selinux-policy-devel-3.13.1-229.el7_6.6>t  DH`p\$ƨ)"nѮfO~=MU͖č vIי6ѦZ[W$%Z?#ֵpk9ڻG/jӓZ_lÑN;KF (w҇òR/w2-?/=6I-p}.l5@_ڇyFoVUֽxnƴI ied[DΘ5RrF2wC^-~F7M|r:ZN ;p3ݘ1(AAωXV `KȨHbMjoZTiwrei2A޵Cb*|yq(b$YTf߀ԠRwgGpa,Mr;a_v:Vt':ͼiA*<ω=V>Q-2Hu w`}#J ֯֔Hճ?b ?Ew0f93c7cae4b0932fd239463f6a5a80437f06228eJ$\$ƨ;dew1*dNXӲXdS)Y!, kvd `%;{}<5awf̀+DeuA]Z;ʨ0?5ؖE5S^$SB.S.?$7du~B [ҁO6#-ݑ*H&97_,!v#:ƝnSۍ'ё/\ OVn+lEF-s{2lltAR0j̩~ԈǙzݾK]&5t!PO5={E'xN#;n/9 Q<? Q,d * ?pt  TNN !(N +N @N N NPNN\N   (8~9~:$\~> i7G i@NH ~xNI NX Y \ N] PN^  b d e f l t Nu Nv %L w &Nx ;N Q(Cselinux-policy-devel3.13.1229.el7_6.6SELinux policy develSELinux policy development and man page package[x86-01.bsys.centos.orgoKCentOSGPLv2+CentOS BuildSystem System Environment/Basehttp://oss.tresys.com/repos/refpolicy/linuxnoarchselinuxenabled && /usr/bin/sepolgen-ifgen 2>/dev/null exit 0p R^q'"-%$#5-3z+*I[+b$"""/H(7?#3J2*G"&'KH>()O63>)j&0h&H// =/:*8"-%FX n'4$7-#3jMw0>w09!B4%48*K66m3-4('<W -* .&.z.^-2.&3&l!*%Q$$FA":4955K*)-:pP9o/UG6.@)>-(252215<$?R.@C.;E&7e+4 7Fl%4^1a.OH$.>6 7=b,t2615w5O4 ?;5RQ#/@~!8}$q06(4N6j4 "-&h7%=$6zLa,I,g#1/(076E+~47,8JC95F%3 Q%!-S;Q5'-&5%8,+7.ahA;HBjHS6,1o"40)/`5Q 9?i6./&95754,!1}'$4.38A-()+CG%0./-4>679,C:p/#0r" J> +w$2; E{*yF`*c/0v>7l)4QQ+01 0)-y8.' 0Y8e>g';6(:60+(yBG".K')\.k=6@,6_a).I947Gn*I}/2')q!{2 &&.*.LN(C$#-3U)I*A19="6V9<7 28BF/<260'(#@_-.K:`6&SW.&,9! &3XP0@z;1E31d$)00313|01(12RV'&6^.'0'22D"2D)f2D)f2!(+J-=C7..*h0xI!& ./.'[EE>h0(-&'W/.U;0AG0J,$/b=8Ez2 M)B'(7$6<=677\6S6SS''g37K)&0hN3!Y1I_ /(()4& $p%/BQ58f'$#!r#BZ--I0;;0TBM)H#0& $%./KJ+6J2r.- 4.2-03-@V55.1.5-7.]/7j$S5i6,549q,,X-J*,+=F0="274:..BCr>*A25G?//-18N%0i'2u(-*(})+!+y() +%$\%B=BW#-'8?9.$:04490#"M.^(Fy27.'q)IIK S =s + *U/V("3^w-:q6A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤[[ [ [ [ [[6[6[6[6[6[7[7[7[7[7[7[7[7[7[7[7[8[8[8[8[8[8[8[8[8[9[9[9[9[9[9[9[9[9[:[:[:[[:[:[:[:[:[:[:[:[;[;[D[D[D[D[D[D[D[D[D[D[E[E[E[E[E[E[E[;[;[;[;[;[;[;[;[<[<[<[<[<[<[<[<[<[<[=[=[=[=[=[=[=[=[=[=[>[>[>[>[>[>[>[>[>[?[?[?[?[?[?[?[?[?[@[@[@[@[@[@[@[@[@[A[A[A[A[A[A[A[A[A[B[B[B[B[B[B[B[B[B[B[C[C[C[C[C[C[C[C[[F[F[F[F[F[F[F[F[G[G[G[G[G[G[G[G[G[H[H[H[H[H[H[H[H[H[H[I[I[I[I[I[I[I[I[J[E[E[E[F[M[M[M[M[M[M[M[M[N[N[N[N[N[N[N[N[N[O[O[J[J[J[J[J[J[J[J[J[K[K[K[K[K[K[K[K[K[K[L[L[L[L[L[L[L[L[L[M[M[[R[R[R[R[R[R[R[R[S[S[S[S[S[S[S[S[S[O[O[O[[O[O[O[P[P[P[P[P[P[P[P[P[P[Q[Q[Q[Q[Q[Q[Q[Q[R[U[V[V[V[T[T[T[T[T[T[T[T[T[U[U[U[U[U[U[U[U[Z[Z[Z[Z[Z[Z[[[[[[[[[[[[[[[[[[[[\[\[\[\[\[\[\[\[\[V[V[V[V[V[V[V[W[W[W[W[W[W[W[W[W[X[X[X[X[X[X[X[X[X[X[Y[Y[Y[Y[Y[Y[Y[Y[Z[Z[Z[Z[_[_[_[_[_[_[_[_[_[`[`[`[`[`[`[`[`[`[a[a[a[a[a[a[a[a[a[b[b[b[b[b[b[b[b[[b[][][][][][][][][][][^[^[^[^[^[^[^[^[^[_[d[d[d[d[d[e[e[e[e[e[e[e[e[e[f[f[f[f[f[f[f[f[f[g[g[g[g[g[g[g[g[g[h[h[h[h[h[h[h[h[h[h[i[i[i[i[i[i[i[i[i[j[j[j[j[j[j[j[j[j[j[k[k[k[k[k[k[k[k[k[l[l[l[l[l[l[l[l[l[m[m[m[m[m[m[b[c[c[c[c[c[c[c[c[c[c[c[d[d[d[d[d[{[{[{[{[{[|[|[|[|[|[|[|[|[|[}[}[}[}[}[}[}[}[}[~[~[~[~[~[~[~[~[~[[[[[[[[[m[m[m[n[n[n[n[n[n[n[n[n[n[n[o[o[o[o[o[o[o[[o[o[p[p[p[p[p[p[p[p[p[p[q[q[q[q[q[q[q[q[q[q[r[r[r[r[r[r[r[r[r[s[s[s[s[s[s[s[s[s[t[t[t[t[t[t[t[t[t[u[u[u[u[u[u[u[u[u[[v[v[v[v[v[v[v[v[v[w[[w[w[w[w[w[w[w[w[w[x[x[x[[x[x[x[x[x[x[x[y[y[y[y[y[y[y[y[z[z[z[z[z[z[z[z[z[{[{[{[{[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[[ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [[ [ [ [ [ [ [ [ [ [ [ [[[ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [ [cd065e896d7eb11e238a05b9102359ea370ec75b27785a81935c985899ed2df6846bbdba1149ef9edd39c6f18d37f29e5ed9cb3670521f142ed6d7d2bf9f2b8342d2c3aa4d008aad3243fd00e4723033e27e253289356cdf2cf9ec46135a8327bceb4f36b0f077b7a232a94e214b3b0a5a85152e4d89c193f92ddaba3ede1ad65c081409d24564f4f74f7a488fc8fa0da18cea310e12b7b419eb71f9e38a17fd565b56711615c2aa76b7cf84f52414b638a687c920caac19629026f06b36a4a969b6f31e27c5e0aa7f30e4d0581464b572332fb6ea658b7b83ae6e30dab1f45064162e5fb6a0727d80c5509356640bb6bed05c209c0a9129f2377d4532c9d2ca9246b319dd0837ef4f6ab7e7337df459b78629de991469c245b8e402f2c43278092cad07170e3bf6eb7fe9c893c0e5250433705da1be04424f574d83fa1b9a5be7795d7bb06151c7d1439892ca301506cf76fc374322f65cf47267aab87a2407d6823148fa4ba2fc488bac7a7c989af62c8a1eef9324049d2689d53363896c4a86bdde70e29369d66557d758c324d79fd6675e924f044429a0ca6946af05c89b3df8baf2284ef2eddad932ef4202230ec4701d363e3f4e24763f409cb00e0c8475a83f47bb2136a9edf6bbc7783e06e85b440258fa037013feb5b789c3f29c4b2c1b545f6b05803cd893b2e3ef3efd2a1f88ce6192820eae8965e141eacac932da41c98eb7a9f8c0c20110677e9ac9b15e640f88b0459da57fb56ca82b9857393e7e0db07206eca4942222164d2c4ac9354903f1acc1d9ad8ca11ad4c46afc80d1b693f3162dab4d15216f0dbc33edf012ee5b966588b4f4b9cdd5d189feb6789793c06b11879f224185b4e5b7390ba9d14e1ef2a38e80622fcace7c399b9041333ad426f694033130b62c375abd4402616cb70aedeb3a8e3506f92af99d0ce0fda3fa2df087c8bd2d86960fc0f2d44c2faf34f85b01acd5552fd6b692f4231b35e22d3b8edda6c7778f4265c8bec6a9b4885df9e7150d5ede96d31d893f09a77cf80e930c5e7bb71602ad8d9828dec07c182ff33331c126a24e76cfb802f63e1850d529b5de513dc462b9d198ee3a627c8239804301f31b107628ec8152f35e361aa950d1322970cfc5f32530b67fa596e8a4edfa9ef0e4fffebb11ff5ce993f2efd6c20b0ee0ff723da131227e90c8a971f267572cc82e1513be2ba91b08d2f8bf25a72ca5fa4b609785e6541af425f3d1dd614c0d04bd1f6c921daf5fe1abea79aa87e4b74fd780e17bd17285e0144acc3f5f088460e5d21bb51cc99286afed1f8633ab638fbdc51ed1602e4d21b52edb2422bb7b3b3d977f32d500f0379c566ac6777de165172a9c17bc823475cd488c1f3ab2de48d8761e50eac4b4f2acb1c7ea941db91315f55d9574879afa400d83a7589d7cf0973d5cf7f1c2928f5bc7af01c0ff490ce1e5049e8604635ffc7d1b0fc1babfea65940d75e9154de940acabecff3e50660a7a6301eae8f28f4f339cf74a42a23e899391cd4ca4269153e0b988288103c897e9e7e95179e8d1ccb78fc508702b46e71cc7c6047db3fd6309bc3f0e4a4ba4848a2cae2322732f5be84ac89843aff4ccc11be2b1ef283a0d1e2f31d67ee20b23f57fb479efd9f760a1f9e2ce1f50909d685c072e1cb78bd831cc378c624534a0dc2b139101227b60798c0e98aaad98a0a512054df11af901bd2a100316730fb88191c88589817ad0d05b29b1b10ed5e043a841cc128e2c75c265c465441a04fd898d4714414918673f11fa8d57dab52bb2efed219dd6892f2b9568eae102d1296077c8a35a3bc6df0347e657014730c973cb2eb8572d8a2dc745aa5c91a9ab8631ca577a8e1681390a057ed8e7a382af148fd20b37766025ed47ebd7c71f51d312bb9aba3937aae3fcf724fd7798e259a49a439a952aa2e9aba9fa3f878d96e3b31a589ebc8bdadd9b8efa995d22988a4f5df2f343c7a2f68fca2363a7c87d5f9879c1e1e48c60bdaa23198ec9cffb30f6cd59f57070a5c4ae126e00cc645e3eb8a4f5a0a0002e24b9fcdb73d270c9596cf35600aa77506e62b0b575feb0ee62e4d8022ec372aca77ca20e149513a595760bf61fb6ea6761115487bb765f14f6f52082a670f62e2f9e2fbd092716ca27af83ac241c1c3b16d451d7f4b52072e541a8cf5d88af96d589f611c003a74269161792196549f97134d24deb44591fa32ff99c9572864dcf535d20f29dce9e4800edf20b2bb75961f4d9d299781990d1312689c7b4e846d0ad9da1b8d6203ac7831d7ded4b9569ca8e33c27ea05ca90bc8331c621329d11096eee8b5eb1039bab005045c3ebe08ca6400b586768731ca79c4918fbefd2dc7fc530232fdc42f2858fd735ff9a6b4cd7c978c33e8657d91a1cff11a0b39736caa46c4faac93be1a3b44a5d0783a5382a23824e262aa5f3df1fc0a1433d58264bed9f784995b80a405dd07f1dbf5f188c8ef6939aad7a86c845aaaa89fbd2220055b0360ee1c31d70786f617d5eb80a29a0ff7f7946289544c6c81b13de3a60f6bf61186d50a158d0ba953bdb423f3cf80f9b6a67c56e9cbf0960f588cea60d7ecbd1b02b3128eafb48728897b308fedf974392f72119427e3556221b62e3be9992099ac014dbbfac71ff495244ceab1fa0b09d7b708687eaa9a60be52e362efde03f6607d9f883cf1f507a3f439076e5e234037551789da8284eeca34beb8a050f602c9685f5d97cbef2550639046f486b797c2b27abfe9e5659fdc744a804a23c158b3b13f49244d63982813d7b25a91e67181e04ad61fc31d71f82d17b05d259ec61673146b7f1be19126d75df2fef416fb107823e573eefeee74382f1084ecbe373ad11cc4585d228476b16e136a80789edb2c05b5d88c98d75d509f89fcbd3fb1ac7008af556dd87f89f735628146fb7ab9c7e5bdb5e367a37a3a72695984f837afa006ced5b0d70f11606817722409f5e500789b572b23bb65ada9cd8cacf84ee156ecc9511c6dc7bd8efb4e4eb1c789f60d7e75f1b2010064f260f429e3891acf9edea0917ccbe408e1e2b5f28c2f105915c1905c1c24966a745e771ab67a6513b92fd932cf2877b5cde9fdfabff7efb75301cbc8c84cbb8ee088941240b61c6c962fc8682b09d06c4b295f0ac6974e82958aea5506dd57e0d6e08d8965154a2c46867db8bdc2bd78105463c232013433be3f322d8fd44ea71e3842ce450ad04bf017faedc96c658f6c31bc6677553ff304bd4ba759f5049c1ef46c2a50a18765f63eade36e9de53c87b0671265a30f2cfe28c9ba09338d01f94fb29a1397d9b15423b12e292461396d4c1b52ee7f7ddc4ce0809f3b557484e66546b48953756267b49b6931785a2a21dc56225305d444474ddc9e28ae30448cc55491731d83ea1f242494a6bc612b261d986798b9d292082c83c065e01f87ab3366a5d6a023f0c7f5cc5acf21f3a83189ab28cf1b4a36f12b7a499ab825f221b641d7da8ccecb29bf8529caf635ebb0d404ae2982c726683b9b942017f7a4b16971a4b61584ab0fdcda799644d7b2044b963c68197010ede2a435b2c36d346eb90a9be347dd2d17acf3fbb43e702f11e3e0d9b329337f9bfd892fd88f58a09e4236ad2014a531612383292c51fa7b40c381f5ff8a7d653425452734c8384a97e61c1e96251e37f9fb782987d73f50e28df14151911e17eacabbcc8662caa18ddfefcd9426ab1209ebb6a5057d8ea5bec944962f90d4f6b81bba12c4c7d5e677199450b6000d80df6cf4a65021039e5997c85b89eaa1e38aa345b59853ef17e25ab4c2e883a50d93b3179bb81ea276a5eb70c59fb1ceaa671eb5423c9c758ae7bdfdecf75b366f88c1028efa6b4f2f46ff365341021e45a441196a419f5042a1e75a2f11300c97ecd4ff3057e4329d68a68afd86c9666d222805cbff7ba82836cd2113f43b5da7afde83ca5578fac36d17b1f7d885302ad08f0d18032a6f612de55fb3a88b61bb35cdd2f145b40c4bd87fb0acd329d4251c1bc5a481066d139cd21f374966ff4bd2f4556af5cd3566b95cad59301a26497d511f015f83df3cb7c37735a02daf15fd643cd332c15c35ad5d45efb5557ea5168356028d6b014837b110086e12bf9d7a3440a20529da115c7a0500e0e50372edfc4fe6e03dd21f9cfc29cee84c4b8d72b6099f66ea41dfdf15fcdbabe1ce20b778fd56379c6677bb5ea3939c72b1be8a48745ea100789b42221f5c003d7d213794cf218e4f7178f931144b6e3197e2cefcdf7485fa8911d2eb671927696993941817da87e3de213b22fb3f0ad4644bc2e8a80c84ca7d1eeaff7bc0a4a05d623d7cfa0bd7edebbd8df817afe7f0d89df0f972ba06a4226341f87e7881098b07e1b2f3dae724296e24f08a95da6d0612a51c4ce5d7a33757a13515d5ac69c1c3745ff76e5b2dec0ff28a06582a73aa9f2948ebf1d4c848ba1c06f7993fc80fbaa350242fa527951b9767cb0776e324f3ac5089d4b2d78baca739d1f6a174a328876d7c0ece33ac8d79508e7d9f10a196deaee0cca72935eff2ef24de631445865bf6400e85b5f00baecc961893a69446aebe6033a7d301f8d1710d0a625af65ae84dd18aa8f2a18751abc7116322ae72e6c46d4dfd3c8b0e279ac4ae0760c4fdbdcb487f844badf9d5ccbd39455878206a6d2de4ffc6e2684125e84e1e5a99d33e8aebe28b512f47f027ca6e3b52d03ab6f98aeb7711846a32ef0903f473b9054e258c35776703793e2a9a4f28e1251438dc71f032cce49de1d399892e6ad86e023334ddbd8529f08ebd8fb62fe612542162abfb8be7a6f651aa5cfd46adc81e89d1d51fd70c949b25a4d447601ae040ff1ebdb5aced20825c07aea3e7600c5749274ad53e2f3b40f3140b5b4a9aa8d9d0797406e72ae51457aba72fd962b477a98b539b95e001323627c670d586ce4cd41a0f735bd5a02fb5ac1c7147ec51a05a2b9e15e1773f5209f2702366743bd22df13378c590d9fddc31221141fa69d714955a23551282dda1dd53c1394828c0106afeedf395fb39d277314e5fdecb63aa96b5a167f9d2f479217e2fcd7f7281d6d9b9a38000d09e8b695cd180e097987c09b226f6cd4c2228029380c8a9e9b898ce96031f6ee12a8803144726407989f3cfe477d00b18e0ef978093fcfae1595e2344efcf9b13d78257ddb2572e6899b7bb6fcd6335d7c12f449cc8eb4e48b8f7105746e5332019882f4e41a5b99189fcd6d3003995d38a8dbbba38c67a28db0b10932111e62c61f24ad38a2dd0776fef11167a257b8fce705b05fec03386d261d8e173e4e84156b33550f71f348521f115ebbb38d3f7fb63f7de68fc33433b7d1f020ee6bdcb2c9709c765628de02718b528845cdbf208ddb1cf39fdc713aae6b6606e1b8a55c2faee3b281f40e7f9ad20522e4fd1b001e903a7e416b8fc6134cafc286e37f6ad453eabcffe0d6c9ca161947d38d1a4722c7540df3840df9461036db265c698d22c46c8c7c0d00e11782badf911a3f378fe26e4de13d07eae6d4ee3018c1e17764629fc1a448384a722a857aa1ec34a06b8c531aeac10b68b2f1d23fd9bcd8c99f7e2b57180a27f6664538fc282662e7cbfef7184f4752a896e8b85be1466c1305384b1b3097491df7cec4d19b1db4d32190738b17beff0a525d85020aab551a7ad34bac6a12283c5d6d00c99c7aceb9a6bc36f1c65dbad5aea16ad22eb06c21db05920ef1f2ad6ef2d8aa5c726981849f959102b066e7a772f0e2820c5e6bf93841ddb53b3e4823fce8ffbb2730a835c7aa431cc7b2538bb57bdb13aa1bb9bdbc2ba7aad48dbbd43ea6d2395a50dc7969a36433df81bcf7522fc9b624baabd263a9dcbb58d406e21f4a4fed7ccd870ac5001b31bf912cb21c3ca775daad65c2603560f361feba5adc855a2c2cc363d9cf8424f8c67d8760a69f8fa0fcaba3e5ede7e974901c9ffcd70657ffaa5b586ab86bf296f15c599eced7f508916c94c363118f0a404d45d01fc5918b2ff578137510d75c89792cad328e49bed183356a122ce642b83bf784b03475d87df92aadd2fb14cd04f4ea2029e00aa544a6dbc272f372d5e74c3cd400271adb43967853f4631d795572fb347793938fecd36e5b94735d90821abd205c6a7254809905fef7263aa29b85340e3421620d2802034e718067dcc1e8baa82fd2fe7ed6d389a55df1163c84c19ba5bd74c58395382264cea54d194f627025bb6e7a7a6387cf3d6a2e54cec12d694b29a00bbafdd4c9f53bf085acad8a72d7b18956b37e344fe0377e30d76f2c53df40aa8155f4a5c15aca5426423523208b51ed609d8705c1120dc87cd6b11e0a74d404f8eeb40922e7bd2994afa18dd3aea79e2507a2f3c0a55f6ba5dca5a8a3d0227ecd53ee9d996db599bf8815e67111d782383c446c2a955561587986649040eee0b48c0515d4079a218ae2ec586a32dac4d0648ef183c2e044448561a46fd5264cc217857e5211c76fc5c76d71b9523f955366abd550039c8742cd20192fc28e0578c4cb8c1bf9ab95035c044838cb9106c22ffa075fb1e09ea7e9b5559d3667b19e3f5b966b7ce9920b2073a40a37948e31e883492c72cc448c57d05409890544078b2e5e85bbf13dff349e6ae6560a1eff3f615daa4806ead43b6aa84c84deca0119bad66cfe812bfa8d04e4266e4104d6192cc11c21c246d710fbb5d2e1110aa35451b6c03475ef46b76b7a97d669ac2525e29ab4163f7d74811d78e1162fd1215b2c0036e3f80288b9f27d223158ed6504bb5b469a8f563868d7efcb165fdb6b4ded2055580b0b0a4e0b0e4f87158b915ca9778c927f98cd31437edb94ff0fd357ce3fbc7e423357a06cc19e166bb0673cf4098de8de13c60d6572371831d51ba972fbdc3d4234dc24a68ae2ce877bcba71c7aa0a0e37195d5c61052027c9b142300ae30f897641aff91f4773b4868507c3d77bddfae53d4109e852d79c85181e7fd84112241809104441187af19ec0cf6cea86d1ea0a522299a9939dfa5f039e4626ba3a8a3f76e128712bd3a35b7707290a71598776c8ee8111849fe7e225b2417f5a4d5810d7af8f8dcc1a97367529e8ab7f357799c69189d452650d5385a302e755c1731c6dc0b3bf7acd8575777da9cd8adc199ba69bc892be9b86efb4ac3008a23e16590fbdd12ae60e32f5b78efb1b0faad599d34ae55b4fb61f837d1f1efdfdeedb03372d52c013dfeae38cfec50500aa6531cf98a99b98dcb368c3a86eed03929779ff80075af586c3d73ca39ed5520254aac74dd1e79f3b9da350c07db0be4989dfe6f2a96ba40d583046cac04c3184f31a338bf24204fb5ea0f1d6a3071a803dfcda854eb82d5b3b95f4eb8686aa31e6080cbd74bb9391624e50e2c655eb447d573fe8ee68359c8e5a258eeaece6a7077272b615125f5cd12fcd0b140b884c303a62306e2132f77fa5ded7f7ec0cdf9c35e3694ad7f503fb1aed09349e0a651c63e4f7efb888a73d0f40d51ad1a0739b36287550e7dc4a1a0821a771723206abe2b56e968e7f6c09672b094e2ab91f527ed1636e41a965c17a19d469d98af3e17d870c36f95c5570c9db2e814655ab6413099719f516483eedea702601bbc4c986518397f9545ffbd9163d2e9f5b2dcf52051eb90c9a569a73a85a6c6a3e61a2d4de4dd752948d59322066b0259305e775e834dbc9f488b1e018380e2bc57529b36bcb3682e61aec44974334a624f434732bc359b9b77a61c18e28039f37fec80e65b1a509575c50bfad9cbe66b94eb499d80e8dcd044d2935ddbda25632f6f9f37850990e1a7722b8c6660ed228fd646f1b6f63bc708b44c7529e47267679d7a93fda230385e52ba245936c933655a2a648e27cd40f7f67486c7b3f359f7d23075973d61051d81da8b89cf62d49533fe34c12cd6e9b4fdadc50c0b517106b2a45a12971dcf693f296998057032b203ed9ce4fca5234e933239c008268e4749345f03a085b74403343ab2921b8b8138cc6b3eb236a1988afe953a699e1f1dcb1d59359c00d8cd0e35f57248b74127cc7566b97f048afe5c6687882c0849f9e703c900d3fa9f75b245633ab72f4c9113fb6cbbbd8e845d5d4b5eaf86c7921cbf74950300743ffa2cfcc6590a707d3663ccba453610293d071e1d1500091fc06528e225954f97e78c038ff7ca9d65d3f11cbefd517db99050693db4b465314ac35a2aa7669b17112b8e38d60ca56c09e83b9dea7ee118ef7ab42978498ead35f7f1716ddcf5b0893a79f4f6251dc86e76281feb4094d05af37bd171ad4b7e85265e4476f128c2b9f7c93f66b857be7ba2b82c21c551b5649f7769c6fdd764e83511cb09976b21acc3e8c06f981971bc269a2b482f5eedf3ee275f7d887e135c859a8dc2675ec76b35f10e4b9945742fa77d500c74d98fa5baee2cbdebe051adf56eab750a0109771bdceaeb934a3c1e522520141276cbb4be155dc57b1f3efd0cade9c78dd393cc1aec3fcc8cfacd8bdde54ccd5d77f1ce9c1c420f46f22c77955dc90793701fe5faa6d2cf1c818409a16e137e9b74173a594335927f0ebfe2be0de3638ca9fcce693bea886a2494698dcf315a7acf2dc0d1842a5a23c1f434b3a09817144933311d07dbe0f3535a33b35ae848f93d9de6943f8d4c1691fd8cd7394dffe44609fef0fa704fe478a7ea86f87f208fff191c1ba903611ada4ca4a3cacc5381e54210412c6e07b8f6e0a022d920bd8f197a9105f93078475614c0901c94f71f754647032b678728017a035d2c2ea540bbfd078965605298cbf66e54a590e4bde95800524564524140d657818ebc9d90ee9b83059446133d19aa18624eeac4ad53371e5cb2f5c7c8ce358fb726fceb9e5f2c5fc1f7e1558b3adabdd52b21cd556343cc80a53fa1b639556535844ee7a11c39bfb59857efbdb5bfec8c834d6a69c0fb91e1bc709cb52a51452ab0e75e1e2b8d658995f766d42da9235b427f4425ff5c7cb325b2d9151144d820df7901b42ca5c4a40ab8eb3845151b6121339a286cedcd6ebab6b66bb43abbdc40cd27508ee4dba8384f6ba3197adc415937698eaa75a64bfa9aed3a1a8f0a75631c7dcfdc786cb97d277e2028df72cdb5d75c02d82065831ae67a294124839a4b3226765dd112da6a10d66b71bd929e4687239e4f8990f647ee0cd8bb37a2ff6fa704117199309948cc25bcb8ffaf01ec750fa5a49970d2464f02c666399fc473392473daf539d5490a19b0bcba381f3a2b56be52d8c20a3024d943ddefdefdb8b4ab0c76de5b68a2c36779b20793d6f1dcae650b75f7d9e34bba0de20cb8f02168600ab984991cd55a987d0eec2d6c6940e6510a2b4bbaa4e67dce8dc696085468ce6610f0b889b369ff3d75ed7379b94c3201cefb81065c2637c584f9aaf81bb1fa5b1ae48744f4bd5f6bddff6543ee993ed0a7f720263d572e9af4a422a978d79ebf8e20b7d10d9bb1cbc21232923d8880f9f6d8f4733a71dd6906445881591b58657ed26e78fd2390bd8fd15656125a9e4aeeff06e5eb49aa801f7d4a759257a94c6a33839b88b35f196a58c6e6141fb3e32510b491c5136e0d09fca3eb0136136e36eff15e0d7b6568bdfa634b8b9e5950ec4c84c84ce4bb644b99cf1063a2e9ff0380929c5d761d291f0b70d62fc9a0e93daebb11a9f94ead76262d54291d0e3073740a5b388b4d3330fb515998d0cf2b34aa2f001062053b8eeea0965267e0501bc36cfb99f4425437f952b5f783561a6135b4478d42cca9e71bb62823613b2eba6a2370a779425e4f9e97855788381d3302ffb09a0b7f57a7ea666f16e68dae175fce1bb03387db4a8dca5b07a251ac27399bceebb33c1e13789fa3a1c6990117e22383b203dedb4c041fda287e537653abb4c500255824b501b233a36c07f8a518ff7f3e2fa9556f558575c7bccf315342f11801ff77df010fe7470731ffe6b1697d9c729bb188ba1a951f79ea668f62b22a07e800a9f578920ed4f2036f52c10b3300a3f0ac26f8fe6b38d2d2b218e28191b0a688216e024465b84fda179f8f11f726216f3f5099d25ad211551bc7a97a6395dcb16a3e281980b78d877b1e49191f3f2820f404001f91bf967f9eafd5b7a38377c78f4cac73f05d1d09858b2c48b1c38a26624c650ca08f3cfcbf95cfa161e11786e1ef8952059667507ea9005e8c876cba178c0e96a5cca3d997bc1780559e93e22fae888904b0d4e5030bc932b3a38fd6615cc485ac59e3947c7beef5979874f5c388db962ada3e605a7d7a0a0d06b4b17d9a477ea9975539d98974342fc77ab92cfe42eeee29099d9972cebee52209cd979bfcd3b3eac89e9a73ebef5efb87ac19cb9c90703dd2f324858c458d1ea97a6bac08e4e96dc21ee7e911bf4434f46378347e1b418384ab3abb00803b5295c7c9648bda3ad7f8f50fde0f7b5ff9df5d579fab8c4cb663d050a6f46d63d77b36e0d624b7cab6f73598ad635a0b665b0e56f749a41a65ebc13348c6575b40f669a6ecf15cbc374fcce099f21251a2b0a17a8cad24ae6cd6f253d7bdc93f7b71e21cfba403e36312c6f85dacb206cf9e658ff00aafcf949ef9cdaea7118e5948f1df48355dfb3fc4659a68bf63a705bebff06cc0a8c1a04aad0172453818059ee863d881dbe009690aac268382ea490dabe197cb543afdead21f8384e7ba788dab9de422fb5a5f8f6586b4854628b756fc41c13c01d6bd77a03e4faf8875ab9ed09a1b2bb3e5d8a2710cf4a7acbd07fc5881223fc16c07e4599d993159437795c3af5a6e4ec7a745221e158808f3bfd31aada683435971ef3f43ae2000437623a32bd46730751aea56d1fff99be9ebf66c05aad9c65fa5e683c1abe0050495286bbcf75d792caa85bd1bb71cf68758c2ae635fb616375aa9abcdbb78e3f3a5c356a173bd6f8f0e7603d3f64e2bd5b5572de178c065baa04595b918723e44b70992819dc558cafa0e2484f66816534932e26cc8f8341fa5a3efdf0fdd2da39a96e57c10ab0514a55ff1495ed571180f18071c22bbafc02ca443e56256b23061ecc1bc6d6fdada24adea9b42421dc02422ccc81c02ef6c6ac089c5646f3e42e144a574780ed1f04361f130a87f2dac84f045bc07d329c6b537369370c8c59233750a6b93a60477f4795d18f2c67223aa74a66f85e021a823f0532dbae5ccf4ee4cfe0b9c38008f3ff82b39205088bd5652e8c4f738f80664d815c97a64bde4e98cc06d906bf64fcac3e96fb18c27740670b458d45328150c56dfeee2599be167b6478c51bd9902bc530a605c12d9c8fd53ef88a9106deec350d6ffecc0bf4c999dc11c6411ded6ab351da0ae9e396682b189408895c7158b485813e6473b698b867c8b8242a1aeb362a2d4e4de55fcfad51869bdb66985c35838e2ccc74a5d34503ce81d4af1656ac82e6857a02da9a23bfdc985c36403d7342907ec1d3c5ef0c7f6b4f318e9571d4e32406a378493901cfbcc81b784dc8fc6563e4c1df4e8b6897dfde05634556afef6daa90d81e4743a8e9d4c3f069326736d47eedb90ab708fa6e91f7750e525454d8012cfa5f82d20de26002c28fd81691ee8be4fb049b958781b96b69376d13c31fbbcb9d135f34fc2c1e1e432308562ee298a1bb9eea7979847d9e254567f0dd6cda6f58684eee1931e2a9c63b6f6c2d2877d860cdb293dd9b87939c1b1e41b11a174375dbc68f63d6dfc5c94d83dc24fc0424313630c2f6cb520b8c0b3026bc908845d1bb1f9adbe28ddcc4ee5594cbff721590d5100943c1c59be26a095e32ad616490455c50d4bf44dbd2dbf20d0564aa53647089eca232048c63a498f3c6f033ec62c55cf69624d0ab9b90681b627c0587f9ed819868709ed419038c775ca3bdd2b899ea23e65393eb50f053be0bdfa19deb768a2bf46bea4ff839780a89ddd65491bee3f7561544fc2e4ad7f8725fa3a98657d95a4fd6d3a0f088d9f7aa15eb5943b497ecf96b57a58801624f86c57a3a4550be99abc4fadd42f669ac21872ae7b5dcfd0b840f2b4c5eb8e9d4d2f8f134d099878a4380d15be1c65d28229a30546e33d35315e47c8f55283aaad1b959ed045777ed39dfafad8806b95406bcbb1f06c1dc4f7b78c320899db3dbaecb3e3668dff6ca6242aae4d9085eb1889721ad678626d24964d0dddd96904b09928c3454d56e096ef0f69b159fb267661ce46f892d043522e29c8e65b795b9ce3962c22b4daeb737e2440df7af0357cc5783be856b6861601611cde249553509a4a9f124fcf2ed69fb70b2fd13db1e53f26593fc47749336edf4c0bb7decf7f12751ba03c0bf2d58cf729743f3083d7fefddc21c72306d39b096efb8e3a5d2a898fab3e9022188ca8f2659ba3821fb2d0436e08f559f703b0431431e2e3b647c6e3d87354120b9ce2d71e50174edd6a31dcdd352edd256fceee40920de4373057f7a43f86dffada709364af3ceae34fe9578cadbe52136bdbeeee9f965c01c10a4a8de5447451d265973a904af8c5f665f6c9bd90ef4f6ab118ebe0236e046dbdbd3a1528986385fe5c24ed9ac4b68f957e5bf91210d37ca3c686294f9c5c48141f2ab4ca2e0d1969998746f39be288e66b0b124b10047ca861774538cd1f4fb14e52cb1b4671b748dbdc662266331cace8b1f4be9fe8e86b73bfef1d3f02a982517add712e7758da8792a98cf1cbdf4710642fc23431ba2f53d3de95a541efdf7fee3d68c673042a3704a69ff547154b5cc0a17d807de4df43915b51317bd1bcdb342e458d7e41911a7a325416193e534af8ad7a30870f4a4bf2f5fa2d8a1b5df79b5be70e6f2c04702db9e98c81b94dfe02f81440b155ddd23d0f56396514cf9a833f7406a31d77601bdbae7ae6ea2a79b50e3d38539476bb4afa41db743e1cf3ca7c7ede289b1982f4e4f7e6933004f6577f27e88ef1b9ab3662933d1b0c707cf23d2299aa0428de9b0658fcb36d4a8eda819c8a74ed8acf9dd28772a017df731068f97c2b153c7b29801d765a89b71c35f9ae164423e6a6cc44af6c5fa86c2c0a5f8299ed88a6aa289b36bd349950b3f6e080db12ac9b25c9b4de883100513a23be77c14b788e79abb94dee62c5d5e59e0ee1889faf7d13c3b73faa4fbf779775d18a997d2644f0f15fd275231f30bdb6e87bee0c046e9dcfa27e484a1d1840c1bddf3785b17daeb9cbb9ab965c35e2da7dc275025e36e1335893ca46d89364e94de0d6f358a891e37effd51de75cb6003e917c6c801c0a7fbdc0d3931af7e1d63da19adfbb25a205445e7ade8ebc67d07703306162adc458748ec27b9f7f333a0953791ff6de38369810710afb55e4e589ef1fa8f407fb13943527454154717be2b1cf407207c601adc61ed2db8c98e8af18128251c3ca019235fa3a617867137a0203e51d8050c9aa1c2d22b7168f316c58ae52a084d04911aec1abb9ec3b29bc89466d538a7c5298206ac2432125e3efe2e29edbb2dc84935bae6b3244729cd49a3f69eaac4a29cb98738e3ab6bbd2760b7707c9c8f94a314aadf3033408be4e74bac07b1ad3d2ecc2e3e3aae0f781aa5f6863d5411aa7c328b4ab3593338a440a4d2b1e8ba53f7b21482d2a1281d69f2572cca2a3eabbf0415932a45ff6382f1fc04d439ef4d2e70539ee15a642abfe08306199fed867fda82d5a211cb7a5fba266df054ccfd68477f4d4d01d020af4ffbc49a208cbe39f1161ffe7e07458ea4fc73b968dfd8cdeb8af35c83a9ca70889e5a8dcfea53cab24d4ec15e0ea350b959948d277a46252a2b4ed6f381534b29cf01ce4d720ae71ebac6b6af0fec329b575fe8479492b6a2ce8b292c0bd236d402f4e89b3c2cbf46b743a86fb869c9ca8cec89515b28510fd22f5a988620be29d8833a5ea256b09bdd915c73da3d8ccc2be8046d2424616426e6fb31eeca996a19ef2a6c18e7e118e5ae95757e166c76de9e03f24d9d165093f1115d05d3190ec0d7fd49b13ce51c429a5850242d2e97e6081441dddae4d4d447e74429371edfce5a9d961e92f9d37caca8e047f9e4420bd651a16463da3fc49b4e0897e22841333125355dab5a21c92d5f226052e608b3fd5313de48330ae751fffd9421668597121d4ba4bf2b3e0d2b3f3fb083bb37f95cb4970eb66060c8c967b5696dbe3342cfdafbfd9ef90c6b8236b81f4f798db294bf62b5dbf5383fcb81488acaa4d218cdecd2589b612dfa6081a18fcffa9c20bbb7468473221929392590bf36f003b6abaef9d2abc2e6aac26c2d9d3761d6fd435daa91bd096fc90e848d75f8dfa3cc59aa7596e59fb83c0fa2301a83341edd487b8d35a1018c3c5f9cb5d4995a44cd581adae3c1a5429b0775ed65f40daa6fb23214d55e79ca86c90b3feb4fb9ca579585bfebbba942ae13c43b3739dd3dfb1ab7e659337e8a59e98ea82638e5729ba64878013810f21ce4292debb467cdabc7df39aa0c66c8c339cadf3a9a9d8bdf753b677d088b59e24e4cd0de3818efaaa8bd4ca462b1ba33b030d862fc62194d4b852568cd0b77da525b6e3995ca27e2bc7f3a14e76de46497b477276b9b0a522621e31bea5c7837235899ba23da3986157a3a8edd08dc6e3f1338472bf2c4ba1a62ae08b72be49a4d2e6edf881e0b1e196082707e4930eba89e3e314cd755eea17809b2b47726e6cf29e909d626e5efdbf96e8948e0cc9bfb9bbd6ec8807afce170740e021fab53cd38c429e7e9c9cd53beb26e2934d0c60fb370dccdbb0885842b67eef12cb9780a681cc2efef37eb789b6dcc166ed4bddec19426c925fc01f6cd3dab7e10aab8a6db906befc078eb252ae3e0bcc3fada8a92898337ada5739fa75bedbf0a7b341606d8efc81c2e09b2103e937baa5072facbcff904d3c70524508f28d0f286e4329169bac1072c12517e083f4751e48dfc237af38b23360b8e50ad251791a47e249d47159c84cb2977c4347904993188eac242d18b3ff1b368d0cf14862f7be919025940c00abdf3ef5ef653fce8cb6fea1f2a8d7eecd808e7a49d74330f86ae08a018315b9d73eed07a0ea21d9b83637584276cdf8c04b094c8ba21340b60293335be1a4c112bed3e53959bc47e2264182228d6cdc1a1e38df197f97c183df8dbc81853983edbafe061d153940201719d7c9fc1ebff4aca064fb3258d5025f0124ec20f97ac6650a5915e8d480a7a6650cd502d7876b96c8c2b0d34cc6ae29a4b78d1982fee62b73274c9a123778bf7cf504cfa00e49a85136885017409a57cfa6daeae2ba2be395839414d5a7da31557c98b8bf88370265644a1da66acf98270771c39fc3224d52f9221dbdcf5de7c1dbf5f1d2506a5260a0dba08b7139f140e756945a2a71e69924a3cd51e260cff696ba6de47de9d6cdd66390ee7d78a0a72366d74b7f219695da356626ed10503a68ee834ae630253a2e24cf3b989ea521270a8c06345cff5c0fa1f7d98b115d5c1ea5d08c16713da02b405bcd99ad0284a8deb3a9c9ae1d5fa5c307f9948ff79f5788a99911f193ad7026d2db251b6c3c36d8815603b9e07bef817520bb3af13684f1cde88ff8722c95ea3f99058adef4445065b4078cca678d5a944cf75ff588a258822f22bdf64bc907c5a1d2b715eacfef340ac42de204070db9fd7784d0d24a2dc4c12b24840b0eb6b80bdbf822e7a1f2e9a1cf636bd0ba11d009c0b5b971b56bbe73d57bfb3688acbe1d4724cc65876772a328ae3a6f0d0b2d368258579d69cdcb0b0db3c12c6d34f97e750efff7e597bb488875fc80b955741a770c849fcb0748976f541d34499659ecdbaa153ce82fa947b5dadc429ed00caa816113659b587c37ef53bec16cd6e7f9ce9f23df392f20483f7aa35d14d3ce92eb557454089e1b4555a4100dd25f8454cf0971ac364d5ec828c18d912ae4c79156d052976983f1ab9482e64472e77052237594d31c80aedcdc5d217a2618c5245e3abe405b08ce939da86c9004116c085babb5c7669180a3b194cfb4b6c961379adac499107d09f881f904737bfd9822a69e1d4e06014144a94063ccc7340d8242848f61771dec84855209bb85abf283ae89fb9e46110517a90fa84bedc5c9c68d33b2f819bea50082e76f0bdeed6de82ccd3b0888095c01164f1440fb718cb335f422c9dc06f4d711b29d38062aae66251dc508328a54cac90b8164c66fa0cee0d2f339b5eac09142a21f1ed6c68c55ba44998145788a7d77ca398b0db46963a8f055b47641ae54bc29d801c03e4f23132479d187d3bb7c03b95279022b87556be3fea1c6d3727d453c1cac31f1f46289276d8cb299ffb1f6708bb2d306166bb112e4d99b4c5d7c7ba91dd7b036aca3590b28f8827a5ede2f3284dd93801e95ae3650da8080e82a5682d061fc08958504e9ae23b3b91408704014df382757b35122edd1a7bc578b1b4fada789719987520694f54587a9b8f38d7e7efc7698e714c7233253076e6e00f72c15f48e6732fbedefb706c291f9ba8aae95f716d06797b26e24a5e78bbd3e3e50ae87c9a9e296f567f351001ea54eef9c05f0f702c30b5b00fe34c7b269a0b76c67c7e3c29e9bd245c13cd00f1b9445b558288b7b43626b210b06088386cf3fe556a9bf4eccb01de1d54a3a19fdf334a0fad4a0e109049ceee15054ef261af9317e2819cccafd387a271bee60b1b1e2861d3c32d54a9afd3943912d589311ced7e6050c573cbc6f2526c959e791f1e584b3f22d382f6436f947c55d9cc1b3c8948a2fe40ee65fa9fbc1117310e87f5887eb299027d139ec2aaf88fdefc2d8652bc5a44d3e02ec581ac09f833bd040923d50424fb3d870858844f9aeaeb2383049a2f0b865e80250dd986cab0326ef601c2703e2d1f44478f42f5c85fe4aa3014e6e00da960cadfd011ab438d3349416ecb1856d5629ae7c0a2c24c8535b63057e5865f38c88d6f6952e1f7842e347bfa82ca05aa2ff9277a8a3d2da6b287fab2ab68b32026047c5bf97925f5237f7db6907434102180a7080a0a7598830bc0537e1f7215b248df42b5142630a15e086b2e06072ca3e67df3504c69064290b298667611a4ecb87ceec4874145914dd65895f5e64d3e72a5995c1f621d8ff64f069c7c0195cdd93fdefa20250f60a25570737ada29e29b6c423c2f5a5d8511fc333a46e3e5fab5b0eb7074d39c812a53721dd82df3cf168e477c20e4d86af866dc1639716aaaba04556cd9e1d7d7c137820216fd75629107ca96f17237cd1f0f6d1a643c8ecade79f2da168bf1cfd4fc4404b8d29c3405d445bad9fe21912e1c8e1deb8504495c28486cd8015d3947f54a636229176ed311194ee8eda3226401fde3ed3d0c767856a8059d927764dc1304a7c57e6f65df88d7bcd680a24f32811bc7a9c4ccfeb730b2d95d88d56bcc8c66114c522b5f59ba6ac21fa7a0282637e6b2a8524cb3a8d70b4abaef83da8f46066398ba3229d657e08c2e6212c65050bce57f45ea60a58f8cb546856a672310fd261492dc7e63801dc0440ca6182b72cc4ed0359f58ad8f3cec4789a369dffd13d60b76253b45fe12f4f92ba2a66948532cdcce7370eacb5ad9b19b4da4394b41bec02de1f2d2afc8a797f0a349eea33c5025e4d076f43731fb8a8dd65b4779dbb0321256027ee289fb63fbb474d029fc97e476ba167e999d7f3548cb18a15fbb668d202e0dd33b56ba1d51c0e9f939db5aadf826b7283f4fc84f20664d2756a5d8b3ae0f57d4d041ba81e50a0bfd7ea117352a11cc759b60d37055a70dbc263978242e246b07e7cf7cd9c9beaf6e41a3667a46a7d7ea7b4ceb35f0adc5d5868201092ac981aabc3f8c96ba8a35928136f76ef9e99abc234f676b6c5ec4d14d261d8c33926807726247ae32be5ba74a57fee3ec2405bb761366d6d921f7870598afb7a5c25c04a8ebff94b50181f8028376e59a1d217cdcf1131a8fcabf8accbf28e0c30f5547cc2c5c14014b6c59e4052b2856b0b3ab8a911ae3384ee2496867a8a8ddada13f276337d0e418dca9e457bf319c03b735fe0370844af9ca4e436e5d0795e64a01b644af369abc48551a0878440d8b963ea2bf3226358fd8c552054f717e4bfce5924a5d33ce8e4492a0f974a9026d21a4694356c38d39214aefef787c7856bafeeb4c4277f1be0d1ee14f6bac928190b0ebfb46efc9969010191fbdd8feeaad3443ff25f5be4cde58b0757179963e485ef0556698b62a543ec83d710d469c19259eee5a9ed7c6630bda66b47e15150e38dce06b4ecae83f10cdc8b5dc2451a9c9f9bba25417eef14f3ecdae8fd332dea86837c5fe42c3b48878f4e60a8b2772c77cfd24e99bf8ce29e6d535fb5c6bdd50b7c5c96eb2e6fc05c1386f8550f4f5aa05dfca5bb5b2e1a0aa16f9760da84fbf58a6b965dff018d9b0e703a7f2829e0455c9d6383d8b6dc5290ea380d5abf3a0912d734c08404a1961cd021ad6d0f12e49a65dd26400dc646f58913d3c41f6d6b1cd6362e6ca545a4118e0781353b6dae77b11e2c99e757d0632c93a0dbe72420c04a1bfc9a99bca001c68dc463bd93ed4195ea555cc725d64092779d9611fa532f3164a6772cfa09ac761340529aa85f8bddd3a042df6ea91c69ad7874fd3fc705b0f86da857e5e37842e26c27d518b9197af49fa00e1cf1864e244f58ab01773ad361ed70d0cc9ef85c4658f3293ead56030d1b0d9ce271f9950cc48b6cf7e7a4c48af77532cfb997c07cf8865e6ec4f2263c6da5374737ed61b5c1e3977172e8768001a8881a910faf3d63780002c2ba8b493e51b8442a7ccd8b1be55625a896da89df9462ec7517ca882e535b81ff5aa74cc3b321c36aacce9d9d0665b0857e1aa082490bfa2efa8fed01484c10cfcaa73d32692d2df87dba1aa3e32d7272618a02115bae84187fcee4d9bab2c2fa6dbfec03c67a9f173a43b96e8139980ff74eae3e13850932dfc2d738547a5c88f65678fd11bef5a0ee38cccd7d725b326f7580f8504b4a7e5595d9c238bfacd1ae94df3d0f3ab821fc304e03e5cb247a99d2208a20de16382dfc68e592aed3918d7721820077f1b75832e2522e97606375f748484080c848507bf1549e1a9ca7292af20439b42578a3eb006d0cf3e98d2d101023df4a35de707fc0a94ddd7db06ce2c505fdb63aab6c11f03bf9fb5f5cba6fdb66c3071440cd2ac404dc266145f26b9bfc6d1a2eeb9fd6db040b25043ddbfa3017e35db5d3230bc718ff4b2388a315d25b642be5e7825dd325fcdc6014f5fdccd1aa074adeed1f883f5b955cc32eafd63c08e85ef20f9f2c0d6903dd73a02c3b30b9ab1362a68a631701b41792d70368b5f9ed07ab2d6acb788eb8b6699e45d5a57ffdcba6d13ca8fcbc21cc7e901618aee646f2f4744bad6365bf86654b3e0be5a984026d79b8d80d26339c89765dec7330300c5b4df8f0e80790eaa965ee18f873c8c8d8206c33c637dc7b786fc31fa793fb6b2fe5f5b113cb52ebd8d313d01666248e99f0f9afbc26613dfe0f252439dabb192bb2a51e6fe73dc35932c3d90a0e0b3d35ce929c86370db4fb1eecb9694742b10f3f83eb64797fa9889f54f8d0c5f43e1e940cb4f2f36da925ed01cb5f36611db5f465317ebdb3dd986db510c98c629a0d9d8615549c0b4bbdf8b984b67de5ab2ba2cbd7e9773f93b70cfa3f52a59371ad3474c6524aefd7e50133843c6da61e07088f0a9ba9d34410ed779d88a8eda0cd8cfb51305ab47dc27fc8adfa227dd23dd578869ec3f92568b4355750400f25ddf989ad3c6ceb222c9fc87590e2118f0502d9c3bd4fa1cc29bdfa2a44001e3419872559e9bba60e1eb1d42661ca02a07821c9715e231d16659037bf469e51889e0e27629c627136e79bbc506b5a893f762e2896026483ca27475c3b314af08f7728ea1458023e215a2af74a02b29c883c90ba88131e43813c74fe7e208383fa4406ce988a1e234d137d5a96677a8f18ae303c391086606d5288c88803b1b2edf9e1d58bbc93dc6330278c3443b20ef45fad78cf0383f5d3814c738af4cfc2d2c32273eeb7af2d8cc6023dedc421a944bf7ab3cfe33c1551601e66e435bdf88cb030787e3bad5a072d9f7cf023104f9769b5cc1bdf7070af5d1ae2b7404d623952a9d42a7e9f350716c94d8fceeb20ade715f14feab9eb09717c056165ce7c1befe2294a8a5a7da2ba384745957bcc2753e4ad8922b52bb2a7797981120aaa092fa36ae0b53a2f470bdf2f388279c9a2e8550a818ddbd7544003fbe0142dde74f4932a6e9491eeb817de545a12718c461ccae0b860101361901e02a8d34cb4cebaa8fba463751660a1752edf7ea378bea4b0f7ed74d05af9214a36e560b578c2397d911f9a2a90603f440c8a036a6348ccf3de9cc79da389259cf6ce85eef0aabfe1097cce788d9d5f320915c755fc6bf344adf85a5ececac6320d80024d2f094875d5e970d196546f92837978bfb6cf89c5b2acb7e40303eb32cdec8dc12aabff07b6acbb23c415e88d76c0294ca1de64c6c2be949bb765b0aa9eeaa9b466f6f159135567e16cd70300576023789b53e4f6f0cd603c34a0cbda9e632a9bbef95d9dbac6d5105db037359ea6658bc9ec4b3d4847e9ce576650a8d1ce5a5298eab096a5ef99a687a756cc3d5290a13fe08557e0afe27d326485521cf2d5338eb526a4278d54a520aeb3f04b949442e07876668936526c9a26b8851443961337f2c7c2d49d60934485a64c3c32f69b8b1a93d9b896dd634e35aef39d110019186ca1e1d33831057ec1a3565685566b92745a905000a716f923781eaaf65f5170de522bcbae1ea0dac8fcd93d7e26139c995c4d67dee6cce6a110804558e49aa8600b872411b01554470bffe128dc152acea48b7a4e4f84e927db66edb9983ecb66f4a8659f915caef3bd65706a28ec8a8d4e838deeba7c159aca2353cf491cce3701c23f0dd63ff4b9123e0e5f9d34d888613b915218ccebaa22bec4a6dfd101486be42abd8c459e69fa5a0893c7fb524e204d809acb490d8ae07ff556a5a56bcfef611de8184e19a0a7ae30ce9d394428cf55600ec4a2186d1963d6f80bebd6f105385b4210b63371e43183410763415ec2763339ba75273e0c3403c0f833a2fb579d4d0ea6650623550b480892fc0307100905f0fdf767b0d9b45e780f92581fc47e087892a7ce67ef783afef705db94406cef4097accb7b06897fec6688d3b36c94d1d2bc5264206535456dfb5cf4480ce07879a428d7f3e517b14fd7e3a9b527640530288903e5726dd2ddbfe4ffe08be4813cf2891149d2f489e01211b12c61f92e8a4295da63955d81a199040f51413eb68350456acfc7c4c469034d764b2fcee57808e430d750e0621d694d8877a5c8c8f2967213d5333a21822eaa2e32d6c6cc7d74f8503a6aac8f43ffcee7898b7a6ad83f65d11d9cec53a70214fe80a8cc472198993a38668445d45f40c587bdcecbf7556427e8ff303ae0b5483c1612d654c6107747f5a82121e1e5edd4f80626fac0642a47042101a30636e768db28b1b9be11485338579b4d404a1ac0304d5c62f930ee2219f72df53e1ca950e897f964ec406b433eab078b92f994ad1e0550b0e5df79f00c12a5deff0d46790b19f5d860077f86c8bf069175acd73fbadb43f5afb0caeadffceefb0c54386815655215c961e471d611efaf747b0c9c6071166445d712a4b22c1d499d03d812106ef8c7b3c3ef83203b74a6ac91cf09656af1a6f7e652240c1cb2047ce0deaeaed443aaedb712d212c4594faaa8dafba5ac79d3fa03751fb47a1bad4acf9ef49d5f682e1bcf8a1838ad196373bc5b1171de7c2be9a6761bcb813e1ed5585eb0007c74017205e7d07b73522b956bbe3e39946bedfa9414e5ade6d9df431fa9595656057d3174b6c512e79d98c549485865d185def152432056b4c081830eae43ac2fabe8759d95658fe5385e2542d4757fc83a2b708d8b3ccfe3f36a5f1f9f8b54d11550d37ebb60796bcb0ed6fd617673e7186a1134fd1d20fc8274855e2afdab9a99b20dffada1faa08564296d9e53ebcc8467b8cf0926519b189b0842e865e710c78cc9d3b8b46373777053aaf07655863a094b52de175fddcf240a8622332f65f35e39998231a754b9d0f0f574fb39febb56ba9e1a53d0c0d600314d0f6a2b289645db91a108970437705c4887f070193a427a57cc4780453b5a9755755e461f3a4af05f3332dbc78f0c582167ae0dadcbe816fbe104bf46fdb29d24022dcbad6ea39762964ddb2cb887835dd6fe215ebab4dd63dd7e94f33d95f64599cf051fe296109d0a682ae5666c895e9153f91e7d9011d4115b528c4c6ac76cb45cb7ee545394d7903e9fe3ccd15ba1579f2636e1e31f5e24912c18c7c915d7fe4a41598d3614c5f7243f0d1d4446eeeef1c91942ec3af2d4d2ac41c49cd1e008bc1239b22a50cc6fedd184c5f14bc11ad56dc218cf4c5a92d9ca8b7de9909fd90f59527e7cb6a1049fc25e61eb388f342a0db666e47fbd0822e721b7698d42e0cf51a477946914da0e4cf59a16b92087854e32492917f9c54e449c2560f8acb004c65b07d90eb29222c6328495206576ee889b697be27cae9ae98a6979331aa3de3853531a73b587b8b6dbc9af4fa9f7c335fd39d1813ff26ee6686d080d73edbce06590924bed6b2dfcda9c2dc19ceabc5aa62b9b96dd0b79634a1767287abe3c5e77ff3664a8e63a0d4bc41d9a4abf3fe17cce0a5749dae973945ad9b56b466baed6ae74b493beff5f23eb51213f2abf033e523e85737590f9a2cecbd91d7317837c99b3750b9f4ae838908b218cc2ffb7536dfdedba685df74c74a9f91fc5a4f3956bb64d57367bd9d94770942ae5fd438f210507ed8e3732cdda707b25f841fa4863cfb4c03b60423cf82e8ce5ab34229f6a3b87d12d564f58a5bf40ecfc43d59cc08ffe5ce01ddba4d6150405365fab7c5d4c346aa79e446bbe686e1224d99246a57361897e3696b836a8dd1b3a537bad0f62f6a79adcca6bb259eeab138593f26a99db4c9e9af051680b0e6b53fe76135a70a6a188b97f409eb1b201e0a9d95ebe8bd36a7bb2eb8e1831ee2039b0594dab169c3fc01b8f3bf94a4da7dee6654986e14d5f67b2949a8be1f8e2629699fa0f0ff187ec6fe73de80fce1b16c2cb6a995a73b19abfe3915229d8df7c8fc58f5fa8a3035f2e9c36b8ae024cfba42dff3f4005c7793006b7aaefb5d2b9eaa2244f99874c4a63934b230af57147a80d425bd24122fa5f7158415d69c4418c4eb00531f24455879b0ebd09d833c8070f38a132a5f6487f6b2b2649cfbd0ae957e2b4b567995e2d24b718d556e71bc832fe94e9986b9af155c2e4ba19cebfb8592b2d843f883332d856fbc2b1ff8409e732cd1b59223072cbe299ad99e9bf23de7d8b224da2c39363345615e287a012df946c73242cd41582c0d95490959d79d7173b4619b22ec9759f01fbecc6b0989849608fa9bc835c8f4d27cf94680e83df5006db289eb108289b04c4187120712e9b6b119b9df60d27cec7fe8549c414b4c0460c94493a21ad851bfb71c4d4e84e92b340060ee1cd5daa2b5762fd2ae4da59ee3a7b4a9b2dadd0fd89d5337551120915496389a13e4d7f0c903d6b71502c06cb78b57a212632e4a12c04c15af152cda18b2ddfca1c6af3d3eb22915eadc336d12f4169fdccd973da4dce893297f4a0b78fa116e1da5d8b3287fc942e81b22e10c6eee07207cf4900e99f9057a428640f55d651b210a1544c447059d1b1886e21ba74a0672ae1897258c13ef5d58e25493b93dccb3be0c544e7f966d96d51c16ace06952581e391c62029ffa4d216639f3a4f11cd49adcfd18c54f6667b584be56788776ae833ec99dafca80d631c4c1994b91ae520e9bc46d9635bff619156c6c183029e327cfcfafc49784d5ef7f447e2ca0a1e6921c2de9d6bbdf4fbe15a5a6e19819c8a60296640ddb04bc7a32385d09af65c4064fdfdb54c8b16798d84c3107a3f3f35e24809fefef4b8cbfd54c47dbaa06f1e0333437d8ba91efbffe57ba3918ae16ed1a1e31aea7c461dd827538ebdf1f9a33dfd2f141364e9a79f408b1cb6884315ee790aeb7ee67b5989659289281754447472965287039fff2e79d5873545c397c1e186354625fe08a6a96fab8ee83db1cd25c41170b61e92ab224e9f19720b68055eb561bcc9c9ecc96dfdc6a7ecf3f41aeec61a014d29e1e01253401e521d5836dfa33e4bbc8bc24c6651d5ab9bd8a8e268f0db99cedb4f4d9d41cbb590bbff2e0ab4d243cafd06218e139e8698c085a7192e0e0f74be2b721cc8309ee7a631b8a893209b5e5d6993aed1fa7eb9f6580297f9024f22dcf36768c096bcfd589237267e58144a12d4a19a5a47c8a672006cd1d6dc08c2afdea6668f902eca895923fb2897a172cc1596a0e75dcc8445cd51ec9ee33eefc56d9baf3b4af19daa6f3cb694a608d8fa46653078a6e2edb1ba95412524a6e5ef4fdb089c3f1d25a53096e378a2c48606106c0bbbffeb32e507f3eca53874b18cf184e8b65af6b74734943787fc995b9ec87442c4a0d89c33fb29607592968ac887c93591636ea8e6b5ead0555f038e8cec63a71ca0edb1324e3867c4d93fc07a3dcedcc8f256d3c9109b8a0042486849c79626fdd705eb2ad872bead401b5d51bc94b23ebfecefc41e52a7338ff3cb35db39b71baf89c52b18f4cd347efd9c26563c730fb69200bfc15e99ab23cb4407a2e05155db30410bb1e610afdb4d0e5e9a463ef3d2ee52379aa1f3d8004d91eb87d88fae2b7d63876bb59af4653f0be8ec1efea3472c4f3947e9498ec68b77e099f9477f06ff4493b61829e49e2455ea10cc262ac7049b3dc2a3ff416af5550ff5ab3fc18aee8b68956c9816bd167e0b4ef3072e56db383760e7b8c93981f34b3bf8f1b3b8aeab85ff21074a1ec670d489a3192e6029f433834ae1fe8bad6c474fcec5c569fb043a60deaca10401112c75c3f10606e6593539b966a14fbe2576493c2c875f368f5083265da7e454012d4f851b89c59a335279f54c4fe97446775750061356541fa0c4ec1a638e00bfcea6e7c97c7466859b2ad5e78a9e73b2b70046c4af71d781799016e3c5d3f896420398e368499ab60a7aa2ede0487359416dd13d9c033d869a000d44c548a6ca2622f2e6be7535b9a2a4fed7d0b089abdbf110aa806c01312d794895e3f6abd2ec43bb48e6d886618323cb59a024018a0b3dd2d81368f0b6f2c03be8572bdf95bfec4b338642073244c42fbd960f469db38cb39b688c82f3d0b87a5196302d6f6d63be138ded2ad1d270280e87e03b8d63ec0a76d6dc8766b364aa3ccafc0de8ddf7ba6994dab358fa7df15f91685c0f7715424b9831f810b4cbea887bca66c626f9ca91b7af1a512b4be3643c68b205894700ae86bc3e676ac75511360cbd3efcb08f510b13b6d9eb793c43514dc492d492f982d0c378ea9a44c845f4d74c8eb31648a54a75ecd277a7adf4ffde661f46bd584863f99ea9a3d465e2f9fa1de6a99797b92e8e84b0b29619a39d734ac2e44a0e69601a6b321201206321e8cde3688e7e6baed523adfe3ecb4ccab07ff254c824b75620a00153a2f24566b6df1c408d86f372e001c1528112068341c1bf9c918236aafdcd91ae0ec24a86d77526e84139d5ea79105d48169bb6ecc9e3280a6cdaa174b5e55804df64b11516ac715a6b11a71eb4ab0af9f55b8b927a1f34be6537f3a4f402a67087c103aaa791d30728342d2ee615e4797f4736d6061e5690984d548c23af7ceee753191c405381beccc09c8395a9b909e9ecc878d84f1a3cfed1431d13c7af66ff95e4a54e2ed6a6696b959d11f62c15c6e6671972bc4a858f2622384bedd1d741afe83072e294c49dc0b3bb77791a9f250f491e883e2ee09f2e8c165fad1403e8ea3598c4e4270fdc2101cdc2f63a3bba3c0bbcc27789f1f4482066dcf95570c9a0030d18da473bcb8dfdd58600cf749cea90dc51f0537dda4e02123de3a89c4ac6c10b5de03c89f969207fdda8fbae8a4669f617a21ff37ee89dc60c8d5009fc7fcb99be25e3f5593972a20d65cd4122cb98fb033108ad860e1c14d9a2eb64a18e2d4dedee179a90958620678d9346ef21e9a09cc9a4ba4b5afc13daf4e96de126e9218b5f159a130977b46977b71da35fe172a4bfaf8a990373b7a13a55c3a4db1aafcaa7a6f0c3481aeb5f440fb97c5a23702b415ed9685c54ed949666bc1c1d8d67ed15b79129da4c67a2df76749c282b64a79979ce8df4a6712b6fd4b2f46ad35c0f89db4adf5198f50b6a6fd555d94e8e6ae9c8d6fe0a4cf2bb84630ac3e08781e8f5b7aa50598b47e71e5a02e539f66657e4dd9ade3a8c0540986b1f23b2c4ef7aacc89028511a78cc6c34bc1c972879c4a500ad615f65beccdb32949f61401d42b0dbaafa7cc32263200e0470cfa05bc0dd2de53aa17786465806421a002a90e7289ca82909b8d11710b30d2d0155a5dd7890de5502a438b21e50df76058ee3d39e3c305fbce422afb935e44d0dfba8e6ad40aab438476ab0e858da922057ce45431a745f97d6ae41977640c36d512c06549bfc4065b8b2f9fdc270d03b1384cb67153b4dcbab32102352e523a03ee06dd1c628f3c7cf178508e73dfa4384585ad7dc33fb1b9d7be532ecf46a935a6e95b30eb42596d62b42cf688f8fbfbcb32f8994101cad07fc51b9bc41641623af483b4df0ba7b3d0e0121169e218e3546f0d070e97bb2bdf01bef4096bf458885d374cae046288f96ce1c743b7587b01bfb22d01e99452697533920e5a79ebddb7936fa5e072620d70404fd5cc40ad5644e28510579f48905c6ffecebb90b6da3a9dafb42cbed218389222be2fff9d5d6a48696c0fc819b433b81c506c186c9cec27309087d7f5e57c50069fa702ece139e3633d8da406643e9cf68dfa9a15931154492100d3b72ddab49a55c1eb277cf5c1268c35ca049099f8c1a4285b0ea56c2c0edac82850737f6137657eb1402fb0053096ef9036aa4c4ecae81c9cbea14e3832a682218c90c78fe5737601c2a4d446c63690115955d1a1f03e281951ceffdb883ce2a09ccbd6c103d1169572da85e456a96a7a21a5fb3b49be41fc84f56a3b2fe17455a4ea25a375c1887094e26643704865e5b8e151b37ffc561ba732236c37da7c99e1eaca264f0af508b5ea05f6be84933c4e086d5f9d6fd5802fe35bedcf678b75b92d3adefc7e7d1a9d3d0a454cf25bfec9e7aa627259f08b193fd9d4a03fea6ca054e2a4d29928b0ebfb90918f86faeafcf6bd400640063b613e12b257aee57bc88154754b52f44d3af84926d97d25c1e7f45b1f35a091f914a5dcb4c63a6d9092b79aa1157dbfc90c4a0c2f81669eb8e9bbbec752841a2f05925d6c5f756dcb72cd0e496020513c0f966d683da6222e93b545130447ec540adb385a5cf8769c016aabbebb7d713f0c33519e38e6739102d70dfb25e6af1803599c114cab81ece03b6ca605bde6adb8291395bf06a58b56185cdf8a0edacea1cb7b663992ebb029f33e3e98a6531327bfd4b6f95aa6809f484ca84e6189a3db608fd836c3006397d37f18ef2cdbb92e9d788656666bd07982877fb8d96ffb0c575d2763afdce345b8f7c965f402a7239a3feeafd28cd788d2874921d9877a7dc459c6f70d15c90e8a19cc53f693c6cb9f4a444ba5ab1d747a672ded3c1b0a249b9aea30097260e3e2b012c0b791b071f14b6e7b74a16bc503129ba11e7add26b0d7933b55fd27cf638ec8ff577546a48626c09a73eefcbdb042f1875ebabf347e2b706f7e1362c9d66b5227285c50cbc49b85f2eb4fe1efa58b6bd1337dea5e60e5bc82f1fa660e24fb66eab7553c050e57266d09c707622d3d016cfa04d42f3c5106ac2ed55e96caa18079c9fcffa33d466c10d8f1249f5a2a33b0797b806a3e90c7a95c9a1bc9d5c265c81ac918f47ba8ca87a4854757106155ee84a1aaa76921b2ad367be8870ed65c1254abedb7915a301c718cdff5dec6d42103550be75479d35e47698dd9f165fbe6ab7c0857ca34ea6abfa5450e82d0431c318073d20e6c2c4d272907872a8f960715b46aa1ba712c57a460c69de43ccf1058034a7b8b1203e7bd706df71e519de4ff27bfabd2cfff6e9e33c03e47ac14734d544af9e66a606de689fd0e8266d565edd3063fefe5077bfd8eaabbc1f27984ad07150f6c19d8e3270a3a48c5274953edaae382d46f9cae3d1de25e56d0ade79e4757b88df4f7d218eba0672368648c1b2dd4d06df87048e19994d506255b4a952187d59f2251ae222d3640f8d0ef4b9351d6d1b175ba9ffa945f21744b7019ec1639be61f654f528d127ab375a8f06d2c87a68fbe6599c8e3f1851b18b776a8709e0005c9478b7374185d7a1944771ed14b6417c70e80dca498cfef8087b6dfb6303829a991a440d896bc135a9ba26d52c4d2b214af3fb04a17b1eac43553828c735c9e16dccd48e47e87736d6473a5df2461f7b150f59769d710d215cddba783963f9f83f73465281aec14da07a2bc1e6be5c5d9c89320f3bbc681f7aadaa1a742279e569100b1e4f2de9cd05b73d471e48c6772f3189a5568bee7b15007559d114fa0c2b78b67fdf6bf35934b1018336ec38f40e9a964b3ac32922c68d38d661778a7d5ad354686963f8a23386615a724834fd2ebeee4e4e47844b71e69c06211f535d8e6276907b70a13a59d2705700437c2ecde191b805feb5aea52cc18f7c07ef78d23d5f45f08000e92e22491ef1bc38b037da91daf289552ee28fc075263bd792c9bfef70f8aa929dae2389a1945ea3a1460e99404c3d35abbf49f290f842e5942a2bfc11cbb8f910c3cfa711d1f410ad65d16f8e6593d0aac3209a8dd6b4fa318e77c993412990d7d4183de503c2ae1929b6d35d13e56906959e22a4ed485974f9728c11c6c08cdf08b8269b91a1e541e9054aecb119dbf84ca1950ba1916ad773d12c773451b9e3cd2509a602087096f8d9a5e6ecb3c510efb29265f4ecaa0a9f016cee4deba08e7dadae716c07b63eb60dd3a84d56250449844c0bd6806b1ceb69978340ebd4241170bd612fa00f55d732e7fc0bd52176b71b2637e4d627f71755420b4d1ed46bff0209dd6bb8e2b630c036c0f203d6e7b821a4df5396bebe9b17bdf8621d8f89ed82b888a863b48f091c0192829540e8b80929ee6f3d273097d32fa9a82cb176b05583aecfe6fe0392e23716be73e619874493b3ec16cfd11b6418af3f9c5ae6ec028b9887ca55838eb797fc539f789811a017cb8ad9c0d419259dd240893c615b3fc6359df9c93502fd37a50a86312531c2914475ff1b9e93b53c72df410a5694a7a97da99ac46580940ae166bad5ef85fee0e1f40472c701190e55ad63014f80bfebf9d7aee01ff0d59825aec592aea34acaa5d6991281b641016eb23df78eeb7fd1d5274ab523909735baf1d07bd2e9843bb6f96d99ddb1f1194183d3705c9c1b8a3006af72cdcabda4695444c8a658e42b328fd275c05ed91e3e9f76c448529b22c7084488fbfa2c99297b98648c160e8961e5d6a45dd50f93f8ef6c384c3a962b97ef1ee264bad4b724f48e3b85ebe9d4cc6dc20b5c3dd1b415cea0df26ee29763286242f16ffcc21b75adeac94d7ab27e608896f7b7aa583fee4d030496f9483949ec5ce00c9f4ff4f3b7ff36a5d52b3d076d4ec0572c37164b9599ef58d993a80811579f9ccb28d0e1f2eebe62d4661cff3ab1240606f4184fa6389e30bf097786e25d82b9202630863a84727626a0549787ca487092ccd5a8269bc9fcaa3288a6e2cba60353a7671bc11d3605d7d14c471c088755363ad5350ee1dc9b645577dc727ce60a470175841bdbae6dd6bcd42be09bd017a28d3d97334798677a021afac3e9c4016879a54ee7abf9d146d75daab8ac3785f60c6e43fbbacca6ed049aefb9d59e1a9033610fa767d7af3098446bbd87a583ae22000e9d2df3acdd1fa4acdb18f02971c88bec22babc847ec60d9d972b1076ec3ced5dcbe92ee73f72c1dc0bad3d9183e567898b377696c33adc5f2cf06f3c92d18478afd371113e8eb0c08c43f812696574f2eb0bb99786d2781fe9105bd755ab53645b988f76a59bb6fee90d3e12186bf4b76e7ead1d3af3958f949134fdb1c2de4da37ef7747a245a45f2674e73060cc22e842b3f0c732311f0e937e4baf44d3e2a1f4ab8a69cba866a9a2c95f5426e999f0987449fe49175f0ad1bd087c536ba4fb8f4c30c1d2cbc49aefa83a7da301819a39034274e29791a5773610f745f0b3dc75a4db125a97b69f1ba388ad9028739bea2b9edcf59136fd97f4365f94d69706fc70797300f1c9cb0676731f1326bfacf462c09a61bb9271f79396c33dd574e5972321e59801f864ee78813fce0095cf575087ed896fa024b96fe1c8b85a36cdc2bac0be1e22e2a59dac2f2062f3b800e0c91ce7dab1462e83b1e57b61f570e13930b21e934c5dffc91264a89fedb88ba85ceff1b1fd9fee37598612bec6f1c446a1570192ba5312e3127f499d66bb252681ff2c8654c5d3789146ac25486efc29031a5c15732e3edfea5b7d68f00425af9bae9d6055306650c337c49920e492dce9a13f824fe382ca4c17b4f1411a95c03a7b771afe1c180ea985fdd3d4d2113c0b5934b08f5c0b65f76899dc6f0741e4a29b944989880861820010b6cc955bdf31b8cd3faf2afa2f8df106ce5d57eda97ec6b8f1f3a40bc97965db9758e4e75910dcd9af20a36133a1e8c27ec584645a70e6a71c0f50a6a391767463d18d70d295b8f6902a08291c5f5f613c5bc1b585a6c5e3a8cdb88a9b6a7aa9b96c987197adcde861d60b0639417149f63fe616cd03ec97aec1f8e4ad41f977df92dcf56d19766e86c48bff1142e04e26cdc0298360d2aaf35ddf59cb18df76a09eb8c5cd99000d4505fca0d7d76ac243051597ae602922e2a9a98f6188b801eda5f398b490cc524e6b512524c79a2e2e852367eadfb639a1676eed45a3d29be0188ea932c40388c9715f7fa6c97e2a9a88421ce63a4495d4aacdf6f83315514afc095c5e0b3f46860c0fcc8c05cc147781f9fd0444917d563ff30e4cfe98c363ca33b3631b307087d3e8051c38e407760833095b770888ec7513b8e9bed20618dc3d3697dfc51728ac22cac2e2a4918c4c160f3e91582cf4a1f61e3f5d0b2cce35bdd6ad7a7190e93be9123349c9aa8570b7e149ad7cf7eab04e83ff3b431e75a7d39464bf3b07dcd76828590efa8e9b1685643427f223921a0b4af7005fb8f2f5cee1be614d845bd03fbddabac9ed459e42683f366e0a438ed142203f9c6de0e38bab901e49e1d5cb8ed34c983fc5c5b4056a0a6f8dbc0c302ee157c4b1953af40328ddd431275d253a4305164a0526de24216fd8797ae2e9b1756bbb5e8506ddecc305941676c2ee06b8096535ff76d2e63591d7114923592e909894d1cec6be87fc7a8964d466aab9e8e6fe2d98b1d0b855418b405d43b558a8b888857aea66e75bf4aadeb64903416f26f54b0e60106efaaf9897e47c7dba281d8c1bbc5f0974b3129f5fccc7c42f11e3117c32965a7b70d39a21dbe1375e5202f785531cbdee8d53ab545de8260df0ca5f4e114fc5f6171e961d13950c8cf7066844048d0913a7d480cfd6198b49fc9722e6c5ed73ac2737608b9c7936fa22543d53f9f930b39aa1afa995389a0cca23fcf2aaefc4235b952fb024a8c99f44e9bf92222f7c4ed2465d8c829d0cd139c343888bf14b897806d389aba2542b221b9a2923b0358ed01d80395718c9381ef0c9ff9035761a70393b38afbe0e27263ca35f00a468bdc42b218c286ae0d365a9d6554d87bb3acdf893d1a02c8f46fffdb59aef048daf29beca98895e5129f085dddb722464d31ddabb416d8e798c9643868e691114fef00b415e9247a49719a667c8133a0da926082cb3285fa8cce47a0db72f8065bce217aa501c33f409dc0db3ec9cb5d9e76a67752fec94fe0afdb4a2e9ff8bf98695a6f6572bd313c9313f654f956ac60dbf46849bd5209fb36baf1d51347f50f9719004eebe0dcf7e284ccdab94bdeb8fc45f4dd554e871e305acc5b2d935acbf4237033cf7b1d78636badd2a2c606948ce5de05cf0a20bc03d70955814e87a4e03af1271c81ee4c25a5c4de631851b2cafbc480f5bcbc46723262a8da184fdfc8ea871f287af1cafc1dffa86a0b972df46069e94528398fbd09b0f02106c0e4e078e90f66978ddee5285a24e7e48508f8364083818e8bdefd9b5bf5d4540e3861983c9cf617de99832f3525141af9568ecff66f865d583c547067071e0d6c690980a2348e0c4432541f4561f8b9d6b88d931aebf26bb2c8412f539dbac5a944eef9da9bb3dfe57c8daa883ea22e89822871bb35a1b46e980989093ba3cd8e0bf119e167c46452cfddace22c92932b9f11598c7d7d34db3641759651e0d8247ea5956be0d85223671ac63f28353ff65cac6ca141385d3edca7cd0998dccfe9370db5326c3e697f232084938e4d90742bf51b85609dc3b26be7ab61ad59b0d3ca04d4c213ea4a9b9abbf12a078ad6b3f0a4cc4bd789b3c3eb33cafbfdf6835efc21be68013c9f9b78fbac5b05a3e7dac7c8763283542e43a4561f6cb8b1ffdff91fb6767df4062e3872291a2bcb86e5731ea0aee0cc8dbf35c2b4a74504a093e86b59f59b8e111e33707975e728a9572890b65804c2e7599e8b92668fecfe2d00a1d900d9d4fa789adf5a2d8e0bb5fa3e5949406aca36aaf18865e497ff3c407be711c99f07852f3a9ee435961b21a16e78140d534d0a9c0b9ed5e636d2506042717e8992c080c3743c628f10bfc0e559137f862d75254f07eefc3a1df61642aa173d8eff6bd29841597c030f8f39bce801ee414ac2ea45dcfde74dae65fb470d4e2a07f7c4688cbf9a5dfaa08cbbab1d63e676f20b78035661d298cec567ec4c74fbea363b9047d4ca8e5ce4bc0573aeaf319fbdcdf3c0ff575c76a269474f386aecbbd724212244bbe003aa9566cd6ed0ee7813a569d5d41ce5645844d7b1f3d8c56ad1d48e7d73a0c6602f4b31e668dbdbe7f41c012e9301ba5b687b9fc378fe50c6cacf7e3e5683579ea1bdf083b016e596ca24d86db74b4331aea53255287e7855e4801e4b3975948229b312bc0dc907c9e0b00d24a7ca044dc2f9c5f863fc4726e90c88b097c35a3c2828ac4a59467bef7dfc157c37a1c3686aba7b3ef3018c5802b01cb43d339a9d6757c47b74d9774d87911612a0fed9e6d3aee44b2853eff196fef4ba1a052c62c771dbd739fc76c723bf0be5d74025b99cf627c3da0dbe6751331089b1309b8259df083014cbe2b2860e144bb4df38d198970fb4ddfa15bfc484581a09198f27287673dc3edb2792cb24eb56adf42c2f9657ff025986d1366356a450209627336e7181a3f45bb802983d9f2e4b733ff0fe80bf8914c78a6ab1f193f954f330bea792c2d3a2d47013d809e9d78f5712ef940bcbc39c56ecc82551bc8eac9cb0a73d0ac549b811642c09588c68782f097be84c49ae0ea6c2dffe96bfb2e17cb300a77285c5e7c1af4e75c0260998408afe0d48ceeb854caa8cb6c11b1413190a1520778d599d518d8dbc9414e085b06a15ea2797a707fab92a88971269b889d57cf5322a1e3ed527a419dd7473c3b867a9987770e469c6455dabcd1ef727e7eddd337a65c140af877575ad3fabaf12b7240c8ff7fc3b365c281390fdf497164718e0584967684a328a3e0ff9eedf4697907066fa7809b82f8859a9bfc30837b22711d45b219ba7273226c7b5ef1fcb4660e1c99c0b4aa41f61ec99764a9f5bc1e185b530ff6cdc385a9a7f3b5c0da751d11f3b04a70ab26d79a2d8a6af59cb1de3ace362cac0aa28ca53d2a47ca387f625388f0e717d58873a46bcfb8bd593394f746fcd690e9f50c96faeefd9c6b6855c33e43fa91f9fe6b04ad410e7418db92446e778182ea9140fac863c5b173ca7d6bceb870412e808af109f01bdf164ccdf344e6436604ed74b499cd9d67aefbc199e7c79215fbc5b265b0eb617bebc60ea28ff191607e2da516f921bc2d85bf29d1055d1462e50de65ff18e14c6165b76761217bf1aca0f11a71b735dc37f7e0c272395f9db7fe5792ea703bda5f1c277d984ab8d62c617e73d4cfdf847ccc0dd0f60d2ed6dc7a77be6f3a0ba6ed419086502d52c046314447eb8326e149b86be4eeadff96f377af9e41c23324bbf7dc186546b754efc6c50354a889e5d20fc379e4064287573c10a67c51cf230d17ada922784ca3a23af51dd324022b32f1439652caf3e356de085c653e0de1dfae01cb8535e2aa1d6ced5c871fd13fa59a317fdfe5d5730779abf715b41b6325a18127b87ec5960685778c89cc0db4a42543966d07e923bfee08ab56ab9152a08c3cd0eb881726308ca706b6ef40d56d54357caf96666fd34de014d79aebc3bb4937559cf392e374395d6c1b304c08cf5c0fc527165b6412bbc427c1647766a74fd08f5bcf2c46b16745612867f4ae123f4d898cbe9e837f20104c34563c7134dc09536b9ba3a9658a9b68e1e03ddb96686da623a2b367fbced4388b38efbb8689020d2694b8aedf85e959b96c70186afcf1890a3c3afb05bb53f12936fa9a8cc90855af81e2fdbc146c474441bc78763ceffd3953a9fb7a4edbcbd80e9c1b7ee178a9efcafd35c6eaadcb8fdcd0dfc601a6b4b378a4ef0f06eb13728ee5ff4e1ef363900ee4461048946a890082d6cff956b73c1054497d428de35f163ee72cc933c8e196c9fd272cf1df210f26088ed19f2f4f9afb58183e1577c05571f07acb825e76de8eecad61efb73289e7a27bfb9579e1172c6f6204e319fa9165b1d78d4e859e1d668a308cd7bb43d06c954c281bcf0d05536bc59229ae1e351a21b1228add1c0b6df0d9d208e036b695d03a31317359ce110bffe7fecd2af70d43dfb4f28970ee62f0261a39cfa1d208a33ed4374eac84d8e7e1000d8ab8f4779e4b0f5074d1e994d0410ead077974d13400ccf2cd53bfa72145eaf1097d462e8b3bbe677bf53a5d62f81fbfb2516af6a2ebc32777b3b3e2d55b51215d946900e18d6082bd2f76f38666e41abc80aa9b43a452399035a5e26c76f15acbad7d39c7e671f509166fdfe0fd5f86c334ef7120a414ace1a4986e0896a8d446f9456ecb63a38e35a21e7e0939f47bec9d6efce5372b301d1fa5ea76d6409a2922e82ec1829f4dfd941c0aebecfa8778338587771e22abf7abb4433653a0b145af47dbd403048acba6e23aade55ed25c8d517b72f08cacab7b5e285ed779231c7ba5f30a55f20b29de773f08ccbdd8fe04527650f937200268f7180c08771ce5b0d9727c65cd476bfc89bbbaa350869e56cf7dd49e25c7e3a454050f0bd8c022e60f79c85e3b931e3b685ae4a8bd1a8f798fe8e9ca6bdb030cfd0b27e3329d1b1a2420e70ac3e7ccff76256ebe0e1673c7317359545e14ecc76f54711679bcbb39e3267273b8ff6d13d349923258221c0b78bd2ff54a767910a51fb0977cd7820e5ced877cf968b7d2fca97661bcb2ad996e778357016a9a46a127ffbf5007abe13b9f5a22dba1905526f7dfdc7db52841e49a75714b5ffc27330403bc1e828c529d960ce0c9482348d59cf819ec6f86ec3e6b21533bb0072118ea7ba25bf76bfc145e35067adadf6c1f1aa4093fc6c55cda04c6fa1847bec9bfd0de644581f0023ce1d597db878674f4f56ac0b4211b014f5884b5ee87228164b1fbd733dad27d94dcfae497586d95c35f679dfb48b7c17b574779ce72edd8598cfdaabc40933a338567ad8900854921cff6ddefe08215b0d087f0f8cbc2b34f2585c0eccc14f296fb32817d6a60544166d426853f4717e2396d6e7d43a2370393e1efd3ba61c041ecd6704b3c1bc74460a60b8f1e4fc99bb8d845f1dde57947bf95819d49bc05d111ae7674ec03ff440ac59bfcf13cac950bd6f79cd9fbe95103010313dd298c701d26c836e069388af06dea4d671b65551c351b40ee19ad8094defca988678c9b54c9a60acea5ecc881fe4b3cd3dce7de80e87175c440c743438d6953abcb7c246a4b3260badc76ff2634a80ec88a49becf6354af2296c885d54a65d9a455681a966ebe22fc039433beed37198100d004632d2de6dfcfa7f2744cbb8910387293678b055791511d5532795d434bf93fadf8f5c713d9554ee1be0483f317ffb20a9daa85f5c4693c1dfd05e02e48dbca71b0b47ac83d5870cc8f957fa825781b804d08304ee33a6f82c90d6ad098a2aadada9af947486875a3bef9d617c8dfd16d8023048603618d71d7ae13ee76a51168946874928b5d2d59505b2182c99f42cf0fec9d610b7ec0b75faf3456bc25fa26265aff213cca275c9d61cbf998679cf2060f94ca34579fe14b719a9c5aff99aa9b269e4049853052aeafcdbc932b53e6194acc06aac8cdd522dc4c0907a54b2ec944c173bae29c0d3536756c8a73091da12b6e69f9ec00396b1b9dda740c70279249887e72c1e0f2723aca98e9fd2c21b2911e34b41032bc530f85ee406f1f8b5927c2ce32df98000dfe78e7bc9b7f60bae3b91dcc7f5005d47a0652df398765d662596388b1b164be5b7467e47a1f89f79e9509a888faa908dff1e450cc3ca05a0d97ce93560008d71240f4b783bfe67c695b91f39a5881caa3c9f3071fd11982ae533fc7913be0e1a5b7e25bd8401e0efda999f49de953ef192c78f62bb073450d2e3e7288382d1fd62fe807bf190659ae0fe13c6b581ef86c25cffb173e5bc5906b7f1e7763e712807a2df5a4629452b69d37321ed62e5821d89b0746926d5750f9987b90b8a622b5da49713162dc802bf651bfb670b69b6327fbdb3a4274edbb9cef45302c7a87d53bcd97e5866968dd1fdfd988d73ddc41087eeb09458c1a76ba3bdf698ab98ec386ce90e106f67bedee1beec35d3d2c33b71d24eb7ac817b7f77af4d3df660eedf65ba61eddd4b02f3457cc01b9172e2a3cd5af74128bcf6fe91c0e61182113ba07576a7d7e1731b8f72ed6d81479199a6fb299e24240611dfe05790800f1ffab1fedea14eda254d3d8261e78f5258ec29d4419edfb53f5c70eff5a69f3ef5c173c749f502e29a863228a03ad49afa84a7bad6b818d741dabb8279ceeeff46a66cdf2dd4c06970a1910ba0f2163a45bca5ed954b03b86ada9d114df5adbd67a24bd25d42ddb8e6b21c820786b6a3e836c8e11880096c88a76e6b3465b2d61fb111456da58dcbccf7b19b300c88db34699a9ca265599305c22a780e0e1bed18fec6aa777cbd0e9969533401615f79cacfe402f11629b8122175a8367c1d105de7f6a1cb88225f778cb322e41f990c6409fe24b6ef4b37780c99d8068089bb3a4b778ec63c80f6f8d03343ef3770f288c724cbb375f1269b1c06cc3fb0b9a69c43ee05525c8e2cae1c326fa4713c68d2cfc23641507addd49be3af9d557b0be1597fcb7a681dd73bafa132de4a34ca6486127234bd0ab6c050df98cf6b0f111f7500652ca14cab4a41fa2d18f1c664626ba70f874a8365ea64d1e1e8a257a1d313a6b652cf6db617dcd22d74378159ef1ce25258c76e1e676aad0722a01e30db706e67788d558e44bd0fb600b177d88096f96dacfd78b5a7997b9a3ae5a4edb6a36cb3618a4cd76d2647302681fdc242673350f2f044f4cdef91c7a5b0091ee7c195e0268af5ef300a5c9fe1406579ecdcb0915397d14f82ed2bc55f8de4e5abcecdfbc41f9e80a83a072d01418a2a544f718ec3d4f6332d1bb2aebb00c6ca66b9999e6bd2bc490523859f0db1dea63779b9f1f84d52cbf3e7dcede8214080c6b54916f512426bc9447266897ad4078118867e0d6746cd99378ff539066b246ecd123bcb3597c4acc172ea13c1e260468fe12b1696ba737e1984e9b593f774c3db1696be6964319b9f9388707bae3ee0858528e3658741dc271e80974045f3ccdcf5c271fa4458e81023f42761c5eb37375dea4e4d4d8b1de0b4724631cb35b0043e7ac67c4edf767115670eaf50370af4cd2637de6c760e5750b8bda3c5351c16a9a5ebc02e2ea24cd10e9fe31deaf0e250d869f933642bcb9da2dd7ae6d92e3c3242c2ca4908bb60f19d68897616973b67dd1f1b037c460f7181782191858f2003a4146daa41901058972d7baf5088dd5f89f294ddf5d0b6af191f36df14250213469c2735942e825ae6d36406817d2ec872e739cc1cb9f0bee817e95e37bb38c24b9bab958654afa1a38dc4c3155c37d1310f014a5860de0637d0a48d23331bf8afc9f5cef164c130ca4a472b360b92d4552f083d6ffc381f8b033bcc0550c42ea706ca15026f0d4171c06e6e3ed636e2d7cfa92856ef967342076d612e419457b0667c8087f01ebfea10184cb54e7c6df803d8878fc04ec7e45e1705072d1a554a5ead50980fc7dc0443a2f51f64bb73fa10f183be1e8c4368441ddb9cc5c47845c02ab67194a7f27a109036ef7c44c33ea236f799350705cf63fa5a8ed6d8075b8d483c41a589c4ef7efb716cf495f839a1f22ae433f35d4c5abbe7bbcec3a78ad021babf3e0b9ff84130557125622e93b0795670617a426fa536430d1dc22c79ef99b0474f5fc4a7812efe5c9e2e9f1a23edfed2340ce460b118525836600127c410d977d7f2e9a89a6b571289479ee50ec969a026d8054077f783ac7038fc45f1d7972c01d4ff6811fb44dbad8a5de90b39b8a8c055e25ba81b4839725ae5f33875d468fa381a5866ebfa41f21cf2bcd32c0a3e171ca4cd5ee36fda6a7de9f0c630430e796fcae444eddb481d8c61f7c1c1a6b6b6df269eb1c69ddb5d6e2c4bde345e22546ca393c69f48b4d52019f1cd025393fb97d193b53654aa6bf784c660040145a5d5da90092751a9294b526d087323a04313b76cbe6447ab73707f48abe7628a2d8e2b0a5de8dc8e7d4baf10cf6fb714170a8d0e808f9b00d1e3796967ea69bbf899bb84605751b423872250ad5e61d0162613a0876f1c0aa27c7c9dc629bc9ef8fdbcd6abcd26fcdf55e0bb080028cb3de1e3785a3320ee1652bc1a553fde8f73da96ace4c55e5d140bc4211918ed8694dcc5d974ff47276c8c157260e9099cb8042fc9f9a258a6a107023ad1f91a1cef61a74521564bee71c2c055606b183fb3e5f02c21d21f45d8c3dceb63edb8779d4e54668ea48b3d283b141db2e76e2cd4f4f609d47125519bb969771a27a129d82b326cce960126a21be34bcc01bbbda81dbdfc70e2cf40f79d3c7da6f29603a5e52e7f968c8bfc4709adfad10b5d2901740c54625168f306997e9ff6a4dd6b3089030fea08c28cf13a58a35e43883a9feaa5b6552041142f20a916a2b4bb0c0892a4ccf1a8707b3bd537b359cd86f831c655102f69601746ba8a29cd9a089cc3796df03360f77c6727dfe70cf7bd1ee97bd070a1b8ff7798ba8dc2e1ca6f09c1ac987da350d1929136cd346b5347b4aa00aa08b1707ffd7ed550b167233ae883db4791025d4d3f0893cae53d0ee29569290f29b0f73b691f05895c9a2c40357ea89b2fdebe78c41e14f014919d17cbe67b0fe6fa854d65c7a2fa0804dd88d8638caa595e49d2bcb1eb6bb45aa447c4f6ff29d308b7785fa01213a796bf7f61237c38b7d6fa76cb760315659cb37e2c88a9cfa7d48353a5e160709aa599f17ab5076cf9010a1aff139e7d908e73c96c1eeda61568730981f77f749455f6d4efa787d9fd40630cae5ce4d302f7cb502afb8a092b1a0447db8c42d95be45ad25ca5db36cd0f24768173e21b968e7f38503c70bfe56101b8152b3e1a32d922a58fe48f8fa01802d578ffce70178b29fcd877d58d2062a166933fc33d52c611c44d98beefc7a2ddfab7b17a455cabf8acab61554a4c1e649c4d228fea931d30314849cb63eea6684d5410dc66d24fa96739949aa615777b13a0849df0f9b95023bfb065c29379f515d4eb24965f0da79ebfa7af2b3852ee22611953769bc08b0df17def102abf69d9e9d2ab0854760e6ee324c6d35d804f0069d65636227f3004c20e2b74a1666b877e0701f933590c14a0693251fb7588d16d011de7e13d98b07a9935ef81774938d1f8dfb137ef0804e32d54efb3566ef86664a6b8d78d19ff938ca4e067e6c9bd56a635ba2884c97a074fd7e5d32a98c6ac2563323e1d7b40da5cc1f7a66385ef4badc4fb28ea729d6a406b13db81f59251659084f059081828fbc0a287f21a7481d8dbacdb4cd8714741779ce7f0b10d23bffed168fe6f15298797240be1ab25efd139f8f6663e275121659798aa25963f01fb9366b0eea86b68b02f48c74ddfd8f7d326a5bcdd419a78d76dc27507ab0aa42971abb2fb8f1b624d62e13980139cfdec46acd5a48fcfc5b86a5e940a9849b14c16368fbd87c5fb40b8f410d515fd63ddfc55c529e5871a4988f6b1478222f54769ccbe8ee2f3b735fa774ab209ee535a968e7f5c73ae0b5de7c384522f475b368931a1de116ed780a373343da60ddf436d33d075b54dc44383d1b526a931061cebb55f946b2b415547f11343fb2be1233678bcf7d349560ff71b11f5ea8eef27435e40088394228db93f8063dea3693be95fa1569f3b3c91b8b67f0b77d4a7523cf67d842d97ff491ac1842f40f10eacde168aec22d2d14732daa332ab4a4c30248538e83dd7afd1ee5d712876feaf7825829e2e7eedfa51679ab1d7c340f9d40420378b49fc3fc42f72a9a0ef50bf647469bdcf7149a89c14818c0ea9b5fee05682c065ca8a9032bb556e10a0a2e7d508f1d60276b6a8186759960374cfed62f261cbbe8b3e77cb01b01c412d961c16cbbff5ec6c655a18f3d99b0b8ba2b4aa9480d626d4534cf488116b5b194add0074a593366f9f4c8ab554393017f7dbcff227adc4f71578342e2d84814a1c949f6d51703ab19ba4460a1548b29a5b52b5214a1bed29e9cc43e8b0590aa3070424a755fbeff2c6ce21c722042d196d7192681845c6f898923b56e5f3a7370eaa6dde6d978e89f788d512a80fc498c33ff338ec7f0c3c600de2bb10c1afe00f096a9ae8df2b5e49cab7828c8b23e925e8b46f8ae63e024d51c5cce6b972e070373aad3419669fce258a3be7b3bbeee648a0c7caae41e311bdc63f25a49691a192ed222014d0071e3d7c64e3592feb0806efb75f5e4af2e6fed4d7d0bd43c4a7c60c815cd80ea50fcf42c7e4f1db51cf0abc3e13f4bf91a41a4fc3dc846fd52471628de83030a44e40e76462c6e3bc2cc3561cfc80134e7d03d955e9d64080cb8010b54d350db79d3f32b95068a570ea03232c72c60631d150f317724b11b487dc910d98e2cb9460ddd235a8dc716278e888689c0d5f78ab3b58c904794b17c4bb64d3d6f28dac34b8a9ee8a1dc6f6bfd1c2e413e4b24ccd3543f6eb8e1b962cf0657bead354f86f08fb83acf0f2d15cdb76cebfbe9efddee249045cc81f0360110d2c9c77265cacf1808e1c01c426620d8e9353ff01078bb31d4e49983b38764b57ede033442be57fe2e7eddbafccba9c67435feef3aa6476bb9f59c22a7186659791f24ea5aa27ff0350e301a756fec499d85eb9faf9d230b40f3982dce8192896f6fae40e80b9e7ea12c5f4d0a31070bfca4ab36898d33f2d5f351ce8cf7e17db47b09b29b6646db4334883c7dead3bc7d0ee01dcae538c3d49b1714f3c113d06102aef49d645173306c4f207ec6eac2475bc8fa26926eaab8daa466e6c34ab10668fa741b86b382e92b2214397f748cd625ba2b58e697d0180c69fda71d034cc0670d4abb988426bd872fd41b642ecbfb6be68dfa4f340707a6b6409871faa6e3067219f101d3cb77ddfff917e482730104661cceb733c1c8990e16b5508a890bb1f9e8d2487295eee1701bcac5abc493de597d5d9cba5cd5af580949919869f4f652c32fabbfa516fd7e11158d2757bcdf0f755df173d3f8a550f91664ee1fbfd1fe2e59ae2715ff9aeea4f6e5041aa73aea79be007519d9e80f3fc68f329869d7f478fe0119f2111f54df2cf7b560fb1b47165ffc114f5cbe2c2859c07c3564d638cf9c85c5b84afdc9e5adc2978b62752b13878a63ee99c68d6b79db08bcbe71bd7d43beac5e3096a2c6a472c0df4bce2087fe04ae6fc39eff4ea505292100fa2e449a20358a447dac2e932e04d7d18ffdbd3f64116e120f3aae0392e635702f6ab8282c7bedeee6904bc2880bd57531f848c8fa136e125585af4a7a7f206ae99a126a67330b01e99d67b16e0f0f06f556418d3eaebac9ecaf854ac4e450620e22a388b25ae4efdcae411eda11fb962a74e49e12de23e88b8e6e8c72121502ca28ab80ec0a5022692b0cc5062a8d2bf2cfc2be101cb922d31a3bb9f5171d85a0a03cc4c51d0a2ce10fea4c1355bb710ada6ec0f11b69a74187f2b1c63f9ba776ee670eedb92f052f1e90992332cd3d3da29b248ecc997d73887e3ff12e12feb5b1939f61c73c0709582ba97883728722837edd1db6f102788d29df604047d15a1852a5dd7fc7c74f30d392c0a8534255713cca7653257ce25fdeced943975bb6ba8593235be0f4f199d174f7843c720ccc6baf0215e17be990c8d2c9236224392020c2760c7d5610f539f02f2d083e892d69f78c18e755a0f356d6c90a8306674d83c32907c66a654183ed03d261ae20ddc26354f38aa3bdf0760380fc09bd7f12b225901dcc213c71318e05bbebd80f524cf5061ec623cf5bc895b4a6077976a7ddfb9c0cd3fa783259354b6a2d9f284552ed221b78d0b55e8eae65c02003e58fb60c50bff4d44d5bbf786a3f5cbd49c3cc914fc3c602d082d7557c3f7ab7ace38536e001bcf52eb0ef80154322b310e2ea795fe7333d0ba333dc1a7a853d0b9825e34ff5cc055917311b257cf36bf141a2decab2f2adcb50466bd0432e09ff47d854ff60e1443cc6d6dacc027bc112c705ab3b6d6c3de3ef5ce27d4d129fdb066237160be102dc61a8690c459a52b319c974404180caf42f8620ff20f9681d46a8953f4291f3de9ff279d00cb82789f9f3390a83d0f9d38050aec674c5c92bff62cf37d43b50905fbfac7db15ec9b8771850627e1f9e770c312d2138fe017e607b8c1642c6193e31f193b69ffac55c595da60862d4d14c2cfe9a6558b3398ed59bc10b4a1822dd6fb02884f6d44ccefd2acae2137921c5c0e61af9b6845095b45d27820b326e1306ee3ae43d05624e3e2bb39362187700f383b59c51594cb7ae9af7a6e004d2ae29e9ed089968a55efcaa2f352623448f5c54666a6b57111956291dcd7f5a4d181bca27e3145020dc777335c5250af53f8800e58796c059c6977c4f1b8cef9b12103cf9c39370af2ebd9ad11b66de9ec2d3451247e2f3f3002408fb776a822a58c313e8616d49869e70d2e7926ab78c4f2c95e286db19b74770a15064005f43ccac5d10198033f1a16ef1b73e2fd166acebec28a489847a9ec8537747b5c83997872a38527282e648560e37180d3acab42a72ecac8dc39a281f1c19b64c8c71eb8535c29c8f8b60a4aaad677de1e20a0f21a524e0bb3e1e91926c4021f3070eb5de9d98a8df57c41452f66e5ce73d7900307c01ee5e45201abbbf8f49bfeafe78720bb61856e7752389ff5d32b760488343be6f700a1c9e55fd535ec4584387630c08a2a48f89f1e7efab7c9de516fa1771def7e4dbac84f8db1de0015aafbd1f2d74e64e65fe58fc43a361506578af56139aefcae540f5ff015076b7336d5ef721d339c3edb3f54a0bac0f82e63cf9c1121397fb5abb17febc0e3c0acb838d464681e2ffd6d72819fba2d563207621ce08ee5421e74da75fed5eb0c36720ac7bf257418746f2b2c0c9be338ced8a733833fbeee05906259c4d26b6769ed477ba6133cee26d58d44738fbdaeb8df99a70d00195f6aa67023b00fa611d4d09cabe9af0010edd6aab27dc4e4815cdd63292e5edb1a572dbf1c307cc0127d6ae1a2edfd548dfbcf3360079f6cb5de7778ead94d8ea779f40a51468df59c9f68f9b642929d27db1b62b28faa2f28889ef015c1b547c2a7fa8b98ceff4c4e721b8d7caac45aec0866c1e62eda03a822517e99d42a6a679d36aea470b4ae2a2f97fef10c28943ea9861b09ba728bb660b6bbe5b2f052c88b744bf24caaae05561feb1a5735f213b9bd71892f0188050dd475e72c9740ae547d17dba345b4fafa7aa952bd9e0639a2d3566ee4e9ad19515d523d2e4f36d26ff1e7ef1b609eb3b126823314ba667be6d09e7c435b4d6e68e5a8f1345e55f2a71d50b8b8b105b87c9be2458431d77b36ccd6f89235c8512dbb2d57f8c59f560879332543b473d0d19165422d731c2350156be4658e3d17ab99a5e2816e0bfeb8868a7cb38627522e5d2d86b7307a41f3ad81341c03ca0d7e571b4dbebf47d47a90638207314b6b00686d4427b56330750f0121d400e9d590df382d206d0d812187260693fd726374ab708767b3ff731a9774e56647d00e850b4e31e47f422588d47691d26fae2c91a9cec647376c3061b1a41f12ad3ea960b18424e474d5462a6b43b3b083d7b8eb3cd3e3fb8ad176138ee32c53af44e90cf24ac6d1b3f3a0fc446c2b2d7211c2136b646c59ef7a8ac5a4faf92f201651879cab5905e6c5ad9b39ee8b357259ac5051ca342f48cb3b5f641e6cd4b740095645d8343e36752b1b57a0f6e303a6a7cf32fc24a3870bc0e3897e96712d82a1225701f8be67aac7299b091e2048947f23a93c985b761fb16454f89dd5cc893f1fa3aa7bd95015c9da68d57bcc35ea31bf25d69551683c6931093b2aadd0f37ed9acf6a408ed91f11101f562a2e2c5f16fdecc66dda489676775b1a2d62b09fe66ff297ccccf99f5aaf8488601f66f11b9cfdd0d91241fed97d3c0088963cfbe070f039e5fcac771780e6b2b245be54f17cfe37e425c0de47acc34e25519300a8afff1f835d63680fd56064190b99b6b0c723e7411d0b183ec38d0aae036bab9785586d3d50a0d062a3038681769da5820da23528c36df7f3c9a828fb0adb085adbe1892570135b9fcb61d795502f612507a641afe9b2b2b93310408eab6a1a581f107de5cf9998413d3c68d6243afa58f2dff4bbb6a97c5c6cfb5f9dc23aa7393ff18ceadaf4bbc3deb8791ab6744ce12d16f90fff60c7d88ad8a30b82042edb1fb6c6411d873e295d3e86ff5ccb94ca3ae8bd5f6b6f6baef56ff9d9f00356a9eaabc41f2f05d94fb7ec0f69329e3ec74e0900a2d326d76e99ea7707e1ce2b7c9e6a3f47ee0d8ab2d7f8cc651eb5cbaa2c6b617062a51b3ac075fadbea8b53d0b781e9091901c608a42fa6a2fb46fa13663a7273defe1808c6027a20202a7fecf228e09b6dc2cc97221bfd0ac131d90c33861c5b993c7248555c7a15c9d90fe9a3214a0d3d43efaf8cff196df2dd4d116b18330f422f44364c29c0198437378bdc402c079cf7f67027fa945b4782c2a06ec557cc466964d2bf2cf0ec14ebdfe615cfb1133491ccc415e202f1ab98e3c738ea119238f3ccc569ff46181e0b82c4db4e1d997566979b1005abebc940acb548ae12b96ad19af931e1cad7869c80dd8228e000126b3b93d629afb1aa9f487a25701d6ee99e4cf2f5b9f207f73e11763352830ec4e195996180fc56c5d84d0615352894cf5b67f2b1e91974da5e501a8b09f090edde5e77c5366c947b3a2746ce229b5754f6427e403fcb271e487fccf3d74e0fe67009ce4d32c4fc1808882f1d4b65436887c30ac2a06f8c8c8f48d1dc75e1446f6e02f13305f0ac1c859912dab3370f14e7959902351550bd14b3d5b84eacd3998c630db20e49958f0d8366044fc900284d5e8db58504fbd6975535a2ee1ead79b6cc88bc6831f661b1fee9d97dcd7f598338c12befa546a75c7bc86c784b367da4df13f70a59c5bf9933e95654b7701b41963d33993a9e0f46e7281411e4e7a3b97906fca7bb82652c94025930124c911c6dd1333e8f7340448aa6fbaa75ba9380a049b41bb86262d4921453133dcce9bd98da9878ff74c6a6ae2b40dd06c1d8a963ad52aef1b26f73e9c57fd52286f2bc6ce8df8781d3c4c68912a05deaf4ef510089374b5a3ea63672190ae97c9a0c79dbd339b36ca5abfece9fbcffc1a6564735f8e5b7ea9ee50b7aa3feee252816e206a7ce1ba545a90f74a20711c831a4554a7c53288733fecbbbf9f48d272d6b65926e6491c7204b34f76048735d6256dc1a9ed16a62193ef707a785456133801b11691fdd576103235c6ba2978ab05ae19878ccadc36f9574c97ce3a5bc3aab4ed3070dbb7ebfae002d7ea4c48794deab0502b6dbe03c1a49ee52728fd3ec92389993e7464e8d8040e60b211d75bcec5adb4a19ca20af1f2232c652fc25159e12e858f3d07f08910093953401a8f70c11236df7992bc2e113e51b20b22a2296639fa6133b6015f802d66852bb2b4b698f1e8a81a76e67687d0b8508a371a3cfb18254265d57413dd9aaae3742eaa265f3456bf9dbdfb08fdf6b477a6a10fdad90e7a3355697aec35bf22a8f84b655ed7fb307d0489142c045faaa914e81c608e59c6f88b82749d9567c46aca74b4e1978b741a44795d277cf7243127e1597f2e5a3ae676b42c162909e2acf12f010fb756d886355f41a24888a64d5dd10af3515f3001e6911908bc84e293c988afbdabb7d440a2ec3de96ec06b56b4b9701e95e5ca10b6589c2733c81269da2cfc17b3d47fa89dd30503200099ee675147c9e6f97da5e3a7856a4decc4b8c165c4ef804f41c533835ac27e46741496675a2431086b71971f0d40370dbbb119242adaf4e729ddf8d1e04b69a669486aff6a0ee039a66c9961c66e0d6d5f78f3a1fff5432c41265936aea1995776862f892861c937f5904d376a339dbf99a02cc9cff84c27f206c5afe488c953a574c797e99f22b5c917e5fd1a90f3c17a4868d0688696a13dc911ff02f1ad4b6203e9d92f77bbe78470dca7c72009d61b3df1e7871b60921a0d54a6ebcaa148260672a3aedff2f9764f8197d9a0b6c934cceb6820a41476eb1b6a9110af53bb182dbf95046145f6bdf102b1cfa86a5afa8b08e603fc927f0460fa9563545c88d7ca5916dfdb5c9b6c767d520679e66bf673ec64502185615b13d9a131fa4651e5c8b40eaa278c771c4fef3acc35ef76d167f79eb68279911984ac9da9e54eb431dd2340ca6c72e04c2da65412db02aaa3246250c507eb8ff42c1d25b629f9340317ce8b71eee0aa0c015b2b905cfa739bcb9db63c6779cbf2a576a132b4028bf070686f89adfaa5ca91fade9b6f6b4df65a63848c502d2d24b94201e4713ecd2aafce1b7eb28ae4f96ab46476eefc5392d6ba2fe7220eb3458363b121c138d122a188c3dc60454f7ef6fbe7479cf56d1a20347d7960a7330ee392fbb02e0d5b59f7881035d8439568b8f438c0d91f38b1467eb4194f28f7a1558882f831aa7bf0679b0059c10180c66abaff9d238887a05ff23493cb18235efb163adc0a06a2c8099bbda391161ad30f52ab2c7627ab44e1ec88fcbfa08277e4418a7a2286601e56877d6269595c4885c64ea809e9c121caa5532d4aaeadb9e9e6651be49f25470bb0dee83448cd59ad75f4cdcdf2d6c3346d6065ca27b286622eb28fee3ce4399894dfbd1846725fad67fa2b818870e0aad72f9499e1fc776431e6fa6a6858f5c6f1f0b56126e8f912a126053d445f27429a596842da82b1c3b8308ffab9ca5d5c88a2d39b0f44968b0ab67222c6b93f8cafda69183c62918e96bd5d949173c140d1f7d0d256ab50c9fcdc61c725a4a1e1f4639c8363ea53abc87a8b8696a1b8dfd51814f19a6bbc18f5c567ee8d89e0a85879c50fc1ac149cba1e9453d5d262d272c3a76a0e254872e1f54e8fa6da6c8d2220605305dc398214609f1e31edd55c8185c46fc00880f28beba2b50b042b26b20d8fd7f26fd662142b0440addcbd3a64e6ee99bb583676f96927d779481a0647ae6a8cc059d35daea794868326bdb485de1940b2a0c5b90489666a5ad85e2a4c336c730d0cc6280111fd237f90c67e4f6815889ffd803bd9cce441ac59e2aadd6e546f9ac17507798d056b2a421d381866b954c30d33a932a629b67e2745913efa188f9bbce163bb69ed44d12c9167c406883793d6e073e31f74637aa4a17c5c1e67bc663294b8f573ebade9b593b1f720c74cc001f07f29d1168caf61ed84f913f70cfa5c6ebbade99e2d4a5a9b2a872a1b1fc75c65337ddb01ea09c027bb0ab8c5bb00cfe363edbbcaaccd3b997cf926dd2ccdc64d98cdaa4389d8e3c46a789810929302c1e8d10c233932e1144928018bde47eaef06a82746533c7a4b9f1b8253c9bdc89e63f7feb3bc7ccc9aee795df2fafc139fc21ea9013ba3a3c248747fa68bb7210b8557073f3fd7cfbcb3a57eab551aead27af9f716c1d528efcf4723c5755ddd767ba5543f9a7b1c112d10174ee53670c3efa51b94b73a0922dd298c2ae4bc7585bafc8404413f0042165cdf82fc68e9466646ef85d2a9b52bf523fe8094b7dd275c84288aa10f6fe14c5dd5f3e8b2e30e2f182083b5a1f4b0072bb58e0004fb9868578a1e1fcb8be370bfec6c5b2d0318eef1e9bb50ab89fd834ab0e625af5527a5e6f82f8a3a405eff949692ed2338cb902ca715293b77dadec10b53bf024f432daa9e080dd7f2810c25b850e8c2e0b405d1375275fa5e832390fdc7373e6977f682b358897fdf88ccd4f323356b80cc556eba9346d54c0472b377c06d453348058467141f388a523f6ee723496005e37bbb98d321df49a1884bc3561c19198cc35f2ff429ea6efe3161f569f92e1da035ff641f28c04a0a8052136df82f8b0447529ae3e27f8a58912e545514146409666760f5425a3225a4c26c143794808a9cba3f10821c3a9a6a419e06c57f5a6dff47370620808ab3cfdb8f2aeaa4c2eeb90405d1ac832bcc1a55bbffa814c3471d27765a5ed6edb3566edd96e20e6f108402df41b49faf48b75484ce9d37936b2f26672e80731901740049f18de88bd5eb2f58dc4afdd7a8f9198992edbed64c2602373c57e2c06bfddc03177ac292e562cbab5e054acd21318a4a10a4805330476c9099e3d7660d79a3b2b8be3c14d05fe246eb1c9964761289d097f71472a6beaa0127023697956632f8ba77250559a15ce9e7f270e6eb1edb62586cfc31cd4fcbed345891201cb9f2834761f84bd88f6ab147e6b3f1ff90139f9c6c4fcca9dca67f6f4474b102eb1d4765f13ddda3746d54e44bdd32806a9a8a179baf0f8d75593777e79ad9eb9a370db4ce21cf5fc496d6e521ddd7f2e86d2fce6bcd92f1dd8028592154f1a8734fedac7795d4c039d5ebd66d4ac8475a137ed935f20c7fad6ec11db1f86058949a36165489f84d9cda1b1bc1d4e247187d32e953e61716bb585c1d0454f7b965292fae8b22536dd70cab60356d1dbd744f7011c840ea57f5b80a17340138bbef39b38a34631fcb4ae8d262656ab1557b3d74e09da980adc68b54c5eb56ba9716374b1522367425691f578ca5d4cfdf22220b7694610d9eff4fad493158fdef22d1c936252b49153004e8c5ae8b53fc55dfc7aee6769d559dc6d0a439d4d709b116e3abb4ead94bc8cda7b0bd12c0a96a151ff242377453f06983beb82d144028101cfc7cb7b12abe9a1ce9de7f714f1c7c24357c98d11145b5a768f01b6e6f2bfa3da6a825728ec4d1186fb56378be287c83bb728ac1f2e844241a0d5cc98b9aab6996b7ecc14b7b499624b294b767111b76681e3bd0002113c7e3206caed1bbaadf9f536c32c97ba20607bd2711ce7fad2a83149529b060620ac3c8be317fcc60c721d23665f16c9e7eb87b8e591da318ca5d60a8cd6c7acc1d3c2d7a06e4483f0186f62e2ba305649189c5e53605892ca44ea79e249bc821f3e82e1c1583e7aadb19f0c574c2e138adaa6efbd425980613fbab36ff49733b6179e15246bc89971830913c0c225e6fd33bab45f351768e60d9016b5dbe6c9f4cce77d160878dc2a27e19edca99840bc821a66df08234e37b482e1cae6644af512098d2495c11ecb228a57c43ec86768f732eaa843d810a0faa286e1fbe63bdc46bf9e852e349d15c0a170c8fffabd3dc7839f6a8190b7184ec66bf453b4eb894885d61e9e21438073e1729f784790935607c7cfded186c2a6b134916d591421f72aef18288cd68f97f0998c659a81d73526766309ac0300415da7b642dfe8ba7e3c9c37af67b4893f119f69985e1e16f4bfc24a1dbb04462575658584d7a752252839e0787f818f41901f5080e1d52f35e165003d5c0f8281cca9a45dc44769f5665d33df75ff7ed753aecec1308e456ddfee4dfb559bb6fb36cfa647b5777228cee24821962f8350ed090a538f12a50724188e273c645315f4da6267f040104edf9029bbb4da1884407f8437f5d1665d870885f1bfcc6b28d3f367465ef32dae8fdb43ffbdeaee77e4193482563fcd3d841e2003850e5a4adfab4a1dab93d42a9d707cc91f5b78382bd068555baee3664a461831989b94c420c1bfc0b53e8e4a1b26a67764ff9d721bd676265bfd2d76548d3ee2aff5fa8c6f28673111195dd8108568c5baeb5928123cc3c1b07c07cfdfb5d1b71a90bc96b083b75ada40678238949c508ba6ce3af28e601b3ff5c087f63876b575fd2eb7323053775f5487a6dabf336946eda37230d3afe6a75e16af37a9193bf5ed51d5efbe577c4527d4cf0d0b8fa8a5f15c3a0c86b2984c2fa556522afdc5cf3989be38b3f1489a775cc80126f4d1a8441834285954db30d2035e886940aa2254c6a7fa3587c874574b47e8979ae0986eb3088e01a1a670b2d7b5f7f042960fea80d5a4b7db00cdcb715765d11897aac6584687657e883a35e36f6bb2e461ef2ffbb4694e11a41c08e8059b623f10c48f63c62fb5a371680dbcbaefc2f43d32e52de3db301729a1b604cf905eaf28e369efd2b04c8a6bb11d60be37de8897e2fd350db4d073e1e0ecdc8d430eadbcce1c2f9483546647d3dbd75abeb905506182853505c63ed3e3fc8bb6c544a55ec2358f987e91434db7b3b17e514d2f48f7319c7ef30eff72cab9a0852645eadbe45f34bd141f5de7b6dd367854ba7fd6658e0ab2ee66dd20f2bbf921f3cc5a0563ec062df41b6c9a4aadd81c262a9683ed1f5beed2cb04acb8ed18581103daeee290630e04d67226f6ac86d5c680cd7cf4c79256d383aad62adb72a01eec6d9f098d5ce17185b645b64c52293358623fcb8c77479dceacd1f35821b2e43b825223eadade6c6fb97aa9226edb450e9c188133f2b5ab21b3600f488f34a18db510c4fb0c894345fc280833c53bb2bcc559bc70effc2b5eca18b6d2a609fba4f8f44f77c93b8ef7d642011a633d790ec454d67642a944ad1d2aa5e96bc51819452dbfd7177f3dd9e1579be6ac226caa88435614d0c29b519def4c5f36f85425bdaf8dbf6e858cd02aca16c6c9d82a0f18c5090080164047f2e975e9ffeac708d3a2b8be97695b2736897676ed49b9dfda9c890da00b0cb6da8a832264cdb48d8779e719246a6a830fd4033094135fd6b9e636240a4e0349526f4536b5bd4b736cdfcd46a88de2344fa8db7a39fceb5b724a9376f7e51aa417f1a10baf63cf530a4e759c4be80b251ee82cb392bbd7183039d952a0d4d1ed64f506d9efe23b37f970187481518b39553343e89b89c2f6dcce66804b8d45e1d55ec1dc36cc679e462ef0170344a83a53bc23044a873d608da8320ac65e235db368ec238efc73a0203508252577fec225b42f66ed7935d065051184cc0371494b774893d57f30bcfbd03c7ab000091123fb60fa23dc7977917000d8e9ddab549cbf957485e17c342807ad67edd3919d1d5c4c847c8eb7c6fb1b6b756bbcaac63bd1cdc9f8d96cc9f91fdca6af5f66e6ddb2355d6387d4229529bedffda6fe0a77c0907cdfcf445c8c720eff421ee021081d34d0b73b54b3d84781a1ada9dc628a4b59f6253f1a3cff7e82c31014abdfb9015711302df5363c688e3232679cfe23c0b273f68c0e161f6548b405e8177ccef5ee92b215d98cc128ec7997bc8f7197c143accb3c720c1f4ed2e331130e4a70df1d89d4ac6bfc50c642cc8cc1b05040cae31594015470b104163e85a9f519ec28427b47a3a8a0b92dac1276436acbb54bac573e9b83af6955baa5e254871e2e681ac5f42219834da9a5411d59f497c6df3a89b46399e8060121f44b73ac189060dcfdc7e66f426462aeb94eb0d7a16135d140ece4e04fab9f317cd83c2da92777bb26d75957c8d170caff2d1572dee417551be25c2b0446cb6bbccead36a25e3a2f523bc9b6fe3537b3fe0aa0918ff2e90d41ab5d8203c9701bc04cc8b426fbb2b25601df442b472e6b5d3c2dde368e1329c36b3915b82af2137dbe48a5ab8cf13af4b255dbd31ea11473575a63c08ff3d36ed69a0982b7e2faf71b27cc091d7944b25c30144c6f1e98e0ff646ca67f3c1eab89ff4d3cfbdcf15e475bdc50b64f802fd83ffc56f99177e399c256d93b6fe616073e922ccea2b52b84eb6e9ed064f7acaa2bf7fec7dd2bee3d796bc0744082041a06cf8f1e45dd44b8bfc02b1a584fd52817f2c16f6d26828f8fe32f5863cd938c5d2c7cab425f6c614225dbc671e97634e210c017fa39c3f630c22a6c1ac6673903e55c2f09c09aad4dabb76072ce6ae8beaf03e48c627465dda54afd436d47f007c5b1c7b52cf55830d6a3dbcd561bac52be9e131182f46854ba40f55c86c7935413f3c9ebaed553f9b9fafb964f0c5a03ee454b8a21bcef78881b1dcd9e4f0944f5e0dee6770f7d32e058739d6a63eb6e264ada03dc9a30d0b1db52bb8d96dc1f7c6265fd93ec0da79c5898fbf9ebb3dc1bb2ffe8ad5eb8ab90e70f448d5fe3fad48c56d1bfcd93dd5b11f413eaeb15c0056ce58e6652cffa6da783774a82e27db165d9d836346f72747d8c8d85f9487e22f9fdd22afb05e33f35a5cf7168954bcfb11617d30de40fa8ad3c2f8f52d1728c2fcf55f6d1ebbd74086b553b14dd513b6350e3a768b8678ca52b18189a5b85564134db150477a016b7824e73e59449451b33fddc3fca5183dc7d9a198d69544c402d09a96e837c02247e4a6130d6eed2a9f2b30c3f738c35d70c85248c3b057359ed5ea1cd52b3d75eb9d54174e6a28ee2c6111a86baa9775f96a245abd0122b84590b748d11e36778668804478853cc95a6b177be3e89ad0d4dd55cf07353cb8977d3bd98060e117840d167f0db84d406970401cb2938b18074c16b36f9fd560d2658a28f3aee83ffb01f39fd96972dbcddd32018d34891143f8288664e979993eba480034fdab02115f30ad476c5814c52236c0351dce3f0dadbe16ad102d558e58e46f4de316d601f1eb8559fd6e7fa0da2edaa56f5a01fe1666e4700cbc5dc1ef9f7674f1fa53a82de533f9084a762ef55562b17634c10f12f1430c0c7be8aa9798546cd20c5eff8408a3cb350afaddd7ee636cd8ec151e393db773f5bbd9e176a34373d86ef942dd0d79b9e271371ed04fc6bee281bbcbc2cb0964bfde1e396a4c18625e8e24c29951cbdc14718e6d5109b0c08565d7735b9bca70a223539dda13c5e09eedc6ac0cfbf99a4807070785cf8dcebbab95d7a05ef72583571f7cf3444111c2d7cf6631862d9975944aad75d7121705fae35559fcc29c10be0ef7945100115b9f3c54195f6ba9878e79c64132a7fe77767413faf8cbbecf2ff69e85ec340b5692343cbd35c12b18aabc308b5d49214f95c8abe9237658b6f43919438f0789c7154d639c21103181eb034aea16574d9b6b961ebaa798d75ac2904f37e5a683dbb687f10e0818620bbadd332c64b26e0a1f4c6f64cfe00b35e9c5c8265032b1bb6ba5b13d924d0d200a10249cf5b69919d56f2f8ee7d0400c4ebf7153181646511f2519b3bca740aec21d724ced7aa4b820ab901cdfea9c89112d9e50021c63c6707ad027f5ca0be19cb4de574ebbafd938b3e9570d8be400d97da0ee86ba610153c7075ffa8b175ef3946454d98d904b82ce7ca96ff4cbac78721ac8c31f05fbb8e42c55b32556888450385e3540e73d58af2f6078582f2e941d213a237de856139ef5954f8af94fa85a9ece6f4b649d63fb0284a9c4fd576ad72a86371c8e8b2f43c27ce93027d0c7593926a6d69e87ea5795b61888c1aa80f605d1ba68fb1af27697f8a409f800b9405fc44a2b70c283d640d237b73b444da8326e7171c2f699e87c63a02d79cc10e62da48ed2f97597ab3c57c2944b11186e1df36974cc03a7c87606755b499406d36a35de4966e5a983e8cf04168af815d21fe1af84864fdbc6fc0b1a881b7f266d8cf96c7b67bd124bb3c785236d119466f2ff51edef931037f4fda1951cc8518579c4fd97d9e6e43c8848d5ec133e47a9aa5bc6f49295e63884fcb22e77fc54e4941241b888a31aa59e107b714f37d474deb8b9a62bd3a6e3867e6b8a972ffcbdd03d0c48345a50b025da83de2dd8136643c674915030edcdde1db0742a3f69d8dcbe5f87362de6cad7bb3b395799a1c98d7ab4b909d19699256f2e028fa054ce49aa8645a150c2dcf0ebbabd87f87c14285b7475ea9fb1a2b772092d94e4a2332122b14c958c48dc2d147d4f797e5cbb1ade04c953f37555803900b7091ad9c274db66dba1ad056534beb09ff8030ec81d88848d7089d787aaaf897a74f9f91692557e5b306cbc359b986356bdfe5682a624c554dc42f3e521c76711beaa01733ba252670a55910720d4e62e0d294f49c7a5be941ab31619b07f28784a8196105c38585c29fbdfdf32b29c9dff18edb10cd5d176199bbec3d9c4b2eb6a5ee2867b255ad92ba3774d2356ce55e4ffee3c5cf8fceed59dda03fa9cda4bd1fc8f7005e2d9b67b2b729af552856a2d69a43380d8e3582bf5a0844ad15b75115a79b3c343c898164ca54480b7c4111b33949585bd30e2e660344012ad27a9e85fdf6ce509e07ea1ad1d81816db8e485d029101155c57641e2839a65c77e5eb43ccd16f81f626bd74c084bacde9e7716266b39a463ab4a1f2055fbdc00c20ea10db76139a5b90e106bfa4a51f41d475c303d094b6aa0303775b834388fee4d6677e18deecb5eaf8c3d591d3cb4c956ae34c7c60fe071f5d3f19cab9a59dd9423c6e88af1fa1223501da07cc214b18724ec1c587951ba0b1dc970bda7dc0ef804fdefebadee0965e023312ab274d01ff551753dc0b7afc85e10b68a9f56428cc2267fab541213b3fbf509cab4daefa4c984e8b1480724e2e399e42086c67fecda7789d5c380e0f257e6e475c63c832aa4b17c31f83ba5d7ca5db9fdc57d4dbc9e8affaad3b65d1b3c4bf0b75df9f602ac32d1ea696219afb6952a294f4b540cce84a33242e065c609afa4e97d83aed8fbc70e410bb4ac1e64656c713f72378bfbae088c13d3e8e1fadbd2f5cfa1718d26c9376cb66449aecd642d476cdd411ab79511ea6608cfc1686b83d4ea4a0f8f197a759b62753860ab0c47b8caa719338d29ee89c6953ed4beebf5685b8b2ba9eb59fcefa66329670c5fe2ca4435c41b5ec4bddd9a69aa5727f8c7026cc337e7f5ea2b85d3e6eadf65d1da59921e9601684cbd6db98176793a8a778e4f97171b0a271463c772de46a0436964b32a57a00ff7e9b78ca13c743767b460bedf3a1d701196e2a87424a7fcdfaf115afcf9476b7992addc11bf5dd4485153818ddfe711c3fc14fb30aa9336100044e5a37d30d6d246459a6c6c38a28b0ee36c5f4ded811a115f23d4853e71cfbc48617fc8d469baeafc65234b2284f93d2a41953de6549f9c41b571867bbb6ff418332d3cbcc109f85d59203bc4d222a70ef70373f65e9cf0780289af7a3d8d168265f3864c5d2e933bacfa2424be11948b89596109584ca6e8ee0144c3d99a82cfab8846844f118601ab906b0b44730d79c9169db3822060b3fe635b51c060ba336c774dd1a5612319c004cd5a626743a468607a7cce9fd29ece8b85e868444b17ce733e80d2eae2e43585ed707a50ce1b2a2173dceff5f35b4dfeb79a69e18ae83d3f8445f0dd7f896096bd7e10383a59f95db4cd85ed6e54ca1cf899e13cd8fcf8d894fdde52f8598fb1581db8f2da9bd57d644127db11aec8803135259c6cad21a3a8cb51b86f5832f74d2d7da4c00ad6e04975e7986d4d7f5182ad6ac51225ea5bf595012f4da7a714ff27a654cbc5614843c848aaa8d1e71be240742e0225408d964430303d332924cf588f4c0bfb75f32c2907095476f00465ce5377a0864ea08f2916a2194b915e61d9829ba0af574d7d8d4fc61be6557c49d9b1893796a674dcd4a2d0ab1540da21721f9ba2889d40d11d15a03f47fb9b4758fb5d396fc3ef09dd2eb17340651bbd4d4d302171b64a5d134a14c2f5761d69baf6e087645f1569ae3c9430bd62569a771c3c9d386357852630d14d59bccaae73e88e79fd335da885dbc26e317a560e886b46237a9bf974c90f17e8d1a3193eb8f6a8a4085fe6afcfc6625155f230cf95e28b02b2aa25a07dd2b9402a7e11a026050b95f200b7f559706d39de6ea5c6a3290939e06c2dca3293634d1380cbea8776653dcd705517ec2d729f81f6402d57a065a801fad2f4c318f858e12657835c6477ac3168ca4094abd3e684a49eecb3f72361e2950d32c7279a81d3d6a36479bb03f1ac6bfca0e129b096f3fc11b1a31322a3603bdbcf5f25ef6983aabfde61dbbfb31aebf6a6438c0de64b0fb58146993c8339ed1575816a6db7850ad758ee3d1b493442e12deb80ae936380c081a69dfbe7b86cbb28d5c225733e9c7e7674418cc7696f6bc482688210a51cea3c76ba11c21c21d75191c1f92f2834c1a9f9c6d1be9ad98508e7b4876621c126d0a3b9432e15f6aef3241bebfc3cb8f2dab4b96f97a61ee2e7312845d3614d817793f6c40190d7b17ef2b7bfc8ce665fc927dfd178722fa98d37e58d5c3ea763893f1f46390b9e412bb7b986e6f26e6b4998a7b7252bee2a919d92a4f63bcbccf52f7a4236cac4964dce74ba8572e8481de412bb53a0ec1667d3f64526bce5b1d39b5a49449f20a6d274d55e60b0c722a8c3606a1aed9a73738d634bd51a4b4be81283351fabfe38d8bc07b96495b56be9c69adf49958224936770455c97be2e895476df55af2d69e308a5b1f898d2d60896055b8f95f99cda6c961be77245025b3aae7411644fea5d5ed7c0f9fb6a9d48af4287b4be060236cee349ec67d4e94f6da473e30d4d406d95c62c1e7814aafe12b62e4ebfa9b4421b156a67e6743bb98d4bd17da6eec1e5a6591e5b6215675d6704257ca0cd1f71717e12fb61f365c8309df3e3e7646cf2ca5bf8fbb0e602e769c5510b11bbf114744ee38b80e0200a059a64daa7b699ea04851f976a7ac131cc0e2da1375524def3476375b4c4fc0e8e9e114f8873394b2ae418d4bff3bb202b523d2b7c897bbbac4f2af74dd5887ca6f5bfdc6a379332dd8f0a6a3b5792c1f1921642c1498dc23802f39f4e43e8f51f3415daa93f1985ad00c9e8768cad571d2016f57b05337882a38ad9f4470d205b1eb895de995fe90369bf0b6c0d73c5923465938cf6750d0a46ef63875d8eb0958c48459bae7ed3d0e6f1a4ff0c876e86f23f199e98d6fc6810cc76de5161e8c5d2e502ef34cdae2115a05ce7760248fbf9d29f89d80de97a7c4ce37d6999ed4c65057c55aa5b6295e0897474a4abd86b58a630b5519e24a96a9c36481adf71efc31aec6227002d4c5671641c259859e515e84034740a8fa2decd0cf594aca7cde73ea9f6beecbfbdac88cac419f91c685e36f599e7419d1b68ee540daf765f2281a336d8d5994334420ccf21ac60cde19a49d0df073a40445ecdd194aecde7a0c42d2d896a031477712bf49b2967b5d1a24f133bb7553be28f71887bbc6f8b53795a1b06c323fab7840c85c24e06f6df3f449c39f7f4cfbc5e74ab0b6f54dd85d46be27789f44508d7a4e0294ddb7a972022adef1feb4bbf80b6acb41388b29f99d86196551e89be73d3fda6fbd1cca14dcc0044a97c9e1430600238a4ed27cb144440da1d6273ec8750b8d8035c7924a123c47777a396502a8ab6b7b98c93fe28a08d8377a606e099c8ad9f42dcac63554b356a129a9e9573fcfb207b27baa436c6d4ddb4f8580d914a1263461e304db5e0815f7dd9b755db529032597b77050aa6c653afe3f7d7eac9e3df2d52b926639aa3f51d8cd5471da36ecf408bd859ce900e439901bd20c3c1bf000f6e62cd234e5fa295118a5b5f55100702fdafd43a7398894f4a3dd4f74889d27294143d5f3609d97ac3323c6f3d6ecbe990dcb5d975358f54153f286e78c8cfbc76cf3e2540614252d267ac9327d13fde8abc4b282014be61a11450aa26626c478ccab01c380f39cea9dc5d67501ab68b06bdcd6440d7ece6f784539530afbb27edb7b1a83bf6576ec304ad3538edd4a02e1fe9ff821eda6d9c8f6eb4ebad0d80fc45576ab4426f0b390ce9fb42312c23430d040d85efa8cde8e1a3c47a082d33cbea897edf90b00820032156816c8cc1218b9cbc41108f910a9a072afb6d94c20b5daa083a8c6f1e49570a82b779b06e91e01eeec67ad5fcc586401c91030a8300014a92973e2b4653816cfd1866ebe6a07b7b9050176f3f0fd7deb7094b96dca67a7fab85f80275b5616414ba3d11bed295420cb62860d5a01fe557eba85cab0dfbdd4ed1d7f30cdc0540690d7bfc99ff1e5915e91fd99a5b94d2d26eaabe72c2e727cb88748e83899ee6f2f6efac8eb7d66b7578fa17671b4b70ebdf40a36ec697ece2a6d2b170bd083c0efd515b81acdf56c750064571d635ad50165f1e98519b12655820ef9393b33d71e037d8ae46f6e9ac84b732b21008111b16796ea62181f264aaa19c362b426516c97bbdbbf0b0da0e47f805847067261b62d7d699124645c6a6a983565815e6de4fbc31263380b6dc811fa9d4c1ed15690b2dc7c1afa5a4a810ee69bb8759c898287630273ba24ee35f314790e09d865d2e82dcacb1ed2ef7614e2bd9aaaf2c7b1fd1cac6b3b56058d33a13e5d998b5cec54b5968271a32ce79f80118678f2978011bbaa86de2c5579e966ae17c6dd435279303fcb2d1cfdffafded27c921d1feea042f83e96f01bff7fc98215044eff87f28e65559c9b030a0676eac25552b5961084f162e8bb638d52c81b091ddbdaaf684c6f1cce30ff4c8c60f55148aed8bc5894c22114a2f37c483bd9d9eb809a483f918cd901f9c48251f8dcb19f35d61bf1105ec96e66f22601575a5abeedfd08dc5ec6669790c3b47e557d391adfb259ee0c86566ea1c4a93ad18003cb35a752e91df73a688cd65b92b754071ce3f6328f76c6d6f455eae1c4cd80e2b05cc183e1dadcd83deab48dcf62d191e0f69e1ea30f050b80640b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c645236986f1affba9e034017145436f7519e5681fa5b9940890979fb54be43bbf437da860f61a59e5d68b7d88764a2eafe69c78d0ec49fd6bf13df87a5b512849437da860f61a59e5d68b7d88764a2eafe69c78d0ec49fd6bf13df87a5b5128493edab1ff7eb6bf33f108e9ac1a08eb16c954b88a844e3119adf5950b44014eb611cb6f5cf19bc18ac0560bff08c21e5a715d9e488ed7b90715ddbb518fd57060e234489f88176e66bd858291d9de7054c6bdcedbb9f19ebedfab02d238b3dad79ac6a853e324ff7c5e92f5e9bbbfcda63466ec3e8a17fd9b3247f183465e93ca372fd5afc77f0d7f38658bb86153e8c7472376a5d735412237aea47881eb714ad1ffba188101427d74509d8786310f1e0793a251f31819283664626cbb6286bcdd109bc3de5bef59a8492c6f849e7cf1c2a665d6b5844e749d36a714fc4eb8f652fe79b889ef808d2d515a143bd50327674d18780056158238e627e37eaf784b4505976a7c3561f4c11d3d6507b4c18b802110be70e1266ecd65aa25fca9510137f5d6822f4308c7525d307bc5aa18c4a8cd6450e22a5d3ff8ec4fd0e0db96029b188fe909be6889a961ab6d53b11520bc8ef965b7387b554bd7c482b02b0f4f80d00110a008aff7aed1c6d66dfb2edfa2605d155c2d97a1c2877fd1bf4d770e6708988dc83ba66d6a40a20293dfee564ed40c41d5e541c2997e512019841b0b19fb878199014dea84874d11e319609135d4251944a93718a1549871f86355fe0d12397a1e4e4db62d46514798e653a11b107fa6d6cbd7c1d4a8795f849809cbf723c6b3654d1ff2ac20fe4e91db0ffb8387d06864cabae9e45d13b197ef3dcccc6b0296da09999c1156c66710e48fad121d7a7eb3f20a9281c83c7715e7f759dd2b11d8da24b078973a81d23f56a3cd370391c47ad7ea923f5233254b2c62a41ea39a3c45f364074338dbc792fc2c11e46cd8506f84eec2d00b8b7cd076d84a54a4e74dfb2af63dad0b61ff21f4f95994201c284fe8f586948c544ff57e966e81d01c4e3d56cb060111b09771b67ad0ce7c76f75907623f84b05a05d45611f5bc55eab02c151e601843afc2885ab9824b294c7d32e6352066793e8ccf6663071d70e16fed8696139a12f8dc737261cc47235f1f6043d92c85ee5f87b03e8429e9657bb9f64a21db6c7e0cca7c1f3ff6a65af73bbecb35b1a93de7ddc539df9a5eb5dc9143c8d61b9b80d5cf522b829938f539a301cd22e79e52f6213df15534953e17076aff00521a5402e73915fd843905ff5a92e6db5564e3ddd38febf2dc5e8b6c7840d556c9d7eed953dea0cf43b01fecc45edfa2a8e9b2cfb89d9914c4b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c6bbc3dcd02c734b5a033bb15077310fc031a2066afa3e7239c3c5c3fa96044da2@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootselinux-policy-3.13.1-229.el7_6.6.src.rpmselinux-policy-devel       /bin/sh/usr/bin/makecheckpolicym4policycoreutils-develrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)selinux-policyrpmlib(PayloadIsXz)2.5-82.5-243.0.4-14.6.0-14.0.4-14.0-13.13.1-229.el7_6.65.2-14.11.3[<@[[;@[;@[[R@[t[#@[@[@[[h@[[[9@[@[}P@[{[{[z@[m~@[i[i[i[dC[`O@[]@[Y[6@[3|@[2*["X[d@[[ [ L@[[[@[ZmZȲZZH@Z@ZZz@Zz@ZyZ_:ZWQZV@Z.s@Z)-@Z%8ZZ @ZZNZNYYA@YYW@YW@YYY@Y@Ycl@YP@YJ_YI@YBvY9<@Y6@Y5GY1S@Y0Y.@Y-^Y, @Y, @Y%uYYY@Y@Y@Y.YXQ@XXX@X@X@XXX@XۡXP@XXg@Xg@X~@X@XƉXCXCXX @XXXBXXXs{@XY@XWXRXRXOXJXAb@X@X)@X#X!@XWWSW_@W_@Wv@W;W@WίWW:WQW@WW@W@WW~W@WW~D@W{@Ws@WrfWj}WbW^@WYZ@WYZ@WUeWM|WBW9@W9@W1@W(W V@V@V@V޾V2V@V_VVCV@VZV @VqV }@V }@VBUUU@U@UpUUUUoUoU5@UUȒ@UĝUUWUU@UUK@UUU'Ua@U~@UzUv@UT@U@Tr@T@T@T7TTTC@T@TTT}Tto@TsTk4T`T[bTWn@T?@T>aT6xT6xT@S@SSDSg}@SB@S>S;S:@S9XS5d@S4S2@S0@S,)S*@S)S)S&S&S"@S!S L@SSS@SSc@SSnS @S SK@RRR@RRJ@Ra@RRR&R&RRR=RʚRR@R@R@Rv@Rv@R@RR@R R@R@R|@Rz/@Rz/@RsRpRnQRi RfhR_@R_@R[R[RSRNRNRL RIgRB@RB@R:@R1R-@R-@R(r@R' R%@R7RRNRR@Q@QQdQQ@QQޞ@Q@QکQکQ@QzQQ4Q@@Q@QKQQ@Q@Q@Q@QQ@QQQQ@Q@QQQ@Qzl@Qw@QvwQo@Qo@QnQm=@QkQfQb@Q`@Q^QZ@QQQIQGQ@j@Q9Q8@Q4Q0@Q-@Q& @Q$QQ@QQ@Q @Qh@QsPP@P@PP@P[PP!@P8@PO@P @Pf@PPqP @PP7@P@PPPYP@P@PPPM@PPd@P@PoP{@P{@P@PP5@P@P~P}L@Px@PvPvPuc@Puc@Pr@Pmz@Pmz@Pmz@Pj@Pd?Pd?Pb@PaPaP[@PXb@PWPS@PQPO'PM@PIP@@P>@P8@P7lP2&P2&P,P,P*=P(@P#@P#@P!@P!@P@PkPw@Pw@PP

@NNU@NNl@N@N@NåN@NNNN@NNN@N@NGNGNGN@N@NNS@NS@N^N^N @N @NNj@Nj@NN$@NN@N/N@N@NFNFN@NNN@N@N@N]Ni@Ni@Ni@N|tNyNx@Ns:@NoENoENiNf @N^"@N\N[@NTNS@NS@NC@NBrN:N98@N7N6@N2N.@N*N)f@N(N%qN$ @N@N7@N e@NpNpM@M@Md@Md@MM{@M@M۝M@M@M‘@M@M@M@My@My@M3@M@M@MMM@MMMMTMx@Mx@Mv@MlMbSM[@MRMQ0@MQ0@MJMGMGMA^@M>@M9u@M6@M5M4/@M4/@M0:M,F@M$]@M@M9MMMMM\@M M M@L!L!L@LL@L@L@LOLOL[@L@L@Lr@L L,@L,@Lډ@L7LLLNL@LΫLeL|L@LB@LB@LB@L@LMLL@LdLL{L*@L@L5LLA@LLLL@LcL@L@L@LzL)@L|L|L|L{@LvW@LvW@Ls@Ls@LrbLrbLmLk@LjyLe3Lc@La?@LZLYV@LXLN@LN@LMxLMxLI@LH2LF@LEL=L=L=L;L7@L LT@L@LL@L@L0LLGL@K^K^KKKj@K$@KKK@K@KK@K]K޺K@KtK#@KKՀ@K:@KK͗@KŮ@K\K\K @KKKKK9@KK@KK@K@KKKKrKK~@K,K,K,K@KK8@KKK@KK@KqKqK}+K{@K{@KuBKs@KqN@KjKie@Kf@Ka|@K`*K]KXAKTM@KPXKEKEKEKD{@KC)KA@K;@K2@K0K/c@K+nK*@K(K"4@KK>K>K>JJęJH@JH@JJJ_@J@JjJjJ@Jv@Jv@Jv@Jv@J$J@JJ0@J@J@JG@JG@J@JJ@J@J@JJJ#J@JJJ@J:J@JJQJ@J J J|@JzJyt@Jyt@Jx"JrJrJq@Jn@Jn@JmJhPJeJ\s@JW-@JT@JS8JKOJI@JCfJCfJB@J@J@J?r@J<@J;}J:,@J7@J67J2C@J0J/@J,@J%@JJB@JJMJ J dJ@J@JJ@J*@J*@II@IIA@IIII@I@IIIX@IX@IX@II@I@IcIIo@Io@IzI)@I@IܑI@@II@I@I@IԨIд@I̿In@I3I3I@II@I@IV@IIaIIm@I@I'@II2III@IIIIIIII@III@I1I@III~@I}Iy@Ix_Iw@IuItk@Itk@Io%@Ik0IeIcGIa@I`IVIO@IJ;@IHIAI>]I= @I7@I6tI3I-I@III9@I9@II IP@I@IIg@Ig@HHH@HrH~@H,H@HCHHH @H @Hf@Hf@H@H+H@H׈H׈H7@HBH@HǶH@HH|@HHH@H{@H)HHL@H@H@H@HnH}H|@Ht@HsVHr@Hl@HkmHgy@HcH`H_@H^>HRa@HQHQHO@HFHFH$@DX@DU@DN@DN@DLDH@DGwDGwDDD@@D?D?D;@D;@D:HD:HD2_D1@D1@D-D+@D+@D'D!<@D!<@D!<@DDD@D@D@DDDDDD@D@D@D@D uD $@D D @D @DDDFC@C@C@C@CCCCCR@CCCCC@Ci@CC@C@CtC@C@CC:@CECCC @C @CعCعCعCعCC@C-C-C-C@C@CCǖ@C@CáCáCP@CP@C[C @C @CCg@Cg@CCC!@C~@C,C@CCCCC@CC@C@C@CZCZC @C @CCCf@Cf@Cf@CC@CqCqC @C @C @CCC}@C7@C7@C7@CBCBCYC@C@CC}@CqCqLukas Vrabec - 3.13.1-229.6Lukas Vrabec - 3.13.1-229.5Lukas Vrabec - 3.13.1-229.4Lukas Vrabec - 3.13.1-229.3Lukas Vrabec - 3.13.1-229.2Lukas Vrabec - 3.13.1-229.1Lukas Vrabec - 3.13.1-229Lukas Vrabec - 3.13.1-228Lukas Vrabec - 3.13.1-227Lukas Vrabec - 3.13.1-226Lukas Vrabec - 3.13.1-225Lukas Vrabec - 3.13.1-224Lukas Vrabec - 3.13.1-223Lukas Vrabec - 3.13.1-222Lukas Vrabec - 3.13.1-221Lukas Vrabec - 3.13.1-220Lukas Vrabec - 3.13.1-219Lukas Vrabec - 3.13.1-218Lukas Vrabec - 3.13.1-217Lukas Vrabec - 3.13.1-216Lukas Vrabec - 3.13.1-215Lukas Vrabec - 3.13.1-214Lukas Vrabec - 3.13.1-213Lukas Vrabec - 3.13.1-212Lukas Vrabec - 3.13.1-211Lukas Vrabec - 3.13.1-210Lukas Vrabec - 3.13.1-209Lukas Vrabec - 3.13.1-208Lukas Vrabec - 3.13.1-207Lukas Vrabec - 3.13.1-206Lukas Vrabec - 3.13.1-205Lukas Vrabec - 3.13.1-204Lukas Vrabec - 3.13.1-203Lukas Vrabec - 3.13.1-202Lukas Vrabec - 3.13.1-201Lukas Vrabec - 3.13.1-200Lukas Vrabec - 3.13.1-199Lukas Vrabec - 3.13.1-198Lukas Vrabec - 3.13.1-197Lukas Vrabec - 3.13.1-196Lukas Vrabec - 3.13.1-195Lukas Vrabec - 3.13.1-194Lukas Vrabec - 3.13.1-193Lukas Vrabec - 3.13.1-192Lukas Vrabec - 3.13.1-191Lukas Vrabec - 3.13.1-190Lukas Vrabec - 3.13.1-189Lukas Vrabec - 3.13.1-188Lukas Vrabec - 3.13.1-187Lukas Vrabec - 3.13.1-186Lukas Vrabec - 3.13.1-185Lukas Vrabec - 3.13.1-184Lukas Vrabec - 3.13.1-183Lukas Vrabec - 3.13.1-182Lukas Vrabec - 3.13.1-181Lukas Vrabec - 3.13.1-180Lukas Vrabec - 3.13.1-179Lukas Vrabec - 3.13.1-178Lukas Vrabec - 3.13.1-177Lukas Vrabec - 3.13.1-176Lukas Vrabec - 3.13.1-175Lukas Vrabec - 3.13.1-174Lukas Vrabec - 3.13.1-173Lukas Vrabec - 3.13.1-172Lukas Vrabec - 3.13.1-171Lukas Vrabec - 3.13.1-170Lukas Vrabec - 3.13.1-169Lukas Vrabec - 3.13.1-168Lukas Vrabec - 3.13.1-167Lukas Vrabec - 3.13.1-166Lukas Vrabec - 3.13.1-165Lukas Vrabec - 3.13.1-164Lukas Vrabec - 3.13.1-163Lukas Vrabec - 3.13.1-162Lukas Vrabec - 3.13.1-161Lukas Vrabec - 3.13.1-160Lukas Vrabec - 3.13.1-159Lukas Vrabec - 3.13.1-158Lukas Vrabec - 3.13.1-157Lukas Vrabec - 3.13.1-156Lukas Vrabec - 3.13.1-155Lukas Vrabec - 3.13.1-154Lukas Vrabec - 3.13.1-153Lukas Vrabec - 3.13.1-152Lukas Vrabec - 3.13.1-151Lukas Vrabec - 3.13.1-150Lukas Vrabec - 3.13.1-149Lukas Vrabec - 3.13.1-148Lukas Vrabec - 3.13.1-147Lukas Vrabec - 3.13.1-146Lukas Vrabec - 3.13.1-145Lukas Vrabec - 3.13.1-144Lukas Vrabec - 3.13.1-143Lukas Vrabec - 3.13.1-142Lukas Vrabec - 3.13.1-141Lukas Vrabec - 3.13.1-140Lukas Vrabec - 3.13.1-139Lukas Vrabec - 3.13.1-138Lukas Vrabec - 3.13.1-137Lukas Vrabec - 3.13.1-136Lukas Vrabec - 3.13.1-135Lukas Vrabec - 3.13.1-134Lukas Vrabec - 3.13.1-133Lukas Vrabec - 3.13.1-132Lukas Vrabec - 3.13.1-131Lukas Vrabec - 3.13.1-130Lukas Vrabec - 3.13.1-129Lukas Vrabec - 3.13.1-128Lukas Vrabec - 3.13.1-127Lukas Vrabec - 3.13.1-126Lukas Vrabec - 3.13.1-125Lukas Vrabec - 3.13.1-124Lukas Vrabec - 3.13.1-123Lukas Vrabec - 3.13.1-122Lukas Vrabec - 3.13.1-120Lukas Vrabec - 3.13.1-119Lukas Vrabec - 3.13.1-118Lukas Vrabec - 3.13.1-117Lukas Vrabec - 3.13.1-116Lukas Vrabec - 3.13.1-115Lukas Vrabec - 3.13.1-114Lukas Vrabec - 3.13.1-113Lukas Vrabec - 3.13.1-112Lukas Vrabec - 3.13.1-111Lukas Vrabec - 3.13.1-110Lukas Vrabec - 3.13.1-109Lukas Vrabec - 3.13.1-108Lukas Vrabec - 3.13.1-107Lukas Vrabec - 3.13.1-106Miroslav Grepl - 3.13.1-105Lukas Vrabec - 3.13.1-104Lukas Vrabec - 3.13.1-103Dan Walsh - 3.13.1-102Lukas Vrabec - 3.13.1-101Lukas Vrabec - 3.13.1-100Lukas Vrabec - 3.13.1-99Lukas Vrabec - 3.13.1-98Lukas Vrabec - 3.13.1-97Lukas Vrabec - 3.13.1-96Lukas Vrabec - 3.13.1-95Lukas Vrabec - 3.13.1-94Lukas Vrabec - 3.13.1-93Lukas Vrabec - 3.13.1-92Lukas Vrabec - 3.13.1-91Lukas Vrabec - 3.13.1-90Lukas Vrabec - 3.13.1-89Lukas Vrabec - 3.13.1-88Lukas Vrabec - 3.13.1-87Lukas Vrabec - 3.13.1-86Lukas Vrabec - 3.13.1-85Lukas Vrabec - 3.13.1-84Lukas Vrabec - 3.13.1-83Lukas Vrabec - 3.13.1-82Lukas Vrabec - 3.13.1-81Lukas Vrabec - 3.13.1-80Petr Lautrbach - 3.13.1-79Lukas Vrabec - 3.13.1-78Lukas Vrabec - 3.13.1-77Lukas Vrabec - 3.13.1-76Lukas Vrabec - 3.13.1-75Lukas Vrabec - 3.13.1-74Lukas Vrabec - 3.13.1-73Lukas Vrabec - 3.13.1-72Lukas Vrabec - 3.13.1-71Lukas Vrabec - 3.13.1-70Lukas Vrabec - 3.13.1-69Lukas Vrabec - 3.13.1-68Lukas Vrabec - 3.13.1-67Petr Lautrbach - 3.13.1-66Lukas Vrabec 3.13.1-65Lukas Vrabec 3.13.1-64Lukas Vrabec 3.13.1-63Lukas Vrabec 3.13.1-62Lukas Vrabec 3.13.1-61Miroslav Grepl 3.13.1-60Miroslav Grepl 3.13.1-59Lukas Vrabec 3.13.1-58Lukas Vrabec 3.13.1-57Miroslav Grepl 3.13.1-56Lukas Vrabec 3.13.1-55Lukas Vrabec 3.13.1-54Lukas Vrabec 3.13.1-53Lukas Vrabec 3.13.1-52Miroslav Grepl 3.13.1-51Lukas Vrabec 3.13.1-50Lukas Vrabec 3.13.1-49Lukas Vrabec 3.13.1-48Lukas Vrabec 3.13.1-47Lukas Vrabec 3.13.1-46Lukas Vrabec 3.13.1-45Lukas Vrabec 3.13.1-44Lukas Vrabec 3.13.1-43Lukas Vrabec 3.13.1-42Lukas Vrabec 3.13.1-41Lukas Vrabec 3.13.1-40Miroslav Grepl 3.13.1-39Lukas Vrabec 3.13.1-38Lukas Vrabec 3.13.1-37Lukas Vrabec 3.13.1-36Lukas Vrabec 3.13.1-35Lukas Vrabec 3.13.1-34Lukas Vrabec 3.13.1-33Lukas Vrabec 3.13.1-32Miroslav Grepl 3.13.1-31Miroslav Grepl 3.13.1-30Miroslav Grepl 3.13.1-29Miroslav Grepl 3.13.1-28Miroslav Grepl 3.13.1-27Miroslav Grepl 3.13.1-26Miroslav Grepl 3.13.1-25Miroslav Grepl 3.13.1-24Miroslav Grepl 3.13.1-23Miroslav Grepl 3.13.1-22Miroslav Grepl 3.13.1-21Miroslav Grepl 3.13.1-20Miroslav Grepl 3.13.1-19Miroslav Grepl 3.13.1-18Miroslav Grepl 3.13.1-17Miroslav Grepl 3.13.1-16Miroslav Grepl 3.13.1-15Miroslav Grepl 3.13.1-14Miroslav Grepl 3.13.1-13Miroslav Grepl 3.13.1-12Miroslav Grepl 3.13.1-11Miroslav Grepl 3.13.1-10Miroslav Grepl 3.13.1-9Miroslav Grepl 3.13.1-8Miroslav Grepl 3.13.1-7Miroslav Grepl 3.13.1-6Miroslav Grepl 3.13.1-5Miroslav Grepl 3.13.1-4Miroslav Grepl 3.13.1-3Miroslav Grepl 3.13.1-2Miroslav Grepl 3.13.1-1Miroslav Grepl 3.12.1-156Miroslav Grepl 3.12.1-155Miroslav Grepl 3.12.1-154Miroslav Grepl 3.12.1-153Miroslav Grepl 3.12.1-152Miroslav Grepl 3.12.1-151Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-148Miroslav Grepl 3.12.1-147Miroslav Grepl 3.12.1-146Miroslav Grepl 3.12.1-145Miroslav Grepl 3.12.1-144Lukas Vrabec 3.12.1-143Miroslav Grepl 3.12.1-142Miroslav Grepl 3.12.1-141Miroslav Grepl 3.12.1-140Miroslav Grepl 3.12.1-139Lukas Vrabec 3.12.1-138Miroslav Grepl 3.12.1-137Miroslav Grepl 3.12.1-136Miroslav Grepl 3.12.1-135Miroslav Grepl 3.12.1-134Miroslav Grepl 3.12.1-133Miroslav Grepl 3.12.1-132Miroslav Grepl 3.12.1-131Miroslav Grepl 3.12.1-130Miroslav Grepl 3.12.1-129Miroslav Grepl 3.12.1-128Miroslav Grepl 3.12.1-127Miroslav Grepl 3.12.1-126Miroslav Grepl 3.12.1-125Miroslav Grepl 3.12.1-124Miroslav Grepl 3.12.1-123Miroslav Grepl 3.12.1-122Miroslav Grepl 3.12.1-121Miroslav Grepl 3.12.1-120Miroslav Grepl 3.12.1-119Miroslav Grepl 3.12.1-118Miroslav Grepl 3.12.1-117Miroslav Grepl 3.12.1-116Miroslav Grepl 3.12.1-115Miroslav Grepl 3.12.1-114Miroslav Grepl 3.12.1-113Miroslav Grepl 3.12.1-112Miroslav Grepl 3.12.1-111Miroslav Grepl 3.12.1-110Miroslav Grepl 3.12.1-109Miroslav Grepl 3.12.1-108Miroslav Grepl 3.12.1-107Dan Walsh 3.12.1-106Miroslav Grepl 3.12.1-105Miroslav Grepl 3.12.1-104Miroslav Grepl 3.12.1-103Miroslav Grepl 3.12.1-102Miroslav Grepl 3.12.1-101Miroslav Grepl 3.12.1-100Miroslav Grepl 3.12.1-99Miroslav Grepl 3.12.1-98Miroslav Grepl 3.12.1-97Miroslav Grepl 3.12.1-96Miroslav Grepl 3.12.1-95Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-93Miroslav Grepl 3.12.1-92Miroslav Grepl 3.12.1-91Miroslav Grepl 3.12.1-90Miroslav Grepl 3.12.1-89Miroslav Grepl 3.12.1-88Miroslav Grepl 3.12.1-87Miroslav Grepl 3.12.1-86Miroslav Grepl 3.12.1-85Miroslav Grepl 3.12.1-84Miroslav Grepl 3.12.1-83Miroslav Grepl 3.12.1-82Miroslav Grepl 3.12.1-81Miroslav Grepl 3.12.1-80Miroslav Grepl 3.12.1-79Miroslav Grepl 3.12.1-78Miroslav Grepl 3.12.1-77Miroslav Grepl 3.12.1-76Miroslav Grepl 3.12.1-75Miroslav Grepl 3.12.1-74Miroslav Grepl 3.12.1-73Miroslav Grepl 3.12.1-72Miroslav Grepl 3.12.1-71Miroslav Grepl 3.12.1-70Miroslav Grepl 3.12.1-69Miroslav Grepl 3.12.1-68Miroslav Grepl 3.12.1-67Miroslav Grepl 3.12.1-66Miroslav Grepl 3.12.1-65Miroslav Grepl 3.12.1-64Miroslav Grepl 3.12.1-63Miroslav Grepl 3.12.1-62Miroslav Grepl 3.12.1-61Miroslav Grepl 3.12.1-60Miroslav Grepl 3.12.1-59Miroslav Grepl 3.12.1-58Miroslav Grepl 3.12.1-57Miroslav Grepl 3.12.1-56Miroslav Grepl 3.12.1-55Miroslav Grepl 3.12.1-54Miroslav Grepl 3.12.1-53Miroslav Grepl 3.12.1-52Miroslav Grepl 3.12.1-51Miroslav Grepl 3.12.1-50Miroslav Grepl 3.12.1-49Miroslav Grepl 3.12.1-48Miroslav Grepl 3.12.1-47Miroslav Grepl 3.12.1-46Miroslav Grepl 3.12.1-45Miroslav Grepl 3.12.1-44Miroslav Grepl 3.12.1-43Miroslav Grepl 3.12.1-42Miroslav Grepl 3.12.1-41Miroslav Grepl 3.12.1-40Miroslav Grepl 3.12.1-39Miroslav Grepl 3.12.1-38Miroslav Grepl 3.12.1-37Miroslav Grepl 3.12.1-36Miroslav Grepl 3.12.1-35Miroslav Grepl 3.12.1-34Miroslav Grepl 3.12.1-33Miroslav Grepl 3.12.1-32Miroslav Grepl 3.12.1-31Miroslav Grepl 3.12.1-30Miroslav Grepl 3.12.1-29Dan Walsh 3.12.1-28Dan Walsh 3.12.1-27Miroslav Grepl 3.12.1-26Miroslav Grepl 3.12.1-25Miroslav Grepl 3.12.1-24Miroslav Grepl 3.12.1-23Miroslav Grepl 3.12.1-22Miroslav Grepl 3.12.1-21Miroslav Grepl 3.12.1-20Miroslav Grepl 3.12.1-19Miroslav Grepl 3.12.1-18Miroslav Grepl 3.12.1-17Miroslav Grepl 3.12.1-16Miroslav Grepl 3.12.1-15Miroslav Grepl 3.12.1-14Miroslav Grepl 3.12.1-13Miroslav Grepl 3.12.1-12Miroslav Grepl 3.12.1-11Miroslav Grepl 3.12.1-10Miroslav Grepl 3.12.1-9Miroslav Grepl 3.12.1-8Miroslav Grepl 3.12.1-7Miroslav Grepl 3.12.1-6Miroslav Grepl 3.12.1-5Miroslav Grepl 3.12.1-4Miroslav Grepl 3.12.1-3Miroslav Grepl 3.12.1-2Miroslav Grepl 3.12.1-1Dan Walsh 3.11.1-69.1Miroslav Grepl 3.11.1-69Miroslav Grepl 3.11.1-68Miroslav Grepl 3.11.1-67Miroslav Grepl 3.11.1-66Miroslav Grepl 3.11.1-65Miroslav Grepl 3.11.1-64Miroslav Grepl 3.11.1-63Miroslav Grepl 3.11.1-62Miroslav Grepl 3.11.1-61Miroslav Grepl 3.11.1-60Miroslav Grepl 3.11.1-59Miroslav Grepl 3.11.1-58Miroslav Grepl 3.11.1-57Miroslav Grepl 3.11.1-56Miroslav Grepl 3.11.1-55Miroslav Grepl 3.11.1-54Miroslav Grepl 3.11.1-53Miroslav Grepl 3.11.1-52Miroslav Grepl 3.11.1-51Miroslav Grepl 3.11.1-50Miroslav Grepl 3.11.1-49Miroslav Grepl 3.11.1-48Miroslav Grepl 3.11.1-47Miroslav Grepl 3.11.1-46Miroslav Grepl 3.11.1-45Miroslav Grepl 3.11.1-44Miroslav Grepl 3.11.1-43Miroslav Grepl 3.11.1-42Miroslav Grepl 3.11.1-41Miroslav Grepl 3.11.1-40Miroslav Grepl 3.11.1-39Miroslav Grepl 3.11.1-38Miroslav Grepl 3.11.1-37Miroslav Grepl 3.11.1-36Miroslav Grepl 3.11.1-35Miroslav Grepl 3.11.1-34Miroslav Grepl 3.11.1-33Miroslav Grepl 3.11.1-32Miroslav Grepl 3.11.1-31Miroslav Grepl 3.11.1-30Miroslav Grepl 3.11.1-29Miroslav Grepl 3.11.1-28Miroslav Grepl 3.11.1-27Miroslav Grepl 3.11.1-26Miroslav Grepl 3.11.1-25Miroslav Grepl 3.11.1-24Miroslav Grepl 3.11.1-23Miroslav Grepl 3.11.1-22Miroslav Grepl 3.11.1-21Miroslav Grepl 3.11.1-20Miroslav Grepl 3.11.1-19Miroslav Grepl 3.11.1-18Miroslav Grepl 3.11.1-17Miroslav Grepl 3.11.1-16Dan Walsh 3.11.1-15Miroslav Grepl 3.11.1-14Dan Walsh 3.11.1-13Miroslav Grepl 3.11.1-12Miroslav Grepl 3.11.1-11Miroslav Grepl 3.11.1-10Dan Walsh 3.11.1-9Dan Walsh 3.11.1-8Dan Walsh 3.11.1-7Dan Walsh 3.11.1-6Miroslav Grepl 3.11.1-5Miroslav Grepl 3.11.1-4Miroslav Grepl 3.11.1-3Miroslav Grepl 3.11.1-2Miroslav Grepl 3.11.1-1Miroslav Grepl 3.11.1-0Miroslav Grepl 3.11.0-15Miroslav Grepl 3.11.0-14Miroslav Grepl 3.11.0-13Miroslav Grepl 3.11.0-12Fedora Release Engineering - 3.11.0-11Miroslav Grepl 3.11.0-10Miroslav Grepl 3.11.0-9Miroslav Grepl 3.11.0-8Miroslav Grepl 3.11.0-7Miroslav Grepl 3.11.0-6Miroslav Grepl 3.11.0-5Miroslav Grepl 3.11.0-4Miroslav Grepl 3.11.0-3Miroslav Grepl 3.11.0-2Miroslav Grepl 3.11.0-1Miroslav Grepl 3.10.0-128Miroslav Grepl 3.10.0-127Miroslav Grepl 3.10.0-126Miroslav Grepl 3.10.0-125Miroslav Grepl 3.10.0-124Miroslav Grepl 3.10.0-123Miroslav Grepl 3.10.0-122Miroslav Grepl 3.10.0-121Miroslav Grepl 3.10.0-120Miroslav Grepl 3.10.0-119Miroslav Grepl 3.10.0-118Miroslav Grepl 3.10.0-117Miroslav Grepl 3.10.0-116Miroslav Grepl 3.10.0-115Miroslav Grepl 3.10.0-114Miroslav Grepl 3.10.0-113Miroslav Grepl 3.10.0-112Miroslav Grepl 3.10.0-111Miroslav Grepl 3.10.0-110Miroslav Grepl 3.10.0-109Miroslav Grepl 3.10.0-108Miroslav Grepl 3.10.0-107Miroslav Grepl 3.10.0-106Miroslav Grepl 3.10.0-105Miroslav Grepl 3.10.0-104Miroslav Grepl 3.10.0-103Miroslav Grepl 3.10.0-102Miroslav Grepl 3.10.0-101Miroslav Grepl 3.10.0-100Miroslav Grepl 3.10.0-99Miroslav Grepl 3.10.0-98Miroslav Grepl 3.10.0-97Miroslav Grepl 3.10.0-96Miroslav Grepl 3.10.0-95Miroslav Grepl 3.10.0-94Miroslav Grepl 3.10.0-93Miroslav Grepl 3.10.0-92Miroslav Grepl 3.10.0-91Miroslav Grepl 3.10.0-90Miroslav Grepl 3.10.0-89Miroslav Grepl 3.10.0-88Miroslav Grepl 3.10.0-87Miroslav Grepl 3.10.0-86Miroslav Grepl 3.10.0-85Miroslav Grepl 3.10.0-84Miroslav Grepl 3.10.0-83Miroslav Grepl 3.10.0-82Dan Walsh 3.10.0-81.2Miroslav Grepl 3.10.0-81Miroslav Grepl 3.10.0-80Miroslav Grepl 3.10.0-79Miroslav Grepl 3.10.0-78Miroslav Grepl 3.10.0-77Miroslav Grepl 3.10.0-76Miroslav Grepl 3.10.0-75Dan Walsh 3.10.0-74.2Miroslav Grepl 3.10.0-74Miroslav Grepl 3.10.0-73Miroslav Grepl 3.10.0-72Miroslav Grepl 3.10.0-71Miroslav Grepl 3.10.0-70Miroslav Grepl 3.10.0-69Miroslav Grepl 3.10.0-68Miroslav Grepl 3.10.0-67Miroslav Grepl 3.10.0-66Miroslav Grepl 3.10.0-65Miroslav Grepl 3.10.0-64Miroslav Grepl 3.10.0-63Miroslav Grepl 3.10.0-59Miroslav Grepl 3.10.0-58Dan Walsh 3.10.0-57Dan Walsh 3.10.0-56Dan Walsh 3.10.0-55.2Dan Walsh 3.10.0-55.1Miroslav Grepl 3.10.0-55Dan Walsh 3.10.0-54.1Miroslav Grepl 3.10.0-54Dan Walsh 3.10.0-53.1Miroslav Grepl 3.10.0-53Miroslav Grepl 3.10.0-52Miroslav Grepl 3.10.0-51Dan Walsh 3.10.0-50.2Dan Walsh 3.10.0-50.1Miroslav Grepl 3.10.0-50Miroslav Grepl 3.10.0-49Miroslav Grepl 3.10.0-48Miroslav Grepl 3.10.0-47Dan Walsh 3.10.0-46.1Miroslav Grepl 3.10.0-46Dan Walsh 3.10.0-45.1Miroslav Grepl 3.10.0-45Miroslav Grepl 3.10.0-43Miroslav Grepl 3.10.0-42Miroslav Grepl 3.10.0-41Dan Walsh 3.10.0-40.2Miroslav Grepl 3.10.0-40Dan Walsh 3.10.0-39.3Dan Walsh 3.10.0-39.2Dan Walsh 3.10.0-39.1Miroslav Grepl 3.10.0-39Dan Walsh 3.10.0-38.1Miroslav Grepl 3.10.0-38Miroslav Grepl 3.10.0-37Dan Walsh 3.10.0-36.1Miroslav Grepl 3.10.0-36Dan Walsh 3.10.0-35Dan Walsh 3.10.0-34.7Dan Walsh 3.10.0-34.6Dan Walsh 3.10.0-34.4Miroslav Grepl 3.10.0-34.3Dan Walsh 3.10.0-34.2Dan Walsh 3.10.0-34.1Miroslav Grepl 3.10.0-34Miroslav Grepl 3.10.0-33Dan Walsh 3.10.0-31.1Miroslav Grepl 3.10.0-31Miroslav Grepl 3.10.0-29Miroslav Grepl 3.10.0-28Miroslav Grepl 3.10.0-27Miroslav Grepl 3.10.0-26Miroslav Grepl 3.10.0-25Miroslav Grepl 3.10.0-24Miroslav Grepl 3.10.0-23Miroslav Grepl 3.10.0-22Miroslav Grepl 3.10.0-21Dan Walsh 3.10.0-20Miroslav Grepl 3.10.0-19Miroslav Grepl 3.10.0-18Miroslav Grepl 3.10.0-17Miroslav Grepl 3.10.0-16Miroslav Grepl 3.10.0-14Miroslav Grepl 3.10.0-13Miroslav Grepl 3.10.0-12Miroslav Grepl 3.10.0-11Miroslav Grepl 3.10.0-10Miroslav Grepl 3.10.0-9Miroslav Grepl 3.10.0-8Miroslav Grepl 3.10.0-7Miroslav Grepl 3.10.0-6Miroslav Grepl 3.10.0-5Miroslav Grepl 3.10.0-4Miroslav Grepl 3.10.0-3Miroslav Grepl 3.10.0-2Miroslav Grepl 3.10.0-1Miroslav Grepl 3.9.16-30Dan Walsh 3.9.16-29.1Miroslav Grepl 3.9.16-29Dan Walsh 3.9.16-28.1Miroslav Grepl 3.9.16-27Miroslav Grepl 3.9.16-26Miroslav Grepl 3.9.16-25Miroslav Grepl 3.9.16-24Miroslav Grepl 3.9.16-23Miroslav Grepl 3.9.16-22Miroslav Grepl 3.9.16-21Miroslav Grepl 3.9.16-20Miroslav Grepl 3.9.16-19Miroslav Grepl 3.9.16-18Miroslav Grepl 3.9.16-17Dan Walsh 3.9.16-16.1Miroslav Grepl 3.9.16-16Miroslav Grepl 3.9.16-15Miroslav Grepl 3.9.16-14Miroslav Grepl 3.9.16-13Miroslav Grepl 3.9.16-12Miroslav Grepl 3.9.16-11Miroslav Grepl 3.9.16-10Miroslav Grepl 3.9.16-7Miroslav Grepl 3.9.16-6Miroslav Grepl 3.9.16-5Miroslav Grepl 3.9.16-4Miroslav Grepl 3.9.16-3Miroslav Grepl 3.9.16-2Miroslav Grepl 3.9.16-1Miroslav Grepl 3.9.15-5Miroslav Grepl 3.9.15-2Miroslav Grepl 3.9.15-1Fedora Release Engineering - 3.9.14-2Dan Walsh 3.9.14-1Miroslav Grepl 3.9.13-10Miroslav Grepl 3.9.13-9Dan Walsh 3.9.13-8Miroslav Grepl 3.9.13-7Miroslav Grepl 3.9.13-6Miroslav Grepl 3.9.13-5Miroslav Grepl 3.9.13-4Miroslav Grepl 3.9.13-3Miroslav Grepl 3.9.13-2Miroslav Grepl 3.9.13-1Miroslav Grepl 3.9.12-8Miroslav Grepl 3.9.12-7Miroslav Grepl 3.9.12-6Miroslav Grepl 3.9.12-5Dan Walsh 3.9.12-4Dan Walsh 3.9.12-3Dan Walsh 3.9.12-2Miroslav Grepl 3.9.12-1Dan Walsh 3.9.11-2Miroslav Grepl 3.9.11-1Miroslav Grepl 3.9.10-13Dan Walsh 3.9.10-12Miroslav Grepl 3.9.10-11Miroslav Grepl 3.9.10-10Miroslav Grepl 3.9.10-9Miroslav Grepl 3.9.10-8Miroslav Grepl 3.9.10-7Miroslav Grepl 3.9.10-6Miroslav Grepl 3.9.10-5Dan Walsh 3.9.10-4Miroslav Grepl 3.9.10-3Miroslav Grepl 3.9.10-2Miroslav Grepl 3.9.10-1Miroslav Grepl 3.9.9-4Dan Walsh 3.9.9-3Miroslav Grepl 3.9.9-2Miroslav Grepl 3.9.9-1Miroslav Grepl 3.9.8-7Dan Walsh 3.9.8-6Miroslav Grepl 3.9.8-5Miroslav Grepl 3.9.8-4Dan Walsh 3.9.8-3Dan Walsh 3.9.8-2Dan Walsh 3.9.8-1Dan Walsh 3.9.7-10Dan Walsh 3.9.7-9Dan Walsh 3.9.7-8Dan Walsh 3.9.7-7Dan Walsh 3.9.7-6Dan Walsh 3.9.7-5Dan Walsh 3.9.7-4Dan Walsh 3.9.7-3Dan Walsh 3.9.7-2Dan Walsh 3.9.7-1Dan Walsh 3.9.6-3Dan Walsh 3.9.6-2Dan Walsh 3.9.6-1Dan Walsh 3.9.5-11Dan Walsh 3.9.5-10Dan Walsh 3.9.5-9Dan Walsh 3.9.5-8Dan Walsh 3.9.5-7Dan Walsh 3.9.5-6Dan Walsh 3.9.5-5Dan Walsh 3.9.5-4Dan Walsh 3.9.5-3Dan Walsh 3.9.5-2Dan Walsh 3.9.5-1Dan Walsh 3.9.4-3Dan Walsh 3.9.4-2Dan Walsh 3.9.4-1Dan Walsh 3.9.3-4Dan Walsh 3.9.3-3Dan Walsh 3.9.3-2Dan Walsh 3.9.3-1Dan Walsh 3.9.2-1Dan Walsh 3.9.1-3Dan Walsh 3.9.1-2Dan Walsh 3.9.1-1Dan Walsh 3.9.0-2Dan Walsh 3.9.0-1Dan Walsh 3.8.8-21Dan Walsh 3.8.8-20Dan Walsh 3.8.8-19Dan Walsh 3.8.8-18Dan Walsh 3.8.8-17Dan Walsh 3.8.8-16Dan Walsh 3.8.8-15Dan Walsh 3.8.8-14Dan Walsh 3.8.8-13Dan Walsh 3.8.8-12Dan Walsh 3.8.8-11Dan Walsh 3.8.8-10Dan Walsh 3.8.8-9Dan Walsh 3.8.8-8Dan Walsh 3.8.8-7Dan Walsh 3.8.8-6Dan Walsh 3.8.8-5Dan Walsh 3.8.8-4Dan Walsh 3.8.8-3Dan Walsh 3.8.8-2Dan Walsh 3.8.8-1Dan Walsh 3.8.7-3Dan Walsh 3.8.7-2Dan Walsh 3.8.7-1Dan Walsh 3.8.6-3Miroslav Grepl 3.8.6-2Dan Walsh 3.8.6-1Dan Walsh 3.8.5-1Dan Walsh 3.8.4-1Dan Walsh 3.8.3-4Dan Walsh 3.8.3-3Dan Walsh 3.8.3-2Dan Walsh 3.8.3-1Dan Walsh 3.8.2-1Dan Walsh 3.8.1-5Dan Walsh 3.8.1-4Dan Walsh 3.8.1-3Dan Walsh 3.8.1-2Dan Walsh 3.8.1-1Dan Walsh 3.7.19-22Dan Walsh 3.7.19-21Dan Walsh 3.7.19-20Dan Walsh 3.7.19-19Dan Walsh 3.7.19-17Dan Walsh 3.7.19-16Dan Walsh 3.7.19-15Dan Walsh 3.7.19-14Dan Walsh 3.7.19-13Dan Walsh 3.7.19-12Dan Walsh 3.7.19-11Dan Walsh 3.7.19-10Dan Walsh 3.7.19-9Dan Walsh 3.7.19-8Dan Walsh 3.7.19-7Dan Walsh 3.7.19-6Dan Walsh 3.7.19-5Dan Walsh 3.7.19-4Dan Walsh 3.7.19-3Dan Walsh 3.7.19-2Dan Walsh 3.7.19-1Dan Walsh 3.7.18-3Dan Walsh 3.7.18-2Dan Walsh 3.7.18-1Dan Walsh 3.7.17-6Dan Walsh 3.7.17-5Dan Walsh 3.7.17-4Dan Walsh 3.7.17-3Dan Walsh 3.7.17-2Dan Walsh 3.7.17-1Dan Walsh 3.7.16-2Dan Walsh 3.7.16-1Dan Walsh 3.7.15-4Dan Walsh 3.7.15-3Dan Walsh 3.7.15-2Dan Walsh 3.7.15-1Dan Walsh 3.7.14-5Dan Walsh 3.7.14-4Dan Walsh 3.7.14-3Dan Walsh 3.7.14-2Dan Walsh 3.7.14-1Dan Walsh 3.7.13-4Dan Walsh 3.7.13-3Dan Walsh 3.7.13-2Dan Walsh 3.7.13-1Dan Walsh 3.7.12-1Dan Walsh 3.7.11-1Dan Walsh 3.7.10-5Dan Walsh 3.7.10-4Dan Walsh 3.7.10-3Dan Walsh 3.7.10-2Dan Walsh 3.7.10-1Dan Walsh 3.7.9-4Dan Walsh 3.7.9-3Dan Walsh 3.7.9-2Dan Walsh 3.7.9-1Dan Walsh 3.7.8-11Dan Walsh 3.7.8-9Dan Walsh 3.7.8-8Dan Walsh 3.7.8-7Dan Walsh 3.7.8-6Dan Walsh 3.7.8-5Dan Walsh 3.7.8-4Dan Walsh 3.7.8-3Dan Walsh 3.7.8-2Dan Walsh 3.7.8-1Dan Walsh 3.7.7-3Dan Walsh 3.7.7-2Dan Walsh 3.7.7-1Dan Walsh 3.7.6-1Dan Walsh 3.7.5-8Dan Walsh 3.7.5-7Dan Walsh 3.7.5-6Dan Walsh 3.7.5-5Dan Walsh 3.7.5-4Dan Walsh 3.7.5-3Dan Walsh 3.7.5-2Dan Walsh 3.7.5-1Dan Walsh 3.7.4-4Dan Walsh 3.7.4-3Dan Walsh 3.7.4-2Dan Walsh 3.7.4-1Dan Walsh 3.7.3-1Dan Walsh 3.7.1-1Dan Walsh 3.6.33-2Dan Walsh 3.6.33-1Dan Walsh 3.6.32-17Dan Walsh 3.6.32-16Dan Walsh 3.6.32-15Dan Walsh 3.6.32-13Dan Walsh 3.6.32-12Dan Walsh 3.6.32-11Dan Walsh 3.6.32-10Dan Walsh 3.6.32-9Dan Walsh 3.6.32-8Dan Walsh 3.6.32-7Dan Walsh 3.6.32-6Dan Walsh 3.6.32-5Dan Walsh 3.6.32-4Dan Walsh 3.6.32-3Dan Walsh 3.6.32-2Dan Walsh 3.6.32-1Dan Walsh 3.6.31-5Dan Walsh 3.6.31-4Dan Walsh 3.6.31-3Dan Walsh 3.6.31-2Dan Walsh 3.6.30-6Dan Walsh 3.6.30-5Dan Walsh 3.6.30-4Dan Walsh 3.6.30-3Dan Walsh 3.6.30-2Dan Walsh 3.6.30-1Dan Walsh 3.6.29-2Dan Walsh 3.6.29-1Dan Walsh 3.6.28-9Dan Walsh 3.6.28-8Dan Walsh 3.6.28-7Dan Walsh 3.6.28-6Dan Walsh 3.6.28-5Dan Walsh 3.6.28-4Dan Walsh 3.6.28-3Dan Walsh 3.6.28-2Dan Walsh 3.6.28-1Dan Walsh 3.6.27-1Dan Walsh 3.6.26-11Dan Walsh 3.6.26-10Dan Walsh 3.6.26-9Bill Nottingham 3.6.26-8Dan Walsh 3.6.26-7Dan Walsh 3.6.26-6Dan Walsh 3.6.26-5Dan Walsh 3.6.26-4Dan Walsh 3.6.26-3Dan Walsh 3.6.26-2Dan Walsh 3.6.26-1Dan Walsh 3.6.25-1Dan Walsh 3.6.24-1Dan Walsh 3.6.23-2Dan Walsh 3.6.23-1Dan Walsh 3.6.22-3Dan Walsh 3.6.22-1Dan Walsh 3.6.21-4Dan Walsh 3.6.21-3Tom "spot" Callaway 3.6.21-2Dan Walsh 3.6.21-1Dan Walsh 3.6.20-2Dan Walsh 3.6.20-1Dan Walsh 3.6.19-5Dan Walsh 3.6.19-4Dan Walsh 3.6.19-3Dan Walsh 3.6.19-2Dan Walsh 3.6.19-1Dan Walsh 3.6.18-1Dan Walsh 3.6.17-1Dan Walsh 3.6.16-4Dan Walsh 3.6.16-3Dan Walsh 3.6.16-2Dan Walsh 3.6.16-1Dan Walsh 3.6.14-3Dan Walsh 3.6.14-2Dan Walsh 3.6.14-1Dan Walsh 3.6.13-3Dan Walsh 3.6.13-2Dan Walsh 3.6.13-1Dan Walsh 3.6.12-39Dan Walsh 3.6.12-38Dan Walsh 3.6.12-37Dan Walsh 3.6.12-36Dan Walsh 3.6.12-35Dan Walsh 3.6.12-34Dan Walsh 3.6.12-33Dan Walsh 3.6.12-31Dan Walsh 3.6.12-30Dan Walsh 3.6.12-29Dan Walsh 3.6.12-28Dan Walsh 3.6.12-27Dan Walsh 3.6.12-26Dan Walsh 3.6.12-25Dan Walsh 3.6.12-24Dan Walsh 3.6.12-23Dan Walsh 3.6.12-22Dan Walsh 3.6.12-21Dan Walsh 3.6.12-20Dan Walsh 3.6.12-19Dan Walsh 3.6.12-16Dan Walsh 3.6.12-15Dan Walsh 3.6.12-14Dan Walsh 3.6.12-13Dan Walsh 3.6.12-12Dan Walsh 3.6.12-11Dan Walsh 3.6.12-10Dan Walsh 3.6.12-9Dan Walsh 3.6.12-8Dan Walsh 3.6.12-7Dan Walsh 3.6.12-6Dan Walsh 3.6.12-5Dan Walsh 3.6.12-4Dan Walsh 3.6.12-3Dan Walsh 3.6.12-2Dan Walsh 3.6.12-1Dan Walsh 3.6.11-1Dan Walsh 3.6.10-9Dan Walsh 3.6.10-8Dan Walsh 3.6.10-7Dan Walsh 3.6.10-6Dan Walsh 3.6.10-5Dan Walsh 3.6.10-4Dan Walsh 3.6.10-3Dan Walsh 3.6.10-2Dan Walsh 3.6.10-1Dan Walsh 3.6.9-4Dan Walsh 3.6.9-3Dan Walsh 3.6.9-2Dan Walsh 3.6.9-1Dan Walsh 3.6.8-4Dan Walsh 3.6.8-3Dan Walsh 3.6.8-2Dan Walsh 3.6.8-1Dan Walsh 3.6.7-2Dan Walsh 3.6.7-1Dan Walsh 3.6.6-9Dan Walsh 3.6.6-8Fedora Release Engineering - 3.6.6-7Dan Walsh 3.6.6-6Dan Walsh 3.6.6-5Dan Walsh 3.6.6-4Dan Walsh 3.6.6-3Dan Walsh 3.6.6-2Dan Walsh 3.6.6-1Dan Walsh 3.6.5-3Dan Walsh 3.6.5-1Dan Walsh 3.6.4-6Dan Walsh 3.6.4-5Dan Walsh 3.6.4-4Dan Walsh 3.6.4-3Dan Walsh 3.6.4-2Dan Walsh 3.6.4-1Dan Walsh 3.6.3-13Dan Walsh 3.6.3-12Dan Walsh 3.6.3-11Dan Walsh 3.6.3-10Dan Walsh 3.6.3-9Dan Walsh 3.6.3-8Dan Walsh 3.6.3-7Dan Walsh 3.6.3-6Dan Walsh 3.6.3-3Dan Walsh 3.6.3-2Dan Walsh 3.6.3-1Dan Walsh 3.6.2-5Dan Walsh 3.6.2-4Dan Walsh 3.6.2-3Dan Walsh 3.6.2-2Dan Walsh 3.6.2-1Dan Walsh 3.6.1-15Dan Walsh 3.6.1-14Dan Walsh 3.6.1-13Dan Walsh 3.6.1-12Dan Walsh 3.6.1-11Dan Walsh 3.6.1-10Dan Walsh 3.6.1-9Dan Walsh 3.6.1-8Dan Walsh 3.6.1-7Dan Walsh 3.6.1-4Ignacio Vazquez-Abrams - 3.6.1-2Dan Walsh 3.5.13-19Dan Walsh 3.5.13-18Dan Walsh 3.5.13-17Dan Walsh 3.5.13-16Dan Walsh 3.5.13-15Dan Walsh 3.5.13-14Dan Walsh 3.5.13-13Dan Walsh 3.5.13-12Dan Walsh 3.5.13-11Dan Walsh 3.5.13-9Dan Walsh 3.5.13-8Dan Walsh 3.5.13-7Dan Walsh 3.5.13-6Dan Walsh 3.5.13-5Dan Walsh 3.5.13-4Dan Walsh 3.5.13-3Dan Walsh 3.5.13-2Dan Walsh 3.5.13-1Dan Walsh 3.5.12-3Dan Walsh 3.5.12-2Dan Walsh 3.5.12-1Dan Walsh 3.5.11-1Dan Walsh 3.5.10-3Dan Walsh 3.5.10-2Dan Walsh 3.5.10-1Dan Walsh 3.5.9-4Dan Walsh 3.5.9-3Dan Walsh 3.5.9-2Dan Walsh 3.5.9-1Dan Walsh 3.5.8-7Dan Walsh 3.5.8-6Dan Walsh 3.5.8-5Dan Walsh 3.5.8-4Dan Walsh 3.5.8-3Dan Walsh 3.5.8-1Dan Walsh 3.5.7-2Dan Walsh 3.5.7-1Dan Walsh 3.5.6-2Dan Walsh 3.5.6-1Dan Walsh 3.5.5-4Dan Walsh 3.5.5-3Dan Walsh 3.5.5-2Dan Walsh 3.5.4-2Dan Walsh 3.5.4-1Dan Walsh 3.5.3-1Dan Walsh 3.5.2-2Dan Walsh 3.5.1-5Dan Walsh 3.5.1-4Dan Walsh 3.5.1-3Dan Walsh 3.5.1-2Dan Walsh 3.5.1-1Dan Walsh 3.5.0-1Dan Walsh 3.4.2-14Dan Walsh 3.4.2-13Dan Walsh 3.4.2-12Dan Walsh 3.4.2-11Dan Walsh 3.4.2-10Dan Walsh 3.4.2-9Dan Walsh 3.4.2-8Dan Walsh 3.4.2-7Dan Walsh 3.4.2-6Dan Walsh 3.4.2-5Dan Walsh 3.4.2-4Dan Walsh 3.4.2-3Dan Walsh 3.4.2-2Dan Walsh 3.4.2-1Dan Walsh 3.4.1-5Dan Walsh 3.4.1-3Dan Walsh 3.4.1-2Dan Walsh 3.4.1-1Dan Walsh 3.3.1-48Dan Walsh 3.3.1-47Dan Walsh 3.3.1-46Dan Walsh 3.3.1-45Dan Walsh 3.3.1-44Dan Walsh 3.3.1-43Dan Walsh 3.3.1-42Dan Walsh 3.3.1-41Dan Walsh 3.3.1-39Dan Walsh 3.3.1-37Dan Walsh 3.3.1-36Dan Walsh 3.3.1-33Dan Walsh 3.3.1-32Dan Walsh 3.3.1-31Dan Walsh 3.3.1-30Dan Walsh 3.3.1-29Dan Walsh 3.3.1-28Dan Walsh 3.3.1-27Dan Walsh 3.3.1-26Dan Walsh 3.3.1-25Dan Walsh 3.3.1-24Dan Walsh 3.3.1-23Dan Walsh 3.3.1-22Dan Walsh 3.3.1-21Dan Walsh 3.3.1-20Dan Walsh 3.3.1-19Dan Walsh 3.3.1-18Dan Walsh 3.3.1-17Dan Walsh 3.3.1-16Dan Walsh 3.3.1-15Bill Nottingham 3.3.1-14Dan Walsh 3.3.1-13Dan Walsh 3.3.1-12Dan Walsh 3.3.1-11Dan Walsh 3.3.1-10Dan Walsh 3.3.1-9Dan Walsh 3.3.1-8Dan Walsh 3.3.1-6Dan Walsh 3.3.1-5Dan Walsh 3.3.1-4Dan Walsh 3.3.1-2Dan Walsh 3.3.1-1Dan Walsh 3.3.0-2Dan Walsh 3.3.0-1Dan Walsh 3.2.9-2Dan Walsh 3.2.9-1Dan Walsh 3.2.8-2Dan Walsh 3.2.8-1Dan Walsh 3.2.7-6Dan Walsh 3.2.7-5Dan Walsh 3.2.7-3Dan Walsh 3.2.7-2Dan Walsh 3.2.7-1Dan Walsh 3.2.6-7Dan Walsh 3.2.6-6Dan Walsh 3.2.6-5Dan Walsh 3.2.6-4Dan Walsh 3.2.6-3Dan Walsh 3.2.6-2Dan Walsh 3.2.6-1Dan Walsh 3.2.5-25Dan Walsh 3.2.5-24Dan Walsh 3.2.5-22Dan Walsh 3.2.5-21Dan Walsh 3.2.5-20Dan Walsh 3.2.5-19Dan Walsh 3.2.5-18Dan Walsh 3.2.5-17Dan Walsh 3.2.5-16Dan Walsh 3.2.5-15Dan Walsh 3.2.5-14Dan Walsh 3.2.5-13Dan Walsh 3.2.5-12Dan Walsh 3.2.5-11Dan Walsh 3.2.5-10Dan Walsh 3.2.5-9Dan Walsh 3.2.5-8Dan Walsh 3.2.5-7Dan Walsh 3.2.5-6Dan Walsh 3.2.5-5Dan Walsh 3.2.5-4Dan Walsh 3.2.5-3Dan Walsh 3.2.5-2Dan Walsh 3.2.5-1Dan Walsh 3.2.4-5Dan Walsh 3.2.4-4Dan Walsh 3.2.4-3Dan Walsh 3.2.4-1Dan Walsh 3.2.4-1Dan Walsh 3.2.3-2Dan Walsh 3.2.3-1Dan Walsh 3.2.2-1Dan Walsh 3.2.1-3Dan Walsh 3.2.1-1Dan Walsh 3.1.2-2Dan Walsh 3.1.2-1Dan Walsh 3.1.1-1Dan Walsh 3.1.0-1Dan Walsh 3.0.8-30Dan Walsh 3.0.8-28Dan Walsh 3.0.8-27Dan Walsh 3.0.8-26Dan Walsh 3.0.8-25Dan Walsh 3.0.8-24Dan Walsh 3.0.8-23Dan Walsh 3.0.8-22Dan Walsh 3.0.8-21Dan Walsh 3.0.8-20Dan Walsh 3.0.8-19Dan Walsh 3.0.8-18Dan Walsh 3.0.8-17Dan Walsh 3.0.8-16Dan Walsh 3.0.8-15Dan Walsh 3.0.8-14Dan Walsh 3.0.8-13Dan Walsh 3.0.8-12Dan Walsh 3.0.8-11Dan Walsh 3.0.8-10Dan Walsh 3.0.8-9Dan Walsh 3.0.8-8Dan Walsh 3.0.8-7Dan Walsh 3.0.8-5Dan Walsh 3.0.8-4Dan Walsh 3.0.8-3Dan Walsh 3.0.8-2Dan Walsh 3.0.8-1Dan Walsh 3.0.7-10Dan Walsh 3.0.7-9Dan Walsh 3.0.7-8Dan Walsh 3.0.7-7Dan Walsh 3.0.7-6Dan Walsh 3.0.7-5Dan Walsh 3.0.7-4Dan Walsh 3.0.7-3Dan Walsh 3.0.7-2Dan Walsh 3.0.7-1Dan Walsh 3.0.6-3Dan Walsh 3.0.6-2Dan Walsh 3.0.6-1Dan Walsh 3.0.5-11Dan Walsh 3.0.5-10Dan Walsh 3.0.5-9Dan Walsh 3.0.5-8Dan Walsh 3.0.5-7Dan Walsh 3.0.5-6Dan Walsh 3.0.5-5Dan Walsh 3.0.5-4Dan Walsh 3.0.5-3Dan Walsh 3.0.5-2Dan Walsh 3.0.5-1Dan Walsh 3.0.4-6Dan Walsh 3.0.4-5Dan Walsh 3.0.4-4Dan Walsh 3.0.4-3Dan Walsh 3.0.4-2Dan Walsh 3.0.4-1Dan Walsh 3.0.3-6Dan Walsh 3.0.3-5Dan Walsh 3.0.3-4Dan Walsh 3.0.3-3Dan Walsh 3.0.3-2Dan Walsh 3.0.3-1Dan Walsh 3.0.2-9Dan Walsh 3.0.2-8Dan Walsh 3.0.2-7Dan Walsh 3.0.2-5Dan Walsh 3.0.2-4Dan Walsh 3.0.2-3Dan Walsh 3.0.2-2Dan Walsh 3.0.1-5Dan Walsh 3.0.1-4Dan Walsh 3.0.1-3Dan Walsh 3.0.1-2Dan Walsh 3.0.1-1Dan Walsh 2.6.5-3Dan Walsh 2.6.5-2Dan Walsh 2.6.4-7Dan Walsh 2.6.4-6Dan Walsh 2.6.4-5Dan Walsh 2.6.4-2Dan Walsh 2.6.4-1Dan Walsh 2.6.3-1Dan Walsh 2.6.2-1Dan Walsh 2.6.1-4Dan Walsh 2.6.1-2Dan Walsh 2.6.1-1Dan Walsh 2.5.12-12Dan Walsh 2.5.12-11Dan Walsh 2.5.12-10Dan Walsh 2.5.12-8Dan Walsh 2.5.12-5Dan Walsh 2.5.12-4Dan Walsh 2.5.12-3Dan Walsh 2.5.12-2Dan Walsh 2.5.12-1Dan Walsh 2.5.11-8Dan Walsh 2.5.11-7Dan Walsh 2.5.11-6Dan Walsh 2.5.11-5Dan Walsh 2.5.11-4Dan Walsh 2.5.11-3Dan Walsh 2.5.11-2Dan Walsh 2.5.11-1Dan Walsh 2.5.10-2Dan Walsh 2.5.10-1Dan Walsh 2.5.9-6Dan Walsh 2.5.9-5Dan Walsh 2.5.9-4Dan Walsh 2.5.9-3Dan Walsh 2.5.9-2Dan Walsh 2.5.8-8Dan Walsh 2.5.8-7Dan Walsh 2.5.8-6Dan Walsh 2.5.8-5Dan Walsh 2.5.8-4Dan Walsh 2.5.8-3Dan Walsh 2.5.8-2Dan Walsh 2.5.8-1Dan Walsh 2.5.7-1Dan Walsh 2.5.6-1Dan Walsh 2.5.5-2Dan Walsh 2.5.5-1Dan Walsh 2.5.4-2Dan Walsh 2.5.4-1Dan Walsh 2.5.3-3Dan Walsh 2.5.3-2Dan Walsh 2.5.3-1Dan Walsh 2.5.2-6Dan Walsh 2.5.2-5Dan Walsh 2.5.2-4Dan Walsh 2.5.2-3Dan Walsh 2.5.2-2Dan Walsh 2.5.2-1Dan Walsh 2.5.1-5Dan Walsh 2.5.1-4Dan Walsh 2.5.1-2Dan Walsh 2.5.1-1Dan Walsh 2.4.6-20Dan Walsh 2.4.6-19Dan Walsh 2.4.6-18Dan Walsh 2.4.6-17Dan Walsh 2.4.6-16Dan Walsh 2.4.6-15Dan Walsh 2.4.6-14Dan Walsh 2.4.6-13Dan Walsh 2.4.6-12Dan Walsh 2.4.6-11Dan Walsh 2.4.6-10Dan Walsh 2.4.6-9Dan Walsh 2.4.6-8Dan Walsh 2.4.6-7Dan Walsh 2.4.6-6Dan Walsh 2.4.6-5Dan Walsh 2.4.6-4Dan Walsh 2.4.6-3Dan Walsh 2.4.6-1Dan Walsh 2.4.5-4Dan Walsh 2.4.5-3Dan Walsh 2.4.5-2Dan Walsh 2.4.5-1Dan Walsh 2.4.4-2Dan Walsh 2.4.4-2Dan Walsh 2.4.4-1Dan Walsh 2.4.3-13Dan Walsh 2.4.3-12Dan Walsh 2.4.3-11Dan Walsh 2.4.3-10Dan Walsh 2.4.3-9Dan Walsh 2.4.3-8Dan Walsh 2.4.3-7Dan Walsh 2.4.3-6Dan Walsh 2.4.3-5Dan Walsh 2.4.3-4Dan Walsh 2.4.3-3Dan Walsh 2.4.3-2Dan Walsh 2.4.3-1Dan Walsh 2.4.2-8Dan Walsh 2.4.2-7James Antill 2.4.2-6Dan Walsh 2.4.2-5Dan Walsh 2.4.2-4Dan Walsh 2.4.2-3Dan Walsh 2.4.2-2Dan Walsh 2.4.2-1Dan Walsh 2.4.1-5Dan Walsh 2.4.1-4Dan Walsh 2.4.1-3Dan Walsh 2.4.1-2Dan Walsh 2.4-4Dan Walsh 2.4-3Dan Walsh 2.4-2Dan Walsh 2.4-1Dan Walsh 2.3.19-4Dan Walsh 2.3.19-3Dan Walsh 2.3.19-2Dan Walsh 2.3.19-1James Antill 2.3.18-10James Antill 2.3.18-9Dan Walsh 2.3.18-8Dan Walsh 2.3.18-7Dan Walsh 2.3.18-6Dan Walsh 2.3.18-5Dan Walsh 2.3.18-4Dan Walsh 2.3.18-3Dan Walsh 2.3.18-2Dan Walsh 2.3.18-1Dan Walsh 2.3.17-2Dan Walsh 2.3.17-1Dan Walsh 2.3.16-9Dan Walsh 2.3.16-8Dan Walsh 2.3.16-7Dan Walsh 2.3.16-6Dan Walsh 2.3.16-5Dan Walsh 2.3.16-4Dan Walsh 2.3.16-2Dan Walsh 2.3.16-1Dan Walsh 2.3.15-2Dan Walsh 2.3.15-1Dan Walsh 2.3.14-8Dan Walsh 2.3.14-7Dan Walsh 2.3.14-6Dan Walsh 2.3.14-4Dan Walsh 2.3.14-3Dan Walsh 2.3.14-2Dan Walsh 2.3.14-1Dan Walsh 2.3.13-6Dan Walsh 2.3.13-5Dan Walsh 2.3.13-4Dan Walsh 2.3.13-3Dan Walsh 2.3.13-2Dan Walsh 2.3.13-1Dan Walsh 2.3.12-2Dan Walsh 2.3.12-1Dan Walsh 2.3.11-1Dan Walsh 2.3.10-7Dan Walsh 2.3.10-6Dan Walsh 2.3.10-3Dan Walsh 2.3.10-1Dan Walsh 2.3.9-6Dan Walsh 2.3.9-5Dan Walsh 2.3.9-4Dan Walsh 2.3.9-3Dan Walsh 2.3.9-2Dan Walsh 2.3.9-1Dan Walsh 2.3.8-2Dan Walsh 2.3.7-1Dan Walsh 2.3.6-4Dan Walsh 2.3.6-3Dan Walsh 2.3.6-2Dan Walsh 2.3.6-1Dan Walsh 2.3.5-1Dan Walsh 2.3.4-1Dan Walsh 2.3.3-20Dan Walsh 2.3.3-19Dan Walsh 2.3.3-18Dan Walsh 2.3.3-17Dan Walsh 2.3.3-16Dan Walsh 2.3.3-15Dan Walsh 2.3.3-14Dan Walsh 2.3.3-13Dan Walsh 2.3.3-12Dan Walsh 2.3.3-11Dan Walsh 2.3.3-10Dan Walsh 2.3.3-9Dan Walsh 2.3.3-8Dan Walsh 2.3.3-7Dan Walsh 2.3.3-6Dan Walsh 2.3.3-5Dan Walsh 2.3.3-4Dan Walsh 2.3.3-3Dan Walsh 2.3.3-2Dan Walsh 2.3.3-1Dan Walsh 2.3.2-4Dan Walsh 2.3.2-3Dan Walsh 2.3.2-2Dan Walsh 2.3.2-1Dan Walsh 2.3.1-1Dan Walsh 2.2.49-1Dan Walsh 2.2.48-1Dan Walsh 2.2.47-5Dan Walsh 2.2.47-4Dan Walsh 2.2.47-3Dan Walsh 2.2.47-1Dan Walsh 2.2.46-2Dan Walsh 2.2.46-1Dan Walsh 2.2.45-3Dan Walsh 2.2.45-2Dan Walsh 2.2.45-1Dan Walsh 2.2.44-1Dan Walsh 2.2.43-4Dan Walsh 2.2.43-3Dan Walsh 2.2.43-2Dan Walsh 2.2.43-1Dan Walsh 2.2.42-4Dan Walsh 2.2.42-3Dan Walsh 2.2.42-2Dan Walsh 2.2.42-1Dan Walsh 2.2.41-1Dan Walsh 2.2.40-2Dan Walsh 2.2.40-1Dan Walsh 2.2.39-2Dan Walsh 2.2.39-1Dan Walsh 2.2.38-6Dan Walsh 2.2.38-5Dan Walsh 2.2.38-4Dan Walsh 2.2.38-3Dan Walsh 2.2.38-2Dan Walsh 2.2.38-1Dan Walsh 2.2.37-1Dan Walsh 2.2.36-2Dan Walsh 2.2.36-1James Antill 2.2.35-2Dan Walsh 2.2.35-1Dan Walsh 2.2.34-3Dan Walsh 2.2.34-2Dan Walsh 2.2.34-1Dan Walsh 2.2.33-1Dan Walsh 2.2.32-2Dan Walsh 2.2.32-1Dan Walsh 2.2.31-1Dan Walsh 2.2.30-2Dan Walsh 2.2.30-1Dan Walsh 2.2.29-6Russell Coker 2.2.29-5Dan Walsh 2.2.29-4Dan Walsh 2.2.29-3Dan Walsh 2.2.29-2Dan Walsh 2.2.29-1Dan Walsh 2.2.28-3Dan Walsh 2.2.28-2Dan Walsh 2.2.28-1Dan Walsh 2.2.27-1Dan Walsh 2.2.25-3Dan Walsh 2.2.25-2Dan Walsh 2.2.24-1Dan Walsh 2.2.23-19Dan Walsh 2.2.23-18Dan Walsh 2.2.23-17Karsten Hopp 2.2.23-16Dan Walsh 2.2.23-15Dan Walsh 2.2.23-14Dan Walsh 2.2.23-13Dan Walsh 2.2.23-12Jeremy Katz - 2.2.23-11Jeremy Katz - 2.2.23-10Dan Walsh 2.2.23-9Dan Walsh 2.2.23-8Dan Walsh 2.2.23-7Dan Walsh 2.2.23-5Dan Walsh 2.2.23-4Dan Walsh 2.2.23-3Dan Walsh 2.2.23-2Dan Walsh 2.2.23-1Dan Walsh 2.2.22-2Dan Walsh 2.2.22-1Dan Walsh 2.2.21-9Dan Walsh 2.2.21-8Dan Walsh 2.2.21-7Dan Walsh 2.2.21-6Dan Walsh 2.2.21-5Dan Walsh 2.2.21-4Dan Walsh 2.2.21-3Dan Walsh 2.2.21-2Dan Walsh 2.2.21-1Dan Walsh 2.2.20-1Dan Walsh 2.2.19-2Dan Walsh 2.2.19-1Dan Walsh 2.2.18-2Dan Walsh 2.2.18-1Dan Walsh 2.2.17-2Dan Walsh 2.2.16-1Dan Walsh 2.2.15-4Dan Walsh 2.2.15-3Dan Walsh 2.2.15-1Dan Walsh 2.2.14-2Dan Walsh 2.2.14-1Dan Walsh 2.2.13-1Dan Walsh 2.2.12-1Dan Walsh 2.2.11-2Dan Walsh 2.2.11-1Dan Walsh 2.2.10-1Dan Walsh 2.2.9-2Dan Walsh 2.2.9-1Dan Walsh 2.2.8-2Dan Walsh 2.2.7-1Dan Walsh 2.2.6-3Dan Walsh 2.2.6-2Dan Walsh 2.2.6-1Dan Walsh 2.2.5-1Dan Walsh 2.2.4-1Dan Walsh 2.2.3-1Dan Walsh 2.2.2-1Dan Walsh 2.2.1-1Dan Walsh 2.1.13-1Dan Walsh 2.1.12-3Dan Walsh 2.1.11-1Dan Walsh 2.1.10-1Jeremy Katz - 2.1.9-2Dan Walsh 2.1.9-1Dan Walsh 2.1.8-3Dan Walsh 2.1.8-2Dan Walsh 2.1.8-1Dan Walsh 2.1.7-4Dan Walsh 2.1.7-3Dan Walsh 2.1.7-2Dan Walsh 2.1.7-1Dan Walsh 2.1.6-24Dan Walsh 2.1.6-23Dan Walsh 2.1.6-22Dan Walsh 2.1.6-21Dan Walsh 2.1.6-20Dan Walsh 2.1.6-18Dan Walsh 2.1.6-17Dan Walsh 2.1.6-16Dan Walsh 2.1.6-15Dan Walsh 2.1.6-14Dan Walsh 2.1.6-13Dan Walsh 2.1.6-11Dan Walsh 2.1.6-10Dan Walsh 2.1.6-9Dan Walsh 2.1.6-8Dan Walsh 2.1.6-5Dan Walsh 2.1.6-4Dan Walsh 2.1.6-3Dan Walsh 2.1.6-2Dan Walsh 2.1.6-1Dan Walsh 2.1.4-2Dan Walsh 2.1.4-1Dan Walsh 2.1.3-1Jeremy Katz - 2.1.2-3Dan Walsh 2.1.2-2Dan Walsh 2.1.2-1Dan Walsh 2.1.1-3Dan Walsh 2.1.1-2Dan Walsh 2.1.1-1Dan Walsh 2.1.0-3Dan Walsh 2.1.0-2.Dan Walsh 2.1.0-1.Dan Walsh 2.0.11-2.Dan Walsh 2.0.11-1.Dan Walsh 2.0.9-1.Dan Walsh 2.0.8-1.Dan Walsh 2.0.7-3Dan Walsh 2.0.7-2Dan Walsh 2.0.6-2Dan Walsh 2.0.5-4Dan Walsh 2.0.5-1Dan Walsh 2.0.4-1Dan Walsh 2.0.2-2Dan Walsh 2.0.2-1Dan Walsh 2.0.1-2Dan Walsh 2.0.1-1- Allow nova_t domain to use pam Resolves: rhbz:#1645270 - sysstat: grant sysstat_t the search_dir_perms set Resolves: rhbz#1645271- Remove disabling ganesha module in pre install phase of installation new selinux-policy package where ganesha is again standalone module Resolves: rhbz#1638257- Allow staff_t userdomain and confined_admindomain attribute to allow use generic ptys because of new sudo feature 'io logging' Resolves: rhbz#1638427- Run ganesha as ganesha_t domain again, revert changes where ganesha is running as nfsd_t Resolves: rhbz#1638257- Fix missing patch in spec file Resolves: rhbz#1635704- Allow cinder_volume_t domain to dbus chat with systemd_logind_t domain Resolves: rhbz#1635704- Allow neutron domain to read/write /var/run/utmp Resolves: rhbz#1630318- Allow tomcat_domain to read /dev/random Resolves: rhbz#1631666 - Allow neutron_t domain to use pam Resolves: rhbz#1630318- Add interface apache_read_tmp_dirs() - Allow dirsrvadmin_script_t domain to list httpd_tmp_t dirs Resolves: rhbz#1622602- Allow tomcat servers to manage usr_t files Resolves: rhbz#1625678 - Dontaudit tomcat serves to append to /dev/random device Resolves: rhbz#1625678 - Allow sys_nice capability to mysqld_t domain - Allow dirsrvadmin_script_t domain to read httpd tmp files Resolves: rhbz#1622602 - Allow syslogd_t domain to manage cert_t files Resolves: rhbz#1615995- Allow sbd_t domain to getattr of all char files in /dev and read sysfs_t files and dirs Resolves: rhbz#1627114 - Expand virt_read_lib_files() interface to allow list dirs with label virt_var_lib_t Resolves: rhbz#1567753- Allow tomcat Tomcat to delete a temporary file used when compiling class files for JSPs. Resolves: rhbz#1625678 - Allow chronyd_t domain to read virt_var_lib_t files - Allow virtual machines to use dri devices. This allows use openCL GPU calculations. BZ(1337333) Resolves: rhbz#1625613 - Allow tomcat services create link file in /tmp Resolves: rhbz#1624289 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322- Make working SELinux sandbox with Wayland. Resolves: rhbz#1624308 - Allow svirt_t domain to mmap svirt_image_t block files Resolves: rhbz#1624224 - Add caps dac_read_search and dav_override to pesign_t domain - Allow iscsid_t domain to mmap userio chr files Resolves: rhbz#1623589 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322 - Add execute_no_trans permission to mmap_exec_file_perms pattern - Allow sudodomain to search caller domain proc info - Allow xdm_t domain to mmap and read cert_t files - Replace optional policy blocks to make dbus interfaces effective Resolves: rhbz#1624414 - Add interface dev_map_userio_dev()- Allow readhead_t domain to mmap own pid files Resolves: rhbz#1614169- Allow ovs-vswitchd labeled as openvswitch_t domain communicate with qemu-kvm via UNIX stream socket - Allow httpd_t domain to mmap tmp files Resolves: rhbz#1608355 - Update dirsrv_read_share() interface to allow caller domain to mmap dirsrv_share_t files - Update dirsrvadmin_script_t policy to allow read httpd_tmp_t symlinks - Label /dev/tpmrm[0-9]* as tpm_device_t - Allow semanage_t domain mmap usr_t files Resolves: rhbz#1622607 - Update dev_filetrans_all_named_dev() to allow create event22-30 character files with label event_device_t- Allow nagios_script_t domain to mmap nagios_log_t files Resolves: rhbz#1620013 - Allow nagios_script_t domain to mmap nagios_spool_t files Resolves: rhbz#1620013 - Update userdom_security_admin() and userdom_security_admin_template() to allow use auditctl Resolves: rhbz#1622197 - Update selinux_validate_context() interface to allow caller domain to mmap security_t files Resolves: rhbz#1622061- Allow virtd_t domain to create netlink_socket - Allow rpm_t domain to write to audit - Allow rpm domain to mmap rpm_var_lib_t files Resolves: rhbz#1619785 - Allow nagios_script_t domain to mmap nagios_etc_t files Resolves: rhbz#1620013 - Update nscd_socket_use() to allow caller domain to stream connect to nscd_t Resolves: rhbz#1460715 - Allow secadm_t domain to mmap audit config and log files - Allow insmod_t domain to read iptables pid files - Allow systemd to mounton /etc Resolves: rhbz#1619785- Allow kdumpctl_t domain to getattr fixed disk device in mls Resolves: rhbz#1615342 - Allow initrc_domain to mmap all binaries labeled as systemprocess_entry Resolves: rhbz#1615342- Allow virtlogd to execute itself Resolves: rhbz#1598392- Allow kdumpctl_t domain to manage kdumpctl_tmp_t fifo files Resolves: rhbz#1615342 - Allow kdumpctl to write to files on all levels Resolves: rhbz#1615342 - Fix typo in radius policy Resolves: rhbz#1619197 - Allow httpd_t domain to mmap httpd_config_t files Resolves: rhbz#1615894 - Add interface dbus_acquire_svc_system_dbusd() - Allow sanlock_t domain to connectto to unix_stream_socket Resolves: rhbz#1614965 - Update nfsd_t policy because of ganesha features Resolves: rhbz#1511489 - Allow conman to getattr devpts_t Resolves: rhbz#1377915 - Allow tomcat_domain to connect to smtp ports Resolves: rhbz#1253502 - Allow tomcat_t domain to mmap tomcat_var_lib_t files Resolves: rhbz#1618519 - Allow slapd_t domain to mmap slapd_var_run_t files Resolves: rhbz#1615319 - Allow nagios_t domain to mmap nagios_log_t files Resolves: rhbz#1618675 - Allow nagios to exec itself and mmap nagios spool files BZ(1559683) - Allow nagios to mmap nagios config files BZ(1559683) - Allow kpropd_t domain to mmap krb5kdc_principal_t files Resolves: rhbz#1619252 - Update syslogd policy to make working elasticsearch - Label tcp and udp ports 9200 as wap_wsp_port - Allow few domains to rw inherited kdumpctl tmp pipes Resolves: rhbz#1615342- Allow systemd_dbusd_t domain read/write to nvme devices Resolves: rhbz#1614236 - Allow mysqld_safe_t do execute itself - Allow smbd_t domain to chat via dbus with avahi daemon Resolves: rhbz#1600157 - cupsd_t domain will create /etc/cupsd/ppd as cupsd_etc_rw_t Resolves: rhbz#1452595 - Allow amanda_t domain to getattr on tmpfs filesystem BZ(1527645) Resolves: rhbz#1452444 - Update screen_role_template to allow caller domain to have screen_exec_t as entrypoint do new domain Resolves: rhbz#1384769 - Add alias httpd__script_t to _script_t to make sepolicy generate working Resolves: rhbz#1271324 - Allow kprop_t domain to read network state Resolves: rhbz#1600705 - Allow sysadm_t domain to accept socket Resolves: rhbz#1557299 - Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow kprop_t domain to read network state Resolves: rhbz#1600705- Allow kpropd domain to exec itself Resolves: rhbz#1600705 - Allow ipmievd_t to mmap kernel modules BZ(1552535) - Allow hsqldb_t domain to mmap own temp files Resolves: rhbz#1612143 - Allow hsqldb_t domain to read cgroup files Resolves: rhbz#1612143 - Allow rngd_t domain to read generic certs Resolves: rhbz#1612456 - Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow virtlogd_t domain to chat via dbus with systemd_logind Resolves: rhbz#1593740- Allow sblim_sfcbd_t domain to mmap own tmpfs files Resolves: rhbz#1609384 - Update logging_manage_all_logs() interface to allow caller domain map all logfiles Resolves: rhbz#1592028- Dontaudit oracleasm_t domain to request sys_admin capability - Allow iscsid_t domain to load kernel module Resolves: rhbz#1589295 - Update rhcs contexts to reflects the latest fenced changes - Allow httpd_t domain to rw user_tmp_t files Resolves: rhbz#1608355 - /usr/libexec/udisks2/udisksd should be labeled as devicekit_disk_exec_t Resolves: rhbz#1521063 - Allow tangd_t dac_read_search Resolves: rhbz#1607810 - Allow glusterd_t domain to mmap user_tmp_t files - Allow mongodb_t domain to mmap own var_lib_t files Resolves: rhbz#1607729 - Allow iscsid_t domain to mmap sysfs_t files Resolves: rhbz#1602508 - Allow tomcat_domain to search cgroup dirs Resolves: rhbz#1600188 - Allow httpd_t domain to mmap own cache files Resolves: rhbz#1603505 - Allow cupsd_t domain to mmap cupsd_etc_t files Resolves: rhbz#1599694 - Allow kadmind_t domain to mmap krb5kdc_principal_t Resolves: rhbz#1601004 - Allow virtlogd_t domain to read virt_etc_t link files Resolves: rhbz#1598593 - Allow dirsrv_t domain to read crack db Resolves: rhbz#1599726 - Dontaudit pegasus_t to require sys_admin capability Resolves: rhbz#1374570 - Allow mysqld_t domain to exec mysqld_exec_t binary files - Allow abrt_t odmain to read rhsmcertd lib files Resolves: rhbz#1601389 - Allow winbind_t domain to request kernel module loads Resolves: rhbz#1599236 - Allow gpsd_t domain to getsession and mmap own tmpfs files Resolves: rhbz#1598388 - Allow smbd_t send to nmbd_t via dgram sockets BZ(1563791) Resolves: rhbz#1600157 - Allow tomcat_domain to read cgroup_t files Resolves: rhbz#1601151 - Allow varnishlog_t domain to mmap varnishd_var_lib_t files Resolves: rhbz#1600704 - Allow dovecot_auth_t domain to manage also dovecot_var_run_t fifo files. BZ(1320415) Resolves: rhbz#1600692 - Fix ntp SELinux module - Allow innd_t domain to mmap news_spool_t files Resolves: rhbz#1600591 - Allow haproxy daemon to reexec itself. BZ(1447800) Resolves: rhbz#1600578 - Label HOME_DIR/mozilla.pdf file as mozilla_home_t instead of user_home_t Resolves: rhbz#1559859 - Allow pkcs_slotd_t domain to mmap own tmpfs files Resolves: rhbz#1600434 - Allow fenced_t domain to reboot Resolves: rhbz#1293384 - Allow bluetooth_t domain listen on bluetooth sockets BZ(1549247) Resolves: rhbz#1557299 - Allow lircd to use nsswitch. BZ(1401375) - Allow targetd_t domain mmap lvm config files Resolves: rhbz#1546671 - Allow amanda_t domain to read network system state Resolves: rhbz#1452444 - Allow abrt_t domain to read rhsmcertd logs Resolves: rhbz#1492059 - Allow application_domain_type also mmap inherited user temp files BZ(1552765) Resolves: rhbz#1608421 - Allow ipsec_t domain to read l2tpd pid files Resolves: rhbz#1607994 - Allow systemd_tmpfiles_t do mmap system db files - Improve domain_transition_pattern to allow mmap entrypoint bin file. Resolves: rhbz#1460322 - Allow nsswitch_domain to mmap passwd_file_t files BZ(1518655) Resolves: rhbz#1600528 - Dontaudit syslogd to watching top llevel dirs when imfile module is enabled Resolves: rhbz#1601928 - Allow ipsec_t can exec ipsec_exec_t Resolves: rhbz#1600684 - Allow netutils_t domain to mmap usmmon device Resolves: rhbz#1600586 - Allow netlabel_mgmt_t domain to read sssd public files, stream connect to sssd_t BZ(1483655) - Allow userdomain sudo domains to use generic ptys Resolves: rhbz#1564470 - Allow traceroute to create icmp packets Resolves: rhbz#1548350 - Allow systemd domain to mmap lvm config files BZ(1594584) - Add new interface lvm_map_config - refpolicy: Update for kernel sctp support Resolves: rhbz#1597111 Add additional entries to support the kernel SCTP implementation introduced in kernel 4.16- Update oddjob_domtrans_mkhomedir() interface to allow caller domain also mmap oddjob_mkhomedir_exec_t files Resolves: rhbz#1596306 - Update rhcs_rw_cluster_tmpfs() interface to allow caller domain to mmap cluster_tmpfs_t files Resolves: rhbz#1589257 - Allow radiusd_t domain to read network sysctls Resolves: rhbz#1516233 - Allow chronyc_t domain to use nscd shm Resolves: rhbz#1596563 - Label /var/lib/tomcats dir as tomcat_var_lib_t Resolves: rhbz#1596367 - Allow lsmd_t domain to mmap lsmd_plugin_exec_t files Resolves: rhbz#bea0c8174 - Label /usr/sbin/rhn_check-[0-9]+.[0-9]+ as rpm_exec_t Resolves: rhbz#1596509 - Update seutil_exec_loadpolicy() interface to allow caller domain to mmap load_policy_exec_t files Resolves: rhbz#1596072 - Allow xdm_t to read systemd hwdb Resolves: rhbz#1596720 - Allow dhcpc_t domain to mmap files labeled as ping_exec_t Resolves: rhbz#1596065- Allow tangd_t domain to create tcp sockets Resolves: rhbz#1595775 - Update postfix policy to allow postfix_master_t domain to mmap all postfix* binaries Resolves: rhbz#1595328 - Allow amanda_t domain to have setgid capability Resolves: rhbz#1452444 - Update usermanage_domtrans_useradd() to allow caller domain to mmap useradd_exec_t files Resolves: rhbz#1595667- Allow abrt_watch_log_t domain to mmap binaries with label abrt_dump_oops_exec_t Resolves: rhbz#1591191 - Update cups_filetrans_named_content() to allow caller domain create ppd directory with cupsd_etc_rw_t label Resolves: rhbz#1452595 - Allow abrt_t domain to write to rhsmcertd pid files Resolves: rhbz#1492059 - Allow pegasus_t domain to eexec lvm binaries and allow read/write access to lvm control Resolves: rhbz#1463470 - Add vhostmd_t domain to read/write to svirt images Resolves: rhbz#1465276 - Dontaudit action when abrt-hook-ccpp is writing to nscd sockets Resolves: rhbz#1460715 - Update openvswitch policy Resolves: rhbz#1594729 - Update kdump_manage_kdumpctl_tmp_files() interface to allow caller domain also mmap kdumpctl_tmp_t files Resolves: rhbz#1583084 - Allow sssd_t and slpad_t domains to mmap generic certs Resolves: rhbz#1592016 Resolves: rhbz#1592019 - Allow oddjob_t domain to mmap binary files as oddjob_mkhomedir_exec_t files Resolves: rhbz#1592022 - Update dbus_system_domain() interface to allow system_dbusd_t domain to mmap binary file from second parameter Resolves: rhbz#1583080 - Allow chronyc_t domain use inherited user ttys Resolves: rhbz#1593267 - Allow stapserver_t domain to mmap own tmp files Resolves: rhbz#1593122 - Allow sssd_t domain to mmap files labeled as sssd_selinux_manager_exec_t Resolves: rhbz#1592026 - Update policy for ypserv_t domain Resolves: rhbz#1592032 - Allow abrt_dump_oops_t domain to mmap all non security files Resolves: rhbz#1593728 - Allow svirt_t domain mmap svirt_image_t files Resolves: rhbz#1592688 - Allow virtlogd_t domain to write inhibit systemd pipes. Resolves: rhbz#1593740 - Allow sysadm_t and staff_t domains to use sudo io logging Resolves: rhbz#1564470 - Allow sysadm_t domain create sctp sockets Resolves: rhbz#1571591 - Update mount_domtrans() interface to allow caller domain mmap mount_exec_t Resolves: rhbz#1592025 - Allow dhcpc_t to mmap all binaries with label hostname_exec_t, ifconfig_exec_t and netutils_exec_t Resolves: rhbz#1594661- Fix typo in logwatch interface file - Allow spamd_t to manage logwatch_cache_t files/dirs - Allow dnsmasw_t domain to create own tmp files and manage mnt files - Allow fail2ban_client_t to inherit rlimit information from parent process Resolves: rhbz#1513100 - Allow nscd_t to read kernel sysctls Resolves: rhbz#1512852 - Label /var/log/conman.d as conman_log_t Resolves: rhbz#1538363 - Add dac_override capability to tor_t domain Resolves: rhbz#1540711 - Allow certmonger_t to readwrite to user_tmp_t dirs Resolves: rhbz#1543382 - Allow abrt_upload_watch_t domain to read general certs Resolves: rhbz#1545098 - Update postfix_domtrans_master() interface to allow caller domain also mmap postfix_master_exec_t binary Resolves: rhbz#1583087 - Allow postfix_domain to mmap postfix_qmgr_exec_t binaries Resolves: rhbz#1583088 - Allow postfix_domain to mmap postfix_pickup_exec_t binaries Resolves: rhbz#1583091 - Allow chornyd_t read phc2sys_t shared memory Resolves: rhbz#1578883 - Allow virt_qemu_ga_t read utmp Resolves: rhbz#1571202 - Add several allow rules for pesign policy: Resolves: rhbz#1468744 - Allow pesign domain to read /dev/random - Allow pesign domain to create netlink_kobject_uevent_t sockets - Allow pesign domain create own tmp files - Add setgid and setuid capabilities to mysqlfd_safe_t domain Resolves: rhbz#1474440 - Add tomcat_can_network_connect_db boolean Resolves: rhbz#1477948 - Update virt_use_sanlock() boolean to read sanlock state Resolves: rhbz#1448799 - Add sanlock_read_state() interface - Allow postfix_cleanup_t domain to stream connect to all milter sockets BZ(1436026) Resolves: rhbz#1563423 - Update abrt_domtrans and abrt_exec() interfaces to allow caller domain to mmap binary file Resolves:rhbz#1583080 - Update nscd_domtrans and nscd_exec interfaces to allow caller domain also mmap nscd binaries Resolves: rhbz#1583086 - Update snapperd_domtrans() interface to allow caller domain to mmap snapperd_exec_t file Resolves: rhbz#1583802 - Allow zoneminder_t to getattr of fs_t Resolves: rhbz#1585328 - Fix denials during ipa-server-install process on F27+ Resolves: rhbz#1586029 - Allow ipa_dnskey_t to exec ipa_dnskey_exec_t files Resolves: rhbz#1586033 - Allow rhsmcertd_t domain to send signull to postgresql_t domain Resolves: rhbz#1588119 - Allow policykit_t domain to dbus chat with dhcpc_t Resolves: rhbz#1364513 - Adding new boolean keepalived_connect_any() Resolves: rhbz#1443473 - Allow amanda to create own amanda_tmpfs_t files Resolves: rhbz#1452444 - Add amanda_tmpfs_t label. BZ(1243752) - Allow gdomap_t domain to connect to qdomap_port_t Resolves: rhbz#1551944 - Fix typos in sge - Fix typo in openvswitch policy - /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow sshd_keygen_t to execute plymouthd Resolves: rhbz#1583531 - Update seutil_domtrans_setfiles() interface to allow caller domain to do mmap on setfiles_exec_t binary Resolves: rhbz#1583090 - Allow systemd_networkd_t create and relabel tun sockets Resolves: rhbz#1583830 - Allow map audisp_exec_t files fordomains executing this binary Resolves: rhbz#1586042 - Add new interface postgresql_signull() - Add fs_read_xenfs_files() interface.- /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow dac override capability to mandb_t domain BZ(1529399) Resolves: rhbz#1423361 - Allow inetd_child process to chat via dbus with abrt Resolves: rhbz#1428805 - Allow zabbix_agent_t domain to connect to redis_port_t Resolves: rhbz#1418860 - Allow rhsmcertd_t domain to read xenfs_t files Resolves: rhbz#1405870 - Allow zabbix_agent_t to run zabbix scripts Resolves: rhbz#1380697 - Allow rabbitmq_t domain to create own tmp files/dirs Resolves: rhbz#1546897 - Allow policykit_t mmap policykit_auth_exec_t files Resolves: rhbz#1583082 - Allow ipmievd_t domain to read general certs Resolves: rhbz#1514591 - Add sys_ptrace capability to pcp_pmie_t domain - Allow squid domain to exec ldconfig Resolves: rhbz#1532017 - Make working gpg agent in gpg_agent_t domain Resolves: rhbz#1535109 - Update gpg SELinux policy module - Allow kexec to read kernel module files in /usr/lib/modules. Resolves: rhbz#1536690 - Allow mailman_domain to read system network state Resolves: rhbz#1413510 - Allow mailman_mail_t domain to search for apache configs Resolves: rhbz#1413510 - Allow openvswitch_t domain to read neutron state and read/write fixed disk devices Resolves: rhbz#1499208 - Allow antivirus_domain to read all domain system state Resolves: rhbz#1560986 - Allow targetd_t domain to red gconf_home_t files/dirs Resolves: rhbz#1546671 - Allow freeipmi domain to map sysfs_t files Resolves: rhbz#1575918 - Label /usr/libexec/bluetooth/obexd as obexd_exec_t Resolves: rhbz#1351750 - Update rhcs SELinux module Resolves: rhbz#1589257 - Allow iscsid_t domain mmap kernel modules Resolves: rhbz#1589295 - Allow iscsid_t domain mmap own tmp files Resolves: rhbz#1589295 - Update iscsid_domtrans() interface to allow mmap iscsid_exec_t binary Resolves: rhbz#1589295 - Update nscd_socket_use interface to allow caller domain also mmap nscd_var_run_t files. Resolves: rhbz#1589271 - Allow nscd_t domain to mmap system_db_t files Resolves: rhbz#1589271 - Add interface nagios_unconfined_signull() - Allow lircd_t domain read sssd public files Add setgid capability to lircd_t domain Resolves: rhbz#1550700 - Add missing requires - Allow tomcat domain sends email Resolves: rhbz#1585184 - Allow memcached_t domain nnp_transition becuase of systemd security features BZ(1514867) Resolves: rhbz#1585714 - Allow kdump_t domain to map /boot files Resolves: rhbz#1588884 - Fix typo in netutils policy - Allow confined users get AFS tokens Resolves: rhbz#1417671 - Allow sysadm_t domain to chat via dbus Resolves: rhbz#1582146 - Associate sysctl_kernel_t type with filesystem attribute - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Add interface dev_map_sysfs - Allow xdm_t domain to execute xdm_var_lib_t files Resolves: rhbz#1589139 - Allow syslogd_t domain to send signull to nagios_unconfined_plugin_t Resolves: rhbz#1569344 - Label /dev/vhost-vsock char device as vhost_device_t - Add files_map_boot_files() interface Resolves: rhbz#1588884 - Update traceroute_t domain to allow create dccp sockets Resolves: rhbz#1548350- Update ctdb domain to support gNFS setup Resolves: rhbz#1576818 - Allow authconfig_t dbus chat with policykit Resolves: rhbz#1551241 - Allow lircd_t domain to read passwd_file_t Resolves: rhbz:#1550700 - Allow lircd_t domain to read system state Resolves: rhbz#1550700 - Allow smbcontrol_t to mmap samba_var_t files and allow winbind create sockets BZ(1559795) Resolves: rhbz#1574521 - Allow tangd_t domain read certs Resolves: rhbz#1509055 - Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow ctdb_t domain modify ctdb_exec_t files Resolves: rhbz#1572584 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Allow SELinux users (except guest and xguest) to using bluetooth sockets Resolves: rhbz#1557299 - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Fix broken sysadm SELinux module Resolves: rhbz#1557311 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Update ssh_domtrans_keygen interface to allow mmap ssh_keygen_exec_t binary file Resolves: rhbz#1583089 - Allow systemd_networkd_t to read/write tun tap devices Resolves: rhbz#1583830 - Add bridge_socket, dccp_socket, ib_socket and mpls_socket to socket_class_set Resolves: rhbz#1583771 - Allow audisp_t domain to mmap audisp_exec_t binary Resolves: rhbz#1583551 - Fix duplicates in sysadm.te file Resolves: rhbz#1307183 - Allow sysadm_u use xdm Resolves: rhbz#1307183 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix duplicates in sysadm.te file Resolves: rhbz#1307183- Allow sysadm_u use xdm Resolves: rhbz#1307183- Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Improve procmail_domtrans() to allow mmaping procmail_exec_t - Allow hypervvssd_t domain to read fixed disk devices Resolves: rhbz#1581225 - Improve modutils_domtrans_insmod() interface to mmap insmod_exec_t binaries Resolves: rhbz#1581551 - Improve iptables_domtrans() interface to allow mmaping iptables_exec_t binary Resolves: rhbz#1581551 - Improve auth_domtrans_login_programinterface to allow also mmap login_exec_t binaries Resolves: rhbz#1581551 - Improve auth_domtrans_chk_passwd() interface to allow also mmaping chkpwd_exec_t binaries. Resolves: rhbz#1581551 - Allow mmap dhcpc_exec_t binaries in sysnet_domtrans_dhcpc interface- Add dbus_stream_connect_system_dbusd() interface. - Allow pegasus_t domain to mount tracefs_t filesystem Resolves:rhbz#1374570 - Allow psad_t domain to read all domains state Resolves: rhbz#1558439 - Add net_raw capability to named_t domain BZ(1545586) - Allow tomcat_t domain to connect to mongod_t tcp port Resolves:rhbz#1539748 - Allow dovecot and postfix to connect to systemd stream sockets Resolves: rhbz#1368642 - Label /usr/libexec/bluetooth/obexd as bluetoothd_exec_t to run process as bluetooth_t Resolves:rhbz#1351750 - Rename tang policy to tangd - Add interface systemd_rfkill_domtrans() - Allow users staff and sysadm to run wireshark on own domain Resolves:rhbz#1546362 - Allow systemd-bootchart to create own tmpfs files Resolves:rhbz#1510412- Rename tang policy to tangd - Allow virtd_t domain to relabel virt_var_lib_t files Resolves: rhbz#1558121 - Allow logrotate_t domain to stop services via systemd Resolves: rhbz#1527522 - Add tang policy Resolves: rhbz#1509055 - Allow mozilla_plugin_t to create mozilla.pdf file in user homedir with label mozilla_home_t Resolves: rhbz#1559859 - Improve snapperd SELinux policy Resolves: rhbz#1365555 - Allow snapperd_t daemon to create unlabeled dirs. Resolves: rhbz#1365555 - We have inconsistency in cgi templates with upstream, we use _content_t, but refpolicy use httpd__content_t. Created aliasses to make it consistence Resolves: rhbz#1271324 - Allow Openvswitch adding netdev bridge ovs 2.7.2.10 FDP Resolves: rhbz#1503835 - Add new Boolean tomcat_use_execmem Resolves: rhbz#1565226 - Allow domain transition from logrotate_t to chronyc_t Resolves: rhbz#1568281 - Allow nfsd_t domain to read/write sysctl fs files Resolves: rhbz#1516593 - Allow conman to read system state Resolves: rhbz#1377915 - Allow lircd_t to exec shell and add capabilities dac_read_search and dac_override Resolves: rhbz#1550700 - Allow usbmuxd to access /run/udev/data/+usb:*. Resolves: rhbz#1521054 - Allow abrt_t domain to manage kdump crash files Resolves: rhbz#1491585 - Allow systemd to use virtio console Resolves: rhbz#1558121 - Allow transition from sysadm role into mdadm_t domain. Resolves: rhbz#1551568 - Label /dev/op_panel and /dev/opal-prd as opal_device_t Resolves: rhbz#1537618 - Label /run/ebtables.lock as iptables_var_run_t Resolves: rhbz#1511437 - Allow udev_t domain to manage udev_rules_t char files. Resolves: rhbz#1545094 - Allow nsswitch_domain to read virt_var_lib_t files, because of libvirt NSS plugin. Resolves: rhbz#1567753 - Fix filesystem inteface file, we don't have nsfs_fs_t type, just nsfs_t Resolves: rhbz#1547700 - Allow iptables_t domain to create dirs in etc_t with system_conf_t labels- Add new boolean redis_enable_notify() Resolves: rhbz#1421326 - Label /var/log/shibboleth-www(/.*) as httpd_sys_rw_content_t Resolves: rhbz#1549514 - Add new label for vmtools scripts and label it as vmtools_unconfined_t stored in /etc/vmware-tools/ Resolves: rbhz#1463593 - Remove labeling for /etc/vmware-tools to bin_t it should be vmtools_unconfined_exec_t Resolves: rbhz#1463593- Backport several changes for snapperdfrom Fedora Rawhide Resolves: rhbz#1556798 - Allow snapperd_t to set priority for kernel processes Resolves: rhbz#1556798 - Make ganesha nfs server. Resolves: rhbz#1511489 - Allow vxfs filesystem to use SELinux labels Resolves: rhbz#1482880 - Add map permission to selinux-policy Resolves: rhbz#1460322- Label /usr/libexec/dbus-1/dbus-daemon-launch-helper as dbusd_exec_t to have systemd dbus services running in the correct domain instead of unconfined_service_t if unconfined.pp module is enabled. Resolves: rhbz#1546721- Allow openvswitch_t stream connect svirt_t Resolves: rhbz#1540702- Allow openvswitch domain to manage svirt_tmp_t sock files Resolves: rhbz#1540702 - Fix broken systemd_tmpfiles_run() interface- Allow dirsrv_t domain to create tmp link files Resolves: rhbz#1536011 - Label /usr/sbin/ldap-agent as dirsrv_snmp_exec_t Resolves: rhbz#1428568 - Allow ipsec_mgmt_t execute ifconfig_exec_t binaries - Allow ipsec_mgmt_t nnp domain transition to ifconfig_t Resolves: rhbz#1539416- Allow svirt_domain to create socket files in /tmp with label svirt_tmp_t Resolves: rhbz#1540702 - Allow keepalived_t domain getattr proc filesystem Resolves: rhbz#1477542 - Rename svirt_sandbox_file_t to container_file_t and svirt_lxc_net_t to container_t Resolves: rhbz#1538544 - Allow ipsec_t nnp transistions to domains ipsec_mgmt_t and ifconfig_t Resolves: rhbz:#1539416 - Allow systemd_logind_t domain to bind on dhcpd_port_t,pki_ca_port_t,flash_port_t Resolves: rhbz#1479350- Allow openvswitch_t domain to read cpuid, write to sysfs files and creating openvswitch_tmp_t sockets Resolves: rhbz#1535196 - Add new interface ppp_filetrans_named_content() Resolves: rhbz#1530601 - Allow keepalived_t read sysctl_net_t files Resolves: rhbz#1477542 - Allow puppetmaster_t domtran to puppetagent_t Resolves: rhbz#1376893 - Allow kdump_t domain to read kernel ring buffer Resolves: rhbz#1540004 - Allow ipsec_t domain to exec ifconfig_exec_t binaries. Resolves: rhbz#1539416 - Allow unconfined_domain_typ to create pppd_lock_t directory in /var/lock Resolves: rhbz#1530601 - Allow updpwd_t domain to create files in /etc with shadow_t label Resolves: rhbz#1412838 - Allow iptables sysctl load list support with SELinux enforced Resolves: rhbz#1535572- Allow virt_domains to acces infiniband pkeys. Resolves: rhbz#1533183 - Label /usr/libexec/ipsec/addconn as ipsec_exec_t to run this script as ipsec_t instead of init_t Resolves: rhbz#1535133 - Allow audisp_remote_t domain write to files on all levels Resolves: rhbz#1534924- Allow vmtools_t domain creating vmware_log_t files Resolves: rhbz#1507048 - Allow openvswitch_t domain to acces infiniband devices Resolves: rhbz#1532705- Allow chronyc_t domain to manage chronyd_keys_t files. Resolves: rhbz#1530525 - Make virtlog_t domain system dbus client Resolves: rhbz#1481109 - Update openvswitch SELinux module Resolves: rhbz#1482682 - Allow virtd_t to create also sock_files with label virt_var_run_t Resolves: rhbz#1484075- Allow domains that manage logfiles to man logdirs Resolves: rhbz#1523811- Label /dev/drm_dp_aux* as xserver_misc_device_t Resolves: rhbz#1520897 - Allow sysadm_t to run puppet_exec_t binaries as puppet_t Resolves: rhbz#1255745- Allow tomcat_t to manage pki_tomcat pid files Resolves: rhbz#1478371 - networkmanager: allow talking to openvswitch Resolves: rhbz#1517247 - Allow networkmanager_t and opensm_t to manage subned endports for IPoIB VLANs Resolves: rhbz#1517895 - Allow domains networkmanager_t and opensm_t to control IPoIB VLANs Resolves: rhbz#1517744 - Fix typo in guest interface file Resolves: rhbz#1468254 - Allow isnsd_t domain to accept tcp connections. Resolves: rhbz#1390208- Allow getty to use usbttys Resolves: rhbz#1514235- Allow ldap_t domain to manage also slapd_tmp_t lnk files Resolves: rhbz#1510883 - Allow cluster_t domain creating bundles directory with label var_log_t instead of cluster_var_log_t Resolves: rhbz:#1508360 - Add dac_read_search and dac_override capabilities to ganesha Resolves: rhbz#1483451- Add dependency for policycoreutils-2.5.18 becuase of new cgroup_seclabel policy capability Resolves: rhbz#1510145- Allow jabber domains to connect to postgresql ports Resolves: rhbz#1438489 - Dontaudit accountsd domain creating dirs in /root Resolves: rhbz#1456760 - Dontaudit slapd_t to block suspend system Resolves: rhbz: #1479759 - Allow spamc_t to stream connect to cyrus. Resolves: rhbz#1382955 - allow imapd to read /proc/net/unix file Resolves: rhbz#1393030 - Allow passenger to connect to mysqld_port_t Resolves: rhbz#1433464- Allow chronyc_t domain to use user_ptys Resolves: rhbz#1470150 - allow ptp4l to read /proc/net/unix file - Allow conmand to use usb ttys. Resolves: rhbz#1505121 - Label all files /var/log/opensm.* as opensm_log_t because opensm creating new log files with name opensm-subnet.lst Resolves: rhbz#1505845 - Allow chronyd daemon to execute chronyc. Resolves: rhbz#1508486 - Allow firewalld exec ldconfig. Resolves: rhbz#1375576 - Allow mozilla_plugin_t domain to dbus chat with devicekit Resolves: rhbz#1460477 - Dontaudit leaked logwatch pipes Resolves: rhbz#1450119 - Label /usr/bin/VGAuthService as vmtools_exec_t to confine this daemon. Resolves: rhbz#1507048 - Allow httpd_t domain to execute hugetlbfs_t files Resolves: rhbz#1507682 - Allow nfsd_t domain to read configfs_t files/dirs Resolves: rhbz#1439442 - Hide all allow rules with ptrace inside deny_ptrace boolean Resolves: rhbz#1421075 - Allow tgtd_t domain to read generic certs Resolves: rhbz#1438532 - Allow ptp4l to send msgs via dgram socket to unprivileged user domains Resolves: rhbz#1429853 - Allow dirsrv_snmp_t to use inherited user ptys and read system state Resolves: rhbz#1428568 - Allow glusterd_t domain to create own tmpfs dirs/files Resolves: rhbz#1411310 - Allow keepalived stream connect to snmp Resolves: rhbz#1401556 - After fix in kernel where LSM hooks for dac_override and dac_search_read capability was swaped we need to fix it also in policy Resolves: rhbz#1507089- Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow chronyd_t do request kernel module and block_suspend capability Resolves: rhbz#1350765 - Allow system_cronjob_t to create /var/lib/letsencrypt dir with right label Resolves: rhbz#1447278 - Allow httpd_t also read httpd_user_content_type dirs when httpd_enable_homedirs is enables Resolves: rhbz#1491994 - Allow svnserve to use kerberos Resolves: rhbz#1475271 - Allow conman to use ptmx. Add conman_use_nfs boolean Resolves: rhbz#1377915 - Add nnp transition for services using: NoNewPrivileges systemd security feature Resolves: rhbz#1311430 - Add SELinux support for chronyc Resolves: rhbz#1470150 - Add dac_read_search capability to openvswitch_t domain Resolves: rhbz#1501336 - Allow svnserve to manage own svnserve_log_t files/dirs Resolves: rhbz#1480741 - Allow keepalived_t to search network sysctls Resolves: rhbz#1477542 - Allow puppetagent_t domain dbus chat with rhsmcertd_t domain Resolves: rhbz#1446777 - Add dccp_socket into socker_class_set subset Resolves: rhbz#1459941 - Allow iptables_t to run setfiles to restore context on system Resolves: rhbz#1489118 - Label 20514 tcp/udp ports as syslogd_port_t Label 10514 tcp/udp portas as syslog_tls_port_t Resolves: rhbz:#1411400 - Make nnp transition Active Resolves: rhbz#1480518 - Label tcp 51954 as isns_port_t Resolves: rhbz#1390208 - Add dac_read_search capability chkpwd_t Resolves: rhbz#1376991 - Add support for running certbot(letsencrypt) in crontab Resolves: rhbz#1447278 - Add init_nnp_daemon_domain interface - Allow xdm_t to gettattr /dev/loop-control device Resolves: rhbz#1462925 - Allow nnp trasintion for unconfined_service_t Resolves: rhbz#1311430 - Allow unpriv user domains and unconfined_service_t to use chronyc Resolves: rhbz#1470150 - Allow iptables to exec plymouth. Resolves: rhbz#1480374 - Fix typo in fs_unmount_tracefs interface. Resolves: rhbz#1371057 - Label postgresql-check-db-dir as postgresql_exec_t Resolves: rhbz#1490956- We should not ship selinux-policy with permissivedomains enabled. Resolves: rhbz#1494172 - Fix order of installing selinux-policy-sandbox, because of depedencied in sandbox module, selinux-policy-targeted needs to be installed before selinux-policy-sandbox Resolves: rhbz#1492606- Allow tomcat to setsched Resolves: rhbz#1492730 - Fix rules blocking ipa-server upgrade process Resolves: rhbz#1478371 - Add new boolean tomcat_read_rpm_db() Resolves: rhbz#1477887 - Allow tomcat to connect on mysqld tcp ports - Add ctdbd_t domain sys_source capability and allow setrlimit Resolves: rhbz#1491235 - Fix keepalived SELinux module - Allow automount domain to manage mount pid files Resolves: rhbz#1482381 - Allow stunnel_t domain setsched Resolves: rhbz#1479383 - Add keepalived domain setpgid capability Resolves: rhbz#1486638 - Allow tomcat domain to connect to mssql port Resolves: rhbz#1484572 - Remove snapperd_t from unconfined domaines Resolves: rhbz#1365555 - Fix typo bug in apache module Resolves: rhbz#1397311 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Add interface systemd_tmpfiles_run - End of file cannot be in comment - Allow systemd-logind to use ypbind Resolves: rhbz#1479350 - Add creating opasswd file with shadow_t SELinux label in auth_manage_shadow() interface Resolves: rhbz#1412838 - Allow sysctl_irq_t assciate with proc_t Resolves: rhbz#1485909 - Enable cgourp sec labeling Resolves: rhbz#1485947 - Add cgroup_seclabel policycap. Resolves: rhbz#1485947 - Allow sshd_t domain to send signull to xdm_t processes Resolves: rhbz#1448959 - Allow updpwd_t domain auth file name trans Resolves: rhbz#1412838 - Allow sysadm user to run systemd-tmpfiles Resolves: rbhz#1325364 - Add support labeling for vmci and vsock device Resolves: rhbz#1451358 - Add userdom_dontaudit_manage_admin_files() interface Resolves: rhbz#1323792 - Allow iptables_t domain to read files with modules_conf_t label Resolves: rhbz#1373220 - init: Add NoNewPerms support for systemd. Resolves: rhbz#1480518 - Add nnp_nosuid_transition policycap and related class/perm definitions. Resolves: rhbz#1480518 - refpolicy: Infiniband pkeys and endports Resolves: rhbz#1464484- Allow certmonger using systemctl on pki_tomcat unit files Resolves: rhbz#1481388- Allow targetd_t to create own tmp files. - Dontaudit targetd_t to exec rpm binary file. Resolves: rhbz#1373860 Resolves: rhbz#1424621- Add few rules to make working targetd daemon with SELinux Resolves: rhbz#1373860 - Allow ipmievd_t domain to load kernel modules Resolves: rhbz#1441081 - Allow logrotate to reload transient systemd unit Resolves: rhbz#1440515 - Add certwatch_t domain dac_override and dac_read_search capabilities Resolves: rhbz#1422000 - Allow postgrey to execute bin_t files and add postgrey into nsswitch_domain Resolves: rhbz#1412072 - Allow nscd_t domain to search network sysctls Resolves: rhbz#1432361 - Allow iscsid_t domain to read mount pid files Resolves: rhbz#1482097 - Allow ksmtuned_t domain manage sysfs_t files/dirs Resolves: rhbz#1413865 - Allow keepalived_t domain domtrans into iptables_t Resolves: rhbz#1477719 - Allow rshd_t domain reads net sysctls Resolves: rhbz#1477908 - Add interface seutil_dontaudit_read_module_store() - Update interface lvm_rw_pipes() by adding also open permission - Label /dev/clp device as vfio_device_t Resolves: rhbz#1477624 - Allow ifconfig_t domain unmount fs_t Resolves: rhbz#1477445 - Label /dev/gpiochip* devices as gpio_device_t Resolves: rhbz#1477618 - Add interface dev_manage_sysfs() Resolves: rhbz#1474989- Label /usr/libexec/sudo/sesh as shell_exec_t Resolves: rhbz#1480791- Allow tomcat_t domain couple capabilities to make working tomcat-jsvc Resolves: rhbz#1470735- Allow llpdad send dgram to libvirt Resolves: rhbz#1472722- Add new boolean gluster_use_execmem Resolves: rhbz#1469027 - Allow cluster_t and glusterd_t domains to dbus chat with ganesha service Resolves: rhbz#1468581- Dontaudit staff_t user read admin_home_t files. Resolves: rhbz#1290633- Allow couple rules needed to start targetd daemon with SELinux in enforcing mode Resolves: rhbz#1424621 - Add interface lvm_manage_metadata Resolves: rhbz#1424621- Allow sssd_t to read realmd lib files. Resolves: rhbz#1436689 - Add permission open to files_read_inherited_tmp_files() interface Resolves: rhbz#1290633 Resolves: rhbz#1457106- Allow unconfined_t user all user namespace capabilties. Resolves: rhbz#1461488- Allow httpd_t to read realmd_var_lib_t files Resolves: rhbz#1436689- Allow named_t to bind on udp 4321 port Resolves: rhbz#1312972 - Allow systemd-sysctl cap. sys_ptrace Resolves: rhbz#1458999- Allow pki_tomcat_t execute ldconfig. Resolves: rhbz#1436689- Allow iscsi domain load kernel module. Resolves: rhbz#1457874 - Allow keepalived domain connect to squid tcp port Resolves: rhbz#1457455 - Allow krb5kdc_t domain read realmd lib files. Resolves: rhbz#1436689 - xdm_t should view kernel keys Resolves: rhbz#1432645- Allow tomcat to connect on all unreserved ports - Allow ganesha to connect to all rpc ports Resolves: rhbz#1448090 - Update ganesha with another fixes. Resolves: rhbz#1448090 - Update rpc_read_nfs_state_data() interface to allow read also lnk_files. Resolves: rhbz#1448090 - virt_use_glusterd boolean should be in optional block Update ganesha module to allow create tmp files Resolves: rhbz#1448090 - Hide broken symptoms when machine is configured with network bounding.- Add new boolean virt_use_glusterd Resolves: rhbz#1455994 - Add capability sys_boot for sbd_t domain - Allow sbd_t domain to create rpc sysctls. Resolves: rhbz#1455631 - Allow ganesha_t domain to manage glusterd_var_run_t pid files. Resolves: rhbz#1448090- Create new interface: glusterd_read_lib_files() - Allow ganesha read glusterd lib files. - Allow ganesha read network sysctls Resolves: rhbz#1448090- Add few allow rules to ganesha module Resolves: rhbz#1448090 - Allow condor_master_t to read sysctls. Resolves: rhbz#1277506 - Add dac_override cap to ctdbd_t domain Resolves: rhbz#1435708 - Label 8750 tcp/udp port as dey_keyneg_port_t Resolves: rhbz#1448090- Add ganesha_use_fusefs boolean. Resolves: rhbz#1448090- Allow httpd_t reading kerberos kdc config files Resolves: rhbz#1452215 - Allow tomcat_t domain connect to ibm_dt_2 tcp port. Resolves: rhbz#1447436 - Allow stream connect to initrc_t domains Resolves: rhbz#1447436 - Allow dnsmasq_t domain to read systemd-resolved pid files. Resolves: rhbz#1453114 - Allow tomcat domain name_bind on tcp bctp_port_t Resolves: rhbz#1451757 - Allow smbd_t domain generate debugging files under /var/run/gluster. These files are created through the libgfapi.so library that provides integration of a GlusterFS client in the Samba (vfs_glusterfs) process. Resolves: rhbz#1447669 - Allow condor_master_t write to sysctl_net_t Resolves: rhbz#1277506 - Allow nagios check disk plugin read /sys/kernel/config/ Resolves: rhbz#1277718 - Allow pcp_pmie_t domain execute systemctl binary Resolves: rhbz#1271998 - Allow nagios to connect to stream sockets. Allow nagios start httpd via systemctl Resolves: rhbz#1247635 - Label tcp/udp port 1792 as ibm_dt_2_port_t Resolves: rhbz#1447436 - Add interface fs_read_configfs_dirs() - Add interface fs_read_configfs_files() - Fix systemd_resolved_read_pid interface - Add interface systemd_resolved_read_pid() Resolves: rhbz#1453114 - Allow sshd_net_t domain read/write into crypto devices Resolves: rhbz#1452759 - Label 8999 tcp/udp as bctp_port_t Resolves: rhbz#1451757- nmbd_t needs net_admin capability like smbd Resolves: rhbz#1431859 - Dontaudit net_admin capability for domains postfix_master_t and postfix_qmgr_t Resolves: rhbz#1431859 - Allow rngd domain read sysfs_t Resolves: rhbz#1451735 - Add interface pki_manage_common_files() Resolves: rhbz#1447436 - Allow tomcat_t domain to manage pki_common_t files and dirs Resolves: rhbz#1447436 - Use stricter fc rules for sssd sockets in /var/run Resolves: rhbz#1448060 - Allow certmonger reads httpd_config_t files Resolves: rhbz#1436689 - Allow keepalived_t domain creating netlink_netfilter_socket. Resolves: rhbz#1451684 - Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321- Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Allow sssd_t domain creating sock files labeled as sssd_var_run_t in /var/run/ Resolves: rhbz#1448056 Resolves: rhbz#1448060 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321 - Allow netutils setpcap capability Resolves:1444438- Update targetd policy to accommodate changes in the service Resolves: rhbz#1424621 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Update virt_rw_stream_sockets_svirt() interface to allow confined users set socket options. Resolves: rhbz#1415841 - Allow radius domain stream connec to postgresql Resolves: rhbz#1446145 - Allow virt_domain to read raw fixed_disk_device_t to make working blockcommit Resolves: rhbz#1449977 - Allow glusterd_t domain start ganesha service Resolves: rhbz#1448090 - Made few cosmetic changes in sssd SELinux module Resolves: rhbz#1448060 - sssd-kcm should not run as unconfined_service_t BZ(1447411) Resolves: rhbz#1448060 - Add sssd_secrets labeling Also add named_filetrans interface to make sure all labels are correct Resolves: rhbz#1448056 - Allow keepalived_t domain read usermodehelper_t Resolves: rhbz#1449769 - Allow tomcat_t domain read pki_common_t files Resolves: rhbz#1447436 - Add interface pki_read_common_files() Resolves: rhbz#1447436- Allow hypervkvp_t domain execute hostname Resolves: rhbz#1449064 - Dontaudit sssd_selinux_manager_t use of net_admin capability Resolves: rhbz#1444955 - Allow tomcat_t stream connect to pki_common_t Resolves: rhbz#1447436 - Dontaudit xguest_t's attempts to listen to its tcp_socket - Allow sssd_selinux_manager_t to ioctl init_t sockets Resolves: rhbz#1436689 - Allow _su_t to create netlink_selinux_socket Resolves rhbz#1146987 - Allow unconfined_t to module_load any file Resolves rhbz#1442994- Improve ipa_cert_filetrans_named_content() interface to also allow caller domain manage ipa_cert_t type. Resolves: rhbz#1436689- Allow pki_tomcat_t domain read /etc/passwd. Resolves: rhbz#1436689 - Allow tomcat_t domain read ipa_tmp_t files Resolves: rhbz#1436689 - Label new path for ipa-otpd Resolves: rhbz#1446353 - Allow radiusd_t domain stream connect to postgresql_t Resolves: rhbz#1446145 - Allow rhsmcertd_t to execute hostname_exec_t binaries. Resolves: rhbz#1445494 - Allow virtlogd to append nfs_t files when virt_use_nfs=1 Resolves: rhbz#1402561- Update tomcat policy to adjust for removing unconfined_domain attr. Resolves: rhbz#1432083 - Allow httpd_t domain read also httpd_user_content_type lnk_files. Resolves: rhbz#1383621 - Allow httpd_t domain create /etc/httpd/alias/ipaseesion.key with label ipa_cert_t Resolves: rhbz#1436689 - Dontaudit _gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Label /var/www/html/nextcloud/data as httpd_sys_rw_content_t Resolves: rhbz#1425530 - Add interface ipa_filetrans_named_content() Resolves: rhbz#1432115 - Allow tomcat use nsswitch Resolves: rhbz#1436689 - Allow certmonger_t start/status generic services Resolves: rhbz#1436689 - Allow dirsrv read cgroup files. Resolves: rhbz#1436689 - Allow ganesha_t domain read/write infiniband devices. Resolves: rhbz#1383784 - Allow sendmail_t domain sysctl_net_t files Resolves: rhbz#1369376 - Allow targetd_t domain read network state and getattr on loop_control_device_t Resolves: rhbz#1373860 - Allow condor_schedd_t domain send mails. Resolves: rhbz#1277506 - Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689 - Allow staff to systemctl virt server when staff_use_svirt=1 Resolves: rhbz#1415841 - Allow unconfined_t create /tmp/ca.p12 file with ipa_tmp_t context Resolves: rhbz#1432115 - Label /sysroot/ostree/deploy/rhel-atomic-host/* as root_t Resolves: rhbz#1428112- Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689- Hide broken symptoms when using kernel 3.10.0-514+ with network bonding. Postfix_picup_t domain requires NET_ADMIN capability which is not really needed. Resolves: rhbz#1431859 - Fix policy to reflect all changes in new IPA release Resolves: rhbz#1432115 Resolves: rhbz#1436689- Allow sbd_t to read/write fixed disk devices Resolves: rhbz#1440165 - Add sys_ptrace capability to radiusd_t domain Resolves: rhbz#1426641 - Allow cockpit_session_t domain connects to ssh tcp ports. Resolves: rhbz#1413509- Update tomcat policy to make working ipa install process Resolves: rhbz#1436689- Allow pcp_pmcd_t net_admin capability. - Allow pcp_pmcd_t read net sysctls - Allow system_cronjob_t create /var/run/pcp with pcp_var_run_t Resolves: rhbz#1336211- Fix all AVC denials during pkispawn of CA Resolves: rhbz#1436383 - Update pki interfaces and tomcat module Resolves: rhbz#1436689- Update pki interfaces and tomcat module Resolves: rhbz#1436689- Dontaudit firewalld wants write to /root Resolves: rhbz#1438708 - Dontaudit firewalld to create dirs in /root/ Resolves: rhbz#1438708 - Allow sendmail to search network sysctls Resolves: rhbz#1369376 - Add interface gssd_noatsecure() Resolves: rhbz#1438036 - Add interface gssproxy_noatsecure() Resolves: rhbz#1438036 - Dontaudit pcp_pmlogger_t search for xserver logs. Allow pcp_pmlogger_t to send signals to unconfined doamins Allow pcp_pmlogger_t to send logs to journals Resolves: rhbz#1379371 - Allow chronyd_t net_admin capability to allow support HW timestamping. Resolves: rhbz#1416015 - Update tomcat policy Resolves: rhbz#1436689 Resolves: rhbz#1436383 - Allow certmonger to start haproxy service Resolves: rhbz#1349394 - Allow init noatsecure for gssd and gssproxy Resolves: rhbz#1438036- geoclue wants to dbus chat with avahi Resolves: rhbz#1434286 - Allow iptables get list of kernel modules Resolves: rhbz#1367520 - Allow unconfined_domain_type to enable/disable transient unit Resolves: rhbz#1337041 - Add interfaces init_enable_transient_unit() and init_disable_transient_unit - Revert "Allow sshd setcap capability. This is needed due to latest changes in sshd" Resolves: rhbz#1435264 - Label sysroot dir under ostree as root_t Resolves: rhbz#1428112- Remove ganesha_t domain from permissive domains. Resolves: rhbz#1436988- Allow named_t domain bind on several udp ports Resolves: rhbz#1312972 - Update nscd_use() interface Resolves: rhbz#1281716 - Allow radius_t domain ptrace Resolves: rhbz#1426641 - Update nagios to allos exec systemctl Resolves: rhbz#1247635 - Update pcp SELinux module to reflect all pcp changes Resolves: rhbz#1271998 - Label /var/lib/ssl_db as squid_cache_t Label /etc/squid/ssl_db as squid_cache_t Resolves: rhbz#1325527 - Allow pcp_pmcd_t domain search for network sysctl Allow pcp_pmcd_t domain sys_ptrace capability Resolves: rhbz#1336211- Allow drbd load modules Resolves: rhbz#1134883 - Revert "Add sys_module capability for drbd Resolves: rhbz#1134883" - Allow stapserver list kernel modules Resolves: rhbz#1325976 - Update targetd policy Resolves: rhbz#1373860 - Add sys_admin capability to amanda Resolves: rhbz#1371561 - Allow hypervvssd_t to read all dirs. Resolves: rhbz#1331309 - Label /run/haproxy.sock socket as haproxy_var_run_t Resolves: rhbz#1386233 - Allow oddjob_mkhomedir_t to mamange autofs_t dirs. Resolves: rhbz#1408819 - Allow tomcat to connect on http_cache_port_t Resolves: rhbz#1432083 - Allow geoclue to send msgs to syslog. Resolves: rhbz#1434286 - Allow condor_master_t domain capability chown. Resolves: rhbz#1277506 - Update mta_filetrans_named_content() interface to allow calling domain create files labeled as etc_aliases_t in dir labeled as etc_mail_t. Resolves: rhbz#1167468 - Allow nova domain search for httpd configuration. Resolves: rhbz#1190761 - Add sys_module capability for drbd Resolves: rhbz#1134883 - Allow user_u users stream connect to dirsrv, Allow sysadm_u and staff_u users to manage dirsrv files Resolves: rhbz#1286474 - Allow systemd_networkd_t communicate with systemd_networkd_t via dbus Resolves: rhbz#1278010- Add haproxy_t domain fowner capability Resolves: rhbz#1386233 - Allow domain transition from ntpd_t to hwclock_t domains Resolves: rhbz#1375624 - Allow cockpit_session_t setrlimit and sys_resource Resolves: rhbz#1402316 - Dontaudit svirt_t read state of libvirtd domain Resolves: rhbz#1426106 - Update httpd and gssproxy modules to reflects latest changes in freeipa Resolves: rhbz#1432115 - Allow iptables read modules_conf_t Resolves: rhbz#1367520- Remove tomcat_t domain from unconfined domains Resolves: rhbz#1432083 - Create new boolean: sanlock_enable_home_dirs() Resolves: rhbz#1432783 - Allow mdadm_t domain to read/write nvme_device_t Resolves: rhbz#1431617 - Remove httpd_user_*_content_t domains from user_home_type attribute. This tighten httpd policy and acces to user data will be more strinct, and also fix mutual influente between httpd_enable_homedirs and httpd_read_user_content Resolves: rhbz#1383621 - Dontaudit domain to create any file in /proc. This is kernel bug. Resolves: rhbz#1412679 - Add interface dev_rw_nvme Resolves: rhbz#1431617- Allow gssproxy to get attributes on all filesystem object types. Resolves: rhbz#1430295 - Allow ganesha to chat with unconfined domains via dbus Resolves: rhbz#1426554 - add the policy required for nextcloud Resolves: rhbz#1425530 - Add nmbd_t capability2 block_suspend Resolves: rhbz#1425357 - Label /var/run/chrony as chronyd_var_run_t Resolves: rhbz#1416015 - Add domain transition from sosreport_t to iptables_t Resolves: rhbz#1359789 - Fix path to /usr/lib64/erlang/erts-5.10.4/bin/epmd Resolves: rhbz:#1332803- Update rpm macros Resolves: rhbz#1380854- Add handling booleans via selinux-policy macros in custom policy spec files. Resolves: rhbz#1380854- Allow openvswitch to load kernel modules Resolves: rhbz#1405479- Allow openvswitch read script state. Resolves: rhbz#1405479- Update ganesha policy Resolves: rhbz#1426554 Resolves: rhbz#1383784 - Allow chronyd to read adjtime Resolves: rhbz#1416015 - Fixes for chrony version 2.2 Resolves: rhbz#1416015 - Add interface virt_rw_stream_sockets_svirt() Resolves: rhbz#1415841 - Label /dev/ss0 as gpfs_device_t Resolves: rhbz#1383784 - Allow staff to rw svirt unix stream sockets. Resolves: rhbz#1415841 - Label /rhev/data-center/mnt as mnt_t Resolves: rhbz#1408275 - Associate sysctl_rpc_t with proc filesystems Resolves: rhbz#1350927 - Add new boolean: domain_can_write_kmsg Resolves: rhbz#1415715- Allow rhsmcertd_t dbus chat with system_cronjob_t Resolves: rhbz#1405341 - Allow openvswitch exec hostname and readinitrc_t files Resolves: rhbz#1405479 - Improve SELinux context for mysql_db_t objects. Resolves: rhbz#1391521 - Allow postfix_postdrop to communicate with postfix_master via pipe. Resolves: rhbz#1379736 - Add radius_use_jit boolean Resolves: rhbz#1426205 - Label /var/lock/subsys/iptables as iptables_lock_t Resolves: rhbz#1405441 - Label /usr/lib64/erlang/erts-5.10.4/bin/epmd as lib_t Resolves: rhbz#1332803 - Allow can_load_kernmodule to load kernel modules. Resolves: rhbz#1423427 Resolves: rhbz#1424621- Allow nfsd_t domain to create sysctls_rpc_t files Resolves: rhbz#1405304 - Allow openvswitch to create netlink generic sockets. Resolves: rhbz#1397974 - Create kernel_create_rpc_sysctls() interface Resolves: rhbz#1405304- Allow nfsd_t domain rw sysctl_rpc_t dirs Resolves: rhbz#1405304 - Allow cgdcbxd_t to manage cgroup files. Resolves: rhbz#1358493 - Allow cmirrord_t domain to create netlink_connector sockets Resolves: rhbz#1412670 - Allow fcoemon to create netlink scsitransport sockets Resolves: rhbz#1362496 - Allow quota_nld_t create netlink_generic sockets Resolves: rhbz#1358679 - Allow cgred_t create netlink_connector sockets Resolves: rhbz#1376357 - Add dhcpd_t domain fowner capability Resolves: rhbz#1358485 - Allow acpid to attempt to connect to the Linux kernel via generic netlink socket. Resolves: rhbz#1358478 - Rename docker module to container module Resolves: rhbz#1386916 - Allow setflies to mount tracefs Resolves: rhbz#1376357 - Allow iptables to read nsfs files. Resolves: rhbz#1411316 - Allow systemd_bootchart_t domain create dgram sockets. Resolves: rhbz#1365953 - Rename docker interfaces to container Resolves: rhbz#1386916- Allow initrc_t domain to run rhel-autorelabel script properly during boot process Resolves: rhbz#1379722 - Allow systemd_initctl_t to create and connect unix_dgram sockets Resolves: rhbz#1365947 - Allow ifconfig_t to mount/unmount nsfs_t filesystem Resolves: rhbz#1349814 - Add interfaces allowing mount/unmount nsfs_t filesystem Resolves: rhbz#1349814- Add interface init_stream_connectto() Resolves:rhbz#1365947 - Allow rhsmcertd domain signull kernel. Resolves: rhbz#1379781 - Allow kdumpgui domain to read nvme device - Allow insmod_t to load kernel modules Resolves: rhbz#1421598 - Add interface files_load_kernel_modules() Resolves: rhbz#1421598 - Add SELinux support for systemd-initctl daemon Resolves:rhbz#1365947 - Add SELinux support for systemd-bootchart Resolves: rhbz#1365953- Allow firewalld to getattr open search read modules_object_t:dir Resolves: rhbz#1418391 - Fix label for nagios plugins in nagios file conxtext file Resolves: rhbz#1277718 - Add sys_ptrace capability to pegasus domain Resolves: rhbz#1381238 - Allow sssd_t domain setpgid Resolves:rhbz#1416780 - After the latest changes in nfsd. We should allow nfsd_t to read raw fixed disk. Resolves: rhbz#1350927 - Allow kdumpgui domain to read nvme device Resolves: rhbz#1415084 - su using libselinux and creating netlink_selinux socket is needed to allow libselinux initialization. Resolves: rhbz#1146987 - Add user namespace capability object classes. Resolves: rhbz#1368057 - Add module_load permission to class system Resolves:rhbz#1368057 - Add the validate_trans access vector to the security class Resolves: rhbz#1368057 - Add "binder" security class and access vectors Resolves: rhbz#1368057 - Allow ifconfig_t domain read nsfs_t Resolves: rhbz#1349814 - Allow ping_t domain to load kernel modules. Resolves: rhbz#1388363- Allow systemd container to read/write usermodehelperstate Resolves: rhbz#1403254 - Label udp ports in range 24007-24027 as gluster_port_t Resolves: rhbz#1404152- Allow glusterd_t to bind on glusterd_port_t udp ports. Resolves: rhbz#1404152 - Revert: Allow glusterd_t to bind on med_tlp port.- Allow glusterd_t to bind on med_tlp port. Resolves: rhbz#1404152 - Update ctdbd_t policy to reflect all changes. Resolves: rhbz#1402451 - Label tcp port 24009 as med_tlp_port_t Resolves: rhbz#1404152 - Issue appears during update directly from RHEL-7.0 to RHEL-7.3 or above. Modules pkcsslotd and vbetools missing in selinux-policy package for RHEL-7.3 which causing warnings during SELinux policy store migration process. Following patch fixes issue by skipping pkcsslotd and vbetools modules migration.- Allow ctdbd_t domain transition to rpcd_t Resolves:rhbz#1402451- Fixes for containers Allow containers to attempt to write to unix_sysctls. Allow cotainers to use the FD's leaked to them from parent processes. Resolves: rhbz#1403254- Allow glusterd_t send signals to userdomain. Label new glusterd binaries as glusterd_exec_t Resolves: rhbz#1404152 - Allow systemd to stop glusterd_t domains. Resolves: rhbz#1400493- Make working CTDB:NFS: CTDB failover from selinux-policy POV Resolves: rhbz#1402451- Add kdump_t domain sys_admin capability Resolves: rhbz#1375963- Allow puppetagent_t to access timedated dbus. Use the systemd_dbus_chat_timedated interface to allow puppetagent_t the access. Resolves: rhbz#1399250- Update systemd on RHEL-7.2 box to version from RHEL-7.3 and then as a separate yum command update the selinux policy systemd will start generating USER_AVC denials and will start returning "Access Denied" errors to DBus clients Resolves: rhbz#1393505- Allow cluster_t communicate to fprintd_t via dbus Resolves: rhbz#1349798- Fix error message during update from RHEL-7.2 to RHEL-7.3, when /usr/sbin/semanage command is not installed and selinux-policy-migrate-local-changes.sh script is executed in %post install phase of selinux-policy package Resolves: rhbz#1392010- Allow GlusterFS with RDMA transport to be started correctly. It requires ipc_lock capability together with rw permission on rdma_cm device. Resolves: rhbz#1384488 - Allow glusterd to get attributes on /sys/kernel/config directory. Resolves: rhbz#1384483- Use selinux-policy-migrate-local-changes.sh instead of migrateStore* macros - Add selinux-policy-migrate-local-changes service Resolves: rhbz#1381588- Allow sssd_selinux_manager_t to manage also dir class. Resolves: rhbz#1368097 - Add interface seutil_manage_default_contexts_dirs() Resolves: rhbz#1368097- Add virt_sandbox_use_nfs -> virt_use_nfs boolean substitution. Resolves: rhbz#1355783- Allow pcp_pmcd_t domain transition to lvm_t Add capability kill and sys_ptrace to pcp_pmlogger_t Resolves: rhbz#1309883- Allow ftp daemon to manage apache_user_content Resolves: rhbz#1097775 - Label /etc/sysconfig/oracleasm as oracleasm_conf_t Resolves: rhbz#1331383 - Allow oracleasm to rw inherited fixed disk device Resolves: rhbz#1331383 - Allow collectd to connect on unix_stream_socket Resolves: rhbz#1377259- Allow iscsid create netlink iscsid sockets. Resolves: rhbz#1358266 - Improve regexp for power_unit_file_t files. To catch just systemd power unit files. Resolves: rhbz#1375462- Update oracleasm SELinux module that can manage oracleasmfs_t blk files. Add dac_override cap to oracleasm_t domain. Resolves: rhbz#1331383 - Add few rules to pcp SELinux module to make ti able to start pcp_pmlogger service Resolves: rhbz#1206525- Add oracleasm_conf_t type and allow oracleasm_t to create /dev/oracleasm Resolves: rhbz#1331383 - Label /usr/share/pcp/lib/pmie as pmie_exec_t and /usr/share/pcp/lib/pmlogger as pmlogger_exec_t Resolves: rhbz#1206525 - Allow mdadm_t to getattr all device nodes Resolves: rhbz#1365171 - Add interface dbus_dontaudit_stream_connect_system_dbusd() Resolves:rhbz#1052880 - Add virt_stub_* interfaces for docker policy which is no longer a part of our base policy. Resolves: rhbz#1372705 - Allow guest-set-user-passwd to set users password. Resolves: rhbz#1369693 - Allow samdbox domains to use msg class Resolves: rhbz#1372677 - Allow domains using kerberos to read also kerberos config dirs Resolves: rhbz#1368492 - Allow svirt_sandbox_domains to r/w onload sockets Resolves: rhbz#1342930 - Add interface fs_manage_oracleasm() Resolves: rhbz#1331383 - Label /dev/kfd as hsa_device_t Resolves: rhbz#1373488 - Update seutil_manage_file_contexts() interface that caller domain can also manage file_context_t dirs Resolves: rhbz#1368097 - Add interface to write to nsfs inodes Resolves: rhbz#1372705 - Allow systemd services to use PrivateNetwork feature Resolves: rhbz#1372705 - Add a type and genfscon for nsfs. Resolves: rhbz#1372705 - Allow run sulogin_t in range mls_systemlow-mls_systemhigh. Resolves: rhbz#1290400- Allow arpwatch to create netlink netfilter sockets. Resolves: rhbz#1358261 - Fix file context for /etc/pki/pki-tomcat/ca/ - new interface oddjob_mkhomedir_entrypoint() - Move label for /var/lib/docker/vfs/ to proper SELinux module - Allow mdadm to get attributes from all devices. - Label /etc/puppetlabs as puppet_etc_t. - Allow systemd-machined to communicate to lxc container using dbus - Allow systemd_resolved to send dbus msgs to userdomains Resolves: rhbz#1236579 - Allow systemd-resolved to read network sysctls Resolves: rhbz#1236579 - Allow systemd_resolved to connect on system bus. Resolves: rhbz#1236579 - Make entrypoint oddjob_mkhomedir_exec_t for unconfined_t - Label all files in /dev/oracleasmfs/ as oracleasmfs_t Resolves: rhbz#1331383- Label /etc/pki/pki-tomcat/ca/ as pki_tomcat_cert_t Resolves:rhbz#1366915 - Allow certmonger to manage all systemd unit files Resolves:rhbz#1366915 - Grant certmonger "chown" capability Resolves:rhbz#1366915 - Allow ipa_helper_t stream connect to dirsrv_t domain Resolves: rhbz#1368418 - Update oracleasm SELinux module Resolves: rhbz#1331383 - label /var/lib/kubelet as svirt_sandbox_file_t Resolves: rhbz#1369159 - Add few interfaces to cloudform.if file Resolves: rhbz#1367834 - Label /var/run/corosync-qnetd and /var/run/corosync-qdevice as cluster_var_run_t. Note: corosync policy is now par of rhcs module Resolves: rhbz#1347514 - Allow krb5kdc_t to read krb4kdc_conf_t dirs. Resolves: rhbz#1368492 - Update networkmanager_filetrans_named_content() interface to allow source domain to create also temad dir in /var/run. Resolves: rhbz#1365653 - Allow teamd running as NetworkManager_t to access netlink_generic_socket to allow multiple network interfaces to be teamed together. Resolves: rhbz#1365653 - Label /dev/oracleasmfs as oracleasmfs_t. Add few interfaces related to oracleasmfs_t type Resolves: rhbz#1331383 - A new version of cloud-init that supports the effort to provision RHEL Atomic on Microsoft Azure requires some a new rules that allows dhclient/dhclient hooks to call cloud-init. Resolves: rhbz#1367834 - Allow iptables to creating netlink generic sockets. Resolves: rhbz#1364359- Allow ipmievd domain to create lock files in /var/lock/subsys/ Resolves:rhbz#1349058 - Update policy for ipmievd daemon. Resolves:rhbz#1349058 - Dontaudit hyperkvp to getattr on non security files. Resolves: rhbz#1349356 - Label /run/corosync-qdevice and /run/corosync-qnetd as corosync_var_run_t Resolves: rhbz#1347514 - Fixed lsm SELinux module - Add sys_admin capability to sbd domain Resolves: rhbz#1322725 - Allow vdagent to comunnicate with systemd-logind via dbus Resolves: rhbz#1366731 - Allow lsmd_plugin_t domain to create fixed_disk device. Resolves: rhbz#1238066 - Allow opendnssec domain to create and manage own tmp dirs/files Resolves: rhbz#1366649 - Allow opendnssec domain to read system state Resolves: rhbz#1366649 - Update opendnssec_manage_config() interface to allow caller domain also manage opendnssec_conf_t dirs Resolves: rhbz#1366649 - Allow rasdaemon to mount/unmount tracefs filesystem. Resolves: rhbz#1364380 - Label /usr/libexec/iptables/iptables.init as iptables_exec_t Allow iptables creating lock file in /var/lock/subsys/ Resolves: rhbz#1367520 - Modify interface den_read_nvme() to allow also read nvme_device_t block files. Resolves: rhbz#1362564 - Label /var/run/storaged as lvm_var_run_t. Resolves: rhbz#1264390 - Allow unconfineduser to run ipa_helper_t. Resolves: rhbz#1361636- Dontaudit mock to write to generic certs. Resolves: rhbz#1271209 - Add labeling for corosync-qdevice and corosync-qnetd daemons, to run as cluster_t Resolves: rhbz#1347514 - Revert "Label corosync-qnetd and corosync-qdevice as corosync_t domain" - Allow modemmanager to write to systemd inhibit pipes Resolves: rhbz#1365214 - Label corosync-qnetd and corosync-qdevice as corosync_t domain Resolves: rhbz#1347514 - Allow ipa_helper to read network state Resolves: rhbz#1361636 - Label oddjob_reqiest as oddjob_exec_t Resolves: rhbz#1361636 - Add interface oddjob_run() Resolves: rhbz#1361636 - Allow modemmanager chat with systemd_logind via dbus Resolves: rhbz#1362273 - Allow NetworkManager chat with puppetagent via dbus Resolves: rhbz#1363989 - Allow NetworkManager chat with kdumpctl via dbus Resolves: rhbz#1363977 - Allow sbd send msgs to syslog Allow sbd create dgram sockets. Allow sbd to communicate with kernel via dgram socket Allow sbd r/w kernel sysctls. Resolves: rhbz#1322725 - Allow ipmievd_t domain to re-create ipmi devices Label /usr/libexec/openipmi-helper as ipmievd_exec_t Resolves: rhbz#1349058 - Allow rasdaemon to use tracefs filesystem. Resolves: rhbz#1364380 - Fix typo bug in dirsrv policy - Some logrotate scripts run su and then su runs unix_chkpwd. Allow logrotate_t domain to check passwd. Resolves: rhbz#1283134 - Add ipc_lock capability to sssd domain. Allow sssd connect to http_cache_t Resolves: rhbz#1362688 - Allow dirsrv to read dirsrv_share_t content Resolves: rhbz#1363662 - Allow virtlogd_t to append svirt_image_t files. Resolves: rhbz#1358140 - Allow hypervkvp domain to read hugetlbfs dir/files. Resolves: rhbz#1349356 - Allow mdadm daemon to read nvme_device_t blk files Resolves: rhbz#1362564 - Allow selinuxusers and unconfineduser to run oddjob_request Resolves: rhbz#1361636 - Allow sshd server to acces to Crypto Express 4 (CEX4) devices. Resolves: rhbz#1362539 - Fix labeling issue in init.fc file. Path /usr/lib/systemd/fedora-* changed to /usr/lib/systemd/rhel-*. Resolves: rhbz#1363769 - Fix typo in device interfaces Resolves: rhbz#1349058 - Add interfaces for managing ipmi devices Resolves: rhbz#1349058 - Add interfaces to allow mounting/umounting tracefs filesystem Resolves: rhbz#1364380 - Add interfaces to allow rw tracefs filesystem Resolves: rhbz#1364380 - Add interface dev_read_nvme() to allow reading Non-Volatile Memory Host Controller devices. Resolves: rhbz#1362564 - Label /sys/kernel/debug/tracing filesystem Resolves: rhbz#1364380 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857- Dontaudit mock_build_t can list all ptys. Resolves: rhbz#1271209 - Allow ftpd_t to mamange userhome data without any boolean. Resolves: rhbz#1097775 - Add logrotate permissions for creating netlink selinux sockets. Resolves: rhbz#1283134 - Allow lsmd_plugin_t to exec ldconfig. Resolves: rhbz#1238066 - Allow vnstatd domain to read /sys/class/net/ files Resolves: rhbz#1358243 - Remove duplicate allow rules in spamassassin SELinux module Resolves:rhbz#1358175 - Allow spamc_t and spamd_t domains create .spamassassin file in user homedirs Resolves:rhbz#1358175 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857 - Add new MLS attribute to allow relabeling objects higher than system low. This exception is needed for package managers when processing sensitive data. Resolves: rhbz#1330464 - Allow gnome-keyring also manage user_tmp_t sockets. Resolves: rhbz#1257057 - corecmd: Remove fcontext for /etc/sysconfig/libvirtd Resolves:rhbz#1351382- Allow ipa_dnskey domain to search cache dirs Resolves: rhbz#1350957- Allow ipa-dnskey read system state. Reasolves: rhbz#1350957 - Allow dogtag-ipa-ca-renew-agent-submit labeled as certmonger_t to create /var/log/ipa/renew.log file Resolves: rhbz#1350957- Allow firewalld to manage net_conf_t files. Resolves:rhbz#1304723 - Allow logrotate read logs inside containers. Resolves: rhbz#1303514 - Allow sssd to getattr on fs_t Resolves: rhbz#1356082 - Allow opendnssec domain to manage bind chace files Resolves: rhbz#1350957 - Fix typo in rhsmcertd policy module Resolves: rhbz#1329475 - Allow systemd to get status of systemd-logind daemon Resolves: rhbz#1356141 - Label more ndctl devices not just ndctl0 Resolves: rhbz#1355809- Allow rhsmcertd to copy certs into /etc/docker/cert.d - Add interface docker_rw_config() Resolves: rhbz#1344500 - Fix logrotate fc file to label also /var/lib/logrotate/ dir as logrotate_var_lib_t Resolves: rhbz#1355632 - Allow rhsmcertd to read network sysctls Resolves: rhbz#1329475 - Label /var/log/graphite-web dir as httpd_log_t Resolves: rhbz#1310898 - Allow mock to use generic ptys Resolves: rhbz#1271209 - Allow adcli running as sssd_t to write krb5.keytab file. Resolves: rhbz#1356082 - Allow openvswitch connect to openvswitch_port_t type. Resolves: rhbz#1335024 - Add SELinux policy for opendnssec service. Resolves: rhbz#1350957 - Create new SELinux type for /usr/libexec/ipa/ipa-dnskeysyncd Resolves: rhbz#1350957 - label /dev/ndctl0 device as nvram_device_t Resolves: rhbz#1355809- Allow lttng tools to block suspending Resolves: rhbz#1256374 - Allow creation of vpnaas in openstack Resolves: rhbz#1352710 - virt: add strict policy for virtlogd daemon Resolves:rhbz#1311606 - Update makefile to support snapperd_contexts file Resolves: rhbz#1352681- Allow udev to manage systemd-hwdb files - Add interface systemd_hwdb_manage_config() Resolves: rhbz#1350756 - Fix paths to infiniband devices. This allows use more then two infiniband interfaces. Resolves: rhbz#1210263- Allow virtual machines to rw infiniband devices. Resolves: rhbz#1210263 - Allow opensm daemon to rw infiniband_mgmt_device_t Resolves: rhbz#1210263 - Allow systemd_hwdb_t to relabel /etc/udev/hwdb.bin file. Resolves: rhbz#1350756 - Make label for new infiniband_mgmt deivices Resolves: rhbz#1210263- Fix typo in brltty SELinux module - Add new SELinux module sbd Resolves: rhbz#1322725 - Allow pcp dmcache metrics collection Resolves: rhbz#1309883 - Allow pkcs_slotd_t to create dir in /var/lock Add label pkcs_slotd_log_t Resolves: rhbz#1350782 - Allow openvpn to create sock files labeled as openvpn_var_run_t Resolves: rhbz#1328246 - Allow hypervkvp daemon to getattr on all filesystem types. Resolves: rhbz#1349356 - Allow firewalld to create net_conf_t files Resolves: rhbz#1304723 - Allow mock to use lvm Resolves: rhbz#1271209 - Allow keepalived to create netlink generic sockets. Resolves: rhbz#1349809 - Allow mirromanager creating log files in /tmp Resolves:rhbz#1328818 - Rename few modules to make it consistent with source files Resolves: rhbz#1351445 - Allow vmtools_t to transition to rpm_script domain Resolves: rhbz#1342119 - Allow nsd daemon to manage nsd_conf_t dirs and files Resolves: rhbz#1349791 - Allow cluster to create dirs in /var/run labeled as cluster_var_run_t Resolves: rhbz#1346900 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535 - Dontaudit su_role_template interface to getattr /proc/kcore Dontaudit su_role_template interface to getattr /dev/initctl Resolves: rhbz#1086240 - Add interface lvm_getattr_exec_files() Resolves: rhbz#1271209 - Fix typo Compliling vs. Compiling Resolves: rhbz#1351445- Allow krb5kdc_t to communicate with sssd Resolves: rhbz#1319933 - Allow prosody to bind on prosody ports Resolves: rhbz#1304664 - Add dac_override caps for fail2ban-client Resolves: rhbz#1316678 - dontaudit read access for svirt_t on the file /var/db/nscd/group Resolves: rhbz#1301637 - Allow inetd child process to communicate via dbus with systemd-logind Resolves: rhbz#1333726 - Add label for brltty log file Resolves: rhbz#1328818 - Allow dspam to read the passwd file Resolves: rhbz#1286020 - Allow snort_t to communicate with sssd Resolves: rhbz#1284908 - svirt_sandbox_domains need to be able to execmod for badly built libraries. Resolves: rhbz#1206339 - Add policy for lttng-tools package. Resolves: rhbz#1256374 - Make mirrormanager as application domain. Resolves: rhbz#1328234 - Add support for the default lttng-sessiond port - tcp/5345. This port is used by LTTng 2.x central tracing registry session daemon. - Add prosody ports Resolves: rhbz#1304664 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535- Label /var/lib/softhsm as named_cache_t. Allow named_t to manage named_cache_t dirs. Resolves:rhbz#1331315 - Label named-pkcs11 binary as named_exec_t. Resolves: rhbz#1331315 - Allow glusterd daemon to get systemd status Resolves: rhbz#1321785 - Allow logrotate dbus-chat with system_logind daemon Resolves: rhbz#1283134 - Allow pcp_pmlogger to read kernel network state Allow pcp_pmcd to read cron pid files Resolves: rhbz#1336211 - Add interface cron_read_pid_files() Resolves: rhbz#1336211 - Allow pcp_pmlogger to create unix dgram sockets Resolves: rhbz#1336211 - Add hwloc-dump-hwdata SELinux policy Resolves: rhbz#1344054 - Remove non-existing jabberd_spool_t() interface and add new jabbertd_var_spool_t. Resolves: rhbz#1121171 - Remove non-existing interface salk_resetd_systemctl() and replace it with sanlock_systemctl_sanlk_resetd() Resolves: rhbz#1259764 - Create label for openhpid log files. esolves: rhbz#1259764 - Label /var/lib/ganglia as httpd_var_lib_t Resolves: rhbz#1260536 - Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Include patch from distgit repo: policy-RHEL-7.1-flask.patch. Resolves: rhbz#1329560 - Update refpolicy to handle hwloc Resolves: rhbz#1344054 - Label /etc/dhcp/scripts dir as bin_t - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255- Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Allow mongod log to syslog. Resolves: rhbz#1306995 - Allow rhsmcertd connect to port tcp 9090 Resolves: rhbz#1337319 - Label for /bin/mail(x) was removed but /usr/bin/mail(x) not. This path is also needed to remove. Resolves: rhbz#1262483 Resolves: rhbz#1277506 - Label /usr/libexec/mimedefang-wrapper as spamd_exec_t. Resolves: rhbz#1301516 - Add new boolean spamd_update_can_network. Resolves: rhbz#1305469 - Allow rhsmcertd connect to tcp netport_port_t Resolves: rhbz#1329475 - Fix SELinux context for /usr/share/mirrormanager/server/mirrormanager to Label all binaries under dir as mirrormanager_exec_t. Resolves: rhbz#1328234 - Allow prosody to bind to fac_restore tcp port. Resolves: rhbz#1321787 - Allow ninfod to read raw packets Resolves: rhbz#1317964 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1260835 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1271159 - Allow tuned to use policykit. This change is required by cockpit. Resolves: rhbz#1346464 - Allow conman_t to read dir with conman_unconfined_script_t binary files. Resolves: rhbz#1297323 - Allow pegasus to read /proc/sysinfo. Resolves: rhbz#1265883 - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255 - Label tcp ports:16379, 26379 as redis_port_t Resolves: rhbz#1348471 - Allow systemd to relabel /var and /var/lib directories during boot. - Add files_relabel_var_dirs() and files_relabel_var_dirs() interfaces. - Add files_relabelto_var_lib_dirs() interface. - Label tcp port 2004 as mailbox_port_t. Resolves: rhbz#1332843 - Label tcp and udp port 5582 as fac_restore_port_t Resolves: rhbz#1321787 - Allow sysadm_t user to run postgresql-setup. Resolves: rhbz#1282543 - Allow sysadm_t user to dbus chat with oddjob_t. This allows confined admin run oddjob mkhomedirfor script. Resolves: rhbz#1297480 - Update netlink socket classes.- Allow conman to kill conman_unconfined_script. Resolves: rhbz#1297323 - Make conman_unconfined_script_t as init_system_domain. Resolves:rhbz#1297323 - Allow init dbus chat with apmd. Resolves:rhbz#995898 - Patch /var/lib/rpm is symlink to /usr/share/rpm on Atomic, due to this change we need to label also /usr/share/rpm as rpm_var_lib_t. Resolves: rhbz#1233252 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Add mediawiki rules to proper scope Resolves: rhbz#1301186 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Allow mysqld_safe to inherit rlimit information from mysqld Resolves: rhbz#1323673 - Allow collectd_t to stream connect to postgresql. Resolves: rhbz#1344056 - Allow mediawiki-script to read /etc/passwd file. Resolves: rhbz#1301186 - Add filetrans rule that NetworkManager_t can create net_conf_t files in /etc. Resolves: rhbz#1344505 - Add labels for mediawiki123 Resolves: rhbz#1293872 - Fix label for all fence_scsi_check scripts - Allow ip netns to mounton root fs and unmount proc_t fs. Resolves: rhbz#1343776 Resolves: rhbz#1286851 - Allow sysadm_t to run newaliases command. Resolves: rhbz#1344828 - Add interface sysnet_filetrans_named_net_conf() Resolves: rhbz#1344505- Fix several issues related to the SELinux Userspace changes- Allow glusterd domain read krb5_keytab_t files. Resolves: rhbz#1343929 - Fix typo in files_setattr_non_security_dirs. Resolves: rhbz#1115987- Allow tmpreaper_t to read/setattr all non_security_file_type dirs Resolves: rhbz#1115987 - Allow firewalld to create firewalld_var_run_t directory. Resolves: rhbz#1304723 - Add interface firewalld_read_pid_files() Resolves: rhbz#1304723 - Label /usr/libexec/rpm-ostreed as rpm_exec_t. Resolves: rhbz#1340542 - Allow sanlock service to read/write cephfs_t files. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - Add interface files_setattr_non_security_dirs() Resolves: rhbz#1115987 - Add support for onloadfs - Allow iptables to read firewalld pid files. Resolves: rhbz#1304723 - Add SELinux support for ceph filesystem. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) Resolves: rhbz#1236580- Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - New interfaces needed for systemd-machinectl Resolves: rhbz#1236580 - New interfaces needed by systemd-machine Resolves: rhbz#1236580 - Add interface allowing sending and receiving messages from virt over dbus. Resolves: rhbz#1236580 - Backport docker policy from Fedora. Related: #1303123 Resolves: #1341257 - Allow NetworkManager_t and policykit_t read access to systemd-machined pid files. Resolves: rhbz#1236580 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added interfaces needed by new docker policy. Related: rhbz#1303123 - Add support for systemd-machined daemon Resolves: rhbz#1236580 - Allow rpm-ostree domain transition to install_t domain from init_t. Resolves: rhbz#1340542- dnsmasq: allow NetworkManager to control dnsmasq via D-Bus Resolves: rhbz#1336722 - Directory Server (389-ds-base) has been updated to use systemd-ask-password. In order to function correctly we need the following added to dirsrv.te Resolves: rhbz#1333198 - sftpd_* booleans are functionless these days. Resolves: rhbz#1335656 - Label /var/log/ganesha.log as gluster_log_t Allow glusterd_t domain to create glusterd_log_t files. Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737 - Label /usr/libexec/storaged/storaged as lvm_exec_t to run storaged daemon in lvm_t SELinux domain. Resolves: rhbz#1264390 - Allow systemd_hostanmed_t to read /proc/sysinfo labeled as sysctl_t. Resolves: rhbz#1337061 - Revert "Allow all domains some process flags." Resolves: rhbz#1303644 - Revert "Remove setrlimit to all domains." Resolves: rhbz#1303644 - Label /usr/sbin/xrdp* files as bin_t Resolves: rhbz#1276777 - Add mls support for some db classes Resolves: rhbz#1303651 - Allow systemd_resolved_t to check if ipv6 is disabled. Resolves: rhbz#1236579 - Allow systemd_resolved to read systemd_networkd run files. Resolves: rhbz#1236579- Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737- Allow logwatch to domtrans to postqueue Resolves: rhbz#1331542 - Label /var/log/ganesha.log as gluster_log_t - Allow glusterd_t domain to create glusterd_log_t files. - Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow zabbix to connect to postgresql port Resolves: rhbz#1330479 - Add userdom_destroy_unpriv_user_shared_mem() interface. Related: rhbz#1306403 - systemd-logind remove all IPC objects owned by a user on a logout. This covers also SysV memory. This change allows to destroy unpriviledged user SysV shared memory segments. Resolves: rhbz#1306403- We need to restore contexts on /etc/passwd*,/etc/group*,/etc/*shadow* during install phase to get proper labeling for these files until selinux-policy pkgs are installed. Resolves: rhbz#1333952- Add interface glusterd_dontaudit_read_lib_dirs() Resolves: rhbz#1295680 - Dontaudit Occasionally observing AVC's while running geo-rep automation Resolves: rhbz#1295680 - Allow glusterd to manage socket files labeled as glusterd_brick_t. Resolves: rhbz#1331561 - Create new apache content template for files stored in user homedir. This change is needed to make working booleans: - httpd_enable_homedirs - httpd_read_user_content Resolves: rhbz#1246522 - Allow stunnel create log files. Resolves: rhbz#1296851 - Label tcp port 8181 as intermapper_port_t. Resolves: rhbz#1334783 - Label tcp/udp port 2024 as xinuexpansion4_port_t Resolves: rhbz#1334783 - Label tcp port 7002 as afs_pt_port_t Label tcp/udp port 2023 as xinuexpansion3_port_t Resolves: rhbz#1334783 - Dontaudit ldconfig read gluster lib files. Resolves: rhbz#1295680 - Add interface auth_use_nsswitch() to systemd_domain_template. Resolves: rhbz#1236579- Label /usr/bin/ganesha.nfsd as glusterd_exec_t to run ganesha as glusterd_t. Allow glusterd_t stream connect to rpbind_t. Allow cluster_t to create symlink /var/lib/nfs labeled as var_lib_nfs_t. Add interface rpc_filetrans_var_lib_nfs_content() Add new boolean: rpcd_use_fusefs to allow rpcd daemon use fusefs. Resolves: rhbz#1312809 Resolves: rhbz#1323947 - Allow dbus chat between httpd_t and oddjob_t. Resolves: rhbz#1324144 - Label /usr/libexec/ipa/oddjob/org.freeipa.server.conncheck as ipa_helper_exec_t. Resolves: rhbz#1324144 - Label /var/log/ipareplica-conncheck.log file as ipa_log_t Allow ipa_helper_t domain to manage logs labeledas ipa_log_t Allow ipa_helper_t to connect on http and kerberos_passwd ports. Resolves: rhbz#1324144 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow pcp_pmcd_t domain to manage docker lib files. This rule is needed to allow pcp to collect container information when SELinux is enabled. Resolves: rhbz#1309454- Allow runnig php7 in fpm mode. From selinux-policy side, we need to allow httpd to read/write hugetlbfs. Resolves: rhbz#1319442 - Allow openvswitch daemons to run under openvswitch Linux user instead of root. This change needs allow set capabilities: chwon, setgid, setuid, setpcap. Resolves: rhbz#1296640 - Remove ftpd_home_dir() boolean from distro policy. Reason is that we cannot make this working due to m4 macro language limits. Resolves: rhbz#1097775 - /bin/mailx is labeled sendmail_exec_t, and enters the sendmail_t domain on execution. If /usr/sbin/sendmail does not have its own domain to transition to, and is not one of several products whose behavior is allowed by the sendmail_t policy, execution will fail. In this case we need to label /bin/mailx as bin_t. Resolves: rhbz#1262483 - Allow nsd daemon to create log file in /var/log as nsd_log_t Resolves: rhbz#1293140 - Sanlock policy update. - New sub-domain for sanlk-reset daemon Resolves: rhbz#1212324 - Label all run tgtd files, not just socket files Resolves: rhbz#1280280 - Label all run tgtd files, not just socket files. Resolves: rhbz#1280280 - Allow prosody to stream connect to sasl. This will allow using cyrus authentication in prosody. Resolves: rhbz#1321049 - unbound wants to use ephemeral ports as a default configuration. Allow to use also udp sockets. Resolves: rhbz#1318224 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow targetd to read/write to /dev/mapper/control device. Resolves: rhbz#1063714 - Allow KDM to get status about power services. This change allow kdm to be able do shutdown. Resolves: rhbz#1316724 - Allow systemd-resolved daemon creating netlink_route sockets. Resolves:rhbz#1236579 - Allow systemd_resolved_t to read /etc/passwd file. Allow systemd_resolved_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used Resolves: rhbz#1065362 - Label /etc/selinux/(minimum|mls|targeted)/active/ as semanage_store_t Resolves: rhbz#1321943 - Label all nvidia binaries as xserver_exec_t Resolves: rhbz#1322283- Create new permissivedomains CIL module and make it active. Resolves: rhbz#1320451 - Add support for new mock location - /usr/libexec/mock/mock. Resolves: rhbz#1271209 - Allow bitlee to create bitlee_var_t dirs. Resolves: rhbz#1268651 - Allow CIM provider to read sssd public files. Resolves: rhbz#1263339 - Fix some broken interfaces in distro policy. Resolves: rhbz#1121171 - Allow power button to shutdown the laptop. Resolves: rhbz#995898 - Allow lsm plugins to create named fixed disks. Resolves: rhbz#1238066 - Add default labeling for /etc/Pegasus/cimserver_current.conf. It is a correct patch instead of the current /etc/Pegasus/pegasus_current.confResolves: rhbz#1278777 - Allow hyperv domains to rw hyperv devices. Resolves: rhbz#1309361 - Label /var/www/html(/.*)?/wp_backups(/.*)? as httpd_sys_rw_content_t.Resolves: rhbz#1246780 - Create conman_unconfined_script_t type for conman script stored in /use/share/conman/exec/ Resolves: rhbz#1297323 - Fix rule definitions for httpd_can_sendmail boolean. We need to distinguish between base and contrib. - Add support for /dev/mptctl device used to check RAID status. Resolves: rhbz#1258029 - Create hyperv* devices and create rw interfaces for this devices. Resolves: rhbz#1309361 - Add fixes for selinux userspace moving the policy store to /var/lib/selinux. - Remove optional else block for dhcp ping- Allow rsync_export_all_ro boolean to read also non_auth_dirs/files/symlinks. Resolves: rhbz#1263770 - Fix context of "/usr/share/nginx/html". Resolves: rhbz#1261857 - Allow pmdaapache labeled as pcp_pmcd_t access to port 80 for apache diagnostics Resolves: rhbz#1270344 - Allow pmlogger to create pmlogger.primary.socket link file. Resolves: rhbz#1270344 - Label nagios scripts as httpd_sys_script_exec_t. Resolves: rhbz#1260306 - Add dontaudit interface for kdumpctl_tmp_t Resolves: rhbz#1156442 - Allow mdadm read files in EFI partition. Resolves: rhbz#1291801 - Allow nsd_t to bind on nsf_control tcp port. Allow nsd_crond_t to read nsd pid. Resolves: rhbz#1293140 - Label some new nsd binaries as nsd_exec_t Allow nsd domain net_admin cap. Create label nsd_tmp_t for nsd tmp files/dirs Resolves: rhbz#1293140 - Add filename transition that /etc/princap will be created with cupsd_rw_etc_t label in cups_filetrans_named_content() interface. Resolves: rhbz#1265102 - Add missing labeling for /usr/libexec/abrt-hook-ccpp. Resolves: rhbz#1213409 - Allow pcp_pmie and pcp_pmlogger to read all domains state. Resolves: rhbz#1206525 - Label /etc/redis-sentinel.conf as redis_conf_t. Allow redis_t write to redis_conf_t. Allow redis_t to connect on redis tcp port. Resolves: rhbz#1275246 - cockpit has grown content in /var/run directory Resolves: rhbz#1279429 - Allow collectd setgid capability Resolves:#1310898 - Remove declaration of empty booleans in virt policy. Resolves: rhbz#1103153 - Fix typo in drbd policy - Add new drbd file type: drbd_var_run_t. Allow drbd_t to manage drbd_var_run_t files/dirs. Allow drbd_t create drbd_tmp_t files in /tmp. Resolves: rhbz#1134883 - Label /etc/ctdb/events.d/* as ctdb_exec_t. Allow ctdbd_t to setattr on ctdbd_exec_t files. Resolves: rhbz#1293788 - Allow abrt-hook-ccpp to get attributes of all processes because of core_pattern. Resolves: rhbz#1254188 - Allow abrt_t to read sysctl_net_t files. Resolves: rhbz#1254188 - The ABRT coredump handler has code to emulate default core file creation The handler runs in a separate process with abrt_dump_oops_t SELinux process type. abrt-hook-ccpp also saves the core dump file in the very same way as kernel does and a user can specify CWD location for a coredump. abrt-hook-ccpp has been made as a SELinux aware apps to create this coredumps with correct labeling and with this commit the policy rules have been updated to allow access all non security files on a system. - Allow abrt-hook-ccpp to getattr on all executables. - Allow setuid/setgid capabilities for abrt-hook-ccpp. Resolves: rhbz#1254188 - abrt-hook-ccpp needs to have setfscreate access because it is SELinux aware and compute a target labeling. Resolves: rhbz#1254188 - Allow abrt-hook-ccpp to change SELinux user identity for created objects. Resolves: rhbz#1254188 - Dontaudit write access to inherited kdumpctl tmp files. Resolves: rbhz#1156442 - Add interface to allow reading files in efivarfs - contains Linux Kernel configuration options for UEFI systems (UEFI Runtime Variables) Resolves: rhbz#1291801 - Label 8952 tcp port as nsd_control. Resolves: rhbz#1293140 - Allow ipsec to use pam. Resolves: rhbz#1315700 - Allow to log out to gdm after screen was resized in session via vdagent. Resolves: rhbz#1249020 - Allow setrans daemon to read /proc/meminfo. Resolves: rhbz#1316804 - Allow systemd_networkd_t to write kmsg, when kernel was started with following params: systemd.debug systemd.log_level=debug systemd.log_target=kmsg Resolves: rhbz#1298151 - Label tcp port 5355 as llmnr-> Link-Local Multicast Name Resolution Resolves: rhbz#1236579 - Add new selinux policy for systemd-resolved dawmon. Resolves: rhbz#1236579 - Add interface ssh_getattr_server_keys() interface. Resolves: rhbz#1306197 - Allow run sshd-keygen on second boot if first boot fails after some reason and content is not syncedon the disk. These changes are reflecting this commit in sshd. http://pkgs.fedoraproject.org/cgit/rpms/openssh.git/commit/?id=af94f46861844cbd6ba4162115039bebcc8f78ba rhbz#1299106 Resolves: rhbz#1306197 - Allow systemd_notify_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used. Resolves: rhbz#1309417 - Remove bin_t label for /etc/ctdb/events.d/. We need to label this scripts as ctdb_exec_t. Resolves: rhbz#1293788- Prepare selinux-policy package for userspace release 2016-02-23. Resolves: rhbz#1305982- Allow sending dbus msgs between firewalld and system_cronjob domains. Resolves: rhbz#1284902 - Allow zabbix-agentd to connect to following tcp sockets. One of zabbix-agentd functions is get service status of ftp,http,innd,pop,smtp protocols. Resolves: rhbz#1242506 - Add new boolean tmpreaper_use_cifs() to allow tmpreaper to run on local directories being shared with Samba. Resolves: rhbz#1284972 - Add support for systemd-hwdb daemon. Resolves: rhbz#1257940 - Add interface fs_setattr_cifs_dirs(). Resolves: rhbz#1284972- Add new SELinux policy fo targetd daemon. Resolves: rhbz#1063714 - Add new SELinux policy fo ipmievd daemon. Resolves: rhbz#1083031 - Add new SELinux policy fo hsqldb daemon. Resolves: rhbz#1083171 - Add new SELinux policy for blkmapd daemon. Resolves: rhbz#1072997 - Allow p11-child to connect to apache ports. - Label /usr/sbin/lvmlockd binary file as lvm_exec_t. Resolves: rhbz#1278028 - Add interface "lvm_manage_lock" to lvm policy. Resolves: rhbz#1063714- Allow openvswitch domain capability sys_rawio. Resolves: rhbz#1278495- Allow openvswitch to manage hugetlfs files and dirs. Resolves: rhbz#1278495 - Add fs_manage_hugetlbfs_files() interface. Resolves: rhbz#1278495- Allow smbcontrol domain to send sigchld to ctdbd domain. Resolves: #1293784 - Allow openvswitch read/write hugetlb filesystem. Resolves: #1278495Allow hypervvssd to list all mountpoints to have VSS live backup working correctly. Resolves:#1247880- Revert Add missing labeling for /usr/libexec/abrt-hook-ccpp patch Resolves: #1254188- Allow search dirs in sysfs types in kernel_read_security_state. Resolves: #1254188 - Fix kernel_read_security_state interface that source domain of this interface can search sysctl_fs_t dirs. Resolves: #1254188- Add missing labeling for /usr/libexec/abrt-hook-ccpp as a part of #1245477 and #1242467 bugs Resolves: #1254188 - We need allow connect to xserver for all sandbox_x domain because we have one type for all sandbox processes. Resolves:#1261938- Remove labeling for modules_dep_t file contexts to have labeled them as modules_object_t. - Update files_read_kernel_modules() to contain modutils_read_module_deps_files() calling because module deps labeling could remain and it allows to avoid regressions. Resolves:#1266928- We need to require sandbox_web_type attribute in sandbox_x_domain_template(). Resolves: #1261938 - ipsec: The NM helper needs to read the SAs Resolves: #1259786 - ipsec: Allow ipsec management to create ptys Resolves: #1259786- Add temporary fixes for sandbox related to #1103622. It allows to run everything under one sandbox type. Resolves:#1261938 - Allow abrt_t domain to write to kernel msg device. Resolves: #1257828 - Allow rpcbind_t domain to change file owner and group Resolves: #1265266- Allow smbcontrol to create a socket in /var/samba which uses for a communication with smbd, nmbd and winbind. Resolves: #1256459- Allow dirsrv-admin script to read passwd file. Allow dirsrv-admin script to read httpd pid files. Label dirsrv-admin unit file and allow dirsrv-admin domains to use it. Resolves: #1230300 - Allow qpid daemon to connect on amqp tcp port. Resolves: #1261805- Label /etc/ipa/nssdb dir as cert_t Resolves:#1262718 - Do not provide docker policy files which is shipped by docker-selinux.rpm Resolves:#1262812- Add labels for afs binaries: dafileserver, davolserver, salvageserver, dasalvager Resolves: #1192338 - Add lsmd_plugin_t sys_admin capability, Allow lsmd_plugin_t getattr from sysfs filesystem. Resolves: #1238079 - Allow rhsmcertd_t send signull to unconfined_service_t domains. Resolves: #1176078 - Remove file transition from snmp_manage_var_lib_dirs() interface which created snmp_var_lib_t dirs in var_lib_t. - Allow openhpid_t daemon to manage snmp files and dirs. Resolves: #1243902 - Allow mdadm_t domain read/write to general ptys and unallocated ttys. Resolves: #1073314 - Add interface unconfined_server_signull() to allow domains send signull to unconfined_service_t Resolves: #1176078- Allow systemd-udevd to access netlink_route_socket to change names for network interfaces without unconfined.pp module. It affects also MLS. Resolves:#1250456- Fix labeling for fence_scsi_check script Resolves: #1255020 - Allow openhpid to read system state Allow openhpid to connect to tcp http port. Resolves: #1244248 - Allow openhpid to read snmp var lib files. Resolves: #1243902 - Allow openvswitch_t domains read kernel dependencies due to openvswitch run modprobe - Allow unconfined_t domains to create /var/run/xtables.lock with iptables_var_run_t Resolves: #1243403 - Remove bin_t label for /usr/share/cluster/fence_scsi_check\.pl Resolves: #1255020- Fix regexp in chronyd.fc file Resolves: #1243764 - Allow passenger to getattr filesystem xattr Resolves: #1196555 - Label mdadm.conf.anackbak as mdadm_conf_t file. Resolves: #1088904 - Revert "Allow pegasus_openlmi_storage_t create mdadm.conf.anacbak file in /etc." - Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Remove labeling for /var/db/.*\.db as etc_t to label db files as system_db_t. Resolves: #1230877- Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Label /var/run/chrony-helper dir as chronyd_var_run_t. Resolves: #1243764 - Allow dhcpc_t domain transition to chronyd_t Resolves: #1243764- Fix postfix_spool_maildrop_t,postfix_spool_flush_t contexts in postfix.fc file. Resolves: #1252442- Allow exec pidof under hypervkvp domain. Resolves: #1254870 - Allow hypervkvp daemon create connection to the system DBUS Resolves: #1254870- Allow openhpid_t to read system state. Resolves: #1244248 - Added labels for files provided by rh-nginx18 collection Resolves: #1249945 - Dontaudit block_suspend capability for ipa_helper_t, this is kernel bug. Allow ipa_helper_t capability net_admin. Allow ipa_helper_t to list /tmp. Allow ipa_helper_t to read rpm db. Resolves: #1252968 - Allow rhsmcertd exec rhsmcertd_var_run_t files and rhsmcerd_tmp_t files. This rules are in hide_broken_sympthons until we find better solution. Resolves: #1243431 - Allow abrt_dump_oops_t to read proc_security_t files. - Allow abrt_dump_oops to signull all domains Allow abrt_dump_oops to read all domains state Allow abrt_dump_oops to ptrace all domains - Add interface abrt_dump_oops_domtrans() - Add mountpoint dontaudit access check in rhsmcertd policy. Resolves: #1243431 - Allow samba_net_t to manage samba_var_t sock files. Resolves: #1252937 - Allow chrome setcap to itself. Resolves: #1251996 - Allow httpd daemon to manage httpd_var_lib_t lnk_files. Resolves: #1253706 - Allow chronyd exec systemctl Resolves: #1243764 - Add inteface chronyd_signal Allow timemaster_t send generic signals to chronyd_t. Resolves: #1243764 - Added interface fs_dontaudit_write_configfs_dirs - Add label for kernel module dep files in /usr/lib/modules Resolves:#916635 - Allow kernel_t domtrans to abrt_dump_oops_t - Added to files_dontaudit_write_all_mountpoints intefface new dontaudit rule, that domain included this interface dontaudit capability dac_override. - Allow systemd-networkd to send logs to systemd-journald. Resolves: #1236616- Fix label on /var/tmp/kiprop_0 Resolves:#1220763 - Allow lldpad_t to getattr tmpfs_t. Resolves: #1246220 - Label /dev/shm/lldpad.* as lldapd_tmpfs_t Resolves: #1246220 - Allow audisp client to read system state.- Allow pcp_domain to manage pcp_var_lib_t lnk_files. Resolves: #1252341 - Label /var/run/xtables.* as iptables_var_run_t Resolves: #1243403- Add interface to read/write watchdog device - Add labels for /dev/memory_bandwith and /dev/vhci. Thanks ssekidde Resolves:#1210237 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow logrotate to reload services. Resolves: #1242453 - Allow openhpid use libwatchdog plugin. (Allow openhpid_t rw watchdog device) Resolves: #1244260 - Allow openhpid liboa_soap plugin to read generic certs. Resolves: #1244248 - Allow openhpid liboa_soap plugin to read resolv.conf file. Resolves: #1244248 - Label /usr/libexec/chrony-helper as chronyd_exec_t - Allow chronyd_t to read dhcpc state. - Allow chronyd to execute mkdir command.- Allow mdadm to access /dev/random and add support to create own files/dirs as mdadm_tmpfs_t. Resolves:#1073314 - Allow udev, lvm and fsadm to access systemd-cat in /var/tmp/dracut if 'dracut -fv' is executed in MLS. - Allow admin SELinu users to communicate with kernel_t. It is needed to access /run/systemd/journal/stdout if 'dracut -vf' is executed. We allow it for other SELinux users. - Allow sysadm to execute systemd-sysctl in the sysadm_t domain. It is needed for ifup command in MLS mode. - Add fstools_filetrans_named_content_fsadm() and call it for named_filetrans_domain domains. We need to be sure that /run/blkid is created with correct labeling. Resolves:#1183503 - Add support for /etc/sanlock which is writable by sanlock daemon. Resolves:#1231377 - Allow useradd add homedir located in /var/lib/kdcproxy in ipa-server RPM scriplet. Resolves:#1243775 - Allow snapperd to pass data (one way only) via pipe negotiated over dbus Resolves:#1250550 - Allow lsmd also setuid capability. Some commands need to executed under root privs. Other commands are executed under unprivileged user.- Allow openhpid to use libsnmp_bc plugin (allow read snmp lib files). Resolves: #1243902 - Allow lsm_plugin_t to read sysfs, read hwdata, rw to scsi_generic_device Resolves: #1238079 - Allow lsm_plugin_t to rw raw_fixed_disk. Resolves:#1238079 - Allow rhsmcertd to send signull to unconfined_service.- Allow httpd_suexec_t to read and write Apache stream sockets Resolves: #1243569 - Allow qpid to create lnk_files in qpid_var_lib_t Resolves: #1247279- Allow drbd to get attributes from filesystems. - Allow redis to read kernel parameters. Resolves: #1209518 - Allow virt_qemu_ga_t domtrans to passwd_t - Allow audisp_remote_t to start power unit files domain to allow halt system. Resolves: #1186780 - Allow audisp_remote_t to read/write user domain pty. Resolves: #1186780 - Label /usr/sbin/chpasswd as passwd_exec_t. - Allow sysadm to administrate ldap environment and allow to bind ldap port to allow to setup an LDAP server (389ds). Resolves:#1221121- gnome_dontaudit_search_config() needs to be a part of optinal_policy in pegasus.te - Allow pcp_pmcd daemon to read postfix config files. - Allow pcp_pmcd daemon to search postfix spool dirs. Resolves: #1213740 - Added Booleans: pcp_read_generic_logs. Resolves: #1213740 - Allow drbd to read configuration options used when loading modules. Resolves: #1134883 - Allow glusterd to manage nfsd and rpcd services. - Allow glusterd to communicate with cluster domains over stream socket. - glusterd call pcs utility which calls find for cib.* files and runs pstree under glusterd. Dontaudit access to security files and update gluster boolean to reflect these changes.- Allow glusterd to manage nfsd and rpcd services. - Allow networkmanager to communicate via dbus with systemd_hostanmed. Resolves: #1234954 - Allow stream connect logrotate to prosody. - Add prosody_stream_connect() interface. - httpd should be able to send signal/signull to httpd_suexec_t, instead of httpd_suexec_exec_t. - Allow prosody to create own tmp files/dirs. Resolves:#1212498- Allow networkmanager read rfcomm port. Resolves:#1212498 - Remove non exists label. - Fix *_admin intefaces where body is not consistent with header. - Label /usr/afs/ as afs_files_t, Allow afs_bosserver_t create afs_config_t and afs_dbdir_t dirs under afs_files_t, Allow afs_bosserver_t read kerberos config - Remove non exits nfsd_ro_t label. - Make all interfaces related to openshift_cache_t as deprecated. - Add rpm_var_run_t label to rpm_admin header - Add jabberd_lock_t label to jabberd_admin header. - Add samba_unconfined_script_exec_t to samba_admin header. - inn daemon should create innd_log_t objects in var_log_t instead of innd_var_run_t - Fix ctdb policy - Add samba_signull_winbind() - Add samba_signull_unconfined_net() - Allow ctdbd_t send signull to samba_unconfined_net_t. - Allow openshift_initrc_t to communicate with firewalld over dbus Resolves:#1221326- Allow gluster to connect to all ports. It is required by random services executed by gluster. - Add interfaces winbind_signull(), samba_unconfined_net_signull(). - Dontaudit smbd_t block_suspend capability. This is kernel bug. - Allow ctdbd sending signull to process winbind, samba_unconfined_net, to checking if processes exists. - Add tmpreaper booleans to use nfs_t and samba_share_t. - Fix path from /usr/sbin/redis-server to /usr/bin/redis-server - Allow connect ypserv to portmap_port_t - Fix paths in inn policy, Allow innd read innd_log_t dirs, Allow innd execute innd_etc_t files - Add support for openstack-nova-* packages - Allow NetworkManager_t send signull to dnssec_trigger_t. - Allow glusterd to execute showmount in the showmount domain. - Label swift-container-reconciler binary as swift_t. - Allow dnssec_trigger_t relabelfrom dnssec_trigger_var_run_t files. - Add cobbler_var_lib_t to "/var/lib/tftpboot/boot(/.*)?" Resolves:#1213540 - Merge all nova_* labels under one nova_t.- Add logging_syslogd_run_nagios_plugins boolean for rsyslog to allow transition to nagios unconfined plugins Resolves:#1233550 - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/ - Add support for oddjob based helper in FreeIPA. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add nagios_domtrans_unconfined_plugins() interface. - Update mta_filetrans_named_content() interface to cover more db files. Resolves:#1167468 - Add back ftpd_use_passive_mode boolean with fixed description. - Allow pmcd daemon stream connect to mysqld. - Allow pcp domains to connect to own process using unix_stream_socket. Resolves:#1213709 - Allow abrt-upload-watch service to dbus chat with ABRT daemon and fsetid capability to allow run reporter-upload correctly. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add support for oddjob based helper in FreeIPA. - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/- Allow iptables to read ctdbd lib files. Resolves:#1224879 - Add systemd_networkd_t to nsswitch domains. - Allow drbd_t write to fixed_disk_device. Reason: drbdmeta needs write to fixed_disk_device during initialization. Resolves:#1130675 - Allow NetworkManager write to sysfs. - Fix cron_system_cronjob_use_shares boolean to call fs interfaces which contain only entrypoint permission. - Add cron_system_cronjob_use_shares boolean to allow system cronjob to be executed from shares - NFS, CIFS, FUSE. It requires "entrypoint" permissios on nfs_t, cifs_t and fusefs_t SELinux types. - Allow NetworkManager write to sysfs. - Allow ctdb_t sending signull to smbd_t, for checking if smbd process exists. - Dontaudit apache to manage snmpd_var_lib_t files/dirs. - Add interface snmp_dontaudit_manage_snmp_var_lib_files(). - Dontaudit mozilla_plugin_t cap. sys_ptrace. - Rename xodbc-connect port to xodbc_connect - Allow ovsdb-server to connect on xodbc-connect and ovsdb tcp ports. - Allow iscsid write to fifo file kdumpctl_tmp_t. Appears when kdump generates the initramfs during the kernel boot. - Dontaudit chrome to read passwd file. - nrpe needs kill capability to make gluster moniterd nodes working. Resolves:#1235587- We allow can_exec() on ssh_keygen on gluster. But there is a transition defined by init_initrc_domain() because we need to allow execute unconfined services by glusterd. So ssh-keygen ends up with ssh_keygen_t and we need to allow to manage /var/lib/glusterd/geo-replication/secret.pem. - Allow sshd to execute gnome-keyring if there is configured pam_gnome_keyring.so. - Allow gnome-keyring executed by passwd to access /run/user/UID/keyring to change a password. - Label gluster python hooks also as bin_t. - Allow glusterd to interact with gluster tools running in a user domain - Add glusterd_manage_lib_files() interface. - ntop reads /var/lib/ntop/macPrefix.db and it needs dac_override. It has setuid/setgid. - Allow samba_t net_admin capability to make CIFS mount working. - S30samba-start gluster hooks wants to search audit logs. Dontaudit it. Resolves:#1224879- Allow glusterd to send generic signals to systemd_passwd_agent processes. - Allow glusterd to access init scripts/units without defined policy - Allow glusterd to run init scripts. - Allow glusterd to execute /usr/sbin/xfs_dbin glusterd_t domain. Resolves:#1224879- Calling cron_system_entry() in pcp_domain_template needs to be a part of optional_policy block. - Allow samba-net to access /var/lib/ctdbd dirs/files. - Allow glusterd to send a signal to smbd. - Make ctdbd as home manager to access also FUSE. - Allow glusterd to use geo-replication gluster tool. - Allow glusterd to execute ssh-keygen. - Allow glusterd to interact with cluster services. - Allow glusterd to connect to the system DBUS for service (acquire_svc). - Label /dev/log correctly. Resolves:#1230932- Back port the latest F22 changes to RHEL7. It should fix most of RHEL7.2 bugs - Add cgdcbxd policy Resolves:#1072493 - Fix ftp_homedir boolean Resolve:#1097775 - Dontaudit ifconfig writing inhertited /var/log/pluto.log. - Allow cluster domain to dbus chat with systemd-logind. Resolves:#1145215 - Dontaudit write access to inherited kdumpctl tmp files Resolves:#1156442 - Allow isnsd_t to communicate with sssd Resolves:#1167702 - Allow rwho_t to communicate with sssd Resolves:#1167718 - Allow sblim_gatherd_t to communicate with sssd Resolves:#1167732 - Allow pkcs_slotd_t to communicate with sssd Resolves:#1167737 - Allow openvswitch_t to communicate with sssd Resolves:#1167816 - Allow mysqld_safe_t to communicate with sssd Resolves:#1167832 - Allow sshd_keygen_t to communicate with sssd Resolves:#1167840 - Add support for iprdbg logging files in /var/log. Resolves:#1174363 - Allow tmpreaper_t to manage ntp log content Resolves:#1176965 - Allow gssd_t to manage ssh keyring Resolves:#1184791 - Allow httpd_sys_script_t to send system log messages Resolves:#1185231 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow dovecot_t sys_resource capability Resolves:#1191143 - Add support for mongod/mongos systemd unit files. Resolves:#1197038 - Add bacula fixes - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. Resolves:#1203991- Label /usr/libexec/postgresql-ctl as postgresql_exec_t. - Add more restriction on entrypoint for unconfined domains. - Only allow semanage_t to be able to setenforce 0, no all domains that use selinux_semanage interface - Allow all domains to read /dev/urandom. It is needed by all apps/services linked to libgcrypt. There is no harm to allow it by default. - Update policy/mls for sockets related to access perm. Rules were contradictory. - Add nagios_run_pnp4nagios and nagios_run_sudo booleans to allow r un sudo from NRPE utils scripts and allow run nagios in conjunction w ith PNP4Nagios. Resolves:#1201054 - Don't use deprecated userdom_manage_tmpfs_role() interface calliing and use userdom_manage_tmp_role() instead. - Update virt_read_pid_files() interface to allow read also symlinks with virt_var_run_t type - Label /var/lib/tftpboot/aarch64(/.*)? and /var/lib/tftpboot/images2(/.*)? - Add support for iprdbg logging files in /var/log. - Add fixes to rhsmcertd_t - Allow puppetagent_t to transfer firewalld messages over dbus - Add support for /usr/libexec/mongodb-scl-helper RHSCL helper script. - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. - Add support for mongod/mongos systemd unit files. - cloudinit and rhsmcertd need to communicate with dbus - Allow dovecot_t sys_resource capability- ALlow mongod execmem by default. - Update policy/mls for sockets. Rules were contradictory. Resolves:#1207133 - Allow a user to login with different security level via ssh.- Update seutil_manage_config() interface. Resolves:#1185962 - Allow pki-tomcat relabel pki_tomcat_etc_rw_t. - Turn on docker_transition_unconfined by default- Allow virtd to list all mountpoints. Resolves:#1180713- pkcsslotd_lock_t should be an alias for pkcs_slotd_lock_t. - Allow fowner capability for sssd because of selinux_child handling. - ALlow bind to read/write inherited ipsec pipes - Allow hypervkvp to read /dev/urandom and read addition states/config files. - Allow gluster rpm scripletto create glusterd socket with correct labeling. This is a workaround until we get fix in glusterd. - Add glusterd_filetrans_named_pid() interface - Allow radiusd to connect to radsec ports. - Allow setuid/setgid for selinux_child - Allow lsmd plugin to connect to tcp/5988 by default. - Allow lsmd plugin to connect to tcp/5989 by default. - Update ipsec_manage_pid() interface. Resolves:#1184978- Update ipsec_manage_pid() interface. Resolves:#1184978- Allow ntlm_auth running in winbind_helper_t to access /dev/urandom.- Add auditing support for ipsec. Resolves:#1182524 - Label /ostree/deploy/rhel-atomic-host/deploy directory as system_conf_t - Allow netutils chown capability to make tcpdump working with -w- Allow ipsec to execute _updown.netkey script to run unbound-control. - Allow neutron to read rpm DB. - Add additional fixes for hyperkvp * creates new ifcfg-{name} file * Runs hv_set_ifconfig.sh, which does the following * Copies ifcfg-{name} to /etc/sysconfig/network-scripts - Allow svirt to read symbolic links in /sys/fs/cgroups labeled as tmpfs_t - Add labeling for pacemaker.log. - Allow radius to connect/bind radsec ports. - Allow pm-suspend running as virt_qemu_ga to read /var/log/pm-suspend.log - Allow virt_qemu_ga to dbus chat with rpm. - Update virt_read_content() interface to allow read also char devices. - Allow glance-registry to connect to keystone port. Resolves:#1181818- Allow sssd to send dbus all user domains. Resolves:#1172291 - Allow lsm plugin to read certificates. - Fix labeling for keystone CGI scripts. - Make snapperd back as unconfined domain.- Fix bugs in interfaces discovered by sepolicy. - Allow slapd to read /usr/share/cracklib/pw_dict.hwm. - Allow lsm plugins to connect to tcp/18700 by default. - Allow brltty mknod capability to allow create /var/run/brltty/vcsa. - Fix pcp_domain_template() interface. - Fix conman.te. - Allow mon_fsstatd to read /proc/sys/fs/binfmt_misc - Allow glance-scrubber to connect tcp/9191. - Add missing setuid capability for sblim-sfcbd. - Allow pegasus ioctl() on providers. - Add conman_can_network. - Allow chronyd to read chrony conf files located in /run/timemaster/. - Allow radius to bind on tcp/1813 port. - dontaudit block suspend access for openvpn_t - Allow conman to create files/dirs in /tmp. - Update xserver_rw_xdm_keys() interface to have 'setattr'. Resolves:#1172291 - Allow sulogin to read /dev/urandom and /dev/random. - Update radius port definition to have also tcp/18121 - Label prandom as random_device_t. - Allow charon to manage files in /etc/strongimcv labeled as ipsec_conf_t.- Allow virt_qemu_ga_t to execute kmod. - Add missing files_dontaudit_list_security_dirs() for smbd_t in samba_export_all_ro boolean. - Add additionnal MLS attribute for oddjob_mkhomedir to create homedirs. Resolves:#1113725 - Enable OpenStack cinder policy - Add support for /usr/share/vdsm/daemonAdapter - Add support for /var/run/gluster- Remove old pkcsslotd.pp from minimum package - Allow rlogind to use also rlogin ports. - Add support for /usr/libexec/ntpdate-wrapper. Label it as ntpdate_exec_t. - Allow bacula to connect also to postgresql. - Label /usr/libexec/tomcat/server as tomcat_exec_t - Add support for /usr/sbin/ctdbd_wrapper - Add support for /usr/libexec/ppc64-diag/rtas_errd - Allow rpm_script_roles to access system_mail_t - Allow brltty to create /var/run/brltty - Allow lsmd plugin to access netlink_route_socket - Allow smbcontrol to read passwd - Add support for /usr/libexec/sssd/selinux_child and create sssd_selinux_manager_t domain for it Resolves:#1140106 - Allow osad to execute rhn_check - Allow load_policy to rw inherited sssd pipes because of selinux_child - Allow admin SELinux users mounting / as private within a new mount namespace as root in MLS - Add additional fixes for su_restricted_domain_template to make moving to sysadm_r and trying to su working correctly - Add additional booleans substitions- Add seutil_dontaudit_access_check_semanage_module_store() interface Resolves:#1140106 - Update to have all _systemctl() interface also init_reload_services(). - Dontaudit access check on SELinux module store for sssd. - Add labeling for /sbin/iw. - Allow named_filetrans_domain to create ibus directory with correct labeling.- Allow radius to bind tcp/1812 radius port. - Dontaudit list user_tmp files for system_mail_t. - Label virt-who as virtd_exec_t. - Allow rhsmcertd to send a null signal to virt-who running as virtd_t. - Add missing alias for _content_rw_t. Resolves:#1089177 - Allow spamd to access razor-agent.log. - Add fixes for sfcb from libvirt-cim TestOnly bug. - Allow NetworkManager stream connect on openvpn. - Make /usr/bin/vncserver running as unconfined_service_t. - getty_t should be ranged in MLS. Then also local_login_t runs as ranged domain. - Label /etc/docker/certs.d as cert_t.- Label /etc/strongimcv as ipsec_conf_file_t. - Add support for /usr/bin/start-puppet-ca helper script Resolves:#1160727 - Allow rpm scripts to enable/disable transient systemd units. Resolves:#1154613 - Make kpropdas nsswitch domain Resolves:#1153561 - Make all glance domain as nsswitch domains Resolves:#1113281 - Allow selinux_child running as sssd access check on /etc/selinux/targeted/modules/active - Allow access checks on setfiles/load_policy/semanage_lock for selinux_child running as sssd_t Resolves:#1140106- Dontaudit access check on setfiles/load_policy for sssd_t. Resolves:#1140106 - Add kdump_rw_inherited_kdumpctl_tmp_pipes() Resolves:#1156442 - Make linuxptp services as unconfined. - Added new policy linuxptp. Resolves:#1149693 - Label keystone cgi files as keystone_cgi_script_exec_t. Resolves:#1138424 - Make tuned as unconfined domain- Allow guest to connect to libvirt using unix_stream_socket. - Allow all bus client domains to dbus chat with unconfined_service_t. - Allow inetd service without own policy to run in inetd_child_t which is unconfined domain. - Make opensm as nsswitch domain to make it working with sssd. - Allow brctl to read meminfo. - Allow winbind-helper to execute ntlm_auth in the caller domain. Resolves:#1160339 - Make plymouthd as nsswitch domain to make it working with sssd. Resolves:#1160196 - Make drbd as nsswitch domain to make it working with sssd. - Make conman as nsswitch domain to make ipmitool.exp runing as conman_t working. - Add support for /var/lib/sntp directory. - Add fixes to allow docker to create more content in tmpfs ,and donaudit reading /proc - Allow winbind to read usermodehelper - Allow telepathy domains to execute shells and bin_t - Allow gpgdomains to create netlink_kobject_uevent_sockets - Allow mongodb to bind to the mongo port and mongos to run as mongod_t - Allow abrt to read software raid state. - Allow nslcd to execute netstat. - Allow dovecot to create user's home directory when they log into IMAP. - Allow login domains to create kernel keyring with different level.- Allow modemmanger to connectto itself Resolves:#1120152 - Allow pki_tomcat to create link files in /var/lib/pki-ca. Resolves:#1121744 - varnishd needs to have fsetid capability Resolves:#1125165 - Allow snapperd to dbus chat with system cron jobs. Resolves:#1152447 - Allow dovecot to create user's home directory when they log into IMAP Resolves:#1152773 - Add labeling for /usr/sbin/haproxy-systemd-wrapper wrapper to make haproxy running haproxy_t. - ALlow listen and accept on tcp socket for init_t in MLS. Previously it was for xinetd_t. - Allow nslcd to execute netstat. - Add suppor for keepalived unconfined scripts and allow keepalived to read all domain state and kill capability. - Allow nslcd to read /dev/urandom.- Add back kill permisiion for system class Resolves:#1150011- Add back kill permisiion for service class Resolves:#1150011 - Make rhsmcertd_t also as dbus domain. - Allow named to create DNS_25 with correct labeling. - Add cloudform_dontaudit_write_cloud_log() - Call auth_use_nsswitch to apache to read/write cloud-init keys. - Allow cloud-init to dbus chat with certmonger. - Fix path to mon_statd_initrc_t script. - Allow all RHCS services to read system state. - Allow dnssec_trigger_t to execute unbound-control in own domain. - kernel_read_system_state needs to be called with type. Moved it to antivirus.if. - Added policy for mon_statd and mon_procd services. BZ (1077821) - Allow opensm_t to read/write /dev/infiniband/umad1. - Allow mongodb to manage own log files. - Allow neutron connections to system dbus. - Add support for /var/lib/swiftdirectory. - Allow nova-scheduler to read certs. - Allow openvpn to access /sys/fs/cgroup dir. - Allow openvpn to execute systemd-passwd-agent in systemd_passwd_agent_t to make openvpn working with systemd. - Fix samba_export_all_ro/samba_export_all_rw booleans to dontaudit search/read security files. - Add auth_use_nsswitch for portreserve to make it working with sssd. - automount policy is non-base module so it needs to be called in optional block. - ALlow sensord to getattr on sysfs. - Label /usr/share/corosync/corosync as cluster_exec_t. - Allow lmsd_plugin to read passwd file. BZ(1093733) - Allow read antivirus domain all kernel sysctls. - Allow mandb to getattr on file systems - Allow nova-console to connect to mem_cache port. - Make sosreport as unconfined domain. - Allow mondogdb to 'accept' accesses on the tcp_socket port. - ALlow sanlock to send a signal to virtd_t.- Build also MLS policy Resolves:#1138424- Add back kill permisiion for system class - Allow iptables read fail2ban logs. - Fix radius labeled ports - Add userdom_manage_user_tmpfs_files interface - Allow libreswan to connect to VPN via NM-libreswan. - Label 4101 tcp port as brlp port - fix dev_getattr_generic_usb_dev interface - Allow all domains to read fonts - Make sure /run/systemd/generator and system is labeled correctly on creation. - Dontaudit aicuu to search home config dir. - Make keystone_cgi_script_t domain. Resolves:#1138424 - Fix bug in drbd policy, - Added support for cpuplug. - ALlow sanlock_t to read sysfs_t. - Added sendmail_domtrans_unconfined interface - Fix broken interfaces - radiusd wants to write own log files. - Label /usr/libexec/rhsmd as rhsmcertd_exec_t - Allow rhsmcertd send signull to setroubleshoot. - Allow rhsmcertd manage rpm db. - Added policy for blrtty. - Fix keepalived policy - Allow rhev-agentd dbus chat with systemd-logind. - Allow keepalived manage snmp var lib sock files. - Add support for /var/lib/graphite-web - Allow NetworkManager to create Bluetooth SDP sockets - It's going to do the the discovery for DUN service for modems with Bluez 5. - Allow swift to connect to all ephemeral ports by default. - Allow sssd to read selinux config to add SELinux user mapping. - Allow lsmd to search own plguins. - Allow abrt to read /dev/memto generate an unique machine_id and uses sosuploader's algorithm based off dmidecode[1] fields. - ALlow zebra for user/group look-ups. - Allow nova domains to getattr on all filesystems. - Allow collectd sys_ptrace and dac_override caps because of reading of /proc/%i/io for several processes. - Allow pppd to connect to /run/sstpc/sstpc-nm-sstp-service-28025 over unix stream socket. - Allow rhnsd_t to manage also rhnsd config symlinks. - ALlow user mail domains to create dead.letter. - Allow rabbitmq_t read rabbitmq_var_lib_t lnk files. - Allow pki-tomcat to change SELinux object identity. - Allow radious to connect to apache ports to do OCSP check - Allow git cgi scripts to create content in /tmp - Allow cockpit-session to do GSSAPI logins. - Allow sensord read in /proc - Additional access required by usbmuxd- Allow locate to look at files/directories without labels, and chr_file and blk_file on non dev file systems - Label /usr/lib/erlang/erts.*/bin files as bin_t - Add files_dontaudit_access_check_home_dir() inteface. - Allow udev_t mounton udev_var_run_t dirs #(1128618) - Add systemd_networkd_var_run_t labeling for /var/run/systemd/netif and allow systemd-networkd to manage it. - Add init_dontaudit_read_state() interface. - Add label for ~/.local/share/fonts - Allow unconfined_r to access unconfined_service_t. - Allow init to read all config files - Add new interface to allow creation of file with lib_t type - Assign rabbitmq port. - Allow unconfined_service_t to dbus chat with all dbus domains - Add new interfaces to access users keys. - Allow domains to are allowed to mounton proc to mount on files as well as dirs - Fix labeling for HOME_DIR/tmp and HOME_DIR/.tmp directories. - Add a port definition for shellinaboxd - Label ~/tmp and ~/.tmp directories in user tmp dirs as user_tmp_t - Allow userdomains to stream connect to pcscd for smart cards - Allow programs to use pam to search through user_tmp_t dires (/tmp/.X11-unix) - Update to rawhide-contrib changes Resolves:#1123844- Rebase to 3.13.1 which we have in Fedora21 Resolves:#1128284- Back port fixes from Fedora. Mainly OpenStack and Docker fixes- Add policy-rhel-7.1-{base,contrib} patches- Add support for us_cli ports - Fix labeling for /var/run/user//gvfs - add support for tcp/9697 - Additional rules required by openstack, needs backport to F20 and RHEL7 - Additional access required by docker - ALlow motion to use tcp/8082 port - Allow init_t to setattr/relabelfrom dhcp state files - Dontaudit antivirus domains read access on all security files by default - Add missing alias for old amavis_etc_t type - Allow block_suspend cap for haproxy - Additional fixes for instack overcloud - Allow OpenStack to read mysqld_db links and connect to MySQL - Remove dup filename rules in gnome.te - Allow sys_chroot cap for httpd_t and setattr on httpd_log_t - Allow iscsid to handle own unit files - Add iscsi_systemctl() - Allow mongod to create also sock_files in /run with correct labeling - Allow httpd to send signull to apache script domains and don't audit leaks - Allow rabbitmq_beam to connect to httpd port - Allow aiccu stream connect to pcscd - Allow dmesg to read hwdata and memory dev - Allow all freeipmi domains to read/write ipmi devices - Allow sblim_sfcbd to use also pegasus-https port - Allow rabbitmq_epmd to manage rabbit_var_log_t files - Allow chronyd to read /sys/class/hwmon/hwmon1/device/temp2_input - Allow docker to status any unit file and allow it to start generic unit files- Change hsperfdata_root to have as user_tmp_t Resolves:#1076523- Fix Multiple same specifications for /var/named/chroot/dev/zero - Add labels for /var/named/chroot_sdb/dev devices - Add support for strongimcv - Use kerberos_keytab_domains in auth_use_nsswitch - Update auth_use_nsswitch to make all these types as kerberos_keytab_domain to - Allow net_raw cap for neutron_t and send sigkill to dnsmasq - Fix ntp_filetrans_named_content for sntp-kod file - Add httpd_dbus_sssd boolean - Dontaudit exec insmod in boinc policy - Rename kerberos_keytab_domain to kerberos_keytab_domains - Add kerberos_keytab_domain() - Fix kerberos_keytab_template() - Make all domains which use kerberos as kerberos_keytab_domain Resolves:#1083670 - Allow kill capability to winbind_t- varnishd wants chown capability - update ntp_filetrans_named_content() interface - Add additional fixes for neutron_t. #1083335 - Dontaudit getattr on proc_kcore_t - Allow pki_tomcat_t to read ipa lib files - Allow named_filetrans_domain to create /var/cache/ibus with correct labelign - Allow init_t run /sbin/augenrules - Add dev_unmount_sysfs_fs and sysnet_manage_ifconfig_run interfaces - Allow unpriv SELinux user to use sandbox - Add default label for /tmp/hsperfdata_root- Add file subs also for /var/home- Allow xauth_t to read user_home_dir_t lnk_file - Add labeling for lightdm-data - Allow certmonger to manage ipa lib files - Add support for /var/lib/ipa - Allow pegasus to getattr virt_content - Added some new rules to pcp policy - Allow chrome_sandbox to execute config_home_t - Add support for ABRT FAF- Allow kdm to send signull to remote_login_t process - Add gear policy - Turn on gear_port_t - Allow cgit to read gitosis lib files by default - Allow vdagent to read xdm state - Allow NM and fcoeadm to talk together over unix_dgram_socket- Back port fixes for pegasus_openlmi_admin_t from rawhide Resolves:#1080973 - Add labels for ostree - Add SELinux awareness for NM - Label /usr/sbin/pwhistory_helper as updpwd_exec_t- add gnome_append_home_config() - Allow thumb to append GNOME config home files - Allow rasdaemon to rw /dev/cpu//msr - fix /var/log/pki file spec - make bacula_t as auth_nsswitch domain - Identify pki_tomcat_cert_t as a cert_type - Define speech-dispater_exec_t as an application executable - Add a new file context for /var/named/chroot/run directory - update storage_filetrans_all_named_dev for sg* devices - Allow auditctl_t to getattr on all removeable devices - Allow nsswitch_domains to stream connect to nmbd - Allow unprivusers to connect to memcached - label /var/lib/dirsrv/scripts-INSTANCE as bin_t- Allow also unpriv user to run vmtools - Allow secadm to read /dev/urandom and meminfo Resolves:#1079250 - Add booleans to allow docker processes to use nfs and samba - Add mdadm_tmpfs support - Dontaudit net_amdin for /usr/lib/jvm/java-1.7.0-openjdk-1.7.0.51-2.4.5.1.el7.x86_64/jre-abrt/bin/java running as pki_tomcat_t - Allow vmware-user-sui to use user ttys - Allow talk 2 users logged via console too - Allow ftp services to manage xferlog_t - Make all pcp domanis as unconfined for RHEL7.0 beucause of new policies - allow anaconda to dbus chat with systemd-localed- allow anaconda to dbus chat with systemd-localed - Add fixes for haproxy based on bperkins@redhat.com - Allow cmirrord to make dmsetup working - Allow NM to execute arping - Allow users to send messages through talk - Add userdom_tmp_role for secadm_t- Add additional fixes for rtas_errd - Fix transitions for tmp/tmpfs in rtas.te - Allow rtas_errd to readl all sysctls- Add support for /var/spool/rhsm/debug - Make virt_sandbox_use_audit as True by default - Allow svirt_sandbox_domains to ptrace themselves- Allow docker containers to manage /var/lib/docker content- Allow docker to read tmpfs_t symlinks - Allow sandbox svirt_lxc_net_t to talk to syslog and to sssd over stream sockets- Allow collectd to talk to libvirt - Allow chrome_sandbox to use leaked unix_stream_sockets - Dontaudit leaks of sockets into chrome_sandbox_t - If you create a cups directory in /var/cache then it should be labeled cups_rw_etc_t - Run vmtools as unconfined domains - Allow snort to manage its log files - Allow systemd_cronjob_t to be entered via bin_t - Allow procman to list doveconf_etc_t - allow keyring daemon to create content in tmpfs directories - Add proper labelling for icedtea-web - vpnc is creating content in networkmanager var run directory - Label sddm as xdm_exec_t to make KDE working again - Allow postgresql to read network state - Allow java running as pki_tomcat to read network sysctls - Fix cgroup.te to allow cgred to read cgconfig_etc_t - Allow beam.smp to use ephemeral ports - Allow winbind to use the nis to authenticate passwords- Make rtas_errd_t as unconfined domain for F20.It needs additional fixes. It runs rpm at least. - Allow net_admin cap for fence_virtd running as fenced_t - Make abrt-java-connector working - Make cimtest script 03_defineVS.py of ComputerSystem group working - Fix git_system_enable_homedirs boolean - Allow munin mail plugins to read network systcl- Allow vmtools_helper_t to execute bin_t - Add support for /usr/share/joomla - /var/lib/containers should be labeled as openshift content for now - Allow docker domains to talk to the login programs, to allow a process to login into the container - Allow install_t do dbus chat with NM - Fix interface names in anaconda.if - Add install_t for anaconda. A new type is a part of anaconda policy - sshd to read network sysctls- Allow zabbix to send system log msgs - Allow init_t to stream connect to ipsec Resolves:#1060775- Add docker_connect_any boolean- Allow unpriv SELinux users to dbus chat with firewalld - Add lvm_write_metadata() - Label /etc/yum.reposd dir as system_conf_t. Should be safe because system_conf_t is base_ro_file_type - Allow pegasus_openlmi_storage_t to write lvm metadata - Add hide_broken_symptoms for kdumpgui because of systemd bug - Make kdumpgui_t as unconfined domain Resolves:#1044299 - Allow docker to connect to tcp/5000- Allow numad to write scan_sleep_millisecs - Turn on entropyd_use_audio boolean by default - Allow cgred to read /etc/cgconfig.conf because it contains templates used together with rules from /etc/cgrules.conf. - Allow lscpu running as rhsmcertd_t to read /proc/sysinfo - Fix label on irclogs in the homedir - Allow kerberos_keytab_domain domains to manage keys until we get sssd fix - Allow postgresql to use ldap - Add missing syslog-conn port - Add support for /dev/vmcp and /dev/sclp Resolves:#1069310- Modify xdm_write_home to allow create files/links in /root with xdm_home_ - Allow virt domains to read network state Resolves:#1072019- Added pcp rules - dontaudit openshift_cron_t searching random directories, should be back ported to RHEL6 - clean up ctdb.te - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow certmonger to list home dirs- Change userdom_use_user_inherited_ttys to userdom_use_user_ttys for systemd-tty-ask - Add sysnet_filetrans_named_content_ifconfig() interface - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow kerberos keytab domains to manage sssd/userdomain keys" - Allow to run ip cmd in neutron_t domain- Allow block_suspend cap2 for systemd-logind and rw dri device - Add labeling for /usr/libexec/nm-libreswan-service - Allow locallogin to rw xdm key to make Virtual Terminal login providing smartcard pin working - Add xserver_rw_xdm_keys() - Allow rpm_script_t to dbus chat also with systemd-located - Fix ipa_stream_connect_otpd() - update lpd_manage_spool() interface - Allow krb5kdc to stream connect to ipa-otpd - Add ipa_stream_connect_otpd() interface - Allow vpnc to unlink NM pids - Add networkmanager_delete_pid_files() - Allow munin plugins to access unconfined plugins - update abrt_filetrans_named_content to cover /var/spool/debug - Label /var/spool/debug as abrt_var_cache_t - Allow rhsmcertd to connect to squid port - Make docker_transition_unconfined as optional boolean - Allow certmonger to list home dirs- Make snapperd as unconfined domain and add additional fixes for it - Remove nsplugin.pp module on upgrade- Add snapperd_home_t for HOME_DIR/.snapshots directory - Make sosreport as unconfined domain - Allow sosreport to execute grub2-probe - Allow NM to manage hostname config file - Allow systemd_timedated_t to dbus chat with rpm_script_t - Allow lsmd plugins to connect to http/ssh/http_cache ports by default - Add lsmd_plugin_connect_any boolean - Allow mozilla_plugin to attempt to set capabilities - Allow lsdm_plugins to use tcp_socket - Dontaudit mozilla plugin from getattr on /proc or /sys - Dontaudit use of the keyring by the services in a sandbox - Dontaudit attempts to sys_ptrace caused by running ps for mysqld_safe_t - Allow rabbitmq_beam to connect to jabber_interserver_port - Allow logwatch_mail_t to transition to qmail_inject and queueu - Added new rules to pcp policy - Allow vmtools_helper_t to change role to system_r - Allow NM to dbus chat with vmtools - Fix couchdb_manage_files() to allow manage couchdb conf files - Add support for /var/run/redis.sock - dontaudit gpg trying to use audit - Allow consolekit to create log directories and files - Fix vmtools policy to allow user roles to access vmtools_helper_t - Allow block_suspend cap2 for ipa-otpd - Allow pkcsslotd to read users state - Add ioctl to init_dontaudit_rw_stream_socket - Add systemd_hostnamed_manage_config() interface - Remove transition for temp dirs created by init_t - gdm-simple-slave uses use setsockopt - sddm-greater is a xdm type program- Add lvm_read_metadata() - Allow auditadm to search /var/log/audit dir - Add lvm_read_metadata() interface - Allow confined users to run vmtools helpers - Fix userdom_common_user_template() - Generic systemd unit scripts do write check on / - Allow init_t to create init_tmp_t in /tmp.This is for temporary content created by generic unit files - Add additional fixes needed for init_t and setup script running in generic unit files - Allow general users to create packet_sockets - added connlcli port - Add init_manage_transient_unit() interface - Allow init_t (generic unit files) to manage rpc state date as we had it for initrc_t - Fix userdomain.te to require passwd class - devicekit_power sends out a signal to all processes on the message bus when power is going down - Dontaudit rendom domains listing /proc and hittping system_map_t - Dontauit leaks of var_t into ifconfig_t - Allow domains that transition to ssh_t to manipulate its keyring - Define oracleasm_t as a device node - Change to handle /root as a symbolic link for os-tree - Allow sysadm_t to create packet_socket, also move some rules to attributes - Add label for openvswitch port - Remove general transition for files/dirs created in /etc/mail which got etc_aliases_t label. - Allow postfix_local to read .forward in pcp lib files - Allow pegasus_openlmi_storage_t to read lvm metadata - Add additional fixes for pegasus_openlmi_storage_t - Allow bumblebee to manage debugfs - Make bumblebee as unconfined domain - Allow snmp to read etc_aliases_t - Allow lscpu running in pegasus_openlmi_storage_t to read /dev/mem - Allow pegasus_openlmi_storage_t to read /proc/1/environ - Dontaudit read gconf files for cupsd_config_t - make vmtools as unconfined domain - Add vmtools_helper_t for helper scripts. Allow vmtools shutdonw a host and run ifconfig. - Allow collectd_t to use a mysql database - Allow ipa-otpd to perform DNS name resolution - Added new policy for keepalived - Allow openlmi-service provider to manage transitient units and allow stream connect to sssd - Add additional fixes new pscs-lite+polkit support - Add labeling for /run/krb5kdc - Change w3c_validator_tmp_t to httpd_w3c_validator_tmp_t in F20 - Allow pcscd to read users proc info - Dontaudit smbd_t sending out random signuls - Add boolean to allow openshift domains to use nfs - Allow w3c_validator to create content in /tmp - zabbix_agent uses nsswitch - Allow procmail and dovecot to work together to deliver mail - Allow spamd to execute files in homedir if boolean turned on - Allow openvswitch to listen on port 6634 - Add net_admin capability in collectd policy - Fixed snapperd policy - Fixed bugsfor pcp policy - Allow dbus_system_domains to be started by init - Fixed some interfaces - Add kerberos_keytab_domain attribute - Fix snapperd_conf_t def- Addopt corenet rules for unbound-anchor to rpm_script_t - Allow runuser to send send audit messages. - Allow postfix-local to search .forward in munin lib dirs - Allow udisks to connect to D-Bus - Allow spamd to connect to spamd port - Fix syntax error in snapper.te - Dontaudit osad to search gconf home files - Allow rhsmcertd to manage /etc/sysconf/rhn director - Fix pcp labeling to accept /usr/bin for all daemon binaries - Fix mcelog_read_log() interface - Allow iscsid to manage iscsi lib files - Allow snapper domtrans to lvm_t. Add support for /etc/snapper and allow snapperd to manage it. - Make tuned_t as unconfined domain for RHEL7.0 - Allow ABRT to read puppet certs - Add sys_time capability for virt-ga - Allow gemu-ga to domtrans to hwclock_t - Allow additional access for virt_qemu_ga_t processes to read system clock and send audit messages - Fix some AVCs in pcp policy - Add to bacula capability setgid and setuid and allow to bind to bacula ports - Changed label from rhnsd_rw_conf_t to rhnsd_conf_t - Add access rhnsd and osad to /etc/sysconfig/rhn - drbdadm executes drbdmeta - Fixes needed for docker - Allow epmd to manage /var/log/rabbitmq/startup_err file - Allow beam.smp connect to amqp port - Modify xdm_write_home to allow create also links as xdm_home_t if the boolean is on true - Allow init_t to manage pluto.ctl because of init_t instead of initrc_t - Allow systemd_tmpfiles_t to manage all non security files on the system - Added labels for bacula ports - Fix label on /dev/vfio/vfio - Add kernel_mounton_messages() interface - init wants to manage lock files for iscsi- Added osad policy - Allow postfix to deliver to procmail - Allow bumblebee to seng kill signal to xserver - Allow vmtools to execute /usr/bin/lsb_release - Allow docker to write system net ctrls - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix pcp.te - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl- Turn on bacula, rhnsd policy - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl - Fixes for *_admin interfaces - Add pegasus_openlmi_storage_var_run_t type def - Add support for /var/run/openlmi-storage - Allow tuned to create syslog.conf with correct labeling - Add httpd_dontaudit_search_dirs boolean - Add support for winbind.service - ALlow also fail2ban-client to read apache logs - Allow vmtools to getattr on all fs - Add support for dey_sapi port - Add logging_filetrans_named_conf() - Allow passwd_t to use ipc_lock, so that it can change the password in gnome-keyring- Update snapper policy - Allow domains to append rkhunter lib files - Allow snapperd to getattr on all fs - Allow xdm to create /var/gdm with correct labeling - Add label for snapper.log - Allow fail2ban-client to read apache log files - Allow thumb_t to execute dbus-daemon in thumb_t- Allow gdm to create /var/gdm with correct labeling - Allow domains to append rkhunterl lib files. #1057982 - Allow systemd_tmpfiles_t net_admin to communicate with journald - Add interface to getattr on an isid_type for any type of file - Update libs_filetrans_named_content() to have support for /usr/lib/debug directory - Allow initrc_t domtrans to authconfig if unconfined is enabled - Allow docker and mount on devpts chr_file - Allow docker to transition to unconfined_t if boolean set - init calling needs to be optional in domain.te - Allow uncofined domain types to handle transient unit files - Fix labeling for vfio devices - Allow net_admin capability and send system log msgs - Allow lldpad send dgram to NM - Add networkmanager_dgram_send() - rkhunter_var_lib_t is correct type - Back port pcp policy from rawhide - Allow openlmi-storage to read removable devices - Allow system cron jobs to manage rkhunter lib files - Add rkhunter_manage_lib_files() - Fix ftpd_use_fusefs boolean to allow manage also symlinks - Allow smbcontrob block_suspend cap2 - Allow slpd to read network and system state info - Allow NM domtrans to iscsid_t if iscsiadm is executed - Allow slapd to send a signal itself - Allow sslget running as pki_ra_t to contact port 8443, the secure port of the CA. - Fix plymouthd_create_log() interface - Add rkhunter policy with files type definition for /var/lib/rkhunter until it is fixed in rkhunter package - Add mozilla_plugin_exec_t for /usr/lib/firefox/plugin-container - Allow postfix and cyrus-imapd to work out of box - Allow fcoemon to talk with unpriv user domain using unix_stream_socket - Dontaudit domains that are calling into journald to net_admin - Add rules to allow vmtools to do what it does - snapperd is D-Bus service - Allow OpenLMI PowerManagement to call 'systemctl --force reboot' - Add haproxy_connect_any boolean - Allow haproxy also to use http cache port by default Resolves:#1058248- Allow apache to write to the owncloud data directory in /var/www/html... - Allow consolekit to create log dir - Add support for icinga CGI scripts - Add support for icinga - Allow kdumpctl_t to create kdump lock file Resolves:#1055634 - Allow kdump to create lnk lock file - Allow nscd_t block_suspen capability - Allow unconfined domain types to manage own transient unit file - Allow systemd domains to handle transient init unit files - Add interfaces to handle transient- Add cron unconfined role support for uncofined SELinux user - Call corenet_udp_bind_all_ports() in milter.te - Allow fence_virtd to connect to zented port - Fix header for mirrormanager_admin() - Allow dkim-milter to bind udp ports - Allow milter domains to send signull itself - Allow block_suspend for yum running as mock_t - Allow beam.smp to manage couchdb files - Add couchdb_manage_files() - Add labeling for /var/log/php_errors.log - Allow bumblebee to stream connect to xserver - Allow bumblebee to send a signal to xserver - gnome-thumbnail to stream connect to bumblebee - Allow xkbcomp running as bumblebee_t to execute bin_t - Allow logrotate to read squid.conf - Additional rules to get docker and lxc to play well with SELinux - Allow bumbleed to connect to xserver port - Allow pegasus_openlmi_storage_t to read hwdata- Allow init_t to work on transitient and snapshot unit files - Add logging_manage_syslog_config() - Update sysnet_dns_name_resolve() to allow connect to dnssec por - Allow pegasus_openlmi_storage_t to read hwdata Resolves:#1031721 - Fix rhcs_rw_cluster_tmpfs() - Allow fenced_t to bind on zented udp port - Added policy for vmtools - Fix mirrormanager_read_lib_files() - Allow mirromanager scripts running as httpd_t to manage mirrormanager pid files - Allow ctdb to create sock files in /var/run/ctdb - Add sblim_filetrans_named_content() interface - Allow rpm scritplets to create /run/gather with correct labeling - Allow gnome keyring domains to create gnome config dirs - Dontaudit read/write to init stream socket for lsmd_plugin_t - Allow automount to read nfs link files - Allow lsm plugins to read/write lsmd stream socket - Allow certmonger to connect ldap port to make IPA CA certificate renewal working. - Add also labeling for /var/run/ctdb - Add missing labeling for /var/lib/ctdb - ALlow tuned to manage syslog.conf. Should be fixed in tuned. #1030446 - Dontaudit hypervkvp to search homedirs - Dontaudit hypervkvp to search admin homedirs - Allow hypervkvp to execute bin_t and ifconfig in the caller domain - Dontaudit xguest_t to read ABRT conf files - Add abrt_dontaudit_read_config() - Allow namespace-init to getattr on fs - Add thumb_role() also for xguest - Add filename transitions to create .spamassassin with correct labeling - Allow apache domain to read mirrormanager pid files - Allow domains to read/write shm and sem owned by mozilla_plugin_t - Allow alsactl to send a generic signal to kernel_t- Add back rpm_run() for unconfined user- Add missing files_create_var_lib_dirs() - Fix typo in ipsec.te - Allow passwd to create directory in /var/lib - Add filename trans also for event21 - Allow iptables command to read /dev/rand - Add sigkill capabilityfor ipsec_t - Add filename transitions for bcache devices - Add additional rules to create /var/log/cron by syslogd_t with correct labeling - Add give everyone full access to all key rings - Add default lvm_var_run_t label for /var/run/multipathd - Fix log labeling to have correct default label for them after logrotate - Labeled ~/.nv/GLCache as being gstreamer output - Allow nagios_system_plugin to read mrtg lib files - Add mrtg_read_lib_files() - Call rhcs_rw_cluster_tmpfs for dlm_controld - Make authconfing as named_filetrans domain - Allow virsh to connect to user process using stream socket - Allow rtas_errd to read rand/urand devices and add chown capability - Fix labeling from /var/run/net-snmpd to correct /var/run/net-snmp Resolves:#1051497 - Add also chown cap for abrt_upload_watch_t. It already has dac_override - Allow sosreport to manage rhsmcertd pid files - Add rhsmcertd_manage_pid_files() - Allow also setgid cap for rpc.gssd - Dontaudit access check for abrt on cert_t - Allow pegasus_openlmi_system providers to dbus chat with systemd-logind- Fix semanage import handling in spec file- Add default lvm_var_run_t label for /var/run/multipathd Resolves:#1051430 - Fix log labeling to have correct default label for them after logrotate - Add files_write_root_dirs - Add new openflow port label for 6653/tcp and 6633/tcp - Add xserver_manage_xkb_libs() - Label tcp/8891 as milter por - Allow gnome_manage_generic_cache_files also create cache_home_t files - Fix aide.log labeling - Fix log labeling to have correct default label for them after logrotate - Allow mysqld-safe write access on /root to make mysqld working - Allow sosreport domtrans to prelikn - Allow OpenvSwitch to connec to openflow ports - Allow NM send dgram to lldpad - Allow hyperv domains to execute shell - Allow lsmd plugins stream connect to lsmd/init - Allow sblim domains to create /run/gather with correct labeling - Allow httpd to read ldap certs - Allow cupsd to send dbus msgs to process with different MLS level - Allow bumblebee to stream connect to apmd - Allow bumblebee to run xkbcomp - Additional allow rules to get libvirt-lxc containers working with docker - Additional allow rules to get libvirt-lxc containers working with docker - Allow docker to getattr on itself - Additional rules needed for sandbox apps - Allow mozilla_plugin to set attributes on usb device if use_spice boolean enabled - httpd should be able to send signal/signull to httpd_suexec_t - Add more fixes for neturon. Domtrans to dnsmasq, iptables. Make neutron as filenamtrans domain.- Add neutron fixes- Allow sshd to write to all process levels in order to change passwd when running at a level - Allow updpwd_t to downgrade /etc/passwd file to s0, if it is not running with this range - Allow apcuspd_t to status and start the power unit file - Allow udev to manage kdump unit file - Added new interface modutils_dontaudit_exec_insmod - Allow cobbler to search dhcp_etc_t directory - systemd_systemctl needs sys_admin capability - Allow sytemd_tmpfiles_t to delete all directories - passwd to create gnome-keyring passwd socket - Add missing zabbix_var_lib_t type - Fix filename trans for zabbixsrv in zabbix.te - Allow fprintd_t to send syslog messages - Add zabbix_var_lib_t for /var/lib/zabbixsrv, also allow zabix to connect to smtp port - Allow mozilla plugin to chat with policykit, needed for spice - Allow gssprozy to change user and gid, as well as read user keyrings - Label upgrades directory under /var/www as httpd_sys_rw_content_t, add other filetrans rules to label content correctly - Allow polipo to connect to http_cache_ports - Allow cron jobs to manage apache var lib content - Allow yppassword to manage the passwd_file_t - Allow showall_t to send itself signals - Allow cobbler to restart dhcpc, dnsmasq and bind services - Allow certmonger to manage home cert files - Add userdom filename trans for user mail domains - Allow apcuspd_t to status and start the power unit file - Allow cgroupdrulesengd to create content in cgoups directories - Allow smbd_t to signull cluster - Allow gluster daemon to create fifo files in glusterd_brick_t and sock_file in glusterd_var_lib_t - Add label for /var/spool/cron.aquota.user - Allow sandbox_x domains to use work with the mozilla plugin semaphore - Added new policy for speech-dispatcher - Added dontaudit rule for insmod_exec_t in rasdaemon policy - Updated rasdaemon policy - Allow system_mail_t to transition to postfix_postdrop_t - Clean up mirrormanager policy - Allow virt_domains to read cert files, needs backport to RHEL7 - Allow sssd to read systemd_login_var_run_t - Allow irc_t to execute shell and bin-t files: - Add new access for mythtv - Allow rsync_t to manage all non auth files - allow modemmanger to read /dev/urand - Allow sandbox apps to attempt to set and get capabilties- Add labeling for /var/lib/servicelog/servicelog.db-journal - Add support for freeipmi port - Add sysadm_u_default_contexts - Make new type to texlive files in homedir - Allow subscription-manager running as sosreport_t to manage rhsmcertd - Additional fixes for docker.te - Remove ability to do mount/sys_admin by default in virt_sandbox domains - New rules required to run docker images within libivrt - Add label for ~/.cvsignore - Change mirrormanager to be run by cron - Add mirrormanager policy - Fixed bumblebee_admin() and mip6d_admin() - Add log support for sensord - Fix typo in docker.te - Allow amanda to do backups over UDP - Allow bumblebee to read /etc/group and clean up bumblebee.te - type transitions with a filename not allowed inside conditionals - Don't allow virt-sandbox tools to use netlink out of the box, needs back port to RHEL7 - Make new type to texlive files in homedir- Allow freeipmi_ipmidetectd_t to use freeipmi port - Update freeipmi_domain_template() - Allow journalctl running as ABRT to read /run/log/journal - Allow NM to read dispatcher.d directory - Update freeipmi policy - Type transitions with a filename not allowed inside conditionals - Allow tor to bind to hplip port - Make new type to texlive files in homedir - Allow zabbix_agent to transition to dmidecode - Add rules for docker - Allow sosreport to send signull to unconfined_t - Add virt_noatsecure and virt_rlimitinh interfaces - Fix labeling in thumb.fc to add support for /usr/lib64/tumbler-1/tumblerddd support for freeipmi port - Add sysadm_u_default_contexts - Add logging_read_syslog_pid() - Fix userdom_manage_home_texlive() interface - Make new type to texlive files in homedir - Add filename transitions for /run and /lock links - Allow virtd to inherit rlimit information Resolves:#975358- Change labeling for /usr/libexec/nm-dispatcher.action to NetworkManager_exec_t Resolves:#1039879 - Add labeling for /usr/lib/systemd/system/mariadb.service - Allow hyperv_domain to read sysfs - Fix ldap_read_certs() interface to allow acess also link files - Add support for /usr/libexec/pegasus/cmpiLMI_Journald-cimprovagt - Allow tuned to run modprobe - Allow portreserve to search /var/lib/sss dir - Add SELinux support for the teamd package contains team network device control daemon. - Dontaudit access check on /proc for bumblebee - Bumblebee wants to load nvidia modules - Fix rpm_named_filetrans_log_files and wine.te - Add conman policy for rawhide - DRM master and input event devices are used by the TakeDevice API - Clean up bumblebee policy - Update pegasus_openlmi_storage_t policy - Add freeipmi_stream_connect() interface - Allow logwatch read madm.conf to support RAID setup - Add raid_read_conf_files() interface - Allow up2date running as rpm_t create up2date log file with rpm_log_t labeling - add rpm_named_filetrans_log_files() interface - Allow dkim-milter to create files/dirs in /tmp - update freeipmi policy - Add policy for freeipmi services - Added rdisc_admin and rdisc_systemctl interfaces - opensm policy clean up - openwsman policy clean up - ninfod policy clean up - Added new policy for ninfod - Added new policy for openwsman - Added rdisc_admin and rdisc_systemctl interfaces - Fix kernel_dontaudit_access_check_proc() - Add support for /dev/uhid - Allow sulogin to get the attributes of initctl and sys_admin cap - Add kernel_dontaudit_access_check_proc() - Fix dev_rw_ipmi_dev() - Fix new interface in devices.if - DRM master and input event devices are used by the TakeDevice API - add dev_rw_inherited_dri() and dev_rw_inherited_input_dev() - Added support for default conman port - Add interfaces for ipmi devices- Allow sosreport to send a signal to ABRT - Add proper aliases for pegasus_openlmi_service_exec_t and pegasus_openlmi_service_t - Label /usr/sbin/htcacheclean as httpd_exec_t Resolves:#1037529 - Added support for rdisc unit file - Add antivirus_db_t labeling for /var/lib/clamav-unofficial-sigs - Allow runuser running as logrotate connections to system DBUS - Label bcache devices as fixed_disk_device_t - Allow systemctl running in ipsec_mgmt_t to access /usr/lib/systemd/system/ipsec.service - Label /usr/lib/systemd/system/ipsec.service as ipsec_mgmt_unit_file_t- Add back setpgid/setsched for sosreport_t- Added fix for clout_init to transition to rpm_script_t (dwalsh@redhat.com)- Dontaudit openshift domains trying to use rawip_sockets, this is caused by a bad check in the kernel. - Allow git_system_t to read git_user_content if the git_system_enable_homedirs boolean is turned on - Add lsmd_plugin_t for lsm plugins - Allow dovecot-deliver to search mountpoints - Add labeling for /etc/mdadm.conf - Allow opelmi admin providers to dbus chat with init_t - Allow sblim domain to read /dev/urandom and /dev/random - Allow apmd to request the kernel load modules - Add glusterd_brick_t type - label mate-keyring-daemon with gkeyringd_exec_t - Add plymouthd_create_log() - Dontaudit leaks from openshift domains into mail domains, needs back port to RHEL6 - Allow sssd to request the kernel loads modules - Allow gpg_agent to use ssh-add - Allow gpg_agent to use ssh-add - Dontaudit access check on /root for myslqd_safe_t - Allow ctdb to getattr on al filesystems - Allow abrt to stream connect to syslog - Allow dnsmasq to list dnsmasq.d directory - Watchdog opens the raw socket - Allow watchdog to read network state info - Dontaudit access check on lvm lock dir - Allow sosreport to send signull to setroubleshootd - Add setroubleshoot_signull() interface - Fix ldap_read_certs() interface - Allow sosreport all signal perms - Allow sosreport to run systemctl - Allow sosreport to dbus chat with rpm - Add glusterd_brick_t files type - Allow zabbix_agentd to read all domain state - Clean up rtas.if - Allow smoltclient to execute ldconfig - Allow sosreport to request the kernel to load a module - Fix userdom_confined_admin_template() - Add back exec_content boolean for secadm, logadm, auditadm - Fix files_filetrans_system_db_named_files() interface - Allow sulogin to getattr on /proc/kcore - Add filename transition also for servicelog.db-journal - Add files_dontaudit_access_check_root() - Add lvm_dontaudit_access_check_lock() interface- Allow watchdog to read /etc/passwd - Allow browser plugins to connect to bumblebee - New policy for bumblebee and freqset - Add new policy for mip6d daemon - Add new policy for opensm daemon - Allow condor domains to read/write condor_master udp_socket - Allow openshift_cron_t to append to openshift log files, label /var/log/openshift - Add back file_pid_filetrans for /var/run/dlm_controld - Allow smbd_t to use inherited tmpfs content - Allow mcelog to use the /dev/cpu device - sosreport runs rpcinfo - sosreport runs subscription-manager - Allow staff_t to run frequency command - Allow systemd_tmpfiles to relabel log directories - Allow staff_t to read xserver_log file - Label hsperfdata_root as tmp_t- More sosreport fixes to make ABRT working- Fix files_dontaudit_unmount_all_mountpoints() - Add support for 2608-2609 tcp/udp ports - Should allow domains to lock the terminal device - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - We need to require passwd rootok - Fix zebra.fc - Fix dnsmasq_filetrans_named_content() interface - Allow all sandbox domains create content in svirt_home_t - Allow zebra domains also create zebra_tmp_t files in /tmp - Add support for new zebra services:isisd,babeld. Add systemd support for zebra services. - Fix labeling on neutron and remove transition to iconfig_t - abrt needs to read mcelog log file - Fix labeling on dnsmasq content - Fix labeling on /etc/dnsmasq.d - Allow glusterd to relabel own lib files - Allow sandbox domains to use pam_rootok, and dontaudit attempts to unmount file systems, this is caused by a bug in systemd - Allow ipc_lock for abrt to run journalctl- Fix config.tgz- Fix passenger_stream_connect interface - setroubleshoot_fixit wants to read network state - Allow procmail_t to connect to dovecot stream sockets - Allow cimprovagt service providers to read network states - Add labeling for /var/run/mariadb - pwauth uses lastlog() to update system's lastlog - Allow account provider to read login records - Add support for texlive2013 - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - Allow passwd_t to connect to gnome keyring to change password - Update mls config files to have cronjobs in the user domains - Remove access checks that systemd does not actually do- Add support for yubikey in homedir - Add support for upd/3052 port - Allow apcupsd to use PowerChute Network Shutdown - Allow lsmd to execute various lsmplugins - Add labeling also for /etc/watchdog\.d where are watchdog scripts located too - Update gluster_export_all_rw boolean to allow relabel all base file types - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling- Add files_relabel_base_file_types() interface - Allow netlabel-config to read passwd - update gluster_export_all_rw boolean to allow relabel all base file types caused by lsetxattr() - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling - Allow pegasus to domtrans to mount_t - Add labeling for unconfined scripts in /usr/libexec/watchdog/scripts - Add support for unconfined watchdog scripts - Allow watchdog to manage own log files- Add label only for redhat.repo instead of /etc/yum.repos.d. But probably we will need to switch for the directory. - Label /etc/yum.repos.d as system_conf_t - Use sysnet_filetrans_named_content in udev.te instead of generic transition for net_conf_t - Allow dac_override for sysadm_screen_t - Allow init_t to read ipsec_conf_t as we had it for initrc_t. Needed by ipsec unit file. - Allow netlabel-config to read meminfo - Add interface to allow docker to mounton file_t - Add new interface to exec unlabeled files - Allow lvm to use docker semaphores - Setup transitons for .xsessions-errors.old - Change labels of files in /var/lib/*/.ssh to transition properly - Allow staff_t and user_t to look at logs using journalctl - pluto wants to manage own log file - Allow pluto running as ipsec_t to create pluto.log - Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Allow dmidecode to read/write /run/lock/subsys/rhsmcertd - Allow rhsmcertd to manage redhat.repo which is now labeled as system.conf. Allow rhsmcertd to manage all log files. - Additional access for docker - Added more rules to sblim policy - Fix kdumpgui_run_bootloader boolean - Allow dspam to connect to lmtp port - Included sfcbd service into sblim policy - rhsmcertd wants to manaage /etc/pki/consumer dir - Add kdumpgui_run_bootloader boolean - Add support for /var/cache/watchdog - Remove virt_domain attribute for virt_qemu_ga_unconfined_t - Fixes for handling libvirt containes - Dontaudit attempts by mysql_safe to write content into / - Dontaudit attempts by system_mail to modify network config - Allow dspam to bind to lmtp ports - Add new policy to allow staff_t and user_t to look at logs using journalctl - Allow apache cgi scripts to list sysfs - Dontaudit attempts to write/delete user_tmp_t files - Allow all antivirus domains to manage also own log dirs - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Add missing permission checks for nscd- Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Add file transition rules for content created by f5link - Rename quantum_port information to neutron - Allow all antivirus domains to manage also own log dirs - Rename quantum_port information to neutron - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Allow sysadm_t to read login information - Allow systemd_tmpfiles to setattr on var_log_t directories - Udpdate Makefile to include systemd_contexts - Add systemd_contexts - Add fs_exec_hugetlbfs_files() interface - Add daemons_enable_cluster_mode boolean - Fix rsync_filetrans_named_content() - Add rhcs_read_cluster_pid_files() interface - Update rhcs.if with additional interfaces from RHEL6 - Fix rhcs_domain_template() to not create run dirs with cluster_var_run_t - Allow glusterd_t to mounton glusterd_tmp_t - Allow glusterd to unmout al filesystems - Allow xenstored to read virt config - Add label for swift_server.lock and make add filetrans_named_content to make sure content gets created with the correct label - Allow mozilla_plugin_t to mmap hugepages as an executable- Add back userdom_security_admin_template() interface and use it for sysadm_t if sysadm_secadm.pp- Allow sshd_t to read openshift content, needs backport to RHEL6.5 - Label /usr/lib64/sasl2/libsasldb.so.3.0.0 as textrel_shlib_t - Make sur kdump lock is created with correct label if kdumpctl is executed - gnome interface calls should always be made within an optional_block - Allow syslogd_t to connect to the syslog_tls port - Add labeling for /var/run/charon.ctl socket - Add kdump_filetrans_named_content() - Allo setpgid for fenced_t - Allow setpgid and r/w cluster tmpfs for fenced_t - gnome calls should always be within optional blocks - wicd.pid should be labeled as networkmanager_var_run_t - Allow sys_resource for lldpad- Add rtas policy- Allow mailserver_domains to manage and transition to mailman data - Dontaudit attempts by mozilla plugin to relabel content, caused by using mv and cp commands - Allow mailserver_domains to manage and transition to mailman data - Allow svirt_domains to read sysctl_net_t - Allow thumb_t to use tmpfs inherited from the user - Allow mozilla_plugin to bind to the vnc port if running with spice - Add new attribute to discover confined_admins and assign confined admin to it - Fix zabbix to handle attributes in interfaces - Fix zabbix to read system states for all zabbix domains - Fix piranha_domain_template() - Allow ctdbd to create udp_socket. Allow ndmbd to access ctdbd var files. - Allow lldpad sys_rouserce cap due to #986870 - Allow dovecot-auth to read nologin - Allow openlmi-networking to read /proc/net/dev - Allow smsd_t to execute scripts created on the fly labeled as smsd_spool_t - Add zabbix_domain attribute for zabbix domains to treat them together - Add labels for zabbix-poxy-* (#1018221) - Update openlmi-storage policy to reflect #1015067 - Back port piranha tmpfs fixes from RHEL6 - Update httpd_can_sendmail boolean to allow read/write postfix spool maildrop - Add postfix_rw_spool_maildrop_files interface - Call new userdom_admin_user_templat() also for sysadm_secadm.pp - Fix typo in userdom_admin_user_template() - Allow SELinux users to create coolkeypk11sE-Gate in /var/cache/coolkey - Add new attribute to discover confined_admins - Fix labeling for /etc/strongswan/ipsec.d - systemd_logind seems to pass fd to anyone who dbus communicates with it - Dontaudit leaked write descriptor to dmesg- Activate motion policy- Fix gnome_read_generic_data_home_files() - allow openshift_cgroup_t to read/write inherited openshift file types - Remove httpd_cobbler_content * from cobbler_admin interface - Allow svirt sandbox domains to setattr on chr_file and blk_file svirt_sandbox_file_t, so sshd will work within a container - Allow httpd_t to read also git sys content symlinks - Allow init_t to read gnome home data - Dontaudit setroubleshoot_fixit_t execmem, since it does not seem to really need it. - Allow virsh to execute systemctl - Fix for nagios_services plugins - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - Fix hypervkvp.te - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Fix logging policy - Allow syslog to bind to tls ports - Update labeling for /dev/cdc-wdm - Allow to su_domain to read init states - Allow init_t to read gnome home data - Make sure if systemd_logind creates nologin file with the correct label - Clean up ipsec.te- Add auth_exec_chkpwd interface - Fix port definition for ctdb ports - Allow systemd domains to read /dev/urand - Dontaudit attempts for mozilla_plugin to append to /dev/random - Add label for /var/run/charon.* - Add labeling for /usr/lib/systemd/system/lvm2.*dd policy for motion service - Fix for nagios_services plugins - Fix some bugs in zoneminder policy - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - glusterd binds to random unreserved ports - Additional allow rules found by testing glusterfs - apcupsd needs to send a message to all users on the system so needs to look them up - Fix the label on ~/.juniper_networks - Dontaudit attempts for mozilla_plugin to append to /dev/random - Allow polipo_daemon to connect to flash ports - Allow gssproxy_t to create replay caches - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type- init reload from systemd_localed_t - Allow domains that communicate with systemd_logind_sessions to use systemd_logind_t fd - Allow systemd_localed_t to ask systemd to reload the locale. - Add systemd_runtime_unit_file_t type for unit files that systemd creates in memory - Allow readahead to read /dev/urand - Fix lots of avcs about tuned - Any file names xenstored in /var/log should be treated as xenstored_var_log_t - Allow tuned to inderact with hugepages - Allow condor domains to list etc rw dirs- Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Add additional fixes forpegasus_openlmi_account_t - Allow mdadm to read /dev/urand - Allow pegasus_openlmi_storage_t to create mdadm.conf and write it - Add label/rules for /etc/mdadm.conf - Allow pegasus_openlmi_storage_t to transition to fsadm_t - Fixes for interface definition problems - Dontaudit dovecot-deliver to gettatr on all fs dirs - Allow domains to search data_home_t directories - Allow cobblerd to connect to mysql - Allow mdadm to r/w kdump lock files - Add support for kdump lock files - Label zarafa-search as zarafa-indexer - Openshift cgroup wants to read /etc/passwd - Add new sandbox domains for kvm - Allow mpd to interact with pulseaudio if mpd_enable_homedirs is turned on - Fix labeling for /usr/lib/systemd/system/lvm2.* - Add labeling for /usr/lib/systemd/system/lvm2.* - Fix typos to get a new build. We should not cover filename trans rules to prevent duplicate rules - Add sshd_keygen_t policy for sshd-keygen - Fix alsa_home_filetrans interface name and definition - Allow chown for ssh_keygen_t - Add fs_dontaudit_getattr_all_dirs() - Allow init_t to manage etc_aliases_t and read xserver_var_lib_t and chrony keys - Fix up patch to allow systemd to manage home content - Allow domains to send/recv unlabeled traffic if unlabelednet.pp is enabled - Allow getty to exec hostname to get info - Add systemd_home_t for ~/.local/share/systemd directory- Fix lxc labels in config.tgz- Fix labeling for /usr/libexec/kde4/kcmdatetimehelper - Allow tuned to search all file system directories - Allow alsa_t to sys_nice, to get top performance for sound management - Add support for MySQL/PostgreSQL for amavis - Allow openvpn_t to manage openvpn_var_log_t files. - Allow dirsrv_t to create tmpfs_t directories - Allow dirsrv to create dirs in /dev/shm with dirsrv_tmpfs label - Dontaudit leaked unix_stream_sockets into gnome keyring - Allow telepathy domains to inhibit pipes on telepathy domains - Allow cloud-init to domtrans to rpm - Allow abrt daemon to manage abrt-watch tmp files - Allow abrt-upload-watcher to search /var/spool directory - Allow nsswitch domains to manage own process key - Fix labeling for mgetty.* logs - Allow systemd to dbus chat with upower - Allow ipsec to send signull to itself - Allow setgid cap for ipsec_t - Match upstream labeling- Do not build sanbox pkg on MLS- wine_tmp is no longer needed - Allow setroubleshoot to look at /proc - Allow telepathy domains to dbus with systemd logind - Fix handling of fifo files of rpm - Allow mozilla_plugin to transition to itself - Allow certwatch to write to cert_t directories - New abrt application - Allow NetworkManager to set the kernel scheduler - Make wine_domain shared by all wine domains - Allow mdadm_t to read images labeled svirt_image_t - Allow amanda to read /dev/urand - ALlow my_print_default to read /dev/urand - Allow mdadm to write to kdumpctl fifo files - Allow nslcd to send signull to itself - Allow yppasswd to read /dev/urandom - Fix zarafa_setrlimit - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add additional alias for user_tmp_t because wine_tmp_t is no longer used - More handling of ther kernel keyring required by kerberos - New privs needed for init_t when running without transition to initrc_t over bin_t, and without unconfined domain installed- Dontaudit attempts by sosreport to read shadow_t - Allow browser sandbox plugins to connect to cups to print - Add new label mpd_home_t - Label /srv/www/logs as httpd_log_t - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add labels for apache logs under miq package - Allow irc_t to use tcp sockets - fix labels in puppet.if - Allow tcsd to read utmp file - Allow openshift_cron_t to run ssh-keygen in ssh_keygen_t to access host keys - Define svirt_socket_t as a domain_type - Take away transition from init_t to initrc_t when executing bin_t, allow init_t to run chk_passwd_t - Fix label on pam_krb5 helper apps- Allow ldconfig to write to kdumpctl fifo files - allow neutron to connect to amqp ports - Allow kdump_manage_crash to list the kdump_crash_t directory - Allow glance-api to connect to amqp port - Allow virt_qemu_ga_t to read meminfo - Add antivirus_home_t type for antivirus date in HOMEDIRS - Allow mpd setcap which is needed by pulseaudio - Allow smbcontrol to create content in /var/lib/samba - Allow mozilla_exec_t to be used as a entrypoint to mozilla_domtrans_spec - Add additional labeling for qemu-ga/fsfreeze-hook.d scripts - amanda_exec_t needs to be executable file - Allow block_suspend cap for samba-net - Allow apps that read ipsec_mgmt_var_run_t to search ipsec_var_run_t - Allow init_t to run crash utility - Treat usr_t just like bin_t for transitions and executions - Add port definition of pka_ca to port 829 for openshift - Allow selinux_store to use symlinks- Allow block_suspend cap for samba-net - Allow t-mission-control to manage gabble cache files - Allow nslcd to read /sys/devices/system/cpu - Allow selinux_store to use symlinks- Allow xdm_t to transition to itself - Call neutron interfaces instead of quantum - Allow init to change targed role to make uncofined services (xrdp which now has own systemd unit file) working. We want them to have in unconfined_t - Make sure directories in /run get created with the correct label - Make sure /root/.pki gets created with the right label - try to remove labeling for motion from zoneminder_exec_t to bin_t - Allow inetd_t to execute shell scripts - Allow cloud-init to read all domainstate - Fix to use quantum port - Add interface netowrkmanager_initrc_domtrans - Fix boinc_execmem - Allow t-mission-control to read gabble cache home - Add labeling for ~/.cache/telepathy/avatars/gabble - Allow memcache to read sysfs data - Cleanup antivirus policy and add additional fixes - Add boolean boinc_enable_execstack - Add support for couchdb in rabbitmq policy - Add interface couchdb_search_pid_dirs - Allow firewalld to read NM state - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files()- Split out rlogin ports from inetd - Treat files labeld as usr_t like bin_t when it comes to transitions - Allow staff_t to read login config - Allow ipsec_t to read .google authenticator data - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files() - Call the correct interface - corenet_udp_bind_ktalkd_port() - Allow all domains that can read gnome_config to read kde config - Allow sandbox domain to read/write mozilla_plugin_tmpfs_t so pulseaudio will work - Allow mdadm to getattr any file system - Allow a confined domain to executes mozilla_exec_t via dbus - Allow cupsd_lpd_t to bind to the printer port - Dontaudit attempts to bind to ports < 1024 when nis is turned on - Allow apache domain to connect to gssproxy socket - Allow rlogind to bind to the rlogin_port - Allow telnetd to bind to the telnetd_port - Allow ktalkd to bind to the ktalkd_port - Allow cvs to bind to the cvs_port- Cleanup related to init_domain()+inetd_domain fixes - Use just init_domain instead of init_daemon_domain in inetd_core_service_domain - svirt domains neeed to create kobject_uevint_sockets - Lots of new access required for sosreport - Allow tgtd_t to connect to isns ports - Allow init_t to transition to all inetd domains: - openct needs to be able to create netlink_object_uevent_sockets - Dontaudit leaks into ldconfig_t - Dontaudit su domains getattr on /dev devices, move su domains to attribute based calls - Move kernel_stream_connect into all Xwindow using users - Dontaudit inherited lock files in ifconfig o dhcpc_t- Also sock_file trans rule is needed in lsm - Fix labeling for fetchmail pid files/dirs - Add additional fixes for abrt-upload-watch - Fix polipo.te - Fix transition rules in asterisk policy - Add fowner capability to networkmanager policy - Allow polipo to connect to tor ports - Cleanup lsmd.if - Cleanup openhpid policy - Fix kdump_read_crash() interface - Make more domains as init domain - Fix cupsd.te - Fix requires in rpm_rw_script_inherited_pipes - Fix interfaces in lsm.if - Allow munin service plugins to manage own tmpfs files/dirs - Allow virtd_t also relabel unix stream sockets for virt_image_type - Make ktalk as init domain - Fix to define ktalkd_unit_file_t correctly - Fix ktalk.fc - Add systemd support for talk-server - Allow glusterd to create sock_file in /run - Allow xdm_t to delete gkeyringd_tmp_t files on logout - Add fixes for hypervkvp policy - Add logwatch_can_sendmail boolean - Allow mysqld_safe_t to handle also symlinks in /var/log/mariadb - Allow xdm_t to delete gkeyringd_tmp_t files on logout- Add selinux-policy-sandbox pkg0 - Allow rhsmcertd to read init state - Allow fsetid for pkcsslotd - Fix labeling for /usr/lib/systemd/system/pkcsslotd.service - Allow fetchmail to create own pid with correct labeling - Fix rhcs_domain_template() - Allow roles which can run mock to read mock lib files to view results - Allow rpcbind to use nsswitch - Fix lsm.if summary - Fix collectd_t can read /etc/passwd file - Label systemd unit files under dracut correctly - Add support for pam_mount to mount user's encrypted home When a user logs in and logs out using ssh - Add support for .Xauthority-n - Label umount.crypt as lvm_exec_t - Allow syslogd to search psad lib files - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files- Add policy for lsmd - Add support for /var/log/mariadb dir and allow mysqld_safe to list this directory - Update condor_master rules to allow read system state info and allow logging - Add labeling for /etc/condor and allow condor domain to write it (bug) - Allow condor domains to manage own logs - Allow glusterd to read domains state - Fix initial hypervkvp policy - Add policy for hypervkvpd - Fix redis.if summary- Allow boinc to connect to @/tmp/.X11-unix/X0 - Allow beam.smp to connect to tcp/5984 - Allow named to manage own log files - Add label for /usr/libexec/dcc/start-dccifd and domtrans to dccifd_t - Add virt_transition_userdomain boolean decl - Allow httpd_t to sendto unix_dgram sockets on its children - Allow nova domains to execute ifconfig - bluetooth wants to create fifo_files in /tmp - exim needs to be able to manage mailman data - Allow sysstat to getattr on all file systems - Looks like bluetoothd has moved - Allow collectd to send ping packets - Allow svirt_lxc domains to getpgid - Remove virt-sandbox-service labeling as virsh_exec_t, since it no longer does virsh_t stuff - Allow frpintd_t to read /dev/urandom - Allow asterisk_t to create sock_file in /var/run - Allow usbmuxd to use netlink_kobject - sosreport needs to getattr on lots of devices, and needs access to netlink_kobject_uevent_socket - More cleanup of svirt_lxc policy - virtd_lxc_t now talks to dbus - Dontaudit leaked ptmx_t - Allow processes to use inherited fifo files - Allow openvpn_t to connect to squid ports - Allow prelink_cron_system_t to ask systemd to reloaddd miscfiles_dontaudit_access_check_cert() - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files - Allow user roles to connect to the journal socket- selinux_set_enforce_mode needs to be used with type - Add append to the dontaudit for unix_stream_socket of xdm_t leak - Allow xdm_t to create symlinks in log direcotries - Allow login programs to read afs config - Label 10933 as a pop port, for dovecot - New policy to allow selinux_server.py to run as semanage_t as a dbus service - Add fixes to make netlabelctl working on MLS - AVCs required for running sepolicy gui as staff_t - Dontaudit attempts to read symlinks, sepolicy gui is likely to cause this type of AVC - New dbus server to be used with new gui - After modifying some files in /etc/mail, I saw this needed on the next boot - Loading a vm from /usr/tmp with virt-manager - Clean up oracleasm policy for Fedora - Add oracleasm policy written by rlopez@redhat.com - Make postfix_postdrop_t as mta_agent to allow domtrans to system mail if it is executed by apache - Add label for /var/crash - Allow fenced to domtrans to sanclok_t - Allow nagios to manage nagios spool files - Make tfptd as home_manager - Allow kdump to read kcore on MLS system - Allow mysqld-safe sys_nice/sys_resource caps - Allow apache to search automount tmp dirs if http_use_nfs is enabled - Allow crond to transition to named_t, for use with unbound - Allow crond to look at named_conf_t, for unbound - Allow mozilla_plugin_t to transition its home content - Allow dovecot_domain to read all system and network state - Allow httpd_user_script_t to call getpw - Allow semanage to read pid files - Dontaudit leaked file descriptors from user domain into thumb - Make PAM authentication working if it is enabled in ejabberd - Add fixes for rabbit to fix ##992920,#992931 - Allow glusterd to mount filesystems - Loading a vm from /usr/tmp with virt-manager - Trying to load a VM I got an AVC from devicekit_disk for loopcontrol device - Add fix for pand service - shorewall touches own log - Allow nrpe to list /var - Mozilla_plugin_roles can not be passed into lpd_run_lpr - Allow afs domains to read afs_config files - Allow login programs to read afs config - Allow virt_domain to read virt_var_run_t symlinks - Allow smokeping to send its process signals - Allow fetchmail to setuid - Add kdump_manage_crash() interface - Allow abrt domain to write abrt.socket- Add more aliases in pegasus.te - Add more fixes for *_admin interfaces - Add interface fixes - Allow nscd to stream connect to nmbd - Allow gnupg apps to write to pcscd socket - Add more fixes for openlmi provides. Fix naming and support for additionals - Allow fetchmail to resolve host names - Allow firewalld to interact also with lnk files labeled as firewalld_etc_rw_t - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te - Fix corecmd_exec_chroot() - Fix logging_relabel_syslog_pid_socket interface - Fix typo in unconfineduser.te - Allow system_r to access unconfined_dbusd_t to run hp_chec- Allow xdm_t to act as a dbus client to itsel - Allow fetchmail to resolve host names - Allow gnupg apps to write to pcscd socket - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te -httpd_t does access_check on certs- Add support for cmpiLMI_Service-cimprovagt - Allow pegasus domtrans to rpm_t to make pycmpiLMI_Software-cimprovagt running as rpm_t - Label pycmpiLMI_Software-cimprovagt as rpm_exec_t - Add support for pycmpiLMI_Storage-cimprovagt - Add support for cmpiLMI_Networking-cimprovagt - Allow system_cronjob_t to create user_tmpfs_t to make pulseaudio working - Allow virtual machines and containers to run as user doains, needed for virt-sandbox - Allow buglist.cgi to read cpu info- Allow systemd-tmpfile to handle tmp content in print spool dir - Allow systemd-sysctl to send system log messages - Add support for RTP media ports and fmpro-internal - Make auditd working if audit is configured to perform SINGLE action on disk error - Add interfaces to handle systemd units - Make systemd-notify working if pcsd is used - Add support for netlabel and label /usr/sbin/netlabelctl as iptables_exec_t - Instead of having all unconfined domains get all of the named transition rules, - Only allow unconfined_t, init_t, initrc_t and rpm_script_t by default. - Add definition for the salt ports - Allow xdm_t to create link files in xdm_var_run_t - Dontaudit reads of blk files or chr files leaked into ldconfig_t - Allow sys_chroot for useradd_t - Allow net_raw cap for ipsec_t - Allow sysadm_t to reload services - Add additional fixes to make strongswan working with a simple conf - Allow sysadm_t to enable/disable init_t services - Add additional glusterd perms - Allow apache to read lnk files in the /mnt directory - Allow glusterd to ask the kernel to load a module - Fix description of ftpd_use_fusefs boolean - Allow svirt_lxc_net_t to sys_chroot, modify policy to tighten up svirt_lxc_domain capabilties and process controls, but add them to svirt_lxc_net_t - Allow glusterds to request load a kernel module - Allow boinc to stream connect to xserver_t - Allow sblim domains to read /etc/passwd - Allow mdadm to read usb devices - Allow collectd to use ping plugin - Make foghorn working with SNMP - Allow sssd to read ldap certs - Allow haproxy to connect to RTP media ports - Add additional trans rules for aide_db - Add labeling for /usr/lib/pcsd/pcsd - Add labeling for /var/log/pcsd - Add support for pcs which is a corosync and pacemaker configuration tool- Label /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t - Add labeling for /usr/libexec/kde4/polkit-kde-authentication-agent-1 - Allow all domains that can domtrans to shutdown, to start the power services script to shutdown - consolekit needs to be able to shut down system - Move around interfaces - Remove nfsd_rw_t and nfsd_ro_t, they don't do anything - Add additional fixes for rabbitmq_beam to allow getattr on mountpoints - Allow gconf-defaults-m to read /etc/passwd - Fix pki_rw_tomcat_cert() interface to support lnk_files- Add support for gluster ports - Make sure that all keys located in /etc/ssh/ are labeled correctly - Make sure apcuspd lock files get created with the correct label - Use getcap in gluster.te - Fix gluster policy - add additional fixes to allow beam.smp to interact with couchdb files - Additional fix for #974149 - Allow gluster to user gluster ports - Allow glusterd to transition to rpcd_t and add additional fixes for #980683 - Allow tgtd working when accessing to the passthrough device - Fix labeling for mdadm unit files- Add mdadm fixes- Fix definition of sandbox.disabled to sandbox.pp.disabled- Allow mdamd to execute systemctl - Allow mdadm to read /dev/kvm - Allow ipsec_mgmt_t to read l2tpd pid content- Allow nsd_t to read /dev/urand - Allow mdadm_t to read framebuffer - Allow rabbitmq_beam_t to read process info on rabbitmq_epmd_t - Allow mozilla_plugin_config_t to create tmp files - Cleanup openvswitch policy - Allow mozilla plugin to getattr on all executables - Allow l2tpd_t to create fifo_files in /var/run - Allow samba to touch/manage fifo_files or sock_files in a samba_share_t directory - Allow mdadm to connecto its own unix_stream_socket - FIXME: nagios changed locations to /log/nagios which is wrong. But we need to have this workaround for now. - Allow apache to access smokeping pid files - Allow rabbitmq_beam_t to getattr on all filesystems - Add systemd support for iodined - Allow nup_upsdrvctl_t to execute its entrypoint - Allow fail2ban_client to write to fail2ban_var_run_t, Also allow it to use nsswitch - add labeling for ~/.cache/libvirt-sandbox - Add interface to allow domains transitioned to by confined users to send sigchld to screen program - Allow sysadm_t to check the system status of files labeled etc_t, /etc/fstab - Allow systemd_localed to start /usr/lib/systemd/system/systemd-vconsole-setup.service - Allow an domain that has an entrypoint from a type to be allowed to execute the entrypoint without a transition, I can see no case where this is a bad thing, and elminiates a whole class of AVCs. - Allow staff to getsched all domains, required to run htop - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Add prosody policy written by Michael Scherer - Allow nagios plugins to read /sys info - ntpd needs to manage own log files - Add support for HOME_DIR/.IBMERS - Allow iptables commands to read firewalld config - Allow consolekit_t to read utmp - Fix filename transitions on .razor directory - Add additional fixes to make DSPAM with LDA working - Allow snort to read /etc/passwd - Allow fail2ban to communicate with firewalld over dbus - Dontaudit openshift_cgreoup_file_t read/write leaked dev - Allow nfsd to use mountd port - Call th proper interface - Allow openvswitch to read sys and execute plymouth - Allow tmpwatch to read /var/spool/cups/tmp - Add support for /usr/libexec/telepathy-rakia - Add systemd support for zoneminder - Allow mysql to create files/directories under /var/log/mysql - Allow zoneminder apache scripts to rw zoneminder tmpfs - Allow httpd to manage zoneminder lib files - Add zoneminder_run_sudo boolean to allow to start zoneminder - Allow zoneminder to send mails - gssproxy_t sock_file can be under /var/lib - Allow web domains to connect to whois port. - Allow sandbox_web_type to connect to the same ports as mozilla_plugin_t. - We really need to add an interface to corenet to define what a web_client_domain is and - then define chrome_sandbox_t, mozilla_plugin_t and sandbox_web_type to that domain. - Add labeling for cmpiLMI_LogicalFile-cimprovagt - Also make pegasus_openlmi_logicalfile_t as unconfined to have unconfined_domain attribute for filename trans rules - Update policy rules for pegasus_openlmi_logicalfile_t - Add initial types for logicalfile/unconfined OpenLMI providers - mailmanctl needs to read own log - Allow logwatch manage own lock files - Allow nrpe to read meminfo - Allow httpd to read certs located in pki-ca - Add pki_read_tomcat_cert() interface - Add support for nagios openshift plugins - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Shrink the size of policy by moving to attributes, also add dridomain so that mozilla_plugin can follow selinuxuse_dri boolean. - Allow bootloader to manage generic log files - Allow ftp to bind to port 989 - Fix label of new gear directory - Add support for new directory /var/lib/openshift/gears/ - Add openshift_manage_lib_dirs() - allow virtd domains to manage setrans_var_run_t - Allow useradd to manage all openshift content - Add support so that mozilla_plugin_t can use dri devices - Allow chronyd to change the scheduler - Allow apmd to shut downthe system - Devicekit_disk_t needs to manage /etc/fstab- Make DSPAM to act as a LDA working - Allow ntop to create netlink socket - Allow policykit to send a signal to policykit-auth - Allow stapserver to dbus chat with avahi/systemd-logind - Fix labeling on haproxy unit file - Clean up haproxy policy - A new policy for haproxy and placed it to rhcs.te - Add support for ldirectord and treat it with cluster_t - Make sure anaconda log dir is created with var_log_t- Allow lvm_t to create default targets for filesystem handling - Fix labeling for razor-lightdm binaries - Allow insmod_t to read any file labeled var_lib_t - Add policy for pesign - Activate policy for cmpiLMI_Account-cimprovagt - Allow isnsd syscall=listen - /usr/libexec/pegasus/cimprovagt needs setsched caused by sched_setscheduler - Allow ctdbd to use udp/4379 - gatherd wants sys_nice and setsched - Add support for texlive2012 - Allow NM to read file_t (usb stick with no labels used to transfer keys for example) - Allow cobbler to execute apache with domain transition- condor_collector uses tcp/9000 - Label /usr/sbin/virtlockd as virtd_exec_t for now - Allow cobbler to execute ldconfig - Allow NM to execute ssh - Allow mdadm to read /dev/crash - Allow antivirus domains to connect to snmp port - Make amavisd-snmp working correctly - Allow nfsd_t to mounton nfsd_fs_t - Add initial snapper policy - We still need to have consolekit policy - Dontaudit firefox attempting to connect to the xserver_port_t if run within sandbox_web_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow dirsrv to read network state - Fix pki_read_tomcat_lib_files - Add labeling for /usr/libexec/nm-ssh-service - Add label cert_t for /var/lib/ipa/pki-ca/publish - Lets label /sys/fs/cgroup as cgroup_t for now, to keep labels consistant - Allow nfsd_t to mounton nfsd_fs_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow passwd_t to change role to system_r from unconfined_r- Don't audit access checks by sandbox xserver on xdb var_lib - Allow ntop to read usbmon devices - Add labeling for new polcykit authorizor - Dontaudit access checks from fail2ban_client - Don't audit access checks by sandbox xserver on xdb var_lib - Allow apps that connect to xdm stream to conenct to xdm_dbusd_t stream - Fix labeling for all /usr/bim/razor-lightdm-* binaries - Add filename trans for /dev/md126p1- Make vdagent able to request loading kernel module - Add support for cloud-init make it as unconfined domain - Allow snmpd to run smartctl in fsadm_t domain - remove duplicate openshift_search_lib() interface - Allow mysqld to search openshift lib files - Allow openshift cgroup to interact with passedin file descriptors - Allow colord to list directories inthe users homedir - aide executes prelink to check files - Make sure cupsd_t creates content in /etc/cups with the correct label - Lest dontaudit apache read all domains, so passenger will not cause this avc - Allow gssd to connect to gssproxy - systemd-tmpfiles needs to be able to raise the level to fix labeling on /run/setrans in MLS - Allow systemd-tmpfiles to relabel also lock files - Allow useradd to add homdir in /var/lib/openshift - Allow setfiles and semanage to write output to /run/files- Add labeling for /dev/tgt - Dontaudit leak fd from firewalld for modprobe - Allow runuser running as rpm_script_t to create netlink_audit socket - Allow mdadm to read BIOS non-volatile RAM- accountservice watches when accounts come and go in wtmp - /usr/java/jre1.7.0_21/bin/java needs to create netlink socket - Add httpd_use_sasl boolean - Allow net_admin for tuned_t - iscsid needs sys_module to auto-load kernel modules - Allow blueman to read bluetooth conf - Add nova_manage_lib_files() interface - Fix mplayer_filetrans_home_content() - Add mplayer_filetrans_home_content() - mozilla_plugin_config_roles need to be able to access mozilla_plugin_config_t - Revert "Allow thumb_t to append inherited xdm stream socket" - Add iscsi_filetrans_named_content() interface - Allow to create .mplayer with the correct labeling for unconfined - Allow iscsiadmin to create lock file with the correct labeling- Allow wine to manage wine home content - Make amanda working with socket actiovation - Add labeling for /usr/sbin/iscsiadm - Add support for /var/run/gssproxy.sock - dnsmasq_t needs to read sysctl_net_t- Fix courier_domain_template() interface - Allow blueman to write ip_forward - Allow mongodb to connect to mongodb port - Allow mongodb to connect to mongodb port - Allow java to bind jobss_debug port - Fixes for *_admin interfaces - Allow iscsid auto-load kernel modules needed for proper iSCSI functionality - Need to assign attribute for courier_domain to all courier_domains - Fail2ban reads /etc/passwd - postfix_virtual will create new files in postfix_spool_t - abrt triggers sys_ptrace by running pidof - Label ~/abc as mozilla_home_t, since java apps as plugin want to create it - Add passenger fixes needed by foreman - Remove dup interfaces - Add additional interfaces for quantum - Add new interfaces for dnsmasq - Allow passenger to read localization and send signull to itself - Allow dnsmasq to stream connect to quantum - Add quantum_stream_connect() - Make sure that mcollective starts the service with the correct labeling - Add labels for ~/.manpath - Dontaudit attempts by svirt_t to getpw* calls - sandbox domains are trying to look at parent process data - Allow courior auth to create its pid file in /var/spool/courier subdir - Add fixes for beam to have it working with couchdb - Add labeling for /run/nm-xl2tpd.con - Allow apache to stream connect to thin - Add systemd support for amand - Make public types usable for fs mount points - Call correct mandb interface in domain.te - Allow iptables to r/w quantum inherited pipes and send sigchld - Allow ifconfig domtrans to iptables and execute ldconfig - Add labels for ~/.manpath - Allow systemd to read iscsi lib files - seunshare is trying to look at parent process data- Fix openshift_search_lib - Add support for abrt-uefioops-oops - Allow colord to getattr any file system - Allow chrome processes to look at each other - Allow sys_ptrace for abrt_t - Add new policy for gssproxy - Dontaudit leaked file descriptor writes from firewalld - openshift_net_type is interface not template - Dontaudit pppd to search gnome config - Update openshift_search_lib() interface - Add fs_list_pstorefs() - Fix label on libbcm_host.so since it is built incorrectly on raspberry pi, needs back port to F18 - Better labels for raspberry pi devices - Allow init to create devpts_t directory - Temporarily label rasbery pi devices as memory_device_t, needs back port to f18 - Allow sysadm_t to build kernels - Make sure mount creates /var/run/blkid with the correct label, needs back port to F18 - Allow userdomains to stream connect to gssproxy - Dontaudit leaked file descriptor writes from firewalld - Allow xserver to read /dev/urandom - Add additional fixes for ipsec-mgmt - Make SSHing into an Openshift Enterprise Node working- Add transition rules to unconfined domains and to sysadm_t to create /etc/adjtime - with the proper label. - Update files_filetrans_named_content() interface to get right labeling for pam.d conf files - Allow systemd-timedated to create adjtime - Add clock_create_adjtime() - Additional fix ifconfing for #966106 - Allow kernel_t to create boot.log with correct labeling - Remove unconfined_mplayer for which we don't have rules - Rename interfaces - Add userdom_manage_user_home_files/dirs interfaces - Fix files_dontaudit_read_all_non_security_files - Fix ipsec_manage_key_file() - Fix ipsec_filetrans_key_file() - Label /usr/bin/razor-lightdm-greeter as xdm_exec_t instead of spamc_exec_t - Fix labeling for ipse.secrets - Add interfaces for ipsec and labeling for ipsec.info and ipsec_setup.pid - Add files_dontaudit_read_all_non_security_files() interface - /var/log/syslog-ng should be labeled var_log_t - Make ifconfig_var_run_t a mountpoint - Add transition from ifconfig to dnsmasq - Allow ifconfig to execute bin_t/shell_exec_t - We want to have hwdb.bin labeled as etc_t - update logging_filetrans_named_content() interface - Allow systemd_timedate_t to manage /etc/adjtime - Allow NM to send signals to l2tpd - Update antivirus_can_scan_system boolean - Allow devicekit_disk_t to sys_config_tty - Run abrt-harvest programs as abrt_t, and allow abrt_t to list all filesystem directories - Make printing from vmware working - Allow php-cgi from php54 collection to access /var/lib/net-snmp/mib_indexes - Add virt_qemu_ga_data_t for qemu-ga - Make chrome and mozilla able to connect to same ports, add jboss_management_port_t to both - Fix typo in virt.te - Add virt_qemu_ga_unconfined_t for hook scripts - Make sure NetworkManager files get created with the correct label - Add mozilla_plugin_use_gps boolean - Fix cyrus to have support for net-snmp - Additional fixes for dnsmasq and quantum for #966106 - Add plymouthd_create_log() - remove httpd_use_oddjob for which we don't have rules - Add missing rules for httpd_can_network_connect_cobbler - Add missing cluster_use_execmem boolean - Call userdom_manage_all_user_home_type_files/dirs - Additional fix for ftp_home_dir - Fix ftp_home_dir boolean - Allow squit to recv/send client squid packet - Fix nut.te to have nut_domain attribute - Add support for ejabberd; TODO: revisit jabberd and rabbit policy - Fix amanda policy - Add more fixes for domains which use libusb - Make domains which use libusb working correctly - Allow l2tpd to create ipsec key files with correct labeling and manage them - Fix cobbler_manage_lib_files/cobbler_read_lib_files to cover also lnk files - Allow rabbitmq-beam to bind generic node - Allow l2tpd to read ipse-mgmt pid files - more fixes for l2tpd, NM and pppd from #967072- Dontaudit to getattr on dirs for dovecot-deliver - Allow raiudusd server connect to postgresql socket - Add kerberos support for radiusd - Allow saslauthd to connect to ldap port - Allow postfix to manage postfix_private_t files - Add chronyd support for #965457 - Fix labeling for HOME_DIR/\.icedtea - CHange squid and snmpd to be allowed also write own logs - Fix labeling for /usr/libexec/qemu-ga - Allow virtd_t to use virt_lock_t - Allow also sealert to read the policy from the kernel - qemu-ga needs to execute scripts in /usr/libexec/qemu-ga and to use /tmp content - Dontaudit listing of users homedir by sendmail Seems like a leak - Allow passenger to transition to puppet master - Allow apache to connect to mythtv - Add definition for mythtv ports- Add additional fixes for #948073 bug - Allow sge_execd_t to also connect to sge ports - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow sge_execd to bind sge ports. Allow kill capability and reads cgroup files - Remove pulseaudio filetrans pulseaudio_manage_home_dirs which is a part of pulseaudio_manage_home_files - Add networkmanager_stream_connect() - Make gnome-abrt wokring with staff_t - Fix openshift_manage_lib_files() interface - mdadm runs ps command which seems to getattr on random log files - Allow mozilla_plugin_t to create pulseaudit_home_t directories - Allow qemu-ga to shutdown virtual hosts - Add labelling for cupsd-browsed - Add web browser plugins to connect to aol ports - Allow nm-dhcp-helper to stream connect to NM - Add port definition for sge ports- Make sure users and unconfined domains create .hushlogin with the correct label - Allow pegaus to chat with realmd over DBus - Allow cobblerd to read network state - Allow boicn-client to stat on /dev/input/mice - Allow certwatch to read net_config_t when it executes apache - Allow readahead to create /run/systemd and then create its own directory with the correct label- Transition directories and files when in a user_tmp_t directory - Change certwatch to domtrans to apache instead of just execute - Allow virsh_t to read xen lib files - update policy rules for pegasus_openlmi_account_t - Add support for svnserve_tmp_t - Activate account openlmi policy - pegasus_openlmi_domain_template needs also require pegasus_t - One more fix for policykit.te - Call fs_list_cgroups_dirs() in policykit.te - Allow nagios service plugin to read mysql config files - Add labeling for /var/svn - Fix chrome.te - Fix pegasus_openlmi_domain_template() interfaces - Fix dev_rw_vfio_dev definiton, allow virtd_t to read tmpfs_t symlinks - Fix location of google-chrome data - Add support for chome_sandbox to store content in the homedir - Allow policykit to watch for changes in cgroups file system - Add boolean to allow mozilla_plugin_t to use spice - Allow collectd to bind to udp port - Allow collected_t to read all of /proc - Should use netlink socket_perms - Should use netlink socket_perms - Allow glance domains to connect to apache ports - Allow apcupsd_t to manage its log files - Allow chrome objects to rw_inherited unix_stream_socket from callers - Allow staff_t to execute virtd_exec_t for running vms - nfsd_t needs to bind mountd port to make nfs-mountd.service working - Allow unbound net_admin capability because of setsockopt syscall - Fix fs_list_cgroup_dirs() - Label /usr/lib/nagios/plugins/utils.pm as bin_t - Remove uplicate definition of fs_read_cgroup_files() - Remove duplicate definition of fs_read_cgroup_files() - Add files_mountpoint_filetrans interface to be used by quotadb_t and snapperd - Additional interfaces needed to list and read cgroups config - Add port definition for collectd port - Add labels for /dev/ptp* - Allow staff_t to execute virtd_exec_t for running vms- Allow samba-net to also read realmd tmp files - Allow NUT to use serial ports - realmd can be started by systemctl now- Remove userdom_home_manager for xdm_t and move all rules to xserver.te directly - Add new xdm_write_home boolean to allow xdm_t to create files in HOME dirs with xdm_home_t - Allow postfix-showq to read/write unix.showq in /var/spool/postfix/pid - Allow virsh to read xen lock file - Allow qemu-ga to create files in /run with proper labeling - Allow glusterd to connect to own socket in /tmp - Allow glance-api to connect to http port to make glance image-create working - Allow keystonte_t to execute rpm- Fix realmd cache interfaces- Allow tcpd to execute leafnode - Allow samba-net to read realmd cache files - Dontaudit sys_tty_config for alsactl - Fix allow rules for postfix_var_run - Allow cobblerd to read /etc/passwd - Allow pegasus to read exports - Allow systemd-timedate to read xdm state - Allow mout to stream connect to rpcbind - Add labeling just for /usr/share/pki/ca-trust-source instead of /usr/share/pki- Allow thumbnails to share memory with apps which run thumbnails - Allow postfix-postqueue block_suspend - Add lib interfaces for smsd - Add support for nginx - Allow s2s running as jabberd_t to connect to jabber_interserver_port_t - Allow pki apache domain to create own tmp files and execute httpd_suexec - Allow procmail to manger user tmp files/dirs/lnk_files - Add virt_stream_connect_svirt() interface - Allow dovecot-auth to execute bin_t - Allow iscsid to request that kernel load a kernel module - Add labeling support for /var/lib/mod_security - Allow iw running as tuned_t to create netlink socket - Dontaudit sys_tty_config for thumb_t - Add labeling for nm-l2tp-service - Allow httpd running as certwatch_t to open tcp socket - Allow useradd to manager smsd lib files - Allow useradd_t to add homedirs in /var/lib - Fix typo in userdomain.te - Cleanup userdom_read_home_certs - Implement userdom_home_reader_certs_type to allow read certs also on encrypt /home with ecryptfs_t - Allow staff to stream connect to svirt_t to make gnome-boxes working- Allow lvm to create its own unit files - Label /var/lib/sepolgen as selinux_config_t - Add filetrans rules for tw devices - Add transition from cupsd_config_t to cupsd_t- Add filetrans rules for tw devices - Cleanup bad transition lines- Fix lockdev_manage_files() - Allow setroubleshootd to read var_lib_t to make email_alert working - Add lockdev_manage_files() - Call proper interface in virt.te - Allow gkeyring_domain to create /var/run/UID/config/dbus file - system dbus seems to be blocking suspend - Dontaudit attemps to sys_ptrace, which I believe gpsd does not need - When you enter a container from root, you generate avcs with a leaked file descriptor - Allow mpd getattr on file system directories - Make sure realmd creates content with the correct label - Allow systemd-tty-ask to write kmsg - Allow mgetty to use lockdev library for device locking - Fix selinuxuser_user_share_music boolean name to selinuxuser_share_music - When you enter a container from root, you generate avcs with a leaked file descriptor - Make sure init.fc files are labeled correctly at creation - File name trans vconsole.conf - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow certmonger to dbus communicate with realmd - Make realmd working- Fix mozilla specification of homedir content - Allow certmonger to read network state - Allow tmpwatch to read tmp in /var/spool/{cups,lpd} - Label all nagios plugin as unconfined by default - Add httpd_serve_cobbler_files() - Allow mdadm to read /dev/sr0 and create tmp files - Allow certwatch to send mails - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow realmd to run ipa, really needs to be an unconfined_domain - Allow sandbox domains to use inherted terminals - Allow pscd to use devices labeled svirt_image_t in order to use cat cards. - Add label for new alsa pid - Alsa now uses a pid file and needs to setsched - Fix oracleasmfs_t definition - Add support for sshd_unit_file_t - Add oracleasmfs_t - Allow unlabeled_t files to be stored on unlabeled_t filesystems- Fix description of deny_ptrace boolean - Remove allow for execmod lib_t for now - Allow quantum to connect to keystone port - Allow nova-console to talk with mysql over unix stream socket - Allow dirsrv to stream connect to uuidd - thumb_t needs to be able to create ~/.cache if it does not exist - virtd needs to be able to sys_ptrace when starting and stoping containers- Allow alsa_t signal_perms, we probaly should search for any app that can execute something without transition and give it signal_perms... - Add dontaudit for mozilla_plugin_t looking at the xdm_t sockets - Fix deny_ptrace boolean, certain ptrace leaked into the system - Allow winbind to manage kerberos_rcache_host - Allow spamd to create spamd_var_lib_t directories - Remove transition to mozilla_tmp_t by mozilla_t, to allow it to manage the users tmp dirs - Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Call snmp_manage_var_lib_files(fogorn_t) instead of snmp_manage_var_dirs - Fix vmware_role() interface - Fix cobbler_manage_lib_files() interface - Allow nagios check disk plugins to execute bin_t - Allow quantum to transition to openvswitch_t - Allow postdrop to stream connect to postfix-master - Allow quantum to stream connect to openvswitch - Add xserver_dontaudit_xdm_rw_stream_sockets() interface - Allow daemon to send dgrams to initrc_t - Allow kdm to start the power service to initiate a reboot or poweroff- Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Don't audit attempts to write to stream socket of nscld by thumbnailers - Allow git_system_t to read network state - Allow pegasas to execute mount command - Fix desc for drdb_admin - Fix condor_amin() - Interface fixes for uptime, vdagent, vnstatd - Fix labeling for moodle in /var/www/moodle/data - Add interface fixes - Allow bugzilla to read certs - /var/www/moodle needs to be writable by apache - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Fix namespace_init_t to create content with proper labels, and allow it to manage all user content - Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Fix sys_nice for cups_domain - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Kernel_t needs mac_admin in order to support labeled NFS - Fix systemd_dontaudit_dbus_chat() interface - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Allow consolehelper domain to write Xauth files in /root - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Allow consolehelper more access discovered by Tom London - Allow fsdaemon to send signull to all domain - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Fix file_contexts.subs to label /run/lock correctly- Try to label on controlC devices up to 30 correctly - Add mount_rw_pid_files() interface - Add additional mount/umount interfaces needed by mock - fsadm_t sends audit messages in reads kernel_ipc_info when doing livecd-iso-to-disk - Fix tabs - Allow initrc_domain to search rgmanager lib files - Add more fixes which make mock working together with confined users * Allow mock_t to manage rpm files * Allow mock_t to read rpm log files * Allow mock to setattr on tmpfs, devpts * Allow mount/umount filesystems - Add rpm_read_log() interface - yum-cron runs rpm from within it. - Allow tuned to transition to dmidecode - Allow firewalld to do net_admin - Allow mock to unmont tmpfs_t - Fix virt_sigkill() interface - Add additional fixes for mock. Mainly caused by mount running in mock_t - Allow mock to write sysfs_t and mount pid files - Add mailman_domain to mailman_template() - Allow openvswitch to execute shell - Allow qpidd to use kerberos - Allow mailman to use fusefs, needs back port to RHEL6 - Allow apache and its scripts to use anon_inodefs - Add alias for git_user_content_t and git_sys_content_t so that RHEL6 will update to RHEL7 - Realmd needs to connect to samba ports, needs back port to F18 also - Allow colord to read /run/initial-setup- - Allow sanlock-helper to send sigkill to virtd which is registred to sanlock - Add virt_kill() interface - Add rgmanager_search_lib() interface - Allow wdmd to getattr on all filesystems. Back ported from RHEL6- Allow realmd to create tmp files - FIx ircssi_home_t type to irssi_home_t - Allow adcli running as realmd_t to connect to ldap port - Allow NetworkManager to transition to ipsec_t, for running strongswan - Make openshift_initrc_t an lxc_domain - Allow gssd to manage user_tmp_t files - Fix handling of irclogs in users homedir - Fix labeling for drupal an wp-content in subdirs of /var/www/html - Allow abrt to read utmp_t file - Fix openshift policy to transition lnk_file, sock-file an fifo_file when created in a tmpfs_t, needs back port to RHEL6 - fix labeling for (oo|rhc)-restorer-wrapper.sh - firewalld needs to be able to write to network sysctls - Fix mozilla_plugin_dontaudit_rw_sem() interface - Dontaudit generic ipc read/write to a mozilla_plugin for sandbox_x domains - Add mozilla_plugin_dontaudit_rw_sem() interface - Allow svirt_lxc_t to transition to openshift domains - Allow condor domains block_suspend and dac_override caps - Allow condor_master to read passd - Allow condor_master to read system state - Allow NetworkManager to transition to ipsec_t, for running strongswan - Lots of access required by lvm_t to created encrypted usb device - Allow xdm_t to dbus communicate with systemd_localed_t - Label strongswan content as ipsec_exec_mgmt_t for now - Allow users to dbus chat with systemd_localed - Fix handling of .xsession-errors in xserver.if, so kde will work - Might be a bug but we are seeing avc's about people status on init_t:service - Make sure we label content under /var/run/lock as <> - Allow daemon and systemprocesses to search init_var_run_t directory - Add boolean to allow xdm to write xauth data to the home directory - Allow mount to write keys for the unconfined domain - Add unconfined_write_keys() interface- Add labeling for /usr/share/pki - Allow programs that read var_run_t symlinks also read var_t symlinks - Add additional ports as mongod_port_t for 27018, 27019, 28017, 28018 and 28019 ports - Fix labeling for /etc/dhcp directory - add missing systemd_stub_unit_file() interface - Add files_stub_var() interface - Add lables for cert_t directories - Make localectl set-x11-keymap working at all - Allow abrt to manage mock build environments to catch build problems. - Allow virt_domains to setsched for running gdb on itself - Allow thumb_t to execute user home content - Allow pulseaudio running as mozilla_plugin_t to read /run/systemd/users/1000 - Allow certwatch to execut /usr/bin/httpd - Allow cgred to send signal perms to itself, needs back port to RHEL6 - Allow openshift_cron_t to look at quota - Allow cups_t to read inhered tmpfs_t from the kernel - Allow yppasswdd to use NIS - Tuned wants sys_rawio capability - Add ftpd_use_fusefs boolean - Allow dirsrvadmin_t to signal itself- Allow localectl to read /etc/X11/xorg.conf.d directory - Revert "Revert "Fix filetrans rules for kdm creates .xsession-errors"" - Allow mount to transition to systemd_passwd_agent - Make sure abrt directories are labeled correctly - Allow commands that are going to read mount pid files to search mount_var_run_t - label /usr/bin/repoquery as rpm_exec_t - Allow automount to block suspend - Add abrt_filetrans_named_content so that abrt directories get labeled correctly - Allow virt domains to setrlimit and read file_context- Allow nagios to manage nagios spool files - /var/spool/snmptt is a directory which snmdp needs to write to, needs back port to RHEL6 - Add swift_alias.* policy files which contain typealiases for swift types - Add support for /run/lock/opencryptoki - Allow pkcsslotd chown capability - Allow pkcsslotd to read passwd - Add rsync_stub() interface - Allow systemd_timedate also manage gnome config homedirs - Label /usr/lib64/security/pam_krb5/pam_krb5_cchelper as bin_t - Fix filetrans rules for kdm creates .xsession-errors - Allow sytemd_tmpfiles to create wtmp file - Really should not label content under /var/lock, since it could have labels on it different from var_lock_t - Allow systemd to list all file system directories - Add some basic stub interfaces which will be used in PRODUCT policies- Fix log transition rule for cluster domains - Start to group all cluster log together - Dont use filename transition for POkemon Advanced Adventure until a new checkpolicy update - cups uses usbtty_device_t devices - These fixes were all required to build a MLS virtual Machine with single level desktops - Allow domains to transiton using httpd_exec_t - Allow svirt domains to manage kernel key rings - Allow setroubleshoot to execute ldconfig - Allow firewalld to read generate gnome data - Allow bluetooth to read machine-info - Allow boinc domain to send signal to itself - Fix gnome_filetrans_home_content() interface - Allow mozilla_plugins to list apache modules, for use with gxine - Fix labels for POkemon in the users homedir - Allow xguest to read mdstat - Dontaudit virt_domains getattr on /dev/* - These fixes were all required to build a MLS virtual Machine with single level desktops - Need to back port this to RHEL6 for openshift - Add tcp/8891 as milter port - Allow nsswitch domains to read sssd_var_lib_t files - Allow ping to read network state. - Fix typo - Add labels to /etc/X11/xorg.d and allow systemd-timestampd_t to manage them- Adopt swift changes from lhh@redhat.com - Add rhcs_manage_cluster_pid_files() interface - Allow screen domains to configure tty and setup sock_file in ~/.screen directory - ALlow setroubleshoot to read default_context_t, needed to backport to F18 - Label /etc/owncloud as being an apache writable directory - Allow sshd to stream connect to an lxc domain- Allow postgresql to manage rgmanager pid files - Allow postgresql to read ccs data - Allow systemd_domain to send dbus messages to policykit - Add labels for /etc/hostname and /etc/machine-info and allow systemd-hostnamed to create them - All systemd domains that create content are reading the file_context file and setfscreate - Systemd domains need to search through init_var_run_t - Allow sshd to communicate with libvirt to set containers labels - Add interface to manage pid files - Allow NetworkManger_t to read /etc/hostname - Dontaudit leaked locked files into openshift_domains - Add fixes for oo-cgroup-read - it nows creates tmp files - Allow gluster to manage all directories as well as files - Dontaudit chrome_sandbox_nacl_t using user terminals - Allow sysstat to manage its own log files - Allow virtual machines to setrlimit and send itself signals. - Add labeling for /var/run/hplip- Fix POSTIN scriptlet- Merge rgmanger, corosync,pacemaker,aisexec policies to cluster_t in rhcs.pp- Fix authconfig.py labeling - Make any domains that write homedir content do it correctly - Allow glusterd to read/write anyhwere on the file system by default - Be a little more liberal with the rsync log files - Fix iscsi_admin interface - Allow iscsid_t to read /dev/urand - Fix up iscsi domain for use with unit files - Add filename transition support for spamassassin policy - Allow web plugins to use badly formated libraries - Allow nmbd_t to create samba_var_t directories - Add filename transition support for spamassassin policy - Add filename transition support for tvtime - Fix alsa_home_filetrans_alsa_home() interface - Move all userdom_filetrans_home_content() calling out of booleans - Allow logrotote to getattr on all file sytems - Remove duplicate userdom_filetrans_home_content() calling - Allow kadmind to read /etc/passwd - Dontaudit append .xsession-errors file on ecryptfs for policykit-auth - Allow antivirus domain to manage antivirus db links - Allow logrotate to read /sys - Allow mandb to setattr on man dirs - Remove mozilla_plugin_enable_homedirs boolean - Fix ftp_home_dir boolean - homedir mozilla filetrans has been moved to userdom_home_manager - homedir telepathy filetrans has been moved to userdom_home_manager - Remove gnome_home_dir_filetrans() from gnome_role_gkeyringd() - Might want to eventually write a daemon on fusefsd. - Add policy fixes for sshd [net] child from plautrba@redhat.com - Tor uses a new port - Remove bin_t for authconfig.py - Fix so only one call to userdom_home_file_trans - Allow home_manager_types to create content with the correctl label - Fix all domains that write data into the homedir to do it with the correct label - Change the postgresql to use proper boolean names, which is causing httpd_t to - not get access to postgresql_var_run_t - Hostname needs to send syslog messages - Localectl needs to be able to send dbus signals to users - Make sure userdom_filetrans_type will create files/dirs with user_home_t labeling by default - Allow user_home_manger domains to create spam* homedir content with correct labeling - Allow user_home_manger domains to create HOMEDIR/.tvtime with correct labeling - Add missing miscfiles_setattr_man_pages() interface and for now comment some rules for userdom_filetrans_type to make build process working - Declare userdom_filetrans_type attribute - userdom_manage_home_role() needs to be called withoout usertype attribute because of userdom_filetrans_type attribute - fusefsd is mounding a fuse file system on /run/user/UID/gvfs- Man pages are now generated in the build process - Allow cgred to list inotifyfs filesystem- Allow gluster to get attrs on all fs - New access required for virt-sandbox - Allow dnsmasq to execute bin_t - Allow dnsmasq to create content in /var/run/NetworkManager - Fix openshift_initrc_signal() interface - Dontaudit openshift domains doing getattr on other domains - Allow consolehelper domain to communicate with session bus - Mock should not be transitioning to any other domains, we should keep mock_t as mock_t - Update virt_qemu_ga_t policy - Allow authconfig running from realmd to restart oddjob service - Add systemd support for oddjob - Add initial policy for realmd_consolehelper_t which if for authconfig executed by realmd - Add labeling for gnashpluginrc - Allow chrome_nacl to execute /dev/zero - Allow condor domains to read /proc - mozilla_plugin_t will getattr on /core if firefox crashes - Allow condor domains to read /etc/passwd - Allow dnsmasq to execute shell scripts, openstack requires this access - Fix glusterd labeling - Allow virtd_t to interact with the socket type - Allow nmbd_t to override dac if you turned on sharing all files - Allow tuned to created kobject_uevent socket - Allow guest user to run fusermount - Allow openshift to read /proc and locale - Allow realmd to dbus chat with rpm - Add new interface for virt - Remove depracated interfaces - Allow systemd_domains read access on etc, etc_runtime and usr files, also allow them to connect stream to syslog socket - /usr/share/munin/plugins/plugin.sh should be labeled as bin_t - Remove some more unconfined_t process transitions, that I don't believe are necessary - Stop transitioning uncofnined_t to checkpc - dmraid creates /var/lock/dmraid - Allow systemd_localed to creatre unix_dgram_sockets - Allow systemd_localed to write kernel messages. - Also cleanup systemd definition a little. - Fix userdom_restricted_xwindows_user_template() interface - Label any block devices or char devices under /dev/infiniband as fixed_disk_device_t - User accounts need to dbus chat with accountsd daemon - Gnome requires all users to be able to read /proc/1/- virsh now does a setexeccon call - Additional rules required by openshift domains - Allow svirt_lxc_domains to use inherited terminals, needed to make virt-sandbox-service execute work - Allow spamd_update_t to search spamc_home_t - Avcs discovered by mounting an isci device under /mnt - Allow lspci running as logrotate to read pci.ids - Additional fix for networkmanager_read_pid_files() - Fix networkmanager_read_pid_files() interface - Allow all svirt domains to connect to svirt_socket_t - Allow virsh to set SELinux context for a process. - Allow tuned to create netlink_kobject_uevent_socket - Allow systemd-timestamp to set SELinux context - Add support for /var/lib/systemd/linger - Fix ssh_sysadm_login to be working on MLS as expected- Rename files_rw_inherited_tmp_files to files_rw_inherited_tmp_file - Add missing files_rw_inherited_tmp_files interface - Add additional interface for ecryptfs - ALlow nova-cert to connect to postgresql - Allow keystone to connect to postgresql - Allow all cups domains to getattr on filesystems - Allow pppd to send signull - Allow tuned to execute ldconfig - Allow gpg to read fips_enabled - Add additional fixes for ecryptfs - Allow httpd to work with posgresql - Allow keystone getsched and setsched- Allow gpg to read fips_enabled - Add support for /var/cache/realmd - Add support for /usr/sbin/blazer_usb and systemd support for nut - Add labeling for fenced_sanlock and allow sanclok transition to fenced_t - bitlbee wants to read own log file - Allow glance domain to send a signal itself - Allow xend_t to request that the kernel load a kernel module - Allow pacemaker to execute heartbeat lib files - cleanup new swift policy- Fix smartmontools - Fix userdom_restricted_xwindows_user_template() interface - Add xserver_xdm_ioctl_log() interface - Allow Xusers to ioctl lxdm.log to make lxdm working - Add MLS fixes to make MLS boot/log-in working - Add mls_socket_write_all_levels() also for syslogd - fsck.xfs needs to read passwd - Fix ntp_filetrans_named_content calling in init.te - Allow postgresql to create pg_log dir - Allow sshd to read rsync_data_t to make rsync working - Change ntp.conf to be labeled net_conf_t - Allow useradd to create homedirs in /run. ircd-ratbox does this and we should just allow it - Allow xdm_t to execute gstreamer home content - Allod initrc_t and unconfined domains, and sysadm_t to manage ntp - New policy for openstack swift domains - More access required for openshift_cron_t - Use cupsd_log_t instead of cupsd_var_log_t - rpm_script_roles should be used in rpm_run - Fix rpm_run() interface - Fix openshift_initrc_run() - Fix sssd_dontaudit_stream_connect() interface - Fix sssd_dontaudit_stream_connect() interface - Allow LDA's job to deliver mail to the mailbox - dontaudit block_suspend for mozilla_plugin_t - Allow l2tpd_t to all signal perms - Allow uuidgen to read /dev/random - Allow mozilla-plugin-config to read power_supply info - Implement cups_domain attribute for cups domains - We now need access to user terminals since we start by executing a command outside the tty - We now need access to user terminals since we start by executing a command outside the tty - svirt lxc containers want to execute userhelper apps, need these changes to allow this to happen - Add containment of openshift cron jobs - Allow system cron jobs to create tmp directories - Make userhelp_conf_t a config file - Change rpm to use rpm_script_roles - More fixes for rsync to make rsync wokring - Allow logwatch to domtrans to mdadm - Allow pacemaker to domtrans to ifconfig - Allow pacemaker to setattr on corosync.log - Add pacemaker_use_execmem for memcheck-amd64 command - Allow block_suspend capability - Allow create fifo_file in /tmp with pacemaker_tmp_t - Allow systat to getattr on fixed disk - Relabel /etc/ntp.conf to be net_conf_t - ntp_admin should create files in /etc with the correct label - Add interface to create ntp_conf_t files in /etc - Add additional labeling for quantum - Allow quantum to execute dnsmasq with transition- boinc_cliean wants also execmem as boinc projecs have - Allow sa-update to search admin home for /root/.spamassassin - Allow sa-update to search admin home for /root/.spamassassin - Allow antivirus domain to read net sysctl - Dontaudit attempts from thumb_t to connect to ssd - Dontaudit attempts by readahead to read sock_files - Dontaudit attempts by readahead to read sock_files - Create tmpfs file while running as wine as user_tmpfs_t - Dontaudit attempts by readahead to read sock_files - libmpg ships badly created librarie- Change ssh_use_pts to use macro and only inherited sshd_devpts_t - Allow confined users to read systemd_logind seat information - libmpg ships badly created libraries - Add support for strongswan.service - Add labeling for strongswan - Allow l2tpd_t to read network manager content in /run directory - Allow rsync to getattr any file in rsync_data_t - Add labeling and filename transition for .grl-podcasts- mount.glusterfs executes glusterfsd binary - Allow systemd_hostnamed_t to stream connect to systemd - Dontaudit any user doing a access check - Allow obex-data-server to request the kernel to load a module - Allow gpg-agent to manage gnome content (~/.cache/gpg-agent-info) - Allow gpg-agent to read /proc/sys/crypto/fips_enabled - Add new types for antivirus.pp policy module - Allow gnomesystemmm_t caps because of ioprio_set - Make sure if mozilla_plugin creates files while in permissive mode, they get created with the correct label, user_home_t - Allow gnomesystemmm_t caps because of ioprio_set - Allow NM rawip socket - files_relabel_non_security_files can not be used with boolean - Add interface to thumb_t dbus_chat to allow it to read remote process state - ALlow logrotate to domtrans to mdadm_t - kde gnomeclock wants to write content to /tmp- kde gnomeclock wants to write content to /tmp - /usr/libexec/kde4/kcmdatetimehelper attempts to create /root/.kde - Allow blueman_t to rwx zero_device_t, for some kind of jre - Allow mozilla_plugin_t to rwx zero_device_t, for some kind of jre - Ftp full access should be allowed to create directories as well as files - Add boolean to allow rsync_full_acces, so that an rsync server can write all - over the local machine - logrotate needs to rotate logs in openshift directories, needs back port to RHEL6 - Add missing vpnc_roles type line - Allow stapserver to write content in /tmp - Allow gnome keyring to create keyrings dir in ~/.local/share - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Add interface to colord_t dbus_chat to allow it to read remote process state - Allow colord_t to read cupsd_t state - Add mate-thumbnail-font as thumnailer - Allow sectoolm to sys_ptrace since it is looking at other proceses /proc data. - Allow qpidd to list /tmp. Needed by ssl - Only allow init_t to transition to rsync_t domain, not initrc_t. This should be back ported to F17, F18 - - Added systemd support for ksmtuned - Added booleans ksmtuned_use_nfs ksmtuned_use_cifs - firewalld seems to be creating mmap files which it needs to execute in /run /tmp and /dev/shm. Would like to clean this up but for now we will allow - Looks like qpidd_t needs to read /dev/random - Lots of probing avc's caused by execugting gpg from staff_t - Dontaudit senmail triggering a net_admin avc - Change thumb_role to use thumb_run, not sure why we have a thumb_role, needs back port - Logwatch does access check on mdadm binary - Add raid_access_check_mdadm() iterface- Fix systemd_manage_unit_symlinks() interface - Call systemd_manage_unit_symlinks(() which is correct interface - Add filename transition for opasswd - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow sytstemd-timedated to get status of init_t - Add new systemd policies for hostnamed and rename gnomeclock_t to systemd_timedate_t - colord needs to communicate with systemd and systemd_logind, also remove duplicate rules - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow gpg_t to manage all gnome files - Stop using pcscd_read_pub_files - New rules for xguest, dontaudit attempts to dbus chat - Allow firewalld to create its mmap files in tmpfs and tmp directories - Allow firewalld to create its mmap files in tmpfs and tmp directories - run unbound-chkconf as named_t, so it can read dnssec - Colord is reading xdm process state, probably reads state of any apps that sends dbus message - Allow mdadm_t to change the kernel scheduler - mythtv policy - Update mandb_admin() interface - Allow dsspam to listen on own tpc_socket - seutil_filetrans_named_content needs to be optional - Allow sysadm_t to execute content in his homedir - Add attach_queue to tun_socket, new patch from Paul Moore - Change most of selinux configuration types to security_file_type. - Add filename transition rules for selinux configuration - ssh into a box with -X -Y requires ssh_use_ptys - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Allow all unpriv userdomains to send dbus messages to hostnamed and timedated - New allow rules found by Tom London for systemd_hostnamed- Allow systemd-tmpfiles to relabel lpd spool files - Ad labeling for texlive bash scripts - Add xserver_filetrans_fonts_cache_home_content() interface - Remove duplicate rules from *.te - Add support for /var/lock/man-db.lock - Add support for /var/tmp/abrt(/.*)? - Add additional labeling for munin cgi scripts - Allow httpd_t to read munin conf files - Allow certwatch to read meminfo - Fix nscd_dontaudit_write_sock_file() interfac - Fix gnome_filetrans_home_content() to include also "fontconfig" dir as cache_home_t - llow mozilla_plugin_t to create HOMEDIR/.fontconfig with the proper labeling- Allow gnomeclock to talk to puppet over dbus - Allow numad access discovered by Dominic - Add support for HOME_DIR/.maildir - Fix attribute_role for mozilla_plugin_t domain to allow staff_r to access this domain - Allow udev to relabel udev_var_run_t lnk_files - New bin_t file in mcelog- Remove all mcs overrides and replace with t1 != mcs_constrained_types - Add attribute_role for iptables - mcs_process_set_categories needs to be called for type - Implement additional role_attribute statements - Sodo domain is attempting to get the additributes of proc_kcore_t - Unbound uses port 8953 - Allow svirt_t images to compromise_kernel when using pci-passthrough - Add label for dns lib files - Bluetooth aquires a dbus name - Remove redundant files_read_usr_file calling - Remove redundant files_read_etc_file calling - Fix mozilla_run_plugin() - Add role_attribute support for more domains- Mass merge with upstream- Bump the policy version to 28 to match selinux userspace - Rebuild versus latest libsepol- Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Add labeling for /var/named/chroot/etc/localtim- Allow setroubleshoot_fixit to execute rpm - zoneminder needs to connect to httpd ports where remote cameras are listening - Allow firewalld to execute content created in /run directory - Allow svirt_t to read generic certs - Dontaudit leaked ps content to mozilla plugin - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - init scripts are creating systemd_unit_file_t directories- systemd_logind_t is looking at all files under /run/user/apache - Allow systemd to manage all user tmp files - Add labeling for /var/named/chroot/etc/localtime - Allow netlabel_peer_t type to flow over netif_t and node_t, and only be hindered by MLS, need back port to RHEL6 - Keystone is now using a differnt port - Allow xdm_t to use usbmuxd daemon to control sound - Allow passwd daemon to execute gnome_exec_keyringd - Fix chrome_sandbox policy - Add labeling for /var/run/checkquorum-timer - More fixes for the dspam domain, needs back port to RHEL6 - More fixes for the dspam domain, needs back port to RHEL6 - sssd needs to connect to kerberos password port if a user changes his password - Lots of fixes from RHEL testing of dspam web - Allow chrome and mozilla_plugin to create msgq and semaphores - Fixes for dspam cgi scripts - Fixes for dspam cgi scripts - Allow confine users to ptrace screen - Backport virt_qemu_ga_t changes from RHEL - Fix labeling for dspam.cgi needed for RHEL6 - We need to back port this policy to RHEL6, for lxc domains - Dontaudit attempts to set sys_resource of logrotate - Allow corosync to read/write wdmd's tmpfs files - I see a ptrace of mozilla_plugin_t by staff_t, will allow without deny_ptrace being set - Allow cron jobs to read bind config for unbound - libvirt needs to inhibit systemd - kdumpctl needs to delete boot_t files - Fix duplicate gnome_config_filetrans - virtd_lxc_t is using /dev/fuse - Passenger needs to create a directory in /var/log, needs a backport to RHEL6 for openshift - apcupsd can be setup to listen to snmp trafic - Allow transition from kdumpgui to kdumpctl - Add fixes for munin CGI scripts - Allow deltacloud to connect to openstack at the keystone port - Allow domains that transition to svirt domains to be able to signal them - Fix file context of gstreamer in .cache directory - libvirt is communicating with logind - NetworkManager writes to the systemd inhibit pipe- Allow munin disk plugins to get attributes of all directories - Allow munin disk plugins to get attributes of all directorie - Allow logwatch to get attributes of all directories - Fix networkmanager_manage_lib() interface - Fix gnome_manage_config() to allow to manage sock_file - Fix virtual_domain_context - Add support for dynamic DNS for DHCPv6- Allow svirt to use netlink_route_socket which was a part of auth_use_nsswitch - Add additional labeling for /var/www/openshift/broker - Fix rhev policy - Allow openshift_initrc domain to dbus chat with systemd_logind - Allow httpd to getattr passenger log file if run_stickshift - Allow consolehelper-gtk to connect to xserver - Add labeling for the tmp-inst directory defined in pam_namespace.conf - Add lvm_metadata_t labeling for /etc/multipath- consoletype is no longer used- Add label for efivarfs - Allow certmonger to send signal to itself - Allow plugin-config to read own process status - Add more fixes for pacemaker - apache/drupal can run clamscan on uploaded content - Allow chrome_sandbox_nacl_t to read pid 1 content- Fix MCS Constraints to control ingres and egres controls on the network. - Change name of svirt_nokvm_t to svirt_tcg_t - Allow tuned to request the kernel to load kernel modules- Label /var/lib/pgsql/.ssh as ssh_home_t - Add labeling for /usr/bin/pg_ctl - Allow systemd-logind to manage keyring user tmp dirs - Add support for 7389/tcp port - gems seems to be placed in lots of places - Since xdm is running a full session, it seems to be trying to execute lots of executables via dbus - Add back tcp/8123 port as http_cache port - Add ovirt-guest-agent\.pid labeling - Allow xend to run scsi_id - Allow rhsmcertd-worker to read "physical_package_id" - Allow pki_tomcat to connect to ldap port - Allow lpr to read /usr/share/fonts - Allow open file from CD/DVD drive on domU - Allow munin services plugins to talk to SSSD - Allow all samba domains to create samba directory in var_t directories - Take away svirt_t ability to use nsswitch - Dontaudit attempts by openshift to read apache logs - Allow apache to create as well as append _ra_content_t - Dontaudit sendmail_t reading a leaked file descriptor - Add interface to have admin transition /etc/prelink.cache to the proper label - Add sntp support to ntp policy - Allow firewalld to dbus chat with devicekit_power - Allow tuned to call lsblk - Allow tor to read /proc/sys/kernel/random/uuid - Add tor_can_network_relay boolean- Add openshift_initrc_signal() interface - Fix typos - dspam port is treat as spamd_port_t - Allow setroubleshoot to getattr on all executables - Allow tuned to execute profiles scripts in /etc/tuned - Allow apache to create directories to store its log files - Allow all directories/files in /var/log starting with passenger to be labeled passenger_log_t - Looks like apache is sending sinal to openshift_initrc_t now,needs back port to RHEL6 - Allow Postfix to be configured to listen on TCP port 10026 for email from DSPAM - Add filename transition for /etc/tuned/active_profile - Allow condor_master to send mails - Allow condor_master to read submit.cf - Allow condor_master to create /tmp files/dirs - Allow condor_mater to send sigkill to other condor domains - Allow condor_procd sigkill capability - tuned-adm wants to talk with tuned daemon - Allow kadmind and krb5kdc to also list sssd_public_t - Allow accountsd to dbus chat with init - Fix git_read_generic_system_content_files() interface - pppd wants sys_nice by nmcli because of "syscall=sched_setscheduler" - Fix mozilla_plugin_can_network_connect to allow to connect to all ports - Label all munin plugins which are not covered by munin plugins policy as unconfined_munin_plugin_exec_t - dspam wants to search /var/spool for opendkim data - Revert "Add support for tcp/10026 port as dspam_port_t" - Turning on labeled networking requires additional access for netlabel_peer_t; these allow rules need to be back ported to RHEL6 - Allow all application domains to use fifo_files passed in from userdomains, also allow them to write to tmp_files inherited from userdomain - Allow systemd_tmpfiles_t to setattr on mandb_cache_t- consolekit.pp was not removed from the postinstall script- Add back consolekit policy - Silence bootloader trying to use inherited tty - Silence xdm_dbusd_t trying to execute telepathy apps - Fix shutdown avcs when machine has unconfined.pp disabled - The host and a virtual machine can share the same printer on a usb device - Change oddjob to transition to a ranged openshift_initr_exec_t when run from oddjob - Allow abrt_watch_log_t to execute bin_t - Allow chrome sandbox to write content in ~/.config/chromium - Dontaudit setattr on fontconfig dir for thumb_t - Allow lircd to request the kernel to load module - Make rsync as userdom_home_manager - Allow rsync to search automount filesystem - Add fixes for pacemaker- Add support for 4567/tcp port - Random fixes from Tuomo Soini - xdm wants to get init status - Allow programs to run in fips_mode - Add interface to allow the reading of all blk device nodes - Allow init to relabel rpcbind sock_file - Fix labeling for lastlog and faillog related to logrotate - ALlow aeolus_configserver to use TRAM port - Add fixes for aeolus_configserver - Allow snmpd to connect to snmp port - Allow spamd_update to create spamd_var_lib_t directories - Allow domains that can read sssd_public_t files to also list the directory - Remove miscfiles_read_localization, this is defined for all domains- Allow syslogd to request the kernel to load a module - Allow syslogd_t to read the network state information - Allow xdm_dbusd_t connect to the system DBUS - Add support for 7389/tcp port - Allow domains to read/write all inherited sockets - Allow staff_t to read kmsg - Add awstats_purge_apache_log boolean - Allow ksysguardproces to read /.config/Trolltech.conf - Allow passenger to create and append puppet log files - Add puppet_append_log and puppet_create_log interfaces - Add puppet_manage_log() interface - Allow tomcat domain to search tomcat_var_lib_t - Allow pki_tomcat_t to connect to pki_ca ports - Allow pegasus_t to have net_admin capability - Allow pegasus_t to write /sys/class/net//flags - Allow mailserver_delivery to manage mail_home_rw_t lnk_files - Allow fetchmail to create log files - Allow gnomeclock to manage home config in .kde - Allow bittlebee to read kernel sysctls - Allow logrotate to list /root- Fix userhelper_console_role_template() - Allow enabling Network Access Point service using blueman - Make vmware_host_t as unconfined domain - Allow authenticate users in webaccess via squid, using mysql as backend - Allow gathers to get various metrics on mounted file systems - Allow firewalld to read /etc/hosts - Fix cron_admin_role() to make sysadm cronjobs running in the sysadm_t instead of cronjob_t - Allow kdumpgui to read/write to zipl.conf - Commands needed to get mock to build from staff_t in enforcing mode - Allow mdadm_t to manage cgroup files - Allow all daemons and systemprocesses to use inherited initrc_tmp_t files - dontaudit ifconfig_t looking at fifo_files that are leaked to it - Add lableing for Quest Authentication System- Fix filetrans interface definitions - Dontaudit xdm_t to getattr on BOINC lib files - Add systemd_reload_all_services() interface - Dontaudit write access on /var/lib/net-snmp/mib_indexes - Only stop mcsuntrustedproc from relableing files - Allow accountsd to dbus chat with gdm - Allow realmd to getattr on all fs - Allow logrotate to reload all services - Add systemd unit file for radiusd - Allow winbind to create samba pid dir - Add labeling for /var/nmbd/unexpected - Allow chrome and mozilla plugin to connect to msnp ports- Fix storage_rw_inherited_fixed_disk_dev() to cover also blk_file - Dontaudit setfiles reading /dev/random - On initial boot gnomeclock is going to need to be set buy gdm - Fix tftp_read_content() interface - Random apps looking at kernel file systems - Testing virt with lxc requiers additional access for virsh_t - New allow rules requied for latest libvirt, libvirt talks directly to journald,lxc setup tool needs compromize_kernel,and we need ipc_lock in the container - Allow MPD to read /dev/radnom - Allow sandbox_web_type to read logind files which needs to read pulseaudio - Allow mozilla plugins to read /dev/hpet - Add labeling for /var/lib/zarafa-webap - Allow BOINC client to use an HTTP proxy for all connections - Allow rhsmertd to domain transition to dmidecod - Allow setroubleshootd to send D-Bus msg to ABRT- Define usbtty_device_t as a term_tty - Allow svnserve to accept a connection - Allow xend manage default virt_image_t type - Allow prelink_cron_system_t to overide user componant when executing cp - Add labeling for z-push - Gnomeclock sets the realtime clock - Openshift seems to be storing apache logs in /var/lib/openshift/.log/httpd - Allow lxc domains to use /dev/random and /dev/urandom- Add port defintion for tcp/9000 - Fix labeling for /usr/share/cluster/checkquorum to label also checkquorum.wdmd - Add rules and labeling for $HOME/cache/\.gstreamer-.* directory - Add support for CIM provider openlmi-networking which uses NetworkManager dbus API - Allow shorewall_t to create netlink_socket - Allow krb5admind to block suspend - Fix labels on /var/run/dlm_controld /var/log/dlm_controld - Allow krb5kdc to block suspend - gnomessytemmm_t needs to read /etc/passwd - Allow cgred to read all sysctls- Allow all domains to read /proc/sys/vm/overcommit_memory - Make proc_numa_t an MLS Trusted Object - Add /proc/numactl support for confined users - Allow ssh_t to connect to any port > 1023 - Add openvswitch domain - Pulseaudio tries to create directories in gnome_home_t directories - New ypbind pkg wants to search /var/run which is caused by sd_notify - Allow NM to read certs on NFS/CIFS using use_nfs_*, use_samba_* booleans - Allow sanlock to read /dev/random - Treat php-fpm with httpd_t - Allow domains that can read named_conf_t to be able to list the directories - Allow winbind to create sock files in /var/run/samba- Add smsd policy - Add support for OpenShift sbin labelin - Add boolean to allow virt to use rawip - Allow mozilla_plugin to read all file systems with noxattrs support - Allow kerberos to write on anon_inodefs fs - Additional access required by fenced - Add filename transitions for passwd.lock/group.lock - UPdate man pages - Create coolkey directory in /var/cache with the correct label- Fix label on /etc/group.lock - Allow gnomeclock to create lnk_file in /etc - label /root/.pki as a home_cert_t - Add interface to make sure rpcbind.sock is created with the correct label - Add definition for new directory /var/lib/os-probe and bootloader wants to read udev rules - opendkim should be a part of milter - Allow libvirt to set the kernel sched algorythm - Allow mongod to read sysfs_t - Add authconfig policy - Remove calls to miscfiles_read_localization all domains get this - Allow virsh_t to read /root/.pki/ content - Add label for log directory under /var/www/stickshift- Allow getty to setattr on usb ttys - Allow sshd to search all directories for sshd_home_t content - Allow staff domains to send dbus messages to kdumpgui - Fix labels on /etc/.pwd.lock and friends to be passwd_file_t - Dontaudit setfiles reading urand - Add files_dontaudit_list_tmp() for domains to which we added sys_nice/setsched - Allow staff_gkeyringd_t to read /home/$USER/.local/share/keyrings dir - Allow systemd-timedated to read /dev/urandom - Allow entropyd_t to read proc_t (meminfo) - Add unconfined munin plugin - Fix networkmanager_read_conf() interface - Allow blueman to list /tmp which is needed by sys_nic/setsched - Fix label of /etc/mail/aliasesdb-stamp - numad is searching cgroups - realmd is communicating with networkmanager using dbus - Lots of fixes to try to get kdump to work- Allow loging programs to dbus chat with realmd - Make apache_content_template calling as optional - realmd is using policy kit- Add new selinuxuser_use_ssh_chroot boolean - dbus needs to be able to read/write inherited fixed disk device_t passed through it - Cleanup netutils process allow rule - Dontaudit leaked fifo files from openshift to ping - sanlock needs to read mnt_t lnk files - Fail2ban needs to setsched and sys_nice- Change default label of all files in /var/run/rpcbind - Allow sandbox domains (java) to read hugetlbfs_t - Allow awstats cgi content to create tmp files and read apache log files - Allow setuid/setgid for cupsd-config - Allow setsched/sys_nice pro cupsd-config - Fix /etc/localtime sym link to be labeled locale_t - Allow sshd to search postgresql db t since this is a homedir - Allow xwindows users to chat with realmd - Allow unconfined domains to configure all files and null_device_t service- Adopt pki-selinux policy- pki is leaking which we dontaudit until a pki code fix - Allow setcap for arping - Update man pages - Add labeling for /usr/sbin/mcollectived - pki fixes - Allow smokeping to execute fping in the netutils_t domain- Allow mount to relabelfrom unlabeled file systems - systemd_logind wants to send and receive messages from devicekit disk over dbus to make connected mouse working - Add label to get bin files under libreoffice labeled correctly - Fix interface to allow executing of base_ro_file_type - Add fixes for realmd - Update pki policy - Add tftp_homedir boolean - Allow blueman sched_setscheduler - openshift user domains wants to r/w ssh tcp sockets- Additional requirements for disable unconfined module when booting - Fix label of systemd script files - semanage can use -F /dev/stdin to get input - syslog now uses kerberos keytabs - Allow xserver to compromise_kernel access - Allow nfsd to write to mount_var_run_t when running the mount command - Add filename transition rule for bin_t directories - Allow files to read usr_t lnk_files - dhcpc wants chown - Add support for new openshift labeling - Clean up for tunable+optional statements - Add labeling for /usr/sbin/mkhomedir_helper - Allow antivirus domain to managa amavis spool files - Allow rpcbind_t to read passwd - Allow pyzor running as spamc to manage amavis spool- Add interfaces to read kernel_t proc info - Missed this version of exec_all - Allow anyone who can load a kernel module to compromise kernel - Add oddjob_dbus_chat to openshift apache policy - Allow chrome_sandbox_nacl_t to send signals to itself - Add unit file support to usbmuxd_t - Allow all openshift domains to read sysfs info - Allow openshift domains to getattr on all domains- MLS fixes from Dan - Fix name of capability2 secure_firmware->compromise_kerne- Allow xdm to search all file systems - Add interface to allow the config of all files - Add rngd policy - Remove kgpg as a gpg_exec_t type - Allow plymouthd to block suspend - Allow systemd_dbus to config any file - Allow system_dbus_t to configure all services - Allow freshclam_t to read usr_files - varnishd requires execmem to load modules- Allow semanage to verify types - Allow sudo domain to execute user home files - Allow session_bus_type to transition to user_tmpfs_t - Add dontaudit caused by yum updates - Implement pki policy but not activated- tuned wants to getattr on all filesystems - tuned needs also setsched. The build is needed for test day- Add policy for qemu-qa - Allow razor to write own config files - Add an initial antivirus policy to collect all antivirus program - Allow qdisk to read usr_t - Add additional caps for vmware_host - Allow tmpfiles_t to setattr on mandb_cache_t - Dontaudit leaked files into mozilla_plugin_config_t - Allow wdmd to getattr on tmpfs - Allow realmd to use /dev/random - allow containers to send audit messages - Allow root mount any file via loop device with enforcing mls policy - Allow tmpfiles_t to setattr on mandb_cache_t - Allow tmpfiles_t to setattr on mandb_cache_t - Make userdom_dontaudit_write_all_ not allow open - Allow init scripts to read all unit files - Add support for saphostctrl ports- Add kernel_read_system_state to sandbox_client_t - Add some of the missing access to kdumpgui - Allow systemd_dbusd_t to status the init system - Allow vmnet-natd to request the kernel to load a module - Allow gsf-office-thum to append .cache/gdm/session.log - realmd wants to read .config/dconf/user - Firewalld wants sys_nice/setsched - Allow tmpreaper to delete mandb cache files - Firewalld wants sys_nice/setsched - Allow firewalld to perform a DNS name resolution - Allown winbind to read /usr/share/samba/codepages/lowcase.dat - Add support for HTTPProxy* in /etc/freshclam.conf - Fix authlogin_yubike boolean - Extend smbd_selinux man page to include samba booleans - Allow dhcpc to execute consoletype - Allow ping to use inherited tmp files created in init scripts - On full relabel with unconfined domain disabled, initrc was running some chcon's - Allow people who delete man pages to delete mandb cache files- Add missing permissive domains- Add new mandb policy - ALlow systemd-tmpfiles_t to relabel mandb_cache_t - Allow logrotate to start all unit files- Add fixes for ctbd - Allow nmbd to stream connect to ctbd - Make cglear_t as nsswitch_domain - Fix bogus in interfaces - Allow openshift to read/write postfix public pipe - Add postfix_manage_spool_maildrop_files() interface - stickshift paths have been renamed to openshift - gnome-settings-daemon wants to write to /run/systemd/inhibit/ pipes - Update man pages, adding ENTRYPOINTS- Add mei_device_t - Make sure gpg content in homedir created with correct label - Allow dmesg to write to abrt cache files - automount wants to search virtual memory sysctls - Add support for hplip logs stored in /var/log/hp/tmp - Add labeling for /etc/owncloud/config.php - Allow setroubleshoot to send analysys to syslogd-journal - Allow virsh_t to interact with new fenced daemon - Allow gpg to write to /etc/mail/spamassassiin directories - Make dovecot_deliver_t a mail server delivery type - Add label for /var/tmp/DNS25- Fixes for tomcat_domain template interface- Remove init_systemd and init_upstart boolean, Move init_daemon_domain and init_system_domain to use attributes - Add attribute to all base os types. Allow all domains to read all ro base OS types- Additional unit files to be defined as power unit files - Fix more boolean names- Fix boolean name so subs will continue to work- dbus needs to start getty unit files - Add interface to allow system_dbusd_t to start the poweroff service - xdm wants to exec telepathy apps - Allow users to send messages to systemdlogind - Additional rules needed for systemd and other boot apps - systemd wants to list /home and /boot - Allow gkeyringd to write dbus/conf file - realmd needs to read /dev/urand - Allow readahead to delete /.readahead if labeled root_t, might get created before policy is loaded- Fixes to safe more rules - Re-write tomcat_domain_template() - Fix passenger labeling - Allow all domains to read man pages - Add ephemeral_port_t to the 'generic' port interfaces - Fix the names of postgresql booleans- Stop using attributes form netlabel_peer and syslog, auth_use_nsswitch setsup netlabel_peer - Move netlable_peer check out of booleans - Remove call to recvfrom_netlabel for kerberos call - Remove use of attributes when calling syslog call - Move -miscfiles_read_localization to domain.te to save hundreds of allow rules - Allow all domains to read locale files. This eliminates around 1500 allow rules- Cleanup nis_use_ypbind_uncond interface - Allow rndc to block suspend - tuned needs to modify the schedule of the kernel - Allow svirt_t domains to read alsa configuration files - ighten security on irc domains and make sure they label content in homedir correctly - Add filetrans_home_content for irc files - Dontaudit all getattr access for devices and filesystems for sandbox domains - Allow stapserver to search cgroups directories - Allow all postfix domains to talk to spamd- Add interfaces to ignore setattr until kernel fixes this to be checked after the DAC check - Change pam_t to pam_timestamp_t - Add dovecot_domain attribute and allow this attribute block_suspend capability2 - Add sanlock_use_fusefs boolean - numad wants send/recieve msg - Allow rhnsd to send syslog msgs - Make piranha-pulse as initrc domain - Update openshift instances to dontaudit setattr until the kernel is fixed.- Fix auth_login_pgm_domain() interface to allow domains also managed user tmp dirs because of #856880 related to pam_systemd - Remove pam_selinux.8 which conflicts with man page owned by the pam package - Allow glance-api to talk to mysql - ABRT wants to read Xorg.0.log if if it detects problem with Xorg - Fix gstreamer filename trans. interface- Man page fixes by Dan Walsh- Allow postalias to read postfix config files - Allow man2html to read man pages - Allow rhev-agentd to search all mountpoints - Allow rhsmcertd to read /dev/random - Add tgtd_stream_connect() interface - Add cyrus_write_data() interface - Dontaudit attempts by sandboxX clients connectiing to the xserver_port_t - Add port definition for tcp/81 as http_port_t - Fix /dev/twa labeling - Allow systemd to read modules config- Merge openshift policy - Allow xauth to read /dev/urandom - systemd needs to relabel content in /run/systemd directories - Files unconfined should be able to perform all services on all files - Puppet tmp file can be leaked to all domains - Dontaudit rhsmcertd-worker to search /root/.local - Allow chown capability for zarafa domains - Allow system cronjobs to runcon into openshift domains - Allow virt_bridgehelper_t to manage content in the svirt_home_t labeled directories- nmbd wants to create /var/nmbd - Stop transitioning out of anaconda and firstboot, just causes AVC messages - Allow clamscan to read /etc files - Allow bcfg2 to bind cyphesis port - heartbeat should be run as rgmanager_t instead of corosync_t - Add labeling for /etc/openldap/certs - Add labeling for /opt/sartest directory - Make crontab_t as userdom home reader - Allow tmpreaper to list admin_home dir - Add defition for imap_0 replay cache file - Add support for gitolite3 - Allow virsh_t to send syslog messages - allow domains that can read samba content to be able to list the directories also - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd - Separate out sandbox from sandboxX policy so we can disable it by default - Run dmeventd as lvm_t - Mounting on any directory requires setattr and write permissions - Fix use_nfs_home_dirs() boolean - New labels for pam_krb5 - Allow init and initrc domains to sys_ptrace since this is needed to look at processes not owned by uid 0 - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd- Separate sandbox policy into sandbox and sandboxX, and disable sandbox by default on fresh installs - Allow domains that can read etc_t to read etc_runtime_t - Allow all domains to use inherited tmpfiles- Allow realmd to read resolv.conf - Add pegasus_cache_t type - Label /usr/sbin/fence_virtd as virsh_exec_t - Add policy for pkcsslotd - Add support for cpglockd - Allow polkit-agent-helper to read system-auth-ac - telepathy-idle wants to read gschemas.compiled - Allow plymouthd to getattr on fs_t - Add slpd policy - Allow ksysguardproces to read/write config_usr_t- Fix labeling substitution so rpm will label /lib/systemd content correctly- Add file name transitions for ttyACM0 - spice-vdagent(d)'s are going to log over to syslog - Add sensord policy - Add more fixes for passenger policy related to puppet - Allow wdmd to create wdmd_tmpfs_t - Fix labeling for /var/run/cachefilesd\.pid - Add thumb_tmpfs_t files type- Allow svirt domains to manage the network since this is containerized - Allow svirt_lxc_net_t to send audit messages- Make "snmpwalk -mREDHAT-CLUSTER-MIB ...." working - Allow dlm_controld to execute dlm_stonith labeled as bin_t - Allow GFS2 working on F17 - Abrt needs to execute dmesg - Allow jockey to list the contents of modeprobe.d - Add policy for lightsquid as squid_cron_t - Mailscanner is creating files and directories in /tmp - dmesg is now reading /dev/kmsg - Allow xserver to communicate with secure_firmware - Allow fsadm tools (fsck) to read /run/mount contnet - Allow sysadm types to read /dev/kmsg -- Allow postfix, sssd, rpcd to block_suspend - udev seems to need secure_firmware capability - Allow virtd to send dbus messages to firewalld so it can configure the firewall- Fix labeling of content in /run created by virsh_t - Allow condor domains to read kernel sysctls - Allow condor_master to connect to amqp - Allow thumb drives to create shared memory and semaphores - Allow abrt to read mozilla_plugin config files - Add labels for lightsquid - Default files in /opt and /usr that end in .cgi as httpd_sys_script_t, allow - dovecot_auth_t uses ldap for user auth - Allow domains that can read dhcp_etc_t to read lnk_files - Add more then one watchdog device - Allow useradd_t to manage etc_t files so it can rename it and edit them - Fix invalid class dir should be fifo_file - Move /run/blkid to fsadm and make sure labeling is correct- Fix bogus regex found by eparis - Fix manage run interface since lvm needs more access - syslogd is searching cgroups directory - Fixes to allow virt-sandbox-service to manage lxc var run content- Fix Boolean settings - Add new libjavascriptcoregtk as textrel_shlib_t - Allow xdm_t to create xdm_home_t directories - Additional access required for systemd - Dontaudit mozilla_plugin attempts to ipc_lock - Allow tmpreaper to delete unlabeled files - Eliminate screen_tmp_t and allow it to manage user_tmp_t - Dontaudit mozilla_plugin_config_t to append to leaked file descriptors - Allow web plugins to connect to the asterisk ports - Condor will recreate the lock directory if it does not exist - Oddjob mkhomedir needs to connectto user processes - Make oddjob_mkhomedir_t a userdom home manager- Put placeholder back in place for proper numbering of capabilities - Systemd also configures init scripts- Fix ecryptfs interfaces - Bootloader seems to be trolling around /dev/shm and /dev - init wants to create /etc/systemd/system-update.target.wants - Fix systemd_filetrans call to move it out of tunable - Fix up policy to work with systemd userspace manager - Add secure_firmware capability and remove bogus epolwakeup - Call seutil_*_login_config interfaces where should be needed - Allow rhsmcertd to send signal to itself - Allow thin domains to send signal to itself - Allow Chrome_ChildIO to read dosfs_t- Add role rules for realmd, sambagui- Add new type selinux_login_config_t for /etc/selinux//logins/ - Additional fixes for seutil_manage_module_store() - dbus_system_domain() should be used with optional_policy - Fix svirt to be allowed to use fusefs file system - Allow login programs to read /run/ data created by systemd_login - sssd wants to write /etc/selinux//logins/ for SELinux PAM module - Fix svirt to be allowed to use fusefs file system - Allow piranha domain to use nsswitch - Sanlock needs to send Kill Signals to non root processes - Pulseaudio wants to execute /run/user/PID/.orc- Fix saslauthd when it tries to read /etc/shadow - Label gnome-boxes as a virt homedir - Need to allow svirt_t ability to getattr on nfs_t file systems - Update sanlock policy to solve all AVC's - Change confined users can optionally manage virt content - Handle new directories under ~/.cache - Add block suspend to appropriate domains - More rules required for containers - Allow login programs to read /run/ data created by systemd_logind - Allow staff users to run svirt_t processes- Update to upstream- More fixes for systemd to make rawhide booting from Dan Walsh- Add systemd fixes to make rawhide booting- Add systemd_logind_inhibit_var_run_t attribute - Remove corenet_all_recvfrom_unlabeled() for non-contrib policies because we moved it to domain.if for all domain_type - Add interface for mysqld to dontaudit signull to all processes - Label new /var/run/journal directory correctly - Allow users to inhibit suspend via systemd - Add new type for the /var/run/inhibit directory - Add interface to send signull to systemd_login so avahi can send them - Allow systemd_passwd to send syslog messages - Remove corenet_all_recvfrom_unlabeled() calling fro policy files - Allow editparams.cgi running as httpd_bugzilla_script_t to read /etc/group - Allow smbd to read cluster config - Add additional labeling for passenger - Allow dbus to inhibit suspend via systemd - Allow avahi to send signull to systemd_login- Add interface to dontaudit getattr access on sysctls - Allow sshd to execute /bin/login - Looks like xdm is recreating the xdm directory in ~/.cache/ on login - Allow syslog to use the leaked kernel_t unix_dgram_socket from system-jounald - Fix semanage to work with unconfined domain disabled on F18 - Dontaudit attempts by mozilla plugins to getattr on all kernel sysctls - Virt seems to be using lock files - Dovecot seems to be searching directories of every mountpoint - Allow jockey to read random/urandom, execute shell and install third-party drivers - Add aditional params to allow cachedfiles to manage its content - gpg agent needs to read /dev/random - The kernel hands an svirt domains /SYSxxxxx which is a tmpfs that httpd wants to read and write - Add a bunch of dontaudit rules to quiet svirt_lxc domains - Additional perms needed to run svirt_lxc domains - Allow cgclear to read cgconfig - Allow sys_ptrace capability for snmp - Allow freshclam to read /proc - Allow procmail to manage /home/user/Maildir content - Allow NM to execute wpa_cli - Allow amavis to read clamd system state - Regenerate man pages- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Add realmd and stapserver policies - Allow useradd to manage stap-server lib files - Tighten up capabilities for confined users - Label /etc/security/opasswd as shadow_t - Add label for /dev/ecryptfs - Allow condor_startd_t to start sshd with the ranged - Allow lpstat.cups to read fips_enabled file - Allow pyzor running as spamc_t to create /root/.pyzor directory - Add labelinf for amavisd-snmp init script - Add support for amavisd-snmp - Allow fprintd sigkill self - Allow xend (w/o libvirt) to start virtual machines - Allow aiccu to read /etc/passwd - Allow condor_startd to Make specified domain MCS trusted for setting any category set for the processes it executes - Add condor_startd_ranged_domtrans_to() interface - Add ssd_conf_t for /etc/sssd - accountsd needs to fchown some files/directories - Add ICACLient and zibrauserdata as mozilla_filetrans_home_content - SELinux reports afs_t needs dac_override to read /etc/mtab, even though everything works, adding dontaudit - Allow xend_t to read the /etc/passwd file- Until we figure out how to fix systemd issues, allow all apps that send syslog messages to send them to kernel_t - Add init_access_check() interface - Fix label on /usr/bin/pingus to not be labeled as ping_exec_t - Allow tcpdump to create a netlink_socket - Label newusers like useradd - Change xdm log files to be labeled xdm_log_t - Allow sshd_t with privsep to work in MLS - Allow freshclam to update databases thru HTTP proxy - Allow s-m-config to access check on systemd - Allow abrt to read public files by default - Fix amavis_create_pid_files() interface - Add labeling and filename transition for dbomatic.log - Allow system_dbusd_t to stream connect to bluetooth, and use its socket - Allow amavisd to execute fsav - Allow tuned to use sys_admin and sys_nice capabilities - Add php-fpm policy from Bryan - Add labeling for aeolus-configserver-thinwrapper - Allow thin domains to execute shell - Fix gnome_role_gkeyringd() interface description - Lot of interface fixes - Allow OpenMPI job running as condor_startd_ssh_t to manage condor lib files - Allow OpenMPI job to use kerberos - Make deltacloudd_t as nsswitch_domain - Allow xend_t to run lsscsi - Allow qemu-dm running as xend_t to create tun_socket - Add labeling for /opt/brother/Printers(.*/)?inf - Allow jockey-backend to read pyconfig-64.h labeled as usr_t - Fix clamscan_can_scan_system boolean - Allow lpr to connectto to /run/user/$USER/keyring-22uREb/pkcs11- initrc is calling exportfs which is not confined so it attempts to read nfsd_files - Fixes for passenger running within openshift. - Add labeling for all tomcat6 dirs - Add support for tomcat6 - Allow cobblerd to read /etc/passwd - Allow jockey to read sysfs and and execute binaries with bin_t - Allow thum to use user terminals - Allow cgclear to read cgconfig config files - Fix bcf2g.fc - Remove sysnet_dns_name_resolve() from policies where auth_use_nsswitch() is used for other domains - Allow dbomatic to execute ruby - abrt_watch_log should be abrt_domain - Allow mozilla_plugin to connect to gatekeeper port- add ptrace_child access to process - remove files_read_etc_files() calling from all policies which have auth_use_nsswith() - Allow boinc domains to manage boinc_lib_t lnk_files - Add support for boinc-client.service unit file - Add support for boinc.log - Allow mozilla_plugin execmod on mozilla home files if allow_ex - Allow dovecot_deliver_t to read dovecot_var_run_t - Allow ldconfig and insmod to manage kdumpctl tmp files - Move thin policy out from cloudform.pp and add a new thin poli - pacemaker needs to communicate with corosync streams - abrt is now started on demand by dbus - Allow certmonger to talk directly to Dogtag servers - Change labeling for /var/lib/cobbler/webui_sessions to httpd_c - Allow mozila_plugin to execute gstreamer home files - Allow useradd to delete all file types stored in the users hom - rhsmcertd reads the rpm database - Add support for lightdm- Add tomcat policy - Remove pyzor/razor policy - rhsmcertd reads the rpm database - Dontaudit thumb to setattr on xdm_tmp dir - Allow wicd to execute ldconfig in the networkmanager_t domain - Add /var/run/cherokee\.pid labeling - Allow mozilla_plugin to create mozilla_plugin_tmp_t lnk files too - Allow postfix-master to r/w pipes other postfix domains - Allow snort to create netlink_socket - Add kdumpctl policy - Allow firstboot to create tmp_t files/directories - /usr/bin/paster should not be labeled as piranha_exec_t - remove initrc_domain from tomcat - Allow ddclient to read /etc/passwd - Allow useradd to delete all file types stored in the users homedir - Allow ldconfig and insmod to manage kdumpctl tmp files - Firstboot should be just creating tmp_t dirs and xauth should be allowed to write to those - Transition xauth files within firstboot_tmp_t - Fix labeling of /run/media to match /media - Label all lxdm.log as xserver_log_t - Add port definition for mxi port - Allow local_login_t to execute tmux- apcupsd needs to read /etc/passwd - Sanlock allso sends sigkill - Allow glance_registry to connect to the mysqld port - Dontaudit mozilla_plugin trying to getattr on /dev/gpmctl - Allow firefox plugins/flash to connect to port 1234 - Allow mozilla plugins to delete user_tmp_t files - Add transition name rule for printers.conf.O - Allow virt_lxc_t to read urand - Allow systemd_loigind to list gstreamer_home_dirs - Fix labeling for /usr/bin - Fixes for cloudform services * support FIPS - Allow polipo to work as web caching - Allow chfn to execute tmux- Add support for ecryptfs * ecryptfs does not support xattr * we need labeling for HOMEDIR - Add policy for (u)mount.ecryptfs* - Fix labeling of kerbero host cache files, allow rpc.svcgssd to manage host cache - Allow dovecot to manage Maildir content, fix transitions to Maildir - Allow postfix_local to transition to dovecot_deliver - Dontaudit attempts to setattr on xdm_tmp_t, looks like bogus code - Cleanup interface definitions - Allow apmd to change with the logind daemon - Changes required for sanlock in rhel6 - Label /run/user/apache as httpd_tmp_t - Allow thumb to use lib_t as execmod if boolean turned on - Allow squid to create the squid directory in /var with the correct labe - Add a new policy for glusterd from Bryan Bickford (bbickfor@redhat.com) - Allow virtd to exec xend_exec_t without transition - Allow virtd_lxc_t to unmount all file systems- PolicyKit path has changed - Allow httpd connect to dirsrv socket - Allow tuned to write generic kernel sysctls - Dontaudit logwatch to gettr on /dev/dm-2 - Allow policykit-auth to manage kerberos files - Make condor_startd and rgmanager as initrc domain - Allow virsh to read /etc/passwd - Allow mount to mount on user_tmp_t for /run/user/dwalsh/gvfs - xdm now needs to execute xsession_exec_t - Need labels for /var/lib/gdm - Fix files_filetrans_named_content() interface - Add new attribute - initrc_domain - Allow systemd_logind_t to signal, signull, sigkill all processes - Add filetrans rules for etc_runtime files- Rename boolean names to remove allow_- Mass merge with upstream * new policy topology to include contrib policy modules * we have now two base policy patches- Fix description of authlogin_nsswitch_use_ldap - Fix transition rule for rhsmcertd_t needed for RHEL7 - Allow useradd to list nfs state data - Allow openvpn to manage its log file and directory - We want vdsm to transition to mount_t when executing mount command to make sure /etc/mtab remains labeled correctly - Allow thumb to use nvidia devices - Allow local_login to create user_tmp_t files for kerberos - Pulseaudio needs to read systemd_login /var/run content - virt should only transition named system_conf_t config files - Allow munin to execute its plugins - Allow nagios system plugin to read /etc/passwd - Allow plugin to connect to soundd port - Fix httpd_passwd to be able to ask passwords - Radius servers can use ldap for backing store - Seems to need to mount on /var/lib for xguest polyinstatiation to work. - Allow systemd_logind to list the contents of gnome keyring - VirtualGL need xdm to be able to manage content in /etc/opt/VirtualGL - Add policy for isns-utils- Add policy for subversion daemon - Allow boinc to read passwd - Allow pads to read kernel network state - Fix man2html interface for sepolgen-ifgen - Remove extra /usr/lib/systemd/system/smb - Remove all /lib/systemd and replace with /usr/lib/systemd - Add policy for man2html - Fix the label of kerberos_home_t to krb5_home_t - Allow mozilla plugins to use Citrix - Allow tuned to read /proc/sys/kernel/nmi_watchdog - Allow tune /sys options via systemd's tmpfiles.d "w" type- Dontaudit lpr_t to read/write leaked mozilla tmp files - Add file name transition for .grl-podcasts directory - Allow corosync to read user tmp files - Allow fenced to create snmp lib dirs/files - More fixes for sge policy - Allow mozilla_plugin_t to execute any application - Allow dbus to read/write any open file descriptors to any non security file on the system that it inherits to that it can pass them to another domain - Allow mongod to read system state information - Fix wrong type, we should dontaudit sys_admin for xdm_t not xserver_t - Allow polipo to manage polipo_cache dirs - Add jabbar_client port to mozilla_plugin_t - Cleanup procmail policy - system bus will pass around open file descriptors on files that do not have labels on them - Allow l2tpd_t to read system state - Allow tuned to run ls /dev - Allow sudo domains to read usr_t files - Add label to machine-id - Fix corecmd_read_bin_symlinks cut and paste error- Fix pulseaudio port definition - Add labeling for condor_starter - Allow chfn_t to creat user_tmp_files - Allow chfn_t to execute bin_t - Allow prelink_cron_system_t to getpw calls - Allow sudo domains to manage kerberos rcache files - Allow user_mail_domains to work with courie - Port definitions necessary for running jboss apps within openshift - Add support for openstack-nova-metadata-api - Add support for nova-console* - Add support for openstack-nova-xvpvncproxy - Fixes to make privsep+SELinux working if we try to use chage to change passwd - Fix auth_role() interface - Allow numad to read sysfs - Allow matahari-rpcd to execute shell - Add label for ~/.spicec - xdm is executing lspci as root which is requesting a sys_admin priv but seems to succeed without it - Devicekit_disk wants to read the logind sessions file when writing a cd - Add fixes for condor to make condor jobs working correctly - Change label of /var/log/rpmpkgs to cron_log_t - Access requires to allow systemd-tmpfiles --create to work. - Fix obex to be a user application started by the session bus. - Add additional filename trans rules for kerberos - Fix /var/run/heartbeat labeling - Allow apps that are managing rcache to file trans correctly - Allow openvpn to authenticate against ldap server - Containers need to listen to network starting and stopping events- Make systemd unit files less specific- Fix zarafa labeling - Allow guest_t to fix labeling - corenet_tcp_bind_all_unreserved_ports(ssh_t) should be called with the user_tcp_server boolean - add lxc_contexts - Allow accountsd to read /proc - Allow restorecond to getattr on all file sytems - tmpwatch now calls getpw - Allow apache daemon to transition to pwauth domain - Label content under /var/run/user/NAME/keyring* as gkeyringd_tmp_t - The obex socket seems to be a stream socket - dd label for /var/run/nologin- Allow jetty running as httpd_t to read hugetlbfs files - Allow sys_nice and setsched for rhsmcertd - Dontaudit attempts by mozilla_plugin_t to bind to ssdp ports - Allow setfiles to append to xdm_tmp_t - Add labeling for /export as a usr_t directory - Add labels for .grl files created by gstreamer- Add labeling for /usr/share/jetty/bin/jetty.sh - Add jetty policy which contains file type definitios - Allow jockey to use its own fifo_file and make this the default for all domains - Allow mozilla_plugins to use spice (vnc_port/couchdb) - asterisk wants to read the network state - Blueman now uses /var/lib/blueman- Add label for nodejs_debug - Allow mozilla_plugin_t to create ~/.pki directory and content- Add clamscan_can_scan_system boolean - Allow mysqld to read kernel network state - Allow sshd to read/write condor lib files - Allow sshd to read/write condor-startd tcp socket - Fix description on httpd_graceful_shutdown - Allow glance_registry to communicate with mysql - dbus_system_domain is using systemd to lauch applications - add interfaces to allow domains to send kill signals to user mail agents - Remove unnessary access for svirt_lxc domains, add privs for virtd_lxc_t - Lots of new access required for secure containers - Corosync needs sys_admin capability - ALlow colord to create shm - .orc should be allowed to be created by any app that can create gstream home content, thumb_t to be specific - Add boolean to control whether or not mozilla plugins can create random content in the users homedir - Add new interface to allow domains to list msyql_db directories, needed for libra - shutdown has to be allowed to delete etc_runtime_t - Fail2ban needs to read /etc/passwd - Allow ldconfig to create /var/cache/ldconfig - Allow tgtd to read hardware state information - Allow collectd to create packet socket - Allow chronyd to send signal to itself - Allow collectd to read /dev/random - Allow collectd to send signal to itself - firewalld needs to execute restorecon - Allow restorecon and other login domains to execute restorecon- Allow logrotate to getattr on systemd unit files - Add support for tor systemd unit file - Allow apmd to create /var/run/pm-utils with the correct label - Allow l2tpd to send sigkill to pppd - Allow pppd to stream connect to l2tpd - Add label for scripts in /etc/gdm/ - Allow systemd_logind_t to ignore mcs constraints on sigkill - Fix files_filetrans_system_conf_named_files() interface - Add labels for /usr/share/wordpress/wp-includes/*.php - Allow cobbler to get SELinux mode and booleans- Add unconfined_execmem_exec_t as an alias to bin_t - Allow fenced to read snmp var lib files, also allow it to read usr_t - ontaudit access checks on all executables from mozilla_plugin - Allow all user domains to setexec, so that sshd will work properly if it call setexec(NULL) while running withing a user mode - Allow systemd_tmpfiles_t to getattr all pipes and sockets - Allow glance-registry to send system log messages - semanage needs to manage mock lib files/dirs- Add policy for abrt-watch-log - Add definitions for jboss_messaging ports - Allow systemd_tmpfiles to manage printer devices - Allow oddjob to use nsswitch - Fix labeling of log files for postgresql - Allow mozilla_plugin_t to execmem and execstack by default - Allow firewalld to execute shell - Fix /etc/wicd content files to get created with the correct label - Allow mcelog to exec shell - Add ~/.orc as a gstreamer_home_t - /var/spool/postfix/lib64 should be labeled lib_t - mpreaper should be able to list all file system labeled directories - Add support for apache to use openstack - Add labeling for /etc/zipl.conf and zipl binary - Turn on allow_execstack and turn off telepathy transition for final release- More access required for virt_qmf_t - Additional assess required for systemd-logind to support multi-seat - Allow mozilla_plugin to setrlimit - Revert changes to fuse file system to stop deadlock- Allow condor domains to connect to ephemeral ports - More fixes for condor policy - Allow keystone to stream connect to mysqld - Allow mozilla_plugin_t to read generic USB device to support GPS devices - Allow thum to file name transition gstreamer home content - Allow thum to read all non security files - Allow glance_api_t to connect to ephemeral ports - Allow nagios plugins to read /dev/urandom - Allow syslogd to search postfix spool to support postfix chroot env - Fix labeling for /var/spool/postfix/dev - Allow wdmd chown - Label .esd_auth as pulseaudio_home_t - Have no idea why keyring tries to write to /run/user/dwalsh/dconf/user, but we can dontaudit for now- Add support for clamd+systemd - Allow fresclam to execute systemctl to handle clamd - Change labeling for /usr/sbin/rpc.ypasswd.env - Allow yppaswd_t to execute yppaswd_exec_t - Allow yppaswd_t to read /etc/passwd - Gnomekeyring socket has been moved to /run/user/USER/ - Allow samba-net to connect to ldap port - Allow signal for vhostmd - allow mozilla_plugin_t to read user_home_t socket - New access required for secure Linux Containers - zfs now supports xattrs - Allow quantum to execute sudo and list sysfs - Allow init to dbus chat with the firewalld - Allow zebra to read /etc/passwd- Allow svirt_t to create content in the users homedir under ~/.libvirt - Fix label on /var/lib/heartbeat - Allow systemd_logind_t to send kill signals to all processes started by a user - Fuse now supports Xattr Support- upowered needs to setsched on the kernel - Allow mpd_t to manage log files - Allow xdm_t to create /var/run/systemd/multi-session-x - Add rules for missedfont.log to be used by thumb.fc - Additional access required for virt_qmf_t - Allow dhclient to dbus chat with the firewalld - Add label for lvmetad - Allow systemd_logind_t to remove userdomain sock_files - Allow cups to execute usr_t files - Fix labeling on nvidia shared libraries - wdmd_t needs access to sssd and /etc/passwd - Add boolean to allow ftp servers to run in passive mode - Allow namepspace_init_t to relabelto/from a different user system_u from the user the namespace_init running with - Fix using httpd_use_fusefs - Allow chrome_sandbox_nacl to write inherited user tmp files as we allow it for chrome_sandbox- Rename rdate port to time port, and allow gnomeclock to connect to it - We no longer need to transition to ldconfig from rpm, rpm_script, or anaconda - /etc/auto.* should be labeled bin_t - Add httpd_use_fusefs boolean - Add fixes for heartbeat - Allow sshd_t to signal processes that it transitions to - Add condor policy - Allow svirt to create monitors in ~/.libvirt - Allow dovecot to domtrans sendmail to handle sieve scripts - Lot of fixes for cfengine- /var/run/postmaster.* labeling is no longer needed - Alllow drbdadmin to read /dev/urandom - l2tpd_t seems to use ptmx - group+ and passwd+ should be labeled as /etc/passwd - Zarafa-indexer is a socket- Ensure lastlog is labeled correctly - Allow accountsd to read /proc data about gdm - Add fixes for tuned - Add bcfg2 fixes which were discovered during RHEL6 testing - More fixes for gnome-keyring socket being moved - Run semanage as a unconfined domain, and allow initrc_t to create tmpfs_t sym links on shutdown - Fix description for files_dontaudit_read_security_files() interface- Add new policy and man page for bcfg2 - cgconfig needs to use getpw calls - Allow domains that communicate with the keyring to use cache_home_t instead of gkeyringd_tmpt - gnome-keyring wants to create a directory in cache_home_t - sanlock calls getpw- Add numad policy and numad man page - Add fixes for interface bugs discovered by SEWatch - Add /tmp support for squid - Add fix for #799102 * change default labeling for /var/run/slapd.* sockets - Make thumb_t as userdom_home_reader - label /var/lib/sss/mc same as pubconf, so getpw domains can read it - Allow smbspool running as cups_t to stream connect to nmbd - accounts needs to be able to execute passwd on behalf of users - Allow systemd_tmpfiles_t to delete boot flags - Allow dnssec_trigger to connect to apache ports - Allow gnome keyring to create sock_files in ~/.cache - google_authenticator is using .google_authenticator - sandbox running from within firefox is exposing more leaks - Dontaudit thumb to read/write /dev/card0 - Dontaudit getattr on init_exec_t for gnomeclock_t - Allow certmonger to do a transition to certmonger_unconfined_t - Allow dhcpc setsched which is caused by nmcli - Add rpm_exec_t for /usr/sbin/bcfg2 - system cronjobs are sending dbus messages to systemd_logind - Thumnailers read /dev/urand- Allow auditctl getcap - Allow vdagent to use libsystemd-login - Allow abrt-dump-oops to search /etc/abrt - Got these avc's while trying to print a boarding pass from firefox - Devicekit is now putting the media directory under /run/media - Allow thumbnailers to create content in ~/.thumbails directory - Add support for proL2TPd by Dominick Grift - Allow all domains to call getcap - wdmd seems to get a random chown capability check that it does not need - Allow vhostmd to read kernel sysctls- Allow chronyd to read unix - Allow hpfax to read /etc/passwd - Add support matahari vios-proxy-* apps and add virtd_exec_t label for them - Allow rpcd to read quota_db_t - Update to man pages to match latest policy - Fix bug in jockey interface for sepolgen-ifgen - Add initial svirt_prot_exec_t policy- More fixes for systemd from Dan Walsh- Add a new type for /etc/firewalld and allow firewalld to write to this directory - Add definition for ~/Maildir, and allow mail deliver domains to write there - Allow polipo to run from a cron job - Allow rtkit to schedule wine processes - Allow mozilla_plugin_t to acquire a bug, and allow it to transition gnome content in the home dir to the proper label - Allow users domains to send signals to consolehelper domains- More fixes for boinc policy - Allow polipo domain to create its own cache dir and pid file - Add systemctl support to httpd domain - Add systemctl support to polipo, allow NetworkManager to manage the service - Add policy for jockey-backend - Add support for motion daemon which is now covered by zoneminder policy - Allow colord to read/write motion tmpfs - Allow vnstat to search through var_lib_t directories - Stop transitioning to quota_t, from init an sysadm_t- Add svirt_lxc_file_t as a customizable type- Add additional fixes for icmp nagios plugin - Allow cron jobs to open fifo_files from cron, since service script opens /dev/stdin - Add certmonger_unconfined_exec_t - Make sure tap22 device is created with the correct label - Allow staff users to read systemd unit files - Merge in previously built policy - Arpwatch needs to be able to start netlink sockets in order to start - Allow cgred_t to sys_ptrace to look at other DAC Processes- Back port some of the access that was allowed in nsplugin_t - Add definitiona for couchdb ports - Allow nagios to use inherited users ttys - Add git support for mock - Allow inetd to use rdate port - Add own type for rdate port - Allow samba to act as a portmapper - Dontaudit chrome_sandbox attempts to getattr on chr_files in /dev - New fixes needed for samba4 - Allow apps that use lib_t to read lib_t symlinks- Add policy for nove-cert - Add labeling for nova-openstack systemd unit files - Add policy for keystoke- Fix man pages fro domains - Add man pages for SELinux users and roles - Add storage_dev_filetrans_named_fixed_disk() and use it for smartmon - Add policy for matahari-rpcd - nfsd executes mount command on restart - Matahari domains execute renice and setsched - Dontaudit leaked tty in mozilla_plugin_config - mailman is changing to a per instance naming - Add 7600 and 4447 as jboss_management ports - Add fixes for nagios event handlers - Label httpd.event as httpd_exec_t, it is an apache daemon- Add labeling for /var/spool/postfix/dev/log - NM reads sysctl.conf - Iscsi log file context specification fix - Allow mozilla plugins to send dbus messages to user domains that transition to it - Allow mysql to read the passwd file - Allow mozilla_plugin_t to create mozilla home dirs in user homedir - Allow deltacloud to read kernel sysctl - Allow postgresql_t to connectto itselfAllow postgresql_t to connectto itself - Allow postgresql_t to connectto itself - Add login_userdomain attribute for users which can log in using terminal- Allow sysadm_u to reach system_r by default #784011 - Allow nagios plugins to use inherited user terminals - Razor labeling is not used no longer - Add systemd support for matahari - Add port_types to man page, move booleans to the top, fix some english - Add support for matahari-sysconfig-console - Clean up matahari.fc - Fix matahari_admin() interfac - Add labels for/etc/ssh/ssh_host_*.pub keys- Allow ksysguardproces to send system log msgs - Allow boinc setpgid and signull - Allow xdm_t to sys_ptrace to run pidof command - Allow smtpd_t to manage spool files/directories and symbolic links - Add labeling for jetty - Needed changes to get unbound/dnssec to work with openswan- Add user_fonts_t alias xfs_tmp_t - Since depmod now runs as insmod_t we need to write to kernel_object_t - Allow firewalld to dbus chat with networkmanager - Allow qpidd to connect to matahari ports - policykit needs to read /proc for uses not owned by it - Allow systemctl apps to connecto the init stream- Turn on deny_ptrace boolean- Remove pam_selinux.8 man page. There was a conflict.- Add proxy class and read access for gssd_proxy - Separate out the sharing public content booleans - Allow certmonger to execute a script and send signals to apache and dirsrv to reload the certificate - Add label transition for gstream-0.10 and 12 - Add booleans to allow rsync to share nfs and cifs file sytems - chrome_sandbox wants to read the /proc/PID/exe file of the program that executed it - Fix filename transitions for cups files - Allow denyhosts to read "unix" - Add file name transition for locale.conf.new - Allow boinc projects to gconf config files - sssd needs to be able to increase the socket limit under certain loads - sge_execd needs to read /etc/passwd - Allow denyhost to check network state - NetworkManager needs to read sessions data - Allow denyhost to check network state - Allow xen to search virt images directories - Add label for /dev/megaraid_sas_ioctl_node - Add autogenerated man pages- Allow boinc project to getattr on fs - Allow init to execute initrc_state_t - rhev-agent package was rename to ovirt-guest-agent - If initrc_t creates /etc/local.conf then we need to make sure it is labeled correctly - sytemd writes content to /run/initramfs and executes it on shutdown - kdump_t needs to read /etc/mtab, should be back ported to F16 - udev needs to load kernel modules in early system boot- Need to add sys_ptrace back in since reading any content in /proc can cause these accesses - Add additional systemd interfaces which are needed fro *_admin interfaces - Fix bind_admin() interface- Allow firewalld to read urand - Alias java, execmem_mono to bin_t to allow third parties - Add label for kmod - /etc/redhat-lsb contains binaries - Add boolean to allow gitosis to send mail - Add filename transition also for "event20" - Allow systemd_tmpfiles_t to delete all file types - Allow collectd to ipc_lock- make consoletype_exec optional, so we can remove consoletype policy - remove unconfined_permisive.patch - Allow openvpn_t to inherit user home content and tmp content - Fix dnssec-trigger labeling - Turn on obex policy for staff_t - Pem files should not be secret - Add lots of rules to fix AVC's when playing with containers - Fix policy for dnssec - Label ask-passwd directories correctly for systemd- sshd fixes seem to be causing unconfined domains to dyntrans to themselves - fuse file system is now being mounted in /run/user - systemd_logind is sending signals to processes that are dbus messaging with it - Add support for winshadow port and allow iscsid to connect to this port - httpd should be allowed to bind to the http_port_t udp socket - zarafa_var_lib_t can be a lnk_file - A couple of new .xsession-errors files - Seems like user space and login programs need to read logind_sessions_files - Devicekit disk seems to be being launched by systemd - Cleanup handling of setfiles so most of rules in te file - Correct port number for dnssec - logcheck has the home dir set to its cache- Add policy for grindengine MPI jobs- Add new sysadm_secadm.pp module * contains secadm definition for sysadm_t - Move user_mail_domain access out of the interface into the te file - Allow httpd_t to create httpd_var_lib_t directories as well as files - Allow snmpd to connect to the ricci_modcluster stream - Allow firewalld to read /etc/passwd - Add auth_use_nsswitch for colord - Allow smartd to read network state - smartdnotify needs to read /etc/group- Allow gpg and gpg_agent to store sock_file in gpg_secret_t directory - lxdm startup scripts should be labeled bin_t, so confined users will work - mcstransd now creates a pid, needs back port to F16 - qpidd should be allowed to connect to the amqp port - Label devices 010-029 as usb devices - ypserv packager says ypserv does not use tmp_t so removing selinux policy types - Remove all ptrace commands that I believe are caused by the kernel/ps avcs - Add initial Obex policy - Add logging_syslogd_use_tty boolean - Add polipo_connect_all_unreserved bolean - Allow zabbix to connect to ftp port - Allow systemd-logind to be able to switch VTs - Allow apache to communicate with memcached through a sock_file- Fix file_context.subs_dist for now to work with pre usrmove- More /usr move fixes- Add zabbix_can_network boolean - Add httpd_can_connect_zabbix boolean - Prepare file context labeling for usrmove functions - Allow system cronjobs to read kernel network state - Add support for selinux_avcstat munin plugin - Treat hearbeat with corosync policy - Allow corosync to read and write to qpidd shared mem - mozilla_plugin is trying to run pulseaudio - Fixes for new sshd patch for running priv sep domains as the users context - Turn off dontaudit rules when turning on allow_ypbind - udev now reads /etc/modules.d directory- Turn on deny_ptrace boolean for the Rawhide run, so we can test this out - Cups exchanges dbus messages with init - udisk2 needs to send syslog messages - certwatch needs to read /etc/passwd- Add labeling for udisks2 - Allow fsadmin to communicate with the systemd process- Treat Bip with bitlbee policy * Bip is an IRC proxy - Add port definition for interwise port - Add support for ipa_memcached socket - systemd_jounald needs to getattr on all processes - mdadmin fixes * uses getpw - amavisd calls getpwnam() - denyhosts calls getpwall()- Setup labeling of /var/rsa and /var/lib/rsa to allow login programs to write there - bluetooth says they do not use /tmp and want to remove the type - Allow init to transition to colord - Mongod needs to read /proc/sys/vm/zone_reclaim_mode - Allow postfix_smtpd_t to connect to spamd - Add boolean to allow ftp to connect to all ports > 1023 - Allow sendmain to write to inherited dovecot tmp files - setroubleshoot needs to be able to execute rpm to see what version of packages- Merge systemd patch - systemd-tmpfiles wants to relabel /sys/devices/system/cpu/online - Allow deltacloudd dac_override, setuid, setgid caps - Allow aisexec to execute shell - Add use_nfs_home_dirs boolean for ssh-keygen- Fixes to make rawhide boot in enforcing mode with latest systemd changes- Add labeling for /var/run/systemd/journal/syslog - libvirt sends signals to ifconfig - Allow domains that read logind session files to list them- Fixed destined form libvirt-sandbox - Allow apps that list sysfs to also read sympolicy links in this filesystem - Add ubac_constrained rules for chrome_sandbox - Need interface to allow domains to use tmpfs_t files created by the kernel, used by libra - Allow postgresql to be executed by the caller - Standardize interfaces of daemons - Add new labeling for mm-handler - Allow all matahari domains to read network state and etc_runtime_t files- New fix for seunshare, requires seunshare_domains to be able to mounton / - Allow systemctl running as logrotate_t to connect to private systemd socket - Allow tmpwatch to read meminfo - Allow rpc.svcgssd to read supported_krb5_enctype - Allow zarafa domains to read /dev/random and /dev/urandom - Allow snmpd to read dev_snmp6 - Allow procmail to talk with cyrus - Add fixes for check_disk and check_nagios plugins- default trans rules for Rawhide policy - Make sure sound_devices controlC* are labeled correctly on creation - sssd now needs sys_admin - Allow snmp to read all proc_type - Allow to setup users homedir with quota.group- Add httpd_can_connect_ldap() interface - apcupsd_t needs to use seriel ports connected to usb devices - Kde puts procmail mail directory under ~/.local/share - nfsd_t can trigger sys_rawio on tests that involve too many mountpoints, dontaudit for now - Add labeling for /sbin/iscsiuio- Add label for /var/lib/iscan/interpreter - Dont audit writes to leaked file descriptors or redirected output for nacl - NetworkManager needs to write to /sys/class/net/ib*/mode- Allow abrt to request the kernel to load a module - Make sure mozilla content is labeled correctly - Allow tgtd to read system state - More fixes for boinc * allow to resolve dns name * re-write boinc policy to use boinc_domain attribute - Allow munin services plugins to use NSCD services- Allow mozilla_plugin_t to manage mozilla_home_t - Allow ssh derived domain to execute ssh-keygen in the ssh_keygen_t domain - Add label for tumblerd- Fixes for xguest package- Fixes related to /bin, /sbin - Allow abrt to getattr on blk files - Add type for rhev-agent log file - Fix labeling for /dev/dmfm - Dontaudit wicd leaking - Allow systemd_logind_t to look at process info of apps that exchange dbus messages with it - Label /etc/locale.conf correctly - Allow user_mail_t to read /dev/random - Allow postfix-smtpd to read MIMEDefang - Add label for /var/log/suphp.log - Allow swat_t to connect and read/write nmbd_t sock_file - Allow systemd-tmpfiles to setattr for /run/user/gdm/dconf - Allow systemd-tmpfiles to change user identity in object contexts - More fixes for rhev_agentd_t consolehelper policy- Use fs_use_xattr for squashf - Fix procs_type interface - Dovecot has a new fifo_file /var/run/dovecot/stats-mail - Dovecot has a new fifo_file /var/run/stats-mail - Colord does not need to connect to network - Allow system_cronjob to dbus chat with NetworkManager - Puppet manages content, want to make sure it labels everything correctly- Change port 9050 to tor_socks_port_t and then allow openvpn to connect to it - Allow all postfix domains to use the fifo_file - Allow sshd_t to getattr on all file systems in order to generate avc on nfs_t - Allow apmd_t to read grub.cfg - Let firewallgui read the selinux config - Allow systemd-tmpfiles to delete content in /root that has been moved to /tmp - Fix devicekit_manage_pid_files() interface - Allow squid to check the network state - Dontaudit colord getattr on file systems - Allow ping domains to read zabbix_tmp_t files- Allow mcelog_t to create dir and file in /var/run and label it correctly - Allow dbus to manage fusefs - Mount needs to read process state when mounting gluster file systems - Allow collectd-web to read collectd lib files - Allow daemons and system processes started by init to read/write the unix_stream_socket passed in from as stdin/stdout/stderr - Allow colord to get the attributes of tmpfs filesystem - Add sanlock_use_nfs and sanlock_use_samba booleans - Add bin_t label for /usr/lib/virtualbox/VBoxManage- Add ssh_dontaudit_search_home_dir - Changes to allow namespace_init_t to work - Add interface to allow exec of mongod, add port definition for mongod port, 27017 - Label .kde/share/apps/networkmanagement/certificates/ as home_cert_t - Allow spamd and clamd to steam connect to each other - Add policy label for passwd.OLD - More fixes for postfix and postfix maildro - Add ftp support for mozilla plugins - Useradd now needs to manage policy since it calls libsemanage - Fix devicekit_manage_log_files() interface - Allow colord to execute ifconfig - Allow accountsd to read /sys - Allow mysqld-safe to execute shell - Allow openct to stream connect to pcscd - Add label for /var/run/nm-dns-dnsmasq\.conf - Allow networkmanager to chat with virtd_t- Pulseaudio changes - Merge patches- Merge patches back into git repository.- Remove allow_execmem boolean and replace with deny_execmem boolean- Turn back on allow_execmem boolean- Add more MCS fixes to make sandbox working - Make faillog MLS trusted to make sudo_$1_t working - Allow sandbox_web_client_t to read passwd_file_t - Add .mailrc file context - Remove execheap from openoffice domain - Allow chrome_sandbox_nacl_t to read cpu_info - Allow virtd to relabel generic usb which is need if USB device - Fixes for virt.if interfaces to consider chr_file as image file type- Remove Open Office policy - Remove execmem policy- MCS fixes - quota fixes- Remove transitions to consoletype- Make nvidia* to be labeled correctly - Fix abrt_manage_cache() interface - Make filetrans rules optional so base policy will build - Dontaudit chkpwd_t access to inherited TTYS - Make sure postfix content gets created with the correct label - Allow gnomeclock to read cgroup - Fixes for cloudform policy- Check in fixed for Chrome nacl support- Begin removing qemu_t domain, we really no longer need this domain. - systemd_passwd needs dac_overide to communicate with users TTY's - Allow svirt_lxc domains to send kill signals within their container- Remove qemu.pp again without causing a crash- Remove qemu.pp, everything should use svirt_t or stay in its current domain- Allow policykit to talk to the systemd via dbus - Move chrome_sandbox_nacl_t to permissive domains - Additional rules for chrome_sandbox_nacl- Change bootstrap name to nacl - Chrome still needs execmem - Missing role for chrome_sandbox_bootstrap - Add boolean to remove execmem and execstack from virtual machines - Dontaudit xdm_t doing an access_check on etc_t directories- Allow named to connect to dirsrv by default - add ldapmap1_0 as a krb5_host_rcache_t file - Google chrome developers asked me to add bootstrap policy for nacl stuff - Allow rhev_agentd_t to getattr on mountpoints - Postfix_smtpd_t needs access to milters and cleanup seems to read/write postfix_smtpd_t unix_stream_sockets- Fixes for cloudform policies which need to connect to random ports - Make sure if an admin creates modules content it creates them with the correct label - Add port 8953 as a dns port used by unbound - Fix file name transition for alsa and confined users- Turn on mock_t and thumb_t for unconfined domains- Policy update should not modify local contexts- Remove ada policy- Remove tzdata policy - Add labeling for udev - Add cloudform policy - Fixes for bootloader policy- Add policies for nova openstack- Add fixes for nova-stack policy- Allow svirt_lxc_domain to chr_file and blk_file devices if they are in the domain - Allow init process to setrlimit on itself - Take away transition rules for users executing ssh-keygen - Allow setroubleshoot_fixit_t to read /dev/urand - Allow sshd to relbale tunnel sockets - Allow fail2ban domtrans to shorewall in the same way as with iptables - Add support for lnk files in the /var/lib/sssd directory - Allow system mail to connect to courier-authdaemon over an unix stream socket- Add passwd_file_t for /etc/ptmptmp- Dontaudit access checks for all executables, gnome-shell is doing access(EXEC, X_OK) - Make corosync to be able to relabelto cluster lib fies - Allow samba domains to search /var/run/nmbd - Allow dirsrv to use pam - Allow thumb to call getuid - chrome less likely to get mmap_zero bug so removing dontaudit - gimp help-browser has built in javascript - Best guess is that devices named /dev/bsr4096 should be labeled as cpu_device_t - Re-write glance policy- Move dontaudit sys_ptrace line from permissive.te to domain.te - Remove policy for hal, it no longer exists- Don't check md5 size or mtime on certain config files- Remove allow_ptrace and replace it with deny_ptrace, which will remove all ptrace from the system - Remove 2000 dontaudit rules between confined domains on transition and replace with single dontaudit domain domain:process { noatsecure siginh rlimitinh } ;- Fixes for bootloader policy - $1_gkeyringd_t needs to read $HOME/%USER/.local/share/keystore - Allow nsplugin to read /usr/share/config - Allow sa-update to update rules - Add use_fusefs_home_dirs for chroot ssh option - Fixes for grub2 - Update systemd_exec_systemctl() interface - Allow gpg to read the mail spool - More fixes for sa-update running out of cron job - Allow ipsec_mgmt_t to read hardware state information - Allow pptp_t to connect to unreserved_port_t - Dontaudit getattr on initctl in /dev from chfn - Dontaudit getattr on kernel_core from chfn - Add systemd_list_unit_dirs to systemd_exec_systemctl call - Fixes for collectd policy - CHange sysadm_t to create content as user_tmp_t under /tmp- Shrink size of policy through use of attributes for userdomain and apache- Allow virsh to read xenstored pid file - Backport corenetwork fixes from upstream - Do not audit attempts by thumb to search config_home_t dirs (~/.config) - label ~/.cache/telepathy/logger telepathy_logger_cache_home_t - allow thumb to read generic data home files (mime.type)- Allow nmbd to manage sock file in /var/run/nmbd - ricci_modservice send syslog msgs - Stop transitioning from unconfined_t to ldconfig_t, but make sure /etc/ld.so.cache is labeled correctly - Allow systemd_logind_t to manage /run/USER/dconf/user- Fix missing patch from F16- Allow logrotate setuid and setgid since logrotate is supposed to do it - Fixes for thumb policy by grift - Add new nfsd ports - Added fix to allow confined apps to execmod on chrome - Add labeling for additional vdsm directories - Allow Exim and Dovecot SASL - Add label for /var/run/nmbd - Add fixes to make virsh and xen working together - Colord executes ls - /var/spool/cron is now labeled as user_cron_spool_t- Stop complaining about leaked file descriptors during install- Remove java and mono module and merge into execmem- Fixes for thumb policy and passwd_file_t- Fixes caused by the labeling of /etc/passwd - Add thumb.patch to transition unconfined_t to thumb_t for Rawhide- Add support for Clustered Samba commands - Allow ricci_modrpm_t to send log msgs - move permissive virt_qmf_t from virt.te to permissivedomains.te - Allow ssh_t to use kernel keyrings - Add policy for libvirt-qmf and more fixes for linux containers - Initial Polipo - Sanlock needs to run ranged in order to kill svirt processes - Allow smbcontrol to stream connect to ctdbd- Add label for /etc/passwd- Change unconfined_domains to permissive for Rawhide - Add definition for the ephemeral_ports- Make mta_role() active - Allow asterisk to connect to jabber client port - Allow procmail to read utmp - Add NIS support for systemd_logind_t - Allow systemd_logind_t to manage /run/user/$USER/dconf dir which is labeled as config_home_t - Fix systemd_manage_unit_dirs() interface - Allow ssh_t to manage directories passed into it - init needs to be able to create and delete unit file directories - Fix typo in apache_exec_sys_script - Add ability for logrotate to transition to awstat domain- Change screen to use screen_domain attribute and allow screen_domains to read all process domain state - Add SELinux support for ssh pre-auth net process in F17 - Add logging_syslogd_can_sendmail boolean- Add definition for ephemeral ports - Define user_tty_device_t as a customizable_type- Needs to require a new version of checkpolicy - Interface fixes- Allow sanlock to manage virt lib files - Add virt_use_sanlock booelan - ksmtuned is trying to resolve uids - Make sure .gvfs is labeled user_home_t in the users home directory - Sanlock sends kill signals and needs the kill capability - Allow mockbuild to work on nfs homedirs - Fix kerberos_manage_host_rcache() interface - Allow exim to read system state- Allow systemd-tmpfiles to set the correct labels on /var/run, /tmp and other files - We want any file type that is created in /tmp by a process running as initrc_t to be labeled initrc_tmp_t- Allow collectd to read hardware state information - Add loop_control_device_t - Allow mdadm to request kernel to load module - Allow domains that start other domains via systemctl to search unit dir - systemd_tmpfilses, needs to list any file systems mounted on /tmp - No one can explain why radius is listing the contents of /tmp, so we will dontaudit - If I can manage etc_runtime files, I should be able to read the links - Dontaudit hostname writing to mock library chr_files - Have gdm_t setup labeling correctly in users home dir - Label content unde /var/run/user/NAME/dconf as config_home_t - Allow sa-update to execute shell - Make ssh-keygen working with fips_enabled - Make mock work for staff_t user - Tighten security on mock_t- removing unconfined_notrans_t no longer necessary - Clean up handling of secure_mode_insmod and secure_mode_policyload - Remove unconfined_mount_t- Add exim_exec_t label for /usr/sbin/exim_tidydb - Call init_dontaudit_rw_stream_socket() interface in mta policy - sssd need to search /var/cache/krb5rcache directory - Allow corosync to relabel own tmp files - Allow zarafa domains to send system log messages - Allow ssh to do tunneling - Allow initrc scripts to sendto init_t unix_stream_socket - Changes to make sure dmsmasq and virt directories are labeled correctly - Changes needed to allow sysadm_t to manage systemd unit files - init is passing file descriptors to dbus and on to system daemons - Allow sulogin additional access Reported by dgrift and Jeremy Miller - Steve Grubb believes that wireshark does not need this access - Fix /var/run/initramfs to stop restorecon from looking at - pki needs another port - Add more labels for cluster scripts - Allow apps that manage cgroup_files to manage cgroup link files - Fix label on nfs-utils scripts directories - Allow gatherd to read /dev/rand and /dev/urand- pki needs another port - Add more labels for cluster scripts - Fix label on nfs-utils scripts directories - Fixes for cluster - Allow gatherd to read /dev/rand and /dev/urand - abrt leaks fifo files- Add glance policy - Allow mdadm setsched - /var/run/initramfs should not be relabeled with a restorecon run - memcache can be setup to override sys_resource - Allow httpd_t to read tetex data - Allow systemd_tmpfiles to delete kernel modules left in /tmp directory.- Allow Postfix to deliver to Dovecot LMTP socket - Ignore bogus sys_module for lldpad - Allow chrony and gpsd to send dgrams, gpsd needs to write to the real time clock - systemd_logind_t sets the attributes on usb devices - Allow hddtemp_t to read etc_t files - Add permissivedomains module - Move all permissive domains calls to permissivedomain.te - Allow pegasis to send kill signals to other UIDs- Allow insmod_t to use fds leaked from devicekit - dontaudit getattr between insmod_t and init_t unix_stream_sockets - Change sysctl unit file interfaces to use systemctl - Add support for chronyd unit file - Allow mozilla_plugin to read gnome_usr_config - Add policy for new gpsd - Allow cups to create kerberos rhost cache files - Add authlogin_filetrans_named_content, to unconfined_t to make sure shadow and other log files get labeled correctly- Make users_extra and seusers.final into config(noreplace) so semanage users and login does not get overwritten- Add policy for sa-update being run out of cron jobs - Add create perms to postgresql_manage_db - ntpd using a gps has to be able to read/write generic tty_device_t - If you disable unconfined and unconfineduser, rpm needs more privs to manage /dev - fix spec file - Remove qemu_domtrans_unconfined() interface - Make passenger working together with puppet - Add init_dontaudit_rw_stream_socket interface - Fixes for wordpress- Turn on allow_domain_fd_use boolean on F16 - Allow syslog to manage all log files - Add use_fusefs_home_dirs boolean for chrome - Make vdagent working with confined users - Add abrt_handle_event_t domain for ABRT event scripts - Labeled /usr/sbin/rhnreg_ks as rpm_exec_t and added changes related to this change - Allow httpd_git_script_t to read passwd data - Allow openvpn to set its process priority when the nice parameter is used- livecd fixes - spec file fixes- fetchmail can use kerberos - ksmtuned reads in shell programs - gnome_systemctl_t reads the process state of ntp - dnsmasq_t asks the kernel to load multiple kernel modules - Add rules for domains executing systemctl - Bogus text within fc file- Add cfengine policy- Add abrt_domain attribute - Allow corosync to manage cluster lib files - Allow corosync to connect to the system DBUS- Add sblim, uuidd policies - Allow kernel_t dyntrasition to init_t- init_t need setexec - More fixes of rules which cause an explosion in rules by Dan Walsh- Allow rcsmcertd to perform DNS name resolution - Add dirsrvadmin_unconfined_script_t domain type for 389-ds admin scripts - Allow tmux to run as screen - New policy for collectd - Allow gkeyring_t to interact with all user apps - Add rules to allow firstboot to run on machines with the unconfined.pp module removed- Allow systemd_logind to send dbus messages with users - allow accountsd to read wtmp file - Allow dhcpd to get and set capabilities- Fix oracledb_port definition - Allow mount to mounton the selinux file system - Allow users to list /var directories- systemd fixes- Add initial policy for abrt_dump_oops_t - xtables-multi wants to getattr of the proc fs - Smoltclient is connecting to abrt - Dontaudit leaked file descriptors to postdrop - Allow abrt_dump_oops to look at kernel sysctls - Abrt_dump_oops_t reads kernel ring buffer - Allow mysqld to request the kernel to load modules - systemd-login needs fowner - Allow postfix_cleanup_t to searh maildrop- Initial systemd_logind policy - Add policy for systemd_logger and additional proivs for systemd_logind - More fixes for systemd policies- Allow setsched for virsh - Systemd needs to impersonate cups, which means it needs to create tcp_sockets in cups_t domain, as well as manage spool directories - iptables: the various /sbin/ip6?tables.* are now symlinks for /sbin/xtables-multi- A lot of users are running yum -y update while in /root which is causing ldconfig to list the contents, adding dontaudit - Allow colord to interact with the users through the tmpfs file system - Since we changed the label on deferred, we need to allow postfix_qmgr_t to be able to create maildrop_t files - Add label for /var/log/mcelog - Allow asterisk to read /dev/random if it uses TLS - Allow colord to read ini files which are labeled as bin_t - Allow dirsrvadmin sys_resource and setrlimit to use ulimit - Systemd needs to be able to create sock_files for every label in /var/run directory, cupsd being the first. - Also lists /var and /var/spool directories - Add openl2tpd to l2tpd policy - qpidd is reading the sysfs file- Change usbmuxd_t to dontaudit attempts to read chr_file - Add mysld_safe_exec_t for libra domains to be able to start private mysql domains - Allow pppd to search /var/lock dir - Add rhsmcertd policy- Update to upstream- More fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git- Fix spec file to not report Verify errors- Add dspam policy - Add lldpad policy - dovecot auth wants to search statfs #713555 - Allow systemd passwd apps to read init fifo_file - Allow prelink to use inherited terminals - Run cherokee in the httpd_t domain - Allow mcs constraints on node connections - Implement pyicqt policy - Fixes for zarafa policy - Allow cobblerd to send syslog messages- Add policy.26 to the payload - Remove olpc stuff - Remove policygentool- Fixes for zabbix - init script needs to be able to manage sanlock_var_run_... - Allow sandlock and wdmd to create /var/run directories... - mixclip.so has been compiled correctly - Fix passenger policy module name- Add mailscanner policy from dgrift - Allow chrome to optionally be transitioned to - Zabbix needs these rules when starting the zabbix_server_mysql - Implement a type for freedesktop openicc standard (~/.local/share/icc) - Allow system_dbusd_t to read inherited icc_data_home_t files. - Allow colord_t to read icc_data_home_t content. #706975 - Label stuff under /usr/lib/debug as if it was labeled under /- Fixes for sanlock policy - Fixes for colord policy - Other fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Add rhev policy module to modules-targeted.conf- Lot of fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Allow logrotate to execute systemctl - Allow nsplugin_t to getattr on gpmctl - Fix dev_getattr_all_chr_files() interface - Allow shorewall to use inherited terms - Allow userhelper to getattr all chr_file devices - sandbox domains should be able to getattr and dontaudit search of sysctl_kernel_t - Fix labeling for ABRT Retrace Server- Dontaudit sys_module for ifconfig - Make telepathy and gkeyringd daemon working with confined users - colord wants to read files in users homedir - Remote login should be creating user_tmp_t not its own tmp files- Fix label for /usr/share/munin/plugins/munin_* plugins - Add support for zarafa-indexer - Fix boolean description - Allow colord to getattr on /proc/scsi/scsi - Add label for /lib/upstart/init - Colord needs to list /mnt- Forard port changes from F15 for telepathy - NetworkManager should be allowed to use /dev/rfkill - Fix dontaudit messages to say Domain to not audit - Allow telepathy domains to read/write gnome_cache files - Allow telepathy domains to call getpw - Fixes for colord and vnstatd policy- Allow init_t getcap and setcap - Allow namespace_init_t to use nsswitch - aisexec will execute corosync - colord tries to read files off noxattr file systems - Allow init_t getcap and setcap- Add support for ABRT retrace server - Allow user_t and staff_t access to generic scsi to handle locally plugged in scanners - Allow telepath_msn_t to read /proc/PARENT/cmdline - ftpd needs kill capability - Allow telepath_msn_t to connect to sip port - keyring daemon does not work on nfs homedirs - Allow $1_sudo_t to read default SELinux context - Add label for tgtd sock file in /var/run/ - Add apache_exec_rotatelogs interface - allow all zaraha domains to signal themselves, server writes to /tmp - Allow syslog to read the process state - Add label for /usr/lib/chromium-browser/chrome - Remove the telepathy transition from unconfined_t - Dontaudit sandbox domains trying to mounton sandbox_file_t, this is caused by fuse mounts - Allow initrc_t domain to manage abrt pid files - Add support for AEOLUS project - Virt_admin should be allowed to manage images and processes - Allow plymountd to send signals to init - Change labeling of fping6- Add filename transitions- Fixes for zarafa policy - Add support for AEOLUS project - Change labeling of fping6 - Allow plymountd to send signals to init - Allow initrc_t domain to manage abrt pid files - Virt_admin should be allowed to manage images and processes- xdm_t needs getsession for switch user - Every app that used to exec init is now execing systemdctl - Allow squid to manage krb5_host_rcache_t files - Allow foghorn to connect to agentx port - Fixes for colord policy- Add Dan's patch to remove 64 bit variants - Allow colord to use unix_dgram_socket - Allow apps that search pids to read /var/run if it is a lnk_file - iscsid_t creates its own directory - Allow init to list var_lock_t dir - apm needs to verify user accounts auth_use_nsswitch - Add labeling for systemd unit files - Allow gnomeclok to enable ntpd service using systemctl - systemd_systemctl_t domain was added - Add label for matahari-broker.pid file - We want to remove untrustedmcsprocess from ability to read /proc/pid - Fixes for matahari policy - Allow system_tmpfiles_t to delete user_home_t files in the /tmp dir - Allow sshd to transition to sysadm_t if ssh_sysadm_login is turned on- Fix typo- Add /var/run/lock /var/lock definition to file_contexts.subs - nslcd_t is looking for kerberos cc files - SSH_USE_STRONG_RNG is 1 which requires /dev/random - Fix auth_rw_faillog definition - Allow sysadm_t to set attributes on fixed disks - allow user domains to execute lsof and look at application sockets - prelink_cron job calls telinit -u if init is rewritten - Fixes to run qemu_t from staff_t- Fix label for /var/run/udev to udev_var_run_t - Mock needs to be able to read network state- Add file_contexts.subs to handle /run and /run/lock - Add other fixes relating to /run changes from F15 policy- Allow $1_sudo_t and $1_su_t open access to user terminals - Allow initrc_t to use generic terminals - Make Makefile/Rules.modular run sepolgen-ifgen during build to check if files for bugs -systemd is going to be useing /run and /run/lock for early bootup files. - Fix some comments in rlogin.if - Add policy for KDE backlighthelper - sssd needs to read ~/.k5login in nfs, cifs or fusefs file systems - sssd wants to read .k5login file in users homedir - setroubleshoot reads executables to see if they have TEXTREL - Add /var/spool/audit support for new version of audit - Remove kerberos_connect_524() interface calling - Combine kerberos_master_port_t and kerberos_port_t - systemd has setup /dev/kmsg as stderr for apps it executes - Need these access so that init can impersonate sockets on unix_dgram_socket- Remove some unconfined domains - Remove permissive domains - Add policy-term.patch from Dan- Fix multiple specification for boot.log - devicekit leaks file descriptors to setfiles_t - Change all all_nodes to generic_node and all_if to generic_if - Should not use deprecated interface - Switch from using all_nodes to generic_node and from all_if to generic_if - Add support for xfce4-notifyd - Fix file context to show several labels as SystemHigh - seunshare needs to be able to mounton nfs/cifs/fusefs homedirs - Add etc_runtime_t label for /etc/securetty - Fixes to allow xdm_t to start gkeyringd_USERTYPE_t directly - login.krb needs to be able to write user_tmp_t - dirsrv needs to bind to port 7390 for dogtag - Fix a bug in gpg policy - gpg sends audit messages - Allow qpid to manage matahari files- Initial policy for matahari - Add dev_read_watchdog - Allow clamd to connect clamd port - Add support for kcmdatetimehelper - Allow shutdown to setrlimit and sys_nice - Allow systemd_passwd to talk to /dev/log before udev or syslog is running - Purge chr_file and blk files on /tmp - Fixes for pads - Fixes for piranha-pulse - gpg_t needs to be able to encyprt anything owned by the user- mozilla_plugin_tmp_t needs to be treated as user tmp files - More dontaudits of writes from readahead - Dontaudit readahead_t file_type:dir write, to cover up kernel bug - systemd_tmpfiles needs to relabel faillog directory as well as the file - Allow hostname and consoletype to r/w inherited initrc_tmp_t files handline hostname >> /tmp/myhost- Add policykit fixes from Tim Waugh - dontaudit sandbox domains sandbox_file_t:dir mounton - Add new dontaudit rules for sysadm_dbusd_t - Change label for /var/run/faillock * other fixes which relate with this change- Update to upstream - Fixes for telepathy - Add port defition for ssdp port - add policy for /bin/systemd-notify from Dan - Mount command requires users read mount_var_run_t - colord needs to read konject_uevent_socket - User domains connect to the gkeyring socket - Add colord policy and allow user_t and staff_t to dbus chat with it - Add lvm_exec_t label for kpartx - Dontaudit reading the mail_spool_t link from sandbox -X - systemd is creating sockets in avahi_var_run and system_dbusd_var_run- gpg_t needs to talk to gnome-keyring - nscd wants to read /usr/tmp->/var/tmp to generate randomziation in unixchkpwd - enforce MCS labeling on nodes - Allow arpwatch to read meminfo - Allow gnomeclock to send itself signals - init relabels /dev/.udev files on boot - gkeyringd has to transition back to staff_t when it runs commands in bin_t or shell_exec_t - nautilus checks access on /media directory before mounting usb sticks, dontaudit access_check on mnt_t - dnsmasq can run as a dbus service, needs acquire service - mysql_admin should be allowed to connect to mysql service - virt creates monitor sockets in the users home dir- Allow usbhid-ups to read hardware state information - systemd-tmpfiles has moved - Allo cgroup to sys_tty_config - For some reason prelink is attempting to read gconf settings - Add allow_daemons_use_tcp_wrapper boolean - Add label for ~/.cache/wocky to make telepathy work in enforcing mode - Add label for char devices /dev/dasd* - Fix for apache_role - Allow amavis to talk to nslcd - allow all sandbox to read selinux poilcy config files - Allow cluster domains to use the system bus and send each other dbus messages- Update to upstream- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Update to ref policy - cgred needs chown capability - Add /dev/crash crash_dev_t - systemd-readahead wants to use fanotify which means readahead_t needs sys_admin capability- New labeling for postfmulti #675654 - dontaudit xdm_t listing noxattr file systems - dovecot-auth needs to be able to connect to mysqld via the network as well as locally - shutdown is passed stdout to a xdm_log_t file - smartd creates a fixed disk device - dovecot_etc_t contains a lnk_file that domains need to read - mount needs to be able to read etc_runtim_t:lnk_file since in rawhide this is a link created at boot- syslog_t needs syslog capability - dirsrv needs to be able to create /var/lib/snmp - Fix labeling for dirsrv - Fix for dirsrv policy missing manage_dirs_pattern - corosync needs to delete clvm_tmpfs_t files - qdiskd needs to list hugetlbfs - Move setsched to sandbox_x_domain, so firefox can run without network access - Allow hddtemp to read removable devices - Adding syslog and read_policy permissions to policy * syslog Allow unconfined, sysadm_t, secadm_t, logadm_t * read_policy allow unconfined, sysadm_t, secadm_t, staff_t on Targeted allow sysadm_t (optionally), secadm_t on MLS - mdadm application will write into /sys/.../uevent whenever arrays are assembled or disassembled.- Add tcsd policy- ricci_modclusterd_t needs to bind to rpc ports 500-1023 - Allow dbus to use setrlimit to increase resoueces - Mozilla_plugin is leaking to sandbox - Allow confined users to connect to lircd over unix domain stream socket which allow to use remote control - Allow awstats to read squid logs - seunshare needs to manage tmp_t - apcupsd cgi scripts have a new directory- Fix xserver_dontaudit_read_xdm_pid - Change oracle_port_t to oracledb_port_t to prevent conflict with satellite - Allow dovecot_deliver_t to read/write postfix_master_t:fifo_file. * These fifo_file is passed from postfix_master_t to postfix_local_t to dovecot_deliver_t - Allow readahead to manage readahead pid dirs - Allow readahead to read all mcs levels - Allow mozilla_plugin_t to use nfs or samba homedirs- Allow nagios plugin to read /proc/meminfo - Fix for mozilla_plugin - Allow samba_net_t to create /etc/keytab - pppd_t setting up vpns needs to run unix_chkpwd, setsched its process and write wtmp_t - nslcd can read user credentials - Allow nsplugin to delete mozilla_plugin_tmpfs_t - abrt tries to create dir in rpm_var_lib_t - virt relabels fifo_files - sshd needs to manage content in fusefs homedir - mock manages link files in cache dir- nslcd needs setsched and to read /usr/tmp - Invalid call in likewise policy ends up creating a bogus role - Cannon puts content into /var/lib/bjlib that cups needs to be able to write - Allow screen to create screen_home_t in /root - dirsrv sends syslog messages - pinentry reads stuff in .kde directory - Add labels for .kde directory in homedir - Treat irpinit, iprupdate, iprdump services with raid policy- NetworkManager wants to read consolekit_var_run_t - Allow readahead to create /dev/.systemd/readahead - Remove permissive domains - Allow newrole to run namespace_init- Add sepgsql_contexts file- Update to upstream- Add oracle ports and allow apache to connect to them if the connect_db boolean is turned on - Add puppetmaster_use_db boolean - Fixes for zarafa policy - Fixes for gnomeclock poliy - Fix systemd-tmpfiles to use auth_use_nsswitch- gnomeclock executes a shell - Update for screen policy to handle pipe in homedir - Fixes for polyinstatiated homedir - Fixes for namespace policy and other fixes related to polyinstantiation - Add namespace policy - Allow dovecot-deliver transition to sendmail which is needed by sieve scripts - Fixes for init, psad policy which relate with confined users - Do not audit bootloader attempts to read devicekit pid files - Allow nagios service plugins to read /proc- Add firewalld policy - Allow vmware_host to read samba config - Kernel wants to read /proc Fix duplicate grub def in cobbler - Chrony sends mail, executes shell, uses fifo_file and reads /proc - devicekitdisk getattr all file systems - sambd daemon writes wtmp file - libvirt transitions to dmidecode- Add initial policy for system-setup-keyboard which is now daemon - Label /var/lock/subsys/shorewall as shorewall_lock_t - Allow users to communicate with the gpg_agent_t - Dontaudit mozilla_plugin_t using the inherited terminal - Allow sambagui to read files in /usr - webalizer manages squid log files - Allow unconfined domains to bind ports to raw_ip_sockets - Allow abrt to manage rpm logs when running yum - Need labels for /var/run/bittlebee - Label .ssh under amanda - Remove unused genrequires for virt_domain_template - Allow virt_domain to use fd inherited from virtd_t - Allow iptables to read shorewall config- Gnome apps list config_home_t - mpd creates lnk files in homedir - apache leaks write to mail apps on tmp files - /var/stockmaniac/templates_cache contains log files - Abrt list the connects of mount_tmp_t dirs - passwd agent reads files under /dev and reads utmp file - squid apache script connects to the squid port - fix name of plymouth log file - teamviewer is a wine app - allow dmesg to read system state - Stop labeling files under /var/lib/mock so restorecon will not go into this - nsplugin needs to read network state for google talk- Allow xdm and syslog to use /var/log/boot.log - Allow users to communicate with mozilla_plugin and kill it - Add labeling for ipv6 and dhcp- New labels for ghc http content - nsplugin_config needs to read urand, lvm now calls setfscreate to create dev - pm-suspend now creates log file for append access so we remove devicekit_wri - Change authlogin_use_sssd to authlogin_nsswitch_use_ldap - Fixes for greylist_milter policy- Update to upstream - Fixes for systemd policy - Fixes for passenger policy - Allow staff users to run mysqld in the staff_t domain, akonadi needs this - Add bin_t label for /usr/share/kde4/apps/kajongg/kajongg.py - auth_use_nsswitch does not need avahi to read passwords,needed for resolving data - Dontaudit (xdm_t) gok attempting to list contents of /var/account - Telepathy domains need to read urand - Need interface to getattr all file classes in a mock library for setroubleshoot- Update selinux policy to handle new /usr/share/sandbox/start script- Update to upstream - Fix version of policy in spec file- Allow sandbox to run on nfs partitions, fixes for systemd_tmpfs - remove per sandbox domains devpts types - Allow dkim-milter sending signal to itself- Allow domains that transition to ping or traceroute, kill them - Allow user_t to conditionally transition to ping_t and traceroute_t - Add fixes to systemd- tools, including new labeling for systemd-fsck, systemd-cryptsetup- Turn on systemd policy - mozilla_plugin needs to read certs in the homedir. - Dontaudit leaked file descriptors from devicekit - Fix ircssi to use auth_use_nsswitch - Change to use interface without param in corenet to disable unlabelednet packets - Allow init to relabel sockets and fifo files in /dev - certmonger needs dac* capabilities to manage cert files not owned by root - dovecot needs fsetid to change group membership on mail - plymouthd removes /var/log/boot.log - systemd is creating symlinks in /dev - Change label on /etc/httpd/alias to be all cert_t- Fixes for clamscan and boinc policy - Add boinc_project_t setpgid - Allow alsa to create tmp files in /tmp- Push fixes to allow disabling of unlabeled_t packet access - Enable unlabelednet policy- Fixes for lvm to work with systemd- Fix the label for wicd log - plymouthd creates force-display-on-active-vt file - Allow avahi to request the kernel to load a module - Dontaudit hal leaks - Fix gnome_manage_data interface - Add new interface corenet_packet to define a type as being an packet_type. - Removed general access to packet_type from icecast and squid. - Allow mpd to read alsa config - Fix the label for wicd log - Add systemd policy- Fix gnome_manage_data interface - Dontaudit sys_ptrace capability for iscsid - Fixes for nagios plugin policy- Fix cron to run ranged when started by init - Fix devicekit to use log files - Dontaudit use of devicekit_var_run_t for fstools - Allow init to setattr on logfile directories - Allow hald to manage files in /var/run/pm-utils/ dir which is now labeled as devicekit_var_run_t- Fix up handling of dnsmasq_t creating /var/run/libvirt/network - Turn on sshd_forward_ports boolean by default - Allow sysadmin to dbus chat with rpm - Add interface for rw_tpm_dev - Allow cron to execute bin - fsadm needs to write sysfs - Dontaudit consoletype reading /var/run/pm-utils - Lots of new privs fro mozilla_plugin_t running java app, make mozilla_plugin - certmonger needs to manage dirsrv data - /var/run/pm-utils should be labeled as devicekit_var_run_t- fixes to allow /var/run and /var/lock as tmpfs - Allow chrome sandbox to connect to web ports - Allow dovecot to listem on lmtp and sieve ports - Allov ddclient to search sysctl_net_t - Transition back to original domain if you execute the shell- Remove duplicate declaration- Update to upstream - Cleanup for sandbox - Add attribute to be able to select sandbox types- Allow ddclient to fix file mode bits of ddclient conf file - init leaks file descriptors to daemons - Add labels for /etc/lirc/ and - Allow amavis_t to exec shell - Add label for gssd_tmp_t for /var/tmp/nfs_0- Put back in lircd_etc_t so policy will install- Turn on allow_postfix_local_write_mail_spool - Allow initrc_t to transition to shutdown_t - Allow logwatch and cron to mls_read_to_clearance for MLS boxes - Allow wm to send signull to all applications and receive them from users - lircd patch from field - Login programs have to read /etc/samba - New programs under /lib/systemd - Abrt needs to read config files- Update to upstream - Dontaudit leaked sockets from userdomains to user domains - Fixes for mcelog to handle scripts - Apply patch from Ruben Kerkhof - Allow syslog to search spool dirs- Allow nagios plugins to read usr files - Allow mysqld-safe to send system log messages - Fixes fpr ddclient policy - Fix sasl_admin interface - Allow apache to search zarafa config - Allow munin plugins to search /var/lib directory - Allow gpsd to read sysfs_t - Fix labels on /etc/mcelog/triggers to bin_t- Remove saslauthd_tmp_t and transition tmp files to krb5_host_rcache_t - Allow saslauthd_t to create krb5_host_rcache_t files in /tmp - Fix xserver interface - Fix definition of /var/run/lxdm- Turn on mediawiki policy - kdump leaks kdump_etc_t to ifconfig, add dontaudit - uux needs to transition to uucpd_t - More init fixes relabels man,faillog - Remove maxima defs in libraries.fc - insmod needs to be able to create tmpfs_t files - ping needs setcap- Allow groupd transition to fenced domain when executes fence_node - Fixes for rchs policy - Allow mpd to be able to read samba/nfs files- Fix up corecommands.fc to match upstream - Make sure /lib/systemd/* is labeled init_exec_t - mount wants to setattr on all mountpoints - dovecot auth wants to read dovecot etc files - nscd daemon looks at the exe file of the comunicating daemon - openvpn wants to read utmp file - postfix apps now set sys_nice and lower limits - remote_login (telnetd/login) wants to use telnetd_devpts_t and user_devpts_t to work correctly - Also resolves nsswitch - Fix labels on /etc/hosts.* - Cleanup to make upsteam patch work - allow abrt to read etc_runtime_t- Add conflicts for dirsrv package- Update to upstream - Add vlock policy- Fix sandbox to work on nfs homedirs - Allow cdrecord to setrlimit - Allow mozilla_plugin to read xauth - Change label on systemd-logger to syslogd_exec_t - Install dirsrv policy from dirsrv package- Add virt_home_t, allow init to setattr on xserver_tmp_t and relabel it - Udev needs to stream connect to init and kernel - Add xdm_exec_bootloader boolean, which allows xdm to execute /sbin/grub and read files in /boot directory- Allow NetworkManager to read openvpn_etc_t - Dontaudit hplip to write of /usr dirs - Allow system_mail_t to create /root/dead.letter as mail_home_t - Add vdagent policy for spice agent daemon- Dontaudit sandbox sending sigkill to all user domains - Add policy for rssh_chroot_helper - Add missing flask definitions - Allow udev to relabelto removable_t - Fix label on /var/log/wicd.log - Transition to initrc_t from init when executing bin_t - Add audit_access permissions to file - Make removable_t a device_node - Fix label on /lib/systemd/*- Fixes for systemd to manage /var/run - Dontaudit leaks by firstboot- Allow chome to create netlink_route_socket - Add additional MATHLAB file context - Define nsplugin as an application_domain - Dontaudit sending signals from sandboxed domains to other domains - systemd requires init to build /tmp /var/auth and /var/lock dirs - mount wants to read devicekit_power /proc/ entries - mpd wants to connect to soundd port - Openoffice causes a setattr on a lib_t file for normal users, add dontaudit - Treat lib_t and textrel_shlib_t directories the same - Allow mount read access on virtual images- Allow sandbox_x_domains to work with nfs/cifs/fusefs home dirs. - Allow devicekit_power to domtrans to mount - Allow dhcp to bind to udp ports > 1024 to do named stuff - Allow ssh_t to exec ssh_exec_t - Remove telepathy_butterfly_rw_tmp_files(), dev_read_printk() interfaces which are nolonger used - Fix clamav_append_log() intefaces - Fix 'psad_rw_fifo_file' interface- Allow cobblerd to list cobler appache content- Fixup for the latest version of upowed - Dontaudit sandbox sending SIGNULL to desktop apps- Update to upstream-Mount command from a confined user generates setattr on /etc/mtab file, need to dontaudit this access - dovecot-auth_t needs ipc_lock - gpm needs to use the user terminal - Allow system_mail_t to append ~/dead.letter - Allow NetworkManager to edit /etc/NetworkManager/NetworkManager.conf - Add pid file to vnstatd - Allow mount to communicate with gfs_controld - Dontaudit hal leaks in setfiles- Lots of fixes for systemd - systemd now executes readahead and tmpwatch type scripts - Needs to manage random seed- Allow smbd to use sys_admin - Remove duplicate file context for tcfmgr - Update to upstream- Fix fusefs handling - Do not allow sandbox to manage nsplugin_rw_t - Allow mozilla_plugin_t to connecto its parent - Allow init_t to connect to plymouthd running as kernel_t - Add mediawiki policy - dontaudit sandbox sending signals to itself. This can happen when they are running at different mcs. - Disable transition from dbus_session_domain to telepathy for F14 - Allow boinc_project to use shm - Allow certmonger to search through directories that contain certs - Allow fail2ban the DAC Override so it can read log files owned by non root users- Start adding support for use_fusefs_home_dirs - Add /var/lib/syslog directory file context - Add /etc/localtime as locale file context- Turn off default transition to mozilla_plugin and telepathy domains from unconfined user - Turn off iptables from unconfined user - Allow sudo to send signals to any domains the user could have transitioned to. - Passwd in single user mode needs to talk to console_device_t - Mozilla_plugin_t needs to connect to web ports, needs to write to video device, and read alsa_home_t alsa setsup pulseaudio - locate tried to read a symbolic link, will dontaudit - New labels for telepathy-sunshine content in homedir - Google is storing other binaries under /opt/google/talkplugin - bluetooth/kernel is creating unlabeled_t socket that I will allow it to use until kernel fixes bug - Add boolean for unconfined_t transition to mozilla_plugin_t and telepathy domains, turned off in F14 on in F15 - modemmanger and bluetooth send dbus messages to devicekit_power - Samba needs to getquota on filesystems labeld samba_share_t- Dontaudit attempts by xdm_t to write to bin_t for kdm - Allow initrc_t to manage system_conf_t- Fixes to allow mozilla_plugin_t to create nsplugin_home_t directory. - Allow mozilla_plugin_t to create tcp/udp/netlink_route sockets - Allow confined users to read xdm_etc_t files - Allow xdm_t to transition to xauth_t for lxdm program- Rearrange firewallgui policy to be more easily updated to upstream, dontaudit search of /home - Allow clamd to send signals to itself - Allow mozilla_plugin_t to read user home content. And unlink pulseaudio shm. - Allow haze to connect to yahoo chat and messenger port tcp:5050. Bz #637339 - Allow guest to run ps command on its processes by allowing it to read /proc - Allow firewallgui to sys_rawio which seems to be required to setup masqerading - Allow all domains to search through default_t directories, in order to find differnet labels. For example people serring up /foo/bar to be share via samba. - Add label for /var/log/slim.log- Pull in cleanups from dgrift - Allow mozilla_plugin_t to execute mozilla_home_t - Allow rpc.quota to do quotamod- Cleanup policy via dgrift - Allow dovecot_deliver to append to inherited log files - Lots of fixes for consolehelper- Fix up Xguest policy- Add vnstat policy - allow libvirt to send audit messages - Allow chrome-sandbox to search nfs_t- Update to upstream- Add the ability to send audit messages to confined admin policies - Remove permissive domain from cmirrord and dontaudit sys_tty_config - Split out unconfined_domain() calls from other unconfined_ calls so we can d - virt needs to be able to read processes to clearance for MLS- Allow all domains that can use cgroups to search tmpfs_t directory - Allow init to send audit messages- Update to upstream- Allow mdadm_t to create files and sock files in /dev/md/- Add policy for ajaxterm- Handle /var/db/sudo - Allow pulseaudio to read alsa config - Allow init to send initrc_t dbus messagesAllow iptables to read shorewall tmp files Change chfn and passwd to use auth_use_pam so they can send dbus messages to fpr intd label vlc as an execmem_exec_t Lots of fixes for mozilla_plugin to run google vidio chat Allow telepath_msn to execute ldconfig and its own tmp files Fix labels on hugepages Allow mdadm to read files on /dev Remove permissive domains and change back to unconfined Allow freshclam to execute shell and bin_t Allow devicekit_power to transition to dhcpc Add boolean to allow icecast to connect to any port- Merge upstream fix of mmap_zero - Allow mount to write files in debugfs_t - Allow corosync to communicate with clvmd via tmpfs - Allow certmaster to read usr_t files - Allow dbus system services to search cgroup_t - Define rlogind_t as a login pgm- Allow mdadm_t to read/write hugetlbfs- Dominic Grift Cleanup - Miroslav Grepl policy for jabberd - Various fixes for mount/livecd and prelink- Merge with upstream- More access needed for devicekit - Add dbadm policy- Merge with upstream- Allow seunshare to fowner- Allow cron to look at user_cron_spool links - Lots of fixes for mozilla_plugin_t - Add sysv file system - Turn unconfined domains to permissive to find additional avcs- Update policy for mozilla_plugin_t- Allow clamscan to read proc_t - Allow mount_t to write to debufs_t dir - Dontaudit mount_t trying to write to security_t dir- Allow clamscan_t execmem if clamd_use_jit set - Add policy for firefox plugin-container- Fix /root/.forward definition- label dead.letter as mail_home_t- Allow login programs to search /cgroups- Fix cert handling- Fix devicekit_power bug - Allow policykit_auth_t more access.- Fix nis calls to allow bind to ports 512-1024 - Fix smartmon- Allow pcscd to read sysfs - systemd fixes - Fix wine_mmap_zero_ignore boolean- Apply Miroslav munin patch - Turn back on allow_execmem and allow_execmod booleans- Merge in fixes from dgrift repository- Update boinc policy - Fix sysstat policy to allow sys_admin - Change failsafe_context to unconfined_r:unconfined_t:s0- New paths for upstart- New permissions for syslog - New labels for /lib/upstart- Add mojomojo policy- Allow systemd to setsockcon on sockets to immitate other services- Remove debugfs label- Update to latest policy- Fix eclipse labeling from IBMSupportAssasstant packageing- Make boot with systemd in enforcing mode- Update to upstream- Add boolean to turn off port forwarding in sshd.- Add support for ebtables - Fixes for rhcs and corosync policy-Update to upstream-Update to upstream-Update to upstream- Add Zarafa policy- Cleanup of aiccu policy - initial mock policy- Lots of random fixes- Update to upstream- Update to upstream - Allow prelink script to signal itself - Cobbler fixes- Add xdm_var_run_t to xserver_stream_connect_xdm - Add cmorrord and mpd policy from Miroslav Grepl- Fix sshd creation of krb cc files for users to be user_tmp_t- Fixes for accountsdialog - Fixes for boinc- Fix label on /var/lib/dokwiki - Change permissive domains to enforcing - Fix libvirt policy to allow it to run on mls- Update to upstream- Allow procmail to execute scripts in the users home dir that are labeled home_bin_t - Fix /var/run/abrtd.lock label- Allow login programs to read krb5_home_t Resolves: 594833 - Add obsoletes for cachefilesfd-selinux package Resolves: #575084- Allow mount to r/w abrt fifo file - Allow svirt_t to getattr on hugetlbfs - Allow abrt to create a directory under /var/spool- Add labels for /sys - Allow sshd to getattr on shutdown - Fixes for munin - Allow sssd to use the kernel key ring - Allow tor to send syslog messages - Allow iptabels to read usr files - allow policykit to read all domains state- Fix path for /var/spool/abrt - Allow nfs_t as an entrypoint for http_sys_script_t - Add policy for piranha - Lots of fixes for sosreport- Allow xm_t to read network state and get and set capabilities - Allow policykit to getattr all processes - Allow denyhosts to connect to tcp port 9911 - Allow pyranha to use raw ip sockets and ptrace itself - Allow unconfined_execmem_t and gconfsd mechanism to dbus - Allow staff to kill ping process - Add additional MLS rules- Allow gdm to edit ~/.gconf dir Resolves: #590677 - Allow dovecot to create directories in /var/lib/dovecot Partially resolves 590224 - Allow avahi to dbus chat with NetworkManager - Fix cobbler labels - Dontaudit iceauth_t leaks - fix /var/lib/lxdm file context - Allow aiccu to use tun tap devices - Dontaudit shutdown using xserver.log- Fixes for sandbox_x_net_t to match access for sandbox_web_t ++ - Add xdm_etc_t for /etc/gdm directory, allow accountsd to manage this directory - Add dontaudit interface for bluetooth dbus - Add chronyd_read_keys, append_keys for initrc_t - Add log support for ksmtuned Resolves: #586663- Allow boinc to send mail- Allow initrc_t to remove dhcpc_state_t - Fix label on sa-update.cron - Allow dhcpc to restart chrony initrc - Don't allow sandbox to send signals to its parent processes - Fix transition from unconfined_t -> unconfined_mount_t -> rpcd_t Resolves: #589136- Fix location of oddjob_mkhomedir Resolves: #587385 - fix labeling on /root/.shosts and ~/.shosts - Allow ipsec_mgmt_t to manage net_conf_t Resolves: #586760- Dontaudit sandbox trying to connect to netlink sockets Resolves: #587609 - Add policy for piranha- Fixups for xguest policy - Fixes for running sandbox firefox- Allow ksmtuned to use terminals Resolves: #586663 - Allow lircd to write to generic usb devices- Allow sandbox_xserver to connectto unconfined stream Resolves: #585171- Allow initrc_t to read slapd_db_t Resolves: #585476 - Allow ipsec_mgmt to use unallocated devpts and to create /etc/resolv.conf Resolves: #585963- Allow rlogind_t to search /root for .rhosts Resolves: #582760 - Fix path for cached_var_t - Fix prelink paths /var/lib/prelink - Allow confined users to direct_dri - Allow mls lvm/cryptosetup to work- Allow virtd_t to manage firewall/iptables config Resolves: #573585- Fix label on /root/.rhosts Resolves: #582760 - Add labels for Picasa - Allow openvpn to read home certs - Allow plymouthd_t to use tty_device_t - Run ncftool as iptables_t - Allow mount to unmount unlabeled_t - Dontaudit hal leaks- Allow livecd to transition to mount- Update to upstream - Allow abrt to delete sosreport Resolves: #579998 - Allow snmp to setuid and gid Resolves: #582155 - Allow smartd to use generic scsi devices Resolves: #582145- Allow ipsec_t to create /etc/resolv.conf with the correct label - Fix reserved port destination - Allow autofs to transition to showmount - Stop crashing tuned- Add telepathysofiasip policy- Update to upstream - Fix label for /opt/google/chrome/chrome-sandbox - Allow modemmanager to dbus with policykit- Fix allow_httpd_mod_auth_pam to use auth_use_pam(httpd_t) - Allow accountsd to read shadow file - Allow apache to send audit messages when using pam - Allow asterisk to bind and connect to sip tcp ports - Fixes for dovecot 2.0 - Allow initrc_t to setattr on milter directories - Add procmail_home_t for .procmailrc file- Fixes for labels during install from livecd- Fix /cgroup file context - Fix broken afs use of unlabled_t - Allow getty to use the console for s390- Fix cgroup handling adding policy for /cgroup - Allow confined users to write to generic usb devices, if user_rw_noexattrfile boolean set- Merge patches from dgrift- Update upstream - Allow abrt to write to the /proc under any process- Fix ~/.fontconfig label - Add /root/.cert label - Allow reading of the fixed_file_disk_t:lnk_file if you can read file - Allow qemu_exec_t as an entrypoint to svirt_t- Update to upstream - Allow tmpreaper to delete sandbox sock files - Allow chrome-sandbox_t to use /dev/zero, and dontaudit getattr file systems - Fixes for gitosis - No transition on livecd to passwd or chfn - Fixes for denyhosts- Add label for /var/lib/upower - Allow logrotate to run sssd - dontaudit readahead on tmpfs blk files - Allow tmpreaper to setattr on sandbox files - Allow confined users to execute dos files - Allow sysadm_t to kill processes running within its clearance - Add accountsd policy - Fixes for corosync policy - Fixes from crontab policy - Allow svirt to manage svirt_image_t chr files - Fixes for qdisk policy - Fixes for sssd policy - Fixes for newrole policy- make libvirt work on an MLS platform- Add qpidd policy- Update to upstream- Allow boinc to read kernel sysctl - Fix snmp port definitions - Allow apache to read anon_inodefs- Allow shutdown dac_override- Add device_t as a file system - Fix sysfs association- Dontaudit ipsec_mgmt sys_ptrace - Allow at to mail its spool files - Allow nsplugin to search in .pulse directory- Update to upstream- Allow users to dbus chat with xdm - Allow users to r/w wireless_device_t - Dontaudit reading of process states by ipsec_mgmt- Fix openoffice from unconfined_t- Add shutdown policy so consolekit can shutdown system- Update to upstream- Update to upstream- Update to upstream - These are merges of my patches - Remove 389 labeling conflicts - Add MLS fixes found in RHEL6 testing - Allow pulseaudio to run as a service - Add label for mssql and allow apache to connect to this database port if boolean set - Dontaudit searches of debugfs mount point - Allow policykit_auth to send signals to itself - Allow modcluster to call getpwnam - Allow swat to signal winbind - Allow usbmux to run as a system role - Allow svirt to create and use devpts- Add MLS fixes found in RHEL6 testing - Allow domains to append to rpm_tmp_t - Add cachefilesfd policy - Dontaudit leaks when transitioning- Change allow_execstack and allow_execmem booleans to on - dontaudit acct using console - Add label for fping - Allow tmpreaper to delete sandbox_file_t - Fix wine dontaudit mmap_zero - Allow abrt to read var_t symlinks- Additional policy for rgmanager- Allow sshd to setattr on pseudo terms- Update to upstream- Allow policykit to send itself signals- Fix duplicate cobbler definition- Fix file context of /var/lib/avahi-autoipd- Merge with upstream- Allow sandbox to work with MLS- Make Chrome work with staff user- Add icecast policy - Cleanup spec file- Add mcelog policy- Lots of fixes found in F12- Fix rpm_dontaudit_leaks- Add getsched to hald_t - Add file context for Fedora/Redhat Directory Server- Allow abrt_helper to getattr on all filesystems - Add label for /opt/real/RealPlayer/plugins/oggfformat\.so- Add gstreamer_home_t for ~/.gstreamer- Update to upstream- Fix git- Turn on puppet policy - Update to dgrift git policy- Move users file to selection by spec file. - Allow vncserver to run as unconfined_u:unconfined_r:unconfined_t- Update to upstream- Remove most of the permissive domains from F12.- Add cobbler policy from dgrift- add usbmon device - Add allow rulse for devicekit_disk- Lots of fixes found in F12, fixes from Tom London- Cleanups from dgrift- Add back xserver_manage_home_fonts- Dontaudit sandbox trying to read nscd and sssd- Update to upstream- Rename udisks-daemon back to devicekit_disk_t policy- Fixes for abrt calls- Add tgtd policy- Update to upstream release- Add asterisk policy back in - Update to upstream release 2.20091117- Update to upstream release 2.20091117- Fixup nut policy- Update to upstream- Allow vpnc request the kernel to load modules- Fix minimum policy installs - Allow udev and rpcbind to request the kernel to load modules- Add plymouth policy - Allow local_login to sys_admin- Allow cupsd_config to read user tmp - Allow snmpd_t to signal itself - Allow sysstat_t to makedir in sysstat_log_t- Update rhcs policy- Allow users to exec restorecond- Allow sendmail to request kernel modules load- Fix all kernel_request_load_module domains- Fix all kernel_request_load_module domains- Remove allow_exec* booleans for confined users. Only available for unconfined_t- More fixes for sandbox_web_t- Allow sshd to create .ssh directory and content- Fix request_module line to module_request- Fix sandbox policy to allow it to run under firefox. - Dont audit leaks.- Fixes for sandbox- Update to upstream - Dontaudit nsplugin search /root - Dontaudit nsplugin sys_nice- Fix label on /usr/bin/notepad, /usr/sbin/vboxadd-service - Remove policycoreutils-python requirement except for minimum- Fix devicekit_disk_t to getattr on all domains sockets and fifo_files - Conflicts seedit (You can not use selinux-policy-targeted and seedit at the same time.)- Add wordpress/wp-content/uploads label - Fixes for sandbox when run from staff_t- Update to upstream - Fixes for devicekit_disk- More fixes- Lots of fixes for initrc and other unconfined domains- Allow xserver to use netlink_kobject_uevent_socket- Fixes for sandbox- Dontaudit setroubleshootfix looking at /root directory- Update to upsteam- Allow gssd to send signals to users - Fix duplicate label for apache content- Update to upstream- Remove polkit_auth on upgrades- Add back in unconfined.pp and unconfineduser.pp - Add Sandbox unshare- Fixes for cdrecord, mdadm, and others- Add capability setting to dhcpc and gpm- Allow cronjobs to read exim_spool_t- Add ABRT policy- Fix system-config-services policy- Allow libvirt to change user componant of virt_domain- Allow cupsd_config_t to be started by dbus - Add smoltclient policy- Add policycoreutils-python to pre install- Make all unconfined_domains permissive so we can see what AVC's happen- Add pt_chown policy- Add kdump policy for Miroslav Grepl - Turn off execstack boolean- Turn on execstack on a temporary basis (#512845)- Allow nsplugin to connecto the session bus - Allow samba_net to write to coolkey data- Allow devicekit_disk to list inotify- Allow svirt images to create sock_file in svirt_var_run_t- Allow exim to getattr on mountpoints - Fixes for pulseaudio- Allow svirt_t to stream_connect to virtd_t- Allod hald_dccm_t to create sock_files in /tmp- More fixes from upstream- Fix polkit label - Remove hidebrokensymptoms for nss_ldap fix - Add modemmanager policy - Lots of merges from upstream - Begin removing textrel_shlib_t labels, from fixed libraries- Update to upstream- Allow certmaster to override dac permissions- Update to upstream- Fix context for VirtualBox- Update to upstream- Allow clamscan read amavis spool files- Fixes for xguest- fix multiple directory ownership of mandirs- Update to upstream- Add rules for rtkit-daemon- Update to upstream - Fix nlscd_stream_connect- Add rtkit policy- Allow rpcd_t to stream connect to rpcbind- Allow kpropd to create tmp files- Fix last duplicate /var/log/rpmpkgs- Update to upstream * add sssd- Update to upstream * cleanup- Update to upstream - Additional mail ports - Add virt_use_usb boolean for svirt- Fix mcs rules to include chr_file and blk_file- Add label for udev-acl- Additional rules for consolekit/udev, privoxy and various other fixes- New version for upstream- Allow NetworkManager to read inotifyfs- Allow setroubleshoot to run mlocate- Update to upstream- Add fish as a shell - Allow fprintd to list usbfs_t - Allow consolekit to search mountpoints - Add proper labeling for shorewall- New log file for vmware - Allow xdm to setattr on user_tmp_t- Upgrade to upstream- Allow fprintd to access sys_ptrace - Add sandbox policy- Add varnishd policy- Fixes for kpropd- Allow brctl to r/w tun_tap_device_t- Add /usr/share/selinux/packages- Allow rpcd_t to send signals to kernel threads- Fix upgrade for F10 to F11- Add policy for /var/lib/fprint-Remove duplicate line- Allow svirt to manage pci and other sysfs device data- Fix package selection handling- Fix /sbin/ip6tables-save context - Allod udev to transition to mount - Fix loading of mls policy file- Add shorewall policy- Additional rules for fprintd and sssd- Allow nsplugin to unix_read unix_write sem for unconfined_java- Fix uml files to be owned by users- Fix Upgrade path to install unconfineduser.pp when unocnfined package is 3.0.0 or less- Allow confined users to manage virt_content_t, since this is home dir content - Allow all domains to read rpm_script_tmp_t which is what shell creates on redirection- Fix labeling on /var/lib/misc/prelink* - Allow xserver to rw_shm_perms with all x_clients - Allow prelink to execute files in the users home directory- Allow initrc_t to delete dev_null - Allow readahead to configure auditing - Fix milter policy - Add /var/lib/readahead- Update to latest milter code from Paul Howarth- Additional perms for readahead- Allow pulseaudio to acquire_svc on session bus - Fix readahead labeling- Allow sysadm_t to run rpm directly - libvirt needs fowner- Allow sshd to read var_lib symlinks for freenx- Allow nsplugin unix_read and write on users shm and sem - Allow sysadm_t to execute su- Dontaudit attempts to getattr user_tmpfs_t by lvm - Allow nfs to share removable media- Add ability to run postdrop from confined users- Fixes for podsleuth- Turn off nsplugin transition - Remove Konsole leaked file descriptors for release- Allow cupsd_t to create link files in print_spool_t - Fix iscsi_stream_connect typo - Fix labeling on /etc/acpi/actions - Don't reinstall unconfine and unconfineuser on upgrade if they are not installed- Allow audioentroy to read etc files- Add fail2ban_var_lib_t - Fixes for devicekit_power_t- Separate out the ucnonfined user from the unconfined.pp package- Make sure unconfined_java_t and unconfined_mono_t create user_tmpfs_t.- Upgrade to latest upstream - Allow devicekit_disk sys_rawio- Dontaudit binds to ports < 1024 for named - Upgrade to latest upstream- Allow podsleuth to use tmpfs files- Add customizable_types for svirt- Allow setroubelshoot exec* privs to prevent crash from bad libraries - add cpufreqselector- Dontaudit listing of /root directory for cron system jobs- Fix missing ld.so.cache label- Add label for ~/.forward and /root/.forward- Fixes for svirt- Fixes to allow svirt read iso files in homedir- Add xenner and wine fixes from mgrepl- Allow mdadm to read/write mls override- Change to svirt to only access svirt_image_t- Fix libvirt policy- Upgrade to latest upstream- Fixes for iscsid and sssd - More cleanups for upgrade from F10 to Rawhide.- Add pulseaudio, sssd policy - Allow networkmanager to exec udevadm- Add pulseaudio context- Upgrade to latest patches- Fixes for libvirt- Update to Latest upstream- Fix setrans.conf to show SystemLow for s0- Further confinement of qemu images via svirt- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- Allow NetworkManager to manage /etc/NetworkManager/system-connections- add virtual_image_context and virtual_domain_context files- Allow rpcd_t to send signal to mount_t - Allow libvirtd to run ranged- Fix sysnet/net_conf_t- Fix squidGuard labeling- Re-add corenet_in_generic_if(unlabeled_t)* Tue Feb 10 2009 Dan Walsh 3.6.5-2 - Add git web policy- Add setrans contains from upstream- Do transitions outside of the booleans- Allow xdm to create user_tmp_t sockets for switch user to work- Fix staff_t domain- Grab remainder of network_peer_controls patch- More fixes for devicekit- Upgrade to latest upstream- Add boolean to disallow unconfined_t login- Add back transition from xguest to mozilla- Add virt_content_ro_t and labeling for isos directory- Fixes for wicd daemon- More mls/rpm fixes- Add policy to make dbus/nm-applet work- Remove polgen-ifgen from post and add trigger to policycoreutils-python- Add wm policy - Make mls work in graphics mode- Fixed for DeviceKit- Add devicekit policy- Update to upstream- Define openoffice as an x_domain- Fixes for reading xserver_tmp_t- Allow cups_pdf_t write to nfs_t- Remove audio_entropy policy- Update to upstream- Allow hal_acl_t to getattr/setattr fixed_disk- Change userdom_read_all_users_state to include reading symbolic links in /proc- Fix dbus reading /proc information- Add missing alias for home directory content- Fixes for IBM java location- Allow unconfined_r unconfined_java_t- Add cron_role back to user domains- Fix sudo setting of user keys- Allow iptables to talk to terminals - Fixes for policy kit - lots of fixes for booting.- Cleanup policy- Rebuild for Python 2.6- Fix labeling on /var/spool/rsyslog- Allow postgresl to bind to udp nodes- Allow lvm to dbus chat with hal - Allow rlogind to read nfs_t- Fix cyphesis file context- Allow hal/pm-utils to look at /var/run/video.rom - Add ulogd policy- Additional fixes for cyphesis - Fix certmaster file context - Add policy for system-config-samba - Allow hal to read /var/run/video.rom- Allow dhcpc to restart ypbind - Fixup labeling in /var/run- Add certmaster policy- Fix confined users - Allow xguest to read/write xguest_dbusd_t- Allow openoffice execstack/execmem privs- Allow mozilla to run with unconfined_execmem_t- Dontaudit domains trying to write to .xsession-errors- Allow nsplugin to look at autofs_t directory- Allow kerneloops to create tmp files- More alias for fastcgi- Remove mod_fcgid-selinux package- Fix dovecot access- Policy cleanup- Remove Multiple spec - Add include - Fix makefile to not call per_role_expansion- Fix labeling of libGL- Update to upstream- Update to upstream policy- Fixes for confined xwindows and xdm_t- Allow confined users and xdm to exec wm - Allow nsplugin to talk to fifo files on nfs- Allow NetworkManager to transition to avahi and iptables - Allow domains to search other domains keys, coverup kernel bug- Fix labeling for oracle- Allow nsplugin to comminicate with xdm_tmp_t sock_file- Change all user tmpfs_t files to be labeled user_tmpfs_t - Allow radiusd to create sock_files- Upgrade to upstream- Allow confined users to login with dbus- Fix transition to nsplugin- Add file context for /dev/mspblk.*- Fix transition to nsplugin '- Fix labeling on new pm*log - Allow ssh to bind to all nodes- Merge upstream changes - Add Xavier Toth patches- Add qemu_cache_t for /var/cache/libvirt- Remove gamin policy- Add tinyxs-max file system support- Update to upstream - New handling of init scripts- Allow pcsd to dbus - Add memcache policy- Allow audit dispatcher to kill his children- Update to upstream - Fix crontab use by unconfined user- Allow ifconfig_t to read dhcpc_state_t- Update to upstream- Update to upstream- Allow system-config-selinux to work with policykit- Fix novel labeling- Consolodate pyzor,spamassassin, razor into one security domain - Fix xdm requiring additional perms.- Fixes for logrotate, alsa- Eliminate vbetool duplicate entry- Fix xguest -> xguest_mozilla_t -> xguest_openiffice_t - Change dhclient to be able to red networkmanager_var_run- Update to latest refpolicy - Fix libsemanage initial install bug- Add inotify support to nscd- Allow unconfined_t to setfcap- Allow amanda to read tape - Allow prewikka cgi to use syslog, allow audisp_t to signal cgi - Add support for netware file systems- Allow ypbind apps to net_bind_service- Allow all system domains and application domains to append to any log file- Allow gdm to read rpm database - Allow nsplugin to read mplayer config files- Allow vpnc to run ifconfig- Allow confined users to use postgres - Allow system_mail_t to exec other mail clients - Label mogrel_rails as an apache server- Apply unconfined_execmem_exec_t to haskell programs- Fix prelude file context- allow hplip to talk dbus - Fix context on ~/.local dir- Prevent applications from reading x_device- Add /var/lib/selinux context- Update to upstream- Add livecd policy- Dontaudit search of admin_home for init_system_domain - Rewrite of xace interfaces - Lots of new fs_list_inotify - Allow livecd to transition to setfiles_mac- Begin XAce integration- Merge Upstream- Allow amanada to create data files- Fix initial install, semanage setup- Allow system_r for httpd_unconfined_script_t- Remove dmesg boolean - Allow user domains to read/write game data- Change unconfined_t to transition to unconfined_mono_t when running mono - Change XXX_mono_t to transition to XXX_t when executing bin_t files, so gnome-do will work- Remove old booleans from targeted-booleans.conf file- Add boolean to mmap_zero - allow tor setgid - Allow gnomeclock to set clock- Don't run crontab from unconfined_t- Change etc files to config files to allow users to read them- Lots of fixes for confined domains on NFS_t homedir- dontaudit mrtg reading /proc - Allow iscsi to signal itself - Allow gnomeclock sys_ptrace- Allow dhcpd to read kernel network state- Label /var/run/gdm correctly - Fix unconfined_u user creation- Allow transition from initrc_t to getty_t- Allow passwd to communicate with user sockets to change gnome-keyring- Fix initial install- Allow radvd to use fifo_file - dontaudit setfiles reading links - allow semanage sys_resource - add allow_httpd_mod_auth_ntlm_winbind boolean - Allow privhome apps including dovecot read on nfs and cifs home dirs if the boolean is set- Allow nsplugin to read /etc/mozpluggerrc, user_fonts - Allow syslog to manage innd logs. - Allow procmail to ioctl spamd_exec_t- Allow initrc_t to dbus chat with consolekit.- Additional access for nsplugin - Allow xdm setcap/getcap until pulseaudio is fixed- Allow mount to mkdir on tmpfs - Allow ifconfig to search debugfs- Fix file context for MATLAB - Fixes for xace- Allow stunnel to transition to inetd children domains - Make unconfined_dbusd_t an unconfined domain- Fixes for qemu/virtd- Fix bug in mozilla policy to allow xguest transition - This will fix the libsemanage.dbase_llist_query: could not find record value libsemanage.dbase_llist_query: could not query record value (No such file or directory) bug in xguest- Allow nsplugin to run acroread- Add cups_pdf policy - Add openoffice policy to run in xguest- prewika needs to contact mysql - Allow syslog to read system_map files- Change init_t to an unconfined_domain- Allow init to transition to initrc_t on shell exec. - Fix init to be able to sendto init_t. - Allow syslog to connect to mysql - Allow lvm to manage its own fifo_files - Allow bugzilla to use ldap - More mls fixes- fixes for init policy (#436988) - fix build- Additional changes for MLS policy- Fix initrc_context generation for MLS- Fixes for libvirt- Allow bitlebee to read locale_t- More xselinux rules- Change httpd_$1_script_r*_t to httpd_$1_content_r*_t- Prepare policy for beta release - Change some of the system domains back to unconfined - Turn on some of the booleans- Allow nsplugin_config execstack/execmem - Allow nsplugin_t to read alsa config - Change apache to use user content- Add cyphesis policy- Fix Makefile.devel to build mls modules - Fix qemu to be more specific on labeling- Update to upstream fixes- Allow staff to mounton user_home_t- Add xace support- Add fusectl file system- Fixes from yum-cron - Update to latest upstream- Fix userdom_list_user_files- Merge with upstream- Allow udev to send audit messages- Add additional login users interfaces - userdom_admin_login_user_template(staff)- More fixes for polkit- Eliminate transition from unconfined_t to qemu by default - Fixes for gpg- Update to upstream- Fixes for staff_t- Add policy for kerneloops - Add policy for gnomeclock- Fixes for libvirt- Fixes for nsplugin- More fixes for qemu- Additional ports for vnc and allow qemu and libvirt to search all directories- Update to upstream - Add libvirt policy - add qemu policy- Allow fail2ban to create a socket in /var/run- Allow allow_httpd_mod_auth_pam to work- Add audisp policy and prelude- Allow all user roles to executae samba net command- Allow usertypes to read/write noxattr file systems- Fix nsplugin to allow flashplugin to work in enforcing mode- Allow pam_selinux_permit to kill all processes- Allow ptrace or user processes by users of same type - Add boolean for transition to nsplugin- Allow nsplugin sys_nice, getsched, setsched- Allow login programs to talk dbus to oddjob- Add procmail_log support - Lots of fixes for munin- Allow setroubleshoot to read policy config and send audit messages- Allow users to execute all files in homedir, if boolean set - Allow mount to read samba config- Fixes for xguest to run java plugin- dontaudit pam_t and dbusd writing to user_home_t- Update gpg to allow reading of inotify- Change user and staff roles to work correctly with varied perms- Fix munin log, - Eliminate duplicate mozilla file context - fix wpa_supplicant spec- Fix role transition from unconfined_r to system_r when running rpm - Allow unconfined_domains to communicate with user dbus instances- Fixes for xguest- Let all uncofined domains communicate with dbus unconfined- Run rpm in system_r- Zero out customizable types- Fix definiton of admin_home_t- Fix munin file context- Allow cron to run unconfined apps- Modify default login to unconfined_u- Dontaudit dbus user client search of /root- Update to upstream- Fixes for polkit - Allow xserver to ptrace- Add polkit policy - Symplify userdom context, remove automatic per_role changes- Update to upstream - Allow httpd_sys_script_t to search users homedirs- Allow rpm_script to transition to unconfined_execmem_t- Remove user based home directory separation- Remove user specific crond_t- Merge with upstream - Allow xsever to read hwdata_t - Allow login programs to setkeycreate- Update to upstream- Update to upstream- Allow XServer to read /proc/self/cmdline - Fix unconfined cron jobs - Allow fetchmail to transition to procmail - Fixes for hald_mac - Allow system_mail to transition to exim - Allow tftpd to upload files - Allow xdm to manage unconfined_tmp - Allow udef to read alsa config - Fix xguest to be able to connect to sound port- Fixes for hald_mac - Treat unconfined_home_dir_t as a home dir - dontaudit rhgb writes to fonts and root- Fix dnsmasq - Allow rshd full login privs- Allow rshd to connect to ports > 1023- Fix vpn to bind to port 4500 - Allow ssh to create shm - Add Kismet policy- Allow rpm to chat with networkmanager- Fixes for ipsec and exim mail - Change default to unconfined user- Pass the UNK_PERMS param to makefile - Fix gdm location- Make alsa work- Fixes for consolekit and startx sessions- Dontaudit consoletype talking to unconfined_t- Remove homedir_template- Check asound.state- Fix exim policy- Allow tmpreadper to read man_t - Allow racoon to bind to all nodes - Fixes for finger print reader- Allow xdm to talk to input device (fingerprint reader) - Allow octave to run as java- Allow login programs to set ioctl on /proc- Allow nsswitch apps to read samba_var_t- Fix maxima- Eliminate rpm_t:fifo_file avcs - Fix dbus path for helper app- Fix service start stop terminal avc's- Allow also to search var_lib - New context for dbus launcher- Allow cupsd_config_t to read/write usb_device_t - Support for finger print reader, - Many fixes for clvmd - dbus starting networkmanager- Fix java and mono to run in xguest account- Fix to add xguest account when inititial install - Allow mono, java, wine to run in userdomains- Allow xserver to search devpts_t - Dontaudit ldconfig output to homedir- Remove hplip_etc_t change back to etc_t.- Allow cron to search nfs and samba homedirs- Allow NetworkManager to dbus chat with yum-updated- Allow xfs to bind to port 7100- Allow newalias/sendmail dac_override - Allow bind to bind to all udp ports- Turn off direct transition- Allow wine to run in system role- Fix java labeling- Define user_home_type as home_type- Allow sendmail to create etc_aliases_t- Allow login programs to read symlinks on homedirs- Update an readd modules- Cleanup spec file- Allow xserver to be started by unconfined process and talk to tty- Upgrade to upstream to grab postgressql changes- Add setransd for mls policy- Add ldconfig_cache_t- Allow sshd to write to proc_t for afs login- Allow xserver access to urand- allow dovecot to search mountpoints- Fix Makefile for building policy modules- Fix dhcpc startup of service- Fix dbus chat to not happen for xguest and guest users- Fix nagios cgi - allow squid to communicate with winbind- Fixes for ldconfig- Update from upstream- Add nasd support- Fix new usb devices and dmfm- Eliminate mount_ntfs_t policy, merge into mount_t- Allow xserver to write to ramfs mounted by rhgb- Add context for dbus machine id- Update with latest changes from upstream- Fix prelink to handle execmod- Add ntpd_key_t to handle secret data- Add anon_inodefs - Allow unpriv user exec pam_exec_t - Fix trigger- Allow cups to use generic usb - fix inetd to be able to run random apps (git)- Add proper contexts for rsyslogd- Fixes for xguest policy- Allow execution of gconf- Fix moilscanner update problem- Begin adding policy to separate setsebool from semanage - Fix xserver.if definition to not break sepolgen.if- Add new devices- Add brctl policy- Fix root login to include system_r- Allow prelink to read kernel sysctls- Default to user_u:system_r:unconfined_t- fix squid - Fix rpm running as uid- Fix syslog declaration- Allow avahi to access inotify - Remove a lot of bogus security_t:filesystem avcs- Remove ifdef strict policy from upstream- Remove ifdef strict to allow user_u to login- Fix for amands - Allow semanage to read pp files - Allow rhgb to read xdm_xserver_tmp- Allow kerberos servers to use ldap for backing store- allow alsactl to read kernel state- More fixes for alsactl - Transition from hal and modutils - Fixes for suspend resume. - insmod domtrans to alsactl - insmod writes to hal log- Allow unconfined_t to transition to NetworkManager_t - Fix netlabel policy- Update to latest from upstream- Update to latest from upstream- Update to latest from upstream- Allow pcscd_t to send itself signals- Fixes for unix_update - Fix logwatch to be able to search all dirs- Upstream bumped the version- Allow consolekit to syslog - Allow ntfs to work with hal- Allow iptables to read etc_runtime_t- MLS Fixes- Fix path of /etc/lvm/cache directory - Fixes for alsactl and pppd_t - Fixes for consolekit- Allow insmod_t to mount kvmfs_t filesystems- Rwho policy - Fixes for consolekit- fixes for fusefs- Fix samba_net to allow it to view samba_var_t- Update to upstream- Fix Sonypic backlight - Allow snmp to look at squid_conf_t- Fixes for pyzor, cyrus, consoletype on everything installs- Fix hald_acl_t to be able to getattr/setattr on usb devices - Dontaudit write to unconfined_pipes for load_policy- Allow bluetooth to read inotifyfs- Fixes for samba domain controller. - Allow ConsoleKit to look at ttys- Fix interface call- Allow syslog-ng to read /var - Allow locate to getattr on all filesystems - nscd needs setcap- Update to upstream- Allow samba to run groupadd- Update to upstream- Allow mdadm to access generic scsi devices- Fix labeling on udev.tbl dirs- Fixes for logwatch- Add fusermount and mount_ntfs policy- Update to upstream - Allow saslauthd to use kerberos keytabs- Fixes for samba_var_t- Allow networkmanager to setpgid - Fixes for hal_acl_t- Remove disable_trans booleans - hald_acl_t needs to talk to nscd- Fix prelink to be able to manage usr dirs.- Allow insmod to launch init scripts- Remove setsebool policy- Fix handling of unlabled_t packets- More of my patches from upstream- Update to latest from upstream - Add fail2ban policy- Update to remove security_t:filesystem getattr problems- Policy for consolekit- Update to latest from upstream- Revert Nemiver change - Set sudo as a corecmd so prelink will work, remove sudoedit mapping, since this will not work, it does not transition. - Allow samba to execute useradd- Upgrade to the latest from upstream- Add sepolgen support - Add bugzilla policy- Fix file context for nemiver- Remove include sym link- Allow mozilla, evolution and thunderbird to read dev_random. Resolves: #227002 - Allow spamd to connect to smtp port Resolves: #227184 - Fixes to make ypxfr work Resolves: #227237- Fix ssh_agent to be marked as an executable - Allow Hal to rw sound device- Fix spamassisin so crond can update spam files - Fixes to allow kpasswd to work - Fixes for bluetooth- Remove some targeted diffs in file context file- Fix squid cachemgr labeling- Add ability to generate webadm_t policy - Lots of new interfaces for httpd - Allow sshd to login as unconfined_t- Continue fixing, additional user domains- Begin adding user confinement to targeted policy- Fixes for prelink, ktalkd, netlabel- Allow prelink when run from rpm to create tmp files Resolves: #221865 - Remove file_context for exportfs Resolves: #221181 - Allow spamassassin to create ~/.spamassissin Resolves: #203290 - Allow ssh access to the krb tickets - Allow sshd to change passwd - Stop newrole -l from working on non securetty Resolves: #200110 - Fixes to run prelink in MLS machine Resolves: #221233 - Allow spamassassin to read var_lib_t dir Resolves: #219234- fix mplayer to work under strict policy - Allow iptables to use nscd Resolves: #220794- Add gconf policy and make it work with strict- Many fixes for strict policy and by extension mls.- Fix to allow ftp to bind to ports > 1024 Resolves: #219349- Allow semanage to exec it self. Label genhomedircon as semanage_exec_t Resolves: #219421 - Allow sysadm_lpr_t to manage other print spool jobs Resolves: #220080- allow automount to setgid Resolves: #219999- Allow cron to polyinstatiate - Fix creation of boot flags Resolves: #207433- Fixes for irqbalance Resolves: #219606- Fix vixie-cron to work on mls Resolves: #207433Resolves: #218978- Allow initrc to create files in /var directories Resolves: #219227- More fixes for MLS Resolves: #181566- More Fixes polyinstatiation Resolves: #216184- More Fixes polyinstatiation - Fix handling of keyrings Resolves: #216184- Fix polyinstatiation - Fix pcscd handling of terminal Resolves: #218149 Resolves: #218350- More fixes for quota Resolves: #212957- ncsd needs to use avahi sockets Resolves: #217640 Resolves: #218014- Allow login programs to polyinstatiate homedirs Resolves: #216184 - Allow quotacheck to create database files Resolves: #212957- Dontaudit appending hal_var_lib files Resolves: #217452 Resolves: #217571 Resolves: #217611 Resolves: #217640 Resolves: #217725- Fix context for helix players file_context #216942- Fix load_policy to be able to mls_write_down so it can talk to the terminal- Fixes for hwclock, clamav, ftp- Move to upstream version which accepted my patches- Fixes for nvidia driver- Allow semanage to signal mcstrans- Update to upstream- Allow modstorage to edit /etc/fstab file- Fix for qemu, /dev/- Fix path to realplayer.bin- Allow xen to connect to xen port- Allow cups to search samba_etc_t directory - Allow xend_t to list auto_mountpoints- Allow xen to search automount- Fix spec of jre files- Fix unconfined access to shadow file- Allow xend to create files in xen_image_t directories- Fixes for /var/lib/hal- Remove ability for sysadm_t to look at audit.log- Fix rpc_port_types - Add aide policy for mls- Merge with upstream- Lots of fixes for ricci- Allow xen to read/write fixed devices with a boolean - Allow apache to search /var/log- Fix policygentool specfile problem. - Allow apache to send signals to it's logging helpers. - Resolves: rhbz#212731- Add perms for swat- Add perms for swat- Allow daemons to dump core files to /- Fixes for ricci- Allow mount.nfs to work- Allow ricci-modstorage to look at lvm_etc_t- Fixes for ricci using saslauthd- Allow mountpoint on home_dir_t and home_t- Update xen to read nfs files- Allow noxattrfs to associate with other noxattrfs- Allow hal to use power_device_t- Allow procemail to look at autofs_t - Allow xen_image_t to work as a fixed device- Refupdate from upstream- Add lots of fixes for mls cups- Lots of fixes for ricci- Fix number of cats- Update to upstream- More iSCSI changes for #209854- Test ISCSI fixes for #209854- allow semodule to rmdir selinux_config_t dir- Fix boot_runtime_t problem on ppc. Should not be creating these files.- Fix context mounts on reboot - Fix ccs creation of directory in /var/log- Update for tallylog- Allow xend to rewrite dhcp conf files - Allow mgetty sys_admin capability- Make xentapctrl work- Don't transition unconfined_t to bootloader_t - Fix label in /dev/xen/blktap- Patch for labeled networking- Fix crond handling for mls- Update to upstream- Remove bluetooth-helper transition - Add selinux_validate for semanage - Require new version of libsemanage- Fix prelink- Fix rhgb- Fix setrans handling on MLS and useradd- Support for fuse - fix vigr- Fix dovecot, amanda - Fix mls- Allow java execheap for itanium- Update with upstream- mls fixes- Update from upstream- More fixes for mls - Revert change on automount transition to mount- Fix cron jobs to run under the correct context- Fixes to make pppd work- Multiple policy fixes - Change max categories to 1023- Fix transition on mcstransd- Add /dev/em8300 defs- Upgrade to upstream- Fix ppp connections from network manager- Add tty access to all domains boolean - Fix gnome-pty-helper context for ia64- Fixed typealias of firstboot_rw_t- Fix location of xel log files - Fix handling of sysadm_r -> rpm_exec_t- Fixes for autofs, lp- Update from upstream- Fixup for test6- Update to upstream- Update to upstream- Fix suspend to disk problems- Lots of fixes for restarting daemons at the console.- Fix audit line - Fix requires line- Upgrade to upstream- Fix install problems- Allow setroubleshoot to getattr on all dirs to gather RPM data- Set /usr/lib/ia32el/ia32x_loader to unconfined_execmem_exec_t for ia32 platform - Fix spec for /dev/adsp- Fix xen tty devices- Fixes for setroubleshoot- Update to upstream- Fixes for stunnel and postgresql - Update from upstream- Update from upstream - More java fixes- Change allow_execstack to default to on, for RHEL5 Beta. This is required because of a Java compiler problem. Hope to turn off for next beta- Misc fixes- More fixes for strict policy- Quiet down anaconda audit messages- Fix setroubleshootd- Update to the latest from upstream- More fixes for xen- Fix anaconda transitions- yet more xen rules- more xen rules- Fixes for Samba- Fixes for xen- Allow setroubleshootd to send mail- Add nagios policy- fixes for setroubleshoot- Added Paul Howarth patch to only load policy packages shipped with this package - Allow pidof from initrc to ptrace higher level domains - Allow firstboot to communicate with hal via dbus- Add policy for /var/run/ldapi- Fix setroubleshoot policy- Fixes for mls use of ssh - named has a new conf file- Fixes to make setroubleshoot work- Cups needs to be able to read domain state off of printer client- add boolean to allow zebra to write config files- setroubleshootd fixes- Allow prelink to read bin_t symlink - allow xfs to read random devices - Change gfs to support xattr- Remove spamassassin_can_network boolean- Update to upstream - Fix lpr domain for mls- Add setroubleshoot policy- Turn off auditallow on setting booleans- Multiple fixes- Update to upstream- Update to upstream - Add new class for kernel key ring- Update to upstream- Update to upstream- Break out selinux-devel package- Add ibmasmfs- Fix policygentool gen_requires- Update from Upstream- Fix spec of realplay- Update to upstream- Fix semanage- Allow useradd to create_home_dir in MLS environment- Update from upstream- Update from upstream- Add oprofilefs- Fix for hplip and Picasus- Update to upstream- Update to upstream- fixes for spamd- fixes for java, openldap and webalizer- Xen fixes- Upgrade to upstream- allow hal to read boot_t files - Upgrade to upstream- allow hal to read boot_t files- Update from upstream- Fixes for amavis- Update from upstream- Allow auditctl to search all directories- Add acquire service for mono.- Turn off allow_execmem boolean - Allow ftp dac_override when allowed to access users homedirs- Clean up spec file - Transition from unconfined_t to prelink_t- Allow execution of cvs command- Update to upstream- Update to upstream- Fix libjvm spec- Update to upstream- Add xm policy - Fix policygentool- Update to upstream - Fix postun to only disable selinux on full removal of the packages- Allow mono to chat with unconfined- Allow procmail to sendmail - Allow nfs to share dosfs- Update to latest from upstream - Allow selinux-policy to be removed and kernel not to crash- Update to latest from upstream - Add James Antill patch for xen - Many fixes for pegasus- Add unconfined_mount_t - Allow privoxy to connect to httpd_cache - fix cups labeleing on /var/cache/cups- Update to latest from upstream- Update to latest from upstream - Allow mono and unconfined to talk to initrc_t dbus objects- Change libraries.fc to stop shlib_t form overriding texrel_shlib_t- Fix samba creating dirs in homedir - Fix NFS so its booleans would work- Allow secadm_t ability to relabel all files - Allow ftp to search xferlog_t directories - Allow mysql to communicate with ldap - Allow rsync to bind to rsync_port_t- Fixed mailman with Postfix #183928 - Allowed semanage to create file_context files. - Allowed amanda_t to access inetd_t TCP sockets and allowed amanda_recover_t to bind to reserved ports. #149030 - Don't allow devpts_t to be associated with tmp_t. - Allow hald_t to stat all mountpoints. - Added boolean samba_share_nfs to allow smbd_t full access to NFS mounts. - Make mount run in mount_t domain from unconfined_t to prevent mislabeling of /etc/mtab. - Changed the file_contexts to not have a regex before the first ^/[a-z]/ whenever possible, makes restorecon slightly faster. - Correct the label of /etc/named.caching-nameserver.conf - Now label /usr/src/kernels/.+/lib(/.*)? as usr_t instead of /usr/src(/.*)?/lib(/.*)? - I don't think we need anything else under /usr/src hit by this. - Granted xen access to /boot, allowed mounting on xend_var_lib_t, and allowed xenstored_t rw access to the xen device node.- More textrel_shlib_t file path fixes - Add ada support- Get auditctl working in MLS policy- Add mono dbus support - Lots of file_context fixes for textrel_shlib_t in FC5 - Turn off execmem auditallow since they are filling log files- Update to upstream- Allow automount and dbus to read cert files- Fix ftp policy - Fix secadm running of auditctl- Update to upstream- Update to upstream- Fix policyhelp- Fix pam_console handling of usb_device - dontaudit logwatch reading /mnt dir- Update to upstream- Get transition rules to create policy.20 at SystemHigh- Allow secadmin to shutdown system - Allow sendmail to exec newalias- MLS Fixes dmidecode needs mls_file_read_up - add ypxfr_t - run init needs access to nscd - udev needs setuid - another xen log file - Dontaudit mount getattr proc_kcore_t- fix buildroot usage (#185391)- Get rid of mount/fsdisk scan of /dev messages - Additional fixes for suspend/resume- Fake make to rebuild enableaudit.pp- Get xen networking running.- Fixes for Xen - enableaudit should not be the same as base.pp - Allow ps to work for all process- more xen policy fixups- more xen fixage (#184393)- Fix blkid specification - Allow postfix to execute mailman_que- Blkid changes - Allow udev access to usb_device_t - Fix post script to create targeted policy config file- Allow lvm tools to create drevice dir- Add Xen support- Fixes for cups - Make cryptosetup work with hal- Load Policy needs translock- Fix cups html interface- Add hal changes suggested by Jeremy - add policyhelp to point at policy html pages- Additional fixes for nvidia and cups- Update to upstream - Merged my latest fixes - Fix cups policy to handle unix domain sockets- NSCD socket is in nscd_var_run_t needs to be able to search dir- Fixes Apache interface file- Fixes for new version of cups- Turn off polyinstatiate util after FC5- Fix problem with privoxy talking to Tor- Turn on polyinstatiation- Don't transition from unconfined_t to fsadm_t- Fix policy update model.- Update to upstream- Fix load_policy to work on MLS - Fix cron_rw_system_pipes for postfix_postdrop_t - Allow audotmount to run showmount- Fix swapon - allow httpd_sys_script_t to be entered via a shell - Allow httpd_sys_script_t to read eventpolfs- Update from upstream- allow cron to read apache files- Fix vpnc policy to work from NetworkManager- Update to upstream - Fix semoudle polcy- Update to upstream - fix sysconfig/selinux link- Add router port for zebra - Add imaze port for spamd - Fixes for amanda and java- Fix bluetooth handling of usb devices - Fix spamd reading of ~/ - fix nvidia spec- Update to upsteam- Add users_extra files- Update to upstream- Add semodule policy- Update from upstream- Fix for spamd to use razor port- Fixes for mcs - Turn on mount and fsadm for unconfined_t- Fixes for the -devel package- Fix for spamd to use ldap- Update to upstream- Update to upstream - Fix rhgb, and other Xorg startups- Update to upstream- Separate out role of secadm for mls- Add inotifyfs handling- Update to upstream - Put back in changes for pup/zen- Many changes for MLS - Turn on strict policy- Update to upstream- Update to upstream - Fixes for booting and logging in on MLS machine- Update to upstream - Turn off execheap execstack for unconfined users - Add mono/wine policy to allow execheap and execstack for them - Add execheap for Xdm policy- Update to upstream - Fixes to fetchmail,- Update to upstream- Fix for procmail/spamassasin - Update to upstream - Add rules to allow rpcd to work with unlabeled_networks.- Update to upstream - Fix ftp Man page- Update to upstream- fix pup transitions (#177262) - fix xen disks (#177599)- Update to upstream- More Fixes for hal and readahead- Fixes for hal and readahead- Update to upstream - Apply- Add wine and fix hal problems- Handle new location of hal scripts- Allow su to read /etc/mtab- Update to upstream- Fix "libsemanage.parse_module_headers: Data did not represent a module." problem- Allow load_policy to read /etc/mtab- Fix dovecot to allow dovecot_auth to look at /tmp- Allow restorecon to read unlabeled_t directories in order to fix labeling.- Add Logwatch policy- Fix /dev/ub[a-z] file context- Fix library specification - Give kudzu execmem privs- Fix hostname in targeted policy- Fix passwd command on mls- Lots of fixes to make mls policy work- Add dri libs to textrel_shlib_t - Add system_r role for java - Add unconfined_exec_t for vncserver - Allow slapd to use kerberos- Add man pages- Add enableaudit.pp- Fix mls policy- Update mls file from old version- Add sids back in - Rebuild with update checkpolicy- Fixes to allow automount to use portmap - Fixes to start kernel in s0-s15:c0.c255- Add java unconfined/execmem policy- Add file context for /var/cvs - Dontaudit webalizer search of homedir- Update from upstream- Clean up spec - range_transition crond to SystemHigh- Fixes for hal - Update to upstream- Turn back on execmem since we need it for java, firefox, ooffice - Allow gpm to stream socket to itself- fix requirements to be on the actual packages so that policy can get created properly at install time- Allow unconfined_t to execmod texrel_shlib_t- Update to upstream - Turn off allow_execmem and allow_execmod booleans - Add tcpd and automount policies- Add two new httpd booleans, turned off by default * httpd_can_network_relay * httpd_can_network_connect_db- Add ghost for policy.20- Update to upstream - Turn off boolean allow_execstack- Change setrans-mls to use new libsetrans - Add default_context rule for xdm- Change Requires to PreReg for requiring of policycoreutils on install- New upstream releaseAdd xdm policyUpdate from upstreamUpdate from upstreamUpdate from upstream- Also trigger to rebuild policy for versions up to 2.0.7.- No longer installing policy.20 file, anaconda handles the building of the app.- Fixes for dovecot and saslauthd- Cleanup pegasus and named - Fix spec file - Fix up passwd changing applications-Update to latest from upstream- Add rules for pegasus and avahi- Start building MLS Policy- Update to upstream- Turn on bash- Initial version/bin/sh  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-..0123456789:;<=>?@ABCDEFGHIJKLMN3.13.1-229.el7_6.6    develMakefileexample.fcexample.ifexample.tehtmlNetworkManager.htmlabrt.htmlabrt_dump_oops.htmlabrt_handle_event.htmlabrt_helper.htmlabrt_retrace_coredump.htmlabrt_retrace_worker.htmlabrt_upload_watch.htmlabrt_watch_log.htmlaccountsd.htmlacct.htmladmin_crontab.htmlafs.htmlafs_bosserver.htmlafs_fsserver.htmlafs_kaserver.htmlafs_ptserver.htmlafs_vlserver.htmlaiccu.htmlaide.htmlajaxterm.htmlajaxterm_ssh.htmlalsa.htmlamanda.htmlamanda_recover.htmlamtu.htmlanaconda.htmlanon_sftpd.htmlantivirus.htmlapcupsd.htmlapcupsd_cgi_script.htmlapm.htmlapmd.htmlarpwatch.htmlasterisk.htmlaudisp.htmlaudisp_remote.htmlauditadm.htmlauditadm_screen.htmlauditadm_su.htmlauditadm_sudo.htmlauditctl.htmlauditd.htmlauthconfig.htmlautomount.htmlavahi.htmlawstats.htmlawstats_script.htmlbacula.htmlbacula_admin.htmlbacula_unconfined_script.htmlbcfg2.htmlbitlbee.htmlblkmapd.htmlblktap.htmlblueman.htmlbluetooth.htmlbluetooth_helper.htmlboinc.htmlboinc_project.htmlbootloader.htmlbrctl.htmlbrltty.htmlbugzilla_script.htmlbumblebee.htmlcachefiles_kernel.htmlcachefilesd.htmlcalamaris.htmlcallweaver.htmlcanna.htmlcardmgr.htmlccs.htmlcdcc.htmlcdrecord.htmlcertmaster.htmlcertmonger.htmlcertmonger_unconfined.htmlcertwatch.htmlcfengine_execd.htmlcfengine_monitord.htmlcfengine_serverd.htmlcgclear.htmlcgconfig.htmlcgdcbxd.htmlcgred.htmlcheckpc.htmlcheckpolicy.htmlchfn.htmlchkpwd.htmlchrome_sandbox.htmlchrome_sandbox_nacl.htmlchronyc.htmlchronyd.htmlchroot_user.htmlcinder_api.htmlcinder_backup.htmlcinder_scheduler.htmlcinder_volume.htmlciped.htmlclogd.htmlcloud_init.htmlcluster.htmlclvmd.htmlcmirrord.htmlcobblerd.htmlcockpit_session.htmlcockpit_ws.htmlcollectd.htmlcollectd_script.htmlcolord.htmlcomsat.htmlcondor_collector.htmlcondor_master.htmlcondor_negotiator.htmlcondor_procd.htmlcondor_schedd.htmlcondor_startd.htmlcondor_startd_ssh.htmlconman.htmlconman_unconfined_script.htmlconsolekit.htmlcontainer.htmlcontainer_auth.htmlcontainer_runtime.htmlcouchdb.htmlcourier_authdaemon.htmlcourier_pcp.htmlcourier_pop.htmlcourier_sqwebmail.htmlcourier_tcpd.htmlcpucontrol.htmlcpufreqselector.htmlcpuplug.htmlcpuspeed.htmlcrack.htmlcrond.htmlcronjob.htmlcrontab.htmlctdbd.htmlcups_pdf.htmlcupsd.htmlcupsd_config.htmlcupsd_lpd.htmlcvs.htmlcvs_script.htmlcyphesis.htmlcyrus.htmldbadm.htmldbadm_sudo.htmldbskkd.htmldcc_client.htmldcc_dbclean.htmldccd.htmldccifd.htmldccm.htmldcerpcd.htmlddclient.htmldeltacloudd.htmldenyhosts.htmldepmod.htmldevicekit.htmldevicekit_disk.htmldevicekit_power.htmldhcpc.htmldhcpd.htmldictd.htmldirsrv.htmldirsrv_snmp.htmldirsrvadmin.htmldirsrvadmin_script.htmldirsrvadmin_unconfined_script.htmldisk_munin_plugin.htmldkim_milter.htmldlm_controld.htmldmesg.htmldmidecode.htmldnsmasq.htmldnssec_trigger.htmldovecot.htmldovecot_auth.htmldovecot_deliver.htmldrbd.htmldspam.htmldspam_script.htmlentropyd.htmleventlogd.htmlevtchnd.htmlexim.htmlfail2ban.htmlfail2ban_client.htmlfcoemon.htmlfenced.htmlfetchmail.htmlfingerd.htmlfirewalld.htmlfirewallgui.htmlfirstboot.htmlfoghorn.htmlfprintd.htmlfreeipmi_bmc_watchdog.htmlfreeipmi_ipmidetectd.htmlfreeipmi_ipmiseld.htmlfreqset.htmlfsadm.htmlfsdaemon.htmlftpd.htmlftpdctl.htmlgames.htmlgames_srv.htmlganesha.htmlgconfd.htmlgconfdefaultsm.htmlgdomap.htmlgeoclue.htmlgetty.htmlgfs_controld.htmlgit_script.htmlgit_session.htmlgit_system.htmlgitosis.htmlglance_api.htmlglance_registry.htmlglance_scrubber.htmlglusterd.htmlgnomesystemmm.htmlgpg.htmlgpg_agent.htmlgpg_helper.htmlgpg_pinentry.htmlgpg_web.htmlgpm.htmlgpsd.htmlgreylist_milter.htmlgroupadd.htmlgroupd.htmlgssd.htmlgssproxy.htmlguest.htmlhaproxy.htmlhddtemp.htmlhostname.htmlhsqldb.htmlhttpd.htmlhttpd_helper.htmlhttpd_passwd.htmlhttpd_php.htmlhttpd_rotatelogs.htmlhttpd_suexec.htmlhttpd_sys_script.htmlhttpd_unconfined_script.htmlhttpd_user_script.htmlhwclock.htmlhwloc_dhwd.htmlhypervkvp.htmlhypervvssd.htmliceauth.htmlicecast.htmlifconfig.htmlindex.htmlinetd.htmlinetd_child.htmlinit.htmlinitrc.htmlinnd.htmlinsmod.htmlinstall.htmliodined.htmliotop.htmlipa_dnskey.htmlipa_helper.htmlipa_otpd.htmlipmievd.htmlipsec.htmlipsec_mgmt.htmliptables.htmlirc.htmlirqbalance.htmlirssi.htmliscsid.htmlisnsd.htmliwhd.htmljabberd.htmljabberd_router.htmljockey.htmljournalctl.htmlkadmind.htmlkdump.htmlkdumpctl.htmlkdumpgui.htmlkeepalived.htmlkeepalived_unconfined_script.htmlkernel.htmlkeyboardd.htmlkeystone.htmlkeystone_cgi_script.htmlkismet.htmlklogd.htmlkmscon.htmlkpropd.htmlkrb5kdc.htmlksmtuned.htmlktalkd.htmll2tpd.htmlldconfig.htmllircd.htmllivecd.htmllldpad.htmlload_policy.htmlloadkeys.htmllocal_login.htmllocate.htmllockdev.htmllogadm.htmllogrotate.htmllogrotate_mail.htmllogwatch.htmllogwatch_mail.htmllpd.htmllpr.htmllsassd.htmllsmd.htmllsmd_plugin.htmllttng_sessiond.htmllvm.htmllwiod.htmllwregd.htmllwsmd.htmlmail_munin_plugin.htmlmailman_cgi.htmlmailman_mail.htmlmailman_queue.htmlman2html_script.htmlmandb.htmlmcelog.htmlmdadm.htmlmediawiki_script.htmlmemcached.htmlmencoder.htmlminidlna.htmlminissdpd.htmlmip6d.htmlmirrormanager.htmlmock.htmlmock_build.htmlmodemmanager.htmlmojomojo_script.htmlmon_procd.htmlmon_statd.htmlmongod.htmlmotion.htmlmount.htmlmount_ecryptfs.htmlmozilla.htmlmozilla_plugin.htmlmozilla_plugin_config.htmlmpd.htmlmplayer.htmlmrtg.htmlmscan.htmlmunin.htmlmunin_script.htmlmysqld.htmlmysqld_safe.htmlmysqlmanagerd.htmlmythtv_script.htmlnagios.htmlnagios_admin_plugin.htmlnagios_checkdisk_plugin.htmlnagios_eventhandler_plugin.htmlnagios_mail_plugin.htmlnagios_openshift_plugin.htmlnagios_script.htmlnagios_services_plugin.htmlnagios_system_plugin.htmlnagios_unconfined_plugin.htmlnamed.htmlnamespace_init.htmlncftool.htmlndc.htmlnetlabel_mgmt.htmlnetlogond.htmlnetutils.htmlneutron.htmlnewrole.htmlnfsd.htmlninfod.htmlnmbd.htmlnova.htmlnrpe.htmlnscd.htmlnsd.htmlnsd_crond.htmlnslcd.htmlntop.htmlntpd.htmlnumad.htmlnut_upsd.htmlnut_upsdrvctl.htmlnut_upsmon.htmlnutups_cgi_script.htmlnx_server.htmlnx_server_ssh.htmlobex.htmloddjob.htmloddjob_mkhomedir.htmlopenct.htmlopendnssec.htmlopenhpid.htmlopenshift.htmlopenshift_app.htmlopenshift_cgroup_read.htmlopenshift_cron.htmlopenshift_initrc.htmlopenshift_net_read.htmlopenshift_script.htmlopensm.htmlopenvpn.htmlopenvpn_unconfined_script.htmlopenvswitch.htmlopenwsman.htmloracleasm.htmlosad.htmlpads.htmlpam_console.htmlpam_timestamp.htmlpassenger.htmlpasswd.htmlpcp_pmcd.htmlpcp_pmie.htmlpcp_pmlogger.htmlpcp_pmmgr.htmlpcp_pmproxy.htmlpcp_pmwebd.htmlpcscd.htmlpegasus.htmlpegasus_openlmi_account.htmlpegasus_openlmi_admin.htmlpegasus_openlmi_logicalfile.htmlpegasus_openlmi_services.htmlpegasus_openlmi_storage.htmlpegasus_openlmi_system.htmlpegasus_openlmi_unconfined.htmlpesign.htmlphc2sys.htmlping.htmlpingd.htmlpiranha_fos.htmlpiranha_lvs.htmlpiranha_pulse.htmlpiranha_web.htmlpkcs_slotd.htmlpki_ra.htmlpki_tomcat.htmlpki_tomcat_script.htmlpki_tps.htmlplymouth.htmlplymouthd.htmlpodsleuth.htmlpolicykit.htmlpolicykit_auth.htmlpolicykit_grant.htmlpolicykit_resolve.htmlpolipo.htmlpolipo_session.htmlportmap.htmlportmap_helper.htmlportreserve.htmlpostfix_bounce.htmlpostfix_cleanup.htmlpostfix_local.htmlpostfix_map.htmlpostfix_master.htmlpostfix_pickup.htmlpostfix_pipe.htmlpostfix_postdrop.htmlpostfix_postqueue.htmlpostfix_qmgr.htmlpostfix_showq.htmlpostfix_smtp.htmlpostfix_smtpd.htmlpostfix_virtual.htmlpostgresql.htmlpostgrey.htmlpppd.htmlpptp.htmlprelink.htmlprelink_cron_system.htmlprelude.htmlprelude_audisp.htmlprelude_correlator.htmlprelude_lml.htmlpreupgrade.htmlprewikka_script.htmlprivoxy.htmlprocmail.htmlprosody.htmlpsad.htmlptal.htmlptchown.htmlptp4l.htmlpublicfile.htmlpulseaudio.htmlpuppetagent.htmlpuppetca.htmlpuppetmaster.htmlpwauth.htmlpyicqt.htmlqdiskd.htmlqemu_dm.htmlqmail_clean.htmlqmail_inject.htmlqmail_local.htmlqmail_lspawn.htmlqmail_queue.htmlqmail_remote.htmlqmail_rspawn.htmlqmail_send.htmlqmail_smtpd.htmlqmail_splogger.htmlqmail_start.htmlqmail_tcp_env.htmlqpidd.htmlquota.htmlquota_nld.htmlrabbitmq.htmlracoon.htmlradiusd.htmlradvd.htmlrasdaemon.htmlrdisc.htmlreadahead.htmlrealmd.htmlrealmd_consolehelper.htmlredis.htmlregex_milter.htmlremote_login.htmlrestorecond.htmlrhev_agentd.htmlrhev_agentd_consolehelper.htmlrhgb.htmlrhnsd.htmlrhsmcertd.htmlricci.htmlricci_modcluster.htmlricci_modclusterd.htmlricci_modlog.htmlricci_modrpm.htmlricci_modservice.htmlricci_modstorage.htmlrlogind.htmlrngd.htmlroundup.htmlrpcbind.htmlrpcd.htmlrpm.htmlrpm_script.htmlrshd.htmlrssh.htmlrssh_chroot_helper.htmlrsync.htmlrtas_errd.htmlrtkit_daemon.htmlrun_init.htmlrwho.htmlsamba_net.htmlsamba_unconfined_net.htmlsamba_unconfined_script.htmlsambagui.htmlsandbox.htmlsandbox_min.htmlsandbox_min_client.htmlsandbox_net.htmlsandbox_net_client.htmlsandbox_web.htmlsandbox_web_client.htmlsandbox_x.htmlsandbox_x_client.htmlsandbox_xserver.htmlsanlk_resetd.htmlsanlock.htmlsaslauthd.htmlsbd.htmlsblim_gatherd.htmlsblim_reposd.htmlsblim_sfcbd.htmlsecadm.htmlsecadm_screen.htmlsecadm_su.htmlsecadm_sudo.htmlsectoolm.htmlselinux_munin_plugin.htmlsemanage.htmlsendmail.htmlsensord.htmlsepgsql_ranged_proc.htmlsepgsql_trusted_proc.htmlservices_munin_plugin.htmlsetfiles.htmlsetfiles_mac.htmlsetkey.htmlsetrans.htmlsetroubleshoot_fixit.htmlsetroubleshootd.htmlsetsebool.htmlsftpd.htmlsge_execd.htmlsge_job.htmlsge_job_ssh.htmlsge_shepherd.htmlshorewall.htmlshowmount.htmlslapd.htmlslpd.htmlsmbcontrol.htmlsmbd.htmlsmbmount.htmlsmokeping.htmlsmokeping_cgi_script.htmlsmoltclient.htmlsmsd.htmlsnapperd.htmlsnmpd.htmlsnort.htmlsosreport.htmlsoundd.htmlspamass_milter.htmlspamc.htmlspamd.htmlspamd_update.htmlspc.htmlspeech-dispatcher.htmlsquid.htmlsquid_cron.htmlsquid_script.htmlsrvsvcd.htmlssh.htmlssh_keygen.htmlssh_keysign.htmlsshd.htmlsshd_keygen.htmlsshd_net.htmlsshd_sandbox.htmlsssd.htmlsssd_selinux_manager.htmlstaff.htmlstaff_consolehelper.htmlstaff_dbusd.htmlstaff_gkeyringd.htmlstaff_screen.htmlstaff_seunshare.htmlstaff_ssh_agent.htmlstaff_sudo.htmlstaff_wine.htmlstapserver.htmlstunnel.htmlstyle.csssulogin.htmlsvc_multilog.htmlsvc_run.htmlsvc_start.htmlsvirt.htmlsvirt_kvm_net.htmlsvirt_qemu_net.htmlsvirt_socket.htmlsvirt_tcg.htmlsvnserve.htmlswat.htmlswift.htmlsysadm.htmlsysadm_gkeyringd.htmlsysadm_passwd.htmlsysadm_screen.htmlsysadm_seunshare.htmlsysadm_ssh_agent.htmlsysadm_su.htmlsysadm_sudo.htmlsyslogd.htmlsysstat.htmlsystem_cronjob.htmlsystem_dbusd.htmlsystem_mail.htmlsystem_munin_plugin.htmlsystemd_bootchart.htmlsystemd_hostnamed.htmlsystemd_hwdb.htmlsystemd_initctl.htmlsystemd_localed.htmlsystemd_logger.htmlsystemd_logind.htmlsystemd_machined.htmlsystemd_networkd.htmlsystemd_notify.htmlsystemd_passwd_agent.htmlsystemd_resolved.htmlsystemd_sysctl.htmlsystemd_timedated.htmlsystemd_tmpfiles.htmltangd.htmltargetd.htmltcpd.htmltcsd.htmltelepathy_gabble.htmltelepathy_idle.htmltelepathy_logger.htmltelepathy_mission_control.htmltelepathy_msn.htmltelepathy_salut.htmltelepathy_sofiasip.htmltelepathy_stream_engine.htmltelepathy_sunshine.htmltelnetd.htmltftpd.htmltgtd.htmlthin.htmlthin_aeolus_configserver.htmlthumb.htmltimemaster.htmltlp.htmltmpreaper.htmltomcat.htmltor.htmltraceroute.htmltuned.htmltvtime.htmludev.htmlulogd.htmluml.htmluml_switch.htmlunconfined.htmlunconfined_cronjob.htmlunconfined_dbusd.htmlunconfined_mount.htmlunconfined_munin_plugin.htmlunconfined_sendmail.htmlunconfined_service.htmlupdate_modules.htmlupdfstab.htmlupdpwd.htmlusbmodules.htmlusbmuxd.htmluser.htmluser_dbusd.htmluser_gkeyringd.htmluser_mail.htmluser_screen.htmluser_seunshare.htmluser_ssh_agent.htmluser_wine.htmluseradd.htmlusernetctl.htmlutempter.htmluucpd.htmluuidd.htmluux.htmlvarnishd.htmlvarnishlog.htmlvdagent.htmlvhostmd.htmlvirsh.htmlvirsh_ssh.htmlvirt_bridgehelper.htmlvirt_qemu_ga.htmlvirt_qemu_ga_unconfined.htmlvirt_qmf.htmlvirtd.htmlvirtd_lxc.htmlvirtlogd.htmlvlock.htmlvmtools.htmlvmtools_helper.htmlvmtools_unconfined.htmlvmware.htmlvmware_host.htmlvnstat.htmlvnstatd.htmlvpnc.htmlw3c_validator_script.htmlwatchdog.htmlwatchdog_unconfined.htmlwdmd.htmlwebadm.htmlwebalizer.htmlwebalizer_script.htmlwinbind.htmlwinbind_helper.htmlwine.htmlwireshark.htmlwpa_cli.htmlxauth.htmlxdm.htmlxdm_unconfined.htmlxenconsoled.htmlxend.htmlxenstored.htmlxguest.htmlxguest_dbusd.htmlxguest_gkeyringd.htmlxserver.htmlypbind.htmlyppasswdd.htmlypserv.htmlypxfr.htmlzabbix.htmlzabbix_agent.htmlzabbix_script.htmlzarafa_deliver.htmlzarafa_gateway.htmlzarafa_ical.htmlzarafa_indexer.htmlzarafa_monitor.htmlzarafa_server.htmlzarafa_spooler.htmlzebra.htmlzoneminder.htmlzoneminder_script.htmlzos_remote.htmlincludeMakefileadminadmin.xmlbootloader.ifconsoletype.ifdmesg.ifnetutils.ifsu.ifsudo.ifusermanage.ifappsapps.xmlseunshare.ifbuild.confcontribcontrib.xmlabrt.ifaccountsd.ifacct.ifada.ifafs.ifaiccu.ifaide.ifaisexec.ifajaxterm.ifalsa.ifamanda.ifamavis.ifamtu.ifanaconda.ifantivirus.ifapache.ifapcupsd.ifapm.ifapt.ifarpwatch.ifasterisk.ifauthbind.ifauthconfig.ifautomount.ifavahi.ifawstats.ifbackup.ifbacula.ifbcfg2.ifbind.ifbird.ifbitlbee.ifblkmapd.ifblueman.ifbluetooth.ifboinc.ifbrctl.ifbrltty.ifbugzilla.ifbumblebee.ifcachefilesd.ifcalamaris.ifcallweaver.ifcanna.ifccs.ifcdrecord.ifcertmaster.ifcertmonger.ifcertwatch.ifcfengine.ifcgdcbxd.ifcgroup.ifchrome.ifchronyd.ifcinder.ifcipe.ifclamav.ifclockspeed.ifclogd.ifcloudform.ifcmirrord.ifcobbler.ifcockpit.ifcollectd.ifcolord.ifcomsat.ifcondor.ifconman.ifconsolekit.ifcontainer.ifcorosync.ifcouchdb.ifcourier.ifcpucontrol.ifcpufreqselector.ifcpuplug.ifcron.ifctdb.ifcups.ifcvs.ifcyphesis.ifcyrus.ifdaemontools.ifdante.ifdbadm.ifdbskk.ifdbus.ifdcc.ifddclient.ifddcprobe.ifdenyhosts.ifdevicekit.ifdhcp.ifdictd.ifdirmngr.ifdirsrv-admin.ifdirsrv.ifdistcc.ifdjbdns.ifdkim.ifdmidecode.ifdnsmasq.ifdnssec.ifdnssectrigger.ifdovecot.ifdpkg.ifdrbd.ifdspam.ifentropyd.ifetcd.ifevolution.ifexim.iffail2ban.iffcoe.iffetchmail.iffinger.iffirewalld.iffirewallgui.iffirstboot.iffprintd.iffreeipmi.iffreqset.ifftp.ifgames.ifganesha.ifgatekeeper.ifgdomap.ifgear.ifgeoclue.ifgift.ifgit.ifgitosis.ifglance.ifglusterd.ifgnome.ifgnomeclock.ifgpg.ifgpm.ifgpsd.ifgssproxy.ifguest.ifhadoop.ifhal.ifhddtemp.ifhostapd.ifhowl.ifhsqldb.ifhwloc.ifhypervkvp.ifi18n_input.ificecast.ififplugd.ifimaze.ifinetd.ifinn.ifiodine.ifiotop.ifipa.ifipmievd.ifirc.ifircd.ifirqbalance.ifiscsi.ifisns.ifjabber.ifjava.ifjetty.ifjockey.ifjournalctl.ifkde.ifkdump.ifkdumpgui.ifkeepalived.ifkerberos.ifkerneloops.ifkeyboardd.ifkeystone.ifkismet.ifkmscon.ifksmtuned.ifktalk.ifkudzu.ifl2tp.ifldap.iflightsquid.iflikewise.iflinuxptp.iflircd.iflivecd.iflldpad.ifloadkeys.iflockdev.iflogrotate.iflogwatch.iflpd.iflsm.iflttng-tools.ifmailman.ifmailscanner.ifman2html.ifmandb.ifmcelog.ifmcollective.ifmediawiki.ifmemcached.ifmilter.ifminidlna.ifminissdpd.ifmip6d.ifmirrormanager.ifmock.ifmodemmanager.ifmojomojo.ifmon_statd.ifmongodb.ifmono.ifmonop.ifmotion.ifmozilla.ifmpd.ifmplayer.ifmrtg.ifmta.ifmunin.ifmysql.ifmythtv.ifnaemon.ifnagios.ifnamespace.ifncftool.ifnessus.ifnetworkmanager.ifninfod.ifnis.ifnova.ifnscd.ifnsd.ifnslcd.ifnsplugin.ifntop.ifntp.ifnumad.ifnut.ifnx.ifoav.ifobex.ifoddjob.ifoident.ifopenca.ifopenct.ifopendnssec.ifopenhpi.ifopenhpid.ifopenshift-origin.ifopenshift.ifopensm.ifopenvpn.ifopenvswitch.ifopenwsman.iforacleasm.ifosad.ifpacemaker.ifpads.ifpassenger.ifpcmcia.ifpcp.ifpcscd.ifpegasus.ifperdition.ifpesign.ifpingd.ifpiranha.ifpkcs.ifpki.ifplymouthd.ifpodsleuth.ifpolicykit.ifpolipo.ifportage.ifportmap.ifportreserve.ifportslave.ifpostfix.ifpostfixpolicyd.ifpostgrey.ifppp.ifprelink.ifprelude.ifprivoxy.ifprocmail.ifprosody.ifpsad.ifptchown.ifpublicfile.ifpulseaudio.ifpuppet.ifpwauth.ifpxe.ifpyzor.ifqemu.ifqmail.ifqpid.ifquantum.ifquota.ifrabbitmq.ifradius.ifradvd.ifraid.ifrasdaemon.ifrazor.ifrdisc.ifreadahead.ifrealmd.ifredis.ifremotelogin.ifresmgr.ifrgmanager.ifrhcs.ifrhev.ifrhgb.ifrhnsd.ifrhsmcertd.ifricci.ifrkhunter.ifrlogin.ifrngd.ifrolekit.ifroundup.ifrpc.ifrpcbind.ifrpm.ifrshd.ifrssh.ifrsync.ifrtas.ifrtkit.ifrwho.ifsamba.ifsambagui.ifsamhain.ifsandbox.ifsandboxX.ifsanlock.ifsasl.ifsbd.ifsblim.ifscreen.ifsectoolm.ifsendmail.ifsensord.ifsetroubleshoot.ifsge.ifshorewall.ifshutdown.ifslocate.ifslpd.ifslrnpull.ifsmartmon.ifsmokeping.ifsmoltclient.ifsmsd.ifsmstools.ifsnapper.ifsnmp.ifsnort.ifsosreport.ifsoundserver.ifspamassassin.ifspeech-dispatcher.ifspeedtouch.ifsquid.ifsssd.ifstapserver.ifstunnel.ifsvnserve.ifswift.ifswift_alias.ifsxid.ifsysstat.iftangd.iftargetd.iftcpd.iftcsd.iftelepathy.iftelnet.iftftp.iftgtd.ifthin.ifthumb.ifthunderbird.iftimidity.iftlp.iftmpreaper.iftomcat.iftor.iftransproxy.iftripwire.iftuned.iftvtime.iftzdata.ifucspitcp.ifulogd.ifuml.ifupdfstab.ifuptime.ifusbmodules.ifusbmuxd.ifuserhelper.ifusernetctl.ifuucp.ifuuidd.ifuwimap.ifvarnishd.ifvbetool.ifvdagent.ifvhostmd.ifvirt.ifvlock.ifvmtools.ifvmware.ifvnstatd.ifvpn.ifw3c.ifwatchdog.ifwdmd.ifwebadm.ifwebalizer.ifwine.ifwireshark.ifwm.ifxen.ifxfs.ifxguest.ifxprint.ifxscreensaver.ifyam.ifzabbix.ifzarafa.ifzebra.ifzoneminder.ifzosremote.ifglobal_booleans.xmlglobal_tunables.xmlkernelkernel.xmlcorecommands.ifcorenetwork.ifdevices.ifdomain.iffiles.iffilesystem.ifkernel.ifmcs.ifmls.ifselinux.ifstorage.ifterminal.ifubac.ifunlabelednet.ifrolesroles.xmlauditadm.iflogadm.ifsecadm.ifstaff.ifsysadm.ifsysadm_secadm.ifunconfineduser.ifunprivuser.ifservicesservices.xmlpostgresql.ifssh.ifxserver.ifsupportall_perms.sptdivert.m4file_patterns.sptipc_patterns.sptloadable_module.sptmisc_macros.sptmisc_patterns.sptmls_mcs_macros.sptobj_perm_sets.sptpolicy.dtdsegenxml.pysegenxml.pycsegenxml.pyoundivert.m4systemsystem.xmlapplication.ifauthlogin.ifclock.iffstools.ifgetty.ifhostname.ifhotplug.ifinit.ifipsec.ifiptables.iflibraries.iflocallogin.iflogging.iflvm.ifmiscfiles.ifmodutils.ifmount.ifnetlabel.ifselinuxutil.ifsetrans.ifsysnetwork.ifsystemd.ifudev.ifunconfined.ifuserdomain.ifpolicy.dtdpolicy.xmlinterface_info/usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/html//usr/share/selinux/devel/include//usr/share/selinux/devel/include/admin//usr/share/selinux/devel/include/apps//usr/share/selinux/devel/include/contrib//usr/share/selinux/devel/include/kernel//usr/share/selinux/devel/include/roles//usr/share/selinux/devel/include/services//usr/share/selinux/devel/include/support//usr/share/selinux/devel/include/system//var/lib/sepolgen/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m32 -march=x86-64 -mtune=generic -mfpmath=sse -fasynchronous-unwind-tablescpioxz2noarch-redhat-linux-gnu  directoryASCII textSE Linux policy interface sourceSE Linux policy module sourceHTML document, ASCII textmakefile script, ASCII textC++ source, ASCII textASCII text, with very long linesASCII text, with no line terminatorsPython script, ASCII text executablepython 2.7 byte-compiledXML 1.0 document, ASCII textcannot open (No such file or directory)?p7zXZ !#,F] b2u jӫ`(qS{ʂk5Xg#əa7͜J۱-9S0XH d/^\oc5®-;v <_m ; ]#(Pg=> l%FǺS O0vkGQiXk'YTZE9Pŗ].3h\|Eꨡ,@vJ9|tzCʦڿM9t<)%-eP a/*F$>T߽ya=5CDQ. g&P<ѓP7~(?1Ai0#WLU$FnI9C&\jj#*(.\X!K)U׌ø$%1F 媬wLr/JwTZ1y G8Yn \ޔ Ƴ7Fg3 ^y%_iI'ъ  {0 ́D#HQYᡄx%}[+J]Œ*9Y@ ,1H@WY[-ի.xi9y 5k&,B<t fXbsN=1CL(4L@xU5},U)CP5/Gfgz_T"uMs~ؾxCvP)uc#IT79 G>܋"/Z↧*' x߂JӦ$7Lק> d*ξK]"@s6+;D^afo%<`ƑM:J:#8oUS.'`L tY[ƹ;6 L52 W}iٛIE}žue;͊p,tH0'B<}*\A-XBeەمc_ك̞Q,4|DZL~zmٔlz>&H$-heJ:UF H bތ|eRJьEN2zvzt)asYRs"JilLP3⚇.s1Hҙ9:ӥ'NRT::JEX*'ĽLS]tvW8:=u3J/h=]VToq _]SDAtsսO=P߶@U;Cz@n_`ʗ(޺@z|&y.8TA,LAكJL!dž}$ˣy:<.d{aE9x["H!K#\ϖZ@gXbBgb 0C[+8f^nQɚaDb+pD%FM,8ɨ=`ē2K&۳v z mS uTyz`MgVݷ[0/3ōUςv-)QDQE HSR1\{AΏu;&s Cc3,JݸGsZ2UeYQV'=փ)HŸ벞s;ugT ]9VG0:5QWL{,P,ًDU˛}kR/\ؘ,j,W3+0Dp D$ʰO x#Xل<.~ k3 ̲N k$~y3tc 11UμllxFM(Vj|圏` ~t:Ħ*7mb#GK5cAd.B ׯoSit'NŨY_7-@90QGĝq sĘuLi[Ԙ6{ױs R/4׼:}in Vy`),+CDᰝr̿/)eWpJ("$HoŴTsFtn.$zh(ϰ6Po},o!EA84eHn<+)?UE#nq[ $H`: 71ؿW /"O`dc{˼u.+:pH݀OVummxkj_h%9=Zm$N#zlE,ie œ<>B" b>f1EIcg<ڛ:˟? GD Z 7k*~&+-۲]{(TBn:+vL;cԍ9 ^jk(B/p1jg`}l{ 󌕟pP|IQꦁ>a]q+\D=f}oks/ ?jЏ&$'ĕ' 5]3]=IK\^y/0_%]OtTijee-?80@$)s% 41:.ΪYTإpf;5 u < 4ZiȨ8i,+#(m~ܤK'&蜸FӐd0p xXڽVO^i}R>qH[ 4y8! xbr"tf}U7(*@o^A p٤? P`GeO93|GEyq\_WaDW?ed-B 8,wQ/jlE];2+R.wmF}L`5x [}@zĈPrJ{XF%opKU'21C?D2}x7ܐ#O%iN1Iu([o | "pH5Y )p V \/S(`l <'=$`evun΄eЉ$)TOW6e}»g.:"w,(625diHpfVLKt&VB:JQYG~y(]ŏL_l YшZ= 5ʥRii 0@eo/fJwXc[]:ڣ)2ntAg}NrH `NBwyHz"QVAqϚߌiິu7;sP4"b/KBhP+P҇NÉxfAᯛڲ_Z7YZ g2{"ڿLokʬSa,w80mMP gcSI/(q?+\Qe읒*%!Yΐjh22a@חₑKQҽg`PK]E$~!P4]7a61&:Hwm_,?JU8ĝ*( _Xs(QQK{r -V߉lVq!$V$yhs/a.xXg'62.-5CU& [:B %>.>N h|OS۟Nj|SOCQvoƔxLVNotI04;kU&K 9Y.jA^j*|k_Dh]񀞎)|s|B(@ɘ "6eSGiz0ÆN(rJ2/(ZZMiA'oJZƭAL9WAZ2^ j9 87Q#n흀"oI c>[X ֙kvc7KYCL2^3dɍyqhpR;ǡ~\^ i/3]Hՙq(C)͹]= x)0* b6-[CK):7BcCDMlRN!5Pݨ&,U$H*9(âL") .Ow9:A0xS,;HJ ^F=ڭ +NBՍ2GUqk{4  ww]Y&ϼ`&ϸ׺ vc5Ï*j 9  =nhTy YT|S{;_}6֐1U]]P>|{̤Spag7h=~ i,D%Cm5J2+Z8-c \ |_J!`Hj/:`G dSJ+2|Vf7! !QA*lIvsrZ@V;V;ީIR3Q{Um'8 FJ7էMZWX~Ώ'_zYLN“T_L6`C e0{0buZtǡ?/doɏC&CqM æԋMW]\e,%*1ٛؗDVn`}w%_E i_fY:n)IhѲqTɯڈcH+SKy?oL5 [.}J hlB_u>bBd Œd|)l2>dX ѷnp)b)ݙdfh'l˚mrh.ŤuK,j=جQ(ɢC+<ۜLmt9N58AɁJ!1j.dSqz{L{._Dhy.xNIɘ>)ĕܚR'l#§. h }Ao ;r)!93ĵed&?UUjo*X= ]%*:.6=(J ųa5N%1g*괢=ߜd!j]oh$"(kNΨlW~A>{GqL,)fl[}#l)-boD},zM#`Ifrx(0v.0W7u^Z˪a阡q'hgs"!ab@$́㬿Ms11\.q'L{< ~Sy1`vjIlbjN,),789NL"`aً8!_g w%:Qk,>սڶ*j*:WetEVP__*2oʼ>ʝgr8Ѹ 9_$7 |#_sX܄B͟9!|# )yHtSQZ C"ĉ5Nٔ?zoɌi0 ILL<|1(k5V^vgiVU! aG~mRLCxdA2P-xg[bC*,I8+Oĸa71Z1A\Yuű4ψb̌8<6"/[Lk:3PDlVd ToJ~v7 v&42ȮOqIݢ8{D톶07Dh?eM&#hJ 3X%Gi*yS+Hx q# 3!jkb`%E#Ad.D=LG59Uݷ86:oB΍,/ !lYa|wiK]'8A`d/#/|*)cR|Tz!( ڦ-sS/#]xRc?{ihYa3,?89uQM=k1W62Fk]VVZ<9V0<,z,+a܋ʟdrp蠈Jw:KIׇqȰ,ֺAvŃr5~n}5Dǽ-,40Բ (GopeNZ5 voNQipTt!ԝ^doS-a p ;^mg9bl_iCc@ƴ?o:g3f4ʔ#Hj٨(<ಒLd ˶F}۬DA:ל:#됂V?"Cwo\t فڱ¹zeH)Jbj34 s}c,r SV44ndZe h! 6bU6D 4א-FI{4T^\!Thғ3DQxڿ)IUǕ PLJ7/秧4OWzKġ"N,}W۫d TZHY۲L,frR G1̕ .EP`oB} r@HցcMw=)>8 c'K` Pp, O)C͊{ZO-‘1EEᭂg}"Ub|ʞ Z][es (}FbW+b-q s Mt837Ɔ^ZgCUçkK|'A2~PvnxHkeT8i|1uBq!ݻ%߾R'yi-HxJ@*i̫8΋8@>!b"9R4ԟ|TJQ!ԕD qrTkE?= U)O{ eH/5^n$tB7WfCGz=7(=˟08^C}ou_wq*|s2  Zud*Qq@ ^X6_T9H#̙FG@(j'4魅#jutp6i#Ϯdk}V``D~-VOP7t# m\G2h ϏZ9]Łékk1}Mu_zA>U=Vg=5Ğwͷg 5.3Iʻ\ %NVhRf#8f8)$/?<s]gmg?BB]Ph $VbHٴ+snk[Vpا`vb즯&/^oEѣP+#/kZH)!x9 J40>A:;O] 9&Kc8Y|`c' wD6dtni!ca3n󤄸q~~՞QjlۼBBMCu"0,Nt3ro*ԝ652c.IiTV UGjfEiD:mիBֵW@Ql0>R Y҂e9oA1b! 6 8uRXK7N7;'_~CbᖾxoD\k ̦ػ;.CLIzX.Ë>c`qw+aO(j ig%yj}CZx-tEXa c {ZIW h~h]O)+V,sfW+˿RQ2~BZ1cŴi*Q$y/VI@rWRf. ;k)O}xf{Bͤ]l"<4" xR &:MeejZSK[.g5|nn%wbOޑTӊ u2r%V6/Eak9RxnX\a#Ήr#!Xܬ#^EBmScd&'0WD#S+6QNF [j1&#%ܞ.}(ۡ&;2U)HӭV{2)\]!|JDzUzKqP4==/cw@"q5$ςj`̤ \T&ԑ|YlgkwmYO04!s{؏Df2iMv!q">2v1_yIIsTWF0Rw뙺.]uA+;Fp?+x* K&i,> x1 vqcq(@h#V]hT͂?ԖZќq;Bg?رS}\=6juGMҌJrqq9 13Dm-Lynvgמa(R#1,/h͂[-QFEZ.76y`:Bb?9H\ uYZ$xU(WzQ ]@w<_iXEtmW1 "{A2ipHZIw@߮a0y2!o7jhs!p| hD Pކ6^r*ͷ\p:oG9%h@j1ax`زhHf r'Oahzb20_ɵ}9Lf,*JNie=5vlHp p%8*eUq6 (8l| Ž9`X~ C_JŨ/A T7,\,X>(Z;r#c a "fV`câ_-&^Vlv{xW(4@04W%usF5B*WAWd {]_>W#Dqr-P&m=|TՋߎi+oӈ\l )N1/)^п|~CbdFOfja(ZE6m̍0~˝5ąn}Ebh@3-S!ن&.P54Lm=bӽ֤#}t/ɸ5 NML"{ F{[9`c BHGmӂ?Wڢ%m12S j ,ZIu,!Y3|c75+3ߣlJPB'a@ɇxj!OEMWd' t#eaݕlYIs, 9JvmVj$nْc5:e'ym9 3^87,kY݄EmZ}ZА(uR,8qGI+`1֯u )=ķSU6v'S_F]FYxjP[8CYx'Pww&&SJhH JgD7Y&̈2Q ⺵2Q/H =./ Q<8 JԠk3B9FTso;!@\nVLGܴ%]6s=mRXPm~-?$(uQ θ ohK/Ne9h: 9ʄZ9^=c"<'Hy1yEYLBҭj5sCUOb=W|V[ݚ֝ ߴ4hّve&tykT8VRrX5͉.MV3׆I8I, E gCן!ee-.UBm ?UZ;LñG.ȣ,fPgW|uN\_+ _~j|u㚢܀S) ~ ,&n$*`Jd`CK><ᖲ^5IR'ZvШŐA%ڵ@dgYY)e)vɖu!34rgOnR S ?O#yr`'w*@ڡR4ɱљ+m wa9לPr Ș'hN*YfBM,nbO;eFGo>a\Z6Oy:`EN)Jgk,p JF*͋:*mܧ6M@+SD_!}'pd7}ygu(%d9]=C}:n&zC5OV\f}s~l-,16!ZԶRhXx|Է~y)EY}QO>X&/?# KqϞsd/ (`?zf%H|KjC'3t!C6U2cCaWRjX;,ҹm`X\cX({ +xa]HWEZFy;K DK( `lsxK3}c*GBR~F+LI!͂Д8@juoXS`!Ad`@ICPq`ZgJ?=Q͘i3IPp{69lE#è!ZȹE]'n S0K(L|F-M?].A&=m^w ʙ|xp%, mHOi|]è䬺LZti/3o+Lǜ2\Ni`$.⊱9;}?S 9&69%$)*;ÔYZu\?8)?xlbbrGSIm)nQQ@%cc:st GPplmYV -?=*O>V%0cr&Ŝg :- p>mrX֚T*aErvǽcX 9y;c?Qu:T xWʙ+.lJY)>"[29Q'GDֻG<{v7_ %Ҍ d=oO;AA9 {+q~jߙ[>*@OsnjEp {Meߧ")Qeׇ!MyvNjKZ3]ڢ>$J'Tv>&a92$-9EO| PNnԁ5W㒬 eR3 x0+0l?}&ߕt|NDC<ze16_pFs)OXY.<azUg -?s3/튍Ez((1#_EkK5Yp|~(^.sʌKF .Qg*] uYJm`ɜ6g">c2K5jp:CM**=IdpK;|v0GӮ"7 b/( Ίx5H 1jcqrF%-iYho*)FcWI&2ZDU8bLݘH(dVaCa],ƹRr gnT\N?rZ'%RBj߫ x@SoG<})\H*r)K{ N#6b5d/ S"tL t [+Y6\_YX.Lټ  f{2aW 5aj4T5_kk9f52Hsm3t Q&cymx#!:8Bs)WWYGEFNΝLgM[X]u<=-vZ_.y8GX/2v,$[S:*>-U]p.u[XgH/d& cغべWG< (x0wĹmĹ< q-tPs8|i=p*bp6>Es.C3a6zJ̓1ե[AEOJxMC] jܣ$a(ܟΫ3W !CܡʅT A'zB砗-=Y.2tHEYom ^͏}W@!& xi1Hqu%Ǜ&#り[^Dl7ܐbHgGQ:Zx&1[ A 'K_SsE褧C7XӐ|)tD/Dz!J E ^/ǥYm8ʨOK me=i6T_Ka_M$ɘ<} >֪̈́X$q|*W[_ vf'WY^~˕\gto !8g)kYmD݆qbh7^(;e_U+Yc"/92eQ3 N &piL (T[|s31(:4 />ц;xwtSJ.ANUVؖd,Ko[AsG}r55[E7nL!h 1i Cq5)l>?Z܂?J}.&$NBuy";l<`Y<[ْQbA96d\j0˘crSG 5pt,:îwV~`O2F Qr8!Ui*ƓYnfzWo:qQ%0#鮍gZN »+)A#M~R.+ FsMClNמuC_d݃\IzgB bЀMՏ"")$ JӦ8#|}! z.X=ݢ? /ܵ֐H:.\^@sr҇Ҍt%4d/"AOt67\48쇙>P'/>U$;Wf> j A>926X7g~,n;1_o2Lo*^/[5HSNԡ܇bfmjIL웑6cNn/1 L)<8v\QIֿ۲p2pXihJ Y%qߋ\.@ܓZ_4H|cܡ&cW!;0z![&kTȄ`͟91R3ˍ>ԑ=b.lyRC9L!ۇJz'MC΍9t q!ݱ:xOT'} lZ d7*eONk%yQyYP=9FG8 ՍX ']5,aІHW*/Dىf Ap~esࡀ?nD$8Ճ ך@J^vrsSiyMc%͵ pBꀩH?R"g؞|Q%!"=yaWeg͐:F x ^Ϳ0[{B,FT2ȿU 7C{ "+MlZjBQ)%N\9SNHA3[[{O#6ᆹ1'N=db Ͷ6]SpTC鄠-J,ne.}c?mP'wPg%>S73ge!E`ÈIQ'd2/}r?hhbAzQ;dY63SFST|J+,j6+2c܉Bxp(EEnE$32X21&Wfd\9u+ }jLjX%clM?*iT=R?dKdH]x ZeZ51LT!G8"wE3#zCŌIAbFc>0}Xu@Pg E7R5(UT&i0Q zVl)Sq4ɭΜB3Ib} gEƙ]\ PcO*ڥczSw^enq}g A2)%(ݫዮ@)^-X'ǵ#l M>50 + zEii%2^vi:xyEjymY P};[dڥ8  W'2+uҍojiraϒJml#/;z(PT߹Nn1/5i+5dVo>8PexqVf4gB+*8aO0tmz!n37vL_F&qd-fH޾ZuKnnNկ.H 5! ;=^ XK,9 櫣F{q_4ʑL/Qqo EX@DKa1ّ8Żov\/V;2j d4Q }ۊ#XӾX-I(̸W[,V3^t F$|C gt[Ǧ CcZ!BWeԿ1gR>lAh4Ҽr7!J2f>Οt' XIpOey9㉱ 2&=u|]6q*J|d\ >M8W\9BTC\s .=H 1""T/Srsy[߀jYɾti>Z -"6,^> C_R-;Rvb'xA; ֞u}r}M٢{֑)Sl)l<+ cr8-:Z!X 9yu ^cD/Mr.KKubj[jլ␹7NSޞBDۗcSMeP9SrkOfTsDmT$6W~-׆8d"&HJ#e2]hЁ "qWpZ( VgW)L hy0І=^5it0NtE[l82F(}l;X!~3(T"iKVȈ "$:QxE0~/8\Lz;5=ls\'R&ɏt_ (Z,'H qLv,{gFo|d&;,\7,-%4Mk n4}AoY@uի+ _sƣGc^\쇽SX%#@%YanyW:)fE)LD;G\5g&'gx$% ZI00у0E__)_JP@+HYB|Ƚנrm**,6a1vsu+7D YwNk8-sW__/-Ka$8wj[VWIry;)׵̜tD_.hy"%rĘD`3v S8pX 'BHݟ{멠`nCntp>o%?KY,~&/E-iϫ3) u:5q qtq:ob_E$ ?*WJ[TغLW4 U%I Db#44A'8_JWvvYVo1Uk"ԳjvG(Tpkp'{,*%\dLe7VYm?N?֢`F#ru t&';RTUJQX?u℀ =.&b`i:#Q ]D0^ڪ'0 lS܂sjW1+cTzٓk/%\0iJr))hI-\"%sE|@7m* oUϫUC}?60n15Ƅ>d Gڇ"tlnJu޸r)W++ 䤂zvZ:9ҲlE륢ѯ/rn0ߋ3ݐni އCz _9BW9sWDiӲ7@t 9o<鯚 H3#1SYJy)%Q{ȷf7P kJ6l=AzW\w -hBjE|5afYxׇZI3'S9VsMD;nN[BwBa:*IzCFXWwBW0'"4 /5HTNdS ,Rm {p2 jK#@SCMj[R_tithh Ui -V~+ ]e`Tehu36o6Uf׮"匑h Ti (/BsWנ'%֎kƳhy!p+I'hP%ӡqT~f~`Vbݲh*|FEV4WD#$U JXx'_]O\Eo4̉~F*Hfg05֙]&vTųܛ>c0t@( #vן و}0eaq:If92[msOȀbhÐI߷lPBsc\(.3zpnbp|vAY*ːxBLmq.SCk1y7Ztm.V^%/"hdhB8}=2D" PgwiU)iӀ B)8"<~dm~= ,8lrϛ;,-w7P\ -\%Ff LU'/јjIV8HѤvQ]/ w1KYzp$'fDSQŻ DV."eF(:^[s)ߪIĻۀ fл4{Q!>-R:FHO~~$Y'>97Xiٲ`f pN}5g4E ,T`E9b@A3G=dm]EK s߉&1JU:xٵH # bt/trݮ廃~_7NY& ZSd?BTLF6'ƹ!P Qkc" cӊs<ҏCFsɁ%xg@ p\7I$(d࣫7ݮfʡpnD3Z <9A' k7Ww\V.vh|xSby*p 4:m[u n tXmZRDat3 *|Τ PI/^6,9koXQ?qg㗋.l馷Gz'6 ŷ!B7Տ9@ͻ$X$) WhR;['dNw6_y';igJ^f` %L {8P rn(k?%ϙܲEQG3DLPn&*(Qc#)jt9jj.:֩dس ;1D9xފQ:| *1%#1piro Dq z(γ&ssWʹG eɈhE[GKC[^x,P\}\cp)% 9DV@Ў[Yp_ uPl@X*wNߜd,uL.x:iw(-ȷPúnwkz3Y.Դq{ 1t_S%zd}gA,ZK'DS7ZÚa(mcs'N'ܝTpp\7Q>=SGcHۧs; .)ct`= 1*u_R + .SWxJ3,ߦ ;{\"rZYliEsƽe{Kc YWw8<]|`$e}l k,4԰ K>Htyj||<ס O1Ubz1[ /b~Ͻj\ ƒc[,翮t~kB 5,UryB:+iP~n4C5/R2b߿ˁz 9ЉQVu.DTp~ "GBKwFcIꉁ"?JT%瓭V}ɨ0 y@GI7.2]xaL窃O5E6MV|rpV,p7˩4 yeE,8OC?+ކz\8}.z(FTy; P^ppIOXǢẉ{ftQjCʲ_9OynLu7\\zg 'a|ګ= )bG{~fk˺HD*c `?_`$˭jgy3!+)uD8S5lC[h ΜBEH6~6X\a9M"v⊾e3:5LXX ؿ+4mQQxЏeș&t _||j_ny)`[  zVLEU^;m%d4e *G2.1@0bVHXPgjڐH ?` bSHsqlk'>40>Uօʹ*!6Ļ5X`It7hC–Ix|H^`T-HA[K]2ٓфZhDP*f[/4жH[)xPc,ĥ*}OsІ9a44 س6>I _zR圁ΎqE@}ߌd%̳n/[?OOv]It<͇Xo 1_rR~rM;)%/,%q%?*Z9`˾;F(0"P-qu_۟6F?pڝ҇SOOc*{>Hs͠ ILOB/VnJMU#&.Ѓ$_+j쭶Z13E= y CiLm&B$~Sck Pt> -ؒsY\(f% sN#vd42=[NV 8u.ѝ[K "0Z*d"R_AidGƁ){ 7qitR)zՙ &۪y;cS}b2 uYiU1>PvVl7eHEp@ߡljO.FE ~nΝ!W9jϘ@}b Jz=m5ns;%?ը3udWÍ~KynKA$n@wO8iAT|F_OOjT"p ,ghɐXE ~1?6! v̕cG}cO,/$C'{> Lʔ9P+, fA$YnfG0B,"u|*"^oz s7q`/ <3U8_2fi w@ &ɳv/%?ڃ5i5N]^M\9fw$8lN?d&5rZAd|KftX_#{Z`_&T5(#˲Gc(&^=tE㡳 .o[JH6j,w:ϟ@kG#.(gc˥A4L_9[6İf%2y N\3J yпr͆M@ `O3cCML) ytכ"Flia!W%V6R@!* &zpDkps -)dp@'KP;7x5-CD*ȃ tfw{wZN״i<wO(8LM\}V_rxÌ0yE㋃5S*3 |/x"P_es-o s )-W ^ѩ<-~ٔD(%,;YYbۋlhYIgA,ly/e.>ڇy.Ȉ(4`[Osg|8|in~ⷍȋה3L%"$HTU'hbL؀m8.6ꖿ)w&+ S[x%UfV-F6\hU+yvc+(͋=x(W»zD _"s Bfqp|fZ"4$o..Dy/RS۱V2?mHCOf6y&fOPXL3,do2'l6PEN YVln.U;7EjqS9Kߥ &HoA NDF@}KKZ TuxmR9VZPR {:?{\bhgo?=r hb ܔu3ו-͞+5D+PBȷO}~JH p4VNIJ?!T7j666*t@%+0O@_Z [x#۝!i wجg:vF/HS/]^"ZmU~XZ 0/q}$Ds˼tc^}8 [ X.(}K+LB~TAk6O_hj2jԓa'jMSY 71V|G nх, #DRlGG"s)|-珼N(nb#˚~_,a4KgOsjHԞ^Ps^uzw.-rկJ_cG FJܬ{ۻ&w!c~@J%B%1'4;O=eD 2n s-DN88A=n=+g@YcAoKFA%77\ӧϔ_dҋ bR99s:`z'$*0*1!wsr^FGY"[ƴ%~e7Ijgh㡴vkO#btLo:SD̓\M>N,bȘ>GBb>]!I+L$c:AkMN 7pB1@8eŘXH SLeE|B^iZ|lnQran2Ϋ)yaY6^AC? @7)eM7X(LW)dxA)#m7U/fyU$6PZ$椳s AXM͟QתDw1Ee}bn [6Q>%PTdA~ 5 F~Z "?`J>1%dyiX.`i/;`M\G߶*ZvyLB,Ǭ>Y_$O/d8٨9͎ūB̧0_}\Ϣ?`x6P{̃n :$db*t&A*HxXks4fYC,M+ LFs&(Ջ<\\)3 q %E-jʊ/Ffmi .m"ځ8/i']z0d;y3=:KoDI<:r/y?U=2 &,:7d/8XbAG*WDc}j@7H0EUe@nV^njiae2Fgsfpnm޸^lXĴXKn,#lca1~# ,h$6V127DQc/£=uqOxa,rp 0eJph$4O> pU*<Ý@#4^a9l% Z>]٫XnKVlNW]"Gm|(UCh#u6C|dVxǡ+z`|hXw#(៷R}Ժ`O@O`D䵇Wk q'Î( E`uEݏiȁ@v:fՋkDw $N|Il0˼k15'&\9Y:M+ފݕg&޶cKbo1B@ѩprDx#y1v 9*"_ˆBQU6AwO q%=DH嬯ޠrI %Ts>Xp]-k;#BȖMn@[.6<Z?bx"E~H"fk|2<~26On6ҭqp֓Y٨'2Nq۹`@niRݸ+xV3FVu~tw6&c l 7Oں\hB.!l}Ql0leh%?8ˬ!, 亠o(kUꧠgF w ^yYUxjhv0ԫ'`iIMt $m_CS^ϝ^WLu?Wd~nՒvʊmcdzWs?s@wraoTrwsۥ;A6, P7P1߱kEAm?jMo=Ω%ac*G{7˚ 郤u?Nls}Zmz޺Fo]@|60EP84{aK4AvԻm>p=OAmЄ_ W(Eq4 3=0Ihȟ⩶ ˢHiB}&my㛄0F%?X.6I7\Ȗkjrf.d- ZGAf]k8f{0JCN-]gBzq\"z~]mOM|knLcFHePozG2'u= 3ЭE1 )_u˳~ xR31-?_zC_fk)A?1 ܊_"FeWrdR:B6\ɛGm $7=ݿ c}8kJqx"+gъts7/zAl Q vÖZ_ ;{Ƹ?džrdnvqB׶`^iASUԼN(*k0L?.W2G"xkȍmјw}M}󅲖ei6s <𥳐#~KNf*%uL.dBg%̛#GһޛK&`쾆+Se3cVj'*p/ bl­$&KSW>\ń0_0gS=̑x/_''|խVm CMivgO /dJ\#FL9E85sQ=;IA5H;6p`i"c+<J董=Wg|P}艤|j@݆vG+vNrŔ᭖u6l1B Z8Gp3Beju^Lp> _>IQ{χ;GɞYޓmk:لkn8+6c Eh'B} ;@uT,ϩE>dMQ7PR8kƴQ^ڛxg/@;m^ 1i}U)|mp8t11xz B\Jo]XR+']׆mWs`W$ Teٛᢎf%@#@$jpՔ_d>4c|r+(a<jܞlϧޠݎԢEԼz^DJ~R3m<ʱˁmΜޘz: uvpzϨzVlu1.ngDzN@o >$*v aV TG 6WL_wjN`.\ϣ7nm!_:[Pa9˹菢M`$:WH팛ky@>!X['sHi?V6/>|$4 J V$VVf*@zf*pRhuJu/mt2SW?S)34Ql"v\z|oBM)#Ni3`A0 D,B?GƝ\7z{kd'^ӧ%|oѮrF4`I 3m#޴f=>=[ŜܹSwˑ1b b G1nf`Еixt˴޾y/R)HUq.P3+\_(+Xt{ۚTPdռ'P> ") ,C2o HŗhLiHA$\`Œy=(l`3n#L ¨9xvwCNmgSkЦ6辡Ej'Aqi,A,sW#d[d\mW6y-ς|a3V/zy6G_h/6P9N_Oi$0)iT=hv K `?3ƿE)d4P>;{⊄:.>d[뱲^-PK==٠K6 *`sUpV,ɃQIʟSs sK>R}h1.2PG…L]{NBw[( iFf(bۢ}d8NFQ'3Ž;t0fJVOo 늋uAş\Kj4#R0+q;mYq]9RZYF,|W$ړ2!5>$X[!kabN.3F)*[m&j{NIUveseMz][,1oo5_ 3ҁ"CwXhCۢgCZG `Rwy gE|f/r #Z(wOVl ڐ:dfus8XZlHOr[5#^]G3=%`LаG/uWK+] Cu᠋UvC1?Y6Cjx Mf5US:G$_H [Kn -qtj&!|_cfyIel'xǓCID9SԌfҁ\Mn]uvaDZ=4|ΰK۩cg>jCHy#T݀UTƣ;\jla.ytAY[YM_J,8`GfN }y%V^ f%j_} wEl [` `NSG׺¹Td c =zIf޵7ˁ&6]LkN'pj /(CZY][9U+!AMce4 $SדER6zԶċ!Mv)" >/\=zM 1JA=e=,Nw߻RQQ1#۠9$nMtũ8$˧)1ɀG=M.PG{I6RXۋ><}WćJMga1)?#lT/.|Xj蜌ྋW>26 WtY$9à?5I!$B:x"A1 ܳF]@)UÙlqc͖knV}C딆E M}+ l0][!;/OIYXn4'@jAz474< ֥5bI& ݏhȿ&tB>οA9˜Q jqzO t:G/\v+paj|5&Jscq%j}|M 7*o] k blqeU<}1}Yfc|%,]&;b57E݂/9j:@L0$Vw##w5R#RN&΂Q;ڰQhs/ I!BcԚE./''T+(}j.*z8V2ijgFCZP~`*䞚 g3&`0;~"{c u{ |ˌ2:&D\(!ЋOyd23[[ƫs#nؘʇ=hym@|R2-"қ [&p6eq;jPӟY e%Co|$L>2 &F]LW0R-,Or6-3E[?ɉ ZYM ]ʸ/lҡ5 Tugɉܬp*{=J<;]’s/*]~VRݏeF=SXm{A'mb9b66˹{(jjO0޶, |dX̆gJ6~>.9KbaTdi*fDa:9}*ƈ=YRڜok2l} J7fEΑ3}I"DC@oĹϺ[LȖ'xGlX(UwGyh$4i"'6><^OYɛZ 3JQwm*⟈TB8^ӉLZ^}s8aל\ڌKz/K˚PD Hq"#:;ZkCAX>p w1yhH}>Pnh܆7.^%j:vS ̅7 \ @۹sa:nR`tVZs0M C0sQR.*˅(Pٛ1:/c083L:Gv E&Mϯz'wnyBB8JS@uXLۜ%vDױ\N:>bijPU:3Jns.Y&@g cy]`"1{trp=d:+OxDD%aHuqFS;Tsگ̢v?R%Ԋjl$zo0-yJLg604X`y<]LUaT]? kvd^{5O!$CcwSZ_ƥcDNFm,,9}L1"_W GWHZ~Ћ"7Z m'KZҦHhwםŶ<*'[jҜXʓ6 ȣo&s:eSHFddbȋr`:4*.) ~sP*U'&Vo~jU*jfE$Y: S)GtybD=|@.ە\F# A[zD%&JpTxL6jtSLU @ Xm[lt^k8Cv%c`ЮBa=\8;9"AыX#/ZYnqT>CB:\mo/Zt,Opz^!/K4'Z#CL$}tKXX5iͬƪb0ej(W/8jnyO[֑E*n4/!=me  ‘f-]X4Oŋe<:MWF"' J'ҺCQ=EaXFåHT=9_.Tsm:x,/z<=C'E pv,NT[ ^]]Wf HZ14sۥ{׉mfQ,:3n 0X21?H y1 灌"1bn沸;ʯz-YF\q 2t]w5"2,ޯ+@I2MP f>EVX,( N#2!%rKF~9@BLXS=6p_)b˂9a`̳1?+ٌ+Fk$tE.:9ٽ@@0]5֔e:N̰y rʬ$,i3ʩioI'"H?. S,o#a#CE t4 b;IޞM%][{_^SB5]s*4r[?%{_Ja¨iv9R@A1B6cN~S+lp;q+ fh/1耐BsaMd儆^_3hvw.N ەGH:*3<4'ޮ֬>H G[5B=iѭ{ԻU/Q`ҹA&Q>J8c t]ji KEHp8$L6,+Y v[Y`Ҷ?~8ǖ:7]VD f74f3E[׆e7Y҆;_XVN3Peɣߦ >?ofDC6]~PTm`Ne]/Dor A;Na=T0>܂aj}xQ.aRS;G,JlaP$oS2k5y',) iwė›Pg-:)Ey])ז=昏PGT*wW0{5B=c3"@ UV]}scLTi[P}->3N9λt@FW9hw-14saLKcoDRH]W-~tg#VT]dD#@1ќ=?|^qAG'Ɣ1$p(-i4M$jH{\."АO1|(e0<~ɮRs[m:K9Χʌ8\A똖BG5~|se`Я0 L@uXi}^rӁ󜂘X/la@Eޭz|(Pn?[Z`nȦ搛ٔLk}B#`=77Kg$U'J;DϦU:rg{kUY<ԯ,N%j3ĺa "4SE|I&{'s·baѸ>/Z1)a;]?$!Qb7XO7W]=# )Mc߄I/DjDÀWAܹԸ d9S)c 4cܘL݇( 'c4UGpQ< >ΪF?we[X~}x8{Fs,Nfi#BuE]Csz¶irM-(?^sD!-2@ç&_uF41v~h,.8 cR4G@(٧o dv *e!\fY@\G.Ur49b:!3+fxMB7i]&W(^ FpW&t|_2FĤ7xxtA F"Pʒ-CHkMBRg( MQaYkKp aukj!4Ψ%Z d.^v,uwϥœUVmhD#F2Tc{ְi ux\)!ge76B)@؎ii4]x%˥-13~04@yϔtrŤA4mbq՟.bHjXfv[DҀP5Z1x "3W> 5 s^G$w|qb7 1th!ٴEYX$@v3mMGub1'X0- *N=K 8 >06y>?.|zUFCN@; 9Q2kTl~+5'Zm2ݢkx/ -DŨ =Ͳoi9Q(*_ ŒyGwA67pJ/jy[ dŌsgJZ?P#)ɳGsg u$>CE噞\JI2M+>`<*@uءMSJ| e/z W761_Vf;Ok5붼e,~A$EFOۘ M->Pa#6CDD,1+#H4ZJ4#%b "+g8QV1#Okk?iPi<ӻLk\PV@OЂﲁvT)3;GEhvvb0W_>E켕Z{yOmQ̑A>FW^#O7'`\/,1XedzV}F %aW{XkĂ*qUlex@r9)VpqvW4҈w`VUp=뿀 ~3 ?M؂(svv/ـ(|$S^{Cr 'z")A(`Olt;n i{a:ᙪ>r&C/5]ЦC,,0powkj3KEݗ\Ym_{8v5z,8qJe&bMQsٯ`N/_;a1`rJ ^4{e!85P!.1Az6B0nN)jgul`M[={Q+[v4#'\MQwP;&cύ`Ԟ?܋dt %')Uaj=4rɝXZŤg` ,rr ((,6Fמ\"/ɘo_Sv/x"2E.c~\])a3_/WŲ \Lh$PCKE5#L񠱷#7 ֦X[QN{]}_*o/xА2\-j 9TQFۙ+_h81 >(N H2RQ,&+?_,v"VPB\EcʂW極K8T6˜ˁjA_J_{/(̅ˍJwVt'U/#F\9#[?)EFO|ϔ뒔e5 m@Vr))/H1J\`n%wu2,v 1#mH)D"cMfEmv?XrH<1'tft=# ؼoC tߗB!}`JB}m'Q]ؘkp#XC1 vTnC1ڿչM{>Fs@GOqiKUM J.P-}Jsm7J$u'WW=7n7M]VH؜)G! d4nwdQ{MoPpy. }lMO\;L4y5yMlU;_&~Z)B(lEI8wYvUyWY=@&U3R]lFJ@DՃAs )bU9_^)P \Y wʭ5Óv!ph]8B DDyj%NaG0GT\?r ˝ BPKL"  cKr~ ~Zў ?+Vu5ϴW/qR= *G| yÙTI0~i5Dv#Kpm#dmfNf/3u'rfaEZ&ߨjOL2T8 G"zfn SK @U}pv^ M>֚W^ԑcd4x^aQ9 S?tȲh9ݡ<b0"@-cih^] e#Wp0Bʫy8#SM#[g?N̛k"{Ч\'OvsfL"ĭR?~#ݲ3vd%Xihd Cyݿ+Kmxg]\6}V J'<50^T_ G%IOxבwTi/[)q& fC)1QwSYD #{m}\ɭ\H5nb '|A ~+ 0 7ct…voRP-~\anLQd]Jу%e6BG4E\ F6E[&gf3첲:3g/39wQz8.LȫwEhSʤ*lS>S âمh$$ /hZ,)uVyò<+7-[#3{x窴bbOgZ*BfitGSތK ȮТ&kHB+iSFx>4E2U&]o^M`엶9Ht?|7%I0̂06?|~j Q.b? TȀP30IjQdMτIR5nK=2~>BJ}i!ׂ7{%*mION,DxՌ7VYB~z(-\8h#y %9Zi!m,-rpa!2>[D;SU?_e:*<)_cKg={n;KН[l +K"]:dF"} *c&UEUP-U ¹0JkQSi1D&ޮyƐ(Z`oAJx;mYpcSnP+\?~kK#%@}R߻LATYk/'h1_⎰\2>eʄ+gLt:M~Wx0dXH D=d͟2tA3jtkq<3;4/oxbNڤ9>Lwd0X T:G,"lZ5Vx!R|V2lA/FM3ͤ˸c7\VqBkf0obu!T~OAqwj3oQ5O QV Xz/uokkɄК6xF@ihED=k{ Ѹe5ugjaA钩&*@s6 xv"q:x0]canqg{BhG YOkom/P7AB3K[*A35uDK6A ۿjJ XOCKܩ쓘)YV?EISR%$SNh CZ?\1ῆTt7wb:vhv&{z ZsÊqգ#̇Ťm\Nf6Jq%#9^CREHvgvbMȯ+e_.-WDu|HE$b01! # P |_Q6pMbacDBne*05{(Fym$52n &nk{F rgVt ~Αr0ZG`Ŏ?41t1m(Czys[a5̽&pޛ &cIj|8ѧU#%fXj6% "W0s͹4aGm@~A#3TqcF3޳]/LdLoTT &ѝPVU/ߓ-Q0I@&et6L8Ey<Vʻ$IhWEl*\pmSe)xi(=KyeEmo;uO(S5g@ WF"G&Ԙ+; n;sXD/{Q-3h?qZ> HJB<ՉxOLc&-/$;Nn-6ǂPȣqh >3G} Wn~f;i06 uxKbMlb§R7s-X%xWAJ6 ՀD}Y_I4ځq ,skP2plBDthEK0Ydͻ `¾eXgk. c 4 l9(!J}kYGFtܱPE~^Caеo ?RqRl$EZ5V$vk9ܮ)8^#X?4'_W3YݨmX.I>crC1D43ZRS0 N"槓{;?x:+t f=IeUץruiIE3"UBU DL#Xh{[Xv妴i#c0d&7QePֆo 6TJY1Kj[\t*d=㏋w6*蠹tOHړ5}^mxAUc+ W[whd2fWcϟ;쓈oq2t$&t5)7^_A"(JᰍR?բbҭ7IoqǴ"T u jeqAOvT(.MHj-6pYCߙA]B,y'ABp x^\q2/~ -u8ajd&,-Oƌ#EUhR 0G#=mIq'#t+!de^8¨|4C|x`oQŸZk:o]Of6pCy&XZ e" &A.?L@eRq܎fm>po )-0$c^aP;ʡ?ZWm=Ѡ\Ur|l$' yuvJ~GZKk,]Z9"o3J4E6v]B훔b3͚!#>g7̬,XE?yc ]W^:&t EYz9 JM6l$-i ptjbA{ֳ/ |{=xkD>~A;d;X=lq+ұk7k.Dv0䏲\qhi X2Y{ LVʮ@jaVs_i\dFrzGF& (8@p늞<~߭uWl=T TZ2܋3^=2bV<{)^P/|S`rfHWNj^utϩaV!M A9R/)J)kZF!T-"#nFC)gV@̘JeO#&-Ʈ &z21;93(>\-jzVbR ~M WMrO͗_VS,[8uYÔ_ lj?#?qH jKhFDM)QcQ"kڌ?{aonڮ}eYZԼosފCHsM9(BI$m Z7w"a71NԱ 5, U&c=˘|[O6PYרm=N5=@Y'r !eG!crtAK/^أc=ɹl9cjW DIi^CwXMv2b3č@b=8> cNOou\#.DX:$9зA]e'- ƒzOΝSmNFu8 ȧ>al>ta;9ul]$0#nyEƍGeD4JgS ĖW}KceKs@l <;iv{"7)Y+ HnZ kXWx*(N1ޖ H(-em27z 94jA\C=ݩӐ0pHlzfLPL+8خ !&@1سkCC7rZ53Ga߃ŶE᭚O欷;A\7< hg<.U?rN]g[RqTyzX׹]@HRaths x+:8e8e;_`hlB_ҋ%A~LaiBFpW1oqb>"!'Im9A$iA :qg.5{1!nx{>ţXԡ宋'|ra'ǝIG(se;Q!~òO)U?uT h1C(H3%UN%,ջF2s2 j;9 GDUh*' ,S/&x <Jܶ#)0Ngi(8QWn5Ph\BzDZIUܥK]9d+[f8QJ J^x§pd,\u~SmL{S S|MJب3y#~|X8]ΐ%"StXkI?\20}i{L~mM)=ڴeRdB ҅@ByfLu2(VRpB GQO5DGҍӣLC4~HXW܆!27kG 3}DkLȺ6wUe520ifo۩sȆ'Lc# k@?P>b7t7Ce`ߕp5OzX/V ٺ*SHYޙ͂r.R9+7\wʢ= uBIO$bGJo MϕBbdnЊ$ը[FLoṉ$lv4cXpls_{A?4'Z~;u O nF z~X( D$`ճ&B ? ][X\|7achaܦi}\_ԂX{OlCwqҮ(=1yB_dߑ=01,*mPU= Qim@◥c .GGzmǎ}-N'7 ڭ8#ʠHU)y ]Y:(MlƗr\O?aYŶvW oq6EF ^~!fFG=\H;V=zs]}_|흃2I=ZJni@w8Lc롱)B$Z u]]?Wɴ|p&tvy$W:$΂QUCa\g1Y 3x*YE{K=> RE¥VDētB\։_2#㈙п+YJO ,wpݮG027:3qI:޿]FHp*4ZBVP6AL \|,J1ر*ʝ K3޷3]oيj_C˩W8~ h+!yYmh&,%P--3v:_, u*l؀P}1 ڥ./ҩ֮8o1r%[rma@NL .iKxˁ0>'CҮw#]  {jz@ڇqD5IFύ}bZ?7&Fk5ϜziP Dhc!*/DQkj%dKUx_IVS 1y<,3׍}͘;3c;;l<.0pXJq;0Qwc6(:yFUDB6{I zs3<}7͉lgqʸăC^0 B%7Ak-0RXr +W OS0ѐûԈa+ =TkڟّkNe&yV @ESKFb䙙uج˒<>bCK"B=ူH^l=$JZl6!ٞ:ؽfJw?~'`88`srXu TᎾM" g^JF<30O'H5I}}.I*FTCBdMkPi;Q^m{򅝮Z%Kq~o f[z-k_w*M#-B[/ B97Hi8Hp GW$ӌOcɘ|< QNEq$wnǫ%i[x\2rL&ұaOAU%)^EwEx^QFuNQV +9vK/ӭ3iHO&> \Hg`cB He!Cq=|U5؋neyy _4UO Kro># la:E_vp3jRyaPevW[&*k5u>M:r۸K3O 4U4|U(x'RV3iIhmB2xdELC ެvF=Dch4 NwH,99j9U [ާ/SRUU&Xhy{\P]t咻#5h2^HD4\܀-a7QMVrxTW>2-[Y'hȺmd**!Udpu젎_̎%GLNY\]$,4}9?z9(!K̤1w*/݅פ5TQLOGōH]eptra*h R} {OmAP,weW̅TS2`yܭBDԵctңI%8y0z޶(jЃL٫Ç%ޑ)"{u #s}Kٵh17 >i+Kyx[lts]'dNYtuPu=nggHJh`aws%aWr~ WU{";KA,&Fs9!)rά,E}ҳe+=OazEQy rZbѼ7}')dzGb:f8%X*|`Xy$Cnݤš{5ifGqu8`I5PRN®[.W7|>@O%L,1M9#&DyK'4 ./_jO2pS)>(X{i{NG+ _'cry|e74h;'u3.E|1 rNw!F-?ڬӯ=`#ttҙ1pa4Cp;7Uui2pT UvI|;n>n:E0Yd Uf%ͷd%)(֘)p'`CCھ ^#J&q fO-o"\N+8G]+Ԓh$З8t;@_P`˽]DKWᎺaU02x^Ԭ@0@V+d)= as *g"_8ǙtZ緕Qn$TB9k8?7[FJY6Rf)f>#Ԓi}Q%!D>H @,ck d֫{`-Vdu[YsyO->O,LtMZ3Ϣ 䲷am'D6=xqzi=Ш ezYoݼ"PV-ɼUʼ2oh _j.RCE1&-L[\ٻ98#:&NʋtDΌ*40Sޭ '?֦ t}n4oYš"e'isifAv>9^0ʍ[~齀I3R Ώ2bߟ|2nܐ_ZH;j3 ?|D`H[y>gu^K&CeP ߱4d=I.O1Luiu9Q57 QQn߁`TsaYʐɓq^E30beH`ŗ ѝ]I0oy,9]0LdU"QדJrRwwKfEޙt|$iS*1@ =C;SݼA|} %] ng?K#/97)({T, )Ei>rAކf\pǛ>HN%/Ma7އ%3׹lA$ A" xHt 6{K.zBv&&L=USM!'޲tF}7Zl0̸9I| (ً]p/@y= C$ p#:)'iS?H6OQGDC2p9gsM6sqN&@".SR~5Ȯ?5X[~Z~CXy2kCX(ΒX?Z,3HԞZN$K $jE}Fb;.i,m݊fpS ;Acno&hRV}'}萙Wg^DͰtƍ@e$A@TI7|%d[r߈;.2ۈ|L,4Bf$Irz-v!mA OCj.+ZVe('c4WTLhgaWvx={I*[ $\nuѾLd4qauu/gA,KYl\xU\A`]dmu(eNG1kNUZlxuÒσ~Wѿsw(˭ _D٩I9#xj-IvjrdNN6ErN#JݑAe; Al?) HEIWvL\^ 0>$8QfޡI`kYߣHjG X(gotgJipQ ilŠ?Y`xׇق.EXU=4OPT`^0wa4{xLR|qz'-b6J-ΑV1<#:@xit)=v1p_ ĩ42lOj4ߎ=FU9<1ۘ;g_OweW=0E2be1*qLQv2(- Ϊi{Pap{#~8mԲ4\fD|FڕO];\tGb/8)g ! \Tm7 6ҫ67uA ib@<)T:,jЈ>}-G3e.ѯH7{ _}ɓw*x1AOvم h;V*wlB7LSI>kv¥K3zVF"Tpvmz^A3]4XEȆCf3Id$;tinLC< *_"bl> NGj G^7~FЅ.ia2+/6d5g{ʼRlwcaC*^Ս! nQ䗦j";4|?5HĆ~FSPqT)@K0˂k-_<>r+K- ODa ̰ ի+s4`cĻæӟ'Dg Y?QT\%gztFev9u]Il #Qv]L=[B\!o/~PHJ`w 8/4?Bf4}mKFX÷(|ŅH uZ.-6b·wOHG ':ѵgA+tł'ٍC ^5J8%x A `]" ͧq7)Ks`B A Se;ig @ͻ>Au$mO6H#h y0Ń('|--550zt+RY !C(w=eDSH$BER ~7&B>%rR`?eNʐ8+%Bi@.s&}.3o7Gsqh[&[2m1,rBt^E;9 !u!ـjofK ̔7?aCVxо9䪸A`q% uŤ9eSvN ̳_هtu v8P (!Cӆ|d{$Hܕ 7b/ u'L3oMbd<}rnA'yAh{ Slݤ?[ty԰~ƶu#kV"'!s=U-H+i N#Fl֣幫.y|7<Dž|qTLR)F6zZy˱Sa1ǰBF=t=[gO1"q" YQn$,0bM P=DӊHa׎p[DfLY#bDA]ԓ}kr\lRj+>G=9֙Kt*ۢ(/†?#Э- /h $̱-z~woB<@ֺTηVN)̺ck/( `ڝoճlf ?Vm7OoBSۅ@\b8=m{yAt%g(MUpMDr~ZB?` s&pK^ʎ,i'ZI}XԌڼ4/Kٽ@Q/S>FOvQ  r/]TH @E LfgiJu;fpp'=B26a$ob#^g4 ʅ*C 1 9}ɇ~m[|X4no0 u_ u=^k7śzaڮ4ᒺ9fn)X}̸͆ʟ=1%vU!7egI,\)^WC4n7*E4ʕ~2\Th`*Hc 0n;Wo47?GIńjym]Mڤ oDZ" #{E>7Se=՟Npzdm((ќFaj6G?2ى l'۠k)k6A 6w(Ou>a{9q=)X>^GPSh(29z[WMdlc@-_||ޣKst{[v@."TͤF%N?/ dDu h.'1Xw\AxDhdRyEWXYq,&ht<ĐE> EazdboMF0%8w; Y~TXj^&\_ޚp<=jҥ?SSSbv' Xi01'NW.mުJheRl*Dn[F f6Sp!La?Y|HZ#mG2@dZٮq/CF)=2Mr/sNS!GKTgɏo "L^'Gα,BRvpT]1gmQvn[x$a3sH\Q8ek4c+gߜje:X,LܐS~' u#~ p0⑁_nJu.=׿<|{L*r.c&-Feqtѹmo\)aw~y؄JѨjC(b $Uq\VްCkb0'![@z!,exڎnF݉Upؼ@^:mS9{r";ҟd77|盔:Jcқ.V Z|e S/ޏ=rU >B11|ޞ-<^}igWt>ۗz<y:c`L0m-rMߦwц_FLybHٞg @ʙX"Ȭm1e'OִWe\~/DD+F`$GeBF>Oy{1Q6/.q#6-;%n}(F[$I;J̾+$`R$Æu^uzp5.`PI0QClLĈגsMs-:B8lp':9df`۹ўQb1k24+|AqV+ P\9Z@)()p$_[jv32֝=4j?ZԳ#H ݑsp0|r 35D'6{^f@A1 g+5f@;fmtSz~&0m]Q<4rA[؍߹J=+$iM!ѡ)P6Be/I>/0#V?j+Ǽs(VΊP˜n*I,jml d=Q4 Euhle48!.YFSYav'9Y2HΉutFɐ"bN17w+Oꑛ>EY-W'"WGAňTTU'JRExJlh $5Kw% \bk|08CAö'.BK~ L Ob>͖&,CįAmrfp_Y}!P=)qç&9M%yoQpHMĄ0cK6gmdD*sp#KeܖO:@J- cA?0;G5)uB&8e/9?U+2KkaӅ@&7tօ-:nq3?̟~!ị̆E^k<|Ed;To B@m姈厝KY7̯/U&|ս̵dUseBsc˔GkţlI#OOQiIHzJ*A3~m*w~_0 gg*dxb?r٤|JC9hk6jx'sծ/.®@@uQeEPӄ`cc1]JރzRVDe68 NLtCfm DLs סzG|þx|Ns,U;T¥I9ȊfqVK<^hH$qfR_L ŏvNMSoVc^_Tsʤ25Syp]}ƷƵo0`HAҿ0t;6#M6·LF{!TbGq NvFwٿnYє(c9IrIhiVE@-kYb$G/e&mCF}8Ap@aS[!˩gB FqbnjQDxrވ7+sALe ĵf[p \`BD{j ,7% J|2B:L;˛LeSrVB_S^zPN;/NiyQ@*2rXvMG;~*ػubc6Dq ٕ4O^X-\z-36$ǒ\oMr'-9J OGu"VQ6f;f![ F"T\@dV2}q~,06EZ}60pxc7g}EtSY;8U*Lˉcë%6~ ,QpU[O'Phx) 4;,V"?MJELE7$UzU6eZո&Iz!Zu(wCT] 㱼nc! j*嵇F#0cةY娝(?W}6)b%\6qtÒ yV=]Q^oo ]K]1t]^NYg~1 'qL0eA_BHYZEg9+RwJ|Wn:!AXۀ$@#Ty)=iFR&="WOw엉@UEn('U(~m;zSmnzWWhW[LdZh*:;"'6}1meyR3{_DBYCr ފ:aS"B6tG|΍- ^Y']yzbթ#㖗S䅣ySDN LD>}=!Ov8f A\ہU{KQ1aaW[^&GW*{ T-|xHM,5;Ve~.(mσxr!&30?;ILGOAxKIm,#YB/+I$ ؽ>/냲ViS>? p0;0@-޻F$/v ̎\hY~1X vg 7(j ut:gx֏!o-3QZ\ʂp֤E";= ZlJ$zyR Ma{heorLIو =680nudp:^c]N8$=M1ɮ8j0 H: VgOҹJPP`q9Xht}X1`+0"eBTB֒fN?4* T"0T EםKrƎ)_Y Lx%a] o!a%.Dogg%ߨ2InaSOy@$klj\clXzzqˬPSD"6~A#1 8$,q.{I\;\-`٥xx*! u Kt&BHDqaaAod@;0f6J9`si 8O!>U6Ļx0Jv s]Zv2t~Sq!'@~sFnO|qES5 )z.dnaooo[(Np]̔u݉JW/UMnd]q/zY n5qQt6t ]ޛ.u)`f|&:oO160XK@{}d}jc4k wLyli4>] u{53* h[mh8†!pr;H PT<qp!)rMH=ZvƕRJ}qOcncPFӫ PR䎡Gwsĸp:Hh G&:XFxbR)q0\-L~ E>LS$?J|I8lBkˢ1DQxwXOIÄbXw͜l3Es_@`4eRng3M X2u-9ꍴ\38L-X\&J8)J))jčbl^'&{q e5=>bX2,%^FpSg೶dLP΂ⴡ2o b4{H}m :D&<ӂ3o"@Rn_q6:{*gܝ"ѰG߳AEUH"&/`yg.qA^tfo,X_E|u('N-29@N)2VXZr]MU4ukLj.dhا0qͽ\g4W ,_v$+{)Y*;0zwSW σSqC9s4&V:$3@(_ 48"/󰻻 :h/lg@`505.䶎cZF"}cp!3tOuߋk<EEȷk\AP}E?ݥ]6,~H1 PM\ z*VaitnݟĂo+D* ΤAt[m6{Ա6qzk\@ a~/+fE.\b jdb97fc*לP"`kqz9H#ɽrh`?MHBua4;#lŨV>8A +OSo˖g,kuNse)Wvno xE۫w6u54}V,i ź}FEiuH4kM-qn$$>da$d~Ei CX-&-^1J:xn.Arͅ:>?h^_sPwhC2`4S>ޡ#l)3Jpє$e HF ً~ tǭ<iOb"ځ(^;՘VWF^{UT8x`L Y( ۷qN,·ڏrǓ :䪮χEtś2a+d:Q7LˮOjUtPz= RT9lJ֐ B GDcV$5MJ,4@9_2 QdPY,0_ i3R%r(DWqAʶF9 UgMӚ1 K"k':JujLЏC(W>'ar٣N;`<j-[!RΣc4@?ay˝XTHefW8@ϕ9SjcV%7d=v(t8? L~D[Q'^Y gI6%dm?uJ~=eo$'6t ]HJYYc3t6I])]%ԮέN4qGPYQVmt?y\N2No|'Ο"IiH|8Wr!`ϡGպ׾6P(^8;BdZ 'i3fqZH[|NX5ODYBnX~.9wVfyVE'.T )u8pO>t`뜂]z?d >K9V%b0 H-6ַb(Cڃ8!1j|N_jCJeotT P7)5%XAFs_Z!X|dI3’Ȩ%bb3O%4(4W dp~_tF|pq0!(WؤҽV;}U1Wq2 XtUwݜl%}4j98 Q@iBE2C~k(֬-!;U@AT;;O3㱹Y4VcpUI(4)ΪDn-1L%J;iʓLqRnUwK>a'n "n sJr>o;2Mgeb/YFhM@+mG_qMK8::(ya]]l8(u ZK8hy~ʻ)+X1h`rպN'֪X8=R^iu|U흇PW3lᦣ#H7VѤ^LD?C >:7ݬZnT^QO sT-464힁g^&.k y %c2le@F2 @ڎsr c0FQ|*xgC~rC'el"w7fd]sU#'PQv*'`yWF~7\aBaHxmz"Er*ι\I{Wg}2ϫ:\LAVXTvґL^ЩAQͫrFNQc2I|2A.u95`}8@'xt{?o?>8&/h%*קq*<> )u? ڗ}GP |æM;uDZ,SUk-;(cshWF<7 fs^JY_@>HjjH^7ӁL>nGf wMP;ɞXKL84`4>ʳ$Ner3&|5bDq%~8TѶlC ~2iq'_q9DVPMs/#*. ``wJl,EÐFٸF21PGS[bXbijvD] :^fI&s!XU*P;Bj67* ~\ں&S'`(IܖP~(Y;S$_)ffHX.ze2qbUc@^8s(fbJKI 6-b^_6 6E}T/^׫s"W3WipS7qX= Sg0q/  Rȫ.?(MR4'L޳='(߀ qhJ*<2x{hp `SL"C@J[FŁCia3kې|)w䬜ժ`КnH1'١ n% ;.a䬥=DBf"d/%L%" kQ +m#mTb':b8!GY2ҡ&Q^Y3. X&O<*JNK.bߌ4Q94<.wg~*Df4y-~)R6wMLС5&YҦo H#Ecbk=$!Ӗ fq6 bćv7I,FTaQϩuT*_w$@q$=YA\/ B=sXKvʧt˻O$Bq$!7J5bя923&bG [ZZ0""C{;L{4}Gk; ԇlvͤQ+ڕDl%dxjDJHQi|oYFi#sDR(&'/TA-串 lZrpqk/39AGD&ͦ1V8R,z}8Ň&4Q&y|c3ɱlƑZk\ZFfOP(gIS9nv.=󂆆hgBʷm@c =yVⅇpVF6R6Vf]rk/~7ag#sw. B;S a% [cn˺E-+ז׍ꩲ6!CGY{O FV=J6j<ܨ7YR# =~۶hnd^QGj\ʎH4dž%A1T~ e6"Keb˴I1 (K&:)O<)kH/`jfzw+-$)IҫIje˺ COw'm!+k~%~R~<~tЛAe~05~EA9X^e{̮9)VK╰Za6a֡*IjC\cKB;{z، ?~GjrO{F`1?)=l'Ԇ$vm0Vs,˒^Gj򿛶! co$6`:/X2~nwh:<R5YŚ!!uAG1 Z19FqbP7(WUuUg? @^fip\B%x;I+Uznr $لK&&Tȼ  ɪkX DqJ (C ?rH<(h8 >DaEK9Q~٧3n>MTSޢ~ ݌3!Cri`w|DZޏeoND~)@ϴo@nRK&=!J :KFb e-6S a1%8=# |<[uoDC>(U1?1u<)ޢDJgP}WFR]J-74ªX0 Hv+Q=I%8Ė`H`r#7&~a PX] c{{xWد9\嶡_<_^OҨƈ0GDE2], U1)"h&c%PzQ]X(`jF#Jo3*v{ӳl*6Hjڋ YI2' 4J۳ᥥܖ/oԴĎLk_3RQ:aN8-Jk* (^#vtӓQ ןX"O#=^l8v)OE؋6gT_L!]vmYsZm@cPOzeE;REi $ڭh[?$N*'Ri&3:v5Q4`FS-GT9՟ZK,ӷ%&W^(qM8!6 + :Gj"̘CnK'R]zl9E]R6,) Ey/E"V^~9B m}A3ei.A5ag |0ePO.lh<,u:Gb@<!_n'^{"G#HCh V\[%1ߪdPt9M̑lmLsuȢℚ6*tKX?#6NiiUP%EjL XЪ Uo܋B1Φ( #4i\C|T'WzB19XY7jXqț=D{U(@v!}k{On<ӉfA F$e@qz'ƈ<X/)([zF'@[i3aSi|dB< ]Y&jG5>(H\]] ۺoӺJ/p#`p,@ ±ߦ<*60tbg[:%Q `'{ 4V]8J*J|*,t=D W 55NA|\Y".srteF޸E9x,G!.}F<5B"mdag.|dΉ 8w-S%!ƞ-5I@v yXǁ`uiqWab: pˤ7z{+>6Aݫ*}]A.H%⯳J>1(G(a>@G7q Oxn6(Y\ٙO\ &Suj֨Se¸qUvEYp iHݾ%@7rp J׮'ٰkAa|A6r{cMEfG=Bv0NvIow$Rރ3 rcn~!`+稊ov0o{$A&׸8ܰ:_& v,0$2jȹ\zu_sWPG?g,=:4/$:LZ-9sHy6ʘL_  M2^oC\>zWS+zKt̆-k' ˧Nf1Qo 2o2IxvLY0pc/RB]% s|N]iۢ+o }Zj͙`p9'wHB탩uvX"mR/hUU}) pu8Q=8$w{(z}YVĸNT /XS[ounuv)S5 IJHC95鏬 JaۓUZ p/U%0_p*LR`:s1N |(?I8ER' x  Aev+~%́X;jL"_2]Gݞi @TL.JguAC;D^ӛD7t)Y756Y SgT*$U5шmXRA5xh^*xg&Kuk7 &a).}eG[3~ɳCgG৪_"F.[3W^POeMjiwVmTa(QICν UVY )sـښnp>ܨ&J$7u] \q|>7#ӸFB!"w#2hzB`[YoNzO'<&j$]Tp1Vp -v\ý@V]jӎ|v-hy_p/?ߓJ1ZkD$MdIt"q.cJG}Q^t:ܻ=TTA*žy|j#F/`(cqi6 ,,ߴ- N/&Ù-qG^Sy+dQ/'߳@3'$ '2h3) *H6+'U:?EJb՝I@.Y:FJkКZ=jӗe?Ǹ˴si$6ސb':KT].?X/Ղ(vLMbΊ}A?VY3'Pqp԰_$%&„q $CVka s_7ڿ'ɕGjiSR'-gzeQs$#- o[I`I[>#E苴kK'bhRb]:e8أt"p8s$V$ Dly(%;KZ~ڙ.)7HlŸd7uU.њ9 pbk 6յFӢ'l1itWlIrlJ>Y풗!k7Ǹ}V6N@Qf[{5%>D!dZ|Z"=Hj[Ε;|x3GPw%OHz!KNVӊ7({R?f2~EbZ֒ D),zdW7^˄dw@{ [@>H3['O?:܎#{+t Hx8UPEIh^{$=[A Z)L1x*d tG}Q7;;2#xjmF}\x R'uьOȇ5~V\pS"t`gCE\#&4zӢ +vQ@q/{8)|ot{lkdXVW6 R#*L[F1hh#3" Gէzpoqw;R~b/bƷ-zX]z,z%yCM8RBnh]Om+{&(8k򭎇\fS9Ɵnu)܏zf=dב7¿ZQ|sY&q30#W!6|j7;a*iD9CP?Q77;FԹsm$$쵉$%vUXY<wZb"xq(&˻!P`f29)3yɑ^_I@)mږatz#fǿc*Eںv?է*OMYJ=D63㎦#!o%_FAe(7t (!< {kF @7 t"Um+X!oE;JR,.{^OعJ`bCa{/bo-2z|A*[h͓#VHYb E= G>(*ϣ =3}il; b?vÂC6LS/ ֜e->{Ԃ;7&2PJ#3/-jnf V3y3;fRCFG[v"AKBςU]rO/Ԫ5s@0)7[.þr#ط$oLBXt`KmnX!_b9zب9 Y%`AI [dLJ/N#( K=7Bol!c'Dm׹=h@nx[˗eWRͬz[,DK 9=vX ;&0ځmPUGKX5gwA/:-yuSb>)wUG*ɘ /dfL_t(HB7>[B2ˉTJۿqd)Y˧3pD_dz?W&qz0EPԗmNـ@1e]z(ĺerx+D'[]=ʈVӚ{u ֬䐜GT76Z1Gz<rJjJ7L\SυGWyCac y.3?I\hpf=)Kv(~Mѵ'LU 9` Uŗllf8@@wVxвKx[t{#IQ1Vگmiqr}*{Q[@(4nm|fZ^ @FɝՒe-ހz Vo AWzFӫ0S*;h#"C{fV^ӳ9<o =Lo; FTN%G8B()ojHh2x<Njs죜v@H gbnh2GDl+)yUY~ ν Kf30:1N0gIw%yx?MxC^##`sM''uaAQ.F8 |lh%vP00TXj x/!Mx ;2{b#fҝ8hƥof _ pׇA}r^Q F5r̫lDF,3a)zf]p@?qi{杛JpT((7c P.qL bjgh[~YRKy/Gcs{x%!o?9!@!  Ej-"Y<[~V~9 wm)_Wٴ:O:EefꆌOgL ޔ% #ah*h#03M`WUL~wojy9程%BX"O&HB\WB&0v+cnV<;evDL5Np n%P{Lz*p(o|hn|x)230"ڄW|1@Ǣ"&M łj9'9i8`Пs6H/$*Gi`uJS*3rLF_1^O"r@)rrH!XUYDaC W*v:`Tg/_nsK0E) goM]aQUsw*FUg4Ԅ> ~6oei芪ஏ}L^-uS,V1QR0i_qjg1SKwa~EC%TPxuUP\&DEw4AHz=:5Uj1RxIlœj|vϞm$t=Vp_ː*o,7D:b_S!>S@*1|mDF=XwP٨6BkFDDjM_^Xyc<>#v:V @bo0t,yQDsNn<?3ݗGQeDvԃlV?kχ }Q\yYuG[r?Y#g5Am~NvzR~nvz+σ ; fw6E rcEO@5e.ţ,6 ÝlT`2a uѝ_{w$+ªV ;ru^as{z+sSn PdGU/oYf^ۧȺJfڂ)1ly':m$ap UHNaQ(#{9{ }DT2z:1? %k9X.c)%AA[דo5M>"tNc35%3!.'[Fd!Խl0m=_I ej H2'd4hFb0Uɱbؼ>(`f!tdɩr3u0P+0dPhdqH0qs=Xg (,0'QGLu,h(c ˨SM?)& (2@נ jųFQq}@Bz[;3xC!'dϞs Ck9GuمIymzq2쬍oS==g$ Ϧ<,\Ċ6N&lIEN z;ЋCm|?h~o*,P'df14#xtѼ8ے} /广$ TBs כ/ޥ8?DZ hI/) C9+9˓w8 otniG~Hx:¾\6KcflF"P}(%! EJ>u^(qpoM#p <ΦuL9˚8Q~ Hh'$T} ~<78 C7r㝉 ;(V}m/-$QoU|h-q$y}PzbT88} J`XJ #L2:5>\l%fl5شZ(U p5PV 휔X:ǟwtTSQ ?ōG.$5n y 3C/[o6ފQ=KPlC kҤC☑T ;(m6| 'Ctӝp b`"j|X)HWs^%<7[&~UT5\s[D'e:Abg\oyS8؇߰=5}3m,x$>lچߡjzR,Y+,3,0[L(d!HQ rm5Y2$5‰xƾ,YwOZ<{NIJ&!?(?ɷdv4>(7}pMԾ ]g0_\{[&f(ce>Ҏ<6 )bd.0Yk!+z mh,Qz_*{W?@3+  =S-v1ȹt,$%߶XPamry%Mfw# bi5gHj>yeozAPooSxy Μ; o @$wJmTyI0 k&KyLꘑ.֜Q 3she=~h&UJÀJ\?_-nWht<g]N^sӸHF$J ",1~>m0[nĪ!|2ƕjc}#:o803?zߐ I {ɏ p)q#;9g-maKф ~'$ ?¶`/яul9Bt+ytrC= mt/xgbn%'@P OP~VRmtx>WuaL=t;%̩=8Z0=4s^5 6ejQd29_^@]'d-](hi%Z!Yp#nu⌅,C4= h؏JGsMYS+;XU97 %xje ТŸtڲUM19t 4::<ANQn'gu8j~=f3#TPbWkSݩ2#] (ۣ#}H7{ E$n;ݶ)rbzUx]x {G- k]I""5sj!䡹,%7PzMb_=t2qWE>-n,7t2}m> ^A o%948Mg6whIGSMpsy LlL4uiYٳUєiM׿8kY~a0o3MUT1lVic#ЋdlNaP-ёȪ%(6n*.nji|mR 'Dj1.ξ0 xgڦɛbIJ}8?AO N$.N6> ~ROoW"Qc.=3 d z&rKD$B6ۨ~b񎆱oiOJ΁[9WƥGj(],gOgGq͉@ ~Ayc9֡|2jXc+JY&&$hWP;5h{Nlv:V&L<,{3iKT*9B_q,cAYf~}- w: :$3눡 T}Jt hK(Xj7V=#k\jͷnH+ǟ8CK*?rP4|?HBwDyc;Z|D4{% ߤ97΃?|u%{lؠ\׫de ~`Z]bu-RyB QĔyc bqUM*f[[=H#[쵙%eJ2K&M e1E+t'ƱG?#F19]_c+*sA<'Wq% f; Ѭ~!AD,l\ bՖRZ.ˋ" }Naq=qܳT8^(t-UM] *-*F?%.?*ߚF:&nOT%Oa%k_4Z|W [^ :Xo H.$J#{y hAy60?ﲦ|~`dV죋\&bW: k.ی۬dX(׿ Z4|I-V If9G+)!%;4H R])U}dɟ*3z·]>GGE ]=E'Hyj',7݌qeq֔5r}ݍ×@BM` N>}3MHJq`Y^E DIWVo,ÛSBК S'ig ^zS( BX"/cH6~qy"0l/^~mI+:% Z,]ܩnޑGeH#}xN'؎W --wu!+_7'.c&JwE7lԲdJGP2*s z4\AÜBzsڗ9:4_&MM ^eg :g?%ufKՒֹd^090FTDnyDa94i`3:ʦG S~Jd<5*c} lclX_G `~1:tLQ}]K10@Y)v_+#TQ\qF.ߙ &6"[[xwhC@Ѩ'ѪF? D)oZ0+kwܹ2<ԷLxդ s8D솷R> Qi˞0Ap]u@P0pLx|&|SSk|? ;IԯB`6WE_b6vݞ25{Ji*i\E'{; WY}}u=-T\%.HA+wi:QdžziYM2D5&A\E߾h)&m%K=)\0*vGam_`)`!sxծQ9qv=gt"c[_AAOƸ372*+sE4DEjiTZ1R$qUPAL~OT=4ZB:ΚY8lEmFPtݣM}/Uj+("Cn;Tj~%SWu(ԺZ~tJH+ʨ+LYXyAԼωh+\a|\WX.>@]ee=Uxim3B"MjLW<#PJbOquRM42,غZ2kA׭7p vp5]T.O5 yb?$  +!hap[|$aPo=wޜՖ?[ 7wFӬK<%E)H+ܸGS-Ztxb@i@ܗeA!X@ꈝ/Kr !c2[L#*isl)k\x# {Za㭇s&_#2 1/V>`djH^%#A'Ek 7>i-D =þf~E9{q4IFtL"QBmt@<=^(ɢ({^G̕ jPl5 G\f"I8YfEЛ*pfZ< \\" 8#"5euo+,Ck"鞻dhYKkzO 0*z%>}j9&i[5\nr u&[aUL:0}vwK "UCDj!ם~痜~K|UE9E)6{e:B\u[g$@GaL1v!C2ƊP{U>Y[0ӼO\KFZ(loAmm4{3.3u&]^?@ iNsi+@>"xԶẛK7.箪Pr.|TX 3ڔHzrV/u%9"L mk=6ce.xSgf^8* Y<.c!F34fhAθe$MI/ijRx~<(`}|p):MQPh54To^ZV-Nk{DV_UtZ܈B,ue!;.䬾×j\ G-~1uJSґAGه܅LOH fV.'lqafGZ YO -*i1&k4ReL{$[.冶j<]{+IO##Qr'㘹UמĐQDSqw3aGT&;>[Q:_uEdPrV\ Re5E`LlE+7!&UcFqB%膅]MVz^Zخ*ڳ~A{9G*%`T~QD뤸,Qmuv.j|V<]ydP b<0+}H`j]q!GØZQUt4d!ޛFeY0{hXZbe62$-䳊3gKVhٕ0b*켈 nSTO1GƋ{c壏 l̐dYyd7_\aVr Ǟ@pl1Fr&9 7gIא;/Sy`5kwEIUB7r8* & mՕ{ODkLҴ$!+sd(DPٜТf[*')Oa ®;('9Tqfl S,sk8hĞvrݰ"ķßb0G<僶f2X% W~]fܰ$sKyEH]1UynJr/TEƷ>: E iK@垨% adf !TV%dDa/?jB$^5W lD™@/ knKVZ@v+ ǯ4pejGIok :>.nхpc\6MpY;AMF'nLSFwÔNtbS$2d#n$zt,  ˮ+AQ r`II8ZnEGOLyV*2"혝}5|8s{BRH+w d\"v:hs=aM0eg2|)&ㆆgp!3OSa'*ѱ!Rm'E\™Z8XB>F1c!$ ͭ).nRWr{7dIz"~l:;);iJ{ P7 &a8j'Ʉx>[%G +{Vq}btbsr: G~t$P#@*M$8:Il7<:(МG+lQ8]h"XJ~ rV#3:67 !9^g$0xJϢKt&`Vs8A5}UL%jQ/‘ei9(g)pngJ>\`hۭą%=vp F 6ْ5mo:˳E?i׹%,GI5F2NJvɫ%u+bFLפ( %̃uI;xnmhmWe'3){-BdzKI+u1=b9%H*~nǐ?A`svDw#jNdrZA3XTخ]旴QhY3zhOxǺӲ?;qԀҨK1z2ն@VMaPLW4s60*lIWHUZMW RD aPv)=}EkdGMT':}el0;חƱVFd_\#3MW&DN Oܮ>#@~f * 0'C2CkIK>ut躖eym O|)/CimɎv GĤUcgP%g,}5VR3 ol55D y`|-R6.A$!/qA&ky|چE/݀$AA7NCAzv'M͚X h쵟Ξ = jy8mL$Ii5&̝􍷧_YQK9: fsEp՜Ob 3B',P;sioynj:Fʠ0͎{8vf!m|) Q6V;OawVq變 gԂߙ~m 7>wY%˰2MͲ _?_~< á7GV *% 0rl&;g s()kT]".J;#_y޸-8'i3 CWAO<9L/!٢tNTn_i*q* !DnNm9[ DB 16ڸyFeYYJ`Ll*&z?rׇ'U.“w |JJѦ||M+8q u\VI.H VtP*f4]];U4IGJ lKQɒGwp"uE,a'x-?dxr}HX?O3ٜv\?dz |!}9:TJY<"S5Mmlh9JVg: 8ؑL9."mW논MraӒ&&S { #D{?&+ Mj3鯄DLBMl,Xr.MgոAMSfChuiR@2O'$W@tplZkHGyBS#ϓ.ę݅20U 1xGzкbƽS>:Di쭒 t&(=0;Y4AE|A{cw{V5FkXxZc 7'OGqc) nSVk]Ybtrpv]$ZF6h-T`ڠյN#MoFrl5?2+CY@u{4-x_ A+k_V鱩eo,o5q _N:)+kCOqmv3ۧ!Z=P .֍$ j*y3b>kԨjKGh بS+PB$OU{H4.^l5=+(ͨPyʱ%P.6^r`%|˛j2\ypB\U'ASn 50OP:gF@=ұ3;sfڱ`.46bA`< \1vp6L>p}pmdA ʎ/?Z쁞?@i5O("S.$Ubr4ƀIwB9[C3?^>LԶ}Pz/-> WOE}nݹ$`h ^5E hE4ݲ{@o{JCYSpۀ,m# o2LocdiJZpm61$0<|p^n?TxGAmj vbϤ+ñܘ/?%}ٱFƝIWՊAW.ݴEFc I$[bˁl"iXp^>'0n ;\ّ%*؄ylb~a x)8`+C7LGSCʂ +SʘS o~DZEF eUXi^٭ c?ؚ7_l=&Ո}Ar]ӔL|lPs+ \+3^~wȗ40#c+LͲ}D J-r{TGLҰr (!rq>4;yN~eL #օ<)-cﲅ? gd5*Vޜ!֭tk0 Fx`{F;XjN z\̐U&2RvkՆ 9?R͙6)&u~w]yen!wcXI/=X2*ycQ,/A'{d{ѵqĄ2'u/9n8NWOcਞ_b+ v(*NϷ'w6 x/fC{`Y"QWx^}p,j/&Ge'm`h4"6(Ͱy^:%Hebw^Fga~Ƣ2YT׈T_;5Ӭ̯y i qxM8J_w ^lk|z-M)d#Y$]Q.mRJɅmU!{0_X&4s18 vAm-i֥zges&;P<[tVsBȿK= i*U|4U8Ytj?k8B\xpR&@d>F>U/Vx=KFU)?+c j= gTI5.2Et:~U ) z%ckt@Z`m]ҚgQvKB{|ȼrg#"!nzUxuYhm9Ύ~X$1cP̙\g;vH͉[Q^%0:Ӈwv(g-Y;X5RUi<_i*F-o{[u&݀+]6sH\heQJ'(q-̗&B^Xȋ\U$,:յ&dށ䦾 1 %U-o[7Q3{ZG2 g.j ҡ|;'bbcWQ ;OlTpQ. W6E-_9R.=QiZP\H.|7K_ZBzϰ?o~9 \C)VNvŋfxʼUtbi٠hY^UaIzYIN@|1}]1wBJ ʎ7<6lЊHP| PLQ&UQZ8CE!d®~iW &2#qB1^j  W+IHy!^Ute7*f]ۖNZ@}RBX"dZBsmYn٪j;E-] S~/lF"M$\:P;Z eǪd}nc#{"!Y$Jp!*jQL5iбw_9"9,7"6Ғe8nu u^rʊ0o_貶))-lkhP`?>y|{ ׆Ȧ 攣CΝa`wH@y%܆%pih[uakѿ_ ̓X]kY_x[ 3bv/"\B6ouX8#vGl*J;_~EkXl4švrXB|MC ȥbKtL])%X8xoLD$ GL9vQlM>{6g(Se7YݱU>Xr,#$Ⱡ9UT`ƙ?. Kpbb),֪t2p 7I1+5ר>3UW1unD\p{ X$F[,مXlyVicyQwIO0cLsRx / 6T?F(ޢ)ƾ$c vʄ x=UqƳ~6 :  JCiBŠ}X)3j*KqOκE}t>lS_`T# %~?|Ô]9OԖttCQ0Jd^Ll-m'h Ycb#s_:c 4ecEW0ۻ >5R5z k&w`VBr~NzjT v0f" p$G̷l]{, ӕjoCVZTnr0FNߒ3@,j 4?]"Q\p<(,%}-t{ auɞ 6(9zuB,yZ3xQ iPtNdׄr3XEQa*s=Ph<̶rq/޶єA !+HsQdhV8^1TYR cQ*c,;K\UZBA=E`Hޞ ؐs׿2& { NJ 2]:Z,-GhCZ -`B\&:@P޲Cd,h+e9pՋ 1 Υ"+(#ze+5qF&݃/Z[JW[#>:d_zy?u/BG6iEP<9o߳E\P6_~O\2Ye^/ F!33f7B9QU^\|1D7{>À=(0.Gx(geL1Y/)9D A hJ!JѪ/ӟcmHGFjaV 4eX|;*,I8%U㮣q&PG1pik:vΐ}"-ׯ&g\W} E-< ]} @Tįvsij=;A$5 S| fJב"S6n@A "RQ pqg_( E -7m*OhF 9$8IZ/51̚:޸,E{?'_ #~*O0{9{/TGj^~^LpMVT"sLa`WQ: Iࡁfn+y@߶}ܫ⣉yY;lfוvPa־fεq-vs>: }$]γZVO %5A# t3NIAP9& y^ר@GkXK2f^/Y9k]!5FD$#M+C=(Y'q`=6ve6 an>{jh3E$}c7HE1\fPUi6oӜMNUP,ɋ4H)J .RAВy: Q)=ΈnɽM1ȗ1[{o1p2{hRx~s;2 ̱O8|&ʒm*@)֙;crf[P A GJA@Q"]@c (ySy؄)Wz2ދ̱Fv*ėnquE4$JsT9Eyo,JIGQica*n4>N[>l-:7u$bPv!/.t׼Yle<'*-ֳxƝkVvbo,RPOFVXW*k©3_Nq^sTu< &HWʺV 8]|) >"&^ږ^U{)1L9nRTiCD9GFuqרp-`@h4?ZY̫2L}WֱT v6;!VGhi1\Z4j8)mf{Fo-Ѱ48*Jaw|@J!EVfX^J^pz 1>[]fQ3˚id,=/ߠp 8Ho֡p\KS2m1Y!u7+ %lNQ6 ~0AdVw)Խp6V.8luK05{mAla YW(Wzbme:!!{);T&Q_|͐b@Άͬ*jr8կǃmIf֡-BpDD*NE-Ƃz_0Iy{}rj*Ra]1M c7Frt}/|* N'H3`f;bB=>qKZ3 R<%rV/; cinwN\ IWVmT;a?eQ3G35k$X<M6p;uK:Lz2a^1"#ژȰa]A7 ԅoO{%b ^$Vbוv TxqWE"H[ x@s& ߂,k 1D.o3JNCC~u'K`o 16 H;r>ɋ &]?Rjء'#$@ٟ@μ䵕;PẄ́g-ÛPƜ/Js0`)[mbM%E 2d/6|0dmP <P]$kDo3d[l1PrZ(\w :qʓ;ب070 \N&KXSɢci oyr XThɦɉޕ!ɏ\RնJ#gq?`l2YI: k'(9vWk^ w[?op/OLD g eĀ+ַw4*)tQ* N<Zڰ!_p?Ԙ|c"Q]`䵍 6?zVzX4c!քsX͝Ga-rڑYq%XFևHoX-~얪i_A.{݅I/W޹3*$$jL0t!PU߀3h˂|D\=*輱R6ЅwX͚ 碥[jIE*Mt*>":mB?^yRh,| !._6A[yW/c-&1ruA Ƌt{v l+ B<&xREVpr< |XG͇ڶH{xIU Ra: ؙN$c"@m&,lvɉ 8} KSKq2B(o&ɶ7b'4%\Z@1Ԥ9˟=Z#ц٥Յn '  B4U s fr C! sQrhA Ί;䜓b|LD#;g]bn ;_"zwڳPR_:L%ca |Pr?cZ8`ξfqլbC{_ɒ-qr6; .ۻ‰(WZW- a22kF~t<#DaOݸE4n6{`Յ0tz^ ؍K Zdv&kAik |"ux\4of}+mIV2(s˲k7' Aҩp/}N L?Y}2|/gm1zBbl+yEWrv1UiGtMۥ-R$1n$ CӬD`q\2 z{ŕ lVM Ex]cfP mEY`$j4ue]_GYE8i;`S藺  qdbc )E' t_ +bmj>@xdVHegz'#m:\Y '0D\T-)g3eF6J90e 8gx~2AE_"|Qz9F@qکɿAh /F2h0s*ya;8;ho@t$mÃZR i6(FhgBqH?>nRt*5dyaSx=Ml$̔PɨZKyJ)TOy[@7<>[I߹Ҕ/Qx1^}@nQImվ\>(h!:"{]=s'?t qqֵ (ٮ|bյ-g @21[/`Y_$"vQC)X>*$H57)QGluH! 9&>]Ļ |@}.rxb9As)U%_z2QsxURNȬOu¹F Skr#C,h.n ,~Gzy1Dɪ( DZhG"^Kq"Ќ#n]8K> lQtJ*03̤m6d?vL/ Nd8 ={h}p=D15 z}r"v38fK]d{C;E={r݅,1㱆e]8ZZt_Ju<EUc<BbzӅt!͊G1g<<7hnpE/#DE8}Ʃ5 0g)b&{x6Rp^ 'Xw~d+ᾁ%90aB_MG&#˫'-J~3 ';H7:V;ų=$MOnȋk& " 9xƅzl@s^ge:< Q=tk/NX"-KNŻD{&"m 3/ * :o;9F8t2 A6Ya giȿe|.P(z-4!w0 5#[m|'z>ע@n>dEvL,HL2 qs4.ؼ%~|l#e Jc9ckQ . f!ܞ1h0_>\Já67#`9h铌f^\VpNi>N( T15r\e;b.~$w7o8dzv*HmY 5M{v&Uߒ; ̙YC=h V+ vkų݁`zuÆvm;(/0.=ޚP D0W!=n&sj" 8x|@Sab{ڲjBC5%' 'ؕz8>4#ӶB; 6k [Oz`7'Spum/1D]m2~& ;g3SQ3FB'Qbn5Rj1Jx$INK{Hjîo8u'&MrPxX]v t%@)WB0$"UAVXcPG jA<ύjrSvWBw(>4#Ƣ:t&=Ќ*搢w-]2Ł (C.QTm77in*@Eǖ@ԆtE1oG`9Yc*})e3 <$m vM$LޱV'ȎxCu"E,c9~e]Fy_F1yFpQf^%[g6+qvm6S) 5jC (5vVF̌}UhO/UVSkB|kЫr<##Zw<^)[)#׺H-0Av?ޑ<;|P9#| &qX㹴rZAΫ;Z\aM[Z5%DH6'FdJʹa8ɩ36D,ʾ՜9"Tɲ@W\>/x4 mz$Lo"_O0I2M+}~Ke1Q1%Zɹf~;U&=6hK-{2 AD`1K'xo.e8h^)#ƭ%ژ13uĪ;_VHH%\Q4N%U+o"y Uvq6{X4Yzkwxچ p\ο癎*l-stSTeI*P? I+t6_&<<_ r.÷jxO&<7(zQZ N*@ _'hl=ZR0B3Z+Dew>88=gw3gF\#|if<@Hӭ]{-RT|T;UR&u-kίǕ)…R=RT)}>㏇~Lp:ԏpPXl Qex宩NP;͝- >h);^2S ,59JjC4O~ΟT=+!,5X~I-F ^:_' V e\6K5sfZuceMh^: hcQ{:G`g.4]Q|T>(!#7"]e:V:e (-W. 6Y*%)KnpWq`cSvmϦ˘ߏ{*R ȣ?35htgΩ"Y^D2g>WGqoP$Q 6F -+SM8QOCz#&m) ͜vY@e0-MNh&8 c- vyCM{8 `%Z~g-C%*qwb" BjbjZzxw<}- #VmVVXC(b"t(ۅ$k]`ZQfJMjV8':j*%8QyϠgcGx92PO406Ag{6m!D;'kKmԶGItaI؄sKrZZܰVп Ƕ,烹[(tj#'vӰ_P~^âG؀5gm3s%m[e?wLexe/ի2E9:-PTYBSDFm0I TPt*{/-r@q6q,D x[zq~#PE.*Lr7 \Ay .u(MlX0R"h»c Gc!njX^*l/$M@|,'x.Az Ma瀗s<6Z|GU+#n [S)?b!J3hwL7%]牡,r[sdӪgR'mIz:7yؼo au\_LP&}{yy&RS,ǫW*gWw$~8CGhgr `X{8e)XT!0(5 ؋b/`3YqU~!xؒlXxc䎊\s#ga:;x-{ ~K=?D ^ASb(}S2*fX:9lγ=iTit!'-nXe)-=dh=L aʆB}Y >H)bqn-~Tv'k -r33vꭏ&qUiX]u!C'p չ|ЊYi) Ul%Gƫ}/UU >}5O89U1{7N &dlVh؅PZ{4 ?'QLi; vkikW؂)<4xc[BB3up"HM^ 5ҏh"XjL\iiU/_['qYUFU&`@aM5vrwhʠke>0o c\t(Uš$DP3\Ř>|[%`ENo?}QyL/+=4Hcgle-v/)kmԭ>F"\hd3C+ndpIi ϸxp}WBl[7AoDb,Sp fpNmKOU^"v6P~g;rs6E_nѻ~IZ>gzl="S!v3 eȴUCf?j )OƂjye͑o 瓨*$%d6'N pTLǑ͜O2E)B=&;Kq U9Q* yAD׺$[;tE?x)8 ~XV5YQ\zͯBjtJ/$!}]'Tg-1=c11('Qq;29X]}^_s?_事, |{ V@mX/>Yli͸6v r)ʋo9NdW87/U6sf$W{Q̝Cw-{4NU"` y!  HdrG\>UPxc #p=cmh^JT*iC@Mm>ooѿO$Ž;2`kT[Wo1LAG54'< wѥ&p]Q\_PᰇRKlGM'?NA$~Y4o>RZ;|4rk7]3@ֵ]9T٦[Q@-Vp &`$jWjS]RТf'NJX2R qZstMw!Kl$gci?Dm nRQr1"ZEJן yׅu[;NnŒjml <݉tY_;$lB#IP2;dKdeV#3'p"Xj#xƙݜЊV b~v!ho xBOh(E)x hU h;đGŒS&_Wś#@\ٚh݊ /.>]+tP5x=ʙǤNߠYѺi=NbR=f6IVjOxL Gg+eX\'^5ERP- sGy@ȵ\,) Ew&cbcB'{ʆV I_kK,o([)KGQU]P"dF'GEK "zb}(WB4σ .:8*6\_f;;w[!fYV-)PE£SwZ|%3.yop]6]K+ ogD|Bg GaFd#(޸Oɪ`#{=-q$\~^U0Ө82{YODVgI A ^8;GpoKGJbۇi͔"ʦT0 ۲B "ҭ*WK %ӾI(0f~hy$4fK @;u{ICW}zdB#B$;ouXml~Jw|L50qMvٗPӬ2zQ16sq'?<^\*eW'a#*=f٘.5=|Er%)+}䎿X;8/SD {e,Q*I< 7Gᯘ6 ӯ '34fGrѥ ebݶ=S@ɕ&o>VDVGE|G̱k{|΢xrm7JJE ͲaSԔeR\毆aL*ODCZ8ep.%HwUܩNK`<@]73h9{h6(CkrQ !3r!X/ꏰHdhL \xŽ3y5뭳X:|KJ;n#e|D:͎FgKgCDQu _ÐX@8o0}ة| 8k4@i $3+;rJֶv=Џє@#GK4걛1n1>\Cb6: e@|Mj2#m5(O6Obr+ !Obdj ?;&{DIHя~طeXu˶{//#}9LJ|@+ýXi DZ+[BґHdXprwS3e&b@Ϩ49 /Hq58BHtbb#KTNw*>_e`ՔkH Zv2@E> xUr-fQCs46`w1`[|̓Ъ#rv$tX@ǩq`/,s/;3zYzPmkFvap6`~me~sjD #7i`6 w!_ 1jeXqON꼳{x~2a~S?7O[Yx92ҎP\3{%X4pZeqryڊI'\/NRYW"БoSq+ %W<\{8p0r5G(p~Z׎v/mʸMg" GRu= JҍyV)E~.;}]Ee:)<'%oe\ޝK-id6% V8xIWF2.I) %:D_:^;;F ؉uPVz$c"\+fp"=䌖M(JYͬOp={ JbG+ZǢEd@\acS?{$2pD(0Rl/\:vW-.$vgKO) '[E`tB'h8`ڽ@i5+JxYξY}L=*5$]̓ҧPcTQ󐙔Mm蔁mk@zM0RǹrpJQ( "WdQO!<tZۺ Z(ol|{l1v$ ׳$WpDG[le@cH@V0 \lniE![}U<^|ۣhaE_'fҵs[7)zN?u c}هfپ.+ Z2ښ|DM x,?X)6KAwdm3W*g6?w~7M2'}Ψ_q||HF K#C؇@ p/ I.1)XW+ƀ4R& :9 UÓ dx#K 20iC ;vyNva&•sm9SZJ.݂tPjYE|-t2҄5ޠ͐RXm:q:5Ng \mfJ`-F2Il&h"೶?4KhĈ|[v֐Nuen:xɗ{KQ\b2Z٦;׷jɗ/3By+1@5޽ʓGsܺ{Ub7XKW)pMv޹%wAD)y`c^/\hF?p#0zIUwUZ$QhA0 iTw43Lw] Y%f3 \܏i|6ub Sb\&FgL1pyi:ůO`Ey[ E.ī \/x.X3q!2 :q{qv;JB))Miqss޲>;ĭ=- _TeLTٛ^E߀1P 儡؟t&ΞDAG2--ㅬ#.l.`R66(W[zO|) pUF{BP~܎9Tۓ88ߓWܛb[t`Ƙ+je:R3Xfy>U̱q~u88BPS߅}VtFh10wzߗ}h5eRoz5h,xEzB՘l{zEWE v.Dz 9Oes?{"8p ޑ$~ﻰlzK_-/#:8x'abcTL*sٳa ^E\cD0وe{ `,εFYZA2O",6.}:|MM:ۏVmh~( 5ɼG@@ZrC&!)F1 `knEW]F̪  蔅gA*Zrt[ʵ7_I30I鴭ZY-b]WI+w eU%r/ohEvfHZꁟI;jC)wK'F+pIPazUC(K\)p~Uu@.'0J'S8HT~s +EHoaLt6N0AB`g aW^Br~4wL0>C)^s% Т' B;,A= v.47~SQx״iTyiuk7nֿzy 7{gY l|6cڔ *׿WPY0!7 r4>z j(bLo^K2ڻa<$?L3u؎ŷ>!ᾱ, 8 (}QwyE`Lj7ڏ=.uWrpsП ksrxۃK0*mcZ|( |DB X$neI|6ÏF{QY~$^!53X}~*`|m_fX7-j I W} g/UsKsSQWIIb":9 54MxFL<ȣ-6Ҫ=DW}Omz ۙ-ctiIo=G:3Wz ]<_ mN^[64"1qvڤ;-f_`I hR^Ue5c͘4 ye ̐U[[%-Ɓ2,'~gBn <@Az+6Zfϸ7?{ z҉ E^bcTPv9FK6&b8&ߏKă0v72F؁k%.of=BȌy)&9TEn)H #0^cm(( h,YިؐږYn`(eV2k _w'PIJ\d*ƨVG561> S'_{%qM5{ܨ D6˘rr!YXƳFh=lzdstN&6ԬJ b8Z52iC_ }~NnhUcʣ@ ;$T:>-`#1-xB]٫\^c{`(ب#+9sY}N$1=D`7 5-WڍXZCvlUlƤ -(RC"1=h/lYj@!㪅9\>y/٧rQ-2qvɤvXttֿـ ]~3Z(W]®2I:m1r:4^yMs:=OqB8rF^W.&t4N.OE6N=j]r31ppPF̎~(=VΪK{ Uؐ]`[3Vt` lCÕqtLe|@N[V1 Z*۳1P, ӟin6?D$[ͳE[&76hʪn!@rOA`|hG!3= B7P{A Y5҆F& wYweP\}biA\ifZL~1aaJj0P?^ n~9Ak{H _3Ϧelt;A!Auޥ%$ [ΨAMC9O?hF tQ*s GUbPRC|If!k ;|z0o!>=0yObWoL؇)›8,1¢IC'E" IE)H_\&<Dcbji}wǂf 0Kl4P*nMAbPd&0z=;wUC}͛hl|I-+5BuQ+AJ;K>}T\dzo ..N%QWo?h nѤGz`ǼcE*oc0~ d)t"AJO5~/VPu%De%JI'򽜑^A ,EO `_u"* {5Ig}yh)1J E=U.CI8H5dVqNj&PKr|e/Ȇ3=>ͨϑ~"E@|})x-Mk81thҔTh)> 6YcsV+F#0O7Iu,)A-' FXm@#b6#xPbPH3(+RH^ͩʖY[q|QU\܌n?D 9i$۵cvfWX:o9~2-~FGg@:H]_Tt9XKki}kL%~TnpT՚Ŏ :YeUbc q*@G8Zza PRZqI}EX #p͹y9($ÞO_ o57T̗Y_iOLJ>B&B3$0dRk5`prLElDn$|;]5`wMLBTM3@uNxAƍGW2dr9I’jpAY Ꮊ;\x{<<$?2 jNlC]I(/ւh+殴I;9ۯk"'-N%$(B? q }3.A'෩%#?RYsD*A>g5> 04Gݙ{Ve -+T!HݦV?ܽgzU 2#s+z*&gо(S_D9X%@߅>5 nL2I1FjSLj AǏI7f?6/BgS7C녽 W粣<Rj( **B|fDГ\5(D[l4DkMşEv( ?KIyVR Y!h9DcK)0ֆ7tݾ+cz[X*mA2F9]mdHDr/e)Frp^X%;H}n^!Bͪ/yD@ϡw5:{pAJVdM>Hm ;x~W@ߘӜ{2iiZB ䷉GQLJW>wJNslf$] LR W# :Ng=Zt$l67%Z:5q'DP) 6̥+ùVfz_lj`btōSS7&jM)gBO嵿q-s }r_%M0qK ͨ.#(so~+~LRx@2>#_Kp wZ#Z\X~We~rd0\C4s%K___") 0_'" g$Kf%'1`J^{)#M߻Xd|s怯8wRO-dlä,@2*E8 f=Xx>[J­Ŧ_g V2ў& h>08!_##y/ONB= bR/\wu_ YZ񜇨:W J!L>ǐFٻtwPJVmC2&7 6MsZts؛YЫޘnAnE\ٌsUغ5[rߎ1̤N/HNLY ҽI诗kuzaaCtZׄD?%z0=.aX;p[,? PD30jYb(JDk˚ _^Saha^9 YYd@6ֽB~?=b= (9Bޑao04˭OtwJcfAYLf)"|=U4]Ϫ;-n½BG7|EGP >|gyb[ښdQ)҂["Wڕ0ۜ\&X ѐ^-TwjNf"QglsNLn2_;;AR[.:QbT_ LvА@i.ϙmDڕvOi: gWcZh7Jo5&QjҷOdD v X+~ Y_ 7^ 71ýeشr~೽\yP\j? 1۷̣;VZL%g)/8$KbC oxEm˨TM3PMTMJ@`[zpK!bq8neK<*IۻLbnR{$[.VsaY iSHczc&۔WzbO"whS,mvz|`\]Mfplla\Ւ'VMOCwLKvTx(eJc1=( keMJf?'5*G{-ź$Dp-G1R0odǯ!R'WJ\ Il$+kCDBdju}@ no_M xx\SH;H%I&Lg:`L!6QP*iE0ԏd0`0wgE:Et 88hb,`*gqҎV:pCw.&0;cShTZ Q 7~ENN߿5. :F+SUpjBͩ/V 3߮aD[O" V\o:5"(jY fwy#==$<\R3N%5"yy' ޷Qw\ŪѩpIM\V???E k3RɝؽI>۰Lun{T3?)2 rv):˷ftc:Zij]'4C$v!YSӶW!'(ǙV!ȓ0hPEZ:# Ɉa?B]Pʮy$][^g zIY7Ok߭^w@ڕz (I]@7H5wCa>P:`f@+Uz跳Jb=#5kyOΘ_х"w]faV )?LI7ӠVaO?)QOlܗzLnTu ñ@hk3ic2_T9^j3@Rv7k.>창@7 &t<>s0KYڰ+'ʥ'b>l<lxUuH /`, 4lȼOouޣv&uMF ƫ܉__+1AZI-aH:4u`=J^fʠK썺^芧\ v~x ^&ylҎ<0/a<-z-M"r7v2э~Ty,quʛjmhdJgUcjj):W36P$R&f2aH&U_hFi#st/y$P_SWR (|ń'J0 *,fwq}.$ǖd^Q~*C] Fc`SL6c~ZLR4{L`L\ǾEƗK[df e+6W8孔A#M^*e zɌ9Hn/&FU G?7 4[4y\v5aB8z"fV [݄?&ɐ$پr:H* 6Zm6>>DEVm j: i!#`JJH} y%|g?ͧe)PV ̎G'G%~BKd85Xk}MA~LI&F:.cןoO \]Ć d6E%+G (ҊDiTADp<h3ux+a@[.I-lcvuڨK$goDD ]Ŋ|FRUH:K`&lήBc6my7.J'. B~:-?hY~wFGjPM\+%".Hfe}ɱ i9_@^Y9#k~ f:Oot3_1ec Kn:d6"44t7\_:'OGUMi7I>f<$, c9vkFͶ{ McbB ;5:wO5_p.̨\KpsW5mvBƀ NE40߄d\&UEVf ([g֭B&ZZ̖|׻iG8eһe*:ZaF3,G--/mCo+0tDg {}{$L`#ÇJ-Pż+D_yQ|ևwgixm놧ca$Vb~9-wrƝkn4gj@l P$dK4]A>#zɷ 2p+!^>#b_()Ш"hBïVOGHjORW|΀jޖLM@Rr˛챜y q F os͸3o/uoL;~{t8=Pegrcũ"_|ϨEaƪEWM>fɊg1J/Ḙr~5(HڍS%%ԫIJh'L.Z>\r9ɰ>:o̰a/;v/&r'qfd3kNa@G% &όhiWZBeoxo)W)i;R01 rSd g %yo7Rw{]m U.YB4q/nZԱ+ ~GjT]KN O*K<\Dt@sQ<-yFڨ.&řm{DyF <=@VB5%'?J=٤>wI܍@KVxДؐq/#rUZ 2{$RKR ZXú~aZtU45f+NQwpG=u{5Q K+*$b`MM4u)+e6ͱЏr28_τQ?1,zJʻ%f"fDI 9,@ABiӼ"Fu?0zA7-k+{ YGQ?uހc(Mj/KS68:xaހHKIp%]t%&:u Eܢ ;A3HGZQ-2^zF, T2CfI+L!mڹڏ 򡰡r0?gp0 BU{ !HWKX0:H,A ۓ-O<'s 6w^($5ܼ8<q($$m/S ʰ=`f ؒBb"P;|=ْ14߹[;C;R^n_mC ??obIJ≮x:35&Y%ӕBͿBkյݗKQ0LPK*sT7ӪE3tOEv kFXXh#X`m^#_iۧ$MCV7C=ُBy0 C/oPR: ?hNnz}b?З Q "sf8-kB-(6WFiq53EO&X-P(ĻnYA+<1~-3CSQN"Jv7l8snFg|X"?IZ۞hO[Z fXNM8Ŕ5 ugJrz./;0dkDpɛwIob4Kְ U4>m i ˢ^&&_IV+Y~:yŶ75ATAlp[\Pmw'mmī,V\F<`M/9p];$V01،0)~cڦ= t[Zw;}v~Qtw8P*apueAf8\w;wT$NFA X A^GCsAqLkS?2?4g.puXLiZD>Uɱ),qB0r v)*^Cp^~`@Wΐ: LyLx`sRz*.4DNb]pEq5 {/{D?wlvQњڽS#94:'l;kzdO]iU:baX5ͨR4A]ܙ:#bgT)fRG%mESb7+*֫E%*H g`=x1ۊĖ~a;aλxlT쎴oэw[s~֒HXn Ɏo k1 p_șF~Y0h&ӽL Vmd\\X^:\cdf`2p}<7>Vkk{gOrtL;0Mĉ_'E'Q"xXcv&=D.5q'?=T")n9!jtpq; p>&4W,/"zݐ 8*.~'9ɣG@WVeE%| A3 $6QQ2k;ujwAAw}yAω?\|yie u][},cy0X =xB U hOg`lukum`ցp~7SW!(]c X-< oF M]n28T3YOJ z]f ٚ8VP ܉ԤwM 8 {{xCƓ$>uv&7cN` E e ͗ :a}0 :YF܂30c|}V8F5n=bc CYjqY74l+u;2U4{  m.A7cqŒ";+SԢD{YO}wW"I 1I: Ip=O?/g~j i^X-[R득O'n|Hh7z&};)X RM9\"z4 |hta焅EMagq|vn6M8.S&NdU<1(;A}D\ པ&T y gVBg1%pg!ԧT+i;׿(h!B:XEuAE4id!an^>NvIz21o!&6*1u5gvb;S]i28ݨ#`=Mn@ LlnL(Pel%JNdSxߣzi[8^}Ֆ8zϚN-~ۆsz|7B]:82$&$5DN`> z`Nҵ[i;aٕiZ@[еk5LY5ujB!"#Y)1gX(!J8t D1(kLSh'<Ѹb&VmN[ODW-K/ҺQ֜.LUWK#p+S騍Lˆpq^y5DXh[vTPx넖]~>bHqZ^/cL_l$v1.MX2 fVk-W_GUG.\&.mT:OsOs0Ek=XiC.&N g x o3 VUv7eszZiŜW hZ Xa>?B sͮ䡳F C ^`Emuy$$`irb7N^y_0#EŸ'2J3.fw.UGtƐ`6Q 04 Q>GsG@ ,#D2[rX+d"inҲm")!0qEI ۲Sv3~oq|3 %/¿2P^|йvW1RŊ)buȂcU}BL#sFIKp7w=`"tb>Yu8uQ|4u2N-pjD/8`qO\u!jlkS L'(,|"lm6IOfvLA|Ijζ9;שV'2V{hZ:qOV2!(MrE_$IYwXA!Wd8/ڄW,%܀{ RvfzLu`*щwa< t,'FJVk0u7/OqVo|)!W'ta?9$UaxKwќ?DN3|jTP91 tZmٜh}_?#g]oJR 6υ&R<q2'2[ ~R<-\S uUaT`  <++U*#ʖ”cōAwۣtDߠ&/| #1Q@`8OH璽69mt+XŜJÁ*\~68J*5]2R-$u:;SFf^^QK*R߾ki 7N"B:k>ehw=3֫ƅbf{&ժo\Gj,&|/jS 87< %;_]RF -.0w'i8簊g&; kEhM[͢uj媘%8 Ƚ`=;vx|qP5*WzJ9]wV+;ϟPd͓4X&da1|z6fۿ+Թ tJ!^u38'qTWƻ-jƷ,!Q;;րr$]bz )s˕w#(8~+n9]e[a0߭L!yZPl7.2e/dOww 8|:>X ȯ#z ZU7R6L [+gVĀ10`I$;,X(wt*rYψLpC2c."huqb|bb%1Jr5 2^AC&$f{jQDPϔZiqc&3jvN{Lx'Z"5o^TZKd1ݺ] _כLǓ,mt<N9 S+HYݕl pڐ`)@M*OWu~j:{Џ\j!z܇qwp_S~DDtMR`(?^*cL A׳>.U1#A1Pej(|lmgtp|_6~2:BBQ+0Dڌ_J*;X$"(\Xx%aL=r^̬Glz:2Nݦnh?=\F`5OdXS; TiU$&I8ͩv*X-i0uMٳ<!r=Vpr/doQbTΥoiHcSN<U%c!*fRđ1Z0a5ggb.@M <`0 gQicL+$N*ͦcVݹ=@-Se@{ fx~ʪԞHkBkx8Sj.-4S:=fJ!M8: Bz/n>Pѿg Qc!Pل'LVisۑKZʆ?PG0j"QA}- QB: &d*mTR,.D=˷)qć*Mcp2"%&bcfl u#MkB|YT[8,R  (_,XӕA$IFn6snۘJAكbvZ*r U:';L 9&1pSܺ߿v7&PVm6(bL{iP/HǼFA?kX5^EM"(n6!~1ZXOmd+c A*nj "JV6Tx}OI)}VȠ12ok-۷I1'0?>pʒVFY-Ic T4a|Tjh)7,5eqzh6/wŴ`Fk>qlq9)1=vTÁN6B7$B)a>m禄,Yf|$=QCfX;0Q1Lyꥡ,7[DBg뼢jџƵ; x&J7q|vO @suc\%ioaILPtϏ\L0TA3h )L-)P!LX ׻'ߤ]'nTNߖTNxMY]Jd(l͇:X4a+)Eg'y T0;_t-e*b6 Č99)-E %*B,]9[6.3sRa=zH{h4RtV4v(-1`.W~.bN,B#H*xŸvJ-+Z[2 i#"?σBs)s|+B 8(`}ELa&'ly3> zl31Ϋ=#Q8]j9_)̿䅬2Gb%ΊKlf ~N7$έQe'6FV};yJTAŧ{fx+n"jX|4]L;{ J1Ե!gz`yJ {ڥN97*e%<~^$CD Gxu CYL2|O]ZfOlyᴤQ10&Yj(p"> d{4GŀߒNۚZ1W5Y\7pM@AG/O{4Q =fbȲfpYr)̙})mYe3!{C~xrrjͯ|&q@e,GGiW^csA;@UűӐP6_PIL6~ݲXZZBOJj gM  ?Kz[e!zi o5l:Vh^c2Uzz<ޝ2QL!w* oWi(:r93AƐ>oZ yLGྌ@]GS zgC9i 䝮u:a#hzQI6ɉyXwg-PJ$~>1@4|L[9P#j~9tGG^G O6tKXn݌.1l>QH}}ɸPEEMI/ɵH*gcX8q',IȂeN.&'Q yf|2tQ=avIF~`Vp_5~{`e큎4;?4Dl~8Y]:+Gl[P6s8*o?V)ˣv^Z_='4#F[rD"^>;<M/KdKhQr3s8kWmDj7Z`^Ҏ?pmo"8јH J+ dWe_pkYGYrM"w7,&7;h`@3vMh+ H{ .25l"~<2/Dqĸ#{6"rOXbQWf;fp=.RFҳG"VwAQ\6@A'Džr -irwF[5d\%T5`TZ+F1dnX%}af3YCp$IǩW]VM+B .' UE.Yog᮴hڗ iglT C5l A{)7kn}C_:)L-m(+Ji}E;Cf\+/-FV F;TeL>#/@D;[rIa^zrHe"l,J %+1lEJ0os,+NJ-'0h\9=}ư^;Qnb4tȧ,jA -\~YyR &hP6Dab.pZ# m(A.4`WH&Mz] vqM ]K>8-~7t`,DS,Oޖ}1(8]AV# ˢ{Qs|զ`˽[gmC/}MHQ ѽrI@c%V> ki)Q8 lH_ǯ6)\?;K 7~(tK>:UCv@]'~{-7~x{kkvV cYjSΤ! +5El~K)VylWTDC54EiT{Up@MY[~詺榟*,9;!<3_!IQ麌3_<磑ru_8}Iu&P%AF" tX5/x bgP d,>XL{hdf1'=Ǫa¹pv}l[g[J6)n~3ZhZm.:{-EJ`sX%gT:Ojm;KUٷ,Öl+?M@I3ş*鵦1׊Q4x!#5Rn[K+NK`z`, 7aU #:ɨ)I:rlp ;ӄWZ>9qn'ȃL JhW9wC@tIs;=OqCsAnDZbi5" q,B8u>ξ&ȍBR[8&u[ΐL :ӆYJV' YLG9 pyK. =J<o($q aݖ_!??2Cdi呫_CNp0gʎ1u`N+C7AS! (mZ 67yqU"o #_#E_ }!@YzHe%񐜭e]6d M]} nw⅘goa3y9uPr Ĉ{Dnn:n6`:[HosHK \u0 ORYC@\UBn0q[@ˁ͂9wB!O%A2GMJFMa_v#c{ҭ(Ƥ;?2hL(WOĞәoeמ< ]3A|X{oB,og "{Ýn)]Z6F皥zb+5M@ILJ,sJ'}ƾS0+6rr[|:7Kt&C2퇍,OHٲ"-%K)zG9kDhxENԈ"771Apgnoۂ]jX c: Ŀ62gQVE=uԠ1yq~ߊX^&{_>=ɖhI5,rdJ`F]zH;WjB\;IZ kQȴ;볒44β L)%j_< o-:Myr̟c3 KWp0?2 НgHbEЇtب .(.eujfu6VxJǤ.hd{QEs*IĶ aJ6!zttfWkL0l]W=I1* ӧT+4t&ܳU G*(~/_5צa_56z`|ֆUٴ^;R[JE4UgY.x_ Z~&fNj)0h* rJt(=D§9ӏ r .UҜTz$No)^dS@$7Ǧd XdZ=PQjOTuyG>`.`~N'MbW|%fog*!gy}cA#J1aV%9nOH@fSNWS*Sc(q6i,g06Yʅ= gǒ 9_)P7xc.Bܮ3er9hMZgiYfq)0ku6 r6ߛ\8rR"T,uR 4":/|2`v ^eblq}A˦qa 3Jի^cff)lQ?8Mbܼn٭ʴ/f 9PKSJ)NzS(&n6>6umkҥ#f'z+jG S]+Td-,~hߡ%[g@$5/4 <F"ġY;*C!IJt 7Jj#5V00df.;}v E̒hze|er[MS+O˛߈C_ RQDʡ}vmϓs8 R2KUDTy`)$a1 %:p j`je nwґRN,GM/=[y~K7Y&RpeR^Y!Ѹ{3ͼs"Qp"I(9>oxtcHEv(D_pX^Z ̧ϥH#7 ˓/̠,ovdµU'0wc;~S<RNP!Bn>/yZ,|BzV+ A?Yw{@fEAW,!*ebonW&Ѐ4 r ܳtfE]-pFD)I7¦!+'Sk7s52Mlu/aC ɾ:zDA.9L/ksb|du^~R\>3e^8,έVc37]x±:)epjo=c!t|fȸKy݂p,qR _)SYLgK8͏/D⬂ hJT.D\% %+! g)6uudk:8Q'B hͷ{d"Rb Mq i$D M΂K=/[wj ㆁ觊kxn {!q7f 0$dfP#eRf-׵Qu7r2:|yʆ4LbSca`%3AH;A]`ST%*HNiL"#04lcnue!F.Ү,D]U ڧFtw}\V42‚WnF[Bs/̊fSڻ C!bD?bczTz0dV l$}ܨ(0DF2`hAջ)@@(#9||%8dǁLs 1B.aAa5YeW vZWB~msۏ!{yx6qDE$wrtZrdLJ6d:lsp<Ր8mH|c" JCM*ݸT,G#/@F*x?a*b%\JHЏHy`h":hݜ46 ;)Q΀Ei*78nxW]&>ﱐ.qD1Є?Nnt [GRyqtK Ix:4KHA5uu}-Gޝj++&}ȉxܓҀcTK irהKRt̉Wft|@҇Eܚ*͂F_ە7T~yoRwQ>V&ƖS%R8Ӥuh=k|zWTwP]DdJ?2vrHM JΩ^nj_,128" y)%V3>U\ȵrPVRhgg2h4:6LCx*N `- ^N(k-#Q]TĠy";D:[#':+B )-F3IPEWH%%OEUo 0:.P=($Cx˙`mWeWFxRiEhJA?;8Z1;o{y;w'?~TyX9$5&њ2k;s˄n1d(#w!sR}Φ9RGC;*j ShvS`4Ұgٻ̞El܈i_u OPGLL. 73OGA\dޗP)fiUVR=&Ȅ摀YP*qmI\LnbMYS8|";@_' pϴlIrK~vv@:f e;0wL=Xd!HnhjJ!04$q\gϸϗPT-L{{Z|r6F :rk`Y2=׿˝f!HZZ+:vkfG Q$x.7Lf*F\%QnľfOQ&\V9S3IIJ<ffi:Tlk%E?N~Wf֩`UE|/m (,#_v6("*j8P2g'x_GqԇA'pAeǭ6(Tbĺ@qm}҂mpe5A*vɄ=t^XYu,0G DVhL+='a c*Y޹%U{0LAĆb5 ^EIp8 >B1g5 d;dmWRزr3x;@aaiw|8lyA2͎kVK4H:I Au[Fai,7Ĥ3Fi8BRnŏنp|R2kWfOOsAra`*F& $c1% ==Oj]ׇ s{QVMM (3"C%ܺ^4@c AS=PE嶧:\fo6K 2,S[C y@q/6 '%SHu#qsi2【 y jS9 t_ڲw6\RHCq.J-w7en"+ |L;$0 2ͼ+ 9 kW7un:Ys8m)l @AG:@gRF ) %B?lyA >_S4_$B( Ci#VD0āh8_΅W+V/Yi}jKc4K"F `÷U /π 9 ^"n=\O a!6L"MD4 6嫯_TMb2._ 2}ӽd0'X5/ϩk#'tV@6dU>~-Y=4Ik*MjRHbKq{ߗ*#DY---.PLnN_4R͈"-ved4d;j1z}˵Vo_@7e pI ǻcI3ByӚiGmw)"}p$z[l1`=}ONn-V(4͍f.C6ZqsFG_s6W4shV&HGiQFLO?7AL&#٣VFJ ob"o5znxqZq#6oxaRt#A/jAun@̀E~ %rF&-> `b?,_.R{+Wg|K c%l@]pQRZymF>voQ)$5<&`jL`ˑS_t>2$PIouYD+##+ڻKLW$t,A9زZݗgX_*,Եt 9;Vtb#C'o V=1تQ!Տݝڍf%;ÎV Tn,\~T@`kCh0"bBQC['3E NP"Nk4-"fǻ-=ҧد2 #eɆY _Fl'/Zb!vKuFczJ' r??BMCoa7AlQ!px̳8Zc'4|֊tB$ymwDK{| dHϨCXK]Oeאa߂=0&_J]㍒;3o_b,/uO2SpVhö<4EFo,#g(C>̀A+~_hF=+[x`L!^KM3J)zÕpЯU&̿ss\>F!mʑ-w+U8 BŹ*Z:HξEh›9rv2Y(ml).R &5.zZޞ~W1|)l\nՉW>(_PGMloN.K 7\/򈈜jPeO%=C s+4 <qG~9BdۤvhY[0(4>V<˫8LyNt5 01R(rY1cs㢂G6m2-;6vv2&@Jƕ_yjGkuQ,,]C#D-j%(4LOpO@?-ok %H",!T)OKc f6?*[b.FDs 18'w>ޮZ[4ծ_MPȮmy ~I*?T挽(V4~!Q"LArk,I؟=m6S۬,st 3<'Ȇ5)ѧjOAUzQv8M*HdSrwWν3nbJO`acj<.~j6QM["Ya{CӮۆ\8[/.kq -d`(퉹ݦ+>m>A$K+ C:]f㑰RW {T-yٙzl 93#iݏX\Dk;jq M״Q̍vTdo߸?J] k&<'1 󮒊\U #Q:x|etQ~)S@ Ͷ^_0|Lbo4*fW{BㆹoݗK亳w#Qe1shݤo|zVX+U=v혓VM.9V)+}ZzX#hrKe)M.d=ҽ,{ic4{S&i}AvL"}&Q~(T6q2Aׂ\ü7Ƅ?~JvMu>P\phSر.r4=k-Vv]a6O#㸳ccCt@3!!qK]AqqaDƈ#dI8&Dz \gEJl.# eUs)Tآ̙ۧn7HRuɃj?5K(Td+ pkʓdi':2Klէ^"n|RcdJG膌3@#Tc!PJxsk(EADLwU 1 @A>.Bo(0l;y\q{bĎU9>)QY4@r?&tĤζ[SW5&9Y| G.z߶&J ݸˌYE"qy|ۈP~i3$yvv6!n>8 @np0-r|DRE'|uiFF;5`RE@QK!SySZ.5P=uAҥ%@.sw}aʭyf> ۷P;b3[M.aSuԥr [\G߇ş*HdiR~q8]7 sϛ|U i Va)+DX hua֮x ~NNѺičeG>G5h$hr(GV ڜ_׿U'B~IH8 MZ@ ̆J IgH!N]1dv鸬*~٢w} z,W#21Z! ۻٝ.6 ]Sq\ҕiPB^X_S^FXtcu,MQJl8ꝫDSv탬;㼭4eY^ӲEkF7e+{%ՔB| DJ<?83A$\8`dc"HX.tbYkyPx6j88eBl䂭7e:P{OwIF>~ b_JkHR!gڥk̯QK%ؑ{de[S,[]ƌP+xQ>*fT6$#rҜn!a.EgoIJwRUJpVR1MN֕|a;K Gyhf?wEHbOBu~wreFRx,3Z_+ytj6aO9'Pj11i[JhË*q8<lXW#I:Fh"ҺqZ"{ ^{RUTNJb9`/)IOE~yyJ'~:pTF(;!7bjL2uwoW!pc؏ (p+jm_ K_̔K.l4Ю%P|5 G0\p( Lf?Yc&g'8 "L KHzbA@Q'P&$šZwPF2Z`'al,pwe 3鄍U@]-"%):\ n@A"tC{iGKt|J abZh{Uw)(097[({yh<qy,E 7/%fc[1U%P >g@'哈0wtI MXbU=|Olzju唁U *jãq_!<+VF+/VQ{5_J+. (6 {פ& ;|Q@.)X~XDCCfᰃ&Ee:̬0n;v!ƽ=ڤ*`PQWڠzm1EG߈/l l>`5Ձk_t߼/sGhe#L.EkpoF;Q+%-kSn./5cM^i>8ΐYji 9|TBR(@d7#ҕU+t `V k4Sxm0A^`1Tա,фtatB|Hbp:v1hpWE&$Wt*Or\,qET-i>bHy h8+\8~2. C[ k*d@yBpL8T&޲J,nѠ9O V v=3fY1P U[5җ*%8zkDPSBJ}{"/v8' i:Ф-[{H|@axk4N2@}U 70twuLd; v_soHe f-|԰C-n_,8/v:=f, Zɥ:ӵ=#гpbş3ͩ>GDvZoruʯTDmeӿ,?85>_f-l rxVSZdTBQaxRyۂ3l&i[mku1Կ셗Rϔϡhn*=)kQJiVͶ>y xG% eBd-&^P,`Ӷ/Ev:0 dWio{)95q?XZS ت?I2kG[ V"k('w\ RmgIvZJε*t~޸klFT քCpBf܍luLB9N+mnZLPJQ8|ٞg -{/X5-Y|I+O8CfKEl6MJqe!()O,Kkg5ja?҂8Z#KRv,{Z@@R]^xV{=EYU z8QaH &Ҧ8C {=`LTKKxc%r0^1#OJ t^fMUA8wanOe&3#A%jL˱Sn ,MGgz#,_G7>S κ>+ hSBbi܏O%,C\dBlY2,12&Ʈކj!p@1gFf'?:,۲ҿf'Z|_Q/ŝ4=FX*!m5yq^ƚa]9]@Sfn"MwR6v j a[z2 5ZaH8_D5?ͤNXmEzn4<^ZPȴad5l hIBqe3 ڴ<*죯V3HPRu3)a]*Ʈ&TqXưW?)@~T*r0m^L.Lr";{SiNdE3t$dN[/z|w_/upI=n8|cb_QR|+@vJ-pfiψfh hdn 8oKd*') v "ܠߨE٭^"l+NRȿ{RwI# 6=!dz W`5g|vu쾚 ]ߏ!e7]]nD2 <2gr'.&x9<U^}7~T<ÚvV<8_  BLJKѰfT.IkBa7@z jjX}ຢ*[D v]$Lo2-rS8-&R2hh9]mCXf]a[~X3nLdN/7y1r:4{nVd0*łn{#ֳ*ckϼ7(Dž),2(+)g_-yes(2Xj~9̀C´^`SZRuDrݭt7CFDe[]AQ6?0Q{nBVu;v.>^)٭; cu6dLy+v`OAmT&#dU%GO)31n@˽4"(a;8|$\(2Ry?>B{y){ux%C^v^2VZXpd~O (2[ u\A+v/T~1bC5ڝ^AiTlp1TNsruy8Jd-ΨA\r* x#zcȽΗӐ?H W3yE$vDT:^ JeLtWĕWBDž(ꎈ=4wuP٬6ExV`a@K[R ]I|eCH ,V=4䠫+Tܛ Xj# 'Tj6ne`>]^I?Aw;N 0J}˜oY27>c! ]DKy = \YsDŸځP;P&ΰa)f-` H̏z3E*oN*T>}qF@(+q,%Lbu1Ha>  6])b*6V[kA"u2-PuݲǍQ_&a&ČMov0Q`&Us!7 PkφKL_S7@=OBvǶW64@|;Ї?M-go+K0\s+rp&U⎇#)QpޔX)UJu1؊i1]2j*qb(g xTĿY5]g˟ċDzhD[KGYx1&aY;"v}Ө!Q TϞ{“?p/Q3֚ ެAn#0ʖiԖ]uF9撚L.acb^^TVv:q*ـW]LA52ީuWFѓQv=>zb!dġ? ̀*Lc4)}jY1[ie-{Z2I=0i|]IK;gBD'96(&T$ DRb$ 3m'y*C~36mҗrnm>gBJ*l,Tt%1?k)C"!nkɃ4:#jnD ,xe6 ̧ns 6TRϗ%6f+@dF[>{ߊ~j ]45Q+$W+2N\A͝ǐTtuK*&.>Pe>Sڹ]5*>`WezU~|ryx=OZ&j[XzۏL<4(HI. ۼݵ\f+v-ޒׯ Y]pRU(kф _^zty M6ɄcۗE' Q{ ~ǿ*; o,(%"W љ򵣡^E-otkf-gD:)m"1s&we'eΰ5S J@U_42/ @!Ϥ:s~X6~kK\Q˘Ne\/4J:{s 0itm- ~7ae4]͊!(>>2>ܧ'ohƤ䝦4jcӚKBZB9?\|HN?t*sV3=!& ZdSo6աe@1+یOnkqC3vi bO)MyLQ:FMcaF,>5E-%mTbAO@Abxx:hUʾ5-Mewldr|\]sX~VGUzpJe G~f~؁Fi%ej 7WlS9\ _z=FO&}-7S Q7]q1 /`6 "L+|xRO HV/vrDc3}r0jybxW&^Wׂ?}:NLv(R,-^`!ݰPn۰,Fdt(X0؂ϝQTT[(LGbUB+~TP~▤̹O^Bx}#Uag}oдvy/ Q6@p+3h4Y9) 3\_z-Swvba|"h֔S~3|w)ARlhvm{glC*^h}Cᢂ"x2\TFı }S?Pݵd=_MǠ%]um8`̮1VCb׾ӅT FR/ݕDף Fta%*!f?`7'OQzXw$E,fhWN]=,8ve F*+-8 khޏX Z㷖i--u}4nӳר2>MKUnW iDaGݰ6@\|E `Ng؇Gid_^ }xɭjr[7pds>م ?05.qM[!J4Tiʢ~{ ǿ>pW/BA\aWyNF 0XN^s$Q0P1atI ml8qAAةѽrCaq@O g1:z $PR:&>\&OĭB* 0ԧxxҐHi;)A<3ǵͭ3dH6G,*{9\DS`tyvo0ktX ,9b[E. RKW|&QW/ٕ3QEsrdt)9 ֋/YF ՖpD4:l4BǮHxxͨt fT^>!Z2\V1 Ɍċ#x/oX5~>YI H)r׆r }JE:~ N7Be_(@FF<1P;%S쩱Lj[C ²ːHxF͸:as*UzܡlG@il7N?p x}GܡY%KD"ZI1/- ۋ9!uwl Zwm<fY6*:@Vǖ畤ސT⮝Ynk҅{8 }3(9\"g1ʏ_do"Tzӈ݋7wOB>і3u7xx1 GjJ;Dvˏ Νz3b~Fs]W!bE'`"q}/.I(s=xlLQ N5-M38;v8bCƉ֍[P4MsbmmN^1Rt074Wf*iX5@{Eu*:b|S!\xLy!Pe"3MTg#n P8TVh7B*ǃ`ry"ʹ();ed**?sx eY_o Y$Qp3%m<1= wǓiOk&3zu؞Pj F53JG* WB)՟~eQuHgJ XY4^ة}4;qzf$IܓP/5&BYqL~XoJFmz&:_F k`eD8pTTP-Mz`ᦿLkcZ=<`-i-Gb~"Q݂9Kp7Z@a|aq1KVB3٭C CcqrgSs9=2FzvrL̷:?QXUz.X{8?YJ=HlZmx!u]u t3GtzDg}p_C! n 4|~KMĹER|'h3g/4(nAI3oAKZˬB*-ASڤA'?j/f|k&1 Nv}і 7hwUK(\ Vn981d3~cO!.e /Gz0LIDw?7wAjjaQ ru{M_JdhA3Q]L`mzL& 87ɣăAfKknxN.\B/;B^R`zscN]k]?C50<)6-x1JS^1ӟz ΀i[J~ #g%oہ~:_8נ-=zZΑ$\0lu3l/ A?.("+E'+EU:52Oڍf)L` AN LN6Ǽ DA +8-җ*=bMTTXw5!b2Iu9\|]=Vy{hityecTnhhK`;>7)3b oJm 8DNdhkw{rUsǂ~JҮ"! 7ަ;cV:lZfl:edI\#{8F>`\' c)Ke<-yEO<> TFe{fyM=c*y;Ҧ2ep%xߗ8!JQ}y_b_L A-##2}$ VOvK3p4T<<]ak<'NoYsSZO1)ˉLWkc?=zؿ[>ha0Bvvhkb$2@_)lQ87}RNQrMuI?l?ifH.qpg3ETm{E)&_a/D{Ob5{:s4k OU?L5  CA#EoLNե9r5š.q-гhd=2To 3oMɑb6MSLi2;Bv{$ /Y!NUr`)eMƽ]#nގÞoc Ŀg0 D%^)@- c|`4hC](}O[߄o\j%zhǷڙ[*-)Zvգ cɹ |7|J:I1bթSbionemc<>!0 5P]Q&au3? dE=" rJ y}M@ [.mfT],!ܑxi;Ҽ>Jx'f y=:+Lko]ǒG+!m"ay8m!ѡpWjzvW;ce!9gF6{J9.T-2ft;ȃxSt5աO2)+Ŗ–aC$ -% ʜ}AxT{n帓Fӥq Щ4PB@&eNΜ1I{]G5Cuvsoem0 $ݶ)b=CB(+FX&~f+C?d<Ϝ#wP0;qЏ7VC8lf[k.VFff'a.*'ThUӚ(~o#6/2;e_6UFnJN+FXdX"U-f#e;A٦adD7/04> h<]R;*)ԫ\}ΰ [w gQK-Ȓ#$hus(Qi2ɯ 𠴔IJ+62O>鍮:tS&W:c/C,:z7X1f{ɀ+YތjQRz,< RD(At暀^)K lGb>F}8߷}Z#ʽkn*f1a{[:'"ZC5jWd:B*-F_%C๔WIA6EP~; KHp8BwYB8giʵ7d4; ,ǎbp&5lMU4"weNf0 %q~C*5=(FjRoIl@D׍!sbמU(*>~}ʗ#C?_^2„=A([?b+ufAV| Kka.P_suiL17_=t;b*V'80n&TPB2 WMb,l{(oNrO-8p:/ٺ!A|ū8Ei} `ZY!7"͹C(C˽)4n(1Gp+2Vc.aK\nnK6 @q=u;0 =lÛ"U6I|B[dztlrAXCc4 4EecZ'wwwí`%.ՃU=Xby{>H`ɟvVԙ_A}8AS\G'i1BDIg#e\t @?%V^;SX*tnHINJ-Aaf.$` `/I`aIx.di%A"ҏ]KQ}YuXf+nDB p\X+n6~G%tvQP{L:6_HC)-ap`>H>d'eMOf#BlL1NU=rriuq"--< xJ!=ՙzwɯ^籃1N8'];RpSQgr6Pw

џYAQ*) `aWK4w"CӬHʁ^ql𛗚C2 ^_sǾpRaIn>d1\t~ \fߗU12'WgP,lQbv 3 r '-9f-T0) ` ̯MʝY4T-d{ dD,QQ c [ۏt2?pO# %IZ/G5_r`nHF^ď~=I*ؙOlN)w/}̵ ]'k=KX. b%Uݏ|#&\ޤT)y\)f„j848B崏7iLѠD>r圧ч!<Jh{iՉh:3on͆|7nNO`G vx3TBJ{WR@)BDt<-Py8L$*GyImNFW!%t 7rbRYOdphɸ.U|e%995CQvI/HZGINk*xS(GGX%4_;c?_52cPyx2¼<)"F{/|vϑ$e s{9 gU; G4ڬA'dC:)^NutWЉ4|vp0E5b:._A׋8M :9It ؙw􎆩PPsN0s3s=7B2^T!]d)3>\DMP80uIJ,&g;5;rz"8wK\|:pP G< ߍoDXh<@,ȎۓuoSmV(X  ?Kta'^#“Umʜ+ҿED!.* 57mKH@eˣ JDgFTX|wmQS iSN\Rvzٖy%W_>?5$A,ĕ\ aӠX!A4|Hɉ) "5a7rTxkNjTSx=d"|i@~!\oKg[kr0\x6EJC3fQI!k10\E1*8!? &EW6rK+ĎQXwu r1ܜWKBrOZv$w 1dq_[o"$JFw*(hu~G'x2R?@qk?`O0ȉX++ EC*]wQ"3@/_ WvP1Dn^di~jrDQT 3EM"y4ri#JvMz U,koq* o{i vX +WҜ WXZCz~RY)dDR_ADT)C EZTwN43[&"RNO2ioYœͷ0jnG,`$׷RD\l2яzGP[@¢%~({x&jF Z5ܸP1/8*YkbPB yG;| 7& -]Ŋ -/X&*'8ds5CJ'EWZ|}_{H/^[g#Ory asU*n>|A!]9\I:nh)V0 Jϑ!T&+?~]Z-';}#N h5fZ%ًO{zQ*N!J+>L֛@ƌ}+UY,g]#OW|I wmE8x(eOB>ʋv&]Fir fi,Es48@oK5l'V}4B/^Rf$lhXn#Od"вsv25FQn_0gy hc3~M:e5}BuQ /ݠ xߍf){\_6\@p4lW:YCӻDcv@?&9}?ٍvjnߓ@tYIXS[IBҼC(ic^*" +P*0&jBD8*fe̬3Qsgtp5/:E4C# Sr$X|򐀵<^'iXݮ>6jJG T HD,n*YY+ԋ79PxLED4/k%VvyT-8|8"f&jkQB9M)0>F}3:'D='sʶ݊s,^mKRz%]0CA&xPO]}DEvQ VoJw¾^YQ[H(Y[3S,[*6D+Zg96PG L/s1 n{[S<8v;FљF]ZhӮ/?PIz/y+2x'%ћ~ƪp zv%"olNͬ< tW4J5y!A+*M)|Vp:rDA`2V% 7H05Xws |Q*qX|sni.? Q=_`x;~$t="jϲp=LCVH! dݦ_S >3q&8c nJC^;"cBъf& ϩp<5' r{ӐQOVT,`ƍrH`yhKp'u.#FϹ py1b輓Ow);:|h:@pvV\W O3-S36evu'rjt KBVfh֚(Tn28 _(±h5Wp9kw<5Z/zS;U[.kpg%eI U}rd7u j#g C<ъu'鑓 SG)_9\UwpniFlg 0չ~7d[x]=LTX1\/4Z|˶B\ 3߲^[(UCsB[UDMԤ!Y=bg'-Y.;l隽φjsֻ.d/pT_#Dk$LӪ@Г0><'5AC- 9j.H,7~ރB!H/O[Eq#LB\0) 6#L\wZ8w0Ö1Z.~/EϬ?2]37OH(}fmUx$eIXZ]?X>lfS\ֱ34p(ia9iOhz/*gvumB(2̙,`^h.W ¬+9VA㳗6\;G"&+U`lqy!BɕCFlF^ҨB%XfZ4cBݱ]P*&Ë`4yd5qU{M5L+&ehՅqpebwBen6QYNUtn+}'D3ӥG)v|eūJwWom{w> Y by~+amP Ʌa+Ckx3_[}QHՠ(8Dkf,ۥ͢2H{~!Ͽuh .T6px~{Ay9(:܈St2e hs UnlWIoӊ*m hhx_^_:X^afwu @g$N>o3x-93]lpyzRpX0ruҋ<~vZW?) |cW-ˎTpXa%;^ =w 0 '.VnGH[.8E^( yQqDK-~g1oyjXCp~Z)Oh UVG8'ؒ=@ zs6M]qTƭW ۂwS,Ks=cgS!m~u‡ҦNF*EO~uTz>mXpD"-v:&EŪ5Nx^(egJ"!%8ͷ]kuly+(uћXfN(ˤrtr<~KwMlcLswiFbjzaCH.[̽ [p~FMB`揪E9։0=#ܫӅ?tNaRVog};C@ac_taX=I9.C* .j䮇qɱtfwB>3R&L"Yp\a2Ǒ=BEDfPp:MD;w*W+m~&^.K3 SUs:=dʪѳ*a0q!"ʡ6T#fDn6a,o~폡KPoqp4-lw--E-v 'u{W9 3ٯfr]B,G[:;9L;AUlbg%E/ 8C?IM9 *IJ97\!BIyPO%U/9.2/}ݫQîPt*Y<dz!Q&xd.$*յIiUgE+LB3MQ)QЄ`Jʑy|牎%,V\ĠPnk;@* ӼD-mWN#0޷ 8fL*d\3D.Z[fMH [sf8=V0F0mY[iEľדvc;Q Z_5IQ$5|,72#kr;AY)c)D }E)Kb"n.3: ֦hϝ)jH_J2y p cGDsx1Wz3]A!p}h5/ FIڡahR EF&$zhZި[c$P_}s @u̓R&=&t7S< y4.PLZd]Hj4^<-ߢlz׼@PA|:Icc} xK21I$}I:&쀁e4%/ 7c߄-7:y< !wB Tvol;˕1p %dۊ2_ Q2WbS@妺!E s$A)1vA)ѳR YP~@xoNsjaU/!9^!2 EqT9+w3> f6nF)`˞JQУxUH e WQ5 :d甝p+@' 3-!ka'ISk0&/ B3HE qVf{<\\5UjKcx, ;'~081v-Y] zґITkTkkȇF\iFU55Y_:'ZVX|*=:ZWL< Ay_ Zd0-?XlԄPh<rhOyڟŔ'WL, ٦v-HrSW% q$+ ugOYg3#F\VN-_#Ӌ2b=%mp8bPb+KC\rX sГ8˻-}8ZGOfqez%*c8|N͗)$,A][1MVn>J"!q+?ulC˼u&{q፡Wt<@\M :h#ڌbmͷ!kt%v $qai\p'N|ܻ:Ym 7X' |ݐ5gYcѴ4jηblc͜%%αplT`\1Lg;{˝j*pxA;cfr1P"kr.f\mLJvv`c8P(RT&" oǠt^y1dH6kqMV"C҇b4\SLtєX7Xa0ja*\ϰY{S_"G lStmMtEz]&%|*1.`~<@1e4dA #T[0[;q}b;H={ݽ̿]m%r:n?IB U5c vfeBe"N]SV6p-*|[?`TU˼LD 2:*38Ushʻ$"医l|0g2腆_@VRSc3.c"PP\fDW;+"|/DU~pa.e&!gymI@Qk*C<\{zR(A2'Fy&5!0*/cuDkbcM!KvL}##S%3 yQuW(](XMz fa 2ez[ hr4ơx ζIZC1ix*ce2ک(,xC;/QP2vO-XVV %AF>42㪎1% ESeQt'Z|=OzdԘ/^ k̛߉x' kyIBn;w_ȡguW.BoG2e4RȊJ(,HTp^Wt1:*O\ޱwnYR #'4 rn1 9f3: `0MWA25S@,K^;^4[6;v룿1=ZնWW+טb3`t66p|͗<1YZ,{V*Kq$~q~g3}"C+o1Q nxHO;J/٭1 JȮ1CJ#M!jPI5@86bEw[ЀK25c۬[7ku */caڴ78K\cFQRg^kir2#f<d JmPz9<|i#gBp+ncXh@9t3SCb-6 V_G = '+i\1* ^kڲR!*fYp7Ң571ZwQ+F#!VqKWQ,-n7֧˚lBXTJ>^B%>a6NJ$V"8TdcG;87cDeM-(Y*J `tHg(I%1W48%~S[W)P<۩^pLqEG{1ҮOԭ$PK]HкLp?*uZDINH [1հ-U)=݃Z$T ]`s`>ѸD ı:rV#y"u-+pMEun$5 Xudm5ʉ:so "2QR 8΀z.&nX]Rw5c/'?wi*!*?P%8a8,[j)Q0.QFyD7nH6 1O49|du&[Aϵp/c9NwYɌ"U;jCCtsj+q =tPۻqrH]ih>) +zc:Kn3flqЫpb((QqKmԙl\ܰQYUvX;GguyeFpIvGv`QW N9>xҰOmVGF*,ӼFU AggDRiH釱G"zJktr)&H]u<'x$#*mj{)ˉkj:,{3J\rc^y"ͳZS1T B<ڹs*n<ʭ]fZhل׮968GOOY+$^5Qn_OW+,8pO[K!k61 OSvsŘqm ]" ʘRFKQxiّf" 0HoSƀnEQ7>a)1cd16>)o{}jhN?ܦ4{&5?s ƹjWs[QȢvM\ڟ3ZG~4]' 5Q`&H+83g;=:;R md0ǒUT3ji48Frt08V62a,E\tq@V#-G, 0z!DE 94WNR 469Udmfx{@Tݺʗ<ںh0|h'rh3.5?A7QF#L{@=$73[CЁ%U"l5۝.NXFn "<uȻ4 X)>3y2H)VMc]yL"Fכ{c=rٔirl?zeN@~ql "%xd E?\3L}RO79%8w_[]cPF\=8_wL]})v!\ aHu7zr.Щ{>̟ }ʿs) TCծ<56gޞۊp1kuwEg1c;dt@T Ϫ9/Ѵv~䀋lIL%(fռsM3` ϩszbъn i?M4B+2z ?N1| 0l78I!PJ|yV&d(Pwd4.8R@DVYf~ y)ep.EOoW6?*rOVd 2;9a95\tOXY6#@>uDgÉn[7v:|*)QGntmr#a4ieV/P Zz"z.0@Bg>:AO6;F fw7rHZ2Rȗ.W+siX QGveLJA\΁̍g3,wvc;'j>FF N9 tE({UEIT5J!GeY@.6q>?pjs@$+||]ܹSnE3K ۨ4ZS?:i@ǸeuG]VSb)0*V0ڣ%g:ǫyn SfBgD!;߽ ֚qJ:`? l|F 0=h(%xq۞(eoniL2H(oA^\ Dќ37ݦ:XHM28ݦ׌xі+DB-2'9'ן2gҬnND`=SDF~?;Sذ\a@5, hdL}Q4dk-ⷩ*!ǞG"LV!0+[|9gzB ` |H=0:n; ])f=,2)N}A:TōᅦA.*i"tCfCZ !YRHŮ){`6u`X,wI3j6dizl& rs(v^n`?;hw҆[6eC ݓĺIr`fhi̋C@§VC@8 (Xc7wmP"E:6Bv'Z^+joWy9$dl1Ur)ݯtF~떁p7{C@;EA|B;f!23 #؜ZRrHwwN=L#N=toYa`]4Jp=ٻ͘sk7wFt‡ 97PQz hZ*yـM;Ϳwv*"ZrM7 +b? Y ;8}H I;U%LV=olSQc(5 ~,~x6P%&NJvMسH8XԴXdLR G3rn Pq%!r9?>cLɶ6ϛڍuÀtM'Mfp1l`uVJ&?W? " uMw%x=&6vPYg+UCR<ԤC!;IOzgo$Z:+QbE:YaN3~ܱ[`NmQYKzM^ lI3FEK-=uI.SMXe˧92dI\Fk> 菟-786ۄio?fc^l$<Z6  (;i_PKK|BO(g@uJ3S"^tqeNbc!E KG(Wc^ /-uOkD:wlv G R*3F&iq% bѠȬҳB2Ae]c*؂f V12^`$WݦL7;g>fdroͺ2سs(.:Xŧ eΚ*UL$/%&Ϡcaj)ĝO:sFMC**lu>Y9~m)4}G2C|Owz!#uyFIUYQ( lr=CϼjdX|8Y&9ñ4^fLVT)&OYT]5hCޤ*O%'O^MJYYA}R[UU1UtkbFIJƱ Wpƈ@W`# N$> qjldśs`Z|vTC)/6zaM8eVo՗fXiZ~nꕩؤk 70'js܂D<3y,}G?dlWdR]cFo we Rz'SRp9_Őr0)n,e+\xm6g݁"{}}Yxt@V SWf1BA~DYRAD:*_Ǩůgϸ+7,21ߏLfqPK}K;* _(^yck_7~?t E G0X{j@Tͺ().ůBni!䗞j=z78!!Oz15h˺m`흐i@` V-Ewt傼w ?Gd r3>gly{{B%־bEϜ:/s*ZBdԌ fޠovo-ft;vBins'v}7i^ ?b{ȶHuP"ûr% 4;YO DWD#umg *qM}z4|#n7bikȯkRleRmplAy\B 4ˬ& H7DŽ|& 6f[.O-{>nAlLiC]y!>h)zq9RXv ^p.L HgiгL2F!:?cy$aCku qZԩQk$>JI+un>\XBs8xeu:yђ ap΋sʠYTm]>\w1E"xb`aVK/dtBN߾CG"TҤC i^-ƸfֶSFY4+6M`*9Dg47.r֬TEL,?0QMĆpo<\ٱ!uȢubrJR7;$WlwRnzL>/~w<& Dޜ+3pUZ<jȒ8ieBID g`ZqDvG>Bipc$o,#񷋓) p+Js y|KZDk_&95E8 h~pPkۀ})(JĘ6뗿Wjj_o+ Ihd'IU 5` yR D%pQVgi5v| qu/K@"7PN>3j.]iNL;M֙O*cEsx飭%^YE|hQ±E,-˱so(מ'%Jy{ .K| !ʔl.8a<1[À]f'ohcwVoeKfhZ~\H%x$iim=l=R3`;g=^-axcQ@<ԝK#}z P+&E[ynU$-7ц0 O;,g[P.}f3 *%#S%#sLm搵δ wKyy`stҤ OAvIۅ_P )1#QJ}߼ c烔1}.]7ykOr̔_Ի+|@oƴ{0ux»D̀Dt8VuK"vJo{)CVt{%MŨʃJMͨHq6yb09@V|Sh!97#}&8 j(k-fiؚd'$5%u|'&lGUv$PB%Swojɵ\C >kt.WIo:m{wM6k]ԫ[cUV_ͺQqRXK_P .%-BogK$ڭX^i~Eߠbu:sp*u}pp~R ^T/ }ոb@US ^OB;G hX~\"oxQZ("OS>P>1B2#Q4`W{!,[\oȋ/fSC+B~ ?:yO[/sbDo?CKG"!& .Qn6/~K{P@`'G5;?30 ƍ.1%",L,] cv(O l|A,-B-b99B4C2֔%(/;OʃdHU)\;~(ٗBS{?l߶ ea_5֠n:g\a K<'}^-BmV]^_ q ýoǙ[{a/2Dͪ,$DMzN "0"*~A=EͺpG,vZRf:jKk5SG⽷-ݕ-q 09Ϭ\jI'=c.hC~n{?$v$TvڏCC.AtIX;۳, Rةzwҹ} > ӳHߨ*K ;Dž)]Z|^C%2J8qT*%9n^n %V"߼?L39}e&a:)]V[AX)4Y_F58(LyrfLxCZ}IF9Z%#d =p-(;AHp+5֒סt&b@.cgdU3#Nc/Q8 lqw vkg1 E#E9R5=&?TnJ2LN_eHo#iL ٿ:t _\zR- O C'"@?憅ןK.&>{z7gp]$lʙ;[ A-+ c5s}uDzoh]eDARʓNXc5K{ wu?_UƎ %)fRNt98|BN3@is{d!S1 \X\ g C}iak09HCSSn,wjՠδwGqm?)jÒZcL=EFd0P,'[٩ NZ|͏DJʩl*ơ{C6FGkBocWJQu$+ws$x66ɸڞ L bW<@6MpitM^.^{AGufՙl8tXrRW0Zfn|XuYh`s='xg3T#q #$1g$a܅=\-!ү-iޫIq># \1{Z*=QRmzQ{R %~Z6he P4sl0,f8"qRn"ix1h@?S<+Mj_?oƑ10=Ep=)˻2?T>q҇~St{ί( )iðקP-z/V3OڞXeӭljr&NJGx}o&j,8!CCΐ$j.uIِbCoܴ/gyk c7kL='̈́_$ }M:NQn |tfA|V8eO,Zlnl\Fپ\b3uͼiA"IFݧӚyS@l尅_Cl2q "wIDy4?9$%bWU>,@gSOՎd8nZBU݋p_: #20G 40ߍ&kM0EO=XBP Y83sz!.G*dYWֆLe ԝQ0[ }=waaY}ů wVt um6ukK1p\?߷ nFx .OM#窒$^eݎv)N}0XTb9S',6\O]禝7Sv I[ƍs ߱0.AA}S͗smC#h!/Pͥop'΍ ~٨B8,҈✑uъłNtex2na$iP=l]nKDT=p?ReX>/Rhz NKЀ'Vǎ Jk\a%SbU* Ը.W cNbR)9Lo%'Idyo# Hq ]ښ6uU4Rvx+P7 n2gwnaI<Ȉf+ ϑiݟق+?<#P]̛rOTݯ?E rk86gfևO.!_mxQC͹Qf *1E?Ͽ*\ls'z}Di;O >u)[$`<:ր {*dB=~4SoUD[͒^hw<RFT觎:Bl/+%ROWB 5:3hտkTyr|=Y kknG H[>~Q NM!Z/e CFV_?aє1e1 C Q2܆6[΍7GVg8 g-ZFj)!tkrvo&8%=Ǡ/D0:k,0; ;?Ծg>2RO-͏&Ț,Twb4,8$@:, 7In)T#m!QN$7 ~8'Ocp7NkՃͱݠJӜ-> T}VCnfz%\=ZMKɓ*4zz&ܘY;;+㨖6WuSNYi']ntjdt'K ^iԮF(+yaL̋k|*n bܨ\Tǘm~};by+Wᙣ筼wb27FX]K3iʧS4yk,#&۴ݜd,Tpw.gj [ŹOP5n1݅{_,o:C*۱hjGި Iwlϯ ~k h\px/^[aN86R xkMK8lE/:֡XЍ"N<" c/VJ/8 ^DX7m=Emf";i*'--HÆ P[z.\AUj<_Gd,&u@`3iL.]27iir b4#R~[圄[5sŠznw fVz2O0S ?w7|9d;}gMo%èWL $Jig<>55].\,<͙Pd_Alc d\"KRx希%Ηr&iƆR,Ȃ(Vj4;PaW\".u!6 & IH_B*R0PaGPV ErP`jNu98:E,C8vPS:k‡-il!Z0.5ZBwld{MKqD9i@!@[-%(/#zphXcFtn ƺZu(PPer, vQ m(acv~ 3ܹr/XK狇QsD}epFOME.yO{; #j|jw> F$׹!!ᱣ#v}J0RiajX F? ;!r3f6ֹ/ Z"DZ4>]->QGF܃ :~qh&C[zu9琏5B5NJ%䯯YѼ5С2lv(b QJ q (N {N[wKGש ]\᪩pnoIEmhG9ΣmZޘݳٶ^ͨRϨڥz1O0#w%=Z`mh& GQ}KgoownŦ"xwÍhB/INmNc=4j`/̮bFvP9 V{y ganĕ},Bpig) =pwG;hS wt,6|S3-BO\3U,5^,irޢIV&mtnao*wNF,5>-q!r\!W)J90%[`EAs#30OQq7<4nZ/Jh]A_~& k9C(b_E8 GAKTKC uPߩfE& Zv\eRj#ԜTbG8Qžyb2 ndt\=g 9}CqPq" W LWDVNG5 }& npQZnݬ pWd'g?y75X;,lETJQkqCZګ wu8[۩),%g)k[eA>yU܊GX?l-*B^S(mQ턥 ff_$QisD,f~E76걇`~Io=o)i@?ۯ1ߤ;wulv~v&$!>!fRP Y6SfBmeddX@9$f/7\t  :@t }ek?[ƽ /5+[דh.-5&ѬAe.(S.| Ÿdµ2`/2,K<,vFi.KxqpD.)7Q3 9HlTE`_mID?!gt!%NR8rw&D95_m9%y ~1/A-3d"-:_suO6)y}'D.8N6¥&_Z3-hFD&-P\iuwiרY[aצ 3w\m*"\4MM}ܢ\Kj. B rD8ʙ\4]EqŸ/'c:m0tc^fAóZiGQAKPGiPz ª*N6|U<S0"`c(%΍Lئ;w<ߠ& D5}~Ƙ|m2J$q-pGB6a.wʲAb/iJp7 'T:v2,Y/R9M@95{#sKcxU OQ÷;,`cn_Ԟ&88 ґA*HP{fl% A5jRbvYy+Ƞ&9Ge@ZVļ$ERe9q\dq=b0] =A8n> ;3cN6iߦcz?B- ёuiqAЊsk&Œ8JQtb}HfIȤjbVqU'ŦaH4eO WX LzV5" GEeCF̬ >BXMO 6)`:; *қ,M\H3mNʡ7=CMu([g"eǿr}_s(x:*Fvh97UCS.8,C4\QM!Hz?BX&fώ|TEc"[*z6v|d͈gq(3Ą^Fq _J#VŐSUڛ%1k殮7:BFKٚO:OAg7ak2[L[ bq0J]0Ej>+aq7,h<<1ՍUԛRr»"gx|r*خ*C>p jW4]SFs"RlVaq!PEۦdﰒ,"4L)2:RƝɠ;f3UV5>eyh^N+3a`K8tрK\lC\N꒑Mu&\W;܌LɊѻ Ф u/MkN^Vv8љ"uSՔw{_GQX?W(.*zlTɣIId W^}x&N_ :K9S Gi xJ|,B mA}:NE9} l"~C+$ϿKN(3[l$Fa0vâRsܯ2NIw [Qq쏶ӖKSsF }!M 9e!FFveO1Ő֙=U!MVB\7! -ds} J]/S2{/uuɈp]_W_ސIx|aڀyLԽhU帑_*z̵>X&ZDQV5 `\{v?t: 3@n<c}m^s GuBEI??/|H PCU1KLZ% u 撈حLU{ZLG Ulۻ= FAAٛDJe$m9߯@Oa܌:RH;V\ M(aȺ7,b%/i9T/]x݈e5 h+ÿ9Dr>)JXlÎM oBU~NbR+&o.9 |5-Ǚʸ$!?wo.ImX\nWzJ@ƺQy#@4㠨t4ڪA"_Y ך\wSܽ.B0;>2efwd.t[#_d,^p=q= y}w㛁0[PSv\;7-@[Hjb9JV.b7rB!2֒%;Z+Kl*VCFw+$d%AnH̀ȡ5ާRܘDyI~' x#X2gӼQNy-~\a/kW%pA)拉n dts9!4, 'Hr1"|s4&j(SČ|}uHH;V4\BoL9:!oL|6(h-Dc۫,f QW,S&^Z}E:LEܴ7Fz6z*=z`a݆'+1C9`\ܼ۹ Tn[V Lp,껝\ lt,-,-7%9Xj·WrT_8FUS*@MT#OFdNP$ p"1'Zli ۥ{q9tEIBLZ :p=6.:KZ٭sv'p58w%{po = L@s NN_+'2lx. H9bcB/2wP%_GPllND: qD馵Eh>)Xk0Pv*KOkA c.9Ѧ;4iS\r< Ă$&CQW֋u$lVR'yf=\.7f/ 3#509BșD@&gKvoNR 5-YKmEyyך;-0:PG#H. @P^ 1=?1J3R )|`D@o.(I6u͗VO Tȥk BL8bzku9~kA{W#㊼c3Q0!;T:(#$giґL_`&R  X2*hrI6K`Cx[Q 5HO~\z48Aju\◃v5Ͳ0oKVUҲ4dU5N`5r$;Yv_،gώ:]S]DŽ>k)39˞̸L6iz) ka@$@#zE-T itkYXݲo2rE\>]E4! 朒]|6|:#c//!QA2wM1,ձr˟' ?Eh?uAo I+MT!Õ7q3z1³>bFYcuwߍ\'Ti5tϳ_d3A3MMjr] %ǜ /~yAߝwKӓb_fՍ|4@ mh+&oQm02g{spJbjn-G?٪G)-wFhc_n~)IUWxlȸ{duqqZ.ڠp'vwuL\ sNW(Kg kq(}hl:ٟŲPbs`Z{[Rlƒq0DyѪ`$vܩGɔ-Lu/Jݥƕ/:d;yS|K S64-Q%ΥʡUGE2s^ %K)zA` ,v7/ǏP,K*#< m}0@_uoU ,UP>xzl5hٴEW 襁nuS5Kja MB =u*dcIЃ F"%6Ju8 ob/nsgFNt Pd:c-D;0u#Lz%Vݓw!lKfG% Rߎ{ܘ#Lν8ev/P?䄪{\$:yw\7oh7e-ֽ}sw,9U[DiIW+ۻAbCe'J>̭4X&:'N_ZK^v>Oy2+_$l-p3FA :5hR"`+bMٷ ku6kR옽fTu%30Ώwʆe,;~.{ʍ((BӮKaZU ugSDB={jd/8&"V`\\U !jjn6e98z.RmX{+ˆGApl;4 OIfC9f|\縪kcCz jO%L[NJ]~ "Gv>|.O!$^-_9;Ϙ\Mቜd="v'S?~g5/vh,0Ɇ) ^>IXZ秧TM/!D=},F3cز?dD<'n؈ܸΉMhmc=yr[LgEo :<ч=d]gҪ.IJ kLR ^yf `_2 o ql+^<>yrcG~e9 y ajbo`#آY G4fPpbsc$>o`xTMxNjN"5w_L4̪ [8X]C(V#$.I?n&Q~1*oOK9ϏY4;Y/Ò:/B5*lfyq*fh!?!x?5bLRxНpv=Q6' B͌>/_ ni᜝6B@$o?1韅(YF/ l#b #`< ԈVboIV`ۤazG^07I#F2z-}r1#NLe G̑ WŎR4;68:Bل "ܞx{mڿX m2cqS|jBp1FEPԯPRLc MI,5+,SV}M?C СJ[^R,0}&n4~8撿\hP6ײǬl?*q;*ZE*x8p3/Oຏ&=it$J9 iV&nHUWճP1sǯ8sqQȹʱZ8aETu wY״tmd˖] C a`z+,_75Z_vpYVRⅇl^?hE2jG_=Ԥ7A˫X q"diæU#WehqSͿH!+yШ@-W+O4oKU,t|,Kx+$ᨡ %'oSex}QQK9g!j0({sb|p0fPup} fV\Y8݂Tu$v̳w>T_Q^$f|P}OnrJzBߢ%G 0}LwJpqܥ-HByZd€%]\4qۼ]t}dҋ4Їar dz_ 'rYjE f `"/d!hB> T3ISO% HI3^M)K$1V&:SQoiO&݄Cnnl$vϛUO-Xp_CBb4I56gA Op`۸D/p "67# t:I<ĚM c*śK,7cFغy8ܒ+w4jI&H])N)Tì,\#n-  hm|uWN ;s)" ˚ O!iWKñ*@P"L"2HN|?RY|Ǜ^Hh]#eٚX?@rrf9yӸv1YPٷs]̮h[׹ӣBטTz0j,Ӏ]ҿzoL{^l3J [,\;ڛ[esY&V6iA<€S9wL4|.S([-ZҶ^mqhߧY_ WQUNzeUaӣ%\*XI{Sp 6 cb#A_#~95`s ұVd xtv/֨7<ppjj8E!) mY+pwۨDkfPigƑ$"X uŘ5%/)ƪBNJXz( AsM"~2e~l"GVJ0 I[5id%/w셏]w,hQ23U/aXOZ jz~JPL6e3d=Ph Ntފ@nk½Fo ;$U)WMɓ`iIck|qEIcB KFCl*[ FEE!gz.|$^NV-=B =c Tҝ~0 wHO ]8 ϔn܌@/Ӳ@bMRh# QPBq ρrGZY @a+i䋹b 󦾒)'(sR/4_0B6_~72W='İ5KMz *;?;cMiϵ]-l袬T Kbj]ݿqJ6)y@V^ZOmc4">ў0VhKgk ^ufwxC]Ѐ:]䪃#-` `vGʪYR rhR=;((>9 U*YwLn;~=@&zN.u,8ri%'Kjr՟Up7T:_i6]U ?s ֥ ;qϮ+moUe*E;2!5Jo(޲T۫"o^h(|[ <7ֱj!U-l8I9w'盝L9+$xҽwS[qVc̻_dem|l+g?Zґ}%.e* oRWLO'8;>+P=9d@~݌FSƒ t-]%=p !u]8z= :Յ1Rgxv%\N: w>iyMo#lKs`lz>N6߉ӛ@Y/iZNmgŽ↶*>=nʄ9Q~ OYA/76Eg Zyݽю]6ljq8/PabA܏9wib0 /fy"NK6,DOekjM֋p59?Fg(~a6)g݆!Kzgb2G(a h\\>w}.N.;&{P22鯹`ESkab6R-O]$7{q qr3tpBEiY&D`Z?KLJO*a]*^&hm*E>g8W cw v, 錊NŢƸ`uDdO㗋c˞r%EӶa 9w] @T&?Ig&-0X@%q{䚉E̢oԑo1o զe#=,W)h8Py}1Up-ѷLJ?1Ң/vx+Plebv259~BNa^ VR:x.7C}Fs+1? jn̔>IC%M"Ga O-Yܴ-^b%ϣ-&4P)Q[bٛ?JѥӁܡ"yU@Cmɥ>d[xPx[Xϛw1 ZC30 msEyҬp(Cp5R1Wmbhz`VIc{UV p г3֊,N{ p%3x:7hlx?ZH+r-29at`Z2>xmU(Sa*IKg))^_:Г5_p (j,r(T2SC>)}+Vqw0#Pw1{O 4;/OzT)>D^FO~E*t Ҁt2Bb'1 !<fsoE#.3)-Kػ L;- M+r%B^IنC %V2Ae=81!VM'R lIO(6DZz.$ndY4+h]UdL/|W#\,QN%$bi_|Q9r޳ ?esuԴ{,DChrk \>a| m!6cѠaRq4)j_!?T?!mqL9XWqo.OfKHz_ EW-G#떔oxpG#4=U iM^iHprx\U('O c]xdpb{=S tP=?Xuv}\XNg vGgb=igP$X$W j:L<"/li2P6I8|}ANL @Ftz(8P)Nw0M5=a/AZy|bwH4T*:fVe]F'8C_hM !FFkzLfeUWI %- aܹq{oH!XaW!]و#O93hxj3xjlu ; YrAo;;;$vd-ϵ ߏKEz@Wz*;eZF 6J>"#б +/?ML1ƇU.lK@axn|I#|)ԯN"ϚRP{ns66?d7\Y{IHV0P" jM 6eN:†RN\$=\,ސ9g"1 M.d.7__R yWJ厫p)LP-"zAEaZ-[(iʎ#w_:05Č^J=svLZ6>4ug+cY7z$Q4jC9`nRttIК\ 28?x#%- lLSJ܇ I]7f 1<Nl12(D,]C}X`M-~B^ 5G5#\ 4.*WkED7$ JWؠ2@NBM3}S* ~/*{Exwrb"LH>8&KCrIk˱[H,Fwf%/jJH7JnNl8Wߣ1*'1V(U"-6&I6:i804TU[o2$v-? o; lgoXY$Z rpx_ǔJ,Iyn5}^G'Le9vS&U~Fjew:bRgUM L@ %ZJa7s*Ӫ'4k%yB~=oш5b6aђo~ۏP`ϋ>z,zA-i;n@XIB`ĀbGw1;*J<ζL>'bz1ӬG_F-ƃU R-x7$+E1u: 37*#}BdK#Vg X(?3xQb2ynTʮgNB؊OnYhDc&0#=abfOi>2/H:(w, 7X#HUi)ysM*2gFD'gl?TS:ڀ,ÌDMtMfo2+jaVF~ :zcR$. }EM}.>MԊ$h ΨU*Jcn|KGHiz3\cA1̓8TTBɈeZg|d(}BN2M=ԳE&6;E}n07^m,/6%V~`GXl~޸ŃUmp*~:'`tSH#<vvlخUS`"dGPg1# t?H*1 lM"HX慇nDU*{.ysHC߃XIOT`r ~/lhwuq΂J\!;4q].rSi_ҧ}S_;}-F6\%){*Jx9HB+ƃ*;z%, UeZ Gaws?ː!'<1*MSw_&;\6urEa-aMVh[\9Wț,\6 >iゑ EKga˶t7%5CEݎKX:߮#(Z"aR4if$"f~4UE)\0 WB)0[,g]VD]u7>8uCRr߁(Ҡ8>sD1U0|C6s%M1 l,Rp C5/_{+7,` )y0FxL'{j4 َ0n-H;rNŽI/Lsnr=a3^n ~Sb2ϔWPms)/Xoo+._$ٯ%O't2ey(US+=˙kFiFT'uØk]U)X:|v(czKh٦mqUc~*Ei l]W_,  A5aJw*[ |4択LHR:*"n8 Y=eR*䪕TH1HWU &g[vd F7Hi&a|Z5r?6^tmM%ʠg FmNAELQɧ)T(pӖp.#X %J;/-,tDPAL)"2R8A8X `޶#XmsT6" zv}J9pp[~|G7[o.J όA|_@-eVa k+F Gk]so.V4yrj6Pq3͐;3BrYI,i܎w}!52kx,7|:yM;!Ʋq+>3>MR>@۳ )/-zᾧ#9Pܿ.hCK+˰UCZl@ХJ%:4*}sJrdT=E>DoF%y+2ZF9Q4cVߏčX&o1F}}.n)ʼn_ZQ1%zK8aSe3+]V}]}f;C_ 7EMTGK*Ϫ,7s*^xJ8+()5_# &+͕FF*hmtbi,V6bt6>: J%)|j8e aΨzhWELFTKgҎfc !|/K_P"pB2$ռRaw=^GY19p6h=%18O8Yr)(.RS܆8J-x Ы:Dsfr/Vƴ? 4OEFe`>ŏzO类 vÄ X~,,ѱifc0ew޳~v H%5?Mi=l)^!0Fmh:Dal DO*eaI#8KxlH'3)rQn1=} 8Vwh{[4(_BЌcXOޭ%v_]zL7)v~EX/A'*^jpJvpN3) a/dB"h|^Zq0^OOO%k[6geZzF:[G eeQAc@Pq_I^ĖFy\.6->K^1X39\@jN_.S l@1?$c H 0ZLՌi%-"ĉ1}|6aDj.Y8_JĔ+TmT;E C|"C^w$FԽA!t# X J7]9 (!{qT88r]@l E 8kQ՚ޏWK=݄Y̭Z GtJʟk'Z._oIֿ9bozqmե@ bsq63_C%u2%Kk P=sڡĀ|Qȓ;iO =hm^!"6ͩG9c6 coݒ l&6Il݆'.< 'M#qu*zny&Z%6˨+ۘo?KS@J:Ca6B'.޿d]37b s$ /aHY2J+kLarTWblL#Xoꓑ~9eBf~=E93OwcM"-u!Y/;<H>-MƁI}l%[&C/9%Ub#:Ng]#dΔ)%Qd}U#7vrQoJYRK&g)= J`!߁x:,"jk]nf)kOr+'ݐy@>߶ U9g`6Py?:rFI2fOtV){p2.MI`4*l9Iׇ5Qb1.tGH‹Bi,zI]኷9zi8Uz Ek.6hS>2#,=AT]rr%V2IlLCz -p?E$h֫+& Hk2(#@G.^TZoڲё#%'X!]WR0."2BV>ky16`8trZѨMwG=9IS9@a Nˡn'%TfnDPOr_P㺎@WVɒ+qHs'H]P5k AyT؁ bRCcܞ#i?egqw nҼ|e Oc6bTr؎|۫tz~ҙGZI:+."8ItTS@˲4yEF)(ϯ{±I 3~hwv\(^R)i4a%M&`rэޒ-Y $ I%H}DgwwrDZv nȉ9 &+PqYVE㷐 sp2 RYd}Y.g؅X=ܻN.>H`ï+pIKsšD-)& 4 }Du'rUƱ,Ԧ@<f Bu;°k^o )Y)zgME#c\ y)DXggb  ";ggqz^܎AKYUs[HF{FSWhu1HQ+RfPƛlj>2YO=RV[o^WqJZͅSjQ13!!,#Wb 4B$'?Y}-ϽHZs-À;!qһ\^ۄ"* [/)[4Br!>=g)H\^gbg$-聵gÂT1!J򳆞Dw^suLy'C߈H*'ݶ0!w׮ qKoJ>2w.+# ЌYx2K>2lj71~ m.Ķ~\tqq؃jRX |gvjE5(v(9w '|[A9 \J GQwj=f6yߥܝQ|h6D/߸A&}`;d8V.]dxKrA+8SNXWT >_E :5uMk !9fP3ʞYq@ɧpO2_{d QQ,BTYfٮPHUBw=YEY΀6OnN 0"XnLg|*ܳ|7 k|`V{`,S_{]U;*n",W]Y 3)c\p(ȆQh'ol9|;EH򲝩<UB䲤7̜l#Zmwoӡ5vݪx.BT݅-#]`F y\*[q/:[)җu;G?強,HpG(P7- G[+QA1^ᗾl AcR"0KaXˤtt- XtMP9}OxŒ*䵍C) P8PckoHw™D;S[wDF-~DVYؾ(v7:ǩ_Fv etp5 O08 2#?kIyVAt{ -ٙP8DբRMA&X&ǚ=^Σ9d@/hq,?A|YrjX^&h/}~$c[^R\Jtä p䒾h1Ox*'^EUhQse"ڡ\(/{Mڱ- seE[{hKqlN ll325#2yv({UeS[R @WpKi7çMSpvV -QU$$S3Wܘ?;#+6Xjȣ[!$INŏT&E S1uxN]~Ut+Ga6Z W䥉 8p]%a0^"N%8;^@+NwYDa+N!DEg#dy!W*5/gоF u&\$W M'X'avk]W{^ʾټn&ɓhn&Ϙ&\HǪ7 ms#n(\%%2*Kj|>VZKl@-p~7o{(Д/g#t!4*5;J+`ٟݐQ'qGǩGAw!\ O`,4VO>Cf.4}$@qֽnY4?9xYZ.J~ZRI! VL)MB9ɤȀk)9T8q 46Z!Gyq:Ϗmx>v88k.5gm*0nﮢJj9W?D4su7,z[ia6݄Ѝ:/pqeJWM:sLPacj:hDV`$QRJ/ce>TX)#qWdZnE2]mR_AYPtzLIQDDK$[PmrԴ]H?:wgtԁXO1+- &GX$(vdG _D*c3HS*T`3QROQgCX-0iJ0.('MJJq_ПN=.?e,&WzFj@=&8Ş $0=##$EJ7n/ܳį,״ca}k= MԆ.CJwʰXWW7ۼֶܝ98&[$*o]hNX.n}Ssx/\1}Nkrs(#cpU.T@f1,OQq.h[?W˙mf.Y8*o5f EN:Mp^b+ol{]vHܑm!iGDCe?2L实/3T(-{D*LCN%UG}ҹ>7v`nl-_> SR>0ӠCKVFԐrm}(6,ݠ<ƕVi"pqpIۿ$7\jsK"Qc6T{Maĵ@5f_“C# Ht6+x-'Q`Ѩ 4?VIMB]%eOUIF+XVye0aH "Պđa(No88IakP>8+!t; 7pun4,~^{J>.aHBT{7g;Qv aka$t .>g-<_q~/ZO=DA/Q(#bD|ZVcR (v w|&#MG… J*kpfL.N#?̿83\g#c5Mq w8Z ~ F#,לaޟ "R^/T%q1jeUk6J+uF͹:7i9Вlh(KpWZE#W#~">squf]F3!Pf ĩ.{[jOudmi_ Tb(apb`ٻcZLtS҆Tð>pǝ=ڈѡ@6 p٥@NAɈp'v^`/(5y$&S̉&;n^yh&hc꾓vԅe4L"LPm guE-OX/H g&jb02+2M; Y)ڤuYsOU5KCbmDJ?mRpNuǮ m^K(HqƤׯi/`Su^叭f̸Onۂ q?p 7Mw䁃+0bJ+fF|g0|pfByq#BTw f}l6tBU3c- O*IN_CgFv掇IUq͇B j%IH@A^#$YK2^YtQѸhSl]i3lUv"$u†cZ5$%s1 y)11Hw9!Jwx >jHStv AШgM;os8=.Laom`09- D./4`fKs%]@(j@ 7Y{Vπtae1Ajt1S ~Aqx`K+&5=$I H]2%˜>>Ca8KFcy3Ew;Yhˊ&}͡|mq2Kﺸ,3Ew6|訤&G"{8jR:vTsT*2{XG"wP޼lTX?}7;'DaA@(Ҋ+}T WI'$fSع~Za-HbR[k4M N6zș"X |N"ƚ`{aiz$,g=چHired4Brc~ Ͽĩ8SCS_8…}wF9qzg]2ߘUσfWʮn(P5_p)SOAN~:vPHfj%L=No2+1%X):JStœ ܛO2x:C\v\_Qq$$[t˫FnͧbDE(%XE,3mluHMXMt^̳~6In~C*Rq?:Ja[Qȧ~D]\|؛كɱcF-x;wރ1 eD/;^n(] /Ku2z~Q~_JgG>_s44kLoLw *wJw (*y8 wV ՖII sRهjT=Xos5ht}evQ WW-k3I;ֺ^aUԄy^'tV9_٧iצu+FҼ|^Hޝ[5Q2+bBgWzTI1[Y" k v l")mۛh ];ڣ8wI|p8 Xp}atzGaZehk0'z6h Z/Fe˜kr HO4˩qFA)0{DR(Vƺ!o*)r|Ϗu$MfEt+hEruC8F :nlya ^<)B>~ ~ abfhLF 8|cҰ-ɰ$>‚VygF1ta1'iw?y:Uuen95Ff/^b#}E0J0¸,:^6t 1g>X=A_Kl9sscW)E(@<{.| sP+2w/uںN:ǧv $0(Ҳ2 TA u<80B~`ǾR @&_(w͈#TV.k IuB;B$YYq i%/rR2ަxv*(vb8G~Ue{{\N]vMg nHPg~1li_4h2孴&{ș"q-IUkT8jH|? \1w=*``4w仈^:5&afX04&d`eEAIyFgO\*8R{$=b74Tg\3VUQދFgge^"mh`q@ ']*b8"ViEV=r0z Ib נo{4LJN!Իނh_lŁ:blhDU]QBf<j;At3f3>el1Ӱ(ȥ\$) Y@lׄV}bpKNFVP_?hW}^díX(5weJH^p J,* em|ḡFKCS%4't9-CP3,^VπRdw]:PNI $D(}GP pT`]>\NyR ×80~s!mᜲP'V >*6-f kF=L[q?.Xd uXyAС4:$ű!sSDZQü5U jok"V5| #]]@1޿N#\B) D qC ]IVCkU/3=W$&A8LӅPπ30(/[B%Z25xXRijauS*Ȋ ԧ=@ z#`?>2~"NԽ&f 䉬ȄikR׎xvo6H'JGs)??u6̊VHu0-~w]19ؠbCO",x $5+_'Pb(>"BKEn.2=Q5[ 1 _kiU)ǣl#ZڽJ;S+2Q4챤Bp'4I@XSL EO:Ƽ16vp}ûVsK %UM0@i;Xb4/8DrN~ZVHU mAj8 ʗjZi< ʱn:@l/<1Hl$7Dy"=(?A~D 3 e@R$ڏ(h.GQf2U|OՖ5V%)_7Wq7+dH꬛|q&[Qg_t\aZa /tA˵䖰M \+wOju 3.@ 1 >lʈk6,b'/j *-"Ŝev\ w9\{e6uoI[>2-3!^%/Bb! BjJRn8%v]&6Pk%r3ĊO|E$$Z L#1ͣsk/ qnKfFTr&?wTfBXRk FGkNci>#n,-$-P) eSsg4Z<:?421@|8,(+Z2)e)Y4~huS<)Kؔwo/w 8Fڏ+Ot@ӎ:nk [6u #X|[ƾDژ].ovDR f@|k!Me<gq^[wޢbCj_)rx1V}-N@AAKg'G񇷢Gϫ3x4()8j+p%g \q-SBm|=nnF˴:댪:FU`}4l/zXpC;[vOe}zp1'CAdA/:5$IWf>5-7ZYE$7g EDzܧ"yzX/f#2ijF"Gl4i%` Ꮥrjŵ'I[ |ZX "|\9UڑqP>"4:j t\fp3f"V`Ʊ֧BF(tVO}jT&Yl=BW,\zqFF*7{~)i{(h-,/<샕Udԋ e 3@@AFϐ>dobBq)M&?(C_W^:1fW4X|'{aeL*Y@՗E%bH)5ST1P9e3s?[ǜDJ60{aU+Q(Owy?6Snĥ`);(4bf/NWzX!}W7-ك_kYCM O+@nrvAV# 3:C"栝|yLxEOA+x"5x1N2y2ܧ<]sY@ejÓh7%h4aS`ĐakRwO-WFHSiqwd1`#,5{]4t縈}> t^9=Wddvd}YP0èY  ^3vŁbƿL_e(uXG[Hk 5n}$1<@~HGz,0{hrápOm?>!$G.!tЏ^hœQ^1 Xb?wzlStc—>ίsם$oNqV눏П'11 oE0xR.M/Hy~>յ1'ʃg|!u! Sӥ f':Iwzxmjm47%'R=r.!{Arlkv ήliLgss5};D52շyi-`q3[w% 1I9Ф8oҩ <ӻ,笾ߑ 13~8>xև:p M4 )هJzһp+J13NvVկ|iվ#&-|ձRVx\쬇 Q3/Cöt>Ǣ^n+g~Jg.ԗ)rVkNi9O>brv6& j+s- .1D4. ǘ^w nηa)i[ӻՂ D7 ʀ.]@>k@8ɎEZl3:k{2j;`ZtA n.]>Dctɷʠ7jB ]:Aߊo%ٶQpG=pHTu m:n?Fns@{NY<\D(sz3ƶ|}V&2C$.' %Nloj`hr:z_08J=`L[lw,fG)deV$؇-xz C=dSq=t% 0azT">8`OaD,}@p{H5J"UIkʶ-dqvuGy@[-e r) ꕯJS9n{etZB̋6)ʈG`CW曧^*֛*ƴ.G:vPȬNo1i ߞuOKȇS O Af=y#`B ɼڳ^!<͇Y 3~[:ΫQ3|!BުIJEto?f {V;:>.](9XIb{ok-zsX'־W՚Y'Iv?+s iN҄#R1.x/6Ϛ)d"t+2nUr)f;å2d97S`|5SV^!1j6Y}PQ^;C<_tY`+T9#5Y,frG-AS.>"kMr+yqF#E"`{M2'͓㉬lL\P}t2sBخbaQhNFf.<̣kw]eQھ$JaYc雷M35ɆTy<=y(Zkq8qKr OTӷ X0g>9^NW5=j*oGy/ %!5{&Z9]LU-MD @z5΅|`;M))F#`F~6JǸF]td dQ\ƃ3h'vhT-:ђQK!P{Da[lB♿nRkuٱ:&f)P1D8NDY gd,{ pYEle6)F SﺿjX @,"DR4$>]vM15Ҝ1b|txd֛Obt L< .U/]fٱ4y^WCgU)){t29're/Co*]n6ɯi[ ˹ݹ>t#DU^}.쫌C]/띑آ_ĵuiϫh/tɓ3`ts]5GRQޝ2|`Ube1%'Ϳ86h/:Rsaᡚ[̯qf@\^4@dM f>^_PJ(M4,[o Ձvc.~`Bc˝L`5X$e I:[7_1s)RvAf_VQ+> IlBVf9pz6DUrLejþY+bsaɹ4Avw0QȔbF.[yPmaϧpMЍcҩy.{6w"1Z..p_i(2jG\*U>_!ZרJ7Q5C5i](']SpO }"*=P*?1w IQe]0ãU*Q\]] kra *BQ k@L6bNQ|G8oUS)7s5U%&e<_ x\1oMobB+(g-Hu ң̕:0zc㈗$1)>~qk#whgJRy^2A ->h0i6%sqT,-O=M($6H?P<% +V-$0'Z- N4vGmلCG8Ukx>! 0[bJ[f1W1+ 7ZNaQ+LR,vE𰟬zÓ: } 0H%mF"$Q!$~,mъJ2Zry1@еKԀ#QԮvKdԿ/QPgfC脠}nMNL;U8`TA; ?z*^,ϣ?q [E8l5"@[włSe7+4)YL[(?M O|!iCxL4|@G˜^0hʅA,$EgB窱C翘rQuA)$"hKṁZ<: \'S%U ś.`i@~N]hT0hYvnteo,+UAe*3H_ޥVkи؛rw$Ǯ\s9r^`dRM;qϮ7P@@䠩 L+͡2Yhkb◶hl3˳riC?9edGT>7ujNRkT `f|[U c{λ%(f2](s/,Q ( .ZR^Eu6&x( 5Z@q `kR×y]x,x fv@jA#֭qo ]ss8tNQ}Cdu.>rII|è:.Ӷ@mJPkw끬rZN\!S!GiA(WK}ZY{<6~) b2k-/;͹I-<`XYjĜvJY#9̽5푐gTwL`BD-Ɂ 6 p fALn%3t½l>x_-ޛ~ZUXK''`L4%%8QT'9zDEsHEwn}8b? \ޝr,[$,ETxlFg.&=cL߲1aN0ՋؖJ Ⱦ.wԝ&.6^%ώ@"ůcۡ+ Op;-ޙ3A$woܑRupn"Y'9u~s']Q!2+ q36&Ou@L`X^T Ώc=s@ƑʸKFʬ]+`׉;L'DE_F*}0e2x|>މS9Aa{Y.$fjjǴ@cڇ WU@EP=)h_pd<dVc#ExYvEϨ'8 ^m!IÑI"x]7> X3MF-2Eê6%߈&Vy*ӓ`ulV.B@lqNb!1m9͸[<aRZ@.]@ nHaD "C̿=4yYQP/->̐4 ho=0Ja?nLEj]`6!gKNbJD&d"G@&ބ#l7^ql"t!~I'k.;?ZJNM{&@"ɦ* bA ?֏>@_sgGt<*ڇ >tI-}Gy"iHᒡ5ťp^J[ c逨 T+niAEg:y@y 6sv}Q,?i3z䮖ͨ56  UYx6*@W/ƾwu"͈~Vqq àLؕ7x1Il}t†=>:_2M@SϵsbG;#3et4 .͆WZb]׮~4gJ1ז5 2{{\"_ _ó79}XTr7،sTBNZ^3+&ipX]Heh$oԏ}؅zÄ69_R#Q(d2E ɚ Yy!蘴Yfir5=k:uq_)̚ZAb֞W6G>s2z_Շэp]ꔒQ IPö S(4ېĻڌY,9B?:QiFe_\x^ha;v-)N.7uN)HEBDW[dy$]:IWb@ypQ8!@{ upXm1܋iBcaC $Npj[y]+EK2&= +MnhGRn)גCNk|ݜ|h+ -z6sOKY3"dtZR;MoPH3ȩS2Tޑ,q1)۩׌d MVQEwy|ɑ:cy.Xmlt,2 07J1_WɚL}]-{'R˹ʟDnJ{a/ G ѐ"Fqiֆ @Q<|ޕ9\]xbJ_ -Ѥ6_}o?sv7 s](RMNjZ$ǗUʕJx&gm =ѝW4h$wy)!Kc.{t?$s%iݡҒ$Ԃw^~<2wHY8қ8!U=Xl&bOpr{V:䢵9gk< A̞mT<;cv+ V"嵪Tv7. ]ի""1u-{d,qʍ87T>`$ ~6p 'ws*1n7[)Ah2  UYYJ7,~s%<Ṣ' /ri dgbєc:┩Pi}HSªhtE<݌p+ m0]ޖ@LfV&=֔#'LY'l!NoN(&2LD I56vY+XnVF#E||`FR$M:y~xNVn!uzw*2Nb=o/ 3ܭH !LwZÏ37iH {[su>$@<Qe~,*>Go,n?{0 ž1'TѤcv}dB rJcKg=wA"N =iTS_FsKwHv!=r#T|˷Xkq{>X)R'|`)n%~$fE<. 6iF00r|YVআdYx.ўײauQ+%}P#cǓ%@M $4h$N۰VDI!V [;b\vBjLŨ~¨I| }ra5t}<Re`G;^R Z ֲ*-^̶:ϓ) -7HF\K!$DoTN8GzwV LkۤL>1muIZxp8Uw5Rc$`XXb{=L~eY-|b 45I~<a!b}GY"!3֌ݢp,.:28Hdɮ`海eT3 A4d"j}NW ~~H^.Bw1g@wE*6_xqI#cFR0v"X#8϶ 3g,2'aՆiWK@Tn<Ãp'$&t'ƈ;RB%K2_T%80AYJv.q?đ&,y ;T)rt|𩴒ЎrB8\oH%0 a`0D{( %O6);ۣ #Ǹp\!v+ ҅> fqDHG/.v S;PqB;!Wb!c,dy*B)iףoz{/5|0Oȳe}J ~ϥX91*t pg}Ź[]. Vc㌶#b+޽cN&F#I-(v|)Q7;?-.Gm]ɑN5"7Cp[T䧨eg myi#{#r5"]X%6Q ;$V:I8S?5Mٟ`zAWM*om㽖;-zH `S % ;kPes kNO{{;}FyقI_17ٛz 2<?flu.Rj12/T:(6Ww'% +X(]^LG*NWE9NZۦmtđ!8FjUg đ! `v&mτr;y,q]c&cɅz*>FZuv(2GUM;N8eqK(eh*wx 3\GG‚=T Wc\GUoɻ/NQGBPQUGcC_}-={ûkRrBUP:AS ],ّ ӑܔ lז&NJ ># %Y&z/W{-AL3ڞ Lۗc.d}gy,UK5w<Єlk$#MAH N81lg9{ʪ~fB?U.jPӽBώb l1;}jDa,rR*%sY1kBYcyi)6S'rb\ GxgNb54}TP: Za!D<•9pšd %%j%V`}.,Hۿ=J5*˟ {Iet0:FA(r Y̒*UCJ-QXLJ!Qt"k=sp%\JyiMJ)⏹E0zZ)SmgB.qFVw RVݍ~~hb_ŝjDM?$MKʗ\T 왺NGZ5;nShJƍ27[x󃧃PFL=֕E\f^RVr#7r}gF CǺB4($ߍ%+ }5rMUqns]V̒SSq\t6+^0w2<{7 +ilxb@(ef1R>Bٴ{duk){c`Ë- cm]1 j-> /+H D"!l:4O+:@䃈}ᦍ~ܿ.m!4̘[IVUTH Q&k6ڢYj -s~p"!>I,R͂:9>:eu?bJ]zab:OFEd Gf%lXa)|kIlue3N'?T79Ű'1y'1 ٯYA mN:_dB!ttLxwkk#3QJK)mm/7Y^(Tlyh\U635r6Y~̲r ?d? ۃ+∺V_ 7y*x=D3?H;*=u)snr27#0$lr|^ ASћՐ8Q>YpaŖ,P9|XK15}x3p!_PNȝ? .KPqAUm"<3F5hɃH9%tEg~I eX5-[JYW% }?*]?ƘQ -jƃ8psqIINKx{%3򏏠$Ҹ>ݑlP8-7 =cN}h^̓Y> /^{rGpT"僅)a,a粥3EIO-b!,c64*|kv-aSzIfyCH.J^*e>2RTe$. fT +$ *'&_Uт6n; NY9Pq#n4'V>h9lypc2|d?\RWj=tɔbf~UVQ?> >oˊ>3ŷ)<=t:b;+CNL.P#]Sfʡ p&ȁf"4%#ك\O1L74tÐesjO 1;rdfEiy})_ p6p JjO 0ioL<<5-@$L}r O7ЦE3e/EfS?<@Qoc 1Wt+x)=mL"D=w+wmբ)ze p='r؎x`u[ '[^hTlNv.Ml[Z8с>P|nɟОvX,J.(P xϭ>yX8J8aKǺ uZ7I;Ix(/@?S P]$bEg -1&2i؃9^8z&W ΌI,kBKX<QNκ޶1pvHiXe:O{aP%XuB4}gN+$n@'!bW(m͊ֈG+ؽQ|V8.X nZNMۑYP}Y[̣6Mg5))J^N9ax6eޖhٕìFۑ_~k &NPh3 kZtӯxtJrV|O*L8f82żbDqm^͝}˯O p֤$F30Q iƴcCzBc)qX剝yyv-SZk;81ϖ"AcE{4ʅ̞KZbTeb] N#,(>JZL&UL)UMŀj ~G_ΒI!|!ΥU΂=xp]&:eq| FT A=˓ުzJnÜ-ܬX 5G@hΏjɉJ|4^E+:o)lwy_ZBnh!W5h pI)-Z1jҗIM$L˪:!6:o1@cx|TN3[mN!K&n)y:/LJ{3{:{?Sbub7Of'xtt8qdөF6<?DjN5|6o_OHcLLIJhAaJVLqj,0PQݡTO;݉yD䵱 = b mb'`7߻qUE@RKh8 !qMj3>JU˂93{n 0z_r|RBto[GWִ,vHJ bU dÁ1&uNJX0r+5Q3ȂC)5gƬrTO4_&!\}f]kx4XOS `ȣ)c0m PMd9 YKAoc`Q| L/^)$pY3:`Q(0tvTpˢ%fjSghb ̜۰ \tg)R͒ғ[Ej<^/ %5PcEz5 RYxSȹ0a}~R5Hsx0WPTÍyf="`*T*~XI/q1if\'Π=C˩]yB>:7ȣ% hH^m[K)Z-U,la>-"|-XFa8]Ŋ:m$Nq_)djU孳s;!js!N )̀6Δ.ċ^zfy,ڗ3cduD/Rp S8>ќ(]v+$H!O!wFqpqb1-Ѡ?U Rv)ƢNDP9i﷜/zXc&(ڋ>FCHq/ʓuI%h޶ Γ] tC&ܚ ?Y-%F@-APOY`t c^څOB/זs2s&G'_,n!wqSg>N绗 .ԛ>߬Kt ^8^ʦ4/Zj 04Z3l5)m<|;VFZiIĭ=_.Mt\~RrC--yBq: &л 0 S09ouKT hi _iSx\  ss24 C ['yVR3J?*_A2qđ {VX4vRry߰j3@ͼ~jE =_%b;x'*P%sOٖQ/~Nٜ ckƘZ{wnrg*`/#>YkkujhӮ.-O-0>Bk>O>FA@?~1s KvtYxCi*j'jBWbR10fmFXw|_]+ëiED^Ra O9)d/ukV}u,OޝBg^ѽËm\7n,X_iv7 JKC :;Вec,,3B<IfSp*4ս x]>d-j|`/L)8Δs-,Kt.>rB+g{d09=wSgN7QJAmyfTHČ9rr$̌ C$|[||֝c?Jxh9` 4 qƂdpِK|3=/@)^Wbn)o <6sdr̝~1:87;O^Aac(G=.1c̒ (#+ts[7ѧ4G//=+V&ؙӥ!ēŷI}*L7r#-/*.]'>zjP|_/eZHNʥ# \j0_)>V|$M`tMi|ҳr!(.+)ݗeUi"aZ_n@w!͑.5RsNb/k 4Br & gTNhNJi$Ky)Ƀ{Tq 4ؾJvZUnÕo7`cPbrqNwʴob(ߐI Ke=ڏB-LPnߏEH[w܆G'LZPU-UCS;ezPN;~GLbM!:E)b_GOI54 Vގ540{a/ؠn"cp|U B#n(D]]z@8ן$r7qÎ3xRUcOZ_ hXͩe(y(Oʖk|'eW⻧zd 4꾅z-Eڂ1!lP ZgU9ܔ"Xd fKzU3؍xb(KEI$sfu0Rp¸|G)‰ y9D ގ<CmڻOt8}d 8=bg^U=J)ݪ-EK_YĴ|d:fAt*u`čh Vvy!W2 嫣1Cǀ RrxM'7`>"V&{1;=S]ܴ7*s!>[4Yr' ¯=|TtDFMS9NɨbV£ &&-y?B_kͪވ%LSjS=p+ p31o!TL% ղǃv|ӄ( ڷk9Y.`WxKH0d$,C܁8JEï)Re<qdoOi¿)!+m:ul?[:/DEC li\CCzt0[w#n yxKGZ?:Rc`T+H6VU7avP.skGzyu b8ܮ%—aDdga7[ϼO%Mj'vOmTѩ|PB* 7]P&X3.g,_ Yf(PgLdbYnz9|'H_ 8s[?}#nPʭ$Y \thR7xQT4C9>% 5h.c$b {VW G4Zj~ V4;-Dg:}(\½Xq*yq]'\w(Q;I_ő^ `yosbWX9Cshep7;2aec&i66v"Uu͉2 QHq&oF ECmh%$L3! 8sdd& 8RA_5BFoT p䟑K/)0K[Hak QG9[RU}ءJ40OJ}!6үyQTވ}?S-  R.ڸ}3D녑 fn"J@h c(#w4J" D KPC}t <.IpMm b0O7! ?հQB&.ӒUFhlq&r{<! 78~],=e8?$wW%1DKpw؀zfʻ%E+Kd!{2P6\sOgOKF[Cazd3u>BVw722uYwSs~QYMj&^HM_oJ &NDaYT=Y?w,oph;B 3yfyu1$&i# 1,AO !S1;;n"N`:5?k!r#0>Y%DۈtI qd9;QeVNWhNjqHN){a8GفZ>pv8ކO{lh?P&ȫOvl͎~czQblfPzęBY6>j/\N˾0r UɃ!U`ypUEȖmFlKP>+!Z SRL1lzwU_ć۳-ig>"EY(%7[%`QEY "]B \"'gܥy~qEu0Nfʈ"YmіÀ"E=R?p3L~8 S?Rywd:nӨ lNjj,4R|0Y9Rd>N{3Eƍ8Mdž:3S3gnάC:Aesj˧|{&UǼKX7}eakBתOq^(_a#M> B7g`e\O*n%54zrֳ0G^=s2EF M8>ӵE'DĪb v%JZ[g@EܥdF&B+¡:1؂[nY0RrԺ}$؄dIyu!CyYj/WDI⑨pк>d<8/(Ǹځ>; I<]a}Y0 k큦N &$gR(خdI"0hpr2]!4#*[:P}$@ ) ^%̩#X׃p]\ g"lJ@'5T @7bqgwlvmԞCU6Zv/"?NNJg"Gn"KE펨Wky5o&̟Ehp -觀DT5kV!e 3x|(޺38%*N.[_/F^.r - ;R*:nP OEY<}D֋yyXyw4qD .4n4L1iģpLe6C~ S]72@:j9?a!U;O7c E"ҀxwX'#~" |z,ƺ L\o7ӓ. ;*zD x1:@: Ak}$D9* J̃ʞ(&Q$(WlP=埮vGawcq6Aқ5DtX{/lJMıگ `wk^q)X-^˴-- ~<>>q uq>FtHx}ܬNrn0U*zZd}?P&=1@jvw#Z&aX*\&a.:THj:w?ǫYkؗsL^hCXMHZ,جʵ:(5;?m bzXKD>Wv_冈NEgDvf.Qϐڀ8>yb]fRF!ph)01QЍ~qǁOU}k)p _p#LAq_6(UaG]z"kJCqjrY}@7Mlp`vQN,c EappNK`H5`*ǚ<|Df!Ϙ0!}>Q5&qu *N&MA~%!"~ %e5Þuj2L֔*tbB=ERO0)uHDvsOѺot5y-e;XΏ;#TEo P4- Aa楗0 ˁkKI2 -#j94w|GDE}3@Ona# 8xSx]>L.;C3zjbgqEꆮ ,|JD 2 #۾(l|Q'Ǜ'6q?lI&\jG2\qnTF*<<p!c0k,HC~7M.˟?K=)W& Ӄg{܌\cSͬP.ަVww)c?W0!G&lX@/Q%0_/K3 $F YS <XYۇ?Lݓ/5,px' ~?lxڟE aKW#J+_x}^QXJb^ij/⊹[L!f:5UztCUK RBTpl#gl(޿3WǣgљyA 8l6ep4}%=hkBw/ڬat=,RR I@\mX\4%ũS/B9 O269vEZOSkHyV560o&@ ~'*bCyb4N mG= Yb gn܁X@g&pqBv崏h{/-=%+E>as)Ƕy#"AXuVWs֗D?L4tѕ70"lRl%0ʔj͹@q"Kj^xi#(Lyt_͘7Gucλd.UPbSpU*I$vl%hKi 9TD\Ѩ^cqav>vK0yX;y} . ^ |DAB+/Fuc >ZĈ\ Y;sipL4np#3N:' W=l ڷXDyWkPc_[#֨*>+ęt /ϔ&aqLנJ.E>֛=?;i>+ޚUW A?Ov s|JS+" "82n{?K0ThT`Ap ,PMW0پI>(X0Kdm>vZ3;yLϖ<n&{QD%%b`Nv,uE,%x4lJ‹D?JTz1,?U1Yf'ƩZՃ Pd";D!ZOL{?ϟS0xĹ-'vk?;Ϭ[%5a)!ڥ)p{ m3$k>z X6wJq-ܗYw[c оakh5"s SJZ.Z3mOdem@Cs5n%?1q4#)yD P?Q,y Wt;)A۸xI}YsA\ K젛+n^ <"w%]: o fI7e~_3X %zA힮I{&>~tVDJz2JJd-߼UZd|`b'ͱM@J+ͽ;r F,+ƸzRNo5GVtPIњul,[p=2*>nU9v4JO`T,Ql $h DGԴbiex%1m&M|/ X%VIF9[d|}YUlW_R-OέjyZX/pt#. @XX,ͫ*R!m ^8dQ7GuzL%c P-B &dArlۂl(!B> s?Dfa˸> b.XXe#:ae/%\('T$ 'grZ$.m t b@!vچ vx˶ǘ[8_( e>[MyT%V/e9g8#"+}zZ`sh"3e,Ї%3^lAH1Y9KW4ܣZrbF{v4h.:w:qMyu\gUq|R'Q`X4 &!qK*1b}orM.s% t4Q)Y9R ?&gJKaV<8DY'҉psR:Vp/ɐQQɒsM zR?P^iaߐėfXQLjۋߏy&95ڔia{#nQز$3FÜ.ef\E2 &RbSFU'Ԁ0&+h+L+8)0.S-57 /+QǠ7DXmkdoc,e0Q:CWW٭$4TJp~ Иy<-dIM< 34řa/|MԺV ult Ztrl\SyJ2l{C%-d"#}G<Ke̛C>K8бmm~(D ǞhXwL7MjQEЂ$ۍ4BNɂf/ }ARou$2HEh )64kVZ{b@=Y,`qDٱ6PN DTU}ߟt_'58=)cUW1 &nMs]fL-- ĩ*48&I?$zuіAB;l|u u@\K,x&*OC{6WwRdA%g\vFSUFX@G JR@.Gf[8e`YƊj_šxQ l!-@tM=z";<ձ85)3֊Af_߽ΕP]Mwk[0]>ʲtWlt 3(@tA,)ΉBb>dݠ;tu8qVh*cQ?чa'*^9e!A\[jhݸXAЊ&nc5e,>oX`[2j,\oFه'hEEcc$;w^OE I \v ,6yM&oī#w]{]MY$/<&v'̳Љ #)p--~4s=HqXQRޱ&;7WK״EEHh^i+Օ*F,mF' fd:@;)G0Q}t0zpOVI[H4eIe4$@TIZE5nH)SR;y\dS1?d;ad(uGKm+rUb2P(N>&1_E_<̩=b7:gTlH@];4: Le׊fK& ;j3=Qor y| "/TܼhT+ )sBkLPb|'O汲->nJfYs$;~8vZ ORu,+,z q<-W[)x``FL=|"HrU 9-q۳Gtmx4xIU.$U秸#w(md#Yzͯ чS9Yse9&R ]5B*Nuʲ)/0AVAUy AJ H+XkR)*„zkBKyqC n38 &,|@iz/ѵҝ".pԯJlIc+^`QQ)j?p!}~Wo, f2]'ns՚vAZRЪ[[ݯzm yG˥^O)A:Q{h =ֵ1lqgh/tY qKË/lU>yh< ,HgwwqX\St~;r&ԉiAidڅ&՛D=锉fl <~QF֣FVrIR|0L2b ItbJB QW͡=fQw٭Oɋ;.CQ;+ݡ[_ Qt u-wja$2%~9ͩNY3n]Hk!IEAFJ׾B4{X]oA4#^^2^9΄iuGN&E,\U)F%tSSʆ&uj}kg:%8o/.L5Xv W]ShL(XO@Gb g:>NkξT":)$6&NfL,G~ҟv55>:S h`Vʏ-L?^U?Q.5|vB+͗(mnVͮ:1jJ(YF.[0>$J1ߏvx+{D\)btFj;9\qwέz_HEʃI3dq -%Ԥb5q[JK Ko `Lb|/ u"ѨE[B>`r']ш`PǾv e]0UHiPo164A!vy.{yF'!I-(bvɭI݊V]οT8 ̡{TxeEqHX)0;yh_!P뗗sw`6a=ml쉩Qː3>"le&GwQconV : lr%IKyE›eaTI":'.pGتblNZ"Q}D/ƥj)_](L1޲岶v٩g< {r^gl)=ݟKqupPd%/UjWB$sΦrr djy6:/Lw5=On܀"4,FxqKI@-():slW5R:G[/e:S"!W[Itɝk;S!_gX<肋3U)jL5Ĉe.q2|E[V+i$*7=[Nm+Uw GN#O櫷 3Wr&Yz"qt:"\it4֫󴵡ICM,H#z_߼OlZքlUyZ~!tA_RUSޚ yW@V}g7XvX(ܢdѼK7#+GmASX6IJ\`ܨ 9WMmZ\yeoNT~e\ˆ|A|lQ d>n4b$CKvLZ{Yt"bsRqpaG ->JwtF9#y0oE=\ LI%9 d8ct TFY0a$&6*o x Bʃw #TcLr*KZiM? v[oI`∺x3`{ѐi %\ P9\ǯ`W<_ 'peZe@J! !d.Bb%I3%{ȧ*H>4S1Yas g4j߾@LeTUVab؞&smI# D{.(q\b8nQ~Q3}&fXTHicGD(,ҍڸ8˭p@]7ZyXvZ+b?cϕB*v8cO]LglL>!nqBK(ït5jt %ܚ+޺{Ϯ6l:rR0ٌxʤL'!i̕ʍQjɼ~4AӔ]XUّO}c7.}CJ}Sd^e&B0F&ۢ*EL;\roEt%ك(2aTuԳP4RMa3eh&A &Uevj{` _~N i FY}$Vioqs]FEosrQ0X{'C̊;.EؘLMCsݾt*Z0&RVxʆC:YoPuWc-8$X82\u3~ýΗS9N@x'{<eU1(f4\#FmFu|f)*x/VC2"2zCoW pa ~]0/ JOL묷90 Ƕ? _M2`FI3\ [:~Z\ aTi`l8/no聞!Sx޿% jKVj/Pf SzVbPNh"Z؟r~JpUr [QwG?_@Nj5vyD2hc 7Cvɟ*=Y?.x@TzAV<}㐺~{b1v9zY[@fr&NDhfKZsә+"[,_yORSm =&ݿ }P{lC fN@j :b3",ݶstҸ58!7P(4?pՉ9M;+ d*79?ȕ*e 陏68Aq)Ad0oHz&ʲ"yrmO 1=~2?UzEǂIgohrbD`gGr.T䝗u?ndw#&I;ʩv-w&m%_x{kUWu)iF%WI aXFKͲn>[Ok^qC©>l~L]\8{pb)'i# ~j/ zw㗿 :h{}J6e#V K@R 86Ɯ7`n_e 8NsKY)1taX~DS#-j64 X菃FV0'$՞>uvV.vU P{+9 _rP)>kUcd ߠo:eЯ'.pz(j,i9Td/1ݔʯòk2 wpJD0jS;]WCUQ8 Zp V8Ciwo^[x^04_E;@^ [I P*G]몱VN A"yY ]`d#qӊ^R^Y9^D Nmpp8\.ϥ Boh-fQ KZ 6QyGU 2Wմ1f m3K櫑QhUR7qb,DyJ6ix+w_2h y|À}XwlcYuJĒSl7 -0M@}DU%/c涗Z\)jc9nJ9b 8,jT%0qM2},*{5燮ERnD_mN_U{{ߘرV:. ԘS<&iJKʣMKZZw`: ftW6f"9en~ܧBVL=US- +=Rʜ6C]-OƭAd7ej(.&9POhρYIQ~Ev\)o?=__4hބXPC{1)Mqa7= <q @YPʵϵ:l.jöC#Α)d^&__*V':nF6m#~K0Cד\xʔqЈ&80s\j! =߬+"c%'0INYǎF"kѬcOM,MD`//J=$s~ ^&8BeShk5#d/ j)֕0Cz!1ALcyR}/.;@9ΪqOz iR>lp*蒂R2K9VHf1~ep2C͹nW=ޯ^9i{Ue"S_1jx/, bR) Afф(Z$BIa5~tZoC7<+6)DLa4gd/!ǚAvOXmԩqГj,1{yPN*$&,5]CӰ{Yc۟FBZ&[!@I5u)3&䐣óVE(X 'Rr`1}DyN`5I_˜5Ffvڋ45*۵p:ʄXH!nH2>zʎ%vsLS*n ;C>?:uj9B 5AfӀ &hIm8R5^]-ƞ Lݭ{mxԼm` h0 uaY dn¸C΄ |L?$tL\Qi􌾬b2T? C;nc=Eߨ~!|_,t?YgLFMv3=V9̧<:LXZ!m^,,Wo D~+k/H!RE(f_ " Ẃ"`)?,|`U9+VϿ ]rJ\Nw^Y~g4S-vج[W>7OcU`~,18Fb3 G:s6th:g#Ya>ų@B*Z[A}zRaGrGX%6>f]HFO|3"v'wOUtҟzfk JܲAbeg숱!Ly{w}Lj |8!S3*A{B*Nak y~4D]&ymU;7B9yr}MO`Yd>Y-U&7/Nb"h:ᣰNiY|Cu"q4t3.5$s=B j#`0dS5Z_`!ע:ُ7Ildru3DJZm#iL%$$*.*"i[GA οځ] _WiL'憄k oTda;M"_Mo蟏FG}Lyk@#NN$!Ur.<>"I~X.Z|uބG\jNkܪka~lD&ТВLr;ĴDbfW)j lVn&(IxFʐ / G{,R J$eWZG-Y.<3 k?ҀWN"cfhxӏD# Y{GB0s!FxגJ@pni˽S#A.yeo^vD'I34DL:qr*L|9O,XZ 6g~sșOhJ.r@QvRtBDM2q*E۪ߩpm .9IF-!ݰ<ĸ%yAۜd{llA"sn3At>\2UC8W~X@e4Qh^bw( )}dWHo*z*>RwbEp(PanWa? JlѤr1%*1ɴd:f3K=YppF|اe,MytI#tg1OE*# AZ\N( l&, _ ޺sGOiWny-f㪯7ZBQ)Dm#/de\\@p#E]qHHx8;tnђ`SJA\HItoG&_]6G,ϡ?`Q* hytao-7Y6?s*IɬJd[,|u+UN%y)=NֵG_s AEټL~+Rѡ<8r}| ^gO(ODV8hֈiHl'S{"Y%SL=O6XfNCE*e]XfI_Qށ܍&)濉_a75aypM(kdҴ\NlG:=Sm"/&bgH RE;Zs:I*L+ev6υ}0z9}`~>*DIBiIlgHXʸ8ؖ#)ƏJB{A"'ޣ!!U'}hF.b^kYɼ*Mņr U1oK !J5i\0Y.(&R]A w,MM%(QTIpn eY5ǃp.6O.{B3Zg!ǨMbln=FB$ۉf{Q߉d&A$\eUhFZ&3nN̈S޻RIC%:+o?]7LϧV%sZn-sjvCΎ{\.2?"({Fj@ d|-&@7g {[XK n\`dؙd{{M E q-Hu\ é@NG?. $sW@෺Ôyt 0X-{?>萩2ڏSu̦\cYߝ%2ilOdC1!Z/Z 3a d5`5x}m(zŎCH`5`kPUmVwf3 R%73̃t$rfLِ==j]RؕCj$H]xQbDQMbe||MIbǙ^z_۹yM-z,'l}lr^.;}B$?XOgXH [дӿ1myB//`Rb\BVЦCF= œhv!uwP0d_6Vd!;\::B߈qY[S Vw ΧxmS;`zB8=kŵ%vw}ee7Cvjht놆 (vǛ.eFushzYcK[P=f9iMvVFibD괊!~~:=8 PCh쩱db ljDb<H%3/2dp{rYgMuu9pACٷ0ѫc9w9#H$qO6&& ,gH Oa U=Ug7a#gq q#}.3ӶO!|d{4]TPp1*@I~ o;d`ް w(Kѵ-hUbHKri\p`8kAF<*RW(w⪕JO<ƒ`6V/U$Rdk9[hn(:v -ʖG,єo#P"#PNI;}MS.A% o7,^Vȴ&8 7\U:lr܎%wz9t\goiUw_y:Cڑ4eZu#l*ڥ;bcvͱ qbz= Ѿ zK"݋T7le( n,#j9aބ=Y{˟R1~~-"-fX3-?f߀Z{SD0>:)WvK |(ixDSnq.n@JRQBiAžl5[qa~¾xi(zش0'}SsaԳ $hd(rn?z4x mpy)Cgl9sUwxqab4P mG֐Tv;lH& 8ʑ%6sG. ٯhm$ dKi7mm}`ȳAᖞokKC1A:WΑ7WewjH[u6Վנcv`6S]FF%NDwbq52v_0Q$?,R7> DŽ%nd/P,w/)o9f;&6U<\Cxo]4 b4!Hu|HefѨł[ s,o3uڷP)| Z3Mՙl/Ӱ6^TU($ 2 ۽@ Gkp!/5uӑ7M?l, wnM^#* ~2: :#* VZR'8X?3סTaDu;O% J{x8-(uw*yT$6b|-t 6і-d[;j a_kV 'Y:7[@ŀI"m)[lՠ"-Zf= pQb;xs:m|&y| -g4>V>UgAnT 奒!LzhQo& >-Btz 9bDŇВM\E 㬰uޘf2SHgu–1 |g*X7K2ӏ)Q ;$Lk{-Ŀ6@%}p;sT\\U %T؈Bb2U{5W-ЄpqG-VF~V9#*WAǎ )Fa)!䂆e?+PZ!10hfC-0pϟK$ 1,'a>z K ]jƗ7>gN#> (B^ {k&8oH /d*ō,֣pƤn#,8u-Qjk=D T\PZb*OgQ۽ib̫'73^5Q1mܮ0 h~mDeihm 9FOyO_M:[z^T ,GɄPȟpƆԕ=eG̭GWO9{ ׼JnypxkZEEAՑkb!ϚhZ{,3ٍp/M[aԄ9eO :l ߬%w;fw7DA|!2$=T>ޝπ۪JqSH^|hܼ~2*ek4 X{&46[ ᱋eM~ C.=07!N!dOY)"E/jW԰Ǯ<3$ǦӔ 3c( Y@fu~Yx0WͿ@ CWU6]+0ХLas3᭻yƆCB vI/G٦eG"8y[;G^~f i\9eηjSl;lqh'2dR_RSbrV@3)ԘdJ!Ό䪄f]+ˈܿꏄlUN9tb9c>hMlt`!*ýSsri ͳ.mIA Y9 ai n͇1O/7Ê.YDYmh7tp"Fކ "ܶmڵ?͜0Uղ%$*Q?I6y# u q]SD!뵻+@avǿ̠rK\G^-wlϧR zLB@4Vр$(EW^bwZ]um9;eQ/ɫ۵p|y{dCeLMrF|߰ >9_H:nZ;Ad) tʓPyZ,Y85)~Gm#3zEZrvѓ* eM>&ͬm"VS~{WqI:Y8A @fH I!юDY<wL]2BtZ|헨W[ ?+%u"j`x_Oi,OyZΩ/" !S;m8#-Ca,eqrUMJ ͎=5wb38WN(N! mAL0?Jnډh6VXj"S?2=1+Eks_FL]oO<],J@&b{`ak#DܞOF!(Si(-/U_UqAy25(Li_1_y=^TT6}Xq+3UO _˼oY;M džVvpl_x%'dmG¾G`*Ay/6cԖjIyB` g~/(ljdWivhÌi5 A,㩏MݓRS a؅ϻBw'in<&5WA#v,xXx?SKwګ lR!&eV ;v#Ԇ X"{>}҉H+?aoߙhI;EHmJ v8s=K(Hb{0>ӣQ'[G{&<0c $<.]`SmC|Vp¨ r?5YO`{*U’ol.xnpFTN<}¯ _>!Pd+h0"M4V_{m@hFܫ|,!f~چSř~'X `Ɵԯ=u1IW 3slfRW`JABeWq"|o YQi'̎+WK{Z"ꘗ1gAvn nyzD;enO& ~iv§oWQbQkLi00=m'`'M=(2,j~B o!5<;VhlȊlw"'-,Y`E/05sR ()b3R pvNiqgIo2+ن5ZcXYkIpglzd۽k&; 4*,#V*޺2?LMD{lEM,w@gc.`K4[paڡ1XjhH8>ySxDYNށ;3{5)^]Eff?BDʎflMB#g"-5 yĻ~5ʤ;Jd2-7ӝVAZu7u$F?8-3NYDל@A>ܞy!۲C4XgPoҬVOJ.nI`PفBfEK\{!Ka;M-6Hq1|p= 5|~Ռ2Ts_Q lWr1inxuVR,q1]1n ta5¯t|yDn3ˣ.[E"8ZeH 8LVDq-+G }ϫ/J0N+{&Gث&HrGNoF6=dT@Bvw'y=Ǘ4P _OHRRE,v Ga QogrZ`r,0y,7cWɉ_5+/J凱OW?L4j*g#n|_tioy (AvqeAIhvs'&& h"B#ҫo<'c sB,BOi$*q똡99'qz&Fܻa?cR%pro^(iz;": ?mŞ2  rt&\6^a"˱^^?:q~T[ۏש45kO9s'br6s_AN˶ˆ}r.d?'ߙy_5"/Lx(,>T~Je&<8y4>et<`~ 9FM) 2h F3*X&'Чr?j--:x ).Q#87@ 9ǹݲBZ=者LڌzPL;iz#o۬Ò1y~=D!=|;U[hpYIHG)f r3}Qu] Yˉө^ x>E*|4ڹ'Ei߮f5XN2yE2Yn ^AD2ׁ:[N3 CugY*sb-V>l纮:{.>u"aX&mHYȰ)`$,朤'kS/.dls*j_5%\/[ _D!fNMXFۏӺPH< SbdSXA 6ʜAZi.y@b 2RëG9H 2pfxߐ!Xb:%ϭ꾋-* ^E? J촢IY3x67K+LE8!xLId"J06Ӵ~\(l$j50-HmB59ӈ"_ȅ7E9#wNq=yf`+>xƀL %΋^-O'&& f% zpU+ySg xfp?uɥ{+lȜ$ގ$y豀wl9%_21YڎZtњrMt o<&umɣcx+=@I>:^UT P1|&˻P$;Df{Ek!㈐POKwv.OT?}a-yD!]8:7h n1e]^ҕce'ʇ2C5Bl|r!F^Y9`eVl!8ʡTk:`s^KF6ޜ+vj{EL^Y z09rbUǾpAz7!*_WcL@lv2cp56NT4w>sk7|RyvokJ%2JJ{4ΰU~:DZ=wh]XP MK(%?܇;"%$1q`CJ;}X.v5溑]lcxK`;eOH6xX]ֺ7HHci;<`] gEM9PcQ~8WTD2l] bv$Yhh[$  |82V1HI"PEк.hē%gb1Rl Drmz7LLO ML&!9h9i+[1=x9ңi\$X"وT< 'XGp`lC dEv6: 0Q|[j Co@aJPs yH@t@8;+"&<-Zs+gPk8 69g:5lo k$n閁̡a"L8Oyۡē+1HlGٮ?4n0?ӖJŲTQ{O+Ӵ*"¥S${C{"eV_>nr?j@=˜mGpqYBMW" .o*27Vߎ/TmrfY BͮL*}U@ +ȑ7vGY B#4sn}.Jt\Xi|jo~qM$iB#uч4ڀ@7Zh]~yCboK%ы`7E|Q_v3(G||)0CݑAfizb ZkAw{t bY-;m^3kЅvہc c!aG;v qVjYgDͺS[olPQ1ChK؎4U4C-~=$kPs_ع(־¦m}q%N{^Ņ|&l@cœ2^%YCi3j&]D,Z9kx*32ޯb~ ?mnq<#poaqInLj|R6  mR8!`ы ފJP |A{_oCM86ld4Q@:=? Ɛbů6TE_4%O,BxfDND*OR P.7}qg8SoͲD8w)j+ꍛ>N=Fk &tf؝b)?wɜ kkY20thӇmJOj$ls˶?݂ЎBTDs6̽)Ƕ%洧tappЁ0gO~=,MٻY4a~'dؚB[IޕMmդ#vAd&Pj弒&99JtM5LpK/DQ^ ;DETXtczMe{#pJȽY} ֹ a-77*i9'v7@7 ذ8;<x6ZpfW42v&yM c8AѴG/pRy+'︂WeOY/ģ7`>:A&EʀZk A|v*`v;wL$RV8Of >20Y},TO}nEOoѵȃB[NVщjђr$us'QKVm,9 G_y0h'9?E;:q;u\<[4mf7!~_Wr\ ^lT@zDUn#hzlLH*CX1m䙢{cv{,Md(M+c ^!cYiH  *)o ߙO%(TF:!龦<.ͷӏGƝ\,X`s[.[)]`6 Qvd5լ2dvϑuߺ7՝͟6@W,$&>*P!?w V.޷*V`Gw'n~$)|=HeUhԼM_א}mxwT%`I@iws.Tu۹΅]-~]AJެM\_{5u]7L|M1QTa5ȼTDCp=DEvdFy쀻PI'(Y?V魓%`?"Ӝ}u .8KUCɢ^hV?GGl @8K2NAVK#,/">Uu6Dr00yD۴%Rڿa#'8c #QsE2Lrֹ/Uٳ()f}sQL+v64ꌍABKv%l'2Awx\W/W:YRxYCi`o,•'f6(B~*S!x8ʘC4L @L'"N;CR^'̿c~mӔ :Nf}&O ݀_2I dKV}u^]cY]oJrf`ӹcpi3 I FJfG8D`yɿIBo0ջRe!s"JX`ܚao@+5Q+]aFF+<;g#S9fn<8„gw<#csiz7L@YL4SNS'7%% ^'X !A90J} f!k/&fU tsC&8R"!zq\s\VwY>j4(}FV8Y_?vk |17{ܨD!YNF'# :h [a{82a K0VCno¸n39CzB7U*-̦KZM2ܾPmT;K*ڡn [+E-gJvq^޺!MGQwPo*C8Z 縌cS&3h~4” tw3n"Q.BJ-kOںjXgKe?p 7A!xrFKoFZD^E1I\o#I^πg_%č\:̀@4d7l^ԵTrk3 `6hяgQNtT}W=:\ͮ<~vAB׬2 ]h6cևRwO=SQ1 eI<0-bF$+`:rDCo4zl(n%ʲ˸6/gPW}6aXfuiûUmV>7v QN̬DmĬp (7,}x$נ{y ps|Szt%.i=NگEJ笥&X܃w9jZS7"뢖% ev&$!3,]cǚWp0 H8Qn?nr^I*bvsِ.@v~.8%Ԝ]Y`ǰK3e_.6uXd%~?s{hf&yױ?<"lƆqgT>ӎ?Gޡ+v|>.y(AW)%i# 6fH* _]TSPXbs@4YV#8d|YqYQ~ȸWY/5,lyP te.쎔sq6}`K -!{CBFwc,)OVf *#[c8/ NbӔN;f tUOE,+?F/6G(!ȹ$å>- i5& +;CrQԉT31@x9U۷&Bh L*rzJ͵j|?5dyڤt+b&vE6z{z[I?o/s9<4&5/1׾gBlǜzD9<*7Ic4߂ 9ϭiDA~gV[tr9C^2 E8)}\ߗ48TuȽ*xIpc0AUᬰ\hU̾^PQFXIh&q5@.|Kx0Dq0c^JYU2<h BBY{XL9D[ k衬MӁJ_0]a2O|~n,uQd IAJMv]lFeb+7DL;MXă͉Un|zwm\'baY?[8HDȺ+aw*WE~Zmǻ _:!4<6;)a kVA(˖vXFԙmE.elk8~YJH{X cWwCV'/>VP'< qAhww[7<}W3;:+S刂Ue!M!xv[qE'6V=e[.>e eS'Mڰy[JBӆVS(S}װЉ;FN/^DBiR*q˜< RT .u* R߲J6_xu%H?&c6,Nt;dKC1Qu1a|% p+)Q=ߌ Pdl2ٻ3< +hsQ%ߺ0Ea}lG!*-i 9pDn\ FFYY.IǞ #6,~SREDo>|(u Rc1V.,hf+2eO;+sVTlϵ(ˡ3~3Ì%y/!v sO͍w"h:d tCwB$pEw"nH#!f,M6XlvcǨh& %';?U1À4DBU*CPMY&V[]÷LrOaDPP,Prw:2Y* ?:l kR{F<-pP|"p:15 @ю\Tn};,f%,b$(E&`_uh/BIi|ƚz`:TNx3\h4zW3)<noy篺 ƣ;T[YGOj(C-U"._1K<:2,|?sxݥAzaʵ;15ksO/<9L{)zOLKV @O%;_qٰ7A`W"m7v4h8F\el.|TP& _ХuZtP,2 &%ki%EX:?C (be[n öf)uL 9,fͰBD j{1cps,VE*@9GТ#)(, ůtzH{o랪j YsH#+|-c`IJwM(+`5J89Dy1/zIaڰ00>kHJް7H=-Qt~D耷O{]o˅,{e-׷&s EԳ^Ұ,g"ܹ_%V܎w"?QB{[L!)쾻af{+U;Zt0e+Mf lAZ4N6/"S-2IT [;䦆.ӤeK;5NUL3s:鎣dw-q#j(Xf科q{^p,Xu!Zo/\zw ,9XkO^xhdg9RH򀑡x5 dOŌ!ں}I.h';Ip8-,b<߬`7![q?a#GR>͐j}IυZ!7 cFZt>Y,>eaΠ%(^'-~!\۔ ۭ](?BS@8(TG~ D ᅴ4#q;Q?=MQTwCWfcbts8rյK!T7 T j-N/;: e „bbd%@ڽ-g'+~3tj/CxO  $*v*U ug4{SQ;u1I)sc'~YIf aJ qj~ [U4Ś¶IYiEퟌ_tY@ɰvˇ <[Ԣ^R'5j5}0((9ѹ;PvR=\edDKڲ(ݘU8oyEyK"8ߧmD\ (1nn-`/~,([ti:j<Z)ף[<-ˏu&i:n'֦qu5ϖ4K]l^!`Pyb4*?9gRٿw^j+Jll\7{83\ZH(U+${TBHiF=YIR'V٢GȘ5:ɰBr(:hrY(;t>'Q==gBr^Vn15Nx +U"|rӸAa*/chG/5*o~<7%#Z,Qj;;%:?ahV |l=lж/U`ydldf$`23GKzTeTn6*ǒdc?NM_ޓjy$WNu*Ƅ:qRAβ#-+6] -.y+6'-- v0p?CA=h`pIěOɘs~=ǁ!g((U~idn.Cg T+e%5EG oJOa\oYVnJ O:?@nl&6*a;g6Tuqסl2{͡MR7KM(`xVL_NAf>N(2SrvUZASgZ\V8?ʀF܂{2Һro"f;)< ?utLO$4)0;hZB5;ܹ4 ؈ m9c6g&^SkGȦ4Կq7{ɸCdI&V k_d0x?ieIbӂLG8 GLu@BLљ?Ðco!;qSmbUT&RO5s69uWшq- .B'DPY %^v,ٌ5̮LH8-BP$,-Ǘ+g>=eWj_4O">]X1Cs*ta-C޲zgmˋ$}_hVmbNnFxc(!ރ.&a% P볲}j@5zYYU2Kj?rdGĥQ3@̗cӄzsP]X/g᷍OFKm>^ԏ+i[' *ׅI“4hl#|%> K.BD@)NTFZaQf"ϛڪ63GU@+ @ 4m,!2?ː]\)x U P<( w!/} MfXl_5ΥF~/XL[ٔ[\r  J|ˣs3m&H 9"h).Ӎlil*) "}TeۇK V['=qmgw#H1Q^N} - ؛gƺ[rLOQ\ѐuZa [SS`#hۨ2*| ,zZV*aFz;Vrx>W [5.d_E-: l :n ҘwBYu,DRo.3PRr 0~5o %6_izk-gt_,؀}u)Ne:'po>QSңT{uIOE):X"@12ХQYm{R$è zk)6[hGVG 4'w $k?5C@y;5BFfia53ug!{814wd> ~q꘨sm1m׾a`Аu,E>BoS|xN7/Qg2N0wcUJ4#S8o= @G)zJyMgNnбv26SioW*4f@N}R LuɊ*w?JYRI?~ϣ)Kne- au6GHxw+ =1S<>1v}v)a.8vA/*bquQL<$g NYM ι/ GV–qk}e>,:͊u֑Z.+ԑr{1&3?I}Vs޲)nΥB>쒍hqGC g1rcϤ'yā!>H oi &n%-4;Ξ_MW>e)Q&srDٍuJ5#Yg)qX߾&p2nhPgiX%cʯIf=Qy@8d^S@J3XVJs۠󞧋, _7d%T6~1H%PSh[4_IU誶hAP;[aehXL^uw]֞YYh- 6LQӦʕWаgmYiK L8R)T0cPgX;U%?Y'HSIMpy6)n6؎܍5_pfN$WZi ,]<L_IQP<0uxYғ!9_HrobSl J%e9@hRL5n[iafOExlńu&?MķünncYsQk6fI|4Y:zMx(zV;:z!T߾r)g(+wѼ%@.1V Y;v9{(gt~'bL ¬C |?NOCZo#9@<@eMtqum;Sv. [*g4|9R>3p~9@fq>0K[Q)i)bJ؆(edM~xaB"@˩3!n* \ՕRx֏zJ(n U`aׄ(㰵 43;O*RSB 42Y%W諹5j4|_cv4ObEiz#ZeTEאĴ/536!HݦxFȐm4ɵ.RJԲB6Cz- Զo%<_]E7#iB+ɥ{ŋ= N]&D|) --^X{EpPxkiaK|hy#̛ͫp7y,k-g!y#uT3T-JiXj}]X-(*ˍ*Xdz= LN &(.90pC'\uŷSP\4ӊlj{[߁#r!`ށLL-Sk7ižt aeսa1\qexFbk1ho2$^|=fH C j[k|?,G;[:sȵMO^-B0{ɽŴGU㥀f :޸ǔ%-GM`K5>RŸVR6^ %u= |yt,2#Q uBo+="L'Bg*O {bJ sUl>|E-;{QJdr?jp*}#OZqF[H{cLM7 N{JSzk949Zv%I;o ǐ"W[B曤 +%/ef@ !qPy\`jG 4'⻰AZrH:]osgu8Һ]G 2ɭ7֓/z7aknXhmqݿ.!590FO ~Ɇ}uTP-,tuY%6FWu+=)[63EfQԒsX'a0mn-XdT7/WRފ E] P};U Y- ٺ|:M6H.`(@{xI4y DʰIt|,q UlHHz!τTPZ4V!tB؂詔ZAGz\+Ur[]9P#Hy9 @"`|S;/# }#:* ^ T9u1ϒhWpsbEgeW}0GD|Q=d_GP {8_>\ҭs,2+@Ì!<(sC+ƿ z;sh΀ծYyB•jdO*TE#&bPNEgsC0x\p߁,mJwi-y++ƛϴ7:U'1EsK!|&ZPM8nf))*a jIٞrr90!HUrx 4=6u#(Z:?,Yxw3{@G΍ά0cc%Q(~Qa~`ʡ3el=*n}ϡxz?^йy' ~[-vxl(cGL+ Z'lKWҳE06c^@qz~TQ+grc{'LdMgi~9K+5(jZ0pW$zEC4vl-úA%lFjN"prՌ`9m;e0U;}{u] -Q=ے#)K9gY|U[g-I/3Ӈ42LG$!5J^9nohޜ&)eFM fByU_ץ80BL2 *sN\u}ZȪqr5q-;9aؒ<Y<ԱSӻGoŐU#<4IFK"^-85-iBhZd F /08x!~2*0XX.OO\Lt]^Zַm=XL6 ]`fu:O  Ί鐮RA,c %iʴόpyq [}Il T~)OBrV(#+*0R 7<-/}%}.!1 YQ^GEǥ!MaNDP (>f/wGǝK DIlEMQŃ V/!ߞ#'|Y6D~SCb׹|oYlg-gv2d uϾ_OFϒ ˋջ"ȥ?`ۍg*1DU$\$sePn5-HUI+; w[E!?C6``P֎*\=5BUu!)N&5A&~!ԭ?>W9}c(p{~rzzWx3* M*rrLm&aF"katAj%> Kx#fBF8MXvKvP\Q^JReoG;󬶜Hׇ MopVZ6%cޕ%L#~1JBW%ɋT´?Q% Vӵfz],D!7,muPIiXa?Z vB*Y!>~YƚLpݍEkB<<^E[k;@B;cqFo4ʿ]7mBLVe1^!X sJh1 n6;ms  eŖ4@įsS LTZFŒLcK/0m!}; ׁ)+ ڌۂ }Zc`iưzhXjJ3D/A0Bi9@yikRY+jE ›n'R~RrLae1ȿyٌ\f_nC9õh*.%eS6bdΐ{*J%@̒YE/c @"#nwOy Khi+=㏘~iMaLK( ;-XY \Z?'aHYa6W$d1V:sE R҂u%G˷b2Mke،m mXK^>ѩ,H!@jkrsyh©v.`Dh~~1JܺͮQ1D|YbH~p  O11I|/zlᔌk,[%_χq8PSKޙ9'?-~=  PD\pXDJ# yR )MI80|qR>cGU\H?8DHvq9J%d!l!]`BX3 兺RSu"\4.jX<_]FIf$ _m4&xX~-8sB>hhGKU 91b&ɴ "~C vg,bJ v@c&5$,H?6gҟ8%^VRnu͜!4‚o1 {~Yؤ@HV3dW.|.FN _Kώ82++%wLEV K?JxPfs.>Pgeu|GXѨ;}o1yƺBM~UJW*Aay_ӣPtLÎH, r/?)?4x+P0x!P[?q'dM/ ϣ~(ƷiZqۖc }D{4f_I8A¬W3=UQukgBĠ:?O4~8}8+"kŊ;p^ ϔ2~ۓDɇ> 谠3TNw7[b2K`U')/21fVQ۸/$2U#9W >l0.׫92E)SRxܓ2QXr>-x3i|f d& `ɯ:K4C9ޖ,$% ; $r[En0s!FZ8ۖKFp6/cƊ1芨'-G.uQl_+j 蝈|yfLǡ2=9ǰ R^DIϰGM0cyY JtqTBb Mxw/'8jc%pk)^Xsk+2+ddaAUK)5g{. ˈWw;YV,'wQ@;t¥g^'T_ᇒ5aG{M#ڝFLl\m]mFW&)bUs>|_ &*5?}2ϙ-yb 1e[ H5yD{fAEnv0Ps(ZK06^Ix-:J#:Jtʓ cnQIc TŬa!r"DFk0Tw)`=ZHwXa-dZWoZ}[(Wu_DY6}l25f`~Ix22wE,Z:V5Ԯ з]{ټ cldwU#p68Jc.pYNj8 LfpApc>{J=#B(Y+DҊ@^u&f*@!--kƴ0t7D)G'q@ aFx-GszEBȺSkPg=3%6/:Zz)fV\-ֱ?rL=0AFP{=HatzxFi\h9>QbeV^si75 oQbej. 8X:[uҢ7O|b/#W/`[9:ⲔJM+T5'հ@QҚ(B&z $"%|HI<x8zDdGRs6(ΞKo|L /gDwEs0oҠJrl}›Sjޝ'e4]Hj5h%[kb@÷Y6rA!ӍJtȱtSD0x;?_y6a&En vd$,_8H$DH7!Om:X/޿m <03U dIP2 OkaDH`etT9~f'=߭ OÄw!6idfgs^.M{3bXOg:exjS~0RlĘ(;?q{ձ-v_xGGMBiq753h>wzVێd\0yh.8 w zfJ>IW;6#<-{#`x5CߤKWi2܈%'/>CDI+ښ(m4v]ijlJ]yuL;漅U'AB&Bs=[ZMCga [0$6K/2alOdAc!ԗȡp6PNZ6ؿo}m'fW5y;aKPr's>҆v(1FL›fp\ⶺmby2AY_yUt Yu?7>z{Tn)h"a{cNՃ)S'E!鸠hR V"rv ^2r;0N+0.5 BO̵#+V௱U :34߻k颣;ј3gJ+҇>RNYORF4"+Ub0^7=>*Or]Ⱥ*K pٸ&QuzӹM:Q1Ю k޺U#+WdC?5JL`^OC ~XRInLxGG-À1jtv6ajYSbzP_|= m0 \a]>2C"]>jl"Ŕ,p-N^kVX6'Bc?RٽL6JA u^LlT{FcVALef{1RM)8!zjdM"K8$2 dCyD)=v"ފ+~_.ix//CzmC+a6 DJZk)Fx vw-U{YVisW孴9981 o7f Ao ,TXE3HP衱TϏ]}j@Irh?آ=K~tyiHm>Q_ ۨ4A-BWI%tpE0$tKA 6̘_@IXC `TH^ 0]{F)LN3fO401)Bʸp"·{ؓ-zeRjG?B?=?vzt)kCLQmncq^,8E/A=왺fPs"'<Η] ǭڎLՏr6׻Ŀ/F9s~`y@^=] mZ:!AP-.hѶk6L ^q|*.d= kJrCh|lq'6bmQ6V 1 "nH8۹!y4(̴`\ler8f X n&&Zڳ.XHJ嗃lZ'../FF0865|TɻEXڜ#O-MA1W ]0 :лSE-s_.<8tI=1Xn;Xq k)C/g4e*zyTR$z,Th cx!Oʱ4*i+:vsRĞtVtP"9_Kd[sN+[OAݦRCga+}aB _ɧǛwcO;K_>9s=s! F-He}ԮKX J$d|i}DftQ BNU vGp*%>T ^ڧ,{uiC_ ´kHZU=?<a/=B{j'2O1`8|ȌD9OWO*2|c*&ƞ!C'$AdyGT-RfR \p;Ak5VO9p aI󵵊Bh&scvF+)?-CS%E䯇W<\yifbAd#ާEYOިq yJft ]KKw`Rs7ζ;!A.Oj`mHJ&xFcB+ȶb8UEI螳'am&ӱ6@k艊sQwl$I/cAE=RbŢB^QhxNHr۫5,Qn8zEq??y.˯B9y |zc [VMp!7W'W4]Bc8v}ucaex+;bg1w7P|;:Ksk%uզr7gf@:5e5bluï[ a\A UxB"w@n,T4r^T ǒ.'팕 꿈Bf^YzLo~˜UNH'p4fht# tShӆku[L<ˁrB7,8R] -CӃG "sswr6"ؚ@>|vcmIBCӳwsZ\ E_.]|!b[ԧo=5;vҰԑ,%e~fܲC9MSEn̟ PX\[ ^I+M%sr|SnD(#0E^UF 0:(t.je‡MvLUaܕu ɰzEÕ+̌`,mn{Wci"OׁlvJd#چiJ 0#5fKĹbPN<+TLWPX1EأRY2 #39͜[vV1vQm0=DMv|T;8́bT$0* /ޢDEq uT J4 /,~K3WAћbmk~ S]XlGF|r09\uč( ^HeliPmX[v,$N,JV2wDJB촮?$o8H5xz#x l腑[{znAܟu"z<8E"AiB|t)حH9[ŤnAbCGDr6+rΪ;ډ$pgO~Y?}mҖ‰;;ؐ2L`@r'-rۚ~M I~gk`n~aNc%Fбp7RwHZ2J[na,TK'Aፙ|78 M"CwyoN&*]NqD[K| 'N]O|Ў)ogyB!pN֟wܢg`.anllH l\=Ó8Ĉ}C0j3uʂ7 ^Oٹ˥}6bsXdi1wfe?i KtFjJNW+QRmB )>Dʂ\1Zȍ<]e2WDOQصv B yV8J0I:$quÐP [R(qW#4BH,6"iw濗MqoGR3E͇'i]i@FC(:AC6xa2锷͂Q6^fcȝ c6SՀW<\M)oxLV<ڇzxC`>G gHm(VˌMܬ{&UoyW`=q=W6\H9_fVڣGj˚** };)@: M7lݗ~K&e6 'ϸQzyv e Ite!Zbn*0(M!V8ҟcazm<UC|{9w*'Y7`M5>]Xʅ& e#Svǭ-˷q'bVMYpufQYKYiVUS/֞G4\4a[Nx;7˲ ˥qB9>7hsb7?' { lǭ&oY͛~@DZ7](_KS5aڱE/JeU~l8 ?Ĥvz ˣQ}¶LּWceV6(㽴z[2c  :ϬOz#|X^Gn4(r1 Ok,yV#+t4QG/F 鱩ϐ;uT] mT ~APBݻ0N[Rb[9BY"Hw!K@ҾL^!Y|.{*(w[J{0q::ˋ*ίʹ) M;LTl:x"iv䉳R!7 ׇOfIp5m|i%|D0NJkdw|.j)/keH͸U=R~0ӥ&M02 ]7ei^ޫ&!@60:!krm^f ,U a6ۭmCnX M xM14#kA~ih0Dȋv9~+FSYpBjQ$kBƴii [n˰<2 :i6-7E p6e』 \[׺/}9d/^kZSrmXݬO\ѳ}#_xAo\1ѧO?UGQ|NΒ1qMPZW-q͋iQs>nF#f@D䖳nZsIdt*, pBn)U7NlqØb`≻v=ndWu$^\?݉/?/ \U(jfB쟝UՄj0fl(?3Y$w2|"x[-j <& A$׶xyP@ XFrjY,M2xuY#@l!Ug'ݣ@2X9޳;2@&86HšH!aOogrO=mH"?ý(B/ }7N;lh}Aa:#`)yCf" !.dn#q -(Y2l9% VmӡlRWڳi?BuH852L/T3vl1z ;TsFrޡqq?<;tb)ym)Yp# -`Pߖ8\nm501ZTȕ~F-I !l I&@4IIެ}=  nd"f9I>)֥`$<{;Eɲ|(8F2Ryiج1CՔ bGټpsObL9:bվK~FȾ>Lc[{6 {H:y\(ZOkPFfo*% 0~*#j+e.]\*{e*(H=1QqVnLIɽX5ouOBiZeԖ0x&pٱhhruR~/.~;y4ݓV[VYxWr`XZh()ފ] /ttX\fncM$=ZL "09r!iNώUSa qVa_hd?HiK[&-4#^ʙH_H: 3"N8){iCJzq~=G#*(%Hv\~8ڑ9sɀd Iֱ8ҼW^+U#g?>?:Y$#& `<2W}C:;Ƌtc|<;>ɶI.n7DaRi=zWy=mO\W*(f`IbsJj#]T4a4U7G)ypWjdOU?+nDeK`ߩ㐊MmbXjr˺{l+Yv*H*LYn@"|ÙsW&C>Y:eOY;ܱ}K ZP.mP%6DwuX,iԐ׵[̧ )8rAh8;wYckofQ#Yfjw;`W=țapLwRrK++U|ԺѦ<.Byn 1/e%EM2FZ=ȁBz<5]SKWN 8ߪ 8/5Rb N`o y| |W=0"BAOCLDSsmq{m^}8_\-H:璞9-~eE& .I)n+\]̙,3$6'5)*E[]gᬘ_xN7]n<0k*[/*5ܞMZ|c|^^V wB "dg~%8*a|5oƛiA<րߘCeUL2<3 3x(i↽$ٽuЬS6cͯV;Hvdoe^sp[&:L0'-3$yT(p;+ތbo5@"<|s+}4/-5֙INIH('9X"b< tT tdody3~$G'e;|>t~!kS[ȝ f6OWɲl:@Dzm@D!璕6ۋ|Ձ#گ5r ̽†!' DohEVavRNhRs+1ͫzVv1\f[@I)P:(m$$xNIUܵ7`n98#^%~$~-e:+!zhvB N} 9om5*[W9H%BaR5o䍑7y3zb`p^Io J;\+~ Z=">d,28}1PN xX_^Z׼Śn GKM0o)!\ pr։D2* {rSzo?$7lrR AtѼR%޴#llkLs@zCK,6K`0&T/ʈ;WC^,)wCb\gW,8Q'⿏L\;2zC,Á(8q̚H`'9>r.! \aXHgkª--.nT]% ?]l%i-jC]֐S#X4k$!|B.?D>B[Coжl}1cc0iz` Tz̞tBr?qֽ4ak! F)(E ֠o `  ޗiA䜗F3|fX9ཽ/|hhhqms=ܒ NԏL1}ЗwyPr6W"F:]?v#}Z=Zm%)CeriY jN(9de(RIŠV[Cv!F? H@BZG Η lluXD{l*H辫Z/S]ECK3Hk'_&8%_Rzov2y?CH{3^Uh~Gp Dk?FDRԏ׼UјHnC#m "ta2@o:0ӀTYeBX#Tn֨TZMK38Tw-.0S&}rqSsm?ds{W;jŽb.p}ѡt LWb\^!]vH[$ X@+ެA\G!naODU3.Fe:&6ɏ\C0yfCk3M!ؘZvS@VjVM=;&iX>9Eg>}{XQ"%Cb =$> ^]X,@+ jAM Z v8y|XkSTSb6*bpH)XJ<6EPgxs#Ad-{G6O1f½9hWGۇ7!]sɉc?~m#,"U>IC(N+ʨ fTUɈJ!.-& N,H4]Yj4!2DIF,PF,먗'/pQhKܨajT#pzRT.dzۊXZ =Nd}WS/Vq8,-}(/o`#B,nBquY$zj[g뢓>Vvu2"`olly{ls;V"xMdzBVQ &rq%˄DX30} 4lU/ X&$0Εiwt}9{tܢ.Yy#A-;97,4k+T z *+drߋ\` hU |9_JsEpa'9zB@:f1Fu/YLB: u?LEy# kfտ[EP ]qG7«6Cѩ%WF[Z[Ij3^Rj]f }QwδZI-˽CqViNDFBbCejn,)& <6; P.9dE]MK]`)2cH?(-vȧW5b X k2w[gngǠ|ց<ܼ3&꫃5BsU&Y=ـM X^iIIB_#+FhQܿ"FJ/KlB?Ϯ6ہ@dfu1Aɯsz}uL,C5~N..7x;23BkV.PN窋_A)\"' ;xfF,PnU\&GGA6C~X+OPW:|'m< {L x@0bb_g1veŊlmE< 鿝VxvH o;ջesGـ?&EZ i"^+@j>;qcRkh=%<S˰Qhlr9uTZv;2 zp0<+m4/$ޞu(^Y"Ǒ"Q ܢV/AxVp<:d ,K*Z<ߌfUh8ԡ\[elbBsw 6/t(k\`.|xTTkNY)%2Z׹&s F,B?B0) {T=:=rGKǗƨ΋⚤ fл &h[H#n4qȗ6<|1xl[Dx]$ xƃ!3)D[L"ҢP+UF*@8]}!5/ g niRn< 2!bA۱xȃy: ~RgVG.#c~LXFD*[);@m J= SSuK3(GnN̅l)1@2ۇ. yTz  ܞ:GeQrMJ7J1hQ!uZN\r}ZJ'QJvh?Y8(]3z (NVsɬ)Ex~,a35}T;f8ٔ`쐓=^[1B<Nߩ/Y@<F&$Zkn`'FR8m+<]o'/x#3UB:#gllfKgZCn @ =6}f]43TA6&| |=3qM*@fΥrwkv?}cuX#Ip٢⇟Ƕ#ȇ6 u'X<]w@d[!]wO̵ͥ#fEjW5^vI]@8m$߮\_/˳ԠeAC\ PAߺ=O% !rwfw>P:%^\1Idfy|t!O1|@V_ǡPfNm?u:1->V}.@( qD19Msjtw?8fϟh0l[;\Nye_0ey}xIZb{C5\@yXs.Q-t6JŷK79b(#ulrhy8'^ gS8629NTy0clMˈDU|>G똯#wU,[qE;&ߧrK+䊈txE^e)rV _^BrL[ώ-DDF1#EL{)[Q쩺? U-/hűƢ4 :yĺPn;\ rʷ\eDt;R6Kn@>C򗽑B[BcuT9(}]1nA1Ъ”b<_+V2O{},3UK̻>7FAo(q=Yf\08/gfΚCDc)]eq{l qoZOVZn5ywpW8Fs>#fq`y#q*jh' \s#8 ҡ^#zէ0־sy"E{`t{ Čk2'G{;f24IǙC|G60dTKoMW{ՍG*A ިdu8dXo$[f K@.eQ-Ȧ݋mS;#fDd)ҧ@) ET"#).jrI]:Hg /.K* QPA\gWA /=:r\Ry.9=wT6ЖfmJ@΋Q*p:,ḿA[ˬ~-w<lv?>Y¬D+p[QaHpc6YKɞ]P^N+ֵ{=b+iQ{WJ 4_ tD>U&nlnl-`=+0=WdOwk~ L 1CVʌ]HReX S3m3Wō.ZCe"6Ka:lQPthȕ9? <6r)3)zH`[;W?›uURz { `^P0A f)q[|^rĬȔ撩DuS-/kGW4T: KR@v\?M@o|E74%"ʼn@',}x|bsY^,-GXX`pY@?|ײpqܖ1q927 RN` cP%$Ӗ҄]{KSmPO40 %/R4uoH&_Ě_Jq>toxӂgl&W0J.bmXIll$"[7pR.1lYop3Wn5hXKpߏLdk!BQ[+Ё7K}bN;F e^1+i}g@ RIP>FA ir5'^npC"7_9r۳pƯW^Rr֥N)e>}x88=ոBjuMibcZO=!GVڣO6G3 ?F!δ&]oHA[9>08ʯ1sBm\xۊ}$x@qY56 H)I}8PT-UY?yJe>ڳKR6tXoXiJSqTEUh sow}HqS#sw,5F߃4>nZɟV_wݾRHQ7\ܝm> ̭Q)I^OrEr>?߷WGLA k}_Q d2د2Čn#H?tᡋ8߲. 0֚p_~:`aӡ)o s kT&gV.K^qntrKvٷjbB"-iE|?dz*L?;5o W\Vqdo(8)Rd+C3+1\B.&{XEȴ^& F0 ZT=muvC~yATo0 b<"Ђ{8Z$#17Q;XZ 0d/stʨuiAk䰈U[#+ t:, &>E(&&ċAY7|dh$#  kO-''w Vґw?'_5u"P5A7,B`"ւ/TNIf$噅/D<1{߼vy\ rZ2ְa%ͩ Uδ(ۅ*LzDJWu z)_V9Qn|ߞ78C@GŪ̊wqWDR{ y'BD5+׌,0~Gtia$< q1\ L#+T1u+F<&s,8 ~j 7UAsa'GÑBXuy=.>޲W׌nrvyw76 {X6^tddEٟIo#b]))k))թl^*0;թbha7nA*7! 1փx@W-G*ѝ,kޠD}*S]VKQ/-SN V֥)~+ыuB8\kZ!s:a dr^C"j&.3}7B$܌]z> ecW:ŠPº45qMFv>{Hx۾4!B&nwmᴬodWPb4 "U{:g՗cLBz+Q <S6s7C"d>˺?CZkڇwxD{$ hܖiC:t&vP7 pB +H&[˜7vOu',~C 2jBaٜ;kd`a} $c$2i])W{ >LOXZ)FGdߞ\&-It]f\sp#Wc)z?K.!z4-M #K@V /nB*->t1T%ȥg65(l$z"V_hS7n&>FP뀟Qymקּ~/0Df(p鲮qT>MqN7{+)ŠwJ; n %Uғx:Bs;"CrhɅ]*ګxwdH :P\,h@P{wіלk,D͎ڿAF F΢6G0T!WCǵ-?ȕ*E(|"[㩼C…rF3-|rtT>r T2v4oB[ߏdapi{l_`;dfP\gEGb0 kZ'9S%~#g}Xol0)3;u9wݹWevV_.%*W) D`Y17UKTI)#i&teg:R(hz3 D7]|[xLZhNE0tݐFC{ P18ُ%+O9Зd Cv')_\Lܥ;,?'4Ehv5qϴ>̤@ WcsNJ?!v{#>CAͩlx ֥QA:3 p"/YG)pĕW,:isdS'VrJ:0MZU'_UUA% U]')&4#I m?q ۮw{ykᔥbљfVL~Q.CKCsA\MS"JnCh!Qޅ9h& @8ykq Gd!X Abﲐ֛&C+ss]# EGy~'Q ƽ#"$χ751$wK=jF+BG@g,gҺ( $]>%s8s>=!~ lPbuU{j?rEmbZC`e.h֥ cg'ɾF> qppU}4Gp1-FGiJ㴼aum4@}ȴη0`CloexθZ=,#GQrn4?7@Bkir{3@ PҒe`w}QW+yvQzp&v| 996,SfWv޶h"x)z rY.z@;V!:Zs=A8 %{ÃO;suD0[Ecΰ?p1*,v hл9]Y%A~dR-e&Oޞ`yq;"ՄjKRX4:ѝ S9hȨD2|G .\Gi*Dd0ſWM'H : e7 6k9T4&ˉܘ~RUo`ȥgѪ~T S}`W{9+hxIU۞"#!:_;jr GiYTk`zoH])JCb Z>OUDRԱ;kC5\\n&/)ץe}1)u*z 2%T7Fe^,u 3݇4iR?ؤÈ@n -'Rx3!vVv]ug۬x,ZN,O+]+UKN(s pׅ .9d q6[񵎨N=;$JtL} nBdOh'WE03-x!a>×2y_/=I #a4mYh!IEЫJ'mxl~ᴀNCef\`o8NhTfTN/攷ڻkE#8JT޲k<[]V!{\ ?Jظp ~[ҏ(M+>R6'gV$cI$p(MxD=Ym}_9Z=ca+ޛmD |CagC =L6ƣn5<T\eپ1Jdxʏ+HZSbhIevSu TG ;%Pb1wp%@†-?;"bzPݒ>.oBgҢ%#JGYsӨML[:I%fsea']S呧՟5tұxgV腘Z6Drkba37oon 6`H_!H$s Y nˢҒ (di1`JQCxO/z_Gf0"/ @Ey^ uN.\GUKa?t 1|p LaY0zeo>D1".m-ک{ ]jQ"[WC[^nQ&ȄxDv`--(ǟZ'X}C9> _]m.oI#9Uցtz#1[z,-*JwŜM+[&@qXb\Ӗxq(|ϫ0eV+O.>H" m왾ÓAE'̡\]X;g/|$Htj GLqۖ&]c#Al5w7O"չ&W}Oz 4s<5 q['C_}Wȇx?"=M=EPN0$N j'Sj$'Oqb*Q#~PY~FEw?{I^a& _d2Gt Kv@Ӟpx_4V;Pd8Vg kT:<]?әV:$?/vn(JVgx9ySB(v,2r~'Y1{r9jr 2 ]H "hSPK-5@V‡H5_!fۿ[n|o-7\&HXv% 2tWt%Kg+3 wܞK+ҁkE)$Ŏq&v nQr^worq.=ޏ2F_Zq1o8[8?~$\]n _Bzx3W+4uy/;0h{N @Fz繃'$S``8^A3[2/9fSy|i'*{~?t 10X,F <))v(ku6|z|ǹ2;xFHyJU q"$SOs ɿ,Q脗}I4)-z%y(eזP& O S拓KM,.-ۻIH `hQ o&!f1]x ^\=Ww7I]$ap"*X"oc M\l/A_9sTN1Z웸aHk\F>Կ9}JQB&4ʂps>/B@& حp\w<yoc`yGv=reTm&3e]goU&*SuԦRi,c+4C7TӢ]ѨڱՃ?/{6 j|^ECD/b, g9iAr\'J.N[շ42.Mwv)ׯ5L~e4Z&$N:AtWބl[ͻ4MҴyWʫX XK ߎn]B4:ۂ0sA MHZ+~ܭZ |V 2/ d6&oNKkШڱX2Lw^Qn88M:4_aGL7\O.lf<?jVKtTŭD se~r.V!ʔysOMxsꏟ`V|S_6 '9& zdwh=YHo_z/Mfx2&6QEߠҡxrpBfȡ `,=R4AxK!Z|OzORO,mRtKJ5;?;^",*k7(³ ]i=owb3!Jюhj:=*̆H: r9/3]yBtu1BU̵#G ӭeu7&LPײ߅[Ǜ#ws?]!BU)- 'Yќې`> D1##4O"lUE3Q0ؗ~f\4t3 !V|=_xärD$0EgcFay@PSc2U#S  ŤGe7|-O&w7sSxTL{Uvt[ KjoEfaª;NXG"1aԛϙd55qnXwl{q3 ЩhRxzemί鑟NSǦ x*7fтJIS?eg8?Э3ꭃ߇ɱN:s,s> ܪBa򢼖n9ϳOMIE K_ \ U">#BCDO6dϣW/mBzRuBD=Pcl'A[;G FV7XKṈ́ c/7~cpmҋR5dbHWG /I-bx\ڤҾeá^9!QΏi19m]oR,ҍQ'Rd_; j? =V =X4f I%P:Te2覃-_JLޅee:$ 7Z<-Lmg$(JiO 8)5[XGӌf$̈́FD!1m0Z83G3ô_9J7<`kU48¾FpP0.-BͭaM`8k+Gܶ [03O¦m 0Q;4,.Hcn))R߾[$R])Wp%1^sOOC_õZ;q㳳 a6Z3`dUց%>d,f3ghT1daW: ܎؈b6{d$>͘Ϫ8]v!?$fvb%,)<;u5'HDO$)_=1 cAgǧ%B\}cR^qfʠ\nXYTS~Gho˺^@Rc ,B}f'm޷f: Oa*#MIC?d}5uz%]O:wEz6//llvw Kx0&]䋸rYZhKn2Yp6`es=(!d"d+`׆b ?T~ӘL{yVr cW:qCodiYhJsE6ꍙvp$ӷtklja[He?dk ^Jo?ǷJ+UgaJfw pҏ=v^t٠ &b@]'X|խX7qUD2ie0jSzbR^.=IJmŹa* Lu r0')q]lj,dzHC ҆A%GPX3v*u:H&A߫K1jMAM_bZC^;G)0Ee(W :}`;.E0h GYw [ յ is{D^cZrBw1*$S[CAwj*Įy48ڽd.@ΊtP>8G4{U)\TL!4X$a1ʿ/lEwdK. R%0B{n5Pݕ^*_wY"8voyc{[[,Te\XuO6W>$Tod]AC][-Uk`#&-ڛ5Zo<='ܷvo>/&?S\]3OYO_;ndj/7/5c,/MCi0:h7|vWm#±R{ w/. oF < FH״׉֭cd${:!:L {!OU$2qZ }'8l4$n͏~9 on1"6B[.VnShc+Z35-7^Sj4\ukZ@H\h_G$2z5]5/ձx/\*րD< )uSߎ&&gA)> ?g;` #F6TZfjrKQC긤(j5pb^9" b(03WΝ_cx I:ޚۜ$ġ‡^0/L[w|*| d$xd|~԰+զe`sН_|KHȻ)Cb9zFeim;GR"dXw~)FXt}bb-'ISUNSziyQ\T5=c=t))TVV4$dս":xg6d%]#i_Qb- +ZɃi;U> }r6|vTF | ţi} }C 1"#(v,,$Gʼ u6c \"O{`/gE5= r*9jQap"lݝ|IűM?Tt)IoϷԗ3"+w/Q-(5?="!Hw<* HpYwP̉Kip&A*頡年ξ1U3ֶ\!bS֑pq<;ܕ.Pݻp>_>/iy5~{h,3sp$UTXJMT)W83*{nJ zd G[r~9lg* @Pf0ٜ(ӈ<;lQ c*X Ѳ]kf~>zt*Ba S1\w^LTEN(W)BG1̡؃-S oDLԨ鲳7 c}2$3Oò'7 QN<^~O6Nmq#idN$F:"qGʰxnqz ^vnmI_vI䠉NYv }8i|@G 3 N!Uh8_RDgӏަ:C G LIP2K1Km[p"! .r67]JbMRqX8\OA1v?X+!cvm4c>9.2ݳA@aLBlэO?jmTDN_4:mih_k>5̥ŒC;|2K|ӡ.K XbtUܵ܈9u <܂B@".]P_(q]~ugEM.^=ۃS*ơ0,RRBkB&]r(1MxV=/ ! _SoqliF?3HS Q͙~ŰUyp(D\v6 kzőR92%l壩0`D ᅑ ߗ)Mu@g&)ז^Yw6)m,_0a޿zѢ LDVu/ T yH)WW.zƢUx_tҮ|77I&"Kn9Y} "И+ zM?g20(zh@fѲ AR^CYJE{X9dLDE!6OM#|N6!Ӷo.5a{u čX% l{$ #j,ęQMYȁw;(nϔ%aquL[$YA2,^℈?6amZD"+Ѩ@CZY[Pto'B,y:V(`t8dM6$`8J)(UQC#|hE_9?5N*Ya[ :䉐EB)w;ٹ$ dRtJrKHQ4'Tȷ%>ϢP43t-" !^Ae#aU}W3p#̜pvE70)S4zP!Jv+]Ƣg"JxokmeQ~{?} udmӔٷb2Z]|@ D$!s`V?Lm16cCToh|%y_<ht>[WϐZ =zn͘h6ʢb:oHN+gc1v'+c^ߗGYl3LzXs~O`soE?.X .EƔ@oT߆}L$<&&{-V8BGs 剼H l 3iasr%J=8$<'k5R9.8ZќTOh %NAB<E+b¾" 6L7laLm [.WyS ~5^T~n')̭-TE:wIMEjٝnmht{EN'^ ԣ'bBgF-1 j8"[>>s+ f+u\jX[{=!O㟠qKMpb $=f\}K[jeLJq*#>P7m4`5`@{~v#L>~Y:yq)*5$2:4 ʩm"6qg{*0KY~ q/f,Gk8Rt*^lG~٬*k>V[Lh;k.vvX &P1N%>+[+nv)mO?w+qA4cXvCdq,"Zzl$Gkxn5 ~ O;LLs.-ngWU|Z7}Sx& ;ڭ}M[ʿK>WM1GtЩ[kD~Ȝg/n޵]iv崮u`Z*|(zP,NqFB+ > [tv̺Q2O3- +*7 NjT_qW#I +0qpWfU%@q^lI[bKOJ jqb+`NOo}V8uqgƝ98΍u6S; ag0̊hw|ۗK/ϒ 6N:Eve-e?٠Sed $N3ky "s2 hR $F5WLP9&,H )P;PpMy˜1SV@ YHTu)%|mlBݫ.v*;f+z/bֆ|Dy uDOn V-g6KW=I&m6pק9Qo/_;~w3kB*ǙǗYB9lג@=ܔVczBo[Ȏ*w+|S-?/zGs)g]ղ 0wdI5 ͰUrQ令 QH[JaC`C"j?5#F5L7ۜ{At+ D~7\xL%pqn]JȳaZZ\ZlR<)duU4,P'W F.-j \]$*6jQdv{ ӽ`* se4HV``ޒۤL(89ijZߔ@ noŎ^e N.Q^[4Zs *Zi%akS)7 #s9gWT/uQ%V44"b'81Pܘ'25|Ol" oX+֍R۲DN+g[Ov/ܜr#ٌc3)oDŽ?HTkH२g8T,`fM+9lN,g>+83h}(<ɫpdJ/t-jX6{옐#Nppx(Cż?͖G{)U|,zL$JO NE^[#-Dr8n=xH%<(p+tIAyDM {je^WhN腍Z7 Gz,o}Ej&7N:lRL(=щ\K͛aCʉ Qm'Pgg!iZ$/lןL3Sƥe*}jFfYE_^v8΢gU=z+kBE-Y ହDB338q1Q"&H uR&ϟ֢K١W5vqF.X{ #аB2f6w`Fb6K5~4x)/sX^wNH- Gp\}N$c+?SI :y͞wf }xiGi j{Jd@*3Z]Hx;*[!EFSBS@fmbJ;)ZppH'e0Uvɿ6_&-w;v4?-P?%u8XA }3V+qt^/6P0Ӵ-aQ 9?_ Dr~@ <'(,^ݥBJ[l_Zi}XQ ,ԒW|y#f4.$`M;)G)Q  !œ랆4?] DOA:s3ɎZT{T*ޯ jmܪYl9`GeӠ)~!TE\zBĉ:Q`4(Wެ ẍ́䟉@KFEdQin6} q3t–=DQI޾po@h![Bұ6c"ϩiDw`ݐ?#Å~LjgK HnǸ$X%%c<y/U pꉠW6%>D0 e6Sأ}} {g w.*h~88~QuU7w`=_ v' 6jW{j6̩^_^?yiHJyv*^z[2͖w$ĝoQ>(]QORF?X1躀lڊ+-*M| gkȐ=Ö^]\ 6Bx) uYO*pJS M3Q|4ѯup'fh4 Gyq_ L_jtZG,UP 7 mew>į㫜T:/;8+k_4ffqZ`$5N/𑷰Y`~30@ߗTB jyBV@b2ŭ Zbx.tVtC8d˼Z7mRhN^QY?B5 L{1*7te@MȂ,}>1WA8EXB!ͭ%BM/|plm:eAFqeB#=nŏ[_|x lN$a0"$պyjCfCS{Yp"ysl{K|o#覭+GZo0\49J*yXBpXf6I@hfQKdfPa:8p{DG ?1ol7Li/J AxJt7"_ )= _0L_|\Gd5Z8qKrR RnjF,.5ƈדmi15l9f-߼h!1\'QȂ_#۔`lp`&WZ%>6EЇNm|zO?el={65tlI\Aރubv%H&!sSGM  rA2=¾ؗTEczC),Z}'ɩ]> Uu/RNGyeC_:frT?WE 2m-\:L8D!@"̙ciOܐKE{K_U9n/^\ćXC~7 O:p.)4žEj$y%ev:wpN>]nmtZǂ)!EJ-"-T]/ 1k?#ʗXZ=[g_D l)yq>e>آӻ}V [>,'i +1]mBq㴸+;Cb)]i0Zc; t T~9TPN۞e~o9xP5=9>?nn.#}#9ۈALCqT:Vc4?ܜd0p `Lӊ{" @29o6kkxB]zWnIp\?ҫ\ .,gW Ii Rɍ4ţ{'5+r!3{X?XRߪֽ3EE-poo@Uk?1k@O _#*! ؖKܰ7isLދ{` v=7Y-HWTN)D@SŗMKZr~'}oCB]䞤|2괈~ 0G/Y'sK=pOh Uj,ҼVK1J"1ȅDfh"ѧ=fD{^v4O>p9s-v3"Ff ( ޻S$Nw'\n0jՆ|<ϷAB +I3tȨem7&S櫽G,9尉2MMCtE77O1Vť2fY>(7sJےXG D_϶ӗЉn S蒝K {YtYtUF<z39{bޮhxA8lf}XϭT D ر˨r6:i1OBn.ҽ"@U"c(T^8CAp~Q+|aJ& ۱s8+f`ې4J#%?;;a䋘CR;%z/;مo<+P[aS3gV3"2K |!< C#_(-QډH)y U4T&cN}+p:S-"?p8l >29$E}[P Ip a>*DM3ctHo:Ҏd'&"^7{mM Sna-`}c$/*4ng$O7yhvYa,j`zw{ 1tI Pu |9(>!؏O4[-`IK"2J'4Zs-{gpTqbЍ.YwJT,s/%<10s'AǾۡeA^hvUBE%+Qᲅ.RmJ;#o_xIJyّRG9x۟f UOʗT^?i$[("HP;Rm]4B/KU׺;! ev^Iߦeȉ5>c.uQIg!1߄I h*ǯwGW9m6}sH^6f~YM~)p`NW1-*\7ٛ>0߮yTFꭘK: ?WBEqi]d 7ngi֎_@e&dmE)#Y`b[)tl>[L}i,(תb4&^BzkI [B@Ϻg=Ĉ3_8q'K$|pCq+C3G:0N=MC]pAㄱR*?EoNZxWt 'g&ɘ&#!-;< .bSߥHhTTP;۵Zya8̱x#qKJ}9eE62đ \EP>7C]O_PNM z“o"Yc фEt #`g"Nkzv0lcK޿C "M`_&:RqZbSz "NG-*_$Q F$[ Mu bE vyU5rΪ}GN($, +K 42Z,R0+"-0#'2zMI5ϥuWzРۚ&k6՟+U.QɱWV˨.܉s)+h7Ua^kbsMUqy3LMǩpzcV-u!tI:j)Xh1>bL]qm\ HD0q֬aImJ!˂㞚L$ɍis]W&ig_}; ۏYhz>/ 48h`/IyXpGМ.R&t':"/i|ݚ6pz46#L~m9rS .xSܷ۷*m Ao~9ȿ0Vtvê苬t bؿ}O E!WmKu|S0ٹD)@gFU9ψzqބDc v#2Џ:Ԫ(cv F}֪Fb" >LOQNzwg+8Oa ̍G8扶a|nSr":jO٪+ UG 2&J5sII$B-?iT)՚-y®㎈MyEKg zͫ,;j Y)P^{V?=7YĢ4J}s9d ߤȶ\O?Oa&1ҊOCOIi}`|O'&>8Ģ7Xt)^^_M.XrM0 LES"z |U7c  [5bymcؤGb>6UFu1DQKRˊpP58ʙFO_dGm, a3ҝP@oј:\J'g}yG`gh0G҉ $WT$PCv\;(~)m8ayp)F` vPO^v½(q9=#qãO.$e9f{:~czIZ-f~?d߾|s|ӳ֎Wٹı>VPqpѡQHzIm(cN ^ڋD9*\8"8+d9| _"\Ḑ!E):; wJR)pZj) Սo (B>mc[3/ILҦVs"?t@$eo xΎX]xj7̗عٺT@1<& }S3@1žTX5%/. n3ٜԞġ~s7´z G#+س[";r-p F~W;.elD%fYĪlrre% gK!{{!Xrw-iV1Ha{юScO @1%C }˹y$kIR^lIeA,3euZZ^2G"!'2X3 0ƅ@)Jr@ݵLaK'5Urvڤ\48]'(xx`ŝX"]5PFF&a'-sS3tA`O9+#] WVTQ{r.L( *X%@c^ςvf-?ZTj ?SQgv ʷ0b5>^)šr=y,9E4m7+W#",L 51̽Ϸ+.H_.1KWR~ .k1W;vGt;gJ^{} `VS;u%Ե4bM|Otl4 b縛O1ENRZ(s@oNACI}TEAmrV-b4&v8+K ScCZ&e}v-k?F&7 BWؿ\ب", x|Ћ"91(Ί2ɱheHԇZL/k*~g>nQ{kEj:57 O@@~Lwt/^?lŶDxKvG\R3h ٗo +hֆW6qصkU~DzL% e &1U@K Za`‚݃ҮdLēaٵҴoL gVP\ȹELBEgP㕊;r楴`o/6a0ʖV`}ZH_u %9!}$|,p丄τ"8ÙZφGhx@ hׯja ݚ1>SrY'*Uj`J(SvED'"I\ۑ\gّ2ri)dOWG{^v` qq|5DKa]<ܹSPD@ 2ӳ2;X yA;Ԇ&)Yok*<Caȯ^IzoXX";3gӵFjy2űņspp"jy!IxpeUkZ䛘;蒷b5p{hGINl#Bg인 gzU2pt+4&#E!d ڕ7e8l*ebN'ƪ{Əd3 sնX@ `1I #ea)Q$ lGx qDנA |m`[=+ۢ<e{0ѥ/| jܞ PA="s7$7Q $AC͸9AÞ\Z$x#Fs95a ا.kyZg&i_6LS%0\`,@Oj0ulzL}+}*g$'<*mV":]]wyrM^yE傾\8.SX";n2UZ@U#`~c(} =[2mqܭ6: G3Q c_鶵kCƮ'<r򀱞f܈F!t@Sq9& ]#aǕ, L/Nw*&۵a3:{[ ܖx3/H6Xd%x-"Ze՜ ?M|-W_v-)Ţ:Z3Rz5|yi/EЮZbgTM~>$WxKCR= ~jyO+\?Z*D^ @ŕY 㻶+r~Lqq0rK>Msß~؏ć>a}<nެ| bpf^tVLB{nI0$pv(ߔڽ#A}a kߋeO7\?%h ig߇f\wJO# ɞ7$DoG;rjaьTBxI~Ih|Ʒ*בG~"?&GRdJȽמ|$# 2D!&ZϝʨRaS6yLKZ}693π/@J 7"4'sJݬ,0-#t,[/ÈKKvo c{/D^Nvfe˽E]G9pCG H^@24E?2攌r܌fSw ) IN,s(>zgN-& 5:QU'=?CUrsb l7,jstt9Pᘇ iEyQA@&S/# 9J _(g*vHzF6LB\(PB|ZC;D٫@px/&nh6G-hΨ١d)x,1X FoCbwdsLYtu^bMs޼xqS;)nSUI-"59aQtmڭ3X'e 8-+ >Ђ#x-=>Mg$ԫ!1ʎv8YV#&D.C ZMObW [W[?*4D'%ZRt*4h̜e^{x(OTW&G }8J󣁂 eġ :p~up{((2i #Fþ^H~3,ЧPz ZRӔ̱ᆚbiNc<XËTR!ʟCkwPoV\ x㒬/K6 m.ѵgEVOs>S׆N̰K1CZchZa&Cx B|EVĽGf@|wc;]>MR|1DBu'?HoLPuB@999+F_Wx |{e. c 88F6e7jJXI|PzKAHDJS lI@vķP\oۘ?Zל0rF+)AY^;uomLL3/n[q (--MnsNrnIT4T;u: n& Fߥsn8cF39P'Qr_Yr)bC:iX-t#)D >]AdF"Vgl{zmy+";aA{1 %-sŕ,\|3[IbA`qRe͟oJL';PV ^cNuHjp/1~ZnxlC IZRph.ݦF )8qzA;){X(xHBo.L֢Iͦ :fHCcB5 Tm h @(JUL|Ԓ*78YU Qi*p>!¨ּubq9:_/GM>!S!'P0i T4uZc18R F$ #ɰdad/K!>ѽj< Gކn8=z;đ魠fbf`nB`Nt..Gt* Z?D )򯆾z6ꬻ x ;9R+#m/woNSA /twI(p-4@g-ԉhϗ`j$ٿ5 A/]BiMy v!fԳk Y;$hQKq$q5A-%I ҿm՝ 4 g@;N8 XT:mj͎Ks9Uɇ$Wա`r`!QpEKJK*f' c^-NDyA:;Zc蓦 _0: ,bKwe+ҍ# *ػ]m#͖CQz 9P܈FkD+Fm˷)r< oC "üөym\d^7ѤyuKYٶPjjX_g/#_|,&0Π);ԉR>[?& 7dP=7AʕJeCOwO[b,t:v1LtK1ꠛXU *s3ޅ@$HTy_Q8 i,p ȥs MQƗLg;CI5Ft$aűm\ȓapcY܄9ȷѸD$:X_<|ݥaT­$[3|p$ ]32ʚU+ 6W`(cn+Z aa1`,ɡř@D2&}p3sW=pb ~Zaa9Q.@85"favaApK,RSiw}Qrӂj]LQuVLOxef7vW!`nNN5[ !+:PrTN$3*|f?"d,J"d=/Wp&,[A 1) `P|.—G>[?_ӷj$h(6Ӑa 5c!Y/f*OCG&b-O Hf?VT''݉>y㷑:e\w==Dޥ39|ݫb8KhtU{"}M= wVC3\9%;sX'>oZiݮAo޼޻a4 xK}/?6R =YO-Xg靮еDurP͎]`B=1J# O?k?V=yHJolW"o!T;sYبn[6 .u]#Qgǃk-QOiX%A˽:>shZ6K+K4Ӱ+u%^z" xi쌎5: #S*O#itX(: !V8+l[1.N{% QF H s\!dJ $fy u\h.͓BHfᎯwqAA66Y'/yh%5P߯gI "+OMY9OTJFZ wY$O;6Ԡέi;$>S[[m% $VdSK{Ԭ+&z}o4Eջt4Iͨg*3(k ^*@f89I=V+˳LAo"mS%'6(S1;H ."e?O{\䪥= q}&ɰh7(U$va,O>em7iq~a=uZN2팁}YH(QIps:(^>%mnI=Cxr^:D /*^eQ>`6a@\uQu\%kpmXjͧixG hlE&uJ.3Ӄ>Y>pc#CE^⡼O ,71ݴcWUG P.xuOq&B -L~ª=!f29q2κWS.ǝkqBR'+2Y.w z̤3sGTft>*d_AUrLW;-Tҩs|& I!gW2&h`c,tolIeKү~y[ȯ#"RyPC2YR-1\5'hYakM\)՜Y@b:(#V֋"~/_o0E(jkR3~ڮFUʪ bf ca9S?輜TUGRJ(B֨؝ܺz UF Z>֭q7BآJGw77fhT >*79^h4e\>kW\#瀵Zjۋ(!2Xd 93}BPg>Z-|Pe6`]U G3iO`̠ D(u'{!c`H-9cN_@vNiP ?V &AWoGBS|:NP u<>sH` zk'Cw< ݌d?' ed”y"ZHu)\˂W}PxcP;c +q p ~?XT35b"s։;3ʴDP}~<3t|G:{v *" +%-% o?veo4nKkK V-߾ dS!A-[Q ~MND-mYf S dsCUpܝ,N=/ւZ7 1?l  F۽6^% -ydPOYSpp@]XCm2 Ú2JsgyHfD7U2L׬dyd㾠b͡'g&j+MpS}2kƞ:ipUcL. 98>i&̈eo1|-⺚-m 8ay{6yd|?KlY-.CV}?LniI&9K 'p[NzI0 H= /dh1XDr:yĭmľ?|prm1,4a5('vG(PL&kw3JǼNJ̭l" W`#n^X~4vzctMU=mΠՁ|%f9"VȲMϺ|IUFW}h6SE=4\D'JQG.i)^2JAKOGϱPk_ VQ#nrhQCE1`Q3Hk@/Su}d n7w0HgdF0YI;?g  l@3IߝmrP%!u;}?FR**d^zz!;Qk9!^/ lA919 IOou۱_W$ޣ%s?2PeWT&Q@80qDs[n 4TƮe'/?s1?C9x }/Xd'OkAD " iA\4W'7,}D97dҕفe}B PY 5nuRTZeI$NU݋X4{)ˊ E! 0s;#G&foJ~N۲e2/ ,WQC\B;wxX~3!:Gis2Ѐe'?&ڒ.S, VAxaJVTfL.nN^Vq|]b6zpETY-B qj&RR#5׎&)*ʠgz,CKts KY)luTb-2apgE\90_ݭRihf1i$ q~UB%og$Yjq̘z= VXRҗ[;QKY4S #f2BSUڋ|PS9.ֺ̖!wXؼbi*hT)ȉT]*Q"s c8+2͏_8$"_F̴*YZj禑c|MkJ[{=%Oe$?d,{R`XĀY5}P%fn+j ML`M, mJc; 6:t k!(C.^Kzc@}v$FM1ڴ8Sj}IAkbD4``o4>8FH\L ԳOS6ꏧ/YQL @0ӌ|ݦ&YӕR,0L#uؓ3@.]QR| Ţ7_ V#2ww .Ff+/:]@e|6f%γ Ī$d)dԟEdvW7:M bhؒ*]B(Vu/Io: {6;("Ps1=CW{HM|wsѕY# p1}9@8ďLbvH08<pGE5.jRXg58iR|a  nzκ:i*)5B8 8v5ෝsOֿٺb%: 4f^YT0~V80Xָ.*wx$Fk!psKXm'YVO#M~HarbZ'XQܥG۬Aɑ@bQ妋/,H2{R03~EinHe1oպ}glݽP\|@4r[yrjD2/Kq S3.n'zw͒p *C"lsB9^: bTT=Q?N4'N@x޹t)9<``x-K5>eǘX(gVEtTO}֌WJ\M^ kBn A=BeCÃw.O@Ns{-zRQbjeE%J6QvDP -΋M`T;Gkޞ`'f< AX~0c;t"d@g̎Vju(|tYvS}1U,g;y=,7Q&A@J@Z2\ F:eЈ]No#SUT9R,N&H).N7u%42ی ڴÿg#}B/Dڛ}ȵWL.tc_] ՔڵIXp1l)DAuCJÅ8ǰ4_˾M@5T1b<ǯ%tGq+NVzDJqaBL(NvJ5iVG?)Um T~&R_o9bU,guc`&^Hı3jB)oia@ $5BUS( = HH)8Q/۝Ȍ\M\&+WW خQ8x[qBs HJmu4qa3tNrLPWЈMLVƌr]epȜյƥ{pl m`d@b2 !A$~Αt,uf P=@5scQر8Z>dlޟm\5UôDm,5C).ٺHصI.o&]K xk6ՎA*Lț!cU@0ŗo>UBS|naW|,vbF\N^`/ 3dUMJNq;9LqD ěe5 sT6 קX:Nom[f}4R {EQ>D F:5;Ca0Mz  u.Zz¡< QPu(E/S"Qg,PxW{F l9αΡ[2T4iY5DC|zQ!5/rRB&EA7p”?G^lRf^x)~L$h>a wCՆku*{=͎]KVW"\~=.i:9RUhݵ{xO7a샏TjSDF6 `'exE @-L -V: v֋>ߙ)hxKpC(%(\9ȸqr"/i༫j:LfPXy tO^kJ3.I\8϶G[5w%xwσ=%ϤLXwD@u 4AA\P/cJ8Yxh X٠p`#T9 t rx7o{01 aV';vJ)&L"3F9.T¬| 3IMS$F||dx-ҖqHŶy*YAɲkPT{zH[b`e|Ԯ>^tZ K.T&EM}\-ZjLA~Lˎآ@PGB+2]MS@tp+z`PiQ`}he>yqԺwƜ*@,r-6M_;T? 3_h>uȢ;WUgEZ*/J5yTMHpCE\LDHhe(|eψ&Rx oUYP?F`1ڼ rbcTj4VUp'DnCOIzz)h]k56W52b+D ?~}o85L#h7VƯ_P= u-Cuf/ORRuo0 {%( %̓/y7.czNl@ -TDam;6 -9JRDY'_Cz$6C$$E&9YfUx,TVCْpe(l5*:S(I1 k9BgŊeE@PP{rKW3e ZPtA.-#\xwcO[gД6pt"v4aGƋ%5۲~}oۮ^*+wpfks\@,@UxG^u yXn 7 3% ӗwYW l501׈;v0⿞ Mh}=}\;!}̲^omwRZ߇M5NeB/JpQn WilP7ޱ1uarn+=mHZMۜme2T_ fG+8XX\Kb:BZ, g*G_qΞ`U>h^^_&2E,=8rN[R9WtMLkйp[\NEc#:2v:HIVR[M#o[(Y;x☓Z T `w?|gy Mث OR+),ǕƇjSnWogbo1LO_d|4n]r:`+L*uY=:.'g$IR מt\{*^nָWJv ~yӴhpܽ&I.a =m8  Nŝ٧| -:НIN}$bJ=ϷiA*`J;Dy7F{LjyW!co7,P[;k߫r6XoHnI^DsZ ܱ{u)i1UէV{¨m*j+>E:qHu"da>fek|{f&œ8w(|zC  $&M<);s>K/&v>t!|z12ztOczd8` ![Հo 5SG_%:9BHecmvPI'1#֚)s}.%QîjT̉^8h?W֚]2.ЋE~Nq6[d= K?C:WK}3̃4{h*bZz>zqS!D=#Ηq!?=Nc֍ 288Uԧf-VS@@>'";K8|ZXq% 4]O-k/9QXcPuͰ)n(҅䶑=9xqOb{%O~GQ|mOzJ*1%U9O Bfi4JXP6ww)_\}'SRkc)'}K!rmZjeBeْS.Ob⫿E I$1]U^J2iTI@!w,>{WYbB0JĠVӺb:y &ip􉖞6$6<-{ %]_DCKNʦԠ,ꍌEmv6 rga*GROp)IL^Dkuon]G(׺ a¾ adϼ(lasq^8JC1?G<Bq~(L<atSۘC`w*; &# MD mG<7CriEAf1Us`={[n<] 5 RͥX:{Inn˅Il;EE"q%ŷiPZ]g~_gZ2`pqߊ(9UN$dEP] Mayǒ[,-rhaoNR6q8^@7i `Ƶ~&G j۝>zah2IͲ@kMy%f3i\TS WecΙo'0S#uvKȇ~dd; sWƍ|lH0)MTHPM(h`Z8[i(1|y%kqвUOu~xsjSdjSH}%#=JΪLkM 4RP^H})k OFmX6Ͳ4ΫyC2eog<bTD`,Al"k:8LmK i&tpaN=f'br o0B?3(*h,V)8eϟu`6fJ CaTŎ\>Gh>pY#R^m԰}z9qJ*1GiY$jh#H]1{蓤Q>gvZ7e%Qܹ",.5L4N @l[R˲L}ydJMK_񀆏ͷ zf&bJ6ڭNxh(Sd~f!ldJmosKuo}WHJ`Wn CZ!"OChm-Ͳ@w}p5&ND94KQ#V3if1[iZZ-"^A5YHAu]m,*~iE׹`#^vG!]¸I艝cELtH`K/n6$BScOkߢN{]jlʰZNC璥 \eYivɀ~aϤ@*iH'iP kÏ*Chy8 &zy1g:R>Yx{,qm_jUԩaiёGQlrtֿ(A*fzkrBF>@d K\ُPˬ]UuZg14TIFbK.s(@ њ5scF};pG0E)xi*!pHa&}"q=iʣ$mKp$Y+8C1+HI(UpJckgVW?C,ZiyCc3'wUW8@˅n_%OJ4tw[+^#+%/ec[G-Jz'dJwn gߺGgvSw]#j@r,1Z0c%^m8W+mX@+YwuLV̥eVvɂ۱#LOp"Mp)AӝԐ9dMט&/B3T^M`dz'80:7TK`HLNp"5\+MS5Ml[4eMн _ TE W%x2)kgL䮤{!ɼ|' Qaz L."=/ H-5┘x/| }tfRxi!6xqj H{/+߲݃`GxSk.ߵwa<Oӷbrs hW *f:(v>mˇ~kFC;gV+Fk,9c^d i$,<;m[_T~r+H9kelZ-xdyABaA[ 3M615~v.kK
D #}tpY]puk mcݷjeRO</ިQTjG2mқ|h)H5Xf#Ԡ_ XL3xr4T~]2?N׾8?Gە?,֪*+G.g;pAVqwfK"bw+ԛ ǓeaM?t $<:Y{VRχ(5`X뚫ga^FD޴nUw{;٬}>؟g8=/VY8sIi"qC/뫝 m+%y`W+ 0gJ9.FU7nG!5̓@jPS0#VWe]8M!)WTGrS&,:]IQbc))s[k" 8*,8GU:$^C'dxpOYlHՌb{o}JU -")Fl;߯ҶW2s؝h CգF0 k^2gp࢟(Y;͎0yAMWÚ|Ԇvt˭lpw%|WS,aӬ(C<1lָйGZyM$뗢#>踪z~Y6]_׎cKsGd]x6q-.Q_6FIqD7ߤ bF=7If DKbcpbZLJtb-Ѯt1xB$5W:}Xn7Z90)2Zk&2kL@c`#\UeDŽ<2ӈZR I},A>&a,pX !,C?LcNk+j1jKj']SK]XJe92-e|uo>*4ܻZKc,ί\pۗ_:EN!i]bgȧJ8Ngv_7TO-^xO0$GdJ7 ;PfIn@2pJN:ta k_7`+X,wkMf'v/I.'h 'AtoLλ,&剸Q%@xZD~bsUo6 d:V/oF$TvQp21g}iyKaU)v; m!TK+d=>Wi{@9 n>^2?}舲lK#@yIHθVJY`Z"=x@9. ᚲ&/HsFg={Hrsޑ;RT ke˜}8ٍcW(@d(q")rH׼qqi<ۉ&F}|`w@1Utޤf6BaޡDh-7s6<<|mbK03'\u\@ O||. zglo(w99/)KX&Nop/gw̜dk^B.#3f떪-*,I:+RᄱoE{-1I$_:iG4\uY2Zξ}r31W6IR, [Jmm[TѮBc药0$gy|b7) +fGKo 04X}VoF` p`*;؍>~ہ7J]Ll:ԨT%Sܖ]"8a񯘭EWNu>:ldQ!/fI(sISI}=]EW[%,n?7SEB[!DDR]oEƩzTw&=YKBKOAC͘5\K?)aZ ,C*VfW@e&]n@{,HkŌ R~ Wߛ˝|A#UCۯ`ط%9*gNCyIYegZ>4ykl??@NeMtens+F0΍MBۑYz-@Y_ɯw;l1oUU>E3[8nL+S&grл !PwS'h ^CVD!'mnHeCvtj 2 9F&/L߇|DuK i/1[ ok{߁RmjRHx29˩q}lRRΏN6=ސϖb|3[qyVjq:H@Pvo{fjx}:vQkvh8دm;z˭ɠw m9m$"MDq ^?ew:oSYK?2w:%,2 k%G>]\6IgkՒ]#~ S^,+&8XݵjGT/xy@4IҢ᷄֋.MǑNO1%)Q!3g |%+ڵ_)z8_SmD}ҙIvn CcҲ&* h\ Zdwu1_V΋z*3u^y>-0TU6dvb(SbeD:4XsTݜ~$ry4m>>b6(&EП-zjs:;2 n+4glD}Ns!|)oO}Mfwfl]lZ߮X1m(xOGh-5{1na?8qUE% y)r!3I$aM_켣sg.Awko<+E".EOMXmTiO|82,ʷQRb~K>J707xeaӽyK~!Q'g7RR>b6i@7rHTdı6ħ#ۅ"P@S1i^ 1!nZHl ոX}KGC"}8<tRs(wV>|:zsMԝAj1+lCy^oMU^M,3wVƨy:dggOH^A/-+%+k)Q?t#1~H ~:6UV;C&Ũ:5ẖEg 5KDV?x\"ĮɌ;2߮lW\01#t߲hCBW瓋0\(_0j4B݃ hUi:]KLcZ:-gUKB^ww){fs^їي`<* A] B9i{Ċ 8{08!{x=1%/m֐^Jc AQs܃,ŶN + 2ft<{orpUGf^$&NfNy W*KOft{opZ澋8` A3fd@qx5ڜGtN;Jč Z| ba[yE 42sP FЉ jr'S݌9c2H`!}4S&B"s^ ofAyWsܕ_rO3~Lz$vOi]7Nei)%Y|ʳօ_^i,AfEk*X w$]4sV/,~h~;ͤhK=׭IķOf([uTgF?>.~[*k!RV5SbqJWҴ}19;I, hdw_ q֟o[SQ u,*6&x`nQakHHpK"NBkczV^5cA fqaү=H#OPLDDt%My cͰ\ u%rfOÁ6y[M<w1y\Ŷ䳛YvtcNp[E#G-އ#G<]zkW7$%EbyЈ7gS:Z[lDE{-┭a\/Ea`2DW}XTQW͸UHm{o;<.r%!"<ֺSDԾ?gҔIkR0\$1poR]`Ts5D\'2H0 x[_ R3WUv#L_3۩+1b3!lM*N7sudŖqP%¬T'(R=%xm^*6C3TÚ)8;b*," ҒbEhVRU<`aצX6:(Oq+Рu fB-4y Z}mTjŇ@fBXǦv 2 T,p+GsP:n>j3m 3^SQ eenY = @Ph)ģx| $,ڢ*J1iXGvF-ʑ &ߛ#c놔^R 6 c fAǗ^鷧>hx zV&AiWߪ8#Sj&aY2|C+) A%aPŸf5Ju@gA6!iDFԹi/o+(D5ʼnsń(*G')>Tn+O|?FK -n- 0l"Ra:,7ӌrVhAIgu?QB[#煞51tr`{U@仨-6AԀ@.~[˽9]$un& =8WSE+n 2uw< xAJ-^NzӀ'8U+02t`C t!U<{ Nķ[u guL?Q|1*4q$iMeΘ1 Ő YPRS}m^&+]&y'EF,a98-vi3^\(Fk17~e0s?V  qqjoI뾪Hqiw@M E[o#c*Aԝen ޒe]DiUq1]Dfkkp%f*OwB-4 }C8qAx6Iw^Qznh)ʢFg!i_1frꟳzFOϗ$[O(PZ1qcrAA 3a#W.񷖾5 GCnefq6qf)(wx&n30#zmO\I@4HE3CKh\i֭%V2Yf"#h,}jt*Ok=[CVoLeRz6aJchi_c "T1Vl𐈨 tK3dͯ%^~,]= Xйo$H҈gYm/3X!AeZu+5jl\,dɄ `XOlzuZwIlj1 .XXzyE`N- ~xW}7 [7ɟ| 6jgrJS%鞁ҏS,ʛWm Myd>[-3ҨJ>LJ0@6 ,Rwؼ8;ޭg?OgH׃K _޷[`y$|M۾%AQŢQ+ElNw `L(ba]fZ-QELR!(9Y:*ތVrKs3N˨ð9\ Cpv%o ץdϐ߾KK iim`߼/H4q|“p4 [Gh0F:$[Q~oh4ϣk>hSl;b),J;ƛY/6df`Fbl<;mB,!(@bגp3h!& wO&VS?iuje- ǡ2L IW{q= ’Pm)hWETq*ڬ+΃[y(-t{*@yyU_aCX ơDL =ЖUn.tIzULa,ڛ8pնM-_'6}J6wqJ22xĎva?lr@ij\L7iH`f7`d<Њ kRCWtçLOe=@7|2ț˛R'!ʴb ;cCw.9Gٰ $N{Xoŏ=Խ"ŋ zGbŢW 9H 4w;-+c<VkX3#QRdrU9P"feѴ* 86`mzЗp0lpZ;*KY:z|\]vg}v:l*EքڱӠ%v؜Ad=1븑W!G 9>̴I%谈O)옫荈fL){3A"M7;ͦ^6kPT0ft/ +'Ʊ2iG8 t^ayx.0y;΋UiQ/7n;jkupl ӈl?YaV3j;C{IMϬ V8ς{B$NiTwXy/Mʿ.w$Fbo lz55*_pDvuxDJHPmMaTyNXF17t'a! Aֱl=dw"oqg[@㍾wS1}"jؘD\ˇ e0v݌# ;}u{̴[qS`K桺sI s8qU @HӇgTz#9ggbt6P1]d=naޣi]-vUڵ/Ł(Jo:ѭȴ?3K{ <x< LDě}!G٣& ݏ7 Tap_LA CU3pOrKIX*Q󼝪9^\n?CR5TgzSt~n.K*ݠ` Nݿq8/.2 ~`t\y |U:{u}17>zYⅻ(&PUSYnihr Q>Q h%n6iPh-yL&!uak?&)+\2^<=Jz4StxuoWg}F9vF3,OQDH֭~֞ȵ=-)оL14G>`GFKb/oA\[!ZHFsuư@Ϝ};[Sp޶:gsʍ׆;@n$ZL,vnfG`YRU&m{6U7eBJˍ9g\f3 ƾ-l0GBV[P_T``bM9+HeJT aa=Z* ^2wQn}`LO$4Eoht17-TUf#Rǫ@=\n9W1'$& ZmQi6|T/J7 BZGNu󲯨᪐Y .$Q芚FM:xߴqXH9pVm"lObQD3b=juQ p}~dcVl\F`Ġl vy :(q6.@NCD${Q4#r7TPVC~ny}T͔>k6]" ڟ@ ĎsUnP/Tvh[rԽqP1"< jBG=;hQVEwgNϼb6鑑 uIޡ5Y6Nd${I'Ho`^7u-RQ(DVr,z(1uz?/qvE04'SS;Z/T#oS (n5ʛ uAj3- U/g>W{xR 0&p1R'''sBdґ`۹<1IWSi=O{͔,]ֺ(-p7i!FvT ;S92k9̵u݁q_Ӄ.xFB\UP{"tW5NTKM nUn)D7ZbHW#XOL8`z C{zƊ9-W@HKr-0_>v4!H 'HXFDUW;Ī"/Rst#(17xjV2|n _N>f1a35`Α{"I|R:}Np5S#'sӱ=~Eց'``[-{ LL]$y 9a7!~ )M^;Z72%*3߈)+Ǯ78q&D:Su%⨪jF i~u9"iֹZcLV PT9Ml١k߾iKġ,%BL6N 'ucO8w0)r Mjsg`.o?pw8@ԉ' <*:я@KRxQQ).e}]݆lXB$)m1 ɴ600np2Q=گ IcQME'D?1[:4ip(FaFHv'keF~[TE췵Q1(8e'p5SɽK-X- z_uxR D?BK3e8c]@|"Zn$ TKB%遮sN4e9lVi>qLNcϣek ܒ1~G1\HÕ3fM#\?+Oa_&(4)I5&Xg&ΡYl [d2-A:#m̪ZWEɪ\mN&·nN40Xh˾,Y3=vv {*8GYAD[S}¯@|vFOpC?ŅEC*GeIܞ =[ĕ|v(?2gt3h:\'Tؙ'dM@@"k#8Qw(e.\D°̸d;{kYh o`]ep-U6g[^ l]WUxv.簱qAIJ@>1񵩆~ d ZATsIͻ|f'+XZ|ag@bG!jA_q18A=&Dy[}$Ňd(r\D:`7cxt\!yIj C)G"|~6CɋeDGՈռޗĀbr iEVױ}&ĕWUUcҐG]; {w(Z9`CAwk/ib1mV#, )6y MJ8ypm<&B0K1oldeQӮEKg{iK%K.l#e؀pJix;`~ԴC-ub1sOz_ŸF2F4I<7_{t%̨i4$'Ukn“V%bU_(-"£00Etj2瑕4y@T[aInlygrp"h>]+#g#+q{sᥲZ5]Xb 'D_Vs`7_gG3#;\P.*$e>:liIӖWLerE?ѠL-NTOxwc'RjHKY X%4QN,jl-06:R0F;v~ẃUAF<-&PNA_Ֆ)tB2f#\auPaWa F fp3IH>IN#$k:W g~WLw/$DQ/OecO+H9u`AP(QU週1rɏt,H;J 1WШYM$啽x:2 㘠c81Mѿr@(N.UQɪbM%LѨ?$^.zeq@]9We2NI`Gg^(x׿!O{^h۩p6PN?fj].D,nY>Vf"Qh@W\~_8=_L0{"+X" ei흥%": )&LvHo(ps?.R2432@`V5S1R1][tzki^M;E3mݼz:a5;@7d:ᩜ _/ЧW=@ tGƹH7(1HP4;ܐL~6'_B~;&[uQ\x}.ZaZV \C"ጛD܉i[ ^&CJu?Fc|DVʻF:@;^73҅}Xf.c3"8]j6e# q}0B{M)I"[3Jt)$&]w(ӀH/~*E.ݹLq$̉8Ps,>RIU{]g)I~=c r!wF10W/m:HrtZ&=sU> =G|]Z,.y` ‡%_z*Zc-X[#7-^Rg:i0}f-=3ϟǽ.)3S.MupbIʑ7]3}zFt=տ:װK鵛n5O[ܸ! jQ9$(ӸD{tk_*HK1|>jU 9 wʝuf?j쬴8V9o-mDw|# d6{%r cWGb92NJ{*'e|fýqplPͦ| [xB7}:|ZKļt5VqBhv є&uJvT dMڹcn8u,ބRxq-u1FXMЬg$pb]7%pҦ;H A kMTQkqD:Tu@mnʖq9ndf+cI5hcGU.{XFv)Ui t9 >tw#0[qIPyrFm$x|p;g-XxC6݅< \|K+TQc*kfF~osꨰre0<?s()D8 M)5Y7}"橷O{Ġ4H> xr(so5?fT+!N-&)Io ;7|"HSijma"!(1i$YsbTxVLZ)%M- ieJ.zmWQ֏V}w^ܶ[j2Pчpq| q)A u1ʒ;M ëQqmR/Y`u^mkC#iʺPAD&bκ\!\C~*CBS`qoA(GI:d^yYu'P<ʮ@/CJr 8?*8I MJq/&zdtk'2e#*8K>9\$|BU1Z< !L,T+#61 hp2]-Nb)HD @s1o>عWdr+qv0RuˌBB3K^P,+&BXK8نaElZ h`po;%+dw:ilI6Du&2iIqq\1TJug[kE0]}*@hOhfV/ww>/4 (^ֲqv)7mBacPʩ/=@ay~"^dk֑FO!3I4^ng:L8'#hj( 淨@ 3:AXUv!^:~z?C+QYuf~ aȮ_<ɨܟǦ)$ ]9 թܭ]$fe nN"8*IXR5`^WH8XI>Ծ"@yxՍM* /Rݝ"LDrk'N cCt)^VmJ(7v5t]-e߈KVҦ\;Bׯr DOn Bw\Rv=UWhǚ eW!XC)S8=:L_gfbSI-y)%+90ŠdƠ\/"'n)AXRrH/<`մ3c sHefF+,5I9 b~s>jB}55gG8Fj4B/^'9zvC,n+fTfCPɍ`Cc\LGω~V@u H ip;I#OD֟\_BB ƴDb$ЧD LwhìLQ^ln\RTSwJ>D:NSbkk<{(.<[/9SydЈ`u]5E$fFDh%ʶ-;iA"-&,x ӦU{[key^ ղ)fגTΐHk@{`'ȭhkY,Gwu0ݮ›CO[g1B\yM$0Oq_jf/˷cOHN3ok+0}'|%%<#l;e9G }ڹ-W]d䉱g4cfY3jѨP!ZS@R]rSY3i$0bf!Af:(.$qs~撺twϏsI i 16\1);!Jz 8}A۩B.nh.Lwk?G͂`ڨR|BA\үe,(Vmk $1R|+nJ >%nlN(INǴ/uf"H 1Jv$C&C1trp9,Pv QiE{&ElA '1{>K뮂/"ƨ!AE2LQhzIp?VK4mt<ַvX-4`bLT=.r&n >3GEi z%KGj~%Y@_nl{N i\!BGQĬ5 Z|͈{S=?%]|5 R}I4c ,#8FI %V$e=d{k# ?0`Ov IzM&[h?iq2Kٽ] A$к{8d0G=M"pvuVW١qh8ۿj^ AaZK K G0oqT-B.ޜ_AՙS"vxqT_/=ghj]82E"~|V@#:eytvFKoJBr[BUɑךS%'<ەEfn #>L4ec)eVShwLnM"s2Toya8A3mHrk[ ھ?ƌrV QLA-ȭ$MHǽd_ӵ{,jRɶ69P#^`_(g)Z+D$'ݛv/}<#%|6P9 ϤBn<v럤GXnF# #^5"[~ctW#uTw@0=Ġ}D^ _), _hjo+"GyY1bNj_e ԵB&ag72,G*.rnS0&o-x6 j!bФL7; C/軓zQ*QYo p.B"Iys#`?'dH:;FMb!+h,υ=ۣ~C*^sPD4\0b_Ye6~߫9JG ?%4 :=%4F߻b \w;ot;zVl'scwP!a$OzsݗS,lM>̰`ͲaoR8MOT{]/.RzbϺ%(cڨ&xIb)zcwQT}@o Ɓ4/5٭zGu P$E6mO Exq( X}.q"=Ycb:YUw{w5yf6tmLw@*t^~DXciŕ;7uC"^%~:s]5M+_;"d2Gj]&!t4&HKzā#YB\~ͳMR`|vi9@grU"F!AXPHШ ~/t~+]-T T 51dP)8$Lu@ аdA$_ָs$cG&;H:zixv8I^b|Lg;C PA,<(Zi|Q;D3LCn@ j!X$T5 wq?GP>k Lphy>Ü뒈y[|Ed5 jDd/F̤uN9ۢ~Ǝt/~?JG6x5p[{K/jD)M yVNd,6At:ߪ"I=5TQp*d%$&"g0rױ6rH\ݺFM% nG#yC6"3F=!8za6u!P|AB~jԊ2g ;w{0WbkCE{r}]C#~T\uf#Y:w_4L[ʯ{ lOú##xK>0}F'<]NlB?UE6z63jKy&~K7/c>}%+>5c>̏؏he/b;9:Ersܭ⾈Ԓm$!Hy_1֊l`0)t7m4"ց=uߨ@*#s["eו߆/Q@ʫ}1EpJi(L VesW=Z ן:r^Cl;9 p)eMw'X?NqBzfxb"l37_ѳ-S|@ngw#J5/+| /<떴EӸ v+&`hS- Y% moNlFЙ;Azt3*]Ymif=4f6M nhco|(!M+[mK_§"ۛOԤ"+L(q$60z6tVmjc38*R߻l:T D }4v*XvA8c:Y7?EJxuϩ1?=Qt+)A +k eaɐkͪ}U{3yzc&$TbfIUPGwoOָ] KEu(y!1N.}?-o•[sD"]v|tNt~un;;*k#oSz}$\W|YTǶ b4k?iV1.ΤFLX/(Y/יom>U}1\f: ipd.FNu0S}S$ȬO6> v]uN `kp(NGvM kͷG.u+F;>̼x>$QH߫/ #vp: }X+mSJ^ 6s 4V"FEbm15DBև<+ ݜ`c4 A$Jc^#l!_ȫ~e){S6G ǰvy[$RѴA @bDzH*G&ٸY_W[b$1M2SB7.슊2f /Ԭ.fB$hWa)2jl:wu!v/_1U!2q<)j{BA3+ЄxT!u(;{{[\!>wIGkYmq?o E\f~Wd}A5sCv!9< H +P-܃R~zUǍF/*$VAXĺs =D̩"!hAG]7HA%i9~(kvF|)z5d'G,bbrrrB16-U/Gp'Hhgz^tl 6p'˙z~'ʉ [q6VY%|Q q)u3نRp_^F@bʩ "ͭ]oWRv#X"TɑA-u5ȡ=CXP?2o=ӟ#`@y9yT'bmo~gp&PgA6Kz+Ϟ RP7GXq'gJY2f}k?tG(=e92CIPi;X<5Z8.UQ7w-*^f;zVA&*X _Au75*%I#0ȘH|Ts {{2#Wqgq5?Mx9Ҝ0wP4kx\b@L[+6@RjW?7aS.KM D0%' w@򊊧Ert@NŸ+ Hm`'Y—iz5GRtcÑvC0齒-CycΑFFAtX匒b$vhYmMa'/"s`y+t2~4  0M .wX?p{*یhH4K㗇h6!24UF%bHms %@՞=u ߩ֕f %'5 hOs!7>ls`',Su!qH޵LC)h'Rl2t Hc 8Ͼ]fT!D" jq28[Ɋ2yr|4{,$ʚEP nӾ8@[NT*w=SQWxihGP6DUA Ilцh~w! 6>+K֦y^ al>cx$͙ Qgg{Tq?h2BRt@ 8̰YlYɿံ%.[eXUp+ȣjm'BvBͻ)A/Q7umfnkHԋ+S$u #%Cᅯ@8zŎy,v$+7IOV/ AKT%/Մ(fב*G(3jY$^8 M ̽cF(;eཱུ|r[wrHضk( ClܶF#ݵ{Mo濞M  ؗRIvZ.|-jfbOC/+/A0>k3 =<(U1ZK.~LdUY,V0<{EOy&pnAS b(jg7-jr1%:cR^`PVP[]J!¼&wHq"A\pc`ac0l#g!wٖEKȇ;Ɋ9WmDq (dS9EkHa&ًq$<r-#C@Mo~ה?΅#~ :\67 Iթ_lR":q&RWAO]\e1P{2#= ߭ǮB*6Vƒ[%.Q%)\wϞUŦǺ@u|*mrPE^4& W=h>iđYA g~\mt8$tts'NecOg{(!L7#(KhS0Vg$M1N/^}z~J ԫ˙6/[]0#~$LݴjvßpAc ;ݿ/'9u{&ll,8uMCK{<VE?? ɷi/ a|$n:2ES87$ÔRmBLH&,r^ZQP趀{QuHx&'9=" }BNkj%$OkEBu\n/wZADu}`:$qFl5@(N u"潁:&4qs]@c:#紓l n9h4T\-#1M"/|["Ejg 37걄XfLt)tbhw$p޵Y7kZ~[5F)7x  ˔%]te-a"?\"W}>j#8Kvp*a!ȱ`kDwz_CWEpBda,o5\ 3;3zM韊ZXM fdqTCկte.Te;Ÿ) dA.؎ہx^P=/._,I4RbC$nw'cB"q<$~q{)O}_-..Zi3͗ Ec`.6^QP( ekGOJqu}S/˯bml)4kt|xt0?=iCw!S˚j0R@raCj!B`Pe:'Ћhmuk Z81YNƨۦA6;TΪXv=7SSRiI bmlOU> ]a`NL~^ .,=14Lm=Uѿ3#<"Y'Ө k:[v0e[S0}Y踮\3.;}WZQZc!cl֏U+uv,0uAuU,F_&gc[e]aw*Ǵ \̓O>EGu?k5NG͟ 56(Gn^Fh2tEA?AQFI#~LuI3ގզ #v IOzҷKm;$D/'M&cʄZ34#kø~_n݋ymUwsq!&Ov_Gi:ݤ$El8C<,Yr=譶ڷAۏJOggԭWU3C$q//i ЬZ:po?$D&/3N 3:0Δ݈P1ER= +Q^Voi}B SqPe sNj#?P_^=6HGOU~:4wo^t޹#w'jTݴU;.gMҬ1Jmmö!1Tpy~a^msC`8)oeZ)uW$*h㣉i2s/ڧ@EyuѣS^͓F碶D%SP'8VG뢧$c 뾠+8{Ҥ4 bpl 1yEs⥮Me]՜8ȉcjm-b!ЇZT3Cja M*XJK@4S{ ֟on (ρמHtE͟MWd(&;T@jml/+ !B*&KF&ze/u-^X|BoR8;^L@ߣ׉`b]&iO]:xuE- {=~TFR+ k!M0bmL ӳf]c3;5}OJHE /qH/n>KG2~ 44o]›`q)q8Uz?"܏p1K'H$ky; tlkFqZd{s M2e,rbvwD܎B˦|}0ŴI}c@w3aV-$ē S"M$fo_e&A<j՟v!Q3Ld-WRL e ҃m]N?p}]ň 2}$2?m2=p]2)BZwC67A;;^J1pqJv*q-^;>у#m[aU -?XĂn $p1.ּ!Iz|o(xyPq ҡF5G6 mcd+8VA1%7?CWn*;]Rbyvfܳeg3E4qeC5; ;)p7ԆXwEby4L3IdIqwh6bU:PɲVbfP[TLʵ[{x9Q&=׆مAV1wvT͏Mw0;XEbr4z`-3 wWpMu BA)BZwyA|P#bHb6)CE*}&y.*(ˎҹ]:՗pthj Hu~q)wtC?k!nlQ2 > P=[}vV.Hngr[UA-b)}Ȉ@`2\N^.Ҡt]8a~D5IOw sV *ك9SmCUFb<ح_e}`@ޘ)WlrŌC)¨ɑ ` S&(h9C_lo65|A̓sv݄ڦ<5T|al \7~>ͯHm`NṞ7 J(Ǣp&+-AD@%OA"8Rlx" YT38s}6Zj29d˂4R 8b♣`N BAE${ςr(SCMtZ4DR cj}@q}YkGWP )ɰ{Fe'ٌSý.1ym-U}+3īD* c.XRZF۠92֦b D8`[xARbCsfRjnQ TQ05Q֍zrPٌ\1mS) Jo  fJ_k*Ϻ0L; IH&^Aа:zV f 7q-ec +-k3;mTͽ*2@zPZ TiO: BNYv+'#Z G|p8a{:5݆o*;i^>Vc.hƴl'Iɮ +sPy.p=%~!)2FKV3W qD$'<㶷E&UMC~?O>=R`q0ÝͼmI}>cvPę5b4<6FE#e(A_G멀-ac6XX=d&d1,W}.EWmoעABÞc#^N,#GS="mAx֊B9S%&La9j@N(A0k6 {2>:6uL;X +H-$.^MzBFUX K.&F/5N<6љx4Q0X Ā&ʯQP^nvٹ4;gA_JhH9q3߼rkh_OG&&. !`)%W c{\@_JgYdkLLS)Qv/gcd~gdJ;S?qU]!hNb0@RG7;A^N#Ly7bY&$ߞ?;<)Y6tKѐYcZl7Fg1!]kzC+{w¤i 9:2ln9 x baw{(TۃE-pN'/xvT΋W\=ƱI߆bTu<79 W5NaŹ8DC3!szV%㇉?}zw't7v$+f.q.&Ij7 ,yW0=r_kP#ͪr94, Wi[#o}_բwdWl0_,~2p]PiM wbyWq2?/4B9}}dqYUu':.Pb#>I^6;k?oTMsot)mpB+AgZ)" &Z 5Lo@Q>h dQeߛW* -5|OQME}:(gh\_gݛ] V;Q >8Sg㐣#I֦PJБciGS߶T'vWH&${؛SćQ`rf|#H;rGJՖDWp:M}~v49>Pe7&Fɷ/4CGS2wrNNC)v@/$QK0:M7f_,UJ:Ұϯ(ja[g W1B"('z-m DsQh X$C=u/&Q _0&*[PDKM@G_K;v2n:ݢ`Aym,9,K!*SÐf]3&L9.I'J#VH\Et+zy孬EC듛Ry|d/yp9 4x@*e@ Bq lg8A/'t]7V׷; EFLJ1[djj8]|o-K[H,={VY4QQ7+eN{HTAReC9+1Q  ņ 8Ay$Dlw9*ht2.010 fepb8.y&"OW )slf7S䝀=zrB&>}lXM;X.#`YCrvHz`PdM-T쥤g/#2'k_cUm Qi] !Q)8ܶ*.)zvO\`R`a~K*ǦBZHcspoQi/VنF ==#bHc>ͼosG8e6 Is(Fc 'LݜG)!;04z>f<^1 ( ̵99Vw~}Џ'k 62Z%"\fiC C95cJ R2tV >g-K$lw9:-7`Na1*;1Zs-^hͅV;=ٖB\OKcJTF2G̛gN43[;yrB|ϫٲ*|I39Jcئm_hf\iw+8a,yF7g. {Ňt]9* Hlpl$!#99g ^˚xr=?= favMJn^&K>Яg܆4? s~N 0^-)Gd`ƮX(3p=aOB<Ӳ Ŝ 0>@)e `%R7#qijM[v?ghbO%}/YI7&a=е?&FDrLb9mfC 1 965^Ib}_K"|2Π{foJdk+shp~<ł)ҵ$uˢFjgj43lH o:Яb_/9#wP[x`~ z0?ATZj nYJ8YM.^qsL۸8̪v&TM5r j ̈́Mc(iA n*B4s8Z ɶCXQѿ&~lT};J?n'fP ecE.jAʑq0*J*; `5Y/ h.f Xfvh OUb -gdk,z2qr_r{)U:HWya\jd$ ^Zt/zU䱊B抩xy" b3f9%Dَbم8IBES7S$%RF\E8ָ[E~>( -t{T^Iޖ#bqܾk o 3$ؾDU~ ;OjuYNɡkrSD>ߙh{S\ODԃ_kze> `I) ?QMh$׺G!jS0 ͡ ؞ZA?߄2{7Aɿh-x`8b$sTbJҾ"_IFiMCSv.U%d+qCGV>4ZNF t5g C4gV~v <C4]uv+_eMs'JS.^obq!N2|Hk%Ye߈ʡd[Ԕ?ي^՞bt{@ ԼҲرͱKYxء~|x岭(t8;b [Ћ2I8l)|u'?;[e GBc]@X%mȹ5?-aȋiip˅ftU퍓Yp Jy8o/U%D: T֣/9:{L{b뇚2 5& `Hs=Nu_ 'x~=#ZRdV("k6$L0*'5A -iص35xL” Oux[|F˨h#4d9dh-"wb5:Bo5~3T6>UԺzB8cVfq-'̵3/$0`ۡޙlΏ WE_]_"OJau%|<ΣJ"3a*0,W7羁PfsU(x #z=t/geS+6I%(&%WQ̯ٶ;ŻeY7d/xEɹ'@k = 2 i".p.H%;#+ [5&xow_ۢ|Q>O NJAG${~o .E?- #Rq~iT=s2)D~$7;2>-2_CҝRJO7 3Jo܎T~${tttz˄y+6S*'{(Rɋ0(EK@b޳1=i#tMZ\>55Q q=y<0zA J X2ƻ͗kc^x 9Α3S?~?Wf[M -ZMOmi+%YK1r^aWWIg Lo(_MXA[RHBU*'5RnkeO'[n=6rNj9%|C †;2s;(`+1bQiXa<[Ј!5ئH>Lru9S JwO-থCqWh'Y0ɍJЈ k cB)9^Gdf?>ċlEFԚEKܿO)˂~F3alD3?Y +nu( %5 65[IeW2уCEQ/q`GO›՘֯( ]F!2Hswc#|JzJΤO$wKL5t/n' n.#  =e_i }~x&,0=jEU~agPȏ'bYv6*]$B۾aiA&R(% b1RY@ evҥ=,o4 [?%8ecɡoN;? Tn=ȥqM!=mbC l|"}_wZOz1| El=~ݞ\N|Gi1~S؇?8orؓ k 3E-1w bICL ^z=h+-y*fGLDןŽ4ϰ0NAIAHT) kuZ%>dDᡐ3,:2?Z"T cb]UjXʦ1E3=!ᆁwe;  %<!gZ1:30uĀy ]"f)?Sѵ8DbM:0ZBZ-òF1pFO7́v">PX_/7L ^f[xu7wErDO/J 䂊PQ૤Y(߯"~U cRR!R|C:}Gw.݈h.D/.:b!kNjSF Cg%y k^163DLUHö'Xmr/>TEǜ%?85JXh ͨO–U2Xrc;Ze67Gul{Jx[-$Ku9k3E4G/_:x>C'+QOW gim?iQAX {un??ȔQ76arH~0CM8&Lխ 6Sџ.OzуJ@cv:޼c :s+W^>A~]2Ҕ>4eذ„g}W`AOR7wµXhD|||K]'Ń:v;Xw!fzyQH7,ߺBΖ;Uz :#?36Iq />x֘oaL ߣ?|o 7M^HX693y:2^Jyŏߴ,=?J)6-R 1X.6 حNO5Vꛑ:z$e#.C8>J|b UOtdrӄÃ!JZYҴ7;3Œ.w8 k)I*YeiL7a4w~ FY!f3!d3(R9\ Xx9eB vlH#$KfZmxnk:?K;RCi"R}ܑP"#~5=n"8px!z3r w#GGV_[I`6@7`J B lVQ{xwvG.琫j(0M[21,|1Ɗw;7$9 6:di@F(  ye1փwwqUޚWL51[ %$e*٫TrEW˳ R[݇E:a= 8꛾:ׄQ eTx{{ ]D#ζAJ=_=YߝJե> ~hE̪eaKKRFxTzHA)Zq1"55=]@ r0ZLlOH1\h~<^+⁒61e;@PSPVT&32{i 9EUg* E Ecq]5x?s`@+wLȆ o`&G?m-x~5-f/S2H Tp+*YK-7Ip8GFP_ /LqnwUö7k :`;LOD64!}Q7К0#qMiq=g/;A4Y×dpvGDC{,1rkOW: SS sɏu69n_*V2CDG|eg{nXRV V|yU ΄{kzt1p2Uj"*$Ƣh6X^ܷ;9AIiЂ0h2N?XjLI>nDp|w DQG+) +^&bpaZ,CVJ^Ƈ^$e H,HoQGJzۈ Zq7i=%|3?_;H:G>N1ݜѦLE3{l`22S#aYPfm%L9*mP>A EzӃ[{fO<`i P| (ekf<%ՓMşrև+:{<|%e$q4 \W֥K0gFq%mu3 ad~%{kxxvV 'QlxwNuGR/*cʝ)lI qpĮ֏R PtF,_tWL'?^8<'2>|/IIa7 R,=4p]b8ƻSo0?:zoi+3cոU7@3^,;;!i[hL/_6q{N`w.WznT:'{#9?723$do_/;9R7?b; +XFl)f˜^ ~o:(~sUhm<0Q\<'!`50bW甚"[,3* d#󑻦J];i,Oxŭ" bTDuN%Fc+5ϥL33AXMCg;qU5Ks4AcK0 Dh?Yn)z ``7x{MЗ?6,,XH@1Nǎ3ӊ NF'_vf}+#Hv%ARwub2@S* Ԣ ;]_}m!iQi2v y(a#!])u4*6M Rܒg;Gp2,Z&cvp4Ip|{,;ixϯH([hKIArk%.n/$,Ý[%+Jj‚G Jh"$ܽTdfƲQbG(JAđ.c!rPsê[ҢpD׷XBQa xbA"6£ͤCs! pVf@yrv 5#*4W 0_"fuVzЇzEil䍆?&0-oWwN\?'zsKQmU, àNV"4$2DH4_l BRp}pSf!vWLTUeXA~)wbi@y}By]yY8 0l$qմ14 zٌtKi% >c5̽~{&kz5EQ&rqy1m˞":īZfц$Tf.=v PՅ'Z1ۏ!8iuZf%HVDh7f6f#) 4'.H"drO]g{^qNfƿeOG}/ hΟ28J?Z!ܔ]c 5{iv?O/!c>s;Q! K8# f[Gf?&U{N75HS J'7{6X:uS\oh.gl8Œl$`fdb4'4' 5]rm/֎3F]}nyr%`z'/7oovTf0(  D Ug.bWܥxgj+4s*߭}s'd;?zp3-ZpJW  H蹭ӘCK&  O0 ϡ)9Z=]B, t/]X:*RbtY\;š)L,ot{ew-E,#Z~ZD‡ip4?EnFj#|bJJZ1&b!ZSӜ⏞l!_ xE]u^^a" G{,G&K\W= &nqܤ  g,kcdTFIFxw<pU,o\]m 1$H?p-v8Ms#E7R\DK"zrmY:-dno 9KlܕZ[*C0qK(U>(Ǩ%|6#Ww5A$<8~/n!) ^J'pnJ3˩>_s^qvJ9h֫p@{CO:3: ۦ"=༧*Z߄Eݝ~bto ~MZ\yl~啃~v;4mEK%Qk'3KZ]MXl$Tfdifm|80\%۴Q("| 3@A0l1*"Bm2VQvht~SB^$747o֖s;L8iz7[hV&D.T00W77JQ Z9t';!6 fꏟo5\r7aU"C n5\DJ&C@)ll6\P(d曗>2,4]@  } rڭxy$O.<W9s25= M5@Tc`)##I'8܌ӮwfRǿ+E A,mv9[Fqѻs1WʞQ\ة+$0NDvE]g҆ !H~t੏#:2s]qHt*_ܤ^oIէO)SZF鬣K5HH),A:|Q!.'н>1ZzyQ ЄVM'A [0vvX`Vy? lu㫓Uk溡\GNMחw cm&<9^k؈yT*ől3pwEPi>hɕ@V4D-+FCN냿9ttǖۅ3ybYw灅Yۚ $<^b ,"bg;ʎ]zQj( Ij@܀8׍T,ጇ#S) Php}$":J"5R\h+Z:jf]I*D8BvU+Szk?-^$rt2RP &H}wdʩ@2h=XifL6lAp|QJޘU ]3Us.Lf4\KKN=W6W]4jK]eixW8!܊9I%^%[+oYՏksIrmeˣD~{ථv:_ <@PNpJ5MFt}z:5oT%t ((`*4Ss7i nn.)ڑsHJSbWYn*CL;5\2,Eςu@-<1rMtKǽUmPΏ{~Yɳ@cC/i4P\lZd"O B%42:nkbȌYw DL0 -&̐Lbba.01B=֟L2:{vC<όٟWDmɴ=$c8SV+t Hی yS&a1dwقyhop0yM'{DYåZ#ްsqz{K6iDsXc[Ac՟KgD'(qta/ Ƌ>oĭݼJoT5SHoղk8T MF@7'>5PP 1EMΕckxي=v',L\-Ϝe:98V~tx a2)%,Ƣ˳#Z>wvC #%L։ԇj$sk9AN;%G retԗ2%>z&E ,P@GL)ҿ ?=b,{3|l kIv2"KD$4aS9ҐMxlC +c\S0([|d'>#|W&, Nry(vRx{xt<^0*I齣5N LzO?Qf eCF]6F/kuvדIMKdux@״tGQPF=5#GS(qĮ6n(h!*av%Fc-ZbȜBDÀ]%ԿHH߱g&i?x%O {P'^7K>"!-XgkB=x~겹kHjiG%5s,69s,uqJ7D1tˎ](̡ൟRs ?b,@}GVPisD@aB]0]PϏޓY;O_JY ߕXufXiBm!)  ʹ!qD[W~q=4bzBE*8>?ZsP1:`x܏пU}UߢC RZ0)MH#-.Jpa+d@ ɻ X MN6٘n-ay͒# M ܮ^*[=c!po y協;bA)mO"SMT.8YY>+͚bKe1b*!> qμ} j8oIpj^:nTs* / &§^?x!j.x2a[y _'Kâ؞bDy:T[-=LU,9= ގfkf?S!?=r2E$ȑx)_Q"Ϟ;5AO'aTP U֊ip` Mex߼M0>z!?2m% 4éЌD.Q0=_첤癘w |<E:= 5:t~CrCXV miJ">[:y UkD;rf'~AȽ4:l?YP>WN7h^9cx!JOl5%WBrIcsjq%?39cϣ#]R#r#\kxHVgOm-jFLr9d۩E AC,5|ivNXnLќkd#cΪӥ:x1֣u%t*ǥ2*ِ;*n?:U >f>%@Wt9Kzy tuM c,:l¤&k1NR^50O,ln o%"hYʄJ\b5G"z.NƯmcMm!E9,&/Y./(UOO33I4Y?mF 7%a7PV\WD||쥁)Z^ό_oš;Q;x]Fp` LDQ;}|}}S٭'Ogcl' %uS-}];rwarJՐu^bXw;Ny`gRjtWydQ=[&kP[X۟A1#~ܛKt-fu-Sv]}y3T9C:b9O_$'WUOYJ^ɯ5)0~}MmQׁAή3MƖh3A\ׅ/!;9W)"m]?+s,׏^4ܹ_U]ugHLo}X?>SRHRtSQ ^sGC1-qtՔL lzh콿|mǗP!c+jEv?Ewb1]k`is_JA`tYqO^oRx#RϼَlT4jBmJdžv͡x~qV dK0W4^L()ɢ*8qI_哃]f KOoLȀ<ao*!.̗  "a镪۾g{㊔:이hhYЫF# hP& -S5;&N\#G8c%j H.Y Zs,wd^Bү$| zmR |]V3;*r´bvM#Fkt5}h[Q6^9eNS7QHA-;I-HXMNiUڄWTG%Ripq懶'[)bָB"x)?STJ7jGaQ‡OR3,?[Y]FiAbp[x'0c=N @Z}A'%C1iv@* x%  `|6u̧ܼf"!/W^]|7w0kZCOy&^vD&y`hc(FS]Oڵ|v}lJ>Ӱ |=g5iiBa<1?!z@[[ӮSF dR 4rDb_L O6I0H!.ʓY4,X=j<`5!a}6foY"׉܎pq|,TLڦ{3*ܮ8Θ9jfn.cɓz}ˮ2ދ ;QWރ 6Xx%翢%bCWiV)6UB&s(Ay?#V@x%_*nE9p"WGˈ_Ǭ~=Pl3 #w$D{fE!q <|n4w̠A)??&/.m;Mx\"JiS 4ÁJ|TQ}ۖ>l|nRr0|βh'+@yt&mOAFKzV&uH;rp'Gʱ.lqP A3hD' MmqvG8z^6)N`o/l+U WTBf&)á$X`M5 %g'rfB55 ̸̞5z<Ί|G;1.ѹW\͖ͷ&hD: [1Ӹϯ|%.todf&@ǽDlpn7T5_Hapw9ǭQSqқ@EԪÉ'Z7CݭhaMkM򢨤mb?fNEbo\Q ӟ}*|U]0UM0\LjdT GҎ9}W͵-i}(Y.ITF(Js< Qs VKW9BlEA#5~f s "BSb>y=՚oh/":"VQ1&ĽMb13(pЙXXP( T4h>v2ܐ[1w6GqAX%?I1@^, N"X$x 1rX%! 3>/A(9v78 J/!|qd(eOȳ)c':ZX DbLj!:Ȧ WXwvwM0KX0Qy%JP[X$2n)3? +*ܿ[*< Uepq1y꜉I23&rzG4@^^:(>\G=d[P)p|9^G@ߦpS,`$T{ U$\(y݉Zm#Naq/ʅWB]>%!Xw &KGhhAkr+_WT{&G݊g"{wa3q'bF1j[ŏszc7LBQP~TQdvZ.xgEeM|OsS(I_{ЌP+DgǎU.]^܍̶LO/vfHSlp }6|&\G#ߠ\HYу:½ #W򰉗Ѓ2`mHvԎ );gx YsNÙ@ 9q8 wNlTv`ًksq%`c6TAC<-.xm",,y2{QQ7e4[.xhwG_Bkj{d2eς2r9!@@YaAtnJ 8 v9 ǴD…c ㇈ %T+&aIY7h*t}5:bӼv\I2X& YKPI8uYROp"(F4Y>6w\bz{>2t{]oP #T`DŽۜm>1޲MɡLsE6s-X&}mwBt>Zńz\aɝHn"[ְ$`»<V| LsS/.4U ed>:{3k 1&&kL,ӓr@PM<[Nu; C}FS7$dG$tn3c.GȂ޺ҎoeGVs#;Z>]0R!d-n1hK>|LX4d hQ3W@!QQ\MBp-aE.̨'Xڄ7:z3DˠY{{$T՘Q _aZ9`BqI3ōZLtnZ䫫ԐfVQ6źW3j|9o3xo :RFP:ST;cye2W)-@ Nr{! &e"gqWFF[he D-q`lTmbnqsHyu @~`&%^=v'~`H@X E¼MQ&IĆ7C.y&8!{g!=?G4M38mI Xܛ$@:&VjyDjU'PaIߩDTŀ Z-ֳv˼ 64 XDnx+_Q)7L:휏TQ4&AXd KJ)C$XE@k86n|l\"jeU5/]2:FגJsqo tL2dPXgѱ =mrE"zI~]!r^̎Tr|E lF&;4 ,mF=Ѥ8BSom<{Q6cpyg'BuLfɑ#NO;k\́`Ήʎ"7ϛ6ˈHցi&8Ju{x^$v yNzo.֮CF<!^PI)(@`yzo}<0NS-VHC zϑ}=2ܺb_q=eA^N UF {XVi⌁5 Q/0uP`LuJ$ 4o݌LmuJ U1J1W_^TlDn91B:LʵpG8P{ d]ƶb9,"N.%ԙ rOLS5E%RƶQ!ۙK7vqWO^diͼLL,xNܓUs_hn8Hgy*1y4 UQ!(a^)nKzPE\9op~_Dddva Ce)R)L qL," `(1D,pH>M5`f%h>$0$B weIy8+E/k,[@#R&HgT(G[a< ( 1sxʤb86gcScfX~qDSD9Đ\I)/*Zh Xr-x8"Tީ]I1bK=:|rHwZy(OW/&X$@{W,і)P_*gv9Z?׈a뇨Z slbL 4%g7Cvm$C~F)t. l)9&S-+vQ,nw9A[fηƃ~:dI -ES^hܭ/ã*g "ڽkNd9A׌Y1)73R0@2#Q+/]4` 0! Xj--/t$e9`B3!<"N #U &hs/lI7u/=P$M$L^&N 9ݓ#G=&5מ+Ψ-,r+% -^ݿٻ5ri|gFK0z8gCYB(SwY0ç!q~٦SpdϛM)6jHNC]`seCxT;P庺޵XE򝇅NVO-TȔڱr֤ѕ = jÔU Dʾ }{,Ƅ PJˮkvHEfI=D71K]ϕ>Mg_{=άX?:^[ϫ[qsRlˀ\r?pSGtg o@?M#ه\Pi3-_ml)E\q )i[r{xUZ"W7(7LfN)&vYҀ~B@ E $ܓAr}vLwmDS_m g2ԦS4MIR\qayoS3qlJ65 CcJ *DE v.XH>Tf(h9$g[af,`ܛ^K?[瘳>UEKS.< 7K}=G]և H.PxUG ~uN g9Z' )S}?0d-,1X*N)p~_f*YnWZap|D4ۯHo0YEgciR^gni}U`JwR>{M)$zڸWc4jfh/mzcAHB'8; xI"m_<S_0.~{% eISn@j]-_ۭ wwut,L5H[ ̉P'`bZwX:0՚-,O7A{668O:1[AtGn3N=ҩ #چ#/X>\كk&_Ww̑~tJoeq*L5!*&jl)[IЊ[WLn<=ѵ [Q@_&1r{J>*Y! ^gk>ݦ ,ؼk?)Y%9UipAh9Ο5Ɠ9Y7FPHHr"DEgM;P,@\.Ȏꞛ3s>} Yd-`DŽ6X;gjc^ÿEX]ZT[G+L$e,/!:TùfdV3\inYE[ HIJ_me;=7 A*D?/^znZLm* rLʚT>E[EUKz_q9RL qꈳ`hM͏{9` <#zUipBN9 u):c!bP `rr3hwflUږUY:|@ $map~Kðv^͟~7 'A$J< [Kc_G:{µ~vC6XZ+%C 6;Mj۪ͫ0 {|AZOظ=gؤupr'X`MYh-;̘)b{hz\2 QI7#O>Y"W p\g X75ENzRėĥ: 2)UΥ&DWf$09,UۖP81辿4އq5\|޹8y*+KdI }KMQ>D@Pec>W>{8B셪^A,LF̠H$%V~K*ⅷ"c܉//Kq{R g#o-R_6 <+rf/0r+6k'r .d,Q ni4pQ#&,)D<8ZNu'9#g:E-v>NJ´o7C{ׄϥ}Dxg1\#1hs8i>P#AN\WkmѺvz ~~rcgŞ1VWpN t;qg@_ ˩ɞlAC"QOHV)ܠ$ cqx /_QDe}hq7B5RhJar LnmȀρam]1l4djꬼ/>0mZc=Q&fpk%)Nj%%\3ϒ7 ) MKIi!Bh|;ir-V-*RB2?ZoϚG^r6Tϸŀ6m>λDgZkg{ Y&P$8*V+ȶ(~arà''O@#р}$b+ o=e%A  mJͽ4cSpfQso_MJjp!y**rXwdF1 E"Q=سC٘?ި+89:\3Yy|-qdZ#Z<_LڣOR$vAke@";B 6~' "dЎ.;޿J e[Q> 2C) Qz=p :5}BeU0whCD]]j-}KBݐXy񧎇ڞa1<>3ÚuE,bԋR5"f?lS 7Ӻi6RÈ}} Zp]ą:~Qvj`e` ÇBhȔ}5nj9GyeWz)z>tO^f,'~Rf!?3tm^=#|QFn\1n _[4I̶ںwC6{#Qa++ٱEm剐p_S(Md!e+ ۫^} =6rC{jMco/A w 'a`) *;XBY]j:aj̱`,pT A^SiZAKwMu)[º(pq#BWMh~J{³ϴe؈bO~K@Ɋ= vw/P Y>0)({T:n`V6ԀBi7 ,Z:P/583"2_ie3ɡ?;?mH`T=bϞB@ppb&Q[mRT* ʨdP[^{LWX7n@R᳏a A`1ocl^C3PG^&|=j?^n5`7j,*8[!A#LlLSw-]$.0ViKthOc mT:u)<#@%2SwE8ca7'iF5ʀ3LqC6FvQ Y: 6$.Sd8E`7+nfCs# J"P>ݎ6сδz UX)eɄ,>ظnE(6@`~< 5 a]&Ah5U"v"COwȰ>OBRko e?ZH^֘%qg{qUtlb':|%31 V@z^@T LDh4h8m>n)-# n9\6ŀ؅.+?ZYoq5MM`l?rĝ CLZ;/6؞db |JX`l7E>8Cs6ʟ yIah>$k~-3s{tqnߍ,h `8u F5/ |x ŏaL[R7[j%qzѦ*خwiIbߨƫ#N R߸Y-+|W0n1X@FH5n~p<2CKOL/4 a=Nyr'Å'q̯[Cڟܔä&`*}?nJB5b~Eh)q 2V8$g *_NUw9#g`03kV/@sedX*:dFiDP$/UG Ό{5]ptR/zYɪm#}(7Ku"$4YS0cfX`^KZU}Q :nСcRk3au; 肞1F鄿9GjNS=Ԣ=Mkza~nPO=9#6RX[Hr>;J1?q6>.QsHƸ 2`[gT:dAe弚mg9(ڙ]Mg>v64W#- #X]>8GlD,z!ͧ,`vzw > ZFJ;9GuYLUPjLL{yuz͖>5-dT7UעI;UM5 aH+.Z+EZ4Vņ3' 9 ]vn]S/6[Y*2cVhMJ($D-exEt;Ckf2o5"1G//S%68L_  DPQZ&4Z% %q@] 7Xp0=_}/-M?ebޡ -d5p|^߸SknVYyi o<;z.@~By?8yne- -8)dUԦ^L|jb1 ےV $lx҂#LbтLﮝؤze"*eM듵\( Lp %;uϡ=?Z8YZ3$em 0⍶EbˆDžqQdB9NKJ%eZsgŽ*?9 ?"1;EΟ~Vʕ)[X7tl!`2w4xZ7k{̂[q*bOb{C6f f_#?̏TEw槔1h₞;vE55;oڄ `qwg*)zf,@,= / v\9x;9bn,8^r7FZ`_>Ueյ)z{1A+yb,'80F=BF -L_PCdٮR/Fo$DEoN>z){}p1g`m47yC|c$s=W V U=(⿀XgVjF Yica8;DT 17cF'NS͡e &*k{I|J&)-7K٪YG2߫A:#3;JUi~0ʞ{ n{[#XP$,֦~n-/@/||;ڜ~o F;͞ÆZG{SC\aSޓv4SG!.ozOFߺK/D*F̗Jjl(xJy$mIt\nlٝ\?{Wg#v= u3omma$Ol[[aM"ߊɠf ݽK{VW!hAR͉׺;h7#LK)L`38<@Đl-b},6ZSǿ,5#9TT9j (tCs]H`C>: IKc!\:'2fD]tEȻ:o{4zOҊdmM?]P(d!.Pb!-%Ac(j|WZ F;!ֱI U1=nUS"nU&> nZty4-EjKx^;PЄwe!Hh2jr0v4tVꚽ,u:GaeN^<)JT?LJK;MAߨ^F]ӯ"~^Eɵofs"E& @v1"׈$ ҦfUj,t,h1[7JAb' (s.+0\lR^<6pËtlUu?8?]U=:n4$O#dr}(`d`4O<-(ldŊ<($;~],R$[BtXJ"U(>rGhPAjAIѪ1$–ߋ'r_'ECf,UgD4MwHC]+TODTG

p٤%  ^_r^p31("%hwL*1+K&QfS،yT y|^WrZnJ,a%|@p\skG]X,E`m-ONg2͙c @_"yaMw3[u~;&vlnٮWeTwr8!$4%D)r[r!I72r4֖Тzy1>$!} ]#=`\; NQ͆ۚ"*UfdbO~Runk:,_LBI7)oW.m8^;b(^N}nc[3 (Kš9n?Dò9Bnt #GRz}b!Q%_ 44$= (͚<LЉ7_KނVZ%IUf< s *C&t0${ORr_#F\ESGXENpE9g쵡66-kH|X:*>9=* !Nu?ڋZ}WK%E@jі)w;nS9:ZGҢMbP B} Y^DKr4pR97ӝXI ɲvz.K >4O/ᆒixk"CMFcšzƜ51Osj5K6giV 9‘SsF` Zpf겳$o)Aڬepu{ e > U#}7tON*ی.SfK$~5RtIs`Y~@?"l͏ r?z˳CBx1ܑ$. I|͢o W$E,!͎1ST!RLE44E-͕ –Vpiđ^Y8̑?UPn ch9 a Ho/ ~ʪi8 ʛ*;9xFYwEb@AgS_M FDGJݰ6IRK __8(HJƭh VBwm]Y+9}<RP4rBiJ73+Kcz}dp`odَe緌PBBQ{i 'zIA㔙B{mk%8ĭJ&ĈM;?I{=l^ (՝! >:4Q6 Jו G`HهU@gIgYݵ0l6i~,_:\ 2[UG4<+*Ϥ!mSHz0!X AN !ŇsE<;dԞI(ɓ?A{ (յpqlRcj=1HS(d+kqXzVXD9_me#(+4ˬ*G/2l17 Y*f.=Ig0=G?QWgElE /!\کC OqwVBgଉ^E0l6V(l]X)8m]5V"Jsμ 7V{ⳐChr[D "? ?+IvՊQULS2C,2RVˑhV@Q^ԺD4}c**kĖT|CGxc›Q5r mF,T<4m5%TCNB"۾ГD3/j2DfOj5*{ F;xbR%))ϾA+D;%(nڐY$10%]kbIL{%տL \IaS6ÿ/)`:E:H@S|g6cXڝ>O `-5!s\Zfբ(:2:nJW&osYh+Br2KeLwY{䲥r+#Zұu'4rxܠExH``2ۯTz(-oH$& jNyߜRގIOc\I=Mԛ's[Ц{MHtvi:-qSЅAE0wO#gh^^՜\zsvQˢ[?NSm.//CPz32 m/ÏYF4=B'[)I,?ob |amSG.-ʶyXΒ9kmw]ؘe(5lhr نh暪f*`ֺaQJmH`_$LKL2uv{`ذxeL4Tqu#pi"}1N\ъ<\WO&EXRPK246Q0H y2(t4cδ3ǝ uz-9L&/H/\z@B-uZr txY9pi$ֳV&r}b92E>X~yYO2dƂ|ɱ3Z>]):[OFC]D:v 3FA#,â}釕-(*M9M1 ]*qdzlh 8d4R q@۞DˤVˉ #»z@.炁nzs[oqtU#Dɷn[xMGۯ*FȰ؂dJF_~5Ei{vT ۗ x٦'/K"zUnܬ׼6YUan!&y !Q9ɝ2C\6Lj#:,,nNYgTmϝ3k g$5 Ic^l0 Q_ IꔟQ;"@2p`ߝ$JuZ@x\tF8C26HDH#cjE!+>̇7n!1iT3IY"WSx%Șɞ%oBamսjgxeH<`@jsL-`Uf4`܅Ntc#9paE6PDAvn [$p֎i'6;2xh[[#c>x5Y̼izsib7ԯ#vjԘꐓPWzBrP1 08g#sxIǘȨșu OQ% #+UqJz!vUAVkx/;PeiB1 -Pс#mPj ,e=SX#׫4+Bj4JkD0 j*7x Jt}rb8d2e~Œ=c`Wolv^]K7){,󍨗3\ &tAAЦ*dZPG%Sż ]ЮxU{.8,&O t-Ս$Cn(P@n#5V?.6ϒDqA$+wr'/{Ms[8r{Q SNc_cX -³&qN>ߠGjl哜 ^ tyJ2U' `v-a\c۹2yA"L[K[F~L?$Chhʇ./W؛ }JcFv^Whl&;,P4Q0y6Clc#=wc# lWjs_j2_B4oĸ򆚭 }~Lc[GnBu?"KW8񕖵^ c԰MgBjܝA4cy=Y檢(ʍ1_9ɢxE{[֫\Ɠ$AX8b|Jƃv8zog&/o |%@ΓewD RFg [)hVp6w"1ez˘1yNe=ѱLjpQ ^ 8^%>$K] :c[ MK +b$4RYO^JƃOd]YM!n\H2ڹ?+,Xf+!dniFLAihd_]W+ 8 %-RЋ6Zi~*6p<Ҏ8Cmk#Tr?FOu:\(Cr8z |2K :SwYv[-`YDæގCw $Z~Ϧ?( üTJ9QzߎvJݓ.N))gj91 ;^L=Tۑp''8ZߡIkڙ@&ogKa<~8^!(n4>4;M<]UVWI˿7n0/0frZ&px=ѽ>_hvq8UJk{+W>8բ˨ei[42 -ҙ-;pXcb?WP1SvӢNqv ~q`8[}S{F(;IJ˰rE|( Qgozvk 5JMFPVBQD.ܑ}r"ݵ$?t)C𤩗AJ2ς\Z4ڙbYj[hTZ"q/9ƖMmZf,O7rSe`ݔ 1f?bK%%T4ĢIp?mgV?èa̋Rzv,~( J-Tj~+*;-ek"6X ۿ,,";^1&|Qxz^ag ,6zDAf :I}fFu 8~_h6ֹm)4܉]T/=/+̥R;g8 F6de(>J0-\c-m-IJOW<Coq)@\'Ԧ_}?9 oR~nJs8,߫ͷ:PHV0^|@K jfbQd=GnP~~-YZ"Y1‰qlMH3" JV܅lXn(Ed8'\ƨB˷-_rhHLϊo$orE}c 4Vr9ۆ{Rdj茜G]:S!m2p/‰z` º4M^V~(AQK}qgܪ3nY eBݔK^nuNAXb_O(n(19@{q, c™OᙜfoۈAWUh-;.+m\g1Bu4%CͨӒ ^2c;R{ ɦmu7)BmD'voP/꾞%alW?ui>Ǘ0Tm㕉]RZghq9=C߂~xh"PO> SQޠ_`bUDuqeDHԢ;8I'=v -7 #͌i>9֮1)GtO;}IEO왑6@UBa`t"l)WXeײ-XJk ךPJKYc@>"{Hl+@!΋dXxM&RT7gpq&m0[SV} t3߹]n}B@_XP96%>c;_뢏 U4@ּdUޜ g"aw" ZLt: ,nb b)-bԀ,K+R*0AY4 RVomؠo(ٖ1hMuz`F|dZ،>9r/#{Vh\ dAF9S+}KoAhl i_tDzWZ˵|n&R@Q#4j:V{VǼ\GyS[Pڡd`MYhOip8<;&᰼isɷn #4s ~PƟΜф~aF@#-7<2|+l C/f; MfΆFWq^1x}O~ 4F(3>Ɲҭ#b0φSI|6==)dgf#ESs R>Yy4Uڼ)6>[Mul0ķ/9W| E~[9CQz&vag!0پG4DgWr -E6fw !>PSWJ'H+vMUEeoyS@C!LJeU[CaOgV /5a>p5q xZv:ww\N6{h#i=Tv#Њ6m)No6M^'§H3Y2\‰OnXwFTKgCX޵L\Qk.d'h_@M^6Xd>=+lR]S5*^ ʡG9_ C$Ѿ=)8Ynԧt<˲pǁq$xAk4ZQVɃ Ԏ{ |xް1nyPKI>˃Yt}ړy@N ,FfLd/Z¸V*Mr#4t-!óp8ثV89Gk2WTnx/kܓad= ==BUA1 n(VBƲaɚ-,r`^7[G6搲Cy~v2+KXĩy¾1`]hsX;}9NĖr.S1.!]{"sSA"AHJLM[TTMwrFV5sRFtW+ U(+r}#GSaKHMTTg9e=RQ}e{J$+L-{uزE)rQ[6pg%L2rw5ԨcrZ80E37P 26ۆ"Yd|l}/4?_g>2iH 4Ia?0$5j ZΫøX)nrx3p8IV$0yeƜPMN5Gs-QjqF5H!W'P1L-DE3:yAq8d}ml 6cov l@6 鳃MT;?6}hu[,6eɆqܘGn,!JvNhڐƚ []\ JQl7'0$!g[eO"L~jٯl'8OP8K@p`g`vځ?=ls* 6#Vfg}i/XAz>ryֈIlwGWB S/5;ʷmE=?}Q$Q!p%K~nz3 F&4rgSj^@z GrgOhc=fT:*Őzߕ<&{%U%jp^ašfǧ K C]N5T0 "@*i;ТS:BZڒX̔Z/' K"poy&)^~GܣaZ{;zR:ǡKg>NF5nҏ׽>%y6G_J(ܞ8!s8[- `٥,YSrO]?q^y87(?5h>_WkV;=#`^ l3vX}z},c"2M~WETi&ѲJn)keRL`:3ZYVAn4l.8/TkAo2#$}ѥAƩ7̧݃T+vZr|go%|0G_Q'\j I؁8q2DL<2/0}#];x{%ЛDL1rMM OQ氪BazP0v)3`;VvDWsW FT"s=^u_rh'Xq> "H=Kڳʿe-&@<)S'n(R8ε .LՊ(! ]fX˰kEs_td\DbI? (<" FB(xӼw1qU̧V,NN}0Agi.ϓ{ Z:T$lP5'*L<eT⚂ F!&#1ѳ20/+~)fǬ-Ć>I>v2h\@$2dбZ;~LL!\ 7OZ?c 1;{?f~|?,r9d0&Bݼ6!\'_ASEƵpmۜ4З8*j@Cw.^gӛ幊hEQJ泉*,{JDzqǑƸы<\LmR=/O\ jOS^ X~yU lëV' D fV7斬8c=-/`2C•4׃YRir߽0G0x("-*]xY Z*(WvM2~0/N]|?dG؄U5oݡ~qA[pShl{7EpQ,͂Dc=$m8^b4ǚ ՞PU":|]%>:)>$&S)YVӿ!kt DvH!G"҃1A PtsUbYOz㖒 `+zYv@Tw5"n֪b ^4mO/IϤf$݌|a8Nݲ5> eÅ()ՌaH8G^ՋA*#`aᙣz-z(U@ aC#^YjQy4p ıe /$b@KLmo5 =mlr_#hS1E_(v,aRE[>FX!yl:>-zRl"  ~)duo)L)|,;Cw+UQ$;|)"VXÆ [jK)H7)DD2qޞۡ1|l`ڢ],-0bG(Ar\_F쁧%)O(*!+}N BsE׌)N U?!m^|KPȹzd N2/ʻ&=<?v]ٓNR`( ǀc/.ϥ4#+:óC-x!#? aGI`&R0Mj.)S1_%me"!,t%݋AllP T ;(@p_DkH邺E7F( K-N`?Rvc+BPsDc1CFsFd oYƀF`4ymZHiqrj8ύ;-%#dW۠Üs%y [xJhNEQZs 8^=Im8җMQtA Rjd<<9dZE[ʩhLQgF:th虚 Ni 5h7^-l4nf;&h #(B^॓m_C͗'Y !#*2#,bpk^ܤ.HKbOVUMոa`v*\ qMr$=x+!s -/M羽2zd1m hRڜz+megpGziQdߝ@z C/qzXib΍O4yH3s+Dl96sP3~, ױe@Η`7z*Vl%繶yqVR1X7=b ʂ"C'7=Gws=~@uR/"gU!x/ĝ0n Ua2S9G4ZE")HJocqqu EU&#Ԝ|U89LE!WՕ/_h^`~TeE^u+7:8mzCOH8;^`@'l޿}AD.K%F fج8G-`]\8W'' y>QDPn_ QE`XKV(@)yyLJ&4!{9_OU4u̾ a*]lhA>2t%=N'K !Kvg8,9ƹ>B#'' W x&>h^w Ϟi")De"Ň"l,YO^ζ'6V:"qK]_YX.qzʱ f :\DI]|>[{xOSGk*0;'^Hpg\a=yL`p X9KV1R(N7侘6@.wAܿN7 ]Y~Z>$N͠g`77:yꢅ~z^ u%S/SU+SVxպ֏MbW`(!F};c"$$yIA*sȾ7XaW yTN~oCZw[9g#~[8a?'lb+ q n712DM]B#G=nT60!`o']nV{BaSUYv,~ H֫|bƞ'_EĄ"nol6eе|{`6G$ % f<îUL'$tϛM l4S&y \^:P'3o/>ek=fqrjיeB4σ Qmd[q69Zo#Le^'h/_J~2gDO,jOH@xðɫQmJc͹HR t)oA?ͯ 1zP+ x5OX/ t`9́<z5eY[{pKӋHٔ#N83Z24.u}qt~CI|D2fj.~`dV *\ +T=)aRMv<)v- 2&m0#+0Y-r QcE(; (YBd)㦘y^'9o;T?sFj >ZCIj.<^":<(Aa٧Dk9^4ƀcj)r-h'eOaewռfMn=^'$ld׍l(\R s]-ZA bAuz{EƲXaI@gpb cWPlp̷鯾H."֓;@DȊ$s_r'جIMr?9ګHogݸA{]к$+9+D58mSAp a$/QynJdr^QVDK}?.͐{g x53: g'R{sw]'-GX}OKڠwɾo!/)W{~QTJO# aDa$5Hގ =sg] DI%:հo#d8YnmBLJNwӪhMr.#xѾyq˽:^D~@-y A #68sgw(i^YV&12FS!Wses_@S4LX,Qu;`ӗ*$( @.ƦHyj XrܟブgP:yK=SďG)e`ebz3^S|~ǰp{ 1_{s7R?G\>qnkG,Ef&)\ǏKUxl+A栯~(A)KCiً$CoiYLgmt(,mKG%B rZy$T?|< J ;T $n*R٨\vYwQF~@;/$O(H,:4KN|jŽV vQRN^i+HfN*j$ߗg ^Ó·"GS]e<.z T.FPA{T!ɓ>PJ;U(OQE l#y(+UL5=ˍ,.} ӆcӃLe]ab= `WR2kq-/e0v'z8 kK w3 ?3JR;.hu@ɦ%dZ8UJz?d0BR 7"v߁rv|p3dGh4yÐ,rkccOS 3,万w=ǭ 8U_w›+d`4xUwDZ Ҭe)5R/XSPx-o0!kPtz.;5,l֢+h֬si-j5Q&'߃ V-6 !UҖKjPiYo~jEC2|AR!*ZHk/$-+#G*8=)@$P+e?6$IzdИg8n"E zH)+_bGx/D*,#7Tgݱ qS+= \r3ٕ=Sj(D6'5FQ>vp̛anr+%jq! 5ϸ*G̯41ڟWـW`dJ鮀4H4fLOWmGrJ~DvAͱ瀸K}o"܋.a="{̞\ 5LSqKK&I8`rs$2)KG4w͜ 8GwW$Jh,]Eپk]GR'uܝ<)g͊_ Xq燨 Ƥ)}wsw32Ԅ#u7p`avx I@'^#䭿bIy܄@-E|[׻=P41jqWi2Jn^Ӳtq؆X0/$jiGqPxW*f) IpJ-&v`JПހ.\s!|C=jwP'zA,u z4ggmI a닮P-z!c]dKA }Ͼ n0lc`jF;QlG%a]=!2xg q4Ӛu+bG;g+ 6HT:'MW6f"V6fW<=l'V1qHݻb@М<61l} 0?Ů:N|ri* :qͬdRppB03"N+0{+\Z1)8)ulacHs^..)hhob Gl$Z4y,P-?*ّؽY$ `*G>Y{i]z_BkViKZVg^`LcWCxBض; uSo]L,Ѕ=d%?N4<Y5j?Ын], db!PhzPz` "vƩĈv 3s.dKJ(}f|uH'H61I32 RBv, J(˕DR"C>f'744a?cIhFETٿPz5q3_}ͯf dj9r,=lBSAh>wMOg!צɧa8SR{ţԠOg h_˽rATvQ.s7A4n"'XNhfab|p[W>z5Ve39tLg&QhX[~ ZmKQd ;F F%c fht< X]>LqуFZe -QeCaW!"m):@p|zYv6] FQnUd}S%?ǔspo#c/ w~N[d(Ն3%q{s*xFD),pw/P`|vpn`3q/s x?pMxy؂]C1.HK+|<Kiɿ̄ףscu@%<*̘#bncYԢW #9gQS5uZRЩ*y8oS6Fw"k9R7nz.MuwneN%0M\ 8ϲ1 Jy >865B + y]:A0U= %NKR˨^;z3DŠ3ACFmΆ)5E/"Uf*]ןއxL 9T4ZH"8tYIΏL!n[Ss=,pq|SK &quk#>}@ZW4-MY_ y!Px!s{?n0 |%uvgɦ[Yn t_}T'ZhYuk9}#Njik Kt}:m-*vN⢣!Bi(CU,65½#?Mh@>SyOM(Finze9ha1NcаC8$i˺ҵ@c5KgnUݑajqy6IE ǐx=OM fB_/-$lÔHd ۉD ~x9,U-=9BP ޖ6p( ڷj[녳A'٤k{\uî=;grs'߾Iz+-lgr>^K1Dδ_ 5<Ǘ^֐L1} tJF\\%ClTcNOkՑY bWe!oLgzs*1 jKh"%i }y8B5͞9n>˾Zݑc2.X,C?*`5% ל2H51P4ҋo٪ܰ"| YRg<"nN`>_f*ku@$#ߍg@iuLaWH47ŸS&Џe )^\Z6sZ\3d0/ʻQ^mt7-  Jecc`V]vg0LQ ۈS8g , J&w!k* }';8C *CՉheX 5- 淹ጥNp!$w\L# kjH<'iÝ3H<. ǀ`3 .!cQ6_+͎RՌq.mٮ$◅Fs-"J`AE*)M_rᐪfD?82A=X2dϥlz:p|tt, wC !{~]\g&Bc\~W#z `̢T6 jxM9Oڭuh2ϛSݺG'>^*?C&|,F!8Q}9k=Eb{Ǩ۞, o)E=x`>Rpл15"xǟH sb HB=v2?MtRopXSl.Kbfʼn'>sJ;8/)Rج<f@1Y #d~S2~ 6>5aRBD:G§ m/=Iԧ7W=^"{n(uY`kO߷d\j85/#E,5K[&FGF7THno" $Y\\GY"u__|uh746>IWSn4Z/E:"Zy DY׸]"q^n8?7)cGYcJa3My=\ *80X/QE8QhU4<}__ P|7wi^spe{-)xz iu՟,Av8-u#j;kKHL 7pG B9}"lu8AgQ,XuvRo9z<+_z:.l6jXUt=Їжȣ>:ITjݟOPt~7;xh1>:- a1~H4|"~-V^7@&{r+7fIa12@TnyGfr+(  6(H#|шhD)`m)HܩxP7 ny0A"{y8<u*.0}}"2Ssx13lr_ QMz`0lyj=#,0{[ps=G@8W w0~xƍ~UaCY] x ʢ|Jbp]VË́ s>E㳖Zm;z'8렵Yph=E9gQ+vK7J<^}~odZțB(@Ψ=Z"u,>0JqtkFr>LT稜]pNz]˧O)>Ҟ2tG*<χc6&e2 g̩N: )}  @w(_׫hM51ʖNj#NQ6NHWʳҿ^ŋM{m'b SuK`lرۢF?|4ڹXwtdMMF:ҩ Npu/b d/땧-Sa2YryrB^Jg ĥ ~jв; R1jyQ <`N _TB 4֍|ߚ1I4a6\_6!br_n{;TpVkH ,T3x TCd m(6Bh}xM^e李=V-"6A؄L@^0;^a?)%!]ep.x 1:#comߒyg;:OI>vv"q{^cL'gЫ*ûB@GiE΍ n^F @&m 35~YJJiaѼc ,ؤ͉Q -?YqnwZԨq͜wTc;~95{iq{jNJwRm*n.Y.ÁG$;z<92a]wS':=O_W0 p6-cs5dE69U)B 7ܶ{z(覶 ~ v@uW.^6q۬ \#*îzv a)&K8$Tw."pJaKOeU&}C/,/p5'H $.Eq)/Y] q\/,74ܷ=5 jD uNQS5>:Jgk'huݜ0UREX>ĊtBh>|n-IyO.6e`l6zۢY-\xi'8LrO3Ku1.PW7$ò4 7 0Q@CvPlߩOOߝӶÆS2o{ ީEݓpKbjІv -C?߽E Ү"l,)<9ZdjХ|i @[܅75IOneU-x.nبV(skܪL/vMFXiqp`0kzDR㉹/$y&z6ȐOJM.F8@%)RAx+.'ɲmyN2O[uHBx[N͒OGsdz'-xR35KaI~4C4&wՠx9y tZyx[h֐﷿N,>BpkLnZyE@\['@q 5X}nRT8O_XhO#@PCC{atyۊdt8wDL,O>Uic`m!<&x=n΀^/._ĪoP.=>qթ{h>3q 0:JFN{Iyn!ypu}35gY3iHmM!ۖ!ᔄ)`k{5 r)#Z5hi(q@~3YMa ޴&ָ QM*&fh01= 'g *3c,q~+-P?wu}lND娫 \܏e-)zrE^Խkֆo՞d!} Z{#adqO ˸ACqy&6OF:,oB6/Fl0>'Ƴ8B!_?h={zw$97VI:?H/?Nx,j!>)gUlamYfPSvA&192q+j|$"H܌,&x5UNJtZn~}QDO9;G W&&HE j{nz(  ERxHWAKY>P7U 27|cT9@,W_1Qڬ)ǖG֖AwaWQ]38`ή0xdlQE9n/\cw7t @qL:xU*ИHCHwJ zi~9%Vu ϕgE&u*(cjyXuTz0!" V>Atee2\cUZ2\}X?g𢽘rơ,$7E~G5{2)mLNʈ V/T"pM[@R8FKW!EΔc0'o 颹qTRMljh0!bw=8D"cVEXOƀ-=X E2W'B9U=_22Wi2ĭ2?M)B@wejAHX,-yG:{G|;Y.֎U@1f<oh+$3%\-}w2(QzM fFٽ^VZGB+k#a>XI[6^O ̟<3[:x<1Q4SϹ U]!ksB~*@{Yx-ЋXTzK!_(ɇahF7=b-i g.etSIP7BަA*VZE1͌ }l *Tez5 HJ \_Z_fZJԢWBh%-eN;I& > G'DIO4y R"6=Yg08{ EO(}o%;\l. r'kD6֎=-R Rq;Xr 66I*n{ koWF꺄TvJEE}rFgfON&aB;Q22ܳ Bf&4YA"U_`$$~^xd nxrHB0,r1Qgf5UUń jv>Zϵg[\.>oxO4ZP}cGuc c[Y(;*Eeȸh?5k[2Gz6ݿՁ'6St UɆN!th vPY亥A/4*"g=B(oJFau3#L`/?Q!X۸`):g(SFnt1x[ 41cK(}@k[R^/RBLI˱0%wd %(%T?Ce64.|/r{Q;j0?fǧ$!V/ZQ3bfN\gSSdoRHa<}nsuxx] x8Sw/< ƣQaw5r#7Rؑ q' k V;d[* u+s 4,+ɒܴPVw3E ǝ%ɘ8Teg@u|Z?e*9Lf T)K+ gLY8#XL kWMU/jEa w].R Lէwǡ2M'!l0_##c i8)Yb3D+ I.(,eE҄A<h))/.G4o,"kk0U}7T:O1=;6m i0979YW; #|W7+rUyYZIJ`ݢzWSP;5wI=A} 7U/n/fCP6^;U9uP\!;Z^ԙmfH3RT; Λ%uXrMj9irCϾ='xGN㵿! J0NniK:}?H+=ɣgkz `z3Mo 1ۭ9ptR]*tn'1O??ݎEH"wsa2,9l~5 bvBlQ<=ìM .]Mzp'*W6GvG03P#Ȗ[rLq. M@py6|lULGB5$*{e &Px8(xA0QiZ=^bm:}PCMF͈٣p;j>AT5wDXH&~`n~EW K+aaOVO>]\N#=7 9X0gA.]h] dnq0|,axxj"tPAMF[jۓ+۞Ðnv5Snc`~|H t iKXjN 4L֨(ǶM27կF9[Mp uCR62OCSdJbLqcok@cJXb]$+$?(B؝rcZR#$he VB%vG:; $@R`&-%b]Y䨟g}HRw=fl6GdP NW_}z9AK;N03WR8-C" @b+0Yfa59كj_J.K=&(YVGO![٨4#5t :syħ~C6 ; 0G9~9 EOB*Zb =TK(q|/a7WDr;Id10X򺠧7QwBC6 g0M]eDa9N8˔v;Rx_rFkI&Pi09vk'"5!6}[i$D%@xii7a؆Q}svv} uėB3y|%bL=YvlcPݭi |_Q`F>|4)M27V4}j0F>dE5SE&@"$ҧ"Hѽ,_x v Z>f xk5碏UzT{kG!<[6"K/}B}Gc|6R]R.㇌ڸ;36t˰?t1\K}Tp2Wͱu4^ n.&@sW.Da8!A FLn֨ 5Syhe4\*_&q.L:Ckv-xm'~qԄy|+lȌ09RΘibfc`L@z+H><puM=A5j1W Wʷ&7ґ PfIRleh܈UkU]WMOhM$tr@[CC{,ȬITOʼn`Yc#@c[.%xD:ֹ3j~≂"ApڹO ;j{㬥tYH QTV·-]0qvZȻf6lӹFcY6X HUp7";(d<ox]=xjNʊ;i 9Yu 1r/CDanWoŧcʯM0{0od  K "kO˷k ¼F xQx&{aiC!+KUr. ' NIl@5Ͳ4Oz2.cA>8K&Po:>>}27~q_[ -jM(?;ӳju ޭ0D0v)m aň\cD|!R֐#軡8g o~Qӥw&&:v`! eE L\BF$ ɴNph% ݥSA[֓h5=$xv=.E~FctVf{r@ǝΦ4rPwsSSĬ, iDK7b&Z6aP0aۦ]|PW6#8Pki닀#HTc"}6I_WE[?z]IZyc34!.VWB: 9F7i{x9'A}Ӭ&]`0}mTF%vhfnݜti^v⯦Kx}(Ҹ@==w@Yv[84Ҷ =#"?NϛᮢXG6?@]6isM}j4CeTx)'(D\HeeMy}?[*8‘K8۸7aď тacw`D ~ ؗJaP{w8I9!'WɵD pt2/|[~.|gFxL% 0sfu*<߂P6)Ex6 5XC/hgT, 8O7|8KK-]L/Sw`MrE2{=,gy#\j5lf|妙ɹK]2'p XQQ`?~*%A~".C<$#n!!@bgQ7E*BőslRL C/c/s=hY {A9aY M eTq&Fv+WG?՛sx'%1Iyrx0D9a0,GSRR Ĺ3pLߩ^~Oɜ_tGI^KDP Q-ȵ;~b0Z\IFv4iZE 2GuqB zCamE–5qC gr("E,pHS>9mc!4glkkơE2.lB/Q鶐SNAςBFdYkR\ܭ;$Wb(ݚӐDӶK(T]ODQK?Xdhz}n<YZזrq w _Y E,غ bmCvx]alCW T-)G=$ɄNrDs!BDXhE:Џ ˢcҬ#4̝loDTbRCbl plŎEAJ ,;![^UB|؋o,C-\ecu"4i5ɒɺ 4ҵzYI_W~oվT,|a/ٹE} 臺Sߥ0'Wdٓ9 8t%P;5]jzaIsx[jk>e╛ X.V㩊\&[e[м2ǖsl⃽YlWQ{F$J<:8‘/S,!.h3}pO7n=buIef64 )QZ}U\@w"+Ghr=>1צ)i+lQjZ%"HIUUKt6q|ZGT >W`u"\[ky4c-֯mys/EaL>cH3{# Y@>@wˬEvEV!: -WThZQ4= ^՚)*j[FI1HX hmݦuY&uɠ>L\]%*bs!>@ќ䛈`ŸbكHI5NkrWɊf4}gv!#Y++#!1-֫MjI+v[殟dyϻh !"^#[N[94ӄ$ij 3n8PǶm:rT+4FO(# A4-7?m!<`fz"(g=0+XeG.MZeсF4nPTAQ0e9fca쒞@JK1$$;u6=StD˷eRx"ћg8m<ӯiK!S.={g$F_p͋g H%Ti%"O7 ُ%SazrH yAn*Jc'hkI7Ni%a2gu(4hhZkߗ1;Qv¸zפr8tKSͬ%h'i'¦XWG,?2 ӻ~kՒ!ؽ!Ar ~MRpLwظRKLV:G{(_r)udRI =  E>TQB sN (oe$[ 2 E# /#C qlbXz-/VJ?R  oP[8Nĕy.P]X?7lP#Š~ nZxڐ5sN MjN>2IWnz҉+z+7kEfLTӦPlDP ?hpI9CǺ8]n&mx,y'J0Wl . Kx't ]3̿GRұkww*r.qusن6x ˦B IV5*Jf?E_¤14/t&m:97T:?ptaUO_ tNŌ [0<C](KxK`str6mޕ=8RAo&̞H4Iq韘T~kA5vN/ ?CD"j8Z8Bc_VSgw/O`u7 =kh.6!"&[DAcKLv:V>L=}8 ת9c/0t1:;Կ3R1Al;%o̜:/*oEp>GE c i4~Lr5g9qie F-$m3%|?!!ȆX3ZohF TvǷx6ipnrF? I'tvГuI8dRord3JQV򪠉(q{T RNjP0na˱6ٳ]^9|nL"Z:>+^ر)1R)RN !-1a!EAP]= u|2ozy"BV*TT*>R_@7{K'Ba6^x"Sw)^"ƨ"1c!\%(qZD :6Kzy0& hŜn\:AROhn!jB=l!Ig @>O::KL/epOƍt4[o B(w%QW gB q|JHWʑҊr1D:M߅C,]WmWjj}ETq4R[ vђ.;65!\V5>7~{M'mRe`8 J<^է8/~Pe[ ~yt懕7lI\b^%*1C/Ċ+JJE]ه/UwA>?85Ns:JUP@Q7oruދ.lu t/er̖ԑdj6e>`]C-HmM-a{?6"%R% ܮylb] dMzqOZKosjP L_jD61'Ճr|+mZat31)U2 j!kcb3 Y\OiƄ8D~n2V+L)){a8'(["TJ6:+Vx="Wެ5u{s8\ ("1}ECԭFIb4oף:~)f[]3,=*֭jim~ԲPՑ;޹l:6D ҞqS]}WESʅj ӓhW|[/r3Z߅@*LS e`2]Zp 81빿BA-KӸf"XR8ߖizszk:!R[VuEMBg'(RD8 *$Ί!DmXV lT}D?A2*[j8vy>^an)QO !˷:<ݤYq2->u<֤ȕߥb5k Q%=Ijq<{V鈉 ;y.0"H-h ,a& LASjGSC㱙+@ziSTJ`-J7M2 sd2oG@Qx"ϱ3}X ~tNr9URJő3Zׯ(2܊D [,twX>T`@~jV N1Ti:۰jn`hp}7599_d^lZ6 |[PW"\w~iWnq=S2)9ATi| ~D$P3sC9vȺ$a[v*4k(B24eNq:dcxT(̧,*K1TDH2Tbn=>mVt:K~mIJCΧmm>%P[ʒ \ϰ+)cJAo qQMi'9n3bع$gahIJ;&$oz~irW# S]ZsL3h:ZdJ{2.F q3횈ǁIӉ7oTɲY\0#{K¥OtfUϬ|@ęʹ3}T3wu oJirDpe=ţ>~"G&<:3Į@޾J"ԊQ3#Ԧق.J]ax,HK7CrWZo<⧁bj2dЀA4 wv Jl&NYKlo$Z8+QNJ;' #0 [% fÒ};(_L\0(zP:ZdrOisu:~Vy`Ba3'VZ@-<=8uѢ=ۿy3B xQz̯.ڀCq69{velO#0%%2pvYI[#qY]rs;5I]gpU ۙ9R$;P֕Cs r =D?$v'$ dNz^qx},|I']Ȍf, JftD&HΡigyF-Ta[#lד̌PZ 11V`.fA(3r&D֞|>FI:-ó{r`!o45?FNŌmykO!gNs UNo_HOQNZ9QJ[k$R7mE o7jW " .a[ry b5ד`D /YTv",T-CF}<ҽZ{*JiC'ӆ$3r4t< c|8K5M+2&U]kǘ,8' zQo.#Oj1[R$s%# ;֖:D sa/ ϖ8%Bv3b75MzFyg RvBlrihg(GfiµĄmE4y%),UQyy(8Snb͝A ԪJn::洼qķiYSg˥:]J0ә'-EcYj tinǍCBwNA-(v"o.gB0*iOKvvHإ/q8q3@fzkh293h30N6t 5Ϩ^`dì~(IͰGhS7\aNVVXY2 B4X)~2Xe+fhJD[+j9$Lm4o75CǍ{(dޥ z蝭;O:eWcË(>ϊ5$DLAnͷ:Uo:UF&&jc+3A9KIyǶ\bqq=kJ^x⥽1W ήß1ϣW]mk?'xk7-y;bR_ jaݏb)փ<^YpKHr@ h2Ei^HL;]#`zLr` r5Jo/Mme_U"iџPZq&ȡGX1tP b7[mcfvz+j  \d +܅x3> AJ>u=%gD"A>& ,5N^)wM_G)Kփ$Ƙ=d$.wdeyR06AQ*r\/~E`f锗&PțROs7#)F6 0 E7$e +Z(δPsC7~HQ-eV]nvR>Μ&ƼAFu_~9:)ϡT҆t0I`Jtv+vo<Ҩmy2ZK9E}+rB@* wYC#1y`wf^c\"i+\3z4s癤Xj6 ӫ^To럁ef.}V WbSYfQa.<:QpV8owLt`v~"ʠ17/r61ޮ¦%#-rw&sOB*3{/'!w>Z7dMHZd$9zP{BFr_sƜiGI}ZwVDn6`i* ap Vb2c !o@ ce+ʴT &fK.9s )3.Z`K<~!xIUo d?,dRs9J[iU;DzPISYF/yU?;~q⨴UoP*Q8SxQ 3oD&XeJt;\*ed;IхyT02*deO Mq VY`IQaA &yIb=Aef>eA!rF7}E̅93ϲ* ĒDǀonWsMnw6C0n+50j.X'KP,kNn133zrûVC~*~>Qd,@S΁E ؑ':^& >_熰]}B2PH`MyTu,WYDm\e}K&i!w)g$5 ?;$2]W{/Iq.j1@]+}`vl7Zwi!~;L}ޑ<=#zJ<07_i@'v*֊{_kţAEcS50]B,whBSU+$b,ج ,|I2 ަN)* 6`DB ,.|P>ky9`) XS}VH=\ɋR7c{}ċ}IJȦT ýv5`fij=yANo)jDYC9WyVGhۼ~"1! UpmAM-dlSϯ If}Mm * n@IW&e(F('-ׇf=,MH=W_ߧcq7f-_yk~ 趝~sĻmpE i--Eҙ b`X=1ZGǦ6^ 9&* FM7G0/?YſR97gbJW!٦A X+TFH1'_@S=2^QX_ \PF;tŌUi49%OkN-2%ڔ ̚$1uf".XYDq,DI@.>|щ7f=2[QVAP c{w߈@y9O%Nc,Oyj \; )y?IrQâ ~.103W;ېC+k yhw1¼oZ0^ #[]$4wwLJxXm|@A[ ^(?W ڢU^gO')v% sK3{!51i6ۅ(H*P;Žq+B#3ɟR5CbrS mQZ%s*!S/"":}⦸z44L?8(*sANts]֛DT#@[D)$$0$mla鿣(%m4wc➫Xe 4ͪ;1\m@!#K몸j@TU0a &,ET(^Zru$ei~4X_ "|v@VFϮ kDMnc'N[c{5MU\/ީI՜à~zqV:NUfz``?w"=j.ݻGZ8myF-L2SrWjq Dk b4GEX0ȀCY% kC{.@n|`J^Ȃ (Gxy)RFqa?TU❨I@7M_gPSfvq\;J|ez&p ؍K펽+YbIWҹyY]YLc@b6i<_WB@i-w̶%2J5khrWvj͹2^MhL/7ӥJMAE\Rfi%! P׋> d5;qviԇd!OC5lC8MVuo;DLWF5{beoj9픙; ؏t}S4eڨ3@ 'z06K3k<J$\x\@Ǡ{kS8TB 7/CIc`Xl)_vIτu}p[>ؖn[Sx -Q`duI@Ǖ> k?x0Bۓ"#T[iМqݘ +:8$j|K tqv3MHm2k̤ƎPp FBF1LL7åAgB2}ɯT,. CrU ;ncb#?z껨rg":Ԓ%>Pzov7#H\=uJF@0ʶj`R][1o֕ { eL+v L Y p?'!-k>cA1nESc`E]oO6=6Rr}!SFM Bw=LZa֛$NS!sN")odrqVz+j1v,Gp0R{ EJ+~GZ;rn](3&w߿HGƛpjANwDE;['"{YɑY\=h߀yXT {W\6g[{P #h(e?{5+2̇ &9HrDڰn[ ȫdGY7(R_l*&P3]͍~2m>s HȨWhnVbakƹ-(+4 ,$b{MP(`X}W&3E 1b8&y}eDPc5OIsDnUIw Q?dۨ qȳe>ZY.EQęXn~fzs$ )PmI7A+-R(ZԂJ|N?&kHBse9撁~(m @B\m@^T0x>ʯ/}󕜷y#TD7B͞xM)bqݺE%T;e/A!_r^QbFSPa- ׭MYQ&=#xgʵL)V%?v=+ڡ)/\g81ڱhNr7o=կ;v鷰ɺ{gdϣC`4XU~bp^.1Z#u'Ȓ^l'wd03s(oY rP/ shE>fAnʺ6ïF5.Sk>6% F:=_^Ӻ.2ס~9&O`W=c:{sˇ288*L/QA ѿ~pC\MI[;U9qe(V{Dl @wj̼ ͻHF9,u@Z%ښ m*O07nL;:r V3x1S}8ޘRKO`(?'-cDgptz @5.W?%<^e"Fk=.^j5QVfZ S.lp1ccSOgUN)1`q?\U|wqaIID6?Hj =1+אQ_5jE^y~9arru$&|i^M\ P]3u)@ĩyzxtUp[Q&ZjN0.ĹUkKI2 ^zL6Ml,c(!9ĻO:qlݛ'=q{ad*ɧ/iRcЇC&2.?(=xg)mkhH{N*ikM(_a^W 3<︠:IG¯ )B Z~y?AUR= tﱆPVN-]-`(q lQ*G \NP[6Q#F6Z7ܼ`TFd<)f`%V>r|-0 ?_L?SƩaLʆs6YMcȣI=9pަ[wϥ'f ^b$b\/y2_X2|lV4ps;dV0gsG4no|-=,>tDJ|>G[Put .}Exnǰƨ[U|-Jm/)T]#`s`jâVܽxJ3pmKWz0Ia@Sm(LR#7>?C_;߄J0qYJP,9n2D j↮1Ogϭ@氁MA^o)-s3ߖl3Ŧ,msޔO 5#ǯ tGl+({7 6bY ӁdsNG-NBH0h*яjpKƷ%]k{FQPq U9UL?MzIr=O6B%QcTTɻ}K|;6; sȞADUk߿:8W2/Xt ެdPF[5N~ۘK>SnC1CWѪtLUf& ; J@H%FjCk(p>ǫ_v.#T 6ň+j䏦|y7vPYOOp >`R\_.1uCJ WAJtS#\̢\!J)g+u'Tך(g[ d81pҾckɫUsuDo2VS=T7pKYA(qK.MḤ«Z_gR#}&!"ȟERCt?;tgYjD;G7Hs"R,$7dnaor,oBo|}1Y흆) RQkP6_?;R n.Xhr mFo0X2 iNpt_:[&$,u:)FGA]Ll8l{Z">+ۖf$<<qGLJ@](gpq띴%il-)Wr=#dO?x )tTFPEO#qJ&k+IϞdzej]H丷 ISJ@bh ܽgp6q>:kr;( to5 O2YeIEfRꂅUTS,$ 9_fYubھ>Kl)WʕHY<(끰зR=!o3M]( y /B:b2j G%pPkz{\>pb$➖+13T}$|Pˌwq~[9Rr [7GD!F8FT?}|[~JY6‰ Pr6!Ucc^{zt]@EK2\Oju>c 헳`F,~yQoYdVP-sӹ Z 9Z ~Ӕ8K<zgq`Y.ܓTJ;+^3[?e yT3ƭbƌ2Q3R>XQ_{.$'Qc{CխzZrZ+S^:q!wzCa| Vk&Uj` 113h,fbF2c6MH65}$ARITTPedpʶ#WgG=zݣ;(H Pl!CV2d4vB/O5in\i[]d8q"kzސ=jbC'$ޙxƮFflrZo6mѾy'A]ƣ\闠WZR܄]_ u;+cMv R1'&N$4 ovмtr @ّ뮞Tu6&x29.%B|)8"fW~z"N\ As=iRŹ">4z1ٛ9)?m=Y6$dE=,{b /2e46GG'&󪠴n>=S,8.2*|,m@`*@7L<?]4t ΋,5Z9y?o\CYD Q_6 M}|6$wꤥЎF&S+L jY.,aЅ4s50Jv0r/xMS@nYCjr }9@CgW9APijs)(b{v9C`O@惙5ګgȿ {}F_tn7u f:{g @ZhjxUĮ THOk}L};/4k J¦Ofa xBm^螢a+Rgr(TCjӢdCiH C P n }_+z 6uF7< ޹U@d~9( )=!FrKyPB3u+p8^/8G㞭7:(F\vTZY֧cM/J ð/j#tHS]XZ$Bfř UsޝO9[ʦ|׫atc<]PogiY0 $8,u lJ x=z1u8%oq& *hOݒoKI@-(<c *.Zrݭj mfG= _D>H}?HA-ޅr6#m'V#rUVc'))d`PأˍWB ǯ2P0+rA".jQ+̶#Z 6աj$TavvP&UdjޚWq˩%Wp=Ui+\vCןh=pSѨ MQ<|(BD0QC#v .#X~퓮Qv#3] e~m;iyGB]/6ۑ\&mrIϣ|+eda{53$r]$U[Lu,.LݣuR ^zdKGAE񣳐9I:+ ۪aM(r{C,KW7fi gh8M4&\x5f-%z9FnUvn|0Pb$yVGQ pXB|1"#i .Skm=5]v.yZA( t+g7sajV&K`=P j:jۄrz,NPU{ \ح1FƑEIk n?xC/,ek?[/'ԙ@m.*8m$ 4׫T+1w|Br'ƫW¬ü @~هnstX$BTCuID{0ih/Qe^}Hͨi0$Hmyz5(CV uY~B!X¸T>_eBE Mf?}2i0#IT6lA[5k+5y/l|[Iz*4l xң@ZcE_ZGX4qAO  x^gkޘ6!#V_j.UĔFOpfq"gL{/䡡S"h6? YCR_T3YO&:{Pm9<8q=qU0k1#5<7u_To8`P%#. Ӛ$s}\CĬfѨ+=S ~%o^B8>~g0791b'$[4ti,)GKjzij{F#g7W5FB,a5fU`e *81A k%R$c$LϛC#=kiƍt]N -qœC .JE.'00EmNSf\"3N㨊\T l wa7դdeYLPx0e/-oz);Z0l<S :7&D+3,;+žZm6i6 s wq;v{9уވ ȳ Y#4%wѴeyZe@ ?hЗmjERb+'" QkG,2gnX}%ްln̞}MN|k볡80HQz诛J(顪s+g5wB7b&&=Q#ZEp4l/#843Ro.sҦn` ۍ'kK2#./G;<rrn45b1 []մ! St֢P(%_hra@4,D5 VyɫUwF hX"%BG AQJ$۱ Z1wNYe:2w9]\\ h p;7{$v V.i{\UssŔ%`Z=6;xm9 h`[;J>ew2nH@^ #R/ F^1nIםc+Γ8\M-X;>x] uWI iݺ q95|1>[4q75R|/=iHɋ#bn߃ E08e<FIHLn1/PLWGGMtӺ4l5 T$7^MNiy?794 (dj(,W^IHрP(Db#m &Kv\X4'%yajFz_d˪߁Uȩ*;aMyjtMv~=X!A t@}nxqZD#&$!Uy tji#Iˀnx. ie@_-Zŝb2L}ح3Y/i%uCu3МNV[ƞ$1YؒZ Eb yGCB_maThq6ҽBj%f/l҈HAmC2 eK\T啐jNY/K`ŵdn Mi'K~p @cB*]{󏎁os "hw+o^h𢟲$p5C}ٙ]% tI!+&Dv~3#ΈS(2:ٟԉB kiB?Cr>t '!Ub>G2u2Dm&QT宦 (4]*ŀ쬄*q#%BK v lyMh?8kb55Ga_,hiԊ'|%lX# 'Uk[}ǸdӇNǘl(x_?uy#w<&9MQ' A z89AA4* 9jB+1lWoF?2>dy{yկ^fvXX0hTe=XxFwC+/;*R0k[r?"!AՔ,BY74IKO\|@kilﺻ#"琱lB 7Gj7~SDDrX* :kI6.ժ_KS21mYd} vB`sS.\oYVw>ѓ=%Y@`VC 3^H w.RJ Oܘ$<)6)ols&7d_6 8.sXA2 KûC$®M4(_@^fvL~W(4,d%uq\R;5Ph}|œZ`.)i}rJĆᏭXdM%J!ihC f>'4E6%M8TG4^d\C>Mi<;St1A¼L ۛ۬ -Rae8?3t@O_A[AΡB FY-: '֎s8gMDlyC9]Z 5I;د}ޟՁk@dmcc:vѭ>atUFM ?â46067aeJx.+O ۗAS2$Kf60! MW'I&'ja&*YWVsK+꺒Jo9=u&sV0Yv@E~yn dž?' xw[8VsKgjxf3Vlk+$VT:2<ͽZ3 3ˤb@WXk:阮Ltir|?OːC04iFM~ d3}*)) lnj|zBikjbٔi-f=Kk!)[#[ъaJ) *E dP#uyŢqUǮ:5$ٸ[3N~TuBۘlpHՐMDQSm$0^ }1.iQDgF?TW\fh=Zр,EomD~s8~JzjqJF=0.$e$ IVGX.N~6Ë|gStI9 6b0OzCTwɭG&9tG4A\~t /wJAĝ~77N:/6gB: zn3u5wI͋.-Xm Pt묘j27f6{:N(G7yA~꒱ꅐ2W`PZnHZ0v-`ƆBWc Uh%۰A(:ó?kpOc(7E( mEpz0:|2>ep\Tap{/xb\|C^F7 }~5 yiY(g*p]!?ru vf*%~j0aIIP%{ܽV5k6'9Ѽ9}e[Lay.tlFjM|3f+yi/jNFtRW]X 6n֣@2I-+,&,M>?RMz3m'-ڣ Scqx+wfcGe_w~(h4<=oa?SPjVh7$<$H4SW%BKOqw6p2.#3#wL$Fa_r9_4:Ujq '>q r'FPqucsg?˓Kv2"Sj( uz~ׂ>Kmas0KHi;9Ċ}RfU"\-Irſ"e#m.*Dޅ/~nBjhq_;N55 Kh1>1C=1|0zq9}"d\;N*W0g0Y* ° >0V(ח.m՟7IUVqH~= Py1UC˦Q'&ё-x >vEv'>Sy%E,znDiE;1$8sfeO2]#WD #8G2@.3X* #Jqt]Ʀp!:fr A)pH*Dd%ekoQ,d@FPN*Bn3L_VijsmJ/+ 2s?M#'K#Lc^ SV2Pj6hU+Isf zw5ϥ?EMl~'_z\݉$j۵hE|O|FUs*dC0uyjfzQJ9~ .G_`y6[f7YݑaQix&}MU ōFES+T|]RwO#ePOaW(2˵1' 8}wDOsיu+)=yҹGssp^5Lْ8j;-`" 0,jNSp`tx}Pnvsx2 4|:DJS+GX#JD-X:7.[-:X:3˿h8 tc5&;~a).FQibs0-$x)7P/90p-)LCkzݫX"M }5P l3ȫBIKf5Gu ^~Hν#>\(\ԎĬ"*?߳g#l"ˁY TG0K:99;mӓnFl]HZDV8 ;G7O -Qp}dX9|-_ 7/{5H`TgkNwޫo2cE„KJiIo05ݷi Uy׶k$=+W##j6f1AO|*> o [&&Q|=@U1`~L9DvWǤՂlxh 9y2 \/Ph>dl ƜWU 3vpːtIJi @.~j]H)ی^ĂOd ^44"%]O"DhfJqs?o8?l8+^,F,jNbYӂ>j"sêF{ߦ䂝' O/Jkot\?ny5M>0d0Jۿw,UOq10D2$ڞoAr֝n)\qqgibhJ;=j&f?˖C<s ̏ 7km5}u6V!S̳8Sp5.=+ $S i`U9\lS5cVp%h)F LaØ uִ`j9>D'ck3wCN_:L}04$ǷY7gK,_tNH1TBP*|zY'\^% jCa$_M1TO/FV.+eƮcX h~0V9ie,Z|8'ڟ|Q֔F(B.W\/ pnj-ך$l";lH-5GdtʺTTYldjVQQ/n=6y3m8d Dv7%3dP),r %bFGDX$A!ϏQ WU^S>I1Q:Is! ?05$Ӫm8va_c/탯*V~ 6MXK8+BBǻ?wj*|ƅ; DFsӺQ^IJ,Mɖq̎rEcX]H))Y+ D)1 ^\X #c{!scư̠OdJEϴ۫6Z1,^ = h)Ke^E/3/%\4+ȶOܯD4e2zG}hxkg0̿5v7$J~<4x*")Kϗ{E||gmEpl'%ͱKzK pKlk)EDݬ2bK\p_޾#%$,d^ՠpȋbeB@lutuuBؽFE#[)o,0AcΠ(N+5LBq[WKOL@ d,CQnf _a@' WrId2sוPG-.# a`yJd3 Zo'-ZJPH {|"UO@.X!6ӅhdD gSW&*Zq=7ێӰ GYɋku1)wX+:5 s]k}+Yx!մTrxA^gI )俳ºD wAŦ[`4; MjEvA1~珛,|5IZRd89l/!K L[!9)Ja=i6 *Ytjnkp 2~ߍi@2"blU;==R+JHeD)| qx9_Чnq¹\j~/DnTƿ¶s1] UQZl-RR Pν{}zUHn \wD@bhNͥh7U¼:{~#~Ua a{ņQ}' ϓْ6KݙOM4 iKpFnu^cvlN9;{ި,VՂ5bm:۴]J!rM Si}sxG;Z(ӅZalQ\ ݸj@>/|E@Ч|[[}t~ur 蟙L~L;ygvbW9đ.n֒rģ,yp;-똊NfzNm p '8h[mE}c_mj$T/%$G9_1ŬomЯ. F= .#^u\w{#5J@A`F6bE dC#V^Ug6y}\8Xn|cSF ),WjkoT|7tEב PgzЄѤ1",oHsV ^jM牣L /U%NSn2B}R~s&zWM~uZ:|9o(ywLcEȜw=6f-!p@)*?\8a0 07ς/Xد*;v?kpdMp/>FHqEo/NW yA"0*[/FWh]mS8&]{at4PAɥ}mŪ=%A“/(Tvw}{Lk(ʣn }*(S,OHcF(ߘ%5^T'՞yfaq]E>+:i#о/)GɱfQnY{b{IʑAztE9)/3\:!06qg3%K]Ђ:9f2'Q7Ol|db||\TojQO,ߎ("W o(?و1,Ayy4r+x(~kRJOmmuYIv*+K >rӊLnZhϖ K뢾ȅr {AE<7\m|KⱣ/܊w@DW))mESUXq 4֭t׼oC !gЯVz(ѴRtnNmz_#NN#sCW-F=)dy?S kRU3NlDI6( ȾkU%wO m E! Vt !Z#}T 1A,GDU{BV A,0 2>x߸@|~_:0#F=:*~ؤ9{~{_J=&d@(yZzLRMwBɭƈex=u4: 0vs|~T:ʽ"  llRD-:v1b mԃ|8kbQ| bC>p5xPGIb6UicMY&^Ym)01P㫷0"6 @*pTAKsИhSxjdŸl`}(|"D@âGTY |"W_h95rF5y(7b|;D16;sbH5@A1]`NY+X Wv r\,(l3cV$QB&( ' Vonn:Xz xvY:]d҅ZLz|Nj ܪ 1FE%3%֏<( GHC1؊59j<&@?ה]ՙ͉oި sHBλ!;Wigji?s1(*]%,EUԂ'L V.Y'Ҕ x t='_0DE0a&ywaE0;4SuvI:.CqӠT=N; ia,sQZC._\6c]`D.B>ֽK8@_('=i[z"ȋdpq҆[P#=(lе/ f>yYZixyn,pSGg .NW':ߡ{85sS9ePNf5zgVӲCSFV)hP4֤P^H)͠jss~ϼupncz~!pq3`bvБb(<ьmt,xm'euFURHa[rQSME:w9p!s%~@C!鮧B1[*PT~lfC:q"CU(e?9jQ ~<di7,G|_%Ez"R^j6ƚn@[Ƣ[.aSެ0~K`7BF}_6|Ib$g~(eJմ!FGP_B/q u $MYgȃHڡWJ;c"w`7?E ~4lW ]t*y}s<%6{(]>B݋Em,~Z,m7)ZT%(T.*GKumXFT{'j5ǨQʞ%,R8v8 .dSkh~oO]VRMhXR9OPkҌp!{g{Y48QEs]AAzCe#0]ˡ*y5 l6+õSP^z'P/ޝPT)Q?"*黶,bok53SG=)S%>s¤'[etYΞ_'(9KZߨ"}=='O egHs 0lִx-6Df UZ*f"G"fǚ&^Z4_Bcˀ kN%z2Y*9,+myv.D r J$Rr4|k0|_;NXgX/%<\Dc,6`m3ے@2ry!Jq?[Y.27P.%4zHsDɅ՞t؈%xw00wŬDmq5uCœuE̿ yq.+}>Yy&xhe |s֝@Oٜu&/dUJ{qW'M7%2gaZ6̤3WҫTA#&?q6mYch*heB>BWg4#vfn/e=Nr )>lwSawylj8˃VV{!X$/2}2D,4DQl%"Rx4EvN|IXs;b![0PTrqzn[fb)W,,b*Nu&Cyd;$UEv0X=BAy9Yiɼ:0Y%2W?g ~"p_!#6ˑ& ﮣr LQ擝.~ҿ$?"`˯8Ta.tКxV1fy߸X|_š'~T ȐhPqK\W?TZ>#OpD΁UȐC)iʪ/.L*uT m-Жw>:f1F:ZZ̃A}5н<Y rҞ#L{'M]L$5ݺr̙蜤+؄jD^GpȬ0ٱO=zw@ iXD߽Eu7ŗM\ *ֹh  37u $RVG!ɀaw-1I@A W!h&{r*LjH|$ jQiAaJT Рd)? 1? @ VAp0ȻpJO'0~?,vA2=P9@+Җy[E<`~h1)ĵYQ,1 ђc>nJ#y`vk^Aq#wmr<9=bu/tؾ$ ~ݹ>+ W-Tw2xm2Ih?Z0]Gjlw= "Kʑm!^0Bi!f_e(_.X"[vKmM)`аZ3 ۱y@2\'e'VzV3GY%Z8tݕuN L^MNѠv>*c) NE=<-ASڏ Dbd|.?F6yṠy)J֏n 1Ֆy$JKܕDT Rd6Z/R]q%idTm]m?UX{ {J ~«͛w 9+M>?x׶ W7Iz{C_G j*"Ёiu -z-a&-f |>:}+VI.|IS95@MK_—9H Lf\t,?mXjܽt.y- Sj.[#JS! @t/َv;l8XDS ^Z $8 D p,Ի")LܐbɇDΦ۽1<յFA`~mOvcTvö"^ѧEdh^(hc-W[8aNۙdDW@v'Rrnț\IQpqY Dn*(AO\)ΘmQ׳c%Q- T$*%7YSH`Qd1 2*Jӛ|}[=q WO ?Gr㑩;C!2QKq<qEtPTY9~.(b?{ K'\#{_wjg/ ȿrLc5 Uݭ+D&W!gU*r 1(FEp 󺟩AB81?Āyj$3KR3;j.'O|9ki5HkAj\"٠*G +s=>{ʙe|A>_yr=BM`g(h(bYfT;$<f8z @#hT꣗r~QڂHK,TWW,jkm9]',GQgXxn#d6xd:7C:?pTw2 b nVCWuD)>)_Qd-rQCw.uŏ?p<_yر(T3Qaw#TBYuUDrH}%ͰVB )Hݽ/^ :{Vr[L!X~VfƱ>)JYT13iك [0sp ^lo,jGkiQYc5{Q$uH :6:s')58 FqWNG@8m$6,ҨҦkuw9 vX-$S #K|mc'ګی?lA%/E+T"r%BqGP6bN.l4łr ^1(T"r ā5$u@眲AD2; kGKpPfGn<6µ#H%Բzk"{!^{a~d_X ӤDL: 'Z-Ӥ>z:uZZoJ FK}/FK(•+dL&uWe?s kH9d;98O}I-Y4h#6 F- !,QȞ"^T%vX1'Yڠ#gCd_aS/ @fkU/|!)S|^ݪDVIX0Mqݷ]rN Yneu'U>+t{)%mWwVtLX퐖.x -@06uԳS5 qṙC0O5X%r  PwwY ykNi+ =.{wȮA|[k ^ F2&4xHt"ra(!5jhn0ide,Vml! TRK; uST"2Ცr;$q`w6D5 nǣv T p6!~ ?}D_gx&zܑv:7v1[\4^>/G{iYWWO`< =KOmC70cuخspxɁqOܞOS<}5 u8A6my/D! (,)9w\TS[3dtaU!EY3;0iܖ)7-#+Yl7iQݤ1Ң؏vU*8""%\tbp]> )<%mRN\I'ҠZҙTݪdM$}T"laW+R,I4˸fZL`\ 0d w V`㴂&eAŨ9y}`<Դ\>U}eTYvl?8%hDU0sG`'ߡ9Tjd2 [RƑ- Zaؕ%pO}Q i,W6^17 IMy0=FR*ef˅;Uw@Լ̼vEʣ w j[vB_-[;"8Sfx1Y\e,;Y`.~|Jdʌ똣mɔU!zU>NJL* P[1 6+Z4e4rùirM4_࿒bHWcDxƭ/N3Oy'ߙl$$$eKv[-h17+vp)PGg\@H,Dm.knL̕E`!X rz݌VEtWiRzl!VBeJf+q`on~FE%hʽ&ʼnd ۨą>W =h_{xm)IᛅS&W S+|;$ŮO3hn!S>U.W*Lmdl eļ?-q Z4W,ov:혫;B1t!DwxkJaZ~xߋĹMN h 5X#xj>X,B3 "Y+R#88Ć]8KLZYgpLYCl'<ӥK%Bo]֯]5QZ(l̾Mdܖvٜ2ZxS4E6#2 Ly&=]@]J#켮#ECvO ;ahn;xy ܖ-vFnA-B)|-Cq^~uݕR)5.7iI_}:jaւi_ z,0Ր*3d>S} 撺ߩPmV-m6C%Hyc,\yP %\16s_Hծb 0!m$qǩ־/o1(*sCY89)$q/ȉ/:XY\%JTZ?N? WPg:ԇ#M^2Aer>펔4 HYۙOpbt"v&l22H[XeE Sx?m}ON|[2 c3%15"ehBd5G؇%ّs;65'tz3n'үqUBlKqFO&9QmߖMZĵ0T꒞ )L f~eTS[;>hNhV ~1w2WxpE %wiӚ93&2).PgHh+qsŪ4Hk\UaZ}c _zIH%oP{,.h&S92|c-3( 8KA(L#9 04ƭ*P ?S:<^JQ-3bFN$_y<hN5/sSmDvx@HSE4IA~-r#"HZD%Xw "Cʟdq_|ft74N|ȫޟfǖnD{b欍~bKNzK!K7*i)+PG|?;}0?F(|1) g) 5:&9S 6КÂ&ZD\,|ej3S^QQ<I|>*l,Y/ۮĤ`x6WpQ _@rs TBeϩ"L54%Trm|&Gp$z! .Mue䓆mMXvanoy+$=jΜʥwe4DH &񦕬0b'z5:, VsP = %SE,pՋ}×LS%/A }|t>94N[j'HeqgMg`aX4lBMXҡԳM|E}%XCa 6K cZ:X|A} |J 80k{%Gy0#nK7.l}]k:y DmG>>5n?n MX +]Xy;X`?R?gx>W?IBBJ:]hVK! (cӬ /iGΓҹ[bjkYK#k4%wJVmI>Ǻiv%Py3kz u1kыߑ25RZ?Мg@!N5IFΣƺjGӦ)GITXb2)]g8vL֫"BYrBa㪜]DLw䑉)3v5d"ȁ2cƕ>[Zr`At(n 6PѤnHz ,?]|"M' j"OouV!ҋz*=| ;2;}Z՝#6dž ^!6 بk.;B( yڂԚRwRP %1n2H;SBևQ\ِEA]V\EZ Fs-`Yi7s돼Q +K|`p՘xRS"zx+gu܉D ͬmvg17m9ړjxhbݢݾWQ ܙ*q=c!lKCA NF:z3R%>ABMV2bb-: So'kisT* #OXaJRag}%~Oڛ9-~ 80"hpG,n7.:,7*^`S%㹉+RJ)iD@' Cj޹{Xzl$&(eZctܤ@U)<%[=hFV1CgB P*\;׎ZZi@\0T7',D\Ϧ~azݙGZB56+'AGN:?}ӑ*W)$gǫ$ [^A2V P;N< bplqr96~Rf/:W=D+G81Lw`F_)$>aMPE)#`l ߸W맺\W_+9Kc"?}їQ Ӑ]jOQ KeAU41య* $YDt]\z;eKc+VG-$%ޘ/ 8b Gǩ}!ӂ$n8-ơū0`Ӵ]ɜFuກ5R Դ5$$lbx`|i!lwɆW~7\ҟޠax7DhSW-mlwp4U1jѩxD?=Q^UqZ,1z '2\lN.,!Aҭ)i2p<Ef m2&&+eR3 ?^'w|%?4'~bӶ;d`U~'Lyk v?KE_SwOh_!~}fsbºuZ ‡y/YGS#O%:l+`H~P^8G.~xZ"ա6L}7DXhE^NKzzs7 ?FN\g0y-ޯ͓PYw{:HcYNiKE8oTm?^ʝ7Z *Yݺ:U ({>:Rab=|~|Q}YxЦZG}wBK]s{im5/zBD6J+DL?o9gƏ9+Y}2D<À4[Ȧ ad=:t l٦I +S $hQj찡UB~EdY7Й́cˌj{b-VSh|Q~ KW)߁3*:33b-F{Z;Xs|h2> Nk.).ݖ#.ߚٽewsްWy\8 8YтkZM`Q\9G Y^|X6"wY-"0wa3dF3dϖ/cTWDj.v ^Y:۸"Yt@ϫaP->CcvbG;%XR 3` ;W-ei_E6>(ugsq6 |!QޱSeG,BqD>f.A% gLmfʚ9ba s!wSƆ0,t,R ޗMO!(VA({bOPi@?aVt[6'y{U<#|L"m^]0:T4 9B 4b_t^7 rrc"˅jsu.['B a] $'(i!񱸣wQKs-`;xK-UC%@1P볦%׸XSka@&Rk]Bu !\LlxP[yaL;kkWKכlNO*vLz!W+#{cl=VT;N0K;YU: r1'3JP3ik `9"AيDȮ'IY(GmxlgX`,_5WhL<;]$Gϝ5/©rI6~䛞u2ҥOjQ1'$v1wvΣjۄ d,e/!UVUyX_r%pDn#=Z'΅m^yR9SGqS. 5 W77G$,hmN0?FgVTQ|>ղt<$HnhڃrSQnFzs"iFNю EEEz/%|CTea;`?ePN  DER^&;X<ޮ?K얒WC%2b+jS!['Ȳ?u@[TeCx.QEsq)+dHl gT(嗛 krT=) ["F rڞKcR oHSHc;*8~ (:|+W)S[&RɛhK'H" 1o|4$_=I,Oڻv~׊XZqzqKd?.蘉7߽tY!4Rg]MÊRlfA:;cr5w~fXaF/ɏLzZvrJDAUL~`:9bg O`ϒM#)Vo&yws+T ~l<^Ԭ(fcKKDW2/}FIuQ|t2M( g}̦Ƒ'vgmb;eɰI'n;~at(Atn4s@Ǘ1UX i B(Q:-S{yh#1y^)S1vD*wɶumlE;ޮQAZϽ j'j@ֿ+}&cUkVRt.drn+V뜔_pau5(=LٽRoCF r9i2ѭ?2n[k/M Dz4G$p(HF2QhYބ@8Vk))p =ERY#z3_r[gㆦuJ۩~`:j(7O)YwOrR-cFd0Sd;;T3 : Ѱ=T}ZlqOrf_Ѭ48DS QEh'QPjJрG[̀-U:a1Ur:NWm|#%+JX$z3\ I [מK)~0n/8XYwu8BL,:\@aս&K!FD"odF2A+}J= bC?[F89ℕ駜?Q%PW'g"n.%a# VǸ# M7PPTF#O=QCYfԊø B_ϣlǿ3[%6V7S:u݀&R_IoMމS &CF_oR,O1\/>lKlBYAN/$yY1:CD7T)%³s#+{k\e1aF3,?&0"͹dY!NHQYQ:&sU[RC׌Hp7C?ts.wF5`:Ȁopd n^ê&cm_iUg;`T9C$To Klp ҏ9gtC厌1C":Hч쒂-"!Q5p|3q/aw{Dv᏾Yz2Rn$ fD]GS<wiQz9wMFFk ©ZOt1c =M :Enk =\]g<Iʒ*`Ũ~Zχk&Õw054=mrD~'aJY 7k=@plNcerEA4Na ĦIfh*y6 (oYO=YHMvMӳ.$ɇػYK]RcPlJe=AZkv Q꧞x| mPxq&JWaKtۇUU]is*jg܈'$0#anXeĸWEqa46I}HHG-4$??I`hx$ [֐J{m˱rta5}1A[A} r~Re&咔,~` !z qqdF]8F{dqJւ+Fp4`ã^VI>vZJ|FRDmM?8ٗ+yHSw4RAn&`G_֏Px`KS$IQcSiId1 ;t[/ y"IwIQ"Y!kbfDo{c1Zb~Ȧq"RO./XN+X -[tJ@݄HG -#f+Z~t:`ct??VJKXZòfUt:#3!yaBjT\ARj<³[ 9X2Ƈ+.Z+Fsor֒" |;j8_b&ِw3T'l S4%Xqׄ#M .lw< 90! 9+}'z̷>M. )rsc&ÄCSU$2zt l̛nnf;ԾmI#RfE(r6$cE(Z).4{V< oZkw=1Peb,|xJQ|sKvw22{砩l~sYIlE@c9F4Yz5mi ~Џܼ +sքB0cdžߡ]: jDBb-*6v[cI8@qRU4vn>szfp:80#:F,W K\W@VC;;e&-ܳNˢ <ҏ2 ?TI殸cg eCtY?9 _b1%viXQ !8NQa@MoվڏZ;'EDKLn yY(*|u]5{$ιPCہ2"Y=% NL>*.tjGsǞyuYFLm$Gše^|м+Z.˘>ci7tD2 .' te+Y2M-D~g+WFY u< VC*הŜl>H+BWN lM tJJ߻{+$9H٩(R e^1u=sa/zdD5{C^'np1JJ`d2*]ڡˇy;'BWcUW3&wd`|4&&7Ӯu!{xM% {x0 cshͫd؞# ÄD)/7uwUҮ($A|&Lަ&1Пqj$JNOh:eTHIGk!wKIvyD+eCoC=)|ddP鮼n/EG=ͷ`*4+q c^%zS %_Ʈ%5TJ0(gn60Z (mx}nUkiV^byj|'l9[ YQ`<[~Pk @e4(ޓE;`49Yc ]4t)>[Dl%]Ikznil~mpQiȐMNLh{8f"UH#6AO/&d48Tqa(pB3\%ٛƓYo$A)=7Y}U{f)g8NMx2 67 s`U› +Ɍ1w[a/|̵FLz]A~Cl&Dc'$p$Aˎw H L+s3gĨlI!|DIr O}N,qoʈv|f ҳ {ZN`+Y (WH򀔟5M]EbJzdI}>y˓8Ս^e58D50VG'@0o[x ?PrJXƒ]TfU| va9W^s3?%PB@BF7U)u=icCb*4Xvczi5}u&n:=lͿ]9;^׀k!}_aݗ6 qvq%rg\2I?ζZ؁0 U9EXI+¹vdڔ3ag\~=Q0`h}|"7Dk?HhFMi6@Gw/Z"yqp"4&丕Б-I ^h{52gjkæT.?jejvF mc[ltdxQX剳#=y tV+`!k,bPem+OL*ЖXq㸫Z`-yZzU)ע0fJJLg hq,+.N[@OR9Pݺ 8[pZ{@H= n"|f"˃v L=X1KhŁT!vNnG B`_KO[?zEφ pW}u %*ieL+:1)19sj0 _ VKN$a)ʓD .P&ZTvC/jYPmڹl(n?UÏ(T :ޕs DN-izͨ7E,MF;[+%X8Q:?w|[!i[ B`q,7]v5ˏ$mu$QOh> jW' "|iS(̇.io&]nO\ >:1 j:|rq; )t,MGB;TJX˖h)"p@.|]˲`4ƛ {0NOjTeZ?!JqhDe.)%{YCH?-"8z@^&;Tؠ u@d6M,/o{fg+R t .#oDRYM[.3-/ix[h2o' A5mdȾ|?KxNzfQ4h1`Xqm| xE1e|_TT.r48's?20Vm^5unjK_>{Sֱ}hXvK˫ؖ W7K_eb?%{(V/L.]:7*{֕#DЦ]tFwR֭àozҩ;+!3 +zv$ q;A=7ZLP61 VٛHح >I+ ? _Bh. ?dxbj#>?oKWrI\>hqBJF"(4NTwT;7U'pMn;˄rn}o<({DM-#%r_7^Ru y9lIGfwCȨ+KN}Ԅ/,!guL1^'*D2Cb֡UOE/Axϙks:|;NYbwE9 !~}ӰԷ{L8mW}`e3 FUM y n.YٌN`M8wB EE25m[h͈=BӀ$!`H64VhY[x8f!Ddtg i ݁&f`CMJ,P ^ yRfMPjШqy =09ĵHV$VHδLqu Ћ&*qѰ*!:DƫR90d~#Tq÷P%8?pHk;c=ٝ)WU:DqY;ΩY8}ш<2݉ݩ[ GmBzAjzd!=UU~PS >,<1SnQ<2%H`_vV-WA)D@+1~PMӖ͟:amb_b7n2WqnBa`UJl%y)1}Bb` I#Jv|F%'C $|sb++<Z_= '_CN:|Y( h'f蚢&:w8ICD G[eBhT?x(aja!;/PpZhTUngcȿ,W ͐{T$,Vmq2I#)G{3uv+6ǟDEJ`V1F:1WL(|rV)+Ր z #V p aU ,}V*O@JfVN_w.P'WYr/^lUzVf\Sx x >a݊ B[$*dR e9)!d,*js5fP-JY}e&BP S"Ql縉-BB-c t*w-t8"? oKٝU,rO@}/ۍvѿ`,P`#&P$+KJS6R2wuvDlyl4>(n? 灿hV.-Jihny4>hqr#+/g% P-}_P)4B}*i;.> pxSg:(]Qu#qy;G,ZTf$ ? B>&I|VoMW:VjKC#ǖ0r&b` U'GJIMӼtXjގS1AWwB=Ọ(Uw(3*;&y5ω._%, ID#^H{';.)E<*}A~'2#;D`x0$4bpi{Cx^74sּAޓ %b8mly'΍O ߬6 0$Ł kTD7 h8(Y C#rVZJ)bkbNC7忺5_+d WoO\J2kg,C4g{!9& =!΋ʜ)h g#ĸ= 똋o8QTOC"ϋ%´UD.X"Op5(v$#>WiGS7:)ΒuBP=#$e2Kc+0-:]Q`q((]Y7h4YOH2˰<_3T4w .ui"^V;.}'5@]}~T%`7apj bPFQd]~R6ZfUB҇Fh++6 ,)QH6PR H* wyB,Kf#\n_V B0*~~(o;H;58s E\& ~{~RK'b~{3[ASW}ejW* 3]k3gNh=_;^5%̴nyh'#yf\"|m)#qsيڐJ.fGŞpDpϑji߳F ~4$E囓PF(մ?O B'<ٰ qY-@-OiB@HMte3|b06c5R{&69扔{ eVkeJ8ظz l ؗ02B[}sBsW݌eO<AgzG\镋#PDGcD{-y]d!iD^X*\PYA7@Dh(k3.O0 R:le3TZ!·sgT Eui$:'?;TB8U \#$㷓k3:Դ̌ n2l+%4u E0s?Fy̢J .S]s*¶WuZDN-ܟs4N@+iS9 \|MUY@в.X2يxð֘X:uӻ}(Y[ pK|ݽ?H;ѺuNO9f&L)0 =q&Q`a镕#; zvdxױj׾jW5Ce65huAF cjRD%UhCQ[+0r'N\^'B~ʤÛwz$v 336w׽Cދ/Ly{fؐ@ H(Y;A: ā P1因~XW|qK:Ŕ@s>5C-g i4Q oQZsd S<*&1Xqߐ(zq,7WCl?N^M1ɴoT=ւ?mI/L]ND WҞ?gDчvWnўtaXȱM$ edŋZLҺ#b"yQh> MFڲ OOFa5ˤ(sJdG s(qYHD32CBؒk,kMi)XyQ;Jz [?k-CWRF7 ԇXB8NoipmSlC"[&'-3>\䩹1No7udg(F.b 4,|uD7ǒ6()0M3*GoFF;|` mN#d|jrSJ>I0-٠2rʺ^2xǟ"|s0RQ=ס] Fz0-묲{_lfR,?8tjõ GrDu"g)\slY'h ua=44ɏ74f`xbM*B^.N+ec_V x`Q>gyWV0G﷙dDLrK++Jwٵc;[#[o3Y+-yض]4Y^` +1HTVRj |.׿`7k.S0;( |>8|z8Pe'Q]H.HcܝmvC1k៖m9XkqeyA(<#FV:cq-&W] zOJ7yqzW@8#bҗhaq ǧ9إ͌JCbi#YIH[TK 7\BDWIN BWxy VOz^NOKТmW Bǵh"mMZf5;jv'chmSJ`Vhzi16C_`.Ԕ^Ӥwcj|Z #!,>ϯqqxi0(hCF>I&y;kZVq!Z}p ,*}DRITBh@ITNDstj`+|tL NϦ Ys$eӥg=n[YnTzAΒΝt,)il04pqfq꒓5 ̱GJnn['5o3w=u *(dX21\?.t* bO:۔y@w;v.5FFPQXY- -(@zЁ݊ν {V0:2\NJ'ϔVYp5/kEY(cmkh퀞}."Ƅ7L-+Dz6* ̉|-l&geQXU-!<.N)N6O V{NM &6f@>Ѩ7E.K@!:|r=`E6KԐV66Th"<K7Ui6)~_L\Vj.r/!dME5(ӭw[mI߹P37t-?T'ѣ!.^IT'Js7B"A)8fYFJӺsYl}5!2(RJ ^#!Y Jy/YN? &gEJ5o0 eES.[34KFqrhk7#痉P8'?)֔NaIx'-Ishwiw-X+.ШŮN[>951Nl^tHsR{fNxg]Պm"ʼnٙ5. EQxQlF8pIEWf 踬xB~)U_WF*f77w:-}-%.Oq,T4xy d+ײbp2}CbuQ"nZ4n|l9qZ'*W?jʉ-LRȃkר.gD΢5.*v=%/͛(D.dVp<"L>z$ .f)_$K'LAŮ|]6ٓN?Srk7ʷ&M(l&,(L+j7BYݘft42R$߳A o8ƀPDBb^K>x:{V_k`Sա/(RǷ]lɈPJ<6c'?p7:*0&JUC:5}uM+;5)O<12R9&#EB79M|_dMaK5j5kc5D=e`]Mmg~'Οhpa{Qx(JYKLҺ2{r^|y()c3DbQ9|f2j~͘)g !D7,F !pGJYr`xR"(izM!=7ܿ؂QmR Kg{ 7gNR06pYq `5? V>r=CD,(a(&>:3X P5kM \,h% ~ 2N(ҋh&~X/^Q""]+%0 +c?'Rt1=w/Fq-EE<"v"J'袈rN ř,RJm e1 2-rދZ܀uPZS\݃᭯řDLp ͋qwX7+s(<ZO]ԯs=-,U~̂I8Qp0>UE=t/P-웼vڼV[٘Cl3s̥rI&WXh طC(xϩGgւL̐Z5%yMS O3 s+Is8$?+$Q=XX?'[.%> k =sFB>28ycYkFKhPĴl983QStGkV#|@`)ջbu3S%krni<Фe|TO1r jG%ʬX7(0t PbE˓0T3&UkeDkڧ89In1y KgT Ÿm\P ek&CZZُl#f _tj5B˦HWx=4c#x/; mvcuK:橻4oGd ?ґuH|ح(0fB/B8sr;$bZ9)Ҫ4u$Ch'3ȼȟ{m49oyk,۶EW54k!'[oiSY6* ȿ.07_(X̏cN򉏋 g ?ad{i9֩hjH=#eܣ\\4= qx Qgz7Nm j\ 0vլ8QuF ]t!pr͢J;z6>]tkPi\dS:&HփcD EtBb&{!3 j_Fˏ\#o'FSZUd>0AvxwSw qv*`Ӟi$'ї6kL1EK+vu_?EwoaћGt%[%٢䄧 9pA'Av[OM[ku#L=9[ 5Ok1~A(0@/ k'UkAwBy?~ؿfycMc5$pѯCN/Z]S\m!)CFvSK8UnQ@]LvtZLP6euit| #9|/ߎG8pdZVubŧ~5OwF oic儒JsIƼ8DofEM_B X2OpN=w~o%vʰ2~@"V%f?>i{JKaqt@س1? :Q-jtAE)..?5mZ{+S3i@b吐wIFz5`x%p>h7_%c9[F@lݖW~5*HOHRO!%Cچ*O܏Rlm;^SE6x *%]m4.{Zzţ BݖF #-]IN0^ U-38tV2G%zkZNp¦W~݄+q-0߶lrKi]?r5x)YjVL9.q0-*hO v nNAQ%{OY_JC^UI V|yҀ@$B!&bnėbQwQOdIEBXhʘd SPC,n$@E9((JJL8rdjmUD 9*d'xP? $o Lܶ'`PfuѤ@#/H`X>t_3ţhd' ?,.$ES:0:NFAǎ a48Wd2+Hұv:Ty%v~{;@Ȭ}Q#{ qRHs+xs0LJܥ3:S9HuoU''I~u"0|6n*Og?-Ġ O  7W8FAz [ΏL@}4,XLO[LZW3Ejcv +ӥJ3fv'3جsk5ۓs83.̍'A(jZ+C@lJ@twΤJĽZ9BjJ buaz^= -&`nw/+cO)E#3\?Tl|?+ŒS-ZL7 LW@eՌI巠~kuVPg;c{o+6 Ʈ2ѳaS Л+36(`&Т%as~\-#;H@Y]~VtF\_ wJٖRee[=ݴ>,uP03n!84`v YSUC.vq JV\~)#b1l~<~&Kv r6%];Zn6b;q_+ܲ,*[rPky\[[0pF84^F<5 mS. Zo#Iu6{ALrD^Iplt/Lx[6ݾy. *5BL?*5֜sƲE+T\ Sr|HFJʼE4U#}Di y}"FkWRQA"kS @i{QD01V Z 1;aC4\kH)S 9iPgH^ կ3f5[Tӿ" 6I/pf`*!#톨TRD(/Ln/=+ -˂nnvaLrj{Ύ((HΩ<-܁ȹ,RFzͫ:FZVyWl Pi՗1$ >ӔГN714HYrk1j/Zn3Bg )^x\C:UB+{)(C3o?RYڳ[Xz|a"[L!N tZ3A 0}&J!9PhB  U&Ite?3wZQzpcR_!楍g_v-8w6=Ox)uD:?klI+1C\B)t,9T YRQkpl]UE*V6!#>E`r]jIB+ HƷ[yKܰE8ߛ(/ l2l2$6XX4M_3OsχS_:\i-?xh6a^Uj@k&֪U bI쇋R-* }FW]Q8 P2BB:̢Rc".t>[ 7_RBxy3tVPG 7UjGth%e1@2XD^=*2|ك!QkB-@ՃQJv#mNUHpfXbQob{2K;⹰(K?Shqg;2chlȿe],EL_Qm}$]ѽ9'o}A{h g:R!Iz/-uCn-γ(N`<s_0g ;k 8wHݤ+1x%Q"$ $BpmOj X^%L"sQ"䧤GHj qo;Ӗ#"eQQ@ye]:^kr a%1,?]zLZ}ܥ1yz[xG2pNڪ[z(d X3!P>Y"$L@e5qÔ iLZE6HJ K, XdWP\nU1zSZ [5<;+TOYM(my0g 3Mfj.zӑ \¦ JN6'R=Ρ)Y;fs-d ~H >r*RLi{_k%©W]DSdR˿ݩc&u»>%Np e D(& QkI\#}"̄x-/l5$ⶹ Hp3] "Խk2V%|1h;O$!!%H]4fe^[RcDDZq@jY.,":08: <-h'\r})&G؟Z},Ewj@7+dkéyW3 [dE^љ1.,4zXҢ_Jfft7k;u$N`wRó0/਽GZp)ÇUu Bì o"Pw<9_]ٛĎQ2vZMLþ9],Չ`׾+ٯud@MU.ŐW/zWBWʊ:^Ha&Hfm.CԳ^2I/MqDPQ9(<>|/C.8͝aa{|EIWv"." L#~ q5uwt"tSKsNJz펮Ifz:Md=aJ3:/MCike/ ^^O(9pEFGv?y.(6?3tE&02 {dlz-gpcIĿ;rO_[v|ChҢU`nLԈ⿀[Խ1ډ,Y]؝bIAMSL16'<#ro'b`W)/V"kEoֳvw񍓭c(WFno{:y5͛24C#o8 lu7-Nn/mMx]BJڻ!㤧[a1]~]*c6x ~ 5.%XcRs!UfM w5xvP$챬k?5jdnpTgX5wXvj:5LJQt #+~B]j bX o?F V] wOdH;*:-Gd z:ZwdɡM>52gCL % LTV27vDFCGhvBX^>I^9_9TR3O:v 7>kf3Fz9MiFӸ71(֤/XC}lG?} }j|tzfgѷ2υ,)sᬃn}s]<D8V\Kٹ§#bTAJyn\hsj8vk=KXnSgFq%ƌ|taX՘q$7jKjaÊR$^5CBS#sSDCo{ 5狖w p.@e̠鮺`~^4ʵvMM0nz/Q_g*~˞*Mzэۣ2qÒ,'^_oZAh"dv9<׀<'"'8hU=ZSc 7? AĜ[4 1qv=/Sr`ˍ)|4D39i f&DTUO! D! YYC@qSњ\L4MAG.6<Å"- *_ELEx0ycV8NuRTE5/W E-R# YbVS{Э~V>,=xl'X.)epqO.,hJ_/:ZT^0K69ކue[ׄ}U45VᚗYJӽ#9WK =L6K',@_n ~G@JsJx9zf &GΡS@s\^o[F7;d%D3MZ+.ll%5D!I4n\{te;qOU,O~!!B!վHH[<Dʹ2M3~t;^%J\#"X ng~?le ƭw( #b? #@a IRu{GQ>Q3:ɣkoGv. U֩;!jJQ9\ '|f43Fr!d?1p9dEQU)0zfd6tEo0?jDn/ re&R?+=ognN),|~.찵tigHgqɄ q^j\e;yLw3&8GAnQb5Ҍ)Lm> .n qj8H!ECˡ.?E3_S u,FҡbYぶu#)}U3xm&A;򕊉M^`ʋ<8<,Y <.^ CbekDd$Q-K$3< }aCYVʼjqA4xڋBLbIL~"Շ=`hxj0 Ԃqo듢1S֎$>.7/1L=O:B3Gox!C Ei="IODϢn(rܢOEsģ߼rW=IRaN׸Ffƽ( %\9o>--WL=<@ő}ڛTAs8mTz4|4R fA#+Lyd0ǧ]pbQ1n(#%R{YF9}/D9ҹ+t U )cauUO2[~{Y(.S{7ާxeЊWwfp@=QFZaKUʩ5b?#ΟM^Kv!5Ou i|۝SmxB)8  ޴ME-P(0K>@m+aŸŹ4f6w^428ڊ`Qpp✼E:=9vg3rdJ8!j:1 vS#mFUiФG-6A_뤧hŧ=sy),i*p b)7w"~-4̻+6 ve[s ef8e}BEG幔/u)MӆJtIQI5yc:Eʄց? SiZ8'FiMD^M4qNbc{;W)jDtD<}ȚUQ?Čh<:sq_a BG{{' ye$cy|労2Gѹ9Vڴx-kfX]mڜY45 \42K{g8qG+;&(ӎђQf3؁&4Šן>0艃_H3N`S1mOmUd,sxn@SlO'S`ݞ+Z}EZ16Λ9vRHc)REWDNm4ϋ*-͇FBTX--&^^{#[X Nt4p::JX 0:cb"$׀##?K߫s0/|=dY3I Akqɭuz.Z$(3f8[E\2%sJ}{c -4Vd{5R*_iO$ {ىr" kYtblyG)2 }%פvB@#D3[,0\B[ )vќro6QQzB8 K@TV|0 m=:`%KU=C⑀K !Ht=\)r0E4`YQlzf *̟ȳcw 2UZŵoVXz0s < h8BGY^Y,W{K:(?پF"S<,s[YC{g^  [*ღD}q M||RYҸY^͜6I1-ď-P|*K5Q i[U:V&rgu}^:#lTGS;A6`ν,jA&sPi5Z%p~<ӓR A|=J+{dL?AO;DEJ# i6 a9׈kmd)sm'8XuH q!{|Dcj?VׂJNʿoͷFY5JzAiG!VtJyHWʄW-@:2*|+JўK\=,|&7!/7:8׍zHiƒ6u'⦧gòϦ JtRG'C޸/;Xfy`&#,!qh T`enߨL~Ckp}^:pjV4^ R}3gOƳgD٠^e=qdExDtrlʔ6@^vCtjb}u"rDn;"|Bt\ %<ݱUC r ,/@^FS@i#P ;`0W96N{ }Npf }To&#ػCSK݉ 0|f{[Gx jfo|Dћ{s}8*wN,ihV*}1k,!=Ǝ?R.ŋ¡ Sj fhuE^n$V#:BwlHz8/Y&H:&94\}Sae< :vW)gR jA;[w6ȉlέ(30zEFYP4@<ؙ:ks)Ym&>4fk&9_mVq3 H>=/Nwa2g5r![O)cc2\=߃`,qbauNQ$dm6b}0AA ˃Fe,ޣOK½y:a|-A0鹴?O|xswrU[uW+h1oa֖ e!UQ΁ː2ZٵUlP)!DHh-!/6a] az\m:&`ϣf7lގ]u☤%ԃC/HOϷ0{C pY*2+?UQ| P.BIr ټMj8o~8/gn+#r(yEtNyZŸ:d@f^]] 8zi0tX5F&6WsNmn;5x-㜕W|S0#NjA9o~ umn3\nò yL76=̬Ά|' {6wsQ/`a3P%lhz+'p\|:t7jF0mV9bu Po=$H4b36otU':4UmQݏXx$fKdWUd][}5/PHIIK*1;V%Kjۏ7ص_De5t.^*NUy,]uy,|TJG7~iI>YO~0D*#*c *j"AqDn# i Clh5ȷiGEFbh/yM}\TSR$qL/c%(o0XuE-mOhO]?X2<'Em)H+6CFeBjau)Vl]:r[2V\wBIi>,?JI [7)j  %"0_n'It%A.?}5?cuDs|D qQ\=/bv~vgWddJ% 1foߍ?9X6H7A407>/_/mvCO?̢5ESTK2=G^Cw:+#1*lD`SaVݪp9pH7p[ɯ-U`‚% iwf=HaīlzJ,b9{TMm-*t =N̪ep^ 3u1_.Kz ~/ړ%Qscj+ASM}[Jd"ߩ/ ĉE_iuTXu"+G: 4^iCXq=?O ; @Xkʶx }_"c1l\;VBZZ/@YvYU8;Eh4 ?G~wrQA%(8a} nl+HC{%I52胸I I*(g v(YV p(ha}G4$5G+iv1Z* gȺi9FgjA־i,7f@(Z.Bl?_P<,z ѫU3*7V0auQ1n;VƩ~Ҳx4ɮB!`4)-Dca{RCQc+%r+F4F6jU-w8o>5gvo6tôe7}P˃R8h]d:}S3ISSRKPFjT( i?@ZL-Q0k>wE/ē?;\7!TF!3web"E%Y=nm3/ K0i5w7vUה&m%$V|c;yZB[+~YWap+[hTg ;G0!ծ_[%NZ_[G8X{ 䖰NeO7ؓ 0jIhfUO;8\8bL}N{JS |903$D[$i@kMGo8z*?OS3 iǪ $z}b7&"MU (&5w,Mv<6 )ݜor A LVLiEo9׎*%| PR@İgZmPÀX;UY-Na'3Q~zQC1XmxI1,M,V_pYx B(n9^*ʨK@ ݀3A׆@ϹIJXM M,8B#L2z הoO^wVH$r5lRxw="a8c^[:; 8jҒ!Qt xֶ -#YYyՅ|F;"ݏpſV/hX|CZL0AVa~Hbqf}p'ט\6t3R6T*txG@w^y:QL6L%Vsatp%ZCx x `gp-nj 8()ɰ9Ԡ\Yf@^Mٗ:8lpG$XՍdFI[U1sMS"J;r?jpȼZNQ[E#ޯ 8}M idKWmw㚯gb,kW,6ĈWӆ/IIS7qZ͚=,y*H 0 ܀*HJ}5ZqЀx* "9z}ӺbK'7+磹n U#T;Bn𜡴^DEX9SU(Xw` JWEn`!^M[! ׻25#"3P)Lq@(k:-|k9Y,h,f",;>?F=*g|IQo/ ِ'L dZL7K8٣v:0+~(S#s?1`YN}wgx5?@T9Ql&|O Ge4"?jx΃DS3o~77 em2N߇!^YGznNdjUQo>*w?·mɔ]/vi{JyY'"@pF)2U:)9"k^+ċېI1qS'%sQ& isK4 l=1mD:W"~'*Qc0MG` P)Y>Mos`Ƽvp؜ aGаgݎ;Q:>S 잾WY;T!LLSMETDOdJՙHJFtZfk)74|1@KZBWmHOB+ <7wi}xSP,e~;&lF-ƽ7bwM KjJ[wm݇-se$*%7x2Vlw1jL]SoP8'xjYYzG3]kEP9-m$X)aVnVvf'U &c6 7~Sx"Fױ G. ̬V8yzOn?oe\C|O&%uF\d @הB#yIm' IDfNn. DMÂ!ګq!Fwgdr,b`+"#%1q~QZ5=$%sxP {o"&#`WЎ9:ФKWr/7mռU“2 i-={힔шV 7#6Ѽva1Qߑٖg4\~+ JԿvV ]G_Zx5(Qa\ýJVk7&#^,0jQ:%yV Ne|$ۊ}uI_m:V¯QKi C}ǝ%!w08<Ȁ loDLէ_&OHVVӬ:E4DiNt۳%vo-pLX}uZ4knډ_)f wz`d5=;a; pO_o7:u~+{戥S8m}AmM"Yax ꦤ^TU]ֈgcM|1ӳMC2o%BE4J]GB  -L{V䉳3bNGFQƳBS/-ms'Iv3rP'(?闃+J(CkqpGD :iỹC >Gs5겵L'OsP;i,(=s Ά"/fQzi=Z8*D1ֹ ->" n&^p'H5pFdj!Y\ai]wgj"4aP]߼7͉ VS\b]pPqg[nX8x?vQ⭸jLEz R >FEFƐ=FPQ4w|+T*.!rm{܊k0[c.26ֽvT`fwE\)1 tcsweZl' {fQ Ri,2jae~Ur+&>kփ<!Z{>?TZ}$]-htݨP=gům>3І~0tțZ^(H eW]kQGɃ>Qfu_S l@a{ 8&ޝvi Q/",5 \s9TDژyo~\/pp)&?մ-@Z)C-Eh.ӊd=n 2qMOª w8(OmwOZ㜎NI]+9AEi[Mff(`7d\c,iYll_F'8/ICj3;NR ښ]٥-0݆/wM D@uV 6vLunh,himљZJ0+뛀^1o` zi(2Kj2˞W3F' 㒨/Riǘv>Q-ZO!,ވּ>%Fv29!A-08Q kYi]tDju- P`t:4}ZjML\N[ o]Ѻ3ahY Eʭavf͒YFe3QXQس nXtA,_R1[9[GwK+ *t8DV畫[_}^p"+g*,ƳU1ꂥ4` RD >LrIBˑuXCRRge葩i֨|ip*/_A63ghXy' *D BٲTtb^M>lQ: 5٬o9gSs=lȀtev]`Ze[ maY2檯0D;+~2|e]'=251TwVh d4rAr|c^ ^U~>0,@Ue h"rR1#WV`?YL ,B'X`:VFr8ի[)q*\)Қ0'37Wg;rd+ݭiO%?&>b{:+fg@5r/kOHbbk6ɬG1KNUQp:1 .:3;YSr(0n1/n};OВ򩲌WP9^N~o| /&`7aH exṩd~]=f_Kֵz(E hȴJIpehf/NSc_!qbE-P| Q !'H߾MnLA(n+ŰU6{zҳTi^ܐfMD'ɱaoq$Ɗh>:ie?zc#;TX"D9c$k8pİ'==}EՔAYMT푣<19P_&8Э Ff&:waNUk_pp2"IjS:JdPn(h7FPQc~C?A›{:%ƺ], o?sx˿'~55#R~-RGNFʥv"-krgtysOCT:yWfÑ R~%K؜Tl'Zx40e`|m,mk@m2Mt:n{y1G9$bzPRuߠVA!U^̅)iJObM,k[KIeP|B 8G^nm !y28_.w,wO~C<uYǔUad|fܨY5u uy)X67LԟJJQH^2 / }W/By(XX}C|N]nίz"qZ#⽵NgnZ,d5D8s(B%\VD4:mNTk_=FT(DZ)Nw5L_HR jW͌hzrյ n${tMx%I6Q'z-&`ܔ4#D?DX|XRvPigf֮Xhð(рHK\1&8+ Yˢ.%1Dڽ*iSA% ~@q>dNfxDY^OGm?إa_{Rhк6}1Mi`"LD]D&1񨷻5Bcc\M|RAK5$v1 ke0i%yuPyxfƄ΄ZzNpŢdhT@=%Tfq ݎvLdS\e٨Go #}hGi,_b-eF>xfh<*+OA(,u3".2 Wo4$ß`\k4h#:a꺌k˸LedML ^j Xo{Y;ּ[f h"EZanUݛ-k߰7xw.ZL=IF>>+Gյ'˄9 oȔNFW}!ɓf * vNMEGa)WD?r@҆$3w;S ݀ xة[VNGQ. r𚇟O~r L~zWHa ȤBK -2' Fx+UOLM98p'K. !ƙ3<6Њ$(HQQ?]@|]ށS0ZBfD/bH {"C`b^KlӐ)&UU|6CPW\=K&5:k9{KWog&'3L%4Uغa\ȉrJ%Iq5~tP#A$QAJކbπݩogB<شNb) N_D/YU VkY, }~2a@6Mļ|AXǤj* l&s F>΋Zh6N.;=  u7G` T}H@z[݇4ۘ\"%atVKo5iz^EYGs, f hэ,,xsns=~!t?} } 9S}{⺂ϰX;!zO]|= KlI \ oC2[̞ ԪIVX!KZ+쇊-4:} y6-3\wI'H1h|[R?"m0tkDRz B5hWbڽd Nj^8gt{gӞ/&FV +NRi6I ;zNJHDbl_9-b3dKI @-cNu~)/oz," *Ɣ%X|CU"'.B*osKwW\c32Fr'a/H mĺ2؋1qIܵ\f7a`i$;/:S43ǸEMvT7v>v HI< Rvb~SIغi?i '/q*1>qRA} ^7W'__ 2=`ԙf9;h`UYwƴWo6_#$N:d7v;{UCJ?7dlEOv4Qv%W%e4lW֟m-ye Si<l|=5V̕JF KuI0!Ә^.TbbkkF;G.SfJh9PjhCO+oG% nIr4ҏF]Y~1|m5چt08jꌅ=e4.xLy(wtYCXNEi 2@i3zc{Z uc{&0yu:oO=[`y>ހɝAa\4<̿g.ɣр=n ,tT~0N`uPZ:EOsӈf6/kfuZIwFgNJY!+–crn @^sϫ sFօW^Qz̔Ư}\$ T)Fk]XG,fڱIZzɊRF#@ X>"^Ӄ-,E@3Cs]IH Ol7G=wZ9G4}٨KDV&ӅqR+ii’e.9#$'ݙ1cŗr:zAn8B|ɧ+s<5 NIO\_J34&J\zl6jȊj12|R0Q~t>2Rd [> cqΕ=TNbh|ܮbM 0EݦrfbCVq#7*Ƨ%aFdaBs4fkSU= ˂-ūoV9Gl$6cq%a|.؉?$h#=$ JOpv1/vnWrEHõDŽjB 8#:PγqDq;1u0ؙ1>MuYvlPS:I ?t4O"eFgězl>Q ʶIb79a4A,dcI@q~E/taC)w/$ڼjV[vU ]*a3j/:}@|#}ԾyIycф_~}]L:Q$|BgJm_MʹcT n4p< {\e(X\rz,+,tIFwMo":1=Y !אR㇦!5OٕIhL+Z^LJ^'6z{ 0"2Er^JXV.?`#yT}5n5sF0KbЭn"A8%FevlI;Q"at/vc'zL&5?pſQʄS*%##T?alW im@ %#{\YM-Șho<ǂ.ds Wt;(#Bni9;oSK25 pAwb<|Bx&C'Y/-cY80u]-#DG, gNTV∊v6"A"XX2$gvuL\hE ]QR5 .G?!oyseyKlfPmvkPIܦٓ".~‡J 8Iu3&:w=:)̈Rla< yYZ|3[QMnfQBYȠuZ5rޱKԘⱉ'3/1vuټ4&_4Bq8 _ܪueZ8"2ĸӀsIr{湆*=VTFUjXÅuq9صrT22H;R9hO)r(uVfęjPn$`L5 x*/SBFVj+>lrQx6ͰFF=N2U-jI&n6L$r^YwRiF\co}#M!RG*d6{ "+0?,Đj:;ede,>Q4";'OT;^[QUd]!..r跴r ΂Ջo'~gV>EJQljO+{ dHycfdq^}PDn!OU"]w*2R;*G؏G!f[\)mϩ[S-Itڬf񣗅d~r\ sl)#(3o8UHbHeI˧CL9t_lhԅeFX eI٭e-'3هPp;LcS$2giHӨP bR/vOTǍƒ*p[&}{mU`w/i@P9S_NK&ǑM86ZW%Y' X/"<`ъD6 |GzxEAg+}MtGΜ0e+A#בɤƃM$ټ'W{pVKI8_Nb%w.glhPVja~n-M΂U2xP7 %juO=+ɵuK,'QPL[n9QihPNմe@j])a8mVGv׆ofR8 "|l/1޻i_Lc Ц_h^xf=) ᢞ:FDy"7)#3QO*6Nc3a}XDފء6?W& $K ?a>*/`E| ;L}U|\A1̬>%+[2RѺAsO=?6cVXH0;̫nt"T+`D!UkQ`L}1tJ$J@_!1R {uV)-P325*/+2xgͲ /)WUEahndGENΈ`}y5NzXi0ː຃xF GnOޣsw GҪX je(yjT ^21au=JIo@&+(.0q-]=V8pa֛PTmVIg]81,4hm\LNSO~J VY,Sr3.P ]_j'U7=)rY/?TTXscq!&^ib館_&,u oXaepc ->@X,yOsWuYn+Y=?2gҊ`Z!1;2 =aحH cje!$1ﮮ^$knꆔ$b|j5;Xw(k)vAkh>N$w Z.뙭BxnbZ^jI&筩A|`(?T/bQ.ݑFX?|cIMje"YPݵteiﰠ$˦/I'..(C%|X$̈ѳ:Rq{ޒ1Xzd-Ny||F" hڪ`CQY|e$TٻSh J$Lnc jGsBg!w 9[EQqvhW̗"-٩#1ZkOEҊۂnJ^1g^v? P(ê7iKAVmp+cX(h5,hnL_]|M1ƢjK uW|ʁqw۸!vKݷr a[0viZԣ ÙiuE**&?XI}CNE!{g{mox HjwzX8$DCʻs 3)Rk랜'TH2=Y=O?0rAm^Vvw7 EP"N]Ғw_X6 kSi7UѹtG}ڋS%DJ_\BRx&?AL %d1QpLj!yV%Un]*i0Oa쪷spV\Ӯ67p`ws:r{w =B?s*QGhn@1:FVEebe"LvYHC .vԛ+ KЬ^eBϥF.7^E "P$ dI$N/I1xB%D.bf +f]>+YFmOzv%:lɧoE hP͏uI4 ~S@[r5nDt>T9T\Pb\ׄsQeW3Rv]B:ˁ=%rY- mnʑZ:]H/+Ji1dLۑ-~-SjlYlzVn =pb)W/VHn7.{y`'vja=fR";y赮QȂD2z40 px&s}{7=(`IEX"UIZ[K'v[\uZ=wfnC0k]>-;DLG! 2Ou!uֿ"h'0}ޤnu"&~ҋXl'Hn F׌*(; ]tyn9{k}ǢM"3 Q0T?&ZX=_[vGW*79 gD#H=MڮX_7 yè9tKK8DI0ń=.4ծ|Km؀t܊*=.=VPOX~q7>L'SyȺ壆| *3HN:1Q[ JmLDgjV227Ȱ7UCHSWAT߷G0']7V?C7 =EWU!xM%w䶿!;6Xs_/jF.k;P /g?oZ9/rZzJ V* d30O-+RhSvlOXP;AU;w!f\ޅNo0Bɵ^W+|7Ā9b- ">T L֐Snȵ|cS0Y.7m;b-.߸R }g.: nQeyh7e$BQmg+NA(wBn("hVp`w<]<$v *-[x 5Ә2~!Ek,_JbYM=>q(R@Y`GӟS SV@+OVSЅHD#k"~lGy3-_g/֦CkCrY>Y9S%5XqFxj^_1Fn ϚYT#@S0R)=S7~/*`ہ-UoI'-ceNǼYf4~gR%]1}XO'YV?*\sL.'89T\WvNc$w0Hnފ@8U jb}΋E "4ZP4v']Eb-J.׌}h`)7澝Qq&pT[} n}hwYU9#iMŲ.ZqE q *D r!H Sr;ZzN|d/oQif@TS`6sqzA1' >f*\DО# t0!;_^Msh"-%;{'z+%E2K"!AffQSe=c[v3{ ?QAψh9(Drq}e{0YuK>WXsYUO ^ftd V"h}A uD\gGKj՟/hȺLr sH]dSkγ+k wEɏX~2"߶SƒVJghHs(K;2P-bWwvq|i?Gv-F>X@ 98Z9 -`aryxbz|U֭']O3@G}jU$L\c7gU~kx̚S|ϻÙQQ0:%I% AO纓GGX-e]͊k,`Awס{`9bB ;kqAgSL*DWX_ҤDV1soC:#-9[@(+7XhDSz0RJpg.Α9G<=^_a(#-k2V)B-_KرG$TT 5'~c>*fr.j}l,Wwq alٴ~gnV.5YijZG3,җE5nîv /yC*Th\mV;}%& vp%̫c.OW&ԒVm.S}o9pVp#ݞ/حlt[𥬦fx/qHZÊf)z,6 xS|sORJ(gH&kl|LP" yhFUh~d)8뮁yЊdm ߧj)Olzʼl w(A2d=AfAhL<`tժ+t!(~ݱO/TԖt:fĩ;S?4gJMT(6-kJ\GkIKl5^z96^N 50PD7=T45:!UX9Gvee&>,WboSΜo:#NQ /+ni;vfhн_ "(lQ22`ӡREJۿ?'bCpS2WHx4ӓR6qb*+#X6&8>puwum R 8>vZLb0˺r.rkJ= + llHEd}fn>ƎS=Jn`CqS^R^ ~}6HA*+R&z䦪Fwly?eW lg=Y߿>&ۜ3kw &`;>sMy¢Yc, -R 0Cv1h)=2BL|J^<񝕍-ϵ*9ZwDoKzG*ÎrłO` V7O-/E%{(ʙno aSОpB$ik842h>Z)9I8|&^gceQ7:.=ݕǘKW_ޅV7)ď|zA5# q~o 㜀@,LEuUU/~RMSmK U2ZW8L{5 [VŦ ȱ%_YaC}^V:}foqwyhJ!kPCMP0wƑs*Xg#pڦ4~~KcVK'Dr%ƐҸ+O0Ry˓ :!\aFD:G =g:Q  v3MrfTȳ:>T%;ռЦrK/풮-{AF͜O?jB똶Σe]JB k5{*~p=-x*Spvq(V!ǏRɹtuSI *'q|`PpK]* &"0bǩ;PLjKWՉ>AVaž(ҡY##}eA!@e^CnTD ~&ݴBTD] e5"X>tXWIPoj#aUyL lV _Mqw"JF"oOӓqP{9hnZ#od6Iro@σDw\>YVEys\uK=WI5qƹ ?W@- AG#H1ܖ8|QU/uH值"%W%xY!֤ZU,)PB2уCWt0Vg?Dz' <$8K(Ցl |Q'2>Rtj‚Wn.NH&2pj"Pev&ύSaWƗKr="bB>!_(G $G%RP[Cp- XJn\L9 p;m(;[QvƘ`W/;Y6tLz ~J]J[B%Kvrwthe+V!sy2FðTZ-ߓ-:mY[uo؈40Ba:G>:+Sͣ3l- ܂r.zlĢpB:R7gK:Zg3*е !OscQI;eb~!*/~0,T)Ӎ? c-)C%<ݚY_x50 ;S:f.櫷}j$4^Qٷ9\zFwCi(ij2u`J5o}.cPB7BA_^^dCQVQXQeR튵A2~ ߑc.4@tj+#n1R底~J2Qy<-١8DeKFū PΨj;ӕ6x@9 A7XȜ _!tNPO[)V&j ǻq'g⎗ۦ 0O̢_E]BėzyΟ*vVB[Ti^~ЧZk<TuNՊ<"/4U\SLN;x[ƴrU/,\[*yF2۝E/91"^g 65fӤ^%r @z0):јj?Θwڷe*dχVgU^iqz59*  /ʒZ^=*FQ &:…Qmۿ%G %/2EL1lf˳. P^}DuH.0!{ygW_E¿zRs[#|f&;w u8w@lCM[II}<0= B&lz|9{/g&{:q+ k~0zvekrRٚvְC_G8Q'nAi1U#F %N3^yzQ d5~dzl8Y}qy1Hs'~JJGMi[(W  2g%)/%KU${/dcGW+U3/6%yʰDWV7}owO;3f{:H(d8:R'$a- `)ugC/u #aYQ ]53bn+ rRM')gYG,\:'~T}:E(RuH_lGB_}zJLD)>*!i97$y1(VJap8gZ~/A)j9QvPW0 VQe`wO4 N@c`pe'݌%I)YfF n#VdLʨ5%jn'Kpz"mEv5!ñMʠ/4R`k(k4y9bm!낵|ZLoS )4\Q_/3;pz-=agSKߞv\er(>hrbxsG{iьq?zG{[_F>e7M lwl(w+Cnd{Q'% U5}oM8i$#QCv5kT^F['6=4 @5;Y IW9ABH` 2V $gЫT<Ra!y N\JK./ &p9۩?*?' C=U-&g~4 Mv%Qh-3(_y$W[櫅i>4/y2g"OB\7iUX TUJGʈz_#64_C d05RK#97؊i^zM vGC]PV3k}]N [r8ӗ޹ 5b%\]772/Qq^T~BqK2*,~iCLƭXr/lԴEКY9)(^}#p6Yઅe\f Rzok ~h}u0iB6݃HU 'CSwV?NFbtMpM*:~}S[F[ˢ^J=(flѡICnc2 ((?8얭=Z Y'Hgm8Bܖ+6)[c'*ZQ%<#jT9@8 I:P&ًWenEij<`NߘxAsWˎEcv?*QHL=UftQXwT_NmH=1 ^*ӧ4BTSO<[~{)KA2qeɰ_o"1NN gt4AT[1OiI Wj0Fa68 А""3PMXwo!ml(BC@1%t#* HE6e=|h^,E4U^`veFgB]ZzFtD] Y-2`Kl , VaUy'~$ROχؗXetY5o^s[ PX3ԓ>My-;xz'ƌCI,rF0 M|=5{8 txɻu:A}O,<`snK`=-SO(.Y(7]/u*95h\b{\_C/TmyTRJ+FRήo`i5(ĜQ 7r¥9= l!a;Hʠ;wɰ݄m[,7OT~ Lжm9>9E1WW~23tLV)ݬo ⍖fHϥ ۿ N]ίkI̹+ʟl:S0,cRJ~! T)'ɑWvX | IMl|Lo}mݬw1j~ ILǺg}pVcܐG}Mմ{Lrv^tV&RWabuL(RAx4dSœ9D)U}T}q=•{MtU 83,RĝUUcvJ|%.xOH9[pe酆bw}DCc[ITQTGi)B:z4iR*)Q,JV "2i+UbDVJtO0.Udk/ObP:g^)tH/mĈ=nJap&[vCkR8tC19. ;z-*ZКcng}B*aJ_.{͈W"CAUyRLr5OUX$D D~37ƁQ^9UBbN( IU#s'\3?>ݛmeIz5[&Fs\_\,vU% 5|6b8̷E'h QkxrGzg=t_os`O:!qN,'ݑW4{  ÙU;0*Uȫp E_BPYn0]T:_vԠT+\Krv Fcȵ$NjT5Isl$9s*8'=[Tyon{CD;gzdAD . Dy3!g}W 6Cε`7.u?H˫tB1tQ9|j޺w5W> 3YiS WYTǀGd؊ւX9ۊV{GwS4ĸ@Ǐ}uc:V7/meA.Y9CVWScrb2'y RZz6L]ieyx_r+ 'qݕifP 7p/I̾ s=T/]6҄TW)1D>^mw_p^ nt qz`R+N ny=u7t~iYuP\^oH~BwkGUSY:aYKZ! U='x(ˁZqZY!9ЎzHG_.t2TOPURch 6[H1APLj^ޕ1btX'!U`AZFüԗ\;OHd|UmKK}o2\:7.` 4~2nL=`$g-dH-_RB4xTwisAr}kin>1/'`J; \ DkMGʛ0Ui~{3[~{$!ʒ-M +T 4:' lD w<*sѤhA(jcg.D$%p=`~ k[n1fsߺF(8Un.. wEòa"x&a6;./*3Rn G6r2{BG2*%4UӥaQfƚ V~0Ra KoJo0w]CS)#X|D,x#KZ0sH$Mҝ%2"uz:V22hiOhSf(y>?xi!~Vh뛫_2+ZTJBעzetN*|9Wl} XMSeY'B8:q}ͽ$5K=>H G]kP~hD:CpވC^sn),4ÔR`yl|7YH=&8K3TӦDPNhF@o*;~)5pи4t h`J{90d+*Lq#RQf[/ѥ/7@a7aK+ŠkwZ9;_[.(e%6IF[=GT-хd,;8'''>d@EĈxɧ ss 8MK ?dd|pc얩wMa?, }z6~\B-xcz<15DP0jC1`˪b@+ p>GF 2nP*mi4(::{0GI|0@`b : fF䙢-0ݺ~MoY!2p+l:dYc0p5:X@3)M(h7'NJ\Hda3w7nB~ʧeh7{g*!wŠ,WCzbmT,uU:-=tA\0+5 LI}7kR瀘 u{`.5]fBsLS3k}/IV6ac1 D3аc,8ۢQwLgMB L')?&жH@|OJz#-6z|S8w?3\Zjg(+-m^i`digQSÚţok^Ӥf!W:̃~*;>S1X-39<{TMmΙnznDǍ8Z`RtRWOZ3M7g!UӏF@"t2;D%d嗪FQBȮ\5W [9yW!=1Nk#V26hXW{$<=OaYSae&!N$Pq/@ 9ke|~_]}~){ІfVbF+sBC`b)ނp3ߵk v 3<ʡ½"7lܒP[v$jY;% v<=X)cr}K;熖vܿ⟇Y #X[3˄dTZEЂˢc# X8F%Գ΁3zI ^FGs&nR{Hʱi_(6IIVޓGx vi?3Jlg*0q/ QNܣ94hc򾳘lF 3ihhJFK@($bNwuŘ*IWA5 d{֘#4ō4TA͡pدL]k-+}îp}<.tAm=]4_GY@uXeq[NĜoTsE? ~DU$D@{2\9"W] 9f_liosN:5:\^V%]3;q΃R0+ܱ1)WVFهR0vg:gh'c EV$%T9t8/[M7KU!K~,Èr3e\ʞUdrKf=J#[VsjuOb,F~?h&j OAOzo}IC> GԒFbU6n!(i-nVp::t ՈY .}ěY|F\GϐbUm},PͿaP|A䨖,ʌNE-T)IvB ao<=?/;٪%>y%3Ye B"l1ĂpT~\2!q^FaS$`EUt) G{$틭-xΝA۫@iUClÍ( 8 6#52[C|E0?Z}%R+W =*=ѻF۫w5ƊŨ*5#TC<^T {Ҕ FIF&~`o[JVFf`Ãu8źczZv({V]}9:ؠ uucy2YitcU䮛Xzfi;TtR$v^mM)۩rj\&әޥ0MSk G꯬ (]t . @%M0 X_wLxQ.}ת6umZkd&WY*f mC~|Ejaڇ hFG:\ణ9I 6K<r?ⳑGGiG|ms **q0r⨾UsܬQ9 ΉQa(Cz|Xjaݵh*+}S,ݚg!b1ηeG fJ`83 = n ̍p.r3[' {f>7DaԨdb^޳DR; $ ]Jt#W_}$95f3;ሹf? N ^54M̆<2x2sxӥǤ7`c}c#qM7LͻψE,Yg{Cstv2Bi *'61bw:En?t2y=fPϪ ۋx fħLkOȞѶevӓ_ uhB$ˎ\܁Ůom29eLCC r/gTuYW3.C5w&p)h'͊~g"d;p#h;yk*,h!n(u(~ $zW׎aDHKkޖ_P6gd D[S2;:(*!vJa\Z  J ;gFZuڎ ᱲP,8)i|f[8d9)iqGK=#Qq3s 1hPnFh%'f;k`&Vda_; !tPGuT17{ƭ<ŹV &/ o&ٶy( 87Fl$1KOd;Ök?csp0( YHGسd]b ~vsџ{忪!L..kdp=LaZ  0K9s7Hfa,®mxwn Gl!X R zgΊoљ 44e@m5R*&R*'T{و]3@oxߙ>f M:@ {?趤oLuzV-Nݨn~'C1k0n$ccւAO >P]l+ܻgJE_eQqۓg@tQa-QGa | ;5b b46JYA~N 35_#VtRE9Y0Ҋm.4.?uabVAvn7JܣB!2.H +D8*3LɣOÝ\ןn=t9?O TI+ev2-L;$߆`7l[ܷ+ՅB ts7}mK|fe/vq&u1by-<>"ְ=RCIV^We߲aq}PΈK0DUJ.0z2l7 BV?p]?T]E%h, ߈.s76igMv ls7-T[B+k[&rɇ@}"2/*|a-]c 6"h5}mSݻ 4>ػ +AR)-Tz-(?}\Ihq.A65ꀔ%NȀOIBBkZ"3ΩHeQ=Y O9mfT@&|K 7{Day'f09F6mg"f9 ]c78Vfi7 XpC <2`d~m~BC) EsYΈ(I7zKbxKgJn۷~`L%'2,H_OeO|omxxJ' ֚hW> nPR)fQb& )/w1`}l8U \q*Q/ 5(Bu]'xB~P.ŠXi}ឣ}n9]XߌWUwS7)~4$ JgEXp 5+&Gw_⛈0_ CT.٤;:תj"oi^8T(sgPƓʿq.yE>' 3q͕PݕmS(bb]k f;;٧?pkKedj]p_Vw?0DH'E__o.Qa/CatDIì6 i!! b4F701S 1SX7&KKO~I!zOh/u范OLK'4NYxkgPBʗGҥ*T폭`KYdfEEcTWxL/V1۾҇|:^9ʩ*o][B~,3%'>_74Kj8F-*7/Tסi1{cyݓN$ }]mڮ΀6ek g)NMX07ͳ4]ܔeK\ 2;_轪_W$[;t/!FaCЈ{_R!W Of$)'j .v5@Y u.eg?%Fb i' l1#>ݻ4sdzdITgxH&-ؾo[k22ĄlgAL.QTřN)) bD9:="p4埆O34SR?˲*~2Dj2Iʳ$BYaQ R1qǺ!?D(YdBJvxߙ8Z u[q<y^A%9qx @;neb-W98#r?Cvsғʮ] hF99S5bΥLUUizos%k,~]$-"P[r7b{TAU@,$ÈS?p#!aWg^lG,ī i QTh8?k}^VC62rO?OQt3~'կRm8TN^~M:Y~' !P\ '8tꄜ5`[݊%vKBy]IўtBX!URa@kAx!fTnj 8oʫy4W<J^j}Z#, &@ʱ!Ng[ W7: ylR5! ™*X6ڊxPi{՜'QcZO|5"81{l/s{QtzEa7-ͤEDFOyBЛo_[ kuFjQ5{0懖Ju(H`,$Gb&BJ ji)a/f6W&77~kI X4)DF¦eŃjjcD(_E.r><0fƦa>-h@[HCBR樔6#uj"Iy10ld?'s/&NAZ^ŹPjVQ-P\*g0gĥπ_ GCM՘1~r8umbgK{]-ԆErD /¸2iRnR22(!v]d)'lozRN>p}ZL.xГw$>H :"[ l($^iJ+)(=><{JSLwpMTs.QK,3jv2ggP=l^Bo#-itT{"PF-E:(/?r:i2C%\NBy͝+f#e'ۙAҔ eܩlݨ{&X1$~ ѐoS<18[ouyF w~+veΘU%Cn=}w{(o; ie;m4=@A} lR thűy2b,Dk{?U^ϬgʉQLrJFq;[<_q raFpn P-m<6z;U"O6~Az5Shl_s0E?+^$>i &ZC Gqq5AO_ϧw;0DZvsRiLK 4T.Lj rMN'۰a:GϰZ`. ӂ鼞$ĜЖ5  x/fw'sMK%޽]2PUoON%5̥+%NF ℔ T'SĂ>I&$]exHĽv 0,sr}ef)Tq;,\Vgw ªYu&U"@>B6Dlt ȣ9, 4v_ ȝ̄u^8l7l<jRPqysS_EWjZB;-ggM1 $[>g@GiA<qj9~rdT`Dk]gO]Gد\uLCriQqc--DD`+ƄDAjF,RnLx,pU703M7I K}\ePg .ZdzlM&CPgL^=1<9$əV6*)*uv+w=.{,B1·lcjTg ,Z#* [ID]*ƓoQR' 2 qB%dWGlj7}ym$K-E-Rw/}֜݃1ӕvvm-\[XgyjZ§L/Ŷ]9BPP0 ÀlNޡ.}$ v,3ǰg1CNvΘWw/Z6[! TӦ8{ }*eSJ(j~$9uY6ctj{c v 3Gv(@;+$ӳ=-` 0 VUf쥈óz9ۋ::P~JAti?*">GκM=O*/۞uJo%Db6_j+KfzFls6bC 9Xo&V£[Qgsa1C 2!*;V])ZpKʻFzjX` x( Xq>s, aATQ`}UH3)M6꠳(~0 ! *-T.f΄b]g4\p,vb1_nΤO, K@s>9mPU\$sT Rq/3(;b{w_'{hFj+U:3WɥnZ/ŝizSNZ%Wj?:omR_UF*ff2e}eM^8uٹ#;v#4ǎ]ͯoO߅a˽'$EXO^]\bL5 lÍ7B@7g/g^HpG9q ]( z ذ֒E_:Un$݈x]r{ӉWCc"ʎvBj`^^i>Du|ѿv3ܡBMx`Î)H?(]c.gr558N>Hg ?&J.t%}_.N=Q٣27e\MI_zeAk jVғ鋈ЃǾ<(`i06;9GY}zH]+F~Rѩe0J9uy7A @ )FѼ?x[8(T_ 㬗MFlAm15ܔƥRJL8f4xnFYڰj2L$]$0{PHmŭlT'kǟ0דm* SjzRzR]asQ;F*u2P84(x#73QCR1@1{^;JBut/BZ^MCXuQCXecԱEϐiȨ+&aÖs+ g8wU&nWAԴD}_5eɕ9<"aXo @QYDij:n+V?&2!Jt#?ZdVsq^w k@zxn칏r^DȊJxYd.~ϳgO-b'5I eZɲnA79SD<*w>*gv FBiRldt']5ޓCjzt!b&ՔA竄%Оc3%d:VN'(CЏm:NGD!N*\JBZF9x: Y> q[ {ޗC"ۀc1mŹݾ=o^adE@!Zߦ1Ago^+?V˃hLdE?Θcʑƈ4%:} y{W:I]IϬ0|% k8[XB%*vh>LXQJs^z6 o곜Yz(v/K<FWBaT} f>݌2Dc~Ƕa:n_)mj=oV,~ [8Q#u neU +G xuCSOY~$`(}93|}-^@6`2;9/AC׍b8N$D#+NlNuf *!A>I3DqSq):^yW䞶CTmI43Wa #03}0݃&? ́<1\#Чp7bs=!gSґimp [ZW*LDz='`TMr).$/bkNM !FB BQnQM%o> ?SBw.3YRo. |֧ve 9]Z% toƂS#tֱ9echkf pںsLs:r#w 1d ƴƸi0ng#JyPΧ%'7}@Eb:`6^/mH<:_КHРKnAn_ur CNtDs:2m7D;CAEoAʽ8;L~!VVߝ ('ȑVl)eUU2)p,FYF7.1tJf|+}`3 8Q3Č2AE-5).ʕ57a{vXoր Coj㐿swSw=hkU=a, Sycl2Mvuڅmz|D =ԉCLK91kx /6FNOYTI@, 젌H|b6 ɚlQ]ƿzdHU|5/2_i5| a@TI4&ZxtR*r1SBJA$ ihe N3ebh:el}p/fӝoPQHD?pe zMڂt)GsՐWIPǟӄe٪,#lz㤖c(eGpnhwzol}rFw""2*F2"?S zB8RΒ79qbiq|r9jlE[ЭHxVnTTt oqic '*,:g]sb7eYG7s)V^ʗ j0̛%d(kh@h`N{^zɪgB}x`o{9LݝAkGyPraU5#95|SXuY<j8cq]hr YWhE)4zC #~t;>r7U#a>_ 3nj5|2oD:u$Toc`Su\V^e>h8@An:sQ#rh$HS=L1kEc$D;=;&ӷ֗'JkwI' 0M'de_P4uIE(n`T_ޡ:篩Psa%y՞N~! Sz~̤I! ˹Nj-ieYX{{g«FҏԒqYaz(+r '`e)wY Iz~\ 0hydedHI+1Dٛ,*O93JlL- ޚOë_y (3eP-Fu-*ƙ3:{7Sjn?V'Pz+=Vu[ոh x蓼߃>%` l(y1VB|"ȴzyC~|L)Vu٧n\~9IE 5_k >4܎)(+] ؠi>Q~JRlato By)&!c `YBsшٰ[r톫0-_=RN )-_"m$p}_0X:I`sXy,<* B}Fb׵S" jX9zn[Zw} r8, UnjM'[qnmse3cMU`Yw-{M$W}Wɳh؟Ze-=hA>QƠ o瞖d\ = lI]%`բ{5y+P}:_٥ybUagoWg"GEbQ{A;J[`9c$$an]b ogGڎz 5rm `UP-&%8V#%uʙP=)e]Z'*6#7CPF VHPX ߝuڨ ucra=Dk~ %zӐ -!/f$+=Yj";mbSM+R*[Gr=$IlaيC3]&*˂]S6g:YXy$XdVzJA& #<i>uX޲Li&跼FˢSԿ'XcVH+ADvRyDi枍4%zC_m_"Daxg+ []JShE^'𮗎d7,^fooTzT%x ,(src&M%&וDGT;j.p(aƟ.;_]&\zTfW)̍? c5rS`$6%[.wJyLT3޻?9Q6o2jb<@%loUzx_(N*EEɏz$uI=yp^FPClأߞ"F;eКLnq.VMH8oY : 8)|ɀ(u۟RsvK^Yȇ Ⱜ=qKIcމupqBۤokp0ʈ#vm ?pZ:qjG*??Fm”$)mX>{k:mV2Uh! ]hхŵl˔TŅ툪ue1 l77QE,I{Іh|>avE1mgxvWpqPTݴޓNvϢxT& R潹hPS 4y`Pol΋Akz|S/]Gt(L938ѩ T"()BmXl( n)(h͞(byo3!ol딭?\=$ JM+ ҎHsFt:) șFz.;fEf&*HH}v;!p t HN痙0.8Z>f0+$,c GxuBhjobxcfO> "'P R.#3JPmʮ}BJY:e.V=[q E>OE90eb\/9kqHml<^2)`32gey[ɬdlQyy`ΐ)MKڪI$ğH<20\}7Rfpy~2&CL#xxM))yɈƋswzLcB$0n >`;@+WH)rh>>Q^ oG46!Wq&hr4I[J!#qqiW)*H,)|g# PpüjEkR6CG8ј@#I5$پM-6^/BcPz %ՃnrʕʋAZ̻wK] ~WDE%wNPSBl.G trU+N,F@Q^XI5:kpLYEȭ~u69 Յf@2)ZD[I?Q,+=^G5;p}fC+n"[(Xwoӯ"Kg,* i\aPMrySýH2.tDg T[@zv/{Fp hX);E99g @'I/z#AExgG{wD% a}N />Ln("GlpT\^O3rӶCC(Ƭ=݉n{[}u#r<8y_쬼Êh8C>%t~/e1"4ܔrI>k a.rw q ZYKYC?҉  n3_q4Bo#074X;XʌV`gt` _U_xG3BGL[[ x5vg>/̐<=38.6H3~ }Ov$J ,J'3G; @$G:A]Di|_MeEoYA CT^a{j8jtʱv/8ZCܼSvWE&@QJ P@Tmǖbqum2;!dP39*/ĀN]l5h׉1;-z!L%E,4w\}((z:Wm\ ,q㽾ǐvNib#fpvŖˉ`f(Y0e+StuxF#Iu$Y:>{IƬIJ\Mq8 dm?zmh<W ᕏȿ/ݫ;v*gK'!I. UtLMAŤѐ`}~tSH?O =~V+op޽,Eu=-@@&U(!NZ>M\^-;$Do7%.ӊlegac4ez*g>,":yAQìvDFh A%3dOL¦BtWVfyRI8l{O0URU=2M3b= r?zqFޙGSZʰ`5IqT:K:+ Lg*Z;^)Bz͟aŕ~P&4&nv9yݫc \8hH2fNbݩ;o+RC`Ԩ9ސ vbxB1{7mb:tO32nc?f|Ynὴ_GL kcH_:Ʋldh(:pqa3im EyzRrOezk  L$,=)1Ǻ4tюͲ jyL-.r ң o3n< SHZEPMYҿ M gh/{l_f MbާA^gDjw<sGcCMX4qn~[keQVs+.7d(E~xk60LG?FתS8ŸWD;K>)%91Mf9vz&hl _fCayn0_2Q{d1*83SP; 3 D' ڇC@Rs1QnD͢SDC\(HײeMC1o%Yv:e6NG5)>!ī  !Zq=]Ł] }>SNVݞ'Bƃ8VKB嶞Q+7vK1L5ʨ/ B˖[#C'߽voaz^d24pb$#֤xQ0u(6 /@,w m9P]hSB.pGBSp.v妠@u( NCJr!J鵒US&̋䢮/'3']` HХG|c5UE/;D>@]9g@lGӮ d_H4P^oyC0?90e!@Y/xHd%iǡŕyqfiJ縮5 qhoOwaۦiҹQD1 j |`Q7h4eꇝ-C>\*ZL' BU1 -NI6ު*_pL=C;8ƅ8rP%ғz8A9.)Tm$e %nC76˟K[K5OP)F3ԩgRvnWx [ax Td|g6ՏՅD @58yqy}6>p9ڂŕb=mw&*1ji7EO踤H q1F 4 SdW Ս(1/ߴ5\EQgͯ*.dk!U@~咡p2唶==W+t^blgEu߻"8- '>-Q}>= y&wToVUY{ZrJ'GjGpa 9cq&7XkÝq axAqmxPurn2l^QK&ă^Sɵ\ߏs 8$ 2ꂎOlÀ64Ibx[gOR~j5Ysp[9BV64  ҹi~g>zmR ѾoFZA-m* /%Xx8:L}7xh g4vY6&(w#6gMx33/aCyZ"%,@<< Z x=pKrן*g #UoWL!h݆ tF{\(ҝn,E3xۼn&JpRj.pt$26uC}p>GK_dž{ԁ##syjn[=9@3nP* ˇcZ c&yǬv"O[0za:91h,eJK5`6r|q_,(<n@T̘gJZۓA+J|^F%[ܳ{<'FUL{}ĠJGG,/1 mYKZ@7HB N&zc&ܿO `dੌ?B~wBOKg5+ O{7O?= iNCt/P(`f\Y#?n "SW~E/2GkY2!Voz(13TYLyb헳o. [:mGr pҪI{ vT1 ߋp&;Icp( c^ʍ3R?A`dOYtR mJz,IzI]fu"ra\38Gp)Guo%~wU Y.*"=oD@#۬*FW~DTM-p2Ž1I'5?T!xU{yk((h@~A6v]l"c}jTO@l=Q2˦= u py04h}R\|QY슊P%5EN|8>b+'#hm04vgTjJ, ZyoNuF.Amc'¢O?uSkDhtM2$tߡCvB`:=OWrIWl yV:z( QWWQc zhDz#ق_֐'KÐij1-0:4Lg9(8xw4RK# π2**mh;^jz:iV29^zJ ~>@oj锸`M/ 5d˶YvEO/υf3Đ!ӥ|/SeX,R}~1*{ _yvƕKdN$hgU;}Ͷ9Xd $?T`Ǜ"Qх ;mFk."jpE" zUX}jBB7&nNIjQAј_I )L_lW%ubk̬%O ÂcncjO8/Av+uK 7E5~ix825Qc,ӛ5L9@^sUj»?fNjƴ. sHi`ZBd. ldjZ0GQ"4 KL,QM>nziXzu}ם6E˺f˙8= U7[䡽5j߻A$wWKz=+!IE?.mj;u0ǂ|?۝@nkBmRb!gBn!quC:;!cx2U &}t~?3y@MnaC">3d X*Z5Ӝ ZA#RF.5xsc;3"9u>p:|~d#gN y팎 /,22 I?ΎvNU1 Z. iToH6&J\u,`nބ\+GQ!7଻v?~([9֡3&&U5- Fn" evhX5`Щ "u`g\tS ZZ4dR\L92`Z. C6ŒCL6|jG~7ñl¸'vKv~ZE0;BPxm( ykYBm|PwﭠeI-`Õ2b]1$dV% S ԩ/FZ(m0O5%YLǮZ{LXnafVmjoKfkQd G'"#X9CPq٘x`,zxaз +X5*őm9[<%K8>Ngչ97GX ̆$~ηyҷccb~AQeQ7Jџg?{Fױ iW1~%eIBVh}O3\|he0sipkPZ:htlS<Ҥ̝ArXJ5Ao9Bu kqgP0[,,K ]9/&,&[ꍺOsu9ƀ1,D1܏]RuJCuN-3$)D 1GX2ήC}}R!Qp,  P~7{ZaIaF2/hq$Y(۰ؤvuŮNI;=:c8oe`[1̊l3uJP{" o ]lPgU:2B4,w, 3+09!”:Hs^î}x~qnIgxl,X@&[RTm5kR4GwZ"]ny+b($cyuxzkmԥbþb%^u-=jэ ^: ա|OҺLVh7P6^q,!"C8Ƕ4/s6F\6yMrN fSZ;U6&(G,uJ} IgNX0Li7ȵ,"%Fs6 +S,AK7ΉBV)K.R40{s8C 7 F;G7#mw6"=P]gK|!b#ɐ\%[پ 9X0uY 7JY[q^Uy],<'_Hӿ<,; _iF#|>a/3#ٮB-YrUQp/ü-eF soE84oPh/@0"Pf33%^ 0Ȳ wBm!V%s.(TW,{;ȏY;2t+Ƕ.0F{AQ'wْy*۟w%pHtupTNC;&/yeŮjz;Qyy6C$&GATn$R ضY~}(VjB^V-h  xf4sfV$[@E զX]Azu< FLL:-pї;yN"{AqgEC%bɺ+zx 1AS*-d\oyyGBhZ__R~]WVZX!˥6d:uOv:YBTQ8]'uK>eN!fr')\Ih&ۖ9`!\$S_%g;JT^Z1;/Z%aɡ8`p 8.A E5zxh)x~lp57i8ٳK&3iC| _z~ eoԝ$*uBM'/4`>]3Ģ"@"NK{Zi&#š既 KdQ:i^:$uX ,%AZ6Jڕ:Gs.Ѵw,GtbA_v aenN q,um|4,PECw'!_ {QLmHgHyo-U\zO;6euP?yYͱ>;``*?HjlL7pzs"O4%%ϡ+/LCoWXZlJ )_A.T/9wɘF4B7N*b15YA:^P5j&{LL˅hǥ ''8s 42؆zM1=7<VuNIFuf;GmH]l˻++6j# /tps|̚>;ITְ0RUDHmE6'χ T\F23ăh||ATLw`F43aMOf 7uF47ٔuoY>T@-D{UQY36zlv-/}8vPBW7d\f-F/@1iCe;$2 Cdnu# tGmҞT4+;0V寚AФ(^B6SҝњᏱN:&qlḼ)"Gf!m۔E*R?"ʲMskNxyQenvR01)ã0x SQ] ްEwIY,Rs*6Oآ(*5|)r2TbEq _dv/"VXLj{ ' n>uVLZ_x \Ʉڏig{D(fXm5NZD*.GSӓԙBЅMf>|M cp¹}Z 7egZ~p7h`F{wG1"f g6 x 0svO b彋Gu幄T7߹x'T GC+wߖ0b}8Tdȕ 5lq]΍*WhZ~B<:pr FzWd6oB }"i&8X<.l>ɻC6#i"(B;7;kP 7T4ɵGɦ><Rc/upU s`'PO聏HQ@Jq7̹ > k{mt =J~LwJz:Yo|*$ azڞ̤1f!p 冷>(0o]lmNsƏr%,m #2ߌZ79£o'}}b0?Y#QX@Wn+ē 8NݖA jWS}cs%ᷦ\ zӝ e*aC0%,h_~=} _E:<0.[5%3[+Pک7sh>@4h\Vi&{'kWI)> BrBf=jOن:ȳe@kߵ٘ۨa8\ш-LM xTw!z2[1H#{"JWAt?k~DCW̬mu7Y V{ }Q 0~[~x{Op?N0mx}G>@2:7R1?CH[Ӵp~ThGB›I/[raJ:2 E>/PIɰ9X]f\۲%4ϔ{ϢdJ `^^ʫ5|In*hc %L{#7B"#rj""Z͉EobFŔc ^ѩ=wBǘT|+LV{+:' :noKݏ:e V؁kmr8 _đJ0N/73g,#OH/ U9mhfC{ x)V>Si4 r~'rC"u|8$3n۩H8ƽ.imsOԒ,J [mtzks;t8")@翮B\,O@R0AʺZ_eFL a6C l/4cX6bEr|+ "EU<w%x i?Q# J.heD5*N jptĊjDQ@n8Ad|!YT]xR a xyVkK#UWu`%7NٲIR >G!7?h/YBKzxG[[D3W/1.c]-gXZ!)cT8TxGV"^T/= k+i889xGw`ttO1w($(; ]w/t5ڢ`6x*.?@8х+,ufŝ[C]/V7 ~1*2SMqͺ^̰ "`IM\"*e'DICU(P'Ø tcprDM7({CsR]c2=ib9arP+•2Ug!4}z8``WQڮC_de¥aO n O*IYlβw:Z"ٵ̫(k!MiDzOaszIЦHя63BG/wt"߬C*9Z"gCPk?HH\u*&k"0 uE FXg#/0j>&aj cUq0e$%;3-0ت&4HX+VPMXFM'ߊʣvAUA19Z`[| ޙ7h{fӅCma62x=͠}t =NKUer*ɠaU$i^G8yK̒$پ30jB]Nݒ Ji>8n+_- wg+(l֒acuLb5[z l+>/t+ M?=GL Zto&ogL|7VO)Bj cHPC&)=lph셺"Y`5 %GmJ~ǞaM~N`[b?8L4w;my~3$ax*pwɗ|h{9Y^9d1~=?0NJBՏFg+F$Č3VdxY}>\Ҁ+.=pמn5Eks@*2.̑8SWK/ᨥ!/ą)u,uB E:]B D)K BT6ܥ/ O#a!7/N x8Qһ-O]ee=I۳ݤ&g4"3MIxJEdRS*IMO&@5}1Pf~h7pyVα_FpBvxAt M4ph:6[İ^ C,f7,Cx4B(dH{@M"B}W@6: Jý<~tbSxs^gHxf2Au[??4s[7O~GD!OgS$ lg@Wc|8z,(X+v;~+I7}*f֝& T%'"}AF܈@"qz`̎zC~7Z$n$' '$Ŵʦ K3e|L,ȡq7l'+>VSVǣ|Ǹr0,\C܇Sw$h }+4P$tx[Jxܚ\u+OI݈"AfDoÉu`L[)k!M?v͌Oo=0*1?Qrs'tA9ՌޙhN&pI4|Օƨ˜7V9JǠ}N1l{eJSP3[_٠,{^.V.~U,֩ մB_ԒzGǕ'L6u.j _0Y8%^DZ [V_#*zz"zޤ#E|9у=vJikS=DčȯMOF& H'mU(=骁Mj [4Y<^/MxT71C/ogjafI'?yvSTSR̳ss7]oA=|_=3C&tfBz3nltVy!x0#[:yAK2a$nǤ;YqLjC?v RRta%SD-׺\~@GAzΛp1/N''7R6%YAɾ2ĦY2͍20?]p@D TMZ)^r%[zbN-w+ȍ^5q"sWZ 0{AW~No"{NKxtV/UqP1~n%He&cxT~Q CieO?ܤP>tl,!Q u٣J1,N.$K+hƩv}}`A@70 +ٙ6N^C8縮6 Hd[ŽݼN$!laBTXMz( ]K9Șazگˮq( du1DBx(/V/Fbe^ݙtZ 1A,Oa!6F9Kn2PH} 9BԬ޹٠A>+b}^*._ ة0tAMюI G1'%+xٵ'n}`6e<4*ή H=L_H:ҹ&]HuPѓgd zz9%Vۿ q&R^`(*,Ro&+音UAX53p!=J-{e !<@J~/<`+SK דJyGZ̐bX'vf\xM6xR̴R51O r KLi4LJ cz,IhP_lo{V.\翊B|'>.\NEEmCL>Ҹ *ptheq:g+!O 6:coׂyz)֬hŴΉQ4~:~ POoSzqp_ćg/4b[I,m |$I}KGG~k?kݢNZ@ 3=lRXN{mD ѴD^M& C_wIB掴~ ]ߟ!hX@m81%:@\Z$I86uxDYɁf.Um ^K7}̸aʮiwdl}cFC #'acf*f+SmH*pf%Ԣ9&RM0=;9nIS&.50_Z$F 4 [|f! dwE4:.CiR_m]--pѶr)_N1p6~"{ {c gBLfbt$%sx'qoלܛK:|7|aF&te Kjd6Bi$}䈍W;Wt;{M{g#W9xlqJ %"zeUF9RB k[͇Qq҅t)blZs;LgAhlK3z]q^@w/"5c@V9+xæ4*m!h8'^O#-1ئS;sel@ 8]K!AXOXCA|Ug)k=ԪѪ~xv mD /b$HuiԏI. uyd{Ȯd8IӷR|[:kt#Cf5[[r(NԵ!>CDa֓n}'=f 1!e XEl!H׉{LDO1boVfCYr52F%TS[K61ڮK2e//ObaEKBq^Kivr祈H_޾N|j )$EA"ʼnjY~ -K!ֶq 5c7&%JN ah) w|X@ m@ʫsVjw -bV]^dHIт8>KN8i$hTRjN>'ī%ozN{3U䎫`ʍFY 8Q(F,Cg 㾻L}Z.oRJХS%qɉ$eW߂9 49ᑜ鮆 }F -v?IC=&4潰fW+sHCIhef'Kp-[`/[mS?×,eZN`Wf %H\i)O01p0OW.=X-0C}<<')^2nTxv$n&޽muN[<iNyGiԯ6>ɥ2JȄlyTZ{J)֙eٛWWIicO$&% } 㕎 PݡBbo 9VjUwL@(`?xj͈K8Z s$'Um:|<g l+ Z̭H#= d"n_7}+HvOWȶAD &ٖ,hBzWa5pFgYNgP1˼ 4}HwF]t '4ֹj[$=NQGٮ}ɕt[q0&T6 P=/Qf\U+ ┋dz;%sgMyF,68d5s/2܎hh!mtS<)W߄.gȮ7@eN}5lZtҧ8 e-?•A;d~4WaB?Hia(p%r*N§VhEҫ$SKեEV hD۳8wEو;>w 1 2K_42wԓ _QifLڷQF`fɈ3qsgIrhhͤl;h7m57~ T] eߧ#ԟu$xMPYVҔoCE,{em̄5 fB>PEzݤ+IO{M --Md&l68trl~Mu#Ys֚=&87n{VX8z#vPWMmq/Gl&oe3M76~#@ 8IRU m- ӘdA&rmw?^Aդ+k&L%Mfn}RQ)M<]7k6Z3!޾fD*Sug/'L=zǵ&%ƆiV "TmEce+^X$u p̠~~OKI%q2Np( g4{( ^~Wis0c fd^=S\(|_1a#-WeWCB¹yq N*`Fܲ?zP YA͝[2tVp0}օ!g ~HR&7r2 ^ 1ͽQfA܍1{6ۡP+ۋ l[ l{6fs^Y@b21M/U~ѯLܬL4`ps aYӯb [yk,c¯QʖC0p a`<0_R41Fkh.v]}qvhOkG z̼K㉦1>­Ip rQs`EQU@%&_3l)(jfs< S&F$|)|cKB|GՄyH[m Nljn )мMKB^帺V> H.xo۳➸Q'd wlʰ58ͥȴ ϒAe׍o#(M7i0bZm6f.WBE xyMl8}$#\T4%/ /R)VGq J`2T. u~1=`v:~TZ\B; /}@y#)e  X»}TйEW~LSV Dޜaof1ڤ|mi1#M\nQmNHFCNkZ[ &!䨗 0l}qK`D(wj(B>ePd:İ:,j蒯KiL`.Rn~r=B7PHWd0ؚ=󧴘hUCXāF}G@tܽKyxرlg-0&}M/֥mS."Qz* Ck^8NY2- W̓3 c(^(dr&n {fj"9nc4xi9[$G}xQٲYS17HǓ-_xU8v]E5=szޝjm9 !@(8ᯄe ~ 2͚} l*P uP'rf}Le ą)u !|U=ة=b\mA2̘$.J WkM9 :ae hVp#7G`RPU^ofOӟFo[숄Yx#$R,CHtÖx[P yi"#'ɠcO,pMG>P Lqu2.ps'c*%Y74n4cȢC-3ysd θ,% ѷp.% D>]ksC@&f_`8wTħ);6}yr:~6 &߇vBk7s_ΎWbVyD'ZHG $mИ6:_FL%ƈ%YYzY^(Te)ݞ`Z1{0#PW4G'\o;`NߦG4koR-aU8x N*k5F c E[KrO>.fW-kܼ,c:#4SWl{lk3 V"ϫg߾C?PƠF[|cT±PYJzC^Rb@_SCv΢nۣ^ S0J Ÿ4}֎@ݔ&> + ɃcNXF>oUs{W3hCu#weJdmSxʥ-  l &x;g{AcP( 8 H' folⷻߓ?py3Gi?;GDő&ee5 8CPINB>3r:30W30-KG$ߕތ~IC~dF$D\4H*D/CNl`ho; !p!ԤÅ˔ SZ-(wo/ 6W=5]Y!BP!d]x2բJՅZSQ) "[f2^SLbAp?G2W]4eeJtOXG3@Ջm*Z֨> /[,b_x~kUw~ۢ#&?,aE}e"у1'k]:w<-|MeÞбo4&M=7{% E*""x}I\,}# .gfhyo+~GZXuP{i9V3궵,Pe1R졅l=f71z ΓQ3WcBvk@aN,W0} + CH^R oq\,݃FWf)qp|霶yz8NMd&oщp|ͧS#MO;]rt?.}`;3I>hmfiƖq&{P@{Cւ4v*Z%2k>x7&byJ?)p]V'>{6SG5]E:a:C0 ZNXOY|mv&Xi*#Oj[7%Hh`M\G̃A}RNt/3_` SCЯ@$DU2MsL{ |jC4dE/8%5WuOP`m+@1OEə: YSGG ײcL)U(*Hh|h/n`e”~ҿ/TV45#gk)QE   z#*gj'+Wkt2`U TR,;QkʤYR;ŏŤ_ۆ(kyguD؞ڱorW =rRE9̫C\)MN@CK? )vUnaJ~NȢkP!P(-?_f$ɨ\G;n#Q)ReT 8m?kVPɭsݞt l6RܒC˦z)_f+vOH{͡:6y}R(},PJir;xi EF?6e8 !;1iI PIDŽLFq,\PBdH\zo>s8w ԌsYS1@\'g}5 &$;^Gaifݻ3}{VٯӮ/Hwj1'2.d;5kDcrp,Bx:`7CoBvZu.Ru\`:EwY{@ fCNqY;hi(B>~lgG~ۗ&zrO9>A.v7"Xˎt<`zMXP_yTr4dfF_97i+j둈 )bCb&S5v啭uIM@2|L">yOQ2v'x5Jߐ<` Éupjے!5+H ˀ@+:#%0R֎q7:~x׫3@zXy?^6՛K2;TM5  晊gVyAoFf#DcIKE3ʳ-=\Mwc|ܝ&j%.;\>F&/ȒNLcwDdzs3B>-јcmH10o:Ɣ_b}>،#[/[ʥ =S43f8x:bE%2]͍Ņzy7gΰ(k.1:"ԫ8!}O}qbϑ>` ¿M,APn[]TJy68=iGF!c:`=4ЫFu&amuu%LɿNWq)m8`Z @dӰlxqD։g2£CEVNFiߓL+GSaC HVS- d{ʲ;&lNL~P!60']gr^0__AJ/dRvQ Q \EސⴸbUx1jIg"cr?SpR(̝hRΤBf[oX쪕7/~Ν9܎}y=๦1͗7LG!T@\aqޢ|ߐp[B0'ev`aCljBؐ(İKh?az|DЭ[OKW aU4G8X{q$}(T~1jSAo po"ntֳ-L{l+qR/"4:݈(rjxv^%.bG S")Y ?uIvhw7ұN]^\dC]p”;djj&nw'IlYbSP:)+|),.>k^u˄z_}my܌SIҴe7+fDЦ \8x"mJlQ1%#<-8Dx9nSSHru9 Yv1@F[V$$ajߛ4\}f82PdHV *Ug5Ö}רjh`o8x/S\791JL+E% .!n0Y'2b`T^F7Ijƒ5)P6jn ҰFاGȫRE}Ey : 3uT;07;ư|idѻkJmwxÎ)+Ttj\( j85)-O XXzTF hF +y`Ge4]sʽ=`I܎xOaO>Y #!.mwgz6NXYwQ[WIҮ|b#[tREm٭E`i_g ہ.f$\4Qa='B<@(-Hh~-&R"V tUù{jHzEXYȡV]t" 8y,)ض52,)Dn6F|j"M86τ)8e-_U:ӷЦPOt

    }WKA_ Cy]v.['DDERgV+ib[]jHBտ񐜔yZȜ\v<9W$uXTYYcGYnYoNZj/g+ȉ0_sL)WUZ(:|,[>e75VC5>Ј>!xk\ Wt53%^ f*wj`Z} xI-#9ZUpJN!Őn'36UXwL>]67 8둂$lJ~uE㬠T\CI%. m{@)O%#ԥ}peO*t^Cpo|ؓ*ZC%?>bx~FI VsHBaڏst>rТ]++(ڎ33ZvAJTfl,S50"|XFhDm+u 0_DgU2~*i2\41*-ܲб7dW5 IDIu&6QM `<(8*Pn%8-tTLv[lo D1>+:uY_1S 8ܵ; \Zv( TA,b .)ٔ9j| 6 Anda0kJf߰ u~VW 挹!*2rC,9&#H)E>9* |1(a}|W+XMs kUl>=}Xf{} #ω PdZ9ҳBD5KZЫ|1OM&3)m?Zɟɔbi#*"Z`nac3 tDTK*J#cn2ڰ3T1'(L>Vr<pR['b4ڸꝿβ4za<-D~ 2$gQU>,PY&ώ56LbAF;[e\n(q /8Briː R=Βb}~c rm]<8s8*iC& tv_[\6P3q& =LO"qrT@_5} >w$"rE&'޾gP{Z%ꉾ)uA{p3*s!V:0t8}\ԭ* BHWvm 4w_f(wEYw Ol003jcҩ$ GkZKjSZ3zRS(%e[m-$OCXL|@ff58,a^ Le߰C\%Jؿ ɩB+omYarV|CQ'=OȔJFd%b_03}(ڙC=7+fa+ [|m7dSg^MVu"ȃsFc9>Q)Cye\4ީ/!618?,HOU&6G>x=Czn5O/UQ*Ewyd^J#p ̫>@^!3Ti 14Ce0C_JR%D֨x&(Q G0v{j /䑜Fi?1\R궫qzu{[1QL[.k `-lS[eeIޚۨ_ٛt'廫;6qd]9< M2CncqӃYR\d*J_Q§`Fy|Qwm͸?v|k.SCfh[3Gt=c9p8@5QIO4LD>_󨝲JI4 fuv BgAffb#{7BP9BJ(U&e=]NtCN$ruwHh֩y&t0- bm/掅yߗM$xp0<,MAzs'1 jE D23?Ᏻ'ќDgGٺVl0<XQ Bc+5'xI2Ad'4W:( %3]vL*Ĥqhfߝ7;(9 ;5ĩeIVDz9 3b4pm݇¦{,Uҳ{$Ve,ݮ;tو..hY [f&}XG I&%jSxL17aڧpo <)T :">1!GoZ䞸rwjWMg]g5SJCD#g󂖆갔.1ջ8e@_B,K.`-4*䇗V {-NAe&m A)M'Ww`P43!BVB A]W/"*b_nO "~&o&j,|O7%WU#+m~oVxS(1J{r^0ں'd&۶&2QR/ഡK_#s70&{/?Nv&;N)+( W]U-xM;PjW왫[(;]8-"/Att=&w(JA ~ IyVl][(^qm'>fH\vmPcbv}WX5? Ӻse[ {&YwrԸt,G'˥O܇ ExK >:svro61%z|`4 TV /):sn{ަ&,sSws[*l͇}),H -Y;ch xx=gx_&B98&C}׺ ,%ۭDt*pb)N@VE$EY|rZIS.b^& g:&a#q-= ~<^,tLf/6,m!峈 X$Q}h'XF D `}6 =Yo"LAW0KZ R21i.D lڀ5Yiﴺz˒1 ==Rs=t.çQ\2}n FCftYͮ*;y6.b9&oj%[9*836-[҅X?Bfƀ>C~^"j EstM_Nh%SpU$BL;mB]ABlT\+ Ca3bLNJ:kcgƁ\?D[ Imx\փ* 4[ͯ(rouf)&@akĴ.֭&Z[to$=ޮɘh =@+\" %3pZx ݘ"Nh zLs2oSF4#=JTu?~Xjv~^v5%-#$7бH Yq7_ )RċN;J}ir!mB ȅwDXY9XJ9(I̩|=ͭZg o0S>œwWރGu l>6d:xy^`пen7I~@1&mO?Xn0`] "]OUo4AG5}fEӚ_~(Ѥ qdٺt@Ui M#ޏ[]'"THY>C"ǞD;mEk-k™\c.h'WXZz,@J~"qќ†Ѿ-g&cNl""] 63j\ =>l8Aa|k 2%- \և̓p{T'v!4bvnDNظꆮ,pd|o+ "!i>St-{fQ1O D$7?am:E)h0g^1ip<}A3JכYJj*'CO"4Oc/XrIք;)oU,B|j/w."EM=T~/-Z(h_a &7 ƤZE=3jf<aTM͍N摕E6P@VV@*&l~+̆N|m T@,;MH4:J6?@ZNGblrR0YѸW.->?-[2vLeuȿcc>pJ`+Q#Y5B-cfWVO+7}Fx!}`FyBlmy>(*`4ttbĹ]467fGjrҩ>sqfU[x:BJ3/AY!%L襇@8\6kUbL6Zg)e)b^\ݽ^; τᡸwPjL|KC8 C@ G]7uHK,4U]Ɯ8 FI9l:,/ę]ɒcۋW~}krd}J}\4Vob'hdtq\ y~yoyGy* hT峉nO2#Eһ8_*adk9O0 ܪ7o>WO6cN0`$h/8}"6w <)H=;CF~5uA&jwA,Vծh՝Na" 0˄Rg>{/R{4M]b jWP3h5O\]+3@ h.|E=B z~`#Qy,Ǵ}qa+xYƬ+Vll] HW֑'@byl܍YcPW8Gc=%7܄ nF?+s=Ƶj?nsydGILeB?Y:A;-JwPd?u28O?cJg,UINrb7t04#C)AJRӹ5PvFNE;ە߹zg9lo6]Q;D' 9JXid%ڥQίY]M?d`ffW:1g=9+ȝ(ps1N Ǻxl7ĕE⠔A[9\ƭûgӰԤ\Kxf jɲꃧU$z~uf߿@*.JKQ9,px8{O_!+y4-@Z/@ J(;R\M @NXIT;z=7]w[ #߬R^4Cӽ}VVM%!;.|H!an_lWOS#>[ѬvRʈ0lރ$$"^a|V ~u3ԫͼ-) K>y#W%'Kg-O;!Eyְ'^Cc/iJ֤Y`x1*UѸמ6G@3,o3pߦZG3iqJ|`2n\3q?Lb*ɵ*K"gߣ8r|SfXDoAcߗE0x贚z-jNj6!C)OƚP!]n2߅2F\LnqpKbФ|F_Z5Eg~ƘMgWYIKF 8՞DۇbAQfZN]NX8 î.PBml4fϝe nEwZT;vck,/ih>^a,4_m_f9E6ϿE^<4'S@ޜ~qpΨ@%b ^ rk ,c0ݤb#0zק19ܭK})c>Q[9\!w50@I\X;Un~OXI ?K`I !eS1wL~5 Aߎ2{ߦ{(seۤz0lD>-lwo#[D}m߀=O{7!mJ`Mno6]ab"~Sґ#Wu0a q+Pzl*G(}Q톷Mq H9bFu)DTX[5\ze[F52`=) y^`O`vWVHv8J;!l}}?@jiE]Dz83sAaoW bQr _)T,逯ݭU'4MY@SwZ X~[sr.29! x_3#MG@,m2â^| xj1vRܖX\vF`3$!@bU5 R ,#?Uʏۻh kQHl/$ɁfI*0E#P;cNc/A:5.j7(D$ bQ{2 V kⱍ@e@A Sb*Ʒp(x6QG6#SMZkUTR!BQ0s0<4}<4 y<-A_Co҆:Pˠ%elJR[BeJg5E5K;Y Z|sTAB 8(薬b@֬j f"b˗́69s~薵n qJM`jsp<W(:%ZԹ*—-Q aLmKp\vc wE96ӾvՃ^wkxuU;j\vPs~R? d^NzKN=qq:T/a"o9JIY'F52JpbO-)d, @[cMIUM6U7IJeWVnQn `~nNz5<Zy"яUvo7~uG~ʶ\A$;Iꎗr㉠zYd!y!(ZeO O^\׸^)R3: .uMe&JG" HIYFl vPy%}Z(.>qf4p}n;- kJD8 ?);6^'1CwɄ1sRy-׹#0 0J GOpDgjz\[uIE'9{10 r{GOYϛe0|afG " Pʀq(CUF6AbUO;uj925~BYx+`}Ke0DN:w'EJN|9wBf{UY˻>V+| p(#Sߧde RȤrbB(Gҏ BtVbm n1 [ry侐5?7$o@L_[v0p‹o*<+۔Lxմ@2Iw 'I'Z@?I:-:4埢z;;iovˇL3BPw<ÔIĿM$DKj_6N]C&$ISL1j>@.0hxHAjyչI` K Z_0gs.t1GZ%͂/s/L#:3?FPqo\*KKn҄y3D Sb]R1٫=FMEwOM16 Ul7雷H3/"QKѪ"p.̠^FY*%'՛kGF)$ϠG$-Uw.VoR-RAVG"$S.oB\(I@F;گE ֓KQsQC1 E5yק5S"Xw/WȄ]n' `_xK9UVfY9 oWrJeXkpɁE̦? `{ /FKu{T# !.:*1F/T%{]8GD2G/J87g\*B\AOђjW .Y@uS'OwDF1RI3?}*y?C]F})ɚ"fj[+y }D,GCC Oߓ=/nPu@^aAÄr Vk V1 c_@&BKZr[}{7/wN.gQr%8A%Z{Mz]=ᕁPG˚,Iif0"vf-mL1$mRօ WwK%jtЖǭ'+خpPۑr☸ x`BZz(z.s9 @ H^fe 7)d^_L3R! |"i8Mi?5>rQf}Yu.ǯ|?lmS: -s)\)-7<~ d.yZ (#W\6taQa ^:F||B>-*їzCis7blq壬s"CLH/PyIGaSwbpA{/NGL=8Hz *Tveay΀ZU>vT!S%"O #2h ZQ5uIOlwN/7b^'/t/a7zPmTlj)Rt!|0=7"u0nSq8ߴUlbd01,i]t ,4nK`L .Rs&[T xH3A ѧW!uE"4u 4Y9W+6v3c8!UMШ?WwrbOS=*XQ֕qHX \}$5 d_=lt">&Xo ˉ[e۪.ͬ}]pu`a}2ϐRԍ8~%%̍{BPx@"/LASvDU_,l7'b.HiL6t=KV@Hgbgp",]RzSw@mg !`݉cXY)(y5)1ao`!02NTe ؿ~]ȟS&jB_piU"?qλknI7P &Լk(ɃuZ:K3ieLBjX$݇ݧFsFpfVSRvN ܸ7F,L3a_(C | }Y=ѕ 61BĀ X5 ˥D?fUgrgøoȡ&%:<sJ 4*N:_ +Àe{  rh{ԑī ;`˪?8t&R1Ф$|swͱbKb\E)Sb {$y0ʖf|M&[Uˠ* B]U',ݛgshc9>4/ihԞ_GMDfD$׭g&{\6Eʧj.Y17$s&A)~As$ɢ83[i%-ڍwi\tɸ}{<rr%ʹ% Vtfԑ귬sox.` J;AxÛh}e4f9@7)wl魷P&ԿպaHB맱uLꪧqRFqCH_[v&9.>o+6[H'dL.c^`KVd aCRJ"8{n㒵 `I}[vvɶ@z`)yѲ 8U4Y"+OrYTl(q񲘞]2k}p1yѼ:?W7Mf s}Ӓ9*,JWc q_wOJCrl6$EdٞE<=;#* 8HgH0]0/5?ԣ~~/%$cS }Kw#J,2 JJLo=qStpHBJl][Q)m[Q%^P },H#k>7e_daЩ|e4NxK ѻJn 6nyu7FV=LLX"2jb"Ip[VZ[%`;qn}JG*;ݡ+lxr!SCs;x=-$gjHPZ? G·O 4fKJ%o1Ov{UwSX/gJe%"E.\Ӂk#,mkXiLPns´X '>DW.g==[G:톋HIUlHqAa c֐ܙI*Ҹ(o!LseҖx,+u!qӭ4@=M 2Y[|SVnX+r[Sş9Ob#8!TDbP <>*yjj+a[MOq6&Ijkf3+5%BCk(kp+3n64/oN 6KE0BS )&n4T'Y'jEqn@S˦k)ܾ^L#9ôI ә@$.b!_6p')\Ylᔁm$E⡦rc87@|d&isBt9%bT<+wJKj$h@Ѭ,|3jhҴwtuQ>g9IŠWioZ"7P={W48H5]blؽoiadm!XG0=Mc!_0Jb9቙-`lݞ,!6JS!NHpBq1[3?Ԟn>n:+9G| #5] bz3&!F{bb t! :*/KlQZJXbVxUb~tXJc(3FÜ7ci˘u# :`w^rӀ6xx\Y*BepUIwae,yj/~8,\ E@sEZD!'"e%? fEPL-]x#k]@1bbCOQ#[Q> xl'qt~kS\rYŀ<0P- 49jULtڒKYtļJ7$/[ۜO:k/qLvG)JO[g˧M&jS:W i cN=>Χ`bN{r1LuzFB'B*R<4wεU %=W =uAʻi{_~F="G75긬Xxݭ !1r!k1-n&j'¸ -JM\0v =qh}62ֿIGƋH:\Yhy+umƹ?[pph`SWSOI|nƾnS4[ f[A7vhHSp {e?};V =_g O8JY1BʋFXZqDKb1'y1'ku LV0PccJF7Ӯ~qorWWD໽Z2#M,`}ǃPK 8 ]>rْk"*5qGk 9p;N.$,DqhQ|@ y6\5N. l9DWɞ4DJ7N@Ǡst]*!#U4uXKDV<9$ f.4w(.2&ɼo*0D\řC5CN`:*Xz0> ڢM+a819580L-9ewT';zQz[鋷>+8sD[ϖ ?ۓ~#o r]"ByfJڎDlt:o <־E?~i{)vLPb Lbe6's\$366$GGWfɕJ@oƺ:e W'o0: E)94 %e qSK)(e'ÜٯlvYAJ>&+ɇO5׋3+>9GCm",AJC XG?MEXe 3-WY㯒ї~]y"1"-8~U!X<) :D9MT CH.d\\5!EpK╭43c]*oMQqWfP.Yi4$_ATv (w']gly` *.pDW#0sT>řwy tF){ĕa53|Bld0T֩AuNJ% ᣢJoXuU;ș3 +Rx!@<~*3153=dwp=}47ʠh c[/jnA;"c-GX5}>@Dz~j-H+ͱӉ!EXs(/*#P "ϖR)UNBܼ{?8>c?0[sIoXJM%\xVߕQSKf#́&=@ʏ?0stH2!pJH$ wPR;`δ&&1}_޾Xj_ sJj`EZ*oӄ7@tcZС.dm֦,ׄj twl t(]4_g"YwHE+>^Ȕ&[ dzbvTF[(yhM͇6+w[TYk`fm *&.ECT]T!5O=V5в_D/̽4&)b*j ~Bc 1㲃+4EzFضf3[(~0F՟.9puG\悐^AxnMNK-wu[<u"/:T,7Hܜ[j-g 5q\7En:"}Ō,n7|Ճ ھ{2J|jRQZM.)-W!( Dvi XbŃف5gv\`ؒP1~i` kjg<3!Keq`J3:CmKf82^}l^-jMr2rix#n%pC8L'xU[=\=l2H2<`@A>s<UʪtY#tP.҅2n9KZfSRCh/hqaBߔv,~kKN2响DOoFcY@#2[PT3ȫJy &ƬHi ymN {&hwH zD~ݐ7Jbg˨s7»/0ۗtfNTTg$EXtN+~P}= &)`e|xY6aS4H&qD,Ulks`nNBF'Ֆ-. ZW7mGr 9 Fz7 -8+sM6`S5_ϹHҳ+mN0(^NyϮBl>T۔$$hOT\!0[<+r@ш wPosNMãhv\:]ާ53p?O@ho.aOy0q@J-ّwəvXweeWNC%O雙$[ " :پ3B-&pc`&ǜJ>9B8h@xK8TTtQn~Po)Æ'Z;9rNquaoJrO2Xg,sdGS7ᶁ-/x%k7jib,J 7PrK#[[:j 9O1LR0\?_df1Ĭ)EӃS]JUj|\lkD&ǚhHyWqP/Lbs)9rNyW ExsNRyAtJhz`DJ&X+)`8FKpn,W9-4lCw&^!ħDhZu3_a*( d$*館߫odlb-^f {]1yJ(3:!02#K/\ճ j ڜd[/'v9;wQyEMSݴ_WJwqN^x(~$%& 2bjD-nAI,pa7eG1Gת *1 B[[;i-DT(N0mH $FQ.,$k;WF-14Nv[ ίs˯-vZŔ|a]lq{~ y3 1gj?C>Q+1uo^Suvb_!Mf-]?`5Eyֺ\!%p 5v[}\%O9=)Bk kopaR9> ֝vv7LǍB1ɣd~ܠ#3oBV<*wVb-;{(ߜw2 nĨˢn8Lg`4K$hy,Qߜ9-Mar{c/c~7łE|o0U\efgh>l=ϖ)xoޫtkp;sLWTb&u(Ô+9H.LAFj+꧛qԼ?0b;H:V JJC;Hn w(Ȯ&5JժrHLz1ջ0Ih; t^PF4%8|2v4 b/j!Es'#ȪaB9&=kRo,MGpL _Ҥ!U?av50¹4ET)?MCbz1E[59+K}e #\Uw զEg [s~bd zvѶaD%G%l[l9t' KxՀzKBsFGؼI"w%.Fw6kEg'k7Ljkv>Sqg^bQ٥,L!sP 0Uσ(eU L1+oG:PhiF b3G;˻}q=~\V%R-$W4\;G;p˱'\7 V當 429[M5\/ GR>Ǔ$ұUC&9ye”ÆRY@Z'u$I M;; G-&M@{ZUXA$#aɞ֍ڞ^z$"Zގ_CvS#hY3WI\v{lg\v9'YG*b6Kfd(\D ߟFҴS؈}M|A_0F9Q4z~\02F`-B6Ƿ%M0IҨ<8& n>2nQ lY3qfq k*rVoftm|x&v2~wtl76x/:V.jR#-/T: d>?~,?;(A9Fû8{fZi) v X/pE(F3u?\ɻ2,7n _G1kF$WBš5DBMʍ"vOqh\U )IIwZ8ŐKמmH׽/l "E@q2>dM ~XbeBΖtq;Ea-ؗ`ԵҢƍRe0Ըqrə G0өJSջX -&?WI1KHW.?/$UG(U->+teИ>^ (w8L)eB 'j= !gĐBe*np&k8/6 : i\eI͓cpN4{cY _q6l%?L+m?%G֌ݔT^n y|)g *XF]GbԤfp^S~F}/=jʮ(Aeû@l5DwY+^ )铏KXqYjF" g($w"u﷚E^%179Sa=z#+v /`hRɼ\B^JfI5u Z1goX|pB|#ĠNRGS`AOSѩ!ˏ֎Q`m&]7xoO,u(ۛ>^1I&;a!*|yR.w޲]fEԹ0`XƒfCzϬj.e!w%n z?!UJ:o1S3Lgk8įel@oG-Lܫ2g6(6^6]77g 84/ס˙"Ae1bGO 8AJ%ٯ^a/M+."K*ɬ/1wMO3@5?Ny⇬{^ T)S2;1P/w(Bk!@]=ƇΓV7" 9V6ޑ̀Ƿ=Q.T VhLđ*hS J u7*F7 HJ{D2޶(=Ԓ#Nd^bHèwՎPa~5lN8!Q!F8B~8d khT$y *JA@%+MH-[xC0.)Bdaې:p%k3ӾnBI8/:PdͧML׍Y m~f:B8W EM<ڋX];KxQ1[_yك: ~14$-U<6hKIIvfwx Ϛ-E-U&CKNp2u" ]mL(urlx9XHtxxB2;L,Nr9OmU#DXVn')ֶ\HYp 8 ~2yOEƅW=HhIfjPDU2]T]y^Q %5)@59EK" FyЋۗw⭤: S3rtjx/i,!Q0$*rb n`.f)gmLw# _yy(p=/- WJl`{.jNXPP=E!ǯGB ؍p&m x&NwČdoqpE4^k6N-_uX?IqzJo> @[(-)Xp~ o Y)oJkO;}~S]ƈ6ZJs )T@gyis5A!HM`^]ж,#}0b7 qD}&Ohò; dgn_1I3kF_}jϲ2:FqhqLC{V"Dp":nPv9XL .xmZC _{ѓ/ Ue hoS*IbK[>,ɲ<%\@=`Dr!g*J-$h:,Imn:uۡ\C[ջ lw(Q1˸4[OY T`~S!#B}_);{ue@[hn*m[U0:mՐ%^9pSjC"VRDL)t5IǧA7FA!Bwo1ͬ/2MKB]FnI$рtuک:NAdujҟ\8%P"2epc`sp%^ 8`&V=I[~,lʏ^~FlLH|4G;<;:[(,v#':CZ e/Mيcn;&?)R5W -P[w\}['}L`mwT_D{ӿGt]C6IVCጢμ*}LSL?Q\fn?)"d02I~Iy8FA`3`G_H:l>gSŽ"}K_48%Ku ƓhB+Qڇ^TelN-M ǟyᇫϻ4)Oa^%iU׍%Um-Be=9'W`zs`fra($-n"WW3 Q+? sQf3P 7 s;6 E %`(ksR-A<&riU}2Ȳ a{2!h9nf3ݒiL*>Ҵ|:4n2\Nׇ~ՠ{ qVCIH-!ޅ?O"/+1ӆ$3Xne@sWqyc(D򯊴|#&}53|sjz7͑k{ 8HOo9)N_ !po%ssTTcl ;E,i{¶#̐|`s!WoŽ^vG!>""LMdI!ɳc0 y7R-H,'~yFe@]Af¡~~icf" Y^] ~7SzX`PTDC="d~m94e`CmP`l $GDIdS>afSJ&5V4 = 4c~֙>k rE `D3vCP~ su:,Xޅ/⤖k;2x@qZu8S5ųa l8G96'1EpvݦYmGa{[< xr Kn)J!$Q  şS ™ƾo(jm7@a}H"0# 5](dTW,JS7jBXG>"YN Ht5ݜڄ&w Q>/bB՞z=.nazːF O.ێ)AlFh">SFK[n_`Uy1Ms؇D .?1YJg.]F)Վ/CPߓ |tcCV aE}ߤX]Lܿ/j͋''cQ=2܂~M[KȾbmA-kӛ H~DWWHlBt~)V=W#I+&Գ[+ b6+D27}oOIKTmՋ}'1֓&I+ ?yB 9Myu,|gfD P*1 _ FhJ޹KUgAXY1RwC}+%,YkEz5fǢeuٮ}6;#ݍM?U_7\xm"f 7f ("Mo\g|e"eaDȼ_.}ȍ|^?YmƔd[1/,m褐,uTr5A0!xZp^|5l5.s*yGa!\"Ay`(s.~m7 ia~x|sD Ź۝&5>߯"h$g 5Ӊhh,6қ%*^B &)G+ ^'ޢY"f xAH_Q:ej\B`DAO2;jԇ-a8!R 2@jDD <1Hk Gn♟ԛ|eq/8ì#¿PY2j&R/WWDn{.VKڌ/)+9/A3L#>64eM:QP>,R+:^PwbFd;zib!Q[C-BD&V)! {#VGȻح2KOXvD2J3uC0tllҽ+ J~Q{`z;R:w^@!ے.݃S+aTLV ?lXӷ"w<W{#ePl1;/ D~>~W7j}k<5ƒoosHX8# ]*{7R;M"~J}P w WeNn g|{0Xyf/)Sx1zr8Rx^X8M8*?D#2uKr&1^"zje#W+BL( 7gaX0oҪsr{h %e-LLu:Uwl=D P@t4Z6xVOU&rl#c&i{G"?kl'[_.L:p]b;]Aòߦ~Rq0#iQfP>|;y3m4[L}6ƨM1jf_n#X2&nx6[8ȮSXEFBvf$q!oJOnRWfo^z'o[fnF.F `-}JnoNnʓV/!BΩƠUG+ H>fSo>0139@ u䅓@0݁Iu[^[|Z }U?bոsBդn>F[9gK*670PP$tCufmb?d!A1H͡G' 懭'u:LfAa1Je .h1ڵu9QM6끡Glsr; WLfik!0f4͎97}sfƗb=}XU ~@*T9$77M{[53nw]H{JICm'B Ѓel9g -$'=tY1g,-=GfR2BӖi=WFG% 1} |H4 [<^ɵh=eR sCirâzIyYpB}t*|0j7ڰ>BW*94'Ui KI·M7NX{bVXZ."3Po%ܫ^Y5"KǼ!PɈ`\ӇD upFahbB$`\תdxc>%k34a\$V1<̟p6 ::-djW}|'p)x: bg5GsT <$qkA}a[ULaÝjʟ @Yk^]I"CJ ok[}#J`{@Ŷ0į(A)?iQqt6HaFBjvH-hI RZLmluqnjFE|ι19d۳jt$.+ **’o'L |r7籜U,o sz K^(]z˄!oJ3>jϕ]"k<c^ `@b0TQb~uFj8?IbJO9TMi gz#`B倜{:W ġ=yt{jd[\"+^TT>FOY:>Ab]{2)7J˔܉3p濳37K9+h!ge5QR|c{}gC~IW]˽MYJ/t0f%KͷP $ymN|rAJկpc‹X' AyhOdBS~"wCX骁< 缊?'!Jfr֭~Y EFNZ&m]0s5]G`FF(Bu7ж,u.<堣RQ6Rl>>7:~~O[ivxJ&db& A `}GeUUy]k Xdоn䒺Ӻ!.uآ4^Pau5vl?1i"pRx؄|q7x!XL^U"kASX9Iאg;![NZVc)#ԯ1XN.!_fGp쒕fATβ ޘGi2 1~$\=TD(5߉bsI`IiE^yotNE_Ms&R2oJg&n?KFzFzZɩKw`*[W<̤A9G^ru ?DX ݾSAL4BGC{CU@o)KrifD E[֏NVuz~ۺ_@HޙPSo)áoL<8=Q Vbj#Y\ ӀSub2ӊcٶb>(n4Fҗq(e!yؔfQIkִq/:'ߵfQPG/t ]O= TlPjU+&]nZE- y~cH8.Ez(hh'Z/ycvK!:>,F^Wr-#^ "\f3ʊRt&Q=oG6u<VD拏,zĦ7Ӓh0|Ic(bݲ<'ZE:}o 8xlk$4#׳۳))(8IU *Puzc{oZ-a+b8RNjY]sU slBw*O"[@2ibVu| pwFsqyߤZ^C&0k磓 ;tagJcBt: drfR2q57FW 0|a]GVqE-aԦk/!G&Kɳ :c-ӕINEQ?&-.h`e5=SNxrMֿ?lLH,^ !G1p`{dbصVy"nlR *cnd+W׈c"Xj5zo^ͯz-݊Bb#Ty yi/NցIlFt)h[I0OTXIU]l{5nرE*^ \1ZFVjX}T4SparG;^;ZA@*fa',sط|mOBAڬ-Jʟww=ivlH\&PSo0}Nvhy: {ԱD8ʼ1 s Cr%0NϵنхmŜ߄Mh=#pe ^n๑<<Z[ݪ2 @f˨62 w yي8hc+!D۪ #Q\ mr˅})Bf`}G1>)9@:x`ZkZŁɫjvAH%@5&CS)TM_2LN #6@ɀlܮsH5d )XLia&r3;>ۆ,lcD2ex hP'aK:޵)󉿳c[m!P@GZDќyѽ%պDpӡYssKBG*"1`(w{,e837tJEw`ϯ{Kl#Y?tVP֊UNğբ|_MO.0Xиp ߦ]j ylnW0 \EmzCsKm>X1u5t^ΟnϒYn6ϺWg2SSCXjR_qAЌg~:^@z@~wز(5_/cd .n; W@Mq7R`K*eS?,#Ƭ2+j1GN y$w8+۞-imѡP40gcq]@Td(ãsh-0I^/rVOud#z{ŃM%)vxxi rJm. *m:9D7,4&9U6L`kw;z"j%#Brf0V9U!JMt|Ok4@I\_'=Uk>o'.IꭆO{EycXC <Wj^z2 pN+)'GegGwD.FpuU^ 1OS /,b{|C5w_$)iVю@ʗeTG9\FqkФ5v?F#9idSNbBp77j'n(>UiÔl2 4d 8Y,'Tt;\q=eT疑UgRDG7cHA5QX'z j~|6Ȧ~> ' Y(J蹠퉎"tբ E D2cJH}zknUC}pj%tU&iY/m.HFl#1@̛6S?kXy p˥o >dǫ4w!v,?k&,5YaQ?lqCr{~̟k7y\ph c# O zXp32 0jUFd&N%V~:c%(<}pıU U45!:Db$_M(K3LJI'Iȕq3dQ(>q6?%$*Wܥk8C +Fٽ^7 @.ܥ{B'thrtLysRZW%Ըk0-Pף޳d:癆=mkT!Fl"id$*!nl;bԢ%1O_@h7a6ހJz1TDu@\;_V >ŚWH([Or2PgURw$;h l;:Z-WO t QH Na&8 \Q&b@<131sz\%UU1^RGd5_1j" ÆD7zuDı\6)%eЗ2(rX8(4 ,eP" ؂AvW$3dp<2lL~1oZPXR, MJ/\ȌWW0tlwdYDݿo%f[:z4uW.r:IC/fpHTR7geI-ޒ15Zmwq: ?wj?f8, x8,d-̗j\y6 >иvA?,d#V-e7G#3RY [z&6djU'*YP~kP9 &٠4;0ʀ5xG }Q,Ӿx@wFMtVb)3N_=fjsr  O|kkq3okWV3;IO]`ieYו,+hyش8(꼼 Pގ={@`FnEP_j'8<]+6"&-I=bs|W󡱪|?{,8_UX )mQ92u6w˜ddܶwSVX]J#CMRBdHx~<4`QFd G"׷*E !o߫oוA #_(z~ K鬃:^*z,_ =V~G^0_V03mfi3C)\Y (pİ_S J=qNLGPaL).P7[r17rB.YIf+ܒ[EV(IQ06<ŧ!^}@m!xyQ(*dUd= \pny nFj4$ldiSY4Y005v :r&RXaem见|t:8WxցaN|hZy*9>pSt;"/J퐻&V+e3" \CjrMp w쨵NBg2bɜ_SsVElʹQ~1 7r~hG7*>S3ˋ K?V">}+;='yk.' "WQ~J Gu) ^c{dEe7kXø9a)/{jAw1_ E߅ D"Kb_+?-vy`) ֠ cI{cA,VmoSzlΊGFFc(C+WIһCn$*3[T<mջe' y՘;D:R+}o$c $=ʍNݾ`jeOX>3p%(\hL69jY^8cT.jmvHQ.&0,Hc;h!PvWŶqp.4 (\+N7yj3K:[f$FF6|1@L"pKbo Y}rqFp6UgmG x 9aHCKVVɍjBcnpor!H"be& iʗ 淺$R%*whJSG=(=+IBY>P.mvF|X㦅t;񚔒 Z=mI?/3;5m|&Wnn'_%21!;3̧69b8>+dRlsŋCein;ue Z??qqŏ~ǿ a3u2>ŗW5wnzН4\հU":ЭhZxWegrK,0HKfl^;_ XUL p`+&FWd'Wѓᰀ:& RB-1%؀"=2&v+dHiTTm~Cxlr#ZsM5ie=}6cs PfQۗ(Yk R 6c Z"&)Ai %R֔Z)fQr^k"ĜfYas;Ը 8?]B9n(y 'O rp(j*KƮ%?0l_Ei){dyfsJK-&]kba]YWgsD!KzG3Rū)\U#@" Raش+)jWPB}.O$P4vLMeP,b ?I0YL+?0s^C)A*vu$\9z߶sPmBX  >x"PZZ<9"^2q,4]# `˃Xo`H',~%ǎxreW1ؾĩ}kq 0QP']A66ܶ K.Z9#*4]uȽ GVC!j$,;Ӡb82eU"XR㐴Y񿬡ikMc/9jP:dՓ ̻vᲯ7>]u=nXƭ1 i ^JvYufagEdKxdI@l1sHN6=a8;M<+cf+Iqr 6 qDc܋ z3yVls)_=Ed\zwĖӼ: N 8 %"DT^[qW-!j>8Ʃ3tBEbG7,QHe1S@|3^ M<[ $l "Y!N18D_[oYݧD][e a s{(G"W8`)󝫵RM,"}$9ƛt$WFPSi599MqِXH cyX&YK!sD2漍gVװgNB }@*T- fs+9K:=.f^>N6C:;IBMTY> )Nļ.ʻV6(qk-g]x=. \#f&|\j yK9F0_G8uq^ "`s=5e}Q>VOG=}4L<HVRn<3!}i 8d x4cV]ˊGNڧ)M(]k0 ݀%-Gd5gZԼFOc2*&1';cmYWt8CO@0K-w(1#vLG?LO+G歀%C* !ެX*i(fuDWBU  A~ZhCiaz6eKc-SL{WfseUP7rҔ22),mˉ Co^WNaH E@}8LmKaY/>$&҈aO2I]7.4̲mEXv*7\I9:za,k22WɘmR|!UbIhduB QtqED[oHR!N]ʷ7L1z$zLM7@ti2en|d#}QQCO ^/HC5\'Uq|k3ZӨ /M$Lوzxj˫#b&b<07}!1<̥_MH)5XyasS{KBVyeuѝG,dT93;[+1'y7 Xa03Vҵ7T 5^1I>~# q#8ؙ͉RTcd"42VxOJp!: ~WhY6&;Z{obƟ#zz"fI5د{ki^@|2LK/]*Zm.hh9tQc߼F#7%qn~Ʋ@6Jo;ӛ1T%t[ C%O_32t!2*NG!YP63MM !*W;꼷#c\?br{6߻x'sUѭRnr<>L1bWz0-N&Q5#@kd]52VʼFo#CM ODdc~ A]"n%i)%Jr[oD.2sT¦,+w\Cֺ EؚBu8C~(nd] "uu 6_WBNG~` \T.#Kp"3"iLc$A/U\s^!_z|c"NyZKX0fstcA2QD\;((&3VJx2Un8!M\7D}xQnOx zQɟ5$/}J?1B7 v{ctD9^=z%8DZ&%U!I]j /os^\p+oVNPمy*MZ=={j#_f1^Qo'eѫ7zx^3ޣ=̅9Ӯf,Ì> qCpA'Q>Q׏s"eTaV.aHUW~rQ'MQߵf\Uw&),e'A2Lиꮿ5E \!6$9A4;}_xUSzv 8"6"^'*BSťFG`I{ UJ'iCDyP6.=t gTz1ؖ"3 2l;׸l؊ʷuAƨTfHbaoD-Ufa/ɁGOo6cl@-'F"N r-bT`ɲe[M`aSG1)zƤD*eyCRP/4#/C<N.VT` :q]Q"^‚XWYzCb4-^B5 7SS.*K}U\ۻr&/fbNş5+.=[qH-j Q*e~ l[lcX;mЁS>>SPaO,ө4H2[Lo`ń}B 0\iӹQ7'd09>7.:y}rÔ16R?[2`I؜ڨ jI)  ɀ4SDrSzӭ C1U4f|/\/gᠥqVm47"" ^D,p%w8V>$mttAUunزjzb!nPWNj䌸+U7N./{~ >6dwLeV̴EJq%}5֍ >?CO#0@ osCqGXKX+5j2xc\n=%e -!/0WEE{j=>fm0p`W/2b0+vE-kcrH]_ rkٯLVYZv㝙4["oEVǮfاᐒS<=0ϯXWZrdE/Fe|̂cHqsW;Y]V"P-I:.6E7~ЧƭvnuGpm+E\ֲSWI7&}q |at1<$G {/)ZHȅFtytk["ul.ñygq* p 2MFX3\aAd\j仾'zU/ ==ZA=ǒCTI%?D>6EN)b΂q/cYA CIbF^ յn\({8}HAMS&-(aG(WϼO%C$$cl~fB]2}IvA7Ua&KAbE.`( ؈T%~ dc(A17ThsbA174 {/!^_\%ć}Luя2XG'U:EA.V DoN*U ͚`-vm]RV&i 2LdTs+UI\"n@ :no![׫d3.huU3qyo-;ִ C'-Peiy ra׬Ȁ>!#Fv"Bj~qa]c5ws_sQm~Vg< rhx&._:[{8޼$.&oMFe%]>(qG=&NHʑ4߿WWX![,mh(`L(o-YY:F$oFLPS[9=1¸^I|k8yzdGt\xMLSqzf4ϸ Vcc[ R/S tTQl٢8L, %goݶNzZ}کRjsQ@m ZW!6;LsmBVîV+\sl';= 1FbެVNJqxEfgXG8WBk2m(x^t&AUAvJ*qT@'OG]ޙ al5G/ٞ4 4'I@qn`!["hvGpJbt.77.2ԍak.(\mcjbK*'j[ ޏ/HV;ا Ɉ3-fN/8z٩h 0@屸TI@lFB8 a.pʆWԮ]-:s?ĸwѡw7ra{7um_ !E0$E?1}\;|tI S&q]ĕ"-܏6haQ@-iLS1y9sg!gܤ܋CWe 0CSKhK D#D6FS,%z9x*\mktŦp۪7'Z .ۅ3]0p B *+εr;:^C4&3+@5Bc Q.LY@f>O ^y Oa{htP 95ںζ( )+rlOPBnثu6։SIQDS0 D*x&hq"Bf@ ~gPˆ4?`Y&lتPZt5s鄧̚/%,vhgΚgbo9_P}T:R,Ҁ\`3=,qI>>p aW%nV^󀽪fђ^!Ay5e#ћHN'<.~;AKL`敁gkvǮBbc mua X+ 5g3u P{ K[[h ֒ \oیH]<g}Ʉ5"x,inNY:f)..H|1v]D9 ȳ"3 hm z9(6ngp[jUn'b");u{ehfCJѿôTѠk9 p]G\8| #7NXG =@_Xxr1o>:?T2*2XU"w3<0V泥~?mpvo\%ӫ8s .*R.BAn3]XWyg:^±{7lQȵIl,; xtǼ+vOoi\Ri;VUX>>@u$3Yjf/6znEEv_c i85 6E~ z"2l7k/燾)\3g(kAXِwNL#+[BvԺCA ɻPf؇*R`'7?#]„ ΢,%>M_/M青|#`#CV%4w?E^ت6 F5HM`x8ј-0HX@#^r3*{.JJ^_3?qqff;ȼ6͏1/w'0}w3_3eL9"=!Nrxy)@hWV ^'܍p t+IcGD&h⽞KKG䞐I`6wB䎪ԆMϷeycW"#[!tbd\(4TD{I]D%JecZmT|NXLVI)C狣#8s:߼ PA1Œ .$iaOmz2Xso =ROr@ɖUk 32^F8CWI ߟDXnIߢE2pŇ(Az)'~IlkRk سsφ(f/~mӳ}kRS TmDgdS2(: rK lrgf?{: I1z{9v&\Wr'+SΙ860~=>&TwԿtEܟm)c|:yo·}N ^Hn8锁 i-ar[E~¬/4E4I6*'ѫЎ}IP3hrA^ߎuĩ_a2VliO1++D(=-oLs=#J4W{7k=D1cNrcL5 RWn[ \[T"u))]Tsɂ2)96_-ڱakma&Nߝv z9]𱈵)&ҬOso8`)Ⱪr ܓ-Reӫ4 E_>Dn{^8u9܍!a`*ʰs(Q[`bTzCNj4,w)f[Uu~f>|C ; lzVxt Y{SPjns*s h4_{YOtp2L~fNC^чO{^DmWgIf f >A_z)&߷pG@˵2zTMHb۽4tp u `%BTיoqf%S]୭XE{+@!Y[Ǔ A<ޞi{S:G*]򐦋~GiMHMPU=m,vhsLj֛1υS]5Q`"C" N>Kka<)UON:FgU)tGbwx&9. ex42uqYU9=X waw$U*UQ2L?Cc@6ިev &eiRQdw|>GP1oQ`r wo-;Rp߄dfe`X :Hrh25-d%S_ytO'dÃJ`2u 'UdYhxkh Tv: h唯i-SH"~핅lY9u\˚XF,ж~]rq/4Y) T9l6ԣ٣b"u CZڭ0bϙXoZ<Ȋol*4±I耏UW> .0F!F%Nu2PY4ʲ-}b~h,MW5bψ㊜o.x+ېdgLȦU <%SH|ȂeJ]-exKm麮=2;UMHa71INm"1ZR"l8PLnݷm \ Ng%+28晞_Z:FRAÚ 0>9\]~?h3@e% R!EBœ.Ef3D^r[2t f/S0"}K$e%$3PWPD$ 8mEaQgH GIdPf~@c &f {!8Xk yJX+Ο ۳73oT@_{v įkP`I=2Cyuad0S\a=,LvLUeQ,ĵ95 =4?~ WT;EZ!H[D, nPx+V  ;:sQ<F~?& ߖ!jYTb,5fzY 5e4CϦ\M(TΟ+ǀ]*k*{n18Rvڲb(xd^ƦoG}cX{DJ@eqzCí^^rS5c 3Tr+4ѫze#UgUҀY+b"\.GuA I48k'A,LFvʅMzP,}\$SO^Y+=F2%i ɑЊ_ma,<ˆ{c){|UXU35qYTrp/ȡd;xY,[vLXvbVF HGsѻlR}Bp[65AC7dxZP*2hE'NE0AWZn},C;o}祈10_‚{NG)}fgegOONj"yayM0$ S&E0*v>?P{߽@⢵ım3:kYbpE+-!BƳOHu6 !Am֦Dњ0֥ņoPJ9?.)GA_ @dte\ϩI]1iwΟ/ ߸,㠠&x"I<%38>6"nbB|+Ck>oÛu'&0ʻ$ߤy*#HD"a*/+Sڌ?_Raƣ61ڏt+07r|n=“Y"֢:| auwh8AmL&7YvhT haCϤ^y(zAz/rusB`WQpk _52(3*FpL'$"76F{r9DzgEcXBQ{ǿOḾakMYtXаgZ9Ƿ#? 7e5`o_ $Guz5I3b$6\v"C%Y1 j6U(?* u@B>doz29TjZfYU =(3ZKeu$A5pc[>|pbxIbǧv,uuŵoieM1ʽn$@Zd\Z;2+\(Q/AG5P'/+J07xLB m^hw+,E&JbO2! ^z.J%SjTP85,|Ȼ{Gݹ q,̰ZI₣ىGw֡͡ϙz.j|Ⱥ܆toy AL9UU"MyU4Y3nc`[`5%4xʨ\u7~eRs8;x( 5v(NQ l,vxe$F#30BG9 q5yM}SOC 7|~# /&mEg_ߙ :wb]nN /Zw&:|&bKk\Y-y)>yuZRwԡq!4slZ VD=C?X-'^qgPk^յ;|W LXvDy?! d١7ePuيU6c̛6+sQ9@ZgeO\'t&>Ch+t~&5_QAwФ@48tOKY_P%Baq7-{P]#3J j&5¶=E1.% H1 j+՗Iw*yL/DcTq X]b?5Y7]2K37X*7y=fW.,N'}T"Q" ~5 ׬&z˶ 3o+#V4at∫p'[yvN U;-@ *\ؖ]B hmoI4M9J{/Lk+zRϝ*J%d|Fɫ(жLAZ2\JJ,;)o#GtJ(f=DGHN$z7l骷1r̆CNj|(?=b]ÜpoM{SA{>w#BXcCciGK[ҴBc&xɷP3R՛t|Vb~[SLƷN2ù\")ZRS sd5zZbiڸ8Gxb o5£|rfxȘQ^^ںZ^)-jJf- ~ ?V-TRD*K ml,8坫vP:_KLmym-fОJ9r*"^֠3F[W1WEvӋRtr4q0k nBӆkK'mz iטP {{7手#BZٌwZ4$aJm?q13dijqP8AS0Mu4,H®5=z4*%5'w酞L97*3Vdz͝p?X_IA(.#+&o\'bA)(>zQÎzkV}V"A+? K?_|TYegdf\f"fx$?~1;_jpt X3O=J DKFjX!26 ѓWA@ mw'bCAVD4)RCb0A2OH+n.DUS`֒4ߠKM?$'*Z)ERu:,Df6ZԘ//C;V?(Zf x]%);eYA|"zY"Ӟ1i[TB_qjgb⁴NG/0PegS.AA'd1vn}"j'E]\imn"p)7EM CO|w`I8y>I.",[ (2E 6|c8-S|&gWJc?#f}C3fwn= HGan:S^Rkgʍ ?4ȫX=NSE;LZOPDKQ;Qs݋A8doi& $ eҖl9Uµ">%BZli)ήI O cr$4Y 0ɲr^YIu^ @H_EZ(p:@kt2H1 >`u Hf^ <-X߾?E).(z1$>lv`fc'{My5%P1 jQ_j .EXFr̍`dA* EyڄP>go}?oHH>ty7 ǽ9x{eղ;0z Ck8< :+w+]HOUbG#EnŒƲ1hY4KO&I{2 ~?z@%Q߬0'0K5gG% RT6vڄ;q>D?lOeGD.GOJ1vwx~OjB<+ mۅ.+YwZwdԎvIm5^Rc]oQ Y+ltiP6MPxG(_]`C˰>'1cljf5TO^c}W$fDcB@Vl`~в $fDmѤy<<ԓ Y;O}h3Sem9KX  /L#yQ]:\q&jSkG%GhHk(tP<,ܠ88=%GR3Zv?bj jpxTiX}x-E G',d XC2x2OK|ݥjOq` EqB%fb[]QB/?ND8ÿSte1܋E?Yq&z}9BLG`bTqvxs'M Qe]8^}0BbU\ 8T. '7 >12+3) FǓ5=mñ4'XpIyC$>TD`Dts_>'ń18`A-Z,PN {En8#}t4iaChG rR?d{,hϨg=6Z"CF a*e4ݬ@?3dcBztg2: 唯$Kfc'Fd>K -$ ]r X{e1&Ͽ/vD'e&]鸙9, Rfg߃_F$VtPP'H!==qlԮjYwtL歃pRs$h?hܔ I'!%:;ד% gx8iT1Jf>ygFx6 b]}eǜagպ&!#TI^O$`Bo.U6qg|yMSD6,lңF o`R+_ItE0|T ISk:K[x]f4c2q[rh.%8t8e vV6!aۈ#餑^0}RBҚG!J k/ܵtf+L/\aDoT9BǮ3D kP#2Z&q09OՈt|ƹgͩe16\Pe '{:j'f{gAA"?A鯺VYFGX:66@1Ҷ֞)jH R&vџ3VHd>ο9+]c vCǽc$yQlmit'Q:)u;bF _by2,83' "iOt ;͐| v=wd 2l8OcCG6(GWxɌJG}/v-Z鳄gX'Հr/ #%!zcCv ]Uں05]}\G@b'ZDkN#Hw.XrSoRי/<gaGwb^NjYq9K|RFOKgllp@UCOXUҕ.p57E49g*7kok!PZ-fJO,DQ#;:92p/i']xĽnM}C*AQIz/YpIš+i~ZwEo]vm(7vA>.S4A>64` ;OEN@NBfG[!!%Os/JEZw)Lri.@sd)`e՘z%@Ca+;cL9 ب (ki|~'x e ;8Gu3ux`6kQM]%m(o L7ZBO4Rw/f8ea  4wkQ)?v!\gvMDQ;Ѧ5OK5YTa9%jX=Uj-D|2A a h?6~Y (uEqTqiVH~rZ eL<c7;}O]b:&oTMC"-ɜYE{1ån~u-+A\7Ѷ$"G(;c$Fަ UIBm@Ɗ>Ix7Eb>7#+͕xn6uQ3>PvOn_:,;: @Ae٤o2 )F= zT:/='5brU&ßU}J) `NAVHR8Wa.Rrh ]Qi+o}JZic64;Ax)p冏bzsD.76$@pf* .ez2D<|5$l@OsJu_Ėy /%]^Oa*w )qp:)r3j$ÏwJ)ivT竌߭[kuN HǣyRr9s܋$L{ }?=R$lb*_$^N_1@~#Vc?ՕU5+P9P/徜tg3kI[ /}Ȉⱦ~h{=Squs\ q"6nGUt*bjPיߪîwckaO~sW٢ !#+O<?zbR̯{ABos1_}IK?:[eKgqѣ#aWCE& syi$ 2vJI8+f%J /7mlTT)3~[*?Un$%]릵R]QRܟGH=6ٺtlGh(+{G:fd+}/3R#nآ&VBJ~U)aIe򱪕ntb1DR`;G3 ߼ e6V ulc;m#X\ \ǕTCKSR撣D T"d)z天@s-ݺWVvag i<$ hZ֨Ee@VkWG$^H0y-h !ئVR?iYo1Y41Kb^LCCO0[r7RHXIaxJ2j?+mx ZgHvV~gRZ(EG:D!gAyÅs)ȳ>AIaǙĞŻŇ+8F"5y8A|BoXsEZwQZ2iơM lu!KFXVt/R Tj_ g۵ k O T!e6=vha6pۇM"Nl_ۣ 1!Β>߰#à^tOeSH<-r[ʥSU>J{Os(clWĞOI`_'؞[0e1Y݂M8e59[eJwv\)%|ᡛBW$HX Zd:$t]l[QeS4Sd% URJd'gPj -bY=\*k'8:Kشtp  K+,_p]0(m+D+ U&6oc.beӨ=OFT?3&#jƙ&KmK.=z(10Co7*Ӄ-[jӌ %p̰q+/ i: u7tA emOaL^^V M LVgžRS3iODgGu8m[t7*LM`oyUP8m*CKT&+e蔒uPT͂b ֶ+p;Ѡ]C8d#뽑mEtw#Ao/+,Noj|*9񊪮818cFn 6T*e f(eRq꣊#$9bo}X 3FA{lXb;'Z#ETl/M ~K<[#PHnjj{ݠmKe~@ЗTg?0a)w]X0}xRIrhnru&fh|ş]AmJ1iBxal fi<pvZծ?F1w5#T0Wz78J!vZ7^Cn'M۩΁dz x5DJcf"s>¦ e'6zR9%-.+Ll(fOxynhO¥JO@fM41iV+0J.Mx&rw:Uu%U'93jbb=D mmzWS*>ܸB֞ Y-FsA=D5>q8ީ( swdܵ䂳~p M2e `meo3]Nhy_Kwb%_?̚i9bw;Lj%tLYbyN`|X 1Oʳ Z ɫ[~>&52 '˩ LM*Y\ae e"';; 7 Iz#^8;Mt1EFZy`p8;aO~\6f*Ҳ!K%DP ɶ7fiflϚѪx R1 AdTl032ƴ)m6\*^WU/wtPτk~\4w] M%[tOƊз8D%( *%k4X6wDQ!uϮ{hXwWE8~,X2Zow$V \so 4W7 @Wu(պull5l>)[]7=vj A_[Ve9>qrt PM$c-"e9XŤ8"-w>vmh&EJvGYF%t>,UcS4Ӄޏ6(S ,J?ջk׻(1blE(?:M @ ېt(؛ۣC7Z96-a,gy=CE I. =֓ ^QKxIlLiaq]kp /m,-t)6q+m+&vr(ACܞZյIR2Gz29VFT'U/=Wd0Ҍ)bwmv$+d$'-~Jdxk|BҟBpHP-Ŋv P}9$C@,`w"Co-:8Z55}ÔgbkŜDR޹ 0Bk*+M߅Ld \0>-oɜ?SnT3ǂ/ Lu s]?<3=Q8(֎eXU±)6'iLA)!:-6~_Bz_  MS16//EIG4+in9 ƕQQDi[SqD^Eq nƒDODҡ˺ڍ_*]G`,_a!*u/,⫱ݚf iߥ>4Z=;2ƴwGկ8{h F]_h?e$AvWGSf)= ncnn:RL *Q\h;y{lUW2˜KRe"J:qⰤt IϺ kKy <&}hN:+z[P'w̜`Rg[ؽdz j)%|-PM ߗb< 36!b'm8 b9zΨC_Ȏca&&ZHeiA퇠JB[T"pee5ˣW0`a @i*w{v3}h:&3;Ts[%db^)%14T6 k-+Ϲ>b Dh-Ӝ#8|@H-OT'TfVRx6#2a:% fX͡A$CZ 狘ԓs&}>;żGWre@@1Ssj%re\•x>y}2Gxb8o sAyӴt +F|y 1h.40$v&ZĺXthH hSB؁SV˞YcPx [T*J͝;nb\G.w>°Lc{N|K.Ц(r[ ЙbJ9Pzujt60L* q d4^3Wȯa T|;{й_x'h0}q."lĆiwoHx-5 h+C?@PBm+Lv%mh]pZW,06 ;g(LJ~C ܛqF;*RXWCG"G2>`ju\ s?OcPY].!*=/߽C KWŏ |kOJ\uj~E"](u?Q-[]( bW3yu]0ߓ&4#H8Z;jxqu5[VG[r A&>1"99&^ޮE.pN$r7D_% 2 Q#VUҺZ`=2P?^<*A` 䗕J7rIrN1 hVn/ ף3#Ι1"rؐN2y;n~yU،-w7?ׯ+ Fi T!~-+,5z?2+0zq@+_9tͳݍ"S ĥ"쿪] $-]nϺ˜N-2x a1Q{_&cP)<@U6JK軪б)d8e(%:@Ny1fFtԻ} :gd?UXHEEZ}jViKt 0z޺$ʱhڧ)x[MXm/c *q8LQ.qDe4Pp\8 egppXe;("Ē%ͩoW'2(UTB1qeoΝ:ж,i{?Yd-"* q|p.]Wz'nS|J.NGxNۖ YG?-JО0Ai`%z7;\ԔSxx$BIP 4BX< )GVv˲;.̫dKt1@u?.O[ dl8gi~6k2BQf(}BfBBE[㢸0VLe|p(xb?9)EPPtMtvd+(_gqxcۤ_xйT jѬd3™: Y#WY Ы2lӤV4$؄L䭙&{#`1D~}{eHv[۩ =핦㿾lE8X̌ _iW)ZX"@4bfh /frB;6K{JQ);W;sp1s`.4[TTGeh.I#|$;d[蝼j5.H8e />^&4UEzC2Cq'`Y`N&2Nռ_ǀ AwnUk{6>ZT1y=ʖPÀQ@^ρ|3֣~pb6O/J!p{3¹H2/ w2(bgTw#ybNJȠB7g@C|I(7`11=w>&ᝋLPhM@F4X:{;$xө}J6H#@7_9$DL+QfggE爧H 7QUB^+2[PS kH װ!u/.jkTwקrn[!HHaQeZ-g&'ӏN(+FA}Eɗ ͢ RZ( ܢKW|K`M \+c4@@RS(aSn(:0K2m$ qL}&B8.9R7蔚Ox0&OE{;:۴n!DM"O'UQ`guP%dN)8\#…=h Pb^'vUa gxUIኴ- 9 g٠hER@g45h?#9WU/X(d:t:(k?˼--ХKLx;^Džh|#=^tt).ϦDc'q @W;;jkmSu৙*\`j((,;7tj$y&B qfu w(r]v~;V`MG+A u S8:%ߊOდc,Z ɇoaLXtxH`)/.jpje@Lo"lD(A -27r$\j};g$&KPWaTr39ą_0^.KahGbt9=ز ZAi{ e<I?VCE_FGv. V^e~'6mtd'tFFgaMGc!mE2hACt=Xbic1_@y:psGuob .?>' F*2^? "`!F5!3ūXA|/p2@yRǒ.WϺ|Ͽ``t_4T$9˵W'#c'O,5fpPMji=,Q@={scZ|2cr<͌Qjw6nIx]~-muTXq|:{ͮ|X yg7X#Yau-G>Ќ*FB?0 "m v[C#=H$) ,k+:g xbXzSyU){7S#2| ՈWxc1#5- aQA y ObIy忪9&co> hמvrwP(uz6\-dD?Daܒ,Mfr!6^%l<0oǀ -{l[0kygZ..<KrO|H~Xb]ǁ8^A-HWQh5\p7Fjmkӽ." !lg5Ov=bdq੢sSj+ʻo.Y2҉3\.ŦpIt!|f̩F*ocg܌ÿm:ҠlpB}5}mz\]ȩ(7_E]5U?Zrh ܶ#65'^Mxuڎ3b:݄Tv-4RgD— N 7eѮcPXY%/ ߆o; t ԍMF L.m!Y_a!$NBrwܰe(bf.!qNғdIk?,UEP E]mzu=A7rH$pn6iŘƢuF]0 9zYKBn:8:|$@ZH<>>O{ueb1jItPJ` j=8㸓Ics8Dw?vn(vL`C|ZKvdS wJ8πK<Y!N3Hg]4f\gsD&qʀzw:ȳ袵"U;W?CfxEtb܍6f{Hu~W"7MfޠbC&a' eM' R~''Kd Y8>9Q@ .d[Vmݟ0Oa]kL{g8E_QIVbY,V5Wړ/-g_ T wYQQƉA:QC+ƁMEbm@UPCTW)tѧK&?]b&˚,ثِgȮ Bg %kw݆n$e W6с עV_ X%8!ʢwfyUt#2g/:UKU(סr,ݔ_ h2HYpt\=Wؠe^У2Z2r\ ,?2du:ԦUZ^+Ob>OJ}j\ sW47пUEb=B6t4l:@-+ho1TK^&ڐ-VTlH*#or ZBnuH‚f,,ĺF/܃c~ɺPD >_Vo~46"+!o ө|o>u}!'% `VDfy,%ᥰ\u؎wc%s H8 XD6Y[T5w lh% _sv2 z!BiKN(;O-$WXgfn=IY.韹)Cz!Ox&҇"t 1Sn"jI8}3נ*FQ'ljϨ& Q;$MgF(Qc23 =>p/6?n͆-M]%HNGo#l^G]2!T0?:m ?g Nζ~-Lm6x_%y$L.0 "Y.~B4]zTx"[:~ng, u.Sr[?ῂ@hh\2j~T7Lٴ$722L 6ԽA͙ 6'BuV7gAvWEo".D%bfxb]?rϾHC6jh9#qja4&pjjDķ!pZD:&kw~UHZ՚a{["f !I!lwpgi~ ˼daU)J0!Fg6B\>WUg^NV8%.oDUR$)-%OlTNF%߅j rHo7NZrp*@i$$8H0乢 lu%Un[H;픋 {28@>mEPwOa{$?XJ?;(a;[mĸ `~$xC@_C+Ihm>p|TWԝ54BDnT4hlEv,ҮNg˸{yְQ={^hc2ٮI)Xo[#3䎁ۓ:ąn#ֳ5tq:HUZQ8- 'Fue}|8 }s$9(ֈOBg``|٧1&'K>!$%ys>Jlcx2 lCXd~d'HBe[偂kLb#&ǛUj1?ړ8NG]&kg\80!X%}fgz:|.VC1EM !iS.țgN(ϸU&Ϥ"`%3D7NRiLҵ8|d)HvEr $IF@n?pq ˕[vu!ݷ@~YFWJ φsՕ}3͒tL=ec,$AwXSx ypMF*waϧ`8K(X? &vʌw|H@RХoD/giߚ* f2 l ;6;o107$K2}XQZ7u_v ܷ0 &ڶUxHm+߿*CFJj1=TBŀ8`6a7s}(eG. `w t៝|iѵn5@v[At:SH-}J/Ek6լY ^#I]B%D~QOײ5?ykSzG#;)lYfą8}żZfFxKyp\.56'׎ct9:<ٳ}|€]Т{Q7{D9k#&OJ!ڪXG6VgUYc%5Q]zdJAgp#PV%{wVP[qP+Lt oe&Mr:q}!F-I(J"wü"]-Bbм`4d3AxXO6C ndq(3)ucE.#\d$& gT7]wVf6,o1t^D(Dy&4*G}z+Њ0(4`?,֖o(3V*SV,]LWQns Vi4֠!_THŻɉokټ!s״pʦm$`{ 3|AyGT-`P͏VbeKNbBu"ҢId rA3[<ϯty C|= u[aZ_#$G-ܖS F0(X'rϛr+o^ BD9/e8YܠA/_zNs^#ۓk *Ix'e/LĒ: qx ;56%E :&W*ah:qlwbb}GT0xȇp!(D2iɋR_TQڸ7fῤ`AXdĨIu;Z0309#W "=B[Y.'צED#/!`,vQuY^-dg*GyYXo # WS.xse0.ș9/]aAzlP'_=+(̺:O}(a_sg̷SO#*HWAO}&.ds!N%5?T^PJx#1K$0y5a/_ͨѧxbZfkqA3Gjc*Uz(k vp*?T/?bl dn7hs+]5Zl(Wb# Ϲ64}jQwos;@"dflLiQG)knr}wpc˕98ɋפ3 ]E- OYh -l=vH%tKuɄ/D&T)_ lH'Lџ;Ub1S|t5s"%^wOqa 9o㱘\VD/?3vT1t>-#ѳa0i]*0ce (b5+%YkNƢv!z1t3= 8:)ͻt6QU=('!ډeS6 XM}Dj8'ֹ/P2Q)c:4 FfyFan Sh@hj5 |SdmNFNYʓ74:eh'_Q.+Z@l",tt']:|COz5Pٍ)nr5f+)IJ+& v(*0:r_ "oE 8ޗ,WIFT<_6cB^Fˁz\2;Lb!+&؛q]ǫ!&ު_qe7V\{Ivz,,JKGdWBkU5==zbKo(d/r[]H,4}U"< X i?xքyt𛗝NP%36nG{'fڵV/Y5| k(3VCm;FA\_C[ZQ$z5XD&VPJlFۑM^{+'z%1ĿLQ%qS GSL3X{Sa]SSNV1"{s/aDAƥQ)?F #Mi=D9w!@&T:$5?!v77J6^ʛ6˿:luA@4'opSTKy1 W'`Up஛}P ϸEäe^GلG*7 y̹X4OU\t0KHBMh SB4jU\&$pп/salz骋b>˝ !xJBQ57Thb**gŶGeB-q4#Beͫ!쏅n/A&HyW|e:f.J{Ϗ)N|{ݤ!ʙo|qFX|7c?E9^34d!,*oO,|qL|l)åEٞZ}k@\4K eG-UȽNhȸ:JcjB>~-5YSR距إ7 Q %:""#E+$['j\QPS5n/D'&_(L~LO&AvR:W==*Х,WV QSgORTPյ1`l'PV`=ۊ(rOe>wa*M"&.ұL zn .'Z`Bˁ2A~6)Y4#;ҬFHtz@{1<^ݒtY8ʩε5r?O6SS2Nrh؜(#6%,9:+笐G/T95xO2xsM ),0O]ĕ@5 1W}3~n )hFdZ@?"e)Ą[JɈآ?z4V`IW!-+rϫ,پDљ t-RGv7Q*kU(QKuXjwy |IzCLu_y8%㥔JG2~5qrQ4wQ `ã^39>ǒ2us5.ˣU'O~nRW8gYA#{$;8lVqoe8· #xcqOSt'SDZFW"&d&VL^@(HL{y3H6\-"-3'r]ehDYMh?d{vc8 nj#XJg5 Wn$aJ]#lBm{qEݢh"L" ?9t0a`%F؍I?Px%P=d1b2hcMXM5K띄u ;guzxd3pǷ{`$~ )Bac6~Fp=](څ]%*h-]s?ҢTfr0zH)΁OhX=9~vxL7 LB 5x&StgN|3mĴA|b^3R ʲI_L;l҉TMvHV~XN"_!#X]X-|D%.U'TQ|#6nCtY1 џk}e=QD=+:wG9G,IБ(ԭ)y`AY#xS pf~$!A*>2Ý;ηPf4Uߺ ;t 6z7:}Ѹ YS 5uֹ\ ǃE/dd퇙Wzpܺ TkzƎ4O0I&r;\ 4 n]&4;T炪fD=ドg(m+R8qS6+0CG}䎇<`T4%2.Lkw\Y[Et+r+i@VbsẮW+.H*Ma y4v]n\tҶ&n<۩ȑmѓ*oNDARJSp 91q޹2 z65YVLh.YyarXqh7_TC<dooQIzRo$ĩO4D.gP TUd}&{2ۥ.e9y;r߰aM fPh7a:PIy ׮G5Uze!>u~'ٞ&whEY8.4F&`+Za'U8*Zm FO6Z sXrvj|Z_v$$R"3wvQӼd?H1'8 aھ\m ץ ,yTtw?\({h)&A|Ef_EyWCn%,iJ1ZPu9kC Jnb;["N9TfLxĎes˽l^q25 jQ[>/@2 1"ٗ+I'֣8۹⨋sM1e vE5}y-iHdERm&iR 'Fy' -;.ƽ>"~' vc0S D5ᓩ<ٺ{+sC*3\B?y y.Z/ax$DUcLw]pPvf)/kLz$DDTgp.`t~y)WWD9Y_YhIk18ukԥ Vݽ ;4 T ;^ܷ`U>o*4D!]鷼щp)))R9SI3V>F錯]8/Lasuw3dOV WƎnD[!F{FtƘ9"%K-aF+yeXݬq#B>){iϦq(S2m Ԓ"w,r{vgO,½[dϠ{$G?ga *,e='+yU|-+z"N6KIpGX$Jux"6wo(;[I FMC"R&ĭ* k$r5B U-~)=Grp,/w>i)bü{ԁȖ"؏&ykPfOK*Aqw'3٪*T|vn'SC3 _I  )(H|!+D_d#/k-F GcixDjV{( pgn*2N2%'èwOMc9i7pl WFgo;Nl̬Z:|c?xl#5Wyj3|oݩhIbdYk*_B)4b*jt/cK!>܁W_0kO/7KhwgVG P\UX؟.k/U{fT fgRwqtw*fW Z4ܓ++"Y" 8K[\KRcPAl6Za2҇媉x;o?͂i!y2xd氖X1Zj"r/!#+ 71E3"6cf$o=nsH] NNߋ ~͋@ɍЅGkU?T4)Hqߵ^ՕV Y,~ݟv~YѪk0'gPh4M\$\t`t]{n>l,>D#%U BFdk>Щ4 \&vlɓ[I9~3Gvp7 t! L;4y{3p/L{-,T>uZ~Ԓ"T?t*Y(hwp5J"ri(0`6NBِ]AG3h)Om=.ȵ[x2|p@٭2`Lg m#x΅YE7l|bD H:kSj8YXH5Ą58-'@b M'o&$`DƀMdU" = YZ\EH0[T@Ua@Z?@FU_3낎/ԊdրU.shE-*o(LhghNǮv-@.|tj8ډ'FN9hw!li{P5Oa]/a8:1 cK,=},< HH HkX˜ij\?}Rqz4# ED?A~Ф`%=J.1gKgn@X\Xzdm-w IJp#Y_+1d v^1uw]ZER c=M prw[pCޞcy=iV^͇ŷ0C:+p}zOPɛBv3^e>d7,؀F)\^3c>*@  _'34IʱOo#P0[ƯflOZZת;!V Ѳy#CY{E[`^?$j|'a~j7#O0X9SJ>{nĥ(a{߼5o<ex~x^ z:frq". &33ɬ5öޟ,=@aR=>ؿPݮ'FѲSY܋Z/.4[SmE\^%9¸ɿ43S:M`ai" P]Bk۵!`˓rV*3IG!"}H=[X@iv{H_9£A 7z>T3"Ҿ6`S|gTlxIˆvW0)s7)0uIYسF _S%30CulpI9Ⱥ"Ψ=M=1Wz}*6j"ÀkWx rwʶDl`)e7兩!ZcYhT>#a&O_=B#UО8{,dȩxQnC ܴJu͋Cy27Ʊ.) _zdvQgNyzcm0}~o Q[z 'FC091[=- =e8&dY?jF~#\}oי0{2^7Yω%3!-Ew ,jeNk|T$[1 xөڻNZpZFÊK~n:b;Dsa||D;y!,8+% ph(Ye6R5*q!F^џꨐH;IkogQ Tk»H{c=|8HR*{9 l܍ @h&fkぺz@K_z\|3ֻoˈ SFcgHê8Nan|?;(t)%=t ʔK>oukPq1iUGeY(Uʏ٧Jf4}.1GMä-/ D1d4< ɡЭ;[KFWl1`T#f=ʡ\r@,60XݯƣFvGHGKLg k5K5*+ o}w0~)֞͊p$H165݀V uVT+Y~6wdjrއcRdz&}P]'A9Cγ9a\n S/NiFt s30H AT p5#B-l!IZ&ɉ栐tƧ10b+NY٤"0-;Mum>*۶5뻷Q+Yy*\ĎzYf“Z6 L+ÿ/ȱA- {yE];zs[ߠ>,F>KlxaPH뼳)B(9e_c={lH r,uw}`j(B԰`yXxccu[Ci4Qy9Ջ7~x 5e;n4`og6,ve1vEF+,]kёoQ|RY5nI[l ,VNKdD8KCP Գ|x, "-uPW6!{ђMt 0Կ@YrE$3 ιRij9Y*IH7i  .mwi2ȍ"5["ZM G2f$W^ UJ. Pw@^ qctpvN̏6%m*韰>6QLexUG3Uzו;qϕG4Ϗ$<_(-0DnSFy^y&.c9W y#N" IFwɠt}΂ۮUKYCC_gEwROUeG69(bs h>Nj)vO'%s[u74^w#uN\SVRwL>$O=bv J9B3:zL~neYI^83ܜpP?ⵥĝl GWAv/fL=]iiQ @hjk +y} X1DdRҟ>\p],Vj}AZ%\SX'xyuFA9+5+@5 J}H% \CS]Z+wĨts)6:6Ju.Yd ~hc޴tԏ)'R|V`jVVOi_[׆ohxf˃Ul+hI”DzQ|vx'QLTQQGy;4>bOvFS%o [3;Tu'oĜKz!gBJ2:Ld]v7[a돹xM)Qg[+j0GuCy](rJO6+P8–&Y0 )3Vħvu7U\ir7 a?v{\>+KUl=t8K0;|a<xA+J;U3 T S=6W=dh^hef P;ujf 0Sa2y" K|IxPV??["Sy>5%lm5Fn/3Patf.<*] )oTأG(}D 3syc![AX1Ǜ,FÃTND)gO dU-$Ib4+gԩ:BUu)}mG,,L/JgS[<5 ҷ힡"} _^KCahި>XiI F|u5:eg/g~A[I a~`d{ĔK:੟H9ZN6ń,N %L皑)'nv7UMIsLtdy^046a{.'eetI6ߧrpbD8@L!| )`fSTb#@XyZ2bfsJsuCڗ㱑z,K[UDѺQTǟ3]PL}7P]]J_fS0';dօnyu r>@{rA2F{Ϻu?7Y!ޗ8P9(rx)ԠϘ54M=sWȿG7 viM?@sTn?g|\`,4s1\D4:WT:H' oc#5ybaKkXj)aH /&>B˳Ń{F눍+ټD>{3|Y"ByuF/Rۦa'Z#Ia5B:"!KZ|[fvnt n> ;02Bx"+(u1{%>dtNf"G "@ PZqYK#d4,2mJ[۝pZYh~297]rw;L\{w&̡KFմEHyGk~)N>g?> m_K:ƾa9޼907Obs=C&|)i.\9L<Z5BֱCqX0Buw|B;{=5ױv(o/wG׽FctoPqFKe@, ˍ0'+nZm@mdY"u9| IoP>ܥOviVƪ]2ߡeWgI+\̵̑{? ` 8L\!>mںÁ,wΟ;pR-toiTDr7 RX.uI!.>ﭷ|Ur?#?3jf={A$F@tBJYP`k3Xgi޹ /( {=gՕ6{ v>Ω|n5SIƅ zH'hcwdظ(r/DSi`QjP4;5:"I8 ]jkh*B~qi@8>d?`,z!Rs}"3] La+,J 8m سwEy_!Y]_snjWkբ1>#BB|PS>S*z|H85G@#ղ+ ]qKpC>(*vN=9E8j$ߒ!L㿟Wٲ *I@c07vU sTx$bW+R6j<EM2RȺM/e؞Rn;zEO}vShjb,npqU9&CtGq<6RB*.R&!:ܡi.Xr[1S@8d`(b+ %-~6[RD zG-ʸk&o)DyPAp&"dh_e`cC,T__C/pQÇp]41nߧTpM$?n^U*WN=R>&1'izL y-@X:jê]3,`5-P\K=z[O3r:;բs^YF}l 2\O*}*<%OwNyp,bn72܋}~Ng)9aB*Mꅲ:bKEM* HYB[XEA>sҰqDšr2'ϯ3Jz[EQIW 4Ib[&w7LW$oGtrs}.tBh>Y(KPB-*rvl>{Iк^3+4x8uj{!`l$ C|""lE8h d37کUX6i0]W5u!/rѸBbo5JI&UЄĜ0>g]9k g)uR__HHf4(*ռ1.#g/%tk_#25'zװzⰏWEC(2 u{hjw"!)=ҵmчZs:뗨 b`XF}JNƭYO.@}=h[^o򾾘U;]6mo[`#! 'e$`k\2FoR"tCXfhK}boN.y#,v9!!/{毑^s`ٜ%%畴or$rumBM4=&Vk ȕU[\@=a߉g_1ݱs{-LIbrL竄V@|g<#_QP]=es|zfv~RV~gwz"KCEEpѭ;$,- V1TbX5B.!^P Ѓ,3/aPNGKppȓyT ƹV&"ۚMa~m޳Zh,x@4g%@*@Dń% d}"hwt Ms <&;zJS:] |M,ÛO[^M萷r-KBj b˶щ)i #.-:_TE4?ݥ.Uk,L |6| t!\j(`)to c 7zPgyψ(:Wf[-i@V Î=nTΚ}P՘#O_8:r]Ni\MDsK\(ֳhovn/*7kef䄒JnY)ܷ sC{yfДp)?:8Y LRމn $odԝ>)OVʨAsN_`'H(ϡm,yl9'Ro,҈Z +M`PM | U}eз@\͔_ B#҇g5k@tlGκ{Ώ7 3ẞkA׌j-ʱ}ş(c4'^uwlzHZiDa}Y4,u<͘8躔KwaOd?69{M֒WvJD^.9InK{ȂD>"%Jg7/#,kVHEqD.f)QOQc2jaJ ԞvujGPBǦJn %NzG8|,2Rj`Y} )$w dvx.۪CJ#Y> X$+kȯN6o+,Zc='!T㿈"Ҫ$^(pS\2dt֑xfod}LHB͒=kle>$a% 'S,{\V5;PR J񺁉oא-U\E@Wo6hrŐ cM:"q M${h V?$$}<W}OYvr\*,g/!W6b$}#em B\DhԐ˳AрZH(mn>~;29T\tvӽo=S5i-safH6x:ුcR=ܾM3h\.Z叱s(}2Lb8& e}߄noDg SFogK GpԔEctMh##U:ݦ0!1u|o;WaiUs1 Z r*ҴOΛvN/|r$ :ZE6nm$ vJrdž>dO/BT~z<3b죓LAGh4x`۹̖\_ r%}>M6z~Fz\_ܴ>_!BSͿDBZ>-w(p0돎Q+LK:&Ne>g0M Etdž $ohHioF0oY}f &r䨉v tz]sW11dKv W/&;a X/_HDCa=;g ݔ0fmifw8>wAʲWZni ӓESJsa[Zb y|&]꿏ts 6UR] \={oG^y2ے'وǸV^ԏh;<y"On{NL)^-ih& <@ld)E$[N\D,R"G,?mބ<  c5td#m`+l8z F4j-*Qe-ߌ!5l>J[ ϶n%ݑ|r1RZK^W0 MFk<$=C3讜)DL,8=0U0\Qz8{;qHI*Sad2 _jdZ^}{o{1=B^U] Sa2j<~s-Z$x!Gs䏽:-k9q hE){W4zEݾeUror/o1ͩ(G}\ QFee&h*I .gb%@".2?^M|\H/KJd=+1kfh^  K&3dqkwFݠU W͎g53!Joo6{fpP5P2q%ox8.fɉ3|ω/HM`W]e՞x[.A x,dQ&P%-|џ'@v| Hm/ B:*?S/݈6'+rK @6 Q@y/HhsCOi毹ֶj@p—-ĮbHH9Y 1)|] u΂PA8q@]2Ϡ7uK ), d'\F.5 ϩobQּT6|oCu/Cُ뒼nFZ~Z{ԁ̓t8O}S=_9 1 s:kG~S->܈BO!nC¦|@E/I0Taw-xk(> orc CrLŸEcU}H7Gr8&+ДbdǞl* 2 iN;Z29Tgh,lP1!NpO 7Șe`77]#?7X2͗풴A&x4E6L.˱Tw #(<3Js2(aNA.|8aJ1kVv'ˢ YMG> Ev=̟8)"1sT}|m7m* I䜦.--UE sL|4 y|z54OAJAe!lw*ͫ쯣/R/ْi ZX#91@J{{QeO u4f"X]6k h}Lv潫xlND %zGO&c-զ]3c7'-/6A9=J7顮ABZ 5G> ^PUy 6 پ|du2hz1J-s; [ R`Y_򝜛 H(9pD`N-}D&>*J*|[c_ɜ$ aFI <nj ABd b/FvPq ";XbY<xS% Q3: p"\+4)I;j nsk$,/6F+Q,dx 薴K2!:pl>o{FLASjtċ:$P1}gIh0c{Wj_nen ?%6ɇ|ҬU`8*AFS\ 9v[73(!`<4͈aҬt=ϔz !1d#R ݱ;㿍 H2sc&z$* H;"pq ])_y|I[kH' 䝢{R{B۶zv6/d[5\'`=--E3Q^.%8F|q#WoxW_~9ή]z& cLM<^ߥbJ$\ 萚M;nR|b{ t$wm_Iz+>Ͷ%Q4WȬN4Ż2 ՞Iyi$S#> gSNMCY{p[shQ<В1G'DG:NDOB]D*Cd ut[d;! 'SFݲUS\g.90i}˧Zt<>2NHm.sw] #!2ǖ̫sVZZz<(C}#qjek jPUB\!@qXsf ,ti|+#uւ;;-I` ]=\l=6LR6E(Hxb`ό>uƃ'G3x6cOCE@ٸN+ӪGn#bň Q>0J.j&և1p cܦ5)\.BRrjpG1?Ӹ(r 1icπ×%%%vlI$Bq^ Σ;Q6XOW&.Jf([g=',oSrɌsi EGۑ6TALLI7e] Ae>6[>sS\[h=hZ n6w͈ b`SdA(:=,Y5/mKUG6-uvigO&6B+([!eDԟ1*XX%†aхj-'u_~<42 ]Bj|z2Wzxp2eU3lM!vEx{p=!p-V9S$@YJȄ afmi]TP5)lӵ<.퍂Baqvs|j>(B~jÊP4<<' %nCoZ!X 1Id4}]Rσ@]q(S$oI.M[ Yf@CM*=˞@_ۭ*_F5nޕJ}gQ~OmC2JQ G]JOF'koEZMaYȉ5,e+ 10를m=F.(@ 'qk2ˍM4dC`jl=<1{B?zq7gz܈T۴+M`5EX"|GtJzu$y<~dpe&e=h@0dXy4I[O3CKLs@AsWrpW8E}w&˅?n/W3(V2zF8$[+&Yݧb:eCPts_z}9RL!h07eb\O*"ڄW`0ja[m_'I jrD(rNА,68da؝Yx|*_hV.FDlEZݖ+/cS5=s0 >ơ(mj!aRnJ62-b{JuqwI< fla>n$2O$K}jo5Xab?)'!#34 I2mVKW+u!WmۑH lW;ÈmEڶ#,q&Z9(.a5V (^4q7xj/0>G%;G p-'g"G?O5"+6Z] It@6[tuШm [$͕"&ma8’;)t̗h}/0#p' < /ٰq]rNN0Qoj\ڿ'qT6rݒ[-i $BTe;2Ңv1O"Ag.B 8Vw.iF2e;o(VA^׋QFʠ 浂L&sWZRŤ=@{_:+09QF5~Z%Wq:ia5d@ Ty;C{ھJr޴%Kd\D[%}6/O pEGVÝ4HGwfesl$/ $!agY`*jSw| 5!f?qR1+ؾ#r ˭K'%wfB持'zP=(#.!x({+&\,5[Ie@4\cƚ$s~@(9:=U '^EuEQ[o$֒`~Ee0+y9ep\&P`S((Quӡ_^3"R"ι֬PGdDJ]|P Ԁ.=T6Jk&Ud>VJSOqS}M:rWOGa֤k`Dr ho!$u/[t"˵rismځDz/3LY\kVJLʼnp/Ӫ v0H,iT֘ϡ#n;{IF4KI(E]һN.q)eh\"Y"2 KIAyCGɥj Q2W F_]CU1 V--y-_ϸ^o@~D7]_"ѤSYfI">5f9MKj"U"mMÝ5gu6cQeaPZA܃:\&0^יMTᖛH.|a[IQ4B.rhY4"~lnN/Z} Q$q)oÌ>PN. MȱC2C#z A<'4XB&+$s[68 ǫ'\\ߩixe5KL.6@'P68 ;K򞟂>$KP7lMNU#xP6oČM5'l)c|m/=Dfⵛk%IF.D0R6>۞ъD٠VZOljQDM3i5s h?CW:~j+JkVlqs&|-e#wMòtP4hK䌍Wh:iI{3ܜ?+@m_\!g.cJ!d>n`\ Ç*89^}!%:1t$+%p{%X+>0r-!@]CkZWDVQH#u eyA+,٨QckXFhKiV,hn2.ZVWN.>!ڕsc5.a^eh Nh yc!mi.!ˀLmN-:(K^:|Sbf4$r0ѳ˒/.ztӐv16s`WwQ'/e9Q0JWUV<@[*ZhPiMW&Pq`~*v0\ּ 'm缻2RjF %l;PcW{Lr;92`E)gҢ>ƬTؿsRLIt)$// lcz-^ /ױ6ƏFqm'Dj/ nLdvFzopz+c^oId9i( RZwUIkiA>zxNJ{Z.]+| B۝vFL53m]Tq;y!_4qԼE)J@87kS gBh #<2Kr޶ 0>3#J!V̩Oۉ7l.s-t(m^,BNaKǾC k>:6azJGmDž 8;)[KdVlNgzpUQSKʍ!ٻN[PY߷Dg?'Twf'_?$d+0}*6jfN2Dbھ'b4)ЄL]ߒJ&O.!p(XTKJ."J+LrCanL>_zjw_Ga0߆ HݺPx'D9j‰He p^ ˂j~ (?L;ddwk.D~eCFsi=^ ;4j:e(Dɷh&P}H!>ŖI;{ ji =WYC oMɰ7-;;\խRKm|QGjb)fYw]QZVγSKT쁳:;ZWK3[)pT E~&t>!ck RA`e8YBd>DKFbq_cnj(Ҡ֘eb ճ738LL h"iQ=%Vr#1_:6J:G/h_7a&u˚2G(>(TanGXM49zo7ށ%Ύ5"ni)X\?;J%/JaĎ:|A\xP W0M/'2El!+V!MδPKpdVM\t ?3Tv\GVEq߈ey]'2Ћ z- yxw +y ʂnn0 A*sGgNkoD^eh/Y Gϥ1{I]Onbx۹!U2bqwoҩ9@04:wwDDʘRO_!LK GM*hG2爥3T7~gF Z.Hn:Gf(84\l~eFZ{#0 p34ÚFbz*ƕ@$lh:y6NlYdho*p𐚉J5Gygu '2ߚ +-Ez<`0Ag#r2=.?,`PV3rYu]'jϳmi E(C|4oYxIIlJkN~:sWiZ4 +jkzOT AEROQ>q dvI3nla&9ʤla>h71 b3R)xu8 l@ʪj.Nn*R ֍3jfF'P8mt>znZ)'{z)+i .:Љ)ef fU; T&vpIy %54Nm^|6~w C1,z!'q`yY8d3E(rF-m 9x*}=yiJ^2D7 ¹w3/K ؔJ80Tt8S*,[/ջ?)+ v=ɸ\a>'12NcUD[-ޕpXgۛY?/|U$,[Ë^ DǕv]r֓uG70EaZ:nyGl VJ-ȷWDtK2Dk*}&pF[ʚJJݠ&s2]x8#}6wN) M*ZKEY$3?CѬ|#1-@XcCˇJ9F^ށ}Fr+H7HrBZƎSp,5֕8GHZ8N%D5b #^Jd`1biݠbMQmؽNr/b{Ϣs+3ЏJ/[V]j# sg)yfAF]M ?"hSe ^!p( Xă)#˯LxDJY"ꖆ,t$O6,Į}ǪN܄3ƤؒsBW mBTۻ$5c6%2:@{웨Ev3_zqP[\VITFg-zp/ 4`"A W)ʍe-;PMySC6PKqh&셈ԬcsM+wberFQ#'o.f6G)y&|ݨQ~FPMF}*Á@g+##ʼQ̄y0{("ɜBV^vip *jݍ૎6u`{\t/^ktfJ6ap]ՎAcU=F)iMKt0цvSwCTC!srCEEϞ[gBp*kMpI;ߥɥ%rC!-h!@r31@7ןKнO:L kޮk}1,|\_OKɶ4)+W3Z5)A6ޚ/A%# Y܂:lF!zt |7`4ޮSi2S2\^| G˩ag̣3r~θmD|Ky u?BVw{X)|>.p{<qͺE*Y-˕k'x,MXu0y3*őBX^v{=m> dŠPH4;pq$Bhܫe[B2V") Ϸ,Iy;$Ip<,]wH޳bpiC^۔X45;-F=NM("! lt /*:1a9̽L" ]z~qrP"*ay5r!H 2lEV.=aM)_ß9cEbvps_ݼ*u@OvAT-xI=0'zCT7Dll.IM=IU`]{Gxi|yKXZ)BxdhDc'[9)QGlQ$]-*ЈGBz*EBY;gI#R4N7m j[- ɫ7/X V~΃`OW$<iIhYؽ;QB!wHD"E}?G0軘R k.0f(%^Ez;mp3uioCW8(Cgkr$HEmj/ ̮"vmc3.mۍG4(29n_)4౩Et{%xGvq_&Bj $ցpw|L: :}X9:OΙQ|gAM\&\# e(M=rtKZWVӉsj<i0&פ#BN~f_ e[,&:ﴌ,,Ga75uy#$x{+mpCLϏɆe-.zSTtmg9cdq#+ܱ9֣V(7Z*I]G^b ŚRe.i/iy[aQjX/;IZ6g]\Ty$淩/* 7cQ(Gc$WXE,[Žern7ԥ|,hbi}WMg@,4f:#Kþ`/Κ9;t.2 $ACB9$&K6lR\qc'8Lʴ_pJ]#a $0Εkk{mPOA!DB*kZxS^"e¹cRv+@ny Y8J;W'&1)qXV81ɴfۣﭘ)9s]j3&*9)CPn~,_2Dٌe FΆu- pP מNn`m*luA+Ii᛬1`1B 3yo5;U}Ig2l覸7RHDl.2s:5goB,>h_`'FcH ԋlj zu>`2q: crG41 1QV,\H 0vQ`QD\St7dF$B٣_HD c+}=S$wg v_py)-\Չ4ȼbIK"`CoG#ENjdRCTuBP`}*)P=TػI-P`0O+(Pl ә?8g hniH˶gGJ]: y'?{ Ug*aД4^Nj-;bRFנRKn˥/bͤK74Od{=&sBeCX}}ďkU(SYa@E_ݍc< s^y6beCRKN{Lu\(ګAn~/7f[-'P!8:'$/|:;Jt)b$d 110^G EH\ȶ&D\xhhq*2Ew[qXEthr&ܤhnf1AxvJ-Q 9cyt]WX.~D!IkyW8ć z3Arm>pkX-q|wp}W7 :rF[*+x"Eq̲EVݗ'Gw$ :#v.1S,*Ӧh,'`FS.;+P4*fϲ [k8L_->k!m+ew58v .R[me sL8'yc3@wޙDBW􊁳I)!+ 51?3-P>wkO^#ppoD=փ|&>8@4DV2e .;xъ̋g,`h+u]X{oOBɘP^ '9pIn%vacCd](^̈́֡ 7n(8$̥K{jE58AeHc8gU?,Ѵ;KκHYƤ57>i <ͻ'HGjv˰gO[\ uƴHu-5F`86h4ݺHd;Tf|d !~4ݣksTCuS=>U8|})(wAeHR?@~ucg] ڄx lnr:)mQ`ǂBb+nU JM&RLv4qfN\a7x?#j?'z?%ùZ"T X˒b|*x7N6\Lrp=x0͵]`]A RJpN|oIv<7" wWDI޲F]P0,mY4d( 3?jҘ3Ե1*k|-Bk.BFG !q=:$@aIjz؎mҫv!ץ75,[A,5Шd\HH7 n-*c7{ Mg.pt;Ԡ}D@ Qc\8ܝ=>n|_TճiǬ4}ȺJYn _\w^6f"}o1q"{5\Sk]ci4AɎXN˜04[W`;աY3n2p]*7wG$zW!VKCܱb}3 QTރq`;7z\[oNdho挫1I)&uax3ԍ#=USAqր^)T Vq0CXmH ZٱH73խyuSY?"- 2foLEa)W b/t`x4 >v|z@yPog GL )Qh<>T,b]ำjsvQ#0+4Tx86iQa7t]k[Ѯ #U)}};hOWNN۝ !d T+?>2)iHI3̵ )^bW<1} 3 j:B/J qDF5 jr|ˣ3hcYM 4L\)Y lfѼ 64 jiQz)B2Zn-mdwq⎬x ,FWI&_c.k%% *A1܋wtcN8a 'ِTx[=`RamZ\{FGEF4{ކ+TC#&qf椙Cv Ν5 F_ 8(Eƀ njY ]70z]&Qhu( ݙ+&/PZ T}krvme_ /a+1kI.?)D6Q?AWvHRL#׺gɤv)cF`D.߸ z84\ |g/V/5'|vIu%W (U*o4Ja>u ,J&)x<8+rodGdu<2݂rV/D p#eT:%0r`WGi+hbf"_Ϩ G|% iu #?蜃I+- D xEhiKPF;9`m@'?z20j@:nX'NYN\i uIv@F0=7Q&Q `K-߈I5)+F MeܹҰI tx6ԑhim&U3uܖuķmiB+0KFRVg',p 8r8ydmr kY|SsD~ZL@́"P+-\מ0bIg^wjQu4bNEFa.811egI2.ul%rx`ќ]ɞIYԠ2uiJ×ɛϿ5Ԧ8WE:aBZ߾uSkp Kpшn, tAI9r8/#@aB͍9 Y 0I6;b8rV#yjXۻJHa8vd,`n`),gZZYSM.I&݂*\B$$3FilGz`L/A= ^e ̕$AD^ ww&3cfyG\eXN^Ѹ%[ |vaj2@N\DB24&p2'] #WAF l{Je[oSV1ݷf68[e3y;3T$;q_Y=`>67'K!!X8enW n9ƽW~[ ̟ |t4#>Yc:?͕>{wH! oxb,h܌9mͲ}jò#,hX 5B[嶜:~K0CW A Y//;,̯Xx_a_wvnaU67X"a (ZQh2#Z9<$NnT5(LL, b)dAW[v%ۦB#!]b<ye-tɎX}5c IҫǢx2v Z/r^0_wZ={ۀbn6pm"jZDm(OPqrt!I%,6]"v@b Y&~KX#SߠyB!,[Y! R:>Ș}PiVD:H@`&9vq~QhJϙY&JKxؠX)[$ ]cV? CqÜvoAX{R=xA:xZGz8.X<8/JGs` W@)t1(LxpۀR0>wCpM}c7'4OC'/qҗ4eYVVX+:%?27j*xWZM )'XqL[[;!m1Íkb [gȯOv/&DX)DVjZ`[<k 8ۛP5+I)4WxBJ>b0USxhqE$? nDnAM1/=H.-:<Rl5u8sEwa'b¨ mh{\@Kih ksEtS۫-۬8|GhxH:V5uzsaq.u Cv,5RcZ'7{jt;zVL*MPl@X >U81;M5y!fNac"|t:W:Ī^?Uw'Md<@bkht%ԃZUNAG>RCV&4 VS^MU `ł}'-4, UěC: ++w1}_X(аmϮ@ۼp/enֶ̝тX!+.6ggmV"=PR3 _#uߠE~*3nA{{ WVƾ1x“{3Ft&6ֵamvr'(^=@V%̽*HD SGr{ujCe#[o==9&q3{yǧv ƴn9`X:"tx)]\/x- SbTc3})>3 =Pb5r_( {Mpk.\U^kN)EۗC(Q O*iLv(Exm/ُwBg\jJjʦ:܍ۤP!gUqrō9E֣c,]%ade#f/Ljv O3x4]e@M^k=8;-{kiulCf(J?ey1D8\ O"E(^\3[fnj>"S&y߷x%ϓ YH=GV N(>K L_|۸tk"15r!(0Xؚ@(8v9HQ>&8<: % FSo'C9ӴW|< P,)mz}}ў\fG7SB TEZD-lp ցy٤OWn#gFU7tK)[/Jk4 `]x[\$3A\+99+>>=b G ovCb+58%ՊxˤZz[Rw dP~"S13dCf^vXkMxGcu4VmBqOS TN%20or4U+&;g^ځϚ;v-":1"xo~jA6^-Mds(LrXnHD78oBE,1 T3.hF9|׵jJ=֘mН;TjS)RGK\Sm۟͗&\9u%?^[Bag 6b Z+. qɦRӞ"ƾz(n1 CvTdhOqZ3R1a@#D?ӮG4V^bQÕ!@({LjG6b֪=Reyܱ5"w\:d 'OǬ%2QýG$; G2 RKYΕ>a)p /Aܩ?`I?5VͥAd&'-vB}VF; DU|1M3hyszCݵW\7hD&Κ2^ZR \SVo㛮Rmfo GA3}?6_e H[0VjMґȎOk|V%O殢p)!bg#Ν#"+R&x |S.@PTwpr[p oKy֚9MzI,亴ȫrk~xya4 en(LiвE[.&?($8t";m|_`_tp?zȗ!%l^7-Q-1^xbcƏ^5SAgQ]{}:s΂D:{k 󮪼p]III)u=MF˃zA^{F љt(QޥRY^G{,6 Ly2\=nI};ZTqV*˫d8XmC4֌$oNc .u<}L[FGLdTt /y\>!P8.A³>!R[͂{$g{L~SEMC(IyL/Tp-T.h6x>MrٶU!| NT`:rq@3 v!IE:~)_%{ $UfΞeqٻF)}\1HXskZ$5{Z<#I2S57v=Pe˲e@R7Ž.Kv3¼+] F-Z?P)1xZ\+}2?N;2nY0H李vA]=bqVT@sa@ \l?4&뷶ŬFl\&4ݷFonhСn`i3 ?G9U`+Pmu#3` 5{_{?J<' -œZ-{ny?of6?  4Q1= g_# x$i] 4_C.JS{%_ uo=4jN2E0[Jޖ& "v T>FWih9)1=\"OGpպIɕGp('ES (̣~\(5F#5[qgmbĺ Vpߩ=q EhXzGlN%:>hU^Z|X-.M}Xtd)[pНQFpn- aRH}:1HY%WaZ/r4 Y`W+Rۭx;.9ilaL_t$j 0+zʲP$mHSүu]*$~b@fw}y\8C̜ePG-"';(`C(oG@a“/ԾLw24e`6Zn#2K+R҉7bE_8#cwG&_9\p7>2˄f,%B#p~N<9q`^][q]dO.MG@zzsX01 To_xD0mj 04ٚtvosW3(5 O%+ioEe H~Laݣ6n9p A!F.QuOv.ɑK(4+$!C *C~.$׸#~8ה1;?DYpE$M*#M4/}JZҋlAV\^&d<"b+,= e;[c^pI7v&;|7 [UG!FT^WĀ]UHf9[vnV'd?}B̑LNmv NBoS/L^($h#n< Y|ީX\(V[Z^1y Hfy1:Id%}o׵RTSU3HE;PdŋND` )r>it[@MJ)Xݦ5w~vq(R'Wn$Jj,3Qͩ#"1QJHaGi-nH8 ;CҶND\?(= pV;sv4LGɞA9{yB㊃i fD]J; Q;~0;Bvc\ՙHrXAx UA3@$꺺! iKR` 81Na+Q:}ުZUxӝNVP@'@Taq߾N_qT߻(2Cy?4#;_>.D!A)o DiXuE`r`V>2;lvF|GqIMniltE%nWqv ˳ZkgܦQ̼pAxlPb|%:үW'>S DI)'_[qzb6nYf٥WU .ÄhB .GCvۄ;e"҂yJ~T_?/gc`^BJ4&!TԣFe庰NaY peELMM)!I(4.l;5JDnz'*>2e+hޣk<]-Az "]ZU’70ץ.T㏙xv8Csv?:㓸ZSջѺCh#=Pӏ߾ew7 >5XdUw@z-K-:j/ҧU7 i Sq9s/TI8ƀ˧1+Avzmsm w>CBor{~dKP5O[9P:LǛ_ϊGNDR/'ߺpA\LJlҝ4XZ)56:0 I"w|}5ҶM2>N`թ˞͌ג;BGWd [d"7,C7e E͘9͜\AlQ R֔/RS~ "2PV}$q1إq8V$_C?ÆRqw6DI;"Ph+z]p"b aث ʼ,򾸁8S]ϼc;[0PNUw9%gKhU:06>gd/s'~Cf԰GZruם.J9* H<OZ:ڵ?E!5=Z6LVFU@HLrzP-&~$040{2]E%1 #7N(]Ip[pGb`x(اq>!6|Y];m ⟇:wj xO1 /}*~4cfŚ&#|PY05@A #V*.v[[Rd;3z,`Xz}|kثcM*]IAw`-t7Ez烺 p?:G Cݬ3Z @7pG?#OPHa3xSaуY!(HμC^ ?6}.3fifZ+h6_US6^A7kHM/`CZ|Md}2Ϲ\ _ن1%YN,ޣrC4z.CGPv KXkw?˒L6!g\$}%h8F!ӁC;u^n|sZdI0^;$A;(%x? ]|9dQqv3PpDIAVaJZ/I YM~ $v8 ׌0i{!{kOo0aoIgr0nt1a)H2mHP-CN׌ǁNxjݻ: _bl_wiX)䲐eo -9O!egzu6 vﲼXRZuNoz;rhhZ5vC:=|L -\l3*B^=va3ƇL|XKGZS,G[ڜZ#.hýTp2 L(cVZ)ƈ LFђW8Ů.BFc?.Y  V|O9 gm$d5 'bQc47l>Z;TRh5r,mm- n Hextָ'Ѝ+<-ԕ2p %"ł ll.Uz7 "t"6G9RⷷvOHQRݨ{yEN;ҮSif(Q0 z=cJ*5[rϼZI%'a]/e!\eH&x}Qߒ*;2G# ڇٓx= ?VҀCF*x7u۾F <Ԩ3t@e2p4q^;:e ;ن=z .L7ŧj\},2e7!W/ʙ',F0Lݯ;<_g$Sq6&_%O}8 k[b~ ަ*a?rGoѭ(xl#c/p3LJdۚP 6hg y/k*mDžf;b#E%N6Z*GY6yO̖3M_g+9UԔ;' 48$z iX.Ɍ9Ƹ~Z&Wk ֘vRaC"$A1jk0a=ؾޖZ's,9`AQݝO$\YΕFKw3K';Sns<]\ \>6ML.@ FR#PBX~h&pɃԩGd*3B@;N4/o2|- `lV;)bʉ6]ͬĜ $-ɗe/n Qy1'"`9~T?WOQa73Aqo}o gقd~Ym@{`saLΈ3դ?ztZAZRJ_$`$Ƨ 0xDLtʙpOQ*NLņYPdi0Va'dx(TluΝu(e5Q蔻ufs3„eR]R*y͞w)|Z%@3>Vr_-+яFJp~\~TzNWV;V6v)F!:'„?=To$ ۳)"8Bp04 *8W49%9/ J"=vO桷Y?o]JaL"ϲƓTN4F)-sKmD i<jG3>-A o 6Бm:: u*`dIzs))&ACB e4G&`lOV1굙euv&gWF+yrj rZen8/hyNgn]<>z؃iJ.h)`;]էIIWC* F% gJ =/Zp(m kPnuΑQל{Ł֫VKC):[@u@ FhEc. E% Xv6[dk$<Ĉ5x`%P%lZʈ7 i,̈*4yɮ\]m)f/eAv: w(cmC].t~d՟Zjj,}YK~M ~U`>fIEmvŸBp' Z55 UHz9>(FkTSz˟}7@bu03'{3*V8;#CCfr7pfk1 4Q.wdGV\D@9MQN~BwAVL h<3.@7Ynh+Qց@ņ `Ç `@,}y"q`G}S,HqrjG"uwNm?4rM(>Yzy حEcg6nJĈ 7 InOwߌI ˚,opʖVLMaG\ᨱr[#bl^Dsi +?^@Y{u $~.k";a1l˾|I\W0źInxzn)k*נ0tsAxPI2s,4dTT]x\bG,stޠ1{.eX7Дkl aUKR瞨X <3< UqumxE&LNCd OD%1$uL9)&R]Ih`ަJoye}Dm{?jh|cDNce]ji?ņhﰐ i{7VtHYl}<K 1kw驔-ᑷgVl910ydݺNħrb¨8{ĿMn@66 AcZ CZ(X|OP?˷To]ͫqC#sAk)fd$5/s|AvpL5OMŻdՐhLUGõkh":,?qm3bL/W)UCV? m҃y7%4Ay*Ӳm ^ &Qc!!m 4qh>Sk/&MRH@s pJ5^$)7l.ߺ|,/Iņqn-B;DT'it ol %Kr[=#쁐e(U7GUC|vaP"kvhAI#4Lt)=Ýgd^izUЌ;ڧaˆ? ęTҳh !5L=uTob@αQϮVޱc ̆Y% ҍvo+kcS7m4F⥉[Gxy1 2w 6g yzc< =#g|0䳭L En=$jl; Wj t OEd"r:hznL\vC![ŝR귂lxnph^ QDE?0^$=ק苨VFm$7ƫHw|.Y6Ҏ0T(m/jϏdp\d8p q|?ZXy{@BԴ5}-?POֺ)"I3ub:!r4%6BUh䑪ø+~(':Gqz1FL}~H.{ۣy?+E8sNw%YQ1,=CYx(➑7uvy#hVQ|w<w&:JM0ھi8 y&a U%J#5Sڦ664UX%R3}eRqC(km(4l%?gTD']nK^C qJ=Z;kMP%<*ٍgx1'L([2J+{D(V7 inslcR?k%t6%) )=;ex0¨'VwM"`x!pU7m#<R0oQu)8o, tj/tPBYu#7){SvJL~8aגu8b-Nuݸ}) lI̚Va 7&sfAY 9i2\,8w*gZQWJQU|p{ k8-pQ.0NTqʹuaD.Hl>Z݅>܇mؙqCh &{;+hR R߬ EҚɝfG*1Q=_r<*➠- V_QX yƕkиcwI-ǚS čpTIka:9/SF_JuZ<%,:7&NY'̨Sea쇀9WF^ I QN>-?̈́zj*af^HWH>>ImPmzV/\j=9^,-9LKм}]&"i3=IE͙s 460КLș<3}OƮs3/KPژkSw:oe_> DUWZХڊCR%5wfWݿ@"?Z]0G' ;Ζ\>ECMA3VhewMolƢ>a }Ѷ|.(}WEzJ2-tu]=kS=gia`&kԘբ؀OUL[$Y;ljwiE6Ύ,ƹNt+ђ:GEFq߰'FSZr|!%9Z{} XۋWBFD4Lr(Ruxc⋞e `h.Z&<|5LG`:)F i=0KI'  nuFzӝy}<w|vlF#fLTT:2!;ɗ*!XʖD$ɭ%:%kemS(au }Rh3:UR_A'5MRnx88F)HR1p)g+5\Hi}X[vk j"^Y u5VA":%_9_sHܗl߉_!IZ$o&c82m|#ꀃhf)+2Fn9mRBi6؎ƚvaEBaM6 c0xQ %rh{չVQ%ֆ~x{;6Km.{S]*FRؒL"xf_;$jah;C&]"4iŽs3#~Zvc5ZJ%c7Q@MZ2>Rbj{5;Qʑ321`?Ϲg%S?y &EUjj>mn±b_LϐKhP4 D#!g =G3n"e. Z=3@W_\!,Z&M㬥!.VeKM;%8=0k~pqb-t@T/}]%ڻp>@@/商:4L?5Cϣ؞ֲG#c*GlqGjm{V7ĹۖB8'ռ]w ̃ݎ01䃟>@@;:a[Ls+3vDJfYc& %HRv #+@R@=T`⮖O׋rU(dU2aMaf0Iq*|IVdz+|\o =/DQ$>+nƖ=Ѷ6p?8{VWRɤ{w-L? ;ʺJ=Sh5kR?0p c3~oQʿ9N~-CK#L,WJksyGE= ʧ!D q{}+xe(n\y0 ܺWjǾz !P'(ywPC#wSZHV~V;8U2Ka"u/ُ@K0D_1?< mȣ5/%F^1`nB WtVH8g/vǀy\-TQd(9{A&[iW$b~軺,OӠ}'PRPT[YRf#_RfEB:<8k(Y:s U^x]Ѩā'ec*J1(Q&I\8e("M=vev酼aDCﭐNѴ>֋gT@$GQ=#`ތAwog+ئ-.<$D|T[9%D TYG}~zs`cvk#|9 x~-1<#dV[GTs[GmJ;Dž9oܷoji}mZA @p: Yl 2G lnh1WrlX'8Ɇm+ychJg`/ε)5$^8,JCFJ:A/Gz Ptm,Ύ;12>VSüqyR,6v%Q˃ʜhDau琨TAj"W./a! 9DמutdHW!:pK($WPY/}.``xva' \\Plbfx¥,#qiR6X)Bo, .Iw Ӛyt=:`IVdzQ 2A!~oRlZ-b vF>j!H:~ 6 _AE" ip?bmfu`ү6P"$XRRz FEQngQ^aS߳j4T&%>$֍M*+*7z[ m^>g*n4wEĵI:)nϭ>bdM}r"lh_3^#-f8ؓ+ob1"JR˭%ǻBlPV!ս:aGqk5)87~4`4eR}RՁŰvg^ 4&2So3F I,xΈIP.LVr d͛"vznrK9a(냞6uLK^f G]ʒp$P" mMJPbah0]u%⽎xvҟlK(^8{{]zM0ldt}X,t6 s=#%`${UºGQ3=jw)>F QҘ|3W Zjmf=[^{tT=b}Lm04EWp򒻡\2]MnSpe|$e8W)`BqL➗\@4,mO":›Tf)J[XVNbӒF/Ȳ(jxZo.6NQl8g~p wq!783:w-ѐF.FWy>}[lNh)eGxnEOM߅uF;b@\TA7xz3~`DkOM[Q'H8W1Im |MM:q戓Ihz$RůNz zL3nv٥& k ĚߧLBz97j5CAվ;h@NZ ݀ȣc"%-#MI;d%uLq eDcgL992Gg< td`-T]֓>{*F ƽh+aܼ# o7kCZAgxdz% SwRӁRrE1 nJGӗ4FCW{:_g]S{~WENdؚ3jH2"W6HTՉh_ -NyD)1;i ^;) gq!`D8"z#]JQ CV/cﳂB-Xd@H#jXbCRXZPNwA:} L6-e9H8@Ң2BWyJ3⌜%,L\@CN+jɴ20OeP(2tjbHXH}>=>^7'¼0jíYA&X]kbA:ĎV=T i+`:G(:E25ƑRC:FCD%3*ƍkwJK aCN=#߿ٌk~zPF853MO,4sjFOvlrh{E(k.jр|-3+k #n9#/g9/iUM[ mq\x=]5 n|@Tu<EsԧBQ2t;wO=^DttͼfI⠕ +sjwY^z%)Vjd%׉{X&! #7D\{WŶhZsEE'^d5٪*xg#2uUnk1Ubj ?T_v4Thu1?%^IC>lVBR/_DW(b4^ ;%]kH/o[ãz"Jp[?5_:ĩd1 \z\ th'hk^b1RΗb7H.jҧOz劼^O$dۡ|v!2PFg0>@> Lp4 jQ4 @R!Ւ[nOGG"&7T<^ܻb\]M}!K=*8ں~}V !kel" 0xZ&J_KTzei%,h6ƣM]'eSg|R1%!9 S1K34:'EMY.>z94L=:Md:hq` t-.ߝO+u2B"yYOI~8B@|KRo bV(D%0RZgTԲ L&z+g,P!d6/ns|2iu}M~Ŵb4NPKgyρMȏ@1 S߳#|qcDcD )ehu/ll%>;AԼ3G 6%CT$vP:nhɜk[U3"Vvuh#b׌7*ܝ'Rg+MMu¾~gpK:Z\ gIO8:M e~IQ,LR֞<1I\*䫖:vX.uMkEС_Ub#eoH< 0c/q+RѸ&qo!voG`ZN41O9&eK"Iޱ9tp2[8Mˢ0Yd L9vR;ˡwz5ePY&ϛn} 3"i+ٛ^&m‰`xҿk\hƜX*0j9DǔLg6k"..[A¯_.Njfj0MP/8SG03x=wvu(&;h޸OӂcZ7o{ Q5Y2? y ]6@z?z91 ds5jS `$K!Sj&a#8 itx:դ}99b2,Cx^wPw3DkKIqxOi.p8:iגEmkjN2h/ e?S/`5x 1_-(Neo-5!1dz oaS [Zb.RZSeE lϼVNbu i%eDe'P4-cgll?1{<%7aboݲ9Ir&kDcO-(7pxBR/a(率 +=nPQ/1Whv12$$Z&wk?G.V+Χiz]aҔ~ADQ4Pd#5q׃|Pw{F*1a9{{<< aV53mi!]Vc͍ft18FtzljFe[x¨O2jf\<aFWP9SBzXaEԩ#GJ<1&c{e`hͥ X#@ L+Q#_L55?HC{L3vgs :JOJU`Th5#OqF2n*SQ*$>, l>[9&- AR \)sW{dOٙ 'Ɂs:dq?3.:&mr4{L|8 @9^'Xc [?P"q(ʠ$efԡ25J"$6x2z^*x].u+> wM5b1ve4,d^5v=k5@Nw`,_2qv~& I凾AFnLPS*jRŪuC< S: ^uyǗ6@[mB},׽ap0Ш# QwGm'J*U 㹣З0&kM}*;Jd:^@>  99k ؖSt _ SW8B8ߘN}p>qbBK>`bU#v ۞>0@[ۃڦq/A!AP+5Иϧ#/U_@57mގ4 v:10 b,;R$;/%2s&Az{mqsXcBq`,yթzw yA+m!1k_)9E$&[>Ҳ ax9us+^jm{<],n79J]P+l "u{H(m/̛q[ .bí`LwzQҮOCTp )v@Tc.ل|7[q!Sԝ?#B>j+Çʯ'$11Q/i٩!đ,p? ;+V[ *7TZShk+cja,Mst"à \X n~892rPw.Q?Do../x$) f^$v~݊2U< d5D:,($2eE`@6[-ԴNM&Ͼ*zu'F_rU_45t oQ2o2y8ޣn@naT5. =~_5*<W,~]ڔ*x{ WW^k-d|B+\Qp^ ttǵqic6u>f*N}S ?~\b5~os^2!.Exj@˼%P=UM$]%a[.;nUi3ރU/49>D6!'3zE̷M(Pk5@qDrGU- ɣC$[Xs V4$V4,S?8b*0Pv@Cڥ gxAK&tI }с-beP[AD9~,bLCE| p^iYK,;VyO%.葴f!¬$G ){B8["cmq,R2pLjCνtpB+ 3SSNr6xPLY_rD_d/{8LQ=ڹ|^^[ 4Zɸp0 9l!u7fl{40QGTHaa(ՙ+z[NX%]n^f3Dgt,>f[43vW{';CxSXiF@T69Ѳ$w)d7T 7OFż-J8@2ӆ~K\mWPﶮ12N[.n dBcs-`NZ_[`~IVZ+})Rv8ۊnO2u#G݉f:9AY.a2 -(O\D[8ئ,cCנrt9Y,>WBe)zgWQ:B 5DE%A7ʂ@F5=SZ /kx(;D+9 ~]]DZTbɕf!_҇J] 1 4 t:&c޲\M/c~gs81Y |pҤt;E® 4B#E'\7&seBIт.Z؎T럐|vYoe\+|fO&۶afp߄- 4mq涮/öue!Ow?hC=boyKLl.. '֜쩂:j]Lq>yڼDأq焳3bȚ5lhC fFr"س;:#~Ü\zaud Q5`e/wܨ?%[2?F-.'aۚ`Q.Ge{,.2Qq9-ɊRi0|X񁒬rͯ .)r1.l?{nȳhl%k^1MCAH 5O҅Z}~z$<'hzFPl!o66rVq(fm3A1d !i7'f{Iym}/iVbUW!3h^aJJ1y&ȡM4f3 sJ8HNZub uS6C[(ܶ_ i Xمj7e< V҅+%.$eQڒMDM5qɃ PY4ILQUxF[gr@apKTB,ob)tzgǭC-,pr\_۟;Ώ?eӹ6jbOh׊I@83X>Sy㦟\z-nVf엵zIH%;pE}~&Q}Kn;f.V_4ƕ*IZ&Pt1'Vb HaZذni-T<$24{m /GoTs߬l`O\ϨR\DA"]dňbv=z2Cn-xqI"CImrt";mX/ğGk6`^K/ʼ3U.V4dFbIgg\MNjC 1bQ\WI;r*7GJd/sx4^ԞQ@=SxJ-P?FQuSʒRXH&trNLoUnƍ>`h2;+1*e /2gJѾ*Ԯ'݅i~9хF|yWmt9ZbUUc]p:Ѫ% َDOR@ԣה-}k$ 2AcyH v{a#-.kHOxv}K#H)o}k|!tyCl;C06w wFD_[J|ߛQw_@v4wyO5f@[qv|fE G @bcL@>ƥf!Af,f[qx7ԣ׍`9_MĘ*"3~Z.~ RafUEy``L>uq?y#̞hχ!ְvwV {8ë=coKWۗ_~ܠs?Q@9ܐ.%^Ijg`e77)ֵ5~=sur}!)39 Izo{Iz!rS@1rTq!ZDE$eRŢ  j^p1lw"fnghʕ;z 8o?IG=[|t=Ju٩8`Ng#LƐf񵇒ÎxH|:uU#imf.#: zws4>LxI x!(%H$+04!ꦴхqOknf6 <^>fP/NhLv/0USxCu+&$u0dE-X+3CS@RDϖFh)6KA.HT)oX)5)jAZã@ewSعl+5kc8XT${T#䊥dÂ"wv*5Ƹ&T(P:hkO]n֭>n:%?A,iQVe‹:~XN4 0DT,fD"ʝs9&p1y"3d^Ai9!B\1c3 6q0r͚>]e^Npw6A Rcawd P[Jy ߇ߵ振K=/naY$lQP)< " D0'6W9B^T#vo\x,,'TYVQNV~z#|K[{!j4r]@7,vg0}f5P-x{;姫2İعz_pj{ !U{:*߹cn3[<~$HCz뵸O%E]ע_f81]vPƜ>VdsOHF; a.Gq8[ :xV1ߙk|yLWLi@v yh‘NvI>[r( #A~A T4=}pNoyݱ( 4TgD;6S*~Ta?Ϟچheo'hoJ?/?4Kk56 bx9C\ &,>U}ӳeG;aFY-8xfga2J7; I䝅 Yffƃh=4?]#7%uU<27&nerv;Ӌ&y̅m3.p8`akF7OW% bs ow[?ǓL]S~EHk3 I 8͆Yq/K`#@ӻ -(3 Q2ILqSզk3at\Nvs`?i(yu3 &>cư "tOh*^V)s̬mu9MlUUPoV=iѹiKsk?p-}- XQlB+6=MnBJ vz;x9XVc!攐nhW^7gbmWuu!}v|ܶbE8\Lm^jLo;kzAcը:#T/(s`[1(ƪ«.[ 0HH }Pw5ܒ"ӦDQv@b>Rx2GQi-b(Xp39fh8^fݐUA,?*Mw{q Tc Fd6_: aa,ZIҐջB0Mr; Zs"Cyc:x~+WQ#̫Ԝ𒐎d@3pk@y,?y];5L\8ȕrN77Ks850)voiM$­+Joףz#_5Mʪw9*904'hew%qȸ|N[K<-^F1rP7iLj1`rIDPXsȍd( 5: s]4[#m=]&xjx :xA&8fD*B F{!'Llj mԜ_˜V)WR5%aXKcWa/ELhc)N_l*ݝv LE:lM[D '5%QDd+r6EۤNb.z| @-"}"ʃ_k.6FJ(%H]؄2z(-*4e3|Ekaͻy)cP欕]7jZÛiR Wgɇwj{]S`B2ff*R|/2T|;k禺 fPCj= @( G)|6aQlTehޏ]؄T16. ՏB<`Z:y@>1G} ,CMkG R[0Q bz_sCNsO ;y "f}XQꐧl@r>Ur23f͒#ɂ ՏsGQTghyg0w~X8Ǚ]c^b#Mڰ)]4V,kypwoy'=,Ԗ*t ZABȽ'!P۪4)ttiY9&x,R)k*bQH "-S pW!(Tzak[ojk^ˢG:Y]]<-LҥL8R&VBRf% hf^|✨ͥ2ԁ{]yHV/+!g 5춲!A> K$dp+ac)$>.=Y[`E}XEec7@!S74F5o9CSBJYp{9,t,qݒ0  !%ϡ: `cr{΄H9:\Ri$5jBVc_8ith%Fs68Mdh<ȶ3TY,ۡf^hˇTXy UmJ)@dZ Ϩ}I#ŻcTК'?#s`qkIUow:y~$!`N=<स*ɩǝBGZ>VmD$ME AL2⊍ `Ck{7A@cC- QWi}?QPxU(x3~tq^"T2IDRb-K( șgLzM>c}6yrn'[ֹV0p8ӪRZv굨H& leaα>` i.%ol7H*KDݣSAIUy"S, [3l Q%yjrC+u.)x)Q#+sL~}AK|FbM||Hi^N}Eb U\Nb,Wx99_XLjLjC3;ƔOἔnkeuEU}wVIj&2\݇GE# , $588bƏ7bPل3~|(rBitw瘈YSby#č9 H~h7٭=#GThPɌ?z,+2/]V;^lI9'd#mϲ|Η_Dݖ$} ~_}˙Up­ >. :cnۙ/=\L?bc=>CW7gr)MJ oـHFmG6vjp;kHĶYt?2^}kdl}kJ<mJ;c^(7&)õ=9 N20`[} #eu-RāLpl ] &$4yOUK[{OhT 80oT7!D qC}}Q!="r-)&#V>S"*q}Z@SuiCcI1v H5|Ov8bȯP2iGas$d $28 4Hja($/zϊˮ?KO@=-yزjq '6o=^uWS8xp̅L-M'FqaKc4NxzO9^~PJ*+m=2e6%zm^wP`p7\ytueF9 9ߒYhEլA41ʆ1]Z* Xл Q Es2=Ϯ nAoD?3#ށ_J(3*/52f)MAz@UŽ$3NQQljftkYdB2.[ӲzF5^(rNWJ7YWB)UM%u._*rl'\3NO&o8QTA00A)7CLQ5e*ILoK q |A-jg9h g_ O|t Cc`nAɣtCbYf  {Vk J \'%FXQ&TDT;OrcnvtJy  V:GNܸO`->3SyI/|GVnj"xrv% 5NBӰc@Q^ v6BZXJꠡֺ%`?<3+F}!^YIdCzT%"Rߒ;9Q!Z”˝YkkYV !"[b7g~0`kh7?C˷SSG ޮ 6d!W={5VEGzB&aUg^k04QX|ZmJ0Lu44] (} aF8X3 쨳iSr> sGuUAT ]6چfˎ@MYy5;桠(BM?1OKB Ϡ!.aKa>MI7 /4ʅ#hjt.v14<ʬ9wyX+ɦ Oh{!LS.˒.Ls^'&D!*@^'CX; #zq BS"5#q-8~sesG#d@B+!:Z[H Q{~ts2OJa/Tx7qf| 4)AYoreq'F0dtW:Y=Gr>`V'HSɼN?<uF?H^=]îdKV1U`-OE;]c%@-ג*/G,f3_)87|q|}wFBIPs=U^˶!;cSVH֞8C < 1B((ڊZe`;_:O<67E<˚\ GQSJ,X|"Kq˦DT{\G#)wpHRDYibjNwKP}vG:;pavb4 Lo CF&"d8}ncH}DB>bc;gM=8wB7 3"C@0xr~ְc3w0bS LH 2|~K$5%tg}"!Quh؏{!W^ɽy:?: ]pPF:cyBx_dɨзMɟGpjE?ew Vs`UٵۙNUuʇŲlt,C!>)V)6 d0HgRG+e;dK"~gSJ$nzl# H%&7A}C?^pӼKWԷn%gBюZ 摖o@m"ȉnJ [`X(* rZ (;5zYc"q}h wApNeu W$[5*9SяQbFRl5]e*6E fyca`m*.w%+Y-Io2:xtg@|;Vk;k|/]kosthJkTJAGC%FJ@:YAK\sxJ<4ݾ4ߑgoT xx3˥gf <RHc%MBšfs(BEHErn!Dۡۊag$[^&q (:taT}ⓡov%k4Th C z"8pnPZC\b2bєh~{s'97 eH"]%,+[.a-j<@t y|X}A,lj%}~ŠڅIpz`{b`mh/3mX(Qޠde3m!,h*@䀽82@֔HՊ4z6cB -4o.<53Q$|pY %0_Eo.,j-ᩘA+p{9'-&̡EB ђu4w@ ёzy_#7-kB$+;fV#}4q8g+d||A^\NX3xsu/QRSRJ{٫\-sxeI1z7M.9xBs fj;"227( M|f!|;7 d3U}^ }-`l¢ڢT~V Lj>0`FZ盁 .!g*Mީ2Y!/S1A+Gć(2g7"?cV A%~WKBB^ȍN+_,A+.9 E|$k7pn{-:GS[%4wqeğt3~c UzT9}:@ծ%-K=F} q}t,C*}W9p//4A=-|' s8m2kCKybעzLENF[5!>()/9O6PpHU9mݓZֳGҵnךۗF<#Ǡ Xt`6LQo>3/B w+G]7i4V)4ʻi@D湘V*oNP|AHG^riGQ6obIj;U9FkPUZ/ID>tM]mwVǺG=8Y(0NάAk㓵uvR"|pTr KѼG Sz!Ik?5Ј^P3=ܿj^_DL06^l&l E ɧRz1ND !Hbym=>)Eq\a `K\O@ppcQQ@a3wݽ/<L;q E H1T" qTj>cijIL<$˒rخن!ci *Oއ Y%6 MN=3]JD\qY$k kqWq:Pc \~GBm5R,TuHTop쵴[+PpxnZ=>αj)B 8ԕnz&Pe@p neEN^iJA1a s)B59죽 >Fގ tD7 jT4GA>Gu&ŚN3[oKU<55qm0O/,͍K6K/ rn G#DgxA&iF(Ot1ir t"wGiFaUl\UƀHy;gT?h'ԟΥ5܍#tҼǠ\#ok<eS0a#sBgp'I2h * X3%IFap|v ,wY5UF}}f궃8Z&L:FP%;dHq,8`SC_ 2KP7PR^gW")}@!0#)N~ѭ˘OfұcDʬQrv]cnGyty6YPAT3 ku8wr4FB@ZA,mıS`9;*G`$K{H2{ne@`huy̜\,C+C>p!x g)9!0qxC)T<#}Wµpph ?˩ 0Zd6L#G ^P^Їi򗚡뿿%W:/.47wD `)g_Cl`q!˄ti@ڹ!w3Qhސ &僶w`d@t.9~|}? fa@+X^UA_PjvT@L R]ңj{#VX<=w[U x,ba[Wxt'XZ]BPa ?,%҃Vy9^kjK漣e/06:ш`]X I+ Zhly9=5-oQ^dXӖ~} ^?ao} )?J$ a_J\g@t+kQꅽ0#' s>C`Ռjxl:lƪ 9d5'߂N_¡rtA~Xh.:r1ve;Ԉ-Ȑ_~I8 Zy=Fry# (V% ^~y9'Dy"U9yN7/gqt5u| ;Iʓ2A ^)=SD0!dHեtG\3OB6Et=jkGYCޞ?D7m$=dityjsC1S:O *!<w$ n5򼐛v{'v)n |H5NGZ PyږèYYa̷ l/6nApX轴]oGNF 3F RZyQG$,[*w頠f]uMV z( bt_ I'ڙJdĈl50@S0GG6Rntx:|p}:NB$ׅS]Gk UB( O>ѹ@?Tiu։Z U3T*c%AAZJ;Ef1f~o&rL9Ec!򲠔ұlEjr)jwBC׾#:?){yTMW@/v:_YvblF)+-f '63Q8ZDm6zf a ĺpqwTbzS;9̕: ˉ)<[k^Rt?Z/4TE{ D/ 2wQ _- ӐPH^+;Yfh-Y@q_0‡NGyCbc!}NU߃jN`٭z9tǏi uW#=ݬZLnRY" cƕd!ڽp\HcB1^=? r (<M~h ~]W=Q*NtIPo쐾ٱbߐ Z%1(_hgZCv1g:qx?NUޘ7P|.%fA}/ +icݙZ' e4=)uyQ,`Ȳ Ai TqP^Fp I #e)$M‹3ZZvL=Vq!B9 7h/Y}l>ѧ@ 6*#x/i"~!PmWҙ`C2|}):M .$WLX'tCVfs0Bu18%.VjS %M m(UÖ 6$@}\%bll륝+Ojƻpܭy iTL K.m?[:=pЗ\o#&N*qW te.hXLq(΁(6D%f"TQv=3jЃFalSӘ?s$@ZŬjG .4c)@,DdDn@şv +#ܕf.\z㸜L4lD'I"VaDjqFw=A/|.:Ջ!Dm%2@|sN~ۘ9O6ў+ē6`;i/W)n7)C 1XZ^>w,쁔BƜvlH?&R+nB߉e* d~ާ|s!?/op_V&,g1r!k7W zҮx%]{KIU"OOC* )6ӝ٤A9]bt]xeM#UbpFt vX8G֦_OIdMQۆ^2(kyj㑑{QQ~&M6~P|e 9v! d=4hG7e`v[%MB*r{U)Og $d:d10VRXa$+tJ0jT\O&M$>J ԟ  c 0%aKm0A9 E s~P$ `3;n9jtkF>^ݢMOc o6zlYm}$u˾=:0O!3=v]6sF:1ђ鵆abʓƠ_!'oEHȈڜ5A={~6B Wa>%hsct yO\OdLPJfy1\M˹b%#})n+` - ޼ʵ\ӈC4Cp>n&NZOiy&-\2"~xrrq.S=9k>\N%AR9ސ] xnH'>#v 7?rk5hL ٠lwϝd{e+K5_8OaU]r o}ĢPc<1阀c֮F5-:(IZZ?fh`pъbl8wB6Hx ^mڼƊ>!P04 2(*d4:t8Ea((a0%,=&;3WPRr@AMFO)΃T-I !sfM.ŏut~pN6#P(|St&1YAD)v/뷉SzMغ48QxÉ"vvT+#  }A@`G[6VQf(\qNDȕ[ 3sngeLrj5 VJdI+޾^BuZ(ƈPCBΥ5 0 ]u,&z6oIc\Y}냣jx>4$z(+yEp;+VWy'"ػS|NKɒBK}SՠVs5;‘i!֦Sǣ93khr*ːG "p]~8(}z9Yu]1,1P-&?4LI Wi+/e@aȮz {M@~o, BI ;vQ (vj?.%wA8n$yJr[D6Px-@e1 #Sr,Fz >l0 0--{Z bOZۺ&Kjt@dnh? o(| C SG }eM#J-gaٚfrpnU6~FRp/ J*-'|S{m)2f7amҜ4ɭب y`]ݛ-[F_@9,/m+Kr|l(B`u ?s(~̌k}`ݥjϷ3xun3A)SNӺRV5zH"J;TĮ5| $$髈 4%8 {n/ޜӽD'BY`b?V.> rnd5ZͶsHO)C $x%ng׌ w 1"bԉl x_+LbSqUٜyib RlwfqQ?)QJXDL#S{Kӣ_s xU\- :nR \7nbW” ?L^ ؐn-rF+Zן& =-F,5Ѭ%ZLqR=hI [wCt]B(EL!@*"ORrr ^Rh6Xv40 )Hc#a4~@h|A\j[__"ojhP`WGUh}w T>ZSrѫqtjw )ZrW·e%Fz3Dj}~s?C*R ֦Ce/Emb/ 5x؂NeIz}}1Bȥi giIŏ."Hז#^.l`OG_55^L4X憠nCڪKlÄ%.ָ4GS4cLkA nOLp!gwiIe 37Mij_ՈlUx[!2 w"E_D3*s5e2KN𦰈1l)Zv3"]sQ:+ظ$0A0Ռ_Ę#U+-{Z- s,MQX:yR"-N02!^ʼnQУ?=жHJգLw\<?SU&(h39Y,k((Z}U2$x}kDž4wNVhN gy=ij_.~ )HQ +65CʠckUoF*@%wSEC' }~5= e bҐ57g[BdLV1V(,e6 937u' ܭ; ޷81faZ.Nu e:n{hdw{tHF3}gEJL)LY=; e@@@e8QituA{2lKxahͬ4}}V$*C.vՋ?*݁PW6?B(D(4[):Q dw.|(%wrhςH>LKZ0i]=uq FtxWmz 7_t J+U!j/7"G̢\iL0גS0&de݂d4#˲ 5E?y+,Á-bV5zٿT );`d8î 2t`o.xu׊-Z uTh,9YZ #y_[y1zjT%$}$M5#bS>?cF?j{?5u AVboxՌOGNRkve]Tuo0>keX0?u.M\ȸ=vnYi9ա!C= *2}5CC􇟇g!ۘq1q>ߵ 2FЗ 4M# r~co:+!@&bk{o8АšhB hǵ.KJvfric =,wGE ?]:b#T+.OͥgidLUFWD'$qJ"m[ ae&'|Ē&iڿ%ٴOmJqfus?&,g3˴gGwo|$Hs> +h?ʅ=ˆ ZO`fBs<sSrB'TRN >IuS ҴxT$"A^0=p߯29RjK'@8Oy撛4Xg&1 w#N.>׭r`N3Ǹ;^!}SUBQ5*t%FK#[>W7RcLx[Q !k5׶?=\ImY$W-2(/{_{s!'b/ w A@840_dqluIS]z!$ǟkB餹T6.vG˲ lӀ`.ǔCHusd3FPώu|[1/~[ zkb qc)$FWb-z67\q 癝žmǣ)Y9*'1=b:*( +7݄F3^9ν WH1T]xY*0ҿP/0/q0SfXq&!5h yʐl2V}z rmQ)o޿fmkF+g|=l9SC~?0$d}sfvDWXc$f;RΏӝhS}(yhffEȯu$>JoԞi" at#WY*#,)A|2ʘGL~IT H]jM 5آrƄ|sT%!vjtKW@īZy(УϷ\dg[*ihFפ: ]+-թֻ"G;kiǛ.H(bvȊ^wxn[_0ՂjL=Tx/ _GE[aB;Eg (S9yQ.uLEPձ.E< (9{[dYpYaX LLnʅM8;wWxLfTDO`)H>]!68Wi$ҩQ@,d;l,S): AOG;ENRc'6awbO|@)K lwDRG>`;kh ZSմ`M6LW>+X∞ @)%]&oFk}bC3AjH;'JƑ0!urr%O'&B4}[bT ލhwf?]e!zxc j؆<~M8dJi4% Q<{BGb(sNb{(o##Fi6Foؤ'.)h+} zbLJ{>Gi@8-h.* rwTq]ݨ+KJcuC@F̍ /ڒgMrS'oa/oYEItnzzUg "p2M8@eҜ %X!qHiC:Gsڑ7w҆: xՠPF|s,qO+"u5bqPvD\P  M@X:1b7gW>ڂ3y%eV׫׿+VX >yEvjPa"s=H63`2EԊ۪޸2`hzO!̄qgR#? U/:ix~Q ՅҞ4hfTBX)#Aa)'TJ^?*㙻_F- o#;>VP0 M.I+Ո9sex&drul \ (wޥP0|ER恹|V Jh.k͒5{&'?RS67KߦS:^ʶCq#> Wxпy*arUzrѮ}v~9wukڎl,&)B*ԕV  -ZDHw|Oʕ1̀N8')tSiav 8Ed=>DLqȇt,@m;rJ$ֹqQ?\0U%rde2J)ݓ4TK>E%_|)jl[>vxRs6wi4l"TŇh0~*f(E(_i)y iK:MʎHYL nBl9d;xy'B8~5ͪ+Y4|:W9ϬFਐ o89sUxqڨ Q&g- Vn]YFoĩ"P" 4DX)#67[kt#_}h\%vw Q$= W[Vdb[Gםn 4ո&}1pʹ*;n2rmEX9#%W@s=S?,di̊'I=RXt /Ssaym` YLg^Lđp XYј%ZTuX5vQG6wlQ̢rE5hёd>鎂8@SqǕys^qn 5Xexݍ?(aDw'5#y}Pvpۓ0WVʪjhe3t7dHJ;3w7۶ݸuZ/=a;9wht P`>v%=(@ĸ-;hp&FM:a v~WE9' >ۥHJE8:9A̝|M"<@\GAm/?D4 `ϙ,}Z8bzB!U㯜@1NSd2-l iRs#H`dX%9蟻"J%1$@:Cm>gaJ-V:hFK 1ރl*4t 1Z$  l)uoDI>^zҿs͞)y{ie,ǣȗ7.d nEYc-?(%hoTQuqj}zuiк ;^#hC|+=e7/9 J9lNA~JF.S Zt z#DodJ?S3'ߎd7rNsbqKI Gz7D7>xXO<&M y8+iA:B~.?1a%:~\): 2QwTE &{c)Ps@D۽ҧl,`zpCT Vr'B S)6X>*o0(<t LrYp{ hA F$ɔNqgɊOJN[}05B'wZW lf3u23K!s9h}N2oXUNțXHo lV{fzu'N4#ȿv) W[!\ox Iӳj$Ѵ^T䂔fJ!'tg4T8y*jdž fQ` %tF#T~22c8M cf:nXi׫(J#)q.`auA_}td;]Yl&*AoO A)lþ ;6fXrO !HX=/Ryqndhv mTT%PH ( oS}`˟;|hKJ=e `_.q"V [:V& ͵JK{>N t^߉h$jI3ō!+jicF x{$WJ?/J~by ?Ӕ!r0Sck.Qnqȷ>}EFTD-ɅH< ?*U|fȝڗFsC[<5V.GONA>b x?O>yXY^׏|1f}N3f|'^ _>UF!"FD=D` )dBTif_cr)73ſUcԣ[|bXV>,ʣo:&(ß-{3;<%"5ְBHo/ҪPxT.Pá {yL;ǖ/} fk D3V$v+:M;(AS0WKWʤyN([LU^DW"^b9kpjX.؊L*IԎYg6'wjU' u2(0<j-w>/xch,b'#J.>'pf17l"@ f5:j/9%,-sƇFl)!vt8DcelQ ftx'51V>!Y>V$TѲ= V{S&ф>s THTu1$SkՆkli{/Km:E"Ze g(Tӱ~ nWȭ6oŵ[R"]iX8{ :0:]*7.8(rgBQ l,#븦p/)b#{Fd4Y)R]+l U6s>JqK{. {ёCZf_0Vx ڦ,N w<@rIwL`g(k›l(! _O(o:}#ޚh'58q4.lDKD5|.v#yf4|)_g7QVݑFAB E3WkON[:F)*ͻ5Bj7)oT|h0*Bcg[A|I^F\M+hD}dL=D8.뷤B9hQY*c 5= A h2k_wbnX̜6#\„vG=GyUR9CNr7M)(`͌xt^8G}COJQ%UӉcq>?/P3i"{`S :m7`ƧQ#~%gКgiJ;N;4ԣA[4H\}ݾՓ'c%ȪTuhw[ӏޠNa'׬_ G %Z㎯@GN'xM <Սdp.1KlIWSk[>٭ R7-cW妥suܓir'H 1~TW,Gk>Sd<3jSB}":ǰ⤬̳fa~VR:^}Hl(<˭pc=,ZZaI~M8󖻕HrF`CMOqKA$evK1*kD ;sXz_E2 ޺L9k䏶b1eDǂ3}5FHmH,N%@$-"UsB!g-.+x_' va$;zPhX-]T!ԛNY*sC?N?R–?;HY@7~ݨ?T܃Qq <.)P4ϐhՔ4Q4`l݂565:d-H %䡎 J#fHj; r81L*xq $aVk+4<ЀIGW&ҩNlu1(<ո=5$}#6RtaqK dĨ;H(dVϻ?0rJV$"6B,<1&>?7DrAov,Z&1U4lT˪)y@:Sq~dJV`0msN@XI0#5zO󝈃#Q:{Ee1$Kx#uUǨzpcM!%I AI!T !Y^lj;Q'V gdQ+AԂcH|P{BAl fNVKy`:I'4Rh+l\@|Z>xKOo/C2 @)PwWv@ | =[~ %1BFt&ǘ ,5 xl+I"NptS) @oʻ+<] (4En\9x3މ}aLߺc>:̤Oz H_tЍ(IAA.vtnq wGk=; =L@$SYV fBmj𩯥lLŪU tU@}\V Mcj7VQ X4r 8Etڗe ~~}v7I0/Ŕ\?zW)~Lj'm{w ~{ci.lPa i;LQ-Z^Ӡn wG$gyMxA5IU:Rt&i;pAQd%Gs /kWLR%H0,d9t,3ٿA`@TS(sW1L0 CoQXNNmF؍boE3 Q^tlB8le]izx0~1_B?4PKM6`Ak[a1\[/j3Ɗ5<(گ :4COXɒdZ†_?X~"Ru Y&'/wjXjߣd>̹wMR~9UyUS||RCX02h`2n{I.JK{c+w]w|4$*^rCOy"|=-2=f Y(g.]sW\LRN vJsg`os Oġx5.EN;]9蔋Ԍb^f>_ںM )?~ȿpх |Fhv 973}o: I>U`Ҹt qH&3NpHZzkwZk Ԙnޭ4yJ)F};4&A!c~8N`Ծ+,k#1̸$UzGƯ@Li_ [әP' +?W 넑Yk] la?Na1ƭI %>F-I-zcY>zÊCkvjf5g}S5w`ޏ#gK& н%#ë%Ӫ܈k|kBz+s < S*j43pM:{:EvR,eJmai`j \J[^Yb\>\ X ћL;t;*8-QH.o;d ,V*.ш /#ǭj™B5EP.:R.2qAgeLQJ߰AS5z {a I'W=Ǖ]>k xujF1n4b  짜p֪(jTQAn4q a'/hU*,'TBi_2P΂~? .&==p#E?OdP+ez+=7vb匡h0E!FmQ=[dgczx</e!G[Ute;sRb'XDefO!XSSlLsnla*ΫLj)1NЗ9QR={U F4 vlsnyy2r=, _g]UG1LhAU*a??3C}O 1?*;Nov60GYܹ=?ꎼFIa=Z1:7&>|[T"p(RBV^Ӯ^T/w]wI\QX! 9߯5!W$心ѣ8!9ϮDH}``rMpy'yP$cdڎl;"8zdrzC+_empC۝e@.M_KrNр'ROgKoѨۅ+P d,$ht H@#wT;hV-fxUVL=[ ݈7s8,j/ Ycs2Vi̇v" 3dI'H*/ 3Tϴ#wdh6hW>61u L6sY/v@orFߨb•ff=yѽFq'^$NuXk`8Mp?cJR\|gD$X Dv١0&!8|i; ?h~&@P{;u8>Y[N%we%g(TA- x'zkJl,Gy:gVi,eeb0M0nb ef>4 T Ӕ nRi#:8R[\iYB# v 1J#t9aʛ) wvr=)YS>hn_V-Np,,q݄]义f^@3A0n*a>fQgs1.Z238MvF&d%5*vWP2vgF\`(et|k,͠Ӗ@nB荏չX||"=MY>1#*:O@&d!Qj,3VOb| ~ ^Do{H!fTgDw?PPʠ}!#d36sN)PW@!KTDgQשZJ^XL޻&c2qђiT]TVF<0JaI/ŜG;ۺTOT?vqƙ҇тe/Xq|Ǿ4Ů%lXl&圳NloFYAlF#s)K"QYyTrP>C%=?U02BVNd5o}էrh7 s?rmFd-銤-d|zT.>w6r5Mb1S#FMT1]a[ cahH-JND;| yN6.zΧc&32@oY:7¹*ZKSG(uMռaTD‰ 䑗;t7G`#,,fx[d`$t_ë((8];I_ͫ<r=Oˌ %kaFOF43Q8fish@*;FSp ̺glkPſZ`D9pJ2q9asEAaV#oa{^0`,xViOоM'mJzsjZg b-Ao6OЊIL\<˾2DI|o&čex&QGѐ[;o+oƱH4+i S{$(Ys bq.m epܙޔn PV诪kk6PgJyRac$˙.?߰ev>hXX$)#4P7ˉY#x? 1T;!gO4Wlv]:Nt\R3ūOZmTFl9_/;rI7ЯQU$ g_ #v@~'Vb*Dr-\%lUESHi0TA\AO6%]vx9`xқ}sI9dIc)" 97PN8kAI;KdTF.I:nWۡ%BtøX~SG^Ӟlҿ!ga%V' #ReZZO~dcZ*+?xEiN06`nC2FS&fM q^wڤ_OSL'9x3S'%V7:X=zM[G`: Id 8,:#pCMg)5\R%Lt-CAb -Ҋ2Ɔ堎kzvM)͉f&xƸjgTLރDq0siM K?EQW)Nhk(8 1)E6$qI̓ ۓ'`PaG ~I`X$Q%+q# (V[&(9' 5W2Uhiq꼚V5Dl 1svb/% WlΊw׏zq@HdA'RhD Pw8_VPv 梔d\dՠ c| j1|\4Z,՚՚"čƔSy RT hsܗ0|-roa8]ݗ^'3EO@lu\ v|a-C((rSkn\;3PRvr:-Rw[!e#h>7 cJ-/ ˈ ѩaVO*H'R 5c_uݕ}r4ZZ%=,.)M{GV*(wkL3ǥ'+!(CN9_)$[=x0#X$ٯ5!coNu6]93h#0uiQf[G0\2CNn~C.u +(B]_$,X+_.)Ԕs5vMVn چI7|i"ʼ,,%c~f)<4c48ItXh\W@<,kV$'ڦ2UߣaMkz˙uǁXm_$6ܘ]r"0Y~D,W=-}Y'ꍃQB7k %Gl;>5s |V?v BV{l$ ?Wgch#D\P\sG8YP*ܩo::V3x3Ђr@(:1RE hTy=ϗeUB$h۬Q+8Pŧ[!]lCZ Nrס^X@譎,jw,m'f$s[_y u/N>Iqܔ"%v \ % @Snt`!0PQOyJ_v ]@ٍ8_~3f!4yo3 T矃B/:Rhx],S+<(j*{h q+:5W#jGkmH*R1bv^cػᐡ%zy H\;ȨLA]oK#P"t-4锍0oˇh?[lMx?x=QN`#A߹Υ!THY&J}UO@!<,p= Мk~%@==3ߒriUxm9Ŀ-o1śg b3'M<ɿfdtMJOu.s4^Ԕ~ VUI%3m_ vM8GX ԡD֜U^D:^E B@*ۯuRbϪ2 NVZ~tIq|:jG&:qC‡:TރaA`hE#0'`N3)sِ"ENi/g֠Gĝc&l@d爛r?{%[ &+G O*YR(Xէ,o;ߺ K7fS!Y)NØ%u_GD )͘Jx܅-XI, Q}sn o#KRQhL#pYDެ(LWq|R!<p~Nx@\O6w?=v]W0E2?1\V"\ىB IW<4Z.` W#'rӮaYB!JNDMy6rBѳr%|C-/ͅAuro(ToM-5$hD?qw>OڸTRsyuۂa 0,u_sssC+V"rN,IBLbmz &%u!s0*5/ D?Wȯ/%}78Fg:ESj?0sqpeEs"5S>M 6ҮF#q.bGfs??3Tmzlr/Oi_}QI(nhv/qw+ D(.RumDPa2>-Ꚗk+3޺_j3(a L?E>tO3_N^B@iS (3q"J ]S9\B)J%#HXfA@P=-~V-mc'IVZZ:7ә]xPݸ׀sgT&dlL/mt& Dv6(=k}0`I-0Pȁ /i Fm}@hN6#(HP旽x0]OGqί@r㉰|"le5-ZE,8-W_І*jyE7^pE$VI>amns-tVYVԂF!fu-(%A sVGeS9~ɖf1&b;H0ٳ*&n̚HHːjuogO#XE&f)#d&Oʾ:WH*qvM/CZO ޤtNVXLތ ^p5=2vPC8i Z3]O 9Z'VxL`DI)'9U5bgJ3 N }yKi\[UԼ ^~Qjʉ1㨛Tdr?Bi( oɰ.cwos&\|I;:9Dmk+} z9#݌ψ<<OJe^RZr+6(@JeUYt7M? h}:uo[ҘMRs"] =O$ǣ7 z6J<x~eL4ǡY܏3 !WcbjxK_kپ"*z tJ(KڙT!Y;C ʈfVTPNi.c=@s`b[Ȓq\40&.gE8FDZў6viun?҂=5ۣ/KDQd?GNV@=?W%SL\!]/-^=΃$[ls>{@6C_9";4H2swŵjk>L0m~Bn:!ʚ1̗vyr"ԕTQE~Ԕ*OdnXfBus߳ Vf=dBswx(ߗxo^xa 쵄;19٧Me CӽᡖA7?W`f"Icn-2}ԐVAvY Lrx'_ZU3ZB;zY R\p|DŽ4@lڐT3d!kJ̍Y:{] z~JtЇPk `y)y74%qwӅK oM9kC|?J3Of^mD s $&m#It $v$@o[_pRxЎ(ܨG܍1QR $&BLe=i45-k. Lpm"}u"yҤ ؠo[Dk@UW^$nwJ'pw;]P 8EZp(ԗ\d G-iwݚh>͠5jRGEJ%GR*&wp9#PrfTY:8`ſHE*7;1Mm(#fp,3I VDZ^H2xt{og DC66s ԢgpSW"zg`0T!e ^ wLdЧAːmňXHJQ@&[ІWIJ@-ªl˔e eL !jwX@N; 8j'}`+Ck! %<2[;`vqq?])0]%՚Og؛N3|UB'^\\;vM*]υmH_U¬]禄J)uUGCE4.{}'ziUP)UЏ35Ӈ"34AE"\[%kR=da*@~nܭX}un<;I0{<`zl(5P_վwpQ/~11:',7L„݇A5~+aU&:V8#?dDy7TS]3M ֱsRmZ;)vz2T,&)2@HD& ,If}ϐQ X.a?*|x9PetoV|TeJV4]P->eH3j405ʯ^k *YQǃjF5f96.)DR i/ӵ%0sTţ.f?"xEh!{Z.}F&u! E(fq#9_Qa<+ 5JjA0[-pɱٍop7| F WMTDFJU 0 wR %C9}:cH3Zq1fvA׼~6mւfo?_E8q&fBuv_Ѥa flY9 X4P1&30d ?It*a$LC!)j͑ս|'@7x{o}z;E7QimCե0A\zʍ!@q ^+jte(O6*g52et~rX#5T(y&XIb8! \)˵8 ?ĸxdijVMl=ĘΉid;I,XFV0_y"a !e03[n9ѐ9{^ ^OrQ%z?GE";IRWWr`,&.,"UzDJ#4^2N42~y–;\ Bt1 'L{BLh+E(̈a~nTx=*GJPe߁<0km j3tp v"ga-0[?sƺ\8 owCxɉ,'OGijmdH"M4e>:N"i#8S3¯{T"^(nI~g!sΐo@$n2IJp稤~!F_\q8=^)2Ƽ[Bfwo>F{QI-5#%ck*JNVӮކz XRj[mA%*7" ,.r!YJU{9FlWS lZQ:ߝZ麓rW [ ߞLi3 ߒfHZkh]tܵv4e,Hx< 맊}~^Oid W{焖N` Z]c|-2/^O; oS_"[LdK'Q^ seG-ZJA:R5><,Pк&P!Fle_M<~hYYzY BP3dx~_qw/nHkɒܱ&yܷMjwp#9bd6g-QQΰh@EuDJD޸"ϟ7o:uD7% ;|AXR (V^)(bfjB5´:>c<"Rlc`f \,YBCb.#R _R@M[), q3tSB@͏h:aLbWO֢crZU L&M:̂ S;Ǘ<<4=ۧEqgV=[P`4ݯ|@]<8FPm"!:wZdMn|t4&,5<Ώw_ A0BT B$3RY 2>l ~..O1hs8bC1Ś(x T3 fS$t# B55C# ؀o[tjx\leE+>yh_)->&W}?bÃ3ЬK`yOQ `q[`RK`ՍD\`3X)`-A5M~kerg˸SƋv>ffҐmX]-F:RC7;O_:Hq+S@dxMw3qSQZ<p&E5UT Sm.6ޙ8؂]}WF$&|k.XOwU*uݐxPZ, xN8&3vH,,Tekkj$A?8|Q"mP`_ְ3s< 3$i1r |0j 8V>s] ү^Op|L&VaK5$45&tÄNBjg{˂p?gyT pi:=))LDf~}1d Aa Zwt 6zoK % Hݼځ` Tku3;" 5xJa_ 8w -e#x잾>4DʶaOÍ0u84cdz jOiǛ5Nce8xe.\@0[ˎ܈T$-XalxO p64.`S+Z~DFL y#XMSXwLJE|jB+ f ;3b͑ocJĶT.C}cIk%|gj2 5d\Jah~4BJB, [.*e9Y0*'“m)C\iwȆ*3\`k;h>FWףNGɝhDt?˾B׵(P/{c],S[5]iE}QH0ulmT]p#VMo;eLY 9Ȅ@eHn+nL j>bsFPrrTֲG9=pPϢ E~#־5[qOʝB颗`|@%5Wkf` W )Yǃz'K.YT窑?f2{/svTG/S-H!p]!Xh!6D@KE}xe MUVq@{sgDS$#9Yƙr4ԡ!`v9yz|IviNqj֮B1LY6 -yuۇM M<Z+9!A^2U$KUDpfp!I_ ڢMt7Ū2d2'#3>;|G[\Nˤ[`$~A~a]7 )idaFY":B&%T8auYGND745(:Pg+4ĉtECg\~* j5H͝mח2Tun=c#z4dCQ`(dz} sԑ idRڵ\Xf0{7<` O_ 9 O*M׸kT^zq[5^ Hsn<K:X]NA캱.Z/ZYۆ7ޗ-}IY6TT*OnE(0yĤN.9b4#9JE~L1'OЋl" تn̰^grPؙR..'KĎg{y#%b; F&796Oф9^֜P6[O#lCVY&۹JaBu3Pxy #$eyy% A;}݆%njWO@ x}_1qQ#Kq'q ](v\Ibƪ)s~]|2'zPU[Gv0lYIj=~alEaop`RPfO3N 4o^ ™2L:5Η{PZ5zx1Sk{>tt xaeB^8b&V B.0D ;t3>0s)Dx&OH 3> L|;Qԛ+e|ꛮ;,((x苎gvb ʧ;IZóͣ(_sJbH[ƲT × 1m0N2ޕժ2%ʀNwo5F)\GWD /63sE$V.1S@D˲xga;1S̛KcS0*<\r*v`2nHs`5k$yNYEa!xAw1~,6oǖR ʠLn!,Y)Z[ܢPz&c>y--doA:Ez@NqDYMފl)SJvKuzԥz2BT|̻eLSL#0" & jpf_e8K!0UAP0H?@)/?(6Ӿ;Oå-'{q,{,~U<=6l#=qgX幦rJbO}`Ms58@n?ԼICp'8rvy:H>l?'TQ9WrfSKF`. %Ve{3%3%AT~ZRX"5u*vNh0ߗ]uvz^Rt(hb֦JY)+y^KF:Tࡖ^t={7Ag9Pk)l5b Wi@;2Ej`Z Lctp{1:z IfN IS䂫DxKL(s52:,R:1긨`H9lL͍4Ċ Ž1y4;N |R~zNfcɀwu.!*յ2(QK S$Y|Ym-V?'5k!_4iWGT\\؄IϷ:f]*`'T>ѢCRvzes3&PÎ'.5o8'Wn'uV]$X.87٩ oqOL,vj V dԠ"a)Pmfŀ{waͬW.Nwy`:FdnHh+OX㺉xVjCR69\QMф͌9'*[[ 8=:>{$qpĔ:IC!;jBZL}ZOnƲGP3u5Pl@ŹX^nOHt읎>=S+Kx ix7N!{0 heZAa]m?cV՗_,6{!^c);gC7 5&!T+ȭpR0om[? j%#[ ݋3/b-yOg.35n+;T1U •9,Ma++hR;MN-Ԭ3Cc&ν̑ F@$bA+Sew0D{zAF)6* ˏ|=vOt 8,n >ajk<4҄YWp~+VtN3qO3L$Mtq*,947|&uͬ:"#o L2ia-8b{4F+'+îWq|زD8gIN -k}1/BeasYY/u!?p(se> u|P"KWoBfn1FHm<ٵsRV.R=0׼o_CrjWaFLO ]*R;Z[l۵l׵"RP/-f`&i8119IooJ oNuE8OP+iq6g;Qv>ɭ#) +F%g3EPHU ҦbDgA LPSң 2 uvNܴt PzN,(`%QD[.HΙ D!/ztB":ōG IqMJm _u!G"^TV+\kP?8WeQ 0a}}S:%K{_t:s+f"+lWcK$@Mi}Y^_b/ 6bK#7QJ:M#z dhrc}yѐҵѩ1qq6Z%MzNwK(=V/L\jp%ope׷]?#2$A ɠ(2[Xz/l72OՅVC+Aqc+kňը/J^o|v8}~aۍYA8L4PC Q"M^fbc޵.q42 x`㝣F9n%R$n2#Yu(r:(LO8ad8s"6OJDZ ږ{5 1 &;dƟ}H 8,lҴGp串W;DyZ$%l ۹_MPUѫ5?M1 'x[pЪe֤a?7Adpe롞06%:~tqjr>ےO&oq_̉3?1Cu,!3pv6<+*ioG"e)eľO d6FU~_ebbB$wYoU0e[jT+{^q*g#r@T+`4t w:\Q.e"cc<Կ{X+1omug׮~тq)_شZGpL T @.q|jK#uPfKJPqn'LMyky: Sow"y<;,Ѓx@޳K65SOakW- +-C($b6&Ε?y7 8c,o@ I6ǒ.To n˽c8?68gRUۋtfJQUk&=Iۈ_&)nwk k3;gm*Ƭ0Y2jdrCu1/l~ ۷.+|UWeWՐhet 3e&Xٴrc㦀&)߽>K.%όqzlf$FF4OMG>xoJf͉[l&\L#Y4+`WьgP2򸷭"i7&[EFR?!=Sٱ!r #UmE<kؓnCkn.DYϿ1L>ESzZ}ikEhd(*!fg:_6 a#MbлD[{ 6?ɥN] 'JͲ;5T[&|њ} S &!;ڝS};2JY/ݵP>\qNLaG!C/0qn,x@9{#N%f^YܰG"8DOA0R7Y\a[Nz񎙛.eI695}p{ 7XG^x(=2dUeMMys]Y?R%)> %wG=OUqTA85-|67JL:6~$Zc6V,uu(8o"EG":[ >BL;V]fͧIZ0G;n~+NE+ =ҖB޴+ɑ7t] pӧmJJ^Y&]c`9EB:Z;IikgH՝vEbI#7́hAg#=n9#5Ģr|>J1jb!.xK܄5VĄ܉^ӺW aBtNA0v°g1߶Pq ,}ZVoYYIs} y`BLryR Umt(B<`9@=+pAb4Qοz~|apq=W{6UXt#)y*`HAE&Uksr+ҍI5|>QIc?9ԫCO)m 5_aO퐪r):́&Uunc7jΕTo^"4wL>{2dDDLj\J̥^Hz[Pu54eUt}qDCPNCqx_g҅OZz֓$ QEEFjױ-9&F.>fF,Kua bS *Q}r@d/ijpo^C,LE+^zPw4BԿPMp'kK+ѲUlrpDմ,_p_5|﨤cR|Yv Q6<=5t: W1[VVRL$u_id~s,r3Ÿ89d]}z($ÃɝB i.˨Qn$[})kz߬=֦)sk@tII>̚^o,;]D>T\X$3-ɮ/ϔ[7e,@?_3?tbW]cnrğ [_T)<3œOf:G]̌uI|nQV$_lK%ecP95TPIfJD@kMkXB}h_d"nG(6ۙOw7P@ xPhsra08YbƃLqcACF"8J~p]vg/(Ǎ,3ѯteGZdCNkJP'[ A U >v2ywc:N}Wb"nhwt ~"57+1b_+{<f6pzDwǮL<%Ç|ģ)SGjlP 휡NIi*Z|QP.y2{cB;+u*"|ݬC9Y( |bzQh Z`k'=5yZ!X Xqx ^6iv 8X>xAS|9tQ^֧mz< |sR.6?!9XbT-ZOKlpƢN =~O4Nq?92mI4|6J#3oc)~9Ǜ(,-]xF6'cTh^]F^ m*/47Dk1`~Imk{Hpdg DfйWU2Vҩ/E JCշoWɧb0`{;2[Vc2/]4NQ79כgFć"NKy7JOԥ- Iv4vnfKE L;)OޅWԼD'*oA߮+ȅSH:6> B`Ǚȶ%KmȁNCc12d7ik*:p:@ A\5JU qhĚ0Mmtߴ lRF 賴e`=KzЮ_s3mMdž_3t4A ;/|AOp%V(&A8yWgEn1@8|?w!.3}@g|J9Q 鳴|ٛ􎡽1Wv1  ٖYMK[|錃3gC;ŁN eA3U}]P 0xg%'rtR)V+D=Ptɦ+tnciaq J˂i#ww|Y$Uu=@YCG?gy~B[AcV Rc(*݇d|^a9ތ@LmځG.Խncmt4#q&.mQb3ךzN^`)/r 7f!n>CIH+y9R˫\0v'KJ,'yҎ| sWҿ6;~!R ^")fDT=ԴiT ?W]~mê4){lT},g4mƭe01ns`gzϭXEߪX0o晷[J>O"\oy[N 073u"؂89aX!uڙ0ZA rt|:ޠ8$u 6FfӝrG Eq)t3Ŕv8e*kGd2d&/&5]~@lɄ7l.l|.IoĿiXB |de{zu [[ ޝ&.8:J!x&,~VKO#*!Cac#b %X dI{u{VQ҇XHOQx}qh$]I5|1+aۭjs5C#P&'|F۩.}5f"?Nhޕ 5zgoSFȠ/G0$DĢ]lJ:t0[@`h5+mΐ968ㄱ!.6bVMx܆ 6<9Y˔^Y^AeSvu0_;}s-~B5K]3܈ 3 ehh.[W-VYJ Wl7ϫ #UɟT ghhǞ=dz޺BrѿЦ xTy k`-=EDU mGj'/%aOΝOBdw}*N)jR@*—<ʛjZ]G1?y>$!IrՀ g pE-8+@V)޽ k1Y(ТbgʨHO~YfH9RհˢFӿ?Z jGNe!Qs1i0  }0»eDm>X\Uve TNy?ï#y#:UK;U ´t ({&^/P#Ba\"Ռj}al5w9%O?yMHܘ\'qǗۈvg 1Vl.O1O9 Nجࠌ5dWvZFyץƓR3Ý?3=†[iU4\%UVxg5vk)N آZL2 %<~@|Y``01uFo&.LC^HLW9}n/2njZnvMh"ܙt;?,ϓs$ut"3*TQ#4(Kc3}ǰ6_-`oB: MOoi{={&b jT]^yT4;=<ڡ>UϏRjfj c'DJh!@ bBREZjԁ[I# mV7.@'_Δ`A!UBVO~/4o!yڱSIСTl77dwQy7ljwdE*p :*$u3\mxk &(r쇃!Ц+iw/K|'w lnB?fJ(G#yL GIJ=Lѩ,Gnhr'J PsWz?z`wo_K'41򿌛CmR"nScn~_z=F`3 [NTUJ`ExZ8:dڎv#X'GqC%_aaGw?:5i$>P3`žRt N[9TDY惬<6NPóKFsTBmxr@q%:5D|7FGBAU{3ˣwc{GY K]ftf2n7 4)&IXrz=䂗^}?GIpLO]ZFFob&ݵ9cc@ 9u_|P[zz<˧)2 J8PE i>ڪ&'$Jv&Ck[<:o>z4d^mYHu7KfE <!c0)Kg;JV97x:hAx_{uTS^U}φw_a ԂX}銙|Zu"ܰ˖ w$6xzR sA[!誸X|@MGF{)BnN2p3O ['[s&?WҒ7B}hAFO_ܪD/bcʶhL``ݵ~̫sB~lxÌa3VC8o9Cmu6( BL5ٌ7Ԓ1&&B "3ɜ^-@ VH?9ŏΪ wR h+2CscG*OufH}cKʃD7$MƗL0@[B-& [GOPҲL^sل]E?SuxԀ;IJwx !;, Zc՛Cf{|z?DZB*"q@d>ԺTRVīJ\Hgn!QHm٩^mwEUVQd_;,l3k˸Ȟ A,u ~v̓jnNܤuYu+[*]?5|B= s:(/A`0KN3J/.W*p\hE[zCƬW$ݔKE; cgf8鐼N<Ԝ|ԉDa!]hܢ]$pW{zV5[W3HE6) -5h<Η^U ݵYp23-M5HB^+/_"ҪY75י\O[\8eTrď~ؑ[G%J}}xF'ƒSfQ:ݱİG)S#麪iVZ͆T"+o4w< /ǥb}؟M?7vAewY/YI0`QN r7zJ^d̽PX pq~-zhEOT۷ *}Ϊ%N´!'LqD4jSwꖬ_X"%c_te&v߰I(vRmi[dsC{Ⱥ[?&^YҐCULO7*I)Hb^YAhx=_D^&Dh0T^C aw#! ))~; wݾ_NQ _I&K`3 )2[ 1<_ p#o,ࡾkCo:sqzkۿsT; R3bL3sTBSUx7XxaWH-!T @q#AY;S~5\UYvͺOszѴĤ; p6E_q<88D^'h(f%K a,K:|,OAFg26aXDhnD_,@́yA\OB3VxJ2sSk1A%BG2_v'gUed~wI(:wk)n/RXnqPrj+2_|q{}o<#ܥ;ٞD-g=pu|?mA=[])`hgFqqZ?\g3;]3ǻ 5NQtXȠ.Kb|p{1@iQЬnC8_d1?C["eoGQ8T):4bsP2Z|S3X1E-!k~ ?1 Ra6=jn_`ERG\3w8!ag33EE4Q3qYJ8r v-|g!^nZz@^ b&&[4%qpXGB5bm"Z*\@ze1Xd)hفM$j+E5ӊB{.nu{ǻ6e@T,(;Cb$F@c;꟩fj@"aBFmPw|\)69t{{.ONHȋLtG~@r"36<'qHyJ.ܔ-,ipkOk jgU7}2kǀP#E!r+]@q2@]°drXt!Ɏ`byOIe#'x0mNt hl4Z?٭#- &A>j@h04qe'z S_2vnb50$"G$r40\} dXb^}5J`Nb7Z6}'e`f ?t|4L,sh85p"5@YX̑|+w8VtBn7 w+6Uz|]%ViAӓ5Fj ndj"(y?UimhP m5ii$z85flw_㐹\ щ>yDt +5(Izx~:̳r'us޻C;_Q浙:*W*n}ejB:<@uqGǣ .74q BQAzόxخ{D'[G:2 `x#\gp~@`:$4:ǾG?C LLq}1C9{wu'B3Q]0, |\fH"x6ScNX{b$OˬÚpNMF1K`wx[Q'=f]ˡ\7_q@ם `x ^(؅nt%|%+fDqW+(ҷ2cwܧˎx5 ~9"rZ(uؽ Z NK&r_ o.ix NU>Q3;XD}Ac~ Q#$1>_ZcvG?[xuXpyiv_>i)1I;c C$`مc[0Z2OŎ)9Bt`AzoW%|l9L7]Ԭ}%8zWDqNpBXk: NJ"CJd/&p(7cVc!̽\h ߢڹsUP8~VԽ6$& ۊwpv 8NKʝ<=nh-@˘3*zfokJr.rIRJB^7*H/&QX<RS]ڌ06RS7h>NHwe#В{kVw=ZTzlf#s?iӲ*[o5.J|s_zmwx$|=ocG(3 gXayT~AsYlRGK}r><%F ۃUS$-W B]`+`a5BVxIM?K:(>4SI=u6yЖ7lmMҒt׭jmGcrE`:'.|38ĽfIx/K7'xlC3—'duWU^!J!kE*73@@?6~"V/ZsY0@Ys80Hu+rdun`e֫hg yq[m 1zuM8ɗi=luEgS̓vPf12AVXQpkYqbTYifVpxaD'pHFEu8i;W\RZq.acd]FN" ʢ5:΀Ksئ>Y|v!爧l tz8ﻖC|qľfV(@~f᳝q^lI'3k0r0&MHZh{膔,Ia-V<#]m`R3w0jK[l=)_PmgFEhbaDפY-r~WZ߮,M_Z @;؜~7YZ3B*#$P* {L(j%$jD U"\>Rm L>j.D\^r8?,sJLLpNbqcP4Ek't3~: d_ȫFnIgZJ8'ƉPwX~4]uC=:rE٣Btsohҝ$Xqҡ[c ȼyHClѴ\k|Uk)}Cg}ۣ"bW磄 W׌?#ӄ6 5F! =]mU 3quf||ue{mL!.fU<QKgV`#C^cn 74^U4[ T:4YtH.Ynלr_[^4?["y3 cD"J.,X\͂H8E]K@d T&lI[+i"!ưa4&,1(p8Qr62N+K`Qmo4\6,'pd?Cҕc`7 z[nLu j+M :Hτ0W^62F *XG[nO{[Ht蛯T_ x~? AgHp̨0sSo1.6'E%=R&ye/#\yFڕg uѢg lvbi-)v\mJө/mqsضb_6ξ7<ݪuިBx,L1S2 '2 U ڋjU˪@Q+zP8 zkB+5%޼a- W1&WN0ѰY5Δ( @Ւg:׳|3VSdk&^`[rQx dϹ1c+ޢ1`+Fϭ9b#R~F%h/瓌h(7O}*4Jd/Py\rr.Fm }:%V'f˱U{*l K&( aC09"$wx2xH<9 +n2twp6:5c&焨+W7ܓ[(c{*-2+B$[U6=(oX^%9dG<@d<s2&)ҬGmgeڣgA;UWkmم-Դ74Ɵ+[geRrϛdžگdiO䢱'j2ZPF\*9}r>+e:gV?TTPʗPx hPUh-F ]kmQAsE?+D܀aDUFQ^ܰrOřlmrB)1{v;/Ǿoowѫi] +3ZAq)[pkfsz՗o %o%ҵ}rk|OQ] ǭ1'P+9k`ki0SrGcv_P\>_Ƚ=VI5ZfZ8ᰀи5ƢN// 4S-ugÝ&#!IGΦtkH0&tHX@䌟Rxg~sl R9/SHiY'Qu )r=K9A?0ET=H]ΦKO#g_DXe'k d)g  "=LHÁA0w._D!.aYA}*z]f7lo7@I? w=j?jh6^Zd~+"̍C~ъ_(2Kc`:\|v'Gj%NGyc.'bA"4XB''Ѐ^]{ }~!2sXYKMtgNZwdiAoB=_BU2 88:3m^(jg嚜P}'c;Ul^|EC+| 2 kLZV{ 1'0@ 1J VpĸgCuEKʗ6j6`6Y+Ou<\Q(]F$$ XȶCw~L M L(KPN3D@ ^h&&ψ(P %-vŸ-멡vMe(Jӻ^1ވz(Mn^ C*6Cզ%$o5)8,(8$X!27H-?] d1:A۸!,X' ج;vhk}=;EC] p4wo\5] p*ovAqnBz|p@3Vc]E^4@9*FA W>$\L`.utެcO{  OH^n9" @L9> [ȭ)&v3#'11fq_<ӨE&)X嬦Go z<:V Ӣ,E6Q&@_&D-'sY|-pAȳ:΂ґI5E$S&@&:Wj/魳+(?6pO<)8pVb<ۘ8@U K**M$7Ef4M?;TDPC!5) sDtvBh (NUy?銑fIૅ$A!k*بP -gZ37vV$;LMZ hr2\)LT N?|TJP:T^gm֙p{W6"YD2tfRoIQByRcCQr$Kɉzk4 uMcz siTrD7/} Hb;roQ|sJr(%AQCg6/3{???YR *q",m@;]@)3ݼiDvvrC8}99F6O$wUa.gc qR!8D3'PVޏz;v'481r"h(YU3iFq͍vটLȿy&ܼzuAϼm\xRF6 U!LO` 9 -k) eE&=J~Վs,Ji(CC_"?A c< ~~vY95LPG|Ke LV7?3fIOH4{ RD14+ -Vl ^>ysռh,"w}?P'.SާQUS ATUĭnͦPZ(|-Uo浉YaCǃS&bX6}8̐5['8'E`n`& "ĬD' ;fr9腻'KI+,16 {4a۬agxq(_#j`2Pט@˯녲Zq\SN6_\/Z*tu+exoc7)z:O_GR; Ek߅݊SwW/pg-Vg`ޤ&2p5Ɣ P1cR)*Rd5qNqB")SERX6+|r q|Q n=oާڍǀ-+fdMn|8t$Vm%h.Kny$h?p7MvmXu.ZO0Aq'%c`kh=P=p dI&ύ d܀+j5?SOzRt2d1A(stΣ0 't"vH1ƀ#h\SlLEýk<O&J P@{yE6N45jGmMoyM>QܦԵ֥^b%S9oZDo@UܶjdWS2dBhy_#X%dogc# !)7٘_}߲a;R d+s LniC-:nF$e6p,J*_A~s|@g*tX"6uƕ~@.=s XAȱI~ИN"(_DEug`0(< "9"&[S =fo(*feDt~"NE[xd^ʣ-5C tO,]8\D-=Iţy%2~>%rψ7O $F=s:M|6+u8(|8Ä79aݳ٠j0-4jatlATH+H;,s^ ҈=MKN/:KLPTZYvܠ{D7bk/ (laKCP1׈FsNY,+q]$zvT5bsm֣D? S:>u P 8b0n@ :P4+ zܦ{ JbmFj?p@nfЖ~AyPOh8A&`=tg:%\J˂ْtSžQq $U&,=F%8` ]=K4iEaj4 JfdOLrҒK,bbdڻs,*uɑ@#az8b(V& viwDoQw RA0u+Dǫ}uB- I"f ֵ,]Kνxn LU~>_v{0gzZpxFXo(B~S#~_keuQxFC? ִl|CSdyZ} d8dA鬗hʵ2dH vMmꨣkp#T@-WK]q_ч@uGb>sJJ/%ϯG:tw Ŏ~p>Hc5&YC@ Nf l8<H]G=MZ&QR-61_wO^4 x*Yxn4vPyiWH{{Zh6b[ӏCwAF[8[۹:+u4к'ܷ!"!A# iJMDN{~;䜥mGZ bN[Gԇ\@4K"4Qq-&\2Ra[ڶչ@yPEr\Tc2,XpF$_ca&}=e2ԫF 3/ҥ-Dz LVt @x6.Z~ܞ"Dd15Qb< %>-{+u`B֚C In4 Ӌc8N49 fLSDj"Thݾ-$ ջbR18xOBUF8voD-+CĤ'c~Z[I D\keGHKqwTfYZ /Mv ǷVNZ)(ʤ!{!~O֍9П3"ſ.ʨpPi.A Ɉug4fi \ C;Rnj\FYDfP^¾x;{<bxLؖOwNC;ny?NݦZƵg_*IPvd,:q%EUv5E\{Sq. da%F` .M\(ܽa[vSE lP 㫊wEfiI`3F0։UqWHs92k?ؒ;s-ӵJEc!Glqj#hڷړ "215MS$sWsDu&m B brܹ u1dXie4D>u&U_-[IȽ#FٳC)ȒT6jn\%^BZJTnIoXF_SP. >+̲ 0lWq>RV`l@٧Kzup1lc[RRZ<g#ֶ K"k-;TߌZuOYk! ވ؉!}2.lKZ^ǼSaGɜ2|"A:g( ճ>7eǙaz "7L$\-"`DyZO-7n $к!v=M^T%2AÌ*G֪-cHBF%1,#̖%윓DLJg AGH ya@ W, tm nزœ L<$g:bwҵTth03·^ =zq ܼLomkWn~+cZsQ=yB"H )!XSUú}YB>|aQjgtÆKveGz=*9x *T䳿&T| J?wI?p,2ԱtP0"l˼꭭0bӷO_a̯ÁQ6 $A&b~SzC»֬J Ǥ1q"&]jn 7gή+BJȩy ė\<#Gw$ Mxه=ViKp2g?ÃB̜;g S\UXG<I8&J+ 掳02g^zDP;ȅ,L+z$IiE])&!aC-O 6ktT&htөbcYxm?$r#*DT[Ƀ-D8y}hZr)TIPԯ f`)W1lR( 7-Ge x.6ڤa k`ђq^n_]__ '!#;0ZD&_Z 2R;eo|\|jgx-'\د O/ Af <|UFڴ7iׅ,ŋ٣Md"ܫKVpb5iiN?$h1RSaԐ@hZ*̹w²R0XwW]Q6Nz ;*Ř/q $i6a &Dnp-W!,'oOa\׺5V#dq-N% -#鑍:HR)uj:ކuH{ d!__WXjb'Cv_r$bT4.clפj`f~Q!(KW^'*nBxWS$H> ZݾY1EwMhW2?aN rJSEGCݓ%㼸.qlEp˥)+3%:M> VE[e&= ? =6;:{gF֓ұ%AوٚW Y4jӱ.8s^ vYVEU^iNhsDAovm!FT<z1m(!^fNO;1\lTuMnXw=*ʴXx7V<46S^0˽Ukb$b5#\5̲wC߫B~I;)`#YTanb?us]2ΝQs7Laio>nX!nRG"W؛" ;vҝX>a1(D%Lܔd'lkq77NC,'hÈm]Gi@i;D5{"KtӲr5(3;YkLJ ͷĜyDPKYΟDꃵfM݁?ר PODB&rjF`(BR1wKv6VdÕjv8(԰V27֛j>& eT$˯(W#v%l'(=;h8rᑨҺxdߊT_۝)t#U97gRrE%02&l{< *ҟ˧2~+M2Qܧ@|% \+6 LxL%lyG(S)Hm진^x4Lj6{8͜g$h3A8#'+7=PHe}Z>Ƞ䰓9KZ8_N*bc襍Gcp A'EKPc:^FZc5X vջ \5aݓPyft6Rip:Iʷ4XgXRsTk<r 5U{ vsd -k&A8QT{oo?BP"j|aaM4^nЪS_XdLjm<81 /Vྶ٦b D)'/1.6+ABe*U*~T~͙&xDm#3Ji}m}6HQOT6%t9"zW_0TeĨ=mF,ø(or1ar?1))p8 nϹky=z9n~=wm/He# emgCF E)gl~c[z0BTk>nhsޝNEbJ!ֻBJay|lUG z4Fv'xl8\/k|0)biK!0/H9!TQe YR@sl!LE =qJ%/ŠJ'n\؇9ÉTmuDCsyJ] qjBR9PAWz'(l< ' iaaofp~"Xd.∴ʗgB+!'hV4e#Qc,Oos:luN?*gz > wk>d5e0(It鷆rzh4tO &)@ӵ i saYYJ\*=h1kUgĕZ&,b[@Kh55ˢz]yD!LR.T_=`(P@o5I8T:Mʶ>Kl2搹[ϐ3 }fTMG% ?wvZN_t䇒T9؆?n7,|w٭ڧ;: م[F?KKr|_6K /*%R׈J^I_1I|\ʤ(1l̫TsD!fJH>z=χ t#CELO6C | :pea3@Pf$}iߡ[>3ӞUv$ؐ(xXܥg˿ibm:OZ@T k{.<$[xN-zhQb9m<;ǜp[T‰䡲$OU8_!l.O(&Cy8yļӿ ۡf!zpt*mumj q6>l Y(ڪQT`Ɥ]]TSr|(m =xQ0ԏsbVV$VV6$gഝ9n}i4M8IȽB(jXO%Occ+9 oy&T'ۋjS E&V[F{3M!Z4.D%8ݕ7Č9H&xcNF;09mqhJl/7}{uqtlx!95%+^Z6TX0A≜K:ùi– "Gl +sշo*BcAu/-ɸi}D ?;3hw&+PEXI!7t$GUU?|c?D:a^g?^s>?n.}{w ;ۣg#0:4<'ȾO})Ln12<-ZRX @[s.t h3);d Wm*w<r|ZΏ^I23ɠNސH}G8&RbnV )BE"P7ds8 wSm2@*$\[`o YW#\MR[ }ŧ3uil==^Ee"qBVq3Ȧs 6E  ?ۘ6Y#j`Lbmv) o0ΥCԎ@cܓEzӊ4 GFU z}_uK]IpFdRbuSV&ZFod:dro8.79u6[>^.= ߻5YE)(sc ڏT?ߍG_%;r{x9yOIJwwP+ \XOZ+J|3խڠQ06{l}r4;,E#yqT:ڙEq&Bx#*ʵ9dZ ̟wek X!L'Qr|w3q˘yk1B_oX\ogG%;t+`x ғYyykk{ 14hZe2Ӝ[IfyWpsB˶ZK_X:LֹE5K%H#X{R ^䗶A(/@0LVPGv b@E_0I176"m$[{6\6uЃݡ`< C[KjtX oJL߿O%Zn}/V*c h!HRq}!|/*u"֒ 7 ?0:06qw`_Z|/&N;gQRT"&K Ng8l!xyv(&D`2aIJC":K=(C,-| 'yfV4t $UFkVL%T S#*];JH5g=*G eSOgюW2,r2Ñ@`!_ 8j $kT\Ք.Z qŬ /)u0oZ:Aaw[gFڞҊ׈udtRzC3']l.ʎ݈S}qt^nHz:n[qM U&nEOKJp$~/fRg!!W̾6abyƦ#a0:2E rKnvFp84(iϖ~ v3296p(sF%j]SuA9(HQuҁY& Q"BԞˇo&˰li-v|3!$û>CN|gv'5[%cWqyz@+9ElQOŖ ei  ~{cEƹֲc;g)HW5'~6"dؾpB+S~/ԼŴb]/oD]k {EN-aln2 %.I`6ܕ`+ ]Z<0^!#qe$*l͑\ ,AT K3)VuvH)]P[To-&Ss#;aGeLR>%tZiq_g~W TʆEOx~0zŎZ7#hu(}FFU2O@4s)b 1hRyP]yi>+vKB3sRϷxCu4z=ة^*;?zh6 '@`-Ж =5,*Hr Yr6,w;Gؐv̄?LzR, V 0# {C%"#75Vh@;tg7{G()kmwd)PCѶxx?ʠ _sOsҤnt6(,7d) ^sHjyeu[\&Lic7K l!g}V=PCY=+}t !"a{Ěz!gmbs6( '7}>KqE2RrX d5X>a@k$.SN?CPtf*"4&B>3L&{[/@ 4aW΍vjTy!A<{1st.7ߴYg_0:%xQ-Kˢ>rƌMD;c+ݠGse1&mR x.70ӓ 0|qJНwcer_۫`eӯ, ꗏQ#q0eRd-ـrZ"|Ow%hJۜ_Xv9q&ȀiHet6$ԅb]Py: R)&YΡӽߘSi*А.;债G nA X j {]:̝<#bTcy#ua_+=cۢ>hN|h,6fDmmN]LMNE}#U͊EH.jXf )`5 JspK|oRX"ʏ4j"3pFNUK$Vb}{X/M9$ "m=)Gܥސc uCǁ41VV_A זeT8< )5,99{ia]YTJ{Ž$>uJ<KpmO=#cě4W oQp."?Pri։<@-vL3 ge% DEuνvϪ{:#7vy_Dݙʟ¢3O;gސ6$!oJA,0QVIE7%#ߏLQbҁM:ndqEzNO JUwX(FNtveK_"MRƽ2%N#kD'uR[Olu,co2tLV0PF ldsNcbYjjQ/#D-~b8Z);ȋxUiIVfb<|mBVJ*h:]򼃵RG1&Y=Mq&MNv@+w8Xf6[[!r>@C4!dJk ؾdkT򱞾p BG[a篿] [zYQv yK$@RY7 [ &cjBD@̥(vcZtQ}J+(i ߿GCsg]SzR n Q^ǎjmӣ'VΈ:͊Gc@\x:\wYo1*{!5cQ+/ܯٍAy4u(sT<`G,% hu/>F#O(H_a]#unݼ$Zl. e9Wr6V@ <)e$W1t>G "VZ_V9X,VICCd$|a/3n(.2\&&9IjݳMc1ŝ^z}la_F,y!xmF#S9sgʕz ɢ *Xܠ2w7wc,<2-\vF6_l'od$~7?QųǁB%xC4+NGhek}g%P+ p_n)6HyuEB꦳~uHYǢQcx벥qx7A4]Rm/~t={Pʗue }'Ѣ"Ï),q}GSڝtyR舳%B0fEt*]#g?nkQH>s[c\#L z"Δ9kJ,´OD8v1H0s㖓2h`g#|!ǔtUO^4rޚig]@c69~_``mw7DƉ>$`P8zt6|/y:J1Yٛ/.MVu.&0(m??|pW9!So{d IIeD{E !hb *TJǐf˜ᱫj!21rާrv$؇aJ"]"HW.u緂:s8{HussnD8"Vi$G&s!):MZCv{)C*uЄ#hHhLD;cs70K40}lE yvS#{f >_m mR0LĚTaT"-yX~/ +Y?0ۦٳ SÄ»z 栅ӐX |I>HY+%:.q7z/(! Lṭ9ZhRp !20;?QėB?B(,C:M|DwԌ*Qߙ g O32ݳ%7EEf4fǸ!,oK˽RQ ?D~KZ,(n/2\m>$`*&9 Z+ D"?#Ra'wQ(:{J*hi m(̝{8[~ϳҌ0/pE3^^sq7si91' ږ[+/jCBSk7-/K׺I{<5uf|$5F{_[^(V+3vC~xTFS /"=gb$$ 8PbF4 lRx)?Q,Q%Bwooy%[Cep5G&%Yb];+w+uc3n;KF\6 KxJ7\udȖeR>#ITNJ ݮO֧zxk̻EV8yp#ywwo b ][ 2[@'ɭ筃 aBV|M(E<[ 0;(*|'QjtTwC[C/'^]xh2wa|RKZBVzo9'v˩]*= $"&5ĝkx>G在d }|Л,C?xn<l̖9qBn{9GPDZAZ6)^wC c~v3UD =SUU|:?5! {E1ڑјӿw_WQEF%vz7ʵa.jS|!|E2Q{H^oY%0k$QLT7ZBI:R4z7E{.|Έ9xz-)'@|@A4FF["6N <CYxuY.ס2qo)|p!f$|M5}[` E[nߍKi'V'񖻌gMuۖt<Vi D 7RƓ dF'>rK0> )Xî69 ')N[;]f G-'e=QR)GpR\'0;ޠė`Co& 6}땦 b'hi4ǡa`|l L/*˧!Lday^6Khm$zU܆#|6P-3[~ L>|՟/٩@ I>tъp6䈧{K]a [Ջ#[y &l.TE's(Ժpk;_̡biиqQ3oA'\/9 \Qiʄ]F0M\}ܺKjRՂ{>?|j[&!ZPلBV"',e;!`qJHP?@}4ˆEM.P pr$դC.fJ[ |ʮWS)g`#'vԉV mP祾xIi7jw}&J)9GՂ@]'`7TC_lC  h6_9?׏G}/3Dn,`f9 blzMtqge %_^4'v[-B^y -m8\Pn(IM!aQHl~tmL4i:c–s2TIϥug{%jb5ߌ*ʂN*yQ}bÚ .aқ6f@ϕ pƜ)mnr)ɓ7Ӊ95^f,]8)'GGUt#LrD'͏3u`Lo`; *;_QL ylO lKc`PKNv7L]hA1A$.w6n-o݀ޜJvF;Ac랠SX7tĪ5%gF=Dϙq3Dˠ-/GIs">JRX-T*)!E-V[)rMx2vɊ Ej pX ⨊jE=δ)IJ(?kO_OP‡橮\#dG\`T:4$|=ˋ&,Nہ=8H}vkEfsZemj[GT)y uԡ H0_wd8ц~8ZLpf"\.~/ZR3T7cnB;݇ xhI;qr(6BaaQ 4+G8~Ʌǻ3 Вn3GBͰ;=VƖJ q?Ma:#nОk-qJ11;B5cwO\oA^i:A=Z*TVJ43D,XښK_uU= Z~3a6bG>IT6?"B#ŭs]L)apm=G?j&ƺb@Wr-bޏĝ5s:A=qA2!X\f2qwv\ V3^a/^&f*W!l`JidAlX1GЌqK.x>-u>:u[=l,d2Tg}^3c;3G#<`dYW\>EO/IR'q].Da; "ܯ$;/`zi'8n2T\}E*?؄3?qgD̓Q?|o\oi#'W&&ok ǜz; ۄRѣ!$- 5Ecv_q[YǸ73cbYG+%|P0,p]x]bbWWq{}Bvv$5?2/lE źR7&8dBޓo`̓ߟE< +O=!3WnFGBLti=iʫB|~ӒφQ,܆$B, `ʅ' ll^JV/7{4ɛ>)"YoRͽh~Lf"9I,=H"YxN~ ضfvt12Ÿ&dHIHl؈$ZipT,;8쉰pzs86Z QO߫5"כc8.A<БK^v"8-g4u8 :=iy-o][9*p1iD\mS@cK_T$Ūy,P=}jEN])y.9ٗK@׵?!ܛ?}NiC~Vy"cug c5@ >q{=DօX?r]]=Wj?%gE_TŃqDp.~@0ʇ+rBOA+,("ތzFmtj1y2G¹ZKwJŒ9NQz9` No8UVi lF N g-ZZg֔R NfL^s zru kwIؘtxAܕ|㟩8VdĪk `Xsm})UQI\"EU"@뻖o;=KL9TG9ދQrߩ9g;![a(W4KH'=?c gX4>hRk"1v3s׀zHt-u&# Ɉ!/wᬇ"gC~Z5B"C艨`Hz XS7s9KCN+iEDCogJ-9e*4PODA_jf =<㌨H )y<=)aDk{NӰsZQ p1wc!ؓ3=h vKQH_l~nTR[d z7]cMDn5 %<ɨ>S>[`6Ɣ-0Ɵ S6 ^ )A:䮆-cK[2b^zP)Kf)u"=C l1lTJTm6 WIb5 (W]$7Zi~FT|鑚y|AK %y$ ,NQ$ho">&>j\홌v凁FS}ۇ6p[W/Ǫ2Ng7KFN5UӬ]7yQ3//A8/ /13 )_QCyWlW(D*5-s_Z=&GK[jGm[ (crQ)Z!C #ȘSxf)a\5l?d :L-vH!'Wh1c4 Ī uj\(2_Q|S@;9>? l}`aO+?kl*VC,~kŁS| 'CB1b7cڹ%,8)brnm[7He+sv0 Ҁ3|9C}_ЈKX>a2EKT\d$Vk|P}/mzK[U?(cGsC-gg_=bN::< bzF$rGgw޾w hI ^Xѥ+D= GI.ʺT"VЂBĶ%-DʺI! 2όi`$o|Q_۫0XY `#0{y)-މ|>6\,'rhjt:Awzi*i\x̶U{G+M˿}KF&!ܮj]fۋM 9> :?#v.>^be_Z~)shujh@y*IuV n\Pn%XBu"ٯ@]f閽Pw(T@fM7@,"q~|Ȇ"[a,o |Lo?2c8&pBCZ}bn=Մߓ8=Mvn@:jGGa̾X$Av'&w@( Mwd @LmɅdJ9Jϗ]~o#,>6q ӕw ۫  S9VA?Rу,ޢdpP'ԹjN?!ް HE\b&S, 5j̴0vXlplOeor{te+]`'~XhZPw]sPWAQEb]>qݘ8ƙv}WqX1+ѝ=&-kA2E@јl #BlxuTMQtYb,Z*E@P(7Buy'}?F6PB.k"/,@J,̄_c$wx~"=[!˓PkԹ0h nv%D !0xcM.6Jڐ=~OUi̻K17$@+~4OZpw?0r|7Qln=EL^GD%.U@pFvstS3"||HUicLJ;jhƢ%F؛y~5wZu7K 4lb *Af#f=ͼw|M %Y6hyzZW`*` m4>j> + VgqٶRۧ-"AHVU=t¼ JzTK՜`,PV)Q/nBE{5kD,Tpl3LLª70y4Z4MJfdxSq#d\1܏ x.8ZtBBiD0Dj 6y4fDJ׳BG;OE/LG@$X_f99*W>LӄwyU?!*i{ u-tlP!R2s>aXFYzZˉYwr;3ط>.F)7vn;|s-Wm]70?d-U2ۆC n{K1*aa\W},`q ˚~wfpN?f^#* (/&{w9XxnzL~T@xZS)ԙX0&Opm XM.ϔ%a?# #h`dQ'9d8B1Ym'Ŏ|`ӊlF)Tl;d'&Nט=m'pc1Jok+e0ץ 2g 5u^"Q],ܟQ[_ Ģ3tйir_ˋ]ehuXG)ξ>{Rq_iB][1 @}H9#dBj;K>AA;iS #Q㖣S|ϣg I̪Vc/l:!VJ$IvŠ/GT:wթs׉ۣ_ϴM#>)*kJALan XuJ{"Nc!Ճi\H&Kuݱ &%Yo`VkD2]!nBrPS3sK. g-.ևHhk#Γ)yF*Np\ 1xZqpȗ5_Yiю/:|޴ tzmߛlm[0Oo$a91U&6xQ_ PaF})9ĵ%>;,"[rZXU]tFxO frLRs.e#T!][{K͂ Qv F F!T jhIW- %$뤙ٯ.2ycp>dTxzhKY 5A 7aiP/t![^ 1=zi&L߅`vҕbqHdS)\X6f_uEHe*h-L1Ls!U=^ ݊To}uBHIi;d$q.ىA `R/FNfhadC:4" Ш xgHH:/Q;fzǤ-~!m $ -Ql_;?&7`VB %Yq(+3z]P9,).JMַp\ևEwEzfxε@ 1bfz/.E&θ`rL$jkeW*p9墘r™vݍ|oG(ፃ]VwshQ2`P>SMxc=LbXA<%q8`Sa*4fE•e w6H>c>dyL[hm_N q;YDWH!3n#0OxC  8_ 5 (QeJmVMd{-z;ŃSi=+ȥkhu/֒X)?|S0u'+!;T*TׇLrZ(C7 DR>F7~YNe{8 `/չg?.!UyG s2VO%X,<[M3f: 0tsBfcT`#r_\nR{Mm!pO&ȶYN %L56ö64>_ꍟ/6bl;Ҵ|t#гhz@l.|D;wuނ ۘ}F{j,K0v ̥\r4 Kv]͐]RDـ|VkJ@¨e24p>PDFa!ȂZ0a/DZemZL-rWA! "hIj*`qu?DBRpƎTAIOظ*A`35VZT)4#kmFmi!iiCBݚ t?m/]6/@`1nۿݸ*Lm~26~C.~Xc~FF8_m/af>oce[GJk *eboDlݡ3њ5 v.SjukØ{Qq'6턾9#sWjbY08셞xm[gGYrf*u, 4nȰ_D8cg-Br:m{`1TaI|9'yE%P/v' w>4xaV ȇ^QOE]vDK?&E>guFj%Wr@&(ViuC~gݭ?aZTWXSSW`-i \܆ Xp UR;֕^ލ]bvx@,}BO­Ѳl"ʣN<7 3oYG7Ń7-{ %(h$"1ȧyxͶ2G'`>2kv%@]Tuec? tYܔq1f#{,T5- 5hơ x"b]k`ĊqR9k &e:%tl%J,qa]: %=qHe03Z/ӡ~x{s"!Pr5'ΉH:'"]f]lsCOFp4"0ւ KhV[A ̌@3Y<צHEl7D[sGҪ?=`/.>yJx =BAcij^Fԡb:X`K{I:ƓY^.wB Ӝ˥ L畻oA8F PʔM* sK"ke{cv,/ّL4 )n ykhXԹ&\lKI+c-n.Y\L?G pf]Ώԟ]D+l)CPxS2.e̼ gLDq"]}ϩ-AĢ$0gW /g%쳉"waS)\4;g\pæk~|wD'82>ܴ:{S&C&h@`=.ȥ|pVK4;ձ犈iK5&\iGU8jCR)00>ϴٞ'ZS~4xVsҖ '4S䠋ckQq]/6WcOjSxRajPL)5Ap4 p@No)Hq!v2Zn>AR<c(޻nW/lV&ڲ-Vթ @4G #>(KCն!Jc`YMnlQBIfa ;F o@*j~h_3d%P`MoAq_@<_4Xՙp$F|Þ 2*>)@zI-7rwCSeʡ+:j4 \F?KTh5[H4l*FHNnVm=z:2Ҷo9pY0FLI[dDZMDC·j<-4"^kX5D4U,@7"`wF[ls{nYOHjJaKE\}ΰk%kKJ\K>(cET:g@q ڥysF3iW? (zy" K%o1v5e2&TčW#;mD"+ n~Mr{.5YK4ʹ*ΐň>uT71.k ц"qC)qhcq̅~ahPFʈi<JJ?J<}] (!%qwP'* ɐBGS()N͚T|]aRו.Kʫ1َ5B21fjl-F)rA,®RhTix10' =fXtb?) JM@z(P8%Uܣ[7a)k?K*`*>a#g/)}0S֌lSB/:,ehהP'5xkHyZ"8H.ɵ*?$:d==X4W] (xBD}?jV~ tK5Qq/pM&A>I%b^&:϶`p;׹:!|Sd8VzIN@AB&f_SkJZ=W,rYܸC}tojpRѾÓ$p;"%Df_!1|?nܦWmcPouY m|MP1KAΠ"j#`,s,IRdD2a7w4^XwKif!ߖƖKv_AN† ㇵPze<JcD+6,yLuuH. J ePm6b,rX'LnBfk%D J42?Zb,l ϵ5}rIPAS>8FkFK7 ]q,^%-rvI+҃&y)2q0]_-Z Pu(nyts|"&ϥ!\9"ߘOy NZ'MQIty\6XH"ﰣ/ai,lkݿ1ɥ[e+z}UPm7( 5CV851 0Nְb^m8JQGRq &31V AZ ʒHU5b279WH @D_څ\efaΚrNǪUcbB]O-R^;G^έ\l <1iH}J]܋q,|$Po׺%cA* i[=O\~3c1$jу{-;JRQoi \l霽ku;7fv:ͻYR`l9{+E`r*Lt% >gR~ I=v3^=vM[0Qy|e+tyWyRv}ӘS/Jnl8,-y˰XBMz\˒N8e_Hybۆj?;04C-i^`n.ØpM xGH,s J~}2/nfR̒j8gomMRNjf.u3[=,BΖ9Js jcO_qsyH)tZ [3 |N< ur@o 8Ǖ|vTv>w*=x=|b %o 9\sV nd̷feΖlO7Mq'd4<KLyEcG*’|-^ ~mOp e$xh8kLA[g3lRgaH'7$|aRu ñP5ރpR"uo )far'W&@f駟|[H\,kD|j&}}{uu,6gV3$?IR^~d^f{ܯtfȄ򅐀hK"'٢ p:~qn&\7prj'v`Pž H0s-ȜKมy8|A(i jI|6?LxVً.g^X*ο_/"_.!]l.lz*1!GaI=6B50h~XkwR j=ZsɠVlmk%w\݆IuҥW5+ylBW+ H p+d_|Hb AF*A Kbd`Xץ&Ƴ_`w984c/4Jǭn9@'dPk2q}q`ה3;>9pZqyl0>5R Uh,67q\XKǁx\JӇFw1PHuvWgDdEU{j0w<gJ2ҽCNnl?nĩ`gVLM;hU=F7q YR(Y]~o=t="b@TqI?tGq}q! J%QWVx>{6rnvE?m$5o-IM@83M*,! }I>ljW<6ɋwDGr_B(ܰqq?`jW:Gһ.UhV.xe; }u ͸UG x0X&}]=}B*jfBr!h6᭣wфO(^5X+e+B#Y4`r` YũqJ$zU@ȢmQY hn;5֭Yy>9uJEXn3Jm"5jB|L騥1&pNBF9ceȀ/y^[$2^T<쑮 @|Mf-nXHv6Eە3<Rp+04'}МapXGskͳQn-l!,8>0f0iI)Ά[t>P&:\CGhO@pg"\A@PUԦ r ח$+~ne"zba:Qy`%x,zi5@TC=V :x\x@MjOT<85yshPRqoVF Zh6-;CoCw4\1M.VW`Vxb f !gts@`kp`h0E֜x _6Dcv=o-(I u-NB9%%x/T8,X}:H1+ݑ( R:87:! ^岟Q0uJPJcG%#{-'{}jg߄C/23rbvKrX״;9Wž冞YVO֧"U|+@8AA؛&E=*4*L;=%[v.d&Ra*N"_USaPs^ױDzo½B62hn4mζ86 6L(wfzc]RfsWTOvB,Stq 7`j)+JWZqUcN?]s';.$a_+hC%IMTӑ%ӕ̚9W^W,07)($o̫`'hLH >MB̺+LXϱa$J{W苪ZhnpJi:Ĕ eߑ;xۘM 'mrCP̮Uo2)u^ia¨c::} g#` It>%ER4Zk6[:a ,շte\G^l %>\Ƹ6&BWTB*,| *~}lyB/6Ky8ʛp7읒 @zQU%x֍~*C'#jhFRC=͗C1wΨ^^S"Q^ R<[$*7GvyM{Qf"ШI+,>6j M 0絎XC۹d9;x KS$n:~yyB8BLe*vJ<ϖpf$'5+qkdv~wÈ]eD9\;fl VFJۻ_*W?j(D_ަ;؄h8uk8Bi# @xҭY7/}ȑ`EA0i3"BXObN{ TvFkxUL\CDR̸z/ۜb{et c>+,lv-` %¡D8ݡ7W &4Ej ~3k v'vʓѥ؇w]_ND f]z\PY}biX1`&e^M<:c^I6SӔ'+S"k~ (f>+4V QN+ z_BXq0wѣ*=_esXo8_>Z|.~G7$rz;Ok d R]hAjƆ6v7ޖ=YxӰrq>rt"?L AY\Fa WLZ&}FrGU#󅯎8ҡ:Ȧ dyvs9q{`Nq^u-Ӄ%4IF4r:9+, )Rj -LWJ#AD8b'߽!gr Cwg(cvs-㩙}Ocg0Lge䅯3 ?I8|zV>RJtP2f.`.9YakQvs9 w?b}i1ٙ9F])uf'.k<%" _$bSjnI>֯颠2k_\+Թ "y+0QV&2&<-?zIV^2}LuF-7LTsva旫T"fا &j& ,cVUw/3LO'1.JݓZ1(l3`]kA5lWLrJ=EA<W(n0V>?Snx AG+< 3QiVz纴TQ k>X2#Y1H䭦^ mbѳ (=">.}ۋA:Ca@b9Ah o@4Cf}tPL·s4+q0 K4#1b;ݏY }%iPbW輶_SQé_. R8SgtR3=tt"8A)}V*;͏H0+2ʚC%t>kC>堲;g|yG[invȢ}m3d;'ZU$ Tm/|3«G; 8~ۑS0VYx^3LӀ7qe]/IqbiMzGh-:=d<:`٨0s*D\֔`g@ΊxYcOҤx潈_b \n3۹>3S߸I^5\X-?w+H.'(WnP{Vm3+|`*njSPljQ{^YA-JdTb09h:KY4ޫv!ӐiAVEإɭ;5Fj_3Ѽ@䈨ie) ~6̵Hz!GT~BleUԘ!p;cM=Y>o\MA6Ly:k6"p}'&a)O,j{譛I:@ؐz|vq溷(~UTUЙz}P:6> L84&LH_p1D&iWA'=]HFSu|)Vgob=gېۉ(x6U5  &, ǦX3?N gL}}?{N}$ iDw϶7C p.VOl}91qVɣU4Ve7̸ ^BO3yd\u"̱5V! kC\1aa8@(33ϟJEWuZ7:=(2f>6f>dt%73kK1PmǴ dr$W8U>I콙lj<;*KJm+% (q VvlfUF$i@:YPpQyͣ:S>xSYST7ALšŽTP=G-10QB:c-8ҏ27?[)[_C^K} O㇡VQz֥٩?aIN4X6>0LJ S%ϋ ygbTsAB,H p/ o]_veW'"Xm0HF׌TnDuabN F[d!' =-v>/h=WPT1x|D-!U ;-#u_*ckl% ;ڣ*r! *H*N:(GY^P[|&#{ ){8zf6L@gMoj&J=E @SG,oXr\=Ѥu[H[6 ƟӁZprp4g 91|&!\~kUeqjjYkr;& "eS\R/i.K$NlOIw>-g*xQof{,ĠFgæ ؍+GJ<_Q>@ZjtF{FWKM[ TCw?Z;QbIc/ݍ޽pn'4i*VT97ܖJv)Z̶ڄmHʢUwh -f" fr15A̍=5Ls040u'KHL%23gJABT_ EA1WN qЯ{ty9ɧRyFKG1!tb <Lƚx39Y$]t1<{RKq {D~L?P|5m1'IbG`;\&،h'? 蜙u!<ʞ ?H,0~#ؼCpaowK^voHZ4+MH90I~ÉF~Hz>VJI%mx}%8؛:TuŀN&nh ؖLj]^f{vUu *N@wDާiSJͻ+œ8Go'*V$N<օVn!X,@MkuW&'vHbiĀgRX5Hv˨wKBtQ;GKi~zva-{^BmyRvb&s{ak^Aϖ!%Q{ڸbUWAr#O#60)lEl^Wbv.q@@7sJ]᝗SdT?ep Fz.BIVP#_O0vx S;8yC7M7fE0C˧(Vx!~wBƪ.c!\퓙&.C1;(pK}v=h`e2纲KI{P*Y8s ?5 TĔx-4P6q;$IҢ(XmmvUK5CKv +j;ys>u[8>xnoJxJlZɌ~/leOu:UOi59Y'JP2)$i"ob ?Ɲ 8YVBjd$7@^LO%>wGU<>ޘ| ~)?Fp{o̖X<:~OFuv)rϹ/z.k꩖^!țO2OK3%YgeEe^\ƪe= y.HC+H%DӜk5pgۤ*bL0[?{ЮAc4"r1uf`xD0M$4~*bZ[L%L-g)kƐWOf9OTC2`W&Я&6tGkT CISԀ:Bx@93ɰdQZ_}mkkUܪ~zU+n` Ň h/tmW<7`CbK6@^ߩ7-:%"o ʬ-Z v.Q6tPWikG`{g/a  (="*nrX5A]3i14v.pn7W  9HFm.d$ӥ^X?~mij#HS=).6"踆'?]&m_G9]V-NJ3hu*OB|0Bp@H uw_bٷwDXJc׆hkcwqtcw$Zߝ[7*2Bh[a;Jci-S=f|yYk@vJ' 0C/vOU2k2ڎʫ͚ԿÍuNS_߻(Әp{Z c9H; @Q4Q*肯=H8+P XI.'Vҽl%/}iq=;LuJkD/ g62SQdPXDh <`NTKTZsvC8蒡cVu*c~ (K$!<;D N2; c:Pѫs JT'ῃ["iK2cMXA-F<0WXq8,2LVD"AY/aoq/PoE5ޮqwKf@GH串R&L/[nm˚-4hNbU(Qo\;e("V;''c, &AوJvGWuIzxd0ǎ)!S6>Ưb="~*ii51^.0#[J Qzo˅^!XȱүR]CY:䫆p$=^SH~:QΏ([jQX+xƶQb2+C*b48ۘU*:s1 n_0] щl#/xĺ 'y՚͸>Z ~Lrogk&c1S >bI#f%?M"=;%;k>\ zبZ/JH:eMwo+΂2њ&~6StC,#̷ |EV w4d'OWwUvQϫ.Λ5@Qbe̎S!Kz塯}2ȩ{ ؕv c,Iw4 9SP$]?hj6pgy9TW+L h;HCJ;\Jg'V/_82XRN*|yvCO_p$ǍDQ$9P8;ag6{IUfzmUkT:)r˵ #+y5VgHJ Ե w=MJҭxat"["򖊿|I:{tCv!8*UVY:lbu6y؅ݡ =:v(G=! >r2Ѳֵ'qXmEdUa82;oνQ~#\l:MRz'h7};dӠ d >odz;7Hp!  C01eL1APU:҄ګs4L3{G}$XPۃXDz1ρfWiyWM5{ [/eh"롑[1/B5`qqˌp9y_s!5 y<PpŢN}\!DK D$n"Hk7ę/N 7y2 ]7},"-Q=$[|u#L(,~ d IdF⊽Ld9P^89;DB&OIfgeq&D+ߊMژFF('~s:FqHx-o MZ* yy'C2O3aJ^˔## ;3H6EҨW7#{_u-bQ0(9"壤v85]9&0 Ea6xj<v 187 gz `QNPHA]m,КK!ōw ~OD= CNĐҤanv:lȳ D4)u"$ë/0 /=0gd(fjMN(0<3[D,ڭh1M_b 1ߵLF!RM("-W..t9W~3[CW\Qty  j Id3s<AO QB}Q}P%g3TI՗YSLPY)CЖ5>}-fLZlGx5ԉw7ʕy:fkfz(|Zsyz{o%K\BJ!oi/Dՙ. N^dUN k&" IiiцȡvL0(/L%^jN/1.*c_ 8R4lCSعDdXlj-QLc ZPW 7֠ï(I^|O|g>~oQ;kA#PGIpnCb Hv"lMR)q9BuA#_F9؏8'+Nds|4MqET;xJQ/ߑbU4ppu0đ_ȵl"U$hz%J#{JEwoUoz jU_iE*B86&a+l7C΍zGii hR1~Lzȍh[eM@(5T$r0L '@Gla?1sk;ǭBt%{[$ÅBdFymaɱl?u<9]@ lط&j{KMq p-5D>frmEP?N*c¾a1fSحtobzd޲ƃu)ܻz(ÐZ1jrXYJz6h⁵K-=*-Qs:*ǦGFM<9X 7!<Ke1u7?#Hl;}t #;{AȖLW A`'h{Vl0")<CM$"KmG{˚PuHW:XÈY>b|<^zT SHƻAbޜ!þΖF Ngy2Beaa5zG~#:pZ>/lL?_a2A7c5{-=$Z`[Q>d扂C7fQߦ%j ᤆ䨹h qRp!kXr"?MT K-2oߑ <9x;1w.ؽeÐ כ>|0qlJmo<6 vemcvɻfyGiZChX\wKjcoԿz*?b){r3Za^c1!6lk {=Br nF(YiՃU]G&1q9LmP]qv6|vewX#Y>f=7;2QG#[vQDXTn+.Wz`ntZ#w.yK8df7,';roKyi֌pa'oey^2k|e(bN…bZEec]F#9q~W)ꋇ69o朼 ga lw|˂Nk4'ב5j,:Gq)AjR}oy^O`!?<䋧dhCR#]&E >>S ,iS;yBkFh8T,B=rD\7>Q3i!qcHסn'%.n^]Lls|V :b(Iҧ8 Yy#d:ȬpjwYXOMr}L[VM9*<ޏk+킯0q,X-έ?g`9 2rHƂ4H QT%:Oz)v viAh)?ļ ٍ.C;0*WA$ ݆= xs@0H9XGbws;ECHaB-y={:7y$N'AfW |.ntABP'oOUu?shEla_,vPK3RBmXHč]ZPA;Qϲ>y4uuph%=x"C& yNlo"Ԏ~x<֢g$ftG*1DMT7I~3i.;'0C|(yiw#|J/x]P+<MbiD `5Tla@P- l(1-[Ʊv< %Iׇu%s֮* AgJX'<Jf@:ߗ\Sԥ6ppJY󖋲uNP .ƒ7~g)/}{i:2* Sg `X~JDI?udƊF{Z صO &&cBk"_WYCUs`M)(x: vbS)s%=22U^g d7D7qA; ճc7^>?bU/0T}M5uG "[kbOsqF!%<`0V(.Ña>)8.SΝ?)z.ya$S}-HDf-m.;sנ% R>ز)A"Exbi9Zag<;wBpf~.i5|GnkUqYD܍ѣ4쇁Pf:^yQb{e_o쭔6 Y{cw 68/Z!q7 LDL[ry5uGUN1'/(@IAa81*~3 % q%JKI@yXױ끻ZEdK] ][_@UCvE07P ]"ޫ \!)-h(gyhi=h Y,\:xUR)KGϽq*jS8t e-LdN)@ Qe!n9IGA,P[c!7[q[[W KRWP {w2>Qvm2n':pyޑ*&bf/{A͵=5k@BshYȄkWD|gcZv쾏CG^H wR5_$x{Y!%r0N.֨>cV3fMvN47'w7C)X6P@Vu%XtZb"q%O9qZTQMxԥ ,-7ǔ;/bӵ<dژ|% tWje+ߘؒ*#RŞ oKB" KAՃK<"H%\< ?'qXz?0y{Q;ǔ&GbOˣmTNc!_̥!yon7N։_GH@}W4^?w=Pd>h@mx3ǂO {) e޼Tws>&͌^PN4k$-V316k% c+g* qOX`D*q 5iJ>a] ڂc|O$s,;YWH=15G p!.uholgݥ*- m]Pj\̓X^ld*hFNF#fQ Qz6YJAJTz`gsy1c:S.y-sZ"Ţ6+bYW^81C 9fptRASf%G9UVy;y8 vZ05LJC-x9yN.e1)|/~ UkZH:,0l:nSCD\zl`A+;@Qӕa:7u_ǠSII <]*S_62tؠ[LiORC  +IvYCJ2CigBޥ`їޣb6&{y@\nf%`x&$S2窒oV5MEyM8e/h!唫Z6m"A%Yƍ$@>y6d$=b8 0qw (ұ5" 6(sNM|A 폒.^}صf;2Zs^npqݟL05`K ,fNe| 6D^<]P a93Qٱyh|6;11"ھrxZ*,̾B`$Oen4:sfn+݇ N60:y6sa&V+1wx"WF``.fRl`t.ۇ̜h`QΗaw+6?;O Ŭk2=<:{Gr6d$DeAu7!t?`[] fv 8^f|6̻(: ĶO[w )Z'HuQlcR۱Di_THHɩ 7&#A#2gFf>OP`bvRx|P슆B :X_^GH{M_4C1A'9O]$Fx(vqbNJjX5Q9D7I\^J>LQIb j$ 1O^٤Sk3t|8!֟Wh;.82戂DX:0quV_f[a.گ[ i:ڴC5SFGY_w $bhRz#L_)UNoS*@Ђ"u2e D(~]2QBY*GZ+ӦMUc9yXHnUX3exiZT80y֬ 6MzHǹ "56ou=s]j&]<+Ely}2%wJEzG} eo酨Dd4ev_P#0K5gV>iVTq*NSi,",y[)[._% rWoOVg<m‡:Kѽ|ǔdFj:=fyFfkSQ^hQavBՒRwltp: e68"Ņ_6(0"jֲ8E?-qkE.\չ]@itMR6AΡT$ zE ]I _?,zmG&%H Ѓv4b~GQk`m,s7sۚQ.u#:My K#uUpMG,qTե$>ycGƱx48tkB֎O&bx(i58n͊`p=NF","wgWڑЖMRɈl)&X / ^ n|(+{,n*`8O`]gcf慏5IS@R/M{:CN5 j%M%ms(91Kʮ{P'0_-;Ha;fHs m@w/2m)VbR|wLsAQ=g5 }?<{e[GMH*FgJg:>GSiO}~ZO19 pѠxJ?AW E*\Ww/9=r]4*3L4w0Ig$v? LOV!q߇^l#qߢie Na f w[|Y9I2yM~*#x)b`# !`w]CJWF z^~0^ܺA"<:0ˑ"k)so]B$1A}貰gXmu9D=s|{gݱ jG `OjI.Ǔ׮E%s=&aA -|%PuXU?{;ٻnaB4$(jm;xSB3atll434Me*8L۪ލ6 (K GFEt ׿~+uJ|2>J t)5ӏBtpi_.mc<:[= Z=bFP 6{n)`πaqKȥ[pk7[4= {yFGF}^e9PH;V KO܋ cQT۠Ȧp2SF\Ɇ~g(sm?˟lO+\.wa.)$J6jȵ֟S2惊S v&WTTrli!Ś._ q̼i)?sK|!b߶rڟ[ic~9L1ٟke!Ӊ=Ojj6{(,=Wpr]OTEA #|v%X`݂Qan Vd> k)O}S$P5Hyo$oQ$%"ccJRth9|RZcLqGƁ9Kid7S&@"ly ($g D׭dJ@=ks8<߈[diMOwhf}%/~gYTeӾZGu nIm50>sH M͛}bykexb%rH$1uYnSii䕲QiV]go#r<d#7s[[FF5Im&Jc i\K_%4L= fC1Wne3EVµ+5muкD|30пSui*zԛ忇(/mMQUĐ>«2X5!ĄAj.+G~)-)Ϗ^c' z~W"aa瓹&MfaGFGv;A+}A~qd ꚵ>l֗Ҟ=s|߂_|AyE=l92*; d s@>vE0|[?!L޲$lm' qkc +ܗFWDD..QLTtghK"oȖ(aa}>r%-2<᾽ï(U`&\BEo/wuA-U@mi*%zQbjDcW@)*ul,9^l rIbG.b-sEȤN} :ͬ(x:S[)ٽ5Vگ| ~[/yf5ab5f%; YC]m=GUA x4þ_P{Z)knJ=yFʥKb&8y>0|jHlIEVCgEu n F\8fk4 ϗ J:{SZʒp/Pj#MbQ?jNt:&bݕ"11S&:"T߼΋A E&[%\ iG.\H8Qw;* X./͌ ƅh1xu>!KIg%fZ#7`)KI &ַ2%TH?PhdkJ@\v(@]QUDtJ\G).6+)q;Aд(B ơ.:>]4݋d#/\|^uxp*sKP9Ūca[+ˉHBg#ӣLSh?:f΋d6k=j(&M5BKeEЎlÌ^PMP͎Oܫ1mCVj0;E: ui.cS'aX:@qyw"0.4՜_tOf-T-"@NӨYϫq6me4_KxJKB=>Cz{ֹ]K-G?AϻL 4 PO\R~82@L&,t?%l.&[I-;A'4 C4):w P!~S:9#Vw?߆,\Sld}ig,(tҹ9  l $(/!;%Cr59Ӗr4 v /\"1DVV~5Dv %:}xޕLY"P3$Y#]&QɩZBQN=fb6w6l?**a9I5B]VM{UTX*4Fͳ! ]R3k$BKA\e4؆8+?O 2f_78]|%;c1~σǚ,/@}tw!kd%晬r˵.J2v%}|_R9퇥gOy1Y!wj'dU,lU^^Avm2r͚YMA^Ό"9V)\ %M>: @X .AN#kL Str-Q-HH\ppkW FmA%+^-%qV,,8=vIocGo 0eWI H_a#Ļ)xF.IWm #^Փi=(dG ZuKP&`taCՎp._cUnk)kc#N_MpN"f{RCVd c;E'zq/{upEO0%Sh%)Z:C 2RH}?0Vs@} +o/@넲b+di?a(h<uhc:N6it;ˋ;_&@47dlVhXW-sWTNf<+0B_t 1O!ȐbFbʷ,j71t[Vß1k:@+='OpEA#t]3gpX72/[?,bA6 AlPh=3| SnwE8"47"8`TwݰKNٹ|'8>?iL+jStƟ5 ,4 vz,䶄! _:!Amx:.r.?CQ>zuMT:SiتX~{ʀ'U ipT <-YK7-12#YQ}/Op&pٻoVe9xpV١X* hg#4AAMƒA2t'[GK}g|4+$M\@ amA h"7߾nŦrnut:MP>k[&%~u\(Mפ% $vFVXާmk/`e{g3ZR*KąTQ !no=<{tnAl"]YTpGTY + %XLKp!ÄoAM&by*],.B<4PidYY@^_mWW1sYUY%ǿ&a3pTǏ9y%V}ƄL©yva/:?M?#^)8 . [}$dz1Yԣ d " Y,{WNm~$8Bʋ6$NNITLԵL\F;dM˒5h$cL+4T[E%>?׆i̸8S U˧m))i7"m*EBFL}nx[wa`b g̃Ap= ѐ%tALقNP(`<;:}?![E)Mv]vq4\6PmK޳@KO 63RWL7Y|[Ԧ|k2x\T-@-"?J523zO͞62qtFuWboBmshBS[\I)1fz1)z?ٮONj F(+cHFjU9j)cRɛ "C̀lYjv襩F +X2Dti t'P!< mVJb.Gd1 ebR6ݑ9i^4H[u?ľ~%wiʎX4H-P:&QЃ9Q߉G1*&ld^xRh%' E.نg~["ޅJ؛Il ӈ0VY+ov5^ IQhptKы䳡5$6(G-Zӈu3 wIgtd|4J 7GLx&7h?Ջ[7ܟ pqHŵ@#bXCKߠ?@ӕΓ]^L%ufu6-@]w[ݒgP9 ueOeMĔދ%;$79{C-ӂOlF&OE$ aHw Es';؍wmDZKND3Sޡ2G/2]T0٩I+S3D:X!kVаEk7(OJ(ŷosD:Qz,bZ=Zk}-_BP$y'De:QN,^.*p0ꀥ+{Wp^"J'>4f_a06Y #%6(s`fBU4x#no-NQFmލժ,@f跔$8`{.x"_5um(tl\ٕ%R@Ax!G5qSp8; J}cc+c+Q*Gw2\#`n$rB M2su\akrIm'JGѦ0hF}1qV͕_3VQ"h&庌{ɕX88}L^X+Q1]Sq۶V4P/Ԁ_-S AP aӲd Xm # w'ωƎ_p 9%E3XRgRSq=ҖD|wE($!p ,QSw_ 2<1&dTwi4{m_mQFp`\2UI tРtrxtȃD_)\-|%[b,>?YSܠlz^OopeB$Ƈ1E/uaH*eVV^bNV$ 18!+3GaP`z?.\77N$ ȥ1r+"o;B%q%Oyʭ@U3rt^:߀Dz3z6][}l'P֧*U2sY%0izӕnS +UJ樹]2WiX-B9o,x|y2iccCW97_8$got63BZUJS+~*-i 5G:!z._CJFJ92{I;px"3a2j+t, D{5@wM-ٵÊ>Ȧ~-{Fø]Q 'ŏ^`bЌs + jȄ`u2sd[%nԯzԋ'TYA`9@P%ⴼSA{\oGe!c}.[?/f{;1j]*8쒸i ޻h!g%ȔgE pbڐBIx:iqqOiQ!c%v5o:R@mo^SA$ЩZ8@AD0a[iD):PcP Qb:sRi@dF 1rgMBI#}#9g"?_ܣ?.2^=@5ӑ]p1 Vxe Ϙed_dGotbhgBm$ IE5\vTa2 Gg`ٰ|}=ZF:,'̽0L` J}Q@y@#I!ބaeC><~pW/Cߧ vRxKfKT0Vbrhov o-y' d sDU"о\Y"ajc-_w,A$Fb<6=u _u.B1N `#J4|3tg~K9qzDO03^."SOVҾ$0JrwA"BװA.&=$$,GGqi>'y];<LSDFp]㢢 w\> OC9<˷Lv26E5r~{e-lʷDxn:Yx(FzB>Nze_>Cwa83EBTQ]AQչom;:z9zi#eKjtIKp\arH&W~WoJvLO/=ټ[ y?JVZaW$ ~ w`Q s+`z l}ڿ_= -Խ 17 Ż>A `wsҜvȱltݔH2Cn =vR Soa5^-YÃ}Z~8xV m0K# B~A}>64$!Uw!bh w)jܬNU.jHh@JAAi3~&1ɁjP;NZ3KEhjq`UeA{5QM9kHrMJӷW ݃Z0N™Qg<cƧέWE#:/0LjҞѢ< O.x?ݛXLy~e`{שp.Yy`)C#9&h |Ę>NsZ~]_Όӓvwͯ({XN˭˧K_CA&c:hYQ VZ- SZoG;x A.sy/3Kc[Qqˡ0˃>֙և6+YEҶ>1Oph4 r /:di9./Ş#M~ Gq-N5 _D)< xzC*<'ξQ(.?Nc`:j#%,"hT^&5їV;p,z̊[pX[z94xj3m6 AwU['4fcWQpg,Яmk29f]|~qZ^&Ʒ]TdȠh|'#sa%A D'gV'dy,tCU\ ⶱFr86SbYPHAz0dXVsV\M[擁2.雎W'"fȚ K-_btq1v\oQ2](6^'Hm<&.i;gNM9f4KR37X2gdQJR5nf;(_U tBYTzMp^JbI‚Ղp46`}hZPSR9丯 -S5` h=iqqK4.Wh?]aĵL!p4Fܴ& 6P}X'S8quMF9J?qZV0yc%$O9ֱ<|^ec Szd>@%MB1:w3g)$dKt>tM9[:BW]!cp6{oJ2B\xB,.:NaʓuNqV`5( ׵kJ@.şy^ǂAKP|ð;94cvE+!y-@IsG 3Y}./R"&\_z)|7ͽvΆ :Jf}o慄zR9FTߒte-K"h$>%c-cB˚`䘋QLGms?2= ?պ'>yoKV6iT_=`#XTXp-kw]4BKdŁG+_7PZ;`<0^_brp}KTV0Jb2XtpZ+h{C>ɡVRw1gh$+sSS#!cm9.CweV3.&R> 9"9vB pGEMym*"mPb^H氀\; lZzdA_\QT'oc&؜t=}gHCe"bר-_j<%jVQ{LW̳Vw*'!*j^"IfMlxOU3L:l8%^0k ۷a[neA6x,QD9`}7= pow"<PoQpTM>gwnz2b> nP P/oJO,&ѐ^+w@2.5a x|]fwPMEUPc~K=g@]Ҭϔd_+vsՒӬZ<5 ܋qL GvccW׶ݭTjWxOT7TH2ozZB!jڋ=gln2jT1Iʼ]O.}i]uv֣7HSy|iS.9WDW3IJĺM2gPpxmc cjyT4/ ]RT_Wo17$wIN Vwޯ&8SzٔXڍ|$JW(z0W~?H^2iR§; o5.!6Y=XәPm>~! G*VC͝>V õE&K v15bHv :/\юϣ.l]hNtvz' iQUzajúAoE^:Lg$Y ~-H&t1b U؁[zP;gj3 H*fIy!}rg55'l-6Znt1Nf ^,՝Ats5(:i/VJ79^r1㾸Q]L:|F~4suJt=;jb<<Fq5?ɵS] FNl P 2>sxA1 ;nG[ 7=CD4$ 1lGY#orԳop('pPFJ‚0 K%p-SFf Eщ3!sRaB6z$Q5Tw؊* q#i^iz2h%uP-}{!WI{q|Qץ`Co:ڷ ?9ν8//DO%MpAv :!bځU˅ kL}H`|VX]!yljLFp Ϊ1|Jl}aF@6Q ؔGE1wM܈\|QcmZn`.e瘇5ToǜW& a)2X 8uAo.\m[ g֦k $8%9xjb˶ekZd{$TuR#~ބ͗#`t7T%/O6nH޾ lIZ0&uY\b1;F`+k _@U%먑Ofƃb`4Bm|a\[g$<MVBt j%v}fl8s@i'[?z&8ؼͨfj*@'f$pq/VG`3`:hъt:NnI\G 7s S<7ĈשM{QI@U 1 s7!o}H~8acbf=:g$qcSA&E{yBT^e<J6BpOs)Fxy 2uܔj8|ϥ,PRPyo~y~@QM@}kerB=ʏg#KGB@F]!Ѿk}(K( Wdxm`#qZB aYx[ l嗊V%8# 3JmuGԢCr4.=xrژ2d][Cv׌sʺPkpDzPpL+6@ke)XEFWV_:#o󺘟tC]žAAh =+]: _.YW@ _Zц %8diQd ]^$!Sm ?n6:%zQyhvk=(zȲp'B 5Lkx!ޢNE,Zd&LsS6Ȕ Fx_tH́MdBֳhE6Ţ'Q[Ik8 7~`8U\eeWQ"ڟb[u s%"KACVw!Jdq?[xCT܂o\q˞7[Kۺ _Pt+T)%ԥAzDK)* /4: e} lKdDz.[NA[{ c}4g`J  0 WKnb@F_4ߛ^!#T%G1&ꏥTNPc>:&n :kp@ ZD.(B  J2OܲL(),D.vN BLTbPE6+%4G?v߄7B(xCF/!`y:?--!`=4SϐS6SȐy^DZ]Nq)Dnf>lk_P픑ՍgpgRz * oi[quJagݭ*T4n84F\+sJ$`mCU#b_L}~\BfDzg0|pYì4m=a~(.7,e >b-cTiBfEA=vwջ>}h;*bp7 {󶘥xTZ\uu(# X(g3+R/@&|!r@`(FWZcTLFG&·@;iFTn@u Tzꎵ0gV٪0,3)/#)Z4$TtÜS8InaYKR#:uAbm-\1I$yY|8eIU[ /etr ^'V)$eXՍ=5X >oB^l`*;L1yhBB#>[[МuF%n7GY,7Rfdn/t@=}r`eD#\v*R.r>Ѐ|+ .0 W\*Q0pw aN?Гo;Vg3xZdKdNL5 )At8+\-OK %%.z'4= #%HBo(Y2[peƨ2z?|g@& =fJ4ig|ҽ:D<\\F:BrtP©c)}kJ wIyӐ[kJx[o G|YZYl e ڈe@wR< Fϛrp (F~[\bwλ"΃|k,xIjI2-o4@LnJڴT|Mzɳ&]&ӈp׌N NCb7i!WR#SS{b;vq0R27p9Z ] N0"J/'ןH屴CD #mam7YAC:G$ AZG( ?~񹝅Y\^z]4?ߛq55&Ø QnHf!V|3AClϸn?D9k51]Sz$qd"MXy VQwS)u7?q-iqk(y`( W>(ʟG{ǃDL5-'6;[6o9٘ i%)?pDY{ 0?=8>?4/) ;Hb),xqfomu(-t:AX oa. Py&=#*+ܥV聱P… ,K۹PMʯȊGũ%{ \  \a1mDʿƋMv_֌M쫞~T5;ݜףncJⰦpw0%  V3֊3%} +B`+u~O@?GP1I13Tn֨YID вIk'(uR7\Җ-:V574ѼBʛ2c؍)ƒ2ɬ^39Zy?˲/'aFH!798 b +OeZSKx\Jo2=ⅽ0#./jo<袷gf"} u4/7/W7}I|Z L]@GhtF{RAqǗk(J:2woG3Bm!\L:4P}2[I:о3(w=Rjz1,m ڛצ 12ՖVz*4lX0d iѡ㲎\,IA 2D +a(ËZDNl QqJ\zęe=b⁑x{xȫSF"،r[wٌnyg58]?oՌ5.=)֑,W"Mo3JNgf 0;].x]\0TU{żп*! 'agiS z'!/V>v&Oy>/Gzs #M3[ZstuGJ}*-?3=l6$B獯W6g< T&jhS_Q۳G`oy7pTg:v}/*L5!)s&hPRVhTokU5USG1n)Վ[q؁/Bg{iޚh 3ԧ ;z\C-R2jy.Usp r$+'[6B? ÚbTc :t}^E'n}\ǀjRqw׹+DR'6%KCQ}%ثGt^׊([&]ar%%F fF_f_X裎Mا|θQ ٠qXmlL~E=va&HԒ<?s QIO@]gl \.S|PU<Ӌ!˖Cf ]l ,2Kh!PR p[:ӈɌߘx 앬P]v/M'uKM I(v̊y4>L,(Ҿ?V֟Xw2g:PM/x4bBEt9^4ٓ3&<1DS;Ƭ0 PulF;0"$L?\ΫXN:X!HKb?YEDWҭޣ#> 4DY&bY{1?br;V3=ΉsȎS)k?LcZ4u4|{~lqVPL_\D4F׬G[ dt<ӕEU89pp0g²^l]z{;F 6})ڧcKiFyK3XF:(~k? f\jj&`}Nd8ne!.";OM!tS bdLIV^B#aEH|`v8= wl?=/4 4:ߗ+/i>E1]̝%Xch[/^ ӂ{sn ێO\',Bg #->'\{<$ɸwė[ηqu^#-7o:r?Z־@ P@>۸t2P yP%J5 ׂ+_V񍅦'IRC(hٲ$\ԧ׬(k $3tHY KMB>E39 5z(%HCo;nx:c# &ʎ;k*`qI3mn^7٧~CE89cx&Io\XKf.qO)w42"ϯ!f. aqåДCGnܚ 4x:!R+}T5'2aTݫ y2"wF! 't zڟ4bI`*z`y-~okkV'yamołG߭Wyk GZuUmcia`:=LdC~#0Qaш%KT@ h;N*T #-@Q* @yޣ%8 AB!e3`=nhq2 F0%7eDhj =eov6EMYD͚"ڰ΋No&MS.Qވ H3|O^ɖXQ ^~h,N]ǯ9v@UʨY]~B;t;b3Ŏ3`d*ƹ#N@o)yljl 횋tO|ߍ dU6񂚭!gO ~EQnuU{4xtW$xJj & xwv1=/۴4NZ#$mR1` "Y [p)' k$45M;˪hTkd[J4rdVkh!쭨{.OǮd29&ԅpXb =?P CLM[T7Ʋ6h)g^F5A'H3OOpV2H\{^D)EXPi N>S)jI'*Sb?o⌮A |P5D᳁`qR,:߱IU@ь7J饤 ,B&3AATTq9*WTF_i =FN#b%,(Cg9`?rmzTCbTõlh ;Vu|"׈ vShշ dr駌v3 p\0x# hx,QYJcďr]^RwBEʹ9{%cBAa¦Ɋ]Vu~G=vk޾Inwc #4ݚYp@փXp=?5%SD<RB<Rg.3)"@k"νc|δƯ+,3X?IYlt?4מ2>@ .{hػFxk`)F;G X&wN+G^瑩bCuZtҸV0W73iNQo2?fX;K 46⎀ьKxS%KŧNor7E>l\`K|߉!_{b[3B˄ j,,w̐"`k~n@|7'dXI%>Ϗ7t,"@@~]T1o,/!鑜ANfѳl35;e/\$;b‚uc1A(/YRCB rsWATG.܆34PWgGG^2TfR6ml/ Fٜc[ȩ W!M%ctI\Qz 4]3ߜ}n5),xWZR'"BǬE}Uk<1 ӓh-CD4_>= pA*".-a]5p_P^ضLyrVcL*LJ (9HB>У}KAOY ľ&BMkc,>jC[N*;=MS)aĔ,hf0ଢ଼g`1S0U$߫vgz0x+nqޢ4k>>yOo=0.#ۭh;? :}T˯#l.e|vC| ,Ȼk`{#.3?&ޞl꫰S }e>>36h8;i{7_#,v#Wݍ۹+w}ؓQцELw's\/pd'W^<ЦÍ1? <^d}qіt*{4%ŠV<ӿYd]h/|aH%_Hwu0zg|v}'nw}Fm_qYι}p1 |nF&&!Zt!5[xq'}n}yM:C]9%@Gɀ3׶JlNz/9K*iׯ.T~t0óOlOD Z@<|"hGt9Ǿ0,іO1 !_&vRzg*ȳWo[h8܁OzTy7 W\X,y>d_X . y@CE->`Z-Q6qL]G#W.VJh$+3XQޔr+=. k$*5_PBcA:۽>Y 뇫{ڱ Mj,k?W9M/nGiB| gV;~EB qL  yrF.w >biWQjp5;;:VIK>Z )_ Oea g ?K1DCޖTi m9g&6JB"D{ފlɚlh6G$q ,4FPm´+WuEaE"g'cHԱጉD]NGd=/yb0nfbѼ:1hw~FE1`l `-eOtT[mߒdV辰zNOx?S8"KVmO8b.#gZ{83'A]Cc#GiVS4*#ׁlnbA]2w戮ʵ4v;S$| cN D hd@ws.J!NU72N[7*FT'a1A4gVڏ{X>vBI9 .qI/Lq:!]As:xrk q 2@Sz󤳼觋TL`A Ȃ.31~D0<'d֢CRdKoݷNJ;H☾,gr3xwC˒yTEt" dhnVۓ08LQ/sڀ)S}[ȭzq;1 K5oҭ^9HsG]2 ԋ$ [9ѭ2Z 995a^?2فv}?E沷"ɓ?cmyC-.+:>J`J{ӊ }F8r)yh18|ǩݻkWFch?[ 5CX  pz\EgŃXx4 ,[Vsd|@Yۧ &sHLPID=G"(7\ǜuj$Nm8he8"i{%^! j:|BX Rif7{0]>(x^o θ)diYJKU~|VlnC!:X i\G/P\ԔST <yʷi0>>KqvV;B!|-Nc|tjBY G "(c5W$FduSFsn Cv?N^6qkĕ.\CJ3wԥuYN@#ɟ])ÉIT݇=n˦@Z~>(8hTx35Saq(@f23)|./{*ZN7g-DfdgVURi=n6e1rOiߙ;]~S$6 NmKKmgfBlxd PS28)^sdx R+EqZ1P!j>K~ꋧX.p$5tWY 'X.zzD3Jpa˂V3ƗͲlK.-_Q` 0F'~:OVY+e7+MQ^\?kwic +k1CF8Ġ2mCfL.}RsRU Ǘ8𠕢vԖ1HMhnK1qa7 όCПa|WT_%] p8M#TCO(0Qsz||U΀M-JcƕƱ&'Hch:OG;y^xY1{r&8(q_՗K^eϏk+&,cB:\McNptu(9|<[By*_߈1fAzCZC<ԛ~qa1.RU|[=e? V.;PT2W/%xnw!Wh=8CB&$K|V^֞ߊ*9h%+[*9>R*P<,(M'I}n`#f#\S%> g{/-Tnk#HK @ ѲAƴQzaQ#geZ?-]b v{)^]xsp4s˅Yp}3ŊVPj ^: @щFM.R%gW5 c8\hǣ.L w4ZGKYVߵ[&A3U\!3PK+_-\ZY@XdJre<ͲNY;b`m9"\GFINᚢKgD渉 Ef\Dl{B$v=8E-~iAֽʥpG>ƽlDI6c>w5=節AѩbΙ|!}]slKDb`7hFy =yqR*ݡf?s`&vvn?^.yC̺/|!@]4}I>Ǚ "]T[[gpMxU31V"k٣d=PeRF*RY2 IdD(ǘW)•lb^ۻ}csB_q $v+`V3PO[Rep>bħԣ9xOɜ'G"PR(P$8[i} `{8"}+6t(Q_3ʣ]6)*ރ<f٣ـ=]pnn2d`U|8.HyVYӑKpHnz߼T 7,U쾃c/!yNZ.Ew1p[iNĢ %_J2~DN~ k?3fKAuYVv# /v}n /!;9r#Nc x-M6Pxmo*&k4%U83G _\k4rR'ipn$;b [\b uR%`- V|×* H~rt"xm_'2nWY?^'+ f@vgI ϑVNUjCt; yD-h*i \R4879;L쬷!hCsFngmϾlp'W=Tـ4Aجm> ޒai^OFv֏|-*_'J_oVKخ!ptnl\1mGh;g$Z&8C1D'`KFEm2]M5 Νobע X݆? V4KT]j06D{ ,orzRI8'V%6shQvtч0C hZniY[ DW&d̼e1ߗ$$`_,R1{#agg)6M*)k\g$Cjj Dqmc]7e3dīҋ Vâ_­;<1 jT%$+G*0%JoٻGڹYe>԰ц=r7vdQ@N,04аU; h@~<c_@5톒1]傣߹ˋ,iO:/73Gyq+늚,$ i?B,o T+gwl.Vv i߯btH.l$Lc!aJyz(xk#NL=d8ג&GO=;c`*fJSdٵ4@|V!EYPf Nj GhxЅuHaQO1{VsSOy5%*sX"|f\K+fK$Yo*>\nQ[40܌2AN׎@BS?;qԊZާNczSJ{p>H *1wـf_x_ !NzD%8hf:V). (/"(c{,I _R-?3Vfئz錳0x.Ըʄ[!G+Ga `}`"X בX t߳]B#R/)L%Z^8X!Y_'~%g,xO@,MMmd,ЀGĬW*U>-N kLz)l*Oii"8Ha972bQ]Jt,-yK`nj:ۺFqĩ16F@Vb#>"O!ˡz؞fbx_zsESv4V2>n>YZcco,ҸvѲQ&T] !1-N$p -'Q\_WV`M!Xpp}B)7W`hj(h%]a͂žwRa,V…QDikM}F _!!\9Β58" {8sZ1BՖRЙtpeN HvX!jx (NR(mp]d~f9. tȓ]1'b fuM2Z_Iul~@]j|Tӕ.4_E]Z% LzQĆ6m_Tx&`H1 }T5ǹݐ- U+x _ SJBT&Vy&U6NOӎ3*L7Dw[K˦IVOP&=j<ӱqF gqزVuy=}04WJrYx,|e*r _"# )` />5]61x)q_`>[x텆 G̼'[!^$L4 D |e`_͸hW@xdL?Cp:2Ja݋  #lLp-|hIIա&jD`[:bJ:MQ!}kz%+-2bq>{NSk VQ|G~\]G8G3tS^H5K0Hqze >ͯ:dbg.KtbL|c| .tsba  sգzz]<1X}.,v&TJVXUtB/6,d)_~wnNdskLbԮqwDgk!"kܦ<ϕc?[|[iB=ڔ?eJiD46дwo4i:[2pvC"Ts*쒵/S)ٙ(NŹjul R l}>_Ie3,`j;Lh`froyjBLTO9<BRvVEtIw秷z)Z+((Bk;Qk,F ͤaAʦrɕ9iωQfRq4mǏF׵ IUt ' <<˕fKJNҸu P1Kz?ث.p鲿T y\cqkHt u|2NDv% Y>z}u`N-yXIבkWq4PHeֱGh6|o{/@]|X#CfDX4d۫F3z\^+>$AÄN!KwP'= sb#JHޙdӞ@3}``z9%l٘˭pMdiEvt1ܡOVҦ^n"*Lْ7T4Bd<^]Λ\1$ ̨2+.Z~+˜uѭ$%O+밦0ÑAS RsΤy@FQ!t,JM1gT*f"^|H GϦ;UoR@>6\ctkD$^*ЎI X3aAK a BYp^dK$/oλrluA; qÖmpM6ɣS?*CƩ3@!]<%Քy9tJ42'}6VZ!5gě 7wC ~hd4}7#4"Asj|Eg2_4ߓ4 yuEc>8 3=nz$o"S//J9"EFwrjPM8}eNL[O9-r\m+-3dz(mz_1Y0I("wbŮ@M,BًjdfG5a{=O4FݼEF?n<Ȇu$hLָ@|J,4iT4 bJ&1T hVqtϕA6;B&;YL#&hU烂.cVDAq3Șv1Gg9W:H*T jJ Yx QǭÝ oF¿KY,#= 5Ֆ^e/% <͆S! VA0^Tx״rQ& 'MhU3"4 ?lUz4뛾uD(ݠ{^l9p9a BK؏m xJTڰcCo_ǯ1@?Z0yн(yqxQ12U/I4J Kb!ym60ΥYs NAu=g+Nh̲E! [ yiETmbhC ໤H]|2+n1<:9itFj\%urڭ IE@$x$,Ţk^=d<03:,TElW2֋*bCQSc=3eB?cU ?u./msyw -c!</Zvߺ\HhR 5 ),NRO6N|s`T/_7lNb!D  %z.\d0N=Shet oSHڇ %hƃ{g%ՀvС >KL~阂#:aWGGI QTz;WXlp_C!CzS2砜^Zm[0$PY lTNtLN,a^cb;GK|$~҇6S4 gMɊ$?N^'+q;fEk x<w>jx7nؐPe D:`d&1;P|b/XLJt?I6 /}z` 8~ELXݯo|x/14_b{ęam}6 !{iV(Đr݉{4[ud{5Lmb)+&M=B%Â<Ƣ18egVucy e{>l[i^2S^^@LRUλI\[dEx=PQDA>LH7l"9JTXdHH'>M6>S^>[T愄& 288 @Aj`uʵq2 #UetgIF[l7M*i\f%TX^Dj0FuZ2ecZ,EE9~ܤYᦰkȪ0X@*CU#|]k wPRЋ5,u4D3[bu#ĉp}4P':DK㔋+,$ï@kPe" .NQZsN!Wg%K*~ʹ鸘Xas]fp Q4T+|XOd]iZ;K XÌq/}X>3SyɮWfYrCCW,hivaFZꤼ5*PmL{,PC8(Mδ0cĝn%XiOd3RDףc?jcFVLLW{o %-L3$^wuvJEru#v㻅ilwEZ!%{T8_)C?"TX%\ȵ1;@&eۥDn ɓ]NRఇF΁ sӹ!K~gkjuknNۂ3?Yos^an^/2R=[1+IXR>.j+,ϪYb#/AhSV-q#n)\+L?b X7-Prv?WU0'"y/[smU S̒pYQЛ7h(d\R=ίn%؋ObƄM|G!1vOc ru;(>03yRpC^ uR`9 ]Csn ^^ "ٲnU-3 UϷnYHGüWd%Z.诠P BվZXj&^O%y=?KeHafEd46J E+0RoCPex9՞ε?6 3vݢ(*`floTQf|ϮyȨDƞ/2.9C{;{!0Ŧʥۼ[R@$BJ(њ?xzs*fH]l-sꝉhk`߬8'Q9]9qB):Y(0r,@866 JA [vGvVjt/4rRFZs4o!DOuو5eXYՇn)ՠN[^k $iF>T%eP8o]2\jt: 4.tXp|4?>VxRqC:ru[ 8`w*r 8`%@/AS+ۍqYƒQe!'?SԼ{WW Ìn[AuIF8 5DE|Jʞb*#e`iMv ,ɳeȾX>I^CV?8gVdz_I@-l\g&yrnQKg#mBm2,A.A%3\6>22Rk=Vuꤕ/vzqx{CR2,£Wbֿa,{O!`ƽIʦ!L!ޖSE<+آ s+]mHk~~~Y2< m=o r  *xv-tS': ]=:Qos&y{X i@4 ck6h(TEi$j!(e#Y.@'I8y<}VČܳ#³7O`^jY)E :*6ڵ ƜTZJ`T DUЧE<cnXn:АgU1j\L'x H ݳëtfϕ"ϰD?OUX/OLx' o_X HW^|^\)Vs׎3NiN7/r܇%?rhM/UF~oۢA8W5*y'U uqY?lW!~$^\e)/w492&1nlY&W Ԯw?h%c`m0-,ϽqxA4J5ְza oX%{/nNrEttyL5!u WeT+p Zp<#G~UJ4uy/4D[ ƛdf_rhD[&OzVuGSJ9pA5xTE"|1J0zی7FrEb[3g -ڶ%d?U#Vu. 2w hXͿ?@7//soHV@.JRܕ^U,☭_zcͯe?]aS̽INz$yo27pmO7PjucGkNeK)b!檘%.+^|q=1kRH?^Jmf7 v-<vWA<톄gP|"o8 j<#KVjT2u-ζڡx:-Zߍ`w.e l}f{ {AEygUNm)q6y(Cf h%<Щ~F@|.gĊJqǤ(P S"-z1>^S DŽYMT V ӑ%B iط$ a*ylݗDs} avyVOF_ ќ8NMɅ'*g wW4@=u?HN3qgׇщTu=F*!RӍ$KJ)Fv$=jDX`Kpz+`C9a?ʵ J L1+"B} 8m{RY7qm!l<.=Hધ{adX=k5$X4W:P/HI^ F2fQ _)cV\:&I-fݖ+-h`Nca .cU* gW<E31j$~5\ד DrxL-WqT[;vk9 +vJLQr&o8_(hb^^ؒ %g*Eߩ l$"qTV*v=?s &C[8Dfr~8dy5}v䙓)!ߕ_Ʈ <ǵ3&Sȩ#G KkIeAKk_4 <ѤPDq1 |*e np ]ؓ'FI u6kFq1.VQ:t3htl9Msm6#!N;ۭ 2x14T,Pet\m78sǡ{%BkrΏJPuK4[>BrƷtZr劢KEV!P11tWL}aPaQogٽiI]g a [d=d2zGH|$>؀(!ݚ',F"eˈĆ.4 "qs ЦQ(=`ELPUڊtϝWZ.my&j9 ԓŁ<&Bg lEV0BCJ@y|p8&9iDd#.Y"TfWU.u;j'-5V&{['jzE~["h*9bƒ')lVҳDm*ܩqב<9I綰Qf*hȳ t,2퀔>hoWNSrǀXө={|z5P5aRPn3:ES,'58<.$" M-LPNYT{*$9GF 7hGZ5`P&ptSxO%-5UlxliYP:5{%i`k!* ?dzV\i$9!跔Q?pʆ e5hl+Y5G xOBH4D7g3ި1P< #lq;3 lwkDyuOC dEíy'qa_2/ at=Lrz<q?bċɑr[n.'U ]PWR#]) W_{›h)<1/d ^OZt8(W9;H8Wт+BUw=w~G FȈfZ³4:Td)EeeXL/M9bR?#|L@l+h-i`J6$D0o׈ϖA?&+WoǶ`QB7Z3FG;Uur~Q: ,[t\Pp4 Pۅ̽(=-wW;dhT]7 2{3٠{^su\=E:Bϟ_2 A]@tm'TΘ]5?@&Y^va? MdF#TqJ}gCgh`8~jPǪZB\G`ɖֶ aՔ&/oaB5>+"V{2*t)2Zv}mOZ .r7Y,YK+PmI˞_5]!j0\0OHf'7n6b#B7S: rR`KaWYk,{fʈ8Rm,'d8ɇgL'l¡ZDIs ՞@u]idY-#TrP 6rªi蔁|mE7_RFpC*5 FME_Hk4MP7Y8EhOX |4U:mЖӆ߱' =)jq2<+-}s!_β' ?xE(ӌ-x zG813VCts)im\+':YbzDZJ/2s.T5672'`>ö6F_@UCquE)'7z<*Jl.O0g6u³ F6 /04Ñ؈3h1{]>5t0VϥV{yM Sմ!dKߛi)Is8Ex89~gWc yL_ "q͒h@(־ =C `h l"tfh@LW|tZjQ} Cz[0+ @޸e^,/~S3&ކB"P Aƶ؆:s󽨍=G{ !m:C0Dyʧg =b^ta/@ L"R5' I9Jh*Њ1e<-VBfzCVpP|(h{[sk&*.??rrCWo!%Q}3C9_rDMM m.i ͜DDu%H=8`](KžMˇX 4Vhi%%d}OT̆'xWێE@$RpUbRLVmkܯu /pdwG"j7uUkBĹαXN>5~T]HFWZw{}bAdxC ΐH-<>nYZ#Lp;6-, xi& VUyhȽNĿpg6sbEu;j6D9Osꚦ&Cu7R 7<~X*wl&x.Wt~V*Vp`x,d~qx$2_?zPa(;@B<)ڱ.S2ECOQa@~ h3 ;X@I:-$,jb+^{|΍CxD܂FI}oi0"6aO⸤ =R&aħ]K~q6~j0C<$t3/MT#延Q䱥BOJ~-񾬒Fp;pBwۿ)U^,%L6?vd9PxNJۈH*fwTeB$2ݠ"8\nUG^ tCbSW Sz5{?7{ϛRL9 CAk(ߊ"arǖ%|O+lLasr.D Yw`^%+4STsZSX/ݫB T,jgd:}>eOKڂgJ ,Q!즑Q)=(LT\(1R/֑e`LFAݽhhNj LBL"ydkh}j:^Zhp<`]Mbo |FpI5Tݡsb ⸠ Ä́{E@ Zj;D쟅 6Æͨ#Y奊ִS88%Ru2Lv^݇Tܦf(VߺXtn=p`ˮW߅(s]nM|- &~l4e ML;OHw\v9 2xK=GA#0G!z>v9קQ}~ ;:MRpW3ѝaAa0W.,RIoi{4mo"t 8v#r&`K {$fuf6[:jxNUPJ$m[u[qd3m|lviZ9WMUb0a@4Y `x5bD`RR>!4o*W w:,K\u՗r7G{~R .ةC/bګ(좲}&;$'U2t-`-.']7D9پN~(iPSc򼈙zzw偁A_LU͇T@4 V{}*[ T~Fl5а'*Ax!f U@Ře2eߨ+8 54Z}"a"ݤKWj }wGl n/MF`E^U&Z9 Hz|2XyԸrvpo ۘ!q%|4bHD=,h05*H8Ba~ _j&Z!՚;D18ג(Lj T`PFd5_ݘqTjAUWLE.ɊUT54t۬f2{$/Vt^GZjٗd&P!r H; 9_K-GOq_ӥ 2 >W"oe*_֍G8m6!{V2%*"k)٠tEgʊ*6oJ'PǪJlk,k>5ys>.GZtU'6'F6oe*b!T4N-*~Ia ~Kq݇Btjxܮrg"mxf ̹.xJnƕNJmożE+:UJ؎> bBcT64Mg ^?LjPQ9_B1-))Mj/r@CqpATL_ؕy؄CO܁B&^[nhy=Y?BtDmll_<(v%3Z~{R+&@Ga|K+k'ٔJ/1 Ǐcе8v@Y~60,]qLJ%-d%ŶZ||Ў%5HB]@$ØKp`N80.cӃιa=*;pE F2w\7`Y7+%}Ñs8oM{l:jKCȶ;W*h|/(Q'@/Ǯ-T_K1s1P{$.&C62[RyMIeaEGUt ?(+`} F*JPoݳ6f&ę*2] 覲P(2ėA\T_݆)mp![v92`w:Vxc^Z"z & ˧*\ T#zf0ӥ~qj%GUQ+6<4E/!~ ׇ]7TOqߝpg.**c0(-urQ p=B)sᨡ8l%e5oFޫ0,e[u+ewyq#!u#:C$L=)o} ` YEhN񢺏knK&]nо\ ;~R/_Q:^[S15?ou4oNPu}xR_AƩ9`CH1xaDb9t5?-ub2][91OK<+`kuSXNskhxRs{cJel_{''R!s DWge=nqbhkF~T-/Ŕ |9 4=#VIxk2Ӄgzlk'QY U) Tj*FEA|ž 8MGA>v8ia`u/[nW#yne[?|p~5=d=5KY%ΪE{p~k(GTg>Tx*qCA)U:/ Qlca*D&f@vR=]׆z%Of檠q(} e`$WV!T?1F`04nIRPsrFVcoWwO^tIŚ;j~w0AB䶢XpTQֶ#"ʎmϡJ}в`!xu4ML`Ҟ|s7uV-~6wTK#<`ͺ@uR0 <s-?O$d,AG' -aEwrb+&@%+`N 76 f";4+G:uvO9HH@ s'0uTxb\m?z]@"ULCv>r%y#.AG~mp|E HPYGMNO8o+MTyn:X3,N*t̗QUe蟔k¯x*ܵf+KB! sijuftY_z.,j4^!|~s>$⤝ދN-\D+ R*%՚w8&-N:#VifݡyCEHOLRjW-ۿLIk9òW.6×P%#c"hVKRdF 5[ uDl<g—&OX n3dmlHZ US\bRzb4Sm (G;|Wfo=#&ob՚GxhysQdK^*тyDjTV(^JYy?y}m童QҏD{76;=/`Y)h 48e Eec0D ̰xBIl-5-9ûrŧP6fOCSK2cǩ*ZSi|$D]x$0˞=}\ۤ$52I"Iˆ3 Gsy +iT. #-Xw!kJ(ɡɐޒT+^"<;D\6co:˯Ae+>eGiorU$bpA=`*b"т2n~ {Pjr0/-f]meSV%Wu8Ezz9#Y4^Z_0wN)B8a塯k?§ʰbof lAp\F͛@j4CxQLt.Af҉3F4}}^"-X}=:u1=dfd!dX'Y" &-g:_= zM RaV:0z0Eڰ= Ωn_3W`6 \|h ߭S  `HcGFP|ta\mi8b _'1S,G.y[򔺰 cnxkzw mjx2^`5Aކ# L)uBiz_zW%v q+9xj1Ŋ,c6Cy\:.YQmo^v,xF1>cuNUEe<>s JrZD{W.Q8 ;-;q!g [^ $x .Ii!:f^.pHI =Wv_(88T$tN-j@/[ښBqg+]&2z:g, HlFPƋ6C-a "Ϙ S:' 5 i#K4sx3A %!$FXXaC>. G@[Ug!?nC+&Πhbnu,CP(kV\j$&OL4+fī4yʸw b'^q !.WHhbȴ#e vg, V>[Blu]vY,WI){ z\ǜA5Vƪ {4 Maq#k_.|>bvrb=iT/Tj1hJzeL!YU0 ΧwQ.XB1F$,:JI71[Ы1Q& &X 9zB`BCS3`q˜[]p-Q(DV-7?f.@;Ც zKgﱮFql-ҡRE GZ'jf PZoJ|5z V ضϋ_r# zb=5ulvB sЧj \0^zXC 囁5?04ЩwRk-D HD7 #*sUF5a~~t3NݧG~`GliZ/NU\{{ג2WTϑLu hJ7^io ӳTdo:p_ۤ$LM~w _8jh\TH%^F iOMVm㒆)*%K:5(A6Xv84a ,T"|< pq2i$Lϯ XaPk׮pU$`z6 mW I+0^L(N /kI$ }Ot }tnb4ѭBRV :ssG/DxdfM7%!~y w{z ʭwZCsmW!7 #\.`lHV=Q]lk=Mt2Te~<₎O O|{̌{:dھѱF:)v5Юky|<̶m4qk5kLt+A; \{%~IS<ݤ(X0Yu&0\Ӛo1̻NN*l$]V>ywq{7YbVۤgx>|;NzIΣYIJ+lLĘall ?%D>ָryPZ3.fƸ՝m3kT?\1F|O۝=Ԥ^ٓp 1~<̏Ä'v;h^.v[|ۭM39!.4"r~Yz͂C#X%{!eN1TtZ("AE[n:Q6K\(Ņ?Lah.Im_70'mb #F rű^?m &eeO=4//CZM.&Vu<攡{Z+ηGP:2sMDI.jSHȲgN0'L{ol"!jE&.IqMzCT˅ ߶HOY-hPxdia~<}WJ4ɀ@PP>@B-(&ϛ¾\KSEfRqT#ܧ BPY] @rfH F 2<jj uKPL4nyJSF5+WC"lô-|?!) ~=` v 7M#*jeo1Qy[^yx ȕ_vc Z2Ig/M&&iEYfNà^Ӷ*4A&Tx>Alai;#CJL,S3I%-a? 6r pˆS2`P*(PZGt+.ڱ1kIɇ˵勒6N 3fDn|njDsNz!rhCyI"I̝]Vi `ߎoIb&ƤW9PnLh{U}O3|BmPYŋU ΤFsr‚nxhEu ֳ$U/%6Ϯ'BC_*"yEyS@ Qa S$Tb1E@Dφ&Ⱥe^$&OF}#XPnXa;m *?t R1pKxgD9fFQ] F ]Po>]Br ޻C^0vè#$N/,'ljw1V3v[ q`Z:0G`zPoopNpK6WcId`KaYcЃj k2r^UUpHY3S+l!;~k!<|x&iX[=Jn~q UyCY GE/DsͷPi_簽tExV&9䟞TA*2T{DEG z2;Z@P.dNPL C1e<ǩ@I|ΧF%V 5gX=8+&quaπ{1M^bL92;u8de\K V{B('ky>8X[0hky Mu&T=LuͿ$OXRrHc.>%V Wu t/1]Kݩ-K283z 9RUDDX/2*tRVXMRӊn 1!rRK0KrX40"ۮRSj@A7AByW}Q4(:D}%U[g.pX#8"Ke$;+- zo k}^K6#ov_YZ!te=|}3HwCќn>/6JwW) n,XY|2b0$Us b96^*8>C R[g2Y؝} -o+٥Z󗠐eX%g1l/_ +)Ja3uS;/ЄQK ёQ54olYj=S^ IO|]w<\|f( (E1˻{P^!38Wܘe(:qˠ ;Q@\\Mfi14t}O?aQe^:)th}T/:Q@͗fgE2,dG/^I߁?+̿[% ,{t7!xjEJK0<+YNlQ q{QPʠx&)eEcUC*DfUWRȝ>YT\EDU($*Y?ْfÑ N;N׿ot]&GfpBHp< 8:ޚϛWٗY߻qBgP~XV!b"6;bMS O,π-؇w=CIuMS= +IzE| p>.4n,e P Mth1eVдWd: c;Bb,qUZxܽrrܮ,s$=5™Xv3Гع HV6l[' G9 P0Ί7w$'S r R 0VpN Sg!h955PY~#+?k^Z5"d8CL ~/wwʧGo&FFٜ<uuAx_:j<%*_h )[2|֖Xߋ*s+%|ӏ@Od@>3cayUD>.ܟ<&^;hDUj;*b,A\'nR[vn)3oY;s祐(='}:&ΘA> /zD}I}IʁYzQ>>o#сb-d;dEC| :,֝G sܓ?%{f K 7nz@9Wj*["so|xS ;95y<gyuσOЛ䔙ȧ˂x_۾v-qªq謮0ppW$l+jZ,})<2h6 YJSKILkr%o:vU|vAˍH廉)v}ls@[L HLAM ~?o[ _bS[< n%{OST1}T-W8\=>yQv8@]H}2|nz:b\򀈈%=XBo^`7`n MŌC`j eXpFX܎K*F&=lqo.|tB( #)R]~02V%ywo4^scpe MS®<2 `"=|ƃ|3zc)6tJ8T]>ݛZ+u$*?s?'VhVxT ;Vj#VyvoH{{^ ]L7FHvC!!@ďRgzm:z-,Zqoȗ,q kW1iUZOY ZY#]F~mY /tel4>BXcw("48$fn c1]!{" .-Ov΃J|Յ>ORvDSFvO|Y?ŋ_EߙQ'ݰ,0qƪ9BJԵEyqP䰺iΞ/)GrA1KEoJܝ"^48mGqOIY2z:+,r z-2`zA8=6l\f& o@9׉W+ ֟4D6>/͢ʣK?tXvjrҠ<,bn0`DFڿѽ'@[ V+ ;ܬ nwg'=uQ)6~T6 (:6g 4Yh`Ȉ)|Ph r*1Vym^ f= "kDVW"uRM<= :e-ؙI9eZ)Z8yU,X Re'ƳD/:R]:J|vޟVV+?y{2r>)Y"n@?i )xPX\%^k7 Ʊ?pyEC1-1J ށSHh4()4Z~VIŤ5[ z$ s2DZDe7_Tݤeo8ul.x^~,~^2?vvܒFfZm2S,Z@gMI+wݰKYyfe?oɡn~_?5bABYcX`[9z^7cg*55}oMm!՜?x5~+d쌓bU[s ~ (AbDF℉h`%JXuq\P~Vȸ:lM3r?#so5k_t&pÕk!*{Y0's6b 4xDѬ/1UZ@χVfI _HG2Eu׉O=4hHR&"k4.XZ6֙|S{/49Q Ԃ4=6u#!4kF'؅.\\VMt}g?iЫE/ r=Lu>_JլNѕiloLb:뒎ȇDYFӁcNn}D4 l}Zk. x@X0k]VjԞ JzDk*ziD9R*N ob C 2eOX3B8]r[& Ҏ(p9%7'5B Z5QY=A931g&MIGx׃όF yݸ ZA JeQnPҷ&')9_Ee:H͸sD8rX E1_yQU^̋]#ZWdBj֠K%:\1qڎjEo<?w!ED\6ǩ] L8y-ҁ6twluNoMI40zvKt'B1$&&,iAp޼L3Sfk5'?S<-"]Iv_`]F|!F"b 0P~p,_4D6t/ .(uvAOz6<+!Q:^w q[+?&лz;{;ЭmHF`pz {>f1Sh牲܆0#K @JRxq(z{=TpgSV*2'%^F=YX~a6cPtA9yɤb񁅿XbyYDNXBq!0/4䧧F-evK%#dn{kpM;ht m?ouY1q= O_]*谩R,j3wķNOFJtVߒw!=B5>MG:{w>=;^3'~3i|= IL4C$paO֎Cn)bQ w6nY}\75 S|(,sVrΐbϩ3{41&ݿyZ>?rӎ(,n#O煪"|*fmk.L&/T\O,+ ‘)իB*9|F4b5U"UaT;Vp z %KieR +tw-ئhFFueԓБ T12n%WaM9&g̉WT{zr8[Ir5T_f3(/y ; E&{ZƹE;}hwd?j3oF^D_5ܝ$P8se\h#~)#@F񜠺~=lUzzR ٩·H -3R٧ G;P5I0/QƱT౬YĻ6r>e܄%84R vi@5{l*ke(ü1 y%P%x`,>ܠ EmŘDHϠ3(.E6XgU ]mbp -2@壧ݯ&\z-_*5=D{OĨSU"% h2\Ü_- ?\uJO^p_6WBQO/QdObԵR1Ԯ Y:HjUsUxs,G]իq(+93X.JgAAXY>G&>̡\ZSț5|ˎOU&+1H -_mA/mB'i Bq"rOGL߭d7 Rˁ8& Pc*0j'l.^;b, ٬r Uμ/YvĿ-֩N I1|N\1q{|\#ܿw3 '](&^,My`PSP:Mr`T[G y0p_^ro!JM\;g(: ]&OjWr0>M5eqqXp-,1#T86]d"FtCU,Y ٌ&(le?|m"зr81y`VO?d5?Uq{DŻ6̉ϋXXcF UrzZ( _H 6)QNN&qP *ox4B':Us?rǡ>E'dzLz1!i ){C+MeGūz T1DŽM#Q0A/7X*ۿ L*V6HU q N('nu6:e?pO6NbgwVhOj|Jdw}u\TL:\Jבe˸`{J~KpdL,m\ȏNw7b딹/XʷU֚hnέ񹭚ah2z䫯|N%%0ó,{?m {EOp5>!p)׏aⅧ/FQ]ٌY>Ŧ=Lkz~O͗2~=0=Fea|zo]rHH#TA2GX@;5ב0;Ӫz̀zVa3E~vV|Ʒ(%e+D҈+3` /Pzd'/J XMOf{+mT}3Hi.gR4C?Œ2/M&{(eNPm7pcGK*PJسK1oTv_;M1[C`\uB\5qRe}kٞn#Bf(*!Si^3RGݮ&18kLm\ds7CiQMx)ψ_kO<ӑ_f*Tw@,| p VLVp=dԽS5` ( q-y/4)I?3G=>\W"hTYi\>Q04,5F.`7ZHVKZ"_șD%e"d,Cw%}{PAFxȩ!ΓX,"XIN 00ۇzxZe ߳򛎑=`U$`کLG jD3 +8\b撨MϢ9x *(ĄC]q.f!+%:~=m(#)qZAxcș7yq{i͚ mFX}񲓪߇D6CGK񖲀{\w A{0X!+Z4R/7)R΍edq$ aX+i_}I3J]?C"LSb<ʕ .ױ wl0?}F8.*~5n`uѬ1#xhFoЛ+5* UX[x;B^s9'N&vc9,/.4jI]x>״FGSӥK7jZ: c}4J{q]{_jFzRgh*$)gـe&b)~)&VR/x%QdDѩꡏ=}]IC\ɧ\N>}Uq=vU{*3j"Qc fCF7, 0M7o0$BU쒈RZ&'yd 4a6 rc[=p|ȖF6u` 8ݲLGZ$R%4 \Z-"%1c:1s+sUC\V+}] ii }Mt? FFۂ|~%"ġ_{b``L5:NfE P& i6}=KJ2:5B.|S>X+yUOvBܣcmjt(b׀qtuk RӗO/{]+5yhEal|jHM#/x褢+P=@+V1>zW|Ɨlj:RSuV(<7<#},JnL]*mZ #Lo_O`@]<7m/UjGP..-c`3ι[~Ԥ8^Ec)kA HfdF o> 2gZ}!p n8}[ ڼtΌs$4M{Iv[cfNE⑿5# (g ^$21QX Q~/~KC%!u)v] 2eQnQ,Ju=(|,{]&^ Fw޳2rw(#|s(H~ָ-X5su1"FZW/&U*JbsY`؏y; }yLD(7Ih~?e jc~i~`*6"I_/!5<}N:w1?:Ͽ&WV0̙ \x(T{HLqT Y/(}G`4 `Z;!_'/됍py؛qzW 'af[q\4l3$:{m^P!0Ki(WʿK ɬh!@A(Vs+ghqe8R,N-{?DFVB\֠1LNd(2);tC@Eow*g$8Ӛ{(*C)`B%d :m"GEBkxQMCs&;NbKZiP"DoSzmb_H9֣ x&|#\_Z|7!'_Wo PM4vCmQv,(s 6쁜ʰ[J$}A gX%[ޜp԰a [h.+Cs=96:t&o\YS+Jű+akNx7,c=ElHȌ5W'U= ؠ@rpڼﹾ-v\ΛMs%+',TĖZ9:ryڝχI:` &E;]U2. n:T]*,صdڬ?hGzL-D^tfM Nن: 6$> b ^XX{-8FWiYO+Z?3=IOiFTboq&E$ _zQܜ5#Mek}'bBi2¥݃AcV =C4[zY#Kʀߎ0M㷭s7':pgW.32/Nl#!̽zu ؞-b+}/Q2 ;]ޢ~w!<ۢ͝'Ġb-]E_Qaآ?1Y JknH=*PɷqSunVn,YP_Z$/#xm9,NKhS1? q+ӤH)vҢ`@%WoG1$&|jMϖ KO^'#+&)2;&5go#͌+|as说*GYa4|,5V - ,Dkis/hߞ6&gj5gwjXE)ZF$km^ץ37;u}om10#~pRW7h v|.A @Ҝ0e~Xڻ 6Evh)!{Iq(Jwf]i^E GˋH-Ʋrvae? JW륿)iPVhc/Ħ ~N-fi΁r"~:* .wG#yCM[d:Ә> 7[2[(%뮶j>n[cRݿ2x[-r0!Wli0kg4~1'+iiԧf}fl"^G/( pÃKR~"5.$e)ŝ`/aɮq]vP=W5I:0e 4Hƾ\K?&˿u-$hJѧPm`)%W!7{%IpP#*5-`[uӰЉI;ozk` D5 VtwF1=y)#j1*_J (:&;KbNuofᬞ s/:9+V"<%ActMX ψZDb/i5];(6brzRBfjvZr;t~bK(H'-R;F4]&>!'j_{$U#gs PdR F/oS*ꅕTPiJn\c;oٛ> GW=6k")w7`GK% v^I¥-2 ؗ*<_"aXlQ#l,|Ue l=:9@6 f4< .Y%Vy@:Hp ܪխjCulH0Bc;Q&e&wpS`/1vk} ꗞ6x-Qd7Q b1:-s&mpSYums{i('3(!`|0hjvu|*̵)kB %+YtzM$Bu]\9CJy\ e؀6x+]+z;Ąֿ*sfe<>) @8grg&ara264ŸyG]Q=(N@MI6FD8^BY^Y%P!aFsƮ@kK}_B9IHr;¢󷝧X񑻈RZ"_x2^|E@ dYehf1Uk񙣅Zs&(/@-iA8|1J&JNjIg&"hY͡V[s2yJ>o+.ÂnSƔz~e#mx@?ؓegbBCj K(˳`ߠE)ژiSE!f5D,N{-pR|l~rn5+_ེMb4ւ8 :ӅK[k`h! 23q=i )_esqW`x+8 I/Gf\y`E1aI-KEabUטe,?iI+K;]nǗmN "-CyL#t'H}ؖW<__a, OMبQڸ"z4S 0qG;DLo|ǣx?D,ׂqX2&T0{mRn]c:xK?=Up_OR;+ՙݾ0JB|,j;,.Cj%L^Tԗq¤]p}),".zj'7d4lMHMVQT1}U\ E,9q?,E16#J sgB++G(Y2EP/ GH+vm7qd}:!*.-#Vo?0  ڏf4Yܭyq#VeLo.@kfDsٙSsPR~ @y!@l^9<; I/$dg]M qfM*8XinMM'  YԦ!DÝ.,n<"s 58jTZT@4w1prh,VCw&b3?PI5{Hk63ub0OUdἢɊ"w_[T#*#_4iEIԤcdZq:Z?tuΟ̋PeF,Hl4+;wmP&cW/Cz4@sfD(޼h) ɗ4H߮0ycȵR`[oߩhV` ]t a">b[a-3ۀ-J%Q 1@XJ*uj;FG pTTWZSܗDܤq+/oOzm/h".` B_@|$Y_yW&E&wv.Vek#5x`zǎdBX9>| d=*U!@qP]k4M*NΓӇ_ģ=o"fT-wkޖ[K:GҢyM=E*HVhƮQt(qO ,v&$҇?t=u8(|x(=A2U0FB`(r gJ~*,,݁r-jS^Z]o`>$L̵^#3վο XkmYXR:FZԟXwoiowwO OO{{̹EE"ԌQxܑ@˰p֬'e3ڶ3@;1[GqOq#%.i eO6f,`~W ":&ioD8[w % hEDMIƎ`9 J=&6? ^=M!Q++Br[fDɝCm奢hj# q 3/gL2uQXcJ:h׀Arx+(َm~]Oqq,ǑN~R̭UCy:HpXNiTH 곆\ W[S)jRyN1 2y7|˔M^?sS\jU3_Q w6;!CTj)Y=o+*?my{ӈ'V̺Fh(鼟fv"ٍea{2ե ms|z4 ȃLqxljҠhvVRX@n5 \ɸE:T{ [_'GңySsb($BV&\ MEq? n3s_DsӃxtjkvއPG ]=6mKuGm) Qmy.VձsKNY@aOOxZF W~\ jdr ЙO3svbׁ6arE]B*Ou "8ݜr!*dёC;S'Wre*,VK16.ϏYWU3g&2@kc~#.3֕Rs$y2[P$Ӿ_qr`*'K`X OٚN/#\JWMd`<{)H:+j+j^rL 4{tpd"x`Z}w|t|Rezq+X {¾y}簰8RPAgmλ<~ZI'lDfGPGt>+L)CުBۮ}܅qy^cҭʼ(gOnj cѣsB'e6a1̽ڻ-E &=]FL9̓7è< ag,$LQӎ S$1f=P IӑDV47D)#ȂaQwX`@rQtҥQ3y=2V&S#?Xhb:)pP~z8~#`k ^ə[ܲZ@+FGEu, g%K]$lj4ިwV@K`mBx{$r5gB+a$e"LxPyeF]'qVq0Ԯ/{",5wI]}ڠ~]Dm,c{:z/7~霻ZK0|B'@1]3ň$A"GyL΃ڵ8hʻKɆ+,n_Is,dUEw?̺])gzsØ+4J/)%v x#q!߉n3;YBLuXbKpMt"I}I)e`AU7s-Y&xRj,cR`V갰pU*A{D`EBb *EϽ`>ļ'w;:.CNNBl'l˷zV(.mado#fluuOm}p2߳ÑAP`agRwF,N͒/JPxMxl:.y-ro;~\=jGK_|ɪYlt9uAl ..o5\3R19xO b@ɊmivF~Ds.tn2{koxBuAG\v>8ߗق) RÓhɇ 6ZS8R8{C P0Eg<u"M@$DݑCA@v1E9Ź6NN^6/|!AA Qk'[ oT\ o0s|[I0etlrak@ܿ = ѹ>iu6_3d"YiSR5r;i>*:1xب P&z9|&MͲyBCyϵkśX'>ܺ  L(ӽ Oxs{Dȹ̆ve^!*&_5,Wu ^nҗѝ$ HcSrow䨈,lkSZRG7N{ZGKN^-^Ҏ,#&EМ P<lh󾹼1WL*ݱ,%\g&& ±L>$%Tͽm^]V~܀?Y#nV/$r?nǻKx 8!rU?)m+" DŽ8(̟0(̪CZinSԿ:W7hp0ƹ$id3&@}M0vxK?1FlN_}5aB%"J~9@SD+)m3tv*Elfr ipZ{˚;SEVe8!T %]P;5'?J&|KЩ է$$;@Kj nݤep'4 &|dƳZ-*w'}CU%\5'  7]#M;bW0`!Z}' Ϗgmor7cpc@㩏]ҭ蟭*%EQ̪+!=t? `u'_?koQ:K-'Zk2]76BLZ\"R*Qg-A_|-'p>5I( QW ϖAD;k3QKSE6+OQ.B=:vOO&A*R j&qfzJ}{\؎ܼ$օf+wNkO° xv?a /~̅S)d!p:Yز:d(mExp;\O*IVu0'ӟytXb* Zk>dO*-E `]H M:fe.&;N#h f.uF'=]HHRT]@J1Sfɸ\܅,5ЈIrMއ1+`ڜSOšD"f.@Zz}BWa Jzt[962i'FŌƋ.ւ5bQƻH$F/^Ce/pAp?Ucm"L8Vw0:0 T]TM@#%'*\5PsBJ+ IY \:M8%ܞ ioM^٧he ߜ(]&].j{]+fr["`߮UZ85 T*oJ!**sZނ0_%q[!p7뱏 ,f0NEopݸ0ݨcC 9rkʛ^7z{x\J10cTvaS] yͷhB*on}P&*(UIa*K(snQPV:)t4N37@q?S)$yxg ԠF>4)>P1IN|4-gHr7Cԕi6wK,EK-`=9ZN?eJ%5ܓJI7-w>" d3QbepHb}Y/X%CȬZ&Q=8J٘S*`][@.|lȔ]]6y߫pDט *"|>"M.JF:cJOu]_.݇&\I'n2DG .dF# Qi%')ӥ tRH)x"B3U;=珣$Zd}Q1LWVc~)xDI-:K7rLLӓhGcv=qC`!zu.|G(*lݳT[Fׁ=Zw Sm!lߒgv/lb)|A P?l2S`wkJ,lE8 WFG-zW_fLo-x@*<ώ [!@>UҐxJoa)@wĕu`" ~4{1ytB,cõ -,=q/$V¿vnIX㠒҄q"0tlp`yMYд̳+|,𨛣A13r\Vj#~X1H!- D1Rv|K04SJAS+aXep%‡}M44ryؐJ/=A{L$YZ6qs_ӌ9À]}7[ܝ Jȿ8ύCjR䆾١&Msq6 ҈X?_e ˜j_y\B=#2iG=*9céFP 2$[E*6 մ1(<ȮFF<& -Vi>O!In>t|'Բ Pop P4,l;%a^C4XU%=x" ^$;W{.MQ!q;:n*,yܴMmg1<A<|ZN5wߟL3 4ȷJJ_928o8lW٥1 b)y$:J@|AuBT+0 d1%5NZ~YȺCAw*⨺}KsԶ_B ɱ*4 DDTv]]6%vH玛# v0B-VUz;<ю#,?AA M}˧W1{%z.VH)Ka{U W@t5nD[{D)Qg]_W=hQݥ.!2G\`TX{2s6/qPq0;FKRfs_{w9qJf Pw<RŠζ;vy$H2.ÿ?xJDTS_1$J6#U8z4CnUl'f׏MݘwKnRB 9R$znZH>扥kRZro@Q}ʇ s%i_hV۲ pzWxZ!0υ,6tX??pn[ M8q6!hrd> +zE$h,9 o\2 H50/YV]Y*K3J8FTU[X0ד#vĥK&ׂ]ǗR S-FX:ZLR\Oj\pv*ʓ*L|(,~=4"!MGBjcPLbll^J)^=Ddwlg[Ȥq]<-^b(. h\,- X<廉FW e=š/Vm-˸v?YCcX9aɗ?Ɗj^Ug_?Ys~H/Ҩ m. p' P, c#>Ř*tw?[Ƀ[/U"ZY}IXF!Ppdȯ.L^Rfؿ>T =Qeä9'"emr.^k p~( y 8:k773Bn-_޸wO.;_O$Ry>7?hE[xX&YD'uLFLt3s{G .]O˱Ҡ\â0:k`KR/ICOb3N;#xUə084Έ6v+#b#TǓNjK%<\h . `\F M|q;6e+8$E#hT:WԞ }Pt @d#&&'"D[Ȃwf] X _[8'Z}٘Z8Vu[E N7Ag[u7vw'qP5ɑժNnڇ:^Sf̨6;OuğU2jpD12ysme=o[u(uT"P,g'S:$y&X@-k0曲 jDWeF>Z[Bnu&)%U_:g0u퉛y+=u1>f QѡL"lCJ[OO;]%bɷ-+s\0ӵ1Z"Q=.Kv Vkі opmj0i~B:}I2cYy 2ؗo= %AasڲK FߤޫzW:h%ENoj m]{q&cp7 ͬh/X_=c푬ri&D^h%:8E" Q^L3v.KP5xXUYg6 X_ylHI #QefzfV[m)QWx_M,f<*"QZ_6s$4D98x0֔%FtC^*@i6HB 7 #+DY4T#V2tjuQ3- #{[i,tvI;9,K'eKCE$ZU'kȴ'ȄǪD۷Sf15Kt*1"`TH/8uV;w~%Sx9?z? Ik u_ǷhRg q&h CȂ,\sN {!x$JPi&^Oh Ϡ5M>}*ڔme#m<=)PO'P7McIA켸ؤ fk:emV{9d\Sv96 he34S#>)nICױu.v?[h?q?uU!˽H0Re\mc_y;S%y j,Wrj5cC"C!13BA!t]zStɦ؆}4tũ> WЄK" n,qxg1+ˍ,wPxy]$:3tk<8Ar"9.1h,~Ft v Ԗ9*Կ uhOܚ+z;H,OK?r}FOMayVǒSEUs1{ԕ~ۈ[-X/Twm5( /Kǚe5]lJwq"o q1i|KpfպeTtʘ\$.`u!x!\EƲة'~kÓ{8i:He/g~Im8eOwS ِ+:r h wgzhŠyd%)ww1}M>Qx6`U}[W]WjvMxɸ ͘% X`q eI$֙ k:۸8tO5-QP}lyͽLfV[G*>z9eSR;ɬbヿʁo>9^KL4Mm4,ȈU+{* |e`鯒 2JLE9_Om)?{Qɐ0 d%Vui"M(e+*6۝~CU| ]Xo$DtT+IY Lu^B fb˩Vŀ˩q8v(!۴tF.pP K㙔$_8ڢ1u(S߹uN=jM$SiT~*`D@v62K1؉R Fi9G}J]bEymf&meV ª\՜&N)l*cŊ{f8on" V6j{G>Gd[ ROC5E4#"'+X~3Ci1p!Sˤ9 0' VpPzz(=2톊ÂپFd-: V{iB";>lO5Y7!g{$v`?Q7JCƩ!tX0puĩĩ RxVJ MS}g^3ajw_6%F8(dlޕB=+|b:%!?ݚ5ꋅZa?Y8YWnǣՕ$vKe8:Fw XIꂜn}#Ǧ5fdAu7V*'&>Vl'[NxmsS/Hr)6|:fһ֔ޚDaq̢x5ZbaXcB{ {SP8r?fL),|sEn$7O';uFlo; 4'_5khO> ]m:b5j]\R,,vx5`.gҡap]9W,c%2kCRn<G=soZ4:i0YƊ>Z\%5 ӁY8 ÑԪ70Kx;N- TEcoHۂחWg`H4rp@W;*=!3kλD8ǽaxAx=*bVPCXG_on '43xV)ꉇj*$_'N3b %b-xA(`{.&F~Jq:]iX:7y{cx1-c4Z׭ί@PS1N}%>?@I SM(MީN67T[Sx+9 (\܄[)0םZ\Wռ8 I`'sȄsݐKw~}\$x*KaʄvE)HqHm)KZe4![ @h^7 [yH-3*"d}yd}/sET^Z9 w^%v@pF<ݾ."3MB]&,`DbCI+>!C*y`?3d"КQuS|V|o[Hpyɰ6?KaN>L*nYU! %ŞE[-% 2{ˡm o4/.Q֠P,[8HYb(`+O X 7MMŲXΆ_d/Xh6᾵0ۂRw*cЍ#\sKrY@7p//y&z@Hog}Œ#'%%fU*xbU:)?051AըXd*)g~3ng{|덾k|)-f^cxW8 ,G(v(־iܡH~ljKEelYдW`{ ?碪f2b4# ,FAC_7?uOthCj㥰oÚfTwXq=Τ䝁% [=ZǤ `2։ܜhZ\&Bgm7sN~ z֠yX`!M{o0D**ɝ*ZUѳ0+|+<ÑWs3SJ2mYb }!MN tTGhe 4nzm ƴhl7SGK5i+FwU[N6gqxԽպ..(=I1KKH5-G)d>Ȏ6gSf;kӌkHģsݑ灨8Ert v uݝwY`SKo - mr9 +voPǼ'BX?8ʜGf7^u4^(J{=SvdpW赲C.#H꣢bO;8s/c0ē#;U*v)n+GE7&ĻWu4.̜܃xsGu2ܸzC!,ޣ(y/"yGڬ`hn,J@E=s&wC5ԮKIw4WVv)TF Tz6tbJkyJu9X䁛83t4\яuO7@DcBEbQ(//Bٞ [ @9kP/FUgSۀKꌁY}^ewoL.n5G!l!E6j(OxrRįhnK?Y5O Gl ASL,yOkޓŜ 23̳7OG'y/g^es0ž_2ó}0"Ju)|@wI(HOg,`6 >=u9X&fP^pəEm'\^RNJNի!VT=">Vxȧ_LC?a9ݘo>C% CSSI,&[SoZ-BJ-%G'?dWlD`Qʢ'#Mۻa1!i1PtU(z<ZΘ C'#)moT*&3|D}xWL6w|jY&A5˜l $t(}שӈWT ۧ mq~\RH{x_DEA{R>{a^)jJ51f >a x8!!wC}c+ bS`Bk<"釤,8x9pg S NX|/Fus g$ C/A֩Y7Xvؠv un‡C1olgJxM#Wph+vmbe?.Cǔwy09Q%^B"Pƍf)>5 \̞H~m_YVo}6 3pdi|?HMJ"ja'YۉEFccު^B'Ĭ5 $AS,ᤵɓ%F~' |#hk(0kJ'"2D[Y"Z.E[: "jE3-gYt)A=.Y>KF:|Rѓs hwj2b$ X଴rPU`IJ mn0'+yL&g*1uYrGlb؏N88#.a]9?sE#I Y=%9K{O1_rmj坌ar5*Ю( 3m:R\P@b^:WS QEfTt3y§Nc)k=* yh_&WG]{qcu&g n;s$\7oJHԘ3򇢅7HՁx3ϧMK0XdG.c=EȱF㤐Po`5`u=~᤹t_?@$H!R559${/dE ۢXQ60#fCrM|s)2sMHyT|BKdb}lcAI9TуR j!^Xj]~v[h5$=ݽC[u8-M%oܶ=mTi |L.{$ = 0 oFdZ7zK(㵪NvoK_!v~a{5hoUUa8=`j{L\2-eP4@]qBW|j$.9?6&栢炟4k\9ոcmc:hG}*$_Gg{(}*R.M?mkb/7Kp $}$,e"ZWX I#kˁwmx(-}n+oÙO U[RkO]9q`1M]vo2qPlefSLL9D?)-XhC|oFEiIb$/aO:75b_D#nAz˨kv#(BY wXO-A3O**>f[1\=ɌFMZ hȿ~($T/ݮQ> 9gm?lA;'}yv﬈)Oƪp^ $1@3I |cc?see:R/YJķN>"Bא!E5]Yt, 㑎by'7S] cKVz9Wz\7D)@NQqqůco 7Hvg.f$9CEqa i{ hE>k3m5̂Ŧ 2u\H4Z7s,W.IIGZSan *$ Aϩ&kXr(* )3·@gjP\O r]ɭPkez4CW;a_hTHJJ} u!䉊컶iǓ2~9\T>ϝQUڬR! n"C_/(sVLM=}03Sr :NZh$BCix"J7fL8Xhf}!~:Of4 Dy1JPGXfBh Ѕ*;k:Q&W=Y(t\cM\7 .]b$pn,{MdMo9t4'vB50ɜˢ]Y#6E-h﫷8m^b_f1HGTվIH|Sa@'FLxJpVMﰔeZ.uI# y /3C>Y%8p{^ P"C|(˜C66irm')FXK)0itn E.CJDRm4;#m+& Bz\)xS:YhJ> T4V(Y"lR% e~Лv3:_Pc5k5l"g8׸stET7!mӆJZ Jf[iykF鐤[Q}:o~W6 ۠gN?WE)v: ȍ*Ս˕o}%26zD*WI'>;S+l]S(GM#Pc%a)7[k;(ޢZ7ǂiHq]*$ Bf# Gy%^ܛ @a[4ax29ewO(vt{RC&qK$P0d;ASeK2dW~JYVI_\ۮ-W<#OA#T$e=?<wTUb#e죏ħQ m94LQ7ϟ+FNu/MjJgw#+kg 4]%Ҷ.:&RӜi *}*= K#6kӮN9w{m}ֺ&')XѬ2Bw˂QڐBbCvA;*j!]V0k=ӣSyW:$OfiEs WZes8djk\C#&!D!p;Z3A֩t=S_?nL "H _QwͣbՍ v T1k|K~" F,]o_X{BٟZz} {/1ˊM߻6VBs ?/oSYm}ڬߍ@X(׿ s5^! ks$k;O}c o%{BLlFV6^= FO)%\r8"ft9صq9SUm^]uC_PdÑE!U9gnCԂ mݦymn!9~=Ŭ_x܏Ig#ҾC LWrb?mSԬ`Vd^ȝ2-?e!u`cNPLm_vMVD޼J-ʩ2΂'u]Ry>3끴 D'xޠJ"q4> cs\aKK.1Q,7LSH ֽ<;ϸ>ӢWйKẺmo`k{o^٢RF&>;bigY$lRc d_ vd6LOf7&GĈ} ?? h |o,_@r9Z!֒4gvgAO>'gpo4+&q ɸۯ:T+Z|`~% bu\:1rH-#x_-9:g2cAw[jlj03]?:E]s3Z:8[Wo,GVĶP&S 5=;&1 `=I#2y-֐f<ؚHK0\SgfHD)G-=-hI][/z1h?qieIh<-s [5H\TpHK^ 4⅀z=#q: KtN<<Ð*3eEy57hC} {|' d9`橘? @t֧?T*&'n9d ZU5* Mz@007ej(\f0Qg'A{ Iş1 ycZD?%-}gmE'$承+Cd<ޝq+gQ?ʐ<-W.ѸV l0arGc~,sC/72XGPRhzvq.2oFAZ/ٛTlUW̪@M 6K2z^SY?i*D>LU`i[AV$bMf 0vhܪ2$!-Gf s%ZzG|̯-O1/YB)09Qm8Ns2z$Q{_+7ysgSxKO+]Ќh2.w{=%]70q?7I(.xmAB"Nje:fiQ[ T8h._a Z#@k@he<Er"6=m6f7}}E 0Z.`ü_S=";Ou&qm 3d(Ln7 *M3%YO~oV1zqW^swLdtΈNdmm!s:֮HXù78ƨk2!nW?"˱.BiǬfs";vXž/i?T/*yQ_K[D74 j)HV c&P1ڈApp7 ="goB0'cUZL|enr&{fn8߁O۹;pzMShJcrTyG\ѪR~GpU;4gVgX:8L+{ӋBup+?eoX X J~*X^NEQch?g\E+O}HxX#:4b[ rkU"W(;5T?c']&]cL{#e -9 };j\;:nI罤'r6A,#HaT |d-@>`uVkemWo7gp.Cń:4+{gu]EsR?V܀f `%DU !q\&xtYO/l6ত3Dv2Uґs&4Auxas%N:UWLqS!ں:Я.MK:HA1f[2UXa<8gv=//q &B#zkK)lD%X>f~0,&_3[ ƻzQ;C*NT#aqDSɋw$(k&'1tە=C{)Ww5 q=Sg$A$soV"3"*TV30ρ4sgʥ#>dωcd!6{98|OCț˳t*HR(yg?wh ĒVe Aƪcn+0xD氰(t5] G RӐLL@#6==o'_ *z)M-TRKcgg2> ,Q:xTOw8sf Ð5)1\DTMb n#(C2ГD5!Fv~Q)"ng Ν9*VZ5P»[<W xy ,a?D ^n /L1Y4DK>ﯽ&F, ~4Ǣjpꏽ`fq0(3[q4 ,[XKM+%7JDݴCm=1sUL•N,X=y2YQx`oiy4Wp0L]˼T7y 4C2uihzhp8 rijqhR=T?:*]&>{JPܸ&ae`lK;4w{9 ] e ]ʪOG:&yhʴnYAF FERկC&X)5zqL2Aڎt髲zHroᶗ/$Ժ*E?K&!3,њ9LM0\څUÖcS>/ 5)e|"1 S ۖ^?İJъ`4KAZ V٧xƬ櫷E9>tƸ<{~(]f*  !'k,S௾!aU)YSZ%(^XٳK[do}ӢATͧ"!XZh!"13|wJOߚ5N n#F # rFWVf\ӎ6>+'c7`Oל)rWa œP?L"JAMM%4CB<1d{=k9q+DZ\}YY]BBW?=Tx3PÍgIHK @fޏU1&*]&J$zS+Q5T!Z\EZȦAgLF ?*"sǘ%ͅ][;$j釧kڒSG޳˟~\9A]|y\TTr+a6z +*vHέAVds1omS휋pcM# NbۤIzR{2#7-ր<|Y:Pw>Qed㍐Ž#11FyJk~l5IX&x/ax[Wz!mrYʼޢKT}WF'^61o8BIƩYTǧK#B!&\r٭556}2Rd`\_9曎N[R wG?HArػ:Ŋuya+'>k&ܺ!A7HFТ\_c49WC9>0h٦4]X7Z%#;$&&|pGAߌ?d& YYNl 1pbDW7}@&yք=iq3iؽpp5]{WhR4{;voQ*VmfP.㗊3oXh\"~A:hҌeg(jp%bQީ00i%#WA2Z8^J%k\/ _1zXAP&Jr}ITԟ̆LF8y|=%?L2jڌK:nl8*/+ v ZB!Up C0 Z((ڬ7ѓ DHM7c$w+cc8RU)7 6yY1=Wy% izӖ +/1iUepbZ1O]{b*Q*+0edĂeuI&Y2H &`)a2l(eryQq]0v. Lvq*V8Y?gȮ]* ԂdqGCyU.K`Yu3/[Gy@Xl'w"|O0<9#"aHMt8nӤSߘ1C낝͛%'WIg qZYZ2d4.+Pj>]%u7CKEQ9݉ €s 8R/nH=;{Kʬjv-kc=>&WtJ hG©w{ b/Ǜ0 #cPN/k 5YpCj&gO/DHwy+d?DRQrEa>6\y J (ve2B?:3ꇆg]Fb`YRǾ=iIbN0 wm=U'$RoL>0RUGLCϰ{bӞ*鵃rהj[X\@rlh5;t&F[aXׅ6U!; ,R`njc(z7|ݟ VvK=fkzfϕw̜6}\_5:I$A"ڀ h xKqF @Xr &Xt}ү! .\kpռX#@J*ɭ\xRm%tPt h&?^;“kFW\^&%&dP#*ӡoҷܭXWGsvDig׮%(|[7s7Ωca>w>#_ mpD[|π񳿎)ףyUZ$pJ)D9~ڂ1,uSџL} d3 rg7wV ;8CV6PnimQc{O@]D45Z(SpEv:j¸Ri5\sE }z1Y-u{6 Og^I稄Bn*:6 V&Cep"Q;֫oD MQ1'QQ|"8QvDO'osH-iDžz\XO:I :l*=J~w;PhRU4tIWZL[v]6?g}60֞(y(yZ?ʹ#Py)>{5҃[#KKQ-9Cb8]?@#J-eQZ*єa6Gwc (Jq͸F{/Zӳ$ޥPR=n"}|͏ep M|ԏQ:Al3q>,uu.(ϣY*OgH>c㵉$ F'twNO7uH0 Z? :V8M!9$n8o̖e52E컫 B %NQAML/9~m:Ӣ&Vо2ڪaZ .[" P[*k-zۚ?';-TR _F٭n2 .#љfɓ5Q* ROP4|ɅOnJMeMe4 &x>\3dx/*;4Xd3 4q*;3$BlFƿূt댺y\P3]n"~#,P_:rTvjM@fGd~-@1fR#N&lh\X1trSdDԂ$i32{$TNi4Vaǰ7SnA,y#&raC0iH=č.i,bnݣ$L9qAA70|)1{y۠, nc6\ebBpzށ%pf:RP^цi5ih ?S189p]Avb<栰|XnSH5}T)qGtYFdͣY-&#?--`bb*ŁdUth\d3 Q+d yy0/-j:J1s O282#tw6֎`vY:ebG8uvVcY\5)d-"9@lR[k^XM~󅵩s%6W-mtWT&̌gW ފUȓ`Mlh%#VfAYơz?|$!s]!Խrm ,oO@y 3KTpPP%Yz+2،"Jۀd.g8r @fKrНB0Nc#OmoTIVf΄$w~y ց!_? wNy+GMO0+44Ո9JllԡξصD7H[L* \+ix5ZLbV ߎf$V'0W¯QNwH4W8>X>%@DF ~ó A\QkIz'8§{k]  Y+D96!sGHFY%?k1h큯 NݼOljgBny>@c.Khxb^ayFW.6{ƽc *CHTܕ~0Džۓϐh}K;w?;_!B~4;uZqx_6#V=\U(Šm|FHP 0N1}3#=&0*q@Kc:ϋhۂ1 ֒.)f:,十_;LWgMCDI=^ws cl*H+Ub|Lrg%X[ZxR[AGl(L1ɲ, hݫsl_#j2(|;YT,r{ Х1QԓJ^S:?[aKCnpJRAүF@55d se9}(Z ćJ~2RCMTSHt.͂OA=@@%99p.Y3E&ҞEkWW(Y6nV9h^N I3>KZ;G֦O6rt Ww0<* br9|8CP_;SdOV,y{ '*A6WXRMٛԩ֞q @eçA+YEa v|J ^Yðgq^úr/A'|wrq!> 95û6̮ -VIW̲\VRJP OT5 J1p&y['4Rfqz*W[{}uF]n*P'1 hz@Hs #+kW89Q#Z!?Lٵ}8&ZxCluEw>rCjiS-7?47Д_ 3"$ $嚅mjv}87m*$b%G-Nfl@x*[^ d_c! 7c[K v2"t,{"iֵڵF'GֿNj8'_t'x |k%SFHE ]Xq1NZto8܉_JuBݳ̓iΙ<^2w)d%̃/{]d<0*XM=g1l[޼6C$c a}nqʽ/8p[ G|qCf#MIodEKٰk|V)#/'7X]6?T& *B ,toT5Pc"wq'$oj-F4IAn9e_}K-[YB%BtԔQ2$6D _Z*x'Ig,i6YꦦIVw/1 m.$n-D|DHly#3HRע4r#z|@:#MK,Hfk.C;Z_7GrAw \7fqijDvyl4z2"B SgO#+MBO 1í 3⧉E㐛E;& ;SBij'&0v,Uy#I>&-$ZS+}/ %'AҫŹ%k~֣]l4^ :7<>DJŗ@քcP"d=il<_' *,AWB Ƞ75ps\VFM>7IƆLk*n% ᩛ~s1Es'\˭|F2)?gH^R0zـi^s꜇j:֞j‰7pb#(&8~,#r!m$4 }n/90q@iOS]-Av:g{@{1hsTw)wvIqucPrACM7sãM9^U|ѭG5aꋞ8yLsS:5:[wJn!HWeP}XSc-c~2Ѭ޲x6k 1z ~aN*L L;)R5J [[IqEzn#"VkLj99SWX07^BIIH%Hqf((WNOg|]b fF*/]汁F'Ӗ3C M1*F\F3U$`u:m&7yk??Lcf ])#N^@U<:R-QLؔȡʹ󵳘 5U$"iwc UXJi 1%l}R1*0N~%<7I=ܢ~44 G=w66F鑛i9gm\: m<Ӏ"T̼ !mcP'K_ NoqmE Ck3d06˯E:А#rJ=(e:~5ky R]VՋ?z/fA5Yx Zb,Mx7y6ƑmZq0a,:kfm$D|#Ն󸖠Sҡ" TcAJKrGCL)ǔ6! f;zX$yD^2:wL*EBXҷI5-OOts%}I&tv~{d ^ WN734G05YX7jX[?` R r?gF%q ?8澂`KhAz)T96=/ٗ'hcЂ:.Ίrh<ô/F*&2aLRѩY`ABh[\UaK5cՉ:ה?䤆j)a~-GWtJW՛N3_K2@ ۰*ix1S,USX,xSw$E%l^H j2fOP.CJ1n>00#(y~ pL138ȵbj\<y~;I Oٻ\n9HvYnC:Ž+% OXo1mI: #V.:;nZ++.R֙ymF_Q7}LM 0z1o7B%`tIrp!bc!$|^^뇭ޯ9@eAYEk?3OdԤe!g,ثA+z0E!?"}PT!m?7J L mK{FK&iݧme=ˌ[vqtXs=Ok mG1O#KXnE 52ɑ7LS |_:/| ls}2hX6J7^p|Yܳg0D289dchz9M葷3I;Dp 7 4>s?pQA!h:ô>ܛ[V;SmS!c:j@AR/r1_ڸm[QPgJ!ppqP:q+ܥX|{Bx&:S~= Y0(iN5rnN܊$ CyŸ?g75D v93k|佇bxqȜRbRΓ# ?nsZX}w$ B3vőj=Gn[ȗ;q*Ru}Bf U76ӨD!uŶc }tQ(a ܲofj?1wFҔ{4b9x`V{ۭmj h{u v$֔M"#Ɛ2zsY|`]XI h<0s6~.w>!B׆&cԇ:'ƼRHKu4CC = xV u-) 9!bY8Q܄hTB4p*?tcd[9vN&9n0yctOPYTpww?p296$ņdqMw ڼ зA/OY"S`EQƿy6ZQN2SEPEyPyQRAi{4:pvEHac]01Ei!*)5J-?Ee9I1r-N U2y0TC-O%5ͳڻ&aud9.AA|A3tb{y( ɶsFG'ᦧbypPD IJ, g5>b7^tV<>k mkr]2Gx@qHtՊ;-Y b qs_h, 7fobΡ2"ǬYyLxNmE}gM"wf7ޏ Z' mϒ?G6Z?>xgXϟx%2[yvUE7Bjw\ѮO k0 )Xp)1%ڻ=[MV‘ZZ)JRܟ,@YHGXv.dȶG澙(ꠔUл#X-~Vo!=RSY0tʁ*scM=HTi- w0('k3(OԦH%^uM"ҮB3]W~_`\=Գ!?!D2dӾE)dh(f!⮖A2f1 dȀM󖀈z&'IԗigKdum5m9 $i2=J37`l󰷋{DQAGTÿe1[ya:$?u.Su 9{g۰vY "Ct( -Ĭ$r_+|P\X*:YU1z)ն}]nm.+}Z@ۚK8脆Ƽ_uUo]-vR-2c '?lmDDʽ𯙽kҭ\BPiyXb .gn~HoY XX:+uHkӧΈ̽{Z' pRgN(3Z^{ҚnHv%w+P*]xA# PsH Er9}-Z( E6@̍z hTR&$hNM'%;uCȘ,x, kpCn>;Mm=8S-Ѧ:PuͭgvP%J ![Ez#AӓQ  >}(*/:z$Y̔}_]ZMύ^]<~N<XʼnnZ cS5Ah`$=2͗, #۪{N\ oWz?vb\ Wg]]Ho앺r-k.P<FѤ^IܝCNCUT:`\kծ;(ߏuI f%Yv"ӿpgH/no){=q3q6X"d՜󈿍f:gCa)uKܧ}n,kFPL6lۍ~{Of2ck_'>u_3 ,u]\8EChnZЂC0#Zvc1!eD-%10';0_F%)Ȳ*aTEZn'Ad&Gd0lթ b^000^)2P'=Gb h@(C҇U+#0 Hn( T o3} jֱB'V/ի}'beBteÅ\{NNAlhdvvi˺Sm,3SVr/lՕ;#H1Nlo<ϸǠ~ε}پKA IQ>-fG?O;ԯ%=]ޭGJe-w|Ѷa13sJ Db¨ 3-=6e-0 ?9&5d,t}[4W&Zshݑ" 8n0Z nBAŬU%Ww'Tpqג9.(aTg1ɚXٓQlljMĠ#:=y$x`gZQcɦ4|v8hJ9KhߒZuҁKct"8PJ=}A6g#uAl<=!Hq\54^/!{W13YP_o@]UhE %WWtkDwA;ڊSĞ+[B Rn8y5HEoIEDY'R՛erMkXiulKKqX95k KT(N蠝{)ς)%ȩE&V 3/# Ǩ'7!-T;e $Ͼ>vjP#*𥴽YOY!-{ʼmusDň(Xp.OI7tCᐲh{GLUĪHڃapJ`؅\}f?ox!l"4dz_+yMADdZ4H\H\@DR70y)k7Ms"X$z/Uj@-(S(Hx`/ 3L,pa|Kp߳CV9CwkQH8ӢIcЌO"avE]0,/ B- (pɞ7Q[GC'|+pk+jItL5VzW -G<# p7r!ZSG-,EEe- \P3~Jkü7J% Z>eej,mp-Nj!&U'Te++R}^!ta?_a.r+"_ܛz,X˓6e0]$7|8GHiޠS5pA^,3-Ƣו桞Wۗnֺ+s#1o ù/^yiΔz4s3/Ay_f.fMcMo ȽI@z:kguEkhm>UM ܞi leP3g\Ɛ#ʲٚZm(@ |W[Hs1Btn섛8P fmxZi$ Ql C zK&bHtpap\Xf?t[x 7W2bG*$+1` Kȸn? auEwV 2dͱ];ܒ9@XTTM8|"tNL6IjET)+]]8AhHhPN8ثqf6T=3]ڿl[EUvJ  AX'?eI #k< z5k_UjB,b "wi*Yzk26kd'1:pɱsߘ 0ĞvKG<>58l /~H7VGܺYt0KonkkEuֳ%M֓EXq[1=CQgCQ8 h0?ʘ"uc2z}4[zi g[EM<b *[wCuB.يw@u NamD 3 j݉[~4ҧJFjYí5mg^l|U2*G޿ Z_&^-roWx{SZ}GQr_PAl0y;|(_Fϯ3֎3?e%MCA+BשDPoA΃J(Fv%>;ZÔt'dNOL%g9:Uglgn9y >l"!jN/ ΀8\ǽ׮978]5|fS4,D|Hs)pC*YOIë @ \|T7E m0*'M?'lS$SwfǢiʗ\Y.{tb`h~ϹdֲKrգW; 29q*)d,xQ _se9^ӗ0yڝ#$la$JP3BK*R֬-f(`Y;v՜+nhByWZ 5pMG4z#y[$ZK96hnDC:DѢrY Me<KJxNGF!OG&NDl5x]NJB H.gvSMvx<I\~oΑimc'+3|@68V5Adt/Plk>p8$BB#G~"xTi /̖,M8@e̘cب0=AWӴz6|Yv>Tb#dqAP͡*|1cozD+|؆dM?w #SgV&ݛQr;FfE ?O4Ft>ܛ}oK8yDHnoY/LX a2>.V0{-xu-_~&*SN"ƒʋsQa(e{0U_&= H rPO.I. NG\2-"R-ԟٿ`sߤD$¾W?2*֋Oz#`t~(YS=:=Ҋd$9Y7rcR^ha߅LuQ姓, *WݶvuR%Fb7 FQ샛uc:E΂`oApV  ӟ`6 d\FTAwxtD !J^%JM=AX!K?3ib!2 ؈.ZMݨycB+a ʷݗOjC9,:oa > ,nU.3<8%r*TV`ƣ>BIqVN$: A䐟Osx۝m+ըG-89\m, E_utA[Sx Xa:#BBOVucX#sHˡFO*z,ūcZ319m%쵫Iƀ%߽âĘc4kۉ߾ ] ^lS :δ:޸b8Ե*ȓ{J=Ȓt1{r,FTUv^LvyY19BI&>%dyW9Mn0ʶrt''hj1r ,Ua^ؙi9\% -5"kuˤ 2Yۓ4#"m4Hnk8ɰbS, [5MaaSa=lojIrshc(jĆQ5Q¾#f>JuZ7PEJ@(wDqS8זR d3ZPeoZ(! r=~sWD &($}כ^|֥DŽ!&gxFAwV/?)7M)DW(* G*uHU~H]sB ǷZq/M*܎ȁ+J(tU2`z_ x QF|U(/ir:Qz3/SQb:g"R?9hKeDҟč+6C6>SBWzSMۜ1{^gC8үCz $_iߖTtYt*\ &3͟Ǚ&ٹ++ݓGΣ|Xw(Nq\f` ;hHL::t8=U7*J.eP/Zs3Iyw0e; -u ahLum`+ G׸$>?W,$m~[RCZ% JWxT^{K!|&`d6!EQ39Z9\y2vӣ!C&ycM<A*Pdn"҇ ctĴA0D) c+*ˀ74eTS$@I.Rh>88Ɔkmh> *li\V!D.Uh|bu᪃DͪuL (a1ĬL }vv+J7]L[/Lb"A7ĭ[^gbQ6 nl3|dqfH qysTG~wHa| l}-tmpAnz$M㹨'= sO"ih(ƊP{X!mr8X|aM:d] !>⸬.`7ȀIdu_ `^}y?!ɡƁ3 _PsK#; n0K/,FYl2}=FOE|oe#W==٤>,Q5@v*]?sLLqg~5D4}g"@pZ9E$-g ⷅ|2d| ӽWsi7F)ڴ[9鈱*Ad$LaUiMF55ùY/}P\r:kвwͺnqg 7D),47sm󆴲AN{Դgizcv/*|9ߏiwl3@E/MCn׭aheyWx+j|I|,I2-'#/c{&Dzv)= rLD=[эRCo%D{P;WT|M'DAz8KuNdM\x(i#m֓ErV~H2_x^2wt#:Yqո&S?ɯjqxD2Ww )Oacc,;,X.. =g궽|0Jpwjs_x׳n@?$ dcLq`&1.~v)Iq1߾} 'BQDrG]I[j\9rCTh ҂Ee`6CӖZ޷' jB%ԨM3{lDT+A>o1V1|x+'-[)B,tHvEj07 v3LzZ 3> 6St#N`34]G;s"p˱/&4}wCuj_޿`8ZpR[pOcw`ku $$1+q7D\LqmnG/isGj0'g2r7hMX9 VKkw͖6k0fEˈ00:gj^5jtW󵵮\~/J0PuW8DWdAvwߟX4ۧ ,4*3]yD2b_Rq0Fٰ7ScoHw&سMX]&=QLf.N`,g~F`,mZ<$"ZT_Y^v0W ~m꘵H̑H+C:;[8 B̍uNT|>z2XI?L.N.L)Z3e!z3hs32 }UhruA$pqZkW&>|&e9´+ܰ1m:deI#Ϳy&Eux@*l5wUxvԹ7U)*`Ԥ{л(cТWx+dhg[Uq.M)م9LđRKoOQ mt՞v.rZ |ѯ1*0MF^3ǯEvuS&:/¦hψ E"$Z~9ɕk@]q@ h(ć񣐘9oG^jcncjX~r=VO,=B?0qj5^1l} vѢ?uyE}>L;x2h%j;F.)35-}kra%>jޚ+u~ЩپiDt%~q;׭(lTHxi$E/0?4nMTiΔў,Kw(xDu Fhwgg 'q]n=qWNz8Lh}C_O暱ϱyz"% gpCrd7%Jqos'Vg,^/㿘;m'HvSً)0JeNWBd@N{Ҩd=Kzt>7-=ՖJWC,Sk/!h\e!9Qu\iKX佯Rٓ[nq \gEaՐZuƂ-lUįҠY+ӦڸX#K}m`@`cطkX0R?I"'JB~pR4H Y{tG5^ZaZ,$C>^5/SտUcPSO}[~QANN%`$ zn\rh9Z-1q}RSӔǻ; *&WД Yw,m9ЀK"VKiSnlt(ˇ=DC{Eoi X ǟrpoea83[]юye6uqh+\!')H=?drM)ߣnoӖ!X0홃2Z71Z#2'X6K zKѿQ0`OD=C> : v/JH>12{fj#2ma4;d.PmNGW&㏶Dr Ql8CkI.F)UP1A竬L%oA,lqg/mt0Lv]XzLHG舮bVe2N"&8I|BV]ߩO7*$/ES':~gx(V.L-R='?aխdJ}3&i/Jg R3?5懜ҕy ;Kd4ʿ5e !J9y:=ջ[h"㝽 iӠcUFc,~k3+CpD bOenQ`)lְ"ә ,F*]`~z80ZYpBBNXK]_@D7̽xC *ugEYMd*cI,TRarKVDE0;BI;vUqWX.тJ4Bܻ^|l*:iVjpb}-> ;A-{+pNyI7޾?b;+ۣC :)4\hQ|Jq+p`JqgwE_KL JlyKfjB '\AnW'uy/_=[p6&6_7>iͫRbNXbh90#DBo n?TBη-j!b֧ADEoc{4#fL_)% 2cU1Я9 :'_g ;ΖUFfe}>J%xo]n{Ge0AtTS%)Ids-!dܖ$]@1E *# P+)֪ !]~P кS]FTx{R Gϵkr5ujT1"|_\ܷ42Y-"4% HqX"aZK `j棩VԔ2-rr 9Sx$EhSg ZǐfaԭKէ?Zq n)c;w߰FC}e *롿Xm M }xQ$o9^Y:d}J6 --E8"MqBN zoh\gWUZ\@?E)o'ޠQZ`'Ti |嵴Eb OqaنS=v<=;{ iĘshh O*,w)p9"lFrOA9LT$ud tX۫ 7L5q_Mx~%Ǽ_ N U9>aF?^0oAǭf709"D,\RBPQo5K]~k&j1 z'w|Crs,J1)bg_Y2ޒeү¿&\Ry!5OI\Xgj=v:=^.x+\q9۸ͶB~"f)ƹ;3!֦sW31)rQ_κqZ^'-3=9r XANpl!N'A ̔Y2 E>=RTz6?@ɤ׼:1;6'RNR2/`LK6icy/l+2F hk5Wo31F"WUdp"E2AaoCMOnMho#׸ $Rn9РC< W+;7 V oT8 3e`Zڪ-,X/ZO.[2wo6zWھڴ)H4m'a&lR?ӮW)ev[deMW_uDCwlHD),z:"'I1=d(s(3@p 8hZ%RHL3_7;,->؈6I6 w%rR ihRa>*:rdG#Nl:BoOZ~bW:uĕXIs[җ/zAѽ>0%^ ,%AJc#7@*Ⲡ8zubWZ"T,V@9d2ѓɬx!9)vD;|N} nKS{G_8V7})>w< [tIMYG2xT@V:$3ȿ;CZ¥NZ ~/8)@^K<1i053!o Q**̾Xz$}ZQjd\DYz>il03# ,IS9i6:0mkMCKKb#tCY]dPVb䫞Ǩ{S:ѱQo띋Z f#/aM;IMmu'Tgqia`Qy=TC K2ÿ8>:уB2]9"q4k痡j]?\e8޸h/G?XS<96wR4ޢ6%9ęF8W͠ra c.#}o*[IF|vUI8MZt7Ȭ}%uPw /0HkUaE?nh ~-VhjtAYruϗhdr,Va#q`PN-.<\lB哦JMXnHK &YoiUiWHY^";l֗1l_`LBpW.aEKIYa?T}"g9soCYF,JKFV0S zGA٬ iXwms3# Zeskь l?9x9{a0#&0g \nH妧0M^"[5}w룴zg꟤8έ*q /-4,wbzƄ ̜Ӯ~ǼWS*ޛ]ap#-8h-TD6GYa7mxP>~d38۶xؕ9jl`RTdeėܚgtQ~7@l1by9N81o5̣r/~[X+6SD VgШ;Jt 9 LhّKj-ɮJCsjq(E `')X2N8}(Qg1ߺ-}Y]@Qj=H̜tob3Pq=-4A}&|l g!2 #엪LfҺgJr 0:];jC҅H7ϓŋ"MO|_;[f]ߢD[u+cҮ]>hIKwrFR|Rr]C > !r<+Ŕp;8ݬz9,ޔR\'S#Bu/y {gO>ry*bXؓ=7xl:04-Q~! [W :P0MF]ܦ7-grZ~XMAvp i]rk{ /ľg}{_ۚua!s&*q~ 2:T|gKpS)K3'MQ>jbt&* p#fȆ}yZ 'WӰ3ev}Euy YQk'ֶu,bD^mk tDÿ∻Rط|+'rwn)L d g"B"ӱ "@biU֟: NzϻG)7_޿8|*Eh5;X2 uiԇ2+$5f2m,mnb!ŤDg)_Yx-7 x 5ĀCc*8xX@} LN3a`Ԡ.V݇\\Z%-"!r%M%R!z{~R6e0GJ#6tܱ 7P22+*= iD ^mdc3=L&(>S|l,'/Jn5}\gm x @x>NNE)̼V>:5gY7=Mhv`%/vA,Lϩyl[ӁUFTaVĉ4㞲XiCRBw+E&i=|1L2xRᓆʏ.+v`Jw6([ s?Pߢ"Bf*qN{X\јww_A=K&<[_ZSQ!r%$:YK_%H UP*uVSYlRV {?R?ҨM":Q⿁*g:ɲmi{C*1U V:tyHk}`%z/zn6~4*ۼ|Kջ=Nb${{`a%)U%˜D^B9#>b\ȡ8M$Q7W 3{(~%4{OI6׿qK}<Ln&=p̃`ɟ"[HYMqx1i(*/+e1T{MB%0IlId/-\ 15[|LbMV >clNy EJZ xS*oQ}|P3 +v f#m;{K꘎90ۺbTE7Of+EA"D[z hۭP۔Ȅ)N8 BdeA MZڊL .w^ ~O{y1`B1u^T~#l5y_ D0oU];H D `W&E@OҢI9TK.$ҋˁdί| i8^$%tOY>˗.] :SD"L+IePjUb-7ڈ+تJaÇ_;uD%o&2D0>xi e1_*k0h'njsӷ].O:˃3'jb> U XUUɏjrmT\0v.1?WC&gf-+?s//p驢<~8O))/YKa7 w<8p(p[6;}]=v%T%vYq/H! )Ѳ)JAL3o'IB2j Q)kŮy[%,Vj-(MOQ4bPs |1J44/ߨ<=YL| 7;xAi+=-RF5DJGILe^[c9c3ڟNde5'9I7>g7CFNŪhR_1i+) g`Lɷsuk@^22@})1Xe0WI?'.ܿ# 0h kzL/k`؃췬jF8'%8)fu$ np5c^Ԑ? 4nD>8q{VrS2@k4quQU̿inyb [Caz1ah*)+ PDwڲ ("rE "<'G_fE:7$Bt_^ U.;-;wX๰h ȵ49E/P˙r3 f=/q˫ -S\ Cb7cŬ0.JlMNzAi5H[> "F#bFa n9 K}nHw6C{VM䛌F 8q|:Bݴ7\;$(_n9VC/=CBӐ}զZIFGtm*רbW.HB2Az"T4=ZI&ͮP |wB̌I 4w^Oj{8~lB}g+*mB4._Y9bS : "҃IXyֽWXb>~T`B"&@зdM,.Uc6 ~ͷW"q:˱N*%z. +/C`Bژ&:Z|c~&^\$a5µހzK&b.v~ZuiW'r' $XQD>U3ϢsD3>g[+źu Sк˸v2!n8)>[x̿wi2UHb\UwV1cY2\< !iEA8Y >2[l> &{Hq"EGKs{$B`xk!;_uߟ{ P^ҎIsƁ'o)O(dm%` Bd!htX@Aa28%8HdW)E\l˿ [JUgIrYbeSxWfaR xjPbQvl4\1RT "PbɃЁ)[z'*5ڸbj &WᷫlѪ7rd; nvDUe{Fmd`XBU_hoN_Bry$d L:҂+vǼ$pk_HcI4D!e@- Q+ <f.csN|7MY2j.|@+avD3kOP%KUܑG-]S2ųT%|PİݧlM[W87+,_.<c}#'VgPU5pf]DRB!`NK ɪbQ?*MkO&!s |ĖI!#iiI\ՈW=ȗ!o#z\;HaoVme#OD0SXg"JUw߹LVf cB}^8Y' {7dt .&9(\fe!@(tA[^IWQ @:Đ8|':R(T\v[i&Q8rĆ uj|C8 _g͛zPn-LslMOֿ-(Gk9O,t;\u1K,F7O9Ip{b[ C T1KW^ղVEOs]|q"[[кmu,Ea ;psF8y1^luq{˜Ky٢TRoZ m2qKI]Yr1]xQ~ p캊T^}O%AvY-6bWᝳC-ZaKzpx` v?P9RF&MhI\[*yV. ̥`(IZ1Xr|mM4wCz679E߄n{R;]OnZZ' dͬT2<JӅke'+.NT~J oOF&!zqq0gdte{ǫX ԵPvJ@5-H*L@{ !qqSabȽ1;[Ec#LHEbUvB&G/vm>p 85"?Z\Sҵ{UxLFQY>0A#3H9/!EzM1J('G-nK/i0 :\;ڬ+Ht瀕Eډ-0ː=W }"YwvKWsjGxi1$t<8nZ@oѷ&i3LyżUo3ǺVXdm=Jy=4;r.;2X{RD!Q[<7 lj ^%| zPZ3]0?gg_'45ι4p߶?{bZ,I^4)ѹz{sAoe㭂N)kE1# ̸߆E3Й4Ͳ+$ܬ5jI |JV~;Ije+ܺ;p|;K͓.ARc)/: ʓSp NΜ.9`!Ts93wё1N"fE?.D&ٹQ%"kܑ7L,,#n6 ƹ+q5kY4:lfb {4:_x,!>yluSW,pJ^[=L:Q+f/䭐cplAꨚ3/9$.C6yPD遈g8YHnX>aE(yU Sn`2EPli t?6RLI_IE<4j3Mj,%]?a΋Lwot7`P/vYd'x>y]yDF8k9)fQHs45P_LCΜދt400/0vU l_>#G'{8z*xNsJ}`;K]J&$pc f%0 cAo)4IIh,k}duj4c[M吅|D /&*%Wf&Z >fc[y .={v1mF"w }QLgɆ&;)鉊;bC,$FGt[:61b86M9./PAdG(j)f⼓鹢()b_Wi'p00kIWD л(S]<z_84G\07dJ7An IG}0_C)2Zjw֌]5j( kX+ig굾6 ߖʆl<BZ?. ,^ҢwT]""TFWxp'|aXlxx𨚁A(wZQ MTdF"4I$?/ Nݛ[mvZhNG VHp0ϖ"$+hXd[K ?^z:tP I{ПәБrA/푇T)AI#I3p0l1 |=ȻueHq=C4xwD,$`_*EjXi2x`kc! 'ڻ \5~*d9N?}(0]dۡsmU>9AI|[-͌s,)һ~=Q3$KCP$ ɕ85H!"e5hB|wo<~|F~ s.z)cD~70#V֒&ʺ5d(ӲY:X,. f_ wuxQJ]tAT;G+Md'cI?s*I6;J:Hv>eR4*3MҺ^!ɦ?"vKՈSҋY!7YDHk8]ko|t.Ԫ%΋,=U8XwjĘC^\T I>`OV7cA J8Y8OXqTL$0&yCa/oo0~ PjW-fG=P=L2^G {],Fp]ktu\ ;ZԪġ:nM:-e*QՂE'Ok[ C~"=kM @vi1WQ>&v/n|9#֬nR;5qkKq`T҈~49^SFȏv~4O< YrWcJ$.5v)s,hKnV~c q*2J,K-6ԯ9|$ѥ 8[3U-FuB7^r-8netT] =}S4E ? vpE1*SVvz4}-zSXF"lsh~ʋ}Ԫsr(v 7IDN;}061%z`V^#˽ҝ|(@ɯ֓X|T.H\"y<%Y j! /웱sOu#3ZV,5綢] @H#/!j%P r2kp q2s- 7NatPwVуؙmʽ&H6}#S 9p0;QUdZUSAb6j*ܮԼdd͌ m%c:>/,%?$Lv K!CRNJzRބB; 8 t9bf p\җhbs@mEEDJ3:@Xag8 n/o.;nMAAܞ=XYGGMoz0TH4R[}Fݯ; L(V?Z" B؞QHkmR6hԉmT*C?Ad1%7aMl%c,K4n1dU=AV E05|+*ڹm>ȾT{u!UY亏cWym͏$`&)·rCi&?sX~r/%T2, Q;Un胫_4|,l-uy?=QT^"NEseR:XWHd^΅vH;,DA4vY,{ょ2z ,)vZ"B5bXÈ oI^du110FlWܡUEl췭k=i429 ( SLb^< ię0lV5p&3nD6OdkmSӦ$ r `Ԯb+yZq8 ؆ Dm> OXUOl|vX1Ը -~e=b^A"  Fֱbu' ݊ ' uy.BD4GI*uiқ=DOz`2T l7 f[kQq΄:[  )pc,[fAgfۑ7A4gRsVí:~ueۖ9EW!0aQ)0ewm-9)aDBuxnN5-H_d_"rV1sS/(q<й v&.?j|b^Rc@ w)1(8opd&r!B0PxɛV g Ch>u!ALj"h'fL!`0ZjTMm;!ͨ!үpVÔ0M`o:ފt@1{M㤡 oѠIi֎3D] bMFioKQ/INCJɤzV@x:t+O&5Nw鬳_3])>5}t`i WRp( LЋh= k\R/&JP! Ӗ'Ϲi?:qя^~򛷵j (0v4kME2[} ]ޞKhMdљ4f7I HǾʆy"tHx ~8nnEy6On<?y>g R qSe62țdc7Ыh(_SoOAjETޓڼȫM,wk[GU8ӎb9V5Z:, ]3i>9q1x 3-1gK=!憗̷ &~$Uﯱ\i(TSUp%r#} ?h*#X_j%P:Nz[w 4W)= NYK&j+ZVd*ľ >+vN"^H͍Om T-ק]+A#b֩RXeK$Y(<Cna7@łMݏP3ȇ%޽][$^"v ʾQi"]5^'q ԲY(?ɿ % |k3}ӞeWwhdVE ڈKd 1zR\U YɊkJR!2UϘ4KqVE7!G 郸6K]bc J9D^nm2͜nRL2=D<{CQ}^r#}(K [aȯQ;2 7f#DY<ipM#9 sZ$F?d<)r$52rm-놵[]E·Y-l䒟˭!37}VlyUԼ اu+.pɼ,K\ f/|-ϙ4(LĩV^Y}wEEm܇1[(+TsUgL,Lhvk`#UFfF;loJa'"5p:|8s¿86Ո,^jz2jQo4 BmHJ"9ENvGc#B"] #Q3u1Oj`o[ݫ@T)F *aO8aB0x<%" %EI Oia6 qN E} NtMc|t}!re50 7ר`ٻI.\"xtGߺ_#xhdq>e@*A{A4S>w^7fDdtpnޗ#}V¦{A.!USD$Լ fQ&Bt'Ħ.^C`1=Pa[]fqkJZob"WU^G \S <"THϦL VuIj(72TwP"Md-OYAh'/nZSpC&4BSIxr㑤Pqϸ ʴ_w-RwP1ЕFE#򡿨`S9瀥 dh͊’k= 'Rq /foxA$?F"g" ,tg MH@ F-39yU ,=G'1,Zw]{޽9 ۷ :ZJu0b1*+/MnJ愻uˊBySZ;t+Bp?@b*\ 26v$> o=,|·d:A0 !>o[3dzƤ0 X^wjdPB4"?VŃ: !]qW(oH`C6=yk}tmrqpJpGw,o17Bpih?/mtS3B!'|<nCKy5*@ yU>_~E^߄@>3뉄Ft?xϹt!ۻX<xY8U5恭=riG %Hވ#dZ-\!&Q$_q( ӝ,0TpmcN/Z/Xh;#bFEoj~0Gud-QktL-~ _oJVW- `>{:0o8 =dv6WMپ[{~vPVϒ&s 1yOh֊Of:Za˪Zc# u_YnKl$0*\6\=*seBuK-Tqy&z$ʍ;ې2y .^b)f8ĝ{0=|f8Pfrvh8"S7GcTŲ\ZuQ% R;N.~x9od[-4P(VytwM%p8F,Y~VP!w1Xf2l*H<"|bޓK~ࣘ7nq:[fAR>L)YG;2$t+oozO>޿ʬǙM؜dyZ%|oSB-ݥnoиw&s`B6C(_j2 gv3#]eRȎEy?¶!ubi#\eGNX$(!rz0:yʐa\u @-~UfkEM~+g+/);tO;?HG},{ ϟB##+b;QL"'`> ȏvjT9Wܻ6kk9 LaUF#],Doeowشfj,=o*A:op.!iwv25|؀8沓}!t99-M~v Mb$g&)z(FMvml,@4f$y 2sgo'(**jHL@Y'gD;թU6b lfB %\4`LQHo $%gP 4(Fj)AQA%^O"Que45LO[CK6LG=m|Bݚ/'x,б]ז]D]B+];4/rƪYg*nZ%އdNueT a.S3$*6D'\Ed+њL&L8\<8u)Aڸ^#?+Nd"YԽ\2:/ˏD䒬E6[.ڒJ:HV1AXG>U7DQ]H- +A$ SGOA;kD`{ _uf!hü^g+r`[w[{S'ylubVmi`:ֺhg-FƱfy r @F{f e52q&a#t՘*I{:i uTԄI)J4:44p.jbv;@nO!0lMr=;C&̬%pt8mų$i~|dQv*kKٌ&s6+{fLZ2ǎzsP-MD% Vr'0ţ0:+kgsz @w|=T%QT3lKY=a탊]3w;] W-XSO}N۾obWp$p~;ZLCzi Cnr , Rmf1t9#@ݼk%hfKolW!e3 1-㳭]DӅshg) |kDLem 2+Rb>L@(וּru%CvwuI` [Y5~::;TRY8; RDVW iҍR-\9cƑ!P[rW?QY)2ڝ!"ügKh(KDxX؀Ray`zCq 񺧛U[LOEz >PEoI9F2~հ3Rn"~Z*( YkZgPQG/#ňtO cQ*lj!3뛜Ff8n Í]?K .Ľ_O ]So%@u)Hַ!mQ+{V~_aƢ["1@&^>x CM58ja7[pUZ6V*7anҌZ[RDP2lPF9 M1zG\b|ӯTrFH; wwڈ.{+ym-ȧ?p婢"5f>^[A95-:naJV78*-mOv#ƺtTf+>!#?wWid:r7WQHwP^GdƠixz\_eI17u'cЗYO#2WWtoQf J?bnO&^?U "Xg)aܺUdT<25$# Kmg+WRQ5Z5KU'O]Hhx !+jqX7KfE!ZA~:Ŝ3~g0IE../7N#=#Cv7s$v^Qڗw:+k;Q{yRqZP$"zSGoOaX\ js^vN޿@ ۓLmp *0A55e.b oKO{9AmZd@%C]"(=y)M HіI=?+ga1!hȍU)+ k-o"f_Q4~9~757|a UC:dn0⦂Z$}Њ gdu':}{7O 6$>ӿJ~k"cW=D3]qœv;hMF?*ФBHMȂ0AYTdczWQLO"z}.[[ˎfŻ8Bh0j],A+< 2Vx 8?f24R$s۟֫hr7&);2p+bCL~ ~ /,t D:GL]ê7مa]=zv^#B A . T}tQ+:++hykYq)7&@\G|5xvy0tE}%pg@0X% ad%;H׃s ǿX^|%Sa>?qn1!$fŜdr6[SybHCGF@ _;H:uc-f^~HOxji|^F^ke\|"m K $$.DTsA "6:? $'$oC-K@"5ȍ;+(tCl: gZS`r?:ԇ)u7(Md"L^aJLa<PW$988~c(r2NP#(t*7/l'D_ n2t UzRq#C+qM=u@`6'eU{g 6R̻y%rnR%=yviT(Kk@ `~YRcStjy6|i0*;_ *PZ9ә?^ʗ\r{|9'BUz82WahgC{WܘUUq{^S"֍18:L&'ED/0%@lp+x 6[}D23'4h 1Qs|fb1?Rգ"jZ! [&4 uN#ϱћaEM0 "^W*S!ׄkRmlC<vc!EYAff^-N(Gyҏ&59=H={؇h:O0(GW q-2BVn97cuI;i]cSLh~a26U7G_PXr|qT?n15KA~HE0@\Ska'.@Ji]Y=5`ȠШEہYꝚ4c|JX*뱣-JP 6L4կpo{:IsFd vE8= p*YB@ҋ؇A +$kq Jh]׷^ (^hdfFKQo -xq lmĴ!!`[4*˻n)_*k;,kSb]fٯ])M47Ra4ߒi zO"!'HbȤA4su_ģPaX;qmcECfhkJt:znM\kj敛ɔDRˡ-zc\weJ=JR矷Ś+po$R$+ ѾK2^f>-]aTK>-$z#W'sܹ`.>~VWNLמljަ 7$*s"8@şM+ .s܊a)[kR~ZSDpyMF*rqpq:v7oAеX q9dFpRxs HFg )r9ȷ#6i4މ6_5]?kBσO6|(Q" {@>y&p;oN ps4p B5OD=`eWSI&E9Mxu^8 Ж*ӭbgRx0+މK経^76jUi/I}UGUjz55P;5O.w5{LbݭܖGMJT5:D ))r"=p|&Yz(`8vלȭi`+t]Q )Ϣ5E:7.|*rV X1ny [ÿ5Dj-V Dɺ &X08`,0O'CR7_.W ک)2u9Ir>Jㅫ֚h/G X@gړٓ0HI ߙ7kI-#`rx) 7\)z%iʨeN!OS! c@ԍ g~ńk^__71IF%}ԍq,{ȤޤX{l΀C(U}9 Ȓ=f _0FbDcbcհzBxIY=WG(ӴN9 S=0zC_zgw~*tʛp\֥˺aVJrYKl(\(&0G#V.Уb;, (' Nδa:d|Y`M؜K繒@K [߼+WW_qR5*ڬ{ 6:$^ю9"g?3DZ'||?BBo4"̝l}VE7h5êvz@g<olt8,sY{P>,_#?O7ϧ.s[BP]y)Zhmʷ0ѱrZK:6(UO, iPAѲK-b(ݲ/_ {k)կh-G404^%#qNbZG,6BQ(JHׁH͑gO%Xwsop^ڗ\,`S";{ ~rk g>.L ћ;' ߨxy4ZZ<9!r+]ΜXjǽ/qWtCTy7&ūk`P'52@R /sɠAY F23mor"uf_Kk`?@P}lwĀ]M(-鹳df xr<5wsR2薀Q9X8]#OQ;`ٴ,dp?yr ## Paxhʓ_> c0KVawpK"ոAȧ>^kfT@ԸY)I0'py5/5c^q~OE7|c^Dսv+^N^RH+w|h,cv& BKZPFER3m;-i/] ͼK)*]w3jK od *k *O"H F UnEAS9awtmI{-~%[:N]}ew-- |d;RjY8^ BZZB(_%!cFjHVwyoC~FD_k"Hp2&^c3}7pÌ+Й`Ϋt&nyyn|Fʫg:Wu "qOkY49D)ΙykM5aVjd-NA.Y%fF݃Z?XOß0c91!); Y} CcL] C;ϒnK8 itwhEaG Ȍ3u {46pˑt/ sTQ)^p+y V@b1J;UyJf}†!&u1O?W= b.KH$ ީLL` 7A(%OHw(.oyL}RAEB69,_?s_09uxc Z#2DqO!; h:F^B-njᏯWڡűhqQ^qRnO{AVg%ӷfgp?F+,ܖ>Ra~gHUU>dh<ʌ8[fYg~jK?}48<2ʒ`YKRVtj`< gbxNgf2y%bgn,iß_9,gN&1h"#@_zyH=Y12K>I &f6o/r?d7E+Cmo0-+KC"]pn , uo!p#΋gپEM(`<JzLɋoX+xW^k^4Z+^]6(-D(Jega-P)>$;|yԟ|7 <=}kjd9%GKWufd6ȩԧ8# p~PRdMS>}-\i n#$X*^ M&Q)AjjFx42 2"52qj6>'z:S I!"\KcVĦzW2ܹc|¤;\WosS zs@"m_6SXN".ݧĩ Fq7 LuaȻhr$Z# ɴ.x1vM\Z‚iًWR.xJRI_1q3vRʝ,2o87 G͠VߡGӧj:$ LLM̳&%K%;Jbc<4+~95x t;P#((;Ew# T6hrdbA 1Xc& PYكt XA^U|US5QqSq).G]_ҧ~e2h%;3atOZtq"#'gYq--QY Z&EX"(\%K{$qͽB;ueu}KD(P9z4J7]rBd{c -񨘶zL#ݼD[#^L pg)?h,GF{ej} VTk}-D:~3~͋!jmpUV4xJ,TF $ Sh AWMv+T5$Iiu+Gϧ%rg7ΠK';7lY兤4IYqV۪_ 8+LhJ'V69-kn躔a4Z[&cF)U_5 >*"`0\[H|t{C8y u7"9Aă3Uٸ]H4Opk2\J\5d#[_ + 88Pj&4my %DQA CE(=8Z2c%I1r}b69:897eb5^LIe< o0}Qi7}{73b~V)u|HQV  nҡ_\6R|lՂOyx"q!5L:2 (!RKkv殹-`'n ~17PZZBaMn1ZD{FgvUTPXȿm&D9*b"d2 AA4cVr&KZRE|ߦ^$]1A|?%(2VaN,QYa7swq|07PcrhVïp"NA੨C v BSlb69E`LUY=CP "#mȀCK5J9eWT2VV񡫭b&=gy[I(t$${T1-,yg;wCcqx#IR!:2"gZL,$vlF d!a1.<)X&"}VYqC:*Yv@3>Y&\fSWmMM Y ?P)ifhS:A>T#i=BhwѡfZm.=Tr}brovD,ى@[ gA4"mZMfEh?+ ΍5FKֿu__ܩ+uOǡ날 19CT:ǿnp.GHso1'.++Yt1|.~+|hw6]iwxZty$WNdRAMK&&*,VbI M8coY 3VdG/54\ovĻGQ(oY/Ƭebٶ@R";uRyokcKsj\d~].Mj9!z6q{GէEC}3hϔ17]6$1lYsU4y~JF\Nd팜k@&-4ooHRbZ3{LġV5h*AqƴpdQbbhk)z$k}BN kJ6<=FV8/ +K;H hfBusWa$,#:w(Oѭb75WLFق"AC;*PΏB O;Y<{ሄʇ%'s/ng^/d=d!UP˯Mk w~ u]]-~ ?:=H p5|JJYMd=qաcEn3.dqOqWx! )ivI ZŲIBS%1ȜB4of.>IQv~I~~|췉J2Ks Ƙ򓱺?`V͇~b_ăbR{eŦH9>|FzFV^("2?m1 x93(JR:OC~ހ<=hk ڗb#6ias\5O'nwɜpq r7˯m&* e3-|̅{p()FS o.dWavm$p!Qplp9jyj5]u;pw5 ?)D"o9e(X=NME. 8gEe7@#d"N=z^ 39 -N> lq5vYLw1>/ k:2EH+׋|ρݐ2pk'/n Yˏ;@0)t"v1w8n~ ;"?/0KUy^G GvT3([Jјs/Kj`^9BR_7ae2P[I\DHɀ-E֯%xC6OB1\J jnicB=7+1OFO?Ҧ--G}j+8E^#Y}^9[6s ZecU1P]ws[|WDZk+ 11\q OHﱯH5gN Ӱ[vQ^?x s.U"ezܲ܃ݲH];@VnF{xsųR΁4 a׵XĆک47dbcP4 XTT *ߪJڸ*]XhDMBpk=(jނ .1_]$i^3ěmNyƈVu%hLQ7d)O0%2i,3{9g,^\zs^-4x4(+PT/ع_kpl, A4f]8-FӁ]b|1.=rG>!8S$y;۽%K(?B|:zuw2V1%Ǣ:Pj||CfhS />1C%)M̼7ndK:9 <\̸ ?<##:Qüځ2ө#,u`4}⒱ާ0V+|`Krw۳d GS{LB{GOX''2lXI۸&M;Y{u4B]2u=NB f:'_*U="ɨ{O:/F T9LD9 Wp} Z 'NK!M JXu0 -W.3BPir,_l\J"nHF6(2vk@3N?R@ZH3KλmYYbZFi{bz$LdOI*]*\6h> 竄1 DHʣtK˙r#'Os\k ?8\>z(/ts{ uy{J,l>D\l/$Me53qr}sGzzu~XG]Ru9J&*\[$\;2_* (m?vnYŮvu'^XTP\~z` ,z+]iP#eP"^ 1OuL|@k@Pt%G pPV! )u- `{}gofJbfFCcMaID"}8/ ͼ聮saUV6y>{ND8_FDƾ4ۊ""7ZDλ m\ƘjlF8Iõ<c,2DjGI󮠭?'FCĎlZA*:PrOWC"zŗ굓ugR.cmWpVju1L[qa7~ڔTtx*+#՟ Y"?3gÞY7m8t(iPNcYszW_9FHF7~ˌ('B]<=?Nk(qZIg3\Cbc!g9o@mE{ndpn=¼P$R{Fܼ(Gl(IG"3c^՛tF 5E\b|-,Pci^+l_)EBրڂ_U3j>T?!>xUъXO}20覃\B?D:!8#Vմ^e(_Ou4;v-6?ҙ4 gwKjA܊UV7m#\CEaFi32g- 9yae;+'İc8b/cIQ.N CA{<(qZ;RBv H}ݙ[]BVwK{z?"cwzYKUoMs? e7Www<֓/v \P˰JHg3).(Pxb2D>1}.3D CȝxY'&X6#r.ߑ$O Ċe3>Gњ<] @e@Zv l@yaPbdɋ-o}w61#ȳ>fOw6S7QѼTv+`oaL|]. FE" Co^B跑*,P^J;/'Js(Bs+Pʭ#_$S%kb~jèvy^ԣarB)&I;~ ~q<~x*.bّzN~M V7н璚a^a9_Η, "n`?ZQ PhsF` YZl[@c/`b=T퟽Ւb lcv~&@N> ˨`0 l5nj =1ͯx/4ࡸJQ<ә7a9k/ pՑpu{YWy UTH;D" z`쇋CR0@iU}_sDْGU7FjQ9=OmB ęJ61H}AǂÁ-F_ĴmU_92" x]C.TU7ϲ Ma@|vnw/^0?Zвt ӀčjWOqX!ʻѱNA㕴~%c}8'qa7C'3n}/依jYȥK͙pO5+Ӏ~)5rγD.ŠG2$μh YL}1(VH^FAPEp`Q`M4җnD}{ػos"kM/kPrD ަ,k-&ΕyGB$ڋK+ &MxnUTq 5f;ovH[zppHBLmeЀxbk뮆ة'wC6Hi^z. 9~}ˋ.tz1^72FVFv-:I:F=d/) Db F6-?#uKФ_3 W{p(.8b6 gIx mj"rÙ%!`v}7LP5 A-=|&)C$n^ƻ1 K=t7Hxr9|Q_=X(6GD>j}X)!Нp,\w|G<4l]CA|M.۱tC=郍U<I0wؗs6CN2t=8бj>.NNI*co~~,%rt_:q"Xvt*52l|TM ;}'dX&؋ IPlBr{՜:$v< z%Y)dTó>7PfCZ1 cR얷<ؐo XT"y1玟YUF?9_ c&/Ҳ%m Q[}ؐ!څCp֖kKcEK[\'ϟ*W;YRhMX$C }7)?w~<~'*h0p0&7~LȆmVx>A"G>F;|B8 3 ]ՉJ5Yy}.-sȧ."KTO`u֚6l&!cdnCzpa$cB;d%Ӹ]+6Q#OIK(.ǀ- 8.1YD[2&ODutQ: ,Z%״i{JUSM!Xo"y SN(\K t;ר^>gjؼտJEoZ*-w5Yp~Ƀ6 <ÿZJ:/36g%.+:kȝIؤB9!~Jz'ۦ㳶+_FYM [{&$mY -C$?A`7UY[ILqLz<z cpwziJ7JBCK@ȕH^\Wv)8 Z A%3_yԱB֭=(zD>ie.!56M3YEj$#깚br[n4)g?_,t]'IsOVgu?\.I[(4iKAXyhPrh%}I1a|.̎Jo(|bS*M]SuvySE jtƂEvsM ]OI6HEE˛6-S/_O6ŝ@~ D0B]nۧdhsLrv9J O|!)h8=hBtArrY%}y?D ¤Tt/W {,!( ,5LaAV@o̺F- I\z ϢcPoz:BvqԄd nȇ@F Lfصy \2%.K+7 `mS0e^vZ:_;*^ MOpu&;t‹htU7ESΠtUw~[Z"ڽ~=E꣱AX~Xq4O)B[aQ>5!ZW?Q&wRƨz!)9Ғy6 #gewPlwH=t J~$zLVnrC ia!s6?.AcR92RLj+ᶁ)%@QsJo ]9"o!Ce'r2:&xĥV'#LNfı흫1YczHϻL$ UkI.2 3Dd3C+-ZUIR%+ҫ\5bFߘiYi$s,#ZE b'/#×L .$#}ԙ/t f܈5j΢6*GKV,12=D"覣Ŋ]B 5OӎU!* 4nHoĔǺS.( 7g R3`F8|(U8'K|/32+*t\"QKQ~z+AQ_zaIфО A ?c_zZb7jCX^YI'PA X4|1]tKEHDxFA5`R:)wVѤpn ݾ@?(ٲY'>v$Cnf)cvsϕ$0Ӹ=πxO@pʝTc/ •=ZS~հߍ3(8E`v2Bҍ&/ZOXļ]shɦ1JhW"ϵ=ؗi-QwUmO  i= >t?IE}nLz")] ΋: sd1`2V)m*~#xoBKGǹ uy.4%ﰷsPW[ $'Z>@S6KrZMNd;ѡ=BI ~jS^0?+nŋD(r޿56{! fa*heBA龭rW|uNZ/O>$(ظoU 1HO{G7ѭ [ĕs5/ߐ!rS)`Ҡ5ǩw -МsFhh ;\ֺ/:grL?@$Y@KEa]o!X A4zZҁCǨ$Oke˖2rS5bcD{NNO-*wt<=eZn4HJh>4vUfzf&HS~g ӃtsӛhJXHkBqi}=#k`އ) PZ:=G^UnH`:č]D f`Hg]A=taZfн횪Ļa-Fh5RX8[9hte sk"Z@Ζ1+ 0~X-q GK8C@ŨHS%BCrs= vs& &\`1iLџ^Eg`;rNØK,Q-}ӐkXJV8{> 4!`kaHvA>jdrB4ii&"8(Xb2ud57 G݋e?/C>U1UҧQ_$6;Pd !GB@Z/S =2 SN^o+J6_$*]niT ވ>‡aȥ1jʙ΀Y* bc1_s]|m po΢oH ?RE|q)2$}٬لu"@q $*6P7'FXO#C#$#QI1FAFeB5DRn5xM]Iqn2 -{TB_sfh{'1 euB|^S][գJ\?|ZuoE8ADqv\Z>Q%`g;`؆ +TgrgCmJ9'KT0> 1{duP/]16r"me=QyZv֠'&$l]>C`a"Q[g+ 7̯d. H 7qk~8Z}!*f$?'A9S~E˸Q-纠W!:%L.4YhNqpOǮ R: %œgs{VQ"Ъ¸wuH$czpֿ4W:UX.N#lpYG L]=9y9zAtbԢC168Y?M,+2?^=n1X"=!h}G: q3B [)9Q-JĽCwT{ uS 0 vx[W+C.i$+Q_,3Vv=Ǖ;x'8ɏ'l\@]pʰD粫_/AM>a8>Y "v LA$kd;0yM .1c{Hh;Ň@_]jGieQ)v[Nb5{bx" EZQ=¯1ﰦz##)ظ5xm3\&JӝbYo2/jC. K7Zi~0BoҲ_~{V_~icW~D.;^#mѓ2bx\EV7Q `K1燡'  ,p}4I&wa[Yn}(&H>-ٟf)^$Ēu5Ǻ[\or 4CS4 GP.-:Sp^Xugvu肍|->%W*cj0yrIwZ.k<܁pEb?|!oЇ?4Q[4:'188և.zhv#BhӇӫSE/ 7P8O[L~Pe{$Ees#iZ.?5Z5Z^>9iȶA u e4| R%a+|,%S{FGߧ/s$T-Ui_D H/w]< fЖGP&9l_*ʀec>[,e>[rE.ӫ?΁O><$|@>0AĻL7CuJ=g\k{H{>U K|3WF0Ӂ`g*^[h>depAw|ͼx݆ o7\{n XX>9L.4]$wAK6.:C-ZCc|t$YzC}B\5)1F*́Iu"tUqxwB$r^fDsK 9C@M_ UY~) S-M+[u0 @[/ъ 뗱ץO1Q"X8-CEP/G.ŕ/ӂyTDp>pu~!}bQ!\T2>$U"yZDR^,䱶S ?M[5Ro'h$ǁK;{uVO/9%ӮMeש+R0 ţ.0 h`ˊǔ3 FcϸQu^@-طTAHtYg+*y2y`A+F;VCtkm.imM[GŒHavmױ*|x|>hT$fAZ l4 G$[Iҟ<629:S7wVIŷԪP mLMn˵}Mt/JW:ƴA!j%$~hŚW]TsY`Ck/]&U Tu¢w4߸l;91r0C"G)}OvFB-ҳ%J3R_ cM9䳲.] ֬N@HFT^@Ărt#w4 ѐ=uPPZS~B*E_lґ"ƗCXďI+Gb.>f3Y\R11%QYH7F?}A^@ZHuƩf^2; [xp>Ob {`tx+;x.Pqf;,PJ'W\H 6τCq?V!8!4n~ 'zVr# ی1Roݰ ;S+3˶hI@&+^3P69ũ:ȟ 6moL76vu * ~N_?P0ɫPJ"?[*o\@|H6;xv.ʧvR@7&n Ah* +h6`PYtTEPM.3}~|텯_Q*(]q.V2U󝣍*z- XB`(IˈE޳+G7}} -70? ,* eCX&M0+/%HnWukc_Bl)Ylk9=1lZKGd!\9>(gKxF-{ =8>DAgl.%X*0#Aarc #T Jb`˳WPG B"T!? 9ɱ dkl4@ JOj~}eBzt|,Ze3IQQ7Sx"@&nHc"P,U';0W Z/ rߨ `P>s~8i>xXh;r_`,K ^JHK1ƽk1tDWeQ)B$m~-Mh\snګ0Z/S~Y,E|d 2 C#dqdfh90E|:A)@:hЉVC*944>$&Dm,[D`6/DE̔h?o[_ESz4r{Rnrz ૒iLxךZ<^Y PqnqS`(2|J6-Aa孴Ý3daʫ,ju88^#HPu0K$p|^-B0;YW }2_ª+2+[9`ЙB#ZeϭhngXhUpPn]hV߀I5cq!JlFwy=G;vTzJ$eDT0r 0XA=RT*X 4ĕ09𹔶/{W4'jDZ#;;=Y$NXƷL( ^]ĢRQ:0 b5d;*O!3o];Ph<w]vvxf ˍp~2IEYi!]CǦg /sOb6>TD pj e9&zy#A6oW4߅(זbF9 gtn_E1rE>??urkqFȠvEkg>W7KynO:"ꑤ%azN"84%z0 &.`Aa[4_`W#|&.U, Pnv.TŒ23@X&>*5#ܠ5 N؉藽sBdVZ\ .uI_߿(kOLNCpe ,  A_/x/-2C703Zd#B˗Y5yPMG.ls0NYV6}kF\ vr?!;lgټOl3s V%VJA0K&1B6|Jsݸ`4*腃ïIk'][]=Ju*RhB ;}YNd˸?F0yc2;e}ǣINd8t>yc9` 7GuLSX.M0EGcHƇ?_W }Pឺijmכ%?Teo)&y< gͩ?g^5ᣆk@Rthu-{%~~ps/hw4C"Ĩ=8Xr<3fS~%1?+{+c}$P0'T;:0$;ԅв>kvv̬)B<Li4E=|z#R|65P _WN`(2 _40{yΥaOpz 0;Ae[3AsɓPU\L (5y6Q$ ϵ+ഩ@}!zڣ3~r)[UR޹5 0r[a6tHP/j1CtF1]'k:ahTZ,2BA1 -{b+ mmً3LWۢ迭O*b~X;?ApW%vAS d+Ώ8g%Ò?pX`95GGų*ط8_(WyI"GDaSEz-^2Zٿ9XyJ)id5 sBϒ2czqgdo"U]NY{Do 4K+~AR~g [_B|=[횔d*qV7 0)rY%:M(2Ӵ;pdzghziyؼ>ie#E^ถ>efo*:;k9 ,絴y=#Ko=(ewY%uo3m@ܿ}pUH-3mQvwušQvI@}icр.`=l Hr܂=CeP(w 0uLYʼnj@: O0Ct`8[(^]/1\V=UQyjg'f}/ynJ(Q-PWVyHT|0Z%eD9iwm5yZ1F0~@kG楬mէr-Zj5KU0 C])+`[[œ4-UݏM0[:Q\rtL1A`&`ǃv5Nԃv=z^l8KZF,c.RQY68'*eLY]. /7ߴWgnϏ9Q9B^goӗ81_ap`eEE;痩6h ]B޳>LH|O,&5Exx_NnX ٠_&*J3MWx|[uh,G"~v˳DC2 \9/D! K-P%+8xx4llu?5Ԇ!,Ğx#hU }0}~-)Mȩв:(C>T&OբSbɪi)oa hc%i9&K3F6qwˆSL^rӤX<[x;Dw q)Sf<|zBJ ֺt뢊uHۦO T. rnDSlRwp|х&ɣFtH7CB>):g.$vfƈV /9Hi.&W5go*M Ѩԛv,l;ԦbZՈM*GP FRwX $xLFtmxł\j.zXRHR@)Įo@ \AlfVک[?@rc 5 *3IP2ṷ*qԃ e;\:ksL1i5J)V﨣CrȢ{gP lxQ+=c- g\V@yΤ:,)z#׾H7`Fv}AZAgp]TGy1eW0E}ps -贖 u+5ffU"$ǔu:j9sG9Jx$3%D!`f=xq,mhWeQ!Z(K*@W+˥Mlq |0IK ho-cp3j#t1;[Ptǹ؅widFC(mrϊn6x~>ͪuBcYAig;@j{ 4mM!yNma`%j߈pkB.6+d5kH$wËTV1=r~f{,۩Y(P#uo;ZdN|XE{^/Ǡ6XpGWl!h p-oM8Cna]M1^v0rf=Gh| I"u!Vc%KCN|]<ʟ0^H3I9#nyt+6]NdBf4"EDP0 鏞G'YOv7re;@uo8c6P3QI/+@ fΏ@mNS!`D1/%Hf3g*!O'ʮuϴCJ1~5o̡o;V3! }=#/Ue9IV/Lv%&#(w]kjJX"7_eغ -.T d]\nm|Am]"njڭda:_ U3i3)εйQ 0HE V8fqLdH8(JOlJܵy{}Od$+z }ANd:W3d*Ӱ1 f"ߑ|)7> \I"[|>Gv]OM#Bk;R$ _]~  >Wm!}D@RC=uBASUE8i?gP`e~`ʝ[z]F-fMP$SY!_^F馭1X;^tmL[5RO1"/. bPCJ0[,D"򦾿M=F[~,@xn#i hHTgcey(o~ZnQUp% s(F Jt]tqJog! +z^O_wLV5="%ƸԳj<el:Of,wͲ?꤬z/m`UpEY2["gu~GI?ilŇo[s-B lj,ݳj|zCף6i!4)t@uܯcGd._!r5>MAdO" zA|Ɋj2m .a?ex5Bp`VX>P~f,>nZ&.e53%m^.D mЮ^+27ŏSpy@F}~Nܯ7$h;6A'EƔÜ.}b &6FeT-[dF,&a7}vPʡGݐĀs Lmx@)QA=Y&_aH3f#4cvؾU$u>9(.u]Ivpt-cK391mX衦OohzS>|p(oҡZg_$5 um6M0Xq7ۀ/Ԑ돾,OEbzn6 9@XƋ7=J??iU{i<=M:P}$|RK\Mo@ 8=, YEJS'qJ:n-) ׺Ejy 2wiUn^ UleQ70peA#rр+ܢcK00|F9'W$nj!G/Y4ojA~&ZNW&æi]G7}wjCqX&M %ɚQ <lQnUhė6rO/L~&_ep4ž> VK'R-*ttNȳ(uBc*p,^Һ6E)ڹ, :F)ńUj8y)E ldjc O$ CqNBgۣ]'^Wdo/0S9q* 6 g"&=~: zD-Y mm8BF #{rYr\ HgѡkZ%xuWZ.ְjUjէJf:QNH؁f 1zr=` w9t[VFӏ`hIJ{vPa+谨Bu͌;|O,a mC)Уp&sDG8 !1J%eE$_5ހFtWw5BYŜpfnp$D?D;~] nLK 2]n@f[N#pgyOڎ4Nmo7}x^o׳zD"[wx,}OdESyIlp}TlI}<epa*Qxweشؓ_&y;yEF rJ jmjgJLZOPdNM2S~m?_Q}v:Vg= :>j<0K9Nwpǖ^.-.4.| JF_jd7<.t8<!S! .;R>#LŢF ?wI8ʃ90OӔ^M~sf ]6 Wg- v0 4tC(VVcɨ2-r#Ѩd;WwνBT }s|"SI6Afr4]|Ulxbզ)T셮'\'/B,7/{NcApN^G % 4r` 6ݴ(HMN×ZB-LWnsJ޷>Q;bA\ȫ{:tԶWc?"` B8wW2*pK%Z9C.vR˒hȝHW:,p(lskdQ-߈+SP2-†!9hۂGlRjAvH0Ty%t+ ЌP.!D\2ݣzZf*r(i<'q *=Ėܩ)scѲz> kWn5+2oQ޲N!+ HAs7WyL \Zt\YK^Fr!n]ť ^ȧ K}|=z&:٘iidJ=k ޚŽ`Lo|돽x`oLjI哹MWj.NKI0yˁ4Pb2˼cORu Ȥ>|e\*kTa-7+&^fNpbTHK)mm4[@mTBƱ!#Ms5Y )4oZfsP|F ELug?;ZoB5Da@:: 46/>1sl)އ9$d''QC'>?5 cJZ:7 i`$a@_yΧh-txTZx4Ytw6C<2Ũt)O(hӻDSedezr9@K;65xxE8L0H[]ϽƾtiƻU^- s weq[U,Pa\>vYiQ $ϳmle#aG0#-%co:Kz;-.S>Whp ]ʯym1afBg~X<*)M᣻Cm9&5022qp4|&*ܥ9B~=|Hy?Xl'ĩiF9[C[3v#*7IOO̹[דoS̴JInp1 6rdb"6v'@P (uJխԥ'vFluH$\ "Yɲ/t6CO:Klџ/",Y nDp`:,+uz DrΨ3]ٕ8ι<_W݊`IyXfdo*""+\$-1Ω e=\@$; hjqCyw$gEoGѢ{W-=Q1beI_F؊G?"cXA7A2 ':&i uDp+="v U w SA-GȀPiÙ : 2)t޵aTBTIGR73*>u'Q'1pɼ0 B@> w4.Txa~ M|a*̔Кk -`VU]Y5 D^m,mg1}=㪈H8NXz-%ݏ߶rAVݙ9 +'@0]mRPܺo-Nh)nsk!0GmZyaMm@Qyzl ƋQAGTWem&x J}}@g. +7nY} Ku>MC75\^
    ynOFmpR Uy^kzm{^c{m~6]vgj*?/ yɌ{M^C? QW @r"c(ZxXdb55f Se5qoU"1Pbpin2 #S}pL5ט[ɜz5j!= V(M_ncyӄ2H.LcTlB%6HA E[xONtk5>z%-R%EE7H˧82|F+,=0eSn3qĖ寱:/-rW8#c`r;&2ƩM~g\uTl`mkOګ䡞-} 9XJEk#qp ӈy;*﨤W+uuI,\`ĸX$3$,F}"Eߗ= ]3@`HN 8羽t$onLNp‡r}-~>=%(B46zd& (p8'J6}܃r8Ԏf0"cPC1U_ߦЃ+vPᐐ7h,CfT˳4j^ܾZ WPfu 7e ='uA=)Z$LsVHO2XF顠7(#mѡ{uw(JƗ3-1M06D:u}NB'jJo_U]vS|݂-cm\LɖkVr~hDyIU~+Sa$$+ @/)6K@!PtRc;A{\cX m ?XWw\:{ ?~IU-b:%)?{,.ؠFbPjAmko,}#KGҼ˧SAl|)wLHhaJ"toHC̆`C\lh uȠ |󌯄sIZ_dO8,U͉ W)6N{/ݶN8wك+U\O-t8qŀi+WHBEOiCLK0:uRta277 6QɄ KciCR! 3(vr~at3A( ֤mPMCc-:%b\ + pu/]yDEbZ4y-/Fi3s! Pӓw92=$:5ϓ9,&FZ8{0D½&e>`{/(@"^\]Dl*XMQl!AݘP_tBwt _Ŷ>řj"lZM'aEX7+?$zczJcK]]7SQ<Y^ ̨b2J6O4VyܑIff_'4>?^+BBl5Xc4ïy Q-[KPueon2):7)H+Cq m3渜Y&RޞA0=^vh}Zr/rޔY$_i߹jcaM<\(̋TMڐěgF8ps.^Jo,ȱgX/6F?@Tʊ=e?׭* pDF(Hxm>?p{-T7 RƜf  s)AM>=XݸW᝽8qA o`@1ސ0Ei9Z"v9x+ V8 wBe⒣M~4dv}&:zއPL!v;{5O1MJ[7i;O%Gѿ*߉Fۭǘ%21hԯ8Nb LX %*A]tpyQE>O۪zKE8vB2LjsWun2b47\&>N:C 4tםiDoɟLĊSY1f(`oc׼p)caF;IlPq0wNdZ&ͨA([?_ (O5)J;JrBZNhܲ9U![OOʧt|Y/<ʹ*yvz;dԥ=l4X,$KQ~@c "Uo&C Be,fa$OWU8 biY_=tlp&)=*@9b^e/%2 ⯶Ȱ3s۫"^=K4p HQۅk󝡹9a<(>i416reMuWt{qnTMVPxGڟ 9?5ӟeT9ۭ g. }Gس?|G "} /VxUZ Jӱ1>pg&1:gh/)Tew^~/lvz Ib8OЧ #9kၹFa4C*y_`8`zAz`_f!aކN=Dt$/4V(C0j1w + AI N!m!:}qbxn2MHY$vQμWw׌}:/Eղ|K`b;TR?}RW4 &ꤶƋۿJ{܂Fu% W,3LyGӟd=%q Q6IK׻ W6v5}߀ɉ/$||~tHṱlɃβ rjVktئdu8@(%:}~+J\`nQ<="$5cd.&RÖF.Aʄ!n1?, {9iXv31K.LRO7>G,r:Q 0e[_ݩ%|˽:0fd""K("Yme U>/3IXe*e%ݓ*e[j/WP  TJ@O]]YƼf:1+bm,+Z-1cH"AlEߓ&- 4P_E $&¼B?75u$0(5, mO6LWpsFCd,fd}nx˷ф Q`sǧd{Idlh+g\N`DDI˞PN,G<Zя-1*jr;P{_x)8c:4+,H eT#\VzKVC{UbCڃʅ8op_@[=d}ZzjNoJ!Őw&1L7xO[mcX7!i#c A8Ro40yx ?,iS&ȫx|␋(3!^bT:QÛI[틑:&ZԒ6b3qFJԍAP̼jt7M 99,Yy:wNv=sٛ:@)]~36 ";`P|xkMnE}\r+6aە6B|<Ȇ-6=KkyCtYu:ExF)6'(Hp87)пk\ Ju؄ԅ}Iw`89w* ӛ4OȆM|lzMo]DQ2QRCo)ă 6HulҥL6W W,"$ƅŮS (xɢkp^; =i &j3)_jWK\qVW4k_su .AS΋X;k#p ]YLJd$wq! tˆ\F*Pi8?U֊ao)zf iՉY#e|La! yٟ Y&4\6C^&́R6dE:_Uv)2/zaKNfRZf)7 XP^=l^݌JX9eYΞ%y!RtnA%΅NGqrj |ސ>1ѻ/QXKk͌닑.nM먗 `T0'/BPuq3jr$SsCmu 17h5"+Kg7Gbltb ?.ʉlcBcI 0 !7ŏp{c튝Ƞ0˴-Z|9DYƠz_7BǴO.PRW ˇg/Y(XM0m[xwbm 0}]U$k,N*:D:5cwU.x6WyNø{2βwM@8m\4Nns*E64@ @)q=k.g<|ZI8G{ G=)Q1"cF;l]S Z`ԵƲ+ul:q4*.,:V*mUkt7B,'ll`؋z]S.]|?̛x E<73(^I߼*}OhT-r6c7%:⾬MϠƂ30\͜ќhwf߶W~bx'_O3SHZkumlU1df"7Jy T#iO&q^Ŗ,(3FS|]nO&{?^;U}ExxWvt_CLvm%oCXd}Wx!>&L:TJ,I|z%侓{I-)#p_(-<0b ZL{'u}4 /sJ-lHF.͛HͻkzF_@Q3PoRQY{䨐1 k fU+8C3 F(jG-"rLB_>ns8ؠQV~~뒇旼߂ b xmh+Y:9^*|) eڎG,r!&/pm0bDа^zܮag-2(O%7ʯHXSs@ 4(ovDpqhFҹƔ '+g(.pHfctBՔ)ĕz$Wb7GSZ9m WӝӂdrZSҧQFoW*_ځt^`xp[l )<4L2":3 2-Ϛ/N\~Ugϰ?b<;YA<1HTn~$pU3~3Kw 1,x|!]ɗ HrB&m)T&~`Q:AM+9ɚl$\ʴVeIOChoI}fV{lKDUg,C\'v&oX^[\, <ؙXϯnWGDq4vٛ wR*ngAJVdAIKP<{ !z'-3ԉT#2k]>>Vտ 6~:"+2/8zZ5?~ nͤ"О1ʽ7*3K̟ܶ7J$*tͦUz4ϖ;xE˾lʚMChiV7S`Xܙ:W|ғE%(4nMϹ4?)~P 1`}l%{9~E̤DShX Tzi.%r^䀵-Q8%,ԟ,T6Fg,R]=5C ob5lY7+]E֑X-Nj)jГ7ʝ'˫}&V Hc-ޑYz"zdw${7{tc"4ֱ \"rѪW fhhiKNmɾq˲ &X;BHJGVoҨ\ km[҇ _9JMmޡ 'eE>lAOj8j [)l)n2eۥdQXXHJzQ)F+c XއNPf5y%Q}5xυHT7ݨ CCOYeso4u%O%fC: qYhh ɨb.*ź}T\;nf[%򼓃С j呪RPQHTW O6Bd֒T°k^4hAW_F$|69 N+,Ef+{pa5ڠg { =mL?y rڄۺȇ&>HtVs6#Sh>yjj N|1}8GU W_teBt׈Q`OR7iu a; -AYr>S땬3ty#1hͤYuoA&OFsh᲻n6 |IG/]lN y-뚌`r'봹Npi1)M>>N.:+ %.ޅt;Ru~ yTEۉ6efwU;~dhy[v.]KzyaQǛa ,HB#<Ϣf.TfBg Ket35a) 4GT˹!vOZ cjF =\ Kvߙ>]磐J(?LjîukՆO d9{4lg9aHbI&<,R"U'5b_!C;scG//#.p 9&%3v?/<-pU"{"/&:7`C"aC;q^3:쌫m@dO (h^b&vj"`)H,x7FcybBk?;>w BwHeO[dms)EyyqKї;h<+ڻGȼo"F \^Ee% 47]&٣ aKⲂ>kSO6=chՁsk&:i͗5!1rNTʈRFuu\_qd'9;B) Y#Fp4Bv?X*)Dv-9jZ}/.='+7+SRzp'VeXE˷hT-pт6|E7Z(3e5_2S b @ڣqZe&E21HB$KTYC/S4۵I]( 5cGom;Ȫ5<}@Z`y@*_{M^pmBUrhmXu tk8⁒7z:"ٝaˏN2$FZ~WQv9ѷx|]K="!I\1J=]oh$7:b8OdVjG&v=K^X"vڊ9t`z*Jx˞޵/h~YGPZ3W!* _554 0/t9?;BOfTwφD'1{9vs汖C1}d}%9ZRD@sڃ?ܨ=lPi LcͿ:s0_"|h@U#̑uOc\s}a=BCg1@7_B}Ke0- [T mh!^nMNq4S%Miyj\J-8ƨkf<!3}n+аվ)sEd!Enqc"_h}fl<;Vː | Wy#{ ~C)IK؉;}T#޶+\}៊'őhR8$O"ҤE177y>ځ8,ThL!TΜC(VF+{!AFGo&X!͎~8Ki;/H,9lkiCv4.: $=NP)-AKq~/LSPAy^u!Ñ۳~zMLEww'k2x($;v+C%oT 2ף-< sp(l?0Mneoݵ- \$PnՇl Ŕ]9CsCV&llwԎuxj*Gꟴ O=*{C-ֻxA']nRRoN.RZY>]50!o9KM4IP1kOwq"w.J6%@!VFYfPY(d^ oVGg) L}Yn" 5c?ɒV9z\ .ygdoPT~_ShRV3ɽBShB*:\t6iƉ 7=V4.ڝ2`q'vԴcr%i5 +B%JX&-Rg&pY {2"ܸOp-Y ar vv,v=O8 PC/?7E < kc9ct:+s!yzĘPV?Wj:`ir " ۵U[/|oznԁ׭&8iTtQn߁3aB.VmK/*crY}LsnEr5Z!*q]: N}y%5;g9AW+snk^S !rr{M8C;Td .JaW֓A^گ菱@LkS¸#yјj5K70eлCAȥ!1PjDd. {QQzP-m.'5h (`{wUeūN7BEtM9DX_<ŭ9*[ǕOgBZT%?77[T ~ʋ¶D&28/ck:& H@g~0c1-K@n#ϓ[wx [xâIԴT2v J" JX!8< ^@cˍoNVQ(tLQwnri(Nga㛒DSu[߫?Lr݊TbGC+) @_"{FjjMJ_L*Lq/D {/.P(k?ɎlrjSp2#ˍ~.AgvBDm Q\aK$" ʗN}n $\;8-Yմp&ilwzp {|T'}c+%Z˕2U6 <]ub7LW2 D@FDrVaq 'LNVܸ) )FEǹwyniGpg_u]۟A HqT<+qH-瓗aKHhgU%MO #cmE$gʬCRG>z4JP֬vݧQ|4N:PR=\AϜX:4G-nC7=><Ġxk.zC"G U>S+ӄaߋuj^Nbx%|;"]vcCתvB2> _@+ӡS?3ne"t\x:2ho-ǐ7e=v^9A+)AI^#K2񷚩;TJ3+cl4%ܥ21$߸8 Hyr{L2OR >$hH8P%)!Yg.]V@144!0Eͭce<>(HG}(q,HKʿ {\c)R,WtpJ ȥBp05vvyͣD v9$h$GS$6!o7=!?v׏l/ɷ0Td }@Elx¶}$L^jCH"9qE%tۑdi dxWx 8ɵj4ؑ ͶF bkvU9mVRk[?ӨN ʄ׷9Z=fɷղz*s4X6i*V{XGJLKl ksVo7kOa>X12#ƾ. `'Du`vK-][/Op3mLV:H;pE4'[N=PPv1 UF]#S˨@lr&:ZEmZ;ndIO(̵_$WTih5ewSS:Bɐchq>a L<fͰҵlWL n0O'Fs;'4[Cogs%ԁ7AcpR}%RB1eV z}B=2G={8}r.O晷nx97H5PxMw)Uf?6@ ^23佊3[Rkwa)#N15?#*(2LL#*1# @ؽtʊΪ;#8S32.1.J=`F);lҥJU\<`?V"wO ÒUG` ;G :8 8C#2$Rapw|]о=#l:Ɨmv }yɰ]0Cl^'Ƌ_ӾQb#VEZOv#AIR , n.kvԔ :ھj4|IٝiΛآ,1˜“x22?҈ͳc^c,7:uJ|6"< h/7kP^'|7)G]E=ZOH<]Soέژ>B+} 'h+3jz8"FK#g< yݡi&#gDTL8Nє ,mep2~V⩓Zw6#kmb_Rs:lzӺƁF K_~v_di^e4/ӛu`N]8ߣJ6G3o@#il /Vw`D86uЪiBb9+gUjۖGӐk My!i=Cl{Ag^#s{K=yu9b-VjK=X6PZj O8NG(citnZcb1TabW0= uyS [ju <J3SrI`.)T5ݾBiGX0uQy򛓜 nZb1&8H%= >nxw Aꈩ#B n /PD%2BEP nfdA/3jgHI:D ZuTMp[sԞ`"'":AgQvBWP@m9y R:|$~fkFS'vV PML0 (׷/LA&^!$NX; P75XQrO*)42=gC#Z>Zo e춴HNV8WK1ۺG!`2^ފo5레WYo<4@UqZ:R$QxVӴ7q,"bEoƢG*RIHGVcN.p$ɔHMRԔi8o(Z<(i t^LSzb85t`װκa!kÚЪu R- 8/ݏڿOao^ 7~5 90eYc,Fo[ qE8}8dq<7 \]16-0bJހbNx'~G`]c]^X%>um%GUSOf9)M`b B%u,Xj[Q?p(np®lu-d*&G_;֯Ȧ!YUT(FlbqhesPYRQ㊇# ]wcUw z䎿Yl;$ƕ*VaN8Rp8F / ,KQeEZSˤ^Ar CBRv $+P)|"z'"1_Uyu=&IV 'xʁ.iU~w*HKD$n<_T P5TnL4:,~Nj}̮ Ε_QR"EzXpփT+&49` r6v)KAX+ ΡN- dDŸoFaV<3P6.T.S+r # #}y J `Q du=ҜT?T̖p4#ij/0İ$ մ׮Pmcҙ!Å%XTR#vǓ.Y^UF9E~ P#&f_'YVWtUH`QWKdI{jЁA^"1,(XHzΙŰTE|[.zu駺?Dݢj&{)P]~|`k K%HH,kWU /z $yWt6 2PiwzF 6P%ckP)B¨ j 5_JSN~턟vqf|pψ(>]mXdxD<8ׅ7q G:D5[ù_HÎ33Bo*sF(A3|🫩+.+TXjR ^AEdW,ę{s19Q$^$@)[oD']cdn3*ejf>=| c&yv-U8Oq*H}{[ؼQ|5q>?4 l yЪK+hw{/45H(I xdQH++pHYo;dD #%:9q)ӟun1'R ȩj7Eh&,MEÐ /K؟2E^rW}{M7*FmStt*ޠs׉L7YAjs~gM[o ]iȸXO1D2Y|i56wg+w~A#i#Bp$! =.k0r!X17\ݑ qX-ogTwl81<]|VftPJ@79iQ,+$F IE@dfKfidd,k8<@^R뗔@xwK?5g{]Y-Q$g?IILz挪0yP9ª6UIDjgG}QD_+[V3 T9LH.-)q~T=[#0Tvl*#qq8y۬\[&kׄ6Kt*9"?~ZZ⠵>݇YKF*[mڙ%6?.*(0 {!)#r'mN0p\r1N<ܰE'c\NH2WR..jTfn (R8ֆ1Ԗu\UfYV;0*w@FV$}. -.:!QHo^;1/x\j!q 2uvٲB4!y9Oz_g|_=uI%[o?ka}q2;H=괶x8<ni߭_le*a"G%Zi+,wI3stW}f",?w jn:-MhHu1Frd}S8Ʀ(1&^q@!-:3P'Fk"QK2N>t--s5F a6<HKnZˮygrl҃4r!ژl+6+K,9QYs﨨b~xC9b{Lҡ {5pQfzAE&{|gCZ Bl't5\ eJ)L[Ke4@jbMt5 =R>`3v`{e=;i9+at#%^WD3~>ۥnm:ꁔYUJ!t>#;$Zﴉ$y$rEzp%8wnQ&1/od޲\ 6$5Nz<ml-p4}6|vǵӸWT]*l2(1eZHtL*UMp3h!%%qLAVS'A)"qʾ 臰ow~|df.ג~h[A_JwQ;]~#U3(32S )3(.['h1J`ĶWxD\P`^"lukʑRС=Cg:.i[V܃-PKS(e(V| %ؾ=Lp(gW2=oАї/|ұ>9TD}y."΍b7=]uf@x9ֆdfY~di abe Z/D i%aǜ6W7u!d[D7쟫L1kҘZ:9r_&")o.7ʑuyaZ&Jz'.h%?`3pp *c|mh=.Tn#hx7\%R?ӶiTb;ک^`aNP \GRyZR'٦ NrC"* !G瓫h~P| ٝ1^Wpu-#沨j2\TNLG04=zzn`a=8p^Qڣ2 ])L\A]\$3F^B0|ĈQT7 > {SAۚ+hT dQ!oH9(2k7D|И.Wb'̤nꇭ3B􊿘Q8e)7T2I[|V Ж„7ffzEjkA5}=L~3Z-vJ}saqsxwuos?ļJdg^_J5Q1+l]ku8'z] bN')guʀ6g?vNo^!$Ɲ1 Zm8Y\4$r:"KP&eY dߺ ք?*W^gQ!|7bn ~lkJև+ , Fa`G#πQwz0$v-Cf#5u/)IނA!<VM <arYfZStŝ@߼j!Q9s\?KB1)AФ\vQ#a"<<4FWJCiT| N cSE^q/ ."+_F9w[mnMViţzHL:~ U/Jģo]g#F$_'ࡅ5A":E%fadvf,^*a^%jl?{/ĩ }kp)#tvH7}TGڳfx);GYKr1ҟw$0լv`&Xp${]N?[}y1+?qǪdmj[(B"U^&"f/Zц@Eߔ>'s2oVSl N97% tD3bp)Nt@C7!9rldxGqµ&Y&-)@LLŬ{[Sgb\fw d0(@)FټaK*01Eő}=`n1;xT4x-CoFuHw+(NU,ߠ(ק:lRcHvWD >lj=5yNe膖o{G.'|0t7wKD5ņg>A;+bz dЄL `ldM>g4<BحfZqkm+aEwF&tR[6?6YݨƘlؒBNvSh-I'销rOU揇'd] ڴ5n7x4.+kTɉaxМ P>-/NV[V^{xRsczĢJ> \fnv`yb ȥąO+B6mۏ]<ĝf8Y~$|m]I0l+l.: K:6yqOL .!5獪g$[k[^-M tՙfx1[p%)}W+{[!dβikii oMnºZɰa#$",QL=DrkjydD`&.*쾓Y{8f8PxޫJPm) N|Zjb}D '3XXbRg\i 5e2"]Q/- X1gp/q`'Zd[EmKyi|NtǮ{T3" ޒJ'Z:NbZU}̱ ¢G|29T$n}w;'B-tw^j[UL1OE;ZRhbp㏿*Z+LFϣНYMEi8N\B\7!'[:o@ٸL^|܅ 8w`og-7HV¼] :fhESjF?m&wz-E,%6nz=g\ )C<}$ Wn5 Qu !%M,Y%G3hh y-9(}UkNr<n +&*}H-1(09Όy3ޚ{C> ?ot4w$ yQme@)ƍRZ/ެ衺mh^(o wp831n[r޼`SBCkY vcd6peq׊i@e;4>H._ܯO^7A%@GAqbC+]g0Bkvasg\uO3 M/F9k'r?|B iUS{0 lw7硿1cƟ*I_:RQZfD\K̥̳`)nhI6Q0 M}$Yf{9dBKJŠqSgVgwDfLҠgNԸkC\p߷, 3QeQcor73#Smb-7(h? `ߩI^y3Vm-hA :^=.,JGjq9œN/[3%X !c1ʦlYKJD7W/4a$?|ؙH9zҠu~Ƌ[5g}).P}Q G>F&38$PwU.Ju ŭڷXm~Cp2p3Ҝ=NQ0䪱?]n"Uq UewГEv.tU]iIǪKR@CV;+Y' FRWngcn"l%B|Et[9G) :\Quqik|`UCW A22 (Gy΢_q0HYa }5RC=5f!YR~sw +B||q!p,I록!'  a~ ";+7u[y)<}onQY)ZU.jsz'jı[;Swò@ƴ*>dcF$.2 {=CgMs]}Uo!< t9n.0V¨tyTJUchtC'([u4Jo4ş!WG)1 R,Ҹ`p7gBc+H>~}Y\[H+-r8 561yX43H¼^4sc >/ݫ\+m"5^-r[[8Y]+pP+!|1=! Z}L[WRD`,%(jqGĒ9ZRYX-6O~WԤM$=FE?6=!9Ơ(:c: &.Y#@?ujR$i1t]/-L Ֆ UncAP0|K ef"`(UXͭԈ7nj.HCOWe?00DbliV5',^&AU9 B'‘Shl\sB>af89'%\3zxY(֕Ew^`W@abv|i{hd'lj=q@Z!zyaq7mqE[C |: YZ