU$KҜCXy( cĻ"rSgs0lܵu>GIV [^u߱JʘJbΒa~y^YG_;=<;{9]mB3C.¼JYx$3aY1b\3GcnSn6&j>zZ8V@NŝSf҇EJ.R WIBb ?p»jRP/i]>z%\0#Kz݀eծٯmTw=.;}Uz nSTd>$]%љB>M7{y;e `R@u+Z]ȳj=)LY#Tߍ6i,MS/yz@{dS#V}|j`|9o ukf+YX61>UQǮ{#qHeyw7@j$]IĪO-RuqrE}wqw'v~;k-,(;QQuufgzK ͧ:2" COFc A":?F^ lo~Yvųzh+X@0&N45Mb e3 O!صRjJh}>z0KhHkJ6[ˮ%n+ΚJ:\Qdzb=(iumaacF4 Om2UMM00Ϲ@F&{ܜI=DŽaDUf~(yAH'ҝ+# Ṛ  0f`UԸo,P;g֞\2?`l9`p/TI᫠\MY\+9h-aE;p$Ą%0Q)XԅT66Q6P-~gvyiy,~C$r0D] Ecm޷SqY=Wۆ~횈ǾxXMebaΌ㸅З[jC)Ew)Q qeY#8$b%ZCkkr" a|w)/DG,MJ݀Sν8EY,Yس\]FKi]ʱ@Rw 9/9HnCxKMmhw!`3jj5Gh5!=Srh "g*WSƼBjgҙ7)ⓨ/ 栋Op`ܝ1-JkXN_ĖTUH,#lyZ,?&C[)pq݀Qr ]ȣA.]#h *756k9I*FR\ t$ۂAjPJ546AA%yz_L/ωF& L>cbz5$fIvNGjfKSۏ)Ơ2+?Y}hfttpJQY/j led_Od . ׵AW7w`?lñX[AO"^53/Ea'5e.Lüz]hZO<x0Gĵ3q=#`ο3?ҝ9^T̼fLW:@~!=,sƛc8TMK oJF̓}Հ.YJ10%3[R.2 &aZOm 4jayڣ,MK{b$q~v4;K܏ 7L*V_ 〰7N2a$J‡~vfLڭ XV5Dpv5#&E~KlgG WtWSIm;u&:PF\ LWbJ,i3}oU"nlӺJJv)(Ti+U< 9Nf!9U ҭ ,P8 qeaHGtX_XIX$s|/HUJe"^chި~$u\nJ+RͶHӝ} OƞÉB~qzJ*@&5`Yj'Phx}Jք0!KM686E7ad͢O yx}M'FaYf[qSWjᷖn'uIZe ~;.\ 9 L+7/0f:g7({7R*,)]_@ cܜ/x*ʖ JD>=G٬.W\BJxЂ W'KtӸپKp/Ip"YPjA(c&A~fer'L6Z͈b tRm72'c;w~m+d>; 8 ⟼oa@Ȭx6JDK\ Mp~XʓGs6ߍs[PCqɶj״1 084 \fny-@~8X}( +xfAL^.d\Ř>{+S&抢1XTx{ь8|踤"*:wX'b娰XclUpXz']fIr(~>w0d]$-}trR*"7nEOĊjBO:r{o9 <9RyՈh\n`aÆ3]Fq[ُ$*D\0{Ao>dC4߆WE}# \3W_M\ sVE#?Z g]<\ygС"Ki;U,ۜd=)h|s4Oɶ_&}uQKO+ c ߃3tζ*csB?9H۲+02qO|>ƫ!B'LXĂW7S>S`zئN6$IaOqd>quJnwG Jpb TbUe&K HB!6E4L%$ |x41™FMՋ&|OX.}%. ii,MV=V֛XRos܀M‡͌$PQrfOys4=t7eQW`;h^bk~Gb&C=Yo8| 5@/cZ *o#qy<6hIl|aI$?Хr6ڑʼp+0/AMK>ADmfS>nc֌[҄ARCxA]C&O%Čϔk +0Ƅ=OKaq-pՊw!tD_(Gt:qlCxWmi ΀h3s;K>)]A~X uv1 yqI" {jS~Qc<11E^"w˩% 3)TRo1G$"ؕ&_!|P3A0i QUV#<y-y;䏃G@2J<2u.ObՄ!ԑDm| \Uw`ۜgB FR"qՒYccn`@-HћIo'd`J!Ac\l*o1sb)(VUzV,wcw,D~R7$YmNi$l ;ܼxzy]1A/t (/yLUT3k( Z68y@7gFv}ܒm\pVd.VV-i.͉:Ѿq؂zOm׻gnL;[$qT K= 6yx7,|S !2C~(^6@uCr6mW6Mtwʽp@[YSÖt F R&=~z_2ġ"ָDы8<0qДGTAPtF@O(gCq<)R 2,IZK#+7(=`1o];~ϒ.~'sHÿ!qH4aѥ[ZۋVaw'GPPp8gI\`0!Qu~ =vN/GK~t*}KRgO,TeLn+42[ia9䜶3ֻ7Q~3 ff0!* Ѳ {6s.D]SU{JALkkf9kǴ-f,r /vl# ~"dˉ"6bޑ\zDfHLOyY3eɵ~{D Mm( Ɲe]!9BÂ$G,㯩}!yJ]VO< fD͈H+E=xnoj.4wʅSE 9C9 Y~6ڦ&k?ڬ+?JEE"m ^y=MŦXSY7 M-.#cz^"2z:0hߵH#ĜTs&Xޝ.D/d^ҫS;J8aN߄0f|%R6ΌE@v&llӵ] jƈ`>؆î'qݍnkOTnp"+@3ru?]j<"[فKi[ ʚH >ִGD1'EKJAB `{Zєr~vJRscՓOHFi-E:w0O?͈ǢǦɄY*VY:0,vjX0 ,F$ C>%X:alW^+0f^Htr"2YYͻ}Nbv:8&#Ouv_Pxt#oBBy^{i&b.^<'u$|&-߃XIEj9EC \7DWY43!V[ި7(zj<%DLdM? !U$m *CU ψѹS .}\cqX Sf[! sF{.QO6ZmMUW̬bvay"6;HTXgS gqC&k%],7P?Iĵ2 ֖L|ҧ$hE,䷟#3.tGvN= ]U)_Zejj +6PlgOI~DH{S^pfU!G ixTq#{@ \ _J@إ PWܳ6&Mg<#ou_!'p?P,^ͳ&Jԝݬݗ WL?0U{{u/Wp, *,̪Lx8[ !~,J$w'M<+XDeUp c*G*kkF}lh-ax3劆# d<*Xb5q+][PT= mRk[3upYq J3KC:fDĂ.LE QW G%xؖ7>s:/Z 礽5(}czن=jbB]/dy$a%īk$a+~gr.-ޱRK[Ts>q񰢅_C&%[J5Ff `e5+=B9dU_}7ōg yI4 yâ䬅Q E&)(+CtY xaX9YUzIA/>w< *Yy|%\ƅO*M%@]ad3;Ar\K #r[r$t*k4$$FKOnDK²oGBK+|1!fQjzID {B뾏fV~{ɤvwL9=U$Y ŢA?FۜZQA m T-b&is n~0j{KqgzF*5!㰨yf</#d~44ڳCfWyǫc(3RPPcmbT] VI:=g&[G x8"^vch5LVZ8 %|Er6 rY޷&]Vўσ>8mHPݘƅ~IA@#ܷSk.LN R=\DO.!u0H)I7ݳ]ouw.^ Xm9I b]0 229IKa Zj}?0 <2 @C7ya^1NWGh!#g"Յ\X-"Ubz`N/ӳ8SrʗTu&s0N,7egQUȫCzn!XتHϧX j99#My^(XsF7 MQEUS8U~}Eu Dld6_lj-g n>'7iFM淐3rϔe$c_(--,+ _6 V`%ĞȖtRԷw.=?&  ] "3}LKgQhuQ'l =@HrgfƥMa/+H#|1j*c67$ոl3  Fr7ŌhM=H]]RH.mvpѾ8ԝP&}MX_]A2s{wB>f,t!Ae-HrvWrږs]ElkuʕT18Z#2$685KBG&};/g p8`od%y"E*cr獘6c>H0+w)?Vסh-䘍*A-n RqoCbڝ Is =}P 󺉘,+ fIO|+1kړM^暀- 9{=ؚqɨ$x;C:~Mq{kBUcJJ\a(n`o?lKFzhrʇra9 nw946˖~sZM#Ml} E"vy\,2^P]:Jo#R7peީ⚔ljLb 4e ? )zHj=qe{Ę@ |:pn)'RsX3`zvqWZlwz}[n@ bz9嚵=IWH^^R]7Y?s%5pK.(W"^"PaoBwxW/lo]FAAe8q$еgLk}+|a"}=*5t 0w{Pf rA{{yV& \*S(9@r}LV 2 Eno-]5~.M]++L>"eC!y#Ȫ%z #VƢCx">O6C\HD =4B%b+m U\X,cOuH6;$F)¶0_`8jQ~*\q{) 9$oF b^%5_Wәf >YsH`-Il{Ȏ4Wsd{[9!攮..T&A3(IOM8AJ'V$Ɔ'{ue%Ha8QY3c]LW,WDWT'?xjNz><`JlSɒZmbcpbDɟ9m`Hʤ-E NjJp[$U]ɷ> < Z| j~p^쁨$y;HW06ys .R#R0g9`9M>4j$9]0^m|;5ؾDM@è(Τ&A:x&\ +E>TlUX4 8+dȃ-\!\Mp Mezt<Ydv՚yjT$J|yM8ky5Ex)x`T W$*qvLBv lS+' )X~Ap NamP\pS'%p4*zw#;6)şCq;gE,:]xdé\~8e)-YL,)r:BFgH61 ]d׵G|k^vҕ $]+.NMuN>lua3ܩ}S0G=7c8zSi+{[>Nzʆ `;ڍ[ JQ ׬;̆pCwi`zuKFpz>6R_8Uʄ.`2 C(Hv;&V, j`KxZ#+a\߉~GBEVx,d7*P#[0'@iY}Eޖpka9ΠTm~nLǾSI5~#B!b[Y{ 1Hc9Pw!r3+}L+*X3~GM6CD#Ӂ/)zol WB6zD gz4Y<{*H0xZPܔF5!J5<&B*q&%s ݉!o_ 5Hy.rNPS.G\/kil'[ OR CVWɥ%pn[Z(*[4MΰrIs؛\):@ 67;VZcKuN4x# ʋ*i9oyVuRz,SS1'氏Wrt~[ JS oAdƶq@ |l^&FTJl?:ʳE96l je9)ʧLR숁/sZCjBi+;2"+̢VXF]NuJJ*jB=u.hSTyjCpd@͌CrguxQ Wd9L%IAmޖ|k'F|b,ٖ)Ϗ׬$|g8 /Ts#Z6.P^mGܺ3Ny{CT<6N3-'[s+OGF?lcS~'ܜiűy5xD- <3ɳvfw0ƯYc+X:AOx2_H8%'zDpF.VUS?$D4J-ãK.&Q +YJTWKXZXۦj|QJQ&%szatw^MI(d sbz I? k#nB%5Aw&,播;M_P W?81(xuIcT-oP"Ur[v_K{ukhVوPTT5;o"qC}$*pjc+WXo^SnahKL,]T`C:І=px*p|hPdoJ: r%lgx#tұFh?)_Al9ԑBY,r}O<'*uﬠZj@8m*lsi 6##XGĠƲVP1TX^]jR$ndd*~ڼTI(1C` h0:%63M{=;t07"cOeKmD.P(1gjAAȰ485n2ʒ*/h?Us:`R;&XgMwHɊq>Ql!kB?YnѢ|'&gwfz^p>**%U@k!?4T 9$9N!iٜ/0h~7P~aZ:_{-ih\NJÂQf R9Wݶbؾ)5tك#r 7}796yn[R 5{h-!Jy ,kHw3ٚ׌r; FN |/ XI'p!J@}rMt_U'@w]CE{nZm1f2"uRxdE!03F/CU\s|VbR)3G_(gLKQRt&?6!irdK`I+D=mS-(|c7@>= 5։n"mȹv,cb%(~9 uxI( 5}IJ%fEº3)0{]k}Ss$*>;[+Ϣe5Adc売`Ѫi!ґӥ֙jJ]dq..CH/@ ɍo5Q犜.#^MĒlҙBc, y5}4):hoAoF~٨ }YM GSa{u1Ӥ {*CZqt"p?|_}R#*!]"#6*olW(Q4ufF dk` lo rɬ)%-R%-D<ɾcZd|Zh] &րB mЗz6^z᫬GJq'YIDK^g_mAqFy%bci\$[:)ҁn,+-NxBÓ4Nh2xy %z՚r=up;# 6[^GXpg 96$,مtcN6 wQ(>(OC)̦۟}QHlo}H40U @&mCjb/.?[+!e5n2&1p8;'N\̛D< yh_ }$ϵ[.Y3p׫۱'AVЬ%k}CCҭJɵ_5h}K0`xBEAb*O$_-jbpFUeȨƑϮbӌv=5 [kD7u=rjLӪ̷$Yz9K LjI~+n&\2=&RsRYcı8ruV!H&kkz# G7w07vJEMfILY9 ¾O4b*1S֧C= % '/PYl)x;NE\ߨ]cwHJ;R"VΠԹ!>;6afS'=ZG-d%>0)i gYga" `z 72yI6ӘB.D]2dƪnc ơ,_>'в_Xeߤ%Y;Xuv&$O~yƳq7y8Lx:n/Y짾z%n\>~?\zPGOa*!)T :jsCI׊a`TaC ;|iك|eupI(DʭAa/|O2%va8 O``*3=vo]P6-?c[ݍ‚(66g+̘Mjlp/%pwJbw}9Fe(H/Bzt׶FCQIS$γfg&ZgBjR^nVǦ94hYA*SFAT<5 zl *˝Qxj[=9hTkr#2P]}(4X1翴a-Uw1RX]GQm蝛#6|6TΧ/Tow_ݡb=2qoꡭ1=!#Wxlpzʦ߬ȭ M<], -2)M` Kк>Rq(yZBN %Y;F<&DkX'VGIAv MhdխŠ22xX́C#ۨƝ-dRD}ĝVIRne/ 5YuȲJVF)Xא~]WuXe¥6ҽRČȍ^qR'9YHu͓n9\W~i ?{9'* +#C=d?w22YoIG> asQ3!/\LmszxXb )59ԪJؼ0V,ѪkC58'.nQ1,Ѣ/Y衬/)qȯXBGk=uc&rl !+Y [kqhiÊsާ%wDNžyxKnak+cƛEӱ2V:[_+8rCXn#E754A*߸I%͌9fש-8U\?}b =Ei E.r1-#vf5ncM#00=Bɯq>mXH5-EIDLNS n\n|& {G D=(L'RU{ {sęo{\x+YKr}zn~*-!{.}s4?תɻ3NKK-H4c4 ) =1;)ƙ x="xL i?)s)"\ns,F OGsX$(ox0ý*zKnà@OtdD!h3FaF~>FbUZ lޠ:bM(BH1gg.2dP;O}/ 圠 BP{rN+87R~ТT> O%.VL*VWx&hy*z6'h#s"pr6u~&8U>ȶٝ߉JX1'>=h_TY Fy - & 4 }ףP+˸i!f9\}052$ȷT.,tْ_#ԅez$.euZ6KPՑ7u6y0q'(5}!~E`vu4}rK yzr&Um%(ح+։ОE%1`STuE g!5Y]MuTJ<[/֏ppAo=DR}#"V`蔁vBHюΞ{ q mP96prm+kxގl3dz(?nF\ R}Q{dj7 G\5jG?dG74D{6}weaSH,B(m 4aO451E*-~͔_UT+^qwb;rO֙TYHݚ_1EFs{YkC!'A:8چ[,8AF$=k30 zͳ+䣸+{A8+J5N`TJ0/Xa`KG36x],.0WFqDaCz& /9T(ClJ>*#@*#`2N~X]i#NU. 2ƣ f[i+/7c_4ȬjmƿS;4ҕaWpd߾=?XÒ (Y'/>̈E,R\BQ(^F/OEvLT>*<Z }PY6e|nz5-sfiv/!W"3%l-o!IP)>zNY`F0?FeyMm`٢1^H)= {{s$?fǞ&]s+^X)S"5ݎ/) σfe6^VEE[HbśdX؍,˿(T=r$l3IPoG..J,JwX)5c_h4m Yҩ5{tw#`R\0K[8+ni}qTN8N;ա6hegN/(BL'ʟ<YFL, >\m>*I$<=Ot/ϫsO%W٠L|ƳwV3R49>#ݨ_#w@YƐ e.KLd?;%yyq VG؋'IG!H7eGq\CnRG aMaibyMD#SqJA|-gɭbx;$S.`8{R4edpcKiB ^`f{#x;Q"sC3_ 8xlK?]4r䤗`PIvz@t摠\Nwà FhQ<sJ)R(;^%&?/]FV4P0 G"!z! `^ Ľz+Yfm73WShob=lO2hc-0~|77i.?7>`u?ùg\a{Xݘ$ H.LvNy絻@pOR%jPMWr7,%SD NֈaIPo+)sWw.MF}Uj;X\@7l5p3;@i6t!_+Y-#嵎e~ .`j%g8*IQ:q ֊Erخ/i "h&s$Wc.%sPTZm<=x"d81t)ZbΨ1';$H%^$;0Iޑ 21x_m֝g{$ҙLef 5-<:ḿLi#%K+ZNm83vDH:K2}_:f+ ڿxq3[j$2krƧ|y MϜ%/$TCd1oՀowKg<<4?+&{ʡ-BytXW W9t+$!y,ْ! O$աFj[~C㐳 6}>&CWtO\b./d鉭!aw#(*_[+cA8X+:< +s hG wre|Kq*'پŋ]П!(DZ ܌z{3M:']3~D9E B~8[S*y܍iԑu8 G yyO-yK:"3rsZsk /E[L'7VP5:.[}y#3^w(~Е 2.aҙ7tp[7VM!21,Q~Gzc+rf=!n"|9D l_!MYs MbX2Nahy@t99^TpV&>FCLmB.bOGp s`3qɢnh{O'b*&LULiY::"%Wc Ph"x_'r[["2D6i7hNGCh×+6P ]_y$z&-Ѷd3ƞ E4ҩ]v5V؝9l~A`F3*Pw1WoF%l1M'^Sx^>o/B/#u\\qK`T 3pw[ tgk;=a #떽 +mg.¢10/A,$;?^6&M~NV˽MUY{H3eE9l6zmeY EӓǏԕ4#7-\{IJo.E2UdEuZuF t <7 Z+z;[8$p@tk}Ϟ>UlM_)a OH_Bŀۊ F8zЦވ=?}>_ OdQ t+Mgrjԃ =Ҥ?`q 4 ZM3H?ZCRsSe̶E]=XyJ f9djHHa gywK  kѨl 1Z(kGavXH4D$ S\S:5H:HH4i $}a( zg>YqZ; `AɉB$ZC\{쯚xI@X;fl4MK>ł!psv=b&=Xv3+uJ(F9+|A| /v&RwκO}*uk2M*%A9x\M/@nF|-eL8]_嵖B!4!e~/mt[ #^l')v 1=@3ITiBEkF;}\pY<muڶ4!ӥ $ NtAtkMD؜='xi)@c@ֽnCŨGb9B53W!b~PAD'#i]{x6'yYN5睜}BC J l<.v1 NMPrmXl!d9TN;: `;,JY_2Kp)-FaoFMZC V\*HvumTSj9ş{nh `yNVS=\ M_bof!FK_H*h7[jmIԘR$\8Gb)L@w.8S6܏76 Qak>d_cwUD2;>0ܰ7Ls#ɉ8Dڗ:=3`B6Ң5`*$ |,n0==YEZXmzpNq, 2dn438ؐ琾 tS)bzȁ?Igŏ'YNsl2T"u:&[cFDe(p{^J0,&;k X–ь:g;JC{J@W}ͦpGc ӂ4թ<#a)Ap-,Kl8ٸ^Ab$3oL?t}*}l( 0;KCϔLj=<^?>pXqyKdv&q)3t؆b ^KWR~ 88btt̸S9c| S;槿t(;B/S9Rn//A.C~`Ieĺab)]-YHgP9;s[;_ 3 tQO_VjG/EӊԸ[Ձ""C#bPb!`yժ<gJ,Ć5CoMq`P]Ǽ]j&!wc66HM?n9Ziph=iz%^vL)q$|LgFmM,!iJC{Daw8xX/Sc1 yR:5Uo= y&bZ-~I,9Wg-n$޷\\<)U _4m.F -L˕:Mb3 f~2vQۚvǠP͊\߇ImB r#7{wl.:[~\7/.bW634R-2GMd Drr#n"g,cQ1p3(^N}Zy;y^95S]VA02+PRQ1A;H 7_ of( $nReJU8({1S/D6@vF܃wS$65N 6F*ġ w62WB[x(K[J eXlyʽ.$ϝ~6s"pHmgA)4Gg$־61qp ڣn=OR1$i>&l/W1ӛ3SW91?mbܝ].3 /[J;8*Ȩ;c#T2Py֩ap E1L7dp eҰ1k^;5 $(~0WڔDLM]̴Н h Jňh"pҁQ6[c4)粥gi3ئT<0aGoR#*S>p~׸'iyKTަpaZAD>ivjpQN^Fˆca~k^_ղ&/F}5Wh|#h:*PoۙQ?τ5#fME2)&~ ~j聯K,Exjg:zC0)6)HP2DM#c 8w ͞/(/}; v@ Ms*5ߎ:i )'E=ܙOP,1dnox=mF]9?^55Qp@>AfkNp8*ѕYv@$hw.1y뾇cOkꘞFkF(c!*fZ QUڼmKiZ>Itӵ! FEv}Ndц)?sF)'>5‘|ͮ[Ǵ!ͿZLuEg,kQޝc`cwwJ%rm:Bd&o?Ţu~N$:NkMsFE߬^༣{- {4՚伾'l9ƈ48 C瞺~0TɆt$oh|vU;[M|=pG:܏mSϨY;/-h7*nչAYώ%;l'HnLaa5n,d{Gu\{ FA17v.7a&c]D*?9F;i)^w{땳"M`"Fa8]sGSg1tyk2b{FlqR-f5:OBΆ1+%C61m`U:]L XĬla_)TQ7<n%q /ړ=Eal"ґ:+TU_oLz VExm R3`fWyxaG۱$JƌRB4̩(J|O9 `m⧗S{,$I,/ +пD`8OC6,;x뜂2Q5/X0@#|eF,@"` JN6)NTvCd*OFuezpRweuΦx2uVRF&X/5 /"DJ!T? Qw 7{(^>4Y+ݼ,=\KY]=˴\r˪m"lSu e~z`O|J$tQ,:;Y;)b[tI(ͅZ7Ը]zȓk‡Ӷ?ZLfQu3bъ[^庈]|O'cOB*ex ΆM^+2 sG눗zZC jd&A ɾJyiT]OC%CÇVwS[\_.g2 l~ /Jq{>c43+>T)LmLI_N΀Dq4m,pbgt7p)hKǏ38e4[ZdN^\EQGb }21!O+\s[qZ"{$P]`B n4`g Ń_Uu9EW\'@PZ1pG5B}ƯY%GV*Rf-OEsZ rRy9Ir֯4/CP̉ˆcGL+N @hƟg)а28INN83fhLDmQmeww>_"|Z|:iV&%fzDƀnÑ f)uî@3 y "Z_\37S@p\r_5$-?Xh+*ۑJ _ŦOvأ$Ulj6Ev֡Mzlq[QQ\c_Z*QDa\H/46)BeOJ)1?FgYԩ`ê^Xd[Nf$ݥ]ⶁ-\n.q&3:r&W>/"a.cϟO.gFib@*`cu9=dވP \Co$牨)V3QaSkͻvH ߬r`9 R}|{6ٵoOl -f92;z|Iv::kvp2CHr$ǜxzqKy 3c:mc3t"hoc›u% UvTWOTaT4>#y00qB-)3vTrm.Hå|P\ #9/8QMg)/UE|7"ڟw͔BUpYz`fI` nX; TsHَ/$t:6[ e҈UQsK#xa_Mj%c3cmDiM)8x(xZFIvG6ϟ{߭I$zdJl4d IB)NNG;)f{eĦG2:k0%PK61& ,ja橼q$+jh"WM5o)pu65(,!'>e' 6<0rSfˬUU;-hXA@΃ESvdPq^Tڢһ; Ы՞]Huy-޹ҵ]Y>n'>pkuA,ΨqNKeVѷU)kM8v0V34z(xj (=VjNrUp5P!:TO]]86%}IW8WrH/ ^:pJQ>>HLd,=\ЭF:LOF,ZV܏& "=9 :3d zNlգѼf8k(L'aڤ"=bx_ɧA"ciIƜP݄_绳&?Xx-;y `Ry~⺠-C(j\ƍO<5MP6H+ e]ާp˨KR|Z~OD[!>M4j:ԓـ0fF' BUb|&)K w85g14Mk7 b @D/E6}#|o1mHRQΎDF>sSS3ݻpoR8lc1g&7?Q(Y y`_l6cT6;\qI$.9[@7 Ҫo&[p;8nBt4|lۛzE>ZD&fG vkua2ʀȕSw_Bm:wktLn6{ 0-=l̲= p]j+:cV<=1^ i_)G=)({O]t- z\oe/?yxҭIy05؞B#H("ڱh634dK8-}4䭁ҤHr-֠.x$?'UJa4Ai8=@x;'*I^Юl3͑RMJ1O%đl((_sô8NNhGXDn?Q(fpaih6+ILf`r-nh,~32,}RcI:2T8 o}{EiQj̓)l1#pn"QHdDfJLt^%*dV'޻g7&'\$ *uW4K;pC@wX?TH䤷/=6 6mf0Y d;+;~R  ’ӴIӅ>C ux q]cCMm_JwZĬ’2x6 U٢?I+g9{,5=mmZ6R%$z%vAS3 ՄuO[WX31M~j\"5|ODS5'97x\[G[Y藰>׾=cRr(}tB7jl6"-h] =G/5|4 돃@]@FS'JTuGRd0⦏ 0Pܩz0e;|Su Z A Pu@bd9pxiD9j־x|S tBW0KeTOI2hPɆRAPҎ I R8x\?mM7/f5BȂ}9ܪ pYE<~RJa}L XkjA?&%?9MРy8K:gBw0{ȘLAgյa-8 )uę@hCv#asέL)Ͽz[ҩ>x} ; QYy0X,V tq퇻N {6hmי4""a倚pe 6` L1tgw\ݣY!cT)k64֍EƆJLiJG>$~E*Q з5rv)YrXgDB\QdgJ ppְ ..m;lh3'Wuc}0Њ)QLXz͍ QؓM4TYuZ̵W9m&VDZy#/b* "Qm hztᎆȦ6ẇհC<0w}V<ޣ5N!//-=: o$mh8> (Nn~.{TvY/٘Ƶ65RGTE3?Q;;e4QgZPZ>vX}~~(G|\q?u-*47ŒИE?W_vBHa`B6lsxU8<:͜dNKոvgO)s¾sMW}067R@`uMu[s^xXDW=KއܮLf.'qtg\B|/u)_D?{|<[뉈x9pST%3eXkP(>T L'EHCijT'tz%bXVꢳ6L%_o%^yq7le1 ? 1#gԠ圔Do(xMHbBH,meL58{gWZx~muMu҂dXFxfxU1YX!'s+0e@DѻgDW%nT9ց V)/[º4䒬"q`5 !K `}Q,R\'a}ҍO 6OϺO\wY(g4Aj Ƒ>& Za"Nb֒[W\]w5(~ag`ZGp~?y6<½ <тUlm0<jM4N`T ^ UWJT{JC^QS7N:8$mⲝ3"Q̖2utDY&r!h:MȄsy/?x&*вO|s$鸞ruK='zd-w&Ŏ?z֤?ڛd[%UyANTxf,\}.?oCf}b V$!W;%4[5ȎK2S)u\4a%;夶iފ;gzXuc)ޝFȡS:f7t6oy#Q*,B-Y.{\].X聦. H֩ej {\FݓmӅm,`Z`X`Њ3oŐo锱]qb`gՙ1{̞j ܅!xpr&e#/B\D؜} f_ChmlUZ@mcf,Ƙd 0N??v#(^ؑQmt"Hm0s;8u|t5 Ks$Qꇌ>v7<_} 2BN awd n<ђݖGi#zrohIps>ة\<&O% y*n=iLPAX\0B8?,O?,-Kw^9̓4飼3_@-ohrU N\ V/?g1y$bLn%o{O=h!Q_oE2c;fQHחٷJ? F IAg8&g!&)@3A)bM\ަW;z8ti5}M%LjTǢY_TTn14%(ȡr+|R·"Aѭ.C6k}msׇ^e|E#,7;ÌK$LŦH N7K|"F&0frxpQ8 '<uNI˭ E9MG9=+;pι'|xğGxwqoo69[jf-LV,wI[#X ?g8>@n=rEҴrUojq*fɰ}WUj}^ 3i[:ig+Fwmҧ7Q+)^cK~̏]xE9BŚl\K;nm܈!ryk拾2ex%!+!+\ 4Sprso}i1}s>׃=:1q2kO\N7kPB ] Bp|1xv IˣhM]J.Q254sttW~*LKw٬7VrIx(ezUjljWķx3;:ZۤPSx:LLzV٭2fӋ*5|&K[I|@ Q X?21yo_Q!CWͤCr ^:jkqWrui͞ASBt50E2":,|7 V89D`qLjwDcg` k\>=6cQoˮXsŅ{+U3 {_wtBoS5VA\UN5oi3a'swVt<%zy[ 3%,lr#gnYz\ ɖg}&so f 7q,z_!tJ͹Gn#Ic'oͯ]K '?: Z{V`0CVMݽÈs7ůC}K9fXr ' l3mEz\{3$Z16u6$X$[9Nԕ#aB7|8 &ZoCYhO <3!宻MNNP ouXX2~}ӓ?Ң` )Y4Ĥf}.EE 7~i-s'GP1ώ#e:2T+PJ Tɦ@.%y'd0wCݞз^|>nߛ+"Xߥ& {‰X'?nPf)j!TI#2_z=1l@Tgz $\^8GŪ])9&8TMˆ'jlZf(܈mst("CZ@6;|+ i"r'EEwۃ &J9]0*1KB2Nsu<"U 0,g?81}y7T`GY%~KTTcx՜1qGc6J\8?&Zsn/+ f*Â~cL ^-W\ r`#8vf$3jr9T=9Sx IH<ӟB_/]Vusuiw Qu)ԁy p肉?ڋeS+Ф\{UiYcly89g;cImjyqfcuA 9R_d/ [AEYşȮN`"P8Ik 0M꿌SVF'F 2z77{ZT|ƄǨ9,/Aq޴̵n zz(-r..BzND ʱ],UR{_D{+QE kgjø" ;TDZ{]+FK|/H:3Ws Okrn%qjWB,׬A~Ji0XgÄ5-9"$,a჻zx/v1RUI#$?kcY/B¾f9kMQj%ՀS$TkjLdHb?\ S-ǮDQuW$Pƿd@ nկNXK-!qukc$?Ka.' cɰnK1}PDQua [)BjkЎG_J#3.T|ɫ%4%\+ҭ Z0 n_;vrkrY? d{?b̭zp{.kj +3""Fg lհ1Hxm7UU*wSs}Xŧ B\vdPjc@dP J_ )БǍɘw]vZZz%X/9Wl$>˝xKȑiIP{AsI =~{kJ -jn:H_OʤݑJfJv4VG{G\a>SMo0 J+d0l'49KÍ$5 0KS5攲cAпhzeR>ht)п]~ 鏘t UȊjCuMO!DAczsIxx'IXJϻ>q;'A#,\Pr "O $*+6n%Z̎gFQ86R}y=2(ZO< #D][x|9{lz7"XM:f)nz)@DXȷj3Cn`>Q!c Uu‚|ڒempbyM[6/4{wVi݄2^ ٵLVrLQ`t9̻rxqQyckQN9n&3;MΏӎo }9ߘhfU![.puYC|L!&8e6j[*|l|ݠ΢ `W_߶yBdϾ468#4}Ɯ{ @֋xsj&RܮR򓶇TA)tHX%4$H) A;f^Wߖ[zsɦMo$u^j+V( $M"pV3JGᨶR!`ؓY]ZV]&w4ufZt5EGuis&ћbvXl ۿ5BttY;..BA㍛o֋NO ML@+481fŸ[j#¸>G`G1=*8#c>*x?q%|:I]oKd!?SO±Z!ޓ{3,16|r_drTt4-0[e2s*㉷doj? 1dž?ʽĖVE u, ˁd  d:{T[`+M))fyp  0VL=0cd+*iE,h[۹Xyďl^?vYS ʹ^&ݵXxLwyh|ZWxjn4Uw.z dI}L&V{s_>Y=,4Z'iNw8rIR@B[ ml]GUsm[њ*7|{6BZ3`g>U٩dP{<6dze1q+jKhL:1TcaV'!ZgD^72TfG䖽0݂D'if @-7uab YaȰ1Ҕ(9cŪDFcӺVRuߡNZP Ix'1ܥ@Wt,$[xeVl}Ĵ<\VFQ<ϳ&&b|{Ձs6zV80=iΓ'elmXk<$eaIhIM7%ZLr!';AwkҴ (w@,ϰlK5iQd$d (b.͢  0>V>@FIGj>a0SR8- W;2x]6IXYjVs1T$4>c 1'|%婧'e"OoŊ7gd67V- *.6r^=ζYIK,q e84O `aa]kC{J8?W! إסLE_߭Ifje0G\gև.?pu<ÀFwSrX`Iz0[+[{=.ިcRq[qԔ!6y;?QOÏW[jޖ#DjA/S\8ǃGhfH9e|M)fn-^ >ԗt9^"\FM(6m$낳Xw[88J44|3M\! >5ք0wC]@Jqk (~{G }r+Rut܌K:v\g(mjN86;QF$ћBtyG2˅y^Hd1Vid{O77|9 `=8' ~LjuQduX5cz"[2F0BГ}/M ~7kS{Q~'rJg1:4# ]{a?DfZ=$7TH8n]AT\m?OϐԺOi V) Kl-Q+z["Q޴}gWؔt5w&A&v+ݶ]OQ1i?Yj@9k Y 8OU/dMT5xWں߯vmh%Y[дXj;79%g3ǖM8AFڢzp_'%XG:4t>:$o gNt4e$QinK.F3~BrA|D3ޅ?_J8@PjhM/ŚACPD\kegW]rD• r?;7r/Ǟ` A#ռ! 4ǏT=EK(+ %g6~('%o~AZ,iJe2ΒRpWg?NU Nޤ ՘ ҰC`-,c41 uEyx KlD)7,^7*ү2{nORR4ntkP7]~lC`nm|ɠZZ 8.06ȋ_֨|*"my2UZ?q(x54ۍ N}Z;klZd,`U;D5/hOJN RR4ҩcaESr]C'hVA\2{=*d! 3 /$ˇx;Z8Nq&#j%J,XJa4''`=9ŀ߻9[7@9BWq{ 4ZfRZ;.*Do>kc×]녬?s'1?XaѷKij(^znI-mA-ȩ|f~wNћjH>& >q3I;Bmov :Ɠju6 DԀ@HnךXx[[Q| /v[T)țu~dqD&#_7]eٸ(25'?|4a@fZчcg4%>˫=Rl$Q|uSAc^ )@n)@:BDdޣVMZW3، Au9-|<.ͬCYaBy4i\Lmb$ yKx)%2x-FLBuGTC+y^dwXҽQg\0g1},ɖzBI`u)r^[WS>xLco==ssgwA@)8s3 e Y,G I"owT-&-T:2üBez~6,sX`[g,>j5+(R ;^A#jt})>!I&:^o|0z7lpXӑ%v+Uj*7 U[&w=FXgо$Jv*hsZ Sc Elь2@^ٚxฆNa}өjɶ)) d,ICIz]{p?#ܴ(\qHԹ9٢ĻgJ]z__~~Ppm~p3Ǹȅ-ɻ8i Y|8qo0٫&=dHKC5k !eK_R봮‚j nCwy/WUH>+㧧2/!w?<"lLPYM$bVs!rcY&T5~ N&i2-(5fx&kl agC}[Ƒq3n$Ef66vG9[I$ Cew=Ia.j:Ž\2 EqbI4ōS;7-2 ?룎 E.(Bj1!ժ|⵼lJ^y Z[݉ .ʸxDQDZOۄBpWaեނ6O0,#5>wE`;l\: #B|;֟ q%Qz5|Co|2Y@SWnWq[L;H&B 3)Uճ% ڿF⋃H`*^bMly(aF;)RfE}'Imo| ɞP\y$'qZ(NH57`cvSl"HPn_~1%uwjղm?^)'b`Ó>ݕO6wKebhI;|&G`Ex,@.s臥CD-F-輗s9Dt90,FIn.- Tx vi]Ȧϖ1?tE>G.LSl_olwnap4~9!2h7ɊޏYrج8#FHc|r6MR=3/pYE￞vz|K `:}8Հ"Rw!ا"-1뿏1ɷr&Q,ȦF1{-Le,#<=|]z6mB"l4#bZ[6Ģ~ڳ~8 Tl5oo;@a!݉҇ 4;!bqs6{e[Aj Og@[o዗^`z ;Swi 9͈\FBgrz|C9@#GZbHJ@}!,cE= dNmqy|)[J5cיɧnt|GNщioJ! gb_\)O]N?LlӉl7@?1[tL26qKb<:$&'Yb/۪o. :ӱ~]sQiFm#0KPS~S0,ꐑb:p' Q*6#uI p2B=> -m3p^7୶K\j+b p:: )7<n3.W?5-AuPo‚'VKXu?i?T}3 %[jYSmi0=DM~ҜtwTj0S`1q o>[Iy"atBu-1~!WĈY93ژjwS.׾4\\b _~((f+AtBM?*MK~k̙4OE}.QJ\^÷R5hiꩿ{͝"D:[B/!sZ:m9 N#&G[0J8 $)kh B90KonVVwr =Y4:D<Ħ»Jjf:&mFKTTuRݻ8!"CVk-QTv|wUT&ELP@<51[JP6Uaiꬰ=; @SI 2;5j͑^k&W 9;b_=5hdƯ9&wX=c+!;ҍ{Ȃb4B괇\"N3D䃧Yߕjk; NwOmSJiI8{cy5<9*2 _h[W هXw}޼7L`9&bnՙE?|YEhX\Ь{8QpujF%Ž~Ozrbe ۢ g|2Lz^rD*-QxE|5Xn[:mL"=j ^“b MO ˜$ 질 q 2 "($7^0Z #sYv*zS_V](*@q.~Rxqen_YY@k nIsZீXgNJ [Z_#Dž`~fs3د%p9˗f.cm\'RQ }#a}Gϐ_v! {GQ*'3Qɗ },vuUn}r@a޴,r-NWLa| Y T"*#ezFxҒS0W>4~ O(P4 5V dmHwx'K*ӟË>!ꛫtyCLg7y&t&U .8op`dB.Ż!fq02T$t] aN;9}m&GEnçS}nU@ I*|6,Մ ȑݦܷR+KѫYbFm$ʦy׵|3+,I`'+`{8i>m>2VxNQE`Gqw7sz[굨N50PJ]ίZ23b]a<;h4ug!⢑"DYafD~ Qc!#}0dm_U)l/lje?tA|uQJBY2'x3}Xqd Rns"jZ~W8㸛D6Qɻ os?K\Qac@-M:Fgb4 (GȨhX ceI@Vg$7$ yřԈ\Wmt ;èklCu\Vʝ ER6nf,Zz0*4Aj\AYm3w jy 82@ cw1M; צR$)@gk$5[`$}`α\oR6ZEwA,"1 :DV$THkד?G߮$~}QT R.CsJwOi&/HazumGp>Aҷ2 A%./|Dym#gċðn@@CEܕ31i0CP's`Ya.BW i3(D[)w0M#*2>w油^R*zB\o^ ƏJ!rhGO\w3_5`|eEY BڷG,?mD|Vݲ'i+RP8Q< y*W4dZz-=cMTʼ*pNoJ+a} 1Dd^z/4 g]{?M).lta9M"~M%HF+jU,,],Z MD 4aq}x[w]SVr>52w@(S^2PTg}=UȪ1 5VX iƐ*#M %O_D*ByNE!s ޑ] >۽VQ'Ilb2%}DTL^F)^L9J$;‘ZfPQ+jI5r#MI9.N{1L bQ>Mq \t`ՁIAqu0E.+r|Yr8j$(E8LXoxrYS`Sl,f[Ab=/x`!; WY[_L=!!bވxIUVmWn!*nX1u9خֱ'e:)?0.ڰ*ejHU!)5R#vA*[vHr!!y<,KB}&:_r硉p 񎢸SQ:j>poL9e702pĘ\ҥzPyT80ai~"(RȽCFX:riƱX"%#H(c%n?&x Tov]pr:B?qR klw֗rhs"ELg,6= >s&+1\(W<9*3|T񑱽Tb:DXFzà\XuZD\1Ɛ{"pOޘylgR&r#2nKa_٨gMaG/& UhN~O8ME! A;¦Й3N51V=~(M|ED`eQ9{,zU9UN-'@Q2erdL(soɳ Y>naB='5]QjogHt8GZi+& 4%jЛImY\8 ]=4VGDm#> ͈,&D,GXR\w:])c7T4xU`pEչ!Ma(C2D^FnbWr޺aޖ-Sr<Ż)bv~iy ,Q4~=5,qOiJ{FXg#8+-l񝝻z|o866FV`i ?=8Բd$Q|!JHui ŒtGL.t"fJhv*Ȩ+\ߍ>A1]Ոц~_ɟ;J)!>[ZXV * SxBo8WăbʶV>ã~g$cq]6P5'txKQ/' c1?K]nmꠓ@*3T_ĚVkRh{]{wB^S7uoUQzO  K '*mWϻ_]KT}.N w읬9ZlFɋX/ërlY]U$h-/M0kV%zh W}5_mă (zC=)a'ۄ Y,JlDž^3!H b2r!8Ü ?@K>;sHvi}11C;U߄t]\.p ]rWKB{8G{25 y4ՃE"ݒ)voƧ52p~|M*v]x ,tIi"ٳg.AyKw{}ʂ"9b4D#^2#IPxUߓ!)pɒsh7^ ?k޸hfE? ֜NpYjdER:$;=Ebd-04Ǥ7)nMYbʹʝVi\ 吩&8W>cšc_Iw'`l2/d!NBNjb1OL-ՍOw(I.c;@;sw͏a;3t= fȾs k㟙@Lwgb P>Ŷ^>!|"Z7⒋fن'|Xv?Ҍ7Q;h,/Ȕ&>YF%H{9ìRnv ?;")?v6yFG?zXPP5$caںOǐE4={y#-UG$LG b$M'eE'U:F6̇J>$|4? A;N$Jq_*nB[쿻iR:߫%u =3ǂtQvA|^(CsTNQXCRg>YoJҁlρѰG0dt+d) ~Ke/K6.VhzQzacv"wU6hyֵ'Eh;(g>Ka[o,^ NY|fcY& j0Dz MP.ove`y-eYI nUt i(nr Qk ^ay7P:>=U]AKwæQ_bo#uf3vϸ*F5gcc$0la 緍\|+ /S{HBYEg!eoF!C0(Z$.ҘsZ<{|GU7 :GYKx'}EP\Y`A\`XgxT|t3]$:s,lf|e" x6'#dbhS,Rvg+?}b{(^f~la)&RN&JDsY;,ZN&$*e'}!UJLe+O_Adwp`{ V4ciߩ10KH~o ]d^J.^n n "L#NkvFqFه1x}gARQvY x"m"}34RFpbu{#Xvi$,&\WT3WQqz$nhZ2AnZg(O,CjF1,k>M,&@!JR*W[Tn-VZM@F3l.xD!ID^.jLrs@C08氥Y-Go>uB nq֮Yύտ=N䕧2tsFeg}CZS+r–aMNc(/u/L$]XUg9ǝl w²Jns%Sj(F:cVZ+mI9 cぷZ} %[LcI#Z*vivQ`4UJph¢*ش$6^+F$7 YPPk.Fh+T3]?s3K׼wp4ʟ;SG/OoӨf!0iK҈U8:ʫsd&KquCUXCa # 0:r_qThuf!Wl~pM,@ _+ܧlO\y M˗p~7| bdou|5q)ݼ%=lW5lc͏-lݙi M.I QK'X#rX3oENx; )!7?I!T\JTs5ծOCځSpdR<`G]boLܧށ˴8fk]-EqbƎ.n!]c 'm( ŮR9[[Y=~+ƲMu|?&T+r5[-މi<F9cnr+|5q{j@pOhyeLz\t8xbZ$Hs{;gVrtmo#ja\S&f ]J'}0Վ+|+|u ?VP'rI֒ yk>2ʓ]o =Ц\>6Z|eSښ$PTE/=W 8׳یaxRen!1J)6pӃ~6;&JCa-`Kb/8xڔgG{.?#XIcK;޾?+|7W)GV. [amCD~@h<:D[B\׺-9H.sy2 L AIcgqU|`;D3uZDևAN;2t{~ESo^uϔK'yeWE&`Kh~2};bh'>Rn6X z`n]!r?E2Y?x uRՙ)j&\(C;4F%e .. `ws.~)tz_KYLI0]8oo0D*զrq#Y-+P&ᇟ(۠@ɃޱF˿F5d(&4E>N虸1%1e&Fd- O(n *a;J}/*\R4Nx]Mt{Ѫ#hpDz'b+se (q1gis/QP'aA4_&Fi^ٲ|vXv/ɉ[D7Ml(ptK@?Ͱ{,ٲ;:]9nwq69 U,1$,H8? :Dh;*!g*L#<6hIP=MyOw4/M ܢ%+X4C 'z *U]N(gnuaLsK8K]fk6iiYIܝ+k`60 `i^PLf-+GsĥKvSa Vz",R- s7O)E6};Xxz{݌s{^^ih'Rڀw=A^!gn);O뙅1œd;7KkvWA>ɒ"Qv(iWXpJ 3cp6_3` 9qK$T#rc=pZk r . /L8ҳ{)Mb"ִj5N0Ç$kGE Yz1J8q9'ՈLU&>GqݻQk2XfkJ<}l_~x-C.=1"hR\@U&B#} $ch5#apYk[ZqCAaG- EA z})ӉV-`bD4)qTqV[%QǙɢ kސi^ VT|;byUQJeYkqmձ˜Æ[|+xۓ"e8@l0 N xTTYQQ;h Xb[#4Zs T.u}J_{I|5tZg#s(lKD<)&VƗ]QAQ_/nknTd76T,B~Lu£g7]·C)vߥٚx)+pD$l7~۵a͝Ftq(XrL" ʼ=uNh[L!D c4fBЎI= ~-YɯVnKcg_."K^"u}F؁%.,Crz߭IzgSSd'#'Sť֌%Mz$"Ίȥ_R$fJ:s[3ecC47g_/ 詩3jdKwt=򮔴N˰TuB,^O+^*9^~X3HTrGtiԋhxx06FF,@3Z} "+Vl_Cg)|V Р@N)J-b{<c|>?ƾlUHtd V wՖt(}èإn%wdN΋Rm*=]Frd+vrՆ%GZ@o'^*fˇ9fOjUF82_KEې#/٨ _Kf]X8V qU`-3#>\b ,HrͨK g''h:Uce$l>݄RѦ J|bLnc_u회Т-bb`*&2⍗>bc/Y"1RzR)&>"ُt`lH"gl瞂 vSZt֔TLѴ"bDžk-DC$;.01olMl&IHid]l0*jc$@d嫇ύЙ gȶ]^٥8EtL/{ܘf;Ϩ W!Lﺙ%xLd]N'Gf~kFO.4~3m>L5ז-  Sa@K'!1S㍎V4,LͦAf@4gKQ$-?SSf\Cٚܡ2xOTh ߆0 PV 3;N;R:<[*n/ݽWQCPCpJAnU.?k1pgOY8jo)hۙ]̉F}:Udqwnk43E4NVސikiv*"v71~ vvi.G@Bt#)3&quxrSC:FOA5Α]BzR;ĢGxܡHQʪ;=IE_Жp㈶ZVj ayӕ}e0 6)#-t")}I^0)ظ"~8Ϋ=۲N<L}B~,7\J aeyG,Ь %쇩~IUSQٯ$NgW^}$_f9䀹.8m< F`ֹI3)d$̾+hKVhR w%lL4|;a6DŽ P)UE64Ղtdiad% qh)hl)iv3_ʟRXîpr?H@:珯r;/5 1(]}O0uٝE9 5B}2I]! >_TM<ڵFCۭ٠:x5e3P tKaf QV#tÿܱ^ʝ{b T%"]) 2"B1ڬKټs!7ਖ਼R5})/>glC#B!.}8 qHv]id%T=u[t+IH_K-px>=33WJT/ZOҤ(qdI2N".) k9rx_.pXWrE ZJrUhiXOOD)i EZcCK@?s@Qx槶Ւ[XQ5JޒGG],nx*I>")Q: TP`Q5erdkM9x&K64rz8,s,d <[~ HIN! eFU'm)Xh֙1UauwgI+9HvTqV" C }78Ok(# t܄ #Ʀ/~'VtHIan:۠Q9 _f*/$ˍY,Jc f!e"շZX]{s?QGpa bDOUsk}''Ǵ:n?L0x[wQ˞2[d4U PI!f=xE u^مրEz(boeYaeB+'Mp_ 㗧TSIv뉛jy`V z|< uZ{/3v+2GK85q%[Tٰ覨[/d t@IY̛.Y0uu Į.8:pb=j"Lٌ4?FljWWA2*9u8ϓCoڜЩpL?^Ij &. ЂTg_~ЕJm(eDxARw!fmEu )#?M>[rN=Y2 ;X4֩\TJQ*xTV Ao}]f4ZL.]ǵKM&G@qcvuꛊU rnx?kK`@Fgsy&ՔK8ets[Wa}'zf{w!J-DCefCty{3 QPB OtAe`Mi1{O8¶QbQsLZ).A].3}4ڬ숰B67p<|r'@']"o[mCMfbUֿnNj\sG~+4F9t{|DPl>Nu`N񵃀k1[#æ*/!uxu=ȟ=%.ELgVEkW{ZBǕ?hOڟ(tkk7 n[A=c6,=qMF)O|#!f1jZX>Kt6RVMI )]oL"4/,<Ř쯻)6WTSS6Q4@k7C:?Ed=hē4AA -!f秡 |!Zӈ kƶK%؏pH+oP5}} V,^mՅ>2{V:;ⰥKgX E;utSXν;(r2]c_ 0P?)'޷f6P-ȷaD CCͥZ\.Y,XQG •"a<+S7WO'Y71޾:![s 1U9'Le"8'+D븑>60L(R`zQq to1h]1;5@>3Ѝ|nxZ=Wni 6\n! \$'R-DF?kkK]Iz]p4!K oȀS#mQ;iD2yç*C;H+ L2s$"?tS-^+xTt.7 Ym_/ @5TrIsOFy瀨5O7~J^ KǔۤEٔ6);\)3ɠ.I(ȡ@u{l.w4"\4vv|B*!JC*mV Xr9PWI  eTqϞ~=@/ϭ6՜vW{7 pz(N6'Yxr#j>w&UG1PđZ 3*{\. } SS$;/opKTz(d7uUG\uq-==ȂtxXEiE 'S=! ؞fžv:]dž87S Z/VP>F(ha b)7$#?CR#\}GqGo_?Vܶmdu 1ޛ\riXWpr#>/oI37[7dtU B;/f | Ɉ4odT/1Ofr&GgC.Ik 9 :N ŮXPb;2 _}K=xMhA2LnĚ~0E,PY\CmYAC}m:BR*ON` G"L֊rm͒:ni}|'"pKŝV9 )P)04ur ^n L+:c݈66 眱JȸYx=ؔo+ׯzkhB1/= ;k16UY]=o.TqR>ᔨTH_]'A>*O܍'~C d,еZ\;c= d=t 8r%B/~> B}_ ee:`0y7Hi+=ǤHZ0Z==;UQcVW @a%_9Nlc=@&Qf : QXC8rT_h7 Xr._=X$|(U ij_9k72Ws:E0 |#& ȉX@ZlLDc8s釽;kwFJVog\RAx/sObơ)ymO,L h/ZnLGAtf 'SVϓo׵6,I,5Y{>)ֲ^QQ!;ԭ?u Sg +^fo|M҇vOOӋR?x>ˎ{iUsxLA~xCl!^3:1tA:p6xt5 my`d Hcyf' dommX>`-R w0Pi 聲\ueyIChJlM_ ;xjzi+8iOAK~!*vu%H!3Мo!u|,GE6(ɀb{j՘19O?Tqǭn ?m0s&od&lN<"Gkq۫G"KiVE_]-ZYYCe[[4o)ۗRCS={z=wRмY]ZLY.awr燌u鴃> '[PRu({h{NaQavFz^r (".0?uZJ]'GDa׺8c/RA_~4#y1ALGڹhU Ttșdby8ZM4hyIf8y WĔ'<"}o@"BR3a2 6u9`4i+Bw,UdfU&m\Jss&Z:f.U1uKVV|4\zB^1#'M4撑E~!o?;'f߿4gg'R5qڝj/yEԸ[z '0#҂ 3$zY{w.bB96;`#lK̴ 5Sz;exQ0͐8CЉP l >N(7P)_T/1;a)蠐e&ϡc$ cf7GBg!`I0Co(h3(5a~ иؚ9 q(yG AF4:KϜe=?R b]z{IZ]~3%a'QW~  S'D(b_.7 P9c 4{ĢWN>+8P@#'i3^gGa$X9IVs${:HҝY$5dž:7L223du,d1XrshђÛv&vpy $UCÀ8  c̴-* o2jL߹J.<./md z(w_p6HW'??*ȕ=S!gȤ"V'\ª%9ԺSeujlC~uJkpFr^*﵉JИ1%z1|$,huv(ǔ4Vf;q *1ԍ!9]i4P ᓫ[Wۆ^0wÙsد^w2b< :p{xhb49R)N2ȓ]CoI@Kpum|puAH.LgӶ%SРLOTu;TM_͚ t8N:1DKGSVqCKAaw 3Vkd纼]+S9qOy_̝DÒz($n?Hv͵k'DdR^axAGm}-00U:M7#wXƔǖ$JS$+)oRLSa< 0FKDA6!z’>T#a n V=7xԬicQy24-oɠ+L{W'bylޱҤh$=4XM"”즋XOzr"sɤxIB4IaJC}|.cn lr;2E@]kb&0.x6~l"^ wD(hƼےR3D9 5H(?tns Ξ՗{~y\ *Q KB:y N_N P"Qn5L="N(_\7}g$99G քVXw5hO G-D@5aUer43]f뗧*=7e8z^ʵO=J9؉Ջ tG"sj͎uJ 6f >D<=\9h^iq;zMd?ic>S14ӊQM]X7%<p%o G /ibEX ̘2 $LHᣝZsc˷ *k 0/Fpx?Y3^}iCwÃv FkTxZ2ӽ;ȇ/35O 3!;_2"FMd R]nKvr ԫhWօgVX3-DjYh.UAKdpji A034]VZKAsπt+5)%,p@.v,8 sGXmȐ=Ds$*rrjZ)[U.c gz .JpKX 1WDYѩ$V+ɹ.=+ve \H̀2ބɊP8p^QAx'1nlW\Hvj_d"үhhR.q=tDmE;*Qʭsޢ~HNR p7u96n}{OZ&xͧ?A]Z_XnpK6%>b<%YUY6]·g(Jx_4}g N|;wR鹒Wa5a^F!<suդ;mtpӊ#?RЦa PL I6Lf6y+=JMZrFw;(Q/U,Hx }"YgU&ɐP,8\4L)$HL֌gb}gb"%/@8})Cw$J35jEܗٓxr H4RaRxs+զЭ ~mÝHjP@WIE kFVֆf'd~{ Bp,d^0Kna*ZD"҄M.ݟm85$B(W@6\_Paḷ,zױ$,GFV~pXpfŏaqT)ziyTO b9ً}ٚACcթiڀ}0~b`zXQ J :KeK1rKE yevؚoDpHnZ!ؙlxl&pv9:+*E U 5l-VQ6$8 B*mM{L9k2 V|#6<[lV01nv-qcd5! w)ed Ks\Ø.c~{9OwcG"ٓ29:1XP{Z ब|jGkW QbODZBh {QwBp⏛xPƜ ~Q MdwQ:*>ϑc19”ɺAAsDB'Gqib6>nt#ѭ}B5 0lid`WIyQ£&DOi˘KM q$O@B/Hȍޚno]2ެ}{dH'ZM0mp:aim3{]ȄR?; [Z=sUc I Y`/,\@X sPm,(|r Q>T;oEXyEwQ20WrF/M%Q(C,M%h&ړ(| |z7^.'(}E50[**1eHU\ Z_:O@Ưf\#9ma3# 7Gqt^ Jy64^ M-ca`iUEL4g]fZ6FE_lAۇ?#:ݱŒC@q$X$4!H|*]M?pF0[ޅ^a*x/]-I$6QgGFEO!O! :@SW* ,)yQngÆw;(܆!#;^ꍅsv#Yqo*o^gk08a4GSH[4{Wi$I(u(K<-@{0|݀|Q<5:R⃕eG&j`;SU%Bl+7wG{&S`^Ul3l )ԗs 6GY Z_X#`YoGejq P>%Rːh篺S{5=V(>bkb3fyH([;/  6dWtq6ol?闇p+M=cިbuӶiC7];+@4yynR>{p)H˙xKξfUmqf[UID_iE 4tĸí$ӱBh))'yV J.#hPc,F#9RcdY8 k {hh3jJqv.Svuca;/` W(0uue(E9w!a3QL{8OaVYDf} J!ٷ`Q\vX'!-~w[sVW ~՜('vT 'N *DA.jkgClm< WCx5' ń}+8ӪUdVnw !1qN4Iu§E4#} SIIQO+R+#[!H(.]Yj#@>;vUEmHLk7}ApG% R`UsGyA3qK ugSu4ų_q_>QLI&9Y EUR{u`KK΋\N~^\.(e<_0>i KM`k$XQKPad}x__| fZnp(dˈg3£Jef{:JMչ856+DIH<7@BGYM2>K~jvP*#Eq(yg۔o!BAgI ȹg:4Pm43htdCBI(G!aaNAֻ0 !!3;@C<6Ar> 6/^[H4lw(Loë ?EʸTKNR%פ&2KeٮklU?T9xo#_ aism y> ^!LV~l[x b_2mXp}9d{g_5T^`1i}5-4CZ)/rP7;њͦ%u GH˕ 2 d6T%S jffXBW3ae$u4G0=ܟ~Q*#biSsϸ5#ߕXQY7C:8w,Mof>Eitpu12p&`Fݎ&OX5+6lM+,7zзI% M$[tl6Q~yB0;,nZ7,vpLelv1K8-[U[|"ilpuF -G#|_}Bce!Ru&)) (L ߋ`k;G MȲߞ2ӶƊj9X;i(lC'`3Qye6LoOXI)/7vϐ9uʃB?nK,i#/Ru[x,áɒX1=-Cu㧾|&͛4a lN 30CQW ^R2!]c -*լV ; ]QHbb"Z[D%L*,s荮RW8_y@9TLj<`Rl\5LGM7Q$ A*k sE~x)eHi))!1·i lܷ3Sc3i0ځ=ͳdUz185`adLC& ᧯ʦ};!VN% 9(g?vvIQD4|0#l`*4/W$,b Ƿpq,T/m^Wy\W/.q_1cSl(tk[WZ%M| ͔3 -~55 jk~4MZk-3H.9;rlDN(q rd L-K<ܙy~gf)fWn=fmK\;U4dץ!/B\ ʪ3*AZqv9z#* X x~cT]h?Avx[Q ~R1\5o37p^hİz\q(h /8"e8[L|zfZ\̆u⹝^椮|1xJ_)Et.fa^$+ԋ>N7y 2,jtXá*N3/Y ޡȏj~7#!Duӏ@(`0Gp2d>~O7p`[F'!ɡNӥB>Jkl+\gv9QZ@گ<9(_du@4M~X/IA{ٚlA[ hӹOQ:z[m.($m->dӞOxVX4]]޿Al )XCJC쁮{^&_mtH8*Er4y6GE%SAB|HX^e]H$kh Y$[6VF+x؟ "IVfi3iz;「 }dWcq:q4M VhDNЯxYNfwdA({>-j0](56َ3?aiTasO ;a ͋φC0օ MvX^Uod?lߎ˴\E^&Ȣ#G_j}?4d@d>T\L>2QbC'/A!OJ;y0-c^5nԶ0~7ulEߌ _@"R2hKe͇R!`x _-M 83[p_X6Rrq7ߐ֭lrOc̟Pq05mPɰ~,qr>\%u*g K3sH&hwma Q!irF?ox;"p.!l`G3Ur/t4w'$WF5nZ7mE~YN ӷ^Qݾ%UQ9a'.YRtgFWFțgb预-|`qB7N>89uCjq~6.rzJ[}v;5FD+1&qZPSe4*pXJ B무F^8f%URjzBa_ ]6-PW}ہ2*OF_`vK-Z7 el\P8*-Kg*F_zaq>@H ,m*fC[J a=ȋp$wՀ<A\Es`ZoGQΪdR^S0 2p sdNX^e|&O,<ʥ'. "/j"MڞJrYUq遰my:E"`8g+F[H(g% `(\LX:Ǐġ*5|_>@ wp@am3*y&Gv=J8inoĩmlƿ~EKRD9Ir֢c_LB8 9Z-Lr=PKӤ?-G~T;A!`iRE+0՟c0ꚸ4{Y^19 /b}.讨YL h%e-3e/KdyeP8cGޒgc 4cLe.G$ki$ao`:{GK y Kc?>)>R YjpJBYs :б%h!ŕVKbFٔSƒb{˗[iPn`7fb?G6P-0Ayxx**#ӣ2ig. jۚ&XSwڐGz!F@▅fH U4K] ? c>xeWtG`?h ̔^u-y#9ߩQ}~ۨϛkԢɮ> 2jE Wۥ{ffq gFYJ낈#ֶԇnH.i3]mϱH[mW"2C)/u1{@`\˔kإ~S ^Dtie|{Uwyv[Bx|kD$㟽{̦"IU+)O=wOK/&E4u(,L/ DC͆Zs=yh N G,ܘ%B'?=>&^=ט%< $2J=F6tQ0I`+qImrT 4J>i%?XyqD"Ue*\X&@ wGϬ=kUMJj+NX7{nPe('-]2S[S }YrMhAʤ^.'K= W'\ fI 6ȤqkĿ' dx==)V7Eݛֆl|9d(V֫ G4y9:.ʁ3+rK3_Y zKߪܯS3]438[{$$2%L}XjptCl;wJՏ Q=ZVL7~Tf[H&NY98l+WY&z]ym%(7.\}W U),5?d3}с4x}1US?Bæ\ Fw#5_s|&S,=с#ʰ@G}[LqC眥'b!EbfcqV/ hu}?f琀y4f9e=8 OW0TBhm?rbg}RbS!L/j\#I}%KvVW8{{~2n,rߪ%CP;֤tQpX`j3+&]9-Ӟt5i nA V>tx`tИ*185j|Gӵ_ eZ0v[ lh>Q%T)啕ɹp!ˬw ZhXO 7(tQ<n(/S=AIO[5(Sc@c6Nc+L!NaUu{&5YΔ!Z^)|o[9l:RN5&SL72xDi`UӅБnɗ`%kS@-'чbZ6}!'y/ id)so%E3w`kg -׈L5TV]]*sZ oL*A, ("}tKVcMCA'0mαL/_% }O~ 9z?M8z`F3U[ݻI#>b8{tߟ]cFwٞ]#7s]s'.QL%yB $9? c";#4b1_h(GZ; ys" ETS<`‹+3p "Huå0(c\i'\ If@(Rp"C 5 [pX32%{nz̴1.ZU|jB2Uw❐M"M mL ]qcK;|evwfIAup!)WlE+Mʫ]F'|]]y(!_\G&Xyj惦^J u7OZytީ)HTh,t|c,ʯ%Q!-.dq .K[ޖ<ɸfg<"_}MItv|+[p aj3_]È Fhݒ\Zb j}'ehz >tW5o] \X27(׳ƾW:spk[wE|t=XXdG^1#LH8p>B0O 9=I2{ i#B})F L2y#*(̾Ea":7ַ-c8=gyfAvq0P!:ōbbYE5_+HXRj}{JښFDz_мDg߇(OKR{U>$WhVaϑ t2N&pCQ|%ѷ efŒt`#~CKK;A݁Kn.Rd"80etgMcLCɥ,K.BzS颡K&|m#|?iwfp^q̎44yt0,б_p+D s(kuv6+'#0^i`5tD t(] 2r*3G4wQxx!Q@1 lOo`oMec͕@`/.#@M|cS樂qDUH ]XP(/96JBK.H5v5/׈i;Adو9cx;ǝF3e9xzN nyuό{ia5B& 5 R<)]cqE]R|rBsɪ]ľH%q_Ӥ Wa{𭳔#J!gMz"ZB9zZ4;HH˸ Į̀ lloV]z)nlMllNU\+q!ճv{e6 eCySTPϡIO>R5c1`Qsao#89ew4*҄^4 j0lMʧz?MEOm̘gL)nwE "p*$A|+ŋkf!3'[:|Ǎ^)c`?X/GfmϥڐKI2d ^bQ8]ۚ/ܯaVL\0ϛ$ܓ༕!=ߧ%8g]7*6 cnWK-KS)I98hcfօme#SŋН~҉fȡe ( d%RByoV(`Z|P}7~QBgJ zf#jhg.6~I҈Y;L'Ef[J1ۖ ueC-,jJN8 NL3\mFM{!v_#w/O7J'a(զFKqw|#o݉ftS̴ B4[AҮ냴SЂ(z9~{.)7-:.on.&+wlq!ø患^op6hR l̑3X4:_} obFmҪ̀_v+Y9>2מ']UTĵaqL>Oe=́GM)s7mT^tYW߭ ]Kr+[sbŞ+pFK`Likф&ݯ0ys&9ieNOVIrIWHn-6ΘEtrˈ0p5M`چlM 6FQ 2P3_< ,ٔbv1Yso'M"!KرJ&=-?u*lKY?k{}*IխAҾK Ӈ J"0{*"f(^Ll zB LVϳTaK9VӐ6.JYLUI9oK"NGLIv;W/~ BQdAuxR6Mq`(_ ܈W#80gDKEŅ\Bg)*ajMm0.RVkO3BCxckoywk*"PaebW|E.]&\<-iӷ']SiB{0sXҙK u,&3*4쾧s4 P9 *u!v %M?f H@\;^2nܪ}0> 0`>" ۓuphϚn5iEɤ L^9qq{f;IO~$L^}yґHstgu(KTWo.WT>j k?E+ŗ:jtٗocD}oX p[bsIBWmh,|Aj7&{,=Rꀤ<*҅ڀRy,٬:z29'Rd|l=lvxRn Btjt$hM7f LhZ]r1 7L: geʲM kXOɓ)sƭPM^UuG /5| :FnE9 QW*#]$SnjWW4^T`tGt.G^䀆!*1?HJZ6]YGZQUZ Slȟt?dY>ޔ_@zp5߄&]n9Rs`䕽ǹ4K,⶟s։gi4Nw4 sGmLPػmJTpO-t9<5 `Sn8 ^!unsY{eV%{&٣(H EeiۦŤk,b:Tf0g$Oӈj3ݍ)UΣ; dZAZPqR־O׹/FE]zVyȳTa lNЩ>UX ۔;kګ*RG~N}.NI7軰pT&XY b, mQ&iG >ss,-js[@?5#G y* $ _yy|?.Yxs.8ȕ@ ڑX)758YCp(סjNnt@ T mvK^&\5.'W;ByUʓ4Y{ᄰR?ՔB ,cz$ܥ:<#SwY_;GhN ׹\iIkKb }z߅7ةyxub]+Ԫda(K+;QLF ]xZZX~zOL&+76 7^$ r^oGoy~E\uUQƺ$j<[.C| K2SMpXӮc$AhΰCޙV ?C8U #vK_3yZtdvLm7|3-zoSt7*N5%XI\BYQ7و]NÎbRߛR!J%srb t uZ) Duo4Ҫ0T "#sV(~}SvZ|8 tЩWLmeuĪ5)}оQݷ 偙ZP1ĠŔSv5]\#jg|7Xݽ "Ȫ@cf @XϰZ-* .U] ^&DuJx@% !2&1hmYϲyT*b,@KͲ*tZ5jm"wxܺwuS1ktѮw&2r,ҧ-v`BqTGp݉yHqA;7M\aTʚqi4un)xa{VWc$,$M>{Q9,RkP$] w  !vF=𨺹\l 4]GtϷREft~y'ڊR-.(6W._] yDO&V|Rg5 "9 Pڹ qnh'DhwtPGvIFV k_KPw;YDh78gPr&ۨH"QLTrXXz g!4k9- zXS̒>GEi'l}sx'=Bem_۴Z1;pb+1J2%D:u8me{s$tTD,tIK=T7ڙZ;+V~''Qdžqwp 2RL2j UH.gIF t 45=Alj.FͶR3Ćy/DU0o] C=S D O(l`ngKF.M*6 x~:.^N%Zfq (ߧS:-y5u L4`ٳ;ٛ7ynC0&#MW/*w&@EzxL4zqi'ѹXv}w2:egK\2bT6ùtg8g=f(W Q q3hu3mrWFihT-\!@֞!Tbop;gytQ/v#eKLg 9Ő}A1eЪ{By{ҥ_Rb\tTY7Q.* bJuHʨU:èW"ܝ@$A2Лt7ezh5KtE3 ߝZOҜ*ĪYfd/#t"Eeِi X#ncbe_\jsh"T"RT@"wGޫ3jFiS$k7*ٔR)OQZ=f/(}WVJ' I'+GG(N!XmkOCޏ 'M.cϔs D68*wەT[F3K~ x{%w,jBS\_5eց7Q,"'c Aܓ;OChi?Xb8Ȱ7eJ(< oh㮩2 H;3U tn{;JkmI1=cʷ>V 'Q~d? CRae`kdė^R3[)ՓJkLzLö6znkӉF5z`XN P`WD *"]3pD][ꠎ wݝI9A,<>!hƔ9go7ܫS"{UФXx]P,6\0 8X)+ ݳOߧ'[N)z5QGNvp 0$-<n%oZ@5#sR#[/}m"8ƠK/>E demytXLlžOlr/g JC"@]JfMWJƑ/«(*_?eKM>X%vZ b7Y‰),^Ct,[%>sY7Ou3xpz3S}=vrmypiH=˵GBE%Ldsq|'k9 9eAlTSӷNX x?oA%Drߚg7& 7g}`'N8& Ovr0f@5`o=hbtRVt*͔( b9oϔ5Q[ւ`]E# 98;aF|m=ؠHb,+ !@{CUMS3`F`@\2z:>&-w{ٵ)_JA]A166{qEuY9N"X(#ϕ (1x-;Ų"fz\Z-جd:0unKAbٟl PuXS['B0w^aW^ p4ŬN)ϴR8XtC AQWqL8l1y$Nm \RۇaSsɓ; A[uH?j[+X\:[a>j;7nULv ΀jK@7:}K\5A635z}ר/Ē 0@p|L7@8 |L/mL9q#=p8qbF%Eل쵠&p֤wv S^ UykLÝkE}@i)XS ?)Bbhph9:z% ;4j!M1V L%[_:p+z519?ݿ}ȾsOVC[Wm%;RFj$<80,qtCcG0i) F泭)z 6@u$FkV!B>5H;fиa꼎}V f]Rtmϙ~Ӟ xBbX %; ݞHvȩ_Hb] ;]!` CKE4x9$cU[ezvl0z &:6\ie/wR|?Զ`7) R+;Fk4rJ0嫹KQhmr ec7oзyUջ[j+^~s #lrX#=6q &ҰiG5 Gp;ʅZ.% EMGD] Q]Y4rY=Gn|L&lex%E87DN_A≫D"Өb&D2`39Ibf}YSVqVz7uzJ^]!'lSN ЩDq芪w\qPP#iOǔ+\m_?_GhhPe}쪅q=,R_:8e+cVΜlrjH\F漛O@|Td@a4=SqĬ8ՃY',Lmy cz/m+_5XrvV7oil͠HԖ6uhB )QrתIw:(ԥQMx#N_4+6Oke X t1~#1u’SOA;8e dZbbwI;!!1ߛ~:Y+[[tem`킱)$p&PS :a"X:~ q0xx/XQ@Gvbd1&:,?OZf1.2bq- f`I /Qd=y+!w92vHE y|ǎeݟi |.tzq~8cz H}<LF7 >j &L^jec#C`AQ^2 б4ݚqЖCi4bٓj0 0b:;e7ӅfR%:GA)z}LkGr,vㄈ-2og詥'V g7N][?>țra $:kzWc4S temnw C!Otvw١fv~urQu`J!*zhj'*Ȏ ϟL# `vf_E- QkMbݕC_w}*aA("]Q>*TXF$Ag=qh:CL!"7U,==i LQzc;-uDp:ׇg; (t赈w-k$k> !k;( Z ;>(76FK#O%+bUxe;gM;WEbR#.q Z{Ӣ0=3F0k7xbπxO~ϖ#Ã+jZl 1K4lkjqSUZz}>,`b#;;F3[q2c uKag8xe,\^|5V/"Қq"L,z>V/ޛ 4xKQL c~(atJ #FFtagSd>ǚl&v5fPҿ~w=^K 5j;pQ ڍt_Ƕۭ'Q3#ZMh%5)eReo.y,Ьy㲒CD$Ǥ;";&et2| ٠.wr,By#n^OX/k=&@r<'XxJKo_bTuz\w"LF梡#;{bV &N%A@ġ^=c0U&L:JzYqaWa6y!1G.,.lV3.#Q7ŏ;v<_Z~4X7iqi?7 BǬ ߠg 8hP- [pt`ØiDonn}'SM㜌%RL"oKIb;w!{ [,:y–h-zCN<[{칩^78{\ҹ#9-H7XH 05` *=E^e4{@aϷ{n 1TB,0@e*8Ui `Г!NG}iDds0 =S1#W;b#L:WXbMz}|ca9pH K.5"ufFfėGH,_A~Q7.K0KsPFp6=/Xci()5*OP̺AWy˵XDpqiW]U˃>/ImCߠrj؀o\UKЛC]Јn{j`٣[<6EE!`#]R3 2ԇ< }Gz$Uqvl#ʽH%rDc%I({^ P K|qML?^R?RPvrLO_jcjw7e}X%QEfP=4 ܛMXr@w&bFxuY U!3*=>jrc˟Bax\fXf)痀w#~NAAW(8fͺٌ҅j/k8B_޻Jտ&yHJm{Ah#1CkJ9D/O+b YITHp#^_3Iku53Ee7CAt\;ngxx{cQ<--.$yW?ec*[GwJ꾖'IQaXJb R27H:WeO")^0Byy7ޕ2'`ڥě67(zǞYHM?6.PKg\&$$(e: ~26֢#{& lZ!RA3{AT)뤔Gg0M;p!k0H$Rk yeTN}KNl_|o /v 'uHl@ޅ0|jR櫼ux"f ^!nwoFU8EET*.* qGe8`*KH#?/V1*q!*ơAlћ.R\jT:~ؔRuh7+_{Flm[4{/uf@˅)Ar.Mi/?>:ǬL5K*LAqC0mU@k5p%KxtŬȲeQΑ`dO8³o5WL)#C)X 3 T!cʠba0sk!Pg+JBdz[Ճ}m+))ZvivB*C& +1Y62ch\ͣgeYCM'["f4?d>T4y!Ѡe>sr#3^F5%n G@<'&i}+0g{F2'-xٶ{_FZ' "+JwG{m 7Qǃhߕpt|A҈^l!Eo˿"ڕ̘H{5]:p-8x= _%k)s8 B=UXEnTLc,Bbp+4aIz/?JPk˭w+4$7>XN]v\yuݭyPbwJz!y|4}Ubl]홁/*3Uz*R Ŕ+;tXJcY%"5UDS"zL4OU('?c6:Q!j;dE9wm4uwz/(.EmAeâ pyN"(dcOJA:xE"V;(>n)DKsP̤ z3=#J̟.(I~qͱ%%ԕ!o3RyYOE[C &KaC_F5ZҤy ^Ѵo\3|+y)`o=uȫlEZuyxgؔ=(`Nm~$[)afah@ UU*" ## ÏI@6S|VJ~GԕZ#V/@ A`;~v`=qؼ̜3i\c{\!KtQK;h>w#eV C"@vF qO|t<p)AJδ5Oc M\ A(LuKs49u(LHqڹEz&3m_c^nrp؊0֪1up(SpIV1}TQ^JMF;[t?m)%i,e ]rU*:>Qߩԅ|}iݓSZ›?옎+98J̤ZKjTW(y0A>A(>uB0㛆%s3CЅsi|łFlm%z w ɹU 7d^,^ڞ-" (haP "dvٺr3,.(xqC\{@Lf/D(baBKstoӋ(|(5`[ bl8Ǧ_ǦR0],V&me~]Tne<#ׂ~x4%E7ZBJ a@\VO:~Qŏ̐NE, JwvүN1Gs o ./uc_U Mޞ?˶ut?Ϲ H+2RqIT WΠ/rj{?f V; O,Pb I+m /t`Uʆb GI 9w\bJNأ]p@zrgZ XD6|EJ@:AZ ;Z<؅_!xŭI~V[%􋞽]A|OR5U ?_=~`΃XLGڞ ƇRRXqB~P]Ksay?𝐤#)'Ud_G0505"8?re0NH7YU Ai lE7nyiY}7IXY+[X#Dn 1SV?e_ JX)I J1SL5_]"|KTj>o+ӼBQM{܏%.{I4S3v=!K~Š,"$9/8u$4ymڑW3fn@t(<Z&=L ^}E'Ȟtg{ ̉Y[Kts;SG7ێJx֖i(V W38u->j Իεz v-JF>)4IiaxIJ hl[Ch#Ԯk,muUM(` i70#)H4:(*BMF0A+&a>3)^-'h ߈t}gImP]IvrDV+a9k" ̺ ^) @"HldƩVGg `JG9qO0*^hfj1h`v0Yv&{^Ø%$+TȗwX7[%dmm)*kEUyyC[;Kމh})C(Bj`2x5)PV*!F|RKQjnB񳗡[=Gz8IQ]͡-Y2,N?fK pdhix` !eN\^ܼK}R_>k5 \õ@!ҵE헬ÿ}~XVoVar;&)b=0#"[Y(<4.!I$캄 5Lעhn=֋'')P:@zQ_ F v3$n+l:@ 5zSm#'uN![vC٦7ʄ 5Ol~fe!dD[E)F` bKUڏ0$P%=1Ƶã ;k肿B~NAw6A$o;_k qRc2':?Pmkj{3%dUT~͠S̴ڷWBsmRQ( mlS//jZ3}󘑁 ;~o(S/JYHH] QBx W/{g vdZ~ z8 !%u~UC1d)X -eUOyr/M+7A)mRCdiS-1#g{LY%wüG-_&T vz{qb:5Rg2e,Vx!̸SVLsvº\y0H5?u %q_XNЉ΂[ow,bx?|B(l=Jw Ynɤ:8M@ !Gv|6$#7gJOP_cۆ<?HST' )L[R8̌QTq4ŷ߽ֈqWޝx/SZÈvP } p2GT:}xԸ^ZiRlWnut ~'85"y.N"& E-lE)j~gR/i+.Lj ug?e"x_H |{b2R&oSDic(f)~W#Tp;(+"umF>RaS^0h:rvL`4USdzh5&g }Tɮaׅ!|>Im4^t@ Gey f1|ik b");CM2'ͯ.L R'G8|78uA4k^j/Uۗˁo\zZ0qP9h8&R |hnhEv瓸 `6Hv!7?h0̛vV OMDPw54B! L?{]{Kq־قאQ,+x Gp?Mk6Ҵi##}5cq+o؋ĥi KsHc'v@*΃Zc2/ SlWSxs&P?;zBl ׹pq~?jqRT~Y!:}CeYFNrXKa}YMrHŅbZ!"\Բ@Dܱ{ؼy^;:Q#bռl7(08<"UE20֏Yth]aZjX:kz;||z.zeWCzX]@!aE4;pY!⛶uTPLw7>ZVm;+?k7][TI2uw@e1|W;*;IA&\12?1hf A=Ah*GxN($e|ױy.mq9|"CKhM]94S-U`i,Z;3 [?~R+qq V@5n^S@C ^[y/xt+7qĂ D'0n`'{g*_" REY`%L̏xk΅j'ȂGaln259Ar~_rl1x#.S($#:}^**zB^s*mMyz8@K1'w_hjU4}3{< ( D8OcfAB+ C >} {_$́4\]ߛ_aò 1!k0iBߚUAHؙ]U>UF0O ^ "hѾqhDgPs{k*]%%F0['Iӎa0}jCwM/}`IBأ1g[jPU}<sb;bf7oD=N/Cb+?j8"(-]@zNr#\gK W" bwKCΚ {yk.bڜV5w-nٙv΄Qc)m1u\ʆΧ0]3*6vY6IPdpjQ#,.6*D^}~jt̺Ӭ ud|ݰ5EpM{80%jt TE(AW{;$,ƃ%ԱQEسNy@3'~gs?#-GI^Gb1j+ÄggJ~`6mMLGQw {/62$$%$wB&wX~v_5S4IfrRDA\m%hKTp?Sqvz1Ǫ'Ƈ&S9qgȈÅW7ցU`)oXusR(jJIzPf}~o }i{}tRRifL֤ LrudOmPM= _iYH,\X8t(jY>3_oBZ}78Dhǹ g%A!# zvfNԄ'&rj1l,ZMX);EއOSu_39\()E֝5a~hXL S7U;2!bLVҦVrFҵt:I4W{)kόB2޸+WӬGiapzɺ0aiﶕ8sJ|RZ): >Oe[V[Q'7  ڑ+ד/q7 taFPCq"&Zp`ΆK[*> qN&# |`l#b*@5Tj;%40P} !w8?'uڛR\D.eoasߚ-AVuʅȆ |8?80ES?Ձ1ټdMT$B:42}Ñ5ӳ^7ב K gElIo$,s ؆r[c/ h˥0G?DbR[v5zVxa1qi]'bwnXdjsQAhMwLC 2g|9S0OWY(5kuB,>yXdg3 Fro+W+}4B8+\ѹ4ԎXIzj)xq: ֯e©. *%نb;{N 0X`$my#H䴊c? 4-pn۝$%ݥ{6)m f8}XD[!`Nc*7ts>c 0uFl'bҁujd*mОQZ5Ugbs'J[TIlԲI)N+qI?"XNR˃z3S"JIbFJKՏ'U LxaCNNW*)-VOwÕ: 3 v88ڄ10Ϣ_KCޝvOTR&/sOJEdFT$1HS&O|n-S] 2q(R&Ob8ÐBϬE[ 'A89]@ %ѥ?"8mQF>Qٹ}+ᮕ[nDuMΙ5pƇX.N5|Eޜ"7%\MF|Άl"ט `f vq dih{%Zϯ.Kbi'ޕ_7yL@5r#GmrUE@Ðb| GmykaZZw'׎–Pj)F$Yx#>D9S.M%t 4?Wp$C,\gw3h(f.PT{PVߨ:Zг `񁰨Eg'fk D Nc%Xdzf{4/kCd_bCRPb(a\I|KSW@d@'4GuT2xѫꍹC "+7+qr ~*dʌ1r›|AQ;{`P6M A0IMlGAVN'=ןrt色v?K-kQ~1*@| iiCݍ(;"&lo8_3 .I$-n?Rc&3Kn:CҒ4}HncUŲNPOOs%&OVWKewܫqopJQɊt^d0-c1Uǖ\>0 ,!݂.r_lK ɽوc'3LXZ-`\-[ kp$!YѐTNA!Du[/e  bB1vFNzgH$ FO:H:Ť ߃ lxEC]$\:0HxO0G*ZVgz9 V vl2A[fi(𫔠B;"To$%K]ÕA6&[una+rUb @x}VjH#wnκe$li g^\$|=gyEBG&-3)}RIxC8b}tBXB!>I︎'jzBjQLRdkZX}[1$]yЯKJ$ =+ez_.oyf"yѦnxaG9^H ?9p?1@qd瞮݅V6#~W$̍'2r>m3@۩1r'E>q]hL*+WP1bsвz@C :)aD ,4QjEEޜ mysdrtIGؓ-n1ן/~#]-RO15뉌YF߸)KD& 歶0EEF R*80yYz&RACfY%:oFr6T%ˆ`Ev U\T]uC$f{b8d|$W^_.q\Xi;*gNk 3xգv0D 8\ۋ;0(Sq/̂6J3v&En J= eȩ&8JtKl/ËRKزF@nuPmkeS=xxZV+3T(a`~fүu`~ FKy9y_ZvJ'AK,Æ0*̻H@?*>͚HJŬ5IiffA'\!n?[QVLЉ3n:33p5h #m5:Arxߙ1 P(UtrZ)Ym2ȃuIB?܆r mbTl4!}94%u obl>a 'ϒǸEVÚQ^ٷ8Yj龋ȥ 1a`v`{@Ed "d5vL3HWߨEu~T=zb$B%1q2{-C޳d d;#2J(-ɠƕ!]_40;$؜1zZ6Dj'>,|0 #jiH Hlnx y!Nh\9xFeU4/}KUOSTŜ,ȷ=K612N+f/%hvJs<2[ 2y?]}f\mN/4;_o1ԾkN[{3V9୮ U6w6RHxWsUk-rLjT ˫p5LὟ!X@t)Vl2io8,ܒ$~y _Q}d YaQ˕)(*=?wF=B UMy}_[\C\ޓ^>Y|c89c#YP"9-̙)֬ހ 1)!#ΕEo0U.6?WPr7]1C ΀J[I H'ˀe[MZnoi.Ap-䘡a⁆ȴTqI iJv.W$"/2AWLDJ :987pЀ,-.< 3jfǘ)k&oHtUypn;{>)EOD7%M{rչk&:r1Ihs Z^m RI rh Cit5$1v|q hub9%27+*'=p/9jYF׼ÑrhG%DTaWPG<ڵm{;oB4hЦZ UAfvsϾ/˺M?ˆaufBC𩩰"hAkV'0Y rPJв`P({u룂* 촕 ^z %Ӵ8a؍.eՙZ$c:[hi`occF@ᜌJBv$ kkucIE**.&x[.6n8:fֻ`鹚d9N1+Q 6{]0cdUwMBm2pFpǙ !zfRS'Z0Wʹ1ln}D)z3,֏ > Ag{b+E؃Nyt!39&y%;zx$*ׄ2|7t\8x};bGx%!HΐЧQiBu#?,zJGiT&P{QxUK ﺛ0!:%;A&.O 93CoQ<6|]Qӫ&VANVݣU5i\$r-h14i-W0Q#hv*F*Ia9{{]0Lr}7J}hί&N"n"uǜZ348msmhǬ!Rw2LQpT`,% 2Far(JBzV*>oG ݗ6RvZ].+z}fU3zyN`υ"* rG¯Knz),$fw[]P9?L `W۲en#jݵZfu! B __UlY=UKiWpjub-^ 3hh1^;-<4`fX/jA)lgV|T|-cG^ta9-"* C١h ]L^yfX;/ 9,@@L_yȷ;ٷScIGbҨ{z[Kn=|KCLJ%; 8W: uMn٣dbpOO%]:pE[0^|3 KΘH0#Oqe)+c*uf @ FZ<5ձvYLk%;n_F򍜻6ZFUDns,`<<>}* V k'E^%]oaoEb4xyKW"tr=ԻPNū3wР(#YD'YwO߁p! GPl=x=I'kvRa~W{!ߖRJqzC@î8 ?mNh:LL3Ш ^ rs3(AD̳ℒ& s =۾GT"B{'Wv]W v8ɭO襈 7_u+Ft>$6E;P9 53?亼j vc嫴_^Tg蝓Wma3B\Q(Ƃv&!xæ"115; xϜ1oW3Re_7YN!C6ǀa5cw"4-8CKq >Bq.O%CHoxjvDACVV: scv+@M`+hs_ .*χZ! vUu@k{ш[y}G _¨_ўc>?M+UZ8jR6%(!ǹjV)lRIۿ3P3O17,<TAkwWzQW8mHHϝB?8z# 4'r{u@9ü^" S8{73sOҫL j6OA{1ؾ 9b0= [G&&gR.ț >ű"YBtA FrN=<fHj̃Lz`Th#|QŹ$ln((Zldb)OIxi1jKwZ;.f(Yi>%<: !!gCԶJ&7W+SKL_/?:)dVS3T~Y ]Tìl:$ d!UO^_: f @&I }r sfpQS'4 <LBJm`|>PViM RUJ۬pUO14VeM]w4[Kt9P҇>M7CdENFZh Gߩ%M"U2ǥzW׉*U_W#P["=E!MAX呗X/݄m^_ HeM z2~"M42-L\Z I{d5ym,*# ?@]来T# ZA i'?5 >s |T!\{$lHwI|A!ݥ{Bx k Vm)bl3>uB.) ʫEgT"@ ޻wSLd @X+f*X)m|;2lo!V i]:'CB|'vpPB R$ZQD ?ZYsP3{q 5"/@FX9R(Y}X[ !kTXxB(fJ5e<oE8د 5^e ]w471*0@K(Hf~C ).N=]S:ÅE{?gIQXu06ytiu;0u1ajE%zBY& pFtr2Mxu -^r«g@>R5oP =jGstnB#Ў!g hЁPྲྀ&KyK՘괕_HK0Cgb\[@+#S'[pCꦂ9@R* Œ 1yu Zz$\E?B rӒ%4PTy{Ic?c:}i~!(Y)"5uAcf€$s&)#dQA /+\` TE'RFFc_œxTL^meyl*~tTgHXXGLep6qT8d`4#zB+}렺pl>2)K so6iQL}s9n]'_N+u4ul4Djd.:bf{ 5}qH./0N?V( f';.;֗[ՠ[P~*F0[<;_<`h(Qu1`AmS{-.r1xO\,oү D٤wC&\qyL3eXCpꈔɾ. qpxsh>O^pAf\YJ)Ҝ͐ i ōHb[Ev5OS [Yڰg)Moƥ5u%j He&\7<<^a?cwsW4QM^&Ssw)Wciv ue&ҷJ4l bls3sVԓ],Ѿ%{$euܩNI%[<@CBSpc"H7.eVƨz 5̓3e'Ww3T7ŹܰĔPM1] >:uI}qk^d} ^|؄+L'7˛g![W15@@B$KC@W|L0*yj`PX%;X=5b,ŭ*.w}uQ}vEv.ЮA|z_Ԣ= Ň1{ Tbe}"f:zؤ/TJGtUw;|SҳKs=|tm&@0Zj/Kp%_;)V[|OԊv^#5C26(dS!^ڄ=uZރ5)߳l" }؀IGVC,Tf/OOgAv}j BƗ<]2;eGlSRڳAƍzʢj RKk:=*]CO}^,oXPgSC!7Bl&ԊݘzC,$t˦0QnNMG{ n懋 r{;GKP< m7&Y(ZyŦ"vW\Dr}~f=BOL.luԔFha 9vhRf-t\ތ鱄 κ^+V E_! @`9~x=zեQ;'+ZyKAXkVV!πƘ]h\`J ӾcN9^Vy"LЕqR>Dvt,YRĖb{yPY[7&mVzX1Dr=ޢ)"ySUԾv.zr厈i xҠIR˽ZyUr rOA*lmha@Y'~+wЋbmTݣidr>߶73=Y8K[`G{zT,ȴS`ݩOD;!{\4`wʶc̪QhV$YB6*m97[/i ~+O/;gDO:$!=1}wuخ__t<K O:2v%FW󡅷iQݟw8n~ƞ`@"Acds_KU^z~WW˔g>!J║l Va#CkH[I^=qU 8rC/'W odEsf#3b$+_rnY`r&U9y0)BxFzF8>,&amy]I{` f:NJoƝ'elI%Wk vW-Ң $HE3ojt㬦 _#gju(dw~lzлr3nN5Oto* ;3`$p 'sAo0A^,qPXR@jKSPm&ޞq*fY R.i{+c''+xd.gyܨ~ˌ]0W^ϜZ&Xtע(²[Ve ,PyI00md1NaA j`a0x,k$ӊT^+-]6Q?_U̧5qa >lϘpԜ‚SsXE'#G\$oaڶ\s~eG2L}X@GD[s mE8X*3P|pɡDY%-:XZS I Ѿ> {kb8FmzRPwVXNrZR۫eV(/SHC-0S5%'}RKWdb d {w%7h3.hi UZ)Øn7VT >gǓr'tMpU9/#'̏đE]9Nm4/ ' PuύQǢYb{$9Myvw?C9EIHC. ؎/~Q^%0<oS@.38xY46iHX k7&3{Wcobn#zϭWz#;.>5o;C%V?Wo H,8hpX7" ^Y>>1E)8{dh gM?& Nڗپ wHS UBz N9Y|*S7R)RI2)Q$hNSzd?ZK]-(hfʨN*,4 ?@%ޢ  p}, 3ȚI36܂a #+ՎW䡨ZSHǎ'`x@8iSkNZ)yn{ Jܚ"Ct8d-X+2")tv緱<* t7zk1Mil\R{j'O Vk%?=v˄d;DC!ۼ&.06Yx42OO.ΠokS(#5sm`dQ"[6x:$qXB2/C^{\ma{@<9 oA#J 8G=[U,d K.#c ni]^V.[ G"*WhC5؏W'د7xQv`@ CY_6$zmj rAT3i3'ɇ֗fZM#~q[*,e9 Y76^HF{>9<dk^4!q8(1[~UԀ& ۞u/׽w5(N- =䁶 Fo?bD˴;zYm}4A40c тi'-zj~H5 37AȢB:g"}ݢn Ϩ/p#(?:Řg$1K,WX+VEq4T7?hUcՓzϓՈ?%3y/$RE.r2ud^zxEwFyȡK媓|r*]dl@s@0 4JwU qi`dCN/L/%FK2"ë#{XģȽvH!y"Lȭ%aq |Qvz0G0W 0Z8nJYh{:GM :Hv",.'CYkkSJGfT~~łĻ)|tk.msDp둵m,3޳@QKOqfk TQ$*{'CG4_:@aOr&38%LTR VPpO[Op-ӭGثǕ)swe]Պq0=p܊ܺ2ƆW rȵ`4IA;Eޮ@20K8'٥a!O5,],+XW35Q%Og@GD9 a&\?lE? yYp#FTܳ1h$m3 Vj1)9D8p cpײn=u r܀lC+ h\E~\2활>hͣUĄb">"ɉqgGjeSU>|| DC]t!S3rD;\'MM1DrE=4.Kccz74l},':F qH܏+HaϜ[y8A]@ q W\uni#"I#ƳŨaW()OJ I*~d0(3 AIWQQcQ 㿂,/A9pMKxL,ϴWoKuT '/Yu#<qjyˡ]ATh}3bO_aHb}Fٞ[u'~Z%pDfLw+yu.@IǓg걷TN;>B"-yaE9hꂹwCгR4\~hD'QQ*x]EG=p8OQBx%/%jVWk[t_V>+j l PyJѦ3.LT[~BS Cy e #ɇJџϊ1'{hhmhȔ>MYh!X*?|ED<:"IrPu&[z<.aF/cSv Mq[7s)kskf<(Qw"㬈Q$q\gz^V qMAV7"Z']H3 ׺[*z_Qϸ~J! a)@2tPs%AS?gN F4:%ï^msF*Z`?Ҏ&-8cQA2v*nŠ'k\1WHAX :()Ei_jl+NCGT&;a "$xR)- q:Ծe7^3X<-o8/ak.geX NϲBJחT2AbC`JQlӆꗲM$fXwXRV  8DXHL=RWnsj7d}yԎ2<,u':{|th = =IZ [ӳtz}zC723![ C*8QAP+63d_{y\:./~'al4j2˵)8+j+6)ǚfoU{L}WpGޑsn}ZwDy vbmN)5ӝ[kQAӥ?%sTf6淵d0@<.zB>V.\.moi7^` zTHt/:ݦ^=VZ[1 `v#'3B6^lN FʘDypdZĭo$x8)TG$w$7"K޹ԪqZТ?pb58GQʆ6J,3j!0ghUv$֣ؖÖK!Fu ĖSݨWkۃx#qOaS e4w 7QE:*ԚU.PGza9G$& U"=U21nbyʬxۻs`>!yIe3“\KcvS&6" 4: ~Y"o0c6'7~؈49;j+H%y67Gq}LpRy7N0g %;^ԐXbgS&nb(};_*3N@a@ \A! DQs۪æ@8Vα I$H14UqK[{efc ֍:֛3R,K}lG%ɕmU ͷ\S`D"|ƀc{8Ƀ0vb1T9VFAc#/;t;gzWCr"TƂ+{S|j8WqlU 9ڿk0Nǫl0"JqzFQgUa:[6A޶p1r2}9҂F˛,GGGE.MO6/s_${F;fǝ96:5KaG*9xg}N[CoĒ\=޳͙LSycI._ZZ6ZGLRHf Qzj;v_me^e&pȶ! F7kZSu9! 8JחZa61HVtDY}YWHoW\; S\A[@]#/Y1ڒi|asj *c8L]k -Xĵs5soG8֩opy~>aAn@넣/eSվAW pՂ Lb }TȠJíFs}fD/7i &`7-rlږ{HCtCѢ`\ 3 R>z 0(M$jlFlޠ/ nҚ|QsL (iU,2+C{TMͶ@m4OLrVv}eJ^J z8.vNvkwNCi3;?j3Pt|&1bC8r쒞sfzhGT f  Cʠ5#ܮHEв-&0{(|M-M_KspH_})aUJ'*wdA9(VsMw^ln Vw.Qlu.H?[[4g P^&֍z+W_ߒO Qp CĢo(fٴ,>0j8YBc`/cM %Ev}Z7 #g٦/}$V%hT[jN88fgmM߿\/X|fG'D#g;\ hDwWtH+m mWrMw4D.cRut1_ j,ǤH.Z ^*̾t3P#@D7Uzq) u+)v+BF"*/Qߨ~JڟHISO!݁'Ց!4~Wt 5ow5J'SτSlD$~ePx3=ܥ<ֵ=GL`ٚk|-qBQFAy0)>{?r.U\ud꾭ކ#3K}a @XA7>5B.qjcȂľcNe~%Gp*ᰐQ=۬$OaiEd.4##. W'L+ >J-|04"~C6I5P,Z7}p4z`:ػf@9՞OQB39`Tk&crۊHatS5vBX_c>Tv]BWG ֢hRQG=0Xj7po"1fFYzȼșgȜQAߜ /8*i*G!O<拕ydGo!$Z(+J9.e&=NBR ̋-ƄW n,MQ:@39|ļ{-s"vr iv瑦X* L^9̽2u:{ap@Xޙk;> b4$;b$Jpl7@o/whW cIzm妩=B"L;02꽸S!-a@4(1ZYAFd 7ܿLT7?o:<MPsj'kM~[f7M (3G&-aHovmZh>b?BQ9MH߿0yIś*Ⱦ-͌b5қ\4?`]4ueufea@h8xбyᮨdҪ!ӪTrqid"8M&2p: eݙfzA(OU5˙?jr hΞD'>,r;GԻDcpJ2oAFIvn]>6dG^\an#F-OfE2*3!\n~\R+\^ Uè0u{RMAY~,L*`q1;1@=7=_` 6٪ćI ÒStTEL a׊PhXvx_ SB /B;E>QT2r|-yFFHP忟l ᒓ7$!$:WJHy]%E;`g6.CϥrsiU]3&184(|tf( # ^$oG8G\o+86es@Qz`S^A~GV11—0:-esW!Zʕ;) DadX 9QvuK!0hXf-NŤ56)+#-<|k*mǘܚ >H] pP[о:^ʶ+E<UF0O-ZP+eʆt(CxE6FGanT$1 OvF+pjkVǛdhAȀ$o?=*K˨ AųT:T@NQFՓ]q@E'x [hXx< ℝ%''ɍݙ)_Љd ,UNB3-Y Zul˫sϘt$q&>V(q,Y\zaC2,o9<EÞ*_m@yD>-"dD(! oWԐ$L?kI@@&">`Apt$.pW֝%FGb}gjYܚ騺+}.ݖmʮՄ=:<|/郿M]iAtٚ+NQZSY4[A-A k}ʤ%;r*hRNӯLd*וuqn"آ:0j&0<U,O1CʰDuOrGh-b˨.n-`2Y(R D<=yG*<q7nGmx*ApKN*IUG ^nUP ȑ) n `k\IX2~F Tjefڤq4T(1V7ҁ8L;: |N5,]BZ}BU?mmORe".R9}gȑ1٘B\|}Ef.T= 5thpb7ΥG{rw߮bG_b`bFqSWӴ|rwx7P>nͼ#8e u$Lw)DRxę/O {,RrhͧӁROni]1o5eoNÔ,9q ب-'0gplV&~7i9Y51ɣ=&ɞhiY*\#Ֆ[y^"+lo1@d-cWkl^4*P^yxupӝwA`;LqB=ORil G,?M>̅lAjTRxo",\a%їE#E6_(%6SgݠI:Y!s?M\뇮r6?f{gVoP*ę&[vn%*e m0e\X1 ?"ܯi97D3(zx]Z_'ƪBKL"K#a'%a[d Qchgߩ=QFm) s^IjD?p  >AŷXQS>aɽ}C{G"#y!r),U21Xv@( "꘦3߬~hOU1#HA 1Eu J8~>MV9MO, Ys0*Яdž(~{ztQj 8 Cv/NuryJ\:k$'!J%\؇[|o@ʦ4 e8K_w3g [-%7y-S޶*hW)byQz Ovݮ. ˏ>&=E-ͬZMB>i tSOi9C.hm0yEY5_Ȋqr^:9 !"|s΅#Dkq-Xoo!@t9.%+-BppI#Iֲ ۏx '#I]HGb4"@JUJ;/R*H+E)0Mro]cq}D8j["GK[2iZp{rO^kLU3}(h\kڊv̲aFun_h\$]_{g[إTH8m\"OW]G{OgR+&[o.|U8yYNw$S△lIBXKá\ FlV^Cggڵd̥Cq0R:_UE%ܒgT:v۠3i˭a-f5o9Cp5k\q$b1*Ɉ e\Y(Ԙpv1Lm̼Ki'j/ڙpc+!~`|%-k֢叭\ }s~1'^U1MtqU Qit:.Sr{F^Vt7qŴ=􃓳b8}[#"3d̽0M4t toAsp)x26~u찆9˶] Yo&Ǫ,2X]M;I݋#(GZuI$! u.LivRag_^-E&P<=D37n)wm;ȿ2k':ċ&vobe5Cr3= zYE)UFP5F]Who31Rv\m(v6i.!~+j9ٜArً1S\=4F;~"ukej_,K\ijG^OQ/y}ȌLQnłJo]MDIRn![ãQ-`%z#%Rԛ[uL)YK⒎+Mo##X]8L'K'n?VƑ,6I~'}w[jn!#Y `r5Vj[)D/aJڝ>_p$;ڞ@qqDE97 * Ja~0á5fD,^AŘ!@2x˰GTW.n$NWZSӶkM[M4DksITq '5Y.ms%9ҏGV\ٿO]Tvk(T LQ gdA|}Tߌb]TZ^>P_ LQֶ$ ԟpm*9+NֈYBC!ߑa:y>8_[k [Ѣ ,Q$Rެd M-V65|Yjvo](P7)fYsHr}(#ʟ,\,Gg: Ƈ<$r=q D4'$ѤeMxVgd_ooHi>UlBbnU8*HtRP=k-zCu@9Nû뉝2蔥 2G() L`pq*,J9B$Ao|K8K ) *P7V@ǔJc`E/̙L-Q)Z{Nbœd~v)xp%W9oC"$ -dYqFJ[0ģvSwV!`C6cg쭉fڪX WIVR#40W9HiG{e6 n0=`2m 5*z{[@\-ׯH\79(އ't}])"8K638å,K-os@D`W;G2nDcl;97=zv症5 AJ&\7"Rnh/m>hb~*DS@:a2Nev¼bF~]1HNz2XX;-O͝׺h%"l]P{2;Kr HRx~ t$Y0Ӡ6pNo9]BXBX# J3~~xH^A[(ڃwu/:4C)}37i5,ā{Kˊդ`\b|(}bE,gO;bEұNg#/ˬ8pc cI'*vk+[kZ}bw+(x~k0"Ánm.oB) Dާ(ܫ׷oe֛M=^) #BV3C/;<2\kڻY_㪂V}=s(~`{2th/E.{NY54:@-<o DdPߐxۣ2X8xvOvNNт#fֿ[,},Z+k30w(VgfDxk Q7-F 5t>y=҈?j8g3JpFS0X}гNy`# d }}1fw_= G&=)KoȠ)'t&%wL (*Lˤf9IT‘AEf3^p+_հ㻻7 <>^Q5rHI+1:-h]ILq5bN#FD!:jCŹٻp1w38.#mIr?|VSB_bx 9ͳiC LLjK}*TI^q/{]q~k0q/깶`Pɖ(pt3'{s8Ĩ2׊$ԠcC &i~^NQ r_U &ͻf"֚M<]y6_TŎx#[a ^ńϥxs8˩" }b5*6a%\:OU HL"f\V=Osi4(^w2}M#{ױ?ee% (f+kaHc[ 곀 f? D?K2 ~do óM4X0 S ll%g&uTM\C/ޑ{CHL阨ĝkR& MC@7R K_ "]llڈXt)x Qbǁ\|S~snF-`2}qނmδL :_Drd(eVeԞ[@X ȱ `, FuxwgDGwh1qOhsek8kV~Mmg'_.윟ll'@W|(weA|Qr3yPZa &=jYze< Ӻ-h/T%Nw  H[xw=tӒ/TQse>Nq,>&F } Eٵ,qZBs:1R@Rsw;> "HDϋ) u6[_NX 8ywe @,gwOs_$f{dR_NV֌>1{.QLIך@Eѓ  Z.^Y9/._K1E(GJd䱔6% \#]M{h!c'qL uq:$']0_To}+/J nQG](X߽aՆCTI,Z>ШuZDԢ\M/^sLڪd4H?d%N^ߎ0 q6\U 8t̜S-'BgH}(XVxv^$ K,)VL n̈,pP`H9 mdpM-&@s%MG%,\?H`&/a@i_,ϙ!?1HSs7. #`2YHp|ac΀*젽<=81&iWf*Jpj4.CǮi@T9 ʺT\3d6ʇUIsG 1N8 Ǵ!Ks*Ttj{a[=Ǥ5 v('0,sȗkē2#azVP {z$ϱF_bYNKop#(\B4kY4HQ n_l{ӹ˦E\_[qX.[ȝҶǂnӢ#jBa-uTϥ}<{@3Z6>#)#iX{~[[(t#7wxFo$5(`d7zKfVAUY%JJw%ڵ@Jnm~pA5aΤY')FYp_;H+6\1tvc'ޒm_+ _Rj-<ɃKA?̭h@q=p/ L(?$ fKl׭Q$I)_#:-M[9+[&fkW. nml פ'CR .7HbsZ%c;ҽc!-.!%d:K6$U*Y.YN|W3[IaB\%Md`#^:'VՊt}А+q͝I/f!H4#t{ D3JRYa͊ߖ}U@Ȃ7?t>NqH*fkC5 ⾺5qlx)ȈoPҪ%MIǶ;;TߟyPV_u >rcryP㋍Q UpMrKF7T޸ϊ/|C > 7J|8AiPbK]S)<.F4xF/mMќy;5J砄\e\y !à E~ZqErn%+BMa#y\t`0_YZtx.XZDUlI;t|MM))dVmKJ-r,_A~f^!!H: i??˵R$w"p̯.-X* >jYj˝0'`B6R_z5gSbbm$/xe'f߁~ X%ƚt#eL*/$\nH\8mO)PuU|Aؼ^91UEn A$!2chLoe<$5<#0L2NtV1՚NV\ UyBI*r _֭ɯ ]1t?n/R_y[y8&NXQ"J7]9:CޘwL53obR~- p2Q< V6SyS2z+}'p(9(B5x/\6(lIN ?O:& CU-EWa@0O红\;l +|o1*BaHӯhi\\!R*vU| `s#SKB;8G SxJұ?}>2'<F6AiރQO"5h0 J(f;9Y̭v@UajNC(! B MWi<oǸִu(bbO32DY44m3K|R(&EU+J7\TCL4k􊢅JO/ƦYJ^cV\SY}5Y@%>LK:f DΏ/=mȐzP@?^uXW 0mwOύ;A`Q@ˎ8'xC-4^](ɒi߭{̤2J@?V?Gwp@,HM76Ҷ P1N3aH=1 b'>eD%o[!wi;e:/"ә]ݩU7o<D~q=|у mED9Ҁq9ӵ@dwE'tV0m[gK? N8_,s5-ixr#`{ 1Mh#D>&r&ؾ/0#|a7z וCb"P \mPk6bY|D#rͺd'p EvՑ,+U:0>1YmOQ_ebS~7/msKAƠMdV^Ep4HI t+ ,O20{fNJQ&VŁ_2 /-=b¹K;r9PPG4kގohtҪE =?x!FZy%f tc ”]7w'@yad}?Ӑ .rRob@Ⱥ92˺[hGq+T82{-Z &kTHC-ɞ0IeьƽNcnuA$'@i4ԫjtFmz u g=r?-[\#RcK 2ĉR\9Gb(#!Qn(eh ub`IXn@!%mfx(8`rpZ'aYa8bGhCud*(9 xÝ7*%VLC=-.T㕞PoiˍFgW~v۞7Zo>e9@)8ĽRXZLXV~RdNso 0iĆ_+"`>}`9؈+`T-PȆ:1-x7-,VOu`%VLٟqƲL?q.|*"xó9\h< 𪻬ŃdC2UU{$E$}Q${&vוE]Bsl5B3zosG/yF7=tPwq:^T3{\$>Aw)SWHOP= 6r8sͨe@_  Ui;TQP:M&AUuBmq֧t~~dъ5 RgeK7cokJ3j S*ʃ.Ou/se6vur*}kޱZh'f,^>8ȤI'%tȶ_Mh9QSʿ!rU}~BX)?-]y`,62Η-I2~n7Wpc>fƐz}\Me0r%W3U~*e^iO^ީX#:8#Ch8u8hkBeڪ>zSQtbX-=Ͻ2,E9 `R 0ӫ$N /lm%\)h9j6p[ BVS~l6 MvR5qSNT>|وغj۳ 7咟܇I7oC/3L YF-fA<`絷P~px<6Vk76;}G,5v:|z`>i⓯xa#k U36f8 ˠ\ L?7P,]xH].)cڹ!wj>axŶaieOؾS)7J3J]-Ϲu@QxvqE]W/Ŧc /u.J(H-,ռfR sX:4->!ҿPgߍ 2("i@:QRGCE,{(to֚l$t6H]Mk;Qvm\51'S`i;\)X7=˸>mŘ8-N')/)erU%Irh.-5:j)qVKsk K}ב6Nxwtx|j~|\Q߲ˇ*^eLڧπKޛݵB[HNWPҪQ[hz$l-j p#|CB\um)!g&ȸlZr5;~|EIn4+{YUp=CYKIR2TV2:>ڜ+|X>`YaB}N Xd?qGc;;F 9QpY2wL$ ў#ΏQdH{j[ad$a9 ѾIѾV̜t֌+L%eko |hE; Z 2klͭvIo,.zɬrH7i/ f4Br)z1E)MO+nX~BWʳ쬇fQ,w7p}gKer%EFWmi.%_04"_Cg4 <~e[aS^]qiPJoޯτb$e/+dAs ]*rtnDOv j6 `R-v_L۠Cu|G yʍ.{ w$w^ {- [a|B֩V%aLЃmu_> ̳QE`ls!0-Vq| usr1+n(n2O\WWJ,w*ޝū_lnKE D\)ϙ~/BK$ǂRVR`,ɠ£f8sS<#VGy_`usDsIqNo!Ty]̢^aN "cLDz DTL|NQJ}RHw{}ŰV@\}re,Sܣ]\? }+;aƜ+ыz? Sr.X& $/u뷡?8uW0ޖ.wl gBQ$"c_50XL:c4u[EYycmg^=bPWsR}򗚰3D&PKsB).zYu)攪lj)@*Y,@FJ)M" er qlzgl&D&23Ó+w%z w.rJ\U .C( [s5-35YYT_ayUYDD*[†G?wځgYr܉fֺL4fH|:0`ͧK|@0`jBl#&k?S.r8:޲k][B ؄]Y) $ 0A~y NA8̩֌7Lo=q>\%[Ka\gKLu3zpdcX2$U8駢{{gFhjWy0 =}ĕ _6?8mG~-~ێievgtYg zepC͜ W6 B>wXF`[$˖I'b{lBF.I&&Fn@K޲ _5 >w-&wk3~d_J\=g>0>wOrpWC.t6SFX[U%?5 oJ>J\{ǫ|g8ot^+}&O! A ^1+j1&ÚXoO{e+P *'n h7[7Qd޴@0]b~07BkXέ*[aݏΙ,1RPbQ%{O/k/lâ)@><u- 5̼U lsП|X2#İȋ WMn78S.䗦r#y7iY{h8_N2D+"9 #|LOzo@x.Yci_>Z_3D Sm"oVN;72>oo"?)E<a_5^phiy(YtP[_:1zјYy5/mQG9,ܸYW8T<_B.%HW2A0_.Դ^0 8vilKR4bHIiktIJ]˔7Ή|<+N]#vtzZCLZ9)*g'@07;ⅹH~j e2]; xj;]7|q\q>0$[ބTA{pfoI +Sg& BϽ鑰V{X3f/T +uW9tP-! IO0>M{ m_3M2\˼/3 dwxF5Hk &C\~HMbl0c^'.L)<Ӱ 6+[MdU=URf!5%n_#cb{L Ŧvyϴ}ʅaFN*YQPbIߠ n܆ܡr|RZIp1 UeƵ 74~cM]kރUjz0([hLd|b YMs6C1:W٪9P'4 q-Ax.ڇ a۪rVx)sVE[lk䤍ݳu4Q "}M 8jdM@TjT+!Ÿ$sz{>fO=BnSH䚍}-;In2*`yk5)^[ @m%m ε˜>="TPqQWSfbTM$xU- pINcFa`yM)j&X(^l U9{{;|3t t|/գm(Oщ'Q|q+%${ִ}D<*[g1D isvw0f|nV&P_WэERWrQ~7![LW~wqg?UJMζ-\-aW}(PB+%Ȩ ku!.=ROxIUs6[7lDuR^OT7'q$g-,\kCv o4 }:fx盿9w/! (TU䎵|oT@)I+ٸi>53dM`^a\/wLh{rppGFL)p~S]L˟'btwu{*rW'*N͋R1OWL Ge1{xZ,%s2[d^0G嵲Ā N#@K!y_i9D܎XQziQ.Pv{nRh#gZ6+u}DsYZDZAKOP>0ݘ~K庀AЇM[ss HӃizP1~A{.hw{SX17$Eڦ~v:0!7=Oa T́${k k@MZ>K )BZ kJ+e"B u -~1E$dG<j}J  }X dx;3pf[z[sn=t+mA$s' hqPd8a,I '5g9s:$k/ Sq6znCz (ʙpHdUlbͶE/Yv'޼I?%1vyԀ{gqT8[#Hyo*pxO1h5#1lZ*g}ѪpG2}A2ʮO9ln0%b+-ihO˚S_>*$OJ ,NkE6 %r"8r*`G[ Kċui(ɇrʳ7+L2'&j\~_cf#cժF&Q6QgbI˭6zxʦyue=j܆Ӏ62;/ՔG{P׿8~8Nv lYa;r>ndj-;A5/ehIzfТ|Pz0G@B;wMJ!_2텕 ajZ/ӌj,QE҇F7X Ô G+128`k2ZCJST)$:/y_5P`k4c'n9GKREzӛApt w"T cY`\lN' G%SFAS'zˮ6.I{5 2|!OBKl>%m@X)rk$WӢ3ebIȖ" Ut1i+G]EGԕ28QPa{}p{<[o> 8'aGo#J}F,u2;AU l/ۻQ >'P"ê'݌XWZ{b@@ D5-蟯)\\M5$±V{=˶{$&X"j;Q[ 1,,6a[HjѮ?-'ߞ*i;w"$,FgpFǠʮy#I^1~]In9S|[9/KٍV{SeP! ;V2P_Q84bѯk8h# _i5*B~7 Z7r(@\_o]4uw@~be8˰ 1\L_hP]3[ :-5*{jOR)Ip.UH+YU[Z/udl[Z@6QiE&#AZ"O^ '@WNs/mjLrZNV&+X_qj1}S^yEO0 q2=C22AQW`K/iP{/lM<`n%;jTdpDWj~3JiӢo@HvYOuaBQv5DѳQvG7_)< gdjwE8bHIUߤ+İv@5ë A)V{߹ .(I_'VyO_;O=v~wcͩg1||/somEk{gH[Xa?*: *QG޵B -H$5g|p^ZfX\bۢڦ,=O 4v}F'aQrE juUp߾=s!0ZrXj)nd'7?ܔnzꐧ: \7h҅J"TʋX5W75kzjغJZJr΁T~f+r#|<TDc 7iNo)mQYzՀBUVq#Gfׂ},@CJ'O'wJXSi|^@LlH_\ Uk>55~љ64/ p!f: ?tY0VwJK{E.*-Et0 bpu0xy8K(h}׾{첤шm nS$[LL!9j94 2 o{[FI ?@=jtI'YilRGzbGŎYkHb&&:i.64c=mѭEs(/sӛ6aζEhF9@s'(#-VcbPURp-קYڋp{O9up{>HwyhAZܲWkSi'>ǺfwE5EKɠ9 -UVsjŬ['&^8>b3ҭO5 PP}JpXTvM O«p1Qk QRU,PlZ.=Ace7>j0R?NƬxtn/FS !/2 ^QAJa*kGUTl?[/;`"ei!j9bODNhQ&lWcTކX10rvu, Lu(U2EhC>]i5@;棏k_=:J 9xM]O@'Uq_c_,5i/}?4לڭÆv }8/ =6dk8)nJr3L f W%m@QXCruFӽv,QBBRMmH{sGN726$P& YGoéL˩,(f% D͞%sv'5gj-jׁ :}qh [QUڍԜ Z;ڃMZ` RM?H6&{k"r1-" -Oӫ/ā7FhDVBhZӛ-+;m|N<'ߤ;_A L0 ,u O5Y)b#yAig݊9 q7J{!cW`+r"+ * u먶ER>V-q#TTkȞ (mrkBIwYJO;6$?ɯL yv Lojw4 L9~ib+b(?x3{x4&o3m㖀NCj|; 0$/e nOv*q 7Ĝ#[-cq:sؓRpʋ?D}!O绦B"_q[imCΙBv+:i԰VKLBQmgz,?C}s(;ǯ9;O3=,T;,KM@DzSXi 0zpgDt@RYD}oὯ}bFqo܃џ^ҤQħP|g|Y߬ZӈS3Ӗ4 y92VH1< 6.lC9xVj6FxPhğ| ,Bwfe0_@S[TR@@[ZbW*Y M??Tګ-lgXn 㛬dtCJT|[194^]Ir-KR [kV*xߖd(Gn Rc$;yѵOA5B L:15WtcFQu@fOy[b ПEЂH,=0!,T *pm'ah4JQ0U r@H)xQ(,5X/6ǪFcQfᇾZrnIZɁYNg,n(.Е+$W aZJϤWq-Z=+' gU;nP mb ³QdtLսT_I5A̲qK ~#ɰO z*lgwzuJeܚhq.ĩ2V-C0*Hսs䲂Ќ͖[6$"fAm{NZ^/S-^|-obsj׵cʗΗ'`?pmd|hgJyk; fȅIg.UlصJ_ǐZZdtL(TDy;~vc&h җ y{JFmuz>sS@ȅ5j;mka%\:O=e}I 3ZV xVDP;Ulg5h9ߙ7xsN#24{uecQj "s[Z)4i:F Rخ*vQ.3÷ d_*`pHMx>ęn0Ҕ y Iy,j4jN_Bȥe''hxyv؎:t6K@Wl5bGb^tOg.9Ux4o3ԉWnAߒԽ'Z@c)RW.җ6BOcO)v3 CXMw#I^5 \eZ*6\ =?O1|9 QRUgƪ+fm"y^`p(oí*k9H VpѢyLWP)Ř(ӷ7P>Ϊu(OvM.9r\='fr;pKƼX9LnU-=3HԄs%[C^я vˁO%MU%?vRb 職i0[ _6Qʣ7"ZbBwkCMTkΙ JLܮ 8NoEѪj\0&EAu`X!Q(:~ T~,TH? 5{N ژS^ o.XMo [MU6Q}Jla7|0aBz0z8#JuU3EMQЍxLڔ=2]ZΡ+n:c6b5Qи1i A^n;Y}$ᄞMWb't+5-@C+%2"\Z;1k0 No/2/F z>ǘ)pg^9T`)Crl;r@&焁5Uf4727t)֔2zn'p)[lr{yabY*w_OG}U|`jMvW9*Ț]LVϭQ8 ܨ)*36.WgC |#m{ǫ:ƺ>~܀Wkt|BreB.Mtl+﹩zh.# ?׵+ Nh~fRwH5^d>8^;PԨܣ+{ڈՎv |.4vaDJkNcCN70],8 mtuڠu?"(osRLha';.E9!2|5%]Ξ;b.a^կn+G*g>t3@"J J v4|Т`O4߰aV?G>?͐F TJ* tw@o6[³r&:N57- r/JFҞZ4GsQ\uEA{8wR낞^eWmgg,2>A#'Q6}]+Qdo[ۄ.7<G^KU>W{:YZT>K>i+իl?tƪuDc'MяJliĎJ~S&Bbk)| 2vYƵa߂lr["z]@"q?N w_乴 lga<6@8f9c_(Bte+v.۫yW.o: $#Yw?2:z0I 7<ʁ(-:Z# 5 Pm4n:G7iBv r3.je@2)PFv豇bM=JB`Ny %}!e 0 | t~eC&l~ '1Ό|Z KoV 0GJ j i>bDs(Drgicp0 .㌻&k)VrB\9ļV JX{Kx<9A&!{ӊL'>+\FSMYZ&us#aSȥ[;ֹ{yM oH̖^3>^Loϝ%>.*|ӖR.Vn/ˣ~')L_?hDƢ HAf2˥u,@ReS<+Ooc:xV!_`3ý$N O6Lw&%>")؟iq:ꁲ1& $h2Ⲙ:k^F*ѲUNƴ+LF7{ `CdU叠}md ;A-FtOtѴ cr_+C`V=50Q-eSj;k VVx`+P3нc3^gm ё?oFx;gM+:G2wZd9N2MUح|TגYlm*"X}.=t->[E >njtxnjO4g hڴuM3Ģ9s8ô_\ 6z:p„ߝ.^_fI95$A;Ѕ+ :SNX8_s- lmbcg6a԰?oԛhՄyѱIREڂ]F"N꺌ҚN'`]^ Ԣi!A \AaɃ_P9 Ƭ3ݢ(eZdFLpG6Ԓn{5-Oee/g`$o@܂c[u 8& F%_gH5WݎggU:ىO-VG;TU>='9ŭ:ΕeȠxlsbRD7yV8z5wORPoaE524'ۑ(`2Re^h?3'(,.e'͗r:&bF?K~ vLE:W9հRhuW$ֳiVVZ $jq+y;i(yUl>3ul8N@=X8GmLG2FCqVqׇav/L/bqku -'ٰ 5PSk}g,w:%)X,xNs0x7/%6| ̹!8mfp~Q6$#6ے3դ< MS&~|m,-mRޫ@5 ƘE_60f)LstbW LMȢ?4m9e BnaB>~x.,nŌ%3N&oӟŦzXTN+?k(Џr7IOfs|e({Q.Om8Z~6ȏ$߂ɏĸ]ў]_xrhyq[jpaoj30PqZ AΰCŘ`>4^U@A%FoظߊSvF! X؞JEQ4hO@Y #ILZȬ>̿ 5pWV<2쩸jY3&Q }̱/_Hֱx-n̤%Y2).ٰ P>@ޫ\8aW&3-͎Eփ^`Uch=0l"ebML gkA(Lz'K a,LN4U1XQjgG%Xo#SEJ@햞 0*}ޔWlXv.O3L\x}ܕsk1'W QfQARJg'P&/>bJOknvNu 5 5rgfd7;J8-7-nh i^ e_w֋֒;c52e$VdMDj9D s>AxT`S@ GD(yu[JGJA/3\N虇ݥv)jR):(=7 (QlСӚ:T2,&I鏯O ' )Yl^7હb]e`D%_>7u@R~pj!Has5XI]E?y␜":5tg|z&Sjs։/S mIY[$22,SQ> 5hZM )e @֨1~Ir؂,܂Xe;:(D` K;9o6CVS7x>@g|aJ{rbOZ1Mo)0ً F dbj/-wiLLyddÜʛLSiEO@1G>ل`Wg@5s$(?mh'zY&)}))-hTd,Ox9MmgiltMoH GěahN^q娒nA, Q,Wtn L+ɜhmiMW% Q]' tQdj|pzCw)nԙ%GhrG|ř\䩪.DJ :6`!H@Y;.~S3]wņ?AW/#3:eJp j^-Z @LgND #cT[/,\'d} lAOrT%qRL @fϝ۹;Jf?wURd.'cEcV[Fډ"R,\RPdQ>yw5\܅72O8J,c,z%`= 4sk!ƒK On%w2az 4Jrz¡SUt|ZХ#_DZFIRzeH'`D+, ɚs~J؆{4+`il6C i-Oj((bөT BzwΠ#$m6tq+ e"`D,1%A,mjz.6 #L[e4%- \Y1y1PZ̎%Zv4:y]t~ x5Ywy5{=x9Np_S~T )uu5M+z! KE +N [җZ "X8y -7h&Fuu^<rQU1E Nv7r  :?ZҮJx2ÇRQ%/+M+XTW#G!#k(-YfQ4'DȆI@gr*m7>0ũ")niGKRaZ# }(ore |ٕPbB9@ɜ-&tx;;+l |_ͿԚu0Gv&m"@~&WKy7E:r金k₢Ԗ&(cPw_ 'dT;U֜Tb%/!7,K{LPW\}9] -jY%%9!Egb$>^)<ǤD 9hCk1vGXxu5v_5 p+Gqfa}j|'SS`qDŽ*3IF5sP)xJ`+85LS]+;} \M-(!ЂN9`N/ b(Wc.K-΄42f"u01XD7 w;gKD5mwaUK:Ιs 7Y$%w*x[˴ZI>1{ᰨH"\T2z,ڜtZi5`HQ~;8$) )$AO 'pBJ5S#4ն9i!yEcP8Z3޴p/$أj3-! },$BtY86~2 _ICJɵ̻~e3,<Ŧxpfˬ족p]3- (-$2 wD/VtժB{[.}nzҺ!~uױ)Uk|x.E$&>>O[ֱgbY?hUzBE+oۃ8K.ոַO\zCL 19jWﰤ~W)HͼVO)\{o' ;?߾=Oʱkn\-TbA}=,P\r4yQizٵd\\U' ̴/1I;Yq赌 '_F|'t@J+[od>v.膿8\ h/ P̯ Fs]%OCH!Z괓D04j_##"nHw|ʋI{TY á;aPȅ =VS#[aN,m(뽽JwL*gwM[z/q }35Y`!_yj/ډ4ߵgt|l6ݨz9e\An#鮦99ZOFzt+G&0MO'׎ v8`n][uG8BM#B Y|mцS&t' 1cP^Ύ#Rͫɾ our/϶[ ;Nc.1=6#U;<IP?"@&h)Ǯ:d 2c2/.~T]y:g7WJkJ!'°Y'q-+DoMb~(bnjzv@Dfz[N~97`9B43ޅQ { fy_r9[~yQR޳4c掘_@jGAU{"@ݡ`O+F6ZT6@P"B7yё6U;拲jFe MDyDz2$ 9sF^DWRnաNr  79Qf''<)c|(˺aZbji1Qj mX {7A뎅]8HG}:|H@;wX 6E=+:2n>Jn# y"x]7q#+Cl >uSv ZGi пaJEPvo):a%8%6̗6 +zh(*v*FpaXI ϮShCű>KDㆃ͍\>X`PQD͉LSVfԪ]02 O?gR/~\ l[.uu>FMue BO{c&0U^~R#R,Fq@wAfdGs` u; I,pKk ,cUܭ-T:bHlF7CZfvⴎAZ8ήTDݒ~?aAN\3n|^#t,7OXHXPTeBjdR[N A*ɥ&P:_ՄqT6/WKύrOz&L c/d 4GIjrR$F]/}ʤ.SWĢw8A`Fwbocnqwg QYOUF,o.^ϖ1oO֋ܸ=$+3*>9J@?`o$J3DA5g`js{+NN]ࣳd(ɘNO\ :Ѡ psno}N<ӇOn+? +!ƂШIsf2M~16&31;H4cxWE"t2@OTYkKN*fZf[p$nsT@(f:>[n4AbhAXWDŽ2-D/4D{ʠ㚠3Ј|<ͪ8#۹h%&`hG)T y0zvcV0?'6 QDcmRxi|HY>r{BNSCCserPng?!5bjΫ&픠$ ]R0+Mԋ_l?#RzOGmS>c:l}>ɡx5Јf4^s=RV\骀sw̆ĵ"!Yk/1Цp}l^nJ2:{@b 歂>ڈ$" u[aO- ,%9P?4dD^w(ۄ涅*ʯCg=`f/yr#Tq١biH,dA Hum1Q&?F !oY5q(h3Fؾ{AZSo: yO d_TYمFe>4gjCHۣ+0m1#O,:]USin=rr2$1:i؏oF{9[f VptcEfG L-]⫕GyQm}љ%?|)t7_Ko-C)f&D4NP~܂CM=cf:x~]~|An]0[GqzϹjdf7|5|ՙIgV!K(8t>E`#"@(~ 2z뗹{ۧ}9gq=~Ӝ"[AO OL, AgEvLo wv'eS<Ç6ݤ:-NKZ9.လz' >v &z;0!N)2얈2WN9?:L۷@_NUJEe׵Uel%Y/I}WqQ aseX12z3_c5/m^g1ExVZD(9K# Kd^ \'$In%MhⱠi*k<&9wƺ F29M7`8Jut*}d.rm Q~y zTtز̣_ ?cn32*WXGs؋q7vl:pƏzzc/W\0ً)4NQnx&늾KyEi^r6?qHT,Yo?EKxqpVYjhD[SvD TEv¯͕ 9X#F_͑c+/RgJ2$=_N-f+`#|rh  ݰ" ƮG7*@, !ӎд*Wxc2ꯇB!8Ich>%-+g/e$:yKPK=Tm$Up]RK䒲g>(UZHVP@E`US6flU)&MBURQSΩ]V\!2=Y=ne3Cڵ bμ 钰s-bm;J6FZ=!K@ʸ`EY! ׶'@;0s#XpeU\x" U8(ƞƇ8$پ%eM',}tNa AY[zU?$}}P&fO4sG\Ȭ}.̎%\e0g(Mp`qj5?K:b,0R~6W=%c,voej} I 47gA.l| MM|I4$KZ1 d$O iM8:|u2hGZ=d"4,@N<^%=In%Ͷ &W1 9SVWx9׻cuG;؀92SSc8^ 'w \@0l޳|nxE2O ⨕s02B_d=k;*Bg<+ b;svuEx NjN%UׅZy-:d˺] Ωe'b5~c3y)Fp"N3l V wLf\nw۱\Ñ:U.s`KKBoߋ1R2 X=Msw݊{%O~Z&Czn m "Of ۳S NRsb^ HaL%? qmbKϬ` :>: +dJ:˓So[qrVj]'fh8IhPu^VIf ԴqE4))XF֑/78o 뎬D㔩ӨRKRmB&B%i_lQsW_;6$|ٚ~T/9Kp&2@tenܒNU|ѩv9R7tʶl3po,hUC,g!}Эk20ɶ1"xX 'ʗ#xI6<4o>cF9Q 2>0} Ux e~}Q{f;??E†à?[fN$%+[)kWRmOϑO0`.,i3:nGK[bQ p=ͯzƅ!s%1fx;]M{~+ .a8OE$N#'Y4gTI,N/ _ڎ vf6MOz]|H͖6ѧc 0%ڣp,N%[6K ݔft0g9 C;V#Bgfy(ܚ3HzSH'˘4S j0|Ӂ<˖;ib+Q} ߖiV\9A PS.ޢ78WGI3 ϟWqGke| 9O'MUY2= b*R'&k[6əQJ*D %;b"jygWER Y.tM[O 1~8kw{U rq0 #1QVKsaBF:˖}hAHA5N9T\1m\5i2~bPA t2zRwܯQkI -Ei*^S3X;eA N~ pxsm3wq4i5+!ӥ'6vK!(D9HXIiuEzj K(#-c0SYiX'ZE4&ܩTu(@XV*o}rREW;gQe"8Fl bͶ1bTyUdTZ ՘Ý^ E+&23ul|&x7RXA)MDV%~ ?"LYinE$ϒM(MdG3028@;)M?٨8SYAS9UrJ˰0rtvhPHޚo)Qέ>-vPjt+UC+a6ޠ_@@ 7A{I7+=NG#qf(sSСU:D(b7e 6(24,P'ufy [k^N=!q-尔QltK-l9S~ML\?Fsg~(^H&#B!| ]I۰6 8o7. r4!jBc4\[[i6-qbF=7H*;zK7?-c&GR14btg_U#Y :A|;xȥ ;le!$^ghw/~Tx=\Ԣx P(:_5WED%V;*74,?,<"% J:zחЊ?@ m1P ܓ"{!XT1Fؒfڢ^hQXX<[<PZDiݸ\C1pYFtϔP(Ne^wz3ON|9TQnԑ kxY zOBz+4f mo8C%+x'.߲W{;<`?2yOb$6[5O'yrpOl2:2bUK1[#FΣkz$Ch/@E #($91X0߫yTe'R)~%ې QBAB|6u {E!|Y.'(K!RDwl\lTHB{,EzyA1X&c#p\y4^iqV-s%7QKZ nk{pԹ.Gv p@t'Dv4wXW`Uz1M,U\ℑkk F&E 'ӛ_QY Ȉמ_h`QH?2'hH7C Es(fX>k@VeX۵YFຒ ,dmZxQBn1zCɩ&" \v![(X[ڕG_V79cq>+v !U|3xЭFʟf[h9£0mIEa h`G4\ɤ0fN=xbO6bM_@s 8Wʡna95RP7,` (%-QjocͲYw&c p% <°4K3mS5Imfd] T]lv&ST]# i5V|&TzU=6 GD /_L \dHU פ ZDZ Vo({[ ރA vܢG1M9"X75n(ŬpzȺ(%LIС.yz5]tKD"`jɧ`\HUR;,C( ̤dP򃬷 ~)LEۗ|kf:£|c 鈇- U-.6apvQֶecwɏrʨ'EZ`GS&9hcH 2~UivݛC16s`f$Y(@ P|S%"TbWcLhLiȒ+fugC XD^Eks^eifM1(Lqb *#DA4;O(qWǻwM &?= cCIjy`@⺋}[$/ wckfٞ2T[s)|}. n x}7Z´JGS _ȈBTą>+b ]'b0F=&J,TC *MkZiϵ0#bo8Hd?:KɃ9 [J&MYgu|EsK=[y2] V3jz|b&83k ;}S+v!gNt^&BibnUń1twW6\x^y 4FB~?ZLe+H=l|$ї/;j2yn[[(ʱ$EЉX.ϢǯF/6˲j9E'M^U % 5]łEA;Zh&`Tq ]Ε6.R+j<_4>SBAoe^!o)Y׷Ih_+9v:&l8" E(^"d't=Fb1|DWT5 7[Ln6T[vWB4~}@)L9!qmXϠȵMZg K Ht!?A]I("VvO ԏr#2rh&;)Q OqX¸6 xtFmjʙzbB;WRݰ Τ?0].r`mVjK7H> 9nZٙݳ0^ H=P K__@V=R646M.(g(9)~jNM{jTa"[1V)%!+O!; =!HDB TȖ=7q1uf6odP "23Я YdErG[p#"Iw6(yupaK3T[f_xq™496!acPix9vd'F !9V[GR`6*[a ಬ9y{e"x;To 41Zq2k| 'X*u|M |YJv#v&>xhKz<po`^;S|^Y+R<|h3tG[TYi5;0M~l"\5(aaɟbc\H(|ޯd$t!)b_LHmeG_zQ:yld$REņTk (b1ml5qKV-nQPP!Y'D2κ=a|\HD|L@={KMf&22Ks+ǟ=*wkZ `3I$£^L|*Et:0T6*+p{ S`.d^[TL=UR:"5%Z}Tpoշ7@>M%WK;xXEejol_`!~[U.i+$&ЋOyfO F_? 5Nmw ?1a'1szM,)2=7-ޑv},RjhKT\ȓf,}*fl?D\$bͲSbɐ,㋹ވ ZERڂSeȵfxm'?֮32=GݢpݐM6'*L̹̆ZGO)P9%[8BMsTo5(ϒXhnrYe,Gbrg_lFUZMD9[nrū A%>YE%nUφ@WPJMh:ez2-9zOÎ*g3m\:s 6Uw&.P-Wr%Mꅇ$y3CytL^H>!U'EkRKN/j lS=dd9 %%]DWJdg]\.( lh౨n:|:f8n_$!eFAm &E2^9ߖ;{~f,'G.{Wp7#}5~!?) ]Dv˯tRQ,ގĦ~m:'p,6)?\VB Y4D t7_Дa~O7Z5lL:/eVxޥ'/9w9"<)jﭦS޿/SZ '\}vZ?5jn8_LsTWWfJC*o$XV,dXc  bb@(lS8@E޵;R ~ Kks5x)RPzy}# fSnGV*G0=<~Bcs_:s;ir:zCNR=,6@y/\N&@:_fr6JG_9Rf~+UG-;f9l5L5x;(N[S=wC+IJY #V+#wE'I1G  {2V=Vl@b?dHw̜4"zrN\^)oRQr (ՙmmCIԙ\Yi$5iX0S -p[\NElF\<qث08K Hv#UN}O(1*o@JWmm#TƢE rM6}y9ɚ ;wvc^D%w9O5Fǿȉ:<<ȑkώ@,2-3G,)_Sfg3A_n7n`mo?堄.H%.n,aD ddcBn*;V'ߵ@! +iwʈ! O =3X_vϯV2['(D3<5c>\/桑Qe|;X[L=J5D>5,f}E#xhzk7/,ϯu ?=wֿqt87/P9siV, ʨ=o[8. t9謷E5f랉( =\jvAJ* <@_L#"v4f.eCs|)Ev}84oyP]0ӸnCjO< u.5lRtOěM!xָ'a8Dr,zpT#X3X> L24^^Na箘\(S^;W)Ҡk;%L8c7q{NF,dtozkrѲ_P-YrcDC8=*ɾ*I{^? lU (=<_h|Xـp奪3FIҒt2L ^ʋ"Df2Y(=X Rf\T'JFŤ$, ˼a#hL { ܲ0V?.̓{zɡ )zYRz` [C]\,Me#ҩg ,HYU-> `O\[aS.b vJJVTޟ\%?Rz IA Ÿ'g3J U]$51gwSXQ$M#(@rby48]1 wQ(qN)՚onrP0>2]x ;8oPr/RuEEl招H y!gdaKæx'cT,u>A5f/?OT9JfHuvN(oh&T>X a[čX: x~hn:{˦zcLŚF&Zu<wɐeeQ5hŠ(^ڄ?i_ S&|񆝢OVkOP2N xQ~>3N"Gic?KZC=C&v.K6R'sZN;즪@G:PˁY@]d2m(f_|2X;I^~wJ_7S_Jw 5X"X6R~OMua>3;3S}_ݘC^:c/.]tDX' pne5pǞ Nt/^W TsHIw; 6]OJsRG]!;|$USgԸU=ǂ9վ ZSf69sB5z:FՒ8sU#AaX*q@V{OL/kCH;SԼì $l-1ك BNvi&QBIt_Â{w^F8Xyď1@` ~=5s{S|hktWE*(nC4kƧaǠ>0i O),i·[)Ǧ#a<]IK;-5UЈ0kۋ@@o T8@z-Φ\Shτ- a~.iV[9ǫ$/JO^wZdn'F%w}nRV/{@ EA(J]lDnVmT$9nI> Դiډy"&P|s^/0jZ+E/u wtetc׍.PL`(W َrzcFW|0W#֜#҃fU m4ETPں` ]`P;AWJM&?M.g7bA"u JɎlB1(N`rY;>ctzNXETnvw cDxd Y:N]x~[JÎ0[Y/tu>vfX5vXN]W]{[i &7wW U¯vEU&,YGf6Ӓ'y0 x#jhm?5UOfF݆O$[pXFMg:`qt2c*C5F`saC H..9cMu#D]ܖS/`Bº6Zvz[L7Td(U6S?/l5;taČ~&na MY M7큠 vۤZ==B)u604d4?N2fLPjeٍOЎ8XUx`5-?zg + tR{̓ڹ@j2ۋ%}V,$qD+BO sn9SWv(J{Ns2…~Y3T4:G5 oVT`,SLބGuRar7BBNayMgʢSV]h9紟RE.vI] u2;tq,~G=w1sAn4!2* s0g>`!ݿL ܈|PNܘp6ߧ\UЂѕ0'Z͕eWYV=,R}Zà~{R%vIc4&=o<~)(5W/ RC\j}+絗lŧV<gp XT>0;zVuzepMc6mt$<硵zb/Ǜfsœl(;3[ 9,T;۴t[\RǨgm Ew},kt,UH~q8ϧ=K G,Xŀx(JB)ĺcCk+[Tv.x rVrhУJp|ٳ5*1U% E>>۠@Nuf1WWtj>ѱ̵?l,esQd鐋 woi.OPmyTk<;\e;q[ׇ]8ƿKl:wrTM_"-Z-PK?\X{?7+vLM77.&ᢙtYܢ12%Hd~ H|͆bd<S˾k@aTfP4o& IX!%ο>QSs W'湽Ū G 5Mѽr뇃hi|W=ɖc+i,k^as}Qڇ t&~e Pr88N< *)D.O€vo! BH}P'dŹI dhZ iwRGv-Ļ)~U!("Ԩg f@wd!e@XuiG>qz)*,6̈>GnqviVq NBVo.4R>?4 '֡26_PHR!2\xض}DsCBEpqayLD$ϭʿfAwc땡64wH9H:V?3yIц=]X[S0|L|Zΐpy4w0.qRjp_4ǻhM{ jȰ9Xf[B[ƁrP/t n:B>*< =nfEpzie!hgUX@4kLBUh\(%s?MB0mgpo: 5GBTTdʥ͹G]GKKGLt)>,7_0|? O%.ƃiPUau1x֌%^h3Bm$5xA'6#KuFd{DvC&BW-0yQ`:^OS ՗'׀":[Ɖ`,KϼVȦ+lc {Sr0$RXL{`!o!eu͊BݟK} :V@30E<&h{whwMQ-D칅<%n 7B_mr_CfQ4H;8F]#pƁqF5.}T0䗅#PUfn^M!kpbi]-VkHt× 8A!7Yn Q[GRfΕFo$%=m?Z2>s~f!h|cZDBx C>|+\H$c͈)6.U<@?DD9zee+׮b_לLZcqρ Yu+8}r[f`̪*c^uپ#((J6!|G:qڄ6ak‰)԰jW`CX+NIT?#%=_}<3~c4i GTnNsYh$@@^֌כlz,'a[0ɉ_DhD ܯ9ŭ5,ȭEƚV N(ϻ9LnGeTX[-er` rMk-K椪 Rz;͠#FR&9BzqiϐWש%ɫ10 S ̖+= NPcѲgEXX^wZ 'MCE# p* e9f}璥3cLK+7L. gDGBݬՆ|ȲCO C^`!m\Hux·sQv^a'_sS"*ԍTq֓RtD)\:sޯgV\rc$=Rr%'ukԉB g֫6 Rb2$Č$c/y=ƾo.LI[~o{OvAJ0WtDyM0ۛT?B%|iZNSw\j7 @G;/S$Ue< U;cEZ*='E1 Y8u)+5"aYLQzr:;Y {*ٚTHUƎ4 p3IՐ':,4(dD^).&Ϡ,,v~ Nz /]k->1pSA΀*Nugn@ĸNdei $\zVwur ®ZaΟQ gᴬ宁_kh #?4m˄UPV ؜=/˺[ء;L3;ãb-liZ/+-B2D%@K͆ ɦƒ#8y hĿ3Jލ@Oqڐ^odSlkfGxea3q7Gw4R{)Gxt9j*WCt!CEKldH*Tp3Bbf$s-+ Ԣ. xS}kRU#tϦ=u,ba_| XGH79A{e" /:]YTvWOy>Cs@t K$S7K8"\1Սf6zaaD; c#'2^{^F:08)#LL{.(|F xmFL s.dJ\P }t䲉=H c&u!/1S6l&uq|׭ GxX\9's?"l}JlyFuUUh Cՠ2궩wݥ]?UUvVpUcټt(qaZ`Q W.U)H^؇%Z#HxK1Brڻצ=+*lN'Ffe4b$" _<fmad˗< !TC1zT)EmN߼K|% v hyE|=˛,PZ1Zҏ,ɪ+vyQ&+Au@0#e7 @LX^!w1@:n@!j|0 d xEFPHGuNL f .LguHP _qg&gg8*+/# kk\ruXQ9 (ܔ5ߩfs -vepszª;eEgm:Q>)bWDErp 4?kZbК#Z8:ۖ>!F2B#pyPseWLui66i{Bb9"tȼMI>ks)*(^V;K>#cߊfuQcn:@>XV_.g_Zcq({ҳ:ց+޷z-d>z}Z8<^sde%lQ]T+>m;y:릡&(!(+&=U:zhQp#ǺMԱxМo/K~}@Hhno-;]O@u(Baτhƙ8Rj,jz׷$nU/aO'|8^%cKU':DJꂦW889;33ͲCJ$K|?6Ҋ/DRHHs3A}Rt_b:oViك鄺K,-I%,yHB(2Pc EbFJwY6Z3(O/YޚFı~XۂJ}Y##pȰMIYD dV?AMC F>PW܁ui9LH)ez}K.kj6։W#0fLm;ń6(ݬ/leJ}gr~瞘-d;oX-OܶT"5 8 UnCr ',*$JBẑ`Hr1fDk8Z'юvcQԉ 6.̆)i ȯщF} \fe2}Slesb(TMsM77ѲxNjTz-q0>v2Z^Bn]UkתkoEh֗ j3mJd㰞@^HQ"tGu_YN,%za:_-9ba丳1 du!"~ S.2UȤ{PDO*ls\rSU#ժt-v`p.cϩ&bk}WgTF4ۢ%CT4g U?5wLu[Qd{zx\Ql ih2!b^fonh->Oē{^(^w>L3$nsP,/y;5_3d*O}^as79OC9TH%wPsw+Pk񍖄f޿ KsQzP$YЂ+OĴnv|8c^ǒBF MV2)L1:[Pzg.m+yB[)<[MltoЍ.NUt =Uq 2ݹC1aeW,Te!/"^ɰyn"{L)G?; C؊|+QVJXp2=v6GC8leM"8xOg Ok ϋYvߚo7t&sfQ@u+4Quثc`nvɂ4tQLhv }8pnH|| :4 {e^;›Y+Z>;LaIIȱ:t DBvTʳvpC²еmA/7tmTQD*Q*F*u14%<Әnyt6YTbGvف A0i'{lT*B!|D 4?֕SIYqߐwag]WPGƔ_2Q呔,E:^ KtO#A)u3G礙6 u.*C>/CHj&Ϊe`:Ylܱ}TI/,$tF BXxޘ -*,_Wd 3~7l"`=7LR1\NJ,Տ)Q;]HdUN.{Y},\K;]hMD/nvS@ tͣJN@&?7ָy˷(".ًEUF^;o8䁿#}Y`Hcn%D:r>MCA+=*~"`TA0wʶUn|f843h 2mP2nCg'ZZ,CRfݿ@50U -c/HGzW?Ϻ+lQ:ߌ}`ц-;=kϽph=䒱7OUz_akdMNZhSX`R+>@Z jw3jFSpBoW ?$ p!,O1Ȓ%^;3Z1]0'joޖlJE_??(,N*EoJ?FR5[Rc:i++Ѧm1LWw6ؗq$%8gR+?_<ճ; CRqUhғ㚳Rf|X:kS`+!%<5,όH6_5pCo-\=5N>Zpt#> jт}e}WHIxEv;ܛ wQd 6O_P8J_Av{];)!xlu-Ao$s0Z0~ :8+ ϳ5Y w ]e g9M7Ӊ]&QvmJy@M@aCZ$=hn_fUylտ'ى6>PZ7Lf;.jA{ڑj۫DL; ?jW,EB~r Y4_Z!@su_pj`W:G"9m^s؃QJۘjO8Jަ(~UEu!aN"| ohnYf=dja־pBQ箩-y)ȻUc(EIE}#P<K_͑wjdǩ2('Rh57I Ū #%p?d _=Hd˚pNV\_LYbuhI6eԂ*SNc++l<݌(F]o*$5гitcYժ|Ftu\]1 ~›q9I?k5Xxj{tpuG s 8j &=Ps6?L =1*5 Nm*s15߷q*SHK s/M%kry2C?v#LPISnlK:#FVHr7[X,P }E/b4f7YK e,**7,x|꽂\>sZ(!P+ 1 YSZyw=}=07 $։F?FgUUIX[ϵqi i3 302ؤlZ|qbyHQf<޵k'uf $]xwvˋT7Z`ep]0PnJHB|0C  Tei;RSW~ u |`)l6DTdC|}K%/0Q96TT$w~+mohܩ.W6SGM_Ec`Z{uj&bz|h(! m~ppJ^OʰŹ8aqx }3CT77_M^Z?r]B'cb~O* D7We, <7L(" zgi)t1x҆,Q[LIP,r[t-;2rsPsتo{v:(yEf_W/\9qc 4-֮oԢGS\ JpA~:}6yp/&1w] |8-(!yݖ,9j#oy8{'!b`e"Z$~-$j!^Òyn-V\%*-45@D!Ql4rjarRȰ:ϮWN~EM>Ϛ"ɺy5ilcrK: Tk `-5pFU(h!WGVhRiA OP~!ݛ<CSNGH]. yż~:^e<4і<ԃӿq WZCS9< 'IǩV=\I--L`m$τ5N7-9>9E(YQCGY<hWr7@S^I Y=-Rٌ MPB­tA`r#FŌDҷj#6\-ooʅ"iR -%V XSvw17 a,x Mֲl(8ǐ9;춄35<&H$!|AF}>܍mԦ5{l{daCI8+pIj,LiʯΎk\_VZFD7J~ۺfuibE!gH. 'J䁻xmlm` !Ik0yuu3Y:jnhЫ!/gτa7<,FnIR?+ofƼ C*QPI,(ԧ9nԞac5LHD\p.hzrԧl7Eǟw !jm(:w g;kyr2etϳ҇\h%T(XW \Ut[~F~e[-ƃ,\-{-e#7q鿐fZg}%t N'*h@Yv+eus-a>0K5v4gXTf$!,2&9,liRkTo4fxfLzټ GO"eO]U&$Ԋ cYH/~>i]Ů1AǭEϞ:UܤF aVgd? yԹ=B/Wkl 6A)?a^uf:!#zR_6hޮbDA~@}: Hn8 ]LCnKPg"_()۞b-\b&z!+ލPRZ߼N)67l#`ИQ qX\/.SǴ2ua*bVqTV~QX-i!h"/ŗʮ!tQm yJp( .ZL%YiJ?[K^J7LEHo^}g 3).<N5&KZ>iÉAMh7X( XnU?bU({gy,U=n|'q! :!GU|˲a Ne¶?t:1nӑWgkjM1(}^A㘐ILXcJ(@ݸJ{ s~V4X:HKf@+9 ( :&oӾ5'gO][_VJf-n75qO_|?9›d hH3OkDi !Ud9xp&40=/JcE#Y2t" R(]VߴKD>ͷKdTq9?-f x eݹ^T _&>C5Р5]@/`n/52>Ӿ_ƙ/lat-{ b耫 z{D; >wA~ύ,߮+0ojO ¡q(qky{Z*nZA/Ec#1}jiDwGh=adS0|c@ụoBfd:63qV+ɑօDd)؂rgӲwYQ>5{FVK[myg~hQ6rUM8| ݹFԃ).$rna\`V1GA23Twad_ MyiFppDPZ&y~aSovk e+#-]y RguS xK2ay-7gyCQn&8GB/ @fXK3T 3B:@ZoHSZo,1*HЦ=KhFwUhR!ANIC xaCf9QdԂ4n*Z6ڪA+m>" mg3gV8=Npp`c)HPj+;OFj@B/@%92*q'ɱ;=rFj NUfX;Gm*WH[_y8Ce,~-O vsF.j5PL] ׂd[רXۑxҍL?Tj|v)Ёlr`Wǜ|'!vD?8(NJ.IC*S*^l6"ϗI(2hOp::^wj͋)Б9}Y{ VXQ%!*P /mg擷q Kft 9 v׊Ϯ~WޔaRY m;rQ40_6k\Ȣt=s߾txHDzO2Qup퉯QaYC%Bqwh!ZNw'az$t*v\DRBү~H2v׏FBQm{V>tjF::}O(>f]7.s]\;Kę0rb| 0a\1agXcĊ@<JM2 fwdo:iv2iaY)$oR2w9Å|e=<}O0!/>.!bLa'6yuoO^Vw=w9'঄9ȔsHpvblG&]f)OL})t~ݧӠ0*Wc2V& Id)0v}1g2G0ryo1RpPG<=ݸZYq:_!ZaޑFc*. ώ0%]j3>S8yk"\lM~:'y ZYb׍#\Y5ޫס+{̪-PbRPԀ8l1Fֶ '\_"=2bϭ h].@U" /i]pͩ[L*,}-E3GjpŦzs~X"#8pQ ؔYj bvpj[ct@2dR|ZUN(Yz0Ir7v"dzb墬&V)&*XheexG[TM䙈:8č+:^hvKl`{oWό^r0[o *hHX]1YMwa$|ӢŠe/-NrtSJ\lI>KemVR-*`M6שo_mBam/kT#kbeTILb1isiM'7ħ~yB۩!w{ڢ4LGo~,s(a+K}CpͭRz3m J$En45o*bEhYg jk3pW];-tlbS//HgaE3O96v'EƔݡ+,LZUȌRH-H㸠\j./fς&hӑ(}3cqfk Ł g}@2ps#f஥!S@YGN+%FWxQg[tHYܷaYMӶNOu2.O q٭pw 7y0aՄś dTr1Ɂf]ˣ`r[Mosz[ HXQ!`OD [ m*x2)J6{A]d ٶtW=qvy?+:̐l_[`DJ }U_:i68r`d#1sa&ldo W/ #b Ey$,^%W7~k-QToW"P6w qss)r~tw| 1e-~I\E6Qp%q|F%('#@(2Ҙ;F͡5H EvԣL*s}r__2\ cL,qɔq1{AnxR9ڗ,vPޝtlU"6hPc͇ ]x ›͟&Z!"]B-͓4 "Ð]^=# J&20vku,̇.lUn؜UO ~_$M`1\y #*[) EE57$/C+>)Oi5 *fN-:崦p= ^(pg0Az#.#hʙРu%?0֟'8iK@4tg0?3҈pI5bǕ_g843zteƇmwu<\A惈_ah;d2ڹwW%H(%Tޱn]I(E071ؘ;WsaǝPp"x ҨFh=Q}{}-9,*"tvOK=iTŹʏi2_^/y1$wR4(e _5 (8R{ Gua&)-+wDhyP~Y 4lDԽ87hk=ҾFr{Il!]́~jILK1~ C ,p#ef>zGUKe+DoAu5,u[_"8kz/hqNᏟ^f&݁. /!$#C_8'J R=:OUw_; 6;tqdM\@Ĩۭ=&z JxGdHXwui~{IQ/S0'fnPlgDk5Hn?@q$ҼV5(G@hϋ{ZwYͥ<:dC%#pV7գwkXI訝~!:co)3.=ɹxÕ7T~!9DjǦ. & ^.E2 6 zx4i7޸m .]/vOP{+ʏCvȑkI~(qsk/ly+{5s 9a/NE~!b˩Qny= E_򤡩W7w"Y UW~Ƌ5cޥ۾SIp/7ES!6k^tNx˩}V$ npj<-U-llLCfVg)֘*wN56> PTB]}Y߼+0g0wxmGhg Jvs!VZJP⎎1t 4mT悳cʭˌSsE*#oǎj%V ZХmLo8`9m>J*Y:RXzµ2ւU\n6q]$=N"3zl(åJG.7Y:i\Ɗ @:w`C˙}wK)9Ih_؏Le{??ON&aeVH&irN"!~V>cD[Ӝ%¨.(8OYgpQ ji)3lZXfT|\VrfEp[ҟ)mp%t$xUAEݜHq*#ܨC瞻21$Z9:asAtƛ-T|e)cP5DN&@4&m OA FϾЭvwUY׍2%h'02)\]Z|ȑC/ XP*i{@#~J"q*N N^;:YK3?;b*~_+b .q`U0#yp^{t%J^ _t ͥ{ TxhS'$]kV#\ו3nKJ cП5S61d҇WhdoY;GD z 0}nư-RW_E=  #;“oյ40! 5nWu^ %:hzDQi<Zq1hYY ~S=1 0IЍ KO$∦2liFhr1E!VNϜuyjgٸuY6YGKY\l#7 拞YC>c`ha3e&$Y` tuUX@U*nUPA4VKM:֔FEd+2e7\t̛7mtņ/C/@:ds' d5 xqQH=e^CIA[*-XW8auRͬӣiϟxOþvq;-XlRݛϩ-v;ܲ#K)u7\M{AUKys="~+%ae@[̦-`a$y{ wuvo_n#`VUoRQM;C|sB0@wp_cG2KD&7w 1w;$WtXWcW)s{\us(gtoqo  Eu ,~"q\M.Dl wG"Zk-(&e+} c7@^vAR1E?fy1{ϦmN kS&]gU:DgʱșcH6feaq:S`HrڙMp iz+MJ駺k%9+'b?Kd (1Yg˨ (i'PV2, |S~H}-SHs[ #*ȧU?<&rDf& .d*ݞ c+%}1]B桥\k>%50_Nʼn\  Y8:*4[Tx͞"3eiHL86]3$f0̼rM#TGm_²B vAS (C3M' ]N\{h`>k>37abzW2Ͻ;֎46Vgauf},ZBc~nUH dP Q2vBPn9[5EH>lINJ6|>P#FC>B=%`i,^x[1#ŝ#6r>⸩q!/$w!xPQrxu $_h[UB;!mjH6Ѫ|2/AOLgWd+1)(2PCqX^ }l} 2ޓyjf׸n"ObGKVB5k Sd׏5 əM{1;~ݬ⚏s4tcL,'$ t<fJ ~}yߑF~tafv-{GX W_܆kJ4͘韡oY?uA'in\fJjICǣVCD*Y~VjWX0ɗN%/BeS0HɍA9~dv^]?gFp7nʃWHaXbR&Fxe~->J`cw1 5*Tng-DgD.82x `1)\ѐ zUcsQx50ڦ-cM54g\UUCN!FA#9{StWEhoNtG}gt,7l Ǜ"zg#)E[u<:9Rm'zK C ;z4c_8O #ㅱf`%[5ӄ|ܳ#UHKmS [dͫvvLB"6Jh[d4u@Skqsu&eFCX0rDU6ral=dF{lSP&pg[+x2A"Z%_\Gn-U/fݭ̗7J'Whu)'XLe +ZG# ,dd~ǣBF[QTvAU\"HLUbw D+d=^c3/!a³8`} =IP|L3?ɉW6*1ǵi-( `7Ƨ!29!HQ )f|ET1#2U䳽cwz[FNjKn2R6%d_t!jSsbi >V4{>c-8PΡKXa3 ɥ0]eS` ىKu9U5 4:1SC1HpNe#sv ! T"n5J"n^hsxܰnaa40sZ;VPC ]0Bj6 Fq"7+삉ؾAq>WV֯Q{ċZ҆2Ho7Jk`& =h:75S59œ. >I1D3fn O#HOt "%0 p ǢqƎD`9}r, : dqU;r8@PuCU-Iܖn_wI & 8:ˍ͈1PKyK BOX6kbX‹~M&sG8?V*m wwE }TV/*#AyΆ]# [TXO.)=L.iʡ3*0QjOux𞏢4bH~R 'VQW&5|dεDK9D3q4ԇ(靛 )*3МY(LpuIWɽP -G5l]ʃ)C\2G)Bי;H%ң].R72RXM/G#P0M$sI~: KD)imXaprBWxut chi"z.MGVWweK,tw!;NC7_=Isz$OQZ 4r/Eoi2U d!wKP0:qQo%oc4x<84)7'$!:hZӍ`\47f:ճTY 4D%{_uMT;D kf۞ȝ^Tefx4Qڃ4}Ke1o4 e*D$t_T3Q5G'!oMu;/L@>ՏFy5`B7ܺā+<)jn -`'mrP𽃖 2mePW$ph?.r{B -4ej+5frf0pHXrcbf%ͽ,XpF89JQ*E r"jV2%t]I@ z;?|?S qCp%K*ڗ*F3u@bK Q yer{פ?|<Ծ薁3qRx7;Um"-$i%% Թ|~ ؋9\=pyL쪳5jxC{[ 6}s|zPUՂ~.[bxK7&l".eto>;Xp1?.wS?{940T~Lj.uX) px u)j)D>#S/ɤJbnK0WsFd7$a6n w5\(ܶwN>=TIZ% Tx'B5a`]M&R'w>p2Xp$3}? .vP]f+Xq^-gFnwEE}ޅ=k#6y"jkbDZlQ~>G1H+SnbQ˕_}p*NI+]|\Qx^7%i ԖƁ/$Dd:shBdx1g_^Q1ۺ" xjn`B(E N @zdNjvNv Hḵ0~,.kd5*o99HJ[C~W鵿bS~"|?-I]Jᣃs2knͼ?€|u$ƾ>_ՑKH֣YAϏM 8]WbM!zɘwoEX Ls>S" B)M7"~fmb>AXr<ޖ:\m痌+%tg3+|6힛׶ zҥKjn']Wze<C+}LX}hHK D @AQGuDOE OrNeH'-̒\K t ΖxWoi,4ąȪ,iS]}')0Ep >vH4 A{1*<%n!TO*z)bQweRؘ[[^="%u>|BfE*9*~H&cE&ܺ#(dn_xcr+G#qwAQ38% #‘6B؎ ؝SKWn*x$Tjm$a{HxXjf[ڊsTDB@: NEҸb6^sOr ΞY҆tN {sͣcGl|Lv?"8(44=ðZyW):!>VU?C)a#@95W&?-$mџɄ:B;3ɉM&0:̵-a7O[~HlILoz<ȸ>̐f,HFGˣ& x ~#rXD^RI^0˘w~)V?ڤOd VCۆʊpP^R/ B/\dH\$e_4{w۰u`g}Zҽm.ifro?˲~I\6]f]~iggcq}ƌY&i 'pmgkȾKmea\OP)nC}nZqAd@WǐfL7$yZh<++e hf٨'w+Wfm4 ޱ}m Cְ)H"#E,g>%l)*U$P@W}}SMn@Tr%ֈ]z~ I$mvVT C9ℇs<.Qd`{@"G>~ΚfR- ?K )]3ɜj5@X[f4* gW>Lk\dV䛶#/N=G&J \!fۮet7upٺ}؊ý3I%~b֤XT7H)*qB+R$ cl}]Am fR8-v|\POVZ#U$oZkH}W@zK=Pٱ~[ jj"Hj)#@-N H;kme]6#" `]OiW&lBא+8.g-vAƞ Whh"Y i'cJ2}_;?W8'Ooܢ65,e1.ǡܼ05`.x`%\K^nD=A7-FAV:1H]Yʊk DvF(&F-VeAn:SMLŷj Ui? JE=`D((2['qODT?>nH,5ox]3,9Uvf|bF\6%ֽKK+ԟ0Ftgw%eŸc\,u% WG.nZ#N\9MNnQ)iO\9|jo@i v 1\rڰ-H.mAs/_/bV\p$If'ONC[I#y) \pi_ ;ߣGsAM nXU,7Q\71 >eʻI3jg{3@MU$m,^)y[6s6{G闿6Uy/|0R#?r輮%ˠ?u?}PË%{/ӯ&QXLĔ.xxtV/"q܎2U :&vH0R=u *أk13PpиrwkxjQ%"fWbz_% 5*h 0߫ 0U@ h&L1MS){7mc=>&2s~fw٩҉f(Z̎ ۋ^}{' iߗNfL54OFFȶHWu"%rd`\6 "ѯ{ED41 4vG:C^_\ %CDtٕkG\5qfy҂k7TbUH{ *L<(nf ur@ǜUf FU9.Gx}̫%!E(h \ zMg0kњuy#+z2q,ح …|N0nZpH# 6ոdL=Ma_=d񬣎Gw/D]V~M &S抴=tl:Ig` RK LAB&w[pUm+f~qS*\%7 # g/C1ezu"zԼ9z:dČ `ZhrMD+yֽos6n?b n B wcoS/L3oi_ut́8.KMam0uFvdxD܁pBqPhPjҺ!8M<M5>^J{k+W\P,v`:+u)6Ua)Q38RE),A%P|$ҭeB= c)%nDt1VU?Ϙ*A\}}n[Cjз>nR*;Y;ph"c"J&T=Ή1jQZdî<8Ty#ZccJB AgAgW`15P!M"@-rh>L/ iJ _!r'sm"S|W&p.Z^ i ov640Wur(G1H6G@Tje5._*r8Ss^Q}`pO! 46rS}~bJtGɟS0u_"ֆ"ͪ4EcUE]\ytɎdqXdW,ʉw  hnM)`12*9$DӫKcc]Z}M"49UO"@{2ӆym9ɕ<nJ#)  t'R鑆ߙ)e+#rqQ簘ʩ\!^(PLY.uG;VS^7-Bȓ;XE(;Ȏ1^k jc\W[/WHj,upQE aSգ;Hӿy̻bmlR(5}%F#DWI6hnK?:H7#\oEƎݷ]7z+gۤ3\X#(Х3{ ki|bM_ya-ҿO]hZEI ~17]n҂E)`BHLąIL&4z!) aw1ѯ ЋG(g먾zc30hf#(MxvW_+Tj(nNv-ڵ҄G#bYˆ<)A8(;ke[)mO2m7ʕ\?}C͉[ϊWeEREW%bnX%ysӀ;Xv 1錺pxKi w :ZPhJ2 ȃP&GT^;} r̬?|m1906P*+Po]9'0 ]E'mP/BU8Z[ K2oؾhk!UN ѱ!{:}1`MxoibWijd-"a- ž$Xv򾇅EqlRuSУ $6H~( \v VR6Ƃ՛( boZ(NAS0%Âx ȚN؉Ùb@9QtSsRu[(%G>q}TB/ /I}l_uMxk QGv;ޅL:umy=!Pig082lXkéu>h.7q>#hjd>metcf.A^vR1yx4)IY\ ()v`|b M~2݄|x4A&PUaBoGn a݂c =ex8'? Yײ&Ԟ+ +=FKܴ[#R|1H()CGQd'$G`z #,;eNom ?' ehcu,l!4NC|p6|$95 =X0F egAS YSbȀ/ŽI¨t*IH|FdO'}hz$!NJRφ{YRs뱔~cNBt:ԆlLp0x1Zg 8E{ГoڶX@HLc|2(zd!J6\b$&_~cco'ͻw,0UI.V{~s+9<|Fp|OUAu7Q }c]To$=Obf\'@1K&mP/R覤PD>?47*XD.пQHfDKZŊ4b9#H^?l5[,_I";Ckx8O tqLTB#"$5i"]O9~7 PnR؄umUґn .N6ukň.X+pf=BlrG?P>/J_6eZp'A#~fGXM1::{gp$cp{nIe;VCR_ F/i:jf(~.!*+ &sq뭎ri^[Pfo{_&M`f5{$7m#n-c%m'#' 'eøm+wsQh dCLWKZi{2s_>v m"ˡx 1kK$uKց E.0 0: x  ODV"(wlaUht54ЉRΤ7X_9+<gsz]B>?Lju"bzX##Ğ޷TNmIݲ^Y'9¯ HjHuģ~]@?QeaW{#RI6-?خofivxS`IRn: NjfR&\qGHq/iY\])fkߎHҟzl1^@ǿGۉd Q+DJ9+CݠoᦅO:`>,j.Xe\_HڍRl1 / [Giw*PIId5~Y\I;(zCӸzH:&F^$ \UH7os?nÿR1cBsV"lh"XBsg0д_OFeKrC &!y rHUb S㋛.pXce ^ Z^];~mgAkڍMQ7 dibv_7b^_S|d%a yA(8~%|Wԙ @ڬT+7bX ܊ qAS^b|i!!%8m7g_e9NA'аI|LlDlMFDN[#y'OR8P{S8N!lBap\focХpj=ivh0DVq>T50\+G%#a]rTGǮk|vn]۩eK` I3ʩ@X UDeO\dAdZrBXI։kQ$QCNfgv9#W-NMsY~$dY3N&ʐ] g*)=WxaoS J~;+6رiϪtd|O%AvU^{m>e@լCaa3*eQt.05[$I7۱'Q44pI=}m>)u=Oˆ_Ø;dH]50gKR D A.]9lU7ʚ$Gyk\ηS^$Ifݣ-K+W~nPL9 6%o4h$g _%`9SqZzgqa~ 2#;*tuN]#}K,< GߋQ_ (R{fFFk <4q I- ?#m|1pbK|zd;9%}ӟbioo2!ҳR.IMDɚ()*Jbnj&eoD>x)=̠pwPE=߂NQ^jWgUM7VRj#&c_>EM=owpC 1ts92nhoC 8%.BIwcFJCp2L E#j꣊@C pC9V-b~1$ ";?F}a3mۻ' ,WFc+g#p1cf9z_ ʢ55vL޵Qf@nreXLa 2xgƾ_@J4z(#S(i* L`I`+l"'@*:ʣ*j~wBp^J/g\䘁oҒFMS3 HW !Oc/Yu>@cs[ƻ,#ė4$A2*_Xn0gPu隯ӛg_(w+.mf0ک`77d -K '5JKh<%7"e2Sr4H.zt6,SJb\%4B\ًN%K8@%RNLe-ÅR@hzC`5>-P $qn "7j_Ɨ‚ym57f>ۏ\vn6ds[F>?,\6P0[c<"x!-P+ }~DيdXF&xȞpD{"mM>bV &(JV1&| cp}`阊͞ԒV\v•+•ZϚ\ķR1@B徭9ז si5jYjS.!D; 'RhJfgX^ .L4Hq}ӏ{#&6dY *mZwq6. ~}5֞ZQhX?^j,L߭ۊ xy LQ!ßn nȾobXc0UND8|wd[Uޅcଡ]Cձjpie@O5C~]97R <+ۏ y/4= '(Ze"D  *xG4d(fhi]^o^(fgz%@*,qSRDO5֭>BF@<uOy .E? h1J۪!Zb֤" x4 <R` Dvl:wXb;JchR~9- *AoHo: ^ bϋc 3ᐯ.ws !Mm-oP-ւDbW]->2lk gaJ%%5("O|Ѵ}zE6>u//SZ_C d)+GK/f;G3 cƦ?n6Vpzgf*z ٟ~$a~؜.×z$1obp:1r~\7Dz"-R}].(oWlm J*8xhD#?>MLdb_TmIyvǁtgBeJTh o{ [w=OtsK)<ކbZ!erhѬ3 JۺAvOU8д}}Yf$9|3QWGOSeїC6Rr½؅^=D (5%np~PǶ!6 d/!PruDQȫ)'F+H" ~s"^ &^!_bQe}Pc Qg2=yM 'WZux#KzHM+-TGފ\y+y~7BT_ ,057%rar5])#!Ro: =ڂ7qJ]..Wa}=(# CKܜ[avzA'}TG8* B/,$+,v%CάJToȠJqkL/AĜ==Ԫ? XakiБp qDry&Ne# 88vP"'|dCMgVcLKҌgҺmuԇ,2+>'H`}R4|ʻ,hCDhfX{>葱m6L8G"E%T:>Sb2[(ם|hBp$GI'WCvpTD4+O2m?2r @.%{Fױ/ h{aURz}r'<3v96`i-I_a4TCU>c;rs]% 3AQ ;}BqkI8.ZJ\-^S ˮ̰4|h\AK8_u~x0ɴlPjsgHo2qw[2TFO eyU$ Ld86FH~{q $8W}|{9ڏ }@>Wy94lP& | ]3,amvM`?G<,(YeK z_&r <Y#\j%@!1eZ9:ӳghLIF[ grH4v4vQZzv7wȪ3OV$`#2imQJH/>E6{Tc)K<*[_lO;Eji8bA'A3(D9,pUXѠ:W (iym WtRZR=)`[;6e|kHMzݱ+dc72M rZ*f|.zK8.W;'+H0yQS5c}5C=E"$V4K7Y X)!g[&"#'ɸAyXmoKSL˭*LZݑ՚Ax|s ["t dICb5QՏ~)Z%ihD#k;B{M#lP8b-hM:C}#2*t3Ln'c'jɻLÂI-}@#Ər33>zGдN `"hڵM%Dj0U!CԲ 4oDt(y7V|!&KDs 7UbE_Xyp%OU=T5.um8ΐ `Ae* _3SO[Ht10:mX"!=*/"iDU={Ća %l3`bb3L̟m(x|!0= 7Ezkr{vTOa!>Tᲄʻ3 أm/PQ`:?]G ź+6 pR(Z2͟~&H+oN<'{zFo7lqȐPao70@")g1b,h+ci^SVT ϩeEFsɐ50F适fȢ> U InXMHDE6dXL1y>Fyiå$a wIſJ[=߀< Э5[u>x-#v r.r!\8{*:$ p# +woaXG# aOLmmw9$$ J'c87\̃&e 5lG_*3~M (q!n52/NB5!., /e[ ;-"y=[ T5~taA$w }+`m]S+7jR(fySJnL5< ]UkVaoe+V4&З!D/gdLK [stָzS E635~ơE \*?崓BDfLn ʴÊ s>mW}5z^t,7_F m?t! 7j7WlPwoc#w1sUU"4 Zt԰iM1=;ULk>3(^KLwh^4j]9/MHo'=,%5hSԼ|UXJ`Bԏp|K=@dzF؃dfB꡵N"EP"i[{47y@.s\p YQ=t`ڛeaMo*R2K>+1 ב!Qmz_ə\>Xc"XJ" ck\aI vIbH/a`̕ iyh@Jr qwy^ۛq5%Ȼ L麱W_:yN&cPqsYwq Xerx:6D>ǻlvce ˧3rOhg4k\ƥSXIQb&3GVdQCƲy5pxƺ_*%Ϯu9?v z'g*[>C4Z"/HZ9SM{ɩ.?=iA]djZ;L~Q/M$:rfrVX_N%C\J׭-'5!R&.ԨƸM(D¸_E۸E4lk*r))[! 9,{D~_tJ2rEx.]dEKL<Y=3[Ϲp8Ú#01Dl(aה 2@qf~f$)&д!ߠ^ufJjt}?t""M): s,I7jݫ`'/rD۽tBGdK_n`Ll\%TFM cPGlNsD.ju y ;JS{Dwzp&n) ;ݨ!6"JװgPĄ}!w ^\U8NQ?,>R Pͩ;j>jthQ#͇篘ͿjKhp^|~RԼ/X/OjtbLD  5wZOd4>pSn,i#5x 7\LKԮ%ǂE`҈}N"1ErͲ_̜*ݱQg݅?5 $`}G~x-,u?u"YAbZ##5T?]6(7[(7fufRlo~,1P >Lc:jLۂbgZ` !VGօY"-㶮0^h)Ć fDKQfDΠwKNw:,!,N&m@7+)Q!q|IdAhzJ]thc8Z)(2 0L-黩ٓ=&}%)DLrtS6{nT|g'CÛ3!}ocώlRNviڿ"k0 RGQV†;n? ʮ=s6Z>0=`2bX-0W;#vU}_T_dlF\5(Mվ9}ҨriR A YCfaAsBec`ǣJ@a1 ZzmMVbϤrxiZf}>O`3A;rS٨`ע%eCMLtJQ;G8)Jy"Pߴv +q@bu{虣1ר8$󍲏6κuQqPaexb3~]0Bld˵A>Vډ3;agmi͎}JP1c߂7[3إ `S3)7ޔ68wq3̈uu[wlՍzH>KBd4*i-I%omz.t>V|d$M_{3Y=Fy}wVa|ux);JH")2t_|\Y&(uY[Qaᖾ%fcjl:]znO2Nф4Puu%/flHn/u\̆ Rl]״ڙNOt^ 5W6VA7O[HsE6|&tǧq f ]9IRѻ46?ŧڶɛp6L>UR6Cl8Y! >Y*+аU<*1M}L^o ;qC ˘#gGWxIQ eHWVD S9ik48q#J_ wTPqZۃogvJHAr^JOHj8/i >:<";7^;S5 IB#e#;~GthXq3Af.%L $'W~ MԚ$<UC.LX2ۛ+wO- 2xVYo,/ ݈ؼ od/4Zwx--W~Cއ:@*LRLͽۈŻ+@IP4X)Ԇu6^n9%;?v}QO}$A'pTYr%,A!bgw7pv>}aAiU@UbXhap@XQTx (pl7()l5$u Q>r< g|^Vԝ' h7B\ୖGVg0jkNУZGSXzٞނ4 :ATmIչ69`y_aΖgC;Gٟ4$U|Sy^ z0*?~aȦ?ta Bī_dirZhy` Hu]~l~Tυ9[$sAL1A2^TDYWB8ASQ4?)l]uꮞBQ!vL ^DF.LЩ=wJD+3y^ ΄%] O(FVJ#+4(eIo]pWʁƉ`~y^7ьkC)5k:̴$ Ɓ4/vѫi+>B/h2߀V= ]62&$2TAߩ9;i?S{ąDڿXh_RRE Np2k:27+vIYKn^c}Cmx~@>#M Un@ 4i Rv1#;{%΢_2q?66ɗ^4?kԜ)`r_ְ lBZ )dAI+:@ ^99Rh Jo>~/jLp <.?PtO.ceGwN4kFIqbdP+ʂ F`.,O] tX8e|;F0ģ:!$}Uٱ\ SI/\RMr|{#OW7MOTEGq׉N>$x5l VzC9 78n's1X1c.[wsʂjNjzC[>Ը>ZX|O$r`AsThzQ+~`)RA9` > mтa \/BP(fGZ׉.y ]["J]>|'M1"Ȱ#g|BOQkwZ)}S&s[SK < @Ԏ7frc>Wq>̻U V|bbvd8bVB ,L.o@$ +6ay0&˃M;k,u-XO+;òLТ&; eW'k#ƥ7]jhB/[pWX=5O)L#3)*gspV"AAۦvmgcK1<"{1mp tJהB(v;cT['!_rvN'Z,1PwSƜoe> U ҾFE3𳪠U~}?L_'Tek;^㜿o2QMǕgKܗ;򆙝ϳfwbRtTY9plZSBqq0x>]*CK2oF ;B'͸@[W /I=H%,4)́ufBDi lT*j/HZPmOźdm~{,8%i`r !ndmnBNIh=";ROLٝr/&i*6Y4k♒?~' 1DݦFS:4!~V.-4ţJpK/UtD Ll,smRJ=mOJ$LX uCbCZ\%7lyT Rݒr(] !!֭B"ZaH%&Xiq+-c>5Յw@ސCBzFb>lViqkm4} K-&/iըBԚ)j<1,2ˍK%n>^v#>7W)V,+srf=ڙ] ޙhd"Up.QDLĸBׅXF49:uD䜷.ShV 7kdCι|O؄ $fT1tQ5DD!ʍ$[m3/;zSR*9\8L›^s*q*TdzY$%@2Ihcq'8jL=gu0~V!sT5N oӫ:|/fd{&BuEX bf{ 6K^gWtCy焼Ӄ!wʚQrp0L>me+juzm.Rgi574 j)ן@* ր.4vJ%ZBC:5Q;%|&xTvvA8GV3F6e-{K7: 9e3<)FW7HZQv.^ёsyB]΍f'6EB{oYRNGat SW5h!fF+˼Tp 2k0"-i~KW!"`J@jހi`VBI:$_DQh"q1S36u UM s 5 f&Ƨ$-55 .yA)}ƆsBBÒ4YM]5#^q [Ν*iRqx3;V,qy۰tjgߍWя"0VVoaշ GL^gYV)\c2IJ@yfbyBcW \dG~kXm s\À!nlm0a~S Xrͅɽn1X )P6CYLj\\]UKhS3!\Q7]&NzF 79xL{J5WZF4ňgȢV!@Zs4Y&0t}n4Cn[0*X9_9NJ]uP6fp,$dň0dPJ7'ԦL5E򸐉Toяbܞ`)۳ћPykY pC S@/H"r%jgx, DΝ O:,F]]kl0@*iz-EDžIL<'-*Z_"DF'ڜ)'au <`#iU7q+q;K)OʉrYV1nܯn&tjWM&PvMf2OKU䡩V ?05C)jn]$?FPZ 9I``S/y9@b85;My Bm=;uR,"wAh XU \k">113sr[_mS "ZjQ"DthSD,eM~!rf|˸zЅK漵.眑zx zn'ΤͿ`)o!lNp!,ԛ/ƒp!"=ݍRM(($i鐘=x AZ\)y,3eiFp.7f8[wqy< JUp~.2qu YkJ@Y4  k"~YpGA2_.ĝ*hPiecºY^ )۩εU(T%agvJNƷJ+q& ~ Xދ9&ޚ3e1Um#*Faà1 4(tu<}Il"uxdYqJ-sG?zjFN xƜP^ 4©nM3װܻ$۠4|Ft(J\AN erocaoEJM>2A>I7xߨ2|оՏI~]=,_+"ZeGƒ%0ڋ0`ejAC+wy=)<}IYgǤ![!K^fyE숵=t ($7ZR#4<:?==V~8*~5mD-|@% o2tVS"3J(m?Y%Y7x 䚻{$1NδfuH  )iEhTt߳[-\M?/[~3zU%fm::ǭ$5G&akdu<"MJؠZpS鴴778~hbi)s5Z)hg@i B Ŕ ڎMaTgP@6l̿! SB˚VZ`M(l) ~~-b Cs Tc.NϮ5gi5lٕ >HT X@Ώi&)pb+o@Lߎyp8T5ޓ+oR:::./$8grIL[x OQH\9iO+{7YZ;ٔXC$R6_`s@J}ER6UߞuHbsiػP|sv% YBV8ŨؕwvZF̳o>EivjUfhѠBB&ݲ@5GOI]hOyL{̍uv, !uia簧x,XrcET'tPH@|@I폱w^lm0阝hu磪Z.H{F0wa8v-2]evGT6 .|mdf}z^)O op݂Q/Co.z /=Z-sJj߂:}ׇVӢʪĉvi:2)ZۗeI̷v*0?JRw}zHGE-P>S_[GÇ,3׎v]g:##?k}Ov/9`kNvThf@o,\lrj&/0r&bv~`0y k|t`ߊ!&c(e}#81r6Xt 79gr1|:c&܉-"|{Yv{AoQ},ϏUQ4^{egaH hL R 5 eVLn}K WTZ#94<~ ;8((Įn!JrJr`O߱s 2G ~r}Yn)}q؞u"eA1h }ۂ)!{M0\&`ZܿyLF(^q3XI@81!ѫz:/,صik $PF MoD"s`&zﱗ%m{!PeEhZ*KmQ%!"jHn+fr[S`G}ϸg 2Lex32kxdC1T'1=j ψ%tb|~=& %ml?nsb"ifMpq<0J.)dӋ~@>>Q, )q2k┢f›yC.X 9Đ.'6.Bn1rѵ'p.ۏ}';1Xٕ>"z}NpHKi7,V/"s^AC'Ցy@(/v-JV"ޯ 3FîX;@%? b9e%pah~} k/M^hykpuPh5;}`J3)N\d^; e瀁nW;hV@yeq1)󧒓 u0lsrD{t -ҍ{SɨMpjI^iJW Aka FVPY޵Wg@F89{)p&H9-V՚m=N?P ?K"BD5o͚u;bI*r|-Y(C+p|%]-m~N{VXC6"PAS`۞^naF"XpK)B45#Kc_9 )sCHn8V;!:-K¿ۥVO$; 9J}qC/=*8*T/JSA2mlaՇ@D IKK4Lf(ڹUv춌fIED%P @2}LuN2\juӣs*fJ|9^<`1H^P(Oa#mh=!r5j;p V?d+5ꌕm'a`hdu/IޅeCp^U¿Y*^w)@,tS ퟛx sA n=ٖ`eƩbaތ=&e#QZ r1?Ef͂&{)GqX0L_S_ 5o"] F3Κwh?BP.}`|M(v*Y/wG5ފl yf-Q9Ɨ(iJoʳqCS6w|0Q.& D P IdBNh@RPNKI~4j`Y1󧵿Al6r9*.R$q)#/\z f YuV(w5sYS;ɥէ^,v^{5,rw݄Զ]KY#io+BL?-nF4ywIvIԇ*tg睒=Tf7.[z) ] :>s1%0D6_չ>B(%:3.Ӈun<THZ/4wj4J<;JxM$jhhH7Lmp>Gy_]}kE[9ɝz(@-f'LB*iR&x$"@ШCqx#m1kј樄rt.TT,QR{UZʑ8F˵3_Νyzj|8t_:f= <&4eMxPwҜ&Nݸ*J-HAz, ;kT/cq8GmK‰߃UuT)]j+hˑ4J%e2όFZ3yxUɆxp—xLxu7\L x+ʱѰ:jcSlވj)ʆCIRm]JJLNag_6#7LdL^2k=]0C|ScY _;.̛m|S셋Nr+nlxHj`-͎~P/U+s~KT?@Yw[w钐ol"] C>9]b<$EIny[LJ˜``,tPpmf e⧭y?xxN[47XQ4 'Qk pUZs.Ny"C<*6WUB`1ͧFoB#Kh ޠBcI7s)qH#OmH> Ŝ(';m=4= yփ9&#v&^?O]oY i38h%WXPFsK~D\fU}.t$X HO`~Dyo7zOd*C:EC}m&`:xLIu9`ΑtXM]L5:J̭7"3[ƪR-cf}f5{kuyb)V閦a9,r4FH}"WLS]z>Ib1]%&coe3A8Ky45nɺ.NXvIaXP&R4HNJƩFCV@;!sEp `Q"; .d+\vlQm<Ȳ+>|쁘:Vi"?$Hz>cB_)cB/2-#|x9d~GkW#p$p@V 9>±~j՗vsE#/|EK8~W3t2 / .„ O mI*2ӣf"f5y]b%Oԥp Ҏy:B`({Y&j~:c稲]q[.B̥8Ow0MF B]IgQZ7_uAPX<82f(N#|yR0;Kio4ĥM.+͕UҺAտ:94s/[#,3&%š(Nx=:΋~Z_ga/KqzEUii_!'C kCx H=SS]x*{gպGx [YQG;f~?B %&Κp))@b,t~U}0g׬+&  Cg1q eZR`;84sf@ӼngxWk jG/m!}(Ꞡ4XFCgEѠHbFߤ?{/-qPu_[S$Aհme|+ \DFiDecC#^58}ė_Lj )=f / JtEL6]ѥŖ%ďP\2¼t`) 45(~+Qfi=}ۘm^__eb iޟfV2.xH9* o7ю"*mڣQzEWFO0Bu CҒn}jo p,'#koi?kM&֙UguS۞V 킔J-nxonN IPԇ:#e43MfzGIw`M0-1gueN˲~zRŎfD5 võ~@1"' |1Xy Ֆa=FHX=m OB޲BVoT~ݤ>6]L6f看r*pi]qi4~ %N ʊ1- KƢ>a/$c foGO0*8ӊTxXt[,ݕ,mĉ ѺB$))q+)hRJÃ&DtM凫*Mz(Pc#=(țxNv9ޜ`(ק]FMN|_=y0]-Zeg;ӗJ9,[.mDzldH<ccQ ]_xVIַkfd"X(MY%1y! zfg~za !tkjJӈR4y\TQ'`Ɂ~!7 8J&5fQC͟ܞ&](r[DV|{.8]16?! A8:}LCS/bXj/BooNYW#CZTSkôkZRsӡd&# \=v[< Ԫ=VV D]3JUd6B$aTP{+n/󌳵JDj@yH9Rhm[Ѷ-:^a#}:c 7dzSHAv mܲ0Op[nXL3\Ђ-ZUQ]P(bA؁`wkHE (_ L?I釫g3ET:CpG/>ޗLh) IM/ gV n!Jb_qo|wtWg/܂S4-#_G+ }gCOy{ԅ,]yFmS*ŋ弎5jPA ѓ3;8e6Z٪OUy wW+TFh0s}B9'p+dTvWmfF]2Htd+PKZ8z0z׭+F}]ڟ;ާ;p#hmrDWz\fp&er08)5gSD IzRP)YvΆ̕(< nJ]O9ʑ&u۲M/hM3euxEvW}zu`'Xvz8yc|4E)4L#8!$ q>N݆'h5nK;E $`YLEᅾq":j>̯ w|}'aP#*L P!KtzO ,BS.PÃۥR~ډ,i5ZK1SRihgo&8ie-. 0R iඤ]mb,,vPrh.7t`J Mk,Ѧ“>"Y_Cw6cߺ9&+QsB\l7 -isTț7)^nҷ,۸Wy-Փv PRگ j:g:|ՇOIZsQGMHia_Vن+^LWG9ZU)cd1Ȝ% ad !-GOSB4S F~gTl&T# i=z65z~H G= >8:q;N"ZE;[ܪd| 2eߤ YF%Qdv3YZjˈ>˹,ՐcN >~j! cc͘E&'Bn)YS 3X9 B*U!gvݮP{Z±7pCn /fEɰ#ПϤO-=b.G@꨽)Q-^P#ݰyBCU[ER0ctt42?+{& 6ڭXZE <շ|dF`LN'>BMޟ<=,^ q|4|zcu'2Y&luZɲ q,WzHjzA/U~iEsjVPK,K oiJܿ :g)tZvF0of2OZ͡c] =I&}g6h PReKomvȚ4SUEM2.yi::z֘}^bN WqMmto"Na3?-~7´YOmssQw ּwllbfEO)EM2Y[7֡L=`I `ND<Zfo̕@!t ?&FWI:4+б9]t0;,xKOd7R"Y [\OU᠆BIfęS:4c8.<%T9 (eK;s)7tYS&uv39" x CzfJe< &~Dͩ@}N ugitb+o' T#º^<}\K^Y+VzWD3vS (l}0Hf\ct+[!(tH"SC3uL  !2Ȏ3+/2N`(QL3DwV2o "f}| 8|5yyb֋nW' lˣÂLMSw#xPGQo* yU4^v:8l7vk!ZrsE|1z\&x?UjV(^[F{ ;̵Shȇy}myiZlwC鶆'L+NnF)+%.&YVKh*4n}T{ B! ÍIMi/\|{}crq]/EN`)LD5TH[A(L&>Odw>@QdNd:{eF_g3 p)3`&]{;DlɿSoCpW4 Zfn X֞GSw1L҄±xfDNr+u"5?;Jl/3eO4R}Y5QR+ˀ.RnLs59ɖB|muP~lA)kT4aBmy%?s* ܓZ=OPqAˢ,PLގ>&J / j %AÀYc9@v#CGm/v L0Sfѡ%0<1%ڎF[?B"-`D\=MkJfH:>kG'h㠏NB3Fb)2lFPyϤ]iP1sʹ6_$ yk.6hF"KOUÙ|؅َAєRM],!,#/&'BL0L7_,𧀫GrnX'+(lΉ>Y+B7arZpW-Newvx=k行kzLrhlIlCk|\3_ DM iO5 &[X.qh\rp{i%'tV ]48^ 4rLʤAݻ=2O1+C2rgIN6oo#e}|>9&slՃhžs?5$%ؤslli{>N~;2@O`׬DoVoho?z2ļP3Hwj.bg!q7] +7E(ePEAK^/y%L nL#C\ ~ W+~YPfk~?̈́iɑ†cCW`Og {|Dwxf6],K܇m{R8؁{)-c'ru_,kRc%6miDW@!łDsqޙ2sG5BZMxO$'3 P_D#kʧ{ M'+9FXC|u}rJEX1@Reld-dgaZ6[{eGZA9Y}oѪʱ:=}[EvS|r 8Lb~Jr1%= p >a._j)l钢5uPHTd$S>t{JU/4);p>􇌥y2]-G'TbYUh3M 2}=Ƒl쎱Z!XEl5c*yxg%@24UrlXOxO#c&w:<(cZC$%|mM +{HBZ؞rC|x%Jtkܗh(ht RAe-؄L6}'}we~x^ ,GD|nvix8գ{ P8k|:@q"F?}'">&"PoT%b݋v{F1 >6D @'b<4p'pةjpF 2C h F;>mDliWNja7爢8Rtݏl/C- PY˂ZaCi=ykW6r[).eVÁ=h*[ ?s{ky+crE$s肵yoThLpdk֛ZV꾺i'R'ZAky2uhgG,b臎WcFױW6gPTxcͤVf3{%1g͌S߶Q[S?C޳;m؇t_m6߿ 9Z jrx-nx(H /+>b +zjIdq˸z<0+,TǏ3!0纬nWs@Zs X8e 0Kf=b MYCWsB:JQ76^(Ƭfy3CWaR v>Ѣ2\oRR5FuI!(x ҥ l-]Vc`Nm-H=]g7V}pK3SW ==2UO<1es/(la?k 9G}c+_ R"?KTqۣVN& `(8;_,D! ñmGI=A Vx׷A@p C=4:Tl@lymRFE | NQaU|mw; gR{?1V}AQ^Qi^gg]L+P Ib'G0&>_'fd\Zg9Cj4MJy-Zok=TO9׻J]Hf}؞S@! vWJP '96X#P,R2kTEv]vTZF\O;dk#B,UU'Cenҝ$c/.` "Gnzl.%|3a$ݖRcQ٨{D`!]am=@Φ[{"Dk'woU,~uAAn گ}v ki=D4NMKe\tNGݠ emWIąu"``Py@kW9n}&rrouQ5{ټCkMsQ޻YrΓH*V@j…Fy|F(σZAx74$M ]jfIIuV?eVQY<2]|C;!#ݶg[[=ƍt|ipD&~Y "DW.-T160L]ȞM k5neYP/+㇥(.YGUwL|:D,X!ndsmlԖa`*h }74l;+ ;oSan8x Vx">k}*QQHϥ@ICnAx"('3؇-]RSxh@(aZq' "Gi(1J47)v77tDO,'fA F `BNH/^&ՎcmAg\*exJ/̏WʵFA펢P[SN8VT2My@f$[%钗Ӝ*໴KGUlFAnB5%T ^HM*nK/?7ӯyCr7)n9. ɡզx}!G7"H9{bk:ZxDx n/C'͇wIqavcy#O;).:E98:+~"cH 5L?sX@!Ze@imP&loZ0MM@b>|NguNA8t|'x҇;" 5#9o7ܧ}G\$oxrnZ;%rj_3@Ӆ59+\eX+8_((r 71h0"˵?bm9jBGv+C01b ;GHIω5M*gz[) )zqGb&+o0d^g"d DXsc޳'C_e OKtS4@GDٝ`HxCOmm`ni#*G ҂u}+uJZ\̼ԲVkO|p_-9Qq$$m3o'3Sf-!\r}_k؝O=Ayʽh@`ΆEEtf,i,+3Npbm.$[̪x :8P%pvqe\܆C4+{7YE#+eo>ΝASe(}*lcHpqz՞k|RO)]u `&,Ls7-yzyY7 3x%SE3ބ>c.Zh+1tMJ:011eWj6e:^ْ|e*^6 i(UlL>UBI*͈t˒_f{y5RnFJBu~ϑvGY@{*<$5M'!)pZ#2$]IQq ک5Rk]YZ|!pȥZ(#^LuY~,滜BJ -.qfm<>xa-:e$0niSΛ@կD+$% 6jWz2 A 1j7_r#97m<ʰcX<Gx~,״v@P󜑎fK"w- {ecFSp\]w= ygı|YH4">5,&M:x)p<%a+v>*|;ȞMK}]|NaRu–ƭa\jU#݁o}3Clhrh,# yY6! ]$C [s4eUoaw%|I1tv C+)CT] lP_#4vyyij.٢1%!91UU"Ӫ}bBZ\9JƖ+Lo0AM;_8]V䋽v>glBtwX8*7WLU%o!O&fS~R$UЍ&o/J4j Z<:ѕ"UL]2%H#TL$ccM&i Q=jAhʮ)F^ .nb-|p=OtPw* +%mV攌^,حk{nDLY?tOG7!}pk"o}zt'P8[3_m9iw\ɏL{a|0j$Z" ž㡂PΉNH@:GF\#R5$Gek30ఆ'300 iSQ?q+֌Ӎs Q}eq0hIO MO b՟#d^rOf8hHOHFlҴ`%/^o>>ey|LY^j6__=qxp %|݇_!0os`y,!3#[ř4j,鹩ZdR8gB+{ܝ'G_[!A-'>iف&]4F`E*Mcb|Ocg΃R^4׭TO.VU0Hp$"BV%6~j%.Q6LU$j[3~ÎLRHYpO;XϘyzn6YCMd)#3FTM-*0la*&fo  $-9;%Sb`|4U˦nvS(kOtGVmJXFrSje*3җ^HvvV1cenę|kϴf"lzfܹ>fZ0෍/S;kv% x>Hd?? ]iOnT9^si! -y2fR鳼P\QeZar8Ta#JZ҂W oTR|YqzIwej) 6G,QyOÊVz[ruED<,fMxWLK$L=3(6fNA[ugL[j4 D3hlDžWm mՍYqI6ȋG3"<ͷQ>KQsᅸV$NQXyBmJxf .:1zP7\ӻԘE EGGD)Q1V=N<nƂbgLIGsa1À)$ZOx޹}/&k~V1,'NSOQt/LZdyv5vJEk&#?] BnN%>I@01bavD֫L),v=X^JՅb./KW]a޹O8dl@09qGWA=؃ ?nBy>WZ~<ʶ!1 )?U&b ?8;.9 DشUr 5>&keY8@(9x9l}o_6I<&=\a7ξŁK_ij%鼉L69h]#3VQ3 6^)%F\rXh* 3K20^N!߷"&G)uHr>?yx OgV4Z/qJ HB5aKCTDRcOv @rc rٯC\^ & "r?..`c 3;3wCA4y)V;*8EA7]Œp# (ܔ*l #z `\ 7ϑT]ݨaHPRTl]V. fXSFɷK~pe Zbu O ێ'ˏVnq,t}&lLCeE5'"C9Жkg(=81bXhCDΥyVG02G@&R;aGz&K`HiJy8uL-H::nLyM,bT^eX `B%Sy.辏 :I)43[.Gd.,] F A5b[@ ~Ռ tu?`,eA-JRMj%ä[;CN_` zuLk ԧ};u$ C\ Efb[ M<'欔iBG.d8НپN8l€K}yFW? M n_@Zp GRS;74:V+C[œ E9yso6ϒeA[;RK (oc,˪4) \b~ @zʜDX$@H)h T z+ طPD%yx,ELCLVpW?Uėcd(&pFd-ѶKVބ4 XX|wS"oG7 تi?f2 J$ɧ۱ qn\9)zk'hQ28Y*1VvZʪw<=b'q XTSfC)_Zuʼ]Og7*dqJ13tY,Pp<@=B [>uڠ__JEFj!vRgm&kJ i$T]sjξ64b &yzhծ"+<4>=Rڂu0]jF&氢xkʹ!v#}till6t[P3k ~}&U761aN6lVLo֎̛kr>+7YdG48=84`@ _ ? BMZGyWW)qy,(LZ&.lPCwZNv預C{#-:jH! oò{666wϝq5/@LH кy9mT 1,7x7]m IU1Oٜ66D^&5)IzmԱqڋ8niiq^a9ޚN¾/-ҹ1xRcЂN,KA .'I( mQMi-_אr**hK5}d9_ sz7&YNj1ɝaX1/lkE_(=uR+[őcJK<{6%Mߡ,ߡ~zv_F5!|Wt:VC8I٦\{WpfIr, 7 F \S3[ _࢞ qM=rK>|lڀY͉l5^|5kWQ?mi{%=]utIȠFp*B]MS+Z$X1s)ov,8 `E" Ša+N)/#fƝ~οd'i}hI;-y! 46Ȧ0j6tYvrHxUW^@o2NGć.N d'餴b="+x%|yZ3Mr)_&c^8ʹPök-rq{)FT4TgeX:ToAg*`nξk6oPMuTB !I݇IOtalEP GϮ!9>k G}wdZ q'kJP{inXZAs H Ӡ [Km ?Lht7^.ZUteĐ%x:ykAn¡jOܡ.MStЦGc' h訍d2i`EwO]OAGX9iJUx/%J  !8=dbPwoZbYPIUQEL=NI`x($8+l-T=:QGs,7Zo;Px1a*o"'Vn?=6@3Wvy\:4~l*\ HvL?˹;%=iNrO7u;8r;qT5Cosٺ8{lvjE.֩U},J1s4̴˷_#aPk&x$MQ䖗Zn$Yz0܏BaӢwjÁm \Xԑ}oNaq%l:8ʁuƜ KYNz9[.M1ңtdJ9SFWH7qSe5[c|}v0]3k~|.ydSWp$ӯS,AGGPsqG}e$?+Mo:6(EN5vf'uӓ/)w`@u]*X:/.g)*))$5@a^LTw* тFs "ln0mZˬDﭕÍ4aqk{^oz}`@f\Cnz$ 6y4gKi N7MϺTovb) .Qj5qS'p_S!mߐK 0@)~ki pX+:\6 m.vG{,5)$@)qJ ~,T)(k18nk$x[t<#i"E8sM&(/~r %ڳWjPa J@m`UԀm?ŚY6NDNM$ 50wF咍Pu̬0-wVG] ɠu`Q ~ÄV5jB,8n.mbZSe\%Ö1#ׇ̒GX6=Zd` ߏgrJ6<YL`@.[CPHߒ \u9`:ho609HgcoD{:E$t5-N-u̵<ͥoѮ2y'Z+ᭈ-\mux'ǍuIw+ީcwwv3gKY73bcto/^hRrf^J,$7S.leM>bYZZEL܇J.ԧOs]?7Ս;]M~HXDĎ.B>K>oՃ{'sm@*9=9~0P.dyDFFzOr1$B~%8P7 A=3q0{n֍aX2tˎ ]H%#ed ~Xi,t<\qOJUG;z ;;a`<50Tgw$C/:1 ҦV;@4"рfz`C.]ЮOc*][(#CZ@whNbE "ʘڙzؚym\Vh06ak菳$h+A@1q䆮nzϟ"ǢEK0s9 ҍz! ,UZ?e#EtUj<(k`HFVDT t)x WiPGtkA]b0jFiM_iƥ BJw+ݐ_ &bHԻ&xgoTmwY{#Ϝ ;LH2KL%ci`7=gM}oiByEb+a@l$5[PF]&ù՘ BUy4pч#n9Rt5Πn"0|zL=',4ߙ([om‚{s&mݝ@Kze-V \E۱zr6=|̱ނH8ȇ2t ’zny qU a/)5is1ϕ3xo kn ǥ6z끻F5/*?C~?mJ`  ēi' =f+%g* i1De/S^ K_cH%3OIhY*̊Sj9 Q&bOp>ڕ%~+srS׸Iu%HΪ E!e)},Mڰpc6ӥVS3F)Y_B%;i)H cbQ0WPp>C'u:k$Ρ!y-71q%MXkUq%6*ˠzO`C)yHKD.Nϝ٣䣅j/s 1n=u0Jqd5i݉z6]J+}M Q1$lpL|\MP$ *(ZUYغ:!v0,Xԁj".*OjÈ 'ZK W+LiA񀟙8F%d3OUMT%<;bN; vX640MtwW-%]Z lRp ^ jP(@ S 'B{3}tC_C]LT8/4XPT 0_2](?^Փ )- D ;oTO3 |HdT~-7l06Nd=BɛDU\?~i]2iH-7e*o/@֗Dڶ1B-+eWnD.`R5k橁2)Z3\(cKYج&x =^0e % WV/?D$FJt?+-&?LSĭ+wĨ 6[ܐ3rzΜ^Nu5zFdvCr0C:&e: b?]kC5p:%0ռ/NPQ٥IC NѹIVRT"~7RcSRputsft}WX 7vP*־KlMK~W^mU(>m[!؈N-̣:Y`K}FhUة9QF mђH ~F?ܠ񐷳aBp4lo}}{ύ3/2Mr*e9k=`7jz=b5 YbQc6s\FU+2ΪR xr- Z87"kPvװ&1NjKڐ"f溬^>S?oDd8xEAn +PFCS8+aQŠ-T8 °H?,j^\ݍCUө8$[6*U$)YǬ!9XsOv#N(1gR')J Ti/(sg2AX$j}ҝnLZ:96TR: T񍠁sFoK5^?><´jub`is;HhجEJ )V5"aAns1sra΁ȘBװ'V߽m\UZtݖ'!gp끆CsM6數fk;(d:4um 3W5N,ƈgƜn?#lljCuA 阺1ygqPK_#80 0br2v}щc]un>ׁN.i+&20Am _YMIn"+jB &PUni=&X/򰓂qz/45IRdֵ6[PۮtB-7[W)dKY8fl3x `ʌOA!lY\M95OMՍ$,xלD+ I:Srl8YB;7BNX~lZIQ_w9%*xsEj(\ۣ;sꀸUaT*_uۆ8(9Д7$ HkÆ&2X\򇷴.}?g:FR=ᘄNyak%@M} +ԡYCN⮯NT i_+* H"ՋϾ)rSy*&o aj)7FP3$ T de q?xP&`".7wWeZc rNn@ ߁w)]T(X)/H)u#޷!dnOoo4nat zLJ B j~4@F\Ƙ5&RcATZfcƅHG&̈́KZfxl3O4rfD mV7=2f2n4hUmPF‹ &i*^?ЁU?U3'ڗ_qb`pWgk {"a3 zݷ^iH-,su;@X(cߌ-kkiY02tCitͽ0֕[S+jZBfUVaY E)g4K5 E1Ġ]lkS=1Ou_^ⲟ$} )> RH 'KlYeTkC |/te|i\4~Q@!ǀ4?/7Dwry#W#֧V$JoQa:EsR\ kw)@IHj)q'u'jrgּ qb*-HDl'/@lP6sԚbߖ!⻻`x~EkT ̉ʵ͂@4zT&NJ9KQۉ9euvh!+X),o'׃}'k8^'L!$="&ew/E^5 qܿvRܧ4 gC$ivØ ~D2kyTST\A?/$-!naNV !,{>PNEx4#Ix-?$M N+47xSj㳕Îm =RtàisS~A.Qr-Ju73XE>9#8 k)p-/C>* c {|_6i3 JpJ2 ڨmb .o2W(ܯn}.Zu1IlH"43\ |6y.f/ /uB !?Ok;n}jlGt) u݆/iv} cRFkegFSƉQ>uCߌWWltg:j ]!`"> ̠]bl\LHmC.5m1k XEn34Dcvr@(T\ZBT:#i4 d=Qu31KFoΝuvp4('ؠrZN7.qr#&mi`39 sQG,ju^ kbvAÖ*v+arA-:lt<>cjfQP!Lt+e Ka}>}6 L<.DX"#J@+ʉGlƒJݠ&zq K~ՇT5暗dGTMƈA{.<&_XP }C[>g)o%(6GAFG?qyޞϪ0B1ghwxڿbaHg>h?Ssݍ9rq?h==S|H5t%3!azAyTt8eԨ5[P]gw ~<\SnI ~xNSBZdF:EěpfhA|bC+YwTtl BWX2t e31hֽ)oXG.;߅}x:*ǛA_ɼqMҬ L^g2L-4_!"=16ruQ;mnް: 4$rw\IewѪ+\AEع?J m8Ʊ!%hئ>:;p2hl ` (겴;zaCv4ҋ:pVKݬddv&Ya$:v?LԷcG Hlwi~V8kE%|};XV=)MyfV 5c+}DyXRN潮ʣCOn~-hO-s::ẽF1t\!¢|3aqIsa ~֗)WnbmJGgX.K/a1~صNht}J۝h" A*#y2^JYa yќFNCV:z`9AgeR3茎Q$[]0{ а:b$@f"oo3=P=AXW2{Qh}~A GÞy2EY$rXjIOeYp*-_sW ;ҿv!+p: }W R ;XaITm+1ʘUKS,~-DVmtxB$ыY!3KX|m%gPo}s@8qZۓN&͟!g=:X.#7hܒw&7%mwai (#xY(\}'rȣ,]|!;ӡ:JO7bZ^۸Ɗ86@xs_`<;-< Hq4k:hca{U NOA^ؠxÉ>Jg0\KT …B'%.?I%s2r7 $+( ۆ91jG_X60 m&$L x0aLnJ^$YKfx=w1v Mیl)2(,5fd?٨[{Xֻk7wf]!cq#tɚ/M'Tew5,UayKq:7^I;ĨVč^fau]X֗X0F؃"hQvP]۟\"729ܟh O۔_vczq{osc6cN ? 5F-ʾ\\M!ҼhGR4}ݞPDn9.sX ɮf~FM^3}`=Fbi%\:xnz.BRkcfπ{>^"/hIx^DُغiO[S- !D<Cpx-pdr>j]Ͱk^qu/p7E'6|tWtQrj(4WpړHn2VJ0.W I@guL8bCowD,L[bE(#0+V+\bA<4#=,3L8J9gZ c@{R|TC i+bV %zF$Q|Cި(U/30֬գykbJOR ΀db 4^v͛{KscIU#ߦ(Ddpj@PИ̡Alc+~-bp0oMخzzAl+#3P2evB%F@ŽnUz -D{ןgPTir@QzbL_sr84HA:Xh!z^xm18k?)?Na\~޼ƿq /n[*mi5w9ӊ'bN%5i'f>X4ykfж7N}l5R^ Sݧ_TOC7fZ|X?0{zdKYtahPT"`|%´;ɾ=Te(Dp$(>ș?ʷN{6{}ӸJ/5i_=p\4'ՄBl _y7vQ9iwta_FĔ%4K0.ϗin G=0Qpt2ʅv ,*6`waC:P0*VϢg1ynɲqd*v^饷C*$y[#/4wبcs&-25 W Q IxBvH8<cCN)&Mɚu[8ZJ=n5Z}[&EkxZD<%xC]eaf  /1Nx؝Wͯ5wtpt}gɑ3Kf 8R.v9U{:t37°:t kqsƪ3\=Y?A%x%889dP5ZIn0p`ΚPr__9W~|4n)vS"|9IG6e3tOF8߲3ѕH${"WW&Ӏ]Bn=uzʒOq+?П݂U}Qp`\zqgi ͜8f%+W= ncv 4Z]CGj(-}9Q,bŵMM?\Je/~z{%LBx+pPW|!2LꎰdC6cOg_ 1z]%'7(n%tJr\HK[cq }T:| hD#`C0]ȮdvBWfɘ?xZ3 G/9 ]ļ]-DŽ~rQZQpwPQtWċVU Y bmTO^G{|sqi RyuHFka?1=NyF?D03հT/lТ%;:yv*V,N ޑY~W: 8sW;jƗ\iWҴS@h1=呐 oH54pglc+k KO>ָ":'{vgWro vj7˫}&2ayBqIML -EF挅vTl2e!6hH~pՂ̱YfU`Vkzx%ሐnni҂NSilQR5V\~\t~S}cKֿѺ T%NiW[6j56C?  ׭:" љDZ_q뚉Ü# ոWEmy3:W_-o9) zZ {T,9pL3yPԏBJPrq7܂t~̒KcWXg:\ϕ*k%gX~LUF|QPyeGX]QW:;Ɠ#hK0WkKXCȧ2Z@P0&U\1ڧm`N,-NEeapNRјPq#OfoJLyŊo|=\̏Q7kP7j*ʍzi[S=IdQ =`Wz_OB};$TF,Հ;vjw.:k>h|rj}.[[m.#BIYDdj@~cmL9~ΊRߓpLX(b-9֨# |U?s*&rg jWx@5l`v2fZ=qiJыm"% f<@ʼPůBSII`Fo{ ;]AA3KIea9B1+Y?$n~&򻦕nF5HY~K5C%Mj S搛ߪb v;"K(2X*[\'Jyy5"^*0sٟûO+?+{ +BT;@2^n13.tDXAxldm& 4C'1 ]'2^=XP~]*9#>0h{< lN1PDK#9L";ygn.lvPW-y/ ox{ *cҲbяRϢ&ą٩`XpF&%GFɉ#XޖK``HŨX<ɉqd咁LΟ*""Zy-mJQe!n$BjJTsy9m}vZеD"ֺ:xQV| J#%k1 5 3)ì kZDZ+)&H [C B憉ɱB%<yp~D?#q ƿGۇU?._u V /xt]k߁HU;kRE,)ڟo(M'>Xө ַ&P-Ƿ@u뛦iP@ăHsԅܚz9VtS R0+#dMWi|&NQSm-Sv٬|jTyCǫE#-"*+[Ĕ^Ȼ15W Y%!B`$0 DIF7p>h]}V ^fuH앾b@ Y˞7KÕW?|1mD/I̓`$ :O+a q#ءDd?S V1Sv,a#&o3MicGy8ߕĘoT½2 pip5g;)^<>౑ w )NJmD"vъnRیpQ*%nTo[B;;%JP]0:ŘfRO^lp~bo`Cܓ dU(fOU{Lr8q#3aFyA7bSh["Yq\nPxB[bI98j0o`'\܊xeԠ{vn5E4]!G@$ g|-RfԆL{m-H~}5/TOç>ug T`iXXkѠls6}/ 0|7~cQ n-wM=AwŽ_W 12ܙ2:'S3k;t"G|7jrrVk@\ Q?`~3oQru*voDccpk~? PSݛϐ'y9f1 zMsM?r=W k4jGE*yGh gq9 K݈ o#oVԀgu})FYnd8}T~+MP~IIM|-*jC|.t۠͡]6vjq2:93 XI= T7˞i2ryjy$bz\)A>D 3sOS-!+h:^>v&n ᱟlY| (‬ۇ"mGr75E*U=JC>C$ќRT #ȣ[KM"Xl*SPm0Cs $L$ˢ6n0,(6vr #PV -yȜ7YO H\uQ ^CX0 !/K.A8VǺn &,Ȝ1݈퇺ӵTDXLu#Kþk 6ĖF8p1M쿬jIQ:ƧГB&*an7a@#fcC` oU,G6lg Q; 7~6+r /~(I kS~}3ijvlS"BqQZ; tp3jk_71ZBMf;CFD@wpJn_]Gʩg1*W9[Ǥ26߷Sp3ͩQuf;>I/9EƓœV)*h c'uLCJ[[^)2d1]U8R5=uN .h` GOel/Xں>THK$keu"Ε>T>:]4⥌0k2ʥo22P .wXhOZ "8(Zd壦/!4=UnIA #i&E3qƼ(ĨNi?4}džK:H/]#jp^qlm ~A64aӅEi^E1ɔojMRQf֢LIixNX=FiAm`x&0cA.e"߮9ڢzͳZyPD ZŤ@`ߔ~d(֙8j8YQbjC>.6>G+(EWb&6Z0CQOBW|S `utyA6 ~Q>A,΃JqQˀӉKqGx[6?QM@|/@ae]MtsѠVj@q(__@!Y.A,ʕ'}xY^EfŜcZ*:faG6; n$277K9*l%eekrٍU,?ݸ&?&}Z2M#oCJk($  Yn@_C14=A|>,zLH\.  /4h,EY+j=2'IT } 6TFl'[FY8-ܭԏ.ZN F2%q5s.XwQdC0=ğW~Hy4̫ѣ|] Ƌл>ɑ}IWyN:+w:MdifDc}'-.9t#58ƺ!448$y7=1n`١46Pu] KEƖ?dCOerj>kX1 ɤ*I&C.tڨ=FEu yZKљwm 螺Jp~eEH>8ϔx@8 d%P 3s/.E/I404   T-_c/$J?+Ëm/ ;]rdkDAK?6) =up+eأFi`^P4^udInĤNUDEƌqòGiS8s;eƧz&bSc$}ufeW@9D+fM͂YK{ kX`p;E.0-XT]ȷ{TCq@%:09ze6v"Uu_my#s c0Gs8oV4:jH݈PVQ4l8|6@ d#LJZxO٥]h2+P܌6ticWꎓ͗ `+9z {xhEƩa*Hv2Gdk2h=16:Bgya jޞ^mㄈ,/I͔$Њėx0Zx2IY4Tgn`]Hazs^]Xi-T':.썃"V"^MZ~zS;L\]?q=[ ;@O:N 6]gȹMN~O_%$^,n!~NjWUū^Kmg B./ޤX}f v 3$gD"}vC-0ƽA$z" 0Fn\bhTT0>[j-7}f>e-X Jk=O/-M/K%|S ̨dxV\ը(]`KI!Պzqо֚}"0=޷\Q"v+R_CS; @y|dpk&AIXvs;' LsWʄhafb.2[!7HH*SxҐm* $Z >2O9 "^~Z:fXcW(f>ކ,V\"// ؟pBǔt} s;Y%~_1_,лZբoryzI?wsjIw?Kf,v拿7e#S'>vey5/!'2jF8*}eIt͙ft2P]fW&%xِL4oDPB;Tm+=q5/a<!ӎa|*TȢDZ gv%k @J- ]00Et4C.Vw_ϿS4n} Dc=9uUL~O6bM+[Y}qN?ו,K-4*<, H.;g 7uRlo }tГ YXWKdJX]|s:Y\vJw11~IT+1fNޯxؔBWkoаn~/lyz_:Cn)D,u9`2{ !<;c e˜t/`WaY\`*h}nO(HBGJ(pBoǁ`hVW&rN~i`qϓ4Ҿ\:|<Ũ%Fᘇǩ>t伬|<x$͙613S5AQP^PA^GN,>sI&^lNtCҢƃU"HPW{ƻPR\a'!bF]8YOlu: \2SCЫݞ%zdQz(8iF*@ ,#Ao$arY 1ldicEXVBgy0hhQkq$TE>ԱԓϷ4h=xO2{9ȎrE=CۀE}c'𝕛|{ ]]StDPl”q)l0TOſKUA9(]']O[X` U괬1Pc-f.|{<`X{g80dUMey-!Lt[YAC?m"LS3뎰b g+$yn;`o!fL8ÑMЏ pK>vF_Ʋ~_N~eMtRN387FFʨ=e . r\?yqȵk.4?_d[5Ӫ/Cjg0e}*e-#p}Rt58u:÷7)?j%*$":8.j2@ "lO 筘 ؋@U/LC^Xx!g154`GRŐ #XgHƆ*)_VyU\ZgDD `T y߅1Hn%.q>ՇiU5(:1P DX[fYLLt:y!091TjEO1f-xTjE#4; a^-ɹ+VON=~BB, $|5VB-bA1jnS]aH}xj&tƊs*|O!mVϞ);D ){-8Fr {k{,Xba h#k6D$s lğħkţ5j ~-FA)ܰыk t\Ab`)Aɳ"NKrM#ʉ.ㆊc:`漜qnnW^}R8gMWu@! kG- Sl)(7;YNHtCKM*+[HkIj'T'CLoϐ>}gIc!]56) E Y;Y҂GLq#F jۤqዱʹ4"?o-8 lG%iO[p Ȅ:׶BazL1z:(|>0gi0}B#cU>Kh13L*78Vpxz̈Až $/e?CGk*S'Cۤs2oG~L?X1X3BC+'k )j[w6kȪиpHOnQ:/z/z9LT8STmo;C4}tv TJ@|\fw>߀^&pԚOCp%}n]6s?nkT?Ɗ3ƼTjdJlP9TTӲK86Llíȵ5f4܃d/f\tO09d{1 | aO|_$]'{h}t*o bQɚ+¬Pe?_ W[k2_-To|%d Z3 u3"~ ަ*+dm!Y.Tr¶M;de3`'O2Yywa0nz8*R?!|$==x\` k[NDĄ ceoG᪬ Fya-6U/kyX:Hzd\MWi~(gQ^9+-r -ܕbM''~|rD 2,3g8LS;[0x@QK,k+en*焧z"3YOeշdMnWxԈ%5.Sſl xQ{{T'VY Z1-d%#ߦlloŋ.ˆAg=-0tN@ʙqL'ң612&%3 [ 2[hV BϬ,Z,hl:䆾)Lt[;x+e N5J+# ԫ}icꕎ&dBL+f,T52Psqآ c- ߗ7OfeHꕄ睟5191AU ^{`r0JRğng%/b=/Q7w ʕOe.T_GrE\M$t~!fxUChhSduʀ(*%Y>>yx19% iouܶmCii`_eOcuB Jk^:jYBܿQٝ7\}ak=Թ` 7}|;*njxxL:-]_ ^Ѱf 8N[>qobxߛ"қHѠ|LN(U #D-:|kqnQ7sf<|q*!Sg7y]_<5K|CX!:RSd3nj;"͆z\ &caP>&iF'+UZh6U@;)G.JiYD\3Qs .r{';$Wdranb$SV)=,)oYVG[3f _{fʏYQ! ڑ\=uY,hTA8*ǥwB&]jҞ^mi' ˵iZ|+.}2%wJ#cNXԇ3G2\zڪl~D  bH$Y7XY\K>;8Q cӭREב!hT-k~_r |ErnD|URkg)5єe[)0wtiUt/,}˼\ηgSnAcA)3ŭ{!RKȂjS\S̬Y$n^AxDa.y3Vf :/ʊυ /t%Ө.MC<̃8Hv@mTt7җuܵ:JC04U=-$ "]^b+9yekrWliC52zۉ!42ޖFW^Fw38_2--OC;1d-z:j?M΅ en 2UmhxOǮepig1\$hiW<% ֒.>af%u wljBV+Xd\b[{jdeNDl4dJg{LڪYUL9%Lr+9{zC>t)lGxnyP20 2QvѯuZR.ٴC۶\s9Km u?Zj_X%Y3a0$y<$F3EեŴaUu.dCltg̪pA]`v|7q lpnA"8~C'.qWDk^ni49G'/,)v@im2qf]a5r,gzg[N3dmޠY˳,|-C!΍si^D$9|މo67DYΘ5K?z#$Ml)IhiV!*"X:Xk1gЬ R fg>Jū ׎vOʌ$k` o}XMG3ocj%dtEBj݉xyCŧS3n|gJK-sk#6 eQ$V|LM2]|oNk3i۸Hvz{;5ȅ7M!Sa\g MPs_E&v*cxߟF ڌ$"o^ӻ\\^s/n`;*fTtZcP=+]z{en~\ $9uj-&,8}G,c+I9dgҰܒcPS6eIbx_I&ݕbjf„ N뒔bqKy窍ۧ0?CE?/ܦGvBflHaLMW{k۩ęHj.:`OP jsaT]I'm&ӯPOf$vٙjehf d{Ѥ8#/ԸQl Tn-mLڥ̔œQPTߺU|VV6꽿q@ք3Hv!`(1]iПyKyQǎ첢TۥSԧ?vTH]7ꕢ,nZ$T5"KL@,iYrh!Ϟ̬9T7 ;򖮂`:p55S32c RD]^럷Ϸ\v0IodE&9[G18U'Q= 'NB[C3s`Uw4Gm(4Ԙ6l!U9uljr4IX*nLTUY }m.Qvj˳T sg] ӣaœ^ZX!9NH:1\p >\[%3jX88xF/SiqOmxo,L ȞKkpkiOXHmGİr?]`i"ʑ DZS^=YL2Di0(!e`4+یx#Yx*5:&-ЏŷgH[x`!HR\rU]c y-j8QM]-c. k7Tlkƞ`3m Ŗaey/Kx/Ɔcr0Bi%X TB-`Xlqa' nRKeٰ@++;p zFJ9޼Ԅ&8C`M؀˦~tYɬvjkgm`*+R 74C5&,O5L6Y|޳`}b(ݝJ#6;D'+fQE!?) `stmU Mc|鿞"__ͩ @lxm==Xy~'AC(8Lk劢dM`1 x _Nm$^4 *o>_dcuVXK)Y}MM'gPh,{y˂L=sFP.Fm/>eؚnPrf/#.YKN '(WxeW+5/DbIɴ6B}̭k*ao@ueZA>v{;LY(v154oԵZî;P#Uƥ)|=K@T&\5Ėh nYЭ9)`ن pd!h`I1 OT2q4ը-<3ᅬɵ: ՝cDw6[ԱzՀpnd]꟮ K(io44[|]{.;eȈX>WiQ@ӂf W|Na^)aw-Չ-ߥb!`EDQ$ B=O7A咣H6KR\еq:9MUm얊p Ֆd̗t~?_ΑX\ez >"w'DHM|E*{J];0 ֩6& {2CYYۆ 6zX$GS6HbVu0Sa}[؇WCEN78U1\xhUM4&Lcէ{TE~1 :|ia!&4{I|FpyVsBeϓ_J/a Z** TPi(Qo)q5qR<#i\[w(ב":a"| Fd[׬*ӗ?9(5"w5_y yJ4E;V͕KgR@Os=Q?3koCq_=&~M'+B{=WQj7O O 'y؊r@MJ"4x >&"D3jD&w(YmjRy+AX3_KY8פiqHuF  +5Wvw)Mѐ%y]:\.R ]kٹHuRB3RNh'E eb4ZX71CpNwk(P[+i$:~?_EvtQ/JG68wѢr{yؓ# ==ſuZ隌j%JYrX//i,%_rQCg~@E PlYdDl,ʐ0񛌀Q 3>w:ޡũ?6)ԃ@58j=N{'|1fr39L,giӚL)%6 ՜dRqr)933lF]vLu!r|%>YZ8efQr?=q^O:oe*xQ3AA `ߐ1Vh8 |-7Pq]p1`Lk8KzL>`O6\|;F Ї1q"xl[º(#ԐP8D/bɿKȢiLn7[CZ2Ypwj ;*!.;ț{s\pۅKu@f7 #'>'DaDSʓ jtPԘDn|܈ȏ`j>0*98y'\֧-\:,= xU\Yk[?=}J?Yj{vƆ :m`&zaW֜8J,VHlFkog4SOMf &^) T7EgOUV7ޞTz!mZq*"3l*Ri9ad\ o֍" )C3+0Z=͗}'\]<:=G#?iţ{㵭P.\4XסRSZ\׫L./>pG(P ]"">$)4_a%= r"ihFE$b&r] <%GgSo͕#DV!{jgL5Bt#5̣LA[tQbyTocmpop7,3DRDh;]LyJFMX@>iߨX+_{S˦i f g߹]O:L+"$L!PqJ @9^Oajs|RhQc TY.F3..`VWDyvG1ʇi+EhƙˡC&?>]4|JHO 1Nm%PHcHvoLٕh'ѷRb4 $r^6;jpvaBS2DJuۂ֏Ac//Eq4#{g'l8 )#螕wwdUr8W('[Gi¼вMj)K$aS&^8l \ +cy5_#/KWO*she<,c%$( {tV+Lwsp!g !&$P (p%\ΣZ/S1\[ ]3ء* KK׊!,$t3.1 Z90rf$wONbDabmFE 1[ ,H =ĸ pC*s&IV~2;pgP/FFܤ6 50Y\-'voq+/YH?(UG7iB:a5Z`QK[xv9I[E +iw a{mqbh:lAbAKybL=E6ݸ^FԲ_&޸/7Тl!+"Ik@TePkDk`i+|J^Bˆa7#VڦF79藂:#nr1~95F" P)]Ի k|{J.:ˬ\z>lC"B/8IkpԷ\XG?ԤF+\Xҙ&F' ZyY4Vr%eap^$yp' ɪhE>s~]lb 0/tqu*|!ĈgSm7E 4+U;ŀ s`}MmSPgim@I"AUǫ"dHď+̫R z.maa*^Y>ؕn Z-s vcy -zKBc YYkkjXMy{=hrcOOCOIOd nɚc0⑗yoԕ!MJPhC1^1g4" o@`ƍC~[I8DN OOJi,4D LEր璜tnj^0(šw8͈x4>؉@GA'[~O':\DTdL+o~ ϭ^ߤ?ra pbQr]$ZivBV{򃠱 Y]×0r!L\q6W5W*LYy6&TWgLczs\Ppcxݑ3)#%0@ iX w(Xrl$=n`PsH_H g7Zyh[)+_`y+p/asf"Ճ~ Rw).̔'i])gdG<©*z::ATO[@+4fw`@:0` =]D>S A/AN&q.uZmu}J&v\tq4YkTϒ{(77j;K}Z?}^[2,Q>5^jɢS 'èbWJ 0"Tf]j/\T}3ƒOḹw^R NPFm.xW|.dX>! d Awb}\j] [dL%?<4LaK >񤨸aw+VA  ~g*dJܫ0~t[_ 4l>t9Q?u22E݈vL_c=Wp.ꭆ$Ɣ^\4,,@`,ĈYlǘP; m[:E_$`'F(^ Mt,t/;&u.p#3&pnƥ"c[^]ua =`>5;4 jghX*uӻz~"V.{bTO-W- E΀5QoF | Y\jT`mNV+3gjC۽%A1Tn!sMnyRX/5 ?ʐǟ?ygܳHQ&\j[;<:7~O t]2R" vU;JPQ`]~bQOamk:PڧnA LECgK/,<.V\4pd{.?@%#G̱Pjj{110']:#"9DhOiīb3}]N3xw`\︶#:h +MhO'&eDZ]dMus"-.Maƾo;L]Z)1FO N9kx(!ULpkarek{a`mb~@2'&6?@wڻl( 5LlgN/V IreYtPJxkBN򲑛9`G|Ezgs)IHOZyNjuw_n놲kC`auu{B8Κnȹuߥ_Xb֓+Wv]>&[\Bo8q4Z\oՁ?>ebsnӖ_9Ðp TIFC뽍j=s,D ԗvϿ;nA"9,251$RSۖ 7--@O@zdMwNAxtQ0! jhE;1eĐ5]5T*졭 t~E :)91z 4`d3P!Nk@xw9]FW7}`K5;kBʢAuhaҾAm^ 8ή*XTﰰ2Hf<ı9v02LHsǐŰ$.>e ic+ÍnCmi1B=ÙFK1:K*Ö/QecQȲI_Qme#@Mgd mo \ӳgj*, Lb_d&}|ITMxg喂$dT\RjM@DS7 ܜFW4mnJMC8\EG+£O\KT8^9vWiKWVTy]8dsG\Z_ bp[[NCWADqjgkCÆVb,4VVp^b][a VvJPO."v&c?Փ 1`ذF>'9vh:M 6ژ"8+{OuɎ\ΙY#U$q]9'(-g>!zSP(UScǸǩN,+w4q>s{CةpȶMBs85$%hǟV iKBx(بޑ4oqvq5\`o15>5@]j<dŊs{f'X.d s8 ,P.=?BSQ>8f_R< ٰXCxتNkvd~ V~Pn,j_=ơ57C_g;\RtAY#L _́V읾)fZda],l =Il7dh)#4ϐ \*~BϞ-s}-絇L v"*}̝liI$jNlC҄S^_G* 3~k%/ /H9fs`1iMDcV% чF(}xOɂ) +Oa!:J\WFk65Xmx6 u#[;,8P`o$f;Ƿבֿ?x=7W勽 r|2QȮ4MJ{`@-5)S.}_ b$_(o6ZMV;hӓi_ k棉:-l2džT]~)BiYB[xAtY3?dθb"P4#~ -'w#bx7p4 sHC%w349q14E;[""۽1K{ ʻ]͘<$L#.c sN E xxqve*1tGԠ6ӋEXF`/~b+Ss* 3ֲoࠋ~s,W:G(9InTK};\OE\ܾ錴)^5X-Qejʣ$j4r 1K GЦxv>8,g;G V4 CDiGʸ9?[F0D [-?LjGw3/n$x|Zm7=iUaf&@&\P̐aqf"=cuXG\6pj!廀44"zEXC*XPJsf\@6WqRP;SN&X*1t,A+. 7_Ce/Q1ܬ(}nF +@ez=]h K᎛c^' 0-,KBoGNWR#, RQ=eb|.>'W/D ;drE\sM)v2mL$KjŠy4c7UWC L~&$D"@gXB1#n~R|Γ}꠼’D?u3Psr}YWPOtcp8vIV8Rݫ'^ _ BdsIcYb2B 0E@B(&-1p !@b?fDf1%q5֯Wre̹I VxtP"k Y[BYtx)Ɗ! ONe%]E i) O Pp9ɼSbv W249}%&' XK"<39FVNnCGHsxOp~[j GNI?`rڜg3aS4ʡICِPQ X50 q"@ᛐ,$ f%sI&1Xxuޅ$ЀJV#>?8Њ1rB^,ЏR`SK,n.ЉYV٥5k6y1Kc4sw#^(9m¤*@;kWk i<"6q"ӏk4dʇeˤt 8k;Kխz#}Wť3]6z_^R><`S"rwu*u p@D[ '2)FCd߰Ik)IZt24=iȷӹ0ф  [ż\ oY> nY/?(:'PC]F?*à :'SErgb04J1n* G0CAٟu2$t=hedF21 `{R:ջaJu Ƶkg]GP Pmw>Vmx/Om-Cmi̖0XAmlC{[ gB^z&b?uzbYGQQp0v*=mLG^%8{9EJ/q;M?t7m4l&@Af=bnj>nr)L L%ۅ:rḈXb)\|gX}Ʃ^ s45.=n{ws߂{[*qnd/L0e`t,9B+'EK,Sf %IJLhm>IeR\q}FO J y7 i=(aI} gn+d^ci|КnuPb(#Hz*Jx_.+h'H{D>lPMw aw_?D yVelEK4l2ysQFMNݯ4G(ZgƕT h/Ƽ5VS[滅'Gh C*Cg0rFK1XqI4wf%hjwOnV}X>pu->ugۂ Yߐv˰ >/mb^@' 9eӐ4d|ޡ{Ńې>Hl8)q ), aƟZ|5sO"]o.-. &mm@zP4{K5P!Yrr-A6͌jЀAao%Z /5FsO茄L|xKF+^|tAc|vU!Q ut qhtIDLJ,  ِ)ϵɞ zq@&˖|T)pq(NFNYmC7Gg U^CK:Y,t69oVi=[]66!{w&)/Cnԯ0G"MC 1?kF¼$*[-H맭!}!GjgdG>7-cm/O3I+\;Qݒ,i8υP5Kԟ# 5rcQթa}et1%(1K6spwKVZqP[ך6ncSL֬Dd 컹 '~\ yέ^eK;l+] 4wU(dwLz=_Դu kpFly맃f;$4K'  >OV;D4=IqxY)s.#ZDWIzTr?^v^ KJ{Or.j87 *g',Fs xbR̓CI= `,0\|,k罿H (?|x۬#g|_F<HjI=WY_քa8eiǽF}⇂F3>CʹQHF3PH3`DW/Ud gjz |BB̘x~dIP>{gHi&^%e~;K6hMׯb9N=.ж7zQg$ἇƊI!@9&>| Xqe2W \"bp3JEc6"\ndmQ8]'41K zWW&[7Gw"C`?5o%@\}uwg}KUE zmdAR݄ߵp-ȞbGeEbRTv`OĪM(FRϵK+g! @ϵE lx9@ڷ$KZOFLoXU?[ZЯM3֡Kjܕv gWPhrDыJ*JQ{OasoZg_=J¹ LuTp44+q^вt=m.O@3F¥UϳRtr): mVbTQwC*U'oZܿi dNWl<#-=. @[ IO4eRB_-5H! Pmb_X& j`j* x.O)Y7҉&BVϷ a .ae59ak bCїt@AQr$<Lo> ]P񔡶lAMlBocY64۲ͺ&?x0yY:\i-e:D[Ϛy *:O&%vѢq%# :g]EoX.fZZ0pwđQl)4-9Rg^PFC)۪?;Q6DL ָikSG~3;p~Mo%BB9FKPjNx|s_ZGU M#@ϗ|%?˥2~kyOp0Û:8/<*NUVQFZQGl#_{R3 *[:v}d$]&ڿM?O2ٞNҜ:76#H`Vt[bԲ OCkuP`wGStg~T#琩+-T'vК8q?lP`K|_Xopph}p] ~=YX@k\>ѬN/EdbZT kGvp[8a|z^hq(N{2}W͆Oq4L(^HdJbJ m?S7;.T!Vi%R U(/a;7aN˽Lژt5i!_ `^C+It4꿐m "?Ǧ%U$C#_2o_/٠"xf D@x`hMs ?Tl!(7\ %0O~7 :*yyi'T>;)U_jjY>@[q,x/!Y$φ: 4\P"^ܿ%G;@5v*T(tԠsvj54P0z mO޵zbygaЈ8H&3jKKMz%B#5@fCt᜗_.R^;k;eB‚F6 Kg-E< 8]g_g!!yCE-]Aguq1 9@4cA#m;M;dQߑiݦTVS~'EhT~q&z؇m ]TP-&]W϶rLQxv-庆.<%GаR-jB)h/`KS!nJJE_M}G`v,C"_=V!.;5)|@d8RԴ/6K׶FԅTF^̮%px27?np2rjOV٩v)2Z~HEMq׻JtV}i_cp |`ȸyzWQ0w=]"wұ>nW itqW #}Xjm${w>՚: |V'R|6G )qf`r0Upiz0Z|tcqE`i*k1> ?i*czi'S5IK#aؙqj y*ʘ7-6;HC'V,@<9>/$͘1)8"5DQR|?H1f$3(ZW֧(*R4ub- 0$4UH]sw蟉jT}vŲ;ġ*@ifC-4hmi^#H$ʠN*uV= ^NfC^HOAinX ,}$b+h(yOAUnK #Y6 ꤡ)iMX-n-'n]0}x CׅA& /!@=Q+-r{^S3[X}vBVZmw%wNb:R@|_d.:ʁ\̨DɋT:Ó9 v4lNb>C嶻ZcotV?Ոz ;Mk=Ny)=<4/|q/j,tzrjB՞T$cO"n _~EEa1 tĴo7Ix-ͣQ -0a@Dh+;~hj)Lq^3+=5ö|0pL~kq݅M_K{m m|[C滻tut'xIeH򺜥:z,*`w1 Y fO*Aj2ż;O7}޶:YܴVx׍:3J8A!$nWj:m|`wCIĬ\ hR$㷛E@Hz݌Mٷ¥V~Ϋ+_E1eJOO6y4|khF)?]#2{ʌkmbuZgRBO1qsuP֕DAa#F$gAL6zX>7KXLO,VF}ӇK JpLhGAа&Сj7Ge?~ˮ7/Pf66Ry Nnyi녔rϿ(j1а'۵J{ϺdtZ9!Tl׈Oi{T% 7%M]!V5hʹ.fg+"8Z'ޮF㐿bjiu:ȾH>-z(6D&C^׶U{'5(D_ N6j{ƹWNrD) iqdN- kU] O @"M@ pwx6HoB|(jr[[lq f7M_gm!5!;}7p].qԛ 5B:auC8|CgNUA{ZZ}Syįr)OV>ۘV@Կ) 2KLm؛:J/Q\84iNιLm6S'B` VgJOSȐOxz\J֌nLIڑojQV5ӈNB_ʲm(TngSv%k`r^׮}8m5P@p".'xJ,/ ?1 0׹k[abYGRj@EPaqBdџ)J;|{xgzVaԠ 'Rua)h:S./C(/qIJ?9? d_2TJ3H~8nmj‰nQu,mn`KO{ ?8yu@aSЦGiPFWgYO"3N6%PDAh7c/P2c =sG/LЫ  e3li;բp ڰ&= Մז#y>?{v@zIױ7kwgq.a˂Xl~ɹyG$#/㫖tɲ!"wGUM/H2W11y7+*i81UߚĦ$H"tGR8Fp.xQ&(.yd&ޭ~s+|BbhA PK,iATgS 1܅=29@c^ŠO=Gb/þDŽE1!.QDJ+q˱Sm24cxҼ&ٰc 39gFWc.:z L{cuC`Ж;|ݗDއ hEKoJ]:^$D,rA3؛sX~7„>Ke B hrKßwc_d5OR3dAh\2$iohdm}kCw1WZd7M%Ӽ܇QxlFo7U#DbG V©uA^gjY $=`p$Ρr.QJw'!Dq/qM<>)>&T@ VJ(L&hϊF2" gs&ggBecM("$d0ő txos_!ٱ6%<]X7 +[. ޹޶]ǟ)N]Kv_ 9fHso󲅽OiOFwQc,Ev6`W',Ysخ^zl 1",>l{ӡ6ٛ$trx PU}~E%=4;ګf322j]v{ ^RH US+ĺ@xiAbO+V\h*oX^--Iօ@|H^!|> }8p p/8~L ѓ0,~;EX49MnǿsSgGպ6ΟR"+[3Te&'$G'b$i2,<.''3v}zHwBco T2qze8 K*"kaT[[gRY'D2-7*SfO'j%n[ZDsoiE)ɶ+ЬH ]+j mQ\_/f>sX'<52-/鉩or$ט!0˻z@ O'&QF]+qC*0Atҫ 5Ƈ\׹Pz|NBEl(j:=`xt>|ViWFK(g=h;.H*=~%}"~p@lFr\^]LTw/x/ˡhOGF20G;;6E# UoT7P(=YzF l|5aSpA<1XhDj]RQo|0qǝ)K8k0iQ s}c؎!H+џ1?Ⱥ`Xwr ļ0$p%H'^=0>$c Z%%XTuX!^]tcQ#B*i˕ˁ{O/*70JCsNy],l|MVFwHkue`_=qeeR9yfEP/\<wS^d A]xp2ɻA<ßgGCjc'z~V  gO0w#(*vִ#ezh8/魙)5:OcaQ>s͒t4"0aO z>[̰zkN# 3RUN/Ka,somnX 傕.O1,B C?䔬+waEvK״m 25p)krg%2k(E;0iHqhL<]͘'Z,ۻ˽"׋&ϐ";dJ,7=A\1qlA *b TzU&v#jMmLIu3l)i>PW4ЂX| %=iSMQ<0F;(.gk v&!!'c'=C-@T?F\[SIkEu$b>y03nF`=ntĠRqzFhwifH$EE3X:'^܏sw<`*τ$nl9AeV`3YƑ҅npU1k^R t4=7d3, 4A C%`I`yH)EI#J9`8gĔMJ bl%к'ϱrI~/DFߋ:sT69kg[21Wc3d6жzd@]+#~/@JverCdᰙ$I`g+hёиu{NYE(kqJ[q?+w`I&8gpOK*mR@g'MQÊieyjx`5 Z:̳`jahoyQ>_E q&}MTog).={?yŧO}=s1?oG{9Y;Z 7N#s:1Uf6`zpsJOqQp9>^^D-`f % MtVbIk_4ƾMxp V[A{HL7Dݎ,tŗ/$Ӯ dFVЅ):9.u~6DL;a3hctT ɋ]/bQw,V턛1;4&#ܲ%+%`W慟7l@ONП5 GMvwZǧlC BF 5>c mȧ9m)A_0@J{D*܆g ,/ ǿTpFrs\вnstQy v(+{'Iցj<1¿|H"?$NPBBUĨ9,]}B ]!{V~n~2s6hQ3 ej RЖ>px͢Hj-!|"e eYn@3yn} ?6?R'9= Y9'1,f S1$Gc]( % utoVٝȄ^Wwt1`{mTYFE0KmM. m,FHTh3CVD $*k0QiIBUȚR ǿJSHcO;ۓtНKxZB!^.X*Sp~Ca62նy :m{+w{~7KCJljOE.tUCqw̫.Z]c@S--+Lb xSsX)u 9 ŲvDW`ߝS^cgmtI9?"$}o2G Xk(#<;oO‡fiFZZbOU+/Ş:F1W?g>MSztebqim0gOhiQAT"F/'V* o>bU.¾\\0zjs([:yLN% ̬sZ`\ɽoqJN8WR/Y,cwwoX19o;oEOFQQXxu(T,'> XA??O.(uο.\uv#hv$Ύ:aﮛ|*=NVMlEH(}Y@ҜtϥKMgm*We:6+ސ#s5oTpA`QLeWbYfͭ7lf7ϖeY;ӕF$)!~F̻e&ОA.99zah?BC.aO̓6琋3N,w(69>D %@w}*7v"Ůay/HzpC톣 |NgsEdB ;I(KE6<,lTd}jMKޅ:i5_jad ,^;fP i =ƉڶЋy8Ռ"̗0W2lNyd:FWd$Eb)Kn PdwZKzh%%SÁ<FАpRcs^|\YPTI!w˵V Cf%%:Zp0iOeޮΚfҹ55?E Oe+p>EиiɫFO܈28Vd?yNgNn Qr7ļUzk`{V͏,z,Nk˂Jݙ23Zώ^ßxhߒZ փ܃瑕T:!S|sY`n"v^d֦ͣ)9Glfׅ{k'N70Ҹ \nR?ch_{!5HnfqipzQ¾ 5'> HJMeJg[VN+h+kTiM7tSw ʐ*iԸiĴ"5T+̸,bhSD0gyxpӎdF3p/3 dmT@hG~PWDB@6OW1'H?fJlR/o3,v6Lv)2W u!V[dr"j*=:ZX,FZlpl2T07o%#| .+40P}ӷm)Onܻ+0mIs}⿮e .GBsr-`cR ͑ȱAK23e#R$FΨ26d+u%k'6B!s;ȴܓZZo+O?g/#hKYX /3(QWzW_$܀p,3rA1N 3_}TM 0Zx~~$Gm;Wԧ i1 M7%m|~$w~6麍sw#L.9v[Q*"V3'%XRgV4&4#}G&{f=pϵOi QG3L[V݂U\p:Ts̖^n(NjfPdgu|UTD!*m$-$]u5Yre$IxW_?)Vπs(PBhS6)F!7$9H+ƨ=ZR.7 0Z{QR, 1AGbwM-,4Cy.߃-ۺv'♓R^\YR)`g&Ap b_vNXnpX -Eg깜Y}/, *q#Y4r~'TbP@?|CH@w ).rv7#_ēWsCVbaO36ulK-#Mzqs;(&yˍ%mk`޾_D%OK?ęYA{s.u(w˺F9eO9Kֶ2K6LKwe`έfPN kDܴʏ T'`F\a ;f#yfH7لCStJ8ښjwh0rGг+t#L{ 愅u4Sz3*@AjM'>5.A@&"i˴(WiLo-n7(Þ/ɒ\1XϟʍDi蜘OM0oȒB?Jێ?e]远$E:Ms\%n*æCI744(vGĘ|( ĀopZ x5tRƚ*[-V *1j絯!8RN[`C$3MZXs7ajo<0fQA5#Ild&>fV71ƈ,b_H `R) .IW~Zk2P۶r7Ӟ*4d88`1[ĥf!7%J@[ =uw |%Yha?m'^qUʶJ2L5wKr&͵0o$׶g:\Gm~Ls2q> +7b888űXސژ߂H'22#bWﳬBu[{/m<Mmr|fS5^p+hX{p\ z8)`ޡB*h4,`@uPwgV'aCZ ?6Y̓zJun L̪[_E Q~Q (oЉE̕1V{iΡwC?0Z,zh^ ZS25cb r|$Ptg]s4d.)LX`UUxNc`&WWGm04PO|t#g"=Isotue.< %M#R'QO־8Jy ƨ`,rQ{.7*{r) @~pLm?b[dV_jivN@/#)\4jO-ׁ!b)p\RS3rRhPT 8du|sw/NPY4xړ/_XFFPցfeΌe~ͷ s94j:<؀wM[e;"ͼ8ŏYj>KOޮ&I/J8BPS. .%1Gϋ_rrFJrF$AhV@!DX>eznPT7hV] Ω'"^],Rd JV4ԵŦMv[Jeze(2RVng)+~JFآui' pnF@&)AbPr /0AlX+H(ZUA|GFC9>0G\.q@ u,͞Vt~8Wr.[Cj'Jrdd/顮nL1akL~bWTmvP|7ChDr6MJ@P#@y]Z=IeEأ p5՗.V5eӽ?m z|QxBhBVlj5. ;^U#es/j3A(iǑ.^}*$v=v1/\KLgTZtA\6zT}KSsg}Kh}T*:B ~ je37Q{ ]|zB1=Q^i@wwf,ha@U h',9uXJ+cMq .*ڗ{k1/fnzSMj왗TGa-!9WT_:* ^Ln/$V qO\B- NZu4Ez9^yx}aaQs!L#ߗ,Lg_Z~s%@&^.CG3 p0GI5aі k1{Й¤jeWc_;S(i sEFt æ(^}J[%4B ʀ518"$j<NޙAJUs[=Fp ii ow?ɿ_0R'o(+i{1[Ene1@qφDAd?2=.AdЉ9%k|xBP ]Nr}Ex3\)[dwUmF-gz3fO_6{š62.m_q(#511SLXD3W}ll̤^9rLR^l*#itls+p}ՑA@'G1<3O `K>qg~E)ri#6;'W@gPH}u|҇4R "x$/ln" I0 K(Rp|/j4h$=HE߽3A7(x#eml,N-{zTԦ&S+}pQ@vt4k=ڙ%Y1_mIMWxQ)K=z'vB?`>%/#`Fb?ͧQFؔ /5ā %-v_߈.*KOu՘_ʳHJTE:oE7l){/ ;G~k}8B.}09H˨c#=dIn>ARL(K:|8`51ܘY6wZx Eϰb=Mq!] GITkey Qbnr}h ( yi;I)4P-j Qm/2B [҉ݏ'zt7Imr!, n"QK̔]Ҏc(y[X/=3:k"T-YeH4'=z'9V<>4(e$sLq.ÎfqZi! ˶baT.@6l2/g!dem)%[OG?ه- 6 5H:H(#Z-yQ{(99&P'uM weҼ|COC;u.:Tj*2O#b^ܤ}V*M9MMDR\U= ,)*c|گq 8p>^&"}f3#_FCSa1dd7\ ih䁦tW,a%c濜 !ܚҡ'^%̲ J/8LZloDc}dOPjѺYB/vSfiG36Qo䉭krP :QkT8:mŪyB`5+lm'|ېZEy9T)vpM(\~d1]O͋P%T1?}׃R x /.\}FaHAY}%8WY ~>ڡGM>|r{ pIo3UP]gPۂճ Pp p tK@E`_ FVO9틋f-xɷ\0V.G9q*x7!dܰ2/5$ y YA=z.fӜ孽G>?A:о[NfZ(Ӥ\-rF֋|` rB*s,qu2faAy/[,twڻU&Yⶤl{u$A2$Q;} mU hޜg0 VcIyۅ. :=8N.'?D OM/xkJWwih_ @[$i?1ԩڒ,WiMbxNf~@4󝑹DvYHކ[NJɜ ? /!^LNi =.- ]+N@ޛ' #I3"4M/=/,W,p?DAG3^ͼn)δ4q@Z`x3"NE/y 4 QG/5DJ UU-EMHn{CH!U<㥀ɰjP#c1))FE}Iv/^lS䐽&(GM:T8/E2(;?',5Z,0 &XJF!QKXKzK-U"7Pq&'סL{.WcjMSe=,cr%[ϩm43S`pF{ ɊO"a(Ԁ xк muoTFy1ox7biTl8)0 wÐZ8cDZoJyFtB|6řRc8vGUvzxC Gm^O,/P">z_LurוL$OxWTl9yg7ۘT~ͣs ohBWlՆ=llc.q_hd0OiB1v$_3PQ,.E }[h.kZ/3+LVãU}qmQOs!nʩhEj-u-|lGe#Tz46lmS6A< B"4)$A Wdl&{\ʵc܀+eu*D/Ԉo M ܚ[TL]THUIƓz[m@?Q2cV]NVFWh&fQej‘DKnF .z `? ]@aoCk .*]So \X.qoJ`hM0:-*=/@ME2P=VS77kg`.#@] gnx n#p\~elfoFl+eI\|_ЙogጅH'QBd! ݼsqu{ $lڛE˰K}I~qe m?jDM瀠M[E>V]g:>Lpd#5zD3 BzVI̞pPW*g9Hf#;ǽegȑl&RBie)46zẅ?q:-p'Uu6n\80{ VX`GN~%k qClqMkUpOPY݇k|`,.!:T),rbPZ\ \cr}_D8KoSfqas42t} Y4N9am^E>YclmG跟K4q.YӲW_ivHQ}#R0vux-Uk<;w'+QJ''× v 5OEL6OOZB5{'wJ9ipTyu }lK>zDѾfHC{K@8¿m6!$ْa{#fNBa0% d>=UpYA[2dIq_2 3]I )%2pl+ ŒM*QK=5F8uVΛob라_ȢyӣTA&zQȮӠxl'H|]`{g+*s@n-o3N*x/4!KM\9a󷗄_A P*`7tBgq*j$SvE\S |6`Q_ňq9f;(jR?bmFlO*DV^e_L󋇻$XgZ$( sqĴ_iE %r@'fn$T/xJ^\[|` V5 Ɩ[:peSz7țrb@D4Z%۬M뾭-;%A (8TU$}=սpF ì|+0Ǔ<6|Q;!R%92H{Qqe"ccTAG"EzftM;MMo;L3I6fynJ/ۡuE"LQT!*>:@,H~(oG*`Ϙx 0υJ6eO&Vyh )W MF͊c vWϻTo/FP%#Mİ I"ƅ;yG +BEB JDښ"fzz*\%U1P繼ܦ(mˆ9F_ F-|y}MԖ1 s="xϿa9$;vK[6MO4fjZæA(@[3rgSAƟVȓ[o.Vm޼.TaL.U4iDTEnI^a3&ȩ"B Y=w׆dx9ܖ6yc@G5Ggm?/\a| 1ta}o#K]8r ABl !%ZA]8q:Ln-ިPKkA󤷶 (Nهd +*%` dӋkZ.LGP .RaR|G֗ ї&WrL}EHF9&Ia+zih8 dn%^̓{5?W80@Wbo{zY;N5X?|J&ÄaS wY{Rm=!#)0][ʙqtSIjTO*A)y:yaqcå(uFE`Ew g-uގ ߿%E+vL7r|z@HW؋0^ˠmCu6v ݇CZ MY~'iHSx.)!Ls7Ko\{*e;@-Ht{59J0 ` R(ϙ:sQzbi^780*AE ]H9/4b 74I]D? $f;H [>Ny$pک]+IKoYNW'o|}p!"6~:hu(>&nQtPt$4\ݪvm>UQTu!, "vxA$)( XW}H]ol@ %ng>@+dD 7Xj d+sq&(ÍzLҎ38^9gĒQ!%oxYf+^趯uM_Wղ:ơU9Xz}IY0 \`d)}ہ x>2*(t[6vC"TkًޔEs< \.J̾L*@4-JzNZZR\Nԗ$=K%m?ONtB&$ZFNZ(n{c6C{RiH$. F2nN4=_fkmj'M~ ?GN [Ùz x *w(]~X0Iq&S;q'x+ 1TK&9'޾T$ީV"v`#;dX~iuq? Lb@ŐBl&@ l+Y\gY%-W0enLfO<='[{_ F]5"ov-%+- 8#i>JT2 [CֻuՍKbc)ہ"*:`1SvbNy;\7ZKM-}v9!|L'cf$}dn{UmV /٧mM~SwQEqEQ>R$NQ)gA!~'I)sܰUD^KJҰ:7 5D)GWiFlΔ]7WkD΍><׎5on[ ߁UǶGjFW|Dũ2HxN-ZmzzYW<.j)TQJjBUTzO>k7 M>A8nwJ`0-uuQOۏv=ŕWi#"C|ܽBxl|ۈ 6;߂+TH*Xߑ]6[L߮7N JY?k|ƴRsK^JX Pꥉl3Fooj ArA TD]b;;Y'+xݡۭMCxD:%&?Q+ύKv#x1-3U˴*hG.QR09HFt_۰k̃y:*u̺EF8;o=W!X7ܝ‘ ea3C=/6oubqo|s6h\5ݰ=̶I̋BYat9\pgK+`0"FIֻ|*N q)~h: fǷXY\(ܒ,Ua/Z=픥.Tqm/G ܂DOKX~ZcFW={e1+(mI}s;l43ɞ!LhᢂZ:~Ȕlv gfk1񞐔O3%"Y|š}_U3g.)ovQVRo> N$aP&qϰ-Zf Yd2ۓknf$x_u#\к"CƁ#0m kG;P#Sr Ԣ)⟤*pmn""q+I}$Nӵl'-"M h14lPlWGжK%-'|ܚȩz+e%Cu=^[G? 2Mr~b+siok{d(Vmf쵠 -;Sz֝!XIܶ 4#]nh8W{?a.Pa;Dq3M_=7~!9 脗SĥC!GJBkpW#jtFX_w߅fmȚJskY[N0pYH~0Q@V( XW1(O>u 3F +oLGb^5Ckj2=Y,W˖,mo34T?]q'SLV?# ^CϤ[(Nәi.sZS.s Ұcϐ6;o`~ki苔VIbGeX(@>'ySxtþEB0N7:8ͤ7_񑤱kǤu.+͍+zhdZMе5uICq¿T=؎s.\=ؖ=4m>$U/}|~ɟbv'znw&We (`$ ?Xw|к=BE*[\E+ ĕ?b?_>|Ĝv׻;oqd 1Jsh{Ù\_82;t읙 DzFW^kJj_'j6 z'&;RhɖǸC ԏ X]V)^0Ś-% wìB8utnbS}󍩗2Lu N`xL` <653":VVZގ l@jutLKUFlI!q*6)j+o2gB_2j^q*P {|+*{ &l DҦ&Y 4P.SF6| O`D^q0kg%#},d_' !XAxN^]9όN%ZwNw/F$Ss!M}#,@ Un`뺡n wvm"Q :oIGT[o6=j & ~MA`k+lANXyNDFu6T^NgȗVaKb؉jEgJZk_q׍fymGMapj+9lɲЪK,8f$D(۶u:`r-0Lxg a^:CKѰvjUDIxo-(fYK}4:O^\zLտ4Q7LFƻZGAڧL=5;&gݖcK?u<((*-y B2`{Wq\́|l@`M" x Ht6b7͊<$xK<;e6kӭPz.E_ueirdz`ے",-F`'&B'VPd1BRo2@jUpk3 1!rx&Q$)턞MhZtc2}KP`pG_2P` 'U&Tu}B֚A -A5Y%Q_}>Sp:$^mc4/E7a|Ӝa;;:_wT.28\("1ٶ2lj~'(!a-^ה_Sh 18 U|pvPeٮ(Ysw DžoK%F fpaZNpB(V8mȖ]"0AxkO&42X6_:QSNG^[P ^V"ָؠ9<_ .Uq&ǫN%ѵC߉!G}\38d6n ̹A5]AAŔNR87C_.woM M$nUt7>x $ڬ%S(Tcy8N]|1PDZ'uj`mCA"&D2Q_VIUK2_Fq cWb%s[dRGݠ躾ny{$ʴk&YOu;a}6jEOY]Ɋ'r@11ߴ[nevZQ}R?~8%aA us zʍs3յ,ҁc8#҅w3K\]4'-/ +e:;ᫌP% xW%ף\[D^nZ5۾NѤkh1._wySO?Zjؔs/ן;mJ-4[β5gcozTH;J(^et u6 +Z*LG=*rU-n nb@Ü24S6}ih}HniLK9Q iu Ik[o7L|bcGˎP;jR"XCC"cĊk|y-PR5~ϔ]7c`B.} ETLveݜdUR7Io|:(r,-R&@΁6߷"DvZS#{V6|jYBnݓ:x)om+[ՋNRTSouq8]VCTݗ;~j)$ mz.\Udu@)lܿj"F>qyٗ臩ыM4z_<lb«אnjd\THVW8wtf#jخEwfL<1e*PzU{BQXXQ 'NmvL ITtEN1׳R(c: W>8ecv4ӮzwF/ qaLM/ H!#T to ;#S#cĭI Zx5t䀂тɲIGa?-Va$P tU(;!rNCOHBN! E.yݫ$3/A)ؒI+r'ʿ6 $>?Z!\I1e=H|:%,KxcwiGTbQ 3⓯rKf`m<530#{8.NM(jf%ɶ> ~="`s4n>c^%,ТΝ97o::d1W>X ' M ~j\!f<mA+c(߿Vp\@"D2,Cg~ʘ_NJukV_ffſjA\\X0O,jRb #FdüoZ9*$p~ABoL H\/ǎs?%v66eBg<];%?o10Ix|RvXH(vĕvt;1fv7LO\ 1cҕٍ%s S({wE#_)Q *N+eno~Qӝ\\j*z yM~]|LəPh}5kN8pnVK xJ9%A l 1ĉHgyi2)&Qc'%%CPQX!FP%)\Vܨ1_KļRB:s̷ rrb欲bƳ8j k0ɹ/vko%_ǫ1w,jnlsϻR)d8/rʋU?JFߐS* Ţ$<?-x 11ƻ{$*+]8N$qt z.C~*+VqaE?33ya<1s*_Yl__QF[un'[ٿe y*z=F<, @qV}/.Kcl}71967bHK!6p:#ն/^E*A ؇J)ׯ"ɂ{뜠j¼V1iy6}PeןJ}ƗPF(d5J6UFE>QUF9{4WP֋˷> Tw*XB[wˉ`)~|TEa?VpLfSf[:;ab3@PJ,7 _|Yj6l06y}m!#Ls ~DdQDHR(|#jcvL 2Γbȡa=H_&ϓyکΩ ET=17/K 5Kæyk:LR}9-W I#|휚&nN^E @fa%b~ A* mOEo'Z|[pf3FсN%;H;pߢWGҤ3e^aY&BD~uNhѵ#> G-qD AvRAyɾHT9+~Qdy7w`$"9ީJ^}_ m@U2OG#hӐJ9H #㞵beG +^mR~nkR?i*Sn0Э<4Uݍ@Id6Bj1@Y|^u &abT~@sg1چHo-pEH.FT8xqHzޑOr]ߌs(vܒՉRQ~ݼ$@?>(s=PCM񵿗ǰtn7(@I+5W%_+FZt?H$nU\s!SJ#yqҸzp TrLa*pi^J)qd/*E1I,x?isl !Es-?\:ӭ;4`uC]$L݉ {o5M6XLq+^sDCs[)fZkByb p\Jeϳ<KNJ l&qO(f%Cf]eYms"O^*ތ(@zG]eT]$j8#*_N͓ KI_M䏺V傤Ta)[]?W"L'M1ЍzFҧ տ0Oo]$[ֆa&y$B0! U)u;Uӯ` v::hTDHӪɃz+E`nPpDS}I\lq`q-i1%i8@*p) CB'J~8H݊1,Uyvic\U9D$|^+So70*8ڥpܚƤ6筃kVZՁDnف.TK&I6CPz3VkؗߵIf5soF4#׃@2D}s= bXg;G=UPۿ`yqJ=ٰ~mK Ǯy+EP.Β}ظv2HE}fl}XEsx H)Wň=Tጉ7 mZ$} }aaǜ/Ֆ:cw|@L 6-F6?5u1<`6@2ؗ?:L_>SǑod4v:,POCrD%3DmkX!(c_730riKH N˒9?+[ꊦ叧]"mc|FVSWh}U~d=ص2iu.c;g뷩]\{Z6ipX#rK@vj_zU _'AL}a|_Ac*A-}?s/zCn1F;r:M3g0?8dF'J9*ƚy#^5,щNXv覬aیHw{bI&Dp9_qNDb|?(8c1=HoզSPEȐk Yu=`,C$ppNW"86gMJ.T',qLj?_48& P q h +Q( ;±bcU^$tH'CDbp$ėw &p2+m4@9}bSjKn\˄e" @Jv 8?9 #m#JNn_q']S~gɛuNG4q$IDPf=@Hƍ 亼Q$iݮԑa~hHw Е, e&U%Q>.uE (o]jpuI+c;+ wNz !zee0s~XorW=Nl!V!t櫗~G'ñ](%6ACB uO.KjX7Aۊ'mx{!jlwoD{3WOѰB@#9 V8%%fBQ6E_V.ߒGK*7 &tЙC㇬oIE|n LV'Hw;F4:4p'ZЛ: ;Sto\b^yξ.iתpw&A/;ZM~T&aY+֗~)o5cDQ#4a6kNӹPEb|ɶ%%mKOl3kal=7-fR)kjWPz0bͻZiNM-6 i X= -l[5Ivmm߬+oq&>_~;%"}Fx#n pW:uX'.D øxi 5T茄QjƖ.N/'^LDkc輈w-}FsflE L%)K&h4",ڸؓ^)z7\ P赍o)R|=αCO`/1k.\{[z TώQ3s Ih|*4\ *j =bNM `|M'kk;KN7b7h ?@Q?Vgj1WI.C)g B$%%l5! j|@lٳ/Sæst^Y%DezůK?ڊ&gɨ  ѠF 9W HG~U޶"=[];J/*_&U:?!eGڇ"uLJ 8}nh^v{=K\Gi3'[!E q1YnVoi/X<5֣yѫ 񏄣W[NNa(qk#AMxoLrH禠` ٥ g ^Uu,*t>jp2o8j@L9d;f ?󱾡؞]j uu$HsHINa:7Pe ("BkgMSrX.uKpUmFdu,џ+}o?6R(J=BzC\li}^4I]H.dU!IfdX'`^d.Z ('Ld6uW%tHr.A +ƛ`(1JJB+zh^_=8 o1&rtf p4 Q| i)~Tc F;D%Hd2Fp6Qrc+Tߥ'-8ޅxu m# ө8 ̩Az}^}; < gY;-s X] k 'ϖ*Å2?F[wy(>p~⪶Jw:叻jvYA*; iJZcb(ݜUZ,dGeurXlݖOc;Ͼ`P plwV'?)͋kT8徽+] S`*6^ݮ#i?e_ƙA03!N Uϱ3A] Vr:WݰndʧżFl{wʞwL57 p!_K^lH&D,ADrG LIGf2'~D Z^2W-Y6)MY?}Y4ClmJEr]hN@*f^LF\1 Qv- Wy|YI@t}wO+q<ܽnm~4&[լ+3K\ٻ1.$ig2 8L-'leUhpF} kw(B^@SƵW^ҷfh<Ʊ'ȔXed8Z9L<k]GTjy'( 0fRVRzrYaѬ҇wAt"w59wp %rJu͝|^{p2[PjsW%/f4Cxl77{wC1m'2jb\q6b) <{ׁk\ә~uHO9K탉( \TW6aмXyugo?/z€BЌzjc3û(}[b1'8CvA(L8KR sF0z,ID׉ 69lSdKV>*WfD2IjYT2ᔀ2|_3GI%Ht[ֻ<ITIєZsIhqlxUpwWEgG02 +#^ƫ@n{/y4i9@_CY+5lvq9&&pPCb~6}jIn%2$dE•5ؔ)o c^/YZ\ȫD&EK“.Xf9|~2Iai}6[rFu.VY!͘2:oYbPC5&U7Qk`*4.R8]V1ussN/`WEff#+2:V-WAʲ {@92uFN$ bB0yrs P$tY='IH͆7 #[A֗ 1C1m9 ADiG8IaߍAрⷬ6 綒{x8[Ǒ6#/16>\gA'σOqΖgJzp&w}=3dpHR֟Q cXaSl0H :삒!WkHuyQ\sѦ%֨E Ae&eEG˪9NT$k[.T5v4j^̍w}US۟7K@hMK|6Ԯz+\Qo2L`y]pq-J>BYzZ0 { {Swc96?.옯z`߉ZβwTxQ֚W!Ӈ/ȝwoNZcb|XrKa٦!M c@X)Kv頁IU(kdX|DP@;MrͧÓ=1Bww"uvd%-|nTY3n>Yo Z3ͣϓonuH<$¾%ű%' GKCsK߅SI.D ޵?WTslO#ˊæB6 4y:Xsn E][G!U?xnxe_aMxw{B{'FEҜiy|O-y25h[ǃ}ޓI$PNhY9{v1?, Hw &ZŢ'=v=Jm"L2Js\ZP[$^?$M(Q}':D<^#JHun[0H[h (}mquJ"ˆxOtjfvQtCƼtP hbBqԹ$}mv0J^b& %X҇D7G!ȶ}s#HM 1}.tEt@Xo}̘&w/#YLZoK*=nÛlO-aT*9\}KRTAr] \8՟v@"v8Pn3{[޲ JngWlѠlR[4[8!pCx&.\9k'A=w#[WaUn,?<ffuF;={wCV Tj<;@l)-H{UHG1^עa2ga (= ߄9>6 *rLTkb֐*᫰SP>:co2$V_1~sE/CC^B[u\Z*";d\s@ݓ-]aw6C 7ÏM,]wp bߴ 8{.O7<{?zaDt a*g^O*e*upI*Tj-Ԝw=X4|̇Jf._;  pّNZB 7/4Fr _~NIbj[t%]7o>nX3}3`9lBܦov摥#621`3\Ac$ 蜥-XOcG6.aXWܐ}˝9oǖ|/*q8I'/e87 >MaA.4Ͷ3Mu o;v^ 8xɱps<|c"lv}jŁgSA ox>VCBhgoU*Iuiźu'SNL2I؀Xk1tmDㄳ7`jIfѹmQc}],CjA;QxɂdXuX×81܁HCuNV[*}|!yp0tHxR;b@%q : 'FG-$t7Kܢ#DharC q0O:)M)6EMF`bcwC YOl1[*sޫD{M9awE+e$&βdgվ6˪R tيb:r~o@0jْSvvFg 4bsZKw+錢#˽7aMy"A{yGnnn5Ͷ/*d O^lN^G&pk5f-cQE֫`{#\;ݥdjuW=iat)ؕ_ۄՉ?onŸIw4A~߅iynSn>k" #,,ۖ+?}k$Qݦk!cDT܋noj["Ѻ$(}#/1Nu ˱-P_Z/Pa 2D Aրh˶7G d.V1\gUۈpęosYQQiKyH4=C،&ձZCI\zQWv;y>KvMËSlyT d' &`MwA{}Z *AY؀R/`emsŠ1^Ήu9Š38o*0FH,ԛ}"䂥P5]놜Ï=UP6ZBTM"pByϣBR nmGkk]^kJ僼7qsк ûʜx@$ *>66T醭0"OiFN=B>DZ㗀yl]QX͕|#&HWVy;AbWM}262y~c="oB:&f@RTeT;M69΢RGA "۱U1*%^ zCBXaie+>j VoETvɍ5dy7j *58F)iw=)0Qv-,چg(V̽9auaqm6\;yqsRZ3נ** .ڃs[ѫS.`v!Ue|MmiDwNo}Z0,E,*-4$>a Pș:XL$H<#deJn#޳أ^U8z+ILl[ *2D^2dw:A9ˇm\\!U*yRu)KA"ve2T kҥY "=;V giO[nw. H ^iP9:a-6,vu \E|{ї@Ɂ o~kDs:9?NV\Ꞅ6*F]ܨ`=.!wt+6ep?nYk'vp&-O,(#dcYݙاtẉs!2t˟{Rcrcqrrβf#ɚ՜~*)vH<dh"vnĮX5USRfrGWGLF(cPc8ԳKhR=r^umdQߢy/<g= Ufč_w,g`=*]mbݙ8/k- ;ݨ:p#нxϝSIIpwh2nߛ=#yQ'2C 0PqHˇ % ݒx%{W_bH[fXx)9|G&6}\WYV=HL7mv)*JrrrȆ_|@1^#|Iqʂ7]G|xj[/.2ŋGƽ6 guO[WJDZ;d\ ۵p!e@iAK\h~h6,qO^"%M9TypLF8 jH+[ Y7AKψ3vE(mRY&*,jNWO…ڿ)9.15`ĵ2r7|!k*(Jޟpqe$M)6jؾyÆ ?(ɢ40i_q 7e.ppt $0Sv^WTzN3267-u\r(Tri\xhgO#ChhlѲpn%L"ÌevKɯr1DX0ob!nqɶ7 w4?C Qߏ]mX.oτNkVD)qgG%$dnwVQZ8?ȘTU(7͠ ,hsegձѸ4sQ׳d)VE&7IdԁqLOŃdtXzR'ϯh.C]tzr\~,]|)B̔:I[㨟hl+~ WYMWK2YiDbYi^`r!L9y]+cb͜e c>NJ|$`N G"~9~.?@ 65f""vɆ0lנDyz+#\!|>@ Ht5"t/%yR\ֹGutuݨ%,.b'b/$-kh~΢wX,R.Vӣ{7%Y]Oɝ)4lJrT[jDcMSU,Z"=/(sE ̜W p%6z3 0}[㣻¥R~ X͘ż;$NT(Mf*,6U"d5,C=e/JJ'1?=nc/&y?ڼ0Z@Fx8~1?>PtU g0w|ށ˅A1wJvG`Tc"f( /=!8b`Ur.56-O@5Om+%AT$ǏP1KvL-`*:t۾ 6snFg [=Pq^ItrWwHvmȠؿ B}|79$ƽ~gW!߹(5N*Zh"u#gg^mmjbmI9;TFn|b$q9]:V,R2}dCrlNCi/MP0zhB@~Ny'O^^ ĥSuMGHV*T$9 PsmS!M$. g*](ѡuzZ5K9E% pN,E <]4G)4(Y*yA7݇e8Vi"0ٛfr+x˙6B( ýPu7wNLsoy" Ѧq{Q{cSmsLA`T]6 8RϓwfP)70ﰚye);ު?.<ܪw^# AF8sR*y":2i^IO'u/ 1P9 O̿.i›--БO"(bSM )64\P xAC?BA::D!IS0]|rטkMaOC]ե/#Ѣ)hbAzt)Sdme7gmmU49ݤVlml4C˵8LV(}sx.~k٠EUJ5pWDO<7Co؛5qƊ.S}׊~ʫp˻ ^ -(N!qhQTHm81zB(ȽXkfV ^>ZS,Ffb\vpZ$Kp1*8.rG~RtF(HӶL?X\{ApXMeG s c'lS~{r.ÕY()ZUN_I}<0F"FT%us+XjWQ>= FMs&60B8,M݈+`~6! qd8C g 0w"_zܨHV AM+b -9;_A1Bh??[(Ѵ7Ѐup@&smQK[>Jw% TU,+-C}]鿳JN@Z'#c$Tǻ?U0Hi`LN;EB~0Z[VVk_ɶ!a_Cb Ė~rTx8ꆈB֎qdW0CZí3ጃYB(j/^~ۥ}{5Z;NO#z\/T/X\N2Wz 8D'=;v49Mĕ _zAao bIV$+XScUso$銆m-|w>'yh״P=N,g|&x+%@~QNw^'&% x?f&SuA,]}x)>pO~gq_Kr{w.GšZ#VV?e D{ߎ*5=/!sQI?*e86a,i5oխ$S2" wD%ɽ6zWYb?=[W rkӓKGGlh뺚NUGeVLaKtf6:; 8!H#N\PXjLtWI~tÞV_SO:~l΢/h[~y\Zj'iW&"4 %\B(8Hl{ pyE'7,2vE|y%[2oɸgRˈ\ {;6 z[gZh'`'d(SkqƸ' Z=C 7lu_Mq=ڄbyX$Y; m֪;Y(yxBP,n5 !svN E.#ufMe23TPEoㆩRXݮX|6M ȼ 1-+FV0Wd"gnj1XOY<\(Iq χ! <a.T +Z\UNhU=mf`&;rE.YU&TX_ǮІD|I ٔbb"袂 ^5G7Q]I '&|ZO~gZXuêwhO F>Y(-UrVuqZuZG=lokl·p6jcU9ӭI*GTs")2Z?}C~=O LXd]QP%}CI*=,bOj|F;'3 3}Ν@N 2_7QښT+T|K=8,# C?rx-dKݸbR}k?= "ݥC+ g2a&!*;[| 3A0t^:^L -LqՒF3)-* \Wҹ x2ƛC7ڊ|}*x L|sLP4QJLX LtLZp޶)r> =W8\%OGw?/,= oNh\{p0/U6A*.hPzu-bPN Vr!d>4I&2eé=#b_hO9FVwH+B'st_r$'.A@A{Gz;p;Vw\){p]|v پP<"|3V0~^ &7PE!wE9{loRe?QwmeZQ`f xƠbZbZjX!(MiYyCikWQA: ,f3|#o Y~`<ۈ@8H v/&#;$x-M3? z lGDM)a ; ˛AS1m *t8q]qhm ʩAPxxM[2S}#s>r$<|ΜÛD9>&Y 1yAѹAmdt_G$PBqŸ/n/{tb)P v<@9;~IԘ<;q?0 su 997ۗs/T\OP<~å^$~Y< X,DG"y)7o%eZ]pqb=FDOr3ՙ`jP&~1E2{a^+ǂ8 B,I.d2b:NkJ(o$Q_pqpөS`Hsil%O1-X 34=(v[yn{ ?@n4轰Q;Srx 〃}d@VC@{^24u%i%y=3ޚEϷiJ)QLtn[Ɵ/6lqG.j|5[5ȃ` ­1^Qe8,Mbj)`uSn%JG?0<KX-e>PB$#M݈)&F(%̨K!rR3*{fqG毜oeޘOg^ 5JxY ?Sį͵N7 }6Hv qAi/eޅ+I,5j]Dņ@*6)g0>u Yoٱ^t^!K1gr3KSn'YcsZ:{&Doz޽}mm7e_sP$LI%7Nɓ5>hA@j1US ͚G؝`HWR{Rن:t;UK ?q$|H7<5Gn`إ%Wm]܆w Tr>YN?G5=QUj 5wwTkyљƆ PX0Znʁ`2-\NBΙ(TsD%Y 岖vT̓7~]՟ rE}B R?s^msĤԻoF`A1eJ@|Dr3=WhQŮo$f% ;=w)tI| Kb /D;! ı<)ebCݳ{$Ï <RAv S*gÿi; P'PVsJ1C}A@4DJft°ȄТdž{/\P;^[USs0Jb'<{~evt9,LTѴd*h a~lh|T'/yEbn!-k((l$ {~~#BһJS'XZi"p,ojA"ofy,w%Kj>nݧA(Ұ`؀|=lE!kʫϳ^iRvkx3:^/iQw~ 0pq-Nv*I{y&C=Tӱ-+|eR XdgJBï㼎^HV,(D<8Xa|fȀj!G5%!zOBAr"%) X@>]+nU߈y b_07HCQ]O |k[5%ip{F54IrZg.x}7/? B|0ܷf9{dR >8֏"=H(ibs5GWXoCb1:G4kߍ>vH063lW0pTbt x+PǕ 2tpsV -y >Qݜ&[k8Dšһ[3 H?eBgDTri|ԉTdF{P)ʋxgM#>xP9Y!%W_|p\EwV:¼+w[khn?cDJ|F0 c*1(ӉqٟT%Dˆ?2aV;9 .M iel 9ά8zi:= y~plsC8a룊 I0do>cg }v]l1nA OTfMF9ij3 Z Gd=J`d j~(M8G*7<7ĜY6E#kF օ]oIܝ^$F96)F&ӾibNW# \竕dBS];sEA/yv2_m%ﵨW:Nh\ujHs%'k-$f;Ce ◐KfHۑ߯!61TSXkqW:=Jw;ѝZÉ٫QTNh/ʩ)2BQ| TpX}ʢ~ֵB(('Pl̝8!ץ;łg1BV!y}/^<<y" ~5*4x0*urfRݙ/єۅQ{0t9 A?CT{3(h e݈~'닭W\mU)b#QkJݹL" ]?j퓬}AG2n{,u , D˱Rh0xW-blj#8OW?Ȟ-MjOI_€pWSMlzmz\ys/T"f!smC<TԎC) H+J. g-LtM.r]I +!oY:](Ԅ1WgUL8ߘFd?JΑܤθ hz^5[~Ƥ]ƃJ)9Mv!ҺaW5lmO~TNIA?\.hRiSqAP Uڒ*(WD$H1MN1b՘nHyA 9*]%6یe5E*xjYGP`! ͽ5%qq&18٧EJQA~639LEai`gw!8˙sfDTEJIc8bpFG'nw\kGDۛK-8AW_DE`_3 Ba,L6z3]=USe聖Ѳsx\m8q:q޴D@^IJt.aG~05eu3snaR(8J/ZH9U_6#<:L 9~ٚ8MSĒ \9v9$P;Q|%Ɗ|ܯz Y5ZjF@Ts&f~}>4Ʉ xV_ '85gp̽]uJ "/^#xT4 ] 崱 ޮp#AhlrℼOϻ?'[mt /YE6Jj[]X(PU0{X4SWmi9%sӭwҷ%O6sun)5zÑh9;^OAbHIYSKunS(|k i:Bσpq[`-V¹E;+ ta5\81az3s$v ZnօwO<~Rѯ$)/z׊Z=[Xu(Y_46 N$PP!SEqdKJ*&7V踟M8a ˜T+>t ctvVbO8 6&ϙ'T/x; z3W΂~h6(v߁uC(8t<{7-|w瘽fSoJpŀ7ͣ|C~b{.'}[c3|q=&1R٣vw\ a*oǔT^qM͕+ gԇ#H>{˳l~*B\ NV4MEN3QEY $ѡvF~.:QV1l3))I i L9-eQI 4I,J !$ gC~5olb ,"$ ) 1MEC.ͥ|End.DpƷGf 7_}AEkD|RU8z['@&hq ͛>uXXէcvkLS ATSaY!\m%t]C1VRG]Ja7T8|h졝$A4>geZ[: 1w k(*",-;P?}F856*õ$y{mo@3n!!ܺ;^{ZS97zfc_zc&rNfާL'dh\<4WR$&_Ro}[772t7{qCќa~M`dP]׎Rz3\N*ʭ9aJD=+]JA8~/8̌K`oY"}LU\DsW'rv>-d(cGkK@7MMbY,`b'iVjYⰯ֖iS&U[b7G~χ^̓Mrfإ>K_ns5:4ӁYr{YX{v!rDJx1[( o.u?K١ (#tm7gyS%?Q)$ś"vQh|ίFEjeo9[0 )Jnvޱsmnx1n[^xYqI饵CJR-zѸ/>k:Zkz=Y |<ͤ]=Dv.ߐG)HA2wwSu Di7Mkgy`R3`_4hh/O hJٱW\5"- *jj][KVXWD4a\1&cW$P~] j r&ho35nT |~=!Bq lPFC3`QB|іD 6iQs`A!x&((`-ztA8(Ӧ36WM 4AS גI S."q`7No$y},GCeҹ;*nM`E̅ɔ&EHytjsM6x=<Ʈt6>pwI];*n [43KV޶X q_*4MF6*9p(UMϽGx-m^1\J "@oǻ_@ik c`à(&9r^50%_56 ES jgBPN8%sBT^Ի8O׽#3{@vf57ȍjrm-k3I ,2]ҔT'حC8A7>Ł#zF>lXROͪ؅EP}~ؙhT+ bH B9qUh/, V-HxN`e; ]9r0*j&W3z:i#([Pq &E0Vk οq_.$%P kD'-Q1[$X]7 YC(^ :pATnX:~#HFւmB{8.ތV+R aYkMA~%A&z$]XK3seoԭ RrOsG;e՛F)тb,9"ZG?X{kFc@5&E:*s}"3 x D&K) kh4 ;.#.:VġjfvA%ddxVNIPY^g^JqΰР3 Jysq$A2D z"[ϒlDuo7;MnxX 3M|)VBw<.8Pfڏ65sN?z˵K3zq$BER- 'zD*t> **urG=y+1w:҇)iVnOQv¾?ζqdݪR wkF*lWދyYhGcMaؔbȬ0a:tmJ%^~1 ;eB,2oE׍;~Hzo?'?P h1UoVQj9*[ XL6Kpv gd o3>{Hۭr+psbKPu~À{YTjESK"P+!+M"& (mX`#^jYi;]ʔ ajpM4],cUS!EE͚3/Yd٨97qn\Z5<>SΰGK,zk `EPi;@ɷy2_S" 3i`G Q9! 58dt[[xAsi(F  i>c3Yjڐ]whtWXeAXbookBHݚٗOKqq:5M}+UOB :^-b F]zǬ»i?2SN#w`2ꌡD:#'Y%h3[E#V‚z ^zbԭ01bN5>9/ tqm=Ao ]G}1er آ8uXwcűu;p.|R-KʴmjHLSbS2HΏZ,r7?K`F GNu.ĺ6X9Xy-X#zxjjF? ͿACdh|"#+6y4"#8닂=-%it(Z[3~]Jw/h@}挍n z&/e'}F:w䜕j9*oo.h@i8mţv5bZ~覯#uې=Ttn#Hl3 4)e)ŻYj!tb w5DqXA' !fKf e&j&ٍ1/{hHi$>|iy E. VLf;$diLۈm%.z& _ jh.D +.t]{ INK FmhU@7Hθs4 `1lB [;aNSFF > }Wt( 1ך.'V76a~R>,<;Q3ۦVQ5r;TO"4(@Tz~ ͆=l u|>  SlW E4W, 08SZn^10:9pf_c\D x8w>bR5$}_O$ \)&\^̴7}vꑡ[7oiZ,"NChF5Ujm㐕Jfev(ylbĒ؛tJ<%l p >|xy)Ƭ%`ra ξeׯ:p94Y[v`CwI`=e972CI8jHIG׶(KwmMtɚ`@_q - e3A$\걧VlRɃAK^c?TN],'^!ȍ4OQ=t(\I1i:=7VR{.-m_x_zelwD֦ j4۩]1Zb2sN( wt\fQ'vdu@xi *Lp~{&~&l<>S}ݲX^EL4u6D/᝔u`E% (@J^'YRKrFa{qS&kbtZ~>SE5䙓J}4 Ng 0CW܃͇K~)$\dw BkܔVƻ/1?qwԎ.v6N7ܰpWd$I;wl! #䮨 P]K&6W"{x9'ٓtO8QVBZ_|8K0ږ_ yndhO!i&B[5< l w{=Bo |qު(\fW5dF!.c$GľWl<{I@pJsqxy>[&ʷ#,8+ W۳o5E uݜo#ywfMo:"Ac$Pjۯ3x{th"n8|6CobĬ=9} (.,:n {c:|Zyܓu$iN@Trӂvu3bLtL h2b>Y-Z6GڊqiK/ 劃ʎN Eye%/jq>/_"d;fxgɋT`Ppc|gXMM/uƌ884W@%rWucd8{5B3)'+^K`yn 0 ghXLUo(ZttroEp.%)lc[iXr2";&,RQ a,X8ٸZXů2 ou@'ӹ;>sp.s@:5m7_vBF%sϫ ot R@ 3WwZɱ|1ZvAՈPJ&mNjz8MoS/]Oa4Fݜ\la1Ȏp ;r$Jv>5 RQ(rnWﱅ /%}'}߃m0@G==X4-QwġK+"} ?4h2y-˒8u7s0i'SEIdHV2+ZqSrֺ[Vhʛ\Z47w./ NM03 8׳{={W= 5M&* ans;A&]id ' i. e%e-ha.mL \дhDNw-`pwfx:jvB7y5P$ߵu;nvz6a.`[7lYuC6L[ N˜zji.t60T4$T9#!1b0/3+O41y_C,|*]poj}mA X$9M8K_AiLUM*Ml?"%]0d th &.uB-BHXZ<_,rn">?H_1xxQׇ =6C?<zO/4;LVӻ γgD{k=6Q,'x!a$xFlm.q=jGV. B#d]Y*NTP~l_i1apJ;O;8˽D]]X J)1`[?B]\\q9(0D+L0~#p^QI8p7a§E7ۖi ;~wJTX,Aer{.);y.8b>Wk:|<:SO +L#< V/4K*fAŨ/ΉZ4a,c8msrzz1z^k#?; t[zwk<|~*pac$eHHz5E3ZR??z iՕ,̵M ]6XO95 Ygr`JqkDȐ k4ʁDa$o'mIEm{`ŵQlE-Y*A?MwkVPC=(Z<>Ofl*"j޶!CBEb 'M:uof8ygR?yΨ51K:qbl( 2QA<#+6@7 n6AJ?T[>H~0-@D؝71q:P I$ {CF8 >LȐi馰#HEHLQG3{n;_f횧o?t)k0jA~>т+Hg~R<՗"QT 0#𛠲$1|L@%t FsO/GBZܕmv1a:2D&NGx<țrۀ g8+@LL"Xfw} & hq6>8B˛xYiNsҿ(LifQWj?`ΪwMOKUI0S^v;4 z̊oN'jiaK!F[lX']'իeGE%9CGed)IVԑC4xEy=M2H\- tx:]J&ͤ">0'.`>d[e.5Όt~FȪ\ ռnb|;hCLqG)7R =ӋՏa+*2Iq;H;AA`2KW))/<fuFw}\ދ\DD(,Aa K+(oG}+)qpQ͐qeO΋+hH0M54n6}fJTq|TyU aW$V;"-sWo#>pS.gD 4-< M. (P䘰q#]EM7Zvڙ~n%m-ەwQ mO;CwGI;[p&J8ɘNغ) g\"rjt} 1N{!Eck1eARR%oZ)`Rʘ8L>YHLMˋ%T%VL g=H,ӱuU:GTHQL|ښ__Qd3lLgT/u9 ߍI^#dP4pVƱBO( iZGl08Ѡu0;d~ QHq au㣎#VڀݧdQk%83\#Zqi#?O%f=2/}f#Iɵ.S97 [&ks(7i4Jv?f*m}v:ۡf=JMRGP 0 *5DM%)g՛M2` Dc OI \$Mltk(<>^g΀j*MK3'pjkB%ŸRS8fWE'Q)Lt lk݃B&sTZ^Wx Hl;pD0k Nc I=.6 +ZG??{Zb{j0Fw^ZWu pc. h"$;P{<#@-+ F{LJhZpq ٚ{oMBEǣvz]-.G2, v%'>0&@މ?@ӕnm70e"C:3zC/ r-,0NlF΀3DwN3 vXT`l'6\3 Ptr5튺=zv+R +uSm#q]D"C ghukX;+056Ar0fQn=!ΓWr !?Wb_YB?Lynlrd}f0d[AA B E z023y.z ϊ#[!g u#U]Y{. k̍sX2iA۳TI)=~ `\ [Bm{̘k(LL ċ߶9Nr۫\U{(t%ɴ8ai1Ss2$.z)zsJUe [c;QwB*Hw^&*3)x1PI$cgofa-i,*!8uA~Ne4(MdU]tLb\ubC6氞RS5z uHyȞs7V# |y@/W' X'xZ;I?5PXwfxA0@kg K&+\ ?3ptfCYA]oQNc}*;F(ݮX tJBGO+kPj({rqä&Oo.` #5(giKz7k@dYƐn>w"q@+ .S<'L b_k^H^10zpEOL])Ұj$q{=s H+T?0we`@J.$nMAV]~VONhĴ  cСݖEUK3!1+:ڼaMf-c35zY-!Ut|BsgOZV\el A-y$r46Ho(!IԷTcZsE>p0uC:2'[S 5vtɦSlOɕ/`c+iP0Ct.@9 ׵]t;k ÉH;desBHcyP,͂8DMQmc_-;hh^VN RUk2Bəђ6x!&Q-l9.UÐ]6_ilF8VTX .t#&ҽo?H%oeo!fuRtQ\MM;I!#ԛz`tplf vKzV;7n:4yPKp22jV +`Aۺi,j?C?3z|LAr`M#,QFCSs GXuh2J_((L4sr&Zv5B!dW#Wj; Tz2QZ%>hy;yIestszh5PO]Gnjd{ͱPwOM89JR[f|oH8?^"gk19mBmLEɃp|4Ǭ%u?$gdeN,U \us% ,cA`J||sL isa߮kZFrFo@~IH$ 4"g/9D^\ 5{|.VIshC%F!T&j׽{=Ӿ#Kpo&Nh TK`M|ƸTkvHWXO$IשMU-{cޝKoάA 'AL6޽p`b2hړdJ9o]UT%>"&Õc/ݯ4 ߆_rG[oy!լ2RESRSdWBJ.@B{/2krI]a4V$<3{BXņvϨy穵 Øci]#h܋C6 MCMtpTIgL̶;l-إm,9q)HM/"<{zwv3,GQ4nIY hr#:خ~] :e,2A%ZKFJʩܳtKX6e)ޖ Nm n\E{û }@|zI4ɃV884 *a\FibPnfɭ0|T Dob!|[Ւ֯f{[JX6&PQSF!ocOd)ɻ:d7f\JFUoX]h 7v[eR%uNwq; Nn=R3)K'<4MpJ<bSµ[U=Q&-1SQ#@vs.pp laamFCnMk4ftEU7I^P}HD.Г[?ҜVC9>{̥eݥ= CvSD^cSN-.m~]2"xVCuB<ᇒ(l4JgA7|/:>B.R5]@eЊ509o͚ʱ<8E2kk:e Ke-~(mCҊI}DW>MUlI>˶ &ԞPV| X|6ZqtP]Щ!A4^Y|ή0CȈs/0q$4zq9?d+!u;Z :VW'e^ mIθ::~ 4թ*&}{t%᫿GguBs Ie)$yɔ!%O1,QXQ**WuX@o:c:EHF=zr657|n,*A{g^D zRt\cS4ԳY'Wn;I>.65 gz9,c ak!A]Fã =(v.-׋Uh]}TbE/A}CSp@~Ç?aQG%JjWg3I~1C%Z"@lLzj|X&6]:CY1ۧX+BC_d y!2?Z׉mG\iB'{BIH@F L6$ KCfb":/`CCh>/"G:X+h`> ܋ l; OH"z_~xz}z,",I2<D_̕[DEk˘Xs6k+VHxMwC+!i RLk WY)ҠH_AAzm\?o$R/ ߯jֳ:Im\zwH &BbU{gՠn Cߤ&k'gclҲU2(eSD)@T]鱽f5]oN3PږhcɷG>Ȋ߀>~{,b$z7=hY<@-)_fY},TQiTk:e|W%+A5\{3oy ?Itj۹71+#qP^Gc.7wXZ޹nLUK9>[[?J[%3w{DPhtDc EZY(3=kjR~^r02[hM33H(6/\-|$Rr@IGGcc,,akUWjR̓n-Y.!Ͽ $iQbt:֘8%4΢230Ha:<@;w!e! 1X&;b@3Wb}AC .[ gWAZ[h̃a])O'Yj*Ł_zu wɡϜCb Y6GLغgo/14تޢ?%dy Y!htae.,ef8ՀzNƄ%4ͺ+* TӅh*N{8d-gr,'lX[z V6Pq|MuSt7Yg[dh6}C~gi0l'r1$ye&JĬ\_POe֓dLc΅PPw ά) u挶[Q04@Sf4?fz$.=絆[+P"\?-&IE{<RE|^2ԅcT*Yn :[y{'@d+iXd7 3.8˰ =H"|1GV'sXy0h 0OA5 b^Y!kR*YqU/2<ݛ-k*ǻB4'W&z-AV:MEckd |-w%dJ̳W1!Lj|{q!/`8l} Y ] zWz^rirƃeqdzM8\"ɃA+j:zmLĕgz,ں<I00GKy[aFmZD4hy3^~4=c#Z%w:Tή(:V>ޖ 58^~厾!chݐUާT\y7D1Ğ.<kq)հIh6R>%M˅_GMIs?HC@8X_adkTЇ "(%NDG?] Hc)4c(M9VrF޹mg ` KA&a{Є*ŧE~b5zǥPh",tcBo&kNs䦯)i&ظ.*[7m!Ҽ/SВFBc{*dI\6א%Y=/fI|[,?y7f+"JwtDU*+"IU\M%?mݝy1R3f$Q:(¿@oUUEeJbQ&o9X;TU($<=HSζ#pgy9G.Xuubr5+ԿZC:뻲W[[nm)9Rhf"COw%EͼSdoX;]t,c|0UsOhgеFGȀJFTpV‚wJ| #rholGafy*oь m\vղfu6\!Ef/hɌ-*OrzE<>[my6ٴܪ^[(2*`hF*8/E&q7;x`$.1 "< '}xus %*L~FFcM}Rn56,{űͰ\} <#s56yGp@'I̺~@qoq0k ?Cn`|8IN@+QZXf/"1NN"]9B%/o0φV}ߡ0xN쥎_'CٶbA/5 :I}y?Ww&DG]Z^\q+3$o4M0%{e4&qCjr/9=ͽ8wS.ܬ`G<Ƅ C"̬RJ vXNpryBԾ dxPea9fcQ|I M$PM<\KH&@b]c}{m6\v`$?*ϾFO&dxKO}d1~VT?:`$~hJBX\Wj`aoX?[_SQ!.mC2&N'jT.MuY,Dq̵P{ۧX(Nz*i/ۜZ gxR;lVICF^ǁʺo82oK$N,)4RFAy腆58[ 6gkUaR'\4t&!KE7ԬRqH_ՍQ;<n0*^s x5SCHo6 \L+Z͙%p<[4>mХ$GOݕԬ̪0ݥ"4˛,'5xI0+4=;2[,t/kg]M!-dJk0bǀoKh?Њd Y:jo.0$$2mm)5"M0>ݸq 1ݜAuq1HG*BW}Lρ^ZQ->Sfx*DM+ L2$BB|\CK+C?/2݇_T$cLJĿs;G/X)ŝ3 6V5&#Oan"VHN#cRࡪe1'A ]bT}2G;-EN|HL G#kkE篯iن׍Asդg E (%7NSO* 38;9[H [a :&C;ڻ4 T"_5R qM+_;57f$y ong^s;wb\7Ɩ.}ΘV֛R Wvu'Ss+ERF\փH/"0,^Bz A1 ?HB@ `:PhUfB0`f\Gab}M6iDr{4[d5Gk%Χ} ht-l`, GUkmz,"1՛䘼#w|P2Tدr/Fs!b`L qu\} Hzvg*IDBLJ]7BCdWE\Cb, ]O7@Z^q{uD!;ALz06qbCtR3;%j> *vXJzMZElmms6^(nk7%mG cۢYIH;F<CP/Ǟ^rN?4٘?5){tyj%ToRЖN,brj;X@wr!ͥNF |̫E9rZQu7jmR_?Ɣ8G猭3Uljar;_ ۩<:0緶fwcMZ% UDil?kivc1u] y5]#Q ٺ _w^"CB&!D6?TPŚ8ovҮ8Ӣb=ICE;Ju"_@_ y.,V(q,ixQ('C'ʋt5a4jʇt}hU)Gf\a5KP*>73:r@KSЦQP鈳u0:$wD U|Lb w%Fim`JuRu__ywe3Q|~BQOֆp?-ݭ%' "Z74?M.js7+ĉ%;y"d Q!sV/k|ftUkDթX#BŴ+Q}\_ң!%8@5V{ZoDЩp 9ci'HܣPu<_@3gMMD;ݺa:}o2!ZċŇm)6:RYd(4_x(pl|jWGj ao+Ÿ0ct[O+OMe+>l4Fc˝vqmً4#3?+ʸyդ8, Y! ~SZィTϹ6-߀ɝM8R'F>{$TB#WN' zrl3W\ Mm=/Y:o݌ &vjiWW۝ҹmg_>2$POMI )-@#ßb-i'y.Zf#`&+2kwyɻnaq'v_HRZV&P_Mmig]'WXN\a=" K LF^D;VX8GJ]_ANRVT (zAV.^X$sPYڭ&ޚt%;xKA5QLq4=g2f2kXfMtBhdMra-[ {VV?P ς)Ӵ?x5j5ﴗEV~|kp? n&'ŋЁ[ ԛ>6gT1rrkOx-%_o.DmI&;4f rq.?4uZ']73&! -Ę=VUn!=^C^tY%G{ՋbKd=gW+Jǎ=F Yji)@ag %r*0[VYDk 7n.Qg9>S6 {zb[5yl 03b*gcX?T)x$hcraZ`(HN-C.sZ"<ٻ5xQK+6%YH[ #G2KEi㈄ Jp00ڼ_ۭ?u: v@!,MY8uATz#p>:|*4зd 50KbȊQ>@W&&/ZQ ~vJG'/t33~x3 :6 jH Vܸmr<)ˠ9j7|Ypl:&7zC",SL|ѪJD= a>WZM Lu0 [(׬IbrK/N9==8=עvw Bs>ج^ Ъast &{TBo1ܚ3<*~%zNHx7ӑ~e ya2On78v4ͫ;]?Ȫf~z7\&3Du=TDـ"A9$Q($d+G&$nn#(J~,gC#{>eWal3@/!06R`;1{,/Jb/^o托Gvt?okmgޜ~\PS*VJʹ\צ YtkY#[=nTb6=64sSXI}lRoJ^nHC3Gs8By3RޛV1E^zSgcw \ʜJ-ILGbEi1&{&ko;_p߭.8#gf|/㵹];Z& )Պc 3C1.q~TNkwߗ  &`Ko%Djkp'E4έ:A9j^W!|"ԡsE^$b61H3\G6cjI > 4i?]?$ .>M:ld:O`Je> z;`퇰 frUAR ,_]QX^khvy^ oCYgxΟ<\G@oP:na={Ag6i?4ZB;c6<yWw|zd+s>L_й Ul{3whO':Hד9 ?zN{W'=.5Y+8IRydkp\(}c~QV!{/\XEԊ9 o'cj$MݐhII ,szife [~{,hˑTVvel餱i+.?1wb}PQ;@ ~2Ѧ{O,z4}=U(\k9I@&IgGK2;TF~H=Zf g^5JCivb]91Hc]h! MKO,;Է>,b` {m@RAʄ6'PTtHJFnAS6=dwJE/!q|S ^QK9 m3ʚOGG`C<6mI]}Bz50i4[ YOLtOv:s<' -f1pu B:{tjv >UH 2~pQPA9@GА ;ZHRX[. W]І:/&Jte#jU){S^Oj@z;e 8 $jm3AE+rhj)IX*S@NWeqs}եp3٬ B@Uj=aM!|Ce;!.`({%bhspE 1bEJPHjRƙPrN@Ol=-'}" -Y֙8WUZc'Z^v.s-:N{g s<'ݓޝ- S)^N]ILꛤǶЖ .hypGw2J?yR"CV leJş>ؑgECf(3%eœ䊄 d8B|7_hMya q}7ü_x,F198XG inD.igiY8W?0 9\/Г ҧ[)hf\cq b*)zCR߃,lT޼%aoќ=Z[Tr:v( omwgy'ȡC'_Wte0f{cވH.[=WviS';xvC7n%MR2yD0ErGjf˱ -"䅀/bLiK>#`fx^K[W`Z*;Ay,A˲Al.tdvxF<"k"7ĆEyϊ.Q5Nq0<^gUF44]wyM,-=G>vl{3@%~6x?K-{dGGJ$̙g('p΀?i>?yk8Fz[/R,3a(e'd)=.p'h<Йg S2W$2g1 TNSBUf0輯ϛCկ ˭lT"eEP^`"/ NNf6St38hBpPr'B^~9^Q37.mRX "ōխTBF;I~q?1oѴDh4ig\yG1bdd3k<` De/#dث8+˗yMV\b}bP4d۹+ F,leU dkIO;I'ki$5VQeG>6kzhyi:d~ՏZC9񳟗#KjvZ Lm)f-霡 l"A H^/zϞ״JctC”kwO ?rlS8]w9w@g`v~uUnTxK$n[œ*1ߋW!B;9頳G{uZF6;1HU UV')P0"EV'+v+z ^ɍ TYaby[\ă|V"f\B#guD2?Z7&rHY [rJ*6El-oj/2|k0?PhHgǓ9o(6pc|x^2vy;z #s3_; g羨Uе;\Ł 6 τ_ 7bSQۻ.>}91;z(0!cme]\o>5zM񹮅~njE aw KZ<@=OFA.*jԚ霵h_)S>ӟ+|ŅY.>mXi6>;-4cD\"r{x݆OPQD 3nlfJֿ7'*.8}dYѷ<) 범6o)ϯnOl3!G^`ꥍ4}ŊxyhRװ4Z[WȪreB B1::uѱNqH}Q#T\t0巛6įAF3B|M|k^@FKUp4IL9өXEb`iw^ |y /|_i|5z`Z ?R#

TaeB\NjT9r pM\vՌ$I^RU{N.`nNH8V…~o_ց[+@D =m9u֠eu ּZ:[b 䁜!``Dh36,僅`qSXTI; MdK{nSHz{9ҿB;Er}ncLĘGCH'm8 MUHQz+œ#lk|&9Z8FF1,3MXţa FDx#3jH~&(#dx͏Ybf5L.$ǂWkaoh TŽNshٓD 4@ط⋝A]Il8ny'yq:ĈZOy&)"31Uby">5&S 7 7ɊFtҞIziT Q^lVWztn掰#̟Uat,&"æyZ/%s"s (Mpq3eyF,L@x߭LE16'SGAb'V/^Pn4OFa,g1!UVEq >„gnfξ֚ JV%?;ӧ8sI3ӭǛD+[(X`a!]+si_F$;}5"'^y[c8Rk{dmHVW$7]R-3Bl a|C =1oc+a"͆ 8*qUT`\|Dxz=[qUgnZ[U}Xc)u$_215(=f #iv=+x~L ]6E3^>:kN]&)6D v St4# ͈ױyd@Y@ccO^g4-D^ hJV( 2o!ړ3ndpU!w*EKlCxn-HIEv GǣgY9XDN !*g_ͫVPcH:U^ o:dӥ ͯ'Dq5'rV:g`HV_[֢y{!uU֪b\g>zVˊ̲&{tC")rEcGL-qP-{. FJ>BWmDV}RL2N]Kwx-G> WJؔ5w8aE9Ž,!6xa J&^LQ:%}C^n`\m4YS[w$>ԃw}XJ Y|v_˜W*_{ǑGM\O]&.e3KU*  &Jk(@:J$Mej 4;գE-\wݟFVFh|#Pc#aN摨N.@YRoNYܷqvO/`@fFrX6;`JF"j*3U}f/C.`֬L8 A1c9JަH@t_lMOsQ55T[[T5NW(Q=螢.q4ݵ˩{@U^~qcJn$@mxEZZ1-P@u'#wK:Z@5Zhd:%45SC]|c2s1!О#wࢎapPzCC[Yh&ձUZϑs6xyĄkx?s +1FWe$ qhQ~^-J‡o(A-AFn(NM1ALDAn>rpp# 4]Gꓔӎyr`HsXį:Qp٘Z!$) Eh8mRz$2eM\+ G 4&\#**gQwʼnm-WMoJebZ$8Gs*2u~KԶqIBL zA^<jQĔ;\v`dАײB>̲,3ҙIuphj zxj5+zetc1V* '5L9%yg͓`I:ZOC#ۚ?rJ˹m+ҫv;cU@Q E K<ڿBF!& Y5>tR9*ϐR>4^&;eBлZYSzd6u,͑:!2 3"KW>\WmRd͒o;2XoZ x*K+Sr]2X VK7s| 4 .w*m`o)tї80c6G"❼^ AbstGeh"q(5ߛy- +[/Z`#͸E}zljW߁ KiLL [:~}g  "o%\h)ƞZ}pA-^50t+}T}:K 5b|ر?k&S2;F)d))p/^H;J၀d]oKJ%+8r0;iS&h'f@a;l2nwM88+X}¿ѧx)wcU#è# ?^E.wХǹĖ46TV;^|J,韱WÌrJiŕSAI( )pi:E{1p?mpffB.@8$wfC*`즚Ss.Dt &;_ sJyԧFH1#x.h3)?oBz"B<½o.۴oSkLƷi"vNTTY_-֧ zBY~OMaa0?YKJes3OAH.5(bEA${I6lLg7|k|h3dRԵf TsxTmVe M@ ]y|[$+K7(y`ᔔ,'x[zSdJ%|G~Aݕ#5Cob!XL#|AG%uo,Φa ru(3hRV)hT 2 JsZfJ+"j&QY'@K; hJ-oC2g JKMF&4FJʗau9A8K7-W&mzu͎Od^gY2 Vk-y'ʸ@~MimY.^/?n<@]@fd8wޫoeU',G|*5rIjgOM@b=$J9֔`/ϣPc4=7 ^y4']P'l%=Sf SX bW,_rf%'Oe7r ~NT'=J'b->oRon>I)OO;k] r2cI.t'2CU1&}x-Dɿ4 nee;`E7 ATXle r]hzp]EۣrK)ܘD:ż4u{m+X'0p#cU@by6)YG n[bnH.:;b=$8]Ft2!  Mx$DUOA@+3⟷w'5]}Q-Tn~ .)s`Va:؟3pZ$2Mb_?|1CW;se:A1h3`T5bl`l?d "rҌK-UTm/n*嫀z| YL$Sb ?gŔ,44//2uh:("\mG"A:Aw&:Y2_vM87\ TPQ&?8ޥ4Ֆ̠@ Jw s4nC@v8sT8ɅXp0'|O-K&oP_g3Cw,fD0({,B>H _}HLY[G մuoϳwp)էni`) a?,ɮWp݉g. +mgF&Rd4sce4uo1.ȉ剜@@j&o)ckV0Zŷf6$T`K(ɇVx''.NJP0p!~ۿNvjšqyf*>8d$tFu I޳@aH22Aӈ)(}nLoM:Ցy _C D0wvyFaZ.L!΀9 gs^}#-8_ݤԁ-Gv=\:0;n%wTu4+V]︇kdF[׍ ۚ%6un@.GB$[W 8 ]fITd8G($p@uxd%Y= oImKzc%dF9ffi} @LX%M66I(_ǿzkOcOMʝ#(̡NWҙldE%d}^rn2rAzh4m'h BW񆑞K#n1AJ+ =gR0GptMsV[L'rE{6z9§H_.zؔBv0t%#ٺZUF9|MP>I= >wak;+a. ?^K0{Drh4ƈ*2QcpFj}'5.yp]KeF~?w]Ay|.yl#TYڡ*Y BbT!$᪪0^zʐIkՉ+NL/Ѳo`i>cjߑ(J)ezQ<I~1kُg*tabM+Q˪MhTA5x[msY>w~껨&{ %7~8HUϫZ9 *|‡!IפX8@9\.sPflVj2krcTg9C)- Wl*(z}rjO PJt{^zu*<Q(|#8qnο]Z5؛> Us!Ր$DΧhx˜<HqH3W)9vdy²jo?fJR0~E C]=8r=&JHR{˴>/""C0]f "#n0X)fq(t#$ EܴEH+fchL/_ɟF&5ojS~mJ6T_y?wqO J]0|bvQeٚn>en|j5tS,7Or\Yu.6":6M,"Mʔ,4ڮI # [;hlj$ AX4[[qo$:Dyqn#W2=.Of|6e!gΗ%z HoKUk)ʱᎀ21HD Fi9 ywLݼ#徚?>Q5ϒi^g% 䰯]b֦ D*g##j4L:z2(]slgc6+)>?UM`|#Gâ`Q1w:95M8 Rǘܒ&"7 kC(|mA+It?SESi K]PP©ߝ{Id< ^V.W5'pūߝS9S\^Ҝke$IRc`hsΔۭ=$ѶsA}5,E)܊ư,htTy1Vf:lBZy]ګCa`BIiAxR#^kw Ԙhj+BfVgS 68!ؗ>~R@8SQ{JzXblK ~"9aDY1PHLJ9NMGd00{M ?K383qQi-e$j( f)VE2']Bn΋ G҅|s/ui#c>ܦk -[W{J֝(5ҝN quПѓ9l.O@һPA2"dG| w "oBIQtL2ikM(7%ە>1#e-ɪ7sXݦnRN{W[Nş6NF&j?pG&WBfJhgbЃJZ cH[2nF%FިV ^=}p0 m%QEVA2X&g:t.;()*ˋF~</Y2XeZF|0Z`-$dEb@E6Pct% QhKe!j]0 \jf^wfb|U+3ooXZӼ1< dMk5UV3Re<3eCoGIʨ@/ טe-j*zbmuL  :ndR?Qayݖ!KacQf9{edKSMuH~ǀ,ɗuĹ@y›~V圌MȨݲ,4՘zZ\TcB+ʎI3qD]wvHT= _(uEn~8ٷM_ny9Fɀ'ehjǸ>Qd/→/FtOej=P h O6)˓O}(,rѩcmrA4 H*Sva4 챮n!l_zz)KuOZg$'tY ŖjшuZ`8 *^7;Fa/1b|W nnnl~يX_#v￧+~'.<`ۦ,_oLRރ}o6w|`䠣H, /P)=loТd)9eSCM dc *A( $LIl6R}GAǤ/&i9΄B[z䍌([=HzӰ)/Gp8Vۇ/fj+%66]-5P?0&ۋ@א*xp*;Jw6 a3f݁c@ J!D1+5[j(m1Xiosb"[=?-OLּ #aϐw qDөuz>e;ۋhUS>_%k&8,҉mNi[~% 'ݖrQXsM1:t]v "E \ˍ#c}i,6 ЈT)SG$k kH_Im/2_s&ҥ󬓚^c5_QvUT "T[95) S 8у"QD#bjNOUc14v %ǀT3+vv=PlSaT}j7ݟK_.IE'WR'HI*y(BETE 2Zcy$`,֟7v Yq|ѪBm#&ا:13Rqn75"oP ' aF=~zkkdο#chP8FHy 7Tp@"UsoJ'*"ӚosRg?jIhԑ"X%4#l*E3ZpdIk3wZL_Ҿp{iFt0qQo8b쐎;viǬX猐v1Qo,E H<)Լ,$R.c 3kMNF=l8=f>oAX-OX 4w8 y%Iw<|me>M o.{:?QJ$\ħ.UF0!FsD>$'SNW}~9Y5K7RO_4)K6 4F#ˎ4;& }un}nOʪ OK%1ė=͈ S.#4mD:fw!.-O@ȂVc!>'&9 6q4w'D֡yЛ!R_IMT 7+گ`RK2L^h27?Ə_t%Agw#Yj΁K6a'Zؚ 0Bq2N?'XkCB'cyέJ,nRV`4tWӜfN=^}mJjyw-Rv|`lyeX6yxLJ,5A,oAݬzJ e= R|T u\/:#xN.:}LYi ^zv磁9wW|Hc3ܿ,kX]'Q.:>4n#~ )B{L):; PC.@ 5+6sbH[3o&S:uؘ}_%ٞ W;uJ>-IH8Aw aYݨ+V6<͠6W evM9_٨Iʍa`~e;0-q  AmsIN!2*+")swTEë~.0TNb%q(.6+:P6cU|B)q_9Cwp:iXTHt[ V@Д?T3,ݸ^+f2KR㋔T1bH,"]0r,:9zX=.2T^b%*ЮTŌU6ۄ _4!6z}Ta|EiBnb H 71f yX9`{?p%4&2p:p!0uq3%ucSWPnh^aL *Ĭg> pQqnm+_{gB$lP?00>Z"y*r-2ߌ>WZŨR K p2kae%.:{r%lXRzz &A7X`MoA؈c }TF\1FAO.@ 4[ A|:: OQ{B Mʣ*%)TO]@k@0( ~Pf5ѺsFFAS.Z9GVM  (zi[+>Jކr$s'~|2:Nܘ$'dxYXwq-Ħ("p ,.wPW8f`ckI` 2Tdk !T+FrQfA{jj>eյTH>wx/kv/T\W$^k>#:+arFGT'qi+8k8OoqQZo.XZQ=‡LR!ZMOTW=$4cHE۞`Z!2Â19i.:[ji!0 Pk'>2uΪ~р$yHJD}?,~'-z"2:8/4k7/:N{V?}HI7* sOAc:qfk3:ո P/=`3[G#4ƘˊDWV&3QʩR_]y/^,cxϠ\).. iATnp}6KjR12oxN:}-+YWY 9Fnp?uV?[]C:QJA%fܑc5A\u䫽C%}Hj?ձF /nHVViW!UKb'e̽@}>eYӪd\(ѲH]/Y/0J2[ ; F8pb!GiQ ^0MNцZA3`A7Y2gG*ImL*?$ԏ<[{'a:>La@ȫ ;*<*SygiX!BZ7Czl~xуonéxzؖ+ԊEQSo'u]"|?r&@_*ߝM[0KD_% Z{znٓFygyI@G`,iՄ`<*Ul(ptO3{X <1)5o'bG!A:Qcx/Pl1]dG lER"rrKfnG .;A=Nae۝Cq!;:lLX-#ZhoKYsWRBQʏ^ ' Rg?W: 0Z~PN2ś<*)Wr@:oXA0bϹ'2yI.U* xV !+A1`-#\!Gj;4zϚ0ElA*^uqyұt#$\ PtJ Q(_<σ8ZS: q~.W}ȮIw7L>HQy3#={,`"vdE:<īit\8B27:6Y:@֨tƪͲ5)0!s@/̭X޷~Okc0ttK>F\ hzT|]W"Sr`Y0X^K}<،CY{h'9̨3a zX.I)~#|Pn~G]G4t5Rbb @8jv2*/oY)HR|:zRE' ?rѡ*:cvo.*ɯ7ܺs<16L9/:R O-`Y#\dwy! '\tnՆ-Mnϥ]A6Jlxg=[4ukٟO,\Çܛf)CI{4{k';4\=nFJ{hz&%]yE,n=Y]+1r#Fe'ߘ91\Pr5sDZU9 BܱU帩n#ڜJ7|P#B`.JAepf]WAwUu7H]eG6ɬi\Ihan5xd I-kZ9vҿ2i*rs".5uSBXjB%I.poh*e2T6J.A"YC2^w:R1ݞ ]\%W!er;)>75 낢~0|u,ϲ=<z{:G=V}ն&}T!lUp+θHyyowKEJkBGyh?'ޚ/c1>5gb#'7ک~ƥ'Pg(^^MEJ_ 6sޟ6`#z3ɐ1+tWߩ= fm5mJIR HF[t (>3)r:Bd*HOJcz}!oc%^}6昭{>M.م.b͒;$o3H)$ A+&6_9oYM8\5R%ZchZ9 {tJ;PÔ̊a=I @G3۷GpB/{cfHzExi>y* |FV48CN v*v0l5q_b,='₤nl:iu;O\SgVh\ x"WpT m+"7>2Wmgکp?w0e*&|kuivZB(sY7?a1ue8r]Bp,D(JŞ,j?#SVE`֯Jq%;+7 މ=n7(ק=5sEYL\Xа͓}<[t+5Ax4.S0iSWjn=܎96tS{-DL04E}&;T",P`A`M=5r&t;MnF9Ԓw(L<ZQיYzjJ@2y15uYlW,Rt{bP (wjX䄌 7Zj rwccH6%? ni{t6w!vdlcaƙ>(I4t-?`3ڏ0DDFlˎbNC~9k$]f-f{KT%7 RC-on=M ypç\H DK@6?%rڙ<͋Dn.A3=ۻG pCeC=82BYNcr/;sFR޺?e!fUUYq`DR0ưXpGZpt*ôK(5o%m%{xT87wܸn N<]l uH{dԍPf<^}f]ZLy& >gXƋ6{ *"[` >X) iYk'ADP"fD3+}^bϡ9ԓ`!P.>gu?p˝Mzڋl7#kXN?9&v? (dG8bBh*)[gK1 %eQʔxjnu!u:GmUZp66kH/=cal0YgQj!F)Hp4HLF4j1fw 48xb;Ck8byKgjme3 ~7cC5G4"gHؾsۀ9{f6\LiDCx|Z*\ F!>GŤo0O܊tlxYtb1!Eׯ FI) .ؑtW7Dj,4ۻIq?Kƪz  {3͉4ҡJ䓓qec,cTH*'>%]SD3)UKG?{&mL^JWEQ3ܫjcϢ_{D, ?!CT?{#,/W_&zܨY`i.pzݙ⨛Oh2i7ե9[n ůɽV~OXv m{o;s֨CœOSy(4CRGZi: эƒk}k?"|8?q#ATWQ)Z@NNj $8S;`fDaH"i}gQ w; TOTz%{NkJqѳ4ual7mw{!$g~Tnc5|Dq_upr?8֡xM7&Em%BA6)Ωxzo^nTU|]6mp'J!$~pwe/%H,7s3& goU$zJNC8c!{*4XLMB]”,uG5i{&(Hlc}?NN24L {xc*Zt`aIFbdT DfD+kD5[WPԧ,+(@%_vLC>kZ ZC 'Հ'JB 9rIQIaѭ!s7.% KWvU,>thue3SPF2)zxe}N:>[AwБjM'9~sy|@_9 5=%A+M2؞6~~p\2{X>Mj+6QH;\ ^Nd fn5cLŗDKCdJއ僛4p(ߡ)Oz$o` +,|EdxPsБ^d&rcyj*|C2˔gCI@ vJF13[bcTqHAnOKb2AvĉʋhyV ^:/EN1{"DG{ Z o,qmID!sR Gwq Cx!+ # ~ ؂@@MQ?TEOkB5U<,FZ>pॾV2˷xI z={!sq7r-]. #g@=?L4Ut[ AZmzǎ@t+p1zAjP\Rv[r<'%=4U?u_?[.2$v"tпm|ox8uuYj?%,c(lWGP|AeGM }P'39%5rRNQ٠&WPFzq&_fjDh=>0d5+ڸSe-”ق\:ڲ*+E!lB$ .d଀7Ho7NPdHAsrpk6(Ei؉mJ Jk cQ<:UkKZ3huYNhp¹jtb~=E}U7NqbI=;I-c,К?!OvJ 쩤T ~ tG{:X0KY*aC\)V[|b@&ϣ>P:*?? /^0%uO伪&_Ɓ'[BOʄLDИȬРD`{)b>US tPQzN(0ZxT%y Q#MoMRU.H.flicnVM0 < .r1)Û2폡 7"{ӑ?6rwO%flB:a್B{N,i1V)* UpԳ ~VS#u&BC%xH/-PL[$? s֚VEk3ph#}jۛ}yS :Ͽ֟^㹋*cO$}x/ۡj7uErw\$lZȩ'!? Ѓ.=64YMCqp)Y}>fWqlY>I7tY(/qW 2>d^F?=\!W] tӨࣝ;0yLUH/g io=nizN\l6za7iDUӼ"%cAn헴N5lUx3&Qa*eA;]Ea[ K˧ވ&#}Qr<+0ē\@kWQ|+v—#5ezXOwYT7\e?FC$AX!yvٿEQ%ѶS8B9Ѵz;~WEIg #bF*0ver)&CKN2V@ukP[t',7 yNhR _-0/ 9w9qD8B) 螮l.F]e׷-'%U:#LW5}f)65.{j?/0gqg%Ԉ_+6]Cz#s TIL VJdq`{rE - t%!F]!2ȾdMuFPΪ@1ĉ>fA8P'w(5tdsߐj6c[XQ?'. hͧH.Ah3q@QʎM~nT8X]xaO?-ȗ%yd8GUꘐ#9Tgڏojt˅EDccT%jao-HKg[ C-"!emuiH'e-e- DlU *j٘{,o%E/ԳlJmnr1Ip^%=|U'DyLLoJ͸1z 7;Rufu } S O&# ]g|C 919MR ]/ec쉸⛴%. nI+ѭu!Su'TRav(g).Se57M?l_&+~SE Yo(`,詷D&vY L>#rh~8ӶtjınنDd M+ kfU#|]oh*gmVp3JSX\+hy]ABb*O%$3A .?,;~^v>O-=8)0, GXFa+Йo]OY,ч-7x&fh?-AzX}  wBvD /)?ԃ`oVH}Сsd} n1Y'f8U52Xxĵ,z!Y68̠kG}2_ nG!RTDiw-'`Ь<tѰNf_Π#/)xiDT yZ8J^QI rD=,Q>BQhKb*xޭ\̅Sʋ&u,k}i=*LY4kZ =hB(Q"g4_d~c4j+A@KFb.tsc2WJ mZ3R\`9P ˥G62%@NV Onklw M?,>Q7:*=c4.ig®竽-t:ًiiL=%Ѥ/!!qPlJsEC^ |V eb,"C7d=whqw{HeaYtIu+jD#0jZү״9~uޛꋳBr\:Gt=EH^KΤA¢p8 LYS[H-.X5^L.ՈVsvՖ:i!jB5'(" @O-0)-TE򌅾Q o-k\754V#y^.n/F,5wqdN )?N"/^Vq X) ;X-~e/x2:ynb6*=n[R(@;F3 f [@r>Pwgo2Y$4ū2'^ޅBaѤ+B|YntGWV=l9eR?f a*\h썹K2sH6ĸ_? 0bS 19qCk;+¬dCOstR;)Z @+\oLy<xi62I`!^]!]ؕջaEj՛T3Cϲ#_M= 1@rElqWkB5|}6OGg#So 3Z.6_`gHᢖGj2}y~򡌹2sDMX50HleEҾ)H{L= uB0`)PQkc BJqr sGf}̭MR l" V]2ajӊ7KpC@ޗ(7rgYqȫ-˯ΩKkiў~'" mO)rOl?x<\;hŁs5dlX_cr}znk\鉴n6c޲K`pL(@iX5)e?[#P *&j6&b%{ܮLC [9OZš߈}{x7Sest/&D8 ^gY"CK>*r6Wr3R,-e38gp{2Zޢy#[Zs)]։`A9oi'5I:#&B`('Gs=bbzBUiQmSBRIh@3(DONvf'6A>FꉸE [:Mi-6P41?O#WIs%d [pO6[oK•y"#I'mDk 1 `L,_'3I5l<Q!U F4j Yߺ1j*_fAzi +Jp4?#^K/2EЂh7KŞVoW*lcoU2ſ/+#E6QeJZi! Wk;]#䤈5fc|ƿ<)cd`k{?4TooEfޢ냘iFmu/!eiR4]?}Ѳ4'B  q^P~P\s~E¨Sr lE(z1+hcמ.gTU+gY3% cri >[ א1UF ]c[/Rwz-qtd/-3|S4rw镦2nvX,ɼv/'U$̸æmqxa@y_ +p&׼Aѕx^q"Dۢ"^LqbsZI)Xc?L&mck'4LdSxt"`a&ǭvA)ے|I,nk(U<ڛ 딼T?э?yӘb"٦VgIZ4=ʀVm`I/pwh5 č}1?_ONg!#`hufvҺzͫpW,-p؄@{އ%WEvV%QZs̵8 yTjdC-w΢^%ih<ط#P؝RlE)*5`w \SzUtqeQp Z'ZѦ.)}@Ar:Ru**؞\Ssxbe 1G?* CXUlQn~`*3Pr$޻gԈ02됈6$դj8xe kA> ہB_m*BP~H_AE'3a/O(襓2b5+H s srʧHZԕ\~8g850w#Tjt4(,!j@ 4/qq/dE+%qjI8Zqa 7ðxf?#V}5 Td[Nf=QrMs4wН %" 'e:2c)ݝaԘ\tATg*x֐{S.%uÌˀQ(EO*j!*aap0s (8;)8mB3st^{8F)F-_28T_C*Ipj'[+e31;[$:4UeKg{}^D cL9ǀRЅ;OjwIYBK\oQf1;R(cd Z#7lz>#: u :Pꀨtm(.ݽ#@ -5m+O< Faibΰۄ%10wuB'+k"1r݀km! C$>5ℕ'LelQuQ "Ex%-b fHmH}Ky=BedOyc֔6b) JFǵ8kA^fLcٿNZҫq]Í h|˞lNPKR^߿~*~CPQDcjY+]Xo-)kQI@`s ر-Y^nZeeP990?ֆmRK` P)iJs S<$g5]L)nB+RԦY{ Ih/VPJW6I*29!O-Hi! j3W99tU@A{-L!hMv?aCْ3+ԃlr^-$/$.TOPijxZa}z'I#Q!_lڒR!Հr D1-1^@Yk aƻS3"ʢ(9L1+ [UOQV9ʭ|:ꝹBV2w&qv0%,#`TlLdʰA,6Oӊu=,QjF! Ld,F:vz4e%*VaV)d≃n#H-0Z;DRn6 >ĐW\X%dh>dV>*\,pv9\6̴HWIYߑ&ғ[KN ^tGK%T 7ltڷ_vU5T7-@a l1*SmlÓGxL!c(W+A-5W]u0'0:GYH9A%ȶKɐx*G*1xU|J@W@kY.j>q<\WgHjDH}_}l( Qӫ`^kҵ#-<|>fѬdԶlMmz(l\Ӿr_j*/.cW{t<` $"UT=-RMd3L8-ސ\&=c H9R*`-ҧՊ&O]QZRRS߆W×.΅(qFR͢+YjMM=#J`Б~%В[ߡ 3('Pgf㎡&A%ߕ\yӶ;(щ?83*+AKثoE y@[Ҫn`kPj03tH#(pf79{kN\;M 8AlL6xJn{FqyoQ>ycV(#$ {ؚ!2ʊGgUE?YIW`$[Hj?.< ȒSApNFOz#'Fmz13)çP| G|n%7ej0S8d;opa5 \jމ~MtĪY')}Z 4Iv7UԂ3`͕Zc})=1R )]yV9:xEdxɚ'+h,[y a Ys Dx0g쪼q-E3ƠlP0/]P$"F-3͕O1!'jhW=e~+y.4ˤ ؼjI YˇS9t^;Z 7Š*Ls%nf20g Xe]!ݵƢ*"ykAɸf]𓥀j&U)~_pԅOGUXnGj:nЋ PVdT#7]4=a}as?r{6Vߨ_a۶WX$Z ^7Mѓ8QvN2XSvrX)=@CZh6 F|W78:ueieW s{$ZQL!%ZUBڶhdab#+}ωn=7Y/w"z>y]#[(Kу♾;Ô~g-~̷x .ZE6AS0e_XI[C4.rw$.zv#-)FK[MeFV[o ی8}:m{:brՏ/Xd+iulR'DDnbF X0\NEk{tH6Td6ܞ4ZJz!Ln`3#t3ԱtᎧHQXcS69Oye79k~E/~2*e)ʪ2&I:_k]aV /_rÚX*gu#_h FR-,b0pt`_|9f0;dIE!R] h3j# FF;Ks)8,v; 7r/*}0^ߏ/Vg+֖7m1C:]Vh.;y'B\M$hq[fsfi})*I#ӓ0l 힌!-9{]}lc&1"/v׎PXFCr;im38:-ǜ\kJ} X74S].YȬ o#!~qڨi"ў* aR4unMw|LpB,A̅kcx:nФ 53$ M,: -oPJ^iesX.v'py\sE[!V_D; u .gJ3sV/u5/18&z{ pԉ--E,#RާT*J  꺵17ڌ~za,̥NpoD3&iTd 9Z$mgr+*%kS(*1ˋR"F/qUlhي#а[-0+ֈ͔HSз ts,I V::[CVji Wbƃ֢dM? bLWŮ 9lg^W6v+j0SCS ͠LI=Y| @䋐E] ssgL=u˘^b~Ȑw5&JQo?h:M]28 oGL`5>^*$kni5~'Gp9.s:ʠHz+RloXRm`z[`HUZ1AG4t~(Z4+HjTcm,-m!7IAxLE\Wݴ6r>]I$^Fs+aj*վ"vKm\a١rArC94yZztH>y!Ӯ;ҵ1#_}#7aiphjI&8sZ +71f[~-!E SmE9QԈ Dn]%M[d6j"M`^SgR#x+{Xj> ^7`A6 dJkO&] $F8g+\Ptw8"KSf3Vww|{IB4?)V[ʢ!Aa3bzA]qJ~Ūb79F}K~*u-\閬A--'!e0Wo ۫JGV6j&5,}{~܋. \"xqx`*&kâZK̡].Q| {dMcDӘ@m i$O_tR"+"e̥e"[Jbo;9`3 Zx*Z'-{OJf0ORx䞛eb G]_!l7beߝ`ʂ_~㨠eTc &΀Μ􆗽[`v& $ΰB1eC t'敟nO׆EH+Qy+ i`'?5w8`и@xWkLe]|Fp#HӱpEXa'ϥ熰kv+h޸h50B ;)Y ﻓ &n8{{MSDx]uWeۆjFv* xHHA"H sLA䞶%%gc'vZ3IϮԟy-r*"=y$hHV1tk'/ #R;YXݗֵLp7zg˜+'=75x:DWYQ''?wV>STᦤ.XӈN{or|Ldgy4t%lHjv@59 Hxv.;W/*^}9tÍ,uDe;ﶊsJ#=T(Fl?Jn?/S  I\Ł!N4t^09~S@%)[tK^MPaz,.hX9 ԰1TzB`X ?5 r0A[6:H.< 'g 0f\u.Ͻ Yqr9cL3//!,DGbRc7k7⯬u!t( g*CV|\AuY-p>~-Z=%~ؽ{Ώ:Sktkxg￟}tY) -̔o?PB99 U0|Ҏm0MհZSh/{_9wdaGbc Jf[0IRT;:;o"қcKŸuЁ|r{,wld]C1'O0E'6]Ve -#B\UQVVB)e srRr(('"c8KӼ|c[ğjONH>_!t[0DU$50ى_o&M@hY^Jƭ3I`#tO'8 9|v}gRtZĈAkrxPFJT֔2u6f>,^Z4"v9tBN18qe蘱C[ a7T\[J 1< u0|}!_ܮ F?zu[xbs8'9CS>/wq?wUߑpF%k7enErzݢU=/2A)θ cݠ}hn$Ih .>م̊Zи/Gi4jm|+YTi׵NOL#[%BIm'RS8p5<ߎp3?w* #ϠlgTy@ز ɚ[+ΐ2[3IZ|\,?m*MfIf勭ոY =;c,DpX'#"/L]7Yx*Y{_O?:]jr%.xX>YY@7=Q2Hs"'elU3#};o_*rW[" kR%.7Hϡ*>1<ڮE\1bT#.%ʥLTaF]ݞ3/F)a1Er͏[W(sjКr7h˫t-]>sa/h -iF8ZgS\_;" J|櫽on|pPҨCM ydՏ2"!?n0ZaD2>`QD=^ Z` bxEN>؁Ж#GIGr;kMZ$܁ߩԼKǣо"x)c3lD7}FX&[1oyO=8-eא"dEg#ϝ !7č2ɨ7Cgń7,{6Z +$X@vzYfɑ7L?/gߨu؀0pGSq! 8Mͬ1\q%MX5{!XKEHz4B;Ѝ'«r>xi,hb/tSN/[W?V<_^vU\M~\O=3Z}2,Y+#U-:~W u723 .;"F ! /?+l3š7 t8upp%ʟC\{W0j\hW#+Sȃ즋4?rYEK\I|Fu Ia@txu}c:P6*;\'Um͡)4|4l rEn_Zc]lJweDեt~DՇur |8Qi>%c-r=6Pǰdޭ):P 6_uϓAb X 0Cinkج6;m3"%.!f*Դr5D _@>LKӧHBqz_^3ܥA_gFX56,:p@S%85C(Qjb?&Zj@r:KݖʏhN._9?gV@\KMfIv pFnN<+^Ldm]p? %Hu6eŸnV]qZVo$';De0)ڐnB7FHD$6KQ>m5:}{WxAmcEl|>!x畺C}|֜3T ͩBzyvZAT*;Y}"J | 6h&BQ8`\ :p9-k*4ePX.wJ͟Y`0 u:^řX)ڟtUkK!w,KN]&Z7 _vu- ys!?!BYy#N|e T!Ŕt4@z4AQЅ+/1~a2TQ"p%B?UVxF`cϩ'yJoup E p6B'BXqLl#v쟷(HdgR¨'4!zC3ݧ Q8J[jf/%^f486'.{Ϳ\2&"w%ՊoR]ǎVZ.0/|RwS0V^Ʌ2wp7@>k@ \C5ZnC̴MMLx. VHd$ߡj0@ߺTOB75lN6\G*PǠlHy]2WF"iV穭b"A2Hp#9nTWis@bgg%ON3RpSHb4REM}弮bf LPNЗ)y1|(i5_ُapkMG`?yHCsf/1KZy6&٘A3tSm\Oro=B !KAHApf{\QP>ˆR厦 (冨Q⋽k?ŕx0#/n!\m9oJWԟ. Xm)8SNzC]ۻmIu85IOA4v pX5Ϧ1PppRрfLhfnǒkwD!|+7l@/6&X%qMJ5Թc' @&*hv1Ko]z,2WyC颞36 'WMjlCá=|&psc9j7y4&>؈lk{'ipx?iߗ;ΖԀR 8ѭw _bt ѷ̌:(v4'fc}7<20Ͼ9KSy##+_?nAOG)o^@:<2Vwö-e?-̋5AǚНGoG.i5IW<-̳ u|Ҟ rK:zPqMHÑ;B<ǵ1dFZAk'"y-Ν[Z#a~ơw=< <^8]!;LRZ?BIȪ 9}I_ ́|'t,s2 a-1m8T|š/]Ac `% f5A)J4k˗!/ɩSs m,/b2gM@2MЧX/"ۄ*! 1p bf 7(@٠_TU@O#(_Z bW2Rid +|R` .%`E/0kI|CAO%AYNM3NH7pA;v,}&,>7QL"ެ$v柙D`;6GbgQ^Z̾Bt+hĊ|E d &=㈂>N%)zbNy4o3BfvqrJO;mG Q[`״\ˑޯ/ }TRǬqzLaaGtjd"kb~qq膑 1%C/u!)̅cQeŕn30:t`ǫ䑒oTfhZXL)*F*,Gmw՗ѯ]x\d߻QQVV zE2OQ 9wK~|=Cc벐y-_Ä&1nQLq<}Vq`UXZ Q@WJa7`7ʰj0hW#DhnWN? r:<*8%<\hiqE*結*DeC76.EZQ玍g|ǿ(oa {R; ,>e: 5m=I %;0VY jvks,8K 9|7!o؁|Nhx׬ us=Lc~ɼCln"I TִO(q Sv_m 5S8gZ*BXk&ęSI)@P >4ȏ`%DOJ]6ՕY+ː'2q06F[tS`N2nΤu{N*i*>FLk3H[Ҿ(Z<;Wkf̗},t̖hg&%~(iX&y*Vo1\;OhsQi'yn N@yP$c-_v`Q8e 9iw~31ozH? 2 g''S3/~$8똷*M!^}p<! O]N!Ҋ&j,k=s!x#k,h_\G0-؉F{P9s=ZuQϚ7Eb]M[f^>u0ښZ{I03V\D| !ܑ%P Ow}-%M~yۂl#lgOo=AϔYڃjQ@q>ְ_rv'*[Tl4$"BW_힪b Ʊ0FG(\jmL3*1AOUmgpHom0譖JD\C1f,u=Օ2O<}S05L r|"TeA;.݂9G%s%ħ')ֺˑN,Ms;[h76r10 /?O"أB89b9`aIVa0Z :E 5ϳHܾxw : U7(UdqxW]S@g缑-IK!٠e0WP4(H-nA.>rOtHra9|7$XK65 ЄmPꌅ$?"Aì Q \hvio?ޞY51ݸ(Qk ko#zK ߥi0cӱӚ$ #Y7$øS#?V.C_v`(͗*݄jC }|5Y W[2-l Kj]zc ;X֕ю!9%'box=f#Ũj-m-u]C ٟ%BM뢊L30hjyFnlHlbA#Ki=T:ʡ{<:==퀁Nf^1%u%qyjKKKQBz:`ҜaA#;"SY?cRuΫk{˄Ճm?MCU xwL,ϸ z5P`)~wfA` Bz!@J2yJz h9/GwxŲ|9kv9GEnj86R/dEu䘞MV'v;?*7!~A]9 3 i_ 6@)!V'Gt"$ޥ>Orj[:ol?ڱ5=Y&};rz&#T1)|Oc?`u--t|Xޗy=rMW,)gI(ѳjvI4s. 8`x1n5J)>"mq ,|d_@SD^@6"V磃߹/cHdU?dʼnj~{X.DI"6H: +Ss\<[L{$?iUgX! םB6aUY'^2#$QȒ/Q }شlYeA6l6z<_D<4j c^$ŏZ)^] iru^>dXcaT yrE#̔a!ҁWu9%#wrdjaTPRla7=@͚g)l Mg%"_ j'ZНXh(ߡzaMi[u7=Q ;,ëMWY7bPoS?=Xb0waIfBuWRXv=Ct 8SZښSw@$}D]w*:-Y{+aS40j~ԑ;jEZ-g+ @ߩW+۳pU܉z3.ڌ o቗T5;C\w͚̖M: Y#,6MiiRf;Ϲ PNN8X+8O{ >֡(ukjK[+D$j\ Sɸ֐ kEaփPI[:̀$ӣץ Rh,a΍6뭟g9bRbt}2.)wsx0"P`T{\իm 2-kY;C5/y]Z灼Nkkɫ6#CY'INɏʫngH^`C&ԩhaɲI}o"pٌRˁ L$J$:8Ej9!d*P}7q?yiUluL RvGc3f=6jopU6Q,E)tE?ʷV3(fç($hNI_hZdQ2#-t??#kIOfSVtПvīڿ|M&?}QvvEʍC|֑[rD&:(2ɼQ!\B++`f]|6+6 ]'{yyO1H+wdN&cfnx?BjJgz IX P.~U=C=:ġo {үH:?# P9p[wVb*Vt.MHOtӏ;-RGbtyKC PR3L;[*#X\J,W<$X+h Lh[JZt%7p*Ѯn=@ \D,ޤFD3v& l6B V)HOguŧ 0smn+ 8z}38 U_D6LU>rjTnZuu{V#QʟZiT(ƕ[:Li(_C9u4U7<<:uy%pt)x\d1Z۩"ۣОzKK4fѼ2 LFjct!~ c<8Z1喳wVH}eVaĻBڽb6,WPgzG(Q9%#T# ̆`;".J-HuC7 /x,Ք/gQ}Tu%F͠'|5]5-䷱MǼS_K< CbD{Hd@YDTSeӄd60B&P0/15irLc:nu;1}g~vqWN`o. Zy]{v]Ff u?pΉ56xl]Er$,cgRp}ijs1f%eD!̇PY74gb 5~~E!r*Lz3ܥr_ƈW >zD񹑍jTF (Qv %ɄL=o\#[iVJl@aO(w h`ܑnۃAPgP`;F8z_өV;3-Wi-sn]Hv>|fS_0!8oR R4 +l55գ&gnqRW0VФ1x]=Ǖ9/1%S?W`GΒ`L4hA Ble Jm'ꪲ"%_v}.t+w=Uy1{i*N]f\M"K1!kJ¼ C}B:S֛)S܇~RPouB2T&]EV`/w"N6g-':_JkIyF8sq0k wȎM*j e05y^gp6D$ft"n*`&0=okOۦSaMm-$6&д1'Si$~(s}d\zD$T$Ĕ^*pԛ(VG,aED3除~30B>kkɴc:nt1.1GWaD2#sc1PxJ*0`C8җqH3!d1T]\5ϰmf짭v@0DS џWuȓ;EYn2ޡC8!d9ѥ4V7d ǹ i+3u'hgd"WLv"x  ]p29<uďVHOJn1_R}z{硤+U8}&,+#Plj͉ԴCnxqZU=f`b8YLT9 slZ㤽 6XOss SE hOp{]uFO9HD"!,I1g>5{'١@S%##UfY$74iz O2Mڥ :Ӕ`X쇸3# Vm?.B#0H%yFhVz-ECF0uC%OdIe|gI(" yq@ЇeLpܪ#[02Qc>RZ͜%FŘg7yדuʄqa^E5@7KXP瀲NxĞ6bPY Y91tt^L9kvV[6-6vO[Ϭ$mqWH00OnĊ􀒞dq!q"Rc3 $/O.7oBR<,kMy57D"Wa=U!Y$t5hbIy{2;{W^xGrTj_a }WXn9qhǟCkT,MEfdn[),5VRp_z0]䉽X( WHJtAN+@pT]3`,]h0*=$^OS!y/,GHC஫#P|uoMUj%YEOL,ɓKF>b}JIxfPȁs'P,THTumau"'fXqbd%;JPPc#%(H"xH/?+fzB%A * ls]ka+R#{;XxACPe;poW%3w,5Nϴ+u}A롕Yu{@y#9qS0 fOGYY{Jn臔'*R ,np1 )*C Pw0qUJȋCs?y U}mTK bWu0'3:Nm04u>Ast qє-R83Φ4wC~@b5ԫk᭼i!)c1DAI3?OC2~{\X!ѷuum{ <WK+6d10ȷ|ml(U2iDr?zGH{nMz d!lYCQ&_A]iWD-H{xKU ~{D* J* o԰ԐZ%Lljgܮ58T5)CJ]ʚ2MzD^u_[{p0{e`zX@矃Y'k%+S*Xyr k7:q):sR±"Js\_RP F Y4Lkܲ* ( 2G'=j>p(~{ p [^3?\ǹ]h@Nm3Hr6 •8m'|1{Cf)Ӛan3I)QҔAg㤧_C҆=dsx֙,-}rЪN NLSrZ^r_MS`,RU\bʜg9v(wڴu+vtbMi omAy7ib_ w ti1z+\l:2v/;Uer ?!`鑒d127rE)nZ3I29d9DׂVx"įos{^ZX dee>\oKم{%Z>ƶ}<4C߀q7 Ԗ2y;;kES'/a)_ݓv_L) ܊[^,>m/O¾ܜupVl43E_NȡTY߾ߍG<Q$ :ۻhj$ B H4`A9^6'Đ<d7#Yr]_bcݶGo nZOX}!<-#kcK}{ԹDRDHSA*WLlt^?ԡ[aI3Y[FPL5nuAཌZn*"Pe/0?`iʷjy*-N1E:J0\ɺ~3/0Yu67+b[ƃ9:T@\*Ap?=S#g¦UőHPd/vϭc4Y?FXz֡¶k|C1D<w "I'|+&~U? ~Ϊ!qȀWrY #_[^FЦeM<߄q ^ CJW1]|BoCMg1HAmL"HΤ3Q7@xB$ і\جc)y<͟R_&lgo^,eBF{<5[w3n (k(vZã1zˇۄzڊ<<ɦI O-r ]Bkf 3!zon&5Ʀi牆Ifp&hCA*y Ģj3+KiO@n#Ohhq)]%@\ E?U.i߄<ٚ`^d#Ody hW˞ز Z}b&3)Rz>dHՒxIQG_6Q5-\Fb(^U%Y?!/mA5#9#D+ tY6cg{%TJ [Lp$2=X{)3b|[7(ڥNI%k +ci/%n%%yÆ馴 yn1sIB(K͚4h%uޫ.AKmJR|TLUhW6R^@ >Kj#Sx99aS!gaY^ufl`/&A:ĉ1d(U*4fs)FE>߉}=ʥ0\lR %zby9hu̵NsL%U 8xMW >NpiV_E%oMؑXRKꣵu\WlKG6jK?GG[ڎ"ShP)'})O!=ХDsFLQh2[iiܯ|79L6uw_|!ViFuD^ՠev!ο?H`&o͓t6@|hk?U}ڀHJ'[f)3Q/ʚv@CA`I3*:N 4lY ]~Emb+읨-JP"㡔t9kgC)-og*>H#WZA"1i}JOӭq1K>_z[^+O] 𼕆J#1- 0[J ġƕ7efnY$\?.}lV;ohaZ\W'"ᠳVAT$(m}<5C S, 8m >/A%³xR'݊T?9[FJ1ԺGYK ;%cptd*t{ l!ժA}P۟k 9KY;Z\ .sy^Nt_ot@!!uW2 . $>Ͽ(e9~Ldc+\fǷSep9A~~ GpZ+qM[1,W+ ,` kf ] s|c bBPu~Ws1{kpG .yׂfbEY;ZQjVCXVu[#_@;w];)SQZSw_>Iө ڲ0LgB*7ٖ,:F=N>grﭾOנHݺns=mJ/U P!n0{FAhE-z.1<ĬUg74c.Gq:HqP'>-P'@ ˏ3ݧxuHJ'\FW1 ?JF ل -Stɋ`ҁ၉XƦeh )-Gƴfqw|s)˿s[bFS]*$*n mŁ꒗kTq2C3/c4M(c?*dM JX-6QQ|E\:^TʢN^q kl &PIp?ko'zhi[SPj&krE2j._M_+f,< z%؁ϩ0EZpS'쾜BճDU\%̘рOS[}$\UA^d #Iy$:ÉhFkABXbWKȻƄFx,B'>c۲n'\&ic|l%ಔ.zJA)H+Ѕ]_iZhF})1D@?2T &%==(k\8.,MUŽ.؆@>zF&+?BYL)fK@En3L0"UQo bJ[:a4T~! 4#g{ekvV(.7L߄YFɔzbc>W+ma]#β.J7zj`창\L18Gx/OR!,Hj)S&㱽b]1DsD/N`V̤sa%sXc̦0YKpH?l'_}LI:)?? nYѯY^{ O9Q^"%g{@PI~ygktCޞUV&Q|d@e=3SaS>!4Q@S 2Uc}fEE?9`g[İx|5;mďXuldݴC8LSy%bF,ΓO[NLM I{pKĎߖ"wW}cI y*BbA\ѵ6̥FuLh9S$zN{MduBZbv ϟg'E|&u_C4ŮLzU6YX4zBI\߸\*ɹoY[6 8i(F)(c$Q->q3:T>gsnnEIςfQ#6NkJeH9/Zl_~b#u #t X/3AyWp #\հ'=KR+וEF)DGjj~NDGT_m,f^c+$ͅIb]3ts@*Kpv2ݽ:nG3CA̶/1Dfsv_3G9Pb홆MBf!DPE#dzhwb}E UܦKS2ezs?xBHGږ߳\-򶴡6NFs$`$ӛlO4Ń+~^3;:bö)J۹7yIwXhL=%U_t'UI*-r,}qőe!X9A'j|A]N=sWbQ|:%-a+8?8LZƤ<*}9e/be #G{R 2EK+XB{oVIMz3@5|\bƷC {`fǂť$^?;v ozo5co*$,zW5ȚvVNU Q-~9,~體`b1p!KA5"`$MAQ+Xv&lk3&+>[8Qq%~?S7< oys%$wɬH{j@աHG^nmg}U:H*ybdO澍BX*Ȼ菢|'d6!nlB18fBwq*j[X/&m"ת)Ry*nbҀ>_.I9PV耴Z6&e>炙nCe8e+i+ V봔hUߞGa3oJo^>/im}NđlfOVtQ8zkǝQ$4no!iUiSх+EeJH#bD%uA9WD&FI!n.`)+^6B瑑sDW\ 4q?`+gĢC!TE7Q :`1^?۔lWN)&#Rt[2Y!.F?sAItjq:.O KȊdTqyd}BB +j-6dqOQ7 b(qJ[شP\Aev}id8eYl憂)5pZl,!pDq riD'ŝ~zÓ.*Re5:xȋ,K]}vb:VE78HQZm/=CI )4t>m5 [YK|V JQMQ euu,V5&S%6+W'D=9_ T73AC1gLR,jAĆ#;8kvP{Yn4Yҙ{2ig592O ;Yk )*kI],]ͯ7: @W ܺ'__ΰ\ 5''(Ԭ;R]lmz\Hi`scSQW X. ߩ.B4ύP5*5q2-,<c4RP}(G-P"ona̟$|&a# =oz,ota>-@M'R}%8VĮDŽoK#S)ſM͕i BAT+U3% { kR_ͻDHz[إO*<0Ḇ Y$?+YZV"`X̴͔ W7ġMPJCRHvs|a%A6lh)`W3R#!R^~ 2뱊Q:ѓm?WJ,3'.hntD WeJhĖt=8]<qciZ>+2vN*MuKt0tZx.1&:5,/?Io«SU*[93u;SMSM?djgi9մė$3 F&$6;/ߌFM+cu-9 R<_N"zu9^Z nx3805|6/D".!oQ׊Tr0Sԋ? @ +g|)j@&a8EE珀_I2b\^iv%8($_ T%K$R`CW?_`h^2,+u߯_%k'@M lB39 -R4Bl~bJitUǟ$]D 1' Ɨn<UY1v5S&sMW)n0uV9wھjDEk^UӼζ9LW8nՊ=1?Q4wⲡY xZoPZ/_OvpnUo8* #`.8cWw<3Փ?h~ ͝x.9˧PTts69y|fkq+|Pzo^`zT;/1AVp:L=K u BZ@+ QTx i;څwm{B~M,nUG1K{qa5 DWu4sP8nYi=;W/="҂vƜZ2MlxM%'%cln q}.+ ϑt Rx%CnB^G*R35kZh10be1.\hH5,k/G. =w|L mݢ' Zv]JAf1~UyE)ߖa-o/k%0yC\\Yr6Ѫ`)w͚!iW׹w1bu>yUtjs1F.b4c=n>j,9r -mKvQTPѵ`5ԵZ +ǡLfL2+|cs޲>gSZfP@CBXğ!y&B㊬rO@D54IgE#ex$L:ǔǷ.j%LVL-҄',xYa\ F*9;Ƶc#Q (|!Sr3huQl Y5$eUBx!jXE-+Ekg֓ƽ!?Ya~F$3`_ \{rn%FYϹ-vO3+e nJ}n`[֙0ӳw#ŏ= =xpjŜ~ЀM7k)mTQ3͉VS~'Q1ի'_D]n56s =D!ٳw +ȧeќ3/h(<1Y_+;V``Jo3N \`` )hF=|Z 14*|q1<}DO"V^P%76Cse0Ƶ5ؙ]}9 +ײtJ غ@$0ٟDm~4qRMGԁ|:VJ8!lyth@ib D o&G4%46Aa* lO0M՘sl;U?,' yY`t$l@Ckٜ d9vd&j\2"4?,B=U@ zSU|ƇlHiBBlBpemtPb-LS1=LhWp*@i AM y!H>}f5l]_\i396&d6Z"SeʐAd:tg8 *U ַWth< GB55(DCNE>%jzf9Y!E4K%>> %%p3YkE%!Qa`ڋF GΙf V#KݨG;oKY;*wS-꯯1T(Ɩt {M뵑HuH}ĢM9.D>l-bxs; ZJMhV߫tHovrb>56?+{2sq{lV 0j6!kv=@fFpӫׂŝW9'x=,03k5]X]MBHA-h7Z [K n`0@:r<>ϓ#PP ^j߼ AosAfp{KMǪ5VdIKopf )kδ۸fNh|AZaGKCʖ#srcX$5$;M5e} rnᯮ$}a uÑT䐖e9(q⧞6@ M3;W\uДi$7D&s=jWQ^.pV6s'oin8ioW0_O;=GmοkAi~jT$_.%^4YZ8F5Ł7}h&|0}OF܎\+;CDa=u.Iq\(.#ˀՊ?ҟ64ӖjtУ(k XxnW~l^MUW:ٚ14{ON_!M9r.8T~ʧD"de7`AwT*P7 HQ.1M40]V9b[ĿZKIWKS7rBt-  ácjwE=)K( zp.j\;V( -Ei<~ϗ y%IkW.V rSyAЀuAY K2xxG $ 7-վHY2 YeU(]vg}d*G_d.^G{nbZw{bi :?p<؆X{6}|-f1ByxH3"?|y&S;s;Rn D5^&Sq65븀cSE>;o*>CՇ+J6/Hg*]9)O,\t0s]-GMh>wk'4\|UJï3[٩CB \e2-ජfQo!a$ WTt{7j̺ڮ?s& "%?B?0oy'(ֵ[4rp Y>;uK!~gli^YiR:g*3zBDۑ{޾C:>NY ^Њw99̲>M wr+sx}zӋ(!ʐ^6"u LKR ]*vcUyX Lݔ[z޶Ի\1 m&EU'CS8#k1D>OtVsv(TkX(px2yo쵊R}%\BbC@|\DLNF Zlwi?U ˦YtLJ1 },nd{Ͳ q[כo;!&𓌝tmXbα̖E ZR6>6)T{VЍ- p,iA;čp9֘/|QEzp 1h7=ݍ~, 2d t$g{Uxyz{?f5h2NWTh2WT\{'4c$rfGJ&-Cv~|X^ju !\dA*m!S&s.ʧ[IL{̪IXҰj`x"S|-B"!SOq亃;ɮKSQre>GK}F^y"ן`0WaYg%(TQk]r߁^̢oy Ͽ֪h[()~vmdɳLlpQ{R9jH<,(MT>DYNNUiOy ԩ3)y~HAMzl= Ƥ\'fs6!6yكdd(FiLc 4`gxeR Q8VN2Fa4CMIfK@cydnSU躚.e }\/{Dp\v8VmǕP,:/Df]eW=DK1_Ei(d2[QɫӲXj1_mkd :P4B;YYERGjK9$]u{]6^Q>kf5`H.]PRcoOj@06(k(3g3aHuga'=KB1{.NP`F6U`MT"M}Jf =۷D¢09j%x7T5O"l԰[z?!뾛pst7w/0Au_>V .JN!Mɐs6\dâRpxL]UKo#)j26LVk A,N6#wliCAW:&=隼YsfNJTnձlG0n:i*: y<֌/,k7])4Y"`*cR,FXAʕ2]&بTG_Mj5r퓚\x|܅!DAס|1ͬd0GJcSԌGu8C>#ذli~0HL [}i xC*'0t8W@tY@qK[MP6mKYT9ޥZf&[ᩓ_>q MħcYX^)FtX*!⨧ , D@cO!,&Yec#s\t[uFKz1Q5Ε3ˢjts,;D3ZVrxhNkguZ"G; )7т[)Ok>.nUTW3&<2aa?t^2 48%jQ?&aJ Eb *E=U3ȚTV^03-b&Նĵg#v>&YM kD 4]v5$hDHl.I&Ss)NPXd($ha 1w_^I8jwyێzK( ,ț`9Ps𺲙ggO ]~]ț]*y0xGNciT#`/@tp.Q,'nnL5`*ܨ˹F{N;d,-VS'4mU5XZ1@{\>x|aW~5IlxoYMbh¬ fiZDYׄ/97qMX}"%v ]p=tz}@?Iϡg^> N ?CDXyXAz鴮[F?P:IaC5$f`9dmfh9n}t b Lo ?Px}Cζ6[f؋''k7?`4 Z,iYAr),q`ެ#c: eզc@1#h^mDLgKS5$04!ZѲ1XQLtCwv ˟bљ)yOA܌J,cm/NE10{Wć*RI[]r*;ǪJ=;/%5\q= }xmpzk (b,#nԾQ?9QeSRZJ}?UpY4.]-̈́hp^69i9X|dQ8knW~Sl^> 磨JK;ZxćbGꬢ*EW%.7syKD&'#W49 drP+ }tR2w(CB0K/OR()4Lƈ~dc1a s>\b%^ZJͭ桬 {+rq1D_Yj),%*xXP-BV (zoU"_1xr̸{swO~"J4xcl>$@g1dεli1_f-;!TpiϗeݴApp4,Ȅb/u{3A϶(hʅM>\8RTI$q]$͝STp >8B !t~COz$$,Fa1ߔAݸ2'IxAyT[|5+zP IG[#wi}IU'?FXy +%=^ ^}'ڨpR: gwBtD+] y\;}w( 8{58-a1^&Szv>w&Ss!+Ud2/A6`W(3e~-4i3nzBny)Auq榒;h ! Q mU1*y, *ԸK 8!c%-HXJՈ T­BيXm"-sM5ru(32*Y+Y#O Ici>By^@'刀ν5y?ymSj&9Id)&`x/pe2ťY-rq~/XQo'>-6K𾖸PywUX@p=*D;xL>)J ·/??Ƿ$xN$0fޙ$Lt>>hO:ՈT0|.EAJr?6TX+XLrD%ٳ!1Ps`;#{{'i8[#_ONJ-oq^]<{K? ̠>ӵC猥ܒhZJؤy(/F^oI J|2hW).։T{V9RnfeX7Ј npKek]{l_Z&h֯Ŏ,MM1 tOfp3){_Jw0(4W]yE"(Oo\I;M^ݿ/R "eoVi{Frdĵ(\&{N%~dRA̡zެ Wej&&l]hEQcz/Bmײp%Z9`YfXr-翼 N1 x2׸:uI(F*uu-11CU`b>g}'JP QXujc.70H a&Q+A|8Ҡi+OVYZS0eψؘj)U*kbat7 PfBwk^GHUɎ (8ʪok QF)UR"_ {´m&aNmCbSLAeAID0-*چ{NSmxZ~e6cRZF)ك|I gp7ij񿁊ʮi 3Lwy"4|90Uw R{AH~Ze㔥<_YJY?&aR*IN@2.E6΂i{`fg"tAWC3,quz1`Md`@U^LĚdWk)R\Lx` (?Z[b7Yvqǡfͥ@F%,_ =TN@8b?꫖a G,~ím˝UǤ-CQSV/B;-k]m%2~j<1~cpAN,Dr-ab起ƝLHC.h$3Me3zRݖgV] N# |x{t~Y-( .TݩL(GE+BJU5 z뇉 P8ECWcw4 aaĉ8ډ RΆh!oy.ՐjЛjaED״(}%Ph+x}:׺%Odgb I9װDe׼][; n` bCVim;eKê+h3C RzVEr#v#(Q<2y5h> U7;d>xXy2i~Έ@5ݱL~zO)װ<6}OF|zU QEgW?Dae @|4KA4VzsKT]h wJ4uT{w޵.!XS"D{7C&+,*\ E+L4qr>I{ 4W|[/EC [āv]ʐѷXglSoxO)ZVԱCо^1,&H(frz0fk~@?˔ @/`f\CQ Fʤ*~A@6d <K1SB ْz]ʼR!eӡ}+Ӣ 5Vl^N҉$| %\{eίHU96wAQ x4Q}zn.?u&4g:"D{tBhDaZy%ˏLroB1)ݎ ݱX a"L2C:LzimgW3FݙPsR K Xa[ZAHI6`˘G(xx3\BDl|Bz׷B;gV͓9OeNLI%$)%S侵S@ 9hRGJ5W-0 *偩0$}ĭ^f{Gv~?ay~ysTe"CsȨɗ_ .ש4$|| ^=նb4;Oi ~``MpIPBH.R}j"j@{z \!QM:2сl=ه)x%齠|7GPD,}9-ժZcId5>XcU}TP(ɿċT 睪Az,$57<5(fhk 2z7<77o% KXLDz?B|ӡ@p)NPʁtY0ssOjQlu d kϧ^g!;*[ ]IpE DJ_/"u\hVo_L`9EbZӼV*I4L@TT Saiz` n}_RfPi |fqAʬUGmg$raz}Ѯ#>U7I,ZT/xGK(p98|RǦ/Yʗ㍶; 3qxosMs*TDxO9uŞ*{ V07BK_zƠV{\& ܹl.adU*5-fK;;^SܭAJ^on2i4El\.O6."u* ƪ@/Ns?HBC`EM6c8[>b d*͟yK]Z6:0(G^fy-bq(Zw$;W 5G<GWEle b3UĂ,K@n%UIQv0ARxy}s3U'')@5Gݹ}&cL[F 3$MgBp-P5AC+!wt@+ˎh1(-Bxю/, GH¬/;x+'QA!`|3IN%Lbny =]>Z$vw@wfEhqY.jȣT/9.49Dz! r 4jF Ef^뙻aQr OHtNP Nģ 7JUXT>)|sgW;iEխӅz3)]>Um:4%*_("~H 9U0V|v{=DBF2t kt/e QК2V m9s)4MѪ")́fh 'K^jT0}&Fn.wW3)?۝ ڛҮn"4j8Ӆxmڲw๛Yxle*/Y6[eP؛2db%Ϝo(D>Cw?iWw*)Zθ"u o0]s-5PFf NP< >qO\Utު$]/)!zrڕEL'w,/{[M^-A$Q 50'F߹U|=IW<|@\Z81NwM\qAKǐQ:ocOg )'믳 7u*pͶʑ:RxzDǢx@D74\bpbm ;[>fC0*<#MrbؘV:>6>weؐըqIŜ&.cY,%:NO2ͧIθv,Y~}vIOP$uꎨ4DwʼnXvGq LBo -_! wLBY dܕd<]N -C\֌&}tj/qɺN-#̓ѩ(Hg G=BeoL-㝇`j>0@iF͉N  K1ur'hD/̈z*DƂ++SwS<9hI*SE%ohp$sA1ǿT ~ܦ׶9!X<{!&at6YmΞ^*K$J ՐrQ[B_5%d}#&$nx$Tʫ+B hc/2{὚KǸWC9Ō/s+_n r"ڏ hd{VF+,qʼn$(R0D#; U t[v|Y%ɑ#O3:4=Ђ~ no˝UV 3L![s?3^[?D 1gKTcߵI x]BAKJgm|IasY]#8gXNzf+quCH}CIW9c>މD9dQn$?KxNXSLQN{kϖkzXKL*T aۨU,CG@H9tR6#m\ZLgtϓë'|gw8΍1zOBQȬ^_8\,+2߁6yG{G7!S"67,k0CB'Ľҟ Pvy!Vf VqDb̊pa|5QNL jJ!:>zǧ]ˀBDT+ rYVyP^ar3M;@4ǂ۔lC6`u!XؓHS&eo}xh@ۍ1$iSJƀsStłyT> HO1%P]k!c6^oLN^"1q5)N ]`\ٱV/%rӞ먭FlM\&lz>ydE I/KNoh#\JSbC_S- 7 *\:HDw ,]~pv卧ho $Օ_{BKYi6^ /*w-!$pPm)*MH ɀ4Չ. N.{A. *ݸ~nhV[b+;xV44%BҺW Jzde+4T{ت 7דkPQ1?Z9&bʜ ZQJC7؝o3l%`Sh+ax}&TV˼-*g팂 dZZlϩvLG(|hQe ,Eꖹ5'&q_٪P<ʧObhPW)||Q 㭒 YLvERI(|3OjqU$񘠘é9/ZىROm/R~,`? \ewT^l69 0%%QoHs@_ tV=!Zk(sVX@Urkֽ.b%dTSװCX(Ţ?``oܵ>DB%h=炾:90ZeNC;Tu&0Q$?M-&C1EC)U }CyB[ 19ڂqIVWR+W79Bڀb]Sˇ $O3ވGO0J b֑+>:(g|hUP,qS?&B6n(ZhNFEq^cPՑXcʁȌGGp zS4k~Q2"PE82jM;aO Ѭ:s zg}-bc.Q5=xV e4#E6#_p7ҷAm?xcxy8!NI۵~t}nz(/M<Y :ѕH'pX] mgp{>xBYNo3Д@;M'(< <~^|۴A0ǯl|+KmHW>ҶW{ 6T?`lz15-x@慤`c]ӂ4-D~B8zPB&F \ @ X%Tx6_WC! AKkKK}6> _jr40imb?(6wxckLe LxLBQhF_TV|":&cG). g}?)ΈQ;8#ZʤDc#pa{oWy ɲjc#J@M} BR$DhGyq,t-[+ pegY{gSxauF9bS-n`̰mmQ`>$hud0i z#WHd<0)Whm TQ\#.d:,7yZrȰMEL$"3M\$?DH(ϝj]c=J/"3%m}CS.R+ʟbڔ-l.^D),pjg 7XG$sWFan{(GGM2#Hvo)]n᯼zvhb=}BTA9Q(T%kTSsxpXm͛?x7yĦ^j]*>"Ir-flJʄG t&juHɧ4 %ϿWj0aKRE% (Y|Sڦk>ܭn,^XmbcZ!v8oIrhxUtZQW=NTkЗ2ҙ,?Ȩ;37*P+B{<Ů>cMC?[V& an:l5+K2$g pxi IJtob5C4s(} r^%"-o" X_f 2c'="'KG'Vs} F,4{\+Pw +-yTw%@"IWPWdrY){W>mqf2n %_@GĪ3<1;D8wUϐS1oO:Nw'Ou.\NםFZ?|4~{|#3-qؿakrL'}߾</֋BaV;"wX:*] $UkڥwC\'S c€g?l4@5E8^%Gخ>8o؅C4_;9V)uRU2XόB wS Fn,8V7J:ւ=Wƪ_xp1;=d.zMm^fx $$ 6ƛ ;r uAP i_Qa(o/!!m)`qY5UwA{$;PWrU1ft##5r @<^']wEĖhVzz[;DT\ %KyBrzI_h!p({|.IGDՙsLjZ{t#nugM&/?g=oP]t َ扶= 57h"QrJّev_݌&4J ]̼[(br1? Pt(Lpd62,*LZJМf4t?l#9sWS$"Cp`YQ$# coz$ko]B~n+3f3Ju^EsWs& q9_**1mY>Wn! :mpCYZcXI&_5Iwi.$Mv7Ub Pؔ@ cD'SKvZo2E[V]B y4m9YL΀µ&ٟb{ȌtzA&ѵ89/:/ ^2]#̠CUg\ՏB!兰G+YdOk6HWk-Q[o=:}ur$'g@dibw4EvPg fOq4 (ia8(C@oybμ5~Ef5tjHg~]gy95PzgMdጁѺѸQp)$f wpiD 5X+֧c?ԩsL}^fdŃ@:qBTf$y?c 1v9aK3OD]zƲ2yi H-f<]}SoPE/ּqwDf3;^;$o~Ɋ+"0.@TbDQ'wbVNQ3%9/ m3U CF6 oqr>Bӽb rcF.Sak2Ö k5?R<.eB]JN`3xMEO%<> IZAo'ԯ0B%f< ~xj0|̭l|1[O>N/j+Z@Ek Y=I(NBaصsBDNc@8DZUTgn!C^2V<Aj1 kEc,Jd62EUjɷhdxRJ-\s#/`hOB=83#"yd7گwmL%(ъ¾< hPH&*J?7"u)ʺz*&6K ѐ@0 Aifh~QTdR5XU(}k- /.3:$3vLZ˦Mu֏Y>j\Ţ 8vg0l["FCKc;u~S2FGڝ% ^ ^ ɼ #y?k=Pǫ?p~X F滪a %dheQ5I6}Il6wDp/= AAϵ"fL˓qyЀfC)E# ںQ^QNkϾ`8N<(Ԉ+jiЩQT%3#.lwH-( hģ9f2cK<ܻٙDLYQ;2Vr{M)95i+;L;w;եQ-?FlcU/9 jL>^|`/n&@@+=)o>4U\9@*2ĶX '+YrdXf$AMe>* h/*>r9Q8*MVMeS1Oݞ (,ٱ4h;Wp7[{TDU)?ZD1\pJ0旰0<0Oe6-xޮyR%uL[Y|{6DlRъzMŕ>^d*dNW.LgCͻB:w?tϕnlg8Hc8RqcmEQ1-~)#Zr'soCgeC64ڻ* g|\ž椤L&P 1xBMWNKR! + :dìW`ëA~~WՆ\ ZSiyj%p#cp@\x+cHR%DSTlC|߳U'~Ц 6hN,Dn r%&Yn{O+pnnʢFDC?x6'F)Ƞf_2혀Y&zUnrxh4כ9v7)}aZsJiu7cU.TN[)#0P [N>`A;-A = 5#3o?oo SmIyTM]^[<&6|HLہ^Wx4/gQy4. g\I)Gˬ?r 9>x.S-G~Q'pm.m.:WCGu %Ix"^ Ψ/bXR|`8 _oF2)KyԄ^E`2|(_߰yy!SRxr86%m(PRzc޿_i_l#g\!߼Y+0F +Y6AW,%SE*CߙlBƋ(/"r?Z9mA[R$&Y~7Kjl}?76%B) <M'_&)&d-BIs]evroWԭjf΂v7苝X{ `7>>4[^Ćc9:"0VA)pGO0s&\g^ü'qa p-V))G9ѳ:)c]O2PK=3-T*' 1.hTNXۿs!뽳0a@,:Xp*)7&L _kDK `/CJJ.<^HXr6T_G2IK-d `rh[7]\v1L*x2J2{ŷP(X Kݸr]tRs26UPJs) )"#KךfIhőaN R\RҋL &}{L `T)JN= ruyITEĂOvvjޯϙ&g~ѣL{~9Y$HƤ:R]cDPvYC8z:?~X@\#|c>5Z\nꆗSA" 2 -Aa xX21~|[y[z)9K0[EJtEs`ܻ2]E`yBl_xbmb-cgp)91H P5aiKLBuۛd8m  j6="y2vΜ/9IߛK|3 )IEr[ wsɿ&؇sz*3,2mszs:UEK+,%:,l R<8+.FZ(RK01',oߟ͒0]Kh]A<_4Ȓ (,X\#A :ѸfpZ ޾נlpl4Hvy %[C1EVĀzxȅ}_H:bW !e , xNTUevqU}\hy(Ntzn֘ڿ?\M'!j2XJJtA.X ~&x9HM_7!HsYk"[iYt*M &'QOp,xa3_؉ƵBMomngT iMH+Sڇ`<0 s\qN_&ip~@u~YG8Z_ɏmzPy໡׽'! JZv aV <-qDۮF Vp eNGtՍ*,=%aXQhBTx}ZU/￰chM9Uvtan<O IW'4swPGraE!v|hEZo˓v?b3ԬbTk|$%4.ֶ[<1eHscD%OsONtܷ~ه\]jB/@޳duJɈ7HJBkgB|]x:Gj ~uj+TOH<_E&Yty%WP\8+ )CɆqvgt^ IX)qBsQ(_^4dKE\2n ( ێ56hi1ATP_)RjcE"< Ήi~~zU`]k qjzK1Ԥr/Gے2\}d aC1)0/w),X&9ɯ2)wUWT3}2\JĞ$} iغi$kv"TDC( %&)j!%mq-`n}3g=DM"";ia_{~X+U Bf4-b>T?^I洟nXNVF{GL%3)փ$ӑz3 V$JCs©,Ec#nEt}}3U9 C^Ye}+nKcX _>WS!T!( ~Z@G6!٣+hPi F0tgMu11O8CCts}QkA_eGrj{%Ty"V&5-ٺC`t  O9qxƭ=1S9.U~RщCO|P7r_Z%l.$9IπI)Q% Oj+g )"NK8&\뢴D;vj\rY AɏyUw׷4|A;Z<%.؊u%bOKn&%uhO ÿ5n8`e%mI5 Jed .A]S˨G>m {..vg)GBt߫~40-opdx'xʏ>EDLsrҩE.VB%J#(HcO4s;^˹ě @ o"=kb5R&7S@/PRwӯo Eӹ. NdzX)N9ؤQڗaSNkwaaFOӻTbysx39\{l7(+jJ9[H*p VNAG t뷈vUobsweaRoӱbu{W(MSad5 \2TtqGIZXPN~AMھtE6p9@:ݬY,a_}ILZy U# IvXƩ15 Y؊:Ke܎^s l}"%^9RU~o YKG:GX=)YɅޣ p{B:gYi|4IBAR˯([XzZ.6LL(kkm3ۢzUV"r7:rp0) Fa9js~ZΤ|$wUHmNy`s1 s2hH}ZEheDoH F8BւYC21sd? pBגLEqÊr4Wm{&Q0 ުD 2隚n'ư$18 LPdOp+"VӟS APTV{W(o/U)_D@_i;9RPpZqԇ>w ?"GH%?No%fmWOr y)ݦ}Kd"oEE\L+6.f7IxiT"3h"#)sxl:MוYE1z}Ƚbg0vUp^M >oRSĞI%Xxsp;}9dFbq-fpǙt<ɐF:U9Mq^uD2OTizD8gsTr˿$Da!~BAؤhCt|9%1)v,f~Ceo9[ GRt2|hytgq腪}!4U כ3 =daMY})HUe?{e|kr.eF:!-3Z.6őmH_1]rcWHxvE1lݟ"ZRE5O'VE܈NP|#E*0O[4Oqō*:-XV)SVuU]2 Ïsx/C&t1f)>ijd nׅgIY`$NHL>gV gǴi%{pS+YCr#ï[mOq*=-(ă ?l1e[}r.@ynlcjP)a@:Er3OI5??=>9rA/RvO%arC4l ?/tNdM-S擓}ّҝQYqӠLSEK,#kbu^WrL F,&1c+Z,]_ķ݄ݷ$~fִ49lk`6360O﫸%|'X O7cMĽ%HkC75s{; cDk{na7im~3S}%5Z2."A0inڦGnh }at OJ`;<}Дw_>4BJY^6 }֧tש; XFE|Q{'iT%KFц:*۬GVZ&D\k9:6G̤t41^ω1iqTf'QN_;i 9+t<;0䌞YU$C`iݙ4xPHbh5&4wԁ"0HVF,;! m}S}'cmҰ-߬u@DBhy'4c[1I6X=(|7;n/Oa-X@czր yߙSU8[aE_J F5L/*- ҊKRmW$HeOxB\T75p~~TP#&hԨz'P!ˠ!Sי^ꪟOJa|oĿ3 % vo!*au 煨#(Е3u]3[T ƯީEqPHySRmSL-,y/~ ?%)c zHLG^(dt8TӊF/ yLqv>X^ ^) t*;fO%ڼBМfO:U3CsSD6ƬtD4y¿8m {-n.\|9!C>\wFUu"!PFޛ\f!Jbc^TBz`-#Y8InKmEVap5}jJ̑6\.a"ff:FB\F=]!G-LCETcW >Dh5۫#T^6W 1dݻ>5vUOm%Pv6OdiqPS~(M@Ϧ89) y5lv*%oR6%:?/Jɗ]Ǽ^xh.s'1w¸"P8Sx1"+y'>S#裬q~l lRq!quz^5(8'u!2mPfdͨYs? |ϊā|H԰̐@j8I賶 f24 ݃ܐ(%.7Zj M$yn}ִ 20ބ"*'^ *]Dm*,}CvCՉT38NXkQcyG:G9"֘_?/%ENd%8+4R57(1F:WfS6 61ݜG Ygǀ9XlutUQ%1)bd*2*p2]R3ϛT& ȁpفtIh$W8c )oal9qf <tU)xkF\P r 8U*۠Cqɴ/A̎h}\$-Ps:}NU=Pmfzюdؖ@x2`1jͽ]DF`AƕiU-'a4+kaX%E‡\9F?!M0c7Z>d~Qm+x:]78,x YMÞp'ЂcM5ޙ~z>Z߳.yLP,^,µV[sU`6} c#[ḀIc3ep/htTMl$ʥ65$h6H 0j#.)pceXe~W ؊;Yn_Xr zǻZڹ/bZF1"ɫJ/b^E)NїqHɅ֬W5MUx:ۣ9J?tG\ x>bXۨ}FP&4ŊMŕKDOց Z*cl3)E; =-}%dK;+<7S4v\3謝z㬡++.j"Ot&;$GFy6ɐneAQud

9[6eoNuڏDc%Ӵ /mc;u/x#gý |*HJjam ;=8p)*R|Β: q@Rpo,숆hl"JpDzv 䙔#rshx wᾮ#sar0-y,{UðDb>1 `+Jc:t_ݛ}[#G!¾[+OL^S 0uQd?d297/vc?C0t/]{P, p!47~@8'!eSU6;?4(8aۏY?GD|7)>V=?k\b.,*h摨a;V4`o.%F>&c@H8l|F%뷔dBw'l[kh% !5]W^ ޖ>IU{s&|-Z3:$=Q 2c2S,H?u2rH6bwEٷՁ@KMӒx664j'.łH?#y:0U!y{I rEk6]zǯ~e(bdO\:?J­xqF<(qio܆0ԑ.0N2˾K9(X@y<3gzIYr[v$t~Y-}GK)[Pmcq *D{+8go[c&3+ T8W%lF:HX*9a9PNO S\'Cӆ.P(C42y ˕'CU#1U2{xS_@xAL^ ~d/. @t%ҁA؏Ži^+<4q~/CrTCexrBJ9Z&ɣ-F6(@@$"MƟI=1ݡH㭮ja܏QQu"ɯ B1矲IRjze{= UO/Po4B𵿰FFI7R̜{K=m!crֹgrk:"4b.Bv럧ID% V?BuR 3iKE smROd;cΟlH _Z+хD$l/Cpw`6hMPQ{Ĺ[0d~1uwlɸG6yqniNſ1T KCp5la4Xy]C8$; ٍUk9TѾk`\s(1 fހoPN鍂,sNي{P6㧔Ѕ+["r ar6;TӠA'sji=H¥w Ė[B}X\iսz6-n9Gm~z^8j:XX2|tkV<-~Ҧ'K'ΓvC&k= JDoz {hN>@ʲD'`Dq{C䩛=+v nG! Sَ{kvQ̻{{קJzoP8¿4=i*08`c$-Fr`z/̱^0.T*tKJL@zW/{TBhOo(yx+^C4~9(C%^El%SSuBL~<6 ܒh#.ē6cy[MmZ6'%șΦYER̚u2tb:D+P0|01Jl+""]CQy(okw9ŠYW`feթ<-OoW'_ۇu03+]lPq{8ɊIȁd5t -zALdp](ܛ${2e4d?X+ ’4Pwo}vW<;=BJ.W~FtO6XRNPQZ0ci·5awk*Lv!z+ޚcWS0@t? /6- [GǼt~ 1WD,a.K0!B  2: %v?mK@relP_jFyH:ct5AbM) TjQkz=eK)Xޗ\ˇF!\G։şW1:f}FX}8,Caa.S+4ZcğiH^a*|p&Ҭ_qRn|:gPPq^p Hn3*NqgG4wuWc@L0iҁȎ%8 {&FbtB?<;(`>o1GDsdV8]uY5dΔ\*{UL]Ϧp>~7aalN&<y0\! D![aDfmk*T+$;L'J/nn&D͇r++%T2WGelc{\/eă *..X9169 p(jj0)Py &(Ufj=4зu!g# 9Ăz|7!͊,$zֽxHG.&WS"@g΍D Q!q'c(Z켌DW?%L {: L'^ʷJI2DC׷x%̚}IFfյijY9<4F6XyYyN}SSc HhR i9Ϥ0U itCZՀ)HaT@lE^7٠P \Sp/8G'j`HXģAW^,X31{nYla*hm-Z@oeյIG^&ɠhnJsSǗ뛧ouh܆3oO:2~e(TFyiG\,'mWoI'mjk\|:+bNK|O_ Tͤ ]YI#O#e yVȖRg J cNMVU䑏fՂzYśL;ݑcJ"o[>xφ1B lTUy]W4 MWP5k%\Y,WMoN ' ۈy+%&F銟TܧT ,,æ _ӕ$H&2Y];];? 6T k Gݮ ?vHSƑ&W~W6?|A]'T?\ -L9䠒AS"E <E"=pR9] |"myi8y<o ;o`zÉ9 UِD:=XmQY/Ħ!HT<5yyj+P0e-7TcL2+mgF-JV~->_V軁ǻ"btފ?s#B>P]bFQ,ᬱW!љiH=cRd"e4,+ۆX aNx̖ڗw - I" FAG+VaN5 4*,,u2|CA3mI bTMb3%`7Ch>:]yh.K(_H.4[) PVY6tU+{d%CZzuվ4>VFFZtYС2J"ڸa/ǧF<'jy?{.N3 z_)rSĶȹw$D?P?K气]G|h4]X潺7; b {TsuBcrt@: `Q텠7e'eL̨妙4oXu ,~I|ʽr4|U$y]5_1X_/Ж߆c˹`uCtB;dtl/M_ĵH(2?gXIM6HWfWjdR_Y43+5ag{QR:uZ"L?g|O\iK΀:2̰k`饨G%ZbzjN=!b~x~QviT> ]D_L4J:PF;' -U&>7&" B\X"g1+_4dp$Xv6ԛn^&8.iC4i4m(OkąT{]A)O!&XUEixqDpAJ:u~ւ ` 7-)Qæ9j̬VWݐ'#V)8~G0q[ T|[ksHGݚMr֦SqEm+w#),\h\ÉJrtɑfJ(n4/C-4#lnu*fS5414 {kRџ٦`h 71(F:q)tT\e>C9 Z6<6 M16_N*}=%@6V-x|&Qt6ԛLV5[L+ ϒkFƸk%].ܺ(r1>rjԧl14Y25'ֻwa&` Q$7{4A2to k 7:pBWK;hW6PO(le$0322e[.ߪBn4i} )'015 hO'p'%$<$D|;& Ɔְ5{d\io&E˗EOɹ6)}]6-٧N#iIȑ$@./j;F-j, D-ͅs𭐄F6M3ڻgXcQg(8ef: ^_fxy'p-`=iHYF[1x5:Rd oZOFs6w{, l4R6-A4L$u|[&)Ǹk|sU_[zuBBIwP El) ۟gRӓ1KQMUXidO'A!ĻC"わ6\HZAӒK蚤{84̥#k _EWlA Է7ikU798Nr}"])dtHBgO͒,"ٷ72:ݾ|tx Nsv@;=k 9\Gm:LjED//wD'e5p7 *ĔT6_b{FLp)ĿXPcZ#!OFbS QFv>.ݗU,gy}^꙱sJuC,g40:BbX#oBGcޅ,(Ze.>V+FrPLhg5x@fQhL,s桞;^ 9\^t<ߜܹ^)!!ѲHT™tT(K4q)Nw}p\iYuk"K"C'.WGhl`{/u#t= f}l}4rHy_DYR^GK.Z`ڎc |x"]>I<[qx ⽽&XtiDg4w3$/Uksb BV{l^)hL./凣MbypXF!4\[daZ,y}X 1F]A~7XR׷;6ÖX1(Շ0?n23X+pHS. J5meF!vv 2Y(e%rIoUTIAtAPiph=5NPL6?R=Ib zf(^FJs}B!oG]?@k Q{U$Ǚ4.ct_ FUx']EaTV{{kT6!>ߓr4vWtϡ(6DG$b6A;-+rV$6;sT6i M$Frb?y"׍~ :'i1p1/OQ`Q\`2pD׶3ͧř9q@Ūuue1~߯[O~Сmw<m{KEWWnH`}dac K̔f^vW%g+@ʓ )jdZK8y:Y`#?( ? 3>6hNیy_}Oecjut;YLt.]E.5^^(#߱.CO(`gmsITRNZBxUl'4ܽ=cVsn|s⦱x ryR+ܛBU.'6 S4Ũ=$ Y3VdG=񧸾~9Rq~UW1Dp\oԏ"Y)gӜSzrVEʃpO !%fZP˳QYIyA6YWB@C}c)-ȴl݅Jy/HtIJ ڔF$-x2bkF\y^~C@͝Ӻ3ҫƱ!xbJ*NMhۀ{נ)~&H\fXF1 @{$J?N#f9*Ǚ"V9 ?l1S;=d;"Bt}Z%Wm f˸>7a[-Na:2s!^%9BHL)ZXC ],w"]:bf#A)Tu ps-{[ĸM}"]HeC^ K 1qi![hZ;1R\Re9[4Bj{~ڔg3:x$8>!Xh)F sfS;E^N&smy`?A,ӲVEܖhDp44Etz,U9;(V) -A]rӫ*Tu-g*g +s%_T 2\pcSmgzx,۪>#rVSy٥dRQi ӡ+>9R)&&:ܐmv2%c8Gq j7%۹V}@Vmo,8$  Tj 2~wfGvo=~|i(mF%SC39ur iAg_׹{{6bU0~4$ X&MP`K4]8fVŔ& Nxc<]@}@#.yQҼ^e?"5'5NԤF& y|9DD慪b҈Z"J4>{_h@;kc:^ELuDw 4cZͤekS%_0FSJ&RTH* R-.UB įk}pf M b&[ 4 FZn loL䄤$Aje|,Z%.oVƭ3*My+DPY&r9Fq*Lc}EEG YSKpI F;ׯX܀Lނl5?cs5yt8{-`kQI"avlޠH]<r1oIi+c)ټ97U"W>>f(bC|*UEl r,`;=nTgi\O dX 9خjiOd:6]l>&bP]@fHW M3gW 8q,mٚ >Pj س!"i$5}6[bS"6oB Axb&Jޖ5tThK{(տQiQu {C w~8%4?((tnj d0!7z5gT2@K8=`8!HX#-OLx>P$g[]fx?UfCP^S-!K;:_h N:G~@YnUG+M _2S*&;g LA?xF'/#$?NvjC82K֌Y &tE'MJ}\%v۸SD"[dfM^b 0ǗGfUeό_ yp1^'L'Ik CC{|lk\oH7tH^S-(PBGzU 38( Q֏&S3-I}O@uŜ #/7Y] H θ g ` 筊P _;;ֺBTΧ>t>jr%kpDO_T8$ǂ6I}8ykz12zY(!oMF -%e^2 {aehٸcb 0ga.p%v^G&m(p}!eI"N0*FiK&Ut*-IȿKSY^!BtZb-)5j$^,֏=EO2꛴oȆ;n(]ԋf*)5WR/KzR| ^πgM}KU_;T6ɪ;IO^6Zۭj1<-ݜ]wIz_HC.}+ާiLw:I-"Cw#.ߴn%Džj)2D]{jfEPHUa @ oeMxuF<^43ULLgpUmKG`CdT k-i㉊ /<EtDFW>,Fx6)gD.s,;ia6V7o<'}N΢W7Þp4O!"C2xrGf[˘+\T>"@ܸH8*A-XQ2 pV_y #8m\j9'vB2cw v G06]`k#3QHoӅVc,% ;-L͊%D{w(%TByb ynq9%ZQm/MpxT{9'@GW%(d[qZ~M<8ȡS':q7w?o~E9dw4jRY78MyW0";['S,VpAgӎb'\hcn3 @YŲ!.`&mQ;?[%h;0ΐ2FqЩ4GH% b>ˢX9LK,y~4GXV*tMuQYڹ-ڶY,+3e"9|t,5?AD9E E=F=$">qbU!_c~FIXCE{UFsLuQE\ۼU -NiF,Sjrz+v)銷9ĸa>̤Ek,(-78ob|AO9&>W H\X|↷?@TD[ܙ[FnŸLM-3eOkՂ4WuN|`5x.)h rK/ @Xhd0iQrw/{s{]Vc سX *$R;6g42/>ZՇ2T8}AыwfOpK.! Ppni ɗ :7-'U i1{m-cRQzr_s28 ,{`h#"`ǃby qLw䚻8)Z畇UfFڌKX/0,䵘*A(^L-}RH~l0$*|Ǫ|ˮZi @u)MH~ Zo!V5 {ȗ(*=s֤m;=7.qEK-eU0{(\,'4]LX@jyl"wmebcpyxYН)0 iYw 3A,A'\V'i_Z/ nmZ+ގlzP,ASN =Hm >UHQ䫸tV- gM'[:dnDƔok#A?v(nO,mYMgM W$oӎ%M/4Z\L8\3PB|f]g3PЖxMy2s8qy/GI7[?7fƽ$~[e[b2"l}?E3]`Hͦ^zϫɣ_/LcAGZmq +yXunل@'|ǍҦ8WlyCHfÑ}8["A҅tjK{e|HR!2Dq&0rozQl4X',//*nyYu[:^5W37nVnׅ]Ǘ""\ RWPA?JhSKzD}NM@HG%g INpKxr֨@[mYUҍ*`&3K*0fg۷rc"Z: 5BqZHbJ8dM ݝC}P1,ߞYXW73;W؉*=Uos?$йQ^KgYW͟XD{<"zbt`0EsslJ|as֋-Ak98u9\^`6CC66xǠkbS[Of>8}4}B˒@ =,k,iJ#! C^w_r5],#辈im8C ut'}uI\T VIs+!ƺ *3ɡrkH`<C?ץpF`aʮkeVvqAׇԼ<*JӷkWP-d L birqrWtL{c9Wcb;,岑;mPS3/Y(X / &pzH/waymQ 7⇾[0ܺS.Evs39H *e$S.p0Ou&݇Y6h Z  &KO)cqT2Hֶog1;G1b4~9N8m ^t6PNa8s ;:p[5۳l 8:7Y=SS)vS0Mڢw).cb B{ ^#kh?9_szpaS7|jL `a.yݭ&vd6C]+RJ׹Luȼ4GmagGen?&,ku[%2< V&iuNp{_oOhsL7:)j!# {aUTcvG DRsLb8b)4SÕ,vnSD$b$ Vx^=񨝍*Bei#vb7m)p8 2_n =v(aɷ͘n\'bt['߭۰ҽB"FXzVBB$^e ܵ*)z7f6<'FUH0<9g |&&ca`$gzǞGi5uHMu:wdhhT,FRgp"&gOUNuca$lEeP2u$A_Pv>;Of2=!a(ebO<=k~ ؛DHQH^UJPt;$&@(h5{E,-N9Lm6?U@>@s)#,Hj[x^eC%de;]͕B!а]ZWZS\1DXIuȒ]ւAoO]O9K7~;8-FT18 `_:/:8a:u|J_3{ϋiuNG<ٓ3i6/>Ņ,Y1uR'/v,~t_HsiW!AmĹzul?e=HY0O E5dC3UZ j9TN/V=eB5k(!#BB1Ρ%5pʽaaْUq֊eh'51## }]*;1j;)KN5fHڈIq1n>4Z$n}}6UҡvI"7ĕq]qń4 *d`Bl3@7$tL7VVCJT,1bkr)< e j>1|Yx7m#|oTX=sn exwmfAWTDVɊd6D']/%P5Ao1oq[%,Vo wB2Ƥybᆿp0F5o[KSV2?j!mx^Wdö:ԉlN{Ѳ1,>kP `dvE?"ྞHb;|IP =7a]M*l!!qs(7I׻M}Z`nP؟H{D]M5e4<-B/7n-?ۥ|Vi5rpi\m.7('3?dj!!)ގ|$:uۆ6u?)SOXu3TٱjWtvv (%/q  'OR|(2Iav٘A*i+XJ+NeXFfg{M-1n#R| kVcd pj;ZN)ЂYQcZA+ig7*QgRA5qt;X[E|Úi¶~a ?n8|2@wYG>w=;9o78zN,0%.=oWTu㧒bmzeo}3v*T@xaIz8Jw@OB,wD ݲtƎRu0zJ79C_rCAcKbܑ#n. /b鍯<4VR5r_A\ 0p3l&@VA 1ͳ'nP_2 | ?T's»{ʬB3#~(+9# ބ-9C0'V|Yw&6߹VP{Ԅw8J1S֪׳Gopgtk?ę Ѿ}AoKHN6YEa]e nhx) qCVTk3߂7o3D17ԷU#BVG~;Z' hOՠ34ڊ)pk(ܔ$$AV4W+ c,أHTX`3NjfaJv~J=ᜐXD'6,4}n9FՇ$0B< R+!/\gg;u܍*%+Qzs|KLE&Ջol,sN0e{1ymNP`Pxtl+ӎ[qjw"OiI+@h-s4{ Bb'A nqbx-yZ>vMnWNEas^Św6O 7MtFkjL>Nv>Z Ӝ-,9:h JLOχ㤐2bMNe'ٗ1m8 тʺ=\Gr3oAI̚}\Q:3 I(Lbby/rō7 qZ ׊]de5r]OQ><)3'mpꥎGK݀nTm:qʩfnz0]vVq3AWfRG [' *:Sv>D:z}Q1&sp^S=R~d<;_1y^@/d:XD?IYrc}aRZ ?¢q,{{au+ 5dO9}lΪCP&7/g)7O"}_; šnzc(1,ԇp2eFgF@z@#y}&IW.q&W'Q2B]%"PwfySA OIgBԘT#]׏%Ϭ-5mfu`R[ay4gw{6<) jy"/֘jjբF4=( (&ðҥ3!}+Ni_\֊!]`'ɹv<&KܩX7RE[Y&[Stң5B>5{+̼<f#dZlpuՕV(fEEʼnx5k$@mM'/vZfޓOb.;]"ɒ}H펣=:lV0,+T/S;fDv뵡+&\V{Q?tX/8䚍rة 3]Uv4UqOЙ9;r{!Z:ڛ"EOV%{ $~HN}+ t9aIR&>6 5-ŎSBD}/(ob3Ԛ i-O"NۏsbBK]\}cf L%p_# {38;4C });cVc"hgnXG&ąvAda>.@g&'2aT\/fZ9׭k=VERf'l8d<`DqQ;'l~:zIlgPD<[,HqB.Srv@62X4Y[=yءu8P:xs91(W;Efs<[gA/ Ѓ@\3%<Xښ=v׎ V'VíP(B2P?޾c֪m\g$5(d/3NNd{p^EvHkrP*4).ՙ,ݦ*=>Nk%BEm:*J`=+R^bw/4mSݑٜh_M UfA jLȉNߴ\F!.#B6QE96PK{OȀP$22`K<`CHxU7YGD[fx%IYXgCS "YBe1+ĔDQ8!YJ&?HcFLG_tsbl^[:rR}a}BKĪFe\.pU9s &3gV|dH=S5>KfuɄ0oC$f@Chiv&eyaCO&H$'R)۴y3Shql>ZlIMHښ>xLY FxlN6=7V3)NB1*d]E"X ӧE?ey`8mDŽ_;GYQ4m^\^+E.&?UUQb9ٝ֡HV U71r.W=jt$!ճk bu\{6 mbcq-=-~VA ҫZm ]wOF N<WapuZ<f!P %J򐁿4E<vJ)vFp%)M.ԸRs~~2k}"#+G"w]yZ,„)6k.< eƼc br,z4|COx'4i&ǯ1`}u"Ǭ*./q@`n13Aʘ޸AdYBJB״:$ K֊ZR| R,4I+ .~bOywf (?-T%#R[Vt"~^*-&֛S٧y)V*Wk,t1N~|._x*o 8'WmcN~thJy sYM \^n˱ϨS@TvVB~UƼߟxW!⟋p5 Q7\p˹D.Hx;dAHa H{+9Uw#Iّn~j/SPty`>Aezq{TzVK%>5,t*{YALㄞ*7@{םJW&̶|8~AeCZ5Ȩ8PͪˠSImynHA|3\F[3AM*jHg]HX+h ~J.m{?YNwQb$j݀?"mL uW{Hg\s5=#^ܸ,`f{s˘'Q,$ nxsSOP!/U״6IDT0v <8K!N"\-Sz2@fZKI+gFH޿?O"?~9Nzc n,a{"<﷦{<<$]7*̡H+ځۺ8sH.ە}6 ͮV ER*ԚAa-n첧3,uL(=dF5eL)d0ugUkd/dȣK5k~np0=1]*Ψj))nMsxy4/Va~V%S[u̇FسןydmkP޲M߉ohfxoS2 `m5{b*E4bYCwjqr]&xt鄢O)5c2x{-RϼlTѾ0gZaTX˘!&WQh (OkĂ q k&c%@*YGGAh/ZW|\m[IG&E|Ә]4ZoYQv9u&A57L-AϞ҄+jҮZj|0\H :!N' ^>”ˑgd_gBnN )ǎ9dU7!X+o4h~1V^Y:g#Vݏ@gUp}%8c.Ey\ցD&'sOui;! A҂fHr1owZ@'}ׇf@MN}ǞO\Ē HiEkzd! ٘LEXZk):_ P* ؀w$meT|:ƻE!{۔~w7W= :RIxKFpmuN, x@vMWCIwK =5JO Nu-#AWԲI!Dp-e?zyj!Au, c [W]%}yxJ5jgȤJ*T?p7YE$}ӯ9{6phUMCoPN OFUPҴ}t?{6Q\IQC.SGDE ^SW3Ot*]Zsw>I'd|50(wH'-fMWV*>swj?UVNFW6*mO7ÙP}Y1. `wvbjZ5ߛ] fyi#XZ4>¶n혖1gfҦ7ErY I$YH)x/~!v1u$3vkxT0;$R-V_"zi*̋^Ж3Hx=^Q,!N{>}ܢW>$FX̱ _u*8pzو{2HGiΠS\]u_NNs 7Ǟ)mG֑Xk0@>AgCǩ*!s%z"pB~ =Vt/@b*kYZ.PwFaC"VsBgTR+qYы z3 TzZ]<{j< n i&&~uh6b†-b2ߗ.mݟ C2c7S*@ȹKXp;Ht`~t,/dsʱzVhagZѥ Mc'wT%KCwSIzl ]ou y@^tJ&C-1f_u.u P-Y=A-/uSύ'4 iʬ -rKF(pD+5ߔ80K]'؟*({ ؚvb &)HkT-zmrPJ[_RI+/dʠ^j)N j$N wKq{h8e/zo T3ux]Bp4RfqfUsqYX/݅:8UY]~-z/e}"uB[} KvIdݝ~"lP}Y>S.+騪t({=ȗfKYF- >h佤REˏM9p1+bzPߛ^1޴u=ԇWJ:FRZg\D!]~Aj[P:B8?ّÏǝ L|FPA-0\/k7G*O#Xb:k4;e5iK3zH5: bSdo)՛0ȼܳ2S DbVN>ÅwnAcuE:j#C),BZh'|2e#SK9cT{Z9T ,]'tҿi}^X!D}G.%XJәtf+[s!t N8De;!o]3v ,U] AЯ ll`MbCM' C u~GR ?>H`ylh7 Hkoܐփ hF0ؒ7g?Yy3*9o2o.UbK"N#ȭ^Rp >%{wuLBGi `>Q~:BLMgzsGAx:$eSj1p\0-i_#R} 0D{!)@azOѷh7ߟ=ać9<'XcFl}h[Y1[ id2k4ݰ9ȣw#9j ϋF:S=6Uj- w}]D*łp<3 }:񥟹/8v /UIl?vwNz~k߶ᵞ ^Y`$W\D _Sd|] v$ 'Q; CQa"D[B һx\b-wb^Bp~ vˉZwԱq,JC/Oޛ,Ya%/z\  nv@+@IŇ Fk,QV1îd^F,09\ Vp#~̠L*?}ŅY\fwDwd1\# _WY H7.hH+U`J 搴|({rsaMc1VIQMKF_ښ9k%WpRTk 0PAx9RPǻ -t5!@ݗ7`Os"CPc>{y Y'd=?( b2C>]~;ܸI9D,Z/g AkG8xNyě}rd}#8QQA 6_R(q˰Iڗa$+$fF H/ʪd_|OpꑟRb*9lzC6 <_4v9f!HjaLk~ ~$MsGK|-/:<gvlޙkLqk`wz^luzO~쿋<9)=E\-nc-^S2lR=F?T;5tU4h*ctL)@E47Tӡrk̩^zO2Jj' /4vð<2x3L&D@&w47ͥ/|}0pՆL+B6hq<@ͥ1p<N!o'ɦe'+:;#F5̢ uINE˩F|p_+mJn̓ݗ8٬&˓Y0U8mke#^޵DȟɐR0SjigEk7 h ?"Cltm5 WwJmDEy3Ov ;^ i^Y%<\_a4C,|ʏ bts+~{ |^ !;UZ,!D"/- 7ڛZ:ڕ џYTdecĭC6G~0Ka<>YᙕNVUeq!0oZ,JygBp\sŶ.L>\=|: =E ~:|cmV<lZIXrMўBNB9EEss^N /BvD%$GaC"vs-+8VnEۗ0$ ,!0&'tS ]~M2OaPT4ac e_>SrJOixƙ8@yBSiTkƤOnM&fwVn~)V'}V->?͒(5-ly ف6 ):9X;~ 13SStǷ܃[D(,}Xk|<)+b΋O@ͯpFH w!!tYmuufNvP00屛YhMLP)j|Q"g΅u}EdN<7`Md0uՌkL?9ׄp0"?c7fLTW=U:ńV*#rp!&5!e=Ll/XD7-2Xt"2bZ45Qmkѷ-֢Y0#2}UJ~;}״xoTVsX1aZX~Rs oB1e&ub).3G4S&ɘ'dCGhTm̡ `ٷ2#_A0;7?+GS2;rl΃<݋IC"=sHH@9ZFz'=ta5T-Sޒ`E `KWMi.%>Pz-N&B 2 h{s>O]6/t4 B?ݫ5+Hk^XCev sߘI j/+OfCFipbc}`:S)CvS粲? y. Y#534%1@1 [#R}Gh-çu6RlŜ`PD﹝MEEC%bs8q4O!VC!ʝgdt2UZͮ 㭾aF⍉ei4}NO^L ӷsʦ' %0:#lS.i[PF3Nc{9Iډ:Ax]9Y +Aqӕ si4Ey]Q OwNG[oT\VR G'P#c{1m:kQC ݙPN<25NƅP輆AiOdQuwf&=4q݆dj:!o&DjK[JS-e?{GNxjg%̘ݯ-Vf8,@%!ZF(t]訹KUH+jvQ_U#\̕q/x fMfxq.7!3M׭\X-86BO?anK^Q =<8F S1;O"[=A!b'{y>2T$YR]=`f>i* ] _qe."(RG7vt~ F!``ǭ"͚ߑiR6 nA_{pNq,hbO}ҵT|`I!S|\u 38jno`!naBxIfK/euࠤKr7ͿGJ֭ν^Xp ˈ*}mn (-^5Qi{P85F9ɈhwʂZ|Xɕ*o JX.1h$(;ytT(0(PG꒫!ٚTX=*H} a}xrb]EPrq U}@r\4>wCRҭo*z攥\G]fUsu?zIB@~` %ZWxރBOd<`O lp48gug]۬r5&(@XznW\‹BVaTÿlVn)i2BvW 0aF~{!T?,z p GQT7(6}./X5&DGTN!X顦I.jdڌKD'5s-סB\L ۵@xzpwjb׾ Q]-)%qZi׏td& X*\:2'AVa:3TT£t; W:181kV A-XG 댻r%G>o{, dwO6j6ocVds푱k"pk /Ȝ~j@}3bԛ8ZV;C"+mq.NiNt;0%P֌J;a xp3DGѤN#Cj`ЀyP\ZKJYUMSjj6<8E^z&@qG5BtUٛ6 +Uz)1D$z:6X;3!d~cx./% @]z 3lմ3ϪQ~WCNpRi[i٬"$ga&V1Q!_ה1i(&/mfpN%\QS*0hc3L})}TO_5h]ѠuH)`^޸Ҕ_ןd]HSl *>8:l|Oٚ]G5t&9Y n!78-:uyai %!0U$K95gD7k}}^/w} {a\@}Ss;aat ԭ``A+ãDSd#4FHyyV2׬hMρ u۱2G'[P\ z7+QQU,E:NZm 70AK}RDk[[a%XmYu&M ѭC2:3]P7\25[LC5.Ⲥ4陿t_1c齎 A_E !ٖ[b1`τ;g5fa9SZKi #X Gs@ ,R{llwBcVNͮ:h66`mkσh sctq=bw@s8,KxbQ^0Qxw<"5ׄfرX ? PCfwe ^X;  習b)uh U anXs}=\rhVz]"Y5OgB`M,%) Ip3TE *ɷb(1\HK08[B@'1./ 1!eAZxN3- |Ҷڅ^ SYd}"}zF`5ᦋَﻵzfOxa$xH +iѕ7FYNQ% WFmTWO qZG>t-wlcַsz}0DxmE)_nw r5B @2<]{!QnL[;q_t@.q@?l}(P*)%=[ &k*&}|dG@xq*jZ ?8y;g6}tVmxgJz4/h`O|›t1% )&oǭ*^C?0&NdġVMAHct'yrD?k]\VR⨛"PA`rl?Qɣ Agl7-'я_)Hj_Ogy$Uo ߌx6߯&ִ19(&Z|4җ 'jΚVs;+:2uOll$4G97 U^ _23JݢEtozE0BRmf-Šّ%`[=ѿϟ^g,P؈KeMǔy^vwt2t,k,P*$?6YoKaJ K+i&Y(L[)߻ "Cdy7'0/ ƚ_kRW3{ G&B8/hGJܬ70Xb{WI+@0h.t50xhl?gz Q"D6´;p.h54(M oL۳dprAm ~D{CKV젠]*TW¹ E n0 F^\ UȇM!\r^'ZCDzf9)\jkt枿b82i&xJK*LN8/mzkmeˁ3.c3yM+ܳe4JRnJGrd67yɩbރ1AnT[]bDc? 5?EC0ղ|$Gؽ fו>rߓoL\8KpB0bJ{Da'>З{'X?vE׫J#2V^ʹs HA1_}œeGc*d"kj:-@t4)=wjԂxOwTˀJwD-G#0' 5_0O|B7N~+z!.5?}[ W/1VTmI_>X4n]bU1%{w%ϐ+:W{A-Q@~H. o~DDow@Fj>:ՁJ* m ҘGC9&}aF`nftkyFO$L@6]- h(k7qYN-n!v:Ub=,t66W}{V=S'RbA9pIt{?wbdY*gW06BZ [;vҌewaZZar,TC\c]ÅX?Xߕ~,]hrGI<}zaMB&ݓΉHZuvW3#T #)r[%xj+;( @e']泳,epxn GIUca e1VlxC_kRڠ:<w5iQ߄._kH#Cm¶|-uSʜ5:JY- BXX Zo[׾sCL\rt!Ӿe BƂW- agp[]9_P@hAřr4IVYW[ .lFK7L~9\԰x4&6qeǺ"keѧ(E[bO&l$yFu-[QU͇Tx0?O=|=wMd-L&/d5( { %훚>3U-f='5r 3#jpm*&߈ՄbaI9[tF %m6Y@b jGx"9F4s} _䣤Al֠2\ nmy/"g+H\ϓ7i'9l&*BW)ĉPHd;eNMi]lyx d&WP)UK_'J?~ =_XŒZR)CS?<9Q+FNY ?6iO,C"\Jwrbgҧ,H67)}>%q}q^318z /S1mՖwMBC K4ǿh _OUa =}IFR{C!2/WJl%Ēm &vyG>=-DN<`&C]JGS_nLRWoZH(ux,9pnkZ]^$ÅnsMo\d4=af] 'OY/ ,*nߔUuj &&Mkh!$*^,fL=_%ݼ{gk~]ZmgPRy7nK&"?v-q,>ڒ*jrQ2@-, /_{Xu(HRHzN4ҹ^99AO0f=˘dGٰX4[G"3k:2Ą{hoK=d5BLq\ZUbLˍ94 fQ%by" \>x3CvVZ&A:3oQQ,B4dZSt@J藽HM<ˬ"uўe8&W ktz~5b5G< cZ@SM5L"RFٺsF&Ri[:e iۛMCpg8igTDD"Tfot vT@z3Z޵Xmݝ(?!o*_ZYdHxJ.Bϯ2JE c<%2w#:w0XNmJņVJoLmFۖ7MHш*6@H>+7{ # p c;ALKTuq>Ե%/''Uoy c0]A9\Gճ .{a aFpo>g 3G&lqo„0O{@~/$q 5u32ydR&Y>4љqY"?FY8Er;n͹H|g|O. ޶uNcO/tC581c+7x!i&k#%-k+WGӦ+N VKs='RIymՃKӑZ0=3,aewr:n߯lMǷs0Ŝ (e T+֌syE|SH4,:ic (|D0R;lvـfAsMh@^l=0R.RdgހlcR )ȁPl00Q{!=-f ΄<_H]^CJFı,;Ev bHYE9ѬijHWU[ԕ-^ "?s9$>0?Yɦ߈z.isn.уpE6) -ľ>mD K&l畘fjvŞ[+Df:91cDϚ$.orG02f"nlt48OL M]lN& ́N"X}s$``)_dTJ.d@,e8c E"#u=c__Ût16-(ߒ]roŭ5xSzD@Xaimn꽎~,< ~Wo`Rkmϊ{t̲B N $7+n hJ$H\KxBTPgrqWK6GGE3x/{dFY r"HНWBE!#iwރ~/H̑0Sj9Q2ISN} S?NNڷXsrc ( Aukv%sW=e!z-؁FϪkCEݴ0 ,Zd!d5Sn՗h=gh2gm^RD22'}4/i F҅1HlN= FIS!F}"#O|!E_9gg/#Ɏ6İ;'$\? jaq&a?{ 2!)<>\G^E +u!׷@ dnsr ն[[fa`*_n_z uMRN8 'bOD{"mibpFUlHpr.^e iwTe1bLbe]ڷ1 lq{R۾6`}Xuq%Łh93wvFsŦwO:HeL*^vH_eNM4a?)0JQz4 "8O dK,-{4`ՕSΞ̧N6, V ޭNvxď34!^ i);#w;o0|q\{/g,b4*gOYt/DT1.ĮTt:/3Q(\.}DۛIBxH,=?I3^Gr6Ϻiv+1JHzE l&֮ 矑_B{EtQHwqlяGۗlK>Yߺ"8e>Io j H鳾.h(Qlp0;PuK~!Q>#ߊP%ּ5LeWSKy֢o hQ+{ *,R[E `yoi@Hc^N|6r43[s[z^2cwyІ]S4UjD΍Iɼ-/z<=Ex|יHGyɑ-m 7z4e [:&Ɲ[b./<5Fʹx&{ZAu9cTʣ)~Bh/S6J;t[>T - W!dB+IyP0Q܃8IE Ϊ~b!RG!Щ{N}Z4[Vs|!:5f(c|.ýL.wة|TّPq IhFL)ge"ƥb.YIԋQ jЦ9vlݟ}[{9BͰ EsfW\>*`GN䈊wvV!8|Feay-~ӨN4T9!J%ҭT8}vHknp10)o0 =kSkÑxd.Nݡa® OLr\&FiTۜyL<k?ԠmO ֵU,ژӉ# $9ly^%0ړxe(m-$ T=F.y>Xz_QQ;.k1w ]f೺*JNX^%BF# cwb})g,f#6a45 Dwkng\?|it V `B.LOuj h֜4au+i ΣکzM EnX7f-V,w ;1#@[85C B½N))KL g͓g\s۠n[uljʡʽ)?JޫRAULQ‰dtw4Ehp;R7تr6ռaj oOÌW \n/Uj{pϝ-sED-54wf$+x3zɬaȵ _5zE_=Zk0(P;4b1f+,?sd$nI ( p6NrDF1?lYcpπSq0$:Kigx' R;&$w,mrA+99\ҹ&D'‹0]XAk;F R 'O'm%ѓ RyWΊ"38h-2P )soq kJKHSpiHʓD~ԺW%1jZ+!<s5-"*0@aҧX|'pY x+ht2s(Ur {/xbOw1\{B{ ??px-Qf;?x-!I9G_7jd-\:D*}`6G?L/4JAo-HvCU* sa㍜q}1c}T P VN0梔SJOZG^+1*ۼ"dSRB ;ȫhlZ.N1Bi]F3^']ڋf6yK+,\Oab>8H'`RݜDm:~h dOxq@Ϫ R*;d1PC s9gue4ξGe L?8*4‘+n?6e?e(α@-1!s>g}eyM6FQ ڸN&ҿbmdFB40s@BL'9/j,V N!Ur< ^?j\*莮+?$< Ϟ5Ht\,Y\y5:X˂[6eI{ oq= q.褕,~V2Cf!5C'`- 6&8b;DDr?OL$NCs5bjsR"-Sxl^F=\rڅ 8^zw"f7|TJ.5 wr3@Stσo4:H(o /,9Pylbg!js!ģ۩uqE8Tml, <.B'Om&yꆵ0 s?Is\7 z#!e4FU6c"sI{i݄k7Xh@HzdkI@ T63>bʊUl:g 1U<;f'tmh͍rh'θ7e!b!ɀI*m996t$tUoTe絠ky)t`}jbGRFe7ϓIYrzYB:> M3Qgm?n:@)o=uB.[!bc4M}8avT'k+8 q˹U-~i]̗`bw]]P_U`œ܌^l^j =?ʁ(v_$O2|* S 5-])!:ձv镃1(xߖpu6~7h?8S]<}$]*6#= ]Ry\꽯*HUHbTDdfV)BhF Ϥpm᡺M8MM8kEGP-uwAwf!]mr6됒O*$̦72ͮ$xɽ@}{b(<s WVBqlxf ˘I:oݶsC^`}-+cyjR*}W`h;De̦̺rt%i$|7B8zGgŖU1,$ NjHfQ[S`}ZK]M5'i+Ʃoؔ>t&nG;e46b>.T˱}0_>/AAjF+^k,4Y ةhbB<ĭjz7LBz: &MψH~-?!UiŰ4KFrbҏKPd_`C5oG zgR 9J^"nnzծ?Ԭ(涕d&3f @XG!a,:T`?6OT+B/cYP:P=ak Ͽ0R v`X,tT.T0m-۞Z$tSTK3 2ކriN~m<\ fpC5oYq1bR{Nzc>\I1#gA'(Tm*EZRlOo*ގk? 5|?r]swy[d'G/\iS4/ K׭ͬ` 9~4\Jof>:?ҸJ#Lºc{ihX/OْÞ)+hkj¹9E=,٘ Y*ܣ82 7K RREw@΢+ֲ(!Ńw"ͫ.˒v{([CC8SWP*E4 *%evKPzDxUdzї>??MP;+qZHv  [Һ)(Xy).Jcv)g]}7y 1|+L/l_ԅQ=|c` 2v VVNHGR/e(MM:\FyjLuɽ,eKf(OuhU Fu;Ix㯾Dz"e*F>]"Y bz=F|q#i'審"ڠh*koM+ymX{&HkYq ε1V:-Ѩaȫ_yWm)|H9Yof%aCJn{2i6L&UU㝣S5کQ>wc"$z'[P er]Y->bR:Ԛ\/4Z~<zXlL;@ץmpo ^q&JTQJDȭ8'S#t(!gvbO"m~*J%1=ŔZ ;2i,@x8<Ev녆פ.><O/rqD\K\` e>%?LnL.}YJ>l{UDA3tnD8H9aOHgaQ`0N\$ٜە)9?)dܑ)7n0l룜q.H1\"l;@LJYPvDfQޱhEI%WﯝcNgT}d5 릌5E]uMډjTԂ.mg|jvv‹$);aH9 ث}b!ր@ÕUHf "L ؅:\%; r  f, lߩ>Q:穧[U!+|߿Kr]G-k?P XsAWМ6I"ll ͲŽ;ncDYՊʫيat냷4\ eI#zĜ@(7@^vWb<}viWtKnVGm"(:nĵR |]RQy q)\hY{ZԽashy0;vUqfe{@NOmf@ :5hVIFZǖV;B =nH*5rkfrzsZ0z2Y-hrʕ[^p,^ f`nxr{ 4$'_?gLpsxߘ2:87=˃b([%ƭgW$E%9q@jT~t`h5 !!8%s ]>T8CKV4wޞ( 8F3HG/V2S9Mc4$ąU6{|l;MhaLF#m/)p ;9_*3M1esunK1J]&m!l'qJ(6)@@~'V`ܛ-Su-OĝQ5/1$SĎWu{hXx4}HU $1e nׂ* Rt\Q}kՕ}۝!chC.}pReҀ Lv:ZɉO5؜omw[7 {bPWd'[s;XM|I嫾@ mua  ^uKr?TE6ze v]ϢFRr!#MxFD@Lggoj:aO>W+iJgןa].x!Q$, M/úӉ %O).!vIڡ2KQ:{[=-d=HSPY%wj"g jPTH7 2E:|CֻZŸ6E'$'*6De{J~RT[9u%z10G%ULn+FO K{=a5;Փm84L'(XIשN{›.+VDQZ;+<sMbĎdM&r":2i8tņ@}N: nCm_6&G߮ df=ҚB[>tQjEpz-LCtjg{N.Z;,5B="[}\;05uyKYe9#"1)!1zbeEDwZ.`<[u_3g֍8 !P"=w!f@a 9t^¡3ܱ[=[<60FoT#*ՂjKb +Zݭz+] J-vQ 23$nuw=e̺*b?r%[ЦLxIx@ٕfgyeM^Yjm>-4«Rl9 fvwBGb\ cϓDCn@v-L34Ix݆u587~ o4,G.m~h`\[˟V%À\DO˵jZ>hXi.yr!n65%]O6!cT6X3O#79,( z +xIۮQ> 7cTaNw#l;penfW|Xo3uaaP6y('QbjDj6a˨ʷzxh``J6g:!G4J )OB{D#Bg_tM̜HK+8 T+ JVSGDN$Ĥ):F.:Zn:Ģ}zi=2U-s qCqZkfNFr]ws7'GLY(k̕Fu/`̸ȤE,{T2UByˈU)l'fF ߫d"  ؚyb3M#aꨬ͐TЉ6xQ#mQmMJeON2?H>8a'G[E 9&V=^ؙ]- $n$JX8.Di֘KH-P$IxƳBJ}rG: I\*S^LQ38Z^͗j29Lp6͛KZy(Y:4H}Ȱ d9 Dn"^ʡ^`J jv(t97Bo6 @WXџ tV 2Cnfz^<Ƽu]%7})/s﷾E_+*24CSWo.;h1~4_oe <]RIV.Zud<#e ~;'w s.pgZؽiDdg3-'̓Q{VA!ZqPZ2,E4K_rɏN3"j-}8>^Q/GlU6a CTwiK63'ԕD1~s-%t6ވLRCBKO{n0a{9,򣵀ERLѾO wxwA{@~=L\l1I$`(* EvQ'.f] 3F;$}u܄Ĺ԰bB*Sh?S(pV#yBЈΗ1霽=7y-9qG9䒋|e$!q9;C.o8[@`9Ag׺^0h 3@x?#ʗhS1u9 X& 6C>x_xba"e@C M G)4xj@P3tqw8"^}>W;?n=n'yZ`anH"NW.,=:Yp8 s n4LƎ\C m72tlM*i_MtIsTD9s#3vFEvoauƚ,+@݅1/1zQMOS ۵6 x֌9rpMvZj@5N<$p"󠩼| Xtk4(Vy޽.fHCfR8_` M3bm Chڣ* TB+Cbq.2Sʲ֚*$6;b,'r`&hh?66>.{&,,x1uGNqངLa'2 }e * tZ53YN JϘW(7`;$j U>>.{JE/S!u Jٜ*O#gͱbsy ʹ#yAyNyuFq%Yk=t66TsELe5Vp!\lcF }fu6]QHKȰ[i8 8b;Łlx35j}Bhvϡy}Si3f볺Ѕ'S 4!}feSRqzgi/7q%ZSGDO7]>Q(t!lKC,5N!B%Լ5fC]AvJ0xکZ},hK9Kc({9k Tڧڍ[u6dZݝs,cA5ԜKriEIfT>?nٶqAѷߥYpxF{ ZJM3NK^)| {8hR,=zg7' jdo ;OՔ oD7{ikg^zR@uƳ\h/ 8D7i憛(&+P,C`Fг?Hs+Ag/Kd5ŀy (o8I8izB4en+EWn`{x^D"~]1VB`7FmF0;%SIG3kV6>v*w4/vU#2f]); I,zs|BE`V|4 -ZAg]Ӯ).52C`]0΀ZA跨B #4R?Es־P^UmEA-AnRbA,N^Žpbg=v@h W/M$Tۡe¼IWgon7k?15AHWeQ9SP}IdZoH0~2^]S5P$J3\JL,% MsRJ#3\?#S QޭR`WZ #Ȋ̻AWVw,iWqH dH>\2}Kde|͸㿽vUI[ՂRO3S"63(M_7IcmOqA#fx5:?aw1M#X\*Fփ;mXȀ,˔6FHw7%y֣+UJ,A[xWʿ$WuY쓊:0<,H4^>-U͢eg}SiO(2WIs&*LտTdlg C'liǮd5PEE 2G\nSt o0Zxfm&}feFtCb:E>I躲+f'28t|ju<X{bB&w+0XH ocPQp3]|DT}؇Q,FzfbCpA"küRIkDF{H7mumMn_+KԯVz6/ǧ7ķt̒ZHJh~N פּAkɰ?6aIfV+HQ;>SӋ:WBzG}BqfP.s Bwpש CKc>B|߮ KDHb 62jC4}O<>BқL'xǝ/ƶP๗+jrͩ k6vy{֪wkC[瘐Cs'fSLA? <,UFqu $ob/6 SI4%/Mt Qc}M!'ҝ+I'})hQ 4r%O=(Xհ!%E@ "\΋n:} nL9"X$%7cPؑp8iDj V rvOoVQ KMHf= F]6e m l.d ~ (jPwa|sQ0FE3ڬiڨ ]'Z}b۹pc~EFt :M"sY>nBQGp:+Qn_г&ڜ}7ME8#\__ȘU&6/Z:zVf])>c|W7`Gs>9f_JZn(OnLnb~&" ȦȞOVʕVxI(/L6i5p2S8S0яv]QaZ-,+@XٱʛoC̨ov{-='ա3Tӓă*p&u0zX9v,0AUlؚ$ict?RJ25հd`=\ ^<.~ir_+(&rYV5sƿSdt¯%9v03GG"g%'>*8]k(_V0:{JN%)&"Ҵ>>PvNFm*k$j{4u_|kRh jNi1kҚ]>?t;>)n5*;ώQӶN1}HɒQtko!5DdPFdOmO0 e@wo֎3j9y G( >pxU=Wd&FdIEf7T1\/@; ]i$,l*EHD/=cB!C S46 /Zm.bO#IHfi`}yBBܟmm{/l(-@c,S4T=}"{D ~@NL'_|B~SGl|W]oNsm[SWXt5<[#3 %ˊBԙ qi_Cnfn8qNأ cQMkv1 oRܮ3 ҫ,GSGb $5Va5VuٶKuR\[gtEM?t6zWy\E܏}<녞B#f$Fz,QuQ9b9fc<Ik<ٯN~{`M=== b/7%b8vTE詳?٩Ik1ni;B܈H;QHr:haFҧ)F8}kߐTЎbI-Kqi# XfGˋQox ƣ(Ӏ낪64qV;JbQv_zfl& szS@~\W/P(zdU\`z {2Bs})ؕ}?VWJ5T -45M =|^RyUS uǼ >P? 62Fr:dcN]Nv\mg#Y\jg3<z@1TF}!8;(u&@P[|Z 1%pNNGhvcRvȶnfjb ӪM^|‚~r Om~2Q0,Jy26C@DGo&jb\:x5<nho<V bŠ֚l?vXQj&\\eLϭrI6(#x3ߺI7_.d)`|1[컦go!}m&HV.bŬDei{!m/-ˎ1Y0\3hu/΁{kH (k^=X +hROm8#XÑ`D_/BLr핞`uٚGFbHܚGE=C|m0BibDZxn3V,Ȕ]sk(GW#=nsSђ6d|ņ|~*pv: 48Q{W%wBYq(jYӳ:{jTЅ]ph$/X*]meܒ;UڪG. 7虠EҳxH,qdrƍ<6̨{t9M1tp!/0Zk jMs)ׅqZ  D v1xIiÃb-z(ťwD5=t?A?KPM{D% Bǿ{\UÖ>]jH=b7Upb pCs10xLpEhWsG:f]Oo3tsw]K`.afoz_l%>(dC'xQ?>jD짗kÃ{X֨WP;c?&ք|\\|أ ww7q<NAȿ_Ie%d; OlQdi.XIOy'.%JD:X. 9"7xIt4}KTu`O9iP{=et]"PA>%Ҝ.mpsAxMWh̋D2YEkUHLjuԃMqѤx *<<ܽ 3 .G6R%s9x8Iɿ*H: Y1b׫MCW)e}OzۓwΫ<ߚC'T1d8nL|eN[^Ip&S/dkϑ`IzIw6*FN *@bDIKSA:t; B^sL%˵8.Mަ/L!I ,X k{MŲcZt6n -W;iqdw'Mܿ$k9JˏFCÃfq U3)A%ӳMI*\Ot<}0fۈ)>)Lɲޭm f֫T~:YΔ :q:x7_W:Uo! Lե7 ߢX1] -~+8J[i+IdbY(z}I5< X ԬI; T9nUM_"OLN5&(ܗZNNҏ(0 <@7+܃Dg,?(Zrվt,¹ CG3?}W`7L"Uh y#PiT`=h-&! mms` xbl}fCl\_~wǐ#ϧO.n?"JV5eyF;4HMPU|~ '2"y+X)o#lFdP\gM2( f2)i3lC xGsK? P@!4Dt9fJ_?ID/Wӎ46#*T &E:y" G3 wVSd~/S~CMԍʁ I) 0pݑmIѣ7^ ¥] g 0ΉF^R=2/+uF [Kv"hK8:l;KnU6sn:v&w]Ħ{GR 딜 a`R?DMߑt#ch:I a0#Mt1 KU{uRQV/sBGdE_`@=n{O!eɏ0TGȂO:*Jʙ\`ddQM?.~Mb_5&H&#L>#XN$+?3wE-I"ŏm)N.G}"`肯~ioTQi@&F}4u7H(~s?ꗤ r=R`Kx$_4qPūbƲlfæNƲt`|×hrH1}B]fS,LTfGWQ;`O`m!ߐJ^E1@$*aٸ7QSg B$pGDOŠBPgZAM> im#n#uӜeFNӬ]Wah Z}Jed~0?>A"$eئ)AO)޽(@tr.۷2B1bkh(#Asli\}m|D+goſ(bQ죠L#IkbfjSEt(fwiO]3 >˃A; Nтfƴaw7 % ZGSuD0mV@f@Kxu[CUO)mVyĒ89U]GC6n]NgC iܩJSu~?k)(c{:=ZI |s$y/3).ׄX;?)tfхN R0/ID9F W:1K: *4u| Yʛcx `7|jpxA ^r%1%Ĵ5.P򷚳Rd~?  t3&RGRVK?i!Է1I"`=s6RFz. vr͎!ǹ@iѿ/-h ?lj@ bzҌՈbfFP&ȴ,2ke=O- $YLLlkq,LTI5dJ4!a\@#+mW#n4`)ԝ|@E&Cn5^x?]k}[n'ykFS~SaNynanKʧQ2~T0~k:S*b[]ʽEYI}"KR{oM.+(]Awz/O 3$N0`&.Q]1kž dKe̲[AE Tr\K.7jhio(k@N<7RX!y`E=>0^^[Ƣ,ĢbBxY2 S.)cnՐt. ny:`=ܩ|0G&oo_>\h$"MEv 3CDӶ.Ձ c;Ya r1idJԴζOa2p"w˫\>כ }HNB}^AfzضGxl(h8W t~%U-Y_]'EiPN 8<#E.FzX.§YH^ʷfВwZCu_&W8fYꔘqj96'5=\&8g{;?`6ɷEͨRB)oBH2 M#Ǻםg$T!"Qd&Xcs11?.سڒ6cH!kRc,0Q$v8ζrx(_Ǖd RZ>+-do(Τ B6cv:""ZG(n f]FZ+L^yM)V}Qt4M.A\n?9v& <I@LZA 6a2@"ݿnR(J ^%RWRKfҹ%v_$2'z*>(@+_m#ʊ3 룙o8{MdMaT0gx.2nzw: ,]VUªC%a=ϊEIl,DxA.U̟m|'.kxݲ&X80M:$p+2õ??m`ԃuQ'y9U5C+]zpK`ũ㜨<ݥ9=|1jB0bAHjH"5VIϼDMݺ!Wݣ1lրSL&̑ NRE9 OwߤHE<ǫ;?h d@p0'3E9 0W)ԧ {޳pk!j=5=Yu-p,*,NN!GY}-e|krG1|։C:,ĴTc=LG`d܄ Go3 `z1-OQ;ܝ&C[+DD6:JU=AN7"iXWr; jn U[ٰ}`+3iz6tFŒ7I~VWf)gz5<#T\48L__C)isrB/y64'WnHvekON"] jQV^ݢXu UA @ ڶ11rꭌVZoG#; \F*7b&!:ŕ*~N2M|Nu̖$侩ۓ|W \t[dh4B|#@X%E0Mޥv=:L@?}nkUW rlzV7#ۜ5SSD}g=7 p z(PFx8n,1!J9IN\9`qmCWgk <}2_M;J([@Zmmi=+x}\ :ɋ>VRș1Z;J (=FfW>] h0+c96R_zYuНFRakExrzE OY^|bqHCB~X|$#j -Bnz݂An_z[jʦ7UwL2;?.i-?eK(J CKwѦ3`Zn5U`ɼfǁ?L ^ yJdƊQˀ\p 1p_%Bߎ#s@= 8D#,"tcoc'[+71 Pr;5`oa*IRgЫH@NL+r8xC{ @sj%HF z:h/=" S!DlZM0yeš ?AhEm}SmFKL'-sa>ZJPTgNi}cG9}C"q팍grs.yJ3jaGkz| ۖ K7ƴCŐH1^Nm@Sc`*iu"riu, M; .3BL}q~IgH"5v,tS/Y7Eӻj-X2~:*7z!Iܗf`ec{S­L_Uͭ,Ő.vƧu?F 9 d/0ޓ`ݒ5|$Cq/_VCg, NCw)$b"ꉏ"W`_\TWZ@(JHPTQ frrI_|FQ>|j-{_rl\N7!Cʐ?0D(a i5 C4ӧ{\rS.e([8wܙ7ԑ6T7(%chiPPy?)E"۟8:]_ Xӡ8Ы\:.+G@*8oн[WKvw+-n Cn5/k)e]B)^-K@Xx1+\`!lQXdM/F>|_8$o=ɳU88jnƍޥGފBI>?tJeЭgV1׹)Njg7u\$\K-zC 7P iv][ԭ:3)pA&=)\yZnZO ӟg/iioteQXh.tA5vxvS:1U=AnМ9G5b;LL9IXAN D筥I]ª6&B}TEZd=^kfjEƱUtC$ eo mJrT k77.ChwUKܐqR;-V# :t)eC`hRԠQtԜ$J*q]{wBm<GJ Rd=ټ4AAgn(nE:K vˠ; NхJ]8۩?~jދH;@1kDZqkc?>֓XP%mޣɃfwKmVN93"F!Zihpd~i'^8[RqFhNv l镉K H*Fߺlt+o'>Wˌz!E |bcɭ>Gk‡fGepyS[c3K&ى(^`_EiݠE2hzI*j22LC*-|/꫄ =q)=non}= K5O? :L~P:tx[]4MRҚv rxޱr:dG5"9%&mN/Š)l 誚~E# mq 7[p4H:7?7fVmuvWemd0=āL~N+nhԀJ^y2 ]4S)u4X=AٞWHd0vKR9n5͍ <ys7I]0?jNVOkڎ?ؑ ^̱?'ppEv* V+tܼP{ 4+]-{mJ貞')gWje;V42ZvܔSYNݱl1q-.DOS?kT"\8˴y~jO7Li]Ͳ2 ܖ7PCH< r~4ȃeրn+AEjY$彂&c[!I3[u#&Y^ӄl` ee‚ fbS")}0fHwZƵ힁:{Kt"> RٱO&%)ć{\oچ*)RYXxjÅ{ؾ_݆NӔcG?OTNZ 2D7(^k%,&_m~]vrީe7l_Nu~ r+O`7r*X%9iY2' 5r˛*2$3:h_{L2vNBh!;N#r3i3,_w,|V[dL0'͊tc s [iQNJ)SK+vKĊu'ˉHIe ]TGqvZ!p(?G^FylB1e?!WD㰸͐툉z32e_7ng ,^jPu0ri3^X #AVӖn{ϙ? jEAgr#'#mV"9B%H&v9i؇x{EI&)I`NYOפ\Ca' d}as#vNPC=;}Ͻ(7gð?7tQ:2"y?w<#*UJ eEASKM-韯/0W%:&j9[o>d#Sՠ 8-Q=F + e=4F?W֪g0֦0=tR*'3KxJ%~7X<ֻ9 ʎ BeC~v .?3C2c.Kk@v*$XZ;TB|~~%qN>IO=YpFGb-É[ډkE\fu#{?e]|u|n%X] 0ۏnbޝu?yݷ˒uXcr ߃{cANT߯a(>zPdX`E!F\X2<΀", 2nv5-'ԼÉ:[}k+ߍ !))|xwF{- QsEcw2W.L>?O삣"M=9N75*~(*oۮ0X͚rR,-nwƘ Ot8a7'Kh5/" Udù/ k1X=sZFj8MYc 4yBb[QDS4{ U!6)"{'#KkhiQJ=UѩWxԼfnilg/T5ə]aȣ BW*##7"ںq{vI8>gT#䔉4mu)G ~v7Dw4ZQ!+\ ,b !Xq(zWwJNT&j~?|;PťtZxҬ9&,JiUUxZzR̞mkO@[cp& -2Lf|۱8s[O$]N[ dD : vs5{t}z'&J|,NOJtkv I#,-HKθFa:.daOs\gX)YT\9Hr,( ިu Th9''\ieg ZVY6_K0n}o);vȎ{3܌/y жސ^".QLEwzR| OG|;U@7cBd pwop3ONu ex}~_ nU>>? 4?o5"Tt+*zj45Y_@2s#xV@v¦s.R}z3Dxs2.w~0z5˛hrvZ@H zAfʤSH1*BೊݮT0^~h/6+["Sy)|LU#>Qd͊%pc00d bd#`f㶦 S]jU([ji9 +"!e/%'#P I_~LZ#my5ZߩNhITW Ǣ+1ĉc13{;pbvB~0H չlh1QI,!7kİ@.b\)B@&'K)qA6>_Mg%,VU| Ac68,) g,{<^Yl~)K!{W?%yFVSJfՎIܝ]ʮG Dy|M9A<"j+ y10sBÂaLA(y2IŅQ+MlƣpAc/(73p"An,Q@93Q_dP&}'!5}]<k[ٸLXYgMD@)!pm6c[xVWx9k3W* ?E[CpӰ_Ej4\$WK%V\Jg2=Djvϳc\OI&Wv'S( "Z0tw tt(:uK!-#=^8u$`0Pg|u0[KLLGjH i٘:&B!B(Ya_{cŦou/}֢:D >X)b ˻P)O_"7-M>le1ؚޮ`V#Ӊj1tY` jJ}.v6:єjq5kA)pUwm 1"Muw W*;8r͝|n iqD%kB0K:34H1ċ2mXWz7ϦOl_]bvp7)n&-%JIFMS<|?ojGB ykKVeU):Q\oD2H(`:)+n╉v2\%9rt:ꫀ.Kh53?Ly!™k0@G9!qӷCBUkNklߧTpz CC$ X5 %"Hbe?s0LӢegAb=r90%3hq^4@j.xL1cD+/ͬ.0Ize'l\셪L_υ< G_F!^:dȭ[~=qr|f 'c'HaHALE?*GVQ[~_ڡo&?@Ϟi*[) ,5=z7JC"qE u>b1\ 55xFzwJCH*X.VR` PY>2jq[slͣ( ^?, 5r.qz-Op5 l$vFfGIi,mM&Rrd3abo D_'I,7{IH/RaS;52# _:^b<ž$"鋱>爵r\I"@K#̋nG %\MG۪1JnsWzkY=ƴT GnP(g2t++>LMJ3֘)X2L&}ے 5wM(+s3Bn+r-Et/X~c_Ih.1:WaRQF4՚6H{RT2WZ>de? 2?p h?Hu z 2/dvC"Y!xe˘`ϯ`!Y5^V>--ԡ>*fՇS_>i+llo+!^55ҏ=7T\\~n3p& U3[^]lb4ʖ uϐ*ބ5arZh_fj/>=t%;쨒!§ yy[6''vd_`2ؑ{_3t5SCaΠwQ c*J5 k^)^̙߰2Vkl|C,yzf)]:wtNAh\:T[jJY0Iv&,"a6ikN-̳@gz(η< ؏X-ijLovNJrhJL\(I\"o&chKuf3w`O#\Ś~ sQ_리#xJ7[ï텣F'3Kأ7^AYت(J-uJ>sEvF2|\c~_ہǸ%\=lhfb[`v z?1X"3Ό fF^ٔ2= %j/+}7`,mH$j,~L2O]Reب]MXzޥp=ו `Xq,\ SVY}6[Qz?'|,TVNoQw|\Nla%=JRF1C6!,*LOӎjFG_.)ǁqW?1f9 .}Tm|eKbi)HVyQ%JKeiߛI:2r.0F3_\)p:oIjvjpTFܯFW\fv02}c$ghXqߓ>ꔺ]Pi Nq>~cH[@g_w>Xe&[Kc&Q;VeF[ fdH=LIsUhiO<#|=,[SfxL5إP4H ;2&8 _kXdڵ+iƶq$vQؖT{~>GoJ[vvUuwCٚ f3' Dѿ9c?3#%Yء; "s/mMaTrDL.,k} fCasa}WN 1!RU kVw뽦Dc mB XQ֑a[Ο)U_'?;O9I QW4p6`Bdб"KN(W!vGa:!m䀑愧&&ްW:%( hؗBJx7_cFs hD-qy)=B#V:]YU^jHl{x˷@1sU71Dё[ _N.%e+ Gm("T՚D~+6HK͢+|PBXAY dۦ{dJ}K)P ͅ Qk؅3us 'įnEo,{j󝭱yIaur|JB z2JJ VR>$ҹH &ynSͫGAB<=wp;b:*ҹHuB ~AǭCFpf{`QZLis}UAY KuKiCѠ2M7QmNo꡶9F@6R'piFB&0 MY+,ZG,34sZ >~WBTAO 7:% iWo+lV@nZQ*S+%HY 0}1"LO (G?$DQ? x,> o|?Gۿ/{>@V~q] yE,) S#E_cRyoujrNL8Hckγ Q)pVG ֪^V $m59;S jK2f?xaA'~zM1->X bRk&wƋ+]8/Ymˡ9X6{NawZ~XH6ЫyxWL,X "h'Rz;I}?3=Dۿ]þ7m *QvP|bUݡv1NPxP[鬬)ό"|_Bj2Toxm퐷{wgwȷńR%/Ϩ:ѻmx$! 7m𳖉,wM'""]B*F]sE:~y EDenxZ?t@[jxNVtWqkWV 4,`8ZٜDӘ2^= xv>u筱>-|oT^P0a:t*nhuq ^}|YXRPwgU8yu& R~.dB"̨W35u};_Z H4XݿK;0^t_Ax3zL$oy3بNedn6v=ܨAlS}&mhRe5 ? Ӓi4&O_f).X6"}P5+hV0L,W̊7*aD`2 )Lm8vpR߰7.S9e{/q1%$OjFT㾖] @U5,Aysf6ӠQ.B'}1n pi;ƫ%#wQR]E!SARyu5'Lwn޷DUS֛x2I)]g!m&ƼZmhGPb\38w-w*?+,?Uo >הⳝ*~E0ETVܥhN3 NrQ'-k%9'3*V;ˉt{XUE NȄhڵ]E=l61ƞi7]<^Ń<;yt9x@5tjlG?+baG_-ؠh+d9}M=~z`.Wv^/]r0W5U1+΢9pE9uW[hfA73ZBdХ9>|$sXaѓEȎ.H/;sJW-sYp) G=VpEi,2INYJnq-fadwG3h^ 6`E'H2X:aY6Ph1/cPf-ӯ4=ݲ ;KW._µ~?X)oV% օXi\uNzt~G ĵo`'tJ><兄S9ܰZAb (f sTn!_bX<ύH@H:WF ^/ 3[ê+NbWi#h K_ .O- }IXp@Þ/ /SRK>Xu`ztw WdZ<`_Ya>T>4^->ש!Q)8+]6`s&ouM|/wJ9ؑ mx$ƛ䅨}d^+:D~ V'Ƕx!;'(V9F$ P>Т)D*Eb:j\x14 ogV>X K]Bfл.D}^P.AhUrjeZ 3. #pH>bCX;bg)9YG8)-A(Lz5o )w74k'7ş (hccB@RPWp$A^,PTJ ]:/O[<y.#T>H"Kߙ{ruG儥9swPdZY_Nk"(2 lTd!:iaMsRp vqHcoc .NLd Q!wE)3SsSb718؄}2utРde=-DV_3PW|D4>2873/] IhjTź!Fώ#%z-%"R"rj]į1yr@6+PúX~ XOjZ}}6yVsuiZ222#\[+UHp3RJ%/禈*?&.Jgf ^1%_rI5$sζֻ fwoCy]3*B`PlͦR$qփsYhkU#͉هΐ{ Mĝ Ccy^V mXQ"]zMya%R Z\Q#7. XM]e|XjBeܔKtq1W,2]XeSе<^P2ߪGHWd؏;SӸbS+XS9ܹOŵ6JUyk {lI6/t?לɫ+?'J[hQF`ɃW!Yl .b2]=j*kEdcȫk0LC)l(,3Rc`9l{T+R#,Zk>[X#*o5}3SHoA}m0$琄b_#@IʌH0 =r5{YFyͅ? 1m9)5#8tҸ&Yd!<:adc,3߮ڪ;9txaN s*9}@յe½?"aj0(@:)Í In|ay:}opqSJX+. xL@ /u"(*pSlHƟflhKT&υ:}+#t&/zwp'u(䧑; dG4c/='F}) CK+'Hl1K ū&9% -qѨ/Ryɼ 75`ދP[ƣ lahפbʹS Tvo0-Nu,x #Ho>Xm1vc.--4}n#6Zz!b## CWPcTWܩA߭ן$GJ4#؀O[_N0MrUh7Czs-2YKݽ0>(QV( Ha"ISyf͎oBwK*}si}6.H)(#-j}@_:vAĆd,n5LLv^mAiA&BCvޅFK9G`nV8Ӄ[1twpo^Oe U\~> ʼn6I$-K3yzF1NUV=PRr08gALXJ!@`ta}3V8L^ EU(`Vz>;W!էz-.MUDS -#3Tq5z#nI16 E~QT6ڎN#6c3H}P8߿~LS;}b\pФbA.+$Qy{d,mEb{BMj29J(+ɞKX'yVWDkzʄ Cb*Ij W*c}0= =̀7Y9旕 qIUKYY,p&f_m)fP\\hÊchZ;櫑< 1s''o0׌,L)aWV^Czj5S`Z\(r.-3/4L3Za}UǕ{~b@b37msP1Ģ控-$5bClNh黴Bod2Gڃ B0B.)?B0gnk7*5c0u0u":؟, 4)+](GG4v|pLń).륭/Kvk5$;H)&̽1 I]B!6R`*k3 J?0>X>j Iհ!Xrۥ:ȳcr&rѲ=,OZ7\L f(sYPr0} E]cҠ Blf`c T?GWZCRx *&!_OS@)RnI"^R47-[. LwY;כ.1F$8N}̡SFؐYVDE~DD; _FI#8g~*zf1 hA30ϵs.Vϔc$]Z $KY_;@/΃K n85le`""/\SW#3hX;.ڿ\ \,POqعDʮK``EN/,W[I5|SAR hTqVۆ)CVm96pUlO6_DK;(0&8..@WGy2n2}qc#2My>! 9m|5"Ce]P[O??Elܤs&x ޕո>ä€0ܖI>9\y2烱] wJ3mdbG/"1 61/ sǃRHaGJ5 xGZx0ԁNuWZvY&kĚ!粬[Gn ڊ̺Q\0~&Xyr0 'ܘɖ2cl)x0ڰ0IPu]r5Đl]l6GY_1&&!/)jrfeZ)T:2SBBG0;nKl G̮j+J iߪBGM[cAX #ȤܑZyu',h 4餀\?'nOX:Cm!Od"9n]v1q<9/GsotTCPX$)|{nHm\6[[w^)}p)UGot3 &~ÆK_2j=᱾ n}9%/. WAOUg!i=7t<P5sm1v(7;T-pV5Ke04S[1o/ |jyw h $>X$06mPE:3+\4ek@H1?ԒL?Wz̭Cf-X yY6'Ro];(*ғn$P>[,%ܴbp:Z"X#IyL%T͗!o%c X2q$WBχåED(OaHaG"M_6˖l h IP˲=#t6z1= Z@8iqG#:f{N7{g}t~) -%JՊ |-)~ ^/e[F3'nEP99f9DGJkWmHTqJIL7w%v47y,_O߆^b&R2[1hJg-{2ëU[ x4 uzo[_\ީɅ/m^b @!qJ[ӢDf*ǯWn̢ܨ0cQ^#5\?6`] PYVkipC8pr/rCc+qޱZšTnq$yߓ:#|X(8~t]}4GEJjY &cOU$@ztR2e^"a=sЅ)SqLI;DP$ z]mHXɒ5'Pl.2nۖUG(Ƅv _6E0\ُ:ZSȠv bT\%ܟ0E[x벓cq]du][ .@7~ 6Tۑ?HɀW]NG@sa5(G"i1VyN);D蕶~H qPf ?;1{1iR}( &}5Fi8=Fh⩦v ^9FĬ+!SEX# XCMI\-CcU^$@7<$ 'ݫ{{ٱ#3bn Λ&ƓP3pDw!yh6aLa9a*3Ch3/ hУ /owEdA`W66)~ " ܛIQ;E7.P6@n#)_ip8Е]Lw4>)(<=d ;gQ%>OЙe?/b! h%zj0<gGܑ+e G<؇O8zv(Ȇm(8v`0M_%V`5 :SUSfu削~2V幋  mKDD̙n/yH)Zn`J%7,g$_9pхrۛPk/$'zD&]=Y󷢣D*@/yE-ApN!  rj PrBAk0F(h 䒮-|h+!*u)R/g2\+ !^X 9C T0 rZUKw`B[;Gaٶދ\F_ي'̨|r"zSoXfryWWltM_+ZavՏ+Ӎ JǂjTI,M LAmP.BNct9щeyg|s BEݟYoOEL=Hrq֊P kԪ? z(tQՖsXo'P`n2jHAoDQj-crE.#3Qü<ضWHp_5?20l&#}A@0o5?_tyϗV7JA.wȲ# ӫ m5]jZJo JXЃq5vEc]v!M$qQ-P0!Gm,A.>'/ǎ%/Sϊ_'ga=~2TN{D~ aCIs7ڍ /[YGW}nwVB ջ|r9vm=]Iw8 ߐAc5s{A,W`޿yui:lut6d311J caB,.+-/]]/,CDtAQ<~'+ gkALeKDIK,K1;nͧӯ9˻U9Pn!ِ؏R)FcDubY{9#6c/L 9x[f?<+_mo`MȄyRi^o3"g1WF0T>јeQ|r]J]Ҕ&pPM/@6zADFE %yRcTFEZL;|]&D]>|`Ƭ=/Em f)=gJ+K"X#SLmfe_='q^1}]A!b8 ;"R .Y((idc.@wo`,gªD\cuR?"S͈%M?>9uRјFZ|6"JZ!q4 SҨ}YIځz)[(VKo=]=V6JxˡB/PM F TF"vGDZmwJOi{>/ć 59Sg)Or]+bc@ P4OcKH;RnF${KuU1Y&ex@ se[skqg6az MS?3@95XT[nȰ>ÃE =CM_OPe]i@j}o #"'mDBݒ^u9@1PЄe`pEd&O `"s{I1ɲF.-7A6c B0BNXrWYh͛-'οƃd}a,)"6 bSʌL vq>Q2KC& ڭj92|R: pH.waeve4'G Y'x54C[ήW姳hFW&hz\o 'x AZ/&Psbc I6'T;|َ[ |IZɋI#.:Nٞquz&^3W'뚖?YovDGk۶yBfZHc1 p(HDTLp5GvM%̼agŃCj?RJ~aB乢H[UFƇ#}j47VxIfTeԪfr%*b2h,]S"We3c"V>Xq.#判YAhxkTEX(\..R/޵*S-17O xwAUE˓&ҧC ߦh1,C @y: ~Ym)>zQ٫šCgы_<0Kuk?K>uA%;g~@tUd0 *SE'ӯIyZ8 ?HqAژ(5ْ*xzk&{NU>D;o(u[#*)G"f>|sN$ Ep-ĩ Q9`z+EW 9pݳS_No lԔ$)to8\R L )/k` />d=텙A"?c<>c@>nN)qvE7d h)GRj_$2%~tHbLة"M䀣86"8,Fq<|Sc+Al{6zq/SuIkVO?Ȑ9ϲV8UI Ǭs"*1SG 'fouz{K8%-cm>s( :3YoXFL;hw7T|8,ʴuJtTL$jw6ëܯ&vؠYS]?} ޽k c`@.s1h,5 ϗƕh;9E[EW+] ׵̀#&{2.y4ڲg곖QW~p²p/*?dnnYfU[bsθb  xI"8kKᶡOzls3;ά7}jg cbĨ`r?0plv \,z̴5qnaC$T\EL62u6ᝮK)$p-iĢۻ /jܢLL;C~ƕPit-&}X9E/A︴Q ύ`(R h^Xe'?_հy5/͕P`ZH1cjx*ѕ:p~=, Ed,n;% $uݎkxY3P>m`aS&i,;]SRmע=!cPe0p|D•4 'Vc~򺍤m%Zɧ"s;J?XBv+tRb@<_bLwxwN뮝NwE(\^_1~x87<#`Ժ)5}!׵Bjdn ܀.d)Lۘ n?̡0Z=W׺C9I=嫰 K:$)Ғ9/Mp7!GIo%Ib sՉnkd{b Fǩݵ#:fU-Sg{1c HShf>8RMUWm0nRHf KMwҡ,@&Rk,9rT[GAߧF8G, % A8ѧw1w%ݶZJ'^!7,?Čeŷۉ-Th)3GY8#{]n:/ ,:T+(cФ=p!y6$߽9pW0fg6Qw'i1>r DՇaGE azSZZ6J8UԶq&;j1[m P+fc))V pɒ9#1L vzt LkE ݡuy%rþ^=lA`F1]*vH @?FxQ'u_JBe15XfQwX-G-L [9,J_fF_濣-b۝"yT}>y5Hy|U2%I9)֍K2I ʰxQȳ֮ܰUI@C`S^YEm 9x*L/d MIX~IhGB];/WжN#_ʖ.m#"acdi07/թҍuw9sQl٤2{.8؊4ln$ J7}/|ߣ$de1[}X .ZuЫLK /uS8P\azE'oG3YPFN~0HV`!1Z7 8]ELF Uϥ 3u XZoƼv]?Id{PjmFJ-+rZۄ>TKB\4 ap|& ] g]HS=) 5ad㰝W 7z창:w1,\/%+ dC׈ _TJ+0@9.SWR]"]>Ge0P< :_E͸;ˀi7_735[bQK~JðܯPk/pyUg`qn{~q)eBг3El_j5lai@^AnMC9!Vh啕1ؽql}Y(z۹12ƓpOD=S KNrzCA&18mY GjStO8 2"pThٯG5a<0HWEc$۫tK$aQo*AhEtAd󫄨 㺄^Ш#՗&h(; G^/NU=+HZio,|ksEQ8֔Zプ޻ݗoˍ O^Q(73UTe BUQMU")&C (#hXMlUҰ%`zgބOwVh+1Ě s>2ϛ!kvFPZPmS$r_hyHCzR/[Kq/f:8*uUnTȞOKpGrCI=3e 2u|%|(|rTia̐7+*oXe?'xu0oj!9u5ppn1 )Hf)"jAǮ(^: ~`llT0ăߟ2zY`S zעL3՝ihkw&/7?/QLyxLbd7;, &5vvRiEA@ ] SԂ:+ nPIԀ|uLV(M n6 Rnh,3 Yx/E~ݕ]oy&7^wnbgeDFՂPuv+n9JCbJdMv'Le744rjfC$V.ݠv 0VH_,46Sv^.7ʋK:)hy*^;!|%RPeyj(=c(fBĔ"<8WAwJ - ʹt,oٲ=o-I%l(9QRZln84<{=cj$`fIm3NBxXJ8,D:ڦl>$utn;K ϶d)vT*`=jw搜sgkg6{.ߣƠdc#v1$Rn<_|bTASǔskJefZ^UZ!K >BĔknq7pI`-]ij=@vd>R9z'V,Huziw!t3m9å!4P8e~W>HϦ)+^n!z%;yA[տ>=6x DrƉ1IL"VgzJy!N>2wط|zd03:#|4aߟO_ץn^*y%^+^q=$X FA\YC)#AC]&ݫZ}oWLN! g}n)ZS4#\QW 7w-|yu6I3_ ny1t;V8/y/u&aJyuF)-x*ZH{J؎vr˙sl]?YƬ9{$Zt=տiw.6ĈybuWl׸6$ [m3`8UtzUxH=4uj<a[d1?t6k rf"O܂FHtL$CWaHD'x$4PKYV Bl&.E$ӎ0x@HwRWD&nU=ݑ*]ݘ(~3\4 0Dص֋2 V S]ꪒUs?w6*>9hl"xmE,!d^\*ZK+GԂ$AN٤k3:Qe 8 N2),h>m򂺗(i u; ,22#dZ'Ne+D?93 =G$Bz"8@?@[ٱ"a4ȢQJe?~Eg*③vDgi -kC]||6&w'Ҏ,&Ҹ^fŧFzOۇ5*WwjJԬZvF67!H%c[t I1DvRy);@Sk&3++tD [kԌ)LJx7QtkD HO[;].qG횢-[#r+5F9<$@9X,p14N1K5weAv^ք12q:,I.1$ HcyCTҧDFjU񂣟tWf1%D9(PyrEbbm`Q' ׍3bMo|,"ՒB|Q"C")/ŠCew;\Hx~˄]_-5fxuuG}+'W^!`VA,ؼU+ [hB&*IwlzNǝLrƏD2ݒt3BO551B j۷_N'@f ,p q5ԓ5HCqc3f5w<qB4kW\z>'ijFɸ^K &Z"}P:e'p r d59+ 9N4 00k&6euUQӈ2L,! ]0=^O]^ \S7堝 CCUd6%˦{] H϶ Lp&پ0`>WJ~1^6{eʅ3pT]h_Xfp龉S<ݝV [ap!HM5N^dq]zEYrLdIBG`{|&F()^- V98"`[mB֖ Jq_U1qQ/NSF9JoSٚh`ͶnW\$@O.`a8: kǿHIN-߽!^G҉ φWLwچ4U$-o,,pqBB a)הgY9a2M+rM E IGy*B5Cw5ŕF4r0CB.+|lgw;(p !IGo y"x ď,OjMJ~p {UZG E PQpX|/wa*X^Fv 3?XbۼIMnU3A-Ѧ8e{f5~l#MCB(vcO{9|^=@S,SUË[Vi=P!/I,*aC UQ mh ůb9DvczBhSFnYrg-R5|ۜy\ԗe?ӑ.\PPϗ3<#Hgp d ?PQPh%i P)Fx!~ݒ.lRTN|],Fs~,ӨNZ_ha@o Wrn΢O1w1XF=R.l u0$`%7)qRWɠ.)ϰ q )uK63o{^MiVN-1 EwPӅS{c3Eeyyv Ӭ~T4N R( "iIdvIxdr NYakË9X>=H=w8NF $;bZ oꈭ51Z]jLz($dg㠅\6Uڇ* dCi vژ vm)Wo_&z~E6"jX8#yS ze*؛&Jvdf44_kc*"c'+lE# N=x Nac#Z)/", IeNR@sj j|ߓ[Tܮ1h~2Tʼn;|𺑃tq S6Jz$®$Ijy,7, $,80%gOWE 'b&\* ^˕i!dp&?!ɮ_ Q%kx`.ox@4ƝV}a/ۋ/l̲hJuHMa :kvn+_XW)gHgg^C'v-JPkҖ'MNځqsG1f7;;Yxn'V2@;zg&[ ZlUoHc0:Aَ:ϕVXxW+&q84{nD3L>\PCD-du[&O2 &ҽm} lp+"{+.щfr$ 4d}B-1NWetk&VޮQJ9fWpф~J~3]1$|rs[O \m1P<),cqK涺X;O=O2͕_g-794`kH Pk\.uY|} yܞ&DZC.=ƿJ¼u?7)hَنВF<3)ꭖgFo(J1 HvQn ˶-}Jv>UjpREY[ l.9RzǁaD)vF !Q~2yZ4IYBs 8;o[7FZ׫Egd/okQqS@ݹ+lz >j>=W? M}yz?:h\'^%nim/D97)d{;د3󅊭@\ntF76^C؅Ɵzs„|4,\|P6.jS?f!E_2 aά':h0;Hj@!Й|uap_E7PN oG yן@NdF*ZW0nZ|t-0Xh T֦6pWSpC,c UY1iV@,|E?W*3s:H) gAQ75NB_ rz w"jKu$tUpK"tcd7pW2Z@g7`a&4Gfd٘_%)UsQ~_&0TLh$c2ڃ"e+0Y`'vb!n}]yFO 2s<ƒqv7 w$rvQC.jxV[jN Ӝwy06K lŖ,F\E45o>a=3XdBMJN~ ϋO@U5tc>@51@!# P%]h}㏄ռ g:i2cD>x+9b 3&uwh1uL4tLڵvrdOyqARh߭88*B+p+6̺c /<p^5],n<4Stb/X$X{kʺ0tcr }τG]Dbp(I"Y_Oxl1)ԥib|V$niOtYSݺiQ[^eUD#vyF޴ܙtt[1%Rif(rDufϿlP@֦`\ZI0;z_~`&GR|R~fϸy589OK&--1gJ#dp:fGI5HS-g.(O`vrys G@_ 0C&ɐ)oIDV_B%@$Ļ?SoB^F4ͣjؗrbz*GBr5&)+`9̓]7 ari*E8GR>3k]U1+SL @ aU[ȡ\`3tЫA"1sx/2Cő}{0Avbh=N9"48Y5bbWHsCƸܙ["ͯAt`N$1ϡLh R>2Ƒ$"bj^Hc)glC(%|5d,5bs?/1YtVԫoy Ix~Vڍ3Hel-ze!P7 xŜ|do) ܆RMs 7{ ij.ծuG mEϘ+-?N{JoY;rK(_\]|4!y>]$ٜNkBc@` |ث_c$g$U !SņsVwdT%*3=4n vi#ՂgQtwǣ_8ᠭFw1!WkӜΧ#ZԭQ-cd!-/̀5 u Dӥ|`RU"9 pw:%% i{GjJD{_$AS$2p 'פ9jjOzt] -^B˷] !G)U-PeqV.-,#wJw5JP2o/x?kR;$bp_yؒҿW8!e; ۸7 wV@ca'ۼm',Vv f(N"\b?4CF$1\p{oGd[͠6ųdؖfZQGZK lmot)o'"ѹW\-ȗh D$l5̩+'Q6 jcW;Г"R˒ s<3aIpzFE׬G `ۍ .byz<0'Ɉs-j+Ć?Ϧ9-ݧ`FE/ 59*SeǑbl4vF[C '0hGߓCÄ)A3!W:( JAPr1(yEC+\O}ܽ{gmo^U n-'2?zE93 CSx;{=es'޴gAQۑ[<Еp|[X"ȴPw3SsFMeMf8ZS_)ث^xzya c˭;:#hB m'w#DnE DG{t̒p}9wb7PJ_3W:EjiMГLvMNj% D)>ѕ5 ZD٢ahHRIro:삧#)<RFtnﹷS@K(UT2gŒeXz3coeATJ$8T~3֙5QOY^ K  M7{7aV[Q}a'Z4Id[/ q\OZ˳#J|z -e.lIB6,OaC-5\pi!4ۜpN{K$S1FBx)5Ѩ,EDǹ>:<HI4. 8o)8.졘Z%8hY|D0-eEpAꢴ[Un7WÇA_Xf_}f՚h쀊 Ժ}OthfpgYnf| Ե\15S=(&͏-j4,^ZZ*D]Ajew[ǓXΓk rUKRHlgYj.VD嵸6^_栆s49 0rK`MХsr0?SjCs;_#`v> X6Idi4*Ų'}Eǯw0].Glk~fQ<#̃ٸvշ[UlЀc(eA}A<,~a~m\ӝV\\,)kPq+k~Q3ysy !!7[)Wͪ뻮|<J1( -wB)rDW_Ѡ-SA 8ܺkd.|}%G'RT o_ëG?,T JC)%>5{F%^˫]Ui %|.&A NteohdNdʄXXCn=ho[l=U ؅ėrT"7 =opXa@'oЫ.V9Lګ'Xh_QDE4eCB^EP @nMu%`,!Ck#*)4(zl/ kx 걊4dO5^ " kgd1ǎ荝s)_0@ixF&pw4[Y~l/Jj v'kPTۨoKXP7gsÄD:6q{qS P&<D|%`TvǙ]*˭\LѕBPsk^*NG RB]ȍ;Jd_k4 }bZXXƤr1ɅݙUV[A #gi\$4?TB|傋/QMT:lƢVJI1H|V+02bؒx.T"ԅ7n Qhwɰ߇qX.3M~ܮm >,"A-b!ytt؇0++NJ,3tg _/X~s!Mi]x<"|^<{َh_z sacSzz!ÄYZ3Ӌש#E!َIwe2q'n2$?9dҽHr:4a_AMZ%ϡh{B8Hg=̻?*CV^j_D$!u)<1BI*F%){`4 4wa$"s@)e\ 9W_@t}R!HQ\*Nao\iE4Qw^E"ML_{K.b.BO\"#FOytxم_|q0ro 'n497#J=(9+PZ NbD   DA^s@]hlS%ǟFM::pڍn0Tْ)۰#}MJop]@-YV7xR+^l+Xul]RK˂ _ :l%}Ihx#);j̸`Xs/8ps'zڇMi&oN-ɜb ȑ3F9.| {hGdx1xVN^A(] Í w:XsA>r}{\h`~,{?h&rNV=ّ*GO#>LD4%J/5&X7 pi#U]*ixw9B]`y}%"3+gvWr_ l"sӰtk]?2a иQ%+}~MFԋfKs徦k Ϋb׷\|G8 q߯dgن@ CJ/!O4+PQ얅%=tu .W_sGe&?lTB&7g T#iz02#Qx/?8#,^fg;^g_+u lWr`Nڛg&@?kZJ8^я(4MεK8dc":Qdw ~EGC oɍ WH˳QnuTֆ(>p~j;'R\h$W)?+ܒQmw4UCV=gڍ{ =1O\#kS-Fj#)f2l84f 1U2f[}e`PixPo?alŜ|7fJptlmֶ22pI?#~ZInLew7H { ` > E+π:*|oaԮupFbSMpu×D$ѥ}˔T-oseCn@G,O^QiPe52^]p(ZВq Loɧ~Xk֪S'Mbʪ9P|Hک SdCOM'lu;\W2ÈR,}}?n;2zll. WI&CVYoqʬME_0I+O<KC08zĬ=[Wяp%'Xq8荮tF04 4`d5,V|šp&4jE tXux7ߥBWw[(X)򜆳8l74ֶ(Z/4v`ة0JDMW\qֹ5H.ib_`f 9B򧌖@p(™S(czVD ZFO-BquCD[zM-ʈ amRHt[G$ 䥰ce})mt^53<) }iz,(jLs4DH!.]\byjwx!=C4p^ܰ )O 4whT%B6a`|Tz1{OļO(9y6=**f~o/i(ce |c Xef(E~Xnk a6AsR=o?~h|q˽=Tuv'ʺo>!z__4EehqJY<6|ڊ*bjusY|};峡,'v:{mD~78ʂf}0#cFn7;s]/ő+kQNG%! ˀ$Z'tB6)aJ~͕C7;A #rG]yjy4&ח&\׋Po*`siԭ/3/<4^ʶ'sڨ$iK] G8iuX0qi:榾I"M- 2PgA_oZi,l3M=*Nۨ!z4yqX-)K(%yZ 6Wc"<+ZwlN욪,Xc40]И^NC6Io6}dTXvp!q -ScKX\Qцi8" G)g+4fsRƌ^cozLX5"YsKvHy_t.?Ap1*0cH)9Ȃt/@F8!vSo"%rīq5}0dTK=[V2Rޭͺ=!@@15q1tqվri70JU 5G : 1`>1dDlն5=T֜gYڟYX]PLj˱W +*6N[J1eUo@w'Ց(GeYmV%pO~zKhIFWIOȠXi`W^ lۿ)DrDtZ;-F65/гpCXJEIT{H79]@=US%ӑ8Jk5޶guB\ZMNOtf:oXE][LԕN:2-;O;ˎ>ĚlP@qB$~5\bNG,:~vlyx ^!="BK%kހ]]1*p1_Q2+a' 剬29s`ڤ#)W'U0!K?xQ8D)`O~Cd)(Yj= }j FrqZwW@XL˖g3a]tZ ,}$qN|ޒ`$ v]3FVc&ˑ;Td>vbLb??eF.웉.mȝ20QȺ}$QqՉ6WE8Z;=/EAZE sxeTjAs?.Wr|o E%c燪j"`)Hi9ň\I{Z^Dxbcx{1C @8 G|hFڌS#Vi+p Wf&k?* N9i"p/ho)CFQǏsl'e?k(`viQH 16O/">ApzZXh;KC;7_Pj {ZiNL -.W_ȼ4CythZiv1l5XTB}?H֗[yIE: hYJ#ID568лLxF2bBTXFΫ-ղ}͖}P;z6sRl.u^8;Ujl%*Y~;!LOGTRbɻ[Kgrd6a-lVљ]V6ҝKj}\-dׁr7Pksk0x) '=mde vȔLR%cpY}Z ]J,λP$O~ZxmAwgm{2gdaOֹݒ)5lSi,J0 @Dg+ODSű&'*IUA0բ-'|m"8Ao?gVWʀXR$(ٚw,b~,Ldᨳ\jq]\mRENfW;U6r=|z{!X#@mFQˌ8v/GlzJk^C+ܢ#re!,s*dgG| {? $J<~e0sA+B5*-U˱R/s6Z1O\n$FT7M4TB֘BKx_ Y-hN/=od=[ w5_tFr7@\˚D3妦gn82'7E'#*in_ ]҇]Ge%yU+eIHwd%GZ4s֦9Z#}#zDѓt(P9/i9 s4onQ\N},0D-i\KsDOP|/XD/q թ0ś6ٴhA56EWI9ԑmZ6L!:ꌯ |0S_m<7 daJ* ?6(>wi&x"2OI^R@FfN] o+Mp䌔bSRF-ț zqJ^e5KGpW}ѓk:Ԙ#9su*3#\Ҧ\w)+:e6Kwy\zQ :%P% k%H;7J'ʰ yF) T ""/MZŚ2JtO:sV a4mBC%lPΈq_ ^ >,pN.^$FSLEL`Tp&JO.M Qޫxpv. 3Eu>$Gzh}ģunuD6¯e-E$ c2ŭ'Pb<Ըo@26wѪdsv=UZfKLJo:zQL@!EʖBG0О&*] @%+px` 4N'OC]-SY*Ѩ .< 0wYKI,c!3/b͞7IS\%/bS{ %Apr^jy!4{/эTvYSyNA%Y-(#-xLwQP{:_EVs =7pMS UQt{9%*'G#fs,^ C^(,g~BK.$.ξ!^pZRտ? t;8FEU.`]#Cy 0 /Bo#羗cl|/)Zmp&[@ 9֊v5M~,R*/{ٍP%~ dИSh^@>cX?q{0=~DɃ5e$K%xvxm*7}t!{s!_YkdIxr?|선O ui*l4m*[J" !߃?%DM5U'hSJ},/,KѱP7&P?eGi#hzjgfa]Ft'5::ZT 1!W&.IIRnIc]8=wY Ĭ8{:r@`a%qܼsI!@/ zvfFKG \BY̓{p>Haů4k7@كLxL PBtc;!P 9iMp(9mx)wqR5Ҫ T>DDzb %/ԬƵGSkc\` E<σ^~u@kvt7Mg {cЃ(>$͎Fv,ԡp(q'ݎ|0{q.@֠ۢ:Is_B@OL2XwZjbd5{Kch lҹS8[FqJo2 9sq; 57!KK*S<47a,}sVOzR"Q2 GeMdChqpu[=vZ+D@5.pu`K'Sbq 3[ywlJCFf)X9rByCٌ(iN'yed_=cϙA쌮pU8jwUw{V RYBC(`^(IxH]8%BxH $s8}\osCS:&vE~QO0>:o%ثv\Ӹmac1ι{i>Z."78Ixrw#1dQ&[xAV0 {*P! 3vFAK]ar\OB0@RϑӾMdv kta[#7 8P 4-'Ṳ̂(Gz*JCר F(mt@y h{uC3-òʳ*?hbC*:X=^!'aIRn˕F8Ss*=4}4MEً]ZF*'c$CkO1/j̠ԉM%4*r r.yf́Kӑ5_mFV9 sgy&FO1ZrD VL%D{@;\ܪ1^e{nhw2>l{wMm҇o-~ 7l`PzZ h7É[L.2P tOX-Z+\4$CEA+>yxTwFu9巙 h]P% f1󢣾2?ҕ܄*)5K\Vit7sP()j*c|{uc(̌i`\9!0y>9,qyTOB^?*R3 gљPKLտ62W/ʼn>M!瘵l=T$H!~\I<^LiUG`]"]:`9h@ז}rWBik];`#K$$w bTy٤C;IHP8a6CHt(5|j0dDR[ K*0Uϳ3LfTKAd>Nfju_H[)O긧uh@Ց_1Ehln /Y׾]h }P^@ZoB^;jyi/y\mߺS@Zsc} mPIx<[w_ta_J]VHm^pu/]%wZKBJF"0\Ǯf뮷&yߚi6=-[zɪY#spZcR:)x9TsiʸɗgM&=wqRiأΐg>d+&ThPA='tl,Xe wN98B(AV.28C-$QpC "~^k01@Mat2(pg@U}#VzMH}A940})SX/_!d0Rw'7Du/O{R^ߴ;,\8އ?!c٘޺:CfTpN9mfe:H")$sɡV@_3f%Og&ʥaBf&>~ICUUP/.J[ZxM_`ƫTqR| ~UU?hH|4lz8/! ڗܰv:k{ "[ kg8^٩@ (BM9&pM X ]mLL}ؓJw F ^pu8mx ՚u ޸908) W4*f[p0 !M7ìv{#cMc % n0*ŵڟ쯣<vE{&LXmPQY1V͢4k@^{S Ӭ$ʣC~-Na L=J)ьg-YQOZB@ǯ,Qsġ>=O } P?ŅH[gͲDBL SI5e+ͱZ+ V`HB$ua˖cA~^c aU_t4 64wF{^`8\-7At+F_ A =n{~H0&ԽE?"BGȑVhJl©v@MIGo*M0SACR}Z&RjmF/AҎ JӪbBg)W:R2& %[u:,55T9/ɬXcNj#1% 61 Ŗ\.LQ!iI~u&; zlV_*'FmǻGIEq^; yw߈? 3LoצL(6:@{ $kn:[&Z@Ȫg69F"VC_g%s;gsR?l )r. WeSD+_G1}.ggyZͼƙtِ+opuM{~{$ab-ɕ>M_Jf&\W8U VŻ[WPM6/+Cj@݈ί3SU|p~*oG.Tޥ&Qlkk-+5l.Ó/>pfXuլQz3npF' >Cyyw: ˱ Uc +Mo4x"݀O-zBqDs`rgU DJ~_13߈ZZ"= ?|NճxS,f"56RlV(("l:m' PC}KӳιFis"1R%]4y,yG` n.ʱkvI﵀q0n"XȚ 3 $2@̌(L&Cyʑ !z;`D|$96Jv \ R֐?Ml|ʗZ3:jOraZG_=@C(Y]4({m3МFY?[olҬƏƒeSאv\:>N[~GJMid Lj@$T =VZ4[;+=Pz=Mc(S&}l7st;|ur꧊ЧHdPN҆ @/o]_ k5Q19 8!&u6| ]4 f ɾVM%cL6 0y"T-Xeg9ծi & iM]*5chY,KuJK J68ǣcqڬ-!#$R|q4bk /$Vxr.>we58GXDW*g=*qxlz5`WMȹiWo5^{uuⵄЊo,HŖ\mKlultfJи75*u7|[ҵxʏ8qqꓴӯ.ґl=xW#jP5>6\$j@AVwގР1U@0oYo2q*ٴq^&sYзf"H:lg^sjPV%Wf()Ol+G=3xCN1M1QGٌg%Ts Vmت8F |']L2zRYתƾ6_i nLU&[;9E!Z[6R0;$sȘwWmtD}ÇjeQ{TWwMf E#/|q*BÔ&p0 ;]LU}'ڥ$;}~':D :kXV x1Zl&]#EQe Ll&~Tx>6X `$:\}[aX':o 2%7Mc#/ BW~Ae e\g$o?$Qd۱;3uFr)3ˤ5c"'M?I&1Ws6Eyϑcl)Nuwm|+y6!̢oG5\gK1Q5 E4/||d6imxOesOzF\.ٝmچ dH'""sK<.\~+Ɍq35?]ay!N9{6F?1Ce-벨[p_=@gu[YJVŽTIN.4_GF*ϝM9;h]Ac7\rT1”.ao`ȑo)iTmdO@?$t߾(x%i E):/|6!EЄ&8 s9r.4x4 dV4OV(-}- n-HF2Dd8Jsgqe:,p\ 1U'isCFYFbٺ%v4H!lkwq,R$|3 $l)xAcUf%glg]ր:_bdz/x]uΜGpM\_>T32K7 ѿv+UW3['vb1n'LRuI)ܣR3$!@.m:ZiPs SY ';:hrL!@YÃ"F0 2ӔYY. 6 ,F$5ځEKa1M?))hݲW٧a5|T%{gH/An>Rm mLw湿w-C D\ݫ퍌tj-kj+P߿"4$6^Aa׫k񩾷  fycrBlw3>x! *9ǏEV{R*~0Ԯ*. 1^>]:Th[( K6VE!涟NW@170QV q+0FX{:Ar.`Bti%;bCo9N3szݬ>~VS4PrU&$f틴_zs-wdÃiZ"s|* ZƲ\ Vm_kN΄<'0!q au{fU3iK0Vt/|ž.}Da1{Rz{%6whHr_gmagRGPO`05Jya5u'ju(cnu9 $01l{o\<ѝGKzz` !6HHq&ҏ- 8FE!(^AU0W3 v` ?qoҧN,m"i{% tuH(Y乚הn;ݞcpS?zAc``FORS=ԫ+ad8_`>.h(gn w-!&ᑎ亓ևrq˨.ꘚdVtoY2MQ9$'EkěD)({E̖m^3qxO vLQvb[ bjp\ғ#\3NG0VLNQNkQmQ׆QMZ )ٖId k%UE ݶq{(B|Æp)J&ӫƮdbE/c!;z&|KNr<̌&K$g:_:愜URg¶IIml @S7[vl8X6sײַTZV2v6訦񥨜;!4."bi}/Vd?kY˥NPĕ౅i zeR-a<,alo_XP3ʐ0I0XD6z ϥEZFA 6`_dh8^;vh_j\ ^3P^+yf-\$ ~xIS2 RCi6h t6i‘'-f:,x:$J)a!Sv+ ÛX/Fn0.t-CۀV].TtW۾kRpe ӊDt"(SlBUR E`SC}qޮPjTo;ui hN%^R}ex hLy̶@T3Ӳ}[b&Y})S'跫e$!ug^nf/QsA0;,"i@)p.'9 c B!leC?3*<#Y7/]N7syIhM#LxAΦ$_΄c u ICYMKtӶשE+yߧP}@޶4sx᭰#|ט r[ Bį=3NCE@EI .X! }F;wc?H9x4'־UbVZR+ WEޓ>I5&VQ)Xbx0G$;(}]О->QWGBINҔ`# 2ݺp\2FJ.As\$nz|wɬꠣ!אUtPT[!*G|N҄=Rc\Yhܢۯ]M8v*%?c;j<! 1ulŐ7! (>k5'fL飞'u* Ue>M!f@X7±(zut8뀳IicnaL._Ϻ(3XRIVԯ ,lI켡[Es.>x[Jfy!IYQ)X}8H%I|Z9\ң֐dArP Je(g: yU$i;Ǟ|;C 6"# ǔ XciSKaf/mj?P'OcT7z{@ʋҁѐx<ك JS"+?MMSeg}&ܼ+ Ӣ??&Rn(QJ#X{2s Kc>F \0f?՚k^𐆴d \{ˎ ɮ ;B/LةZ!5sWMuLVv0xym|Bm_س QU٨VHM@JBxXĒ"l8%P^q+K7^rwrg P]'T:á9LG{񬖩V6]$*]gj|7wNAo:yuyvH@ /a\VL1 &bhm97 L4yK'-9J,/3Y^kڨвFNZDd"C\?EV9ț$Ec+ēvp#Ar/'%ش*x?2kvb[9j E[Er'Lefژ3@pqIv*l†3-VLx y .hSK1;U*P~!ZgkYfY~iȇ-av{CmT pA;^菠`I7q|Dr-QGo3`}\tIm" R[BAgFk އ.ލ婨1,]_6L/r0,Pj܆ܘY!k?VE@v?-va6W}EʥmكzQRd5T4cF.;'Z/ EvSRS/5=XAET[}#'9Fi# .2mw :ŮtĔV#5o.]Aԅ~w"L}N@aggK:퇚+9t$0u H^jGNQI)5<HC/ʒ+" JTBdc*`b? kO Ag0^0DZI3Qe] lQf0%X.Mr9cM6yY`z&"^8 9PtIia]:Pm ]dF̵'5`.(D8L5=.} i1RBLyu4ܐ (m$ Ft|>ψ`]"!ں[t琉r&5fwV>4R>Z×KՆ Iqc\557. R(K-8HȋyQd_F1!y Hdm)\&#Yt`y"l\KuXfη`y‹Tk'< ,Ckc;#ARuQl3&_&Bg/r|_*՟ҬZ刖t5]CpƭO[#Z.I)Կ{[{S .4Ha ēFrI>k_e3ܠ fHڨwu9΃9qvF<vdqfd3jsY=oꂳ,H RꑻDJpXjqL}X!1Ibsك ?7xu9. ;{8A+(L&DM|S Dia=^uNc"cě9 ҫ1ĝ(C|H2*םx)=#BToD y= GdKU },t<B&O;2zźqat21"EAy՝WfŨ'q+O _hoUo R>T5yt/xl_pVr5HzKu m$#<e{qYPdVYEw̍X[,ޕڳt hS{ ?ICXQr?o 摙Y*;ppqx \&cRc9iaCoIjl kn9z)p_in^hU# J 1/w XcNv9-]DR `?CWWn!UG5?Ko haOykwyk#Ytqﳑ8vf5kx0%No7HSੴ6:mpkbۥa=; p)"$-j݉4pO8dZn } F6o Z0Wwat(F+W dI+&)U,"{RYKS+;4]NSO)/R8?b Nub: kr(\2cd>i_ ;{!YY`Z5o.Si_dgJ,jxY\S= Зw}Ue'|܃uUXn*R=Em!|dЧAUAũ*kDg;&{ Amc!k[1io p0H^a֡R6whFh_.C7DHT+L Æ-a%r-3%Lsc=Gz)X?I`#$o&eފL[px>i+βjm>$PYS?x?h 9i#kG`ςŞ~۱l֮u?ZNy~)U*뮲ʻoIĜoDRNV<DbX;>|Wudƈn#2hRrvRYdzG{_hqLԏ_'%`e&2OJͮ6kiRޔZp_ёaC!Fe`RUܝ"HsNtYp& (sD$ pK_#O`1x[r! U?zTd$mmgE\ [uF%W/kMxڔ*ڙu#ZL涅Y$P2h|mj3qXh,=rZ@]ũB\j5 riʭunM#wOjpU NG"楒wz (Iy!F^ Cb!N 1WXWթ2ֳE-'\?n0QgzA 4$F򖬺9w"6W\>!<#x7c2n Y?X%ԹacVy|He3Řx}~hQ-ҺZ)nn4g¨Wq%=t<L oJg#xi.;PiEgqslwGSH1 "{?R#î美UDri! [*?2&'50XmM+wxH;$e3qo.KtGJ؎PN;. ALm9ii;Aix[ҺOJҼvewKJѕXs@PltθM= $߃QeǂW7Hh1V^n OmSZKLqSY߰꿃U(989c(lϚzD^ Lx-Cǂ?XAMchMv5H.ey=Ubw:j NZx<9g{cuVS"j+IN7#/H|,'*Ɋ!l -6ӆ(Z$ʻH~o_~81WAf"5l1&Bu35J icG֓ɥ& cp]Ca\-zKd,8\FGDBFyv Fw$ZZ IYT rbz_9E8A[['7s07޹JSO,[Py9lʋ(J'u1$VΗL /k0}=M 6Fؒt0Y/Y3"8\mJ(Y&Xޚ蚤+ecBR5SSa!Oto`Mv@@2xN'0CyǏ9ZxpG)pH S[[jRTUkM8Nv:K*OV^ԁ#O.: Qh*G eGn_6mx\O;TĊI@iU=|p.$R(W]ʘx'R7/^#0;g<{u _R?[+y[h8|7ld-}h,V){%jS*ÿ}9u7U=tİ–bD%UK!#^ʰ]58Vk'qs|mW_ll.;Gb6(c'5¯L`?墬NqA_%duMSLAt ((c,Sy~L{'|2PلP,gر, KCB,NsL G,d]؄tQ UWTXg[Q'*`< S ~N]>pNX&RC *ȍb9Ϛ|0%Ao CE2J F8DDM=MCf H=r@4'{K$v-hϩIdYONj̑Ɋ堿ve =?3txޡ>%E=z0o~R*/55qu|&X;-z5R벣IE&]o7Uhn(8G τyđy jK2 etoxcX5V(?FclPך(6b9H@8-񬁄Sf:5>+c^p ](pOiBs!Ktz% )LgVYWKI+4gb/,1C%O{3Oe{$OӵRy>fc=yHȉνqV}]. ݲY𮥃65?*ТZqja35 o0$t͍~#f$TrB,jw>v s}n; ;L!%E":4Q@][C'N'?ȋxJ3SV*VEld]S$+\7z zUDm <%Ut `c_cPզirЬjkٮl뭖3iK^$L|ek?[yy*Fzt*Ǎ59n^Uqq%EeFڜILCQcI'DiyƞΓ̠ vBλ:3I,ՉBjx®cQfA!qwT엱>uC(j#ecULA!>@@4,E2'U<LGSۘ on7gC yaO$3ִyo P 3 :bJEFƣAP:$so4^|*$ AS_$s|~=vФ oǩA_c7:N5w8 WM ,[+h=GҀ-W|D2ĶfU0; 6JV1B$bj엖^ZN9⑐QTgkci Pur"EI MiY8SNz'^Rs8FӔLzw(y;_!Y>i&t4ϊWZtf1"Z&z;=3)n0fVREEKb ; [;nO0\HS W}DkZeDshi3hvTצn@MɌ:vq~]7jQPZC2hJaPnqGB-ʠJ-w76oڛUo\6+ 6 ѻ֙)abXH˙!QTe@D)A#'8EN+\[ZA& 9mS" P%]UTF';!_:aĪFUoŒ4B76%,1P?e肐 "I@s*`rrONm}7Vhed'jk5(Hp@rjykcS*~G7ϸBS` L@}{4Ƿ.ƎD#kF]B"W7XG97 nŢHۏ9S>[h/,'9ub˜n*)AV^J]uĉ)xL(g7b(JZ&8kV Pi/k*Lu n|񘻩![8sVD#Y=Oj}mT^y-"[l]5g.źc"ܺ&hg)%I{ ) ݫCN>ԺN\q!huz"2U uC JXY._t+:i;eYtbqt*¶8 iI ~OlƵ2M3ܕ+Z1 <@AsAV3}s@!XJ좺#t2rFfjB">m EH-D=3Raӆ|D] 3zd̩c`S)hҕ8e g]&V۪p,D_p=SeLMӞ`9UD埫IMͽ+ l%^v7@F)ޣْjF|bee6ņ ˎl{ .u3\Cg,px{1|2-WBv]47N$A+:8.vBzhm\%j-A9im6|A59[Hc*qP/AP  qF0N piAYwDdgw48U1C[)GLTÏdj :ľ#8(& 6`(Թz%WWF?QbUAǹX/\ 1ĕP38TEEI(H<,ܗwa/7~ϣ[+siUň![kMfr9=0S ٤HVNsqW`M0Klrp9 G_,$jL+`;@*}}9 d@Tctn`>xV{)hiU.0 zf-(f&C~YHrR8:0:@Lu, XHx2?gp@++~, ޥWLkѲ3/Ghx!(P$B/L'̱@t8W M.SԏJ"C%`^{YMiz?*17 iB>[.uB0Z& T*4 {^:k@Fr`Ak^Coç/> 2k3*yz{rWA1x2FO6Lu-7:zC Up'yM%##r>dqvT!-x\h_M=$1ZKIF>\h/k =bU쵽Qw{Ϊ&YV]Iu&O0^d*#n>p[KMB0Ry<)`?1!B=TLn&]!ǁހ 6Z-opP,v*:-˰wc>z<1F ^gU^„aCrI-CE޿E5 X4XG?nvw 9ddiX]+כ9nۉ!S+v/92sͻU@x -K;Ep̰q6/YF灧ݞg؅`uअk7D]DZ3OM,- ~Mp7-9oѐk!7n ̥NQVqZYd'rS/(lJF?6dFaz U[6XEniԅ-`\Cd+r{T!Z23K #m!Fquudd%7lvØzk+T 8o` .'b=p1ou"GuADXަM}obwUiaтhGFt6 qtHWoR87_$ؖ^AK /jf'eɸc|=7m'`!(0=-ro770&<5<%f8PM$, })cm#v;ӎP"HR(,ՇrvA䗋|plI C"i4FJ,Lq,G%ZRXsVP*^{L|BŁI#==~ k&lUnAJJ4w7!VJ {hE_XUY xIvaU`"'bt+4uBf#6K=$n8ָ;0۝"ّM4ж)*`@xB)bu>ʱ>aO`S_*\y=jq R%G14/&RZO071Qj` MW1 1`8;DkO`M0p X\1?/h֊zF'nVH5Ma'J@-Q68dZ`~XYQ|dJvʹeu!o@`nak/_Z̆eseaJUxIθ"E|Cb _P\G˨-M=yZ]~ v(PtKe9.p34#-drj>7~[v %4}dvBZ˸BUs+ c@߭tew2=P?uEv61[ib=$NW;zDJGta~xOk20:țT/F. k,g`61bAW3[SSg*aw]P*+)RXAĻKG_4Hc}Lu63gZ8Ē zcʛrDY D!l>6Uي)7G$dweQ}9=4%Y<02MeJCh+gzpEx3 |:)ˎe0#Is~rC3}~|9.F-R)w^@Aj@RӮ%>#>lE=4n1G hZG4!ɞ /lr7|N{ 㖒ѥW2O`+csʷ DK2HOzw#ZV}񎱴l|:Vb !@-m M ~潲X&;Lp{ ΍81OB.+tLη!oQ{z<$ps,F&f5KI"E.L [Bma&Ct[\IpQΈy;zY/T}/Y>D]-ngY1?YYͦѺ@v !_t{D"'3K$8}x~`\?DVj;ИD[+Vҡ Uر=VrmI礰ZGYGlsѝ7wf!43b-6쉿w#w_<u%EܭMY]?'j(le +L0̅ު4gz$ҽ(Nw,UAAl[pxiVj{ 00^;’2ՑȜfvy}t"Uߥ٨8}@}1t |n˨Bd#s'cr@.U - Q(pAImeڷЈ E*RG`lG3j3l `(0gͬJ {}T&ぅngqJCY2ld0X!w٬4IwVՊI7ŁΣu &5foA8㿐>_4~Av1IGq(ѩh5dlueY tngkCN4ۀʡ˖K5XT:}z/v\|upG#VTjJ.jnWY"e?\HbMN_֓yϻf"rlp1Sj۵$-E쬛PGPOSYKE7wpO2fF[&f"\]9?h1qk}Edw ]NAˁڰ`+kE]W,*5&_ŹtЬ>M ,LyOIFLO>p'ɂa m:i(v6E aG c?9r;C*%~`Q);%!7`9~ Nx"ҎCxpϵv+\}f*Jwo^r]!АS9jÈF5Z+.2yAQwב|jGr!(`Pd`%M诸C+rUV=I 7蠚ܦ/ x }YԊdS̞%G` *m>BZx_2 ysQ=Ǵ/ݡd:fcOкP(RF܋;nˇ/pB}^D0`m|m rY1^wTԳCx8M!1:tehU&0dɏ[g7ew'ԥro2=,+첸=yC?EaS rwNmH`[<K|ę)'Z7 YJGc]׵O)v*5Qaއ>@ i "0DNHӁ G&":dNJf[Iq\oK$<@!>Żm ica^tR| ]S/l)ZΠ o黀@+JGEă(i  ^Խ巶ݵbJC;>2]:16^WJUݯ/TS=Z\y!T _P3d-sgDo[Ύhd76i,a6.+5.H{d($9"QP"{¨(vjz0v&NMaęJIXPP=mٔ̿C/2LIaZ`ryl[cb L~ ^8yCGp4&F]2;'"`+}m3/p@QF#VYT FZ2RdT4̜sSc}`>DqnO[Cp-;{j wNkنvB/Z6ٰeG?07( f2 ɕa>8"+F fJ2ц8ӒlSSu.yK w`%ͲeXWl34mqE:x FF{P|74^fP,nA8w@mQ!GM `םi/ʒB jpIcD7S9`fD\pӬ&QO+d,;L0%L$TYҦ8jš/{d_}p#!}Cs=Vi`˼POv^NpKq2H]fEKх|楂1||#_-\J@A8RHpB[`ZDI!S ut5Ri'to#Y܍7[sV)43m~j4Jxѿch8ǜ:< DWdѿmjک{z'ēIBa}c19( gTȊd V^%(zQc0)d^4?uq(?YZ^"o$&1OʒZa4XK:jd 0 &!Шӳ'[3b Y&)fQ,U |@'RP%(E`$fCZ% GJ4 Xp-JUv 'D;oCG##tU!)%Q -WrwdP5+a#$[n떟)q*Gel;ǏS?zemʪɉ 2fd)YSlVjW*VAiq+*) 1; 1F3qp)y/҆cČdS߭Ow` ?xP_5~&}B0b@6Pǧd.ydܤ:_B )@'"ESpE^iqn8rNNخ4&\#+> ~ux_v(B޲aXAHEKC)>bO4TBܒCYa(ϹΛܑUha`+RU5^tͣc'Afe9= ɐp_Qd>FςFj9C9pt1|_7}TldIAΏ`Y\.]ʴ ڵX?P)@ުҊ1"s=M &Q^W?cFnM_g^'~ps#Tc&9YQqķJ4xb5&A>0@o!9 6|lRy}XFZvp qt+&[WwHHl4M٘R Z 3'ţ4Oi\ܡD@!AuI 7{/:gl9elbqyp@PA7V]62ŋ{YqF~9VM00A (@{-W3m-vW^f LA伪$Jv*, tK0kNqwwsN'{žϋ+~M>:ZJ΋!y,;KJ.d&\W? 5`FOӯzvA5nvG {CWx6-BEBn9)?$o!,ګL&9^".Ћ sjTVu=WP!g(!j,RYBdL)+/䅸5lǰdey9tSRzYPWV!aةe9M}\5 ϣg-Ӻw̒o`骵%4dr:F2$뾙_ FY Gnk\msAC9$ƻ|1ԖKm0B@=K |V–nlUBo:sHs3c:s$&Eɨq,e0ZA^ch F邒XFɉoY49SDpJvxw,[?;Z,Qgjo1iټd=)Kw@fU@]w047^r|9vbh >|=pI2t͑ˎgYiKV!RnƠ:F$cp0v;B@! +z> nrj3 f$ :ӻjiQQv0oo."\wH׏O׾SR^KtdGB]BLTm)$:}j-ܲDgk?S.kNР:>"(8(<`E^Xۊ&f7 :ZpJ O `iG$:q8޺P pel 0RwPLlqp:_qa*SRZmם#p` KGo5;M7Z_8 -wϠX(j9Y]~tD6IQYsCEA?3؀f[+I1NL{ 0"'Xc<,aއ:`dYˮdO5;ipѝڅ PYvz)85Q2E#KV̙B-v-$@>w4}@\%]zfRSS  U4QWvW bp˧al*NmxZD4 C&J(9vL׀F]҇ ~p ?6MVW+!ɴ K&|cn߷bo8>9 ^3Mg9-w[00,=DKfAM3 3ފw//D~I˅4>R8T[u:+cUouY˝B$iS_Ĺ$,Tb0|"-bZ6R4'TΜ|1뼮Uj>"6k 9Deo^T-GF#풛 eFvX;2VҕY}G$ NM4^pUBWrWá,E}YXfnoLUHNBdWo v䎚8BV"<ӓ@_<}( 'ֳc^P(}Tq5Pd1${ҋ3Zdo@ְ!PSK6OZԳBKVr72(@I %w~~(/ )  .$30+ N*OZɰ-Οr(5U׌KS Odd Af蒥{Y'ɅS!c cW]%k}eĸ}]K) MFJFL>YȻshPЧz'SgWݡe -Txlr~̗|T-+*aT z%ԧ)1 zh{ixra[7g`3p3^jIݲ :op它瓪b_YnN</hJi2/f#8℩+ے=1iW={ )ua ӵ1+ߡrG#~T옥oftR\ަQ zuN\@a9/3v]޶ {b ҆Fgx43i. O= ł%qEe}9X^_0>7/q {$ᱦ#yBT盥yeYDV8+b X;&RL<4poNsF_o.+p A$M܇M |ş0Q}U[#pߠ~7BcV]*=>lR[,fUu/z8JlȻ z\GT 2qDjΟ]/}O@2 Mϋ 3[eI!bv~DyR!m6c_?f[Z)}[ku$K B~Er~{ 0^Gll1CUN,$7P&X_^Y&? j;%@S4mE̗% ^*w%$~OL#_oF=BI.t`de(9s5^2urlVi3zQCuPk.CpD=ٯ A=- xo6Y8ޫFI%LCK $K >e Z)K!ɧDo;-D>,6ٍ'?n'Zj8o3%zC0HTj~ϯƲ1 '+jLKIk/EN5 _lHū^97+j_ryRawdoӯ9\R_қr0K2_큷T1VK> KAFS4@.~{̘YLf8"*tLC1ݳsk#6֝Ybs>CJVMNb5yE&1.oXZ&+<,9! ]|bơ%2~ңb2xJzl×GBae_̮lpF'Ǝ`HQ#C-0}kL7iOprϡkq@oI(`_Pg+q>2ZQSV,E/{5uNΠ}/ yg'g>$ek|PzIKoP7:"%Dg,Ai3^:}ރ (s&MRgJ77RE՝ p0a*_ycoQ2m@DءC{Io D_ uwOAs}-^ڻŗu{#ڀBZ.صIh3W3+/Jlo3,tͯ >-|! 0ȑ y;Ed61޺G,S+\9gP9r*p%( EkMt %p~tl`/AtrdN9&P Z|?[ [=EX.D 3Ţ Q;2O9?+p8oѤ-Nx o {  uRd+_$2_)ms8{Xu0X|Ez ԕ%|t-q`J8nEf("BD(\{綂/J?H\l_R(Zg[R<\ky?lG-6ua'*,T5}5WbfE:qe&R}%(pY܃Slzrm6ūe+Z6 YTvge^{4&`[. `6ڔf^X2'2aQ@\I(וg0 J,):s+\٘S8trIL\ՁU]T}?VRhy ٰT/eE,ͮ{ I‹q@2Ɯ/NPAe>y\z\۴Ffnl?˗m9.C>"U{ܺټmF|=HCd]%>;1TɟE& ߓPy܀\)4YvݹUgce$.:n+I]#Xz pL =LVꛪ"ShHdT6WwP\|0MVnqHw ^ $&80[>ϝCAڀYR.e:sG iWIjoyT3&./*bd[j2Wob: HƿـUCq$t">|EK!O#f|d%{,Y90nJ?¹*N QmwsƅإN` 6C=-Ssymt3Olj͘8ZqVf£,ZQv*^[#|qQu1t\z7;4\%XLVbf F y]֭gU5ԍgl{X_<닗rm]xO'Ոwd?V򆪒p-c@3hˀw K;V:vY»&!"7+p|v"w/8wMb3 `6+MUN5Z>㻧Uh;7G7S~G,)-8f݇J#yܜ%=aq* YVbuQ=·gy"JH8Y*Ekjk>:Cɔ?)8_DpQvE,sKA(Q!V:2mjYPfk` I%Q }_7p7%s^(# 6,=7p8J>hWYe!i<8nxM֎9gZRg 87?i7D>ݺf DH?[;ɧ4OH]8gB V5 '.%UR؈}$ D1Dfu+ { =&<%"D7;W)Feq橔rϭB6Վ *ž(>]xrjB$gEb[~Aܓ{6Fv)D[|S]CbLKu "m4` Lvc ÿ3b`g2w$G%nQX2v&s~pO}>aBX'L4cQ.xjrb'ߛ!5C q: {p<E4!́ uiYLޏ)Mcfh;8o]Wq9%Y'Gnm > d!uzE&=fZw!enV73S`uz\6ݳQt=*a}+i>DM6U`l7Żf͛L 6iJkZx >Lwqa%7%} тӋ:yei¨ s)jE'qpzKOɽSEz"&ړwg}h=ZߜbǿwDP6ޓ鎩LIo3; r!18LL%?j,CVJWrluxkx_/dsFR^gPg^Et)j#h<\sDLq"6CT?\BHh4 ݄J"ʌ+\\4̫{sU׉SzLd꟨d׉:.wpV\XzX۟!H2Hr dP͘d#uF^3" 9;no$]1X}AV:MLF~&k0+,ĤUfȤܚߠ:e24爝JKSlnkr`Bh $e xyGa,YB5;FqQb=R`2SjbQ@($?Z??iNS=VvЊ!@ ׷G5L׹w2Zvtgc&Q2VQpe79pfyw"[H~%D'yUI)}(2\ɶriRE|PáxjY٪`/O{cJn. c ۨ%bbe,":ͳ?#GU'BT¬!-a8< ge"fD\QIz^LGՄ:'h]*qݎwpP[P:[3pb"kU{DlflovgҠEN L:am(z0)_$1+΄Н>lX}7)2׀DJM3b'͑gK[z+8(<ã $MP+)UD`e2K}J8M=9WK%Ll湂p}]a? `6}AWHKoݚe&mK>^+?Qߞҙ0BQ˖^t'Bۙ^JR#z bO8%DL1+e/ `EN\Yq: \]J,LCc?&/V,԰ś+ـӄ%|=keT:A8sbg 09x}C{`>x~=eKlCWU`exuI $v+>~V9Z3D:E*3EIHhW ϪBJ99EdIqFӕyr>Ks+dNd䌓nm]Fۉ K#r'wɑ)S6vvq7nf]pbZNPzl1b274?32X0{quI< Qf'G%g#A| ǴTPQ") Ie# q2oډ@i<ÌξⰍ\!|u+1euИ'?M l_& &y!ߏ%>~,/gNƳ..ϥaŪay^j S9 MFRJc[flJW |%Oc8`ӑX/P) UUt_F95ĆZZTU |̂VUhR?-+@2XuKM0C1;B±ӏaӀǫStu$wXfݭLQH݊HM& :շNn`UV$XU'$b\vtzπm?#3 Ev@zZCzQ  j,^"$.aˍ0̔]l[k' v">sDXK!y oLt[Bs1U/Q$ [Q< [ͯu CEW$3z䶫"m]uhW8@++f[X*Θ@0N=ogN;cQ# 9bk>k 7ZCmu_Q%RS׽'/Ous+ rDڕ #$MLݤz~ NEϗ7V%y+`"]а#i/Y,`yHK3l97aQQ""HR\cjI|ZlEk 7O^ +%A[7mq R^ O}~PSESvv85$I`' wa< Rd%rޱ7~+ja0[RrCUoZsͩ{=wtUlKCp?dfD_JbslZIMx h.'Xş갩\H!+E6B..\1W@1F{o9fR1닣tu#$]JҀsx?G5drF4ͨeT $w\3nPh 4\"vF>" }:teM:@H[fuӐ.&Cwԗ86+[  Fli|9%k! % F*4v`> aC,L_:U,ICqY2{lpmC[#eӲ[܉p5[f!֐g)¤0 $ NRN^{Џ$9JL je j;\FW3HJpd>Ǘſŕ/HEDaI~du32нUI8 C@>xcsWJЅ>5x:,]EuPxH*B%[ȄuC-ocx{ de ;3m\ˇbEK1i&`RLjC2,1ӞėzHucgeܙ zn5\I)/z atmzwªX%,LĞ8 {^oFw @? W9+%5GM-k+~r8'iDm7uZdǯwPuE/-7<,΂< g O7AmsŅ}3iM"z>L1VIJ3qiuŀ߼QBPl֍y;!W : sq2㚶Wc24{H'=(nG"?W+ 'LOQ4gԞM5\V#5hcy #LU^[d''>{2}+֕]WnXotk2w1XzODJtg"Vz+*+$iJwͿ,k|1HBcu /?%C=HzHF2:`{6͐R%R 9[OW󮛷kT.k]'|FjBLg(D $r|[l{cՕYa[*\M4 @O ǶƁǫ,k '`<0C /9JDA޸#RXHQ&uc@-'ԀyqgDQ?#Adކ 94a,ޑ8c_2qm p%pj/``"݆ڝ2}q.,ܨ%C//y*6-Iq!d7 [DJSG`uں,# OF#{E=-&%Z>.PYc}ppb!F^T`K1'5~˻J+[/:C%>Ebak@/I6q Uz*^;"hFI`Tr-=қ˩15WkH[+[F,DrZrjXH@Oc)Mߢߵ]C'=cHXQ8OT=IJENxl͵gns{Kܣ,kr0p6y{rfwEpzZ豧T^5i7]`9puw=L% 5ir^.QJsoM#rKdIO%@!gVd[~5* [2 ,Iܹ__e죯Gl{Ac"s&ƬDL,b'(wg:P·{vI[Rph F9bM8$SWe&Ўź`˒N0dk{`yJ2= ,R t4PqQ]*mWG~YǶZK]R0B+bD Q7ɰ@axlh-6e6Ϫv_]$gu8b'[P&N%ߥe :U=L˶Wj^Sh|FHrh#).% 5/?_KeEzn-*~H p.ZO|aʨPxXUA12"6,/j))5˴g=~xΤR6~lKQohuOUX8qi`nUӫOUr!i(a^h`A1TAx~;8صc z=:-o1CT=dH{68f9#e`‹>W7Aሗ`H3T{JLg Ld#S@08rcB\kEkK1d6lg ԤT7]%ϋsg}})0Q~bٱɉ0܂m`,0Y~eUTGC^2^;@+3R8rv:n_O9yB8_Ѥ $pU\6B5<6..M٘& HrFX{ا_])W$ K5vғhR\{No 11mb6s~I}qw/sd1ty_њG6hNgvZZY|-|m)^Tt`IF4T+<LS eTZdZЂn8{:gX";zݮSN2m /Yl ?IDl]Q@îV)_ϯnZ+Ķ2Kf8A>O1!cJ13}=7BU^ic W$5ifƿ݈}NbE1&ԫzSPyvSmcKwm[qѱ>_ߝ̷@1^kJRyBHD=g-(}1Z}!H{kȌ 3VGb vˠU_v"t'+.%VÌԨ4]L>4/<$3vuu"7X4ǝ['Nb:#]T!߅}ظfa4C+WE+@%@x\#U[ >@}GS=ai/Ȏ".)q'0dh۽eÌW⣦ Ⱦ0'A7\Zf5!uG s-:~al;LCs۞Ph/ {ʸ1(g")>U;Zl[3;:u8Q~Dƹ3&L|v=4$| 7FS}gITlB !i?679DX(D'&@ǭL\%˭1!bX]21*Ka'Gl:A|ټl. ОOd-}]f,iD֎ zP5ܙ̤n 3x9r_K;?_r҇$|Zݳ^؞ft,J#c/4Bquw3*{iS̞%\'\MJd5 QA* &c6Bp-$?]MCyTi=$[N6w] 1]~pvYgׂR^qо`cx8@(0gZVDv Ink^&@>^r`;^O0x%%@|B,X _\ [QAUlЫMn\MR$o~l fA$2JШ-Y;d^Yu]اa lviyɖRz=H\̧M^vO9J 0ErF^V@ 0yd:jM0 R9$Hܡ;sSbh`-# @~nõ[)P ق-5]粥P*o19^Irhi{ESR9`QA]3ne&oEV0 &q˹e =g Gٸ";< cJ}|s]/3c/qX#at߅  3QDkҾA*kXP 'UQ%'vd~&/2& )` fJf8jӲn}-"Xœ{"]V{jwlK 1ST(/ps9S*w/TIUjcvg7WVSn~|KU&JIgBc DsI_ɂ#]y}—xV xۂIsNJHBNk9wUp+U"Ɉ'Kvi n|7D ЧV:R ۭQhqUXѧift&kMMLvź j~s7XFKcFI ˳wb`ɏM}">©B,8 5 1 \]VNVL2oLk0oaD$g8AzCv3Wo!+~D-陎l"#5`< ’.FrvS`T4khhid&xD9"s&j))4Ue2Bl"*Z[}q.Nvf1Dud̹?Mw@+X#;buKUlGK8HB*|KHZଓ!A)8`UH-ZRTO_!:%9 ʪP =UdtxRꕗ8ܙMEIaCDDd-ϰQ!?6ѕ DJ\u.]ټ/VIyV@ebV\i9Qn59R/q8  m-l4rd] =<bP)31 P_f$7-嚞 }"lȍc7b?X,)V wq* &2K=rF)i7 Sh@;iB0v78⨨F}7)|M|ySdĻv5Gfdq5G%VH7PhVUF= -q@=,(P╡a B]wVHWzqs uO`Bȏc̶iy8,I)WضѼmK_j]ԷFhQ>ޢc Q2G[$x /%҇$K7H l!0Y؋bK@s%sdo#nkW3zh 0wm/r {1%`a`U$aǏ4+Y˦ʶ=Wʡ,O_|YW$ѽY8HL(b#aR_[p`u^a b&*,&je8B!ҐH%FʹL;x|oxcGaFº3G)ڰ;rr! P3ٻF᱁QMkIk8eI`iPUd㙎~)o,XϰX< .]kwΠ7x f5iS7EBT6lTASBPa "9ӝ hFϿ=~R5@4!<59qliE;*`@<щ)Yyl(fs>`P1ѱQ$ԯ !@EB`&szt {$(:_ IiȼD& kFJE bS?2IftQ.&<ҙD*M#,>B׼ȒQV]RBd H' ,1\+*3 g[f\1q&5/fs߯jXG.ݢn8q Nz|7[0;!ôr.\t"!@IQ6Zer1Lf~ yy#UV+C[ޑ˅.qywrÊJ_1+6 yL>geV~8_=u[;.)cN/>VJ/T\%nMJNTOy~1sI.WI_׌խn6"j?JA^x\cĢqV{'!I@ab$̓4$%ZI %pxPP<TnbYT/Y1or 48NNufPCiʳ>ӟÕvFZf5QIlOXgR!b@\*/N $t%R^.M9TƊp dWx}? u^Aœ<'qϯS3XlUżTV57eC L'->]y_FߗGV$P+9 -uc*@m`>RrڙH!ZX{Elzz怙:x0 zfOG2O$I)F0rM{X $Z@PǓ5s&*+:i$'N# XfIj6Ow?;DR=!z̀ec껍x_Sq%1f$="j'[NOQdH{EACs|%cdG5P6B#SRh_BljZS[SXWZ؍>[k_ih ,S^gb6]B tMiR}v\+dciY%zyD) m=oTP.՞'z͈_noFn,LF?` HN>OhTp:nnȯc.=(ӯ\14_1`kA?xiM(T hYL -(VfthtWct_}l/ +JVc? ΚBJNͩdO͆&(ͻp]ٱ5Rxÿ&ʱ5hd|_tO}V2ØZC Ҫ;bD4{_ε>柘;p'lt5ƒǒ8JRLE_2>.iTO#|Qy 30u\+hiW@塼0U)\P=i6,9o'\|sBN毱CM'!p`E4l) viD\N<.Qdk@3Njc!J"xMmYBɯC G"%O (SwmI-OS1Ֆ^61 ^zf0ώ5<9ekKլKKoT)J+UJK,$%OܴOsRu&vmŔ.M5!u$̊7LEn޴M(_~Z- eeZ)8ni | %&ͳ12$6ܶwJU];9_Ӡ!kJNݙL6-udGij#OWmݎM۷ޯ$&㝙릔z|Z6W(|ȠR`@ma zNK.j^Bi1:W 0xC.JdSw&%98ž`]Wg>Ixz!%iS)}ǂ!tRvP#~dyU!B4 .$9ڦzn%-r3*iO kyz"_\? tijt)ʐj엗u {wS-N"KJqG/I 5aƏz+zNLK6]fK~Z.ՂL1LŦ_sPXl#Ig֥c5Q Gz=(BVs"R <2d1`ָ1x*@26z=:+f͡:$%?T4G[?wKYo i "5|qt4j[$*׏Gaeljn>r& 7֯gdƄ ~t \rKFEQ f fYlskyJ&;Gqq@Ua,e_mH7%ڎ^YGRQ UcUPQ Ij;4}M{\V MRg>em'b'S:q,3!#rGGV#/}ZDLӢQ-5-qu'$p7sŸgC{Rj#3~Rqka(xTmR6A4YH"7M?V9 r- cv fIƔfE'fN-Nx_:S"ߊ.άi9ic@zŵ;Ŕ#CFpڵ_i_b|:X&6kb: Q+s`e.B&ty޽G+ђ/]Mu i^GH֬C!Qt]❶ AeΝ)\^X&a#2rk)=ްD7{T2bцHH Rng!|9e &Ǵ^BRԅ1ZǑ3&OM1,lإȰnG?TіQw3TFhϜ|`:#G@ބj_|L@sZne##*L$&b!( NB󮨨ݔT}]h !(udXs )ĸu֩S:xps+(8IU_օSwG<w/S݇kh?<؎OQ~8EY.>% 'vf/?^x=}Q@{% )WKʰvzDB=?(/-k;ơt1 F,yaJ,7>hg)98ˇIeOJwrp+Uj)[ēXHFc7Ʌ-߁=a!c//#˼ ~H7WwJ|FP%==1]pՂ,3!Sv[~b9ICDȫ s;$hXIesNKy~vm_5[)׵*8?ɮp< (|u6ݎu#=N_H\ʱ/,].^n0Su[^[b6O69@=tBN)JG'DI0m s<NVH:kgswv>ŵwe[;7(Yaє tiM . -"ՠA^ӅF72Oq9}TKI?j 0f 7H#]AbƔ9 :"]c,wvnoEh>954&}w8jAu>_Th:_ '\cM?>̧PWkWm®jeH.4ﰤ͢ Gj> =!]PV:!c@R}H{'w%BUg+ K5k"UP 'RVH,ajawWc]&G0zKYʽ&6M3QrCS`0e(Vts=Dj@(F$ql9rh(L 8T1/ 2NDp%Y@ G3ٷ }Pp|ἋK%mYԭz +*.ӼXX6tk_ܧrcI ((G,H\`3b?x-Sn5%6 ƲH/hw%S,uuQ8])o7gu&|2)h#5,/UQR3)z`5,U~>'gfs CQ6+Q%`}7XZ;\2moH1„swoxcq"Q2t^I*,MbBfI`/|eHM ЮngIo.X gXB OCӰ(<v1DOɥ!5dM:@uAx-/o5$gۣzI=?.GpL7jH;l_;Ӡ^xB=rn sG/Λ,E{,6 Or, $gy€ rZX4q$ Xa|몴9-#7.2rF$|읞v^cbzϻ!/e(~tU6^86헐5T9`K7}冱ݢg F̓b4ʸ~(ADvZs2Ϥ# ֣1Ivap@W9r 66`YSo䌬Qʐ5V$1j >AB ~W mǘ+7xVOV֞,X^ D~Ӿrϗ'6hZHaǍְLs.:𙸪 LjUeV!*O צ',RŲKۛunb]w90r]By ֍%9*w/tad"˿f%TlQ6VHĴ=z)> >Eu4̬Oi\"[DwUCuwZwc jw]t-oIgb|h%.hPlV>pwOStHkW&!}Kv&B"Fz)cM61IJ5Ǟ/x|Zugr#:T&ʂ.TFaM\ڶOrZ6~+],Ac0^;K p҇aG!By;}ku!O)E!ʼn2~6[R{Wt5&|4, r  !٘UfFY~@wm儫\vm쟡# ħJӀxtsS挷:D9,q v:`%z;6wQ*soCt9pXx@(`?2lSDHv7nQLن- *+c&_d<Ҝ(DWſ*CCeT9sWC/;co1c't0jהer%mvT\LLj^,f}Jzk4'7G|-ê ac[Ir o#Z?AΚ"y;?~Th!EF/+J U]_nӾr~_$ pce (MnUL1r~UZ#7eZb"1WʸKk;>ʿ,h,E4 VCIAՐ]p6 û)HkOO rįׇC톥%e1%Y*ۡIɠ\Qp'ILv@?Y%f^ zv>-{TL#נ> ;Sݏ z&rp*o4 ^C`V)8w' J<8}BV?/[puy5[?}q^szʒ!`Z z!y–_ثܺ`FV}aԱʜjAHD<=Ï~3 ƳWF6R#zJ5|5qf}{ݾd?&D=\w\8(oQ/ <Ѡ#zN>߮zę'_el#L0)?.՟ZkeKk'ڂOS-DظҎNwQ|Yd{ (VAG! b mB>d"=+\=v'boEXJ?*G&YMe2 <~|%RgpC H&bkR-W!짵؜f[yMd,_ܩd#CesK5;e֎S2{7 dcli2h[ KS[̧$]tAK9s{Ve;(|*QBʸ%azu+}LwQ[#*T6uҞRcIHPzۅgX:]@ g(JSL.%[v!buTڢ=Z[y_4Kds;"ls1ߴ{2%*bqg~zrM#.Gb"M yȯz#LMP肼|ЈCftvWW0_7F1nxFd{0C9m0iW>ŸWLHx|c+M!98 R-fLthS7Cʚ6PGDnGɧŧ2xc!=lit4vţmQϏ<6X-kYՑjK[Yڇ?ltZ $bsƳEARrmM+: nzs4\RHJ∐(b M&(D3oʢU@^}Q n8ZR(͵~*f1WP^om2`MO?4o.WQZ9#V3Y,_\HMsL9lwƨ=0T ]˃{V]us:w* sfO#O[V9@#jsv=M!8ܒ dRWFV/s{m=H'f%CsVE=_; y..5kR٦?^K6`ssfRizpTk X$_+}w#̫1W΄f"Ɉ&w x̀j:*7{W3!A%7=>NGKkԖt=c7x}'9^y %1b$ !"* (|3T{b`LOVz} /r,0exSfXvF*PC$3/sE)Rws B7ɔ"^(߆eILޮ1fvJؠA\x]R3NaNR ֲnRҬtvEEvlaED%Uˁd[,@rW9$_N. t;S?Q}Wy)V   [bk jvHCy^q6$$0cHmn(wA]n97ӳT0lk> h !~ZEkɨDL=SF`0(BG4F_[x)bE*`nY[<#v*"tWwbq! vm0y-&1N؃~S\R;m,=ӓُj;)Z9eއ>AXS=5zsīK7PS@WH+^`Us% H{6kRrqڥ<f̫|TmLP A@'IUF^ڈ{fzfZ vRd]1QWԏLjr6CY+i*|hN9oqM'~8䐟^V8{|:~@bDiCv!q`TSL'p̒\|Jހ$ 0eʏZ nM?n>;!ʎǔ|jI܍PO&pK5qc8B_X35)2!U:}U`x7q)4LLjWkϞOg6yt<.d}jғV $*Zb!5m qcrp4tOr" H-Tۤ2.}@?Rt$Ud,) m)) 0&'abA#P 2@DAu}!|:dzk}%٤ 92c}qJ+?frCLRO-[a"hxOzOdDpi$(F]༩+Ϻ6AorI:&$zJ <Ҟ+񇪴H1h#^j,y iMFWO܎hk[bijz.7H+ nhrT!@+  Wﹹ\qcqd[Q`r٫p2w"^rHőNq&s# W M}q~*@@nݘE0`t~w |9.r) /0n#Q*HjuȮ^KEp_ۓ6ܗ @}^qљ1!goÌs$hdKZ &aקl⑽,K67 ѣŕcp)]? j?NIfNJ׬ }UPL;-q X)>$ܻRN,{`NW ؀E+ɪ'Ca5JAwM ق5UD4@P*aNYSSO\RJmXK?Aѧ/HCG3 ?8GNY̠?]NڝC^d}7-(Q JZ< .Ӵ!e_q݂,y=h3B^ 68兀DG&&*TY}J̋7|k0\]cn z|Tk=0r:Q/Z3,3I3Ei{ KE#IG`kw*!Ĥ3*:@E-U 2 JB.&[?6 VlǶG'evޥDNEm$a mtgۖPZ:ߔ/is,+C/vo-l, YZ : k7, *'>;bԹ_E~D]`V/]*dǥ T=#|58rLXǏYV@̿1E~>7TZ4<PcaWąkS#wBPp%0)}40xO>eny| cnb_)*v@ ǧwyaj؋C%9^OR:DImV:ĦtEdL\heIN'jKh"&zvgv vɒcS}G%s?AЫ(X!w 5"nccN;AD qy(  r,D6SS;Ц]mHA'd@]J/< ݼS ,gf)e ^P~-Լz]=\{2SX$}{HizW?O.|#`rކx <6>}gG3#6`˯m1]vV1y& #5٪6bɠ=/ mखri)}R(dgN*sfbqswN/=I=79bJA'h  (i%qq㟞 ~H`..p<9s!3X {ƸT_c))IB?$ Y4MnVE4˟txA"1@*&[dMwNfkjbQVF0ź';Ֆ x4Jt@Τ-aFˮg?Zׅ38*-S"4z^RWsMo$"MO*aH=A;>JmDxl"]ԸV[W\ytB׃1MbWpCöbl M`ڡI!l\-f=T>O˃U}X.j#*t1\ve#D A; +% o@c jsgIb&JĖ׼e榏K4YZ|A ׶ABc|dB/+.Rh2-_XmHuPuEi:/%l1>x-I,TR >T s+ su }0i22XUR4U]SŲW ?5x>cꨱ{9#{885V &!D"|7{ \iv/q0k͔0_)X^hܦtet ٘_qmP6̼4acŰFqɺv|%Ey/{!:rƴ : VWl)-^:qonb:㞡NKsYO43RڠL\n$` cA~!`w>~@)4vPc|;6hC_d: C N:S)G_|w$/L]s6~,b_@HA Ieg*-x.H4Ϗ=^+t&Wo]3 cnT>/6EML%aΝ]dBw!MvnXҿ2 Vh2P)n7=薔۳Q?$2ohHĀ.As۶پ,>LMnSf>x&mH>MAJLK&C rdýDz4qzrO8YfhZp|&bDܥښS1EK8|*0?jeqWGt8:ΣEC\ң+%_leFr tl}ITm"x N;3u=fe^J|!#f<ƜP?PvvN>j5V>Gg,Ɋ?l9} C2=鸂v2 {]Q;3r95kS@&5]u[>3;Q\OWvi'8lD~PTZBzѕ,@{&ġ*DI@ TLL{@%5z>N}erхV]J|)čàȾaEp7*Nkr\a;cA_!6%7NŒ{~c&}}LQ_}࢕7**N# k}+P:Q_x'9(9 mݜ ޶[-ŞSxd|~a: Uᨏ2x$6ix%ovu/.\0qp{/e at~BpiyYM`"P1T|KKȸ̇C%|ˆO{BǗbIAg6,q}" Qtٮ V3݄ ە# 6cw<Ѿ&!Q)Th>(GwWoi[0ޞS?#])J~$5La6꿛>-e{jX,ԯ1%|n٣Tuf\@hxq=Ӡy.'83%!TL>gW2MUn]k/A?KR|v3fS{DMp%+ xITM}:`wr߽BA)GhY+hVG,jCPQj 6 \r0Ho?1}_]mQ c2X$)zI]#֔,zh-%ouG `P1NX?251n1@y5= yK&/}BN'ٝIqRyOw5K(̫K!֛w3lpӓt$߭}|:oY*eN4(VX i1] Ĭ4-e(ͬgI'O~~rN U`uǜ6꿲[g[s`,#MEp@C\I=w5?S„T, -AƶOd c53 y,.(uC;2Rڇz1V這uo8r]A{, kHwt }>J-O)+,1D4,C$6 4qqiw)d5Hs|c?yJ m@gchsʖPqрE"6Q{6xLđfEit2_K()dx;:X/LIpL/.KP]e1+KʤnEˀ,syG"IoWi$[+Qf>f֛Q`kC4Rk߇HLב:JhlM7B[1O2R*7_W0֓ 0C5JL wwxET`IZtIfP~ t0o!.)lPiLǎSTxom[z? i%zFQ?S.s*zi7!.zփ&L,taC!\pi6{ 5cK s^qX4gĎe! 1{M\zCȅXumM+ ;/r0WCy;A15B̸p/T5~e]6Və2i3{yL<4X1FpQzdCI,߼<j(.eZ13L8-`9'Ήd'h>6pTݺ Qeδ>_|19ի:s+{xD %"e?|}7Nh*|4FMSBG̐[$GBKw@!dkcu}z㄁8$=mså΅`{pvE^EJ*7VSiJ'OK,渉4}tab ];S¨U*j &Yku Z ܨ(7] X5@}~!|A* X"^"P<\^7CRySݴwQG0s3TRmqֈp%BP`eV5ⲁYN{3Oy3k^@%/B1a$UK~Ca-#P B>= @F PfBDy|m_|2eWwzVk8/$yzS^TϽ6js0fxX%+&) 5`r,,o@5cЧ4RN^=RH2Â)H2V,V(@a XBY`m$“۾:w >VH9͞UXz,eUbQ`Qr9QPaq`,:ƴEFwC+VSٟH,ǒE=A1qyU~m jao1p`[bO'?DO\ʙ{7c4 IЭ~.])n:.KZO}/ìy~gm]4s Cr:Ə#Z\zϜ؍Sgqr>?XXT8Z OȪpQk A$6H5 T]zwũ"&lڠ0ՠTsanVG<3shASh9p/ ץel|+q` U0fJ[:o-[r zi͟5%p\2 $a'G_WCWFTh`߶J^̟ )EKRw}eJp}*rFNЕA- K#mHW"tΜUi2}U6[PtLkWZ:" M%MlE3j/F;IA/=ueT}DFf\/&b3 e>) ŗkܲzиƧ,obwH;kԑ8y0IKb:rZ)6)V:@#Vb@-^> jIK-{V?gyw.pAjO' jYQ*dM(bMiTe +U78 C̥$~f~um"7N!yh[N嫳w>y6xG?#NWW*(ܭ!um") TXDj𣵧ٰ d/= `X(S: nJ_C[{f*_?@ua XUzj6;BQ`NB苊 z, )$h)% h4zMB5DG>̌/ZT":4$7s/pd X2Q9 UQY ǾtfY"tv;2j'KW0A V+hꃮq 9e\kZ@r83D;sSIÐ .O`l2 AwRb:.`+uفzzOƑEبɠ8s*q4F/Z-U߱0]qpxr_^Miy$&K_h}яpD0`d8Ig!F(hD*cY`vjTslM,v|6O#|f\B6I!}1,D0rcTA_x]|Rn}y]Cyw*ԘΪOZl_npX &t Jo-9zӗUgHP튦%U!Fbtz]I:F<7Šr&$BDO>w68>F1Chb!k(mMoA'?SQo-ԣ8 -!G O]H\u"Pw]^ )Aˉi\(lW㶵8VhKs\<1cqCk'\I.% b+ꃵ;>@t>'ojtlT[9F o.*q]ɢ2XO٫ni$4" !7ʶM:8'yG NZʰ?S8D\`ҳP/J e C hQ'iK: ^>BTB[r.t6B(DnZ KӾs_-5@+ug/u(XovjӋ~-uYX/s7;4~JU hf썘P(pz7g$<1&XWgV2LF-g6GZDG PfC1 9{hOq`'~!D„/CRJC2Έm5ufBWM jVl!o5 Wf (bjU鯵5Y۷KM#].ȼ 3H}Cξ \ o'+o\]+ Q^HOǶۭ(2žv/M;!3n7 e㺃m! } =-dgWmK,4r% +NW[Ǻy%i[\ yףeΕZ <kaNSגsC3hR=6K-I `n6>v-A# xUx),|0y@1k`C(H#Í׭$' Ǧ ׋af@:{7Kg 5vkt\ۂr\fˌ;"y), jL[׷aASIS ITTϪ?4~sHLIa$C&.;tw>lI H|r65> ; K\\ZW d`Ywx7yh0uR!Dʵ,t7qajW HjOv4P*I?toyTb7`q_o?,HZ~p~.@|EHZ\ <Պ;6)/lMyQ<N\)?+?o .r>_h(yn"As: rN9;97"u[4V1אָpP_('?i؜mx=KpôwMr^Y(LZS8̠vAz9l.McGSC$j!OaC-i$OcPg L]>{n0\6BVS q|OzU浥 eX:1#k!/ɲ)>K\$L"jw2o= ޛTK7tj¬/d$/V*&jAW7SD˟5, fqD)(V#0Ko4u[mR'e)WWUI.|+ճl)*UuVcή\*|c%;] d7`e,$XֈGrXw{;*flqyaeo>=0{H u`y`Si `iCQydsZc';Rsgo? z+f#hX+&3]6 M|{%p/]kg hr.$/vJeP:t+)`}ZOZVX禎,'܃ \"ػoORٔQx4u1eJ;rJ{T'x_1>}`j%XF!rvM,SҀbf3 t*@16PVN MO{TxԻGtCmTo 3dod?VlQ^v1Q\ptnqJGi6w#['j$0%0 < rs) `)=38'w c)܆`Y}fd/p3n+ctHp0|;hIG'WAG=0LnS=#YxH{=l{JW 9UWSSf+Kdcw| 8a{&6?~w Ee51[?Pliߌ3d=g ڷ`Ǣ2?.5E8->r*(tƙˀA8*UtfQXf=ܵDח7:e4I7c瑱jCD l䧶ݎh/ȉkRMT")\a, 0g "&{?Mt}]^!δT/mϡ@5[M48{iF p\ LC5^hTx؇l-i|jT+|"qoZ34[1x''78Emnu yz W;۵i$g [W ҽN;0Kdq{c$`)>$I\ҙ*V?Q}Y~ſcˢO N]6h{ym!rAFnggm="xѢl]N`B,tZ4b{xՐ) @K@g|؈u{7]0c9c Όezօ8:=H gxTXCbY/& '^ԍ]1Ku uaku|P3 mmSbh7 cՖ 8~j Elǀؕ -C"wa7@/wHz&雘7ES)D]ٴ;F֏UmJpVS`5vD![*pR"Yg2HmBltQ(jpq9:v|2ºv>S-ħn9op\vOy(H7?pC4Cx^^ SZ%'#nBkd"{+Du.c"P9WA=ugc!kzge"lꎃVf?2_-G_{%nAlI^QԆ/jŜVj+kܩDuAū;efG2ixLU_Yl7X"P+s,8&q<`8XDA g@z7p(q gr+f>=ڏfӟ h;-htp^/"1#:}d'{)LmN^ 0!ڷ'ώ꼅u(IPJ*]\; tz:4 ΦV`,;}=A;s㔪g\.tDŽMہx )ww"PL2y^ ,L~,%z[*C;qW'd:) QG j6?͗?GZs/IzL&;ѻ(!UgupNȯ6t[ª5bu$ @c>2մ eޑ8T[`M>toMN2K$}f7RY^4"ϏAJjS /k5'Mι?h}mwq \; +B-1/$틹["ʫu=@"#d61Nmv)bJn5E; ޙC>^DGMw2kfN&_=i)̈%V&#:X̊WqMvl !0^i*]U-YLϹ6&Fﭜi'jP\۟v D I_Icz0R 56uEv?zs`ᙉ ٩輨=ՑuRZcVD_yE%z"ѹ^KFb̙Y.Ąm7LTjH`  b@̮vަwFdbS$||ZdoЫE?Jeٔ)L+xW7ݏzJ'PYʫ6.JiXcc=W~eHk4[7Mq2a$HXqI]W;J_V+7 Kx[U/$Ղ\\Hdbx%ĦTR1~Rb逪bѰPpt䨰3SoقG+B],ʃe`҄F3?,=f˫bSuwno ÓV}~'JЁ!v'*|y OK2?uxzCQI<E5a/o HGし@OHX> 4t^}i0Dhpij=;w \0#ɯg+I=76'@Foq i7-t?R݂u+fܛ&}'<=n /^m1>Gp|z)!틭dA,J*6&( JZ,!~X"^S2JM$a\⁣f~gZ9fp8A鮍IGP!zX?Ax]`b9r1wb?Gy  dD{Sѽ28_~hqtjy Jk;&,T֒)4wn]YSx.9@YO9T"8)Ս0]5T*YG7 xJ׋ǚ &n/6rR/EJ~ް Ka@ s@} -isDJkۢʪ V\xO6M.½]T+t@T ]1LM#KN[;`YR}C&A~>4V FuNYjY!-ȣ/*)YJJ7D ϭvb+u`.,㋱ ("¹GCӛ /IS{1["[q>8o 9xY 盙4m4ÊC _q%kj/2~@on4]d F!=8T$cT7w(-m$|41%%PC/cJ#t굞$ElٽΔgcAdP,R>)Xk,p*qzDĤt&{¹Rhe,2<"(~ԭLO2k-%zK4{ɳrhN~.̈́EpKOEvKr8r)!lƆKq0%-]aEKN7aŋC(pӡw #MzH3=WtʋS!~hu(AV{ъ DsIuD.q5!O!UGw~fM{ÁcYaѯ藎U ` qi]+N V3`Z眕N3n#K*8մu"6|6`.Μ*:hn)Z 0$| إ֬ލ4w% ª1'۾i,Û;M2 (Ƣ73XhOa͓?ǜ2d t%xvJ1| !YjݏvQp5VTi2w߀v ><NRRx\~@rmڳDÙʢ'BHku>JuK4SDVBD/+.$x] a/_{̪i+eĻRC@ tmTg֛Ҍ5XLq6'bD3ny%J`n"_V{I&a.h $fCIr}jջ el$2Iȋ!g{&3D{.kp?}׳#gcǮOVYwUP3j' ?${Lf/^)LENj}5\nFxL/ $.w\jQϷ3%!pʏ-/.K*]S:-މQV*4h*C+ @kpQclɣqu |ű=@"LYrث* aJIDt?%/$ڰm2Dwl@3&5RCa44)M9F0*TE0fC ][g\/L<:Jg=PDPfQd7翢S9a`3A wGeo o/"$|v<4@ހ(@M,\$d:,m>5`Ij#&idI򤖧eh&VN 0RAou#9CTCR+J5sƊ*Fv$V# zNSr$ń2GrZͩ`_O;G~Ts,;`;eƈWi VU,|^-35kw֮CqPI8+&o\1 S 8@}׳qڽH/cj oh%֏"bPvT4!Yv0;KR?襲jǝ5];*qݔ[4=s i78L%%ۖwx'!Z*%< 71KU/@ޢ$HÜrC<ޡv !0Q ׽e 7E%aK09EwNvSHy„ 9x({|0Q1?i 4v0ozᕇ]H7m{=khd2rZ2uS(fⰺ%D ߣz|Y G)^GzIaj' ! ^l{Q@ņ:**cCuhA|r* ۚzWiyȳ1_~O5#!NYބ>~Ԓb, =C߯xf".#2YmeדXF|,k-xNU{=S˽[2f><[;Mv"C Q1,3%"}ؼ(*|# {=Ohٵ]wHq|bEKCڋF J}81dOؿuh8La?tK!\I; ؅C8J9(:vfCϺ"^H4 z m4lc i-5}TjBܾsB[:aq/Ӡ%+j9&hV FX!Ո=Cș{(|\DŶs%Q)+]){v(I*S_ZXby(Mi"B0-6tO":|_9#EV4Po鰌نd!颢Q+~UY/lq!dG웞p y98:ës<6j7\wL?ゟU&Vj۫+M@?~ xGr2$+_|K/UgӽGE8E`ΗHLJ~z/@lZ?a 4>c‘Y-F8ڒ+2A0>Jca?I_[`==c&`ot\  7aeV퐅q łmOB(!2 <~M{EP e ;)%P1)RHIP [ב^单^O>7%6/~2d{a )y8?JXp QEK|'&b; h<idG(9HyǨ%W>gvbO6;] ~Rn2xZR-] P0 ${5:HBso^>:N]vNl(ZGR1g r)=$ Q!UDMy6AHxV)Ҵ|F !j|Hs+ Iv؃L/խ[Kc ]Jf SNR5dqb(C=^%EףB0 kFC1E>س~%O,cij9a Ov/x 潎B١bkh;M ކ1VUfHW[D'5(FcTpqmǀe>Ըnm'J:3ali ?r [;{w8 a cf r]{^x!6lg6}(Le 4܇>)UwȂpC(f?;~F @)kݡ~9^.[1vfy06._cluCdb<+ֆl,RudGᨒҦNWc;il;C"kۅ4|ؐ0uTk9$@hu-n<3co6Z ׭T<̋mEybp-ꢜ#SkynWGsv.l/Ĕ@1Z;Ԍ%Z`Ge'2ϒhò1N4gB1@Ff{‘qZBo?؋9Vr ,܊݄7qjyaC6$PIԅx 5{ָϤ3ϣe%x+ ~y)~`#IB|s%*s/c6S&mlOV{fC$2"E<jeQd:hqWUOe܋܄$hiVXi=&q9y(0s_6G,yu"PlxyGs@/IymPkcv!54.4%;b_PUC. #.g[c5ڞLmTw QB  <{i#@Cy\a7589Sh=`HO;׍B[ZSퟖ)E} SוU0:K WG v N) , !+ y,ߥ%dX Ak >υC~3![(sy[QXoZdd!݅dn hΖW|=)֞l[٥Cg0T/&@ϵ7Qx`?Zm}wnܑ(:g',w#ҁahk*iF ^|$'OQNc$ (<@j`f:ZLa|]#FxLvX^"+U2\,^:i2JV^kKZ9OGPŤ4ߌpӓe.nU-.q;K;fe,sӐ;M1u]kZ_jylkY#Xͧ/ 2NUI)-G|R9P< v?<5G?~E?_8e}m%oXG£_KTBIhb2^g~nuw)h&9k Xٮ!]B5vP;Zx)@ͅ~Zf*(}<]03D|7$_.MEĞʇB=IgIZpwc2=fAKEOtIv68/LՂwŸD6_Wʯ"WD 2]\!`DN|n.2yהmj@L0' L@L66hbt>~ j@w O3?~v'gؚNPB{Hv^ jJn zx)cCNR3& TmЄw iH؜K6?όtE_9YMywW%벏&BHb[{i" fR S0^FSb6 6j4d),95=kٽ('ځNE4[cpW1!ݨ,v~`.rrF 2=_ba?j\56fYθn§PjKA'tݞfnnL2hԶ=p\䦅grE~Q t<1Q)5$;Kyz5g<& r.$z 84S!-XHk k$ u1L^O8&.J' AJGtb{ vike "yPNKd j@SKcP!.GԾLh f5?Zq.xIE=ITj_g:OOWGQBpsV(ë 6#pe55?REGQ){Dq%[GL%lSgg% V{[Ǩ-zb*@> 6ag3ksuyM0l..cd2 %*bN5Key?ZB` 5uq 4Zс+9tg' \SD2 yZIIk`LI;z67'8Ǡ8VqFykA{;t#>pJ<(IeЂ休V#H*W-bHE4q[lHEv ͝i%^Xz'n!T~ND9aHN-S4@>yJ"ԯ6?hxB1B0_NW7T S{Lr /fD2$wǬ+r^O3TӒbRDWF'K~xݏj&;ܣ-SqbO?{9C_`:dEAzќ\ەޤgQQ["D  yNYnXm$Ҙ_0|?8*b{ƮRQ5sy0{o;b_tk Y!I kꏂ;SP QË"0M.(y1QpO+^?Y6!_VZWǹvQx+`9JB@Rqt̝ wq2g8L1@LQ!phXV#rS hfR |)ia;0oNGGÈͥ`^x ~]q].?9 g9H#ʼOK@`hb) fx<\씒ۿBiœ:@1Be5A/aj,,8rd+gI`΍J'LSF(u rw2)/b1bnX5{2Hm%EX {&QIN@ltN-t+Km;~.ݭ'ysy)f9] 5ar} 0_E<+ͻY6tلaK%B!.M>fN$S,qo>@qb5Q']7.F'zi[]J?8X})E $0vod$3v˻}954V~R(q!7Е)ءLJ+9ӂ~qÿ% TOYEY'C'upN}GeCqfGc Vs`Ƿ@9(6 tK Z7V' m?=M[>}(Y&f9!٦Wl*X4&Kkiy<@Ts"ys1fPu5ita:퍐3`=K7aQ1Аe! &0(rff?G~+ GxXU^u{a#P`c- Mi]T+S[^+ymǺ@Wb+5 1hݴ 6HhJ1G'z{r u\i:|i-2P:ic4^cL*"X5$ga f/ JQ0:Z&߮Eq Lݥ=:e| 6;bz\V#m.K7wee횂 ":k*9X?9ߏdnJ˗.b{G:k:G8%GX4 9k0{m\;+՗s?c v3[f8d 6vJ.J=3af쎍Tj^5 O*`\ú^ hVglȚO3O݁TJB5o}91+9e_qp}=:VQ$Z?D񗢨!MP . i%ұ;J[i AUBW?bA\indeEdzj+SPAݕS\ak$-r D\4(#߿v#uŴPB%B+t[o1i_\|y .=TtUM,c49)C1 9kS$E q\yIzXsnewbVeP>Ԋesr*Ƨ^2*iG! ;.$0#-|&Q"! ݪ@yGe!C=e^N~[V܆>n[OJi|'H6=?% Gc!WH]3pI1}saV /P35s1kJ({e-g֪}ן7LБWKȋ&#)J/vO]ۼOO1i\UIv+٭)-oX/$Zԁ1b;n*pys8CC֠kx.C4^V]% 'z0XD};'QKIq=!MY^aQL=FdvK৬ 4RrS%XSL0O9S$wI ܋"eNZޥ%-[у_ajaf[;OP߆?|;a\,V'0Pc%Db>A4aFv)Ywlmpw7PH|i-IB!W-\IXSm$jC:<5yd7Jiel.M&sͰ;r047>PlAf`"a%fz =/V6bHT.A-\[0"/g=(kSt3{T io3L"v:=8v{̮%C7y(B$gk axw'/rwWjc#gvuv<+6N坽HN7tRmci{qKid?Ķ>DKn<7J4Yc49OR2U9;0)7Wl7+YX$nq&JA(Kj4hϯ\\ {4?ϩ@*w"$cqIĿsn$[},Dl b34Ρo ;'az4E(fzZ4 ^"u,n f @Vu, 33V&6i0~z  ',{ y(-k4w%$cvc~?N_Zh'?8 4~䂈QUheIA  hQsNgXgXnZ PbT|q+5JN)X٠FnjsR)vwΖp4{%5JI޾LU׍g4##G~7 Ddcش$' AdRʤi#%pn2J~)~7) V kJl&gK 5XS3ұ.m&bsJ_5m_%?.ߐ_UʁSȕbGV i{[TJ6yoeІLU !pĔS!b)x3|wKDUaaiUO2_T½A_VR07;aAI Q%'B숻u/,з0 ޢTKS TFfwQk ^"ԏ>uo׌%nc'kp8dN HgdBI>\F) MM*?k"|(o԰B`&ݖcrF%Xm: ,3c {f'whWT}OCqUqV8] | Y H\\i䯬PV*;ˍ q<)Dn$u6 |Pzl;cP  d2\:?I$yCY|i0YWвOX;iq+[T> };վcGuj{u$JHQEoz&4Zfk[tr!KǻğcǨe럁=03ĝ x%'lmQ7Md3rDw z &=IF?kYȟ\;{ ؁9WІ7rkѥ'd,Cb|ClfRFU˧nJK[4`ͷ^%l?9vs6J5~c,( G4p{_#͇%rkS[;Nf'pD}Q "WWi{$TJ!qrc. Xl$0Oށ4Ox)4aLWi^Tw@$G1a,ު0o{Tg#>| nPİ_%hs4Yálb46;Yb}=xedTG$Y+FZ4Mh'%"f?2T.J/{RzuY|Kn-\>E!D`*mk0N].w%W"68}hS#哽dsdwi EfAX4b"VeteNDֳ:\a A,|99Rt+lj1*Fla6plvc["tx.L8dㆩpzbb%):t&*EE0}'?g)`B Ƹ?3{9FDR;y]!S-8xM8:/&D=Re_|KJ]R$!V|êJOա 19,Nj;F38z]wji^> q#=)k.Se14ê#RPl =`g>WCD `dDt<3~ϋ|_f *2XIfh=:+/fOùLo]~T).\lTg10Ǟow(ꘘ` ?nAu'r'֧n F 0Ǔך z pfF׎j弌!`iWRج !i\\t`"۝+&zT_7 ;n& (is!J=Sĥ6q7˧;z~'MG_D㨁>*%謡V1S̛,UjAʵ5N^ϟ;p_3^ (Ε.rq`&-z-]#ZFRmleM~|#FWz [Mͺ*:ND-"?< _RN%"d{πKڥJj&] k y9L/oN0{T.0k…ɮ Gvp ȵLdN4Ӿʏp ~vE٠v`/HafcOVXc"؜ApCme0 ~M^|||D[CC Ӫ E`3yxDSoT{t,W60,.2p]}e8ּ;7Ld)1&¼BC(ƴJ~왣ؙXBj,5Y$T^iwxu"^u~b|k_7k.d~UZVV¬ð6g ! Q3žxjq>&W1vɈAE$3-6J~}=+xo-9oKr~𮏢ϚL;,Dtei~/y lQ> B+],IoriLiANI~LL+KL>0r7EIJhHi.Ƥ~49sN?qqzoR9ʱ"p:_>n%)?rL/"9:)9\p7\ MF|b2i*K8no}dyEEkD'trVoDLg[6cΒl$*)?;XR^pϿ,^ QAeX@=_d",$GԍV w3, uDxs5D4EqT df$*xHuH$pH13vRp9P'Y@ 8$2v1 ¥;9aB RkBbx2;,TNhSN%o8^!و`8oxF̙xoHnE|,RQޱwmP+zn%:;̵D%/3~bq̗\Vd5ME៼]e&O.z3ډxTR`#nCHfWDl*ЦPЖ~~䁨mtjY*`Ehdd!P@C*-UA\ ^ |)M)Q}j+-F=B? -+c\2:,ǭP֕!~_ʳ@N:lW )k݉>)9=TEӧSGx޹\@zQ݅%{nX,l /=汻(ap-KV1Y6h\m6 M 06ZWOSlaR$>\N1rִX6i踥9bP\=n60Z 9YK=i)$7vIY]C6u},nz9ހ؊T9 W3f0"  |GKbCdCŎq\`#V_f[nHJȾ5rt񭴶aՠc%Eɹ*ޯL)Q#;P3F{=3zzqzRo~~+k`tL Z>E8R ]ИZQ$ !VVf 8иl|9}wxS,1& G|MSI?qo9g8 LW(}a'as]Oi!" !WqpO'/Y!jlXlg{ ~* (ˈY6@Q Tcӏ=d,^]=ݼe]KŘ<&>*@% oLxձl>'W;><(jc>C# ]Z-M럅q?RR#MZdvKk`k2;ܱW>|K/ 0?.rMЖ}N{wdx}$y?*Gw7Mq &;IiPG\btOLWWŨP2p(W9?'U(-4J:V_Aŧ,S_R׽(S-+j'b->g.]s/fx1|qc1Q;nOD o5aCHq6[k5Z7L| tv+HMlO_/؎(KE*nD ̷EM6Yj'JwHO}{s$4jZiLP.fpIŒdmiv&7ZGl0(p+t%.mD[!ڊl7<8,ݏ V N&OJ7ԅMjhǖ'~;= 8\'cn }2KeXty )b~9E"V0FQ&K0[u$O:eZi5΀8mCW{ n[|w/j8Ӛy6aV:U/ӧN3[v/=o<__{W0=Zf~xH^BDbB< v8oHJ./>}j<>HTiDE5h*uԙoa$[ X5g!&È^ H%Nj< Qr3E#x<|Y5\iMfyh4<%c¢NS\ sZRAP_FsѪmBޱLFTN/t6aRP-s< g= ' ZSLUd .CÂ#{V$%]ŷ =%)b*\ҴWVpBȃK{v3NdĮXQ='֫_w4oo_WՄ=,̮] V5niؗ9Ӱ32{o}0*.B 5,!0D,TPn4@Mun ܽf5%L~q+ Jq" Tω:our|3n֑@wz!闡Z;ZKwKhx6rgYb?|:3ǡSVNzn-S8f}\Q* n]%G4Pb+_Is7N5 K)8/|3"iKdD1BYg>HM`lWKI l ~ po)o1p$xx!/B-ܢ%ө#r&`<.RoԜC Ld/1I9J8ڰK7qN߭x7g+kWoa+șӚx߻2^MT0*&ke8<(/MOK/sLZ%N '?C$m9<5YEsS!5 }Tx+9êEtKm@ך-c|TC&MCM;ޟEfN9bR# ^F3UL bYe,"ܥЬG1M]m|C>F`_o-@+"bY`UdPEH${=3cW#AJHx6CԺMDL+L:L^xJG5\GGjM{:0uygF!xOM5 _(7Ec;\Wfv5~V[{卹#@f;9\f殆2a} ss,HLa չF&A0xi2ylԔTOhuFD*澡é^E]wX4yڬ1kyZ*GΤx|l@OSN)!C{CrSQAa ]yr~ X0-0d"8JJG8+řXRţK4t30Z{K&)zojv!n963i{'AthM,nIĤY*={ɐ qݻk<=qMF1YIt5\.Y̋R-9ΪcTÊ`enݒ&3(gՃҋZ7ߵ}]g|̉@14 >?016?RaPF*htܒvRלP۳%,PIB$$o Y8Ս&mIWVᨼAYV!szgLGRY; ePFa\d}LL)hZʇwZU}IkaŝKYpBqyv=\ՋY0X^ mGA.$u-/]/x?HSzqD| PJ_Lkqr(H  m,{K J_|b8HEy]:*Lɿ4 9W_Կ^*P"ba޸?,R)n"}'//A8Dϊ2E yh QumL|6{AgES@qp3_AĆ)=,sSOf 2$Y)*5Gэ.&l\s7QܽlCޛߍ"׻#X'+赴)ΕϬX(6t^EX;Q#0CVRLXP9Sq8чRo`(U ktΰBc7̡Qos0͹ymH5>t;SG Po.Ǒj] 02! ANX8'hq>Dyp9q37>ssx3@ ]߽[Z,b/GSS?߾U56})/UzHoHn2mWBL6iI˧dotNtw{}= &(zbPyI&z|NFXd]l1~!x5vjyCWT.l+$D$x[Q6h.+OʂLV5,z&)Ig &mWѡ~%ϸ .ͮ.SXSRQW ?}jtgǽ˚;$D9d`#󴱢,?c ^I'ڢ_lǟPq?]0ngD#kLF>2v"szz,쇻@9ԖlQ;(/M vqįr)qZ=+)PhzeR4B%S.\TW٫V+M1:ZrUAc.Tk !/&ffXN3ILHKjpnve4R#۠7m5o{̵.@_.O+< +Fg8)I?LyALsNWV)#IW~j[GO} `y%A@($BoL&[,ɩkp GuI췻WjvagXbYӠ*67 /P%hM,+<1z!5,ؾ#ZȭozT_SP*V;qi]ł D)6H: 6F c@Z*J'?MX14uLb˵cyNjճHD%6Zõ"WsרA+WUV)rw$+Op>iEh675uK(\DZ [`W bHgúƫY/F Mq0wŔmu~e2zTxm{Y`-ڪe3 '*CIaۮТ"<$ӫ4 `٠u.iu.םպ]vCLu\2LhjfҺЯw2f?%TbxT҂cf5Kؓ^elp!o:҅k]b~IV&z##WayPAu,H@pFm8Wb-dqt`pK<Z~N[kVT8PZ>X+//pѦ.^`7n[| Cg)MC(e\:['08sȳ]ݟFߕa@i <mD{2~o\d辇,@cP\Ƀ7nO9xViMQ#V} +zZ Zf^Cmf T6pHYHGf.@#ݹG,;b$I8 3 b8W&#*dR eq xMZwԳ1T98v}_ zEuogӦ+4xޮ;<}7)(P-R5OK56&ufTRb̆rNo`c<TJ#?˫uq" Xá= tЬoa,n+^sN?x$C,@(\m)e8fFEQ DR&WӇUm6Ƥ"a|[M`R);7 Puu_./k}lQol8_]3 @YyyTF9epOoσaS5 2c'Z%ЌFTD$ ub>wze]>|)tt>Qk@Nj|FyeRAP 3Gcb{|(m4T!x׉Iʉ84aɴ#*nX`M).3$cg7h)HFH; XLaqoWw%Vh}?C!3:9,4P@1EJ&f;]S gfe}ϺLg0vEa"Fk.7gsrLiC8HL冇鲲45s1&SϨ]y`9@VK^ܳG5ù_x#^.Tb<"v7k hi RO굃㦏NTEM2Cs#MJ围2zY_6f1!(Κvm+ۙQ~0 gz[{"[ ՒQˌSfeh.H)cJ&M]e&b9=pӱU)nl! cc< z֕ΘP@3kY!5a:Yav|c n678rsD[}Yybj U_iТ'! %bgnx^ח]Q~f^H0_C_fꏾ HIsrbbU V$]qn{O(3B@>eK(B٩{F}VMWc<\ߜנNcIqB&g[ő^ S`Toxhtg+G*S1 ɁJF6j(=|Bg^ȌS0/PQ`~{8E=$Ew,gߖnB(yO;5 Ad= r@ھu+n(P␨rJ|~;ƛN@ieK J(gatLe=<[C^W: VPj陥T}Su%e`3ͥyU6i?#k1M^1c@ȭف ^,T/c 3adbU(6Vz훻@R~ *a8BrjW\wbޤIIJz C%ABTjwz %-bMC ! _ꮕ E$ITJ~ j &f}Ieoa-꿰(qZSF}&tRBmЭV#"I(e*6y/Q?:E:4G s7`VN A֙H5(c?l$׼*ct="RPؽEqjᛐYhkI1{^:uPdC)+\xhޖ]!wН*{rÂ-wʞWoeS5Y=0Mi\wκm8cWRi2$Y&\Kf.&hU/C"b{OwhZJ8ŚĘ\/g}$ U>o}!QꯂKt[}'3еcV•wNyPͪ<k(L>c۩QM'lmو˵HD>2Ō_p?Ezv[!/;`lmyOKpG03ȲrITu([\)t3#'lo"Q"s: 1Ix`94,r(|~ЉL1 &ar"ۏ=JRFE`c= _;uY/d-3:a\pxxM mPo#/'m'XOՁ}_''MBD< 6M4h&{5X8ޞeǻαX]ph/QCF:kƱb%du?9MVBiOg}Ý~P5K}x"P&ZyͽMS~ =#K$@`Ex/׹_qX]_#:1?Ynhjq5剗<~p{6RJɳm#f}Hy[o+u\9$sQj9~^Ł"XAkvu[SgG?5$ƩŶq;0ҀCwkժIU5̕1@ow(IJ.2٥oFu21rۙB=H 3Ҵ)ꢘ|EQ\?(e|[uUWHvȂz^理c @V"g'Fje\ Sra7r&[A:7/ Q 'pNH~pꚰ_r::>zGLN9!&$X\dK îW *HĦHʓ>1ܯ/$)1ѡMKR?y^,v3]HzDU {8uVyw@ s& T@L7T.@(^N EtW[k8#J$>ύW NjwwuN.SZڵ@@Jj궼舰(jf*HEg&b8J܁l`5x,L<2g}v8ϳWHk$g(x;l[+[V٨LnRs^ŒpNY,aaGI! (;1..!ߢ](K |} zG[l|C !zk igPؕ+K0*S`$9f{0"6~ =s{V9^c~wv0OZ2eCh\ZC@Bp--\NM=cI7\ڭH]Lc "j<P9#RRd@AV# E oNMI4 MPZKE%:>+?IsL[3O.˼"o:6%\i"Z:`0v:q*F_7YSJ<)qZ_>L U*N:k0!KF[E'*]`rY\~_])2:wb#I: |VZ>JGJ ,\LTxxZ?^~q5Lsm1Ylgz- (-9ec1ɻz[D FH@2ًgvkNhyn%uvuuTy-EgP .cCC : YZ