selinux-policy-devel-3.13.1-229.el7_6.5>t  DH`p[q$ƨ=5O(2[1?NRĸ: lhXu_I$sG~A3 QەG=~ZRe*>  4z)Rxh+7: .D?+#>0F>ƒqх U2_\c`]@wHXgb3] | T,N; QsL*>[<[PCӂ;:5'Ne 6P4TC͕kdJtTp6S `*Sj"g%BaoaLTRge0#3IuBd|?i`%G1Mm~ʥLf7[]EY'uҳ4h0uiFQ.ġ;qedw@-fuM lf._ b7uΒAw3"fyb, 1N ̓#+9Tbn+[''91cded224b70b93eb131cc1edb59e70dd48f3d6cK[q$ƨfZϣc3m[DbdzE*`M xc9/`T錠EQa7j0g';nٔkf<C|(+;4wh0R`)嵞QP9a<91O Fv& CR gp=K" SwS,Y_|ۤM(L-#O:;).,XGY>;&7tp{Ixoo_";boUZ>w0[L\[inC>z>o^, M {}Wh*&b>2])~%9^P:dz W7#Լ֨cYpc8S“)Z E vI7k7휁ae8myM8Yz;1"0am¬`pQ5PH`AbH, Μ?Ü> Vx׿p=`XbJЀ5^jr>9 P? Ptd * ?pt  TNN !(N +N @N N NPNN\N   (8}9}:$'}> h~G hNH }NI NX HY L\ `N] N^ g b 1d e f l t $Nu \Nv $ w &Nx ;8N PpCselinux-policy-devel3.13.1229.el7_6.5SELinux policy develSELinux policy development and man page package[x86-01.bsys.centos.orgoGCentOSGPLv2+CentOS BuildSystem System Environment/Basehttp://oss.tresys.com/repos/refpolicy/linuxnoarchselinuxenabled && /usr/bin/sepolgen-ifgen 2>/dev/null exit 0p R^q'"-%$#5-3z+*I[+b$"""/H(7?#3J2*G"&'KH>()O63>)j&0h&H// =/:*8"-%FX n'4$7-#3jMw0>w09!B4%48*K66m3-4('<W -* .&.z.^-2.&3&l!*%Q$$FA":4955K*)-:pP9o/UG6.@)>-(252215<$?R.@C.;E&7e+4 7Fl%4^1a.OH$.>6 7=b,t2615w5O4 ?;5RQ#/@~!8}$q06(4N6j4 "-&h7%=$6zLa,I,g#1/(076E+~47,8JC95F%3 Q%!-S;Q5'-&5%8,+7.ahA;HBjHS6,1o"40)/`5Q 9?i6./&95754,!1}'$4.38A-()+CG%0./-4>679,C:p/#0r" J> +w$2; E{*yF`*c/0v>7l)4QQ+01 0)-y8.' 0Y8e>g';6(:60+(yBG".K')\.k=6@,6_a).I947Gn*I}/2')q!{2 &&.*.LN(C$#-3U)I*A1996V9<7 28BF/<260'(#@_-.K:`6&SW.&,9! &3XP0@z;1E31d$)00313|01(12RV'&6^.'0'22D"2D)f2D)f2!(+J-=C7..*h0xI!& ./.'[EE>h0(-&'W/.U;0AG0J,$/b=8Ez2 M)B'(7$6<=677\6S6SS''g37K)&0hN3!Y1I_ /(()4& $p%/BQ58f'$#!r#BZ--I0;;0TBM)H#0& $%./KJ+6J2r.- 4.2-03-@V55.1.5-7.]/7j$S5i6,549q,,X-J*,+=F0="274:..BCr>*A25G?//-18N%0i'2u(-*(})+!+y() +%$\%B=BW#-'8?9.$:04490#"M.^(Fy27.'q)IIK S =s + *U/V("3^w-:q6A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[ [ [ [ [ [ [ [![![![![![![![["["["["["["["["[#[#[1[1[1[1[1[2[2[2[2[2[3[3[3[3[3[4[4[#[#[#[#[#[$[$[$[$[$[$[$[$[%[%[%[%[%[%[&[&[&[&[&[&[&['['['['['['[([([([([([([([)[)[)[)[)[)[)[*[*[*[*[*[*[+[+[+[+[+[+[,[,[,[,[,[-[-[-[-[-[.[.[.[.[.[/[/[/[/[/[0[0[0[0[[5[5[5[5[5[5[5[6[6[6[6[6[6[6[6[7[7[7[7[7[7[7[7[8[8[8[8[8[8[8[8[9[9[9[9[9[4[4[4[5[=[=[=[=[=[=[=[=[>[>[>[>[>[>[>[>[?[?[?[9[9[9[9[:[:[:[:[:[:[:[:[:[;[;[;[;[;[;[;[<[<[<[<[<[<[<[<[<[=[[E[E[E[E[F[F[G[G[G[G[H[H[H[H[I[I[I[?[?[?[[?[?[@[@[@[@[A[A[A[A[A[B[B[B[C[C[C[C[D[D[D[D[M[M[N[N[I[I[J[J[J[J[J[K[K[K[K[L[L[L[L[M[M[V[V[V[V[V[V[V[V[W[W[[W[W[W[W[W[W[X[X[X[X[X[X[X[X[N[N[O[O[O[O[P[P[P[P[Q[Q[Q[Q[R[R[R[R[R[R[S[S[S[S[S[S[T[T[T[T[T[T[U[U[U[U[U[U[[[[[[[[[[[[[[[[[\[\[\[\[\[\[\[\[\[][][][][][][][][][^[^[^[^[^[^[^[^[^[[_[X[Y[Y[Y[Y[Y[Y[Y[Y[Y[Z[Z[Z[Z[Z[Z[Z[Z[Z[[[`[`[a[a[a[a[a[a[a[a[a[a[b[b[b[b[b[b[b[b[c[c[c[c[c[c[c[c[d[d[d[d[d[d[d[d[e[e[e[e[e[e[e[e[e[e[f[f[f[f[f[f[f[f[f[g[g[g[g[g[g[g[g[g[h[h[h[h[h[h[h[h[h[i[i[i[i[i[i[i[i[i[j[j[j[_[_[_[_[_[_[_[_[_[`[`[`[`[`[`[`[`[x[x[y[y[y[y[y[y[y[y[y[y[z[z[z[z[z[z[z[z[{[{[{[{[{[{[{[{[{[{[|[|[|[|[|[|[|[|[|[}[j[j[j[j[j[j[k[k[k[k[k[k[k[k[k[k[l[l[l[l[l[[l[l[l[l[l[m[m[m[m[m[m[m[m[m[n[n[n[n[n[n[n[n[n[o[o[o[o[o[o[o[o[p[p[p[p[p[p[p[p[p[q[q[q[q[q[q[q[r[r[r[r[r[r[r[r[r[r[s[[s[s[s[s[s[s[s[s[t[t[[t[t[t[t[t[t[t[t[u[u[u[u[[u[u[u[u[u[u[v[v[v[v[v[v[v[v[w[w[w[w[w[w[w[w[w[x[x[x[x[x[[[[[[[[[[[[[[[[[[[[[[[[[[[[}[}[}[}[[}[}[}[}[}[~[~[~[~[~[~[[~[~[~[~[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[cd065e896d7eb11e238a05b9102359ea370ec75b27785a81935c985899ed2df6846bbdba1149ef9edd39c6f18d37f29e5ed9cb3670521f142ed6d7d2bf9f2b8342d2c3aa4d008aad3243fd00e4723033e27e253289356cdf2cf9ec46135a8327bceb4f36b0f077b7a232a94e214b3b0a5a85152e4d89c193f92ddaba3ede1ad6cb41c91e1753ff6d4831bbad400f404526f81fc0e21c7d5019f44a1283d49fb820bb194aef56119a76904d8fb953036abbc9c23562291dcfb1e0c65aa2febcf0b104188d4cc86d01e1bffe90b4c63a12a6b0ad4908e068e65880784992155cad55a928e91a823458eb51df4520ff2da1f59ecc463e15e3fdbc482d9fafff94492fce31be43261fc39f40cf3eb7a0df466182d4df801ba83167b27a1b1881f40608ef456ffdc1413fa95d1df69c1a4dc3d4c199a440c3df94fac85e1f54eb2bc32231162c11dadc416e3e96491cf503ecde578aa8b407f412e59d8ae500796e8f58345d676ac655a2c56474057da0438c1c40879aa06bd0e46f04a4b01e628bcac1e4e83a19bae98c79111c7864c51a00573bfb231719da1493803bc1672c7fe8ed27c5246aa0ad448b9a5e603d1dc5392a3bc0680e53f1e74f0b68552cc74680d2b163df8523b2d9e2d5703051ee5a3b3aa5a12cb445a4886c237b3bfd01ef3bb385feacf74ab76fcd3f55465984dea0525c34df20366f8035d793c8685fbcfdf20bf7ec60727cbb8d1816d735e30716765c99a99c1b1f97c10024436eff60c232ff1f5de1ea967f3d1bc4bbd6fefa4dceb17f9babfd3d62df7ea70b470cc92de0bf98aa78494a9a0d593aeb62cb822e8a3655aef482ad1c7271be7d976be1b534268b39ecb5b75748dee9bdf2c5609e2adc105631edd1174e0140368743944b15071390fcf85116acafd93d71994d66dc5fe62805b2604196addb0c65173785aaab5795313527f4a971e6e0261f8924be4e20a7b6e543d73f4572ebe5b7c8a0665bc48fc450d113d0164f9867a0fde3f7d609046c5a51ac338547dadb18bdb7a59676e6c92db52bdf6c7623f6ac1486ea08830a5fdcd98cf1ab6aa24d2e76463ab76131319a9d6f5fcdd5d1641f4e1ba198b488fcefd84e1163964ba090f5ae71f28e5d486064d92fdaa39d7a5943604b6cb41bede5d076d481887bbc003e19f2bf6fe66b2d9ef5f8a5da75dbc3612cb9ed4e0ad98e91a5d12dc13d56c1e0ba9d19f27948d12587924d7f0cf9fa53e24f472bb925a2b50907b5e24093c2c1c163b7e2c27aeaa3ea204a21c035bc180c02e4e9c643e9dde0bf5b3659db7fe39aefa99fe46be42285fc4a21eeabb9de94afde294b03dee117bba903141d9f4b999dbfd0e0a0ccb9103d3e2a9930ff7dec02efb3096c1d3bdc1bc910f407cb01b9e7d1c6af0f1bed3132cf14f289b9c7d6b97d736d4401df13efb0e279486afd442fa19eb2736c2372908bd6472b9df15776d3c57d8a162db5650b03f30f8dcaf5364f6b47a1d7deff1b3397bb945f068837e4fd03f7f9663d335dce5459c5245c26ede4866914c1002dd4790cf75094de1b51012dc603dc90d3b4ee7a9fd4dbffde1304eaaf5cfb2ab51b5ac8c3837cc509aed5ed9601a047bd1ead24a274c0f6f117da44ac52f2274598149f446b216f38b4f9f1a771bca86e9157100780fc452841a327d5097f435acadd06143ff79297ae20d27c8570331865f7544349594654229480eca6e619d4fc8c7b9c089f93c9102e44c159d0e3981255c16299a6213726f49b53b899c6406dd0ea8ec03c55316b255969cf86f86299b11135146f67d701cc853f4362f332338a77c6615a3964b75cc1ad5391ba333c282fdb5b152c64fa3bf75784982b0bf1d9049d33eeac759889640372e3cbc3b23bcd51838408babd1df9752efb7e10dabcd345e326cd5e3ca887a24a0f648c2e14b546b4eab26e3396f217db2d58ef8019a7a1eda6582350590fa3baeb2e4f9792ba4063394afd6d5461abc5a672c532e6dbb872f71c761120ad4aa319e1f7de02c87dbd24aa12387baedfad3f073a0032abf7955ebfad12b5a698ddb09b7ee73d34020780e0dfaaa9e56e1dafc0052df70a21cb0d540a9a044718b50feb527c47a24984c47211d6d6d36e147f12b4009c31fa76164db839a28e812e33a0274d33bd4bbb3da98d8068534d3e1e109e661d428ee3c01161c0a911d144adcd24c430fd081d5073e6a521bf03ff7715ded2ad648d4269dfa1821e2526674bbc934a83b35e394fa8e138d7bcbd54ae75ef65109123fae6a60508f8cb999e34adeae7436583af5e98c2283dfaac350f3158404ffa13347e32ccedbe9cae951a64abdec9b3a6f6e2f8e90c9c2fc650d2fb7f3c9ab4a1c48f762494a6e20af1415bf75df147583204c6d17a0cd1568a92e70699e5cf16583de2f29112f1ee5265427954f7005663e930118d8cdcf0c77e2a74abdf26d01924992f5543d93055129e814fc08a961c8a849f1b7180607d3d17fa97da93527ebf6bc05d02ece763f60fa8cb7c032c435458acf17aefda17bc101fa155cffbbce4b410bca06736ee3282028713465de604ce6b4531a3fe6267da9a040b7c3a936b55797af18842dfb3deaf62dc6e0f93eeb69e227996630f2f9e928485bf964c718a67df45be0d2f8af061b3c0a8c3c092e1ca59998db1af6cf2099752d1846bf678d827f1170e9aa2fa976794e5997a4b931378aeceabf7b6428123363488ac8699ce437f1ca790823dd1cbe3edf7f7dd1c405684ae5fa8674c0d2654c23e84b4a1ccc594eeb9c5c736294ffcaa171a052f2d6322e205097c4e86cfa7672ae240f013bba03044104e7c7b8ab91f8cf66470ccbbb17bca15176e1baeb1c6015beebe8032ffa6c302268213ab3c49e7f88f76393c7cd5e899f8d0dda93ec5c7fe5c57fd20a88a4f37cf89967f8ab7ae1e2630557a58f528ae793916b2069d6648ad19fb2790fe7bec9e156ef491399530ae70da69b402ef3044a96e1bbe2ea0c39d7f652859aeae3056608c15ecd929ebdd38f501849f474514d557f18a60930e8ad7a192ac1fa3abb7efb687011781c82a9f9c5526b61b25681604482be010d038ca2c93bed4ff95b3ae8ac13a09d1ae6c8385152035a3265c2a83fe8ac2fe29b261900c8d58034e3fac9a92b2952dc987715a3a4998a9e1e4174da05788864d1d29383d9574deb13e4be1e1131ea4bc7961dc9ea3a2d928e353fbf896cb32082935015ef744de0cf96660c6de896cb0a165ea46cdca8ad3770770eb0ad58c22144d1718e29b4c93273f987b04c77fe308e247f770eaf8cb8fd3d584ad2f436d1f90ba3c2d06e168eed1272837e60651e6f66e3d4f5a7fe41b9fe7c51fdf54b52a397850acd2d8778fd38e9117207943cca6bd31f9446f0f6ef82979144e457b37dcc357d897d16ffd48740660278eee3139e08c38a5267f0f5cd0f4cf9aba7bf0ac01566567fc0d0ff1c9a4323d0eb49458eac0d394ec77680779b2c08b3a8c12722653971375598fb146ad577cd4f409d5dde608d91fadb598accba73959f13057f15f2050919d03f62a5fa74dacece5e0843c647ccb19e395a2bedfca7d6f1264b21697017cf8762283c5d37cc9a3f9a4a1270393a5016bf0b0e36fc2fbebaffdaaf8d006ec9943b1110150265dacd597253807124a862d8311ee534b437f8569317a97284720911ab4ff36e958acd0f0bdef9f1d132c1484a9f91abbc60948f4d94902a6bfa473d40c0f3af410461af3e40e39beaec3ab2d4e8f075761b1cca85f0713fe3b1d7c4b33a4f2fb986ebc4bf237c0b204ef335c5f8e216894fd158c0daed24d123cbb85107ae20adc3105987b18d5dbc62cef0d06efa45758eacfd71b66adb33277783f0c6860d390f0ed7680a63d9da39aedbb6048e7114582f85a843c8ef47605c12e205d25258a55d046d4dd79aa0e6cc2b6ac75953fc4e3ba358bf3029e8ac3f4908d90212c5ff799e2f32725e1cc8fedf55783ad978e17437bfbf5a3a31f7d7eb7612a78eea2bc82722c4bc8fa255b1b037868191af448ffb5842f531c8f698dcfe55ecf9ac16312f0957ea48b9665e1e970659f80598b1d26a407bc6ccfaa4a882406c3c618f3c451bbe67e1f9a2cbee682869f9103423e9e346b34114584dbe7945961768192698e19c7c7791efae84486ff7109c0ebb7463370a631f9dbecec19790fc5a141d333c558aa6f783def9290d99c4088f4d285d93afa352275824d4411a649b87eae3794c5039e70dd849f0270dcee986d5e014439934f4b4a91570ec963f992300ab35c1c9d033741a24e66a1268e34e0732e3175aa7f5a3204f0c4f60968256b8e1292c211a10926a759bfbf317e2888dbef86a0f524c79e16b0279b655c401870e110e3754dafed0fef3e953175337c331bc574790ee6031f48068989ef8cd3e5ab26fbfc8687b876e30ebcc4aeff53f00a5ef2a72b49f2595207daa2bbd02742e44a8e9b471a887cf3bf6fd84e2c951fdafcf23215ec8b0ecb1500068d0ae290ac5ed8b97332f2649d46854ea827df003127fa58e9a88c5a26a611399f745b94f9edbcf2f5d3af4e1a88df6673c403fa3dd26745a128d4db7ff195ab7465acbda2b0ef7149fd9de3da295227be04c732a8e93ec2fd3c5b982cd9d9031c3c77001089cafa8a559154eecf000e2229b1f9cb50cb60a33deca433b31214c252ff80afa4f70fe63e0c06ef8abc10ac317843596f5a627c4cfb533b11bf2ba8c3bea91a5dc4c4a77238be3338f28390487e7fc34da19c86e9b74b183556120478ef6b1def0a1802775fe461b3a0ad71bde18e22976503f6fa429df1323d88786e8f491c336870d1ecdb552c771a21af172902c068d951e862e75b2f0d37197d61e84e8543792348aba639c317c54ae0fefbd3dda63f724c5a80a33c1ca72ab9b4d96acb06d930a85e0ef068cde4e237fa29fcd0a279ce72983a536252b145339d27ae16941a242b923ee4661eadc1f7c20884b2f0d7d0bdaf71f931e84fdc72f83e1e8da7e4ce7ea15b88a5e552115382827433b16a05ca9accb1ee89618b50b27db265fcd1f6197bad8c3e619a8e6a5a33bfbfbeba30b14854f720c05caf6edf5a223070423d2aef4111dc0d37165bba9d6776c1086a6d4ac6e0f5bac2effb269dd16fc7496e86ffda635ef94fe70139b77b649e573c50b0e5db88951ccdb6cc8e6a316c4cd95c69aaee38334ca26f1de76b0d64be4068edfa09b071649bd6f1379e114b0f8a27210e18410119f9fc24b6ae4bdf9215ca6deb4974b4fbb10816bd6b96d190afca77172bf2e80accb48c527d86c2de4f3b577418cf4a6a1183cacfa5da51fd907727731eb271719e9509349f4d7a426c5e34e6d70c4e6c994990d4e82b012869f9f58084c022e4c66ec35ba5029d72efc576a9b91b924b4a2c6af8e6830d86afc317d0465fe36bb639c38167cf0071bf3a5332b127767e21434b70614b48a1142c32eca29453551ce8413e30f8fd152b5b79a6f1dc263ab60df3342078ef9f006b21e6c40edba8b1ebdd42e2088d400c4d5ad166534911e0cdb64aaaf6112c0626e17e787bb80bcbfe3005dc9aacd5bab3149da3b21e1ca4c3b276c3b54f7dda4cf106708d0b957bb6b370c9b6c0a2794f3c006c468957d7895b30528d0bcbe131b9f0d2a86cc802ad4091fdf677179dbd701cbc515bf988b135943233aadf75844fa8a5f71f78925bc4431544592f5b2c1a6a192d48c2d3afa2c764e2023c3c64da90b67429a796b39323f8a40116ecd904b1613f418fa6675957ae22b68e91666a5e1574dc597a343473005f9ef5d546102ac2a44e7d974b04cd5cde05078ec790527d06ee9ceeb74d1d51833de0d299f440194b8b1e6e52a396be59de327fa52dc8693b986ec768de39b9534ed63c7efead189e312adf62cb93bf2136399dc1225fc2802f397de432e6fa99297e5477ff177337ac70411e11ffbf9521365755d9cf23b0353ca655e0c9eeb2009adf87a2251dfcd2233b4e26bf71aa3775f8ab95c6ec88162f9c1355cd0d8d2a531f8d1da0e46f6bd7aa4ca7107fbad0ff64cfdd2090ad24e0d798fa0f052e0c00fff1e347fefb62c49621444d6dc520b8e806b3dfe333d579d5e1c5b33c964157bf2cbc9a1612dbccbc517d78321a1e7ed04d5fd1b8bdcc53011e5b97279a86ec1df93f8c6760b127292f162c5f2ff9e7731d692255eebbcb82e6847941b81fb40365da6385a0c4c590014826f3d77419f4ad3e039fd805380b979cdcd7a7b81694a580738b2f3648dd688e9f1e46603f0e0d94ed31e744bfbcd76e63418462e96a58ba6dcc36aea77fa7f25af9b3a9dcf661eda3a5d292902cd6de3052317583bcefb7bdf4076e6d3ed88261e18f1a645b8689df2a9eed4d561c476f14cb5afbf9756f666e2ddaa611add482e6c7f80035ec950a03da87bbcc3173f2a3c86d047e3fd6c59383b554e2cd99d854459de5061c197e15e231f058867148040ea43a84fa4bde7f42243abdf8fbf367dd4e772d50fa84b717db81699003dbade02beb78400fd24fc3d34714d587301bd0f1d525d5f0a869bcf34042a1bbea829d4aab05d817872d9ed883205e5d160bdc2688037c7f0a858fc077b33cc55006c0a9bc7b8889abb6987e3f8333712433a665e587c74c31322b4ef561a87329b671cf8a78dfab03988b0384e8fd31d44222cc49222a7a69b0d1f26cffe3c9933f425b2a788a8a2bc1d8b0bffcca162f0bb1e8b0cce585bed7eb9c6db6750efc4bfae418f03dfca7ce379dbb9d2e1c1b4d8d814f0acdbda124eb09643ba6e9dde04626686fa642e49186dd1b76e52ee53cb3d059dacb0e25672b50c30f0d4671f2dff6816349d8f517cf7a6c22bd7a3f9f0d38be4898cc97262d22f4a6027d4331d19a8bb1046debe308725f4ef93c0f66254f8d61b7ad525ad4b2b7b0e1e29a9763675cfd7ee987b97bf93a73402dc5ec7ac43696c607c4f4ba21ee333735f21099b4deae00a3bf9054114759ee9d9074bb9d813c5286bb674a058ae6fd30237db47470a28cc025d6f8933d9095a79af250f3b329fb9e4cf7f3d57e607a24a1e090d627da165823c5069820a423fd761653ea6434efcc408d43db5ed644976c56c4a71db6d56a3914699b4095f57ffaaa10c92c635760cf60eca7bc31a16e165fc8f667db0c51fe13081bce7606e47fee9834b5969a176c0c259d6ca9eceb2c2fcdfd1b97c7966eb71f82a497f9ba906b8bf03ce440f2946f4e9909c76a6823ba777bf4e3aa7004c93c98a6a370b817a023b1cc991c7c11ad0142b35a3a9f328de45e6506aefdce66425fd6bdaedfadc02e0da3e11e1c096895c3ce93ddefb96296e6fb7975034822c91b0079c97b900e463441364c980a621f5abaf8ba4d9029e8465423e1d6ae3eae60eaa1352b8ac1de2712ee9abd98ba90f4045c4aaba8f152e1c2efcf460e06ae9d4d5eef3fe399273213f09aed8e2eb6f01d20280a06fc008bf7f471b5acbcd0caa31d2af8c1fa2fab60ef896fa4f17a051b67586c137e5b130a597c5a118f9ab56d028c66dc600502177cd0b656d73896090e0da89766289b30e07b99f2c8a845600b3dacec63a5da3fd2713ab9adfb72ea66cfb7b6b0b94bf30e2ceb27df6c185aa2fe1e524234018e9212e31b584cd34a2700745c52c54265e7710d335051125e77940cfac3d194d68c4b998c4d336fdf2c8ef7179fd9773a7a824aa4400ff65262337d6cd48c4df7a6cbbfe6fde46c6e284f1d96b056abba7e08fd679f5affd871a7674a8749dbc1cd69f8d72e0b71a12f18bd470332b11e5ed216a50217c5c167b536476b9a7a3de8879a82d4fb487d8ded1184fe4a36dd03bb62aa7998fd8fbd86f038b4da773da1e241bbef6d795965de34a73246c68e16fd7c38447136eea764df48306652cda4eaa2b7f38cb58cb5f6f28e73b7f919c645389ee894a71bff0cec8581454684095992e94a50782abea1cf5a9f99dd9a3664b40844b307b411d26aa9179f2652fe6641c6a46fe8e4cb54d2be7cd393de182cb80306c716f42a9312950bd3ae742d139507c613da562520f316074a91b880da7149ed2273e5c36b4c0f36d399ffc85cfb436d9621aeb949f2ae395b1d2819ba0dadb2eb5648b95d72a222e2e66dafbaded2cacbade917ef449ca036f8e3ff86bd926520d6305fff95a1ca42e6fcd45b651f8639e51a6bc8fccca408380f16f794f5e9f6ac95e7c174bd959f732e3e3b61077e5ad254dfe205f4727d9149684abba9d78b5252b8fe8edb06613e35b11cf0a6a6885ff1ce8bfc9a4318a45114690781c488b319b03388ebd5e7eddf6eaf2ddeaee85d121980ae6eb1131cb89b565e9c5543d667eaf26a331928a6278e253093d5ca06a4d1279e1e7bdcd94868794ecda29beb7da46406c24e3b03ad227871375ccce70c1b2a3202d9ed5a2abed0088b1673103b3f24139a05a74dfa5ff189f22f76998ee53e32ff188c4953d36a1065f0d2f61aff052af8f22b8c60f35bf45f638e1b52fd99072f880226bf54ec771faaf695c4fa077ca93e1b59215b55a07b330c17ee5338cb20f69c1fcc2cef444014f5a5c77946a59d982ae987db5348bc2f5c915e6ce147f66e828c357137d03ffaa6202e9e54e8faecb934348940c44332e39f4a10a0b49b5d3a00ce8ce2f32d96e7af467f1f14718e970994ce582b5da82a070f06a2210b87b3ba261bcd2ef4a33ed48025e032e76e36141b27d9711c23c79d8841f0aa73776eff7a389047ca630373e44128bc9c584aa4140ea848cc9ee8679cfa478802788b07779b89a6774c33713792a584c271f3b6da3eebf2cab4122559430f6b3e99ce7fc66dbdf8b7ed62cdb4d530d0b71a7d4edd75c394642a54253da8805a746502eeac788094badf02529427ed312befeae2ff2e7f024effddc7875b6de8e5c2ee1b668933ca6f1eb77a557e72c7dae53a64a54029b14295591d9db8451d74f459e3813c47f8c2d0a5243255914ec3bb7d3d35b46413578983e9e5fca35c695955071a7ceb88e26c37f6f92a03055a8b3c422783349ed02d54bce658b31bfb72e9ab43d0bd055bb259965094d490157202d973099d18f0bfc5bb12959e23b2b34c20e744d67d6dcdb944615b7f63308cb9f2733f1c69ffdb9ea2bf56f14b27d0531ca4ad3976850683cc15707fb24900e675209e5a9946e1f30e357148f38eb5c36c57a1a76ddfc349d04aa99c4dd3b775e9b278107357a81e90789b066cc0e836403256895bcb75948cdfcf57ace3f6a9aa0f2ad9ae277028ce84dd8f0db8b3b104941d75889b78b0d820594c632a400e9ce01f10d8847c4934b6b91f40f37d1f6e30f80fe9db80e616c31372ce23f2b991adf1ddc95321631f9e9b720f0af8122a01c681bddae451cae5c4f530ea6158b8aee3b98f413aeaf9167a85a92833fa25b6f2b2e27781d5a0a6da217b45e294f73dca2a7e96cf94b58571e034d00821bed73fb7c734173078037673e4fe2f8da9967f51dd09e6e7a9361650c7dab4ef420ec04df75b19000128bfbcaf0df44ee6093c1601f5c6a2ace5b206496bab62349af468c09b551ca7008b77ca298c3b459d19dc50fa9de92ce42953d150671ce4c427433fa2d28e8fd78800e9e4360b647e804e8cdc880a073e168b344ae92882bd9e9755a6866b88b7ef2f5bbdb30218de37574383c90837c2fd4d4465d6c295396800f38992078db069b5c18c75cb95824a9b79f704e87d8dbce07b53b62ea2e1a0ab94e1313a5850afa7820c9d4c68f596346decc0102fce2285a65e925decb59b92544a2dcb933734d4683ad9ae5e11b0ef8814c7a71f6c169a0a15bc992731d1947667b70374059079aca8bf2b20bf6c7e1257ec7997176d84936ba10b94bb22e1fd986364b30119ed8dc3b080063a254e75a09a0241ed251e63fa9185809771f391c6ae73cdda1922450009262e8b2ed0fc73fb612792e290069236f69277e23a17be3e3c91606d202c0b9d543091faea52e6af9a727837fc561e5bed48ea14456704b3561d66888d2e9611c107ba8814176a1e1d27bbefe7728a9f6502fed711b83afec2bfddb223b10e87cac401f5e6fb96ba851ff57f04940487850c12b37126d7e946d1d60f3907f812d289255482d00e4d9b980bcac913c9f7b8d90d03917172849aa15cb1e17330b4d06aa3e383da2961d23ade1f213ec027017eea4aeabd4f259bd38cba50c705a54a37cfe013465232d0ba3c4bd53a1b8d3b1eff32ff37d5cc7686eec6befed3a64b7f421f07641fe046acc2435d802d0610880cb1be04b53da886f01dcba9888d84a772770d1a2411e9f0ec11238e7021236b6a93efcb36ccfe04cc5c90ced52024aa7ed7c57d5d545fd38efd87c8b7141d8271965959ddd8df481ef78e61abc29e02c405d4a940e4a3cd5c68598a2a73f0f809c5c766b453baa25711f9329f49e37afba26775fd44eff369d0fc8de631111216256bbd7c37a7d313bb76b7236b2aa2ca192ba90ba4cf2935fb3f0802adac24bf1928705beabe90c2dfe907a40fa3315d18ef30d806a979f499097fc30b7fb25d48beaf460df95b1b1d1a9fdbe12d4837f1ea6271719583e69e803639ac07760ee5cc01441d5805ff11cb991be8522ef79de1cc69e4b21989a801d5149553d9f9983c2635cb2c65e1760b26ca953ac3e22a8032c929bdf78977c70032510398f1a6823a30f44e6a11b489c9929805a0d096b9ee4f1c238e3d998434a3e0565082d121fa2d9ca3626b1a1bfdb85b5939888ca17498e00d117fc5015e37bab044defe3818bf2cf69bb1fb7226ae390bddb5b9f6b11691ce8c03378b9fdae6abbb460539ad30e8e9696f936eed518ee81df4deabf7d1b75462049abdeb51fbf5304dcfeeeb23eac49405fb6d63db6758f469aeec420c792e25776281b0c361602b2905359ff23a479976df528eb65ddc3a40b74cf6fb0486ccbd46a503c13f998bd587a9bcf75364d760032eed89c0c09f5878a4655901a795a65ca8429c1d86317b7e51f58afb9f275b38f44783e58c9f6450d887168e07f0d508be0895faddfed340035e5df67bfc868f293d9d2a6153f444a4184c1348d67f7ac3e7c69e54c4413844da20dd0f3174faca22971f23ccdb939a4bc2e70fee7dbc9dfa326119bacd1d037c6b017d7fa12c6253cf7912bcd1c14d42952c4bc75ae67aec2c77976ae4a7767ad20454f9c98eddcb3f97e2affdead33d99fa3dbe23e3680cf132d653af3ee48df05fbd07af805b2781bc278e412c9647541cdf943bf762c2c3d7a427a7b02518d99b5cbd7421b23536cf21860d3b91d7d87ccd469032dba39d9d02c77183d8bc378425540c9a239f3a89f07550a0812d9e4386e04b9475bda6a1b9a41435ceb6a417a14764b862b84936020f59f3e8460e97c52b767800dd0ff82cc904c09a90a8384e6432834c7d96c0db4673bbd1ae7a3f6571599cd3dfa4e015432158e0e2be43b10954e28da41346ecca28f955e9e6801badd0d12f8eb8a513f6b6d069e728bd8c4d820dec98725d069b008a140d87cc5eb3d11058b674781f3d8cc3b6f5e5ee53d8438d68581cb4dacfa62f496fbd2e31702eee4d63a2a27470cb00f85e95194ec54b94dfcaf039e255d97f05b6c81c7632658929d6accdf629f367674c24bb097ea72e09b71c8e05e1de6a0d64e702330328e90b40c9817d8aea0094059a8702db02c1e34f36fc8cd9b7e44ea9f95c704cb9ca92b7edec1cc7317259556b8d7c52e50f1a9873c1bd63d01bbebdff981bc1370735331a04f2dd676607d0d0923fcaa90dcbb4293ee790374b542c9bf16c5115a72d752be509adcc5a1d120b5a14b8d382c6273bbb7688c8e932259ce933ff5703ae7ca00028605e96caa6ce132d36fa9dcec0ff266fff2399d9e50b0edeb2431d27e8c8ea6f90bbea2619e82f1c6c8efee35780897e75da6e103672f5e3cfa8843075a549560c871e04b5b1fc8e8530742a0b50efc41bd65f774f9521e3c92682d953ec594a5e2c233e8e6fe1537a0c38a580a92d631dc1fd0212d9097e6f6afed32f183610d0d0df23df722432029b45d25dbc016cde1a8dd55f6b733f5c9df4e49e7aaa2c64a6873b1ff4ec4cb6c62ffaf98c71efc2e5c6fcbf73317f289938d23592db5281fa8e0f59a182f03006d9feff6c5ef112a0db392ce6bedd460b299bd4aa28aab9ce35e89289fce3594ab06918105bf028756c74779346a5ab8624650cf8b5edd1c33df72452c89cd9968ded72c1028a71d14b894175764637734f66e60c6e672dde21cb93ae7a40b2b90c2458184fc93a97718afef7b04bc79b93c5211e397f21ee53c874a46f4fa4b6a1fb19b92f86f8f40d67bfe9e08ac4fa7382b53fb141d9fdb42d6006a7ff84644c7d883be634b8ee20e968c62ad879e49fcbb04191af80876d0ba511d6549f497fa915edb20c5916bb8f8e816d599e3295b974b3d5afc7e3e28d563d92c65d79c2b856ee5a55998f91a3665226012364ec477b950b5ca89ffb6f6b19ecd512c4d19b3a8a0efe0fad41e2f0f938fca4f96af4a0c4b4b3f51f53b065a0c00011621ee7b5b6d8b96bd02bc71a52a28e27cb8b2d9e93fdfc636b5b796b97e3c1bf7d355d76c6c89d0886a56376845133b65a399a9a8a28289b7f6f29948462c987772dd1fd7f5161849bba46af5c07f295dbbcca2ad12ac93ac61942c00f7b4d863facae5f75887f3d32f057d6d4ef069213103d5b534c3f3057608b256236451af4e85b85d55ac263e04e8a409b2639361f4e7f3938543f58634544f3001481faf3ef22032aa61e9044867f0a554ff0e40e70e1b70b019d0e0b413a72d2481a3203474197439efb4bed6b20b37e8ff2fbe941e31e9688423a9de81dee873296cc31279d82729486444017a5b8062eb83c203382dbdab40af76d6f11f848d4ea5e63b70c8d6f995a0d4d07dc430b48480c7dd889dfcf1a27343f29602b78d8c93ef93054c8dc936c54536cfd22edfa6117a15d353bfae93dbbfb24f0c02fdd610c7b2ad6be1e2b5dac324cf1fa43dbba902abb830871f1b44f3e3ca089722bfa99ff91e68c770bc777d73c08a57ead53769aee06e7851743ef09c5e732635217f5bdfa1fbabb2263bff88065a4644804561a4a242d7ec77d28024fa43f4cc2516244a4fa84dccd439123009a856f787c0fa52befb2906fa8a9c9adb6e6b48c133881fe3a8e39dbebcb5379d400d67bf56c7502e839efa24e4f78b118cd6537dccaf6dadca01b8d76e515b59540eb8e01004cc6e6d222be0ee96fd07600d2bed5fb9a2606d7e81d069a98a6a51652b808c7822ba9b98519dca34460193a20a36523cd76288d03d2f990a27bfe86a30f21f34e4c6e72aa8feb090a2ed99fce0b025165414ee6383fa55f09917f549786cfb4905d888515c73cdd5ce3f436faaca520dcfac46fba9ba1e802497ed67bdf130ec2c96608b27d3a41c3ebd6712c7bbc778cd154a3cbe6602347a057ad57f865d74dbad236548cb2a4704d0c4e0585792e4c1b3a164d4200444a136b250527229f3c7b28d59118d5121fbfa564503cbcdecec3025e6fe591526c1fee720f41be9d2158bd661f4c8e781027cddd83e3e1457dedd65750a785f0605772edd35604ba3f36232bdd2b56cf294eebfbf1f26f044caac6ff03e9662bcde45c7be6c0e96f5da75586e82319546040c3c1d50ed9982ab7153b3b3d29994ee813d4f1d2115951ff1f632878e650f60176468e5facb22ec23d8c1b3564f9b97383556406ecfd2e2df4d5b374a30a230b07b18a70313fe811c36da0e3bb4d7cf89be7bd35b90459633a9785fda813417b1ad57d2acdb68193bb4b3a49e80c80f962b1aa7263464785169057b153a7daf42a13fcd0a4ce442b890aae32aae0f70b767a02a153e575ecb4b3cc902be97ceb767a23e2192c397225d12d8abfea45a303b2b5afd9decf82cbe1df153b3373a143b92c9ecab109eaa18a69b20fc31e8ebd0261f51c244518cd339682e42155189a271ff2abf60018824eb4fa673d7e08efc4f51440e9328216c222e7a322338940b9e628b51c92095cbe064bbf42e0dfd85f7f792f7c134794f5fa507925a1db3d96f1cbc7072882c14c78404bbcd069db415e2b60b4d363809e54ad64a5fb29e7f08cfbca0e1a1e3c881fe9db3dc52ad58932cb2572747492894b3fbafee6c332ebfa84f1fcc3cfb6b38668ed2e93bdc43c1750581805a5f18158bd19ae136d455c4c2e59e66fd19aa8442acfd7b760fc851d9e0c214c39b578690326342c816ab914e854dfef9e803afd54e5e177fabe71e6b2711d55489c2d6472b5b363836c45282f789b32383d3892751f057a41b8d143371788b0fb964c6ff9292ac64f814d939385437a00e247801bd8691d30d8fd9a773aa10f4eee8ffcd5493c32a297fba74de9d21d6d0ebf5a417e54c632db37ef6c8559766e108cf57042544976af3049739d50eee058607e4ece93134abed5240a0301e7ef01543b7b92d7f4e4dc124ecaf77028fa7f30287ed36e4709bac6a668fd530546351c9b543f39ff42d6373269afc971f020f76405b892bc40ef02cb13d4fd86a70af7d17cd16ed0b3b7ca0a161595c1b76c3ff06390201a438de6885b54dc0503acb35ddd6cb8c0a74f02a9db375be4cf8a6499056eee90f8255d73dbd3b8c9065c6550c1349d5b93ef52671ae99e96cfcfac089e264567805bcc57af092880751b14b5ce897d3fc34777192a9303daa0980cf274e4285283612c675e73dc49cca0e88f36d29e69c206f3244ceecab78346c017b308a35a5ba00d46e02ea5a55f2cbcfd6064f2d75f0dff74a22ea2dfb1854c32d574bf29e0a342b4138f3d0b8670cb4290849126962416edf731f77d0973359cd6b03fc8eba272c0438d068052c42e4bf3e2036e12007f63b59e923f40469e8b974181c2f1ad99ad2d2021eb84819ebff110048dca8c307f5b40ccc3e8519ccc03d9f479164d07e7c9a43b764075dc66ce9a52f83d03c8206c9f9d07f7da1339a98f7f1465f7a8e8b48c70425ce82db35843e95574132b7bd5c0eb6ae5dca5e8c4051cc1c73760bddff9e2e8f974962aea9ecfbf9ec10b1922d10e8939433098297151588fc007f0251bb4d6357b0ee903628349dff66336c151f7f2842a5f8c730bfeb6ea4daeaccd06a9f08a1dce234ce534ac118b2ccc162d75e3154b358eb98faff57e98123557d08b5364e2de5922ab06976ed42135273702b34b5356c5487bc5cd92a5217ea1fedad0955fcbbe93599c44306c8dba96dd4a62078acc4569a3dc43a4727c38bb43c4ec8fdbe9d381436177497ae458b55183ff8039885bb1a8e51f03e8cb69d7236f71adc6723611b581317be3152ddffc695ec885685e4710b239a025a9ef829e341278103a69b9b59f5fd76dcc24fd98163265f35b00ffaa14b266b837f1b62ff183eea554a82e68cc93915ebf48c286f8189807db127b7c3c2eb515fb06f83acbc4292d03a0d0e53209b2e1b6836a0c4354c0981b347ac0a47660f52d6a37f2327362dadb9f6dd18a4d0a3cadcd7512acc2646dfabfdd278d8b67b22b02cd695caa7f0c5a447e52eb7814b57fcb4fb8fcbf2dbb08ac81f461d8f2fa04d400b5d0c1a3b4c9d8d99ad6b6a818ddfe1a83fab69e4ba465767a6806400fb4c45b30f15bd4bf1207472315bdc158804ecec24060e8f2c835c1eb0802d50a45fdc0e72ebe8d98deae1b86dc8e16e3e011b47709bf7887a7d296a0525095fe34dcd7b09b5fa13bdb895138bcc1702a88150b8183871a44f5c76ef130d73af11ffe63ef91b49b63f9ab37872241a01e0b7923295369e19213f8aa68d106615d2588d839b0998d08c5da7328bfdbc08862dd212dc643ccd187ea17180e50f106ec45a7f8780f929951e96e34bcead67871f9d7e77a275fa044c9549a16fb133378032b34bdb4d33c57b70d39b939cf234978c27fb9e87f960292784eff4e666055e9c7932489fc706996c7438bd0381d06e0f123a7d3779bf3111eed98ef3ff2af26ab2ec70c26dfaf429a3eaf8805bf9cc28b2efa1086bf17648243d3e7ba9f647d6fb748ddaefa70bd2058e3a97788f162df43064ef9b8d0d09f93745fb4ace9cd6b7a1a6aeb38c07a08e541112a5ddecd4938d330c9603a602e90e32004c74c04f3934c248a4268c0179e7a2334f6df7200ead8d93fc2e8d9e16addceec9024dc03e81b6a53dfb10f767e970f71e5e966235db91d87f9f0eb9b2c30ab4c377e372ec13edf76f3ef7635ef73498d35ca2d8cbbd2f2cf9a5871593659759378e702197a77dc79f33231f73ca6c999b66466975fa69691d391b73a042e8a685fd364c813f1058492b2e263083fc442b499800f99e26e2724d8cc81c9ffe11ba1e74e2f3022bbfd45d7854728ed9ead10739b56007a17e74a170cfd9ac12b2aaaa0bf65a4f6c1be902da252a097ce93c0bbf528e0efe6d80bb3fa11ee34d780924989dcc2f1ad6d7c5003d33ada569b1ac2850b7303d143f05372b924647d1c21f0173076715b4d3c1bf408422254d0f87dfe517ff31c6108d89811cd7329a9b0584873deb72d2e5a1d800972e51a39cbb092e8c59c6f615c51d7bb97abc4e50014c1333add8faa1cebff14ec5f7731e33c23864b531d0fb94d0b7d759c22be81ef4da5fa920fb62ba07a80b25dc7a4af507d05005c0e0d48419e2e5cc17655dfe27db5482f1845b932dc0904a63d7899a613e8f3b498d716a451a844390075d8aa7104be2fc4c4a2c261e671a3a981bc4ec953e2e6b62781fa7bcf1e4e0cff41932da773a207686e4c896602c8cc2c7fb3964a2320a30a1c66f9b84adc4ee8fc26a8d92456ce272cb0ab0c7c5693586bb5411f82a14de7e6591dd3c4f58dbb2ab37e749c97ae1984a09b6d0b58631dc071dc7bb5d207c81f7e669a716706d9f95ed135c97da4ebc0c3e138e61f4f8f2d8e4a6594ebb1b2f40045b5e4488b2c700294b17cea0faea9a31857b87d7e260555b7d442c5d952c3247c6f2f3700dadf7f8c549fffb9bf374ea79d703133cb8bcba0e768e80287b87cb05baf94c668e55d84e0683dcc49f89e23be3f4c93ab99e94c2edd3f8f8d914c37a3c037f67303f9fe2fae5c3caa88298a794de30f9ae0d047205942bbc6ef4b43ec97316a1bff0458eefaf1f2037adbcf26bb1ae101d571c836508b5ef53f22f40c7a08a97fe8665a76eb10b952bb2f1fbc554e4dc701c04de7dba3f5fd432fad5ed4feef4e70ffc75f6041d5e36c88529ea5f57732d6d92e72a614e2a3b2521013d9b4e16580faee391828b46e3330775ee2b6da8f695a7ddda71f2b6ebe948807576cca31fc4063502f59455e782326623294987a1f7c7b8576c174bef75572dd04a21a059dddcfbd6c979465620c724b2fdf1319941ec8a10dabd4f7a9adf2696b65df8b285cb3cb7f5ea47da9b2e27351b3725e1c8f692d8ac40392cad1b36fe5e1805c5b532c96d4719cf27615c301d0b60f24e007f55ae6115cb0cec721c9531bc92d86f3e5bdf3a01fbd85cb4b0416447eb0228e4c12b555690e8ce0a933e33beb8a055fb4ba2dccbdaae60ad6ef0ba559a815a1465cf2b7406e00352f18d949dec76aa25abf0e72fb01f23c27b1991ffdb7bb3484090ad31e899aae86f50b7a1766c61465f09740831004e7339a2876a0e32af0787f28319aa55a9f59bbcae9653b28bab8453c8a717b2d88b7e63ffb15fb2b7b73d160e7de9a4c83900ce3ce30bb3008ccc2cd778fa611de36ca37d195765238461b3f8af065a22dfc2332f47d7d3e83308e82c094fa07765e0d61bd2a8ad6b012b98dc80e99741fd957f0fe0105f3f596a7f5fa6fbfe4f496cb78d12159f8ee4d4bbe9e61b01b7f79a8d46e6c9ab4c5bd5146e16bdf70f5287c513cb85a2cb70e2ca2875477632a885e2441a40e6f258395ddd2e7eb37fd7f356791b186746c8e6d7ae7234c4c69cf52a72cb73aa31086267e351c11b35919df976ea0c1ea77211fb5f10f76bb8c65cc054ed8005191366e2a414ab70be582245dfab2c7122db0a64a7e1024f62084e03dc14332d661aa45d30d3524eac720e3d8889dadc5a896e4dc87bd4a086058cbe8285e345b1468b0dad65242fa7259ae0e9161e2393abe0eec522ac06d27cd4a4d0a5bdd2191abcd1c93064186c78e7b0725aae83bbb1a3b777e82d7019c6e11dcdfbb4a8664d93f32bdf82bbaff3e50a0aeb433d2dc41ff57709a06ec06aad8e3d406f9bde18c4429629c93e00b419f5abacd54a126dc4b531ad1d2a9e63691e95682dbcbf4df045edbeef762a8e8a998fc6b265a74cf51607544e30e76778530449e494b7ded008bfcc2f0604d7595501b07d238c2da85c2a08fd1f5e1e261ed3a8c7e397878522090c7207d2044c62e9d97ae1f1557c5c73a5f1e6e0a69bd291a6adc984392d125452dd476ac90259d07afe3f114c86aada922ce7bf4271ed97d0f76c50f87568bab1e3589eb8a09db5594c84f7ed2f913033d2e0b359f2ea646b1708f6b16421c262708259a2070115184fcad9383b47577fbcf3c9046c2c2aa56f7be86ec7b09372142114886fd907c128f50fa998f7f5191ac9244ee4eded8fc7e3ba72341f174be93ff0fcf246722861bd74223567465ea336c05690495ac4efc018a3f6109dd9b16d8f88e4adda1eabe82adef03d811cb1b1529f514243ff1c33ec2c3349f44b9bdd8898eb23645612dc9ee2550954eaad4e50c6ad2e1991720c98d1d008d9a0d88b9c0c7662fdb1257de867f0e4927bc42842ef01c04f73dabfdc7b0f42c597792399573e73521c47158a51e1cf8e5a1ba6deabe475c0677a6202b4a3d80da89e754977260216e10d7dd0a4d39d51eae8626257826d1c6a3c29ce4d1c0e9bf64a6ae2a1c9d02323ac8455c224879330ed0b982c307d17dfdba4d75d835c3a1f78ff2362b42c7ad55b42a9a52d16953b755db37b238675b6ab4c895034f8593b761a28041ec7b7980d03c3c99d8eee0ecb5920500cda74d3f1b6cc38759119f203482e407cb40c345e449462c0a234e74a57b5cc3dd24509898b2f22cb090723beb9dd91b997610f8d869372ce57c117aac532897634d6e4c544686266ee7aa8fe9661474d6d553d97ac73b9b56a54516214bebf46d3cb381062421d679504ab823dd04a28c59a2ed9437ea2cbe4d0d9099c60f31e08b26ccba70a3bbb84c90d84da8c3dd08592b409f44925da98a7e3a1082ffede6a502a26b56301e810da2ed38cad9ab4cc40b0e37cc12c2d6bcf5360d7289bb8dd9649e9c24d0b7472dc6ea6a683dfad3b8c90698bd42bdf17d34d1e688f52274406151889f7b7a20a99ff30d21c34ecbd08a0784fffaf2007d2233d2ba0c3ab3a3d2b47db7e157a06b97f9a7bb3611b44bcb02e81e8f4d62a7baeb9b5ece046031865cac20cad716efa4af04351b9748082bda26a2e47720568141bb161e0cf613cbfde8f516107ac598c47e41e5c401aa9ac2baa758127b6514a315cb72429cc7b96cc677ccf47d37b92474f0d08c56b4120e331a4b715f982cb59474309dcc2ad98e4448f5aeadf5d5932bff838270d0f002089b4bd39525cdb93dfcf53f8574e982078682248bf337e374c7fe71f2ce093d5a8d83a4a5357aec4ed7331d4b03e6cfd42476e413cf4905fdea0b4ac51fca5c753cf6922f38949bda91ddf09ad086bfdbcf119a48c4976bcf4d27ce8989576aa1344ee61ee5998c5ddfbaf04ad3a42b465a52806a6a46b426dae1bfcd92986a61297da67f591a9995cf16b19f9ee6b9947ddaa5a5cb122cf0d0cd2615ad21e1ad810cfa3789ea33de7d3d521e6bb823b61c749270ea2b4b0461dfdd274c09c2444a5c2fbb9b153aaf110e868646f04c941462b4291796264708d3f3f51ee15ba13332befb0438180c6db41590901e820dc07d95193ea19864d485dab18f2abc3fff0d55b15d8e328967d7614552d78ab9e38f367c75ef237bc18d0c9f2ae9fdb5c4763a4353c28cbb844f6324ae8b52ebef1a8f4723611042267499df04222751c0b4d0c7a37e4f4e950ae5963515f539112e3bb0276d50392deffbb1ab44d2d72badeabe91b5143a11a03cb0d0038cbcd4119c5a4cb37798c14bed6c7906b050b60cf5e82cbf49137f03b8bfc8fadb9a6838cfa63053076643848b79113fb7ca8d8cd8b2ff41f5df8097f4aec2369584b9d8b567c982ece78fd574a2cf0a6b793b18f9b5bdb2c0110ba4608094493f23f1a59f95a8c98562d61bec1983127a306b0ccde2f4cd7bf67a3c909c44eba01df77794f9f6c1539d0bff4c628a4aba7b83a50525012e18b31050897e44637fa2e48e2cad2a07761921bbd78ac53920c4cf33463718d86cf5c1ed8dbd286e5b0aedf2780b4f8833e6716ed24f273cde090258d19800ba0ab669316de649176315d6fa0aa9d089c25847284a5939d82a4463fb93e99c4832d7b058038c8ada70ca2f3f2980c9f7e28f1898e2eb311dfbbf8ad86c5362d468ef012aa0d6fb610b99d94b0078ec2aeba73f0ed06d6388be2d083b8048d043a9272ea65111e49dae77a033d3e95985a5520f8f077cbeaa7ad748b4f19a7578cbb094b77d857b3a8a5338d456e90242d525c83860b590c327f834e218fdb0ff47b9a9bd0c5d672510ee28b591901d69e49027ff622934ba8ea18ed113f5b2435f627bb3663a32c36069c2e18c7067d5e2ae94388154d53b6522455b5ac126c1584aab347db2684eaaa55a2f2d6aa081c11d910ff7680746c7157008931bf73845f9626e1639267eb67283f6a6fb25ddc9d4867f8e14f1081223c3a8f70cb3330249a207b253b4b77d0231429460be5d3af4b952e669d33decc66c860285d058ed883c12ea33b17fc1192841c1c31b36525703e54f762b4a13e57c948a662a4811800f30cdb610651e8e1ffda37d938b430e39f89aa2c73667ab8cb3fe40ad907ade55ad812fcb4100466490631c6dc91670e53e2cf566c4d4c93b34baf8733ad29ad38fa98bfa08e02aad00faf8311bb3647936248f60578ac8d71f93b4b0fef7c85f76527da5c31c40fb5349c2319b8b4cc39d066d61708117425876a588afaa5bf05adcdb4626ddfe807b7a37c0dde897a5d6a1412b4f936b8ff3e64ee0b1ee6121de4d749a8904bc8fad9af2f059ed52a21b611284645bd84f0345caa73a3a0636fa42e2fb1eb47d856dd82ead2f044013f722384621940395713b064ce8c9063de39ad19d85ae7995c32903c2f7e68aec471294bce49906aa7b61ddca8c09a52ee6ddc6d24d615403a39c9f5fe447603e558a3bfabb06a29d91f450324eb660c998a66d7705ff3e98d9a5bc5a8435c03f464c115288052d9794f1834de29d91cb0cca16039f2d2137ac0853fadfb9ba3d32ef35105aa192287c6aa86c7a0fba86550991bea8335fd6f763fba965d8ef8431d63167cc0bd41025fde91a981cd7826341adc0e996bdfbd35c6c2b905f2ae96a8d627a3905d0eed100cb82b7b91f1f804b4d57ce983c039cf64f6b56bca79bed477c49294e37ef940df55a168f3c07aaf74fd01144730549112c8f025baf0aa2739370e3abaed3ccf15700029aea483c8f5d6e4185b9e21cfd30ce93db78d943a5c5f0f8a20dac3c54c3eef30b1439bbf9cabda7d7b4c860b5167cf5a1006c097c0aadf8feea0d3946a2c3de31bab7c1f90ee087ca4beac1078dfbaa6a64adef76f5d9e50acfd09957cafe2a639f3737cb5a3c2673f952889cdeda6b5d1b2de2be85da8e85a8af991f00774e9be692be48abc7e3d2e6745673317bd32426368a3181d0bbfe0432eefb2c955df1a05a6477a2d5eb2b41f5b0df6c28668a71cdc8ae2d011efd0d0ea0a2767b94fa440ad110fd41b4a55d4ceb4874ac91ccfc17af756d37b220752ec51ad3a1f16878f9811e2a354bff955211b7f95c232bd3773307dcb0500d39b5460cc7659e11cd12a20b80428fd159b29f3c46159da38ebdc24b402ecf1cf4b526bf902fb51656fb6e1ee3905116187b2106b3b3bb713969ff79fa556cceab5969eb72e00a54477cbea3e2eceb0f4f8d9df9d9dcc2691973f888f3edfec5a72b5ff9a89a633a13adef77804e522fe7207b307144795570360bce8accf71b7a9b1aa93f57652bb4c7535922f37c07422340ab9c3d169774dc012d5c4551e8fe495b370d6effd83d257874e9eed066be473466f6d8f6d3fe0e02d3bd7b09d1ac8f749c2366da1fba4eb3b9f91db77b980fbe0f5412cceed4a87522a2240e1ae214ab0ac93a2832888f8d3e2900eba01ea04df41a51bb27b65644d8d770b9354783007865dfb9f43ff01ca4b36da35edc2f672e02b23b5c1760ab28436fbc557cbff047078f63c354cb734c9efc49dddf43de8e5fb31bf5513d781871917cd84b7249fdee1d05197612d7b292d56d8e97329111e67cbec7013328a30eda8810e55fc9e85a5a126c4417ef9064ce0aab9ef47ae1b523a7f9765daf5f26ec721c931c4845c07b870561e1e9562b017a2742e6af9c9cec08322a0f1ce8186ed11d92372e3aee718f2420410148678bd3f9e024d7a4ddab450aae42b69dc381d0cf05849c1697ed737f8877ee109ab0baf9c4825a7234788b673068cf0e021034ba783944d1f20b16b6c41447c5990e33bbb2b2ba4c6e7e33c0b8ff965e49d208f6f12551ff86430de63b38faae74a9e41b66e7a3a62121da64bc3f9ac23de2133ef66802adb14d4a89e9c9ca35fd272a124cd7d920447283ebcdb0acc5485539433deff5095961e2e0f83894561409fb8de8f2e88a815d90ff37ded9e65e055951f96b3320cf25d7b2aff3606b4840e5fcd37db6a768acfff04cba6bfe565bda7f1d62671d1f1c5aa724e1cdc023b875ce046992b8bedd689562706b2232fca9d05dac51e6cbc6452b753839ea32ea52e93fe9e1b7d37ee21f53bbfa6d2a1b37863fb120395398860cb664663631bfcbf4cd801753f93db50489c331bee0c999cc7ebd0bdcb90f635d180cc298960f0cb625dc34d0687990e8424dcfc4a234025b8e48cb99561cf215964a9e6a0a05f08baab2060e9bfaafbd3411b152aec4f648d86ff7a25a03429579f0b351eb0c4e61b4cf11f564d30203301c52e1dcb57ccb8abd80ee289fac4243ef2ecc48ca02d54288f423d779259c3a228641f9436a049b164d8698c5f94db0f192c1c9eb5486826b85642079b2cd283c0c66efa6401c701a1138b640e96590a33d3bb14647d421e85903f126b0a6e3ae0ec8e80e0fc30e854e7514f13792fb13f4ec8c4fe01903e364c6f2d18657110fb424023f9116e3ee0f5680e6ecdb55950a7d52045b1ecae951018d2166edf0c9827be146e0c9938b67b44228c750e36da424bbbfe62a226cc3dd5278ee9a86a84e7a882997ef5b895790a61bc3907479957fa81c93614e45068f85b813f5a6acfe4d3ecc8289e9fe7f6c8e931fe5a8786e1dda0ff0cf9fe5c9c639c786790738cfd17655feb04280ffb2b48f49b11bb2b40f16a99b194a78adc016bb66928cf53f253cd0b0e74ecac5eb8b9ee1a171570daec850704f01c2da81a5121f5779dbfab751a94cb7c28a140bc3d0f5779fa7ff8bf5f3a676dc912e7cc613701a2ab29643315d11d4a874273180248addf84b9347870a690da17d1a9a848b32d72252adea4cd2a5d501c42437f9401da0ffa38291538f5ca389a81ff72b952b04bb15c0a8e11f9b6eb7ac1f28e10072d4ca05191e1ca11e3467eecd56a1cf370be54980abd972a61b3dd97038926a754b2464480e86c35aef60aa7740dbd0db931febfde7c195e58144337753e94c08cc60efc7095d464f694d0c135a48538a6f38af155aab65adb187ca29fa33337e9b57439902c5a858c55b41098a0f87202a6e17f7fb5af38f56286f751f550dfd89c132036660c699706b218f1269999cbfdc12035150560ca901f94579d46d9f4b4d8aa40ef03959978667de1d6a9dc82f6ca1c349dfcdefb372476e38fbfc12547c516fb7a0eaa75fff459efd87550ea330fb1c40c01aa35ea15819b2e4146002429343bc4eff50598c688bbe4560fb6c6e18c97bb1fc5e038e628eb05d2f329853e7ee0d414a86d99c938bc6be529662d0cafd5fc0c2d5b5aaf94110c22f7e8b7b920a48df1adc086ba767b02b3251e9c7db0de7561ebad2734c4c8541df4bc5850c7eb5b33f3f0aa631851d65cb122b82504c4606999f60cba56bcb79f3b1849d13f18b1bc5855efd629e48b3aa2c9871d85c260974fd694c0fce4624b366c6b6915cef792cc6f9b5d7cc496b976b06b97c7e58c97dadfccab7893afd0d2c08106be43d0f415115ee4e305463765bd35440202b4d0d6501452510b01fba1ad777ecdc95f455a8b3f0131e78ce12a045d2464726e291f05bbb27ab8aadee3ff028698a11e9b6dd96f1a5b9c03d2f34278d2303bdb0160e8b052e2debb750d90bf7ac0bbdce015d78f9529627c2ee00e1de188f10df0968b52a2751ca3545dcd79011b7a63b3d9d359f0e9729c2263d4482369d628c73df4dca6459ef138788ee99052dc6921f7d84525c2800269a8b425fade6745af1bc62eb8d8ee7f947030cf3e5596de2bbec267ba30e27f997fd649987ce08d4539b006520b95062bf686b3062a00c06462c29ff28bd3413f31536d88d6a95cddaf1a248b87d5d91c8aa50e3ed068d94beee2c7368689a754f6a139dac54f8791136c78e2b99228535cbef2d477382bc927177d66cc03a22a1e1efb1145200e66693dcb137260bef1d0c166de3271647fba3128dc69ce455dee62db32befe4d9576eb7ab6e3101edf11ebb921db87be90ea338f193f9cddec9554ca0782f5a1a6f969cf93a246f2df2a654a9b8d3adb8b29646094a78847af223aff4715c67543216806fb255e7468858d13b602eeb4572accf685cfc3105828a49befc95154fe39853b9d02cb81f8e92a7c4109b8824bf69e9e32182dfb33b6887e916c7706143d3e17ce91759c0d12a53956c6eca86afd19b8167cb069c44a95f0668081b661f897ffc521d3d769cd8dfc19e624398afb6aa6db0fdef3493ba2f7a8fdcdcbb713b3f15bbb2b1f75f8be23a991295dc89178aff7d24f0a23720f0dd62f100af5ee0dfad3a38cc6709fbd78a25b1156925589f47c63eb7a9bc4e3a2f9e2b2f75d303f83d795c9bcf9b072b074643ba46077ca7f1679fe6e01a4eca65a34bd1824ad32853da05a31acf3b183ac0667cec12bd02414a8a68393b68bca567c13316948f57ef8a55ef01995c90978a972e8c2958f0e4cadbc501094b8ec86aac67ed974569810aef3426fdfff403f8decbaafe7763228afb6592552442889c6ef10f979938a9ff886bd6fc55e7317e2343d08dd09f276c3e72a08376f9fb93b9c64d3cc3b58f6c8e9a1fefe49822197a55fdbe1ecdc8c437bb66d8057c7b751d1e664ae9b2c34bcfd25e08487cc6cd62981b7cfbda4f4f247b010e9e8928fc64fedb063998a894a25fd18b7c9852364732ab8703396bef2edf4e7c85cf5be570d2deec70379389fdd6a66fdb39261ddbbd848fa64a20043ada4cc171da23f3343815ffde09847810fa4e238f9e002d77c7921e274296c449938a8d746b285e15ce9b76679d67e0764441a91b9b101fdedf221249d8985ec27f8dd684a9043f24e4c830192cab06fba4376cef28cdbed30860bea35bdcc9fad32485a459e6093b66431a8a9f2f9621b7a4012709fbccf15cc730df84652bc60e4b1f84c4661ff71bb8c3f68b0e4f8c16bd0855941b392cddc7c18c8dea2f7eaf19e0788e9ead15c498b4fc086bc754121fe5fe353ef83ff924098f81e2a7d87e931d9122c2c77ef2c5cd1553dfa577b38ea9ec74cf281448c3b2d536744e201be6c095cdd006150633cfc5d24b0f6ecb087486462847ba4c48d1a37d40f1b6cc0e203595f3eae37fa5c050056882d6bb9e4128a31121bcf79a04531f4a8beedf1325c4e79653f0f447cdc1663627350200cce16f5705e69729e02c6d58f48c604e4c5b3a15fae886f8e97fa5c935299bef6d231cd2f52d6352852f60a7abf84c8baa3966cdce1e437ba78f04304b67db6cd48ab50683cb4654b1e9f87fa32fa73fb7c00dfa14511614f887964547a7c28143522f538e59234486dca2ef3e596a2ed1549c43a826433b9635fa12b8d9e0beb234e0f56fd6ac5286b1b4b9f85951d350e535f4c31202237aa4dceda6f1e3c23b3757f16a13c95cf5b77ca3001ee1f72be2a68e5fa30dc5373cc0a8d286bf16adfe8ab4594ed3f2d8b90b9f5b0f54197f28011e154d0a1d887f26eaa5f6e5fa4ba41c84ca67b89785b92ab0ebc7fec18a8ad77d994791095228a5d8b5ecd552367d38f4d54bd469bc263e35704f9d028a6e5f048fefe00f378ffc06e801e6f2e85256270b52330ea78c6610162599c6e80e27317a0035ddf337e7d91229a40cc9fd3858633ce20166e658c61740636a04ea59e0bb871b0d503241b5dd39e436eb3ff94af968cab8ffea8518fb0a4e5ca424edcebca2ddfba50ae652c24d48012a691f09d4c9758b251f3a6dc23e41b05fed9a064ca43888e313396151558ef4e42c7d14713c0a0434e3e3e87f60049b38ffe47402b0ae303c8900728d6b85ff6b07699c3a3c02a6017d18ee239bd193846beaa5dca9129ecd526d217ebac6e32e83e6972fee8148ac33e2b7e5b3e7ef31487dbbb67ef85fd88b8ee3a1653b4de077a3548aebf5cd7b512fd8c8bda26ab5d875d8f188be6ee045854d1cf7d2243dfe03dbae1a72a007a06b00dd39cb7536a6da04ad7283a0b30737aa087385c4e65ec6e7c266af5894f856847dc0a066750ef5c6f0022b46c21c5d1eeba0783df1843e85cead58c7306bca27dfb4db27e43a30159eeea8d4e421d62f9d09c1f5eeb07e145fd8243f862b993a2a9ca52b862cec19652a687639685767e652cd99a04bd84e1c06c2a6f8de43c9a95ba5b4b3ecbc6df4840deeef37587829f3727e9bedd5661966aa5c92b0b6f4c26668bf04cf52158bd588d9c4418a3dfaa0f3930ccb76afb878c5969ff6cee60297d32051ea949bba31eefe938ff76b70a828d0784a20ba8966554a1c9c0f052991c5fc313f4b0b04124cc103502192d20453587f1ad789fa902f8127e9ba1ec6a56fec3454a3ee0af6805b9e9ed74737867033846c6370d88a43cf65f7f45e0269af5e49177c4e8f5992d0f46129d120dc601f15901540b060d3845abbb0d1546371dfccbe185ac62acb4cb4c212b1d404c47faa0da82e0f1028cbb0b8f93dad19e18ee05c1daeab87881767b2d5c78a640f92e05420ff14859883d2e048952697d204c6afc641e4e1e41b25f6119e581831338f7e4074f899393e0ab51fd223064ae60858465031d79deb5667baab10c36d200b21313c4727242181ea1774c7f7d8421358df423f0c667beff6483fefb5296c7f6871c9c49b5ec0f007fc06dbccf7992d02b9d6dc1e5381c15bd49f4afd2ed704867760136f420a9338230f951039c2df2496b89bf07e5f4472054b82e716560c145bba1b12b8dba2f603522925e0fdd0ab9de0731640ee735e451047c757d08dd995f01db7aad964bacaf77da80912ce36be4070354856a13fb5fbed8416596cb6baf8bd13d409934a6dcce9e13b7f5c12e9e48553bedeb31e44ed17ed17b6a7e6ae473f7a52d33924af917bb51991e003c0b295f420bce692eeab616a9b25b178f6e0c67a3033ccdb2315cd79c6a3e8830eb55329a07584d4998fcb8f44df00b14025fd8af4df9761097bafc8a2f3115767716d1f6541a679f112792c87f8f4c4d6e145059dc7aeb2a3adeef22204dcf2e4d121fa601c2f2cc8d8a120603bdb161fbe8d8632c6109d8562440db7f9b131885dee4243e5971b6a169b663afb0fc722b05d4f8ab6da47a8700bf01d3e95ff847344882760c30ded91ec24ad50df543bdd8c5e57b4438ac8306ba38c2bf1e288ae7a78e74099e6f1c1c94bb1caaf0a534a2359e7099ecaddffa474363e9d3672e83740b11e97a4e8968d3b45f2d556ba79f01d6f091076a02904470cc2e3442d09d151e4333b43300e30dd21add99ac1503c5c071a749963033354b8946aec79b99f37575e0221f36ba3d8e3f85e49f54d50c01a7d7c1574785b50667b03a49d2e0e98343e2eb085d365b0cf57c3bf3c1bb535083697ecb2a277bbdf2f8b3466d6471e4c5a2ddebfe8da80780e5ecb52abe1a25cf74482d5830f2e178d084b48e74eab62692e4752acda7c0e3618dc5a3090fb322498c161c622d8ac918be6b9719e54ce59681ec9d7e5cb6c3ad926c40a21ec2a54fd84b26e46bf3bc105339ca46b19a8696a6f819dac69c7219e349e91a3324212dc9b2e2061df1204e56f69a16898eab21a0cc3bb061d604055b1b734752f4fbfb4ea5413d7e62bc8f9d800cb87ec45991fa952573889aa6958df14b6bda1f248cedbd49a529e091a81b5cab127e42ba8ffa420a73316e50aeab002104e453a0fd2acad3824e0ca25ac8d94a0df1d793dc75859e36567f7ebac0b98234b14075f525c37bd0670a2f4708847c3cbe0a4087679364f9fae79d3adc0d973a1f9155b0a07bbadecbb51163a79ee5d32a183185c80e168acdd086ee3b78bf6b58bccdd985c19f48ea76182e16a44ec4d1313108fb82c76f18fdf4ae45f782a99bb54a4a9ff269bb083a2bfc47222ea6e38348c88b8c98fef7967bc45708b94b2f744fe2f8b2a9b6bb68fd7b14bac710ac20340b7dbe3159b4cc4417835ce7d71d8977b23025caf8614a9c8d4fbba5fc8ffc73e2d90a2a350b41163c832c1a0d38c9dd5580243e63b371040eb98fa86e13bf99f07c50b20075b43581c90b371bbe824bc27c235bc1f5dda2bddeeeaf0be60c680492d79067d414861ac9d2e313c85e6e0e6f7ab2ed8a4070bae1747b7a60811e350ddb5458ba0ceaa899386b4d6dbdcc61537ba19f93b232e59ca25890ffff862082ebfe5ea838c67aa53443ff8818deaa2309d9b846c50800441f3131495a1b9ae102e6bec9bc2c93b1330de16bd03121e66200e79c8decb3bd32d39c1f23b68e4843766199a43fe62801238e7abf17ae141f63379e54af8d92c02ece2c8577d18bf11915a937c266680ea1de8b7c3ac350a50b9a8399477b71e01c3c486bebf95c691a435589f1b4e17a5d07567b523d2289bfe5a2e8165eaf5d7c9ea457344ddf685a6d2e1ce8e3e536359ce3d7d9df01367a354b107fdb6fe84d6034f3c7c9604ce2a9724faf0cb36e8347f8f7461152d4abdd8bf48f7db8aaafd240651e4c4357dbf5bd5aa8644060a49e8c6819cb249dc110a86cbea4778810bf0ebef2e75825cd5dabcfdc2202f37188552cdaafd73b11355ffe8ffa67578b544103a28e3216667aa1c9cdeee476f64a0622349e47357b84a4b5d09f765502302ad1e42e71693dd14ebac5945256f9e5f6c0264c37ca38571609499b342fbd285ca41fc09b51ba68a820328c1def0513f06bc36959c6c2504c90c3a31247530ce6d7051d18e96741cc02d414a74184ed917e342a21dedcccb3fff1c426f7fd6758717a7a51907bab1bb6e9e7bf7d77e1d6f8b56bc7573ac54f6644c23fef04e32be07a5a7e33523546c4636bb8c34ed75f65ff1500a0f5710fe47514e6341010ad7b1fc95edb222af955f92f0565bea952658abd8c64c3b8a5ea86bb5d88aa86fdecb95f7addf9cd940ab151a07a6d1641d340068e09ec03e3d50c4ff31343b368532387bed244089b90ec27283274976016dda4b600714395d8d3aaf7acefa0ad9f94ffcd3ad1c3956f130a66771559ba074a7ba387419657a19c5f9b30372cc4efa98220ce25bfa5e476ec7cb39e1ad9371d9355d7d14c471c088755363ad5350ee1dc9b645577dc727ce60a470175841bdbae64e3fdcad2d7108d8c8d52d7fd520bfcad48656e9fb8f57a27f65c4a09527c89b2737065ce5341f136cda9f6b8efb3cb2a62ffeff0329ee73aa94c81e8ce4ca2d4ce7296e96c5c21fccc00efc2f03c080cbb0829e8994ba5001fb3286301b7f91a63b74215651694e83d1d4731584c81f1bb8ae9172d541bdd94a852b23fb400e372fbacf59d7079a8bdc5bbbd345aa0a10669d7a8b2a4b39c8da76fc4f0744df0145963f336b6f13c118da33fee471953faa15a1d2dee2e3bd2eb52a7c398729300fb5669c893e7a0e304256499cde5421e8753e7178ec99839109c556bd398da35111a1681492e31ab3176daf385ae8febf158361d9098a5a84ba9964fd74e0149dec26fd8cdc489b49e58b17303b6b0cddd2f9fe26989255752254639301a00e971540ce774d00d26da7847e370409223e8bd335824c1de65b22cbc0b2f0375191a6777c99fed9f102702ec082398678cd881431af7fce988f9491528e9f82048882022c8158636da4b196723c69d09ce4ef8241bed18916a5c4b1c9f15e9ad7b6cb08dc69efb86b04d721d1758e0c4e47a4874d51710b7f0097af709293e9094fcb3cb3a4ffc034589366f679ee0476fd9ca47a0194c0a844e2ed3d6e9cb14f78c5a8e2b6dcc75adbeb8b205b8a5fafbe49a3cbfd5240125baac041b9e1fead3b0a7cf1d5b35fe74597ece9a67836a22ac901583d3fca5f825f8f9017091dd704c174d1eca70b3bb0e120f376726740011232901b503741592ec80877c7dde300d7c4de06a9d513d5c6f61636694ecd4504cca307e5788925cbb49801c4edda1ead50abc84e0839c18eda5c9f4a4941d2cd218b1fad0780976593f685f1bdee401fae8527ef01918a30e33e85dfe377daee8ae9f53494b3297661a137725462bc79f8607111759e222075dfe18ecdebfcf168f3867a3c91f3c6b617c3547ac2d56bd8c8d88e635e68e518ed97aeca2349e9a67286b77001efec006b253f39741da903defcc078f288a37e50d577571b3f1ffb9c282d9a7c86064c599b15a163510712fb6305318c10b503a2b584f57a46bf99b36911485c04d9142c2a73b7113f131a294cd0e7af63acdf3c2d5690666aa066f533eb14bb44eee5c7f4a6b6f472bc497a89364dcf2e2a7866928855be630a176141fb6ddc4509d0a8ea897344bd205ec4de1e4a93caa73252c7b77be65838505b13995f10f90cd95bb5969887e11a1f0c967dc07059a3e46c1ec75632d71c7a8b4778fe5a1c6e2ceff1ff036bd564f0b5b60341924cbe2f4f7213b005fd5d71088457c16a3c7904372b510b58ec92aeb03c343d1df1c71af8e100578b0fa86b798f9cdd2879e9bb520b3bb56dd4a5ac9b4fc1c38059a6f77f3a408754ee2fb28dc01690a0a22b8cf561ffa75fb16012ff265c7116fa05d8c6828b289aac018fe7601c4f1517900d5915a7a44f89b10462c2f349b67b43bab312829c1e40859d82279689ced13fa1c1f5a93bc25c2ae51b1b111b4a00d740f76387385cca681e0c16aef1c62323ebe8d77621d4269437d4536fd901878fac6a9c0b29ec253986d92cc4bb9d2eaf528f2b68aa841b0c3922a22a58098d07166f13d8f39e6f6b77e981f6268eea6938b20c9ad8a1ccc295c48fb4da4d1ae933991a420081219232baf36991bdb7597a326e28fc5e1e3ef574cc9e499de6873ce7c6b5f1fa2b37a5d5bae9455362cad7310001135b28e111d15da0baf205c86f0537f40f55081a3ce278cd9e286c86e885371e76c83ae308f08b439b78948899d002e8065b80cdeaa4a504c3212d3081d5dd5de53e48759b0029f0184e9bb9cf4630b3c78a53c970b9e23c9580bed965318183ba9c78f641f2881fbe3668b918c5e2642a3d35a8693cb882c945d70acb72ac40e46af52fa7e22a4241986d32c1f2490b0acd1bb433c66a6990306f1adb0ca0fee8861f823480d3f308b35b9e99c1beab5e6a6874d2f288dbf56e0cb3ce08cd25473ccbe6cf847d18c225fc3ea76f4da286147bd8776aea6ef2f118ef03dc69cb4b3611bc4bf4cb98e51db45f7d5ab2ef2e8f11def50a7b08bfa76023a063be917072f1f8880a02b7c604f99f1857e9e510e218bdcfa44931fe2c25c79c4d1d9fa08794bd282ba745ff83dcadda3634570579f8f834503a41a751eddd426a4b08451cfa8e8a3c3651696aba959aeaa69048cfe9c3d5a8f3486707a3f1779bfa6d5236322e10d88db3faadaedc03f3b665f2da2412f13326159864f443819bc37847b5057f6d3ba551400bfe019f58a29008cd65a9d755d575e34ba55823efe9f06cc5a0aba563d38a2750ea70ec8a8f58002c2a21104b25325e97d3ae7b804f32fd87bfd166d7eb571736a9c6c4d4a04fad7e033a5a3152692e9d1b730c99c15817af1ddce40b394f854c8aadd377e8f2009483f6b20d805f2a19172c3dea00eb06d89bf2f0b958e27968c21e3b32fe787b48c34a98f6da99800e9eb6111b49c285ea86fca9877e956c6a72ef5d2e67583b4ca24400a3094f37194cb6d11c2c5cab1cf937e136ad568fd2b31a6a5a0eb9811bb7030b66835698a6b7c1d18d3557a6ea4cc36a5fac26c0e591f601bf048065d0b1cb0a7e8ecfdd46536698594758f7197bef203647ce6f7d95fa4ad3bb0f5b1c3469ab1d26fa6f06c053f49eee8382f7d439c261cc7c20ce6aca507f39eca23021008c71113ebd6056b01f84d080ad7e5360aed04b8a66387445b81479f8acbf57fc9cf5b83d6d5761a68caff4b5e64865854aa9c57787f3a88853d39ca7a439cf39b436547182fd38d089e876fae791e436a594a56dc8af1494684c74d6b9a072c57bb68bb277e52ba0ea60e544e73688e659efedcecc8e568c0460f5dfcbfa3fc57dc7e46b0958946bbb757bf6ec4d7a8f2c5af9748a466de6cb39c780104b83cefc60fa154786fbaf9d04d07920212004f794cb8c110d64e44c0dbc3153d66b1a0715b8fb771153d5b93bd1db06d72eeb4e6576b3103ce546fafdf143d6a42445223b3591a22f1110eb414c169b7fc462cfed6d31acf33daed87e8ebb9b7d98974de2eb133c61c703ac2ec0d577a62eea41265d76268dd5baa2a1a0edb41c663e43b25451121c941e8ee2e4f450220fe0f2b96fc096c981fb77f6d7213edab00be61b853f1459947e87e82cd001c9a05a4be6e9140aede628737c1bd9b6927e2ea02c4f65fd83f74a2584f8408ca66bd48d1a17037e9c078687776835cbfd5229fccd071e921680197d04eef6f3264a4747138dd4c1d0ff9a0d85b2954925ca3836674aa611cf2b67875bd6a4cc20d2c8ec92cbeb847c5b1c0ddb136fdfa5dd1ab5278b2ae8ee00b9d5ff6ece910a85847e645fadd11a6bbebf9c4fa3f116fa8904749741b2e5c8a1e37d4504e354ec9f388cb6499846cbd24ba46702b21e0429f1e1b97e9daab1abeeb4fe2493795ed3a3e464e53add1e7f25e8600c208b3519770b19d3f196a7d081fc81fc773948b3b70762816a2b0828cc876df2d429620a93d6c50f9850988a66fc4be6cfcffda659c5331debebdd4b09b0274995eb1d2cdf66f3026c8c2d8ee0328ed596373862bac9d29c92713dd72f0193c36ad111464af3a2b20e57461c180113ec090591852791ea2b22c4cf711e1f53a9927006a2985dce224d80095d4a282cbd8474d830634cf13815e9528e2c20ee60961b4173c29e7b79826927301688876dbcc522241a2fd8c130a42e2047c539a6c5e8671dd467862bcbf145d1d97efe592df0563eeadfd6d0317cfa8275f49956d89eb0dbf6a7f1f1f9dd0f48d69ab774219522143464b0c9272a4970dadb64faf4abdf0cda555c9a1d66f56fb7f1f97cdaabfe743cbbdbd462fbdf7a1f9bcaff1b18f5624e7c7dd422d6b73dbad770a49e982c0b54785d284c2cb787a059b37d85f1685c86d5344c7d8af9d27c0708f5d8d1e2a30919c854f21f89168f3eff0e49ed7b8cf0e2d772ec046b5bf79772a5e7b240e0c3e44907e2c5e66da6ca021931ffc130cc1d42bb615089c982800994bd38db421923aaa516258ec50546eeeacd40dd44df7baae19b2104a3669ef30ab33201f96ae6ce19c923b7365d9895eaf94b4b163d8cca1d97205f5db0294479461ee11987453fdff23a189e862795bda868eaef38a0f25645b26a075db1b781cfe4171575d76b429160205000249353acd83451bd5aa48a12eb26e5e2578f2303c1df2214f2abbc5cf232d3d159aeec2ad373d86dfaddbf64095276f535e44fd2800850e3c7ac358f46ced7b9d106a11f8cd6680f0f3d977d57b70d20aafeeb963a48a627532a5a33d9cb0ebb41968036dac710e2c66a863b2c211be4ffe3107ef8b751fe5633a433cf986bc30aaa4bfe9def8e8530e272fd3b09b2b8280ff9b66757af65810f2315b0e46aa9d315bb2a483a484eee80a1a7c5dbe33c649cc006fc2379f190edf053b807055afb954e9a2812045159f260bd241377225ac96813b87c541d41f0100993dae6fcb09ac736067362bd63c987665c3a23b954130f6d98cddafff2d1f020dc2b44f2c81d78ef61aa1164c56b14a95ce1077bc15ec013e6e533f9bf89a08f17c40b0ff13281edc158019212111c09e3677fe8edfc6ce4b37258302622c2ac13b6c3169f03a155e31ee48c7138f6cdce7057131ae4a315f48bf4e9aebcab6b99a7d1a2f6adf6db4ab0bc680759c28f3f57400286e3db8f664eefaa247f2fc2290b38cac7f2266c2adf82722623f7a1c9cf53ab01b83a9aeb198edb4472068ba8f313117957ac8dcf122ffaf9d734f87af7b60d428fde2bcfcea94157e3bff6efc316871f49505214c9595995d15cbf2143ebb852c5ec7ebe9dd0f55330771a286a3ac64d46d851eccf55797365cb7f9b7b51c9ea3f15a0a04ea2d1a9a04ca46fba343803a64481fad9422ce930916546f3e5934a801373aec3303351ecfe9ce25ce4e76bb84ab258aeaf5ff7caf8b67fb0e6927d766b0ff2d79329382e956ccf4b7f065c2584c091c1a7a31a80bdf9462477d7856d51c42780bad3b1745621eda5bc5bdf19df370be84ad7a5e032559a2c30dae2d0c60e76bb7297a5e52a1d87ad6c49cacf61f326d3f35756de2027575c6f9c8c654da028b21be85c8ccce82ebbff37b870c97c2fcd638214de05229faede318d8c86cab88bde0a64ffedb98d2e299a5ebd622652619d1d4a964a4f01f4ab0013a5ae623c0ae29a26c621f1622039d3db87836a1c31fdc36124c637b4b76ede6bfc46975d673b706b5f0f372e404d025f72237087af88316747072cf3ed2b6a87006b26940b4d8bec6d68a6d8adca6a3d8df33ba73da2174bead9d027df6c410a5b365d1d3542d92bd7c866cba81fcf0f0fbc10d58f6f7baa522e952ec8d48f1868f969d967a188474cf6056ebecb340fcc995a8d26e140fe02c4510b8bd619519244bb4a92a0d165d4f6a532b1413c06ff671ebc466d39aa87a6658f20188d6742bd7c18c46dd297bd229952d761dff2d6a86ff48106da06d2c2df0d3c62e238ddb275ebb56b2707e9dbf3bff93853a84d334b2618aa9a6fbd891eb8030e300f75c9c405e528fdcbc8f883be3e40d0cfe9a9bd7c1a98effe40ea6439c6498961126430826faaada5a85e3cb957eca83d9a2254afc1f87efadba8cd99f60c3718622c6f156f709199af9769cdc46072f97c17b08486c36e46d16c19321d70e1aa1168973a7102ad6d407d16bb61d0e742637d8b814df918f49349bd075ceced9e4d9c57b304847c1a6b185b92218453a6f83734f5c76c3b93bc00e433c1035228439b0527fdea0bebe3d989c371425be230b8f9a0abda496abf5d84de4bfac2fcd5c493a1473cfc9520e456390bda6c5066b5ed686b65e48518d1188b2f4eacccb689ec6a248205adfa642c8aeccfc557a4c8d498c8021bae37b53f66047e83e3b8361e292d445a71a6363407f4dd487110a5ee5c4fa11a83d72651beea7d9859a42585339ac43789844106eef03976af001ad9b6c803403d3d24b85391298e3ba6e12fe7dea59a2885fab18fe5e0c9a226461d68dce2a90f9064c3fb08eac677c8b6cefefbce875d22c8457a48d6863b00712f8bc6e58c52591a01ec3118157b97f8102aee0fb839dede639bc8c3ef23c3f3f6494fed3bb3e0b8916851a23317e9ffc3689dcc902b876c3931921de38c95d17b5f9c44ca75aff0e4bc62f00b0efbbd9478e6840060bd19e04a0a5fd84065392e51225180a4de6ce28c7012176b2fe70260e4d439a725dfc5ecbbfb9c36a37aee418789f6792676e3929d36b0bf2c29752cecd238409f8ab23c826de3a2d8a184ae12638f662b22a69b9b6345e6588ece14338d1a53982c56df5e40b0b6a5bdc73de7074c6c2473d90ecb54509e84abb00f0bd35843e42acc167ebb02267324321f09938c1109cee771513be2a8a2ead273c4fddd92d0bf2c8372bd1fc324f1d700a3080184760094ababba4c19432fe06b595bf2677e00bd8e68ad9e6050f2dfc198823a82c05565c1c5492753710f3c9e3f82843d2f25e9d7e3acb4103d56fb301372d19feb41c81906f4f955ae65ee1106528ad0fecc825d47c1df424e2044dd9935e4574b5d4e32dcc29eb852cb5e7697a47c3bcbbd3488098404a8f4d37da152960da998c4821c31543e1cc1e52aeb79edc6da07ba9baeaee7525c0f6815f0444e7c61782d96ee49933a9ec324435e495458159d239ea9e027d343912c35e00c0e49aa1a8cd755d156a05d361d32dddc3e660f7ab78657d63274c50fcb0593b6d39b8e8280e7b056664ebc5c1c1223c75ac14c611479a02ecae9675d3b8d6d891a2dbb3754c39f0c8b872b702da7cb52a8646894b01b815b6f9b6818cf2072cd8453df160f64df0f8e4dacdd33547294f550354b830a38307c21a35abb98e3827fb120c994552cf0894cb536bec5179103b812543e865e7e0ada0d090e1d9322f169608d7fe5977cc544c661268fab8be5f2d31e5095ba9c2aea049e58ac36de42aa33159a010f8475cd3145129b6a3f215bb804672ab070d2a0d9a44c7adbed54ed760a8c2fa6e08a907d4cf5139c9ba1e31cf13fc46d06c205d0007c0214ecfa291f809dc7eb7ae484cdd015bd3b2d3acf987488f993c76e99f84e7b1698c362e76893ce81870e73d79201a927bd6f1e0d41df49c91a867c3327e61337f6ac56a532338029eb0e688099fdd9dd2a5a237406bae92cab36f77bda4c19f87806f7c406a80db72c0d498452ed4eaf3f5c70eff5a69f3ef5c173c749f502e29a863228a03ad49afa84a7bad6b818d741dabb8279ceeeff46a66cdf2dd4c06970a1910ba0f2163a45bca5ed954b03b86ada9d114df5adbd67a24bd25d42ddb8e6b21c820786b6a3e836c8e11880096c88a76e6b3465b2d61fb111456da58dcbccf7b19b300c88db34699a9ca265599305c22a780e0e1bed18fec6aa777cbd0e9969533401615f79cacfe402f11629b8122175a8367c1d105de7f6a1cb88225f778cb322e41f990c6409fe24b6ef4b37780c99d8068089bb3a4b778ec63c80f6f8d03343ef3770f288c724cbb375f1269b1c06cc3fb0b9a69c43ee05525c8e2cae1c326fa4713c68d2cfc23641507addd49be3af9d557b0be1597fcb7a681dd73bafa132de4a34ca6486127234bd0ab6c050df98cf6b0f111f7500652ca14cab4a41fa2d18f1c664626ba70f874a8365ea64d1e1e8a257a1d313a6b652cf6db617dcd22d74378159ef1ce25258c76e1e676aad0722a01e30db706e67788d558e44bd0fb600b177d88096f96dacfd78b5a7997b9a3ae5a4edb6a36cb3618a4cd76d2647302681fdc242673350f2f044f4cdef91c7a5b0091ee7c195e0268af5ef300a5c9fe1406579ecdcb0915397d14f82ed2bc55f8de4e5abcecdfbc41f9e80a83a072d01418a2a544f718ec3d4f6332d1bb2aebb00c6ca66b9999e6bd2bc490523859f0db1dea63779b9f1f84d52cbf3e7dcede8214080c6b54916f512426bc9447266897ad4078118867e0d6746cd99378ff539066b246ecd123bcb3597c4acc172ea13c1e260468fe12b1696ba737e1984e9b593f774c3db1696be6964319b9f9388707bae3ee0858528e3658741dc271e80974045f3ccdcf5c271fa4458e81023f42761c5eb37375dea4e4d4d8b1de0b4724631cb35b0043e7ac67c4edf767115670eaf50370af4cd2637de6c760e5750b8bda3c5351c16a9a5ebc02e2ea24cd10e9fe31deaf0e250d869f933642bcb9da2dd7ae6d92e3c3242c2ca4908bb60f19d68897616973b67dd1f1b037c460f7181782191858f2003a4146daa41901058972d7baf5088dd5f89f294ddf5d0b6af191f36df14250213469c2735942e825ae6d36406817d2ec872e739cc1cb9f0bee817e95e37bb38c24b9bab958654afa1a38dc4c3155c37d1310f014a5860de0637d0a48d23331bf8afc9f5cef164c130ca4a472b360b92d4552f083d6ffc381f8b033bcc0550c42ea706ca15026f0d4171c06e6e3ed636e2d7cfa92856ef967342076d612e419457b0667c8087f01ebfea10184cb54e7c6df803d8878fc04ec7e45e1705072d1a554a5ead50980fc7dc0443a2f51f64bb73fa10f183be1e8c4368441ddb9cc5c47845c02ab67194a7f27a109036ef7c44c33ea236f799350705cf63fa5a8ed6d8075b8d483c41a589c4ef7efb716cf495f839a1f22ae433f35d4c5abbe7bbcec3a78ad021babf3e0b9ff84130557125622e93b0795670617a426fa536430d1dc22c79ef99b0474f5fc4a7812efe5c9e2e9f1a23edfed2340ce460b118525836600127c410d977d7f2e9a89a6b571289479ee50ec969a026d8054077f783ac7038fc45f1d7972c01d4ff6811fb44dbad8a5de90b39b8a8c055e25ba81b4839725ae5f33875d468fa381a5866ebfa41f21cf2bcd32c0a3e171ca4cd5ee36fda6a7de9f0c630430e796fcae444eddb481d8c61f7c1c1a6b6b6df269eb1c69ddb5d6e2c4bde345e22546ca393c69f48b4d52019f1cd025393fb97d193b53654aa6bf784c660040145a5d5da90092751a9294b526d087323a04313b76cbe6447ab73707f48abe7628a2d8e2b0a5de8dc8e7d4baf10cf6fb714170a8d0e808f9b00d1e3796967ea69bbf899bb84605751b423872250ad5e61d0162613a0876f1c0aa27c7c9dc629bc9ef8fdbcd6abcd26fcdf55e0bb080028cb3de1e3785a3320ee1652bc1a553fde8f73da96ace4c55e5d140bc4211918ed8694dcc5d974ff47276c8c157260e9099cb8042fc9f9a258a6a107023ad1f91a1cef61a74521564bee71c2c055606b183fb3e5f02c21d21f45d8c3dceb63edb8779d4e54668ea48b3d283b141db2e76e2cd4f4f609d47125519bb969771a27a129d82b326cce960126a21be34bcc01bbbda81dbdfc70e2cf40f79d3c7da6f29603a5e52e7f968c8bfc4709adfad10b5d2901740c54625168f306997e9ff6a4dd6b3089030fea08c28cf13a58a35e43883a9feaa5b6552041142f20a916a2b4bb0c0892a4ccf1a8707b3bd537b359cd86f831c655102f69601746ba8a29cd9a089cc3796df03360f77c6727dfe70cf7bd1ee97bd070a1b8ff7798ba8dc2e1ca6f09c1ac987da350d1929136cd346b5347b4aa00aa08b1707ffd7ed550b167233ae883db4791025d4d3f0893cae53d0ee29569290f29b0f73b691f05895c9a2c40357ea89b2fdebe78c41e14f014919d17cbe67b0fe6fa854d65c7a2fa0804dd88d8638caa595e49d2bcb1eb6bb45aa447c4f6ff29d308b7785fa01213a796bf7f61237c38b7d6fa76cb760315659cb37e2c88a9cfa7d48353a5e160709aa599f17ab5076cf9010a1aff139e7d908e73c96c1eeda61568730981f77f749455f6d4efa787d9fd40630cae5ce4d302f7cb502afb8a092b1a0447db8c42d95be45ad25ca5db36cd0f24768173e21b968e7f38503c70bfe56101b8152b3e1a32d922a58fe48f8fa01802d578ffce70178b29fcd877d58d2062a166933fc33d52c611c44d98beefc7a2ddfab7b17a455cabf8acab61554a4c1e649c4d228fea931d30314849cb63eea6684d5410dc66d24fa96739949aa615777b13a0849df0f9b95023bfb065c29379f515d4eb24965f0da79ebfa7af2b3852ee22611953769bc08b0df17def102abf69d9e9d2ab0854760e6ee324c6d35d804f0069d65636227f3004c20e2b74a1666b877e0701f933590c14a0693251fb7588d16d011de7e13d98b07a9935ef81774938d1f8dfb137ef0804e32d54efb3566ef86664a6b8d78d19ff938ca4e067e6c9bd56a635ba2884c97a074fd7e5d32a98c6ac2563323e1d7b40da5cc1f7a66385ef4badc4fb28ea729d6a406b13db81f59251659084f059081828fbc0a287f21a7481d8dbacdb4cd8714741779ce7f0b10d23bffed168fe6f15298797240be1ab25efd139f8f6663e275121659798aa25963f01fb9366b0eea86b68b02f48c74ddfd8f7d326a5bcdd419a78d76dc27507ab0aa42971abb2fb8f1b624d62e13980139cfdec46acd5a48fcfc5b86a5e940a9849b14c16368fbd87c5fb40b8f410d515fd63ddfc55c529e5871a4988f6b1478222f54769ccbe8ee2f3b735fa774ab209ee535a968e7f5c73ae0b5de7c384522f475b368931a1de116ed780a373343da60ddf436d33d075b54dc44383d1b526a931061cebb55f946b2b415547f11343fb2be1233678bcf7d349560ff71b11f5ea8eef27435e40088394228db93f8063dea3693be95fa1569f3b3c91b8b67f0b77d4a7523cf67d842d97ff491ac1842f40f10eacde168aec22d2d14732daa332ab4a4c30248538e83dd7afd1ee5d712876feaf7825829e2e7eedfa51679ab1d7c340f9d40420378b49fc3fc42f72a9a0ef50bf647469bdcf7149a89c14818c0ea9b5fee05682c065ca8a9032bb556e10a0a2e7d508f1d60276b6a8186759960374cfed62f261cbbe8b3e77cb01b01c412d961c16cbbff5ec6c655a18f3d99b0b8ba2b4aa9480d626d4534cf488116b5b194add0074a593366f9f4c8ab554393017f7dbcff227adc4f71578342e2d84814a1c949f6d51703ab19ba4460a1548b29a5b52b5214a1bed29e9cc43e8b0590aa3070424a755fbeff2c6ce21c722042d196d7192681845c6f898923b56e5f3a7370eaa6dde6d978e89f788d512a80fc498c33ff338ec7f0c3c600de2bb10c1afe00f096a9ae8df2b5e49cab7828c8b23e925e8b46f8ae63e024d51c5cce6b972e070373aad3419669fce258a3be7b3bbeee648a0c7caae41e311bdc63f25a49691a192ed222014d0071e3d7c64e3592feb0806efb75f5e4af2e6fed4d7d0bd43c4a7c60c815cd80ea50fcf42c7e4f1db51cf0abc3e13f4bf91a41a4fc3dc846fd52471628de83030a44e40e76462c6e3bc2cc3561cfc80134e7d03d955e9d64080cb8010b54d350db79d3f32b95068a570ea03232c72c60631d150f317724b11b487dc910d98e2cb9460ddd235a8dc716278e888689c0d5f78ab3b58c904794b17c4bb64d3d6f28dac34b8a9ee8a1dc6f6bfd1c2e413e4b24ccd3543f6eb8e1b962cf0657bead354f86f08fb83acf0f2d15cdb76cebfbe9efddee249045cc81f0360110d2c9c77265cacf1808e1c01c426620d8e9353ff01078bb31d4e49983b38764b57ede033442be57fe2e7eddbafccba9c67435feef3aa6476bb9f59c22a7186659791f24ea5aa27ff0350e301a756fec499d85eb9faf9d230b40f3982dce8192896f6fae40e80b9e7ea12c5f4d0a31070bfca4ab36898d33f2d5f351ce8cf7e17db47b09b29b6646db4334883c7dead3bc7d0ee01dcae538c3d49b1714f3c113d06102aef49d645173306c4f207ec6eac2475bc8fa26926eaab8daa466e6c34ab10668fa741b86b382e92b2214397f748cd625ba2b58e697d0180c69fda71d034cc0670d4abb988426bd872fd41b642ecbfb6be68dfa4f340707a6b6409871faa6e3067219f101d3cb77ddfff917e482730104661cceb733c1c8990e16b5508a890bb1f9e8d2487295eee1701bcac5abc493de597d5d9cba5cd5af580949919869f4f652c32fabbfa516fd7e11158d2757bcdf0f755df173d3f8a550f91664ee1fbfd1fe2e59ae2715ff9aeea4f6e5041aa73aea79be007519d9e80f3fc68f329869d7f478fe0119f2111f54df2cf7b560fb1b47165ffc114f5cbe2c2859c07c3564d638cf9c85c5b84afdc9e5adc2978b62752b13878a63ee99c68d6b79db08bcbe71bd7d43beac5e3096a2c6a472c0df4bce2087fe04ae6fc39eff4ea505292100fa2e449a20358a447dac2e932e04d7d18ffdbd3f64116e120f3aae0392e635702f6ab8282c7bedeee6904bc2880bd57531f848c8fa136e125585af4a7a7f206ae99a126a67330b01e99d67b16e0f0f06f556418d3eaebac9ecaf854ac4e450620e22a388b25ae4efdcae411eda11fb962a74e49e12de23e88b8e6e8c72121502ca28ab80ec0a5022692b0cc5062a8d2bf2cfc2be101cb922d31a3bb9f5171d85a0a03cc4c51d0a2ce10fea4c1355bb710ada6ec0f11b69a74187f2b1c63f9ba776ee670eedb92f052f1e90992332cd3d3da29b248ecc997d73887e3ff12e12feb5b1939f61c73c0709582ba97883728722837edd1db6f102788d29df604047d15a1852a5dd7fc7c74f30d392c0a8534255713cca7653257ce25fdeced943975bb6ba8593235be0f4f199d174f7843c720ccc6baf0215e17be990c8d2c9236224392020c2760c7d5610f539f02f2d083e892d69f78c18e755a0f356d6c90a8306674d83c32907c66a654183ed03d261ae20ddc26354f38aa3bdf0760380fc09bd7f12b225901dcc213c71318e05bbebd80f524cf5061ec623cf5bc895b4a6077976a7ddfb9c0cd3fa783259354b6a2d9f284552ed221b78d0b55e8eae65c02003e58fb60c50bff4d44d5bbf786a3f5cbd49c3cc914fc3c602d082d7557c3f7ab7ace38536e001bcf52eb0ef80154322b310e2ea795fe7333d0ba333dc1a7a853d0b9825e34ff5cc055917311b257cf36bf141a2decab2f2adcb50466bd0432e09ff47d854ff60e1443cc6d6dacc027bc112c705ab3b6d6c3de3ef5ce27d4d129fdb066237160be102dc61a8690c459a52b319c974404180caf42f8620ff20f9681d46a8953f4291f3de9ff279d00cb82789f9f3390a83d0f9d38050aec674c5c92bff62cf37d43b50905fbfac7db15ec9b8771850627e1f9e770c312d2138fe017e607b8c1642c6193e31f193b69ffac55c595da60862d4d14c2cfe9a6558b3398ed59bc10b4a1822dd6fb02884f6d44ccefd2acae2137921c5c0e61af9b6845095b45d27820b326e1306ee3ae43d05624e3e2bb39362187700f383b59c51594cb7ae9af7a6e004d2ae29e9ed089968a55efcaa2f352623448f5c54666a6b57111956291dcd7f5a4d181bca27e3145020dc777335c5250af53f8800e58796c059c6977c4f1b8cef9b12103cf9c39370af2ebd9ad11b66de9ec2d3451247e2f3f3002408fb776a822a58c313e8616d49869e70d2e7926ab78c4f2c95e286db19b74770a15064005f43ccac5d10198033f1a16ef1b73e2fd166acebec28a489847a9ec8537747b5c83997872a38527282e648560e37180d3acab42a72ecac8dc39a281f1c19b64c8c71eb8535c29c8f8b60a4aaad677de1e20a0f21a524e0bb3e1e91926c4021f3070eb5de9d98a8df57c41452f66e5ce73d7900307c01ee5e45201abbbf8f49bfeafe78720bb61856e7752389ff5d32b760488343be6f700a1c9e55fd535ec4584387630c08a2a48f89f1e7efab7c9de516fa1771def7e4dbac84f8db1de0015aafbd1f2d74e64e65fe58fc43a361506578af56139aefcae540f5ff015076b7336d5ef721d339c3edb3f54a0bac0f82e63cf9c1121397fb5abb17febc0e3c0acb838d464681e2ffd6d72819fba2d563207621ce08ee5421e74da75fed5eb0c36720ac7bf257418746f2b2c0c9be338ced8a733833fbeee05906259c4d26b6769ed477ba6133cee26d58d44738fbdaeb8df99a70d00195f6aa67023b00fa611d4d09cabe9af0010edd6aab27dc4e4815cdd63292e5edb1a572dbf1c307cc0127d6ae1a2edfd548dfbcf3360079f6cb5de7778ead94d8ea779f40a51468df59c9f68f9b642929d27db1b62b28faa2f28889ef015c1b547c2a7fa8b98ceff4c4e721b8d7caac45aec0866c1e62eda03a822517e99d42a6a679d36aea470b4ae2a2f97fef10c28943ea9861b09ba728bb660b6bbe5b2f052c88b744bf24caaae05561feb1a5735f213b9bd71892f0188050dd475e72c9740ae547d17dba345b4fafa7aa952bd9e0639a2d3566ee4e9ad19515d523d2e4f36d26ff1e7ef1b609eb3b126823314ba667be6d09e7c435b4d6e68e5a8f1345e55f2a71d50b8b8b105b87c9be2458431d77b36ccd6f89235c8512dbb2d57f8c59f560879332543b473d0d19165422d731c2350156be4658e3d17ab99a5e2816e0bfeb8868a7cb38627522e5d2d86b7307a41f3ad81341c03ca0d7e571b4dbebf47d47a90638207314b6b00686d4427b56330750f0121d400e9d590df382d206d0d812187260693fd726374ab708767b3ff731a9774e56647d00e850b4e31e47f422588d47691d26fae2c91a9cec647376c3061b1a41f12ad3ea960b18424e474d5462a6b43b3b083d7b8eb3cd3e3fb8ad176138ee32c53af44e90cf24ac6d1b3f3a0fc446c2b2d7211c2136b646c59ef7a8ac5a4faf92f201651879cab5905e6c5ad9b39ee8b357259ac5051ca342f48cb3b5f641e6cd4b740095645d8343e36752b1b57a0f6e303a6a7cf32fc24a3870bc0e3897e96712d82a1225701f8be67aac7299b091e2048947f23a93c985b761fb16454f89dd5cc893f1fa3aa7bd95015c9da68d57bcc35ea31bf25d69551683c6931093b2aadd0f37ed9acf6a408ed91f11101f562a2e2c5f16fdecc66dda489676775b1a2d62b09fe66ff297ccccf99f5aaf8488601f66f11b9cfdd0d91241fed97d3c0088963cfbe070f039e5fcac771780e6b2b245be54f17cfe37e425c0de47acc34e25519300a8afff1f835d63680fd56064190b99b6b0c723e7411d0b183ec38d0aae036bab9785586d3d50a0d062a3038681769da5820da23528c36df7f3c9a828fb0adb085adbe1892570135b9fcb61d795502f612507a641afe9b2b2b93310408eab6a1a581f107de5cf9998413d3c68d6243afa58f2dff4bbb6a97c5c6cfb5f9dc23aa7393ff18ceadaf4bbc3deb8791ab6744ce12d16f90fff60c7d88ad8a30b82042edb1fb6c6411d873e295d3e86ff5ccb94ca3ae8bd5f6b6f6baef56ff9d9f00356a9eaabc41f2f05d94fb7ec0f69329e3ec74e0900a2d326d76e99ea7707e1ce2b7c9e6a3f47ee0d8ab2d7f8cc651eb5cbaa2c6b617062a51b3ac075fadbea8b53d0b781e9091901c608a42fa6a2fb46fa13663a7273defe1808c6027a20202a7fecf228e09b6dc2cc97221bfd0ac131d90c33861c5b993c7248555c7a15c9d90fe9a3214a0d3d43efaf8cff196df2dd4d116b18330f422f44364c29c0198437378bdc402c079cf7f67027fa945b4782c2a06ec557cc466964d2bf2cf0ec14ebdfe615cfb1133491ccc415e202f1ab98e3c738ea119238f3ccc569ff46181e0b82c4db4e1d997566979b1005abebc940acb548ae12b96ad19af931e1cad7869c80dd8228e000126b3b93d629afb1aa9f487a25701d6ee99e4cf2f5b9f207f73e11763352830ec4e195996180fc56c5d84d0615352894cf5b67f2b1e91974da5e501a8b09f090edde5e77c5366c947b3a2746ce229b5754f6427e403fcb271e487fccf3d74e0fe67009ce4d32c4fc1808882f1d4b65436887c30ac2a06f8c8c8f48d1dc75e1446f6e02f13305f0ac1c859912dab3370f14e7959902351550bd14b3d5b84eacd3998c630db20e49958f0d8366044fc900284d5e8db58504fbd6975535a2ee1ead79b6cc88bc6831f661b1fee9d97dcd7f598338c12befa546a75c7bc86c784b367da4df13f70a59c5bf9933e95654b7701b41963d33993a9e0f46e7281411e4e7a3b97906fca7bb82652c94025930124c911c6dd1333e8f7340448aa6fbaa75ba9380a049b41bb86262d4921453133dcce9bd98da9878ff74c6a6ae2b40dd06c1d8a963ad52aef1b26f73e9c57fd52286f2bc6ce8df8781d3c4c68912a05deaf4ef510089374b5a3ea63672190ae97c9a0c79dbd339b36ca5abfece9fbcffc1a6564735f8e5b7ea9ee50b7aa3feee252816e206a7ce1ba545a90f74a20711c831a4554a7c53288733fecbbbf9f48d272d6b65926e6491c7204b34f76048735d6256dc1a9ed16a62193ef707a785456133801b11691fdd576103235c6ba2978ab05ae19878ccadc36f9574c97ce3a5bc3aab4ed3070dbb7ebfae002d7ea4c48794deab0502b6dbe03c1a49ee52728fd3ec92389993e7464e8d8040e60b211d75bcec5adb4a19ca20af1f2232c652fc25159e12e858f3d07f08910093953401a8f70c11236df7992bc2e113e51b20b22a2296639fa6133b6015f802d66852bb2b4b698f1e8a81a76e67687d0b8508a371a3cfb18254265d57413dd9aaae3742eaa265f3456bf9dbdfb08fdf6b477a6a10fdad90e7a3355697aec35bf22a8f84b655ed7fb307d0489142c045faaa914e81c608e59c6f88b82749d9567c46aca74b4e1978b741a44795d277cf7243127e1597f2e5a3ae676b42c162909e2acf12f010fb756d886355f41a24888a64d5dd10af3515f3001e6911908bc84e293c988afbdabb7d440a2ec3de96ec06b56b4b9701e95e5ca10b6589c2733c81269da2cfc17b3d47fa89dd30503200099ee675147c9e6f97da5e3a7856a4decc4b8c165c4ef804f41c533835ac27e46741496675a2431086b71971f0d40370dbbb119242adaf4e729ddf8d1e04b69a669486aff6a0ee039a66c9961c66e0d6d5f78f3a1fff5432c41265936aea1995776862f892861c937f5904d376a339dbf99a02cc9cff84c27f206c5afe488c953a574c797e99f22b5c917e5fd1a90f3c17a4868d0688696a13dc911ff02f1ad4b6203e9d92f77bbe78470dca7c72009d61b3df1e7871b60921a0d54a6ebcaa148260672a3aedff2f9764f8197d9a0b6c934cceb6820a41476eb1b6a9110af53bb182dbf95046145f6bdf102b1cfa86a5afa8b08e603fc927f0460fa9563545c88d7ca5916dfdb5c9b6c767d520679e66bf673ec64502185615b13d9a131fa4651e5c8b40eaa278c771c4fef3acc35ef76d167f79eb68279911984ac9da9e54eb431dd2340ca6c72e04c2da65412db02aaa3246250c507eb8ff42c1d25b629f9340317ce8b71eee0aa0c015b2b905cfa739bcb9db63c6779cbf2a576a132b4028bf070686f89adfaa5ca91fade9b6f6b4df65a63848c502d2d24b94201e4713ecd2aafce1b7eb28ae4f96ab46476eefc5392d6ba2fe7220eb3458363b121c138d122a188c3dc60454f7ef6fbe7479cf56d1a20347d7960a7330ee392fbb02e0d5b59f7881035d8439568b8f438c0d91f38b1467eb4194f28f7a1558882f831aa7bf0679b0059c10180c66abaff9d238887a05ff23493cb18235efb163adc0a06a2c8099bbda391161ad30f52ab2c7627ab44e1ec88fcbfa08277e4418a7a2286601e56877d6269595c4885c64ea809e9c121caa5532d4aaeadb9e9e6651be49f25470bb0dee83448cd59ad75f4cdcdf2d6c3346d6065ca27b286622eb28fee3ce4399894dfbd1846725fad67fa2b818870e0aad72f9499e1fc776431e6fa6a6858f5c6f1f0b56126e8f912a126053d445f27429a596842da82b1c3b8308ffab9ca5d5c88a2d39b0f44968b0ab67222c6b93f8cafda69183c62918e96bd5d949173c140d1f7d0d256ab50c9fcdc61c725a4a1e1f4639c8363ea53abc87a8b8696a1b8dfd51814f19a6bbc18f5c567ee8d89e0a85879c50fc1ac149cba1e9453d5d262d272c3a76a0e254872e1f54e8fa6da6c8d2220605305dc398214609f1e31edd55c8185c46fc00880f28beba2b50b042b26b20d8fd7f26fd662142b0440addcbd3a64e6ee99bb583676f96927d779481a0647ae6a8cc059d35daea794868326bdb485de1940b2a0c5b90489666a5ad85e2a4c336c730d0cc6280111fd237f90c67e4f6815889ffd803bd9cce441ac59e2aadd6e546f9ac17507798d056b2a421d381866b954c30d33a932a629b67e2745913efa188f9bbce163bb69ed44d12c9167c406883793d6e073e31f74637aa4a17c5c1e67bc663294b8f573ebade9b593b1f720c74cc001f07f29d1168caf61ed84f913f70cfa5c6ebbade99e2d4a5a9b2a872a1b1fc75c65337ddb01ea09c027bb0ab8c5bb00cfe363edbbcaaccd3b997cf926dd2ccdc64d98cdaa4389d8e3c46a789810929302c1e8d10c233932e1144928018bde47eaef06a82746533c7a4b9f1b8253c9bdc89e63f7feb3bc7ccc9aee795df2fafc139fc21ea9013ba3a3c248747fa68bb7210b8557073f3fd7cfbcb3a57eab551aead27af9f716c1d528efcf4723c5755ddd767ba5543f9a7b1c112d10174ee53670c3efa51b94b73a0922dd298c2ae4bc7585bafc8404413f0042165cdf82fc68e9466646ef85d2a9b52bf523fe8094b7dd275c84288aa10f6fe14c5dd5f3e8b2e30e2f182083b5a1f4b0072bb58e0004fb9868578a1e1fcb8be370bfec6c5b2d0318eef1e9bb50ab89fd834ab0e625af5527a5e6f82f8a3a405eff949692ed2338cb902ca715293b77dadec10b53bf024f432daa9e080dd7f2810c25b850e8c2e0b405d1375275fa5e832390fdc7373e6977f682b358897fdf88ccd4f323356b80cc556eba9346d54c0472b377c06d453348058467141f388a523f6ee723496005e37bbb98d321df49a1884bc3561c19198cc35f2ff429ea6efe3161f569f92e1da035ff641f28c04a0a8052136df82f8b0447529ae3e27f8a58912e545514146409666760f5425a3225a4c26c143794808a9cba3f10821c3a9a6a419e06c57f5a6dff47370620808ab3cfdb8f2aeaa4c2eeb90405d1ac832bcc1a55bbffa814c3471d27765a5ed6edb3566edd96e20e6f108402df41b49faf48b75484ce9d37936b2f26672e80731901740049f18de88bd5eb2f58dc4afdd7a8f9198992edbed64c2602373c57e2c06bfddc03177ac292e562cbab5e054acd21318a4a10a4805330476c9099e3d7660d79a3b2b8be3c14d05fe246eb1c9964761289d097f71472a6beaa0127023697956632f8ba77250559a15ce9e7f270e6eb1edb62586cfc31cd4fcbed345891201cb9f2834761f84bd88f6ab147e6b3f1ff90139f9c6c4fcca9dca67f6f4474b102eb1d4765f13ddda3746d54e44bdd32806a9a8a179baf0f8d75593777e79ad9eb9a370db4ce21cf5fc496d6e521ddd7f2e86d2fce6bcd92f1dd8028592154f1a8734fedac7795d4c039d5ebd66d4ac8475a137ed935f20c7fad6ec11db1f86058949a36165489f84d9cda1b1bc1d4e247187d32e953e61716bb585c1d0454f7b965292fae8b22536dd70cab60356d1dbd744f7011c840ea57f5b80a17340138bbef39b38a34631fcb4ae8d262656ab1557b3d74e09da980adc68b54c5eb56ba9716374b1522367425691f578ca5d4cfdf22220b7694610d9eff4fad493158fdef22d1c936252b49153004e8c5ae8b53fc55dfc7aee6769d559dc6d0a439d4d709b116e3abb4ead94bc8cda7b0bd12c0a96a151ff242377453f06983beb82d144028101cfc7cb7b12abe9a1ce9de7f714f1c7c24357c98d11145b5a768f01b6e6f2bfa3da6a825728ec4d1186fb56378be287c83bb728ac1f2e844241a0d5cc98b9aab6996b7ecc14b7b499624b294b767111b76681e3bd0002113c7e3206caed1bbaadf9f536c32c97ba20607bd2711ce7fad2a83149529b060620ac3c8be317fcc60c721d23665f16c9e7eb87b8e591da318ca5d60a8cd6c7acc1d3c2d7a06e4483f0186f62e2ba305649189c5e53605892ca44ea79e249bc821f3e82e1c1583e7aadb19f0c574c2e138adaa6efbd425980613fbab36ff49733b6179e15246bc89971830913c0c225e6fd33bab45f351768e60d9016b5dbe6c9f4cce77d160878dc2a27e19edca99840bc821a66df08234e37b482e1cae6644af512098d2495c11ecb228a57c43ec86768f732eaa843d810a0faa286e1fbe63bdc46bf9e852e349d15c0a170c8fffabd3dc7839f6a8190b7184ec66bf453b4eb894885d61e9e21438073e1729f784790935607c7cfded186c2a6b134916d591421f72aef18288cd68f97f0998c659a81d73526766309ac0300415da7b642dfe8ba7e3c9c37af67b4893f119f69985e1e16f4bfc24a1dbb04462575658584d7a752252839e0787f818f41901f5080e1d52f35e165003d5c0f8281cca9a45dc44769f5665d33df75ff7ed753aecec1308e456ddfee4dfb559bb6fb36cfa647b5777228cee24821962f8350ed090a538f12a50724188e273c645315f4da6267f040104edf9029bbb4da1884407f8437f5d1665d870885f1bfcc6b28d3f367465ef32dae8fdb43ffbdeaee77e4193482563fcd3d841e2003850e5a4adfab4a1dab93d42a9d707cc91f5b78382bd068555baee3664a461831989b94c420c1bfc0b53e8e4a1b26a67764ff9d721bd676265bfd2d76548d3ee2aff5fa8c6f28673111195dd8108568c5baeb5928123cc3c1b07c07cfdfb5d1b71a90bc96b083b75ada40678238949c508ba6ce3af28e601b3ff5c087f63876b575fd2eb7323053775f5487a6dabf336946eda37230d3afe6a75e16af37a9193bf5ed51d5efbe577c4527d4cf0d0b8fa8a5f15c3a0c86b2984c2fa556522afdc5cf3989be38b3f1489a775cc80126f4d1a8441834285954db30d2035e886940aa2254c6a7fa3587c874574b47e8979ae0986eb3088e01a1a670b2d7b5f7f042960fea80d5a4b7db00cdcb715765d11897aac6584687657e883a35e36f6bb2e461ef2ffbb4694e11a41c08e8059b623f10c48f63c62fb5a371680dbcbaefc2f43d32e52de3db301729a1b604cf905eaf28e369efd2b04c8a6bb11d60be37de8897e2fd350db4d073e1e0ecdc8d430eadbcce1c2f9483546647d3dbd75abeb905506182853505c63ed3e3fc8bb6c544a55ec2358f987e91434db7b3b17e514d2f48f7319c7ef30eff72cab9a0852645eadbe45f34bd141f5de7b6dd367854ba7fd6658e0ab2ee66dd20f2bbf921f3cc5a0563ec062df41b6c9a4aadd81c262a9683ed1f5beed2cb04acb8ed18581103daeee290630e04d67226f6ac86d5c680cd7cf4c79256d383aad62adb72a01eec6d9f098d5ce17185b645b64c52293358623fcb8c77479dceacd1f35821b2e43b825223eadade6c6fb97aa9226edb450e9c188133f2b5ab21b3600f488f34a18db510c4fb0c894345fc280833c53bb2bcc559bc70effc2b5eca18b6d2a609fba4f8f44f77c93b8ef7d642011a633d790ec454d67642a944ad1d2aa5e96bc51819452dbfd7177f3dd9e1579be6ac226caa88435614d0c29b519def4c5f36f85425bdaf8dbf6e858cd02aca16c6c9d82a0f18c5090080164047f2e975e9ffeac708d3a2b8be97695b2736897676ed49b9dfda9c890da00b0cb6da8a832264cdb48d8779e719246a6a830fd4033094135fd6b9e636240a4e0349526f4536b5bd4b736cdfcd46a88de2344fa8db7a39fceb5b724a9376f7e51aa417f1a10baf63cf530a4e759c4be80b251ee82cb392bbd7183039d952a0d4d1ed64f506d9efe23b37f970187481518b39553343e89b89c2f6dcce66804b8d45e1d55ec1dc36cc679e462ef0170344a83a53bc23044a873d608da8320ac65e235db368ec238efc73a0203508252577fec225b42f66ed7935d065051184cc0371494b774893d57f30bcfbd03c7ab000091123fb60fa23dc7977917000d8e9ddab549cbf957485e17c342807ad67edd3919d1d5c4c847c8eb7c6fb1b6b756bbcaac63bd1cdc9f8d96cc9f91fdca6af5f66e6ddb2355d6387d4229529bedffda6fe0a77c0907cdfcf445c8c720eff421ee021081d34d0b73b54b3d84781a1ada9dc628a4b59f6253f1a3cff7e82c31014abdfb9015711302df5363c688e3232679cfe23c0b273f68c0e161f6548b405e8177ccef5ee92b215d98cc128ec7997bc8f7197c143accb3c720c1f4ed2e331130e4a70df1d89d4ac6bfc50c642cc8cc1b05040cae31594015470b104163e85a9f519ec28427b47a3a8a0b92dac1276436acbb54bac573e9b83af6955baa5e254871e2e681ac5f42219834da9a5411d59f497c6df3a89b46399e8060121f44b73ac189060dcfdc7e66f426462aeb94eb0d7a16135d140ece4e04fab9f317cd83c2da92777bb26d75957c8d170caff2d1572dee417551be25c2b0446cb6bbccead36a25e3a2f523bc9b6fe3537b3fe0aa0918ff2e90d41ab5d8203c9701bc04cc8b426fbb2b25601df442b472e6b5d3c2dde368e1329c36b3915b82af2137dbe48a5ab8cf13af4b255dbd31ea11473575a63c08ff3d36ed69a0982b7e2faf71b27cc091d7944b25c30144c6f1e98e0ff646ca67f3c1eab89ff4d3cfbdcf15e475bdc50b64f802fd83ffc56f99177e399c256d93b6fe616073e922ccea2b52b84eb6e9ed064f7acaa2bf7fec7dd2bee3d796bc0744082041a06cf8f1e45dd44b8bfc02b1a584fd52817f2c16f6d26828f8fe32f5863cd938c5d2c7cab425f6c614225dbc671e97634e210c017fa39c3f630c22a6c1ac6673903e55c2f09c09aad4dabb76072ce6ae8beaf03e48c627465dda54afd436d47f007c5b1c7b52cf55830d6a3dbcd561bac52be9e131182f46854ba40f55c86c7935413f3c9ebaed553f9b9fafb964f0c5a03ee454b8a21bcef78881b1dcd9e4f0944f5e0dee6770f7d32e058739d6a63eb6e264ada03dc9a30d0b1db52bb8d96dc1f7c6265fd93ec0da79c5898fbf9ebb3dc1bb2ffe8ad5eb8ab90e70f448d5fe3fad48c56d1bfcd93dd5b11f413eaeb15c0056ce58e6652cffa6da783774a82e27db165d9d836346f72747d8c8d85f9487e22f9fdd22afb05e33f35a5cf7168954bcfb11617d30de40fa8ad3c2f8f52d1728c2fcf55f6d1ebbd74086b553b14dd513b6350e3a768b8678ca52b18189a5b85564134db150477a016b7824e73e59449451b33fddc3fca5183dc7d9a198d69544c402d09a96e837c02247e4a6130d6eed2a9f2b30c3f738c35d70c85248c3b057359ed5ea1cd52b3d75eb9d54174e6a28ee2c6111a86baa9775f96a245abd0122b84590b748d11e36778668804478853cc95a6b177be3e89ad0d4dd55cf07353cb8977d3bd98060e117840d167f0db84d406970401cb2938b18074c16b36f9fd560d2658a28f3aee83ffb01f39fd96972dbcddd32018d34891143f8288664e979993eba480034fdab02115f30ad476c5814c52236c0351dce3f0dadbe16ad102d558e58e46f4de316d601f1eb8559fd6e7fa0da2edaa56f5a01fe1666e4700cbc5dc1ef9f7674f1fa53a82de533f9084a762ef55562b17634c10f12f1430c0c7be8aa9798546cd20c5eff8408a3cb350afaddd7ee636cd8ec151e393db773f5bbd9e176a34373d86ef942dd0d79b9e271371ed04fc6bee281bbcbc2cb0964bfde1e396a4c18625e8e24c29951cbdc14718e6d5109b0c08565d7735b9bca70a223539dda13c5e09eedc6ac0cfbf99a4807070785cf8dcebbab95d7a05ef72583571f7cf3444111c2d7cf6631862d9975944aad75d7121705fae35559fcc29c10be0ef7945100115b9f3c54195f6ba9878e79c64132a7fe77767413faf8cbbecf2ff69e85ec340b5692343cbd35c12b18aabc308b5d49214f95c8abe9237658b6f43919438f0789c7154d639c21103181eb034aea16574d9b6b961ebaa798d75ac2904f37e5a683dbb687f10e0818620bbadd332c64b26e0a1f4c6f64cfe00b35e9c5c8265032b1bb6ba5b13d924d0d200a10249cf5b69919d56f2f8ee7d0400c4ebf7153181646511f2519b3bca740aec21d724ced7aa4b820ab901cdfea9c89112d9e50021c63c6707ad027f5ca0be19cb4de574ebbafd938b3e9570d8be400d97da0ee86ba610153c7075ffa8b175ef3946454d98d904b82ce7ca96ff4cbac78721ac8c31f05fbb8e42c55b32556888450385e3540e73d58af2f6078582f2e941d213a237de856139ef5954f8af94fa85a9ece6f4b649d63fb0284a9c4fd576ad72a86371c8e8b2f43c27ce93027d0c7593926a6d69e87ea5795b61888c1aa80f605d1ba68fb1af27697f8a409f800b9405fc44a2b70c283d640d237b73b444da8326e7171c2f699e87c63a02d79cc10e62da48ed2f97597ab3c57c2944b11186e1df36974cc03a7c87606755b499406d36a35de4966e5a983e8cf04168af815d21fe1af84864fdbc6fc0b1a881b7f266d8cf96c7b67bd124bb3c785236d119466f2ff51edef931037f4fda1951cc8518579c4fd97d9e6e43c8848d5ec133e47a9aa5bc6f49295e63884fcb22e77fc54e4941241b888a31aa59e107b714f37d474deb8b9a62bd3a6e3867e6b8a972ffcbdd03d0c48345a50b025da83de2dd8136643c674915030edcdde1db0742a3f69d8dcbe5f87362de6cad7bb3b395799a1c98d7ab4b909d19699256f2e028fa054ce49aa8645a150c2dcf0ebbabd87f87c14285b7475ea9fb1a2b772092d94e4a2332122b14c958c48dc2d147d4f797e5cbb1ade04c953f37555803900b7091ad9c274db66dba1ad056534beb09ff8030ec81d88848d7089d787aaaf897a74f9f91692557e5b306cbc359b986356bdfe5682a624c554dc42f3e521c76711beaa01733ba252670a55910720d4e62e0d294f49c7a5be941ab31619b07f28784a8196105c38585c29fbdfdf32b29c9dff18edb10cd5d176199bbec3d9c4b2eb6a5ee2867b255ad92ba3774d2356ce55e4ffee3c5cf8fceed59dda03fa9cda4bd1fc8f7005e2d9b67b2b729af552856a2d69a43380d8e3582bf5a0844ad15b75115a79b3c343c898164ca54480b7c4111b33949585bd30e2e660344012ad27a9e85fdf6ce509e07ea1ad1d81816db8e485d029101155c57641e2839a65c77e5eb43ccd16f81f626bd74c084bacde9e7716266b39a463ab4a1f2055fbdc00c20ea10db76139a5b90e106bfa4a51f41d475c303d094b6aa0303775b834388fee4d6677e18deecb5eaf8c3d591d3cb4c956ae34c7c60fe071f5d3f19cab9a59dd9423c6e88af1fa1223501da07cc214b18724ec1c587951ba0b1dc970bda7dc0ef804fdefebadee0965e023312ab274d01ff551753dc0b7afc85e10b68a9f56428cc2267fab541213b3fbf509cab4daefa4c984e8b1480724e2e399e42086c67fecda7789d5c380e0f257e6e475c63c832aa4b17c31f83ba5d7ca5db9fdc57d4dbc9e8affaad3b65d1b3c4bf0b75df9f602ac32d1ea696219afb6952a294f4b540cce84a33242e065c609afa4e97d83aed8fbc70e410bb4ac1e64656c713f72378bfbae088c13d3e8e1fadbd2f5cfa1718d26c9376cb66449aecd642d476cdd411ab79511ea6608cfc1686b83d4ea4a0f8f197a759b62753860ab0c47b8caa719338d29ee89c6953ed4beebf5685b8b2ba9eb59fcefa66329670c5fe2ca4435c41b5ec4bddd9a69aa5727f8c7026cc337e7f5ea2b85d3e6eadf65d1da59921e9601684cbd6db98176793a8a778e4f97171b0a271463c772de46a0436964b32a57a00ff7e9b78ca13c743767b460bedf3a1d701196e2a87424a7fcdfaf115afcf9476b7992addc11bf5dd4485153818ddfe711c3fc14fb30aa9336100044e5a37d30d6d246459a6c6c38a28b0ee36c5f4ded811a115f23d4853e71cfbc48617fc8d469baeafc65234b2284f93d2a41953de6549f9c41b571867bbb6ff418332d3cbcc109f85d59203bc4d222a70ef70373f65e9cf0780289af7a3d8d168265f3864c5d2e933bacfa2424be11948b89596109584ca6e8ee0144c3d99a82cfab8846844f118601ab906b0b44730d79c9169db3822060b3fe635b51c060ba336c774dd1a5612319c004cd5a626743a468607a7cce9fd29ece8b85e868444b17ce733e80d2eae2e43585ed707a50ce1b2a2173dceff5f35b4dfeb79a69e18ae83d3f8445f0dd7f896096bd7e10383a59f95db4cd85ed6e54ca1cf899e13cd8fcf8d894fdde52f8598fb1581db8f2da9bd57d644127db11aec8803135259c6cad21a3a8cb51b86f5832f74d2d7da4c00ad6e04975e7986d4d7f5182ad6ac51225ea5bf595012f4da7a714ff27a654cbc5614843c848aaa8d1e71be240742e0225408d964430303d332924cf588f4c0bfb75f32c2907095476f00465ce5377a0864ea08f2916a2194b915e61d9829ba0af574d7d8d4fc61be6557c49d9b1893796a674dcd4a2d0ab1540da21721f9ba2889d40d11d15a03f47fb9b4758fb5d396fc3ef09dd2eb17340651bbd4d4d302171b64a5d134a14c2f5761d69baf6e087645f1569ae3c9430bd62569a771c3c9d386357852630d14d59bccaae73e88e79fd335da885dbc26e317a560e886b46237a9bf974c90f17e8d1a3193eb8f6a8a4085fe6afcfc6625155f230cf95e28b02b2aa25a07dd2b9402a7e11a026050b95f200b7f559706d39de6ea5c6a3290939e06c2dca3293634d1380cbea8776653dcd705517ec2d729f81f6402d57a065a801fad2f4c318f858e12657835c6477ac3168ca4094abd3e684a49eecb3f72361e2950d32c7279a81d3d6a36479bb03f1ac6bfca0e129b096f3fc11b1a31322a3603bdbcf5f25ef6983aabfde61dbbfb31aebf6a6438c0de64b0fb58146993c8339ed1575816a6db7850ad758ee3d1b493442e12deb80ae936380c081a69dfbe7b86cbb28d5c225733e9c7e7674418cc7696f6bc482688210a51cea3c76ba11c21c21d75191c1f92f2834c1a9f9c6d1be9ad98508e7b4876621c126d0a3b9432e15f6aef3241bebfc3cb8f2dab4b96f97a61ee2e7312845d3614d817793f6c40190d7b17ef2b7bfc8ce665fc927dfd178722fa98d37e58d5c3ea763893f1f46390b9e412bb7b986e6f26e6b4998a7b7252bee2a919d92a4f63bcbccf52f7a4236cac4964dce74ba8572e8481de412bb53a0ec1667d3f64526bce5b1d39b5a49449f20a6d274d55e60b0c722a8c3606a1aed9a73738d634bd51a4b4be81283351fabfe38d8bc07b96495b56be9c69adf49958224936770455c97be2e895476df55af2d69e308a5b1f898d2d60896055b8f95f99cda6c961be77245025b3aae7411644fea5d5ed7c0f9fb6a9d48af4287b4be060236cee349ec67d4e94f6da473e30d4d406d95c62c1e7814aafe12b62e4ebfa9b4421b156a67e6743bb98d4bd17da6eec1e5a6591e5b6215675d6704257ca0cd1f71717e12fb61f365c8309df3e3e7646cf2ca5bf8fbb0e602e769c5510b11bbf114744ee38b80e0200a059a64daa7b699ea04851f976a7ac131cc0e2da1375524def3476375b4c4fc0e8e9e114f8873394b2ae418d4bff3bb202b523d2b7c897bbbac4f2af74dd5887ca6f5bfdc6a379332dd8f0a6a3b5792c1f1921642c1498dc23802f39f4e43e8f51f3415daa93f1985ad00c9e8768cad571d2016f57b05337882a38ad9f4470d205b1eb895de995fe90369bf0b6c0d73c5923465938cf6750d0a46ef63875d8eb0958c48459bae7ed3d0e6f1a4ff0c876e86f23f199e98d6fc6810cc76de5161e8c5d2e502ef34cdae2115a05ce7760248fbf9d29f89d80de97a7c4ce37d6999ed4c65057c55aa5b6295e0897474a4abd86b58a630b5519e24a96a9c36481adf71efc31aec6227002d4c5671641c259859e515e84034740a8fa2decd0cf594aca7cde73ea9f6beecbfbdac88cac419f91c685e36f599e7419d1b68ee540daf765f2281a336d8d5994334420ccf21ac60cde19a49d0df073a40445ecdd194aecde7a0c42d2d896a031477712bf49b2967b5d1a24f133bb7553be28f71887bbc6f8b53795a1b06c323fab7840c85c24e06f6df3f449c39f7f4cfbc5e74ab0b6f54dd85d46be27789f44508d7a4e0294ddb7a972022adef1feb4bbf80b6acb41388b29f99d86196551e89be73d3fda6fbd1cca14dcc0044a97c9e1430600238a4ed27cb144440da1d6273ec8750b8d8035c7924a123c47777a396502a8ab6b7b98c93fe28a08d8377a606e099c8ad9f42dcac63554b356a129a9e9573fcfb207b27baa436c6d4ddb4f8580d914a1263461e304db5e0815f7dd9b755db529032597b77050aa6c653afe3f7d7eac9e3df2d52b926639aa3f51d8cd5471da36ecf408bd859ce900e439901bd20c3c1bf000f6e62cd234e5fa295118a5b5f55100702fdafd43a7398894f4a3dd4f74889d27294143d5f3609d97ac3323c6f3d6ecbe990dcb5d975358f54153f286e78c8cfbc76cf3e2540614252d267ac9327d13fde8abc4b282014be61a11450aa26626c478ccab01c380f39cea9dc5d67501ab68b06bdcd6440d7ece6f784539530afbb27edb7b1a83bf6576ec304ad3538edd4a02e1fe9ff821eda6d9c8f6eb4ebad0d80fc45576ab4426f0b390ce9fb42312c23430d040d85efa8cde8e1a3c47a082d33cbea897edf90b00820032156816c8cc1218b9cbc41108f910a9a072afb6d94c20b5daa083a8c6f1e49570a82b779b06e91e01eeec67ad5fcc586401c91030a8300014a92973e2b4653816cfd1866ebe6a07b7b9050176f3f0fd7deb7094b96dca67a7fab85f80275b5616414ba3d11bed295420cb62860d5a01fe557eba85cab0dfbdd4ed1d7f30cdc0540690d7bfc99ff1e5915e91fd99a5b94d2d26eaabe72c2e727cb88748e83899ee6f2f6efac8eb7d66b7578fa17671b4b70ebdf40a36ec697ece2a6d2b170bd083c0efd515b81acdf56c750064571d635ad50165f1e98519b12655820ef9393b33d71e037d8ae46f6e9ac84b732b21008111b16796ea62181f264aaa19c362b426516c97bbdbbf0b0da0e47f805847067261b62d7d699124645c6a6a983565815e6de4fbc31263380b6dc811fa9d4c1ed15690b2dc7c1afa5a4a810ee69bb8759c898287630273ba24ee35f314790e09d865d2e82dcacb1ed2ef7614e2bd9aaaf2c7b1fd1cac6b3b56058d33a13e5d998b5cec54b5968271a32ce79f80118678f2978011bbaa86de2c5579e966ae17c6dd435279303fcb2d1cfdffafded27c921d1feea042f83e96f01bff7fc98215044eff87f28e65559c9b030a0676eac25552b5961084f162e8bb638d52c81b091ddbdaaf684c6f1cce30ff4c8c60f55148aed8bc5894c22114a2f37c483bd9d9eb809a483f918cd901f9c48251f8dcb19f35d61bf1105ec96e66f22601575a5abeedfd08dc5ec6669790c3b47e557d391adfb259ee0c86566ea1c4a93ad18003cb35a752e91df73a688cd65b92b754071ce3f6328f76c6d6f455eae1c4cd80e2b05cc183e1dadcd83deab48dcf62d191e0f69e1ea30f050b80640b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c645236986f1affba9e034017145436f7519e5681fa5b9940890979fb54be43bbf99f2f71b43a722f685d02df3e388d22f59d29fac0d4f0fce99aecf54c04bbea999f2f71b43a722f685d02df3e388d22f59d29fac0d4f0fce99aecf54c04bbea93edab1ff7eb6bf33f108e9ac1a08eb16c954b88a844e3119adf5950b44014eb611cb6f5cf19bc18ac0560bff08c21e5a715d9e488ed7b90715ddbb518fd57060e234489f88176e66bd858291d9de7054c6bdcedbb9f19ebedfab02d238b3dad79ac6a853e324ff7c5e92f5e9bbbfcda63466ec3e8a17fd9b3247f183465e93ca372fd5afc77f0d7f38658bb86153e8c7472376a5d735412237aea47881eb714ad1ffba188101427d74509d8786310f1e0793a251f31819283664626cbb6286bcdd109bc3de5bef59a8492c6f849e7cf1c2a665d6b5844e749d36a714fc4eb8f652fe79b889ef808d2d515a143bd50327674d18780056158238e627e37eaf784b4505976a7c3561f4c11d3d6507b4c18b802110be70e1266ecd65aa25fca9510137f5d6822f4308c7525d307bc5aa18c4a8cd6450e22a5d3ff8ec4fd0e0db96029b188fe909be6889a961ab6d53b11520bc8ef965b7387b554bd7c482b02b0f4f80d00110a008aff7aed1c6d66dfb2edfa2605d155c2d97a1c2877fd1bf4d770e6708988dc83ba66d6a40a20293dfee564ed40c41d5e541c2997e512019841b0b19fb878199014dea84874d11e319609135d4251944a93718a1549871f86355fe0d12397a1e4e4db62d46514798e653a11b107fa6d6cbd7c1d4a8795f849809cbf723c6b3654d1ff2ac20fe4e91db0ffb8387d06864cabae9e45d13b197ef3dcccc6b0296da09999c1156c66710e48fad121d7a7eb3f20a9281c83c7715e7f759dd2b11d8da24b078973a81d23f56a3cd370391c47ad7ea923f5233254b2c62a41ea39a3c45f364074338dbc792fc2c11e46cd8506f84eec2d00b8b7cd076d84a54a4e74dfb2af63dad0b61ff21f4f95994201c284fe8f586948c544ff57e966e81d01c4e3d56cb060111b09771b67ad0ce7c76f75907623f84b05a05d45611f5bc55eab02c151e601843afc2885ab9824b294c7d32e6352066793e8ccf6663071d70e16fed8696139a12f8dc737261cc47235f1f6043d92c85ee5f87b03e8429e9657bb9f64a21db6c7e0cca7c1f3ff6a65af73bbecb35b1a93de7ddc539df9a5eb5dc9143c8d61b9b80d5cf522b829938f539a301cd22e79e52f6213df15534953e17076aff00521a5402e73915fd843905ff5a92e6db5564e3ddd38febf2dc5e8b6c7840d556c9d7eed953dea0cf43b01fecc45edfa2a8e9b2cfb89d9914c4b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c6bbc3dcd02c734b5a033bb15077310fc031a2066afa3e7239c3c5c3fa96044da2@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootselinux-policy-3.13.1-229.el7_6.5.src.rpmselinux-policy-devel       /bin/sh/usr/bin/makecheckpolicym4policycoreutils-develrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)selinux-policyrpmlib(PayloadIsXz)2.5-82.5-243.0.4-14.6.0-14.0.4-14.0-13.13.1-229.el7_6.55.2-14.11.3[[;@[;@[[R@[t[#@[@[@[[h@[[[9@[@[}P@[{[{[z@[m~@[i[i[i[dC[`O@[]@[Y[6@[3|@[2*["X[d@[[ [ L@[[[@[ZmZȲZZH@Z@ZZz@Zz@ZyZ_:ZWQZV@Z.s@Z)-@Z%8ZZ @ZZNZNYYA@YYW@YW@YYY@Y@Ycl@YP@YJ_YI@YBvY9<@Y6@Y5GY1S@Y0Y.@Y-^Y, @Y, @Y%uYYY@Y@Y@Y.YXQ@XXX@X@X@XXX@XۡXP@XXg@Xg@X~@X@XƉXCXCXX @XXXBXXXs{@XY@XWXRXRXOXJXAb@X@X)@X#X!@XWWSW_@W_@Wv@W;W@WίWW:WQW@WW@W@WW~W@WW~D@W{@Ws@WrfWj}WbW^@WYZ@WYZ@WUeWM|WBW9@W9@W1@W(W V@V@V@V޾V2V@V_VVCV@VZV @VqV }@V }@VBUUU@U@UpUUUUoUoU5@UUȒ@UĝUUWUU@UUK@UUU'Ua@U~@UzUv@UT@U@Tr@T@T@T7TTTC@T@TTT}Tto@TsTk4T`T[bTWn@T?@T>aT6xT6xT@S@SSDSg}@SB@S>S;S:@S9XS5d@S4S2@S0@S,)S*@S)S)S&S&S"@S!S L@SSS@SSc@SSnS @S SK@RRR@RRJ@Ra@RRR&R&RRR=RʚRR@R@R@Rv@Rv@R@RR@R R@R@R|@Rz/@Rz/@RsRpRnQRi RfhR_@R_@R[R[RSRNRNRL RIgRB@RB@R:@R1R-@R-@R(r@R' R%@R7RRNRR@Q@QQdQQ@QQޞ@Q@QکQکQ@QzQQ4Q@@Q@QKQQ@Q@Q@Q@QQ@QQQQ@Q@QQQ@Qzl@Qw@QvwQo@Qo@QnQm=@QkQfQb@Q`@Q^QZ@QQQIQGQ@j@Q9Q8@Q4Q0@Q-@Q& @Q$QQ@QQ@Q @Qh@QsPP@P@PP@P[PP!@P8@PO@P @Pf@PPqP @PP7@P@PPPYP@P@PPPM@PPd@P@PoP{@P{@P@PP5@P@P~P}L@Px@PvPvPuc@Puc@Pr@Pmz@Pmz@Pmz@Pj@Pd?Pd?Pb@PaPaP[@PXb@PWPS@PQPO'PM@PIP@@P>@P8@P7lP2&P2&P,P,P*=P(@P#@P#@P!@P!@P@PkPw@Pw@PP

@NNU@NNl@N@N@NåN@NNNN@NNN@N@NGNGNGN@N@NNS@NS@N^N^N @N @NNj@Nj@NN$@NN@N/N@N@NFNFN@NNN@N@N@N]Ni@Ni@Ni@N|tNyNx@Ns:@NoENoENiNf @N^"@N\N[@NTNS@NS@NC@NBrN:N98@N7N6@N2N.@N*N)f@N(N%qN$ @N@N7@N e@NpNpM@M@Md@Md@MM{@M@M۝M@M@M‘@M@M@M@My@My@M3@M@M@MMM@MMMMTMx@Mx@Mv@MlMbSM[@MRMQ0@MQ0@MJMGMGMA^@M>@M9u@M6@M5M4/@M4/@M0:M,F@M$]@M@M9MMMMM\@M M M@L!L!L@LL@L@L@LOLOL[@L@L@Lr@L L,@L,@Lډ@L7LLLNL@LΫLeL|L@LB@LB@LB@L@LMLL@LdLL{L*@L@L5LLA@LLLL@LcL@L@L@LzL)@L|L|L|L{@LvW@LvW@Ls@Ls@LrbLrbLmLk@LjyLe3Lc@La?@LZLYV@LXLN@LN@LMxLMxLI@LH2LF@LEL=L=L=L;L7@L LT@L@LL@L@L0LLGL@K^K^KKKj@K$@KKK@K@KK@K]K޺K@KtK#@KKՀ@K:@KK͗@KŮ@K\K\K @KKKKK9@KK@KK@K@KKKKrKK~@K,K,K,K@KK8@KKK@KK@KqKqK}+K{@K{@KuBKs@KqN@KjKie@Kf@Ka|@K`*K]KXAKTM@KPXKEKEKEKD{@KC)KA@K;@K2@K0K/c@K+nK*@K(K"4@KK>K>K>JJęJH@JH@JJJ_@J@JjJjJ@Jv@Jv@Jv@Jv@J$J@JJ0@J@J@JG@JG@J@JJ@J@J@JJJ#J@JJJ@J:J@JJQJ@J J J|@JzJyt@Jyt@Jx"JrJrJq@Jn@Jn@JmJhPJeJ\s@JW-@JT@JS8JKOJI@JCfJCfJB@J@J@J?r@J<@J;}J:,@J7@J67J2C@J0J/@J,@J%@JJB@JJMJ J dJ@J@JJ@J*@J*@II@IIA@IIII@I@IIIX@IX@IX@II@I@IcIIo@Io@IzI)@I@IܑI@@II@I@I@IԨIд@I̿In@I3I3I@II@I@IV@IIaIIm@I@I'@II2III@IIIIIIII@III@I1I@III~@I}Iy@Ix_Iw@IuItk@Itk@Io%@Ik0IeIcGIa@I`IVIO@IJ;@IHIAI>]I= @I7@I6tI3I-I@III9@I9@II IP@I@IIg@Ig@HHH@HrH~@H,H@HCHHH @H @Hf@Hf@H@H+H@H׈H׈H7@HBH@HǶH@HH|@HHH@H{@H)HHL@H@H@H@HnH}H|@Ht@HsVHr@Hl@HkmHgy@HcH`H_@H^>HRa@HQHQHO@HFHFH$@DX@DU@DN@DN@DLDH@DGwDGwDDD@@D?D?D;@D;@D:HD:HD2_D1@D1@D-D+@D+@D'D!<@D!<@D!<@DDD@D@D@DDDDDD@D@D@D@D uD $@D D @D @DDDFC@C@C@C@CCCCCR@CCCCC@Ci@CC@C@CtC@C@CC:@CECCC @C @CعCعCعCعCC@C-C-C-C@C@CCǖ@C@CáCáCP@CP@C[C @C @CCg@Cg@CCC!@C~@C,C@CCCCC@CC@C@C@CZCZC @C @CCCf@Cf@Cf@CC@CqCqC @C @C @CCC}@C7@C7@C7@CBCBCYC@C@CC}@CqCqLukas Vrabec - 3.13.1-229.5Lukas Vrabec - 3.13.1-229.4Lukas Vrabec - 3.13.1-229.3Lukas Vrabec - 3.13.1-229.2Lukas Vrabec - 3.13.1-229.1Lukas Vrabec - 3.13.1-229Lukas Vrabec - 3.13.1-228Lukas Vrabec - 3.13.1-227Lukas Vrabec - 3.13.1-226Lukas Vrabec - 3.13.1-225Lukas Vrabec - 3.13.1-224Lukas Vrabec - 3.13.1-223Lukas Vrabec - 3.13.1-222Lukas Vrabec - 3.13.1-221Lukas Vrabec - 3.13.1-220Lukas Vrabec - 3.13.1-219Lukas Vrabec - 3.13.1-218Lukas Vrabec - 3.13.1-217Lukas Vrabec - 3.13.1-216Lukas Vrabec - 3.13.1-215Lukas Vrabec - 3.13.1-214Lukas Vrabec - 3.13.1-213Lukas Vrabec - 3.13.1-212Lukas Vrabec - 3.13.1-211Lukas Vrabec - 3.13.1-210Lukas Vrabec - 3.13.1-209Lukas Vrabec - 3.13.1-208Lukas Vrabec - 3.13.1-207Lukas Vrabec - 3.13.1-206Lukas Vrabec - 3.13.1-205Lukas Vrabec - 3.13.1-204Lukas Vrabec - 3.13.1-203Lukas Vrabec - 3.13.1-202Lukas Vrabec - 3.13.1-201Lukas Vrabec - 3.13.1-200Lukas Vrabec - 3.13.1-199Lukas Vrabec - 3.13.1-198Lukas Vrabec - 3.13.1-197Lukas Vrabec - 3.13.1-196Lukas Vrabec - 3.13.1-195Lukas Vrabec - 3.13.1-194Lukas Vrabec - 3.13.1-193Lukas Vrabec - 3.13.1-192Lukas Vrabec - 3.13.1-191Lukas Vrabec - 3.13.1-190Lukas Vrabec - 3.13.1-189Lukas Vrabec - 3.13.1-188Lukas Vrabec - 3.13.1-187Lukas Vrabec - 3.13.1-186Lukas Vrabec - 3.13.1-185Lukas Vrabec - 3.13.1-184Lukas Vrabec - 3.13.1-183Lukas Vrabec - 3.13.1-182Lukas Vrabec - 3.13.1-181Lukas Vrabec - 3.13.1-180Lukas Vrabec - 3.13.1-179Lukas Vrabec - 3.13.1-178Lukas Vrabec - 3.13.1-177Lukas Vrabec - 3.13.1-176Lukas Vrabec - 3.13.1-175Lukas Vrabec - 3.13.1-174Lukas Vrabec - 3.13.1-173Lukas Vrabec - 3.13.1-172Lukas Vrabec - 3.13.1-171Lukas Vrabec - 3.13.1-170Lukas Vrabec - 3.13.1-169Lukas Vrabec - 3.13.1-168Lukas Vrabec - 3.13.1-167Lukas Vrabec - 3.13.1-166Lukas Vrabec - 3.13.1-165Lukas Vrabec - 3.13.1-164Lukas Vrabec - 3.13.1-163Lukas Vrabec - 3.13.1-162Lukas Vrabec - 3.13.1-161Lukas Vrabec - 3.13.1-160Lukas Vrabec - 3.13.1-159Lukas Vrabec - 3.13.1-158Lukas Vrabec - 3.13.1-157Lukas Vrabec - 3.13.1-156Lukas Vrabec - 3.13.1-155Lukas Vrabec - 3.13.1-154Lukas Vrabec - 3.13.1-153Lukas Vrabec - 3.13.1-152Lukas Vrabec - 3.13.1-151Lukas Vrabec - 3.13.1-150Lukas Vrabec - 3.13.1-149Lukas Vrabec - 3.13.1-148Lukas Vrabec - 3.13.1-147Lukas Vrabec - 3.13.1-146Lukas Vrabec - 3.13.1-145Lukas Vrabec - 3.13.1-144Lukas Vrabec - 3.13.1-143Lukas Vrabec - 3.13.1-142Lukas Vrabec - 3.13.1-141Lukas Vrabec - 3.13.1-140Lukas Vrabec - 3.13.1-139Lukas Vrabec - 3.13.1-138Lukas Vrabec - 3.13.1-137Lukas Vrabec - 3.13.1-136Lukas Vrabec - 3.13.1-135Lukas Vrabec - 3.13.1-134Lukas Vrabec - 3.13.1-133Lukas Vrabec - 3.13.1-132Lukas Vrabec - 3.13.1-131Lukas Vrabec - 3.13.1-130Lukas Vrabec - 3.13.1-129Lukas Vrabec - 3.13.1-128Lukas Vrabec - 3.13.1-127Lukas Vrabec - 3.13.1-126Lukas Vrabec - 3.13.1-125Lukas Vrabec - 3.13.1-124Lukas Vrabec - 3.13.1-123Lukas Vrabec - 3.13.1-122Lukas Vrabec - 3.13.1-120Lukas Vrabec - 3.13.1-119Lukas Vrabec - 3.13.1-118Lukas Vrabec - 3.13.1-117Lukas Vrabec - 3.13.1-116Lukas Vrabec - 3.13.1-115Lukas Vrabec - 3.13.1-114Lukas Vrabec - 3.13.1-113Lukas Vrabec - 3.13.1-112Lukas Vrabec - 3.13.1-111Lukas Vrabec - 3.13.1-110Lukas Vrabec - 3.13.1-109Lukas Vrabec - 3.13.1-108Lukas Vrabec - 3.13.1-107Lukas Vrabec - 3.13.1-106Miroslav Grepl - 3.13.1-105Lukas Vrabec - 3.13.1-104Lukas Vrabec - 3.13.1-103Dan Walsh - 3.13.1-102Lukas Vrabec - 3.13.1-101Lukas Vrabec - 3.13.1-100Lukas Vrabec - 3.13.1-99Lukas Vrabec - 3.13.1-98Lukas Vrabec - 3.13.1-97Lukas Vrabec - 3.13.1-96Lukas Vrabec - 3.13.1-95Lukas Vrabec - 3.13.1-94Lukas Vrabec - 3.13.1-93Lukas Vrabec - 3.13.1-92Lukas Vrabec - 3.13.1-91Lukas Vrabec - 3.13.1-90Lukas Vrabec - 3.13.1-89Lukas Vrabec - 3.13.1-88Lukas Vrabec - 3.13.1-87Lukas Vrabec - 3.13.1-86Lukas Vrabec - 3.13.1-85Lukas Vrabec - 3.13.1-84Lukas Vrabec - 3.13.1-83Lukas Vrabec - 3.13.1-82Lukas Vrabec - 3.13.1-81Lukas Vrabec - 3.13.1-80Petr Lautrbach - 3.13.1-79Lukas Vrabec - 3.13.1-78Lukas Vrabec - 3.13.1-77Lukas Vrabec - 3.13.1-76Lukas Vrabec - 3.13.1-75Lukas Vrabec - 3.13.1-74Lukas Vrabec - 3.13.1-73Lukas Vrabec - 3.13.1-72Lukas Vrabec - 3.13.1-71Lukas Vrabec - 3.13.1-70Lukas Vrabec - 3.13.1-69Lukas Vrabec - 3.13.1-68Lukas Vrabec - 3.13.1-67Petr Lautrbach - 3.13.1-66Lukas Vrabec 3.13.1-65Lukas Vrabec 3.13.1-64Lukas Vrabec 3.13.1-63Lukas Vrabec 3.13.1-62Lukas Vrabec 3.13.1-61Miroslav Grepl 3.13.1-60Miroslav Grepl 3.13.1-59Lukas Vrabec 3.13.1-58Lukas Vrabec 3.13.1-57Miroslav Grepl 3.13.1-56Lukas Vrabec 3.13.1-55Lukas Vrabec 3.13.1-54Lukas Vrabec 3.13.1-53Lukas Vrabec 3.13.1-52Miroslav Grepl 3.13.1-51Lukas Vrabec 3.13.1-50Lukas Vrabec 3.13.1-49Lukas Vrabec 3.13.1-48Lukas Vrabec 3.13.1-47Lukas Vrabec 3.13.1-46Lukas Vrabec 3.13.1-45Lukas Vrabec 3.13.1-44Lukas Vrabec 3.13.1-43Lukas Vrabec 3.13.1-42Lukas Vrabec 3.13.1-41Lukas Vrabec 3.13.1-40Miroslav Grepl 3.13.1-39Lukas Vrabec 3.13.1-38Lukas Vrabec 3.13.1-37Lukas Vrabec 3.13.1-36Lukas Vrabec 3.13.1-35Lukas Vrabec 3.13.1-34Lukas Vrabec 3.13.1-33Lukas Vrabec 3.13.1-32Miroslav Grepl 3.13.1-31Miroslav Grepl 3.13.1-30Miroslav Grepl 3.13.1-29Miroslav Grepl 3.13.1-28Miroslav Grepl 3.13.1-27Miroslav Grepl 3.13.1-26Miroslav Grepl 3.13.1-25Miroslav Grepl 3.13.1-24Miroslav Grepl 3.13.1-23Miroslav Grepl 3.13.1-22Miroslav Grepl 3.13.1-21Miroslav Grepl 3.13.1-20Miroslav Grepl 3.13.1-19Miroslav Grepl 3.13.1-18Miroslav Grepl 3.13.1-17Miroslav Grepl 3.13.1-16Miroslav Grepl 3.13.1-15Miroslav Grepl 3.13.1-14Miroslav Grepl 3.13.1-13Miroslav Grepl 3.13.1-12Miroslav Grepl 3.13.1-11Miroslav Grepl 3.13.1-10Miroslav Grepl 3.13.1-9Miroslav Grepl 3.13.1-8Miroslav Grepl 3.13.1-7Miroslav Grepl 3.13.1-6Miroslav Grepl 3.13.1-5Miroslav Grepl 3.13.1-4Miroslav Grepl 3.13.1-3Miroslav Grepl 3.13.1-2Miroslav Grepl 3.13.1-1Miroslav Grepl 3.12.1-156Miroslav Grepl 3.12.1-155Miroslav Grepl 3.12.1-154Miroslav Grepl 3.12.1-153Miroslav Grepl 3.12.1-152Miroslav Grepl 3.12.1-151Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-148Miroslav Grepl 3.12.1-147Miroslav Grepl 3.12.1-146Miroslav Grepl 3.12.1-145Miroslav Grepl 3.12.1-144Lukas Vrabec 3.12.1-143Miroslav Grepl 3.12.1-142Miroslav Grepl 3.12.1-141Miroslav Grepl 3.12.1-140Miroslav Grepl 3.12.1-139Lukas Vrabec 3.12.1-138Miroslav Grepl 3.12.1-137Miroslav Grepl 3.12.1-136Miroslav Grepl 3.12.1-135Miroslav Grepl 3.12.1-134Miroslav Grepl 3.12.1-133Miroslav Grepl 3.12.1-132Miroslav Grepl 3.12.1-131Miroslav Grepl 3.12.1-130Miroslav Grepl 3.12.1-129Miroslav Grepl 3.12.1-128Miroslav Grepl 3.12.1-127Miroslav Grepl 3.12.1-126Miroslav Grepl 3.12.1-125Miroslav Grepl 3.12.1-124Miroslav Grepl 3.12.1-123Miroslav Grepl 3.12.1-122Miroslav Grepl 3.12.1-121Miroslav Grepl 3.12.1-120Miroslav Grepl 3.12.1-119Miroslav Grepl 3.12.1-118Miroslav Grepl 3.12.1-117Miroslav Grepl 3.12.1-116Miroslav Grepl 3.12.1-115Miroslav Grepl 3.12.1-114Miroslav Grepl 3.12.1-113Miroslav Grepl 3.12.1-112Miroslav Grepl 3.12.1-111Miroslav Grepl 3.12.1-110Miroslav Grepl 3.12.1-109Miroslav Grepl 3.12.1-108Miroslav Grepl 3.12.1-107Dan Walsh 3.12.1-106Miroslav Grepl 3.12.1-105Miroslav Grepl 3.12.1-104Miroslav Grepl 3.12.1-103Miroslav Grepl 3.12.1-102Miroslav Grepl 3.12.1-101Miroslav Grepl 3.12.1-100Miroslav Grepl 3.12.1-99Miroslav Grepl 3.12.1-98Miroslav Grepl 3.12.1-97Miroslav Grepl 3.12.1-96Miroslav Grepl 3.12.1-95Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-93Miroslav Grepl 3.12.1-92Miroslav Grepl 3.12.1-91Miroslav Grepl 3.12.1-90Miroslav Grepl 3.12.1-89Miroslav Grepl 3.12.1-88Miroslav Grepl 3.12.1-87Miroslav Grepl 3.12.1-86Miroslav Grepl 3.12.1-85Miroslav Grepl 3.12.1-84Miroslav Grepl 3.12.1-83Miroslav Grepl 3.12.1-82Miroslav Grepl 3.12.1-81Miroslav Grepl 3.12.1-80Miroslav Grepl 3.12.1-79Miroslav Grepl 3.12.1-78Miroslav Grepl 3.12.1-77Miroslav Grepl 3.12.1-76Miroslav Grepl 3.12.1-75Miroslav Grepl 3.12.1-74Miroslav Grepl 3.12.1-73Miroslav Grepl 3.12.1-72Miroslav Grepl 3.12.1-71Miroslav Grepl 3.12.1-70Miroslav Grepl 3.12.1-69Miroslav Grepl 3.12.1-68Miroslav Grepl 3.12.1-67Miroslav Grepl 3.12.1-66Miroslav Grepl 3.12.1-65Miroslav Grepl 3.12.1-64Miroslav Grepl 3.12.1-63Miroslav Grepl 3.12.1-62Miroslav Grepl 3.12.1-61Miroslav Grepl 3.12.1-60Miroslav Grepl 3.12.1-59Miroslav Grepl 3.12.1-58Miroslav Grepl 3.12.1-57Miroslav Grepl 3.12.1-56Miroslav Grepl 3.12.1-55Miroslav Grepl 3.12.1-54Miroslav Grepl 3.12.1-53Miroslav Grepl 3.12.1-52Miroslav Grepl 3.12.1-51Miroslav Grepl 3.12.1-50Miroslav Grepl 3.12.1-49Miroslav Grepl 3.12.1-48Miroslav Grepl 3.12.1-47Miroslav Grepl 3.12.1-46Miroslav Grepl 3.12.1-45Miroslav Grepl 3.12.1-44Miroslav Grepl 3.12.1-43Miroslav Grepl 3.12.1-42Miroslav Grepl 3.12.1-41Miroslav Grepl 3.12.1-40Miroslav Grepl 3.12.1-39Miroslav Grepl 3.12.1-38Miroslav Grepl 3.12.1-37Miroslav Grepl 3.12.1-36Miroslav Grepl 3.12.1-35Miroslav Grepl 3.12.1-34Miroslav Grepl 3.12.1-33Miroslav Grepl 3.12.1-32Miroslav Grepl 3.12.1-31Miroslav Grepl 3.12.1-30Miroslav Grepl 3.12.1-29Dan Walsh 3.12.1-28Dan Walsh 3.12.1-27Miroslav Grepl 3.12.1-26Miroslav Grepl 3.12.1-25Miroslav Grepl 3.12.1-24Miroslav Grepl 3.12.1-23Miroslav Grepl 3.12.1-22Miroslav Grepl 3.12.1-21Miroslav Grepl 3.12.1-20Miroslav Grepl 3.12.1-19Miroslav Grepl 3.12.1-18Miroslav Grepl 3.12.1-17Miroslav Grepl 3.12.1-16Miroslav Grepl 3.12.1-15Miroslav Grepl 3.12.1-14Miroslav Grepl 3.12.1-13Miroslav Grepl 3.12.1-12Miroslav Grepl 3.12.1-11Miroslav Grepl 3.12.1-10Miroslav Grepl 3.12.1-9Miroslav Grepl 3.12.1-8Miroslav Grepl 3.12.1-7Miroslav Grepl 3.12.1-6Miroslav Grepl 3.12.1-5Miroslav Grepl 3.12.1-4Miroslav Grepl 3.12.1-3Miroslav Grepl 3.12.1-2Miroslav Grepl 3.12.1-1Dan Walsh 3.11.1-69.1Miroslav Grepl 3.11.1-69Miroslav Grepl 3.11.1-68Miroslav Grepl 3.11.1-67Miroslav Grepl 3.11.1-66Miroslav Grepl 3.11.1-65Miroslav Grepl 3.11.1-64Miroslav Grepl 3.11.1-63Miroslav Grepl 3.11.1-62Miroslav Grepl 3.11.1-61Miroslav Grepl 3.11.1-60Miroslav Grepl 3.11.1-59Miroslav Grepl 3.11.1-58Miroslav Grepl 3.11.1-57Miroslav Grepl 3.11.1-56Miroslav Grepl 3.11.1-55Miroslav Grepl 3.11.1-54Miroslav Grepl 3.11.1-53Miroslav Grepl 3.11.1-52Miroslav Grepl 3.11.1-51Miroslav Grepl 3.11.1-50Miroslav Grepl 3.11.1-49Miroslav Grepl 3.11.1-48Miroslav Grepl 3.11.1-47Miroslav Grepl 3.11.1-46Miroslav Grepl 3.11.1-45Miroslav Grepl 3.11.1-44Miroslav Grepl 3.11.1-43Miroslav Grepl 3.11.1-42Miroslav Grepl 3.11.1-41Miroslav Grepl 3.11.1-40Miroslav Grepl 3.11.1-39Miroslav Grepl 3.11.1-38Miroslav Grepl 3.11.1-37Miroslav Grepl 3.11.1-36Miroslav Grepl 3.11.1-35Miroslav Grepl 3.11.1-34Miroslav Grepl 3.11.1-33Miroslav Grepl 3.11.1-32Miroslav Grepl 3.11.1-31Miroslav Grepl 3.11.1-30Miroslav Grepl 3.11.1-29Miroslav Grepl 3.11.1-28Miroslav Grepl 3.11.1-27Miroslav Grepl 3.11.1-26Miroslav Grepl 3.11.1-25Miroslav Grepl 3.11.1-24Miroslav Grepl 3.11.1-23Miroslav Grepl 3.11.1-22Miroslav Grepl 3.11.1-21Miroslav Grepl 3.11.1-20Miroslav Grepl 3.11.1-19Miroslav Grepl 3.11.1-18Miroslav Grepl 3.11.1-17Miroslav Grepl 3.11.1-16Dan Walsh 3.11.1-15Miroslav Grepl 3.11.1-14Dan Walsh 3.11.1-13Miroslav Grepl 3.11.1-12Miroslav Grepl 3.11.1-11Miroslav Grepl 3.11.1-10Dan Walsh 3.11.1-9Dan Walsh 3.11.1-8Dan Walsh 3.11.1-7Dan Walsh 3.11.1-6Miroslav Grepl 3.11.1-5Miroslav Grepl 3.11.1-4Miroslav Grepl 3.11.1-3Miroslav Grepl 3.11.1-2Miroslav Grepl 3.11.1-1Miroslav Grepl 3.11.1-0Miroslav Grepl 3.11.0-15Miroslav Grepl 3.11.0-14Miroslav Grepl 3.11.0-13Miroslav Grepl 3.11.0-12Fedora Release Engineering - 3.11.0-11Miroslav Grepl 3.11.0-10Miroslav Grepl 3.11.0-9Miroslav Grepl 3.11.0-8Miroslav Grepl 3.11.0-7Miroslav Grepl 3.11.0-6Miroslav Grepl 3.11.0-5Miroslav Grepl 3.11.0-4Miroslav Grepl 3.11.0-3Miroslav Grepl 3.11.0-2Miroslav Grepl 3.11.0-1Miroslav Grepl 3.10.0-128Miroslav Grepl 3.10.0-127Miroslav Grepl 3.10.0-126Miroslav Grepl 3.10.0-125Miroslav Grepl 3.10.0-124Miroslav Grepl 3.10.0-123Miroslav Grepl 3.10.0-122Miroslav Grepl 3.10.0-121Miroslav Grepl 3.10.0-120Miroslav Grepl 3.10.0-119Miroslav Grepl 3.10.0-118Miroslav Grepl 3.10.0-117Miroslav Grepl 3.10.0-116Miroslav Grepl 3.10.0-115Miroslav Grepl 3.10.0-114Miroslav Grepl 3.10.0-113Miroslav Grepl 3.10.0-112Miroslav Grepl 3.10.0-111Miroslav Grepl 3.10.0-110Miroslav Grepl 3.10.0-109Miroslav Grepl 3.10.0-108Miroslav Grepl 3.10.0-107Miroslav Grepl 3.10.0-106Miroslav Grepl 3.10.0-105Miroslav Grepl 3.10.0-104Miroslav Grepl 3.10.0-103Miroslav Grepl 3.10.0-102Miroslav Grepl 3.10.0-101Miroslav Grepl 3.10.0-100Miroslav Grepl 3.10.0-99Miroslav Grepl 3.10.0-98Miroslav Grepl 3.10.0-97Miroslav Grepl 3.10.0-96Miroslav Grepl 3.10.0-95Miroslav Grepl 3.10.0-94Miroslav Grepl 3.10.0-93Miroslav Grepl 3.10.0-92Miroslav Grepl 3.10.0-91Miroslav Grepl 3.10.0-90Miroslav Grepl 3.10.0-89Miroslav Grepl 3.10.0-88Miroslav Grepl 3.10.0-87Miroslav Grepl 3.10.0-86Miroslav Grepl 3.10.0-85Miroslav Grepl 3.10.0-84Miroslav Grepl 3.10.0-83Miroslav Grepl 3.10.0-82Dan Walsh 3.10.0-81.2Miroslav Grepl 3.10.0-81Miroslav Grepl 3.10.0-80Miroslav Grepl 3.10.0-79Miroslav Grepl 3.10.0-78Miroslav Grepl 3.10.0-77Miroslav Grepl 3.10.0-76Miroslav Grepl 3.10.0-75Dan Walsh 3.10.0-74.2Miroslav Grepl 3.10.0-74Miroslav Grepl 3.10.0-73Miroslav Grepl 3.10.0-72Miroslav Grepl 3.10.0-71Miroslav Grepl 3.10.0-70Miroslav Grepl 3.10.0-69Miroslav Grepl 3.10.0-68Miroslav Grepl 3.10.0-67Miroslav Grepl 3.10.0-66Miroslav Grepl 3.10.0-65Miroslav Grepl 3.10.0-64Miroslav Grepl 3.10.0-63Miroslav Grepl 3.10.0-59Miroslav Grepl 3.10.0-58Dan Walsh 3.10.0-57Dan Walsh 3.10.0-56Dan Walsh 3.10.0-55.2Dan Walsh 3.10.0-55.1Miroslav Grepl 3.10.0-55Dan Walsh 3.10.0-54.1Miroslav Grepl 3.10.0-54Dan Walsh 3.10.0-53.1Miroslav Grepl 3.10.0-53Miroslav Grepl 3.10.0-52Miroslav Grepl 3.10.0-51Dan Walsh 3.10.0-50.2Dan Walsh 3.10.0-50.1Miroslav Grepl 3.10.0-50Miroslav Grepl 3.10.0-49Miroslav Grepl 3.10.0-48Miroslav Grepl 3.10.0-47Dan Walsh 3.10.0-46.1Miroslav Grepl 3.10.0-46Dan Walsh 3.10.0-45.1Miroslav Grepl 3.10.0-45Miroslav Grepl 3.10.0-43Miroslav Grepl 3.10.0-42Miroslav Grepl 3.10.0-41Dan Walsh 3.10.0-40.2Miroslav Grepl 3.10.0-40Dan Walsh 3.10.0-39.3Dan Walsh 3.10.0-39.2Dan Walsh 3.10.0-39.1Miroslav Grepl 3.10.0-39Dan Walsh 3.10.0-38.1Miroslav Grepl 3.10.0-38Miroslav Grepl 3.10.0-37Dan Walsh 3.10.0-36.1Miroslav Grepl 3.10.0-36Dan Walsh 3.10.0-35Dan Walsh 3.10.0-34.7Dan Walsh 3.10.0-34.6Dan Walsh 3.10.0-34.4Miroslav Grepl 3.10.0-34.3Dan Walsh 3.10.0-34.2Dan Walsh 3.10.0-34.1Miroslav Grepl 3.10.0-34Miroslav Grepl 3.10.0-33Dan Walsh 3.10.0-31.1Miroslav Grepl 3.10.0-31Miroslav Grepl 3.10.0-29Miroslav Grepl 3.10.0-28Miroslav Grepl 3.10.0-27Miroslav Grepl 3.10.0-26Miroslav Grepl 3.10.0-25Miroslav Grepl 3.10.0-24Miroslav Grepl 3.10.0-23Miroslav Grepl 3.10.0-22Miroslav Grepl 3.10.0-21Dan Walsh 3.10.0-20Miroslav Grepl 3.10.0-19Miroslav Grepl 3.10.0-18Miroslav Grepl 3.10.0-17Miroslav Grepl 3.10.0-16Miroslav Grepl 3.10.0-14Miroslav Grepl 3.10.0-13Miroslav Grepl 3.10.0-12Miroslav Grepl 3.10.0-11Miroslav Grepl 3.10.0-10Miroslav Grepl 3.10.0-9Miroslav Grepl 3.10.0-8Miroslav Grepl 3.10.0-7Miroslav Grepl 3.10.0-6Miroslav Grepl 3.10.0-5Miroslav Grepl 3.10.0-4Miroslav Grepl 3.10.0-3Miroslav Grepl 3.10.0-2Miroslav Grepl 3.10.0-1Miroslav Grepl 3.9.16-30Dan Walsh 3.9.16-29.1Miroslav Grepl 3.9.16-29Dan Walsh 3.9.16-28.1Miroslav Grepl 3.9.16-27Miroslav Grepl 3.9.16-26Miroslav Grepl 3.9.16-25Miroslav Grepl 3.9.16-24Miroslav Grepl 3.9.16-23Miroslav Grepl 3.9.16-22Miroslav Grepl 3.9.16-21Miroslav Grepl 3.9.16-20Miroslav Grepl 3.9.16-19Miroslav Grepl 3.9.16-18Miroslav Grepl 3.9.16-17Dan Walsh 3.9.16-16.1Miroslav Grepl 3.9.16-16Miroslav Grepl 3.9.16-15Miroslav Grepl 3.9.16-14Miroslav Grepl 3.9.16-13Miroslav Grepl 3.9.16-12Miroslav Grepl 3.9.16-11Miroslav Grepl 3.9.16-10Miroslav Grepl 3.9.16-7Miroslav Grepl 3.9.16-6Miroslav Grepl 3.9.16-5Miroslav Grepl 3.9.16-4Miroslav Grepl 3.9.16-3Miroslav Grepl 3.9.16-2Miroslav Grepl 3.9.16-1Miroslav Grepl 3.9.15-5Miroslav Grepl 3.9.15-2Miroslav Grepl 3.9.15-1Fedora Release Engineering - 3.9.14-2Dan Walsh 3.9.14-1Miroslav Grepl 3.9.13-10Miroslav Grepl 3.9.13-9Dan Walsh 3.9.13-8Miroslav Grepl 3.9.13-7Miroslav Grepl 3.9.13-6Miroslav Grepl 3.9.13-5Miroslav Grepl 3.9.13-4Miroslav Grepl 3.9.13-3Miroslav Grepl 3.9.13-2Miroslav Grepl 3.9.13-1Miroslav Grepl 3.9.12-8Miroslav Grepl 3.9.12-7Miroslav Grepl 3.9.12-6Miroslav Grepl 3.9.12-5Dan Walsh 3.9.12-4Dan Walsh 3.9.12-3Dan Walsh 3.9.12-2Miroslav Grepl 3.9.12-1Dan Walsh 3.9.11-2Miroslav Grepl 3.9.11-1Miroslav Grepl 3.9.10-13Dan Walsh 3.9.10-12Miroslav Grepl 3.9.10-11Miroslav Grepl 3.9.10-10Miroslav Grepl 3.9.10-9Miroslav Grepl 3.9.10-8Miroslav Grepl 3.9.10-7Miroslav Grepl 3.9.10-6Miroslav Grepl 3.9.10-5Dan Walsh 3.9.10-4Miroslav Grepl 3.9.10-3Miroslav Grepl 3.9.10-2Miroslav Grepl 3.9.10-1Miroslav Grepl 3.9.9-4Dan Walsh 3.9.9-3Miroslav Grepl 3.9.9-2Miroslav Grepl 3.9.9-1Miroslav Grepl 3.9.8-7Dan Walsh 3.9.8-6Miroslav Grepl 3.9.8-5Miroslav Grepl 3.9.8-4Dan Walsh 3.9.8-3Dan Walsh 3.9.8-2Dan Walsh 3.9.8-1Dan Walsh 3.9.7-10Dan Walsh 3.9.7-9Dan Walsh 3.9.7-8Dan Walsh 3.9.7-7Dan Walsh 3.9.7-6Dan Walsh 3.9.7-5Dan Walsh 3.9.7-4Dan Walsh 3.9.7-3Dan Walsh 3.9.7-2Dan Walsh 3.9.7-1Dan Walsh 3.9.6-3Dan Walsh 3.9.6-2Dan Walsh 3.9.6-1Dan Walsh 3.9.5-11Dan Walsh 3.9.5-10Dan Walsh 3.9.5-9Dan Walsh 3.9.5-8Dan Walsh 3.9.5-7Dan Walsh 3.9.5-6Dan Walsh 3.9.5-5Dan Walsh 3.9.5-4Dan Walsh 3.9.5-3Dan Walsh 3.9.5-2Dan Walsh 3.9.5-1Dan Walsh 3.9.4-3Dan Walsh 3.9.4-2Dan Walsh 3.9.4-1Dan Walsh 3.9.3-4Dan Walsh 3.9.3-3Dan Walsh 3.9.3-2Dan Walsh 3.9.3-1Dan Walsh 3.9.2-1Dan Walsh 3.9.1-3Dan Walsh 3.9.1-2Dan Walsh 3.9.1-1Dan Walsh 3.9.0-2Dan Walsh 3.9.0-1Dan Walsh 3.8.8-21Dan Walsh 3.8.8-20Dan Walsh 3.8.8-19Dan Walsh 3.8.8-18Dan Walsh 3.8.8-17Dan Walsh 3.8.8-16Dan Walsh 3.8.8-15Dan Walsh 3.8.8-14Dan Walsh 3.8.8-13Dan Walsh 3.8.8-12Dan Walsh 3.8.8-11Dan Walsh 3.8.8-10Dan Walsh 3.8.8-9Dan Walsh 3.8.8-8Dan Walsh 3.8.8-7Dan Walsh 3.8.8-6Dan Walsh 3.8.8-5Dan Walsh 3.8.8-4Dan Walsh 3.8.8-3Dan Walsh 3.8.8-2Dan Walsh 3.8.8-1Dan Walsh 3.8.7-3Dan Walsh 3.8.7-2Dan Walsh 3.8.7-1Dan Walsh 3.8.6-3Miroslav Grepl 3.8.6-2Dan Walsh 3.8.6-1Dan Walsh 3.8.5-1Dan Walsh 3.8.4-1Dan Walsh 3.8.3-4Dan Walsh 3.8.3-3Dan Walsh 3.8.3-2Dan Walsh 3.8.3-1Dan Walsh 3.8.2-1Dan Walsh 3.8.1-5Dan Walsh 3.8.1-4Dan Walsh 3.8.1-3Dan Walsh 3.8.1-2Dan Walsh 3.8.1-1Dan Walsh 3.7.19-22Dan Walsh 3.7.19-21Dan Walsh 3.7.19-20Dan Walsh 3.7.19-19Dan Walsh 3.7.19-17Dan Walsh 3.7.19-16Dan Walsh 3.7.19-15Dan Walsh 3.7.19-14Dan Walsh 3.7.19-13Dan Walsh 3.7.19-12Dan Walsh 3.7.19-11Dan Walsh 3.7.19-10Dan Walsh 3.7.19-9Dan Walsh 3.7.19-8Dan Walsh 3.7.19-7Dan Walsh 3.7.19-6Dan Walsh 3.7.19-5Dan Walsh 3.7.19-4Dan Walsh 3.7.19-3Dan Walsh 3.7.19-2Dan Walsh 3.7.19-1Dan Walsh 3.7.18-3Dan Walsh 3.7.18-2Dan Walsh 3.7.18-1Dan Walsh 3.7.17-6Dan Walsh 3.7.17-5Dan Walsh 3.7.17-4Dan Walsh 3.7.17-3Dan Walsh 3.7.17-2Dan Walsh 3.7.17-1Dan Walsh 3.7.16-2Dan Walsh 3.7.16-1Dan Walsh 3.7.15-4Dan Walsh 3.7.15-3Dan Walsh 3.7.15-2Dan Walsh 3.7.15-1Dan Walsh 3.7.14-5Dan Walsh 3.7.14-4Dan Walsh 3.7.14-3Dan Walsh 3.7.14-2Dan Walsh 3.7.14-1Dan Walsh 3.7.13-4Dan Walsh 3.7.13-3Dan Walsh 3.7.13-2Dan Walsh 3.7.13-1Dan Walsh 3.7.12-1Dan Walsh 3.7.11-1Dan Walsh 3.7.10-5Dan Walsh 3.7.10-4Dan Walsh 3.7.10-3Dan Walsh 3.7.10-2Dan Walsh 3.7.10-1Dan Walsh 3.7.9-4Dan Walsh 3.7.9-3Dan Walsh 3.7.9-2Dan Walsh 3.7.9-1Dan Walsh 3.7.8-11Dan Walsh 3.7.8-9Dan Walsh 3.7.8-8Dan Walsh 3.7.8-7Dan Walsh 3.7.8-6Dan Walsh 3.7.8-5Dan Walsh 3.7.8-4Dan Walsh 3.7.8-3Dan Walsh 3.7.8-2Dan Walsh 3.7.8-1Dan Walsh 3.7.7-3Dan Walsh 3.7.7-2Dan Walsh 3.7.7-1Dan Walsh 3.7.6-1Dan Walsh 3.7.5-8Dan Walsh 3.7.5-7Dan Walsh 3.7.5-6Dan Walsh 3.7.5-5Dan Walsh 3.7.5-4Dan Walsh 3.7.5-3Dan Walsh 3.7.5-2Dan Walsh 3.7.5-1Dan Walsh 3.7.4-4Dan Walsh 3.7.4-3Dan Walsh 3.7.4-2Dan Walsh 3.7.4-1Dan Walsh 3.7.3-1Dan Walsh 3.7.1-1Dan Walsh 3.6.33-2Dan Walsh 3.6.33-1Dan Walsh 3.6.32-17Dan Walsh 3.6.32-16Dan Walsh 3.6.32-15Dan Walsh 3.6.32-13Dan Walsh 3.6.32-12Dan Walsh 3.6.32-11Dan Walsh 3.6.32-10Dan Walsh 3.6.32-9Dan Walsh 3.6.32-8Dan Walsh 3.6.32-7Dan Walsh 3.6.32-6Dan Walsh 3.6.32-5Dan Walsh 3.6.32-4Dan Walsh 3.6.32-3Dan Walsh 3.6.32-2Dan Walsh 3.6.32-1Dan Walsh 3.6.31-5Dan Walsh 3.6.31-4Dan Walsh 3.6.31-3Dan Walsh 3.6.31-2Dan Walsh 3.6.30-6Dan Walsh 3.6.30-5Dan Walsh 3.6.30-4Dan Walsh 3.6.30-3Dan Walsh 3.6.30-2Dan Walsh 3.6.30-1Dan Walsh 3.6.29-2Dan Walsh 3.6.29-1Dan Walsh 3.6.28-9Dan Walsh 3.6.28-8Dan Walsh 3.6.28-7Dan Walsh 3.6.28-6Dan Walsh 3.6.28-5Dan Walsh 3.6.28-4Dan Walsh 3.6.28-3Dan Walsh 3.6.28-2Dan Walsh 3.6.28-1Dan Walsh 3.6.27-1Dan Walsh 3.6.26-11Dan Walsh 3.6.26-10Dan Walsh 3.6.26-9Bill Nottingham 3.6.26-8Dan Walsh 3.6.26-7Dan Walsh 3.6.26-6Dan Walsh 3.6.26-5Dan Walsh 3.6.26-4Dan Walsh 3.6.26-3Dan Walsh 3.6.26-2Dan Walsh 3.6.26-1Dan Walsh 3.6.25-1Dan Walsh 3.6.24-1Dan Walsh 3.6.23-2Dan Walsh 3.6.23-1Dan Walsh 3.6.22-3Dan Walsh 3.6.22-1Dan Walsh 3.6.21-4Dan Walsh 3.6.21-3Tom "spot" Callaway 3.6.21-2Dan Walsh 3.6.21-1Dan Walsh 3.6.20-2Dan Walsh 3.6.20-1Dan Walsh 3.6.19-5Dan Walsh 3.6.19-4Dan Walsh 3.6.19-3Dan Walsh 3.6.19-2Dan Walsh 3.6.19-1Dan Walsh 3.6.18-1Dan Walsh 3.6.17-1Dan Walsh 3.6.16-4Dan Walsh 3.6.16-3Dan Walsh 3.6.16-2Dan Walsh 3.6.16-1Dan Walsh 3.6.14-3Dan Walsh 3.6.14-2Dan Walsh 3.6.14-1Dan Walsh 3.6.13-3Dan Walsh 3.6.13-2Dan Walsh 3.6.13-1Dan Walsh 3.6.12-39Dan Walsh 3.6.12-38Dan Walsh 3.6.12-37Dan Walsh 3.6.12-36Dan Walsh 3.6.12-35Dan Walsh 3.6.12-34Dan Walsh 3.6.12-33Dan Walsh 3.6.12-31Dan Walsh 3.6.12-30Dan Walsh 3.6.12-29Dan Walsh 3.6.12-28Dan Walsh 3.6.12-27Dan Walsh 3.6.12-26Dan Walsh 3.6.12-25Dan Walsh 3.6.12-24Dan Walsh 3.6.12-23Dan Walsh 3.6.12-22Dan Walsh 3.6.12-21Dan Walsh 3.6.12-20Dan Walsh 3.6.12-19Dan Walsh 3.6.12-16Dan Walsh 3.6.12-15Dan Walsh 3.6.12-14Dan Walsh 3.6.12-13Dan Walsh 3.6.12-12Dan Walsh 3.6.12-11Dan Walsh 3.6.12-10Dan Walsh 3.6.12-9Dan Walsh 3.6.12-8Dan Walsh 3.6.12-7Dan Walsh 3.6.12-6Dan Walsh 3.6.12-5Dan Walsh 3.6.12-4Dan Walsh 3.6.12-3Dan Walsh 3.6.12-2Dan Walsh 3.6.12-1Dan Walsh 3.6.11-1Dan Walsh 3.6.10-9Dan Walsh 3.6.10-8Dan Walsh 3.6.10-7Dan Walsh 3.6.10-6Dan Walsh 3.6.10-5Dan Walsh 3.6.10-4Dan Walsh 3.6.10-3Dan Walsh 3.6.10-2Dan Walsh 3.6.10-1Dan Walsh 3.6.9-4Dan Walsh 3.6.9-3Dan Walsh 3.6.9-2Dan Walsh 3.6.9-1Dan Walsh 3.6.8-4Dan Walsh 3.6.8-3Dan Walsh 3.6.8-2Dan Walsh 3.6.8-1Dan Walsh 3.6.7-2Dan Walsh 3.6.7-1Dan Walsh 3.6.6-9Dan Walsh 3.6.6-8Fedora Release Engineering - 3.6.6-7Dan Walsh 3.6.6-6Dan Walsh 3.6.6-5Dan Walsh 3.6.6-4Dan Walsh 3.6.6-3Dan Walsh 3.6.6-2Dan Walsh 3.6.6-1Dan Walsh 3.6.5-3Dan Walsh 3.6.5-1Dan Walsh 3.6.4-6Dan Walsh 3.6.4-5Dan Walsh 3.6.4-4Dan Walsh 3.6.4-3Dan Walsh 3.6.4-2Dan Walsh 3.6.4-1Dan Walsh 3.6.3-13Dan Walsh 3.6.3-12Dan Walsh 3.6.3-11Dan Walsh 3.6.3-10Dan Walsh 3.6.3-9Dan Walsh 3.6.3-8Dan Walsh 3.6.3-7Dan Walsh 3.6.3-6Dan Walsh 3.6.3-3Dan Walsh 3.6.3-2Dan Walsh 3.6.3-1Dan Walsh 3.6.2-5Dan Walsh 3.6.2-4Dan Walsh 3.6.2-3Dan Walsh 3.6.2-2Dan Walsh 3.6.2-1Dan Walsh 3.6.1-15Dan Walsh 3.6.1-14Dan Walsh 3.6.1-13Dan Walsh 3.6.1-12Dan Walsh 3.6.1-11Dan Walsh 3.6.1-10Dan Walsh 3.6.1-9Dan Walsh 3.6.1-8Dan Walsh 3.6.1-7Dan Walsh 3.6.1-4Ignacio Vazquez-Abrams - 3.6.1-2Dan Walsh 3.5.13-19Dan Walsh 3.5.13-18Dan Walsh 3.5.13-17Dan Walsh 3.5.13-16Dan Walsh 3.5.13-15Dan Walsh 3.5.13-14Dan Walsh 3.5.13-13Dan Walsh 3.5.13-12Dan Walsh 3.5.13-11Dan Walsh 3.5.13-9Dan Walsh 3.5.13-8Dan Walsh 3.5.13-7Dan Walsh 3.5.13-6Dan Walsh 3.5.13-5Dan Walsh 3.5.13-4Dan Walsh 3.5.13-3Dan Walsh 3.5.13-2Dan Walsh 3.5.13-1Dan Walsh 3.5.12-3Dan Walsh 3.5.12-2Dan Walsh 3.5.12-1Dan Walsh 3.5.11-1Dan Walsh 3.5.10-3Dan Walsh 3.5.10-2Dan Walsh 3.5.10-1Dan Walsh 3.5.9-4Dan Walsh 3.5.9-3Dan Walsh 3.5.9-2Dan Walsh 3.5.9-1Dan Walsh 3.5.8-7Dan Walsh 3.5.8-6Dan Walsh 3.5.8-5Dan Walsh 3.5.8-4Dan Walsh 3.5.8-3Dan Walsh 3.5.8-1Dan Walsh 3.5.7-2Dan Walsh 3.5.7-1Dan Walsh 3.5.6-2Dan Walsh 3.5.6-1Dan Walsh 3.5.5-4Dan Walsh 3.5.5-3Dan Walsh 3.5.5-2Dan Walsh 3.5.4-2Dan Walsh 3.5.4-1Dan Walsh 3.5.3-1Dan Walsh 3.5.2-2Dan Walsh 3.5.1-5Dan Walsh 3.5.1-4Dan Walsh 3.5.1-3Dan Walsh 3.5.1-2Dan Walsh 3.5.1-1Dan Walsh 3.5.0-1Dan Walsh 3.4.2-14Dan Walsh 3.4.2-13Dan Walsh 3.4.2-12Dan Walsh 3.4.2-11Dan Walsh 3.4.2-10Dan Walsh 3.4.2-9Dan Walsh 3.4.2-8Dan Walsh 3.4.2-7Dan Walsh 3.4.2-6Dan Walsh 3.4.2-5Dan Walsh 3.4.2-4Dan Walsh 3.4.2-3Dan Walsh 3.4.2-2Dan Walsh 3.4.2-1Dan Walsh 3.4.1-5Dan Walsh 3.4.1-3Dan Walsh 3.4.1-2Dan Walsh 3.4.1-1Dan Walsh 3.3.1-48Dan Walsh 3.3.1-47Dan Walsh 3.3.1-46Dan Walsh 3.3.1-45Dan Walsh 3.3.1-44Dan Walsh 3.3.1-43Dan Walsh 3.3.1-42Dan Walsh 3.3.1-41Dan Walsh 3.3.1-39Dan Walsh 3.3.1-37Dan Walsh 3.3.1-36Dan Walsh 3.3.1-33Dan Walsh 3.3.1-32Dan Walsh 3.3.1-31Dan Walsh 3.3.1-30Dan Walsh 3.3.1-29Dan Walsh 3.3.1-28Dan Walsh 3.3.1-27Dan Walsh 3.3.1-26Dan Walsh 3.3.1-25Dan Walsh 3.3.1-24Dan Walsh 3.3.1-23Dan Walsh 3.3.1-22Dan Walsh 3.3.1-21Dan Walsh 3.3.1-20Dan Walsh 3.3.1-19Dan Walsh 3.3.1-18Dan Walsh 3.3.1-17Dan Walsh 3.3.1-16Dan Walsh 3.3.1-15Bill Nottingham 3.3.1-14Dan Walsh 3.3.1-13Dan Walsh 3.3.1-12Dan Walsh 3.3.1-11Dan Walsh 3.3.1-10Dan Walsh 3.3.1-9Dan Walsh 3.3.1-8Dan Walsh 3.3.1-6Dan Walsh 3.3.1-5Dan Walsh 3.3.1-4Dan Walsh 3.3.1-2Dan Walsh 3.3.1-1Dan Walsh 3.3.0-2Dan Walsh 3.3.0-1Dan Walsh 3.2.9-2Dan Walsh 3.2.9-1Dan Walsh 3.2.8-2Dan Walsh 3.2.8-1Dan Walsh 3.2.7-6Dan Walsh 3.2.7-5Dan Walsh 3.2.7-3Dan Walsh 3.2.7-2Dan Walsh 3.2.7-1Dan Walsh 3.2.6-7Dan Walsh 3.2.6-6Dan Walsh 3.2.6-5Dan Walsh 3.2.6-4Dan Walsh 3.2.6-3Dan Walsh 3.2.6-2Dan Walsh 3.2.6-1Dan Walsh 3.2.5-25Dan Walsh 3.2.5-24Dan Walsh 3.2.5-22Dan Walsh 3.2.5-21Dan Walsh 3.2.5-20Dan Walsh 3.2.5-19Dan Walsh 3.2.5-18Dan Walsh 3.2.5-17Dan Walsh 3.2.5-16Dan Walsh 3.2.5-15Dan Walsh 3.2.5-14Dan Walsh 3.2.5-13Dan Walsh 3.2.5-12Dan Walsh 3.2.5-11Dan Walsh 3.2.5-10Dan Walsh 3.2.5-9Dan Walsh 3.2.5-8Dan Walsh 3.2.5-7Dan Walsh 3.2.5-6Dan Walsh 3.2.5-5Dan Walsh 3.2.5-4Dan Walsh 3.2.5-3Dan Walsh 3.2.5-2Dan Walsh 3.2.5-1Dan Walsh 3.2.4-5Dan Walsh 3.2.4-4Dan Walsh 3.2.4-3Dan Walsh 3.2.4-1Dan Walsh 3.2.4-1Dan Walsh 3.2.3-2Dan Walsh 3.2.3-1Dan Walsh 3.2.2-1Dan Walsh 3.2.1-3Dan Walsh 3.2.1-1Dan Walsh 3.1.2-2Dan Walsh 3.1.2-1Dan Walsh 3.1.1-1Dan Walsh 3.1.0-1Dan Walsh 3.0.8-30Dan Walsh 3.0.8-28Dan Walsh 3.0.8-27Dan Walsh 3.0.8-26Dan Walsh 3.0.8-25Dan Walsh 3.0.8-24Dan Walsh 3.0.8-23Dan Walsh 3.0.8-22Dan Walsh 3.0.8-21Dan Walsh 3.0.8-20Dan Walsh 3.0.8-19Dan Walsh 3.0.8-18Dan Walsh 3.0.8-17Dan Walsh 3.0.8-16Dan Walsh 3.0.8-15Dan Walsh 3.0.8-14Dan Walsh 3.0.8-13Dan Walsh 3.0.8-12Dan Walsh 3.0.8-11Dan Walsh 3.0.8-10Dan Walsh 3.0.8-9Dan Walsh 3.0.8-8Dan Walsh 3.0.8-7Dan Walsh 3.0.8-5Dan Walsh 3.0.8-4Dan Walsh 3.0.8-3Dan Walsh 3.0.8-2Dan Walsh 3.0.8-1Dan Walsh 3.0.7-10Dan Walsh 3.0.7-9Dan Walsh 3.0.7-8Dan Walsh 3.0.7-7Dan Walsh 3.0.7-6Dan Walsh 3.0.7-5Dan Walsh 3.0.7-4Dan Walsh 3.0.7-3Dan Walsh 3.0.7-2Dan Walsh 3.0.7-1Dan Walsh 3.0.6-3Dan Walsh 3.0.6-2Dan Walsh 3.0.6-1Dan Walsh 3.0.5-11Dan Walsh 3.0.5-10Dan Walsh 3.0.5-9Dan Walsh 3.0.5-8Dan Walsh 3.0.5-7Dan Walsh 3.0.5-6Dan Walsh 3.0.5-5Dan Walsh 3.0.5-4Dan Walsh 3.0.5-3Dan Walsh 3.0.5-2Dan Walsh 3.0.5-1Dan Walsh 3.0.4-6Dan Walsh 3.0.4-5Dan Walsh 3.0.4-4Dan Walsh 3.0.4-3Dan Walsh 3.0.4-2Dan Walsh 3.0.4-1Dan Walsh 3.0.3-6Dan Walsh 3.0.3-5Dan Walsh 3.0.3-4Dan Walsh 3.0.3-3Dan Walsh 3.0.3-2Dan Walsh 3.0.3-1Dan Walsh 3.0.2-9Dan Walsh 3.0.2-8Dan Walsh 3.0.2-7Dan Walsh 3.0.2-5Dan Walsh 3.0.2-4Dan Walsh 3.0.2-3Dan Walsh 3.0.2-2Dan Walsh 3.0.1-5Dan Walsh 3.0.1-4Dan Walsh 3.0.1-3Dan Walsh 3.0.1-2Dan Walsh 3.0.1-1Dan Walsh 2.6.5-3Dan Walsh 2.6.5-2Dan Walsh 2.6.4-7Dan Walsh 2.6.4-6Dan Walsh 2.6.4-5Dan Walsh 2.6.4-2Dan Walsh 2.6.4-1Dan Walsh 2.6.3-1Dan Walsh 2.6.2-1Dan Walsh 2.6.1-4Dan Walsh 2.6.1-2Dan Walsh 2.6.1-1Dan Walsh 2.5.12-12Dan Walsh 2.5.12-11Dan Walsh 2.5.12-10Dan Walsh 2.5.12-8Dan Walsh 2.5.12-5Dan Walsh 2.5.12-4Dan Walsh 2.5.12-3Dan Walsh 2.5.12-2Dan Walsh 2.5.12-1Dan Walsh 2.5.11-8Dan Walsh 2.5.11-7Dan Walsh 2.5.11-6Dan Walsh 2.5.11-5Dan Walsh 2.5.11-4Dan Walsh 2.5.11-3Dan Walsh 2.5.11-2Dan Walsh 2.5.11-1Dan Walsh 2.5.10-2Dan Walsh 2.5.10-1Dan Walsh 2.5.9-6Dan Walsh 2.5.9-5Dan Walsh 2.5.9-4Dan Walsh 2.5.9-3Dan Walsh 2.5.9-2Dan Walsh 2.5.8-8Dan Walsh 2.5.8-7Dan Walsh 2.5.8-6Dan Walsh 2.5.8-5Dan Walsh 2.5.8-4Dan Walsh 2.5.8-3Dan Walsh 2.5.8-2Dan Walsh 2.5.8-1Dan Walsh 2.5.7-1Dan Walsh 2.5.6-1Dan Walsh 2.5.5-2Dan Walsh 2.5.5-1Dan Walsh 2.5.4-2Dan Walsh 2.5.4-1Dan Walsh 2.5.3-3Dan Walsh 2.5.3-2Dan Walsh 2.5.3-1Dan Walsh 2.5.2-6Dan Walsh 2.5.2-5Dan Walsh 2.5.2-4Dan Walsh 2.5.2-3Dan Walsh 2.5.2-2Dan Walsh 2.5.2-1Dan Walsh 2.5.1-5Dan Walsh 2.5.1-4Dan Walsh 2.5.1-2Dan Walsh 2.5.1-1Dan Walsh 2.4.6-20Dan Walsh 2.4.6-19Dan Walsh 2.4.6-18Dan Walsh 2.4.6-17Dan Walsh 2.4.6-16Dan Walsh 2.4.6-15Dan Walsh 2.4.6-14Dan Walsh 2.4.6-13Dan Walsh 2.4.6-12Dan Walsh 2.4.6-11Dan Walsh 2.4.6-10Dan Walsh 2.4.6-9Dan Walsh 2.4.6-8Dan Walsh 2.4.6-7Dan Walsh 2.4.6-6Dan Walsh 2.4.6-5Dan Walsh 2.4.6-4Dan Walsh 2.4.6-3Dan Walsh 2.4.6-1Dan Walsh 2.4.5-4Dan Walsh 2.4.5-3Dan Walsh 2.4.5-2Dan Walsh 2.4.5-1Dan Walsh 2.4.4-2Dan Walsh 2.4.4-2Dan Walsh 2.4.4-1Dan Walsh 2.4.3-13Dan Walsh 2.4.3-12Dan Walsh 2.4.3-11Dan Walsh 2.4.3-10Dan Walsh 2.4.3-9Dan Walsh 2.4.3-8Dan Walsh 2.4.3-7Dan Walsh 2.4.3-6Dan Walsh 2.4.3-5Dan Walsh 2.4.3-4Dan Walsh 2.4.3-3Dan Walsh 2.4.3-2Dan Walsh 2.4.3-1Dan Walsh 2.4.2-8Dan Walsh 2.4.2-7James Antill 2.4.2-6Dan Walsh 2.4.2-5Dan Walsh 2.4.2-4Dan Walsh 2.4.2-3Dan Walsh 2.4.2-2Dan Walsh 2.4.2-1Dan Walsh 2.4.1-5Dan Walsh 2.4.1-4Dan Walsh 2.4.1-3Dan Walsh 2.4.1-2Dan Walsh 2.4-4Dan Walsh 2.4-3Dan Walsh 2.4-2Dan Walsh 2.4-1Dan Walsh 2.3.19-4Dan Walsh 2.3.19-3Dan Walsh 2.3.19-2Dan Walsh 2.3.19-1James Antill 2.3.18-10James Antill 2.3.18-9Dan Walsh 2.3.18-8Dan Walsh 2.3.18-7Dan Walsh 2.3.18-6Dan Walsh 2.3.18-5Dan Walsh 2.3.18-4Dan Walsh 2.3.18-3Dan Walsh 2.3.18-2Dan Walsh 2.3.18-1Dan Walsh 2.3.17-2Dan Walsh 2.3.17-1Dan Walsh 2.3.16-9Dan Walsh 2.3.16-8Dan Walsh 2.3.16-7Dan Walsh 2.3.16-6Dan Walsh 2.3.16-5Dan Walsh 2.3.16-4Dan Walsh 2.3.16-2Dan Walsh 2.3.16-1Dan Walsh 2.3.15-2Dan Walsh 2.3.15-1Dan Walsh 2.3.14-8Dan Walsh 2.3.14-7Dan Walsh 2.3.14-6Dan Walsh 2.3.14-4Dan Walsh 2.3.14-3Dan Walsh 2.3.14-2Dan Walsh 2.3.14-1Dan Walsh 2.3.13-6Dan Walsh 2.3.13-5Dan Walsh 2.3.13-4Dan Walsh 2.3.13-3Dan Walsh 2.3.13-2Dan Walsh 2.3.13-1Dan Walsh 2.3.12-2Dan Walsh 2.3.12-1Dan Walsh 2.3.11-1Dan Walsh 2.3.10-7Dan Walsh 2.3.10-6Dan Walsh 2.3.10-3Dan Walsh 2.3.10-1Dan Walsh 2.3.9-6Dan Walsh 2.3.9-5Dan Walsh 2.3.9-4Dan Walsh 2.3.9-3Dan Walsh 2.3.9-2Dan Walsh 2.3.9-1Dan Walsh 2.3.8-2Dan Walsh 2.3.7-1Dan Walsh 2.3.6-4Dan Walsh 2.3.6-3Dan Walsh 2.3.6-2Dan Walsh 2.3.6-1Dan Walsh 2.3.5-1Dan Walsh 2.3.4-1Dan Walsh 2.3.3-20Dan Walsh 2.3.3-19Dan Walsh 2.3.3-18Dan Walsh 2.3.3-17Dan Walsh 2.3.3-16Dan Walsh 2.3.3-15Dan Walsh 2.3.3-14Dan Walsh 2.3.3-13Dan Walsh 2.3.3-12Dan Walsh 2.3.3-11Dan Walsh 2.3.3-10Dan Walsh 2.3.3-9Dan Walsh 2.3.3-8Dan Walsh 2.3.3-7Dan Walsh 2.3.3-6Dan Walsh 2.3.3-5Dan Walsh 2.3.3-4Dan Walsh 2.3.3-3Dan Walsh 2.3.3-2Dan Walsh 2.3.3-1Dan Walsh 2.3.2-4Dan Walsh 2.3.2-3Dan Walsh 2.3.2-2Dan Walsh 2.3.2-1Dan Walsh 2.3.1-1Dan Walsh 2.2.49-1Dan Walsh 2.2.48-1Dan Walsh 2.2.47-5Dan Walsh 2.2.47-4Dan Walsh 2.2.47-3Dan Walsh 2.2.47-1Dan Walsh 2.2.46-2Dan Walsh 2.2.46-1Dan Walsh 2.2.45-3Dan Walsh 2.2.45-2Dan Walsh 2.2.45-1Dan Walsh 2.2.44-1Dan Walsh 2.2.43-4Dan Walsh 2.2.43-3Dan Walsh 2.2.43-2Dan Walsh 2.2.43-1Dan Walsh 2.2.42-4Dan Walsh 2.2.42-3Dan Walsh 2.2.42-2Dan Walsh 2.2.42-1Dan Walsh 2.2.41-1Dan Walsh 2.2.40-2Dan Walsh 2.2.40-1Dan Walsh 2.2.39-2Dan Walsh 2.2.39-1Dan Walsh 2.2.38-6Dan Walsh 2.2.38-5Dan Walsh 2.2.38-4Dan Walsh 2.2.38-3Dan Walsh 2.2.38-2Dan Walsh 2.2.38-1Dan Walsh 2.2.37-1Dan Walsh 2.2.36-2Dan Walsh 2.2.36-1James Antill 2.2.35-2Dan Walsh 2.2.35-1Dan Walsh 2.2.34-3Dan Walsh 2.2.34-2Dan Walsh 2.2.34-1Dan Walsh 2.2.33-1Dan Walsh 2.2.32-2Dan Walsh 2.2.32-1Dan Walsh 2.2.31-1Dan Walsh 2.2.30-2Dan Walsh 2.2.30-1Dan Walsh 2.2.29-6Russell Coker 2.2.29-5Dan Walsh 2.2.29-4Dan Walsh 2.2.29-3Dan Walsh 2.2.29-2Dan Walsh 2.2.29-1Dan Walsh 2.2.28-3Dan Walsh 2.2.28-2Dan Walsh 2.2.28-1Dan Walsh 2.2.27-1Dan Walsh 2.2.25-3Dan Walsh 2.2.25-2Dan Walsh 2.2.24-1Dan Walsh 2.2.23-19Dan Walsh 2.2.23-18Dan Walsh 2.2.23-17Karsten Hopp 2.2.23-16Dan Walsh 2.2.23-15Dan Walsh 2.2.23-14Dan Walsh 2.2.23-13Dan Walsh 2.2.23-12Jeremy Katz - 2.2.23-11Jeremy Katz - 2.2.23-10Dan Walsh 2.2.23-9Dan Walsh 2.2.23-8Dan Walsh 2.2.23-7Dan Walsh 2.2.23-5Dan Walsh 2.2.23-4Dan Walsh 2.2.23-3Dan Walsh 2.2.23-2Dan Walsh 2.2.23-1Dan Walsh 2.2.22-2Dan Walsh 2.2.22-1Dan Walsh 2.2.21-9Dan Walsh 2.2.21-8Dan Walsh 2.2.21-7Dan Walsh 2.2.21-6Dan Walsh 2.2.21-5Dan Walsh 2.2.21-4Dan Walsh 2.2.21-3Dan Walsh 2.2.21-2Dan Walsh 2.2.21-1Dan Walsh 2.2.20-1Dan Walsh 2.2.19-2Dan Walsh 2.2.19-1Dan Walsh 2.2.18-2Dan Walsh 2.2.18-1Dan Walsh 2.2.17-2Dan Walsh 2.2.16-1Dan Walsh 2.2.15-4Dan Walsh 2.2.15-3Dan Walsh 2.2.15-1Dan Walsh 2.2.14-2Dan Walsh 2.2.14-1Dan Walsh 2.2.13-1Dan Walsh 2.2.12-1Dan Walsh 2.2.11-2Dan Walsh 2.2.11-1Dan Walsh 2.2.10-1Dan Walsh 2.2.9-2Dan Walsh 2.2.9-1Dan Walsh 2.2.8-2Dan Walsh 2.2.7-1Dan Walsh 2.2.6-3Dan Walsh 2.2.6-2Dan Walsh 2.2.6-1Dan Walsh 2.2.5-1Dan Walsh 2.2.4-1Dan Walsh 2.2.3-1Dan Walsh 2.2.2-1Dan Walsh 2.2.1-1Dan Walsh 2.1.13-1Dan Walsh 2.1.12-3Dan Walsh 2.1.11-1Dan Walsh 2.1.10-1Jeremy Katz - 2.1.9-2Dan Walsh 2.1.9-1Dan Walsh 2.1.8-3Dan Walsh 2.1.8-2Dan Walsh 2.1.8-1Dan Walsh 2.1.7-4Dan Walsh 2.1.7-3Dan Walsh 2.1.7-2Dan Walsh 2.1.7-1Dan Walsh 2.1.6-24Dan Walsh 2.1.6-23Dan Walsh 2.1.6-22Dan Walsh 2.1.6-21Dan Walsh 2.1.6-20Dan Walsh 2.1.6-18Dan Walsh 2.1.6-17Dan Walsh 2.1.6-16Dan Walsh 2.1.6-15Dan Walsh 2.1.6-14Dan Walsh 2.1.6-13Dan Walsh 2.1.6-11Dan Walsh 2.1.6-10Dan Walsh 2.1.6-9Dan Walsh 2.1.6-8Dan Walsh 2.1.6-5Dan Walsh 2.1.6-4Dan Walsh 2.1.6-3Dan Walsh 2.1.6-2Dan Walsh 2.1.6-1Dan Walsh 2.1.4-2Dan Walsh 2.1.4-1Dan Walsh 2.1.3-1Jeremy Katz - 2.1.2-3Dan Walsh 2.1.2-2Dan Walsh 2.1.2-1Dan Walsh 2.1.1-3Dan Walsh 2.1.1-2Dan Walsh 2.1.1-1Dan Walsh 2.1.0-3Dan Walsh 2.1.0-2.Dan Walsh 2.1.0-1.Dan Walsh 2.0.11-2.Dan Walsh 2.0.11-1.Dan Walsh 2.0.9-1.Dan Walsh 2.0.8-1.Dan Walsh 2.0.7-3Dan Walsh 2.0.7-2Dan Walsh 2.0.6-2Dan Walsh 2.0.5-4Dan Walsh 2.0.5-1Dan Walsh 2.0.4-1Dan Walsh 2.0.2-2Dan Walsh 2.0.2-1Dan Walsh 2.0.1-2Dan Walsh 2.0.1-1- Remove disabling ganesha module in pre install phase of installation new selinux-policy package where ganesha is again standalone module Resolves: rhbz#1638257- Allow staff_t userdomain and confined_admindomain attribute to allow use generic ptys because of new sudo feature 'io logging' Resolves: rhbz#1638427- Run ganesha as ganesha_t domain again, revert changes where ganesha is running as nfsd_t Resolves: rhbz#1638257- Fix missing patch in spec file Resolves: rhbz#1635704- Allow cinder_volume_t domain to dbus chat with systemd_logind_t domain Resolves: rhbz#1635704- Allow neutron domain to read/write /var/run/utmp Resolves: rhbz#1630318- Allow tomcat_domain to read /dev/random Resolves: rhbz#1631666 - Allow neutron_t domain to use pam Resolves: rhbz#1630318- Add interface apache_read_tmp_dirs() - Allow dirsrvadmin_script_t domain to list httpd_tmp_t dirs Resolves: rhbz#1622602- Allow tomcat servers to manage usr_t files Resolves: rhbz#1625678 - Dontaudit tomcat serves to append to /dev/random device Resolves: rhbz#1625678 - Allow sys_nice capability to mysqld_t domain - Allow dirsrvadmin_script_t domain to read httpd tmp files Resolves: rhbz#1622602 - Allow syslogd_t domain to manage cert_t files Resolves: rhbz#1615995- Allow sbd_t domain to getattr of all char files in /dev and read sysfs_t files and dirs Resolves: rhbz#1627114 - Expand virt_read_lib_files() interface to allow list dirs with label virt_var_lib_t Resolves: rhbz#1567753- Allow tomcat Tomcat to delete a temporary file used when compiling class files for JSPs. Resolves: rhbz#1625678 - Allow chronyd_t domain to read virt_var_lib_t files - Allow virtual machines to use dri devices. This allows use openCL GPU calculations. BZ(1337333) Resolves: rhbz#1625613 - Allow tomcat services create link file in /tmp Resolves: rhbz#1624289 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322- Make working SELinux sandbox with Wayland. Resolves: rhbz#1624308 - Allow svirt_t domain to mmap svirt_image_t block files Resolves: rhbz#1624224 - Add caps dac_read_search and dav_override to pesign_t domain - Allow iscsid_t domain to mmap userio chr files Resolves: rhbz#1623589 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322 - Add execute_no_trans permission to mmap_exec_file_perms pattern - Allow sudodomain to search caller domain proc info - Allow xdm_t domain to mmap and read cert_t files - Replace optional policy blocks to make dbus interfaces effective Resolves: rhbz#1624414 - Add interface dev_map_userio_dev()- Allow readhead_t domain to mmap own pid files Resolves: rhbz#1614169- Allow ovs-vswitchd labeled as openvswitch_t domain communicate with qemu-kvm via UNIX stream socket - Allow httpd_t domain to mmap tmp files Resolves: rhbz#1608355 - Update dirsrv_read_share() interface to allow caller domain to mmap dirsrv_share_t files - Update dirsrvadmin_script_t policy to allow read httpd_tmp_t symlinks - Label /dev/tpmrm[0-9]* as tpm_device_t - Allow semanage_t domain mmap usr_t files Resolves: rhbz#1622607 - Update dev_filetrans_all_named_dev() to allow create event22-30 character files with label event_device_t- Allow nagios_script_t domain to mmap nagios_log_t files Resolves: rhbz#1620013 - Allow nagios_script_t domain to mmap nagios_spool_t files Resolves: rhbz#1620013 - Update userdom_security_admin() and userdom_security_admin_template() to allow use auditctl Resolves: rhbz#1622197 - Update selinux_validate_context() interface to allow caller domain to mmap security_t files Resolves: rhbz#1622061- Allow virtd_t domain to create netlink_socket - Allow rpm_t domain to write to audit - Allow rpm domain to mmap rpm_var_lib_t files Resolves: rhbz#1619785 - Allow nagios_script_t domain to mmap nagios_etc_t files Resolves: rhbz#1620013 - Update nscd_socket_use() to allow caller domain to stream connect to nscd_t Resolves: rhbz#1460715 - Allow secadm_t domain to mmap audit config and log files - Allow insmod_t domain to read iptables pid files - Allow systemd to mounton /etc Resolves: rhbz#1619785- Allow kdumpctl_t domain to getattr fixed disk device in mls Resolves: rhbz#1615342 - Allow initrc_domain to mmap all binaries labeled as systemprocess_entry Resolves: rhbz#1615342- Allow virtlogd to execute itself Resolves: rhbz#1598392- Allow kdumpctl_t domain to manage kdumpctl_tmp_t fifo files Resolves: rhbz#1615342 - Allow kdumpctl to write to files on all levels Resolves: rhbz#1615342 - Fix typo in radius policy Resolves: rhbz#1619197 - Allow httpd_t domain to mmap httpd_config_t files Resolves: rhbz#1615894 - Add interface dbus_acquire_svc_system_dbusd() - Allow sanlock_t domain to connectto to unix_stream_socket Resolves: rhbz#1614965 - Update nfsd_t policy because of ganesha features Resolves: rhbz#1511489 - Allow conman to getattr devpts_t Resolves: rhbz#1377915 - Allow tomcat_domain to connect to smtp ports Resolves: rhbz#1253502 - Allow tomcat_t domain to mmap tomcat_var_lib_t files Resolves: rhbz#1618519 - Allow slapd_t domain to mmap slapd_var_run_t files Resolves: rhbz#1615319 - Allow nagios_t domain to mmap nagios_log_t files Resolves: rhbz#1618675 - Allow nagios to exec itself and mmap nagios spool files BZ(1559683) - Allow nagios to mmap nagios config files BZ(1559683) - Allow kpropd_t domain to mmap krb5kdc_principal_t files Resolves: rhbz#1619252 - Update syslogd policy to make working elasticsearch - Label tcp and udp ports 9200 as wap_wsp_port - Allow few domains to rw inherited kdumpctl tmp pipes Resolves: rhbz#1615342- Allow systemd_dbusd_t domain read/write to nvme devices Resolves: rhbz#1614236 - Allow mysqld_safe_t do execute itself - Allow smbd_t domain to chat via dbus with avahi daemon Resolves: rhbz#1600157 - cupsd_t domain will create /etc/cupsd/ppd as cupsd_etc_rw_t Resolves: rhbz#1452595 - Allow amanda_t domain to getattr on tmpfs filesystem BZ(1527645) Resolves: rhbz#1452444 - Update screen_role_template to allow caller domain to have screen_exec_t as entrypoint do new domain Resolves: rhbz#1384769 - Add alias httpd__script_t to _script_t to make sepolicy generate working Resolves: rhbz#1271324 - Allow kprop_t domain to read network state Resolves: rhbz#1600705 - Allow sysadm_t domain to accept socket Resolves: rhbz#1557299 - Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow kprop_t domain to read network state Resolves: rhbz#1600705- Allow kpropd domain to exec itself Resolves: rhbz#1600705 - Allow ipmievd_t to mmap kernel modules BZ(1552535) - Allow hsqldb_t domain to mmap own temp files Resolves: rhbz#1612143 - Allow hsqldb_t domain to read cgroup files Resolves: rhbz#1612143 - Allow rngd_t domain to read generic certs Resolves: rhbz#1612456 - Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow virtlogd_t domain to chat via dbus with systemd_logind Resolves: rhbz#1593740- Allow sblim_sfcbd_t domain to mmap own tmpfs files Resolves: rhbz#1609384 - Update logging_manage_all_logs() interface to allow caller domain map all logfiles Resolves: rhbz#1592028- Dontaudit oracleasm_t domain to request sys_admin capability - Allow iscsid_t domain to load kernel module Resolves: rhbz#1589295 - Update rhcs contexts to reflects the latest fenced changes - Allow httpd_t domain to rw user_tmp_t files Resolves: rhbz#1608355 - /usr/libexec/udisks2/udisksd should be labeled as devicekit_disk_exec_t Resolves: rhbz#1521063 - Allow tangd_t dac_read_search Resolves: rhbz#1607810 - Allow glusterd_t domain to mmap user_tmp_t files - Allow mongodb_t domain to mmap own var_lib_t files Resolves: rhbz#1607729 - Allow iscsid_t domain to mmap sysfs_t files Resolves: rhbz#1602508 - Allow tomcat_domain to search cgroup dirs Resolves: rhbz#1600188 - Allow httpd_t domain to mmap own cache files Resolves: rhbz#1603505 - Allow cupsd_t domain to mmap cupsd_etc_t files Resolves: rhbz#1599694 - Allow kadmind_t domain to mmap krb5kdc_principal_t Resolves: rhbz#1601004 - Allow virtlogd_t domain to read virt_etc_t link files Resolves: rhbz#1598593 - Allow dirsrv_t domain to read crack db Resolves: rhbz#1599726 - Dontaudit pegasus_t to require sys_admin capability Resolves: rhbz#1374570 - Allow mysqld_t domain to exec mysqld_exec_t binary files - Allow abrt_t odmain to read rhsmcertd lib files Resolves: rhbz#1601389 - Allow winbind_t domain to request kernel module loads Resolves: rhbz#1599236 - Allow gpsd_t domain to getsession and mmap own tmpfs files Resolves: rhbz#1598388 - Allow smbd_t send to nmbd_t via dgram sockets BZ(1563791) Resolves: rhbz#1600157 - Allow tomcat_domain to read cgroup_t files Resolves: rhbz#1601151 - Allow varnishlog_t domain to mmap varnishd_var_lib_t files Resolves: rhbz#1600704 - Allow dovecot_auth_t domain to manage also dovecot_var_run_t fifo files. BZ(1320415) Resolves: rhbz#1600692 - Fix ntp SELinux module - Allow innd_t domain to mmap news_spool_t files Resolves: rhbz#1600591 - Allow haproxy daemon to reexec itself. BZ(1447800) Resolves: rhbz#1600578 - Label HOME_DIR/mozilla.pdf file as mozilla_home_t instead of user_home_t Resolves: rhbz#1559859 - Allow pkcs_slotd_t domain to mmap own tmpfs files Resolves: rhbz#1600434 - Allow fenced_t domain to reboot Resolves: rhbz#1293384 - Allow bluetooth_t domain listen on bluetooth sockets BZ(1549247) Resolves: rhbz#1557299 - Allow lircd to use nsswitch. BZ(1401375) - Allow targetd_t domain mmap lvm config files Resolves: rhbz#1546671 - Allow amanda_t domain to read network system state Resolves: rhbz#1452444 - Allow abrt_t domain to read rhsmcertd logs Resolves: rhbz#1492059 - Allow application_domain_type also mmap inherited user temp files BZ(1552765) Resolves: rhbz#1608421 - Allow ipsec_t domain to read l2tpd pid files Resolves: rhbz#1607994 - Allow systemd_tmpfiles_t do mmap system db files - Improve domain_transition_pattern to allow mmap entrypoint bin file. Resolves: rhbz#1460322 - Allow nsswitch_domain to mmap passwd_file_t files BZ(1518655) Resolves: rhbz#1600528 - Dontaudit syslogd to watching top llevel dirs when imfile module is enabled Resolves: rhbz#1601928 - Allow ipsec_t can exec ipsec_exec_t Resolves: rhbz#1600684 - Allow netutils_t domain to mmap usmmon device Resolves: rhbz#1600586 - Allow netlabel_mgmt_t domain to read sssd public files, stream connect to sssd_t BZ(1483655) - Allow userdomain sudo domains to use generic ptys Resolves: rhbz#1564470 - Allow traceroute to create icmp packets Resolves: rhbz#1548350 - Allow systemd domain to mmap lvm config files BZ(1594584) - Add new interface lvm_map_config - refpolicy: Update for kernel sctp support Resolves: rhbz#1597111 Add additional entries to support the kernel SCTP implementation introduced in kernel 4.16- Update oddjob_domtrans_mkhomedir() interface to allow caller domain also mmap oddjob_mkhomedir_exec_t files Resolves: rhbz#1596306 - Update rhcs_rw_cluster_tmpfs() interface to allow caller domain to mmap cluster_tmpfs_t files Resolves: rhbz#1589257 - Allow radiusd_t domain to read network sysctls Resolves: rhbz#1516233 - Allow chronyc_t domain to use nscd shm Resolves: rhbz#1596563 - Label /var/lib/tomcats dir as tomcat_var_lib_t Resolves: rhbz#1596367 - Allow lsmd_t domain to mmap lsmd_plugin_exec_t files Resolves: rhbz#bea0c8174 - Label /usr/sbin/rhn_check-[0-9]+.[0-9]+ as rpm_exec_t Resolves: rhbz#1596509 - Update seutil_exec_loadpolicy() interface to allow caller domain to mmap load_policy_exec_t files Resolves: rhbz#1596072 - Allow xdm_t to read systemd hwdb Resolves: rhbz#1596720 - Allow dhcpc_t domain to mmap files labeled as ping_exec_t Resolves: rhbz#1596065- Allow tangd_t domain to create tcp sockets Resolves: rhbz#1595775 - Update postfix policy to allow postfix_master_t domain to mmap all postfix* binaries Resolves: rhbz#1595328 - Allow amanda_t domain to have setgid capability Resolves: rhbz#1452444 - Update usermanage_domtrans_useradd() to allow caller domain to mmap useradd_exec_t files Resolves: rhbz#1595667- Allow abrt_watch_log_t domain to mmap binaries with label abrt_dump_oops_exec_t Resolves: rhbz#1591191 - Update cups_filetrans_named_content() to allow caller domain create ppd directory with cupsd_etc_rw_t label Resolves: rhbz#1452595 - Allow abrt_t domain to write to rhsmcertd pid files Resolves: rhbz#1492059 - Allow pegasus_t domain to eexec lvm binaries and allow read/write access to lvm control Resolves: rhbz#1463470 - Add vhostmd_t domain to read/write to svirt images Resolves: rhbz#1465276 - Dontaudit action when abrt-hook-ccpp is writing to nscd sockets Resolves: rhbz#1460715 - Update openvswitch policy Resolves: rhbz#1594729 - Update kdump_manage_kdumpctl_tmp_files() interface to allow caller domain also mmap kdumpctl_tmp_t files Resolves: rhbz#1583084 - Allow sssd_t and slpad_t domains to mmap generic certs Resolves: rhbz#1592016 Resolves: rhbz#1592019 - Allow oddjob_t domain to mmap binary files as oddjob_mkhomedir_exec_t files Resolves: rhbz#1592022 - Update dbus_system_domain() interface to allow system_dbusd_t domain to mmap binary file from second parameter Resolves: rhbz#1583080 - Allow chronyc_t domain use inherited user ttys Resolves: rhbz#1593267 - Allow stapserver_t domain to mmap own tmp files Resolves: rhbz#1593122 - Allow sssd_t domain to mmap files labeled as sssd_selinux_manager_exec_t Resolves: rhbz#1592026 - Update policy for ypserv_t domain Resolves: rhbz#1592032 - Allow abrt_dump_oops_t domain to mmap all non security files Resolves: rhbz#1593728 - Allow svirt_t domain mmap svirt_image_t files Resolves: rhbz#1592688 - Allow virtlogd_t domain to write inhibit systemd pipes. Resolves: rhbz#1593740 - Allow sysadm_t and staff_t domains to use sudo io logging Resolves: rhbz#1564470 - Allow sysadm_t domain create sctp sockets Resolves: rhbz#1571591 - Update mount_domtrans() interface to allow caller domain mmap mount_exec_t Resolves: rhbz#1592025 - Allow dhcpc_t to mmap all binaries with label hostname_exec_t, ifconfig_exec_t and netutils_exec_t Resolves: rhbz#1594661- Fix typo in logwatch interface file - Allow spamd_t to manage logwatch_cache_t files/dirs - Allow dnsmasw_t domain to create own tmp files and manage mnt files - Allow fail2ban_client_t to inherit rlimit information from parent process Resolves: rhbz#1513100 - Allow nscd_t to read kernel sysctls Resolves: rhbz#1512852 - Label /var/log/conman.d as conman_log_t Resolves: rhbz#1538363 - Add dac_override capability to tor_t domain Resolves: rhbz#1540711 - Allow certmonger_t to readwrite to user_tmp_t dirs Resolves: rhbz#1543382 - Allow abrt_upload_watch_t domain to read general certs Resolves: rhbz#1545098 - Update postfix_domtrans_master() interface to allow caller domain also mmap postfix_master_exec_t binary Resolves: rhbz#1583087 - Allow postfix_domain to mmap postfix_qmgr_exec_t binaries Resolves: rhbz#1583088 - Allow postfix_domain to mmap postfix_pickup_exec_t binaries Resolves: rhbz#1583091 - Allow chornyd_t read phc2sys_t shared memory Resolves: rhbz#1578883 - Allow virt_qemu_ga_t read utmp Resolves: rhbz#1571202 - Add several allow rules for pesign policy: Resolves: rhbz#1468744 - Allow pesign domain to read /dev/random - Allow pesign domain to create netlink_kobject_uevent_t sockets - Allow pesign domain create own tmp files - Add setgid and setuid capabilities to mysqlfd_safe_t domain Resolves: rhbz#1474440 - Add tomcat_can_network_connect_db boolean Resolves: rhbz#1477948 - Update virt_use_sanlock() boolean to read sanlock state Resolves: rhbz#1448799 - Add sanlock_read_state() interface - Allow postfix_cleanup_t domain to stream connect to all milter sockets BZ(1436026) Resolves: rhbz#1563423 - Update abrt_domtrans and abrt_exec() interfaces to allow caller domain to mmap binary file Resolves:rhbz#1583080 - Update nscd_domtrans and nscd_exec interfaces to allow caller domain also mmap nscd binaries Resolves: rhbz#1583086 - Update snapperd_domtrans() interface to allow caller domain to mmap snapperd_exec_t file Resolves: rhbz#1583802 - Allow zoneminder_t to getattr of fs_t Resolves: rhbz#1585328 - Fix denials during ipa-server-install process on F27+ Resolves: rhbz#1586029 - Allow ipa_dnskey_t to exec ipa_dnskey_exec_t files Resolves: rhbz#1586033 - Allow rhsmcertd_t domain to send signull to postgresql_t domain Resolves: rhbz#1588119 - Allow policykit_t domain to dbus chat with dhcpc_t Resolves: rhbz#1364513 - Adding new boolean keepalived_connect_any() Resolves: rhbz#1443473 - Allow amanda to create own amanda_tmpfs_t files Resolves: rhbz#1452444 - Add amanda_tmpfs_t label. BZ(1243752) - Allow gdomap_t domain to connect to qdomap_port_t Resolves: rhbz#1551944 - Fix typos in sge - Fix typo in openvswitch policy - /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow sshd_keygen_t to execute plymouthd Resolves: rhbz#1583531 - Update seutil_domtrans_setfiles() interface to allow caller domain to do mmap on setfiles_exec_t binary Resolves: rhbz#1583090 - Allow systemd_networkd_t create and relabel tun sockets Resolves: rhbz#1583830 - Allow map audisp_exec_t files fordomains executing this binary Resolves: rhbz#1586042 - Add new interface postgresql_signull() - Add fs_read_xenfs_files() interface.- /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow dac override capability to mandb_t domain BZ(1529399) Resolves: rhbz#1423361 - Allow inetd_child process to chat via dbus with abrt Resolves: rhbz#1428805 - Allow zabbix_agent_t domain to connect to redis_port_t Resolves: rhbz#1418860 - Allow rhsmcertd_t domain to read xenfs_t files Resolves: rhbz#1405870 - Allow zabbix_agent_t to run zabbix scripts Resolves: rhbz#1380697 - Allow rabbitmq_t domain to create own tmp files/dirs Resolves: rhbz#1546897 - Allow policykit_t mmap policykit_auth_exec_t files Resolves: rhbz#1583082 - Allow ipmievd_t domain to read general certs Resolves: rhbz#1514591 - Add sys_ptrace capability to pcp_pmie_t domain - Allow squid domain to exec ldconfig Resolves: rhbz#1532017 - Make working gpg agent in gpg_agent_t domain Resolves: rhbz#1535109 - Update gpg SELinux policy module - Allow kexec to read kernel module files in /usr/lib/modules. Resolves: rhbz#1536690 - Allow mailman_domain to read system network state Resolves: rhbz#1413510 - Allow mailman_mail_t domain to search for apache configs Resolves: rhbz#1413510 - Allow openvswitch_t domain to read neutron state and read/write fixed disk devices Resolves: rhbz#1499208 - Allow antivirus_domain to read all domain system state Resolves: rhbz#1560986 - Allow targetd_t domain to red gconf_home_t files/dirs Resolves: rhbz#1546671 - Allow freeipmi domain to map sysfs_t files Resolves: rhbz#1575918 - Label /usr/libexec/bluetooth/obexd as obexd_exec_t Resolves: rhbz#1351750 - Update rhcs SELinux module Resolves: rhbz#1589257 - Allow iscsid_t domain mmap kernel modules Resolves: rhbz#1589295 - Allow iscsid_t domain mmap own tmp files Resolves: rhbz#1589295 - Update iscsid_domtrans() interface to allow mmap iscsid_exec_t binary Resolves: rhbz#1589295 - Update nscd_socket_use interface to allow caller domain also mmap nscd_var_run_t files. Resolves: rhbz#1589271 - Allow nscd_t domain to mmap system_db_t files Resolves: rhbz#1589271 - Add interface nagios_unconfined_signull() - Allow lircd_t domain read sssd public files Add setgid capability to lircd_t domain Resolves: rhbz#1550700 - Add missing requires - Allow tomcat domain sends email Resolves: rhbz#1585184 - Allow memcached_t domain nnp_transition becuase of systemd security features BZ(1514867) Resolves: rhbz#1585714 - Allow kdump_t domain to map /boot files Resolves: rhbz#1588884 - Fix typo in netutils policy - Allow confined users get AFS tokens Resolves: rhbz#1417671 - Allow sysadm_t domain to chat via dbus Resolves: rhbz#1582146 - Associate sysctl_kernel_t type with filesystem attribute - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Add interface dev_map_sysfs - Allow xdm_t domain to execute xdm_var_lib_t files Resolves: rhbz#1589139 - Allow syslogd_t domain to send signull to nagios_unconfined_plugin_t Resolves: rhbz#1569344 - Label /dev/vhost-vsock char device as vhost_device_t - Add files_map_boot_files() interface Resolves: rhbz#1588884 - Update traceroute_t domain to allow create dccp sockets Resolves: rhbz#1548350- Update ctdb domain to support gNFS setup Resolves: rhbz#1576818 - Allow authconfig_t dbus chat with policykit Resolves: rhbz#1551241 - Allow lircd_t domain to read passwd_file_t Resolves: rhbz:#1550700 - Allow lircd_t domain to read system state Resolves: rhbz#1550700 - Allow smbcontrol_t to mmap samba_var_t files and allow winbind create sockets BZ(1559795) Resolves: rhbz#1574521 - Allow tangd_t domain read certs Resolves: rhbz#1509055 - Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow ctdb_t domain modify ctdb_exec_t files Resolves: rhbz#1572584 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Allow SELinux users (except guest and xguest) to using bluetooth sockets Resolves: rhbz#1557299 - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Fix broken sysadm SELinux module Resolves: rhbz#1557311 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Update ssh_domtrans_keygen interface to allow mmap ssh_keygen_exec_t binary file Resolves: rhbz#1583089 - Allow systemd_networkd_t to read/write tun tap devices Resolves: rhbz#1583830 - Add bridge_socket, dccp_socket, ib_socket and mpls_socket to socket_class_set Resolves: rhbz#1583771 - Allow audisp_t domain to mmap audisp_exec_t binary Resolves: rhbz#1583551 - Fix duplicates in sysadm.te file Resolves: rhbz#1307183 - Allow sysadm_u use xdm Resolves: rhbz#1307183 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix duplicates in sysadm.te file Resolves: rhbz#1307183- Allow sysadm_u use xdm Resolves: rhbz#1307183- Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Improve procmail_domtrans() to allow mmaping procmail_exec_t - Allow hypervvssd_t domain to read fixed disk devices Resolves: rhbz#1581225 - Improve modutils_domtrans_insmod() interface to mmap insmod_exec_t binaries Resolves: rhbz#1581551 - Improve iptables_domtrans() interface to allow mmaping iptables_exec_t binary Resolves: rhbz#1581551 - Improve auth_domtrans_login_programinterface to allow also mmap login_exec_t binaries Resolves: rhbz#1581551 - Improve auth_domtrans_chk_passwd() interface to allow also mmaping chkpwd_exec_t binaries. Resolves: rhbz#1581551 - Allow mmap dhcpc_exec_t binaries in sysnet_domtrans_dhcpc interface- Add dbus_stream_connect_system_dbusd() interface. - Allow pegasus_t domain to mount tracefs_t filesystem Resolves:rhbz#1374570 - Allow psad_t domain to read all domains state Resolves: rhbz#1558439 - Add net_raw capability to named_t domain BZ(1545586) - Allow tomcat_t domain to connect to mongod_t tcp port Resolves:rhbz#1539748 - Allow dovecot and postfix to connect to systemd stream sockets Resolves: rhbz#1368642 - Label /usr/libexec/bluetooth/obexd as bluetoothd_exec_t to run process as bluetooth_t Resolves:rhbz#1351750 - Rename tang policy to tangd - Add interface systemd_rfkill_domtrans() - Allow users staff and sysadm to run wireshark on own domain Resolves:rhbz#1546362 - Allow systemd-bootchart to create own tmpfs files Resolves:rhbz#1510412- Rename tang policy to tangd - Allow virtd_t domain to relabel virt_var_lib_t files Resolves: rhbz#1558121 - Allow logrotate_t domain to stop services via systemd Resolves: rhbz#1527522 - Add tang policy Resolves: rhbz#1509055 - Allow mozilla_plugin_t to create mozilla.pdf file in user homedir with label mozilla_home_t Resolves: rhbz#1559859 - Improve snapperd SELinux policy Resolves: rhbz#1365555 - Allow snapperd_t daemon to create unlabeled dirs. Resolves: rhbz#1365555 - We have inconsistency in cgi templates with upstream, we use _content_t, but refpolicy use httpd__content_t. Created aliasses to make it consistence Resolves: rhbz#1271324 - Allow Openvswitch adding netdev bridge ovs 2.7.2.10 FDP Resolves: rhbz#1503835 - Add new Boolean tomcat_use_execmem Resolves: rhbz#1565226 - Allow domain transition from logrotate_t to chronyc_t Resolves: rhbz#1568281 - Allow nfsd_t domain to read/write sysctl fs files Resolves: rhbz#1516593 - Allow conman to read system state Resolves: rhbz#1377915 - Allow lircd_t to exec shell and add capabilities dac_read_search and dac_override Resolves: rhbz#1550700 - Allow usbmuxd to access /run/udev/data/+usb:*. Resolves: rhbz#1521054 - Allow abrt_t domain to manage kdump crash files Resolves: rhbz#1491585 - Allow systemd to use virtio console Resolves: rhbz#1558121 - Allow transition from sysadm role into mdadm_t domain. Resolves: rhbz#1551568 - Label /dev/op_panel and /dev/opal-prd as opal_device_t Resolves: rhbz#1537618 - Label /run/ebtables.lock as iptables_var_run_t Resolves: rhbz#1511437 - Allow udev_t domain to manage udev_rules_t char files. Resolves: rhbz#1545094 - Allow nsswitch_domain to read virt_var_lib_t files, because of libvirt NSS plugin. Resolves: rhbz#1567753 - Fix filesystem inteface file, we don't have nsfs_fs_t type, just nsfs_t Resolves: rhbz#1547700 - Allow iptables_t domain to create dirs in etc_t with system_conf_t labels- Add new boolean redis_enable_notify() Resolves: rhbz#1421326 - Label /var/log/shibboleth-www(/.*) as httpd_sys_rw_content_t Resolves: rhbz#1549514 - Add new label for vmtools scripts and label it as vmtools_unconfined_t stored in /etc/vmware-tools/ Resolves: rbhz#1463593 - Remove labeling for /etc/vmware-tools to bin_t it should be vmtools_unconfined_exec_t Resolves: rbhz#1463593- Backport several changes for snapperdfrom Fedora Rawhide Resolves: rhbz#1556798 - Allow snapperd_t to set priority for kernel processes Resolves: rhbz#1556798 - Make ganesha nfs server. Resolves: rhbz#1511489 - Allow vxfs filesystem to use SELinux labels Resolves: rhbz#1482880 - Add map permission to selinux-policy Resolves: rhbz#1460322- Label /usr/libexec/dbus-1/dbus-daemon-launch-helper as dbusd_exec_t to have systemd dbus services running in the correct domain instead of unconfined_service_t if unconfined.pp module is enabled. Resolves: rhbz#1546721- Allow openvswitch_t stream connect svirt_t Resolves: rhbz#1540702- Allow openvswitch domain to manage svirt_tmp_t sock files Resolves: rhbz#1540702 - Fix broken systemd_tmpfiles_run() interface- Allow dirsrv_t domain to create tmp link files Resolves: rhbz#1536011 - Label /usr/sbin/ldap-agent as dirsrv_snmp_exec_t Resolves: rhbz#1428568 - Allow ipsec_mgmt_t execute ifconfig_exec_t binaries - Allow ipsec_mgmt_t nnp domain transition to ifconfig_t Resolves: rhbz#1539416- Allow svirt_domain to create socket files in /tmp with label svirt_tmp_t Resolves: rhbz#1540702 - Allow keepalived_t domain getattr proc filesystem Resolves: rhbz#1477542 - Rename svirt_sandbox_file_t to container_file_t and svirt_lxc_net_t to container_t Resolves: rhbz#1538544 - Allow ipsec_t nnp transistions to domains ipsec_mgmt_t and ifconfig_t Resolves: rhbz:#1539416 - Allow systemd_logind_t domain to bind on dhcpd_port_t,pki_ca_port_t,flash_port_t Resolves: rhbz#1479350- Allow openvswitch_t domain to read cpuid, write to sysfs files and creating openvswitch_tmp_t sockets Resolves: rhbz#1535196 - Add new interface ppp_filetrans_named_content() Resolves: rhbz#1530601 - Allow keepalived_t read sysctl_net_t files Resolves: rhbz#1477542 - Allow puppetmaster_t domtran to puppetagent_t Resolves: rhbz#1376893 - Allow kdump_t domain to read kernel ring buffer Resolves: rhbz#1540004 - Allow ipsec_t domain to exec ifconfig_exec_t binaries. Resolves: rhbz#1539416 - Allow unconfined_domain_typ to create pppd_lock_t directory in /var/lock Resolves: rhbz#1530601 - Allow updpwd_t domain to create files in /etc with shadow_t label Resolves: rhbz#1412838 - Allow iptables sysctl load list support with SELinux enforced Resolves: rhbz#1535572- Allow virt_domains to acces infiniband pkeys. Resolves: rhbz#1533183 - Label /usr/libexec/ipsec/addconn as ipsec_exec_t to run this script as ipsec_t instead of init_t Resolves: rhbz#1535133 - Allow audisp_remote_t domain write to files on all levels Resolves: rhbz#1534924- Allow vmtools_t domain creating vmware_log_t files Resolves: rhbz#1507048 - Allow openvswitch_t domain to acces infiniband devices Resolves: rhbz#1532705- Allow chronyc_t domain to manage chronyd_keys_t files. Resolves: rhbz#1530525 - Make virtlog_t domain system dbus client Resolves: rhbz#1481109 - Update openvswitch SELinux module Resolves: rhbz#1482682 - Allow virtd_t to create also sock_files with label virt_var_run_t Resolves: rhbz#1484075- Allow domains that manage logfiles to man logdirs Resolves: rhbz#1523811- Label /dev/drm_dp_aux* as xserver_misc_device_t Resolves: rhbz#1520897 - Allow sysadm_t to run puppet_exec_t binaries as puppet_t Resolves: rhbz#1255745- Allow tomcat_t to manage pki_tomcat pid files Resolves: rhbz#1478371 - networkmanager: allow talking to openvswitch Resolves: rhbz#1517247 - Allow networkmanager_t and opensm_t to manage subned endports for IPoIB VLANs Resolves: rhbz#1517895 - Allow domains networkmanager_t and opensm_t to control IPoIB VLANs Resolves: rhbz#1517744 - Fix typo in guest interface file Resolves: rhbz#1468254 - Allow isnsd_t domain to accept tcp connections. Resolves: rhbz#1390208- Allow getty to use usbttys Resolves: rhbz#1514235- Allow ldap_t domain to manage also slapd_tmp_t lnk files Resolves: rhbz#1510883 - Allow cluster_t domain creating bundles directory with label var_log_t instead of cluster_var_log_t Resolves: rhbz:#1508360 - Add dac_read_search and dac_override capabilities to ganesha Resolves: rhbz#1483451- Add dependency for policycoreutils-2.5.18 becuase of new cgroup_seclabel policy capability Resolves: rhbz#1510145- Allow jabber domains to connect to postgresql ports Resolves: rhbz#1438489 - Dontaudit accountsd domain creating dirs in /root Resolves: rhbz#1456760 - Dontaudit slapd_t to block suspend system Resolves: rhbz: #1479759 - Allow spamc_t to stream connect to cyrus. Resolves: rhbz#1382955 - allow imapd to read /proc/net/unix file Resolves: rhbz#1393030 - Allow passenger to connect to mysqld_port_t Resolves: rhbz#1433464- Allow chronyc_t domain to use user_ptys Resolves: rhbz#1470150 - allow ptp4l to read /proc/net/unix file - Allow conmand to use usb ttys. Resolves: rhbz#1505121 - Label all files /var/log/opensm.* as opensm_log_t because opensm creating new log files with name opensm-subnet.lst Resolves: rhbz#1505845 - Allow chronyd daemon to execute chronyc. Resolves: rhbz#1508486 - Allow firewalld exec ldconfig. Resolves: rhbz#1375576 - Allow mozilla_plugin_t domain to dbus chat with devicekit Resolves: rhbz#1460477 - Dontaudit leaked logwatch pipes Resolves: rhbz#1450119 - Label /usr/bin/VGAuthService as vmtools_exec_t to confine this daemon. Resolves: rhbz#1507048 - Allow httpd_t domain to execute hugetlbfs_t files Resolves: rhbz#1507682 - Allow nfsd_t domain to read configfs_t files/dirs Resolves: rhbz#1439442 - Hide all allow rules with ptrace inside deny_ptrace boolean Resolves: rhbz#1421075 - Allow tgtd_t domain to read generic certs Resolves: rhbz#1438532 - Allow ptp4l to send msgs via dgram socket to unprivileged user domains Resolves: rhbz#1429853 - Allow dirsrv_snmp_t to use inherited user ptys and read system state Resolves: rhbz#1428568 - Allow glusterd_t domain to create own tmpfs dirs/files Resolves: rhbz#1411310 - Allow keepalived stream connect to snmp Resolves: rhbz#1401556 - After fix in kernel where LSM hooks for dac_override and dac_search_read capability was swaped we need to fix it also in policy Resolves: rhbz#1507089- Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow chronyd_t do request kernel module and block_suspend capability Resolves: rhbz#1350765 - Allow system_cronjob_t to create /var/lib/letsencrypt dir with right label Resolves: rhbz#1447278 - Allow httpd_t also read httpd_user_content_type dirs when httpd_enable_homedirs is enables Resolves: rhbz#1491994 - Allow svnserve to use kerberos Resolves: rhbz#1475271 - Allow conman to use ptmx. Add conman_use_nfs boolean Resolves: rhbz#1377915 - Add nnp transition for services using: NoNewPrivileges systemd security feature Resolves: rhbz#1311430 - Add SELinux support for chronyc Resolves: rhbz#1470150 - Add dac_read_search capability to openvswitch_t domain Resolves: rhbz#1501336 - Allow svnserve to manage own svnserve_log_t files/dirs Resolves: rhbz#1480741 - Allow keepalived_t to search network sysctls Resolves: rhbz#1477542 - Allow puppetagent_t domain dbus chat with rhsmcertd_t domain Resolves: rhbz#1446777 - Add dccp_socket into socker_class_set subset Resolves: rhbz#1459941 - Allow iptables_t to run setfiles to restore context on system Resolves: rhbz#1489118 - Label 20514 tcp/udp ports as syslogd_port_t Label 10514 tcp/udp portas as syslog_tls_port_t Resolves: rhbz:#1411400 - Make nnp transition Active Resolves: rhbz#1480518 - Label tcp 51954 as isns_port_t Resolves: rhbz#1390208 - Add dac_read_search capability chkpwd_t Resolves: rhbz#1376991 - Add support for running certbot(letsencrypt) in crontab Resolves: rhbz#1447278 - Add init_nnp_daemon_domain interface - Allow xdm_t to gettattr /dev/loop-control device Resolves: rhbz#1462925 - Allow nnp trasintion for unconfined_service_t Resolves: rhbz#1311430 - Allow unpriv user domains and unconfined_service_t to use chronyc Resolves: rhbz#1470150 - Allow iptables to exec plymouth. Resolves: rhbz#1480374 - Fix typo in fs_unmount_tracefs interface. Resolves: rhbz#1371057 - Label postgresql-check-db-dir as postgresql_exec_t Resolves: rhbz#1490956- We should not ship selinux-policy with permissivedomains enabled. Resolves: rhbz#1494172 - Fix order of installing selinux-policy-sandbox, because of depedencied in sandbox module, selinux-policy-targeted needs to be installed before selinux-policy-sandbox Resolves: rhbz#1492606- Allow tomcat to setsched Resolves: rhbz#1492730 - Fix rules blocking ipa-server upgrade process Resolves: rhbz#1478371 - Add new boolean tomcat_read_rpm_db() Resolves: rhbz#1477887 - Allow tomcat to connect on mysqld tcp ports - Add ctdbd_t domain sys_source capability and allow setrlimit Resolves: rhbz#1491235 - Fix keepalived SELinux module - Allow automount domain to manage mount pid files Resolves: rhbz#1482381 - Allow stunnel_t domain setsched Resolves: rhbz#1479383 - Add keepalived domain setpgid capability Resolves: rhbz#1486638 - Allow tomcat domain to connect to mssql port Resolves: rhbz#1484572 - Remove snapperd_t from unconfined domaines Resolves: rhbz#1365555 - Fix typo bug in apache module Resolves: rhbz#1397311 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Add interface systemd_tmpfiles_run - End of file cannot be in comment - Allow systemd-logind to use ypbind Resolves: rhbz#1479350 - Add creating opasswd file with shadow_t SELinux label in auth_manage_shadow() interface Resolves: rhbz#1412838 - Allow sysctl_irq_t assciate with proc_t Resolves: rhbz#1485909 - Enable cgourp sec labeling Resolves: rhbz#1485947 - Add cgroup_seclabel policycap. Resolves: rhbz#1485947 - Allow sshd_t domain to send signull to xdm_t processes Resolves: rhbz#1448959 - Allow updpwd_t domain auth file name trans Resolves: rhbz#1412838 - Allow sysadm user to run systemd-tmpfiles Resolves: rbhz#1325364 - Add support labeling for vmci and vsock device Resolves: rhbz#1451358 - Add userdom_dontaudit_manage_admin_files() interface Resolves: rhbz#1323792 - Allow iptables_t domain to read files with modules_conf_t label Resolves: rhbz#1373220 - init: Add NoNewPerms support for systemd. Resolves: rhbz#1480518 - Add nnp_nosuid_transition policycap and related class/perm definitions. Resolves: rhbz#1480518 - refpolicy: Infiniband pkeys and endports Resolves: rhbz#1464484- Allow certmonger using systemctl on pki_tomcat unit files Resolves: rhbz#1481388- Allow targetd_t to create own tmp files. - Dontaudit targetd_t to exec rpm binary file. Resolves: rhbz#1373860 Resolves: rhbz#1424621- Add few rules to make working targetd daemon with SELinux Resolves: rhbz#1373860 - Allow ipmievd_t domain to load kernel modules Resolves: rhbz#1441081 - Allow logrotate to reload transient systemd unit Resolves: rhbz#1440515 - Add certwatch_t domain dac_override and dac_read_search capabilities Resolves: rhbz#1422000 - Allow postgrey to execute bin_t files and add postgrey into nsswitch_domain Resolves: rhbz#1412072 - Allow nscd_t domain to search network sysctls Resolves: rhbz#1432361 - Allow iscsid_t domain to read mount pid files Resolves: rhbz#1482097 - Allow ksmtuned_t domain manage sysfs_t files/dirs Resolves: rhbz#1413865 - Allow keepalived_t domain domtrans into iptables_t Resolves: rhbz#1477719 - Allow rshd_t domain reads net sysctls Resolves: rhbz#1477908 - Add interface seutil_dontaudit_read_module_store() - Update interface lvm_rw_pipes() by adding also open permission - Label /dev/clp device as vfio_device_t Resolves: rhbz#1477624 - Allow ifconfig_t domain unmount fs_t Resolves: rhbz#1477445 - Label /dev/gpiochip* devices as gpio_device_t Resolves: rhbz#1477618 - Add interface dev_manage_sysfs() Resolves: rhbz#1474989- Label /usr/libexec/sudo/sesh as shell_exec_t Resolves: rhbz#1480791- Allow tomcat_t domain couple capabilities to make working tomcat-jsvc Resolves: rhbz#1470735- Allow llpdad send dgram to libvirt Resolves: rhbz#1472722- Add new boolean gluster_use_execmem Resolves: rhbz#1469027 - Allow cluster_t and glusterd_t domains to dbus chat with ganesha service Resolves: rhbz#1468581- Dontaudit staff_t user read admin_home_t files. Resolves: rhbz#1290633- Allow couple rules needed to start targetd daemon with SELinux in enforcing mode Resolves: rhbz#1424621 - Add interface lvm_manage_metadata Resolves: rhbz#1424621- Allow sssd_t to read realmd lib files. Resolves: rhbz#1436689 - Add permission open to files_read_inherited_tmp_files() interface Resolves: rhbz#1290633 Resolves: rhbz#1457106- Allow unconfined_t user all user namespace capabilties. Resolves: rhbz#1461488- Allow httpd_t to read realmd_var_lib_t files Resolves: rhbz#1436689- Allow named_t to bind on udp 4321 port Resolves: rhbz#1312972 - Allow systemd-sysctl cap. sys_ptrace Resolves: rhbz#1458999- Allow pki_tomcat_t execute ldconfig. Resolves: rhbz#1436689- Allow iscsi domain load kernel module. Resolves: rhbz#1457874 - Allow keepalived domain connect to squid tcp port Resolves: rhbz#1457455 - Allow krb5kdc_t domain read realmd lib files. Resolves: rhbz#1436689 - xdm_t should view kernel keys Resolves: rhbz#1432645- Allow tomcat to connect on all unreserved ports - Allow ganesha to connect to all rpc ports Resolves: rhbz#1448090 - Update ganesha with another fixes. Resolves: rhbz#1448090 - Update rpc_read_nfs_state_data() interface to allow read also lnk_files. Resolves: rhbz#1448090 - virt_use_glusterd boolean should be in optional block Update ganesha module to allow create tmp files Resolves: rhbz#1448090 - Hide broken symptoms when machine is configured with network bounding.- Add new boolean virt_use_glusterd Resolves: rhbz#1455994 - Add capability sys_boot for sbd_t domain - Allow sbd_t domain to create rpc sysctls. Resolves: rhbz#1455631 - Allow ganesha_t domain to manage glusterd_var_run_t pid files. Resolves: rhbz#1448090- Create new interface: glusterd_read_lib_files() - Allow ganesha read glusterd lib files. - Allow ganesha read network sysctls Resolves: rhbz#1448090- Add few allow rules to ganesha module Resolves: rhbz#1448090 - Allow condor_master_t to read sysctls. Resolves: rhbz#1277506 - Add dac_override cap to ctdbd_t domain Resolves: rhbz#1435708 - Label 8750 tcp/udp port as dey_keyneg_port_t Resolves: rhbz#1448090- Add ganesha_use_fusefs boolean. Resolves: rhbz#1448090- Allow httpd_t reading kerberos kdc config files Resolves: rhbz#1452215 - Allow tomcat_t domain connect to ibm_dt_2 tcp port. Resolves: rhbz#1447436 - Allow stream connect to initrc_t domains Resolves: rhbz#1447436 - Allow dnsmasq_t domain to read systemd-resolved pid files. Resolves: rhbz#1453114 - Allow tomcat domain name_bind on tcp bctp_port_t Resolves: rhbz#1451757 - Allow smbd_t domain generate debugging files under /var/run/gluster. These files are created through the libgfapi.so library that provides integration of a GlusterFS client in the Samba (vfs_glusterfs) process. Resolves: rhbz#1447669 - Allow condor_master_t write to sysctl_net_t Resolves: rhbz#1277506 - Allow nagios check disk plugin read /sys/kernel/config/ Resolves: rhbz#1277718 - Allow pcp_pmie_t domain execute systemctl binary Resolves: rhbz#1271998 - Allow nagios to connect to stream sockets. Allow nagios start httpd via systemctl Resolves: rhbz#1247635 - Label tcp/udp port 1792 as ibm_dt_2_port_t Resolves: rhbz#1447436 - Add interface fs_read_configfs_dirs() - Add interface fs_read_configfs_files() - Fix systemd_resolved_read_pid interface - Add interface systemd_resolved_read_pid() Resolves: rhbz#1453114 - Allow sshd_net_t domain read/write into crypto devices Resolves: rhbz#1452759 - Label 8999 tcp/udp as bctp_port_t Resolves: rhbz#1451757- nmbd_t needs net_admin capability like smbd Resolves: rhbz#1431859 - Dontaudit net_admin capability for domains postfix_master_t and postfix_qmgr_t Resolves: rhbz#1431859 - Allow rngd domain read sysfs_t Resolves: rhbz#1451735 - Add interface pki_manage_common_files() Resolves: rhbz#1447436 - Allow tomcat_t domain to manage pki_common_t files and dirs Resolves: rhbz#1447436 - Use stricter fc rules for sssd sockets in /var/run Resolves: rhbz#1448060 - Allow certmonger reads httpd_config_t files Resolves: rhbz#1436689 - Allow keepalived_t domain creating netlink_netfilter_socket. Resolves: rhbz#1451684 - Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321- Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Allow sssd_t domain creating sock files labeled as sssd_var_run_t in /var/run/ Resolves: rhbz#1448056 Resolves: rhbz#1448060 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321 - Allow netutils setpcap capability Resolves:1444438- Update targetd policy to accommodate changes in the service Resolves: rhbz#1424621 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Update virt_rw_stream_sockets_svirt() interface to allow confined users set socket options. Resolves: rhbz#1415841 - Allow radius domain stream connec to postgresql Resolves: rhbz#1446145 - Allow virt_domain to read raw fixed_disk_device_t to make working blockcommit Resolves: rhbz#1449977 - Allow glusterd_t domain start ganesha service Resolves: rhbz#1448090 - Made few cosmetic changes in sssd SELinux module Resolves: rhbz#1448060 - sssd-kcm should not run as unconfined_service_t BZ(1447411) Resolves: rhbz#1448060 - Add sssd_secrets labeling Also add named_filetrans interface to make sure all labels are correct Resolves: rhbz#1448056 - Allow keepalived_t domain read usermodehelper_t Resolves: rhbz#1449769 - Allow tomcat_t domain read pki_common_t files Resolves: rhbz#1447436 - Add interface pki_read_common_files() Resolves: rhbz#1447436- Allow hypervkvp_t domain execute hostname Resolves: rhbz#1449064 - Dontaudit sssd_selinux_manager_t use of net_admin capability Resolves: rhbz#1444955 - Allow tomcat_t stream connect to pki_common_t Resolves: rhbz#1447436 - Dontaudit xguest_t's attempts to listen to its tcp_socket - Allow sssd_selinux_manager_t to ioctl init_t sockets Resolves: rhbz#1436689 - Allow _su_t to create netlink_selinux_socket Resolves rhbz#1146987 - Allow unconfined_t to module_load any file Resolves rhbz#1442994- Improve ipa_cert_filetrans_named_content() interface to also allow caller domain manage ipa_cert_t type. Resolves: rhbz#1436689- Allow pki_tomcat_t domain read /etc/passwd. Resolves: rhbz#1436689 - Allow tomcat_t domain read ipa_tmp_t files Resolves: rhbz#1436689 - Label new path for ipa-otpd Resolves: rhbz#1446353 - Allow radiusd_t domain stream connect to postgresql_t Resolves: rhbz#1446145 - Allow rhsmcertd_t to execute hostname_exec_t binaries. Resolves: rhbz#1445494 - Allow virtlogd to append nfs_t files when virt_use_nfs=1 Resolves: rhbz#1402561- Update tomcat policy to adjust for removing unconfined_domain attr. Resolves: rhbz#1432083 - Allow httpd_t domain read also httpd_user_content_type lnk_files. Resolves: rhbz#1383621 - Allow httpd_t domain create /etc/httpd/alias/ipaseesion.key with label ipa_cert_t Resolves: rhbz#1436689 - Dontaudit _gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Label /var/www/html/nextcloud/data as httpd_sys_rw_content_t Resolves: rhbz#1425530 - Add interface ipa_filetrans_named_content() Resolves: rhbz#1432115 - Allow tomcat use nsswitch Resolves: rhbz#1436689 - Allow certmonger_t start/status generic services Resolves: rhbz#1436689 - Allow dirsrv read cgroup files. Resolves: rhbz#1436689 - Allow ganesha_t domain read/write infiniband devices. Resolves: rhbz#1383784 - Allow sendmail_t domain sysctl_net_t files Resolves: rhbz#1369376 - Allow targetd_t domain read network state and getattr on loop_control_device_t Resolves: rhbz#1373860 - Allow condor_schedd_t domain send mails. Resolves: rhbz#1277506 - Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689 - Allow staff to systemctl virt server when staff_use_svirt=1 Resolves: rhbz#1415841 - Allow unconfined_t create /tmp/ca.p12 file with ipa_tmp_t context Resolves: rhbz#1432115 - Label /sysroot/ostree/deploy/rhel-atomic-host/* as root_t Resolves: rhbz#1428112- Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689- Hide broken symptoms when using kernel 3.10.0-514+ with network bonding. Postfix_picup_t domain requires NET_ADMIN capability which is not really needed. Resolves: rhbz#1431859 - Fix policy to reflect all changes in new IPA release Resolves: rhbz#1432115 Resolves: rhbz#1436689- Allow sbd_t to read/write fixed disk devices Resolves: rhbz#1440165 - Add sys_ptrace capability to radiusd_t domain Resolves: rhbz#1426641 - Allow cockpit_session_t domain connects to ssh tcp ports. Resolves: rhbz#1413509- Update tomcat policy to make working ipa install process Resolves: rhbz#1436689- Allow pcp_pmcd_t net_admin capability. - Allow pcp_pmcd_t read net sysctls - Allow system_cronjob_t create /var/run/pcp with pcp_var_run_t Resolves: rhbz#1336211- Fix all AVC denials during pkispawn of CA Resolves: rhbz#1436383 - Update pki interfaces and tomcat module Resolves: rhbz#1436689- Update pki interfaces and tomcat module Resolves: rhbz#1436689- Dontaudit firewalld wants write to /root Resolves: rhbz#1438708 - Dontaudit firewalld to create dirs in /root/ Resolves: rhbz#1438708 - Allow sendmail to search network sysctls Resolves: rhbz#1369376 - Add interface gssd_noatsecure() Resolves: rhbz#1438036 - Add interface gssproxy_noatsecure() Resolves: rhbz#1438036 - Dontaudit pcp_pmlogger_t search for xserver logs. Allow pcp_pmlogger_t to send signals to unconfined doamins Allow pcp_pmlogger_t to send logs to journals Resolves: rhbz#1379371 - Allow chronyd_t net_admin capability to allow support HW timestamping. Resolves: rhbz#1416015 - Update tomcat policy Resolves: rhbz#1436689 Resolves: rhbz#1436383 - Allow certmonger to start haproxy service Resolves: rhbz#1349394 - Allow init noatsecure for gssd and gssproxy Resolves: rhbz#1438036- geoclue wants to dbus chat with avahi Resolves: rhbz#1434286 - Allow iptables get list of kernel modules Resolves: rhbz#1367520 - Allow unconfined_domain_type to enable/disable transient unit Resolves: rhbz#1337041 - Add interfaces init_enable_transient_unit() and init_disable_transient_unit - Revert "Allow sshd setcap capability. This is needed due to latest changes in sshd" Resolves: rhbz#1435264 - Label sysroot dir under ostree as root_t Resolves: rhbz#1428112- Remove ganesha_t domain from permissive domains. Resolves: rhbz#1436988- Allow named_t domain bind on several udp ports Resolves: rhbz#1312972 - Update nscd_use() interface Resolves: rhbz#1281716 - Allow radius_t domain ptrace Resolves: rhbz#1426641 - Update nagios to allos exec systemctl Resolves: rhbz#1247635 - Update pcp SELinux module to reflect all pcp changes Resolves: rhbz#1271998 - Label /var/lib/ssl_db as squid_cache_t Label /etc/squid/ssl_db as squid_cache_t Resolves: rhbz#1325527 - Allow pcp_pmcd_t domain search for network sysctl Allow pcp_pmcd_t domain sys_ptrace capability Resolves: rhbz#1336211- Allow drbd load modules Resolves: rhbz#1134883 - Revert "Add sys_module capability for drbd Resolves: rhbz#1134883" - Allow stapserver list kernel modules Resolves: rhbz#1325976 - Update targetd policy Resolves: rhbz#1373860 - Add sys_admin capability to amanda Resolves: rhbz#1371561 - Allow hypervvssd_t to read all dirs. Resolves: rhbz#1331309 - Label /run/haproxy.sock socket as haproxy_var_run_t Resolves: rhbz#1386233 - Allow oddjob_mkhomedir_t to mamange autofs_t dirs. Resolves: rhbz#1408819 - Allow tomcat to connect on http_cache_port_t Resolves: rhbz#1432083 - Allow geoclue to send msgs to syslog. Resolves: rhbz#1434286 - Allow condor_master_t domain capability chown. Resolves: rhbz#1277506 - Update mta_filetrans_named_content() interface to allow calling domain create files labeled as etc_aliases_t in dir labeled as etc_mail_t. Resolves: rhbz#1167468 - Allow nova domain search for httpd configuration. Resolves: rhbz#1190761 - Add sys_module capability for drbd Resolves: rhbz#1134883 - Allow user_u users stream connect to dirsrv, Allow sysadm_u and staff_u users to manage dirsrv files Resolves: rhbz#1286474 - Allow systemd_networkd_t communicate with systemd_networkd_t via dbus Resolves: rhbz#1278010- Add haproxy_t domain fowner capability Resolves: rhbz#1386233 - Allow domain transition from ntpd_t to hwclock_t domains Resolves: rhbz#1375624 - Allow cockpit_session_t setrlimit and sys_resource Resolves: rhbz#1402316 - Dontaudit svirt_t read state of libvirtd domain Resolves: rhbz#1426106 - Update httpd and gssproxy modules to reflects latest changes in freeipa Resolves: rhbz#1432115 - Allow iptables read modules_conf_t Resolves: rhbz#1367520- Remove tomcat_t domain from unconfined domains Resolves: rhbz#1432083 - Create new boolean: sanlock_enable_home_dirs() Resolves: rhbz#1432783 - Allow mdadm_t domain to read/write nvme_device_t Resolves: rhbz#1431617 - Remove httpd_user_*_content_t domains from user_home_type attribute. This tighten httpd policy and acces to user data will be more strinct, and also fix mutual influente between httpd_enable_homedirs and httpd_read_user_content Resolves: rhbz#1383621 - Dontaudit domain to create any file in /proc. This is kernel bug. Resolves: rhbz#1412679 - Add interface dev_rw_nvme Resolves: rhbz#1431617- Allow gssproxy to get attributes on all filesystem object types. Resolves: rhbz#1430295 - Allow ganesha to chat with unconfined domains via dbus Resolves: rhbz#1426554 - add the policy required for nextcloud Resolves: rhbz#1425530 - Add nmbd_t capability2 block_suspend Resolves: rhbz#1425357 - Label /var/run/chrony as chronyd_var_run_t Resolves: rhbz#1416015 - Add domain transition from sosreport_t to iptables_t Resolves: rhbz#1359789 - Fix path to /usr/lib64/erlang/erts-5.10.4/bin/epmd Resolves: rhbz:#1332803- Update rpm macros Resolves: rhbz#1380854- Add handling booleans via selinux-policy macros in custom policy spec files. Resolves: rhbz#1380854- Allow openvswitch to load kernel modules Resolves: rhbz#1405479- Allow openvswitch read script state. Resolves: rhbz#1405479- Update ganesha policy Resolves: rhbz#1426554 Resolves: rhbz#1383784 - Allow chronyd to read adjtime Resolves: rhbz#1416015 - Fixes for chrony version 2.2 Resolves: rhbz#1416015 - Add interface virt_rw_stream_sockets_svirt() Resolves: rhbz#1415841 - Label /dev/ss0 as gpfs_device_t Resolves: rhbz#1383784 - Allow staff to rw svirt unix stream sockets. Resolves: rhbz#1415841 - Label /rhev/data-center/mnt as mnt_t Resolves: rhbz#1408275 - Associate sysctl_rpc_t with proc filesystems Resolves: rhbz#1350927 - Add new boolean: domain_can_write_kmsg Resolves: rhbz#1415715- Allow rhsmcertd_t dbus chat with system_cronjob_t Resolves: rhbz#1405341 - Allow openvswitch exec hostname and readinitrc_t files Resolves: rhbz#1405479 - Improve SELinux context for mysql_db_t objects. Resolves: rhbz#1391521 - Allow postfix_postdrop to communicate with postfix_master via pipe. Resolves: rhbz#1379736 - Add radius_use_jit boolean Resolves: rhbz#1426205 - Label /var/lock/subsys/iptables as iptables_lock_t Resolves: rhbz#1405441 - Label /usr/lib64/erlang/erts-5.10.4/bin/epmd as lib_t Resolves: rhbz#1332803 - Allow can_load_kernmodule to load kernel modules. Resolves: rhbz#1423427 Resolves: rhbz#1424621- Allow nfsd_t domain to create sysctls_rpc_t files Resolves: rhbz#1405304 - Allow openvswitch to create netlink generic sockets. Resolves: rhbz#1397974 - Create kernel_create_rpc_sysctls() interface Resolves: rhbz#1405304- Allow nfsd_t domain rw sysctl_rpc_t dirs Resolves: rhbz#1405304 - Allow cgdcbxd_t to manage cgroup files. Resolves: rhbz#1358493 - Allow cmirrord_t domain to create netlink_connector sockets Resolves: rhbz#1412670 - Allow fcoemon to create netlink scsitransport sockets Resolves: rhbz#1362496 - Allow quota_nld_t create netlink_generic sockets Resolves: rhbz#1358679 - Allow cgred_t create netlink_connector sockets Resolves: rhbz#1376357 - Add dhcpd_t domain fowner capability Resolves: rhbz#1358485 - Allow acpid to attempt to connect to the Linux kernel via generic netlink socket. Resolves: rhbz#1358478 - Rename docker module to container module Resolves: rhbz#1386916 - Allow setflies to mount tracefs Resolves: rhbz#1376357 - Allow iptables to read nsfs files. Resolves: rhbz#1411316 - Allow systemd_bootchart_t domain create dgram sockets. Resolves: rhbz#1365953 - Rename docker interfaces to container Resolves: rhbz#1386916- Allow initrc_t domain to run rhel-autorelabel script properly during boot process Resolves: rhbz#1379722 - Allow systemd_initctl_t to create and connect unix_dgram sockets Resolves: rhbz#1365947 - Allow ifconfig_t to mount/unmount nsfs_t filesystem Resolves: rhbz#1349814 - Add interfaces allowing mount/unmount nsfs_t filesystem Resolves: rhbz#1349814- Add interface init_stream_connectto() Resolves:rhbz#1365947 - Allow rhsmcertd domain signull kernel. Resolves: rhbz#1379781 - Allow kdumpgui domain to read nvme device - Allow insmod_t to load kernel modules Resolves: rhbz#1421598 - Add interface files_load_kernel_modules() Resolves: rhbz#1421598 - Add SELinux support for systemd-initctl daemon Resolves:rhbz#1365947 - Add SELinux support for systemd-bootchart Resolves: rhbz#1365953- Allow firewalld to getattr open search read modules_object_t:dir Resolves: rhbz#1418391 - Fix label for nagios plugins in nagios file conxtext file Resolves: rhbz#1277718 - Add sys_ptrace capability to pegasus domain Resolves: rhbz#1381238 - Allow sssd_t domain setpgid Resolves:rhbz#1416780 - After the latest changes in nfsd. We should allow nfsd_t to read raw fixed disk. Resolves: rhbz#1350927 - Allow kdumpgui domain to read nvme device Resolves: rhbz#1415084 - su using libselinux and creating netlink_selinux socket is needed to allow libselinux initialization. Resolves: rhbz#1146987 - Add user namespace capability object classes. Resolves: rhbz#1368057 - Add module_load permission to class system Resolves:rhbz#1368057 - Add the validate_trans access vector to the security class Resolves: rhbz#1368057 - Add "binder" security class and access vectors Resolves: rhbz#1368057 - Allow ifconfig_t domain read nsfs_t Resolves: rhbz#1349814 - Allow ping_t domain to load kernel modules. Resolves: rhbz#1388363- Allow systemd container to read/write usermodehelperstate Resolves: rhbz#1403254 - Label udp ports in range 24007-24027 as gluster_port_t Resolves: rhbz#1404152- Allow glusterd_t to bind on glusterd_port_t udp ports. Resolves: rhbz#1404152 - Revert: Allow glusterd_t to bind on med_tlp port.- Allow glusterd_t to bind on med_tlp port. Resolves: rhbz#1404152 - Update ctdbd_t policy to reflect all changes. Resolves: rhbz#1402451 - Label tcp port 24009 as med_tlp_port_t Resolves: rhbz#1404152 - Issue appears during update directly from RHEL-7.0 to RHEL-7.3 or above. Modules pkcsslotd and vbetools missing in selinux-policy package for RHEL-7.3 which causing warnings during SELinux policy store migration process. Following patch fixes issue by skipping pkcsslotd and vbetools modules migration.- Allow ctdbd_t domain transition to rpcd_t Resolves:rhbz#1402451- Fixes for containers Allow containers to attempt to write to unix_sysctls. Allow cotainers to use the FD's leaked to them from parent processes. Resolves: rhbz#1403254- Allow glusterd_t send signals to userdomain. Label new glusterd binaries as glusterd_exec_t Resolves: rhbz#1404152 - Allow systemd to stop glusterd_t domains. Resolves: rhbz#1400493- Make working CTDB:NFS: CTDB failover from selinux-policy POV Resolves: rhbz#1402451- Add kdump_t domain sys_admin capability Resolves: rhbz#1375963- Allow puppetagent_t to access timedated dbus. Use the systemd_dbus_chat_timedated interface to allow puppetagent_t the access. Resolves: rhbz#1399250- Update systemd on RHEL-7.2 box to version from RHEL-7.3 and then as a separate yum command update the selinux policy systemd will start generating USER_AVC denials and will start returning "Access Denied" errors to DBus clients Resolves: rhbz#1393505- Allow cluster_t communicate to fprintd_t via dbus Resolves: rhbz#1349798- Fix error message during update from RHEL-7.2 to RHEL-7.3, when /usr/sbin/semanage command is not installed and selinux-policy-migrate-local-changes.sh script is executed in %post install phase of selinux-policy package Resolves: rhbz#1392010- Allow GlusterFS with RDMA transport to be started correctly. It requires ipc_lock capability together with rw permission on rdma_cm device. Resolves: rhbz#1384488 - Allow glusterd to get attributes on /sys/kernel/config directory. Resolves: rhbz#1384483- Use selinux-policy-migrate-local-changes.sh instead of migrateStore* macros - Add selinux-policy-migrate-local-changes service Resolves: rhbz#1381588- Allow sssd_selinux_manager_t to manage also dir class. Resolves: rhbz#1368097 - Add interface seutil_manage_default_contexts_dirs() Resolves: rhbz#1368097- Add virt_sandbox_use_nfs -> virt_use_nfs boolean substitution. Resolves: rhbz#1355783- Allow pcp_pmcd_t domain transition to lvm_t Add capability kill and sys_ptrace to pcp_pmlogger_t Resolves: rhbz#1309883- Allow ftp daemon to manage apache_user_content Resolves: rhbz#1097775 - Label /etc/sysconfig/oracleasm as oracleasm_conf_t Resolves: rhbz#1331383 - Allow oracleasm to rw inherited fixed disk device Resolves: rhbz#1331383 - Allow collectd to connect on unix_stream_socket Resolves: rhbz#1377259- Allow iscsid create netlink iscsid sockets. Resolves: rhbz#1358266 - Improve regexp for power_unit_file_t files. To catch just systemd power unit files. Resolves: rhbz#1375462- Update oracleasm SELinux module that can manage oracleasmfs_t blk files. Add dac_override cap to oracleasm_t domain. Resolves: rhbz#1331383 - Add few rules to pcp SELinux module to make ti able to start pcp_pmlogger service Resolves: rhbz#1206525- Add oracleasm_conf_t type and allow oracleasm_t to create /dev/oracleasm Resolves: rhbz#1331383 - Label /usr/share/pcp/lib/pmie as pmie_exec_t and /usr/share/pcp/lib/pmlogger as pmlogger_exec_t Resolves: rhbz#1206525 - Allow mdadm_t to getattr all device nodes Resolves: rhbz#1365171 - Add interface dbus_dontaudit_stream_connect_system_dbusd() Resolves:rhbz#1052880 - Add virt_stub_* interfaces for docker policy which is no longer a part of our base policy. Resolves: rhbz#1372705 - Allow guest-set-user-passwd to set users password. Resolves: rhbz#1369693 - Allow samdbox domains to use msg class Resolves: rhbz#1372677 - Allow domains using kerberos to read also kerberos config dirs Resolves: rhbz#1368492 - Allow svirt_sandbox_domains to r/w onload sockets Resolves: rhbz#1342930 - Add interface fs_manage_oracleasm() Resolves: rhbz#1331383 - Label /dev/kfd as hsa_device_t Resolves: rhbz#1373488 - Update seutil_manage_file_contexts() interface that caller domain can also manage file_context_t dirs Resolves: rhbz#1368097 - Add interface to write to nsfs inodes Resolves: rhbz#1372705 - Allow systemd services to use PrivateNetwork feature Resolves: rhbz#1372705 - Add a type and genfscon for nsfs. Resolves: rhbz#1372705 - Allow run sulogin_t in range mls_systemlow-mls_systemhigh. Resolves: rhbz#1290400- Allow arpwatch to create netlink netfilter sockets. Resolves: rhbz#1358261 - Fix file context for /etc/pki/pki-tomcat/ca/ - new interface oddjob_mkhomedir_entrypoint() - Move label for /var/lib/docker/vfs/ to proper SELinux module - Allow mdadm to get attributes from all devices. - Label /etc/puppetlabs as puppet_etc_t. - Allow systemd-machined to communicate to lxc container using dbus - Allow systemd_resolved to send dbus msgs to userdomains Resolves: rhbz#1236579 - Allow systemd-resolved to read network sysctls Resolves: rhbz#1236579 - Allow systemd_resolved to connect on system bus. Resolves: rhbz#1236579 - Make entrypoint oddjob_mkhomedir_exec_t for unconfined_t - Label all files in /dev/oracleasmfs/ as oracleasmfs_t Resolves: rhbz#1331383- Label /etc/pki/pki-tomcat/ca/ as pki_tomcat_cert_t Resolves:rhbz#1366915 - Allow certmonger to manage all systemd unit files Resolves:rhbz#1366915 - Grant certmonger "chown" capability Resolves:rhbz#1366915 - Allow ipa_helper_t stream connect to dirsrv_t domain Resolves: rhbz#1368418 - Update oracleasm SELinux module Resolves: rhbz#1331383 - label /var/lib/kubelet as svirt_sandbox_file_t Resolves: rhbz#1369159 - Add few interfaces to cloudform.if file Resolves: rhbz#1367834 - Label /var/run/corosync-qnetd and /var/run/corosync-qdevice as cluster_var_run_t. Note: corosync policy is now par of rhcs module Resolves: rhbz#1347514 - Allow krb5kdc_t to read krb4kdc_conf_t dirs. Resolves: rhbz#1368492 - Update networkmanager_filetrans_named_content() interface to allow source domain to create also temad dir in /var/run. Resolves: rhbz#1365653 - Allow teamd running as NetworkManager_t to access netlink_generic_socket to allow multiple network interfaces to be teamed together. Resolves: rhbz#1365653 - Label /dev/oracleasmfs as oracleasmfs_t. Add few interfaces related to oracleasmfs_t type Resolves: rhbz#1331383 - A new version of cloud-init that supports the effort to provision RHEL Atomic on Microsoft Azure requires some a new rules that allows dhclient/dhclient hooks to call cloud-init. Resolves: rhbz#1367834 - Allow iptables to creating netlink generic sockets. Resolves: rhbz#1364359- Allow ipmievd domain to create lock files in /var/lock/subsys/ Resolves:rhbz#1349058 - Update policy for ipmievd daemon. Resolves:rhbz#1349058 - Dontaudit hyperkvp to getattr on non security files. Resolves: rhbz#1349356 - Label /run/corosync-qdevice and /run/corosync-qnetd as corosync_var_run_t Resolves: rhbz#1347514 - Fixed lsm SELinux module - Add sys_admin capability to sbd domain Resolves: rhbz#1322725 - Allow vdagent to comunnicate with systemd-logind via dbus Resolves: rhbz#1366731 - Allow lsmd_plugin_t domain to create fixed_disk device. Resolves: rhbz#1238066 - Allow opendnssec domain to create and manage own tmp dirs/files Resolves: rhbz#1366649 - Allow opendnssec domain to read system state Resolves: rhbz#1366649 - Update opendnssec_manage_config() interface to allow caller domain also manage opendnssec_conf_t dirs Resolves: rhbz#1366649 - Allow rasdaemon to mount/unmount tracefs filesystem. Resolves: rhbz#1364380 - Label /usr/libexec/iptables/iptables.init as iptables_exec_t Allow iptables creating lock file in /var/lock/subsys/ Resolves: rhbz#1367520 - Modify interface den_read_nvme() to allow also read nvme_device_t block files. Resolves: rhbz#1362564 - Label /var/run/storaged as lvm_var_run_t. Resolves: rhbz#1264390 - Allow unconfineduser to run ipa_helper_t. Resolves: rhbz#1361636- Dontaudit mock to write to generic certs. Resolves: rhbz#1271209 - Add labeling for corosync-qdevice and corosync-qnetd daemons, to run as cluster_t Resolves: rhbz#1347514 - Revert "Label corosync-qnetd and corosync-qdevice as corosync_t domain" - Allow modemmanager to write to systemd inhibit pipes Resolves: rhbz#1365214 - Label corosync-qnetd and corosync-qdevice as corosync_t domain Resolves: rhbz#1347514 - Allow ipa_helper to read network state Resolves: rhbz#1361636 - Label oddjob_reqiest as oddjob_exec_t Resolves: rhbz#1361636 - Add interface oddjob_run() Resolves: rhbz#1361636 - Allow modemmanager chat with systemd_logind via dbus Resolves: rhbz#1362273 - Allow NetworkManager chat with puppetagent via dbus Resolves: rhbz#1363989 - Allow NetworkManager chat with kdumpctl via dbus Resolves: rhbz#1363977 - Allow sbd send msgs to syslog Allow sbd create dgram sockets. Allow sbd to communicate with kernel via dgram socket Allow sbd r/w kernel sysctls. Resolves: rhbz#1322725 - Allow ipmievd_t domain to re-create ipmi devices Label /usr/libexec/openipmi-helper as ipmievd_exec_t Resolves: rhbz#1349058 - Allow rasdaemon to use tracefs filesystem. Resolves: rhbz#1364380 - Fix typo bug in dirsrv policy - Some logrotate scripts run su and then su runs unix_chkpwd. Allow logrotate_t domain to check passwd. Resolves: rhbz#1283134 - Add ipc_lock capability to sssd domain. Allow sssd connect to http_cache_t Resolves: rhbz#1362688 - Allow dirsrv to read dirsrv_share_t content Resolves: rhbz#1363662 - Allow virtlogd_t to append svirt_image_t files. Resolves: rhbz#1358140 - Allow hypervkvp domain to read hugetlbfs dir/files. Resolves: rhbz#1349356 - Allow mdadm daemon to read nvme_device_t blk files Resolves: rhbz#1362564 - Allow selinuxusers and unconfineduser to run oddjob_request Resolves: rhbz#1361636 - Allow sshd server to acces to Crypto Express 4 (CEX4) devices. Resolves: rhbz#1362539 - Fix labeling issue in init.fc file. Path /usr/lib/systemd/fedora-* changed to /usr/lib/systemd/rhel-*. Resolves: rhbz#1363769 - Fix typo in device interfaces Resolves: rhbz#1349058 - Add interfaces for managing ipmi devices Resolves: rhbz#1349058 - Add interfaces to allow mounting/umounting tracefs filesystem Resolves: rhbz#1364380 - Add interfaces to allow rw tracefs filesystem Resolves: rhbz#1364380 - Add interface dev_read_nvme() to allow reading Non-Volatile Memory Host Controller devices. Resolves: rhbz#1362564 - Label /sys/kernel/debug/tracing filesystem Resolves: rhbz#1364380 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857- Dontaudit mock_build_t can list all ptys. Resolves: rhbz#1271209 - Allow ftpd_t to mamange userhome data without any boolean. Resolves: rhbz#1097775 - Add logrotate permissions for creating netlink selinux sockets. Resolves: rhbz#1283134 - Allow lsmd_plugin_t to exec ldconfig. Resolves: rhbz#1238066 - Allow vnstatd domain to read /sys/class/net/ files Resolves: rhbz#1358243 - Remove duplicate allow rules in spamassassin SELinux module Resolves:rhbz#1358175 - Allow spamc_t and spamd_t domains create .spamassassin file in user homedirs Resolves:rhbz#1358175 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857 - Add new MLS attribute to allow relabeling objects higher than system low. This exception is needed for package managers when processing sensitive data. Resolves: rhbz#1330464 - Allow gnome-keyring also manage user_tmp_t sockets. Resolves: rhbz#1257057 - corecmd: Remove fcontext for /etc/sysconfig/libvirtd Resolves:rhbz#1351382- Allow ipa_dnskey domain to search cache dirs Resolves: rhbz#1350957- Allow ipa-dnskey read system state. Reasolves: rhbz#1350957 - Allow dogtag-ipa-ca-renew-agent-submit labeled as certmonger_t to create /var/log/ipa/renew.log file Resolves: rhbz#1350957- Allow firewalld to manage net_conf_t files. Resolves:rhbz#1304723 - Allow logrotate read logs inside containers. Resolves: rhbz#1303514 - Allow sssd to getattr on fs_t Resolves: rhbz#1356082 - Allow opendnssec domain to manage bind chace files Resolves: rhbz#1350957 - Fix typo in rhsmcertd policy module Resolves: rhbz#1329475 - Allow systemd to get status of systemd-logind daemon Resolves: rhbz#1356141 - Label more ndctl devices not just ndctl0 Resolves: rhbz#1355809- Allow rhsmcertd to copy certs into /etc/docker/cert.d - Add interface docker_rw_config() Resolves: rhbz#1344500 - Fix logrotate fc file to label also /var/lib/logrotate/ dir as logrotate_var_lib_t Resolves: rhbz#1355632 - Allow rhsmcertd to read network sysctls Resolves: rhbz#1329475 - Label /var/log/graphite-web dir as httpd_log_t Resolves: rhbz#1310898 - Allow mock to use generic ptys Resolves: rhbz#1271209 - Allow adcli running as sssd_t to write krb5.keytab file. Resolves: rhbz#1356082 - Allow openvswitch connect to openvswitch_port_t type. Resolves: rhbz#1335024 - Add SELinux policy for opendnssec service. Resolves: rhbz#1350957 - Create new SELinux type for /usr/libexec/ipa/ipa-dnskeysyncd Resolves: rhbz#1350957 - label /dev/ndctl0 device as nvram_device_t Resolves: rhbz#1355809- Allow lttng tools to block suspending Resolves: rhbz#1256374 - Allow creation of vpnaas in openstack Resolves: rhbz#1352710 - virt: add strict policy for virtlogd daemon Resolves:rhbz#1311606 - Update makefile to support snapperd_contexts file Resolves: rhbz#1352681- Allow udev to manage systemd-hwdb files - Add interface systemd_hwdb_manage_config() Resolves: rhbz#1350756 - Fix paths to infiniband devices. This allows use more then two infiniband interfaces. Resolves: rhbz#1210263- Allow virtual machines to rw infiniband devices. Resolves: rhbz#1210263 - Allow opensm daemon to rw infiniband_mgmt_device_t Resolves: rhbz#1210263 - Allow systemd_hwdb_t to relabel /etc/udev/hwdb.bin file. Resolves: rhbz#1350756 - Make label for new infiniband_mgmt deivices Resolves: rhbz#1210263- Fix typo in brltty SELinux module - Add new SELinux module sbd Resolves: rhbz#1322725 - Allow pcp dmcache metrics collection Resolves: rhbz#1309883 - Allow pkcs_slotd_t to create dir in /var/lock Add label pkcs_slotd_log_t Resolves: rhbz#1350782 - Allow openvpn to create sock files labeled as openvpn_var_run_t Resolves: rhbz#1328246 - Allow hypervkvp daemon to getattr on all filesystem types. Resolves: rhbz#1349356 - Allow firewalld to create net_conf_t files Resolves: rhbz#1304723 - Allow mock to use lvm Resolves: rhbz#1271209 - Allow keepalived to create netlink generic sockets. Resolves: rhbz#1349809 - Allow mirromanager creating log files in /tmp Resolves:rhbz#1328818 - Rename few modules to make it consistent with source files Resolves: rhbz#1351445 - Allow vmtools_t to transition to rpm_script domain Resolves: rhbz#1342119 - Allow nsd daemon to manage nsd_conf_t dirs and files Resolves: rhbz#1349791 - Allow cluster to create dirs in /var/run labeled as cluster_var_run_t Resolves: rhbz#1346900 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535 - Dontaudit su_role_template interface to getattr /proc/kcore Dontaudit su_role_template interface to getattr /dev/initctl Resolves: rhbz#1086240 - Add interface lvm_getattr_exec_files() Resolves: rhbz#1271209 - Fix typo Compliling vs. Compiling Resolves: rhbz#1351445- Allow krb5kdc_t to communicate with sssd Resolves: rhbz#1319933 - Allow prosody to bind on prosody ports Resolves: rhbz#1304664 - Add dac_override caps for fail2ban-client Resolves: rhbz#1316678 - dontaudit read access for svirt_t on the file /var/db/nscd/group Resolves: rhbz#1301637 - Allow inetd child process to communicate via dbus with systemd-logind Resolves: rhbz#1333726 - Add label for brltty log file Resolves: rhbz#1328818 - Allow dspam to read the passwd file Resolves: rhbz#1286020 - Allow snort_t to communicate with sssd Resolves: rhbz#1284908 - svirt_sandbox_domains need to be able to execmod for badly built libraries. Resolves: rhbz#1206339 - Add policy for lttng-tools package. Resolves: rhbz#1256374 - Make mirrormanager as application domain. Resolves: rhbz#1328234 - Add support for the default lttng-sessiond port - tcp/5345. This port is used by LTTng 2.x central tracing registry session daemon. - Add prosody ports Resolves: rhbz#1304664 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535- Label /var/lib/softhsm as named_cache_t. Allow named_t to manage named_cache_t dirs. Resolves:rhbz#1331315 - Label named-pkcs11 binary as named_exec_t. Resolves: rhbz#1331315 - Allow glusterd daemon to get systemd status Resolves: rhbz#1321785 - Allow logrotate dbus-chat with system_logind daemon Resolves: rhbz#1283134 - Allow pcp_pmlogger to read kernel network state Allow pcp_pmcd to read cron pid files Resolves: rhbz#1336211 - Add interface cron_read_pid_files() Resolves: rhbz#1336211 - Allow pcp_pmlogger to create unix dgram sockets Resolves: rhbz#1336211 - Add hwloc-dump-hwdata SELinux policy Resolves: rhbz#1344054 - Remove non-existing jabberd_spool_t() interface and add new jabbertd_var_spool_t. Resolves: rhbz#1121171 - Remove non-existing interface salk_resetd_systemctl() and replace it with sanlock_systemctl_sanlk_resetd() Resolves: rhbz#1259764 - Create label for openhpid log files. esolves: rhbz#1259764 - Label /var/lib/ganglia as httpd_var_lib_t Resolves: rhbz#1260536 - Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Include patch from distgit repo: policy-RHEL-7.1-flask.patch. Resolves: rhbz#1329560 - Update refpolicy to handle hwloc Resolves: rhbz#1344054 - Label /etc/dhcp/scripts dir as bin_t - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255- Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Allow mongod log to syslog. Resolves: rhbz#1306995 - Allow rhsmcertd connect to port tcp 9090 Resolves: rhbz#1337319 - Label for /bin/mail(x) was removed but /usr/bin/mail(x) not. This path is also needed to remove. Resolves: rhbz#1262483 Resolves: rhbz#1277506 - Label /usr/libexec/mimedefang-wrapper as spamd_exec_t. Resolves: rhbz#1301516 - Add new boolean spamd_update_can_network. Resolves: rhbz#1305469 - Allow rhsmcertd connect to tcp netport_port_t Resolves: rhbz#1329475 - Fix SELinux context for /usr/share/mirrormanager/server/mirrormanager to Label all binaries under dir as mirrormanager_exec_t. Resolves: rhbz#1328234 - Allow prosody to bind to fac_restore tcp port. Resolves: rhbz#1321787 - Allow ninfod to read raw packets Resolves: rhbz#1317964 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1260835 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1271159 - Allow tuned to use policykit. This change is required by cockpit. Resolves: rhbz#1346464 - Allow conman_t to read dir with conman_unconfined_script_t binary files. Resolves: rhbz#1297323 - Allow pegasus to read /proc/sysinfo. Resolves: rhbz#1265883 - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255 - Label tcp ports:16379, 26379 as redis_port_t Resolves: rhbz#1348471 - Allow systemd to relabel /var and /var/lib directories during boot. - Add files_relabel_var_dirs() and files_relabel_var_dirs() interfaces. - Add files_relabelto_var_lib_dirs() interface. - Label tcp port 2004 as mailbox_port_t. Resolves: rhbz#1332843 - Label tcp and udp port 5582 as fac_restore_port_t Resolves: rhbz#1321787 - Allow sysadm_t user to run postgresql-setup. Resolves: rhbz#1282543 - Allow sysadm_t user to dbus chat with oddjob_t. This allows confined admin run oddjob mkhomedirfor script. Resolves: rhbz#1297480 - Update netlink socket classes.- Allow conman to kill conman_unconfined_script. Resolves: rhbz#1297323 - Make conman_unconfined_script_t as init_system_domain. Resolves:rhbz#1297323 - Allow init dbus chat with apmd. Resolves:rhbz#995898 - Patch /var/lib/rpm is symlink to /usr/share/rpm on Atomic, due to this change we need to label also /usr/share/rpm as rpm_var_lib_t. Resolves: rhbz#1233252 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Add mediawiki rules to proper scope Resolves: rhbz#1301186 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Allow mysqld_safe to inherit rlimit information from mysqld Resolves: rhbz#1323673 - Allow collectd_t to stream connect to postgresql. Resolves: rhbz#1344056 - Allow mediawiki-script to read /etc/passwd file. Resolves: rhbz#1301186 - Add filetrans rule that NetworkManager_t can create net_conf_t files in /etc. Resolves: rhbz#1344505 - Add labels for mediawiki123 Resolves: rhbz#1293872 - Fix label for all fence_scsi_check scripts - Allow ip netns to mounton root fs and unmount proc_t fs. Resolves: rhbz#1343776 Resolves: rhbz#1286851 - Allow sysadm_t to run newaliases command. Resolves: rhbz#1344828 - Add interface sysnet_filetrans_named_net_conf() Resolves: rhbz#1344505- Fix several issues related to the SELinux Userspace changes- Allow glusterd domain read krb5_keytab_t files. Resolves: rhbz#1343929 - Fix typo in files_setattr_non_security_dirs. Resolves: rhbz#1115987- Allow tmpreaper_t to read/setattr all non_security_file_type dirs Resolves: rhbz#1115987 - Allow firewalld to create firewalld_var_run_t directory. Resolves: rhbz#1304723 - Add interface firewalld_read_pid_files() Resolves: rhbz#1304723 - Label /usr/libexec/rpm-ostreed as rpm_exec_t. Resolves: rhbz#1340542 - Allow sanlock service to read/write cephfs_t files. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - Add interface files_setattr_non_security_dirs() Resolves: rhbz#1115987 - Add support for onloadfs - Allow iptables to read firewalld pid files. Resolves: rhbz#1304723 - Add SELinux support for ceph filesystem. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) Resolves: rhbz#1236580- Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - New interfaces needed for systemd-machinectl Resolves: rhbz#1236580 - New interfaces needed by systemd-machine Resolves: rhbz#1236580 - Add interface allowing sending and receiving messages from virt over dbus. Resolves: rhbz#1236580 - Backport docker policy from Fedora. Related: #1303123 Resolves: #1341257 - Allow NetworkManager_t and policykit_t read access to systemd-machined pid files. Resolves: rhbz#1236580 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added interfaces needed by new docker policy. Related: rhbz#1303123 - Add support for systemd-machined daemon Resolves: rhbz#1236580 - Allow rpm-ostree domain transition to install_t domain from init_t. Resolves: rhbz#1340542- dnsmasq: allow NetworkManager to control dnsmasq via D-Bus Resolves: rhbz#1336722 - Directory Server (389-ds-base) has been updated to use systemd-ask-password. In order to function correctly we need the following added to dirsrv.te Resolves: rhbz#1333198 - sftpd_* booleans are functionless these days. Resolves: rhbz#1335656 - Label /var/log/ganesha.log as gluster_log_t Allow glusterd_t domain to create glusterd_log_t files. Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737 - Label /usr/libexec/storaged/storaged as lvm_exec_t to run storaged daemon in lvm_t SELinux domain. Resolves: rhbz#1264390 - Allow systemd_hostanmed_t to read /proc/sysinfo labeled as sysctl_t. Resolves: rhbz#1337061 - Revert "Allow all domains some process flags." Resolves: rhbz#1303644 - Revert "Remove setrlimit to all domains." Resolves: rhbz#1303644 - Label /usr/sbin/xrdp* files as bin_t Resolves: rhbz#1276777 - Add mls support for some db classes Resolves: rhbz#1303651 - Allow systemd_resolved_t to check if ipv6 is disabled. Resolves: rhbz#1236579 - Allow systemd_resolved to read systemd_networkd run files. Resolves: rhbz#1236579- Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737- Allow logwatch to domtrans to postqueue Resolves: rhbz#1331542 - Label /var/log/ganesha.log as gluster_log_t - Allow glusterd_t domain to create glusterd_log_t files. - Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow zabbix to connect to postgresql port Resolves: rhbz#1330479 - Add userdom_destroy_unpriv_user_shared_mem() interface. Related: rhbz#1306403 - systemd-logind remove all IPC objects owned by a user on a logout. This covers also SysV memory. This change allows to destroy unpriviledged user SysV shared memory segments. Resolves: rhbz#1306403- We need to restore contexts on /etc/passwd*,/etc/group*,/etc/*shadow* during install phase to get proper labeling for these files until selinux-policy pkgs are installed. Resolves: rhbz#1333952- Add interface glusterd_dontaudit_read_lib_dirs() Resolves: rhbz#1295680 - Dontaudit Occasionally observing AVC's while running geo-rep automation Resolves: rhbz#1295680 - Allow glusterd to manage socket files labeled as glusterd_brick_t. Resolves: rhbz#1331561 - Create new apache content template for files stored in user homedir. This change is needed to make working booleans: - httpd_enable_homedirs - httpd_read_user_content Resolves: rhbz#1246522 - Allow stunnel create log files. Resolves: rhbz#1296851 - Label tcp port 8181 as intermapper_port_t. Resolves: rhbz#1334783 - Label tcp/udp port 2024 as xinuexpansion4_port_t Resolves: rhbz#1334783 - Label tcp port 7002 as afs_pt_port_t Label tcp/udp port 2023 as xinuexpansion3_port_t Resolves: rhbz#1334783 - Dontaudit ldconfig read gluster lib files. Resolves: rhbz#1295680 - Add interface auth_use_nsswitch() to systemd_domain_template. Resolves: rhbz#1236579- Label /usr/bin/ganesha.nfsd as glusterd_exec_t to run ganesha as glusterd_t. Allow glusterd_t stream connect to rpbind_t. Allow cluster_t to create symlink /var/lib/nfs labeled as var_lib_nfs_t. Add interface rpc_filetrans_var_lib_nfs_content() Add new boolean: rpcd_use_fusefs to allow rpcd daemon use fusefs. Resolves: rhbz#1312809 Resolves: rhbz#1323947 - Allow dbus chat between httpd_t and oddjob_t. Resolves: rhbz#1324144 - Label /usr/libexec/ipa/oddjob/org.freeipa.server.conncheck as ipa_helper_exec_t. Resolves: rhbz#1324144 - Label /var/log/ipareplica-conncheck.log file as ipa_log_t Allow ipa_helper_t domain to manage logs labeledas ipa_log_t Allow ipa_helper_t to connect on http and kerberos_passwd ports. Resolves: rhbz#1324144 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow pcp_pmcd_t domain to manage docker lib files. This rule is needed to allow pcp to collect container information when SELinux is enabled. Resolves: rhbz#1309454- Allow runnig php7 in fpm mode. From selinux-policy side, we need to allow httpd to read/write hugetlbfs. Resolves: rhbz#1319442 - Allow openvswitch daemons to run under openvswitch Linux user instead of root. This change needs allow set capabilities: chwon, setgid, setuid, setpcap. Resolves: rhbz#1296640 - Remove ftpd_home_dir() boolean from distro policy. Reason is that we cannot make this working due to m4 macro language limits. Resolves: rhbz#1097775 - /bin/mailx is labeled sendmail_exec_t, and enters the sendmail_t domain on execution. If /usr/sbin/sendmail does not have its own domain to transition to, and is not one of several products whose behavior is allowed by the sendmail_t policy, execution will fail. In this case we need to label /bin/mailx as bin_t. Resolves: rhbz#1262483 - Allow nsd daemon to create log file in /var/log as nsd_log_t Resolves: rhbz#1293140 - Sanlock policy update. - New sub-domain for sanlk-reset daemon Resolves: rhbz#1212324 - Label all run tgtd files, not just socket files Resolves: rhbz#1280280 - Label all run tgtd files, not just socket files. Resolves: rhbz#1280280 - Allow prosody to stream connect to sasl. This will allow using cyrus authentication in prosody. Resolves: rhbz#1321049 - unbound wants to use ephemeral ports as a default configuration. Allow to use also udp sockets. Resolves: rhbz#1318224 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow targetd to read/write to /dev/mapper/control device. Resolves: rhbz#1063714 - Allow KDM to get status about power services. This change allow kdm to be able do shutdown. Resolves: rhbz#1316724 - Allow systemd-resolved daemon creating netlink_route sockets. Resolves:rhbz#1236579 - Allow systemd_resolved_t to read /etc/passwd file. Allow systemd_resolved_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used Resolves: rhbz#1065362 - Label /etc/selinux/(minimum|mls|targeted)/active/ as semanage_store_t Resolves: rhbz#1321943 - Label all nvidia binaries as xserver_exec_t Resolves: rhbz#1322283- Create new permissivedomains CIL module and make it active. Resolves: rhbz#1320451 - Add support for new mock location - /usr/libexec/mock/mock. Resolves: rhbz#1271209 - Allow bitlee to create bitlee_var_t dirs. Resolves: rhbz#1268651 - Allow CIM provider to read sssd public files. Resolves: rhbz#1263339 - Fix some broken interfaces in distro policy. Resolves: rhbz#1121171 - Allow power button to shutdown the laptop. Resolves: rhbz#995898 - Allow lsm plugins to create named fixed disks. Resolves: rhbz#1238066 - Add default labeling for /etc/Pegasus/cimserver_current.conf. It is a correct patch instead of the current /etc/Pegasus/pegasus_current.confResolves: rhbz#1278777 - Allow hyperv domains to rw hyperv devices. Resolves: rhbz#1309361 - Label /var/www/html(/.*)?/wp_backups(/.*)? as httpd_sys_rw_content_t.Resolves: rhbz#1246780 - Create conman_unconfined_script_t type for conman script stored in /use/share/conman/exec/ Resolves: rhbz#1297323 - Fix rule definitions for httpd_can_sendmail boolean. We need to distinguish between base and contrib. - Add support for /dev/mptctl device used to check RAID status. Resolves: rhbz#1258029 - Create hyperv* devices and create rw interfaces for this devices. Resolves: rhbz#1309361 - Add fixes for selinux userspace moving the policy store to /var/lib/selinux. - Remove optional else block for dhcp ping- Allow rsync_export_all_ro boolean to read also non_auth_dirs/files/symlinks. Resolves: rhbz#1263770 - Fix context of "/usr/share/nginx/html". Resolves: rhbz#1261857 - Allow pmdaapache labeled as pcp_pmcd_t access to port 80 for apache diagnostics Resolves: rhbz#1270344 - Allow pmlogger to create pmlogger.primary.socket link file. Resolves: rhbz#1270344 - Label nagios scripts as httpd_sys_script_exec_t. Resolves: rhbz#1260306 - Add dontaudit interface for kdumpctl_tmp_t Resolves: rhbz#1156442 - Allow mdadm read files in EFI partition. Resolves: rhbz#1291801 - Allow nsd_t to bind on nsf_control tcp port. Allow nsd_crond_t to read nsd pid. Resolves: rhbz#1293140 - Label some new nsd binaries as nsd_exec_t Allow nsd domain net_admin cap. Create label nsd_tmp_t for nsd tmp files/dirs Resolves: rhbz#1293140 - Add filename transition that /etc/princap will be created with cupsd_rw_etc_t label in cups_filetrans_named_content() interface. Resolves: rhbz#1265102 - Add missing labeling for /usr/libexec/abrt-hook-ccpp. Resolves: rhbz#1213409 - Allow pcp_pmie and pcp_pmlogger to read all domains state. Resolves: rhbz#1206525 - Label /etc/redis-sentinel.conf as redis_conf_t. Allow redis_t write to redis_conf_t. Allow redis_t to connect on redis tcp port. Resolves: rhbz#1275246 - cockpit has grown content in /var/run directory Resolves: rhbz#1279429 - Allow collectd setgid capability Resolves:#1310898 - Remove declaration of empty booleans in virt policy. Resolves: rhbz#1103153 - Fix typo in drbd policy - Add new drbd file type: drbd_var_run_t. Allow drbd_t to manage drbd_var_run_t files/dirs. Allow drbd_t create drbd_tmp_t files in /tmp. Resolves: rhbz#1134883 - Label /etc/ctdb/events.d/* as ctdb_exec_t. Allow ctdbd_t to setattr on ctdbd_exec_t files. Resolves: rhbz#1293788 - Allow abrt-hook-ccpp to get attributes of all processes because of core_pattern. Resolves: rhbz#1254188 - Allow abrt_t to read sysctl_net_t files. Resolves: rhbz#1254188 - The ABRT coredump handler has code to emulate default core file creation The handler runs in a separate process with abrt_dump_oops_t SELinux process type. abrt-hook-ccpp also saves the core dump file in the very same way as kernel does and a user can specify CWD location for a coredump. abrt-hook-ccpp has been made as a SELinux aware apps to create this coredumps with correct labeling and with this commit the policy rules have been updated to allow access all non security files on a system. - Allow abrt-hook-ccpp to getattr on all executables. - Allow setuid/setgid capabilities for abrt-hook-ccpp. Resolves: rhbz#1254188 - abrt-hook-ccpp needs to have setfscreate access because it is SELinux aware and compute a target labeling. Resolves: rhbz#1254188 - Allow abrt-hook-ccpp to change SELinux user identity for created objects. Resolves: rhbz#1254188 - Dontaudit write access to inherited kdumpctl tmp files. Resolves: rbhz#1156442 - Add interface to allow reading files in efivarfs - contains Linux Kernel configuration options for UEFI systems (UEFI Runtime Variables) Resolves: rhbz#1291801 - Label 8952 tcp port as nsd_control. Resolves: rhbz#1293140 - Allow ipsec to use pam. Resolves: rhbz#1315700 - Allow to log out to gdm after screen was resized in session via vdagent. Resolves: rhbz#1249020 - Allow setrans daemon to read /proc/meminfo. Resolves: rhbz#1316804 - Allow systemd_networkd_t to write kmsg, when kernel was started with following params: systemd.debug systemd.log_level=debug systemd.log_target=kmsg Resolves: rhbz#1298151 - Label tcp port 5355 as llmnr-> Link-Local Multicast Name Resolution Resolves: rhbz#1236579 - Add new selinux policy for systemd-resolved dawmon. Resolves: rhbz#1236579 - Add interface ssh_getattr_server_keys() interface. Resolves: rhbz#1306197 - Allow run sshd-keygen on second boot if first boot fails after some reason and content is not syncedon the disk. These changes are reflecting this commit in sshd. http://pkgs.fedoraproject.org/cgit/rpms/openssh.git/commit/?id=af94f46861844cbd6ba4162115039bebcc8f78ba rhbz#1299106 Resolves: rhbz#1306197 - Allow systemd_notify_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used. Resolves: rhbz#1309417 - Remove bin_t label for /etc/ctdb/events.d/. We need to label this scripts as ctdb_exec_t. Resolves: rhbz#1293788- Prepare selinux-policy package for userspace release 2016-02-23. Resolves: rhbz#1305982- Allow sending dbus msgs between firewalld and system_cronjob domains. Resolves: rhbz#1284902 - Allow zabbix-agentd to connect to following tcp sockets. One of zabbix-agentd functions is get service status of ftp,http,innd,pop,smtp protocols. Resolves: rhbz#1242506 - Add new boolean tmpreaper_use_cifs() to allow tmpreaper to run on local directories being shared with Samba. Resolves: rhbz#1284972 - Add support for systemd-hwdb daemon. Resolves: rhbz#1257940 - Add interface fs_setattr_cifs_dirs(). Resolves: rhbz#1284972- Add new SELinux policy fo targetd daemon. Resolves: rhbz#1063714 - Add new SELinux policy fo ipmievd daemon. Resolves: rhbz#1083031 - Add new SELinux policy fo hsqldb daemon. Resolves: rhbz#1083171 - Add new SELinux policy for blkmapd daemon. Resolves: rhbz#1072997 - Allow p11-child to connect to apache ports. - Label /usr/sbin/lvmlockd binary file as lvm_exec_t. Resolves: rhbz#1278028 - Add interface "lvm_manage_lock" to lvm policy. Resolves: rhbz#1063714- Allow openvswitch domain capability sys_rawio. Resolves: rhbz#1278495- Allow openvswitch to manage hugetlfs files and dirs. Resolves: rhbz#1278495 - Add fs_manage_hugetlbfs_files() interface. Resolves: rhbz#1278495- Allow smbcontrol domain to send sigchld to ctdbd domain. Resolves: #1293784 - Allow openvswitch read/write hugetlb filesystem. Resolves: #1278495Allow hypervvssd to list all mountpoints to have VSS live backup working correctly. Resolves:#1247880- Revert Add missing labeling for /usr/libexec/abrt-hook-ccpp patch Resolves: #1254188- Allow search dirs in sysfs types in kernel_read_security_state. Resolves: #1254188 - Fix kernel_read_security_state interface that source domain of this interface can search sysctl_fs_t dirs. Resolves: #1254188- Add missing labeling for /usr/libexec/abrt-hook-ccpp as a part of #1245477 and #1242467 bugs Resolves: #1254188 - We need allow connect to xserver for all sandbox_x domain because we have one type for all sandbox processes. Resolves:#1261938- Remove labeling for modules_dep_t file contexts to have labeled them as modules_object_t. - Update files_read_kernel_modules() to contain modutils_read_module_deps_files() calling because module deps labeling could remain and it allows to avoid regressions. Resolves:#1266928- We need to require sandbox_web_type attribute in sandbox_x_domain_template(). Resolves: #1261938 - ipsec: The NM helper needs to read the SAs Resolves: #1259786 - ipsec: Allow ipsec management to create ptys Resolves: #1259786- Add temporary fixes for sandbox related to #1103622. It allows to run everything under one sandbox type. Resolves:#1261938 - Allow abrt_t domain to write to kernel msg device. Resolves: #1257828 - Allow rpcbind_t domain to change file owner and group Resolves: #1265266- Allow smbcontrol to create a socket in /var/samba which uses for a communication with smbd, nmbd and winbind. Resolves: #1256459- Allow dirsrv-admin script to read passwd file. Allow dirsrv-admin script to read httpd pid files. Label dirsrv-admin unit file and allow dirsrv-admin domains to use it. Resolves: #1230300 - Allow qpid daemon to connect on amqp tcp port. Resolves: #1261805- Label /etc/ipa/nssdb dir as cert_t Resolves:#1262718 - Do not provide docker policy files which is shipped by docker-selinux.rpm Resolves:#1262812- Add labels for afs binaries: dafileserver, davolserver, salvageserver, dasalvager Resolves: #1192338 - Add lsmd_plugin_t sys_admin capability, Allow lsmd_plugin_t getattr from sysfs filesystem. Resolves: #1238079 - Allow rhsmcertd_t send signull to unconfined_service_t domains. Resolves: #1176078 - Remove file transition from snmp_manage_var_lib_dirs() interface which created snmp_var_lib_t dirs in var_lib_t. - Allow openhpid_t daemon to manage snmp files and dirs. Resolves: #1243902 - Allow mdadm_t domain read/write to general ptys and unallocated ttys. Resolves: #1073314 - Add interface unconfined_server_signull() to allow domains send signull to unconfined_service_t Resolves: #1176078- Allow systemd-udevd to access netlink_route_socket to change names for network interfaces without unconfined.pp module. It affects also MLS. Resolves:#1250456- Fix labeling for fence_scsi_check script Resolves: #1255020 - Allow openhpid to read system state Allow openhpid to connect to tcp http port. Resolves: #1244248 - Allow openhpid to read snmp var lib files. Resolves: #1243902 - Allow openvswitch_t domains read kernel dependencies due to openvswitch run modprobe - Allow unconfined_t domains to create /var/run/xtables.lock with iptables_var_run_t Resolves: #1243403 - Remove bin_t label for /usr/share/cluster/fence_scsi_check\.pl Resolves: #1255020- Fix regexp in chronyd.fc file Resolves: #1243764 - Allow passenger to getattr filesystem xattr Resolves: #1196555 - Label mdadm.conf.anackbak as mdadm_conf_t file. Resolves: #1088904 - Revert "Allow pegasus_openlmi_storage_t create mdadm.conf.anacbak file in /etc." - Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Remove labeling for /var/db/.*\.db as etc_t to label db files as system_db_t. Resolves: #1230877- Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Label /var/run/chrony-helper dir as chronyd_var_run_t. Resolves: #1243764 - Allow dhcpc_t domain transition to chronyd_t Resolves: #1243764- Fix postfix_spool_maildrop_t,postfix_spool_flush_t contexts in postfix.fc file. Resolves: #1252442- Allow exec pidof under hypervkvp domain. Resolves: #1254870 - Allow hypervkvp daemon create connection to the system DBUS Resolves: #1254870- Allow openhpid_t to read system state. Resolves: #1244248 - Added labels for files provided by rh-nginx18 collection Resolves: #1249945 - Dontaudit block_suspend capability for ipa_helper_t, this is kernel bug. Allow ipa_helper_t capability net_admin. Allow ipa_helper_t to list /tmp. Allow ipa_helper_t to read rpm db. Resolves: #1252968 - Allow rhsmcertd exec rhsmcertd_var_run_t files and rhsmcerd_tmp_t files. This rules are in hide_broken_sympthons until we find better solution. Resolves: #1243431 - Allow abrt_dump_oops_t to read proc_security_t files. - Allow abrt_dump_oops to signull all domains Allow abrt_dump_oops to read all domains state Allow abrt_dump_oops to ptrace all domains - Add interface abrt_dump_oops_domtrans() - Add mountpoint dontaudit access check in rhsmcertd policy. Resolves: #1243431 - Allow samba_net_t to manage samba_var_t sock files. Resolves: #1252937 - Allow chrome setcap to itself. Resolves: #1251996 - Allow httpd daemon to manage httpd_var_lib_t lnk_files. Resolves: #1253706 - Allow chronyd exec systemctl Resolves: #1243764 - Add inteface chronyd_signal Allow timemaster_t send generic signals to chronyd_t. Resolves: #1243764 - Added interface fs_dontaudit_write_configfs_dirs - Add label for kernel module dep files in /usr/lib/modules Resolves:#916635 - Allow kernel_t domtrans to abrt_dump_oops_t - Added to files_dontaudit_write_all_mountpoints intefface new dontaudit rule, that domain included this interface dontaudit capability dac_override. - Allow systemd-networkd to send logs to systemd-journald. Resolves: #1236616- Fix label on /var/tmp/kiprop_0 Resolves:#1220763 - Allow lldpad_t to getattr tmpfs_t. Resolves: #1246220 - Label /dev/shm/lldpad.* as lldapd_tmpfs_t Resolves: #1246220 - Allow audisp client to read system state.- Allow pcp_domain to manage pcp_var_lib_t lnk_files. Resolves: #1252341 - Label /var/run/xtables.* as iptables_var_run_t Resolves: #1243403- Add interface to read/write watchdog device - Add labels for /dev/memory_bandwith and /dev/vhci. Thanks ssekidde Resolves:#1210237 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow logrotate to reload services. Resolves: #1242453 - Allow openhpid use libwatchdog plugin. (Allow openhpid_t rw watchdog device) Resolves: #1244260 - Allow openhpid liboa_soap plugin to read generic certs. Resolves: #1244248 - Allow openhpid liboa_soap plugin to read resolv.conf file. Resolves: #1244248 - Label /usr/libexec/chrony-helper as chronyd_exec_t - Allow chronyd_t to read dhcpc state. - Allow chronyd to execute mkdir command.- Allow mdadm to access /dev/random and add support to create own files/dirs as mdadm_tmpfs_t. Resolves:#1073314 - Allow udev, lvm and fsadm to access systemd-cat in /var/tmp/dracut if 'dracut -fv' is executed in MLS. - Allow admin SELinu users to communicate with kernel_t. It is needed to access /run/systemd/journal/stdout if 'dracut -vf' is executed. We allow it for other SELinux users. - Allow sysadm to execute systemd-sysctl in the sysadm_t domain. It is needed for ifup command in MLS mode. - Add fstools_filetrans_named_content_fsadm() and call it for named_filetrans_domain domains. We need to be sure that /run/blkid is created with correct labeling. Resolves:#1183503 - Add support for /etc/sanlock which is writable by sanlock daemon. Resolves:#1231377 - Allow useradd add homedir located in /var/lib/kdcproxy in ipa-server RPM scriplet. Resolves:#1243775 - Allow snapperd to pass data (one way only) via pipe negotiated over dbus Resolves:#1250550 - Allow lsmd also setuid capability. Some commands need to executed under root privs. Other commands are executed under unprivileged user.- Allow openhpid to use libsnmp_bc plugin (allow read snmp lib files). Resolves: #1243902 - Allow lsm_plugin_t to read sysfs, read hwdata, rw to scsi_generic_device Resolves: #1238079 - Allow lsm_plugin_t to rw raw_fixed_disk. Resolves:#1238079 - Allow rhsmcertd to send signull to unconfined_service.- Allow httpd_suexec_t to read and write Apache stream sockets Resolves: #1243569 - Allow qpid to create lnk_files in qpid_var_lib_t Resolves: #1247279- Allow drbd to get attributes from filesystems. - Allow redis to read kernel parameters. Resolves: #1209518 - Allow virt_qemu_ga_t domtrans to passwd_t - Allow audisp_remote_t to start power unit files domain to allow halt system. Resolves: #1186780 - Allow audisp_remote_t to read/write user domain pty. Resolves: #1186780 - Label /usr/sbin/chpasswd as passwd_exec_t. - Allow sysadm to administrate ldap environment and allow to bind ldap port to allow to setup an LDAP server (389ds). Resolves:#1221121- gnome_dontaudit_search_config() needs to be a part of optinal_policy in pegasus.te - Allow pcp_pmcd daemon to read postfix config files. - Allow pcp_pmcd daemon to search postfix spool dirs. Resolves: #1213740 - Added Booleans: pcp_read_generic_logs. Resolves: #1213740 - Allow drbd to read configuration options used when loading modules. Resolves: #1134883 - Allow glusterd to manage nfsd and rpcd services. - Allow glusterd to communicate with cluster domains over stream socket. - glusterd call pcs utility which calls find for cib.* files and runs pstree under glusterd. Dontaudit access to security files and update gluster boolean to reflect these changes.- Allow glusterd to manage nfsd and rpcd services. - Allow networkmanager to communicate via dbus with systemd_hostanmed. Resolves: #1234954 - Allow stream connect logrotate to prosody. - Add prosody_stream_connect() interface. - httpd should be able to send signal/signull to httpd_suexec_t, instead of httpd_suexec_exec_t. - Allow prosody to create own tmp files/dirs. Resolves:#1212498- Allow networkmanager read rfcomm port. Resolves:#1212498 - Remove non exists label. - Fix *_admin intefaces where body is not consistent with header. - Label /usr/afs/ as afs_files_t, Allow afs_bosserver_t create afs_config_t and afs_dbdir_t dirs under afs_files_t, Allow afs_bosserver_t read kerberos config - Remove non exits nfsd_ro_t label. - Make all interfaces related to openshift_cache_t as deprecated. - Add rpm_var_run_t label to rpm_admin header - Add jabberd_lock_t label to jabberd_admin header. - Add samba_unconfined_script_exec_t to samba_admin header. - inn daemon should create innd_log_t objects in var_log_t instead of innd_var_run_t - Fix ctdb policy - Add samba_signull_winbind() - Add samba_signull_unconfined_net() - Allow ctdbd_t send signull to samba_unconfined_net_t. - Allow openshift_initrc_t to communicate with firewalld over dbus Resolves:#1221326- Allow gluster to connect to all ports. It is required by random services executed by gluster. - Add interfaces winbind_signull(), samba_unconfined_net_signull(). - Dontaudit smbd_t block_suspend capability. This is kernel bug. - Allow ctdbd sending signull to process winbind, samba_unconfined_net, to checking if processes exists. - Add tmpreaper booleans to use nfs_t and samba_share_t. - Fix path from /usr/sbin/redis-server to /usr/bin/redis-server - Allow connect ypserv to portmap_port_t - Fix paths in inn policy, Allow innd read innd_log_t dirs, Allow innd execute innd_etc_t files - Add support for openstack-nova-* packages - Allow NetworkManager_t send signull to dnssec_trigger_t. - Allow glusterd to execute showmount in the showmount domain. - Label swift-container-reconciler binary as swift_t. - Allow dnssec_trigger_t relabelfrom dnssec_trigger_var_run_t files. - Add cobbler_var_lib_t to "/var/lib/tftpboot/boot(/.*)?" Resolves:#1213540 - Merge all nova_* labels under one nova_t.- Add logging_syslogd_run_nagios_plugins boolean for rsyslog to allow transition to nagios unconfined plugins Resolves:#1233550 - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/ - Add support for oddjob based helper in FreeIPA. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add nagios_domtrans_unconfined_plugins() interface. - Update mta_filetrans_named_content() interface to cover more db files. Resolves:#1167468 - Add back ftpd_use_passive_mode boolean with fixed description. - Allow pmcd daemon stream connect to mysqld. - Allow pcp domains to connect to own process using unix_stream_socket. Resolves:#1213709 - Allow abrt-upload-watch service to dbus chat with ABRT daemon and fsetid capability to allow run reporter-upload correctly. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add support for oddjob based helper in FreeIPA. - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/- Allow iptables to read ctdbd lib files. Resolves:#1224879 - Add systemd_networkd_t to nsswitch domains. - Allow drbd_t write to fixed_disk_device. Reason: drbdmeta needs write to fixed_disk_device during initialization. Resolves:#1130675 - Allow NetworkManager write to sysfs. - Fix cron_system_cronjob_use_shares boolean to call fs interfaces which contain only entrypoint permission. - Add cron_system_cronjob_use_shares boolean to allow system cronjob to be executed from shares - NFS, CIFS, FUSE. It requires "entrypoint" permissios on nfs_t, cifs_t and fusefs_t SELinux types. - Allow NetworkManager write to sysfs. - Allow ctdb_t sending signull to smbd_t, for checking if smbd process exists. - Dontaudit apache to manage snmpd_var_lib_t files/dirs. - Add interface snmp_dontaudit_manage_snmp_var_lib_files(). - Dontaudit mozilla_plugin_t cap. sys_ptrace. - Rename xodbc-connect port to xodbc_connect - Allow ovsdb-server to connect on xodbc-connect and ovsdb tcp ports. - Allow iscsid write to fifo file kdumpctl_tmp_t. Appears when kdump generates the initramfs during the kernel boot. - Dontaudit chrome to read passwd file. - nrpe needs kill capability to make gluster moniterd nodes working. Resolves:#1235587- We allow can_exec() on ssh_keygen on gluster. But there is a transition defined by init_initrc_domain() because we need to allow execute unconfined services by glusterd. So ssh-keygen ends up with ssh_keygen_t and we need to allow to manage /var/lib/glusterd/geo-replication/secret.pem. - Allow sshd to execute gnome-keyring if there is configured pam_gnome_keyring.so. - Allow gnome-keyring executed by passwd to access /run/user/UID/keyring to change a password. - Label gluster python hooks also as bin_t. - Allow glusterd to interact with gluster tools running in a user domain - Add glusterd_manage_lib_files() interface. - ntop reads /var/lib/ntop/macPrefix.db and it needs dac_override. It has setuid/setgid. - Allow samba_t net_admin capability to make CIFS mount working. - S30samba-start gluster hooks wants to search audit logs. Dontaudit it. Resolves:#1224879- Allow glusterd to send generic signals to systemd_passwd_agent processes. - Allow glusterd to access init scripts/units without defined policy - Allow glusterd to run init scripts. - Allow glusterd to execute /usr/sbin/xfs_dbin glusterd_t domain. Resolves:#1224879- Calling cron_system_entry() in pcp_domain_template needs to be a part of optional_policy block. - Allow samba-net to access /var/lib/ctdbd dirs/files. - Allow glusterd to send a signal to smbd. - Make ctdbd as home manager to access also FUSE. - Allow glusterd to use geo-replication gluster tool. - Allow glusterd to execute ssh-keygen. - Allow glusterd to interact with cluster services. - Allow glusterd to connect to the system DBUS for service (acquire_svc). - Label /dev/log correctly. Resolves:#1230932- Back port the latest F22 changes to RHEL7. It should fix most of RHEL7.2 bugs - Add cgdcbxd policy Resolves:#1072493 - Fix ftp_homedir boolean Resolve:#1097775 - Dontaudit ifconfig writing inhertited /var/log/pluto.log. - Allow cluster domain to dbus chat with systemd-logind. Resolves:#1145215 - Dontaudit write access to inherited kdumpctl tmp files Resolves:#1156442 - Allow isnsd_t to communicate with sssd Resolves:#1167702 - Allow rwho_t to communicate with sssd Resolves:#1167718 - Allow sblim_gatherd_t to communicate with sssd Resolves:#1167732 - Allow pkcs_slotd_t to communicate with sssd Resolves:#1167737 - Allow openvswitch_t to communicate with sssd Resolves:#1167816 - Allow mysqld_safe_t to communicate with sssd Resolves:#1167832 - Allow sshd_keygen_t to communicate with sssd Resolves:#1167840 - Add support for iprdbg logging files in /var/log. Resolves:#1174363 - Allow tmpreaper_t to manage ntp log content Resolves:#1176965 - Allow gssd_t to manage ssh keyring Resolves:#1184791 - Allow httpd_sys_script_t to send system log messages Resolves:#1185231 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow dovecot_t sys_resource capability Resolves:#1191143 - Add support for mongod/mongos systemd unit files. Resolves:#1197038 - Add bacula fixes - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. Resolves:#1203991- Label /usr/libexec/postgresql-ctl as postgresql_exec_t. - Add more restriction on entrypoint for unconfined domains. - Only allow semanage_t to be able to setenforce 0, no all domains that use selinux_semanage interface - Allow all domains to read /dev/urandom. It is needed by all apps/services linked to libgcrypt. There is no harm to allow it by default. - Update policy/mls for sockets related to access perm. Rules were contradictory. - Add nagios_run_pnp4nagios and nagios_run_sudo booleans to allow r un sudo from NRPE utils scripts and allow run nagios in conjunction w ith PNP4Nagios. Resolves:#1201054 - Don't use deprecated userdom_manage_tmpfs_role() interface calliing and use userdom_manage_tmp_role() instead. - Update virt_read_pid_files() interface to allow read also symlinks with virt_var_run_t type - Label /var/lib/tftpboot/aarch64(/.*)? and /var/lib/tftpboot/images2(/.*)? - Add support for iprdbg logging files in /var/log. - Add fixes to rhsmcertd_t - Allow puppetagent_t to transfer firewalld messages over dbus - Add support for /usr/libexec/mongodb-scl-helper RHSCL helper script. - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. - Add support for mongod/mongos systemd unit files. - cloudinit and rhsmcertd need to communicate with dbus - Allow dovecot_t sys_resource capability- ALlow mongod execmem by default. - Update policy/mls for sockets. Rules were contradictory. Resolves:#1207133 - Allow a user to login with different security level via ssh.- Update seutil_manage_config() interface. Resolves:#1185962 - Allow pki-tomcat relabel pki_tomcat_etc_rw_t. - Turn on docker_transition_unconfined by default- Allow virtd to list all mountpoints. Resolves:#1180713- pkcsslotd_lock_t should be an alias for pkcs_slotd_lock_t. - Allow fowner capability for sssd because of selinux_child handling. - ALlow bind to read/write inherited ipsec pipes - Allow hypervkvp to read /dev/urandom and read addition states/config files. - Allow gluster rpm scripletto create glusterd socket with correct labeling. This is a workaround until we get fix in glusterd. - Add glusterd_filetrans_named_pid() interface - Allow radiusd to connect to radsec ports. - Allow setuid/setgid for selinux_child - Allow lsmd plugin to connect to tcp/5988 by default. - Allow lsmd plugin to connect to tcp/5989 by default. - Update ipsec_manage_pid() interface. Resolves:#1184978- Update ipsec_manage_pid() interface. Resolves:#1184978- Allow ntlm_auth running in winbind_helper_t to access /dev/urandom.- Add auditing support for ipsec. Resolves:#1182524 - Label /ostree/deploy/rhel-atomic-host/deploy directory as system_conf_t - Allow netutils chown capability to make tcpdump working with -w- Allow ipsec to execute _updown.netkey script to run unbound-control. - Allow neutron to read rpm DB. - Add additional fixes for hyperkvp * creates new ifcfg-{name} file * Runs hv_set_ifconfig.sh, which does the following * Copies ifcfg-{name} to /etc/sysconfig/network-scripts - Allow svirt to read symbolic links in /sys/fs/cgroups labeled as tmpfs_t - Add labeling for pacemaker.log. - Allow radius to connect/bind radsec ports. - Allow pm-suspend running as virt_qemu_ga to read /var/log/pm-suspend.log - Allow virt_qemu_ga to dbus chat with rpm. - Update virt_read_content() interface to allow read also char devices. - Allow glance-registry to connect to keystone port. Resolves:#1181818- Allow sssd to send dbus all user domains. Resolves:#1172291 - Allow lsm plugin to read certificates. - Fix labeling for keystone CGI scripts. - Make snapperd back as unconfined domain.- Fix bugs in interfaces discovered by sepolicy. - Allow slapd to read /usr/share/cracklib/pw_dict.hwm. - Allow lsm plugins to connect to tcp/18700 by default. - Allow brltty mknod capability to allow create /var/run/brltty/vcsa. - Fix pcp_domain_template() interface. - Fix conman.te. - Allow mon_fsstatd to read /proc/sys/fs/binfmt_misc - Allow glance-scrubber to connect tcp/9191. - Add missing setuid capability for sblim-sfcbd. - Allow pegasus ioctl() on providers. - Add conman_can_network. - Allow chronyd to read chrony conf files located in /run/timemaster/. - Allow radius to bind on tcp/1813 port. - dontaudit block suspend access for openvpn_t - Allow conman to create files/dirs in /tmp. - Update xserver_rw_xdm_keys() interface to have 'setattr'. Resolves:#1172291 - Allow sulogin to read /dev/urandom and /dev/random. - Update radius port definition to have also tcp/18121 - Label prandom as random_device_t. - Allow charon to manage files in /etc/strongimcv labeled as ipsec_conf_t.- Allow virt_qemu_ga_t to execute kmod. - Add missing files_dontaudit_list_security_dirs() for smbd_t in samba_export_all_ro boolean. - Add additionnal MLS attribute for oddjob_mkhomedir to create homedirs. Resolves:#1113725 - Enable OpenStack cinder policy - Add support for /usr/share/vdsm/daemonAdapter - Add support for /var/run/gluster- Remove old pkcsslotd.pp from minimum package - Allow rlogind to use also rlogin ports. - Add support for /usr/libexec/ntpdate-wrapper. Label it as ntpdate_exec_t. - Allow bacula to connect also to postgresql. - Label /usr/libexec/tomcat/server as tomcat_exec_t - Add support for /usr/sbin/ctdbd_wrapper - Add support for /usr/libexec/ppc64-diag/rtas_errd - Allow rpm_script_roles to access system_mail_t - Allow brltty to create /var/run/brltty - Allow lsmd plugin to access netlink_route_socket - Allow smbcontrol to read passwd - Add support for /usr/libexec/sssd/selinux_child and create sssd_selinux_manager_t domain for it Resolves:#1140106 - Allow osad to execute rhn_check - Allow load_policy to rw inherited sssd pipes because of selinux_child - Allow admin SELinux users mounting / as private within a new mount namespace as root in MLS - Add additional fixes for su_restricted_domain_template to make moving to sysadm_r and trying to su working correctly - Add additional booleans substitions- Add seutil_dontaudit_access_check_semanage_module_store() interface Resolves:#1140106 - Update to have all _systemctl() interface also init_reload_services(). - Dontaudit access check on SELinux module store for sssd. - Add labeling for /sbin/iw. - Allow named_filetrans_domain to create ibus directory with correct labeling.- Allow radius to bind tcp/1812 radius port. - Dontaudit list user_tmp files for system_mail_t. - Label virt-who as virtd_exec_t. - Allow rhsmcertd to send a null signal to virt-who running as virtd_t. - Add missing alias for _content_rw_t. Resolves:#1089177 - Allow spamd to access razor-agent.log. - Add fixes for sfcb from libvirt-cim TestOnly bug. - Allow NetworkManager stream connect on openvpn. - Make /usr/bin/vncserver running as unconfined_service_t. - getty_t should be ranged in MLS. Then also local_login_t runs as ranged domain. - Label /etc/docker/certs.d as cert_t.- Label /etc/strongimcv as ipsec_conf_file_t. - Add support for /usr/bin/start-puppet-ca helper script Resolves:#1160727 - Allow rpm scripts to enable/disable transient systemd units. Resolves:#1154613 - Make kpropdas nsswitch domain Resolves:#1153561 - Make all glance domain as nsswitch domains Resolves:#1113281 - Allow selinux_child running as sssd access check on /etc/selinux/targeted/modules/active - Allow access checks on setfiles/load_policy/semanage_lock for selinux_child running as sssd_t Resolves:#1140106- Dontaudit access check on setfiles/load_policy for sssd_t. Resolves:#1140106 - Add kdump_rw_inherited_kdumpctl_tmp_pipes() Resolves:#1156442 - Make linuxptp services as unconfined. - Added new policy linuxptp. Resolves:#1149693 - Label keystone cgi files as keystone_cgi_script_exec_t. Resolves:#1138424 - Make tuned as unconfined domain- Allow guest to connect to libvirt using unix_stream_socket. - Allow all bus client domains to dbus chat with unconfined_service_t. - Allow inetd service without own policy to run in inetd_child_t which is unconfined domain. - Make opensm as nsswitch domain to make it working with sssd. - Allow brctl to read meminfo. - Allow winbind-helper to execute ntlm_auth in the caller domain. Resolves:#1160339 - Make plymouthd as nsswitch domain to make it working with sssd. Resolves:#1160196 - Make drbd as nsswitch domain to make it working with sssd. - Make conman as nsswitch domain to make ipmitool.exp runing as conman_t working. - Add support for /var/lib/sntp directory. - Add fixes to allow docker to create more content in tmpfs ,and donaudit reading /proc - Allow winbind to read usermodehelper - Allow telepathy domains to execute shells and bin_t - Allow gpgdomains to create netlink_kobject_uevent_sockets - Allow mongodb to bind to the mongo port and mongos to run as mongod_t - Allow abrt to read software raid state. - Allow nslcd to execute netstat. - Allow dovecot to create user's home directory when they log into IMAP. - Allow login domains to create kernel keyring with different level.- Allow modemmanger to connectto itself Resolves:#1120152 - Allow pki_tomcat to create link files in /var/lib/pki-ca. Resolves:#1121744 - varnishd needs to have fsetid capability Resolves:#1125165 - Allow snapperd to dbus chat with system cron jobs. Resolves:#1152447 - Allow dovecot to create user's home directory when they log into IMAP Resolves:#1152773 - Add labeling for /usr/sbin/haproxy-systemd-wrapper wrapper to make haproxy running haproxy_t. - ALlow listen and accept on tcp socket for init_t in MLS. Previously it was for xinetd_t. - Allow nslcd to execute netstat. - Add suppor for keepalived unconfined scripts and allow keepalived to read all domain state and kill capability. - Allow nslcd to read /dev/urandom.- Add back kill permisiion for system class Resolves:#1150011- Add back kill permisiion for service class Resolves:#1150011 - Make rhsmcertd_t also as dbus domain. - Allow named to create DNS_25 with correct labeling. - Add cloudform_dontaudit_write_cloud_log() - Call auth_use_nsswitch to apache to read/write cloud-init keys. - Allow cloud-init to dbus chat with certmonger. - Fix path to mon_statd_initrc_t script. - Allow all RHCS services to read system state. - Allow dnssec_trigger_t to execute unbound-control in own domain. - kernel_read_system_state needs to be called with type. Moved it to antivirus.if. - Added policy for mon_statd and mon_procd services. BZ (1077821) - Allow opensm_t to read/write /dev/infiniband/umad1. - Allow mongodb to manage own log files. - Allow neutron connections to system dbus. - Add support for /var/lib/swiftdirectory. - Allow nova-scheduler to read certs. - Allow openvpn to access /sys/fs/cgroup dir. - Allow openvpn to execute systemd-passwd-agent in systemd_passwd_agent_t to make openvpn working with systemd. - Fix samba_export_all_ro/samba_export_all_rw booleans to dontaudit search/read security files. - Add auth_use_nsswitch for portreserve to make it working with sssd. - automount policy is non-base module so it needs to be called in optional block. - ALlow sensord to getattr on sysfs. - Label /usr/share/corosync/corosync as cluster_exec_t. - Allow lmsd_plugin to read passwd file. BZ(1093733) - Allow read antivirus domain all kernel sysctls. - Allow mandb to getattr on file systems - Allow nova-console to connect to mem_cache port. - Make sosreport as unconfined domain. - Allow mondogdb to 'accept' accesses on the tcp_socket port. - ALlow sanlock to send a signal to virtd_t.- Build also MLS policy Resolves:#1138424- Add back kill permisiion for system class - Allow iptables read fail2ban logs. - Fix radius labeled ports - Add userdom_manage_user_tmpfs_files interface - Allow libreswan to connect to VPN via NM-libreswan. - Label 4101 tcp port as brlp port - fix dev_getattr_generic_usb_dev interface - Allow all domains to read fonts - Make sure /run/systemd/generator and system is labeled correctly on creation. - Dontaudit aicuu to search home config dir. - Make keystone_cgi_script_t domain. Resolves:#1138424 - Fix bug in drbd policy, - Added support for cpuplug. - ALlow sanlock_t to read sysfs_t. - Added sendmail_domtrans_unconfined interface - Fix broken interfaces - radiusd wants to write own log files. - Label /usr/libexec/rhsmd as rhsmcertd_exec_t - Allow rhsmcertd send signull to setroubleshoot. - Allow rhsmcertd manage rpm db. - Added policy for blrtty. - Fix keepalived policy - Allow rhev-agentd dbus chat with systemd-logind. - Allow keepalived manage snmp var lib sock files. - Add support for /var/lib/graphite-web - Allow NetworkManager to create Bluetooth SDP sockets - It's going to do the the discovery for DUN service for modems with Bluez 5. - Allow swift to connect to all ephemeral ports by default. - Allow sssd to read selinux config to add SELinux user mapping. - Allow lsmd to search own plguins. - Allow abrt to read /dev/memto generate an unique machine_id and uses sosuploader's algorithm based off dmidecode[1] fields. - ALlow zebra for user/group look-ups. - Allow nova domains to getattr on all filesystems. - Allow collectd sys_ptrace and dac_override caps because of reading of /proc/%i/io for several processes. - Allow pppd to connect to /run/sstpc/sstpc-nm-sstp-service-28025 over unix stream socket. - Allow rhnsd_t to manage also rhnsd config symlinks. - ALlow user mail domains to create dead.letter. - Allow rabbitmq_t read rabbitmq_var_lib_t lnk files. - Allow pki-tomcat to change SELinux object identity. - Allow radious to connect to apache ports to do OCSP check - Allow git cgi scripts to create content in /tmp - Allow cockpit-session to do GSSAPI logins. - Allow sensord read in /proc - Additional access required by usbmuxd- Allow locate to look at files/directories without labels, and chr_file and blk_file on non dev file systems - Label /usr/lib/erlang/erts.*/bin files as bin_t - Add files_dontaudit_access_check_home_dir() inteface. - Allow udev_t mounton udev_var_run_t dirs #(1128618) - Add systemd_networkd_var_run_t labeling for /var/run/systemd/netif and allow systemd-networkd to manage it. - Add init_dontaudit_read_state() interface. - Add label for ~/.local/share/fonts - Allow unconfined_r to access unconfined_service_t. - Allow init to read all config files - Add new interface to allow creation of file with lib_t type - Assign rabbitmq port. - Allow unconfined_service_t to dbus chat with all dbus domains - Add new interfaces to access users keys. - Allow domains to are allowed to mounton proc to mount on files as well as dirs - Fix labeling for HOME_DIR/tmp and HOME_DIR/.tmp directories. - Add a port definition for shellinaboxd - Label ~/tmp and ~/.tmp directories in user tmp dirs as user_tmp_t - Allow userdomains to stream connect to pcscd for smart cards - Allow programs to use pam to search through user_tmp_t dires (/tmp/.X11-unix) - Update to rawhide-contrib changes Resolves:#1123844- Rebase to 3.13.1 which we have in Fedora21 Resolves:#1128284- Back port fixes from Fedora. Mainly OpenStack and Docker fixes- Add policy-rhel-7.1-{base,contrib} patches- Add support for us_cli ports - Fix labeling for /var/run/user//gvfs - add support for tcp/9697 - Additional rules required by openstack, needs backport to F20 and RHEL7 - Additional access required by docker - ALlow motion to use tcp/8082 port - Allow init_t to setattr/relabelfrom dhcp state files - Dontaudit antivirus domains read access on all security files by default - Add missing alias for old amavis_etc_t type - Allow block_suspend cap for haproxy - Additional fixes for instack overcloud - Allow OpenStack to read mysqld_db links and connect to MySQL - Remove dup filename rules in gnome.te - Allow sys_chroot cap for httpd_t and setattr on httpd_log_t - Allow iscsid to handle own unit files - Add iscsi_systemctl() - Allow mongod to create also sock_files in /run with correct labeling - Allow httpd to send signull to apache script domains and don't audit leaks - Allow rabbitmq_beam to connect to httpd port - Allow aiccu stream connect to pcscd - Allow dmesg to read hwdata and memory dev - Allow all freeipmi domains to read/write ipmi devices - Allow sblim_sfcbd to use also pegasus-https port - Allow rabbitmq_epmd to manage rabbit_var_log_t files - Allow chronyd to read /sys/class/hwmon/hwmon1/device/temp2_input - Allow docker to status any unit file and allow it to start generic unit files- Change hsperfdata_root to have as user_tmp_t Resolves:#1076523- Fix Multiple same specifications for /var/named/chroot/dev/zero - Add labels for /var/named/chroot_sdb/dev devices - Add support for strongimcv - Use kerberos_keytab_domains in auth_use_nsswitch - Update auth_use_nsswitch to make all these types as kerberos_keytab_domain to - Allow net_raw cap for neutron_t and send sigkill to dnsmasq - Fix ntp_filetrans_named_content for sntp-kod file - Add httpd_dbus_sssd boolean - Dontaudit exec insmod in boinc policy - Rename kerberos_keytab_domain to kerberos_keytab_domains - Add kerberos_keytab_domain() - Fix kerberos_keytab_template() - Make all domains which use kerberos as kerberos_keytab_domain Resolves:#1083670 - Allow kill capability to winbind_t- varnishd wants chown capability - update ntp_filetrans_named_content() interface - Add additional fixes for neutron_t. #1083335 - Dontaudit getattr on proc_kcore_t - Allow pki_tomcat_t to read ipa lib files - Allow named_filetrans_domain to create /var/cache/ibus with correct labelign - Allow init_t run /sbin/augenrules - Add dev_unmount_sysfs_fs and sysnet_manage_ifconfig_run interfaces - Allow unpriv SELinux user to use sandbox - Add default label for /tmp/hsperfdata_root- Add file subs also for /var/home- Allow xauth_t to read user_home_dir_t lnk_file - Add labeling for lightdm-data - Allow certmonger to manage ipa lib files - Add support for /var/lib/ipa - Allow pegasus to getattr virt_content - Added some new rules to pcp policy - Allow chrome_sandbox to execute config_home_t - Add support for ABRT FAF- Allow kdm to send signull to remote_login_t process - Add gear policy - Turn on gear_port_t - Allow cgit to read gitosis lib files by default - Allow vdagent to read xdm state - Allow NM and fcoeadm to talk together over unix_dgram_socket- Back port fixes for pegasus_openlmi_admin_t from rawhide Resolves:#1080973 - Add labels for ostree - Add SELinux awareness for NM - Label /usr/sbin/pwhistory_helper as updpwd_exec_t- add gnome_append_home_config() - Allow thumb to append GNOME config home files - Allow rasdaemon to rw /dev/cpu//msr - fix /var/log/pki file spec - make bacula_t as auth_nsswitch domain - Identify pki_tomcat_cert_t as a cert_type - Define speech-dispater_exec_t as an application executable - Add a new file context for /var/named/chroot/run directory - update storage_filetrans_all_named_dev for sg* devices - Allow auditctl_t to getattr on all removeable devices - Allow nsswitch_domains to stream connect to nmbd - Allow unprivusers to connect to memcached - label /var/lib/dirsrv/scripts-INSTANCE as bin_t- Allow also unpriv user to run vmtools - Allow secadm to read /dev/urandom and meminfo Resolves:#1079250 - Add booleans to allow docker processes to use nfs and samba - Add mdadm_tmpfs support - Dontaudit net_amdin for /usr/lib/jvm/java-1.7.0-openjdk-1.7.0.51-2.4.5.1.el7.x86_64/jre-abrt/bin/java running as pki_tomcat_t - Allow vmware-user-sui to use user ttys - Allow talk 2 users logged via console too - Allow ftp services to manage xferlog_t - Make all pcp domanis as unconfined for RHEL7.0 beucause of new policies - allow anaconda to dbus chat with systemd-localed- allow anaconda to dbus chat with systemd-localed - Add fixes for haproxy based on bperkins@redhat.com - Allow cmirrord to make dmsetup working - Allow NM to execute arping - Allow users to send messages through talk - Add userdom_tmp_role for secadm_t- Add additional fixes for rtas_errd - Fix transitions for tmp/tmpfs in rtas.te - Allow rtas_errd to readl all sysctls- Add support for /var/spool/rhsm/debug - Make virt_sandbox_use_audit as True by default - Allow svirt_sandbox_domains to ptrace themselves- Allow docker containers to manage /var/lib/docker content- Allow docker to read tmpfs_t symlinks - Allow sandbox svirt_lxc_net_t to talk to syslog and to sssd over stream sockets- Allow collectd to talk to libvirt - Allow chrome_sandbox to use leaked unix_stream_sockets - Dontaudit leaks of sockets into chrome_sandbox_t - If you create a cups directory in /var/cache then it should be labeled cups_rw_etc_t - Run vmtools as unconfined domains - Allow snort to manage its log files - Allow systemd_cronjob_t to be entered via bin_t - Allow procman to list doveconf_etc_t - allow keyring daemon to create content in tmpfs directories - Add proper labelling for icedtea-web - vpnc is creating content in networkmanager var run directory - Label sddm as xdm_exec_t to make KDE working again - Allow postgresql to read network state - Allow java running as pki_tomcat to read network sysctls - Fix cgroup.te to allow cgred to read cgconfig_etc_t - Allow beam.smp to use ephemeral ports - Allow winbind to use the nis to authenticate passwords- Make rtas_errd_t as unconfined domain for F20.It needs additional fixes. It runs rpm at least. - Allow net_admin cap for fence_virtd running as fenced_t - Make abrt-java-connector working - Make cimtest script 03_defineVS.py of ComputerSystem group working - Fix git_system_enable_homedirs boolean - Allow munin mail plugins to read network systcl- Allow vmtools_helper_t to execute bin_t - Add support for /usr/share/joomla - /var/lib/containers should be labeled as openshift content for now - Allow docker domains to talk to the login programs, to allow a process to login into the container - Allow install_t do dbus chat with NM - Fix interface names in anaconda.if - Add install_t for anaconda. A new type is a part of anaconda policy - sshd to read network sysctls- Allow zabbix to send system log msgs - Allow init_t to stream connect to ipsec Resolves:#1060775- Add docker_connect_any boolean- Allow unpriv SELinux users to dbus chat with firewalld - Add lvm_write_metadata() - Label /etc/yum.reposd dir as system_conf_t. Should be safe because system_conf_t is base_ro_file_type - Allow pegasus_openlmi_storage_t to write lvm metadata - Add hide_broken_symptoms for kdumpgui because of systemd bug - Make kdumpgui_t as unconfined domain Resolves:#1044299 - Allow docker to connect to tcp/5000- Allow numad to write scan_sleep_millisecs - Turn on entropyd_use_audio boolean by default - Allow cgred to read /etc/cgconfig.conf because it contains templates used together with rules from /etc/cgrules.conf. - Allow lscpu running as rhsmcertd_t to read /proc/sysinfo - Fix label on irclogs in the homedir - Allow kerberos_keytab_domain domains to manage keys until we get sssd fix - Allow postgresql to use ldap - Add missing syslog-conn port - Add support for /dev/vmcp and /dev/sclp Resolves:#1069310- Modify xdm_write_home to allow create files/links in /root with xdm_home_ - Allow virt domains to read network state Resolves:#1072019- Added pcp rules - dontaudit openshift_cron_t searching random directories, should be back ported to RHEL6 - clean up ctdb.te - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow certmonger to list home dirs- Change userdom_use_user_inherited_ttys to userdom_use_user_ttys for systemd-tty-ask - Add sysnet_filetrans_named_content_ifconfig() interface - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow kerberos keytab domains to manage sssd/userdomain keys" - Allow to run ip cmd in neutron_t domain- Allow block_suspend cap2 for systemd-logind and rw dri device - Add labeling for /usr/libexec/nm-libreswan-service - Allow locallogin to rw xdm key to make Virtual Terminal login providing smartcard pin working - Add xserver_rw_xdm_keys() - Allow rpm_script_t to dbus chat also with systemd-located - Fix ipa_stream_connect_otpd() - update lpd_manage_spool() interface - Allow krb5kdc to stream connect to ipa-otpd - Add ipa_stream_connect_otpd() interface - Allow vpnc to unlink NM pids - Add networkmanager_delete_pid_files() - Allow munin plugins to access unconfined plugins - update abrt_filetrans_named_content to cover /var/spool/debug - Label /var/spool/debug as abrt_var_cache_t - Allow rhsmcertd to connect to squid port - Make docker_transition_unconfined as optional boolean - Allow certmonger to list home dirs- Make snapperd as unconfined domain and add additional fixes for it - Remove nsplugin.pp module on upgrade- Add snapperd_home_t for HOME_DIR/.snapshots directory - Make sosreport as unconfined domain - Allow sosreport to execute grub2-probe - Allow NM to manage hostname config file - Allow systemd_timedated_t to dbus chat with rpm_script_t - Allow lsmd plugins to connect to http/ssh/http_cache ports by default - Add lsmd_plugin_connect_any boolean - Allow mozilla_plugin to attempt to set capabilities - Allow lsdm_plugins to use tcp_socket - Dontaudit mozilla plugin from getattr on /proc or /sys - Dontaudit use of the keyring by the services in a sandbox - Dontaudit attempts to sys_ptrace caused by running ps for mysqld_safe_t - Allow rabbitmq_beam to connect to jabber_interserver_port - Allow logwatch_mail_t to transition to qmail_inject and queueu - Added new rules to pcp policy - Allow vmtools_helper_t to change role to system_r - Allow NM to dbus chat with vmtools - Fix couchdb_manage_files() to allow manage couchdb conf files - Add support for /var/run/redis.sock - dontaudit gpg trying to use audit - Allow consolekit to create log directories and files - Fix vmtools policy to allow user roles to access vmtools_helper_t - Allow block_suspend cap2 for ipa-otpd - Allow pkcsslotd to read users state - Add ioctl to init_dontaudit_rw_stream_socket - Add systemd_hostnamed_manage_config() interface - Remove transition for temp dirs created by init_t - gdm-simple-slave uses use setsockopt - sddm-greater is a xdm type program- Add lvm_read_metadata() - Allow auditadm to search /var/log/audit dir - Add lvm_read_metadata() interface - Allow confined users to run vmtools helpers - Fix userdom_common_user_template() - Generic systemd unit scripts do write check on / - Allow init_t to create init_tmp_t in /tmp.This is for temporary content created by generic unit files - Add additional fixes needed for init_t and setup script running in generic unit files - Allow general users to create packet_sockets - added connlcli port - Add init_manage_transient_unit() interface - Allow init_t (generic unit files) to manage rpc state date as we had it for initrc_t - Fix userdomain.te to require passwd class - devicekit_power sends out a signal to all processes on the message bus when power is going down - Dontaudit rendom domains listing /proc and hittping system_map_t - Dontauit leaks of var_t into ifconfig_t - Allow domains that transition to ssh_t to manipulate its keyring - Define oracleasm_t as a device node - Change to handle /root as a symbolic link for os-tree - Allow sysadm_t to create packet_socket, also move some rules to attributes - Add label for openvswitch port - Remove general transition for files/dirs created in /etc/mail which got etc_aliases_t label. - Allow postfix_local to read .forward in pcp lib files - Allow pegasus_openlmi_storage_t to read lvm metadata - Add additional fixes for pegasus_openlmi_storage_t - Allow bumblebee to manage debugfs - Make bumblebee as unconfined domain - Allow snmp to read etc_aliases_t - Allow lscpu running in pegasus_openlmi_storage_t to read /dev/mem - Allow pegasus_openlmi_storage_t to read /proc/1/environ - Dontaudit read gconf files for cupsd_config_t - make vmtools as unconfined domain - Add vmtools_helper_t for helper scripts. Allow vmtools shutdonw a host and run ifconfig. - Allow collectd_t to use a mysql database - Allow ipa-otpd to perform DNS name resolution - Added new policy for keepalived - Allow openlmi-service provider to manage transitient units and allow stream connect to sssd - Add additional fixes new pscs-lite+polkit support - Add labeling for /run/krb5kdc - Change w3c_validator_tmp_t to httpd_w3c_validator_tmp_t in F20 - Allow pcscd to read users proc info - Dontaudit smbd_t sending out random signuls - Add boolean to allow openshift domains to use nfs - Allow w3c_validator to create content in /tmp - zabbix_agent uses nsswitch - Allow procmail and dovecot to work together to deliver mail - Allow spamd to execute files in homedir if boolean turned on - Allow openvswitch to listen on port 6634 - Add net_admin capability in collectd policy - Fixed snapperd policy - Fixed bugsfor pcp policy - Allow dbus_system_domains to be started by init - Fixed some interfaces - Add kerberos_keytab_domain attribute - Fix snapperd_conf_t def- Addopt corenet rules for unbound-anchor to rpm_script_t - Allow runuser to send send audit messages. - Allow postfix-local to search .forward in munin lib dirs - Allow udisks to connect to D-Bus - Allow spamd to connect to spamd port - Fix syntax error in snapper.te - Dontaudit osad to search gconf home files - Allow rhsmcertd to manage /etc/sysconf/rhn director - Fix pcp labeling to accept /usr/bin for all daemon binaries - Fix mcelog_read_log() interface - Allow iscsid to manage iscsi lib files - Allow snapper domtrans to lvm_t. Add support for /etc/snapper and allow snapperd to manage it. - Make tuned_t as unconfined domain for RHEL7.0 - Allow ABRT to read puppet certs - Add sys_time capability for virt-ga - Allow gemu-ga to domtrans to hwclock_t - Allow additional access for virt_qemu_ga_t processes to read system clock and send audit messages - Fix some AVCs in pcp policy - Add to bacula capability setgid and setuid and allow to bind to bacula ports - Changed label from rhnsd_rw_conf_t to rhnsd_conf_t - Add access rhnsd and osad to /etc/sysconfig/rhn - drbdadm executes drbdmeta - Fixes needed for docker - Allow epmd to manage /var/log/rabbitmq/startup_err file - Allow beam.smp connect to amqp port - Modify xdm_write_home to allow create also links as xdm_home_t if the boolean is on true - Allow init_t to manage pluto.ctl because of init_t instead of initrc_t - Allow systemd_tmpfiles_t to manage all non security files on the system - Added labels for bacula ports - Fix label on /dev/vfio/vfio - Add kernel_mounton_messages() interface - init wants to manage lock files for iscsi- Added osad policy - Allow postfix to deliver to procmail - Allow bumblebee to seng kill signal to xserver - Allow vmtools to execute /usr/bin/lsb_release - Allow docker to write system net ctrls - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix pcp.te - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl- Turn on bacula, rhnsd policy - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl - Fixes for *_admin interfaces - Add pegasus_openlmi_storage_var_run_t type def - Add support for /var/run/openlmi-storage - Allow tuned to create syslog.conf with correct labeling - Add httpd_dontaudit_search_dirs boolean - Add support for winbind.service - ALlow also fail2ban-client to read apache logs - Allow vmtools to getattr on all fs - Add support for dey_sapi port - Add logging_filetrans_named_conf() - Allow passwd_t to use ipc_lock, so that it can change the password in gnome-keyring- Update snapper policy - Allow domains to append rkhunter lib files - Allow snapperd to getattr on all fs - Allow xdm to create /var/gdm with correct labeling - Add label for snapper.log - Allow fail2ban-client to read apache log files - Allow thumb_t to execute dbus-daemon in thumb_t- Allow gdm to create /var/gdm with correct labeling - Allow domains to append rkhunterl lib files. #1057982 - Allow systemd_tmpfiles_t net_admin to communicate with journald - Add interface to getattr on an isid_type for any type of file - Update libs_filetrans_named_content() to have support for /usr/lib/debug directory - Allow initrc_t domtrans to authconfig if unconfined is enabled - Allow docker and mount on devpts chr_file - Allow docker to transition to unconfined_t if boolean set - init calling needs to be optional in domain.te - Allow uncofined domain types to handle transient unit files - Fix labeling for vfio devices - Allow net_admin capability and send system log msgs - Allow lldpad send dgram to NM - Add networkmanager_dgram_send() - rkhunter_var_lib_t is correct type - Back port pcp policy from rawhide - Allow openlmi-storage to read removable devices - Allow system cron jobs to manage rkhunter lib files - Add rkhunter_manage_lib_files() - Fix ftpd_use_fusefs boolean to allow manage also symlinks - Allow smbcontrob block_suspend cap2 - Allow slpd to read network and system state info - Allow NM domtrans to iscsid_t if iscsiadm is executed - Allow slapd to send a signal itself - Allow sslget running as pki_ra_t to contact port 8443, the secure port of the CA. - Fix plymouthd_create_log() interface - Add rkhunter policy with files type definition for /var/lib/rkhunter until it is fixed in rkhunter package - Add mozilla_plugin_exec_t for /usr/lib/firefox/plugin-container - Allow postfix and cyrus-imapd to work out of box - Allow fcoemon to talk with unpriv user domain using unix_stream_socket - Dontaudit domains that are calling into journald to net_admin - Add rules to allow vmtools to do what it does - snapperd is D-Bus service - Allow OpenLMI PowerManagement to call 'systemctl --force reboot' - Add haproxy_connect_any boolean - Allow haproxy also to use http cache port by default Resolves:#1058248- Allow apache to write to the owncloud data directory in /var/www/html... - Allow consolekit to create log dir - Add support for icinga CGI scripts - Add support for icinga - Allow kdumpctl_t to create kdump lock file Resolves:#1055634 - Allow kdump to create lnk lock file - Allow nscd_t block_suspen capability - Allow unconfined domain types to manage own transient unit file - Allow systemd domains to handle transient init unit files - Add interfaces to handle transient- Add cron unconfined role support for uncofined SELinux user - Call corenet_udp_bind_all_ports() in milter.te - Allow fence_virtd to connect to zented port - Fix header for mirrormanager_admin() - Allow dkim-milter to bind udp ports - Allow milter domains to send signull itself - Allow block_suspend for yum running as mock_t - Allow beam.smp to manage couchdb files - Add couchdb_manage_files() - Add labeling for /var/log/php_errors.log - Allow bumblebee to stream connect to xserver - Allow bumblebee to send a signal to xserver - gnome-thumbnail to stream connect to bumblebee - Allow xkbcomp running as bumblebee_t to execute bin_t - Allow logrotate to read squid.conf - Additional rules to get docker and lxc to play well with SELinux - Allow bumbleed to connect to xserver port - Allow pegasus_openlmi_storage_t to read hwdata- Allow init_t to work on transitient and snapshot unit files - Add logging_manage_syslog_config() - Update sysnet_dns_name_resolve() to allow connect to dnssec por - Allow pegasus_openlmi_storage_t to read hwdata Resolves:#1031721 - Fix rhcs_rw_cluster_tmpfs() - Allow fenced_t to bind on zented udp port - Added policy for vmtools - Fix mirrormanager_read_lib_files() - Allow mirromanager scripts running as httpd_t to manage mirrormanager pid files - Allow ctdb to create sock files in /var/run/ctdb - Add sblim_filetrans_named_content() interface - Allow rpm scritplets to create /run/gather with correct labeling - Allow gnome keyring domains to create gnome config dirs - Dontaudit read/write to init stream socket for lsmd_plugin_t - Allow automount to read nfs link files - Allow lsm plugins to read/write lsmd stream socket - Allow certmonger to connect ldap port to make IPA CA certificate renewal working. - Add also labeling for /var/run/ctdb - Add missing labeling for /var/lib/ctdb - ALlow tuned to manage syslog.conf. Should be fixed in tuned. #1030446 - Dontaudit hypervkvp to search homedirs - Dontaudit hypervkvp to search admin homedirs - Allow hypervkvp to execute bin_t and ifconfig in the caller domain - Dontaudit xguest_t to read ABRT conf files - Add abrt_dontaudit_read_config() - Allow namespace-init to getattr on fs - Add thumb_role() also for xguest - Add filename transitions to create .spamassassin with correct labeling - Allow apache domain to read mirrormanager pid files - Allow domains to read/write shm and sem owned by mozilla_plugin_t - Allow alsactl to send a generic signal to kernel_t- Add back rpm_run() for unconfined user- Add missing files_create_var_lib_dirs() - Fix typo in ipsec.te - Allow passwd to create directory in /var/lib - Add filename trans also for event21 - Allow iptables command to read /dev/rand - Add sigkill capabilityfor ipsec_t - Add filename transitions for bcache devices - Add additional rules to create /var/log/cron by syslogd_t with correct labeling - Add give everyone full access to all key rings - Add default lvm_var_run_t label for /var/run/multipathd - Fix log labeling to have correct default label for them after logrotate - Labeled ~/.nv/GLCache as being gstreamer output - Allow nagios_system_plugin to read mrtg lib files - Add mrtg_read_lib_files() - Call rhcs_rw_cluster_tmpfs for dlm_controld - Make authconfing as named_filetrans domain - Allow virsh to connect to user process using stream socket - Allow rtas_errd to read rand/urand devices and add chown capability - Fix labeling from /var/run/net-snmpd to correct /var/run/net-snmp Resolves:#1051497 - Add also chown cap for abrt_upload_watch_t. It already has dac_override - Allow sosreport to manage rhsmcertd pid files - Add rhsmcertd_manage_pid_files() - Allow also setgid cap for rpc.gssd - Dontaudit access check for abrt on cert_t - Allow pegasus_openlmi_system providers to dbus chat with systemd-logind- Fix semanage import handling in spec file- Add default lvm_var_run_t label for /var/run/multipathd Resolves:#1051430 - Fix log labeling to have correct default label for them after logrotate - Add files_write_root_dirs - Add new openflow port label for 6653/tcp and 6633/tcp - Add xserver_manage_xkb_libs() - Label tcp/8891 as milter por - Allow gnome_manage_generic_cache_files also create cache_home_t files - Fix aide.log labeling - Fix log labeling to have correct default label for them after logrotate - Allow mysqld-safe write access on /root to make mysqld working - Allow sosreport domtrans to prelikn - Allow OpenvSwitch to connec to openflow ports - Allow NM send dgram to lldpad - Allow hyperv domains to execute shell - Allow lsmd plugins stream connect to lsmd/init - Allow sblim domains to create /run/gather with correct labeling - Allow httpd to read ldap certs - Allow cupsd to send dbus msgs to process with different MLS level - Allow bumblebee to stream connect to apmd - Allow bumblebee to run xkbcomp - Additional allow rules to get libvirt-lxc containers working with docker - Additional allow rules to get libvirt-lxc containers working with docker - Allow docker to getattr on itself - Additional rules needed for sandbox apps - Allow mozilla_plugin to set attributes on usb device if use_spice boolean enabled - httpd should be able to send signal/signull to httpd_suexec_t - Add more fixes for neturon. Domtrans to dnsmasq, iptables. Make neutron as filenamtrans domain.- Add neutron fixes- Allow sshd to write to all process levels in order to change passwd when running at a level - Allow updpwd_t to downgrade /etc/passwd file to s0, if it is not running with this range - Allow apcuspd_t to status and start the power unit file - Allow udev to manage kdump unit file - Added new interface modutils_dontaudit_exec_insmod - Allow cobbler to search dhcp_etc_t directory - systemd_systemctl needs sys_admin capability - Allow sytemd_tmpfiles_t to delete all directories - passwd to create gnome-keyring passwd socket - Add missing zabbix_var_lib_t type - Fix filename trans for zabbixsrv in zabbix.te - Allow fprintd_t to send syslog messages - Add zabbix_var_lib_t for /var/lib/zabbixsrv, also allow zabix to connect to smtp port - Allow mozilla plugin to chat with policykit, needed for spice - Allow gssprozy to change user and gid, as well as read user keyrings - Label upgrades directory under /var/www as httpd_sys_rw_content_t, add other filetrans rules to label content correctly - Allow polipo to connect to http_cache_ports - Allow cron jobs to manage apache var lib content - Allow yppassword to manage the passwd_file_t - Allow showall_t to send itself signals - Allow cobbler to restart dhcpc, dnsmasq and bind services - Allow certmonger to manage home cert files - Add userdom filename trans for user mail domains - Allow apcuspd_t to status and start the power unit file - Allow cgroupdrulesengd to create content in cgoups directories - Allow smbd_t to signull cluster - Allow gluster daemon to create fifo files in glusterd_brick_t and sock_file in glusterd_var_lib_t - Add label for /var/spool/cron.aquota.user - Allow sandbox_x domains to use work with the mozilla plugin semaphore - Added new policy for speech-dispatcher - Added dontaudit rule for insmod_exec_t in rasdaemon policy - Updated rasdaemon policy - Allow system_mail_t to transition to postfix_postdrop_t - Clean up mirrormanager policy - Allow virt_domains to read cert files, needs backport to RHEL7 - Allow sssd to read systemd_login_var_run_t - Allow irc_t to execute shell and bin-t files: - Add new access for mythtv - Allow rsync_t to manage all non auth files - allow modemmanger to read /dev/urand - Allow sandbox apps to attempt to set and get capabilties- Add labeling for /var/lib/servicelog/servicelog.db-journal - Add support for freeipmi port - Add sysadm_u_default_contexts - Make new type to texlive files in homedir - Allow subscription-manager running as sosreport_t to manage rhsmcertd - Additional fixes for docker.te - Remove ability to do mount/sys_admin by default in virt_sandbox domains - New rules required to run docker images within libivrt - Add label for ~/.cvsignore - Change mirrormanager to be run by cron - Add mirrormanager policy - Fixed bumblebee_admin() and mip6d_admin() - Add log support for sensord - Fix typo in docker.te - Allow amanda to do backups over UDP - Allow bumblebee to read /etc/group and clean up bumblebee.te - type transitions with a filename not allowed inside conditionals - Don't allow virt-sandbox tools to use netlink out of the box, needs back port to RHEL7 - Make new type to texlive files in homedir- Allow freeipmi_ipmidetectd_t to use freeipmi port - Update freeipmi_domain_template() - Allow journalctl running as ABRT to read /run/log/journal - Allow NM to read dispatcher.d directory - Update freeipmi policy - Type transitions with a filename not allowed inside conditionals - Allow tor to bind to hplip port - Make new type to texlive files in homedir - Allow zabbix_agent to transition to dmidecode - Add rules for docker - Allow sosreport to send signull to unconfined_t - Add virt_noatsecure and virt_rlimitinh interfaces - Fix labeling in thumb.fc to add support for /usr/lib64/tumbler-1/tumblerddd support for freeipmi port - Add sysadm_u_default_contexts - Add logging_read_syslog_pid() - Fix userdom_manage_home_texlive() interface - Make new type to texlive files in homedir - Add filename transitions for /run and /lock links - Allow virtd to inherit rlimit information Resolves:#975358- Change labeling for /usr/libexec/nm-dispatcher.action to NetworkManager_exec_t Resolves:#1039879 - Add labeling for /usr/lib/systemd/system/mariadb.service - Allow hyperv_domain to read sysfs - Fix ldap_read_certs() interface to allow acess also link files - Add support for /usr/libexec/pegasus/cmpiLMI_Journald-cimprovagt - Allow tuned to run modprobe - Allow portreserve to search /var/lib/sss dir - Add SELinux support for the teamd package contains team network device control daemon. - Dontaudit access check on /proc for bumblebee - Bumblebee wants to load nvidia modules - Fix rpm_named_filetrans_log_files and wine.te - Add conman policy for rawhide - DRM master and input event devices are used by the TakeDevice API - Clean up bumblebee policy - Update pegasus_openlmi_storage_t policy - Add freeipmi_stream_connect() interface - Allow logwatch read madm.conf to support RAID setup - Add raid_read_conf_files() interface - Allow up2date running as rpm_t create up2date log file with rpm_log_t labeling - add rpm_named_filetrans_log_files() interface - Allow dkim-milter to create files/dirs in /tmp - update freeipmi policy - Add policy for freeipmi services - Added rdisc_admin and rdisc_systemctl interfaces - opensm policy clean up - openwsman policy clean up - ninfod policy clean up - Added new policy for ninfod - Added new policy for openwsman - Added rdisc_admin and rdisc_systemctl interfaces - Fix kernel_dontaudit_access_check_proc() - Add support for /dev/uhid - Allow sulogin to get the attributes of initctl and sys_admin cap - Add kernel_dontaudit_access_check_proc() - Fix dev_rw_ipmi_dev() - Fix new interface in devices.if - DRM master and input event devices are used by the TakeDevice API - add dev_rw_inherited_dri() and dev_rw_inherited_input_dev() - Added support for default conman port - Add interfaces for ipmi devices- Allow sosreport to send a signal to ABRT - Add proper aliases for pegasus_openlmi_service_exec_t and pegasus_openlmi_service_t - Label /usr/sbin/htcacheclean as httpd_exec_t Resolves:#1037529 - Added support for rdisc unit file - Add antivirus_db_t labeling for /var/lib/clamav-unofficial-sigs - Allow runuser running as logrotate connections to system DBUS - Label bcache devices as fixed_disk_device_t - Allow systemctl running in ipsec_mgmt_t to access /usr/lib/systemd/system/ipsec.service - Label /usr/lib/systemd/system/ipsec.service as ipsec_mgmt_unit_file_t- Add back setpgid/setsched for sosreport_t- Added fix for clout_init to transition to rpm_script_t (dwalsh@redhat.com)- Dontaudit openshift domains trying to use rawip_sockets, this is caused by a bad check in the kernel. - Allow git_system_t to read git_user_content if the git_system_enable_homedirs boolean is turned on - Add lsmd_plugin_t for lsm plugins - Allow dovecot-deliver to search mountpoints - Add labeling for /etc/mdadm.conf - Allow opelmi admin providers to dbus chat with init_t - Allow sblim domain to read /dev/urandom and /dev/random - Allow apmd to request the kernel load modules - Add glusterd_brick_t type - label mate-keyring-daemon with gkeyringd_exec_t - Add plymouthd_create_log() - Dontaudit leaks from openshift domains into mail domains, needs back port to RHEL6 - Allow sssd to request the kernel loads modules - Allow gpg_agent to use ssh-add - Allow gpg_agent to use ssh-add - Dontaudit access check on /root for myslqd_safe_t - Allow ctdb to getattr on al filesystems - Allow abrt to stream connect to syslog - Allow dnsmasq to list dnsmasq.d directory - Watchdog opens the raw socket - Allow watchdog to read network state info - Dontaudit access check on lvm lock dir - Allow sosreport to send signull to setroubleshootd - Add setroubleshoot_signull() interface - Fix ldap_read_certs() interface - Allow sosreport all signal perms - Allow sosreport to run systemctl - Allow sosreport to dbus chat with rpm - Add glusterd_brick_t files type - Allow zabbix_agentd to read all domain state - Clean up rtas.if - Allow smoltclient to execute ldconfig - Allow sosreport to request the kernel to load a module - Fix userdom_confined_admin_template() - Add back exec_content boolean for secadm, logadm, auditadm - Fix files_filetrans_system_db_named_files() interface - Allow sulogin to getattr on /proc/kcore - Add filename transition also for servicelog.db-journal - Add files_dontaudit_access_check_root() - Add lvm_dontaudit_access_check_lock() interface- Allow watchdog to read /etc/passwd - Allow browser plugins to connect to bumblebee - New policy for bumblebee and freqset - Add new policy for mip6d daemon - Add new policy for opensm daemon - Allow condor domains to read/write condor_master udp_socket - Allow openshift_cron_t to append to openshift log files, label /var/log/openshift - Add back file_pid_filetrans for /var/run/dlm_controld - Allow smbd_t to use inherited tmpfs content - Allow mcelog to use the /dev/cpu device - sosreport runs rpcinfo - sosreport runs subscription-manager - Allow staff_t to run frequency command - Allow systemd_tmpfiles to relabel log directories - Allow staff_t to read xserver_log file - Label hsperfdata_root as tmp_t- More sosreport fixes to make ABRT working- Fix files_dontaudit_unmount_all_mountpoints() - Add support for 2608-2609 tcp/udp ports - Should allow domains to lock the terminal device - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - We need to require passwd rootok - Fix zebra.fc - Fix dnsmasq_filetrans_named_content() interface - Allow all sandbox domains create content in svirt_home_t - Allow zebra domains also create zebra_tmp_t files in /tmp - Add support for new zebra services:isisd,babeld. Add systemd support for zebra services. - Fix labeling on neutron and remove transition to iconfig_t - abrt needs to read mcelog log file - Fix labeling on dnsmasq content - Fix labeling on /etc/dnsmasq.d - Allow glusterd to relabel own lib files - Allow sandbox domains to use pam_rootok, and dontaudit attempts to unmount file systems, this is caused by a bug in systemd - Allow ipc_lock for abrt to run journalctl- Fix config.tgz- Fix passenger_stream_connect interface - setroubleshoot_fixit wants to read network state - Allow procmail_t to connect to dovecot stream sockets - Allow cimprovagt service providers to read network states - Add labeling for /var/run/mariadb - pwauth uses lastlog() to update system's lastlog - Allow account provider to read login records - Add support for texlive2013 - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - Allow passwd_t to connect to gnome keyring to change password - Update mls config files to have cronjobs in the user domains - Remove access checks that systemd does not actually do- Add support for yubikey in homedir - Add support for upd/3052 port - Allow apcupsd to use PowerChute Network Shutdown - Allow lsmd to execute various lsmplugins - Add labeling also for /etc/watchdog\.d where are watchdog scripts located too - Update gluster_export_all_rw boolean to allow relabel all base file types - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling- Add files_relabel_base_file_types() interface - Allow netlabel-config to read passwd - update gluster_export_all_rw boolean to allow relabel all base file types caused by lsetxattr() - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling - Allow pegasus to domtrans to mount_t - Add labeling for unconfined scripts in /usr/libexec/watchdog/scripts - Add support for unconfined watchdog scripts - Allow watchdog to manage own log files- Add label only for redhat.repo instead of /etc/yum.repos.d. But probably we will need to switch for the directory. - Label /etc/yum.repos.d as system_conf_t - Use sysnet_filetrans_named_content in udev.te instead of generic transition for net_conf_t - Allow dac_override for sysadm_screen_t - Allow init_t to read ipsec_conf_t as we had it for initrc_t. Needed by ipsec unit file. - Allow netlabel-config to read meminfo - Add interface to allow docker to mounton file_t - Add new interface to exec unlabeled files - Allow lvm to use docker semaphores - Setup transitons for .xsessions-errors.old - Change labels of files in /var/lib/*/.ssh to transition properly - Allow staff_t and user_t to look at logs using journalctl - pluto wants to manage own log file - Allow pluto running as ipsec_t to create pluto.log - Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Allow dmidecode to read/write /run/lock/subsys/rhsmcertd - Allow rhsmcertd to manage redhat.repo which is now labeled as system.conf. Allow rhsmcertd to manage all log files. - Additional access for docker - Added more rules to sblim policy - Fix kdumpgui_run_bootloader boolean - Allow dspam to connect to lmtp port - Included sfcbd service into sblim policy - rhsmcertd wants to manaage /etc/pki/consumer dir - Add kdumpgui_run_bootloader boolean - Add support for /var/cache/watchdog - Remove virt_domain attribute for virt_qemu_ga_unconfined_t - Fixes for handling libvirt containes - Dontaudit attempts by mysql_safe to write content into / - Dontaudit attempts by system_mail to modify network config - Allow dspam to bind to lmtp ports - Add new policy to allow staff_t and user_t to look at logs using journalctl - Allow apache cgi scripts to list sysfs - Dontaudit attempts to write/delete user_tmp_t files - Allow all antivirus domains to manage also own log dirs - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Add missing permission checks for nscd- Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Add file transition rules for content created by f5link - Rename quantum_port information to neutron - Allow all antivirus domains to manage also own log dirs - Rename quantum_port information to neutron - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Allow sysadm_t to read login information - Allow systemd_tmpfiles to setattr on var_log_t directories - Udpdate Makefile to include systemd_contexts - Add systemd_contexts - Add fs_exec_hugetlbfs_files() interface - Add daemons_enable_cluster_mode boolean - Fix rsync_filetrans_named_content() - Add rhcs_read_cluster_pid_files() interface - Update rhcs.if with additional interfaces from RHEL6 - Fix rhcs_domain_template() to not create run dirs with cluster_var_run_t - Allow glusterd_t to mounton glusterd_tmp_t - Allow glusterd to unmout al filesystems - Allow xenstored to read virt config - Add label for swift_server.lock and make add filetrans_named_content to make sure content gets created with the correct label - Allow mozilla_plugin_t to mmap hugepages as an executable- Add back userdom_security_admin_template() interface and use it for sysadm_t if sysadm_secadm.pp- Allow sshd_t to read openshift content, needs backport to RHEL6.5 - Label /usr/lib64/sasl2/libsasldb.so.3.0.0 as textrel_shlib_t - Make sur kdump lock is created with correct label if kdumpctl is executed - gnome interface calls should always be made within an optional_block - Allow syslogd_t to connect to the syslog_tls port - Add labeling for /var/run/charon.ctl socket - Add kdump_filetrans_named_content() - Allo setpgid for fenced_t - Allow setpgid and r/w cluster tmpfs for fenced_t - gnome calls should always be within optional blocks - wicd.pid should be labeled as networkmanager_var_run_t - Allow sys_resource for lldpad- Add rtas policy- Allow mailserver_domains to manage and transition to mailman data - Dontaudit attempts by mozilla plugin to relabel content, caused by using mv and cp commands - Allow mailserver_domains to manage and transition to mailman data - Allow svirt_domains to read sysctl_net_t - Allow thumb_t to use tmpfs inherited from the user - Allow mozilla_plugin to bind to the vnc port if running with spice - Add new attribute to discover confined_admins and assign confined admin to it - Fix zabbix to handle attributes in interfaces - Fix zabbix to read system states for all zabbix domains - Fix piranha_domain_template() - Allow ctdbd to create udp_socket. Allow ndmbd to access ctdbd var files. - Allow lldpad sys_rouserce cap due to #986870 - Allow dovecot-auth to read nologin - Allow openlmi-networking to read /proc/net/dev - Allow smsd_t to execute scripts created on the fly labeled as smsd_spool_t - Add zabbix_domain attribute for zabbix domains to treat them together - Add labels for zabbix-poxy-* (#1018221) - Update openlmi-storage policy to reflect #1015067 - Back port piranha tmpfs fixes from RHEL6 - Update httpd_can_sendmail boolean to allow read/write postfix spool maildrop - Add postfix_rw_spool_maildrop_files interface - Call new userdom_admin_user_templat() also for sysadm_secadm.pp - Fix typo in userdom_admin_user_template() - Allow SELinux users to create coolkeypk11sE-Gate in /var/cache/coolkey - Add new attribute to discover confined_admins - Fix labeling for /etc/strongswan/ipsec.d - systemd_logind seems to pass fd to anyone who dbus communicates with it - Dontaudit leaked write descriptor to dmesg- Activate motion policy- Fix gnome_read_generic_data_home_files() - allow openshift_cgroup_t to read/write inherited openshift file types - Remove httpd_cobbler_content * from cobbler_admin interface - Allow svirt sandbox domains to setattr on chr_file and blk_file svirt_sandbox_file_t, so sshd will work within a container - Allow httpd_t to read also git sys content symlinks - Allow init_t to read gnome home data - Dontaudit setroubleshoot_fixit_t execmem, since it does not seem to really need it. - Allow virsh to execute systemctl - Fix for nagios_services plugins - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - Fix hypervkvp.te - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Fix logging policy - Allow syslog to bind to tls ports - Update labeling for /dev/cdc-wdm - Allow to su_domain to read init states - Allow init_t to read gnome home data - Make sure if systemd_logind creates nologin file with the correct label - Clean up ipsec.te- Add auth_exec_chkpwd interface - Fix port definition for ctdb ports - Allow systemd domains to read /dev/urand - Dontaudit attempts for mozilla_plugin to append to /dev/random - Add label for /var/run/charon.* - Add labeling for /usr/lib/systemd/system/lvm2.*dd policy for motion service - Fix for nagios_services plugins - Fix some bugs in zoneminder policy - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - glusterd binds to random unreserved ports - Additional allow rules found by testing glusterfs - apcupsd needs to send a message to all users on the system so needs to look them up - Fix the label on ~/.juniper_networks - Dontaudit attempts for mozilla_plugin to append to /dev/random - Allow polipo_daemon to connect to flash ports - Allow gssproxy_t to create replay caches - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type- init reload from systemd_localed_t - Allow domains that communicate with systemd_logind_sessions to use systemd_logind_t fd - Allow systemd_localed_t to ask systemd to reload the locale. - Add systemd_runtime_unit_file_t type for unit files that systemd creates in memory - Allow readahead to read /dev/urand - Fix lots of avcs about tuned - Any file names xenstored in /var/log should be treated as xenstored_var_log_t - Allow tuned to inderact with hugepages - Allow condor domains to list etc rw dirs- Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Add additional fixes forpegasus_openlmi_account_t - Allow mdadm to read /dev/urand - Allow pegasus_openlmi_storage_t to create mdadm.conf and write it - Add label/rules for /etc/mdadm.conf - Allow pegasus_openlmi_storage_t to transition to fsadm_t - Fixes for interface definition problems - Dontaudit dovecot-deliver to gettatr on all fs dirs - Allow domains to search data_home_t directories - Allow cobblerd to connect to mysql - Allow mdadm to r/w kdump lock files - Add support for kdump lock files - Label zarafa-search as zarafa-indexer - Openshift cgroup wants to read /etc/passwd - Add new sandbox domains for kvm - Allow mpd to interact with pulseaudio if mpd_enable_homedirs is turned on - Fix labeling for /usr/lib/systemd/system/lvm2.* - Add labeling for /usr/lib/systemd/system/lvm2.* - Fix typos to get a new build. We should not cover filename trans rules to prevent duplicate rules - Add sshd_keygen_t policy for sshd-keygen - Fix alsa_home_filetrans interface name and definition - Allow chown for ssh_keygen_t - Add fs_dontaudit_getattr_all_dirs() - Allow init_t to manage etc_aliases_t and read xserver_var_lib_t and chrony keys - Fix up patch to allow systemd to manage home content - Allow domains to send/recv unlabeled traffic if unlabelednet.pp is enabled - Allow getty to exec hostname to get info - Add systemd_home_t for ~/.local/share/systemd directory- Fix lxc labels in config.tgz- Fix labeling for /usr/libexec/kde4/kcmdatetimehelper - Allow tuned to search all file system directories - Allow alsa_t to sys_nice, to get top performance for sound management - Add support for MySQL/PostgreSQL for amavis - Allow openvpn_t to manage openvpn_var_log_t files. - Allow dirsrv_t to create tmpfs_t directories - Allow dirsrv to create dirs in /dev/shm with dirsrv_tmpfs label - Dontaudit leaked unix_stream_sockets into gnome keyring - Allow telepathy domains to inhibit pipes on telepathy domains - Allow cloud-init to domtrans to rpm - Allow abrt daemon to manage abrt-watch tmp files - Allow abrt-upload-watcher to search /var/spool directory - Allow nsswitch domains to manage own process key - Fix labeling for mgetty.* logs - Allow systemd to dbus chat with upower - Allow ipsec to send signull to itself - Allow setgid cap for ipsec_t - Match upstream labeling- Do not build sanbox pkg on MLS- wine_tmp is no longer needed - Allow setroubleshoot to look at /proc - Allow telepathy domains to dbus with systemd logind - Fix handling of fifo files of rpm - Allow mozilla_plugin to transition to itself - Allow certwatch to write to cert_t directories - New abrt application - Allow NetworkManager to set the kernel scheduler - Make wine_domain shared by all wine domains - Allow mdadm_t to read images labeled svirt_image_t - Allow amanda to read /dev/urand - ALlow my_print_default to read /dev/urand - Allow mdadm to write to kdumpctl fifo files - Allow nslcd to send signull to itself - Allow yppasswd to read /dev/urandom - Fix zarafa_setrlimit - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add additional alias for user_tmp_t because wine_tmp_t is no longer used - More handling of ther kernel keyring required by kerberos - New privs needed for init_t when running without transition to initrc_t over bin_t, and without unconfined domain installed- Dontaudit attempts by sosreport to read shadow_t - Allow browser sandbox plugins to connect to cups to print - Add new label mpd_home_t - Label /srv/www/logs as httpd_log_t - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add labels for apache logs under miq package - Allow irc_t to use tcp sockets - fix labels in puppet.if - Allow tcsd to read utmp file - Allow openshift_cron_t to run ssh-keygen in ssh_keygen_t to access host keys - Define svirt_socket_t as a domain_type - Take away transition from init_t to initrc_t when executing bin_t, allow init_t to run chk_passwd_t - Fix label on pam_krb5 helper apps- Allow ldconfig to write to kdumpctl fifo files - allow neutron to connect to amqp ports - Allow kdump_manage_crash to list the kdump_crash_t directory - Allow glance-api to connect to amqp port - Allow virt_qemu_ga_t to read meminfo - Add antivirus_home_t type for antivirus date in HOMEDIRS - Allow mpd setcap which is needed by pulseaudio - Allow smbcontrol to create content in /var/lib/samba - Allow mozilla_exec_t to be used as a entrypoint to mozilla_domtrans_spec - Add additional labeling for qemu-ga/fsfreeze-hook.d scripts - amanda_exec_t needs to be executable file - Allow block_suspend cap for samba-net - Allow apps that read ipsec_mgmt_var_run_t to search ipsec_var_run_t - Allow init_t to run crash utility - Treat usr_t just like bin_t for transitions and executions - Add port definition of pka_ca to port 829 for openshift - Allow selinux_store to use symlinks- Allow block_suspend cap for samba-net - Allow t-mission-control to manage gabble cache files - Allow nslcd to read /sys/devices/system/cpu - Allow selinux_store to use symlinks- Allow xdm_t to transition to itself - Call neutron interfaces instead of quantum - Allow init to change targed role to make uncofined services (xrdp which now has own systemd unit file) working. We want them to have in unconfined_t - Make sure directories in /run get created with the correct label - Make sure /root/.pki gets created with the right label - try to remove labeling for motion from zoneminder_exec_t to bin_t - Allow inetd_t to execute shell scripts - Allow cloud-init to read all domainstate - Fix to use quantum port - Add interface netowrkmanager_initrc_domtrans - Fix boinc_execmem - Allow t-mission-control to read gabble cache home - Add labeling for ~/.cache/telepathy/avatars/gabble - Allow memcache to read sysfs data - Cleanup antivirus policy and add additional fixes - Add boolean boinc_enable_execstack - Add support for couchdb in rabbitmq policy - Add interface couchdb_search_pid_dirs - Allow firewalld to read NM state - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files()- Split out rlogin ports from inetd - Treat files labeld as usr_t like bin_t when it comes to transitions - Allow staff_t to read login config - Allow ipsec_t to read .google authenticator data - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files() - Call the correct interface - corenet_udp_bind_ktalkd_port() - Allow all domains that can read gnome_config to read kde config - Allow sandbox domain to read/write mozilla_plugin_tmpfs_t so pulseaudio will work - Allow mdadm to getattr any file system - Allow a confined domain to executes mozilla_exec_t via dbus - Allow cupsd_lpd_t to bind to the printer port - Dontaudit attempts to bind to ports < 1024 when nis is turned on - Allow apache domain to connect to gssproxy socket - Allow rlogind to bind to the rlogin_port - Allow telnetd to bind to the telnetd_port - Allow ktalkd to bind to the ktalkd_port - Allow cvs to bind to the cvs_port- Cleanup related to init_domain()+inetd_domain fixes - Use just init_domain instead of init_daemon_domain in inetd_core_service_domain - svirt domains neeed to create kobject_uevint_sockets - Lots of new access required for sosreport - Allow tgtd_t to connect to isns ports - Allow init_t to transition to all inetd domains: - openct needs to be able to create netlink_object_uevent_sockets - Dontaudit leaks into ldconfig_t - Dontaudit su domains getattr on /dev devices, move su domains to attribute based calls - Move kernel_stream_connect into all Xwindow using users - Dontaudit inherited lock files in ifconfig o dhcpc_t- Also sock_file trans rule is needed in lsm - Fix labeling for fetchmail pid files/dirs - Add additional fixes for abrt-upload-watch - Fix polipo.te - Fix transition rules in asterisk policy - Add fowner capability to networkmanager policy - Allow polipo to connect to tor ports - Cleanup lsmd.if - Cleanup openhpid policy - Fix kdump_read_crash() interface - Make more domains as init domain - Fix cupsd.te - Fix requires in rpm_rw_script_inherited_pipes - Fix interfaces in lsm.if - Allow munin service plugins to manage own tmpfs files/dirs - Allow virtd_t also relabel unix stream sockets for virt_image_type - Make ktalk as init domain - Fix to define ktalkd_unit_file_t correctly - Fix ktalk.fc - Add systemd support for talk-server - Allow glusterd to create sock_file in /run - Allow xdm_t to delete gkeyringd_tmp_t files on logout - Add fixes for hypervkvp policy - Add logwatch_can_sendmail boolean - Allow mysqld_safe_t to handle also symlinks in /var/log/mariadb - Allow xdm_t to delete gkeyringd_tmp_t files on logout- Add selinux-policy-sandbox pkg0 - Allow rhsmcertd to read init state - Allow fsetid for pkcsslotd - Fix labeling for /usr/lib/systemd/system/pkcsslotd.service - Allow fetchmail to create own pid with correct labeling - Fix rhcs_domain_template() - Allow roles which can run mock to read mock lib files to view results - Allow rpcbind to use nsswitch - Fix lsm.if summary - Fix collectd_t can read /etc/passwd file - Label systemd unit files under dracut correctly - Add support for pam_mount to mount user's encrypted home When a user logs in and logs out using ssh - Add support for .Xauthority-n - Label umount.crypt as lvm_exec_t - Allow syslogd to search psad lib files - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files- Add policy for lsmd - Add support for /var/log/mariadb dir and allow mysqld_safe to list this directory - Update condor_master rules to allow read system state info and allow logging - Add labeling for /etc/condor and allow condor domain to write it (bug) - Allow condor domains to manage own logs - Allow glusterd to read domains state - Fix initial hypervkvp policy - Add policy for hypervkvpd - Fix redis.if summary- Allow boinc to connect to @/tmp/.X11-unix/X0 - Allow beam.smp to connect to tcp/5984 - Allow named to manage own log files - Add label for /usr/libexec/dcc/start-dccifd and domtrans to dccifd_t - Add virt_transition_userdomain boolean decl - Allow httpd_t to sendto unix_dgram sockets on its children - Allow nova domains to execute ifconfig - bluetooth wants to create fifo_files in /tmp - exim needs to be able to manage mailman data - Allow sysstat to getattr on all file systems - Looks like bluetoothd has moved - Allow collectd to send ping packets - Allow svirt_lxc domains to getpgid - Remove virt-sandbox-service labeling as virsh_exec_t, since it no longer does virsh_t stuff - Allow frpintd_t to read /dev/urandom - Allow asterisk_t to create sock_file in /var/run - Allow usbmuxd to use netlink_kobject - sosreport needs to getattr on lots of devices, and needs access to netlink_kobject_uevent_socket - More cleanup of svirt_lxc policy - virtd_lxc_t now talks to dbus - Dontaudit leaked ptmx_t - Allow processes to use inherited fifo files - Allow openvpn_t to connect to squid ports - Allow prelink_cron_system_t to ask systemd to reloaddd miscfiles_dontaudit_access_check_cert() - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files - Allow user roles to connect to the journal socket- selinux_set_enforce_mode needs to be used with type - Add append to the dontaudit for unix_stream_socket of xdm_t leak - Allow xdm_t to create symlinks in log direcotries - Allow login programs to read afs config - Label 10933 as a pop port, for dovecot - New policy to allow selinux_server.py to run as semanage_t as a dbus service - Add fixes to make netlabelctl working on MLS - AVCs required for running sepolicy gui as staff_t - Dontaudit attempts to read symlinks, sepolicy gui is likely to cause this type of AVC - New dbus server to be used with new gui - After modifying some files in /etc/mail, I saw this needed on the next boot - Loading a vm from /usr/tmp with virt-manager - Clean up oracleasm policy for Fedora - Add oracleasm policy written by rlopez@redhat.com - Make postfix_postdrop_t as mta_agent to allow domtrans to system mail if it is executed by apache - Add label for /var/crash - Allow fenced to domtrans to sanclok_t - Allow nagios to manage nagios spool files - Make tfptd as home_manager - Allow kdump to read kcore on MLS system - Allow mysqld-safe sys_nice/sys_resource caps - Allow apache to search automount tmp dirs if http_use_nfs is enabled - Allow crond to transition to named_t, for use with unbound - Allow crond to look at named_conf_t, for unbound - Allow mozilla_plugin_t to transition its home content - Allow dovecot_domain to read all system and network state - Allow httpd_user_script_t to call getpw - Allow semanage to read pid files - Dontaudit leaked file descriptors from user domain into thumb - Make PAM authentication working if it is enabled in ejabberd - Add fixes for rabbit to fix ##992920,#992931 - Allow glusterd to mount filesystems - Loading a vm from /usr/tmp with virt-manager - Trying to load a VM I got an AVC from devicekit_disk for loopcontrol device - Add fix for pand service - shorewall touches own log - Allow nrpe to list /var - Mozilla_plugin_roles can not be passed into lpd_run_lpr - Allow afs domains to read afs_config files - Allow login programs to read afs config - Allow virt_domain to read virt_var_run_t symlinks - Allow smokeping to send its process signals - Allow fetchmail to setuid - Add kdump_manage_crash() interface - Allow abrt domain to write abrt.socket- Add more aliases in pegasus.te - Add more fixes for *_admin interfaces - Add interface fixes - Allow nscd to stream connect to nmbd - Allow gnupg apps to write to pcscd socket - Add more fixes for openlmi provides. Fix naming and support for additionals - Allow fetchmail to resolve host names - Allow firewalld to interact also with lnk files labeled as firewalld_etc_rw_t - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te - Fix corecmd_exec_chroot() - Fix logging_relabel_syslog_pid_socket interface - Fix typo in unconfineduser.te - Allow system_r to access unconfined_dbusd_t to run hp_chec- Allow xdm_t to act as a dbus client to itsel - Allow fetchmail to resolve host names - Allow gnupg apps to write to pcscd socket - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te -httpd_t does access_check on certs- Add support for cmpiLMI_Service-cimprovagt - Allow pegasus domtrans to rpm_t to make pycmpiLMI_Software-cimprovagt running as rpm_t - Label pycmpiLMI_Software-cimprovagt as rpm_exec_t - Add support for pycmpiLMI_Storage-cimprovagt - Add support for cmpiLMI_Networking-cimprovagt - Allow system_cronjob_t to create user_tmpfs_t to make pulseaudio working - Allow virtual machines and containers to run as user doains, needed for virt-sandbox - Allow buglist.cgi to read cpu info- Allow systemd-tmpfile to handle tmp content in print spool dir - Allow systemd-sysctl to send system log messages - Add support for RTP media ports and fmpro-internal - Make auditd working if audit is configured to perform SINGLE action on disk error - Add interfaces to handle systemd units - Make systemd-notify working if pcsd is used - Add support for netlabel and label /usr/sbin/netlabelctl as iptables_exec_t - Instead of having all unconfined domains get all of the named transition rules, - Only allow unconfined_t, init_t, initrc_t and rpm_script_t by default. - Add definition for the salt ports - Allow xdm_t to create link files in xdm_var_run_t - Dontaudit reads of blk files or chr files leaked into ldconfig_t - Allow sys_chroot for useradd_t - Allow net_raw cap for ipsec_t - Allow sysadm_t to reload services - Add additional fixes to make strongswan working with a simple conf - Allow sysadm_t to enable/disable init_t services - Add additional glusterd perms - Allow apache to read lnk files in the /mnt directory - Allow glusterd to ask the kernel to load a module - Fix description of ftpd_use_fusefs boolean - Allow svirt_lxc_net_t to sys_chroot, modify policy to tighten up svirt_lxc_domain capabilties and process controls, but add them to svirt_lxc_net_t - Allow glusterds to request load a kernel module - Allow boinc to stream connect to xserver_t - Allow sblim domains to read /etc/passwd - Allow mdadm to read usb devices - Allow collectd to use ping plugin - Make foghorn working with SNMP - Allow sssd to read ldap certs - Allow haproxy to connect to RTP media ports - Add additional trans rules for aide_db - Add labeling for /usr/lib/pcsd/pcsd - Add labeling for /var/log/pcsd - Add support for pcs which is a corosync and pacemaker configuration tool- Label /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t - Add labeling for /usr/libexec/kde4/polkit-kde-authentication-agent-1 - Allow all domains that can domtrans to shutdown, to start the power services script to shutdown - consolekit needs to be able to shut down system - Move around interfaces - Remove nfsd_rw_t and nfsd_ro_t, they don't do anything - Add additional fixes for rabbitmq_beam to allow getattr on mountpoints - Allow gconf-defaults-m to read /etc/passwd - Fix pki_rw_tomcat_cert() interface to support lnk_files- Add support for gluster ports - Make sure that all keys located in /etc/ssh/ are labeled correctly - Make sure apcuspd lock files get created with the correct label - Use getcap in gluster.te - Fix gluster policy - add additional fixes to allow beam.smp to interact with couchdb files - Additional fix for #974149 - Allow gluster to user gluster ports - Allow glusterd to transition to rpcd_t and add additional fixes for #980683 - Allow tgtd working when accessing to the passthrough device - Fix labeling for mdadm unit files- Add mdadm fixes- Fix definition of sandbox.disabled to sandbox.pp.disabled- Allow mdamd to execute systemctl - Allow mdadm to read /dev/kvm - Allow ipsec_mgmt_t to read l2tpd pid content- Allow nsd_t to read /dev/urand - Allow mdadm_t to read framebuffer - Allow rabbitmq_beam_t to read process info on rabbitmq_epmd_t - Allow mozilla_plugin_config_t to create tmp files - Cleanup openvswitch policy - Allow mozilla plugin to getattr on all executables - Allow l2tpd_t to create fifo_files in /var/run - Allow samba to touch/manage fifo_files or sock_files in a samba_share_t directory - Allow mdadm to connecto its own unix_stream_socket - FIXME: nagios changed locations to /log/nagios which is wrong. But we need to have this workaround for now. - Allow apache to access smokeping pid files - Allow rabbitmq_beam_t to getattr on all filesystems - Add systemd support for iodined - Allow nup_upsdrvctl_t to execute its entrypoint - Allow fail2ban_client to write to fail2ban_var_run_t, Also allow it to use nsswitch - add labeling for ~/.cache/libvirt-sandbox - Add interface to allow domains transitioned to by confined users to send sigchld to screen program - Allow sysadm_t to check the system status of files labeled etc_t, /etc/fstab - Allow systemd_localed to start /usr/lib/systemd/system/systemd-vconsole-setup.service - Allow an domain that has an entrypoint from a type to be allowed to execute the entrypoint without a transition, I can see no case where this is a bad thing, and elminiates a whole class of AVCs. - Allow staff to getsched all domains, required to run htop - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Add prosody policy written by Michael Scherer - Allow nagios plugins to read /sys info - ntpd needs to manage own log files - Add support for HOME_DIR/.IBMERS - Allow iptables commands to read firewalld config - Allow consolekit_t to read utmp - Fix filename transitions on .razor directory - Add additional fixes to make DSPAM with LDA working - Allow snort to read /etc/passwd - Allow fail2ban to communicate with firewalld over dbus - Dontaudit openshift_cgreoup_file_t read/write leaked dev - Allow nfsd to use mountd port - Call th proper interface - Allow openvswitch to read sys and execute plymouth - Allow tmpwatch to read /var/spool/cups/tmp - Add support for /usr/libexec/telepathy-rakia - Add systemd support for zoneminder - Allow mysql to create files/directories under /var/log/mysql - Allow zoneminder apache scripts to rw zoneminder tmpfs - Allow httpd to manage zoneminder lib files - Add zoneminder_run_sudo boolean to allow to start zoneminder - Allow zoneminder to send mails - gssproxy_t sock_file can be under /var/lib - Allow web domains to connect to whois port. - Allow sandbox_web_type to connect to the same ports as mozilla_plugin_t. - We really need to add an interface to corenet to define what a web_client_domain is and - then define chrome_sandbox_t, mozilla_plugin_t and sandbox_web_type to that domain. - Add labeling for cmpiLMI_LogicalFile-cimprovagt - Also make pegasus_openlmi_logicalfile_t as unconfined to have unconfined_domain attribute for filename trans rules - Update policy rules for pegasus_openlmi_logicalfile_t - Add initial types for logicalfile/unconfined OpenLMI providers - mailmanctl needs to read own log - Allow logwatch manage own lock files - Allow nrpe to read meminfo - Allow httpd to read certs located in pki-ca - Add pki_read_tomcat_cert() interface - Add support for nagios openshift plugins - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Shrink the size of policy by moving to attributes, also add dridomain so that mozilla_plugin can follow selinuxuse_dri boolean. - Allow bootloader to manage generic log files - Allow ftp to bind to port 989 - Fix label of new gear directory - Add support for new directory /var/lib/openshift/gears/ - Add openshift_manage_lib_dirs() - allow virtd domains to manage setrans_var_run_t - Allow useradd to manage all openshift content - Add support so that mozilla_plugin_t can use dri devices - Allow chronyd to change the scheduler - Allow apmd to shut downthe system - Devicekit_disk_t needs to manage /etc/fstab- Make DSPAM to act as a LDA working - Allow ntop to create netlink socket - Allow policykit to send a signal to policykit-auth - Allow stapserver to dbus chat with avahi/systemd-logind - Fix labeling on haproxy unit file - Clean up haproxy policy - A new policy for haproxy and placed it to rhcs.te - Add support for ldirectord and treat it with cluster_t - Make sure anaconda log dir is created with var_log_t- Allow lvm_t to create default targets for filesystem handling - Fix labeling for razor-lightdm binaries - Allow insmod_t to read any file labeled var_lib_t - Add policy for pesign - Activate policy for cmpiLMI_Account-cimprovagt - Allow isnsd syscall=listen - /usr/libexec/pegasus/cimprovagt needs setsched caused by sched_setscheduler - Allow ctdbd to use udp/4379 - gatherd wants sys_nice and setsched - Add support for texlive2012 - Allow NM to read file_t (usb stick with no labels used to transfer keys for example) - Allow cobbler to execute apache with domain transition- condor_collector uses tcp/9000 - Label /usr/sbin/virtlockd as virtd_exec_t for now - Allow cobbler to execute ldconfig - Allow NM to execute ssh - Allow mdadm to read /dev/crash - Allow antivirus domains to connect to snmp port - Make amavisd-snmp working correctly - Allow nfsd_t to mounton nfsd_fs_t - Add initial snapper policy - We still need to have consolekit policy - Dontaudit firefox attempting to connect to the xserver_port_t if run within sandbox_web_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow dirsrv to read network state - Fix pki_read_tomcat_lib_files - Add labeling for /usr/libexec/nm-ssh-service - Add label cert_t for /var/lib/ipa/pki-ca/publish - Lets label /sys/fs/cgroup as cgroup_t for now, to keep labels consistant - Allow nfsd_t to mounton nfsd_fs_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow passwd_t to change role to system_r from unconfined_r- Don't audit access checks by sandbox xserver on xdb var_lib - Allow ntop to read usbmon devices - Add labeling for new polcykit authorizor - Dontaudit access checks from fail2ban_client - Don't audit access checks by sandbox xserver on xdb var_lib - Allow apps that connect to xdm stream to conenct to xdm_dbusd_t stream - Fix labeling for all /usr/bim/razor-lightdm-* binaries - Add filename trans for /dev/md126p1- Make vdagent able to request loading kernel module - Add support for cloud-init make it as unconfined domain - Allow snmpd to run smartctl in fsadm_t domain - remove duplicate openshift_search_lib() interface - Allow mysqld to search openshift lib files - Allow openshift cgroup to interact with passedin file descriptors - Allow colord to list directories inthe users homedir - aide executes prelink to check files - Make sure cupsd_t creates content in /etc/cups with the correct label - Lest dontaudit apache read all domains, so passenger will not cause this avc - Allow gssd to connect to gssproxy - systemd-tmpfiles needs to be able to raise the level to fix labeling on /run/setrans in MLS - Allow systemd-tmpfiles to relabel also lock files - Allow useradd to add homdir in /var/lib/openshift - Allow setfiles and semanage to write output to /run/files- Add labeling for /dev/tgt - Dontaudit leak fd from firewalld for modprobe - Allow runuser running as rpm_script_t to create netlink_audit socket - Allow mdadm to read BIOS non-volatile RAM- accountservice watches when accounts come and go in wtmp - /usr/java/jre1.7.0_21/bin/java needs to create netlink socket - Add httpd_use_sasl boolean - Allow net_admin for tuned_t - iscsid needs sys_module to auto-load kernel modules - Allow blueman to read bluetooth conf - Add nova_manage_lib_files() interface - Fix mplayer_filetrans_home_content() - Add mplayer_filetrans_home_content() - mozilla_plugin_config_roles need to be able to access mozilla_plugin_config_t - Revert "Allow thumb_t to append inherited xdm stream socket" - Add iscsi_filetrans_named_content() interface - Allow to create .mplayer with the correct labeling for unconfined - Allow iscsiadmin to create lock file with the correct labeling- Allow wine to manage wine home content - Make amanda working with socket actiovation - Add labeling for /usr/sbin/iscsiadm - Add support for /var/run/gssproxy.sock - dnsmasq_t needs to read sysctl_net_t- Fix courier_domain_template() interface - Allow blueman to write ip_forward - Allow mongodb to connect to mongodb port - Allow mongodb to connect to mongodb port - Allow java to bind jobss_debug port - Fixes for *_admin interfaces - Allow iscsid auto-load kernel modules needed for proper iSCSI functionality - Need to assign attribute for courier_domain to all courier_domains - Fail2ban reads /etc/passwd - postfix_virtual will create new files in postfix_spool_t - abrt triggers sys_ptrace by running pidof - Label ~/abc as mozilla_home_t, since java apps as plugin want to create it - Add passenger fixes needed by foreman - Remove dup interfaces - Add additional interfaces for quantum - Add new interfaces for dnsmasq - Allow passenger to read localization and send signull to itself - Allow dnsmasq to stream connect to quantum - Add quantum_stream_connect() - Make sure that mcollective starts the service with the correct labeling - Add labels for ~/.manpath - Dontaudit attempts by svirt_t to getpw* calls - sandbox domains are trying to look at parent process data - Allow courior auth to create its pid file in /var/spool/courier subdir - Add fixes for beam to have it working with couchdb - Add labeling for /run/nm-xl2tpd.con - Allow apache to stream connect to thin - Add systemd support for amand - Make public types usable for fs mount points - Call correct mandb interface in domain.te - Allow iptables to r/w quantum inherited pipes and send sigchld - Allow ifconfig domtrans to iptables and execute ldconfig - Add labels for ~/.manpath - Allow systemd to read iscsi lib files - seunshare is trying to look at parent process data- Fix openshift_search_lib - Add support for abrt-uefioops-oops - Allow colord to getattr any file system - Allow chrome processes to look at each other - Allow sys_ptrace for abrt_t - Add new policy for gssproxy - Dontaudit leaked file descriptor writes from firewalld - openshift_net_type is interface not template - Dontaudit pppd to search gnome config - Update openshift_search_lib() interface - Add fs_list_pstorefs() - Fix label on libbcm_host.so since it is built incorrectly on raspberry pi, needs back port to F18 - Better labels for raspberry pi devices - Allow init to create devpts_t directory - Temporarily label rasbery pi devices as memory_device_t, needs back port to f18 - Allow sysadm_t to build kernels - Make sure mount creates /var/run/blkid with the correct label, needs back port to F18 - Allow userdomains to stream connect to gssproxy - Dontaudit leaked file descriptor writes from firewalld - Allow xserver to read /dev/urandom - Add additional fixes for ipsec-mgmt - Make SSHing into an Openshift Enterprise Node working- Add transition rules to unconfined domains and to sysadm_t to create /etc/adjtime - with the proper label. - Update files_filetrans_named_content() interface to get right labeling for pam.d conf files - Allow systemd-timedated to create adjtime - Add clock_create_adjtime() - Additional fix ifconfing for #966106 - Allow kernel_t to create boot.log with correct labeling - Remove unconfined_mplayer for which we don't have rules - Rename interfaces - Add userdom_manage_user_home_files/dirs interfaces - Fix files_dontaudit_read_all_non_security_files - Fix ipsec_manage_key_file() - Fix ipsec_filetrans_key_file() - Label /usr/bin/razor-lightdm-greeter as xdm_exec_t instead of spamc_exec_t - Fix labeling for ipse.secrets - Add interfaces for ipsec and labeling for ipsec.info and ipsec_setup.pid - Add files_dontaudit_read_all_non_security_files() interface - /var/log/syslog-ng should be labeled var_log_t - Make ifconfig_var_run_t a mountpoint - Add transition from ifconfig to dnsmasq - Allow ifconfig to execute bin_t/shell_exec_t - We want to have hwdb.bin labeled as etc_t - update logging_filetrans_named_content() interface - Allow systemd_timedate_t to manage /etc/adjtime - Allow NM to send signals to l2tpd - Update antivirus_can_scan_system boolean - Allow devicekit_disk_t to sys_config_tty - Run abrt-harvest programs as abrt_t, and allow abrt_t to list all filesystem directories - Make printing from vmware working - Allow php-cgi from php54 collection to access /var/lib/net-snmp/mib_indexes - Add virt_qemu_ga_data_t for qemu-ga - Make chrome and mozilla able to connect to same ports, add jboss_management_port_t to both - Fix typo in virt.te - Add virt_qemu_ga_unconfined_t for hook scripts - Make sure NetworkManager files get created with the correct label - Add mozilla_plugin_use_gps boolean - Fix cyrus to have support for net-snmp - Additional fixes for dnsmasq and quantum for #966106 - Add plymouthd_create_log() - remove httpd_use_oddjob for which we don't have rules - Add missing rules for httpd_can_network_connect_cobbler - Add missing cluster_use_execmem boolean - Call userdom_manage_all_user_home_type_files/dirs - Additional fix for ftp_home_dir - Fix ftp_home_dir boolean - Allow squit to recv/send client squid packet - Fix nut.te to have nut_domain attribute - Add support for ejabberd; TODO: revisit jabberd and rabbit policy - Fix amanda policy - Add more fixes for domains which use libusb - Make domains which use libusb working correctly - Allow l2tpd to create ipsec key files with correct labeling and manage them - Fix cobbler_manage_lib_files/cobbler_read_lib_files to cover also lnk files - Allow rabbitmq-beam to bind generic node - Allow l2tpd to read ipse-mgmt pid files - more fixes for l2tpd, NM and pppd from #967072- Dontaudit to getattr on dirs for dovecot-deliver - Allow raiudusd server connect to postgresql socket - Add kerberos support for radiusd - Allow saslauthd to connect to ldap port - Allow postfix to manage postfix_private_t files - Add chronyd support for #965457 - Fix labeling for HOME_DIR/\.icedtea - CHange squid and snmpd to be allowed also write own logs - Fix labeling for /usr/libexec/qemu-ga - Allow virtd_t to use virt_lock_t - Allow also sealert to read the policy from the kernel - qemu-ga needs to execute scripts in /usr/libexec/qemu-ga and to use /tmp content - Dontaudit listing of users homedir by sendmail Seems like a leak - Allow passenger to transition to puppet master - Allow apache to connect to mythtv - Add definition for mythtv ports- Add additional fixes for #948073 bug - Allow sge_execd_t to also connect to sge ports - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow sge_execd to bind sge ports. Allow kill capability and reads cgroup files - Remove pulseaudio filetrans pulseaudio_manage_home_dirs which is a part of pulseaudio_manage_home_files - Add networkmanager_stream_connect() - Make gnome-abrt wokring with staff_t - Fix openshift_manage_lib_files() interface - mdadm runs ps command which seems to getattr on random log files - Allow mozilla_plugin_t to create pulseaudit_home_t directories - Allow qemu-ga to shutdown virtual hosts - Add labelling for cupsd-browsed - Add web browser plugins to connect to aol ports - Allow nm-dhcp-helper to stream connect to NM - Add port definition for sge ports- Make sure users and unconfined domains create .hushlogin with the correct label - Allow pegaus to chat with realmd over DBus - Allow cobblerd to read network state - Allow boicn-client to stat on /dev/input/mice - Allow certwatch to read net_config_t when it executes apache - Allow readahead to create /run/systemd and then create its own directory with the correct label- Transition directories and files when in a user_tmp_t directory - Change certwatch to domtrans to apache instead of just execute - Allow virsh_t to read xen lib files - update policy rules for pegasus_openlmi_account_t - Add support for svnserve_tmp_t - Activate account openlmi policy - pegasus_openlmi_domain_template needs also require pegasus_t - One more fix for policykit.te - Call fs_list_cgroups_dirs() in policykit.te - Allow nagios service plugin to read mysql config files - Add labeling for /var/svn - Fix chrome.te - Fix pegasus_openlmi_domain_template() interfaces - Fix dev_rw_vfio_dev definiton, allow virtd_t to read tmpfs_t symlinks - Fix location of google-chrome data - Add support for chome_sandbox to store content in the homedir - Allow policykit to watch for changes in cgroups file system - Add boolean to allow mozilla_plugin_t to use spice - Allow collectd to bind to udp port - Allow collected_t to read all of /proc - Should use netlink socket_perms - Should use netlink socket_perms - Allow glance domains to connect to apache ports - Allow apcupsd_t to manage its log files - Allow chrome objects to rw_inherited unix_stream_socket from callers - Allow staff_t to execute virtd_exec_t for running vms - nfsd_t needs to bind mountd port to make nfs-mountd.service working - Allow unbound net_admin capability because of setsockopt syscall - Fix fs_list_cgroup_dirs() - Label /usr/lib/nagios/plugins/utils.pm as bin_t - Remove uplicate definition of fs_read_cgroup_files() - Remove duplicate definition of fs_read_cgroup_files() - Add files_mountpoint_filetrans interface to be used by quotadb_t and snapperd - Additional interfaces needed to list and read cgroups config - Add port definition for collectd port - Add labels for /dev/ptp* - Allow staff_t to execute virtd_exec_t for running vms- Allow samba-net to also read realmd tmp files - Allow NUT to use serial ports - realmd can be started by systemctl now- Remove userdom_home_manager for xdm_t and move all rules to xserver.te directly - Add new xdm_write_home boolean to allow xdm_t to create files in HOME dirs with xdm_home_t - Allow postfix-showq to read/write unix.showq in /var/spool/postfix/pid - Allow virsh to read xen lock file - Allow qemu-ga to create files in /run with proper labeling - Allow glusterd to connect to own socket in /tmp - Allow glance-api to connect to http port to make glance image-create working - Allow keystonte_t to execute rpm- Fix realmd cache interfaces- Allow tcpd to execute leafnode - Allow samba-net to read realmd cache files - Dontaudit sys_tty_config for alsactl - Fix allow rules for postfix_var_run - Allow cobblerd to read /etc/passwd - Allow pegasus to read exports - Allow systemd-timedate to read xdm state - Allow mout to stream connect to rpcbind - Add labeling just for /usr/share/pki/ca-trust-source instead of /usr/share/pki- Allow thumbnails to share memory with apps which run thumbnails - Allow postfix-postqueue block_suspend - Add lib interfaces for smsd - Add support for nginx - Allow s2s running as jabberd_t to connect to jabber_interserver_port_t - Allow pki apache domain to create own tmp files and execute httpd_suexec - Allow procmail to manger user tmp files/dirs/lnk_files - Add virt_stream_connect_svirt() interface - Allow dovecot-auth to execute bin_t - Allow iscsid to request that kernel load a kernel module - Add labeling support for /var/lib/mod_security - Allow iw running as tuned_t to create netlink socket - Dontaudit sys_tty_config for thumb_t - Add labeling for nm-l2tp-service - Allow httpd running as certwatch_t to open tcp socket - Allow useradd to manager smsd lib files - Allow useradd_t to add homedirs in /var/lib - Fix typo in userdomain.te - Cleanup userdom_read_home_certs - Implement userdom_home_reader_certs_type to allow read certs also on encrypt /home with ecryptfs_t - Allow staff to stream connect to svirt_t to make gnome-boxes working- Allow lvm to create its own unit files - Label /var/lib/sepolgen as selinux_config_t - Add filetrans rules for tw devices - Add transition from cupsd_config_t to cupsd_t- Add filetrans rules for tw devices - Cleanup bad transition lines- Fix lockdev_manage_files() - Allow setroubleshootd to read var_lib_t to make email_alert working - Add lockdev_manage_files() - Call proper interface in virt.te - Allow gkeyring_domain to create /var/run/UID/config/dbus file - system dbus seems to be blocking suspend - Dontaudit attemps to sys_ptrace, which I believe gpsd does not need - When you enter a container from root, you generate avcs with a leaked file descriptor - Allow mpd getattr on file system directories - Make sure realmd creates content with the correct label - Allow systemd-tty-ask to write kmsg - Allow mgetty to use lockdev library for device locking - Fix selinuxuser_user_share_music boolean name to selinuxuser_share_music - When you enter a container from root, you generate avcs with a leaked file descriptor - Make sure init.fc files are labeled correctly at creation - File name trans vconsole.conf - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow certmonger to dbus communicate with realmd - Make realmd working- Fix mozilla specification of homedir content - Allow certmonger to read network state - Allow tmpwatch to read tmp in /var/spool/{cups,lpd} - Label all nagios plugin as unconfined by default - Add httpd_serve_cobbler_files() - Allow mdadm to read /dev/sr0 and create tmp files - Allow certwatch to send mails - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow realmd to run ipa, really needs to be an unconfined_domain - Allow sandbox domains to use inherted terminals - Allow pscd to use devices labeled svirt_image_t in order to use cat cards. - Add label for new alsa pid - Alsa now uses a pid file and needs to setsched - Fix oracleasmfs_t definition - Add support for sshd_unit_file_t - Add oracleasmfs_t - Allow unlabeled_t files to be stored on unlabeled_t filesystems- Fix description of deny_ptrace boolean - Remove allow for execmod lib_t for now - Allow quantum to connect to keystone port - Allow nova-console to talk with mysql over unix stream socket - Allow dirsrv to stream connect to uuidd - thumb_t needs to be able to create ~/.cache if it does not exist - virtd needs to be able to sys_ptrace when starting and stoping containers- Allow alsa_t signal_perms, we probaly should search for any app that can execute something without transition and give it signal_perms... - Add dontaudit for mozilla_plugin_t looking at the xdm_t sockets - Fix deny_ptrace boolean, certain ptrace leaked into the system - Allow winbind to manage kerberos_rcache_host - Allow spamd to create spamd_var_lib_t directories - Remove transition to mozilla_tmp_t by mozilla_t, to allow it to manage the users tmp dirs - Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Call snmp_manage_var_lib_files(fogorn_t) instead of snmp_manage_var_dirs - Fix vmware_role() interface - Fix cobbler_manage_lib_files() interface - Allow nagios check disk plugins to execute bin_t - Allow quantum to transition to openvswitch_t - Allow postdrop to stream connect to postfix-master - Allow quantum to stream connect to openvswitch - Add xserver_dontaudit_xdm_rw_stream_sockets() interface - Allow daemon to send dgrams to initrc_t - Allow kdm to start the power service to initiate a reboot or poweroff- Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Don't audit attempts to write to stream socket of nscld by thumbnailers - Allow git_system_t to read network state - Allow pegasas to execute mount command - Fix desc for drdb_admin - Fix condor_amin() - Interface fixes for uptime, vdagent, vnstatd - Fix labeling for moodle in /var/www/moodle/data - Add interface fixes - Allow bugzilla to read certs - /var/www/moodle needs to be writable by apache - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Fix namespace_init_t to create content with proper labels, and allow it to manage all user content - Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Fix sys_nice for cups_domain - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Kernel_t needs mac_admin in order to support labeled NFS - Fix systemd_dontaudit_dbus_chat() interface - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Allow consolehelper domain to write Xauth files in /root - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Allow consolehelper more access discovered by Tom London - Allow fsdaemon to send signull to all domain - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Fix file_contexts.subs to label /run/lock correctly- Try to label on controlC devices up to 30 correctly - Add mount_rw_pid_files() interface - Add additional mount/umount interfaces needed by mock - fsadm_t sends audit messages in reads kernel_ipc_info when doing livecd-iso-to-disk - Fix tabs - Allow initrc_domain to search rgmanager lib files - Add more fixes which make mock working together with confined users * Allow mock_t to manage rpm files * Allow mock_t to read rpm log files * Allow mock to setattr on tmpfs, devpts * Allow mount/umount filesystems - Add rpm_read_log() interface - yum-cron runs rpm from within it. - Allow tuned to transition to dmidecode - Allow firewalld to do net_admin - Allow mock to unmont tmpfs_t - Fix virt_sigkill() interface - Add additional fixes for mock. Mainly caused by mount running in mock_t - Allow mock to write sysfs_t and mount pid files - Add mailman_domain to mailman_template() - Allow openvswitch to execute shell - Allow qpidd to use kerberos - Allow mailman to use fusefs, needs back port to RHEL6 - Allow apache and its scripts to use anon_inodefs - Add alias for git_user_content_t and git_sys_content_t so that RHEL6 will update to RHEL7 - Realmd needs to connect to samba ports, needs back port to F18 also - Allow colord to read /run/initial-setup- - Allow sanlock-helper to send sigkill to virtd which is registred to sanlock - Add virt_kill() interface - Add rgmanager_search_lib() interface - Allow wdmd to getattr on all filesystems. Back ported from RHEL6- Allow realmd to create tmp files - FIx ircssi_home_t type to irssi_home_t - Allow adcli running as realmd_t to connect to ldap port - Allow NetworkManager to transition to ipsec_t, for running strongswan - Make openshift_initrc_t an lxc_domain - Allow gssd to manage user_tmp_t files - Fix handling of irclogs in users homedir - Fix labeling for drupal an wp-content in subdirs of /var/www/html - Allow abrt to read utmp_t file - Fix openshift policy to transition lnk_file, sock-file an fifo_file when created in a tmpfs_t, needs back port to RHEL6 - fix labeling for (oo|rhc)-restorer-wrapper.sh - firewalld needs to be able to write to network sysctls - Fix mozilla_plugin_dontaudit_rw_sem() interface - Dontaudit generic ipc read/write to a mozilla_plugin for sandbox_x domains - Add mozilla_plugin_dontaudit_rw_sem() interface - Allow svirt_lxc_t to transition to openshift domains - Allow condor domains block_suspend and dac_override caps - Allow condor_master to read passd - Allow condor_master to read system state - Allow NetworkManager to transition to ipsec_t, for running strongswan - Lots of access required by lvm_t to created encrypted usb device - Allow xdm_t to dbus communicate with systemd_localed_t - Label strongswan content as ipsec_exec_mgmt_t for now - Allow users to dbus chat with systemd_localed - Fix handling of .xsession-errors in xserver.if, so kde will work - Might be a bug but we are seeing avc's about people status on init_t:service - Make sure we label content under /var/run/lock as <> - Allow daemon and systemprocesses to search init_var_run_t directory - Add boolean to allow xdm to write xauth data to the home directory - Allow mount to write keys for the unconfined domain - Add unconfined_write_keys() interface- Add labeling for /usr/share/pki - Allow programs that read var_run_t symlinks also read var_t symlinks - Add additional ports as mongod_port_t for 27018, 27019, 28017, 28018 and 28019 ports - Fix labeling for /etc/dhcp directory - add missing systemd_stub_unit_file() interface - Add files_stub_var() interface - Add lables for cert_t directories - Make localectl set-x11-keymap working at all - Allow abrt to manage mock build environments to catch build problems. - Allow virt_domains to setsched for running gdb on itself - Allow thumb_t to execute user home content - Allow pulseaudio running as mozilla_plugin_t to read /run/systemd/users/1000 - Allow certwatch to execut /usr/bin/httpd - Allow cgred to send signal perms to itself, needs back port to RHEL6 - Allow openshift_cron_t to look at quota - Allow cups_t to read inhered tmpfs_t from the kernel - Allow yppasswdd to use NIS - Tuned wants sys_rawio capability - Add ftpd_use_fusefs boolean - Allow dirsrvadmin_t to signal itself- Allow localectl to read /etc/X11/xorg.conf.d directory - Revert "Revert "Fix filetrans rules for kdm creates .xsession-errors"" - Allow mount to transition to systemd_passwd_agent - Make sure abrt directories are labeled correctly - Allow commands that are going to read mount pid files to search mount_var_run_t - label /usr/bin/repoquery as rpm_exec_t - Allow automount to block suspend - Add abrt_filetrans_named_content so that abrt directories get labeled correctly - Allow virt domains to setrlimit and read file_context- Allow nagios to manage nagios spool files - /var/spool/snmptt is a directory which snmdp needs to write to, needs back port to RHEL6 - Add swift_alias.* policy files which contain typealiases for swift types - Add support for /run/lock/opencryptoki - Allow pkcsslotd chown capability - Allow pkcsslotd to read passwd - Add rsync_stub() interface - Allow systemd_timedate also manage gnome config homedirs - Label /usr/lib64/security/pam_krb5/pam_krb5_cchelper as bin_t - Fix filetrans rules for kdm creates .xsession-errors - Allow sytemd_tmpfiles to create wtmp file - Really should not label content under /var/lock, since it could have labels on it different from var_lock_t - Allow systemd to list all file system directories - Add some basic stub interfaces which will be used in PRODUCT policies- Fix log transition rule for cluster domains - Start to group all cluster log together - Dont use filename transition for POkemon Advanced Adventure until a new checkpolicy update - cups uses usbtty_device_t devices - These fixes were all required to build a MLS virtual Machine with single level desktops - Allow domains to transiton using httpd_exec_t - Allow svirt domains to manage kernel key rings - Allow setroubleshoot to execute ldconfig - Allow firewalld to read generate gnome data - Allow bluetooth to read machine-info - Allow boinc domain to send signal to itself - Fix gnome_filetrans_home_content() interface - Allow mozilla_plugins to list apache modules, for use with gxine - Fix labels for POkemon in the users homedir - Allow xguest to read mdstat - Dontaudit virt_domains getattr on /dev/* - These fixes were all required to build a MLS virtual Machine with single level desktops - Need to back port this to RHEL6 for openshift - Add tcp/8891 as milter port - Allow nsswitch domains to read sssd_var_lib_t files - Allow ping to read network state. - Fix typo - Add labels to /etc/X11/xorg.d and allow systemd-timestampd_t to manage them- Adopt swift changes from lhh@redhat.com - Add rhcs_manage_cluster_pid_files() interface - Allow screen domains to configure tty and setup sock_file in ~/.screen directory - ALlow setroubleshoot to read default_context_t, needed to backport to F18 - Label /etc/owncloud as being an apache writable directory - Allow sshd to stream connect to an lxc domain- Allow postgresql to manage rgmanager pid files - Allow postgresql to read ccs data - Allow systemd_domain to send dbus messages to policykit - Add labels for /etc/hostname and /etc/machine-info and allow systemd-hostnamed to create them - All systemd domains that create content are reading the file_context file and setfscreate - Systemd domains need to search through init_var_run_t - Allow sshd to communicate with libvirt to set containers labels - Add interface to manage pid files - Allow NetworkManger_t to read /etc/hostname - Dontaudit leaked locked files into openshift_domains - Add fixes for oo-cgroup-read - it nows creates tmp files - Allow gluster to manage all directories as well as files - Dontaudit chrome_sandbox_nacl_t using user terminals - Allow sysstat to manage its own log files - Allow virtual machines to setrlimit and send itself signals. - Add labeling for /var/run/hplip- Fix POSTIN scriptlet- Merge rgmanger, corosync,pacemaker,aisexec policies to cluster_t in rhcs.pp- Fix authconfig.py labeling - Make any domains that write homedir content do it correctly - Allow glusterd to read/write anyhwere on the file system by default - Be a little more liberal with the rsync log files - Fix iscsi_admin interface - Allow iscsid_t to read /dev/urand - Fix up iscsi domain for use with unit files - Add filename transition support for spamassassin policy - Allow web plugins to use badly formated libraries - Allow nmbd_t to create samba_var_t directories - Add filename transition support for spamassassin policy - Add filename transition support for tvtime - Fix alsa_home_filetrans_alsa_home() interface - Move all userdom_filetrans_home_content() calling out of booleans - Allow logrotote to getattr on all file sytems - Remove duplicate userdom_filetrans_home_content() calling - Allow kadmind to read /etc/passwd - Dontaudit append .xsession-errors file on ecryptfs for policykit-auth - Allow antivirus domain to manage antivirus db links - Allow logrotate to read /sys - Allow mandb to setattr on man dirs - Remove mozilla_plugin_enable_homedirs boolean - Fix ftp_home_dir boolean - homedir mozilla filetrans has been moved to userdom_home_manager - homedir telepathy filetrans has been moved to userdom_home_manager - Remove gnome_home_dir_filetrans() from gnome_role_gkeyringd() - Might want to eventually write a daemon on fusefsd. - Add policy fixes for sshd [net] child from plautrba@redhat.com - Tor uses a new port - Remove bin_t for authconfig.py - Fix so only one call to userdom_home_file_trans - Allow home_manager_types to create content with the correctl label - Fix all domains that write data into the homedir to do it with the correct label - Change the postgresql to use proper boolean names, which is causing httpd_t to - not get access to postgresql_var_run_t - Hostname needs to send syslog messages - Localectl needs to be able to send dbus signals to users - Make sure userdom_filetrans_type will create files/dirs with user_home_t labeling by default - Allow user_home_manger domains to create spam* homedir content with correct labeling - Allow user_home_manger domains to create HOMEDIR/.tvtime with correct labeling - Add missing miscfiles_setattr_man_pages() interface and for now comment some rules for userdom_filetrans_type to make build process working - Declare userdom_filetrans_type attribute - userdom_manage_home_role() needs to be called withoout usertype attribute because of userdom_filetrans_type attribute - fusefsd is mounding a fuse file system on /run/user/UID/gvfs- Man pages are now generated in the build process - Allow cgred to list inotifyfs filesystem- Allow gluster to get attrs on all fs - New access required for virt-sandbox - Allow dnsmasq to execute bin_t - Allow dnsmasq to create content in /var/run/NetworkManager - Fix openshift_initrc_signal() interface - Dontaudit openshift domains doing getattr on other domains - Allow consolehelper domain to communicate with session bus - Mock should not be transitioning to any other domains, we should keep mock_t as mock_t - Update virt_qemu_ga_t policy - Allow authconfig running from realmd to restart oddjob service - Add systemd support for oddjob - Add initial policy for realmd_consolehelper_t which if for authconfig executed by realmd - Add labeling for gnashpluginrc - Allow chrome_nacl to execute /dev/zero - Allow condor domains to read /proc - mozilla_plugin_t will getattr on /core if firefox crashes - Allow condor domains to read /etc/passwd - Allow dnsmasq to execute shell scripts, openstack requires this access - Fix glusterd labeling - Allow virtd_t to interact with the socket type - Allow nmbd_t to override dac if you turned on sharing all files - Allow tuned to created kobject_uevent socket - Allow guest user to run fusermount - Allow openshift to read /proc and locale - Allow realmd to dbus chat with rpm - Add new interface for virt - Remove depracated interfaces - Allow systemd_domains read access on etc, etc_runtime and usr files, also allow them to connect stream to syslog socket - /usr/share/munin/plugins/plugin.sh should be labeled as bin_t - Remove some more unconfined_t process transitions, that I don't believe are necessary - Stop transitioning uncofnined_t to checkpc - dmraid creates /var/lock/dmraid - Allow systemd_localed to creatre unix_dgram_sockets - Allow systemd_localed to write kernel messages. - Also cleanup systemd definition a little. - Fix userdom_restricted_xwindows_user_template() interface - Label any block devices or char devices under /dev/infiniband as fixed_disk_device_t - User accounts need to dbus chat with accountsd daemon - Gnome requires all users to be able to read /proc/1/- virsh now does a setexeccon call - Additional rules required by openshift domains - Allow svirt_lxc_domains to use inherited terminals, needed to make virt-sandbox-service execute work - Allow spamd_update_t to search spamc_home_t - Avcs discovered by mounting an isci device under /mnt - Allow lspci running as logrotate to read pci.ids - Additional fix for networkmanager_read_pid_files() - Fix networkmanager_read_pid_files() interface - Allow all svirt domains to connect to svirt_socket_t - Allow virsh to set SELinux context for a process. - Allow tuned to create netlink_kobject_uevent_socket - Allow systemd-timestamp to set SELinux context - Add support for /var/lib/systemd/linger - Fix ssh_sysadm_login to be working on MLS as expected- Rename files_rw_inherited_tmp_files to files_rw_inherited_tmp_file - Add missing files_rw_inherited_tmp_files interface - Add additional interface for ecryptfs - ALlow nova-cert to connect to postgresql - Allow keystone to connect to postgresql - Allow all cups domains to getattr on filesystems - Allow pppd to send signull - Allow tuned to execute ldconfig - Allow gpg to read fips_enabled - Add additional fixes for ecryptfs - Allow httpd to work with posgresql - Allow keystone getsched and setsched- Allow gpg to read fips_enabled - Add support for /var/cache/realmd - Add support for /usr/sbin/blazer_usb and systemd support for nut - Add labeling for fenced_sanlock and allow sanclok transition to fenced_t - bitlbee wants to read own log file - Allow glance domain to send a signal itself - Allow xend_t to request that the kernel load a kernel module - Allow pacemaker to execute heartbeat lib files - cleanup new swift policy- Fix smartmontools - Fix userdom_restricted_xwindows_user_template() interface - Add xserver_xdm_ioctl_log() interface - Allow Xusers to ioctl lxdm.log to make lxdm working - Add MLS fixes to make MLS boot/log-in working - Add mls_socket_write_all_levels() also for syslogd - fsck.xfs needs to read passwd - Fix ntp_filetrans_named_content calling in init.te - Allow postgresql to create pg_log dir - Allow sshd to read rsync_data_t to make rsync working - Change ntp.conf to be labeled net_conf_t - Allow useradd to create homedirs in /run. ircd-ratbox does this and we should just allow it - Allow xdm_t to execute gstreamer home content - Allod initrc_t and unconfined domains, and sysadm_t to manage ntp - New policy for openstack swift domains - More access required for openshift_cron_t - Use cupsd_log_t instead of cupsd_var_log_t - rpm_script_roles should be used in rpm_run - Fix rpm_run() interface - Fix openshift_initrc_run() - Fix sssd_dontaudit_stream_connect() interface - Fix sssd_dontaudit_stream_connect() interface - Allow LDA's job to deliver mail to the mailbox - dontaudit block_suspend for mozilla_plugin_t - Allow l2tpd_t to all signal perms - Allow uuidgen to read /dev/random - Allow mozilla-plugin-config to read power_supply info - Implement cups_domain attribute for cups domains - We now need access to user terminals since we start by executing a command outside the tty - We now need access to user terminals since we start by executing a command outside the tty - svirt lxc containers want to execute userhelper apps, need these changes to allow this to happen - Add containment of openshift cron jobs - Allow system cron jobs to create tmp directories - Make userhelp_conf_t a config file - Change rpm to use rpm_script_roles - More fixes for rsync to make rsync wokring - Allow logwatch to domtrans to mdadm - Allow pacemaker to domtrans to ifconfig - Allow pacemaker to setattr on corosync.log - Add pacemaker_use_execmem for memcheck-amd64 command - Allow block_suspend capability - Allow create fifo_file in /tmp with pacemaker_tmp_t - Allow systat to getattr on fixed disk - Relabel /etc/ntp.conf to be net_conf_t - ntp_admin should create files in /etc with the correct label - Add interface to create ntp_conf_t files in /etc - Add additional labeling for quantum - Allow quantum to execute dnsmasq with transition- boinc_cliean wants also execmem as boinc projecs have - Allow sa-update to search admin home for /root/.spamassassin - Allow sa-update to search admin home for /root/.spamassassin - Allow antivirus domain to read net sysctl - Dontaudit attempts from thumb_t to connect to ssd - Dontaudit attempts by readahead to read sock_files - Dontaudit attempts by readahead to read sock_files - Create tmpfs file while running as wine as user_tmpfs_t - Dontaudit attempts by readahead to read sock_files - libmpg ships badly created librarie- Change ssh_use_pts to use macro and only inherited sshd_devpts_t - Allow confined users to read systemd_logind seat information - libmpg ships badly created libraries - Add support for strongswan.service - Add labeling for strongswan - Allow l2tpd_t to read network manager content in /run directory - Allow rsync to getattr any file in rsync_data_t - Add labeling and filename transition for .grl-podcasts- mount.glusterfs executes glusterfsd binary - Allow systemd_hostnamed_t to stream connect to systemd - Dontaudit any user doing a access check - Allow obex-data-server to request the kernel to load a module - Allow gpg-agent to manage gnome content (~/.cache/gpg-agent-info) - Allow gpg-agent to read /proc/sys/crypto/fips_enabled - Add new types for antivirus.pp policy module - Allow gnomesystemmm_t caps because of ioprio_set - Make sure if mozilla_plugin creates files while in permissive mode, they get created with the correct label, user_home_t - Allow gnomesystemmm_t caps because of ioprio_set - Allow NM rawip socket - files_relabel_non_security_files can not be used with boolean - Add interface to thumb_t dbus_chat to allow it to read remote process state - ALlow logrotate to domtrans to mdadm_t - kde gnomeclock wants to write content to /tmp- kde gnomeclock wants to write content to /tmp - /usr/libexec/kde4/kcmdatetimehelper attempts to create /root/.kde - Allow blueman_t to rwx zero_device_t, for some kind of jre - Allow mozilla_plugin_t to rwx zero_device_t, for some kind of jre - Ftp full access should be allowed to create directories as well as files - Add boolean to allow rsync_full_acces, so that an rsync server can write all - over the local machine - logrotate needs to rotate logs in openshift directories, needs back port to RHEL6 - Add missing vpnc_roles type line - Allow stapserver to write content in /tmp - Allow gnome keyring to create keyrings dir in ~/.local/share - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Add interface to colord_t dbus_chat to allow it to read remote process state - Allow colord_t to read cupsd_t state - Add mate-thumbnail-font as thumnailer - Allow sectoolm to sys_ptrace since it is looking at other proceses /proc data. - Allow qpidd to list /tmp. Needed by ssl - Only allow init_t to transition to rsync_t domain, not initrc_t. This should be back ported to F17, F18 - - Added systemd support for ksmtuned - Added booleans ksmtuned_use_nfs ksmtuned_use_cifs - firewalld seems to be creating mmap files which it needs to execute in /run /tmp and /dev/shm. Would like to clean this up but for now we will allow - Looks like qpidd_t needs to read /dev/random - Lots of probing avc's caused by execugting gpg from staff_t - Dontaudit senmail triggering a net_admin avc - Change thumb_role to use thumb_run, not sure why we have a thumb_role, needs back port - Logwatch does access check on mdadm binary - Add raid_access_check_mdadm() iterface- Fix systemd_manage_unit_symlinks() interface - Call systemd_manage_unit_symlinks(() which is correct interface - Add filename transition for opasswd - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow sytstemd-timedated to get status of init_t - Add new systemd policies for hostnamed and rename gnomeclock_t to systemd_timedate_t - colord needs to communicate with systemd and systemd_logind, also remove duplicate rules - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow gpg_t to manage all gnome files - Stop using pcscd_read_pub_files - New rules for xguest, dontaudit attempts to dbus chat - Allow firewalld to create its mmap files in tmpfs and tmp directories - Allow firewalld to create its mmap files in tmpfs and tmp directories - run unbound-chkconf as named_t, so it can read dnssec - Colord is reading xdm process state, probably reads state of any apps that sends dbus message - Allow mdadm_t to change the kernel scheduler - mythtv policy - Update mandb_admin() interface - Allow dsspam to listen on own tpc_socket - seutil_filetrans_named_content needs to be optional - Allow sysadm_t to execute content in his homedir - Add attach_queue to tun_socket, new patch from Paul Moore - Change most of selinux configuration types to security_file_type. - Add filename transition rules for selinux configuration - ssh into a box with -X -Y requires ssh_use_ptys - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Allow all unpriv userdomains to send dbus messages to hostnamed and timedated - New allow rules found by Tom London for systemd_hostnamed- Allow systemd-tmpfiles to relabel lpd spool files - Ad labeling for texlive bash scripts - Add xserver_filetrans_fonts_cache_home_content() interface - Remove duplicate rules from *.te - Add support for /var/lock/man-db.lock - Add support for /var/tmp/abrt(/.*)? - Add additional labeling for munin cgi scripts - Allow httpd_t to read munin conf files - Allow certwatch to read meminfo - Fix nscd_dontaudit_write_sock_file() interfac - Fix gnome_filetrans_home_content() to include also "fontconfig" dir as cache_home_t - llow mozilla_plugin_t to create HOMEDIR/.fontconfig with the proper labeling- Allow gnomeclock to talk to puppet over dbus - Allow numad access discovered by Dominic - Add support for HOME_DIR/.maildir - Fix attribute_role for mozilla_plugin_t domain to allow staff_r to access this domain - Allow udev to relabel udev_var_run_t lnk_files - New bin_t file in mcelog- Remove all mcs overrides and replace with t1 != mcs_constrained_types - Add attribute_role for iptables - mcs_process_set_categories needs to be called for type - Implement additional role_attribute statements - Sodo domain is attempting to get the additributes of proc_kcore_t - Unbound uses port 8953 - Allow svirt_t images to compromise_kernel when using pci-passthrough - Add label for dns lib files - Bluetooth aquires a dbus name - Remove redundant files_read_usr_file calling - Remove redundant files_read_etc_file calling - Fix mozilla_run_plugin() - Add role_attribute support for more domains- Mass merge with upstream- Bump the policy version to 28 to match selinux userspace - Rebuild versus latest libsepol- Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Add labeling for /var/named/chroot/etc/localtim- Allow setroubleshoot_fixit to execute rpm - zoneminder needs to connect to httpd ports where remote cameras are listening - Allow firewalld to execute content created in /run directory - Allow svirt_t to read generic certs - Dontaudit leaked ps content to mozilla plugin - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - init scripts are creating systemd_unit_file_t directories- systemd_logind_t is looking at all files under /run/user/apache - Allow systemd to manage all user tmp files - Add labeling for /var/named/chroot/etc/localtime - Allow netlabel_peer_t type to flow over netif_t and node_t, and only be hindered by MLS, need back port to RHEL6 - Keystone is now using a differnt port - Allow xdm_t to use usbmuxd daemon to control sound - Allow passwd daemon to execute gnome_exec_keyringd - Fix chrome_sandbox policy - Add labeling for /var/run/checkquorum-timer - More fixes for the dspam domain, needs back port to RHEL6 - More fixes for the dspam domain, needs back port to RHEL6 - sssd needs to connect to kerberos password port if a user changes his password - Lots of fixes from RHEL testing of dspam web - Allow chrome and mozilla_plugin to create msgq and semaphores - Fixes for dspam cgi scripts - Fixes for dspam cgi scripts - Allow confine users to ptrace screen - Backport virt_qemu_ga_t changes from RHEL - Fix labeling for dspam.cgi needed for RHEL6 - We need to back port this policy to RHEL6, for lxc domains - Dontaudit attempts to set sys_resource of logrotate - Allow corosync to read/write wdmd's tmpfs files - I see a ptrace of mozilla_plugin_t by staff_t, will allow without deny_ptrace being set - Allow cron jobs to read bind config for unbound - libvirt needs to inhibit systemd - kdumpctl needs to delete boot_t files - Fix duplicate gnome_config_filetrans - virtd_lxc_t is using /dev/fuse - Passenger needs to create a directory in /var/log, needs a backport to RHEL6 for openshift - apcupsd can be setup to listen to snmp trafic - Allow transition from kdumpgui to kdumpctl - Add fixes for munin CGI scripts - Allow deltacloud to connect to openstack at the keystone port - Allow domains that transition to svirt domains to be able to signal them - Fix file context of gstreamer in .cache directory - libvirt is communicating with logind - NetworkManager writes to the systemd inhibit pipe- Allow munin disk plugins to get attributes of all directories - Allow munin disk plugins to get attributes of all directorie - Allow logwatch to get attributes of all directories - Fix networkmanager_manage_lib() interface - Fix gnome_manage_config() to allow to manage sock_file - Fix virtual_domain_context - Add support for dynamic DNS for DHCPv6- Allow svirt to use netlink_route_socket which was a part of auth_use_nsswitch - Add additional labeling for /var/www/openshift/broker - Fix rhev policy - Allow openshift_initrc domain to dbus chat with systemd_logind - Allow httpd to getattr passenger log file if run_stickshift - Allow consolehelper-gtk to connect to xserver - Add labeling for the tmp-inst directory defined in pam_namespace.conf - Add lvm_metadata_t labeling for /etc/multipath- consoletype is no longer used- Add label for efivarfs - Allow certmonger to send signal to itself - Allow plugin-config to read own process status - Add more fixes for pacemaker - apache/drupal can run clamscan on uploaded content - Allow chrome_sandbox_nacl_t to read pid 1 content- Fix MCS Constraints to control ingres and egres controls on the network. - Change name of svirt_nokvm_t to svirt_tcg_t - Allow tuned to request the kernel to load kernel modules- Label /var/lib/pgsql/.ssh as ssh_home_t - Add labeling for /usr/bin/pg_ctl - Allow systemd-logind to manage keyring user tmp dirs - Add support for 7389/tcp port - gems seems to be placed in lots of places - Since xdm is running a full session, it seems to be trying to execute lots of executables via dbus - Add back tcp/8123 port as http_cache port - Add ovirt-guest-agent\.pid labeling - Allow xend to run scsi_id - Allow rhsmcertd-worker to read "physical_package_id" - Allow pki_tomcat to connect to ldap port - Allow lpr to read /usr/share/fonts - Allow open file from CD/DVD drive on domU - Allow munin services plugins to talk to SSSD - Allow all samba domains to create samba directory in var_t directories - Take away svirt_t ability to use nsswitch - Dontaudit attempts by openshift to read apache logs - Allow apache to create as well as append _ra_content_t - Dontaudit sendmail_t reading a leaked file descriptor - Add interface to have admin transition /etc/prelink.cache to the proper label - Add sntp support to ntp policy - Allow firewalld to dbus chat with devicekit_power - Allow tuned to call lsblk - Allow tor to read /proc/sys/kernel/random/uuid - Add tor_can_network_relay boolean- Add openshift_initrc_signal() interface - Fix typos - dspam port is treat as spamd_port_t - Allow setroubleshoot to getattr on all executables - Allow tuned to execute profiles scripts in /etc/tuned - Allow apache to create directories to store its log files - Allow all directories/files in /var/log starting with passenger to be labeled passenger_log_t - Looks like apache is sending sinal to openshift_initrc_t now,needs back port to RHEL6 - Allow Postfix to be configured to listen on TCP port 10026 for email from DSPAM - Add filename transition for /etc/tuned/active_profile - Allow condor_master to send mails - Allow condor_master to read submit.cf - Allow condor_master to create /tmp files/dirs - Allow condor_mater to send sigkill to other condor domains - Allow condor_procd sigkill capability - tuned-adm wants to talk with tuned daemon - Allow kadmind and krb5kdc to also list sssd_public_t - Allow accountsd to dbus chat with init - Fix git_read_generic_system_content_files() interface - pppd wants sys_nice by nmcli because of "syscall=sched_setscheduler" - Fix mozilla_plugin_can_network_connect to allow to connect to all ports - Label all munin plugins which are not covered by munin plugins policy as unconfined_munin_plugin_exec_t - dspam wants to search /var/spool for opendkim data - Revert "Add support for tcp/10026 port as dspam_port_t" - Turning on labeled networking requires additional access for netlabel_peer_t; these allow rules need to be back ported to RHEL6 - Allow all application domains to use fifo_files passed in from userdomains, also allow them to write to tmp_files inherited from userdomain - Allow systemd_tmpfiles_t to setattr on mandb_cache_t- consolekit.pp was not removed from the postinstall script- Add back consolekit policy - Silence bootloader trying to use inherited tty - Silence xdm_dbusd_t trying to execute telepathy apps - Fix shutdown avcs when machine has unconfined.pp disabled - The host and a virtual machine can share the same printer on a usb device - Change oddjob to transition to a ranged openshift_initr_exec_t when run from oddjob - Allow abrt_watch_log_t to execute bin_t - Allow chrome sandbox to write content in ~/.config/chromium - Dontaudit setattr on fontconfig dir for thumb_t - Allow lircd to request the kernel to load module - Make rsync as userdom_home_manager - Allow rsync to search automount filesystem - Add fixes for pacemaker- Add support for 4567/tcp port - Random fixes from Tuomo Soini - xdm wants to get init status - Allow programs to run in fips_mode - Add interface to allow the reading of all blk device nodes - Allow init to relabel rpcbind sock_file - Fix labeling for lastlog and faillog related to logrotate - ALlow aeolus_configserver to use TRAM port - Add fixes for aeolus_configserver - Allow snmpd to connect to snmp port - Allow spamd_update to create spamd_var_lib_t directories - Allow domains that can read sssd_public_t files to also list the directory - Remove miscfiles_read_localization, this is defined for all domains- Allow syslogd to request the kernel to load a module - Allow syslogd_t to read the network state information - Allow xdm_dbusd_t connect to the system DBUS - Add support for 7389/tcp port - Allow domains to read/write all inherited sockets - Allow staff_t to read kmsg - Add awstats_purge_apache_log boolean - Allow ksysguardproces to read /.config/Trolltech.conf - Allow passenger to create and append puppet log files - Add puppet_append_log and puppet_create_log interfaces - Add puppet_manage_log() interface - Allow tomcat domain to search tomcat_var_lib_t - Allow pki_tomcat_t to connect to pki_ca ports - Allow pegasus_t to have net_admin capability - Allow pegasus_t to write /sys/class/net//flags - Allow mailserver_delivery to manage mail_home_rw_t lnk_files - Allow fetchmail to create log files - Allow gnomeclock to manage home config in .kde - Allow bittlebee to read kernel sysctls - Allow logrotate to list /root- Fix userhelper_console_role_template() - Allow enabling Network Access Point service using blueman - Make vmware_host_t as unconfined domain - Allow authenticate users in webaccess via squid, using mysql as backend - Allow gathers to get various metrics on mounted file systems - Allow firewalld to read /etc/hosts - Fix cron_admin_role() to make sysadm cronjobs running in the sysadm_t instead of cronjob_t - Allow kdumpgui to read/write to zipl.conf - Commands needed to get mock to build from staff_t in enforcing mode - Allow mdadm_t to manage cgroup files - Allow all daemons and systemprocesses to use inherited initrc_tmp_t files - dontaudit ifconfig_t looking at fifo_files that are leaked to it - Add lableing for Quest Authentication System- Fix filetrans interface definitions - Dontaudit xdm_t to getattr on BOINC lib files - Add systemd_reload_all_services() interface - Dontaudit write access on /var/lib/net-snmp/mib_indexes - Only stop mcsuntrustedproc from relableing files - Allow accountsd to dbus chat with gdm - Allow realmd to getattr on all fs - Allow logrotate to reload all services - Add systemd unit file for radiusd - Allow winbind to create samba pid dir - Add labeling for /var/nmbd/unexpected - Allow chrome and mozilla plugin to connect to msnp ports- Fix storage_rw_inherited_fixed_disk_dev() to cover also blk_file - Dontaudit setfiles reading /dev/random - On initial boot gnomeclock is going to need to be set buy gdm - Fix tftp_read_content() interface - Random apps looking at kernel file systems - Testing virt with lxc requiers additional access for virsh_t - New allow rules requied for latest libvirt, libvirt talks directly to journald,lxc setup tool needs compromize_kernel,and we need ipc_lock in the container - Allow MPD to read /dev/radnom - Allow sandbox_web_type to read logind files which needs to read pulseaudio - Allow mozilla plugins to read /dev/hpet - Add labeling for /var/lib/zarafa-webap - Allow BOINC client to use an HTTP proxy for all connections - Allow rhsmertd to domain transition to dmidecod - Allow setroubleshootd to send D-Bus msg to ABRT- Define usbtty_device_t as a term_tty - Allow svnserve to accept a connection - Allow xend manage default virt_image_t type - Allow prelink_cron_system_t to overide user componant when executing cp - Add labeling for z-push - Gnomeclock sets the realtime clock - Openshift seems to be storing apache logs in /var/lib/openshift/.log/httpd - Allow lxc domains to use /dev/random and /dev/urandom- Add port defintion for tcp/9000 - Fix labeling for /usr/share/cluster/checkquorum to label also checkquorum.wdmd - Add rules and labeling for $HOME/cache/\.gstreamer-.* directory - Add support for CIM provider openlmi-networking which uses NetworkManager dbus API - Allow shorewall_t to create netlink_socket - Allow krb5admind to block suspend - Fix labels on /var/run/dlm_controld /var/log/dlm_controld - Allow krb5kdc to block suspend - gnomessytemmm_t needs to read /etc/passwd - Allow cgred to read all sysctls- Allow all domains to read /proc/sys/vm/overcommit_memory - Make proc_numa_t an MLS Trusted Object - Add /proc/numactl support for confined users - Allow ssh_t to connect to any port > 1023 - Add openvswitch domain - Pulseaudio tries to create directories in gnome_home_t directories - New ypbind pkg wants to search /var/run which is caused by sd_notify - Allow NM to read certs on NFS/CIFS using use_nfs_*, use_samba_* booleans - Allow sanlock to read /dev/random - Treat php-fpm with httpd_t - Allow domains that can read named_conf_t to be able to list the directories - Allow winbind to create sock files in /var/run/samba- Add smsd policy - Add support for OpenShift sbin labelin - Add boolean to allow virt to use rawip - Allow mozilla_plugin to read all file systems with noxattrs support - Allow kerberos to write on anon_inodefs fs - Additional access required by fenced - Add filename transitions for passwd.lock/group.lock - UPdate man pages - Create coolkey directory in /var/cache with the correct label- Fix label on /etc/group.lock - Allow gnomeclock to create lnk_file in /etc - label /root/.pki as a home_cert_t - Add interface to make sure rpcbind.sock is created with the correct label - Add definition for new directory /var/lib/os-probe and bootloader wants to read udev rules - opendkim should be a part of milter - Allow libvirt to set the kernel sched algorythm - Allow mongod to read sysfs_t - Add authconfig policy - Remove calls to miscfiles_read_localization all domains get this - Allow virsh_t to read /root/.pki/ content - Add label for log directory under /var/www/stickshift- Allow getty to setattr on usb ttys - Allow sshd to search all directories for sshd_home_t content - Allow staff domains to send dbus messages to kdumpgui - Fix labels on /etc/.pwd.lock and friends to be passwd_file_t - Dontaudit setfiles reading urand - Add files_dontaudit_list_tmp() for domains to which we added sys_nice/setsched - Allow staff_gkeyringd_t to read /home/$USER/.local/share/keyrings dir - Allow systemd-timedated to read /dev/urandom - Allow entropyd_t to read proc_t (meminfo) - Add unconfined munin plugin - Fix networkmanager_read_conf() interface - Allow blueman to list /tmp which is needed by sys_nic/setsched - Fix label of /etc/mail/aliasesdb-stamp - numad is searching cgroups - realmd is communicating with networkmanager using dbus - Lots of fixes to try to get kdump to work- Allow loging programs to dbus chat with realmd - Make apache_content_template calling as optional - realmd is using policy kit- Add new selinuxuser_use_ssh_chroot boolean - dbus needs to be able to read/write inherited fixed disk device_t passed through it - Cleanup netutils process allow rule - Dontaudit leaked fifo files from openshift to ping - sanlock needs to read mnt_t lnk files - Fail2ban needs to setsched and sys_nice- Change default label of all files in /var/run/rpcbind - Allow sandbox domains (java) to read hugetlbfs_t - Allow awstats cgi content to create tmp files and read apache log files - Allow setuid/setgid for cupsd-config - Allow setsched/sys_nice pro cupsd-config - Fix /etc/localtime sym link to be labeled locale_t - Allow sshd to search postgresql db t since this is a homedir - Allow xwindows users to chat with realmd - Allow unconfined domains to configure all files and null_device_t service- Adopt pki-selinux policy- pki is leaking which we dontaudit until a pki code fix - Allow setcap for arping - Update man pages - Add labeling for /usr/sbin/mcollectived - pki fixes - Allow smokeping to execute fping in the netutils_t domain- Allow mount to relabelfrom unlabeled file systems - systemd_logind wants to send and receive messages from devicekit disk over dbus to make connected mouse working - Add label to get bin files under libreoffice labeled correctly - Fix interface to allow executing of base_ro_file_type - Add fixes for realmd - Update pki policy - Add tftp_homedir boolean - Allow blueman sched_setscheduler - openshift user domains wants to r/w ssh tcp sockets- Additional requirements for disable unconfined module when booting - Fix label of systemd script files - semanage can use -F /dev/stdin to get input - syslog now uses kerberos keytabs - Allow xserver to compromise_kernel access - Allow nfsd to write to mount_var_run_t when running the mount command - Add filename transition rule for bin_t directories - Allow files to read usr_t lnk_files - dhcpc wants chown - Add support for new openshift labeling - Clean up for tunable+optional statements - Add labeling for /usr/sbin/mkhomedir_helper - Allow antivirus domain to managa amavis spool files - Allow rpcbind_t to read passwd - Allow pyzor running as spamc to manage amavis spool- Add interfaces to read kernel_t proc info - Missed this version of exec_all - Allow anyone who can load a kernel module to compromise kernel - Add oddjob_dbus_chat to openshift apache policy - Allow chrome_sandbox_nacl_t to send signals to itself - Add unit file support to usbmuxd_t - Allow all openshift domains to read sysfs info - Allow openshift domains to getattr on all domains- MLS fixes from Dan - Fix name of capability2 secure_firmware->compromise_kerne- Allow xdm to search all file systems - Add interface to allow the config of all files - Add rngd policy - Remove kgpg as a gpg_exec_t type - Allow plymouthd to block suspend - Allow systemd_dbus to config any file - Allow system_dbus_t to configure all services - Allow freshclam_t to read usr_files - varnishd requires execmem to load modules- Allow semanage to verify types - Allow sudo domain to execute user home files - Allow session_bus_type to transition to user_tmpfs_t - Add dontaudit caused by yum updates - Implement pki policy but not activated- tuned wants to getattr on all filesystems - tuned needs also setsched. The build is needed for test day- Add policy for qemu-qa - Allow razor to write own config files - Add an initial antivirus policy to collect all antivirus program - Allow qdisk to read usr_t - Add additional caps for vmware_host - Allow tmpfiles_t to setattr on mandb_cache_t - Dontaudit leaked files into mozilla_plugin_config_t - Allow wdmd to getattr on tmpfs - Allow realmd to use /dev/random - allow containers to send audit messages - Allow root mount any file via loop device with enforcing mls policy - Allow tmpfiles_t to setattr on mandb_cache_t - Allow tmpfiles_t to setattr on mandb_cache_t - Make userdom_dontaudit_write_all_ not allow open - Allow init scripts to read all unit files - Add support for saphostctrl ports- Add kernel_read_system_state to sandbox_client_t - Add some of the missing access to kdumpgui - Allow systemd_dbusd_t to status the init system - Allow vmnet-natd to request the kernel to load a module - Allow gsf-office-thum to append .cache/gdm/session.log - realmd wants to read .config/dconf/user - Firewalld wants sys_nice/setsched - Allow tmpreaper to delete mandb cache files - Firewalld wants sys_nice/setsched - Allow firewalld to perform a DNS name resolution - Allown winbind to read /usr/share/samba/codepages/lowcase.dat - Add support for HTTPProxy* in /etc/freshclam.conf - Fix authlogin_yubike boolean - Extend smbd_selinux man page to include samba booleans - Allow dhcpc to execute consoletype - Allow ping to use inherited tmp files created in init scripts - On full relabel with unconfined domain disabled, initrc was running some chcon's - Allow people who delete man pages to delete mandb cache files- Add missing permissive domains- Add new mandb policy - ALlow systemd-tmpfiles_t to relabel mandb_cache_t - Allow logrotate to start all unit files- Add fixes for ctbd - Allow nmbd to stream connect to ctbd - Make cglear_t as nsswitch_domain - Fix bogus in interfaces - Allow openshift to read/write postfix public pipe - Add postfix_manage_spool_maildrop_files() interface - stickshift paths have been renamed to openshift - gnome-settings-daemon wants to write to /run/systemd/inhibit/ pipes - Update man pages, adding ENTRYPOINTS- Add mei_device_t - Make sure gpg content in homedir created with correct label - Allow dmesg to write to abrt cache files - automount wants to search virtual memory sysctls - Add support for hplip logs stored in /var/log/hp/tmp - Add labeling for /etc/owncloud/config.php - Allow setroubleshoot to send analysys to syslogd-journal - Allow virsh_t to interact with new fenced daemon - Allow gpg to write to /etc/mail/spamassassiin directories - Make dovecot_deliver_t a mail server delivery type - Add label for /var/tmp/DNS25- Fixes for tomcat_domain template interface- Remove init_systemd and init_upstart boolean, Move init_daemon_domain and init_system_domain to use attributes - Add attribute to all base os types. Allow all domains to read all ro base OS types- Additional unit files to be defined as power unit files - Fix more boolean names- Fix boolean name so subs will continue to work- dbus needs to start getty unit files - Add interface to allow system_dbusd_t to start the poweroff service - xdm wants to exec telepathy apps - Allow users to send messages to systemdlogind - Additional rules needed for systemd and other boot apps - systemd wants to list /home and /boot - Allow gkeyringd to write dbus/conf file - realmd needs to read /dev/urand - Allow readahead to delete /.readahead if labeled root_t, might get created before policy is loaded- Fixes to safe more rules - Re-write tomcat_domain_template() - Fix passenger labeling - Allow all domains to read man pages - Add ephemeral_port_t to the 'generic' port interfaces - Fix the names of postgresql booleans- Stop using attributes form netlabel_peer and syslog, auth_use_nsswitch setsup netlabel_peer - Move netlable_peer check out of booleans - Remove call to recvfrom_netlabel for kerberos call - Remove use of attributes when calling syslog call - Move -miscfiles_read_localization to domain.te to save hundreds of allow rules - Allow all domains to read locale files. This eliminates around 1500 allow rules- Cleanup nis_use_ypbind_uncond interface - Allow rndc to block suspend - tuned needs to modify the schedule of the kernel - Allow svirt_t domains to read alsa configuration files - ighten security on irc domains and make sure they label content in homedir correctly - Add filetrans_home_content for irc files - Dontaudit all getattr access for devices and filesystems for sandbox domains - Allow stapserver to search cgroups directories - Allow all postfix domains to talk to spamd- Add interfaces to ignore setattr until kernel fixes this to be checked after the DAC check - Change pam_t to pam_timestamp_t - Add dovecot_domain attribute and allow this attribute block_suspend capability2 - Add sanlock_use_fusefs boolean - numad wants send/recieve msg - Allow rhnsd to send syslog msgs - Make piranha-pulse as initrc domain - Update openshift instances to dontaudit setattr until the kernel is fixed.- Fix auth_login_pgm_domain() interface to allow domains also managed user tmp dirs because of #856880 related to pam_systemd - Remove pam_selinux.8 which conflicts with man page owned by the pam package - Allow glance-api to talk to mysql - ABRT wants to read Xorg.0.log if if it detects problem with Xorg - Fix gstreamer filename trans. interface- Man page fixes by Dan Walsh- Allow postalias to read postfix config files - Allow man2html to read man pages - Allow rhev-agentd to search all mountpoints - Allow rhsmcertd to read /dev/random - Add tgtd_stream_connect() interface - Add cyrus_write_data() interface - Dontaudit attempts by sandboxX clients connectiing to the xserver_port_t - Add port definition for tcp/81 as http_port_t - Fix /dev/twa labeling - Allow systemd to read modules config- Merge openshift policy - Allow xauth to read /dev/urandom - systemd needs to relabel content in /run/systemd directories - Files unconfined should be able to perform all services on all files - Puppet tmp file can be leaked to all domains - Dontaudit rhsmcertd-worker to search /root/.local - Allow chown capability for zarafa domains - Allow system cronjobs to runcon into openshift domains - Allow virt_bridgehelper_t to manage content in the svirt_home_t labeled directories- nmbd wants to create /var/nmbd - Stop transitioning out of anaconda and firstboot, just causes AVC messages - Allow clamscan to read /etc files - Allow bcfg2 to bind cyphesis port - heartbeat should be run as rgmanager_t instead of corosync_t - Add labeling for /etc/openldap/certs - Add labeling for /opt/sartest directory - Make crontab_t as userdom home reader - Allow tmpreaper to list admin_home dir - Add defition for imap_0 replay cache file - Add support for gitolite3 - Allow virsh_t to send syslog messages - allow domains that can read samba content to be able to list the directories also - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd - Separate out sandbox from sandboxX policy so we can disable it by default - Run dmeventd as lvm_t - Mounting on any directory requires setattr and write permissions - Fix use_nfs_home_dirs() boolean - New labels for pam_krb5 - Allow init and initrc domains to sys_ptrace since this is needed to look at processes not owned by uid 0 - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd- Separate sandbox policy into sandbox and sandboxX, and disable sandbox by default on fresh installs - Allow domains that can read etc_t to read etc_runtime_t - Allow all domains to use inherited tmpfiles- Allow realmd to read resolv.conf - Add pegasus_cache_t type - Label /usr/sbin/fence_virtd as virsh_exec_t - Add policy for pkcsslotd - Add support for cpglockd - Allow polkit-agent-helper to read system-auth-ac - telepathy-idle wants to read gschemas.compiled - Allow plymouthd to getattr on fs_t - Add slpd policy - Allow ksysguardproces to read/write config_usr_t- Fix labeling substitution so rpm will label /lib/systemd content correctly- Add file name transitions for ttyACM0 - spice-vdagent(d)'s are going to log over to syslog - Add sensord policy - Add more fixes for passenger policy related to puppet - Allow wdmd to create wdmd_tmpfs_t - Fix labeling for /var/run/cachefilesd\.pid - Add thumb_tmpfs_t files type- Allow svirt domains to manage the network since this is containerized - Allow svirt_lxc_net_t to send audit messages- Make "snmpwalk -mREDHAT-CLUSTER-MIB ...." working - Allow dlm_controld to execute dlm_stonith labeled as bin_t - Allow GFS2 working on F17 - Abrt needs to execute dmesg - Allow jockey to list the contents of modeprobe.d - Add policy for lightsquid as squid_cron_t - Mailscanner is creating files and directories in /tmp - dmesg is now reading /dev/kmsg - Allow xserver to communicate with secure_firmware - Allow fsadm tools (fsck) to read /run/mount contnet - Allow sysadm types to read /dev/kmsg -- Allow postfix, sssd, rpcd to block_suspend - udev seems to need secure_firmware capability - Allow virtd to send dbus messages to firewalld so it can configure the firewall- Fix labeling of content in /run created by virsh_t - Allow condor domains to read kernel sysctls - Allow condor_master to connect to amqp - Allow thumb drives to create shared memory and semaphores - Allow abrt to read mozilla_plugin config files - Add labels for lightsquid - Default files in /opt and /usr that end in .cgi as httpd_sys_script_t, allow - dovecot_auth_t uses ldap for user auth - Allow domains that can read dhcp_etc_t to read lnk_files - Add more then one watchdog device - Allow useradd_t to manage etc_t files so it can rename it and edit them - Fix invalid class dir should be fifo_file - Move /run/blkid to fsadm and make sure labeling is correct- Fix bogus regex found by eparis - Fix manage run interface since lvm needs more access - syslogd is searching cgroups directory - Fixes to allow virt-sandbox-service to manage lxc var run content- Fix Boolean settings - Add new libjavascriptcoregtk as textrel_shlib_t - Allow xdm_t to create xdm_home_t directories - Additional access required for systemd - Dontaudit mozilla_plugin attempts to ipc_lock - Allow tmpreaper to delete unlabeled files - Eliminate screen_tmp_t and allow it to manage user_tmp_t - Dontaudit mozilla_plugin_config_t to append to leaked file descriptors - Allow web plugins to connect to the asterisk ports - Condor will recreate the lock directory if it does not exist - Oddjob mkhomedir needs to connectto user processes - Make oddjob_mkhomedir_t a userdom home manager- Put placeholder back in place for proper numbering of capabilities - Systemd also configures init scripts- Fix ecryptfs interfaces - Bootloader seems to be trolling around /dev/shm and /dev - init wants to create /etc/systemd/system-update.target.wants - Fix systemd_filetrans call to move it out of tunable - Fix up policy to work with systemd userspace manager - Add secure_firmware capability and remove bogus epolwakeup - Call seutil_*_login_config interfaces where should be needed - Allow rhsmcertd to send signal to itself - Allow thin domains to send signal to itself - Allow Chrome_ChildIO to read dosfs_t- Add role rules for realmd, sambagui- Add new type selinux_login_config_t for /etc/selinux//logins/ - Additional fixes for seutil_manage_module_store() - dbus_system_domain() should be used with optional_policy - Fix svirt to be allowed to use fusefs file system - Allow login programs to read /run/ data created by systemd_login - sssd wants to write /etc/selinux//logins/ for SELinux PAM module - Fix svirt to be allowed to use fusefs file system - Allow piranha domain to use nsswitch - Sanlock needs to send Kill Signals to non root processes - Pulseaudio wants to execute /run/user/PID/.orc- Fix saslauthd when it tries to read /etc/shadow - Label gnome-boxes as a virt homedir - Need to allow svirt_t ability to getattr on nfs_t file systems - Update sanlock policy to solve all AVC's - Change confined users can optionally manage virt content - Handle new directories under ~/.cache - Add block suspend to appropriate domains - More rules required for containers - Allow login programs to read /run/ data created by systemd_logind - Allow staff users to run svirt_t processes- Update to upstream- More fixes for systemd to make rawhide booting from Dan Walsh- Add systemd fixes to make rawhide booting- Add systemd_logind_inhibit_var_run_t attribute - Remove corenet_all_recvfrom_unlabeled() for non-contrib policies because we moved it to domain.if for all domain_type - Add interface for mysqld to dontaudit signull to all processes - Label new /var/run/journal directory correctly - Allow users to inhibit suspend via systemd - Add new type for the /var/run/inhibit directory - Add interface to send signull to systemd_login so avahi can send them - Allow systemd_passwd to send syslog messages - Remove corenet_all_recvfrom_unlabeled() calling fro policy files - Allow editparams.cgi running as httpd_bugzilla_script_t to read /etc/group - Allow smbd to read cluster config - Add additional labeling for passenger - Allow dbus to inhibit suspend via systemd - Allow avahi to send signull to systemd_login- Add interface to dontaudit getattr access on sysctls - Allow sshd to execute /bin/login - Looks like xdm is recreating the xdm directory in ~/.cache/ on login - Allow syslog to use the leaked kernel_t unix_dgram_socket from system-jounald - Fix semanage to work with unconfined domain disabled on F18 - Dontaudit attempts by mozilla plugins to getattr on all kernel sysctls - Virt seems to be using lock files - Dovecot seems to be searching directories of every mountpoint - Allow jockey to read random/urandom, execute shell and install third-party drivers - Add aditional params to allow cachedfiles to manage its content - gpg agent needs to read /dev/random - The kernel hands an svirt domains /SYSxxxxx which is a tmpfs that httpd wants to read and write - Add a bunch of dontaudit rules to quiet svirt_lxc domains - Additional perms needed to run svirt_lxc domains - Allow cgclear to read cgconfig - Allow sys_ptrace capability for snmp - Allow freshclam to read /proc - Allow procmail to manage /home/user/Maildir content - Allow NM to execute wpa_cli - Allow amavis to read clamd system state - Regenerate man pages- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Add realmd and stapserver policies - Allow useradd to manage stap-server lib files - Tighten up capabilities for confined users - Label /etc/security/opasswd as shadow_t - Add label for /dev/ecryptfs - Allow condor_startd_t to start sshd with the ranged - Allow lpstat.cups to read fips_enabled file - Allow pyzor running as spamc_t to create /root/.pyzor directory - Add labelinf for amavisd-snmp init script - Add support for amavisd-snmp - Allow fprintd sigkill self - Allow xend (w/o libvirt) to start virtual machines - Allow aiccu to read /etc/passwd - Allow condor_startd to Make specified domain MCS trusted for setting any category set for the processes it executes - Add condor_startd_ranged_domtrans_to() interface - Add ssd_conf_t for /etc/sssd - accountsd needs to fchown some files/directories - Add ICACLient and zibrauserdata as mozilla_filetrans_home_content - SELinux reports afs_t needs dac_override to read /etc/mtab, even though everything works, adding dontaudit - Allow xend_t to read the /etc/passwd file- Until we figure out how to fix systemd issues, allow all apps that send syslog messages to send them to kernel_t - Add init_access_check() interface - Fix label on /usr/bin/pingus to not be labeled as ping_exec_t - Allow tcpdump to create a netlink_socket - Label newusers like useradd - Change xdm log files to be labeled xdm_log_t - Allow sshd_t with privsep to work in MLS - Allow freshclam to update databases thru HTTP proxy - Allow s-m-config to access check on systemd - Allow abrt to read public files by default - Fix amavis_create_pid_files() interface - Add labeling and filename transition for dbomatic.log - Allow system_dbusd_t to stream connect to bluetooth, and use its socket - Allow amavisd to execute fsav - Allow tuned to use sys_admin and sys_nice capabilities - Add php-fpm policy from Bryan - Add labeling for aeolus-configserver-thinwrapper - Allow thin domains to execute shell - Fix gnome_role_gkeyringd() interface description - Lot of interface fixes - Allow OpenMPI job running as condor_startd_ssh_t to manage condor lib files - Allow OpenMPI job to use kerberos - Make deltacloudd_t as nsswitch_domain - Allow xend_t to run lsscsi - Allow qemu-dm running as xend_t to create tun_socket - Add labeling for /opt/brother/Printers(.*/)?inf - Allow jockey-backend to read pyconfig-64.h labeled as usr_t - Fix clamscan_can_scan_system boolean - Allow lpr to connectto to /run/user/$USER/keyring-22uREb/pkcs11- initrc is calling exportfs which is not confined so it attempts to read nfsd_files - Fixes for passenger running within openshift. - Add labeling for all tomcat6 dirs - Add support for tomcat6 - Allow cobblerd to read /etc/passwd - Allow jockey to read sysfs and and execute binaries with bin_t - Allow thum to use user terminals - Allow cgclear to read cgconfig config files - Fix bcf2g.fc - Remove sysnet_dns_name_resolve() from policies where auth_use_nsswitch() is used for other domains - Allow dbomatic to execute ruby - abrt_watch_log should be abrt_domain - Allow mozilla_plugin to connect to gatekeeper port- add ptrace_child access to process - remove files_read_etc_files() calling from all policies which have auth_use_nsswith() - Allow boinc domains to manage boinc_lib_t lnk_files - Add support for boinc-client.service unit file - Add support for boinc.log - Allow mozilla_plugin execmod on mozilla home files if allow_ex - Allow dovecot_deliver_t to read dovecot_var_run_t - Allow ldconfig and insmod to manage kdumpctl tmp files - Move thin policy out from cloudform.pp and add a new thin poli - pacemaker needs to communicate with corosync streams - abrt is now started on demand by dbus - Allow certmonger to talk directly to Dogtag servers - Change labeling for /var/lib/cobbler/webui_sessions to httpd_c - Allow mozila_plugin to execute gstreamer home files - Allow useradd to delete all file types stored in the users hom - rhsmcertd reads the rpm database - Add support for lightdm- Add tomcat policy - Remove pyzor/razor policy - rhsmcertd reads the rpm database - Dontaudit thumb to setattr on xdm_tmp dir - Allow wicd to execute ldconfig in the networkmanager_t domain - Add /var/run/cherokee\.pid labeling - Allow mozilla_plugin to create mozilla_plugin_tmp_t lnk files too - Allow postfix-master to r/w pipes other postfix domains - Allow snort to create netlink_socket - Add kdumpctl policy - Allow firstboot to create tmp_t files/directories - /usr/bin/paster should not be labeled as piranha_exec_t - remove initrc_domain from tomcat - Allow ddclient to read /etc/passwd - Allow useradd to delete all file types stored in the users homedir - Allow ldconfig and insmod to manage kdumpctl tmp files - Firstboot should be just creating tmp_t dirs and xauth should be allowed to write to those - Transition xauth files within firstboot_tmp_t - Fix labeling of /run/media to match /media - Label all lxdm.log as xserver_log_t - Add port definition for mxi port - Allow local_login_t to execute tmux- apcupsd needs to read /etc/passwd - Sanlock allso sends sigkill - Allow glance_registry to connect to the mysqld port - Dontaudit mozilla_plugin trying to getattr on /dev/gpmctl - Allow firefox plugins/flash to connect to port 1234 - Allow mozilla plugins to delete user_tmp_t files - Add transition name rule for printers.conf.O - Allow virt_lxc_t to read urand - Allow systemd_loigind to list gstreamer_home_dirs - Fix labeling for /usr/bin - Fixes for cloudform services * support FIPS - Allow polipo to work as web caching - Allow chfn to execute tmux- Add support for ecryptfs * ecryptfs does not support xattr * we need labeling for HOMEDIR - Add policy for (u)mount.ecryptfs* - Fix labeling of kerbero host cache files, allow rpc.svcgssd to manage host cache - Allow dovecot to manage Maildir content, fix transitions to Maildir - Allow postfix_local to transition to dovecot_deliver - Dontaudit attempts to setattr on xdm_tmp_t, looks like bogus code - Cleanup interface definitions - Allow apmd to change with the logind daemon - Changes required for sanlock in rhel6 - Label /run/user/apache as httpd_tmp_t - Allow thumb to use lib_t as execmod if boolean turned on - Allow squid to create the squid directory in /var with the correct labe - Add a new policy for glusterd from Bryan Bickford (bbickfor@redhat.com) - Allow virtd to exec xend_exec_t without transition - Allow virtd_lxc_t to unmount all file systems- PolicyKit path has changed - Allow httpd connect to dirsrv socket - Allow tuned to write generic kernel sysctls - Dontaudit logwatch to gettr on /dev/dm-2 - Allow policykit-auth to manage kerberos files - Make condor_startd and rgmanager as initrc domain - Allow virsh to read /etc/passwd - Allow mount to mount on user_tmp_t for /run/user/dwalsh/gvfs - xdm now needs to execute xsession_exec_t - Need labels for /var/lib/gdm - Fix files_filetrans_named_content() interface - Add new attribute - initrc_domain - Allow systemd_logind_t to signal, signull, sigkill all processes - Add filetrans rules for etc_runtime files- Rename boolean names to remove allow_- Mass merge with upstream * new policy topology to include contrib policy modules * we have now two base policy patches- Fix description of authlogin_nsswitch_use_ldap - Fix transition rule for rhsmcertd_t needed for RHEL7 - Allow useradd to list nfs state data - Allow openvpn to manage its log file and directory - We want vdsm to transition to mount_t when executing mount command to make sure /etc/mtab remains labeled correctly - Allow thumb to use nvidia devices - Allow local_login to create user_tmp_t files for kerberos - Pulseaudio needs to read systemd_login /var/run content - virt should only transition named system_conf_t config files - Allow munin to execute its plugins - Allow nagios system plugin to read /etc/passwd - Allow plugin to connect to soundd port - Fix httpd_passwd to be able to ask passwords - Radius servers can use ldap for backing store - Seems to need to mount on /var/lib for xguest polyinstatiation to work. - Allow systemd_logind to list the contents of gnome keyring - VirtualGL need xdm to be able to manage content in /etc/opt/VirtualGL - Add policy for isns-utils- Add policy for subversion daemon - Allow boinc to read passwd - Allow pads to read kernel network state - Fix man2html interface for sepolgen-ifgen - Remove extra /usr/lib/systemd/system/smb - Remove all /lib/systemd and replace with /usr/lib/systemd - Add policy for man2html - Fix the label of kerberos_home_t to krb5_home_t - Allow mozilla plugins to use Citrix - Allow tuned to read /proc/sys/kernel/nmi_watchdog - Allow tune /sys options via systemd's tmpfiles.d "w" type- Dontaudit lpr_t to read/write leaked mozilla tmp files - Add file name transition for .grl-podcasts directory - Allow corosync to read user tmp files - Allow fenced to create snmp lib dirs/files - More fixes for sge policy - Allow mozilla_plugin_t to execute any application - Allow dbus to read/write any open file descriptors to any non security file on the system that it inherits to that it can pass them to another domain - Allow mongod to read system state information - Fix wrong type, we should dontaudit sys_admin for xdm_t not xserver_t - Allow polipo to manage polipo_cache dirs - Add jabbar_client port to mozilla_plugin_t - Cleanup procmail policy - system bus will pass around open file descriptors on files that do not have labels on them - Allow l2tpd_t to read system state - Allow tuned to run ls /dev - Allow sudo domains to read usr_t files - Add label to machine-id - Fix corecmd_read_bin_symlinks cut and paste error- Fix pulseaudio port definition - Add labeling for condor_starter - Allow chfn_t to creat user_tmp_files - Allow chfn_t to execute bin_t - Allow prelink_cron_system_t to getpw calls - Allow sudo domains to manage kerberos rcache files - Allow user_mail_domains to work with courie - Port definitions necessary for running jboss apps within openshift - Add support for openstack-nova-metadata-api - Add support for nova-console* - Add support for openstack-nova-xvpvncproxy - Fixes to make privsep+SELinux working if we try to use chage to change passwd - Fix auth_role() interface - Allow numad to read sysfs - Allow matahari-rpcd to execute shell - Add label for ~/.spicec - xdm is executing lspci as root which is requesting a sys_admin priv but seems to succeed without it - Devicekit_disk wants to read the logind sessions file when writing a cd - Add fixes for condor to make condor jobs working correctly - Change label of /var/log/rpmpkgs to cron_log_t - Access requires to allow systemd-tmpfiles --create to work. - Fix obex to be a user application started by the session bus. - Add additional filename trans rules for kerberos - Fix /var/run/heartbeat labeling - Allow apps that are managing rcache to file trans correctly - Allow openvpn to authenticate against ldap server - Containers need to listen to network starting and stopping events- Make systemd unit files less specific- Fix zarafa labeling - Allow guest_t to fix labeling - corenet_tcp_bind_all_unreserved_ports(ssh_t) should be called with the user_tcp_server boolean - add lxc_contexts - Allow accountsd to read /proc - Allow restorecond to getattr on all file sytems - tmpwatch now calls getpw - Allow apache daemon to transition to pwauth domain - Label content under /var/run/user/NAME/keyring* as gkeyringd_tmp_t - The obex socket seems to be a stream socket - dd label for /var/run/nologin- Allow jetty running as httpd_t to read hugetlbfs files - Allow sys_nice and setsched for rhsmcertd - Dontaudit attempts by mozilla_plugin_t to bind to ssdp ports - Allow setfiles to append to xdm_tmp_t - Add labeling for /export as a usr_t directory - Add labels for .grl files created by gstreamer- Add labeling for /usr/share/jetty/bin/jetty.sh - Add jetty policy which contains file type definitios - Allow jockey to use its own fifo_file and make this the default for all domains - Allow mozilla_plugins to use spice (vnc_port/couchdb) - asterisk wants to read the network state - Blueman now uses /var/lib/blueman- Add label for nodejs_debug - Allow mozilla_plugin_t to create ~/.pki directory and content- Add clamscan_can_scan_system boolean - Allow mysqld to read kernel network state - Allow sshd to read/write condor lib files - Allow sshd to read/write condor-startd tcp socket - Fix description on httpd_graceful_shutdown - Allow glance_registry to communicate with mysql - dbus_system_domain is using systemd to lauch applications - add interfaces to allow domains to send kill signals to user mail agents - Remove unnessary access for svirt_lxc domains, add privs for virtd_lxc_t - Lots of new access required for secure containers - Corosync needs sys_admin capability - ALlow colord to create shm - .orc should be allowed to be created by any app that can create gstream home content, thumb_t to be specific - Add boolean to control whether or not mozilla plugins can create random content in the users homedir - Add new interface to allow domains to list msyql_db directories, needed for libra - shutdown has to be allowed to delete etc_runtime_t - Fail2ban needs to read /etc/passwd - Allow ldconfig to create /var/cache/ldconfig - Allow tgtd to read hardware state information - Allow collectd to create packet socket - Allow chronyd to send signal to itself - Allow collectd to read /dev/random - Allow collectd to send signal to itself - firewalld needs to execute restorecon - Allow restorecon and other login domains to execute restorecon- Allow logrotate to getattr on systemd unit files - Add support for tor systemd unit file - Allow apmd to create /var/run/pm-utils with the correct label - Allow l2tpd to send sigkill to pppd - Allow pppd to stream connect to l2tpd - Add label for scripts in /etc/gdm/ - Allow systemd_logind_t to ignore mcs constraints on sigkill - Fix files_filetrans_system_conf_named_files() interface - Add labels for /usr/share/wordpress/wp-includes/*.php - Allow cobbler to get SELinux mode and booleans- Add unconfined_execmem_exec_t as an alias to bin_t - Allow fenced to read snmp var lib files, also allow it to read usr_t - ontaudit access checks on all executables from mozilla_plugin - Allow all user domains to setexec, so that sshd will work properly if it call setexec(NULL) while running withing a user mode - Allow systemd_tmpfiles_t to getattr all pipes and sockets - Allow glance-registry to send system log messages - semanage needs to manage mock lib files/dirs- Add policy for abrt-watch-log - Add definitions for jboss_messaging ports - Allow systemd_tmpfiles to manage printer devices - Allow oddjob to use nsswitch - Fix labeling of log files for postgresql - Allow mozilla_plugin_t to execmem and execstack by default - Allow firewalld to execute shell - Fix /etc/wicd content files to get created with the correct label - Allow mcelog to exec shell - Add ~/.orc as a gstreamer_home_t - /var/spool/postfix/lib64 should be labeled lib_t - mpreaper should be able to list all file system labeled directories - Add support for apache to use openstack - Add labeling for /etc/zipl.conf and zipl binary - Turn on allow_execstack and turn off telepathy transition for final release- More access required for virt_qmf_t - Additional assess required for systemd-logind to support multi-seat - Allow mozilla_plugin to setrlimit - Revert changes to fuse file system to stop deadlock- Allow condor domains to connect to ephemeral ports - More fixes for condor policy - Allow keystone to stream connect to mysqld - Allow mozilla_plugin_t to read generic USB device to support GPS devices - Allow thum to file name transition gstreamer home content - Allow thum to read all non security files - Allow glance_api_t to connect to ephemeral ports - Allow nagios plugins to read /dev/urandom - Allow syslogd to search postfix spool to support postfix chroot env - Fix labeling for /var/spool/postfix/dev - Allow wdmd chown - Label .esd_auth as pulseaudio_home_t - Have no idea why keyring tries to write to /run/user/dwalsh/dconf/user, but we can dontaudit for now- Add support for clamd+systemd - Allow fresclam to execute systemctl to handle clamd - Change labeling for /usr/sbin/rpc.ypasswd.env - Allow yppaswd_t to execute yppaswd_exec_t - Allow yppaswd_t to read /etc/passwd - Gnomekeyring socket has been moved to /run/user/USER/ - Allow samba-net to connect to ldap port - Allow signal for vhostmd - allow mozilla_plugin_t to read user_home_t socket - New access required for secure Linux Containers - zfs now supports xattrs - Allow quantum to execute sudo and list sysfs - Allow init to dbus chat with the firewalld - Allow zebra to read /etc/passwd- Allow svirt_t to create content in the users homedir under ~/.libvirt - Fix label on /var/lib/heartbeat - Allow systemd_logind_t to send kill signals to all processes started by a user - Fuse now supports Xattr Support- upowered needs to setsched on the kernel - Allow mpd_t to manage log files - Allow xdm_t to create /var/run/systemd/multi-session-x - Add rules for missedfont.log to be used by thumb.fc - Additional access required for virt_qmf_t - Allow dhclient to dbus chat with the firewalld - Add label for lvmetad - Allow systemd_logind_t to remove userdomain sock_files - Allow cups to execute usr_t files - Fix labeling on nvidia shared libraries - wdmd_t needs access to sssd and /etc/passwd - Add boolean to allow ftp servers to run in passive mode - Allow namepspace_init_t to relabelto/from a different user system_u from the user the namespace_init running with - Fix using httpd_use_fusefs - Allow chrome_sandbox_nacl to write inherited user tmp files as we allow it for chrome_sandbox- Rename rdate port to time port, and allow gnomeclock to connect to it - We no longer need to transition to ldconfig from rpm, rpm_script, or anaconda - /etc/auto.* should be labeled bin_t - Add httpd_use_fusefs boolean - Add fixes for heartbeat - Allow sshd_t to signal processes that it transitions to - Add condor policy - Allow svirt to create monitors in ~/.libvirt - Allow dovecot to domtrans sendmail to handle sieve scripts - Lot of fixes for cfengine- /var/run/postmaster.* labeling is no longer needed - Alllow drbdadmin to read /dev/urandom - l2tpd_t seems to use ptmx - group+ and passwd+ should be labeled as /etc/passwd - Zarafa-indexer is a socket- Ensure lastlog is labeled correctly - Allow accountsd to read /proc data about gdm - Add fixes for tuned - Add bcfg2 fixes which were discovered during RHEL6 testing - More fixes for gnome-keyring socket being moved - Run semanage as a unconfined domain, and allow initrc_t to create tmpfs_t sym links on shutdown - Fix description for files_dontaudit_read_security_files() interface- Add new policy and man page for bcfg2 - cgconfig needs to use getpw calls - Allow domains that communicate with the keyring to use cache_home_t instead of gkeyringd_tmpt - gnome-keyring wants to create a directory in cache_home_t - sanlock calls getpw- Add numad policy and numad man page - Add fixes for interface bugs discovered by SEWatch - Add /tmp support for squid - Add fix for #799102 * change default labeling for /var/run/slapd.* sockets - Make thumb_t as userdom_home_reader - label /var/lib/sss/mc same as pubconf, so getpw domains can read it - Allow smbspool running as cups_t to stream connect to nmbd - accounts needs to be able to execute passwd on behalf of users - Allow systemd_tmpfiles_t to delete boot flags - Allow dnssec_trigger to connect to apache ports - Allow gnome keyring to create sock_files in ~/.cache - google_authenticator is using .google_authenticator - sandbox running from within firefox is exposing more leaks - Dontaudit thumb to read/write /dev/card0 - Dontaudit getattr on init_exec_t for gnomeclock_t - Allow certmonger to do a transition to certmonger_unconfined_t - Allow dhcpc setsched which is caused by nmcli - Add rpm_exec_t for /usr/sbin/bcfg2 - system cronjobs are sending dbus messages to systemd_logind - Thumnailers read /dev/urand- Allow auditctl getcap - Allow vdagent to use libsystemd-login - Allow abrt-dump-oops to search /etc/abrt - Got these avc's while trying to print a boarding pass from firefox - Devicekit is now putting the media directory under /run/media - Allow thumbnailers to create content in ~/.thumbails directory - Add support for proL2TPd by Dominick Grift - Allow all domains to call getcap - wdmd seems to get a random chown capability check that it does not need - Allow vhostmd to read kernel sysctls- Allow chronyd to read unix - Allow hpfax to read /etc/passwd - Add support matahari vios-proxy-* apps and add virtd_exec_t label for them - Allow rpcd to read quota_db_t - Update to man pages to match latest policy - Fix bug in jockey interface for sepolgen-ifgen - Add initial svirt_prot_exec_t policy- More fixes for systemd from Dan Walsh- Add a new type for /etc/firewalld and allow firewalld to write to this directory - Add definition for ~/Maildir, and allow mail deliver domains to write there - Allow polipo to run from a cron job - Allow rtkit to schedule wine processes - Allow mozilla_plugin_t to acquire a bug, and allow it to transition gnome content in the home dir to the proper label - Allow users domains to send signals to consolehelper domains- More fixes for boinc policy - Allow polipo domain to create its own cache dir and pid file - Add systemctl support to httpd domain - Add systemctl support to polipo, allow NetworkManager to manage the service - Add policy for jockey-backend - Add support for motion daemon which is now covered by zoneminder policy - Allow colord to read/write motion tmpfs - Allow vnstat to search through var_lib_t directories - Stop transitioning to quota_t, from init an sysadm_t- Add svirt_lxc_file_t as a customizable type- Add additional fixes for icmp nagios plugin - Allow cron jobs to open fifo_files from cron, since service script opens /dev/stdin - Add certmonger_unconfined_exec_t - Make sure tap22 device is created with the correct label - Allow staff users to read systemd unit files - Merge in previously built policy - Arpwatch needs to be able to start netlink sockets in order to start - Allow cgred_t to sys_ptrace to look at other DAC Processes- Back port some of the access that was allowed in nsplugin_t - Add definitiona for couchdb ports - Allow nagios to use inherited users ttys - Add git support for mock - Allow inetd to use rdate port - Add own type for rdate port - Allow samba to act as a portmapper - Dontaudit chrome_sandbox attempts to getattr on chr_files in /dev - New fixes needed for samba4 - Allow apps that use lib_t to read lib_t symlinks- Add policy for nove-cert - Add labeling for nova-openstack systemd unit files - Add policy for keystoke- Fix man pages fro domains - Add man pages for SELinux users and roles - Add storage_dev_filetrans_named_fixed_disk() and use it for smartmon - Add policy for matahari-rpcd - nfsd executes mount command on restart - Matahari domains execute renice and setsched - Dontaudit leaked tty in mozilla_plugin_config - mailman is changing to a per instance naming - Add 7600 and 4447 as jboss_management ports - Add fixes for nagios event handlers - Label httpd.event as httpd_exec_t, it is an apache daemon- Add labeling for /var/spool/postfix/dev/log - NM reads sysctl.conf - Iscsi log file context specification fix - Allow mozilla plugins to send dbus messages to user domains that transition to it - Allow mysql to read the passwd file - Allow mozilla_plugin_t to create mozilla home dirs in user homedir - Allow deltacloud to read kernel sysctl - Allow postgresql_t to connectto itselfAllow postgresql_t to connectto itself - Allow postgresql_t to connectto itself - Add login_userdomain attribute for users which can log in using terminal- Allow sysadm_u to reach system_r by default #784011 - Allow nagios plugins to use inherited user terminals - Razor labeling is not used no longer - Add systemd support for matahari - Add port_types to man page, move booleans to the top, fix some english - Add support for matahari-sysconfig-console - Clean up matahari.fc - Fix matahari_admin() interfac - Add labels for/etc/ssh/ssh_host_*.pub keys- Allow ksysguardproces to send system log msgs - Allow boinc setpgid and signull - Allow xdm_t to sys_ptrace to run pidof command - Allow smtpd_t to manage spool files/directories and symbolic links - Add labeling for jetty - Needed changes to get unbound/dnssec to work with openswan- Add user_fonts_t alias xfs_tmp_t - Since depmod now runs as insmod_t we need to write to kernel_object_t - Allow firewalld to dbus chat with networkmanager - Allow qpidd to connect to matahari ports - policykit needs to read /proc for uses not owned by it - Allow systemctl apps to connecto the init stream- Turn on deny_ptrace boolean- Remove pam_selinux.8 man page. There was a conflict.- Add proxy class and read access for gssd_proxy - Separate out the sharing public content booleans - Allow certmonger to execute a script and send signals to apache and dirsrv to reload the certificate - Add label transition for gstream-0.10 and 12 - Add booleans to allow rsync to share nfs and cifs file sytems - chrome_sandbox wants to read the /proc/PID/exe file of the program that executed it - Fix filename transitions for cups files - Allow denyhosts to read "unix" - Add file name transition for locale.conf.new - Allow boinc projects to gconf config files - sssd needs to be able to increase the socket limit under certain loads - sge_execd needs to read /etc/passwd - Allow denyhost to check network state - NetworkManager needs to read sessions data - Allow denyhost to check network state - Allow xen to search virt images directories - Add label for /dev/megaraid_sas_ioctl_node - Add autogenerated man pages- Allow boinc project to getattr on fs - Allow init to execute initrc_state_t - rhev-agent package was rename to ovirt-guest-agent - If initrc_t creates /etc/local.conf then we need to make sure it is labeled correctly - sytemd writes content to /run/initramfs and executes it on shutdown - kdump_t needs to read /etc/mtab, should be back ported to F16 - udev needs to load kernel modules in early system boot- Need to add sys_ptrace back in since reading any content in /proc can cause these accesses - Add additional systemd interfaces which are needed fro *_admin interfaces - Fix bind_admin() interface- Allow firewalld to read urand - Alias java, execmem_mono to bin_t to allow third parties - Add label for kmod - /etc/redhat-lsb contains binaries - Add boolean to allow gitosis to send mail - Add filename transition also for "event20" - Allow systemd_tmpfiles_t to delete all file types - Allow collectd to ipc_lock- make consoletype_exec optional, so we can remove consoletype policy - remove unconfined_permisive.patch - Allow openvpn_t to inherit user home content and tmp content - Fix dnssec-trigger labeling - Turn on obex policy for staff_t - Pem files should not be secret - Add lots of rules to fix AVC's when playing with containers - Fix policy for dnssec - Label ask-passwd directories correctly for systemd- sshd fixes seem to be causing unconfined domains to dyntrans to themselves - fuse file system is now being mounted in /run/user - systemd_logind is sending signals to processes that are dbus messaging with it - Add support for winshadow port and allow iscsid to connect to this port - httpd should be allowed to bind to the http_port_t udp socket - zarafa_var_lib_t can be a lnk_file - A couple of new .xsession-errors files - Seems like user space and login programs need to read logind_sessions_files - Devicekit disk seems to be being launched by systemd - Cleanup handling of setfiles so most of rules in te file - Correct port number for dnssec - logcheck has the home dir set to its cache- Add policy for grindengine MPI jobs- Add new sysadm_secadm.pp module * contains secadm definition for sysadm_t - Move user_mail_domain access out of the interface into the te file - Allow httpd_t to create httpd_var_lib_t directories as well as files - Allow snmpd to connect to the ricci_modcluster stream - Allow firewalld to read /etc/passwd - Add auth_use_nsswitch for colord - Allow smartd to read network state - smartdnotify needs to read /etc/group- Allow gpg and gpg_agent to store sock_file in gpg_secret_t directory - lxdm startup scripts should be labeled bin_t, so confined users will work - mcstransd now creates a pid, needs back port to F16 - qpidd should be allowed to connect to the amqp port - Label devices 010-029 as usb devices - ypserv packager says ypserv does not use tmp_t so removing selinux policy types - Remove all ptrace commands that I believe are caused by the kernel/ps avcs - Add initial Obex policy - Add logging_syslogd_use_tty boolean - Add polipo_connect_all_unreserved bolean - Allow zabbix to connect to ftp port - Allow systemd-logind to be able to switch VTs - Allow apache to communicate with memcached through a sock_file- Fix file_context.subs_dist for now to work with pre usrmove- More /usr move fixes- Add zabbix_can_network boolean - Add httpd_can_connect_zabbix boolean - Prepare file context labeling for usrmove functions - Allow system cronjobs to read kernel network state - Add support for selinux_avcstat munin plugin - Treat hearbeat with corosync policy - Allow corosync to read and write to qpidd shared mem - mozilla_plugin is trying to run pulseaudio - Fixes for new sshd patch for running priv sep domains as the users context - Turn off dontaudit rules when turning on allow_ypbind - udev now reads /etc/modules.d directory- Turn on deny_ptrace boolean for the Rawhide run, so we can test this out - Cups exchanges dbus messages with init - udisk2 needs to send syslog messages - certwatch needs to read /etc/passwd- Add labeling for udisks2 - Allow fsadmin to communicate with the systemd process- Treat Bip with bitlbee policy * Bip is an IRC proxy - Add port definition for interwise port - Add support for ipa_memcached socket - systemd_jounald needs to getattr on all processes - mdadmin fixes * uses getpw - amavisd calls getpwnam() - denyhosts calls getpwall()- Setup labeling of /var/rsa and /var/lib/rsa to allow login programs to write there - bluetooth says they do not use /tmp and want to remove the type - Allow init to transition to colord - Mongod needs to read /proc/sys/vm/zone_reclaim_mode - Allow postfix_smtpd_t to connect to spamd - Add boolean to allow ftp to connect to all ports > 1023 - Allow sendmain to write to inherited dovecot tmp files - setroubleshoot needs to be able to execute rpm to see what version of packages- Merge systemd patch - systemd-tmpfiles wants to relabel /sys/devices/system/cpu/online - Allow deltacloudd dac_override, setuid, setgid caps - Allow aisexec to execute shell - Add use_nfs_home_dirs boolean for ssh-keygen- Fixes to make rawhide boot in enforcing mode with latest systemd changes- Add labeling for /var/run/systemd/journal/syslog - libvirt sends signals to ifconfig - Allow domains that read logind session files to list them- Fixed destined form libvirt-sandbox - Allow apps that list sysfs to also read sympolicy links in this filesystem - Add ubac_constrained rules for chrome_sandbox - Need interface to allow domains to use tmpfs_t files created by the kernel, used by libra - Allow postgresql to be executed by the caller - Standardize interfaces of daemons - Add new labeling for mm-handler - Allow all matahari domains to read network state and etc_runtime_t files- New fix for seunshare, requires seunshare_domains to be able to mounton / - Allow systemctl running as logrotate_t to connect to private systemd socket - Allow tmpwatch to read meminfo - Allow rpc.svcgssd to read supported_krb5_enctype - Allow zarafa domains to read /dev/random and /dev/urandom - Allow snmpd to read dev_snmp6 - Allow procmail to talk with cyrus - Add fixes for check_disk and check_nagios plugins- default trans rules for Rawhide policy - Make sure sound_devices controlC* are labeled correctly on creation - sssd now needs sys_admin - Allow snmp to read all proc_type - Allow to setup users homedir with quota.group- Add httpd_can_connect_ldap() interface - apcupsd_t needs to use seriel ports connected to usb devices - Kde puts procmail mail directory under ~/.local/share - nfsd_t can trigger sys_rawio on tests that involve too many mountpoints, dontaudit for now - Add labeling for /sbin/iscsiuio- Add label for /var/lib/iscan/interpreter - Dont audit writes to leaked file descriptors or redirected output for nacl - NetworkManager needs to write to /sys/class/net/ib*/mode- Allow abrt to request the kernel to load a module - Make sure mozilla content is labeled correctly - Allow tgtd to read system state - More fixes for boinc * allow to resolve dns name * re-write boinc policy to use boinc_domain attribute - Allow munin services plugins to use NSCD services- Allow mozilla_plugin_t to manage mozilla_home_t - Allow ssh derived domain to execute ssh-keygen in the ssh_keygen_t domain - Add label for tumblerd- Fixes for xguest package- Fixes related to /bin, /sbin - Allow abrt to getattr on blk files - Add type for rhev-agent log file - Fix labeling for /dev/dmfm - Dontaudit wicd leaking - Allow systemd_logind_t to look at process info of apps that exchange dbus messages with it - Label /etc/locale.conf correctly - Allow user_mail_t to read /dev/random - Allow postfix-smtpd to read MIMEDefang - Add label for /var/log/suphp.log - Allow swat_t to connect and read/write nmbd_t sock_file - Allow systemd-tmpfiles to setattr for /run/user/gdm/dconf - Allow systemd-tmpfiles to change user identity in object contexts - More fixes for rhev_agentd_t consolehelper policy- Use fs_use_xattr for squashf - Fix procs_type interface - Dovecot has a new fifo_file /var/run/dovecot/stats-mail - Dovecot has a new fifo_file /var/run/stats-mail - Colord does not need to connect to network - Allow system_cronjob to dbus chat with NetworkManager - Puppet manages content, want to make sure it labels everything correctly- Change port 9050 to tor_socks_port_t and then allow openvpn to connect to it - Allow all postfix domains to use the fifo_file - Allow sshd_t to getattr on all file systems in order to generate avc on nfs_t - Allow apmd_t to read grub.cfg - Let firewallgui read the selinux config - Allow systemd-tmpfiles to delete content in /root that has been moved to /tmp - Fix devicekit_manage_pid_files() interface - Allow squid to check the network state - Dontaudit colord getattr on file systems - Allow ping domains to read zabbix_tmp_t files- Allow mcelog_t to create dir and file in /var/run and label it correctly - Allow dbus to manage fusefs - Mount needs to read process state when mounting gluster file systems - Allow collectd-web to read collectd lib files - Allow daemons and system processes started by init to read/write the unix_stream_socket passed in from as stdin/stdout/stderr - Allow colord to get the attributes of tmpfs filesystem - Add sanlock_use_nfs and sanlock_use_samba booleans - Add bin_t label for /usr/lib/virtualbox/VBoxManage- Add ssh_dontaudit_search_home_dir - Changes to allow namespace_init_t to work - Add interface to allow exec of mongod, add port definition for mongod port, 27017 - Label .kde/share/apps/networkmanagement/certificates/ as home_cert_t - Allow spamd and clamd to steam connect to each other - Add policy label for passwd.OLD - More fixes for postfix and postfix maildro - Add ftp support for mozilla plugins - Useradd now needs to manage policy since it calls libsemanage - Fix devicekit_manage_log_files() interface - Allow colord to execute ifconfig - Allow accountsd to read /sys - Allow mysqld-safe to execute shell - Allow openct to stream connect to pcscd - Add label for /var/run/nm-dns-dnsmasq\.conf - Allow networkmanager to chat with virtd_t- Pulseaudio changes - Merge patches- Merge patches back into git repository.- Remove allow_execmem boolean and replace with deny_execmem boolean- Turn back on allow_execmem boolean- Add more MCS fixes to make sandbox working - Make faillog MLS trusted to make sudo_$1_t working - Allow sandbox_web_client_t to read passwd_file_t - Add .mailrc file context - Remove execheap from openoffice domain - Allow chrome_sandbox_nacl_t to read cpu_info - Allow virtd to relabel generic usb which is need if USB device - Fixes for virt.if interfaces to consider chr_file as image file type- Remove Open Office policy - Remove execmem policy- MCS fixes - quota fixes- Remove transitions to consoletype- Make nvidia* to be labeled correctly - Fix abrt_manage_cache() interface - Make filetrans rules optional so base policy will build - Dontaudit chkpwd_t access to inherited TTYS - Make sure postfix content gets created with the correct label - Allow gnomeclock to read cgroup - Fixes for cloudform policy- Check in fixed for Chrome nacl support- Begin removing qemu_t domain, we really no longer need this domain. - systemd_passwd needs dac_overide to communicate with users TTY's - Allow svirt_lxc domains to send kill signals within their container- Remove qemu.pp again without causing a crash- Remove qemu.pp, everything should use svirt_t or stay in its current domain- Allow policykit to talk to the systemd via dbus - Move chrome_sandbox_nacl_t to permissive domains - Additional rules for chrome_sandbox_nacl- Change bootstrap name to nacl - Chrome still needs execmem - Missing role for chrome_sandbox_bootstrap - Add boolean to remove execmem and execstack from virtual machines - Dontaudit xdm_t doing an access_check on etc_t directories- Allow named to connect to dirsrv by default - add ldapmap1_0 as a krb5_host_rcache_t file - Google chrome developers asked me to add bootstrap policy for nacl stuff - Allow rhev_agentd_t to getattr on mountpoints - Postfix_smtpd_t needs access to milters and cleanup seems to read/write postfix_smtpd_t unix_stream_sockets- Fixes for cloudform policies which need to connect to random ports - Make sure if an admin creates modules content it creates them with the correct label - Add port 8953 as a dns port used by unbound - Fix file name transition for alsa and confined users- Turn on mock_t and thumb_t for unconfined domains- Policy update should not modify local contexts- Remove ada policy- Remove tzdata policy - Add labeling for udev - Add cloudform policy - Fixes for bootloader policy- Add policies for nova openstack- Add fixes for nova-stack policy- Allow svirt_lxc_domain to chr_file and blk_file devices if they are in the domain - Allow init process to setrlimit on itself - Take away transition rules for users executing ssh-keygen - Allow setroubleshoot_fixit_t to read /dev/urand - Allow sshd to relbale tunnel sockets - Allow fail2ban domtrans to shorewall in the same way as with iptables - Add support for lnk files in the /var/lib/sssd directory - Allow system mail to connect to courier-authdaemon over an unix stream socket- Add passwd_file_t for /etc/ptmptmp- Dontaudit access checks for all executables, gnome-shell is doing access(EXEC, X_OK) - Make corosync to be able to relabelto cluster lib fies - Allow samba domains to search /var/run/nmbd - Allow dirsrv to use pam - Allow thumb to call getuid - chrome less likely to get mmap_zero bug so removing dontaudit - gimp help-browser has built in javascript - Best guess is that devices named /dev/bsr4096 should be labeled as cpu_device_t - Re-write glance policy- Move dontaudit sys_ptrace line from permissive.te to domain.te - Remove policy for hal, it no longer exists- Don't check md5 size or mtime on certain config files- Remove allow_ptrace and replace it with deny_ptrace, which will remove all ptrace from the system - Remove 2000 dontaudit rules between confined domains on transition and replace with single dontaudit domain domain:process { noatsecure siginh rlimitinh } ;- Fixes for bootloader policy - $1_gkeyringd_t needs to read $HOME/%USER/.local/share/keystore - Allow nsplugin to read /usr/share/config - Allow sa-update to update rules - Add use_fusefs_home_dirs for chroot ssh option - Fixes for grub2 - Update systemd_exec_systemctl() interface - Allow gpg to read the mail spool - More fixes for sa-update running out of cron job - Allow ipsec_mgmt_t to read hardware state information - Allow pptp_t to connect to unreserved_port_t - Dontaudit getattr on initctl in /dev from chfn - Dontaudit getattr on kernel_core from chfn - Add systemd_list_unit_dirs to systemd_exec_systemctl call - Fixes for collectd policy - CHange sysadm_t to create content as user_tmp_t under /tmp- Shrink size of policy through use of attributes for userdomain and apache- Allow virsh to read xenstored pid file - Backport corenetwork fixes from upstream - Do not audit attempts by thumb to search config_home_t dirs (~/.config) - label ~/.cache/telepathy/logger telepathy_logger_cache_home_t - allow thumb to read generic data home files (mime.type)- Allow nmbd to manage sock file in /var/run/nmbd - ricci_modservice send syslog msgs - Stop transitioning from unconfined_t to ldconfig_t, but make sure /etc/ld.so.cache is labeled correctly - Allow systemd_logind_t to manage /run/USER/dconf/user- Fix missing patch from F16- Allow logrotate setuid and setgid since logrotate is supposed to do it - Fixes for thumb policy by grift - Add new nfsd ports - Added fix to allow confined apps to execmod on chrome - Add labeling for additional vdsm directories - Allow Exim and Dovecot SASL - Add label for /var/run/nmbd - Add fixes to make virsh and xen working together - Colord executes ls - /var/spool/cron is now labeled as user_cron_spool_t- Stop complaining about leaked file descriptors during install- Remove java and mono module and merge into execmem- Fixes for thumb policy and passwd_file_t- Fixes caused by the labeling of /etc/passwd - Add thumb.patch to transition unconfined_t to thumb_t for Rawhide- Add support for Clustered Samba commands - Allow ricci_modrpm_t to send log msgs - move permissive virt_qmf_t from virt.te to permissivedomains.te - Allow ssh_t to use kernel keyrings - Add policy for libvirt-qmf and more fixes for linux containers - Initial Polipo - Sanlock needs to run ranged in order to kill svirt processes - Allow smbcontrol to stream connect to ctdbd- Add label for /etc/passwd- Change unconfined_domains to permissive for Rawhide - Add definition for the ephemeral_ports- Make mta_role() active - Allow asterisk to connect to jabber client port - Allow procmail to read utmp - Add NIS support for systemd_logind_t - Allow systemd_logind_t to manage /run/user/$USER/dconf dir which is labeled as config_home_t - Fix systemd_manage_unit_dirs() interface - Allow ssh_t to manage directories passed into it - init needs to be able to create and delete unit file directories - Fix typo in apache_exec_sys_script - Add ability for logrotate to transition to awstat domain- Change screen to use screen_domain attribute and allow screen_domains to read all process domain state - Add SELinux support for ssh pre-auth net process in F17 - Add logging_syslogd_can_sendmail boolean- Add definition for ephemeral ports - Define user_tty_device_t as a customizable_type- Needs to require a new version of checkpolicy - Interface fixes- Allow sanlock to manage virt lib files - Add virt_use_sanlock booelan - ksmtuned is trying to resolve uids - Make sure .gvfs is labeled user_home_t in the users home directory - Sanlock sends kill signals and needs the kill capability - Allow mockbuild to work on nfs homedirs - Fix kerberos_manage_host_rcache() interface - Allow exim to read system state- Allow systemd-tmpfiles to set the correct labels on /var/run, /tmp and other files - We want any file type that is created in /tmp by a process running as initrc_t to be labeled initrc_tmp_t- Allow collectd to read hardware state information - Add loop_control_device_t - Allow mdadm to request kernel to load module - Allow domains that start other domains via systemctl to search unit dir - systemd_tmpfilses, needs to list any file systems mounted on /tmp - No one can explain why radius is listing the contents of /tmp, so we will dontaudit - If I can manage etc_runtime files, I should be able to read the links - Dontaudit hostname writing to mock library chr_files - Have gdm_t setup labeling correctly in users home dir - Label content unde /var/run/user/NAME/dconf as config_home_t - Allow sa-update to execute shell - Make ssh-keygen working with fips_enabled - Make mock work for staff_t user - Tighten security on mock_t- removing unconfined_notrans_t no longer necessary - Clean up handling of secure_mode_insmod and secure_mode_policyload - Remove unconfined_mount_t- Add exim_exec_t label for /usr/sbin/exim_tidydb - Call init_dontaudit_rw_stream_socket() interface in mta policy - sssd need to search /var/cache/krb5rcache directory - Allow corosync to relabel own tmp files - Allow zarafa domains to send system log messages - Allow ssh to do tunneling - Allow initrc scripts to sendto init_t unix_stream_socket - Changes to make sure dmsmasq and virt directories are labeled correctly - Changes needed to allow sysadm_t to manage systemd unit files - init is passing file descriptors to dbus and on to system daemons - Allow sulogin additional access Reported by dgrift and Jeremy Miller - Steve Grubb believes that wireshark does not need this access - Fix /var/run/initramfs to stop restorecon from looking at - pki needs another port - Add more labels for cluster scripts - Allow apps that manage cgroup_files to manage cgroup link files - Fix label on nfs-utils scripts directories - Allow gatherd to read /dev/rand and /dev/urand- pki needs another port - Add more labels for cluster scripts - Fix label on nfs-utils scripts directories - Fixes for cluster - Allow gatherd to read /dev/rand and /dev/urand - abrt leaks fifo files- Add glance policy - Allow mdadm setsched - /var/run/initramfs should not be relabeled with a restorecon run - memcache can be setup to override sys_resource - Allow httpd_t to read tetex data - Allow systemd_tmpfiles to delete kernel modules left in /tmp directory.- Allow Postfix to deliver to Dovecot LMTP socket - Ignore bogus sys_module for lldpad - Allow chrony and gpsd to send dgrams, gpsd needs to write to the real time clock - systemd_logind_t sets the attributes on usb devices - Allow hddtemp_t to read etc_t files - Add permissivedomains module - Move all permissive domains calls to permissivedomain.te - Allow pegasis to send kill signals to other UIDs- Allow insmod_t to use fds leaked from devicekit - dontaudit getattr between insmod_t and init_t unix_stream_sockets - Change sysctl unit file interfaces to use systemctl - Add support for chronyd unit file - Allow mozilla_plugin to read gnome_usr_config - Add policy for new gpsd - Allow cups to create kerberos rhost cache files - Add authlogin_filetrans_named_content, to unconfined_t to make sure shadow and other log files get labeled correctly- Make users_extra and seusers.final into config(noreplace) so semanage users and login does not get overwritten- Add policy for sa-update being run out of cron jobs - Add create perms to postgresql_manage_db - ntpd using a gps has to be able to read/write generic tty_device_t - If you disable unconfined and unconfineduser, rpm needs more privs to manage /dev - fix spec file - Remove qemu_domtrans_unconfined() interface - Make passenger working together with puppet - Add init_dontaudit_rw_stream_socket interface - Fixes for wordpress- Turn on allow_domain_fd_use boolean on F16 - Allow syslog to manage all log files - Add use_fusefs_home_dirs boolean for chrome - Make vdagent working with confined users - Add abrt_handle_event_t domain for ABRT event scripts - Labeled /usr/sbin/rhnreg_ks as rpm_exec_t and added changes related to this change - Allow httpd_git_script_t to read passwd data - Allow openvpn to set its process priority when the nice parameter is used- livecd fixes - spec file fixes- fetchmail can use kerberos - ksmtuned reads in shell programs - gnome_systemctl_t reads the process state of ntp - dnsmasq_t asks the kernel to load multiple kernel modules - Add rules for domains executing systemctl - Bogus text within fc file- Add cfengine policy- Add abrt_domain attribute - Allow corosync to manage cluster lib files - Allow corosync to connect to the system DBUS- Add sblim, uuidd policies - Allow kernel_t dyntrasition to init_t- init_t need setexec - More fixes of rules which cause an explosion in rules by Dan Walsh- Allow rcsmcertd to perform DNS name resolution - Add dirsrvadmin_unconfined_script_t domain type for 389-ds admin scripts - Allow tmux to run as screen - New policy for collectd - Allow gkeyring_t to interact with all user apps - Add rules to allow firstboot to run on machines with the unconfined.pp module removed- Allow systemd_logind to send dbus messages with users - allow accountsd to read wtmp file - Allow dhcpd to get and set capabilities- Fix oracledb_port definition - Allow mount to mounton the selinux file system - Allow users to list /var directories- systemd fixes- Add initial policy for abrt_dump_oops_t - xtables-multi wants to getattr of the proc fs - Smoltclient is connecting to abrt - Dontaudit leaked file descriptors to postdrop - Allow abrt_dump_oops to look at kernel sysctls - Abrt_dump_oops_t reads kernel ring buffer - Allow mysqld to request the kernel to load modules - systemd-login needs fowner - Allow postfix_cleanup_t to searh maildrop- Initial systemd_logind policy - Add policy for systemd_logger and additional proivs for systemd_logind - More fixes for systemd policies- Allow setsched for virsh - Systemd needs to impersonate cups, which means it needs to create tcp_sockets in cups_t domain, as well as manage spool directories - iptables: the various /sbin/ip6?tables.* are now symlinks for /sbin/xtables-multi- A lot of users are running yum -y update while in /root which is causing ldconfig to list the contents, adding dontaudit - Allow colord to interact with the users through the tmpfs file system - Since we changed the label on deferred, we need to allow postfix_qmgr_t to be able to create maildrop_t files - Add label for /var/log/mcelog - Allow asterisk to read /dev/random if it uses TLS - Allow colord to read ini files which are labeled as bin_t - Allow dirsrvadmin sys_resource and setrlimit to use ulimit - Systemd needs to be able to create sock_files for every label in /var/run directory, cupsd being the first. - Also lists /var and /var/spool directories - Add openl2tpd to l2tpd policy - qpidd is reading the sysfs file- Change usbmuxd_t to dontaudit attempts to read chr_file - Add mysld_safe_exec_t for libra domains to be able to start private mysql domains - Allow pppd to search /var/lock dir - Add rhsmcertd policy- Update to upstream- More fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git- Fix spec file to not report Verify errors- Add dspam policy - Add lldpad policy - dovecot auth wants to search statfs #713555 - Allow systemd passwd apps to read init fifo_file - Allow prelink to use inherited terminals - Run cherokee in the httpd_t domain - Allow mcs constraints on node connections - Implement pyicqt policy - Fixes for zarafa policy - Allow cobblerd to send syslog messages- Add policy.26 to the payload - Remove olpc stuff - Remove policygentool- Fixes for zabbix - init script needs to be able to manage sanlock_var_run_... - Allow sandlock and wdmd to create /var/run directories... - mixclip.so has been compiled correctly - Fix passenger policy module name- Add mailscanner policy from dgrift - Allow chrome to optionally be transitioned to - Zabbix needs these rules when starting the zabbix_server_mysql - Implement a type for freedesktop openicc standard (~/.local/share/icc) - Allow system_dbusd_t to read inherited icc_data_home_t files. - Allow colord_t to read icc_data_home_t content. #706975 - Label stuff under /usr/lib/debug as if it was labeled under /- Fixes for sanlock policy - Fixes for colord policy - Other fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Add rhev policy module to modules-targeted.conf- Lot of fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Allow logrotate to execute systemctl - Allow nsplugin_t to getattr on gpmctl - Fix dev_getattr_all_chr_files() interface - Allow shorewall to use inherited terms - Allow userhelper to getattr all chr_file devices - sandbox domains should be able to getattr and dontaudit search of sysctl_kernel_t - Fix labeling for ABRT Retrace Server- Dontaudit sys_module for ifconfig - Make telepathy and gkeyringd daemon working with confined users - colord wants to read files in users homedir - Remote login should be creating user_tmp_t not its own tmp files- Fix label for /usr/share/munin/plugins/munin_* plugins - Add support for zarafa-indexer - Fix boolean description - Allow colord to getattr on /proc/scsi/scsi - Add label for /lib/upstart/init - Colord needs to list /mnt- Forard port changes from F15 for telepathy - NetworkManager should be allowed to use /dev/rfkill - Fix dontaudit messages to say Domain to not audit - Allow telepathy domains to read/write gnome_cache files - Allow telepathy domains to call getpw - Fixes for colord and vnstatd policy- Allow init_t getcap and setcap - Allow namespace_init_t to use nsswitch - aisexec will execute corosync - colord tries to read files off noxattr file systems - Allow init_t getcap and setcap- Add support for ABRT retrace server - Allow user_t and staff_t access to generic scsi to handle locally plugged in scanners - Allow telepath_msn_t to read /proc/PARENT/cmdline - ftpd needs kill capability - Allow telepath_msn_t to connect to sip port - keyring daemon does not work on nfs homedirs - Allow $1_sudo_t to read default SELinux context - Add label for tgtd sock file in /var/run/ - Add apache_exec_rotatelogs interface - allow all zaraha domains to signal themselves, server writes to /tmp - Allow syslog to read the process state - Add label for /usr/lib/chromium-browser/chrome - Remove the telepathy transition from unconfined_t - Dontaudit sandbox domains trying to mounton sandbox_file_t, this is caused by fuse mounts - Allow initrc_t domain to manage abrt pid files - Add support for AEOLUS project - Virt_admin should be allowed to manage images and processes - Allow plymountd to send signals to init - Change labeling of fping6- Add filename transitions- Fixes for zarafa policy - Add support for AEOLUS project - Change labeling of fping6 - Allow plymountd to send signals to init - Allow initrc_t domain to manage abrt pid files - Virt_admin should be allowed to manage images and processes- xdm_t needs getsession for switch user - Every app that used to exec init is now execing systemdctl - Allow squid to manage krb5_host_rcache_t files - Allow foghorn to connect to agentx port - Fixes for colord policy- Add Dan's patch to remove 64 bit variants - Allow colord to use unix_dgram_socket - Allow apps that search pids to read /var/run if it is a lnk_file - iscsid_t creates its own directory - Allow init to list var_lock_t dir - apm needs to verify user accounts auth_use_nsswitch - Add labeling for systemd unit files - Allow gnomeclok to enable ntpd service using systemctl - systemd_systemctl_t domain was added - Add label for matahari-broker.pid file - We want to remove untrustedmcsprocess from ability to read /proc/pid - Fixes for matahari policy - Allow system_tmpfiles_t to delete user_home_t files in the /tmp dir - Allow sshd to transition to sysadm_t if ssh_sysadm_login is turned on- Fix typo- Add /var/run/lock /var/lock definition to file_contexts.subs - nslcd_t is looking for kerberos cc files - SSH_USE_STRONG_RNG is 1 which requires /dev/random - Fix auth_rw_faillog definition - Allow sysadm_t to set attributes on fixed disks - allow user domains to execute lsof and look at application sockets - prelink_cron job calls telinit -u if init is rewritten - Fixes to run qemu_t from staff_t- Fix label for /var/run/udev to udev_var_run_t - Mock needs to be able to read network state- Add file_contexts.subs to handle /run and /run/lock - Add other fixes relating to /run changes from F15 policy- Allow $1_sudo_t and $1_su_t open access to user terminals - Allow initrc_t to use generic terminals - Make Makefile/Rules.modular run sepolgen-ifgen during build to check if files for bugs -systemd is going to be useing /run and /run/lock for early bootup files. - Fix some comments in rlogin.if - Add policy for KDE backlighthelper - sssd needs to read ~/.k5login in nfs, cifs or fusefs file systems - sssd wants to read .k5login file in users homedir - setroubleshoot reads executables to see if they have TEXTREL - Add /var/spool/audit support for new version of audit - Remove kerberos_connect_524() interface calling - Combine kerberos_master_port_t and kerberos_port_t - systemd has setup /dev/kmsg as stderr for apps it executes - Need these access so that init can impersonate sockets on unix_dgram_socket- Remove some unconfined domains - Remove permissive domains - Add policy-term.patch from Dan- Fix multiple specification for boot.log - devicekit leaks file descriptors to setfiles_t - Change all all_nodes to generic_node and all_if to generic_if - Should not use deprecated interface - Switch from using all_nodes to generic_node and from all_if to generic_if - Add support for xfce4-notifyd - Fix file context to show several labels as SystemHigh - seunshare needs to be able to mounton nfs/cifs/fusefs homedirs - Add etc_runtime_t label for /etc/securetty - Fixes to allow xdm_t to start gkeyringd_USERTYPE_t directly - login.krb needs to be able to write user_tmp_t - dirsrv needs to bind to port 7390 for dogtag - Fix a bug in gpg policy - gpg sends audit messages - Allow qpid to manage matahari files- Initial policy for matahari - Add dev_read_watchdog - Allow clamd to connect clamd port - Add support for kcmdatetimehelper - Allow shutdown to setrlimit and sys_nice - Allow systemd_passwd to talk to /dev/log before udev or syslog is running - Purge chr_file and blk files on /tmp - Fixes for pads - Fixes for piranha-pulse - gpg_t needs to be able to encyprt anything owned by the user- mozilla_plugin_tmp_t needs to be treated as user tmp files - More dontaudits of writes from readahead - Dontaudit readahead_t file_type:dir write, to cover up kernel bug - systemd_tmpfiles needs to relabel faillog directory as well as the file - Allow hostname and consoletype to r/w inherited initrc_tmp_t files handline hostname >> /tmp/myhost- Add policykit fixes from Tim Waugh - dontaudit sandbox domains sandbox_file_t:dir mounton - Add new dontaudit rules for sysadm_dbusd_t - Change label for /var/run/faillock * other fixes which relate with this change- Update to upstream - Fixes for telepathy - Add port defition for ssdp port - add policy for /bin/systemd-notify from Dan - Mount command requires users read mount_var_run_t - colord needs to read konject_uevent_socket - User domains connect to the gkeyring socket - Add colord policy and allow user_t and staff_t to dbus chat with it - Add lvm_exec_t label for kpartx - Dontaudit reading the mail_spool_t link from sandbox -X - systemd is creating sockets in avahi_var_run and system_dbusd_var_run- gpg_t needs to talk to gnome-keyring - nscd wants to read /usr/tmp->/var/tmp to generate randomziation in unixchkpwd - enforce MCS labeling on nodes - Allow arpwatch to read meminfo - Allow gnomeclock to send itself signals - init relabels /dev/.udev files on boot - gkeyringd has to transition back to staff_t when it runs commands in bin_t or shell_exec_t - nautilus checks access on /media directory before mounting usb sticks, dontaudit access_check on mnt_t - dnsmasq can run as a dbus service, needs acquire service - mysql_admin should be allowed to connect to mysql service - virt creates monitor sockets in the users home dir- Allow usbhid-ups to read hardware state information - systemd-tmpfiles has moved - Allo cgroup to sys_tty_config - For some reason prelink is attempting to read gconf settings - Add allow_daemons_use_tcp_wrapper boolean - Add label for ~/.cache/wocky to make telepathy work in enforcing mode - Add label for char devices /dev/dasd* - Fix for apache_role - Allow amavis to talk to nslcd - allow all sandbox to read selinux poilcy config files - Allow cluster domains to use the system bus and send each other dbus messages- Update to upstream- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Update to ref policy - cgred needs chown capability - Add /dev/crash crash_dev_t - systemd-readahead wants to use fanotify which means readahead_t needs sys_admin capability- New labeling for postfmulti #675654 - dontaudit xdm_t listing noxattr file systems - dovecot-auth needs to be able to connect to mysqld via the network as well as locally - shutdown is passed stdout to a xdm_log_t file - smartd creates a fixed disk device - dovecot_etc_t contains a lnk_file that domains need to read - mount needs to be able to read etc_runtim_t:lnk_file since in rawhide this is a link created at boot- syslog_t needs syslog capability - dirsrv needs to be able to create /var/lib/snmp - Fix labeling for dirsrv - Fix for dirsrv policy missing manage_dirs_pattern - corosync needs to delete clvm_tmpfs_t files - qdiskd needs to list hugetlbfs - Move setsched to sandbox_x_domain, so firefox can run without network access - Allow hddtemp to read removable devices - Adding syslog and read_policy permissions to policy * syslog Allow unconfined, sysadm_t, secadm_t, logadm_t * read_policy allow unconfined, sysadm_t, secadm_t, staff_t on Targeted allow sysadm_t (optionally), secadm_t on MLS - mdadm application will write into /sys/.../uevent whenever arrays are assembled or disassembled.- Add tcsd policy- ricci_modclusterd_t needs to bind to rpc ports 500-1023 - Allow dbus to use setrlimit to increase resoueces - Mozilla_plugin is leaking to sandbox - Allow confined users to connect to lircd over unix domain stream socket which allow to use remote control - Allow awstats to read squid logs - seunshare needs to manage tmp_t - apcupsd cgi scripts have a new directory- Fix xserver_dontaudit_read_xdm_pid - Change oracle_port_t to oracledb_port_t to prevent conflict with satellite - Allow dovecot_deliver_t to read/write postfix_master_t:fifo_file. * These fifo_file is passed from postfix_master_t to postfix_local_t to dovecot_deliver_t - Allow readahead to manage readahead pid dirs - Allow readahead to read all mcs levels - Allow mozilla_plugin_t to use nfs or samba homedirs- Allow nagios plugin to read /proc/meminfo - Fix for mozilla_plugin - Allow samba_net_t to create /etc/keytab - pppd_t setting up vpns needs to run unix_chkpwd, setsched its process and write wtmp_t - nslcd can read user credentials - Allow nsplugin to delete mozilla_plugin_tmpfs_t - abrt tries to create dir in rpm_var_lib_t - virt relabels fifo_files - sshd needs to manage content in fusefs homedir - mock manages link files in cache dir- nslcd needs setsched and to read /usr/tmp - Invalid call in likewise policy ends up creating a bogus role - Cannon puts content into /var/lib/bjlib that cups needs to be able to write - Allow screen to create screen_home_t in /root - dirsrv sends syslog messages - pinentry reads stuff in .kde directory - Add labels for .kde directory in homedir - Treat irpinit, iprupdate, iprdump services with raid policy- NetworkManager wants to read consolekit_var_run_t - Allow readahead to create /dev/.systemd/readahead - Remove permissive domains - Allow newrole to run namespace_init- Add sepgsql_contexts file- Update to upstream- Add oracle ports and allow apache to connect to them if the connect_db boolean is turned on - Add puppetmaster_use_db boolean - Fixes for zarafa policy - Fixes for gnomeclock poliy - Fix systemd-tmpfiles to use auth_use_nsswitch- gnomeclock executes a shell - Update for screen policy to handle pipe in homedir - Fixes for polyinstatiated homedir - Fixes for namespace policy and other fixes related to polyinstantiation - Add namespace policy - Allow dovecot-deliver transition to sendmail which is needed by sieve scripts - Fixes for init, psad policy which relate with confined users - Do not audit bootloader attempts to read devicekit pid files - Allow nagios service plugins to read /proc- Add firewalld policy - Allow vmware_host to read samba config - Kernel wants to read /proc Fix duplicate grub def in cobbler - Chrony sends mail, executes shell, uses fifo_file and reads /proc - devicekitdisk getattr all file systems - sambd daemon writes wtmp file - libvirt transitions to dmidecode- Add initial policy for system-setup-keyboard which is now daemon - Label /var/lock/subsys/shorewall as shorewall_lock_t - Allow users to communicate with the gpg_agent_t - Dontaudit mozilla_plugin_t using the inherited terminal - Allow sambagui to read files in /usr - webalizer manages squid log files - Allow unconfined domains to bind ports to raw_ip_sockets - Allow abrt to manage rpm logs when running yum - Need labels for /var/run/bittlebee - Label .ssh under amanda - Remove unused genrequires for virt_domain_template - Allow virt_domain to use fd inherited from virtd_t - Allow iptables to read shorewall config- Gnome apps list config_home_t - mpd creates lnk files in homedir - apache leaks write to mail apps on tmp files - /var/stockmaniac/templates_cache contains log files - Abrt list the connects of mount_tmp_t dirs - passwd agent reads files under /dev and reads utmp file - squid apache script connects to the squid port - fix name of plymouth log file - teamviewer is a wine app - allow dmesg to read system state - Stop labeling files under /var/lib/mock so restorecon will not go into this - nsplugin needs to read network state for google talk- Allow xdm and syslog to use /var/log/boot.log - Allow users to communicate with mozilla_plugin and kill it - Add labeling for ipv6 and dhcp- New labels for ghc http content - nsplugin_config needs to read urand, lvm now calls setfscreate to create dev - pm-suspend now creates log file for append access so we remove devicekit_wri - Change authlogin_use_sssd to authlogin_nsswitch_use_ldap - Fixes for greylist_milter policy- Update to upstream - Fixes for systemd policy - Fixes for passenger policy - Allow staff users to run mysqld in the staff_t domain, akonadi needs this - Add bin_t label for /usr/share/kde4/apps/kajongg/kajongg.py - auth_use_nsswitch does not need avahi to read passwords,needed for resolving data - Dontaudit (xdm_t) gok attempting to list contents of /var/account - Telepathy domains need to read urand - Need interface to getattr all file classes in a mock library for setroubleshoot- Update selinux policy to handle new /usr/share/sandbox/start script- Update to upstream - Fix version of policy in spec file- Allow sandbox to run on nfs partitions, fixes for systemd_tmpfs - remove per sandbox domains devpts types - Allow dkim-milter sending signal to itself- Allow domains that transition to ping or traceroute, kill them - Allow user_t to conditionally transition to ping_t and traceroute_t - Add fixes to systemd- tools, including new labeling for systemd-fsck, systemd-cryptsetup- Turn on systemd policy - mozilla_plugin needs to read certs in the homedir. - Dontaudit leaked file descriptors from devicekit - Fix ircssi to use auth_use_nsswitch - Change to use interface without param in corenet to disable unlabelednet packets - Allow init to relabel sockets and fifo files in /dev - certmonger needs dac* capabilities to manage cert files not owned by root - dovecot needs fsetid to change group membership on mail - plymouthd removes /var/log/boot.log - systemd is creating symlinks in /dev - Change label on /etc/httpd/alias to be all cert_t- Fixes for clamscan and boinc policy - Add boinc_project_t setpgid - Allow alsa to create tmp files in /tmp- Push fixes to allow disabling of unlabeled_t packet access - Enable unlabelednet policy- Fixes for lvm to work with systemd- Fix the label for wicd log - plymouthd creates force-display-on-active-vt file - Allow avahi to request the kernel to load a module - Dontaudit hal leaks - Fix gnome_manage_data interface - Add new interface corenet_packet to define a type as being an packet_type. - Removed general access to packet_type from icecast and squid. - Allow mpd to read alsa config - Fix the label for wicd log - Add systemd policy- Fix gnome_manage_data interface - Dontaudit sys_ptrace capability for iscsid - Fixes for nagios plugin policy- Fix cron to run ranged when started by init - Fix devicekit to use log files - Dontaudit use of devicekit_var_run_t for fstools - Allow init to setattr on logfile directories - Allow hald to manage files in /var/run/pm-utils/ dir which is now labeled as devicekit_var_run_t- Fix up handling of dnsmasq_t creating /var/run/libvirt/network - Turn on sshd_forward_ports boolean by default - Allow sysadmin to dbus chat with rpm - Add interface for rw_tpm_dev - Allow cron to execute bin - fsadm needs to write sysfs - Dontaudit consoletype reading /var/run/pm-utils - Lots of new privs fro mozilla_plugin_t running java app, make mozilla_plugin - certmonger needs to manage dirsrv data - /var/run/pm-utils should be labeled as devicekit_var_run_t- fixes to allow /var/run and /var/lock as tmpfs - Allow chrome sandbox to connect to web ports - Allow dovecot to listem on lmtp and sieve ports - Allov ddclient to search sysctl_net_t - Transition back to original domain if you execute the shell- Remove duplicate declaration- Update to upstream - Cleanup for sandbox - Add attribute to be able to select sandbox types- Allow ddclient to fix file mode bits of ddclient conf file - init leaks file descriptors to daemons - Add labels for /etc/lirc/ and - Allow amavis_t to exec shell - Add label for gssd_tmp_t for /var/tmp/nfs_0- Put back in lircd_etc_t so policy will install- Turn on allow_postfix_local_write_mail_spool - Allow initrc_t to transition to shutdown_t - Allow logwatch and cron to mls_read_to_clearance for MLS boxes - Allow wm to send signull to all applications and receive them from users - lircd patch from field - Login programs have to read /etc/samba - New programs under /lib/systemd - Abrt needs to read config files- Update to upstream - Dontaudit leaked sockets from userdomains to user domains - Fixes for mcelog to handle scripts - Apply patch from Ruben Kerkhof - Allow syslog to search spool dirs- Allow nagios plugins to read usr files - Allow mysqld-safe to send system log messages - Fixes fpr ddclient policy - Fix sasl_admin interface - Allow apache to search zarafa config - Allow munin plugins to search /var/lib directory - Allow gpsd to read sysfs_t - Fix labels on /etc/mcelog/triggers to bin_t- Remove saslauthd_tmp_t and transition tmp files to krb5_host_rcache_t - Allow saslauthd_t to create krb5_host_rcache_t files in /tmp - Fix xserver interface - Fix definition of /var/run/lxdm- Turn on mediawiki policy - kdump leaks kdump_etc_t to ifconfig, add dontaudit - uux needs to transition to uucpd_t - More init fixes relabels man,faillog - Remove maxima defs in libraries.fc - insmod needs to be able to create tmpfs_t files - ping needs setcap- Allow groupd transition to fenced domain when executes fence_node - Fixes for rchs policy - Allow mpd to be able to read samba/nfs files- Fix up corecommands.fc to match upstream - Make sure /lib/systemd/* is labeled init_exec_t - mount wants to setattr on all mountpoints - dovecot auth wants to read dovecot etc files - nscd daemon looks at the exe file of the comunicating daemon - openvpn wants to read utmp file - postfix apps now set sys_nice and lower limits - remote_login (telnetd/login) wants to use telnetd_devpts_t and user_devpts_t to work correctly - Also resolves nsswitch - Fix labels on /etc/hosts.* - Cleanup to make upsteam patch work - allow abrt to read etc_runtime_t- Add conflicts for dirsrv package- Update to upstream - Add vlock policy- Fix sandbox to work on nfs homedirs - Allow cdrecord to setrlimit - Allow mozilla_plugin to read xauth - Change label on systemd-logger to syslogd_exec_t - Install dirsrv policy from dirsrv package- Add virt_home_t, allow init to setattr on xserver_tmp_t and relabel it - Udev needs to stream connect to init and kernel - Add xdm_exec_bootloader boolean, which allows xdm to execute /sbin/grub and read files in /boot directory- Allow NetworkManager to read openvpn_etc_t - Dontaudit hplip to write of /usr dirs - Allow system_mail_t to create /root/dead.letter as mail_home_t - Add vdagent policy for spice agent daemon- Dontaudit sandbox sending sigkill to all user domains - Add policy for rssh_chroot_helper - Add missing flask definitions - Allow udev to relabelto removable_t - Fix label on /var/log/wicd.log - Transition to initrc_t from init when executing bin_t - Add audit_access permissions to file - Make removable_t a device_node - Fix label on /lib/systemd/*- Fixes for systemd to manage /var/run - Dontaudit leaks by firstboot- Allow chome to create netlink_route_socket - Add additional MATHLAB file context - Define nsplugin as an application_domain - Dontaudit sending signals from sandboxed domains to other domains - systemd requires init to build /tmp /var/auth and /var/lock dirs - mount wants to read devicekit_power /proc/ entries - mpd wants to connect to soundd port - Openoffice causes a setattr on a lib_t file for normal users, add dontaudit - Treat lib_t and textrel_shlib_t directories the same - Allow mount read access on virtual images- Allow sandbox_x_domains to work with nfs/cifs/fusefs home dirs. - Allow devicekit_power to domtrans to mount - Allow dhcp to bind to udp ports > 1024 to do named stuff - Allow ssh_t to exec ssh_exec_t - Remove telepathy_butterfly_rw_tmp_files(), dev_read_printk() interfaces which are nolonger used - Fix clamav_append_log() intefaces - Fix 'psad_rw_fifo_file' interface- Allow cobblerd to list cobler appache content- Fixup for the latest version of upowed - Dontaudit sandbox sending SIGNULL to desktop apps- Update to upstream-Mount command from a confined user generates setattr on /etc/mtab file, need to dontaudit this access - dovecot-auth_t needs ipc_lock - gpm needs to use the user terminal - Allow system_mail_t to append ~/dead.letter - Allow NetworkManager to edit /etc/NetworkManager/NetworkManager.conf - Add pid file to vnstatd - Allow mount to communicate with gfs_controld - Dontaudit hal leaks in setfiles- Lots of fixes for systemd - systemd now executes readahead and tmpwatch type scripts - Needs to manage random seed- Allow smbd to use sys_admin - Remove duplicate file context for tcfmgr - Update to upstream- Fix fusefs handling - Do not allow sandbox to manage nsplugin_rw_t - Allow mozilla_plugin_t to connecto its parent - Allow init_t to connect to plymouthd running as kernel_t - Add mediawiki policy - dontaudit sandbox sending signals to itself. This can happen when they are running at different mcs. - Disable transition from dbus_session_domain to telepathy for F14 - Allow boinc_project to use shm - Allow certmonger to search through directories that contain certs - Allow fail2ban the DAC Override so it can read log files owned by non root users- Start adding support for use_fusefs_home_dirs - Add /var/lib/syslog directory file context - Add /etc/localtime as locale file context- Turn off default transition to mozilla_plugin and telepathy domains from unconfined user - Turn off iptables from unconfined user - Allow sudo to send signals to any domains the user could have transitioned to. - Passwd in single user mode needs to talk to console_device_t - Mozilla_plugin_t needs to connect to web ports, needs to write to video device, and read alsa_home_t alsa setsup pulseaudio - locate tried to read a symbolic link, will dontaudit - New labels for telepathy-sunshine content in homedir - Google is storing other binaries under /opt/google/talkplugin - bluetooth/kernel is creating unlabeled_t socket that I will allow it to use until kernel fixes bug - Add boolean for unconfined_t transition to mozilla_plugin_t and telepathy domains, turned off in F14 on in F15 - modemmanger and bluetooth send dbus messages to devicekit_power - Samba needs to getquota on filesystems labeld samba_share_t- Dontaudit attempts by xdm_t to write to bin_t for kdm - Allow initrc_t to manage system_conf_t- Fixes to allow mozilla_plugin_t to create nsplugin_home_t directory. - Allow mozilla_plugin_t to create tcp/udp/netlink_route sockets - Allow confined users to read xdm_etc_t files - Allow xdm_t to transition to xauth_t for lxdm program- Rearrange firewallgui policy to be more easily updated to upstream, dontaudit search of /home - Allow clamd to send signals to itself - Allow mozilla_plugin_t to read user home content. And unlink pulseaudio shm. - Allow haze to connect to yahoo chat and messenger port tcp:5050. Bz #637339 - Allow guest to run ps command on its processes by allowing it to read /proc - Allow firewallgui to sys_rawio which seems to be required to setup masqerading - Allow all domains to search through default_t directories, in order to find differnet labels. For example people serring up /foo/bar to be share via samba. - Add label for /var/log/slim.log- Pull in cleanups from dgrift - Allow mozilla_plugin_t to execute mozilla_home_t - Allow rpc.quota to do quotamod- Cleanup policy via dgrift - Allow dovecot_deliver to append to inherited log files - Lots of fixes for consolehelper- Fix up Xguest policy- Add vnstat policy - allow libvirt to send audit messages - Allow chrome-sandbox to search nfs_t- Update to upstream- Add the ability to send audit messages to confined admin policies - Remove permissive domain from cmirrord and dontaudit sys_tty_config - Split out unconfined_domain() calls from other unconfined_ calls so we can d - virt needs to be able to read processes to clearance for MLS- Allow all domains that can use cgroups to search tmpfs_t directory - Allow init to send audit messages- Update to upstream- Allow mdadm_t to create files and sock files in /dev/md/- Add policy for ajaxterm- Handle /var/db/sudo - Allow pulseaudio to read alsa config - Allow init to send initrc_t dbus messagesAllow iptables to read shorewall tmp files Change chfn and passwd to use auth_use_pam so they can send dbus messages to fpr intd label vlc as an execmem_exec_t Lots of fixes for mozilla_plugin to run google vidio chat Allow telepath_msn to execute ldconfig and its own tmp files Fix labels on hugepages Allow mdadm to read files on /dev Remove permissive domains and change back to unconfined Allow freshclam to execute shell and bin_t Allow devicekit_power to transition to dhcpc Add boolean to allow icecast to connect to any port- Merge upstream fix of mmap_zero - Allow mount to write files in debugfs_t - Allow corosync to communicate with clvmd via tmpfs - Allow certmaster to read usr_t files - Allow dbus system services to search cgroup_t - Define rlogind_t as a login pgm- Allow mdadm_t to read/write hugetlbfs- Dominic Grift Cleanup - Miroslav Grepl policy for jabberd - Various fixes for mount/livecd and prelink- Merge with upstream- More access needed for devicekit - Add dbadm policy- Merge with upstream- Allow seunshare to fowner- Allow cron to look at user_cron_spool links - Lots of fixes for mozilla_plugin_t - Add sysv file system - Turn unconfined domains to permissive to find additional avcs- Update policy for mozilla_plugin_t- Allow clamscan to read proc_t - Allow mount_t to write to debufs_t dir - Dontaudit mount_t trying to write to security_t dir- Allow clamscan_t execmem if clamd_use_jit set - Add policy for firefox plugin-container- Fix /root/.forward definition- label dead.letter as mail_home_t- Allow login programs to search /cgroups- Fix cert handling- Fix devicekit_power bug - Allow policykit_auth_t more access.- Fix nis calls to allow bind to ports 512-1024 - Fix smartmon- Allow pcscd to read sysfs - systemd fixes - Fix wine_mmap_zero_ignore boolean- Apply Miroslav munin patch - Turn back on allow_execmem and allow_execmod booleans- Merge in fixes from dgrift repository- Update boinc policy - Fix sysstat policy to allow sys_admin - Change failsafe_context to unconfined_r:unconfined_t:s0- New paths for upstart- New permissions for syslog - New labels for /lib/upstart- Add mojomojo policy- Allow systemd to setsockcon on sockets to immitate other services- Remove debugfs label- Update to latest policy- Fix eclipse labeling from IBMSupportAssasstant packageing- Make boot with systemd in enforcing mode- Update to upstream- Add boolean to turn off port forwarding in sshd.- Add support for ebtables - Fixes for rhcs and corosync policy-Update to upstream-Update to upstream-Update to upstream- Add Zarafa policy- Cleanup of aiccu policy - initial mock policy- Lots of random fixes- Update to upstream- Update to upstream - Allow prelink script to signal itself - Cobbler fixes- Add xdm_var_run_t to xserver_stream_connect_xdm - Add cmorrord and mpd policy from Miroslav Grepl- Fix sshd creation of krb cc files for users to be user_tmp_t- Fixes for accountsdialog - Fixes for boinc- Fix label on /var/lib/dokwiki - Change permissive domains to enforcing - Fix libvirt policy to allow it to run on mls- Update to upstream- Allow procmail to execute scripts in the users home dir that are labeled home_bin_t - Fix /var/run/abrtd.lock label- Allow login programs to read krb5_home_t Resolves: 594833 - Add obsoletes for cachefilesfd-selinux package Resolves: #575084- Allow mount to r/w abrt fifo file - Allow svirt_t to getattr on hugetlbfs - Allow abrt to create a directory under /var/spool- Add labels for /sys - Allow sshd to getattr on shutdown - Fixes for munin - Allow sssd to use the kernel key ring - Allow tor to send syslog messages - Allow iptabels to read usr files - allow policykit to read all domains state- Fix path for /var/spool/abrt - Allow nfs_t as an entrypoint for http_sys_script_t - Add policy for piranha - Lots of fixes for sosreport- Allow xm_t to read network state and get and set capabilities - Allow policykit to getattr all processes - Allow denyhosts to connect to tcp port 9911 - Allow pyranha to use raw ip sockets and ptrace itself - Allow unconfined_execmem_t and gconfsd mechanism to dbus - Allow staff to kill ping process - Add additional MLS rules- Allow gdm to edit ~/.gconf dir Resolves: #590677 - Allow dovecot to create directories in /var/lib/dovecot Partially resolves 590224 - Allow avahi to dbus chat with NetworkManager - Fix cobbler labels - Dontaudit iceauth_t leaks - fix /var/lib/lxdm file context - Allow aiccu to use tun tap devices - Dontaudit shutdown using xserver.log- Fixes for sandbox_x_net_t to match access for sandbox_web_t ++ - Add xdm_etc_t for /etc/gdm directory, allow accountsd to manage this directory - Add dontaudit interface for bluetooth dbus - Add chronyd_read_keys, append_keys for initrc_t - Add log support for ksmtuned Resolves: #586663- Allow boinc to send mail- Allow initrc_t to remove dhcpc_state_t - Fix label on sa-update.cron - Allow dhcpc to restart chrony initrc - Don't allow sandbox to send signals to its parent processes - Fix transition from unconfined_t -> unconfined_mount_t -> rpcd_t Resolves: #589136- Fix location of oddjob_mkhomedir Resolves: #587385 - fix labeling on /root/.shosts and ~/.shosts - Allow ipsec_mgmt_t to manage net_conf_t Resolves: #586760- Dontaudit sandbox trying to connect to netlink sockets Resolves: #587609 - Add policy for piranha- Fixups for xguest policy - Fixes for running sandbox firefox- Allow ksmtuned to use terminals Resolves: #586663 - Allow lircd to write to generic usb devices- Allow sandbox_xserver to connectto unconfined stream Resolves: #585171- Allow initrc_t to read slapd_db_t Resolves: #585476 - Allow ipsec_mgmt to use unallocated devpts and to create /etc/resolv.conf Resolves: #585963- Allow rlogind_t to search /root for .rhosts Resolves: #582760 - Fix path for cached_var_t - Fix prelink paths /var/lib/prelink - Allow confined users to direct_dri - Allow mls lvm/cryptosetup to work- Allow virtd_t to manage firewall/iptables config Resolves: #573585- Fix label on /root/.rhosts Resolves: #582760 - Add labels for Picasa - Allow openvpn to read home certs - Allow plymouthd_t to use tty_device_t - Run ncftool as iptables_t - Allow mount to unmount unlabeled_t - Dontaudit hal leaks- Allow livecd to transition to mount- Update to upstream - Allow abrt to delete sosreport Resolves: #579998 - Allow snmp to setuid and gid Resolves: #582155 - Allow smartd to use generic scsi devices Resolves: #582145- Allow ipsec_t to create /etc/resolv.conf with the correct label - Fix reserved port destination - Allow autofs to transition to showmount - Stop crashing tuned- Add telepathysofiasip policy- Update to upstream - Fix label for /opt/google/chrome/chrome-sandbox - Allow modemmanager to dbus with policykit- Fix allow_httpd_mod_auth_pam to use auth_use_pam(httpd_t) - Allow accountsd to read shadow file - Allow apache to send audit messages when using pam - Allow asterisk to bind and connect to sip tcp ports - Fixes for dovecot 2.0 - Allow initrc_t to setattr on milter directories - Add procmail_home_t for .procmailrc file- Fixes for labels during install from livecd- Fix /cgroup file context - Fix broken afs use of unlabled_t - Allow getty to use the console for s390- Fix cgroup handling adding policy for /cgroup - Allow confined users to write to generic usb devices, if user_rw_noexattrfile boolean set- Merge patches from dgrift- Update upstream - Allow abrt to write to the /proc under any process- Fix ~/.fontconfig label - Add /root/.cert label - Allow reading of the fixed_file_disk_t:lnk_file if you can read file - Allow qemu_exec_t as an entrypoint to svirt_t- Update to upstream - Allow tmpreaper to delete sandbox sock files - Allow chrome-sandbox_t to use /dev/zero, and dontaudit getattr file systems - Fixes for gitosis - No transition on livecd to passwd or chfn - Fixes for denyhosts- Add label for /var/lib/upower - Allow logrotate to run sssd - dontaudit readahead on tmpfs blk files - Allow tmpreaper to setattr on sandbox files - Allow confined users to execute dos files - Allow sysadm_t to kill processes running within its clearance - Add accountsd policy - Fixes for corosync policy - Fixes from crontab policy - Allow svirt to manage svirt_image_t chr files - Fixes for qdisk policy - Fixes for sssd policy - Fixes for newrole policy- make libvirt work on an MLS platform- Add qpidd policy- Update to upstream- Allow boinc to read kernel sysctl - Fix snmp port definitions - Allow apache to read anon_inodefs- Allow shutdown dac_override- Add device_t as a file system - Fix sysfs association- Dontaudit ipsec_mgmt sys_ptrace - Allow at to mail its spool files - Allow nsplugin to search in .pulse directory- Update to upstream- Allow users to dbus chat with xdm - Allow users to r/w wireless_device_t - Dontaudit reading of process states by ipsec_mgmt- Fix openoffice from unconfined_t- Add shutdown policy so consolekit can shutdown system- Update to upstream- Update to upstream- Update to upstream - These are merges of my patches - Remove 389 labeling conflicts - Add MLS fixes found in RHEL6 testing - Allow pulseaudio to run as a service - Add label for mssql and allow apache to connect to this database port if boolean set - Dontaudit searches of debugfs mount point - Allow policykit_auth to send signals to itself - Allow modcluster to call getpwnam - Allow swat to signal winbind - Allow usbmux to run as a system role - Allow svirt to create and use devpts- Add MLS fixes found in RHEL6 testing - Allow domains to append to rpm_tmp_t - Add cachefilesfd policy - Dontaudit leaks when transitioning- Change allow_execstack and allow_execmem booleans to on - dontaudit acct using console - Add label for fping - Allow tmpreaper to delete sandbox_file_t - Fix wine dontaudit mmap_zero - Allow abrt to read var_t symlinks- Additional policy for rgmanager- Allow sshd to setattr on pseudo terms- Update to upstream- Allow policykit to send itself signals- Fix duplicate cobbler definition- Fix file context of /var/lib/avahi-autoipd- Merge with upstream- Allow sandbox to work with MLS- Make Chrome work with staff user- Add icecast policy - Cleanup spec file- Add mcelog policy- Lots of fixes found in F12- Fix rpm_dontaudit_leaks- Add getsched to hald_t - Add file context for Fedora/Redhat Directory Server- Allow abrt_helper to getattr on all filesystems - Add label for /opt/real/RealPlayer/plugins/oggfformat\.so- Add gstreamer_home_t for ~/.gstreamer- Update to upstream- Fix git- Turn on puppet policy - Update to dgrift git policy- Move users file to selection by spec file. - Allow vncserver to run as unconfined_u:unconfined_r:unconfined_t- Update to upstream- Remove most of the permissive domains from F12.- Add cobbler policy from dgrift- add usbmon device - Add allow rulse for devicekit_disk- Lots of fixes found in F12, fixes from Tom London- Cleanups from dgrift- Add back xserver_manage_home_fonts- Dontaudit sandbox trying to read nscd and sssd- Update to upstream- Rename udisks-daemon back to devicekit_disk_t policy- Fixes for abrt calls- Add tgtd policy- Update to upstream release- Add asterisk policy back in - Update to upstream release 2.20091117- Update to upstream release 2.20091117- Fixup nut policy- Update to upstream- Allow vpnc request the kernel to load modules- Fix minimum policy installs - Allow udev and rpcbind to request the kernel to load modules- Add plymouth policy - Allow local_login to sys_admin- Allow cupsd_config to read user tmp - Allow snmpd_t to signal itself - Allow sysstat_t to makedir in sysstat_log_t- Update rhcs policy- Allow users to exec restorecond- Allow sendmail to request kernel modules load- Fix all kernel_request_load_module domains- Fix all kernel_request_load_module domains- Remove allow_exec* booleans for confined users. Only available for unconfined_t- More fixes for sandbox_web_t- Allow sshd to create .ssh directory and content- Fix request_module line to module_request- Fix sandbox policy to allow it to run under firefox. - Dont audit leaks.- Fixes for sandbox- Update to upstream - Dontaudit nsplugin search /root - Dontaudit nsplugin sys_nice- Fix label on /usr/bin/notepad, /usr/sbin/vboxadd-service - Remove policycoreutils-python requirement except for minimum- Fix devicekit_disk_t to getattr on all domains sockets and fifo_files - Conflicts seedit (You can not use selinux-policy-targeted and seedit at the same time.)- Add wordpress/wp-content/uploads label - Fixes for sandbox when run from staff_t- Update to upstream - Fixes for devicekit_disk- More fixes- Lots of fixes for initrc and other unconfined domains- Allow xserver to use netlink_kobject_uevent_socket- Fixes for sandbox- Dontaudit setroubleshootfix looking at /root directory- Update to upsteam- Allow gssd to send signals to users - Fix duplicate label for apache content- Update to upstream- Remove polkit_auth on upgrades- Add back in unconfined.pp and unconfineduser.pp - Add Sandbox unshare- Fixes for cdrecord, mdadm, and others- Add capability setting to dhcpc and gpm- Allow cronjobs to read exim_spool_t- Add ABRT policy- Fix system-config-services policy- Allow libvirt to change user componant of virt_domain- Allow cupsd_config_t to be started by dbus - Add smoltclient policy- Add policycoreutils-python to pre install- Make all unconfined_domains permissive so we can see what AVC's happen- Add pt_chown policy- Add kdump policy for Miroslav Grepl - Turn off execstack boolean- Turn on execstack on a temporary basis (#512845)- Allow nsplugin to connecto the session bus - Allow samba_net to write to coolkey data- Allow devicekit_disk to list inotify- Allow svirt images to create sock_file in svirt_var_run_t- Allow exim to getattr on mountpoints - Fixes for pulseaudio- Allow svirt_t to stream_connect to virtd_t- Allod hald_dccm_t to create sock_files in /tmp- More fixes from upstream- Fix polkit label - Remove hidebrokensymptoms for nss_ldap fix - Add modemmanager policy - Lots of merges from upstream - Begin removing textrel_shlib_t labels, from fixed libraries- Update to upstream- Allow certmaster to override dac permissions- Update to upstream- Fix context for VirtualBox- Update to upstream- Allow clamscan read amavis spool files- Fixes for xguest- fix multiple directory ownership of mandirs- Update to upstream- Add rules for rtkit-daemon- Update to upstream - Fix nlscd_stream_connect- Add rtkit policy- Allow rpcd_t to stream connect to rpcbind- Allow kpropd to create tmp files- Fix last duplicate /var/log/rpmpkgs- Update to upstream * add sssd- Update to upstream * cleanup- Update to upstream - Additional mail ports - Add virt_use_usb boolean for svirt- Fix mcs rules to include chr_file and blk_file- Add label for udev-acl- Additional rules for consolekit/udev, privoxy and various other fixes- New version for upstream- Allow NetworkManager to read inotifyfs- Allow setroubleshoot to run mlocate- Update to upstream- Add fish as a shell - Allow fprintd to list usbfs_t - Allow consolekit to search mountpoints - Add proper labeling for shorewall- New log file for vmware - Allow xdm to setattr on user_tmp_t- Upgrade to upstream- Allow fprintd to access sys_ptrace - Add sandbox policy- Add varnishd policy- Fixes for kpropd- Allow brctl to r/w tun_tap_device_t- Add /usr/share/selinux/packages- Allow rpcd_t to send signals to kernel threads- Fix upgrade for F10 to F11- Add policy for /var/lib/fprint-Remove duplicate line- Allow svirt to manage pci and other sysfs device data- Fix package selection handling- Fix /sbin/ip6tables-save context - Allod udev to transition to mount - Fix loading of mls policy file- Add shorewall policy- Additional rules for fprintd and sssd- Allow nsplugin to unix_read unix_write sem for unconfined_java- Fix uml files to be owned by users- Fix Upgrade path to install unconfineduser.pp when unocnfined package is 3.0.0 or less- Allow confined users to manage virt_content_t, since this is home dir content - Allow all domains to read rpm_script_tmp_t which is what shell creates on redirection- Fix labeling on /var/lib/misc/prelink* - Allow xserver to rw_shm_perms with all x_clients - Allow prelink to execute files in the users home directory- Allow initrc_t to delete dev_null - Allow readahead to configure auditing - Fix milter policy - Add /var/lib/readahead- Update to latest milter code from Paul Howarth- Additional perms for readahead- Allow pulseaudio to acquire_svc on session bus - Fix readahead labeling- Allow sysadm_t to run rpm directly - libvirt needs fowner- Allow sshd to read var_lib symlinks for freenx- Allow nsplugin unix_read and write on users shm and sem - Allow sysadm_t to execute su- Dontaudit attempts to getattr user_tmpfs_t by lvm - Allow nfs to share removable media- Add ability to run postdrop from confined users- Fixes for podsleuth- Turn off nsplugin transition - Remove Konsole leaked file descriptors for release- Allow cupsd_t to create link files in print_spool_t - Fix iscsi_stream_connect typo - Fix labeling on /etc/acpi/actions - Don't reinstall unconfine and unconfineuser on upgrade if they are not installed- Allow audioentroy to read etc files- Add fail2ban_var_lib_t - Fixes for devicekit_power_t- Separate out the ucnonfined user from the unconfined.pp package- Make sure unconfined_java_t and unconfined_mono_t create user_tmpfs_t.- Upgrade to latest upstream - Allow devicekit_disk sys_rawio- Dontaudit binds to ports < 1024 for named - Upgrade to latest upstream- Allow podsleuth to use tmpfs files- Add customizable_types for svirt- Allow setroubelshoot exec* privs to prevent crash from bad libraries - add cpufreqselector- Dontaudit listing of /root directory for cron system jobs- Fix missing ld.so.cache label- Add label for ~/.forward and /root/.forward- Fixes for svirt- Fixes to allow svirt read iso files in homedir- Add xenner and wine fixes from mgrepl- Allow mdadm to read/write mls override- Change to svirt to only access svirt_image_t- Fix libvirt policy- Upgrade to latest upstream- Fixes for iscsid and sssd - More cleanups for upgrade from F10 to Rawhide.- Add pulseaudio, sssd policy - Allow networkmanager to exec udevadm- Add pulseaudio context- Upgrade to latest patches- Fixes for libvirt- Update to Latest upstream- Fix setrans.conf to show SystemLow for s0- Further confinement of qemu images via svirt- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- Allow NetworkManager to manage /etc/NetworkManager/system-connections- add virtual_image_context and virtual_domain_context files- Allow rpcd_t to send signal to mount_t - Allow libvirtd to run ranged- Fix sysnet/net_conf_t- Fix squidGuard labeling- Re-add corenet_in_generic_if(unlabeled_t)* Tue Feb 10 2009 Dan Walsh 3.6.5-2 - Add git web policy- Add setrans contains from upstream- Do transitions outside of the booleans- Allow xdm to create user_tmp_t sockets for switch user to work- Fix staff_t domain- Grab remainder of network_peer_controls patch- More fixes for devicekit- Upgrade to latest upstream- Add boolean to disallow unconfined_t login- Add back transition from xguest to mozilla- Add virt_content_ro_t and labeling for isos directory- Fixes for wicd daemon- More mls/rpm fixes- Add policy to make dbus/nm-applet work- Remove polgen-ifgen from post and add trigger to policycoreutils-python- Add wm policy - Make mls work in graphics mode- Fixed for DeviceKit- Add devicekit policy- Update to upstream- Define openoffice as an x_domain- Fixes for reading xserver_tmp_t- Allow cups_pdf_t write to nfs_t- Remove audio_entropy policy- Update to upstream- Allow hal_acl_t to getattr/setattr fixed_disk- Change userdom_read_all_users_state to include reading symbolic links in /proc- Fix dbus reading /proc information- Add missing alias for home directory content- Fixes for IBM java location- Allow unconfined_r unconfined_java_t- Add cron_role back to user domains- Fix sudo setting of user keys- Allow iptables to talk to terminals - Fixes for policy kit - lots of fixes for booting.- Cleanup policy- Rebuild for Python 2.6- Fix labeling on /var/spool/rsyslog- Allow postgresl to bind to udp nodes- Allow lvm to dbus chat with hal - Allow rlogind to read nfs_t- Fix cyphesis file context- Allow hal/pm-utils to look at /var/run/video.rom - Add ulogd policy- Additional fixes for cyphesis - Fix certmaster file context - Add policy for system-config-samba - Allow hal to read /var/run/video.rom- Allow dhcpc to restart ypbind - Fixup labeling in /var/run- Add certmaster policy- Fix confined users - Allow xguest to read/write xguest_dbusd_t- Allow openoffice execstack/execmem privs- Allow mozilla to run with unconfined_execmem_t- Dontaudit domains trying to write to .xsession-errors- Allow nsplugin to look at autofs_t directory- Allow kerneloops to create tmp files- More alias for fastcgi- Remove mod_fcgid-selinux package- Fix dovecot access- Policy cleanup- Remove Multiple spec - Add include - Fix makefile to not call per_role_expansion- Fix labeling of libGL- Update to upstream- Update to upstream policy- Fixes for confined xwindows and xdm_t- Allow confined users and xdm to exec wm - Allow nsplugin to talk to fifo files on nfs- Allow NetworkManager to transition to avahi and iptables - Allow domains to search other domains keys, coverup kernel bug- Fix labeling for oracle- Allow nsplugin to comminicate with xdm_tmp_t sock_file- Change all user tmpfs_t files to be labeled user_tmpfs_t - Allow radiusd to create sock_files- Upgrade to upstream- Allow confined users to login with dbus- Fix transition to nsplugin- Add file context for /dev/mspblk.*- Fix transition to nsplugin '- Fix labeling on new pm*log - Allow ssh to bind to all nodes- Merge upstream changes - Add Xavier Toth patches- Add qemu_cache_t for /var/cache/libvirt- Remove gamin policy- Add tinyxs-max file system support- Update to upstream - New handling of init scripts- Allow pcsd to dbus - Add memcache policy- Allow audit dispatcher to kill his children- Update to upstream - Fix crontab use by unconfined user- Allow ifconfig_t to read dhcpc_state_t- Update to upstream- Update to upstream- Allow system-config-selinux to work with policykit- Fix novel labeling- Consolodate pyzor,spamassassin, razor into one security domain - Fix xdm requiring additional perms.- Fixes for logrotate, alsa- Eliminate vbetool duplicate entry- Fix xguest -> xguest_mozilla_t -> xguest_openiffice_t - Change dhclient to be able to red networkmanager_var_run- Update to latest refpolicy - Fix libsemanage initial install bug- Add inotify support to nscd- Allow unconfined_t to setfcap- Allow amanda to read tape - Allow prewikka cgi to use syslog, allow audisp_t to signal cgi - Add support for netware file systems- Allow ypbind apps to net_bind_service- Allow all system domains and application domains to append to any log file- Allow gdm to read rpm database - Allow nsplugin to read mplayer config files- Allow vpnc to run ifconfig- Allow confined users to use postgres - Allow system_mail_t to exec other mail clients - Label mogrel_rails as an apache server- Apply unconfined_execmem_exec_t to haskell programs- Fix prelude file context- allow hplip to talk dbus - Fix context on ~/.local dir- Prevent applications from reading x_device- Add /var/lib/selinux context- Update to upstream- Add livecd policy- Dontaudit search of admin_home for init_system_domain - Rewrite of xace interfaces - Lots of new fs_list_inotify - Allow livecd to transition to setfiles_mac- Begin XAce integration- Merge Upstream- Allow amanada to create data files- Fix initial install, semanage setup- Allow system_r for httpd_unconfined_script_t- Remove dmesg boolean - Allow user domains to read/write game data- Change unconfined_t to transition to unconfined_mono_t when running mono - Change XXX_mono_t to transition to XXX_t when executing bin_t files, so gnome-do will work- Remove old booleans from targeted-booleans.conf file- Add boolean to mmap_zero - allow tor setgid - Allow gnomeclock to set clock- Don't run crontab from unconfined_t- Change etc files to config files to allow users to read them- Lots of fixes for confined domains on NFS_t homedir- dontaudit mrtg reading /proc - Allow iscsi to signal itself - Allow gnomeclock sys_ptrace- Allow dhcpd to read kernel network state- Label /var/run/gdm correctly - Fix unconfined_u user creation- Allow transition from initrc_t to getty_t- Allow passwd to communicate with user sockets to change gnome-keyring- Fix initial install- Allow radvd to use fifo_file - dontaudit setfiles reading links - allow semanage sys_resource - add allow_httpd_mod_auth_ntlm_winbind boolean - Allow privhome apps including dovecot read on nfs and cifs home dirs if the boolean is set- Allow nsplugin to read /etc/mozpluggerrc, user_fonts - Allow syslog to manage innd logs. - Allow procmail to ioctl spamd_exec_t- Allow initrc_t to dbus chat with consolekit.- Additional access for nsplugin - Allow xdm setcap/getcap until pulseaudio is fixed- Allow mount to mkdir on tmpfs - Allow ifconfig to search debugfs- Fix file context for MATLAB - Fixes for xace- Allow stunnel to transition to inetd children domains - Make unconfined_dbusd_t an unconfined domain- Fixes for qemu/virtd- Fix bug in mozilla policy to allow xguest transition - This will fix the libsemanage.dbase_llist_query: could not find record value libsemanage.dbase_llist_query: could not query record value (No such file or directory) bug in xguest- Allow nsplugin to run acroread- Add cups_pdf policy - Add openoffice policy to run in xguest- prewika needs to contact mysql - Allow syslog to read system_map files- Change init_t to an unconfined_domain- Allow init to transition to initrc_t on shell exec. - Fix init to be able to sendto init_t. - Allow syslog to connect to mysql - Allow lvm to manage its own fifo_files - Allow bugzilla to use ldap - More mls fixes- fixes for init policy (#436988) - fix build- Additional changes for MLS policy- Fix initrc_context generation for MLS- Fixes for libvirt- Allow bitlebee to read locale_t- More xselinux rules- Change httpd_$1_script_r*_t to httpd_$1_content_r*_t- Prepare policy for beta release - Change some of the system domains back to unconfined - Turn on some of the booleans- Allow nsplugin_config execstack/execmem - Allow nsplugin_t to read alsa config - Change apache to use user content- Add cyphesis policy- Fix Makefile.devel to build mls modules - Fix qemu to be more specific on labeling- Update to upstream fixes- Allow staff to mounton user_home_t- Add xace support- Add fusectl file system- Fixes from yum-cron - Update to latest upstream- Fix userdom_list_user_files- Merge with upstream- Allow udev to send audit messages- Add additional login users interfaces - userdom_admin_login_user_template(staff)- More fixes for polkit- Eliminate transition from unconfined_t to qemu by default - Fixes for gpg- Update to upstream- Fixes for staff_t- Add policy for kerneloops - Add policy for gnomeclock- Fixes for libvirt- Fixes for nsplugin- More fixes for qemu- Additional ports for vnc and allow qemu and libvirt to search all directories- Update to upstream - Add libvirt policy - add qemu policy- Allow fail2ban to create a socket in /var/run- Allow allow_httpd_mod_auth_pam to work- Add audisp policy and prelude- Allow all user roles to executae samba net command- Allow usertypes to read/write noxattr file systems- Fix nsplugin to allow flashplugin to work in enforcing mode- Allow pam_selinux_permit to kill all processes- Allow ptrace or user processes by users of same type - Add boolean for transition to nsplugin- Allow nsplugin sys_nice, getsched, setsched- Allow login programs to talk dbus to oddjob- Add procmail_log support - Lots of fixes for munin- Allow setroubleshoot to read policy config and send audit messages- Allow users to execute all files in homedir, if boolean set - Allow mount to read samba config- Fixes for xguest to run java plugin- dontaudit pam_t and dbusd writing to user_home_t- Update gpg to allow reading of inotify- Change user and staff roles to work correctly with varied perms- Fix munin log, - Eliminate duplicate mozilla file context - fix wpa_supplicant spec- Fix role transition from unconfined_r to system_r when running rpm - Allow unconfined_domains to communicate with user dbus instances- Fixes for xguest- Let all uncofined domains communicate with dbus unconfined- Run rpm in system_r- Zero out customizable types- Fix definiton of admin_home_t- Fix munin file context- Allow cron to run unconfined apps- Modify default login to unconfined_u- Dontaudit dbus user client search of /root- Update to upstream- Fixes for polkit - Allow xserver to ptrace- Add polkit policy - Symplify userdom context, remove automatic per_role changes- Update to upstream - Allow httpd_sys_script_t to search users homedirs- Allow rpm_script to transition to unconfined_execmem_t- Remove user based home directory separation- Remove user specific crond_t- Merge with upstream - Allow xsever to read hwdata_t - Allow login programs to setkeycreate- Update to upstream- Update to upstream- Allow XServer to read /proc/self/cmdline - Fix unconfined cron jobs - Allow fetchmail to transition to procmail - Fixes for hald_mac - Allow system_mail to transition to exim - Allow tftpd to upload files - Allow xdm to manage unconfined_tmp - Allow udef to read alsa config - Fix xguest to be able to connect to sound port- Fixes for hald_mac - Treat unconfined_home_dir_t as a home dir - dontaudit rhgb writes to fonts and root- Fix dnsmasq - Allow rshd full login privs- Allow rshd to connect to ports > 1023- Fix vpn to bind to port 4500 - Allow ssh to create shm - Add Kismet policy- Allow rpm to chat with networkmanager- Fixes for ipsec and exim mail - Change default to unconfined user- Pass the UNK_PERMS param to makefile - Fix gdm location- Make alsa work- Fixes for consolekit and startx sessions- Dontaudit consoletype talking to unconfined_t- Remove homedir_template- Check asound.state- Fix exim policy- Allow tmpreadper to read man_t - Allow racoon to bind to all nodes - Fixes for finger print reader- Allow xdm to talk to input device (fingerprint reader) - Allow octave to run as java- Allow login programs to set ioctl on /proc- Allow nsswitch apps to read samba_var_t- Fix maxima- Eliminate rpm_t:fifo_file avcs - Fix dbus path for helper app- Fix service start stop terminal avc's- Allow also to search var_lib - New context for dbus launcher- Allow cupsd_config_t to read/write usb_device_t - Support for finger print reader, - Many fixes for clvmd - dbus starting networkmanager- Fix java and mono to run in xguest account- Fix to add xguest account when inititial install - Allow mono, java, wine to run in userdomains- Allow xserver to search devpts_t - Dontaudit ldconfig output to homedir- Remove hplip_etc_t change back to etc_t.- Allow cron to search nfs and samba homedirs- Allow NetworkManager to dbus chat with yum-updated- Allow xfs to bind to port 7100- Allow newalias/sendmail dac_override - Allow bind to bind to all udp ports- Turn off direct transition- Allow wine to run in system role- Fix java labeling- Define user_home_type as home_type- Allow sendmail to create etc_aliases_t- Allow login programs to read symlinks on homedirs- Update an readd modules- Cleanup spec file- Allow xserver to be started by unconfined process and talk to tty- Upgrade to upstream to grab postgressql changes- Add setransd for mls policy- Add ldconfig_cache_t- Allow sshd to write to proc_t for afs login- Allow xserver access to urand- allow dovecot to search mountpoints- Fix Makefile for building policy modules- Fix dhcpc startup of service- Fix dbus chat to not happen for xguest and guest users- Fix nagios cgi - allow squid to communicate with winbind- Fixes for ldconfig- Update from upstream- Add nasd support- Fix new usb devices and dmfm- Eliminate mount_ntfs_t policy, merge into mount_t- Allow xserver to write to ramfs mounted by rhgb- Add context for dbus machine id- Update with latest changes from upstream- Fix prelink to handle execmod- Add ntpd_key_t to handle secret data- Add anon_inodefs - Allow unpriv user exec pam_exec_t - Fix trigger- Allow cups to use generic usb - fix inetd to be able to run random apps (git)- Add proper contexts for rsyslogd- Fixes for xguest policy- Allow execution of gconf- Fix moilscanner update problem- Begin adding policy to separate setsebool from semanage - Fix xserver.if definition to not break sepolgen.if- Add new devices- Add brctl policy- Fix root login to include system_r- Allow prelink to read kernel sysctls- Default to user_u:system_r:unconfined_t- fix squid - Fix rpm running as uid- Fix syslog declaration- Allow avahi to access inotify - Remove a lot of bogus security_t:filesystem avcs- Remove ifdef strict policy from upstream- Remove ifdef strict to allow user_u to login- Fix for amands - Allow semanage to read pp files - Allow rhgb to read xdm_xserver_tmp- Allow kerberos servers to use ldap for backing store- allow alsactl to read kernel state- More fixes for alsactl - Transition from hal and modutils - Fixes for suspend resume. - insmod domtrans to alsactl - insmod writes to hal log- Allow unconfined_t to transition to NetworkManager_t - Fix netlabel policy- Update to latest from upstream- Update to latest from upstream- Update to latest from upstream- Allow pcscd_t to send itself signals- Fixes for unix_update - Fix logwatch to be able to search all dirs- Upstream bumped the version- Allow consolekit to syslog - Allow ntfs to work with hal- Allow iptables to read etc_runtime_t- MLS Fixes- Fix path of /etc/lvm/cache directory - Fixes for alsactl and pppd_t - Fixes for consolekit- Allow insmod_t to mount kvmfs_t filesystems- Rwho policy - Fixes for consolekit- fixes for fusefs- Fix samba_net to allow it to view samba_var_t- Update to upstream- Fix Sonypic backlight - Allow snmp to look at squid_conf_t- Fixes for pyzor, cyrus, consoletype on everything installs- Fix hald_acl_t to be able to getattr/setattr on usb devices - Dontaudit write to unconfined_pipes for load_policy- Allow bluetooth to read inotifyfs- Fixes for samba domain controller. - Allow ConsoleKit to look at ttys- Fix interface call- Allow syslog-ng to read /var - Allow locate to getattr on all filesystems - nscd needs setcap- Update to upstream- Allow samba to run groupadd- Update to upstream- Allow mdadm to access generic scsi devices- Fix labeling on udev.tbl dirs- Fixes for logwatch- Add fusermount and mount_ntfs policy- Update to upstream - Allow saslauthd to use kerberos keytabs- Fixes for samba_var_t- Allow networkmanager to setpgid - Fixes for hal_acl_t- Remove disable_trans booleans - hald_acl_t needs to talk to nscd- Fix prelink to be able to manage usr dirs.- Allow insmod to launch init scripts- Remove setsebool policy- Fix handling of unlabled_t packets- More of my patches from upstream- Update to latest from upstream - Add fail2ban policy- Update to remove security_t:filesystem getattr problems- Policy for consolekit- Update to latest from upstream- Revert Nemiver change - Set sudo as a corecmd so prelink will work, remove sudoedit mapping, since this will not work, it does not transition. - Allow samba to execute useradd- Upgrade to the latest from upstream- Add sepolgen support - Add bugzilla policy- Fix file context for nemiver- Remove include sym link- Allow mozilla, evolution and thunderbird to read dev_random. Resolves: #227002 - Allow spamd to connect to smtp port Resolves: #227184 - Fixes to make ypxfr work Resolves: #227237- Fix ssh_agent to be marked as an executable - Allow Hal to rw sound device- Fix spamassisin so crond can update spam files - Fixes to allow kpasswd to work - Fixes for bluetooth- Remove some targeted diffs in file context file- Fix squid cachemgr labeling- Add ability to generate webadm_t policy - Lots of new interfaces for httpd - Allow sshd to login as unconfined_t- Continue fixing, additional user domains- Begin adding user confinement to targeted policy- Fixes for prelink, ktalkd, netlabel- Allow prelink when run from rpm to create tmp files Resolves: #221865 - Remove file_context for exportfs Resolves: #221181 - Allow spamassassin to create ~/.spamassissin Resolves: #203290 - Allow ssh access to the krb tickets - Allow sshd to change passwd - Stop newrole -l from working on non securetty Resolves: #200110 - Fixes to run prelink in MLS machine Resolves: #221233 - Allow spamassassin to read var_lib_t dir Resolves: #219234- fix mplayer to work under strict policy - Allow iptables to use nscd Resolves: #220794- Add gconf policy and make it work with strict- Many fixes for strict policy and by extension mls.- Fix to allow ftp to bind to ports > 1024 Resolves: #219349- Allow semanage to exec it self. Label genhomedircon as semanage_exec_t Resolves: #219421 - Allow sysadm_lpr_t to manage other print spool jobs Resolves: #220080- allow automount to setgid Resolves: #219999- Allow cron to polyinstatiate - Fix creation of boot flags Resolves: #207433- Fixes for irqbalance Resolves: #219606- Fix vixie-cron to work on mls Resolves: #207433Resolves: #218978- Allow initrc to create files in /var directories Resolves: #219227- More fixes for MLS Resolves: #181566- More Fixes polyinstatiation Resolves: #216184- More Fixes polyinstatiation - Fix handling of keyrings Resolves: #216184- Fix polyinstatiation - Fix pcscd handling of terminal Resolves: #218149 Resolves: #218350- More fixes for quota Resolves: #212957- ncsd needs to use avahi sockets Resolves: #217640 Resolves: #218014- Allow login programs to polyinstatiate homedirs Resolves: #216184 - Allow quotacheck to create database files Resolves: #212957- Dontaudit appending hal_var_lib files Resolves: #217452 Resolves: #217571 Resolves: #217611 Resolves: #217640 Resolves: #217725- Fix context for helix players file_context #216942- Fix load_policy to be able to mls_write_down so it can talk to the terminal- Fixes for hwclock, clamav, ftp- Move to upstream version which accepted my patches- Fixes for nvidia driver- Allow semanage to signal mcstrans- Update to upstream- Allow modstorage to edit /etc/fstab file- Fix for qemu, /dev/- Fix path to realplayer.bin- Allow xen to connect to xen port- Allow cups to search samba_etc_t directory - Allow xend_t to list auto_mountpoints- Allow xen to search automount- Fix spec of jre files- Fix unconfined access to shadow file- Allow xend to create files in xen_image_t directories- Fixes for /var/lib/hal- Remove ability for sysadm_t to look at audit.log- Fix rpc_port_types - Add aide policy for mls- Merge with upstream- Lots of fixes for ricci- Allow xen to read/write fixed devices with a boolean - Allow apache to search /var/log- Fix policygentool specfile problem. - Allow apache to send signals to it's logging helpers. - Resolves: rhbz#212731- Add perms for swat- Add perms for swat- Allow daemons to dump core files to /- Fixes for ricci- Allow mount.nfs to work- Allow ricci-modstorage to look at lvm_etc_t- Fixes for ricci using saslauthd- Allow mountpoint on home_dir_t and home_t- Update xen to read nfs files- Allow noxattrfs to associate with other noxattrfs- Allow hal to use power_device_t- Allow procemail to look at autofs_t - Allow xen_image_t to work as a fixed device- Refupdate from upstream- Add lots of fixes for mls cups- Lots of fixes for ricci- Fix number of cats- Update to upstream- More iSCSI changes for #209854- Test ISCSI fixes for #209854- allow semodule to rmdir selinux_config_t dir- Fix boot_runtime_t problem on ppc. Should not be creating these files.- Fix context mounts on reboot - Fix ccs creation of directory in /var/log- Update for tallylog- Allow xend to rewrite dhcp conf files - Allow mgetty sys_admin capability- Make xentapctrl work- Don't transition unconfined_t to bootloader_t - Fix label in /dev/xen/blktap- Patch for labeled networking- Fix crond handling for mls- Update to upstream- Remove bluetooth-helper transition - Add selinux_validate for semanage - Require new version of libsemanage- Fix prelink- Fix rhgb- Fix setrans handling on MLS and useradd- Support for fuse - fix vigr- Fix dovecot, amanda - Fix mls- Allow java execheap for itanium- Update with upstream- mls fixes- Update from upstream- More fixes for mls - Revert change on automount transition to mount- Fix cron jobs to run under the correct context- Fixes to make pppd work- Multiple policy fixes - Change max categories to 1023- Fix transition on mcstransd- Add /dev/em8300 defs- Upgrade to upstream- Fix ppp connections from network manager- Add tty access to all domains boolean - Fix gnome-pty-helper context for ia64- Fixed typealias of firstboot_rw_t- Fix location of xel log files - Fix handling of sysadm_r -> rpm_exec_t- Fixes for autofs, lp- Update from upstream- Fixup for test6- Update to upstream- Update to upstream- Fix suspend to disk problems- Lots of fixes for restarting daemons at the console.- Fix audit line - Fix requires line- Upgrade to upstream- Fix install problems- Allow setroubleshoot to getattr on all dirs to gather RPM data- Set /usr/lib/ia32el/ia32x_loader to unconfined_execmem_exec_t for ia32 platform - Fix spec for /dev/adsp- Fix xen tty devices- Fixes for setroubleshoot- Update to upstream- Fixes for stunnel and postgresql - Update from upstream- Update from upstream - More java fixes- Change allow_execstack to default to on, for RHEL5 Beta. This is required because of a Java compiler problem. Hope to turn off for next beta- Misc fixes- More fixes for strict policy- Quiet down anaconda audit messages- Fix setroubleshootd- Update to the latest from upstream- More fixes for xen- Fix anaconda transitions- yet more xen rules- more xen rules- Fixes for Samba- Fixes for xen- Allow setroubleshootd to send mail- Add nagios policy- fixes for setroubleshoot- Added Paul Howarth patch to only load policy packages shipped with this package - Allow pidof from initrc to ptrace higher level domains - Allow firstboot to communicate with hal via dbus- Add policy for /var/run/ldapi- Fix setroubleshoot policy- Fixes for mls use of ssh - named has a new conf file- Fixes to make setroubleshoot work- Cups needs to be able to read domain state off of printer client- add boolean to allow zebra to write config files- setroubleshootd fixes- Allow prelink to read bin_t symlink - allow xfs to read random devices - Change gfs to support xattr- Remove spamassassin_can_network boolean- Update to upstream - Fix lpr domain for mls- Add setroubleshoot policy- Turn off auditallow on setting booleans- Multiple fixes- Update to upstream- Update to upstream - Add new class for kernel key ring- Update to upstream- Update to upstream- Break out selinux-devel package- Add ibmasmfs- Fix policygentool gen_requires- Update from Upstream- Fix spec of realplay- Update to upstream- Fix semanage- Allow useradd to create_home_dir in MLS environment- Update from upstream- Update from upstream- Add oprofilefs- Fix for hplip and Picasus- Update to upstream- Update to upstream- fixes for spamd- fixes for java, openldap and webalizer- Xen fixes- Upgrade to upstream- allow hal to read boot_t files - Upgrade to upstream- allow hal to read boot_t files- Update from upstream- Fixes for amavis- Update from upstream- Allow auditctl to search all directories- Add acquire service for mono.- Turn off allow_execmem boolean - Allow ftp dac_override when allowed to access users homedirs- Clean up spec file - Transition from unconfined_t to prelink_t- Allow execution of cvs command- Update to upstream- Update to upstream- Fix libjvm spec- Update to upstream- Add xm policy - Fix policygentool- Update to upstream - Fix postun to only disable selinux on full removal of the packages- Allow mono to chat with unconfined- Allow procmail to sendmail - Allow nfs to share dosfs- Update to latest from upstream - Allow selinux-policy to be removed and kernel not to crash- Update to latest from upstream - Add James Antill patch for xen - Many fixes for pegasus- Add unconfined_mount_t - Allow privoxy to connect to httpd_cache - fix cups labeleing on /var/cache/cups- Update to latest from upstream- Update to latest from upstream - Allow mono and unconfined to talk to initrc_t dbus objects- Change libraries.fc to stop shlib_t form overriding texrel_shlib_t- Fix samba creating dirs in homedir - Fix NFS so its booleans would work- Allow secadm_t ability to relabel all files - Allow ftp to search xferlog_t directories - Allow mysql to communicate with ldap - Allow rsync to bind to rsync_port_t- Fixed mailman with Postfix #183928 - Allowed semanage to create file_context files. - Allowed amanda_t to access inetd_t TCP sockets and allowed amanda_recover_t to bind to reserved ports. #149030 - Don't allow devpts_t to be associated with tmp_t. - Allow hald_t to stat all mountpoints. - Added boolean samba_share_nfs to allow smbd_t full access to NFS mounts. - Make mount run in mount_t domain from unconfined_t to prevent mislabeling of /etc/mtab. - Changed the file_contexts to not have a regex before the first ^/[a-z]/ whenever possible, makes restorecon slightly faster. - Correct the label of /etc/named.caching-nameserver.conf - Now label /usr/src/kernels/.+/lib(/.*)? as usr_t instead of /usr/src(/.*)?/lib(/.*)? - I don't think we need anything else under /usr/src hit by this. - Granted xen access to /boot, allowed mounting on xend_var_lib_t, and allowed xenstored_t rw access to the xen device node.- More textrel_shlib_t file path fixes - Add ada support- Get auditctl working in MLS policy- Add mono dbus support - Lots of file_context fixes for textrel_shlib_t in FC5 - Turn off execmem auditallow since they are filling log files- Update to upstream- Allow automount and dbus to read cert files- Fix ftp policy - Fix secadm running of auditctl- Update to upstream- Update to upstream- Fix policyhelp- Fix pam_console handling of usb_device - dontaudit logwatch reading /mnt dir- Update to upstream- Get transition rules to create policy.20 at SystemHigh- Allow secadmin to shutdown system - Allow sendmail to exec newalias- MLS Fixes dmidecode needs mls_file_read_up - add ypxfr_t - run init needs access to nscd - udev needs setuid - another xen log file - Dontaudit mount getattr proc_kcore_t- fix buildroot usage (#185391)- Get rid of mount/fsdisk scan of /dev messages - Additional fixes for suspend/resume- Fake make to rebuild enableaudit.pp- Get xen networking running.- Fixes for Xen - enableaudit should not be the same as base.pp - Allow ps to work for all process- more xen policy fixups- more xen fixage (#184393)- Fix blkid specification - Allow postfix to execute mailman_que- Blkid changes - Allow udev access to usb_device_t - Fix post script to create targeted policy config file- Allow lvm tools to create drevice dir- Add Xen support- Fixes for cups - Make cryptosetup work with hal- Load Policy needs translock- Fix cups html interface- Add hal changes suggested by Jeremy - add policyhelp to point at policy html pages- Additional fixes for nvidia and cups- Update to upstream - Merged my latest fixes - Fix cups policy to handle unix domain sockets- NSCD socket is in nscd_var_run_t needs to be able to search dir- Fixes Apache interface file- Fixes for new version of cups- Turn off polyinstatiate util after FC5- Fix problem with privoxy talking to Tor- Turn on polyinstatiation- Don't transition from unconfined_t to fsadm_t- Fix policy update model.- Update to upstream- Fix load_policy to work on MLS - Fix cron_rw_system_pipes for postfix_postdrop_t - Allow audotmount to run showmount- Fix swapon - allow httpd_sys_script_t to be entered via a shell - Allow httpd_sys_script_t to read eventpolfs- Update from upstream- allow cron to read apache files- Fix vpnc policy to work from NetworkManager- Update to upstream - Fix semoudle polcy- Update to upstream - fix sysconfig/selinux link- Add router port for zebra - Add imaze port for spamd - Fixes for amanda and java- Fix bluetooth handling of usb devices - Fix spamd reading of ~/ - fix nvidia spec- Update to upsteam- Add users_extra files- Update to upstream- Add semodule policy- Update from upstream- Fix for spamd to use razor port- Fixes for mcs - Turn on mount and fsadm for unconfined_t- Fixes for the -devel package- Fix for spamd to use ldap- Update to upstream- Update to upstream - Fix rhgb, and other Xorg startups- Update to upstream- Separate out role of secadm for mls- Add inotifyfs handling- Update to upstream - Put back in changes for pup/zen- Many changes for MLS - Turn on strict policy- Update to upstream- Update to upstream - Fixes for booting and logging in on MLS machine- Update to upstream - Turn off execheap execstack for unconfined users - Add mono/wine policy to allow execheap and execstack for them - Add execheap for Xdm policy- Update to upstream - Fixes to fetchmail,- Update to upstream- Fix for procmail/spamassasin - Update to upstream - Add rules to allow rpcd to work with unlabeled_networks.- Update to upstream - Fix ftp Man page- Update to upstream- fix pup transitions (#177262) - fix xen disks (#177599)- Update to upstream- More Fixes for hal and readahead- Fixes for hal and readahead- Update to upstream - Apply- Add wine and fix hal problems- Handle new location of hal scripts- Allow su to read /etc/mtab- Update to upstream- Fix "libsemanage.parse_module_headers: Data did not represent a module." problem- Allow load_policy to read /etc/mtab- Fix dovecot to allow dovecot_auth to look at /tmp- Allow restorecon to read unlabeled_t directories in order to fix labeling.- Add Logwatch policy- Fix /dev/ub[a-z] file context- Fix library specification - Give kudzu execmem privs- Fix hostname in targeted policy- Fix passwd command on mls- Lots of fixes to make mls policy work- Add dri libs to textrel_shlib_t - Add system_r role for java - Add unconfined_exec_t for vncserver - Allow slapd to use kerberos- Add man pages- Add enableaudit.pp- Fix mls policy- Update mls file from old version- Add sids back in - Rebuild with update checkpolicy- Fixes to allow automount to use portmap - Fixes to start kernel in s0-s15:c0.c255- Add java unconfined/execmem policy- Add file context for /var/cvs - Dontaudit webalizer search of homedir- Update from upstream- Clean up spec - range_transition crond to SystemHigh- Fixes for hal - Update to upstream- Turn back on execmem since we need it for java, firefox, ooffice - Allow gpm to stream socket to itself- fix requirements to be on the actual packages so that policy can get created properly at install time- Allow unconfined_t to execmod texrel_shlib_t- Update to upstream - Turn off allow_execmem and allow_execmod booleans - Add tcpd and automount policies- Add two new httpd booleans, turned off by default * httpd_can_network_relay * httpd_can_network_connect_db- Add ghost for policy.20- Update to upstream - Turn off boolean allow_execstack- Change setrans-mls to use new libsetrans - Add default_context rule for xdm- Change Requires to PreReg for requiring of policycoreutils on install- New upstream releaseAdd xdm policyUpdate from upstreamUpdate from upstreamUpdate from upstream- Also trigger to rebuild policy for versions up to 2.0.7.- No longer installing policy.20 file, anaconda handles the building of the app.- Fixes for dovecot and saslauthd- Cleanup pegasus and named - Fix spec file - Fix up passwd changing applications-Update to latest from upstream- Add rules for pegasus and avahi- Start building MLS Policy- Update to upstream- Turn on bash- Initial version/bin/sh  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-..0123456789:;<=>?@ABCDEFGHIJKLMN3.13.1-229.el7_6.5    develMakefileexample.fcexample.ifexample.tehtmlNetworkManager.htmlabrt.htmlabrt_dump_oops.htmlabrt_handle_event.htmlabrt_helper.htmlabrt_retrace_coredump.htmlabrt_retrace_worker.htmlabrt_upload_watch.htmlabrt_watch_log.htmlaccountsd.htmlacct.htmladmin_crontab.htmlafs.htmlafs_bosserver.htmlafs_fsserver.htmlafs_kaserver.htmlafs_ptserver.htmlafs_vlserver.htmlaiccu.htmlaide.htmlajaxterm.htmlajaxterm_ssh.htmlalsa.htmlamanda.htmlamanda_recover.htmlamtu.htmlanaconda.htmlanon_sftpd.htmlantivirus.htmlapcupsd.htmlapcupsd_cgi_script.htmlapm.htmlapmd.htmlarpwatch.htmlasterisk.htmlaudisp.htmlaudisp_remote.htmlauditadm.htmlauditadm_screen.htmlauditadm_su.htmlauditadm_sudo.htmlauditctl.htmlauditd.htmlauthconfig.htmlautomount.htmlavahi.htmlawstats.htmlawstats_script.htmlbacula.htmlbacula_admin.htmlbacula_unconfined_script.htmlbcfg2.htmlbitlbee.htmlblkmapd.htmlblktap.htmlblueman.htmlbluetooth.htmlbluetooth_helper.htmlboinc.htmlboinc_project.htmlbootloader.htmlbrctl.htmlbrltty.htmlbugzilla_script.htmlbumblebee.htmlcachefiles_kernel.htmlcachefilesd.htmlcalamaris.htmlcallweaver.htmlcanna.htmlcardmgr.htmlccs.htmlcdcc.htmlcdrecord.htmlcertmaster.htmlcertmonger.htmlcertmonger_unconfined.htmlcertwatch.htmlcfengine_execd.htmlcfengine_monitord.htmlcfengine_serverd.htmlcgclear.htmlcgconfig.htmlcgdcbxd.htmlcgred.htmlcheckpc.htmlcheckpolicy.htmlchfn.htmlchkpwd.htmlchrome_sandbox.htmlchrome_sandbox_nacl.htmlchronyc.htmlchronyd.htmlchroot_user.htmlcinder_api.htmlcinder_backup.htmlcinder_scheduler.htmlcinder_volume.htmlciped.htmlclogd.htmlcloud_init.htmlcluster.htmlclvmd.htmlcmirrord.htmlcobblerd.htmlcockpit_session.htmlcockpit_ws.htmlcollectd.htmlcollectd_script.htmlcolord.htmlcomsat.htmlcondor_collector.htmlcondor_master.htmlcondor_negotiator.htmlcondor_procd.htmlcondor_schedd.htmlcondor_startd.htmlcondor_startd_ssh.htmlconman.htmlconman_unconfined_script.htmlconsolekit.htmlcontainer.htmlcontainer_auth.htmlcontainer_runtime.htmlcouchdb.htmlcourier_authdaemon.htmlcourier_pcp.htmlcourier_pop.htmlcourier_sqwebmail.htmlcourier_tcpd.htmlcpucontrol.htmlcpufreqselector.htmlcpuplug.htmlcpuspeed.htmlcrack.htmlcrond.htmlcronjob.htmlcrontab.htmlctdbd.htmlcups_pdf.htmlcupsd.htmlcupsd_config.htmlcupsd_lpd.htmlcvs.htmlcvs_script.htmlcyphesis.htmlcyrus.htmldbadm.htmldbadm_sudo.htmldbskkd.htmldcc_client.htmldcc_dbclean.htmldccd.htmldccifd.htmldccm.htmldcerpcd.htmlddclient.htmldeltacloudd.htmldenyhosts.htmldepmod.htmldevicekit.htmldevicekit_disk.htmldevicekit_power.htmldhcpc.htmldhcpd.htmldictd.htmldirsrv.htmldirsrv_snmp.htmldirsrvadmin.htmldirsrvadmin_script.htmldirsrvadmin_unconfined_script.htmldisk_munin_plugin.htmldkim_milter.htmldlm_controld.htmldmesg.htmldmidecode.htmldnsmasq.htmldnssec_trigger.htmldovecot.htmldovecot_auth.htmldovecot_deliver.htmldrbd.htmldspam.htmldspam_script.htmlentropyd.htmleventlogd.htmlevtchnd.htmlexim.htmlfail2ban.htmlfail2ban_client.htmlfcoemon.htmlfenced.htmlfetchmail.htmlfingerd.htmlfirewalld.htmlfirewallgui.htmlfirstboot.htmlfoghorn.htmlfprintd.htmlfreeipmi_bmc_watchdog.htmlfreeipmi_ipmidetectd.htmlfreeipmi_ipmiseld.htmlfreqset.htmlfsadm.htmlfsdaemon.htmlftpd.htmlftpdctl.htmlgames.htmlgames_srv.htmlganesha.htmlgconfd.htmlgconfdefaultsm.htmlgdomap.htmlgeoclue.htmlgetty.htmlgfs_controld.htmlgit_script.htmlgit_session.htmlgit_system.htmlgitosis.htmlglance_api.htmlglance_registry.htmlglance_scrubber.htmlglusterd.htmlgnomesystemmm.htmlgpg.htmlgpg_agent.htmlgpg_helper.htmlgpg_pinentry.htmlgpg_web.htmlgpm.htmlgpsd.htmlgreylist_milter.htmlgroupadd.htmlgroupd.htmlgssd.htmlgssproxy.htmlguest.htmlhaproxy.htmlhddtemp.htmlhostname.htmlhsqldb.htmlhttpd.htmlhttpd_helper.htmlhttpd_passwd.htmlhttpd_php.htmlhttpd_rotatelogs.htmlhttpd_suexec.htmlhttpd_sys_script.htmlhttpd_unconfined_script.htmlhttpd_user_script.htmlhwclock.htmlhwloc_dhwd.htmlhypervkvp.htmlhypervvssd.htmliceauth.htmlicecast.htmlifconfig.htmlindex.htmlinetd.htmlinetd_child.htmlinit.htmlinitrc.htmlinnd.htmlinsmod.htmlinstall.htmliodined.htmliotop.htmlipa_dnskey.htmlipa_helper.htmlipa_otpd.htmlipmievd.htmlipsec.htmlipsec_mgmt.htmliptables.htmlirc.htmlirqbalance.htmlirssi.htmliscsid.htmlisnsd.htmliwhd.htmljabberd.htmljabberd_router.htmljockey.htmljournalctl.htmlkadmind.htmlkdump.htmlkdumpctl.htmlkdumpgui.htmlkeepalived.htmlkeepalived_unconfined_script.htmlkernel.htmlkeyboardd.htmlkeystone.htmlkeystone_cgi_script.htmlkismet.htmlklogd.htmlkmscon.htmlkpropd.htmlkrb5kdc.htmlksmtuned.htmlktalkd.htmll2tpd.htmlldconfig.htmllircd.htmllivecd.htmllldpad.htmlload_policy.htmlloadkeys.htmllocal_login.htmllocate.htmllockdev.htmllogadm.htmllogrotate.htmllogrotate_mail.htmllogwatch.htmllogwatch_mail.htmllpd.htmllpr.htmllsassd.htmllsmd.htmllsmd_plugin.htmllttng_sessiond.htmllvm.htmllwiod.htmllwregd.htmllwsmd.htmlmail_munin_plugin.htmlmailman_cgi.htmlmailman_mail.htmlmailman_queue.htmlman2html_script.htmlmandb.htmlmcelog.htmlmdadm.htmlmediawiki_script.htmlmemcached.htmlmencoder.htmlminidlna.htmlminissdpd.htmlmip6d.htmlmirrormanager.htmlmock.htmlmock_build.htmlmodemmanager.htmlmojomojo_script.htmlmon_procd.htmlmon_statd.htmlmongod.htmlmotion.htmlmount.htmlmount_ecryptfs.htmlmozilla.htmlmozilla_plugin.htmlmozilla_plugin_config.htmlmpd.htmlmplayer.htmlmrtg.htmlmscan.htmlmunin.htmlmunin_script.htmlmysqld.htmlmysqld_safe.htmlmysqlmanagerd.htmlmythtv_script.htmlnagios.htmlnagios_admin_plugin.htmlnagios_checkdisk_plugin.htmlnagios_eventhandler_plugin.htmlnagios_mail_plugin.htmlnagios_openshift_plugin.htmlnagios_script.htmlnagios_services_plugin.htmlnagios_system_plugin.htmlnagios_unconfined_plugin.htmlnamed.htmlnamespace_init.htmlncftool.htmlndc.htmlnetlabel_mgmt.htmlnetlogond.htmlnetutils.htmlneutron.htmlnewrole.htmlnfsd.htmlninfod.htmlnmbd.htmlnova.htmlnrpe.htmlnscd.htmlnsd.htmlnsd_crond.htmlnslcd.htmlntop.htmlntpd.htmlnumad.htmlnut_upsd.htmlnut_upsdrvctl.htmlnut_upsmon.htmlnutups_cgi_script.htmlnx_server.htmlnx_server_ssh.htmlobex.htmloddjob.htmloddjob_mkhomedir.htmlopenct.htmlopendnssec.htmlopenhpid.htmlopenshift.htmlopenshift_app.htmlopenshift_cgroup_read.htmlopenshift_cron.htmlopenshift_initrc.htmlopenshift_net_read.htmlopenshift_script.htmlopensm.htmlopenvpn.htmlopenvpn_unconfined_script.htmlopenvswitch.htmlopenwsman.htmloracleasm.htmlosad.htmlpads.htmlpam_console.htmlpam_timestamp.htmlpassenger.htmlpasswd.htmlpcp_pmcd.htmlpcp_pmie.htmlpcp_pmlogger.htmlpcp_pmmgr.htmlpcp_pmproxy.htmlpcp_pmwebd.htmlpcscd.htmlpegasus.htmlpegasus_openlmi_account.htmlpegasus_openlmi_admin.htmlpegasus_openlmi_logicalfile.htmlpegasus_openlmi_services.htmlpegasus_openlmi_storage.htmlpegasus_openlmi_system.htmlpegasus_openlmi_unconfined.htmlpesign.htmlphc2sys.htmlping.htmlpingd.htmlpiranha_fos.htmlpiranha_lvs.htmlpiranha_pulse.htmlpiranha_web.htmlpkcs_slotd.htmlpki_ra.htmlpki_tomcat.htmlpki_tomcat_script.htmlpki_tps.htmlplymouth.htmlplymouthd.htmlpodsleuth.htmlpolicykit.htmlpolicykit_auth.htmlpolicykit_grant.htmlpolicykit_resolve.htmlpolipo.htmlpolipo_session.htmlportmap.htmlportmap_helper.htmlportreserve.htmlpostfix_bounce.htmlpostfix_cleanup.htmlpostfix_local.htmlpostfix_map.htmlpostfix_master.htmlpostfix_pickup.htmlpostfix_pipe.htmlpostfix_postdrop.htmlpostfix_postqueue.htmlpostfix_qmgr.htmlpostfix_showq.htmlpostfix_smtp.htmlpostfix_smtpd.htmlpostfix_virtual.htmlpostgresql.htmlpostgrey.htmlpppd.htmlpptp.htmlprelink.htmlprelink_cron_system.htmlprelude.htmlprelude_audisp.htmlprelude_correlator.htmlprelude_lml.htmlpreupgrade.htmlprewikka_script.htmlprivoxy.htmlprocmail.htmlprosody.htmlpsad.htmlptal.htmlptchown.htmlptp4l.htmlpublicfile.htmlpulseaudio.htmlpuppetagent.htmlpuppetca.htmlpuppetmaster.htmlpwauth.htmlpyicqt.htmlqdiskd.htmlqemu_dm.htmlqmail_clean.htmlqmail_inject.htmlqmail_local.htmlqmail_lspawn.htmlqmail_queue.htmlqmail_remote.htmlqmail_rspawn.htmlqmail_send.htmlqmail_smtpd.htmlqmail_splogger.htmlqmail_start.htmlqmail_tcp_env.htmlqpidd.htmlquota.htmlquota_nld.htmlrabbitmq.htmlracoon.htmlradiusd.htmlradvd.htmlrasdaemon.htmlrdisc.htmlreadahead.htmlrealmd.htmlrealmd_consolehelper.htmlredis.htmlregex_milter.htmlremote_login.htmlrestorecond.htmlrhev_agentd.htmlrhev_agentd_consolehelper.htmlrhgb.htmlrhnsd.htmlrhsmcertd.htmlricci.htmlricci_modcluster.htmlricci_modclusterd.htmlricci_modlog.htmlricci_modrpm.htmlricci_modservice.htmlricci_modstorage.htmlrlogind.htmlrngd.htmlroundup.htmlrpcbind.htmlrpcd.htmlrpm.htmlrpm_script.htmlrshd.htmlrssh.htmlrssh_chroot_helper.htmlrsync.htmlrtas_errd.htmlrtkit_daemon.htmlrun_init.htmlrwho.htmlsamba_net.htmlsamba_unconfined_net.htmlsamba_unconfined_script.htmlsambagui.htmlsandbox.htmlsandbox_min.htmlsandbox_min_client.htmlsandbox_net.htmlsandbox_net_client.htmlsandbox_web.htmlsandbox_web_client.htmlsandbox_x.htmlsandbox_x_client.htmlsandbox_xserver.htmlsanlk_resetd.htmlsanlock.htmlsaslauthd.htmlsbd.htmlsblim_gatherd.htmlsblim_reposd.htmlsblim_sfcbd.htmlsecadm.htmlsecadm_screen.htmlsecadm_su.htmlsecadm_sudo.htmlsectoolm.htmlselinux_munin_plugin.htmlsemanage.htmlsendmail.htmlsensord.htmlsepgsql_ranged_proc.htmlsepgsql_trusted_proc.htmlservices_munin_plugin.htmlsetfiles.htmlsetfiles_mac.htmlsetkey.htmlsetrans.htmlsetroubleshoot_fixit.htmlsetroubleshootd.htmlsetsebool.htmlsftpd.htmlsge_execd.htmlsge_job.htmlsge_job_ssh.htmlsge_shepherd.htmlshorewall.htmlshowmount.htmlslapd.htmlslpd.htmlsmbcontrol.htmlsmbd.htmlsmbmount.htmlsmokeping.htmlsmokeping_cgi_script.htmlsmoltclient.htmlsmsd.htmlsnapperd.htmlsnmpd.htmlsnort.htmlsosreport.htmlsoundd.htmlspamass_milter.htmlspamc.htmlspamd.htmlspamd_update.htmlspc.htmlspeech-dispatcher.htmlsquid.htmlsquid_cron.htmlsquid_script.htmlsrvsvcd.htmlssh.htmlssh_keygen.htmlssh_keysign.htmlsshd.htmlsshd_keygen.htmlsshd_net.htmlsshd_sandbox.htmlsssd.htmlsssd_selinux_manager.htmlstaff.htmlstaff_consolehelper.htmlstaff_dbusd.htmlstaff_gkeyringd.htmlstaff_screen.htmlstaff_seunshare.htmlstaff_ssh_agent.htmlstaff_sudo.htmlstaff_wine.htmlstapserver.htmlstunnel.htmlstyle.csssulogin.htmlsvc_multilog.htmlsvc_run.htmlsvc_start.htmlsvirt.htmlsvirt_kvm_net.htmlsvirt_qemu_net.htmlsvirt_socket.htmlsvirt_tcg.htmlsvnserve.htmlswat.htmlswift.htmlsysadm.htmlsysadm_gkeyringd.htmlsysadm_passwd.htmlsysadm_screen.htmlsysadm_seunshare.htmlsysadm_ssh_agent.htmlsysadm_su.htmlsysadm_sudo.htmlsyslogd.htmlsysstat.htmlsystem_cronjob.htmlsystem_dbusd.htmlsystem_mail.htmlsystem_munin_plugin.htmlsystemd_bootchart.htmlsystemd_hostnamed.htmlsystemd_hwdb.htmlsystemd_initctl.htmlsystemd_localed.htmlsystemd_logger.htmlsystemd_logind.htmlsystemd_machined.htmlsystemd_networkd.htmlsystemd_notify.htmlsystemd_passwd_agent.htmlsystemd_resolved.htmlsystemd_sysctl.htmlsystemd_timedated.htmlsystemd_tmpfiles.htmltangd.htmltargetd.htmltcpd.htmltcsd.htmltelepathy_gabble.htmltelepathy_idle.htmltelepathy_logger.htmltelepathy_mission_control.htmltelepathy_msn.htmltelepathy_salut.htmltelepathy_sofiasip.htmltelepathy_stream_engine.htmltelepathy_sunshine.htmltelnetd.htmltftpd.htmltgtd.htmlthin.htmlthin_aeolus_configserver.htmlthumb.htmltimemaster.htmltlp.htmltmpreaper.htmltomcat.htmltor.htmltraceroute.htmltuned.htmltvtime.htmludev.htmlulogd.htmluml.htmluml_switch.htmlunconfined.htmlunconfined_cronjob.htmlunconfined_dbusd.htmlunconfined_mount.htmlunconfined_munin_plugin.htmlunconfined_sendmail.htmlunconfined_service.htmlupdate_modules.htmlupdfstab.htmlupdpwd.htmlusbmodules.htmlusbmuxd.htmluser.htmluser_dbusd.htmluser_gkeyringd.htmluser_mail.htmluser_screen.htmluser_seunshare.htmluser_ssh_agent.htmluser_wine.htmluseradd.htmlusernetctl.htmlutempter.htmluucpd.htmluuidd.htmluux.htmlvarnishd.htmlvarnishlog.htmlvdagent.htmlvhostmd.htmlvirsh.htmlvirsh_ssh.htmlvirt_bridgehelper.htmlvirt_qemu_ga.htmlvirt_qemu_ga_unconfined.htmlvirt_qmf.htmlvirtd.htmlvirtd_lxc.htmlvirtlogd.htmlvlock.htmlvmtools.htmlvmtools_helper.htmlvmtools_unconfined.htmlvmware.htmlvmware_host.htmlvnstat.htmlvnstatd.htmlvpnc.htmlw3c_validator_script.htmlwatchdog.htmlwatchdog_unconfined.htmlwdmd.htmlwebadm.htmlwebalizer.htmlwebalizer_script.htmlwinbind.htmlwinbind_helper.htmlwine.htmlwireshark.htmlwpa_cli.htmlxauth.htmlxdm.htmlxdm_unconfined.htmlxenconsoled.htmlxend.htmlxenstored.htmlxguest.htmlxguest_dbusd.htmlxguest_gkeyringd.htmlxserver.htmlypbind.htmlyppasswdd.htmlypserv.htmlypxfr.htmlzabbix.htmlzabbix_agent.htmlzabbix_script.htmlzarafa_deliver.htmlzarafa_gateway.htmlzarafa_ical.htmlzarafa_indexer.htmlzarafa_monitor.htmlzarafa_server.htmlzarafa_spooler.htmlzebra.htmlzoneminder.htmlzoneminder_script.htmlzos_remote.htmlincludeMakefileadminadmin.xmlbootloader.ifconsoletype.ifdmesg.ifnetutils.ifsu.ifsudo.ifusermanage.ifappsapps.xmlseunshare.ifbuild.confcontribcontrib.xmlabrt.ifaccountsd.ifacct.ifada.ifafs.ifaiccu.ifaide.ifaisexec.ifajaxterm.ifalsa.ifamanda.ifamavis.ifamtu.ifanaconda.ifantivirus.ifapache.ifapcupsd.ifapm.ifapt.ifarpwatch.ifasterisk.ifauthbind.ifauthconfig.ifautomount.ifavahi.ifawstats.ifbackup.ifbacula.ifbcfg2.ifbind.ifbird.ifbitlbee.ifblkmapd.ifblueman.ifbluetooth.ifboinc.ifbrctl.ifbrltty.ifbugzilla.ifbumblebee.ifcachefilesd.ifcalamaris.ifcallweaver.ifcanna.ifccs.ifcdrecord.ifcertmaster.ifcertmonger.ifcertwatch.ifcfengine.ifcgdcbxd.ifcgroup.ifchrome.ifchronyd.ifcinder.ifcipe.ifclamav.ifclockspeed.ifclogd.ifcloudform.ifcmirrord.ifcobbler.ifcockpit.ifcollectd.ifcolord.ifcomsat.ifcondor.ifconman.ifconsolekit.ifcontainer.ifcorosync.ifcouchdb.ifcourier.ifcpucontrol.ifcpufreqselector.ifcpuplug.ifcron.ifctdb.ifcups.ifcvs.ifcyphesis.ifcyrus.ifdaemontools.ifdante.ifdbadm.ifdbskk.ifdbus.ifdcc.ifddclient.ifddcprobe.ifdenyhosts.ifdevicekit.ifdhcp.ifdictd.ifdirmngr.ifdirsrv-admin.ifdirsrv.ifdistcc.ifdjbdns.ifdkim.ifdmidecode.ifdnsmasq.ifdnssec.ifdnssectrigger.ifdovecot.ifdpkg.ifdrbd.ifdspam.ifentropyd.ifetcd.ifevolution.ifexim.iffail2ban.iffcoe.iffetchmail.iffinger.iffirewalld.iffirewallgui.iffirstboot.iffprintd.iffreeipmi.iffreqset.ifftp.ifgames.ifganesha.ifgatekeeper.ifgdomap.ifgear.ifgeoclue.ifgift.ifgit.ifgitosis.ifglance.ifglusterd.ifgnome.ifgnomeclock.ifgpg.ifgpm.ifgpsd.ifgssproxy.ifguest.ifhadoop.ifhal.ifhddtemp.ifhostapd.ifhowl.ifhsqldb.ifhwloc.ifhypervkvp.ifi18n_input.ificecast.ififplugd.ifimaze.ifinetd.ifinn.ifiodine.ifiotop.ifipa.ifipmievd.ifirc.ifircd.ifirqbalance.ifiscsi.ifisns.ifjabber.ifjava.ifjetty.ifjockey.ifjournalctl.ifkde.ifkdump.ifkdumpgui.ifkeepalived.ifkerberos.ifkerneloops.ifkeyboardd.ifkeystone.ifkismet.ifkmscon.ifksmtuned.ifktalk.ifkudzu.ifl2tp.ifldap.iflightsquid.iflikewise.iflinuxptp.iflircd.iflivecd.iflldpad.ifloadkeys.iflockdev.iflogrotate.iflogwatch.iflpd.iflsm.iflttng-tools.ifmailman.ifmailscanner.ifman2html.ifmandb.ifmcelog.ifmcollective.ifmediawiki.ifmemcached.ifmilter.ifminidlna.ifminissdpd.ifmip6d.ifmirrormanager.ifmock.ifmodemmanager.ifmojomojo.ifmon_statd.ifmongodb.ifmono.ifmonop.ifmotion.ifmozilla.ifmpd.ifmplayer.ifmrtg.ifmta.ifmunin.ifmysql.ifmythtv.ifnaemon.ifnagios.ifnamespace.ifncftool.ifnessus.ifnetworkmanager.ifninfod.ifnis.ifnova.ifnscd.ifnsd.ifnslcd.ifnsplugin.ifntop.ifntp.ifnumad.ifnut.ifnx.ifoav.ifobex.ifoddjob.ifoident.ifopenca.ifopenct.ifopendnssec.ifopenhpi.ifopenhpid.ifopenshift-origin.ifopenshift.ifopensm.ifopenvpn.ifopenvswitch.ifopenwsman.iforacleasm.ifosad.ifpacemaker.ifpads.ifpassenger.ifpcmcia.ifpcp.ifpcscd.ifpegasus.ifperdition.ifpesign.ifpingd.ifpiranha.ifpkcs.ifpki.ifplymouthd.ifpodsleuth.ifpolicykit.ifpolipo.ifportage.ifportmap.ifportreserve.ifportslave.ifpostfix.ifpostfixpolicyd.ifpostgrey.ifppp.ifprelink.ifprelude.ifprivoxy.ifprocmail.ifprosody.ifpsad.ifptchown.ifpublicfile.ifpulseaudio.ifpuppet.ifpwauth.ifpxe.ifpyzor.ifqemu.ifqmail.ifqpid.ifquantum.ifquota.ifrabbitmq.ifradius.ifradvd.ifraid.ifrasdaemon.ifrazor.ifrdisc.ifreadahead.ifrealmd.ifredis.ifremotelogin.ifresmgr.ifrgmanager.ifrhcs.ifrhev.ifrhgb.ifrhnsd.ifrhsmcertd.ifricci.ifrkhunter.ifrlogin.ifrngd.ifrolekit.ifroundup.ifrpc.ifrpcbind.ifrpm.ifrshd.ifrssh.ifrsync.ifrtas.ifrtkit.ifrwho.ifsamba.ifsambagui.ifsamhain.ifsandbox.ifsandboxX.ifsanlock.ifsasl.ifsbd.ifsblim.ifscreen.ifsectoolm.ifsendmail.ifsensord.ifsetroubleshoot.ifsge.ifshorewall.ifshutdown.ifslocate.ifslpd.ifslrnpull.ifsmartmon.ifsmokeping.ifsmoltclient.ifsmsd.ifsmstools.ifsnapper.ifsnmp.ifsnort.ifsosreport.ifsoundserver.ifspamassassin.ifspeech-dispatcher.ifspeedtouch.ifsquid.ifsssd.ifstapserver.ifstunnel.ifsvnserve.ifswift.ifswift_alias.ifsxid.ifsysstat.iftangd.iftargetd.iftcpd.iftcsd.iftelepathy.iftelnet.iftftp.iftgtd.ifthin.ifthumb.ifthunderbird.iftimidity.iftlp.iftmpreaper.iftomcat.iftor.iftransproxy.iftripwire.iftuned.iftvtime.iftzdata.ifucspitcp.ifulogd.ifuml.ifupdfstab.ifuptime.ifusbmodules.ifusbmuxd.ifuserhelper.ifusernetctl.ifuucp.ifuuidd.ifuwimap.ifvarnishd.ifvbetool.ifvdagent.ifvhostmd.ifvirt.ifvlock.ifvmtools.ifvmware.ifvnstatd.ifvpn.ifw3c.ifwatchdog.ifwdmd.ifwebadm.ifwebalizer.ifwine.ifwireshark.ifwm.ifxen.ifxfs.ifxguest.ifxprint.ifxscreensaver.ifyam.ifzabbix.ifzarafa.ifzebra.ifzoneminder.ifzosremote.ifglobal_booleans.xmlglobal_tunables.xmlkernelkernel.xmlcorecommands.ifcorenetwork.ifdevices.ifdomain.iffiles.iffilesystem.ifkernel.ifmcs.ifmls.ifselinux.ifstorage.ifterminal.ifubac.ifunlabelednet.ifrolesroles.xmlauditadm.iflogadm.ifsecadm.ifstaff.ifsysadm.ifsysadm_secadm.ifunconfineduser.ifunprivuser.ifservicesservices.xmlpostgresql.ifssh.ifxserver.ifsupportall_perms.sptdivert.m4file_patterns.sptipc_patterns.sptloadable_module.sptmisc_macros.sptmisc_patterns.sptmls_mcs_macros.sptobj_perm_sets.sptpolicy.dtdsegenxml.pysegenxml.pycsegenxml.pyoundivert.m4systemsystem.xmlapplication.ifauthlogin.ifclock.iffstools.ifgetty.ifhostname.ifhotplug.ifinit.ifipsec.ifiptables.iflibraries.iflocallogin.iflogging.iflvm.ifmiscfiles.ifmodutils.ifmount.ifnetlabel.ifselinuxutil.ifsetrans.ifsysnetwork.ifsystemd.ifudev.ifunconfined.ifuserdomain.ifpolicy.dtdpolicy.xmlinterface_info/usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/html//usr/share/selinux/devel/include//usr/share/selinux/devel/include/admin//usr/share/selinux/devel/include/apps//usr/share/selinux/devel/include/contrib//usr/share/selinux/devel/include/kernel//usr/share/selinux/devel/include/roles//usr/share/selinux/devel/include/services//usr/share/selinux/devel/include/support//usr/share/selinux/devel/include/system//var/lib/sepolgen/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2noarch-redhat-linux-gnu  directoryASCII textSE Linux policy interface sourceSE Linux policy module sourceHTML document, ASCII textmakefile script, ASCII textC++ source, ASCII textASCII text, with very long linesASCII text, with no line terminatorsPython script, ASCII text executablepython 2.7 byte-compiledXML 1.0 document, ASCII textcannot open (No such file or directory)?p7zXZ !#,of] b2u jӫ`(h1B6eW2T(pGf .Asfwtr# 4*<AE*{NsA! ){pCH"L\ߠ@ΕG% 2/m H7qUƆݎԞvE7닣s*%ܶ!ɞt;My*Pe1sBV*4WH8 6g񺛌W򇳑;嚠]Rh)F3FTz07DڃNPjFl;6Ūjly 'Z>\#{pykT|d (^RQɦVttUg/f~ asdz-^\>i2,]dRO&-7MOFCUE;!D㊾\o".HTtέӚ>DYYb1"̓,%:g+ ͝,#ݕ )"SE?M Wڛ񐶅 \iR}W=0Xbz?ҫC 5 őt$ReY'ޑ*}>bzß[@c O}p`@'{EfoJI sDs4V5Ӹ'{6s P5'lJRoWL %c8%Q2_abV*Y9%cd%q2ŕtK{me>n#-IݛP/x:,O L{lF3uDd(k5)y봥t-iQty7B_YR>@)LNOu"!Eu )]:c-^&Q *I&<=z$ņ/?DѽNeW$p.V:}2Rc I{:;D <1%(w&2ycTn`,st Og{<'Sx3gڏn[SS&Z:Q2_rb^Jn\U;{CF1e0-ގ_}MTm:c0(XVv>I\<``e5J/nɤ_46{cN'OK.LB9Owz%>k.Ij:DﲥM^O@ƥMr&JC2槑#^KjS΃~}ܑ*.͢덷ˋ@xC $kaigk,,55s]r*-W%*%.!F6>hͲSoox=AFy쮚Y@G"9PK/ĽH"mtub@,\V" _SjN9{>f@Pl>&OJKFCO߻v؋[걡fmDO>h:YY.+κ'`158>1gx&`|clQƥ:Dh`6tEM"1X{FO6Cb=LРMN:U|+Tc NOOŠ'WSa8aL5.izL`'4g Ǽp{GU݃oe`kI1o2ӈWZF7)1.,Tc H-w/ !cf^>J4~a ,_ҠK0qFz05D#=U"rrh(2 `R#B i Lgy}qx~>e[ GHφ"_ߖsu|ē.OHsJgq[`l'l=un.g e '[Q1If5V9#<6rK\̱Rv68ۈiyL:8ϯmk\&*Ilٞcy^9d+Zs͢f[ǿ{Qwܺ=Cg L|R=:mm-fG鷡e2wی@ּ\Hv!|~B7VЫ88zA("V]<¾8/ۀVaG+bI:WL; 4&Mb-j[M|4M NNI)PЭp;WS@"MsE%v%{Ͳ/J\ax8܌}JatTt>u^VK7^TjIئOQ%'s9XuHԻ&c<'CxtZ5(/ռT$l #iFˢ ǺCg]aleX1tsFgpIFo])x܏ )h~/fmګuyGZ]= M fFsyGu2s.fg(PHp(2umP X :])TB,"ǿk,p4Vvb\n::^qN^90GդpP?C[4K -)1g;],zdܢS#Y_`=8$ 9o?<7 .ïGHk".M[02lţ&6@fwtd`Iv1N{+y)NV.DhJxig:!j7Xv) '`3x е$]ޕi%keџh, >T"ÿ4 BS}ˁPx-5_: &w-JҔ]2$?[ԆXJU& #B, > tA7@:3f@JNhXGG呰dT)`~pPF_vZ_a`2޷e 96{t]twݓ<4aslπc2?AxBtHYhU+iPcfmE`O&ko 90k$^Аw)9tQVmjZA|rGp6ÆWDpWQ⏁VIrwM Q2C"&zΣ NN:/GBOjΘ9I*~{B5@wt {${+ʴ,OpU>} E3\9$51Bc/vP0d뙟fVw{X⁞ڻ4ms ^pa~qa6P/DV Ӛӕ@7|!Dی$ z8ɥkԖi):^k+uWfo8m騒ᏊC=[9ŇjԊK@SN]񓹊ΕI46)0mfT2Csq0vu5ǤE%XGH=֢oCXR){.."+3kv%YK jt–HA8twT7g5Dj΀!TfMqF=3HIa L٬T"q4n8f;hWѢ^fQ,iVjbNAw]*ۣ'G<Ѻ"/K#nLүp8K!衆G<ҷq%YZtdJgV9ztM40 Uc^vɸhw:2z>K,c hsJ<_˞q'cv-೷QF/3q`3^Y/@lqKCv\#~rܶ3Wr*wǖ.kK}-|6Ŭw fRAT^ lHop 25cQ6A܊zV;7 H| ;c1E0ݾ<^Fݤ0HȢΐ:011Sʞ8 տB uH~h 0yp]nf=2d}}3| ٢SVxk9lFO}UP}nE8NLCP5+8Q6sj W9\⅌\pOlvB2:,hrep=>QM~ / $B>ra}Ƹejxfd3el H]7kRuտz|2uB{&L(;+:~}zuRC ΁xL)'WTUDE|n=+]Y?[&_?xOޏRdJ~̳O¹hrV=2dCxOqtR pM =e:'` l;07?"}v=$C qm["p1UPpf#OX&h THے? tk&!/B[v8'L2L6lnH[ *>+eͿN<&k.I #/:.ID1[et7xB/*斏4>Œ2YQMypρ{،>/ և(aphC_65k.2"^mDm{p,8'/ 9&brQ '`v`@b͎>EV3-kWO23f=d@Uψ&oX4hXT,"i{E!lkū]0"Xaiԟ(?pP2uW&!XT%AgN37BIXERϙ'li(Ë-xmrw˳ӸX$/1o2a}G<+/CxWëfYzi zl+$q XTg#,"X f{eyLG.Ѻ9d!u::ęH ;r2_ii ]$/@Oqy9'U1 X+2]ˢ1ehhk[vQy5z%t/3kՊp9ud6cZ&bkM3Rw~:Zor9O|q7!]LI$nxz:AA\Wx}6sȌ!tv\2$$|[Z),Ke ]n٤_)Ӎ!&5s14'LJ$dBhHR6>iF~Ȑ.$qu0c&=tt*:$s/P_I+C,Ǜi`+묬3o-ST֦EL34KZT_-g9)1B$|QL̟d@5FKndZԷ^z¨DNy* twa m6}S^Q-7;K6 guZHrׇPꞅ3Aq2d36s`Td)<ˆ$</>z\IRl: lV!N1(o͵mNK҉B?~'6 1!G!gH X&+F>r({3yn[kP'2 C!ǵDgvUMƗHqFHdEMkBü rhk!oƝ)A?+ 8̧([X*Oч~k/|f 몀[‚8V}4/| q[>¸\Q #۫p;1 Qt0 mc6ƾIK`\~؇ih|`Wg:1qvO$y"hS1 o51ǦRЊK<^)!lwS94UgDTͷwз%J s*unB[͸]^Uwp֏HϮCD9 j!,bM(ZB324g:t΢10wnZޫ䂐.9ȿYS-PՐ|]BI{A ~V %aMf'{I͔d,І/ATRڃeFo0Q`8I&^cH%fTv8%lZ@zI3mooBA;C]4f6P$K<`^5`wxϟX軷s")CKG/|nA kmjȄ7sФ~{lw917= 4jBᣃnr%b5pRuX*ҥof|5!c@P\~"uhto:7{LA(nwCeMrxael n:ZBr Z;|ʆC$^SGX1ܹY0~r?VIh2(% ky,9CP)~nTc*a F`)p5QM'oP~^4!J9/!7BYKd\9Jք4.#7´&2 1l{@~CA[VA۽X5ix rPxnK6znˢ. yEdYg+LM=Ԯ:9ޓY r➤&psY;#nS/ }7X+ӊo]{6֡B^w4WR'$cͱ4>؆t 6I!l*`8)wec45 +*fK jHn\`3HBZo_?;цfFÙ t?dtK!". R#y%t?>2L{Â?OѸ)B cԎt H]5!u1d^ufJʐLJV1SAOg2ANghL%K˖KuɒVcSAs3r¤w8gaMѓi:ϊKa.ɸ_{b[r)e,A3`^Ӕa9@7&@C .iq+'(#~ئJu{G`J@8bSʢh״;[؜{0N}eUqv_0Y|˂ ^Vh cCF9 ;L~&\ӱتhYjpGĩ)]*?YkZ ТhCkTAbկ!$qjWXr r|zhHX9}˓"W!+Mxoo8דޅǨ֭#;@pa$'6&Y|!Km&nSE^.ڔKq^"1tg^!#E>mV원dơq{y19ܐՇ1F$h^ϖ'9 ;5{`{\mbŠQ-DPG/kȺݨawKU b.jG!2HlJqt +V笄EbU 36u1 ?͘w_v%lϨ%x9*VgMS+Iw$V1A:Y۫g 5->U?tC #%qr^ %NVDb,mPףf"fE+:ҴčW<&^}*E%Fz/<ۻ[S[X}+ODp}ԩT_ޡQO:5F VNUPnp@[u%Lpi/e#Z~XӘ/u# cd;od8ʚ/pNV!0s9>ۜ^IMA@&_'J%ǟ#C[" z%f˅ $5/ c+#Eb!TSVLOT JÖn9=y D\MJf$+Rg=IMLy$KyJ/4F_ X>%k1#d48|C샦ZT_H&a_~CIne+$dcb) W=1ESm%N;a1>}JpW:}sg suZjzχg˓ p([}$xf+ZG-&zK~j#]4䆀Ͳ2 Q#c." ()eL7^۬ WWy5Yy?qBxN٩v>?u]>70 |nw)!+=Ο;{΂aw}%cGB0m5d2Jr] iҾF;B%O)Juk~L'ֽo/u0t`7^L u)ڟ̓6Ĉ1qVub#>@QG,[C 6͠8Ӭ7Q  S[@= Wr`w[oK&e|N 4*x\vCwrIama#!,w[yHj"ŋъ򐊴)؆%}01^F玟V%@Pww4Mb3{/%s\ߤ~BJM<(';8@zN愯*VK3E&FNףo'}hI:}(etl%,aȘaulfQxD:|a8iȋ)glۈ,>x/ jol@wwbds+ -j4rͿ]'ҘXҥc3 {EzR\d1*Y˖AA2ġA onUɄMl.`R ON@g(g[A>ڮb|ii-[^0K΁. P=7bCM)Au-z^0pppQ`"uAHr4(\/Il>֮peɗxn_VFNK]Dž<]dA XK}oXRD\/wؼϞQ$lwW*s)CA2ާٗ$vjWh1>u@Ѹж9zxo)!JwZl9DH{ȹ0% f)V2ԿE3R.iW6-LϯRSZq gHPWǽ%& .Lil+$V<)YbJ0BFRG(m0ydfӣ*<0SkC:突'(V~zJo7D>PIh5вϮ0XЩ!{~͛b.ǖ<&>&[ {82ρR*%xʾtu'%%QmNYK'Z;uҬR%'ڋ!i<{&ҥ 00qD#ƫ ?Kp<)s t(-D]ed6+TybKƜ!ƺ{?XX|7 Kk<)Q 3Rj?;w@'VǞHOWol54&vx|/h0ⅲ4&x[$6_ Xn1 { N\3@*XKk+6lnP'A1"?;q*B9R9ʓϡ .9]0^Ͳ mX|c1))aj@hcADR7ExCGfENq|K$9X@`Ȟ5Up ˤ6|O JrPWzޗn_]ECUr/̓z ?~)e@4hƐ[*a0+Ϲ;NM$N=1U@7@X-~܁uoyhfNM|RdC/5CfUFuY,6#uYdb JpA ;3@pbC;m{aF1Þ}?Sc o-gSN!d~:z3Y)vOt!rv1"(VDTo響,ˣޑNu>PY Xcڇ(A:4ڢ>[)d9ՌGO8A~..>PH?{ҘYz| %~z9VPb:[@O޼ףԮ>JHDX~#<U-Yr7ӄr/hȃLه4!Ap}~K-W#,~x |iiDUN-S i('F.a$ &(kdp Ns>lŢbl7 gΠ$DιGT͗+_ ǵXbȽޔ 5E;N$ \Iv_aϩGE2ᕓIJ~,m'+79mtn1}<^#00vzh1AԠ'AȚsTYwthMk)%pA%۴"%r6Tx !ȥ΃<~ Qh4LdY2<)J>)8>Q~Ͷh&ٲv l9+ ,EՙK>h6糷uQ:Z$Cc =SFmM >*zЫ [$CZPYj`WLߣ1<~:#tm?oV?._F03zA\ޥ2D5j*1n%\=P "AS =; {wO+kDkw\T\ Ty1b뉶CM%ɿ26wRYKunB"鞓a&m!Aúaio,@NC`nMhCf4gЦ t 0gӊۯr1%W$Ex!x /+adYtէ.gy;@pqh9B^CЛIю|nDStLk*/2Cv[zo A3)O!rӊoƮf39luQOtv:.y#Pv^ׇ $c!|Qx8gA7Uh(M4 cpf ɡJg.bT)>}}U#{ԾOC[WiAH€ma$yO`bn[Jj#$a+)EԎ6 ACZI .#N<&<"M&`k2 E㻂Y`!+2H\g썄NvAl3Crj C9cVZXXB}{%ISk .i[vIT_4B|A6$-R+:$bTpi_# QQo4=r1Rr0o鋠ґ !@b+{;0Vؚa,?7J>&6OjE隢+j@Ũ(ͱ+B[M tlΌt'<;-eְېBx?LMCGG\X<<|4s}qN\ORbyl}IyׇhhBSSw;>lt0H՝lTZ~VkD>+-g>GJJfN0od|*qb`y.ފ>Mn,HxHĶp kӶsPC2wjʢE B/ _OK ϫ]_r :Iʭbݬ,S#<ZIrx 4=fH ǤFTnOMd[I†ͶMd|=vP lM?i D&WL1^`mBLA[Ww,(U@D7f|Nwm Z⣒k _JK!ٰc ̙}BmCUYфA()s0] q.T+5+L)+\#] )ny\Gq^v-FP+̅ _C4mD~o@ಊ\ *Su"U%-4PT1L hY)O|:}i+Z|lrcjbh1wGT%ތQ!'fHwUgגe3ti3M^iH3l<5,vr hOy[ RJ \ [2En nŦ e`JZA+Y2S rTmzc )[0ۚXTLi^Pޒ`7czIJkkϤ15]YiF,.-R&4if%p 31S3P( hoDǒ5 ܥ >1BJv>QiǼf:UP&+{xkw;_wyYIvuԤ2h;A&c | c?l (ID'gR:~ɁbvZ\:1(t5FM>^;%N۳B{ g;tԟռeQM?;]_Ә&>oLs<߸#^݂z&2tL?)͠Xv7E +@Vl ]tŜ KbBhANP?H0ݏ<l_O(cˡ7q& 0X1246Qi0{9r;hC->RͱwX@>{xC;){`QേP?bz8(A Qu8neq)Z>;k6B|iiCvB H/p> BЗE@ 4@'{AzєvL`JDB@Ú80k?{I>,LJby0 s+6hP|9K \UxSce^ڿEĔLx׵i_ []s_Zg\F7 1NF *J%?fj/:VdjD Riv m4--q5Vc`b!m`OXZVg;"tm:$6 P[#KC~7%E'؍֓S",S>xLL{u-=N/#ɡlI҃ 4Ol|A+SE'5֬[ڹ53dٷPj qr=V>dhH RShv7,~E$qZL'.(ޮ(׈̓񺭨?дdɺWCdz קݴ؁Cg!1X0'Ku‘JtifF` ôF(u_>es`m.sY͋<kI3݈+D7V\ (7lD`X'޿?˩ ImGahDs>/px]Y+6YIy*q«L"]K}#]yWjo4Cjb9b':D֝M 7m/Yz!*9<{aEkVmRK &= ؊>`sEA}vPڹic_Y0V!%Wܒ~`k3YApW΄G> 6+ƹE% re h/ _Cg'NP\Y,U3laHp7ؠʨt캣w;;dfkF4pjE-kd7I]W"fpbHhrgm/5S@8nhmtL_HEP(Mz%:Z1b($6ojvuxiJO7*t:J 2XCOmZE32q{>jF[NFu}ggU*͝^p="Z굛c ۬,C?3!{] hVJ_鱹e?U2`8-J@QBGAՔ0-DIC)9:MulDgn֛&> Y]4I'D81ݰVeYOQY+U#B="4=&^7ĉt|=`g fF@l<RYlA|QtOh@ڧ"qakxν9/,$n~ޕ7erE.e<*Z=ssx}3Ĝ.2\$@{OFp1VdRN.Ĭi+r\(?G:_]&i%rY|$Ӝ,T S9hRAAjb{ ˎɼB1@.A5a,-}XQ>G8k"ƂyIW# M ^b:#ZY =D(&d2b@arMs&/?YK"FɧE#^ Kgc 5K@rxg-'uER=SM-cM^X%0&.lvٕkPN-PԞ"o/G?ROuVN_]B[dYZxaOXl=Ot4KP5 jL7#x'fF{5rL 0CmnZG4 J=_z}ج)9i ܊VZIr Jekl؛ ę& h6ɸOojHPbCx<\gdf^ϋ> OԬy=4CXQy[ϣL x*2s봃j&z+63 1%4fO'-Y<$L]w m$l՞^Ca;~*#,%9ekcQbZPVŕPctlFr؍[V۷~yҽ.cBBr QR/̯'Aᗈ#a[Ӫ+Buȋ&?)l ? H-B+D6:ĴMس=&e^Eo OEeoOƧsߍ>,Ȭfl9!;@ $'ɥ s# M]Z?K ]4KPj_ $DҔ;@`װ3I+6]Պ`M^cx ;4ǠOi:Ԩ 3P…j]ַ2R]CՕ 줓5P1[QIfzs$+7Io*[Gl_uWԟSW^CY.?wJ5I25oT? @qiĬ|sV`)ȴ&7 k:r2>T;x,iJ ^*lYID}"ԗVp[dGE3J~A;HIW@b2AvD9E+/10%g:5 _%s>`aAaWJk;!2YJEE-+PGfQ,^9`+v0 rywdBaIVnFnGmz8vv73-u)SKJ<8@*~㳄4/H=mԐ zrM My=I9t4$A3·kuOG#- =4ÊZ2+Jĉ=$z$su2#*%ȴbDٯxL4(?4Ӓ!ٿIb2 xv71l'ߙ[.2O1ʤ4 }6e鏹*F3VfsQ#]W9ϟKInDmAC. C<#loqqqM;F3hA [w p=ݭ^cA4T%[w}9O$>p#om#[,^XӶlxJ l(S\ǼVd{Lts%/*6mV?JL[xǚY$oy$Y`C~[ON/}ˡQ%v,n `0s,\yŮX\9']C|9|٥tE 2\\C®50^Ĝq=Sܽ3 y9 [ g L5)y44@| eK: B}AM!fG7SbDDE[k9\ {k*2f.݋BhLe 9RXͷɕAIwWWSl" D tlW:M^|Pm8OK҅s{fe6Yp`zcQaTi/UՁػJU@ձTkb5ri~Mg]\fa"L.t(m7^}4zbJ~BTQȘV0A`e9gŏ4'eX?~t5ƭЂu ̔Qrg$i_ANuQ*C0D901Hgh/! S #갺"m-"K^tQ<ˆ\XQx@Q%/53q]h>L?77dAV2Ǯ(eGj)ԃG+H )]^fpu><.랪\NntZ /(DVC%JD;&/q3=/fi㹡5dˎATN +H`<J&i1}[  0q92*R5w=2xшmg )Lj2Ɇ@9YTzBdEإ S^ yJ5њU8*eAN :j~S==dTRty7@L՗O.,z{_@ ۄHjվH~W&nҗ勊~#[<({8UqYH^<|'5 (qTA{~"@#ϖ QTgS_<1ܼ_s+NhH <߇;=D$6#K^ج#sw;1Xw䝵9W&<(kZfS x`+Z@r?] 1I9tsZ0eF!J#d0_ l¶$+Jd/]M-HƢ|_l tc^o@{2`LQ`ↂ'Rtʋ~^`C&v@%BzqԹrl 0S!|ܰR86n{%u:7Kw;8x426yi"bL̞v! :L҇pJoʻ`'o.~ %\nj( }qQԩMטǛ⩔:Y6{oY!|,J䊊qU;Vf537@a,AE@]g[, '^Y X2FHy+0=e ; K-,rFᐰ`,Y0A7Li48/ZY]\}jG|ʱWmDFɐk3xJRrb2)V5=Stܴ:-z,Kyn?Y)>.s{_#CmKE1"eE]z\"`xs(UG sJv~}DE-*8捭92q*bѲ٢w +@ \JtfKO^Yic>uϕ턛!6GXxP9E \E2C,Yx~r;m3|{ 琜P=SzRߴқ@&=Uy qYHM9P{v^<_J=4~Dd˿Gd?VM (۬(岟TݼHSb(>sf|C6-r#ѿ~2F.AGY| dHFlvHFcHcЕx[<s23ƯY{*.&&YQ_9*ۊoyjrٳ6tIs}euM]/u,OrfQUhPtӻDO{%a][pٞaUR+:{?Hof+tS,XD2Ht'mfʼbՖ6`c\'q &T9$B!-*>jESOM?-G!Zg\u`nԏضӊ.0LmkQwɮZ^tzU}[ojː/4YF7 r[R/YKO됿˕oQAGG3SZ:,'L$'KX5!& Naw8EJ]{ED;IcMq9PYR>z0/5ʳ\v|`j&OzeQ݄n#رI(_"JŘi05ĻW^y嬓=d_0’8Pѕ:_cNזr+å"1-v"ڎ6Ks?if;BiWfYCuKW"z[(Q!$EPͥ%ܤ*r ŦaMM!"GқEK[6tP@l(| V4u;A. $0[h3Z_՚>i')Na7.-~/2OCsw?cH;lM !P qX4b $pg]X1윑)>Lp ӟ!&S0 "-vꘟO]ri_% f"r(rDFfori_2Sq:xfL#DXwJ]I/ Rbcmܼa?ڜRJۜ'mLD^F>d8u֮Glź -b74"i">6>]Kuf~!v{^;IjR8,3y:Jhd0iNx6KJ Uż/<VS:sǩsFOOXK4gnaD➢C=7_I=65ڦ42yчiƝ#X[ph!܃w13 V;ݗHР|Fi$<>"Y@7J#X{F4 bn,8|VÊI=c ~ߘ7b]X4ܝdwc4NAe*\Z>m}Fn'ةmq^8PMdAn'9og@Mq_ ?`{E{iZ͎CfrQiKVpWU_+ Lc}$瞦(qs!IHlk/tWx,g42ZOpaLx0F86i_iQ`yjۙQIX[Baخ0QL{KC_tVO .ԜyIo5ى׎.³H|8a@T y}\Ȗ(N/TX4~ }Qȇň`ku>P(6oFeyF-ql -:e,Kc:ž?4SLe܀WRW(GN8-TͶ-AVv8U0Ru\g{Y)%lŹ J2޲KnkߩMWyHU{"Ǵ5BآT P,H,lFYO 9uR˧FJgw179쀎w/Ʈ05iq$]f_~LN'Kʒ\T]6o.{r7Q/úV#>XR(?a!Ԧ̵<;˼}u'h]/Hh0[g \Nw'[TӠ C==5n >c`62x/< 9\&v[-]~-?GƄ~Zd{BQ]1YsQ{뽒N…C%.<{\aHu/IBM&qzP꺎` }Fĝa L"r-w?H_ zvÀ04BɆ:i8=%U_&yM1=rU[BD嵐J"Pjg}"HiƾlFwn<1 \l̎^෷C}sI"ec[.ŏ]n(@UWIw?ڃ`&&7j)]+}$@ :$7F9B:Eg5xBLK,#<2kDo/vDc5w1Fw8/slyS4ûpWP9w /<)k"${tOXBe)QCy~u}0fXß ^iU>tua=D̂9g%lřns=xi Q5 :.?Kdy[~n"c m撡\$m>dX)OdHΨzpPy/ai2>$@vHUKxRbGE,N&xSB4 Gk^z=N#eyGu}hק#ܩC7^ 17Gn6zIB֐E#7ۣ"Ux$MfCPsbȟNAv/n鯃=Fbco`➢3Fx!Zi:8sӀF\qj}2Ű.-icjlC!C]!$'Un0s8Cy͆ʫP#E" j6 pT0^ RpKP5t c׻"xȬxe= g/ ]n]F8S' D(@j"+$wL]c]k&p[J 4*3CmM-؏K͟"ɯ*к,@'j1AIeܜvU%=kW['3GSAJ\4Iiy`1PEC_|}.+bv]E02=N>oˬvIj[}?r820zޖlٴ4Wda;31jҫ$>[#y)?ٗ1ް\<;$/zЕDz֭\;SM_KŃL=XgZ<ad0> CAHXg7Kql &6P#HM% 1mi~\~h񩵴01.y 믍V-fs8;潈ϛqyX!fWw0)WGXoOL\oZETAu)j l}ōW>ݙ}ݯ C_$-_ޖXY| SH5vX"uY`^Qp!7[K\>ޓf ]e˸.c8JF% 0Tg͟Nݤs.h>FIW!8r!"r 9'KJ@am-wc{YuAP\a`xBel-K&.-`9۽d&L Mi\#bc\B#&o:o!W|̔1f8#o, 8~QWBgz&#kfLL]3WQŶ;x|̀-dR1PVrޒYV.ֆqs5miBEE"\=f}g>iiL,3M?cԽV?[\znAΑh~kCxk,HpK6BI3hO(ձJz &):6N@?!.I݂gc79?>v1-xqFl\ٻ(EKǯFk'\8w@ u. OH!1&T!\̽<:4Vo~ r^bk`qȨ-HܠRĈY ?WMNO+AZ`zAΨK7D'6ybryS1R3-L4︸{$^ceZZ`ͮEˬS>u< enZD`o3l;"b-ޤamd6f';lӃӍpz _1]ƼsW@`-]rdqa@uw}B  78 ̏c. -bwPFz}BNq>K+=.8SG:]22XFAzL*Dډ#x{䏬nvlضLGOcjq_GIF_UX)!z#,ȱi*ɒ1aQ_B7pqr0?k^[hk-MjJHg:|0ifʐ2uɿq=۵HV`K(#`*ٯ$ BX~_= r~r<8 "k=\|yIyd,ҜU>lC(CȀ~raCB8住f:MbE(]~nc8bQ͞OQCskYRLĉk%c*a(u6!τD'5η~NnUruP >eĶE,#w_ʹiHiI(0 MSkZylPUsִQâ/K<ҥVg| {|?E,=|dN޸6I)+vUk*8kܨ{~lȷl9m'| eˮdяY2#%vXKM]M~٥Fsa:d#$Kf%`A:vQ5b\R'2y):m) C ]MҩY6S+!F VJ!]ln& |Xpa_@* Chph,۽F?mK2kLlû@? )ɒ %C6fE;Y&O0cn{!Elw+I8gdw=ãD;f*S"),)\Yv`5m*VwWz;i:s {݄|,"[ܰ'1lPbe&ή+R/fPMwEk 9^ vy#эUǥ*2//!ZbRXˇ+\~-J$f,#ITs__@J xJ"l| V] &S\I2;9S$ekDɅ-FBƆ[ KL#*UDP:WtƲu쯧\ ZEuD=C5ަ͒ o\F)aD &zKH֊Tpn,D' z!p$Pa#'-%&_zʜϩqry4o V`/fqTJkq oNwnb;JoCu`XwM%~&W À-cZ8bKXV w?;P-e0tF y~@ϼ6X}=(ї>T5iV%8v *rLi˥Дӝ&BBPi^MKh,'!t߰?Ik>)X?$)CQg[G>S}x~McĈj ۬med,h}㸥{H~0f A"UFO^eM"Z57a,{,l'lW@綀缻=d"^ǔ*Oe+j" pte/UN203ĉ> n buG2nnfbpqR5Xie`$,/tw7tO79j!4O1isqR 3*^=)쵲ab; <΂sDYj(d#Ҧ̘Ȋs5CZ:(M#ΒlǓ.b*KbջU  ʍUxe[^% Q=mHCxA~j}Nn* h\ڧ+_8Mwvz}!rSu[RT?HT8˹N@0FX;+Z-KlFWK&f'fvZH3i? $/5$%v{K:NmRi?wkѶHvk'3~p0Z2p/Y׃6;jQz4g}r_;ڋIAPL*.C>y&e $me9t\ !#]@St:u!y?$߲vn5ˬRl~gН/d0LSq`H~` 1W;8ɬTϷ*7f2i6Ć=_T@?,5 Qy!A S hͪ򙊲vEi(~}d=] -qoA;8uT14/!H*|yBKCTfhY* y}8OY5yt _?XLKFRƭ1! HiL[3f5lݡT24\XȡJN9c2_1cv i>G,}KSVTB*I-\(٥5 &mV0}Pa)( #ȣu0Vzh72fwB͟go!) zGT =ӟy\n[Q_r5PXǘޒ)ܵg\-$VkhO>Z!|iUHsu8{q_gvg#zELWyNȵwX9u/Υ(U@ G5pĎfR_D\bqIM8abvd^m^"g [s6 0svr/Ԝ` O #S u'R / ""@nRc1*V/!xǎ]*4z",&:J;aڸD$A24aXi)>| PFUKKq?(舂^ r?ӻ6 ]_4)! K&`׍ŷ0>Y"?/L*"f!s; F@Qy; @!Ca8;50[JsEIWAںs)l1L fUe4鴱 UXso^yeB&;^g2q.Z7đrt24nyJzfxKUn1$ :Múpmw.ilOsg<;W_PLG^ B\dӊH*4v D[7U4(.Dj|AR`ɺqi0`H=Jp0f@~ekYߖ\%=XWY a07P06Y,akg!P6~b, ݨ\y& #F AQvrAQw: \}9c=V̒]j S WYnYT:F9$iD6?EK8jV3xdy~ y[cJ\{s$!'lcW p&mƜXJF7İzX&9ˉq]#u'1 6Ʊϗ JuIe8*| Zx瓻$,IѽU((RrCzqV6ᔟ0iÐl)`jmsvx/?Syo#8S"yYTg-:w.ǭ a4C'2^BQ1JLS'EC"#^s[XITb[TW놊]h :yA4ﲙZiige߇p*3n^!wm-U*6P"%KBj.-G3sI)h6enbL⁥#Y[@!'i5Ftcz%WEA7S۴yԨm%UդdFl}y3%/sPo4n%-;6uJ" A3+A>\|"IE _]ḧ́k6^GK~:^G 7iFz=4=mgLO4 C=%p. F< ͦ|S239A:iq:Fa|Bl dck1dp|(D)2=讍\r[L[u- d}GfLa}Ɨ(q͊PM#]Ҙ4pk&%OB41PU Iʩ,P2{3Y]UiJKգz,Zq)P?椛)ܑ-YV"ʟhhϫvxm̽j{!L4Bs-GC ?r!=-V6i0߮ &!c&9_G|,\^ys?vkF56 `G?NX*2B؝,Uk&tGt;tw HW-BJ&Yfr5u,3WE1K$eD Dq(qBsHz4;yU\܊F(S-G-pжMl<|wR}hZ;;b):S摰6AζGfz4n&c|_y2I;( qST 1ReӺC-`‰6>>S x}4`.:]= *#: oD {&k>AhW}'J5ŨruJFhՓT_fI-O&Q)&h)186ߐ{fmD^>gc˱` 4qyŽEkPDE,iya^̮\ h„$hKp}@o;@`;ƯjMULةT i(?4ڄWܕ ?2-Rw7)BDٽUl񃧎߭%oYtlz\=>Go ީEuXeOwD21']k^[  V3pV=\A$j7$3U?P0IG$fTe<'0>|8ʞ!Ǭ#wKbZuVp<-hzncLx=zK!_z Od`)}sA(ic@j\v uh<\Ήf&S;*pEp/ ]궻&ndTNgcߟ~O% sC|KhRM&2V1rGhԾ7 @y/qFC6۾=Hѳ  N1Z2?/Ri ] S]݂,Mm!q1Ց_Yvq_J@tcu(6Ťo̔|bzp]\GβU㚱'i/ϠQ5#:xhr^dqMNٷiV9K'jF3}߯̏,Z (.^ۿ=)!5L7 qO;/@Oa|X9 dJAk?O`%#vi[\NQ(;ex+ +N(02J7/Nr |78 7ܐ$Fj6+o1!w3y b=^89O,9y:JFxݖ&\eݾ"g2`UgYZ^O\'O݉; Ujĥa{wJ _+ @uR<Kȹ `sfE@Lb˛ܹ̟`.ֺ] n^#nCœ!DGS;'N+@߀Ϲ8+PK>:_3̟Q@xy,d8Dߜ,F@E\s;3tuCMp.DLtS{𞽮^ūxD-BkE[BlvOI<ґBr2uk q:8(o !‰q-00)nzǕ[Ooj #<G1k.,toAq z,6p392w; = Fnǔ3F9=iH o[bzNi'Xi. 01e\i+ȓ]`+_~LG(RHԏ]̎εUin2 X(^Y匡m)8]5ɵ. `EIHYݙG;B)1f}7 eVYsPIf{\jADaD|}V|2,zp^GQuRvO"iWOhlNCAyڙ؜#E]v0q RNO}׀8 Ӽ^[̕2C긪 $U/\ɥ f^MHϏZoO suzrj>:R*d.2SB G;Jf7P0rZ _AyTҭSw.'U  =p77b|,Q`!<'?1pr~$PVE2[i4M+&BY28BHqUQzﳢALO۸ y\:zRǔ +*65Фc{3Jb76Lk|Qa\bdp/4dlŵǩ0'S:Հ\40 LӠT_KV|JGFh-aʙ rudMD;y62忈l+ns|/\8(_/F5_ײ=k *E048;2چK!`k\>- ?P8z-Ѽe{롿Xn,l EU"|/ҊD S ^VgUU&RhmQ#5gf;զj[Ut 9;%D“ΛDo?Kz$!ߩE&ұt+7;mU"T3if m/2!&wc&r*.(t%%o;a* LOnIp抻h`?1. 8)(-e[ũ!#Fr&v'q*:5n\ q0 +bcf _jebE-Iݖ_ÎbOdkƣg ۱x~XHHK:F56r=Tz0Sop?vӿW(M`mP4C3RHi=m <JAwc(}ۖ#%Sc;*|q0m\ i0 Xu݃(<+8Gp}+Jljy4_ n]¤MO`@w]?Ъ]J[VHgWӍ}NHA{iV9Oj 壸m'0fJ`D|*j;I#ѥ;@Bfbm^jn4yK,k*[㧶UBV=ǭzեY5FL:{dzZwˌ-2uT8/M_#kFBx;-)Cؿv2`7q(bJsxEu+PoH_}꧄G|q|DDL|$ .{ckH~1i>r\Bh}`|%nrS ePEHFD(1"`vSM|V>%AfZ`%-b%G!6yPzf;9aZ(pk-?:Fz_ @ "Ƣ%PlgvM h: QnR<'Qs&_uXIHGM[^Yܺ䞯>PID_05VpIR(l [WhoDDQT'bΖdx_ b/m2bL;JNsI jӾBԌpo7:yf{a:p|wSXtw+(rcolm+\[琮`"AYN@ L\2_>On 2*fo`Cu vkQqɋl ?3dъa#_nT"Pee6u{j؀$W^W8((;0=DO_z~"X̂T@gVf$M:@A7ߖO≷x>~B[I͂ɱ @N6\R!pd/HZZ02czS>QT3.UA#4BiX.$hEX\xDN3{"%c|&3d|R$i4W@v{QhTa93`k3'_(/*K&Kzs U Gz-CU)H冡M,Li뫉&?`9ilmbC}/`ĿTm V?gড^GuO6ھunC8>M*s/w/3Kf#4b*gDh 1DF\|j_{1صYi/j32D%cƺrBC{rcIlY ib=Ƙ\xQAwQW O#Td# pB}-Ex:-pMIvkO>T˗W2Sfg##Ƶg.F;",V$S#ׅ)4GcdrK/&db>Yi3鿻.ΌaxXy3Oց4o: >sPa#EU];~hR UfG9GNF`UEIBu7h_<=4r)2Epv #-__KŔ K>aʲÍ*f$uA.c$Ւw"4;w0 H׼hhof DPR>Dxo(|޽UG,%g3{ >~wKdg2Խ,A~BfQt'%CHyJ_`T*F q n+ MBKG&RO HBgՑpA}8 7\B=G LG5>+ @F$h~;3eZ 8",3.BZw&ݽ<$U F|"^^2jiV"vudOxAR&2(~^& f܅,̿̎O rRZя3= (0>8nR+ihEyy( e"oSf+z[WY|~qdnp. $Nk,r@էRM 4&x8 [םg}.^:J喀گKzQut}@a@+6+t踓  "e2b0L,XtRX<'.f4qC$y..lZERtMi;"*fSۇ㹊IGJ@S|"71tYGX~U9? QK:_qPb 4fߓ V0%djdZ> {<$*sog5/0V\bLS[XȄu?/#Η(ESNܘUeLWT0Rqöaؾ*] /бY9ٞ|buE>uԀyw}b'Z27ۣFweS\qB,H㤇v:(Mpy8Ns'c{sT:a7#+nP޿$VEֹ$6EuIXlj[Ӝ皂Cx<,j7ȑ[(WS«1C;/4` 뛇=|zqPs $kEI.t d[o_BE+H* N#Xɋgj;>VhBhoԎ*"h Y\qPȵClb;mC]X+uAZ^.1Gѓ.64FфfuvmZ  aH|*ghni*fd;BouėY`3g[ g:~'jin)ht~/ѷtMVQ&.Zc?뤗穂? 묋q Մ|N?sivXFR(Mr#궁GUGMKyg-IܵµIƒ#t" }^mDbƃgD/`U'Q)WG !GM Gމϧ҄MblDًD0J T@skd(tŐs,CaɽE:إ! uIM mK΄U6guLY™|E2X)\[%Ɗ)k (#U,ޤ.C\<1~:>ix׶a#q?#λ UQSX)uRf%[?F[c"D(G2 ֜yUZ᯸i fjzӟ(Aα{TnB^|`eDlBlݒ,UAlR/ڙB]MW9'(D2/e/:qXJpaw`QƐDj21j^?h:bQh.~LD`)CZ2o#G8yuok?6V+hI?"z(][ƞ $AL%,Ncd)M YDރ/ <㒳~B;3P3rdN"?b7zyR [߈@u/r=@hCa ;!yO)te>PhD20Ի+ϩ}RR V 2s^6 R!sS!o/Qbaz*KT.j .V{M:/Y *uذ|Q%\|/0] ylpi;wW0H+ܕ/C}c~S8OJZB&7`~ܰ)hqPK9Bj=J{X7)CG-4iiH6]b d hqc'4ۣ #ݴ=g)ftuJJχjvߨO`Elo؁_߉RVYT^Byd72 }RF2①F4K'ӭ@)x;-gp :uu5(8!u4=D#ۤ%mtLCF& ôʔa/LT8EqT@TR~~3Qع= cc>X˔6{l !5;}d8G˓ j+ ^٣5ҩ6ml*Y,T6tAo-_03$yN7aDe(m-v|Jf^zRxy2}eg1AD%XrM:%\egK;gxߣLdN\_qL$D}L\&F#|)X-Ғ3Toڔ9{f8kڃ7D믢fm{+o&*<`\ӹ^{&>UK/=0+`Icvר}iVf҆~{2;<ʭ)U_ߖC(G-P"Nq/6EhYz]qJh!΀ 9tR{< iw]z[C {]WzL6@WJ,WH e-w@\1\Hjbhh'+64/ǎcH 3èZ< E i|:t s5[?wCO\ \j$:EuT!,b%(c6bͰsZͺ/,5|MP̐[D%i>J#0$l&}nI \-Ex3/5@Szqޏ*F@*GL_F{s6̥ ?⇏ 6[xVOP_19_ MnT(*kVLؙ,'[],7Y\1!)[TE4 c cq=GpM1>t ֖'!')O 4wĝUGg(ztrY*$>J?dY^&DS谉ҮO*u2&*+-8PہBkMSD)$/աj,Qd_,I$A)-d*x է+O*-ɵV)PMK5CaxC'co62@H-y{Íz@H_@F D@dI'YC*i{#qMSb,:1EBcTL (`#Ah>a׊/~CAF`L+ JPs.\YQ3 ~u]IZ7YA\mG>R.D.1{ƀZcf zhhnfAL{HS!zP5Z`o!Od{-<,}Q!aJJʾUP|,33= Փi+ ot:cFU }p4y%*Pdh XWrؒ6(MLoV2^0 R$tx9w+zI>x4p}S4Ue'FUr! u~.4PZOOQtڌwh,lFnֱ|R{x=R̪M4aMyמ Otۙ_9dW!4P{7)p5"Xn~a! la,oFn6׳-ЋG]gQh-tKv&&vC0| YRm=3~P+Rz ju0t}yWU|X)~BJrZ9\ĺ%wDjfM|휛'{RVTv&XLGG![ъM? mh dIm-8 OK*t&3Lp("*FT] O`j)7$@>B՝ЦthwN.f2C謕MXoGUZa{=u$pB̟|t92u (ZE0_&~&8'\ޟvVtٲ7HI^^|x*Zd[Xjex4#G+pvy9 Gm(V;w%KM&>r5/3kT7V|B@K@ ^lPX} \GTA F VԴzPJ}[Exo2DEk1x@8$mrD"݊:FQo+< b \#Sp9mPӕ̥aJdIDX4gQW#,mz?csw @W EU;πVS1T͂úe#<[z9lO⻤wUyE;H scD 7w~*S {nqrX=_wYL$UIWCێ#zXėF,•piЛ,kGϰRdoYp*+5x}(3Bz)y;fK֐ƊHOjs[IVBtm eX)4S"E%N*ssz*ٶ\-Vb6rU0Q6F ?˲yY. 9(ކcVSҶm䋪BI;b\u0+t)RtEZ#)48]Fo@"ӈm Z&x9BHVQ:EɑѭsA~ и {8!i.u,yKԳR=nCw#zV&,Ct#Vȃ/{ϝVbS /_;kϞ47# 7>"< |r/LB_+ B C}7ЭSiwUrmO f9v6͒ύN{EGPtBΤXI82qQm uJ/p@`D`/ɆZP%HVD\SGXIe r\ $ k6wz<P6Uu"<3Z)HRzpNGJ[LJplzҖ猪=^忍(;Ex6%W }o>.c3uDnCҪׂ"M&zsAU-.{ymwq]$ eO;c|,=)CS3m}pRD55rɀl.4C6nx;Et/ We00Ԉ;Iu@r@`-`x1f":,ѭT;kOˠ y2ddz*2kZڛ,Sɩ6&&; ô8zsZjXXY#.{F$(\f = 2+k .CK-ꆺ-GZ+k~' vo[[W\:腡>9d|!\1bXʆl򽄔]vFB@Zq"]Y=l78+sÚxBD{NPLfƢ.ᶼPFA@OR"-WP$<$zI>䧣ѨH\Z+S!6*:,#\m>75 8:B2 {l; h +$0s~4DP@=@Fe6fR,᭜>O%4&Ū81 _hGEǼcOܯڝ YÔ"G-'H1kB_}$ -w]ɵӸ!AN^l]Dv%M -*&adTif Qp,UpEgb>Ix2bE\khiݒ@,]< ZJXd fǪoTa˧d>A4 DkQk u\U K'cxM(.ϝq\pj[A.m͛Y{zwIVW4_~'r0$0PhƏz>lH̯"w|<1y2 ($4g` };6 mg#sfOD/[;L<3soTm04z '"Q4He>dƌ/gnZR, at<%N?`O줢%ie#j kUy4* <auF 5bw'kUN][8J<ֆ$]/oJuCU=g6 K3]a V2(:fMXv=GG1s iɷMj97^hY@Ow߇mΆDK`Z)" EBg fS+IX8'3&Ulu 0I؞O\|D pwMnx/J޽`8"wS&9Uc³ TASԀG[ 0FXG[Gxh;P\%xa{cM_lj4`Al'jƇצ}DN\P5h$ӻ:f @ÖW?fRgށef6o2Z%W|ldd/]jI('p/9G(;hL46u<y5&JMN֖A:JjzW1T+iHPS rZe`(8)7lx%4paN:+B3PE u\_֏0^]kT4p[^~l84,ݛ-.B!gHFgVxq-i[h,|_g3>k4#wG6Rbv&oz', 꽗1(6 $iF<׬4t_cWC,Йe1ro,qpy`EsTVe6ev9l* o@nJ6 ⤀eyTUO}Rd=ZT鿤j vz5M+8UO8s*#՛lr!=(#N5EK m#쾅+5J.b;HLEU %`d ?nʼnHUR~[F6\DMʏŐɵVWKjʾ ̽ GSu̫g`\L vɸVsEnF 0. a !7sQf~q.Ti֔ T ᣧps=L&l *A62ck"f-DFyEX,g\)Kz23E~t@ \ @YJAi~V Wfro(S"qN^H .LE ;-" s`u張޺:d2p(7u’kKܶ@!li@ HJvI'Lyߓ}^`ZB/ߖ" w7){UB 9uzґ?{KPG.dWcY+}>z=jpxC.ɚ U k/%LogzT>R)$><kA|g88 `eF?! /r=g&M~yAk&E㓢u6>o|i@EtZAhMN:p"S]V(c^:I*oT(1xd't͚!dʘ#N[XKӦ8jWMXrM-rtv9Mē gy,F'^:v\dt6}1 .'λS=v"Fan7Z30h UAGSt""^s+^mTv~(毐SɾUj[i^kb‘hķ/=KMdo:m&W]w$ VK, (l"=pcUoQxbZw]w|Qf\żni⪅Sv|8V{k%+%qj~pk$}6 &:X=#B#o9!u'*j4qR!49m_ZbGXKfP$Y-kcCVn,NLI{c: ~ n{aS9[?:[vU<)W"/#4Lva#A 椹Xj;Kz[~ax3!HHμ:3sҷ"޿|sgY&ҩ[|`$񗄻6y~ KI?b! ?,|VݎY #6k럌cam`N[>A.SXBI#iVW<=\mfMGY(rg20|krn߫M(+ȚNGکXlC_i6Q}[u W  UHiCMBCKio% uc)H1S̬e5= ; Ѩo''UҚy͈3˿8IDw4j"t?P5i=o$tXD̶$eҩIHxQ }ߣAU'++jjyJԧV ^WOɦ^"!q׫ߌ xϡ*pq::y lm =XmimƵ?RSk!aG+L ]ŭZ(gFς2Ěү!-^*7?%V !vE[`@^lW$֭PH;\ 4$}PbYf:Z7ܤB쩣ni)Z3@̌5*ʮ}̑Lj.,esXQ |!ɴ#ƽؼgq\xm|jM`69GM9y|ק(diU"8ԛy#m;wJwum-?إ ;Qwl aWtH2îx0OTQ躷Yzٌf90yJW2/"oAEߓ.tP)!_/X8+mw;9_-[d#z7gzz魐zC/̫ d 3RdedyiPxznԖr'FŁ4aJB7{&̕D tb{:2H,9X(hsԚ%퐌.ݣ}xkffNa1;qFR idy4. iwO0k e.3<ٽ+( TL fCT}5}XZ)(?&f$0AaU&d,Sme,}ݾ{puj;]``/s0OJ #-)0+T{8{FFJu~|XvwcP=j)I:< Vm>PH~7uU|埯so$6Kxe#-o;盃vơďI];њN̻hKu4~oҝs:ȯ~Ȑ6GY)䁿{x?B!J&.^o74?)шPmv̤4mn!±8GVu9ƿ3LJg1]cL U RN|U}W+L{MtGrN#YFTWh1h\jiwi~_r9gJ>f*MgQ9,EyyJr{у1$Dh}|l="Ó-N<yQJMAڶxp.f$a2|M.t/sۍSlk  ;j]u}%3q9 [B*GZЎ+^)4/S$w{Gm|v,mxu-ϳ R.)YtC@kLR]/ujع@즈圏* NL4@)n퀕_ch?%mˊ,>%#i)2w( j'aulx5Jp a][$˲H2T')S+F]jߒ%e!oW2ЃEfrv{YK̃ݐ3z_JF;&cnHʔl»w+S(๣jAvKأG0x9Fvqۓ6W6f Cv.0(ARt3~PB$(PkH5ڳ\e=1Q119=ؽhLp)>5ַ'B`gA gOwSoʸ&xYAx#q#дkTPCC)tA?|" &:FnmSz:7m;:A} *X6}*Qls>jβ^bzT+0RԴߍsHX1گj? FG[޺红W$|¾'jݙ`zSDx!hT:58ĉAz1R*vr˚䙮߁2v?&ej?);[/Bˣ 1S.b̖@ xMmU]b)F@/}',6J R>H$Ƞ,=G}&0o|'&y80gU8YQ_a,18I0$s,K,g='Eo-FЇ8HF|WsM|T{:tΘ\p}i5\1'î8w\O;O I\:48h hc3-rm?В֐l:-Nccd99{(w$*=LIg(" ai4luڑaw69|:@xq/3PF .d:ש# 2nbi$&o%媭rH/a`n[y{ttAzzb9x iD[;?;&u7%6|ɭbtز+EӐY_[lysZڞfk+XHC\=8ִ.ϝQǖ\vW#H' h5^ʊG};8 5Wr]JB-JUNc!*FZwabp/|Z$hTq W^ zG ڤ<771, yFoijd8;ȵJ7$_aJD%Ug:"gy6V~Wk'uOky߇ fZ AN,aIdݍ]Yl䄶MZ,>A]U fzy( zm<~?1 47rX9k' M`&Js?n 3/6b1S2\RU_9.mv.[#ʮ}$ِStpƫksYa.(PtC{go!L[Wff>ڕ|%/ʖjA&HI{XXc#U8^7@wBN'`jվ}c$:ߴqgLK#Bꝳ;Ҭ8M s_ kB'LrG!3ZfgeKKcР pg # C/?p/M5]e)uVy=h$iTgQ(f8$yXT^&"5?uM@bc/xYF].%MZJ Y*??mz9pB-l/!ņ]Ji;M=Oj4DiVHd'EݲmلCzC>LW,iགྷ Y,Lw%c2@],j8!-qχ瞡vGB!mF?[FFO{X)ޫ0n4ԫ&Rޗ„I}6m>}Z"PJzV&t53 4,ma`)-0Z~Eh;-27ԅK7,#d}˂,~$5x\j+|Qr.W@z*Dr?`0 mwCO3-,94]posgk]+*1>BM0xSOἸͦ圝zU6=2$ "TLҟ.1c p7zML26zYmi"9_u!&', ""#SUNAeJ;}޸(3l7b8bBƌg{o65!!@(fVP ^TM:7rW~D*'5W?+zx~y NQ]mWmi$OE(9l辮6{ȹT`4?7LkPQNw9lsb+ORYf=ެQ. n\S0KfM% EG%% ~߿উR$b?]F%dST,/KmLCL]PҖ,/Ѣ9Ul~z,6ev0{᷶ !Q^BC5H$= #;̉h!IR֐VlIC*1jif> Y뇅~~NK湞Ս ҍ&:;9nDC_F Q+kI#54rC'9k,1f 7Me)Y릜t?I%uHd2$Wpn*OeL4R]gx>4o]vtMP4&BB~Cl8DM%OW$l}x/Nنެ#fpЯ>89təgЈ|>]6*#\}WDFs3f[T.{%1ee >=5E+*"fdʙ0 )7O qg2CYǂaTy8]ą X։w~W*8l=F~{o>&E$DNЅ˃x95ӝs#&Jc q`bwCxgGBE9wqjXǃK'bIuێ}n!{&\^ҹy#u>qrA`fҢd=٪L2`kM,Ě)mhK| 2 |R~xs̶쑠[_$f(03l#+D޸<'l[f JU$xv8lx- ܽc&!1SJQ<NPF,ˉ3FtjoUr_ϩ݃MuaPyJYF憡r0]EEZ ـxG맖R2աR@~WFE/H3bT#U7ӫX 6',\м?+JyIzqd%Jݟp2Pe4Kq4{u=JQ { 9#% I0q`< Sa1Sٖ&$߬Fv쪥A?8;*[!qkw49KFef$ĬM:)r(׸Ē,Θ"oC D~NTr!Dɩ|J#4ۜ`}Ն2$(%UBĞ2$[u ,*a=#.pWР:PwYS;lIve|͏i8Pp=竵{*h)? .!?ףKR޺l$$f9k+޽@߽RM.h eaI%k¢(MLPYC0\Ќ{FD_LLL}khsk˼$^?E[o 6r࢛Kiځm݌ƌ#g=q;g 8"qC`Cm!ˆGGOG髮Oޡ>edPInR?qw'OW6JDfژԯ[#fƐwi;ZlJPh' Ƹg #>`֦:%9jehjSd?_F4Iq;pqP]ͫZa:7ܜLxiμ&MPF^/)[*=Z3?6Cw[Ց8HjgXkx'p yap1nѿN ?O9G.)P?OxQJcɩNՖ_SFׄ# S4 7BCƋtWqotƸ1,rTB w1LM|uهjjêxz}Ɨ$8(3)sMD_]c@9a9EF-0LM~d.L)`=*-^e)#8#K>qk~!-fa4ctÍHݭEs}A3wB_UH@]HﭻiSfK>٨: ci ^Sc^uƔ\ w2CA}l_>:WÊtA& Ρ>5~[Z#H&5}^pUdJ+ߺCA]5,D\XƈWqM1ǠoxY? Q,$t*`*. C xX=>T,:M5 3iQ#u;/(3pR;Ǽ͉Re5˦e AhRm/U+@=sd14(y~vsc>ŇgTu>ȗ/4>vWt{LAV?L텍-&(pEsѡhNi (Ъ c]F| ?N{CGz8C#P&J㡣M;Nځږcs(t:0x=.^x;]7gveNpaE+ƔQRj`qTbAʈr6\T0?ٮhضV$ѤIܵ/K)Y[{4Ipӷz/+<,/@)_WQu+tq%  1(J~HJW3˃@VX/&xvٛCs1C"/)sm)/yː Gl[vX[z"wT!XEUD8s6oF'RJf [;G߹X;( 掲EB6.Yl=ڥ&$B䏳.zTfrr4E[R߮1u_s_d`|-V_W(]gSυ:Zm%˚qt ›+J̢1͠pGmU8JFL"**A1^N3kXr*(r])nsdp 쟉#%QZ.8epxRաMTǐ7&+m.!Ui5S\A9Z`Q1hAt21Sx$jF~AQ%,;mu&$ "Z$Ǫks `h ܌J]U=˰ P-z8J,Mɵͧqv7#T]9dRF!'AwBѕ;yHZ1qaJ:H]jD¾ 6G hzgo4J*t5 Z5!ơAOC&˒0޺TA0 +xRF3F(m$k T/+A(MC.08>ABdtc0EnuKDy(þC%*θ*h8ڟϛV,nM5spu|ȍoO%QTՀNIaz_xH!JIkW}R"_/uS蠪Ldۿi4)f«̮dFMlXsX76zCWHKnR]#D0-'vȘ ` l?T9άv g4 w@$>Ck"yC bq=WdQUƏp%aq4G3R6#4\0-R´TSё} yEh΃~m"t*$qE# y.4-Ĺ};P,qu""xf^N)`8|_(fB+KkS_o<"1+n.2dIJ"pL}ڳ-okfU5mр#ںgCJm._o1;U,¢*X6Rh$/ݿCA+[duy7JqWǡ:E5P?ƛW 1boYCGcjaw,yo TǡgM` E[E.mc·Lm #ZW}&4j(n1: DOiѡB1tjBv֍^37f,Y0Um5V~x'rXerj¹t#[Zna2ְp ]z,صe"z'250 02s ^HáGb[ +:\(Y:1c"j"ġBzq0ոRP,VCI'߉~$N]M5`6nI"dn6Qh;->b:B:f=v9`ByP̚z3+T<M2e#Xn?#o̤>%3dWQE,b#s*ȟ9.Jf}QוuS A1*N q3# tjk ]HvO"8v攓lϯ,y;jQ6$}C`q"xg>A/^}ًr2Zb z o]>ߥ녖z)K&\?$A=RH;:څ$A%L&$c)t 6%B5DwdPE-+pAF:lg,#D}#N]>v{[aKO!;Yp_=%E1!vk?5OT&e ua6);[$#Cx)FAPۢ9rIE>@Sr!_ Q{#"ܰzf3:sD8h`Rd=!tgjF1e٢R-XO h}4E'YZ@&z&DLp,mkhc`"5B@{uD!MYuo7R(CBGZ ED gZK^-Z(f:!mBsqtZhe#%$sV<酬2} vdvi!1CF UtOߤ7~  {<pb k6R6VUF%.M6MO#&|Jᰆ6Pd]rLe/@kYϷ&W: UOr[{V+&F *i">W#^x&+$3SMm^?#;APtp_Gvi^mAg.頳l~ƠwR7MxKra°>h=r N K~R* NnnLoۺX7BאĸQ)(yaܞZ6 ʨl z7Hl,E[BgҌ"xgxD+ ^/bJ!Y ܨ9ُ`Ĭ!YmF4H*;INUxȣRZ,C/.@SQx}aʿ [oyՕ>ߺl'{[4W7/Pl$!!\$YPE :ˎdBtdҎKi3+,ViXFGkVP7d&@W)l9I9e7o}OBMa/l@mH,xM'FN\<P?miuL4J"&U'줚 :;jo tm̟LlAL Ä1X X( Dsۙ[2?C;jJun\-E4ҧhUsHZe0g i[x'9qYWFئ_jԧF\+q_*βalI$@isiJsCy!K:#?cbOT5$]jšo%2|"Szg(6BbđЧI2O Oe ;Nrx̌ ۿjY ޟjl26qe(!$/HP{C6J_w6=r,L!PV6XYa}x[-HWG!U֜4M(NPr)/(I2I~1>[ nQipi8pԛ+Wgۭl_𗇄`%33EeA+K Y'iq }*7uIg#ɢ\[G_((Mn*̩|`xd~4 }X%Ic/(/2BvZ֋SGu]PcWIděJPU|3 zq[ 7^L4+Op1U 0xy/#H93t/[\Ybg1w=(ϯX\Cݍ9D 6 J&hP ȁTM) gnaDgy`͛:ܱ\_J{:- k =)x5qE+I\gn6Y>::lx`7Ƿy+^8O+VE 8UU.娧8}_{<vĄR[v.JnɬAɪoL^LR.W=0V4i;3Od7\Xd(]14|f geNiۜDQVo$Fi؅z+lLp>?^2ǧv^ i$OXO̞3\l<3Bb{ku"1G:Xr/EZE'S@'w4s;"ՅDW]Ś*l@*?;C3hv@ +3@4bLzxzc TqD$0~\USbi`i=.%},ϙh|`G`0fW{ Ñ'`.L!3ѾXQ@S}*RQhBm&)n5`!s\~} c,,R;Zyp?!~dBP2CqnjE27̖y=o2.,τh7MbJ7:kmswQ,A3 tr4zrcmUKY⊮}+kSvXty.[E;FܣGbe`e:RGoL[$@i A᫂#) v =%=csuyӉCꨊt*ҫ{9^}`gI,1f!h!Ǻ cK-D򟊿6ݮ>kIp$Q#`Y *)oM;a:'%S0\&]^总eHu'[bK!v{ 'o.j@ᅀ;CvA%P!aa7 ވp]7\n0l@' hYGӮG1,+peD30hxyg5iD+6V. '`p^ܧRᦗvcЙ _@.K$9e\8<ݥGka:  ǻu&Jύy٤5k4C[~y)~Z4 =]W_1pL׬I@u/; :_+"}j|yp (~ytUŜ F+kqJAߊx}e1L ԟ N 5{?AK?X _Ղ~WgnNH,_\-lXޅl ^s!MTMtRj~Sv)DjP}uCSs*HW553_K0ZT8a}6?'5UT DzNRf 88̕ iey+Hg CV~skdaAdQ`=oq'Me]cp@ 90G;g N>"n&x}wBX,_!'>saaE䚫= FI(0΅qe8}ީqdϰVb>Y69zgz;_KKJ9rNNVh@znRb˪)#< hȐewV0x+T]J?&:JpX@r(>5ˤ( ON(MJs0%B&3Ǖ_M73g F)vbY87+f}|L'7s,U|lO⋇m1hDg`,iE+Gx XBG^pPg[`-6YT.ё;5f RD]nŢG`B9[glzfzc32;t3TUp(|p VEӦήӬ `rkށ41)>{ GZ ^`觗X.+Ch hu5ŃVYćbjɸX\Q^¹NNNqzUvSް]L a B}TAr$ ݅@|]Rzz:ܤ Gj8ZBH(mh;|849ӛpjͺ%\^yڞ8;,Z+$D");ۮ)=($Q"C"5,•U>MXN6/r"`Xg[Gi&zoX"0 p릖[҃YN(>7=Fav{= CΡN'\`7&B5+3Icl]]F"lx͚7Kׯ"Ѿr2ENOXShܜƩ`j<3,F<zޅDmelo;7,+OUv y0;q&H$Ja4Ǡ)v e:2iQ_R '6)˂?A<+ukm# \PociR7}&o1%X a .IUszf^RSΞ3΍vj@@{(LI:əkBt! .ppIrsCz6";βZ#+N59 <)=.-[,˛nLHLώtjޜ@3/CNk' Vn]yVз>.>[|;A ۀd(LU?uX.FKcF^*FFg;Ia} ylORViBbJV'@++/e:2! x=\RJKFL@RNyJ?´ D~f*MOwL10aMVb. ^xeI+_G5B]}#F:BMuhXBŽ{klIzY(2}{N,>D:ebny4cWn,U^k(%O%3e<LW?ۊ \qةp+"<ɒ>|Oq49X }nB@V3gbΤtdJN0Ru\o-׈'oF/Fx#޻sh6[pjLUrCտu"nnë3 j w@NA~2hfG ~G"zl4v]А΢K4bWkL DdzҁBvONcC ֊ ~(br%2[ƫÁ?ftE= L1U,YcY ]xjZJ4Bnӧ AԐ L;OR,Ƅ{(6nqm,R4l%X,C;Gwu˷9U}&7ׇ? v{LÕeA1ۗP^xC]!2%?ꖎߵ{>H(mZ;wє`?)ԣFbD}>A \!_95uߘ'Wui-KdCd r>B Xk'G7}"bdm7} Lԗ gm=CO $r (? 53D־epV'\NE&ădkj;ܛ3c1X?T 1p=$/K dXrr07+KN3 W?g m3B({{7L[8f!EV[`krIs>,)4㫋'2jijY%]8[^rgn RY{gɯ++w*c̐([,lP 2ETV H ӧ@8,ox4h͋9àUm+PRN <L[Ώ\VW'| & 7] E(FYrf*&6ShSCGYUdʕ4+8X^# H%"(X|: 7{1a(HGlG8J XY\0FS "jccz6yٸ6u!{#"tEܝۤbxJ 6e`w9S )zXFNY&@2_|Jwݬ'ЙӡRS#}K*{F$W@81 F%Mk-<I]L쒭(L> 8P[պĐC1 yO\q%t`">?cyu";˃?d^rͰO% D]IuY90P̵LƔތ<8/dHUWfmF #XkjK{L&ړ4m70"&h{9oxh?.sÓ$K`ӑg։yt3lqkqPM6swN$j+?s nmu׌28,)t%?:la~x+Ytf_Rl6RkCzc8&CTx5IŐ63G#ȏn(o}866#sK3hS F jIi&] *fo]LXNUZ&;3Z둑NH.rRBឌZwJNӦ\HF_)~!< MD?=Q;3_,`ŅE2t,G\V"Z3Dd/vG{\IA}-)^hܟgUmec6ddyzNV#d AAms:gȄIkFU+qG 엯pV@JhE>zRS >S BJkZ| SQX@8D>eK V6 E@ku$Mxuۖj'gL~.aT῿ >*QX6B{x&?+{땛N`C& [M3-W2'|;t55*|z yF %ׅȜƮ :LO>RAWVX^dG /sF8@msk* ǵ:0g!/'Tfݺ21[GU{Z,7ߒSÄ՚J&ԣ_<:-8ϑt {qr;:Uj- 2ØĈfT=$-6{yHbtAԝs iy,k|*bwi|<;}-$JMt,9\Xd#&S۝g*hWϒWrXM @~K/m,G^,ڂGTOǯ殪3KW`ހ=zaڙ7.q oBRF$l.?g}!u$*A9S#iG:y@k6C)o)eK˚-RR(G6pyW<]u̾aY!m; = Mm0:sƛ2?~\~ _XL llϖ2Y_,Ix]rY}')7Ci&_|Ǒ@}=Mkۖ &lؾOȉoI:S_7pxF,/;w$ZNAƣ FPL&;h_ 4|CwcvI),ꑠwlǑۆ2;S?Fr؝=kuo ΢'V)ڣE.W[Y7kDXf2tXH$'tnM;ez-Jhx3V&'عCQOja& sC5=4SxXeS ց~HztE 0D@\pC] L>uH̵!!Z*$ v *D\;P`,X5csLv71mUラ AN .ǺEJk+z:26 8~3Lkzl24)_Yk;%Cmm$c%XjЈ i[m h`P9she_&owZ{[ (q̓QD u!-Ʒn"LCo-#6Ri7ftAU Ú) ux鉻Ȇ%d.WNŽSh%q4^v?:1'D}MOڮ{fSM-968L \hȷɖ/$ 0cv) g+(iYw9V&2*,CqF,T[P_Y&cKA%!h ls]$^8]!&O5 sk;e|X,A*5 r)51#ߵs˷k*~y˷"!5Ke Yʓa?zhcJ1ESu}E̤"`ԥ{kک-hTdbŭ'9uݗ%%OwsN"QѨ_g婞]Rzp[h {Z'`VmzΩ.p{0ok"SI"B*{L\ GW';ZsW?%Z5l~ Ut!\p_@kj#w[']26c3*'XNBRPnm`ّ{Wm9>_47gK5I r*q<-BMRdtH@}HeAO0PmgX#E;0(g wBB@)U\qQ UCnA|#|LEhjAx!,JfGg o=Nun'30\ >N;z'+s$] Cv -kժ`]xgI);vnEЉ'ñӜcpY Ҵ'7 :܅b"`(^TU|G H`FgNGos?!Psu Yo a+s M&{7Y*;tMd 'UrO,Fr.XD:8`M۽]qize:2=HrGy >S ?kCLFGxܞL,%BH8VQ9~pacf]My zb tٌK|:, \NfuΞ ').N~c7@QV$#؈OjpHp %W1ߪgJl4Y0z3>G2=_)lUGOw Q̺ ̔w2cӇ(ߪey6*Ã$YM8ѮtZRqg9M̲*@RjFp:/P(C'oOԧ%^J& ;tެ͚3lF얜YD!*t?"|Vrq;fo+0RXr 7a2:`7k$+t +M>KXKHM{F" gM>X0b ˞aSmE=cF[CZ3jc4kC~J."\&c ,m#!zE`aMhYqsEfL{s\Uu󇔊5-{"cw!Z앱vir&40%M|3?I{/( ,Ga^^$>k{qC$I0xChhbGu0}i:u4^`LhHwާ)_eSƙjᗊ5t7042VW} TVyDzxG~r C7{˰DB\Dn4 }r_pv-2&@ YSx(.Оן`;pRx»H=GBwI1^(oVn-3ڣ!:ݤ)&8g+k.ma?X˲c ӚlvuYx~/]qȅkݛZ26JL/$bGP fz܃ 7wg93rz|JZ:b#V9(`wSs;zD)-tbk5ZiJ>r [JsXfr'[CVlv@;VVo.^;[F-Kb'[ d ٱIReeg6u(_qf5ԀAjsM`YU5ymhuhy 6*|0|'ip|)&һl5 ?>wDS,] e DSn#CS2"x?Bg-dY `4.-aǎ*bg% .RĘ?I((@A#&owZ7Y͎z oei+;˒׺u~48~ tŸUZFoLMEU\/[ А]ù%fNO4ܚ{gŲF(h&NT%rMݔ巛*aED.M?[lS*|ʕLWvyLhׄ٭,7@c_yTG%j4 Z3.[Kv Ȣg_z# `6 '˪H|>pm^Mʋ;0=khMV}4y#WHin9ΉQ񩕙 >~rn>C,Dt$Bu6O(=MN܍P0ަedsXdh(`M[\FN3NLQqbtgf#_&/'+;2G7eN;w49{d0w6T- INjvJ.;t\qYm  cp“+]C6@8nx<\ 0ΌJEhnv/qeS{v "7B"6F86}fȸ,fARJ5y^ٹahfkW)M=E`#qcpjq**0c8FNz-kʶ,ڊ#9#m̑kPvm_ctݞ;-R-'@nr,JNT \L"q'f`Ae Y02ig.]θQLIXz_#GVQCd,m&<1D&q^Ͳc֌vvcĥ!˵D#H-@ T zw'pݒreN[7"ގkx:G k^ېꈃ+ SBaw\z#^M>ckd:#9O J3A+el{DRQ|3š7 F*?PUR$ r"G!U-OhlY=w0CXUiP,ʤtyp_y o?V5唜0 RmllY G 'W A"FDFx|vgRKzb$P)0hϔIZo^SpMP>WϞq[6n2PNL yez5c b/Z]Avirx:[y"j wړ3)3G5bonօ5?T 7RP%ik7M#̹ǴBȑ,7RFꂷ}S', CgϪ#66 F)ذ~Jmग` SaϠƔxE1˹Q8)!Uek*d٢ȋ\j#T$>ˇTmdJS/dg O\x΋ևnN, $pd_ZSBN4y/:K#0i ^\[p{[sPtޟ=UǭM~qok1u$VnR&m-d};))5jfzղΐƬrI%"q/.9~?2CR=' OLY/^ERG]s;~d([!3gj$.XTdb.Z? ;T81OnoxU2 U۬2c"Vʾ^] dym g,T0dad50͡{oJHղ\ڵO=qGK҉o̫iʺҷ2[clO$㳅<ǫjƖt?٤ݙsOe>3:QZ' B{z:pL M|q-GTPf[$iGmE#hsQ*]\Rc  ½kFD~p6-ńP",B!#) fzts:T`unL|AP'cॖGq+a1Ĕ3Sq} P*EC~hp#nCaȻO4,*lL#E~ZjƀKlԏ |dYF!V lj"`lIl]Kҥ@i~&^i~Ad*t)t… (,EsK[hi6ҘIhwN~&׮^`fe=k 9VvOȵSwC_F%hJu|_S/SGZa> sa<d?סףMߡX^-!/ؤA1By}k,GlYBVVK15s UyY'v%{gρ:YZZv )6t_vK1KJصi,Zuۡ*c8&1st@_}U^epXE;¡/e)#>f-iWn[YQO껕U$Πyk_%3.2 n)\vz7-5VPR|>py\U`ǭK:४hY&@^RH1m<뛹C!jv91< ^DCٞFlJN/pBY 0j[ HNZzNъXPQ@ ,!d>Ow!] uC _fV[n,g;m\Ȅk}@ncM^u20 3]hfY8Ԕ bs`ͣߥX6 ۶<}WOI3XuFLsf Qp-pIicd1*/2)r܈ L,-4IFwt{6|jyG=Aʚ>1s3`kLiP^#N ꖻlНu%7}BXh][*h†`,Mt:}\aS``xٓ^3 +eLZkp+58 aݲ渱L*+5ph?VNk 9`G&'G^qO; eg*TdB M{HLfxG09 /b.A@YC&Т =TMJ$.%noe x K4RF)'ef_=\ᣍ̅t-I[䙺{QŠ-(ဝtl_P Ͷ0N,'PE 01녂%l}wMFe~ȯ'嗞/E\pEDqt+_~nk JRISj Sr M/[iWA;廉wCe]ҽ*jI@` {c:8RD"gL;(5we$+8 1o<į%ag EWq<05S f xT*QpH{p CinN9I;+94sC 1gDC?]Sc/.g=|-\f7`Y]m,SkZ~{Z~"DZJŒ2 UOJE+}\4*oKdqAU~˄{q!jK6H eGsH/gJ7C)S$}%n=Rk@NjIE>"e#\s(;1q\ulr|hJ-&"[4}/8 g\igfjCs[z!SBEa @ ̩?Au 5'pm_7#o՛܅ۂߎ(LW8% ~c)4@>e IC:}d(s;H*ruv3 m!$G~|᫊c`Ŝ;>Z="xXL-uێӡs)sDž uV. *-)V|Ƒ}M:3, [[\@hTI0Ik#xjQU!x8+6Ik( ik ñw"lY87hnWlB)^ݕMtי9$~w. _ڷQA'L'/GYbj}r6 .E%@+UUtE>&K&#ͽx DnXiå[^6Ec-9Q拷9%y[k CֺhoZv; goHGQ׵ya2df}LС Uz=Maʵ aGn3su)3W y\^q }mGUtTrbOFkU aM4=KK^QX{^/A2,^ F) ۸FcppAv櫪(9R弎{w1ZdcZBi//'®n6Y3e&XKCZ=Q=fmUp`h1<֧@ތqǨ-4ppx!;qo=HE (]u#nT0XN1հƓ!ZDdoFxh 2A,g).S`'\+B[AKN>'ɞ1ս9wGL Zg[v'.#'Xb&pAoN.z*%G~ +6ih%Z61-Qc7Ҍ?:n nDe+E" &/c* eT1(zQydjWLKZO/Ê *_ݢvIOzD s/ 8-=4@Z2E?, e[7[5u' Se|ȳSp˸=b8D)1ZQs`$Ω-svn/c7&:*Z=܀%L84w4gG;(8-Ir!yGönߘpqtԮ*5]fc^Z-W OEJ['Cމ^Mq71Ksz@3_cPɮa L6DR3,Q4pK_ N}aE_@ G5?gּ[ ޥz*qpTIŢ]CXߠmLJzP^4705SX6] N'Ir [%H0>M4/UjMS+#\^L-lڼ+&*C{0;Wd [VNErB%qdCbe+f `c,}&³DhU% R/aw*"vU-2$Je{ntH0)sa s$?`sLߖX:,wdZBe|3ԛKYQb\:x"p0:pVF=&q ݍ1NXjSIi@YN=>2쏻ВrX 0>'Mv@ zOw@~)/4~#Dž[+ڕcU qLL#31x;R}dm$z:)×q/1|":#*%N3^~wW p/w:*+v,eúB?4'Qx#`fԫ9Cw"o-lgc2`΁6zinU1FcG@P@=`AN^?S@$ 5V8b) 0d}E3OM&M" xqoO-Cx}[rSZ}2 4,4xqm9ʆIp[H0{VZ|qȾ%vO-^nV>X2Zq,2XT Gv5 6Yt+\`}s4R2Zi_E0Qܨ ,YC2Ys^m.臨:8Nu>9iF7WvLcϬfQϬbG6i8FHߘ :@+Ti_Ɩ+ DHԤ2Gpn[#ՊY6kyjq R$—]3cd/F)4D$Yz44ڧ_9G@O JK"IMvet 9r Q'YdK7^O=<;" RwEއXEz䐊u@J=#[輅~iis@i%[(ȡwɝ8E$= B9 ~@!fiͧ,Vw=9"Q>?ccfO۝DXi&/m-qr]1z(IElS/k4Z (b|+ai\[ 9<&<nƤeDTL ok0&ƔS5马_ 242"s#'øwslXO=ɐI?uPdQ}F]_/Vbdgc=ps(Ҽ c5 (Ar _DOXTlXEa΀)2>Xӷ6mQzލf% /Qt{"U}03gIؽ]؄JR!?e +Uw{chN_oIs leD.:afb8| X9"!N_XFbPR]AMw" *}&0*GMqS|Jl f-&JL 10h.&ieeRl0ϘWVGG'zVcL΅Ihn뛟:ώ27iS Yx9M5d#A<ߦۘozbP LrUaLu8>l4+n`Bdk; KYcW=7ۡ!"0/^'R.ؤõCEHwrBf.F\ +xb c rC.ͮ;_%sL3<\EpWDƤO-Y3{7R).6H@*")wDH=SN]ESՃDD"\}jBG/k`0&otJG}}s6-k@ғ@4DŽ"iPH3.UMu٭ΪM`Z!ҚU#҄6u(/[;-mQ,!F!6tq$m.a!pv36a#XÃ?a:Y79w#3ձLX|rL0Ye+AjA7Ŗt(@E#Vy[@K̹6| 2W(x&)#J +Dک AϷ fz"yN /d>(&s3AffriG VB)-e xJYhbipuY-#;vNavT~ L`H{s& @i8T ˈJ"6 &e`4g) Lb؁TЬ;E,y"ߜˬ?o]U>wvǶ.Gʐ@gQC*e- zl d/Y1[d©3 !]&Cb^F,)P X XD^:8t!5p㏏ʲL*PK: a+V45XU'9.a-өGʴ>gIWPȘsEK iz m n!0#DѴf0Ի"r8 FVwny(MUeJ tz6|ːD6b W8bʎfЪ_#M%awYbPPYvo-V7w g|klqʊka 2ķk՗.emaK" CA7Z QtFƉ@jBzPVڳؗxznJEaO.vKB1(x+f׷"R4 #?X~#,wf>l2@iKhPUTnSX*7H0XON8;|@Q~tLvrt4IP7M"Ī%xщ[uj@#sAV?o)7TZǜsMH$?{o> inoD^\?E+lȣSW.dS\b=yq(L h[Sa^k33j}c *ʖ>&hLՎװdcexV?B4YK?8:gj$Lңr?8i/2r)ݪmP}SeVpHbW<eiGex-p(5c:H>˄M]AST"ufB&8hГ,y4MfyB$ e{EχVʙ=Ѳڻgj(n/>uzmrK]:K=Ebc 'œσpy٩_{ml\sTA6pp;//қ@04"~ +0&"A;>Gv.К$5@hM~ʰij zȨx:J: w;+.HQŷ : a{FBG" ݉Ii24Ŀb4 x|0M5RӍb0Ab>?˘l.)ePH33Uje`Y8K6ZH6= GcDv 471p!w[^M|W؉4_k-}-d>AIm %a{mpOAx˷[`ډ5 ͛ T-ƂIILFXRGGJ=tm[*vj▦oK18q#&o#ѕ4"xrͨw:|oLl*;fݛ@CC8Oy?X;QbPl .ȅ* ~C>I?F[ Ld11r؜} ?o 4|ʸDd:L5e)A. EWD 2,s7*Ed'pyS< giHLWUZ_S wH, ^ W~_-_[ۇԿo@]cDPdjG&S$@L)_q}ປ/\{:Æ,Fxv=i0j,3(AĐeTNRc2qF2)DYԛ|ҙI SO[]o tQ+R VhՃ.'8˩-.Wp#WTƛ PF 'E$ICG9P5o*E3ɰIX0DK(1 s['1pn7 M%ʄM@ly:>~Qs)mʅh Ufڢ|UXQS/7Ur6N * wY4FqoEU6*MpRLcA6ۼ*b'|sæ>EUm9닋} VZAهP-|IaV/JtGʑ:US0xgEhR I˴;5Ѿh DyqX(ZSsJҸO٫'dEV!1~<ƕh577_4lنd4e.*O&&1HJ;)*"fԝpmҷ+DGNm†o`@oJ1Ѝ`aZa_w ȜfZ!F7BW>ɞ25YXGmچ,sg kh}=}M*v5'ϡ>ruz@+gK.ORr33byCC4VU$=gʟR.(?29Kʺe-jG!fIȟؠF7 I^SS&Z,eB^-i]`W9Xa{Dž`ucVN$6s!ღ)$L[1(R0'0v }R-c cr}XH~#d:wM:un[T1,,?I̽Q;bxD+N`Dllˁ^tTL}y--KG7%sŇ95똅s~?Ig+cO? vd"0{t?%}* D[JS/;gsWgLwi-M,3\<+F(SHs_U1:l\?f/EJg8<} 2]tt~i(a #7s `)Q&@YzJ*9.@UnGL֕qɼF%xܡgYdq u=]i<9x¬; Ʇ/7acɹAnϣCVaN'7 @feWgt;dkl2顠bMʱ>́fkӋ\ › &i} 8455cf| e*K*5D!%M4"kgCxczBt})ᕏoD{/])l1)Ȧ*ŮOǶ Q QrDuo|t~9 ]z 'C/6 a@yχ,J <HwtӉ^~8GFՖآ,)[bʣ$|-_{ |KaWfD/AQ)M`8\p? 9|b$'>( Ӵ;iVǜG a[2߈,vy. 9議kߌ9Gg**Q'@7`P\ bm s 9wpx-&~ "6 ~:BP[^D#ѽW,v٧#\u J=0i;'9$B2ُvtLDiH7P+7,kWiV bX2HTܤ1~<!iA>l]P6y `VE M75:Gk Yl3<9dO~?~N ?]ae^>*r C㖪:cW>;M+Jj| !ظ>GUW'=k_շMx'ro֤GdyS~,=m-.A4#[mz4IxR%2?6e<-ܖ*̹R;oW-^k&B}01x^ pJ/{ϥ~ x ~,\ω]ey/0e9pmH%I@wFeZZ^Uv; |H0;as} \Ax ĠF+,1iE30Єͱn";}W*LJ)K*7vz=Z^-\&]aY&LE@\_ݯhhJgQ|(ָbug* :#o4ZYD_mq-Tk=-}l1btWMmM_ eZїL5D8n'N3\?mb7RwE5׉Dn.PCLO0RySu1@%ǪGٺ:XԡZ8Ɓ9nIߑc¶wwe_d PyȻǻ"$S th4Vj43.l ^v2ZOHelVOlh\As#T!ѐb\ٻъ >U "QcfcUЃńNY*8tM [Ҵowy7"[V4/c;x7!o\.՗8chYG)j\[~7*4,ȪX|1fABu)Uߋs"M"1v%p.aJ]@?hcU83ԐAl#ҿ>g:IrshYY]@NSk[ˬ6Ɣ]mh!fpۄ#{V7MFBxXgeEBeB R9Y;몢3է@,jL᳡=R2]` ,͒f~LGHݵ\P,QW+Al҉"<2nN|W5ZP+o3#/F|H:A]h;4J\b)o2׆O0O0}S"}?Bv煗o/>ܫBcoŷ})1ާEtV⪇J܄HVg͙Q9/=փ 7p& Z/TG%$ TBEkEy_i0^]3tm(/EͅAz|H /ˡ^`u!CO&xXp fƒH_‹YʞɅ^Oy5H%txhI![tprj^ef˾+`h7f F,Fө%~\EYJJmʒc'X?tsQA>c<ί΍ ہ$/ ^vHP}b \k~* a5vw&g>p·܌!jt~V,)vpao4ƑY]9N>L%=!WcF4;LԾ|{VS~r. N0@`\Le5f<ʺaYCnWM+n8}|*3ťA)lfΉO"юT-B;]/,[:9:6ܥ2a%ޣ!lҤR ?$ 6,,oS_upeN`XŖrz3wuS̏Kѯ7v@!1.LaCeMe%Ut|f$ͭ>ӁqT?hdb;Fe+aA4y4$S)d{Wc8b@j;^SKIh1 +F<=U8B!l);bq 9k6c/1e]2 y$X|&/ a-'>xtPH ̇]PhV /VV Abփz3B >qyups.*d [a:ečIˠ2LTDŽ2I{r0 h^ b , MH|Enu{Z%ە[[(kN&TD?Y8 ڬT_-}[a~\'ۀRJԔ#/;=ۍݩ|GJBytaQ$ȐHd W-)pZ,pY gZ!Zn{itQM J3`kaȓNzT,"Vʛ"-Ht&J Pn h)l8B!/-YKS?`ߋ3r(Ă, B wQt~,nwKpvzXiCw/]]^mem&<-w==aԐe nWiw^$'M>!,czڽ)Ar"bĭ!м((KѨ#(ЖLw0lRהT⎋Nj8rWc/By ~ L#RUL賥䂮n+9-JI\FGDj"ǞMDzyWa {DIkU }>yasښเ鯒x[ҡhʿFZu)hIũq-DQ7޺xm^al(qή%ӀYYgtC1#=c~fm `)#q$5"AE!d$+7nOБZ{L>YVս"qbwwH asf4?wgWzyi=WiCYt1SFcϬ"C5?2Qg$̙T}#=@eb{Ze0քBvZ%ȼ+ Y6tV ]:}u鱏- 1ncJ_iyLohK*պN&ڔyI{Dp~]k%\Vp -$"Ew@Z}g{fB!1R–j[Y>%>zQkH@*HqyIc!C9A8teT{H 9([]<uP϶,~Go G4~~gGne3M(rd7evk\G ab53 > |w${t֔ .GVOv'~jvrHK_@"_!G&g[ O?cq<uq3n^lJ}G3ͯxָsG*3Tc)ӮSj:'ZY[Y+M<Ѣ^'r#2v+ȐzaNVI[ M[)FQ w|oдshI.]~ɢ~ۜ2[3[9Gb4.lްsTOzi~4 ^Op(93kH [C4T "55ntFQ镄%(E [b*  =]L)Mp+D#lnFOIR.>-pCN 6֚lh",Tj6bM› 35\J X0ƒ;X#9}u~P~U=&Lַ1(@U :E;=pQN> F;좁D OֵmҌѐ~!Ľ% ͹#6 ype3ū΂~d̀n|"=46XkY}n+LvOy$AqDSp]ԂX18gqUP ظzt@텐aGX\$i%3riQ( SyQ<H0oٕiEj8URaeO) ~aFm/-;tށ ¹hVO)jgkߢJ>񏊿FucyV/y6а~dlț!3t)+C`PUq E-XE*(;q׬RH }@Џ" pp㑭#:I&UsǶu9)_3GC6%ʠ\>Yk [έr \`F9‰\N^NTZ7bz蝆ggdJ0HɞG1hu }w}(j".V0 DxoK D [s4lFX?ȧA[ 1p6x.hp%1;aB=^egʥj0;^dk51:綤E29:,`-g#/7h10(k=whŠDl%\ivu䈚B=U3O>:T.z(׽c4t7q7!!9k!UPv!-ӫruj3']ܼl Of+Q׉yJ5}bp{ @2); hCLhi ,ZPl[1(Gw; eveaEh514jQS=Eж>oٝ_F0#}a7l ag37L;D<_744KWtj).ӧ1:ն<'ZXB$L0D#vk yV-[BGحIXn&8*3B`  4̙1iwVXd9bn?Z~/[ >o d H+v| ?Meb^,6~L_/~w)QINڵ{ I˚>!KoOlf>7a:1Uwz1V Bk=JdtA dI}Tq\dH&l֝yhַCȕuȌ8_R&qG@d H[P+~dIc&FVj:  f!aMJ\H'{|*)]NaXIuvQ4$<v{Cع8Ϭ+KR[kYpVXU UE蘻_zѰĭa?ή*XSRQz:&1Ƃ> wW-jPPV_ Ѯv17 5%;3꼫7`KXGn1Pؼl&&Ni>i1Ͱ)騢A%Z^vX偪kNnraE@_H\:[d`^o|!(@P3%~<77/s< ȦѥN"79.2Sr|dd>b2nK3[6 w{Pmp`#p<Ը csg⋽FeOv_n͂6"LJB4I,%5ӱ}zkfr}9wԀGQoI+d:&l݃0ƫm?&@D3(=Mk\6eG&}+ea>vܼ2jLv NwGs񶦏fi)2_S{+Gd襥O,EjT!іnR4Sh6Nf[ɛ7gFTMc Nx`& aقTp~ʆD0o-ױ"4_.*E?H[z &r*NP2^N0\H4iΞc;?ϱVuнx R@Tx&[aG`xM`,a$*U?>,x+M h "tm(FQxPeWNA@͒=?sv};>^U5{)" **+-.cEqo2(1j/9w w!HSPnQV󨣿XC~ybޫ-OۮW D"m$'Gŗe35L0ByZ8Hۨ=@t'!~iz;Aa7™1b9SboT7mR ^)NizfQ2J$IK@xU3ӛ$gat6YTe5T/!}EGO Ao;q`8j9czQ P$݃&զua  KP>/r <b qXUofgxIړC<$Z+YW^ۗ#SJK o:\)ӤQDYe4Ow2?X='[t9X-ާѨ.kg 1.m8$Ȼ*2njKHLzD C:4d̴F z\Y#"r¦H#xը55|Ĺ4g}id]O4SdMRI|\$#y )죠Qy,}Dҹ>pj80}Ca]o5{47"JUwh/$@{il yy"V.}IH|38#ʰ|;O !ۊ)B F.tUɺ`U.0K&%W10BiՃxZyRsӱUsPv`{S3?KLk%.OL<:?Mbr`R' 7lg׎ ֆ!qzKDh keD] gS >H#Mvw/G[fN(GC^ #Ooqqʥryvp7=j!U@'`% +7Q_ )ŗE"JG06VK*^݆T+PUЃjp훕'LG4 :ZcB|1j FVkITP.p~eX &?\k|#d~Ŗܻ\)ZB&~v*]&P^z3(UFJ T$#=Ӓ V &b D#Y2ao]kFu1E6;#‚'g!-&$;bĕ*{ָAYК9{q_7B"VJ"g) \cl 6#D\c&ٵxn;Ĕ\wޛ#)YyIhwEB(OUaMAE1!fd8UkkM' k,., 1?  _#'X?ΖԴ&  ࡄѝ0xJr3d{UKHtQ+L_+Y/v prTuKXc['% Eb\9 5Hi)f>y}κؚSGi@I-h")ivЧ N~q\EۇF1,1;N. c #^LmͬZGwj;$yϹnZш@=C+ՊCWZ R>@2ſ*^HUHe`IR!v&Gj>G*,.E9Zj?J%Æ=*.hf!r-Tf <yuhlC[+D6N`,eɨ/Jpe&1[d]Iv\&ԸyXn7~hW} c跢ObJ"-̅,Mcsc@gOA̤_Idnd}brqcL rѾ5)iuƃ}A2I#D͉<] ZfM.lSW_)jɏ 1V^wc&O^'lg/Ausـ|-ssvLՖ`v7`SgP,꽂Dl9M[ eCwG*&.,(}aBR(DL'ыtt]|N݈/鳲3:o54kUhٍYXA \d<0qɉ&U} [Hf!P̒E7$n$ߎǾmE}hfS1RJpJ>[)G! S.&0SzOJd{ 7a~A>Qe|3%J~pzi͏-`b5-Iw̞%ytK)T^jgze3r( ؝j2c)S)|'E P~ ̟d͖_$,!O`Bc8viM!1Q/b?h R>`.NQt2b!9v}EBgGk[+H0-CKiu@tH 1굁Ϡtv_s(5aK+Me|CpZgM_^ y@cpCJW7bjRfbZ۷$I.d#CeƝOzuk@N n8RAP]: +<0< RRs&NSdgv{; pH2^ z'yY>y!IO7?3[vlI7:od1bbSv\DNBⶅ5RfHV{+ `S*qd@uǀz/ ;|HFZ>{oZbՕ5E/FN=A| a1çY)X3A@2eN$~]lM`_jy4Z Q/K<ugib;Uew`cH톶E_Fr`v?-÷#-Fgrmƥ]U҄+sV rxjЙ } ;3iG)fuڈtdkƅːpcnO.L.)!}^td7is h"I]{C L`uHq}kfVR6-ƣ{B (nٮkeZE]0P!K)o] m.C<)WRgTc_'g/q!5RJqjTv@ ISyc 0Yہ~ڢlt'D[֏>C[I .ޝY>ɧZUtytI*E $a^EY#t;3en=vNJQȟǽZBnj!29+v 1ԍ̰nY?\2y-BR٠ޡ};rpG=_e%L/ImQY"KP`p8S<% GmҞs ;[69&^aq]n1?d'Q6&҃dI6JT0ׅe#aFJE'5H@eD0Kbt%n%L\/j.xz?3q+w`g$4SPQbUVhFV xX1JKw8@6F(sC/hNGN1vQJ0S搖5n{I&wwnSmگ:ny Hqqp>M.TD)f^ޚJ>>u[ϱN B<;ad ng7sG_pc9fr ]]]Z]:qJN+| Ԙ6 4u>ecݞ79f\XP:r[8#E( u"E1<#]*{h|U)^/2W#۠QuF&#M 3Ôp894s~e!Ӎq L}9La8X.崣2~^='/M$}M! D2%eh!;z~ÞO)|KlP jw&8+T83%ϐy~0c\G6N*gbJ㧏rX>CNpwY _. r;SX1 |G!%cلj G1k,|#.00h^[xN6>MF1 bid`SJUʡmy$K6`ثʇe`Gc5ط"[ I;.Si%9BCJ0CXbܪ~$rѾs 2 j3 Ȯy^V{Ql? j)>tPMmt+v$a8[%m+vݏ>gyHF^^LoG nMVջN>kKC6[~7r5 dɭଡ`k~?ZKŅ cbhRpڵ*R/L~a‚=9>{ֆs~G?O7tdti?n쪳*+(v {gx\u8l0 qǃyB<6(վԝ#|USp "TO6 (VIuqv;t R[ GM d/˶ZNo^|eZ0H6tFjV?"CC'FbB6! G `D  Ot`WW/L aM䴓|b/2%G#!éyTL[_'^k%jjm3mSO-h /I6[Ռ?+Vtq$*R]h"/T+GHN.}RW2A"]<\`|,+_4+|8L'b~SoVXTLWS0rkYP_iH juAIETeg#8 )%!;LЗ;6TPjd~SGV+V1q dPGQ Ej`2,s:K2C|/ '2G F 5+jy؈YX$>N"<|l tz> [T`:De'" O7 E@>m=IЪK;ztJRa1)# cE,RϪP唨sak9nCeO$N@b~@!2@F['}ʫ^DHQ&)n<"QvXKZ HF? R&ȝ0XK z9ssxklcf!>'eԀ8OԆYIi-a"vaH"xɫcP@D<"G)':pH0~B$bbܥ2vCk6 IWSy] Z"'KȂk3V"~1hXvo[0ߝ\z Y>0!SIfBãE(#uD7eXI3r J4Dd%[zƚJ_O @6Cq_գz ,b\!! En:)Fd*ξ: dn?\~EG|3Q@l˰*=tU6K}ŵ Wk|V-h1 pX2Fa <8e!Ѱtߝst(&u4IWQ6y"5)} ⁽͐=YKЖQFF;pzEO.&/:_yإl Iix0(T)޵ؖ6 =| Q(H:LMq􃩐aHfV XJ}k\ ? ?աv6mXFgDE@i*7J h6@F?kf[>ȣPYR򏸤p[ ڝ>e!h-[vm/H/;TŦħwB cAL5p;-\)'ܒ7^ꪌ$ĿHL2 }B MGbZMK;9~db&α`ݾ*9 ]lb_")Ťx̟Xˉ9cFaP}+,߰7ٝWئ{> !z:.LuiTonk~&0K*½%MC{õtǐ0t_諭4 uP+l*\lۀ,\*&GL-/'=[?$KR07ћmq~2V^=4{zym(o˭&SݚV18IPB-~$M-7le. !ĵ- _g]t|?`h)8ma;O'ZO]0ABl@W\QN$2IDQfwrE}X8zķFF t_䶙ӽ#&ͼ*UJ2R@[qI޿YZ;0kO5i=Ɗ3WX$K7˕ gs uQ'pc4ԯG _Y#"xR" KZ|_eqDB}K'=aK,Otįvueku0k~|Ckbc«msy`7fNZ?85ӪfA٪@ *=\*6epke`Nu$vdW9.0㺵,Y1,%6, Dh]cUu_b ^;ZQ mBw@MzP+FԛrnP>sڄ3[N=ËSa gA{W lfZC8%E']iʹupҤ [pB(Aj,3O?u5i32722W^'9Nҡ>F#,S\z ߳PWJr9-0HKc;쎖@C}q'dmߎry*/U[[Qe$,W?g_蔛l1)yq"c; 2$ɻF ơӧ%$Fg Oaps4J!EOgwuCGK~SֿDI|) nןaGYMg{L3!&:EkXys;E3:}x k!e?"D-SH$-)d Pn G*hAۤn3$j%39 kkrА1 )@S&ߨ~Ti@#Il0uN/5^Wh ٸ22]j+K sэiE! ߨ"zLq`N:y^GSq, %)篶YU΋l!.QW'+p!ͻyIuRC츯HxF! xNPp\N0x<0߇8 ]%4x׺pmu"4v4LC7E烀Ls4?[x͵tPC/PԏP_hĺ_4 e;xs)?機X-j2PAhwwt`U>SD^!P:q!HfR,Xn% p4|s 21ѭPf*" mhoLr=v?Jg)|5ΏAH;eb,s ᝏdTUzw᣾1w3Y# }B 5[;e4~.glQ!wIh`51V$EPk"OEL>O}1S1]r-Ggdyzi^8# LWܤwz>9ky֝^:Dȭ5OoΜȋa0TXU@gl:ӣ-9;m($ٖJCޛ:E1 TBͪD`jL%NDX3RUr~ZaO`;LlSҞVbɺ[q#o'9h;a- '}cE8IJSN!KCú$ss*tVcGlI-j#aqUByZK_,B 5' 7In?)I;B Cѧ5Iqs o+y="e=V[Iv4*EH҆Qz>,|l$U$p'uUg.{ۑ)IJg)V.< W(XFkԕO"x +;;9.cבqt4F; mחf`QMZig"wmT~K~lqs+w2ffJ4+R~Ur"T捛GU $k/ R#~!)'#0/uU:L,yX?)XmZ^Ȟ%蹡Ӡ7K+%cLAs )8Cb)F~'[uh >wSbyo}[49W?b P0gct/L5msH]`J ˡ0$tXu#Jtڦ-'<^`3|ۈqJn/zOoeꍯiG~ /F4Bm+b* Cm,c#_3eZ >GXv.JA*"$*MX k3{?NyUe͏KW1hIߏXd/np7%g\x"5D:AT/>&T;2ͅ}L*Ɉo ^)gKh-Y1 g2r$B^afbo^q3kPEkA^EcKFƊVu#Q {yVL 9%$]69kT}{}t`3{맥{9<)!s(inW~u{1 S%V/kgO[8dyX}aiKwD{^6Ңhڥ-+˓Ap(5~ R6`}iDl|{c,#I/E.KN $fX6ô.إ;"rBMghs맘5x koiHU凨 ;6S)QyE HI:$1'92"Vv]Ԓz$rurmeu"O3K#YyVG̀J FBAKjw>!~w v41j$Ve1>MTd$ܨ2 WV4H2^;NFG:h3R|{)(dDꉄcm͍dRpY8y:C`OA  4;1lUO%5 #`S0L aϡ~ U .9ݢ{wRK坑&5]s~@~<'lgv#BHw\nc6Z4mҸ ~87JQ_ڮGS=߱5Cuz3uVz\&BYFQ"F f5/I;7.\V#E-=s5a/LPC&̋#ڏqqgJ?ߖ3jsJ렻IT3p4Se\Xħ3'CR}p(Co'QMjܵе)2f,jVy~K),624wXu'u}|p!Hڠ!a Ӯ`鷛A| tΉƛxihyشn{)ĺVyڗ!6Gy>ͧVwyOVTPAo# &~vIaU2:" S@0QzX-`8݊xS|#nuӊΏtA+X5k̑BNM"!Pҫȶb=BﻱLϘԢ|e{zeLhM:ʊ%+a pԲ<i=wE=KE'p%€Vpuf?!IXa& jQ4Ӄ|SD[N5s`FɄJ ec]vfi$< bK } {NiٝղOQIءxɅ1pkaq-5qHΐ=ERpCY*Kn"x;x,2%\ i +FzX8 H"ӳ+G쑄<u/S]tWQڤYx& N oNJv;[- QQr[_ZfwtEodY>R+q3A,1KOhi[:ˑoUI+w1EzI`L|`(1#V5aw֢ٲ]:%w8@r-խv\1AŚa6WZ@KK*Fv.JVºCZ$}\6NGA#zw,J#JCcBkQigZ^W1aª=k|%_iTmֲ;J^O@L񺅤R,y˩pB3GOXu4>Ɗ+eg.nGJ$`Fy j̠DFnGjkɾJqo.b2AK~lzi{=ܱEM6I3 H"aSiUgoWLjWQWȉZ9Q.WpFR1|Q3Jtc#1sn3Ծ` V'r OҔF9n\iMfA3TX"hM)kOuVV K8F*l25*3E/]P ~J"A}H(2,SMB)l b8(L"qpq?(zݢzc>PԆvM'7Hp91NWbR[gZ5WJHJx4I _~Ab p+|/R~[i Zw5kR놯$ȶwH~"n"12K`5iP#v zXQE;hÜCKeóOWt. ȧ Pׇ7` LY{lH\#ƶ?O M^HNJ1r,8;4A~kmf4Ii&yNAW|AJnz$إp? r5VH)QOU7 \X'xl'c]iD"@gm ŕR4fgU9BbInp2 ǏWA$c >^{d37g|*we)YD>WCϏ*U(t8&,rOwl{&^@Ox?)Xe5>[-qw+T[KqR-LÃE:/RT2y Y+ʝƮH`OJѢ824ږ&^] iϿ2bMKF?I婄z޽_&Kzfbj h;KxB4A 7`ش)kDL]eq¯!)6V.z-moy(PcU1xzqjp`'̿bKBHNMJE\@/ 7V#z[8l?f|T^diGKn ڧ?gGw!.ƴjmnJEzZd(ogK.?FFu1k!Yk> .>agp , T\eԏ5 4XJC<)7TsٙmQ6bKr/HJM`v߀ r@X\\Gc#NYaw'mfUC 3̚W~_| uB8j鎢l*\2\ yr%[!!lߞ8DJUr ؉ {ZYy1Z| CEacC\+$)T ghDg5FDD]b"?H cYT 'U$b=A|J cANJz}.r"7FD k㶤(kJ8-eݍm.k)]"[{ sO3*E13#h<^a|D{~嫲p7"ܾ=;>U`Re9m,2cpd4 f,QU@Ezu r­F}ҿZYwyJ&>E {q0/yJZsȺQt_6 ,']q G>DYeڌ.Uk܈"J.O+-R=fU> &b;=w xRDUֻ8#+q >'|f*,5ŀ"zoTpey$E,U?؋l*]te5E/ (gYly_q/PAYҪU'vd[<^kؠ~}Q En޿o9uy]5c;Xt"^VoH|'_&vsDNq?R䣄_p9TzC"sp:E3Q+E-4n s eDh;R(-uYJբ. )l G2SZs*.d9΀yO0,[J]/*>>g"{{@[ Chg K„j}mMpY׺7X@Q Yi r/'ykܪ )nWhqߝB׫f=,ma{|S|v,njR(Qv[X\@;eɌ ?F46oГ16$/9WDe#mt+yp8mXT]P?nϊy+mo۝c=-;*er_AKmMhcvCZZbMTl<05Hgv/_Z>WQv2*-ӳEGACX:$fW3EZ_F1[)X1 l|BSpQ k՟jtptʪq2:@u!<>"ʺg$W[PS3Ւg(.u+v]_,AAz(Tw^8۶a#Dsԍ?ˢg V58h@w\!pҏpv`˜BH &0(^}Ra(;S~YfiP` RUސ*< P O )z¼ =0*d9k ]b)M}ZTnZ1bPGt4{v)\]B'Z5*k,)jq]g"rL=ږQ`C4DtHAع;a|dBWT%6aX` {|\(})]+06?6ًzϭ>d9i{MN2,~F.k(3-!--k='}ēl1ΖL~tbi{3/O9\T3zo/j}lwuw1Gr"5}faZ9Vo0YEE`Y+$5tNT3 ɋ[`Xޟ6[> H̻t[ MIl3Xnʱ\<q5 Lؤr3Hw'vp9IuG!N;4#@ʒYk? ¹r6G=vh$L޸OqyY '9 ^FinZ,|j; l=_ɬwtB <V="+)뷄 Kz"rq)MPר#:[\m>fO5Fgt2Ľ%3ed˟HE.Agw;Q'p?ٟa)VK-v ÍP"Yjn${y.3E 1a3I0ɁRRS%D W3-NX7nwԒn@\bśX3RVl 3ȸIAO+tmB7Kz 47SDvoF5^˞ـE!ۈQi>Fd }$dx~U1"RRr"p?-,6 =%,0: F:k{<:4/Jq;Q^XS:IϠ0X[;'x4ZL00 y XuYן6M#"b3IGӠRJpl^!sʾ=w[0"46Őܬs<~fK#5q;ݱH#7D~m"LuؿTpqd,)մ )2;q\Q)?jRBva^D$*4OXaM$Mh+^,Bp>yj{NPzP7CJܺ=DxѼ!,GGơԆ^EYVjKTOR@JRa&˗L 1D8 Ɂ^!DsΣel0/ʀU_ s;&l_6ԏ+ə~RA~֨_fUYK\IƬ8ލfu06GG0,p~λؖ5o=P!Ei뮗zSttdW9Brwm_58-GAėHLN*vJ:Dj2g,裲KPRv䄝C_΄;h~ʭ*6(@{#Nh w tdӕ2?[&TzL hv-.R*7ޒ"*VFL6O!-l!J*Y}ce6Vɾc,ϴX  Ռ>ɔÓJN  V A M̟>ZSAԨYQDؠ(ε B6m u/iaqma2yqQƷ[PU+6Gp "UMBQWhN &/(NA;X |,/4GEb ɎօsBA`6os>$ "~h k]*Xl:ɸ7,~+G-1uӷ=aiLcV\ؤ4IΘqcL JF6xή 8yi obL [Q5mmtKS: D!Ygdĸ\I)zE\M!+DqJڦ|`E^7<8)jFlIw=`K(o␧9b]t9|oq,#vWTgWek'O.gcGY;KɌ1YJ̵߶2rx1νp8+_۠pl͇. ʥTQ)@ ;)QҒ^X%Vfݭ<{&fZ--_MD_(=xͲϊ$VZ(ҳ эt>&+0.|H11TJ(gawj ڴg-*.|=8K||9sβ.&L3^GF$<6Nï'3(lӡe]>ur32 CpXAY-`akfRHSby_t_n+BiڟF]f̀ P_Osvފb˾`XZ&TfwO\ϧ* Kӵvw9huڵd?x_ROr/g'>M@9Su+eqw:eEsc]=sפV*@DAh/N_vzaƣ\' yah$sV"'hUqm]mIr[;u%6hq,uoӱJ "#mHxEgrNu-iCi>\"̗ԥyxէGJ;a 0]Mfԋ(;qͻcQr6zX;?/!l9'\TlܤGL@t??NWvA䀪_WpGH^P'hpFY:₻5֟uԬ#.bNL[7p?XEU#Kܛ4dz+|5W5Ҙ0tqШ0+5$6xB!$S>x>*p|AjOk FΦ5)m<)c `hh'e»; yi{jc:L[z1Pن | 2qd"$t~yہ[%!F=6"l&];3VvFh:M](/m7W H/|A{İ͗P8]Vߍ,Rp 5>TF}xK@Xu;{t_F_FXzR*Oi]~9P&6V8nl@"7I'l>_ ʋ}9R ]_na7}Q?lZ9.[CΎf$m,d6@`+<&3%W;>mn|*eם'0].w8O8 2Y[ZSo}S{h<3td,-PI9^N QJY@Rʕ.SRA G5h!O3}h$DTe{@NsBRXw2fNJ~Zڷ׹-sO%^aOo?.J]Ϲ~["҅nkO+A5(&L@Z؛<|¢w2;WR"u1WS5d FCBA lj"rm;eK}/4{զ[)ڨjz'εu(lLmPPwŚ'kp= lE*?+ K^ “[:ڎ~LROF|ZB=|,H3S@r2\y RS^p若qgī|^9$C1XUsCX=x;ZR8 j+3…5()8sÔQQqr`:9D(p :Xx)̭rij̍K|K8]:NF0U1`6[Xr6#x %iJ,?R/(@%O"įXJ)Zt# e>*)'ϒ@؎j ]=ĉl_fK/'-""o醴erW8R!exQ-50&/DmTbaԡif*}G巊%䌥>QF耗'eYta7ijcګ#Pݷ*W |H▴.<ʽN&>\vu}5֛wJ'Ւ[ pSSx Ϙѵ5f*/+wRd.! ddzP" pr[ZvXƍFgNxPFeWX&%o9s}?|b4"hh@A2&aAӳif=Ć(]iգVCI=!SM]x>-Uηvz_fJ>/#|TuT^kO]1GM"ڣm|n2 3 כJ]q/l&mjWpUY>rtAbfDmBRS,$䣥 ЮRVpޠ ڟgul"*I DnMJ ]Af-hVHh.i6ϑ,ͽ{e_䚴H 4Ȋ[ .>MVO齅&KY`#:0Pϳ1-_ tPJc!-IiC=zvkXB w{!!!BxTb\=Lgk*R_سRGApo1.cI>ϼDaŀ/YH,ZdHxxIX;-ƯP47!YKpXZ%R(qtKv+?{Ȼ#h_^PFАA(օ{͝оٱ U(5#h%eZ`ZK5Gv:xEaQm%ٝj+hb>\y4Ϡ;zJW<_V|BCɪ)M,LҐ1/x71!w !3(P|v8|$//=!W씎&i]J\`|qshU$+ _B<'Sͯl̴F'. 4?5a~zjjm^1, 4P#Gµ›<'c t%e/}0f4.ktO)*YGf4^euY?٦fr0slk+K b?GS@a2 t6^C'6Ѭܒ o`2[j行ZƝm-Ȗp7SʥƛsfxƯ8 ̶ ߱9F)vlEyW-vzTfi{FMїwnj?gy O+<Ϻ_IXP- (H+' @ =vЋ<!t fRq˧ާ/Jwxˤqc136hiˤXAJۺx0 ĽP'ϩ%MazTOIӾ@d朵M/{xwbYYPiDreZc;(#E~eɾ,aa'b}^qxIg[/)+eFX.4X,ğ1.aޟ5X}zkI::#r.5̶ac˲k]n[ {F`alJ9YvٕG>zSEBrjmNqF'GWje ?~Uؚ$umԉ }h|J#1W]B[.w|՟N6D;"6fI.\sA+n0u`~nP8BO2,za_GbYO4\;$uܖbWWGO+2#2]K_̉_,MDA@Pc=RBYV3ACٸ͡`v$e2Ϙe:X^tєMVZ$3ʷ@!(6Zb5V\pd^wH˳~ms "YTڝz fznNݢyBwr҄;1WXލnN b^^5sEZD7kUJFDYMd a#zm]/SgвrRq~M4}&V86PqZ baXiӬ@_5=fFg} j<8@{[-8ΏytfW͕}u[a-.eԼ*(g"VQ/(A;BĪ% iW>#$|91m`bM&Vs!Nk-x^Vhpª"bR(ΝOeF,K#g:'B2ؤ%|y&_*&S9(/8gBO (X}0au 17ߚ#ҮWTw;i,=Qlzh',K^CwZ^&"&7[~ U39s~Ü_=ũ}XvrX aFa&e(ZvC|Ky#l';Tj, MXOe{7R* '88GVFPdB5Z+aj,.kd#2'Vg@wU5a&MؐF HO\%d{GCL{I={@F}ȋ-5׉ 2arj r<ք|VÍԣhB΃2+E^T l\HPO y\YI?a(=)d[lcBr$i%oѭnd.>ֻ |v(@vdJ:Hf`JZЎ)b_K^ݾPLF䞾Bѧ&f]xC0Z;\s仗Ւf.,D}`圴;+bf 6!{I[N}cc=Hr .LA1좪TUF`d1;++ RSV2{>|}"<]ޣ6 A64:D.n}p7m6;u 2c!GqᆨSӸLJK^ݫg US3-*XN?MIiQ-(I2 3,sXޤҬkb8rB/;?C00nJ4W$zZ12ךQ'e YȕgSJ Rw-ߏat?6"NŦ3:F[,? N,% ÌFDB)MC|uBj2M0&Xc+FG?Yu'r~SUl %ǁwC$$VQpL*M'tL$sF232J0$d:Y9Ҹ)[/Q?/ѹIIKP {s2.-QYhqD.X).L(}}9 ؼIݥc ڡ1B}Zz2N_t<7"e^C3N8!ٮym/vߡv雂VTJzx$5<" SNW}nL<U؀HrhN;vrz Z\4O s l&UHfX:hw#0k{aXW$wq+37~H qI8tN@ mglKpp; `p2dPjZ*2 + )"檙vuWD^AQV.@%r(8*6C"7"p[J4"w cH>Fɺ-eh1qN-{Տs>^qZn%We{ nCv!ٯ0^XU3Cdв3,VT/1ӫB:Edn+7%V2ym=t冇=B~sZi;ʣ#,oATͿt&3ms8ϢӰlp~x. C/sMr&O 6/fJ>.!ުp;Mz!gd~S!In^VPE6cciTC\?-$.ޕznJ c5bLPaP5kC+i\|ZTy"jZ=uFW?oƗ0ֱjR܈MC}l9ﰚ*-9ϷDi(BѢP"xSEƦaw+m^3ܿ6 3Xja.?{Ma@m;-ˏcq",kݧŘTEg7.A!Oj(TO]*(q_r*ܖvEgZ'T3LV(_}{o&,gt4,3#853hQ ]79p*jf#J0x[ Q,Ln۾rpf\->xi^i%Ѫ(>| |'oaXeD?(c[8xXE˥a W\GHbyà$`ݡ;bYH"p "_] #c A0z엤} P){/'ƸtNf=5#oȰKP` 7bf5-mt8; t`;}b:Ձ(xGIpӊ9r :z}bŀ&aJ, t2pk̀c p]OnQڞefq^q?Ӣ86Ic&@>*j#*BS[)UQN˖(hc [t%yi  [I! VW˯]p=uPsruPr/6~BB{.Dlt^ȖF(L}GJv i5 kH%HP>&^aN0$BS9iG$ݯJ$6 ]J_Mvܩ5`kE)~FKt|Q+(UUaemlʤ9tꆂXFuگmL&:PE ~c-!=ڍqgߥ(p4ɦxߣSA,1q}KSf[Ԝ~9IW@H!;}?Fz m|T7d7tC /l e`C6z{cm<'Ɇ(*9hL_uqkdЀ""$gIK;+^ l;ZlLr*n-C/Hq283x>4Ҩ }Po29~"2J\QxO8@Xi! {9-J׍7bzX}{vsJ|z &"^k:j]hz>?=~XvU.lTBEc䇮H2qţ0%"YohHu3:l#(YWrF[ṣ`dD!$\T|M?o(0*=R*0LgOsusjפ43*6ۓ`&*  GF@+b+8K)""![*ʒG!əǡ(I-tp9ΏKv7!OA8ao%S#z%Y ~ie#d2bm9q8dN[vb\JF?A-'8a nC+1LT38M]yUˊ9B;FCkgӎQ@x,"g>l@oNJytlZzka<.}eeR VgZ[_uC)aڏ9S =)e3w$Z`?{(MvjA/1@olHX`ԓ-A6:M ;oB.iӖLthz\Y%iٖ/S(i,0g: v:IAȫU?jw/l!ĖvO7#Ƿ7 NE7MR%ʈXR,]Hq.Lta6B%H7L#[o8dĂ􎓢, C \zwǸ6EnNZ c,b-CB 9p?'j&\#_Ř E9,|浻&H|v=vQ򩄌 >]N*[( TCBpu* xD~-x^۬ q+WF eg3dt ks~iQZ,x ;`. ϭ~ƘwVAwᅱxQ }Ks!m|O1Id$gB|{z'mW6NP##ƣvFsp$bhnw*p)M q#~Qes[M3[}hܛ> ӈC  ,Ft9Ö(ɗk٥ԓusC2÷^$ _ݏr?>>ƈ!Cs=Șw(^6sIPe]+)SSÏݖcԞO_ͤ Zhڗcdf L۬DoyՂHJ~j\CWSMLMs&5Υ~yLD+OC' ~/6zԹ-DGB׹ΦoT?B AL ^<Ԙu:Rrtu_I' 1Oca͚xV ֶޓZp3yGι COPt DOMjd5FTHtI1R NN7{l.kXak@ZGm]X7 ze݈)))2ʇJ"Ifaķ6f}L'&1̨a%dg/VLw= ^]]3)-)cqG#6H g5'ȯW6ouX /iˋ @Sq; %d? xѯԧEz&Sٵ|S>䦼47tG~rC$a+uKې5xn;_-&\4o(G?aMd|g} 7:1I+dD`vL:LO剣xd Gw]zzzH 3:adA ^-+zPL'uFV `aÏ6C1xRJ3e}7 rB)׬σ)Íbg4&u4q$dKµcm\Vl5$8Й}S>L/ Ehkw=o5O`2+/rA[mz!P2XNFLJYTӘ~*!mU+1uIIN듅_hV-"g{tw%>࿢+iD/F$Uw* 2* lXvW5nj+O;;f/`YH4*vS {~ꝵ~֕Yi*Udypˣ0~~d}9eJL^O:$Pof6 O_68gsZ}/Tit} &Lb@S. ;k}>"e틎5: !O[OCcig)rHuR5dС ՆC/!F`WˤDžf6rn)e¿`_bB 3Jy w NKأh j%]g*f\+(CDy\!tm0,$o@k|{nJ v1J)xK,\AeHPROY7'NY53L wZnl!"?\z#Oa5,t Yd`S=f.**M Aͅ~C wݠ;",̛cPQ >o^5>ݓNOkw`5⻦P3*Dth'wZٯʢ3@=y::3RQ h1roĀt!;JpV/w6RzF'u7C_D؀-^le|(~xÒ z\Ȏjt&a@,` >ǵ{SX_AshulaRWvgRJh`aCYtfl O2zfLGgfN2N4 S:X*@ZNד$3݁qt@6D bߎ}\_Gx{)D xWDS719(Oپ$L4 䂑$>8w6k}2N|*\Bչ-a3\N݈k6gEuHw9HglGceM{ )>]z_l/=ugPBqK~0S\bTq[8ī"7xˌWobybRaAwe}(vtyZU_^IMZ|tT+|7{_=ZWW^ڂ] ,y|ϑ$g6ؾS'ƄZEE,\m| bgS:+&$ٚX߿YvBBģFn~ D\1d6cD_,I{< yHrwhJqqq`Ą#oK?jp*MR8Ќr}71w~U=v 5yPH?" V`ܖ B\oLmY3[#D8ʣ|7ɾD[땶ED֝As[ xg1쮰`=͢2B9ژ9_[M%d)J#^qJr@R4N8}k+R3*gu3ݔ5&NuP0@$' ʧPfTm'^(!Q*2d{2ps3.aE׮L@L\ÛYǂBNi[DoGf8,@4ծ:ĩdS+|ZhdK$j+an.#UU'[7op#47E5ẍ́:1z^{&]aW:#[5Y1C!H_hU[Y Ľez*5Y(v6' KpFSBvf ^oyWaOgL(|M' Z0~7Qʂ[ @y׍h)ɘٽ!ݸޜf|UB DS<{GrOF,i\ š=Kwg! \s,o}b(ׄnc2փI8zA|B &M D{ԡ*O=Jp.dO@g8dw;@:M= ^ |4sHdz3IfO c'gC}>K1aYڂRRJv j-SYFxLڏ~fUCv[>jq] # L1:~:;A5ad*3V|[(RAV>DY=]f] [\=-|]wP =;`Oco"(=tP+0nlXѪT6I::R'[I0uݷ,,G%IlfD9/ MλRɃťjˁpVpf$!۱L"SC?Dx܈Q[܎"#lNຑњ|&#cf`B]]6f {&]ƖV1O͡ 2x`QNUcrz_ͮ hj jK])fq4 sPgx`]+5fAe%|A!Ȇ6Gt 3 1` Q[Dn_{[cŮ~mWZV4)hFa;c_\Ƣ$1O({sD(@$Z=FJ q3_z4`QWcNXOm ;F:=~5hXF/*3E2x@lpw׹j߁6 ޛ><'o"УВKU\-(fru/«ۘp ap>v:0ցgIuT Ec ~CkO$r@v53<E )"3'LW+wK-$Y0G]a;YXf%=g-^_RC A/rWxc0d?LoλA2'8wS7ZpXcq8ݨߴ;PG@h̲Y/G1e-G(Wf}$,5̜5Đl\k6@ T$ zSͮa5.YVIsmQ*ZviJ_^͇˭ S+:weY@2p>ꋨݤߊ,ۉUUދݹ/,91fѰL9Hgp9"%&O%%8{|j[ЂPj,#_/Rүhdtj?jڳٞ;'(}҈I:(OiR%=j:iMj^'hLPeя'/bevP-`؆_&慏a(xbB3irk=HPR REo^et15iBݪ6hJl +NsI(.OΥ{*5X/Wb+zH~5Hj|Y 1y^F|@A0NTrT=oD]%~ތlDO.\LJۇ(NK!v}i둍 _5']oU AO'B=eQW&9)fJ]y|VelT 1d!N4S==o3b ߱[}k_ Ơ`[iɨ+E?ᅦ͡ â<[>dva)o?r~dͽ ;^L'r_v+ o a^8f#X/g>ݣ(+辱33h[ub$d#TʄS(Wߏj!9۫ {Cq_%JLkVd}{ꩋі:yzݡP '.jO0[KX_q?ywI4.P 7|[O?ЦYCqߏs"S%$  2snoGL ^懝E+8x 2|&Vu#dRww*\O.3JKeŢ;++3(&G)՘w?f;Ϗ!@5\•&qwwۚ616m7 o$z§HMv߷GEPM񇣭l}$ zi2ԜG\ X?Z~/Y3Թoz"%@Lߎ7T@ޒ2nOԹ$_`],+ZT?:89YVFFk8,RH52)GDU rB%di :,-@:S?% ^ _+UYL 1veNIՌ*΍v: .}#"Vcy) 2L;>SU6+ϲNq^}&7blT}@:С4滞2!Pk&. 2c*~{>ucK\ lڿNs+#۾yw5yW#@Gd;Y_,Ȭqϰ)D՗*t+K XЛU2WZڰUc"дi9m?.鏣=} LS[E?LB?'lG]hA:́CL1"X\5'_ bf jpaL(x:d<רIҽυ+~}]2/A=L^|KB-$eApuҀ-d )eȞ~M.Dړ6 A5!j{<[bK)DZ˾'1t䁁W8\GH-뀣(qpƦp˙"Fe'x77eEH{ nB};cL'2lOzY3 [=,~f oo`STX |D4'#̘nlHq$8+}=Sa5jE7I-5Lf-{ {Q?[gxhy.#]Do'niwHǨ|2gԊ%O|U\dVģZ2Z!"sjkAYMxY{5@(LNlo̔CظC< ,@,pd2O[gF Y*L蟣wu-NeűU)a#P_ aZjU72gNPxiǒ>]1?;5[Lmd.< <*4GN_0{ I+b]!*q v ;ђ| ^X[ Q/f=64\f4NyG>]@4w]x26W(4'py-!ra{rW3T=4XP{X(W U~qaw$'Vmu} B-^n;֍2l(DɁq3LִpEW@tݠ N J!h!x6:P7EeQ2RgIq~nY@V<.lesf$DB'B94>kǤ1ZqaAݦ[I]Mx.uְ^y=~ЙjGlAChͽ*AMׁ#daׁ+rI/Ag~9D[yH*C)o n!U×}ތ3)_VBxѓYu2QQrW02>A;0&xD) @x\t&rh#cX3Z|b-a LSEzŖ7draCdc-p\F&/'r<(huYZCrWd믮=SVv*P #j$cF4dXxa3=eY !o[!aPMKL6m4c4ACy n0dGۚ5^=<=Hozbz4YhQј-4uzpIIJ=P.* Z}͜k(6LB]?3ё44xHnVKODQiȟGe`~_6 .rs1V8> ѭj0,S <0L*: xҠ> HԝA JYp&Za6 g3ZK~BZ}1$9GOį׃  u$ :%Q^(#ZUz)TR-H|D;B+Dd=S4r,5)Eë6"\g#7ɥ+wX=돲!QцCٞKmZQf#2-7f顙5g\ffI,I/DJн=ϙ!PBKG?V^HP|<c9׫_KN/=!qPsGQb1H)+Oyb Om7?h,7u MSOL5r5@ pSӉ i x`q I&+D.b+ʀrpq)+J8!-h/0GHY.._ΗGȳH%, 6T)TRkLFWe9-z`YG4lGqRV:$4ؿK?Z_Bԓs EՃ:68Qy6^G=6|ژݺZ,]CIwώ W] /҈+PNw텱cB_MdqPi)P̎V`X|ijMIxf+ iN_K S_ilS5կʢ ᒵ&_sp_8ȚomW[%vۍo='4 D&iNrR^ȔQΆ2Egغ6#m_M6Xl hsP# 9jĕ+D,A^q ӛX"Oz)dC 3p[2+WV$K+SU'k;ל|漚-g&W kx~AX6.WuֳJ텵LfFKp ۨ!F`ү7.W%𻜍>r0F_ bBrm;*W"tMor>>(ʿ'.> -,lSV%,c.1&}`E<`6z)vʧѪ:0% -2%:(NͷmtC)Bxz،PL[l3=J:ԝ*{ t%33W;U\Dv)3I뇷@!<19 r.WEGU"DLD}5/c92*jW #}܎sk"WicJNns6Ӷ~wMt4HKPwtOJUFNm6;.k wR!x`17V+I)L' əZf}a)I"\ɮ]|O'AċA `ߝ>ТMRǝ石[Qnjsi~ UeY1y%h^O?8a?#B+"wGHwae+ojIK X1c`k9#jK 5 ]T0fgE҉I28C0_RhK쌡+ĕ/pVLto+}=,x?T' % a,hQȁ+ժ*vz}& .t9/=l“|*v&I'u &\mKU<8kq7!dLJ'!1>GfS9s(ɹXqQqf=9S z0C@d 9cT: qnܿF}j{Zb>f؋bE7‚HN?RssY Lt%-o2%SO` T8bR^ [zNϿڻcw(bc_$mR쥬vnGJ0i) bQ*0U?lQ z+= SK|RehSrPI}0Jk]ouY'߉3a'`2vJyɫ/4J(xـƞˍȤL:`߾G}.ޛI1.VvldҘq0&)ҨѰRn}e]p̀OWJܩ+T5pMftKEOm_4.AL ^ 뻟 wx2&F^-(8ۃZ=`1paxj8klڽ`~WNN)VL s7)|u(F_a΍VG`8ˇ%cWd(*MlE-JU= &BFs,1ӥzWMZ~ki- M18j30Qe5fGGe})s{ֳ t1U!,Қ˩ K-''::E1/k4 ]m“GUexFjtp]レ& PSɍ'$ŵsk=.m>^֪^LfXMe.sU%{[D7XDϷQkicÅ 2 O: QnhJݟ↮GP1 >>L 4<`N.m"Ѿ7._0:uL k[\S:Xa1cN)ZHK265CsopaοuBl“h>u_XQFiJjQj7WB\7 "׍{KE8|v!:`,3W4;lmP~"X8"8/Vj;i\xO,Tx!on9J)׍B0yQA51Y?B(D ^hI2֢- ӬزsaR$03[Nf>{PTŷ>6# ^0i~k 5aSE'餿KR!X Lf|xZh[Bѫ4ά[ t#Pܽ%Jf*n^8g/XXeET,%? cf5PV!_wX.vU&t:OL.RJ]j=?un͕bHL7TUBKĖ0UHYC ΄2$Zl]~Xcf(0)fu,[Dc=YJ|}:[aNJt'dw!\Z8HF:#PPh5H䕫4W@f &ڑʔk8^G ."N[_Cs+M{GOXeqlADJ^v{cHTIy]M-(gn~s c1 2?.ĪψNihm!, _X>>(ܧ'#!Y@ҕ|Y3P1uj~)3Q[NřLE.k LVpvLtܻn=+e?yfK\YFѮֈ;edDv1s+Ր5zSrQĸu͌}0ׁ{yͅR f#@oxىuv(la kJH-y ;,c};U)V|\=ݏ+6SEds i"ݯ;/ˇTd9}3(1LPZ9 Nk l ّee! f?gwT%$]DAp.O'MrՀ5;Ia^" &ZV Bzfb:S-S=&[}c2-@ E1FyC,ȂUW)|?(1h1~.}QLjJǓ 2>^@|w'+a4j!uzG ]\k U7'XRP܏Ce?d;YS)lw&_Rt hk&7[[4KRO8!|>z9Mq6ӑ8[f QR!;8^`{GȩiS@0rQБB6f:P-t!G0qSP`= cDŽ ݈g-X(Gs,@ aDM˭T\5IRt0v>Kӟ1MR2'iM],g&+{l\ 9Ne?Ӵ=~4/5pI.9EԿE$9KWq&H╹1!^J\I?!2SzDoV^Pvj:0_;qc2mK_\|a0c( z[yC&m.xQ%>~wD [Rxn֖;KZχF[|ǁ[ k U†&ϤHKRDbJy!َ'\y 7A/<,V*z"WW:NGgWyɉt4oaP/VcX'Ax]y ?-4&3{}{EMZlw/ /x-cF6ϫPg#/="X[7$%x6>D%%][ %TLE8ttTBepLe wڔMw|m=VnF(_7EeQй^#,'SpGNJ7Zv{JӅw4s9=צ&Q(wm+Ԍqr2<_,c84A$~umCFLAg J ȫ-$ݯk||ss |ՒntפrX b߅PД$yUӘrUA*%G?H%"鷡soH IC|Ո(J0sկkDBI8Y%)lx]X]t6# 18{i B̨,waU@1VI̅[bTr; 1 4_2  y#wYa)z"1fvY7Ņ]?~KٷWSYk*17A! C1 O(bE6?2gF&v&|&Hxj$x qH[$_8w~qfl{ݕ@idpLk4#jM,ٍMݔJɩFW~.,oDZ}څj/N`,QV(z ɱ@Ch ۨq$jfNH2#a|= mfwG(Z߈K nŝ3r؟4@s vVITN}@!Ӎch5mG $ K?%8SNrh۫v@VPLYJ^Kl4,/\wPle6~NI$5xS |l pcU>xoH2v0Df@DUz_A:K qq! s4#ʐVʭ’Qly7%=G˟ jj-տӒdkw ~=";J?9=)~_~-ŢFc#JsMw%(=gQPe: ;ۊ4 3eX3}ACco0nU]|I+ivf[Lre%)EnFY:==sSMtKAǼzz߬Cd+A˰@k S٩k6QVh IV~U#ho|H4z}2Z89 T(8Ṳ1^cP[aN{ ʐSmȋod>\j4 Z3qQB>'AEN4x6wkascC^"A aVfJ"fx"ȣ3<+L cr䗍nV^E%RGjßE3>e?,hķXSxyi ͌6MMHLh9 Tq+]v]pe BR..PsY{,khW[_);K^l(2@zQmɦW~lǤJ<NjUu:Ǖǃor#ZQm$*&SWn?`m%̝s6>`0.XEyK_Z [I~z+~QߋV\lm2[WXv\jU[ k#Â_;ꝑ7kU1I[ս(o]U'[BqAtd8eI>^B#Ҧ\).I$TS^rm=R3&h-qC[Ta/AbJsX\(Q5qP5CVk=Βt/<z> ~d홱5s˜Փ8b.czsq n+xo cmRHjA^a\l./J #M&?^gREP3^e-SZBq|ʃ((D e |œ@wE%oePǎ+¬0f..G1'0fu $;c$e|b"aut0t6NdJ0Wȓx 2;zCdž}Ug=d] {_ͅ7БcNin|UjŸ,*0rjB8z4aXT6eχ/ B߈@WrI ŇX+Y='7R{R^(lPQ;ag/HBUY7.xT1&;Cyf 4'/Qda -k EN$:%U.DDv ObqU)PbV Y{=b! P=-Ӯ撐zI3Tg?C[HK)#Q9#V~vnb]a0Ƣz(ԜQ%Ӎ?.t@[V/"P2-}_M{fK.';g,dircU$:FJ᷎SPdtRG7L4sk>gG7PfXB4 /KЏ)Yp یYZ @P¼ktr3u,͒IY^?'xn]ڶ\ؤ$KJ~BA][l!uO|^ql4Mp4qKsjQ5O G{)/ aռ1Y(n|3ڞwp_;nzI -hx_qIE\'wn&%}9>;Qʽ)SI_db&x0HSOV(2R'O0;|Boj,ɳD w^KvFǬ6(^UnPIWTA4F9U,w:QcgD'Z6ocϪyyrJ[R$[VHLTk/Ԥ6u1QT-*EL*~Dtn>ڌ|'!7‰P 6f|#u^.[ i6J:J3UӘqgbM }=lt)(H+?VV~14 bI0*"h3.U~-|HiƷ7z}T|LS{K=>B@opNBZUuTNOpj.S`.CmNaR)O*J\~,oH+%T+j̑6++ Яu% E$ŗVd="Bƞv~?(er^>k@06r;1ё0VXrڦⲔW'ʚ+4xƧ VBIO5=ދ&ayc\Q eo2oؼ?#Z|PHsԯ 㠤Q1%p s_GV.]8 $Oux%<bvdheKZ`Ëpa 8֔E$o7"VA9da`,ҥPyOcθa J0뒰2.A#G9^6!:|u A)fK?l1l eá.\G0Z/V~.¿ߊs1::NG"UNt~9? cf}2Pgd3e+MاK>{̔5RK_a)B=<۩U@J 3N9Q`۪!s{0LÏrZ yXb].+T['dZ`%uiS4fRBA} FyNrfk6~ysaEGH [* 064A܅_#PY8@\Ȁ4oRh1:!j%eO媽0DbXӚ ~z+ rV`Lr r?-OQR Lm EVvI39Om I:wNl7R۟b\j+|A0#U;&%| r.bZǼ&![jT %wD P1u}J&xu&9:.Ȯ4jfKb/D46L匨6¿e,'=pc.O\xKKE\7A׃%{i֓p,) +SDҜrdZt(|8DzƁew>cs5u5'ڞ0qb1r1fDL"e3g~aCsdHEaT^Tn|0O0͐v"EӍ!{?8@J?!j7*< EB8g[|C@Y$^!l0~)R*FͽfPuu'IaBv3zYq]']]2)9V#1G}cJ vV'uqP-1\޵- Hg|Ue$9 : DqPAS]SJPͰ՘8{ҍojF6T;0f]f5ԹG< Z*͆aQhJp}qSb3Lm/?ŘV[: 3S?sS@ByܧTnǖ *ꦮ{2~3RnKQ}fK6v+vi#{t:,ed' nc߀~53)_LF'FWqv8dyL(**.Kf 2eL7ޠVhxdh-9e.h'D3g yƳf!1H\8iݩ ]#jjWg KvXzģؘ޵C6fY*D_T&^e}}0"MgmWS2ҹ6REͨ.!wYQ|E2.7 ZدžBr,7yžU(\|zl DyQ9 Ӛ\]>x.u.m󒆚KK@Q;pxa_bz(r6Q#3%hѝ%٪Bg@ C3n?VI.Ac ,#T"k%z!i)Cv6:wV6glS;ns;Q^ G&ii |t6p' (V7oyQ#g3UWa3?np)8ʂlwAIK\ !] a1~nMիS1Ff<}f/ƗN? &mBRyfq4Әpn>.xvv4%DBVغN9Kfr$p["kJ?6 OXV6KN.|$)_\{y~(tX~)PMX^j07Ӑ Ezʹ-d~RI,v4;U~YDk ~M5!j][TH b6"{./%ܚQlE.&r+D!I'I-6655(KQ t0{K( Қ4]\|![A F/sC=% ߰\趮,4w7pAe Yb]'S=>XIZPE% 5" :˷r[r.a{Q` 62".̀ P g5i_SU+$S?0n'࠻F`O s0'u5!?$ NjY"cbl佌KfP#p蚹8;R*Abdࠫ?h?m* H\W\T5%l*7Ƣҟ*0Զvt"8b?bJhvA3pxJkXԳ'џm[1-ebz`'P9%J|5vJ -e?پnv Zygw&AN 7$ފP_=J -׭fl>)Yte~+[}p s;M(#NxjT%#s(Ԥtuuf_Ô'ɕ7 5,AV^&O>^^]A-F1m8:% !:˴^vFi.@XIOe̟nuEoxBd8,E\JW!y[ 0<'z2M ˹yy#L5Nj4bif}mwkn]mn@WhJi$\Npvlbh(¿)BR4f UL̢ ?n!Q4檭BY;f'&#nWh.䏅 )~, Cڻ{oCBx4g10)1gټ~3|]ƞVC#4WCLZ`hpBɧ9f@̪aӉ&~nT+E 9hb HzKe@}rTϘVS:R ^uEɊ'KTvr3*,+h}1dZz rXИ›s~ltM@"XI T<~+P2 u)G݌6.X,I3H>;\#h S=+0Z03F<@K@0JWuI[ #]EKa ڤMp>4rsePxٚtVc f7IOqE,^ItwVJVFfRunɛXxکR|ux2䃮O@,ȕVď5篗X>i+嗯 f9-u+˪>S$I v-th,6?d@Vv!.C A>yfim^>CRɓs'X mIß 돽wXIQ86fAgOC #qfI|X/jLh3pO}P405(n:(%ʊE@:YJu.T`$}i=>M24 #y,rU j[WaJǫ.Sd8eh{XenPJZOXסkUr!1X+"n4% 1c43 ><3^1 6K*'v`pl/klrXƒ'iaL4^̍xs= WRK]!fp@Fh* <+W̋SKS߿jP+;W1 :G.d9Ч<Yp7R*`{HccAC0ACAfG߆R$%b$*o'5 uZh&ۃd7 ?0W"h鱢&iNϻ-H {֐P8|..Qə}K/!7Eœ':~ɕo WtMMw)ֱ:\7ޭdfDh%>'̭ wJdEZaJ38a䏉"°25޵j-YX:pUP d+>sW)tyHjײsSdM׾L&_ FWrnKmPXCJ;%}鹵 apKEvZɒ:ݠR(Κaì:Mc)|c"r$c+4]X`38Eu{\;<J*HB(r)XP1IA+%\-!4+V3YhDYTg)jHbDQk`1=ˆ-Xm7:lIl}YJOsմ|ئ$:jaޖaԫ/t $ w#_Jm`:F-AG'lR*FoNK]s< b"H2L2«_(zN=!Rj AmALTX&M%#Ip׵7yh7x oml5/[R?wړ:rӯ9QRm61cg[ې7sK:D̀pB я ɞQOB=)"Zi&M 7Z\C-gM n!6Et.<# PBx=Q]7A λ>P=X% |Yg:>^#4_5ҹk7IsecTm7ER\ь2?j0dQI>u .<% RˎX=2U[;|vM=H,A ; auța>]ҼwJgFrѿ U^ 8@<71VI7)v /`3ADCRr. M:YNJ֠e

"zlJ@T5P g>Nr.eH5^JذёcTSqΕ$M8._B^K(]J8'WLkoUiV}@hpf<̼ů;ghf ;Nɥ`V+JNLbvN0=b7YN2\2ӹ@ ~X-i|&;|$KüRKV23 $vta^"m`)\{]*BtYIɈC5hNE-U]Nw?ߞ7S'Cڠ/ yOI<9jpZ't)_$w곃VMf’-^0|Eyw*v0&G1/f:X% [ْM|WOm kMQ9 (Ù=l3 )f$KY7u[p@kMVFN@lEC jt>)]J1|gwڧ8*2=!F01ZcyDnwgT\/, ŌScө*y">d݆43t/Y!&|by}F@c®?D|EGzۅ"ev|qᡯעNugJ&ʪV9D䚇 @ 0Z?{ ȲAK|J#遽jҐ8+ = ?) au\Os6B9$)CW5dSdA*P79szGXc׵S+dxQ2QJ:"݃j8Qg#Oe*C1$Sh13WUǝ91oާĄ-vrJA8`-*^`I/sŠl!X/_$DF""v8T@; >.{wdO ILl$pR@xGl^"MY%3+t{} +:V y94o賏 fo \q@C\lnˏdg㫣j!b'CP5݇'/$*3A:An?y7Љa ^/1Js~ݍUW 6e_{t\:KKզuzX0 b\n%FRwJ伭7w9v◣QB?Ч @!C 3=XxBB1~~gNO SIÍU*qN%J0+ rod7Z[bөI|Ͳ5ym+4%Ӑ3D4F; :~yt.фs7Uz ͦ[h4O2.{CP_ϖ .LE#0,T*JZ c㺜H? q8k܏I7݇!ֻS8 -q+ N8,b}av;}/n'm3AcM;UbWc# JsVlԘsкv`LyJZS:${nY`=W t]u&/.zX ɅD]oDylz!S[mĮS|f*<8~Q8 g3!2oXU)҉yQR7~O!'kRv.7Gg!GC nG2qSN0I7\ K>GkZb/MPI?SмN}#m,{5Dbn4alwk\z?%jа~ٻ6un˘fEAX#_T8BӅOlU!)^W27wg2%O^t6enJT3XqSsXl5"L7443o%:CP\sG̱A;*GDʈft^o&؜_Xk`p޾a⣫1RH{15g]_i[ s!Reoh/Ä?]Tg+-ga|mr9~Z^"KN[)pw4 ă.N™سR=B,cڲ}(**k.g:1ţ{_tZǜWZ L8/@#hp[tͲF;EOϡ.Z/gaPҜ7fyͪ~LK#d,?VW$ bcc-S83;H2}> s>S$l۸X8Ѱ{CXg#TkېE m:fN?JQ AjdOF~uC14O% E[0JW`G~hcMugJ2 bBGÂЕ EWs ]sS6S6uHcTy ng8@CsH"} ՐȖ~n¯g 2dFʒa9FY锵{g"5hfM*"Q`_$G; d@Imrc}g Ft:hKSN"ov]co(=;BLS^4p H8Ԟl:?U/;3s T. 3.x9iǽIW&N++!r VBgU]Ν*Wyմ &FT*]#4g\6B<3.\W"ziZ26Mox<PE΍0 a4npx&Z:M^:WsgZ?aW~}81G)PzĦJDs:?"rr&\Poip+Jn".:S&axŕ^QIOo^u/RNInZѽ\ G1]߮Œ˼'v |s{^,׏?O6ќF<фJMZe!.xwƉ=~LTYW5onI(n τF8czXC v0r=X*12AaK#swD,4"e+'N}< 1wOI?f+񐟫Q^rMG6hg>p|e_5Mu\LZz?_C,~3bjmEvѭDz)Ekkt$'E]~C4[mӽ౷6qrhGY53mE\!E-`\p!x_p}ąn򠒋TYZ3zSwP14.yqt&qb.eKy<w]orvgZtvJ&4D6G8cpJ/0&V2Jsjhl ݈h3x_G>DQ2zB{ ̩ N9fޫy͹} H1r~m$w&{ʢ8 }tEH:}50X&70v|t:6hLF),..x_K(h9؁zXU!Ф@Ye5a7nBnv Wf vzF((1QikYJ fQ6ё2ep;ÛKsm$^՝̠U[K % 䶫4yaub`ۉ>>/COzq@o "yehc \w<\0ϱx_hŀ9b<є8xh3@͖`"6TߠD"s]%alP{G;q  [Mmzmv҂ѮLmI_']b:0oP~'09,R< txk6lR@ݞW{&ƕVB`6Y ji`ٽ5y+ b v gQw]w+'ǒ[9ZnH)/MK|z5S8pl98FKyzZ2m).K)UH|o{Ŧ<#ʮ})| h2u6pv.Cl%%ܛ29PƗ2*"SLgq%[-[zt_<%$r?'K#  BWn3,agQ;"D_<ƏJ҅GV2ĻKS7Ŭ!U0~ZYr\ q'P>bm=X!I\#`@x* \޹Wu>cKk#J B"<7Q;^[/נ$=Lo5ရIV]-I.[WZa]c)>tL}T3-acV''ŅlR-)Pv9?>e 3*!#QlA^{Qx`}Q U8OYN&]}cziOp^5CL0 \BKˇmSGj3!#C]%{J%s8la̒goްĿsElx+?kuϯZ,|Ypʟ>{㚼 p5Kd>䵒*?U~Sڣ7P^~Yg:yRk,bàg MH`eu\E> [-Xl@ltY s ]_VQc*?B$ {f`Q@ȷ$Ε|xSly(SZZcLe5{6-ځv8R1LF㛲 SHt%h8ݞa t svx4^GLA{ ċ64DOSufy!}}wưuRtr7#LjjĴK32E 'Sp[Do)4Ntϡ v&NjVdp3Io;zR >*4HRMcP 8tNJݓK{]W3C8m'M 4qr~QQ(Lȫ;Fрl[ԉt4ueTS+v@r*SiUR@>2CpIoqm QT"后q,JދR~ik⬏pWэywLc<>CfkjQk!tD/,"[B&ЭJHt9iJ$ #-FsB(/)(ج63f"w.6)xQ nJIfz|_ͥV\VA 5[:(L8; (/杊ϒ*6wLox7pF2^v?7@(r(ʻʗ˦C9pgXY?S|,W8Tu F'}٬rZtD5=&vo՜որң?X-|\SĴ,aVNdz AW&y7-pQqb,LOEb< E+>0jQpgh`.q+$j:_D2f}ĎA12vZOu&)) L]E\+ N㭶ww bicc^ `I;BL< e5O &̷Mp5J8 fD܂(-^Ώx uQ?{;. I6R#sFd"T^{V4+"6d*C(VR0 B_-Z~[A ɹmȢGV#ٙG๑񻯥Ώ{ʥN^Dn[c5Xa/I[+;{ UuC [Tv m J,u(m?%Hڪܝ.jhSpw6p6$< vˁcU{_ϻAYX#{FAMtQF^V O9.]$+x8}ERVas@k7 T c+7VOQ;4F*f,H"f!wH>Gh)=wGkó#v)LMIbhІIaAE f%GsMxϛPVS:IMdH#ŷ#yc3p73Ñ@*֕%Ӊzuխ @g5>?T4|.C𙼖cv4<4<'H`EP?znMhig:ga vZ}./OԨH}gǾML<#4{|Rkô|eeXRQXy3߉1Zȶ}Tc}\Ij;rmn9hѶ6" \Bk栊|rXŹx t ʑ3x!G,q9n^|?Pu.2kЄh E'pQ5QźP=i:DI뗆H0dֹ:NET' UѶ$ #dqE%Ta%|9*$@ͯ8tx^oI y:/. `IJyMr:1.wf CjEE+yD7@1L~!&f{s!|g`yvNt+|blRW =)ݗ?B|i5l!!zM5SNK*ށ :D`Wʆ*4W=Vfd 6"Hbod/rP3jVWt#{d)r׍{{C )Xc-3Y:+ 6'sCTDhn=%_5%Ļ]1riE6Vp(!8|I~2 J ȓ<ғe\Jƥj2+S|nXϑ q:ɟJkQE,(Ν-ՕiQ~ 88h];f>H1.C}"NLQ@2( 0ff52viߨ;>cՊ=}y_:ȒKs3: Hf j$K FVɖ׀8KDUFZmNI8^'!"h5ׂ7!~fb/(Qw]OfnX[ڴy=% G-:!C9|j~  SkM131в$ ړ-=Vֻ T+߄3NCl%h:]*y;bRӝ])rw{p&b_W ?yBnS{Ea{k?ܥxCh={b^~ר),~䞾HoQ}|:fO$G3OE461KLGn. &PnU682iR7;Kq 6nzvp;(fuWϣ[Cah|b+z*_'1ϴuxRyb٬4ER [J/:\\ṊhQd-hhx( L^s@J,{6gte$:8b4ԏ+9@g)W(b9t^ny.<`AuzGa,az] E RݞSfHZભT\yb? fcr.d:ل*賑oKls&2ŪY֬Qh(F tg鷜鋲CXNdA5L=Vۜ,I1{([#I"V. (Kp^mM1z7š1ա! eԝ%y>c'#@%؄l1SҴ# jl=k`fb;nM3 .f=3i0cD,oykRe)jn9 fx` F!O-|bTWmhiΗsp#pS0Yg1-!@RC"t"vSlFT϶?~h }Whyű] ަlu:SnMaQ&a\]6wu}=@JdF4BSM&Nc A72OO7/7zY62Y'Luf(ԙғ +P(aBs,x>F0gސ &un#Ree;-FRƬG`~  z1%Zr>6&-\* 8]o=?7/2`f*ЗKioNܑxȔ;" |̢6vr̖K43 zlW҃M)4.K;/ģ~>Rҋb%'s 2ww|"(9&S3nbٝY]J:!t4B*$W-e;< 0]' -?rn]b(y<ƫbJc b"Ku[K8Pq`lx/B*c2:W~F3<: ,zt=>}49M DN IA')йjyTfsPWeK #7Č}qɦc8 s!62FLڨ'4JI 40hXXRͳ=4^}xv`:/PQ=~qܞD2p'xNb,"W)U tPNJ=SL_C37AHW]~d-zJgc ~_?N77Qק L_l ]c%zVzu#q , xR0PjHv<4]EDG=,dJ۲H.R*>J06lUF\d!K%L.@i= q2<@u3ؕjƄa } :XhaGw˛ xi@r)nt!\G6pV%[<=T-St-k-z]Mo˓~'s= %tdNF<ڈ$y\})9TlO-=p]FBQ.%U^dmwL" "ZXBDv㷚luq, mT @.n0LE ϳו wN6n%^>|ƍ/QZpړ]TkEh*ѭ=\_wA fHP,4f+i ]"ZH<>7dBsQZ31,4f[LQF*^49ȋу=~6jfNv{̤!BYR@ m_ߖY%D[lsG]S&cN;m\ LSl@ #j -t 8gGU hBq#f? pu_b(ǒPV.ˎ_4Rw)Q"#D(! Zvժ6{RCSIw[gR$Q>ϕ*g‹$g+븪q -hsfKµheC 8¹sHTfq|nԩQ_v+|I&EiYDIF'QDi8|2_6 $.J̉5P cHqK%r"-Wˌ~|?jgi9w!qƠL;SqAڡo o>&y2Lr]n-RTYot&F{Snۉ7wsxaI+f>YkiE( S[ߒKq`8c33?o-q!j |5z:'D%k qObK!h/y%Q`~`ʬ)=[Xx:8; RHyS2̒ec=h1aX) ZM!K"]$ElU0r D$z$/:*7T:p"Pz6ۼk-cIkfJ59ۛҊ%uK]os}'5yE1SP(ڂĒ#kp MK* HD~Q,2QWCQ "#} yG.:w+k6yԏU!훻2Ʋ3wLjz :Nx?>?+HWMI ,k_'$h3Y;S> ӗۺ@}EOȰKNNV>je0WGvDJqĥKbq\ᏺCaz .o)ܯ`j}Ir ̚CRW$W)5k[,Ua垆m37JSi*o`r T)f`95IExHA>9gZN< ˝OE {N+ 㭳Z],tOt3&(-Zs[o-^ȲTF[k_5 2mphxWβ Hi>Ŕ:gN0_9p~>ݻQz&]D["GP@#RcEor=;F{4Ne;PMɗӰLm1;z&b^;$(~`uyzh5T;cQV:s.h޿i2X=}zpēGpPB̙)BD(r\ۗsŖu&ZhLս#bu$#: O~j Tm䂷G9 OP,耖9> OU\Rvq%rNx*ܷy>fʡ-a 3vی1hyx.OԣD^z jO"JXZ<je!]|XvVO`PeHCcW;3q{As9Jc@?(P3;U4񬎏:qQzŻ9#pJK.h's0kۍrQVhnmѤpUHOgY>r7mb(IDUB^cP$JaxJ5eIn`{RFD{[EO1u ?WqZǴZ3qcRa!TVtr ǝ=ɡ&zdU0=ۏdZAy'"Mb@Wvh/'nIśCw4H<IUgV/nɥxdY2ŌΚFh:ꔯTuN(<~nrNpܶEf@gd)=[h+49KB-!.i۵G8A #$@~Bwe}</GHbXE 4V=#rE/!Ae* oe2\Ro{XFWXdBSb6 &Q檯elj9嗱Օu==QȈ)PnCJz [wjFpeFhXքi,U?L5@Gy'}TgSQ]GQe2:I/a^1W-$2jw7G0sW|Mճt 06eC"d\]|&5sH(ws z9篳ͩFg V^1 U=9GؠX 24w)Z{5CA`vhd,N &{*sE5eq8'STt 3NW04c|}H[wEz/)J|=RrŢ25LjPr+ufl1qn ,9xUw 5(X4ܮ<(o&DV6 =Y8 uoE8H\-1Ǥ11g@i:L4M3aS1 6 D9b*/R}G&w"IRW% J1Lэ!o_yxJR!7ZQ;`*z;'aŹb2 q5y&-8 GT_?)1>VKQ,=O^ywR-"9= r*t?GX2/IP ӸV:uY fx@H.=mܮ:'Ry{Egb%;liUjM.|d_;TUC9xlʦ9\cn?e;c/N̍;ڝhL^~ ^EiWߩWkUz1 1%mm1H+WnY &~S2K*2Y,S_ٙrT/%T ~uPzF{wdh6wf+,ډ*젱32_} Zn1CWȿE\)( n('}|:JOR~ =\V X>U3A 8fq r|39`Y}z>51DkVo1p` 92xr.$\r=q1 w+t^8 |f6\<:E5/芶B\XƼߥO o\}a=JmSMY}91[e#wȫfl˸Itp99kXh6BT\4X4ֵJEM*;Hn^*˹i{beQcaQDҫ+K|SG}X1ciK-""Qb Z>;U)Ȝ ?Hӧ78y?bk`,'EPp:3j[}iV{8/PMsN\VIsӿ}YNUĵ:4olX+vBk'Ġ>_Y:[iHk`[zWn(6uhsJԟ3]?Ps>/(MAMGA+R y(dN&x5V;QZSc!UnL'qQϤA#~ۤ|AK(+r4ʷmޔ.ԗdd&R[wY&Hgګ{"~*}Vs2WO G[ȺatHh[R?e|XW>"IQiwѤ^az"+vu%^SŃHx)y,y[Ą,*kx IFQ~ W-?mă@mcvu*G vV>s睾b~(g bp2m'E|и;3h1)N3tvAڃr׼E?ՆğA?Nz\MRuCX3!aO0RcUHs:)~z$ _xJkO*'0pFb% 欃p7+nМB;KTEo CIw–vwzwnoWaۮ/[7wU/Z^6ghP!˴O!/W0K?=`" vһ7f>63:bY 8="4R\&d{.L?Kjm@^~IOIDX!q}<)ڰ6 7e|O$As$mgR~뇨`?8Ū+{xƧ8ޛ)\+:u}O_|isoZ{d$_V0֩w:J]`oիg0V3>ZfB›fGXΡVq)Jԝaݨ= pA%XK' gЦ2YW)ndW3_Wq)l5Du~+5zC 'aХqZK6oj/e~|1 qGjoWd둣B)]&i*ɨ&\&^w`vXTY, ]%};\lD _? y1b=a9A+$hD>K U tw . ƟXY b T$GrZdQQ ^Z>qܕ͠Ǚ:${18XTi.O9VKbIj{ #=rj }JF&=] bɂKϿ9,Zk]b;9 |A*a[:7Bv*fYʱ$o]u[y%FTfཅ@:?cߣ7C cVn*H JdL!%,TRԣ9EAnef2,Kg(N4N^ a(@3 (/Q{ 7i]3R|E*s6(3;4wYP:577*gX!ъ:y>Lnze _^y(Ĭn 5y>X(o;( 2w\ث4k/Wֶ ׇrDo/,> +XK:hp󭕲S5m`r)fn[ZFe|ۍ}W٤%䙶+ I< p8oDbi3`0 +P9eoA >`&GhjG8x"1.lr ssYbM,ۚ-Z 3<:i>m Vf]/67#@Å yw ն ;unz hF))k Cl]Mia3՟M9% hf=lqwI6( '+ 5nS?7{aKA )C eRzX{)NBj;m7ègԔo>>ӵ@߅ y}%j{K& qY&QTj)( '<^1kBl|WuĻ֣9eG2Ab2Cy l<π` ϖ3ZP?k&"g6 )rsHߎSHQGi.ʖ~ޕl*iwgCi7F׋Dlh0u'n|nJ]a,Ń 0[6dtԒ ĩ]O>bV}K~h[[(!佬_E;n< lL^ X+,fxLUb=U7{aX[%oW%+6K XY\ ޠk -Ž 3G;iqaA r2MťepM/%|pQc'%NxשyK#)q<2!`v򰯿EV.0_]Tgo㓕0wPzG&ԣI{3oKz/uMő$L>`6]~Xrփ^e{rʿƮ]v/Fӣ b=auǜq|,ݐ 0 B$ MEa m*3\gMLW}FhQ;yY"x%aUdI'T0:.rXl".M`P~ȓ ܓGmnebݲTd]JwT~+Wvdp\Pu<}‡dӄN~[/yX-\@.A `7fpE[GV[&aw5lٯLvX~ipLQS \aQ(z$VBKʃV=FA7.<;E oZ?R-\I(3@3ʞq\꣯ Q=풛 M|LgPiΊͻz8e8dރO F. d۞wx*co 'EcOw-:Eוe7^D# N6(GsfN$F-L?$%Ɩ>U_B00!v'׏#횶n\6 Olnf\ HEp;#nm~Ol߇%q_ᏹR,Sg`HXGTpqwnLYd08~Ĵc*ij Q\Mَ%]܈WVLG1b"Y/ڪb-Գĉ=@V.W%R s9Y M$BR8 o5n~F$\Ri~̳_?N"nPg(m#u`6&E:dSqvW~bCANZyPXfvFa]M5'9Ho"k7bOaJf׌ȋ&*ǂ:N0K'l7 {ŦS& awt] 6Me7eye:rAmƀ^Nsh;'sMѦ&H42Q:Wɫq_I4ҁfzvY"Z`o)K8Y: R,z5j4R|UK<ضٚ7ԅRXqsX׾P!&x4q2>GƁ^pY1~Xa_/Ir?D'9fUrl5F: E3\Jyо-MuT.r.]yE@r|bl0~o ~ެ% ޫ1F N1mX&B/͙5 Y!z慎O0BҒ?z?Q+g=Uө fh'Suڒ7"ba/Ŭ>^'BQFvL&ZViEJ}w.8U'D:+m_@&IJ7OGdSUMFl4,MvB,^NI #Ә\0R~L{՜dἫK$9 yP Ή o>9CR'`O 4P|M]^LKj൨6Yh}/L D` \O{$O_")w9$@"n Ǎ⋡B3+$z2EӾWo'σ9 AD62Lkqz%.t9 PvvNK*eVаƆ,APܿ;$؁.Kp\Y#{$I~[|^gZCRSmXlgKVp>QûdFcZU05꼅1ѐA@wO dA{tݬtMw* wKc5UJ^uvw*ZC>~ M?qҞnXNٶ?Dێё̼`&yJ5bfmx|=jo}7ն+i:W\4"S(Vck>ZϹ+Ivnj,>D9 Y`W*7׆TQ8~Y1*h{F$84'gc4!,߹>r%n}'Ϝi{TqL/lYcǸ~R3 eШs&uj҈U'uk6.ДrW\Pp]*O145]6:X deݧXab5@9wXc8#$4Bx8.ɆxPZZ~J `^C׊<c_CkfpHrL W48V~5ܒa p>%BJ{4 4يn::9@9ߚJ?wqTYݾ97~d±tq%U{3ߔ*4xWu1aa#p!AbzFqJ옎azcUqgJݼ=ȑ IIRwz1iv)vW]SEJdGE"koJ #ֺ\nFJc0:Sx ֯Az0_P0nE]* .rq VƞKyPhdId+b?IBMAw 2n~Y^З SY Zb$EbᲱqy"&XoH@-iWmX3"l2#*FCXnD'/It^=[R L|iԓ8ʞs{y b_o4@bofԬ6Lxibrv,L*b \m9WT]Ɇ.lwl?(߷0lmBSt5c}E̗aLcB-5p|+yǕ' sPXIqZ, kb'3g M|7^r4EZt/0*Ղjy:tZ3`G0+ND(V̍?!E>; 8P5@wOwqޑJ%HGt!'nSE >@VՎ)ࣚ` &{[jDXU3G('f,džWFГŤo[zL?*]*Ў_:m퇀^¢ZRjHNsD]Tr_F= Ì܆؀tgiew*Ȫů1 @2iB +WcCL 6OBNg6?7oks簜Dc[H@ԛD? xVtfйvvWtBeE0AF"|ƚMM@Y3'C49}H*FT܆/e($D=.mZ8V/m~B4GI-}'Wz5m_ᢷ#6װf6]V=->Va_ͥlj6{"_ ȕ?N]"%#"j0X #+D#Y1U`{r>ĝ41>ɮt~zJst}%UK& h?Π (Bψ8/Ҹܵ-hVYU³4ʋ$u}4vu$\'II G>U-WƜ5G@T6~qōtW Vr $u N# JG v =4_P Ʉh M#(lll=!r#l".oZ9"erwV!eBBDo%{5UsdFIԨ+>(HaGܽ_Ab(x} U8VӔ?]Т$GdaE!78tKk|.lڟܪmҝ҄EwṞxv3r^p,! 2 PЅ#u/%[1Yr^3QmI>{—VE|>0o/@mElW O&X@nS:~Wʞnam(*dHR8B#qy.!^|F3PX`J+6F4J%/M)=pjFwM5kYP^G+G=]$Ʃ3p fp@2 x8&pXhOI5e3?}Y3嬭]{7MD9[y8pxA3v'*-v8o ]PvF3~`i[<;/'(گp􆲒d|ѤE0NJWWr.A R+Mلhkmk>㢔`Dw՝ÓoNTDB}5gƙi T<kFa*h{lC{CKQt;T0k f8EF`8Ɓ " >D)[z8l? 04䠨Tn3ezL5[ǂ3 ?_Flmؚ>=\h[z̑y2viX0RƘut[KѴ%c0jt"JLlO%_(bQt}|ketWt>L%:?qIzdNT6I{`u0kR?\)ʀQ};Ep>85 ))fWJ:5g$Ypd-5]~˝'@ϰ}kޝ0ݘ|p:)7d y{w[)/-Vz}g3Os H  ?"!Wab$ytD֓/lcBpcdնL>~Ih2 o+\hm";OwʿJ ceǸ3`و616xwkT>s'ؐPAnBîvrK/йa㔵; +1踱 ?7nGTn[9<6imRj{b (ZT5&OR ŞU"Qu/)*N0O?MIFH3!l(]Ecַl~.+lWbTQ$"Mc9R?OYDr+ gccH׹O҅Tki x]Z *9Nxϖ-Ne-b62IبTcf'[۷&n51[rr))&ʢZj|h#W#ޗYxxQūa[LFĤ)y9ʫۻp՘ yq<"}CɸR#I){pR6b;1aVc{nli'iݽ]gAdS~$q WȆ8 \(Mz@}Iu9tY)w "9bRD#{9s'+0 `JOQѦb___snBn$SH3њ!KQFHbb(^<[i)*<\4fSVdK~-7X"^i';EN9Kb ymuC[A]yEcRcuZÛb؇lU6{4)W38T6d :њtqT?A1EC7 Ϸ{{?l*=]@yf/kb2R笛Bmfh -ڻ)ױk8Fdo fkAeyx}ZZ-K#8k'N0~mpv<ÆWaOws]e(| aO<6Lmk5[i @NjyHܾ-Ej:f?z0H$4(\Y*H=r~יhP/[\y †krgւ <_:r9Uz.7&Jc_uҀeF#ij`^2vN4wڸLN݋a?82nbk H`#:zAV0 !!f)"h*ļ|D2n5z"Qslb'Xה3\~cnw{҂9nX XC9bbpd#i3714C%zi !}?42c9)G|{_ÀFV̆ &~NuV-+6EC՛ *j 1%ȱdFoa]e*ׄHpI[ZCL&MBSZ8Wo=@״(p }!fW!:Fr8L\oZ٣ړ,b@ߵ*괸J4[` W8b]|7'He vq<:qr<&;hL1.@XNE*q?Rz'،n!Պ@`Pih :[ԗaw'PXH }?^%l@biT+Aa4A.B/x!_{0Z<̚@^9|rN7na1@FLIaQ5K1WSsuOr\u`Mv;-蛕% ~"uIj}3v`1MIWz]D/aP-SJp H`'tux6 ѩFATI$?_z$c; _䋄 J<N5{rrVnM(])ia(0Ţɼ 2c4h!D k!Uv.T"jOiJ i>~%?Ij/(i >+gV7>a0㦒 HW5y%s3sy^Nu,lD|߯Jǜj8/63-rڼs?a Yah* WA-ПN6m h7Kb'2__dx9{g[tl1Up"Ω]F1$QI2108Q WL~vz~'h?O jSg3Mt=8_5~_ϭn/& &G7 U/GEXj8B^QTڠS'5ȸ\Nma%PTG䠈Z=nh(۱u[眫3Z@#n,V#kwԢJttgj;AĽmz.M #M`<sXjfv^Na#]br}Ij@PmI[,\mlcAp>50pe+%@i)ӻG2UG @<7# 8%yw1cFD)}ڴg(hYaBy)1foܥ^o#0oWӏKjF+}@4q֡@1HP ݲMG$&6 BNoEC[̱6Sx DFI:e7]lxEE  —m^!=UTxm- l]:J .ooiͭ ؚc0ps~;ΣxHqd7ڃ LyC_C6r8܀M^:n>؞%,|::Bo9zj뤢hf=i~ 8f?OAěn!tn\qe0h~$q َRc,Wu-|,$ՠECB L@G[ B#;;F-6ȷ90ңő)$Ҁ6s9 ԻX]n>-(~V Dl7$BAR.s8eqʆ6h84ф.6 0|)?$$붌}^`AOO9+D5ۏ<3:= T{9()Q. Fo_Y^%7ϐEnS6"EsV!cW>fO||j6@Nnkq9}Wk.x߈QnW9*F (aZG9D~ %BfF$PX / Y/Ya!?0ֹ/y}kд8Ն0;"jWA?X 7y3OSJk?(CSHM {gqx$F"u6-i UR.ѧ2w[ \ X$BeS>Y\1M~Y_K$?jvwf׏i]Q<>rF.Vdb􅈍zbv~":"cqȸ"Ik>`uZ"({eaWJ$&ӈ 1%4U~K7q#v7Z.`a}{'ϑ}w! 츏pup56/ARoh J3^* ЭxJEd :'7B?0m2!ǃpc$׍r8+kIWzQ~%WBh}ng|nEX+7S@Pg͔Prs[no蔚q51+fJW s "Z|+GA D 7 (*3ή9` rGQnۯjiRm Sj-vkhP X.E-=kh=iB1L~"d:&Q4f&hv#ԶՂ3) Yո˕B׺૏!x/"h){;e9Ft_z%7@7jz@RJPS('̞$".1s t=_a]3ۀ8ug)Hb ^ڠ& y\ge+nhXD:b}JZȠ )Tn\WWŅBIؿYfみ9ռ7vG10[L)G%T ُhn^E.X}fcu2fS0=}8fScn4TzWAmQ,)HkOXo(f,e i$$b<;65m؂yݾ7֯lq1r,t;9I׾RUX =緥'/3GJq$WkZG.jpQ?߯d$5T0l̽k(\C:RCІѕ Cm#za;胂6%őHC~RG;].Ne(:X5B0_ 3ܣkgW /"@0!O1 y{ֱMnGI`&xA{=@p9dÇX:db驏{21vuf %̣mߑWl}9pCS8l8dJ"O><o*9A dIXi?@dB{-THM-bq뻴ɒT3""ތ#zK(yߎB^$͑݌%+K¡䌙Xm mYN9{ƂdꐭHQ~*Lk  z®];O?+a{#z(2/֬gV癤Q9vɰT 68RstKz)S9A}{<{¸מu?7j; P oj:e}G'n,<$P:DuwIOj`qCF<{J>&ʹHMATv$/v*8@ı(^jTSUEf.d%Y0\QRWkXȯA[0- M\"i&1Nd=d؄/V|#`ϯ<^9(MPG_r+H<uf{J o >{5rvMJF9F&K d+}o:]Q2p sڱ80pT[ <*V+ ?Y]~q1W:ϳ2 ,|NĈ8^JUA*/(YnNC.VS\iٗ[J"N.S#>!Z*^bkVZY'\\-O 1>OEI%\31oDmF<~N6ĿIǦ):8MCce>.;30.銸>|h:6ݺ 4޲q`]+/W\ Lx.P֦ə^ಧL#rܝ(O0^G zE3nރ}OMUdA] ^69.h^;ĻlH̽ƺ9^p(GZT㳖q"8M2%0ʵ ITط_Lvڲ\7_oSʩĨjn8d?}CsJ+ =ƌ*Obr!RI\ OXXˈ2O6ªt.5 H VeCz̋ri+(Oy;&4Uo=_+.!C%w cGIJl {,dՑxPR\܇?&R"@ CޤDp}͖7ҮV qi ̗TSI&ey%{8kS"6N3k}fBh؃jVC9%a|d\ÚwOY |Fq2/ z }ҟTW>ECL۪f&){ } k 3BJm]lJJIQ~6N#ԱHYtJ|1rǎu9 ɹ/(ՁudC. uwUgфXCP'ch`Ss[B?256-doW*a"?+u%=Ni3PM^߸!^#a*<c.2| ;2c=wAGC'Ed+ĄM?;K[skP@ 'q-s*~-pdg[aPvHh[j?Ƙ8}?KmGcH(1 xd^ Ι({i=y Wan3h)UX>lf=:r.)-|#?CR"(IR:rؘ76ĩ=p"g'ca_nt -v1Ih?O\"qnB%~G+u_ 9P` l4O/ =Ռ|Sg  y6#vvzG?3hW#wư݌K`HWAvCQw\嶻 tZ鼍:l , DmkxA|TG﫲Nd/Ua~*NJQ ^}\  @6|Ak^M%B]Cxٲ &)8-Ņf:|Қ'(;N"g~%Į[35s[#ym4R_~.08oSdbuoV=zg="\ĸP`>\|2*!l`UGCG1ן u#fM%Wz6rlɾ^';'RH0>DIdv'|ԼV0xCٟaXY@*P"ت^/,]Y=&Xm8: /9O/zNp|W!H> v%{ei nhHƃ-+qSN8l!3)[.dǁ'W&nv:XZ6R+O͡~sYHsJ0WP+XOq|CorikB J}|x6``ZՍţp.ÍZݍKK_539 .̽5d^H"J%@TԴ l"` $BL0O4k]iHߗ&t{{ebՖCL$i :J@ LX}cqyv)x91m3p&״4qH*3Rhs+ \df0*Ks0b9Vb<50!wٯ}iw*cdzMv+G Wqa!~@AxaVqFZ݀רW4a_C K!UD`ò=Q8>,_ cVEzfn%g|ND2FF^/jx>=j]n0Y( 5[`%\tL]x9:&wpaEEe]xspcT^c9ڪ4)Ƈ#p(07OBW=E㔣?eJb8ie 9T/@~m{)\nolx]0E:%R }+?qNl5ɧE]Hn־)FS=P 8ƃ.Ƶ̓+a%jיl Eɑy!@2E7ysrlC Qz<ɺ\Oa&.PsX ~B+[8 pkVYTmHuYR I%f,f!ъsG&cEga&DZyh3bJIFU!(p ȂzƆlÜÓʎt ,$aO6V:*ԅ0\"l ,; r@|S2-Kxd؄ьig0Hv[y+cOg o;:?AbK Lq$@.eM>q C|4%NJ!%.i<ϙ/\az'l-)%O."Dd^:h f\(($ Kڣ"u+SISl L],chNR6-hH50DJB1[-ǺoT0JjQiz&Xc< (<0_@lJ-X:PҟuBт<._a_2J_)-a[KTNGkB]wm-*s$ m#WTK#0Xo8_l.p"zϒQК=GAb6Ћd=kdy)F(.>>&20FҦ#H{db@ $\FҾ e?f7>GIYťCRpf b' e4iq?&}|U{KU{oǀRE0 BoGnf=wuSUL(c^a6ӹܧYh[3GU%YdTzɇG,Z쾒'`>$&ܥoLuK;+' C^ߦ}z;-ҵ/sE]F H~XBy4S9L}G33( lX<6NDޖrCjvg$!0aoͻ!1!TcH]fʟq'6hCBh̔î&F+BfSTo }#^`]Q|L@wL__ݸX˂|yg`)wxL߹rR/r4<B@dGjoBp6Mu`$7=[9.f6.ſ!`8I𒐑)Uy:pBM__QCio Զ5Xic#d}@NQ+E;2sK$Q>?Ď(yz$O UU/kO&[QlyG@զGOT[k&(@ Ow Qkwc* I${2u G`,b(s Yv{{>LRxIa89 u`%]rz/wԤgYgg?˓)xwĉw+r!SdEMox46ۉ>Mg&˚,Om5m3oF D;GVY[=$sA쥮)L⩡.b2|rSZ;i.^vyz1/a9%Fgg涾Pc _=1olqU[)U4E/' b$&&DVB5?  {Փ?^!o@Q2"0(GC׹& na\ΤE#wݡ)D7&$js%FF #k1|V5="_Y^!m@k6z,ޭ].w<"C6HˊFr ^RbB: (6^LJZʐ FMddft rfhRױ_ 9=O(s_b.Smjmu] Rx+`r/1qɅƓZH 7s2iȅ:-T\ٮD$DYY3 |-dv2khi[李=@u;4[Ε-k0ON'A&h^l/!m'h'#I~jhV&$0`&ڌnVooNUrڰАʒˏfgmsĉotj&,[\<륯5U#^n@ŽW]^}DM Bvcegvq d,䎧i/$ UV+*38 MXG)6 KQ17'#;6Jǵ]Ta;F6@C֦-meo˄%1~Uk,קM䏧XYaWN1@nyDlOM|iCJ{N{-c9U-A$Q/l*0^|:1A:Sfy3v*2fHuj}bcvd ~J.xeFE:ƍwFEqZ'e1R[VME{uv 96CEMfR:~4t#@}P;k끖sGXMPן/& 81:u|應eܗ*VsA%Q\d dE)|ssqb % N)}ERq)p /vAeVf`Dy؈ÕH\!x?ܯ*)q5cJ_m~ii d<!oRԚ1 m&|饋Cնy˞8ٚr(EXrƭ) `(-Ay!+]SKKfLfNC9zW5_{U9Zp9qw4f}(Sd.Awz׏$|kAq\җYCW,fEsZUCO?sQk); b]K\.\VY# +E?>.#f .EgKG'#vJ2eW3?yf#P8&yz J  SEfU"0[4:UlCxYŏKg|uND/ 9|qirl4?&/=? MY~&2hU'0M.8T+W$4FTÇS1}l,4($1\j~3 ֥?R\[f]vj@12֧E7RLcM%GFl}Z@L26>þ9t~4j}9ig}tT]'g5סJS)lDVnmd64mp$5BcSt8ޒLNԣ mRf=w(g"a&s|&r)D Ӌ2~ ХBFp-oI +KhUbZ&a N*IE̤~*a}t}H킌 X9(+[AT (izσvșP }UtA-F_{9=O!CcYoRt d'`rǯddkU=G[Lf֨%2G<1cFKct)F:iH(dr4džzMr,]_:oiMqϚ-03Y2 vS[ʼn%C50muv~Yо؟KN 8=SX!FMF< )8$=S뉭ˎʼn(6<$o`UábLxTˀbJ+p#p$ك 3-4lKޫjpmnOUdָ$e;2>k?D0d2SK[*zALJj uMp$Tj`MS!Tor/LJ!ehHNl#9]ѓ j^LU<=-ՠ0ۊwdwl۶D5T\-sZjWؘ1dd7Av330^PZui/w}qlI< (13ynJa%&h`x7j*f-un?2[xgv(ase+3ͩ@(3on4ోotY˗ͱ,aրxa88 e%w{^Ki տuN6 Tk'2s7|&>GQ/=1eP2Y&q:a5Y\8"zQ03IxPyLe7P'KE&r12Ӊj)iwXA1G5 ߥLgzWЈk̖8Ԩ;M׸a?Dep}h [ ¼uswy%x0iYvV( VZiLc6Cy_I-NKĕڬ.9L»BL}vb!4WaCbxssIK33R(Ad̹z!G ŦVCjT":8ʾ*$3",| k9$ƭjzuwm ă%#ϒI^gpZƘx,zI\ې|/멍gb^n9R G96\4rYia|p&lVU8yfNB\ާjh of6-P-~ #4|>}JF0ہȍnsRO81{)Q'x.pUC^"# u!֙rUKƘ0_aNy^G; ~C̶Ҏ0rhwcx$Q.U7xJAu39Q?3T'$WZnh3l­sBⓘ桍-h̓Kϧ)e"9rW>PpU Uha9dO{G`i0mW w9#ѷ 5BCqM Jw') fqmG3^KXWKb"-6>R]c/\gA?;+#5"lb@Be"v<ʎm» V./5P9=䘩D 1xK'~R  `o7((*uwSp}Py&.N (ID]UJY},(wBX7kVfw1 u-oI'\g3BnaLe aS;~j1.4(]4 &XVdG˯CI{3+yL#BnШ"qzfE<C qJf8pիV:m]PtOmiB94(@DaǸ Zrodh#0d)vY#t%<}6@4ظDs꠰"G؋~Jl< ~&{ $ZEKF"6?;X=9AʒU f+\<:E U6bA >dIꭩ)HƊiv 'qQO9 ;IO^JE<)N.PP'ԆhЉt饸R95KзO|D1uFٕ?7ȁ؟J̦Xa "8$5Js[='EfqYC㕄2r0vaRs&9QQ:>Hi+3I݈Rt(̂cOqh;v$yS{ÙgKTnք4- EnY?h5cz7U/H}ZؠIcv 4: wp}|V)0NFMHKiU(*a6i@i?k[mÂBع3JEC\9ǾEҺ{'$?LE+J4x>?-2QۇgQQ~c3 IuΥ4i| ΅kWRH(!`7CBv?)[Z{fGk7xct:rgR9[#JH;;~Q6]qmX8^3P G Z2+W9wzϕh*(dD"$s%Q~uҏxM Z5Ni2|VLN$f(mj_9}a;ߪIhwCj. }ߦDޘ{ta'pU&gGaWˎ_lpTw9851qF'%Q3% :Mbi jďDζރQge=T3 ͊^9Ty`F$`fRP~ tG( MX ?|xbţcNrM@eKk9YY4GU>DtoUvtSHć8Cu$Z[\%wGsӞr[(0Fe߅0%3qiD>DDqF`xa#`w)-Op{jAF$u8.e͛P}hH8 +mt~{t˨%5jvfK_ynkEv{JOh= +&/96mLM? ׁ+ޭGkgJ;׾`\}Ќ"d@),s|>r.e>_[8.5b!hf¦n[|4,jCMZd .">g;֢h}ZnKvv\%"DDo1 C+?./Uǎ۸'3IF;1oښHa|"e;'0.PVc=?LXӚiS=p c\GU)HTxzCUf<ԬHΰ:Ʋ9uC9G,5ХvIII+LZےր„82X1@pS-mY B߀P\l\Ef?mZ#w^ c+*=lEd gV jz'%ءx'V_1l:}'; zw{`?p Y8'[hffBHCJ=Hᱺ9.p4$L*]{1^bAf6k F o>޺{|d -6Mpş6‚~x/ݙ΃{qt9n"yƩ *5-|XCn4ooS\t.V3G 5^Y)I fXT^v C{ЃMUO+f}m]<ەdޓC?݆RR$C-\scfHPq ki^9:*õeUp3Љ!z@b #YlE+ T J&+T ?M]9z!FqTEu&cy:;N$_AU=z)6OJ /jBWMmkz}-oH o֬S5T qݹE4 jߩrŒPW)x+`N}NX/3Si9M ;"UK ԇ|;{u2: 迲:K ;D= P$>뀌Hs iL?ߐ /7nmX/vL1+U\- %Z( @yVZl/R^`OOB}  `| !z{km&o)AnB^;LHTI@+WIpcw^"e$ ^-$c/dnF~~"dqlDim-Hc{4O~gL-Q%:Q'SpV_4unGp!x;Nc(^xu.+Ī-{$={*_1CSXX}dZ 8UAN4x7Ewt[0RB⳴4DAř)?j[$m|"+oqR:!w2T=/(pwA  }oe"w:8<ufTkpr`Nh/T=M1^%rj[,5i+-D=Ͽݜ7Ev7TZQŸ7f)Z_KB˄Z6 j7aV"ʌdu'fP͉V?fP9RX 1Lk ޗ! irR{2IEyREKg6i&9qt6Z("F1lK{$Ӧ77H\黮/]E|5G*:}6 *f0W8o]$h~0H= $^E%YC$"U5'_jM^U.0mm?O 5EDPpj%bpE|S((NlUliN6IYեm0!NGgS7en"IjE_uZOܕCXg\`/' vB2(Xy|xDGs%:#"O.xs<=o4Y⻮3Twgȣ6 {13I<Ֆaj rzbc04^Üv" NPi&nkۿm:h?P xu' Gg F g7q>]+ьf-95JuJ1An;:}vƐSkAL8>X|?j%8Z6~~k!W<20f̪xt9=N=9c$Ґ5~UԣfA0 b49YU&ʂ(Ct5dݖĦnux:< ogfq mW(MXHXC$ z'vB~泣MIU!Uy2Ja8;iofqPAo i aY'S`B`Aю>Q1Kk CġB+2}Yer <}#XlFj{QaE BvX$7w.;|Nwh 7skL}::punwL}Cf%hqnge4{F8#[P7Zr0 :tbuӖf55:mw],9Sֹ'ά0 HBh PS:%һ٣pSyZf?Mxv䔿脇2?c#$e)噣/8pt<]Ge w'Qɩ05*⎩&;~͇$T;2X& #[q3b}Vx8- EXG j-xVbT'ʼn?;T3f*|ljBRq;yCA tSz6-tYŠA iR槔~DP)Ώqp%ټlzC' br~_Ã9%`beJI?m /q5ҕN~0ez$ p'MyŰӎ!q/ߧ4Ujh5[ay)_ּ(3wR~z@uJԺ]mq/y喴8}{Rd9c*rՙTf]hw+Ȃ ndKq7cM&s Ѥ޺)EoQI$iYڵJ^f=v638BT{jóN-x #Enf6[YT2pStwҋ."F4X'F+fi\d5dwvIV0!l9-b_m`1Ӯ8Wh*r޶,ks%ZqaO(b H/a#\ nOu?FIEpmi'ccMĘ<^?uۇJ-ldüfI &X%u:any*'VO^7g+~`@gtz->ݍ|뚎Oz`Xp!NQu:hA8AŨH#́) S\ngN}hTM$Td> &tu$v-7FRDd2zS&wDf~Z~\is)%Q2QEjb6B}XClI,֭;' BQ`{%M^t6weNj84γ2; 'fnrfi4MqsC_)qQ^I)#U%4&%u"M7Y"yg.# `544o /$#تh)76"Yӿ6:O\OMКγ¶q)>a#XC(g"KRtvV |Y$BWԙA6m`EOmMָ2C)UL6/swc2vlDB ʷ T-hijg`Y^|ONc̎iVEݎL/a!~q$cIp8Lo0'  *)=VY7( } 8l1ŝ򳀵#8#y9޺n樂P+:,,c:z3i9ja$*:;VRF;+t;-j3T&T/IU I$*x!C Bh=PPOTHoq~_9#sE^S Iy vh775nZvGpeWxu< *kq:\K\) .?-%'𚌑`$#k ^J g"XLofV1wH\eiU.HDMPߊ2LA%6En;ǂp#;R 9 xB@ns^~IVn$%6|X Bu`G۩-T@;n_5_zvIR֍ת卫843WSWj)vkXsiըXv~bnNy[BmCTJCH0U X(H\@oGW輐Ϩ_vos\N `9S#ȍt۲%m-.' `,&96 vNEX37F b/^KF¡)CcnR9>6]ڀ92i[Vǧ{Eu&usUi%Tb ̅ aʋRJh Jƨv73 ߞx1[%<\#X:T!F 5y)첔<"/~ gpq{"`n.hToI ѐj 칊1 PcO%8+Fc0=n=Cfbot4){}zjA]tyzXQfٹ%ԕ u_F`8m-Nq6:0}^[%Wה*'&ۃffdn'.,v,X9(b܀_sE}#muqs案G552x epf-ƌx d Cp0'V, ZtK=ibHh}GҸ d΄l1,0y Wի52;c:37V*·h3gJS2EwX<ѧtR)LwCaiJG+S}eСB;(KSվ(²8;"($*kqkYS+HFSPd.vU;DQ_5bǑ:baA̲\?q~_'}"U׺u=P$I:M#kmeTf^ +#&O}u4@xګEdvc2+%&۳3 Z' euq|zF' *A:`DLCb<':I>^ rq~b;)Hucn^7`nIP UPqPf~xj*Nov+*PXG+Yno3>anT䙟Id9fb*٢ӤPVYwKkuߌHAװPSYyd%T5RY+R0%bt!XnDzilG ?Wiݓky9\=" D>~hȊoPkfhP#8셓COQ)\4a qh뾼OjoҸ"CsDU3.~@wVel:.eȄ5ƾ g =KaQ6ᡱH8)YN༈qu͝Qbw?M jYJU#11D5AV2 i^6 ńF0 ZWIf0Y&Ti2mZg+% ;z~3 Cĕ _LN3P9GZң_$6BU}{mt{2`7=zb, \&}+?K9zBr HbZƏ&ʊBeK㨒G0XǷM$˙O9T?=`^W͎fu3ªꎤBPY>gxV-!c M]D|3;青4XtwU-n0AՃE'gE1; Pbc/Ru w™; WA9šci̖aҾ~TJ~]{5" qꖧ%+E^bmۘ"9"'j2BBIC$Tb$0(Ekս A˹i4 :ZyrnPNĸoW>, @ޙTOxnr6\\_ַOIU2/DqyMX7DzBWgZjχk6{8kv(2̀*j6NCZi) ICe/~?,\1)UVa"T(D8T} V^U}UTNӮj Yz7DiƆnSm`m(0FGz|H]Q`%mv}Hn}ɉN,0D}.' <&5t Ra*@B*9ݧz”崸e&1zQLY?`9dv\@A^[䰒G*1b6웯^3PDY 0]q.ؓKBMuM^y ^)tFn jYFUwok*؞ogC<˯2 *<} @mp<P(Cm8_y-ӌ1=,xKu=S/ju߫]eXAى6͓H51oVyHbbgoHŀt6WXb49=lɫ_*jfomc %B> Žs~hz6;8}UmS ,)]|l q2A6VXS{.jY^o{E<rEЁa8إ*K>8`Y4 5CuL@kv6dr:qlPQSiKuJ}Fż;d9sR (\ВzQ=|@ Opi0*,f%ޏ$ba@i}Xڂ!LW׹ =yLp C*S̉P;zzd$FM8pT?6!@2oi3 VRܼ-6f=*ZtE047tDT$s}sΘ,^1#4Bx˰:>p:`դ4K71r>z}9 Y\xe`iBbŠOC$88f4OѦ鼔1!jS;W{\ޣTMp'tX>`.+gd܈i9[/)De)~>%F uov4߁ϰ ̶qfcORirs^N*UPgf R, ϵ_CBV9۫P2q}_ {=5Alz@!a2eF8S9xxH>b9~n(,ݵG6?񞌦!|T`!PLLޒDB$qe|sZ'W#V:FJK~McƊ0 Zi*FN)dl,0Gdl_&{)N»G=׈L>*`gz%iaXK=QcR˴puVQсA\Jƀ:Lz@GZNXMEE0 MFהU¬$GC?}a΋fuڿIoow3ܸ,߶yNUGQL#f"8֫D$CO Iҙl$2o gS Y}xz˼Q&f`mN=JEPJ.I1]j֗en=Xx?nFwǃ7.U9ŨL "]K~[qHؗXҩY̪id@* CYp#AB֭Xj J|S fT,OjLi&<}jl͇ӄ=#VLW&;B:GeݿKDm G/݀V2[{oyjzM`#Ld !qta_d'ZD- yPLKqkWe^}-]!3&v}#7eP3Vl>Th|Ҡ }"Ђ%>1(/qJMh8uQ=O}.wՄ[T.9Ͼa'$Pc3v;#`{2o@]sJG,d^}$i` Ly #m.Ć?P ˹ba3) ֎2Cj3cu2F |{̷ غfPk6e8ѾJJjTBX6ZCO׽!E4E,kn^t.!g|JPZD'/խWL5 I1HK]!@<{F[N?cǛ[y}Qyb3.9drH<ß#k8+g@{5>Ҍ=6vYTSMF@XK`=$TL[P\ݑ0/z]uKm?4lv?)NPʆfa5ꥑ6# 1{J![;)=HEmښxo4ݲ;4vY[PqF%ʦ I6Ptz~p)| n'F02~7D}ɇACiKYE[M|xqn=Ź<GtϜy#W!ug54L};2)#Έ[uI,ra!PKoղkW62 HO1l®㰂א-LKn4u[raDYR/Q g|鐯1 iBgfi,J X =d_cm=y9Fט,W6! hpnJJ66,q\W+%UCHg:쪼js\5Qn]wb]WSc{ j A_TW|A];bfSnƣƨsS#̻ӂ>G'rd5(jˀقNK?Ḋ$?t|w h߰hLF 6>_.TCe1k!AеoaIaB[|a#$$=0^ո'36;-/U=cAzY%sf52Y#vIYhLU(>t"5οw&SA8Fm9>/6=s ^rVqI^`0W8YJ\1nv\쒰vs>/~ow!IҪQBĉþ5Lw34PҨc,aX4@C%OӈydthLrztg60SOe85ˏ<~wrd'j1Wxa00)t 킱78s{}.>&s7Xmkr _:Np,k IH Bu72݂Ciw*6fj δ_Y)ƫ[VE#sDZ2׈p CWGDlֿ@oQ*APhN·U TLuǦ jCeBFe+O<(;xY+3^OׅQrA'"PtWK)޼Co}-YrP30\Oy@EwLəC 헲0>mcbMrj u}ĝ$yI-af6/Rd4w:c(9X͙`߹s i=uZt1YZ%hc}9y诠$#oYS7H^/Ɛ h&MM t&{d_4u^R/j/2Ư)3[_vBRQ;]φ1,Ɍ?/ABG^+stNUjQ$ڥuZasXv5"}}@\ֶ[''Y:kA{ϣ;:yURÖ|٦h?I1B͈Ѓ*Z8 GG~2|ö Ǝ,U}EiO 0(|F3'n~嬝BKRc0.ꡜEn85?cA#*+<>DݕN ^瞌h}4IzCbWY&^q`ACbj0U!gvbӽ@l%Vk?(.\@2PE!{=uȜ|ב흫F(@z#%޶R*.em˪zXYBCB#}xS:~( [C>Yb)`*:!@.f[K nC20,X)^s F4T^^͢aJ셯j ȉ2?~cݎN[oEu K+Uc+xIcKgV(zN?G z2Q_MKx\R)G##WS90.Y %~gc*_ZfJ *yDo!P%)VbL2mzz\I}kH9_KNn/Pi1jnҝqc#HUBXIq۶8*2'Wӵ늎|g ж ]~fؕDeviusy}փh`C JepWx$dǢϨ6T&@6'hqFhg4MW,I|G52,z#}b<Ɏ\vST1 -&UNa_A %Ҽm|JDl2vӺ:=qPX13ӅUZe694JI)Sc[k07BWGzpl#E}A")?{{ع:{8 5(Gr ɺA?//8M|-ՕBzL|ɩ:֮؉B 9 ͰrZ% 8"ԨTc?kI Zݬɤ"?k4eA2_`Uyy@!ңH[gI,|;+( vÛM@v_ ,v|Tʼ;`rx)80_mv;"+ʵ2E7X? *1Őq&ƚ8|YCPRLq9DxmppP>PӉGijiuoJ&c:p, Yc(5s4ߓNL^)UI"Qz%6i ݗFlD?5Am<݌C?GT0HIA?ti'A +d14ДW/=xI,"RxPUgahglZyfļ {OloU:RGJ  JH/KF*Dh{Gބ_lV۴N5tm{ P׳ZFMCߖӘ]_#?P#fm\}&_QByx3{ά"ܵ8_0_C]( DI;O| i,_7ED9h[WW7o;T4"b]R3Z5[A^~&G$ #?kfk83Q\e3 U<'r5}]:\AhL Mwe{) V:͠ԣb g@HmSALə$? .dT*ɥ\)Y1' JT9I/jN.)D'i3CIlyd3_9H,h tM qwkۦ9؅Eɼɍ d3,N\L2})w Gs*mh 7Gz*}e#",,E/۩~Xt_ *@/rgtPw; Zة-Λm8Q0C\@F𶁟۠*Ve i}7앑җO-C^&O/ (B; m,H/-)xFeJlQ'tx~Л "pG/[Wۗ4Cꡁ*R3's=t-KjRo6.( -4wnKT0!u^qg#enoH!](0ۚAVYAE'.qE]7~5GO#eSƦ10{{WCJ귩t,wnǟq"i텺Z'J׭ZN~ţ6\4B#A?bOT][& Du!ml҉f{FY="w}Yj$Ȝf^]pYs 0 9PyN8].L# $\s3a@d&3MF`!W ZO}GƂש8t+|Pnyo@b':.CuGՑy$[߬)(_p2̀VnlN /Y8g?}HٜnI%J;'4eBܗlk"b$h@{1m1g%º<~ C{dq['jtY=o5/Hݾkf9:Eߺ.sn QƠZ4Nm3TZ>ߨ!h!zώ_ ", 3:jckiSңYlqCh!LGZ }9Μ?}t$WdJ0*$lӏFδj=2Unt@~`⫔~5cT99{OOw RF ȮάV=esp' ­d/Z#v['ms_V:/iJ;jo=0@ٛd;!p32)8/zy d" r`Q##Eyz*%(Y `4Vf!Ԋf4 *9:$zMU"a꙲fhMw^ZۥM5 BV{E/>qlZ{Sk|jk .y5xD%7]Ȏ4dLՃu8FӕcœꦥdwHbltx)F|QUYBf,)E=gjjck b</T`Dnh^U[t;F4`ydM' 1*^' X_]w4JdjI;-0]CZ}wz5|9bRKw)xQg,jHQX|f2jI>˰S\vSG+ԎEC>ܐAi1Qo@p8s6,0M,۴WZ4YY՚25TFʠVjMӍ[d/Rg-8-RBI}q.͈CT)*/mQ\ րOU@x+|KjExxy(uz½HB'-BBj]<[Lf̷fT'i׸.@͔" 7ʹ(-μbkeMrג0:\i Kpl{3PGJ>[ sWZM/-['{9eT";.@WWKbs-ܱ&DJj [=MD;΅1LEtmV/ۦAv ˕\ UME*Bk I_Gfܢ{+.9 ^ٱ+h Lӑ3>1m}jdKhvΛp~ک8ƃ5 YoM9@e;01L 洛׸`(pm#{06?vs|;zW`a8 ԂG#m<'wOy`[BU=ɞG#ycc%v:w.A;TR֭\9uB2=)\wWPdu^6ש:!#e!Yǚ:9" >n3=ZРFY@$M\xWJKԑ++.v7n?[kɧwBI։t'_#ް2Y@/8y+vL۔:R@|`L/JУb/59{R\R Gf7>D2\ElMRO˰\MG @,f|Nj4w#;PfIrmJR Z zddZo5:SBzK&_bœͻ^WIh"KۄczO+Yk>3|l\-C1+bn=O_+ȮsYPt";'(Spr pl~WvVベ`sbMY<=~Y;ͧm1&\l-\:F+̜+YBotQ A/i $e &I(CETqqCq.x R AbS*@`"lecn=C&R/r^>V3vK 0cفeq@оs3C>B˃MO%.tD,3RI X<%\I8(zH {B^rKH!>bEy~"D_l; i]@ *GkpbOWYr23ps'l<dDsꢴ"/^Op-lAeBT~9D n[%*f jWZmriViU nV3o)|{<-2nUlPf.F͂0pϚ.Xg^'E͒j],/ʶ+a,%& EC7T:ω}hr¾k}Ap-ggf^S;cÓ s{CU0 #k֝}e<At)6mSgxUcclY6M@T&a+`d/?tjF9 ] 9F(_gUBGK2WWbaP+~`c4kـ">$cqg!}+PE1FSƛJIҟPBaEťȞZlQnN#. Tl[XZ3<=g۳bF&$2S2ޝc3yl`1[fdH7)Oym>ܑ ,=ׂfq0D`={Pfu HB?t26tVc?(рI`SdYLk@kRI\!]ǀQXbVa2קc-B ^&/f̿86֧`4ĒKF>@ sORćmE8Ȼ@mZ{P.ç0n _/@H7}쑻!JG$QVqQ;L=iB|(TLuEpdJ'!w+p]-oI|m ߽DG"wlTl3 Anz! mgO n]; 6ZI)IeDH*`6ac+5Z~}X]6f` z a~U)JzCr+]6AD<QtWp5tj*Uc!LE[r{._?HW~3؏x 7P9А =yI0 bI$场@kTm %s΢,w-1.3=:5i-Y͗,J.B:È`pҏ7ex'+*_$?UȞj{ds]/(bHR58:iIHیucgc+Bכ{<](LGA,w;,cysls%S{:  +IV?%3'T8TXHk*T7b/qmĎow!w3r;YgUY,JF5Uc+Ue?LyP: )Vew,$Wi& jhy):{~(Q;ucF ΉPZ:P g4Uwkey!]EB+{fmӽM ΎT|9?&E)~|g?MƺQDq>{)\yv \604zAp*G®h9璵\/u0KK5TVGc@ joQe#Cr&OZQ:)Zφ6Nw5z#̨U>B/ȤXpڬC{B&e isӀG䪃qBNU/CϺS{l]MrY)l0\fV2ACè0ѭ@()+.(عmۿ(,uLϩ~G~~"`+( Yp9ʄ&LBw'Q~>]*qJ\/%l4cR7; U|y63bF P-wt8F[+'ʟ2㤒|>8b>Z^z#x.>o/ VNz.F$%btG5ɔF4Τ:x0IҙlEWbxm20E݅nScI4QX œ]R؇C i@{NQOxjW=gc[T&VkGuW\oKq͌o8uU~?p cAd":RT[#I74sW!$dVwP:iwSqŦIem6ÒuxinD<}/lo1+hyf􀜹L6+lipICI܌8'fsk"`2tժ]8F0 {vsLԭ. %^?mZn ڒE:]e=ݦ'Oώsx)Lk<_v龢|pI') ,!AP]2ʺ]GlK'?4N6DԸ3BVDkVs >/U%"4BJy wq{ݯSuZ VڎmO4o+?ܣXx56(aCzRsm*s1chV%AdJ |N 'vϒVF%K>mrOEQ€.>rXo/~$CY=VM=iCȡt̝m'x%'hA/N&]ˌum`BJՅƍ;k\aVKRtA a[JD7tC4PW{Di#\$2ec =-kcR<=A+,O&wbyXs)ʴ`("#+ NώplV}Uw"U!%DAP>KĄ_]ylD,9nvhzw Ute8Y䓊E]WFXR:"EZ46>RyatdoZFY + h%#f㸴n65) -0:{xH\[QpK eZlnbRVDVFzBN)؛1XS;(|og*Ͻ]z&d,d2SZ8?LUh &9%ܮ `0g-P|ZKƇZwk”7kf%_+bte pd0n7Acw&4 甛ssqcQƯZ` QH-^tKg-tqi1fM:^pxxpd.s/G 8C(sXuiU;[$ڳ/>'^ڪMLJYV&5'|9c ~֤9QVsu@Miib&f{-ę< (O1%?5aV,y3,+g8$!Qa}[*OdntqNU`,A{*EtG"̀~EG,^Acl(ZsyEBڰBM7ow«}-ᙀ~v{FycT=mvQ(H"]ͳ&#ljȿZxq;J9L&57c^w-r&=璣{>9/㲞G^^0$iaǏ^ $__zm`%AJZ9iY`oUo aU!۳ :q>3Y3(h-@ dLDCpNy\[jt<]h@ag͖$roǩQA5B  `y%I2%_*;'Y@tЬvc1v"XbhV|)7@Z}e&RFF@iTimYgs`(f疷- -X z ś'8H8Y>u5d8))߷ǻ}b#,~xs^o xq\oRiGZ d ~v){F[}1Sr3 $ƲYW`f`8:q5IOEF̱JT u/N 5:d8Y!rfӰiP3KjXIbtD egIs᠚3;T||yd&ܮq5jGKr\~\p>w$y#GRf91d-|qbk"CERwW~-K U GT#U'/4L-oAWiz~/v~2Ap/5 `'-dq^N49m; =Z ۪p Q1YRAM0RPnpN|.|<(Ň:pBr}ɛ R3˦b cNZ dww+'ͽD#gy3"%3GQ+QY[8*$.ƨ$.D$T lgǾO(᪹$5B+u)I!tabñy- $磊A-E5*[qqJP_Fzb]4zn`U9QY,Pteg^p $< $m["5kXw5h*g8S7ȭ];LxN` jҠ굋MhiRaL[J.Y%NA-w*D &Zl+%rxᰄu^Wp?Șۙqj*_?Qbxm/˸V{D:n{1_ԗS7>怒4l$DmB{&-6d!T^3Kj x]Y|D]0}=k`/{;Lfka͡]J1.M7s}f7x,,f7)_gjFOr(dLnO?Ġ5ZEǔU8'u!(sc8#?vw:_s IEo| ЃG#*aPǿ *zvm0S6s[xJf&Z9A~6'g-cR4$`Q Ir` &s&g0j1#>(VK}5)#WpixyJow#waT=0=612Jȁ"E0v z)X_/VDq9 fQuoV8 {ZnSYU0P-/v0 |pts'rVy0H8/v$W]rjZ,9&ƨ3Nwd|vቡej7kwKn0 8O)Fm7+>=\{n4‘j1 _8IP /=cF%5:&ˮ55mG`>j79sơZt#Rւm@9dYJ;utcⰽ?[$!3,~> Bw2?8E6)4W*xTXbKÈ̓P=| c ߏL"M$ܳi00TC_uZ@M&d x :t*)3>d׫љD/67uYc?+(Ewoϲ5s;+A׭{f1MQ7P}$%mboAM1ā~"@Yl?%A©.$ԏC((|;1dFt,`qkrW[0 *v,e`6m'q_qB-G &e -axT .QVlvFufzr%zXD zEOL({ JOGs%bBnЈS_8%\Zy=kuZD|o[sB[O֘ `d!0 P=* :8`"襍%~@vxG;x <pSnJV6t7bOAq˓F:mx-XDFD  G[&js c\+*&62ȎqScj抅z ^r3*ݻ6zt񷼁sp<qJ +A4m'T8y Fo/Ʀ@QYlUompK)sj9vbv'3{VUw+B6$PzOWtL/sqLE+ PsnSE=$WЫV=]j熈Ss*F{njfK0~)t yg$y7:1Y4w\bJ+ާkPg'ڰ˓ԫmFfoF2\X׳VQǓ\hz Oب. 2TvGSf4QJ'8P8dt3<܏x:\\9eA&HaDA*p^ѻ¶F:+uq:ygLZl 0q )RF-'ꇐ(oHklr([)Wcl]`ݎF%]S+ ZZx;$:ĥńYNvKLT-ޣ>H.YgŖG[*'v( z]RuP;N2'\XnQ<)!iOJ[SƷk_f_`kM}Ex`IfM5Z͢6ZX\K?h"Sj>Fh @q-H[6YUXabP|'';̨]ƺmȽ0-,Bs<@3締$7'=jvn,@ʇ0akj7b!EʘZ!h8 s@еL|z~)QulH.hWۧ]z_$:&\Oy4ZyY%2|bC1u{clkU {i,1v9a(j2GEѻJT]'C0sLkK0=13VLsf*|5Mbl%Eб] VRTB X Oz1<2Pel緵0TڰYy|fe;8|qE&9 Q疃oh?MP4d".!{`Aq3`tm2>[DU./Ghi͂;-nQ }qԟX"m%lSi$ o!D[%ѣ{g(J nqS,U^{̄gȬӴJ{25?%MK0ck"FV)CC67fpNkKWؔC;I61Y}y%I@.CB&ںʟ[Gn7$6{&*U.~u@N6$q\ǭU7ʋ-UUFѥ{I8z*[ЛgK~?WfQ1dj5mw%T>x.TR6.?H՞C m,PAmoKy@1Lbx{ }xn=gr-nė_ʼn"Pv'jA/X:#os yq:7ºZ~:r+:k)_dR P- ک*Bۇ]|}/Jv%N)`i&I¯΋A[+|CrG'lT0srB2P_ܓPP.3q749teZK[RX(L'BQA)J@>9|v[YMĵJ:K/fjc_~yQ9Y7Pα+2:Jcy܋8/`7,#?*{RiKxC8_B9Ji9luwD4l@FQ,H uc-~C}=d#axwE=jn{鵭W=:\z?[ =3{ۏO*tahVۧ*d,pMJމb$I6Erأ~;Џ3va_[[nHsB1骮Mg3NbvM#.ooec[ /R@鶆]O)NtC$ֽm:aW' S\o )(GV6HGyOxr7^6&`]ܟ$@yBڤ5ggW;Aa;'`>dMڠrYk7"uGB1]l.[oۗ;sv4Ӊ+>+ ~b_[w?Lj|WQ[ oJbJ;xO)1'&ABiT |>&alrk+gŵyUij}a<{D&S]'|9'iKE^1y |m,YT: OJk*]ՎS,Eeu𲊍bY^R6`VgnpV{BFO*"`zZ.#)2iS5 <\KfIAvB 3&丞A{-lYgo225o-{z؜l ؐ 呝oORQO U;/)Ht"Xsn\SemF6,I6^PIXBtH1-XصwI;ح9@62'\KamgssJ'$ܻ_T+tДd V=y%;Lڊ!z7~x<^1҇PC l01EwO.D^ ۻ Vfwo)3m8+3[ãcg- ɚ!H?&Zr?2qH h%ǭ3uNUuF;bG?љYy^8 }ܘizi۱AdKҨ &ѝg}ʱ26+\> bi\-›NJX V/$Kιu}v{-X9D0~wH1WyO6Iom #ќbfHaX?]3{?Dz5Z:;(31q_ /@BW٨Vwōd 3;훘ہ(dy<w]xI!hQ `rhKxG֊ :Σ w'J`zǧ࿧?]He\8R4L]NvoZdVe>\/Lb mu PY;FR:s$1ūP>8{8nꉠ)lz7dS8z~UCwx j{+˵ckf%,^5AEuONVNC[Rۧ˔C>JR#[ِky,]M|2KIvt, ȮF&D; i!]*jŇ gwP>$('j%3Ylfvbj.?#\v\:zbT_gG)ING\f/c3}&:|-h%.)[G=|J ڒ>3(feq۟'Hi?R5;=9ODvsB+Y i|}}7 NrW ~U2`쀎 #I:jKAjФF6NhiؗZFEF͹SZ]xCVz\\ x~JggtCpڟi4EG\`J[hNYF_I H52p~i)`X3=E֒{ycTH3E1pRiCianP:jTsQY@㙥 H/'}$kv5W ]i7G-YD.nU_ K{?߻4RѭP&biYw7f]X7nj&G5hAk\UtmF(h|?Op_"5–NZ7 ;%~l_2OOS=]+|B]ޖtڍ|IL1!rHKq 12L2FH a;rk5߈%- Y| /օ7T@S[.Ϳ!&Jw5CF7dQ#%QUQx=?cd[ݝ@LJ۷0Vqdm\]? vNpsRat0gI",)ŨO" )cd*\_OU `lFV]-k}3D{'"Z \R|hC)¬1J7k(r!ݪ.T8i7RsK5_ix{ VɊ!v_9 - $7/) O17GK;.RqKsD#C#xIZ(991=jF?%nqK8$j!{T0x>SpG"P̘%Qͤ&‹!Wd 5L+Koat|5J=~+pȱ4*\;zxξ0wҊ΁;Vb>6֪1H#TU<8"[utf5kg,c[?%IȞh:=@4l^A7BE1cO^ drfT_G0Exy]c*|F2.IzS;lsmMTGp^u9`NcZ!pwlwZ7~ut:*z>pXuO%LԶ%^Lx=oV%J5縴 P\FXm_TX--y[fq"7߃:tc')`SD13 շ(.KuUF(emǁċ#G%} O8OnMa yAOL[X\ް}ڸrIL]e+'>`c"P{LIKE'tN_*]`0gЎ29{n 1>GNnNXG(lzẙ:滛b}S:"`_~'ǥ4WD@]fV߭]O**dqD5G>.fF~@ {639Q90`\EPe/c33}M;qk<} ~K]rfa^g\fP_fOS%Lw"MrFx>~B Őt ZEINyuȓTV8%,rX<;*SG~ע SZ$.zthuG|ht]@LY"&[hXvYJqhʝQYJI4%$FSp"F0ɫ3s^Mވ:TokLUPĒv)?BTm'Ry>%pA(ffJT* ˞)@{k.",v =Iq >t ٙ+cˈb w{Tp-O؏$&>t K*aڧ$p3"ȇ_*)"FT {wT؞*,@ CDfˋUd8_;62Oʻ:QpzuFcKGI( GFih?{f앤59a Fkw7f*b~ve;BGn4rַGnAxwD+Ě"g.&/+B@kB2]}M)h„`M ]MCcĊP|! uwV#Vu/ |#1Ecö)as̠zoB DbCUfxуw~=}~P+U2ұE0~>(I;B#W*Gt4fE&,X/,z/ctGgKeϞ"$’ݠu @`)Yd>y<5.T{K{pp{O߆+1TĕD7 ķi]:ÌjY_Q>#ϫ B8zT_?O9c ǐv ZnNU0WI y8ۭjLT A4j4=8kAT؉^<=5:yRln\O =go&ظ&K}k򴒞vyh~u}[3; NJzEN*SSfY9I아b$.7xϥOSߤJ;g _DIKO~r8uM6fT!ed*1dwtCbHRH갺:sV_ uz!\N>`ZQb c~0 k6󸼣||y3U*·→LgBg[e^Q C­KbHAI@ҽ˿ 륚]vP,-!M{m? yMaHDI{뙞2* dKƺ=wQC7Kg k yyVG.SD[xƼ<D1P-SM%O,Q}FQҴ(6Y dQ6G*U QOM].?Wgq<1N?G6I P9CKౠsJX ȃpsëۚ*0iQg/aHǏnW{Ng*T5$)+&"q0#XrsYsw6شӱ~!q!.a^~{v4XU'T栚jJ'CO5g RFwšB_c*e|W[jqҍa{(rY]<ȝ pw ӱXKF=r 伣Uw &ojlۻux@b+@sznI7h٠Mwp츍v\8C+קRut̩1-(bŻy^}D0oփ4=8' zAtB jsiHpiCXc+y<+ӯ$aFwH1>A;ȺrOA-ي3(V)icQo/3fIO~ͺF9 q5 n#)J3b̙>꧳v:_TjTw$~Ċ11{p(΂ׂ0RY=Ka9>>U-ʸd?:מӵuzFhL:HUvr>@[?6]xɉoaI7s@kH*}& cȮX 2UxrǫXAZsAyYq|T$l;qـ4_[;sRxưď%X 'qU U(Yw,z@3a'h3 bQ擾٘\bްD$#Ciaz V&Au9d7 ng 7RVh6m#D 鹮pJHZZ/=gS5 V4##1jroNhR|CA)˝+=5 1҈AdT% ֧|\3T Hݿjg 4 ;bkFC ɷi\H0ԘZ5>>)lfaAF'X_=?^:jceI !IY[iQfLUH_#Z =` 4$R qx(^)JZ({|G/16n[\S"B^\dҔɄ:hES>3(׶ݍe,~ n 6hqi!TЈ7{<TS{46̊$P7VvKwiH 7ؑߤI :xglp2#zL=ծ*1'4/:4?׼f⭩e h߯拌E80V*zd',żq"G})¤} U >LXpoM⳨y7=YTlIDmUgds,M{F*)3lT 4u )qNjD /0'j* <'_kB׹.IF8eazs x @k5x&r&ygvNVwr=Xk\d^Gf wW\#KJ  #cci'8dlH Kqk;!wry<>Aѝ+˺=-e2ڏzs); kTXR3}{ $O32߁h^(L?S̡;ksN>iM)e;E."܊K󛔓 `r3'lAV'RL`*=F1TF<=9׈`&|TlV|8J@/_@Gd~O0X2%Z)qbwtEѨ0\&̞I_g{):/}M`U&2U% rLTàE,!m*5qzIrbdp` &T}r3R ?a8\6hhQ\E ,,RoVKMzę:vq)kRb̺$~f͜f)@tUR 3&8.(/`NԹr׫@ҿ+oGh!ì3HWmWn$!+JrqF}{XMĚorc-t<0~ހHufpBTQR.5} ` RrOp:%*q%ࠝq5Q\"%cEin -ß#2+b!yty2i7ɰM}o[5roO&MHXJFW.?A/F[="6tm5Pb+\|P0WI~u4X49(d:B~ȱ0m-s >eB1cS} E&s'L{hgGd\>[x02ޜ7?8|RnAY:6rafV?Mȏc@;u{;&r0a5|**,'9Vx+tpT4?[7Hv>p_jOw>I8X9]f.t\\ 4ڶFtԁr"ɽݰXk{`2 ȾC~4RP!k_'gZxO]e2HInΏum)hT=z+f% ᵬ+ J/8}=dsP%JOpŏNQ2 |4XNE!LF#ޱٞצMJZj)B v1O󀫤D8ᛟ>zG0ɒv.?w.kԞ̫E.Gnq$d(r0oajfqm+9Ɠk馜iUxՋ5I 6J2Klc6}O{}⡮EXXˢ Fy5Yk!W܊]:BEjWNHJH}39vʗ'FfLK/b8sUzB'P!.&A*c5W:*4FJ:"Sb (I A`A)IBG,䂇⋸})(IӪh]تlu fD*[:c{_J:RC()f$͸B:4/|r/.gTDޔpz;7 AG. C.F|^3;V1ĿPl:lGF.PHlqe)R +O%!ʭ3%g= ̝B ǭgKϦ/B&-CpBբ_d'<%֣Ft+{8bEIֺ.QS\-֭INED7l~&qoxpaaګn#G-Tœ8;pVo>]1s;9b3=670e}_ߵ+} XK.MܾXD˞Dlz3 ,, "թ$[JUB$CeIe0uةt%Uv-W!wD;Rk=TM^ccDO wۺyTx7!юPWx_Ȏm{Kh[Tkѐ| L==,ܐ~vZ(*qlVys*hWwվBWdK5!~EXR a7@ ú iE}Jzuo\`+!(HpHINO suXyFr5`J[6Nz.6j3Ȫ +Z4:h~؆aqCE9G~mDњXq|Z' J t`+&Xꅣ!f0_>2,ALƒ\h8PWw< ]%1c~[17)}krYnNpjzJF;YFHNIRǝ.]ocFM ?3'-+ p9Ɨ]8(8rd9A-ߔ.zދ!%2 ]*&3M*D9W{O"SsCdGaP~$UBz ٍSK>pIom5vN.¶"bPOn*]P|@d L/n6K'1߂ y58-1t% `S?,0 5HCSOJ}=Fޓ P`GQ LL]5Blꆦ:QTS{5Vo^5vZTM;mR6mnȤ6oڹ33@Oh:`~I̻܍5Aic 2Pt,iuN9l^g &khU'/U\VaAL>~'P@MᶆcĜ[)k,(&E{uM; m%$3@P7sj0+ ϩ l&#/[$ Fuo>PZML89r'xwb8[FqY 3 OqTM[P _8K~Vb=o>e`cKKIJZwϫ_ nASxSv~n7:Od-P {ėLDm~wo^z01t8Lw K"pwE䉂B -^ Z`@?f+֌n=Qe %DJdtll7goaʵm!-EǓw]]>0oS8PG,(RhѠ^dY]ŲoԅGO'_@hb@; ʤM?Ϋuӻ CF~ S(eAϓg>y2"RjV%')?xHD(Di0Y3q(id-ZzuNdV<7ev~Yh;7557ڈb~_1(_^1%@WEnL.kSˬ o?G[(W`s>7v.sM:&?so1LH߾|:?8? ? ֯m-;w,Ґ|j7!njLxC!e6LTئjhNr6$9,,57)c}1eڐZZґevy.㓥,bU]K;ͧM`Z༨fҳ TvD3{}Y`RW^8Z/Du/1ׂ6&p]RѝTβ.ԜL"1}\I i S߈M5CwcLB&~ӐI=kU.lT!Aʽ ?J_肧sgr#IXBѠ7g7~AHZ[h|@C$ig=ޕڗr_fݷazZ:N/J?N!܊F Lb i52]wo 5/;ӭ_[ { gq */s)ۏȄA(pxEt"j6 ,5Lt"QENH˩y8<ʠ`2 :4[hG#P7PxW7vMU#l0;ξAϨW3pjiNFe^׋BbGV6)RږĨhG5EQ;e׌7$^W~ė2Dڿ: 8BpV ÇtRLR!_J6wYʜo(;;;l;3g#t#"4;a2tF\$? vZz;iyl)azAg j<s#+bO5JuW~Jyo&ㅣzi=O6Tdlt.׉?qI<8IoW5`J qhmI4s ըJ aa!Hv]`NC;ǕWb=xiES3Cʢ,RyJe[Lܹ$*`aGfV. R?-8\#.8ܹB%)ZQV`S{ ;Nc~rj._?}vRN!'SC6v)tQrL#rɚ[Lv5pk+B[eL̽YartHM/ciM'͎`NTa7=Yoo9 2"MlKDy\F-\o9!1=H"t dx@GϠnKmeIlšPvܐ$/@VƜnjBˏHib?XypRh;^BMh 96iDC`>6)o,##Lf|HOMo$FƓlɟ+C۞ajg$wg*њ 0w=QZ”""ׯ- ɟd<5Rz H*J@)dr+7κ lL Nچ|`٢~(G9Fo5q,<(\Q"zT6̴k;Ĝ;3 rFj#K-@z$֭Tx*OtQ}o6{KI m-g ɓ5h=1!jn2vд PNS= Dˆqw+ -ojD"v&*'Pk" :}Rv V}Ժ8 z c\ e-3fZxĂT183 tþ e/n玔Ei/KT7x_fv:ޡD\A5/=mRgb9|! yg ǂThe~D14v14+, 袠 K4QDZ*8wq_._G>5 I9Er*_N ؓVۨF}39Xnu~Ђ b9wV|*qF#H4$l'JWz`JAa6jӜ%í oDMCq?;gI8hb|0ҿ`΋{ds;hrz7rK2auC]$oPۜVU5BЮ/ULCh߉]y)/k@,zD޺|EI+0࣓׍Lr} E!pIt pѶ ֓ 09JL!71hݓIn\BY}F`UZI aW[<}oe=/`J i(l 2|{T{`&%~OI ela)PKXd>8Zr$+XPqs_Q|rl6p\m%:r8C_e4!Ϛum&<8pe?BhN8V݊y nr[m[l05}kûIQxocmW`wk҅Dd<1Gb俍ab"S:-떥#%zDg+gɹſI&7JN2ɋadj1g٫04Υcf4 4^O7o3L`3ʈtoyNnCYjPTG/AO>/Mf61HFw!@fхZO aCPYXKoOzҚ83Nfp4,Ep_\.f_'qk^[M~Y$*oJ,.[f%a0,/l2sR&S̬쟽ET|g&q${f9MB5[l2 o 3AL[^sCgIR5N2o_{6qmu_"t)z* +R>eAoͯ&r:0zB_71KͬqKX$V>iZfu뼚fDJ8.<#h&Oҥp1忎 _WXtLӫqzŽon\`tƑӈ=zǢ6K3,;dRO fD}+B5%b C1d@\d .Btr(b2Z=eO`̭ӹuCP\+5cCQ&25fGhU/ID?F6 Lq͌Sl<гe P_M.~y,sr{bnԻfN1YC>ـz/İQ)W ^|wKm*8pdɩ4#/<6{زuz7?ǻ]|| r*8ʋ4Y.3hb=Ʃ8YT"YYݨ "RNMƹӀaAHhϺ[$O~U3)KƐ2H}0S>]4.H[*lYR?>8=xdgQ@qP+* {/Fi 9r_4mwFr%Z$)2,ҵO(ކǦRr'uQ.oI+`CrX'&$pഠ s~GwF ,DW} R}hԍ>^Xrqx PAL~2RBv}Uxpa s224ܯE2ޟ u6\!51fI \l7QG PBŝyV$"9]L+&\3x2yNnXU))ہx6aKC^!%.>R@FQ *DJ'ӹD_W{8G>tt%$yC3;.CAJ46 8~[IceОL:TQ"1!$Hg/..ZOuY ?)){jdl15Hvؕ6T·Yϙ ,^KE$SDhHsu9KaߏH+'&e*?t6PSK| :sC-W yg~z_蝷N3HOTRY٠y_$c̪V0;EM|3MTn*l ȅl(ir frAqZ f}d kgO㴽W\5js|9;m: .+}$p[wHaE UW_u#Fv;ѻ*/&ʶ$*!MР> кG,)&_+IZ\|Iͦ=aڙIeQXp~>CZ7t cw$ޔszSi־&#ֹU{f5<{t0~B 6|i ˧CAwZӏ2  UJ@6IEq2RL94UѭR:nlb ͖^<,&!qțtAo65RL|m%/&nz.J͸̅Ƽ_Lw2pcz? f!| 7*#"_ WHxS@,IŹ@Ez9A7 i m0BsX)Pnd/6 ߄c0,IB۠'8 'ԨvQGʜ.w]7b>r^Șxƙ(ł֋תRK_Mz(DZ g+S ?#X@@o`8Эchjojs.C6`WT`X\xWt5ShY_)LOLZ~6EwŬi^b_D'wYOa2n%P9[\u> >c /Lv6Sb#lpigijSj]S{f'֖T* -]Z-I'[#1 dFUbVuIUqv&Lg[C\ )ƈMK=z6t.vYӻstGP){&@8+Tzc%M_Bj2/O 5c?r`FQ }A u.~/S_j\6i&=K쮢݃Ѵ0 x{q=b`Ӥ` M|NEwkqI1wuO_O*SFpݱ`} !$ENf*tr%=t!Xx~h%5{)Z8f>7yIg ߜ1oXuӃ(GA]dfϦ@lFl@ g ~K?U/o ibIMՒX\ jqx?L؏ARs=ɶ8*8d#WpPcG@חtj;4$ 9V/?WSte H4%¿ܵ42Ϧ[7yTw@*cz\75Ѩ Kdq7Z(IG\A7Хk7 ZDd3N>yو㹷ű;wEXN)j/[Uj\EB|Zv#,ʔG|Уsš ytDQmk8m\,"M1skKѫYGji@XsfB #|( {Kwq2IUO+؆0"a3 A+n.Q {tF^INEpƴMJ3T {a?FKMmEu qbV\1>ύCjkk{S<1zNDi!*yz85&ʕJbAoZP4Yi^0MIª *MFhL(DIf,] CZ~o3#A1](Ao#BRvk}doEͶ}r{O]Js#" <,й񌪗1R]9d!T駜NxwFh/8[VpC (vR A)g!&oOx9kO@L㜗V̦^iCfќYWB7Z?yf=iȐc%]w5^PhmUCQ#'6Y5ȘJWGW76c)+~1Qcv5m|ö6M鈒:C*;w=訂KODS.^Mn8]*^ yX2)#*ʮ8wZM.fߔ#Q$ӨUU}fD}Y~1k&Ĭ-5Qi ao(9~Rv9윧h"k\pYTq ,.8i($4Qq #[M2(e}Jg$°rR$/y+4#P2$ە ]R8E!W6#ݵÝ/A=e[!A^46gM@M)*'zwjFǖmQ;-;pa n8{xT׵M˒ͧa,8H&3ϗ֐κ;21HL Ύ4\3) a%;2VY}H#[yb Eh C!IY3@Oy 7)cڶ@̖bK#gH:;*Rhoj 8X,guF*n$3.N)u{N.}>{*~$ >bH +MH;%WB8@m"1nG{a\c/)-D'P ι@Y8%;F{E o\&@!i#=Ɋ O B.b+n /zЯ*Bp=<*/>dxzp( }!̌bq{0l[J|׶:JC\i YuFVG{L 0#%ITpXAFn,2UQ*¢h "sѱhV=/By+햺n_C6f,mMf+ |}X!Fu5GMֈ! F줾9(ɲmarphSW-ؙI], QζıϿM9Hc(0g%*ڲnJۣ=7IE\B3q!Ͷel H!U6|^$wwM^`H+-[({oqdyQJB È&ԒGDG9^oFPa ڒ>|&Tq3=QQ5ӈgGpag;?r.OIkk>>UrwT7>|b`VKa$`(~9}Οr]u.mͧx4%v6bgqtﮐtBFKkR3qǩ3zH_=seT Bq/X!} p^s.CV+q8rdlnRU#/VTG>i=D ~X'3VV!|EHRZS .9 W A.@8p"*iC<1h:ͥS)U!q YjQ{K᚟룅i}<`ɍS˲SKEjr@E4[md+4ϨtyGE1;r5b5sbAMkVNeTV-V Qnŗ :]SomH1+ hF fu1PT$afH]Ȩ9{@K?g1 [M"/ aJ_[wFxqnwʇNRO`DN#>%vu"D:ÇQ.$G;YmAS6/9[kXvޏAae,j(!+:iɩ=izMsYR[V# J]V |?:sUCk-_?`s 7b(0a>,Ysj:*mp}܍b>4c `ULi!9rM\:oGA*u),qt$? 0gD:&)bϛ{uag' H7lg[S(b{ NMF+n$MaF@4ŠcbQ>4s}Ѿk Dcs>hm-z#'ֹU.daQ%eUA葡FCKC`rc *j  jaڪg ѝ3{6j\IpBЏ\epX(|\%ǒ D{CUxJ"P ,@H/wϗ#klP}ED+@'x\UdD=grX몹`ފDž{?(jMpׁ 6(h{ZiWnΓ>\-/o/(qHQO;*$`@-nPFz *nf͍ bYpmcfdMFtz 6i]rٶt+w~jвaQonSpbIPč=6f +ei ׺.kǜ ,i<'IP 1=&e_A(­e@ԧRY@g#,&/䘻H~ !hpDyZrؗ0$C\q4W_j6jM@Qr8\Y'u 6!z%seu-!ap rdUd 59Qk$s[y 's28 bT)L6T$R P]S;_t,X O@ _fRp.= ,)vL8oݕwШ0lh(NٹdɠVFk-e&ū{ϧ^"}ıX*~!ҽSWi?w.~`TyLbBV!OP nI:_9jf6z.4>Ŵ[n-.9@" 䁅n"9(yN u(z (+$q.)p@Q#d:c?$c:πvuBlS:Jsm$T}Gث(% xA@xKd( 5Gf #DX唑aʆy> 8V3H"D/`6Q;}! _ף: [r a$ɉlZpKKWAt|ei,ɫ.xo ~ i?)ӆ< f B $9;C;G(ilC OuB3z.Σc<_=2RS׊窋Gc04ĩi41<@#!x*AVXV<3ŜA%vܪ'C8M*KNLm3R~b*aq\>K7>򏠐NdN͛u Ơ9LdmouU|.r$jȣ9f 4­?WGyi``* w1ixYPQYD=o>pE Zqe/Y xs/yuKtLNʘsk&VU/Pi -*"MO6(8QaQy Uuc<.CKoYsiO>H5:+ǝҪ0r;WiAE-q/sAWùiG$VwcRpju"xPy,mNVؚVGa6 #!`cjT9ym(~VD"хͶa27h!&sQOC{JfM> )I!GA^f pD=tg#[}N2;"28rA ,=\S= e0HYƺƶo;v7MHl[8,~0[Npz|;vre5AfWC`>N2}bEB~3%]դ!<hd"nDNZ&dt QF=R?5‹ _1l})'79KTe҇Opm ;ryd|2>x#)5*NCiMcOHӐwfb r'/JN (|JdF~NPUfke[ /KQM[G:D?n]Oy76iQwtc|,Sy7ni]*Wo(l71 ݍDt;" OD݂Kyu0 Ēms³)Ȇ_f l{.)I/Xfl"ɭA}W'H?[u^^9Wrɬ/]͊m9o/dЇ-govPℲӸ3ԝҎvcؚg"-W pg[]SE-[`rwt\ZM,|zo_{F<0l.kg%KziK-+-軩m1H2ThMaWco7soӖmԅb2!,RxeHL etH-0]K `0-s >QɞC7+:{1wq BjAsN4l_9j]/FrZ,I_>p\Z0"%jem( & >F* <<.M HiZ<-bA7 2Ɏ\V5%%!-gaڨV1~c f Z҄a[=3y`U o *N&ϓw>43HEEh[ o!S#hW .ND \r^ ʇVHytk=S9ٚV$ăTn]=/y M ܘrjPڂgOV]Pkl TsJ7'uNz4Gg,3ڈDג 8kGĂ=G(#*JڑuW|Q[5ͦ-P0ҡ}46b4ݜ=\jѷO"\X˛ 'LBw"kglrkV\U_p8]nH ]Iϑ6)6k@6Ҡm' Y$69Itߒj!D⾦_#a4Þ|!B!y0L!k?_v_lHC;kzˇJXVךԁ 㶜7ʹ՛imk,A/J UAaM${[p2x^ﵦӨ[[ ,O 7#!/SAIoքs|&N0-r\jo4H옉! х9v JP,0QRAǒN*$ ĬPd̪nbR|A=Ǯv>fϖ NjI@@"SE}p#Wzr86jAv,\IY l KOg+sӆ v]bנpOx6(;p'-h!@ɗieECyNP~)&'B3YVAT5}h4xPΆ3:߀\)앃W}EZl>YWK>6 hhzz(veQCq+y*hOT>Ql;xfOj/,6. UׅvF<0DH}i$HԜaC?+agǂNk׶۾gzBDpIcߌ瞎W6Z=ەoWSGK UwwbghMs3ex7eUW+5Tx=p sb9[׉JR,Cl !&R38>ྚ⺳1U:t7.dw}-UfEO@0U)= jpZHpJ YW:<1^n'%jPG8c#{L 3c +rR pTU|-ϑ]p&tq]q+]D8"hTf}d5Ǜ0|Fg{Fg;ov7N_; s?[N'zS$ʵxbl 3Zam)#AG -烕Uskzy9wOm* pb{s (I?_ v?mǣmR~+lɰ?t̽S!N۫%Gm_adn}$ܗGW&i$N_Y|+9b]?V{cbմ"XOXRrŃafF]u3$UsB1>FB15EmyC[&+J/V=Bݷ?M>Byp≨T ܅,O 4fKJ [&% I^] s9ڲ=f6Z^fyVޏmI%SqOA(wr7GZDs%wC'\$դPҴ|KAIJsD3`t-e0@?)$KѤ-}S3n2dZS$!rh95 MĹD#M\-F )]H #moG{NZf8_2CC QR=eј+v{%`!C96b,Mt2锨'4uAR05!I!|.pi[ԣWysx R.`x՚9 *+9;sSzxgQSC ́okE'u/* kG9s4+-Avdb5߹Q#G_!DvVĻ[Xb߈~zZtiudIeu^nvhb>h[ `/Bb6B@ePCj?mwb#Z?Vn's")IQ٣zCdcD'9r u+-g.Soj@;2=O~ύ V0-4g;a.}PCdn)\`VyҊ' ;J 'bU#vq7$#9.#cqqZ$Zo>氧gV\5Z2qג Yj+v$VJv@A9nl4]Y-, { !%o.1;v޻|~ۑI34mt\G}`dSE\BOn'+L {;W>?OD@~I .~zDɸfie`V+-"¬qMY $')GG c܃Fab;zLsDŽŻɳJl3ǩ G多IW}MwiAЗ SM9Ơɒ2OXsĵH`^ k+k$;dXW!k(. `4&N@cUPuvi 7%|R=4G3,5"5|t}gSK /9i<M4\L4xS`4U`Qu?@afO^ xs:+_Bs sr,lr lgpڸama̵p$Q{H}a Ŀ>;A!560 "`,kq8OEjYi:ĉ \3teO+8$sGiv:|D W1ѥқ Wi9Bf '_1Z}|U4TvB:;k U( \hoF WdZdb PqV O`ܡپʂ9thϺ K[A Ug[?1r bT-M73@+[Ųr84F [smL8GӵbW&'`Hre!_4]t;ѽsu9ه ^?S|6ݲu4 HlgAZk>m 2BIɛHq;ӛQÇRk=dfwu Cu2icQv&((;s$!oFj Qjl YV0իqJ #jW3!c07,l$,=U@='%بDnx;bƝڹ2 "CdkP~9J{4۽>սwTۑxWm,rQ⌏, 1 Fb zF*sy7!oؚjR YZʯi}dY$S#ӽ8po~)Ntd~ 3UwiC)%Y2Ijfr1pB)\i /9kOq M:p(0',nњRkwR"N54%OXc@E-SŻS1ۉ]H3xlanz6Twp [ۢ?3Gjgh:aX͈ONgb9m] =%gXn2F1(S3gm4ްK~jk[CP gܚuĤOVH7Opxw' AtMsC-u,C.b͘4rroV5g'G$HyXډڭ'0Ȱ˅aQfs~ ?R}=2 R~x~ !aYӃ navԡ4=3v0c4+|ZY YZm<K}6x}`f@\1`o#'z }8W\!6g>"B%WŅ6~)TYẕyBW1%:Dԑ. D3n/eUEB6Vv)Vܼ$#88cV\$U}8xw}%1~#\<|MG4|oIW1 ­\}KxfCv+'Sgv됢r5Il9)?BEUqbni}(x߽*]mƄ51+ B1d==tD$^tvng^&72Y̚ɷ8L\FR8MgVv[nO XJ14q*<$#KH )FQh!B{\鋅$XW e^#@,MaO!x%#i5sTCj@Q4s*}Pukĕ'V "3]rOq+TKɣ(WlB$uug|=Ա׊uCH (>櫲}s+S$֩9_?*U~vKde,\jT΍]D{~6Z[4$ .vaI Ϣ/HTY.ὀVopkYy$+A'<'if浖 e`x#ކ-vlJ$A<օZv*((.xM2MSj8ʘjqn㕤ķI͂!z+%E@}Pr/2e>_"/Bo'$I3pӠ3ra|>gg;kۧ{R5cBv+LtBȯh+̊B &!G)4^)/e0qH .Wϼs fa:&8r70PO0Jl\~ޘj8л\"wHMJ5?tnO 7L>u@׽3pA/P ~)-=&i')/x29*R)yYvk䤡d#!}mT-6"RNci>-2?t.Qo3]M75,cm\LY? XV{)`60n;vSm.xbuUfCH$ݍiZd*H}``^r<<{e<,zBR U`!1eX{ @lzg-*p'݊r McjlZQp? bO<C&ӞO )EUׅ7MVs^?1KH?x+|Ӎ_~HqTq ̘* D]+hpWqf-Cv㹞Uޥk- ,*WIIrЮHI˕9D< λ~\R[WyBz;"ؽ+u-se:O*Zо>jBۯ*e pۣCލӊ%H/cco}FFBG[N.ֹYsz/`&8BRjN)#9qk qAۅqElG=fL@ʸRX#)Lv+4ɴQu$ˉ}'r1 pZ'͒׵Ro_/`^ZR [1EE++VD6|[Ś*ѝ" ,Ԑb#Wk5++-r6yTBW(Ub\# 0)ܑ&P %kX9dms 4[LI|k2{7ݮ_;`A€”FD㻧|('?>K"l?VqRdnrj0Pg'ĻyfL ]cdE1$E}SictOu ib!mu'EÎd'`̌pwߺնyNA֡׃Z)Kt)ҝ}? }boǯ}d$mAFdwJKV V6őZb,g5O&\#X3~걱iq.V#>k(K54< OM =O(8w:J;IH=SCiz+41`R^uKWZq6ۧ7*w}55Q:rCZq!zadXȯ@'VY3m4Q#QkގD4pxiq0zbQr@Ѐ؇MczKE(w~Ar ? Ry:'JڴlBX`43ȑn]v"jSiJ0HEv*/4|b=3qkrFIu UokmF FR@}e޳AJ" ^7GM5oKʝL'ۂ ]5Jʑmiԙ<8Of} 6?WRg@[ :/ӜQk9@%6Yڏ'93 ?ppA4EI~/@Kr#p{|O&uPQw ,ۋJhTYnAԺ+)0¬)s0y!׮B%URͲQАjjs/ ;kY*JM-[0rph5 TXy[-k_<4!FG:74og\!xn8}-+!{@IOnWO|`H^ M%n5ۢkD;bUj ,rVvdԇguiH.'=Q Nn+} YP:[ @QJWSrF/]; Fi,L2} 'Bj; ­ahUۑR\Ә^Ն?[hd%qM5dRe:`SvV;I(H h 4_J~o9S/ ӱ %5_ Uo^lz˶$`WB1IoLÊF_R4hvtCbrÐ\ R|? nWԨd&%$IeH,3W|'%`O2J\L,3'?+/&9jvt{qmv jޒAu _hF#_Z;W|D$%Hh qػzVy^yڟ+vb]?Sbbè-[i@فu,S0' 3 p[Ѣ-m+K:t.,8)\}LL,H~Q2?!gAySr[0V<-QY Lq{D@l!/Ow6TI얀Mq2P&:J7+ gZ^{=}yWZ𑉍xctۊ~zA-I5T(}jn-͜U"z%W rUP>"'ޥ77`l܅t[6Dq6^$ʐqWo- @#L,|DR]^r kґٴ>e n7'w{]ygtMe(afAO? |Y8U#NzT\27Dϖbʂvf5R`R {iwn)8(g@ ײgM-~]lH@+;zgbi -˜󎷻({gh\\pF rĠ ϸV"T 8PLݫ@S퓗'[P$}CsͺY92I$hhhEH׎Lg ȴ\sV{S&az"/X.lxCH:l8أ~!qOF. v6K?" ڟ^ 2q\<l y{d] FAf&!em0gד1.4 }S ^wRM>*=;?e|hxX6_T, }^IMLn`ZV6 3m*6 ,o 8M -;CeG di²Nz!H4g[$~=ЧưGj$r<^nn`ٲft 0(OޒO=:EFp7;SЀAQnp: cH̘h)⨁$4*IƖ0[h -}xZV "NjI޸ĦwhjNB\byk2 MuCgiZFYhdJ<ݴb›mw夳򒼐tԷEP0w"`(1[,Eor"8Ŧq2S{4Ѿv<|~RPzhG Tkc>kGg=1Ђdj EP1+G捎/89CW!yrI5R;*FqqRpLb6uKV+! \ܿO׫NۦwLk8y!j9!lO܊?H庉rH4Y^ Y2Pdn^0s$a<վoGKhb/M, 1(ݙ:.bNY;>FY:bM4ORQȀl6e-e AF3݂#z=~@ }>6> Cn}5y`8gxO];A/{.*04B-NdV~T4QhCz?,=J''ue S\Ȯ!݂)=%k?@5prЄCN_ztCn +U%@0YEpNe*e9a_U-QwDZ@Hs0*o:FPdIE^qj86074sWef#ZmQ8Bםl;8gWK"iPA"p*}*] ZPF5Հ SmdOh‚o՘m5\M:-R׆uحr0'yd%5$^tΉO GT9ܣ-8{#m_Wyo<oӄZY-kfAB/VԿ#!/:}5 Ά% Xc蕯ɇ! xECZ,*MhP ECa>EDYоMm?z  GT) iڙgĮBjnVxYc3^9`?v*' ם۝w&@{*~ZؙS[Zݴp>Q3s)iAm<ݸ  Zg !y_3_yrkUu|?H.]*{|34! USh/[]rr;l)Cf>@m: P\4׊!Ol{b2KOZ9%W=˗ЊHzy.o[!fG_Nr*'0< ]eNu$*&M M+dԅtvHL]o4G{N+JCJ86Usnr+HuiL74^l?+cؑz_eC*YZ@J"x0zRe;mj4m9Ds[&40ŕFL9(mu4dt&dwZ+22vB~EB0c\1ߟYZD j;o2!Yޖhൊ_=iHF ߻^o&}_g|++ Cph`jm:'62h<|pFI_Qf NᬈXQ%$>רBq9D =_eG;@B1'%1qՔY`M黼^Ux ]csGm'76ϤP .CB=)_*@9!#@ɬ 5EeV*:YY״CwbņT0v[\: .-h:pJu>@%}j&2YMV 47*6'td~tgM(b(lj00ٕ{O8|=պWeROKA;fs@c񑐁 27aRga||L!̴>hnΜ*pW֍C7:As:sÅ4T+/ٶ[Cpn(iρ+ QMRd]#XB'!OCKDԏX*a}8a1EJyn y?VU%~tф D9=?,Q:h×jZT^QOzcrC,Q[=V؃npVUY;G*Md%]&HR~|ng0C:%e\)N,әJ ^ 6w{4f]~{;1Bğ1|d&J?3LoiW{/;ɢÌC8SwmIfъ-U^S6,$7S m4FJg@y>kDY]%7 vON/VG)r+Q2mF#I4;C!I^ϳs4pQBg*,J03ގd垫$q]4G* $%Zg7,igqETSjP5 L< ^T1fԪ+wi'a QDNT,1a:vQ玲JJf9dGi;ܳu˥ڻ˂spC/h%*)HQY+8^ mB2IsFE8 3Y5:}_ t޼ڍNWі-- 8 yn# w@&b֭)i>Ť )46o<1=6hi{ v:9(9.>pHޤ/ B\@z'q3r6, 7 n!Z\IvO@_QLOm:&ݩl{gDLaCl#ͮ/7Kߚp":/)fUt9ylQ0=dbq$i31%yjG .C/!TfΨb6 QR^e9n\t+FyNtec@ݐ1ba+GY?;eIrEgAH嘇V Iif GBLw^f;D|qL޷S )׾T,g! "a H*B2K(֩Pr;#a`w;l \e$Qxc?´KC)xL< ODPdC26"ًc71f "$N\U$)8ݾ"ÇyC I7LJu#[!Q|OC&&,?1Rj$o2տ7 ^evuzxf,^_ bqI \QkRU87H)P{S! RW듟1hQ=XRtP% n˽[.:4\ќE;xSta7a (X|=ƯJ>[2k{d}qCd7J0W)J:ol?L8#LQ-& Kej bqϒ ],(lS/F H pnwUfm;=ś&["ڽɓC!\rͷ1N4)v\}&,?@L2PgZ\|*(c@.Y[7ɜo*NA̙ ]]78Hfژ n!VeӄMKzPp ~-IGeC7/buemJ9:TU @6*RJylxv7:Z蒆3M{3(k;P %4@;Xcm G: url(M`?Ђ;]S=+$Y4$KCsE0׺EW__*gr.mtt> (эFYHl׾ȁYMx@S鸺_<ԁ؜i,7(i2cgWaJ=9b};f$Ӫ9jC4'̔0/ԺSr B}!]=q6qZ[ x( H)}$mˏ'mo؞M.[u,> $V6Y]u~9>;o4:] =ο61WNr(?I tUlWh}3o0{[˚ :^ Z*9D0,U6닡tgHo}T+{]esǔ5$=p=Qu|2ˉnLQOTjWDre!NL82 j{Q>qaoAgCLU~K+b~݊[ۺ }'{fW@aH8GȦ:pX4 d[y*!l34SVbݒ8rNxE} & 35a @S6~S(_Dt¤`\yJcICZ|z`ft͐BpՋK|uG1r٘v"pØ`r٤N՜LVࣛA )F /,JVNI2 ljye I !/g0ܑřH (J"j`nmNbZ79)Z멞N .]8YWz%L1 [mZXg$Y,ڹ'!*|v'Qh18>Uߨ/︎p/SsӣЖ>g"Ck+;;n Q#7;|7.ɂe*06Sx3z1o2mPF~=~ۜ4ȓml_n1tnR}nԭ F¥YQEeyRrF{v{|4|U숔M_Ib2w?4wnson0NfznN!^)zd_4(?"P'ќx;%7SWECp纒W~08b`:,Pp\R뙌LɊr~q^g^c>tV4\B0SFKdEYiTQs9oM&aCzaC#j&^A(2,?G U;Ͽ:bg[./SmZ?ȭ5^vcE#i!b?a{:vGFRt&;q+P.#s ?Rxf`% )}$l9_<'(@~n]ajV ho,%\\"p\=}M3A1@{Z~]:+q5gLE_pDbDY.ynŒbtE n4.r|U{$\-~ c%2_δ 5DfN͋i3o\{vnjOQT5E{޴6 !6?\bWBI+`YVBhVMНm]*p~gCבЪR"i .,~'(73!]a#Vb0>a.QhUGA,q6P?OTJ@K,?!\iTɛj($K_q'F#ɺI7\k$ro&y B\X[kfE >49d~p=/l3ZaL. yKl1XԴkwT]Bf#W9zVH"9&Ɠ-u"Oσ7lB\ 5=2)m[ r=Ъu?RL# -HPB!j6ZeԺ 3l{{5F@ЊX/$&B7(X}u n .3U~V|6ӋU- _PUn:,7E}XcY"V]ϭx簹ݫShf\[fa4)q'huV8T#oW`A Gmfj~UBJ(pWKƓG=Q W-@7+~$ilB޼ɲ /|[π;}tAKڽx`E 4 jH=5/: R"h$} ÝƓqipyk,Z(I6Y~V %ן计}|ơXHjd1/y@YQ4R}E7!$}J=c`W%O7M Ə=ւn瞋QH7d Z ,CBQH W H{mv(mKo\'@""ќ렫(|+>B!ҊΪ k B ֚m(Ry.Iߣ /VX>YpՔ<*uY KA]WHNzoI$Xe{vlN-)6Qf̩6K?.eׁ 3wIl@bNٙh*qeiTׅ/Գ9k TA a;>]^)>.).5+XT$WxɮŗQcydY<#w3*7 ] u[KJ9WQNxg|y+RU4Opoig8mW(J(aݼ݉k%kqpΕ4 :6TUt!C8-H7)U5*L(V n}cO_0l&Z"v{j3LɛZ晻cs d+`@lv] O6nwk,"oY[;S@w8?j_F'ZaU[z/=J %Or6$Rj2*"RLO;}F=]<ޠaT;QV<:ȍF{DULLgq:\UbUM0PљY<:l^boZ.. S$@NH#p O9@B\3)mceNY-=c|1v)tO?2*]|NMeX1]ŗ<}/LvTcndP}K+!QSw}+rmmRK#jX$.Ù&pt: ??RE n3MJ+"A? :W}>|&H;qa5atM8}oȝK\쮅'%dKIZ~{Ho~&Y |fas9$D6. ,-}5fu{ǵ{8tTv}p~pC u&~toO gDP2Dbz9@TUmo(۫06qRwN ~m~;|Rem/odU)LȈ!ev3S/( H5&FdC Y"- lp6R4Z93?ƵF&/7oAe] sdbR~TrϘ>dZ Y^a/mCsx\փ? ?&{o݉MÀLC䉻N`0O!JCb xͶR8+LlGd躺Y2(s0M1b]e-OF!L?}'*(8BZ2Q='hl_-ة^῕LR7̟(u7/Tk)Ro@`dI!ef"-,@24Nw"+J7|qlLߊ|fѼxi++ᔌ6XB5š k%ob?fur;>pbHEH"?V%^(u!.,>@L"uѿ`Ąm}boB43#bnehoZ{j2p$t $0}v`d ,:4qxnE?/J(,5^eoJQ%g<T'숆/;:jtqb9t@SP2c_ßQ|[nh /Ǣ?:Yh}|/#6G,StC˻-[`?4{# ^$Ę07ibLOgyͨXvaߔ_tߥw4iЕ[39Qds]NcTx ,ܑdkkƬ']8>[4uGCCp vGF񓮚O|)鎘<҂zh%6hm`!*^4,j,vE)-X16e[~ENㄼ2K\{Aɢ#S>_tu׭R[rBU95AIAkd,h/@Hٶp~Z] ɳ'/ `$,#љ8y3c"UB`3I ⴦=G#^xZ}#οG^ CUR|t| $)F4/0 UWa kgMx&dnI~ʒr!٢dRՌi8HmC7eMZ}fDFO_H7<ިC gdrBL^Jem掜20zZNvx1Ji8~{ beoY)Hq@GT!T[[/˲L@[ ц>"GGm׎f{d]Mo:, Δ,̱x*hCcUgÆK[Z}>3=F n}hghf;kh̀;{B }ď&5ʗe~ju8j O'$@W(hhG!A"Ss%KXvʯT6COC3dwa/k6abn677TP6h*2!2[9l^,ۿ+k O<FëvYhDAڛBdяK]#_@xÿo)HŎZKN`j/=a1WoKPD qp:Y\ 52絵zz;j}񅗏Ge{q{yQ_7ICЙwo5Zi)# e葸"寧leӬ#Gu̓tR=p礰J̀7p:y,>zv}:اT`0СM;wZ, ;@>ڟ" pB@ߙ-$DY%@@=1|?О rcrWS 4A0li7@[YPNs/ >f_ ^jrM6L.ӜR]3)`Z9<ꅂ u=_;Z4d=B&t/7%7ύEn2M+/Tq%f}UnR؅ϼa$vyg [D4pqMT;Ԏ״S}bU uPڬU' Gτs?f8z]K2Tʋ\v`9oFvwh@箐H6H>ʊ )̕ok8_ OgpU QQ O}vV c1EFO:!Bm5zQSWhR'aƏt4s9K۶\GHuH_*P+ELuo }6K$/ @9` 7[~5qLsc+HPҼ}kmWJTՌ8$5rW-CcMc%s!ޏ47luƴ-Ժ-.'.x/hoxYފB9kcXY;%7DƒwniIKvy=4rN_E8*9"ɡ/xksrn܅3ԁH;~ (\hK ؾb\)­Kn_ Lew^y, AG ı$+8-G N! t2`zi>.#&ǪpH׮"TlKL ;n|TvJ~Y>V^&p£D>/5^`3p$^/ELZqg\N>5{ =bLVݬ _1K[)8O+#}k}Me!6QtkkFDdX)Yo7Ez=U!3( t3. olywdb.$r|& Zp"wK=Cǫӫ|I A'K'un 2i#Y಻fؚP<R8HXTGf8J4 N|w~A9.˪IV yjɮEkL=^`|<IJ^BόWIᐇ!-#nəov:8!$g; Pl\JALw רA{$-~sS P1N 2cat;P*@L{/~QWY[mg[_}y@MS2F'u+8{y%Z:1cFpք3w$UAaq¿y.}V$ [97Al˽-Q@=Vg~6c҂Fz$psmzK3^ZD)T!g5y0D3ÉÂv~[#e;U.qCj&6kx7IV$/՘snhnh\ch~+vb}G 4S6A~*`P紇:Z&\4JSd<uA1Ry( бólb̌a4"eI";8Okb=vM<%tfNtG;]I[ѕFA e#Box"#G^e]"WܴSO)ljl:NRrB,K't2L3SZ2ڞ=p/R9/p̽G%.y8FF.rIܠrF3.QF>87$hhJ 1/$TW. ZNhxbR̍GTm5/9qp*_kH7+y;wۆGXٌc1@،ϒaK[R8hD!AޯJclDˉjpfp<!p(i(4..qz u%`lܞgq"!jr&EfAщQR'桷[@fP{U,Pj 522z|ƨN*-*5!;wr*cv5a羵,rq k/>æ!;vʃ wMdKU=?U-f8ʡ~nFOBLA͊Jr{'VՁ[#&Zal^=t=qrC=; #sr$WQ t@!=}#f} ;;4MLVcR+I|eyԦVm/Rr9Vͬ>{KdDgSVѠuĈFt~TV׫ɯ s{o6yUG/x{>C Pʒ?5P;ԃ\~,Zu0_8+褉4q5W[_ԀR+eG?W w{ԖG!| &Rf ?/G4 oqSv}y:T59 $4{Z39@뜫-pj%Z!} DU Oxv"2v*p$ S ?! > v T{z)|_Y^TRF{@4)kjR7yd(e%%m6Z`_2dJ6 as Z~ "=Kn%l4K%mzZoʱTņMс3D"PS$AIݓSno OAsLNK'LYT|<`gairkkrL<[7J$o AY}Hԁp3d˄(^V~8 ׬j-(O(Tɇ'8Ҡ6 a1ViDLOA x[d].ϱ?΀C6Ov_rb0/W0|tqrK7ٳ1B;( mDBy kasT Fc x T6V*|vhU8w<ޯiT_,hX ze;Y &E IP ~@g䰕ΟgD5 m|%iyT"FtNPD{\~uj11&.&lӠ wd)|n w$nx?:)ReB13!|<`»0Zܓ_(V^@^f<;4Od3۵=+R. ?͍d?4ھ[iFS!|GHV;!z͖")(${%{P)x7uy)N=#aJ~n8$^2bNR2|[ix/Nt+~e.NZr~YGQ3,F#=>RjGmĸC`R7\D*B?w>d6?4_:ta`/ŒxWhD:k ]]p;%fDկ>Y$eyh?H:ܧ !~C =]UUڲ ӼH )ZZs#Os\>>1u{GQ\^%Ͻ_H%-L==~\cYdw} 1y6ENsCY׸'J6 SBwD>L)hO*HNG 9zJ6i#,4c['Jr0(cC 4zaanj|bV)PUaY;M0V>]) VP5ftEQ 3%彙6!wP̴9ۢ$qJ \NmzP WEsءz78}{x܋r@X׍A aH `" AU|ѿ⧇6>D  KBP;VWXōLש A X7Ud2.j-3F` eb=bވG*ٽGTO[o''4lm3e+eYUnÿ˵XѦlm*='+Cy2hX2)Frj3,t7A1VR쎼 OMi}Gi#v΁UVpIQ$T;- _Vpl 1.O/ 1$"]lUun6`36Cyr9р +%{Dfɳri0,;?vUu-zE ƾD/-j\z~YXͼ0 RUFfQ]Wvz'/R߅Y^Zs)];.כsϠ2#0B7׳~"7?)`Ly7ڙ~bKtyGƸ9eq ď" A{4Np$B=C ^X+Ob$z a2,X6_qN'f$Dgz}`Z\݉~7 /U7~Ha!:P+sf{n2ѴkU߽gnVd %n,c:իW+ qG uLÃ?alq8Cnlք]miJr eرuiLw}1Y[j:u u <53|:>v&(_9 zޏa .r7/V?).: $sC՘sB8e]G1bXk#bBUQ7ktChFXEshvZ .rk$ϱ NP&m]_#߃rm b~ cګp˞崭Z&;^L%1]vϽ'* jxsRlUˇ $vg3M!ЀJZAnAYˉ*FEN&-aj w%bxA8Cz gf`[p2wcrW;Hx<ECK/_1=?dl(Yu5iCo`f^AHlOaG㌈yŊ׷pQUN)"~Tƣ psƖ E.ZϛV+*t2)&TF/r&_]$0^ݜWX.|DG{a'9 SkL{Rm v*5)vAx3d$m'K=YeM|Hpr00U rU䉔W* f:u&@>ksn/ l&wK v:V_л n'/'b)Jn)gL[ߪzp:3cfuEd惟P,S|z,TEmbĶ $|ępX0.%Ƹea<Kњ-5-Vj̋tFvȵC|%%qQ;Qu&\̡uDRZᓝ?3%CfP:GT'VI_ +vQWT`Yujʁap"uѾ|0|:aiz-;4=/9>{Dd]CY D|q`AxE(ycWC|nx鯭a9&DT+d 3/|GF}I. tˁJ2&JM2[13P\~m)ʫ[r;HoLf`x>#.J j0w]]V:~#agе81cYim'n2t0v{qwWٞ/bt @u!sz6E LuXiXZmt5;ht ŁCqnF؈p2eͽ>fgP@hW> +XBJH//W^Om!׫d־q#A9ojCPzR9 GHKpC"/o\8,19MDu-̎5:TW ף cfsM,ڻ`96ݰӆ/YTDJP9qw Ӎ89u ߹E,OleIhO&zπ Fdk.V8Iz&|nyZ\b,7cs0KaJj+L|TyMc#̬Ѯ;,r:q!4 S,[F((%1Y YBXd}I`JX99I@ʎQ_nTKjW96 5"AhCSe7ҏ7R"S0kϋOYF[_\!׮?(>5f[χЛ`; K! P"A'Qel9ZSQ듌Mh=ur: E݈I٭Ϥv߂I.8lm@S24D&F0X*hށ7 ݎv:>I#4ƄpY:õ3Uc' =[=< 80 CMt@C.Dq.Ze .O%Hx")/ Y}[9̗aR,NǪ\u%,WߺfUJ$] U:}mFQMTCZ7+B%ȰH:6Erq:4s8orGV_DiL~\MXj;&SO ~@ups<"տA`=‚׻KƁ3a Xuu{U :,_™bPMgm ˝OK /LqtE~)=~%If0 9\gl0f7d(Π< OӃ[3*pcz6_*g述ˉ\G@>۱u_}jGDfJHnvmaRFHzOł;,6:6"2Ydu=Z:t1hJcld r6 OfVм1%lJzl.]ihlY他nK/;ag+C«{NȌ(Q=USlb(V1RTmєWS({mk8`zXXͿs.SDaI#_.) QOO/ЉTrP;}ka32a{J5_gcC}H$qW d$!qw6Ytm'{rCl3c'B[:}-,oiM(JFBbʜ'xӫ:zd˕Pѥ5)fJDO-OWbwE̋ݝ? n8|7&aiFG$\٬5'mf9Ի i;B/ˏ&@UB$p1 5p*r:+D7n/ sR`=r7I%KF,Қ5ڶQ[yaž+j6;Yg%tms_t`,5L |dl * יؽB@fPXQN8C3v&H^ybKB<*Ԧc| (|ole&xBR4&mPs{,U m[sBDRM ɧ.ūa8KEW$ 94`kчh0`ΧS՝24M~3)]mFO EŃ9c>1pG;vkd`;z):*f9J=yFb㹐??i GzG{[hVoV.U&@݊}2k=Y=K$[v,qZskF}V.Zɑ3r yxEt0JC,_ŞVM@%{}H1t!7M$ak4R, `yUCPYmnLHVJWh]x74& H(^+*R\w,XTgW: A;N=ZΦc} ,4!G,AA~Hod^r+Kk() dlg ,CwVvZuLMZ_{eO>LNʬ:lWD׊?Uf3oKЫ,g,~֏VԤlGWlTERW)˾<Ap#Ø*7e?^}a/ڡmyr[fE˹٫J⭂ 0g!n2d`|E2O}k?^TB˒CU`a"nmfOw*?,Б:?><ɚ/WE&&-fPs- wj=|G"$& ';ʃEۅfڊGx|VY>(L 9ů9QJlabDȝaEO ){AŠ,0#dBZXE0B cwL5:'P i$ku@ÃZ?F-]P- KupU HMq#U- >Qk9^Mu;Hf<'W%j!ճu9!u .*\ Щ)n߽y[2غZ. LQ a8@k!ENⱃAp"|Bh.Ǔİ` ߉9NƘwYn G٪k%[boP '0#sS=zq.pL [Y()٪4D#iӱ1NC UUWNtQ]$ySkM7Oy̆휽I/?Nc_z{:5u @᷅'6{ E i4u?+gJ@^v lvrnoZ6}@_*&w`}p>,סmCNL1Pkji2a>_!Js]<09qyGgK`;3S]8 -jY*E܋8eC& HI9Npbu`Vjy^2Vҝ* &u =Z! [3b!쀬]9ʫhg'Јs%u>HhE/-V/DЋWV'{ɳn.͉(ACv\LP0[Xå䱩D]8@k Im!S9#ŸuSݧ' QMknrm^v917Af]iM,^ x|> dHf0gHFJYh-bKs)dߙ}>P}pX Til<'Yñ2r0`Nq:hq17#x3Vbt, 6:!Ý70w2" k0@VξbFI݇Xe~D}6rzb01~ misrUY瀘ݺg[0J|u %F};ŪI3eLyƷ~EMYqS*;ՐQ+x1zb0a=eSbYUk he|۪LlE3sef9`ax`+у:q!㝍4X)@o>ʰu:ߖsdkR[ma\(^\v މc^SVQ2NZ ǓNibհi,9(c A5?xMRҸtUpBLɘ .}|O;z-M/ u4U]vBBW }R'{oSHq+ΓeXgHY**_6G=,z\,< 8M Uo:K~t1A\ Q0۬ %@9G'Et`He)r1.M"Z%p48ygS;Ff^&=W.ja3XTna˳g0s?Rv#SГp[ iB}(tHH- nzLd=OR[qb/T(1o/) CEdtL.L?_yFxJ'RK{hO6^t8{   rf_]P/QFgb~ґ;446T4K,h!7:StaL<'~I>q2{)ˢ3nuFz^\m1eQhk?҇reqv8y:!;Ns+ .U{4"QQjbJ*{Jb6Ɛ}GF+A+A[yzVAKRRir\fKpGZ& ^?0Y#q+ό*[#UжiÚ$JC%V%A!tN܀guv1ܾvR]Qΐh@7bLL c E]DQQ/EGB[rN94|@QrrNr5hʅw|ujƌLG?s!7N>S} ?oGYetnSZ}C?7% $"'ccHT1VDu Ǩ&5"]r<,n[!&X8iyx{db7}.J_ҖΝ|ۡ;fSL&x%w׺6*?_YllIZKA[=E 01^QϷ"'s@}#E-!t -=ىfҠY6?]Γi^2M3Qd:XaY EZZbH7`Tmc"Aj$_M{sqPmV B}+{tw%y0h_>CHc9R{;4W,_WctPE(O{#b>9gr!4TYV-lx!,~IΌ3940Gae(jN/i3XEqA{ob[xC=Vz."R%' bv+CI99*&矛:.`;۪-k|A*a &"W&ٷO ?4cQT 2^XeDhMe4tJCU],sso)yqxѨMFDE pe<"J.-'y<1S/-M9]L1-JD*Շײ'ʅbCtQP}Hml^bU%S(%/&9CJٚ%;"NvȨ8] è|{#|J%BNZ|^أ9 ?ҭ'ƬάnUUy efPI{R~FBe 2inaY(Bomo즶!O1& %ox˒MuX u/$U}ec\*mɰ]Rd8cSHc‚>3wZV?~@jzՍJv xBµg zm IXǪx&sKPFZ:[Ĝtø0X,;UOCvADcjKBc_%2QJS ]# -~=^j~MF i'#}E9?'ե}ܱD?eDҀ.Q>'ݢV9U4/R7AiXSHkY/lxOA{PrWkT#BGwޑR[Ѩeg 58cqXnqۼ. ]5@hPQ!(L!zLu>is{3Qtޝ\"QjGJwMViO9le& =fO)%{exewk y* \y fLܲ%3n{D+>TPxb$Y*Y*$Sɤ{$En*%1TRWsz09mZdC?(W*X/?e:)V(+o;WEE/$*-1I2ތi`y=Ū;`Q2dJ+F k8r'/.))mq*4n)C5r+ [>nh8 7p{ '9ծbO_b>3" ~Hd"p͋ սuX cݐ$*ovl6Yq.iXs\k/: ˾` `*>)9#}=:c0bV]]^$z/u|9PڱE1n/bs&;0"h6Z`T6 -<.c{3 IviX 1WD4OГ5,PQRnx!\kfxRZXój6&܉۹8Yֺ_7+Sdg)R:˶h-- n5t%>Uа}\TL`'|{p HhZVTH掄՘/wbMG_Pb{1~n_]@kq^*fry򓕇Q6:5uM;^g"99Ppy3Э%xy)kvs3UۓLߥtҙ!07ۥNX[:Gm3ajT Cs8͆Kl׊ŅD&Yz2o 0Mãd+ʷ!á#@e}d5y`@ w ~AsϚ@hш|) ?Ҫ=M-6E a9o<|Ɛ̵Ԃ'{F31cif[Sv`?Ɵ?Vr7U;&Dۑ_s*G t;ikI:,?}Йlm'SW{: j#mtm"ZfA §#|A+,``ߑLUBGwGw&0[zE50d (sN6S^ymՒ >bI罤M1rBtv?Ctǯ P8n8B lLsdA~ E1eM0Vv:W1ﳦ3wKĥ>ر`1Cu:?! RU;UЗ~kEE.rǔ~*6~uDfCOK|WqܵR]֝pZד:  '_SrI*P/Bfxl^A_kO3Nʇ=ertgyܟFNzeǾAn {եEiV C@7x Do?NTbUQ;4V?@$V3마7 cД=ڒ4%(|p]»9>Nw t#o+s]5[.q-6f;(C=1 L-4N*RH|Y;Sb FrO,G:W%+u]Xk)[&L%A=6`eƂvg XbssC#* ٗ*P͐wsɆ]+/rQ9l2đPKzK#,gY^|DiɭFiD-#C0:Rh!}W"oC':/# c_t!~|]K:iwb QK8BS9Gޟ U$tF\X'ߓ6 ' |-`X aʹl^ Mr>-io ֥cc&:)]VR>+{?|O00@YW!B OlΣZKnqELqHUV괨,BG~d.tTsjQآԉ("[kRog;obOg=ٞ@~+k4~.sqm=Qıp0NS|&(*LDQf,4$@N;0Hv9V372`J~`)eD7ZlWTlD-4 ȗj .(NzM6QP'xq%aNzuRMX@d\gU.I +Pwg9$FM,42rNYlMFQ~AB%7w}joVfƙC 4)JtҢu5L ygeA:,TeӉ`SZt2 GsQCo9Ϳ[ +:Hogs` WY&DI~]~,= F@?K(TSک~5ePS~K4 a](q> 'ч`Z2/DK/>",ʏ$t'Uq]s+6RwxT(7)ݵd 0-`-!q&9޿5ĕ^:Jt8A˛oRW?P<4>u1sŒ O|EʑbWJ}u gؗ𻇷*aь.[2N?jP&kՠ7 L#e¯ R~ɍ Y>;r6[+>PBvy}WM (Qjs)㷏çrE3YAЯZ.E'o/d}.t.HHjΑx}L7jD{gPwcߗCc4lLH}ĶJ'8nL>%d3ќ8ʒ .ΤS"yuC-HU_j1Im6G(~pj= [GM{;65zl8,ܰͷs BGy Lwi@>)>]Kn+M3m k_č6?!jwFڔ&fWM1L!.3`&pJ'71 [(ol@ȲU\XSp~=0}rA)ok.FJ(yXK*mcEœ.43Zj r'V('G XAQD sZ.*˝X? LBÅ EP=aF;f8 j5lEme`}"4 &hXz )!eo}NLXU鷞p|jsOϡ+5O{7SfzRjtAi˼7˺uRQ ,$g6V,)LUIsunǖ(2ocЏƫP{\<";B ؁W`829uT0.f\*:зNX5W; ZMUq<𐫝UCi~ ipʪ-NIHhc+[A9T$-c ̀a*DϦtV%꺗#ado_z7NIӍ cXY83.Zj9L-sWDx_Sf%Fvڢ(LQ[Fy pWLNTc^F40+OiK-а?35"DO:j>l=^[Ad.7DO'dhʗ6Lz) {}!@s}Io@*pa_ 7_N"ʐN1{$я-}JY$ԩ%Vl+" 3{:˴c(vHL؁"jގ 06K J4 ) ~G+S8?rؑ9_cՓBQtK*OY*%P ??q^9[3j6b 0C[(hp*2M1Wy+i= i^ž!̠$"džw\ }vaCG$]=訏0*⽭J-F$YWUvئ9?%(5lG7en*$pc`HpՔ[H@~{Y rJ"H7Vz"e=#kSjY6>.|0b 5k?y|;oZ`b}N~a|&xNl(Ay*+ڲ=ÛC^NT-෷wk3q)i#,[;E'ǡЋ)4}i>ob`+ph]V->/gc*Q ,8`pp6 -Tn:E<jK:~4O.SSWOF GqΓBSJ|awZWcƑbbIDO|1 Uh7X8n9G͔OL}TI5]%=R`C+VgM!K& N/foY3vAKņM"P,uWc=\g*A%=1bKmΥgg.zH-iէrdM__k'<4 n8S pZi<PpJ2xnu3x KCO`@ BfƘ{ޞ(áUf2rbTݨ-,7c lC'+xWrqK(W(L dơC8&є8WSnsx1Q6B[M`I%=,Vr@߮hE6xӷۢS}&oPJTTt]|lnBc!w-'aR_Bȓ~.f9N>9i3 kCO:Nzc,O Im ɊZA]t)j0˕r: aTJ] IpCoUeX\bZҫ n=|x`R$H#cDp$w\^{B*ۣ("v-p\*B+{MbW @qJnKGYHAj(x)|HSl>~ސ)L.gJ:JDL`H{YmCɯh_L2VA8ԴZ2 ,Jc+[n?NY/Y-U];^>YAx~K/Xtf!bȥ`0; ˃^]\g =F)gL 8_8ȫZj{-M7P.?*jgޱr;ɣ,~ƙba8?G]_ !_cKn86pgo"_#t4tG3+h_5`}*] wM&]Y7?*z''A=I!G3-9҃kj֟:҉!/ 2Z0Ӟ5<Ζ/<2 7! w{n-ްY /{5hb判qgn:ր/O(J )pò}.'J;ۖTXߒJu9)5ݴ*x{t &0reM-f}#Ld}0? 4H8/K/0Q~KJ||Exe@0 /gJ (5, s 3b~hgO+qP ?Fz ՟7foH#wn4HvO1Wp~R-X\(+h0|2])(u@6 s&*Z 496 |DM+ )(˻ nR}tBVf?a#w\bF癮UW~kG=V+檉ByfK! Cs ZH0Xg 06 [9@ZD()BHCFvÌ i藐UBZJU:rnL-%%1ÙpC4̧ɥ6kkq?w@17p#ύoƒ8:^qjɴoiſЃÌ\b Ë@~!XNlWojF`&t 0@qs9N''`0;h\a&gbc5 !ވ7$ˤ ٟ:|E$!pznb^^Z׸`a:{Hfku)ThY=ݲTo>y1*l|ϰ2nD`H`C0|_z;dcYZ`r~/#@K2[SnBmt=Iscil)!ڸ^,jhFy0@֦ؾJ?o? HXl:ʢybluwr=ol{X XĆpS+"%;+rHSE-#'>ޟ00dF͗Zy\dX. ).e2a+9o\ J'o$a]sq \jWxH!(Itf 2q;<[Enc^$&K=@鉡+<ߜu~{+ ]1:qfԈ^^PZu+7!"Z)"0 3@ѸAo>RU/$/ZŶzzt΁+b{bǑ<UÞ|C Glz_5C9p9v2xh/{z{;2`~KE>SX4X{`7F֚y}4 0՜Qrsz.ĶQE6\$ެˏE\mC)&.I^Zĭn( cf3g\CY +ZkĂl*ʄXGW<?֯c9!2 C6)\.8!9|TN0{ꝰ$K+m:W`MNo8_$z<\|:$u4Nsj2'-<+WBt\^*L&S<\|X^x kò(| ɀEb!:kY”k7k.bXe{拾EF4-,a`WZɹ o:öz(Gx@R.49]wAPP=a΅gvtfjfNM.)wqDm0cG@lcqhIrj]1Je>!oN /3Vw2s~@6 4}3Nu/UPf)#ߑNС. Fr3 Ar)1ZęO]vc6d65Aп yn; O}K b{cCC:{7bOD Tc?'ml r4,hnOF+k07"aEnerbe깉]{* MƗ<4JQT_ cDz^$yuɵFaGc|'G'.)w*ƤϓS-D6^ƫ+̄Ԛ"fϚ"L;@]av1㮮؁q;f#mb? v'/)~uoԝpm.ݭ>q @ϲe=!LnM \ؑyٟ3x3HkiO`}oT0fodTh#^## CeL4;Uޱ"BTCXÖ(B(lƺhkD٪lHKPp6[?F˝bh)d4elUb֍u,rY&Iz3cŠ0`.񮱃MU^~m]BfW`ʖeQA?˄х~ËkYZ8ׂ>A]nczniz4;`e|SCLB6c ’Lt82)z V}9NS 6P$1m"Zaٛ ArD.1j+@bIGH.BMqa Xi9B0fQcZeWBρC;Anچ+9p2j^$kN$F[kٮј,~): 8+q)7w.mjjWS>W=A>:tf}Aq"ePқTVd*HOzֆ㑅2wȒh ݐi 15ִgȤ%nMO,xD=zvQ9J VRE$w|066R4(LO >&D#A՝JG{rȯYsG Қ_<id`K2iU@|NJ7i9[Br{j]v'^ 0z"9 'hW:gFZi7Mj(5<;j#YĨ?*]p4a]= h?v69++Tq^6ZnAq'a8< Qmrx0 E<&P)r}ru +VsU}wڗUSX,sR m;K; "X';`[Q"W)1HU[f"n9 ,f,:Uw#xlHR[ ۈOUʛ:yG8 ׀ǷDfP-8YD 1<LoPp@`GX1(UIhۭK*ŔSFs}m^a}o''1#Y$,kNL\}IR|*.VLr&0`R– DOx E' ϡ%0zՂ,A{kj9k6y,{\ם$DO)rm#ah.d=J]nHbr&Ӌ$C]d&9%Z};OY%¥*a4j!V'_ɽG91̡͹v30J+uS)=K ;Vv{R^(dZ'hM^Gp}8agr8Ѭ%'oGg<<ǔ^&-/2YSK GlC~j 6µ*]*J[)e2.H.t$xEɰkc[f+`@b&-R, fE02†<ƞ,[vV˗H|tC9a3~bVVHIJETqwV̲ΫʯDW0hmSBK:;]-==[Z wz_ɬ2jd)A M-t&ǢJׯ)wE w'jۻ'4T16Q`0BmmAW&[EYjADRFCפ0SyHw"tZ^(8?X" sax ZYF㒆ȝŻtM{,cgh`\`mɓȘ,k#@vXmAdx 4ْz;epp|҅eX*.x܀=ǚ+4.vMe2h:){$;[.IѓJ ƫ/_#w %Z':*; *}eA16a!W*%ٕ̀aOZs|9׿e]M)JY-TS2BcC'ĵʾxg*[&@Oj''֨[G +Q+] vcay+E  |fݏh$F|y79vJpLPVL9yC7Z֤7''X7BVC'֨ *|6bMzy.f/|]xvՆSvO]˗A )?)#Dpk3n]HtӍ!ZaeҀW(Wv6ݝD|0p Y̳,n|R~ZMy;b0,  eSdPLsmχ\mcrj:N$)j DHH,Plrb׬LP aa =Yi7xw͎ t*)xf.@f6tB[Sϕk^P KMZ]Q$[mp";_l^ۣsz?90XZ Q cɏ+C[L s܏?+Y|ςd[mH-TJ'؊lըhsnHP5j$}h78@$em/$ř@CnONrW6t&0}.8pg\,|<[ZWVʑa,*{ǓD -"ͤT~_Oː3r?&tr+yd:3(ڞ/JojPv&̽([W|iXDbT:ʘՒDC7} 'plJV:_(QVV,+nigAtStALsdx\-;="#U}`~?(m^#e nk{S@_>z ԜKp4 pZ)3ؘE?_j T犨4^Hr#8PrzEF[iA!9FĦ.bi!Ѿy-s3GAJpp?Sz=>>#ظca\-5nKKB}Hd SiFbpaètϹR7LӎҔ@KVf$7,_{Z߾(O2J83Hj)qA|,kᖅ؏l޽!ۙ̀YT;`lDJA|bzuPbne._F#g`ʮ8?bۏ O4BM3IH>Y }ΟxY?7z3`=q~oS~6GJ2 ){Zk[U`U7K2|Ɍv=E~ 4*$][\vNYw'$pZCȍHJ>]f[Lx^Y+&3kQ8 j>cg`C`^ dŨk.#E~w!Y6}Jy0>:;M?G> I\62jj-YUWgʁZFV3Tt/35g)sƼlÕj0c^ ꤚG'TzA^{SS[~N=$cFf큓gzEw  ʨ@Z|YQwk~feY7=f~ &rބNӐMc  ڀ/CQZۤIX5ASZoE+k;L"Tw=o8z/8ḚڅZnmSfSmbkTGN UHpHPqY;J0@ty ih2-q[ݺ)+e p|I~nO@O[>`vcX84%O*$7AN09y!p\W6PsbG-UfxVy)n;#r,t]29ȍ;6>?{YO*568Ptf$'ߓDz ;ͫ`L壊\y<~z gon/&2%jx G)r {:5!["Hڼ(B3Zop]I%sbjNOA5 F'a{SQA1ǜP=V'lpSYeB<-D6bm2A/j;ܖ䒨Ol,EEqsNbmcR"\$ܮ Yw RDo W\V9_uKLTHIe}G([\RCӛL. dlnw V`_U0+êqZ'vRCk"$ Ӏit&ap:Nn-RPB޳b$FYjW=5 'sGJ }pdZBllRf#-xR4 Rhl$ćӪ@C/Gh AM=EAzq Y{ms_s..I+C/mbFBVbnqP</)E1`<8Fz J n)[G!$V\bv+8µ%N'6|]@=Fz8W^'m7 jjBE_Uf A }t.3],!>l@EnƋ " T$=Y/LŨWd\O&g/59Ѯ705U0?7mQg2GN"չ]d&i>Âcx+]& -3S^3%`(ۯyx@rgQ-J?4Z UQ4,\CD包[e~_Z8dFUqyR᜗ h@HOÒ~/p] riDs /}Y wi6rL.1:ܟKc ')}ca2M Dh0d!"\CD=@2ac-tMttxFSUe!"uEZiEqha{^vzXxvcb^./[e/ni ͚αMmO Ƴ|;P$SL1 774_.9'g=(oW!<kw) B@[s*ș\ pz(A3{CA.R1ٚDlmGy-MVr!/ lHIY@k/igh( qי?7YzȇS:4/9Z;5~0:83BsjG{om흂 q_.GE|JW¶[Z˯|ӫ*{ ɋ˝$s/N?r!8lfPソ__ $PAylVѻ XDcS V \˪ܺ.Psٝ2?B MY =:*>1[Wz6Rk^nMZ.L7_o `WD[R`37&_ƜHxk%6a-Ge m2@e﯊{.x黣ildV7 P/ G]`@''tp(sjT;@dq/?M\ }\zɫFA(K?4.8a4[ĪϧKp"XO KTCPWdCh 7#?vACV->2㵎,E3R()Fji#r/ vLߩ{:'Ύ$^1Pt9;v}kwmk"8\v;MfbLR ak#`Nw_nKЧVrO ie ܑQ̡:1%j+ hr>wDc:& M9E|X}i2H}BMrR/E6[q f1*{˦M $`;Qqb #ɕ;2⼲XITB'˨G- I׆ǯ᳜To b<)U9ZlUkt*cܧc|C!=[tfUSqtuRVo&!M'YJ`K)w RKn${Jմ+;jq'p4w9d\CU)-WWuoB֩8Y%wILkId>sC Gzw!UžE.4+bEWECn*G2*>cm|>X)˅VFzM<Kq 1H]\l\QEx a8^7)Vc:F@*&;I9I@dx複 B3j`Yκ%W=FX;MlbG&,sl %h pv8qj H'HOer9/z5ˆPeھ -Z X~nYΦĹ3#5@Yti"܂FgMs|sw,5JooYIMor(5>⽥ic?I!bgs=ldypu}W,f/xl`W䨔9Rt;3AqXF2Ll;&Uh(]S۱j`}[2)lIcDN@;9ڜ4V.&xJJVB믹R_#QY^5|7v}m$2/hMZ9Au .:u6G| M \A*' ~Av4@zE*хsV/",% %gAtf0' azH Z;b}͗fIEՋ$.Nnڢb}zW0pBO~b.&޶<dy=8.9t,I*[7oXfN [5h]mI ŝd&u``܂="Gb +։Vfa ̣˫lM A*1ab_ 3愂S+%c5noCCq.Ʃb"4UշLoyԘ/nW9GJ|zP\ ٧ b :W]i=FUw0e+dm~л!ܐFnŃ-IpMC~)WFhl_##hsnVEBNhut6?] jT{kh0~ |[Wc(d(pGratTSlXI-S#\ks- gU| t}*-lma+bgنֈ]\s'uҍF^ 7_P$$x9p~O_+_ Nh,߶X><_wZ<)FkB:`A(mߞ)NZԆK:w]|HM(AuȭSDRr.QjdPqEҹY8y KsJ1Z@[FL;y&Yru»?H&Y_P#z:Af!c ,!Np.5Y5p~{J%n<|,}&N%b$5[P=,U#NI+}%sqxSx:GS %FF 4 3k[khpDΐ{BG41x;,ya80Vg9O\v_a!MWoQ3>o$ ޟ"r"A!G"ݹ&jiڙ)W[p:QQF{Yzn}򵣔z 0AzJlԆi>x՘mc9fX 3Dݿr!@>GӥX܅ṕ2>WvKi Bt;$Nɴ5 ~];y du62n`]tZ"GthYojB0K8x̪P=C7A!9X{Ԣy>a6B\,Ӏp(mvx}d Ѯcv-[ _D|2 #_D4`K@`@yF1Σ E{=U) #a@[x `?veh7jtz#Kl4$cSJCjz04hi`<+f#;x }Ћ"KO4AT@ 5˰`n6e&JXxx WT³UfOj<ةh(&Y159`\{ m!Y>|F}9RMȠ%(.pmqwH\qP5N413ٹu T2}s)O6ư8-<ϑ.ya03-.R0,8ޘNV= 1:v˂;oe_ʌXfMfߩ~'^FT`\>{r\y`0m΄ih[я]a`,5NTF2/ nG>Z_h»oTߚ4WHYAK717P:j]8mO."ek܎kt"DPN0*]?h946ޝs%_`}a ̫&-otTVou;YC6϶zAat@ΗB9 J  ^0;>? "ࢤF5+ ?^՗9c/ժO[x ڙTEɝyNQ# 睲cyt)Up2xs+.Hu!/? Kkb\@H={U+*zs + cܢUs林 8:s?.$?g-BW1zbaLV[؃D-D`upX);ͤ!XGsl9,*@ת[v0e&dx{-ؐT}.]Xj ϦT}=6\ 53(3 iӢL'^G:?Bu>Aߦح9"[1ݏ B8pƯ[ @a%Ї8w,5h% uf*%EMaS]*{V\_Z*,u?e*DU^g2Zv1T%;%<+~޳2D0W$lĢd;IS+386j)AV0~xI'KfE-`o:?؀mUY}ݹGgpzX&NFx{VɕqE$ssk\vDtrؤ?ӌ@kZ [#$o:(`T͙'Z1oڦXxS`ъva3V.MeC,Jdnj"^g@nΏ~äq2|;x)9xC+IV.3+|oKU٢KLXF壸]hhv&H1O,Tn[Eeq֭9%!{hh0EהO|f]wwIuHBJܗx9V1Ox|Ks#J  !왪ymmKb -?zihΓ>AՒe6םZK0%/{K!>IC^*sՠ9JxOδ>Cל]K0K+A|e`GrU2 :˓'q攱#ov퓸PNe,5⋆Zlc2aD -ݲ1OJik`^IiT ˚rg0 Q!yHY떋.<">)B QmXu4^ &f}̽f1nSPpõ5B$Q\~DS n b XPG4$)'.!oQǰ¥k{Prz!Vu;Սݍ!> A(k-}* ؀6clNpƒpz߷T}2\3̈́u-(WuRlV6e!sR \b%!ηY[~hkObA,|^ ;:jǶGmXbLUjҀMx'(Ԩ4? j81yrstcz]"+;1x?w4ɕLJn( 'ټFIN@!=7T׌\I' j/7dilcK7Cڦ7Yұ l&}ڬK - =>CWfNi \=T.7.(m`-j?#FUjAlIajk?Æ>-'4"Lz B}bR0!Jg ,*/npzuUHXt\A@Dr fnr#`{k ,w(9]e-IX>5O`7IrZvqsVJ'F6tꘀ+C,$n+āvz\ue۽ԦW5 P\G^(SG,?O-~D*Pl!5tYy7?*PMYdi(@֒B#*8U9-10*QʞУVQZW,qpVW 67{z(~C[TI;U0?AS=nȾg0oK;>Y/ >UFM.Vg(V'/+X~:VR%}0.4aP֔H|)hUip^6 Sl6C& WmҁzW&wTH@h%yT!T6)4:}y z-9¶!CHDrn^|;38[x|o;(a QSjZ8W;gO(Jǻ.9RO\+/3?'v{>J {DfMdNxY5=.쐤(aZy&AeaZ )$tӸ޹*= ^}h<9UiTuahX@#ߏ$".Q` ~xϊh]XZξGMU"~oqE__8,6=I ٖP}]_eF_B aKa6FWW4%5$ P@@Ym`k ]st|۟iRgE\&RןU4ybω7Nײ(EoƘP41Yy⸀1\.c1!Ltֈ0zO|FÐԲOۛK^7 `;78?=2['G>`q䦛F7=h^p&EӪg6Y `F+y#(xIe -@,rFXFs"lXԛ&Ʌ7p3?k)p[Ղb+S' 0~O66߅)Iavnot݅ci:44)&_i yVTD%^IxdS}/D^_8oF6TO ?DW~Ԃ^w"K]1}{,2ۖ2 aN9s~4V"=U`  ~%SbK!3ojHwɴiJMUcïM #~N+=[OM#R80 i 4,%:_4q~SI6 ,ɫ0\v[emW'F QnH; >( ZQ|Ș ~_9X@V2V7JyHx>ͦV#kwԘHu^-xѧ_Z`jBw7hQtMKe/T K"s%VExE I'ð?{TUu bӣhRcL'hTCIN`˗i1CiGejTu3Y5gW \w## a5̒&r&F멹Lvڷo.&sV"7; K$4nGKmն[/E0U<- 6uQc bX9lO.CP.ׂV7)=pg(kJ$zM3Ȏ|m e_Iq:;W]`Cq'*:Hc0-U;ѝ 0D [cv{4Xx]TpMA>%f7JA $&9W1 !,\D! C}֋߹(R2)3W!6}fMKCbmԛͤ5h%7޳_~ dN? I3v'R-\ڇlp 5ߦEYmˉMN,ao8>ؐWt`MF4Ug?y&qjn"6'. h"Pn\hha#p=y&kw@}F O'[b?&c'`!0V#rA@5qg]k$"=9tG}Ep `ҝ1HlOY&*Y@l<#ZduV-0=hzu[$HPV.hJn'c; G-pݥłuTz:b:[^GH\Q{0ЬvW9~h"k}'~"D>#Ԅ>ŵV N=0ue3ӭkf%-QvO7WMB+ Љٗ_ZzE|yVp$1(56_A0X'9G{ ^$'WIH ksA|pY?렴5Bx N.tϴhGD(eX2/[X7Ղs`~g)}9݃`KJwt27-,Jiu0fUВ42cm!!s"zIQ_9$aWǻFs4 M%Ѫ?eA۠m7Ǯm+ ?rL7ha4Tv7ͥ/4H1Ѿ]8",hoٟDq aD ϱj;hEch3}In& #)wMj!/^ nUW|d%ﰚT,va8`^s;Y.ćP"bAի3v_F.)yS7<;rH͒ vjo8=L, ; ՔQ\Ԏ:`z%~ca c]DHx`D<lg"{tᤦ _X$zQ&7lO㷻8"\ЛFy Cq%ߚֳc%Gƛ&d;gkN@:[o.7IsXx;6,8tͬCVp*hLy}f˦INjFZwj,6c/?odڄ;'D@c®ϷM靦x+ w* < Kj/}RH4jQ\]]΢O*#U9t;"gML YH&sf$?!sv90D5h*^[+ȉ*SD]HRU2eX^=a[rz1b+EkQ,UƽH,~@|rehyRw|UFa-a08`baC6XOC,mmY+YYsl&$Lbƛ W$J94"0IL'F%@/mEL ]Ht1  uנ* 3g2%du(ąJ+?ftx1>|vLbg`-w`@y[\Mga:Ɇ[y*OY&ml7ܘψ y=yjW;-FŠC'$liIe˸ u%j6@vՂ@cDOc NKa 7p7Baj(&lM+{H3ٿOnƶDMIe}g*a4x嬪elqgKćuXLS{4?tMAE 2 ]ॡs{(깇#_k^&oKf;j6+eW<#3 ֳHew`]usz~e~EPl58 5u ^rpSZ]Qng͝U'Yi.thN=iOL,bM'TWPD(6ldj^j4M` (eUe.!][.:DsY_腂Џu%A,kмB2;< WwP*0QA/?^2fyV@%^"Υ@G+iX$ RΚr)fe/fdKk K#\O!F25">6#tFSq\!rFK! <~q h ݲ` F(&REph{xD4(i kP0];-:],Mw]gfj;G,]7Wiȼ~aEd|&ʧrpNw 2qXkԠt"! JJRH,7@xyF]M~*XaG1 P8ш'B*8Q}Dz/?c Pә .7oW;,߬*S)=NzGQ_U۾0eiUl -D1b][:73*1K멾L]o:_)0kKK"^:b%.g pY=_)]lr}>nÚ& C& ntrŶPԺ&DTF%vcx5pR=~6?G@.Bp_.^oo\%v8X-:Nm0:=~V@aR,t9cxO0y2iȆH\f_^DhJNj:~(YO X (of},$5C6o;Tۭ)^u =US~N!y4l/i!LIK+DLW \ZV⼟)Tg.9"uU{`w%;vՠw"9mz0UCsKxF&AcJi!ePH(^m;U.jbH>fՅzlՐW]orij, nCUm UVO($j9T\ 0n[UܪgJ?% r.l-`zyՆa!.c2oMn9 ѧWuOݥ5 QCag5Yʌ'{[$u~G ޫwG]fpM1, sH3Xz+D^4Wn/0U{E`XGp}γr(۱`K !YLʼK i< E(̀cc QϢ.)u6B v ǘKD,M?HTD'9,TΗ"g6L^{цp)\aN_Qf? eoУɖl,aC=mckim!QIf x74hހO;E&41`$KtÛ a(r\s&--=d^zh܊}D V7(M}D)fM 3# خ!_Yuk4^W$jpŭ|f4C(YsrU6v4oi?h5lοzkb++@P#TpG4ᇅ1Cm*g$(.~J]K~Dd;H5DmG6Y/ol ̫S5"2 ne`n-Y\[-rnCv:'X_d3Dv} ةagJҼp̌~cg3{>+xQ-r$T^VG" 5[2)um;V"o@K}ɿlp v,Bhz{,䝊TF@t(#KFۣitdL1ܸ%$z ]Qh=GvsA=cqyi3!%-$5:Ltih59_=t`V> 6Pt(z4d˅1V8j3auH\ /*9WaRDEi0S ϺOvkЈcBUB㏍U\yg9;^C,l5iSo.}E26uF7h3jx R z\ZKA)0 o>'{ 6QR&1 ES#iigSH>2*\6%.IŨd@.?,d du=϶9ٴ4T)ߛ:cY./ r`s&?vl"s'$DRRq\"i|.3%ڱ@D}^C$%c9CSQk{! 6ǤbXkZz^1 co-gFю`:v@_GDB{$| e_طL/O+zXՃ;DױsD7:O(52Nhp9r:bօ\;57E69u^8VH J!.|Imh_0@w0~-b"9ѽtT$Ǎ>β"DVLL-q;#aoӹo3Cwi/5nO%B9Xm^N371Keَ+Jf"Q1}_5gFִSa)^}¯XVSEM/-NsGKRC<@QTn>'7e9D$zg9:/7sx:IG,G.kYZbiEuLUQv2+ᕮJȭCPy^;.poַs8DS{'Gq"RJDsh?XPE}n l$UyA*1t:=~j㔢\}]C.ҮopIR6j!H# ƞ 1b 2tc^IY} 1 in8`QLJCcǨħۊͭ2'=֠C$]BQݧiYYi ة enKmQeC%s||v? >ݽXm*תׁnJr'7J 7q’e0Wu>n $V q˴d̚pQĩ ?l=sz'?92>{ǘG(?'q5 ^SACe>*)v*G䳨;_nгƏSf3YZS垩,F4Ǭl00aFhKJ/4K=/8])ȅ)|8O6|Bgq&-)giRmӭU*l3p,ORiP7c\P:`_hfv6h '3.g p3Y[xJNgRPpzu!˰|'Q4@&1q{ /D"8I VڍR(F7 ""kR@>!?3Y;+ז_*Wb#-_T2\Vd[CV*090wYms<̦- 8>G´>1n~0mANГ>~3>f>zEsT9gIiuO'yE7/eATdD.y^j ϗlߓ@7c~jMN( /DY0}c*P`׌3"pB:I}'0L״W;"PnGl<5n]/~Pkp#q6._D7Z ڭ$A.y\|2Ẁl ` NV' Ǫ2AH8U oߨd o+ZٹnĶ[VB3φy6`bMv}Oi iX*w1fY?3t kk " νu3оiFD%s +@5i'LLZlzT󪠅DgwrC( =:X8DYQ:?sŒ>,XVybafl(I0%*8bOWMBrZb!V5rZQ+x69>.^>w3ܫ5zӿGE.-]%a*U£k+p8i8y#UŎ*s'_.XRxGf;p>M;dִIYqeGynC~V{ȗ?{8z8z|"wdžTHLHNs*r"1 \Z'!+˸VA@/%yUq 4 K0 Y ^J179íRSTߠDiL'KP<ɚX`7ިbY1$2TyݯOڈ;"s\Qt%VҒ`o)2uvvwO3?q-w9b`[G8 CrX D !rK2u "j,h.noI=T-(b`!2 ;w5\{@QXהvn$qnKF]իZM(k08yA@X8c3%ia]&+ZxErI68§s^K]5j`@|#I:E&) "Fvr׹%8 qqm#i10Hv/!O4Zz9)Vٽk/U)gy~oj;P|DS`/ nۢ>[ 2VʻMӕZC+vYUKTؼ{e0DNƇRoy L!(Vnl*,X?~oL3@p.~ӄ& OUU KRV-lmz}^Ces_]q½HsV `ݏ{6Y|9FLN{m,(3ZӨϥ"d^{u^;yҪu!+**3 !ॶ&T!@[CC^7 :"l7\ԎN=-*VI|܎bwd驖gvv[E;\QWz]:ͦy/ms'#.+B[QRfMkfMXl(λQЖ&WvFmţճBrֽ nZ~n〞P_'NX;0nxf%G/U#ȓn7Cl>Q%N%2sNC u U@.t\4a^Sw:/ʛ=rG?&ΦGmU# :fѴ9@$Z35'fyvi\/2Ё y?Š|tpiZ#5]Tx|ʀCas_YRzfCu%R9(TCMF yޭ#ov6c\o q~/1z@}G3n $1F}4(͑X ٚ_^p1*_S `B<&R>T4U->x85$vēhh LIQnaq4TN/VdLTL>dgxUʲ̴y#ZV=g}1G[l!h vaDMЭbSÜ)vՆqYe2n7{p06p}}y3 .f0x*`˜,9mM%y4 2b2uuB;"VNV[ϔ_~)OPr?7JSU  LF"UY8Z{ N\u ľֱtL淕w t@uAZas̾D!2z;Q2s /GJב) $#;ש"_=7^.HĪǡ6r9NXa!y>E l ;pP\/}Xytg=hYt)C~kgirq'e_pZYHdg\Y%]e1`LMmjxwYYWe< gG14e۷Yt噾,D}FLXz6R. *@50M1ִxЬ41 @mZi8rV]!B@$?7iЎ)+f喡m!/M.R9DC4+ ?7&/D>U+ &C N *~#AkvrN'9)j~WkKIٝ:g%M%WlхX9~7mm@{~nҶ30G292plBhxvA qzb >dVpC xbeE\Ax/MuL3d䠾Wz7``"ػ_oom_Uy0"=Ṷd!;㞚@/jؒgzm!BKrԑXuBL>m${MSb#pJOClX+3)wG٨3), }co>CnzABϑs;":>sMs׆%be{14F>P1Fle$7 (c] 7~AII&B_3BFqE= j^5~x97$YjI"]VFocTmwteP4NǙfyG=J3 ӟH;6]h J0Y.ͳ`s>ށMe)Yߐh?Eſԛ}'=n!~010)quKGZL-,$pK*+&DYTNt/UpEշ`6R/'X S8::8*"WiaN.\cÓzdxyCU$? A{M۹$N9Ol_ŠM}WCFJAGѫH{V8;bU:ƕ [!؛wl-S-XpUz}ʎ,|*Qʴ{d 9:8Rn BtYRˉ4=02R_H{Rׯ(0 1YpzYO{Jۯяۆ%H s&nRaK]V[z(vԽl?$V(~!kg?o $u*Y!ƺP%柡-mpK>ص#oE|c[DUIN</~g:Y ҩuG@lx>wuTHI f $OrB@) A 3Z]&MIy|+mpv5C!U$p09?%>e0_{ YM>?lsA7г*Sэpq9F7y'#eK. :3rf(GDsѤrKa¾`v)]?4喗Gm'c4Z^ D4[g{%@D9yX.yG>Eo~L~0 C?7#TTTfe鋻=^;i0ʁAARqG+Y ~ʸxkb xh%y{^zkyg.˜ xUvDmwqr&شShAUW*]mb*g a [R,a'Uˆx(v@6j[MX-w֖tmTQW@iy*65zH*Z3 gqe׺|@~Y]ė%캪؏#7{ˆ|4 h,|N@Aj^cOJC:-*]]wLS¼BŒWui0m`cY4~.&[z)N~  TBYϓzf 2۴u*dS>l~MlϷ+^* ص|fWȨ]*縭oR6 G:$o^zr* DڑءȶzaϦ!&ncGinXA NAx2qR!;+Q9nʊ_![Z`LٔVeAS,ɂ\V!pr,:qƠp$޻),eztޏ +(j>s(csO0\vIL<Y$e$56[?qjoȍZ2XزMC:C}Dί=<574A ZEjz-Z$9ēCŌ&KK'$i* ٸhL,fkشCҋm\?< e~\A{r(/񦋄 mI~GƒTFNuܥ2eoN{0 ^oUq"pk+%r}z:t7YPA#Ɗ~\-eNyR#HƇ׬ àh+QJ݊(Q߶1vW160 } 03WfrKQ%` }qyps1x! y77HgW|{5~މ~pI;YbKKBMV^@R{t6Z xrg]cٕiLj?q~he/۠xֻ)W8U<@"-^|̪$JusgUHu̼q?aWUӛ߉mSiOn'H=XP7__V6KVWJa2DRQ3Un'$0e |C59ΣEgKgL8IxjYˠgF#[IhQ0 SًdBˋjQ|Gd}U|Yd8ar$&i< # =PUˁ #o܆[]|źr^[OCēHh aY8-Rk$(aYRbGn?׾V[nIh evGXjprU%!Lv?@%]'EO@Ydd9;(s]!P+:l ݯ݊ϺvSmC! BDXKĕ6VeÊk$SL4!GK:VD~xKN8lj1)sU쿷pjF2a䈻P,}XŪ3R>O&9Hni.59OFpH'l%^ 6)Ɖ@m$dlhf@ι6_XedRD*se]IbE Q6# wFfF]Y/!=BS\8Au=i(O2L)esaPOL)PRI5"H±оN @4XY- #k/0'8ꛚbX8;wjяQ:ZQ5–ue7'hk)sBMiEx,Ĩղł|Oe95z._cj[̔`J=}v2a֊ O Gi{SlML=YmbzwT!l$?mXx)_⠱&*}U hܥ9jLPgh.q*9 L'( j=2 -%Wv U(˿Ѝ$}AOFı,:T9RXX7<.~"="^QKf,\h60] xhzd6#Γ~Ñص#$js@}f -r lR.nбuXD$"Ui;j1ءJqB|$vPu.ѫQ'zKQS=UC]vA>xnxL(h$*'7/_7CoI3PA7nh׌CeCNЎx=] 84 o$ !k/("^%]L[$;E%quzUK_4=#)c{]jeVzXiyz=:BH17KC DRVL(=aZ>c:Ы(0e+0Ԭ2] jj֊T[ 8O\HpI 1Ü0&F\:\Jh+ ~URd,Inm'nW]T nLja=qг'pNU :-9FR#=4]E5;TJ8A%ՇEGV_˥뛳$rS?.EJuS_dATh +#AX[.}9EZymca@{kkj-(ԃĊ60_<I;yKŸTqf5Ҧ>|Bh-*LutX$SE2{> dAGYb nm25km8pYsnaڇmMx:7*R/iqt_kQn[i@fc;@ Mn.=8`AiD 12ؾN yS8W#7X ڜ)EEsmGȌ ,w%Q{mC}e͞'lݩ07M[I(|"Q5TB*z5. k{Xfr⹪ ރFop!O9ۘTڻ~o*O~P8u? 5L?PdÚ,1` FhNs$\򴽥KlFHV2(ɨ@!BA,f CnU[ 6qgMhMis0L4\,8Fpt2d;CvjNZQSB:y}I-Gs>')8[G0V uXԮʇ"zMayX &zCLѭ `8BQ4N|wq{35`|T7+Ty%EN @$Gőd\%ꍍΊlayI-Bָ>0f~&OѺT 悍a۝¸pvVtzkɶl> E0OnXVlO^V|P;_$y(1^XKW,t9V2AC8 3coeiE c?9b>fٹQ|.+(:JA[Tr|Ϛ]X*Hz(vaGnՕOh"HfU],=G!Vŭx\+?;$O bufzn|A91P|ڃsdw&w]G;u6W(KR9O"$}a QNT\BꗟV4/G!1Db {f4zA9}~W e *}G,ʹsgW 5A|®4L43䊶,9n 5 y+{:R*~STce$BjOZ-i~g;_G"! =yhumD/6ܡ/V0+wf {8r~  1p'ֶ_+Z+\u HDJY6&zMWsWMаZ 6hGcVِU LX^Ьyt# e n ]SFƊQ {k vx ;ծ|ޟ7P6EŒGw}̭ >qkOn/{*+c  mF' ɪrhMEt&k]wxA`Pj=w (㘿8l#iM>+7Wv2^sGBAk2wlp]ZY0Q3{jP,vr;1Y]35avv⺳g{,aq W{ldC{ږ aU;7I6WQ$' A)2CET`%ύNA% w2_ PVU$١V2 u+NE6z&WBpv"TirT=< `R+wdqqΗ1RoGgaa5'²0Z[*P$aFZr\[HX#T9؎UqKUWA6dpYZzxΛ e&ܒA}u[ĸ%aGۆ2G@z!IjC{W2+)þK96P?!=]r!:[f`yrf 7NJ޺Kjpق|{$iUqE5NB->D}ozv2#SpAvfcphUVz;nۏgeb=ŋgw>P2SpE*lsnmg0[aL3{gPj)!pTDF|wRhKkM94q@~Pvd)/@llEzp@VAZ.ERmxcc_ю*s -UMhwQ*kl, h埃ݨŽK5c-ˤ"-k G R([w>YsBIMn]%:u@7idL%W6c]174t=ui$eP<j [j{mk6BfcQ <;I8+N J3yL@*z:nО`&\_]~Yz^]";\r >[-i<3 @SM ?,浸*'u\ln1x\Cɲ|>ggix3hMڶI(" Z%HurpH.YCTТ{v3ue%k?X& V}U-(@-z(%@-ht 8^J+F'%>7 G7& 3ƵREgd^@^,lS.OXJQDMS]N!,|.-E>AkA+ *y4I_H9E4cXܸ !4큘}=n[w-jcK/ffjIOt{=AwԼ/_!EFtw-Epf%Ž54ӎ'S,LSp(Ti"~`QMЬQJ/D+6hYbV"E8 cy*j /&28n#gDR믚w,TZMw[h00zT̨~UΜ U_\u]( 6}Os3$5Z^/jѨ/!F+6 UQγ25 y!&u2L͆4)ԌL~$P= wXk*GGwդ~@'4۞yOXDMi(5Ozvb*Rt)O*k}/*iӜM^j+TT9#8'\AӣrTaֹeꊪ\E0PmG:.CtgU46~!0rƟ }vr.-*lzL!dęj;Rv3{cPA;gEڎP؋c:Mgcˆ.fQΌU9x= 39nه+1։w+c-! }ט[m_2I7" )nH?*9Te9uWenֳS0Nm RbJ[Ң>r@l=L L7=LӐ>wCͭCTc]$2p]~bts7>e8#7(\B6/u`<2A{ Jy~=:OB>ӓxnyUd8uq"Ɇ]wM*/ر~ |wi4 PoѬv֫5x,~(;@&<޹ ƔEoKۚ:=%n gF+BjT\ɇ5r[e{Χ+#!rl2vHHK= K bۦ_Xa?j2( 0´oqgzVm[V#K߇,`藫`/yp^neEz ~?:"Hk?M 骨m#}jm5'h9 5F)3y!ni-t#ptF..`jgQ?VeHL1X\a;A-#ꝳpyvw.,#U2L5wD|um^,t ɷδ?E*5&{u[aCZ'WsQ* B쭂\\Skg7Wtc0jPJz?]ӏzzM⴩blai"pAXT*"b$6F4 |h2gץQaXF^!C?kp܏uSLܨӪsYLs{]3EQysRrɂ~m<bdJXs4ԊYNKX^m*S|%lu(9޷_S4]:IP#"R|`ZxTH%%I14ZetAW@ߝj Iʠ0J/.v$I~/ACZo0Ps9<%@/}˾Ӕ'sI#5 Uho=Db]f-֨+*P땡< vmS"eWL퍄 0CybScݮa.Wa 8 g~5)xn/ p^(z1-Zo C\0mS lsX3a|P˄g}: ޏi u^wNU5`כ^3vz@AuT7̩qsLA?Ui+[fB$k+KӺ蝤`0RצsRDӬj|6:cDF"(E^QkWfT랆<[}_9f.=GX  (.su,p̧.#ݐ>{,lԾ]*-f'jk <#a|0Oz:.wMvhbsu!9Ш:"U ˅yb@>HgC6Cify+-mp!LZ}/]-V+,7x-\XI4BP[ḕV΀@Z0TֶLOA~{Lj[)ꤜ'^?%CO\ ?eZ7xV( hǫxQ&xiSf?pL+ǬYGb LwU>i( i6X *P!ɬ#Y@{ΔĪ\L~@Z*h"cTNJ[.Sz=f&oh9"e0뫝fI6oY"OA̜j]A[Ts{2$g~^}y<jcJ"!_kxVX:yxZa಼{>KBLX1 ̵X3h*Nl$qo}7QQ3)O@(~} k0!> 6~ O(5ö8ęX+5͋K$:a#(?R}u^3@3-T ܩ@`YlhhӐГ~O/P ^gS4@nEjG+^Wߜ[H6_|CAmg5eO9xsZlL ^/'_>3~?׹c{ǚPdCvyGD)AԻ Sx$mI.'92/-*R=j|Qб?S\Y/cߎрw~p [M]ɂ U?Yb"T]v gOVKQ2p^c&}dwլu'nKX!K+v᨝,EU>1ׄ=uw|άȓ "7&!`D?6o?ғ_nB<*)c^rK{htebvk/v1ʄb 5bcX$8#dCѳb¯?hKHKvlIFF Y"`OG+h}Goy g,ׇnE4SXb +f_jӢJhFrϷ@^* .+S'lYf;gM혙R`Ӝα1fIN{4~$Su lW,LAULa-_IOHH+c[4YV,&C wzRt.ӈ7is#AӲlϧڧ/ w5IzY9Q2h4@Dɹih x^T['ˏ^ߤAtCՀ"^f FxTށ1`$t%< m|`Q&"N΋!# Nj1 BoJQx[躌@#Eֳyz5_@qi-ʇ5MW_ h*P.)%ZD׫8ʿw a0ycFYvՑGcXN7Jitӊ9*kՆA Bnb1? ?>3QӃZ"9ŧWv <f8&;"+ AZ4+Be"w{w7WQSK O6]H(3/!j63 4K hזm(dϷ-֐*4i Q}-aw܃$6Syd6rx~4'/d_#S (ϑx 3@y&Qo8NtFy4Pv<7' PUdZ! _ν ˋuWVV)~k5XBZ pwˆ@'XLƪž8~ z焱kO MЂxV/u!j Hz{Hy嶰Zjqt&Ж=;(h A1zs`&۝\JП"x#JgXi H+ 'qp1" Ƿ:isZRV98_{r8]WCgWn]yʙgVOޫx֙s촃ZȪ\ΏGML|g28SA  I6tkaNQӕx#G>!iVһֿD@q>6dՒHm`lj7BGjv:C^}*"+(.ਧ<.xn9YRikG26-kjE8Gpǘgָj5^7C pD-ΒvR)?817Lc r-WW%@!y (%˼9~mڍ..vO!c 8-2*HJw"ρ $qA0vLf.P҆rg3BT-|JNQ⬛RցF++?EOiZ,, |p +|kQ p&AR=ʞ3.#$UY<9̡ObgɽPlcXѢ㖇 A!?~m..^=\DD PTZ T r G` Жy'>ݍĽPGH+iGd5"M!/^nYs~4*lmNUQ8Yj9rEqW⭇V+fE4˜%E yhD>G#O꺾LWe*F]VXEjO, VB@>ǵZaW e=l=<"x:7!y 飱O8_9NͰMYٓhA42t`[C9@gyNA*Ȇv}s:Qh:+-1Lifl WgBgCvNd2_eFfmCxIq!ы aBZBv}ύdТ,Iu4I,)?šSDurLD0ҭ. e}؅9"w8ǀ?6T 'Tb\" :)Jۤ]_611>7W-k|`P_u8_wXi"!@2֍;ٸQY.̉dQ NzI7pf\@t7{r_F.z鋜.4\uOӋA`!`kGjh\-^ljr`^pHmmjʝy=Ѝw :r#AKPYck*:չ0>0fzu[tZR|y Ŧwi!@~K.`gQĕzd*6 L7px@!7/Ar Q-02WJRM'#LxwVU?&av;"jY |' ChP"b7*ȉڷ:=-pK3.Qw8z4Q܌iT4{hڍ)s# ־3 g;0"EVuj}+}~Rv-^: N&wȫ7Lѥ(m2!,C[3`"# \{r- y.WlBY4mai%dCڕ KM&*Xnsϧj$JbQJ%LG\'cXlѣ Mj-40{׻䟧DJb%y~uY.^Wɂ"bN(*dvv2ĄqPys8١:p]Oh{;\g*A<'xOKK.ړ^{gq4:aJٚ0=g~By/?);Aߧ:m~.Ɓ-䞹lJ#w]VǼ<|:OtVfF 9%+{|-'&%J3=U -.$&3ӒV)Rj֌kBKO0@7,1U4T]whHBۺgK7uՑ!PpM1 q|#3 -/\MʟH0g#eV@Qjf XtY5Q+g4aa|M<ް"= ҕylh.[4mJ=4+0EMLMj"AKau.lOQ$Lj+R$Dc] d&7 䄻Mt_u[*ڥbc/$E/ $d玽?#= m ,=wwo&kLӪ/dhd4Xeš9r,Uu \li?)Fĵ!b=z<dz U1a6uA=({ޑ;JF 7PȒ CD3ݍAxz8 .*kApȊ/'dZ苆)0.d4XSvM5&"4´FȽsAuЌT魪I _m!6R#iZ"b'u(>":Cp5|rfS4.3yqK](v-t#N^H?KC; ߰Y{$\:.3|xXDL@>}qfiԉO ?c#.|8Q;`R3@o؊P\8 .|bo$u+L42#&NB58?4&_iSs0V0a.gbȋeo:6^%2zvWԜCԋ ;Sm2>XD#=KFC*<Ź÷RTN7'я t%0aB]=¿Uӥ9q&tjdwFa%qrl$}4`Lݍz^}`!l4C>⋺p?BE-l)c'! e$WK@7VG̫[|ӣgjbX]W<īm;E7ɬ :Ț{@,Dd#P]L;p'ښ=m-BuM~nY/e@5kVN) #Ak@3BwX48:ygDCkuBRXZ+q0'R[LJ:Wٸ@cF'ߕe"6Ix\ ޢ1LC{bȏ<J\Ȭ}/oRNkM 폆e1ư sljN 7%;ćŢGr!D^F'0?\ws@M,'?7pmGMBNpA 6Uz:LܹWFZBH[J ňK!|=+VԼw%+G%Fz4=}Q ԦOy9%D=jinw/ #1u0ՙ&t<B*w5esLwtfV nN3c:om%TwlGt:a X)jF4fL3fY4с: + H/+Zt,,sFS"r_}t7)+4Eϼ*G=/s"hMvc `:.+xAg.1h2操,vߵ3C(ʶ)ĶF٦G׎v9dܼphaPY>0EREkMhJ.T"GzY#б7XHWkGa7lѰK1[2ߪρc⸃ !UY4Byq~<, L!a?S^bz%)E]0bgj|܃Nc^fٯot,ox>jF4'fՁ͙L5 A؂sPP˟u)[HdJFpc _QKPs'SQὌz.2B1]XoϹӔk0.M0RZ`~kK˹9 OR/KbhR n(!dI(L]" ':_Sg3JuN}K!MO 4碗{hfXA4у̚1t(;wl{\Ei\sƲF #7EDVlE\Z)N3(85*W!Nk?w>C~]?xպ\$Hܠ?>[u(_⹦'C#:I%x1lLߚ[*YVCZw77*x^nbM ys"*q$u~~:t_2P;Z?`]zjuK5zŻCK?$~#QӼ; X1mÙ[ VovX=2iFDa-.D :ܓimODMtmJzASB.~Sx7x_T h䒛nDF DIsuE?&.]^,4W:uۼt Ƕe U!~;BYAͳXʞ)Krnts7I jq b*5҅%|]B6|5Z7Dt9kpʗןK2Fo:6ffk^FR$Pp,LZ7VJ-/k%zDfT/!~=C)Hq}$4 Ԭ W1[XX=^8H5 `/{vnq{/]ͥ}Ƞ/m7uo뢺ܓOLK4lPC`itQwâqB VhN 9Ԍr(ibɬ2ǽpNT6 U9R{9-/0mV=wR6@vMr1XrZx{룝VE_w~P#iFbًUOiqKѩx)#xpǁ~ ,0) {b}=Q+*F ^m ;H +mvQRKcY>ʆv.ǫ($+DawsqmTEp=4E_yNmk{Z6wAʕA (W]D(6p\QZ< phRMXrF5B^4_WL p}#R, =nʘ{AUn=& -=xP VX%5DL󊽮Ëȵ;L 7Š1/. 3/xҜOp?M) ް,YFρyo~ɰ$S|LbXo @y3˟*dOi-(?eE ~0&aX) ]8vsx=->_ب,M|37=(؋t] u^TrV|+\ {k84qjf]·F!D6Ơ24VK=KmaQpA/bhJeӯ}]oѣڡ쿮0ice]p{XnCs6xGܥz7'4B tM-2 j,0h$8ۧ8!=(= |A^2tcKC:`s]yQvI۲ͨ:%-aJ|Q\@$8D.KFKPJ*4ͤfz,DޤTV^:;[Yr^yTmݠ43Ĉc'dCr\5)?3ô+u!IkQAdz#4⧤Gv) ,zٖOK)!G';ՉcaМ gYj*ΧM%=vt "EgV,4T+fd5b.΢mEzL&3y+= PWYontB6B.#B+Tb렚o.a@|`!y<`xnpoC8`Fy^|4cЙyYV-g~@Eqx+ac^Nfvmg\nP~|9. pQ$_{QgKFmm aSns@1y`]JƄLrX\g99IXൕHmE5^<=m?ͻ2&o"Tx!/h;[GjG*$5pp0ºSB'V)Y_g;ŵK'__pDw= &7Bq-͂xtnX9u]`2 ׾)}sቷ> L̙olo#Fr7 )U G_ܴEb2t!|o`ނ0v:i&gTI 98B3c":MMx=6ږ 8!c{e/&x!Y ʭw1ӅVPtBi BOro=u[vra3%K.t*`̿ (:ZMQԟs7՞7[#jtnXP/rVTC c~(8 `_ئܽ9qD `wYpNO^٢DckUdt&I\"{NxwBǤ'jt=#"1S8>UG^3H|*Om{37 =}2vr\eBuXzH=d9*.t 3& S;D(ݱ@I549aLQ Rl%w`^ݫr}hFy8Q [7WP17{Dwd^.ǎY(It="$Fomμ[+IlP  M=BRX\vK73o; nq9Ų MʞkiK.6 ynȟ\u%e(U+_"ck1{I'bsE5 PALB6~g&^+TKsu*ԘcYT^?˞FXS|yA"Y-qۖUr M jmpn3b~AfZVnpKL<rD\^[ܼK5|8iJf@tLzV/7ϕ0t?GkR&=V)fVfԡQ Z%ڄqP yu)4J &;h\$=e7PF ƩR 6ܔ zchiքoG҆yyRKڜ;gH ȅ}c /%oWsܶ0h񃷉.qZ%1@wdN_X@+E yjI7c/(M̒vS;XeD<\R?É`J*8+?ɖo#pbaC:'6lxe7Wne ݴHc0[I, '4K/β ۣeVfEH:9Ѯ-I Q(Vq`~Ԥnq8x4YfXcQ:n:i/R[a SZ#7woZaX]g1B ״Nb^TOEQ.h 8$1;%lύ#i-58m9Sv&|QjYiQ4 O -# dAa,D7lth зf \_xNR#RvK?0gC0xV9 vpG[!uJJ͐0l2}N;|F: )3CPe$P/Kk-NM3*d>ex>^l>VF|uowZU\2f{ft o6=wAnyj)Rr:wwpHT\ O\V,J@ؓ^lr]S)VJx WWsv)@T4H8*/i5!Xb&xbVfp/JZ$|U~" RșfLU7uMmE$?N^T^="6F85j\8a---~~y^GIQWM:HsZp+rCXo)V  )HH};ٴFČyv;!&˷(&a 4ʿIC#!Pҟxn"ZXZJgOITl++c0Y}  j;f㹅Fn婩6;GS- 1MLM0_b_q{BP8 @a^̏R7ɫ7o7ZcO[uZׁA Eo8.:ا_YMJYHc ϣyv܀ࣦ*6ZÕh;Rm>(džc N2?d>G\Y?PHxaB@:,L횎)]Gfh 5̑po]VAGC=Z+?"Z%#}jiw΄usLoD5sƌunpNV^ ѫrk}o8q|g l铺! B#wxl{Fz#[,Q;?n8jC4x>_Ϙ.Av:6cǷ_nhCJ/CF| ??6DR=^W%^Mo>H4~±ﲐt>$X_+OM򼖸~5\(Jp&w$K*pfBۖĢ>hm͈ uV-ĦS #@ ~eS4R(d$p\YDS rYԜO_>Ua Hf_X[[ q٥-?^cHNnד:=ԁO .L+_ 8rTI6Uخw.HKEү7T`Š\:3 :]8և: {b. [.iF B/hXn-΄CCO#Kͩt FVuj-P*FωpT7O; "dP/ؼwרIhJ.ʆ& #ޠYa_uMG}Z7>y/AȎ2T5|0\ kּ+$fc! O\.Zl'~uqQGD@ RFSmu!,Tb k1ng|51A_G*}ռ4;W Â{t4k]Z'68nZ Z$@![5 6TvM,\5Op 5}#XRĿ&ؘ9ҦUX*9"Mn=jG95mbO, eNr5S%C%Ubm$] 7c<{y'2׷U&7ؚΤ;@cH\_jȏ_y'InjLnk= ע@I㛣T1%E6q'e 4z@;,K/vu7:gJ |*l.H#x'">H3°vzgEXXa%0vd~+^1Maklhi>E 5VV'fvz?*I&jbD4'LAjj"g^ U0\}2R645&m_I% ."Ǭa?XakS0}^%Q2ˆ_灐mj-88p!k30ð8`+%3s+R:Nsp&Ni![gPib ^ĽJt--[>"dRоۯ5n{][NI0k)yB.0ekgL"FɜgNyq؄a6M8v0#R'" T5*S[Rs} +X^pυ\;c:ӕ\aTNiK c6GDjr8>O༵D;#7k߈oP+W0 gQO}I&_sgRfFZ}(w[rrTt5uo ,yj/6sa"%v̛嘖lÌ%$D忮q@;OgwɎ>x>eo^*~[ŪDW(D(('Im w``w_NKS0ؼʏ.Eњ2Afǜ Sv{/æ /BavkW?N0}{a)?6{3Zt^b ň.G :PR,J{wp J k|jdPQNӎ`V*hBxҧK֜* +xBkF⅖y=ĭǪ͟U!fzz{DrBE' ̨fZz:JLh[%]1'>[.9eY_V91[㬁 [h7]&E#)sGH4a\2F#\>dfsPk'wX}fZNV;BF羜4M0PcK Wd"mu%Q:-T7 dtm]k( ~.mvlYU`X=D'kө.&]]FՏ{^'lxW@K1&fnԝ ˤ;A@ˑ1*}&KpYvjz1]Z0qNWE~I+(k]!p.K-zhr.\VؒZ¦z]xbB!Bkz'Cbl&i ǵпs&rN ]QAfQr"*TFu:a\FC9Wf朋3Ew 5jHa`G?4׺X'qyлwC9:'WvP 5|j!1=O^TL@ƃ庐`ZWt dot.ݑI"NL)ZyC-`(MtPcQ[`7ȃ.v}] iΩ!XsP16%ɋ죙)Fv 6,\ݡ*m! p޺R[ywCO ]{~5 <\[7۩^>i5v,7vC̅7?CyȵF:)a8]*+[ZXN=vϚ+~fTg"@F{Lq\ij -Up=nIaj. ĕi  "*G*JBXЛ|8tE▆; e*[)-WQ :zCDŽA#mbΩ=%Lj{ ! >! _@}, f'ɕ K)9YUsK1L3JL,vDHބ ^*(rho TT#xs`=jTę^լ_Dߢ`tض9 |myxLA饗@yc}ǩ}V;ץt4EItۊ}ƠF5n#¿h65%whYh¥u:W\ (M}m(7F-.~w2;0ڦ<8"2q7=5+*l.0;+xv]8uyHcBF'4n[:ܞRI|/Nc_X^OFH+?ДT,π{dCoGeX4*\g{1Ug7\ Yomn-A 3l3FCetlo) xW (%ي@W~c Swð*G~T+}P18UwPbZZZ )9ˆfT?~WC~D%AR(>%unԛ89ʾtJs]Dum0,ī0:~W׶wƄ`(``rV].13 ~ [Kuv|u5Dk"vSPQd4fm%i(vJp@,FR}Iѷ0I 7^P睸S䣻21sq:K̩:Sg8='If4)Gi Ǡj35hHIR kʻsag-`Gt:XNICݴW XyjɝO"vO]_(Tvw xU>|ܟU+ ӊ *MiC3" S^{󑩍d3q%?R'5'^RaG:N"4 <0Dښ'6;ZZLt H*?5h-NVa')Z^)dxgbաNr!Kvm&R$} CژqZ}³ȳ9 դqUdM5bM,-$Jt%mc Hl4h&NN^ȄDW"ބc@4G sJ2r_3#w bğb@zLAu5iZ(4Neh5=%(GÆuWUV^Pc.n8&X͊IW% J,S%f-G4qz+QmJҵ'ţ7ٞ6f{AQەA"gdcGtj!,텃lLzQ>rdEQ@㓼X^zBj\HE"t2++KD':ݍTPO:~K.>{AwQ_` \(sQ_O@rjM,r{@ظ|T$}<1w:}VX,2dN$-{rGG{V$߂nJ{Y>~g'elTK^z x/TmlUm姛ׯ؎Grx=\t-^$;;')Zx;.Q(H.|%ȹac2fI q8蚍Ba>yY@ Yݾ.LaL^BOAܼ/+5kc?t$M2Gs H$F#`$hqSJ禅{I lKT5Ex^jޛp Bi:3MԀQ' C*5t&r=5P&}Ǘ9!3ɨPۀsb/:}$rt!mjÒ*OQ*ֲ6g-XuIآqC=Pymĸhڕg4&MD^Kqf\ouksd6j"I9-B=}[bHU~Jl !;T\7'"$4zw \6Rs93;*zY]QP?WzNJ=!khK3М&r`'mUz|%#?} $nkNP$; #z__g1S.#ec ƫGw˃(h&Wsqvz+P,_oԹbm}Y ZN%&: >٢rrv[ǨY\X8I&!Ms@Qdb;mXjU Q*g V+5:V^Ydl(ڳ$]KhB!/f² dKgDMˉ ,O^*a2U 7pרe[یP@'5O?;ȝl" F"n4JZ oU)$|XJ z~-Cb.1|3xR `A}Si^L8շ0KR@mIVrv\](1LQ _pWjEćn6=:g+Pj3D]t<;@IzJwK]M:皠(oMj6"VݹcyIO~fKi_t ]ʀ0 ľyt^+`EVaWWl}kJq+Dg_+zwwl _:*?̈́HQ.)cWQ3:hWӫFQqne3Ἇ[+RYIWyPCFN˚|b05mѫ>j5_O1Q >}6;cglEC÷989!'׷z]vf%( |y6C{wU{~(/0]qW PXW*k˶gBHEmc˱x]ne {N\e΄{n5`މXC[`c# HM iu&~#PaȾ T^8;I$JRJó#K%:JjV{R6y&7U77n)| vZC\ 5kP0-VW vI52qŭEԺro ? RQdBFxw dt_GbdkPj7Nà ^Ô~ع\v :m]IM1.KyFÏ,GCϔLs}xo ?#V^%."q jzl^%]8h$?1wn܂u}C"Ka6;IRsx҂rբ#9< s, UIL>, Ј%᛭(H*S+KN11wv+?w0j]:۹켈;XC\&O([*lnbbf>Ib}1fk.ûM:時6CD ,s/*@: -muVﱛU~p, F-όГ"IlhAVfc*+[M\9-7 D*-$϶N6rc;<)yTFHsG*m oQx~W*tr65=w!?d8 SC0&vneL^ L r9RCr]ʡ; ڞc$zjC_7XߒPfԹIfj>VD^54M?&x"$YhgWK%Z[IBH3.eũQUf*_ŝ/@mw4ib}C4nqu ^B+]MfcJ :joa4S PUyb?5FnL7bR݅ "F5贶H)XpV4(f:*K`hyE`cH1&>-ڵ;QhN8vv)sYo?^VlrYHD $<(ps#\I@@Zgη>nUʵФZԒi3P flJi-$ w2atK pMrډ|jgg00rD?mn5'~0fQE*Ŕ>i> C`K*#w20$!c޲_)9{K-UE> S"(]0#v:_iG83m'ّܦ *L}4P1h5S/ABzWl'вLW 4Xurϩ 0Ut)!PjXrtP]j3@Z^k3]Zz8ZE6faG_^ب@텹x$?V}5 < tIDOpfdEO_*P]DmLU$DuG4Eo*xTXJ&+J ²igxFPlsrG1ϞdS O|8J"{BFʆ$^ bg3۟PuH`-6 lQY 'ߏzzxYҗl).;wYT\l?]O Wda{CRM۩a$! (lǕoZ>$%pF4fx<ů08!vldu$yl ӗ1@2*[Rm$9n#,#5[\cQ9Α eII( m,;^ij'e`5ڰ_nXO6u.3-DM}e" OͿX#Ρ!>QR(6*LW?$q P`{ p7>?S=}:t@ Q>Ia4ዮ37{u=:Ůt#PI28~@foJX"Eq :E6&E֋^DmM)DHićpЀϹܓ'RB[J?XTU)er:a?'4cFu^7F?GMs615LW97Q~/}2=U=Q w^? 6X7UІdE=oP Ûr3T8%CI $41@j~ZG.`I-}~n.}x==Np,YF#DA#CN)=Sx$3lDsޚRj6}#<>XwRRHMVEӕ``OiDHjTVi~7R_ł#-Q] QTt$GO]lܟAQ[%:~TטǁLJ4IAfN`UB\51$ t6fTMƎ ܷ/9d6Z$kW"T$CmP G9iofX͵qj|d7+dg3?H~A O[x_jjaz _t6LTzPC3Ţ`>4Kv`'3'UMĠb<޺BsΖ;wwve{#U\6گ]oyIQ@v&.UfT/ӹLcw{R3U=d<<# ّ52N 7b޳iU!pPO=Qa SsLungτ }:,=qRrBL#V\Q!oXk P0 !U_t CJX.dhY>ġCf2f+ysSO} S5WWDhaHkrF'wHK"C.1]Ƈ$z$(Y~ Б#TLt5,-xEo;ԎMdM1Žini<+0Ҧz6$UN r7m\lbOJ|oe/ j8\$o!3%M]ÄCTa\]$A41&PJL<=Vw&K&mM[LVP^@쮱5,q5I٫]'~W)Gwqu WZB jG?S~ŋB`UeJ!>4U}PbԾg=;6,z5Q=.rdJ)Xrј?}sADēM?tDn"`⺶ +E` x, ]g9ε/#fêv*G1s);t_@mTū4W %SXE~#"z#mabPGl{4yM;QMv2+BBI(v>71Nk^ -%۵ͧi yĬ޷$|:Ģ9'qNN:@q_M{@&)k\J NBf#E>= 2-3{z$2BH +TwZLIDA4ot'zPy3^H"Zt'M')YV+ |0;M")pNU8δ`@NmI8׼ ymAf6ZLɋTDi7Ry2ǶAޚf$];638#>_NH Ͻ`깴jW{>5o00pG$_5$7!V/_~՞wNwPN11P{',p.\e|_ɍHv4C~J-;((Jߦ=0g/΅ tݿJw(fF>+Ca^6xKxØ5/ ;Qy1D|Zއ|WBg3Yn@Q&bZ~τnQ +]SepGQWɎ(|L-Ch?`zϝhR)ebЋ&Qȓl(Cj-w™dzVcݍQ$"E\"0Az ǪJ䵧/c#7f%Oto*J}x fwPt9yx#/2Rsi iO-:V ~%N!pz%; v )<j$`fq>;=B\O)Iv#tG(kyF4Hg*k9+.>ߣ'=^IS <n}[C*qpj);"<`0:N2 u,n۵JۄAm8>.L@'&8)e)g}RǾ.)XVَeV5%h]. QFg2gHxŷVbKrU>-W1UFrWM[]"hRҵ?PdzR㟢q ]ZT?k(4m|$oId,LMQLUDle~X~}_eFV|~ $O0V}E [rր%R)%R\^\n=sT+Ȃ6?8 .5$v6Sԅ%}puYdq ?^Wy~԰!VRHome*}4m\P4p>ZOL#5`[xjLA{} :!,g߽D_+Q+Bd[hgY&0Η ֟7aӞZySpXiԤk=pە1/>y^[z7B2΃ h](Fx93(pgL/qF&ҬÀEnfƝ^6e).sB@( Tzwu'J" 5ei}W|k{5 mc:kۭO= r91z?&AīO+O\PZI.IHV~JjH@%;}U͵9+6}JNkL|Vt ^$3z1Đ5#0<b#lOP0 ,̽4NUfk+7c쑸9>T۲Yc^! ,]2ٸb?9::smfTעdm5ɭ(|lRցy}! ZzR~+՞d+EΫP '`@e2HKϐ%-=Ci`rVn*˭{떒2^z!ïd/_l#e v?oLs@YD\٨fW!P haB]EѺafSPKƎ?6E<;2'ŕtS)e"Ac;/U7dP"셗?yIN.^h6mHdArVk9ԑ(-}V({nd< )'Q? P>젋:3aa&UU^*)ΐvD)ȧ^9})󜄑QOT,W< wIG]]q *C%`2c,.rŮ,NEqUM{/}-/WzI: 臦b3}wxw<*LɎ0Iv̈JEebl35d&$"cpoN%e ;^, #!s xq%EwisnzBo•\' I9wE0PƔرƽsDWQ]9v*5gTzr9TI&?FIgm(~ ƎgiG/~uܾ-ތ _vY}wF;4-MG,w}>?)݊>~&-'*QZDy_gD ١q Ƹ^<§w,jZ$#1"Vp^wuvC5о~؜ Ĕ/m&Z d5X"Pr?/eGh:ž@w7/Dž&9v(Z@RI%Yf 7 zHwQz.afWH ,v{¨ n]%^ܠjLLP&A-&lpY;o`u^<دvWȀ*w,߫k-ϱ*n v.3%q|Qpj5å+o:b?6Zy"K=k6čp f2M=;Nro .҉u.\]m=p3R0O6tk..z\YVoI;,D-l\6 P΍'PQ{qΤ '%zq˒BbSo>h\k>-b+ up0!D3OIqbTS(;ZX^U,xmr>ve-r;k ہ ҷ*r^ўl&FjmZ8X|.-8o׹8ZDk-hF 34tg bܿIT/*%3[,yhPÎ+&bѵ_ک`7bzJ09*p%!P U8ql!L]~pI_6塗ay`@;XX\PH=zbVS412S ]7m͑vze3A15{x|#RN x^H/#U ),F=qjEZwt_U{мpn}f>l[OV<-Cu{bnԤ@O,*Wlxu4:wd̸tN! <bsKn:˷pvt:CZ7v w-l|Y$GU^>fSlɔSLZ!Pڋ1Q݉Gh^RQ,<13GKaƒ$לjմJu2Ɂt҅SEB6ŦԨѡ[X1Ürqm2]29⧥M5|TNlF bfLmRaY5WKpf5dc RPeʾ G 7IuK5_VsP@P6h1=(4떂9?'V')j붠rLJd4- ~D|IIDžrr/e]=Ed$ӜaN([1$mxjŨΗ/UhM"|A-cfh̴6UfB}4<0qPiېtI|[7**BҒR;wq{UG|O ݘ8ǵry>"mZ#[Y7$l(H^VyS:*}"&x"%X~B9zbsȦ Ku򠸈 d y^ n^7ww <;Vh ?^!zڬxrGY2n2Ȗc$Z hLoz^60jv{H uYCUZD=kDIXc߭rFr f\O+w:@](V\M7aIdv)_vzH5$:xتkB-ޒ}U)Uu __e۝euNȟ* 8{ 㶰bRh OidQOnF # zC#ݧoi c5qTIdc']dلP\J#+^鉶˜VH[crZcoB>֪-YayP>@F:K *`Bh TdQ΁I:JKr;F]^SL>( XCfoBTr!~G[T἟ҝ0|kB=#ܝ·W#T`pk}I?)j#p3|es@`}Jy-u  1bc>DNWNI_Ceg>q]> t#‚2,-KZ@mP2Gq?wGUd4MSg|@U;,nO;hs2J$[P7"Ax R:8k8iUEU{ip0f z]2z82`ii7A;1Z_iGvNDR 'R!Ҏ)vVI |twL; {/,pł_z]2-wh#z[p?{Ozװ|ZEG^{?m@~7rM,Mg]ruë | SvZ~Ss`ŻNYM6NvV>R:Ѝ#W|#q!3ɻՔjXn$NũVc]'n%q6$X$J]z/ePݲth!rc47 n'T4A],~26tͬ @R;v)ːC+ d,s2/L[ \8m5Q,~{Ë N-][R[Sݨ#/lqken>|76Gx 7E7^%htD&EbOy :rPOQZr0+tKF?ruR3^E1N5ӕML\/rH(wꦝUns>w``A7nVh}%#3@J aZ_dgC֎Ol #0Y>3T8V}Pvp+}>`%E.'"8pĪP}o<\fU(p{ ?F*'2tM Zv78Cq{uc2֖p*5U]ܺ"h$}3Q|^UߎY8Ɯ E9d%Pc37”>vǪ&r)}L= '*ZH=ؒ'Cm-U} \57 I%ӥ/7 .Ȫ<=79\;j 52]K:A;d,G~ͮ k^ zOvMJAGS K稠^  IܠaND&œ͆wM2(4HHz*-h˻١v<)p8|[!cDcZ&'pZ}=IvL~9}_ !o+7H >S x=+h:e ҠC?j3"a Ƣ3\ٵa0 >`He4~Dp W2 --:E6ly .4õSD',1Z:d1'Y!TIьԱ-~mϾ/n~UUF77Z5|ewE`90ҲPcr=B;5$qTx.vYwp$0Ɓc[ԩli<ي 6V`W+EAsbCA#XriUfK.ҘX/6_b WSA{nQdhQ_GM'z Q}TXJފ߿kHli<mcn 1h;6)Y.Jkfr\nfN7OWЦg\+<fp\ovC{_Bz!.fx̰ 3/gSQUS[X# l!myqghhB$8>؄bUPyzΘn b\="*BGS/y.={ M5\xK%"[u_7#V:lB" B^oǫ;e*+lH 2E2B9:H\`bvX6Q  J1B2k^rJđ~|v#X%;!' ӥų?雹xP\bM L=z"ʉ,Ʋ'f@)?]U"B 3; zy*:sp g<yPxL#ʤm5{flg%}!|>!2:⦉>ή?+"$ِ*aM0]!Ֆu|7q 9(7o/lHOoT^*d=H H^.vHs#??Ys@H6/@#Xf(~k@i;kGc'4+*rQ5t %]ScK6'%Q+[BܒGBeLB/ =vX&N%}qCPF I$l]ǟ)#˽{MX">b.9>< {,$ LF(E+"#)/7b̤tD!#5n!1 ,ѿr)=kb<̴]ؼ=շL`ۨ#ba3b~cҎ-HnG+n8,Gt ~YP3wvX8fO M4LA#sqa'@ lTдgU\^I"__0dqcsp6^/y+Yʇ:x+sF\=f*]҉$#3݇6=m#T>dc(&1rX/@>u(I ʑaOod*d]e\y QK.}Di6E&cpᗱIO $ni# :NJ|Vl^lX^W1l_Bm{~ m`snncN`(7ʇc|٠]iy7lvv =8fnsTV۹',¦O "`k\eo&z.}.50PF ̿[:h"e(cZlI9ȁX#6lgW*qzAw{Q|Sf5d*.S>1_4w,1(IΝsEZR-ŏ2Uy AB&~xIֺ/ِ\.ZagmWN Gj`3V/HT ^x7>6Dba&V~s?c?n |^3b]0UU^Peere:z_ueQL7#dÇM~Z>2U9RUj +K*fД󝛊K=Gd cQj)Si #łƩ? ?? \N}tV)nZS=5a)iryx(kPBx{EK|ndiJۤ$̽Bբ! h08ekGגqxGV\sA^jwb>R/Sr/5]Qe`Q "̢5,eli+4KqʐxxMA6\}j&^,o QmiE|3'O~X9W]6'#\- Xq]&:S9^DrT#E˷a;YL]-Y!HxV^?{@aNJRYf]`(8fHah J@}S˷ypA,ϲCg6K r, bcTn"1:g;2nlZZ`(u=q#y~z:!h/}+Vcd[Su]v08iۭ0O%<`hݡc{ VeϨ#y>OWmms]%x@1Esg{j"Z8"eg5)@.M126?ރ "ta3$BQ֢ʙ0^`=_G"oZP/B"mFcnZg3XV`xW_ u?S!1da;vU(yT^nanV C.[3, m1^xjX"kBv۴F>y0O>غY@\iK]ȡ5GE(W+QcQn͏m-I.33X!vO#4㷴vꂧQ}k ҅|iI+w&ԄZY^ܚ &r0`9ͱAG[b `hcʋ@Xo3/d("iXFXpWV^_Kۻ4!yi/\1 5GI %9k8eQs~k4@gmIt==%Dg#Dm~gSmE_#V# 5XdI{ f>K0Bgp==Og~$; /.$ZB84'؇5HV)V_QZQH  M B\̭/2Z2rYdׯUz]RǪ{XBiNi;?wdryQ}s#)=1p QIrLjqG+MNdB7h=V?t. c;gO s ei2?k K } /pfg5@9Hd{_fO{S ]i^4o-TN5eԶ 5I<roWUFn1ۄ{bY[N?*" g]0̲Y RZZP@gCr>QQK] /G~}-\)cl{YQd3{&M[kԎ|XKx,Pq*c06s }.d=8,3&f4ag1SS7ȁ2s#}=l0v%,Ht+nd W(23*n+$2Hޣ* yUS'RS8% CJ޶wzx+ 'HҎ\:ï-rY0:xXwձ苓x Ik~HౄGɟBK6]*T+waT*79Pay c u}cA·zW\v+y)Zb'[Mޝ\zacWen2-+8ޏJA<U Tp,_ĜuN !|y=b:.7aܽ{iY Llnt0QJ\4+նZR"j^<gKh±&sr P4PE_0ۿKʹQ= AXUp93 n/a(}+6N}a3+(G;M~c8ŋ5O[M̗=LUx ڍ&zP,% uy #+}£6pxC'ڋbz'Tbn<}/p Kvk3zfDK#%CSxn ۪ j(kn08deL雊q(d]W=ֹq7@I"ޟž5ZZ܎kɿ>^?ީ:AP5?Tw0|ql+ZЭ-bv{0*S/\[цbo_KBWɝ=/q⏇f'`xQ3|"dgԘLuXj^jf 2SF={Igh[Ж)˿E cҀ- EpDK)ulŃD(MC[ G=,SOܝ[ƴyWr@6%PTCёͽ@Z3pC3&+P^-#pM5}5@;\b"սi0/ S%&;Ōҋo,Z2^\ d)oJGkhS%Q%6E=k$ CSܱx;eLi53QS: EBU}Nm,QQgO[|N#)!"eǃܣ]3 J@^9(ߧvΊA6X;bu/bX}> 6C$;9I=ȃnk\_C]=㦫޻~\o裿SQiS?+7?pM}q=NIDC,$Y+$eо{OpCNrYLi!9I1^(D|3AC8Vw^YIZKak=Ts#/XUw!Ctϐ=鶲rm*=ҐaJ)4\f{=n2FYRhp`zk,GӋ'S!UʻwnAc T]v_ޫx F'E٥~/MbmN]9izpmp8owǚO~>H!QBw(t[ k˪kYײg܊#nGF1CMH{q3%w AU-sWW$Ჲ;x.QX QFKs7ԊLo=Kh8a ˤ]xݡjzppofG.2N5E!+$AG:\Hh,Ƿi/:ͣgl;Y )߃^AI.y3?9?nHk󨈚-aW"!&#M?ŀG^}-TnX-oPؓ%n Yv8926,!=3ZMYֳfaS&G'Rn >:m,k*MD}׼|2zeJ*.zG";wx2O|nՊ?rodӔ/m¶jJGPo0 VPx`*F =X2Q ȦlX^"`j󨟶UoG6ծ2.fzѓhۊ'a t gPi[c@'un%& ?,j'5/5ޚJ϶@xps T=F`{"糈dVw7)W#nx1&ꖚ0}§mѸu8}MȟwĚ1'b|M%ܥ.CLn_ DLX l`LPY막>XJb9;_MI{›Ϗ[N*ֽbhk~ '|Ze@F'O[$z)#WDf7vgN˜ =D,9ϏP%~Zj(9;h)kvD_J{rL7êw߳AE 6T(;iH,S.V :>淘}i:%zAH+-AZ$PfɆOwK82[guom! / YSpSw=Sֹ{ Y9ӌړ6} Ft0ŏ "ՂKCqחìFJŶN݀Ga E-n iO{.#GZ-K]b%4v1{ RJmQx*>vVW7>4{skbAO`>\m.>MU̬d+2*!Ģ:H.-sXS]hQ)ERduf3E5₭} N:v-q >(8cV !u$(' #N3l$/1II3`Ⱦ"l |&!v5H>O< اYZ{PTt%?n'>O(GBEgH%6KN,"f9T,xyD9ۢjO{[ucѲPb.?e` U)vBgA?b_p Ja l=S85}(ޮSL{~U+OB$7&S7UlyWazL|<~K$Tlid(DzaFg J AX0YJ8rfp[p1OIe.&g0M{/"{3Ҝ?s yѤ'9V̩}$J4v"TךvbˇpO=d\^ևh$M4cb*=J)_!T:'?;V8 /RJI v>.a[ꪥ-5ye/;Y!w}__y@+.bՠ'G:7pUh^E pV/ M!8 6i|>D:A|2*Qoh,IO70\5F_/wyf\c0vs䟶tl2=:^Kݐ {2 cmYɕ l8g4?ɏ ]0M/pא0 Iˋ@/pq/_~X {;R,rHK|4deZ: h+tDEJ]*Γ I٥asGƂ1`4)W׊y|\bTҽ)cV*4^y{' |JOGf$DSmL&|IO8/^tWg8j4UaU_Dj\ ӄ\Sv3?-DCmFZ$g2-Qx<-S&Ν׷s798엦;N8e֟+{琣d@ȡ>AG"_6 RkoH|_`7-1"NmRdT.B(H*7:ֈUX6"^jzJ@ #+"o^L+?8˪TWLwĀm'}{mIek:¼UDe1 0.ón0'!D lq\Oؘ/7D؉qgtM,v.%x?`c2+*m"pe$ snrG*WbDذw!閨Nqz_H W┟ŋg30mO)>{oz h{3k~Kl Y QPRfAmxBNKvn S d-}*$NZ,]h0]0 2wpL;4tIBۤLa7Gw,rs!RqUgwyGG^$,NvY~ĕ0b<ǣGT<^oPOSs݈UN'Oѷ|[VٹҶrߚx7*V{`nEVn5^*_LD;ԽB7V t(6 ⯶e4$ޭRRb7H]QEẋ*RP)2}ZwH`B􋁮Т5ފ1~wʹh=$DOȰ@Xu0,"v5jkԘ.y2[+w]cz߳Q3ȸܼ1܈쮎? * !;Ju+SL[oY|*QOSpe*֫$=Pib%'R(a"Ec3wC-/e7éC=]S}_G_i+C ιh.3na9O6X [ Rq.­^h5V+7!`_7ؙY%ӏޗu (-qh>]+?T~-^]_b\]=iP]VdOB~ k- C Ytg 2ͳ1SPڟ C#ׯ|OUHTJ+!-1@YSa1Vӽ Z}|&,sOe,%XI I^47,sN'r6~vRW_ݤQ2>< y`ۭXcFm$BE?iRĉhjAq<5Qi@.+|C2h ZZ{ToZzS2?E^=z 1g&cZgOU$_~TٲKBWSmTLxU/w0>e4_0aXaJrX NAR5I.B!ÜKӵ|:DmOQ9w6wiNyf*jfpN$Q La2?u׶I|k@$3uGLMFӎ2끪O3+0#Oo2)&눉o=}Xs\`CbG~ךh9k[_o"0"^XxZm+ld##l]h#wZ#8Y21SXOi@ :D\X9k:yip*2Y* uQV^f_gK;rpy|(&\zCmmʻ/צ]c&{pqv9V﴾ص7㌝L>X).a#F `b^w{9]WYhIi^8v^-_b3H &{u8}Hl2 /(H Cc iWw6C .| \˛$HK89p?zF{X~fkK}L\gfP7kzg}l)å Xpr2mynxw0xN~ζW>!aAEU-[zEAoF)k˶?\hŨxuC L/ё~A}v/i@3&?9gx@Xe!{_SF)snpXLPR6KVaV[LPm'ifeX[]ZDAZoiqz {D_)K]}l:?U2ӢuT9 i$ O#:B+6W fŝSd!j P.ˇg~^>pL*ChdPNb}-IvN/`hO\Oۋ| b!TӐFohd=d!`גF\y"o8ܥiLMz#lW6]cIJV"Nc=m[m6O߲(Mе**| K}Be5 rmLl5{S-슮20u΂{z"m2HOvQ kK@%lY̺I3#Gr #X)XZ yLu˂XX,)lm:B4a{w~Yˊ'QHJ(?3ْVoNr9Ag{`bCJzw[tNUgw|mlޯ &@Bf ^rBBS}D,&mB1!߃[0Xq;ً-!:洀RtilV:a85߳zp j=$۠K^=K~ onN\)Gf9ߩS?] />Pت4դm-?~G 5!"9jTA<3~#E ήf;U{o*kKifao5:ɾpf~Jtm"y`9fjl|c/9ZTFv&An2VСHCÑ^f,㵵 M$9@45jA'yQd$ -wf'+EըU-2Gg1$/4GA@[M&a N7XxLTM+ Q׉gَ$[Ϣ]!@{'fձ]s R%ӈfz;̺o*d|D@?Ꙁ gУn VY0x<zFש戫BZ,cX+EϦT-q4gP_8"qڣtr,i12t@rޘr)/Mˍ+ VP:kó.yFQJ OV~^X\?^/0emʪz[*s@XZco芚K`>nod1L;n =3Q3>|c:'^=6jx#k Dל*dl/Kyox52b#ie!{Z(\i>HZ-6P9.#X%C{"sy$}hk>z lgt1krzHfFqߜ 1p3&mZh_0#V?3{MtVJXA+H氵z>rG[>jvwA` M4/adӊ.Y%1&cGxft=t9_x̼T + D$Q>0Wzp _9j̓3/$_$Pv 4)Lx\`]߉\0 0&cX}t&)!_ߜ;Ҁ=GcQMCQDE&8;Uuzo);ẂH.HPvAl5&BEڦM>WT_akÅ6G8_ol%v&aac lqm#>s|'sɫ [Gb`lr 9PH|ӧJv֌LcQ EQpkE.rƮ/]t%n C`[mBÜ3KI7FZ8u=P<56A+Ϳ _$3梵¨.笐 ޵ 1/j~h%p\j#_~m&B{ZEl-Xa ExxSG:ulD͆Jj.[ѾWň߯\809lƛ(gQnI 7e zsҨ*)>g-&J^ IR%[ì?xВ%̃+,oQ}~.]gw+x^nXL t.; c CӖJ|HtIb/ O%S>I=]3AE>x{O3LtSQx&eYzKU(m@9 oB@\PQ_ިh W9TGKoӣzz_ :@|о+[(D<.g!E *'ᎈmg>\C-9T8y`Rj3p aC#vȴB $jTD`B]Z.ꞅA7~b8~A+$/+88` =D&t,֒V q9iVbML0-dDCf'o҇T+Vjl~rѠc CǶmjY?'/v`:^,)2Cs0͊Dd0zIkz'|RlVKI?nQ8!ғ1jd:៿1RaE 8?B]8lMYF!EFgbYlDk|K8GYwqN-z8#!If nWD HЙf?]끓ܦN"ietkt5O no0_i_3HqiOJ1NP, Fhx}ZˌvFh)2*j jg-I7ިJb^'lo9$B Vo>{o uñ= LA[H.Ϻ295>K 'tV& 1\QwbPY" :s͒Q;D\O߈&ge``kPe=t@w޿UsT:k~?Q/D"bT^E@ OA'A+JB4@V@uoՃe=Cu!p`"m rAi (KuM O-H_=ܽZ{.N-~{O=)ߠ9o+dY/se=+CO i⼿D7,>2Ɋ+~ˁř~aגni^у7VUQlAk$=gS6嚬TL- c}XͲi3lz_kO$T\0C|gk&qEY d%ߎn-!znɈ{7R1?Ͷl!e)aMH@Ԅ8%! %.Eu=Q@v#oR%R.~!QWgqiK:Eq)>;_xQnݬ}6u2G% ɿEӁGFSJ$">֘^!p*ONz8/a.j!6`tʝ b*K3x܏ NFYM00dֈpڥePH[Eۭ2"چsPF6>氠 FA`(5Z\߃YNj l2P\PL$C+Jg' (I1#^9-}ܛ$q^9zHEzRZZ}fw_hPra+}+ Oԫ8)jo@+A}46o 9"$>6Cw9v1TfF N``/'=nC߯뮖~((Q1Ç)-}9LNmmW4KL0=/6{w2@n\!HB Q`j[tQsP!5yl H,UT` gjL\#Ji!tW0# UrU$ HMC݃40uk>pºP zA ~7׃ȎpDKl$aB>tc6pwoiBf~( qNߝ;`EIowWuB2 cCz9c^:5UuuSm |B8bņO&Eg1tYh݋5<+&T`rLjCD"XG5x/*ŕ7VljRV$0X"B񧭚wVj*1ePIyȟC8/.:ֈߥ͉6_ŋ%< }ao oc@TvE3 ׿N۠ߣ/x5|DwM- K < wXhxH!\e^a=ro4yk@QĺJ٠Ce+M rP:WkJ36T͹ppI_ՙ]'l zWMhΑ.$]'^6&hNY0R:e)=x~]*Dt{ ?>!)Ǩ-"ᥝѩ]@Kf^`LDVPΌ2S3%꤂[z6U J,Ngt6xKiwȐ<)Σb8])|K"h(@< 铪J;.ɬQCygF̴X=4c8Omș1˰IlĨvTK9n6l ?Dh,{)3[u.1As^#q%yh&Ww>Ǭ=`xe1O;FR@6y)^BBA$="2q;׻ȹDЪg Y@@:4|!a.`qQD`)n3)T4ήqucZ2j?\[T%%q"Km`RD8Viƽډmf1 t 2Wǃx2:t᠓ref/.!7wϢT+<3 i sʸh1uq" RvQK^5pg@6̟P@3f=$d]RBE &g_Zd;>`'y˯/5E볃z3B冾62N;ed_>%}FvD 2 "޻*qۚuPmW",Eɐ4ShGztM qVڨ(ZAybZ>0 1mM b qd8}^!P>~*  <]L{l<[75\KFp8r lLVvh+XpP^"ުD+Gy7k-_'vD?Hj:mA0c%WzT$Y e5{W9|d+hՍY.V+ya9+VS\tT`tم,3A3/m IS*h'ɘ}0ۖ5a+sY_ CS2z0x†pT cCue>gsa}"=ʎj[7&"şOOn5nٙ}z6U'm|w7p2"M\w[&}z9_a 1qa܄^V颰c>t u]Y@0D|EZiM12|t,D!rxo?3#bH>2੉8YG)Xfګj^$p/є>JJ>M;"o8QY-q"/2{R?W0oivf k{mͪW#i`;bp!g{Vx R$ )&R5]~2yKAzeoqa77JFu4ةw WS7&e,]m\j|~'Qҙ=-iKGvAǞw )BUon[9J)c**qұ*ЇQ ɹ@J!QÔ %IQ7(7Nz;ŠjD8^cB2QI|w`L55ҏ]yQq=偅Tw&W=4T7 JJ/'Րn+\f 5V7o3q=Ҕxgp2 t+V@لթ?._, ?10wɋ۲yJ; >J%-ȓC&; J=@S#*\ȅueyg@BtY;W_ Ÿ?ynʺWdUdbTotwMn3 (0lh{2MۢmaH[-%PqVo!&Cw؆2Lͥ-btҗ=WTǁOD 4jC A>~ohj`03vOh)sC3V~TBK{arP7{'4tdF\iBet) E2&ۓzcb; G% *[c%йPIwf7u"GEY2Yde< Vu(lU^?3(3t5hCy^gth +gam=&ʂjJ c\pi2°iB=X $?afO?(*<׆m%{ArJ *v=6iͨtZtBL߬^vdMVաWHщ.D||&iG׻&xRah%-/fKY4 ϖ|"5x1&3yl+F4)R~@NQoIN\]UB ˉgF^.@#ksjQ"SQAYU/`UxGn_!ĭnhLc -Oqrt+C<7ywg)VZqRRϿw轰\PXLcQdE]diRTꪔ3%z %ˡS$dG @ٷU'z[%5'h4Wf-c̮Ϳ>6_t͟og%x䕷RI _gO}?|~U+|ޙ,C'Hz 6r4!i5eKj8ؔGMIi\</Bt~Sl㖝$Z@\ۏ6S~ cnm8N11?Xc;mE$uWV2Z"\(Cӱ{ImCdP6x\ {w4ZPJ*_Я,-'Nf\($l }!^d žZlT%4}I䈙{ ;+{hjIs/%"`co9FdENh&,1s{LJ"}&X C &("Ԩv `[vfUf> Y ݅z H.n%B nv6 g6MK|H,)p*s;=YTOism/6L0~aobai̠RYñzOVȭ]s9p X]jo حn xNEO(!d=d]cgcl̞:]ޏuJotpiHo͗CVD*z;2 :)j'Aq2H*P[ gO:2y8Y xᬸ\Z~sv2U5C&bcE| =aBw?&OIu\^gڎp7J Im3K[-?wL!Nzt.0[pazi |bI5c*St>` l\BZ x٫yWr06 (N/` f݄d~Y=iOk.{io@b~w%i;ZUn4&ES@pJfPCUS<VEs# b ڐ'e@ݕ'k.6j``zJrgNYxTEzr Q9L26 ̫sJ.lyVKcqc0>ϩCB} #A1;tF>n&\ϪVkqBtnl1XnN|{5V8+.*"s5;>b),Zߒd8A}.LH⩾}HQ1-]gY2#Dy"?f)6LKlݕ~-sT)4Ty'ENAچV0YP#I0on5%"Ƿ<@kNj=1nPPHiYi?Ac_XZGZ֎Ͷ/ t ,MܦxUm')(3J "͋LÏ{=#@|_|a-I$Ѽ] 1#mo {^:ķ%w,ÆsJ-W0CF#bO!OLqš.{gI` ߸r}[KGYv?1c1K}$۳g a Z}%i"B5pt~GgāƙT>RD 2"Mr % 6qAimlv 2'L>#NçfEkwD;wF+ d:(%q@yU+QJf݋!x'0o#;CnGp߀WBGo( :L.*UYd'O\V{^Srax]33@iaS ˛iTclɁʦh pKYi2.I0֍4#.M@2QII" _%`^MW zK$QE$zbvՅ }<g]ԓuh3v^M~ٵf]/8Fy#oGjpF6T`\ᇽ#~ Q>W@0c.Hәg@I;/ucZ0?5s""0\Tz~78}!q?4ޕY"~yK_lH5Ҧ,C5m6~iVtw`۵+,o'hR G=L7&HYAOH4ܻө̇N0L[GSj Pd |ChŤ>^cnKk9?mdu&] 4Èz7gd 範|Yeڟ%jeY` | Lɪnfhd|yzJ1S\5h\҉^5(* Ѱ4=9_7@!_hAcqHudu*tʆzhދuy9>e!O 7-B'E5N8uvn3Lc LE93 ǰ{󍱷Puoj׿am^B6$NE&il 9 ]^}mvN/1ry4ufqP1T} 7_+V_AjQ"7:WG6- gS F(Fkr+.TaϙXH_=&w1OK"3" Y-S5WDCj)8ֈm`ZD J lI؀:99'+>>Ⱥx2!7`_x"wrvfN޿ <` Hzz+g!=2K:7@|y#PMLNl%L{l S4VaOc9*(1nJpṙBR*%ʸ nPFcj_y޼w7uBga;2m2xb|ZB+m~{rI{F},YwƲ+ۮ?I-Ž98oT[Y 5%ps{HWVtˤ+aK6Nt]e'o%u{ PW̓/;gw@ߗ5@c "5k\x|nBB)Y&(v/BgNٖB^\(+<-slEzP{?T,0:3f8;6R_E* mhP^K>#C - |h DXjJdGd߾yUv )2|H2d"3.wt-r$d#B?' N3 VIAaţ^ r%MdMk =٨d`KmD4 E"Z@KZwEeWA9o(yUHl~ :I wļȞyX޿;!GXl:b)}ZqQg]S")SEȪ'5*дX +Ov%O~& K ;8 joqv[>b9u3EF@>Eg.A={=̶X94;_6Ԭ.z`5^@EW샔nE"zDE@A׻`FtmG&2'zhdx/諵3qGhJ,)\ʡPN <# m 7|PXpXst֚ 'uWՅ{p^-TAJB FPZ#*\! yKEa#ht#d`C:@}?H/ٜ MܮQ:. ȢyIG 7FOw?d^ }DZkP -݄8%"ԍ|w:ymI&8*X>/8yӎWX$!sVrTdsw0Fb{_{J۫w ZbkR8$#JeM @>UI1Jbqǀ*W9[VP]Gq֯ 3 'qXJ;d27ŻJ>_tk.PA?da,y*4hsA6x6c tA?c*=8O,KNڶGHxr$JX/p%$!}`.Zjl Feߞ*|W mbۡ3Wn @ZFFGI%܆sB'I  w3md+dzlX4la76K~Ks;eY[r(F ERyp}K%6lgr+q { ,!Z߷uh3%90{nuui;qc\)j[pB-mA LΒA}}ylZ7_9%YIrl|c(>W cKQP#[fa(2exMP7E%BKd̴[X0oXX<_ǁ.%YaGI|+ⷼ,UiMȫJ7jG|eCA_crhWEB?RS c=!mv4ㄶ{x=rq~-a@poAgdTٓI=F$Oч) Z pFo`"ZYeY0EPggyH>SCT1W1wV,7KhОQ ֈ[M~p ̤/֝ $T4Q^d;bXqw{w]x__ʊ<ISVGyc0VB"7%*/s'gxY+mL-Tn7K}D]NNa}x (X H> }d  f-9PPdl_tg ?vfFr3@C 2}`JۊV9W+¦ )F+7gb>p!+杻b=g.oho~H/4 =3N.p#ޤ$ʡ 嶺-qAUf_FF|3DM"%*.|!NX9!jsW}1cW )Eރ*!S${X!s spՄjl*AݘUa<ʔr< (SGtD `j7/!ÿwgxe[ÜC^N-r\s(2VeyJU@-[wb޺ȉjx)S^͒D]6M&1E*$)m ?7,,X#ҋ%h%a n27ɗ^:y|Agk_KK>W[]ACYX 輲a:z;#j6b^lݰ7Vi!SG,8>#<7\3htD'ډ` ;zi*|ZffD'aw2;H?oCe?.M5cŪMMo .PxlZjɪ=_CUy,@GzjAwg\N5z8/u&k5uCꝕ[iPrK3)V˧Uy&ͱA``3J D@7uChmtt%9UN/ck&;\G8oDqQE3pt6i{ߗ~6Aܝ7nmC`4bןEТuwSD8 Jn9={+u/ p%]]=ĕݶ^_CGv)|١(i.6+RیrC: GՋ%#a5o=Y8 `YC* 0]D0K*fa7H:>B~lJq>?Zxa_e!È'SγnFJ.`a+.T(Oz›EFRAYt`0ak=ZNj퐢k*11;?YNbatp+P(w{e"yAZq櫬zy*V 0T>H"~| Zf$!ۜx߮*Uį{]@o& G0(ڰ2fUtW3XthZNfXnuq-yՋ)T2YGtv[;l%&)ek)j:+7LPi^CT]Oحl{ZSFa#⸘o4! jdRYU i LĤKsHaphFc3Suv`3jzS!jvU3`t"cY-5X?_IO,]F8+ȽNw?RlH6\7)K;<e±D Td42S/=&oמE67/}DU+d;4]_UmF/ѲHN*1_ݪB_~ے-etxKޠᑏ̖DM9ΩhjٯsB^Dže8-(F4(9=|<5md[miM R,=UO [aX GPnֻxƨP$_|Uw"GQΐt]62K('8?dzG]%l@INF1ʐqm4 2q<C 7gtnl_ڤ5ƞ2!'流`cw^fc~?|d_ "ʟCWh2(} x@-kEO[4u(9FB nbg+ƺ1gST48MoHd𿲮Z2:KBlXzJS.U#uJtVԕ_sˢrLs+U0UEwT G8:Ո\}'ƺkp a38N%Lk6(>2=[f`N:,"m wC6鞠6XlG$|RidBd җzS$S%&^0P N¦81,h h3vt/HOe:%UC^x S}i.Tٳ!9FhΣXPχg'x>$ )6 Dn?"u\W@ߦ)\ۮ>8j?`xAZW!q9+^3yYS"~^ԄV #?B˃fá|mLT͉xf7dc0<<ƠNUB?8(SO'i6۟i,2W  tRbo>]v [c>(H2 Ι;|Pcx*.άHԶ!;8l .I:jS^DdZЪ^o%(mE r)DɅM8~G\̒c º\oi'i| ɂo|q[LUs@bGeWWCV/2;9CM'=YQԵ,x.==#8՘C+Yܘ~'%~ K3GmY"Qy3"WXnk8R`91  p:IҦ5٥S4bǨJU:ȇm?: \Rj#qd4a8L9VN/+1fLѾDb&o+DWk.|nJS٬%pZWYLŚYiADPo(6 $+eNQh4wq#[t Rb L,< *rcy#EWQvJaW]3`! ?3 P>u', +5 Ēm/hIEj)la vkM.zhmO;{߰\Kge&DlC.xԈ@*㗷hx} |u=J2#}'Yq dUa/c .g#7oZt"b0Gz<[jINjI:7; p^Pm[ cdR7goHlad\_# Y=fi47,ORgEY*ZȑL b<7 5hts솿KwMA, `y)&PsH>>?mRGݤ zMC|v~KmGºqFA*d~]wBR$]S봘^ :'y9e0Q<*y[%inwcb8I?Vv3'd`a mo&st}JO'[KZPiոKf`]5s&xWb(jj:3`JF\=*woV6̃[*Qf!4Tͤm%`xk^h9湝/3dS|HH7GM#ɘojIM~bki3^/łj,`HR+ZbݡL1mj]bX_7/%)Yb/8I5'^@ߌw=K@>gިqPa6Ľ2$UVwCيV""` >=ncs^ܕ s9+ӜxM=9Z1qHZ:0tM"ML]Y+>]qgsF|[gOXKB1BFRjdYM0昽Z=D qo&UG+ZSdDgE1S+{Gl-*5QY x[}c4:\ZL OV5,WYbڥVŵM,qڍke1B:N 90NF}xR5Pd WWL"q x薆Y?':(C&aT1] *VpV 3P$$4%uZAO!jk` ԃ&845!,9iU+IEh# jŅ | r˩@ O+EFONL{ ĠsA_Fd*;Wja紫OܹӘ G%*jB& O  OMJVм[(wM7u"a +UBmT7u: H!2%  x3iÜXAMMm|1:uޥ<8 d51b/p.{}9ɔ$T.TVNeu}yn Y17]R|c%4n8L/ G'S)1hŎqmC;`W(j$;&ΐ]0vVYsgTݨ'q/<~ܺ! ~Iڌ JGhE~DuQH(6& 9-Lz&O7;kU8NߡJ%*I|F e}LǦM=Ηwۋ=zJ@>3:~HqHBׁ@u:wo33Uq'Y~ȤyJ~0^f]6 ך/AX;2+?Y_Oj<'il-?(3:Mݤŏ`|ksl*p Ҙp(dGuZ'@ni& Od8P6 ?V''gBq!R ;w2ؗS.i2JKFu oӦjvŭoӹxajgX*j\P "t]tDiMpBf7Ir-LOb )S9l3Ԧd~o/\H MG%n.Zi#~bz^bQk ;6]dB2_a䯐$}u{O\Z|=2la_܌P-L54:UauL_ r|,STN`-{i8h瀲(1^ޤ.+Bs17=y#P{X %nByo:C]?2~硋ǩ(LUti'sJPv[R5Wal dHTL &@*UoVԟa{$.+Is6o+H TO-6APap:>Ny p!R,SRR6}H9-4%z `\XƏr>*4 `ߔ,9R`S'=nige|J5ޙh y/a_Lw{m$*-?^8NɽDd^ xwg|-4U捾JPS^y%|Li}2oV3::2pSkYN|`ݫT(>]֛2@Lj17`d0Ɋָα%ϠAGv ~o[2z E!a*` _ЄtR/Ǥ;[1ǐBpu|;?VQ#pˁRS$"aB6L*򐡗+g=DM$c>9!'1-7DeD=HԠbh5JZT; `ٶgf_ARhYl^;06Ư(KdG0VX%Ac.IXf+;A& V 6=:}F~JPS!<qbD%@]MM,1xJQp~"" x 8]K[/e<(LN7% ?1pHwO2yVwC-i/8{{OjkDQVʉw?Tk_)= _O.S걘r'TYrDuWrCs ޖ]z#wCM{-^BTuaIrx2YDK6c  sp/@Nw@En5ڸWbl߹C@-{h&vN0g+N.]ʲ(sןc®᱕x`MֵU٤4V;(j%Vf`=fTB9ݤJԖޯHvmbat0BZ{T;Ci(Bk^c5 I~dx{=٠2(ESK\]\J_WM;ŰUnNœJ^[3v`E,  0HG.H! #bM8󅩓26 ͂`R[= : }m6z.e}Rkj=H^Ÿ)݀Mg )PCbcF'}U}g_3t^Hǘ"VqFy,yr?HUuw[#^ɻ_}EB$(:‹%^256$rrKTZt IA"8O\ 6 fy|f,`$|UQjEW](?gxggTҠ@j*Hҝ})xlE%%Mi9ɮj&;Ĕ1ˋ+Zx6 8#^JRbyPAƷ(ѷڿ5~KjYKt_JxX*ͮAhz$_п(ڥǿ'7]Z+3x4dd!-ȇE da-!Q;ޫ<}@2o"woݞL9Y(Tp'>tZwyKyP\9Mp4JvJ? w GJ75m|@}"׋f\m+鐃+RuԊ\(+ۦ$EtgiФ:w&Jȏ=-O+K>3Z^p&ɝIN}Xu9KiG.Ӑ AVZ_Eqn)잸jmeɖU5~ 3X0LT˦qMvDv*.MFyºղR.O6 iyU;h[bm^c dVa*NL9{D*_N 5/Pw~6f6Y*c5C ;i?,8ˋwBIX~H1NzdmsprL:vpH;}> dNs0̛ Akox:~4IHp}pe/^pK|]Oq[d<@#.Iy/K:c4E-]c}ionw '[=߅ڣ` NHUED^sň_@kl6^!=bQtZι(Ex+*KV/py)=P8) Φ)(W ce5k]Ҟ1<τBD;0Cb2&f%;o]Jz)TNLF껹kXva!Su*f6=8`^FaH*8yV{XBWN9r"' b.Uu2>805PPd@HIȩO~eQQR!]@f,]*^-0ZtJF o9h;Jb4E  u]˄m0 N{:EEVAn;zA kbk3ړ픊"&а{Bc'!cN~LދvSab edg kyRo1"k)̓k_B \" 704cϙjR/~_+©,[PK)j} ͳ%,_>>u`su=#WeݽM ׳|>ڪ3FIætnn)IWS$Ņec]$eWO}D_]N<2ԍAD^AT=>&bj(xO R,g?Bv BLz {.%ئ; ̨U 7ŇiRוO*kmȚ~\?F(9U%-M)Յc3{j`+$x@o`jK"|+E[9xr|ݍTNmGq]6دfǬE,heݶŧI| l7.xxRkW9A) [Q& $p#^p@'pt|Bj^e$P"7 Vv/$av<@9REU9BJet],D-ڸ#ŐBHa%qF<^O<@[&ZxU} HNȎxYW pƧ"-zMdϒLq >e5A'Ƌ\!k߁]|dJrXJSn:Ox-~;EsB R\i!jO? yD'SK݆by$$uѿo9(%s^B:6 } G\rD<[0WҗfIoV]QQf%dc#|np/E~ip!H&Zq$A +B,Q"~cE_c뢁`0\Ar'-z|ʺ %K2(E"Ѵ24R?ük]jW mp+U/߼ b!>3V+L7uy85YE#c5.}6D*F#<@XݨU i ByTh[?R勦#xtGTz|m咂ց%kVp\ml4n\ (e1ڼW6ӕ.&?ՎVw%lRtwMZp=u",&`gUUw"rswv#Œ瘘=t*"BAWg,Ɏ"YP$!buC\I;EZ g| |5t:Uߊp<i{y@e`d h#yxts~Fh l72fQ)) hͿNiΥ8>q暜ړu=~r5ұ3qkI-j#.Dp+iT @m6JA}/R-W@y-.}dQRq+^:e ߜҭID!$pՄqq|/GZͷR "fŸլ˳Yi*}%)9FVPzV8!Ot>" {B`\Sh{#@)WTҕzǚr$QLюi'XP].rO-KlnЭ MsqW'">56!s/ׇ2Y+|q; c4LxV2ɦ M]Om7z:n5sAaUg8$lZq,`Z.W^[dLoHԚV{HSU뙅&.RjRc&ሷ/?UN{e%g =^uhf YE3t#e+h u /r6`kmS#+(j(l*ՁeķQg'$ Q#odc-$;@) alrgHj@l3+DF4#k9{{,uWv6,wfgvIn/SƤ?OWy M'%ٲbkuC4vpښe{?Nţ+o-X`J5!i7ew@UCJx&?Մ?F`lQ9 א\3(_'IQ?6g[.HxZ;lT@T'L[a/8n4% !V4 WC+1E 1|~jy,1PZ}Xwj*(V@#F۹.oKKZ;Hn^ pbϴz ;2'6'ZԱR^[w0To7+1i\w}fp -C #xd!NYvbGZx'T|K8=9\ uGK$-?e])Vٔ>6߸޷L9]0*^eGs*tdשzU}Lh0l#>Y)ΗzEm|jv+vp#: )~-`4ƁLlz tBD:rMd0U\6?#ϜD: b:N(ug4}|uG*wJ8YL Aa`Ĺ-&>hUz%uxȬQk5{sK.*&Öh!f` qq8 Ճz`׈9qK-DA0G3tm646V[. 'wmC'k̄_Ik:xZ .i2xh˺"Ɵ6֑KML)Mp M߫Q[#5LGTae-@F%˫qYs)H''U(N^ngSܬ%!GP:DI~*+Ɔs~r._YkJ$3Dz섯#3Q5E]SL.~4}LUM)k@bNť=/qme.ܗrJŸmjnJ4B &,$3̖kxx\^%.O7Z9y(=DRu8 Y :k։`4@֟kVJ賈b<$ Y%[skJ;9t2;ˣ}3bG՟֬c5Lh^('$Wȼc&@HuŽШ2xމqʙ+m =3噇|PoBr%L0=CVFgQMm ?C$hh2R?5;1 W=^ [XuH/#$b+ѷ!̵e]9 OMmD8e e!S: 5tjQdLf[<||̔D q _3u `fɸ\Z[`lwmvA賢7@33lcڿ*OZ:ա=? 4ZQ;zn59DB[v%ֳR ThjU7u\ɢJt2$սDLxi070/fqC 1rj=r]A:XdS~` e)V96ϊʅMm=H?k j~$CY:o맨#E;)G֋"N%uY $Tz#q+Ɍ.L&xvGwѠ2  ]TRCC>"6NHFggҳYo1V{WN+td\CH):} XJ$4f]3|ycRS0C-ǃ'xJu 8㱗 #UV]Hg9YFTl@J7l'WkzP%m5 O\NWrb|=ɀc>~pݱ$3'.|T8Hsv+j6jz6QVj.IXï I3h(ZcGU5ƄW`b[6QNV^M-FTݻZ)r-:0vwwr0~DSӨ<ħMF4NZ|^{xOCcXq&\2p%2cFM'y9J FP񗃿 gG0*Jv` :@՜POeyv t~YL D!(_U+*x >XgIW 4kI[YpiH:De֤$D5ՄB 5D@:7N +UFD"*gK@MȪ#rRt 09u6ֶ>i-Ƀ \r2ƣPQؖ jnoIjcvU=ȌpzMa7ʛee VΐP\Q}G%I1P=S uY4vE43%}Z]ڍa{j H}XH"z50VdKM|80| z|*],T[W]To[ޣtdj-zP]iZ>ϱTGm7x_`WGB}~V4ĥOҡ)Gq9kOulXc010{BE|dĞpxR+$p處j# u8\с3I.%T0-|߭# }[;r\FI+ nrYTG>󴒗7EA K1R=`[/>zCl%g#Uкb(NR&sȯHIu:kpw |;ȇ M&ip( Wn=4zp.%oVP!V !b1 U6t@JP^[@c8l'1i{Y7zT+؈םzKu)R4B><; gs[JKAAW2@ G SMixUAAԳVbs 0ՌA|r1S CvY}OC6¸];x zG¾?l4V/uˡݣ*tLXZo[.S¥-RBWe&IFFPeW[7fzda7s ]+*/C{P({ 83J8_mNOQ).8C QOFL̶7qrbA[nPiLV-U820naO!ZmzwжQ< 8ȶ3{F{S2μCv iLn+/}TC=5TiiSinl'B;_Fyiõ ,*gl$+&&iZu0pQ<@^giIlhw T:kn u$KM`bޏ/4u {N*CL.,nKMǣEMv wt lU>]9lJs-nX+ʭ+d.9i@֩N?^LrrmpS"%<1IPީXmxeo_4'{PWy8~FՔyۨMD,'$<(9$3>a{)jL4|cw_CWGw5Z1{vӢQ;d!|$V!:BDjl5z _Ké;bnso@\c|Js&HN{FF@y( HM Ρ*DTib$w{&b S{A^΀TlEF[D2i,[kDc=?zb|pWؠyVRgoI D<6eC-K3-d|.8eSSUZFbTRvV ZDng΃S)kHY.٢͐ؕg$+Wn* + IH(H-񚚭] RW1gü*nf?y9+Z ׹f3sϷ~H?`w 5`p6N-f$x2J>?Hz, KȦzb!jg֭_FKH']Xc= Q7G:xGY '#YB/~u(0]U8ȳ(S8;dH-IwCӅYUd<}d6/B!hv`AVњ=s^׈6U؍_ހ|(ϛn %iC(L1 Ew_EP CAYQ5 P~Y6}]Ի24H{ O-ZxK9C*%,}EǻPcfդ<*I!D1LDTDP= FJ@}'B25Vcmpʗ)AGRǀxPI̽A^<3;|AJ##㏒~.XGKObP[tU#d߬Q`gF a c0A#,]"14' 5|h}90вhuhHǧ~AH֋؀F$/赥Jhz"1Fx>N 9ډ% Cf'8\#!e "9M*Q+0Sv΢y0xgIN0DAlWi&>9HG[dcxe Oҵ;v"BjV٪!NI[\x}#.6mZ=7ۋU#- j\?[3=,% %xdX+rl2!pëԕFEYj/`UHE*!E!9ZG]I800p(gPnMD]S^9|Hkʤ n5#|dn?7cJXbLk _?`Q:r&܏lTbi`|}I~k_m&91m5kcԞc {7f sEG0:E^UA՟:˅ VX$H?DqvQ\gfJTZ, <od-賦{Gǝvר";mUw%yZ-)tj۩g3ވ5BV[x*Z “Xf"ە*\)*m]ɹ̏ev vEnnKyLrjF(ul^-bx")(ĺrJ`OslYg24=PL(d6:h_5sؗ-m'Yyc^F>m73Hy^: bΧ@}Y*YR!y_ s xsuZ.v"<:̝flA%WD}q2߁wwb&=gmک9ak d~XEJ΄#Q ]Rot#gL_Z5Z1 ]b KJbNʇ'X=e0|MPLi[pР 2^̎MTvkN/W;0c# CPlx TO,vA|az̙vm82货*^*[t\O{l}VU=L|?IG=^\؝rCԏ2C.Yievjmܛ9+} ΀0#OGiײLqɌH::iX`CKEZU0Hǵ].X V^2<Y(ZZ> ɧz&* f2zr3Aekk D|w恧 =jU1>+-er Bmn;NDFJm)4%LNSIh:El+z#j-vFXkg`W *P68IˮR]5fߎ>-B#Z$4P^Ok3o3R[qvjZZ+^ nN; a,NR]\o2(GgYЀ!V~P 2Si!haN6XwAT7H#i Չ r=/w61>?%`΄B^CH(!:%bLPkEW*IIKcOu ) ;bfJ"/C[M_ /ŠAڋ0JvgnWrhzڏ5:䅙FǡM7aՓ&ş\Anz^W~JN?bW*3 ܙEX%0Nz` >߇h^F8{|.6- ]ң/~ϑFzdZĉ;۵j,%jIߎFAڽ)z_1֝yri8M&*)>:pKo=EgZ#YnsUyx΅C Jew)Z(_(I- [ZYP3N EVΒP{6/>M? `>q02LoG=.hׇ-4+@Ve? BF]si2xƼaЫס3'+t}]$FRuZG&YZ*^BcPk9ۡJ(H~ YTb#K"XpQ*ؙC<ꕧ?_6@ n}ڤW uW ;FW HvZ߈Qi,d*N oiƒh2j)^6~([)6o*`>Cɢ5:+)@p1tS00VͼZ^`޸|0DžOT[{qIJX0Oុ#N=Jzawph`Q&7 ؼE_)jQ, q9|o6 hr~{5> f>)#f94LM(v~+=KYw1gaWK:VoF{>a5@n&{?Zj(R*HДkBg{K@λ릟Hjs[Uy*[&そ+Iۇ)I;bEqpT,rȜH": ~{?H[7y;j @|L-#f_Jpo{ & ̕:]R/Y#svi*zm)ɐG#1f?3dT łeE:F&} *5jK@&ʕdd78{o%Z ltY!BN@FU T//=jƒ9D,doG*Ko\ڪiZo?y21BU u\9&F 8i#FAHw$]2O*WU8j4>.$fE3fME EW j9xۙkyww!ӒL\V+8/3F)=B*2Mx$Z؝ F:R_5* P7=q4 W bܝ_K@ёeRwWՖO-3xAa)pHW<[.mΔepGMG-hMA| ;CRWY*LT@܄P_e&e3V#B29C!O#P쌫)xR߲#>,l|O*MƊa)W}T~]sߒݴnXŝǮaTlcYPGLshd[q4R'eAT+&ZwcivLFTOd@J޴IJG֍[K],hrg qB"\4@;ݎA7am dpYP^Yu`}Icw\Lw# 4@=;`Z??7Ur4j/ M`g(R}T׸;kj`cWςXӮ ~]|key\ ! YxU\MyipqǔwtH*i&. nx́z L&Lnk5 PіLHRɏx%NYc ^՗֊+F9+$bo%bB8Cs'cNmnS<$,old@Cg#v _8Mw  ':O12'Z)M~jQdho"9]˩|_aN-J'4̜X$y FTA? ^@A  %6>`| ty[ ڬ+ZG( D^ED$m '$y^Q }7AoF_Rg9)bHw=KPM~H1fo4 V>z;\J-Řn4654:N%}-O3|u*ӟڶSMrzGO r)0bYEj26*^eY5_\$~vmf|l኉.)e `[">X!kEZcbT K%s 󉵈`Ⱦ /{0=$N9hj6vNA:[!iMXO~ts 4lupuxb'.9&8xP0ͣϑb/oڞ!0 ?i-y;2^ oiK+B-8_0a' wZ!T[KcZ!)= u Q9iT~ l$Mi&#(%h4>)%%riq߿ɦuԀ"o:O;te/z6}r3LiJ(jNΜŗ':`dE.4Qilʍmqᅡ9dCDHHM穇pVxsH_*/y6rEϸ:H4jPJTQ('#ѥ0êS6﫣%#`t #2 =Ď@m?j͗DLt8hDxiقn6mjT 2'z@mH71:Zem]Fma@7s^mD.9=o1Zi@YtbB'ä`iu7}ZE0^wd߯CBuc~pS lK\˓|.6W }1yE/ TTh2r!16@G,z@yv7$~C'oyLpznh x12in7y>#<KHb-$S;J8ʷΕ*\=>jl ](v]hQwRM! Y_TO1GeiR5I'UlۓKqm{13 %CDLwme)Ҝ'}k)z_ sZ$LRK Sw%R 8;-a@2x-u$%oWS= corBbq(wfDVܵ%>J+ ]vCGW÷qaqsH5aYwQ.&mDPX'52}n$h8^O|G;ipKbY5Y{f*,O~8#"rNg؊%!1dFk!Ey o[%X18a%wkm;Q_hku=%kz-L]> 6ߠ?@okfp>ޑxBߍ&%i3H>^lݸ/3Q` skZRd$m̂hg5u?oNx7kl.3n))f Usyiѵĸf#(ƇXZUj (0XRɁҙqEԿ3b_!>[(B_&nvz?R>-%*dXfaw4=)o.qT]c*jUe_]C:^:*'b|LD2BrPWx 6|aa8dӉPd*{IZO]+T} 㟪Bcj&Yu@E'i3`Ed{?dH8p$8~b{go 0R&\QK?C~Kw zwN-lc ig>:dB*pJ^a( DR6rY7k9OwvY__;Vd a\^//_2i]j8W3&͉{oOPĎ-mw@v=Nf|ĵjgШfU. Fhw qt$3ؠ)` 7Oek6>arTO%byh\:,Ho2 n,=K?> e>.#MRly'Q}[L8OP1ZQX.eYʛSF\ '#v|:~cR< \C =@F<,psp/uf%|o1\Yo(KӌC78&<G _&AD8KȴpgBos揢 qHFDuC6[FXOUo Rzi|PtԆ:Ѡ)y[,ʗ@ibZ rw=8|0ޖ?l@d\2+ 1xaZ83 GC-b,ok?I5K+T<}Oa]'\b9'ӫr"xw}'_1l>YMsÙWRz̈́¸8+;tSWSY*QZ!"t؉ .GPMH<9P'/Ac>lhBr Ԥ`jUDdr:Y_- VdH?˕)xU{C1<)|Ϙ 2y5!NgYa4~MAf^v1Z6RlbT,%q$; {jq\et'WVܥ eQݻnpfX+_R6'ғ#;rƬdWqha9Q&V2_G\Ku;u,xfGu遐\| Rx1CgfAh{c2]Ha&*8|VviKhFԿ pyi hesbF d]MsZÙ&?ʟR@hEDXiw]iڌl2rzZkծZ[CmږwSz3Έfcz}M1rAP~#'{S,?J>JzԾ27}+ y }  G%wUoMOWs"opS^IO8Kb(!>78l}*Kh1Bzy){d,¿WLumL'DܴL,]7OBi:vOZE*C_jWՇMcHV_[mW䙁@5 땾Ȩ ZFҹZD2jH3'b kBB{BmSpԗ$z墴}q/ݫno]Fw&-$LGѽ1ȨKl`Rk& ܩbpO&۴ M`%{.[쮡q~ᦑf蛳U+3^,j٬lړ%OΨaUQR.E]EFrqM%T^^h3r>{(WohԄ9_`eiى۾ٚFQ;]M:r@ylk> C)peӃG_}-)ׅ=]ՐPi/6%N,a"%kV+YomS}|KEaϢYh6Ii[jxxBgp=q9M E.Towϫ՟CQZC\" g* m)i֛8&k8'ӵ) HJy%Is%f% EvrGx [ʄS("̤f)'Or?g\#Ncx̼Sgޟ16&V__?3U U/UӹVH\bkT?U" FCg@W[ |I ~\gNN pQJ 9ҕ},wtѹ"t"lɇDUցLoV8fXgq]]E鋙=2싡ʹNe_$͖3gj8`SN61!w5y*nMbruxۏf=$|MGO=6F$nXd)8'7[32n&ت0#"rx%}Uˏm]o4dQx3"ɔyrÄ́U/ϐPQ$NK/bmE_#Xcz*kYa8m4ZA sBg {Ak# /n1=q:xȻcKwJ>+X"*օ khL,-Vi,싈V'EH ;@ց̪^K^9{*¦Cên+_7ϐ &n@OJ ]q= >$#m5Oft= Xmh81(v_sj,LDteqhBBɥ4iaRgzP+n0rw _#m"P,D~% `;.o~Bw1%;>gwT9*%(X3nd*;Z,K\\ieZ ĤcYSOìc9øJ3~S\m?1n!F;eIR^S Is-ÜQ"K8W#+& YqSjTjnq~Bn[7Q uNQ`P-Ih0Hi쭕 G ~ S4ơt1ӷcnl]8x4uO -dXFr˞>73A.$_+:U4hHS4t-%%?}-7\J2W[Gs4t=s@cNTtoD#\'NV:T-)OKzjtZb `2%b!6)7"pho/fyãȄዙGj+ImjT#K1vLaAHD`HB!}jĞ@ZNf ՗CUT͓Ϫ-DB46Gn6y&AB/C>$` a! k ,MluxvJ1%͎Ad@zG S2뻴0w>t~fC!%2<]14F!] a&cKb*"v Ծ\=wߧ9~8gt軷6ʾ0採bs @2oY˙4e[GsiUQvInt*nY:#q~ĸ/IԎ*Y1Q!# 1hF -Dg {^<Uh?pyW Y4X;8e+x 4i2LuEI"PA_ryDKO\2aزP9qV 4:lM0ʺǵ?:6m =3;B{l]wK\Lr tZ B~^[U5$r|A9ycW tiO6U@1hawZS Qŏ8X l_`]\Y!軪cD0&#@^܅9d1+ yk9VvzrΔz RсuI2=4(Gc3Y 9^^f `D!87 /&yXE(}(vUzCZf  F&G.IH$ZKJZ ł&T\68S.w- ЌFOF 5A.\ ܍sb@J@!r'y/ݳO@vxAWČ1/};Y~f&"pFsϖcU`$_T pҥ-zCEn$EX,e.<'rr&tw@HRx_dORQώd'ˆAA4]tf_A~kw;*z-*<즄JOf!z= Mع,4J/4bSDm!=`>[;xUsMPӉhjݫ8ZK\=/Zl[@Zj ;JTցxS8IThmn?u)]gk}v̠X ۼ׾/z!o *N6B ){i1q}ΈҚ_E唫/SSfV ?4볉C_1xd0z]@Dߊֻ|o?s[<B!YBLrvLU. M|zGWJz/lq~߿ oQ1m)gXL |Suoz3}rx !a$ڎ1[|tqe:xRvsFyۦ2 u` 7spzgkh@oJkU]:$ L-7("Ca5^‡,9ww9XmtScSkz.ϒ7ұGWvw>WpDY-\TS夸w.q0kEmP=T$Mec o?d5U*KVz §(Rh 3º6UazeSUżzF辻zN*XRԥ>&&(E=/xvc %Sds7z[`]tF;y(?.uX.PIL\QR݅xPR6_TO"4|dodlI QuKn@ëDObE7mqRd5kt&X `PTA_æ$hKQ@wR% Ѭ䳤?4>Wd߰Zjl7qI"b OιrY`g6YarlWu~JS_Z;1daJztk$!f^ת0Y 6ckƷe&96؁/ŀd?oI m_$~%plbH $?T_z82!5K,򃣈G$e"F$_-|c+#pQb^;7ԹJq/hS V"g9tT&Y%ŢKR"u1 tMvmĹ݈'pi{g6@q$ gՁPF_ &հzM1nN(]M^Lk6x" =6`JOlfV`z"0D&Pˮ 6yGVjThz 1v*":$> 8.,Z-ւT`K\'ƜvY"|Sqf `zTLWTäuGcōcd* ) 9_'D8FPQ-N2~MSBYѲ04G5?hM#CL<5͓tm  6٩ė/ߦ+fZQfV9aZqfnLӷ!uTT"RLd%A;@vh.בP8hr q HQ x,zʣ>9-_ae`Nu!p{! $o٠բϲ[/߇IίѼCr/\:*q )¸(*i#R'>9pu/Nj_ۂ ;=Am&Uba( #שf"ULl~.:D)z;rf$|bXKd\:*!0($,*?;)Z뭍DX{+^1 7 l%hB3%%©;ԵB}' yk'1 ERUbX+iXOĭlY'lfcc)qz^Tye(q\IKsA[{{rlIXwl8T'ppY>蕴DirT) q2m&zl97ɕv-QkzTaJ&CBތ%+\;\\-#8ARypŅ5p3rٻ?^Êwm6:G:zlG8OlQyS7+AӅv2U>s,FH7jLQBzgI.C`7W Qm[Pz]( ,\pMX%șorɒ .VR8;Eȩo͐~mzlv1h1@|7.BOHk!*6NҌ }7Oލ6D!>:wŹh>Қ1;˸ d,FcD~xF]ouNU& 3̈́<|㏱ zQ͖^oԻF1L۞,9ќx(P\|]g;|`ۧ*0W>.t| QQJoy)E.oܮyB8Re2>wqOcٻ()nV4IsZR1j~$bwIßǡ6q8=d )\".?E{3ꔰY_'+>Vm͇:EJm_?ъqeR@p4Yw閘Ġ i,| #?C'`$P?BUL@[aj| Oob8c[,3tT˲KH$͖ڕo_;-CX'YF@΅!sîԩC':@+:)ϥuu[240+mNF7< ZeAT!OH_/i|T&aoK1`RFAF"2|S;+FkEb y7d \Ml 0DnwÂ~^Յ'jd-'$4.MIW˭V?``J'Y]m{Yg RL`nn'1bf{TNXHP9}cD~/eiofFmoӺT-Z~ ~O![՘c]/5j4ҹ[}I9N3FP\9l0|<܉渋*v"+!<Вy1*ˍ(D2}Q`!D!Kijڿ Ҏi2&<޶ӬhĠWiaʚf&WZ>(6 !+CegCr&)Au͘󈯺PWwo SiCRP[ }ʲ5+#^>);|2ewgzNh xfDbzY.R7&Xd 9Od ʮՊP^; &t>d#>_;"Ho7.&Pɰ^ أUs_:Sp@[>)Yq]Fqq}*HĤEˀuD4=`EC %͋Q[#Po0Q4JWN먨$RJ"AuQ~zj0yw`\fu»븊 Vb s<%+P qC]o]}Z)E'+f䰋N#11Kc]tġ ~,^ h;#d<[tl~t έ+N>͏nbKcjBư)3jnP񢺘x; aĜXGe89V#\Y@X˛:*HT;S<̢qAڵ,q"w ؽ]+m6ZvۇjìL[ʱX樗f32H 2]$}Yy_ia )ٞibέQ!0j%j4rذ^Ia;[s<"S[Qj.X#>8DzqNKs%ifrJdDK7OOG-&ѹ͕tI!GIT8ÂBDov(`;G#{%i~`(`j4Nd{v` G|[F`e2IޠncjOVIs NUv_nTqyc]'lYn FmhKir>vK-#}Gge¯oBȱMҏpDKhC@<0O$:ԯ }= 9v.~} xeϔ38# ӖHV[sICY楍pglJoFI|ʐ[թ`nKtFF/=U{#TU2LQ&z6j,˔++-^0M^%bqOqem A"S*޷#w8c景E^RGJA*7^u9joǻJ?'^0/;C90OkqlU E;;$e)o&6kA}G"^ voJX€ɘ[MW!OyՃ7H-ʥ4Q03Aj5;ʇhm"#҆<3<,\GxY i ȡĔN68g`xc yKƬ1^BDmȺktjRfPvln L!Ŕ@Á:A/x;芮¨JрUn86NG^bzG`iL?y_$ _:ҕbc41^?H(XT[:$q-v=Ćw`ȓ~2ʼ{2>CBga4s+ \#^8B@70K>jD؎^WkG z\`fS !fGtE-!c0q7 zZv05*77[b9 da$sx.ʒE,aZ%9a6'=8sSdܨr'}QE<;@dRFcP(:wB+nLDta\j2i^lQ7d{Ҕړ"%=mQifD{ zW.ubZm6f7"BpO#nQ~%4 L*RPP(XCn;0x{3O5s#\ehqNS:^b^\vqZa{Exf L0oAL{c+ͩΦW5[ǻjJ&oߒ"[sbn=0O&\$M4KwSDGsGK!ݚ v'aUIiHrV<+nseRU'r*@Pt 6 (~eZE:"ЌJ~KQɅyFY. +X[8kem4MLPҔf[kEjW ]7NdaT^"F8+BPTM0[ f?SnY3t΋@ug,qܧwVgnjDNWYqyn;[je'R>iٍ¦Tx{p7Qz;ΰzXCYtaj?q`~dUoU ׾S;#J s;/H"ej ؇f5c+RQ Um{ցe>{Qd 8(gu)cxTomgdkF4YE^~ԑQ;S3^3ۦǵw]FzZ eEdaJk*||wtF{hTul á\O :dΛ4,nEʝȦ?:'$.a#2!R׈Oթ)ZXFsT`N%H% V+?2eBi֟GPT0:eG_ŎW<αD IЦYC_qWn5w=*+{}{* !sRį9O)t]aqN#ss8pxGc|CV6χCJ50DzҩS;G"4zo]:%U)}.@RCe.G2S8~4b?p,E}l3U(N}xWU0c~:>Jmr%{6$ :CP)u9#~]SLf7Q!)n[{4Q 58'o[m9ueJ0 ?Ei7XZRK ]0 `Ȉ1tla4LJǔe0ݏ~^frʯKOJS%(uf/8ɥB] uf .icrW}dTT7ћGwa^EɊkL$q RteNhjٶˉU}λ uVW+041L脞RBdM9ZGQ/JIIt@Axа P jo-_Ot {-f0߁Kd=jK#3ЭZBzSo6d{@r"ݠSYE $d~Fys.ҚIeQp'3 B!9c'}7=7qNM71Wq-e]CG2,}|a>mGG}8Z8LҞNP%N' z5f&]n%A&b\/Л>ǧP;͝;bBH-E<=fO"J:r攅L}J~4hG—L~Ev Jh0 gG4)]s=bLh:o28>"õ{43g3k2/(֦$phafD%]v$" 37wXr`DH@^mdEoЬاc 3 b{_!$ =}xog.sLD pQA5^#P7M+蓥@VyiBhٕxL >91ӂ{60CvʪmR<3m߀MdƲ_gxYmHb2} ..nG5z!`QVr}6Iۧmbˊ 4?_߇8_H1G^NW$bdWI-)gFn q׷&A}4s$LΉZWDH*ءwԘp8j?\ J Kw >s2p<@_y fEWNr;* }Nr5}{xVyJc#//h cWU6l@Z:"$HnHDKkNAp]ki1GJ-0.whc¦u !7y^EHqZ[Z'܌A-6'Y^u%)>e@ҡsaݴeT sI㢔=ґqZcd'hOТ[qBUj2VKο!Q=G^1d@D`x 7jxъ2xImtXU%߸xT(j.* 9cr?n9Py518& vc6ේzPe絊UaPfWct"'鿷LD=Cb`k%5J"}:),T(2Cd>[$IV<:ㅲXf'Y-ЊN[Z^]{(Q 'T4k½w*߿`}y>Y#;4s>&&u!b Ұ:= 4ٺ*iPjُW!zji]c)e{)K%%N8(2q[BKlEN+8Q )/-|פ٨!XI//Ex<_>%'lDc]D;\x[ ITXgw׏]T6$.EC+!)Dọgggݦ@ ^& SA{oUƑn),r:rZVHL9qsM0&UROC=:;LN> UU•uo>ǻWvDW%G p;1ѫٲ-{M. ѭJ6n-M+(((D 5bn*,|[-sR0*(W AoGIWXpMrZ>fzp"i CI,@SF!0\wf+2#j?” V#$X O|ZE˛>U,-L\`@(\Il; ɣ2,E$O(Q *b֎4< ˯nw&Ӟ>-G[^b~.ez:'%\T Utj4g\LW9> U\*ŶkJ|^j6UI>r}xt4EÙa`?Qk@e- Su8RawǰfU^u{`26Tr2𫴫=E~MrǁY?VvYµ% tDe% =΂֌g*>;~]>%/JI; \` >r9DJ}X FzUmמy~m5BCJzxJSxqni2WV;1"o7NyCvJ>0Q(qr`r+ĪW,Z0F?!)Y%mdvmialpֺ\ԸZz>r I4gERv>:=#usIzgS0Ҍ0c;v&.w?o rIB. ]A(ej*CMf"$+- /G8#O м]~e Ւ Hz;&q؍d\`oNs2`3k3(6@9"M "KbW=92zRLM#¸hHW!5Ͱ~D}Otut,WDO:'%qRU\X ;Lv/H980# ӲwwN]V 5ZlZ}̲3 [ws9tF.ܩeg<2] ye݋5vcڍ)΋99i@'EL,潿f.W<2" +Y'<47//r4g@_lm;=6*/!09Y}Qc=^QX K_$p(GhKBCDeP0snRuPI" bGB:V3N?Xϑ{NFp5ߞx{vyHCtkqb>ث82x3DVƶ_mͰԿi?։hb9bi3~ef7nH,DvDV5ܶ Rگ$Trha+7qVA,;-șyNGhkLhe`gX6)&[eR yU;4<6n,^%kqF d7M%+JȦ'8rm Meګ=cLLڹّEc̭Iad ΅ȷnej26>Ӊp*@Şk*q`x ,رUS%{ |fwʲ͌l.##uI9mu53 _Z Rse"5^|P;) gZ8 &;] *I`-f6b{6i]IJlPymx;v{ԁpàυ7dtm) meR#ݹFJɺ7W24a)w$=i}NқkAfup .+G_;A}Ə{Ĩbm 鸝#}W8* äwfeQ]RJO+I;8 ?`@ؗ_>'?0dzia;RZ"+$d7rÖJߊ0Z`L BT|-SUD{FoV4&laM9jCƍP[|C.˲qui'\:p}!:C;>ouXY54 -rh^pn|mz 3•{k?κ?o# i\>"r =f2O x!={BuKўmJ}z 5X ;G0a Y:] )ϽEC\#jytY˷!O֐Zf6\ 3M 0Ps„ :>ޚtXr^a :@ gއj /Tݼ&|A56mPSF8[wnCdY;/#6yUG0݊V 篡GmUle@ 5^99h A}hsUm?S*;Y%CMˤ_Yn֣I Lg9_>a&lxHn/Dyۖ>yk7c xF८eEPiu(X J]\ Ps`PS0\Jh A0P'vm]d,SI,cPMcj! ؓO՝;R|$'6 }96NLmK:VU置&d D3O_€ drL?HKaxd>AՋ暵=Q=V/2ϹE Hr~ʃe 5X?#e.Rh?IL6>ѱ"gXZOۻ+af <' RpHLـ\uG+i?M2/3`_b؞^#Yٜȧ.(V| ﲽy{ـz 'GkD7冘'u+K^Cb }cl5;-볖N Y Y}W]su_l;yz!H='_d7*?徔&ihWڙa6aPE>Ե\4G e!}s|ЛʰjX6ŒoFR~v|a 84'/2:Y +$ѭ|3鱷Q>PRBz*?2]Crʯm{=nd2#V:\9Vh3anUhG2N B! SFlA`Ct (F$*Z"B\DO"QVoYh8빟M2YŪgMKOxK(hX]&2pA pC+(s5VHXނWMuGφFvO6DZDJ5@#YٿZXzÛ=i6 "O [{<~=W)E'v͌r4&d)'㚕Jna?DTd0(76sQJNߓ xw_7͵i2C+}+JR(T#"(iU3m FusneWՋѰB8Q`+) VC8q*wCSt>Q+}EQ@i2c/h[YX[,3\I6B)7<%+ӡ sm5LPlV F1`x7bݫ=rusY%<,dDoPY'W+Xb£}s>5 ajG0яr~Ӏ6,V!G97Û-^oX $]9222E kR'^l$oe;N,Ջ%W"lsDbk_n@ݢd9!mɂ4MsF9.pf'~A1cL{oȔ?vDiׄ5t7w/s!躷ejwvJuڶbՇrˠ[N)Ucܳ ˮ+\?=R.S IA̦@kcp y',EZ/i|EmV=:lHVzV~{,h͇ ]Jb˳]DB_r_T^(n"65GpǘʡH6/*O]!\37oɐ$WD3OuYC+(q+R= nJ G|tp˜gZ'τg V~F3Dl*v;ڮydG?";؅@B,_0S'+j7 \uZ>gw3GG+xi/9I9`qbݘKN(69avׯ§({T G clBA =+*p(PXdS|u/ѭ#9~FPZZK|EG7}lsUY .SUߋASFv{:jؒHƴD髳T0r ).ٍ^%8mI2g.jnhM )3G?K>!8 l}ά)MC)A)8!mb2M.:UZJ':f-Ll&9-񲙓r{~`S6ZE pȪ)&1SinM naW'qTtaJArk"fۉG9+B& /%'ׂv]=g_zoI5G;?:&v7R%R176f¾BjЊ1jVwD$5)B8pE?C4#GȘZDST)&+_gc(u2Uu,8'ܘ&D̴612Xi P*YDuA-=SĊFLã~TE:KzyZg[I b;G]ð{lPq8?\|8dja10G-DP: eܦY~Doc*^ݷl\٨Cxa-wK&?q8sq#49U bŷAQiJY8~/ O1T"zkú'A/"yhe/Ĵ`酫˓/yvLߊۂܙӜ܅jJ˥C{250Tƃ*` ^D)1.13[ LRx- у7כsBi* q2 jr`.ݖ;' m:ŋ(9V6(=Űpko^&YܵoeO4 XsZՉ/lCe}8|&'v\kev[F16uQ`2%w4vN~+p+-GK 1MFch]"JbZ?&L}V e$2Hu39BO$QZqzX)gBtp4xk`ЏD,!n;p t ;Q.͍ɇva{+q2L-K-o\\*?ᘙ7[A dnk7 CejR&qXmi7Ocvމ³ A!zP1L^ sE9} iv_uN!Um"3L/(")Y=#1XifR>ٖGzak:*Y%ӺMAPOs|\e7uļ؅y+dZCRw.EFRNla=` Yʹk~VNXg$"y$O:!VS(0s؝tJY*6Q/,zdvLRd+mYv#9sք~,hv:z|gc}{AuoUņ~gW ].~J ̙QYoɭxbE,q8$Mϲ\C b„qHZ6:Ϭ;Pfٍjր #s9>p [V3vPVQ7jB.tm Y|:Ơ߶e>%26b@_wC9[X,XKYg`bb;_]C2[j"EQ̾N泏bnB% e?o+\ʊ4!}bM1LyJͅ^qGk6W'wM|)Q;udf93/s?vOA46T<r:ę|$s J';TGEYϊp0R16::xq ,i=؟]̖m(ZY5۵uwFPu$Qp JAy wעq%b{[EviJxoӻ&sh[4}S#!8]g}@aH*>*<:}΅Y݆Yč"B/BhQL6zu==HaӤbI zFSO߸s#`qBIŠnAY5䳿sXĥ_jv:6lWzԍSFxDIc6J7evw;M$ >Bv~\>eR^5~n; **џGl?r*|y,]{vqG_#$.zs<~bp99pmBԱ@*]`6}.r0:9=5`mȤߠ pRB+3,LmhҋFKY&:+|(rf 0g%7D7!5Ǽ0l)PD= b4vw!=b-xOo$2uB9V.l\x o%3I]*mv!=`0Lmz[1.|{g#\h}c bpLhB\q ȀG}0~ 9*u{UwEJn%3trOR|4`׷%K bܜ4뛢}r!JQ!}Bt=n`׮JY(>[9pi<=6۰ďBo77 X7Q̸a*DhxX@'(YŹBtD Z=@9RI$ZLS4ƿ .vJtq5 '?Bč?lO}XΞeAm)vl5*oP턞/De'D^r+#+_}"/* WY" B yk+.hSK!8DNe RDiۄr ۦ*L- u ה?Dmk.٢DpG(>@ǶFZSӂ<<% mT1??0 [pq^/{'9ZD[ j}d' I \m㝷O)OZ*gO`0/.r)QXi>HWiZFu\'_۲9%X$yr]BD߽y͋񆣓%D;9DuMPcAýG6EGLtWS6hj/!;m0Rꩡ|9ς̗4JvUl_J˦UwL~|*̒>-X[ U79RBͳP͌x!aqCfY $yg(A~X c_jwˁ|%SyԳ8((]Tfւ@X3,K7Ok3]CPL7dT%eH('é*F֔9\~--`̞)A~ 0,1Zn̽BQV|([{dQ\1C8# <ϖG/9/b GHo:F\m$m5W&K'8:;a#/6:!J 4\5,kB M"ZKꁜnԯgNPq.d9_i,~Gdѡ:ƎGLIA9!ėd] "y I[E*pc07(5 3ejousļբ}Wd+kjFԅD )#wj }mK-m{o#UL'BRf,}//, DLdD&Y8x" hE:"괡$DX.VivtK`f,:zosM&Gx-Np[ii/yܧwnf*}uue/`$ѨajV{VZgW[,$oRPQtFJX=O%XIED.:-$9:+5^< ^cmz᭨>GPP ,K%\RZa~4:Cѭ tog~BYR/ˁ40n󬰧r5 m\yY- HyJrrO5A#`\05L쎿6Lpo;M@< 'k^rfw9@J8=7ݹ@nD$vF㍀ԈrRtqz*=30NNqu#xړa՚wkYq1AM|Ey#a7ޢ $1G) :&d= 燍Q".jE344 +*m':',< I0t!L!ڤ{G*`*bWEػP~I}LL0{,4 %ȷGH\,S`O @!OB=x+yev?~?{T$_X_|%.5y_ 11 $ j@*R{3-: &gu2dAM1Z.rndce( uD`n6W_'!DMlLUԑ엧vީ EM^Uj78/z'Lmγ72αw#@T+^IÂ(ە rue6W ~Jhkj9q<{`UR.M]KnL_GHNļl9#6'H|!u0a/:x-^.De,,i}lI.+ 6Oy;sʶڼLV-oE/lyp%?gN?6!+P8)v_9ҔI2u.M)¼>8sMPUL ep5!X5Sи|!f,9gہ4D! QWW9kJ#Ը-xEvo_٧@E>3╀o5g؂#(ԥJkjj-$ЯorV]TlV*}^_^d*+i` D oGg_Ͻo9RF&jE뛋WIUƿ&$j{nzM66DD}3 fZ8tМw?~n/Pa|#fLb5Dpik0^ZPGaZgYPZjA%IQ@}ǫ3q7` P3ҹ ZV Un[0Nk*q9?ϭ5n%]C y;<-8+D헸"aS>e5lm w]@E/~t y] Nୁ8!EVeRGl&+\b,l\hZ4d.4Ou@s*7 b/b^ϥ4Q$ax纾eFwx0jɂ2^Hg^8n fQśD4GmQNODR3h|6mJbe01θRm By1 RR5]@&k yeh>/z[Lp3>.t/LҨ*ࡑt>pyrqxC梳b A Ro:@^95a ofv',N)\t<4ɛT0Hk&ը>f& B”"E5i{7*sPśE>ew菓ŪGhG[vٖ|GGvVl֠'%>ztJzQbʫZAj˕/`<~ĊpΤd+~i _Dd;VJRЉ,K2dZt"^ %XM|/ShT+B:db5x"Qh>U>TC)J\ɾ~U!u[4I.Ԝ=\D]'~I|`t%OTwtY7n5s:R(C4a"vJ8Dp34D,~%N1JE@6{mE 4v Cgb؟zA*Frht#|@\}<똬DLlIhQIu uw*DYn\ ϴaaDlnPw/+Lu; S "0>R?zz;@zzp=MOJC]F9Rc@4{ -.{,TYעRc=S ]>i[9 汼KZaIٝ{l+`r׸#q77um8_޵PZ cZa<=i%m=^WBk§dѧ5Og8H{2`zc땳rSFqp@Kd_/4vM)zʃMreƗ!pueGʈ"ZU" l.]Y2z *1[PZzq~Zʮ32U3@pje ʓ(4Ji 4 YleiIM#juBJKTċ8\QP\2c7jG*$+L:jc2A"96qao~#DA˙}T M[O`_TLR O]WA&caE-LV?.aR4n">'6aJQQ>}4eZc{~,#rjɽȭ3لPs *~?Mnfjܪ9pp.WYye~PzPmB|6!㓵^Cޏ#sRbe/v`;RY|m"h* = m1-` l9rq7xw*8$nq}C!U(iYTP~l7gBmg2JUeٱ7cuŒb1NG|VesGv"bd6t#.8!Z: aqTXp׮{t|+g&Du0]dpGrz @z?CV.Wgoþ+HTs: Vp]!KTn2mk17ы}|(-S' (#"sɫTI^<].W Pv3+e@g ka,A\ScrāpJKI:#ljusfVGǹ1Oec Ƿ+Y|}7 퓿 rRk.;2>Qs,h9yz*l$?"Inv L 0:5hSh8-f~_~WaZd RmHW75[;G iUަQsWU6ݐMt4:(0wﲈ&ӻ]ste‘g^Qқ\O'7'i=Ii5qㄴ3Yve2`J; ,cخ - }l+|"Ρjӈ02d%ڣԕe1OK#186W /8[0@RC㚓-Y8q-z,[+psPKly,fX+^OPG\H-j]t,恺kpݹ#0d}.=V˾DzM #=;<~,TfJOZHhIGqG<#&,4y U75R؅+b-y,^sw 8)y\G1+T9{Vg;rOem.#y$ˣs#D*EFyNNo$qRE80X(Ga(C7 cZ@uuޚʈiEn HLUᔶ (5^?g{w j]7e[:a]8'T>r]@a( bzEΕڑ|-٤]I"fTn Zv5 IN)s.-{Q)2#މev.g0nGTh8x+:φ\wh!E 91`bIR/ѹTc 1E)}Q$өu ;n(D$_ԡaXo UaqByg f:XkxʽA)Il5XNU;F1gWfX衹jX5(sG8aᏺb.xHzeuֲcM[OӐw 2[/n)D5.ΙHH^ax y Buf+켐@z-Ph{ȦGh'?L&?3|h *A oJSg-`&iB'Zu6"ʍxj'||fOU0]K8B:Nv7ManƈSTv~qړEߛf`o[m2OCr9 |FR^!Wdz)n;GvP=o:yZi쳪1@^*4,f (4TK4z@Jr$O ,0ѯWg| Z #|Q/R^cL(@̺#h;iIwNƾLCs \poM-m9ǟڄA15%Z3P_o*$]"\wSG kk C(Mkt9\W#ǟ@D?6" LްZGPK6Xyr5QZy΁>@jc_ab +eG'?~ 6c,)o'l*nת+N 5af"'SmZ)BN2s6wrrY3iuDmz_G@zɅMI6FXQbw#LDTSePD$H*uAŸV W{[nɘt;%@%JҦ-`-z}' bYLDR^^3Ix^|Butȱ& OnVOI!KtMGϽ@=R:ۉH_vR,$$O\l9ϏPz4P I5fݼ)ꦤ*H4R\3JSW!y Ip[OkENEC|$ ֕EN"]נQ1 JnnqPIKiJ.X+4b`^-6׮kyVvAܢ KLnMv^h%ܯN Fr˷`jd &uk)c|U' qT&shopN {C,o vb nbf|9܌E}wwKjU\2ՍP4J*8XmuT!־ia.APXbOP6 I"|Yr]X(:xZۮD+ZgX=u\a{Y7X9״gVWr]wR˔bR?`gwwdneL3Ij$}|Z"H`|JV|U7$ "R;6-\}hW p6Ҫcro 8 ׌puc"yY8oG؍ΔB3ϗ?y#7x23JN =nWn.?$) t@m͋ۖ\Sn1k#؇-bekr%UII`Ag\rBqX#(gK]SpLsٟ4YROW,Ib5u4 0H\ CZ,eUfR#2=J>sʢsN9SCUmP FoD͸P}&'qFMn"j0 UO~I 4_7rNMhqIZOLKTH طdmIGW2mjVY[tg@54 }*DS|uyX1֊Sgb_\sNN "4r(w-'#DZ[* BՈdm F8l ]14Lc+}yQBy>:̹GeFH:. '[H*$Z>gv1 Ҳˈ㘶 +_]Lj$Vj!Cl7gPy@o7H^İ| 1:U`P_xVhc? ɒfh,ɨReG\HHnjGB#N{~NyalϖHRS E'}aV<\UH]!K=LЂOzϲ32I\ K#quU tgEB$Np /$G&Z9`1/}֖(?3\ad(b|` Y,ӕ8ݴ^𗍪|،&ʌ.*eE](4kdM~fZI|E=`5}sO K!Y9WK yX Jހa:afAVe#$2D9H]/ |B<ȁ55=G5K?Zo`3InIg'uYVfT6'CEQɰ|)?4NS|UɪqGMmȚ*R\5:Ѧ:ka#[C:'+%Dz6묝<,k@FObmaHFʏBى, tljm2}jH%93t3'\(Y>j[rqpw }ᐹ67*&W.gCIA%K.^S2MsFv4'5(i\,/`ht,#V"^0$%)Ty"KP;k?VM௾#ÇC`Zf4³-kw) l> !RH]cv7|8XXʋw=n< iSe X.ƥ''%DIvC*D|+xcF(ɢ}J#Dә@ ͮwW5dgW2}47U} ˔y;@{QNPW慎W"){{]A2|䇣)!~'"5 5&drӍNޥZsgz){g~G!YKv:vc:Or2qFF"#Pqt5h_^Ӈ26-㽹a*P*GJ;4Ѫtsۚh62[?KW6DLn̠] PŖCs20$}> e\N^ 'MD/= n; i+ƢI\g5fU2BԦSwoST=f?KZ<;O³faҜb 6! Q)JoL+JP d PcHLgRTg$$ "*Ug6$/0.%S Ww]W^+S'qc +'~?>sxzOfΜzT҆RVSӪ9grS-kݒ~TSf?`+Џ;QZ`nXO3 RZK"Yέv/jp -*=~ Q=aK#sŗ!`iyIݸ_G @UX;6zZQ |B༉TZctj!4}9+F3ŞzVK 3Lj%PYdd95Y.hK٘`'ʶra["‰sOIbE# ;9õ(Aßtg%i(><-УS|uOlZHlk'I#^-Wv4!F\$\^?8 •39@CCy.?-VKUr|*Y7!Aܾ&P>uWNR̚ka!8a|*R*cAr֊8ѻVF&Ul@3sdm6e3bfuzHdVcQ8<#EFB ѐ۲PcRh%N8}wgFg$kb2g}%6m&7٧ `-xSNw|%[<ũ,h σN_^$<#oZ׿Ұȥ9C7'ylZ≞a`:gW$CUG48a)^#6܅s,ex" dM} ڰd/Pg"=561f]2&Ps> "R$]s+38Աuo(ޙ`u~VNK4–ֆ^xZ-;eCv}M'/<ײszRFeЌ6حt`X#oժA@4߉fs*"Y0ǐMz0rTHI!>`TZ^_X߀ǘ9n}hD7P<. Xi*(pQai7Sm~8_xVrQp3ƲHG0L Ï**^m<$ pQ3N^h`,YOmDt^by[CMޘ;T/F).9}"0f^f58qp->᫓9W㚕GI1tv] i(Ws.V;vD Vy͛6]"ͼ%z%hZ^XKJ4t~YjA{ɹ6*T8HLvR ad;7Dz? Tw=D廳0h4ύ#C$_:zq/z)2N9M240g h@&NJ8մ&xv0,4vVgJM[n3i,E2S]5(`-IM]<]y"ܿ~¨Ng'mVfQX͆ ATuYvrrz26dn[of=?s<W `qg%AN `̠Xܽ.= ]yxcˮQhɪdw֚".}?zDth<&$fmݤ n=,6gݼCT*WAGЎ +vs^D51Tb&h=N9F(VhIK^ r_Oa&#,&-E%P H*@Z2jG9ƭBl@|CG#w<U+/F,~:F{qx˪qHa)+;Oc`ハ=ψ>fցKn^qQRTAp2|n]^Q٠qWbang]ulow_++.k(`TchW2{ o֬@Ix |{_LqCo/ҹ@)ja%STu "lODZ ;; H& K̫, گ2N7T<ʙİq"J Ϯ'NwtNu^jixQmSSrLJHo _2x&VƹJϨ K']WB ~1'zbGec6ֳꉀcV#.WEH_֓ML یxTv嵉:7WHNF+],6`/8 %IvWB`|.esNU F^r˥ V7AGTqbjSD\N(ӬH<_!N+H!0Vl[G"\g i. kQ@n> / YkuuD-\U`控ч0$?׽N]M;`j igSb>`) 5i}?31:jd[@ 8cT%}X_1B{>جY%.7lV + yvT6+uGa`ēt#$'B|>0*Hfz9zv ORo c%>gjlp&UDa O̹ؕŠ!)[W @#ZԸ^ê4<^n mW^ybnuab6w jZ 1)٪izGT|ܬX5PzLf`%E9 %}x[KSw'-X I{Tհs0Z tgAHV'PAXNZZ+CCȕОmHMn]!iKq2%u3B:bVY108V# H{Re45&xXB,)-9Qw3_n/[n\%3_ %a+x)1?cowH!Iq6~p.E$ȩW 1oPQ)0F5x8:Mh[X8jI ,'Xh ڂ8Kh7s8 9pa~-ECbW#__ im-!\m:N@w!JtmP[.rEDe'-ٖe$Z i$`=Wǂ@|c%86|vlk7t~^&R+ ٩ CgԐmg&Yuqf| Th?˿|nkk цw~8 ؊vgO'Л&IRa*[e7xgIp'ʂH X L:ࡁ>nDD~h.4mEz98J6x1 5;#pnQ& #]`#Nve;%Kzܸe+s2K1Y:tx?gZnc~~ ~X#r+svՎ[>GOp?&.9(DEAcE.󑐷K)~;:l_)wLn^B* <)v6<ԧ.,zQWS^g[WPO$478y;wܡ:9/8w. AN$M<Y'޺-(zF}Ę#bJ_i@~Iiw?B NQ*C]~>)tnZt M//V֢FC ZS^ 7{y5z-|^WJ4'7)M3.;B YӢKZak!Y7 W]饜`O7͵߶Eݸʥ7 #v1Tn;W靛QWiB $2Ya[fC  #@`E\ŻS[ȐT%PTr~R$#D>Com1^s3ZgH1Qi!:5$) k~XX|٩r(٘ "Xm{| lH-@#2MdRJn=WF+ý=FRфvPTxGZ/'5+dco{}PgcO9f3V|sE۶wR}[RR}aͶ~xc\d'`v0ta@60: euxlM$.<rmD(f{Sk=K! M_niEJjYpt"2qxL|ڞaN'-O1ua)YȞG:Gvzo sI]Rr2iR 4 $q- ̙

e<&Sv4I - BV\[0x%}T:x0_vQ'U=f]g BE% ަ)IZim/$?Ji *]n;N"2.=E%)4`ѭkɡ&G8ϭe֋B0oG=V&ID[`U"#@yX&}M 5]w;Zq }]Ƿcr){(qsPOV4f p¦DoypgbĚ0e]0 áDOuB8zL女͕ L "C6Ejo7׫z|BwMgg*_j>-%hoH2o+BwcZ8GI-H 0K$&׿'ؤpFYlQe ]q--b.SC[ Ƙk朰f7Qp%A_D%IE!SʉluAP]Aצ1,-5M5~p~+ XE`>-viaFݳ6,7dbZ91oɆԈWƟjHw6/,  _{L i}Xqȕ{ܪAILrQJ y3ccUI -X\=vt؂ N#mIh5'eGdJ C[%˻Xp4ʿ{b%MBoE߉xE9rsSW.RE!}GؙGIlTNغ8;mEଌ7?CԹq)CAo{ RGq'Ğj|t8Q,HQ=uIӷU#s5 %k Ί0E:d$*k休8Y ʥL i\2PQS@kAӖz6kQn8+N.B8H0I2IK x6t>36Anj\/Źi>!!ۚCDqY<{v Q=r =B;]CONgŪ9ˌҮ#1eC(-<$*kz@La($wbNsY94Լ{7>ojqΘ-D'C=`m6䏥l9q͎X\/0Tk(ߚd[X/-FRՖ+W½9w6✁"/k)o,@`5F4#`&mR.i Zh_L/jV5j9#i_[vD +tO RwA0B\*.g S U#C+44ޔ:@+XF@HGq@ $ }o¸ժkcsk-EXn KNgl1GQ{]k,VVi?7l `48q܋j!X 4LnuRGm]h>.='5Zk #*("`5њK3+;s{Պ=ոt³b%yEck |z-JA,fIip`h ϊ.HDCJ4(F?0^҂hi0\-ސD w(y(@|=A>0Yn]ZniNz)5Hsޅ*$Gp]`:sd;]{Lp+p}Zz4Ln$̋豹 Fj@606깑[ ~QS *\ $ی+m>etF.oP9oZuHH;,¬2$k,x̷$6,uOVQaa\A\띆;g=mu㚪qo{}Lgބm],T2CP[pߎ46_8I+=C3W[q-cDA/6_@øqu8ha1XHijkJ G>. v s֛ >*[?@{}j9~dTG*wSrW^}Ǡ_Wsht~b_3 9崖}ai f:'Z' q%l3z/">wS Rqy6gi]%l XjרqFU= dޕ e<8;kE$S= CZtOmNdX[7ȮrYy&[K ʘ.H 3+8e{Q%$d`6S-"tV) Hr쨂B ̟tö}m_zRyY?M$扫ęT KICȓ>S*$UV&? ;t͕wQ :ǙiBgV (kQb^B,$bG8hT)&5lhnz0YcDQ{NS)+6R8Z">\tG*`\^FtT&Lzm\S,S*'[ ZWoci`:ahC7KɛU#.yz-PYcOm՟ >16 HFN8}1lAWV0 ޤ>`p"ڵ);Y).r\gq۝N%p5 MnsF`ġ3i ؏ܯϷa7CX %˖b<DiRuϑjf7L56Ą5`!k /pN3In+Ͻ-\^n(GLDQvQ1'@~$&u[*2.U֌ Aj8F̢lyBe_CY5Y@7N7"ȩ!u "Gh=n!'P`͊% Q׶p.i+0K~$ή~kM>kӍƢm)O!-*?Z9d//h\"F]B6;1i5hʗ_ + A&!`+K{nYhi"TҥP_!3&T"dbs+8$a3{sZEg138FS{QXWKdpّ7Դ`9,%BjdDإH+ v~ mrBeJ]6p$5Q4ysWǭX׶6$s^ckQ= +"`zȓӿs |ktץ.uc;A0ݵ.?0 E§4nTܗ7MJ+S WAEnP|) M3^VpVpE"M?Dzu:w5 Y;6~|UHf2H6Bn1gX̮TUIҵo!?Ptpz奦>KP8y fH.fkSXr)}VJP]ˀTL(Lx#=YRW\OA''zt}xKp?Q+j{cEs-47D}}in(cE?'oNM?|Z H sr\L=`ƇȆB֓aUI67Qy<24>A{Nb1H)O3;1"^27rA\fVIdE(U]-7$A%XzWa@ Ν]9?eu{1ݪc4`"dˮH LrP]9eD{՜!~Gٸ?~m^HE+ec,,d}4_fGxH'(~Nvӡ,Qq+ 0G<9%uErQ)Fh#q5~ 4AA=83UyX:?QiD;D+lj͕ .VOhXвPQR)nۡKRVEQֵ3LH_/)6C%O1iLܪcTqq%z:pm\,s =Q9`ɠ.P::!VH@xp$NZ e*аRb Ycavz2Z =Q)V67neT),/Hi9s&r/8{bh jca9S(LDxRR2<L%1&wa_xj뭍xJ.TzNbF' /QLJCmXnjk`/\Ԝ gsiL4ݖJ萈M>,]ГD\v9nCτIä3lT&"5X3g籃g<5*r}pK<(54s[㽺Ļ鑆ϸO MtPI7Nڎ\P3;hlcGCwFKt5)K&t$6R EKC LE9%TOyVgG,0rh"OM{C?\e]&;')9}wؤɹϓ;/ C@]b0ӁC./ G m,pWp9nZ1v Wx`q}<!G [ffQJ$4W',BY >qa ?}bWMӧ[[I̦;Ş'l8+mQ} êH3NCa}jݬ N¸Rn'sY&#E"|IiAHy2n@ w %9P^=CL<*Lh1 +0NwQZ0U!dRyS*)D.<!-2_t P1}18;GORY_-ئVbk'/#dYf3@i͊쁪\#eXOkSdznyD@.QyXL +E~#ɤַcMP7kCrۘdv}&ZA"t:&;&ía pC @Y8PHEa}*pL Z$>|!;#%ci!e9QeENɩ9Q;]u%*O@ 4z-c06i92[ЍѝZ.“5(Hnv|..#j*~La^\†LB_tyIJZH8c YsЩ[#aWU|/ C/8f F!" B"1\|h,xOzWQ_*e 3 IV!&CMeR~sKCb,t,BpZR[eHeH2}L2oT^ԍ5_>$Փ{{Wqpb-J*%E^kSm^_NT;X_N.69.4bk[a:oZm%k.S8Gm ͌#w{S`#Q@U#".d˂S:7x!|ۙJˬ##KP%g@%Wf}#&`F;&kMHJVML]i;ToBްËӰkS?5J]3?%G;nwL[.!%yR.sIRLacʊCּ,a((2H?ơ[tĉ'|/bT Sqa\:kʥzDul?ĪQp`&{aVuޗ~ޅ˖eu9_K#?OlVlp,f`^;x IcO~GOڥEjهuy{ eԈKlX1ϝ$uOk]MpSU.Epl@5|&,8\YIl, A7d,;ZktӰ|]XnBi^B˽q81 n9i'\^.Ypopw)qᯄ޻!8[smMz,nFZG"(V &I6m( C+!u{t0wBb?R- W]DV6bOiZO/o #{.IMCVlǷOnI$y5g{qs]A4#EyO*,Se]2/x=LΕ*2&qO0ZMD淡Sn&+cu2WFH3~%YR,axYIYuoѥn6MpDpsv` ^ XH?QcB:0Kraz !h]4`U빪ȎLƉJs6zψxK:q9+E"?, r!xZD9A/Łn_">>0@:W2-H6,wT޴-sx9( u8CE%Qsm{ )TC`~r7u[qq)쬪Nꭀ5lQWdɨ]HOtR!E>}#R7Q|wKN93EVLv,'a@~- n) KKUI I7Β.ǵ8BA>pª"n5|w|m{ YDڒ&4i N/Zjn|r4 ^8ġG/왨J+#}WnϬIDPhJENs+jx<GP] ȸ"Ṛ լTNO$.,bq,u˶5ɺW3b:;x@" A(־ K h7(IѤ7+c#&T'ulJt %p;;vD뻝09h/%SdG~HR^PJ-L!ጰ2ܴ9 )#zfra p |UeMIU1~P^wT*XIZK(4CbÌV[g'<3|Ԧs@ +j 6b߿lO(S* Zx E:pȚx5-PKj`+TC9^w=fxUn3K[;|[b!~KӀdi3}NNav#@fӠa*&RPU;eL*A֜{7W?DIR)`❷U<}`cy 栔=47Zc1N8lJA?40GH2_yP$)-55>5t#/LGsג<8Bis}'f)Õ}^yanI$*cWb 5CpĒ~0F "1 qzGsb5 tLf.΍[3Jd,π0%c:#|4xR$K96IÙ c+m( M }cD6y V]۳RkvvƩhNb5 $IHRD?Hy! A#j ~qۂ tKONl)ڡW]YK;=u"0?jr6RFF2] uN"Gc  tbf -ԍ^"C3L:L[k~u{jL"h/Rz˒OeY-UZ}sA:,'Lf&tU@ݴMƚa3Wd!!lQDybds~,,bbymaTIpz ;fx-ٿ=x 3Bf}̀}_ިU%t".#D>M a5[#hˍ7Ȗ]w䖞.2V+ Zx^Ej P6!boZxwn窕ҁ& h:T:(.5mg@ѿKvLtш:`g0ݗ2@Bqډ`Xk!/.6XT ?}NnUy (zoytQydFRǬV.{<7[BQhx%5 k-KbGѰL&T}q?쾟AJD|~vʲ͸Cl6"gͦ@'_ofĺ@^wJ_s5ecJYFP[[$i'/[_U3# 8Z Y{,{3D&ge]U˥%>7M@l,EYx*Cʸ'vɟ!gӪ9#:e˹,5]Vl:kPIBڸܚWmlxGO(J-!^5_>鶂T17 P!z -Jm;%&]nkDz|'-1)-Q)lIEF:gzޚе%# We] J,}â0(ܩh\C#0b (#K`yG8wș˸EҕG쁝 8+<.RE 0V,}4^|4U1&FG'_ Y5$:DF%Kᮁ\'.t[]M/Ux't h&"5*P+zHbPuUQS89 ]P Ju2>TZ FJu]-Ys'75Db:y7u vqyx3w~3kK/esޤG♨#m{JQZ3 ^We4zN`PIYZe ~$<##  @)! x|8)R+HExo) BUK T]?O iY:7̐7mlCa*Wl5[&3ZoPYyYCT`>Y먳;) p%f|oeSH7zXj2O;&ܢ trl:6S1LyVIcR\5^>75eʮw4/J9= R(g(0_b,#6:ICo7/ u}f "lwlG⧷Y0Fѧ9gPp5uxQ:+R,Qo- 9=_*K`ZC{9|\sJ0S!y9Sl`)?Wp%ogWZ=WtRW ]rd'Y!lu-'J6 <77Ku՜4AUR8_(o*huH-N5 6rm&bI!3+43+׏?)nGrtJ*uIvnalE-XY0 ag:4U'm9DE[[DOIVw"e y =f_Wکn2ߠ*4=/̗ N{  L/,5 E,Y}c;ouHdl1y4k@A1H &-#7>p 2h&jHq/m@9~CfZg$$eLy`SN)z]g8pypӛ2)ݧ)4W>]Ty6o][?#,2^sg$Omeih+ ?9GA( xV$E,|M"(-cu~8FfVZKW.6T(QiDx[6 o,{X&m5nnD~EdY4L˒O^Jt[P>t@kbc9i q`|Pz3tx{23+T-IƿNjjBP}SѪ3N"$qr#cd}{Uc\VL{ᤇx9%2q6OHE0FP;UfDqo^t*cZh|"k_sX}x"雵{>tTEN>yu:~L~1#T:{ '7~<#i2.՛u8*ACyqgMK03;/~ /iWn E2i]aȸHxuz%gsʦusGt7K*lt\ZW]hǠCe*;/'ZD=vxE 7Ai2>X7"Ӽ){UW.=6y= u{9޵Jaq%^l؃K WdĬ^:*EC{qr|ދhJ^g 96J/) $p֐\op MN8k*}R52%-g+"f˧T+q͹*xa#av/@ք`ZBNxoBc<'жM@=f}EQr[YAǘtZTe҈g1ECma?z^80uEX9Q'Mə1#⫋gU |uy>7c~O2LD臩* E=d_8)( m|+n_oBU: ٻRRQhQ9GPK^`-*IT_@ K#mWW_B(Ȃ<3W`7W(s_s\t u"ǣO՘ Mym>)*y3LN|Qӈ߇GB 8>\])A!dܸCf)Erͭ*vuD3eFKQy1x.OX5\jpYtl_ma8׆~\d:M#ٳ=pqQVw?"Y=aз^e'yҚz/]V& "ߘNEo.h&@:r]>K6y1tn7$_ą}I9+e6#z?A5^w.Oj^W/ptQŴ݇N^ZU󫅩>4y!-*2pu-*ꊖ.c뗤4DTWqΎ'|tIy *ז~/al*՟i/xD!EB0jWmOdꃈ`Stp}ь^gYVBx|dW!X" ]s&`Mo Y34}PtCHwYiY҂T.PVWh|n whJ e3e]/jHvfBbjFm\,S:r տo0+47bQ 'ޓq7k V$X?)>ѲFY:kT樨1} Gd| sSQgc (}TB 9NT" ɫO_AfkHtWut)^;k%jYelX`X$}+JH=>&n!8"˜8j *aŻ@^r HfnܛP_1$IɍH8?C˹L}6|Rglo:A@O7YQ=aAvQ7FMT-X P;W RlەQC6PYCEktljN +ZqYbsf}` I\Kӣ9Vq*mGUJwQ&׿+xId6M'.j\ed|䇮1k@lO0HT[ֲI4CE}ʛϷ 6) -觬Hq :O;*'#Mjie@r|2 9{ EDoGR?R&*SfB`hj\>zo=2覵c Lphߞe;"Qq`;11+ń!]SvM'lz]D8H^䌲^PҨu}r]+u/!XW #|ad yt( GxViB"AOjtj:r]w6 ڑUTvcaIKG5n+t,KG9.xX[8P?Ҳ=C̀/1Q`11p)k& cm@AH\C9rj7S*\/NmU>7<;]&txa5\GG.M}bh\q&.o0"K2\[j ;0F{\q"'|ދysLj,N~+pڮjvQ`Z7 =ϫJrӎ&״k&Zsm䃧d (>2|b0ђe0ߕnAaSkLVWUiXQ"oI.a=_!V[2{qê9I_RpF9)E灟7T@azZ+ QivOOs0aal'`&oT/ftTF'oM)_V99S1 đnZta0Ǝ-]$队?TvvN{gu <anhFV,ǥ,asKs`7clN&'á9н(2~J%lzF7 #3p~d";y$5S%%@+wfxF$_ʊt՘L.57*5ƶ$ y¾XI?0Gݩr^}^B3HO S!q2 o0b`DQqQiB;L4|5\1_<m9] C BIҦ*_NH,H$ jD؟ Vb{T:בqQ;H*vLA.O[Uya8SyERzFed|~pZqeSxʏ:Pl=sZۗ:wR˻?Ajz*Bi?̎D@c߆x,cdg:a fɖ虜Aǡ~)X]a $RH:md%bzU_0z>/.0n)+d7.zClKs84H潧{-$cpE]3G&kI#[-|8ț': r'3Lxn;R}X!=4K RZ(1Z h`yM (犭LOȩ\u!2UHQR4ڼO TR{pPi!4,0$1h|pBWhjva$Y}iBc=XRK$8؟PU[@㌽Z1JUN 3*t߮J7*1,f[)B=% nty|"[^ū'CrEJ؉"8lNONw2ݶBnjeW͙!9^Q)(*Q{J?g.ƻ&%584:rI?ֵU q%BP@{2Kd.!.&;?,;7):Tq`en>&]S $gYmD4a$9AvOD/ !ieHi#:CD)+%$lv_rd*2e殰G=WLX*b y$Wh@[-L.f"-:e?->*<3@"@jãruwAm;}w<Kۼlܣ,&26aDbx{֍(xE[Iаe /Q瞞2\f:+UkF I`p\~"蘁B\䢤 ]v᠊ ɗ̰^>BB;g&ԋ|> 7䠓P1ޱp4ym ~^rЗM Z15H(7F!oM}N+vƻ+z\6JK኷vt\lLB&C+P0(S&|xǀ1Co;Zo-Z{ylm!KTIZ?z;SMRXa߅ގtJ%d:@SR䲟;cMqnnaT':ZE%7S&%h1]xj3St۴@C cU>tvXX5hLOW4D.%7x̐4V)R-"¯bBPr]TķTOGցΝ+3wY 3|xIe@?Gٕ32oU=MJtLYR+ 4Rߗk 56Ov0x.,r_G+Sݧ.]erSN7dI:eF |ޅʁ|g0CъkĂD>.Fep(4Vf!??ݥmX1b&FJUo!Flzyy!+)}S}ˢ}"qt~⧃کYѰ})&lH=2c\9ϰ(,p ecyIɯ3WW7(;RŤFؓ”[S'TMO$$]]ʸ+t-phs-tAJ4<}854n K@ݼbWq0i.or\]570~bd J}4p2C (TYOM}𹩻[+iP_z;e/è/ >*Ê O2ꍦ-y~E0@/a+Tl Avs_m BCYgnbdE2yN(*WIfnXq~h,iL Z`t٠lEH;&1,'hugJE?ŃJ_W|JpenF |>X5WR͂K8Am/,?' p97Ba=%fZ NX$֕{oMIG=5쏖5>ZНuJ%Xǭ~VZ#7ẇd(N7Z7ݐvR:-AHCg)`sH%lسa+e;V(%[G4/rMi^{DҤY÷1"ziyolEjC6J̴MFOjd1׉mDyf wbRwYb>C+')D291^?:i 7}WaS ~7qyA('|ζZi(͌CEFNYx:g.k?@,Mx6:/ih&FTehp @2ܢ~5bALo3d5BY I3xYdB@G|\P4xw|*N THl4CmUB6Y.xɢf5+Ai-0]8!Jlj }r^D~&V(ۇ _m~.ބDJ @"oma#d9߁o26q,hwo&f M|X-!brSchE* 2T-HyPQT^q}|#qTfkS=Ǥ>QRwCXӣǠ8"bz)C# -_57 =NU':2ma!yʾgZ 5 qj0=`UduWƶdX/Znٿeu]ߙR7iv&7)إEcpbu2А0춁A2D_`d߭%\sUJ9;$bn1 5Ehy<}d}aa7m/ x6 |.B{ܨWoSXq%<2lL4HA^8Aݹq^ D^e7mgqD:Ë~.N[jwpa?!t E֝퓽>>'lklsmLd sh8B CxCulcEQōC׃srjUaP:;\0ȣ? '·MDoxQT[7rXNX?$!ܜVu2qJ)$ />-~2֡Um*;P<9Vy k}*4Fe}b ;J 4]chO*Бkp8fOׁG5xw%qÓt!kLV'̇aEu %1՘  p2^tkea #0s`m{X5+..սKf,;r1݈3BUDWuW ? iEciICSZ6Vp' I ٤K!n ?nF<|Gy%èRX=TԁqZgT6 btX|<^J֌P4,6Q{9Nݱk5y._&}7S+߀MƶyoZ'V/bLɴ:ݒC#6-"60ú.+PHYѸAzz"HduP`jriǜf@ ]*n yj".Uˆ# ˌ>|eވ:z@kd&,xOsJ" +q{DX fHu4LZuE>,\޼m,jU]j[-gڀIyyWw Ft+P:\`F=mmJA[}OzfG5{ S)Oj/jh38|ejCU#Y\#S;}oR[}Db3«:<<4V`#[j63 =~|dkY۫qE3ٙ;65+k1ڣ dQ(8dGDBix=t'Kc3DŽ!\6$>;(5 ul\xր%b|5UVIdGo5s1M 60)aDR2*?-;׶x?'@) r@D !ͅeH xikF SgX#9+ By"'aaK %SUrj?'$*?}󔙱ŢG2-P#*mm9/J Ž%UOjN6ϲnfNϋ=$R mFK'.ˎ2kAf>@S3'Lm$Lܟ %H}L͚1rlQ*b/jOτ'*"z]vƔnS3cOƪNKz"@nTJk|7lH044V~n0Vt55>S]_Cp\ƉZw7S>&J%nNEZ]&<Ńp!(&Y-?q&w ^1dXBR‡1X6=xnGgkѶq]6iRUwK Vlk4>wK-L2h&;1 (p"aV4<:Et.l >κ_{KlD~qmq 4mQoCiÏw+;Bu+EA@Ξd&Z>_rώi|";<3SE*^Lܪ؈b~Բ=s*8>m1Jf@뵝 7fJ=$ iGNHPG󑥆j8&l_&P!G~CYvS~лY>?zUi{{8t6MW:- ^ N;et!"~ EԺf b_(O$,q7SK>6m0 iTD%Ӯ<Ԓ1.PL tEa87&އy2^ʢNF<[5CP0)nK*Ju#wʄTFINSn }g 9$r(9l!&tA=u͏r_N;sL_jœ^(D/<`MƗ/#\zh<7olmnQDo:;nҽ(K!}BbsZqN||9C`dWudѡL[Mq69Y;і%M9{@pYbMPP¨.46ɫ,6KBpOK0k)<ꃼh~Bx4J7Jv[t`~jqD+f> S?P %v9A'-00Pgjw3>yț֝zkƓDe؎XM"OseIS=JVs)(u$w4M47T&T.0-$7{q8%\C@lk-r#4 6xK# uetBj+!~.`M 苄]~=S(/*9` j~<d!,5ke()]Zd9pC3mH<4]m bP`^벊"WqtDh=-_y<ꁯŕqVwH(]C b= f Uyfޗ6Cȡk_ '3D_-|TB- JR-}i/ǭY0^SkeKt"9_Aw^<4iogZ뀶U pihK3Ғnzvk|QzHBrx(ܚb[zj,[}u1xT)45j1WCZU%>!\kCZo_<'ܛ/"_MC%2> mV !qeђQXL74G.K𑮬BS f 6PٗH鷼kSfa+f\ծ|ӱyz#vA 9|ayxlFhJz:[x$]B*TɪƉ#yuR€&*=)v4|otfyUv`Y~]ɠ_ ܃2%KA'Y+JP5^-]d-\.I87G6yy xy0345:wɁC:2"ffaOSD!z8xہӉhaz53%NrXY"Z k -smӑ ų^)pM3“V c2sIaL "Ј R;rX[t>/)/PYB@0 J !\2r%CETUqXʌt3[.rdza"Ws2`¥K41_JIJ1$b E` %^Ms{g pzK"$0^g~eE\jKtiTSV.)gd4\f~akԉˎ$̐v^Fi}<;~V}!GnJ-8.d,`mX U YDn C#Txo3.e`$KݝvXaA&oIz$`ҼlK@|F\Pdq&:nKe:<1jTj$L[<$f]"]3Dh\Mjh*g͋^ꝩ1q-bo!hkQ|[8o+wvQv-0 s^1uWc8ҧ-k5.=:OΞ\!S.@uLgĪmtzaɧ=eW++D=z&=jN @Sm?s4 `hS񆭋'%hj||J 6/#W'e\E* Ik_|-6G*˗MR 3l nuZmZ8)Q713U@ltyÊyXb<>KV7v>CAAUJfk6b7 s./}_5|Iy5r$V{Ebuj %jӽ&`'GaMgkw-{a {t EET @ S=D Ցfùr| E%"(˵}A(wf}.曥ވ}\:FE ;w܃|QgϺ0`Gw cThWF+S`H?"> Gemn[\8y,Qle/qL|[Gݔ~U| ?J ?7<}ukl-*a2M&s&349a0jۭԲjb`NL ;M%5^*ƊG$PklUըa73|3g`.B eIS_dDȪj|I_$ N{l / O<= ĬdfVόr~tF)6ſQJ81Wck׋6hIjY.9K JB I~kv^k|a;yEg ExE/s^?PA??Q&cu, Ti*ȂNJ!h=a_ac7UV3{NBT(K@(PWx͐?tLG|=OK" pgayŠKVdHIuVCg`s4, CI2pTSy[or&V%-xjt)dd֨ \ s"1{{6aW^lЊH Tk2o jH[٤[^tej5o--WmFȡdzv.ܟ]{S3lC!Ԩ1QWe0byy0g 'ys7K-?YR[2|ǗkUIʺyԎE0*IpD/R,)u 1EUdD;qA@_?^*:f=E3Tn `"ʄ>C=zϣ=ӓ/w!3"Ck^Zx'+^x͖{^ŠWJ)Wo;o?r`fCo`&ur8$uxXȆnr)urGkA15ņIH7)ͳyzKbεQ;}:xN> C毺M,\g(KmE-v]Hm׮6u\# A$ !q:yna]} ~&ӥ(N%IV}AFO&5"eӓ fPBfI[b'2iqWv#3qOo/Kudٴ-cV TwrsKUߺo}\"eb ݉dr/',T.hsRD3T^ ӛf[9b"\v!DOڬ/xg'^lw+@}KyʆWM(:u`8[0{fjrd񩇒ݷHs.w/W1X#"Pص/tDeG\ r1?EngΦ1OeWuIi%"| ubM a*pBl[>'aMws̵ς'y'V7 s>xl$Xէ~{l˖~QHZ!I%"qI;gÖ[cӈ@'K̖?}\7G* 3SR&JP~\HX/2;ni9VLuq=D=:] l)4t|_[G*RfqzX)nQf~i,FiUS/9f_bs~\ bv )R7S &Ԝ8Y;X9^2~#'4a(t;;GjbR:ݐ==93黯iBeϒ+ jwEA:z5 jlhbWDNgLI!$Еy*^βg]RV +eɯ.1r?;L=x '*´-*( BK mREIsP'Z52l/Yl͂cFC c4I0 o ]]9%w$}φGrer>GgBeppF$WgXo[وyxN9;Goqz|c3l/I.[KSky"RmW%lTROyQS  ж,y[~\UAZiAe?eM %]8%8ژ؁q)]D)JNh%̍gE0~T?y9қc}ִP#&mHUiz팯v:9XMEZ&Ou}k}Z>H-G*A+#>w{GQb@(ؙMXRIzY}?V \CB5y~a=pQwX'Jd0jF}yǪ'!*uLuw’|(`P mEAy :`Hv_;9 MKU/0U1Oi R re+U*SV3+?ۥmӕCK5DfUL)kd. |FܝKhMD\t[ЗpUxxf.]FlA롇ٝ]v덟]hفp2!NϨ@PzgBIj@hK7Fvza_fJߥGpo\'EV6G%6bV|;:PU 1/Q)Vl~=Sh4L#@5V#Ԃ 5.lY rOcƷ|j%>etvk*Yi-ESyڳ/.੃mU]IG9'sT$_yΔ6fIKDžSVk}l8+"tID%rᴂQ7Z1"iQ( ㅯ/ `:@XCGjUTg>贆b/f8C&en|I3lǪӢ\´m4>i-z*WHid-fbRd_^ Tcr6q ns]zQKSh c+;3t9I܂DDBËnuK{@!@AZHfT3{IW|Gg60 TpS7 GoZV TF:FjeV=7= WQMp0,gl'+>#*0jYlvitu *XkE`6y3^Qό#Y(i/x::՞U$no!M^&GͰTx=tۜ(pan:f3i<3nKzT,~vANt{l:VL4VQ ~uU|S RLm c=2g-1ib(-mҡ=RYzEn.EV e,slI-8<읞oIC:cgu0xy 3ɅBÌLNנrYC#< S&. ki1 20ncMX? tLSKf6qR:Yv9Q?ϼPR?" }YσUu:v{&N O1 tf#y:##m8e ąϠ~cNORw8O6⦭H@{ҥUUs(pkqvcRݔ2BȺRYΡ%>Ya_BI$>: WnM %Ɵޖݍ(fvPDW7%mOVmI@orPή2 7 YX8/iefhSR?V$oO(rLveuls $\=ۣ@èT" qA!X߂]d:e " ;n{XaXy3LL˽S:@LDrt/3,&/N>HOkQ^©J731@0d+ߕYFk[ μU`08jV$Ew?^CTwвs pp6jL aV"hG#Ҽ ۤ_|K $*u'pҷ)J|k䚵U<2?0o|s+ۻJK gđDÈPH~x  8ăğWY0>INUU̮!C2&H SZ}Vc TW0`GUPpJ?~cTǙ#t2 9 S銭1XΌ{a>zL?,Z3 ve盢Ҹq 60<nƊp6-[%rRIq9W %Wpk08zm+vt4 e'%7F,PI`#!UPKd.:!Ƚ'G`TgHGW-1`Wֆ@"@c8B^7g ]O&j炅S P\ü*tJQtzWQ(bJ)p+?'>n W@d j%}pF.Z\YQ㰅}o !3CG ˣ (%}oy8ۭzqةoWgfzZK c`n(ȃJ _qQVvv WopQ xNp+6UE_[%RF) ;HBU#WXՃj4_q3/nY?FXBYc |?rd@j4 0;:ֿBN_ɰPtBR[ qwf8jC֓JQcUgo4!ĸL8S wnZuo.y [ٰ[tP]fAgU'"r0@h5]Lg$R BJmsHgNL|\Cih}?}@^| }]2\6ޅ>ߦn:w"Q+x0Isq{ J->8ȴh`Khib9)2Y8(.`˳DyǏKꩶ(EWnW,Oz;U>)H8,`)m8@V6\E*B-shoƴQ0E=]ض#}/oDw$yFθ诉IŨJ:GGTYc~pVW% KFӀ\%a;r!RwM/zx//ζ,~jL67y*1(QbZ2n$|W7sw0X&'|*Z>.Wj6+/@ƌ8aޤj7JV;[c)Jjům&mҜpX^SAM lncۇ?v(+*P#.mBȒhrc'2ot'܍ktɬKo Qrɓb秓"\+5Han7p OdL_`th^m <$MvQūVKMp7qx SlIRta4I߱wsya'ƀ%04` oC1jy|c'E<)RQ?0ֽrsQZ.[ZD3;pD0̐e@siF ?DPB%<O5]z vC@_˲6 2-mQ4I<֩m+G# TlfK`̔+0}b s؍'펕lKx4Í5b3<`abͅ2.ٖm,PsQRWt6CBN 4ī7J7/vF!+85mP3O0ZRQ1]U2#ͦ9*ݝ]5(XB!/88SЙ 8Rr"K$:Bzn)Jk4% fJy _T|Tv!ջђ$PeofWjۨ+[qfSWC!`ip8 3 |ٚ,@@mxeHUdwg~uI,KbƟ,ҼlB 9p\[AgW1>< 7JmxL|Zgu1aFAL}}Du}YQiQJu-Ѹ=VDrix3WSm\-_'0zB<8.UZ\K.^͐w8*Y!N<=UIui'3N;[ҋjN\zk; VVxolnY՘BS k}}<ݨWg @ DZ(Mrƶ5B1yW$-YrGz"$vWB&pPuqV@^S ! j8M_k8l~ȫU/ d-o|.1KS~(RsM‡ZLqbkl ;@3^~6c*ůVKJ=^W+d%ʠJzxi+&)ʇɺeX聙d#+SI*7xCQy@%ʵ  ;D>IwԳ"eg$,8۬ywZgz hPJ㜡mTaI/nI4)!OD[Df7O^]$;+Y <T Ԩ4&*hg i :l1Z9]TN-N1-ކx]"|>Ov?oC+/B~!T!H 4)r,*0e =uEn[c7iOzH)5fn߭[2oE_k?X +s\tެ{O?m>o{S'({c1ERUZI$h2\G͖Qց@8?o'Pn"٫;  Ymڇ;KՀG[<@eR`^$r/kWD't? ,4-&fD]y1o&yJLBA@d}=<|dy6n'y ~UN.%0I@ _geQ+F \7Īr=zxJڟ7/ (FI+^2_a$]8PMJYKA#Aϭ6)Hf|S-\߶>A?/O8gHQ(OY+0|90G<vu`K&S0!JF]M Z?ި[b:G!. k?idk s8`Jv-"m5W$~@7ąQ+}XӑޕlK) կԐǃYh;8 :>VTMOsTMwYwT ݡ6;paR:[^&J/3~(JR81ƑV$ZWH2.r` -3oz-ztoEe^"I34q*dA61!<)=;V~'}NUBpZ5eZP403RЍ촉t?l .R]#W|ԟTqԘ4+ Kl7SFV? r_b`Os)^j};􀠜V\? q4L8Qҗ%2X$S 7ո9N|1F]; hiP>++1Pl#@҄xS#NW!N5)Z{v12Yw_\7z0YaQ4U<7nqM _44Y΀!eE@Bo{%}!^2 +-iRm)f ^K˫V !+WmXNc:wCSnў#4[׫#g 1_u:LM&,uṀcA ȶ+%=_t![v9BthnԈk%J?`j^G}[t$$.2\¬d^&A2wi lp&C g5J@Gy]!,&]ZEDI2`mg>*)kOAֲU1?UEVp\d:&+17x6or|6|4x2z3LJԯP&Zz3M|400!Kycu$3 8o7ôQSpAh(pʵ5}{/{?Xר]'L̿w*ś,JIflE&w\*pf@r]I%˱o:ICt r%n > l1Qp '< ˂P $+ZA1^|HJ:$2NJiZ̚Է"AGőp~o c%Scw "8է۸Ax%x}>SδMWHͪjxFh 9 4}/ߍ$g&%[7N*^&O]Q{jgwe?te;Hpww+8zjOE* ٠i:őutf$ +;(!Dč.j(?TdC݁`pi7 [xSJpw)i #YY̜s᎙YJ|C^/(id24ӿ|AOqiZZUH9gO>M*_!0Pd)+ tt$MT,.Y*z,[):N!HV0 ։@@<.:x/7RG%^r|j4Kyޕx(fd)?o@аƮ3@+#ndfT|qYqN/A뻥S؅km|uW64WZX ?dĭ#{,c1dfAVjID ˃ q/ 22r B$͇m_qeMν$IB:Uơ񆣔nQŮdC)"ky>0{Jfe9&aűC#!2%_H$0IݝI/Z)mby!B[懸 P𠠏YvkzN]'  _=`\ܿlTfӓ.?ɜU1܂m"6N@,;&o`L+ҷ#҉@IQI!՚P[31}-7,Nc Y=_UYAFݩ {]BT5 #_t!<%Xhp1"@[k-Ɂ𷥳 r촑'IPԭ֕O-k?Ɛj ]ez|{Q5؏RJT_a򝋱*PNq7pbyR>7>f?IRR[\^SIBh $W~'vUOs[Օ7( Kjմ:).h ghFKm#HNsQY$f]w$ c!; :a1wrl0`E6g8kN=W`s|?]zn=3``} &~%^2?Ĭ\5:|bI"vo] AP GMVh @1jzC7"X%r<~Qc諭Sf-='ԺhO!:]U#^^eM.ҋSst}ML BGeVcK'KO8=`z5{LTtӿաaQJ8}-]V`s yڥ& S"2P ~|FԌFhQo탩ӄw~]R:= !ߙR/hd#7c 8$7ԯ]o'vew36v\0zipp|Ayh-D dFߢQF:T!/EM4<+ SpSlVS }x|Nu6/g_zvIyPC)`F;jh^3|j5;όts0UUP㰿J'DMP 1ǚ!YtxAIo]Vk0*!fa2vM~. i  ǡ$ W/ Y 0^،|'Ԛyf"n+TqOÂMccTbg4hC1ÖU oɀ bF9>rX?߇pޔ2c t'S 8} ˀ3d6 @I1F?.@=pQ=¬l9罂f'PBnh4)QJ G^ۼiֱyWI@ޣBˆ*PD-woEH$*g.3 ۗLp La-fV&Ϭ~3_nJk<ȷǠ!@P%A5IEI}{ѩZ MfZ xO!%=w8Cw'Q-A!$m<])7>L[X[B 7^ŀyjWҢQ>CT*;H64' Br]y TVwVH|5<aVC)`S%R_q~ꦱKlzGGl}d\$ h5c*2b%j%ŊDs3Z}%+dItǏ) y@#Yf6jk4Z‘/=ֆBr/}Xs算r4UG;Ԅ)eCqF.6^3H{{N\壋d(Χ9P5.飈"SjAR``WY&-;J42 I엝F%]s 'Zcؕ;H4|'Ii$程O,e#<= m5x4.җDIvJyuq?I=1͌-jɉq5)عI/t7Dz''3M͎ #n$s:1ٍ[6OSE1 8N']hzgytM)9莄--\~~,P4^[ ׉L>i9eDaf&wkl'9M IZ[K;Gks9jOn_b}ٞzT>@a 5ĂE 2skKd"GYpK/2(`"3CW6:"sU*Pnҋt?&%,}_۸9kzl9(nsɳPUB(o+eAqnIc^(9>mnY)}WvyA Ŭ SMvY7H/s8^Qjb&GHb8bDSӳylU uTlm9A u㨒$|f?s㿯+"?fZ0du%ol4xqY.yU 7Մs3' T{Ŕ#Ic\Iކh<(VzYDq}shZKbo[O* FQA0*\P( SXح727d޺s^p;ИE-4wz蒋&]Ž^ilZ<4:g#A e-TQ@ֵmUkOr$Pu!E(o+6QTṮoLJ. s-WByo `oo_qk( *j@K;UM))GSkH86e n'h5Gm$V\G/ѿNL!MMǗO= }z0VKr<4:-/=s = Ta2Tt'OJ \=] ,˗Ka򍉛s7[Q.N7;qsv-6M / AD^زmumFT@S'~'+jөWi uw%DÎ pA  ^b?YQq .-?`x*U,1}1\(n!w6誷tBXY33)Bp rV,"!P-t1v1{y-\g^rx Q\2Ɇ"bOS[ѴqrBl Bѥ4R[RΆpʧg;dF UP &,Ɛ]$ή|B a2pnBPv{TR* 0 U(Q#!0 p0dG_dr8c㼭G]kay{V~ 5x>WӗJpN:LRP~`ԃBg?Dj҇1!l=;PopZXW}0G6'b\Ȋ%Qvg]˿Q+C^?'1hqwͷI[6+L(J~JcaDI+_/إyOyҁ.zW^"լ57Y( ߐ.3uk΀k>Pl@H0I μH>uw0rnm΃.3Qa<#6Uvր`(B-_}xֺ˒2ZZAm J6AJ Ss}=~MZXh.wk SLg耵1G؋AIn''n0iy qswP2 ((C΄GIX9^_'u9~ra/ol^!?{Oj2vxQbE.mTnQNk1^1n/.yp4%(dŻ~vf b2Y] *!el+ 9"lI5k M0\>9?0 *ˈ@*[KpŴNІ-Yax<5q{3& .ҦWd~/%>~ k{+FjȴTС疞tEo4[?F$t! yf5GE}T77^O}9/ugu8ܕwOCm'Bgl/z٥4Ht_H@KBCBv:t[ ʾ؎VHߗ'eh4EDrCA-OkCͷ #[OéK(S04tIKXAFQkæH]5OmHoR_%'4q;H14%R]\JAM1)NZk /6@> z5@ɟ鯐&ɿ*Crz/ ЪF;9t69gw5#N/p@0@z?yl{ n\zGм( 15eCfanN/QLGsw)Ř4P0}$qǚԩ-mXy͠:z?NSJWv *{fSu(Wy;oRDu)[&q>CV9c3iB0CޑoS`nIMҩ,=Ű椵L%IEYz4$n&ezLx^!)_&&#CBĢf]j&+FQhJYQ~P ܰuboo_UHE@C@O_8}Q?,ӣS.vxPa4t1Fp s7>0-aU@m)ӟRc+Qc5|GWs1^fb߳xb{f~V+`4씽޼)%qи6xK't@Wd,FGE=[K> - gf/0 ?ad@ /b )M1E|dF7P_zOҘ]uؔ fΛV;Ǯ}<}4@:RPó#T#=}۸5>ċ9ط:@?G*^$C _a,5";V#k2C͡Hl`4vG0t]7XL]<=ΉXO~Dv{)>t;osҞ濈1 ]E$UoT9d4{E찡 _X_|Ox "'KB DS9g(np*ĹdTgގ&f%jH"oP`C{VO~ŊZ`ue_Em$ yq 6RyX]IY\DK:ıTTD|P#1[W8_]a1yh&w -ƄVw 6W'gVekva#]D5`ԈA#ޘLv2Ϡ>ׂ|p61ͤ@PTmPQfn6οٟGݫT(~n\yP{~Etv5)IƘ7d&G-Pmji3?R>;ƆeN` MsVxS*nk-\!5|&-ş*~?Yy @n&MgH ` Ĥ֧ʦK8yAg3 gSسUr0ޣ.A/O׭pF$s{B hA(=gŕ:/΅jBE,x5۔jSBSX"}s@SU0Q|2|M6[#.&z BF;h\zL餑ŭ|?q#Uoryw 3i1/H=/|F6< G6dTuHx>"1CA?G^) Yc<[\Z 3vYUR=VKQ8/;wɏᾦhnq"ōF)y%Τ*8~ TgWt:L\3!3#p>wO~3"ć;$56-K{yl L&*K^9>jo jύ=C"'ՎNoEmFC+d.I'!t!fq/8/ <[r"g~JرK31L]6 unjИJ?Μtش ⢓5Do&VatA05`d ӨzƼ&>iDhvxcր*sn[+P BGlܵ4 ~tP\@+71WMB4t&@0fKoJxfJ&7E׬3"M~YA2b=IE a `됬$zr*yr5 G-oTͽ:13-r%}kv:$VS⺭Ǜ[ k_^ %-vb_LN#rγHsu!T!J\ׂ8e>g켾px!6JG3[>9\(W͇۵$2f5{ȋ'C#$lU`9M8oGO)I"g"ײ UwJ*϶L=e\P p]}X3>rih$ȴe|AfLFH> mB- -VVsB1= ؁foԬF MS,.ȄTy8~Itm%V2D3N[k]ӾB^A-G1<[L|K/>$(LEJ&5}AH?F [<ʲڋb7(i |yO ȨvR1R#y;w;s}eUE `28 jw qjG*H5DTIJݞpC+J 8ma\vmq2TdNS?2>ڱ^ *Wq;l#nQ@hY{MPֆ BRhbawL,A 6q AN!|巡,4e-XS6niNzBcw qra| `l>i&{@%J|:T2<_O.uAIߩT9D^bw>=ϑ=z0q0k|5yr+opӆc=28(MPV&nY\qUN1%X\R|"M8u!`8!>YluufT1C.#`BiʎK%M8vά5(aT$8Oh[A'U{(6h*2)ZBABH2O+犎#?Sf7Vlz WHwi LJJlߦ;wGTs_&S ]~G]kZ5,l -bʂ/l>-RJbB 2Q:Eg38}*?X\ ˥sbTL {~eC> gQF:&Ec޾ah|`>nH;˸#qz0v! *17F\鳯߼|f 3P+l[K[mbD3F|\kU':+}Q B~*cQ @ˁ6΂\><5BdA4h$j\ ȋIL{I.%p N}v3$RyҟJ,n¸q8 0ΐ<5Zl3,[ouCb2=v'p;sCz&x8cZ7{,"9?;qYƼ3(9c+4}R^p~ 2xRWšL3!-GG u;3+tߝFLѳ D}b^B'2YkM*"Ip@S8[1 WɎIM^M[5c5\GQw]ag\Rз@vG8.bO|֛ Jx3A2Oj<0lSclFe^iA#72bO 4IVssiD] ^ >lߪ–T8|bH5EݬN֞z~=7@8r0gRnPF:? ͏w,yϲTTwybfBʮaD%L~+lxY|eZ {3|hBџV$Te23,EvW.ԅjxSrF~˃tljC6ןB:Y|{"yȸ}ėh}alG^Dbq_:T m]֘X>#1#: n &.CiCg*Z~,3>ؖ6$-8l9 ؃6kHXM]sB]p^+ Fa-UPp|Hp4OoVK1U=ث TxaTdWXAB nr.X(@HZHhu;*'GEެv0:4m|x^cs" :_=uNʒ%.;gT}QՏML].(=(ϥu? \X ;3wi+s0b0HPz$}t{9= 8-ywc|IaQ&`t:T~Ny_. IіG^p %) Ӑ:yZZCmt\$}a=^UG `gIST-؛Hl2 ݠS6uEC62d}0S6Yzݬ]TNc.=""n `}5C U}@WA TXxz߈ňF%{DB|=2PF|@y}{? p,# 㽖T*J҈t=pL` Q de0#֌xGJhXPG"GVwt}I#r![DjkbUK\Ye20X)Ϩ>so9j=TE"#X,k]bK??t2X8ma9\\-Na~^NVl8KcFZ"P@W4QxM~ŲFi<;A@8k6qQޓT2M PgItD%[S׬.{& %IĒ*fAiuCmu~= P "/hF7y5AgI?L[?,~|eKow&i4b8>[f^#{-f?)bq[bӉw GgD' Xo0KZL * ~Lq$u?G NP{Wj,SCkw0&>q%ߔ?jՑv6H,S,qWoC4@"PPn}/R!1cpK8ѐq5 ˽})}uYה9MC&;Q{P߻Mt^wHCib_OIDb:.- /Usj>{*8.`t;'=FcQ$/{݋$X"77v";v'z+wӨF#tu /1D3Hݟ&V;lbuV?Fvݹh^rʨ +6;ɰtHFTz8NC#J.:??#ÿKbړÖzӀQů,"L:FQHK:#~WWޣ&}~z[?Wǂ%#|; IѼLZgm/OEmΈkXRZU#{y4 DP^>@xFYpf ba"#@ʏI/<LT2Q"geCO48- xp͆x-R`wX*P? /Tc`1 xxJVUAb<Ҽ姿\8NAt˞nVi0}Wax_'Ҥ1"Z/[!0\AѵBjg;!vۘu="ekKQgXY@O[`n[:>-}g]"jƵn!u]2sJT /̗3\2̎s/"t^q[y33!Th`t!({hȔl0L,r.qLu->< .A=Ͱ*txZ^!vNE}Y>c'c ғj3BN*ewQny-4SO=N<Һ4cZFgG|Lɦ:8)$ "U^]iQu5vNB9 BbWBOTO/ײ,5g ( .dKW9u4V[/2FcKN̔*.Qg.Ȍ{Cin9 p;iLARL Qd#y|7ȅ$ĭzӴ-F 2yj4{B ljwх= J&95%>ýHؒPe{-5ǵ>DnI>iO`yUB bDiD9E>$ O?>}݄HIOJޞ_;G OOS GK[)4,euYV%'~8c{Ϊ2+#XUmG&s-C7lh>S]O&Fzv k[oOd @z)\/|ODM^#%-Y#{Q(TNK!^f|0 ի ֗Xgƭ_ I RA3*{r1 `! l^R<'XJ#l<^'7cU wnt*ȣ̑7;vғ)BNyb$;8H ߊ0<"Ye\4]4iɳ7P^o 'j*eHhl>6ެaš5?-vcV!6/56Ԛ.y7XTLU\~_+tKdy+"&&{j}-a`g<Z^;R ⯐=j -zSݷusM3tIg,FXH-Jz9Dcs2N"PPaacYwX_6MxK"cm 54Ŧݞ8- b/*̇$n6PR C}oU,ucaJ;50kƨK6lK}3;Q\5#W)RܠBRg)`#RvMߡ$y;_K6_p&ٵᵑSꢲ~kr(bSmЅzǛ Cʈ=U$7ħ/ݍвkx~DŽtquZ3u9gיyc>#zI-צ+VEel{cXay^^PZu&1 MTP kBf#T Q<]muEzTkdTM`UAC6f|#im-U'#Plˠ5֫=]M1w_Upl$=& O4")_b:vkBurMݞ#VgbaXFP\f:^|wxj27zd$!,s2rs~Ǜj2YL-G1kZKN A> ~q;!u}O&s)H+3loxz7̏75~4w@$[{`LnbF%䝬c`V8 C!jh2@FJ]#ީM!+y9kU)NO0l>PH l^?b)Nۭk ep#d֚ґ|蛹9ܗBH],q *QL3Y [[}\wJS} qk=v2͜ L7$_#c=ϐBd!:chDv4#]iڳzsY2q/۞N *Ekk_E ʽSlB4԰ص:Y<EY\`Hb@P+P" /ևT>=ԕSkd"cKLkF{lA =.hԱ~9ʇQIMo G9&I=ߣ?OTϿvB KOgl/L≯OO&, ? TZV '.T2`X)+!WJbt5?(Ri@-k~N eŒGD53Z::,w+2T?7ėez1[]|%1g㝳T[dKik2/=؄SiPkWͰX/Ͷ)#~ndvEn^ T`7ǿ#:Kc4Tֳ̩u&5Ұ>( rZ[!e&\hLqqfw7j('(mfQ'~x Ź]p{0g ,T2]{.C{/;w\O#C'ϼRH!3jdZ I :&%8cܠ.{Py:PV0oMǮ'&ZI Z1ř#8R4ՀT \kUJd:t0畁qwˡ8,zFI|:άKGcrRT,)M c=?ԃL _E1=ܓ[iSY߹s[;dj0-1 k)(~$G;ev螉P \:'S鵙|sn오.|穪5b5v':)-/qM_|A#Ӳ:;NۿT-X2IfMg7&<kEL#cm4{ut~\Fb m$ !W "F)JRa BJix3)$ acTAU Aa:"]4蹼 &M`@-Jd$X4#ړu +EZ#@ټ =o;tXbRAE ʬ()KIDu g[3duπ3S!u^ *;xG vJm$+Rwl #]5Ă?lq(JҁʨQ,ꥡk,lu0Kg6ZQ.O}|S;l׻ 1KCy/v9Evb;?$E#}1ޘ32W̐V {ZB ;ܮ3nO!:Rhj5.).ӏɋ2I:AZ?5Pm-7^PG 1}1EQŮlJ$lof߂ \=kɏxB.{13~ @6\Dņd5|C *-ܪn fajaL!rm?DuzW@hv:h (T+Pe}}_h¢a]OWze8tmX!_?8celSC ;+w&IW`wUpgPܝSb"=Z,lD,'aj)ѤO$*tkiShe!]iN[L*tͧGo#4 |Llw#V],G'9V7c{ؼ_%AL'h:"=-kI٣ ay Y"p?xg/8e y-e0QZs>^LfR eqϖRk6 nz~kܷ/MZվb;46YoQ>"T0Db,+)fCkGDh#T~\?h)O{#+݅4')2iS~F{q ,ǩx[My=e+svYHQ * Nj6\(im2-]i#]=* p>Kz< ːLQh>\o 5P!W==*Js4i]ɗl-\bRlU ASrUr |{$M|Nka%AbC,G &VFZ})Cz9ڀ%Q{3+! B=' A\4{Jt8Ӫ BwGkO{قoPzY\hAW?Li 8"ըLZx 7^Ё1;w%׎֥u9@* *.AZNKVP`,zD[hZ*utZ3ZU!z_G=ڜSdkfŽ7oqleťX5]J!R."&J:2T,iSjЇM 0&< ySV&}[6-g4N]yrIB/zi۰} o_IK9\gq*t2(ox|[3LKgW4V9!h @a်`:_7my'68q9(@O$-C :zPVyklҠNO؂{狓lj3"0:h.\7m?R`c IoԚqBҒ=΁HIn[yg9OnEi&>RB!53%9 "92jXEuq>&@ Au%^L% 1]?= 1XڍyMM[v[n4N#U6!ak7SMêTG<̻FeIWdDHY07i1 t Gb2/)x^dPyЊ &DIqG{Di㟍Ёj{4ZjE5fmO<mYo!@UjNZ>] w"V܉#N#ڒ6%aʺ|3JC7޼+TΟEy-bgV9Zo8m4 ,*CF}@FOfLe~ȡƵ LTdˆ%f P]-7Ԉ(fmE1 򖶤tZ}yv>8yX׽yGJJ%z39ČuH܃-&?)Sh,o)ﯞF/VUKITJVv=a/󉴜tBr!}[yŶ+ŢxP)]_H.Gji]"Y&_? +>CMjq<Q\j"%P74~C^GMUY? |1,:1QdˊugpVɧD+[ ;(S8*Ӻ"ΌyX$Ov [[]o$*!hl4/R,s*{m'5",yŎ9磛lw(+aKqBS&Z\l,R?%?7-@ Z'*/aORÂ-Ul'82m 'տ\!m~WrNtRi>ۏX>=n[pSigyyjLUqMl/2 >d9u))<U` M`*lj"},a^3% eK OZ . < ozry\mEOk494|Hd%A"3kx$ ~uy{Ʒ@[z ΍bB6y&W/h >bC/ ZW(賀^٘ {̩;a4#XCRWZ0U|E() Xc轌 Ì*߰=w5)OeM]OYT(:%/;:p|8 ɹƄReP[İGV8d# E|3$bm? L9ɼ1-98+%r/},tڸޟ#jTo5V<,HfFDb}TڢEWTz" S<]OMQ7)QiwWqap<\F쬭S]:ѣ@⾽aG3A@ LDdlBV bBLVret<3?Y=DYO*B,U4|W1]fqzͨ'NP8VHS_]{x,j/龎5nP+yS>XÆ"f6ℏDf19j)rzw43ėâؖlvF5̗MC(3FoxʼnANdEUo#.tu(D<[ECwsWڇu"&lγkS~_z y[cd|4<K`qkE9'bQVjܸ_kk젮~B/wH2Y m>p$^xt4F%s6y i,󌙬ȆP8das7w,Arzʈ'|L-FLn2l]ƀtjr\$YwPza 7fgRL|E{bozÃ2b4J{aR^˖|hqiV |^ᆸ6씎Ǎ\w5J!x(D+sT,Z͊>d70iқ |Xt"#5C-`؄VKuV5b p޲ǘ˰7c`7H@WV^.p1if7Ȃ \u OÊY8zHr\|i:,'p8dr|KcFruiM|^~CZX?-M"_FYv4,5trDq /كo6뢙.=?5V63c5yɤUM&lVsuˬ"]/+~z@ 3i^jQ77q`>h$!Yޛ;Մf*TOqs GNvmL\jr2g]AD/HL?FN^RAOLirpt-9Gu\m7~O>f:}TD-kVɠәAb7cABuxbo %&7L9P_8E\;z?xӦwB0*|2n5Q32_ "E[}LD~9ϬM@xA,i: 8inB|8_amt@(a! 6&ᓁ=:+(kX=$ihɤ2Np%oUqUp:-)o+[ 7c^&; N'Yrᮅfp f67ů.ݬXb~JhqWTS=nyl.q?JS{WYj1|\뵠y9Zxلq'}gTuԁo7MgO'!T)*<5&&as.A%^ 1aӋ_6sl z|*{V,6u,vQV 4ޓa5?Ϡdz=4HWK9Mq1 Ktjo!W*8$3iDM,T{U?ƴK>dFʩɩBYR:U.V JYK3 0-g,c=(#1=E1DY`fصX'3"+Ħ]:ڐ]3OV B'ITS-BpIWe7ZXs#'Q1ZQ-J_ gsR;na)ZD4:z1pRͷ޻C<s[;KMS$II}<-+" 7v;'+N?Sb%]$Q)z|4;t XT˩8US3- GQ0㪞dr_5 _NeRƊ HgueT4$guqN$л="k,w13&7ι6T`<Hn`)#Q:w;/ekLW.ƿ|4@ i@/Xa iUn nr3Ͷ_L3KoB޺?."$X|oѿPt9m:&o1fʟ+Iꉋ}S5lFkt]c LIibe-H2Tq4u 4wj@l.7XК&՘L:FԂW ,2Gn}+}&*G=*4%ǎC3' 5&t]0gzoJC0a\ޕb$0g-TJY8]EQYpS&pL2C1AZo2Ħf,]KpFUUE $/T@ }ޜ? V8m=8M*9RU yQ) m~-(Z˼Eʬ9,GLnjr[ s˃v/x Uߟ?S5T;RCbk<:5v+!38GV+GF";YDs eIR`l7=́QQ>7WK~wxy#PB 2ԎX>k2fmx&/a?6I5ݪAG'.+'KZl 3$7$Y&: =*+vSY3?9gK0Bf6s3߆Wm׍7-,JvV|yK  b۷]C@c *{uD ֠A2)?'{<<|OQPblf][`%;P9pOBOI#pV잴8Ya̝hADz'@=1I&/GsE'dG0L;&\sɁ4:?6_2cD|, RShleiR?+j,-3-/+HY+Yq[`?PQ۲@[`f%[ATB/D$ uu B|~gM%'@} :BE|BэS/"ET]+03ryLg AFh. Щ 6 # ";FܣXl_ !$`3FQyg.rH (BBBÐ0e,-icbߋHs\. in41 0AD^0e/ꔅ-SR>A~ ̦zǁ[]IO_A ?% ę8$ٟb" 'WvQ,3Zw9㯙vǚͲS^CiɛQY7m U'[X [Q|ς=OdHP=dVN c0beeAޥd{T#fws9-05J6 Q3s%;x"<ެdlYĽ`T_\g+!֑pkNO2qPk|AxCҌIӡb]Xʹ* HqV=agwwuVƐmf-_5uXOr[ڟԨNص{* _:t/`&o,YqZÈfmDSM ߉ە|$DbaJe%p%WDkҘ*0Uz|eûf"4StO̯eXʌ5^)Dħ%>@G+bMGP1EpOId[UӸ94tۊ /*#5glTApg8ٟ$|XMK(󈇡8e05aI]l 0XJ4=hM1V7D5-UճaoaF ١36)z[8?gOsC.8.Fom#2 d3ݴIӯã Ff{!Zv_o$MWo lgbC`01uKy4Je>h j7LA>S2߫$OnA|7,(M;a=GQϻy!q+x*2ƮTn@yy9E`zdx٭]D~7Z.F!""D3W>? )<{}n җ,87t ,r\:G{emZsLcHCVg0QiHVn{v ɽ ݖCzBo縅*Q:x&bȒ Y \x[68ѥBK؁3ȏ&#=t6}:yx XdNfI~26w?024пYY8hL/Ƣ o W]$DnY5YU Q 24dZ.BEG7S1!X8D,Ќ=}?^`R$/Tv DD QƘDdj T^ZKߢALH~/fHll:ȥulUsM I1(\QO0⫉_% i@;t˙=kf; EnI0$Zςe3mmqILKUS:yWMPRke&piM10i`NO-"šǩBu!c\ZMVg^+Q޵4+Q{H*R)OV*{t;D$ABΏۉ1W_ , мX~jD]bD_KfR0st6(c_o -ZpMC:<3t|rn_tuG.dd dرpfOp1Su#fVkD_1~TFzr> |", t_MZѡ ?R3 ٲZxd/'T_>aqQO ͱW& ,,P|f>%Yħ- }E%Da*΁5_z߳|$ݲpO#A>f-/hhBOE)ib?ճ*.G,7[~[df~۴D $: I2#IB&\/O7$61XȲݷOި ѡl L 1NOZE|~Q;Ζd UkL& Wظ$+-JZ}N8M2nx!?D[W{`ߘ'՘#B5QcDDi[jJ%\ly:JJ!"Y`a߻܃:` g^f5v{/a'yu߷|@s0lXE`Q'Bxz SxεRn=ID}@.΋=ΊJ1q9uOOEtnVJ}}Y¡x5GѥyzOFWߟw첳/NlI͚.tBW "omfP򎉈"S(^޽1h: Nvu]uq6L&Mz0wLvAnqҖ!uҺt H[(MfuTDO+vb =p P>܈TTaINr74`jYIpRUɠT[UCSLFm甊֝w3?4$ޤVq7 =g- \&Dt(=&HWvWMdǵ V,%'s:~PabT. fh~U|pz~?<ڡ P?*nYWC!$ՋKfh޽CYڶW4ΪGL^%*#1.ge | h"o zGA#D~'魕EX4'Ph4/Q'櫆: uF*Ŋ>03sej!`2?خ#P,e?Ōބ{ ^KSs_ A4:@@>'z&v4 &DeazvzzHx^"u<;,9gHEӷ1!2yY~`W`~,SzeDOlÀ X\zU,3UXlA|;!OFJ()ȓbGNt/ly:@64}"'^w 4=|Ee&l4πk=ozljK ^8-~w.r-N$ΏV *g\J9Tc:=Jf j/˫{v2D _Pg~Mt0u-<yقMQk;IHH ~;TA*Id[^Y}PLOػO`ߵh#H3_gG}OZ鐪ʼnD|D3tOJ(ɬF˜0Gr45J9\HkL^GTב"42فV6 +"4%%PUd6ϊ$<[>t' 7Sjar*AJL,QW&bd v#JQӄsNE'>u5w+âuPTv=G_@NcZf w;RxSF*,PP*6@i'|c=&S+4Zj$A9)mns;Zk/C{|<"4;b "frwS[J"@%`j{/t WRLYxz> NBѽ+R@P>{H3v=AJrJ&tn:&q06B\A*4\}&ɾӦViS0m%»Su2v˳L E4f=N m;A$ -S(֭CF4q5  U308A,؆%ȱ&;}{܂O}1p c6dƓ#`wemzfrlSGȱ(:0_Fo־.Q"4DhIuQth?`}؛&g>W'Mr^XbdB/2zA[kH/twXtqBW'% *F [S+$`/$oD0rEjRE[ϾQpLG.V3K6:7^RX"sap訵5 ʋ X ڤWXų !WAyO.OKWEO ,LAҲD>NN2qc y]F[2NKUJñJD o/98  e4)BHceaI(;*9%`$_E F&^ӭB`hO,֕s3>0Frr)%2tP9jXb- vX=p6t'M>hM>D{(WaV1Hc_*qnL +@ z-#E.W&K',s&nb#[ e|6jcpKT7y_ {˄>9t:]=JffPǑdRfƻ@['EᾙxMKNPٹ;l-D>Ip\u5-OA {N>>=HgQ:`QeŝZ@ȸP4"Gr8 \ ^o$ED1fj+ mK~3,ͦGms¼Edk*1Lp)#+y&.͆{/! .[4@4&ʹw12'z⽔챠D9t=(l"k[oAXa"QR 45" ZHQ/GkW;)827ldaa=yGH R(?v^{$g :҈'%LG:[D|JCi58z8)^:¶T_̵c?{ܶQ6*ez:wd_ F;'y8̼]S:9UN)so/ʚKj({ zg1#NT;r Ab"ziYtJ>׋俖R=0Lf,OU; iS6龿 Yhi ~4.9z36]"8qrYg8Un˜`-i{xqQp ͥm!]̛_P.>w0M%>m] 'T<%Ċ"5K 4VR*#nVߥ2{tǠH8 Bun ty ʜ\l "nK3af1a">ynWY11J^9w[Vj Y`h9 ;0fnF`d{7@~ l>(72Lg77LX%.%y4ӱ0q,ahn Ey!E6^\ceX<<\.1STKIcp'^wڂ>R 03L0!.|ޚ52=\#&$ **5󚠳Q<=<.( i59;Zr Vr"]*O1Ĭ LGr̦5/A!fImE%賬NG R0Mg>fNh;%cf$oᢽ~`"(~9CD[-r!:r#%i>Rul;8\NȀE=5sRFlK#솧XE2b-Rb(А$'~(54/3ј=,>[@gs 1*A8[@0(joUDkWǐR^%x"FٶPd2kaތw6 n\v'I$5R`ચdKQ(ق, 57nzc t`Ի)}͸â]wtsr\PH2m`&d\ħʂ_&@#c"grpRAC D,F  t(dV vc*Sc{E/94 ^_9X@;q),>i>-y$D͇K`*kj/nޗQgeZv:w)k8Bɩ"u9-4U !㑨b +^;eewLp^̗*[R*Qx?rΪ55ry!tت8&|j|+H*S!Sˮ"@*3jVƾBK:8X-a/uDS \O/݄|eCu\v&C >B|>""`T_|N74)x>8WkuCf׼>z8bB_}k lKfAYvHVz94$۸eb8(zyDPU ~$BA[7B]9|j'OB3KM37m(O^|cPby7~y=!& $XW,6RHN:`\mҟf\8:73%b*`wyY%)D%+aߟe'۰F?vӺCMiGlNB|G@0`p0)n1ZBs#CCHCE1*L ,x`9>X#A\ňiG<*ֶ!Ҁ!bQrAceS)aF@@iYCpym4[G .gǜo}rVj/S1wlLY;tdtJiig1sSuL/}:0a#,B>Zga>+bh0y2Ƨ DHi!D/ IVlyT[᜔CI4 d./ [K\;yPP7SԤe!%:@l(ј4use]+gwόgCN|pJo3tjzɇ"߅hI J'6QݢĽ,0mCq-;ZO񈍈(5EU/aAWQd;)|C7|V{@oJcn f䘑PG]Z~(Fst/啫3o٘"ʏ,BzsVi1|hM%[(reyYrP3g;ޘFd(M"I)\? do7{\Qv8Yħvnt^&<^UULQ\ׄE]zJ6J%\ix-qf弙F8i=V/#2; +FҸ@ xT$J Z`m omw5{v2_}< Pl?k:6SW`pgjm[5p@V F,ZcAnvDd=wJp\ #l\i"ݚ^vd؛~aubPckc'pGە}֥`j H&;m ܸ/_a~Xa{ b?T*'7˵CR󄸧3n1``'̔6*h!EG;,ͬ|6u:MZlT E0?L|t},daN^Gz̈́;ɢ5*kP5,.@ɭxG0 + jzi0xfXᑂ*ځC3򳈽i~] z]i=$3$L/z1T=P8W3)r+;X4{HcoUUsJLZY+Mk2ūxV#5ę"G {aJ9BRWz hcD ,5z>n sۤW%/p} .4BJ ESAyPVk#fxYAv:qŚ+tͷmMt2Lԭk p/;2iBW^6IS'g(-Vt$ A($kYVw07b`sA}GLb`}62C%ҙrm;@4klP1[MS%xP DjjѼO| O&(|qX*0Rg;b_T`nu?Q0I*NeA*6, zkȯ4uɿ>!hvHNe c,[g}H SKC&W ̒\OcTr(Mأ3řZpBx{jjGA@WBo0 +<"O .'k)C~LIJ60z,' [uE Q(V2FLra0j z݇a9s.n0~J[uC&ҰN]*RnaV=!SrN!NL _p1O1ZGg”ZT)H8? _`ۦ_zjgi #6T䐾F2J1[ gb#9`E:HU=tHhەfb6`$9(bO2&^֑扐&D|kb0t(HʌNW_`ښ1lDғ%TJ_5! iUy7)/qʱ W"C'|~zh% nօy;MyhjƲa(c.wfi޸yAR̫ ẁ;mϊX u~˚MƑ /ҡ8X6*<uZ4(|7Yj( NX/fUhi.9vG7AJ_)wO 3-pt JPf nOݷKJ?a`wvҪ; Ls-*C[5,Ak8BtP /H+y2YOx'ǎDFצ([[[ޖF-l' |wAB~) PY\oMtTg 1a;Ѫ[P gд%1_PC&7}v,YF8^+:o5_F˶g:rg-_;*/5oux +Zgt7=[4]{(r+Ԃs)]Wjfvm4c~k(0+51+՛TǶFձJ ir!\S`M8HsA,O2N E3<;ON+˱~ VfчlnELG ٩Q Ah"dzve`/5\ʡv(%<E <ċ6Pz0&F=<:@Հ>NpjHwo4 K M{+359=1߀W(' <xhY +Z wcU(ǷGPPspEX2GDpH R_TK IGR:j&#A-DIaDuz6zUiPH(ٸ8@kɭVePIpHТGdGU\c-ӑf ,m+@mw3bvyEIKf FǥYN:9ehr̩P,W8B @&އRnJGep-~^h'$K=t׈/0 =$J`E=-v;kj떑hՈ3W'Z @'fBq ]asl5u=l[z-!zQWOloha@:}~70L,?u}Q=yop}us\ )} X0}'CyjX=fYOM< xR)@*дۭK(/bi`40C-H U>Kx%̥)kӺWeءu|<# f>nzNJ,f%]g\"eAgs4 kse%aor `ތ'b..V \ l=J㤎@ȃPbѴWݎn]cl>d]Veb5tjA,l={ !rUIy#ISB.b}zAtKrt9D/!=a`L@ A.Cp̥^U|C*zk4́(ifi4gȣrS]52OYƹ,jE0C&^j r(DG~=]mYO 0i^Nz֦B!ȕ&˶6hLf6X{̖]F?@* '@ƷT刕C|)c{4E ܪH ̉ɂONEy5#^)$#smbVWAѺmGdx# >t( uj3/O;D1xo#lIʄgRAvAO]gcB9~j֨C-'~NtkDN;.(]/_>"bCrHe l-*]?M#Z0Mxʍ"_e,m^8$3?iDAlӼi_7>%Wh}⋞dZ%{$։*DrqVjˮ_|UĖ*z9 |M^&8ھ.EgFA-$|IlYc`Axm6m7Ž4{3#Α]f腪% HUVJ|wnNt ctCQz3)KPV1W"aİ5`WϷP3^6ęX9\g仅{1 $֠|3yS `*@)Bv/*YQu75CYoMMÜ|%/Zͯ0&_9>]ܳrDf>[ 8\e yQ WYzehI#+߯9q=}$vq]nf0||75cK<}@Ps7B^>g[+Y''V7fV&U|&lXm,f>>txGXXOA1"f`˅u)B gPr..)9.Lжt~t]49WHZg'͎) VzT`#kz4r)؋T/}f8k{m5l3o5xok`}|Y +3.]MhDʌ NĽ}X=>ߊڎ zgYqϾ 8Dʉ&?$s.u-q-^ ƣkEeUôLٰJCR}r K8 :PK0qjqւ9\HϷA@F:=6a Uʔ)tdnU}bu_{n\ ^GUArA4,< Ϛ{rk`|`uH u7JmAyuU_[PpO. 1(iv$>ob˿RpG0DiS 8Ӧ5璱0Or%8{39s|\&Fm.5r#z dJ`zXM44-~/ǍQOGRIviSQT>@L-)?"k[/my h|2RW|( ?Xطb\F=2݇R5E,aA$s9`|#vg舄:6b k?CY_ߝ(eqzoVZ8s$TYLĕU5PZtY >6x`ӞUT:$;<( WSۨVg+XʲJeϺBC5 8z$\0ovMKYXl[qoKB EM)>-{QutU狫YkT/rA2zpͨe[v$$@ XC,/k8Ӹy*qly^'`^}[lضX!XK NymZ9b @H<ٹcaDZT {qA0G]Y|r*p;2Kp /l𲦔v;"b  9Bm.X4h|Z1Rd&$ \9p-0bnV٬I1 f@wu/JZ"-^1i #oQ*r:8 Dd߮ދt/k(rjt_0wݔcD{&}s>4iO M@1a`q#6VFLp$ Xt٧<ܨﭔeU3MWnnHA,|V{Rte7n_*߼PʖudBG>m)ɕ;lIZXᰵ^YroBȾyNY R ă)R#[J ·9q9I:dD}ޝ=p7b|"l:!"g )aV1B!F{DʚR>=&|0LR$wpsv4\*td5J4>2$<놶,Ka%*ʶPb2 Dֹˋ5<mQF밗P[ypَA4/BBЫoX]%z?8+fū7Zx)6nFphSBfNoNz.|H˒ӥksiIQ`sӕ |`&ʀ=p8~ȧ<#u0=5I#,qN B.%9^Է-z5&g>hyۛkb6Ld^C׾RcgPYҨ:`'р/U-gg=[LCǝikx_,MSOWMPYALd'@$xe}O-ȭaRYЄ4,ZlXl?;7|@?7pLHSM1}"+1IgXkG\8qL(/-'S\ A[p\ qYNQ8O*@VV#3=dT)S ۩_1^i ͗Aam40_lKJyF[_mW=ehWf]DO _SRsEu;;dЍzB5g}kDtOSrOH uBz>2ֺ%oC_aO+wUP4=Z2vf0=Do$x5ܒRB7SFiBlrt N{Q$5w Ht)ikWZB"MxCUQʛ00I[hwH>}~l 1CiB戚ud^h ^zadm ,`a|k%ZP΁_vligo[C0X9LJq}l0W CTy 5ݒwiToSer[թoԴƟ H$a= Q&P:54g& G'M -HxZG_ nf}$e"$oe'A {{x[8(kŽE='V]dp*_7Bnʌ;*j,m(;NFA~>^W;lQ߻y9Ӌ`!R{ifAi^3v-mDN7h|8*fuND-k="uǠrkZd`Q@Wrxd&&'01),RjU?Qs?!}? G0%x䮮cj+Fͱ'V÷)%Y󻛍/t RR1\%Ь%6[i(Q&N wF'Ѫ/ε;5T2X`aT_oivatKmfD0 C+oy=7kY~w{>  B5u> IԺ#OA8w/F oN<2Y (Y.U`"]z$lf xQ©s|8[޹[)%/Ѷ1,Vn2~rRFd^K8=R@% D- .~jcG'mLs5RY5qF>*_RL5P۾A8s;ܨ@tuho\ $Ъ 2ēV."+̎_+XcTWT&LⰵnI\{x=gjlʫz Cs );i{,z}h׳Ym2;A + RE/I3`D\>,Ci u,{_@B.gbUiqP&Ide5 oJIvpǀ-Ǥ-d[GaHx(&垨΀47]sfNplAt!sn|G>Rm0kBH?Щ<ܺȓIHDhG?I22d$Me Ԛ|7眐%0%7ABR˥GO&b4g\02IK0 hU/H{l7#^_\y5 .8n*1,wM햀'KADxqF=Ƣ,2nZ+&NF[u7KCb!E[a"m7oszisf|նfrR-!fsTJګ;/#Vl~B}ӈ:0SO׎WX]$EC ً ~3!4Ɩ7sw dX_# d:ZG'/ toLGy(,/}aYyRvXCM#*j0‬le̢Wa.BeSp`~Dʫ[c7y?+ӎRwW:սH$)8W106 jxt Dae$+N:H38 FbC7~XUsɈ'`N) td$+3- i/f"{좪{PRǺ泵KfYW) `Ђ%b>|2thJT*+ka*-Cݡ@%,E[p&4e:`)W5A"t%!B: XW q+cf7$T7N2T8>SlUlAý ȈjMca2%B8[V.ڥni U^DLֻL J nrBD}{ #%𰂝uar]pU5F4jUm|&3-=sapb?:v:cw͒J;.r9jLۯ<A m@gG̭aUm_t -MO7B6;X4QYADQ0'qu$j >ݢ#$,QSj {"d|U4[nm] 4J_@4?wh'g *C|Il]O,샬*<2}FF܀%eb><;lk fBRң4Ҵw vU1E%'zae%RPrz} 'nƱ5L.ȈCq86vNjKViV%Fe3fps!a4h5T؝LN>1 [ʓ_d$O{+c2:V,K 4}$}k5F|M\AUp~2vj4I--ķpVbzP"!5(@B@I4@ReZJG9MI0Xl:sdC~`N#H:V<(ȏ@d6DO$-m}+zrҚ?=[UHefa}zFI?nJ mA`ВD˔[G ɢ/Wxtd=E0y *K]c&Bg~)/XuA%Pt0@8޽{]h@w^CK/-Ȅǿ $bdp5ḭh:β`Sw/ ax/B 4qCT}j AC>Y-vÓMGaX ӗÔm. I,:IɊߟcg >z3qw[ ,a< Xm p Нb8l^^{L{)XBB…ϣUfȰy(#U*2fltXa+/9Nz XW`]A+; APZа!)<.xּyLj;@bSH7¹79e蚅T5ޙ{F-@ x7ll4c'ucs+N(y'舾7y uA e$n8>Oq֭0X;ne?Σ!&Sw `y'F]qr7:#פֿVUCXMn@BGMàO5ˌY<@1l\X/j`H% B΃:,(z[Pݧ璶=,1C g;IE?,kuۙc[hX4'ڰgY5'= h~ּS..s2v]#W\́Z81b]Hժ)ծRpXM苖 0!#( J$;WVcdmaJ{ܚ ?7+N]o7kfSj>11Zԫ[y""2=eD3ܴ谰MXԲCfbZig=%Չ ogL#ӂ<}򬵊wб%:IUpV& N&cLk~gђ_)?RQg`=@}6ɧE: k%`$9,o1}l5@k'FL2p U9k'a~ ܥWh&WYJA烁2XװזSmЁ'kg mün (ZM O34='%!bcAm?9-? ug HZXMA2Fs I|vI3!:/?+vD^r.|G.%xƪ8be)޶}#zn [j[(mգB;T0(o/@ R}s/(U\1t_XrP;c!RCv +E]d͌z4FaMVUSȥO !eslt"&}aL[h~N0IV"rE6ZmzG@bQc<ƩQd |2Iꬆ44paevt,H/k;s_(^<X ;_Bqy._dvWwC=!2,q=cE=B%Kɲ = 4 ? /2Ō"uq̎aϒ_Lv;}hAOQ:S[51.eE4 j<ޝm/(wW_Ip PxNwޠ&BIk(v9nP|#d:_ dN*;%;Ux++"ZyyP6p{'8˽䎼>SePib37:F"CB-0AJ.{' W"H^!'8dE%iLO~uQO:+Rg{74yzW-?RshK=H*dGYE!lGF7"1P/qJIg[}oMSø^Y3|{<[?bt&WcX0FC>mq2UYՆ,–G|Ϸ͡3\,\QJ)ē4z:IrBݚ2BRV"C Ç9Tnf{:?DaX0vzy[Y5;y w}1hjȴO7"Ny|n~SUrwQ\'*o.iQxO^]_N ~UPfSQl! ڋw:az=M$'bWĎXE-͊P3ءc"S6♔E4tB @1ϳ~G >W !~8)G o&:iH{z'-V:d V֝餾3q4tW(dC (Uhv+0; Yr蟀'ޥʢ-awhdt5qo,'d\"&U&F׌xXtl} h;sx# x".nd]vk%<J?U6)izg_bn낪}˞0lK[&usP $YdgMBbXa֡Av'mAj(, 'F%]?8GhTFudxsH8>tT=״a&­0V0ZM a-Xl6u3@Ѥo#P!o )̬>'~kT(:#~Usg=ztI~)# w +砕(`Rw&4qo%NiQ2|š*#D<$i:C/JGC~{gzѭ"&WN-\8-f$}.(dƙmXVVvFq;^ѝUPbya}R?حUuԡ'(!j7T6*n̶mOQ%#qs5V͈ LVkw f)[- kKԺH$#Z.>PGQN׸njUu($N+O^ܵQ+QV$B"@@Y"\vW8oр`w:~P'<~.7|b^f-hⲴ;FL ˺aş2|[T@S5 *&nXAo-)̖ONsh /6@nA9u[QZZr%$^͂0Ru dGWp/]un tFӸ{֊:gF"LMRkgWBjR銫qX>K|OKTTRJ޸ d3MMhN#J0xDP=jgW!5L`LK&g"h.yJ\-_L?F"s{JD|/GXo3[({T.#d򁚊xG; Ps xEؼ|DƆKf$f d.hMx݊L0.f@Uq D`#WC:QÈe뿱1f)'Eߦ( 5~SgI̹ |O1C. g Mego1! Gz ^.J.:AB ei;Lz%(,ώ(MJ(Cq. ђ&X:b'P8#SYӌ/";$6q[z9\tw5c!z.|\#U5x<|[n9k"Qt'/+#Hed޽+N2:+xS.yJ!KzwruK"|تHֺ7giku韫ٹΚ#W' `]W=^lN^84]8N΍C `x-}t\ $ngvՐlQUu4wGT(+w9YOJ Ml#ˢvX0T~yWÍxz^"a3i'ڲ+A+1rDR\`bl@K`]P]+&߱]o~l^m;mM5s8YХ+mRT‰ia1:;ƞ`m)_HĬg#B63xЦC"?&P&#ZdlSiHұ5@Vx50>GLhJNaQ*HiI-|FݱΨbőucHiϱ~:16Ih7nQOlϙsՍxtBuYoFJu[ʠ8wϳTFj^;<+zZ/֋]kFv[)rSl!cg_D fL|@/큦 I)n!V*>t"~2SyUV3ZKPw .;dr౐C,AHEerAP0>vlhi -]ݞ" %aBV` 7_`az*;DTbg+̟1x(n֐DiVGY1OZho}is1͝8stuR&'y{?93tѮvQ+;U[2CwКW;Q`}dM@)GԳG#a 2%0i$IKJ )%!w~ކgU.} wRۡp]PPwVP +d~NJ.JIET8TIӁDxUI#'e&pGaP8I]L(ey@Z{ʎr7X~ҢȂgȩO6G"|jPeG$W0. :ej~|[-]IWl'2t .aG{~ Cj_8UteԮ) 4UF (r\3'@,ڨNLTC (OIƮʯ 3TvjX1ϭ0ҀsŌ^k&R6۶?|Y'?vHg}ហBCjqf6a̻Ƿ>Xq}Go).즴̧aJz 1GP(5w殯 ?Ǟ|$8ه7_›ZPOZ u}v>I9ԮD s$BFkPNHힾBL~V`pan :?3yD)BT2N)c4&ƙGKԂ+֠֍ޓ?".?k卉Ǻ$vTg5OOAU`+Fw!zσz9A70@IM"\׮Lc'&xlsޚJx0pzJ@H4Kg !a0eRэ(Bl@DuOVZlb=؈"@ ߥHoo5u`Wɿ?S3֌6X3o +%R龄eP!јV=v62ODW/fu=S:p;g+ RdΟ-IfNk݁*xɤrolO xN=>A0! Т:wJܖ>ZK]=e(%N bia h_Qs4^{{Ln&L^6%0N Y(K/_`l},%(ۜ$`~npAekem7[ 47uΒU69KHC?4ji{@j2б,fԻTqѠpampYc5#|EeTO2S?hnI.<4{)g_8X9Iݸ;bjaIe;GZ0]w Y eXW ?1o@$5ЕkzH )vҝՈ4QŴPMEReꅯ. 1|ھ@,٧;̡ḷײJ`)6iOI{0L2yD5[.6tV)36 lE6$r>Ʋ6"$+K0`> &k? 3ZDmzQB">mlcu>FS|dM@׹Q Z7]KU9{M_?5v&`ϯW~AQ\E\^|z?tѡ0\%sG%k@4u5U DM@$tن*!$ ; s/&XC8T#P#O2^Tz%)Ձ1{p)V5R<&ct`0o>#/t l@Q'{0}!JQs6HwҺ\C=-@]4 DŽz{3 M]ȵ@9f&ܳL^A 8:GltIT2>P%2a{`uZU''嫨;[|K)zՁRO8"^*}Ps 7?J }hFҥcR]0+4*r@$ibv(NF\?og*]i֕D 1hTٱ '0X@ؠ;P76s m_}_ʭ>x .r>yY*IqjtjeB+zWs'mڭ7 Y1oiqB;:]{/hLt{|A ?nKI;?ȉHZu?GnmŽ9@FW2x#HZ{~åaRڼ5a^l rłL5ævk=*w3?l46Z3ꃿBSaM{⸶\7l՚eq%uB'%uk|$$bUHH:d\n&IbSj[p1L^]x]6HS&A~&dvo&"b!tyT ݇'mZ19L&P=}He#V; P$eI+ ]$w9Ywj$",#۔o _Kat9ס.mj= o)Ay=-ߤտҮܥO6=>u[3z7A0v]䯬.^MZ𡕨ʮvQ!bo^{A7!Rpb䁑/xܱa?aǛn"ck)9ܪ$Dqeau%S:3wG{w#Y'/?zCۂSI3ԋ+H=/S^ 6g K062;U'rAP@7EK6y o'Vٗ&ѫW1Rvc~&̓ߛS>ǵUR ~?fgPdb*,eIkDf({]H8_\ #bhEF-'S 'E3Ma|h}/)qQ[HlyƂ]6$+@F]{X uFfZ^D5sGƶ':V^ VlYy^jdJq!gV IY4㼇T߸=DdourɏJl D(xQzB#="}/S`ۣC=ٌ] 2@ 63#ũ65j=(PUp 3!)<\"Ĉ~ο~;g@7o|qiqFINbJ0)u )bק8di񻳌?V)6+$ܳԒ2:%3 cYyŒ3!HCڝCjA3PD!_gVdl?%,|HI ]v"@5#m  wۤ /j`QvFK;VA0䔂2b2B\Öuin{@+bd[9 z\XSK_&9ӵk_g箨 ;W/m#q:e.hl/TK{9 TY( c߸1椴ޒ%CBsFYKz=MoLWRwnGM9e/α @U%?Mݤ͕ch" Fd*7HU۹^@:O=9Ĕq$ΙfmN'¼QQӃ|St%bM=Ҝ$I GFӡݚaN $]z #pGG+2doœ׾یٓ{kRľf@/:?lc~~6rজN씆~ˤx6L"vi$,jM/H>c<贤0dL/3$TV}p򨀜m;$,  6ٗ:$<559ϺTfB Yd&$(DԸ ݽ#*+ ·(fGƥ!̥KG d*f?:kՁ`jPI+'ج\-8ZJs a:B{sH.RUI42B?!WV<wАt 5#T޵#|Cm5̀IXD0̶x.NLw &NhXmK;noaœf-ղF(?,CMBE+-iVl!=SB2L # zΐ<~Y8Dn 0W{ 7YOV8kq5u!eɬ)dZwEF}w#'<[[OiY} d'$/8p b-N(tpďDqqM9.(wMh3=?7n B()u]`B1jf,GG_(4nVܝ@gn!n8c|jwL8>і bY ;]0ul!|>ӇpUE5YE4ζ.uzɞTp5w0mAI^y!ܰŎpkȉӛyi[j{ yXOlno 9}{Ō/ԡշCYޏZ.k]ѭI&Z Z] Jq+5:˪ٵu tJM~'hɻ$i^FJL%` (,$FP ; AQ[Q~vm-$Q[ d^3L{>PP<kS6r z=$a͞NLXr("5M+ ʋ{G0Fe:}=vr4\ѩ"ˡguFå~y2Z`j\Pq]6hݙK6qT~U[e!=xyB:VBIIw2!{W: VM'嵄r?je%Psw/JSիL3Za*l*I%p{6;El8a#y1D~-|tZ6zP(dyPɱ/6MXJ%#{`^x0#%ڲ},G !Y4; &mD/޿,5kǭqU9|ЗEJNBndQ@%{Q/r_~0e[sm,|8 ewY"R&L#aqv8Ut+2_:'&џ}{=Ds]9z*T'P[ L\DwHb O~}$?>,5d8{N'x^\ψ`Ȗ쏢QB#Ӛ1DhdrA,ѝã1@y bZO,#nZ0e;wr *c^jN'.962nqWVFҝOGF|YO8U[G$ HvnuD%UaId'~C`biJ^͗|Gf 3PE"Ü^Zqi-cdbюec-'HjP7|/9N?GTG8،K4T:V1 4z8#qm,,962ČiF2p}' m"]+4\0rLQL 9d*oނ FzJˑ9ĴԐ8rL8BFXDY*VTq%itpUzF+/HP+ڐUIXk%v)oh2O`p72ޔy|w{MII)9jXTO=>c4ӿkq7Ef&9kNCb_* Lf[|ޛbSbAhO!To>FTW\u;63'lyxO gE˓SPD]YD{#I穐+IO5^F?IB&ʮZa7ֹ'vTB .by醮 Y*&tsXedK V+:F2wuR>xeʗAnQ;üoŸ'.veⴋ[cX0UnJ\&~ :lH shĒ=Qbc ""hXd}?/ީ:@ޒ$]/^ٶ(= m#NW m1}ꟓKh4F^߽ׯO*(-BMA35'NS96,|͟׌Yo n8'4`J7Cg[Mw&gT(DƪEb MEYRݪYSCg:;!{"Sm--o#_8u3%\ݾ,fN~؍Ah'P`pȞg'My"dʠkjs [ ۑ}VORfZ|dfI35l/bR _Q脨2(53Kq-4ǷIh2~0=0P,= '2| 9y/3+"0n@V%K$$_IoK/kx} 0 OIx\F[da߿)M`L 4`V-C2ӂo)fMFc玶M8h[m胚'{vc^#a38vKj NڣnȧX[WCZNo a :Sl_CiL_?6<z2@Hs|fEj6 aPhfjo"YbVUc2[ ϲ'OYXn9ܩ}p ER Ķҹ<$GR$ r"TZ#Tы }f2 INol}Sk Kɇw=CEݮXݰ x/8 8F6Q^9:#sh..hn׹\(M1Vl, ϰ_A^$!hRE=݆4m$}#Wqc|; VIBo(c-.EPJ!#=ΖP™Hb|O-̏ ㍡KR]LAAefH4}$=棸 D4I ;w3!Z7'<7C CμÄ; :ELA̦]4 ׾BG<r5NN ܄2t1),s)ƕ#jZc4Ul`ȳ*E )S` 2 6som\(m߇R򺞶E]8!Aј/Cq^fUi`MII6s/= MIILu#Ag<tpE;33Sinf$`{fQsq`z%U<Pgi4u ό^7_ 5VgDYy[b0_ Agpe#Ți"|6ef$rq&tDGN H$n-x_)b|k&FB\/Wεʫ%"e'#Bq=qcS2auj72aɢחeOK~[ObdGtBW|7D}Ɗ9mHN7jkJ:Іl1{l:?z\pȀ!D~=&^w@8a$%$Z<{067yJP4_лZil_i KiEw"ڨƳ^h}$w28pQ 1kfuɹf֓WHe5?9LqD V"V*,.SjMDE<T:/k/KK n-,t fcș)%-H7`7u)Ӄd5qwķe/lے~k9bh}mxy$<ߝ#d}ص G%֩UbMDnSsc7987By@N;)p(Xm\/" \^zIKϣ*@ ٕ\ڔ/8%z/QF|źnj4[D-Dt#wfYD)Vf4760,;hIdJvY2C;J+܌p*bLXéE4:ڡi޺ӾKۮ]jUS؈x*_iT /edPIs߹*?'Us S(/nWQ&f"^gzpI+%`Gg]&:rr|~^<[?cۻYV*YPH@7y.,s{[^qDL}| OJŘv:,*cCڄZǓeĘ qg{;2 \<@R3ނJN*CX:7e>Z-0T1qhY.xM0*FH Zȱ%+#X99u׈tT&d)HP@Z5 {淫JFytVWvgFIݫ ɶϑR J}h%"[4h=&.BEbi)1 6NFȷNj`J^CSeXU( ўQipgdqlr&9̝15 s%-ل9A3iQ6:I}|(=!6˥"!(kg,H҇ùz cO WTWs{9EXVI%sZ߳6%@p 9G"J)@tW[!Ow}6eh8:.rػxCM&h7BM#yW0sVp.V4@ȩ7IЍTF<`,K3CjM׹P~ɌE#k_Z"|Dz\6$dT8*Z?[ F䌏MlMo}coeB<!7&F5 yY(#W~pi,ՠ3{嫼\kC}e0[7o997+60!g$]rHPX[u ZY K gćo}/D0hu5qij$e&}jѵ˶ E ?eTA6rBV01TX( =bl?k+dSoe]Nh%wdkd?KosCgS36[&!y^AGLd<'f;-;1Dp;WudkT/uj 8̍! [t >G (>)l!3 V!XRD:W_eO9jƠ`߳VX"Oy;BҨH3R/{ "YiS‹ɬ]sЖ{ņżf8>'ȃ*> <6eCnJ'0m͸ M+-Q{ 8\:.֨#){V_'Q'382sfIгb!?=?>*H+TOz+jF79#ᮥj-0ѐo95S5Rl+ښ; !5Ӏ99`T ~,:ek8~2p|f|] vђKpu ӟ3oW}9 -{+- v/o;.o~]g[Osud:pU0p wFW.t6@ϚaC?/emh)1_q}PWb)Mlkg'lĚ: %y2z+;(ug5sOm >anˤMLΐ$f:Dp1Kh#}UMt+w8ޜ sd^\Ÿ6`ouDc$ Q'jkfowȦCL'6 [MMEٌY Ycf{wbLn xܲb3fEW$,h :9}P4ZA=0Мѓi\h3s wLg+bM W +i˭ۡFf>e~ۿ뵕5bch&D:|氽iF: XHň=*T~#f0$`e8^IMn~;h^>`6s΍RqUFax/߉7ߊZAЁ,^vh)k)7fܕ"}mo$(jfi$-!'ߜ{aVEVӣ]NS-E) HԧōS?6? Ha36>0n$C"RnYuK}4+O8\fQac} xHTηB}Lz8X\'f9%%V`ngDV*yY٤?tF·C _[o7j#_yy#a"gX/J"s} i~ {iH%fC|5ˌir/|R$y8¼ŌOv2̸LG.=0l~s&\`R;#3:/KoGuL58MǞ$eȲ@+ݱ ,$nj ݌T𢓫:ʢ;qR)}W2󦻹C9d`qX/8}-MtzxA=X02Ih+6L{CE*J^y a4{d7}ک ˞\Hp: 4 ޙ]}ܲ՘xCjN";;+E\IHװ?NZw|#,ݸQ`F|/fX_-f} P- ~V$s#w.t+ڤTNe`c~FB{]f(p"?N$U>N#~ 1y]|_FQ 5NnmOskQrL/o I:Q\יtΛ}VbPj)Wvko!Uz Jי/r- PnS?cJ 7p&SK׵)S{Ϊ"zO&0AK 9W"uh;2g9Vt t}o񮨸I|=%^\.Yz8e5Eb0˻ KidQjjߑb,c@ammrr a:ֶ$Ll0\1ryY.Rg4%-.|"O9n;i@$pWEɖls8pv)' YnQ ۭ^TF?А챃 "Z(axޖXD7MT{xy};!F$3pҡ37g9((Fђ Xנ.7:OtwP\MiyΛY><E=-a) eoddvɒmPaq7ӈ_I]jd2ɚǖeDgNw&Mc/gUl"S-M9(PƜ{ֲmԃ\mF&[a˒n96. 2|RmpxN}1qRǚ_8yn*ŽVhBc#ou RAڨ F\hDOҗa)qTH@-%VKDLdШSVBX#q~V|GE6IIT*s:ON!EW{ш'0t+}ԠGI*bdlGѽo⧴]8Z˹gTߣbtIEe#h ܙ8̍{dOAqRu^9YZt]t;dRWOI 4ۄgYh|*D,?ŷ1EΓ,*sxNxް(+ µ/T:0_+L` I<Ր#V;fu@& J7b*(.g"4n`pGቮn/FLE٤Pr 4:;vWrwL>O]Y5jc×wnYA5"J_{yU@*/nta_K5FZC40S$YK: 0{J=m :+oYn^1>5*Y$.oOUw'#2=2S4 -43vwkA0T* ^Ib/l'@W3XYA=d}jln䝕#jߵ[/tۺLȍFƏey<m@yj2> y~_NFQ8,6ȳA ܝF QK3" +i۔ZͽJ8BbwZ*&PWOmi%[N9w eaU|ο@ i4h}Ж.(\H Hlj,Dml2q p[?&}'I}8UWxYB_N8AAd|غ]&뇺~__|{J|BTV:* *UVQc- iuJȎĻo"Ě &φkl]13;Ou¡QƩo!&´P)D8Kg2L fqg6#R>5ɳ:R­kǸ$iTK\^m}g*\" ;kJ鹺 rHYwED}6VFRUT}'<`-9%]ҸbCɢ*el_F))-N,󑠓`kCq\Trr]-əpi@C=\}hV+yg,Lj?Z%#]tu/5Md3`iA#Uߓ4ȥβ2g(fZ½XhxX;6pSRjj#$($b ,*Z )0CEVV+YеM3Aٓun;q\Pljw7L! vS6@EDzOL6?^Qo;2"ad>)=bL1,z; >m<*.R?iI+U?Uq5ԒjDkTVgᮊ߁zzBQHFcX| MAv -# }^RĤ`ʩw`@+(9=LXO[fyS{0 $4-14bv+Im-gM5ڰ=Y\Bݡܑ̙XC26_BPsu*!<ene fgsB̘d@) #.FBg$f@JnVC'^} `o:fAuJnQ }`Y<9F[ w󯒯Zސ[-n1QYPn!cjlNֻI0# B需W/~$ {`g/y+CV$L]Lsǻ%mD=SRR8!gI5`tt5-A3W͠)ĹD Wi1Ыp 1S,JA&:'Nh]6VOҥv=+G{ȷU!0 X 5yq1dY"%8vշʕEbՠx>BvN.7<ͷvɍ5~9S nL4ە>~ÿ ~-pyZ\CB?zq3mgmw^ܓエ9+%>0#8Hf~q30o|VGL&oaGگjqB#ZutU]f&mCO++Mk:i:7hد"` h kȿMHsNtg( ʐ!P-f Q{o`)w "QPP/]go0Ӵ߀'`A/cDu<;%Q) B|cjy1,&-Vۀv++VWzS؜0q''7)b qe,y.LPtiU.9is\;ߞ,7a*ievmxX$þB9C>ڤuOm.`&8q%A!Qcerp=KY]z.\$T }~D;[QNkGYb-{bnt;Ky d! lT6: -0@%MBGBx /d4E W%D~Q 7 -}S!l|G9#aӖ>STF9٬|X0E//hg ˿d/6RP "ˣ$*?cܯ Ҫ@hE~ Yܫ*R*\C^Z/|ϡ.w UR8NǷD4GW孺im%7 [nv9桏FD+^J1a,@Sz\SқV/ِlP줚H7!r'ژD&% 6)~ƆQRj(9$짝@砍춭Y#7K/n2r*CEtި(YLHB15:`")F.58]tvR܁/oO('*H)`}37]uƮaP /mFvshm!c8p}(oiF0LOՊJؔ|^ZHDM S˗Ē[K/ xkdJ|LuBO}Qp.'Ꮆwqnn2Ρ3yl[K̰Xмk}0t7HZ))1=`k;Ik`&_;ٳY)XS.C@n/-5 ?EU]׽ƿ2]TQ{^2xq%e ^JD~Ob"/owF}AӦ5|ZG;b1N+\3 $,e[Yc4t_ti!6S0֊-X ‘Q;.(de$U#;dR 3)i1UҲ}nfx$I^ݴy)gS'Pj$ G|yխ?{Mʛt`kשIќyģ'ƞg6Ч=(;y` Ǜހw*a$-킜Fd7RXw\Z{? ] vT>`w&\A kZ?t-*$h.= %FDS%De& XWM5a)7 vN)ˈklwv`$^ց Eb8˹&D| ˓E['Y3/r{!g,h:Zgr:Az3I_Vo>&r@R >‰}Öu@mA[;H{ёV$He/S*v)EQEC[I]lMyX۰SyYsc&8Yݚ#W(wr'H ѰkaMsY}C" 0ŚnakSRy+,8Ay+L )AȳhY$IrF. 3{ֹa$TL4wZ΁Zl8dg ;af٦I ێC<b1HV[J*`t$t;c➗Xy/7+vw+Bhk9ozL9de86GZs p8o!`M,^.gW5_j.˫}į%$|ޤK\Ynxi[3<)(iq7B(~$VLcKLķI2\p_ؗIANQ}b!$NXuiUgN0-~ ~=䯑NfYzaź E77`CyBܵ!j]q W 4T=XM[M=$j \M,f4 ;_Nuk/iRc.TvkG1ks0ZAovDf XcÈ}>p|#}QnCxo^`=l0_n(-U )ДG,\>[Ufaʹa; hLmyoF*}ႁ̸h4bi5g}Zbz&rM65_=m,o &oz0ٿIJX]`'oV4@6;6$<>vpV6$rT'vx=jX8ӕNLEeK ^}+"pUIFY#z5Ed K\7E 0q4ځ+]1(gsJIv(u7̮N9^:935M A6,>DmsSyA܅jkLۚ~4h%F"`>!"Y3t̖" LcT ƺA~TQ3þm ^=CF6&$LͦRr7(d6TWȤ^. 1K)_;nBGY.eN-OMR  T$$EңXvo ܈A2ffY~Σ4\f,a^OEm &0fD)Մ7= (EZH9 6JBRN5DR;N]3X$MAҘ=땺{ 28mkGjqrLIN/9P} ,؍{܃\?; {3z G3[{c/Dطݚ{ 8MƬp77~j[)˷ d nc+9ᰄ }zi 46F>!Tj 7WsbP熡AW8cJbvEX՞e_jzodxdmh '}F]J2v bMH&P5(lP MF_s3sabsj@@Aahm`rY!֢l脁QCRzWOg s3 穦fK Sx*;E :"#E?øIw *R2nuVmp$whV3v'WTWwK7 _e96'p0-os},7zh<Ƽ2' Ab[|iIH=@Ue‘`ٯ )(0Y9?\OGQja~t(v"s%JkZo,@ң}#ј|T*쬸u͓'H&}  r?SY:=?%PRͮl!.L[395ٺG]\'&\ [\%8'rrhhwƺ@&~M PڵW uf>J0[@~j)"t̙iO_-ea)MTx8Y%{G Eȳbzq]X-8QP0gQI35G~x?8aVW u}hqYT6-/E~!!a=rEԥN%i/;!\}IIb+ONlߞ8͵gk}aTdF[th>mW/oIub0pLydw)0Y2,uY]Ѵ iSAi TJ.-$ ᴧ\fL`zê.}N?z'><{Epe{ M]1Tz)%Lۊ!T\9w-o`#ph(L7y8HO]f@D/DJVz!.) ؛ZsۜpG1;Y"V >2yX,;lι{W<'[2c,tCzKk1Z-Gx=Sj%BwF?ak}tTIʯ)𚇃 -Щ!jfv .\/UpЧ󝙞'x!GE+1"WI/'(e_]JrE;`zF$Zr HqɰG؁u/k]ݓ4έi]Nzo61[Tz ke78@9e3)~6M Cœj*Fț%ʤx몇`sUo1$ >p i%M`!0H 'Fȁ}IeXK2=rL:KP˳>5iG*dqUp>B_+*/miȻf9V" ( 9^/8%|M7ע0F A0GM5pUrqʬչ?b=ʴۑ3]?.)bƷEB_xU杔{} }WJ#T$-n0` VǬ 3,w8t4k D5̋e_U*!c9G(OlV 48(S5өC D"r|oB[2ؘd"z`v2|*\t-7krdj()Cm2 =x)EUFK`mXl"S :eِ|\Tff8$Lu6=E_"TuAV_Ɏ~cc)| D.3kgO Ƀ 1Pz%o|ӱry?VڽM~rx(YJHVfqlokݔ,iu7J!] Z\mW1-B!Rqy嚏Qa 9D p4w&9vme8Ӳ=ci#0>SG4y?@#hFe^xbON;<`5|)0p b+l]OuY Z6+w=!#?so)B+<ﶀ ]+T"xힻ3+%B^ 0 '#;:$M9jnVOez Yx9b z4~LfO:e}}+r6Bki}*>\c)uV t@(OeB]6=j!vm)OOv*."ǁ=ߤ[z"P{uP~17́K^{ c249n<=*jM}etDBSMZ TSv X!Dl[UC.y6=#%4̸VR%cl쬐u^;Jjb;O:rNLxedw엣Ί Bm[}y2xRo,@mROmp~lwlihm, UQU;^3'Eu']+m> øsKh[kDEƑF4zg(k}*]7uVԓk͌Q>,T>lժ(Uo-aټQD%"=g %[!AY+ Օ*XZ1],>v55QngC}N2Ԥa~aU_UPqYo҅ę̡\XŌ5yW)?WyQR\_c};-Q<{ZT(yyïC$eMRLd!Inq}Q[b6Wf9eSi. fv (vԦI+{{KuUnOB 9Z=]A({ $I7,ˮz\L;8&Ϝh*@+ab9W}k8i#[na""*aUѰC 1kh=r ӘbkDsgf t+ &goMW2ZQ?ulw} y.Hv&ryhJ02]EIٕ0>;D8֢{/=栵x1!SR+11ab+|GWytLK?foIYSYbiHy]ɄO bՁLK03qGkX-т8zN ܳ1!bvzƦSŸ:%Kx[c*aۦu׎Ryv?׋ӻ2y6r {\ BLsX[9I33=g`Puu|9_y5 rrD8o8'Voa}xi+UGB@b{j .OBUhj0hߴ7 _CQ<reوxT'{:/a-O%Qw뗔_T,4-n򹚤51iذI{V^kUwBu-/&D0 t֋ Mw> c:-vz`e>l9ipxk5˫s.? O6"xF~o!H^#f) nkADf7!A&y_7n]: Jc v :9{or~"!i 8TY|.ݐbo?k黖]Ҁiї c@MEr?u#sٝV1 z_oF#yx2CZG?};SlbAm,(#ȿSں-B㴇[`EExf{I۶YxuGV Uemd |Raxu݂l;ʁg$Z&g|O7K+nQu̓LC^ƾ2?v%ihbۂ\$h[T/rV|K+D΀zDPRF7sUm)FTL)n=/[`w$XTU*Y@Dt ٙ(}ݑ%:t& Ϙ)[ZR}aWȖlmg0+jJ%7MZME%dDMbȗsڬZڜ!-*X/!2n1?NjGdEygb4 4l!mdG/&⤬Ր H߀ i6/ r!hۻ+ZTwjY`n\Lc y0o7:Ym3`_ ~UA^)^$|]x0 U44sEly2~~am~ ,o6 !Q>/$˪t7 0o:$3h X(.֟P`(D@j^YL p5N.E:r,!8I7j3,RBhAp s9]JkKN(+GÊPQ. HSϭY*<͐78Tql,\[Eӏ5gμK降WwG;ﴹFWmlκh#;!`  (&C WyHA3y>dW8Ci`U0Q\A2{;=gvy|wK`z!Xief臐L9F 3WkUUE0 \- D0-6JQH)a戭 zB )L#?8SG.Ie[<>o氀3 w|A-R?L֞Vt\ ]= GJ"wKZڧՃRoL ɂ,~>ܳs~YA~RIy1C-Xi\%d@[}[㜰 +Ў]Ik (CGArבP8e0q +{e<i`﯒2FgkI& kvnuhW ”;>߈e8EZe#1vb'1鷮PfzfGZ(1"\%8:a76ldS{OOì3=JZB]bYo`B?& gf}ɦ3Qebwh]عFKv wQ7GGWr AZP4!XQVX~30h 2cz)pp(FUtsB-֠;%w~2Gq+jza?8:!A[Zdw .˘s4*0A й0yi4 sϏ ['<91K$l;J~ '9N-z']w)?p#SN=i؍1]ЦnF4z鰴W)0(]JlL`"e;уR|>*zL4 =>?]}U64Af)ϼ/zC Qw1N::Uv:gI؉G'lpƛƛ>xw.Pǡs!G'U1@`Le}?i~-c8K"_CWHCD`Aۮ&N>.Cς::&\I?fu*_GٓA~GO3|Ql u. wNQ٫9.b+fWEMPΆ,~OMZkjZi]c~C @eg=5 ?Fm}VI͕QIGP)̦I¾dѯ_88Q*-ܟ h3sSz9.8$1}~+}=3 J0pj q#ǥ."Fb_)'q(gkSbPEY47('C0S`yChט o %ޯd*$hC27`aTM8ؒW0 8j hGąR!eٟK>o<;%0#bJo)" Lyh?c-~_C/<2? CS 87J02맽)7)"yw@/gn9d" 蹬 g$d֝Б6:6 k+i>Yw/S-&$뾤/e/Tt((2ü&ihwb4P2xDžvm,]xAD:)D|&^45_'4(}3bQ)6?]Y@äOCÈY ՗z&LB|16XsLl"A!P!>M C.F2汈FlJx1f.*&;jh˕ ]ea!0[RtѶ%P#UyǶ:++:chg漽[Up %yPiN!M`10?ԕ,B 1=XV2[wn̲+#d9ë&ĸ+}7]`x:.)&ک_{jPa"wT *~Xv%buzqhbVWOroAQ3pgfAa1;*}9;3^=X%9BaRq"rT AY H 7mn; z`dF<{<#awY$"N1k'u z,7(OrDIH p Lx<}%R-_N?_ ,(!B3iF 0 i83Иܨ%Ϛ:nܤJ=uFp:0# @z_TcI(7 H"ML5б'N\]fİ<4(4D$x@ zkP^%6n_>x8rɇ,ǝdr6ϛﰩm}#m131| +hEHTRxÝK"fE}C}ێ=9JCX!Iy~ŷx3}!\9#]GY2~¤8w;MU͌[d)6ZaU9}v;=u4 ?SPEf1qzk\ԆaR0E(QV-8=+Y5B=Lp mx ! VY@{ EM}`*;.VLMƢfltZ 3J7lzaF7=>]=n 8Hܘ]H.:fNBǶ.Hj㖩ķ @_AJq9 UlrS@M[~T7b^/m 8SYSR O_N(uDŎ S: KZJ#.fS8[>#BzY+B%PйTQ"zX,ڷN};dQX b/- +o;9eQ)X@D=l0)Sb&S1ˑPR؈`8X[x*.]o˪!.a ">9[D7u:g0B™/iE k51+eilWykձUνj117AhZOXw-=|6Ƶ"HV _Du 6]IA7Tis+S\db0v0vcb߮m4 $+&yy]YHs"밓D .8QiHe@sIrN'~d:LP| d>⊈›GΘyUߣ7H<H/ObkMPl QHGVR/; r`J;2jfN-_tSl6~lY㩷`[@郉pSC~= |#kc$-J0V=C !A@:ӬQDVk6;jA4 FfHlr:$ _xXFÄιFoyFX@ˑg,(-] Σ.V' ]KWnr\\Mo б"3Z  1 p T68 ~1~@?*b9>Gg.0$WE3ͰƗ S˯Ks2iRC-!pT""U$ֻdFY(, AirIɩs XHt ͽm LLg?2R1J1UAFkʸ5̃ {rp2_\1X瀼S]}^@&<'~enF-$n`;F8Sf^ AN a c I U{5nEKk>> D$4cy [72S?14㴠91ߒǑa]gxF2Sx ?y} M*_s4{)k Gɣm8#cr!ꙧd|`hlkDmt\v@lu;שּׁC](l)Oم/E.Pu~+޾u! mdVGBs/EwHKXU_*b9hu_:DdyhBa:&,dqU];匯rZj~f}.M6/Nԉτs3f Rh_fPg&Uj5?i^H.#umǛob2Rn>sy[dg@ ֥X^Zx akaTN\),y7l?d6ֻv(wZmEd,ڸ5w`4o,j- x(j] xWLGJ:E硽*.hN5})@}7p騈 ժ`c m0Fs(MEfYGNfN^i¢s7u3_9ⱓ'9,׷u!\# \CA8SQ|z!0E2u3[9*gnsxJ^u?/hPJۑW! WM9pl̕]}KGNwuYCV a(?3B|pT%nV̉59fľl4׍jʛ,.p8S O$Z7rirXަ!5ѐ#J+y5uhD.i)>f1U.ėrHȸœ'j4:‹_e{ T̥ i6hmryQLP dp$x/ن_=qiធe(2X3 ?-?Cɂ+ӖՈA=pc']YXa MթW mj+aeac,fStC\ ;ӳm9亢P>MO;KVvgj=޳ S݌H/zt=^0\+{ȫQ!ўB|\xE)SwK ݕMr&?u b!HEm i79GT`Z[ڇF%/S80~)\(uM_oG| N0Lx5+sE])a/\DfԴ#W|̇dyḮCEl_Š5Rm8Ke]YӉBprӱ R॔)^`tdHo k o+0W/܏:T4!uW9 [;@ZŖo(ZU >rp )C& #e'ǝNs46@C<8PSwv~}@i} "Н- F09{7h&3n4ukɂݘ?@6i"1/\A=W0?7%ژH-0Ŏ>ByJ@jZGkXQSEf%4'<~{e)9@yYήєjyl:MOA+hb^b 5q$Iir5Zk!хM!4" a[-w+2(4{;R `kk}=zNݼ3p  NUɘuWt0 (˸Nu@xU2&XTKo сλ /SzNm[Kڃ,ΞFVe(<QJp`pA'`m M$:Dz5&@j@#;nqi0E^nfLt%oB0ņjڗF.D~$(Qf4l/.i0L${(h;mܒ]vSt23zuM1=NBJ/%3 *ʽ[0ۼt{լ˿1wuO}[I܌1Zu!Z` \sJX{Ҽ@Z{ޤ_RTiܭoe?nÒ<][˿N$N}f?eά{U|I\o&5uqW{\șRbdQ7nk2N?#w2^|ᅔC?RҚaT Sdhk!DuD5܉]ʭox? hp@bbDc!̴Lu~*WA9u/☧kP8.S{򢼣MIH,~B:?G(&,ݻ !H) 1π>-vFZ1mÈxiB/A 2"[~>]:wH|Bz@ Ѫ \=]2urKزtމ|࣪^ImPMu֧ͅ5,A&nlsm<]Z7q]דW__|DDx\Jr$.=03%-)JU@x^vVf+ Ƃ61O-Mt,ox4L unk`%[2ތXӵcFkH^3gLq\D)C p}mxi=b⾖kiab#ʼneVmQR6A*KO^bA>bcsl,Tm #!%{! 7>'xҹ OwOgZ d7+XOb u݈Ԩ)9w+zFnn]QI@3nƭa(l@B~$_[E,7v^ ICE{qiZe^.<ǟ$_S< [QcÝF.S53nJoOaZp;fQ20A2vN 7 "˖Ā@'*`SK!£g;K2ґJ,'<')Ǔ>vFr N 9]p77[80J%H}rU\N<ާkXqmqcNA i[0xͣBJůHvrV:Yվˢm8Ur+Y{vL9bY]YCyq6摵 VPٹ Y_U톞nj@6\1"9I6  /o^)8|_eu?řc?xUSq~_?jq4GB0C^Y$k$P:W&Cz@l%l2[t U~ %lUh{iv"םn.kJ,wIZ'Zig!˄}xy` H3.5F;F{Y"rL>=Xgs]P1Kȶe9(p!-ކdu]2#?PZMi,@D&j :IFO%h)èap&~HS 2jX.閜Z &\nO8ct :jvzϪzB+$&+6hiC[Ђπo |ū^xAfye{RP"C 95a'Pm>[R&jkxΌY1ZýW{`1$Jff0/켈 C*^EV7q 7 ;aZvӛ4&r_gĝmN λ%ķJ$7E~+K"q[:{0(h֏ȩOFc -=+ ΣZ|_+.?-XpcӎnM|Xxx0x8~TƻBhOLc\5eX ɺn"8lOۏ`{#yB4f *֢,_K=A(Lɾ^ &P fyJ46kt/b,/\b3ujO鍟KtjؘL7 2i3ܾ,wLvYd 2ߙnۑ~ ["uXHG^]XwFp`zpDcۜ'Ko^Ŏ{^La)lrl@8hűF%8~yJ y Iʠ#`fDAZp\^(SD0`@zu`HxLO.0ny!PLugs1k nj< O ]% b^nDJ4~Q}{֘!2ܴezS&-24Q ]+A oJD3Q 4?%>f,;TM  <_C|ooh]$njQ-OvΞ6e-I}Ga&>C5X.ͯH3\c|}=>8І‡kah.9@nqȹN12(Z{1jn.f&8[/ /+7S=՛9iK̰𗫏kaHǟ>ȹHFG NgiĄOdxߐHTMs[)$7y{T0a]܏e*t09Y zBv8~0o.Ƀ4hG7nNJT+^8{0!Oêm7hA G:|Հ4H6' (;dl0= r~}"1;ق&e׏xu4ˏi `u`Ҽ3IE7gHvv/|~|VE-NZuJ*,ә}p$1pNC1N<].~Jҏ`X#&K-Q*Z!t]ңpgFQ2T){~$=kRS`m j$Df-9iN6*4F'5#h9_J*kh萎E+v&oNK/p;f˝qFNTt<ȏ0N?;vh mh>Ka)c0yˁZ};2ʊk Ia.|sȏU -]ـBPǐ,]cۯdomBvf4 id=})"$"s*©ݲ.-ACw(W O[rf\P'_]E"Da״R?}ٿq=W-d7KVhBKп996-Ji(y\@eeJK(?C`W+*s8|EŨ6s ZMQ¿dv1ٍewM`ݜcw)TY=5gDVluKB&3~9f^zԲ)ێyRWLgQA\"PoHH4h.:_ȼ9{T'2LDAMj6jE)@H{Ƅ/w FM7d]Bfْ&ŒȡqzWE&YNk42:v -9[NHo|bWu͐qwN菨P(l}{G֦a%)<qg@v=B1rӜp/[?C T2xY?wnG!fRZ(n"YE<+OYU!YXU;KdzPw`ҊmSGqv%(}6=F\9>:G[Nqp~!Sr2,Įby2|a?#bLb/"rڦ ˄jiq[ޭލa%vUc*?ZKsI|<ɣ,Zy[d` ڏBQ_ڛ}$4)-ոѠk ,6!('|p%pWabFe''|-RIvOk/ϡ0w1egFC-x;]&-)푛|vm̋'lSzkvҮ`2gF~'.U2ͮﴽIbBj^!L҈3{5ȋ%#.\!F $ľ2r򳛿6'tr<صBR"[_<}9yaPM,ߠ FN(b:nvG\f T(J. HRM=[@8%0z 9>)/ 4{)!,!Gm{c}]n(=]a:ό7YwIrRF!Mؔz8rlz #Ўa3*M*=sLT쏽l!g> $QJZNXNO6Z߄8~qL!2Sc#y5*\7&u.㊢BbEz QN'RGjV'!*Gқ>sG SXJ3Ϋߓ*5E'"6n\yv٭ZRϱVe\.-JNJnqΞNsKF:P6K$a%=N-ߣ$t޿ iL1 rO 2iF&!$~0~ :P7 AYde.β]S^US+3䛽l ,$>ɩ9]k94 GtZ@6fEuթ9>ew-Z} ~s}=S V$ʵ/F봱ÛYu50٠~:, SZr8dt=plܩP?pBB T V02(f$6(kb(&$]](Se}]}&-[%Sv􉿅7S`v113vB?Ĥ"5uz7AvAƾ%y<*g~#m{NqB(9=G ;sY<> Hq(n bt6TqݷlPkBߘeԂHtY=p坬Efϼ '!)t WVXDEILI>''[B6n!=)g*JkV(D>>(ia"y= /_o@D~EL˔@6c&(TBQBrX6tNc6f 1 šy>M+:C>Wsa`8,;ѾUwS8$4T^@i^y= jh1d[`:[ ? };l0:8.R,.E<d$z5oU6q5:F4G*{ j_Zm;yE- =]U-ꥶBSX[rJ? km[IإHV#MUqXٔXѴv[6b[KHd٪[ir@k(bSb&k< &rT pϼ'ĩA-44/pb#m&xb&B9x~mRk_((zjiI?vw (#cJz$Ce'@J&m_&TTbʛ#_=K{ 'Bc!|Kq6hOB-MT c gtbnHh]M˕ IOTb& ml._`o-{5`:y1mlac I06bǜo{dł}a&BJ6>Bl6" 1O O~7~p9՚ j[] ̇ˮ-sdɂ:lWpВ +@ i#:Ҭ?Ex],ci6s}$>3 OBG~c-fu X*id/8nV{Ԅ⩭;hL::4DbɰǏG7}lWyo؈SmmEibl-Rގ'f%<6J=W+!K@/ f)kL:^<#~RO,h謎9[:1&(ЉB{RV8KIvG*R)thDBo=A=^/bJ<:5X4K0cEӕmy# ~or^0XA#7-_x#*S5Jc"g+lIK:XX{bWI[d\i ᜧs466{CaKVnof!/*$DZ%j%o\c\vg%@GmLx zo&@U[yۚX~O}[_KwΔW!hYt"ty/!4G`ƪV9Kפن:ANv& $YcIQ7Y 4sg~lm܇/mJ6%_W-4F@?<=b6BFX}e٢NR[ H {]I)`iyX4=FpyNGq+fS~mS|H)-*QJV0ݩZՅl9St6=6 EmH t?Fh$].?L!Hz:xWg$^&r[ѪXFŗkIaaFd=On7˽FF8t>w9̥6_5MA,+F5o4! (a2 Z ]m;;K⋁M"<QĶcljų/4HW_;I8OڅlsdONk4T~W\C, dIf&O{{{c.:>9H|xJP& ib]}"~5` 4L5X ^ 4MfؗUcy!,ygzę[z5ŕI`ㇶ[c(ڃgIN}T(a˂#|&HN\.?qqﻄ@'^+"3]"ENAu:Y:1nDM}8h2W>y -3w+,wb4"մx PtGm,ϛcX'ڣozZ2„m## fi6*,S\+e E:Z:'B_YrAΩ̂,.5j;,Y^@6JGhXCys+20IR1QĀǸ\@lFc) >N@^ Y,[px610Zs&Dخe ]~쬢,P=/V189pe턏'>jН5\D>W0R9hU7os nEHl{C>VgeJR}])hKW!t) `$\vTjヶM-T]?d|X9&/3KmD*űnnod|ȃ ioSފ Db:.u,<\1D1E| -O ]zCJc::<|@{c (AHW/pM`J|n#ՉFu#*l 8,V78h)&) IV~ӫUNHĽI2\ZS,mF:#G$8 lj$ӷ54a O%ù1y)(X 6Ƀ-ʼn}ME(i|0-,TwHtܺmxy=PF 50?bN$}ev*#.<`Քvu,8Q%Y)&zyt 6 w}[%MP=ދ{5 Q 9'G$iRe'w5S<,s8":{YTm؍w[E 6q--cr@~I[ZYc|٘ "ij P1Av.T`Q|(eQ9&@.NϤ.@EéNbfBf#1Z𞝤 f^(KvHNpQAgypsWɢ䏸Cwg1Kc"o5VluO*R#w${G&Mn\] u }LrI:A mv!aSM 2)"XG+SB+_r gF )AرZr7CERA7 @ۅtX"εUq^`"fa܎,ܪ_49椯l@*[wMμ| ֦*^*Oġ͈]lLƮY"k3s pF,KjVEɬGy"HnVWNk?L˰P'WX^O:Qވ*l!(B5U!4olV#ف0^KU휯cWp-FrU43$0WW8W\,-cޥ\py at@ Eq2"`X9JNwށ!el2w8eJC=q z,ǹ=[rn=0n#)N܁°.:Ikyp`?%k=tLall iwvXcPRJuJcwA_t2}w9;2?gS#! MqAA.ͥ ?x4O{oIt,=-Wp?Zd2s\T˝[zĶWՇ]9a`jzO)A6B,[ҶD[ޢS w?9j09 K h],'gSԋjK§H5@6δUrHUrK(& 3Ei^/͸3[I} C8ʕr4AƟk~<HъeiWuܡQHL}"@yl,ys\mU^ ,OvvGt2Qt:ŕ6;'A߻%y JHJs.FzxC;2P3Q4`_ 4%k4.(HjecE-lBG6"kP{nÖ0Ѓ8M@+*Yq#Xf+J; ZP`}[ed_jG^2WDv&-D:wdI##}Q-&F?aԯ bw)k lqlFRŭ<2^1q>(VsqSI堞%xq\tyGTZ_Om@Ar̂rajV/K]8mf" 5UYŨ/vf'ܹy36RlVZ |vS].n(S`%owTScڗ 0#@IwdHh7q;[Sbz],2 a>t %-ݧVעCb8 _%3M Hb T7{Ys\d96bd\G<l 2\zdJg)ZռKZ٬i6hC- 98ثu?mC3`Aҩd 1Q1v^mf M 3tf(S |>^!E0BfvҘ5&~97| ؚ8*"Ai#4T_]fҷ*]f¾)a ^Ϋ3:InQP9  ]FGCcSuǦX93U;ɩi sR*J?醗cV 06ԨJvBOhQgGﴪT`NFOq3A/fjWLhdjE'55je2o6}EMzF6)IY*x4{'Q S\X`ȓ^_^O~<ÂF^"gJELUw4MUsK8g e;򉐌;շyXU3NZCo-^S(iI'cKVEBG&7qh>NpXpL܈2@Y^<|c VZ |$i0[=kѳ'X~\}Hٿc0t< 9+c꨻CiL& V\_u'S"G>*\g9xsOsT2p Z EJ8}_K3ހwr/e_BcO>c&y@h &xTVRXex2YÎx6ݻBծVKwϪٍ6\Nʾ:Β_(ۺF5m|W DC vqu^`ุl-÷ #h2bܸR {$d;Kέ|u%/VA-)sݽH5_Z۳~"㷥ND; Jʏ|mo[\x4E5,%y=&ڗtSr/uMF` aգ+`;.q83߆FQ2L;Gmmg cJs~#Easz؋dX; ` ٌ:eqƻN}CAl_еEM$71J׆|7ґE! {MA=R K6N6RX.BeeL}^PŠz1?{ӹ6YD14B,yڢ6 # ;"JA ]JHն'j!m)5lUFKS3mrȕ)O"z-, J1? H%ɶ[q&HzVPsH)PE={cg,y)FblHC_yu` ,E 9 $/$t ةfsۢǞTpF$*.[VI%)eAe [Q3>b΅<:  ^ca( h߼<[ԄDTޘ[+?< X>NV0b]3{'A=0r05[5xdM۬gyUFOǩ*=ùTmJƖ7|a-z]z)sxN\%C^^m7GymFiְFTs؈_S+2I]NSS,ŷC(]H /+cyJGa~AѣI:ElxXSDafugzj:j %lv*aa?{gVx|Wq3]l9fP桥pw$$8?r$X  SËeRĎ &J][#sr !:6qc{I&EҬ&B}0H<)K#/9\@CaHghK;+η;m[T2NB3a-O*'NxZv ͮlsfN:K߽1=DA,B#L]@)0X̯@Hr, ?K ~Nkπ%N%|uΊz / m :ە#s AlVY҃;&_,Ae [fIz=%'DQG۰1xȐ^c\.m]&5g/Tm;W3%AڰXT>\ K&D=)%8ITSDJj"/:*cdhA$9"(B/wkXEY:W|}ؕI3=[4Rq$ܻ8f _1lHFd m9ckC(=ޱ&vyBhTg;8F7h@e/;Z]0LKo;"bZ\+ɚ>#̍1fޣ2;VdJJw{A 9ڳ uo L* 0E N7MtZ(#c? (W_!僦IIO>R!x۝ V{,QSS`.i6C$&E(ǜS πۘ:B }? ~Gmj8Znj7 ρ|G:ռk$D1;&&ʕ9t)S$A<#͢]_TȐ@6;T'PG›N$+8=TTXMuWJ9l `ۀ9wt>PԻASUom ׋vW{%VΛ=c5pĉ"UXttPm] N/|{2Op n 0|}1[zRKEѸǶ2))w[C>N]BgfEV;Ug^XPߙd|6@K?eh>E?`dc^_:G,%xħ5D6X[O$0%;Ap&UH4opR>sxәՇsh!LDgzxb6/.%KKp=%Cq[Q1+}QlœV֚˪+7fg2uf`m3%O,P[Ol}f`ۄb|å tib \U,Eiݯ69;Z oJ\_ 5 o:^XI: `̇IWZFߩHV3y`>n hcC*WI:Kq$~ȖjmfQy&S5eyM>(Q\NhCB 3ձ+&nlf]Qr #efү#Ǵa2s4Ƣ*@?!0K!{HRǪ;j1bu7  XKj7EǀFml,1 ){/:L|۫\vlጜvqw2+b~-_T`jkimY'4 m< E}AYk|ÿ qV+`.Rf[jF@$A"j3`8g&,K^yh:{~2ƵSv~^lʊ+h_Yo΄~=%T&OɶuCE㓾_RuQ9^x ]u4F]f7'pluVSB D :4OU<%rU'UD]^צzo0b[!]0cEpL!Q~h{eYk["ߎ'3\%lg9\ƋrkQu5ڳ:KL-^`FcӴQc ^)+% ؀LOg]E;݊y1-B:͊ĜJg ٭ Ff\E&hj]rEˆ-!c$j5ZMHJ(0H p#9JmH' &ciEIR:I?N*Ҡ } Q-#}4qFxp?p"_UACbfk0hŀ^oQ3VY{ͬ5?J=_7/d;c3녍_yc-x,I{[S="v2u4$kRĂIVŨ$1-qm@軜+fqq:"r=o~I{5HnV!5 AQȬ%^!CAOxQ̣<^46ո*q Ǒl$NxE?3kO9n{ pCV 7nhs=Jn@Vp[TU?(^u2 $8On5bB@ء|Cawoc[woأnI0.϶4zsDcvs=NłcP)Mx>ߋWG丶(:>X&A[HU/j[WK!ؽZռF P4?tկյ3ҩK"//>e#Ɇxն}*h_@&yb1І;k /|`8t_w:NVI|žnj;rYVlaFU%eg9aGwٟxZmKoA 10{45c̀>&qc]Ti!(jlm<$؜3IJfo_?݄b p 'шa_fZ'DշU. $w.M7Dy%[):`-U#!-Yh*#ȣƞ`6޿wbDhz L Ӷw&0MdFj~cGp`-U2}Xc>m!#FgϙS=5Ky;qb:rU{ݾĠ^L)Rcg[0OOYm>z!H.}}&6aqC+qD$x{y W}~9sxpFsIܬ(q)Ak1WĒ8'CcNT9dj߯^;?exk%dwaoq<D~A1K4`t\6<&خ~ep|=-N@Y q8ßJpZ$5V0)NRlL/ +Q`]^}͔mN'!oCY/ߣ~d/k E9f0~ߛ> :S*M0-q֯}P'*vaJ;&z~`ٖz3.g-0u.iIU^@>%.2PM$P6BP>v=Ū5Y@"I1F'n1pGXQ8I9Iǜ(Gl5>ƝX#rY=vݎ^k.4X~"A`zHK7c_% D,=,&^3c_/LԜ>[LΖyzޓd


osA-&~.Ă _x͌ύym0%nh"=<.盛|ߕM pZ]'cԦ#J@A()>a(UjoPU@ @Z:dϜ{$0Y%0O"ˇ!JVIWYtV'/頄n{94Q GyϒcиYLZn<+\(ָR1 aq(˟zs&{a?Ӹ?bk8:ZY ME9{wFLm`SH6%݊U??$>2\w8`~ 餵EFС圙z%}v*lHt-,^ЧA~v \30RKqptY>G1g$vy8c.pC0񨚫w\7~FYghX3v{gx b^(Ý/B*ieX$E'ZoBvR|^*\!JK=~.3JH76~2rvnu;Y&3܈T[B5jmnΗ/RnMx&pf HXIB Wb ZE\/5698ŀp#cz; ^A<^C׮-B/(vdTFzvv`^AصL2 ::$K' .e_㙯t pz#Qatiٲw]r{w?gHtũ7Te$(EK˶I6U6h[ cvH3UcZG|_3;gsAyMN묩haF]bo!dSX#RKyn?@ӓ [*mN4B<N͉D"vfzN9T/'ˎ40zM{ߔ͕j¬-nuXgAIY'.[:8?Uo|Xw]g࿏lբ.@S"zX+^=7) \@5P(7X^2ԃhJFP*]?њOTK $Mf]P`HAl>~EĝtA]֠E1Bwb~~[NvҾ /@)ӡBJ<ozJ@ = ̿8> BD =gNKmlT>=4GӴ@ M2d~T3 bC&{sx'"2QyXr.: tdϵS>  ?Ků lƤ5<ڏ>4I]Zxda}bE~lw\ DingQHF뮺{j˿F/C|I orwH%*Y#`KB}z3Y۱hM3>.ao6Lav9 9odף+aL\KxS՚21/@T#^H|tL5q{Gb^RٜK$Rsrˏ A.4_ua{ ޑxS{sB'_aU/dL,z猼C.b;%l.QEN΀L W2r-{¾>ev̧7G@.t&ZI QsrpʿA"m>F~ZISő^s y88?GbS¿8`#?,ʮt".T]@il=i9Sq?:RV q&L {M4 ; ` <4B1"qT&]r<sai6Gƀ'5&04Eׯo+XI³e"t,,ظALP-+Qˁ5>Ek.4 2L'8tUF ]~P9 uVKyfj3m_*g-[#c9BfDaRd׮X4;Ҹ@."* Jc&h{\ԱaL8nJZ KۜTyf/z1v6&xq A'+&.}3ܭʸyލ APɔ MYR;tQa@2i\xAO+{PcfԵPs_4I2X* Wُ 7m@nV?%.G)VEUߵ!czUq8aTarkc(^D&˔*e951d=}4vu#L! ZMg?&ĬTRAkS~${MEN+yc %YZݜI^ f e QФTIђ]ZB_a++ FZHYg웳ye)RבSPT)5*,=Y^1湪QNֲr&B-DM nnQpa G|"¶O.HK|:(Kl{:x/pʔB^lLR_=S%ҙ9 PzV/P ot \Ve]&[xw ٯP#v2<GjH;ox>d/Ot5o֢%YhbnJ ?XHx#!|+Ox,QCw8GZ2mQe}Ly^ep3Ԁ%#t*idwI?ѺF*zNd>> #eELg]0D6 j| ] "*&@@:7΃DkAJ3nPт_Q*3ppv&7vw:BΩ A ? wjFKz5gUj'*SIr[i;Usy`}W 4 (jYN|6|~#x-> S(UKyt4`S,Pa?OU& [E]?"\׻ aMe8vD2}켖#Hϳ/c^Q3>T Mm!~*h3b*9tw* HZ|v@>zp"du?S*Hoz勌d_eD[n>ge^⩀bOֶe:1KI];cW-`YS yG \&Q#v fUynqDqIWf#'2_R&in$PvQwnyԧDb=`6!>ȥy2AD1+n& 8jv5ԉ> L-CGJ:.1u^~j*U0D_Ҽda zx!m]_sy[6lAY H2XU~67tt 1rq$4ExowW|k(mśEyGTc:DUH>FHgQ̬,O&fo\YVپpPN'K 8x1!0ݣ{^V 1@ [Q#۔su3gyFHS;ގ<.u bF:IrYP]żk1eFF'<,e͚^ꂬq2K#Sr2NXP{Aj3r-03 "ˁe !h C B5\no.gtM%Myog  m9.oNG'DON^Vٞ}pBԳͳX;;槤KΪ>7qV8"^ Ce @,bsӡ:Zo p[?U\M>N &6[lh?2k3ȝjc?$cIiC|v (=!. @ca`uBq: Y©Ǽ&)fe2ΛC77>o&tL=(tZ8J Vd#boƬv2Wy~WoRL7ҚQ3S :Lj-厩)i;o7wx* 2X#w%u#vfx"zfϣ;g+(Dqؖ dR:S'J mr$DA µɳ;锢Oق9ÔO=ԁh3=3QA/ :q,w}R Pr$w&s</yICrƈ3׊ S'[ ̉"J@u<C?MV!Mt6 䣶&{M ړR LUH"/#p(L`|ml2xjjewxOڇ멧ۭnY5rFmJq{+ayFZX}xA|3Ff<:-z%L#aT?qɚާa.z?Q LAg.g6M I?y-G)_UhtZP^GE;Nx5bY|TXˍ1+7n %db Ӗ,c%%bM@ ݣ ?ږ*pCEVH.suȾj#zť~/8MxȀ=a-cM<+E4(⽀R=]A|Bա"v1uV.OI rEVE$RYM0íΏ:| | adgqA4+/o͚rSpi1{:43"6fqFqjԜ #MP-V0;ǍOt9XBe(O&ʝh|b"k_!_ڿknm]zg>א=% rn^ BR!D{Zu44nQS)'hŎj,/Y$QA`voz96bbW%ЍT-%~s+pt,^Tgi~\g7AO rnhByeyǝVJ?CaƽO_`UQMP!ٲo@3xT±bWJjN1xkh6;/!^ Uhvn5]6>:ь|f\@FuZ'ò4T)n5睲"/_415f }RfM;ފ=7##4}]=찝X/V `/W,yU 0j ^ksJ3;uqOa8KאܯVt6AY1Pؐ<9+Jo\LGR@EZOk\8 aU`Q9`iRxHKAMyjZpvkN'Qmdg0=+e 7axEz{x'T!-騪']?$Z򲜄X#;}B0Z*I7M0'_OaF=eCP9뫁i--ދpxAl/QĔG*y׍N%і4ڧ5 ^5VJӒA }m!jk[q=~ =Zub!#JCtDV8 ,B = NH)5)w-qZ7hIhŜȳ#n 9H͋-u^e _dplyy(9;_X(4kNj>tw3T$h잗cPo$ֹ&M'ޒb"!R6)E݋u62;z'c`3`!l+( ` @ﭹ-,JM]+A'NVcq3w칼1uVs+z%ₗ}ku+uˈIpѱ} ƶ*am!eW ,Q/_/I,"$55Yq+/ˀU Բ7'7iǘ!=tKAbm! I7(C1H7@qEdS4٧ »R\)A O*f.֭SNbB` f(fQ? @Lz^ư@<0B [`C3UnY[-[8͌&/H ;&4y$fR9MZ0m_ cU{#<%D ε][#PݡhǷ[~!ܹTNhڒk[ur#J~}Ŷ(w!1dlB3sV||{R{'֎`ET*-}9" "&~|YzV}m>.qݍ 0ذ-6KHS;$HRΌ4{ĘNLQո #V-Qg ?P]ѷ/OwbF$Bx 3]Vb" "]5EE7XD5EjnsUʸ8VKW\RZFx2og)hRFһnzLy%7NIEu#FsB'XsӦYáld]y*q`kW/c>gm5 "Xtk3LBBLo ![ M;6 Rx~Zgڿ78)y}NӉԂ/:#oÚ#!ud@0lQheb Kv-ۡj2WK4h;M;Q|F~>0rgi)4'%SUM- tk0CSx!7^pt~w>H YkP̿ &(#[yXD )W`W~iB}{(ހ+?V%Y<"< cBO5?Po qbk7VaE#՛v9_?W۫6چa>>RT@Op_X2Pf~( oh1!( Pw'Fu7藌!iX*luԶJ:T$u3gR4A"c#)73I"$1".,#%rO=JDa~S@yj5Nmapibf "p`u3c+>JH.rJoȃ*v$OlĖ$>B|l=V`ER()] OWm.Vq P,BCa21ou2TD!ccj0CmZP B7APFSTdXaE>a'}`LujmM_; ?r sͪ;6]tGv\'JTQX9x"oɈ"Lx"{S)v4YľsM3O?JkuoZ O,b́AB I)^;DžT-v=O*.qOxH$=@r4Ha4M{Sk $ NVSXxFtOtKZ>2 7h zH7FjQQ \ڸz e un~j~;@s+ȧzdx(cX*ð:izo+t7rfo0vNƮ\gdkCy}B;RgE=ġwu?azėK^ʪmX9֣A y=(7֧$WS9>Y0֣I]D;)ĿȋMm\Dwr++o?iQ@1N ׂeVSLOJ^wRA otr#NA75VuIǓHx)m v{r(/_l可>Bջ2!X1woA)OB-ax& ?aw??߮wh2P}R`JgW G)0N|~+kAM7x_7dKo^WCi]eD`gOaAN SL-YCK ĥs[Q1@D+0,yXJpƴGқ/~FwvU'xV^l3i,} 0 mơ> ۏ#nIrʒsXx=pOԥkirc$~aUHHXefX<47QwbJǚϊdTyiQ܂QDlK;nӐ;oPϪ Zi,錋0vNƗA$̚o<~qzP!5U R1( kif?4 i' U"H\r(G5 8G ],M0ف I@MLI21륎~tܰxm*bExz=-ֱ/8@-u'9I폞^c\~ U4=ڡl{7jy-jY0k"v_ &}K&K9' "X6F[ls6Vw'/dxc+A>d|G3ْ Q"5-j$2PUIBk1AQk}PɒݙBvA un{*N- T=f{2d *8,Q>>8c0=$58K{vy[ q&/p,49`?4\n*$ra'mŔ(IÚLv8Q8UU+NԢc0vlMsĨ;$Z%K9\Trk&QG㳐u=w!Nlf$a^#!yt.>F^ꫨTNËˏO`kɊ=k%cxyS/KTTEeQep".G9 BG!=`wX U2"#Bp`?(&WsAa> /LP(3s?;Su:@ba4 7, h|'kX*E>e׈ iiTC~4mώ>1g?7/B]p0)PF_{>g $\>5u!7z@6uK=q!4`8ڞ$Pa>מj^0s)KCct_prZp+Q4~Ѱ;vD닒D70F4ʂ6+_.D>jtB8 YS1?-ڋ{׉@oAw֢h]H, zKOhbb4Y$t]LNPB^7lE6p'd>$.HZj^B&AZ T9I\Yߔbvy3{żRصฒV ]=>*QG@BmYD?:d/+e5@frMǑ1[+6'! } x/Yx`I鬳 5TLxֶ2UhOKk+\Nel tQ3 QU]U̎^W`.%{+?Sbdy\IYhȬ&B FIo XByc.Qᗧf)_Z!aeX|ATG!?,R1BdR2ք6urT/^|$RT9%`xuC4u@,a1a%H+Q2KXb,AN˺;0 %=6:C9.N;1߹HĎH~tdi J!- y?޽H˷Ovc}-j3ŒOD|\N]v8sAgk=a^/W\d^t pO>b(NuC[wfA굸-qm<9++ 5r*{g%u$|=.j?>m)xCPaO MI*0AiRy! Ϥw6^1vrǟ$Ŝ=\>(^Pŝ"v>^qAj9?(QrƔs®Y%^b=xYGyLMoqihH:ŝol~w?bՈML7Fn7|&3d^F=jTu:ZUQJgrWwRs)_՛-W" EK9ẽkΜmV[& Ive:W1%mh)|l8%R5$(gӘB@C[ܛ$;Ŵ&:}LLmmIn;%]|3:0 eG?,%)^~qjWb`˔wkQV!avd6a(Qd)=?nl~e'$YmD]2dZQD0b`oy촡?-k* c݃C~./.A`j,[b/ 7$o3|-cN(q$[#Lr\(NM(ՊTCbPRg.&R6D@]A&&_\%'&y+7*Xר4V P?k֙$y5$,KSko GAjx=!N``aIMyȬn!Ӯ)zKf 1 X-UK,=[#;A2\k#1LJ2HfFAO2TR-oLP8!oԨ]4nT.TyȀFi8|Fu`h T("ZȹC/ݗ1!_(bԶ5xŭF#3[p%ic9E"Q9| sޮ h ,Vh犡Gya,|V d)l*Xɏ(mo4}$14ߙIO:/;?!"6L#f5J8$zsՈ5r7%lz(цBPKj4&e?=d$zR?C۔!TpC']mngb;VPN94Hr)9]\?%]M͜@?]?^~'F#ƆE#_d].AZ<XfIbn!26&)!/ݶe(ҡ6g˫0} mÙ _2i|~1 wLtjO'?+sYJVtymsxrPgEZ%(7^T7w(đgA_cFpmߥt УM#DUKE[<nQHh TP,;Zg ̢))jsN8e ͪʔ-Yjz=GP~ {aمd({qb喇g߭9rvBL y{LIbLx4}.ukU46w.ʇ򆡹q RHygMK5E1:1]!#yC'l5wp,Tr9aY%EmyeDG-cl?Tt|՜Nƨlb|,>w#\]hX ϨڤeVTP`hHy-4|Qj\t^Zͪ]YC@"U@(Yá5L *u7zce:Gny ]@4(` }}^"R^^喝^-Ɏ8N#I:#ĪnPhpP86$q89 &% 6#UP:,m}~ atnHO c,h0_ ;׈Fl]2vp&&<npQXZpùMKǘrGKI%5Mcwb7ZLOċ'&I!FoYa<)z[]_} \|IlzUbui/ hG‹'3IL.hx5#eY,~e[5*2+OW܃i6Ah>I{St (j>&.䅛J6L r_+ rVn,]2ȵH%i%7չOo[Ю|T.xŢhB{_Gօк/<}Ec(X0+tKӺ}y9gHj5/HjЈ:²vn սmb_3T>)̻bE,%F"Q9Ee{Rpp}R!ك`3*nq<1ze(, 6= X >+ۺ%𛋮ZJ4߁yW ]qDхpA ~WHӡAz'6^n 1!zS2y+iN_ 1:MOc*P9aRŏ7%>C|㥦+_E G(D5HLNoE[i`g(ebDmf:&_B."4oN?k.w3 +٘ÍhT]KIp5'tSNֲYxkoy 4ha-] d@8׍k~Cd= -,nJwN!Z(]Z #"SʭȫBb * )i4PNT}K%!EQcX"QDO^]W^G7ja"H&~Nٿڏwf;峓Y 07 RV!}X~IKj.>v ŰGS9=23ִMQ 6¦Ȥ f)Cn`7Dߩ( (+޹oq.SY4V-s)WJt5=/SsnKMRYNJO4OȒW3A\M[ܱ `NmʙC\ȕ1ܿˑ#0AvQ'|Lo-<-,WRhk6MGEp?6aTƄsU.NGhgXghj565P9Y L~D,l_W/ u.<6FzO&WV^UA=#7[s!S9%'3HN96 ɼeKcԪf#%#(-PGf߶=%RR*h:WSO̎dB|f`YS8ε7KN*k0nPln dJljEdb3+6[X^gK_*L:""`> sSX ac:5wQ˙8b4@5rzO;vT$FU ܡ*0 6⥹շ'%ׁ"=ky9X! Tl ֲ_`ǡ::d e LD;?/5Vc펭GL|855Zr%a4wO$ I~L wr]sIy&Ly@+vDWBA-,`?4]om GmC9!Nb3Ũ?7' Pwd8ڑE9Сyeot%jUe F0w=vaSͪKByY.cmh<QJ2C#29Ӹ5ItgI?)OwO{PMP`S½' {)x+sg^a.\Da[RuԄ*V7{Eˆ!ty_Y""7e~ī\7CJUe׆ޓt !*[!.j@&Bq{L%PѴ1yʗj+v(B ip~Mh (A{ C YRWWM0mm'͓jQs(;WNėɸ1XDzBg?WO1 ~n(C`zƏswj0!Oąb&b˞c\/p[PG_=& ?7D*o]-u6.{{П|Z6BaeFH> @mAq>.P*k4jvaĹ{X斣Iz> P>}Mvz?'}'Kelx%˒@rЛg% Gy])O@cc:}>>~:KA+ui wVZtps(T% *%zcqi:{_ɚhS|kKk%Ff˅Ygh?O(e)?!ֻ5=oE}96K[ù~=)jN";B}>SzGrY%"XH:-H-~RlX%|.hc fhӏa$Pz)j}%^#iVV:!VҪK.1瑬lb4JU0+ cbrw^I}z ezwg1"֡j6fX<-̗fc(?|KIf10D, ݹ1(SVT)ܚf6Y!Tf5 Ą5ο*oݠ)@k:ǩ2Hnd i71&} 2T&q 9B~.aRC@9'a  4 /L19tx;!eU,HOl#"fD%w`yom 9Wʟ>}Y_@'c(Dyi~7US':SE.+mYR)R[LnU3cky2e)%7$XqqD_7ӍeW"=tVg`QsA,8}WrAq S.ɟwUݽs Ro-[郼^rfeӣE&}O5.-?Ah=5gaE}ŨD =ew]`¬'A8 `Ɬw>E=m!F+7bp=b514.'9+* !(]\qdvA̩; z 6Qoǃ1*kt"1=n)Ĥ3]i?WDPes_d1]}Aׯ&{Zlڗ~i~IFyC=L*3A5ޟN+2N!{wǂ՘['(?!F$A]A)4b.T7uxޔn~(8osҌVTxq 8N#9%[b= U0Qf, zn;3n>t[ _=~HGÊU~<++/z]j+-+/%jVPT-ޖ싓.̝VwX1ȑ"0x GG2Mw@Hy0-Ʀmo ?ꔄM8hz.SoOd/;9k0zL1@1S0Q~w,ܓi?.M|ͺ JSǀM(ħ)`@Lr>P pIidfPH[0.j|.޳ pᰠgg/f~&sE 0ā;-` XIϚ4tC\u`fnGH 6ƵR.ox=RZ٣^z;Vٝa$]8Q0/6Հ2<_0?~ʎs^K_JM UuF{lw[eM%ӗ[Y0ds =8)A,dRq:X5bN: QP O٢G.^@kE>5%+:ekrcu|ަE/1wڹoR2n(NۓYE_7 'JAY=oW 0lUoB*~Sb*6xcL E'!Bx书,oRWo"H8 h>- 2n )BX]9BQ)7b|OS o:Os\U+m\؊W鞵_y眣lڧ8YDQ!Qقܬܸ3\A*ǔMi|L9}4zUo !ڦGb55=6VeND4g B]~m_CGyn6ᵒ Vk4L IcL{`H>Wp T^" @$rQ¹)L_!"U'~T\9J+.!r yJ?v^&)*J0%Ux, \Ko YDJ[av"f+)=G˥~J ӾP* y S1FnЂ_<"ƵQɖ{mQn`H) ry4gmIcЪ:Ԁ,Ppa[ͻLD~z?>(KAt)zjF ܥyX`>DpWU^ mh}Xw_m{{]ǝciKRA.2 Hȿ1bfs-wE]غQÐsIP} iaF VXDhsRʊQiDj-'lC=y{[G;NћXI"m7֤'H e"dlGQl3[17}u!|m?s]x,{9Se8" O0 ^R}'[P 4a"քOnLx j#,BER0.3R) 2a#kC℥ox*[(n!_^ N*Spl_ _a_[hOq#z/t 7},FZzϓI\?eO*t13%snQ+"5C8ȇiI^CzuAT&j@;βi2e xY7/NR00>zHh͂no `Fٱ< &=Ei1>kDMk(yZq]+1&Π\|.V(< 0\ᓼVdk\|̷8aeBZ/j|.yo;E݇`se 8X0pdyb.O8RM-L#.eɱ3sn`g9-NEʆGp'bf;%+>{ եT(E*-{v\P"C~S2 h0+pݓ ߃f ̂%6?j@k8K,4n53e(x0n1I/'6!L5k3dkt&했&f,|t|&maw)$t9@2> x6f[KW"Wn_=N\8;0n~M{NJcyq^>NPEi1`1W'Zdֺk%_DD50x`Fʨ=/ګO.4<[4~y,Ci'KB'k io'P~|iBdP<_&`8ޡtoJcٺv 'Z= )n22mq=Z_{$ oXE ͇4f Rhv{f"1XB"$Qg5Q,{%kq|ol,' 6בNlq}nw-mmt'}kDJ `s'G̿4 v' ka];/;LƇpdvm+mp?EQ4![f+UIWߐn ˀ-Ux=/H(cVK' x0$>^zs~+~Ɩp Nrf3YM\Ot*]޶LUsg? $1V5_;/G\!S+VLr]?רof*جr)j3Nhso^Ĵ ~<7yQ\᣸s+cy6'CQHXȥ'eNK,??q(އ=]^~K&V$G9G~Уbv~\pCIy? B-LOoYqrh,D65c̟-8OL}c^?By)[j0o8*c`#Z͕KN}pZ"\k/97ٍSbu )f TR8Gi[ d% C'g0)<@ ŠBه,*<t%Ⱦ ˫üGLTh"rΈBz٩ѣߡG*#-)07Lm*lB( D9qDObv4u6V۬KWU !e_pB#qOr/i}]?}G^],iKv}=k- Y*ʩ 1}rnHB ZZj [FcMc;aVp88ap_XS,uWS0?m2 `=ߚK8KAfb5tTT݁)[rG o>۷r?' WgToEL*87ETM!NJѦlĴboěbMRJ ׀'x!E?,fG헦iy:YӬkѫhDms+w.;H <"S# DǨԮt<=x 8ulkMh&3uӳ:}D0=w`V]VSP BL[q.@{Scz^5HmJ*+r/lG~pA?(B Fyb}S@WGXu̲GY2"Y'zF_)xfkα5L%04D^7\eFk4Ey3]SXg.0`{[6.)DH% U/ wqD٢"Cijw>~#z G8.`:Ŏ_R6Ѥ>%&&Jǥ ÛB+_gҨB|fj 4^[unj@nsZ)7X/&<ø+wE_-ʀ`=h |OGi۝뛠T0 rB9)dg048ŏuoW),wvbH=?^IJ܉=+.8H4@OVN_e2s2_,ȯ%M$REip3ji%s|+2IBF1J%tÀvѢg :#k{,'r;gM}vo5^k.LxZmT cNҢaHyƭf?qeLJY/Ohu*޵$>ywX;Քyo k$C߼DO"Ȩ,d^ѷ;[29:@S K~FjKRKW7ǯK^+TjAub;PjśW##VUiOFZvfB)Cijɓ!~hnDD{L @!wHKL ?63Q:7ࡶмBPUsG P+򴃪C3ew;>d2翷Ih.")'ja[Anh}Nx᫫\5WÃGLdoӥJfwS#L|;NNŢsw='wŪbGϡ鯜xV{Tʜ%&^wN,ҡ'* tXqDlssV.-oiDrv*.J~ҋC颜$ ,LT'Ŀ>.1 fmyTՌ6P/&3eT:8ZGDt =sdٛ?I5ȱ׭3uQ#wcr)F8$ĀQӵbm "SY&  Ͽ >ɜE?-qMRGl:F(1a@R00m5dutHd؞5 8yXH#dEٕ#GntBl:E4y2h3Kq d㻩]eC9` ?`TR^pO>o=Wn [[CZhPIl0Xqi{XЈ΍^&ij Ty֩4RB;@6i咬&\>0G,8KhҔZmے_SrU7S !~5Coz${;Cg-fL?LK,o[V1EЧi.pF O޶DLb)rPQ.S%=YL6@T]ST "\08A*.<8!)H%Y)l]u"De`@~>7N6g :*o\~1jW{j Y*Q^dt|5 $(MJnvUL;[2NBKm0Z<Ϧ]zH<0\ϝtju 4ocџL~_}!v"q!0>g-%Ӈsy>~xa͋|ؽ11bC}J$H xnhVbce.1m\c]9e#0)Dn+B8_BZQ [,:f0d2jg4IV.^=X.!>*s[(ΟXAqA]\M5*Z m(AO'ѣ<i';l=e Qzs3=5wXCyptΑz c: BV n"q:h7k#||,Sg^K{V@Rwy- &ZnFeyv^zaBExd,/s; ,fmSS@m{,ߐ6Ts.y1j.6v䓈H&CP& #K!8nB62RAD2 uqOըUͱW \h8;mx&˛ƽf!;11A CI~k.?q6ƫ7Ij?(kᱣy$[o\C9c#ϛUcO *m~TgRUs0_8?jh7Jtf׻—TAkP@&~\5vBJf_AWa@Lh#s1R[5?<M*{[tR[ȷrΚki^^$`+3le<8=le(D%.>ih{Ea˕BCw#6; :)H@gUV<ĿK NT Sb֦:v ~>MYpVu6xPLĝ ,11^xY QaoVǢZ'z87Dm{j:Kt%Q iݧ]cGKM٘d9E9NMt(ſɃH^0ߙ&Ja P4^Vjl3E,f RX*Hg؜B\g-zt@Q?`, bPbf}An동/b >7.6O\Z}ey`T8T:Ҫ]1, W <ͷrh'Abc-U }5+|t$$)^JXJf婊Me7{"䨴%"c_.WO9 bBSMD e4 p"IQSfЪ"L.Bot?6|PTElh_qjk,! x/%O~SiY)s-ICaB.UnZi2` )`9._ {> xT zբdR)!0IX͈yuB:42zɌ{-kӘoG@$ZĀphy(c^Lkr6vCP pMy(_+7آ2bɜq0_ g@#hmcG>;LO#yjr,7?gUcD7 -)#_4ʼnҸUZ#qS&b5gҦZmfZEizo52&.cH05a*;DҮ>_ 3s(U%L@^ٺOS[;!6^OKE;S)r T&SVI{R@Qwhl<$H5!yTdBQ.ŗaZ:M>0" ]PP&8%^o^(+X2rD"܈>2)R^͎kJγ8)=>0u`-:UEi XJW1[>f-5׊7GAZy)3)wɧQAk&ej!ӯFwrA!515yŃZoζ%uE>BK[J[C"uu"YA$dMdVN wn ܃{\+/:݃cڠb#+%,3m6Tߡa0fz&XbZKa4z;ib=RӂY KՋ j#c(vn᷋WRBwrLl#ti`kAC7;?]\hӘWٶPv~rPz{UȔŹ%?pԩAlˆ` ](J`,_B[MmH̛oإwQw~8| N(Epwެ IAѨ:G7>y~9HE7XoQ=CwxHe9 __,B~Usˌz2>T0aip}Ni3i<&'(aWp"c6nsr_qvyXC{̮#Aʆ@89Jz)mK}{n1"]ܖgl8gd}ؽf*4 bJ&!;r&p$v V GZzXws?Y{rht(yCi@ 'mNrU϶UK)ֽ>V0.0GJSN>c.`ĵDH v1qu*1mAˎY3}Xxܹ[ic$VYQkS%颢^@AIϽ70Ad(}>uDIYE-3?"{&i%1 e'A1brC'褡-bOܮkϼL(՛ K+w{"MX$}\(uHhװz-%t w?z*7kpM:ys,YGLr]>P]V|> tS1e `J6+k3$MNd=)]!k&l@%0cQ#~bU"wkBxĖ `"\iSh>N`sLN/>qu ]:.Tɻ#hC唧ó:\bKVq߯X9qOƹGV8d2_7)' )rGB54h_;/Z4.!4|z!a)1e-;) y ن+{؃婟l "냯]1DLJOFlBL(_p :d@`ux\}a98}k҇C!}"=Q2sΟ4M>xl#ER9r vخg43+c0 rv?ƅia /S K@oM`^iI>~UaLƅK[׶NL]3F(ؗG^E'xzXLc<nxr˹(ӏ] y66wFzW̻Y= DPAO_"m< ۷T3/}ĽҒvGe&a37%>e FI~^N]Đ$5\ÙI@?;ը/gubWۧq{5hnS;BAbr`⅚FM@`Jgr ['~~el 79砒$v֭)>?Jr]x(Tz>fRiQEFΩnA@ yI!t;U$2 ^@\sx>axPisb#h)6hVQϝP1V"ج&S#H\dIV rٝ=O18qLt?AzfA)Cm$VġC=Q[&`Pڷ/Ұ lLYD  S05]w*yk Wֹl) >5L FV.ue Og|Lkdc,ZC7 5u-kZfEZMZ˛َ[a8R\K:WLsu:՟m\ik>v2E$?NFNJnhЖMH(9 hO^m׽Ҟ|q#Bv*R.zX,a(8(]b,hCc%?Ir%,=b|nDѦkk%/A<Æ!"vdM$_J]“n [KF>pZ6MݸQp2h $T/<Lޞg@>]x5)譸!oO1aG-ӷYntk>M &"|/=4oo!NDkwz4bAݴv'Y73_i5ur:nE,y{Cn IpQ~oMohӧ.i. d:_ bFD&xZJ0k!\O$mP\~va_B·KCVv al>}t |AR|ҍZH.,6tǘS|4$hGEJ rElX q-|{9c(4a⠛%- 'C$f2/mt[ ⛯UiVǻkbp_q^Ȑbdw446-!o8̛ }ҳ߃kYx~ʣʗGqˇ&I2:r+K2$2^.}13EgUʓ)+yS0o7Ylwrbv,I ҏofYzh:,OkF4i;IJ 1꯭2k-W}n $g,ZPɍjKTjjO}%\|ʪ^)f e89oK W1 UjeP{H*mtw2%@d{sg78qϭ_A~~.@o={'LL2Sta)=Q4U ڝbȹ5#}%Yt%|H5@);J{f7#Р0Zh ?\_|%ۘzvRˤ-(uȥЈlij5Eq Ls5|PSd=X*!StOSv ,up7K HJ;4!cU\ !ɴ @JYQg+; cQt!SNBc I4曏Y%!}-קּSPw6;B^ci+Ϊ*ی DX;^i]+"Fe%aUBd(o,(ϻ@kg=N<E%]d$iu oUH;cdlf.|OK1M r(mQ7.:LG#p@ЪWD~p&Cf_}?C @쓷/YePI9~P ctͯx=ј^ \jr9aMvmՎ`U0}G"N>i6|̣D졓3_l5kg ` vv.ÏZ:{z>sY3(h!dW^mL)"NpžREncVծ|8$G-u h=)<X*hxҭ|Wv!5L kRkYnY5Adk+W#1O 3QbHbGM,Q܏`<,+IͲZjcB ln4gSxm }0 jufP,5i&X$U%Ƥmnȏva!to١iI1zRDbwn]tu@5 3fX>tC U'r硏oO^^E? p&%qq~ǛwW]>mg q{|oK& 2 D Oml߲cR-ӈI΄{Aŗ[lɰDMvmS("G nS /^0 ]?Dž=5'+ dEײ$C_ePF`I\\3 /Κ'MrЁ 9OVN0y3o,ִF7福>"іw#A̩d*0) _YG:qtR 7֓zK6Ծ+B\| N0a8y>|:(^eL Q}ږV8xr rEGd͕hT y]W#{4<9>)kVShV΁0KW@ { BP3z{mV&CWVQ~%bjtNZڂfWiȎy mQA! <"] ju25V|TwNc])ll6WzvdVwB~S͔?q9oϔ`臃[395M#V!#o!'gLOxH~E= :pjA.zt@|v lfA]Kb$ Pv|S " ]sBoW V a5E.D N3kP|AAƒ jm‚iyx"DE7lBsUA'U7HIuͷ?dN?2<m4q8t6pl"'X{ jb!+uzlDd BPU#z,^?^SR:ùpc&xb - LL, p71ll[ kcn>֯E1ah G=ƒv[Y/cC"J):Mvz8  RR8'4? Wp2IlZ?}qA[> $Z C*љg jOcJ qm׶X1^tfBJ94I۶˽=# F Oõ3Olxh͈Qr1vZD.*H=yBk͐=b+Q[:!xMaK t^l< ۀBhQv)>ͪNT:GaN6+nh/XoB3.[Шls a1c)0 (œLX'uc1wS7hM3wOQ?h籫 ):kT:M闂WXͿA-h@XճBwre]ZHY$GM)|ND YNȴ$V_'gﮅb@*ӁDer*~ԥ%aac C.gŰӻL\ŝX ȮEj;[/u?w,S&OLpCC)/Mlk׍;C墜 S$/nIuewZnHcӟT{,)ѫ~Rݥ]E'uoҦ05:A'viBM&TY,?>5pW~nָKlǽU'?ryÈ'̔}69d57AnZ} Rnȁ->g&6~$4fz蔓wX`Ϩk#LVW:'q+p͈p…;e>$Qꊅ 1l;~پ^Åɻ]`a/Rw%3ܴ:}sD4%6Uerܷlmpn>Y7bT@N \݆wN$MȧDBÐ \S,$v]y(-0N#Dw>Z{i+mba[>\T@/[=H\L =P[rR/ZnzɂH\@7|`{FP,/fqE`uf5<Ct!^6JuG6|s l3^k=Jn>r m-Hd[ؓ]Zl} XĬ;XIp\ۤ=v8Šz (?>pڂ_@l~6lUR$1I@7ث6LHb*VVʮǠX;?qxRy$]X<%cYbADN!V^& ]`P%H|r0hKo?#$[(Mgчu~b;وh03`L 7$u X6zq8;23oeJG}]|S"m>fBq yy3vDpU,oXq4Kd+"GTe`ϵ@Q0H/ӛ2U#4?>812\rhp&?- ՙ :1!pǠRN) |?ZLAxtvcFrK ۊXLGqfNDLq W{^lӤf/x,ơe sHp7EWA!wlK\ҍՆ_t\9,bc "S ?+(/9}ZdeͰC$!Ypf'y[vi:;>b@r.`T/8{^e=7Pޖuoв6}Jypl-X+@ uk쳗 fa 6}HukosapT´bJupkzK>HsuM`ZsARZ;kdqwcMUdbq^kD u W5BfA 9 -^RT:sl32=N)=͸H*$D;ѽ36:jXrie8v?=nHfWq6!T:GGP6T;r 5/WV`Ύ$ΟM|H\Rc r:l){gd0s\7<FrKD]Z.!T4 gvr4\1,z@a3_+{K IjWŦEލiaE@mrwc-~Zm*PM8hs.i7 Ɂ 9CIܱG2ZL+ˌn{$BU ,HiPht6DOχHML Ӌ8ňCMylQgoЎ;դAl;-Q~Ɉ 7q2O!'.!84E=HZTac7R hu;7]90Ⱦj9<ލVjڄҔ H 4Mۉ"`8io +/ k Odpc  LWŘ }g$Kdt#Gwbc:79`J;s_+մH.ӌo&$=2{}bONude4D83O@9zKwc@&<-gA}.-J⑰PZa4:Rv2h8@Cbz̦kW ilAܭL32{4 Ѩ/ ظ_s_HcfJYm%J-#<7PT3^`"c5cc[5guB𱙷cMCѫ<3>wzB*e`=FJdK1 A_djNo?1/k] qZ*$ G*w}qæ[xU&zm%t  VWԯFф~!@ Fya=2NjETW9zֆ*r ߓZ+_CM;2qe;sh4> =oK>FkZ,1喽'y$-"fs.x2ûiY=G(QV|i񗥙ę RIeWN :HtKqU*CƇ[Hĵ'Ӻkj*dd̚i1--{Rj2iKݍFnF`08w9Yn008WVFs5g^RdaZJIPOtȜp_rC(hDo` Z"d9=8`Op//erhg>I*75B&nlk"KȇGO֔gdW$P.^M.yIZ6\FUIT1Z2J{"*L`Y'f5Yp,d#*ģ!܍לlj퉨_ϙ TJq9;;vdvhBazk#1H͍?.57=0\RUJwQfdz,/:s XsP^8vZ̷olC@cQ 8 r_}} gxX0?WDY b+?02jnԫ7~YmW*# JD6Ed1!wAW`-7)a/j,`6,-{wYx׬eܹ(]%=! rܷW~%QG]mDQY^6eZu@O(Iһ>KAt +hkJ$zwl7?mKtyGt_̍ND68]'Csӳ#U̥'c\ !kj rcPW-3^2tM>-w)TΊS$jw0HCp7+LelZG<|;@} ÷`5!g +rnbt::I߹oCp֭ }b@@d{@v (%ɾ+)nWIwTC wEWIIc]-/b.se4iY-\LJ$ [Qt#M;HSldV,5EasϲeXYݩ'57Vdt`"yhRa.DzNuԺpyz 7eU~gQ%eela&+(IS1\9fЊP{C~X= ۗUe~H9;\4o`c { ~7J;Nq3dyB?tPeQl,bZ[0b Rҫ:&/`ϙv#YzZWzI8 YBlM޾o=fNs> ̄vxi.+pN$^Y\2vwN3[=G[hCi,U<_W}^Z-벽U?Ҭ$4` AM_tR(DÀV,7U Oƥ*Ȕ|zf|e^Ր*=+DV*`#֏]H 1 P/RG:[!ToWExwOʹoEDD mW'Fu0 KqHb &oM'!Cev \Iv(.RD3r3ϥ bKo{ K }6T}y L= Œjl~DE!B 馚혈7_Y qKF7r|24?:!V LrM( R]Ӣ ~;4+kՄ 0s2,8[@h'\IW7P*>I7*ğiJC»m-ke.d 6>]RFlzSN["og Ǒr[vn bKJPuf^YR$b\EijM| EJLy!PrC/d& RY!C(:߲IO`o{~;$XԘ s24(8~f!0?D4ij It lx$۱ZH9pв?iJqqن@A }RY:Uu<9kbʇK.%U san#.3A"Ow|5)bHvuP̉TS@ԠWaz_0XP]2ԁOԳHjzժ+#-B3negDr62>FdgT'EW x{_5{OG(J^~tfB.jw8땉$īb*5ܒPl0@r=wg#0_yU-.'Vu_ 98_}"H55zˌ07 _X/`E-@IJs^F :I%ьYE;+MץF vR8!nqЯ> ;A?ho1 cFYrKء04GzlrOv`S%U [*F=Ekl\ď|0B죡nm"LG ,Q6{GT}͕J"DHt>I];E2ՔP"(7 j?]"n]R@?냸]~Ei2&VxNz=Z?">kjkH?'_Ir1wfsP{*5¼]p- L4-ra (vz&(x1ڦ |$9!Om80|'sz(y@PAd}c;E˳mÒl,guA.LΩZδy4iF+F@9t;S6&:e3` :%qCS:E\f:g [#n4UiZ7с~>g<3x;~E}+XAW <7%*mVxFtO dg ]p OIXHL}Z5PPvpXfw{|;ΌzZh|h1"x3&Y4b9<1zm]0K ?IL<&{4TOs|N @#gHݣ5!Z&vp7)77HCMqtu 6\(U+m}6U4 ="RIs+ouf,&ְȏO5tU\{4 hb NN _6(7Ñd 60L㾀NcnH|'aOU@]5qEsז$,}h`q(Ea5C\ە^8.*kaWـg8{5c/~RqL"0l2}|5J^gmP~R3[p ˺TI [Ȓ fx6]`1,^=~a,iNPmbuB+ibKVIb.ևBq X @ʱ pט,(͇ap($iq,d5zu,cSNeE5zq_urFd?qc3HήPxOn(DZ& z] ^]Vd|^thX_L^XA^XJWK9`37V/Nmϝxqm2DW8MT6G5V:8˩T&V.Ql=l?ӫ,!:QvůY^\c]ۨ46"bz r"fRGïGOǫbbyd04=C, //"]W|Kc'`5FtR{rؖ.!oÙ|}oD"9dz\xJIu,_GRY8=sE3\L_0%~.G`~n`ysS"B=^l9nn 4:j ٍc{=oS^kz3pkqJFX bj Į}޽J @%6á$[.ZL 0ƓSo!{x<,][ {nw,(`!IZH5L@԰7Nz׎g_< ?kY3 a z#]NZSg݊ fr@c"ƾg٢pFyֺG &jhBXM@G3e7#?&%C L6K0ؿf0n,GA2ɶ;p\erC 0un'H߾PV] ;d[tgD,؂QURja=nM7F005{<UJ4exU mQCℍĪ=C^R'nͰ؎9qRۘyěA` uEī|t[<~n[j>ߢ=R3NJEuuYNi\[3fB4zߏ*yv<3L,DneХCPW4p -e k W,hɬ!+{i뙣+dRx$[j<>G,j}%kkq!\&<#6su[R@3ML4LNŊA:i-CR(uJmp>?ƴR'|о83{⣿.D3rO;V$ ZAB% 6_~nYi=N3Z>Ɲ|dsFASYU[n"u\+L bCdx0= $Q,B%=ړKc}x~"s:tA]Z=| +7+1g#QJ)s;3NWEϏjL9HHXۛºb9Gz[Zȴ͔Ep7S q5 /S- #y3fG!=XԬ55>;<=z0`zA rNbQvf)(v\ѴTCgoǹ C T^{ב2т dEsx>S_%Ѥ :5O[25Ȗ-O2a6t,s,z\Y.uU}`O&B:eDЩVU\[Αߐ#w:"V,`9d-guMD#<'bخI<%O}3 *v=[xݩ4ClzfWZxJ},{yS`E݇nTTSIU݈ q`z% l3ŌRg̓4Fv(&"Մ 8s^+5K$.}X=P(Ƀt6rZR~^!|Eԏk,[˫ͮ_xXI QK}ESD,VzjMo,%R͜n yZXe AgYg(Z~_D1d$v 6b$T;jaS`sIJg쫿DzoZs%YvA1u*F٩K%zAs v~:Ef9:kI@  nԏ3Zr]Mb{sּhWu}A#k;uCl[C*d.sŃZ-T":ysR]=dJA m4/oÁjbDQJ˷"P1w֨sp_?Q)^P sYvy+)t0oeC]xR_vqCUE(j?dKR+O*Ψѧ܊QQumFyҰ}  U!-8s6[E:|=@ѱp)C T/9B r\gc~` m {VCuyEh@TاC`muY ~PN%B^fLY2-S4B6 '|)$X|X@YZspQ#,Wn4FQ9Q]noH<~mF:ݼ2}g8{YV-ƉgjOF1d3fuzCՌ*o0r{~4s2PTkj )wl sd fpQ;7&Ua1t5>D"HsL]ȭ)4RY1lO.uMMY#2VbBkƧfr7ؿ>=O0IelkGYvh^ak}ClܗȺd+ʛ^p'G k" vԀ!dUٱM!xb-D |4965#iVĴi!)jW'~Dj9HǞa~ ˩Z6~4/(f{#I"dt0M?1)ʼ"&/{X($uxd4#GDHGɁNVlr]4;`r p1/,'0߻&ÉzTpQsJIQה-e#OG=tFOYNIctH7]m,eγ]a&Kn(#EsQ 3i*?O.ʡm~87+԰j~}Be6⁼{[nּJ\\T";z 㾜AH#+r'8?2bo^]P!mQ(-JM<Ej0UIa1ґ>A8hGUA'4cݎk98䘞 ,uC6.KHs 2 .9f|s"4. _}7.S=$֑z|47J|K7PawwH$ "&pv9k TDFe6 k|-me.v| پfǑe>}4VzlZ'QmȄD.; bFe ?D+Wc/"2(9WqjBzIf|Dqy=C 暮~׾ h?u@죇{iڢD0ߞ}$u"[F/I>BS aј+63jBJJ 8Kwn )>7d7VV }QmQLLfzj`%:$4)#!Ֆ7JBˆEm}p1N 64ǁbd0%8Qه).mC^_n̉_{dZ1G?;]4N%wb ůȕ.BB8|zK(F ReK{qSb/MŠƛkKW $ͩ5)`@ek H\0V~eg=_X(6r9p#V)JBr SM7y\([ʹkwV+IoKD)fBpil %9 0oS%stQB=5nB ޚ"&C\kNojah,C!tOQ(jdϓM#_pz$6dNb Im{S!ܷv]>|Y>hQk]k1h uj?*9!Ť8ǞM[W\Xp=JtKr}ȏ k]9]A 0§=^9D<3BO^T)ԲY __cN? y3_Č22E]s 4$dRKDLV4Ao_+贵if5UJy.Y<*I>V(>q'R@1ö%6j/P>mEGԏ*Y&9"T+TzwjG'I,XaJG`1)$㴗?'<'GS Wϗjf0o\=֬~0LAݧCu-\́^w}%˵mjK_/9ؒPA5ޒV8Oz]}yu2 _Rє0h)C>=d.vg)j3˟O"xhtHߎl)A-H2M&+ޱKaއȫ"#9ŝR 1Ynڵ=`aٯ-{= MQ͑6}N!?o 5 9/`fR\jzɤ)@_D4aEt "TIOw8Qﳗx <2Q4ξC Nyw:w_oi_F y,>yG*ѵudڲEȑ6C\j; &VJ2.&"|iQ_M$<ڑd_'mv<ΐ']BE'Hm`H^&L3Y2>h&Ξ-Nhy%0 ܲ9Pؒ.'18ֺ~XdXt$wv\}ݥRV*ߡ\ҾzfZoSSX%QgێciaJKZαTYC" '> 7`3C2Zn4g#MH rJX@; Afh'[\|YP049f`[ zjwC ˆwk<հ f[9f5l{<.Ŵ ^<]߇JX0i ̼4#i DҦֹ*3ϚFv:d:k+e޵)ASi=sghh8l4ψ-B~|C#ۑ*xۿŠH=U:bH} c`jJ`p~ӄ!ѣ72;| ˏ D¦|R䃒i#Xi "{SqIPILC p|R>X[Nr243O,̰߿q$sR D|B|\9_&k0Ri.cӺD8?q#IDv&^ȤFfYl_B(/ G hIMVo fZ ^'@PuI!~,vR/aY%F8s5u|\P7y*4Fm]փwժd˳ј騈 J%2VVhxK]<+umxa>ƿ!SMcr7|XE ѰXl%G4Ze{}HZoM`ߑ]$6:㍏+F#` v45,E G6kK{Q1<9h$.+AüSQ-Ls v=rRgKVM1*{>* ވM CyX({\\AN}oy#aHP 퉵FUM+`6'th-O~$y6! }* #~$N i*JW3 fM`#0^%HP|j/o!l C0ݱ[ͩp uuY1YmPm4^kgn`9mL{(.f0%i HYz(B/Fޤq'*}2ZJ[|;l[MƏF#B Js,4ֱ&f r%]3.#C) B9l=ϼBt녬{L,TZ Pff]XOb$xKCfWPjPWɐ$zDʈ.U&TN$  a;$]fՒ6r`zA&Qn~(^_E\6wWbgö6]Es7e~5/?} &\u{5i@4Yi;߱&CK=3qKz!%L8N{s1 @?>g4*O aRN{?N.x Hpw/5VM>ؖ8|hi)7<=Jd IRDneHJpHآG W.LDd)84\wA(~d6%X?IoLB:tghUrJm1:iqs>a/,rG݊P1I_gޤ}6w8vN[/' Q72F:gJsfm.mbc ĥyA_yR!)GȌ얎h{{dLC[6۠90 J. *A쁀OKe" wA+|cW4-ߢQ.o;PzV+!@Ɣ+ +1hV^|yZB*Jt:1\i}<|YuxSvcPP Ӯ'Z {umTc "`% Rˢxp.c҂DC҃DF ^,CrQ2gMwc.Nv~r~UzfyUIVA4զ[+;wݐ*.13 ذJ vtJtbz[h;#Ɏ}K<|7jHiJLې-y'Zz$lYoX0̅ ۿw_:S+h&r]H@?]&0.Je6$[aVj1M1 M|#M )I&:+V׻3~nw,[^!?`pXHzZ,Q@` |wR=(aj)ޠ1cG7ı0鶦0Po@audX5% l6'%.;KRXBP8`f WIՙ;=*X(ItfP9qFoj5-8;2r|׮ɸƛxcu~ׅj2bƊ)bi&%\C4I2({+NbQ_|c!wg>Chh;`b.XB+t翾 Uz%:#W7KP;[=Ee wa~8ճ2?hV :-4(a#+t^s-g'.l1=-d4[cL~ΘΔ*:.{#Ϝ Ħ}KwtFg x/6QIYc1KRcG)I-c䘃ˑ,@-xz<>@7[ KÝ{xY\0J`׀Fx1痐HWInuLxA(-%;ČMm w9u8nU@{ i_pB:zW} /#+@>s’a:<<#>AFOP†mÜQ7dq}<'wT|qyN1E3W O0k 'h,ǯ+K'(VLIoz"X/3ǁw#W UW5G }}4|BA|Go<-F2k'zI߶6i[8޲5.ͽg6{%Iy ϗ3zDqekl9fTfeO4]Ε*ɼ+ZRHT&`@ ,za>gBjٞR_!u^?gJ|<1BK%M $g(Ku!I>`h,Š6g6sr8Z0{pyBLV5=ayrL9Ֆ֊kQ>ȩ9^|\ lXAĥzK5Ͳ,hrp5x'R螒ח8A%K$l/(|m!Sp>8NHez i$ HCt!#@am!"X^GWqqsk0ܷ(ğqv3ҚEaev6``h@%V2Ʋ-J|OҎ،x:O[X,̘WDUV5-G]JΨDsͯͤ3n-ir*>N,zpHPz[Ez qeX̦gG@p;bo|QT15jEl*dem/N(vhZE#m/sL䁳M'IsƿGYhlGesbHfIA DiWP \@MzIY:1i gӃ\*WںnҤNXX Hz;nl[ x>,H~J. :llQ+Q]IM{4Bj]U" 1uwcTɥx%hxQ?UFQ>p#K+(Bv1AA+}IǦEev6 q[ =禄w vhqqjݾUz_0T*(g+ª µ2T 2q s1lӅ(L o\ YڶJ'(祩whC5?o{Õ+;]}=Ytq h,)J%liA~.q[L=ifDv w+~q7+y7+s1oX˨$k〵3J - s }"4;B m\Kpj(g,VŶ+}]zX1H{ў.Pz6  ܋30$YZ4{:?03~@[V09L;|Idwgh}aP\,@= APC}`JWk]%s&dž @gE6TL)غS4.ƑCT%Dt*D ONAj#IV In=Hֺnjr-{ sʡړw33ւnJ 4=8O"ʍO'' $I"AʰD>^G~m rY_"lǶ*b4(!Xfл+sߴ>,|_L9rbG^?o5~IGm=P5۱j oLyHX+uVs<,HyI TByX7=+%LfPX礧lVGYXM̆7SVCDwY}Be*8%=݂I"I7ƉYSWlW =MPfGg |x@bu5Q3*=\E "\:٪>ԕ774{bd!ٙPpJ9@-GLcyx @^1ڂ0 #|L?nE*Rt^5E^cd_-0 WaA*"q^fMЪ$.:oP(I4‡:Tg*wV.enA #l>C*W6#}1)^&%NP~ҏUrv0D8fЖjۆkNja,;!Eap!Ox@[5&Vǯ>r2(7&]채g*nI*G>Jڲahdʏt)|uEmV"r[A&ܑH M~Ļ;A~JR7N$`odvI#Wt`n.flza,qXĪ=^qw\z7Kmz|@9$M`Զ.oCј(@tzA(ཀ␮% DtEf!QWɖ etÛvT2V2Frp$W숦`c)51Nٮ4ބB"=LK=?J{}՚Ç+=172l f.=ett <ұ7H8Ysp c}zci3p~[}`t6963x$ؤ,%Oz k)I ZjK^x@6DFHˏNú2Ʀ&XLFOZ,ŅmX%\=6XS|| w-nJq+!KTD0q;yzwmЇ]0}!)W*Wg%GQXkVUw-~_QI%a'!maUgS,: 6L_1}(&m9+/P\i: md]JU UhktJ[ _ſM%oZ{0BHzϯN܍uAzz•%;װOh&0%xy\U'@WI3>FjT HGXWs}ˣ7`Z∊(͎1W*3~aDђ*F⋂"Y j̩_JT(hc2JV"E߻/BRoTHTk Œ` Ί^_V,uxԜ! "Pq.Q54 3l_<]-Jx(FlK*&=o sCPO"<ޮjmTf#ϔdLMW'k+W#f7ʤMc)1KMON#NYde[|,sb EhaЯ]diAId8K"'uo7$9a-3%;-@;A\5D邁ހ |)GmUl_g7^s)̗pqͱq<2&N++p~<]zhe )4q(X#A8:i0Em'?d!D)TUCkT}ma(kk5٧Փ zw GGqZ詰/Kt78Ѝ,R1oMպϧyGf@~any -rVjGV1){BNH qLĨ%F|,Ĉ^1bp7=C[)t7&!'psPTHPs 7J"Z,*8 ɖQg*m 7}pu}-?4U!)֯qjJi_&x*rQ2KʙfgPO+qQ58^Uv;%^ 8RIl- 7VVr 7Onr_F3Bs=Vܺ]< BUsy)6I$3Dn4χ5_)!I C w"z#?L?jt0biYXm0})ͅ 3[eϰ9A=Iw9~Ec@Id =ZBEۧd:Fj 3@,Tl$x|d@ĸHOvA 1 N}`2k.R+NmLU;.gx!8H,Go*d@DVI5^}2)#tMVcbr?9zXdT֊ЄVI'RGCWm::it/<|W3FpMz $UOLuHK:y~ abFl zA&|N;;Q x[] ? ;2G,iӯ?8(@&ٷ) p5NQr5-jtݘ&hp,+uqtdGue1Gt~ltmށ`eFC J˓gEl uԘ^VYՌE82r0 sL R+ȔI]}&,{M+AxcI*" ;g}#Rn=/LAz4md,RAl#.k[|& ,WO3U?۪Ժ%E;wِƊ['͚^\Xt1Sت kO}jfjZ*`w|Q,K%MitDz#vNT"1E%|[X{$LAA_.kkˡ3^I5h;:o["08C&)t^8{.t\WvBcI~.|whqT''V 4fGO֦b@]9!oIDQ0=: x@+5)N,w'^R<5`Š+;M{2ȎEP-+f9cIJR'R/?&8clQn# l_ݣܶ$hZk:mӲq -N3ANETExbqu3{%^ ׆LmVh>e]#(`u WM;,49՛wB`AM1Djp#u|bV3$l|ݽY ȧ? 3չ (N AS#/L"4Ir-m|ew>g9Q(VWw%"@F;]$;q  ';;~iO1'ڑo)P~ vU wCwM/@]gL#ee7ǣ] Pl* 8\>*ӋRwGm  πb ۜ7g Odj`zp)U3f\pmD}pfY؊)ԫ[WÒb 7=1^s1%By* Gti5 2!, |uQeHߠKR4`rAAo6u5}*0kQh]JX3mҡ~ V9j/d K:ƭ-<~:hGȕ+s,S" XIЎ\vtNNJ7[CFw|[С[wM#j{FFQgO-I{Pn҆/+HF+iHy,niH֡wm^Z|) )Ji:'>vՇkä6Nݓ5(!Ux(^̐ [y NxgSeZqhjRVg7\8@MtGX&>3HJLӁ,NqsƧyMhZc +BԓDh"3m,uAj'b*Tl2u'"8',T, 88z91.G<[ S7aϩ}H ErnޗSpj;}n%hԤdB6Wۯ#=E)ejZ'r.ƥSfp`:\鐕B=WS?A求 vbOx^3Bxrh6T4 ڿ2dx x,{^O.1S2ˇGjd9p~ث9{,z[J٩ء81tػuKUL/%P|os(Li:ȤE2$ 9MebU ygK9)5F ĉ#I@df4pjڽ%Kߒ^mo ʵߛpF^D ,Բi#j$>.p=e-cS (9׿NE[p2m{ys[_'<1M'nn<GpAS2Wpz"!?$$e8{g=nlNW=UB|aʶ$A:XLL%,,>D$>tl.619TՅbCʻMjlAt Ə !=4@+L<82c0|/X]_Hig~g m$ع=TbV0CC8&z_p7Izή1$C'akn][|`?kxL2%@ Q#k n OGS,JDE[#&Wtjiըf2?$Xag߾`kAU&dq!e(iJmPcFQ2Ūo5|V(OVF!M- |7],6G]^;3 ] TZjvT&$B"fzI˅ >/2鸻&'a TIcN`1g:U*opbNUt6qSqoBI(#9oS$0&\`j2T`wAq*THC0a.jbw5݋&(#GE;%nFH͔QGeWU~E=$ JO0UUWLyW& {L yܥfgNjVЊy/^l. ?T8q rhmvwJ鬶,Nˢrx;NoqF2![m}؅.zR&o-a9Km*plUC}B(maP[#~X| Z"# 443CF:7̀s؛ A.LF}TO4fCI} p8&>?.kjUo^N_i6BNFX!ջ)YW y1j;̬rj N Hޥ/K[R޼kٮ:]GpLh_=RD4j@/3տIeG׽֋Eo hi \Ű}̨.C췊7'cfz?ֶ7qGRdcȵR?79_qNoI;),pJ;fƼ\5ύ8ZS!) MF deԢ*u !,%sĐ9>j(e!Ij41{]Җ d֠ʲYGNp׼!1Jѕ 1/tdrkw"'3yGHj0%AG'Ϣ@ڠ*&_StRRHTrۚ*`m5 }K$izQWz{x}GJ_ e nL%u/nncN޸'EB{>+TSǡN5+q5~jmx@ Zg!{Bv%8|B"m;I `FZΖօ4SƯLjPMuk KRZl8e >uc -DkhX 8=; 5 ~ FiJ7u"SOt&mJ5B 'A\;4oD_!~a;tsy86UQ4\MDڗ얫zB.R.:ôI}D{iFl6,IUg-5mb^Cocu,cV[c%%cjm8n;b9;3|!~dT;n#&wU|XX:8rЀ:R|.[oհN֑I '- KR~hv e >v,5wppqc;!QX=f# 9O{Bх3%8K!G \EWng*MmaCtnW!> 9)Ex:B&ḨPX[yôl O70g@(d@F:Ub0Tj^ qX/e`-,ein ä=:闆R e-Znb6Z̘NBN/wy 7W'zLU͜–Hh]X|o8txy8_qp(r63qbh\$TOpmh4!gхg2kn$૎5#:`3*ka@Ω]̔Xe%-׷1\wHd |͊-y$Ii?|ouD %3nu-aҨ)T @XW߸q(A$2JC]!"IK\b#emA'PMV~3 yE/,XέrU;]FYcs(Өk'3ic0)lG 1LWjrC2 ߷< ~hWel?QdY.wzŏױ#3oqn5}89v'\S 5TE;|oҌh`RMYi~.0x\X{:fzdp{`GU~?^1ۘ,&n|un˳q_虪 DLe G1 jrW)*qp2H6 f}֣o@ID'ez哪8#8b zlʏ)tJ.2~v%#^iuV/]OAzDNպ^H H:djIzbݤ'V#$,3N8g d'h $@=WVNz>q]p!XI8;]j2/k$=z-Jj',uϮ?fP뾋 : 7?'+=hHAU/rSUgɳFyx[ ܛQh˸m=32djE`Uw;{?MԖL!ғ~6֍bѰW&]R. "bm(rAhPk`V!OU$R3c \p6m:`\wG5K෽HG/DC/ 8|R1V>]ܲ޷5$PpCr@-v!P2o+_Q 6Ž4%_z/蚲TU7s<HY8ƛ~R^ϡPQ:Ȁ:~Q0WMJuǻWlHݏnh史Eq,U&07=*SlQk6TݎUV!_ITF;`.hd)E;Ϩ-!{G.m-IVs2ƢeW.Si3.@10% K /ӮvV_3j(J|R ,߮_]/Go=b %6ѥu>M1 EhBƁ}rC;мC0 x^_3Ew;e˩Z6L62H=Qp=!\vrX&{HXM#fψQ~5G3%t '.L#s1Xjs^t͌bOqE B8<ڻKKv:"7R8#rGGw߰gG@Q|ܐNX_t?+ @}T:bQCUmxLQ#Ԣ dlQU-U "qo t!&[OX7I?0g,(醩7<ީfc%܄p9LMQ4"ʣ ϟפlՖqGΨ,!+7 u-Hy#^S0Dgz"P4 G"q# WpG!l=DJJMQ.:/`t j E¹N}N&>qr׭{$翇yB橋U%[^'M8Hѷl5m5DOJP\$lea\ղbj%.|[Z;ɽɃ) /0p7[_[TXR9U!Rk[S1*.)>7-DdPp5gذJSZ*w-ʆlP" =SA0vMnXI"xJU 5H>`j___gVఊw٪:/&&V$Sz`wLFr%|Gϖ9l3F1i# \ϐI);{O ?ֈ}LK1bl|2w|Ore 9'sOk0,[q69b\XlDžP{VuҧeYώepP o*--,RrT= P`<)&H4u-ϑ{$R`\H Gֹ7C<o0q(omu@Mϗ{ /k(0kc]ι%>=2}HㄩTS)u#bm h%s(n/SE}k"y{WDK8ltfPl!_BK"JZp'1Vh1խ|"]$&3Ą1% >֥\ `D리^Ÿ $Qi"K-i:PAssX :GqLvTPW{B?-mm#Sx+p,&E[*ӽ3,nrU2u:{0;&4ʾpy7* zPEK]OUX GNF3͖? <'r_jt_"Ći"\,^gvTѼ@_.K = Oªɓ<ϋ7JٴwMYvU~e>K e䱌SeW]Vr$~.X6K<̣~ 0Pxn"vt,ժf : };31ڊz#`wJG>W= /|C-O"K' i^f,Scۤ')*[{Vk7R8(!e3rH䜲TQ xFq߳e_A='|܁tStDZ5,k `AjԿZ:~8#2dfxrOXJ?XCe /ҩa lZѓVe?H8w3eCs(Qc>RF4$>pmroRπުm E*G JAwP9ͧs*w&`JRӘKځ*|gJB:ʣfKJ*'?02lmnw tgK̨}ߒ=x]Y :u(m!4{]E8Tv_7x8\- a~~Pgi׵!XҚߜQ*F0򃌅+֙[xY:5ʇ%h<&P^y;ǵx{hYoN@"Qw*d" HZ,3{y .$`E$ X.)\N}TX.ɏI@j,h y4]PZ#0lJRnGs=r "ƅ`;aW] |u:z3Ko$e Ź1ïgN`QL.$3u7R2<<*C6%!Wd2)/0;5s% l C$27jmï7XxďjN*2[y@b !$g pєk@_1H+PaD8%ߡP3I/P9ԅ;,EFYnޣBDL g"iKZK%zkUN֝|0IdG (B:ݪLx|weaHt,jADw{>ϫku,FFOV%b􂪫37XǏzS $rGI1}0;.GMA1곚s0@k5avڒ#bMkR(`C= @TZ]utہ&ÄEOuZfLଭlf 'hO?8h>*KJ,/x3.<- O1WIBJ)(XIo2d#6F7W[NkHR,liG@p%5[KhKuɴڇW dAM~Sy ?ks8 qPQj Cq Ћ%9&;jgw?i[*L6~#c (w8hLFj[X(%ZK7,AX-wcC;C) '*gU'U*<& LGE5n,mFf$'|1H *A@H[h{~QjJ\QgrmxlA9NI]N#qcW̸k;4؞BQ="f䡜o EGFg3kBfK QN'c/v$4傤%/ǂw .![_-;0j`` F}?!@"$ QFU!3-y9 yQȚK47G,C~w`j7WIו~XjʣȔ=TyBtYv'DL^Rl oݨywl"裘`x\MӵOJnGB+nJI$K0l!s(|/pqTthgkd?Ewjj4>zRS nf'oހF2g/>"n0+C.f!DvFrDtcp/er2=ZQQi8 \Up.6gd/8tݬW#4kcC^.l?=YP f`wg=2?- ȿW`9#)A {ٯ-ŕjR r#7ߺr* /؛p"#*[ªN7ǎWN,mqz:7wKH֏d/7Hc8,Y3dY3g =ֹ[6#I %cClȎQcZ`Z=%̴-3?VuA!Ì=@69YȜ΋d+z̴r?5=K~pIU~ஈv"xH5kxܝ{)3Jv 2-]>ͻMr[lMz7Fr,Ź a˝5}$KgMN/|Dyx+#/K,ȅv~`4r!dwa!;m"hIJuu5 PyQ$t!҆ 2 :ْ'9dUT&+&EXjgZK@H]zae`cP~m?}}/V0&A,֜#iiXfV>0 AQ"$G.UWÛ!h$TD J @Akۤ$g (i +zSl[*D%'\hDXr{bluoɐҮ)C!^Vz*d1\|E{ 8Q< RGwAVȵ5z>s;,M-q{)-ё `h~>f_u .3AATi.,^W%UN.O3MrySmk>յG|Rҵjn}|3Cy7V@Ol0EmA-$J rPAק;?x(i{pA^O5bV6+67b!rYJjD3;W7c)1cn#"y~'FchG#vAfRq78q-Bye핟(yNim4zXP`JmaƞOZ ZqRyR1W7*[5/pD34εe㐊h a+S]}.!uj?'ᕿ0ռpB{⑂KNSVT|lLDT~PB9'9eHՆ*F)Xy۵E1HZ萘cR㋚>j,mQd҂s3T.uk*(!½k˝Z֛݄Vx3;)O,\@aJn,R&0c;c<,+1[^"IԂ}}ye$}-o/\jO邗1N٭R}žvd1#XuiYjKSWswr !5h-1&DŽrpzUiFqE/S ;yTa%6LފC(ɾ0gɉ _1OЄ,`M{O'rBuVWD&`@ox#X!pe+ wۧ;mL+%y[4ϋϮ*& v\:#|h5YQVIԔVS&a-!``֖-&st*P`RE*YZQ[],c@I^~,'4&z Ӄ哹ьu1:mF8Esڬݏ;1v=]k/nuNwM7τ9j fs;]F?hا /7:%,dScp@;VۯQp~H}06DʫgGlOo tw6 OKw =Hgg7xݎ_fpy 2 BJpIM(q4Pd N4)YHEa{`'UCņr2@[F;9F5eQ eܜKI<@g,`vpphu 0UZMh^E&=_e|L('F>቟~ U~BC?R\X<#K{抽nI_o=wbQa57q\AR99H>03^&E^J$k_ҧAUCVV,[>x@ E&@M1{{3u W.0rA 9'[Kg4){!)aSX~2Z} fAl.F# ̇㽫lS`tS+=(> !̳Dd$SW tZ^Qpe(;;'fZad+Yh5 Mh䧆=w!bStbXPw9-/,t~zuE.f}߽5T :Z@4hB& +x.5ጯ%z?znyUāuxvOPŘ mK"MS LN'h|aIS+( a{>TQvK~SjS=J 'e1f-`#ԩ9)w \C-u53ܤQ囸 )bӝ7J"+-I%x_B~F+Vn\ٖ1-BٖE 'MPjm~itV=f+'Y 0cy#(F Wh8_s~f'eV4GNFse:s:obro7-ݿt6_ϻȘ,R/QFqkrW{24P3W3V\@R^gR Ui>+Ss$`J6لY)î)X tqbً8&4\Nu!6GOGt' fvvxfMP`& mɆ[_qt$xc1 @AT%'4D&xp>ÓXa)PuhfXq`TJdƦ/,K[t(0RDIqIed&I 9 h;S5 F ꇺ{& R7mu~v,a1l{}Lr }l@*z1 x,iU6 : ?r~!@igRP~lUN k#+PF`("DJ¶<yTzR&ē횭7kr+ 0Io'2VaC~e?]S\aHE@Q3;_ٗdu9WWJ`uR!TgQ=ߔ‹DώgY? R !P#@Ntxɿn-U韈 @ ^O$*w頫hM\~4O{Dodަ|VEnm+b[e1Q6Ew'qRDLqq霃IPÁOZ8slB:a"YF` j4(j+oD<8:;IwS4X&1:htgv"'> m&dNdj Y`)b=myoE.^LZY z/D hP=ѽ8R!``#ѢY9{ *Vͻ g S_^/:?w62̣!ZHSrz#_I[˙+]l/wwK2q=s4Knf5c)G7iu!iY߱(U0!sw]U"wl`-~3 bGX=RtRDWm58k =Z.|.rjύ2_ZyvAD-v?Lg>v[E$Ci䁉e ? "ٹsCbY+Yږ0G'ͪlm\Z~qmwUI+f}z faèEw^We Cpҡ=EB7kw#EXA?L?h6^JdqEbd0Ly)eݤ3=B-P+,[Yǽnv&R]"ᖋssߞs`Wf[omE!;b:@ug"Y"hfEL !KrGqpvW ˞-)='%QYLD{OK}<=h="@ڲ,J'x9k\UYީa!qLT׊D̴.)e<JfVoJ=C(@7Ӈ%!1sSE%yNHGr/6wya( vъyg@N<#-.vW5ٙw#1+Qj'GKm1֓''ւ*\YK`;MثfAb"{pzM h9B#ݟm҇%A컋R(AsUg V~N N{Ũȝqˢ<&˱PL~<wwe?~6s!{=^CV;ǖ ܁Eyb;{I_!~L<؝ k1 @.#`(X $[H7o~t7ihnpn[\㬛h;,mNQXƦD{_'Yԗw"%j60m[|~^)[)1trvsi֞ F{xSیe򜰷#ǢȈ< tk^ pl2FFfT )ߘUet,ԑĒ/|̽A*U1.38=1R}O!^|p67A/0oF'-b.h5[0om) *"2~ئ%aˁJ~45t՗C$/:yUчC܂ QxQ/gp,N4M~+rKQR-O ]ͥ\'+xo#h[ v}C..廛EEV_0+@J\0-W~tTM%H#@%B^DzcR\LǵlwV'- PI؛wNJipquMܪz6\mhc!*a[SFJI`.3x~9vF>`w@gJ 8{]SN((L{d74.`55][GOW.ūo)D<uGG7_9`a2[by55$˛d=;x8 /GV1N!G\eS gzc,?›L7g&2\wÊ6kbF3&Em<*h=%hRJVM,ц$wa3ǹ PNf%&tam5q8 F a1ctB8g֌;iL cH`]&>`q`:&Dmt9L4˒[DJ5a ,ӔeT,AuXFO_Vl)sKyѠi9} Mj!]x0Z iL@H2R/kglGs`Q ̽HX|0ݷ2/n2pvȡwNU *` I؃SUVpK@hcccPهgTĸf%N\ \KOyb퓻D#AM:b}#7 Xj3oJ= Adw"v?u߬bg8NFFHqǨQWU+qnJR L@("@?npG?xaNsf샩zMr ^M\W:lqT*LusC4.\U6s}iR5H̋~/݅ZE,^v}5]8Z+ʘ?&#MG뻻J +%5>O3ӏp¤3!+@uBU!"?O#Jp!ZPU LR_I <; >ouy;`D<@SbU#3м9~if2&^1:eOQ/c-95 ˺U3PEA* ށ?r4Ze($}:UdOX-㓞'2vwȹU* EEiBrFRoqPVBM]8`sv Y)Ў{5V),;jU$5si۟ ^UlVHy_(DB6$Dg)lz,OÑΑ1QxT%c|>1L ?_gN\Uhɱ1g`$)/97!"zǒ@ތY{ i}G؉FuhBލ&-4 %N;.ę,?FU zXɼٷlVbaQ0)J u1/w_™p&AN߷sW2vip4}zűi0 "O5\(ȶ`A4 I-Y:81~Piɒ"Q4@Z|f YFpekIwzK!jgTwՔa\ehC 3r?]DM|⮽Exf."¢R03<$a'!Q s+a$Nڐ[]jhݍ]űha,0j dV}CZoJ؛7c>$Fgi|i"̂D/hz_:|Rr)JMw&Bw ku TMC?mLJ ǟ? N ,B mwML߬$n81[SPtس/b &6Zl.yO*^`ja<FހJ [t02q}87(I{7h4~95CN͸!؏{<Û.YjZ`n<؍*!Y Ԟ4KfF=HMXOU ׇ-#Z``Ol֗qa=^J3is>߮˛aJ B;Ptk`!;ɳq'K? *w!}M8WSf658,/?g@_i}NFIFbԓۇEa#, Ԫ Fwo7h)\>?qs>fR"=[P `vN>zX$0!ԁ; ljEO/.eykWPvGgNEy@npr(^53E@σvCvW|B=<7Dծ`{0a* -7@$fhY*7h.ыsY9B@Lo4FҀu$ [e?/`xª4~(U|@ۘsWhb{FJ5顭c^P#&Hg_R e9HY.&RձS4ɺQEw $fY"OZ\d1I8dhj]Ff-mv!Y [ 0˄_ڳ׆݀Y{At)~=r ˽\5纼a!GtFC;2[f*%wܭX[%ԻHcY0~m\PU|Q ?Awzn$Xϭ zs;[ 0Jc`/4M/7kkfq;Ik/_W{r$?rhN߉,ͤ!Do e_[b}'/0 Zt-Haz'Z\ |lʈr.xڳLEz]L#)ٝە33)YAa`1ZmBTb$t( 1Z~վ5ĥI<*l B)yDޯ~.Ljºb;&_W+Q|;PHd`e}܋ DI"KMv^8Co;iu e#_?ș3;Zz|É9fj%Xb;.{#@M"`B% T!<[ldRݟ]зϾJ2sl=c@4\貊#rv @6M$;Mh|TrildJ3%XvD~ryÈg &ˮ-|̩˜tIH?r=/[FF᧊8\WIғEؤELS GW7989 Bca_F$`* Eet0 W{gXfs'KG/5cHHs*ާe|yY᝚xbqXdT#lö>Sl{Z#<o`lV-p/sv;% QE,nzCm 4ؤ #͙ G93sXQԕ~fe|1J,艆du_j4[{ݙ]l#hbO&JRU +mMZ`S,H*2~ y[~5).=Ԫ3 wQn`-MSKVOht^{oW!U >.~CZWS$cTU$پbija\\}LXXt+K[ȘAF BKQ!(}jt|q(JT@bpT?qcIͯni&d7fFp@HE<@IV'|Ō\E#f!}6:\ޓSqbOɺ_F aķG!ӞwJpF)ţj=E_նl E7Qʇ?;R tv,C9ͭQ$qY ?uxź-MkfBywD253 _H817ueثj3<>b9BIc9>ף\v. 4$ ٷW>MBufEYgo^{s(`aH }>1pu2]Ϫ2l@5l_}UUS$5~>PjJKglh;`R W iQyJd9]g?YE#g# wS>Omd2Vvc2Iܯ} gfK(FR W &p Wʅ;1۴Jb \: 4!!NCz/R8n+u;rn`gO;YԦa;9ڔ8m?4h)r? X8P#jp 8kMjU`j']_b&?z ƚ09ʛM*~0J,LEԢ7X5R!$)Tv@O!,><!ޓhyC|3gBiM<YF2A+o{Nt^V)"޴G]7 !mO6TU3)LmrT#m|Qu{u.gR͌Q񀚢 3k %*7:2Z:?|pYgeصeX5kor[5et r!c16%-4%*BĂưT`0tg$/D9# ?Rb;j <.Nϙ6qR=gB.z8POR] rZ Bɪ0$D*w[LAp`nb.Qb K sdhX«?Ȓ.q`Sd x(0%AyKuh=+Lj?^qƚ\کbUhu DZMBc]7h"3)DQ9HG [jD-=$q8?_SPQj8u$WL/cX]XjjH37l!c1{xCkw0XH9 *2Rb (Ѐmڄ Lg=-\zN&vh+5AjNM+|zCȬt  yJH1ΐ܈&vz;Ğo-`V\'n(oCtŒ&#bWXq z9riĔ/R_HxWJA fԚ‡|7 ET4Į. Xz@˰-UL}Qs'lsyQףpUHF{rr÷@!~dϔyɊ"6YgAIs'/mP8KPʎC$k 0c4ŮC: 9?.^rl 2|"L-}v_S11K',JS+T3VOm_CHs1XQb)NּA+6^!|<H; SAGY`']O^cPX4aȱDN(WSHa?Rs<+AzZIFckS}>u̗ux"zgys`xU'ϩe9}'Me @tG})!Qt׃g55z1eIݯbcQ/ͅڅɱoq!DZ3et `T??Ԣ-{th SU{13St_Yi/`]B|kjߌorI%.7eZ#"ݑـ/&0:j ;4W9Asa;Y~ԑJv^AiV"ijk yXm׻&r-GKF`e,?~w֔Pp\{ @a>v@ه\ȍ(SU c6o@2s_LC]XB4ufS"8}0r(TFϥ| f%1"fNudjV!0%5h<. c t/sAFl+% CD)"q}b*_?!gb&L~iIu"l|_Uv ja)& ^+%'P5֣:Deb+8Xd$͘($8Hr588ۊ7xM档tzU?UiyDW0u" :]Sae`PaJ X( NED(z@)#,Ă_ v$ `&SA3\zK+@[Bqq*WbpY"E喏o['a z"{MɵLeЪO4|) "E'%Qdhiof'E*l8`d-lJ,Xbj^' ,:XIR>ʗ&Cr_=zy ـ}#bt|*m{dxzۓtpӪXO׸wA '&)Sǒ}k֘ԯo}fNL?Qr4>$I@F15P9{oo(0L熋??tZi5.} lz[4j/V6YZ[ ֑R$1c8֯+&/,fo!P qDАZ2$<ܗHM<+,!V3;*A$pc5!е`R6 ǔgHqT}bzgյH˳0m*z"}f b cdr ltKҩE!8=k!a^on;"WT+;~i3 c5\aKyUw X{c獛!r?/!02X}M*R4(f=7IO HA 4XX輘,6_WGz}Oa0ۼM"RvƝ /ק &MNNR>3g9Fv^ NF':DV(gizM عؾ/CMeu'(v <8BngR؉_[T;;

w/RMS2\//5x-#(-.u U.%ǺFA0?ctw+NSJ_u FcI5\2omq&g7(kl6L` l# Nȇ"zoAQgh Eن[c*94mPvC軿 I﫪Ҧ2Sүp=9=`qޒytǺsb=;v=1\fqTҠlu;oTlJtePc|Znqh*f[y0C"}b[G;rP6:o<|N7/-jGӬo ֽ<%~W3)YdP 9tCL6c<^kPI5*ujNU,3 ^l[ӭiN`CDɳo3{[j M4F'[ݙ5iu7t$6 j}&`9!Oj%:_ۚ^8*ȱۼ-]95i4 U4ѣ9#?G\ͳ(uLE5v 0x'#V%3@sihcbuf]n)e_ tH('Hf\Y;7 Eӭ̭+%cDe>,SO+EԀyan%o1&%YEرMƴDޮ%ߛՖ.n)+UUC!d*dX!=_mϵ3n˻p," TsÛͬ܈q|VUgdPdL`l hJ1g9 ~iڗOt"8`d?*2/dir-Z.%51#ύR>T6IC OA&t)ۛRg&\.+Nm>39w8у 0s1-s FN/_t]v.MZaO4^MVVf:a_%X =afBͱEe-B2zv+T,/'*c.:ŴWII84~;H$oņZCp‚z@:\tļ!Xp N?=kCÆגܟӕ/,Og-(^JUӢb"Rc{>Rܤ 3|߸Ǻ+s}r mW!5}.  C_v00VP\QlЏc}z>`DcZ@ݽ6v}zq=%}TtZD\ARP<9@L D%YYz@fN7q=:_xp@)q>/{m%^ƣnְ8`ʟ2 DM𑔊ӃQb!FS6,{!mM 7C"|o-\տSسM@-:`ޖVVb͏R [ bŰ5MvXek%EWIwՑ#Jl*$$gO<'j?le {Jaܞ!_' ܏`-@o5WS4|NLĺM{'NA8"*$^j˯(RFD>ǞX)SC]#\Emp _'?Gf$rs$nhX;>6z;<3S4 ;X>veƹogDnfS5_D" A`13*~-ΈsŹjy{J>~@)9R\TL(w B'Qb,6+GY[[4{)gM < q[տ's8y.d5;_W|I;8]e"xȪheI$=#\FN7bKXt4sUHۗf9fގ!i6:&I;"Ƈ8OeQ!e1=Bќ8qGZ)0&cS"ob^`6;Nxi1,y,U"WfbSD_@0eO;3X& qjY>lj^#xX /g9˳9jƓ7&<%'ao <YMc f{8YzaW,% ap ^h.&#i8wB{51c;DfĆRFd(^(VX.!tK\RL߮/=ecX hFKv.n?k04%Q"%KbȈH\d_<5چ2b 2 bіuP2P"@, }sྴPĻe>/KIUfƚcx_B"/:!cUݜ%b0={ZW="ˉ EYb)ޔqGA|lrl}7ݩk^%7)zF,T ά);歍0|/4v;k7؛pvJ8@?W.Qt_\a@82zE"JP[@(>(̶j4ƒX#qHg4V=j9aPZA\۩_@RUGGKD.AG5UQSΖ36qrYaPU1Ps+o{#L1xG>ؕ$׉ƙ&r7șEpRco^dMe0|̌3ɟ5|:S'bRXdTbb;P.9B1 2AL7g.z7j?-N_ /s٫Mc0ݨ1RtǹXnmMTm;!\͉ёW9gM23G.U)Uy-dB·atx4\g&y"M8]:\|n(HxGDZz+F1*Wx}ɸbYu@#~[j?` Z'W^ywa@N&فo_D](vx F4>#KFd{*̡͝eh+W߭@ZN]'f  1>tH*İl `tƤ+^PbujyNabwT+"zC{{PpTGMU)72G\1|4{~ɟT*IJh7AP9/9uZAJaQ)hF_)Xk">Ue?~>}nXaU{H|Xn&& Zqo1MT)D9n;oZiO@ H#z^LkP(sCDhvo'Y`q+u@<`Bȳss;/RQOFk_NܮnD-gz>Ch,HTHC|S= 7+-;v0ћZ,I+[/:3%?wbASG79Zam.3^DV kF=fû%Y/H7 V:b j;vBOpDCc:6L' AzԃXp!\1؈Ԁİ QĭiI̝{NF4vzL*۷@;hH:bȜ8/EW咅;[)eTM)ç@tj + ŵlFNk%0<LD[E|B}+xK8p\$5Zm(-1AC#-8Ƕ9ɋrxr+UtuϙˉHT55M>tRed#]C5aC$[d_: U {wvJXfgne SK~0=-!iw-VGHlB}m!1=$˿T431g\5+PO! LRʪ|1wz ᡩ=YSĆ8z=RWbB$ 4 KRZ+%߱ 7q3?:qF pcũ %/hc= ;;EfylSauMдH+z4_[ )#OQE j>ɷ9(NF[PٶJA%cx=9:ۈ$O>F N X7+uo:nKe]q&ihT cT f܄jp0J-9[]3iܷ_De$Rp bR1ILbX|^}X/!y!L"rqL0,_o8Ki7NM郯\b ?$,o%Ʌ,2,E.ƧPG7&b)`mP&NSNmQ9!̩(Aw0.ķqB#iLJ-%Z1\s &cZ}C #Fռqp]7X cg7[TP:0xԤyOML>B@/6Й=["nO_r,@bA LxxLVxJg}k5&'OD;wђзo?ngH%S'*ܭ٨ZEGQhpׂ|p2'ql=:<`md*x1[^y\X 07t;)`3lAϧN |^a@Ks`oA9S5y9nHVj츯IhuV38OJ$ cR/ Rxzs8~Ǯ7! \ֿ:y9K}~|a"1mZO٤9P AeSz2Ö #~?cGrl#sVԄVМ40(vrBy>!}2>6,N#%. ǐ6%-$dQGsu| ]hU07[ʢ%ĚPniE .(eUD iLbGSc3ԘV[_G#ssz# Wn}zwJ2! #+@3a@áwn[cC.zDH} 9'[6ۻq!5&F;V--S!\ɼV;6{HcS.Ry0u MWQ` XxlLgׂ)CO7vEy-dN7y5 %Z̛n8pip;lIGK*YmHOLcJ9Q蝅0A'> P_یʁN_%d4D{XTN8æ쟩/d< =Ҳq̶ (AIoO-~&@9Ⱦ&<#eL?h'LLA@b>_t\v ,m&U}e)s.GVPj^ jckͳ?y}u4`Hʋ~s0H󚘊 i]g o<4PVzl;47H6j:82lSa2GJg^Hn=u)뚝y6&(lZZ%6W׋AH'0A[ mjU{'@Z6޲ rwT'E4zI W[rMMկ -9zz5ξif0|Wp3@Fÿe朧SRsȖjaKР% r} H0tzb8t}cPYdQސ}VV;rv}!8afejT11A@S5ZdGޟ]A%<=Cs&g6su}1ߥ<` |%󢱶ȟ%ι2S tRyV^7UL^'>8ڽ {]\8lv "? pk# FLO26KzV[X$M}AZE4;eFKrH_~6qm}\6tM GYR[LA{an78NCA+'t%c9V |қY*%Jɣ8g?"@Ȋ] +Ĭ^8ޚ:6 cj,C ]j ݃z{Ӌ? L6K c뽕'lH:St_ὢClZ1Pt8,ֿ*2"`x'42ۏ's095-=')QpPrhA^ Q' N/K9:aj&IӪ3N bN-_a~9)^5PFO0m$:(thHf$ҍHhGmQ^M{ĜzkH6ف9OÉݦ{*EC%N)p#~i{X1ZLfIBqi (Le;wf5x)a5D3}G{\02Qc12;Ы6{=,J8A KX Ϣ\6 2k̓^UdIQ1/! `.\0}"d/W$ĵv2&iMǡnKAV9nX_#5AwoX*#J޴ugĚ%:{z;ÃҚ% cۀ7,2{,DҩEy5=dlA<nR =#ι4uRЊwuN -n)@2|dxs)*-׏aN=g6Qd+?ێ xtX:E jzg h ׃ʧa_膰.?#va/ģ;!=T6rr 6^|?+XiDVoV1A߿QupS:)SJʪ fsBnqf-6 5+ P/bs/e^|q>K<QMGdGPYϴuF%%GlüՈM},kMBZ0`װz֜c򻡷 0fȏ`d0.Ӆܷk300(ml6VDzK}&wXOH.{/M]1>:`lCc4V~3\i) @7y"9s؄c $MD,Ƹ L^}`ˇvO)a38K/UXJ@Ӟ#p&I6}]RA"SsHjߴ1q$7upxF[z(77CF{tg̡Mjg nkPjGz?Q9w)朾*5,KNiifS\ƍk>׻drI,te'O1PDoJ?7nD"X}Bg/D,VOr/w$!MoVLW5%vJq~εNXY3) >2۹{&%#vx˪s/:|HU0ykfiw7e''@#G5wVqnKqJ3:SB6r~}smY^ܸY--^25>K l$I=5S@PhכmQ7&cܵgZmKmSԂ2@wdO9!I7>o(_S)(^I-=hE]_U]}LVѦd{tuC˧jwJ|WX g!* F <{vWo0 $tNK*,h#aL3x9,!9u_" цHeVrQc͚a ;ތvٖ6:{&xL쉫@c h<.&(FSϧJf<bl:3WsӘ;!jla:O QͨTW3J O&Haa^=> DbWp4GI3B5젼z!I3Q:A䏼?SZ;bn↳4źqƼmZ@`H}351V2-+qWb2fGq&Gs?dHuiK2>?LlBs@3{\#ALMX>* #"K*SkZ{7U7O}$PY(UqXUK79M]L睴eBu\Xt%i@aO8ibPus0 7FN\ZXvg'kWm{ a7T>y}WLM "=%tIhDEGy$M[}`v9n#dK@EV40K$@5CSJX7Yuw> 8]BU-"̇lKk̙A@z.فŶɺ[k+U/ßnf'`GDz1}{\ߍX2vԃϢ uV(Ֆlf>%@>q~٥.`z JAPLϸO6f?LXu oe+>c |*>JqVkyQpy[HGj!uE4e_{k'zW#t9|BèIjMD[ 1&W ]nʗ@fPJ @Tx:N6Ew`8Mc=IP/kɽ/eS|[Ggݣ +cЕRQ.D<pQɝ?XJ"<ӌs)3EgO w uBh6^,c4y5OPi/x0V*L¯%cqw+*B WaLse< IY$CA%q,yk;OiĹ%- I-P/s:9drS 1Ju\lqB5W:Em+aRaDns.(w.`VCPb;^cۼFe1*tBns&rח|kdF ;YZX369׭nC6?e(z!k.`|+ B.8i뽙='/zՐbKՐ>R>Fp8Ξ^{gJ<ا "I4+iՎq9q[GPz&坃HתJ&, !];rفeĐ~tc?;][Įn`%qB1kbm\ TgcWҁ˽E(O[mWMT,T,ZFf`+զ1[#+aʨ̥-c@ ڡtY69S3.cRY.Άժ'Jl֘fi ,uW`#l(.)gh| ɹ ;MwӪq/ذ֎#)0 (2OL5sFqz(+ $?k) m?ݹ9Č"b~6aJo2`%iogaUv% B Y׿V%H\&X~d7xTr%E/O@y, "+OܙяN9 Uփd11T%'M J<>Eu3.Pu{\l#dUdܝY;r.scr({BNk Fs=5tnnUucN`=~3O3 "׉4ArGHP >2ThƷyV+͸3xg!XI/JImOwZ.?Yq1A77!xm6å<#Xi `-/52@R?o;ן' pmz9c0bj{e2+ae$fٷIQ&DpS!T90Љ9h[$vEoI2NB {hMv}&2gz13 e`L;!A8ts2#*8Nq7MĐM'Sɐ "llP: s_A@-8-(<БR NE@->Y:xIaGۂ+RhP;\/$%k-sa1#ReHU] ᚣ<婸:nj.C_yCs!OyCWUOkc˨XyE(si%Tag'JILwQ B;2HW'2๛{uJ0R)b({s5pœՀ4D 2zq |?`Ae_ny &d[~dꎻ8dPPcHl,cuϕ*|zH*hz?EmEd.؈Y';UPIY2˻r BgoGR곫Sbz~jp*1Kd2`ج%3{0vNʯK>s8 vXԪ![H "Kva4J.D֝ccM]sgq‹ӟUВ+j%x('9P;[CD\u8ظ#$N'/1$%Q_xXaEAh{,ϳԺRYN$#p1fioO)ӕH#`f~_t7-#3hpbg '15&-_AŕsmցV_)4|U&M4a)2X( U"+b k7D*ls#zhc,d1,W)eҗ:m@| ,AVLj#F3"id@ 6;eM{tdoBtw71?N<0\nc[fE /Qвa.YOze`kME|:H`*Vn$Y>6"4XYIf'(]0'sZ\h^N5A,zŗ/`8n=jC!!ر6N|<?{iý32"CirnC~v]V`1}ޓ%to"PK 'zf7 үklA[&PJbHb#EǸYuxme(H*d-m{WN'&j^z,OVU!A_֣'P 3R1A*u#{=`Lwϗx - u xCo|R@^avwV2H܏2"MMwӫK&T E7<M&̇՝eL/*嬋t8a?Xr2`[S9*:{RR(s͖ʴ6^73Aj9=Û)E8HGQ8IGZeQP-B# g2+_RCio.BI;&j%=SpQ ?,@$eԂ_Xh}oRb01fn#UbzH 赕'"U+?wsfR4fƳq! b̑ȋ2uJ_i oFPޭ=4m2{W&Ϝ%㮙 cٜ|ɒF"(ؽdbO} -`=vx#i q ӥlF"5uL2cWռ*mO8+yV~Q-P P@A?< 3pP=E8jj;'pIzU]ϻ\_e-H>\$rקCDS`EƎ6i*yp:6 =Paqf^`F:_ńBA5ݔu tF5@=,K`iF!"V m?pc>"0tP\+m.NSֱji6 #:lP3& X1CQԛˬC+w,lyxcmkUIA\N+Ͳ:[0$!bU܁Ic{+!婕(<'ڡ3e1 0%JeF~d/eLa { t(If{~At2GY8LPA5q䃇I-1٘3MV !a-ɀc`]ʶuʵ6Ǫ r5S+n}i`m6ΚN~F Hf/I` X2`FY#-^\?~ϥSD^c_@11\~ )\Up1gm3A$җm$e؎,.01DAѨڞT (5N/]Lx>5کIeu@&mxo4WǞ(#քqMR.Grj' I9hőh>p&)Ab6ǵ''7md9ɺ>^L',>4}o)*2kƭ[vCt qڶ-ۅW!cw<5G[ #kmX6ݥZ Q; Ť/1/XwPb8Zզqw6zg~^8`_ )(shH1*lB,K Xb (*y`/yMU*tA0D0e%=jd1* PNٖc X d^QƼZ*bƈ+lWpMj͍qg,y7<Uou;b*=2\*M+%n*Y\A![J hʣ6!Oti8+2Rf{ּ[x8U}UDnprȅGe25hM/Z It=%Lז@6iif y˵23g(X=HOEn`JVDn#w4rѰDFkЎD#{_-Շ"Қ1RKB KK!^Wz  ~=BOs=Cf|c!rgWEZ<;FRv8ߚ?3XTGFeqA][+GИ?t!==庬hJ%wxW3'T B-`io>YL|hwo oD#~81ǻUhs >*T '7d(`PIב4 z2KL"&i[؟ Uj;݌n㫰gNLM.^s;|hkSwnH-@C$No6Ta-h;' bwhY 2;1T#䗃7]$`|Ͼ v^ <^'O*\eRak8CSλ %&>ҭ҉2©c}4^"B; f֦f HK5l€>U|ʊQd? x`}kaQHqOzÒ_3V3q%f܎i89쓋`Ql63l(1_RrT}aI)b2OKT%OY(47گ~"{! @y\iBfYooN~&o3U)\C?IкcONQ čwxU3T? [,M-<9,A2 R# l:܋.|mIj6:j[Yo>+.8}<蝗ɶ5~3H ??*v= 柣5Ǚv)3CL֨ ! J`\;XޔCTzFK˾:sdQ4 dS&SBmU Q5O%v^XPt"{ZlZ-tQնڀ]+ OC[~vȺ/Ǥ0r TqML)iZBOaXCͣz7 D;ωj1dK}~+8=jpS:F\:{ix+"2We].yH) 75Cc&Y+TzVs؋*\Հ^K'*uf)l|8veZG'q ;O[adYryQiݓ@\:pڜ1Io$<{\C &G%B7;A,]OY!#pdKVƪvSほj؋S4}bX+58+$Wr-{`!Cĥ->}7s^cߏ4.cF"v8rqɊ]nȷ3&:5,Lq&}}?աb>5O.z~ioEj`)g 0]JzOF"U<=WwG\0YhJ#4}괢X=(CʎXxjWom5,/TT>~ ,6+[p(M  Բص8'ʩI0 ؽ3'Bq"Gⱊn.D1 ]&̉ȝ{}34HBa *`sQҫ\0^KESZ +~TDE@B>V#qeA;a)~ԊU$ZܙB08-CI$G}K$ZE;$ v\Ugِկ525Ҕ|xSUb\7^m4 " }TzHy 9SJB ET=?Dž`.UStK $6/ڤ FخXc]}2\ͣC(: KtrJڡ&0=)Z獬XMYd!x |Yc M{%eNNPS5kJO{AR{)j1].{΃S#nR\BŢS}M ۱lTCGA9}_b-Aҥ4s+  5ZVgN8Vc`t_}wxODBӈ3S9:oX-8Ry5A ʺ5Pk}uŔnOsٖQsGذ]RxdֹZfe%]]W1g;#NV(I.+Jx?"^/ ɶC3#ֹ61D$ J 5Cã}'̊r6 w9N@ue/v`|$4ԱQ$WdȿT8quG9oec!hےniL9ח'B&n)^q|/A\,3s5Z G kQN &L[R+vۼkP>q686a "CG3dْzWZy6SZfb0bnY_oFC]oYDh)BۄoTolItl}J#Jiu"'CpLv OO^r0a Ă?nL[7xPs -#5D_q4`gӤ$s\_f9g+ޟXLCfƖ7*krnhȇ4NٳϓOo48Ӭ-qdOxU%7FԺ: ߝ<-[p.nrI o蓂Y5rBxo"SVAXo|aK.Vq=dQR5Ӳpm=]RȆ{#"{_#iM`sQCD)>XUqH\,WeΪ)rfq lvfJ2FhR7.}5uЅh>M]WOVI*4!niޛ;T!x#OӈքEP/os _0GgK#CQG:TVZ\Rro;-HQ0Y|g](Em^)u2D4ulsiœRV@ }َAUyO)Kz"SbBW ]cI`Yw!뤎n=(g V\RK 'Zu4heRB6(:RacZm]B> ƔΪaCBpUQhqc|*_؛~{/(n̵";a sLTXř>%}[;ª.%xQ J*jl=ĨFTj6|ޠShtMܥrQUَ3ЏPօ% K?0'=d ,^o}ؔ@Lh6M@͖Α+j]FU1;Ւwۯ PHǪju#l,^&8ID=F$ڳ!!m3M1WT}yDwsW#7 pL4}% uYj~w=b߸k!EÂNjPQd|(3T%~eBO~x%֜04V|z?$UD_i1/~Eң&g׼;+9̡!,q=C2b"mseHigr@<Ūwd ,Į] ͦ#;h~|*çSkfр>s- :9ث?yC>(sI6E$=l*Z);[S\ٍ@[Yb-1@[˛K+ P-dv7yzfӯ"up8@r۲J}1ML})'Q)W|Y:H7v Ktg  ['C-辵 lwdK܏=~Z,o'Y$1%: qC"\!0i 4hu `"m gB\'~7=MKb ]Cб.~<&u faLVV2[ zH@0C2䋮Vp/j~xS_s`EYZxb3,Yʦt8 z&ȵIȞ) (-&0~)[_l)߱܅VȘr, YB.NUzB@Yv2(7.x nH Z]z4(TbRZ {es ;W˶znx3LX0 q|NxǭרHtr+ h%՗,ߴԯwep-d[/Aڴck&i/B$Sݿ%-G;/ ,%)h8yNcT߄n_ x̍l!d8ϊK}UK r=ؕYKR[8)v;[o& fZUkaaY O( bNQVNNu:^Ȍcڭ[)΄5&R;63!R+JJxq6dF4zf.Q~%7yQ cxﮘva衃$ЊhGxs-T:NQÞP:&z5P!9[8,ˍ#4zy@KDT(%abi'mgG'YvRGiS0H$BASpgrGCF"l'?ZI*%&d"(z!6eUL<'rO|I$ĎYql8w Y1-vi8hr1,75*íĮ;;Ji'RGX.XV k<ٔ'_+1!@KB/7>D il@5йFJdFZ> g-K T1H?m$x&DV 1NMI̛P*#SZy".i*k3f| X ީ[xHX赧'UMh-7i܎VIG N~B=qBSQB%) AVUaPu\̌ fLX'AclM܋ۘbv"4]!ܩFL_by uגD;& 1I N/NH- UU"{%t`Y݈o5}{3:-T} =-Qg-IRxKU~"bc}$*Yb%䢃3Gi4"u2ȼy@#Q4u7L-Pr wE3m1dBW=My_G8Ex;Ҁb꽷w 2M9| yoFC}l%dP4@^ `\\CKJИWc` S=%`BFZ[HS4z ,RT{So䪇i<1U)'^{uoJD.IV=7a'QK3o^J*UfN]am?zs+ørWPw3opwiSb \JIw30hE1 u[JЕ".lo{1";%pSkka'%ݾK:%ش{ t4\UU󭸦 g0hI^"$-wk-:߮[8tεEo40;iMTӜxCYf7X%nrSLK~PdRu~H^YUԪ7Z"5U%|EV?c*v>s`j.$pL;9GyM)f(ۻXA%"U񵙔hw㗖} =I8>LZ\tȴhtKPN6w,d>[rG]}ԟ_Ts8ؚ\/"1JxY4^;7=YKsCBgYU!x- !+aB=j4+HDwFZn8On˔L'ˢm,:< ZZH|írLdfklǧ1"2FV=8y>/0+uZ"m1h^ebtiCOPEfߚ#Aʹfյc9D Nv(O%}lOϊeMx A8){W,9?K9:[oՀ¤0]D b)scI (J PT\ҾBsž$WAKMf0a=B_FipvhzFBæY*O~]ЭARZ TóDlu=|ڨ#sE8x'tz|c Rڊ))𩠃)w'zI(`K!74f~Ah'w0Mؘ_,|-ɕ 1d"e+ D 놇o^$G MjR(~1m֐@.em?J U<10}[n;+=;JbW0!xpB?¹VF~Y5M6aGaHBrgRz?Ef0R7hNv:tW4 ΅EŗDV9A9ym [CZo?ZT|Γ=Kw]-̗WW8OiTN)B$2+9bg~(ac 0bbn_78u1aBaUˑ9=}? 3JG>\ ԅ'w)apߧB] W듑[N6@dC{ر\Y^bwPC3IQb~x'hVO+1, Wa_X+^ZvC-!ˠA_9BֿN|_y@DI9⇽SjgVO RoZ*㲻yj]K Ч>~WC`C)j{-ZҪ['$AU-ebgrK\WS\_ K{lЀ϶ qM"42*U[A|7o}.Ӈ"367NݻyH'\_8Mo<hSEMiJJk F!TɐJv?f`x*b#jRY5Jk c7pNqK|fīJGzx;h_)Gvh0WxJ&ϺɽKW3;`mo~϶?qKΟ۱ :ω/WT\QvEAeqpKBVIPn)l L,tT g>5fƾ\0m&%L: ?6##s$oq*9yR>.z"q[lG-*4?QQXNı3>^ޗ 3ei/t.XRpBkVP/L]Sk̛\w2l6 :Zm7KR 6wյm\@]yx+}01)aPU键&SA%~}M=s<,CbiE /`8y` ,AӜh).rUjZ_f06"`槂~Ϡ Sھ+< ^O60][t/0:L7 &Z@Q˸K\XatZM~5K;.DSj hp,'$Cg QQ @+(_bRj _墡00W& (8lzQc0&ʀ\aiL  5X j+\)&ǬV+֊ 9 w]m4ޔ8pWǼU"lP͔Ųԉ.G5R0!ߞD?M<̼' &9AO.Yy Jdtt])% LJG X'EGjÆ#AAԬ_ƵvjkF?ߏӺr+՚@˳sf(րP<J[\F2 =6I8.8N%7vA5m!+oYqó8'y/JULУ^ F! Mzhw.Ө:].F#[V(1ZnA3ohdhQ|=/UIWK*͂v_8y)|>aēۛ}5ܝg᳜yE 4+x @{; |6'yW3S4 bی٘3nAo 0r}e8o 㸳C V_f#u&05g/KJZQEO OZLpmjH2s%*[onR$DIJW{bq1:d4.zfe;ekkl,urcLLEZ ՠ4{^К3B20szW"91ZJEBtYͿ4̨"iPJ!gXP*).!N]L+. rѝ6Tj_=^c֎%kji  q4e^ec$fb$OD"2 l:qo:JH\[#XPR؄x3fPalQi3ETxwkwL PyΤC29.r-s rsE\vdԄ"l_$ %ݎgb0r6[nJq*ė@&3F\ 1(ǞXֲęIۖ.:ƀ0^#A :@p9 .R-eh 傡`[#Ʌ&?&'6@Z> 0{_@ mo׆A7PbQ ::K,Y /a8U`+ 3[qK!-Z1r?ƿ‘H ܇#6 "ߵ7YW3g9PְC-fȮ7 mH\?BْDܤhGPT3` ?(uB/5=CK0|s6'9%ѓ4h=k) ]s?8>XŐNfy~!>1/^HyV֮..|znrk0ԆƉski37<^ve6 'h*rW5P (ra^%LV b2wuqVֻ*_#⡓Asmc)gGwH:Be}[mϧS/{= ߭lU3q4,œ{Pl}vzB_S!妝`\^HJkI Y D!b  p>K5$e8ۜ NZm }NQ8_R.Obf&}>t|>缽0ζ+UT@u_⺶9␽q2oMdF\s 1~]_qU|!DRfcD R#9X[_j lx!(V$a5 U=?V" XY{SvYVDYgfu]eؽ=؂UDRWNL:fU^!V@[˅n5&cM(A"r} 52>V0u h諂ٛ0yVậ'A[f:p I-Wu̠CćWd2UVs/`GoR9 ,yCEh. 1:nHP,ۿI2)^,U M |$_w8HEJ@ۙ͘*y?WSdaR4iy"HU#&QA!EV o Y|w>Jx*6QE8\0:QEg#ϔ3X&1+o߼FV {(WiYb],h%'!&˘u]fCXG1DEDxmgo" siR,w\˰dPmנ58u}Qeͫs-nnP!*h%w?OJE}#พ/2b!u*6b3=vPC&u߰AڳC1~ьFb`4aE'捌F$:ߚ+2UbHX;&w=v-j r)Qp h:bs$u*d{Pz>co4!wFADTCqԒ7f #m:VȂs"suU_w*GCpS]ۇnN\CQϘ q^OnGUFBe<Ɂ̮X J Y|^)8{ϗ! +BSQ:((8fW~rѾf$̭t'*rޛQZSv*=!MLKDw#9mqƙzqY&*B pA'0NfGqV}AQ+hGZ2 c Wf6cT"b[@m ĉRt ڞזsEZ4S>WI&$DCe;y :=3a8 !qʲ, P޽X|U2?61x3 e>͞8߱v_uЬCe~؁oC*ؤE2wInI:u: d)0kUPlE&.1L ] wk͊r~ YWuF +c%0l(d"1fLIߨsy4ƙƬ8wàoV #52ոvN}[n$l^#&U4%yKXbZms-W?>co LWrMC Crm1tFI`ހEj\JE7&崊p͟2?#S60Iʢ؏S UQwAS3 w?EwO~[;&LrQ ;q|ϼH[3GN`LX5i<*Xhd~'x}dV?~gY,ĽU]>zU`A(UI-sĚudmfD AZr1̘ dƲN߷oۼ~mL2oj-C¿ ?՞ ,|s-iTkS䐬Syd} A}1Z<"onji tp~sEgx%xLGnJNnZׯXah'VxSc3+չv{w~| @uAѺfW rzVzWgab j٩Q& D1kTWGh#H :@ TSE X Vs3vSq_4a `Gkv rG5Eu%sQ] mĬ̸lO8lw1Ybɯ0%6Δ`&<7՜|_M-q~wTx{k-0׼&O/3$}_0( P@i=J`95h;yO믾HO>Êΰû*%F=^uҰO|$9Y!;d+Vfx+ nt~eeXO-V$D<;ϒ2-gp>dXs]#CCaH!9(0u~rv(x.V[FxW!׊J"d"ui1 Vmc蓧x|, DykTOS JҘlD-~a&9mNy&Bm4Eu948΃+ѱCس4| ։M!WiϘ_`raF!4טE n(d/m Qt-\4͝C j k%B!>9IhaCg1ɒZO-+N(innCIP\`8 {?{s/]֊~ˇ$Y$.XYģ( 5Mz ImN&֦DR%[(ubҰIL#͋Wg!Co> !ϸ U$m؄vT UcQ[VAn,-7h?A9#$B'n9WG_K.@;Hv^Z;P!.#zt] s$K(\_[5x (J_c(;u@{#ڌb::Au!Y.^$]X7lBvqƳhqF1pklňf IdS2vfa/C Ea\.$ygE'IUKo/|э*;w ~jy`zC. ^Z1w>$ 6;{:5fفjmvx,t{.?SDm4 u| FTZIP,\*Rɦ2t{T2$&0Ʒ`KBM@"9rf2 i%pRxNt~l0kE[{dEx$6{` jK]Aj,YeU?\Ggqnd"Dy` n|N1kOA_3bPv/UpbrX;flq:a{Za-@ezf#x.zL]BFӫ,j&zv#pi+zĠ~y~ vc=hd)ٝSSrXmlBT\}L1 G`V`5gO(% Zb.{c%Q*MCXwO`Gozr/ ~)8BcH8sM2oR#=%>!Gh#/lp]waiaC (Ӡ=,0o‘?Mh{*8Zp/ vɨ{d=.S^mMPty4KjXܮr \N<ɳ sa1᯾rTXpBU bt5=M6B0P&  Q6b{)B!3׹-ŕ7ןt 53}y.FܻE MS"b8aZmD_Ə(\ڝInU؉iCREkE\boCܛeFWj&N4J.*FYN [n'.38gi Ju_xwL!Eh5tr; ;PR^,xWۤs;q:<4}<$_6g(&o.ܾ0҈` YaJw;Xc,M>bBi%\0H|EQ 4^CT]3}ޢBƶ͔8Q<2)ڠߨQwr-13E:i# W0hS{i;{fhTT|l>W63ю-x)-ˊEEޫlfA RQXn"4{KYӒYL3DKucQA:FRޟsm[l, Q<EtǠ)1*iOH0-:r )W8*.'."2HIe*Xmcʎu57-w ٹhkbMi9#Ib6$9:n :Fb,&ta@ay=`=o&SٽiV@` 'n$L7Rq/+WǛ!SXzeN25k IZ(JK_W^,5:mjK*=)L&K6^?05Ia8|a< ̕U#d`-սν|aWB!k4I .Ja'{,hcan<??NC{rz^ݧCTR c,D8u6cD: 'F"T3`:KK↼ؙ O;;Lq|HĬ]T6VOZ:b-ș ˸q.pZ2~r3B3J=$hJe:@p,tbxZ0of h;089{~:zrlìYv4+)V7]SR8ʠ FPՐ}!sN̸o@4cp_Xg}ZSCբϤB= ]޷߅up|{)TJ̓u']hC:tYOkW0@ShGc $c g7v>ΤF+#\h".ռSe>ɭt35Lf=Z=(֥WG{p+]GI%pY|f/*C>(q6X)2H؄)B(Ԕ8Ad[LV.KP/d{hlYe8kx]ZVC1:Q]Itm/\MG! GRpv"]fH v5յ:6"Gk))댑sb*Ƹ-ЩFtRI 2o d!>_nƭ4T`+;ƅ~*>= :dtU5|7UWmns^TlZTfm, AmVgJr.nuZsjDgҒ4-m_^Fq1e]6@͋+zBRb4}B Wmmm=lIr-á(䁢$0;Y1WW֨fy2?eb4 (/+Yr,p(I5j7d8*}7d82Y!X17i%5&,ސ I֊}񰏚nʽ6 ,DI)G05ZvvkjzNu5o YK!Ы LJ5t&LWɚ̝_]gòڣ~-i3"Յ*,)wEĶkVe2A}ٔ/W-1]YbJL.qCT?ߣLT0lk&1xs:4 %b VI|IJ`wcP1ԍ (P;},łzr6V^)]H*BױYGT{~4:VРwkr>S&ϲd@/&`"tqr@TI8LwT=:T!,^&:=}NL5v:$ޜsyw[d0o玷;r19wbfZ7au5?X=DMrSh_}M Gk%N>hU""H!XeRmRְm%8콟 @ y J3wG,)r5 ֙@"C#\=$.>': i~輳 =eZE<Ԋx0 l~9NqLcne>Mz"DF# VٯG˹%1?L?@El+_`ˌ e7p/E@)Mpi< mTDS"Sy7r^e=[| u3eEr|s/-#]yC[YK]Ǧ%`ExXcxg.S USIWlЭn5uH+f`6 O~muU +\Œ݋ٔ:h3%\V`#>C, um0Lt 8Xvm>qY͋[ς jm A'A2RI5k㪰*] X0q)Lb7:}"2DŽhz >vUpS 0;RP$n"Ɖc\rre$D!P{W2AeJ^}>`b߳b#5gzl a =sa3oeg F=TދfYd|j"B%%@X9cn,Y@MN;Ч^<7F3ips̹SĚb ]J2mP*p'ښb~16X28-2,%'&D=Sq"zU Oby^\V|s YTӨG#9 I)3hQG$Wt.y! rP ةCFP fX(z(b~Cvͱv@PaVǻCTrA ,z$/;hG)Br!^X wm{(vbMV~n5nگV@6B@T.#ȱ,[qȜLs oL!E Zcm})/X9?NMτe@{.^ DN&OznUv?r~!nqEtfd,^pJ0lv0*yڐ7|hPֈ4C&۶Bь%efIKG x,2It5C*%gG|*UuH.'U<3]ir@4Hmxs_t\yt0r {Ɓq4WlБwaQe*4!A8"k_a;q0"nsPS ĪwRGjܖ(9tG-j>{ CK$bH? R22T{;ԑB&i~,,vphXQ?6]';iZhaaN d͖\"AA`ReV2ܢgڑ H3 x$!WR<"2y =\[~GMKI}*ژ) pT -x3X^W*C&+ sJ#S+bTp :ÛJaM(`UV?뎭2xȽ?%}:畋gm!cCFI @@#J*Ӷ5.b?N%DUmŵ-B{񁳴eh.7&- eH)53[5E߭;jsQ^85GI=j;Pk.@Yg@:[_rrFphoLh<ȷd/cW<{-$VASmcy<>a4p$W".טΞR A. ވ`;z.zZ;?K@6aX\MyQ>%F+@ާ:ufYGka!:v|2SH*$\N̹?߄7W!X"ˁ%}o_n u="EMOe2x& [5[uկ&@2۽*a?`k]J (w})lq?=[ @3'#M Nh,SfE QڞZNțVa|&*RCl)ZW"emPf' Bx]Xޑu,a%% M&PONoˈp28O9RX<(Yuł}Gel\ŭzdFEY)/l0͘t%a[=b30#A:~6߃2,-zgs`;Gl ̫ *՚ Z[:/aF401F\ EJ=e~r({{j(K*y"qA[Jcsxł UK,ammYl~`ggv 0$mqZ8uZjv;Fz" F,B2,jn&AgZ#%AW'Ёh~Oxauכ\/-gdE[S14;vѬqo9onJ?dXks$] 7^ȶ&IΪف̪8Ivmo9f+fϰw .L=/חasp])-o?VK*st7S7Ά-ӶzG/vŏV,D DhS ¿!~=Q&k3oE:X*zl:TxuKzCmS&qhH*8u ދhm$ fe/ }b#o2'kW6tJ\WF}qwb[&S϶%;pᙌ4%?z}Ry$pdo'z5QP*"蠾Dk;=6ciA'$,NvަHn͇ʢx+/Aփ-[S.%J"KGr& '䜮a|4C7 |mw` #gdr% 3.Uֿ–OLrTaG9P;h(p^G2b)7u+W),MH7)mF_>۠Xg˿X\V>pF8h ꃔ{м`baBMUa!nDh'^{G+3^U?ə![l%PbQN/lh~dLPu{=c"nEOA^ඍἇ')X,oM rBl郿pߦ(W@TlvyvX͟v:%PAz4O<2wѵ-ԇ7G ttpE)^M<"&8wLo;R^CiW}ek8/F\F"XI]D.-O8⎒^? 2MDfv Է+μɴ(n(.]h:"x8nn/)z2FybHftCܳܧ ͈sA2@ IԴu M'a<}$qز=r^ %buBEs@hxdTd}!уMޜf7WUO2fƬ:?dcU k5H-.R >"<ۼ4 } ; GU›;l)swK*T+S>(Gq9Ca`;0EtÚ ezs$TiPB;˸#{wTlAs&vހ0Cn鮠ۀz/J)8 &__Ni(+U AH2J^Uʥ(WVOj?Yr0 K ݟ2I4%iX4J@kot74d# R0SALK./G"QMR5;F`u]ɱwm<+jٰG{+sUɾ }Rmf-Q֙ړ`WFN:]*;2X hhZO)Zn„pp *# ?D&(HZvd̩b`MѸ Ȍ3Cw ew,gLVp>U]>pR-}vDg H B>N"5oGnP6]@Tgˡ"$mJz΂S0QXcD#y)Q߳q06]pO6b8JLR D3i~h#!h>q˚B즈<2i䨚LРf~x[Mh +bܫJI=R|ُŘUl%rL" gؑIk gށx ЃO1$ErVE˃P(Ka7'5'TPds;UBDؖoȐ#ӈ{$U:i`5R52Eb?.|R%qr i1AXjG lGv[FUVٷV޺*tV7C8+QD7ngQAEo2E#YsyɾZc8HwǽC4W>"i+}y',+.Nw豺8=b1F?VoD5ȭa.\qd"w'.k܁6Vd#֒t6^ᚵ&K(8^ln+ p0i`"fUH&d~_%h"tq- l{LE@ӇK/C 4r"BAx =$5QmvDҴMN, >$`w'8_1&+f f̖5fip!R15|_m(e;cptvgPW37vUഖu=۩|"H-' 1]9(_LȚ/OJ [j8^4ep m@tdE{LLTjql VTD{^Uר6[XzR l05/Ufq8uȑQ$ctÝQ٪LK-~0T1h;)QYN;A5BTa-%oHŗ]kT*r~Jl(GmES(\ q,V)>*UOe86σ=^~L ՐWlQiu{*URA-eCD42,n(d f3??lOx$'_Y$A}R?ƆsO,4+SKVD6v^LjceL˄)g<[>a?wuDaJ@f6 JۀNAvUvm#tVjDO%5&{"},sLM5 o3GtE^탄<[֛&ш pvƙnʟe\f>St`! Yz"F})6Gu䱚ou|O}gƯ1}5ꐲS#Y8?*/;cpDH1&Hq[ Ԥt`.VQ b:td7#m XeaxLeTQm$W7f&UUЛ vpս ). A }`.0őDv+mW'7q ]r躟86t0n˞F,P/?0UoW7'moKp:4( 4y뢅p #B-re02%r=LKVO\p{w)XX'@SStwHbs R&_:b' Ey":dV^ IeY{ZGi!G I8n'^wD'rt{T"`,1+#*]X[Wg8!;SfPbyz+S-Rx yMY͕ᙻA]iYʗy-ța2PzgKfc뚜mMGZzEE9 3jPUJQzr5ʔCpH?Ypӈ%HZ 7_lBc-X1- tbCeCKw% ɂc věYH˷Zx~-@QHV7J$%eM؝v<7\~qM-|RZJk˰XqL9ɳ3TpN^n;fi_z^laFv֦M!\;4iYUղkA뫍MDq&K4L*&W !9 zҡY:l|m$%5e_-+L&('t3mi+Gـ&1[W/Ӷ>⌞^ӥeJPuNí$t9MKĝ 03 8XF=8ND"*KlD""qӏ(`'16@/Z&2n6 נ~`G/F*ꥥX}cw}N!CM53@ц~\EfmOt&!o.9xi4RqMxrK HOal+(SJCtr ; DmcW9Ǵ;:NDZz{8Y_m6MzUp(*QS׮v`&B T̏ﺾb-Uwp՛A}KT.*5Q> Ct0Z~tzwf -LQ*1_;rfέ`"ur9^Ԍ1ߡ`e9ٹ&XNe L(5|ZpykMRzARĬLHVN ]9S{ 3_.]48hV؝7_KMbC\Gr3VƦ]o=U%r)Z{Npս~aI6دUs40WEKO{r`(j6Sn|:̶iȅ(.6E~#ƨڌ J{No&lO|h4ި@ON_]e|PFZ"XoD]E$w3M{kÃ?E!(O/Sקld6@ iHӼ1>Q쫹5D"5<Lh4 (WG ?Y.CjW wSαqJi6 wh)?,PդZor"x҄<)M+B$_uue)ߊi,ҲV쭟m<{ϕTm `Xrb"ۜp+ct rꡖ`Qp p,E٩uΘ:N,y땺R?OL/ 0޷rʟ#rٍCAHC"[:[I -b2t,28LJO6[*pRtWޞQ(1쀸!o|An;?(F_aN-eG)y^ZQ&zd' :儎Vd9Rob<1 1| ! R:CͧJmeR'A}4ח!he}}l팜>w!kwDL_ cZP <]cj09bo~lA, ySMxV2_ʖYwѨB1&y-%a1?$~Qi{KC PW0D{# ֜)e #B*&| ̃?ŔHVCk*E>dv+ y"w'FOO .8ħJm^|UT'MI=.5j \ᜢKPyx?L> "$|1mN&zzrDQ۽A-Bӌ3; Rgֳw6fXG %d%!EP`kv.ɔo>A0,}}(R߼Hs5bar(ԡe X|V zuhqeYFDE?I!пQZqcHPBAsv@>{E4BYwCwJ+0f3L}{j@KED̍^3loMjea O|@5i͵_l^!́h.3!"V!|&oN:ꌜ~(;2]Lhm75DBrd­xU}8JȔs+_Vlv^Xbzi+y0;j2yO -./Vް$ !kaJZ_Eb>igTIw6AG!/AUp +<A޶[bW#~^:tD +JŒpʔty4d[j s_: ƭr=q-)nXzs}Ǐ.[lΓ3( -,-_o5D$Enÿٙ+촍1 !?D[ZN+8PLY&a)Fn0j'[!Q l4si:w$6w\@C̑SB;dׅ8pZ-](;Fh0XZ5s,d]@@ZL?ݓ])Nbv2)>|cY ݀" xuee$= -ιJР \?nFbļM]&[+kKfǍR[kDSC!ͬ1fl&Y0Өə6f0o%j/'~-Q=e:qfB{ȠW[Koظ>7b\=#e`f#ϋKM.g<إ**zf/%1]VxN/8AK"JJRC52Eo 6~mXh4/zpm3;"w:ג|(ˣ~;,gFz740Co@- GUSpqzɱE}k:.ql4)FQaǹZK-A =nuسv*)W`x_G\zOSRW/nb _Dnqp$$|'>"s X!Fx{W(Ϫr<ޯom(W&bJTurNGb^MƔ\utL+] ):X+Hڜ2*t 3HIvw-B0tL"(2 £ WW2eP;-@uP@& 6 h+A@t7d(Zk%1Nvi*pKߒWR dywX`5i*:dy\UE$AK e$\~"ƙc+6~MQBx3A8ɓG?sm]ζl{X^(#Jj6e۝yG)i st q3\%^ʍķWpUOa<h;V<2 u구ZxҢo ,T=!UZ yRGҼdG_ ZٕвOLGkgiC}iL[g(k['ylDayo KFY /6$R$MI`iq(mUOձS֛̼)lϬ c>L6>ʿE?C^cWJmZºoRe0gX%2mly䵢y%Xr8u\|Dh0ajw7IB*Bux1o=]rokZ3Ϡ"D,2Uz4VNmYv%y3 G;B %!*f~ C/4Cd亀]hW#mj!l}~}0θ"o'xk8kAܛߟuu79Jp>xҺ}n}ggNK tZb+ԆI9=L(vB!-]C{ [A\<j,q2w{d7 N%BlVF.|A&^.2G|n˱-̒鼶mٔ8/o=X7iHT4H`"/ >z a0صI|`<@*_$B6sƧwsiD|ةFP:h R"ke"^aEEs_hCB~ڲ-[!i ɏ7F|f3j BD?T;"W2o jÈL`DPaf,٩n\Fہ(KU۷]M|?YNOS >pt/RJs\1JlQnWʧ `0\=N/˰[ $Tl?.GBEAV[>^p}*Xr=*}h8Cugkc²դh\!vhׅJ&9~1@7b1E) *ɳDN_ BuRW(dTo3\DÃ4y柣ߚ:\zNQTBMzy T-QQku"%EzЉov> g$k?EP6M PK4'Keyi[!uؠar30c=11#s嘒x{T kbM\R7:|zNd}:QqmƷYpyIG3|)"7ߗ/E̋@# )MKLTg8Y-O>2oWӌ)5Fw"FRg{)X!՚j껥{0Ǡwǡb E?Zu3%brɟf˳MތeX"{:醐a{./rݕu(H m%}0jy}jHU (w{tVifHJ>*Β=V3j!B2'QWۧK M;ю ;7qʈ;[_r= 0~޻w^61C_QĝP:u ^MC=8 8wD̮I|0+Őtp[lİKb8cI#zڻyO*ttOE?2g{ ֭a\S.N|"`%Tx& 2č& yTRӂ@ɏ5ӿcZs2\tB-QhٲDNvv5vy4F}Ί%;cPpȺDn/9 .Wu[1K"RNgYۆ .ٓ[>/?]~p2|gnQwc{,0~LrE(ǭl{Ƀ{VlWA!t Hcx\flWNJΩf˶%Ѡ,۳Ƌ3 # aanWĿT(˩"g۰xhzd- ZFy2GZO~]r9sNBiwlEJ8Be3vGc+b|qMFC]rGFX݅^ #+:Űi X?{0~n@Zpřk#%$Lҡ6NBdɾ&mQ@X1ޗ>!;t!56/}o֔XVܕJZ-~ui- B.謵_>"YJMzmv\0r RMMt<>IƇf1y?ĪނCuU\Gv~g`_^T;xD޹_ ~9ִQ+!`KRZ{.1:s dڇ<=v:`~ԞՙߜiI'/dր k֠rTb2\3pV,H+8׾r /)'3By:?2Mè6_+&Kͩ:խO>)Mzj>$-A⏧{[֬ zQhbx+Q;EAEKD!Eq wd g[ғѥ3ILX#ZtBck4rڹ(xUUv%R8,Zy{mO1 [gQk;YdG!.'I 1dXgk'>+P,IU`}U/ni^a.GOFuH_z@+¯t87W/u$zG>h| ?)D,p]H.ĝ%g o߲5+_0pE~ǟ+3=LbԵxlv1[ ]Y;]'Fv[\/=z-lt@dDÛLG@~* ޴#q׷?ꔆ ŋ|pZGjcMʊ[H& #Z®haB>~R:ȿ(cEZҀ٥$OJTSť2M=9>$81}]n~W}g'k$se 2CqKf/S4(=BbRn@9#v5EҨF"?Vp]rQmE^ 4\*5a5@$lIkt55n٨lp W4^+DtHԍ\/m+C 6Q 4pC B}ep a=W$ KXJM}9 QZ)-0TY.f_`O$\4WG"g~$QF5)H6}equ]Ic۩(˷BsZKf[F@xUA|ׇj9fu3l{|dFOvBqDZ˗JAPZJUCU yG0CC)NgG>Fl/>s IGo+"sX_~XK]T#t&՝='o?Z`\ ]G)h L`rmU)`&7.IL CgiF3㔜fq<)J٭AOo ߤݶ]y]5 !֌dXaӆ< ?#joܪIa\.aگ-vvVK``%隘f/{඼lLi @2o,јR4K°Mr&O % )raR+*T5!0tNE$nH9"'I벲BEd, V1nC<@FDmi ե-N<iL3ƈw. XDK(sҢ.s d@O/̎ ::$63x d SFYb9M,k4B-$b3Z\/Ż3:-GupT*As7Eng ]uA轓ld20!JyU|OqAo J)Ob뚏XPiXaJW^ x&4M B8 )7i@XV Np)0šC|:{1Qt>ux%ro>.Կ8vDjGuI1lxՌr O0S2IQU0e/L#G-Njo]Wgg0ګДH^Ea~kTc=[xk3}7Ʈ}b|=Ҧ,YuJP맕f0wD~[X91_ޏG/OS `!MInq|ƾ9SU}$Ag,*FnHvwR%,qV6i3{ZN^F%4tjvu:Ĭ+{.ݖXⶓ?|.fQ8CMp|hmccV}"]Yc|%N?7v`F@ʰ`Ttʁ%͘N)|-Wޘk3A#q]؞@ӂ= !q6SAgc.6|_ސ |1bމT"zׄm= oW&dոaf8Y`"x29r&sc VprؕFI n:9>IYW旗쒵Rҟ[O0ndl6O(zjlˀK#0VcQXa+f닞Pg妰ݗM`Sd޵S]-*>s> U'CzUk:HcFq/U)D-I9:&?"n!%m mtn]\ &g Ogt*RuZyinZl[[:;hw׎":q7ޓTi]nF7 'Rdq[p _4SUt=xwQ׼bP& AȬ˰ uYG7:-AAQZ /n WϿ^vUҴkng}fpKANʭ"aF= L%\@.qQ{ KsKX {h˂d2A?!&,Jv * E4eϼb6RH\ǽܒNznB{ODcˢ~U\_= )Eݏ9~^:O=򳥌tBZ#|\1B;ϯ$qqld+=*m c~K&y~v!Y$;.[B%bJWx&v?8hnQe{Hة_dAE dPL{i%$+=:;:*  OsΈKR-AAC` ن=).[4Ig)Eچ,:); 5U1D ͳ7=sk%ұ9%%}FK(>vG7P)غ˯݆1LeDƗ)۱E43z-Ӻ,k"Ul FC hL{8ГPO5 Lx# j Y_;Vo݋q V,+mҿՖ}hIN},hknهQ>ns,׋{'eOrI(ܲhqiLcEk.Ԁ~3u)\?Dz@Zlg:PIHna-!ed8hwя›EͮA/̵ě1e^J6dgQe|ɳ ͽ1UBrj*FA"J2DUC,V(t A|EOz( [+Yb3Yc1*ԥErQ) ۞ʡvC~bS' 1uR^NsǐE+,:7QocO};0-8*vMWXŁX_m3o'Na䔔*Ƣۭ>wJz%G٤pD>zޒ9 P8;A B}rO?'#Y$C f}~Kll'4|uLGJqh3>z"q5v;H_$qO@y~ÞQ~ slg.;æy0x9Y#ɓIl6hFga u9_yU-PL+%wkױ s?H#X\/.;%g ;Bv_̪A SFPnP'`hWb@`ӯͣG:RiVEC-nP)Hk:TXr% ,qbGp~kSw rko_&I~ ^ bXuÏ9gBS[hѾ>37hk@#\¾ [Y㗱A1[8R kqVǕu_'Oӳ[P]0m4RGecNh4 EU.k y} IoYQbf :: ^A>Th{j 4 :͈b@a}uLJ}|4݁ P/ m] 5~F֎$ _1\m:6|䆩pKgҒNf,ݺtځIgPj@CŮ 6C\Fωܖig 3's i.*LP U^Lj[9̧QI8vFH#j< \hDyx&-OeVz@Ed?O^]'Y:m?By'CAdKOb;Ak\pT87Nb)>˂h`䨰rb!#C"LYJQT)Iu ;/草B='5xw1&kQ`lrr\h9qPS%freZX%@Wo*5p-AY\z-$u jcM R3$q報o畸v^n͙G-\H"4 87@a.=rq99ƫReW ٛlhD:)e?k\|Oxf]NWcp;' E , ּgZ!{W&=r ]ö Y{4db̦Pb?;T v{yRTTſ2LG5b{D2Sͷ:ؗ\+ `. s#FDea(׈u:tL9}_%C'˓(#\ _5/xJ24)aF +n q&T6zz LcZQ8  8JU U3EAB?[;L݅DM}ɛsWTZGx-'Ր2&vcUma5F ҶO>`qtZ&&~i^6ߦ LK.iYDR/Ņ+♱ SŊRL`ͷ|q `i/Fq>$F_ A4Uw4Hڜr35#QmN}6 srߓ}fpֶӁ|Fn߶HYT9XRj.7>AxRnґ' J 65]/=$;pMK-MiS omf u:Xd,U6>UyW…l'aVnLQKA+OlUM<Ja.G;O7Gԯ5 |C43MU +4`f^_)x51r7R;s*˫x =%:YIYP8jyf3ζ)O6YqCp GXL -|b6tqm@݂1^U.HyфXv\i~}0 OQ([CU &zʉu|%9j\> ܬvsR>!,#$'N_}.% er~ o&V(z,2p|\޿ rP.6Rc,,1NV7 㴁/G }?:vPLy*̎KL"u_Hrm0 K SKmӔ50?,jg$vJy l%nd4qsR5-"d}줗H..+'C[|V;̈5B1zBoi?k th^rA~ى?o~b©5ęwY7 ~+%vk&Q=iVtt7!'\%FкFϩHDNQa sּJjD|0Dq~"뾉ƸS (Y]Iɸ7ب^i7T,UO^byX|zlgY['*5b_ԼN,;n6Z?$˗-{33c?RƁ(N'j3&t> -_! ӌ]n ccgT y+ }r" j+Sİ. ^ˆDv7hՂc>S@HCu_9P"&}GldN 0hy~6H}HH9Dފ6T@ay59"Qubvk5W)Ԧ(VD- &]im7݀lh'ϥS+WG%G wǵF_ S7/rk-Zx:E'n!&='4rq@` |xmpqVe.2R'LZM)Z_̋T !S6Nk|!My=r S)q,5l9P75YZm#q7|.x^Ր^yrȀe3}cѤwƝ \^)zcm蕢1gg#ؙ%e(8fw6G*Z-;6)`{8}-K1yj| ư<ֱгdv cm5wG;})wP_|YxȔ J4A_@jZN*a{/2%=.F1%VQpU+QĘ^OlTЂ.S"ZjrܬQ^ !9xk[ؕ2pAb4 91(<=|4QKB#숔i舽dD2nxTrob %AW>Qg/ǀx/ *d6vbB{!ͤjT1x=4)6Vik u ħ&L#8i'Bh@ A56 '*nf TNo0ݦ^asyēWed[$zQ'\q\8A@MHl&+A<6qPdnZYGX%atԞ1(zAel\OFk"H*W|5BL=N1ȆB9c 8u!%gyӒ_87ҺOVخKV4kǔGӴ8Ďp٦qO_ 9eȤBUl/'MǕ fyE5,+T./_) h^Qd)ٮ<'5n]P' Y]'j וaZ4gG>RoF;Xc|44N);8^P[g<slT4R卡XW|ٞe` 4=)w^CWzע&ܑ?n#ͪ0Je%qcf9o3hEXOGl ^! t]Լ ?2ewSUV!epw{fH-G|- *7N3>lg-MZr:Oba#HՅ7%2U6y F"g M>vt8̡.ƍHSKKc#R 2<nlgQ.=A5W5'Z2Pcq L6]:cn;&ndI08Jl :Fb f}Ol>kLd0_y< Xւע:)7|Zuj܇1}Eʌ WlT'`C$g|]hnREWbNU =1*Ƃ@!x~/9̛AHa7H -disdp"U<9UdWrsC)\F\Ά&Yl1yϓpk{ete5Y5&Sx: Ҟ ir>Pl3{ x3+Xպ Y3l?&Hdڃ8p'{g|G:"NWՉnA_uZd>:O=%Ct Z :U\R=>mExo/'s7%fEB6?4q3r]w7RWf}d)oZ:jokȯ:(9_OM 29@z_ݾT[3zYTſ48$rW2Hijk+{~VvJp&.kx`p\L3 h 1>+w-=rP\1A$вsuc Ó=^i:́r}dvZOҌ#i_@3 1(/nȢQN,iOqv5@L|'|'4IWS[M*9=/.?$^[Îf]v"?TȜGY`ڨq`j!tatrˆ . ʂ<@ vpsjo%ə:|mR+(@ڕ'1v@D"f6_ y:a·Wo*PDjM,A* Cs 옿U+Q)Tr[sġC-]_(_ǵ! fb|Wz*G c3lzg`2U4#L5| h * E!(ZL S1ObD7YM7@_8vsdoex<'o3"O>Gsf_2N5D]a)O|OZ+ `T{聥Mn?H^?т)qY48.Qw8ggv:*$kh65z&10giVpΤAL!АX|ZjLL Ҧ!?xWOG@O+<*ZG+Ieڕ`؊ >0mk:ڶ0z:?:3cY:k>75 @VQrUGjqKp \tok/\"RFu ]F^( ku {9;@f MY+kX~{ A_j+;x.U o%ts MTېbPwim^`հf m !4"T=ל@|w?Z bQIZ,d Pw O.jl~ M3Uϫ rM7&G|jEe R ^ &G:G`m'U sJpd͠˔zg]ئrV -iW{ƓX7lnS~ndewQbӦ$|H f]8s;+?%Db& `Fg˞RQW4g]H rL_uNHw*|pr$\lm]M""Əc1EbJ˕0~I㿤 b(x)<$.- S$89\N_Mh"pjGv'4rWl:IDɧxXg yq>A#t}޾ijKFRD_hNJᅭy,JTd ;#RokB(|*a{Ct+~ٱޜlק8ﳡ?o lQв'iS8a M-pWtAa]p<%@+QKxT`UWicX/&\6BV5 xo[Z%S ƐS+(;7`6q%Bt(ZH:l/% 3e?fzWbǔg \׍x!Aj{0d.JKS>k2ՙ١N ?F*cZqMx\ova0{bV,_)LJ)(!I%g6 oem̃OvKMi̶?>d'$rD"~Dh1`5ThMa2S;ήUY҅.̌8˵7ΎJS*xIoO2O|\`O 5e<<;zb3qⓥ*VH>М/Jn̈ 65]r0 t~vH7rdM2hBS*}kM}PxH8(2<Ո:d~ZaJoNOۛiwBq7o<+VT a+{⚄Y޼4C~P5Okg〉xp席I2E6i Erth)r@~lӎ eΠy%ÆLwYKCeE]Dx[3,:1^qN~`N$xGnP4pU qփ8'-eCc&*c+@I+fyfx7NfTJǝqs6 f"-qMHSKB|3uA7:K[١XEM{Nzc۲B"zJ|7W$p|<}G=a0$z'^"9 ؊?_Zayd#sJi̞qId S$k؁6,iVȩi ya`<5{*E~cKˋ93qLͯ"!>OA@) L0{߹zE! :PY,svGjeHZr/~6ȹ99}M޾V(}H8}=YD, 7˪Mxz*o}$bw=@7aȭqP쒳.{Jc>涶+b%`HxG# 15WF-E^l u&|a]޴U31E1BCvObK?v/^qehVohfBb܉,((5\$egy?(d|-Vh@&wΤRj) k!C-|OIB-*%]"GVaf?ژ[)Q?n'i{FH&m;mM#|a^6ni'wc^.ZQv՟߸5Y^n, T -)ˤ'ybwU8LURuY/(9F[8QXx+ 6^)|57¢xGDrWIz1O>T .+@z3I%rWA_ESa_ w[Fˁ԰ї":8;r͢b/K3b4!\jg۴+#4Wa~l>|ږF9|*chXKD$a%w=ưٽ=N;lX.Togp;BU"n.@,4;dy8;nQ( *;91sJv)?H zG GLSANqG$uE,A^9q'Hxd fmjr?'EF4m &kINw;9RlK#@2`WU/ Sb/yB?ʲta-5=%+ .W x'5 vR a =JJ-G ʃq`pl4 ؇gR ~ XtX?Z!ېoOXZSh'J7qu|wJՊ-c3kV@a2Ca-692/ϵ=<.y>M^> abxM,h$_'%Y - gf;l8QcG̱2-z&641sҙ ɨ #$0s4m_D-Kӥ "Ťpz`NVϺugcڎ{#-K ވ˜QR"$`$ib ?gNˀY$Wo5"O(iWS'P_{|{h_.4<^:O,:"?KZ2IWC[z>3q2g(~ؔдvhq4GNQzՖ]kWT9$t ]-z;UܹnN۴K0[%#)i"|njtBIG1b)yQsÍ,\.۪J2!Ҫߓ'Zk=Qb@\e}6_hR|7j c+n]D󢋦VcY-ka+A,މN?IrSWq)5W._vT{QO02+e٣VIUܜ&%-i25xi֑IOZG*B5o|/D%jg?Ro30tSB,L%B@u{] zxv\&{E=z@$M|shתp 1+#&*Tl/cr01"n9zbwrЍNsI_ϊg!xC(7\A9T @_0IwJҚtZSe^3]TBI>iG腗Ԫ[0ݎ_ a2O$Hh#F§8R2nCf }<\oUGHZZֆVJ?FYUI8dxbyRohg-ɽJ\G)#3B!^yїf%ؾ xԙtHK> TRU6&b.<뽆)Gޣ. wx4~- (=QOAB:,#:J.ʷ:@zgPcDB/ۺ*&seH`d*o8+Uɽ[oJZX,:[.F~&"77QU@A OQdʠ.?"g*o:$qb#VZaz-OyB35n:F(.bH 8fhf"p2-\9Oئ 2?[ǂRViY=ӓ8`kiL:LbxcT9U}:"37?*E xV ~DYgہ̭PV>;SJ-GNUNhWrTBq{y0ډΪ/;?P|kϝ\y!!dszM.J>#(Q֖Pl QHA*@҈ 1"F0&^eސ`KY0C2b*p hIJ*ڻG2dd3{tĢtyF)^An~l?ae{$s[r!oeE˵M7qD(`C=,m$ J`TN)xZj.Gbv@.l؁N8^QR(  Jak24n/"}gMܽŗ^`2Ys(idG[ٵ\7| ;g8J!]I5l AI&j|ϙ$N?KsN  C'4Ov; vpq:B~'㿱ĮUrP[4#5Yn|Gtb#Q~ϑyOj7g`?GVp| G/P{+/_0:;uR&MǴttM6s2yrX`ܸXB:}a“n=y c^(85lEF>m3_Sz !̦=ih:mY۾v,A̓sa%j ><_\=Rx_ wR|תw/IY)KK]*Me\W$ e$%PB'HF"x5DfSqt}@nR{;4t=k^MY|u~=#m6%dȍ̒lF&P4ĬnWٿGQak}o\$UFR~3a7dRwPS 7g{5;aߦ$ b=!LzW_"3wޯ#2>錈W@375A@[sd. ФF^ j;nٗLadsUs-t!3 S69U?u[p3z\1 3U}l< Oґ~ZdSN|s#܀I:N_L\G-4N6"CoƝ;ik&mΡ=?mO[VS2hpKݬPg@<8Me6;L`2ĽRغTWyCy276ZFK)hlصuɄ 7Qa9xwf .vKPKY2o69PsR-TJ (%L2/L'`R" -ץ^7Ҙ~&(WÍ֠')7$O(bXeBx# )FFB6T;3uE9i˭]rr[c6@57]ձMՒ)U=G+(ٚAjbWބʨf)7V?n;hlA7VM\ćM0G}_zƒKJplMv缋p6,ݚ&jQHTs&Q+G$BmH<NOzzo>)KP퓬''21m%՘p#YiVbYܐ8|W4%Yzz`B^q,T'bܞ_O+}ݼE#S:E˵ +_OӾ}Rݦ1Yd L4:5^yd͕ \}7ƾAĎ]9 &S0M" ;S+!J˥" 6?lƸqW4/ ׭*>e@9^,$$MU$N-s&|v}xim psL^u"]LӝGݶ׹pgȮ}I'&ѣe_څf7by\G{+LCERk `nBK++FI^0f`xv%V!vlh\EdLYU\ܳbxh_ !#roYJቛ-CIDʾY?O(\=!P-ɕae_]Z +F5ã~j>pzĤk؆IIREqcFof= h|y{#BDNo=e8jZQhUWlO'P_]G0wm^]CemK 讳{8D+NՑa[bR78NtoF SyM.BkƽdhɺZD8ll!ܺ/,\bOQ94h~lih@շ SK1NA{Ras ;Im?Z^Nz7?~r%#԰RfK%pŻopSQE\M%-gʾ`KO:].U;yIE"[\ͼ5&x$p/ç6ⳒF+ۡzcŅFJ<]:dCh'GVܜd3'_,o礳uZS|`剳:jx)> r =ð)1ĪrLt8Ե +xiqC\V>=Z9IAR6W&=$| Hv9GC^\P.0pvscD'5~&4~'I xvFEwB&X 9MPNTJQ]2N x:]r,S]?CC& aO!߫+Albf>{ëlUa 4fwҟyV/X> N^g BE\h]>U98ѳJUX_^ߌC'3+R"^oGw B/@\C ruQD5]͢/AE4e8HRo9Y xM:+v]An쀮˫pLmOShұx9[eKFLϐr7cqF„5\ W!cl'7ZE:~\bPmg2&]]sgY5H0!ýΈ(H<(RwFym^?^-bC7jv)>Ht7`?7d>9bxcJl8`vAf|u1<>ſ#f~NJɨ@kIlN7N/Lѓ]G"T5f@ ˬ_ et4^C nXsઈ `01-G捘MK=NQ 7 IR(83Gs+C,氶Ew6VdS!pmE&&V"xB@>+d9a) N'RN# U=]!n$ϑ|Mq鷉Kyl𛈧Gfɝ` 05)a+?EO'NXV>+g8h&6i76a|S:t8oʷ\)/->75֐sϖ`RMpŰğkzwYwͬIAbw֢XfN^Oߦ 8!c$H)&p[Gwe[QB9w5ͼ:cg1Ԇ^x3_UUk- tT!q_g=@ 0I/:{mLo.8Cw ~+SKVfrXEQZtAwNW`tPm[XFVы֊!Q$c;w X6`_7 =Kq.,\IT59N\DŽ%O k!_&O2pʗ4,Z"tv9"O?.{<\mW"ao{sS7#TO:"=h [s6:SMYGVI;Ͻ6 _p˔ oԃVXt.j 3VT, JA$ W9̀G̙'nt [jµy60)Xb?wUu5C~7su뛪1ؠoG|^Dh~(~;Ҫ VZl}u#2y {+~J(3j/w݆# M2|{BN ͡w5/M.ն4Ai j/$:~:wUy,TK-Dͣb a2~g7Q6vyDӨIRrzͽ#TD f+߇-i F98Ytu~FayK(aq"4}g^?OWDQmEs_ 98]剁!)UC[Z6N2lADo`@R]Z>.2dxJ?v5w'S% 9~U|Xٲ 3kCr23/ZcRBl˜0{q:UFJ \yq]BU4ø'@&TϴNR:kmv KS*ಬ/Cp-RK63!<ނr0Iw6 '΃L^t+}3bU5JlEP 7oW zg|% It sx}88j˸e9wrb"kmO-,аNQRpS]kȚSq \#M,cTf˸ˆs a ڑO}$-$2a$HE_AҴs^c*p4.R@;  -{xPL~)`@H"ɰTZ ?Rmܺ$1q ;-Z; ˜ď`=Hԛ Xn$6d}h#e/SSuNP(?05)+Mcz\I,uIx (oj7O HhD[OmbAc=RF/NFi?& "DH@`_< 5MEHv(0 P,@ߐ9UB# tàţ)Z"!cIw8;`:q2L2ԉC¤4z6p5ː/?mKP,;Nf5NZl$wl5<N43_.A޺If Dihe¸x_fsL6;V|/-EV ɗ~TÍϴ~ i; 2m4f2]y㌘&Go6_ԊCi4](-/ `LSf~s;}LkPK*IPaJX=V(ejuP]_qod!Wo;HmJQ$ ~rzDE*lu1`YZ!:o ,ƕ@=]>ɳ/jx-ov-y"w)Λݬ®<2 e?OBz[-Bv ZhN~bޚxo(iNfO2"?̾tďE/t]CEF`̴$;]NXdDGֲwM>M9NCMU^Ev zu(Hd>Ch7x4=9`k`?*kn)9w0/d $x%XlINmŔwDсVq a,T/<_쌳kUq3z3*eT@+`NFgd&?eUWB4Mb~`hYh:y{ZhŃ)Dm)IR#Q=ƠGnrX$?U?Ig515y$fޠF_Fb T%=hG<b?nn^̮$l;c9Z?Zyvi[>a_iDU⌑ںU[ELc!Kԇ߮yE<# ɮ(nvdz mDۍQoה]Leg~"2fZUj[hBItFےfȧ°x"Yפ0װHQ:m 4ZTuXڟgen *4sn ai`~QbqP|`˱ؖ{(J)+ɿ~{ rVg;3A]|BȞdS(=R PB+[6۔#fp ϑsWr.;-\*BAӶ\B.>򅦴1JEQ Y;vuPl|:_ tMX3uo6%ajZh7<~d!RCvMcۯo~sBp8 *E(濓_T}vBWf'fGXQLL1!~d}3j)݄p9iա+xr$GϼKh6^ϥ"#p@N cnE?}Y EשF_i_T 4q:nztԆS?`[<&& 쬨V&35WZ\S3 xN rŬxAbEo"s䇠B WIV_:k $4/ܭ!ky^ yMua&b:\}كЅyυaPJgt*,[N6&>RR3Y=va҆rϩ<VUWk8Äso gav9x|iI6Ќ3ӹ!$+7x\tFccrrT્݊w#~'d`/ (%ͣ_ &!Mӎgeg flBs6봚^{E).mhWpjt41"E=olEMB(ף֍rp/%sum:V5/JQf·]&'' I1͗uKVUV}̀ >ldrtgglC)L =|@{fQWa/_BB[Զ$LiS^~EYW*cs 瞱RxdK,p軂AF+ fNmc^W)DhLitkZn'#Ps_Vm6"`;z34I"k,Bj@!Z :A/c Rp 6J _gV;ĂBv PeXٚ/dm]oX k0>~TC}Z,wTր-Y)@dᓏ3@@M\#]o1,& âI.zL=gQ?}'&3.{Fܾs~_шѹdgBUK}@ψ2J|RPX[OiNͨIl1?ݭ#v}|mv)Ys?yZNR3\d,2ɸ,BaZloo #w~ U!Vw9~^+-U#G{7[͠BFA!(lǢ4ԧ:5`@ x+'&M* Hc-?߃0˥M/}cIgaF%KXev]BUi2IlMOЖ/{]7,ktkBv&uh4u.Oһ֓(0De턑I^ ^=7F'4Coqɗ5_OoTio3ǩSܯÛM-3f"zSe=_9rX.~@@n5>Oާ~IبBCa)M wTsTpjڮ|NTs$^2fix`f{4U@HAcl*H}}`T4=[5ຨ@B]]|UŁE]e%P{xߒ1ƒDvQ$#Q@LmEHgW)2zUZ0PN~s7>u?1E V?X|5 ..UAc Z&s<`î,նsB9jƜ$T꼱{\H;.џ%w";R 3Tg?S+oV@䟖5gWR9Vҥ3:Qow&mP!B.7s9@u{#BIRcٿ,*D`0}fV:ve+K(PܻjK#6f}9a W-b~ Xn-zrdz_Ө<0u$hDU>9/- 0v2𥎓hST:5 yU+.;%R { bYURnwY.E|v|B/$NkW#AGr~T1 HL?G} S^edl`&+B]t1TBh3T1NMc5֎Hbà>'x~͗+ЀCΫFh˻s]XÖeBgzDoST1Y:Rʿy϶QKB"_+i{6/〰pkI(IڳeKS~N ;bN'c =LfhtiDŽ|*_νj>[<˳HTFb Q{B"or#nfxDYL= 8bkdTEmhIO@E 3q.A@#"Ǒ0|\5ѿwۧ2㺏H؁AHmH Yj!՘/ j+IGbvvO&͠:,Qz7͵3G8{u] m hλ"<r(>+1Sz0&2@$Ν{gb'hWJG)ʱ\OdzZiGCPs p9Uu.+r̩~ OXQI"=ǜ 0Ulss{\Q _E*"~,@srŢ1 lLn% |˅g?WYy1n wvo~{wv4SMQ+LsVo`qI}]\fSXb~)fʜ_ FO/ u.o>.iHص {PaA0O]UЪYA/I@#:?j2n/R %ohM|>U]dG0Kʃ[i:; 5f I DS1ujf'dbOV.]F PÄݞ"\?&O9(˸ u +[ tǢr%L3֍¾#ڰ/TeȠmu1zc/Už=#Sh&φ@vc 1%ʓcc|L!N^)-+@" dA٬G?]6EGH9xY'2s#b/lvT=1[0mס} @6@(7bw&8=tS /P𤅜yէ'Grܬa(;eEzuS >ݪP y_y~b_6I.}2N-E5yZ<Ak$Aāu /OkUqV25{(Tz-~āe_R{A7zUٖnI4E 7EZ+?Mʱ OlQ^df~\&jFa6AWwswXJ毿F8cl@;wηc{TkS~^`:c߹ĸ!CHU3~%p{9 7S-t앨R<-ݖ EY$wO"jd;UmB["8%,q,γ瞰iYjySJ"( nej ٮI>~@wf;o9Db-E6Y2nUa][-~Fۊ{^l\>N=LmӟP0 DN Q |4^P?)+zD3>GpH$]\vڗFa 2IT6fvD +LazD>I7r«T?7P3G@K(gJkMnve5XYGC #sEN_]=1g^H|fžd5xlbQ3B &|w;L}H/m6k E5XΜ rE=8WrZ.Tl~JsUA$ AמB$cVP𣹳ECV1ӐHswı_~DCigꑽFV֑<|Kf9i81BWb =K4*3<x@Zp1z#kcTApշmA+2ی1lYq[2Q;ptl;iۚfxH ?ivRu>ͨVp s'esoEЫM境U/C9iVleZ :/J0Yɑ}u 9܏%S Gll/:@&.'ӯ|B.«CP4o͛.f|i֪a܏kPXK`IVfz{mzjKEx pgWRٻυ:zt^9C $/nL“o7j;GZcNc/ rY Ibe]d@M*~!>cӟ(+>e/49z$l1uf*_ٱ+- =Q9 ] [ظ}M`ψ b;grRQuP8EB10vKK2s}ݨ;*_\?Y(Ӥ/C5ph("CO(Modz\Rn8$RH8˦ v+evdI9ek0 PAߓ<<{MKºg6 ?J\%yYzOxӄ@/?qִvK?{GAbi`0Clx/)u+yhRtaj jJ.O3|Yh -luԀtkab(\CgfB>y E79_;87Z2s. [56CrN%z`.W%1.L(pY'd4mQ77Α+M+.0'.dj|Eb_kz!K:vq퐛Y י zOKT MY&&5)BdӝSL6c!k59 d]-}OD}fKO,0Z`oH 6tT)88mA ZkD$z(z2{ϾP!)g$>LN[ܤS '@KJwG\\b˧Xa4 ꔖ\jn$ǂv-2OVz);di Ϩ*\e_*ZO0& 0_$?[Uv{cvVZ2Vbt/3^wI0cBnoxң6̴Ru"QAs)¥"uZ^jH@ۖ",ɭW+ʈ&aXcoYS)n) 0GnCO&BmQѨ'LL|ղ/?ʈ+j(P-uokWH9'`χ*~^mt+EQޒ;eD H@=Tl{4ac,~5*EGwHu Ɏ:imR5JP0?zѼK "_Bٓ0bss適uD9J_DgGu[tKϹwr'uh F `QJ:8c;ů\Р<ŏsMhOOwPO$+ssX3Ȁ 2 iFe^Ƃr+Q/1J4ϣMgG#v( 5 ;@ RG@E[$^HbnZqU=jͼ=_] &\AhUlfj|j9]7$ j?)Hvl+w7.w2'ZUMBT+X\VozxF!(*Z/צ@+ W|,F{PcuLAuf1x)Ǒ]yit5~S!kD>UԴ#Q*8iǥ'q9OQ@}a~Q3)*ݽd.>>cS{zuќR߂+em0OZpy5̠fbsxc#}elȹ{H-fIdkap#Tӟ=>*x:n*skt28cJ?n  l=7:g;C+;#311<" <[=~9 k s 3 oN-0n?DaRd̛hקvm:d"=HR7{s{A+aQnjn::> *oċ~,h Yݬ.́ m f"_6/B]1S%hӹFcrӱn346~ 2h-)o>\*[?h[kqR\ߚ`B CUtimv%N _Đ 2;GT i+: 7f<<}ͫ2A:̜X+2%V_]p4;]YYk'$ ,68[<+uW{ z#CR{߲ƫC-Kayzʬki#u;/զreٜN5P(4f@>TF;@Z_T\Eu&(`V OƼzx?Lۇ >y4tosR#O@&lex_ a1x߽X|0IyZzb8VR+EmM?QJ~7? '>6>{3P 0Hn"UTmJ)I  G4v7-׼/Z/aqA`Lڀ)1~=ĩ9QaCuA~5Yâ)Ȅ:̧~va R1B' wt4 a89`0e58b7D![τiRB0AHY)Ìy-L̟(S #}uն.Aid&oO&`1눨+>?3p$4h%EKƲOh5 #ѡ U ^嗅7]xXy+H>l02gaWRbW ht8|z?(\Mer#NI5YDi >vm;s%0R0aŊCY2kHFC`ΖU3Zfۤms3g/j0qd裢]%IzmV bBz,/Y!IBl;GE(?FW9<uzՂ:=Nj ;LJ.}A k%f A)uXʟm ‰V61ӦԵ:7kj`~3 /:0:oF$ˬރ]>ϲ\2Q;^SyUA='yݚ.N,Y')`rH⚹ E=4rJsVk`ĶOғ2/!!0-%ul(~N<ĉjJ0US'2EXY$wfA]bk,DygS,)X 4X*0&%L8jSb2'h]Em;c+B/?}+Uk Vvi:MBOΏqذ=}sϜAvMJFvf؀?\LwhxU =QJQlY9QFo=M(:΢[ [WE-SI\Q)4}G^"o@e]/u}uLs-)ۣP.TM{Q7SM Tp_FzԲ*)>U%KEO 2 ڋWl+zT9_+yǧY$1Ԣ/4^0T&[~9'!WFy"Yzx$ѝB妄-|UK07'RFщablWjT0bKlQ'AȉTZP 6k4[s-Q\[ YȪ@/Et≀ (k/)_6 PUs%nZsh'B莩]ͻ"Ǹ2WԲZ* <@5>wл߰OQ2ͬ7bͪr^t/ONu݉RL±\u6/Kۿ eqTR,x-c bѭ0~{5!]؋s~څЛ\!xf ֑SZg[k@!Pb qꨣ_,aގYc (>-QèPwEomEOeLfsb΃|+(Y-2iLwQHIuJQr!_[XlOӍxcOj)T<^YeTɺMؒJ] D:ULϚ|az]CNbۄ͎E`?"&U#hƧQǿ [gTbjVse_57k4Tdz5='/x"ĿZ܋4:xE}ys2̊d8=Q:lo< A͚EF_lů'(ӨUYoUV)mkM:㽫 0@I\t7wKs᫶$+YjI3l lq37(/úS9Ԭ=ۓªL`^ Ó.JȆnzߡg}q^&=SZg]vo뢯]Q jkY}؏ZA)tͱI'xvC,4L{|k'43{c/XzZy]ش*ߣ]n:)bc/EKb: {W_6LZO.U"ݓ"-8 n|3 r&ЪXϭ^$n^ZsՏ/W%LR2OnDVM~I axNþ?쐵QaLa}$" ՞4 F\Hȃ9R{?58F_ړvL]/=D+>7c[EV< WڶL=ysC ̿ϏCK7bl!8qJ#x[RfL~AW4e`T.?u轫-Ak}b$ \"(Y+ܨ* P6rIB:@zUgK'- 4MT<"bo@J$z1|Ko/Ǻ ) Ϙᇞnz j?N*~0#)Xcm=TmDդ"cq.4` ѥN!8KnGDNX#nb:2%8Ӗ.ޏ׫] n`&8{}e.fGZ)Dy焫) nnoUM4;`I]GTZv&aY  D&|^At`-&LrEj ܡvY4 9}w]i o;)K_OZc=`}$nف/ ';8 oD !=I<}K@cVe xDMDĖ;sg٬ ?"eSp(/d=%&t>]iH~"֍LE/}@촉C\~g%Is oXÖv%N $]SRh~*0qy@ÏZ~cXsbVaȸif ]AO]ԅ%Xv|ȝ~y=JH5$] W럋5s.b>dK}XC$mD᪶raP_f8#*?Nj\T 6*+-9 nl5*rV(5S5ڱ'=+F cI /*ӈV|뉢=S: :(ZΠW# ؎Skd*͗ Doѓ_ ;(է(m^O>_l_0זLbW6%nmҞ  8Q\N_'d湒5 {Ik[yC#bHKAc4Pu;7dXJj1􈝒ɷ}9D 14 T mL>q`5e) ΣKNo JSrHJ d8nv IdJ౵7?jt0ԛw@ "5yQMw"&Gcm=qƶېx]0ҫǦN<:}&4"]2w giɩ=`-N}R1:CpAoUh+ԣO aPlD& eNrbn~]hYN_|۩7SLth+Lu~3S*hPbP>]BAvǩW%-PUd*5˜k<O5B(h#=8kW8ᙯjW/\gڴf(>@T(+Rb!,͟dr{09_$ʮ5J&ԩ)P%+w\V47լe~ްmB6}f楰#K_āpeZ LViu03`qyTHw.zcq?1HE>ɈT$zRo9CQT\[Z|Lco3ĻGnF&X=-Q@'])R+n:ɺT@ϑ|i. e:N,iy< }5c}2j6@%IV:rĢDOf{kSKlh dUNMv\v];%Kq\V]f9%fLR\ѾjV̩s}/ Q ЖaFU%Sϟ9)JQ'ѺFlXw1%Kx^=ڔ ܈s{Qߋſ ұ~=.bR~[ O"ղ&iݾm'F@pRF 0k9+)V _ab}m#&fyAJf.eϟYI?Lyd7myP=1٢7n^Nigâ&i=޴RGl^{!A7n[45J Z.~80  N'LZc^͝j*.H9u7vX{kA_\q %KOs]Y>U _Ck4Rb#??׼}8"vl_@9VL-%;lHQ)@:?7zZh^:`n{@ղ&Mam~u: b5Me:!ne D6K<4< ~maǢSϼ!>K:9G,\)A {v֤cEulS{e6FV.${LvJ9l+ V01e43pJ|=ܴG20^HL30Ν =@.;w?t0OA˛.wcߌuWkEv\' 56^5oV#Q akv^q6&?ZD-pF`jeBv`5X GaaBEAZ=DΩ`xnMxw׭gHl%y:·hB#h2s:&3:[/tUr!\y [eK2Cfcvi(Y A*)\FͮyI80N-#qxy7e 9*#H~=:m`Cb>R& "E%3փccwNأRPGiVrLy1(^ Ÿxa){lH-~b}flm\Qԣï/!ހWЏZ'/.4+3PЕMxO D3v z>}c-0cp*b0?$C.`KBDE/$P]qOڇM($UwcƶO,dlF|q U] N{3=Չ`Uj0LUMȠm)4 .o=H{H7 鋬fRR$npwK' ґ>M@zg@Q+ *v Qk@cZ`؟G:Gi2Ұ(f9׳N,>|PJ.sp T+6+VSxc wU/GC#"|eqdPCo؆e|@DNR7lkUb"v%%Y܏,&Mqc-e,\y2~6¨rZMBjyʾĭ7QI}|rq{n6/e; '"w^̛r[.jA1]B4AGv=}2{Q(/ɣl5]|HdH)(QUPYO ȗYa$pQ$'qw6po*{8Ž9CU Etg!֭Fɞ'| `n`YuÞV: /b?S(Bg&Ɋ"2CfΨh|IOl"lt +|!!0 #+V):Cļ xWiJ]m KD= 4ВbK4R1{kt ZQkl7f+hyo%5֊y]YDR.ld w:TL/V7b4;GD%̕l/ΰ&y;&2 -bW" %?slj)CMLfҐ!p `_Rջo];{Ė x_gm]@"hX4r9GlwhdO<`,P q_\.NxSZP`fpmA:ƒD&yV'7ݛڑGa.y ?*ܼcOo"44c3BZb1ڟ3Uh(_-2h[F}`{ShR/I5PsIc SR Lfj%NPF׺gR l1Sy_FU*߶u aIԔLp]Mf%x_hLC)p4ԻRYnDUor(,=ݴ !ܫ#y/¡+C F+`Ս nWHh .׽@%3ԉc}DB4x m@""J :2jcVD ]N>NO P >ї(5z#?*(}4{XNf2j )q;a79?N3ey?4]3>&{/ڶiܠK]*4M#&'O?Xmy0u] Ճ`rDm{FyTz iPo'4+YX R2|]oBğ/SٗL*?m9OthI *wc?A86%PWצyC:l[&7$; ۟wo4F^lNb׋綟%L)O=Q hS {iͳp57Mv+((4ؖXYG Wd^S~h*. y 09m-R8+΍CO pAQi{PwTFB}ӣ !~WX'oPk91%cDt8XF#1mB>Jx@+lh@+DU;l!T{ .K(`-B>u^0\$/Y9{] 5psv6m8n5H}Uz'9S{pI_:I_ٴMK} u~s$Hjd6a9{4H@4A2or2h l.pSHG\x-zf\@@fE` QM]`)NL ʍzؤ0D8* z,.c;EiU4w?/R׻CßLP ev:fe%r'7H,Wymh.~Ü϶J_/?Q|34*ӬKe{,/]v9R|y&(J,A8PȞs1'uaGIn1&o^"Qb+ApA݁sN_CZv`S{rP~ u㮨F4U$ \Ere lz-Q|Sggm Q>b"!͙G.(f7#[AVW?" #vР%E8})ʮܥ hmOvoyJ 4pڃJ!ȉqn]\jMYrlwq I0 9¤:3RMӡ*)f;/eO5Ǩmd?= rK x߀= iލP'|IhgSj i L?y2. [gac j.nlQ8f+4e]Ar` aX KEn.A=ogl |VEUQ۹ ,dK!=,&'MZ2pj}!(,tyҾ\w) 11B概ߣ>ds񯴏mU+XarFC/]۹i]J#R \-5Ů{&I-8")lϭ+`9 ZƘވG+9Ô.)ڝ !~)QzdXg(ڤ-' R>Mz3 a[o,"XCޑ8LŜZA `lq Zf?,M I`tynVRA3|cA''߽)}%QMÃ,4wS* F~iDJO{6v"X@M46DrʴX*$j DPp=3P+t$U|>h"l[ɫ9CYl%wN>|3EBIlFKCP>4τ6-x 9Oh+*\a"0L츀_amndAVMf"rWΟw;[fggJSp453ʡllV\@Lar1~8"bhZKRq͞6O]Hj|pk&^r݂G 2.w&1ەj܎Վ=}RF fsQnf2IH$Bx#?c/d%bBaNO׶%Z6#| }!PʾXrXG!ĥRޞ記kGET yh_+B41qIm_^W g) ray]4cxVBׄ<|v T6lXjb@{Jڤ{̍JO0!_V8xx`7([#@3n8ف :XbZAPkSxӒb݃% XҚ }7f݄g _h Ѳmi [)o,H07@Rd-F)sή?WlI+1]+X*|(e jkLZT)٘SbHn=VZ$Ó / Qٖz-xN0m!f&G(ɓd6{ ǚ6VIP9$nЍ#GkBg`\m~Ks ]gBOՔMznV|?Zd mցT]OzXV!!vZ]\Z83 C. Ve՚c@c145 OvpI_]sQMkVA|BޑhcΝvr)5¥SKr 'L#5vaMX\hҎ}A-Ok %]K;d,IZ0r fu>q<֦WyoрS\(?KA?n;U$2W[I_:}p_9tq 'ň#p6 W^v~xud~Gf8!?9;. ԊA+ o"#BR^eV 7pFjڧ%VSz7XW``bNP+j>4^ӓ] yHh^:d}0)ztxhѺT.4w{B0e%Aj~82zF<14F+kCȇ7$`+pMnU~ø`Ww61.5F,v&J);:DX}tMzZeޗ`9᳨5v 4GKݦnB0 WM9M|]a_̦v_&gcJ J[>|+a#S8•Tǎ Q 0 kС)w, DbvDnEEᲟF*H>D23q Qp!}PչM\S?l[B֙6:)^a%<>kl,oMbfAߑjB1/HR1#&Po5bHsG@EYjR tP% kWVjyz{b={U_ҷf_\TQ!:_U"n'OtbMnCavzN)x= NIȣ,{W)i<'g#0&ГWP˦5 OX6mkL֡bbijxq;'ߤxgd5*H&[Z@S s=l{ڷ| zEltTX&XHJf8rd;w4T׆I;6{$e:*sy@__>2߼ZANT@Tav`9vfx$=M}yExKFKu /6[*LL6%BmQwu`B9=̘unݭ/$%ۡe"Y F_?x|McLzߤjO08D bzڇyne_ywnZԱtܫ@п"~v[-V&Y0R-;p]В$c_WgObGX^NtCǸG8}I SȿٕCL -g}&OV65GO=,3wu:RV-e$)u(ߋv…%ϖ6bg[ AM _Y":l,vM$I(wWMhW#Rˏl-9~'رUVD%hܤH4:%K/Aݏ@H-x'I>F?bI޳$il,\F 0cuHM̹h,?k`C7F( qȱ)Ƕ;ZJ3H9KXxP|G%/8?Ùv,5YSˌoJ*k/aU0,s )+8s;j, eJKe?3H#';\O7sršyiPO%"㏡-Z8ydv;wm2֖{Ό~kgfyxaKJ4R4c2!1~4YlU&L$˔Ƌ:eT jv,)d XZpB+w5ב3Y= 8uwK3RF};Q[ k;uFVlR~YL`޺6mR0 ;Hm$#GszƏR ʼnM"wg98ye m./?i{,i"s.fT@f.?^ÙSaB`U`@ȏ> wY,xЫ8].CMn':5?M=>ʝ~rTB%L29M9^)e),X#JG"goi6q0!z+P*4Q (RIW=W*4ιhfrxdҩifֲXyK3Ou+XnV@ {FlatbaA&%m]tXurLT'e(-=D#Y6Л A?=dsڃ$_8M5k<ŢQ3Q% $yUpU-*NN0!ϬE% &9S)ҬpXoZ|ԗN: ȪxQ5{ݛ*kBĚL}żv-IK0'uWߝ!0GT>?Y=/!Yښ9Ж7Z㩠\ÝMCT&:ktG++SҒõy!(ҽ1m_,2ೠ II;v!F/î_])de<|:1HzGd] ת'WRLt  U?2ZU8jgEH4 }LH/\r0} bp a(JUkTw M aVү>smZQ:ɫZH*`[U#z\/?uԟ2_AFr̬!etr5YP>1*h;BlǯiLt zJoIkݱL)uMEeV+)~SJ3a6ٵ5"LDF:%yL7` 17UK izFRnt=T+4Ba%}S{4ZT'G6B=y\u~ *4@ýWl[xQlS*3Tܻgo67| n;B'z-cGXL<~Uk0sW.AnULJ]l-͞ʢ[cZ}xj"~ęipՉo}!,L4U-ӎ0l~{Jl7{, _#>M3[0y)%,W#yPoAgJd(/SOj:=l&|g۬}IN 4Se()ňO- BxltR gF8A,Zf$!xY?1]V.%sEw&`> ̺g[S:7팰@7/m5;rĥ)czL֋\~=v7[$1s:6<$&m‘JQ\ŬTRJ?a5ڴ똬L- zy=x=Q+  *]1[;nJIdP&MQЅSz!i^16$tJ`d=)TJ?un4kcl|TqE5Fؚǧ/ RgIpDhC*0~<]ԷhQ-[sbn/dmۻ#|S~E7udTΔrv.+MvII$BḎ,go|<@%%bs_<ɀ?4g~k׃SLf\SͰ1o䐡?&KBϜ!AJ}D$F֦MO9Ѽ t3eo:=2ȝį Q.Z/lɩF'8} vĖbJ 'HP(R_Bw5])py(ޑ": 2'U u5l $I\1pW6R״)^ ҁlr@>v[*B>AQgr`кoK{\k7F'*J[K *SE;Ld(ߩٗ)9*,-5<8O3r) /OCy];/U|u\GGZ/qhgM:Yҗ6gc+ ڐuD#X%u^<&Z!*wPM{NwQK8c 鏿|r<(= 59|SdûL)oX)>Aou DtL~cPuZxKiɁ=o.P.Spm1V{yJ07D\J`%`eS?<5,Zڼ y__+R@k-(h;C )/@-'D&T9S42'kݍ!'Bqh(`X4ȹ@6N9Y0KNUwP>?Xò ece++jDy>\ Dl *,DȨ!-oJZUFtNXZ NxΪ!ɦJ;)%1t,%Jsk{ՠdo]/(\d$i.㪃WdNӧa$@YY:oɱ'%/`"m'6G²T!$ y'e`ΫhWZы'Q3b> c|}n}σ*]4!,+Aĺta>kqȘJ;\|OL>lr8Dăv;)L%@=FfK[aytqF檼8MPB+cwp>=FZD;-e?u  {e8Q {nBW`zž ISœnvU9'gzHSlQGt0.7qH/F;9mAp12GBTNlAvӾԱ1!Z0p^-x۫u(1Y1|BO UQY3x|Ǧ{>75;2.F8O n;߉Aj~ᡑm<ػ9gxkDq04R3upkS¹yl1QJ\sjK膆W_THJO̸<~HwWUĤn<. t]|(N!+qVRk`Bk(+zݢڲLYs_y ]Vlt=wYe!eg$HdnIu#PS|{^%X[ 0^u{G؏A:<<eemk,#g84?4i'rK`w"7iI;_Szı?.sz7d d8zm`J{?Q0mi.<-g<(?sW%A -D/=usMLKfu2I{@,*Yq KyY'ݐq{j[llՌd8WWn`COT{n̽$pW~W%jeiZS*i.13σ_ņqc Mf Yea.chz,NZL~n3 ?Z ?uרQaw{-8?@Pr}SYBWW҂javk-㰇& F}hj+$ mCTJy%?Ȕug;kE>: )j(>UFLKmWѼW3ВG:<.=/G*Mvbvu5kSAaHWKN C r$.+1ZEV8[qDP!DzW(5t0`qW-;Q2 I=rhRPi9Ў}RWQSMҶiV2U&Wz1@Kߏi {/F8ޮlgeCւ8)v.]h#ka\r b%~Y(Plufu ֱr8>( W6B7p}z=ݒ1xFMs8[[%haxa#ƣ?gBɮQH@~ ]yh);`k,EVđfJmнM!WGc$ ShCKc*F`J|ɐZX0 TDg,V~>'7VX$I'yG.\2N|if{x`_TD >݃ږGZ:$ ۵L6kRղrcOe 3"Lπ_c#ʈY{5=Tcٯ|SS^>rQcQ {,nr\*-X+IzZŪw4@ܫD:jFxOKTj+xL.gsI7uh.݉X;%#&.aJU=(JVM-I$[ :^q(  ܬ=ѐR~W#POy3R d E*q˪Gk7 ݕZ*A&yov$3*%ebtKN]. C$Z4`'VpzchRFA!'>d<[b Y$<֜vѥMLOj2ӹvT#% :%#RZvS,ҫxԘoQ=t]t x[dM#35Zn*GQ!+ħMki~Z\k@¢@$zg7a ! B<MJm1([z&_d[(z-6`<$/e;C0lVTe<<( PMbtਏQm2o/1y\rv[n7X2]tsKy'/H'ΈPN-t6d]Il"ޏ..9 w)=FMilUv?/:?e#"gΜ.nI~ʆoE"ƶx*Kr-,N՚_EbC gPE8nVSwzUkblN:@Fm^C= Ro*h29n,uфU%+w6gHRS oj7|}5+78=ujޝNiaceŖAZA:Kf?[vd+ " }^^0aT8I1۵>%NyZ?$os9K9i:Q]B1=*+g.֣Yw{{W6-d|C$\i0 n PFUP/q9J6ꅟ{PRM*ac Fćb(A*4ͿWTZ٣O#4;0ecrQ%=/}3[vyqN\ȜB}Ov|ڃ8DvG,Dh[Lm2FSL:~yLqDb雩0,vݬH |iIe\Cr/0ęYQ.< [)@#'ްeJger-4'CIP..ASؤÜ]j8|0仍v z$)mjx8uSɖtF lš*0B:1ԍd/ vʹ1$>?4,5$bjjƬ9eB.VrAy0yObЉŹ/cQBf=`3E(x7B$oa bfu<[f85Ըf,zDM4GV7mi㚟gǮyJK)I(X퐭^ܽxu_9wV+n^sjv;]Q{q a"g|*I2*L("S& H`Bь2#}^hr pɍ\U>t= ԣ}W4yЩlIUZF{a;<;BL[E{F )?u/f\ >1r# vr yY( '|p>GY%RaH*p  Mj!˰y10I:iI"E. y(D$ ;.~W)ZfZU69-SGPfv:Ω;ÞtCL =L?{!q~/s-Em5zC.]T`uJBGZfQIaTe#y3&ӪTTCN*Ot7GBOP&l 6Ѕ+nQ%J`ñGYtJȽwҧx{G}u٥3%i!#bW1$K=Nlك',Hx#\>]@RmXxn{WhGpsdaJfAfif?O@?3xRis9 E{eC"Ԁ_lT̈́V)y3zǣq*19$xЃC V@). mUTF#tچ$ieJ9rC eZeAOLc~F_s9rla~!,PغFٽ:&<Å@bAOdx݆5F&f*1wn!a4*86ZS9D'tuP\POL<8c-TIV#y n9͟xٸ  OP/w湝|Jsk$֛0{(rףB/]Ms68@oL{8X+UgD zG!}@f{,U? :Y(-!$R/t-tE$rdȿO]EJLJUM,,^jfT>uuchŚ[jmMҫ'8b $n7!P&O/5p.xqR>R ?z 1aU*V{I_7D=+t/K+3ݱDNEb$:yg◓~.5nb͉ Z^yχ_dMO]g`LCxVZܔ7kThkgqbzMg oi uL^19Ŭ_0eѾ{%jC7O]$̹فE USHGLk6lVXqjq0T1P#Lp^UP"spgpy$ 0O_m)g;)q 4("h+Wr_Fa ڵgOd_xn<0P):6XFB)\)#/]W&L.v^Li3w{^%e,[4n_~1{u "ɎU'"bm4ɹ$ ڂJwdy y(r`%jlĮrl-ၜ9c @dQ3صJ2/N='WY(i`\*`+B e9flψMpd<ɍج5ƠRXQbM3ꇨuFr}eΨڷXk ?Z%:DT\y2Ƶ(O cA7؊.n9#^k)a]G(}s:O tAlL$_,ᑩn6QQ!ȃQ,YmE>fѦk<.$%i̓FzUمz \5ʙJs([է^,} SqT#>6h6OS2Ts5B%h=O,j=&H\]Nzi"~ {*3G?ɅF<,^F?p]zҜ)]qM4 UMv\e qcPE2_W!I+/ދC

+ )==w<'OhqMw! zw„Rͨ8Kf~M?ȥ%+`? 6 Aꍂ4 8xPl5(j58y2 6)G6[b^(MM6ਁiJ=sr*?S8R?@B0(V2LvL$1L»M,we7OKmWb~q<=֧Z.FffO3;YZO7 ft㥸>-(UwS܋?H ܙU69dаĶEŒ2QyZ-Vͩ՟>}[ qq͖l/ξHX«Pj7q(i@|QXpThu(GoC52\bjhEn#IHTD)J?bvw"5\X[. QD0&P%.E) Y.C$: w([}eJC3@ ϵwڢI7æQ\G۩x 'O,|AC,+۠`Fm7It%ԁue_O[2lU fH.NB9 a#PV(1h3~@PK=\OIϛnpf!!iR<+ _7mwy%{Kn[e6.I.Ա}؇8 al8r&z[U{*RP}rh{kW&~o8aBFYM 6DY{ZDۡtg" P!LRxSՌ8hGjpE@E`tsp,q?^L CO0Ras^_hOS=ً8LM|6D́zvvq֤1}D(\HQ MRMK=gBCobc*am.1Z[GocFSO]+BYQ2,Į72`8>ÒƏetZ<2>D,u3{a|u'P"C -] 3%g{=B ǿ#[l<E//.9ddR M,Gh?jH @(<>bKj/~zCθ2sD^,IBx|'A:mtIv8A S7ʲRF;ZX]/%0y3o.v+Zu~B\Ǿ3ѺIm@M Ɩ5fXhkƣT`S %Ht[1"dJ|`}Ư=|!B}Ŭ|p9 .V|>o_N{9y >Y|#p#:78҄iRI>vB%:v @B@cRћv'gY{! Q#@C{m܂zĔZ2{;ju;mIni֎R^YbjvԲD]i\^bi(6C-i =fnYͳ͝%g}oj ff֘gFm$:8=ry}dK r=%7R4'zo^qI72SH%Lռ(?c6GX~TZM =-ŕMTզy;mR+u4H;FN¬n|m]^J刐7jmH''(DzgWv7B,tv"!pJ1H/ "ȳf_@eA@}A#p7jMq\36i$+&,@{RK#{IZ:0-A,YkYE ^t%ǿԠ*TM_f⪾^8X\D .?;D[)@{ŀw<j/8PD:GW dcá88 -˫c=,e.k%~Z`X`}ϑ4ڎ&C  c8oS@U;]mf:Mطc]t6R_} 1) 9V*xDd61v=vE%o>#41 1ןy^TBqṃ RͶ" "j@MkM/F z,X-X̵/1 r HZzڔ@AWjKS:3U3 ¸G%γum$StvD95L>B$(#날Ba@A0 *<+.ЁPwp.Q5vWE8`[Ǔ Y:Du UQbɔ ;"Љɍ:B=4_TKֽcwre 'VBV%fBr\z$w0궜N9nhMU(8.4"|DZ}>5R! _7)45vm][;yq[EXwPXLp<m`$ *=Plb6<:1ߥX(%or8:WFi&H;l7k!WE(pܱ>xӆ$1EJc͖j=b`@#2}$_}]rd~qׇ[5S eeUc>Oe_>8؀<0kȳsv&Pb| o Jt"AdXgP<*g8ӱMzTS*UU̐h429ˈ{ ^Oܭ[^`5;^SbKSߩ2jj$λ/KoV*]3! m֍؍DƌA~XiҌ.`HaE;=2y[cfwVV=V6d@2_f[팪kkN}y^fX'O>}R` WgARt}Yv{&k$q3gj;D݆̍D<L; @wΓ ')9]y/a VK|6ȘoUEy{4OLW dj~V^cZ;r@P\%0CB+~E0a]E[n5<#:5x1T:N;fdq:4̧ǶV9(פSuѿFix @ƙ~V]! WYmgziOigBhyM!ƀB |V2ȑM/2 duSnsI| b=ATJ5Søl ^7"^^rۣ;"ɮUN1HVڌe,iDY/Q)>;ix`dhf̉^.;EZDﹲFJiWt|l[FBޗ(׍!N6i>v .od,L Rr*e*.j-b-49 ̃^;fG>Ɩ}6ǓA>ydM&?,IL#EA6H%6֝7eB, i6rFn,j'Zsdt<1#> ^٘9?{쇺Y=|Gth?&gjMB,H5 Xz JZ/lR-3>|j1fmnN_a=qgeE7Ӆ3o'w&|_U Kn~J1>c^rjbT%n *v8ynCyItP"E&tG1naX$fRLfHa% A,`t: Jq"TR;A5͙^[^\Mh#4O.U]tD&' "Qqb Q=eszdĚ~:u,;g#ض әM3.l}̏;j:&M3%g= zدУ"8"0EIbvQu%k]\h{q>d/?5ϛ.邞Cǫ0vm3kSS3ly {!M)^de?b!x+(8(IecPR>YkΒ/Y`o`B0nTX5 U- E<3O(kYh!Y1qlyڅMEVϬo} >'j-U =`tJޞsS  F^M( u\*?0Kar`(zUBۦd.^ e$[Jj#g B'soR ّYt-!&zcP/r>'s[@S5e[;j] w׸0c2.m N @Y@ۣTIO>LBǿ<ܩFkI/R2JǏTn;#~SQOZҐƂޟv==Q1d%r%zUDns>ᆋ!(Wgwޞտ# \*durs;nOwX@ͷJMO5ψv`o(Ao?u"?/G8PoY(~?ۮgo@=<7S֮ r$ dtxOb%2d(uZ"^`x3M ?,^oAσӶ2w>:;(1٬F/=x^!?8Ț*PpSmU]4${Eך9:ZS', C5CX]LB _.dCOh= =EK*7 q a6uuz!sco<\&6^\)4ڻhLoLa| X6gшR.*GJN f"SX3D+= Ll~lVo!eBAƂT/+.vfĬ39WK v"YMqϜYT̮udXbAkhFghRX 1o(}H!5*{oaj:1ѽw+e, S^}S\xkT2y#Rؖ*OBQ]v_TCܻ9@HęH Aӧ,4!8o[n}J[ z-s(t@]Uu<}cƒ@rL>R\FJ*Iu)9xۑD_>1;/P/!3\60%+,n l֔Qҁ ʨ]4ΫTZee|#+P刀^=H탫\pCŜ)>!/k|rR 14.9\ }p!=)bb 3{#۹Sl)Y67{/>ZmB{hت}5T/hu<X.H9d0B'SN]t4Os8# ܕ2& Y=w{,'ż!xH܌YAVpA1怄ʒ)u𵐐2V"7{S1:]iڼs&GPZxS^~vSDxUM.B9bf9Ƹ &Ec$hߛ.<[)Q)'uy Y /RW?wkJ5FL-JS!P\%#kΧ9]JlUmC_<@pjȔ׿Ǝ:>p b7<ͫDJ^Mǻk˚e@IY9%-orzYlNT4l[ۀ` ,U%*+aqM kZ>=rqS# [61x3hNnoBoQm6m">,l¼; =ΖQCIgINH)BX U[R6"rllzʖj|=\#Da~L#2'XS9Y*D!:h6z%a򻓓mU\~qIh|*Bqʮf/Ju|QT|qeޡL)&U/Zm̃~5qptK_^Tj5_1AKQq>`^Ŝ,_A=݌Or>PjpN0?l=~/g.X];#,\3r4z_L2$ wbWʄC*i1b(Lֿka}ȦɁ=KG[l[rXGi+)֩m;^pKL9nr8$fr!u2 !WxqEFKT!av@,P7c  hUfcG@[ ѧ xZhD,t9 IK\g<AbK}Ӫ K;(ۋJvoEim ه]kGyNW0gF%aֶ ,zg|M"B]*:uʴO x/n4{Ӌ9zs@u $s g423o;enɈ*[7S:W[`WuUsO&_8Hu #DYJ3+ Y]v\]>y6{eIQN"REUAHɧr=Fr n}|^X^'QLg͈ıN22TQj]5<՝}qSo,n8*l"k.PۋU4Һ$7Jo7/ ~3י@Rje}BGeInxoƞ\7Gqbgb]B 8*$9Dkj]Yᾢz*ʒl;XmjAG|L ?&ÔFb?[IiAbCo2nTA΃}3lpfS`4%oE4kI9@xu)兴'jf/x@d׊Z7TGt aaL 8Qe'R"]= }(12y= $?gH|; ,%rr&Is%MO~S>㔍"o=YˢESC7\JEKfb)sI9\p_Qoj1rEM=񮅉#mD UňM?+T=w98JVn$犋UY* smL.ۜz.>ۭV!2!:C(ꧥgk)P| yBkcއr .gZȴsטY[mnhGX%A4++lBx Z,?~+FJ `']ֹE[[ j($\Xw.J$=k*Gh\8H9<Uh"nFi2IVGQ8>@Eٺu큇·1:V ˆG6(hQ9bw- rCݧYQwO@2}Sů~‘wShQ{`+o>ʮ7_`-k*Ы|y iǓLyeWMY'5Vy7Wcth-]7fVct8^Jc [8\wJ(}4ѐ$˛d㼬Ňkd$j0FjiܹzU\J*c[9# Hh] 9 "N*սjrxp9 BkTXp2'WAlzuHv!3Gʅ1i7Yy(=y9xH7\dOWEMg-wÜˏQմ$tf{n)߭_ȰS&5 ,0" (ƿ3\PT7SeX|T' LIY!mQVv5 {?c&#8:Ћ7bk$i:\MH_W9VV >(lC;Vʙ'Y>=WWfL$!Ӥ J\%,be/!,˰G/*2{텭%tL̇Mq%VNRŃ͹1%.W]Iq~=7k}UqR)AG#U\ԧ gbjd]7f!ڠf=4CuaYZ~$.]h}Pm;=LcDwq4VSnzGw/v 4 /OMjLj,z~ >z!|a"|؃ ؙ1:=o]vs'T z;mx 0B$6:O}s!i=ʤ/Sr*ZN;Ohfg7P߈ð/6: 6&L*4c߷QU 1af3w' tvõ7zC+P- va2QAbP-^i NzZΪd+aUĨM<Ѹ hѡ[AU1<ţw9ekZ!N]V*k 8v'p+N;N07C4;FE;;6ڞŽ Yހ#/Qe&z;1rKNtiy[5aseѪHW~< =Y%~UZTupcgp"x"pxU77'ɨe|Xcj |@KSUuVއ{NE'{~;(Yt),6br'Nνꋨݙ<-eP&A]8G9IjW0XIXu<jwcsL=6j]jZGд|p@ؐi{VWRÎ5Լ̳|t}Bz6%_5I A؏SUXW҄n XZ&Ckڳΐ6GPt;۵{&.MtNǩaC[pΟ||\;o!`b=Ck/He:z}=e-G JLIyJI얼H%Qp@yu Li[dSaУ/M=rhgz̃eាf hmĦix;3e7 JUL:tsK0C3Ҡ(,!H%[7)OGCd w *rXHyWUW96][++2'J F哏gnO<zĝڑItqCqJsk5Fu!ct`,8 Hͻx;F:V;s+J[Sd~S\p/[z`$5L%14zҎkConp\{Sl.1 C,Eb74IU ,B)4jV1?Uf̽v۽VBJW!8Z K2Ն/;AHԦ0הo YbVIĮ:Vس`$ B[#%idA)) c96M,]>Aqn񗣳bBm!gP݊ \\p@5Ax"<)YS+J\~׍ Υ c5Ark%Qmyf]? ܭ5x:2v{ dNWZelK%]"1lԈ4n'BD 99H$4J[߂C>9(V[bBd1*WiI pg#|=t!Xs%H|dڌhFT0 ީΊcXƘ]3Jm-ahGv1=DQtя" a.;Zڜ{ALʹx!Vl??0^ŇrzPNe[f5E6W[m3&7_MLMvC?Fԍ.䤼\Ok*G JjS+V_ƳPi k %p Y2Wۉ!O1ƔgеW~Sb}Ju)_tlXŘN%3yR C"K75HON}e"mKd;@ ml%ˋsR/; ^f[TR@W.mL̐3HW5fiVD`ês a6KgE[G7w, rqɔvEG+aKGoZ F1^vQ<: kF i[!ưľgUWp>h%xyui}r;5H"6zsJsDʎ[ ;R8ƻؠL6z"=(nu?iIR1ΗXbO!΢@AH۪D&u_X\/S=mnbJǓlFm^^ָaC|UvI)p$"r+yW[ iTP)_j=/1%/\ b%4F=q@Ɨ=ߖp(LqE&d w#wM S]T&2J iN\,nZDN:.ƣ7SZB+? -OFgs>S,7n/`ZM{}tیQs ;j?_͒ͤC |4l F,NVFbw;eUz4DT_+Mds@#=.2l J~(7ypcu8lɽ$r/({#|9X7>#ʬn0!O^~PMaLm#>nsM{Ag`1k|aZ skXhl ~ܲƔpYנȘ8/h7\wܒNc~_? X}c y?<ϯ!qYƔSmR6"@WE%{ɫ/R/MH *~M*(kU)FC\8PҶs>زEDo&&%n" "r2 9!/HN(:gX74Dv~,vky"e%:`xjF&;="+ Gvv;~YQF= z;G!~8ń0EuZ5M <_rd&y@e{0t]Zl_eW;@ BJ. /?AMō|0g-3:9D=PFCFzJ[sȹ[f yЕo!+;/)TOr\]ti{o!1@W]=c}&6cْndp%l!zn-peWBȜ 6A%-27m 0&q-x8NzsNKWMumf}u7dDq@( ^ۥhwOw%_;Twn\4OZN˜Oqv3*q4u3#U* QUF紽3'&IL+]HcFQlh' * wzM㾤h@:=6ވ; 4+3%=F:'5g" =."|= Q{1;]DҽTBTfwd:O*333[T=s|1r=WHv\y";hNsDƚ&_W: h-f=#\ ۊr^i ^ӰN8l2>DM JejjC+0' N lL"83127 uQTJhB^^Yc0l>wFZ7eϹҞD"16kMJ9cUCw;hloymߴHS&G1 AuvT'-&VYT*yeij#Ԗ0l9>Ht%61'w\OU[*ůRC6 9=+8 ;"JB+Y߄1aRBz-G0èF>Y5>w'4/mMU7| ƿ޷#d\* ]_1 dPE:># 8x^ҼF(w[8r(E+Q_[c25z#1~ع%R;N;ܕ.@k &~ U_aȜ΃w6gg5ل8ǔkYEs4(zԄms=sPs ^g``3 꾠q¿W]Q,IfG|<;K 󴊙a/Kn̶̗v)Ǯ͓EQT;YalO2)z`0l-Ny椘5=0멪$-IAw][}Rtfj-. Ю&=f): i'm.#I< cc a޸b_LS-.7}hvN#)b1 N9N!&zC\yv82)eMq;ϞDTggL)nu- 86fv;kB]&ʽ\>cxM{ ?!'%)T;h<7dP4M~3 D9dCPnգL1Nsz;E5WFO:W1L5ёm[obáTe\4H?& kX./RD0H* 1{e}qb9Q)$]]oGwdooWD4l_#3tB&$A:0/*j[09O[t O"1[ X EvM,g%-N>Nslfs+3_|*ij`"",O~2F(<,Cjq=@,VΗ&Hn )XLK*jWBr3Qz1׎OLEo{*' R?\ՙ߹Zar =[Z?'^Y8i :q;Oq?K<JoCDʘ{ 3ץ" [ kxB>Ч{HO2{Toݯ>1Wnk%]hP @L,z~_ ZPr7%!I91܄20alU'FXk$K5ܠGE+td nh' KqН w `zCЧQd54ƔYrph}-V0f{m Y~3-_3,ByE=BQ'Mʟ,9]ᅯl@`IωtnL; vGp؀'|P2@NeDQZKWff xqM(0/S>˿gPźk-^U¢vߋcilm(C-!υOx9#a\s'/bB`>9E>[W`TkjmJ*XgI0!Q@I4`jsozHlF&h,KZ;5(66=®>=~<vl޲ V˭q,tRa׾PTX P,8,wxl],ksLwU/% 7JIOeü?pyQi-ZW<^sػ$Ϥ`}tyFֻ/F԰2P$j hؐf.b].Da_$1ݳϣ\1Mrc aߎ:Cm"7S)QZ1myNF;-l)(}y[П_;yK+4PA{]W uKT״#"yaŠ"jQw%G 4P/hNnEZsstn6sh#p5[c2sm\`&H$ n@IeHdgkHt햗00GMwGǷ7^w#w^B/UWWzƶ9CnɨCH(9:+!vQD>x/Yzm#w0/#$+NJY9nc9Wz{8Υéh9)l#AomV5iOzgOo׺QnHw'9q,X7Аmrf<]=;2{8AJW_4],"exPŶ OS4ag9t*,),xХ{fp'f]MpVcJ`v!X<+Ւڧ<m"\o5&^>2[, ~oW<zd ~=b4@Y|m%pt2&$g ;hɁٰ>a>ô'8 qZlE=0+.1%6mQY%`~/#AHm"aA 8ftФ4]Ӥi 47L,w5{Njus*؄lh"%4 "pꄺ+FuC0Н HQoՉF܉ pJo f+hj(„5V.< ոjU-3 m&G0@m`8%?Ty V@SԎ^UXǐg}&ISKph@3ݸ 궱WVB8sT{\}O  QZ1RD=y968'PƏ't,ُ-^5ouE*`e74)Wn:'T6~j)٣W:r^ʸ*WN؊HydFp j=NKz)sHnTA{b>k2ZO(A~443=ouvi@-9rG.ߛ:;xA yUbND:vg~t}!wcdNַxg Wf ջPʖQURlԏz9̞/2TX23 oN[mHrpuG P1Qƃx̦=fx~Dƻt*}ImrM#IJbIÊak-˪+m@-wFDZc|&ZԒHiaV S.2 ܿ[T%Fu Lk ԉ7o 8h5sUsd.vSlĊg"/h"! cYcHD!&*ȑ 6]2rD*ٚ~*D+ ( $e4ʬ`7qC#ohW/0e5SY%GE['ݭk=Y+^~0v]sQ~˧{3^&RE&Tw{Z r ~w._:kMAMRl˻x XFR}m<;#BtLƋU?0Xnym5 |BLL$u9ė'|fg[7{H4AJP/^Ø ВK맍{#k NaD/,roYxz]!=v3YUu$)`{Wk㑯A`Gc|")J$+Jђ$uUs39pXȶ :\%R^ X8ViT>=|l"@lEmgo5]M%R'DKPwe0dx)~|Ǵ~S6seiCӵu#u ֿ7%b9czȅWƽ-d Y+n/p_je1w4GqNmK D/I⒰xV ;(N,Y 'YM!9_¾"x>C0End1c>J:ox,~#f9`H4Eo7fHoQ7* ?ͼ:^xf[7Q;L&=X4!uDw8;((nQ 0y?q6{t_2^u~`m_ ]”&Q, >yAݶ̀RD21t v)29~#CZ ٰb_'鴴ycXnM=;65-i 2U:=a/vRg"C9=28m(jYqU)ys= ?J L0LDbUYeO/`lM |څw4()t=P74=3#-OOҙ&)r4t9s U>;XU $ r xٽAdOHf&RL+"6D&lGύ1y)} 5kPn~ PP%AFXm9} Q ՎZaDr!XvfVCԜ{8k\Psmt 7OV ]haC'rap+ώ-&HEէ+~ON9 1g\ h)݌mui VXtzm ,ysO տ2|ׯ< ^ OEWZSq2Tw Ao)":7|u OHuU"3%?p"}dM^/صܾ UDQ:[R`C,SYbzd~h-5Į$N!;J|UMAO6tR݂<^&#3[N':*a]/ >B˓`NdOb9>m:b$b~c&E^ѰKDV6 NP\Hx\pS,a,"ު2@]ucˠ[mYtFav01Ev+g%Axo]2׊]-zՖZ: C,3Wc- xtߙKNx*gtgHX$}FĹarr Ao0G !qg 7;ᠶ"v7ݦ!vx8Z&yc; gr5|0 e~q])ڴbAbbjȳ2f=I:mܳI=f 7 <O&j˫ ُ:=g™ug:`yB;;Ԫ ?H|5Bp/C^e.HΊ`_Wnd?Oxo50ГC lM6˼s⩟PzT:[/q^[X8m8۬?iI ces 7VYԥ$5;E2Eo"ru̚R>V-s̥ON CKPYڳUh{4 '&_ enG)O'Q-x1GLxt3wo4fNqfr:zZ$[iP@ n섧x_oW!<Hݸ[0Nq!lbAҀΈ:%ּd9 ch\cL'E6T@a:r³yrGxVqHڔTHuS%s<M6cI[DpC~߬J,C[O⚠:_ h3)F?.⮹L8-$73R$%A^3u<4t2^6:[9<עb|5Bh2uǘZ6sD"b k jOSH 8@(sr.0k؝M 5^vxċΛ.:wPQc}VpX8xϿyv`qg)ړfL>a:%:I4ק&sD6[cDc^P dnWOb0+QVTirBw2_<>բd5؉r_ .g^`ޝr%l30L=ŢP` ܤbEqQ)~1- ׊XbCBKDUG3\)׻|: :'B]PH\b ,X,FkhXFYHQM[ŮdbR\ͦYLIV d`yu2B>)[>_Umv_zٱ!E0CiQg$&Gɨ҃B>j1/ѥg{Q^W(GU$┿ /|Iʪ|΅{VΤ;Ԩ}5ߦ4ן5O=ms{ l>ۡIu>GJHvkkէ9W*ahghwpܪ6߽=~#n޳) Au^}Kײ }4[ݕҠ8{d$Htz>Nn`6-w9_Fr;61%Y&H鎚1T.k[9Mrav5BI`D-}v?"5%dp v ]=sr+FOfZijh0oΞDDQGx8=*_˜͗O61F3舓 PU0g~WKf~ٲSqqmWMk% C$% YL,lt4OO?bZqK c$qT 2\ȃ8n~^ s#Z*.J4-<ѧ\()CWzgvG-BGj^mz$mIQ0W|}1BlF%ISơXQ=>ĞMOڹOI*4jox},&ئ_ zSpc#> &+t$8\Rj[?o \PyjlaV5q/UMރ<6F7I~ 6~ .L5Rab~U:tm?΂ьT*L\:6K1/.2=̏ [^B52MRķbC,7帎$_^Sc%.ɾ]ڔ՜iYJvAO|'.G.! χC~l:_C" VfZUdk1d|]2t XU50{{4ټ\txDV9U)@+"m,A$+#J l#1I/VnmPI7* ?iV70{J9Om+AӼi+8zY~33FLJ s]TtjۻK.0k~k]}h"‡,`Υ;LϽs1i,2R^,} }͘@&;XR+wvв'@_t-p3}Gچ ~b\%tA_9Ёs #I+q#'g&>Z2h)o<|}aqP"u[+8 4*!de^$Aj[U3ivky č֒C6XBO;99L)S($p:F)-@H3eeB)[N.\Ml7c?ks5 ,$G/k|8D~߬$um\2?U;FYT8$ #Ըf~M{g/;'-մ{D9X~ʘšRiA:;>$E 3:_ /TZAh P:qT>vk6 u9s<'HA2ܺvKk\D@I)EsѢh:+d]JOVw3>@"2fnYCVN곘}%sT%U{yj) 4Sn"NT-H# Yg\T.haHGRr)>T"o`UQyS>b\Ft*uuu#cbY@2j 8Z{M -8:8];CRsZe'0~*[G,- *7 d'/G\!Ѯ!c磏 :U XW3aO =KS7|B~lY/ V]Sq^>%m'u}<#s -pRmi蒞5Xc) \WԭU8Χ|T6s \M9篂Ug #N|SLSZ`1S)5Ji{&ƺp41?J-zeYY0kJv WPLHC@`ګ:rQg')OlL=wj/H">wP6R?0o#R5o2tdx(A7z*֛xX/ B&%_p9Ǩ}4Fʆ[%$(5x kz2^Ͷo>ř ˷}pMuD%taՏI3C]1_ 6}LH"^BjD(':hnt~5d:Lx!w$%=Y5xa6 aCn1 H2oZ^qQY$H՛{z1𒩞Y*DLEaw`yQͲ#}9ʺy-3\fJo3ʘ;+3e[l3\^.L߇xlBg]2=F)d;k?w?D>2nltܧ8GZ73Bq癱F`t0o/ވKbt ^s8GKm'P`~+z(ȡ-x'R cPb{+{Za$h2eL)xf.XKbg-䠜!r48Kq8␸cʃ|ܳPŀL##E2P _RYDˮ+sFyW}SPUyY&gh&$4M8AiUCP#ހ?]SRm<fҺhO|#yfڗ#34yb2zCA,Z7RRh(g넻d6pQ.D|h#|"]0aBRpPPO\g BfDLY3uCNn8-<*]Mhڐ5bA | +%8)zL z~7׆&qӂ6.O{n ´4. V=5(zR`@u}5,Ex[l:9Q/8=fU޻Ih=|%LPw VJsiY)n7 AQs )X;w?,a>j>0^ytLAr^_skYZI Wuф-} M$ӐKӪJ0p븑g׮03PXo"Ԡ/UOo6ZKN>qعrmL.+gPEJzzD:[ ^*_]f_CxیO}ʃ]iKt0>3IgK1[v jT3QJW gYZ `Êmۇ#⏷Sshkg2~e#,H0f\ K3u`5c}QRwDo7&If7ew $d[݄9`徬2m$^l.@yCR }d}7>' JRwv|ȏkxA{pZ띲D_}4S,( !_vg4U8fe;B4TWhF6 ZO 裫 >I?9Ӊ1խxRQ׍m;v]isڞlYmnDpuR2g×{fݖ'cQL2F m4cZBPfS[=z8vvqIτ޺e1z7r>ZQp,OƶvV2A,bΧU^\/˭V .)Ш, %#K}#U4P-U^g,WpH< '+#)y+x\ݙf?^pY沈Qq!7**5&1H'/٪H牆3{ ;cH SMJ٭1-q$9#Zo:-w |)$,7dK.JR*9!A|߾x}G;!j(ξ%#TjZ^/ _/2~i[vX]YZ3y̨)lyK桨7+Իਯ`}[Ё 6&+YpzMݓ \bN}aumEFQԱ)RA2pкVRqfg~Y o(4gke>ʙ6*캿T|ؿ]N B\ۃ FWѩE8O+z+jQG @l1ŌffH܅/roeOMoy/'>&HJv0*o;X.Zt#;+B1m+V YA] |`̯ZE5$Wӄ5ELx1nC 8{mp/v$A-$N^*yW!Jkٟ:jĊ)/׉~{:KV'KsF!c ڶr$!LkY'fSYCFo_?Xk-*؉zB76er{Y Rs+Y",U7ьq?iHY+t{8ve- MetSToBP(pt,'Qyv`[Z qa!8珅lqvj<O7?9(㲽gRgQYCY6 uJы >;jG]%Htb·aE HF p= J&̻Dh3<jf䳥=7h$~犿[>4*~·0(TJSqlϘ=OdZy*|'=2Z[Ȯ=ڤRIOuQ\`-s9K9_Sp; n wdsCqeۀx6z@'DaiǏPQzw?j :(4WJ C+/5aθ@PA +a@?. C~GA;+ZET,@]PWX+Ug3zgFDfǖs:=+g@ydWO [+(7\t˧et^DjChvzTF?lk c*EGFqV4z#2ȟQ G()7/a8e^`d3*:9i V~/G*djMӤA CyJNnI&/ (s!T#p(Lu%X6&ʥ)P%ñ]p%Br@M I쐛;'*6%J㉄+ vGY+c!$8edMP>KY VyH[Uc^ɝ^.[ Ns1JgKՅ|;xCjě2 Sx>'kTt8-_7)+hkaxǾ3VEӹGH]ADEY+2^psܫ dFQ7By=>͏e:@ݎէGb65sHYۛö'U-mn߂0XږԤf2T0|ƽuL[;2$ۨ)^VҔRF1+<"g.lS *~-,u T |PjMV%OaxOl^ *\4.bWݢ]>Q"9R[UGM.13:/&A/Is=;e0jG=K\8>KW_д@\%FۯbTIkUXw%[?m6Uw_7>|E<#[ Jj=`se.S,X'OҬ~ڵ%~~TRNiY cBk4+̥.sF4qjʜ5-P=6_ɕL/QNs0_Fs[gĪ(=<PZ8^λdnT&Ja= Zrc$b$U(DCJ/g{s^: G! ~]#c^"JD6K1b/7x K^5;YFRah& 0ڟw7؃x!6a 6䢺\\vPH)d_?"9,K*e&Wu*xa EXhd:áuoܪ}mq䡮]] s/z(fjn9mHs2vm*L΋TiNs_ӧw^0F 7" [Uj,tŊC}=~܌m򉥂nb¡C`ƙðQÜเ<nE> @1 ݐ*exG>~=t0GAw{g٬sG2BY܊#fYy!HMڵooP OgKTl{0@~V.>*<[}P { voUqh,[%x8TU'ķ=n:Ţ!>Q &lS#Lri|?%.bnus )KB *HtVV9N@4mT[v3SdKlD&  RuCH) JjoИ-  O8` g!tTZ/S Wu}Ny.6b:UPǡ͚fJem[S(ӥ {ˎ[?fq^XOG -qy:k4d($8m~?>R(|O̰Nϕԛ6aj) ȵ4o{?xI:w7t5db?&Qܝ֧25U[p9ъ(h3+H_2E(r Sg5I P76_2Z~1 X1K V*H@EYf(眻H%Hb%Ǿ`Ht`œ zbƸ3Kle@*^ǫ?yrŎ#3V<QpA X> c& sQޚ1G CL%b^HZX獅Wp럽~ѵl2*7umsݿ6cy_v2qMk1xe~$opİ9J刼1k5d F`;W ,a%'ZhJSwwRR z!!7J:irpwH8yZuO\V^Qv-RTDS…;#g׏9ȊƱ,qꎜlI 7n9!j)DahS[IiERxjM;jŔ4[1ZŅ.5}ҖƮmOaEZ֡Kwmzէh3|?&eHwR4KDsҼ7vP?^jKwES ̰ rB^IͦyiCx"RQ. PSmq?~ߘ L!SNrc4z1&@#]] -dG}BGv29.zރv!Za*5zA & ,;E^"2C$LQp^h2(vj*j:-+sčL]r֎t#MEfA1mf?49X=(xxkhĔݻژ {JM n?@RQ`ipq\ޝ+b ,, 3l8QQrB >X777X]ԶDɆ>$yqHƣ!D1Z"ɇcĈ" qEF# ?4k%CNo+4j.B yyC$CHZJMo`Ei2D>Qwgj mҳ];:O:Ufe7: pw]z-?U_:U! GvJ,ޘ<7(;w%߮^\PL)G}~&/dkZo^1hJE9bkCCVEwm׀z(l> Ԭ[_дb>F$^34P2Z+o=2HgaL bUXbp|MІ^HoӐV[`u.9OگENwC#]6nș>-m ua)!ʭoM*dm פI[bH4:@ O옂cX&|uL |OxLB%ܒ~( G/?yTD>CMzF″9ު0بMH#׬첌2o|I&?ݲv3.5_.ro By^U<;q6<2*Ymo:=?M[ DbJ^i_@>,C(xQ4Nq/NjtE$"%`j==RܽJ\K+E75ѳ**aAefuNx% 6.aGҳK8wy?6RtTϘpMtC*M 79Z፟޼xڦsTqFAF)ԯ*p⥦M%"fhk WX=>t!@%ɮ*_ÝVޅV`NXl5`簩X릔`Cc;7k[&"o/◴醩`4r_oBTv2>_[F!yƣ_nN*lѾݗϗ))?YKǵ!ѨvvPqHZ@kXF܇RQؼ/$>n QpWB?=fKFجA8 c(vE>H(4*b|ɹ,PNWL> ~ߤ9wM'Ubմe ^\{jKw{>̫lqI0ӡ] T JJ< S% ٥"KAV 5s@0J~st ۊ'f?3B@@٤-i3:As$W@_T?a _,'ӧ+Q !]:VuyNom  [wɗ95";.Tr\ؓZθ9pѳ9o:8IpPEoS S1:j}FD$~Z'D%zng)%&,B [,gXW&74v5:oşS\14ɕM:[>rRՌ`B@ L3.23R⪃x"F5<ߏ3D:-ƒ"z0%Ufг4N2՚J1kĹ8\BTnb+Puob).һԋ<vyEb>q-Gy_y/J!X7]AUhӖkXAvYRS8ϟ^ MR#z#.!iY~dT[6J&fMgE"ۀG ~GF\t;v=+LO>i^$f|`V(m Y09?ӵ c=L>Zk ˷Ov ,_2X K nG RƀnO>[+P]i (O}Qa1ISYG5FhOHXf5aFURE1>5M4!bpAXԬ* >s#&7HQ[`Y( Y'.U^9,{ɝѠ&j㷏IUZ*T*# P+zrγLF@X^dY^\@3KaS?tljnoW*]\6~ 9Z`,P_&nߟ|,wk#Z ̘J :D]g+MIg&ERb'ꛪFi%zHR<A?-xY24nO$F.byz oço oPv!ϮT/L#zM>D̸`l. Gp#}(yO'{)Z](Eg@щ]$NAq JPX a7`bzΒ '7 ]klM{o'Icwh/P9fmԎw\$(mHO \@hIgs7*s%QM&6emlEYJ9R؇&7"<<"8\וyi\0:;k/{=u},A2M$t1~:|.Cuy`6 3T߷Lya$42 q`pv>o:( L\~4CBcHyM yC̋V b=*C\.  61)n< F2ag3  3NP,Լg SSNS!ﮎ*ؕh@f̅KxQJ0}Td Rb`ñAB)W}]XdgvBأlObJ/w֤`.?mJK>ՉŋA4Mx-@;~{vӅ'. :HgEܭM&̧jݭD9<-29{|)aki >!CB c:%*a)$@(Ο3;=/K])Ui:̂xjnpÓy\an!F10#vӅ7֨D{臶DĘ;oE>\ΤJ(3-X]FLMoQ qwJ昚c`M37RV%1DMj bO`y1HKn غd۪G@dOaWdԜλ٪)sYwpL` rn-/ZjPvLf [b.(1WsC\oӍ @'Oyac==oi55Mn]" OuS .+^4c; )+ xہ(xGV6tQ>ъڄrdT3"BʓlLJȺk܂l==C{޲pEFBB.H/#ÕdG @4&8G})}n(!VՅj4ADVu&p $Ҿ9MC%.X"ls_QmJ'x#7l`^-O5_Fnh(]0Ly'JⅨ9-^Wp;\%byl+ Ic8iUuĶ@߰`rIكD''p-jZ!r邬tRKLe* KSDn`_,R=ȷz/9=ѷ26R6.h>~&?U#ivi_y8]Zjڀy *٘Ѵ>lIx' ';q5N-qan-)Γ c|iΆ'}W%ރCYNDm3tlؐ2?O)"z`a&PR]$(4\yOuQNT=%3JHʍVaE1^c\[B@ 3=9 0TVەT"'sa )iNAIyxaԑS*nzr]("_ .7l?uL$\9DeN(D7ovV.m\ k Vڜ_6q"(* w*3e"f9j4U"d ņHH*-#LZhRێ]636cG3tH p hZcWtՄ@Yv۟֒ЇҞq+&kzP([J2M/՛V$.PE9ެ2?!1Bn'\?w~]릍x(RwN4M8a4@ >=|o̬L&9+.&Cjqڈ?pXZLVoGDZq;)Mm]8=5dfq4qHu2~Nfxs.]8#!HУ,{=e76ӗL`䁫@*7+ȯ;`Bž0bIe* GYg_6q )j'aZb~; ̓Iڈ\WKQߙ6nol&[ݢșqJ@1 +ցek؝LfM m#"W&tVCvO2";Arrӥo~YEǞ8 +1=ds]co] ]ԟV@q`Z$"-\N}c\rm 28 ҩrE:0tuwlb:u򗏔^9#cZunь0| tUID$}])m7Ϝoh'[ A\]S2LD$,`".-u,rEᛈe LDfJ[; >+1q=uŐje_9)&&jЪ?)-c~aMW.] tB4s s:\%r^n !,Z`?s/~APHxV- ^e6m2GsLjmU&nozXt jxjxԟߏ(NQyBL*)'-=҉2LF'q=k3UBuJTFfAL6ZbsʃRZx#TK1@)Lg?SF}}}bq/DAvְXH4k<8'%H`XNƊ@j*3մ=$#BI?3^EW5.1i*,J W$ٗuZ` 0b)# <\߷e(-ȒU @;%b22J=u'M 3]"QkR_"z?<1I'j̦!bY~k:);3D0sAG6d6G|2Vi9^tZ}3eD<'Ȉ'(bHlY|. Ǻ>Ca_+ZM uo(h %MbṄ!j{\2`EB%GcB1"康fq% (P8"!w}俓 ܻč=.s}v< 7Lt0jLH4d+Sx @/4$ -52F_K)sB#n ^ס^*`sfߦ\#3?r*Ui;uzWj80zf$Ov"lNFJ7-&K7-y\=!P]s!)7L Έ!@Al$8 g0}G.Tf B7>z-%ш֕J2VDx*@[C*@hӾƐmyG|J乕ݝ(p:fԮz!!/uh>xV*5'dw*{@-V/c%6)h4MGHjVΓ{T\*ZY qI]n?f&A൳S$%$8(X~3d ٹ4xֻ{JQ Ka*\}7ʁTV&-G|QTxbs\4um76^|te =e$"MHiiPA-8lu_s:{*bI'؍!r>z4mVX5aGm!c?; 0ZPFICsP Af=MńQ*q+pO4>K<\Q z8y@ɩ޾IR+tDɒE]"KpAD{(^vj U0hRL7C3Kx)Lg34eq9pM|[= 1MKa"O2b0V@S͆|=Lʀ2\qvE:\n6+ \HR,(ڽ=sE[k! %d_FN+Ǔ~1~DO/sfRAA-T \|.xڂBN, *qOUƽ_"T̤2\:w4#tSR^q>qvcAvdʰRskҩ.p&Z1D6$rB-] _T1cx{7k㯛>S`xEs:ZQ8ȫaVtV|B ,5y@&.@D8sRw2~- R;sIhL&ݽLK]l,%2l")hh:—KNNn]tA]%}b;`(? 5< "UU,@ pŗGvon |gIL0~hזʂQ*^ݩ*6Sizk 1mS$f${,.g]PY$cY3~"\C5mжzǰ:kCҌD,a]:3(F#XUY.E B]zS/V8zTXР Lnaˡ0M?XpٔV>;EtFTvs9°M-p+TC5zno)xkQ'Xzuj#K~o¬(X{+w-G|BڨHQfm-J S ãqH\ ?[Ԧ Sͫ9\F74Z|q?  tpXI;M`|!F90UiO#<+xmۛ473A!_qU*'f6E8+!/K`bk!ַFz@2z=TK7C `TubUvb3bX[[GF7V,hw }c|wC4 X@t_贕ۖealGrJs!YOJ!0+p*IȜS&`{ѵ}'o))&8o}?mt}aPNH(.w0y;ÉpY3𳩔7dFERr.mWfGRI]6Ǹ@ƌv[k1fvri;܏YOne3u9>Z`#רQyRxOh^q“R T L(Ϭ^׀m o% wD٠6)6~ Щ (xrʋS2Ծ|9 A޲5%}ZᷜCL+ C6k CoTx0Y}PKy׃y_J+ :{ qX0z$-ׅI6S%gQzcsRGq ·A{;^-`<3J;:qX͘&Mlj{q?FwXMA% 5-9v;lW_7jq}r 'VuɘR(?!hN._=aЏO\q^JB+ w?s&dR8+a &3H hSQAH S0e¿τJǒ >GHAY8.lB} ̮Er٥/Tc^iRҚS++ xt2qhZZP.Mp@mI4 x=m^6xPY u_.:_ Hsȁ::CUZMϵ UݔK[nePp?lʉ@54Ji)I$%Cp 3Bۅ=z 4`u٠HTkg#DH>b:Pqh@s! !z(MY(@^^ÁZ\3^F-$=9K# :Ma C`%#a#LMwW7A]le`4旗8DtP{uZFdWV (=̯E~]˝<O8!_kv4K'EӒ(?(vd.2&x**+ 6JP2%[6$WXN|_MNa~PcWiiPMa\~ݡpe~B}2*5Ty.K:Cdm;&05$[ ~l%M h&:HY9,<D~ĬލE+T׌Rm] ;چ ;s`ښlD*9; m4gT1y*b ٨=bn`gf]f&Jvs׹z%>qc1so"?]B^;FZb/ejquPb'kM4tؿ-'(;_c~\*ВZvK#}fcE;<_oc/4)vۡsŶ 3+=[m`)AO8rW+kn9jS\hWSb&:l{\bsqw-iqf ?Aĺ^8k(ָ4EZ=~_@Q~t(6:c:Ea/)tf 뒱dW$f㳹068u$"N9Z\1acdԃUF@{?"ldGm 俔< 9.60}iGztOƜr6)fQ>/DaΪNA$hzUa#do`ɧBE.<x:4:@~|:РR&v }Gl$ꚂsT׊*bf*p>(`#l 34Ax_hdTC" I' y1`٪]rT4,=YŰ~ w}b 8!Kc·Z>9<{ ,(s^ 2;?1[?)BŸyFynmaȞV ;cX߈h@ ܮNiSⴽ"X~+ ޓ219u^퍉v(gEdziu`o\[Ƌ("UH 9k%W*pC=`C7|7 i앺qHh㐢)e.瞎#0 8?Tо+0" ;5XTSR0nԯYRHs ;Y6/2مZz* ı{F'W\+/mivd 3 ix}Nᒵq!p׈y/)<[96dhHӾ'!qIs0=D (g1 nXZ%Nٚх,t|ZIj"~ؚ/[Tt$T/2L'z{&ہN4w rJ*%utwMMO i:2w(Y{p<3kbLU;msb6m?#D| x!5dWW[ǰp7Ρ2~ 2dD1K, 8KNfC~Yl GhM?MaDf :T5ycDu[s{^ϊ>KuԂ۳|H;`N `Kv #2|0.8 ,sR O~ff9zv ;W%QM>i˹-S !?-wof[a2;ke7pkqoh\" Iwz uY [JX3 lm/c^BNbo&L]JdEcCR7E8T*#jO5!9 >aLg1A,WYCzRC<Ԅ@a}[ X`믠d4V#?Ct߼ANdQd0<'\FWMp{JF=)GG+%XL,XЮA€7Gt+hS{OFr8e3dCIM y rru6XBvKЧ;ڬohTPWv@#@9o :!ƌPd38/*Iهʀ,x#mƭ/\ƿaț&U@a4TQ-FHtL3p4+"R#Qh j?()6Oq]>7mipwi}ƜN"?L4+ߪMBZOBIؙsk|Ƈ%X"[̻$|"%`K_ W N@@" crMs9q\}u@Jz6uawcFJտ E{(|٥XB u9ioֿ`Wn{PJ ~%O=i1R* 8hjmb$i23#!U~4FIdzQ8OLMDS_: Z9DۺI?0WO g,^Pzbǥ\;p0Lu)i6Xd{`!IHtD!,Jj;?'Iw1M{ް3|d(t "i GY s^  ̌Z5qzQRuNp1?nVa @t"#8dϖgk7 vڪ{ˎT"HpW~ށ\phkyUQ`5PTGS5t (b|l؂-XSըR4qO؝"X`A5R H. >i ad»*a?(N!I/JR-9iB'\_il7XȓyvNιEm̘=C +8i噀 >qO(#>Ln%ʟ'F@[!KsEMr1lXF}i PiGcy_!-ѿE8TuYGG@&YK*#!۰ l3 P8I%0 ̍l Yh=ϚLo삫Q\{:_wbAw.&h {8$+h/xL@uǒNrkj]F?tR ;@xm,V?DఫO@'vaIO: rEZ&Ze3]x|EpȣrGtIw7 [Y(QEĜWZ1urS4d7?_uqBh|S嗊S/{H,j}?aw+ӀtoZ٧53y=4-$Te[Z۬Q_2DX+#ax`hGx@<./nY n*i[Td 0:Rhp*M{dXPkk~tI!xD߸uSYgd^QYs躝-]kQ"!@ ' Ň#}%vy2`/i(PDSoהe(.>, gl-K ,GFl{Db}Z5.gFqlrt?qjx6BeԉuFqt``V[V/ J[м͜| Xе,?/(VC)0"f|H3_,G؂[es GgH\ L%^,([`ߩu]jQUv/cTay1]TAܱ <-Hk2T ~/U@iD.~b(ϩ'Mkim˒|`P,NG[UXQ|jn)ꆎ$h׉Hq#X -qI96qc ؏0W-g,tcg840Fdj nf-1L5`lw558q+|F /8+q֎DD;3 Z΃`P2;7fO'^LPr':U>)& W.TU JqTz|64<[鯢R)i6lC!N_\p2ۀ.UWyhajt fqiqп1I-I6:&ooNE6rMFV͎%_3DxXIzAJr4 ttX2KIl׽3)52k=t[DrzXg=iQkF1u _$F@sMGO*W޸ج#~C{ vB<$Dt6XԠ>fQGMnڏ$k(`T" g) oy*k3c,L H`bYgRXo$xVVrf &r5}Ak11yCnJ HHr.K?|XtV$gDJato(yid)M$?4&"4ʣmx]UFFRZ <%̻q ަSAap(Xj !JŃN[$R*RNkH0񔎤{/l ;8ŵ[m9l T7cmҌ@9~:mOnzԁl(-Gk9T {zBۜ7VsK~%P67<'@<HrzB("BQyV*Q_+æp 2B!8 T/&d,Q8;{afo{̶pV`8’.x !bvY8?/n'|&gO SL5lK4޾Z# RDD=4~k^L[iN3<2iYC{'B|- tjA˖]- sFPSMðƉK1Ֆcf?`W]:(cCt:?њ_j3cݚp%4KZVDtGq-vMBAr2ieP%i P\kxOրxFJipWK,6)괁6m E/\E ΧmZ ;%gSB7dF4(n|lˀdFf!4D!_n#4:nkgτj=ä[u%U\-ºVDKs(JS+) GC#ACgǮGp03?s:/?O2B#6A- /k,.ƚ7Iԟ<~#KzEGJ<+/Ed Ċ^(m"Y6G"pDAmgF?$&Ŵb3_T-`3iI͂%m'T1o׻~~f5n0n'߃˹Fʐo{2Y8aL1CO8x͒zXouIÒoFGB?et84")]Ze xafbC3A`=! JԐ[/ ~KYV4,Uz se0*7gU/;p=1(0~">gmt*F﮹F]vFM/k~LH}4 =y0; aP:& ^4 ?Uk+h*:g9{N K!Fbiq\/Eσ kDYGٸVW.6~qi{104&e)]TSVsw|jz 5ˡr|sJM?2155ҝ$ F}7oy֠s 7 [0i!gF̌ Yn436~ϜǀkX`;*~Ρ)P܏> 2]XNB2bAu ˤg"mWK`-s5[ToDu6m(r6a|=qbAp*wG>#;UP'dQn)Kf7b~cOzK&H|@Iúe=7J.)o1]YIrFh6im6@rӹ_Bl3#{}%al`Fr* (>mSI90<3篅IWxSg22mB %tF.8`r/b;'z?T3_16 wiog5q`yƔ/R lnURF+1R1dL7Y6sdx&Pqt>Qr"6R3md`T'}Sbf.J>PF, /6.o_?`d$9a\*rfrk]TsoALarG4N64*9OS@CBe͍9Ⱥ/b<0 ߗFvdYg)%}~b]d2 +us:@pҖ<`0֞&6&2I4[J֚i'tӭWzgܷ9DP/Crf8Ysr-2hjh{^NA1aIS_SmCS}1vԄ36:QP.^cފEb.;U&5 ?0aֹܻ{D9 >l@Q)S:5Ƣ4݂Ĩ8[h;헏|+! ô.[ ({FtOD<6 ;5@WFf\:Y|EvYz-SE9]#?u^9$3ih^ѭj5*|:-`qVvYRz:eM_(} [R;*k^r% o>efq!)-AST?afԸN'W ٢,іkaoXgT&/y?cԥY|DNJmέԓn㇎]XSwT50Rhb( xM66MSFcA=Ec(!:eHH_h;Ub;eb#= \ߓȭnofĄu?KlL^XiUe])G̐:Ș` =k~{a&.dozh 5P]GfNF/i8}?v2sENn6JKJHǨKRLzqg)Koq% Z5 )dɣufz͍m ̍bV=3}tƢk .tt ȲN|>3w{c!%D_$ ,REm_XQj_~ޚD\ cx*5%ԕUb;j=au!?AkHW]!nB8c+qLp뗳N|Ryľo5W)ezKg q7%Bԅ[Iʄz){ê9q\.e}IkzcE@eL6kЫ9.mS,i@nFsG Pf:iy=BO?ZHɾF1z Ď&bqZٕI߰@ d; scvtTxPͲ}^!Z&1nƌ]7C>3;WWiܡ^reԮ L?# ֖64E7RU7X:BlcDGx6 *N?nSAWT,S/؋U4cZq#Txw,16$$"^YbPE}(E4t;k0[]>tu{&jC?.hPL+tbL u4P||oV ~9}u9р9ȓ])0e1s'[KNaZfGoт}Q98W$\Yh 7M_L^ABcͥc1ڑ"Yc{ܹ#7G @Z}]`3{2RAD4jD9lMfWZ Q a~+g.Yp>?Lq SĐ,\lrJ/pEC9 R,I}Oe3K_wIR w],q d/D>_r. މO,( 8.e7UX k9˖Il3z&!9>CC6lFY(꡴e,3='2pwQC̸T2ް{ fJ N(S,njR?p>%#`l~PN 0fTX`i5r(Ojr@cw,~r|)K\Lȗ Ys`FUTYsz[c]y,M@o<(F p&5LY>"gީ"(WM 66+mXX_beT0uЖ1Qƀ0@.a&7$ќ:JMS$=g!rmV=NDaTK!cSoC ϭsf]CT9F40*:-WOR딽 Z e5k~Hhy[_BNvQbL kf].]#{QśX[G @Fų\<({@D&FGK! ZxC{ɔlI0(l佁 Iَ=ő|S'n%o!QƦa= }t A@?ט/׽msjpʼnuk!D'6WH%FZ߄&_]Ii iofF˦)I59 FVk4IsY iM u̚܆Pn˩L!KHay ywA@ܽA. z6XUp@_53Z ~my8߬c vztsZxZ?V _#*28`p$t!>D*'x pϡwh(M{"r(k6%޵/(ܡ;48mܨUF~j>}Fe;a J Y\(>^~9o$5 9LQRKq; fE!p )9r"Ks3eH=@̛lDC^jh_cKEbE;6BF&n5jwd&y*A [Q$.F&,8F,w`8ĝs&^:R"G9. ݫڳU"Qu2dÎJZW6 0c׀y[dvF!UR@ yx^SZ/\)SIlt:|lzq!@Qٛvx7b})0J{D2sitpfT1Pjp7Z?Ϝpʅ۱etނbY@<`2 N}`H:^ђSr- $pl`e9Fۻ24ΡP_z'Gjo>V@}톼 5Vƨ" $~xm roaJA.pHO;49C2i+_=#?y!,7T쉏{v=elΓ˒OCrU4҉?(F[F%89ttC/-͔#H3F').Zl `0l3!; QlO9`s[دǁj `vr_.S7[aάbD/ %J;L5"$!mW3BZ8q#۞_JB_)2Zȧ,L]ARk\'ҭ- Y[l`Xuhˮ5]n.6$ Ghv>b @j\-DBZd[؈B YY2Sl\C휘څke]BD2uk&TW9yFu>{gXG+X^,lj|_0V<ˆL}0=B]!o(a Cu5nث(أHb`u칹afn Y7BTpR qT{s*3)7R<r#)>$ۋ q+4n= IfTL]po0!@ u6{iõh9aBDu$7U.<,n޻(X[ MP=nLJhef 5.J8pHA|UԇLR|"({p'۾Ǿ ݙzn=#Wbƺ>a+~K ^*Ns[j_!*x^X-K^k<4%5$$\͆Y .CE (}},7Nh@p8њ\ #,9=;żaӮp(;|G\UhU4B bmՐ1 $S&Z>,0 4A-V#y5(L55ᨰq"p-_2,W<]. tjMڪx zLkO &Ws]D ueC+Vu<ԱcqlAx@؊^3g(7ƕJǀ?&rM }GBA$1gJ/zWs͖s=SCa&ns߽lw=;}1!`931- ި)|Z*<[ 0vn0W yO` JGy$b:ͻ+ܵWNO|F>ȐL6rQG{ʟ& QfEx|k}tg9I9vb^[}.H /k=6x| @,҃(JK.4G+ݡ7t5s &FC|8mH>5 D=JEacX[rh-6^Ujh1ؚT^q8T捙86gjΔڽ^N䦷)w6mw=|@(^ ?7ѿֲ H0(M߁Gۍ|1Pfڞ@ƟX,>~&">)T 61^4'j]Ń)/ЦPH`dKYc3sWoHS﨑&n=<5ӏ_m2#g7cNDOHR*y4٠D}>\v\L~Vvԟl&-R'l>c!钖2b.V++D̉S o_C~O%A|i<:斠ؐ`w YeTI?FYG?ġ>wZ1T7U'lreC!Rl1tٶ>)~h_(5UF=@m` *6B KGO4k[ǭ58j2b{(zB!Z>l~|[+'_ɽ; uDAڮ_zc~ 7뫖o3{ѱZ:p 60oۚP8-T"V=iP*!nIy2m#fmm5lNH^sI,[9F6fݠ PmY17h;J)eSO_pC@Jt:b%W9$pKt036 R!A{H-oA8֥s*3Q 'xFZ=ȁ Ql^XX=u=ǵ\T_+ΫAy^h?/yDcyVQ̉Fk԰J׾85捜 b'*)^kF$^ 3^x(:fR-sx<x3Sh?=t. 4뢅7`ƻ:X0Krg8AK f a/4KN bq&gDN0S/ -~-?7 ,yܘN7aO$v>?m{WB$BJ!l_}>'榈_$qN`PBK?1yò8M.\5* qk'6\a7USe:8KЦ7oAt+d 4cJXNN`ϩjj_-p0qgs!mggbKq[8 &|B;mZfUz|(j N(nw!p\2+V1UL{9y `ft6RTu,8uf+S?idA t†еZt}TC<ˎg2{ԍזs9!.1!waE .25%;V9U*)%j=B{`edynldZh-V4`V66ZJW"H`B?#S|#07_)ūQ|? 5y2h7dh52(-ِXi &@sSr[}Dz-/.CT>VQƜ 'ld5f'pn⢿L%OwAy+`gr I*Z`Fi99 :TZz7ϓr_G}b+|^0\鍢Gl", e[77Wι MS4ta/1D~X N`b~YeJ^@F`6s1N8c|=;ݝ':}:K:Mlq ARH) paei|9-z&3e织.s!“x]`!nunUugѦ׾>ܟ~(u*"x)'c8PݏW:KA ]i%nɘ37}n-3pDZ\_SVaDI`6I)/Rlv.3zS v,m7x?)c@Z9qz:R;!0"i̻yX*ȋ~fu? gmT«Ң`+}/Hq-ki+P#T-QLIxZ @ J@`i8S-tD4.g3fڰ@O5{g^+mBYueQYl,c슶Y87jnHk \qh} C;DomE M>;\"| 60dAlTBz5E nі1YIDVPc!6,Jpf'rcglp(]%&ſ1bqRHǹGRгm h~oV~RkIu9;F{#N 6fLBHj EQ=bX.x*o;2ݟ=ඨ:vw6GKHCđ1ET($lKۀc%4|Y&~]92gJ[fA9icνoYW!\ތ6{(5: .ga/%/1,P$ť= ੆㝚 h'֜wJy 搞:ݫ*X7 ' ς߈Xgvt5rifw)zk)3DXF r{L儲}UFM~n\ N0^NrVΖ|d~Vy9)=v$Rw+nW %N@x)z;~K9F>:RDw$}NB2񴜄 nRSd >1J'߃r۶dCw bIyЪ_TAurϥ[)9dBkQ5_+6;ZLJ&-bPB+l1 G b"Yꓤ\oHq:ϫ4>TgW*o4_x[#.$7Ѵ28 .Bv6l9b% ju`ێ*'B;>|X/EPRYMGx-{8}N qkx RŊW^Yr|Xam.iRx".1'Xwpj7~o%׎6Bx~;`!7(:n$[3ЍF@BP""}#H{"5j=2_ɑdK+!m@U;)cfR?me־;X}^'"3(iY-J2@&rXU5hV D@H4Ve"T}4U8(:f3h}rz5h$tWn7rT Nٖkd,,~-#wfl[YfS-^<̦b@uII2a@?N HM%Ʈ<; RFSAN#7J,l :FԔ q#wstz./Fw*3!cO*42NFgk󂲧i/D4Z+/- = )j`4aB̵3#]26=oIB'j9hQ (]":3O١=qk>{-y3Ċ-BwiuĥZїz5aGM>2KE^V:3+#u/.YN%]"ZcaqiQPo:=*U g(ZųaC7b7M5\ظ ~V&W&]):ċiBװrI;ɛҨ 1^zxxLn6AxNTi!05!zfWݪ4llқEuN5?lU&`*CRa$YDn%>O@{Ą@r-JlҘ>:L܉m[zMM@T)[i%Z#6/] m BRqܛ3p9l`Uk$Tӂ.Ӹзlo"wZ 9\|¡lR#HO {VZv|OȜy>Јn!w-vU Կk`sny0OQqsϫz V(A .]&i%=n*dB2S>o+|zxZI03FUkJf4R[[gя(a^?[1LW:'$ 7+ \ˊ?懺B׵ޫ§$1*ȩ""3{RfbZte^ޫfCZTp"$hx(}'R{U@/c3B"l?5a|QR8o*j}cZ\.>Y1dE$U]F`̛ɝ#Țwu6}0Nw1%|PIi-/7HUܡs(a9^$ }b p;?t.B Ϭ="ęwx]Λ jf:VedE--jݶ7/ƬAz/sh!' B9sC.44mC!VZsЎyH(y3v "[ꐥeO-F9B>w{EՀtLD(|K0O.l/Sʔ5f.}@|:٘>xH'Y9ȩvꏮlhWoHsXƯ˱N/ط6B,1rG>Sm&^87P!CߨՒ5o?5HY%CZ/w"h"[RTe8Q2|Ipy4v׳$2$^m3Ǥg3^ڜ[yyyК6xc`R:u 3gYbe\Mn@gF~6Ӹjjo4y]\b3;(R4]%ߍMa+pE)k }ͤaU1ۋ(Ih"/`LIi=DŽu1_n0 n|0/&)jy `l Ng"ws,V8W TZq|G ;=,:+,$ݴJ=-_T"=PB J4Gcaup!Y_4[ КT:<$ÏqPf͝{WJ`mKNP# ͜lorgg- CF;aϳ϶ߌhK-Iefwspa,{=BH2J}rjW 0ӼQ-R,s82ٴyQ?hL)MݪE:u #PsZ2c1.*% ,F(7 h_F1/z:gjg:mN)nYon&82DrP 1]i\o~R ϻ-hba)ބԏrtJm/hގ}j3On|͹eTf& emoLӳe|q){'0̧57)@tI7 Uy7P )vZsF[ jfX2}k?)N#;SmCYpzU+_ Tׁ2\lעLjai~蒁('6t۔$/ ЁL vT.@ٗe;M3腧Gzt֣']ׄG:v&Ň}8%98 J;Tp-&YRDCS&>hx/+Ƕɤi ]Z9V X MkVK W2!e핚` nrM`AB ^g%<5I4OԁTCgJMwR= pA6HdkQӤE9Y N t1`rǍί˯hEdkQ G\*h|^8@ [%~W;Z -JƄCY.}>*H"Qg y7bsc[bqz:W]FpbXCye%zFW,ZzH\g ?F_%w@^nJ20[Ϲ\qٻ'@Y ,1ƨÑ?(1{:T 9]::Dßp^ju~84"p.R:"&ư 7;ķݙ\y|A . εpB޶ǞuvfbO6xoC/K]eE̾긊Ka)㛶 Ynw,]T{("Pax|p`L>+wR>"IX&WNJ޳\Rqw\?!.e[o9zgdZVjg8~²,&ʿoV8* !,SkG$֪n{d(:씰;}XWYꏬ5O bxs4 -ctKo> 8J,.Cnm* ZcjcWD8Ʋ|f*!11!W4P&*mRxp f̦~" p$2ăq>-a]Оq-aQqmftr#],V-"^ilWoN6SMb2Z]{A醾T%g}Ӱï°ݘ}fX]%#Έh?3͏gٻYyTsN'_̊Q| T&:y󝍥0Wx]f-I-{30ߢ}|Y٥B\Z^?AV<0<;ظ+Z fB0D@5!o*YO+!O eǁ3)PBG'S0U(WPᦁ,6ѡGEo^`<)\M>+Llyz`Gka +0T1_h&iRKh1 YN#΢`&v,Q^-֋)aj"ҝ*^8BukGvZkAl2). ̀90D|I?D.hבž51f}ReI?̴Ѽtzjb,hZ\> XVw(uvx' j%m$z36O5.*hi=gƁnṋ߮A7ЃH@i= ϊq _uo6J:]w8. Z{|enU[|gt<2"elxu7Xa +eLY>K15L%sL"^r4J{@3Ռx@ H+z; ܷ||_őmݞ qf9}M~wGr_`wZJBӵv{l'և*tށ}]Lw?t񶞍 nIYjFm=~,|gNѮ6RˮNiSbo+h#{.bc,1pFliN, -hM2#H + ^o,.X:(uNٹ0c3HEYnd nluܘizGQS&ʞ 8^X&[DmrQ /18 ntVjQl2,?@5[J/6w Օe=_0epՐŬ)tƤt= f52"el8z05.1EgU 'OoL9k}jH3iR:~grk @Ysxh=',@5 =ROHȩ]Ab֠`p"c0@bw[޹>Ax- bo m։t#^%(=,aW֡҂;ky 4 y=vy1-DbcԛEHxCfB,DCi~㛩|[f3l|bf05Dn9\@k}MV۬&6Li+SUs7Xgwnp@jfkuCz[mAIضXϣ]?ڪN:WDز/.'(/GO8:P*GMPO~tm O혞8˵^ 4:qu;#\\ˠ#W]HK;3_Oj6{9-kO\3Zl` 7U]& H f*G3ΞyOupP4Tɽ7ML|4oM<+3{V T"aVpBYb'=\]9 K7#~A?Qc?W@/8/r?@j5p5J !j"k|s#yL9KUN;TWo6ü]16@tnh.0z66n[j∰xV p 8kdSo&sc[MWp~/ u!JAM.Au3Io Q]pjc8HgHƂd50,[xק9i{nmj.bG#3Ҵ(XYN |`^Ŭ4ԟ_/yHe/+J ½k.]C{*GU{.?)_ZǷ D6t @2T9G _R98 SZھ^kf:ui&s%_^c4JQ7uz>IXhED66 >M| 뇮c&#V◟)C,=89!9l,djt LM1a%e]2V$LHGDud]zN$n2#*|~5CD`ĻIT+vL! IնV4 w֎1* ŪlmٲCJ'~&V$2QlkUц&!{HG CrtBf9-U!!p"9y=Bp탒Њ/fgLl LIқJ]Aa{ϑ7|Le~& Jȹt N=,L4 zLjs BzuK%`T)|u=:}aaJZJP ]/LxzjhMpu3 f3;;B$ܘ)+T' 9DDԭx=A#1es 5-br O EMNsTa+kh&ؒG@եsk8p$L"z=OCqK2Ax?Th6lnwk/ŵz֯pMMi!ᖛՔ(9XkTS! 0|K@sRD<p|SD`O<^ 18%*/vI:F;91inH{Z{tb"0KlkۣuTA$I)N=HUgeyYpNStF+U,( t>ъMkUH:IU׿ȖxJyĺqEsDB)ܟi׏Y]5_ᣖ-c'}h|zMG3_m{0<0;Z>PԓhVڛ͘$㨎*\{Dk>j׷~$жACY3'YTCOg(f^F5-GM}ϗPbc?R5z=V'8e*V֖6у_$#sK/'*=q4=+MԪVDd+0\a6,:yWFt3BWl-r簆R 6)yAuVxBJeIi7'j(MA~ܧwB=/ӱf1'%d猯0B[iDKfv/ؚV}mvEw݀u3w`/\vl0}{g+9 حI䂡m"ԍ\5p*XfWN^<)mU,ǩ06މ>`B{MNJ9oL ^n4_@ і7!xo0V+YiP#N6FǷ?2Ԙ[_Nޫ7޵Jfuf$1ͽ$. -Ni8onY&JH_cԎ,D[B x8&C%8u<^hqeen=q ^JI?V=Elo Sca:&'j8FTԥpQ;wBXg,od :ffRRdmKC;跿+]oLJYp(~n6@NBߓtc $29w!?dz^#VE_ ZQ!GMZXrd;Ci:?:9'T%5 d}sl/jg[Ty@hR Yhڰ*r`.Si Z6(Ⱦ/xkjU$[!]/$0 ‘__ TVq9%]:4ӿ ,YУkbGْ$+Xl6RDP^)q y ݴ۲6A n]@zԾi!>]'8$t4xc^wo4E|h0f|B~ xXѫKCu%6;5tYĤZ4v&3rW&&2PK3b3aS6{B8%wECֲr?'d Në} &$LZQnuC 6_VqBqL* @9Ū[Y}OY??d:Gu\m'RQl y.[[;KvM.,_Iḓ򾪡VJ*0u' 7Kr[ Nl/5;33w)|^hXG&_ d/fD$3$AyΙ`ߋ~5<薌짹f`G*BKBY\+SN3i;ezIhei&y;/Ŝ(PK62nZZ'!6abszWA=N~ش*&C5Dsdh.>UPÇi0KȤkI:6)T MpH2U4]{"L^`p(N}*9u5OMp; 3Ƴ+XE)xR&6m7!Ou C qkq7٦yՔg!39Q1V#]1ըߕ8&*Йj(iă߲3U%\^YZS%n~$oHIgV]}}g :-;=ի{hؑJJ83qpT1J0(e*}w~/x[+(V<' Q=dxK'N@ w)kJwΦ2?" ,<;^_ (MF#! k>{'I>%1  WLT貶`+?M5oJ*{'{މۉ#1N_7Y"V:3g10կ MxsUr&s/k O]QRyh!G ~APAKٱ@2Iں!ye P {f- r2- ګJ@oU& %(=@KbwKcK X]OOsm)/0 k X+KR9W-& o[E'ئ1'!V]QĠެ !>Q01<Q- +0%va5jCz%gScg0_z7楐֏= l6 h ~TKHEҬ-C>@M+*:6x%iƮ9Yi ߋ/\_E*t`t:4T`?ü-:('aHduwEjS͢~S\t3YK9PTvz 9q1ۀ;LLRi1_$'WKp*Kz?o"U_Ù(0j4èH˂ǶeI8u9?1{h5ly>-eo1/OkMhy2tPuҢjhKBZ(Un"]@ۜ{UuG֑ԗgN<V"5Tqix1T=#10inF5S̞08vPOFnqB0/#V xQY!ˌC;^@Rxs{XC.9Y sRL ,]i;A?{.fYb'ޜ9>/8R\ɍi58VܶgyHaxWsd-YрmA{^xzɝgjeŘXL=ېۚmTɕi[BF Kbv•%vhYl(+ mXE:Zuڴӟ%5T83vRӬ{z@.*Z1/|JPTEPަ %¨G2X2;SI=!u}ݶ"kͤGV?½qv'   `vg.`2"w~?=bv>]K a KS\Yvt8[|qlO~5p/x^6 aF178x5IXd측?qDMԆ%0]K7QH0)"\FxE4I? {r>'I Vui>*NLS䓇\o|Q`Ғ EJ;{&Dp, $&ťU7IJ [r`5 FJM}\=2haSڒdЯXj|SH8Y;G'S;̃nqOtI9Vq,_Љ-Nvw;xyч|מ:O*nnTu>]JyԗK/PDq<2^T]5b8EΚqEtiVؠ3+&$W1&>xVwB?ִ:JT'/tjNF@I?o"Zf[Udd0VZOyqIRi06v_xG6HUrn+RWJٟ6}uenEJ̱*akDplh,M}`l,l(G9pѻv978Ҟ >.)ؐUiƭM.ߺS "&M} 1a'8$ GOrYx.0"m+sG3V/x:.D IRsL<[sa_h:R0B_0>'ѧΉsZjlד㺽ỷeӻsS[쑼l ŎU+.`4dFxx y]w1i-/aj5EUab妜4q&aitY'_lN FE擀X!4HQ-3j.\8!Ԁڅ${ $hkƨo~h{BW]KeFt9jm} \>tcu~Vd|6pbP\}';,ym (LZ|Zlxo޻+Hj11c1hj lN"O t!CzԤcYHw~*7y^cFD[n"S젻"zOCiH qT?̢@˾\{ܺ~1g~/T:]@pmlاl2$d~"UjFZ?>ѹg *V7iy 'gFKr$ߓ [Z d1/< g v|iUp)4VM&"حO |tx# mH&҅ϑpA>uCX^2bbCZR{} tr#5Ieɾi-i51 Es?AO {"9pbт MOMWeމϽŽ|rCųk66:4Vg)]%%QZEBz  GtYÇ׮5T;ҥGqsUٽ-'}:ddHyWmdDf(Fw̑#]@TOHMdp@9f tʶv磄\ćԍ3ϒ*tJY{$jm\&МT.^R_dS"@1 yn.3[0˦-]"ZfٲCց-[7vbjZwBxR0,>1O@.Y8ɜ+BPJ6JK5bx"_ݾfWt9l,u]ww+5An@f2rA$v>Rӟ+^Y7޽ - ,Q ט\|1xL\$AA{Hxtׁ6lwۂڜMQvQto> a J\[om歘H̓@BtEۜb=#_aZ&}]i?ռg3奥&_|p1CTdbqgXA/x(<$C^wi f&TĒpX6ee?𫮻+0c5n;=yw,e{+&t@Ą''𨴏KDeE:/(wVEyAm#%| w|ij` zIv%ɡO-#}ގw;25B^p7x K&DUa؆pFA@Yh8Q׸R)$q,MdblLw+aq$1͞Uqߦ4څnn.50"nbn苞od/ꕎP&TNtֈIԊ]oCM"߫ U1=k (3ޥ7M扞O!OuxSU6&k7&Dt3uҢu,.2EqBN/;rM\"Vnw=ƛU uY6- 7ENمh{Pc+ UѴ5.DGe3dwԊtRwdm@J?oln,ݹamc5K`v],D.,Lv|}L^):7*7oh~$pi5$?c&_?EWLi-T^z1?U/Jᲈ|;+D(!l0Bv}nM֤! B'!WuN]=TGwKW9ZB$7 .`^y03~$~J]{#cPBN~ڒ/[‡ȔHZ}/ a9Ӣ ?È=--3z #@!IJԛ^2V_ $yyxqKw&),*a? dk/ޖЧ&=Da&]h!/{BrV#5f4|'ɹI8*T,kq#D([6KԼFM!gY`q2@`Ʈo#"ah [;MerrV yY(keńK~tPY<ц`ɰD^Z anj-`m }( RkIhHz'"7H f RLݹKWU[t6 ;lgK%Yp?iP̎@+G+o 2ep xרÝN q%F2#1,xV: b2tBTi'wDb܈S]YDk.Dg an5-T >T9tmЛHq{[J&]<眑P:T˦P\qܘ[{G1 m\Z+,FUϯ_L@eԁ1Pk%:^c]-j<ёV .TW1: ݽWhrKm$"߈766J+V῭-|aJkXuͼ5 +tT @J)[ J~;d<5h3L6 8oa[@>ۼJz KMyoM_fʠݘZk(v2Yilp"pls0~&EhMVQP?.2pom57i2VO˨hq/{ʕI-иF:)]M5 CYx-_ɚU'TD>P[6'XLIWD? MOةda+ฎPF*MReZ] 1 T?*s={E5C` V$T6%o7-MX@!vI\65VI(ѪP']8F\=VV `ٛdy6aU5- tSmAZ3;;I'Kz]2q1݊hb`ȂGI 1)P qqMεL4'0,dny QrlvOݱ<#*H {ޓ%ڿ7k?LOT$,h0֗;KKdV+ʴiu1[Ilg .2utCv* 2{mڶ4ǰD>QشJ槸ƍ%p6z[V_睇rЎii6>!QK1cJro1 zRcKێbu>7{p `;o`/o^ ^-(vSB3oTO)=FDZ@3Ό5-/@L9[1 p*@WY/ս( !#g돖KI\䕄.*HN^`[aqtNWk?7%APdOZgܠLjSMi$(E>s"8Ebwř2!p&gib3)َZMx$b9&8ە!+GJPed"JJАlkFP!6(8'09Gm' ,s;FD%Yza"iv870=l#E=hRzjk@ߍftw9Wsk5$@;`ϒ tl+r߲c|`R`LT pK!fz jN'rۘ/=+8FlCbh ?eҜ0ouGd1Mwbgg6+LjdR7nnbuR]=Ԛ2ʂ-pCPO0* ,W dSb'RȚHZz#_TۏzAVHFĻiXQucxN6nNqtJ7h7'nh!m&qTO\K8k Ce2m8 #f VEpʼ v&1r&caV!Ĥs&KANuIEg515T 8{,BnFH i?WST7GsgʳWCIșӞ^s9 S1ĝȿ vɺͭ8#&12ld>3֎2d stpxm2I焭P`i"yJqд2GTTeZWOL'% Ku<Kps` lv͞!{g6vbdp_v&Iİ ez0ˍ%FXɘ7e6!ӽ3XA |l~dS]Эe*7nh鳜Z2o8#&):;VaπԌrPY(Q=4yĭi%R\B1e^ -@tz!$lk!XL8lG-fـ;>\?wEks w͜-rEf:o2Π,\墨Wt!N >%aVAO9 _ T'6Wg#SfL0(w,vcQyޢJ_(5x-VfmJG?䫭ߺ}UElZtWQ+T byܬ#ֆaq [u*|&'V`d3{ڇ|ꭄh:ih?E^/˼ =Z-z_"}Cr%PtTk40 cl^x#CA98\pWܸxM\QHuB";Ld. )E!ok#>[g]3zbxqL[6trM] eH8n|!%%kZw]ʂUr?♖vV@( 91;lXùlZ|"e7BcҗcUOXk#J صcw{U,H_*-R7}3 %,@|.0B!.Ʒ Ϛl $bd܍5IzyqT)3w-2zd#``,$<'ǰ=Br`sѳXUܳ@<^#z.SU14m`P? ލ<8D gYz AkXyg [GƫFAD9lXe%=jʿxף^. xl_DǃE!;E+ QUЈ .@+k}D{)t8{fOR{,kɆ˝z,^mE3aIE!QԐM`ֆ P\>eL@ZTq C$(J.MC!!;`Y4崥/TNX/%o@Eq) B մn>e}uy~r mK&G#`hD]V p7Mn5// &tHJga8 кPrgaE\Bi2K*X%q<eOȤ౫MǼ2"IBh8CrMkmq&nYWwlkY㺟I?>ɗ `+ý5_֯ŭrRwY~zìFKG skO:hkALJ^vLFd}^B9bCWq^H 6L.˽) H_"#a)@"ArX/vjk_{9)dЁw?#/adVͅC?YZ!j sNW$°G8YY*pҍ˜ԦO IMkIhWf\GoF^je[l~8eG;#F$n+Fz5WO̧ W R]ODB1Ҩ+šnut6u=--xS.L,qtz3uU>%t)9ZgRK* wshXa!atQ |@5ڞY:2nq}(gs/rC. tᛉ7Tw^UZ* <]|g4^@`@aE)<Q$k4lD!0$O:`+\'˺pv#$9G˴ ?ؕE -&I?3Gq xO1y= h͘K4ƌTFk׿25);#Ly޲P6N $a7Ul) ]v 97SPfH ȇ^23~j8p!ٕt 2VdV|AN!nS$tғIfi[Vt2aSWX'XW fhuNHj#+ _^} M3'k&cQh ]YlDA\nf\Rh]ߌ*ju FLBij]&wEi> ݒ[^NkD au3BVt`[h:'7[cP&#O.~ wԭ_YCFIB;ؼRw::u>78 QM!m8PGf5{t+J;br  !uφ/ HM: }NA#y}R;-DZoJꐞ072lUr;9wK ޑ=CR^zVbF`FPzmx$ 1o =P/请qPzIΫ*ɿ}С3$)Gy CDyPY]4lΓ*`-, ͚tS0 Z?X-W{=j{do_8!jV !z횑2 fI ^h \n:QKQCY6/iƤ0 _^R;簌2gjv&*9`>߀|tYWI <txY S}' 3jNyBr55CO]x}r[ #&9uBAqϿj*Kl ݮ '#ǣBH< JExò"DoV|F$v&4$Vle.ْ~]0z p5\][9|2ay )5Cf9 dR>~M@(KyXUlpKʥ3ˇ+_2J<:*4e?%< G+yG p|40`niv%FVvmdC\d2,HҌ]!a}Y{B;?=R3,b_J #;Vn wl4^9%FI'wGvk8hF:|԰:Ȭ6M-le1N`).ߞLyPpC!~-mLJQqwG3y]2U:N3lR8AڿeOJc_Բn \M*ɗ3`\ S+ :4pA'"sd\ bI/䅕 \BBF; L6cS%ak3 :8(_\(O9aG*2ZWă&z75; ,q?ϊ%>S$}jnUI0RDhpGƖ w/ިI_VCػ҃gMOuDzp~cIH1:% hUHX2ۅ -ذ(uDr8p0EeVG͓qS)Q!:`XikgPokk|!J COu?SiXFi0RFNNͅQU:~w~Zމg6ye"j6^A!yQPgjpƘDro8YRސ!o'lZfCOisTc4Q!t"! T r\H2ԣ[BrHV?ZSEBJca<26Cy%p4&^#saG'PLwy Ga$|wVzE?󚂗nD۸'r2" ?v-4nÖ'ɬ)6 BjM}b.*Ugɣ%s5W\<9ϚYl G,Q}9c9[z8߈mf:Jlчy8;גD)^Gj}ZL#zjٟ3}c:+w!i*yB޶"r!"rj !ڈo8;uHckr;8~lK]N*b/Ԁ8[m}5#) -fUAh+Y e7R\zF%+bQD :%" V~.zpNouS+u7ff@'x唆;>ҖtG' L19t1(&UJ2yc|T1w47%5(w"Ƥ=7T_z "?$1(_ -ȖzmBdm"8Ydz@ tLE7W>8s7i&IjYþmobat>@@f[F>'Xxw)^-قΤ  j t';;]aarɏsi $`^J gqXzuǮadn>BԴZSF]\\`T?z}vr+w`Efm2 +櫡-2ESj4{ -g;Ume ke6v>pj <U>KGb&g%?#ϒÃb ٚ$A('hJD&eMՐ9G xu g 5r/:뚇50 ;2Ӂgd0-`̝Kѳ['EPxB: E7a-km/R ć}zYК:ŪDZ4fɽ )ĬL$G2`  hR3o+=VzNpe7͏9oڐDq vfQwm>yh#bv|kgSo`(bQd]EN<]Zi(MІdQ^ߓ$ةL3S Gԭ0hl5q8gPBW䥂Q"\(.rvRXvߡg1Rv\0"S 7sԇjK\5Ts݅gU^'}xƪf|P{J.ƈiŠ_oٽtuP,Tb)+5X;z}"}${g; KpѹƮío@^k(:u+#u09D5eR~ajl"Hn^t ʷt04+9&è"4r&*PA^C67Mɖ@Z`}PCD)R3wLoӸ¶1}2Y@;WXD+^/ZHՌ>qQjPu82R_ok}ԕ7LUT/4ma'6W..Tax£u^)v]EJjd# ׈#3U3lRD!\q7`׏`wChM[oUXF7%B9A, xk"fD̰ޏ^<*#9pC3ϕo(j\ROQ:i.1noq %Xwd@!kW30XOiRc)1~LŐ2)Y4K S jYH ;cbH#1Q~j|񞶗l!l@|_,rԮxhg46ITF` DVA6n߰ٓ9)K84(# !!}jRshZ:1kRy.߮fI׳S1Fωsdp`6q#N_t U47X|t<8A! >HCJ|"enbYDcX"(Jn *m33oU="ب?M''sV-;c#SXB+p!/y`0$&xBoB9;huҝjQ[=d[l#2<ʠFti(~< q)t훍n"J{ԭB Q>cť9V. x/he2A%RQrR/h}XƖ77r'i߲!Z#;^.k퉗rk15 HqГfp/JnoQnzj,wՎ<0ׂit[Ut5p5.UPvZqt% ϕER 0P&3= cmFgND [iR/OD.$3.'8:tdƬ Ylp%reM.*ݿ=ԞFMGX^H ZT' g욢P{-Ę8+?S+xzy0ʮ\.wb!CHOw:F!QMQ]r.Ze+M a X9ܭ} Rwh$wbblD$%w4Uj q!;r4#4=ĉ>5&H*ljL):ABZZY{Dȡ}frᓗH E/ȦL4$EhXٳQTVoGgZ`?~ DsV0?R?*4-<'$iaVZHr+:QW b 0q_C}(.fEL83HWQD_}j -ߡPUi /ߦg{DZy = a ;ii]otUġw%]Vr>KwjmT<&:dg{3ke_Seb#Iuao05m—INR"ƥs w- 53:V T'?40}0L|/O=}'Wwe,xelVhPfr*@pG1k@0 Y[m1xŐde\"F- 譝rq`꬙>+a9{@1".;_pSŽr z5K(T ,kmh/vdaZkL9 SwTx50":TU zx ?Y {wkbL]M*qXOf`'xV/xOF4Ѵ/L^ǡ\v遁OpX XSFЍ]Ӳy7T8_(eFwJLjqG /vV"'m)ܥnd׳1Bgׇ;3cp.nJ371VI 4 I;KPәrRrdu/pg fX JA1ƇE9l>֔~:,5KS;LN=Nrk];577ArH᪥RcMX``,qTt2K UC`2NNM$+LkUwh@i_8G1p ~8FQMCSΕUyFu$ gVϛK1kNwKqpM-f(9`3+C2ܹƠE4c:Ԛ9̂ǖ&~owƢQi سs U_j#6%CEz[m|F &2g;9ᇺN~)}/ߩǤm(JJ.ixܓ?X-% oUoYLAmV`i dYN/ 7H Bk>4:jۓנPVeF;~Am-vE=uG\& h"V=*ꌮ$$AR)\Y"A@WݨB%w*u>^~vчh@;pT5cFxuZQ--U!sL#wz4ܔe/"}ɢ:+ItǩB{ǃN`"Ա,9)EФp7̈O[?/x: EJS 4.P׬hh@z_"ӺBM:&@v):^3 jAhQet6dr 0ju3571; hŇnjP[&+?\gӃw(w^[\W MNދJ2Y2g6:![̬\Zo,Pu/6ݜG_Yi;?&*SH ӷRVF84 ]uU Q>tNwy ;6XAHFLp5$D;(d]\vn 7^%Ί%qǹl~N4ڻ,Vqݧ K|Z6_\m I[O1Zۦu~ ^t*}շIoz=p{̆y]skɡAE1&( }a"/09')F2>tc\*8`6E)1ˡɉZlL$1&Iv6TX[F9݇ۅ˓$YYwQJ`ٳ-O.;#)oۀ1u}+,}h1Bjs3m4'1BЃ!8,"9 .St`z1tU|,"*5l&?,kϽQ}*b.Z.ƹڏSvcFji`7ޫ̤J\Fnj1Nxٴ}=sMlkm\;6o;3ԘKtuYľ3JS|nk~Q>$Zg0㺅2[!zK)8gEo]ۺgf/|Uaֈ"WGH<$Nq)[[0 J PY$ẗGrBX;P<!S2T3zrt.? .ڤ 'ݴ K0 ^Q7巪JSŎMϦ8k]fop HJhl 9z|8DwW+$:AR(-T.Ա;}Snw߿Y`Ͷ+%#(n5<0frQoO߁"S+ u#\6V#ۏ NGmAVPu_[z uQFj-9Q~m&1f3fA?aݱ-vp55u 3d EsdɿxwcDa2@4r!axZ-3)kbU]j ]åHs'3O&U9 (a CcR%v<"7E=v=Acw*Ѯ\î]BMu1s_Snw(vȹ@QhѬv/lkU/:PSnUlg!o$eAE`IrëEեnL[%BlY,枕ԛw,lPQ wSA}zP)lmqX{5î6h{B"5Gu\hSme)*m&B+ +jVhɚ< tp|}Ę\.ń4xoT&o9/Jc2!}GE1M;gfTޜFwFxaؿpte`d34 vWyKp2T\I*a:캵 >10ɻ9 !ϕ?N`iŀGTr}H|&t_KoT\.Ԃx@%bFiPK%Ko5(b?kL0B+n|IW6F90f ;y/9k 5P_>'9$uIS^څ|i [fvJTd!\Ns9BY_e* ~4TR;KFآ:C2a%W6]#D﹐ŸQeW#SѤggj%-8+jx$#f]}1?VBGEw+pWA#!%pxڕ7pb`}rKʻUpsEd͞mW׬x Udm(D4EF7WVuFeoPW/O>;/-J,oԴWHn-8+ uET1T[ٯ} z[+)# hD8; r U^ / '%]z_+H GBCRrYx1- 1w"3FdWpdr:1цyᄚi:^uh8~TV,l$wK'(̴aR3%6\ZĢm7<$ɟH t r1PכTY&t<൭ ZubO{R:֢+P^qv\6N ɶaxG؉ln{{L; sY6FVaeW׷*.0ܯ41Ȋ' n5M2!Z| Z?=/3K͕^jF$]fe΁^q?46q9 n >o晀LDzzz]l1&l!|&n~o25$pпRu'%B5񶠌ftn Aɵ^b̖<"10U7Tp.%;yic.y:"(URנx62 n{5Gqʋň+ejdw0S1B ?Ŝun,ą8{|פ Vb ƐJf&oR,wKgŠng1D[ ?B~3=7ߵ3=a;\C,\ab&=43] _0|WK`Wmb+sV`yjU0OH0DXCeVEv2~, >dAWY<2~`{beFcĦq}@\{$p1` L3Ǿ+eִ{ֈJܞ ш~G MZAUi@}_|2CB nƫ,-Q%߄@"Qst%+@9ǹ\$hpu͸{Pt*`mEkݥn!troQB!aI%e6yb z*cJ$8|ZU/"拇eEhN ~[<Cs =}Y1L6$}3s 'X#}y] .d4I.%iio&xYi0utwq7tz?o|7@ $%RBЛ'Xb=Pxf5)H=G~QTW Fͬ6WE8;Aɰy+,U;a-:{V,,lSA~5ipS"[2`&W^rY9Fxw$a1ڼnpDGl߯M7f$ଘy $*}lۃe#<;)`2Bpw!JkG$ Ti`#Ό#u52{_Ek{3*ut1z]QMktmc4\䮺78XR*xurQ3̃ E0N#yyߦ H;W~|b6WC*ڻ@PȆ3ge^&<-z\_s(60m\O+}TK&HvvQ|Ldw}ݭ\lo*j_(HQmYk1Du}htK5h] .![ӿWݹ0fMh忼u?{H#!|Zf,\Jd OABS]>8Lrd'O"ZlUlbȤXw' fw $qpG[$|}j4(‰*~8ȓY)(` lb^#)ھ~t'!ӱD*_GƘ{Ii\&zeA3ӑ72G4 J VKJ-dz TmQIpapT8'i_! \tl(x@ ZUqKQUNO蘎 ۊN4aJ79[kO!UPV&1 ѭ*u Xw|nn5L4(gjwl&{]sCUݕ_7;{EJdۤX_ )44)mf7Ԏky)Yl0Q#2giUGT觔Ύɍ$(ɩp3~R B\4b@+~G`U]h[3o\KL,P_Ocnsax'GYΎVы:}o>ʵ%N{`O5bx˗/3ǍY6 b1 Xh{hB aXܵpG=(LVFORԿ:1\P9J}7^C]ᜬ ~oYd5%y A15QN68۸4FCՒS_fAth[V7uȮiJw!@w>wv&U{ChtKƙ$J#y~ ]48*Ĭ+|8[M2i2&P(3.9^m|W} . mleIBi_:Dx&P#M v\2.0>#DCvxn62 =ߎ<&"m/ 6+Sh_S04l(6¢kOoF]Rd`L^R|򎅩 KIe1 > !_qq c ˘w'*2y$8_>ۖD??{t #<U|p)D2m|T] jWM B[iA"CqZ!G UFq -U&퐽)Ҥ$G|v87~@.0Q\NGxo^NHy'W Di.]yMKpU{36I)C`]'ZzxQ~l?TBuMj%n>|ĝV8Ӕp P!hqLxm `IKg"lD9_7ޚ`^hcog)REU>(!l)P GBAR0;l9DRe@!NA,̼},|Y/꜌9*j8.| +Vฌ܀ш8z П>`m5kwxt'5P)j!I9Avv1FE\L@ZWh<l}uݒA'D#-ɭrqpH8ʎCRҾVߜek((6wxF̿t~}Z`iO"LPou } |.耟z((tuLwsÃL@"@ybDͬa->!eЭͤaw5[!B^adg {~" ܤ_ͯ+XDD9Z6U@aA5cã!}@*Z}ɫqJ2UahP5 %[7L3!$לɼ>a!\mHn)b'q8jsr _4yL |YwHGǣ}ŊxyFxX+EHÌ<ź _?#g%LF0cBM.*e5#i.9ȤFs#քǔ!WUe2~g-:IvZm7ʫz(v{8-|.8kGkmjKI/o"? a q37Aoad޼Z-R'XPjX#ۿBZqr}uIUgd@Zy د$^U]5}"IU422R 4g;w[%cp) L 1ϱƮDŽrWHR8}]>aN4ˣ}н gt8,RU]pȲ>,cQ;Fu[z؞-Ow﬌3zKx JrAѤćnik;K3 ^p' >>+6󉗀M* pwS40sPX"V&~*1vlq8^zS[eߎlŷm^d2Rd$_aO&۔Uߒd|ODt!ɒ7OQ^Nn ⹻1f`.oq*fb|Rcmh324#Եhr|¨2 Cb)Lz!.͖%-;K]i0Mײt-AT,asZIN J"2=ńv6Dͯ#?dV_L,3 ; 'ͼA2xud)E-_zKG,s=hd~γ O5Hp5*%4_Jc6mԼ++=Ju0 /S'eL AxPxd;Z*F۵5vZǠ,ĄI#ɷHrI3F\4 ٜpmf8 Fs6~vQμ!Qng/YD'ذ?|d{SqBT>!H9&h|0)OYg >O8t+ݨ"l|/hDj@-}%ឆ[K(24<4M*;ܯ37/me#q= 2$OM2{ n^pE%#ma G(疭M>k+1\JDA) GfbȁFC 'P$]G -VW<,\{ hJURgւ,.2vf-n˼ƤEj 9k', ~mo>nCb Q]ʹIY{4 nK+R,ybwF0C 9.2($;G)Rj^_cbyynTs< ?:3ks7!C\!YZ~3>@ľG lUT!6Q]{PBl<Z0.H| `(fH!gfܖbV+V碑Kc<EGZuOeJf9 C TDH{|Lho/9n]y%MZ7 _%δ;rxً:)-ȱ0NnaPO)q'\¶.7z73BL])khEqv<|潼@0wWvfG`2T= (޺C#xɩ 2W[d?.v01b38f2XT.йܚ4;\^=M pDIKt3 7ZJ2 RY5Gn}k OLg&,kT7cl2m7_0oTbhk»w*r 3\~X\E^΍2r<ހ4zX}DhQf?-X6+: XHS{ W=OrÍOciuJ5+]k1 hC{1#켬f>ik28RGPȉ6sjs+%xyBd'ĦPZ8G jfp+.Os*#lTE>^#9B]C=IѦ B5kYTPdenq ݥo|ȶKU^ٷEobWQF8ҬxSCmӋBIku2^g2m1B4+joZτ@nFX@kgr=2f$v8߄bY|_UKk:4;+%芩h%^ "*ǴH*e#YOB#{|rv;9,J@ ^5e 2zΩUZJqOpt (߻7`_>?_Q `*I\KAR)P`̶kπ2ơAj~7YĈLŽPNysݻ^iqpXV[X$ "4`LH g oA<|A Lɱ87Ss j+Ct\ $'WL@nch,B$3~/Te/;8Gp_tb6kv'< GjhE^-㩿{#4,IR2R3ɺw+ ,պ Nq4-U?A//NDkKrcޗ+zߟ+P: C8cʌZʗV˗u}KYNk!o1L[xE{D*VQb&T~TJ}?g\XhK8Szʲ;91;fl :ܪl3-lW*-Ԟa tqv=.|jCStf||Cgf{BNa7Ck 6 s"78s(Qk9a㸚FN׊(ـ0%+N\`rNĎT Aꔑ6rGȶ:iNhJK]L%%KŀX >YM(}˧wB3| ϥ.jXO 6~0`?0Mu 8a}f٩Jp\BDGyt ba(52qx'{{s|K5i"Q 3 ] ?m K/ٲ[(|:xV[ >dS\I VU;}֤+ȭ]@,kӪ8g$aTDSL~~@ɱ&4oH5;jKUJ@Fmͬ>r ^+촀q0)B3,OmVEne/:9Xj)6adj Hɑ?)HX6M4c# Grl鲛;4y%53s筝?be' *|D_~m*hmj.~wᵷs#8Eܾ|$u1-ke"'?А_ЉdR.=Q{!A+ "E)H\03ahAhjh,e{ z4i(&FУXMĤ:** 92V憜WD.f kҒ{tq]QZQ鞉IbzjM"R=Yo߼@qW&kγ*[ {E1yk%#w+j-Y]S}EHN>!a:{G_`Ibb 3$toG^:`o_ ̙]=la\Xl27e" .D0LK:=8t|Ǎ7Z R?䣠~B{d)D4E2-RPN1YօW kLOӷ+b}zr  .`t*x ٴG<zt6! lQCţp7lַpz+J ?V Dc:~t]#2K`H`N&G9>&&]G X̠2 @ͧ{9 u[ |gFk:Ik՟;b$ q4|LÂӭ>Ny"#r%!W?UmRJ%HY5 ?: ɢ_gSjߜ`ă0rdt[`ahfrj=1[VoA| _,<ãyU`&խl[[$;g,(,EZ }+p3,\`%B[aܹ+o؂YVe%YMBiOr]8!M&Ⱏr74O[M 7/ Aʺ@bgȸ=eI)0^<*?跒jXΚk:׆f[ܳ$%:ht%$LжaybI䦴IBr8E6s2PcW#4ͽ7fq x@ww_ -?LQmƂ}鶋եJ0y/z0ژf,tVyK$RB"wUiz+tYz-wlKҁls/p c֚%ZgLJW'RKwFw V=銜dDx7[7(_w8}^Qtr=/?ՙ ǹ`R8@"նz Rr[-&BBHqRI?!&!@ȋE5GUzWYs~lb+*xe(5BdJ`7.l:#UuG&&0VlnY(էʛ WC ֛И/!f&?E[`uG`G (2^I}(o?4e;?BIflq}s_|JU+ ZD92gt=YYP5* w+Z%1{ȷєmhЪa˅xYXYM:@E劑l.r7o _ږs*Cb:3 p(f ,ϸb&NU>IeTrlXϱpK7—1p2fdK/ uKN8Ցj^$y՘J+2|8oEj!#4cxF8=O< uXYMTy bEn.ښj;?h'H!&dkū 뺷t-6'bY\_Ot1lkXN%iXV:N@ԡ ZP,w`x z@8`~3޼P.$ wW8}x~V0*L`($LM> ]ԅ}.4^jF|c@F2O|XÃ͒c* S@xg~0`gYZL 2GR۸5XS*}"[Lv4 ['U:S w$N()RXfq㞲,K,(򭧬)0&9*rl_/uEda/aEF%S?^,@:jqr>H[V,{{zVOG_=nT6n TiyEUn]qǏwYJ&F=2NyV\NPŁ/*E@qvb2qL(I&V50I(,jLP{YO{-SvVcԹwEtku]oOrIHe$R;Am E*҉1Ȓnɕ()M] ,qIO !Zc`=hy[JV!bCɽf:/yΣ{<SXZ^ w 3%sͬqFGe4qKth s/a<ʻBc~.E. "tMIQ9BxeR/UJE* ^Fbt"G>G[P{Ԅy  dPOX㢲.]FݾkE"j. Xʶ9 ^++C3mxkDD9y9+-!qo_6+`X> i:q  1U<=2w50l\ \1`&MeN#ZS ̋`b䠎&tɲ=231H vhdYb`D! 7&>*1# rpPןn<(ш5ֳ=TLaBbRY&S|җ2vl ]_h\-Xfb%)b-hMj#e2CHw]f .7&$E^ӕs9Mh-y?m:h6[Qt tͅyyDB^ż&L>{]O3Gt;"u-i?kPQB MVכ}|D|W˞ʻeyh66酎QHCp3 DnsF1ZC<Kl;߰2;yDߩyj y` qg߽+.Fz4K/UR)+T;Z0^rJM*o~eLLb͆qU1g M6-|#@a:E@&cmAtbg 6_OFP 擽i& FߏZ} MU6 'R(Az&ءd#li//OG'jDt5Y1e6EWIv3b]I$׋ɨiV2x<3졯[f\aJW6R{Jz\YD :TSCK.,]]ڬarJWNdQ-fa@mF)@g5XT, ~r+K"uMwG ?/9)KC.PB>RE ;R.$n@z)#E(#2QȘ#m -N7#cP9P$dZxH*z8|]F@ESy0Uq-7aR}h -k>s+s=hggX2-s.ky%Ixdү5ds2it@v7T-4uuR)OT\1k0hP[p]6*cXk [!tjŧXx}>@lD,T>ċ,I'_ 8Ʒ l/.ZҺVp)Fqk&iEWaa<*U ŧ [* 030Asd+%larqI8f"9W41Gmgɨ%()}{PmJ &Z΁@6zd'klj?aB/lOaˬT7х:0a{җdsxTA`:i!Rj\^ڍiz"m ;b䌀\=gT[`{ce݄s $J+_[hdO8x,bH96@6V>AC!pC>Xqk_ &΂OtHn4UVZR伤І%O-Ydw<w|DGY# !K73BO$ܪ51v깅YSQq2AO/H`ۍ #(ObL A .9dscRkYKT%;IޏsN.FFx\@2^\P Jg^6Kl3ADT"",fM&xb'bBm-C}cwЈ߮4q+U *YΫZk~.ǿ}-d΍| a`ID<>H la)vL1&>1(^>b 21LY@nXx) *Sf\4`7&{jE[(Kc*5mm-vgE\*CUSao`!%4NAbԊe@_˺˹*WcR1!Ou@403y(H_:e*Gl}9B4, !jŒ%1C$Q`Ov9LiR> Vy:EmV <䮌c;@YEsk$@X&>= *pL 1Oe"%hjFW'9_^-%f 㔼6o@)_ {*Gow\#Sd{xd]gp 4H)OӄI=c(˞ʪ>%U6' i =U/ȒWuv. &p4 hQ):n=VS\6wkX*m]1_Zj9uLn=兪!NgMaf)K| p!te̋8@LG|ZE^^)GzB3>z*عQ^ÂզdCM-j;ݞ: V;Du-+Ty#܈bYVFƏO={>1fc;gwȆyLZ?PTlj0U/3=rxn=Pjxp 3ՙP%?;gE>8 ܞ5i- (H+,Q@/ȀhZ}x T'bcF47@y4 @Cݭr[S,gr hOB-OҧLܽ(+o8Zp0RSyf5?*6q._ E!U#c}:RQ~PL QZ۱UQD%%Պѡ|.L&VDT6O rWf\ܢ ɥ2.4[ݱpfa{pSw$E p0JwOڋ:xS.Fl Ƙ0da(+Q̇MNkr!QB+me EI[#v!N5s_ocm7#onF:7XL:5#|4;dTA^_:=S'!+4gi+P >,Mt(z Rhƫ͞8S#AupZH5*ڄ /Ǥ ;4^W; e "z"v0ە6Wi Ѝ I$* pv'vj∄ӛk܉,kX lks6|3_&kgM>x=pS<5jmӫŶ3XwY'J7WND4ؒɅ|&+P DMGlƩ3~*'JΌ)bc/kh,.4(سaۆP@Ή3!+R|S&0Q@q2_[DVkdz)Awf`:t,LXC|eu'.g ߃ܕah z NC_yԎ=> "$h{װm{PT.w U.(4j~J.80iUH[X.6(/Nk*]7A~^zQ^N@]Ads g$JK3>߷x M>:z4V_$`Ig0dKkcEMg F8m{GnBtχ7Ԏ nUVNk%܄O=Q hvGrRw sKIɂRA *3(^oub8mDIĜ_Z‡)F` :+F*zBL⅄= VM!*cdUmd~ܱMID-AQ'*]}# is .&W4isdwoʺox7ץuE誐 }nz#* +@70ʨex={H˰spTWe?ˍ=맞BY#( <zTS旴|ݑ-z?qv A$3]5s$+x[.kZLΗ=U_eEnoM[5yQI&tFآkU.Φ8naS'U-V;{εUl/T`W@2 f7U4!&Oaw^*!C왊E^IA /tAU+5h" -1IrqjQ7&3hvf>ֽ|W 8=a`%[JgAA/`x8s}$ zs ƍF!>؏fZý%iqu~ě&]UrP[ʙ4 npj)MQ-~]ºL0#-TK> aй%Ol, 1]VTzry7ѿ8',)L,79Ty6Z/l8ch_wϙ)z+ά?ՎH3qfg=E |z)>T[F]&y .ۓf&O27$) y^b沴Ta,r.1H:[c)23@i(,qzЃj|%)Uncpc1y)j`pzP Z 28lpIU](9HŨ\"- NƫCi 9 k L6|2^hv_519\Br_  k3=0`_enQd(c@9Sc]rW1P@3f$u^Gΐ` bڪ^VU3d 2W9p=^f,PGB5WMpBJG$i1I"ZÈaBo[;cjJ71"AWiyhǠSθpW['OC?"WיhzjAGUw1u|_Ŭg nwEeMG~jPR ȅ65t~LPn ͡x q8! Q)迀~!݈J􅪻kfX p !ud,~ =wL4x8+6/7|@p]/73#!]IbK<z>*P8#[nx<q *\@Cm.]h-:vW D]4&ݤ*lN/yxV,-Ib[;ymbз-=s\̦:@9G{ /v[mT!f+wX*aCN0_W*6Š&z38?ȢR:U7-r7THq׈I*uf#f/t2ZQ-vЖT-Ac,ne,v7|-lCSznKT;u1טD*>nrV&uL]_H;Yro#d}F R83NQ^/yBP'M3 S@m\hC8Ԁ pKqjL-$$BXCXE͇ IjՔf#4Nm,ֈw=zSS򲛯21(ad-ǿlr.[MCոtimʘ;&r:n,iy`bUrn]} y/_3'#!,(YֱP2aKWtfւW2yܳJ$ZZ)& q9Ե1^naXMVYw;;<1_f swzTZt>6~ ʗk-DUfdv{2T eyԹDNed=8l%,*p WA=C8xKŵ( xӀihRUJ3:d y7OI:|+HBcOp(jbL5;4ޫȍsWTbY:p [ײD#nk1^p#XE&&v:|c~]NJH,yPR7ب26X6)ЅjL֒4NِEJrU5Uo :9 V?0~喔NgO~WT*HX2? Ri2_j=yӊ +D٣A0"U+~NHGN/T?U[+ì,~y:r!#hs'uIN:GP䶟WT5kcTH3&ͫooDD;4NPN^ f#T Mxp)Q@5bp=FU :$D>#g_z^TB/.1SkX.̆^҄1֙)HcK#kZN|%ν^OΊ20'}d *2ZOH՘Ϲ0 &]E:3_f˴{`~'=Z CV($˒HP o@w XhvfDy'Ȁ'sqV3vR;xwu@6u_;w~mrqnLcȵ;^-x_0Kc!a^C\4'jo!NR= Ic\f}س16c~魮P%61xֿRVHoԹ$퉫~,w wuI=%̠,]>1^ Y+qg?=2ѝq}w"{Hx2Wd 5G*C%S[w(6ǜqçŻzQ?&$~0E`K ̈SaJXrsgBHqn?C DwR>{Sk9ǥ=GzAmSwe 'q C\eTz-qD& Pyi Zw=y'F<"lѣ&rB_dq;l5vNOvGr>];gu z^+֣zu&h[% ?t%]S,|4YaX*j<0G~Xw+DKA&3k XV\"jp%c t( kuQ>.SoQZ[b9 {,.wj__PdB6ݸXC)O#Qv{b'M"z费# a+zTiB/AYXv-Gᄏg>\S*-"vKB/%]$R5OU)QpGĽu͋W8'iv.LGnD!8%+>J XmhJF- @d"4m^>"D+t⭎BkiN H^ Zg-.a?q hcYevA~NZ<_Q a~gY\-k$%LBP-ճ-vi$'Jx lB=*@LtyZ-ttoJ,},DIW/nrJkAKccJ{K=]u.*vFdԵi.FWo,lmQ$6qXcһϸ㗗h$o"'KiHV\G"ڃM'^i3/OSi*\@2%kNI'\wU+=s U^QbL~\ vͣ)( fs(M^P] N5 X&\a@ʤ ';6QT!蟫Y{MV%D5ج"QW p ;$pfZӏ'9~Fst&1' 7ry-UĒ_RwB{u S@rt=Qùkd# xU`$@up&$hWE" e gYgw^H<>#ѩ<i ZZL 7 C]Lndu̸1*?6iW܇DQ%?2BUs v?RCfB }X*Rz!fF:+|6JH\լNÜx:|;pfQN&WS-ƚ>!HtYJ(h, 0RT$\`z f"Iјexl%#!CLNpR?4Jm ٥AagBeX8o [zs-pdO|Z UG4 o!j0o$W9j^8`lR#`>&>S/F5gj5mKqWHb j}T‹i {R?xSMy?Fޓ@%1ђygʼnʎHt_s9 Ph H`z֬n"=.idi#0!:1Hf~_@PH7/!XmՉzn| cVl*o]k4~ī#/n dc*~-g |9x,xѾb&k]f2[Kxbћ F^$-ut G$ˮjA0`/C]3eP޼O.V0tCŧ[%r)8X"t>ɩNј Z]lS: A4K C[[?*[T$da<ƫHE4?>4bxB!tj9*4mw&$S"Eh&&{Uӎp=m캗 [߶ i{a$bGLJ<nQ޹ ČNta) e>S$0aq&_Kg"#P o Vaz[RZN<֡ NEtG;;ru~Meg]B0`RYDc0zdbɦr󻃑ֽpش/; '09EO8-d.|R)ft_M¯[j+ ƫ ke.Q7pvn-Ho. tHX"aKVlԲ5O*= Ĺ@\C8%c*Op2(#Y"=}b~M]^YL rPyL{S^0juh Rˊ.~a(kzNEoPXwR`Lu,X `W[T}4gVXӂJ{6h''  3Ai%!`N@0D^fv[1<1#̗M;w3 z&{?Y~-zϟ yP!'c ;,r.i}hu)Rv. ծsi5H"{v#ؐOOX +2myϽmXP Rş {0*RߐGO$i=5 F sv b 9zFxF>bJEio/)yҵc?|v}V2k !S>7PS?`שxQybXH !H4\`= $r\65S"Qg]%RRF!l}Lv]0:rYFtx(qFbi$ZO>S] fӄ@掞 Kv/hRIzU-9كv@KU?>dﷺD7Z\'Lkx RXYlv_L-PTH 'ݻ`C1VSRNVb %'_W7_#؃W,PXH);ZȀ2JM$ZCEKqi[[SYt5ƍZLτBXvi{r~Mu(Kp rHM#9_[j\  H6Iς]`ʂe`3\ӷ f2p_9 -v!v6i|sHJ۶$D:My̓KX+N+rt´Ȯ́$r^ٰ^J7bMGn,FoSqsZO.h{]cI#xat "Ď?:+{R,̊Q!LF,ٔdL}c7)}&S"!V"7:&0"-!GJaɣM!Fa>OҐ5GT:=Зd"Dh*U.q_dV1Prf:%Y枖%7'Q ~ 6} a {@X(N3Q4h!U7^fz-8셍+~dc}97}܍lG@P\+>XŖJbCZEr¸bϊVbC~'~OڽffDí+. tM vhРI89ų+.9ZQ n+rf[OlD ^kbFSk.''WP . t/ 3hW@\1 j! S'x<ނ$*ġ Ѣ~XrQ~&|c/:s2m͢RI *3QjRhLdv#\e@Ւ_^ ;aZo(N' fB|&}v㟕3dؕd1(mLS7fqK8kn;Dv<  T@{"Mj=h1sk G+#P[y+ Bsj;oûi1Inmu66vۏ%&6EtHU.aŚf(gnFJHs L>+2ܘ37;)eX<踤R3B@WdLT~Lm6ZO5""BFr(v+I73e sn u20E Ef+WD JS L[JBHfN}8bڑO>/T9l+!~)Q &3`%R3n=Nӄ}*o<>r<|Q/ͣ) ՚ND{`ތH3EtYn#m<ثsAk. Ϝ&6~vRp +7u)qڬ/(V{a'FPt_"MQvI~Y (9b `m;UiEhbiB5;:k}%TY@ - ;k2܇udjNAb%Td̢%8Y썃2Ѕox!c1 6}g]ZBDoybS%X{?^u ELz wnHTK?88|N~ k-6[y>S3f:ݢpy+@܇$(IO _[߷7|9Yg#z& 4Q߫=%mgdsC's _+p/` ˲ ,|7]Ӓ;ҷJB? _#h76cCk#G%G`uBE? =95fҫݒVHCe^;,t͎; M):%V^B^~R:AS`>.ޜiw+Z_XR/fz&]"3anժ10X6oj b(Ri "PM~+F3sIgZtn@46x/Y\/&}R̢1I 5rlQh_; [u| e/`֤JiSu_.Zy@'Er14IȉoڶE AMVWP8Sfb?j6k\mX;x;c3~,v CA ia%}o|shy(N_ /tUCy NȘ0(ɲ.ebn 1OgypFk,=,x7QC!q&|#5_ԥаOcH!PJ,/.&-@j<]7!7Hb (| hC1ocBXܦ$Fdp[?&;>@AFBgy\ke@A zދ#Di49 *mdhCc aE 4H:Rwda} Ŷ81 2b2~2\svQ܄ѱ@VkC _ >V%y0B8ћQ^:QQh.OXdi\]®e}uuOHR!\j*=1ȖL`'fewTJV$R;'Uݩ$q K1`SVKf<|XYfIz@So$d|S*CKz&z uiŬ@vYm0Qᆭ;Ѧo;6**jdRP{؂'u7kbmRXP9kN~p~=ax*BY2ʢlzGY*~\ѠI_NlHIEjMl6iU*1gysR7oŲb W|:+YXϥZ\4߾d%_mPi2l:GhV MJ26bvf9:޸tA̹^W0@'g =5#j7KæL` g#ޢ_b/&v:sooѡ\G>`n_`mQҮI:CH1_lRMkM`-T+K(fHX{y}cQƲ"m({Q{pj*xlIʄ߽1rkbkcά'7̗7j9F.Ց@Шe5~9@^PpornP+YN8(biwp>ȆCSyj7@|N1Tݺ,3ڟO.I=Up2ok|n5ZAT. L/Nݳz#*X$V7 w*ߛ_|DXXA55%|l@\J$zW E"㾣mzIT*E qIVңY6IMLh6 zؾ껉totb#~V"vaLsֲWmVF @^'>y~pBp-="ecH,ʍYb&)P 6-|W2k3YkpPb'C2bS&ؗ~fL/p~̍rԙ~\{ꂉ#RBVXśy_}oU&͇F]O/Ql"A?.Hq&3 G֭y]+Gg jB>՟5n WڸzkP9Օ,{ϣ;q[lֵy 8T$>x·?Zi3 :~g<9uYzoAxޚ$-M;0T/u_hDPJb5L ~o0Ǝ\*(-yk ¾H/o\c_ [Nu[=yv7̫ B\Xb/L]`PӝAKU y"_ڈ Kav<i?SZKV)Y2JMIlpTId6Sjz*ot9PV5G@)m2ן<^M蠚<( s S[eĎ΢3}7x3ν`z8{FΚ*wцZf7n̽XUOc}K]^>2ׁa brbAءUb7 -&_ ܇(>+E,# BjLDURMcU:|2{9rտ۾C% փ幩_՜PYʨ¯`gx،DM]&e- /4փi|zڊCe}vة^'`Cy\hXTՃX,,QV$ A Ƽ.O߫t\ts#+ ֺaC 5=qL+υ|`6˥C!"b} GS0OfJҳ qK?ӅFZ\sM[bC/2dl@ֺ#Ï&q7_c AձeUQ(swK_A7RlA̅30hAggƃ6+6W3-@ vZiw$B=$-c ߉s499wm'+GqhƑpKZ@!uZ&MSdF2zC/G7_t~:1.Ve@ : CuC7BL%N:>W'͔TtU>ۘ)anE_/+^xoC8$XrփW|12#QT7wg:.~,cY*t[ ,D A=% Ni.epk$%GBChtx*9fzǦNVmÓNbN|f65a{&%T}h?հ(Wv5"ђZ_gj{X=62uPLݓA*b_a YWWnN^'6mt7?fw,pSv8P}UvzbT|+7 k# ^^=w&=Za/l 4#'(=PnGy;;#L%T=юkCc݂ĞP=yp/Med/E}5ZQǎe4j L8r(4]P6[M# -Tr>=6zJ+u.\W}?Ĥ)t`NYҴe+ߤp?a'~ώYX $[K oӭhE1>`GaYDdW&UAh:}p[.zΧ?)O`-KXSeiO2ssp!Ѱnw3,nVQv '~Od3Da^NK!bySvNJVPpĘVveQj3S.~,/ TYvbѳ9'V[<,{Y+MĞYxc(=_ qc 8dy)3~e7x.,D&F9hge &:PthLQ`jF1&HEG`x6%7w,4 xc~FՕUNbF:w!gyZ|ZLźlgmw˸@cӥL.xc ߚ%t;g4 f&sHEZ 8*$0@(0 Qz0 荕0f<L)pĄOȁ8>%n8S:}36L6 `pO%{~G802xA?GޤLxCz<'^Tia90(KrkQyVhc"'p?mj;'WbuɌ%HAovkBۣOQ> RaҴP>E?P })Q׆3s`7qwکGP'°uxwX,kRsqG3|ېp8"a $1g]:{8-8ڝX;1}*j2Tjnm y}!9:~U/`q[TI)qYj<,لu+ߒ4tAVkFwC pVӉsSR QZL/ԉR? )*|4*<0$ ]zHc-#Ni>_Vw̺e5 .8mqkt&j*8U `n:!Ts9TEU9MoDv8N톮D/[De2:(y!a"ůb l]ߝ'i,l4k}iEV\[DџY}1$U.B#wB2z}[=A'-$HE)Ōg"_Y5 YiL( $03us"+Vc̣v-g-o.;zf;L)9fdבK*N,t3Dhh{~@Ie^ %$9 *8oeS y8j:ӽa< M,wvaAQ=$^$=V6 ޠ#9^=b"2F"1!j]uN%oeLi)ujM_ 7b2 {+`\@Ν? mkEp@֨9njl ,XM۾c%*RPYGd*> n-eQ4X0f r< 8%z۔\ a}vĦ!5Mh][er\Ɔ`;`!6B7_6)C,ڮ9\{pb=J>+x%Wpep)i,+ !ۈ&n^#S8V{`F$j.Zq3}. n{CSCo ,JC89ZA Xٷ4l!yPy*t / _iMrjڍ7[_#`"itmc=it c0l# Kvptg?iÕz?GTOIzJYm EaHlqعůs]jEcl_P\ 6 l"4ȄG*rR9(]K=UzuO אMْݨ&Ƚԋp^h$oT'}hwn  ^ e/ ݾ@X{8N3gZE%r0>뗌 AJ&qJ҈}#H[V\;iJm!2d8IVeomL|5hQR)ȥE!Ⱦ4kV'"++vGK/ҳrbTNRg)]KSm#6+/VRcW+ܣ vAV] AwnNը3wGׂ$A{iwඓ M@{\b]UN)PT-+__XkfwatP++$"Žo~>o=<6rDʔ3Ļࢗ/s)JB9u\:ϘicZ%g[@)&-D5Hp HBkw'in9\ýLϽv# w lA|ʛS\03&MfjjJZG4.܅^N(?&]~Ckd;,0!VqRUD ϝHV[IhȿZ2=o6/ t@tYU4G)lZܖEn}KCfg^x9Ș@!/7ۇC~گ+Fn0tSk < mC s)Q d?gVH_7t^%(A1sE/<"YsX6fI8;l}C.P6˳g׈PAqŦD :r5V!t ݧI*\fX|veqoQ6 VEzӬ (%>w aL^zR~^|~}9JP+K}S A^*#'C}\1Gu@ƺo!tf%T`Mwkس'~am=CENEg:bQɽCyi&/RAMGeE SD=>k+!E@?I3Yv+\swqkS+xk 2VJ76@܅T[Xmj> nm<41ɖ_Dw)bĆLj&Ul3^"^):Nf1A}/}uQ 4=f'8;|0l2e-`tI6f[ZMoCB5CǯQߋ].I'X%&2|G'IȡpMSx #|oԖ}жZPSK恉vkf0X] r?'3%+mfyE_;´ᓩzu{]G,7*m(PE,{ܽt i pP \5Y-V|)& 6̢7CV՝Wj]{<,w/ Z+& 8oz_1!IهkwL )3Y\o|q߸i -&HՄN{tK&>m3FBlstafKtW8u .+.ߣ@q -SI- P],wF)yLJF:5%k@kᓮ/:,Oɭw >R,O?8ЉJ XZ0{dɘ j_fx= f ϐ;[V-۱ ;/J`wOf]uAE Bid F i8k^뎻:E yYq4#BC{ƹ{]pg63h `V=^1fV&%au.@I~3u{K鷞 >eiQ.֩?=(Rnhi.6[ /P%H Lay砏2.x!<3^f?.n)kI0TlMtCmEW_ၘ]KBwo#i-{#wHe1~YPΖ[ pKWɇ@I|SEKJNx;uE#3lI3GoQA`Zh0q_m?/"N = pMV}r#nƲ.̂zԚ5(˜"'XYv(Է781B'E" ZH_,[hnwvbpC}0~ԭ@*{Cߥ>8ԥOT!~g5{]sI)=)']*~➈d-t'C<ϙԮ#V^xO1TH ARu;m+T i1ԇei9<&6ӝc:4wKS82C)B=HN? &cꛜa0Ni"t-r{ҼB%(DG)6$.hau0k 9vђ-Rlp =C3hb V&{VprB%na6 [?}|I70Azw &cmѕfˡwTF{?r,ԂcSuWJ<ĞJbH+"I%d/, /3Vibi2V@txY &r,~j@zABʳY|<(] ;gr(I0uA;xL|(ybٽ:͆Ӹzp/L/Wf* ;a̟BuMWk8t7:U]!wMF $+Pw*?% DƖ\}\*:$/m@B2.壺dMည`V-5 օ\K>Lz]? rNj9?ioaJ!s}܄H/Y§3w^> sHo3hbU{p2^2=ǎ$$V,K SfG9tZ6-"A%8ᔍqs iPfL'?4 '",p {Z6~ Ŝ;C+ ]wuu9/!)8dXKM'A.dK&+f]@DžTDS e"B )Pް  ܵ_B5|gW–>2yf|a&S;o) 4U)bq$;i .| 8P`I>-멂3;Ws&Sz 1~ M47|.1=z_C |Yɿ 22y{6b]q}5❪W|cvtrH[fMT ^T˵Sw`zqCMX3"̶"k0᩠hQi|Ëgŋ#:٪S4 R]ky0/։YKDV/]u\_Y )?(z##|}&YnNZ;f" F%Yqe=_+c*)U 27<8fq>Rʭ&`m] С9*Pϊ?ZCVg\GR`_JE&Rk9eɉ^NKgwV .l Y˨SLBW}#d+mM6&͞:B>@2]86CQ^@&-k槀x4.ۑY# ^־ʍox2_*L.rH鹟zKx ~d 2A5fjm:o׭?_"&d|~溩( *c:o$2mcyI=4SgWtse}y,gKCQ|՛ǻ2DŧNfGDt&_ϒ4o+2E)NBH~o^f&pk ^!TI{zw^>:L»(w:h1NxS>?`x$wBQ.[V fQd5A2]Dd v W^* BU@N%Ke O˭ gׁ=g_IGz ֙Yؽ"zuY b iŋC|Ϥ3:=ܱ sҀʐйg1DK4LqM vdjsCuy\J*f/.%8).xoW)717{$F鷂=jL*nGBl)nEolrHU i*ژC>(GB&(Uzo#*a=8'|ۚ&qgޤ8(ʼ>~p1w1"^?^v ƒ ^{KN2\DݎaԶ'ѭ f36{X*R!;Js&P;b-uԸ#/#֊b4E3.~h·Q=F-a?poJ$[rKPR}Դ!!FaaT*=%ys0jO?wTGu4$(qeCl<T6Kwl vr|bG:&9Ň 7[  7aӌ P el;u0-Q&9a(B|K~wxs7ij!: IzoI"Bc* |_52б,]<%\ GGGlSv]<0tS'"m#:f䲹=k`f[{ +FWQX .)M]PŪ e׸࣠.%QPco x2J#ZlӌaH-tua|TZo\2 x+wC p׽H`iFַ2C$HCW1kB-"V0ר%zΓ!>!6iv䭾-(uzV+N-E|pbHL5#*Hnis1"ع(\[F\:3+ Fu`w19"Gֽ֠?{. _Ev~peD#$4u01I;Eqenϫ@+-V({CY^1zJߣ`MB/+Dk@||W8zbٗv8(w~EQؿ wtGΕ-9@/Eh +fw ]`)6 7RåRQ -@6z2+pM5149$XM_-M 8 a0HϨ:-f]vzTU "t{seQx|T;4c݋>Fm $&  MN\wm A@Q(&~S/ȕ[)d.>\uu HONV\9l[IM`L1_rɆ?BQdqEYdP,>r\-*sG?-Fmi2mCr3Fe .9P GLWЙ 4{'C`ߋJU'J$(eeѺ K_'< Pev" L a_Q# I&޾XI:dk^F+<P\\(vad'υa;a32_"e\Sn"U$ɋŒoV2HZXeT#6%.j[{ |v»'f`'?ѝcq)M{>E]n@km%ڀPTDRSlr'٥p\+VM{( WW>4v(=6o_oTS-sCQ _w eKME)iTD; ^5 :+,^J?/u#?=n^i-U 0"MXZp݇#;[CYKBlB&[l_̟7vQo=5h,{!At!#(4ros\x#Oō7O3o8$:7FGh XXQ|]6pS YeK+^$-[膘۝s"=w:.t`D+{?lH)b?y9:ny*Hh{(I)]WͥYj9[sysqE-hg;Y_L֒M3nwr{pLj5Alhv+$+{2j;Y Gbem!8u 0ȢbKt=s)e z{䅱(62xMA.9k!̈́86xClsK8Mw*VG>$'jO Mhp@&?f>jC+ʛ* NJ2%ʬ@#>>R L\vb.  K:oƻAqb0/U6Y6Ltd>-s: @pȿ)d#,G7Hx+  Ј+u&R`3B1^[;0wp*Ix#'-dyg'L8 ϩW)-5f)I9;_"B: `1E2v۾k|ʢ(QpV?RKSFAqYCugkpe); 9=".l!*( m3UXe"[!ϩg.,Jz G*Zc4/bQ qj|F #x0[E-rNU:zĥąSa`!S^uym&&P 6Z gmağnףM*vZBIˍ>p%MX >tjr<_f25ߦ; YBb>}5U )r0\y~msB>*)SM}Mt^QX66wHUo }SWTmca{9ANzۿY {) T"r3ln;Q'V3 Ov%Byրm&?&95@͙J) }#khdwD3 >Un|Ii} bGw셶% PWblxo2m"|?a fUKEπB(\{9K;>0V?N~7& zH-*;E0pfe%D:,0HPm2j+Ď*uw.ia_JJJU vPTƞs~֡_ ;פ;oEœYס:,CEuR M@ľ@q6 oEXZT`:JD6+X@ja}iP/XGT:08yf P. rU2MhQdcBmd~ ?X`jM6sSrH(9v#נucLoHrhG5{DR,YBZckb"yEԀ3K!!-:Q?Zs#h5Ũ;prqMP9Dʰ\@XoXsӎdl Ȑ'!Hg4AMH;t1μYR(aQDS~+weVlNA-tpBl b>*&2AQy.pno 2TZ3cAvq_ʜӼ>G=mCd9Qb &5|Y}FpWg9-UK13CWeqaU.26>G@`ut^Ek [n91,xVPٮ~W(Bnn(;Y$oՖHh};!9Ԣ( h7[]۹9Iîx\@UNݾdl"D (~G%uJ>vm_:{]k׵ovk`+6^@\ SUQy'mK"&uUjJApeIgEմ /_H?jMZFs*~6h27Q&mGaZm%w83cD m)t I-U$v«PrUA&`iV[idh΍{P2\NmB,^ o^j SnG)dPکޭA'3%妟ET5Lҵ\ž—UҖ`g*}v{5" 5}@& W `Y|"dψ}PJN!|LH_uq-B0q}LP_|ڶ'L_4ON`W©m-[y%k\N1dzcg!!;H#DŁ79_q2dVe7A bAU A1KRf r\hfo)4Ҳ2Nyijd<7%{I HfAdh[a8Mњ^Moh^c0'#*W-H(0SvDow KwWfEU(Lv{07:Tu rH99[AB+E};GͺRtGvc[DY鋷zT@,+,HFxZ'5lPy%QL h1k0ouZ{͇?tÁ9sDq-iuH=U}ۣ+1c~](N8Y(s84I El4)3}?F يI>'}j-g07lS <.QnqAĦO]om2cw@6^[!^5DԆ]%\[n`@[e,N[  pS~ť;›ARg8홷"؍Wtڲn .@G\踐ǩWY~c? oxej",]mJ$ LԾ$_ѭ8{7G^Bc}FKD:ZPA5CS3[y(o )p[uػTeb#m;x/2  w̸8vf7D1T]H_b_ˋ `Y݁jB-cIrn~qZBƧ|Mnfia&wڷ,,bszz|AjC$,`rnMY`ƺ6ڂτ%z 4M|O\8uwd#yWPZV~ne]!/HU)JXc?l)#˽"> ]45=A2ځU2LˑAtBZe`mGZ+|d/p/Q!vi)Y[;}* Fm)?G`\(ʌX֪3)g;g=Km"@X> {e#k_e1oH1`ܮ2ZSghMα^D_znl$A++BcؤZLCtYHWOR\T(9wnf.cH.:)LgBZƝ{߂aln۬ѨЏEdR 42ɞ_R=:뜚_leG`=+_@ܛrMts'c+}_S 1~h.nwL>OVQ -L/6, ~νLq)-ѹ!mN]҅ 9'!"CB ipдvXUWK2PLũQ਑?veʹ9[Tzr+&p_-ux?L'Ҳ3Խ$lR0+0:嬟:H>(hܥ~(+{XʰD_(f\wvױFMOswn3-_Jѧ ,|w{xP!SSoҠS,}"2&LPGRO.=<raolz/lC$Aѕ4oRa0[aCpy`E)3N9`:QQ\NKP~xEƥq~oM .Ohm^l@aSFF7=cm EVS v: [s qb3REtbb{C_:xTUʸPCEhEkVYԀui2K=oS"T!X OQZ:4D-#SSEzpE9wך0(gg9H~ 2/S:mR|&&w3rvR]*JV$|o܂hL.]{πך3#!4@HـQARrED.ゝU2um^g?W5Ӛ-POAKӕ+}t+Ou$94) 5!ӣV_PkvGxPOgvBT`0Ÿr=ԂNJsZXNY F:u1~eDFhWyJY=zݻ#7TڇNWg68ItmMD) XhS'}s797)ՇIXH}1a?KL5=$cx7%8w0\']N&4gx7iFb$+5w^aM3 x0I1GǏ9TJ^8 `,CG/:"I,FREc¹qbrb{>Pц}@ɔjSݔQ*鵨~+$*g$FsM:kDNk bw^Ր(ED(%|_hlf^g롁e s. aosSJo}/6$r9]uBN"5I33~ j2H56EEB 4ֆzK6clL#lI+Q'!*O]j5X [ePh JA,rNI=}gͫnnΕ^d F@0Ev'(hm/I0_IP-J R,m&V%rij<:ҿΪ{d}8Z "g?+ZnkF,fNFXBr rcy+K; Dـd֐` -"8o0^7Eabu<̞Wֲ,I V59Z!^ z.}wu8>ƁKër .Њ"Vmqڇyh~ w}9xk T싆l1 c?a+ ĵ4WGv!E%.?JHV@TQ3/7Df{勗5V%|T(؝;ZW58-P;Ȭ/cnd<& =s0m;"(ի4ߴ ei C* )Xԋ)V8i53"̜ǮdӐiV,#rdϟU#ur;Q+ⲽPhSݵ4!tg 򈛫c: SD^P\t0bII{t6ѐ0XS͗7p[f " qWdzsXK1 |[#$үrBoũ(.[YS=Ks;?//FSKґ,3蓘el!Ift Y!gtC4erOqFE BQSc}g+7L05TA/nUn9ćSاW${[AA3,G&n@.Ɣ@fӪ0Il=9&nIrE9v_ D-JQU4?KP>L83)DCD_F2)]Ԅzoվe xs⾴DSAXsOY~EE.P9 JH~̳?@?tb ~*X%?c;6]q *j=EQAB48qW=jOU(O5!'41hP {è{Lh)ӥȇT|PF"Q&U9ݴJ쁫i<I.$g~LF;6R $E#ĴñMh82.f"E1ҥ6֬z_XJWufz@vۙ, %fy/dI|gPe ``ʳ3XOG2[`-2rOu~I,c%@MFɁ>0 [u1'/{*-@i[y:UBDu)^~R<- =/׎AݩMΡ(" (^֨l|SO!+t~I[\p'o_yC'ZCoe+uzc)I/(qH9K&^-},ąHGT%qǛ:) Md39,Ա}Bk).b*;vU*^z/6_ۄ5M'3t̅WM_w lΟAB"uc~5]FkZL D zOAuG25g +urE9S2}r aMߜ[vNK!>LqPF}j:JwB~@r~ xHMgWOJ8FD!Ƈ@ 2ŃFcU18+K)`I_ms~']@U~ {dh )9u.{F) pȉ\C$p*&U4c8ba^ٶ4# ҎZiUevϊ6+t߇+"HlzlujF$Wu,pQid̽5߂{ x*wHlϩˮ='G-xU[kÀ@4؋9ܓ:vE+7DyW-sXLe otCN aVd~]͊.}`8y[N?mߵD+Tncl@l_(˙7_Nta|"^n.ڢPK}rj"_\xYyдyUB# /̽V( /E]Gqbl1'f~Pg G[Vk8t7HޚX&^[ky]nq A׏rb}fg9 Dɨ` 3ubv]$!Ϋ /lxM)}lzmQ$l) H{T=߄dwHK iv sl$^u ֳ9[%O܅rN)F6ߩ bĨoYD)."d8h+Y\t$?UC&MM~B-?Hh䣀NK|VG빛$sCfiN79V T3ʚ&XB. l$ВEeHټYDХ1roA%1F;~3hX8msݓEMMu&]>>׬,RuAQ9VYWj YüxrUgWsF~ vd^V U]W} qewZ@j,/#?)\]@&p^5c܌f U\ oY՝Ev\sQ~/_)s`zC l": YZ