selinux-policy-devel-3.13.1-268.el7>t  DH`p_O$ƨǠNSo {V!Sg<]D0|N|.['/12u50y`5Ue7,Tjo\rNC|_4EP[9dJvHIU? WG̡i\;O7iE?EjV|jOa"ij3I!xfDi(![S, sV_.8P]Sg;dvfz9"Rf!<{)t8d,P`@!!)kiyQ֝Q/ Q䁗~SOt m7pɁOOk$Q&s,M{ i:+A?LW50,G:QDD6¥t/6@858o&f(N&k^D7۽'Vg6G #s\>9 L? <d & ;lp  PRR !<R +R A(R R LRR.RR8P | E (89$:-> G RH 8RI ΀RX Y \ R] 0R^ 3) b 4d 5e 5f 5l 5t 5Ru JRv `< w aRx vR 8Cselinux-policy-devel3.13.1268.el7SELinux policy develSELinux policy development and man page package_tx86-01.bsys.centos.orgpCentOSGPLv2+CentOS BuildSystem System Environment/Basehttp://oss.tresys.com/repos/refpolicy/linuxnoarchselinuxenabled && /usr/bin/sepolgen-ifgen 2>/dev/null exit 0p R^q'"-%$#5-3z+*I[+b$"""/H(7?#3J2*G"&'KH=()O63>)j&0h&H/0t =/:*8"-%FX n'4$7-#3jMw0>w029!B4%48*K66m3-4('<W -* .&.z.^-2.&3&l!*%Q$$FA":4955K*)-:pP9o/UG6.D)>-(252215<$?R.@C.;E6 7=b,t2615w5O4 ?;5RQ#/@}!;A$q06(4N6j4 "-&h7%=$6zLa,J,g#1/(076E+~47,8JC95F%3 Q%!-S;Q5'-&5%8,+7.adA;HBjHS6,1o"40+./`5Q 9?i6./&95754,!1}'$4.38A-()+CG%0./-74>679,C:p/#0r" J> +w$2; E*yF`*c/0v>7l)4QQ+01 0)-y8.' 0Y8e>g':6(:60+(yBG".')\.k=6@,6_a).I947Gn*I/2'*q!{2 &&.*.LN(C$#-3U)I*A19="69<7 28BF/<260'(#@_-.K:`6&Sn.&,9! &3XP0@z;1E31d$)00313|01(12RV'&6^.'0'22D"2D)f2D)f2!(,-=C74.*h0xI!& .0J.'[EE=?0(-&'W/.U;0AG0J,$/b=8Ez2 M)B'(7$6<=677\6S6SS''g37K)&0hN3!Y1I_ /(()4& $p%05BQ58f'$#!r#B--I0}=F0TBM)H#0& $%.:0KJ+6J2r/- 4.2-03-Ah55.1.5-7.]37j$S5i6,549q,,X-J*,+=F0="274:..BCr>*A25G?//-18O%0i'2u(-*(})+!+y() +%$\%B>BW#-'8?9.$:04490#"M.^(FO27'\ NMDYWBbY$5ud/ \6ja 3] Vi1>q)II!5 S =s + [*U/V("3^w-q67A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤_tŇ_t=_t=_t=_t=_tŇ_tx_tx_ty_ty_ty_ty_ty_ty_ty_ty_ty_ty_tz_tz_tz_tz_tz_tz_tz_tz_tz_tz_t{_t{_t{_t{_t|_t|_t}_t~_t_t_t_tĀ_tĀ_tĀ_tĀ_tł_tĀ_tĀ_tĀ_tĀ_tĀ_tĀ_tĀ_tā_tā_tā_tē_tē_tē_tē_tē_tē_tē_tĔ_tĔ_tĔ_tĔ_tĔ_tĔ_tĔ_tĔ_tĔ_tĕ_tĕ_tā_tā_tā_tā_tā_tā_tā_tĂ_tĂ_tĂ_tĂ_tĂ_tĂ_tĂ_tĂ_tĂ_tă_tă_tă_tă_tă_tă_tă_tă_tă_tĄ_tĄ_tĄ_tĄ_tĄ_tĄ_tĆ_tĊ_tĊ_tĊ_tċ_tċ_tċ_tČ_tČ_tč_tč_tč_tč_tĎ_tĎ_tĎ_tĎ_tď_tď_tď_tĐ_tĐ_tĐ_tĐ_tĐ_tĐ_tĐ_tĐ_tĐ_tđ_tđ_tđ_tđ_tđ_tđ_tđ_tđ_tđ_tđ_tĒ_tĒ_tĒ_tĒ_tĒ_tĒ_tĒ_tĒ_tĒ_tĒ_tē_tē_tł_tĖ_tĖ_tė_tė_tĘ_tĘ_tę_tę_tę_tę_tę_tę_tĚ_tĚ_tĚ_tĚ_tĚ_tĚ_tĚ_tĚ_tĚ_tě_tě_tě_tě_tě_tě_tě_tě_tě_tĜ_tĜ_tĜ_tĝ_tĝ_tĝ_tĕ_tĕ_tĕ_tĖ_tĢ_tĢ_tĢ_tĢ_tĢ_tģ_tģ_tģ_tģ_tģ_tģ_tģ_tģ_tģ_tĤ_tĤ_tĤ_tĤ_tĤ_tĝ_tĝ_tĝ_tĝ_tĝ_tĝ_tĞ_tĞ_tĞ_tĞ_tğ_tĠ_tĠ_tĠ_tĠ_tĠ_tĠ_tġ_tġ_tġ_tġ_tġ_tġ_tġ_tġ_tġ_tĢ_tĢ_tĢ_tĢ_tł_tĴ_tĴ_tĵ_tĶ_tķ_tĸ_tĹ_tĺ_tĻ_tĻ_tļ_tļ_tļ_tļ_tļ_tĽ_tľ_tĤ_tĤ_tĤ_tņ_tĤ_tĤ_tĥ_tĥ_tĥ_tĥ_tĥ_tĥ_tĥ_tĦ_tħ_tħ_tħ_tĨ_tĪ_tī_tĬ_tĮ_tį_tİ_tı_tIJ_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_tŃ_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_tŃ_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t _t _t _t _t _t _t _t _t _t _t _t _t _t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_t_tB_tB_tB_tB_tB_tB_tB_tB_tC_tC_tD_tE_tE_tF_tF_tF_tF_tG_tG_tG_tH_tH_tH_tI_tI_tI_tJ_tJ_tJ_tK_tL_tL_tL_tL_tL_tM_tM_tM_tM_tM_t_t_t_t_t_t_t_t_t_t _t!_t!_t"_t"_t"_t"_t#_t#_t$_t$_t$_tŃ_t%_t%_t&_t&_t&_t'_t(_t)_t*_t*_t*_t+_t+_t,_t,_t,_t-_t-_t._t._t/_t/_t1_t2_t3_t3_t4_t4_t4_t4_t4_t4_t5_t5_t5_t5_t5_t5_t5_t5_t6_t6_t6_t6_t6_t6_t6_t6_t7_t7_t7_t7_t7_t7_t7_t7_t7_t8_tń_t8_t8_t8_t8_t8_t8_t8_t8_t8_t9_tņ_t9_t9_t9_t:_t:_t:_t:_t:_t:_t;_t;_t<_tń_t=_t>_t>_t>_t>_t?_t?_t?_t?_t?_t?_t@_t@_t@_t@_t@_t@_t@_t@_tA_tA_tA_tA_tA_tA_tA_tA_tA_ta_tb_tb_tb_tc_tc_td_td_te_te_te_te_tf_tf_tg_tg_tg_th_th_th_ti_ti_ti_tj_tj_tk_tk_tM_tN_tN_tO_tŅ_tP_tP_tP_tQ_tR_tS_tS_tT_tT_tV_tV_tŅ_tW_tW_tY_tY_tZ_t[_t[_t\_t]_t]_t^_t`_t`_tp_tq_tq_tq_tr_tr_tr_ts_ts_tt_tt_tt_tu_tu_tv_tv_tv_tv_tw_tw_tw_tx_tl_tm_tm_tn_tņ_tn_tn_to_to_to_tp_tp_tz_tz_tz_t{_t{_t|_tņ_t|_t|_t}_tx_ty_ty_ty_t}_t}_t~_t~_t~_t_t_tŀ_tŀ_tŀ_tŀ_tŁ_tŁ_tł_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_tœ_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_tœ_tœ_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_t=_tŔcd065e896d7eb11e238a05b9102359ea370ec75b27785a81935c985899ed2df6846bbdba1149ef9edd39c6f18d37f29e5ed9cb3670521f142ed6d7d2bf9f2b8342d2c3aa4d008aad3243fd00e4723033e27e253289356cdf2cf9ec46135a8327bceb4f36b0f077b7a232a94e214b3b0a5a85152e4d89c193f92ddaba3ede1ad6fb218f73d2bba8255a74fe015d2df2910ebfb243a62b489e4f1c8983f9bd9e5ec786b38bd11dd9bf88c9d6755fc9d2a2faf730a08fddf44b15e25b149c0dff30c55124f8ae803295d188a3c2944250e556407ba3e03fa2143af89da0abf555acb971188553ef88e90f21acd5dd10b9b7dbbc0c180969cb1e74d6fc503a36b6356b5f86fbe61170847f3c0c49992f40604affd8bb72b38aa9428e1c25651ff24503a75adbeb38396e9c1f65274a8eb30e4a6c2b36273ef2aaec133894d7ff1f3f49c33d723b1021d9e19b26d411348ce6e53d53c2a8980fa40f17d9a8fd75ee2bf08bc4f32f86d4135970cbced7f6379362814ac889f3f07d7de2dae927e8f0271cb7ef51ad05324a77f77a539b403aae66cb46f7f43ad8e1124cfdfa03807acd1f7b526e1f5a903ffbb350a72d576a053aef51bfc8be2b89f8c10c12abe53988ec84d7930258aa2c0725b7c77a6e71760c86618952a991d2fa68165a3608bbfc18787494dcf5d4bc782b7158c289214a15cec972f0e28e4371191da3fcdd07859e028645b866e5ca04ebc40b047c45d30b656a0601c4b169e678765b5349271e54fd3b0cc1a097c824bfb6f654f56aa5707827a4e9bbca76afccb7824f407b0c31d95d224a5418a3efb3a6cd1743f855c02d94dff599dbdf5e24ed1f0a76f5fd64238215e9ae22ce7196abd12b8972a23d94a731c8b2c0331bb8cae322a1ed69fe46d30871a1ca4cf7fc858157963b7d56d4529b4826e6e5f0dc15fee6919efb0abfabffebaa544a7ccff0d1accd0803834da12b9d120dced6189d572c3e5df26e1b167c9ec0206ffc6f71cba4079516a2a325e9624a38f18f71850479a324a53303e54b8b48be9a52461102ffee64a5043144d759d9bf3fee5535c1b0c9c141428c512537d950b6c793430de590e2962be29a24e96c59d9c3fd222250ced112968834b876aa025b5777d9e6669e8dfece7c18b20d7299bd89fb92144d3bfa1ad3d687656a7961ccab2865bc7d6524f7fb03232ac77e744103660f0aad552970f4d1127eac6264fb31e692e7c0fd023d3c2c5b68d40bb679f6cdda255171dbcd87947dce5af2b0325c9570079922e11553528be830bf192eb3fcc50832c3c5a90c5298b9d9e937c13fc976ab5a44a492694ee8d1203620795d53676249f8dd3c169e040add5707fe8c58714de38638f57a87a8bcf990f02fc75b59fa0ab31bd0f526e736e5b6eca598ab44b3dae620b90e7e602c7315225eea9d8c87059fe60b52afb61d5f10aec870f5f9fe52d54fb276b3b4a6015ed6f65ae6f27cf6c4ba8014be3a475673078f90544ed9cf37a146c01bc5c93d397231039b1d78637de5b3b4a50ec3463091bc300be5693f28246368013312e865041ddfb2f6757fb7ef9e8a1139e82f348871de11d870b937dc24490d4fddd1fa958a6d591aa09b70bd4df6b23e44e23d6c705d9841ac7ab11b1358e4fea02d3d3c180c051283d4b303236b8711a959d3a14fecc9f8d6a4865884437c648f54d477e25a62bf671e198241348b072398fec90cdec7f370bbe2573926825f44703afd27d4a7d265b46dc4a1ee86e5397695047b0b2e259a00054c7b6305a7fcdc1a21f91d8a45b7d37f7bff5b3208c4ceab1d240775ddafb71c644fcca04b27a70105871577c260e0efb6f21b89c3f817ae3617e5fb7fac704fe27ad76c41579303fdc482cb6e29a479537857cd86b31c4372bae58e2b46d24097a0204e6f48110bb4547394a0103b5e46c6240a3ba0b5edbde64620e8488b8932bd322fbf9d0126f60fd55138ee3f04290b8e903003415638c84d25c94cf183778b1d9bd8bc5bca701088ae95689517a66db5f071652e5795e653615bf9a446b8560b5c99330e78f55664038bcd1950a0329a46d2cfc5a5642ea3c29333c11d30dc48ec1b066e21a4f746da1992072f8d399a613929a3f4f02d724b26eac798e2be460b062c684ad065c0ea4d2f7e10f261830900958c639087f8089b10ef43f9a4ea4b0e2f05125def28b4f76a617a94d1a2b125fdcb1951f8432babb75041511082a8f31f6ae0a478f8bd6731d6a4ade36c8ad91ebf9dbecac923de1cd738c10592117a801e1d21da2885631f6e30278d0bf2aafabc7daddc623ff4f29e3d9376995b22db458db6a7f2e4f12469d45dd59f21356d141b6ba9505d5910c10322cde819d59dbf152942133d44d0d80d8fde2eab2284c1dd03633892d92551fae5bc4846c209c1465064c533e3cc651933a096e906b092165d6c1a5e664f8533e7b7cd1fe3c300154ff5d332ef44cefb4d27ad9b7e27cf0772aef1d7b19ecfab393973826dcbb506ea6fef367684d42a34fa5603665d859e636bfa709831fd7bd722a7dbfe9d8272c245b837af3fd660056741adde8c674cfef416aabebb423bad8a7e71f83b05e560cfff800356143cad139bdbd3502912030bdfda7ffc5f9910eccc0b56352b71dca85263a8f09c8a7bf9b131314cba69f402897b7b3a9ab351aeca088469a4f8466870b74dc8c44ea332cd939d3e0c29d6b6334d4bd0ebb32ccc25a17b789265354f3e60b8c7682d074ccee2ebafb80cddc20b53fac96109ed871d3f63232b7b659a54810c56e830b32f2b5b124978e2e667e246bf240c8efd1faee1cf0f4a9277c159c8019f1c19130eea909c98bc5dbd589903ed64e1ddb74cc6ce95ca5b2993731de2229a27be9e74da19637152c39bf977b70920c9eba8f3b5d55bad7d69d58481d53f378883ec9cf7d887f219ff665908badba9866960adb73368f4c5bb8050091541fbe23e4da5758dd88fd56f9392bd69be8dba58908ab36968161022dbb2331fc316c5d6ad7513707b0d4391d233ffb9773c8d85e125edc7f7024d1f1c7fb33247773d0121d6d47ce7103fe92225a3d398c7bb9e0d47c2e5724c4c1000bc6db2d771a3ed9fe0a3cae8000d9e783baa503a7acd18011afec101a1e849a4d5a0bc4abcc4ea8f02fbf40c263b859680c6d68eccae5cc95031935ae47c7be15fc2f5a54ed88ff6cb2b6570720f2032cc6d60feda89abd83d2ed4a1de1279d7913ef5d852fc2b21704259fb5a4b5345b45b3b6a9e541c7f159005f507dcb0c3ec116d0407723b672692810ee8cf9f9b1fdc691c5f9979519074424c5d95e441d3ec2bd7200659d54e0d55b50dbe4cdc307f98538ad0da6007f213507f121f3926849988b58ffdce0a01a397f5cce25e2e9867d31c93c8afe98c8ce62b5691b15b0ddd0aaaa487364d7b145d8babdc0cfbc49533531d39da9449158b1daf2f67b28431ad2baf6013b1fd17b52004fdcf211632bb08a61137f2e9b4ac97ae0209177708859aa95d1b03a5e7580180001e136353e3f1b157d2a49d3706b0a27ea24f33f33585a60828ec9e725b7bc2e9382f489f0c8e4050b21d69a5e7a814ba03f22d1d84eed9b5aa08c5b8cd92cf144963846c83e47b7b809af14b1d1ecb0543c7a58286cc007ce68b6b26fab71f26e21748b07ff69376525f195eadd1574eef2a67dcc44d17775964a8443bca7b3860876659d10a3e4b1101dbd9d19619e20c943fa53b9e735a9d2c096fd9da145159efacfc423153083cf2c283873ae0d090321ce70e21916c16608266f812e50164e825afcb06cf4fb97aa72587280fe553a552089ea582da6093c9c621e21a95700cfa359363202164027d5678af187995331015236b729ea199ae6ec2db0e539980a54d92a41c31f20fa90ec77b600c59644dab0772d051cb1d82a9e2b479dd8725c888ca7d64a8f059cb6fa2991ea0e47d6f3d62459bfc292fa2a0b5cc9197d22163907523b528fef6f11905bd0e5c8151687930a34df27b23f81a4bb75f3fd45897a7b4881a6acf55ff519bf005d263d7d543a70f3c145cb088834dab954a5c92b40d7fea04014fbaa7255b79263d831556d8bf81468236206200ef8a371d2c806e68d6c57658d6425c48a2603799e6863bc4bd2fbf3100f4e33996ba1ac41717f5b905c66b289fc37fcb1694eb3f64590dd9b6d90a652ef8045e6a3600ba07e1768155b6bcc63efe8f5cd7c922b0e583916ed07f68110b8bb0b8ad376ec83f9868a5cd66e1c10dfcd082d6acb6850566b51527a400e6be629ca143d0277e6c616d6af9275cc863b07cd962a853a4a4271cce1443b3d5b4fa04d80316d7c0eb588cb8824aa87aee8ccfd22c08b3d1ce00e7e8bb3afcbef816ce83e0ab66184160b6914c90f034d87809d1265dad4925a3db6d82567cfe7015c83996bafcd0bb929f78c409c999689f4ecfd1a7c88d4dcd48eef3885bece911eab10b4408c41d782eb8579152fb901889e61ff7095e5bee0e465ead7b7f80ce4033ff38f463d954d628ae372c4cb28c9556b275b12aaf212eecb77e5d12f192fd8cf7066e7736482f627dc4be3886d109fcc3f9dc1d2e0a7b671b44acd832bf8b16bb8c90b795b469999366fa96bb510cf851a45a3b70b7dfe0a2706d6a371eaab8a837e794cf85deebf9f2bd3af2c77d8503a8cf8ea21034ba9094dc7c2950fa751a7fe8a9ae2dd0365ca6b4b64bdeb9ad47962a562e26b47eccb879c5e4e53409843e3e80e8e163a8f2deae7d45932f6bb36c21bb2d277f8ed008e4fb7b9642c1cd812b06879f62133364d3846eef3decab01223a34e6101938ef3a83a91773b806fee567695bca1ac2703267d381699410d3ccdd21bdfe0b3a912ad55e3672215e8b406d1b611dd7a79bbb7e98088aec4842d47c1869023d581e9f7581b446c9616e612cb68f8faf3692cde4e0a80df1897b6929aa66fb1a3fd95b1939f33c6f2a477023f3755d9d30ebc2dd7fabf21e0afdf191a8801a1b7cd73a37c150596ee82d8a7d393605c6e9f0ae416df72f04bb5e545e46eaa68645ccbebfe1db95926a5c92200da17c5980953c48fc98403e678b8883b098fb1ab858a26d60fca6c589c7a05752ba50431366c53cc8e3138b9352624c95ada3c88f9bea7afe1e4e87719a24de8c6c59adab7176f09befb2a15e4c7e0260935ad1e2b383353160db421d8b22d938b011679e59990fba6bb74ec057506f5fc18cffcf5cb7f089abfd662cd18a971645990eb4b9f035d741d5aca3c76593ecb973968cf08319cfe20e0079ed3892c2784365c4d1d12b84bff2ca844801e07ec350777e773abb9ec147b17f0ee63c59f80759c6a51aff1b3bc2a81e7d5bce8b9d69ab4c51e8004d34349af570608435fcc1e69059b740535513ed69ccc08748ae47f5824ed0aa182c97e67244d768e70af1d873f9d069e4245b55eb3a16d2a0eba63e68e8bec15af2e8c905ecd812be60b8ddb467209a15fb706a03684987b6f696a6b888d42ce6f80d865a24dc1011265c6c7efbec5af70cb971373b2ba3f711e0060cdc4f82c036c5d76577364a94e2beac00c9f558e3ecaa4cb61f7a1a8be23b52a8556a5215d1843744bc3ad87807e76f6626f6a8ea4dd7356ce17aff619270963c7308dfb59742d44ae88063f3c3c5e2a9679f014d880f10482d9002db3b9f5b3dfa0b927eab2f19e4bd8270e3b6c0a0b287c9200ec8945e1677b9621783ed1bc65bcb644758db4146ed35cf57d830a2e629bef6522823e3dbb48d1e45dfa0c4dddc18dff3df7870ffcf33efe4e4fb335a58b55c103ad3a6c84250c8e4b0878d906ffa4e73ec0840d5f19ea142f9da238d44b6ede25f7bf8546fae892dcd59efecd5de81264e2cfd7dc20908c11280b5541e05f75a7faf43081ef820e9b3a091ba7d74c12b10c0b7da1c658a9daeaecb61da7b7d96f0551887b289c8982377ea74cf01eed464015e9b6ce5ad5b912eb9720081cdf003a61490c05b4618f49ae7e61c72d4a47b5cd0e8147602f574501af60fa97de5aa5a1b85375f337556682e15b1c1e3df53e564f4608b90d4f1ec863cc15db063b391a5f0173d0c57228568284b5a12bed595f069998d86e30aa04d5afa65741196b4f38bd2007b10e0344e53a3dac201af9a4e0e43bea72ad84cf88c9165a8eb5b5a611f416e8551bc869271a10e77c7b4bfdc5d0b6a489391a1b9a8c780c550d000119d76d773a9883b2113b7b86dd24b118b2d5d531c929f1ad717283a6d1a1f8007434f58fbf20ab18c1d2e5dd6c9e1148392990ff628473eb5fbd1e131a72e3d5e9b50fd171344181f00833060962b7a2e7ccd8edc2d96a519951b75130d532dda3967ff50c3cb9882dc1c17b47e845126eefeaef79c45e8b544254a82a27d6c4d1752eb9822aebb954e8ebd3ffaaa4f5c41244034393abf8ca9ad63544061e06c02cccdfd1cabb39df437a880e17e324e23cbe69ab3f10220ff1a8e40d6727cf9c4d5efa57ac2fe08c2012a5042f059649c7dc64ebafffdbf3b337556ff3a0f14126fe436e395216d91c2abf51ca5335635ba4a052da51372e78b4dc095da1599da76457d7b8f1906ee0b643ba94e319e647abe99d2cceb7afdd6ad527f5145cd05a1afe2efafc93311f0d05c37ecf02a645729572adaa1e0db7f18619e46d104b5ed88925f766a4f87a059711b078969f2e29476c7ed4ce56414c10e79eab024aaa7cf16f7e0d33b113ad27c4e08814b82b58a70da48faaee7e74621008dbba2175de2dccf18e6389ef425ce8e1c547e90cb2496d359f25f93f483540f1cdb7fd02f79989d0ecb787da6cf8e0c79873f2c18f092be55314bd9d8a79a2e4d9a1335e3c6d321b9a44d36b5f9f642f972c5328a1c4d22130340ccb43e2aa3ecf802e6d17797b8f54f1a31d2016e61643d16d6a52460cfe6d1328f2641aedcdd6a1a6b229a7c2956dd23a434f7fd1a076211d30549df37136f97c8501ec41872153d11c3d52d2b15e9ce7db8da31e54d0a246fdf485d95780810de220a2f1828311421275631d6bfc5040eecc5f9ea051d0e30489d8092e42b3ec77d068ce648f13800d7f996350b98d8849764ebb3e4c8323dae304813292dc037ce6a5aca7280c153640a6520c131d4f62068e9a9628b7256605fda444bc5071d5038ab553537360f0e3647cc2cc42f6281d6abaaadefbfdd6f646be68f90d78f16fcab804880567618fe7068ca9a317f8c1f334f084dfbb3b4c3d26528c8f191584ded4252b421400c1bec75add60e4e462b4fd374c45e853459aadd3fe5ed5dd9953c8bd587c64a374859a0c10de7be4574b21e4af329897aca0b7a541bdb49aa57194fd41954bdcae2967e1113e76d0754f7413dfa9f9b8cf2b8da267b5aa0b63889eb9d27ba3dfbeee4b1352b7ac146b771ce1391c13fad4a06214c1b76ce9319f390bde8295bc4ba983bae254c7e616ada40e8d5074fc5d8bc05dfa55325ebd397909c3211df040d85cd5476fdcf2f574c5d333bff4c45860b02fdb7d846f897b9f0366b8a557c545007916f5d51bc5211b938dce56285991b49b7466ff87e317fad3e444fca8da7e64b688b358cfcea23738fbd35a5c522c15cb4fc6fdd6748268e4c8b3ac8c080a2fed435ac5f3526e8c1a228d3cde1e64f915b3930370fa802dd46e7b1291a5fb9d9485d9db85307ddbc0cb2ae7423f938c13b5ed8f64239d08bed4f6f733afc4b5519bafbeee9d1d59736bfdda7d676f3a369ec9edb8829ad8f1e799ec4db9de066ac89fbec6653f2aa9d077ceab7c0b8bdf4e21c46e693127c98f55ce1cf5ac528bf9f7b4bf1dfd97750b40ae04334e92ce0d934a22da215d6cf86eb5de00a7a1a3ef1073012366dec2032d692ad0521670a7c043ef23787370781407fe0c6c1ecfea6abdd69716856a6e1bb12eb1e63a0574788149594b2895d91696dd5c5d505c52d60cfffa3803ce2e42b212f093b4e3818ea741c9f49227df4d64a117119803108a4a47b0aa61c5f00ddc2a1d9ca968cd80064b649e40789ccfcd1d37e3c31b4007550a5aae5a6d19cb6bf25fe18b839a20225a388b67697cbe3def85edf054a590716f5ad02c4db7b3d50ef355a7dd07a3c8e777b24ce5362b24d1968ae27126dac5432fae265b3e5efda96230f823c8793ecc43aa31e2417b76088441dca722ef9318125aa9e4b5a82f710e950dbc8a9c70c32725b49a074b8a9d2c801c9a98cde972fc49ce342ed71cc3ec8a70d66db65bef45be74a456e074f6b405c9d2077a6ed15b153311386ced2965b6479cd7e8f57e5c651db5cf5ef39edf53a75b3c9c7d99ab0eea27f973de174b7d8c4e1900609ba6e879d692144343dfd1174920450d1459fcd2d9029638877f28004adc8796992ba1f11f0b36e6f2ecd45138a1c5eba2b695cc5048b8b3b6cf1072c43823f94e28c63f298471e01ea99a3656b958176a7b820ad1ef14497240b65c5fa186973113e2a3a0cb369ea211391ea8eeccbf44e274f989e90d07b47a90b72b7a7955d1759be12c5bdaea87040e4b72a0ec334e3094392f08a215acbb9b0f35c1d1bf6bc8c7371eac0a42ebdb21dc846fcf1a68b5727191db65428e478644fb0d8249d2a4ca3486aa47acf9f859a769838a9b2e086ce0810bd302822a2b7f578201e603dbaf21741057588a918b0d42f429c2e7350c38c1d29a041d2416148da807aeca763161ee020c47b526ca55ce6aa00d111b14e144b1a6af7ab1dab1a13a27d639562d17db3845cb8a0769d33d2235c132b2c7b1cb7c4d99def1c7005608159cb15f914745620bd64f09603cc4ccda731c1e71a35cd6c2c85d28a094bc0ac4be9aad5db62ff9513bb62145e9d0cb257a9dfd2aa33de9413ef230ef385a43f9c330efdd9591f22ce8a839977ff1acfa3c809f1fd6171900ae7f903e14d65424830e3c2a89dfdbd6e46ab33c6dac7373675beab9bcbfd94f806e3f4356a95c5a30b6ed65b5ff83517c9c633c1567af0744c8348df2ba6b5e06adb04f3b7a270572d387ad168a4be49e2da6218869b90c0a9c66ab8e6d0338fe110d81a23124a43c993e02999559befc618362d899a99c624dfbefe9a6cd579f1eceaa012d7b8bebf5225bf6f4b99954eebacdf5aa34713c6ffe0529e47f379da028c4aa6d4f5c3a58d2206cf16b41898633c5d372dd85dd7f19cac7b049a530b0d66edde188d49255f414f6fa1fc8eb737b2a0dbbe6abf2a6ffeef2f857027eca28490f186a92b8bc487692152b549ee68c8335c5bd6533e7eefa5862fa53fe6536b505ee8b85af4ba5159bb4002f5f97db7ad22143b8a0c5bfa6888c43ed3cba6b2b6f760644498dae3efee5af0f83a8c95cc94da6419822ce81618f7a0f3c7fc05f28501d637cd6e4b9360fa733f58ebdaa370dfa1efb78fb3aac598e4bfe38207106a005317cd1bef932baf8910c3d2db0d8fc053bb0b5f50a49fce64b869792a28e6ea1fcc186d0611af28000b9d4b4e64848e96828fc701158225baacce2d511ad98a5c876100fcd9ab8dac2b2e7f12872fa0bbcbadad46fa03ef3fc0ec2fd79563229d271a8bbd8faef20f076963a10c7affc94cf39912e3c3fe0dee13e417f2871c3f0510613f3dcf4ed01752a36635e86a8fb55dc9ff9a8e1488e8cf034c39bdbc5a28deeb61c5744e6bb8049898d2aa57b19df34534be6c796f5203555bcd04c56ea994d90dfa484a6ad1c0304a6b9901ce26c645ecba902ab61820cdd5be4de633c58f050eab654a4cabf524dbb37827767aba0e987e0716c2aabd83ed6321a617a27e2e6a29607ddff0d5905af10909f24dee3972d89c15044f4056ae81876c35d27202128bf5ec400464dc0840e4b80a60e560d42e3490df8285a73bb7a6423fbdef89ae900e8beeccaeffd547d7666848840998efc481112a2e8946c2fb90d4f20184d30f02f17bbeb3323525ecf76aa79d6fbe4ecc33fb4ce76374590f9439bfe4254d439ddafa50651104d9e02997f3742147eec452502e0e345461ec47f85bf98fb9dae315920eb13ba87c0afd13ed6ce593aa99393d385d44f5c9ef1bb5bf7e8cfb2aa1ae7fba78f8c9a818988bd2447654923c75074bda85c4bc25389c0e79ccfca763164b3662511aadb3e51f48f06ecabb754768abb57c6a3df65f197aa54fe51158a729f4cd2f736a7b74c7eb1d0edf6992de21b98cf7befef54450fbeb0e3edc325aa28a212b99c7d61da8f6f4ab46c1b7df515d30b00f6feee36dc4676a9ba261803f4621f4d10946474230f9b09f678419c260045cb866cb86848f8f743639275b51ef83df45dca81022fcaabffdf6fba405b38bf40873a29e68260cedddd86ed3b589311d5fdc7a9300e37eed021583653271d94e8df3b4672466b1d27b81fd2ce923f7812db7569482c5901b541dd31610ccb99188cfde62547836a44851cea2700c420869e11a87ccb573ce1a8aa5e304f0a76170ea5e12541cd1ea027a5360e4ad6f824dad236f2ae748095a2532d2820a20762754e5c3123d6157b03e740c58d1f00c2f0020f412e630a8b5f885a822c6241641f54746d3e8ab77d77801f795d76f565f25ecc763fd2dc0aa111c301cdb5b27bd4dc83080edd448303c21b4f7840733e27e53cf910e606fcfa2ab43208209e060774fd571c76dccc65716f8fb79586a9e4ee4e20c117c8f0565bf9ee6c680d82b73468aabb7996bb15179107337df01d2607aab36f702cba23518991f4b5e25deedb80e8d700e66eb34a14c2af94f3bb40f87105d5caa6d62b24c8a56905761e694097eb7d9b0d4dea4a4707a8ed8325bfc68b6f754e615af54d553d07e95911dfa5ed969b565edf152173fca021a35c4f12b268f88d89de8067f48e3b87a1feb81367d450c52f0289d841e4b713248267a023ef2f3427c5a53d8cba9b0a1428cdd705eae601de3c08a37d42f7ce83bfbf6c895770b041c6717a0358cbef29a16bb276dd5b0dfa45c0986c1c2286a8ff7630e9b890c3797be7bbe93f51c19cf894c21af4259c58bf826e38ab91fd129acb94479d779460d947128623230077fd3bdbbf3e6ea1dcd77062290419ab0fdf6550acdcdfd4738c9227269d9552ef38c496707bbb3599bbbf5ad7b680ee0f58ceffc98669730394ff15285372e81da795d4d867f4dba85371631272a9ff3c10f272d3be0cad8f445e15b4671fe21e3da27c81589140b000c2c5a963df92b36be6f4f844aede0e189e58ff214e6d9e2f3e6e03d0913bbcdf1a45c1fee7a99a39de6d80cfe17dfc6e78f80838a385c2b966b3bf3fda406bfea8e39b7ff796af6797a22d0ac64b80f6492c5c0eae5302c70436fd04f4014f9eda653cd40a39d7c5bd8a3191b75fd9064db733808d865907484a46de82153ff40254e0cceaa7518dd5eecb60d0b306cd1972acabc75005f3f957698cc1641b6261b47b73a4d48e26c162de80a9f9ed95c1893d93e2e47f3001e03b29358558010771f6172f592cfec77dd7884b8649a2a50b19209fed4bd69e4cf3f9fb8bc40747372a0737482d42f055068d31bc0f92aebbddc25d5ee97c015943a4610bdd7613fd95515d7575e3be62a6be7e3f601870cae1af676ad3fca35d6c301100f91340f4e971f7a45ae3450f240c18a2b4c7c758c7b9b15f4867cb4f2b0244a93f5103213503c11acdbbf7e058653540eca356381ed01da097ab67b174d89056ccbad46a7ea32337b61bd9fe84d34ee98b6c082ae737bc74c3b77c6b149b0f33395c6e29fa11b7fc2a681f12fd5e988ea97a7ebbc70e29b67ead6c46bdeb29f63beeb0cdc740fac7c2177316aefa79b94757fc46bc6c7f2c5e5502395124cd25c69d75ee7ac5026fe80fb892efd222f7e261e6e9a32d7d84b8f2a0404eef173e4ffab72be6b1dd0f393467848df7e99072381aa7ca40628c8f3f6054d0b89d77e14c9438566868c467ef20970a9607ab3e3b63df5d7f5a358a0ea29a9d842e137c41f65ea536da6bd44727c12db09abf1f6639f75ac8bfad3329a9e5bcc2dc837ac956683badffb04bd227843649105dda8deb6c8aa0d8be441d4ad2633775f714f25308d4349efd19ed2e6b929d6d2ae16a55aeacfeefb6705ff710dac6d30e3a3992135d168ba751cd2eb4d29d17fd37daf9a26a56c3fb57e48d45259c831c1a5ed539e1603d76c9de147c8202e5a8b817db1dbabdb0d250dab611adc9160db42be13185e701fd23c1e1e5341a8117da1a619454a2f7711ea81e36376df23108ef10e1bc0f5ed7e7ae366a15d44fb7cd78ddb74e2154161263b5140ed0ad155dd76d3fa67b39ccced0d0814567beb75a876daa0df1af847cc33996f50869fa8faa913b3fbd7f07c567a3853e9ecd153a6923ba3aabfd27e386f2bc2a2d5f526f8c9f3cd34dc0b90ac883ea3efadaf98025346d6a866c8d2080f8e57ce322feba65542faa07eb12da425d54fff13ed2575c70a0f4441c7754ca7e9cba48c51af219e5070bc282fc0d34fa4855f8cef70c40c793c1af1c7899af4c8bb8ba0d0323eec41d159a657e6b3dc8ff45a35e0becf82eeb23552c6c8feb0bf9809ac02db8210a5583506a3bd44286d3aea0788dd03e7e2980807c8cabefa29e2939adc5484063cc4c51cba6445ab793e4ff569004e478544c2c3b97c9cd82b6cd21d829d1ae5ab8f6ed90240203dc300e22443235abc48f54de0d9c13ec133ccb130e60e1b88a7c48146776d1aa21dcf85e72d9a678536498a4bfed86e72321c9a6b156fe1d03c8b1e58593e8a642479fcb3eef18b5e95d5d61e80bff4ba5d9b2276c5517a68df7c1074c80ed7fac5337fb95807ddb5d550296970685064149d416396217760ca21afeac137b82879d648778008c648a017d05b1484ec7c21fb64a23518f20883a8a3e9ebc1e49ddf04357e2e136f977dfc9044e0e21f825b616ef0fce038736b404539ade5582aa36b28fab645d00bfe3412d7d1495212d65b27f9a4bd037bd83423b3c1a19fd554c5a900028f0c097e3136c8cb145e60f951613af2c4d4db81f9ce5b856fabb6de76cfd7f8dee2a7b556b9abfbe73073210f91dd06d443cc79b9e0fd645ea852eccf73368f7703486aaca382cfb471e05e35b601af408e72c0d7782a787a28b3c99607fe059b6ed1d7facc08823bfa2bd7486d526e91aeadadbf304fc03f9a083caec948fdbc5b81e682f06ad363d332920532465d5cd1fb38fe680ae9dfcd1e8de31f67634415348569aae094f43d79baf509f1ffa16ffc3c999ce2889b98284937cce6e25a548ba51c99c973adc95219be65818bd010ea9ef38132d484ef94758d3a2563c24bb2a69b27a1ccb14a3b8d7939a891093cbb88a7b960d15a97b2fd7e5b215fc7542cdf4fdb0cf8392bc38205b11d3b690460fc55043eab319c4909498d146cf4cb411949bfff934a81107e540b88dfac4abcf219f71534fb49c7e717c78c6b4472076e4b31da0790fed95dd70c1aa49415970f9fc6105a293c5f2a62c1295897f26cba9dd4d98526e9268f72fcc6419661914e746687c55e584822ac3f057df8641267712322802fbb5c6a39f0246732599d84815b9e67f549a80d85815376709091d81da4430b71c722ccf37d540ac0ef5403dee05201d5bb3196913b832efbc8caf3cf083a2379eef2219a578218a472553944ea3236edade9948d6d8ef8b4beeb95dd856204bd868c74c5a1cfcc866181eb7ba8b1d07dafde628c61ee9456c232ee8efd0a36803ed12a801468fe1ceec1ed33a1a8072541b873996f9562b97bbef8ee24b32c2562e11e0137f1cae5b011afe4e3138efb37f7fed290846c87d136a0e23894b2f4eb0d4a894040bdf00bb3cfb82e16c7ca612b7c5dcf30a4555a863d9e4c822d05d61ea1d7e37e6cbb1ec153aa47c85e50619a8ed5f761d6e99a65bd56e1d0f80cee34862fdf67170666599e2d16d59408385b464b224b5057e77cd82cd66c4df4f1391cebc123672ef3da027e5119de8e745df549f1efa43e0bcf5292b457f455bd871a7891afb4d5dbe9ba195ccc87741af176fb4ce5c69d59b1b39642677ab613dd81400c36e4e2a4999a929d32948d1050b08189b8716550dac7fa8083a39fdf4a9fbd71beb36d0422de15a83de62c1ed7a2f53bad0c00c0de8fa27dee90a0d6cbf6f605a0bf6ac2703efc6c0d07ac2ae72cc66472a372261b0d4160e92b84cb3f3f1d7b32bcac83cfd9d824ae08e01fdeebc0e26f955023a777e0a799921963fd6b27182c7387a14e10aaeeedf581a12a3a4bf6fb2211adfe9a1b56e23921db3dc6e23dffb97f9f66023dcf0bb31ce0612c52b6d5fb266d294b822167a6ef3225e6ccc95326d964c830bdff26a9cf23d1bd26f28fc785178afb50a30efada52a0395906f2dd2fd1f72a8b11d529d2aabffe6f10550a97bc49954518b376440b2aaac3f7a4bf6454a62dea011b5c6e037afc7e9eba6e442b34b55af825f8ee5cfd5955b70d4402b1cbae84bd318620d60dfaff7ad17e097b7fbb9045215814adaa4f8f180abf289bde9aebb74f44d2e70c8854878616c59434f08c1fbf6deefa03b7d9a9956b6319c6235cc916fbe8a65f7fffada456310865b034ad8e350a2b34ecc197f94c7399531d68f820e9a3a54bfeaa8e197849bb422ef73f2faf4f0819977e71d3bd35213b26a2b4772aa9a2c025c89b86790535a9b286421be133a9682b915b916fb5a975f717e36cfd69039321db1fdf46e4bafb6051a91a0397c13a36af2e14fe7eed36102d097573df878605dc91146c1de77ece9f0010f858315abf2ebad6f59bcb8cd3276d53990dd2fc1445886e6b110cee774822a2d9ff74f5f51c03a7f10d913c69aee576ef99cc36aaa5050d40f00dd852c7735a526a80b3340791dbab88fa7aea450dcfbfb6f9d985d307fb36719e9ed06e7aa6e33cd7fbac55f37e9eef44a347860ea1eb9d01f863bd574d046630b2ebd671f052fd6e224a68e4eafb8650e2962e2c9d6d3f331cab01115e3d1c9bafcffa7d45dd691665f2ca5280f2c25ec97ddbeae3fb6d1f3840cba870c0028e49c92e7a99f07c69e0c48c7e77ea8a1cfe58e2cd5ddf21c60225d32f728a7b65bf0bb933881e7b5a27aa6a45963934356de570935cff54381e65e9f58f8ba76403afccd3546585d40db9483e1a69b261fc22c672f9cabf246195f4cce8f8e3b235c99e25a8034c0b32c95e49e6c3b1ea7409027efa1ffdad18361d1249004c3be902287e3842a5c8e3503d80883b2544bfb3f15be26affa51f71457e7cae81754c58f4117e8e9e19992887bc035ac1d5d9a9169a34a1d64337300f2e7239a58d675bfdf89d7d1cf4cec48a4c709f38dd87402b4d233e0d665c530544014cf6fc21aa8d345fcfb250dd3e5e93966c09474c3a2b49906ba7c18787d12e23c979a6068e28be8617100f30f27db61e9788ee6a9d67263bdbc3b914dc0b00658f8e94ac87b7c84d5137e2e97db9c6a2f4c3718d4f4d91ca8b159c2163f74b1ae3b8d9d110594a1e12d96667525a59382a07d2c2532899936da915229329f341fb95276fff84e6ab57e7b70100f0f587c52df49dae56ed3199008b866c93fe578070f6df33ccbcfbd0d82d077f8d04d7704adebe2e900c09b22aaf62a8e5268b278dc8459bea765bcd38723a8d03081d81aa4a707dbf6720a9ffaf4ccdaa112309f3bad280ce0b3f1b732a459d711f580ad4aeafd9469e87a83e34e61ad579dedb72b51f5dc0eb1cef581facec1a6ec556773f4c90866d3179122ef80ed327f0d5d415536265c13b36d893114efd93b3261b7dd28f5447d6662a7776afa79e3f21eae824d48bd37acc70eb41b0f743f52177f538f927fd87142df3f780cdac4a61aa24ab3fe303dd416ce310c501392c5b839d4e75e3b51b6de090cee59d153273699d2f4477c33956cb174c9e8a84523c892ddb8fe5b207e2cf3757f77d199fad536e95160ca03fd2fe939e24e1dd26a80f9a36dc8d38fed6efd05c0cfecd352384678f31544ad599ca1e5329a545e00cad6322b109ae6c7b28e21dab5047f3b792c045b39bd479d18b63c48dc9f479a851f351038aa8b1a8cef395ffd791c9504c769e5634f8323408f5aaf5201ab4c7229734e85d61c35b85fc3c04fbfc44764f070f499027dae217632740edcab24572c88898c8e7a7a0bc60076e1bc09ae95d17b4aac75d332e4b16039994279d9296f836ee1c5cf8bcf5be56c7b55d4d131950f622b14d96f80f11f64cde88737673c591469695d45f450ef04a66b0593ddf1fe60e05a2b4fd4715135415c9246173976527a6ff69724f37145ae02241dc34a6836c4ad8886642a6573b723700f31edb1d12d1ac7ed122bed86233f4f357e4a1f4c4c50802a58212fba6c97e4d08d2a4a5d99d646047f67384d3e2757c546d14e0ed99356cc9adb1436556e8a598970e04f58e4c7dba53fc54e50d47d060dcdbdb3ad2a15a70990da35a7fbc2e6c94d13101f2ad207679753758d846d3c798164a72a8f674b48395976d628d0b05f29c82c464e92aef1d45b77f78c5f8ae704a7d36228395ad5147d8940201e3fc6b08fad7c6e5eceb1646cd43d9438149887345690b9f61d8a1351a0ab737fa9514a1bcb7a4fc3ee0798d783568523c4eb4b28f99c54bd23d59e16a5f68d3888ce3b1879e134be9777f1a63f21810ac90f86a4e61f0d685c9c8a7400f4307e89131d6025aaec4d2c4125c0761f3aa50f5598c99913d8481b24e3dd371fd8ac453b64273a8b329954afab486d1b88555f73ea5b81edd1fcae7f746dcb84feaf651308b025ac510c335a93eb32293ba8056613a45c00200da451d73f60eba53e3032f653c7e5a60a91ea41d4ab9470ef99c675ee678f013957bd41fb375ce159f665fc8d679592f7db6f4ce5cd2adec1d4248f62337497e04d824d2ae2ef47dc39d6880de595efe4077d2f4ad36a87af1f9c197c25dc6b1e43bccfb5db4f94fefb10b2207bbd5b51b455a447a61d17c82b7f8fb4948de6596514d8805fcae5897376a928c8aacad6d29b3cd75fadcfa6387c629090fbb9ff6737cde6719cb9e14e46f4761beb9e2c1bf25594f801aea5839de6307083e295056336b6e0e55a519e5fb478c89bc8866a3f29f3246eedbc8d267c9e392c9d43f0ac54afd652c5067cd89e40dec98852e7ecc0ade711e6c158cfed0e22523919a2d798eca46d6c26b814d57ee1e856979656f8b4577647b65aa247813e0d3d7928669275a7b1c07ae659fadb928f443409c4617727cc0c57d2c0ee6bec2a753a392a9ac5215af30424726e8294cd50f18f022e7d4128925256fddd4560259f2af9f63840b6756800a606f57e49980378afc31ce4452184519ba778472634b7a7c9619555df27b1e2fe22a63ac890e17c83baad6df42e1bac6c4488b4f15caae6ab9ca5bc55a09dc45378ab60ec6a19cf1f647a3a77e5aed1ca492df7faa4a2d3eed9789a941ccc66bb8e349309c17a133cbe7de5d414bc5c778042b33027aa657881138459284b5a49976c0c0da9caf8d58732c73af98641f13b8a83df97668dcd0f675b6a01e97f58f44339d9ca974b39275855991f5605d2f7ada2f68d1e0c5ea475b7811cce869b8f6825b7647a366e72cf892732cd807cc7acf3a11ea04754a729a40bb7778a755e23fe24589ecea7c329f59546d824c59ace9b8bcadb761d14e1bf1495866bb0d524616904ec2196175f8e577065a3223657baf0b691e7073b5dc60a4c79b039bdedda83d027080959221c6ca08269a2df96a317adb02b97655a557e522cc656fa608afb5112a4506cea613937e72df7797f6b34027a5a8dd5a0e2223fa329cf2a67a191f156a2d024a6d3ba95e7565e17dbb78f2f1dd33a076f06d0da4f77cd2f59a084a10bdffbbf826476624c5db8da2b20c6ea73d0ac067c5386a6d68f55b0e2030f2906d753f966b39f4f1cea42cd67612eefdac8e55dc58320497e586bfcaf320a7da5fe875cdcf0dc44933ffe08e30527ad8d703cbc36b368cc065152f5d8de8d775abcbfb375a8ea564eb01a5856a983958d8aa8d5b3369174c33462b4279c7399c71e56b647298b9278769952f715272a0f731fd94ee1b0f6dd4ca2b42daa3565fb58a76ee3a2db0b9b53f27c5680dcd71122ad415d7925ddf540f8daa28a48781d76d9b2db800bef1a632509f344117a4a7aa7acf1ca68982ed6080ab312e1c763060c8939ba26dd0b61b1abd1dc9a241bfa4c3dbc3251502be3a379f29b3162b710ca399cbebff721c514b5e8ed284131fc43133c51fa3d74fc97d4dd4bd6f3bb3000a79531643ea85c8ee869b7c401da8a34217909069d39473cae8b90623a5a169bfb534513a11c26becb9b3ce41c00232dfe272b392f28bbcbd469766414b5a2583de4e2978a1424d8d93db29d21c5a403a8423fc03ec7849f22c1e9138176ee5108e510f315103ac4e6ca54733dc6a83eb638e5e9a7080db614991c8fa28f259ccb59c6b4d439c0247506fa507e24f9229b4f24bd742a7fdcf4c56af87e59c4b69641b7b5517c601a2c76a2a4fa60b837a5857cc6edff22541c6ede7d71fc18cdd5be9b1b539cd89d9c54a388c1ecf602293ac8e55396cc1e6349af09fdb6d820016e4e5c946d7fb1174206d33647a562833e3c705d4d7ea3eaf3d83deb30576328e4672752191e8a98ff02b4f5d065688a24a49173a616cc6beebddefbac35e460b869b1727de362e43b9450c3daa14083c159df62bca100d50316030877a5d08343eaf37fd8b3763f8a9d35658fe9ed199e39be87bd3d9fb3768386c96a8e487a4d2e46980a696f6449f8eeaafa6a448a603ca78716e109e5b7a4945aacce67caf42178833f2657ed1e170bd08d15be8a1bbd816c8874e78499f27e761189c03eba654989041b4bde1afdabcee87d7700b47ec96a79627c4bb9053e191d08b83033548e985ae7565e885e3b387afcc1dc48fb4e7d3b0cd510bdc8d267edff6b9e9f104d9a5ca427b80c6e3238a1572238619121b6b6a2d4db46733452d4454a8a7c92e586379a19a2d91548adc1647aea580cfff3eb9ff1ee99cc25cdf665cf985b6ed4286db5b50a8df7a2dc1a55fd2ab17e8c10133eed281feaa5d1ccd5db18cba1c2aa48360563cbc4b1a1cf597d34c5f42dc3d86ea4bb337ca095622026bc99d1b9eab2cd71e7dbdf4eeb04f008ddedde7c27e33b6b5b283870261b1ee2a8cf051f4113207c0f7699f38c0ed69f8710821bf812cbd87c3eaaae04d944a2df8ada0daaa472bffcaddb0bb98d93df88eb2bfe9f1a84564c24c8bd44c1563e166046abce5af722a64e1dfda2faa48f027ad7bba2359dc034790a621b8855d8de466f01991c0a308f9620f7827fffa36786963cb28fe7c73110e4658e403ccb18b1452a9a836ff51591aeb0b69f709552ec7fe92a8fc828474b72dad5b0a91d09690bae1608a34bb730894e96701d1c12cefd7389d386dff22a0c1f5b2a5fd8bd62efa02efb7c290f4a2bc34c02151ef8068239899cc7cd064922d095036f35051c90f0bcda01305fab0e84b3c4f9fd8cd84e52503ebbd66637ea3af48aeec7ea298ea2aa3c347f763689185e27d4889d71542da65ac4dda7fa6e54de00a3a3f267d8d62695301c5de00e79fbefff9409b225d19a0e18a83ebfdcaf818911d85b383ec52f8d5c9a874bdad29b2fafac449e07e19f812a1ce5f581dcb4bb645e1f7742f9dc30e0a9d070ee80d93702c9d86b46e19e96aaae25238fd3ae8a21a7796e01c7edffe37842e093150fe623a5a95042ec85f21933cf7acd29f9905e712aca535598b3b7edbb70cff23d732ddcb27a4cc47b1818264db7e3810ee39f2fb1f42e0dd2022cfc63c7d6eeb308f84784f018268b8f2a45d3e6219b440fd5e8c6f7baad9dafdb6586ff4d5c3aeeafca25c762467367c139ae0b0fa371e0ed7f2e33e4fed9870814c33439680f5f41f03125610e4f521a517a77b10cda7c1dbabbd56a517c25d83f6e273fe0432cc66dfc89c2e0520ed8b646f6d7c03a5b21daf76c06a5862ee5aef2874a2165d6762e8526eff5ffb54f7e1057aad873544fe5d7b5355684d2a3fc56363e04a5ac871932dbe84ed31802c8af55836e17e0a6e017335105d7fb8c29606bd7a3a84dfbc95e8386b3b4c558c7981154ba686edcddf0772aeaec2f8563bf5bc9c13a73b696426d214f83429ebf165ece41e1ecd6c2e0dcc5e6d399e9f20772bccd5f27a91b8bde688438d718f2bb7dff221717d795f0a0636dd118f0941af502c7ec5487258170ea4c75aa454f10c3e26b6982069e65640fec2f552a4aa2de456a7cefed4ff3c22182c903c53b098f02ce780d27de5dac5d17f7bd002b7c77794840f97f14005884c57c6ff0a61b5bfffb72de74ed375836e48e71c109bee34c9bea6717c6419ecfa44cfe9d24fbb6331c059d1ca4610addbc68077fec4c592b69ac06e1cf669487a98e4028907a90e003772ecb4ec407244adcd66547504a4881a60d87dccb34049e4bf6d2e85e26652f187aae5bee7d9ad5dc9812c5b77676d881858d2b7dc5b0c8a9917f534d32dbbc5efafd520826bff92229ee913c14e8e3e0bc0612ad342c3e772d1a8ecc0c03d99cc429247a09a2fc910e489a1b613b0cd730c1fe288c30870e9ec85fa800b60951665182f44004cc51af00de43adaf8a2538f412a2abb281939cc08d0588e3d4c37eb8df94c313fadbf3e0c4edc163dce89f71c3ccf096171023f2e7b43c3879a21eb78b76be3d77bcadef79b91dcf6df3b9e29cc03f5439545d1cf3946c38699b87bc7fbfadfb0ede71aea5b70784736c444620875bb35df8483d054419a796dd0d4a37fddd8df247bf224c4f5a8646bc4699e5ff4efdaaaa9cec7cd505063c67a83f7ae5e8c9812cdf88194f7c439656ec684b8563312d212e6f5b4daf11e7e758459cf3372aa703f5538903ef81ba73f191672764624d0e3efb75b8dae33ffda093bd8cccc68a902994366a0a3488b68b73e30e5fcc54b82ba91dfa9ee2a995dfef8fbeb58f201e050c55d90659f673e149c0d52b100ed9ac7056c8f05206b2ab718062b79eb6fb81d235577bdf995f295e73708e1a1687024110a58bfa5e5448eb22ba2c06380cda7b36b98a150bd931c98db8955953643f071de292ed03b0c448bfd6697022bfefe00ea15a43f01b9062909a2111c8c1db04f39f246a2b65013ffc09c1971e51a02b3747d8e12966dc041b49093df79ba3d63b656eb3b5cb8522c5ec1899c4274ff538a3dbc190d7bd286fb2b3d00c2dbb4bf48fe65db1cf70111e7e44e06d212001c86444ea7ff2ed5fa49ef50d0339db06a8db23c79141081b4f3dcdb62aee407f7af9a14063bc1da7b7bf228e5c39a8898864d37de7e3c51623259d2e7bc1d1f86b1cc27771f2704602cc09d297fe3c8dbd056dd9ccb5da1ec19c82d67664e49b4c246d2f59d079031993ce236d6267257571942572d5abf1b5e7c64d790fde56dcfda4405b5510bdee11ec748a088e025f10db495575857f1fcfc17b61de473eb4478c767864ad0b896f114e0d83d04d991f5742afaef6448b7cb60b3f77f51bd1992f19c13c187138d582ad652280a59c6ce8485b0c03a7587ad7497d657be83868059ec05ebbf54d01486f9409f70b92ba3142836b0f2ace6d04b1385823322f71c07b8ac21c821afcad21ea92053301835808d423041c3d85a6f875cc7d0460b8e071e99de7b98c2b12521e097acf77aa863352fa77577c59e4e7f977ae8c1528c2d41b518e9f6ba7b959d1365aae4831232857163c21b13c26a27653c27cb93bc6d94bca4d480634798b7296e99a8f8c41294af92327ae45a8447f9fc3d2dc9421943ccc27c5820cc91da334d63c11245e4d6f8781e9dda6b014a0fd85b53508da9d6b0aded48354680b160e66391a4c1b1fb6f9a2625c2601673c12da9000e97b0e554d4b98cc9dbd2c88b8f025d628a995f4ddd83860599018521650e0f957e425dba35248181c4c702b8665fd8a5adafeb2509bb0a8b5173181914872f3ab8d578621d3befeb445df1966b61ee30fbf56f77e2fcf4d4202abf5b65a00770d02ef43a298233c09ba7b0fdeed7e8282cdbce6a8e63e4bd05a5e15a7237677c4a1accf08639f7662fa102932dc9aba6fbf054a5c58a0938ad2ecb2599186c0729e8d09e8a4b434742013c6d3b5a04fe12b6db36f74a6f7f05ceb56d0f914343e35953c5599f0d3442d18412608af8b967a9bb434f696c5dca01e101eb412a7e042e5e4a831ab54fa9dff2066ccd639edaf66a4703ed46db9a3148e1d334eb8dc25f774ad273bb75acc18264802c1f25ac6347273c4636315a99ac9375476bfdd77b5cdf27dae97a36ea74e689e80d20ce7fcdd0cc1131e89e6f87642e3992dbacb0bba3e22c133fc098de3bd99f520e663b03d43fdde747f44238c4b5275c9d6fc2d5ae767cbffcd10cd0a6ef3f77dedfc9b79e42395b8d6cc6c1a00d35b591d77f2cc51f4e8c714c30e9e8fd9e7d1d39f0064b3b80f69984a7cd12a36b25e4149985c6659566f2b154a0bb074328b1e1c81c3a68f45c289c0816de841c9a7c51fc2420994a596c3ee1b521249a2f7c0e47d72bfe2e762cbead03401eebcae08a0548a78026da6c6fdda99a827d8483459e6d4489bbedc2e4f7fe403f45c8344db681b77fbc55f7692666768b359967a718dbd74869359fdc1fe73e9dfeaeb2975e24a9fdf4de52b9d7a7ed2963d8cdec941b9d3997e59d5e525289b892fb571b755588aab2cbdaa55bee90604141af4a3a84f64c4c5a07012b42937e50a053f35a04e54b10757c5564739337f7f982ad400396973688bc738175ef86def092991860994c358efd20ef5328d2eab0607e6e6354a439ca1e9accbaa72bf31a467e346a04e4fa45815e20345acce4e68794d85434e658599eb12f15d1cbcccb4130368cd3a3329379321d86e1b2a6307368f6829bd0d9ccb697b40609f86829fa6de57257bad5b94d55aa74f33685974efd7e0b9288b3d0d66e6bb7db62d8b3c416b1cda8e9bfbe32527d1b3239ed4ff9c6d504b004a4878faca42f360c8ff01ee669c63f3b22eb91cc471d4f6fd97978c9d8504f9106fce26fcaf9fd1cd068b73a1d1c12f232ba7ce51f325336ce30a056693bedb9edf3c768808ea16c88afdd655fba84e2a3a8c15cc6d887d56a658a7b4a6155a4627661225c23be1d93d6293124517e2ffdd772e8418ac6abb0af7212e853e9802a011130bf33c829ea32ee15bfab25a20c28a141fe64786f4d09ab99c2909b92099dd746fc09e927b3af5e92f201847777f40953e975b4a8a82fc5491ded38871160828798fefac5ab3da83cdfd1601c13d55400ac885ffa852745d3e72190dbe9285eaa9891a7299f0e6dd4d94627bde776fbf805e3fd58f02e2712264ef7cf0a215f052e620f5aac294666b137277da91f3f6bfc91d7374f5e92dc82a6ba7b562c435684bd66ee5c1567903cb7ef4d03a40d3d764be0a6e5c9e06b3feda80ce3d11d14a09af451f2818002681157e0ac00c8884affc00f3317957b7acf10a50da3ee3f95070fb85e8b1caa01469187e20a6460b05f2e1a55b8a34bad8d641da2f9e51051aad3d896602653d4fa13e8f1bda0a6fdd2facd3d575e449b1be965d96f9cd440c83a1b978773453fb21803b219e64ca9100a41d443780867168a54ee919dfa34a2029ce85a220f2617a68fe29cc6a4dcaf997dea35c4d490d100ea26b134673baa821995e0cbca359c89287a5b88bf931df0ae377f54550e278974a5ebb8d0fc5a1487192fba05da4979fd651f301d5a8ae6122b050d1401ed5ed5f44760a9efbbf099184b26092e8f29a58c3115850096e4569879683b8a802c026175a0648252eca6ad3b6063442cb47285470fa497595ec62cbe88ff735d8c7ee135da2ca2e8e38051a93af3172917fdac726265fbd6a9cd6e8c5fc6100119bb6ed7e2627d43044583836cbfe1c616ff55bd38526186ed96cc6bba0cab3fb26d583b55415c067740c0ace871724ff8eb027a81ee09221435d70671432e5b72829d18d31317725e584654c6e1d1b652f94f46a67200a7155d2e990df1d60906a617bd99b66568984af4af0989b7002d0925d7399f2355a86c48f384921e9e3b31df1004278e5455707088acb765a9ec0b8d36414c61438df6b1ba3babc84aa1303039360b78858e877b41fe49e6e788b7e396e73edc1df165b53c826a2e6b0848d37e8e805502a21eb10a025319a8e10def85e2a9b34e511db3c6eabe9d521e086b40a4a8dc976af22a23d26b91538b012874aef63719819dc861be0df312c89ff3f2bb1de14de693708b3cbe650a8747469cc36bc915b5c82cf2173583cb3633146d30451ba6dc954f3d2bdb1d2ef722d51801209de34414a57a197f7f00b3cf363525df3f07e385d04982e36ab36ccde4f8a85ad016a69491ccc7a747c1f4a8a0dbac0ede591b36d014844109ddf7f19017fbc3ed44e02d73cd167543058918c822fdcd670c27d8f57ec8c31ac3a30426bea304679d0415df67a14c3604537d869e43caf7d13ea2d1bfe6a0f0d118fc5c93baf92e188186f4c5792800394901fa80361d1283134bbc033187aed82e80b7235021b0464b72cbeafc2916823d24efcbd26af688e9eedda5a70d9a0bef8be48250dd64f6d835b9b6e250d2b25995a576db37ffb9d117733e233b1a7b6e39f8b5b20a389629859ac5d500ae9cbe36c4fc8dbeb3e68bbc9df9f6c943bc012fd595bf2dec21e7a57f366914b12e34ce8b8900808b2e1fddfff1fb9aa5325c131400fa29a5a2a300d040e854249e5d20211defd5f91876eda7ae6e5e9ba44f702690ef79b139915752e02c0e253f3855ba2974139abca0b33767644a62097d7e83a51dc46dc06725feec6ec3b38736b1ab15a401ba49afd510cd05b9a1e0fbebd4f0a4056e5c756405b4e9932c5ca4d21138de9902673aa7347f97581bc703e889e3a4baf44d7058e54b2dbeaccf3a7629b164fcda120fc45d7c0cf9b1ca2ff1a7b376f59f0dc8c65e214920e87cf20e1de447d3bac39cb7be2ddfc76ddb865d8f0e5f2a6cc24a8f75a79da19387390b4c890247bf9e0b283ac4aaf4cf9e8dc2c92e24211a018c97914862d3e59908becc9ed2547cacbd5934cc04d5f8644bce7d356d80776494c74b90649dfc31c0b3d903114a04b4dec64f732d82cc9cf993c7ae8a0fd29ef3dac4ca37b0b1723f7da262a3a447a67374520f53874bea63129ac56867166dc78cde48357e79dd5366d8366c8ac45213d285b06ef63d17abdc0d2cbfbd7fdc3e6a92bf1e68ac3d1e254826b9775ad1e5d2ed179f6c9dbf8190d294fb56fef24da21ab1e5866b7ace4627ec9154123de02cc4adcb261c97cb86acf5ad680f3018bd67b741217b8af8b07875f6574d757d08fcbcff6ce598ccca09f8ecfebdda97b2ab8ee0047bad66ce4475b7d2c2ea924c191c8033b75f0fc8ea8896ccb18e7b74b2eaa05a2178d3e62faa2a6de663ce6c01ed2ce33b2c012a1407e206018b9e2cc4d0795fcd3ab733a8ed96b87b2d1974a5e456585c2ffa5c935155bfa1c71e4ef9e529a962d8b416371b85d3cdbe285355fbadf15f4adeaea0016f4c3241cfc1ccd7fecf6bde21e256ee266ecb4fb02d8dc2edcbfead0ebd6937258fd1e37da8a30049d845ead3728b48515841d930430c36e9b0f00767252001e49767d2af04c88e36d2468661d5f44717c196f87a92a472d05405ce59bd7dcf4d8fc8f683f164ac9cd345f3c6ee4a6c3548b36b4e70a076bf3ce2f07c479aef00aef2b8d9abc346c62de892a71d022af256096439b1b88e096885d957fbaee5b908d6a4fb41dd2279c46bcb8e0e485c0386ce86c22f0c31bee11e8e9a14c48bb796f9082c3976e05f63c931d3473c9db935af7d3eb524d2df497485244ca85436edc8d7aa415401175552ed58fede9658380f5af9c5a78f08ce72ba8a992cffbab84632ee6bd698bb58a48e55d1f9f4901ce58b536a3bab1ec26c753c17c79d0c4bae2253e0803dc0e18d2b284f040976a83fa769803e0f1dd606299aa430c9f8ed576bb27f097833fa28654f03771358a7f47b74f5d57a57599a291da69be1cdeee30833f894291ad5b682dcfc7462e09427d31ae68479e589cea54a3866d5b42367350293fe18a6d85dabdabaf8c9ab4da0c7431db34d5836824f1ee74f5016ddbc23cb4946a0df35594887e014c78e44a3f2bbbff25d1964fc6d6cc5fbb558ad2a7f2153667f2be1a55e921ecdddd714ebc6b230f88e6e6f907d00c085cb96b5406794f53ba98b01c9932485731d0118c1cbfdbe73fd6f9b3cfab5d6d5d9c7e4101c5fd2ad47f8d6d913b0517e53fe6232f0184db83f017849b4ba251169c69bb7c2817ea67779db9349124484d4d5e228d5041f218985efca625d8cdcf1af178b6d93ac54b3bc47c1949afe718472ecdac5c09e377b1aa1a2056bff81539eaf22efc9766792beac5bbaa3ef96ec408828ee83e768c7e06f6c8850d6a6a05551e9c8a226f8fdb72e2a9d63cd89571a549c3262a402e736e5c11cfdc366a42a2db6cac53be486d0e0b1e71321091f2f34c8a49ec9c3217fdad8a06b321099fbe422316c8164885c016064ed2ee1ad7a00c7974d2089cd348599d59b4f46a7f21410acd832a77fdd1f743451ef34be2d2d28d5a51569e5dffb1423cb87a744dc50dc3712d6a5cb6f80efad7277d5e2e75f56fb0d4c41e82b0bb303d7dc6e4634038ee04a06422c0b857ff83127f151c40eb25768e30757d7322f8ebc7188a1118517e590c5415c3afb289ae4e83dd56f2ee03073bff1b73fcc3bfdddd2a7406d8fa5dae23029b8461c15c917658c841a5cf53a8eef8d3c2302fef5b0da08ff8424f1c46f9387db61c1c676afc8e3e5568fa9873f861ef3f447bce1d6f1ddf4942acd71d8f523884cc3123b2394f55cdb3fed86d8ed110c3689ae0fbb6c3d219e5b303123fb93e719583cf790653cbcbbf0fdfe35bbaf8b8dbf14d07f30dffac0562baec90f924b9274f3a3fe336bff76ee02b1514e15058b008f3cd375033fd26174f290bbd08a5ddec426d6df5c8819cc8dfb613ba329b9181b62e4e1d3622a6057cb180fdcb8613ede2907ce41a5b50cfa6ca8814813977ae38927cd3fd857a60882c462ec31f47e4e7b9a24a8cd3f6da1a33fa0a1a041bef8876973d84d6b74320e1235a8bbe5e1003ffac2430a2973240fa785c0c636512309f910c9d09c53306656619dd414c74410d3b0189e3f604e38e6a9d00c0165381d1f28c190226f9aa6345dbc0a85c70f80b3f7ec4c85c3f887cffef2b914aec3b7aaf4d0cc345919666f5ab45dde7d583dbd25b1866630351e7088b5ee9db160566a911fe8bcb942835e460893d93607ffc060ffff2a9dfc7a2293760adeef0c0d802712de278b0103a8bc06ad169ad61a9df47da074514d6f40d6af9f1588f5bf180e315e1229c555a984a9ca7bc5523cf9b1af78163822a9e5ff489fddd4b0183a0ad412d4dfb7e40d3de2e1102995adb0369869900bc065c57e0d490df769e0d3fadaf76e343eba5dc1ca9744a7a90e2372233c1422ed770837fe851ba6b0a735e0978ec73f8096ad004b061759599927c4b0b8115a1fe046017b3996e8da58aed7084044204e2467aa44abc44b7632bf5e1ae9e1f587fd40a1bdfddc5932ea79e01da57007c709327c82c4e8b3614bc537b203cf1518ba7a41b7dbb6c11e81ce515848d0966d66942196ffd6e3b7ca2d713dbf33c7f05a5e366f27ac0be9abae1865b6431180e5163ff37f8011c78168afafecc07426bf23245c5f4ed90346b3509e21f90d4db30a2d9ca2a578bded41ce804dc3911d576c9351f80a0f04c8e3e292483324af34d063781183e68cc9d8b5d7ecd90bffdb89e01d9b867f71327d37a857ad65c4f13c190446a178c9e6d7df4059ac058a870337d7f58ff1574f0d3ec4cf979c795076686f6591c64778c666b47938d6e348b6a218a47cd0f22b4dea1c90c5172e4de32f76417107b662aa7f243cdb0fa6ddd2454a1d422a1e7db839e78ceb36bd249d31ecccd6572bdcb6626157571f6504719ecf7714917978f854ac88cf77bd1afd0c944116c3b5ca5f40b7dc49f66322770e0f3a4a0f749ea7b9905fb994637b1ec34caac1d3a196f8f1d9ac0ee1d5dac0521546dad6370a8c25ac01f9e8df233d3841de1c58ca97830f8db38cfaed75e3fb3b6808a2f1b930ebbe767b8e6be3b2178a759e135e96dbf6865c78c0928fc561e300d42cbdd5c272aa4326c0b5bb049e61cb47926dce3deb770b0a803db6120eedefb0e366dde278a3c6fb12688485642838c9531a5c4af532c947d333ec21098c6362ed59b9d2dce778923b9f05f383640a3f94213c3c9ef9afd5ecfab545816796026f5e201ca03bd1c38a7fe32613e8ce2ad35024adf680fd44f273fb2d5a6fa384d727eb9ad8168e5987fd23e3024762916c21fa6c6f907abdeee482b3d82911b8b010125d2e0b8a723328bc339e365ac28fb236d27e9f1a4b176676852048910aedf56ba64fd9175207fede8ce3c86574fa8ce13a070435d9d7dcb95e0e51a73e9adc431c45e810f16e91c830bcde39349ee74fa02c9eb870b372e78735aace07e6a8a23b07715eaae6350dc71086e8a56e694a126865fe0a0873147d52c4f831619782b588a0c48d937f1507b4dcefaecb227de32a071a945ea6fcd749bf4bd8c6161b39d4f5d3c24382bf1f0e3706705322da4e14f982ec3b44722cb3e05ea24b1d2ea5d8662330633946b382dd28910c102c3d26deb7e30f337746440339022431b84ddf0a13d4c70bbe732bc626c388033193b34dc353d47ee0bc6850866a9d66c6129310999851cea220adf475b7fcf939afe577f45c82559c74fd8ec933a65f99e1253c083c208c3d0a5b9ad1fded6a94774d65cc31d98a7d380f5e15a1c472c6c7900063a1d2ab5e56193aea881b1b67d10775870b7ffb6074d605858c4ec933edbd8516fe5569c9ce773530160a9e75f18df0d062a5a8f3cf648acb361f57f04623c6740a95a6c74f99ab11fdad6002747437d0ce76984dbf7aa81d72fed06c00cf2a85e1ee23048fad2bbce5f19b68024be0eec2284769c2882a3a88f42b5c3f40732a89b5b7548d012c54933f214a258babc36215dcb4deb9a5bacf6e93770864f1b0f62a32d1f82659979a870012cf5656020ad8bf6f5321b3e9df1a5b11dca3e57d36b9b7eaddd917c28f5e7b4f20cdfda45f89b22b12afb747810cc7451334dd02d0e32dc738936690453fea9cad43d6282d48d0f0a8f7b6d0610028515cd31ffc22a4374a62ce08aac5bd126e03dab2d523bb30ba24d72e2ccd46be90ec3dd8a18657ffa41a987b4ea72bc549c934ab04ea51fa01ba6b3c8df40fc1f1721e663984805b4a14be530b0a7ef4d43356d6338ef653386b7ce502b06b6d272ec59301ed5cce4379b3c63247a602bb4b99a3cfe68e8e59c363f812a241d79c2e3ee2889b82f1617fd082d51414273598b28dd078c045db5893f5c974431ba172d6d9e75e7517e09448669fc6ffb7a4887149e8fa0ece7d7816bf7d83a020fcbd2220f6c0e99b1af5bb5c8686abc21526b1495a34911c2746f0b685128a00b17888d4ccf71bfbd0fdbd50a0ba67d62b5f6a602791269675b66b4b2920e5845108b0455a481a412016ec518a41343eade25567623e3f599acb094554c56d9bb22d889141b52d0d4ee48f26e064ae4b6c5d4de036f42ed81c6700bb9db7e155e6b0b6b5596925fddd77cf63bfc8fca91d6e0afbeedfab485e0853b359d491d7961283842b0556456a578ebd42f9f38b90858521b70c1a548fd1f10546f3b6dc0e1d006416f0f420a2803222e4547786d7171b1a1029729162d57ea68db55eb405577f5ffb95680e271306a9f65c739966cc1367a1ca0b7495cea23271ff9681860730575d7d14c471c088755363ad5350ee1dc9b645577dc727ce60a470175841bdbae668140086aa544c1dfb15e8afc1980a68ad28ba53c95e47ea6dc3247acaf4e8cd375c9f4599b3b11f38a6eb7fe7dceb7a44972184a976046ef6338d0007ef19d95a2154fd9da87fb627bf6775210ce327274383101d6bd3828da7d26cd99b23a1b3cbfe880686ef5a5ae0da119bdcd85cc7c40554760eb941a3435379b2c84cec98e8cd4049a5da5c5167b08763afd66eaf09c5266040ea776527a5a32380f3b992667439ec65bd3e86505a3e6db163f6cb67aa89689621158f67d52c230c8f8f60c50163262abaf6c9f38f8dc21502b5bba1494311ab4f2943a81f7d72aa197e445286dad102c872c2ef4d1b208c919728defed3edd965824bf0e037bb97606e620b3cf67d817ec722cb148dd1b0254b7e4e543a4f4360547dfff1a8036ba8f4760cdb6b5ad18d08faf931d605645859830e6c2a7d874dce97e2d2a12003453a449c50c1acf01abdf25850ccaf7d519e7b1ca688bcbab73aa3df2c771ec61d10d2954f599bcf82ea92817f00b41e27d189a3776c03e7261af23b6ae467d4ee2a0d9157b6fc631639af9cd3fa7499faa807d791a67bf39c3b9f32b1cd53dd52f5497752c72926e347908f7de02072d7e00b92a519ecb7f132b6b523c0a348259277e11a40537a30103aca73b246b55b7455ebd08fc438f5be39e89d7c1e6cbd0a5cc0716bad5e31f46e84f52fa1d3a0ffae15c005843ad9e022cbbedb190f87ba74286fb9253a1a285ae9920931d7c27f432332a83023d84912b1b98faca340a47d2d0ed77c37f4c6b98a3b5868727c4825e38581cbd52ad51d7cf1d73d4b003aa2e55fc106463846eb6e6b44a0f96e6e8be368a60539831f5797954ddace6048aaccf2b8f22f57dff598a275bc636862eeb2e4572c72e6f343c55e806ecc3e27fe91ccf39b9bcf7046fb6794a2f091ff69ce11618a6719755b19a1beb82e4ea5c3d604ea3e6122f6639ee3dd94ac93231dd4ab87145540e4b18c0e109ff47a51f2feda64378c1855b94e7474cf1134466c122bc0d0f7386fe700a97c8e6bab4658e2b20dec407a6f7f2e421a0f4c1adb6f2b2f58e33510fb70bb329cb1e5982ac67ec4c3508ef30bd9ca5393c5d9c98f850dbf8b5daee875a1d50a2a79b806aad7d3c45c7cc506b31abc39e68472d4e3d841f825ca33a09d2231c678e43f0b3a376e19a5e6551ed762c216eff5170bf941319ccf7b506ff5d3c5646eb0b6e81a7d2599be15912684ee6dde1a9e37072c042b8c1711c1798cd9e3bbf6370303eb4e11224f469751690d1c2d2dd90263d8d617dad6d84c14bcb365a67d144b08073d0b49e3de954b16281845e660151f0098daf924c197bedceec13ff1579f898db3b4af8c1abb636a975cb6057231fcc8e8e957e9910a5c7f132529ed73e025cdf71548eb9cd311b7cc546e2dde48111b30cbe50ee6b71574d9e0b7119362df2add9ce54866a40517a47ad97a0af4df4791f8d182d3ac54c9b3de9506f9d67a64a93c4b95dd33a21c7fbd42b5bd45e2f7fdef442bf3a9e6e5dbc6c6eb30d3a074075314758760aa5983fa1f62477c10253fab423ddc8e23120dfc415e046ba471eb11df9f1a6c7dc9dffc7896850113c1c7339700a76765a1051f1193a3ec2b57d43ebd79c9f59315e99cca143cfb4752900007329eb14245f6f3f0373511eb7f9d587d938af154d3bb7f1be8b97307bef04b5b0869a425feabbd0c35834f6e236f95ea08ab94470865e28608b0aacbb5d60a82bc7801c4d134e04025bdf5d8192480ad5047130dee2f7c5e81ad8c96ec0c0d25589f325499390b7bbc90d45be262a100649ba9d11eb485d3cd5c13af704e4bbbf8a1232cd58de06fb25bff04cc39a9a37063da18df5072be92b990a44584cc115583bc588e34e4b18120a91d6e9aab2518132a5b4d6403aedbef14c93e87908d34297e8b8974740e5a89594d29f45cf07ca76c4c9347ec1c62c484fc2a1d53737284e8074a5c5c9a9df5d37885d2f4f4fec26acab52044a07cb60b4f237379b159acb2426ebff628fdeb3b4baa98059cb592994e35dc2e3a1814d931427999a5272a0743bba5bc18978fc7be89011ff17e7b8ee57417c91739eadd39afacf3f64684f2b18227f3599cf03bdd71435860cf587dde6dbd8cfb86715cd26b279e5b3b45ec74c6bc7fb011c26ba7ee9ffa7ea5cb0f024a6ad33ee2b17f0e2d150fc6849ce89c564fc4166735cad41544cede45149ab6e2a1d1f34ad0c7b0ff13d84ec059d8958c12c136aac19c8c9e05563e34e7c00387aa9a6e14a4ebe5fdf7d68015615d2bd0bb26173b6f7d7ac00b6b1f87e6048e0fc33346513be55714da599f54c419dcb6e2d50c8a9be0b4f973bc9671c1356ef4f61f7902c16bd744ac0131e155c2fd8c9d5d42d960411b3ba52ff1ec0206dd8367659ff682138c2210fb385829708c4aecf745472c5f7dc1b6ad2b7cf318d54a602c89a1d57f5088efdad637356e9474c7096a50bc626755f94a3ac0dfe5eb8fdaff48b1aabe725746f8ec86e0473d1316eb393f3896a3bb83f7ddc22bdbf8dc19a55ccfd1c8a68a829a789f9500db1c9d7fa4bd0977d5264a711ebeb6f886c6d567d1c6ec520c4f7c9fe2770bf157eb41b468bdb8306c6ae7e79e110b063cd7eede3afad28245143cc0c86e0b35391e1544efdb0619c50a6b9fb6e3fac2ce88fd7e09399b86b440904479c83462324b6c137ced709635df1de433f55ff41958eec33b18c0dad74268ca8d26164e986e94722118b3a47db82dbfb7a0eb07994f60edd8ff8b56af1bd2cffd336dab0b241a75327944a740edd383e5497ff7d398c69dc4891dafa4152ede8d9bed3c067f945b42d6c5767ddc3db51f06d6faa918ea610ecb7734d08a261fa350c9a31f7d2c3f5072c51686e7592d502eb0b441f2ca121d7518fc448c97c4eb9ed1f6f7ae999fd81f6a199a740a30790f8c31f745afac0ddc93e2e67d409e998faa9c65ad83746e6a3373f200e31a0bc224152a1d0fd513a4c1fe2fd5e4850abf502c6671a8e4807bcdcab6c0fc469cb5881c4fb2df74c7202c5246808bf9c98e3c450ea478d096a9ceba1600c2f55fde591bfcd82902fb33409fcde1d7312d0c3a66dacd2f3971fa2b99ae3181cac3b270fc5e281b9e333bb1e1a125f158028ec1c6dbad7ec7492490aeeb775c7d4ecc1d534772299064451aa4767d62dbb2b569fe87c5d5a8cb2fba88d46305205a71099418336fcc7263374a9934a3b3fcf16a832bdb30b3dde1fe3091e022ceb44db452fd74b1306bed8e38b869ef440a6c998cb87cf21b4d8995a26d9811648f8811cdaf85cd2cd87cea8185146aa3bce2ef87a53bdfd5c33877e37ba6d837d81e019ea5f2c0c074c7bc15c72990078ccfc9b2dec6855701b8cebab70e85077a179c99f3b47685192b8f1ac46808bd3db00af6ff1c44d6bbccf77b2128c20b8f70ab2185375962d7278370d12c3df8af84007e8d1e78b5694087217c99f3771c3da9b073ce848b23f21a73ed85ad4c586b8a2f9ddeeb106cb36d930356547b4a72c09c29c80fde5cdc3b32f63152a1d339d29b78fb6d1ce4102f0f8bb0e95162951cc86f74b013daab4918c8b4a916b088a4556ba6508d8a9672b41442746426e05a0b9266706d20febb8207d2d51b9e9688e1bf0b8f386047d0cb93268b0295b815dfccf4712a4d6c620d2a9aefd23a5133442073d5ee2fe49157a7d42a87199c0f10382ed9844cf59367f467d276dec9435b88c18c121f9570442857c3985319db88e2dde5f6fe7faaf250ebffc60b74dd941ea2b5e7767bfcd5ae6faed59d473dadf5012e327349ae1386ccb16992000c2701cc82849128215100fc8bbdeead85f6e3f53356bf6eceae73e576ba595707714ce96436fe0676a499926085a28a639f728c10d9012974784f8ad229ee3e824291842da2aed1cb49eb5f3b6d07b49de405ae2afbca02be583c3e4169faf255e86a1da3841cd2b163fe4bf1c4eb574ebe2c87f4e53e6b42ea587d8e1d14251174a97fef8b1b87733562cb18ab6d5e9257c0ea6292e020105b334c061c448ecae8b38f520a6a969d5591cb208700f8f90de3e5fbd1caa0593cf22f2c1ff1eeddc6e89dad6820ae1a80888954050449f7db2e87c2871cd7c6e78b56af7f64e0563ef1650ae59baf5d141b67a8f26c24a36e24ad4c1615eb5fee302a9803a172f465c450cec83354a8612b578b3838bf75f01026014257b03f40d9b01dcf515bc47d2195390728bf4a4917acc5b0b20fd0239a66738e2e464f13e36b35539672229d8f5bd45bdc4cabb248c0a68988228aedd993406caea5e202bf4cf82bb004c6ae04f9171788cf2572ec9dd930eb133ecf9ceee67f345143fd27a1077932d81f2be887b121d0413c716dd7714a7a3e2545670408d144b0a5b664fd3899fc0e945f2d6e25595532f1eb68e1eddc85c8a6a2616261a1adac3f3ceec8e0ef95c5c0263e87b73e65bd123c1ee3b2fcaccffed81f0bbcb714aa56e68f7c2458e94f443a9e79164aa3116b14dda58a6baf0493969a1b708895f7077c9cd732e8bfc21007d1899f1f6f0b67d864788e05b9f9ebf7245e3951bfad0275e78441b2e4cc975f2e024a64045493a2cc9a996b00be8f7b4f29012e2504b2067227bde9a39e7f65b81b738cbd4ed4a2b1d73abfe829fd464837bb8cceb392d8daf687c41ffd77818b7fbde85ffacd7b16daa374c630b18427668982f64b04c1e1823c1ba43d7931101a34d885bcad42409865c31d4a5f47d483c1f43d7b8b56292fa34e1418cdc062ad51e36a32216e6d7bd1e0c8443d8de93455ecf7a5464f933a5ce6667cc2fbff70099fe6f8188c8d777e968b7edffddc18af86af8cdc461c7b78008ce3f2e4b53f17d2e16785d6b300021ba685c3a90eac94a0f8ce51a1fe71e6accbc5346202e294d122a8bac82315e6eddc10b28c9378b36a65563d4816f8b468e17d0334c0f0ded532638f9d982aa10faff92655489920c182859fe674b07aae5fa7374c7e70c88e2067fbdc163926498bc9cbebf2579fa6ad1f311abfac06237606eaebac0af0d5885fa600cf233545700e4b19bb7aceea473accaf32fa02a64ab7cc8f8b992fb36a9a1c29a47f501e5cbb0c04608cb3e831929d75967ea9c2ddf10963f2060797d4bb18f40e8613a536e6cefd4790b106f0b8e11a65955d5e5d8fa3688a245d96251743fc645bb107ac4275ae9a877b60796215a19928347434c6a0be56ad19ccdc9dfd23af02445d95e5bc6f2ccc546c54513e87c52b04be0087054877a950067a8f134dd8a790181af9eeb41314606becefc3e6c8c07bc8c20603f466aecbfdd3d3e564a300f53c01a970164d6748d628446cf3ae1cd4f2494d2b249b5854793fd96d5efb84be21733db568a56e9a97da2d7f94cfe9e1c17df31eb4dc840f4a8efaadd20191708efa405306a201f6f9e32b9ff4e69f7de9eda795a8d7677dbac6e7993e83c37323ad1dc027f4b288f1802fbba66071d7e664b161a68fba7bc396ce779f3f24da9b539db5e6b95f45c68847a144fe0a9d91bc6b96cad6b8964f784dc1ea87cc2cf41b2a04184814245a9baf84390f2297dca0952c4ad51439c99146251c7b3115a3e21c67fb8668e69ec3580655cbf4c77a2e25af1d45e66eb694b0d9c9c1774a50e885314b2d9ceef9895d740951bd300a33aafc33627f7b5fecfbb57a23990891b2c32e29cc4109db564c216c063612eca7cad53fffd40db783aa596135856c3d0a5e6a43e2cb9c0671bc4c050644ba94a95affdeed9277b5b13c28455dc34949b11204cad80c54fd711bb318c355764a77edc2133395dbd90e4a56e9c61b83f863ceb4bc25c63cb283e4146a7fbb9b66fff8e72eb8c92484ebe8664ef93650447fee148dc5dd17b46a90c5171612fd42fd3e771507a11dcbfe133307f13adfee37ccc06c79b4e060c76111030200bac0c0448444ea466f9230a75f57567ba2e9dc93d41e920027218df19df22ec90a1ade739a51212a0d25771764787e911892c083ce2e9c9e90c367c015911af6ea18439b445fc93ca1600bc7f762b0d8509ec9c535271ce030ed561b61b9064017814496facccdaf0439e47e12ebbede283c28a6f3f610124d229d96c465a1aaadffeaed5999cf4239bf942daee007fba2f00352d692b56278638b5468d8bcdb9cca6cf4f8cf971f6c602307c15089c16862c10fa92ff171c9dce37d841759731894a4c5a3ce16c348690838ac66e01bb974aa51819359916ad60ac632bc032f76a38e0e214c9a7443a8e59e7438a9c924a445eee53fc6aad2ce5075ee3ce59a1ed53b8774d02d9025a8fea7eac7c0769fdf7e7872a06b43b53c59fdb242005e1613c3a737798b7f3b90bf6bbea0802709fb68ce60f803692eac9abdb668d93b547812cdc0f60ac36e5003312b3036c5460221f69ac120931479b806c07c698b8128959a015c9b2d3e5a2edec390262a2c22067a272f243684e7f9952bca7f11acbb43ec9698ffa4678e7c855977053bb71285bdcad904b9eb8b0697ec6789cbe2b9ca8e0a6fda074d0c975d075df663d145317d3e5a5fb72eb739dbbcb7f516f10d7c9092eb4869d62318a7168126c5b2accc330ed979ca6832f106854963547e1c88c5e34d04c3af2859053bc23a5f85e1c75e768301f2d21b0a9418184dc20d831c69bcf4b11824c604e2ef25f74691b7a9a87edd164f66465f2e12aa569af3ccd80fc276f50bc4a59714b01f1bf441b258e5a39b365f1f55a742ca27b86de97be1517710f25e23f9d3d5841a703325072733060f472fe8ae5a46dc1402ac9e8fda7980125125757c10bab58b2c540f38ac1da9b6f4b022248aa229d7c564fb80c40319cdbc68bfaddce3e53d06a0bbeb3d98445a81345d768b7a5931cdd510ed28b8eef41284b380e15b6f407075c71543394249339666c9f17b044e1f39f66c8c9b8a780d8d9faa18b0cdc2545d475c45f6d08f8e246af413c5ff5188a70258fbb9a3e94566990449f8fe7d4ba48049ca681a40fda3631db0ada2af28a984d6c601ff6332acd2f4bf694011b48e8352a5a34290799f3c0d64871eea149c65eef28f781632c5ba1ad591d9ce7d0fcfa058ff109d10f0c620f2f40aa38d4d3c2108962f249cae631bfcf032939ea1ac192995da4185f88413a901459fffa3c56c2f952d8b0c67b2dfcba738fb68fc8f6c92b2b7625787bc30e58483215af281ba557032ab14e89c48439b0b732d523f5c70eff5a69f3ef5c173c749f502e29a863228a03ad49afa84a7bad6b818d740f2160be5bb8f59230216358d5d515be2f80baa9c19846a359cf14aa65c5d326ada9d114df5adbd67a24bd25d42ddb8e6b21c820786b6a3e836c8e11880096c88a76e6b3465b2d61fb111456da58dcbccf7b19b300c88db34699a9ca265599305c22a780e0e1bed18fec6aa777cbd0e9969533401615f79cacfe402f11629b8122175a8367c1d105de7f6a1cb88225f778cb322e41f990c6409fe24b6ef4b37780c99d8068089bb3a4b778ec63c80f6f8d03343ef3770f288c724cbb375f126c932c4d58bee0dd606045c9a5b27ff0d5597b25f5ec5c232a6a3d697601ce0e6d49be3af9d557b0be1597fcb7a681dd73bafa132de4a34ca6486127234bd0ab6c050df98cf6b0f111f7500652ca14cab4a41fa2d18f1c664626ba70f874a8365ea64d1e1e8a257a1d313a6b652cf6db617dcd22d74378159ef1ce25258c76e1e676aad0722a01e30db706e67788d558e44bd0fb600b177d88096f96dacfd78b58a1537209074a42c22425e297d11704380c9d18a3bd86ce35504f5127815feabcdef91c7a5b0091ee7c195e0268af5ef300a5c9fe1406579ecdcb0915397d14f82ed2bc55f8de4e5abcecdfbc41f9e80a83a072d01418a2a544f718ec3d4f6332d1bb2aebb00c6ca66b9999e6bd2bc490523859f0db1dea63779b9f1f84d52cbf3e7dcede8214080c6b54916f512426bc9447266897ad4078118867e0d6746cd99378ff539066b246ecd123bcb3597c4acc172ea13c1e260468fe12b1696ba737e1984e9b593f774c3db1696be6964319b9f9388707bae3ee0858528e3658741dc271e80974045f3ccdcf5c271fa4458e81023f42761c5eb37375dea4e4d4d8b1de0b4724631cb35b0043e7ac67c4edf767115670eaf50370af4cd2637de6c760e5750b8bda3c5351c16a9a5ebc02e2ea24cd10e9fe31deaf0e250d869f933642bcb9da2dd7ae6d92e3c3242c2ca4908bb60f19d68897616973b67dd1f1b037c460f7181782191858f2003a4146daa41901058972d7baf5088dd5f89f294ddf5d0b6af191f36df14250213469c2735942e825ae6d36406817d2ec872e739cc1cb9f0bee817e95e37bb38c24b9bab958654afa1a38dc4c3155c37d1310f014a5860de0637d0a48d23331bf8afc9f5cef164c130ca4a472b360b92d4552f083d6ffc381f8b033bcc0550c42ea706ca15026f0d4171c06e6e3ed636e2d7cfa92856ef967342076d612e419457b0667c8087f01ebfea10184cb54e7c6df803d8878fc04ec7e45e1705072d1a554a5ead50980fc7dc0443a2f51f64bb73fa10f183be1e8c4368441ddb9cc5c47845c02ab67194a7f27a109036ef7c44c33ea236f799350705cf63fa5a8ed6d8075b8d483c41a589c4ef7efb716cf495f839a1f22ae433f35d4c5abbe7bbcec3a78ad021babf3e0b9ff84130557125622e93b0795670617a426fa536430d1dc22c79ef99b0474f5fc4a7812efe5c9e2e9f1a23edfed2340ce460b118525836600127c410d977d7f2e9a89a6b571289479ee50ec969a026d8054077f783ac7038fc45f1d7972c01d4ff6811fb44dbad8a5de90b39b8a8c055e25ba81b4839725ae5f33875d468fa381a5866ebfa41f21cf2bcd32c0a3e171ca4cd5ee36fda6a7de9f0c630430e796fcae444eddb481d8c61f7c1c1a6b6b6df269eb1c69ddb5d6e2c4bde345e22546ca393c69f48b4d52019f1cd025393fb97d193b53654aa6bf784c660040145a5d5da90092751a9294b526d087323a04313b76cbe6447ab73707f48abe7628a2d8e2b0a5de8dc8e7d4baf10cf6fb714170a8d0e808f9b00d1e3796967ea69bbf899bb84605751b423872250ad5e61d0162613a0876f1c0aa27c7c9dc629bc9ef8fdbcd6abcd26fcdf55e0bb080028cb3de1e3785a3320ee1652bc1a553fde8f73da96ace4c55e5d140bc4211918ed8694dcc5d974ff47276c8c157260e9099cb8042fc9f9a258a6a107023ad1f91a1cef61a74521564bee71c2c055606b183fb3e5f02c21d21f45d8c3dceb63edb8779d4e54668ea48b3d283b141db2e76e2cd4f4f609d47125519bb969771a27a129d82b326cce960126a21be34bcc01bbbda81dbdfc70e2cf40f79d3c7da6f29603a5e52e7f968c8bfc4709adfad10b5d2901740c54625168f306997e9ff6a4dd6b642635308a33e7fa964a666fbf436c2dacc0444c8256f8ddc5cb975510e16e093089030fea08c28cf13a58a35e43883a9feaa5b6552041142f20a916a2b4bb0c0892a4ccf1a8707b3bd537b359cd86f831c655102f69601746ba8a29cd9a089cc3796df03360f77c6727dfe70cf7bd1ee97bd070a1b8ff7798ba8dc2e1ca6f09c1ac987da350d1929136cd346b5347b4aa00aa08b1707ffd7ed550b167233ae883db4791025d4d3f0893cae53d0ee29569290f29b0f73b691f05895c9a2c40357ea89b2fdebe78c41e14f014919d17cbe67b0fe6fa854d65c7a2fa0804dd88d8638caa595e49d2bcb1eb6bb45aa447c4f6ff29d308b7785fa01213a796bf7f61237c38b7d6fa76cb760315659cb37e2c88a9cfa7d48353a5e160709aa599f17ab5076cf9010a1aff139e7d908e73c96c1eeda61568730981f77f749455f6d4efa787d9fd40630cae5ce4d302f7cb502afb8a092b1a0447db8c42d95be45ad25ca5db36cd0f24768173e21b968e7f38503c70bfe56101b8152b3e1a32d922a58fe48f8fa01802d578ffce70178b29fcd877d58d2062a166933fc33d52c611c44d98beefc7a2ddfab7b17a455cabf8acab61554a4c1e649c4d228fea931d30314849cb63eea6684d5410dc66d24fa96739949aa615777b13a0849df0f9b95023bfb065c29379f515d4eb24965f0da79ebfa7af2b3852ee22611953769bc08b0df17def102abf69d9e9d2ab0854760e6ee324c6d35d804f0069d65636227f3004c20e2b74a1666b877e0701f933590c14a0693251fb7588d16d011de7e13d98b07a9935ef81774938d1f8dfb137ef0804e32d54efb3566ef86664a6b8d78d19ff938ca4e067e6c9bd56a635ba2884c97a074fd7e5d32a98c6ac2563323e1d7b40da5cc1f7a66385ef4badc4fb28ea729d6a406b13db81f59251659084f059081828fbc0a287f21a7481d8dbacdb4cd8714741779ce7f0b10d23bffed168fe6f15298797240be1ab25efd139f8f6663e275121659798aa25963f01fb9366b0eea86b68b02f48c74ddfd8f7d326a5bcdd419a78d76dc27507ab0aa42971abb2fb8f1b624d62e13980139cfdec46acd5a48fcfc5b86a5e940a9849b14c16368fbd87c5fb40b8f410d515fd63ddfc55c529e5871a4988f6b1478222f54769ccbe8ee2f3b735fa774ab209ee535a968e7f5c73ae0b5de7c384522f475b368931a1de116ed780a373343da60ddf436d33d075b54dc44383d1b526a931061cebb55f946b2bcde161065cb864915963c35219870dc42e260ab6bb141437565ef9fc46b8e662228db93f8063dea3693be95fa1569f3b3c91b8b67f0b77d4a7523cf67d842d97ff491ac1842f40f10eacde168aec22d2d14732daa332ab4a4c30248538e83dd7afd1ee5d712876feaf7825829e2e7eedfa51679ab1d7c340f9d40420378b49fc3fc42f72a9a0ef50bf647469bdcf7149a89c14818c0ea9b5fee05682c065ca8a9032bb556e10a0a2e7d508f1d60276b6a8186759960374cfed62f261cbbe8b3e77cb01b01c412d961c16cbbff5ec6c655a18f3d99b0b8ba2b4aa9480d626d4534cf488116b5b194add0074a593366f9f4c8ab554393017f7dbcff227adc4f71578342e2d84814a1c949f6d51703ab19ba4460a1548b29a5b52b5214a1bed29e9cc43e8b0590aa3070424a755fbeff2c6ce21c722042d196d7192681845c6f898923b56e5f3a7370eaa6dde6d978e89f788d512a80fc498c33ff338ec7f0c3c600de2bb10c1afe00f096a9ae8df2b5e49cab7828c8b23e925e8b46f8ae63e024d51c5cce6b972e070373aad3419669fce258a3be7b3bbeee648a0c7caae41e311bdc63f25a49691a192ed222014d0071e3d7c64e3592feb0806efb75f5e4af2e6fed4d7d0bd43c4a7c60c815cd80ea50fcf42c7e4f1db51cf0abc3e13f4bf91a41a4fc3dc846fd52471628de83030a44e40e76462c6e3bc2cc3561cfc80134e7d03d955e9d64080cb8010b54d350db79d3f32b95068a570ea03232c72c60631d150f317724b11b487dc910d98e2cb9460ddd235a8dc716278e888689c0d5f78ab3b58c904794b17c4bb64d3d6f28dac34b8a9ee8a1dc6f6bfd1c2e413e4b24ccd3543f6eb8e1b962cf0657bead354f86f08fb83acf0f2d15cdb76cebfbe9efddee249045cc81f0360110d2c9c77265cacf1808e1c01c426620d8e9353ff01078bb31d4e49983b38764b57ede033442be57fe2e7eddbafccba9c67435feef3aa6476bb9f59c22a7186659791f24ea5aa27ff0350e301a756fec499d85eb9faf9d230b40f3982dce8192896f6fae40e80b9e7ea12c5f4d0a31070bfca4ab36898d33f2d5f351ce8cf7e17db47b09b29b6646db4334883c7dead3bc7d0ee01dcae538c3d49b1714f3c113d06102aef49d645173306c4f207ec6eac2475bc8fa26926eaab8daa466e6c34ab10668fa741b86b382e92b2214397f748cd625ba2b58e697d0180c69fda71d034cc0670d4abb988426bd872fd41b642ecbfb6be68dfa4f340707a6b6409871faa6e3067219f101d3cb77ddfff917e482730104661cceb733c1c8990e16b5508a890bb1f9e8d2487295eee1701bcac5abc493de597d5d9cba5cd5af580949919869f4f652c32fabbfa516fd7e11158d2757bcdf0f755df173d3f8a550f91664ee1fbfd1fe2e59ae2715ff9aeea4f6e5041aa73aea79be007519d9e80f3fc68f329869d7f478fe0119f2111f54df2cf7b560fb1b47165ffc114f5cbe2c2859c07c3564d638cf9c85c5b84afdc9e5adc2978b62752b13878a63ee99c68d6b79db08bcbe71bd7d43beac5e3096a2c6a472c0df4bce2087fe04ae6fc39eff4ea505292100fa2e449a20358a447dac2e932e04d7d18ffdbd3f64116e120f3aae0392e635702f6ab8282c7bedeee6904bc2880bd57531f848c8fa136e125585af4a7a7f206ae99a126a67330b01e99d67b16e0f0f06f556418d3eaebac9ecaf854ac4e450620e22a388b25ae4efdcae411eda11fb962a74e49e12de23e88b8e6e8c72121502ca28ab80ec0a5022692b0cc5062a8d2bf2cfc2be101cb922d31a3bb9f5171d85a0a03cc4c51d0a2ce10fea4c1355bb710ada6ec0f11b69a74187f2b1c63f9ba776ee670eedb92f052f1e90992332cd3d3da29b248ecc997d73887e3ff12e12feb5b1939f61c73c0709582ba97883728722837edd1db6f102788d29df604047d15a1852a5dd7fc7c74f30d392c0a8534255713cca7653257ce25fdeced943975bb6ba8593235be0f4f199d174f7843c720ccc6baf0215e17be990c8d2c9236224392020c2760c7d5610f539f02f2d083e892d69f78c18e755a0f356d6c90a8306674d83c32907c66a654183ed03d261ae20ddc26354f38aa3bdf0760380fc09bd7f12b225901dcc213c71318e05bbebd80f524cf5061ec623cf5bc895b4a6077976a7ddfb9c0cd3fa783259354b6a2d9f284552ed221b78d0b55e8eae65c02003e58fb60c50bff4d44d5bbf786a3f5cbd49c3cc914fc3c602d082d7557c3f7ab7ace38536e001bcf52eb0ef80154322b310e2ea795fe7333d0ba333dc1a7a853d0b9825e34ff5cc055917311b257cf36bf141a2decab2f2adcb50466bd0432e09ff47d854ff60e1443cc6d6dacc027bc112c705ab3b6d6c3de3ef5ce27d4d129fdb066237160be102dc61a8690c459a52b319c974404180caf42f8620ff20f9681d46a8953f4291f3de9ff279d00cb82789f9f3390a83d0f9d38050aec674c5c92bff62cf37d43b50905fbfac7db15ec9b8771850627e1f9e770c312d2138fe017e607b8c1642c6193e31f193b69ffac55c595da60862d4d14c2cfe9a6558b3398ed59bc10b4a1822dd6fb02884f6d44ccefd2acae2137921c5c0e61af9b6845095b45d27820b326e1306ee3ae43d05624e3e2bb39362187700f383b59c51594cb7ae9af7a6e004d2ae29e9ed089968a55efcaa2f352623448f5c54666a6b57111956291dcd7f5a4d181bca27e3145020dc777335c523570d541bc674e94c4934374829c23a70308b1932cfc1e5aacd9156d5f73da866de9ec2d3451247e2f3f3002408fb776a822a58c313e8616d49869e70d2e7926ab78c4f2c95e286db19b74770a15064005f43ccac5d10198033f1a16ef1b73e2fd166acebec28a489847a9ec8537747b5c83997872a38527282e648560e37180d3acab42a72ecac8dc39a281f1c19b64c8c71eb8535c29c8f8b60a4aaad677de1e20a0f21a524e0bb3e1e91926c4021f3070eb5de9d98a8df57c41452f66e5ce73d7900307c01ee5e45201abbbf8f49bfeafe78720bb61856e7752389ff5d32b760488343be6f700a1c9e55fd535ec4584387630c08a2a48f89f1e7efab7c9de516fa1771def7e4dbac84f8db1de0015aafbd1f2d74e64e65fe58fc43a36150672689ebdef7b06b565ce79bc4ec2335c89b84780985086a74e81da4c032429d717e5c979d276fea444f6ba91edc42f5caa9dcef02bbd32e44565a745ecc2d53207621ce08ee5421e74da75fed5eb0c36720ac7bf257418746f2b2c0c9be338ceca525bd2d9df8086e4dd1b39c9ca6771ae45bc522b980eff22650f48f22a5c66df99a70d00195f6aa67023b00fa611d4d09cabe9af0010edd6aab27dc4e4815cdd63292e5edb1a572dbf1c307cc0127d6ae1a2edfd548dfbcf3360079f6cb5de7778ead94d8ea779f40a51468df59c9f68f9b642929d27db1b62b28faa2f28889ef015c1b547c2a7fa8b98ceff4c4e721b8d7caac45aec0866c1e62eda03a822517e99d42a6a679d36aea470b4ae2a2f97fef10c28943ea9861b09ba728bb660b6bbe5b2f052c88b744bf24caaae05561feb1a5735f213b9bd71892f0188050dd475e72c9740ae547d17dba345b4fafa7aa952bd9e0639a2d3566ee4e9ad19515d523d2e4f36d26ff1e7ef1b609eb3b126823314ba667be6d09e7c435b4d6e68e5a8f1345e55f2a71d50b8b8b105b87c9be2458431d77b36ccd6f89235c8512dbb2d57f8c59f560879332543b473d0d19165422d731c2350156be4658e3d17ab99a5e2816e0bfeb8868a7cb38627522e5d2d86b7307a41f3ad81341c03ca0d7e571b4dbebf47d47a90638207314b6b00686d4427b56330750f0121d400e9d590df382d206d0d812187260693fd726374ab708767b3ff731a9774e56647d00e850b4e31e47f422588d47691d26fae2c91a9cec647376c3061b1a41f12ad3ea960b18424e474d5462a6b43b3b083d7b8eb3cd3e3fb8ad176138ee32c53af44e90cf24ac6d1b3f3a0fc446c2b2d7211c2136b646c59ef7a8ac5a4faf92f201651879cab5905e6c5ad9b39ee8b357259ac5051ca342f48cb3b5f641e6cd4b740095645d8343e36752b1b57a0f6e303a6a7cf32fc24a3870bc0e3897e96712d82a1225701f8be67aac7299b091e2048947f23a93c985b761fb16454f89dd5cc893f1fa3aa7bd95015c9da68d57bcc35ea31bf25d69551683c6931093b2aadd0f37ed9acf6a408ed91f11101f562a2e2c5f16fdecc66dda489676775b1a2d62b09fe66ff297ccccf99f5aaf8488601f66f11b9cfdd0d91241fed97d3c0088963cfbe070f039e5fcac771780e6b2b245be54f17cfe37e425c0de47acc34e25519300a8afff1f835d63680fd56064190b99b6b0c723e7411d0b183ec38d0aae036bab9785586d3d50a0d062a3038681769da5820da23528c36df7f3c9a828fb0adb085adbe1892570135b9fcb61d795502f612507a641afe9b2b2b93310408eab6a1a581f107de5cf9998413d3c68d6243afa58f2dff4bbb6a97c5c6cfb5f9dc23aa7393ff18ceadaf4bbc3deb8791ab6744ce12d16f90fff60c7d88ad8a30b82042edb1fb6c6411d873e295d3e86ff5ccb94ca3ae8bd5f6b6f6baef56ff9d9f00356a9eaabc41f2f05d94fb7ec0f69329e3ec74e0900a2d326d76e99ea7707e1ce2b7c9e6a3f47ee0d8ab2d7f8cc651eb5cbaa2c6b617062a51b3ac075fadbea8b53d0b781e9091901c608a42fa6a2fb46fa13663a7273defe1808c6027a20202a7fecf228e09b6dc2cc97221bfd0ac131d90c33861c5b993c7248555c7a15c9d90fe9a8c34923b3dedac4a88f8eb0b71d778f94b607d1ec95217f8bd5b03214536d4f7c402c079cf7f67027fa945b4782c2a06ec557cc466964d2bf2cf0ec14ebdfe615cfb1133491ccc415e202f1ab98e3c738ea119238f3ccc569ff46181e0b82c4db4e1d997566979b1005abebc940acb548ae12b96ad19af931e1cad7869c80dd8228e000126b3b93d629afb1aa9f487a25701d6ee99e4cf2f5b9f207f73e11763352830ec4e195996180fc56c5d84d0615352894cf5b67f2b1e91974da5e501a8b09f090edde5e77c5366c947b3a2746ce229b5754f6427e403fcb271e487fccf3d74e0fe67009ce4d32c4fc1808882f1d4b65436887c30ac2a06f8c8c8f48d1dc75e1446f6e02f13305f0ac1c859912dab3370f14e7959902351550bd14b3d5b1b012eaac45fb19825896a5adaac9d3374ff6a40290f56314ae3967fe76610cb84eacd3998c630db20e49958f0d8366044fc900284d5e8db58504fbd6975535a2ee1ead79b6cc88bc6831f661b1fee9d97dcd7f598338c12befa546a75c7bc86c784b367da4df13f70a59c5bf9933e95654b7701b41963d33993a9e0f46e7281411e4e7a3b97906fca7bb82652c94025930124c911c6dd1333e8f7340448aa6fbaa75ba9380a049b41bb86262d4921453133dcce9bd98da9878ff74c6a6ae2b40dd06c1d8a963ad52aef1b26f73e9c57fd52286f2bc6ce8df8781d3c4c68912a05deaf4ef510089374b5a3ea63672190ae97c9a0c79dbd339b36ca5abfece9fbcffc1a6564735f8e5b7ea9ee50b7aa3feee252816e206a7ce1ba545a90f74a20711c831a4554a7c53288733fecbbbf9f48d272d6b65926e6491c7204b34f76048735d6256dc1a9ed16a62193ef707a785456133801b11691fdd576103235c6ba2978ab05ae19878ccadc36f9574c97ce3a5bc3aab4ed3070dbb7ebfae002d7ea4c48794deab0502b6dbe03c1a49ee52728fd3ec92389993e7464e8d8040e60b211d75bcec5adb4a19ca20af1f2232c652fc25159e12e858f3d07f08910093953401a8f70c11236df7992bc2e113e51b20b22a2296639fa6133b6015f802d66852bb2b4b698f1e8a81a76e67687d0b8508a371a3cfb18254265d57413dd9aaae3742eaa265f3456bf9dbdfb08fdf6b477a6a10fdad90e7a3355697aec35bf22a8f84b655ed7fb307d0489142c045faaa914e81c608e59c6f88b82749d9567c46aca74b4e1978b741a44795d277cf7243127e1597f2e5a3ae676b42c162909e2acf12f010fb756d886355f41a24888a64d5dd10af3515f3001e6911908bc84e293c988afbdabb7d440a2ec3de96ec06b56b4b9701e95e5ca10b6589c2733c81269da2cfc17b3d47fa89dd30503200099ee675147c9e6f97da5e3a7856a4decc4b8c165c4ef804f41c533835ac27e46741496675a2431086b71971f0d40370dbbb119242adaf4e729ddf8d1e04b69a669486aff6a0ee039a66c9961c66e0d6d5f78f3a1fff5432c41265936aea1995776862f892861c937f5904d376a339dbf99a02cc9cff84c27f206c5afe488c953a574c797e99f22b5c917e5fd1a90f3c17a4868d0688696a13dc911ff02f1ad4b6203e9d92f77bbe78470dca7c72009d61b3df1e7871b60921a0d54a6ebcaa148260672a3aedff2f9764f8197d9a0b6c934cceb6820a41476eb1b6a9110af53bb182dbf95046145f6bdf102b1cfa86a5afa8b08e603fc927f0460fa9563545c88d7ca5916dfdb5c9b6c767d520679e66bf673ec64502185615b13d9a131fa4651e5c8b40eaa278c771c4fef3acc35ef76d167f79eb68279911984ac9da9e54eb431dd2340ca6c72e04c2da65412db02aaa3246250c507eb8ff42c1d25b629f9340317ce8b71eee0aa0c015b2b905cfa739bcb9db63c6779cbf2a576a132b4028bf070686f89adfaa5ca91fade9b6f6b4df65a63848c502d2d24b94201e4713ecd2aafce1b7eb28ae4f96ab46476eefc5392d6ba2fe7220eb3458363b121c138d122a188c3dc60454f7ef6fbe7479cf56d1a20347d7960a7330ee392fbb02e0d5b59f7881035d8439568b8f438c0d91f38b1467eb4194f28f7a1558882f831aa7bf0679b0059c10180c66abaff9d238887a05ff23493cb18235efb163adc0a06a2c8099bbda391161ad30f52ab2c7627ab44e1ec88fcbfa08277e4418a7a2286601e56877d6269595c4885c64ea809e9c121caa5532d4aaeadb9e9e6651be49f25470bb0dee83448cd59ad75f4cdcdf2d6c3346d6065ca27b286622eb28fee3ce4399894dfbd1846725fad67fa2b818870e0aad72f9499e1fc776431e6fa6a6858f5c6f1f0b56126e8f912a126053d445f27429a596842da82b1c3b8308ffab9ca5d5c88a2d39b0f44968b0ab67222c6b93f8cafda69183c62918e96bd5d949173c140d1f7d0d256ab50c9fcdc61c725a4a1e1f4639c8363ea53abc87a8b8696a1b8dfd51814f19a6bbc18f5c567ee8d89e0a85879c50fc1ac149cba1e9453d5d262d272c3a76a0e254872e1f54e8fa6da6c8d2220605305dc398214609f1e31edd55c8185c46fc00880f28beba2b50b042b26b20d8fd7f26fd662142b0440addcbd3a64e6ee99bb583676f96927d779481a0647ae6a8cc059d35daea794868326bdb485de1940b2a0c5b90489666a5ad85e2a4c336c730d0cc6280111fd237f90c67e4f6815889ffd803bd9cce441ac59e2aadd6e546f9ac17507798d056b2a421d381866b954c30d33a932a629b67e2745913efa188f9bbce163bb69ed44d12c9167c406883793d6e073e31f74637aa4a17c5c1e67bc663294b8f573ebade9b593b1f720c74cc001f07f29d1168caf61ed84f913f70cfa5c6ebbade99e2d4a5a9b2a872a1b1fc75c65337ddb01ea09c027bb0ab8c5bb00cfe363edbbcaaccd3b997cf926dd2ccdc64d98cdaa4389d8e3c46a789810929302c1e8d10c233932e1144928018bde47eaef06a82746533c7a4b9f1b8253c9bdc89e63f7feb3bc7ccc9aee795df2fafc139fc21ea9013ba3a3c248747fa68bb7210b8557073f3fd7cfbcb3a57eab551aead27af9f716c1d528efcf4723c5755ddd767ba5543f9a7b1c112d10174ee53670c3efa51b94b73a0922dd298c2ae4bc7585bafc8404413f0042165cdf82fc68e9466646ef85d2a9b52bf523fe8094b7dd275c84288aa10f6fe14c5dd5f3e8b2e30e2f182083b5a1f4b0072bb58e0004fb9868578a1e1fcb8be370bfec6c5b2d0318eef1e9bb50ab89fd834ab0e625af5527a5e6f82f8a3a405eff949692ed2338cb902ca715293b77dadec10b53bf024f432daa9e080dd7f2810c25b850e8c2e0b405d1375275fa5e832390fdc7373e6977f682b358897fdf88ccd4f323356b80cc556eba9346d54c0472b377c06d453348058467141f388a523f6ee723496005e37bbb98d321df49a1884bc3561c19198cc35f2ff429ea6efe3161f569f92e1da035ff641f28c04a0a8052136df82f8b0447529ae3e27f8a58912e545514146409666760f5425a3225a4c26c143794808a9cba3f10821c3a9a6a419e06c57f5a6dff47370620808ab3cfdb8f2aeaa4c2eeb90405d1ac832bcc1a55bbffa814c3471d27765a5ed6edb3566edd96e20e6f108402df41b49faf48b75484ce9d37936b2f26672e80731901740049f18de88bd5eb2f58dc4afdd7a8f9198992edbed64c2602373c57e2c06bfddc03177ac292e562cbab5e054acd21318a4a10a4805330476c9099e3d7660d79a3b2b8be3c14d05fe246eb1c9964761289d097f71472a6beaa0127023697956632f8ba77250559a15ce9e7f270e6eb1edb62586cfc31cd4fcbed345891201cb9f2834761f84bd88f6ab147e6b3f1ff90139f9c6c4fcca9dca67f6f4474b102eb1d4765f13ddda3746d54e44bdd32806a9a8a179baf0f8d75593777e79ad9eb9a370db4ce21cf5fc496d6e521ddd7f2e86d2fce6bcd92f1dd8028592154f1a8734fedac7795d4c039d5ebd66d4ac8475a137ed935f20c7fad6ec11db1f86058949a36165489f84d9cda1b1bc1d4e247187d32e953e61716bb585c1d0454f7b965292fae8b22536dd70cab60356d1dbd744f7011c840ea57f5b80a17340138bbef39b38a34631fcb4ae8d262656ab1557b3d74e09da980adc68b54c5eb56ba9716374b1522367425691f578ca5d4cfdf22220b7694610d9eff4fad493158fdef22d1c936252b49153004e8c5ae8b53fc55dfc7aee6769d559dc6d0a439d4d709b116e3abb4ead94bc8cda7b0bd12c0a96a151ff242377453f06983beb82d144028101cfc7cb7b12abe9a1ce9de7f714f1c7c24357c98d11145b5a768f01b6e6f2bfa3da6a825728ec4d1186fb56378be287c83bb728ac1f2e844241a0d5cc98b9aab6996b7ecc14b7b499624b294b767111b76681e3bd0002113c7e3206caed1bbaadf9f536c32c97ba20607bd2711ce7fad2a83149529b060620ac3c8be317fcc60c721d23665f16c9e7eb87b8e591da318ca5d60a8cd6c7acc1d3c2d7a06e4483f0186f62e2ba305649189c5e53605892ca44ea79e249bc821f3e82e1c1583e7aadb19f0c574c2e138adaa6efbd425980613fbab36ff49733b6179e15246bc89971830913c0c225e6fd33bab45f351768e60d9016b5dbe6c9f4cce77d160878dc2a27e19edca99840bc821a66df08234e37b482e1cae6644af512098d2495c11ecb228a57c43ec86768f732eaa843d810a0faa286e1fbe63bdc46bf9e852e349d15c0a170c8fffabd3dc7839f6a8190b7184ec66bf453b4eb894885d61e9e21438073e1729f784790935607c7cfded186c2a6b134916d591421f72aef18288cd68f97f0998c659a81d73526766309ac0300415da7b642dfe8ba7e3c9c37af67b4893f119f69985e1e16f4bfc24a1dbb04462575658584d7a752252839e0787f818f41901f5080e1d52f35e165003d5c0f8281cca9a45dc44769f5665d33df75ff7ed753aecec1308e456ddfee4dfb559bb6fb36cfa647b5777228cee24821962f8350ed090a538f12a50724188e273c645315f4da6267f040104edf9029bbb4da1884407f8437f5d1665d870885f1bfcc6b28d3f367465ef32dae8fdb43ffbdeaee77e4193482563fcd3d841e2003850e5a4adfab4a1dab93d42a9d707cc91f5b78382bd068555baee3664a461831989b94c420c1bfc0b53e8e4a1b26a67764ff9d721bd676265bfd2d76548d3ee2aff5fa8c6f28673111195dd8108568c5baeb5928123cc3c1b07c07cfdfb5d1b71a90bc96b083b75ada40678238949c508ba6ce3af28e601b3ff5c087f63876b575fd2eb7323053775f5487a6dabf336946eda37230d3afe6a75e16af37a9193bf5ed51d5efbe577c4527d4cf0d0b8fa8a5f15c3a0c86b2984c2fa556522afdc5cf3989be38b3f1489a775cc80126f4d1a8441834285954db30d2035e886940aa2254c6a7fa3587c874574b47e8979ae0986eb3088e01a1a670b2d7b5f7f042960fea80d5a4b7db00cdcb715765d11897aac6584687657e883a35e36f6bb2e461ef2ffbb4694e11a41c08e8059b623f10c48f63c62fb5a371680dbcbaefc2f43d32e52de3db301729a1b604cf905eaf28e369efd2b04c8a6bb11d60be37de8897e2fd350db4d073e1e0ecdc8d430eadbcce1c2f9483546647d3dbd75abeb905506182853505c63ed3e3fc8bb6c544a55ec2358f987e91434db7b3b17e514d2f48f7319c7ef30eff72cab9a0852645eadbe45f34bd141f5de7b6dd367854ba7fd6658e0ab2ee66dd20f2bbf921f3cc5a0563ec062df41b6c9a4aadd81c262a9683ed1f5beed2cb04acb8ed18581103daeee290630e04d67226f6ac86d5c680cd7cf4c79256d383aad62adb72a01eec6d9f098d5ce17185b645b64c52293358623fcb8c77479dceacd1f35821b2e43b825223eadade6c6fb97aa9226edb450e9c188133f2b5ab21b3600f488f34a18db510c4fb0c894345fc280833c53bb2bcc559bc70effc2b5eca18b6d2a609fba4f8f44f77c93b8ef7d642011a633d790ec454d67642a944ad1d2aa5e96bc51819452dbfd7177f3dd9e1579be6ac226caa88435614d0c29b519def4c5f36f85425bdaf8dbf6e858cd02aca16c6c9d82a0f18c5090080164047f2e975e9ffeac708d3a2b8be97695b2736897676ed49b9dfda9c890da00b0cb6da8a832264cdb48d8779e719246a6a830fd4033094135fd6b9e636240a4e0349526f4536b5bd4b736cdfcd46a88de2344fa8db7a39fceb5b724a9376f7e51aa417f1a10baf63cf530a4e759c4be80b251ee82cb392bbd7183039d952a0d4d1ed64f506d9efe23b37f970187481518b39553343e89b89c2f6dcce66804b8d45e1d55ec1dc36cc679e462ef0170344a83a53bc23044a873d608da8320ac65e235db368ec238efc73a0203508252577fec225b42f66ed7935d065051184cc0371494b774893d57f30bcfbd03c7ab000091123fb60fa23dc7977917000d8e9ddab549cbf957485e17c342807ad67edd3919d1d5c4c847c8eb7c6fb1b6b756bbcaac63bd1cdc9f8d96cc9f91fdca6af5f66e6ddb2355d6387d4229529bedffda6fe0a77c0907cdfcf445c8c720eff421ee021081d34d0b73b54b3d84781a1ada9dc628a4b59f6253f1a3cff7e82c31014abdfb9015711302df5363c688e3232679cfe23c0b273f68c0e161f6548b405e8177ccef5ee92b215d98cc128ec7997bc8f7197c143accb3c720c1f4ed2e331130e4a70df1d89d4ac6bfc50c642cc8cc1b05040cae31594015470b104163e85a9f519ec28427b47a3a8a0b92dac1276436acbb54bac573e9b83af6955baa5e254871e2e681ac5f42219834da9a5411d59f497c6df3a89b46399e8060121f44b73ac189060dcfdc7e66f426462aeb94eb0d7a16135d140ece4e04fab9f317cd83c2da92777bb26d75957c8d170caff2d1572dee417551be25c2b0446cb6bbccead36a25e3a2f523bc9b6fe3537b3fe0aa0918ff2e90d41ab5d8203c9701bc04cc8b426fbb2b25601df442b472e6b5d3c2dde368e1329c36b3915b82af2137dbe48a5ab8cf13af4b255dbd31ea11473575a63c08ff3d36ed69a0982b7e2faf71b27cc091d7944b25c30144c6f1e98e0ff646ca67f3c1eab89ff4d3cfbdcf15e475bdc50b64f802fd83ffc56f99177e399c256d93b6fe616073e922ccea2b52b84eb6e9ed064f7acaa2bf7fec7dd2bee3d796bc0744082041a06cf8f1e45dd44b8bfc02b1a584fd52817f2c16f6d26828f8fe32f5863cd938c5d2c7cab425f6cf1bff7e5c4035ee8bf6cdd48374f49db86ef77444d0b73acabbbe06d193f015aad4dabb76072ce6ae8beaf03e48c627465dda54afd436d47f007c5b1c7b52cf55830d6a3dbcd561bac52be9e131182f46854ba40f55c86c7935413f3c9ebaed553f9b9fafb964f0c5a03ee454b8a21bcef78881b1dcd9e4f0944f5e0dee6770f7d32e058739d6a63eb6e264ada03dc9a30d0b1db52bb8d96dc1f7c6265fd93ec0da79c5898fbf9ebb3dc1bb2ffe8ad5eb8ab90e70f448d5fe3fad48c56d1bfcd93dd5b11f413eaeb15c0056ce58e6652cffa6da783774a82e27db165d9d8363082158db4c2fca14bce0b913326338a952f0c298c13f4e34914b7a30dee0b507de40fa8ad3c2f8f52d1728c2fcf55f6d1ebbd74086b553b14dd513b6350e3a768b8678ca52b18189a5b85564134db150477a016b7824e73e59449451b33fddc3fca5183dc7d9a198d69544c402d09a96e837c02247e4a6130d6eed2a9f2b30c3f738c35d70c85248c3b057359ed5ea1cd52b3d75eb9d54174e6a28ee2c6111a86baa9775f96a245abd0122b84590b748d11e36778668804478853cc95a6b177be3e89ad0d4dd55cf07353cb8977d3bd98060e117840d167f0db84d406970401cb2938b18074c16b36f9fd560d2658a28f3aee83ffb01f39fd96972dbcddd32018d34891143f8288664e979993eba480034fdab02115f30ad476c5814c52236c0351dce3f0dadbe16ad102d558e58e46f4de316d601f1eb8559fd6e7fa0da2edaa56f5a01fe1666e4700cbc5dc1ef9f7674f1fa53a82de533f9084a762ef55562b17634c10f12f1430c0c7be8aa9798546cd20c5eff8408a3cb350afaddd7ee636cd8ec151e393db773f5bbd9e176a34373d86ef942dd0d79b9e271371ed04fc6bee281bbcbc2cb0964bfde1e396a4c18625e8e24c29951cbdc14718e6d5109b0c08565d7735b9bca70a223539dda13c5e09eedc6ac0cfbf99a4807070785cf8dcebbab95d7a05ef72583571f7cf3444111c2d7cf6631862d9975944aad75d7121705fae35559fcc29c10be0ef7945100115b9f3c54195f6ba9878e79c64132a7fe77767413faf8cbbecf2ff69e85ec340b5692343cbd35c12b18aabc308b5d49214f95c8abe9237658b6f43919438f0789c7154d639c21103181eb034aea16574d9b6b961ebaa798d75ac2904f37e5a683dbb687f10e0818620bbadd332c64b26e0a1f4c6f64cfe00b35e9c5c8265032b1bb6ba5b13d924d0d200a10249cf5b69919d56f2f8ee7d0400c4ebf7153181646511f2519b3bca740aec21d724ced7aa4b820ab901cdfea9c89112d9e50021c63c6707ad027f5ca0be19cb4de574ebbafd938b3e9570d8be400d97da0ee86ba610153c7075ffa8b175ef3946454d98d904b82ce7ca96ff4cbac78721ac8c31f05fbb8e42c55b32556888450385e3540e73d58af2f6078582f2e941d213a237de856139ef5954f8af94fa85a9ece6f4b649d63fb0284a9c4fd576ad72a86371c8e8b2f43c27ce93027d0c7593926a6d69e87ea5795b61888c1aa80f605d1ba68fb1af27697f8a409f800b9405fc44a2b70c283d640d237b73b444da8326e7171c2f699e87c63a02d79cc10e62da48ed2f97597ab3c57c2944b11186e1df36974cc03a7c87606755b499406d36a35de4966e5a983e8cf04168af815d21fe1af84864fdbc6fc0b1a881b7f266d8cf96c7b67bd124bb3c785236d119466f2ff51edef931037f4fda1951cc8518579c4fd97d9e6e43c8848d5ec133e47a9aa5bc6f49295e63884fcb22e77fc54e4941241b888a31aa59e107b714f37d474deb8b9a62bd3a6e3867e6b8a972ffcbdd03d0c4880060a0297d9841d384b36f1682bc92768a1aea387214791408a323d534f9a3a362de6cad7bb3b395799a1c98d7ab4b909d19699256f2e028fa054ce49aa8645a150c2dcf0ebbabd87f87c14285b7475ea9fb1a2b772092d94e4a2332122b14c958c48dc2d147d4f797e5cbb1ade04c953f37555803900b7091ad9c274db66dba1ad056534beb09ff8030ec81d88848d7089d787aaaf897a74f9f91692557e5b306cbc359b986356bdfe5682a624c554dc42f3e521c76711beaa01733ba252670a55910720d4e62e0d294f49c7a5be941ab31619b07f28784a8196105c38585c29fbdfdf32b29c9dff18edb10cd5d176199bbec3d9c4b2eb6a5ee2867b255ad92ba3774d2356ce55e4ffee3c5cf8fceed59dda03fa9cda4bd1fc8f7005e2d9b67b2b729af552856a2d69a43380d8e3582bf5a0844ad15b75115a79b3c343c898164ca54480b7c4111b33949585bd30e2e660344012ad27a9e85fdf6ce509e07ea1ad1d81816db8e485d029101155c57641e2839a65c77e5eb43ccd16f81f626bd74c084bacde9e7716266b39a463ab4a1f2055fbdc00c20ea10db76139a5b90e106bfa4a51f41d475c303d094b6aa0303775b834388fee4d6677e18deecb5eaf8c3d591d3cb4c956ae34c7c60fe071f5d3f19cab9a59dd9423c6e88af1fa1223501da07cc214b18724ec1c587951ba0b1dc970bda7dc0ef804fdefebadee0965e023312ab274d01ff551753dc0b7afc85e10b68a9f56428cc2267fab541213b3ce4ce53b48aec637c8ea474774f6bdaa573f4eed9fd4998559a0670d82f622dc57e6e475c63c832aa4b17c31f83ba5d7ca5db9fdc57d4dbc9e8affaad3b65d1b3c4bf0b75df9f602ac32d1ea696219afb6952a294f4b540cce84a33242e065c609afa4e97d83aed8fbc70e410bb4ac1e64656c713f72378bfbae088c13d3e8e1fadbd2f5cfa1718d26c9376cb66449aecd642d476cdd411ab79511ea6608cfc1686b83d4ea4a0f8f197a759b62753860ab0c47b8caa719338d29ee89c6953ed4beebf5685b8b2ba9eb59fcefa66329670c5fe2ca4435c41b5ec4bddd9a69aa5727f8c7026cc337e7f5ea2b85d3e6eadf65d1da59921e9601684cbd6db98176793a8a778e4f97171b0a271463c772de46a0436964b32a57a00ff7e9b78ca13c743767b460bedf3a1d701196e2a87424a7fcdfaf115afcf9476b7992addc11bf5dd4485153818ddfe711c3fc14fb30aa9336100044e5a37d30d6d246459a6c6c38a28b0ee36c5f4ded811a115f23d4853e71cfbc48617fc8d469baeafc65234b2284f93d2a41953de6549f9c41b571867bbb6ff418332d3cbcc109f85d59203bc4d222a70ef70373f65e9cf0780289af7a3d8d168265f3864c5d2e933bacfa2424be11948b89596109584ca6e8ee0144c3d99a82cfab8846844f118601ab906b0b44730d79c9169db3822060b3fe635b51c060ba336c774dd1a5612319c004cd5a626743a468607a7cce9fd29ece8b85e868444b17ce733e80d2eae2e43585ed707a50ce1b2a2173dceff5f35b4dfeb79a69e18ae83d3f8445f0dd7f896096bd7e10383a59f95db4cd85ed6e54ca1cf899e13cd8fcf8d894fdde52f8598fb1581db8f2da9bd57d644127db11aec8803135259c6cad21a3a8cb51b86f5832f74d2d7da4c00ad6e04975e7986d4d7f5182ad6ac51225ea5bf595012f4da7a714ff27a654cbc5614843c848aaa8d1e71be240742e0225408d964430303d332924cf588f4c0bfb75f32c2907095476f00465ce5377a0864ea08f2916a2194b915e61d9829ba0af574d7d8d4fc61be6557c49d9b1893796a674dcd4a2d0ab1540da21721f9ba2889d40d11d15a03f47fb9b4758fb5d396fc3ef09dd2eb17340651bbd4d4d302171b64a5d134a14c2f5761d69baf6e087645f1569ae3c9430bd62569a771c3c9d386357852630d14d59bccaae73e88e79fd335da885dbc26e317a560e886b46237a9bf974c90f17e8d1a3193eb8f6a8a4085fe6afcfc6625155f230cf95e28b02b2aa25a07dd2b9402a7e11a026050b95f200b7f559706d39de6ea5c6a3290939e06c2dca3293634d1380cbea8776653dcd705517ec2d729f81f6402d576f5dabf30f4a8cdc49be08c481f63d7595360804f33291665408c80c03c205b4f72361e2950d32c7279a81d3d6a36479bb03f1ac6bfca0e129b096f3fc11b1a31322a3603bdbcf5f25ef6983aabfde61dbbfb31aebf6a6438c0de64b0fb58146993c8339ed1575816a6db7850ad758ee3d1b493442e12deb80ae936380c081a69dfbe7b86cbb28d5c225733e9c7e7674418cc7696f6bc482688210a51cea3c76ba11c21c21d75191c1f92f2834c1a9f9c6d1be9ad98508e7b4876621c126d0a3b9432e15f6aef3241bebfc3cb8f2dab4b96f97a61ee2e7312845d3614d817793f6c40190d7b17ef2b7bfc8ce665fc927dfd178722fa98d37e58d5c3ea763893f1f46390b9e412bb7b986e6f26e6b4998a7b7252bee2a919d92a4f63bcbccf52f7a4236cac4964dce74ba8572e8481de412bb53a0ec1667d3f64526bce5b1d39b5a49449f20a6d274d55e60b0c722a8c3606a1aed9a73738d634bd51a4b4be81283351fabfe38d8bc07b96495b56be9c69adf49958224936770455c97be2e895476df55af2d69e308a5b1f898d2d60896055b8f95f99cda6c961be77245025b3aae7411644fea5d5ed7c0f9fb6a9d48af4287b4be060236cee349ec67d4e94f6da473e30d4d406d95c62c1e7814aafe12b62e4ebfa9b4421b156a67e6743bb98d4bd17da6eec1e5a6591e5b6215675d6704257ca0cd1f71717e12fb61f365c8309df3e3e7646cf2ca5bf8fbb0e602e769c5510b11bbf114744ee38b80e0200a059a64daa7b699ea04851f976a7ac131cc0e2da1375524def3476375b4c4fc0e8e9e114f8873394b2ae418d4bff3bb202b523d2b7c897bbbac4f2af74dd5887ca6f5bfdc6a379332dd8f0a6a3b5792c1f1921642c1498dc23802f39f4e43e8f51f3415daa93f1985ad00c9e8768cad571d2016f57b05337882a38ad9f4470d205b1eb895de995fe90369bf0b6c0d73c5923465938cf6750d0a46ef63875d8eb0958c48459bae7ed3d0e6f1a4ff0c876e86f23f199e98d6fc6810cc76de5161e8c5d2e502ef34cdae2115a05ce7760248fbf9d29f89d80de97a7c4ce37d6999ed4c65057c55aa5b6295e0897474a4abd86b58a630b5519e24a96a9c36481adf71efddc96315cba56b0e648dbf25530ee8f03c8433265c28cd29475daaa79058194de73ea9f6beecbfbdac88cac419f91c685e36f599e7419d1b68ee540daf765f227cd6e91a6f1a83ac16f7619fa2c96da41337d7228a77a8bbf1659a978bc7c23e5cae67323f20d9d69bf343769ee98114b192c2d8567db0a2347fd93cff02620a59c45887ca6a95b586a04bae80994c31d39264e90306f73714ccddc98ab09f33d46be27789f44508d7a4e0294ddb7a972022adef1feb4bbf80b6acb41388b29fdb5eadb1741d38ae895ec6f034d72efe08fe09efc1063a32664526e718f90d541642e7a88852594ab25eb9eab2c473f4e86ce95f9ebb533d1a8d8a592931632928a08d8377a606e099c8ad9f42dcac63554b356a129a9e9573fcfb207b27baa436c6d4ddb4f8580d914a1263461e304db5e0815f7dd9b755db529032597b77050aa6c653afe3f7d7eac9e3df2d52b926639aa3f51d8cd5471da36ecf408bd859ce900e439901bd20c3c1bf000f6e62cd234e5fa295118a5b5f55100702fdafd43a7398894f4a3dd4f74889d27294143d5f3609d97ac3323c6f3d6ecbe990dcb5d975358f54153f286e78c8cfbc76cf3e2540614252d267ac9327d13fde8abc4b282014be61a11450aa26626c478ccab01c380f39cea9dc5d67501ab68b06bdcdd25871b7f3edfdff804e86957530235d7ea279358e444c2dba830c6fd5daadf7ff821eda6d9c8f6eb4ebad0d80fc45576ab4426f0b390ce9fb42312c23430d040d85efa8cde8e1a3c47a082d33cbea897edf90b00820032156816c8cc1218b9cbc41108f910a9a072afb6d94c20b5daa083a8c6f1e49570a82b779b06e91e01eeec67ad5fcc586401c91030a8300014a92973e2b4653816cfd1866ebe6a07b7b9050176f3f0fd7deb7094b96dca67a7fab85f80275b5616414ba3d11bed295420cb62860d5a01fe557eba85cab0dfbdd4ed1d7f30cdc0540690d7bfc99ff1e594e0dd369785079e2cc436db5a506ed65677921744aab605757d8f99d80cd79397578fa17671b4b70ebdf40a36ec697ece2a6d2b170bd083c0efd515b81acdf56c750064571d635ad50165f1e98519b12655820ef9393b33d71e037d8ae46f6e9ac84b732b21008111b16796ea62181f264aaa19c362b426516c97bbdbbf0b0da0e47f805847067261b62d7d699124645c6a6a983565815e6de4fbc31263380b6dc811fa9d4c1ed15690b2dc7c1afa5a4a810ee69bb8759c898287630273ba24e0a58de5608a0b0f5b0273c930fbc6aeb8b2ec767e4b8cf94740f93edbb0277d158d33a13e5d998b5cec54b5968271a32ce79f80118678f2978011bbaa86de2c5579e966ae17c6dd435279303fcb2d1cfdffafded27c921d1feea042f83e96f01bff7fc98215044eff87f28e65559c9b030a0676eac25552b5961084f162e8bb638d52c81b091ddbdaaf684c6f1cce30ff4c8c60f55148aed8bc5894c22114a2f37c483bd9d9eb809a483f918cd901f9c48251f8dcb19f35d61bf1105ec96e66f22601575a5abeedfd08dc5ec6669790c3b47e557d391adfb259ee0c86566ea1c4a93ad18003cb35a752e91df73a688cd65b92b754071ce3f6328f76c6d6f455eae1c4cd80e2b05cc183e1dadcd83deab48dcf62d191e0f69e1ea30f050b80640b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c645236986f1affba9e034017145436f7519e5681fa5b9940890979fb54be43bbf761f7e602171fae46ac46a6b8701ff70f973a10070a0f786ee2fabd99c573c20761f7e602171fae46ac46a6b8701ff70f973a10070a0f786ee2fabd99c573c203edab1ff7eb6bf33f108e9ac1a08eb16c954b88a844e3119adf5950b44014eb63c8d900fcc619be33d08fd58502389ad641764bcccc2649d0c88659fc24b6d7be234489f88176e66bd858291d9de7054c6bdcedbb9f19ebedfab02d238b3dad79ac6a853e324ff7c5e92f5e9bbbfcda63466ec3e8a17fd9b3247f183465e93ca372fd5afc77f0d7f38658bb86153e8c7472376a5d735412237aea47881eb714ad1ffba188101427d74509d8786310f1e0793a251f31819283664626cbb6286bcdd109bc3de5bef59a8492c6f849e7cf1c2a665d6b5844e749d36a714fc4eb8f652fe79b889ef808d2d515a143bd50327674d18780056158238e627e37eaf784b4505976a7c3561f4c11d3d6507b4c18b802110be70e1266ecd65aa25fca95101a77e1f35756774bd632f5c4eb2c37314911471375f8123b8c3fc9ea3a5c0cc6d9b188fe909be6889a961ab6d53b11520bc8ef965b7387b554bd7c482b02b0f4f80d00110a008aff7aed1c6d66dfb2edfa2605d155c2d97a1c2877fd1bf4d770e6708988dc83ba66d6a40a20293dfee564ed40c41d5e541c2997e512019841b0b19fb878199014dea84874d11e319609135d4251944a93718a1549871f86355fe28ef6282e43d78006dfed31b909d581b41acb46b9a049d7babd678a808a8b42ef723c6b3654d1ff2ac20fe4e91db0ffb8387d06864cabae9e45d13b197ef3dcccc6b0296da09999c1156c66710e48fad121d7a7eb3f20a9281c83c7715e7f759dd2b11d8da24b078973a81d23f56a3cd370391c47ad7ea923f5233254b2c62a41ea39a3c45f364074338dbc792fc2c11e46cd8506f84eec2d00b8b7cd076d84a54a4e74dfb2af63dad0b61ff21f4f95994201c284fe8f586948c544ff57e966e81d01c4e3d56cb060111b09771b67ad0ce7c76f75907623f84b05a05d45611f5bc55eab02c151e601843afc2885ab9824b294c7d32e6352066793e8ccf6663071d70e16fed8696139a12f8dc737261cc47235f1f6043d92c85ee5f87b03e8429862ec396b133cb906d4fc51662f88cdb3cd527f0c6b7012ed9be804ded9422125eb5dc9143c8d61b9b80d5cf522b829938f539a301cd22e79e52f6213df15534953e17076aff00521a5402e73915fd843905ff5a92e6db5564e3ddd38febf2dc5d98f8fed85c6075f8b02b13976a0930190debfc8b9465651dd71ce4610e5dd7b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c6f0f73a33836688f5f01e1ec80ba5725affffe64d3ca9d151d5ffbaf1d6317b22@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootselinux-policy-3.13.1-268.el7.src.rpmselinux-policy-devel       /bin/sh/usr/bin/makecheckpolicym4policycoreutils-develrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)selinux-policyrpmlib(PayloadIsXz)2.5-82.5-243.0.4-14.6.0-14.0.4-14.0-13.13.1-268.el75.2-14.11.3^^x]µ]]{@]{@]]c@]n]V]V]S]R@]Ik]:@]5@]%@]\F@\\9\@\ޢ@\\@\@\7\@\\~d\y\s\k\V\R@\R@\@n@\;(@\2[v[[;@[;@[[R@[t[#@[@[@[[h@[[[9@[@[}P@[{[{[z@[m~@[i[i[i[dC[`O@[]@[Y[6@[3|@[2*["X[d@[[ [ L@[[[@[ZmZȲZZH@Z@ZZz@Zz@ZyZ_:ZWQZV@Z.s@Z)-@Z%8ZZ @ZZNZNYYA@YYW@YW@YYY@Y@Ycl@YP@YJ_YI@YBvY9<@Y6@Y5GY1S@Y0Y.@Y-^Y, @Y, @Y%uYYY@Y@Y@Y.YXQ@XXX@X@X@XXX@XۡXP@XXg@Xg@X~@X@XƉXCXCXX @XXXBXXXs{@XY@XWXRXRXOXJXAb@X@X)@X#X!@XWWSW_@W_@Wv@W;W@WίWW:WQW@WW@W@WW~W@WW~D@W{@Ws@WrfWj}WbW^@WYZ@WYZ@WUeWM|WBW9@W9@W1@W(W V@V@V@V޾V2V@V_VVCV@VZV @VqV }@V }@VBUUU@U@UpUUUUoUoU5@UUȒ@UĝUUWUU@UUK@UUU'Ua@U~@UzUv@UT@U@Tr@T@T@T7TTTC@T@TTT}Tto@TsTk4T`T[bTWn@T?@T>aT6xT6xT@S@SSDSg}@SB@S>S;S:@S9XS5d@S4S2@S0@S,)S*@S)S)S&S&S"@S!S L@SSS@SSc@SSnS @S SK@RRR@RRJ@Ra@RRR&R&RRR=RʚRR@R@R@Rv@Rv@R@RR@R R@R@R|@Rz/@Rz/@RsRpRnQRi RfhR_@R_@R[R[RSRNRNRL RIgRB@RB@R:@R1R-@R-@R(r@R' R%@R7RRNRR@Q@QQdQQ@QQޞ@Q@QکQکQ@QzQQ4Q@@Q@QKQQ@Q@Q@Q@QQ@QQQQ@Q@QQQ@Qzl@Qw@QvwQo@Qo@QnQm=@QkQfQb@Q`@Q^QZ@QQQIQGQ@j@Q9Q8@Q4Q0@Q-@Q& @Q$QQ@QQ@Q @Qh@QsPP@P@PP@P[PP!@P8@PO@P @Pf@PPqP @PP7@P@PPPYP@P@PPPM@PPd@P@PoP{@P{@P@PP5@P@P~P}L@Px@PvPvPuc@Puc@Pr@Pmz@Pmz@Pmz@Pj@Pd?Pd?Pb@PaPaP[@PXb@PWPS@PQPO'PM@PIP@@P>@P8@P7lP2&P2&P,P,P*=P(@P#@P#@P!@P!@P@PkPw@Pw@PP

@NNU@NNl@N@N@NåN@NNNN@NNN@N@NGNGNGN@N@NNS@NS@N^N^N @N @NNj@Nj@NN$@NN@N/N@N@NFNFN@NNN@N@N@N]Ni@Ni@Ni@N|tNyNx@Ns:@NoENoENiNf @N^"@N\N[@NTNS@NS@NC@NBrN:N98@N7N6@N2N.@N*N)f@N(N%qN$ @N@N7@N e@NpNpM@M@Md@Md@MM{@M@M۝M@M@M‘@M@M@M@My@My@M3@M@M@MMM@MMMMTMx@Mx@Mv@MlMbSM[@MRMQ0@MQ0@MJMGMGMA^@M>@M9u@M6@M5M4/@M4/@M0:M,F@M$]@M@M9MMMMM\@M M M@L!L!L@LL@L@L@LOLOL[@L@L@Lr@L L,@L,@Lډ@L7LLLNL@LΫLeL|L@LB@LB@LB@L@LMLL@LdLL{L*@L@L5LLA@LLLL@LcL@L@L@LzL)@L|L|L|L{@LvW@LvW@Ls@Ls@LrbLrbLmLk@LjyLe3Lc@La?@LZLYV@LXLN@LN@LMxLMxLI@LH2LF@LEL=L=L=L;L7@L LT@L@LL@L@L0LLGL@K^K^KKKj@K$@KKK@K@KK@K]K޺K@KtK#@KKՀ@K:@KK͗@KŮ@K\K\K @KKKKK9@KK@KK@K@KKKKrKK~@K,K,K,K@KK8@KKK@KK@KqKqK}+K{@K{@KuBKs@KqN@KjKie@Kf@Ka|@K`*K]KXAKTM@KPXKEKEKEKD{@KC)KA@K;@K2@K0K/c@K+nK*@K(K"4@KK>K>K>JJęJH@JH@JJJ_@J@JjJjJ@Jv@Jv@Jv@Jv@J$J@JJ0@J@J@JG@JG@J@JJ@J@J@JJJ#J@JJJ@J:J@JJQJ@J J J|@JzJyt@Jyt@Jx"JrJrJq@Jn@Jn@JmJhPJeJ\s@JW-@JT@JS8JKOJI@JCfJCfJB@J@J@J?r@J<@J;}J:,@J7@J67J2C@J0J/@J,@J%@JJB@JJMJ J dJ@J@JJ@J*@J*@II@IIA@IIII@I@IIIX@IX@IX@II@I@IcIIo@Io@IzI)@I@IܑI@@II@I@I@IԨIд@I̿In@I3I3I@II@I@IV@IIaIIm@I@I'@II2III@IIIIIIII@III@I1I@III~@I}Iy@Ix_Iw@IuItk@Itk@Io%@Ik0IeIcGIa@I`IVIO@IJ;@IHIAI>]I= @I7@I6tI3I-I@III9@I9@II IP@I@IIg@Ig@HHH@HrH~@H,H@HCHHH @H @Hf@Hf@H@H+H@H׈H׈H7@HBH@HǶH@HH|@HHH@H{@H)HHL@H@H@H@HnH}H|@Ht@HsVHr@Hl@HkmHgy@HcH`H_@H^>HRa@HQHQHO@HFHFH$@DX@DU@DN@DN@DLDH@DGwDGwDDD@@D?D?D;@D;@D:HD:HD2_D1@D1@D-D+@D+@D'D!<@D!<@D!<@DDD@D@D@DDDDDD@D@D@D@D uD $@D D @D @DDDFC@C@C@C@CCCCCR@CCCCC@Ci@CC@C@CtC@C@CC:@CECCC @C @CعCعCعCعCC@C-C-C-C@C@CCǖ@C@CáCáCP@CP@C[C @C @CCg@Cg@CCC!@C~@C,C@CCCCC@CC@C@C@CZCZC @C @CCCf@Cf@Cf@CC@CqCqC @C @C @CCC}@C7@C7@C7@CBCBCYC@C@CC}@CqCqZdenek Pytela - 3.13.1-268Zdenek Pytela - 3.13.1-267Lukas Vrabec - 3.13.1-266Lukas Vrabec - 3.13.1-265Lukas Vrabec - 3.13.1-264Lukas Vrabec - 3.13.1-263Lukas Vrabec - 3.13.1-262Lukas Vrabec - 3.13.1-261Lukas Vrabec - 3.13.1-260Lukas Vrabec - 3.13.1-259Lukas Vrabec - 3.13.1-258Lukas Vrabec - 3.13.1-257Lukas Vrabec - 3.13.1-256Lukas Vrabec - 3.13.1-255Lukas Vrabec - 3.13.1-254Lukas Vrabec - 3.13.1-253Lukas Vrabec - 3.13.1-252.1Lukas Vrabec - 3.13.1-252Lukas Vrabec - 3.13.1-251Lukas Vrabec - 3.13.1-250Lukas Vrabec - 3.13.1-249Lukas Vrabec - 3.13.1-248Lukas Vrabec - 3.13.1-247Lukas Vrabec - 3.13.1-246Lukas Vrabec - 3.13.1-245Lukas Vrabec - 3.13.1-244Lukas Vrabec - 3.13.1-243Lukas Vrabec - 3.13.1-242Lukas Vrabec - 3.13.1-241Lukas Vrabec - 3.13.1-240Lukas Vrabec - 3.13.1-239Lukas Vrabec - 3.13.1-238Lukas Vrabec - 3.13.1-237Lukas Vrabec - 3.13.1-236Lukas Vrabec - 3.13.1-235Lukas Vrabec - 3.13.1-234Lukas Vrabec - 3.13.1-233Lukas Vrabec - 3.13.1-232Lukas Vrabec - 3.13.1-231Lukas Vrabec - 3.13.1-230Lukas Vrabec - 3.13.1-229.5Lukas Vrabec - 3.13.1-229.4Lukas Vrabec - 3.13.1-229.3Lukas Vrabec - 3.13.1-229.2Lukas Vrabec - 3.13.1-229.1Lukas Vrabec - 3.13.1-229Lukas Vrabec - 3.13.1-228Lukas Vrabec - 3.13.1-227Lukas Vrabec - 3.13.1-226Lukas Vrabec - 3.13.1-225Lukas Vrabec - 3.13.1-224Lukas Vrabec - 3.13.1-223Lukas Vrabec - 3.13.1-222Lukas Vrabec - 3.13.1-221Lukas Vrabec - 3.13.1-220Lukas Vrabec - 3.13.1-219Lukas Vrabec - 3.13.1-218Lukas Vrabec - 3.13.1-217Lukas Vrabec - 3.13.1-216Lukas Vrabec - 3.13.1-215Lukas Vrabec - 3.13.1-214Lukas Vrabec - 3.13.1-213Lukas Vrabec - 3.13.1-212Lukas Vrabec - 3.13.1-211Lukas Vrabec - 3.13.1-210Lukas Vrabec - 3.13.1-209Lukas Vrabec - 3.13.1-208Lukas Vrabec - 3.13.1-207Lukas Vrabec - 3.13.1-206Lukas Vrabec - 3.13.1-205Lukas Vrabec - 3.13.1-204Lukas Vrabec - 3.13.1-203Lukas Vrabec - 3.13.1-202Lukas Vrabec - 3.13.1-201Lukas Vrabec - 3.13.1-200Lukas Vrabec - 3.13.1-199Lukas Vrabec - 3.13.1-198Lukas Vrabec - 3.13.1-197Lukas Vrabec - 3.13.1-196Lukas Vrabec - 3.13.1-195Lukas Vrabec - 3.13.1-194Lukas Vrabec - 3.13.1-193Lukas Vrabec - 3.13.1-192Lukas Vrabec - 3.13.1-191Lukas Vrabec - 3.13.1-190Lukas Vrabec - 3.13.1-189Lukas Vrabec - 3.13.1-188Lukas Vrabec - 3.13.1-187Lukas Vrabec - 3.13.1-186Lukas Vrabec - 3.13.1-185Lukas Vrabec - 3.13.1-184Lukas Vrabec - 3.13.1-183Lukas Vrabec - 3.13.1-182Lukas Vrabec - 3.13.1-181Lukas Vrabec - 3.13.1-180Lukas Vrabec - 3.13.1-179Lukas Vrabec - 3.13.1-178Lukas Vrabec - 3.13.1-177Lukas Vrabec - 3.13.1-176Lukas Vrabec - 3.13.1-175Lukas Vrabec - 3.13.1-174Lukas Vrabec - 3.13.1-173Lukas Vrabec - 3.13.1-172Lukas Vrabec - 3.13.1-171Lukas Vrabec - 3.13.1-170Lukas Vrabec - 3.13.1-169Lukas Vrabec - 3.13.1-168Lukas Vrabec - 3.13.1-167Lukas Vrabec - 3.13.1-166Lukas Vrabec - 3.13.1-165Lukas Vrabec - 3.13.1-164Lukas Vrabec - 3.13.1-163Lukas Vrabec - 3.13.1-162Lukas Vrabec - 3.13.1-161Lukas Vrabec - 3.13.1-160Lukas Vrabec - 3.13.1-159Lukas Vrabec - 3.13.1-158Lukas Vrabec - 3.13.1-157Lukas Vrabec - 3.13.1-156Lukas Vrabec - 3.13.1-155Lukas Vrabec - 3.13.1-154Lukas Vrabec - 3.13.1-153Lukas Vrabec - 3.13.1-152Lukas Vrabec - 3.13.1-151Lukas Vrabec - 3.13.1-150Lukas Vrabec - 3.13.1-149Lukas Vrabec - 3.13.1-148Lukas Vrabec - 3.13.1-147Lukas Vrabec - 3.13.1-146Lukas Vrabec - 3.13.1-145Lukas Vrabec - 3.13.1-144Lukas Vrabec - 3.13.1-143Lukas Vrabec - 3.13.1-142Lukas Vrabec - 3.13.1-141Lukas Vrabec - 3.13.1-140Lukas Vrabec - 3.13.1-139Lukas Vrabec - 3.13.1-138Lukas Vrabec - 3.13.1-137Lukas Vrabec - 3.13.1-136Lukas Vrabec - 3.13.1-135Lukas Vrabec - 3.13.1-134Lukas Vrabec - 3.13.1-133Lukas Vrabec - 3.13.1-132Lukas Vrabec - 3.13.1-131Lukas Vrabec - 3.13.1-130Lukas Vrabec - 3.13.1-129Lukas Vrabec - 3.13.1-128Lukas Vrabec - 3.13.1-127Lukas Vrabec - 3.13.1-126Lukas Vrabec - 3.13.1-125Lukas Vrabec - 3.13.1-124Lukas Vrabec - 3.13.1-123Lukas Vrabec - 3.13.1-122Lukas Vrabec - 3.13.1-120Lukas Vrabec - 3.13.1-119Lukas Vrabec - 3.13.1-118Lukas Vrabec - 3.13.1-117Lukas Vrabec - 3.13.1-116Lukas Vrabec - 3.13.1-115Lukas Vrabec - 3.13.1-114Lukas Vrabec - 3.13.1-113Lukas Vrabec - 3.13.1-112Lukas Vrabec - 3.13.1-111Lukas Vrabec - 3.13.1-110Lukas Vrabec - 3.13.1-109Lukas Vrabec - 3.13.1-108Lukas Vrabec - 3.13.1-107Lukas Vrabec - 3.13.1-106Miroslav Grepl - 3.13.1-105Lukas Vrabec - 3.13.1-104Lukas Vrabec - 3.13.1-103Dan Walsh - 3.13.1-102Lukas Vrabec - 3.13.1-101Lukas Vrabec - 3.13.1-100Lukas Vrabec - 3.13.1-99Lukas Vrabec - 3.13.1-98Lukas Vrabec - 3.13.1-97Lukas Vrabec - 3.13.1-96Lukas Vrabec - 3.13.1-95Lukas Vrabec - 3.13.1-94Lukas Vrabec - 3.13.1-93Lukas Vrabec - 3.13.1-92Lukas Vrabec - 3.13.1-91Lukas Vrabec - 3.13.1-90Lukas Vrabec - 3.13.1-89Lukas Vrabec - 3.13.1-88Lukas Vrabec - 3.13.1-87Lukas Vrabec - 3.13.1-86Lukas Vrabec - 3.13.1-85Lukas Vrabec - 3.13.1-84Lukas Vrabec - 3.13.1-83Lukas Vrabec - 3.13.1-82Lukas Vrabec - 3.13.1-81Lukas Vrabec - 3.13.1-80Petr Lautrbach - 3.13.1-79Lukas Vrabec - 3.13.1-78Lukas Vrabec - 3.13.1-77Lukas Vrabec - 3.13.1-76Lukas Vrabec - 3.13.1-75Lukas Vrabec - 3.13.1-74Lukas Vrabec - 3.13.1-73Lukas Vrabec - 3.13.1-72Lukas Vrabec - 3.13.1-71Lukas Vrabec - 3.13.1-70Lukas Vrabec - 3.13.1-69Lukas Vrabec - 3.13.1-68Lukas Vrabec - 3.13.1-67Petr Lautrbach - 3.13.1-66Lukas Vrabec 3.13.1-65Lukas Vrabec 3.13.1-64Lukas Vrabec 3.13.1-63Lukas Vrabec 3.13.1-62Lukas Vrabec 3.13.1-61Miroslav Grepl 3.13.1-60Miroslav Grepl 3.13.1-59Lukas Vrabec 3.13.1-58Lukas Vrabec 3.13.1-57Miroslav Grepl 3.13.1-56Lukas Vrabec 3.13.1-55Lukas Vrabec 3.13.1-54Lukas Vrabec 3.13.1-53Lukas Vrabec 3.13.1-52Miroslav Grepl 3.13.1-51Lukas Vrabec 3.13.1-50Lukas Vrabec 3.13.1-49Lukas Vrabec 3.13.1-48Lukas Vrabec 3.13.1-47Lukas Vrabec 3.13.1-46Lukas Vrabec 3.13.1-45Lukas Vrabec 3.13.1-44Lukas Vrabec 3.13.1-43Lukas Vrabec 3.13.1-42Lukas Vrabec 3.13.1-41Lukas Vrabec 3.13.1-40Miroslav Grepl 3.13.1-39Lukas Vrabec 3.13.1-38Lukas Vrabec 3.13.1-37Lukas Vrabec 3.13.1-36Lukas Vrabec 3.13.1-35Lukas Vrabec 3.13.1-34Lukas Vrabec 3.13.1-33Lukas Vrabec 3.13.1-32Miroslav Grepl 3.13.1-31Miroslav Grepl 3.13.1-30Miroslav Grepl 3.13.1-29Miroslav Grepl 3.13.1-28Miroslav Grepl 3.13.1-27Miroslav Grepl 3.13.1-26Miroslav Grepl 3.13.1-25Miroslav Grepl 3.13.1-24Miroslav Grepl 3.13.1-23Miroslav Grepl 3.13.1-22Miroslav Grepl 3.13.1-21Miroslav Grepl 3.13.1-20Miroslav Grepl 3.13.1-19Miroslav Grepl 3.13.1-18Miroslav Grepl 3.13.1-17Miroslav Grepl 3.13.1-16Miroslav Grepl 3.13.1-15Miroslav Grepl 3.13.1-14Miroslav Grepl 3.13.1-13Miroslav Grepl 3.13.1-12Miroslav Grepl 3.13.1-11Miroslav Grepl 3.13.1-10Miroslav Grepl 3.13.1-9Miroslav Grepl 3.13.1-8Miroslav Grepl 3.13.1-7Miroslav Grepl 3.13.1-6Miroslav Grepl 3.13.1-5Miroslav Grepl 3.13.1-4Miroslav Grepl 3.13.1-3Miroslav Grepl 3.13.1-2Miroslav Grepl 3.13.1-1Miroslav Grepl 3.12.1-156Miroslav Grepl 3.12.1-155Miroslav Grepl 3.12.1-154Miroslav Grepl 3.12.1-153Miroslav Grepl 3.12.1-152Miroslav Grepl 3.12.1-151Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-148Miroslav Grepl 3.12.1-147Miroslav Grepl 3.12.1-146Miroslav Grepl 3.12.1-145Miroslav Grepl 3.12.1-144Lukas Vrabec 3.12.1-143Miroslav Grepl 3.12.1-142Miroslav Grepl 3.12.1-141Miroslav Grepl 3.12.1-140Miroslav Grepl 3.12.1-139Lukas Vrabec 3.12.1-138Miroslav Grepl 3.12.1-137Miroslav Grepl 3.12.1-136Miroslav Grepl 3.12.1-135Miroslav Grepl 3.12.1-134Miroslav Grepl 3.12.1-133Miroslav Grepl 3.12.1-132Miroslav Grepl 3.12.1-131Miroslav Grepl 3.12.1-130Miroslav Grepl 3.12.1-129Miroslav Grepl 3.12.1-128Miroslav Grepl 3.12.1-127Miroslav Grepl 3.12.1-126Miroslav Grepl 3.12.1-125Miroslav Grepl 3.12.1-124Miroslav Grepl 3.12.1-123Miroslav Grepl 3.12.1-122Miroslav Grepl 3.12.1-121Miroslav Grepl 3.12.1-120Miroslav Grepl 3.12.1-119Miroslav Grepl 3.12.1-118Miroslav Grepl 3.12.1-117Miroslav Grepl 3.12.1-116Miroslav Grepl 3.12.1-115Miroslav Grepl 3.12.1-114Miroslav Grepl 3.12.1-113Miroslav Grepl 3.12.1-112Miroslav Grepl 3.12.1-111Miroslav Grepl 3.12.1-110Miroslav Grepl 3.12.1-109Miroslav Grepl 3.12.1-108Miroslav Grepl 3.12.1-107Dan Walsh 3.12.1-106Miroslav Grepl 3.12.1-105Miroslav Grepl 3.12.1-104Miroslav Grepl 3.12.1-103Miroslav Grepl 3.12.1-102Miroslav Grepl 3.12.1-101Miroslav Grepl 3.12.1-100Miroslav Grepl 3.12.1-99Miroslav Grepl 3.12.1-98Miroslav Grepl 3.12.1-97Miroslav Grepl 3.12.1-96Miroslav Grepl 3.12.1-95Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-93Miroslav Grepl 3.12.1-92Miroslav Grepl 3.12.1-91Miroslav Grepl 3.12.1-90Miroslav Grepl 3.12.1-89Miroslav Grepl 3.12.1-88Miroslav Grepl 3.12.1-87Miroslav Grepl 3.12.1-86Miroslav Grepl 3.12.1-85Miroslav Grepl 3.12.1-84Miroslav Grepl 3.12.1-83Miroslav Grepl 3.12.1-82Miroslav Grepl 3.12.1-81Miroslav Grepl 3.12.1-80Miroslav Grepl 3.12.1-79Miroslav Grepl 3.12.1-78Miroslav Grepl 3.12.1-77Miroslav Grepl 3.12.1-76Miroslav Grepl 3.12.1-75Miroslav Grepl 3.12.1-74Miroslav Grepl 3.12.1-73Miroslav Grepl 3.12.1-72Miroslav Grepl 3.12.1-71Miroslav Grepl 3.12.1-70Miroslav Grepl 3.12.1-69Miroslav Grepl 3.12.1-68Miroslav Grepl 3.12.1-67Miroslav Grepl 3.12.1-66Miroslav Grepl 3.12.1-65Miroslav Grepl 3.12.1-64Miroslav Grepl 3.12.1-63Miroslav Grepl 3.12.1-62Miroslav Grepl 3.12.1-61Miroslav Grepl 3.12.1-60Miroslav Grepl 3.12.1-59Miroslav Grepl 3.12.1-58Miroslav Grepl 3.12.1-57Miroslav Grepl 3.12.1-56Miroslav Grepl 3.12.1-55Miroslav Grepl 3.12.1-54Miroslav Grepl 3.12.1-53Miroslav Grepl 3.12.1-52Miroslav Grepl 3.12.1-51Miroslav Grepl 3.12.1-50Miroslav Grepl 3.12.1-49Miroslav Grepl 3.12.1-48Miroslav Grepl 3.12.1-47Miroslav Grepl 3.12.1-46Miroslav Grepl 3.12.1-45Miroslav Grepl 3.12.1-44Miroslav Grepl 3.12.1-43Miroslav Grepl 3.12.1-42Miroslav Grepl 3.12.1-41Miroslav Grepl 3.12.1-40Miroslav Grepl 3.12.1-39Miroslav Grepl 3.12.1-38Miroslav Grepl 3.12.1-37Miroslav Grepl 3.12.1-36Miroslav Grepl 3.12.1-35Miroslav Grepl 3.12.1-34Miroslav Grepl 3.12.1-33Miroslav Grepl 3.12.1-32Miroslav Grepl 3.12.1-31Miroslav Grepl 3.12.1-30Miroslav Grepl 3.12.1-29Dan Walsh 3.12.1-28Dan Walsh 3.12.1-27Miroslav Grepl 3.12.1-26Miroslav Grepl 3.12.1-25Miroslav Grepl 3.12.1-24Miroslav Grepl 3.12.1-23Miroslav Grepl 3.12.1-22Miroslav Grepl 3.12.1-21Miroslav Grepl 3.12.1-20Miroslav Grepl 3.12.1-19Miroslav Grepl 3.12.1-18Miroslav Grepl 3.12.1-17Miroslav Grepl 3.12.1-16Miroslav Grepl 3.12.1-15Miroslav Grepl 3.12.1-14Miroslav Grepl 3.12.1-13Miroslav Grepl 3.12.1-12Miroslav Grepl 3.12.1-11Miroslav Grepl 3.12.1-10Miroslav Grepl 3.12.1-9Miroslav Grepl 3.12.1-8Miroslav Grepl 3.12.1-7Miroslav Grepl 3.12.1-6Miroslav Grepl 3.12.1-5Miroslav Grepl 3.12.1-4Miroslav Grepl 3.12.1-3Miroslav Grepl 3.12.1-2Miroslav Grepl 3.12.1-1Dan Walsh 3.11.1-69.1Miroslav Grepl 3.11.1-69Miroslav Grepl 3.11.1-68Miroslav Grepl 3.11.1-67Miroslav Grepl 3.11.1-66Miroslav Grepl 3.11.1-65Miroslav Grepl 3.11.1-64Miroslav Grepl 3.11.1-63Miroslav Grepl 3.11.1-62Miroslav Grepl 3.11.1-61Miroslav Grepl 3.11.1-60Miroslav Grepl 3.11.1-59Miroslav Grepl 3.11.1-58Miroslav Grepl 3.11.1-57Miroslav Grepl 3.11.1-56Miroslav Grepl 3.11.1-55Miroslav Grepl 3.11.1-54Miroslav Grepl 3.11.1-53Miroslav Grepl 3.11.1-52Miroslav Grepl 3.11.1-51Miroslav Grepl 3.11.1-50Miroslav Grepl 3.11.1-49Miroslav Grepl 3.11.1-48Miroslav Grepl 3.11.1-47Miroslav Grepl 3.11.1-46Miroslav Grepl 3.11.1-45Miroslav Grepl 3.11.1-44Miroslav Grepl 3.11.1-43Miroslav Grepl 3.11.1-42Miroslav Grepl 3.11.1-41Miroslav Grepl 3.11.1-40Miroslav Grepl 3.11.1-39Miroslav Grepl 3.11.1-38Miroslav Grepl 3.11.1-37Miroslav Grepl 3.11.1-36Miroslav Grepl 3.11.1-35Miroslav Grepl 3.11.1-34Miroslav Grepl 3.11.1-33Miroslav Grepl 3.11.1-32Miroslav Grepl 3.11.1-31Miroslav Grepl 3.11.1-30Miroslav Grepl 3.11.1-29Miroslav Grepl 3.11.1-28Miroslav Grepl 3.11.1-27Miroslav Grepl 3.11.1-26Miroslav Grepl 3.11.1-25Miroslav Grepl 3.11.1-24Miroslav Grepl 3.11.1-23Miroslav Grepl 3.11.1-22Miroslav Grepl 3.11.1-21Miroslav Grepl 3.11.1-20Miroslav Grepl 3.11.1-19Miroslav Grepl 3.11.1-18Miroslav Grepl 3.11.1-17Miroslav Grepl 3.11.1-16Dan Walsh 3.11.1-15Miroslav Grepl 3.11.1-14Dan Walsh 3.11.1-13Miroslav Grepl 3.11.1-12Miroslav Grepl 3.11.1-11Miroslav Grepl 3.11.1-10Dan Walsh 3.11.1-9Dan Walsh 3.11.1-8Dan Walsh 3.11.1-7Dan Walsh 3.11.1-6Miroslav Grepl 3.11.1-5Miroslav Grepl 3.11.1-4Miroslav Grepl 3.11.1-3Miroslav Grepl 3.11.1-2Miroslav Grepl 3.11.1-1Miroslav Grepl 3.11.1-0Miroslav Grepl 3.11.0-15Miroslav Grepl 3.11.0-14Miroslav Grepl 3.11.0-13Miroslav Grepl 3.11.0-12Fedora Release Engineering - 3.11.0-11Miroslav Grepl 3.11.0-10Miroslav Grepl 3.11.0-9Miroslav Grepl 3.11.0-8Miroslav Grepl 3.11.0-7Miroslav Grepl 3.11.0-6Miroslav Grepl 3.11.0-5Miroslav Grepl 3.11.0-4Miroslav Grepl 3.11.0-3Miroslav Grepl 3.11.0-2Miroslav Grepl 3.11.0-1Miroslav Grepl 3.10.0-128Miroslav Grepl 3.10.0-127Miroslav Grepl 3.10.0-126Miroslav Grepl 3.10.0-125Miroslav Grepl 3.10.0-124Miroslav Grepl 3.10.0-123Miroslav Grepl 3.10.0-122Miroslav Grepl 3.10.0-121Miroslav Grepl 3.10.0-120Miroslav Grepl 3.10.0-119Miroslav Grepl 3.10.0-118Miroslav Grepl 3.10.0-117Miroslav Grepl 3.10.0-116Miroslav Grepl 3.10.0-115Miroslav Grepl 3.10.0-114Miroslav Grepl 3.10.0-113Miroslav Grepl 3.10.0-112Miroslav Grepl 3.10.0-111Miroslav Grepl 3.10.0-110Miroslav Grepl 3.10.0-109Miroslav Grepl 3.10.0-108Miroslav Grepl 3.10.0-107Miroslav Grepl 3.10.0-106Miroslav Grepl 3.10.0-105Miroslav Grepl 3.10.0-104Miroslav Grepl 3.10.0-103Miroslav Grepl 3.10.0-102Miroslav Grepl 3.10.0-101Miroslav Grepl 3.10.0-100Miroslav Grepl 3.10.0-99Miroslav Grepl 3.10.0-98Miroslav Grepl 3.10.0-97Miroslav Grepl 3.10.0-96Miroslav Grepl 3.10.0-95Miroslav Grepl 3.10.0-94Miroslav Grepl 3.10.0-93Miroslav Grepl 3.10.0-92Miroslav Grepl 3.10.0-91Miroslav Grepl 3.10.0-90Miroslav Grepl 3.10.0-89Miroslav Grepl 3.10.0-88Miroslav Grepl 3.10.0-87Miroslav Grepl 3.10.0-86Miroslav Grepl 3.10.0-85Miroslav Grepl 3.10.0-84Miroslav Grepl 3.10.0-83Miroslav Grepl 3.10.0-82Dan Walsh 3.10.0-81.2Miroslav Grepl 3.10.0-81Miroslav Grepl 3.10.0-80Miroslav Grepl 3.10.0-79Miroslav Grepl 3.10.0-78Miroslav Grepl 3.10.0-77Miroslav Grepl 3.10.0-76Miroslav Grepl 3.10.0-75Dan Walsh 3.10.0-74.2Miroslav Grepl 3.10.0-74Miroslav Grepl 3.10.0-73Miroslav Grepl 3.10.0-72Miroslav Grepl 3.10.0-71Miroslav Grepl 3.10.0-70Miroslav Grepl 3.10.0-69Miroslav Grepl 3.10.0-68Miroslav Grepl 3.10.0-67Miroslav Grepl 3.10.0-66Miroslav Grepl 3.10.0-65Miroslav Grepl 3.10.0-64Miroslav Grepl 3.10.0-63Miroslav Grepl 3.10.0-59Miroslav Grepl 3.10.0-58Dan Walsh 3.10.0-57Dan Walsh 3.10.0-56Dan Walsh 3.10.0-55.2Dan Walsh 3.10.0-55.1Miroslav Grepl 3.10.0-55Dan Walsh 3.10.0-54.1Miroslav Grepl 3.10.0-54Dan Walsh 3.10.0-53.1Miroslav Grepl 3.10.0-53Miroslav Grepl 3.10.0-52Miroslav Grepl 3.10.0-51Dan Walsh 3.10.0-50.2Dan Walsh 3.10.0-50.1Miroslav Grepl 3.10.0-50Miroslav Grepl 3.10.0-49Miroslav Grepl 3.10.0-48Miroslav Grepl 3.10.0-47Dan Walsh 3.10.0-46.1Miroslav Grepl 3.10.0-46Dan Walsh 3.10.0-45.1Miroslav Grepl 3.10.0-45Miroslav Grepl 3.10.0-43Miroslav Grepl 3.10.0-42Miroslav Grepl 3.10.0-41Dan Walsh 3.10.0-40.2Miroslav Grepl 3.10.0-40Dan Walsh 3.10.0-39.3Dan Walsh 3.10.0-39.2Dan Walsh 3.10.0-39.1Miroslav Grepl 3.10.0-39Dan Walsh 3.10.0-38.1Miroslav Grepl 3.10.0-38Miroslav Grepl 3.10.0-37Dan Walsh 3.10.0-36.1Miroslav Grepl 3.10.0-36Dan Walsh 3.10.0-35Dan Walsh 3.10.0-34.7Dan Walsh 3.10.0-34.6Dan Walsh 3.10.0-34.4Miroslav Grepl 3.10.0-34.3Dan Walsh 3.10.0-34.2Dan Walsh 3.10.0-34.1Miroslav Grepl 3.10.0-34Miroslav Grepl 3.10.0-33Dan Walsh 3.10.0-31.1Miroslav Grepl 3.10.0-31Miroslav Grepl 3.10.0-29Miroslav Grepl 3.10.0-28Miroslav Grepl 3.10.0-27Miroslav Grepl 3.10.0-26Miroslav Grepl 3.10.0-25Miroslav Grepl 3.10.0-24Miroslav Grepl 3.10.0-23Miroslav Grepl 3.10.0-22Miroslav Grepl 3.10.0-21Dan Walsh 3.10.0-20Miroslav Grepl 3.10.0-19Miroslav Grepl 3.10.0-18Miroslav Grepl 3.10.0-17Miroslav Grepl 3.10.0-16Miroslav Grepl 3.10.0-14Miroslav Grepl 3.10.0-13Miroslav Grepl 3.10.0-12Miroslav Grepl 3.10.0-11Miroslav Grepl 3.10.0-10Miroslav Grepl 3.10.0-9Miroslav Grepl 3.10.0-8Miroslav Grepl 3.10.0-7Miroslav Grepl 3.10.0-6Miroslav Grepl 3.10.0-5Miroslav Grepl 3.10.0-4Miroslav Grepl 3.10.0-3Miroslav Grepl 3.10.0-2Miroslav Grepl 3.10.0-1Miroslav Grepl 3.9.16-30Dan Walsh 3.9.16-29.1Miroslav Grepl 3.9.16-29Dan Walsh 3.9.16-28.1Miroslav Grepl 3.9.16-27Miroslav Grepl 3.9.16-26Miroslav Grepl 3.9.16-25Miroslav Grepl 3.9.16-24Miroslav Grepl 3.9.16-23Miroslav Grepl 3.9.16-22Miroslav Grepl 3.9.16-21Miroslav Grepl 3.9.16-20Miroslav Grepl 3.9.16-19Miroslav Grepl 3.9.16-18Miroslav Grepl 3.9.16-17Dan Walsh 3.9.16-16.1Miroslav Grepl 3.9.16-16Miroslav Grepl 3.9.16-15Miroslav Grepl 3.9.16-14Miroslav Grepl 3.9.16-13Miroslav Grepl 3.9.16-12Miroslav Grepl 3.9.16-11Miroslav Grepl 3.9.16-10Miroslav Grepl 3.9.16-7Miroslav Grepl 3.9.16-6Miroslav Grepl 3.9.16-5Miroslav Grepl 3.9.16-4Miroslav Grepl 3.9.16-3Miroslav Grepl 3.9.16-2Miroslav Grepl 3.9.16-1Miroslav Grepl 3.9.15-5Miroslav Grepl 3.9.15-2Miroslav Grepl 3.9.15-1Fedora Release Engineering - 3.9.14-2Dan Walsh 3.9.14-1Miroslav Grepl 3.9.13-10Miroslav Grepl 3.9.13-9Dan Walsh 3.9.13-8Miroslav Grepl 3.9.13-7Miroslav Grepl 3.9.13-6Miroslav Grepl 3.9.13-5Miroslav Grepl 3.9.13-4Miroslav Grepl 3.9.13-3Miroslav Grepl 3.9.13-2Miroslav Grepl 3.9.13-1Miroslav Grepl 3.9.12-8Miroslav Grepl 3.9.12-7Miroslav Grepl 3.9.12-6Miroslav Grepl 3.9.12-5Dan Walsh 3.9.12-4Dan Walsh 3.9.12-3Dan Walsh 3.9.12-2Miroslav Grepl 3.9.12-1Dan Walsh 3.9.11-2Miroslav Grepl 3.9.11-1Miroslav Grepl 3.9.10-13Dan Walsh 3.9.10-12Miroslav Grepl 3.9.10-11Miroslav Grepl 3.9.10-10Miroslav Grepl 3.9.10-9Miroslav Grepl 3.9.10-8Miroslav Grepl 3.9.10-7Miroslav Grepl 3.9.10-6Miroslav Grepl 3.9.10-5Dan Walsh 3.9.10-4Miroslav Grepl 3.9.10-3Miroslav Grepl 3.9.10-2Miroslav Grepl 3.9.10-1Miroslav Grepl 3.9.9-4Dan Walsh 3.9.9-3Miroslav Grepl 3.9.9-2Miroslav Grepl 3.9.9-1Miroslav Grepl 3.9.8-7Dan Walsh 3.9.8-6Miroslav Grepl 3.9.8-5Miroslav Grepl 3.9.8-4Dan Walsh 3.9.8-3Dan Walsh 3.9.8-2Dan Walsh 3.9.8-1Dan Walsh 3.9.7-10Dan Walsh 3.9.7-9Dan Walsh 3.9.7-8Dan Walsh 3.9.7-7Dan Walsh 3.9.7-6Dan Walsh 3.9.7-5Dan Walsh 3.9.7-4Dan Walsh 3.9.7-3Dan Walsh 3.9.7-2Dan Walsh 3.9.7-1Dan Walsh 3.9.6-3Dan Walsh 3.9.6-2Dan Walsh 3.9.6-1Dan Walsh 3.9.5-11Dan Walsh 3.9.5-10Dan Walsh 3.9.5-9Dan Walsh 3.9.5-8Dan Walsh 3.9.5-7Dan Walsh 3.9.5-6Dan Walsh 3.9.5-5Dan Walsh 3.9.5-4Dan Walsh 3.9.5-3Dan Walsh 3.9.5-2Dan Walsh 3.9.5-1Dan Walsh 3.9.4-3Dan Walsh 3.9.4-2Dan Walsh 3.9.4-1Dan Walsh 3.9.3-4Dan Walsh 3.9.3-3Dan Walsh 3.9.3-2Dan Walsh 3.9.3-1Dan Walsh 3.9.2-1Dan Walsh 3.9.1-3Dan Walsh 3.9.1-2Dan Walsh 3.9.1-1Dan Walsh 3.9.0-2Dan Walsh 3.9.0-1Dan Walsh 3.8.8-21Dan Walsh 3.8.8-20Dan Walsh 3.8.8-19Dan Walsh 3.8.8-18Dan Walsh 3.8.8-17Dan Walsh 3.8.8-16Dan Walsh 3.8.8-15Dan Walsh 3.8.8-14Dan Walsh 3.8.8-13Dan Walsh 3.8.8-12Dan Walsh 3.8.8-11Dan Walsh 3.8.8-10Dan Walsh 3.8.8-9Dan Walsh 3.8.8-8Dan Walsh 3.8.8-7Dan Walsh 3.8.8-6Dan Walsh 3.8.8-5Dan Walsh 3.8.8-4Dan Walsh 3.8.8-3Dan Walsh 3.8.8-2Dan Walsh 3.8.8-1Dan Walsh 3.8.7-3Dan Walsh 3.8.7-2Dan Walsh 3.8.7-1Dan Walsh 3.8.6-3Miroslav Grepl 3.8.6-2Dan Walsh 3.8.6-1Dan Walsh 3.8.5-1Dan Walsh 3.8.4-1Dan Walsh 3.8.3-4Dan Walsh 3.8.3-3Dan Walsh 3.8.3-2Dan Walsh 3.8.3-1Dan Walsh 3.8.2-1Dan Walsh 3.8.1-5Dan Walsh 3.8.1-4Dan Walsh 3.8.1-3Dan Walsh 3.8.1-2Dan Walsh 3.8.1-1Dan Walsh 3.7.19-22Dan Walsh 3.7.19-21Dan Walsh 3.7.19-20Dan Walsh 3.7.19-19Dan Walsh 3.7.19-17Dan Walsh 3.7.19-16Dan Walsh 3.7.19-15Dan Walsh 3.7.19-14Dan Walsh 3.7.19-13Dan Walsh 3.7.19-12Dan Walsh 3.7.19-11Dan Walsh 3.7.19-10Dan Walsh 3.7.19-9Dan Walsh 3.7.19-8Dan Walsh 3.7.19-7Dan Walsh 3.7.19-6Dan Walsh 3.7.19-5Dan Walsh 3.7.19-4Dan Walsh 3.7.19-3Dan Walsh 3.7.19-2Dan Walsh 3.7.19-1Dan Walsh 3.7.18-3Dan Walsh 3.7.18-2Dan Walsh 3.7.18-1Dan Walsh 3.7.17-6Dan Walsh 3.7.17-5Dan Walsh 3.7.17-4Dan Walsh 3.7.17-3Dan Walsh 3.7.17-2Dan Walsh 3.7.17-1Dan Walsh 3.7.16-2Dan Walsh 3.7.16-1Dan Walsh 3.7.15-4Dan Walsh 3.7.15-3Dan Walsh 3.7.15-2Dan Walsh 3.7.15-1Dan Walsh 3.7.14-5Dan Walsh 3.7.14-4Dan Walsh 3.7.14-3Dan Walsh 3.7.14-2Dan Walsh 3.7.14-1Dan Walsh 3.7.13-4Dan Walsh 3.7.13-3Dan Walsh 3.7.13-2Dan Walsh 3.7.13-1Dan Walsh 3.7.12-1Dan Walsh 3.7.11-1Dan Walsh 3.7.10-5Dan Walsh 3.7.10-4Dan Walsh 3.7.10-3Dan Walsh 3.7.10-2Dan Walsh 3.7.10-1Dan Walsh 3.7.9-4Dan Walsh 3.7.9-3Dan Walsh 3.7.9-2Dan Walsh 3.7.9-1Dan Walsh 3.7.8-11Dan Walsh 3.7.8-9Dan Walsh 3.7.8-8Dan Walsh 3.7.8-7Dan Walsh 3.7.8-6Dan Walsh 3.7.8-5Dan Walsh 3.7.8-4Dan Walsh 3.7.8-3Dan Walsh 3.7.8-2Dan Walsh 3.7.8-1Dan Walsh 3.7.7-3Dan Walsh 3.7.7-2Dan Walsh 3.7.7-1Dan Walsh 3.7.6-1Dan Walsh 3.7.5-8Dan Walsh 3.7.5-7Dan Walsh 3.7.5-6Dan Walsh 3.7.5-5Dan Walsh 3.7.5-4Dan Walsh 3.7.5-3Dan Walsh 3.7.5-2Dan Walsh 3.7.5-1Dan Walsh 3.7.4-4Dan Walsh 3.7.4-3Dan Walsh 3.7.4-2Dan Walsh 3.7.4-1Dan Walsh 3.7.3-1Dan Walsh 3.7.1-1Dan Walsh 3.6.33-2Dan Walsh 3.6.33-1Dan Walsh 3.6.32-17Dan Walsh 3.6.32-16Dan Walsh 3.6.32-15Dan Walsh 3.6.32-13Dan Walsh 3.6.32-12Dan Walsh 3.6.32-11Dan Walsh 3.6.32-10Dan Walsh 3.6.32-9Dan Walsh 3.6.32-8Dan Walsh 3.6.32-7Dan Walsh 3.6.32-6Dan Walsh 3.6.32-5Dan Walsh 3.6.32-4Dan Walsh 3.6.32-3Dan Walsh 3.6.32-2Dan Walsh 3.6.32-1Dan Walsh 3.6.31-5Dan Walsh 3.6.31-4Dan Walsh 3.6.31-3Dan Walsh 3.6.31-2Dan Walsh 3.6.30-6Dan Walsh 3.6.30-5Dan Walsh 3.6.30-4Dan Walsh 3.6.30-3Dan Walsh 3.6.30-2Dan Walsh 3.6.30-1Dan Walsh 3.6.29-2Dan Walsh 3.6.29-1Dan Walsh 3.6.28-9Dan Walsh 3.6.28-8Dan Walsh 3.6.28-7Dan Walsh 3.6.28-6Dan Walsh 3.6.28-5Dan Walsh 3.6.28-4Dan Walsh 3.6.28-3Dan Walsh 3.6.28-2Dan Walsh 3.6.28-1Dan Walsh 3.6.27-1Dan Walsh 3.6.26-11Dan Walsh 3.6.26-10Dan Walsh 3.6.26-9Bill Nottingham 3.6.26-8Dan Walsh 3.6.26-7Dan Walsh 3.6.26-6Dan Walsh 3.6.26-5Dan Walsh 3.6.26-4Dan Walsh 3.6.26-3Dan Walsh 3.6.26-2Dan Walsh 3.6.26-1Dan Walsh 3.6.25-1Dan Walsh 3.6.24-1Dan Walsh 3.6.23-2Dan Walsh 3.6.23-1Dan Walsh 3.6.22-3Dan Walsh 3.6.22-1Dan Walsh 3.6.21-4Dan Walsh 3.6.21-3Tom "spot" Callaway 3.6.21-2Dan Walsh 3.6.21-1Dan Walsh 3.6.20-2Dan Walsh 3.6.20-1Dan Walsh 3.6.19-5Dan Walsh 3.6.19-4Dan Walsh 3.6.19-3Dan Walsh 3.6.19-2Dan Walsh 3.6.19-1Dan Walsh 3.6.18-1Dan Walsh 3.6.17-1Dan Walsh 3.6.16-4Dan Walsh 3.6.16-3Dan Walsh 3.6.16-2Dan Walsh 3.6.16-1Dan Walsh 3.6.14-3Dan Walsh 3.6.14-2Dan Walsh 3.6.14-1Dan Walsh 3.6.13-3Dan Walsh 3.6.13-2Dan Walsh 3.6.13-1Dan Walsh 3.6.12-39Dan Walsh 3.6.12-38Dan Walsh 3.6.12-37Dan Walsh 3.6.12-36Dan Walsh 3.6.12-35Dan Walsh 3.6.12-34Dan Walsh 3.6.12-33Dan Walsh 3.6.12-31Dan Walsh 3.6.12-30Dan Walsh 3.6.12-29Dan Walsh 3.6.12-28Dan Walsh 3.6.12-27Dan Walsh 3.6.12-26Dan Walsh 3.6.12-25Dan Walsh 3.6.12-24Dan Walsh 3.6.12-23Dan Walsh 3.6.12-22Dan Walsh 3.6.12-21Dan Walsh 3.6.12-20Dan Walsh 3.6.12-19Dan Walsh 3.6.12-16Dan Walsh 3.6.12-15Dan Walsh 3.6.12-14Dan Walsh 3.6.12-13Dan Walsh 3.6.12-12Dan Walsh 3.6.12-11Dan Walsh 3.6.12-10Dan Walsh 3.6.12-9Dan Walsh 3.6.12-8Dan Walsh 3.6.12-7Dan Walsh 3.6.12-6Dan Walsh 3.6.12-5Dan Walsh 3.6.12-4Dan Walsh 3.6.12-3Dan Walsh 3.6.12-2Dan Walsh 3.6.12-1Dan Walsh 3.6.11-1Dan Walsh 3.6.10-9Dan Walsh 3.6.10-8Dan Walsh 3.6.10-7Dan Walsh 3.6.10-6Dan Walsh 3.6.10-5Dan Walsh 3.6.10-4Dan Walsh 3.6.10-3Dan Walsh 3.6.10-2Dan Walsh 3.6.10-1Dan Walsh 3.6.9-4Dan Walsh 3.6.9-3Dan Walsh 3.6.9-2Dan Walsh 3.6.9-1Dan Walsh 3.6.8-4Dan Walsh 3.6.8-3Dan Walsh 3.6.8-2Dan Walsh 3.6.8-1Dan Walsh 3.6.7-2Dan Walsh 3.6.7-1Dan Walsh 3.6.6-9Dan Walsh 3.6.6-8Fedora Release Engineering - 3.6.6-7Dan Walsh 3.6.6-6Dan Walsh 3.6.6-5Dan Walsh 3.6.6-4Dan Walsh 3.6.6-3Dan Walsh 3.6.6-2Dan Walsh 3.6.6-1Dan Walsh 3.6.5-3Dan Walsh 3.6.5-1Dan Walsh 3.6.4-6Dan Walsh 3.6.4-5Dan Walsh 3.6.4-4Dan Walsh 3.6.4-3Dan Walsh 3.6.4-2Dan Walsh 3.6.4-1Dan Walsh 3.6.3-13Dan Walsh 3.6.3-12Dan Walsh 3.6.3-11Dan Walsh 3.6.3-10Dan Walsh 3.6.3-9Dan Walsh 3.6.3-8Dan Walsh 3.6.3-7Dan Walsh 3.6.3-6Dan Walsh 3.6.3-3Dan Walsh 3.6.3-2Dan Walsh 3.6.3-1Dan Walsh 3.6.2-5Dan Walsh 3.6.2-4Dan Walsh 3.6.2-3Dan Walsh 3.6.2-2Dan Walsh 3.6.2-1Dan Walsh 3.6.1-15Dan Walsh 3.6.1-14Dan Walsh 3.6.1-13Dan Walsh 3.6.1-12Dan Walsh 3.6.1-11Dan Walsh 3.6.1-10Dan Walsh 3.6.1-9Dan Walsh 3.6.1-8Dan Walsh 3.6.1-7Dan Walsh 3.6.1-4Ignacio Vazquez-Abrams - 3.6.1-2Dan Walsh 3.5.13-19Dan Walsh 3.5.13-18Dan Walsh 3.5.13-17Dan Walsh 3.5.13-16Dan Walsh 3.5.13-15Dan Walsh 3.5.13-14Dan Walsh 3.5.13-13Dan Walsh 3.5.13-12Dan Walsh 3.5.13-11Dan Walsh 3.5.13-9Dan Walsh 3.5.13-8Dan Walsh 3.5.13-7Dan Walsh 3.5.13-6Dan Walsh 3.5.13-5Dan Walsh 3.5.13-4Dan Walsh 3.5.13-3Dan Walsh 3.5.13-2Dan Walsh 3.5.13-1Dan Walsh 3.5.12-3Dan Walsh 3.5.12-2Dan Walsh 3.5.12-1Dan Walsh 3.5.11-1Dan Walsh 3.5.10-3Dan Walsh 3.5.10-2Dan Walsh 3.5.10-1Dan Walsh 3.5.9-4Dan Walsh 3.5.9-3Dan Walsh 3.5.9-2Dan Walsh 3.5.9-1Dan Walsh 3.5.8-7Dan Walsh 3.5.8-6Dan Walsh 3.5.8-5Dan Walsh 3.5.8-4Dan Walsh 3.5.8-3Dan Walsh 3.5.8-1Dan Walsh 3.5.7-2Dan Walsh 3.5.7-1Dan Walsh 3.5.6-2Dan Walsh 3.5.6-1Dan Walsh 3.5.5-4Dan Walsh 3.5.5-3Dan Walsh 3.5.5-2Dan Walsh 3.5.4-2Dan Walsh 3.5.4-1Dan Walsh 3.5.3-1Dan Walsh 3.5.2-2Dan Walsh 3.5.1-5Dan Walsh 3.5.1-4Dan Walsh 3.5.1-3Dan Walsh 3.5.1-2Dan Walsh 3.5.1-1Dan Walsh 3.5.0-1Dan Walsh 3.4.2-14Dan Walsh 3.4.2-13Dan Walsh 3.4.2-12Dan Walsh 3.4.2-11Dan Walsh 3.4.2-10Dan Walsh 3.4.2-9Dan Walsh 3.4.2-8Dan Walsh 3.4.2-7Dan Walsh 3.4.2-6Dan Walsh 3.4.2-5Dan Walsh 3.4.2-4Dan Walsh 3.4.2-3Dan Walsh 3.4.2-2Dan Walsh 3.4.2-1Dan Walsh 3.4.1-5Dan Walsh 3.4.1-3Dan Walsh 3.4.1-2Dan Walsh 3.4.1-1Dan Walsh 3.3.1-48Dan Walsh 3.3.1-47Dan Walsh 3.3.1-46Dan Walsh 3.3.1-45Dan Walsh 3.3.1-44Dan Walsh 3.3.1-43Dan Walsh 3.3.1-42Dan Walsh 3.3.1-41Dan Walsh 3.3.1-39Dan Walsh 3.3.1-37Dan Walsh 3.3.1-36Dan Walsh 3.3.1-33Dan Walsh 3.3.1-32Dan Walsh 3.3.1-31Dan Walsh 3.3.1-30Dan Walsh 3.3.1-29Dan Walsh 3.3.1-28Dan Walsh 3.3.1-27Dan Walsh 3.3.1-26Dan Walsh 3.3.1-25Dan Walsh 3.3.1-24Dan Walsh 3.3.1-23Dan Walsh 3.3.1-22Dan Walsh 3.3.1-21Dan Walsh 3.3.1-20Dan Walsh 3.3.1-19Dan Walsh 3.3.1-18Dan Walsh 3.3.1-17Dan Walsh 3.3.1-16Dan Walsh 3.3.1-15Bill Nottingham 3.3.1-14Dan Walsh 3.3.1-13Dan Walsh 3.3.1-12Dan Walsh 3.3.1-11Dan Walsh 3.3.1-10Dan Walsh 3.3.1-9Dan Walsh 3.3.1-8Dan Walsh 3.3.1-6Dan Walsh 3.3.1-5Dan Walsh 3.3.1-4Dan Walsh 3.3.1-2Dan Walsh 3.3.1-1Dan Walsh 3.3.0-2Dan Walsh 3.3.0-1Dan Walsh 3.2.9-2Dan Walsh 3.2.9-1Dan Walsh 3.2.8-2Dan Walsh 3.2.8-1Dan Walsh 3.2.7-6Dan Walsh 3.2.7-5Dan Walsh 3.2.7-3Dan Walsh 3.2.7-2Dan Walsh 3.2.7-1Dan Walsh 3.2.6-7Dan Walsh 3.2.6-6Dan Walsh 3.2.6-5Dan Walsh 3.2.6-4Dan Walsh 3.2.6-3Dan Walsh 3.2.6-2Dan Walsh 3.2.6-1Dan Walsh 3.2.5-25Dan Walsh 3.2.5-24Dan Walsh 3.2.5-22Dan Walsh 3.2.5-21Dan Walsh 3.2.5-20Dan Walsh 3.2.5-19Dan Walsh 3.2.5-18Dan Walsh 3.2.5-17Dan Walsh 3.2.5-16Dan Walsh 3.2.5-15Dan Walsh 3.2.5-14Dan Walsh 3.2.5-13Dan Walsh 3.2.5-12Dan Walsh 3.2.5-11Dan Walsh 3.2.5-10Dan Walsh 3.2.5-9Dan Walsh 3.2.5-8Dan Walsh 3.2.5-7Dan Walsh 3.2.5-6Dan Walsh 3.2.5-5Dan Walsh 3.2.5-4Dan Walsh 3.2.5-3Dan Walsh 3.2.5-2Dan Walsh 3.2.5-1Dan Walsh 3.2.4-5Dan Walsh 3.2.4-4Dan Walsh 3.2.4-3Dan Walsh 3.2.4-1Dan Walsh 3.2.4-1Dan Walsh 3.2.3-2Dan Walsh 3.2.3-1Dan Walsh 3.2.2-1Dan Walsh 3.2.1-3Dan Walsh 3.2.1-1Dan Walsh 3.1.2-2Dan Walsh 3.1.2-1Dan Walsh 3.1.1-1Dan Walsh 3.1.0-1Dan Walsh 3.0.8-30Dan Walsh 3.0.8-28Dan Walsh 3.0.8-27Dan Walsh 3.0.8-26Dan Walsh 3.0.8-25Dan Walsh 3.0.8-24Dan Walsh 3.0.8-23Dan Walsh 3.0.8-22Dan Walsh 3.0.8-21Dan Walsh 3.0.8-20Dan Walsh 3.0.8-19Dan Walsh 3.0.8-18Dan Walsh 3.0.8-17Dan Walsh 3.0.8-16Dan Walsh 3.0.8-15Dan Walsh 3.0.8-14Dan Walsh 3.0.8-13Dan Walsh 3.0.8-12Dan Walsh 3.0.8-11Dan Walsh 3.0.8-10Dan Walsh 3.0.8-9Dan Walsh 3.0.8-8Dan Walsh 3.0.8-7Dan Walsh 3.0.8-5Dan Walsh 3.0.8-4Dan Walsh 3.0.8-3Dan Walsh 3.0.8-2Dan Walsh 3.0.8-1Dan Walsh 3.0.7-10Dan Walsh 3.0.7-9Dan Walsh 3.0.7-8Dan Walsh 3.0.7-7Dan Walsh 3.0.7-6Dan Walsh 3.0.7-5Dan Walsh 3.0.7-4Dan Walsh 3.0.7-3Dan Walsh 3.0.7-2Dan Walsh 3.0.7-1Dan Walsh 3.0.6-3Dan Walsh 3.0.6-2Dan Walsh 3.0.6-1Dan Walsh 3.0.5-11Dan Walsh 3.0.5-10Dan Walsh 3.0.5-9Dan Walsh 3.0.5-8Dan Walsh 3.0.5-7Dan Walsh 3.0.5-6Dan Walsh 3.0.5-5Dan Walsh 3.0.5-4Dan Walsh 3.0.5-3Dan Walsh 3.0.5-2Dan Walsh 3.0.5-1Dan Walsh 3.0.4-6Dan Walsh 3.0.4-5Dan Walsh 3.0.4-4Dan Walsh 3.0.4-3Dan Walsh 3.0.4-2Dan Walsh 3.0.4-1Dan Walsh 3.0.3-6Dan Walsh 3.0.3-5Dan Walsh 3.0.3-4Dan Walsh 3.0.3-3Dan Walsh 3.0.3-2Dan Walsh 3.0.3-1Dan Walsh 3.0.2-9Dan Walsh 3.0.2-8Dan Walsh 3.0.2-7Dan Walsh 3.0.2-5Dan Walsh 3.0.2-4Dan Walsh 3.0.2-3Dan Walsh 3.0.2-2Dan Walsh 3.0.1-5Dan Walsh 3.0.1-4Dan Walsh 3.0.1-3Dan Walsh 3.0.1-2Dan Walsh 3.0.1-1Dan Walsh 2.6.5-3Dan Walsh 2.6.5-2Dan Walsh 2.6.4-7Dan Walsh 2.6.4-6Dan Walsh 2.6.4-5Dan Walsh 2.6.4-2Dan Walsh 2.6.4-1Dan Walsh 2.6.3-1Dan Walsh 2.6.2-1Dan Walsh 2.6.1-4Dan Walsh 2.6.1-2Dan Walsh 2.6.1-1Dan Walsh 2.5.12-12Dan Walsh 2.5.12-11Dan Walsh 2.5.12-10Dan Walsh 2.5.12-8Dan Walsh 2.5.12-5Dan Walsh 2.5.12-4Dan Walsh 2.5.12-3Dan Walsh 2.5.12-2Dan Walsh 2.5.12-1Dan Walsh 2.5.11-8Dan Walsh 2.5.11-7Dan Walsh 2.5.11-6Dan Walsh 2.5.11-5Dan Walsh 2.5.11-4Dan Walsh 2.5.11-3Dan Walsh 2.5.11-2Dan Walsh 2.5.11-1Dan Walsh 2.5.10-2Dan Walsh 2.5.10-1Dan Walsh 2.5.9-6Dan Walsh 2.5.9-5Dan Walsh 2.5.9-4Dan Walsh 2.5.9-3Dan Walsh 2.5.9-2Dan Walsh 2.5.8-8Dan Walsh 2.5.8-7Dan Walsh 2.5.8-6Dan Walsh 2.5.8-5Dan Walsh 2.5.8-4Dan Walsh 2.5.8-3Dan Walsh 2.5.8-2Dan Walsh 2.5.8-1Dan Walsh 2.5.7-1Dan Walsh 2.5.6-1Dan Walsh 2.5.5-2Dan Walsh 2.5.5-1Dan Walsh 2.5.4-2Dan Walsh 2.5.4-1Dan Walsh 2.5.3-3Dan Walsh 2.5.3-2Dan Walsh 2.5.3-1Dan Walsh 2.5.2-6Dan Walsh 2.5.2-5Dan Walsh 2.5.2-4Dan Walsh 2.5.2-3Dan Walsh 2.5.2-2Dan Walsh 2.5.2-1Dan Walsh 2.5.1-5Dan Walsh 2.5.1-4Dan Walsh 2.5.1-2Dan Walsh 2.5.1-1Dan Walsh 2.4.6-20Dan Walsh 2.4.6-19Dan Walsh 2.4.6-18Dan Walsh 2.4.6-17Dan Walsh 2.4.6-16Dan Walsh 2.4.6-15Dan Walsh 2.4.6-14Dan Walsh 2.4.6-13Dan Walsh 2.4.6-12Dan Walsh 2.4.6-11Dan Walsh 2.4.6-10Dan Walsh 2.4.6-9Dan Walsh 2.4.6-8Dan Walsh 2.4.6-7Dan Walsh 2.4.6-6Dan Walsh 2.4.6-5Dan Walsh 2.4.6-4Dan Walsh 2.4.6-3Dan Walsh 2.4.6-1Dan Walsh 2.4.5-4Dan Walsh 2.4.5-3Dan Walsh 2.4.5-2Dan Walsh 2.4.5-1Dan Walsh 2.4.4-2Dan Walsh 2.4.4-2Dan Walsh 2.4.4-1Dan Walsh 2.4.3-13Dan Walsh 2.4.3-12Dan Walsh 2.4.3-11Dan Walsh 2.4.3-10Dan Walsh 2.4.3-9Dan Walsh 2.4.3-8Dan Walsh 2.4.3-7Dan Walsh 2.4.3-6Dan Walsh 2.4.3-5Dan Walsh 2.4.3-4Dan Walsh 2.4.3-3Dan Walsh 2.4.3-2Dan Walsh 2.4.3-1Dan Walsh 2.4.2-8Dan Walsh 2.4.2-7James Antill 2.4.2-6Dan Walsh 2.4.2-5Dan Walsh 2.4.2-4Dan Walsh 2.4.2-3Dan Walsh 2.4.2-2Dan Walsh 2.4.2-1Dan Walsh 2.4.1-5Dan Walsh 2.4.1-4Dan Walsh 2.4.1-3Dan Walsh 2.4.1-2Dan Walsh 2.4-4Dan Walsh 2.4-3Dan Walsh 2.4-2Dan Walsh 2.4-1Dan Walsh 2.3.19-4Dan Walsh 2.3.19-3Dan Walsh 2.3.19-2Dan Walsh 2.3.19-1James Antill 2.3.18-10James Antill 2.3.18-9Dan Walsh 2.3.18-8Dan Walsh 2.3.18-7Dan Walsh 2.3.18-6Dan Walsh 2.3.18-5Dan Walsh 2.3.18-4Dan Walsh 2.3.18-3Dan Walsh 2.3.18-2Dan Walsh 2.3.18-1Dan Walsh 2.3.17-2Dan Walsh 2.3.17-1Dan Walsh 2.3.16-9Dan Walsh 2.3.16-8Dan Walsh 2.3.16-7Dan Walsh 2.3.16-6Dan Walsh 2.3.16-5Dan Walsh 2.3.16-4Dan Walsh 2.3.16-2Dan Walsh 2.3.16-1Dan Walsh 2.3.15-2Dan Walsh 2.3.15-1Dan Walsh 2.3.14-8Dan Walsh 2.3.14-7Dan Walsh 2.3.14-6Dan Walsh 2.3.14-4Dan Walsh 2.3.14-3Dan Walsh 2.3.14-2Dan Walsh 2.3.14-1Dan Walsh 2.3.13-6Dan Walsh 2.3.13-5Dan Walsh 2.3.13-4Dan Walsh 2.3.13-3Dan Walsh 2.3.13-2Dan Walsh 2.3.13-1Dan Walsh 2.3.12-2Dan Walsh 2.3.12-1Dan Walsh 2.3.11-1Dan Walsh 2.3.10-7Dan Walsh 2.3.10-6Dan Walsh 2.3.10-3Dan Walsh 2.3.10-1Dan Walsh 2.3.9-6Dan Walsh 2.3.9-5Dan Walsh 2.3.9-4Dan Walsh 2.3.9-3Dan Walsh 2.3.9-2Dan Walsh 2.3.9-1Dan Walsh 2.3.8-2Dan Walsh 2.3.7-1Dan Walsh 2.3.6-4Dan Walsh 2.3.6-3Dan Walsh 2.3.6-2Dan Walsh 2.3.6-1Dan Walsh 2.3.5-1Dan Walsh 2.3.4-1Dan Walsh 2.3.3-20Dan Walsh 2.3.3-19Dan Walsh 2.3.3-18Dan Walsh 2.3.3-17Dan Walsh 2.3.3-16Dan Walsh 2.3.3-15Dan Walsh 2.3.3-14Dan Walsh 2.3.3-13Dan Walsh 2.3.3-12Dan Walsh 2.3.3-11Dan Walsh 2.3.3-10Dan Walsh 2.3.3-9Dan Walsh 2.3.3-8Dan Walsh 2.3.3-7Dan Walsh 2.3.3-6Dan Walsh 2.3.3-5Dan Walsh 2.3.3-4Dan Walsh 2.3.3-3Dan Walsh 2.3.3-2Dan Walsh 2.3.3-1Dan Walsh 2.3.2-4Dan Walsh 2.3.2-3Dan Walsh 2.3.2-2Dan Walsh 2.3.2-1Dan Walsh 2.3.1-1Dan Walsh 2.2.49-1Dan Walsh 2.2.48-1Dan Walsh 2.2.47-5Dan Walsh 2.2.47-4Dan Walsh 2.2.47-3Dan Walsh 2.2.47-1Dan Walsh 2.2.46-2Dan Walsh 2.2.46-1Dan Walsh 2.2.45-3Dan Walsh 2.2.45-2Dan Walsh 2.2.45-1Dan Walsh 2.2.44-1Dan Walsh 2.2.43-4Dan Walsh 2.2.43-3Dan Walsh 2.2.43-2Dan Walsh 2.2.43-1Dan Walsh 2.2.42-4Dan Walsh 2.2.42-3Dan Walsh 2.2.42-2Dan Walsh 2.2.42-1Dan Walsh 2.2.41-1Dan Walsh 2.2.40-2Dan Walsh 2.2.40-1Dan Walsh 2.2.39-2Dan Walsh 2.2.39-1Dan Walsh 2.2.38-6Dan Walsh 2.2.38-5Dan Walsh 2.2.38-4Dan Walsh 2.2.38-3Dan Walsh 2.2.38-2Dan Walsh 2.2.38-1Dan Walsh 2.2.37-1Dan Walsh 2.2.36-2Dan Walsh 2.2.36-1James Antill 2.2.35-2Dan Walsh 2.2.35-1Dan Walsh 2.2.34-3Dan Walsh 2.2.34-2Dan Walsh 2.2.34-1Dan Walsh 2.2.33-1Dan Walsh 2.2.32-2Dan Walsh 2.2.32-1Dan Walsh 2.2.31-1Dan Walsh 2.2.30-2Dan Walsh 2.2.30-1Dan Walsh 2.2.29-6Russell Coker 2.2.29-5Dan Walsh 2.2.29-4Dan Walsh 2.2.29-3Dan Walsh 2.2.29-2Dan Walsh 2.2.29-1Dan Walsh 2.2.28-3Dan Walsh 2.2.28-2Dan Walsh 2.2.28-1Dan Walsh 2.2.27-1Dan Walsh 2.2.25-3Dan Walsh 2.2.25-2Dan Walsh 2.2.24-1Dan Walsh 2.2.23-19Dan Walsh 2.2.23-18Dan Walsh 2.2.23-17Karsten Hopp 2.2.23-16Dan Walsh 2.2.23-15Dan Walsh 2.2.23-14Dan Walsh 2.2.23-13Dan Walsh 2.2.23-12Jeremy Katz - 2.2.23-11Jeremy Katz - 2.2.23-10Dan Walsh 2.2.23-9Dan Walsh 2.2.23-8Dan Walsh 2.2.23-7Dan Walsh 2.2.23-5Dan Walsh 2.2.23-4Dan Walsh 2.2.23-3Dan Walsh 2.2.23-2Dan Walsh 2.2.23-1Dan Walsh 2.2.22-2Dan Walsh 2.2.22-1Dan Walsh 2.2.21-9Dan Walsh 2.2.21-8Dan Walsh 2.2.21-7Dan Walsh 2.2.21-6Dan Walsh 2.2.21-5Dan Walsh 2.2.21-4Dan Walsh 2.2.21-3Dan Walsh 2.2.21-2Dan Walsh 2.2.21-1Dan Walsh 2.2.20-1Dan Walsh 2.2.19-2Dan Walsh 2.2.19-1Dan Walsh 2.2.18-2Dan Walsh 2.2.18-1Dan Walsh 2.2.17-2Dan Walsh 2.2.16-1Dan Walsh 2.2.15-4Dan Walsh 2.2.15-3Dan Walsh 2.2.15-1Dan Walsh 2.2.14-2Dan Walsh 2.2.14-1Dan Walsh 2.2.13-1Dan Walsh 2.2.12-1Dan Walsh 2.2.11-2Dan Walsh 2.2.11-1Dan Walsh 2.2.10-1Dan Walsh 2.2.9-2Dan Walsh 2.2.9-1Dan Walsh 2.2.8-2Dan Walsh 2.2.7-1Dan Walsh 2.2.6-3Dan Walsh 2.2.6-2Dan Walsh 2.2.6-1Dan Walsh 2.2.5-1Dan Walsh 2.2.4-1Dan Walsh 2.2.3-1Dan Walsh 2.2.2-1Dan Walsh 2.2.1-1Dan Walsh 2.1.13-1Dan Walsh 2.1.12-3Dan Walsh 2.1.11-1Dan Walsh 2.1.10-1Jeremy Katz - 2.1.9-2Dan Walsh 2.1.9-1Dan Walsh 2.1.8-3Dan Walsh 2.1.8-2Dan Walsh 2.1.8-1Dan Walsh 2.1.7-4Dan Walsh 2.1.7-3Dan Walsh 2.1.7-2Dan Walsh 2.1.7-1Dan Walsh 2.1.6-24Dan Walsh 2.1.6-23Dan Walsh 2.1.6-22Dan Walsh 2.1.6-21Dan Walsh 2.1.6-20Dan Walsh 2.1.6-18Dan Walsh 2.1.6-17Dan Walsh 2.1.6-16Dan Walsh 2.1.6-15Dan Walsh 2.1.6-14Dan Walsh 2.1.6-13Dan Walsh 2.1.6-11Dan Walsh 2.1.6-10Dan Walsh 2.1.6-9Dan Walsh 2.1.6-8Dan Walsh 2.1.6-5Dan Walsh 2.1.6-4Dan Walsh 2.1.6-3Dan Walsh 2.1.6-2Dan Walsh 2.1.6-1Dan Walsh 2.1.4-2Dan Walsh 2.1.4-1Dan Walsh 2.1.3-1Jeremy Katz - 2.1.2-3Dan Walsh 2.1.2-2Dan Walsh 2.1.2-1Dan Walsh 2.1.1-3Dan Walsh 2.1.1-2Dan Walsh 2.1.1-1Dan Walsh 2.1.0-3Dan Walsh 2.1.0-2.Dan Walsh 2.1.0-1.Dan Walsh 2.0.11-2.Dan Walsh 2.0.11-1.Dan Walsh 2.0.9-1.Dan Walsh 2.0.8-1.Dan Walsh 2.0.7-3Dan Walsh 2.0.7-2Dan Walsh 2.0.6-2Dan Walsh 2.0.5-4Dan Walsh 2.0.5-1Dan Walsh 2.0.4-1Dan Walsh 2.0.2-2Dan Walsh 2.0.2-1Dan Walsh 2.0.1-2Dan Walsh 2.0.1-1- Allow rhsmd read process state of all domains and kernel threads Resolves: rhbz#1837461 - Allow ipa-adtrust-install restart sssd and dirsrv services Resolves: rhbz#1820298 - Allow nagios_plugin_domain execute programs in bin directories Resolves: rhbz#1824625 - selinux policy: add the right context for org.freeipa.server.trust-enable-agent Related: rhbz#1820298- Allow chronyd_t domain to exec shell Resolves: rhbz#1775573 - Allow pmie daemon to send signal pcmd daemon Resolves: rhbz#1770123 - Allow auditd poweroff or switch to single mode Resolves: rhbz#1780332- Dontaudit tmpreaper_t getting attributes from sysctl_type files Resolves: rhbz#1765063- Allow tmpreaper_t domain to getattr files labeled as mtrr_device_t Resolves: rhbz#1765063- Allow tmpwatch process labeled as tmpreaper_t domain to execute fuser command Resolves: rhbz#1765063- Update tmpreaper_t policy due to fuser command Resolves: rhbz#1765063- Allow tmpreaper_t domain to read all domains state Resolves: rhbz#1765063- Update sudo_role_template() to allow caller domain to read syslog pid files Resolves: rhbz#1651253- Allow sbd_t domain to check presence of processes labeled as cluster_t Resolves: rhbz#1753623- Allow ganesha_t domain to read system network state and connect to cyphesis_port_t Resolves: rhbz#1653857 - Label /var/log/collectd.log as collectd_log_t - Update gnome_role_template() interface to make working sysadm_u SELinux able to login to X sessions Resolves: rhbz#1688729 - Update collectd policy to allow daemon create /var/log/collectd with collectd_log_t label Resolves: rhbz#1658319 - Update sbd policy to allow manage cgroups Resolves: rhbz#1715136 - Allow sudo userdomain to run rpm related commands - Update rpm_run() interface to avoid duplicate role transition in sudo_role_template Resolves: rhbz#1651253- Update gnome_role_template() interface to make working sysadm_u SELinux able to login to X sessions Resolves: rhbz#1688729 - Update collectd policy to allow daemon create /var/log/collectd with collectd_log_t label Resolves: rhbz#1658319- Update sbd policy to allow manage cgroups Resolves: rhbz#1715136- Allow cupsd_t domain to manage cupsd_tmp_t temp link files Resolves: rhbz#1719754 - Allow svnserve_t domain to read /dev/random Resolves: rhbz#1727458 - Update sudodomains to make working confined users run sudo/su Resolves: rhbz#1699391- Allow virtlockd process read virtlockd.conf file Resolves: rhbz#1714896- Rebuild selinux-policy build because of broken RHEL-7.8 buildrood during build of selinux-policy-3.13.1-253 Resolves: rhbz#1727341- Label user cron spool file with user_cron_spool_t Resolves: rhbz#1727341 - Allow svnserve_t domain to read system state Resolves: rhbz#1727458 - Update svnserve_t policy to make working svnserve hooks Resolves: rhbz#1727458 - Update gnome_role_template() template to allow sysadm_t confined user to login to xsession Resolves: rhbz#1727379 - Update gnome_role_template() to allow _gkeyringd_t domains to chat with systemd_logind over dbus Resolves: rhbz#1727379 - Allow userdomain gkeyringd domain to create stream socket with userdomain Resolves: rhbz#1727379 - Allow cupsd_t to create lnk_files in /tmp. BZ(1401634) Resolves: rhbz#1719754 - Allow mysqld_t domain to manage cluster pid files Resolves: rhbz#1715805 - Relabel /usr/sbin/virtlockd from virt_exec_t to virtlogd_exec_t. Resolves: rhbz#1714896 - Allow systemd_hostnamed_t domain to dbus chat with sosreport_t domain Resolves: rhbz#1705599 - Allow rhsmcertd_t domain to send signull to all domains Resolves: rhbz#1701338 - Allow cloud_init_t domain to ccreate iptables files with correct SELinux label Resolves: rhbz#1699249 - Allow dnsmasq_t domain to manage NetworkManager_var_lib_t files - Allow certmonger to geattr of filesystems BZ(1578755) - Update tomcat_can_network_connect_db boolean to allow tomcat domains also connect to redis ports Resolves: rhbz#1687497 - Allow lograte_t domain to manage collect_rw_content files and dirs Resolves: rhbz#1658319 - Add interface collectd_manage_rw_content() - Allow glusterd_t domain to setpgid Resolves: rhbz#1653857 - Allow sysadm_sudo_t to use SELinux tooling. Resolves: rhbz#1727341 - Allow sysadm_t domain to create netlink selinux sockets Resolves: rhbz#1727379 - Allow systemd_resolved_t to dbusd chat with NetworkManager_t Resolves: rhbz#1723877 - Allow crack_t domain read /et/passwd files Resolves: rhbz#1721093 - Allow sysadm_t domain to dbus chat with rtkit daemon Resolves: rhbz#1720546 - Allow x_userdomains to nnp domain transition to thumb_t domain Resolves: rhbz#1712603 - Dontaudit writing to user home dirs by gnome-keyring-daemon Resolves: rhbz#1703959 - Update logging_send_audit_msgs(sudodomain() to control TTY auditing for netlink socket for audit service Resolves: rhbz#1699391 - Allow systemd_tmpfiles_t domain to relabel from usermodehelper_t files Resolves: rhbz#1699063 - Add interface kernel_relabelfrom_usermodehelper()- Allow sbd_t domain to use nsswitch Resolves: rhbz#1728593- Allow ganesha_t domain to connect to tcp portmap_port_t Resolves: rhbz#1715088- Allow redis to creating tmp files with own label Resolves: rhbz#1646765- Allow ctdb_t domain to manage samba_var_t files/links/sockets and dirs Resolves: rhbz#1716400- Allow nrpe_t domain to read process state of systemd_logind_t - Add interface systemd_logind_read_state() Resolves: rhbz#1653309- Label /etc/rhsm as rhsmcertd_config_t Resolves: rhbz#1703573- Fix typo in gpg SELinux module - Update gpg policy to make ti working with confined users Resolves: rhbz#1535109 - Alow nrpe_t to send signull to sssd domain when nagios_run_sudo boolean is turned on Resolves: rhbz#1653309 - Allow nrpe_t domain to be dbus cliennt Resolves: rhbz#1653309 - Add interface sssd_signull() Resolves: rhbz#1653309 - Update userdomains to allow confined users to create gpg keys Resolves: rhbz#1535109- Allow ngaios to use chown capability Resolves: rhbz#1653309 - Dontaudit gpg_domain to create netlink_audit sockets Resolves: rhbz#1535109 - Update fs_rw_cephfs_files() interface to allow also caller domain to read/write cephpfs_t lnk files Resolves: rhbz#1558836 - Update domain_can_mmap_files() boolean to allow also mmap lnk files- Allow rhsmcertd_t domain to read yum.log file labeled as rpm_log_t Resolves: rhbz#1695342- Update Nagios policy when sudo is used Resolves: rhbz#1653309- Allow modemmanager_t domain to write to raw_ip file labeled as sysfs_t Resolves: rhbz#1676810- Make shell_exec_t type as entrypoint for vmtools_unconfined_t. Resolves: rhbz#1656814- Update vmtools policy Resolves: rhbz#1656814 Allow domain transition from vmtools_t to vmtools_unconfined_t when shell_exec_t is entrypoint. - Allow virt_qemu_ga_t domain to read udev_var_run_t files Resolves: rhbz#1663092 - Update nagios_run_sudo boolean with few allow rules related to accessing sssd Resolves: rhbz#1653309 - Allow nfsd_t to read nvme block devices BZ(1562554) Resolves: rhbz#1655493 - Allow tangd_t domain to bind on tcp ports labeled as tangd_port_t Resolves: rhbz#1650909 - Allow all domains to send dbus msgs to vmtools_unconfined_t processes Resolves: rhbz#1656814 - Label /dev/pkey as crypt_device_t Resolves: rhbz#1623068 - Allow sudodomains to write to systemd_logind_sessions_t pipes. Resolves: rhbz#1687452 - Allow all user domains to read realmd_var_lib_t files and dirs to check if IPA is configured on the system Resolves: rhbz#1667962 - Fixes: xenconsole does not start Resolves: rhbz#1601525 - Label /usr/lib64/libcuda.so.XX.XX library as textrel_shlib_t. Resolves: rhbz#1636197 - Create tangd_port_t with default label tcp/7406 Resolves: rhbz#1650909- named wants to access /proc/sys/net/ipv4/ip_local_port_range to get ehphemeral range. Resolves: rhbz#1683754 - Allow sbd_t domain to bypass permission checks for sending signals Resolves: rhbz#1671132 - Allow sbd_t domain read/write all sysctls Resolves: rhbz#1671132 - Allow kpatch_t domain to communicate with policykit_t domsin over dbus Resolves: rhbz#1602435 - Allow boltd_t to stream connect to sytem dbus Resolves: rhbz#1589086 - Update userdom_admin_user_template() and init_prog_run_bpf() interfaces to make working bpftool for confined admin Resolves: rhbz#1626115 - Update unconfined_dbus_send() interface to allow both direction communication over dbus with unconfined process. Resolves: rhbz#1589086- Allow sbd_t domain read/write all sysctls Resolves: rhbz#1671132 - Allow kpatch_t domain to communicate with policykit_t domsin over dbus Resolves: rhbz#1602435 - Allow boltd_t to stream connect to sytem dbus Resolves: rhbz#1589086 - Update unconfined_dbus_send() interface to allow both direction communication over dbus with unconfined process. Resolves: rhbz#1589086- Update redis_enable_notify() boolean to fix sending e-mail by redis when this boolean is turned on Resolves: rhbz#1646765- Allow virtd_lxc_t domains use BPF Resolves: rhbz#1626115 - F29 NetworkManager implements a new code for IPv4 address conflict detection (RFC 5227) based on n-acd [1], which uses eBPF to process ARP packets from the network. Resolves: rhbz#1626115 - Allow unconfined user all perms under bpf class BZ(1565738 Resolves: rhbz#1626115 - Allow unconfined and sysadm users to use bpftool BZ(1591440) Resolves: rhbz#1626115 - Allow systemd to manage bpf dirs/files Resolves: rhbz#1626115 - Create new type bpf_t and label /sys/fs/bpf with this type Resolves:rhbz#1626115 - Add new interface init_prog_run_bpf() Resolves:rhbz#1626115 - add definition of bpf class and systemd perms Resolves: rhbz#1626115- Update policy with multiple allow rules to make working installing VM in MLS policy Resolves: rhbz#1558121 - Allow virt domain to use interited virtlogd domains fifo_file Resolves: rhbz#1558121 - Allow chonyc_t domain to rw userdomain pipes Resolves: rhbz#1618757 - Add file contexts in ganesha.fc file to label logging ganesha files properly. Resolves: rhbz#1628247- Allow sandbox_xserver_t domain write to user_tmp_t files Resolves: rhbz#1646521 - Allow virt_qemu_ga_t domain to read network state Resolves: rhbz#1630347 - Bolt added d-bus API for force-powering the thunderbolt controller, so system-dbusd needs acces to boltd pipes Resolves: rhbz#1589086 - Add boltd policy Resolves: rhbz#1589086 - Allow virt domains to read/write cephfs filesystems Resolves: rhbz#1558836 - Allow gpg_t to create own tmpfs dirs and sockets Resolves: rhbz#1535109 - Allow gpg_agent_t to send msgs to syslog/journal Resolves: rhbz#1535109 - Allow virtual machine to write to fixed_disk_device_t Resolves: rhbz#1499208 - Update kdump_manage_crash() interface to allow also manage dirs by caller domain Resolves: rhbz#1491585 - Add kpatch policy Resolves: rhbz#1602435 - Label /usr/bin/mysqld_safe_helper as mysqld_exec_t instead of bin_t Resolves: rhbz#1623942 - Allow svnserve_t domain to create in /tmp svn_0 file labeled as krb5_host_rcache_t Resolves: rhbz#1475271 - Allow systemd to mount boltd_var_run_t dirs Resolves: rhbz#1589086 - Allow systemd to mounont boltd lib dirs Resolves: rhbz#1589086 - Allow sysadm_t,staff_t and unconfined_t domain to execute kpatch as kpatch_t domain Resolves: rhbz#1602435 - Allow passwd_t domain chroot - Add miscfiles_filetrans_named_content_letsencrypt() to optional_block - Allow unconfined domains to create letsencrypt directory in /var/lib labeled as cert_t Resolves: rhbz#1447278 - Allow staff_t user to systemctl iptables units. Resolves: rhbz#1360470- Label /usr/bin/mysqld_safe_helper as mysqld_exec_t instead of bin_t Resolves: rhbz#1623942 - Allow svnserve_t domain to create in /tmp svn_0 file labeled as krb5_host_rcache_t Resolves: rhbz#1475271 - Allow passwd_t domain chroot - Add miscfiles_filetrans_named_content_letsencrypt() to optional_block - Allow unconfined domains to create letsencrypt directory in /var/lib labeled as cert_t Resolves: rhbz#1447278 - Allow staff_t user to systemctl iptables units. Resolves: rhbz#1360470- Allow gssd_t domain to manage kernel keyrings of every domain. Resolves: rhbz#1487350 - Add new interface domain_manage_all_domains_keyrings() Resolves: rhbz#1487350- Allow gssd_t domain to read/write kernel keyrings of every domain. Resolves: rhbz#1487350 - Add interface domain_rw_all_domains_keyrings() Resolves: rhbz#1487350- Update snapperd policy to allow snapperd manage all non security dirs. Resolves: rhbz#1619306-Allow nova_t domain to use pam Resolves: rhbz:#1640528 - sysstat: grant sysstat_t the search_dir_perms set Resolves: rhbz#1637416 - Allow cinder_volume_t domain to dbus chat with systemd_logind_t domain Resolves: rhbz#1630318 - Allow staff_t userdomain and confined_admindomain attribute to allow use generic ptys because of new sudo feature 'io logging' Resolves: rhbz#1564470 - Make ganesha policy active again Resolves: rhbz#1511489- Remove disabling ganesha module in pre install phase of installation new selinux-policy package where ganesha is again standalone module Resolves: rhbz#1638257- Allow staff_t userdomain and confined_admindomain attribute to allow use generic ptys because of new sudo feature 'io logging' Resolves: rhbz#1638427- Run ganesha as ganesha_t domain again, revert changes where ganesha is running as nfsd_t Resolves: rhbz#1638257- Fix missing patch in spec file Resolves: rhbz#1635704- Allow cinder_volume_t domain to dbus chat with systemd_logind_t domain Resolves: rhbz#1635704- Allow neutron domain to read/write /var/run/utmp Resolves: rhbz#1630318- Allow tomcat_domain to read /dev/random Resolves: rhbz#1631666 - Allow neutron_t domain to use pam Resolves: rhbz#1630318- Add interface apache_read_tmp_dirs() - Allow dirsrvadmin_script_t domain to list httpd_tmp_t dirs Resolves: rhbz#1622602- Allow tomcat servers to manage usr_t files Resolves: rhbz#1625678 - Dontaudit tomcat serves to append to /dev/random device Resolves: rhbz#1625678 - Allow sys_nice capability to mysqld_t domain - Allow dirsrvadmin_script_t domain to read httpd tmp files Resolves: rhbz#1622602 - Allow syslogd_t domain to manage cert_t files Resolves: rhbz#1615995- Allow sbd_t domain to getattr of all char files in /dev and read sysfs_t files and dirs Resolves: rhbz#1627114 - Expand virt_read_lib_files() interface to allow list dirs with label virt_var_lib_t Resolves: rhbz#1567753- Allow tomcat Tomcat to delete a temporary file used when compiling class files for JSPs. Resolves: rhbz#1625678 - Allow chronyd_t domain to read virt_var_lib_t files - Allow virtual machines to use dri devices. This allows use openCL GPU calculations. BZ(1337333) Resolves: rhbz#1625613 - Allow tomcat services create link file in /tmp Resolves: rhbz#1624289 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322- Make working SELinux sandbox with Wayland. Resolves: rhbz#1624308 - Allow svirt_t domain to mmap svirt_image_t block files Resolves: rhbz#1624224 - Add caps dac_read_search and dav_override to pesign_t domain - Allow iscsid_t domain to mmap userio chr files Resolves: rhbz#1623589 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322 - Add execute_no_trans permission to mmap_exec_file_perms pattern - Allow sudodomain to search caller domain proc info - Allow xdm_t domain to mmap and read cert_t files - Replace optional policy blocks to make dbus interfaces effective Resolves: rhbz#1624414 - Add interface dev_map_userio_dev()- Allow readhead_t domain to mmap own pid files Resolves: rhbz#1614169- Allow ovs-vswitchd labeled as openvswitch_t domain communicate with qemu-kvm via UNIX stream socket - Allow httpd_t domain to mmap tmp files Resolves: rhbz#1608355 - Update dirsrv_read_share() interface to allow caller domain to mmap dirsrv_share_t files - Update dirsrvadmin_script_t policy to allow read httpd_tmp_t symlinks - Label /dev/tpmrm[0-9]* as tpm_device_t - Allow semanage_t domain mmap usr_t files Resolves: rhbz#1622607 - Update dev_filetrans_all_named_dev() to allow create event22-30 character files with label event_device_t- Allow nagios_script_t domain to mmap nagios_log_t files Resolves: rhbz#1620013 - Allow nagios_script_t domain to mmap nagios_spool_t files Resolves: rhbz#1620013 - Update userdom_security_admin() and userdom_security_admin_template() to allow use auditctl Resolves: rhbz#1622197 - Update selinux_validate_context() interface to allow caller domain to mmap security_t files Resolves: rhbz#1622061- Allow virtd_t domain to create netlink_socket - Allow rpm_t domain to write to audit - Allow rpm domain to mmap rpm_var_lib_t files Resolves: rhbz#1619785 - Allow nagios_script_t domain to mmap nagios_etc_t files Resolves: rhbz#1620013 - Update nscd_socket_use() to allow caller domain to stream connect to nscd_t Resolves: rhbz#1460715 - Allow secadm_t domain to mmap audit config and log files - Allow insmod_t domain to read iptables pid files - Allow systemd to mounton /etc Resolves: rhbz#1619785- Allow kdumpctl_t domain to getattr fixed disk device in mls Resolves: rhbz#1615342 - Allow initrc_domain to mmap all binaries labeled as systemprocess_entry Resolves: rhbz#1615342- Allow virtlogd to execute itself Resolves: rhbz#1598392- Allow kdumpctl_t domain to manage kdumpctl_tmp_t fifo files Resolves: rhbz#1615342 - Allow kdumpctl to write to files on all levels Resolves: rhbz#1615342 - Fix typo in radius policy Resolves: rhbz#1619197 - Allow httpd_t domain to mmap httpd_config_t files Resolves: rhbz#1615894 - Add interface dbus_acquire_svc_system_dbusd() - Allow sanlock_t domain to connectto to unix_stream_socket Resolves: rhbz#1614965 - Update nfsd_t policy because of ganesha features Resolves: rhbz#1511489 - Allow conman to getattr devpts_t Resolves: rhbz#1377915 - Allow tomcat_domain to connect to smtp ports Resolves: rhbz#1253502 - Allow tomcat_t domain to mmap tomcat_var_lib_t files Resolves: rhbz#1618519 - Allow slapd_t domain to mmap slapd_var_run_t files Resolves: rhbz#1615319 - Allow nagios_t domain to mmap nagios_log_t files Resolves: rhbz#1618675 - Allow nagios to exec itself and mmap nagios spool files BZ(1559683) - Allow nagios to mmap nagios config files BZ(1559683) - Allow kpropd_t domain to mmap krb5kdc_principal_t files Resolves: rhbz#1619252 - Update syslogd policy to make working elasticsearch - Label tcp and udp ports 9200 as wap_wsp_port - Allow few domains to rw inherited kdumpctl tmp pipes Resolves: rhbz#1615342- Allow systemd_dbusd_t domain read/write to nvme devices Resolves: rhbz#1614236 - Allow mysqld_safe_t do execute itself - Allow smbd_t domain to chat via dbus with avahi daemon Resolves: rhbz#1600157 - cupsd_t domain will create /etc/cupsd/ppd as cupsd_etc_rw_t Resolves: rhbz#1452595 - Allow amanda_t domain to getattr on tmpfs filesystem BZ(1527645) Resolves: rhbz#1452444 - Update screen_role_template to allow caller domain to have screen_exec_t as entrypoint do new domain Resolves: rhbz#1384769 - Add alias httpd__script_t to _script_t to make sepolicy generate working Resolves: rhbz#1271324 - Allow kprop_t domain to read network state Resolves: rhbz#1600705 - Allow sysadm_t domain to accept socket Resolves: rhbz#1557299 - Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow kprop_t domain to read network state Resolves: rhbz#1600705- Allow kpropd domain to exec itself Resolves: rhbz#1600705 - Allow ipmievd_t to mmap kernel modules BZ(1552535) - Allow hsqldb_t domain to mmap own temp files Resolves: rhbz#1612143 - Allow hsqldb_t domain to read cgroup files Resolves: rhbz#1612143 - Allow rngd_t domain to read generic certs Resolves: rhbz#1612456 - Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow virtlogd_t domain to chat via dbus with systemd_logind Resolves: rhbz#1593740- Allow sblim_sfcbd_t domain to mmap own tmpfs files Resolves: rhbz#1609384 - Update logging_manage_all_logs() interface to allow caller domain map all logfiles Resolves: rhbz#1592028- Dontaudit oracleasm_t domain to request sys_admin capability - Allow iscsid_t domain to load kernel module Resolves: rhbz#1589295 - Update rhcs contexts to reflects the latest fenced changes - Allow httpd_t domain to rw user_tmp_t files Resolves: rhbz#1608355 - /usr/libexec/udisks2/udisksd should be labeled as devicekit_disk_exec_t Resolves: rhbz#1521063 - Allow tangd_t dac_read_search Resolves: rhbz#1607810 - Allow glusterd_t domain to mmap user_tmp_t files - Allow mongodb_t domain to mmap own var_lib_t files Resolves: rhbz#1607729 - Allow iscsid_t domain to mmap sysfs_t files Resolves: rhbz#1602508 - Allow tomcat_domain to search cgroup dirs Resolves: rhbz#1600188 - Allow httpd_t domain to mmap own cache files Resolves: rhbz#1603505 - Allow cupsd_t domain to mmap cupsd_etc_t files Resolves: rhbz#1599694 - Allow kadmind_t domain to mmap krb5kdc_principal_t Resolves: rhbz#1601004 - Allow virtlogd_t domain to read virt_etc_t link files Resolves: rhbz#1598593 - Allow dirsrv_t domain to read crack db Resolves: rhbz#1599726 - Dontaudit pegasus_t to require sys_admin capability Resolves: rhbz#1374570 - Allow mysqld_t domain to exec mysqld_exec_t binary files - Allow abrt_t odmain to read rhsmcertd lib files Resolves: rhbz#1601389 - Allow winbind_t domain to request kernel module loads Resolves: rhbz#1599236 - Allow gpsd_t domain to getsession and mmap own tmpfs files Resolves: rhbz#1598388 - Allow smbd_t send to nmbd_t via dgram sockets BZ(1563791) Resolves: rhbz#1600157 - Allow tomcat_domain to read cgroup_t files Resolves: rhbz#1601151 - Allow varnishlog_t domain to mmap varnishd_var_lib_t files Resolves: rhbz#1600704 - Allow dovecot_auth_t domain to manage also dovecot_var_run_t fifo files. BZ(1320415) Resolves: rhbz#1600692 - Fix ntp SELinux module - Allow innd_t domain to mmap news_spool_t files Resolves: rhbz#1600591 - Allow haproxy daemon to reexec itself. BZ(1447800) Resolves: rhbz#1600578 - Label HOME_DIR/mozilla.pdf file as mozilla_home_t instead of user_home_t Resolves: rhbz#1559859 - Allow pkcs_slotd_t domain to mmap own tmpfs files Resolves: rhbz#1600434 - Allow fenced_t domain to reboot Resolves: rhbz#1293384 - Allow bluetooth_t domain listen on bluetooth sockets BZ(1549247) Resolves: rhbz#1557299 - Allow lircd to use nsswitch. BZ(1401375) - Allow targetd_t domain mmap lvm config files Resolves: rhbz#1546671 - Allow amanda_t domain to read network system state Resolves: rhbz#1452444 - Allow abrt_t domain to read rhsmcertd logs Resolves: rhbz#1492059 - Allow application_domain_type also mmap inherited user temp files BZ(1552765) Resolves: rhbz#1608421 - Allow ipsec_t domain to read l2tpd pid files Resolves: rhbz#1607994 - Allow systemd_tmpfiles_t do mmap system db files - Improve domain_transition_pattern to allow mmap entrypoint bin file. Resolves: rhbz#1460322 - Allow nsswitch_domain to mmap passwd_file_t files BZ(1518655) Resolves: rhbz#1600528 - Dontaudit syslogd to watching top llevel dirs when imfile module is enabled Resolves: rhbz#1601928 - Allow ipsec_t can exec ipsec_exec_t Resolves: rhbz#1600684 - Allow netutils_t domain to mmap usmmon device Resolves: rhbz#1600586 - Allow netlabel_mgmt_t domain to read sssd public files, stream connect to sssd_t BZ(1483655) - Allow userdomain sudo domains to use generic ptys Resolves: rhbz#1564470 - Allow traceroute to create icmp packets Resolves: rhbz#1548350 - Allow systemd domain to mmap lvm config files BZ(1594584) - Add new interface lvm_map_config - refpolicy: Update for kernel sctp support Resolves: rhbz#1597111 Add additional entries to support the kernel SCTP implementation introduced in kernel 4.16- Update oddjob_domtrans_mkhomedir() interface to allow caller domain also mmap oddjob_mkhomedir_exec_t files Resolves: rhbz#1596306 - Update rhcs_rw_cluster_tmpfs() interface to allow caller domain to mmap cluster_tmpfs_t files Resolves: rhbz#1589257 - Allow radiusd_t domain to read network sysctls Resolves: rhbz#1516233 - Allow chronyc_t domain to use nscd shm Resolves: rhbz#1596563 - Label /var/lib/tomcats dir as tomcat_var_lib_t Resolves: rhbz#1596367 - Allow lsmd_t domain to mmap lsmd_plugin_exec_t files Resolves: rhbz#bea0c8174 - Label /usr/sbin/rhn_check-[0-9]+.[0-9]+ as rpm_exec_t Resolves: rhbz#1596509 - Update seutil_exec_loadpolicy() interface to allow caller domain to mmap load_policy_exec_t files Resolves: rhbz#1596072 - Allow xdm_t to read systemd hwdb Resolves: rhbz#1596720 - Allow dhcpc_t domain to mmap files labeled as ping_exec_t Resolves: rhbz#1596065- Allow tangd_t domain to create tcp sockets Resolves: rhbz#1595775 - Update postfix policy to allow postfix_master_t domain to mmap all postfix* binaries Resolves: rhbz#1595328 - Allow amanda_t domain to have setgid capability Resolves: rhbz#1452444 - Update usermanage_domtrans_useradd() to allow caller domain to mmap useradd_exec_t files Resolves: rhbz#1595667- Allow abrt_watch_log_t domain to mmap binaries with label abrt_dump_oops_exec_t Resolves: rhbz#1591191 - Update cups_filetrans_named_content() to allow caller domain create ppd directory with cupsd_etc_rw_t label Resolves: rhbz#1452595 - Allow abrt_t domain to write to rhsmcertd pid files Resolves: rhbz#1492059 - Allow pegasus_t domain to eexec lvm binaries and allow read/write access to lvm control Resolves: rhbz#1463470 - Add vhostmd_t domain to read/write to svirt images Resolves: rhbz#1465276 - Dontaudit action when abrt-hook-ccpp is writing to nscd sockets Resolves: rhbz#1460715 - Update openvswitch policy Resolves: rhbz#1594729 - Update kdump_manage_kdumpctl_tmp_files() interface to allow caller domain also mmap kdumpctl_tmp_t files Resolves: rhbz#1583084 - Allow sssd_t and slpad_t domains to mmap generic certs Resolves: rhbz#1592016 Resolves: rhbz#1592019 - Allow oddjob_t domain to mmap binary files as oddjob_mkhomedir_exec_t files Resolves: rhbz#1592022 - Update dbus_system_domain() interface to allow system_dbusd_t domain to mmap binary file from second parameter Resolves: rhbz#1583080 - Allow chronyc_t domain use inherited user ttys Resolves: rhbz#1593267 - Allow stapserver_t domain to mmap own tmp files Resolves: rhbz#1593122 - Allow sssd_t domain to mmap files labeled as sssd_selinux_manager_exec_t Resolves: rhbz#1592026 - Update policy for ypserv_t domain Resolves: rhbz#1592032 - Allow abrt_dump_oops_t domain to mmap all non security files Resolves: rhbz#1593728 - Allow svirt_t domain mmap svirt_image_t files Resolves: rhbz#1592688 - Allow virtlogd_t domain to write inhibit systemd pipes. Resolves: rhbz#1593740 - Allow sysadm_t and staff_t domains to use sudo io logging Resolves: rhbz#1564470 - Allow sysadm_t domain create sctp sockets Resolves: rhbz#1571591 - Update mount_domtrans() interface to allow caller domain mmap mount_exec_t Resolves: rhbz#1592025 - Allow dhcpc_t to mmap all binaries with label hostname_exec_t, ifconfig_exec_t and netutils_exec_t Resolves: rhbz#1594661- Fix typo in logwatch interface file - Allow spamd_t to manage logwatch_cache_t files/dirs - Allow dnsmasw_t domain to create own tmp files and manage mnt files - Allow fail2ban_client_t to inherit rlimit information from parent process Resolves: rhbz#1513100 - Allow nscd_t to read kernel sysctls Resolves: rhbz#1512852 - Label /var/log/conman.d as conman_log_t Resolves: rhbz#1538363 - Add dac_override capability to tor_t domain Resolves: rhbz#1540711 - Allow certmonger_t to readwrite to user_tmp_t dirs Resolves: rhbz#1543382 - Allow abrt_upload_watch_t domain to read general certs Resolves: rhbz#1545098 - Update postfix_domtrans_master() interface to allow caller domain also mmap postfix_master_exec_t binary Resolves: rhbz#1583087 - Allow postfix_domain to mmap postfix_qmgr_exec_t binaries Resolves: rhbz#1583088 - Allow postfix_domain to mmap postfix_pickup_exec_t binaries Resolves: rhbz#1583091 - Allow chornyd_t read phc2sys_t shared memory Resolves: rhbz#1578883 - Allow virt_qemu_ga_t read utmp Resolves: rhbz#1571202 - Add several allow rules for pesign policy: Resolves: rhbz#1468744 - Allow pesign domain to read /dev/random - Allow pesign domain to create netlink_kobject_uevent_t sockets - Allow pesign domain create own tmp files - Add setgid and setuid capabilities to mysqlfd_safe_t domain Resolves: rhbz#1474440 - Add tomcat_can_network_connect_db boolean Resolves: rhbz#1477948 - Update virt_use_sanlock() boolean to read sanlock state Resolves: rhbz#1448799 - Add sanlock_read_state() interface - Allow postfix_cleanup_t domain to stream connect to all milter sockets BZ(1436026) Resolves: rhbz#1563423 - Update abrt_domtrans and abrt_exec() interfaces to allow caller domain to mmap binary file Resolves:rhbz#1583080 - Update nscd_domtrans and nscd_exec interfaces to allow caller domain also mmap nscd binaries Resolves: rhbz#1583086 - Update snapperd_domtrans() interface to allow caller domain to mmap snapperd_exec_t file Resolves: rhbz#1583802 - Allow zoneminder_t to getattr of fs_t Resolves: rhbz#1585328 - Fix denials during ipa-server-install process on F27+ Resolves: rhbz#1586029 - Allow ipa_dnskey_t to exec ipa_dnskey_exec_t files Resolves: rhbz#1586033 - Allow rhsmcertd_t domain to send signull to postgresql_t domain Resolves: rhbz#1588119 - Allow policykit_t domain to dbus chat with dhcpc_t Resolves: rhbz#1364513 - Adding new boolean keepalived_connect_any() Resolves: rhbz#1443473 - Allow amanda to create own amanda_tmpfs_t files Resolves: rhbz#1452444 - Add amanda_tmpfs_t label. BZ(1243752) - Allow gdomap_t domain to connect to qdomap_port_t Resolves: rhbz#1551944 - Fix typos in sge - Fix typo in openvswitch policy - /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow sshd_keygen_t to execute plymouthd Resolves: rhbz#1583531 - Update seutil_domtrans_setfiles() interface to allow caller domain to do mmap on setfiles_exec_t binary Resolves: rhbz#1583090 - Allow systemd_networkd_t create and relabel tun sockets Resolves: rhbz#1583830 - Allow map audisp_exec_t files fordomains executing this binary Resolves: rhbz#1586042 - Add new interface postgresql_signull() - Add fs_read_xenfs_files() interface.- /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow dac override capability to mandb_t domain BZ(1529399) Resolves: rhbz#1423361 - Allow inetd_child process to chat via dbus with abrt Resolves: rhbz#1428805 - Allow zabbix_agent_t domain to connect to redis_port_t Resolves: rhbz#1418860 - Allow rhsmcertd_t domain to read xenfs_t files Resolves: rhbz#1405870 - Allow zabbix_agent_t to run zabbix scripts Resolves: rhbz#1380697 - Allow rabbitmq_t domain to create own tmp files/dirs Resolves: rhbz#1546897 - Allow policykit_t mmap policykit_auth_exec_t files Resolves: rhbz#1583082 - Allow ipmievd_t domain to read general certs Resolves: rhbz#1514591 - Add sys_ptrace capability to pcp_pmie_t domain - Allow squid domain to exec ldconfig Resolves: rhbz#1532017 - Make working gpg agent in gpg_agent_t domain Resolves: rhbz#1535109 - Update gpg SELinux policy module - Allow kexec to read kernel module files in /usr/lib/modules. Resolves: rhbz#1536690 - Allow mailman_domain to read system network state Resolves: rhbz#1413510 - Allow mailman_mail_t domain to search for apache configs Resolves: rhbz#1413510 - Allow openvswitch_t domain to read neutron state and read/write fixed disk devices Resolves: rhbz#1499208 - Allow antivirus_domain to read all domain system state Resolves: rhbz#1560986 - Allow targetd_t domain to red gconf_home_t files/dirs Resolves: rhbz#1546671 - Allow freeipmi domain to map sysfs_t files Resolves: rhbz#1575918 - Label /usr/libexec/bluetooth/obexd as obexd_exec_t Resolves: rhbz#1351750 - Update rhcs SELinux module Resolves: rhbz#1589257 - Allow iscsid_t domain mmap kernel modules Resolves: rhbz#1589295 - Allow iscsid_t domain mmap own tmp files Resolves: rhbz#1589295 - Update iscsid_domtrans() interface to allow mmap iscsid_exec_t binary Resolves: rhbz#1589295 - Update nscd_socket_use interface to allow caller domain also mmap nscd_var_run_t files. Resolves: rhbz#1589271 - Allow nscd_t domain to mmap system_db_t files Resolves: rhbz#1589271 - Add interface nagios_unconfined_signull() - Allow lircd_t domain read sssd public files Add setgid capability to lircd_t domain Resolves: rhbz#1550700 - Add missing requires - Allow tomcat domain sends email Resolves: rhbz#1585184 - Allow memcached_t domain nnp_transition becuase of systemd security features BZ(1514867) Resolves: rhbz#1585714 - Allow kdump_t domain to map /boot files Resolves: rhbz#1588884 - Fix typo in netutils policy - Allow confined users get AFS tokens Resolves: rhbz#1417671 - Allow sysadm_t domain to chat via dbus Resolves: rhbz#1582146 - Associate sysctl_kernel_t type with filesystem attribute - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Add interface dev_map_sysfs - Allow xdm_t domain to execute xdm_var_lib_t files Resolves: rhbz#1589139 - Allow syslogd_t domain to send signull to nagios_unconfined_plugin_t Resolves: rhbz#1569344 - Label /dev/vhost-vsock char device as vhost_device_t - Add files_map_boot_files() interface Resolves: rhbz#1588884 - Update traceroute_t domain to allow create dccp sockets Resolves: rhbz#1548350- Update ctdb domain to support gNFS setup Resolves: rhbz#1576818 - Allow authconfig_t dbus chat with policykit Resolves: rhbz#1551241 - Allow lircd_t domain to read passwd_file_t Resolves: rhbz:#1550700 - Allow lircd_t domain to read system state Resolves: rhbz#1550700 - Allow smbcontrol_t to mmap samba_var_t files and allow winbind create sockets BZ(1559795) Resolves: rhbz#1574521 - Allow tangd_t domain read certs Resolves: rhbz#1509055 - Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow ctdb_t domain modify ctdb_exec_t files Resolves: rhbz#1572584 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Allow SELinux users (except guest and xguest) to using bluetooth sockets Resolves: rhbz#1557299 - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Fix broken sysadm SELinux module Resolves: rhbz#1557311 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Update ssh_domtrans_keygen interface to allow mmap ssh_keygen_exec_t binary file Resolves: rhbz#1583089 - Allow systemd_networkd_t to read/write tun tap devices Resolves: rhbz#1583830 - Add bridge_socket, dccp_socket, ib_socket and mpls_socket to socket_class_set Resolves: rhbz#1583771 - Allow audisp_t domain to mmap audisp_exec_t binary Resolves: rhbz#1583551 - Fix duplicates in sysadm.te file Resolves: rhbz#1307183 - Allow sysadm_u use xdm Resolves: rhbz#1307183 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix duplicates in sysadm.te file Resolves: rhbz#1307183- Allow sysadm_u use xdm Resolves: rhbz#1307183- Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Improve procmail_domtrans() to allow mmaping procmail_exec_t - Allow hypervvssd_t domain to read fixed disk devices Resolves: rhbz#1581225 - Improve modutils_domtrans_insmod() interface to mmap insmod_exec_t binaries Resolves: rhbz#1581551 - Improve iptables_domtrans() interface to allow mmaping iptables_exec_t binary Resolves: rhbz#1581551 - Improve auth_domtrans_login_programinterface to allow also mmap login_exec_t binaries Resolves: rhbz#1581551 - Improve auth_domtrans_chk_passwd() interface to allow also mmaping chkpwd_exec_t binaries. Resolves: rhbz#1581551 - Allow mmap dhcpc_exec_t binaries in sysnet_domtrans_dhcpc interface- Add dbus_stream_connect_system_dbusd() interface. - Allow pegasus_t domain to mount tracefs_t filesystem Resolves:rhbz#1374570 - Allow psad_t domain to read all domains state Resolves: rhbz#1558439 - Add net_raw capability to named_t domain BZ(1545586) - Allow tomcat_t domain to connect to mongod_t tcp port Resolves:rhbz#1539748 - Allow dovecot and postfix to connect to systemd stream sockets Resolves: rhbz#1368642 - Label /usr/libexec/bluetooth/obexd as bluetoothd_exec_t to run process as bluetooth_t Resolves:rhbz#1351750 - Rename tang policy to tangd - Add interface systemd_rfkill_domtrans() - Allow users staff and sysadm to run wireshark on own domain Resolves:rhbz#1546362 - Allow systemd-bootchart to create own tmpfs files Resolves:rhbz#1510412- Rename tang policy to tangd - Allow virtd_t domain to relabel virt_var_lib_t files Resolves: rhbz#1558121 - Allow logrotate_t domain to stop services via systemd Resolves: rhbz#1527522 - Add tang policy Resolves: rhbz#1509055 - Allow mozilla_plugin_t to create mozilla.pdf file in user homedir with label mozilla_home_t Resolves: rhbz#1559859 - Improve snapperd SELinux policy Resolves: rhbz#1365555 - Allow snapperd_t daemon to create unlabeled dirs. Resolves: rhbz#1365555 - We have inconsistency in cgi templates with upstream, we use _content_t, but refpolicy use httpd__content_t. Created aliasses to make it consistence Resolves: rhbz#1271324 - Allow Openvswitch adding netdev bridge ovs 2.7.2.10 FDP Resolves: rhbz#1503835 - Add new Boolean tomcat_use_execmem Resolves: rhbz#1565226 - Allow domain transition from logrotate_t to chronyc_t Resolves: rhbz#1568281 - Allow nfsd_t domain to read/write sysctl fs files Resolves: rhbz#1516593 - Allow conman to read system state Resolves: rhbz#1377915 - Allow lircd_t to exec shell and add capabilities dac_read_search and dac_override Resolves: rhbz#1550700 - Allow usbmuxd to access /run/udev/data/+usb:*. Resolves: rhbz#1521054 - Allow abrt_t domain to manage kdump crash files Resolves: rhbz#1491585 - Allow systemd to use virtio console Resolves: rhbz#1558121 - Allow transition from sysadm role into mdadm_t domain. Resolves: rhbz#1551568 - Label /dev/op_panel and /dev/opal-prd as opal_device_t Resolves: rhbz#1537618 - Label /run/ebtables.lock as iptables_var_run_t Resolves: rhbz#1511437 - Allow udev_t domain to manage udev_rules_t char files. Resolves: rhbz#1545094 - Allow nsswitch_domain to read virt_var_lib_t files, because of libvirt NSS plugin. Resolves: rhbz#1567753 - Fix filesystem inteface file, we don't have nsfs_fs_t type, just nsfs_t Resolves: rhbz#1547700 - Allow iptables_t domain to create dirs in etc_t with system_conf_t labels- Add new boolean redis_enable_notify() Resolves: rhbz#1421326 - Label /var/log/shibboleth-www(/.*) as httpd_sys_rw_content_t Resolves: rhbz#1549514 - Add new label for vmtools scripts and label it as vmtools_unconfined_t stored in /etc/vmware-tools/ Resolves: rbhz#1463593 - Remove labeling for /etc/vmware-tools to bin_t it should be vmtools_unconfined_exec_t Resolves: rbhz#1463593- Backport several changes for snapperdfrom Fedora Rawhide Resolves: rhbz#1556798 - Allow snapperd_t to set priority for kernel processes Resolves: rhbz#1556798 - Make ganesha nfs server. Resolves: rhbz#1511489 - Allow vxfs filesystem to use SELinux labels Resolves: rhbz#1482880 - Add map permission to selinux-policy Resolves: rhbz#1460322- Label /usr/libexec/dbus-1/dbus-daemon-launch-helper as dbusd_exec_t to have systemd dbus services running in the correct domain instead of unconfined_service_t if unconfined.pp module is enabled. Resolves: rhbz#1546721- Allow openvswitch_t stream connect svirt_t Resolves: rhbz#1540702- Allow openvswitch domain to manage svirt_tmp_t sock files Resolves: rhbz#1540702 - Fix broken systemd_tmpfiles_run() interface- Allow dirsrv_t domain to create tmp link files Resolves: rhbz#1536011 - Label /usr/sbin/ldap-agent as dirsrv_snmp_exec_t Resolves: rhbz#1428568 - Allow ipsec_mgmt_t execute ifconfig_exec_t binaries - Allow ipsec_mgmt_t nnp domain transition to ifconfig_t Resolves: rhbz#1539416- Allow svirt_domain to create socket files in /tmp with label svirt_tmp_t Resolves: rhbz#1540702 - Allow keepalived_t domain getattr proc filesystem Resolves: rhbz#1477542 - Rename svirt_sandbox_file_t to container_file_t and svirt_lxc_net_t to container_t Resolves: rhbz#1538544 - Allow ipsec_t nnp transistions to domains ipsec_mgmt_t and ifconfig_t Resolves: rhbz:#1539416 - Allow systemd_logind_t domain to bind on dhcpd_port_t,pki_ca_port_t,flash_port_t Resolves: rhbz#1479350- Allow openvswitch_t domain to read cpuid, write to sysfs files and creating openvswitch_tmp_t sockets Resolves: rhbz#1535196 - Add new interface ppp_filetrans_named_content() Resolves: rhbz#1530601 - Allow keepalived_t read sysctl_net_t files Resolves: rhbz#1477542 - Allow puppetmaster_t domtran to puppetagent_t Resolves: rhbz#1376893 - Allow kdump_t domain to read kernel ring buffer Resolves: rhbz#1540004 - Allow ipsec_t domain to exec ifconfig_exec_t binaries. Resolves: rhbz#1539416 - Allow unconfined_domain_typ to create pppd_lock_t directory in /var/lock Resolves: rhbz#1530601 - Allow updpwd_t domain to create files in /etc with shadow_t label Resolves: rhbz#1412838 - Allow iptables sysctl load list support with SELinux enforced Resolves: rhbz#1535572- Allow virt_domains to acces infiniband pkeys. Resolves: rhbz#1533183 - Label /usr/libexec/ipsec/addconn as ipsec_exec_t to run this script as ipsec_t instead of init_t Resolves: rhbz#1535133 - Allow audisp_remote_t domain write to files on all levels Resolves: rhbz#1534924- Allow vmtools_t domain creating vmware_log_t files Resolves: rhbz#1507048 - Allow openvswitch_t domain to acces infiniband devices Resolves: rhbz#1532705- Allow chronyc_t domain to manage chronyd_keys_t files. Resolves: rhbz#1530525 - Make virtlog_t domain system dbus client Resolves: rhbz#1481109 - Update openvswitch SELinux module Resolves: rhbz#1482682 - Allow virtd_t to create also sock_files with label virt_var_run_t Resolves: rhbz#1484075- Allow domains that manage logfiles to man logdirs Resolves: rhbz#1523811- Label /dev/drm_dp_aux* as xserver_misc_device_t Resolves: rhbz#1520897 - Allow sysadm_t to run puppet_exec_t binaries as puppet_t Resolves: rhbz#1255745- Allow tomcat_t to manage pki_tomcat pid files Resolves: rhbz#1478371 - networkmanager: allow talking to openvswitch Resolves: rhbz#1517247 - Allow networkmanager_t and opensm_t to manage subned endports for IPoIB VLANs Resolves: rhbz#1517895 - Allow domains networkmanager_t and opensm_t to control IPoIB VLANs Resolves: rhbz#1517744 - Fix typo in guest interface file Resolves: rhbz#1468254 - Allow isnsd_t domain to accept tcp connections. Resolves: rhbz#1390208- Allow getty to use usbttys Resolves: rhbz#1514235- Allow ldap_t domain to manage also slapd_tmp_t lnk files Resolves: rhbz#1510883 - Allow cluster_t domain creating bundles directory with label var_log_t instead of cluster_var_log_t Resolves: rhbz:#1508360 - Add dac_read_search and dac_override capabilities to ganesha Resolves: rhbz#1483451- Add dependency for policycoreutils-2.5.18 becuase of new cgroup_seclabel policy capability Resolves: rhbz#1510145- Allow jabber domains to connect to postgresql ports Resolves: rhbz#1438489 - Dontaudit accountsd domain creating dirs in /root Resolves: rhbz#1456760 - Dontaudit slapd_t to block suspend system Resolves: rhbz: #1479759 - Allow spamc_t to stream connect to cyrus. Resolves: rhbz#1382955 - allow imapd to read /proc/net/unix file Resolves: rhbz#1393030 - Allow passenger to connect to mysqld_port_t Resolves: rhbz#1433464- Allow chronyc_t domain to use user_ptys Resolves: rhbz#1470150 - allow ptp4l to read /proc/net/unix file - Allow conmand to use usb ttys. Resolves: rhbz#1505121 - Label all files /var/log/opensm.* as opensm_log_t because opensm creating new log files with name opensm-subnet.lst Resolves: rhbz#1505845 - Allow chronyd daemon to execute chronyc. Resolves: rhbz#1508486 - Allow firewalld exec ldconfig. Resolves: rhbz#1375576 - Allow mozilla_plugin_t domain to dbus chat with devicekit Resolves: rhbz#1460477 - Dontaudit leaked logwatch pipes Resolves: rhbz#1450119 - Label /usr/bin/VGAuthService as vmtools_exec_t to confine this daemon. Resolves: rhbz#1507048 - Allow httpd_t domain to execute hugetlbfs_t files Resolves: rhbz#1507682 - Allow nfsd_t domain to read configfs_t files/dirs Resolves: rhbz#1439442 - Hide all allow rules with ptrace inside deny_ptrace boolean Resolves: rhbz#1421075 - Allow tgtd_t domain to read generic certs Resolves: rhbz#1438532 - Allow ptp4l to send msgs via dgram socket to unprivileged user domains Resolves: rhbz#1429853 - Allow dirsrv_snmp_t to use inherited user ptys and read system state Resolves: rhbz#1428568 - Allow glusterd_t domain to create own tmpfs dirs/files Resolves: rhbz#1411310 - Allow keepalived stream connect to snmp Resolves: rhbz#1401556 - After fix in kernel where LSM hooks for dac_override and dac_search_read capability was swaped we need to fix it also in policy Resolves: rhbz#1507089- Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow chronyd_t do request kernel module and block_suspend capability Resolves: rhbz#1350765 - Allow system_cronjob_t to create /var/lib/letsencrypt dir with right label Resolves: rhbz#1447278 - Allow httpd_t also read httpd_user_content_type dirs when httpd_enable_homedirs is enables Resolves: rhbz#1491994 - Allow svnserve to use kerberos Resolves: rhbz#1475271 - Allow conman to use ptmx. Add conman_use_nfs boolean Resolves: rhbz#1377915 - Add nnp transition for services using: NoNewPrivileges systemd security feature Resolves: rhbz#1311430 - Add SELinux support for chronyc Resolves: rhbz#1470150 - Add dac_read_search capability to openvswitch_t domain Resolves: rhbz#1501336 - Allow svnserve to manage own svnserve_log_t files/dirs Resolves: rhbz#1480741 - Allow keepalived_t to search network sysctls Resolves: rhbz#1477542 - Allow puppetagent_t domain dbus chat with rhsmcertd_t domain Resolves: rhbz#1446777 - Add dccp_socket into socker_class_set subset Resolves: rhbz#1459941 - Allow iptables_t to run setfiles to restore context on system Resolves: rhbz#1489118 - Label 20514 tcp/udp ports as syslogd_port_t Label 10514 tcp/udp portas as syslog_tls_port_t Resolves: rhbz:#1411400 - Make nnp transition Active Resolves: rhbz#1480518 - Label tcp 51954 as isns_port_t Resolves: rhbz#1390208 - Add dac_read_search capability chkpwd_t Resolves: rhbz#1376991 - Add support for running certbot(letsencrypt) in crontab Resolves: rhbz#1447278 - Add init_nnp_daemon_domain interface - Allow xdm_t to gettattr /dev/loop-control device Resolves: rhbz#1462925 - Allow nnp trasintion for unconfined_service_t Resolves: rhbz#1311430 - Allow unpriv user domains and unconfined_service_t to use chronyc Resolves: rhbz#1470150 - Allow iptables to exec plymouth. Resolves: rhbz#1480374 - Fix typo in fs_unmount_tracefs interface. Resolves: rhbz#1371057 - Label postgresql-check-db-dir as postgresql_exec_t Resolves: rhbz#1490956- We should not ship selinux-policy with permissivedomains enabled. Resolves: rhbz#1494172 - Fix order of installing selinux-policy-sandbox, because of depedencied in sandbox module, selinux-policy-targeted needs to be installed before selinux-policy-sandbox Resolves: rhbz#1492606- Allow tomcat to setsched Resolves: rhbz#1492730 - Fix rules blocking ipa-server upgrade process Resolves: rhbz#1478371 - Add new boolean tomcat_read_rpm_db() Resolves: rhbz#1477887 - Allow tomcat to connect on mysqld tcp ports - Add ctdbd_t domain sys_source capability and allow setrlimit Resolves: rhbz#1491235 - Fix keepalived SELinux module - Allow automount domain to manage mount pid files Resolves: rhbz#1482381 - Allow stunnel_t domain setsched Resolves: rhbz#1479383 - Add keepalived domain setpgid capability Resolves: rhbz#1486638 - Allow tomcat domain to connect to mssql port Resolves: rhbz#1484572 - Remove snapperd_t from unconfined domaines Resolves: rhbz#1365555 - Fix typo bug in apache module Resolves: rhbz#1397311 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Add interface systemd_tmpfiles_run - End of file cannot be in comment - Allow systemd-logind to use ypbind Resolves: rhbz#1479350 - Add creating opasswd file with shadow_t SELinux label in auth_manage_shadow() interface Resolves: rhbz#1412838 - Allow sysctl_irq_t assciate with proc_t Resolves: rhbz#1485909 - Enable cgourp sec labeling Resolves: rhbz#1485947 - Add cgroup_seclabel policycap. Resolves: rhbz#1485947 - Allow sshd_t domain to send signull to xdm_t processes Resolves: rhbz#1448959 - Allow updpwd_t domain auth file name trans Resolves: rhbz#1412838 - Allow sysadm user to run systemd-tmpfiles Resolves: rbhz#1325364 - Add support labeling for vmci and vsock device Resolves: rhbz#1451358 - Add userdom_dontaudit_manage_admin_files() interface Resolves: rhbz#1323792 - Allow iptables_t domain to read files with modules_conf_t label Resolves: rhbz#1373220 - init: Add NoNewPerms support for systemd. Resolves: rhbz#1480518 - Add nnp_nosuid_transition policycap and related class/perm definitions. Resolves: rhbz#1480518 - refpolicy: Infiniband pkeys and endports Resolves: rhbz#1464484- Allow certmonger using systemctl on pki_tomcat unit files Resolves: rhbz#1481388- Allow targetd_t to create own tmp files. - Dontaudit targetd_t to exec rpm binary file. Resolves: rhbz#1373860 Resolves: rhbz#1424621- Add few rules to make working targetd daemon with SELinux Resolves: rhbz#1373860 - Allow ipmievd_t domain to load kernel modules Resolves: rhbz#1441081 - Allow logrotate to reload transient systemd unit Resolves: rhbz#1440515 - Add certwatch_t domain dac_override and dac_read_search capabilities Resolves: rhbz#1422000 - Allow postgrey to execute bin_t files and add postgrey into nsswitch_domain Resolves: rhbz#1412072 - Allow nscd_t domain to search network sysctls Resolves: rhbz#1432361 - Allow iscsid_t domain to read mount pid files Resolves: rhbz#1482097 - Allow ksmtuned_t domain manage sysfs_t files/dirs Resolves: rhbz#1413865 - Allow keepalived_t domain domtrans into iptables_t Resolves: rhbz#1477719 - Allow rshd_t domain reads net sysctls Resolves: rhbz#1477908 - Add interface seutil_dontaudit_read_module_store() - Update interface lvm_rw_pipes() by adding also open permission - Label /dev/clp device as vfio_device_t Resolves: rhbz#1477624 - Allow ifconfig_t domain unmount fs_t Resolves: rhbz#1477445 - Label /dev/gpiochip* devices as gpio_device_t Resolves: rhbz#1477618 - Add interface dev_manage_sysfs() Resolves: rhbz#1474989- Label /usr/libexec/sudo/sesh as shell_exec_t Resolves: rhbz#1480791- Allow tomcat_t domain couple capabilities to make working tomcat-jsvc Resolves: rhbz#1470735- Allow llpdad send dgram to libvirt Resolves: rhbz#1472722- Add new boolean gluster_use_execmem Resolves: rhbz#1469027 - Allow cluster_t and glusterd_t domains to dbus chat with ganesha service Resolves: rhbz#1468581- Dontaudit staff_t user read admin_home_t files. Resolves: rhbz#1290633- Allow couple rules needed to start targetd daemon with SELinux in enforcing mode Resolves: rhbz#1424621 - Add interface lvm_manage_metadata Resolves: rhbz#1424621- Allow sssd_t to read realmd lib files. Resolves: rhbz#1436689 - Add permission open to files_read_inherited_tmp_files() interface Resolves: rhbz#1290633 Resolves: rhbz#1457106- Allow unconfined_t user all user namespace capabilties. Resolves: rhbz#1461488- Allow httpd_t to read realmd_var_lib_t files Resolves: rhbz#1436689- Allow named_t to bind on udp 4321 port Resolves: rhbz#1312972 - Allow systemd-sysctl cap. sys_ptrace Resolves: rhbz#1458999- Allow pki_tomcat_t execute ldconfig. Resolves: rhbz#1436689- Allow iscsi domain load kernel module. Resolves: rhbz#1457874 - Allow keepalived domain connect to squid tcp port Resolves: rhbz#1457455 - Allow krb5kdc_t domain read realmd lib files. Resolves: rhbz#1436689 - xdm_t should view kernel keys Resolves: rhbz#1432645- Allow tomcat to connect on all unreserved ports - Allow ganesha to connect to all rpc ports Resolves: rhbz#1448090 - Update ganesha with another fixes. Resolves: rhbz#1448090 - Update rpc_read_nfs_state_data() interface to allow read also lnk_files. Resolves: rhbz#1448090 - virt_use_glusterd boolean should be in optional block Update ganesha module to allow create tmp files Resolves: rhbz#1448090 - Hide broken symptoms when machine is configured with network bounding.- Add new boolean virt_use_glusterd Resolves: rhbz#1455994 - Add capability sys_boot for sbd_t domain - Allow sbd_t domain to create rpc sysctls. Resolves: rhbz#1455631 - Allow ganesha_t domain to manage glusterd_var_run_t pid files. Resolves: rhbz#1448090- Create new interface: glusterd_read_lib_files() - Allow ganesha read glusterd lib files. - Allow ganesha read network sysctls Resolves: rhbz#1448090- Add few allow rules to ganesha module Resolves: rhbz#1448090 - Allow condor_master_t to read sysctls. Resolves: rhbz#1277506 - Add dac_override cap to ctdbd_t domain Resolves: rhbz#1435708 - Label 8750 tcp/udp port as dey_keyneg_port_t Resolves: rhbz#1448090- Add ganesha_use_fusefs boolean. Resolves: rhbz#1448090- Allow httpd_t reading kerberos kdc config files Resolves: rhbz#1452215 - Allow tomcat_t domain connect to ibm_dt_2 tcp port. Resolves: rhbz#1447436 - Allow stream connect to initrc_t domains Resolves: rhbz#1447436 - Allow dnsmasq_t domain to read systemd-resolved pid files. Resolves: rhbz#1453114 - Allow tomcat domain name_bind on tcp bctp_port_t Resolves: rhbz#1451757 - Allow smbd_t domain generate debugging files under /var/run/gluster. These files are created through the libgfapi.so library that provides integration of a GlusterFS client in the Samba (vfs_glusterfs) process. Resolves: rhbz#1447669 - Allow condor_master_t write to sysctl_net_t Resolves: rhbz#1277506 - Allow nagios check disk plugin read /sys/kernel/config/ Resolves: rhbz#1277718 - Allow pcp_pmie_t domain execute systemctl binary Resolves: rhbz#1271998 - Allow nagios to connect to stream sockets. Allow nagios start httpd via systemctl Resolves: rhbz#1247635 - Label tcp/udp port 1792 as ibm_dt_2_port_t Resolves: rhbz#1447436 - Add interface fs_read_configfs_dirs() - Add interface fs_read_configfs_files() - Fix systemd_resolved_read_pid interface - Add interface systemd_resolved_read_pid() Resolves: rhbz#1453114 - Allow sshd_net_t domain read/write into crypto devices Resolves: rhbz#1452759 - Label 8999 tcp/udp as bctp_port_t Resolves: rhbz#1451757- nmbd_t needs net_admin capability like smbd Resolves: rhbz#1431859 - Dontaudit net_admin capability for domains postfix_master_t and postfix_qmgr_t Resolves: rhbz#1431859 - Allow rngd domain read sysfs_t Resolves: rhbz#1451735 - Add interface pki_manage_common_files() Resolves: rhbz#1447436 - Allow tomcat_t domain to manage pki_common_t files and dirs Resolves: rhbz#1447436 - Use stricter fc rules for sssd sockets in /var/run Resolves: rhbz#1448060 - Allow certmonger reads httpd_config_t files Resolves: rhbz#1436689 - Allow keepalived_t domain creating netlink_netfilter_socket. Resolves: rhbz#1451684 - Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321- Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Allow sssd_t domain creating sock files labeled as sssd_var_run_t in /var/run/ Resolves: rhbz#1448056 Resolves: rhbz#1448060 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321 - Allow netutils setpcap capability Resolves:1444438- Update targetd policy to accommodate changes in the service Resolves: rhbz#1424621 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Update virt_rw_stream_sockets_svirt() interface to allow confined users set socket options. Resolves: rhbz#1415841 - Allow radius domain stream connec to postgresql Resolves: rhbz#1446145 - Allow virt_domain to read raw fixed_disk_device_t to make working blockcommit Resolves: rhbz#1449977 - Allow glusterd_t domain start ganesha service Resolves: rhbz#1448090 - Made few cosmetic changes in sssd SELinux module Resolves: rhbz#1448060 - sssd-kcm should not run as unconfined_service_t BZ(1447411) Resolves: rhbz#1448060 - Add sssd_secrets labeling Also add named_filetrans interface to make sure all labels are correct Resolves: rhbz#1448056 - Allow keepalived_t domain read usermodehelper_t Resolves: rhbz#1449769 - Allow tomcat_t domain read pki_common_t files Resolves: rhbz#1447436 - Add interface pki_read_common_files() Resolves: rhbz#1447436- Allow hypervkvp_t domain execute hostname Resolves: rhbz#1449064 - Dontaudit sssd_selinux_manager_t use of net_admin capability Resolves: rhbz#1444955 - Allow tomcat_t stream connect to pki_common_t Resolves: rhbz#1447436 - Dontaudit xguest_t's attempts to listen to its tcp_socket - Allow sssd_selinux_manager_t to ioctl init_t sockets Resolves: rhbz#1436689 - Allow _su_t to create netlink_selinux_socket Resolves rhbz#1146987 - Allow unconfined_t to module_load any file Resolves rhbz#1442994- Improve ipa_cert_filetrans_named_content() interface to also allow caller domain manage ipa_cert_t type. Resolves: rhbz#1436689- Allow pki_tomcat_t domain read /etc/passwd. Resolves: rhbz#1436689 - Allow tomcat_t domain read ipa_tmp_t files Resolves: rhbz#1436689 - Label new path for ipa-otpd Resolves: rhbz#1446353 - Allow radiusd_t domain stream connect to postgresql_t Resolves: rhbz#1446145 - Allow rhsmcertd_t to execute hostname_exec_t binaries. Resolves: rhbz#1445494 - Allow virtlogd to append nfs_t files when virt_use_nfs=1 Resolves: rhbz#1402561- Update tomcat policy to adjust for removing unconfined_domain attr. Resolves: rhbz#1432083 - Allow httpd_t domain read also httpd_user_content_type lnk_files. Resolves: rhbz#1383621 - Allow httpd_t domain create /etc/httpd/alias/ipaseesion.key with label ipa_cert_t Resolves: rhbz#1436689 - Dontaudit _gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Label /var/www/html/nextcloud/data as httpd_sys_rw_content_t Resolves: rhbz#1425530 - Add interface ipa_filetrans_named_content() Resolves: rhbz#1432115 - Allow tomcat use nsswitch Resolves: rhbz#1436689 - Allow certmonger_t start/status generic services Resolves: rhbz#1436689 - Allow dirsrv read cgroup files. Resolves: rhbz#1436689 - Allow ganesha_t domain read/write infiniband devices. Resolves: rhbz#1383784 - Allow sendmail_t domain sysctl_net_t files Resolves: rhbz#1369376 - Allow targetd_t domain read network state and getattr on loop_control_device_t Resolves: rhbz#1373860 - Allow condor_schedd_t domain send mails. Resolves: rhbz#1277506 - Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689 - Allow staff to systemctl virt server when staff_use_svirt=1 Resolves: rhbz#1415841 - Allow unconfined_t create /tmp/ca.p12 file with ipa_tmp_t context Resolves: rhbz#1432115 - Label /sysroot/ostree/deploy/rhel-atomic-host/* as root_t Resolves: rhbz#1428112- Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689- Hide broken symptoms when using kernel 3.10.0-514+ with network bonding. Postfix_picup_t domain requires NET_ADMIN capability which is not really needed. Resolves: rhbz#1431859 - Fix policy to reflect all changes in new IPA release Resolves: rhbz#1432115 Resolves: rhbz#1436689- Allow sbd_t to read/write fixed disk devices Resolves: rhbz#1440165 - Add sys_ptrace capability to radiusd_t domain Resolves: rhbz#1426641 - Allow cockpit_session_t domain connects to ssh tcp ports. Resolves: rhbz#1413509- Update tomcat policy to make working ipa install process Resolves: rhbz#1436689- Allow pcp_pmcd_t net_admin capability. - Allow pcp_pmcd_t read net sysctls - Allow system_cronjob_t create /var/run/pcp with pcp_var_run_t Resolves: rhbz#1336211- Fix all AVC denials during pkispawn of CA Resolves: rhbz#1436383 - Update pki interfaces and tomcat module Resolves: rhbz#1436689- Update pki interfaces and tomcat module Resolves: rhbz#1436689- Dontaudit firewalld wants write to /root Resolves: rhbz#1438708 - Dontaudit firewalld to create dirs in /root/ Resolves: rhbz#1438708 - Allow sendmail to search network sysctls Resolves: rhbz#1369376 - Add interface gssd_noatsecure() Resolves: rhbz#1438036 - Add interface gssproxy_noatsecure() Resolves: rhbz#1438036 - Dontaudit pcp_pmlogger_t search for xserver logs. Allow pcp_pmlogger_t to send signals to unconfined doamins Allow pcp_pmlogger_t to send logs to journals Resolves: rhbz#1379371 - Allow chronyd_t net_admin capability to allow support HW timestamping. Resolves: rhbz#1416015 - Update tomcat policy Resolves: rhbz#1436689 Resolves: rhbz#1436383 - Allow certmonger to start haproxy service Resolves: rhbz#1349394 - Allow init noatsecure for gssd and gssproxy Resolves: rhbz#1438036- geoclue wants to dbus chat with avahi Resolves: rhbz#1434286 - Allow iptables get list of kernel modules Resolves: rhbz#1367520 - Allow unconfined_domain_type to enable/disable transient unit Resolves: rhbz#1337041 - Add interfaces init_enable_transient_unit() and init_disable_transient_unit - Revert "Allow sshd setcap capability. This is needed due to latest changes in sshd" Resolves: rhbz#1435264 - Label sysroot dir under ostree as root_t Resolves: rhbz#1428112- Remove ganesha_t domain from permissive domains. Resolves: rhbz#1436988- Allow named_t domain bind on several udp ports Resolves: rhbz#1312972 - Update nscd_use() interface Resolves: rhbz#1281716 - Allow radius_t domain ptrace Resolves: rhbz#1426641 - Update nagios to allos exec systemctl Resolves: rhbz#1247635 - Update pcp SELinux module to reflect all pcp changes Resolves: rhbz#1271998 - Label /var/lib/ssl_db as squid_cache_t Label /etc/squid/ssl_db as squid_cache_t Resolves: rhbz#1325527 - Allow pcp_pmcd_t domain search for network sysctl Allow pcp_pmcd_t domain sys_ptrace capability Resolves: rhbz#1336211- Allow drbd load modules Resolves: rhbz#1134883 - Revert "Add sys_module capability for drbd Resolves: rhbz#1134883" - Allow stapserver list kernel modules Resolves: rhbz#1325976 - Update targetd policy Resolves: rhbz#1373860 - Add sys_admin capability to amanda Resolves: rhbz#1371561 - Allow hypervvssd_t to read all dirs. Resolves: rhbz#1331309 - Label /run/haproxy.sock socket as haproxy_var_run_t Resolves: rhbz#1386233 - Allow oddjob_mkhomedir_t to mamange autofs_t dirs. Resolves: rhbz#1408819 - Allow tomcat to connect on http_cache_port_t Resolves: rhbz#1432083 - Allow geoclue to send msgs to syslog. Resolves: rhbz#1434286 - Allow condor_master_t domain capability chown. Resolves: rhbz#1277506 - Update mta_filetrans_named_content() interface to allow calling domain create files labeled as etc_aliases_t in dir labeled as etc_mail_t. Resolves: rhbz#1167468 - Allow nova domain search for httpd configuration. Resolves: rhbz#1190761 - Add sys_module capability for drbd Resolves: rhbz#1134883 - Allow user_u users stream connect to dirsrv, Allow sysadm_u and staff_u users to manage dirsrv files Resolves: rhbz#1286474 - Allow systemd_networkd_t communicate with systemd_networkd_t via dbus Resolves: rhbz#1278010- Add haproxy_t domain fowner capability Resolves: rhbz#1386233 - Allow domain transition from ntpd_t to hwclock_t domains Resolves: rhbz#1375624 - Allow cockpit_session_t setrlimit and sys_resource Resolves: rhbz#1402316 - Dontaudit svirt_t read state of libvirtd domain Resolves: rhbz#1426106 - Update httpd and gssproxy modules to reflects latest changes in freeipa Resolves: rhbz#1432115 - Allow iptables read modules_conf_t Resolves: rhbz#1367520- Remove tomcat_t domain from unconfined domains Resolves: rhbz#1432083 - Create new boolean: sanlock_enable_home_dirs() Resolves: rhbz#1432783 - Allow mdadm_t domain to read/write nvme_device_t Resolves: rhbz#1431617 - Remove httpd_user_*_content_t domains from user_home_type attribute. This tighten httpd policy and acces to user data will be more strinct, and also fix mutual influente between httpd_enable_homedirs and httpd_read_user_content Resolves: rhbz#1383621 - Dontaudit domain to create any file in /proc. This is kernel bug. Resolves: rhbz#1412679 - Add interface dev_rw_nvme Resolves: rhbz#1431617- Allow gssproxy to get attributes on all filesystem object types. Resolves: rhbz#1430295 - Allow ganesha to chat with unconfined domains via dbus Resolves: rhbz#1426554 - add the policy required for nextcloud Resolves: rhbz#1425530 - Add nmbd_t capability2 block_suspend Resolves: rhbz#1425357 - Label /var/run/chrony as chronyd_var_run_t Resolves: rhbz#1416015 - Add domain transition from sosreport_t to iptables_t Resolves: rhbz#1359789 - Fix path to /usr/lib64/erlang/erts-5.10.4/bin/epmd Resolves: rhbz:#1332803- Update rpm macros Resolves: rhbz#1380854- Add handling booleans via selinux-policy macros in custom policy spec files. Resolves: rhbz#1380854- Allow openvswitch to load kernel modules Resolves: rhbz#1405479- Allow openvswitch read script state. Resolves: rhbz#1405479- Update ganesha policy Resolves: rhbz#1426554 Resolves: rhbz#1383784 - Allow chronyd to read adjtime Resolves: rhbz#1416015 - Fixes for chrony version 2.2 Resolves: rhbz#1416015 - Add interface virt_rw_stream_sockets_svirt() Resolves: rhbz#1415841 - Label /dev/ss0 as gpfs_device_t Resolves: rhbz#1383784 - Allow staff to rw svirt unix stream sockets. Resolves: rhbz#1415841 - Label /rhev/data-center/mnt as mnt_t Resolves: rhbz#1408275 - Associate sysctl_rpc_t with proc filesystems Resolves: rhbz#1350927 - Add new boolean: domain_can_write_kmsg Resolves: rhbz#1415715- Allow rhsmcertd_t dbus chat with system_cronjob_t Resolves: rhbz#1405341 - Allow openvswitch exec hostname and readinitrc_t files Resolves: rhbz#1405479 - Improve SELinux context for mysql_db_t objects. Resolves: rhbz#1391521 - Allow postfix_postdrop to communicate with postfix_master via pipe. Resolves: rhbz#1379736 - Add radius_use_jit boolean Resolves: rhbz#1426205 - Label /var/lock/subsys/iptables as iptables_lock_t Resolves: rhbz#1405441 - Label /usr/lib64/erlang/erts-5.10.4/bin/epmd as lib_t Resolves: rhbz#1332803 - Allow can_load_kernmodule to load kernel modules. Resolves: rhbz#1423427 Resolves: rhbz#1424621- Allow nfsd_t domain to create sysctls_rpc_t files Resolves: rhbz#1405304 - Allow openvswitch to create netlink generic sockets. Resolves: rhbz#1397974 - Create kernel_create_rpc_sysctls() interface Resolves: rhbz#1405304- Allow nfsd_t domain rw sysctl_rpc_t dirs Resolves: rhbz#1405304 - Allow cgdcbxd_t to manage cgroup files. Resolves: rhbz#1358493 - Allow cmirrord_t domain to create netlink_connector sockets Resolves: rhbz#1412670 - Allow fcoemon to create netlink scsitransport sockets Resolves: rhbz#1362496 - Allow quota_nld_t create netlink_generic sockets Resolves: rhbz#1358679 - Allow cgred_t create netlink_connector sockets Resolves: rhbz#1376357 - Add dhcpd_t domain fowner capability Resolves: rhbz#1358485 - Allow acpid to attempt to connect to the Linux kernel via generic netlink socket. Resolves: rhbz#1358478 - Rename docker module to container module Resolves: rhbz#1386916 - Allow setflies to mount tracefs Resolves: rhbz#1376357 - Allow iptables to read nsfs files. Resolves: rhbz#1411316 - Allow systemd_bootchart_t domain create dgram sockets. Resolves: rhbz#1365953 - Rename docker interfaces to container Resolves: rhbz#1386916- Allow initrc_t domain to run rhel-autorelabel script properly during boot process Resolves: rhbz#1379722 - Allow systemd_initctl_t to create and connect unix_dgram sockets Resolves: rhbz#1365947 - Allow ifconfig_t to mount/unmount nsfs_t filesystem Resolves: rhbz#1349814 - Add interfaces allowing mount/unmount nsfs_t filesystem Resolves: rhbz#1349814- Add interface init_stream_connectto() Resolves:rhbz#1365947 - Allow rhsmcertd domain signull kernel. Resolves: rhbz#1379781 - Allow kdumpgui domain to read nvme device - Allow insmod_t to load kernel modules Resolves: rhbz#1421598 - Add interface files_load_kernel_modules() Resolves: rhbz#1421598 - Add SELinux support for systemd-initctl daemon Resolves:rhbz#1365947 - Add SELinux support for systemd-bootchart Resolves: rhbz#1365953- Allow firewalld to getattr open search read modules_object_t:dir Resolves: rhbz#1418391 - Fix label for nagios plugins in nagios file conxtext file Resolves: rhbz#1277718 - Add sys_ptrace capability to pegasus domain Resolves: rhbz#1381238 - Allow sssd_t domain setpgid Resolves:rhbz#1416780 - After the latest changes in nfsd. We should allow nfsd_t to read raw fixed disk. Resolves: rhbz#1350927 - Allow kdumpgui domain to read nvme device Resolves: rhbz#1415084 - su using libselinux and creating netlink_selinux socket is needed to allow libselinux initialization. Resolves: rhbz#1146987 - Add user namespace capability object classes. Resolves: rhbz#1368057 - Add module_load permission to class system Resolves:rhbz#1368057 - Add the validate_trans access vector to the security class Resolves: rhbz#1368057 - Add "binder" security class and access vectors Resolves: rhbz#1368057 - Allow ifconfig_t domain read nsfs_t Resolves: rhbz#1349814 - Allow ping_t domain to load kernel modules. Resolves: rhbz#1388363- Allow systemd container to read/write usermodehelperstate Resolves: rhbz#1403254 - Label udp ports in range 24007-24027 as gluster_port_t Resolves: rhbz#1404152- Allow glusterd_t to bind on glusterd_port_t udp ports. Resolves: rhbz#1404152 - Revert: Allow glusterd_t to bind on med_tlp port.- Allow glusterd_t to bind on med_tlp port. Resolves: rhbz#1404152 - Update ctdbd_t policy to reflect all changes. Resolves: rhbz#1402451 - Label tcp port 24009 as med_tlp_port_t Resolves: rhbz#1404152 - Issue appears during update directly from RHEL-7.0 to RHEL-7.3 or above. Modules pkcsslotd and vbetools missing in selinux-policy package for RHEL-7.3 which causing warnings during SELinux policy store migration process. Following patch fixes issue by skipping pkcsslotd and vbetools modules migration.- Allow ctdbd_t domain transition to rpcd_t Resolves:rhbz#1402451- Fixes for containers Allow containers to attempt to write to unix_sysctls. Allow cotainers to use the FD's leaked to them from parent processes. Resolves: rhbz#1403254- Allow glusterd_t send signals to userdomain. Label new glusterd binaries as glusterd_exec_t Resolves: rhbz#1404152 - Allow systemd to stop glusterd_t domains. Resolves: rhbz#1400493- Make working CTDB:NFS: CTDB failover from selinux-policy POV Resolves: rhbz#1402451- Add kdump_t domain sys_admin capability Resolves: rhbz#1375963- Allow puppetagent_t to access timedated dbus. Use the systemd_dbus_chat_timedated interface to allow puppetagent_t the access. Resolves: rhbz#1399250- Update systemd on RHEL-7.2 box to version from RHEL-7.3 and then as a separate yum command update the selinux policy systemd will start generating USER_AVC denials and will start returning "Access Denied" errors to DBus clients Resolves: rhbz#1393505- Allow cluster_t communicate to fprintd_t via dbus Resolves: rhbz#1349798- Fix error message during update from RHEL-7.2 to RHEL-7.3, when /usr/sbin/semanage command is not installed and selinux-policy-migrate-local-changes.sh script is executed in %post install phase of selinux-policy package Resolves: rhbz#1392010- Allow GlusterFS with RDMA transport to be started correctly. It requires ipc_lock capability together with rw permission on rdma_cm device. Resolves: rhbz#1384488 - Allow glusterd to get attributes on /sys/kernel/config directory. Resolves: rhbz#1384483- Use selinux-policy-migrate-local-changes.sh instead of migrateStore* macros - Add selinux-policy-migrate-local-changes service Resolves: rhbz#1381588- Allow sssd_selinux_manager_t to manage also dir class. Resolves: rhbz#1368097 - Add interface seutil_manage_default_contexts_dirs() Resolves: rhbz#1368097- Add virt_sandbox_use_nfs -> virt_use_nfs boolean substitution. Resolves: rhbz#1355783- Allow pcp_pmcd_t domain transition to lvm_t Add capability kill and sys_ptrace to pcp_pmlogger_t Resolves: rhbz#1309883- Allow ftp daemon to manage apache_user_content Resolves: rhbz#1097775 - Label /etc/sysconfig/oracleasm as oracleasm_conf_t Resolves: rhbz#1331383 - Allow oracleasm to rw inherited fixed disk device Resolves: rhbz#1331383 - Allow collectd to connect on unix_stream_socket Resolves: rhbz#1377259- Allow iscsid create netlink iscsid sockets. Resolves: rhbz#1358266 - Improve regexp for power_unit_file_t files. To catch just systemd power unit files. Resolves: rhbz#1375462- Update oracleasm SELinux module that can manage oracleasmfs_t blk files. Add dac_override cap to oracleasm_t domain. Resolves: rhbz#1331383 - Add few rules to pcp SELinux module to make ti able to start pcp_pmlogger service Resolves: rhbz#1206525- Add oracleasm_conf_t type and allow oracleasm_t to create /dev/oracleasm Resolves: rhbz#1331383 - Label /usr/share/pcp/lib/pmie as pmie_exec_t and /usr/share/pcp/lib/pmlogger as pmlogger_exec_t Resolves: rhbz#1206525 - Allow mdadm_t to getattr all device nodes Resolves: rhbz#1365171 - Add interface dbus_dontaudit_stream_connect_system_dbusd() Resolves:rhbz#1052880 - Add virt_stub_* interfaces for docker policy which is no longer a part of our base policy. Resolves: rhbz#1372705 - Allow guest-set-user-passwd to set users password. Resolves: rhbz#1369693 - Allow samdbox domains to use msg class Resolves: rhbz#1372677 - Allow domains using kerberos to read also kerberos config dirs Resolves: rhbz#1368492 - Allow svirt_sandbox_domains to r/w onload sockets Resolves: rhbz#1342930 - Add interface fs_manage_oracleasm() Resolves: rhbz#1331383 - Label /dev/kfd as hsa_device_t Resolves: rhbz#1373488 - Update seutil_manage_file_contexts() interface that caller domain can also manage file_context_t dirs Resolves: rhbz#1368097 - Add interface to write to nsfs inodes Resolves: rhbz#1372705 - Allow systemd services to use PrivateNetwork feature Resolves: rhbz#1372705 - Add a type and genfscon for nsfs. Resolves: rhbz#1372705 - Allow run sulogin_t in range mls_systemlow-mls_systemhigh. Resolves: rhbz#1290400- Allow arpwatch to create netlink netfilter sockets. Resolves: rhbz#1358261 - Fix file context for /etc/pki/pki-tomcat/ca/ - new interface oddjob_mkhomedir_entrypoint() - Move label for /var/lib/docker/vfs/ to proper SELinux module - Allow mdadm to get attributes from all devices. - Label /etc/puppetlabs as puppet_etc_t. - Allow systemd-machined to communicate to lxc container using dbus - Allow systemd_resolved to send dbus msgs to userdomains Resolves: rhbz#1236579 - Allow systemd-resolved to read network sysctls Resolves: rhbz#1236579 - Allow systemd_resolved to connect on system bus. Resolves: rhbz#1236579 - Make entrypoint oddjob_mkhomedir_exec_t for unconfined_t - Label all files in /dev/oracleasmfs/ as oracleasmfs_t Resolves: rhbz#1331383- Label /etc/pki/pki-tomcat/ca/ as pki_tomcat_cert_t Resolves:rhbz#1366915 - Allow certmonger to manage all systemd unit files Resolves:rhbz#1366915 - Grant certmonger "chown" capability Resolves:rhbz#1366915 - Allow ipa_helper_t stream connect to dirsrv_t domain Resolves: rhbz#1368418 - Update oracleasm SELinux module Resolves: rhbz#1331383 - label /var/lib/kubelet as svirt_sandbox_file_t Resolves: rhbz#1369159 - Add few interfaces to cloudform.if file Resolves: rhbz#1367834 - Label /var/run/corosync-qnetd and /var/run/corosync-qdevice as cluster_var_run_t. Note: corosync policy is now par of rhcs module Resolves: rhbz#1347514 - Allow krb5kdc_t to read krb4kdc_conf_t dirs. Resolves: rhbz#1368492 - Update networkmanager_filetrans_named_content() interface to allow source domain to create also temad dir in /var/run. Resolves: rhbz#1365653 - Allow teamd running as NetworkManager_t to access netlink_generic_socket to allow multiple network interfaces to be teamed together. Resolves: rhbz#1365653 - Label /dev/oracleasmfs as oracleasmfs_t. Add few interfaces related to oracleasmfs_t type Resolves: rhbz#1331383 - A new version of cloud-init that supports the effort to provision RHEL Atomic on Microsoft Azure requires some a new rules that allows dhclient/dhclient hooks to call cloud-init. Resolves: rhbz#1367834 - Allow iptables to creating netlink generic sockets. Resolves: rhbz#1364359- Allow ipmievd domain to create lock files in /var/lock/subsys/ Resolves:rhbz#1349058 - Update policy for ipmievd daemon. Resolves:rhbz#1349058 - Dontaudit hyperkvp to getattr on non security files. Resolves: rhbz#1349356 - Label /run/corosync-qdevice and /run/corosync-qnetd as corosync_var_run_t Resolves: rhbz#1347514 - Fixed lsm SELinux module - Add sys_admin capability to sbd domain Resolves: rhbz#1322725 - Allow vdagent to comunnicate with systemd-logind via dbus Resolves: rhbz#1366731 - Allow lsmd_plugin_t domain to create fixed_disk device. Resolves: rhbz#1238066 - Allow opendnssec domain to create and manage own tmp dirs/files Resolves: rhbz#1366649 - Allow opendnssec domain to read system state Resolves: rhbz#1366649 - Update opendnssec_manage_config() interface to allow caller domain also manage opendnssec_conf_t dirs Resolves: rhbz#1366649 - Allow rasdaemon to mount/unmount tracefs filesystem. Resolves: rhbz#1364380 - Label /usr/libexec/iptables/iptables.init as iptables_exec_t Allow iptables creating lock file in /var/lock/subsys/ Resolves: rhbz#1367520 - Modify interface den_read_nvme() to allow also read nvme_device_t block files. Resolves: rhbz#1362564 - Label /var/run/storaged as lvm_var_run_t. Resolves: rhbz#1264390 - Allow unconfineduser to run ipa_helper_t. Resolves: rhbz#1361636- Dontaudit mock to write to generic certs. Resolves: rhbz#1271209 - Add labeling for corosync-qdevice and corosync-qnetd daemons, to run as cluster_t Resolves: rhbz#1347514 - Revert "Label corosync-qnetd and corosync-qdevice as corosync_t domain" - Allow modemmanager to write to systemd inhibit pipes Resolves: rhbz#1365214 - Label corosync-qnetd and corosync-qdevice as corosync_t domain Resolves: rhbz#1347514 - Allow ipa_helper to read network state Resolves: rhbz#1361636 - Label oddjob_reqiest as oddjob_exec_t Resolves: rhbz#1361636 - Add interface oddjob_run() Resolves: rhbz#1361636 - Allow modemmanager chat with systemd_logind via dbus Resolves: rhbz#1362273 - Allow NetworkManager chat with puppetagent via dbus Resolves: rhbz#1363989 - Allow NetworkManager chat with kdumpctl via dbus Resolves: rhbz#1363977 - Allow sbd send msgs to syslog Allow sbd create dgram sockets. Allow sbd to communicate with kernel via dgram socket Allow sbd r/w kernel sysctls. Resolves: rhbz#1322725 - Allow ipmievd_t domain to re-create ipmi devices Label /usr/libexec/openipmi-helper as ipmievd_exec_t Resolves: rhbz#1349058 - Allow rasdaemon to use tracefs filesystem. Resolves: rhbz#1364380 - Fix typo bug in dirsrv policy - Some logrotate scripts run su and then su runs unix_chkpwd. Allow logrotate_t domain to check passwd. Resolves: rhbz#1283134 - Add ipc_lock capability to sssd domain. Allow sssd connect to http_cache_t Resolves: rhbz#1362688 - Allow dirsrv to read dirsrv_share_t content Resolves: rhbz#1363662 - Allow virtlogd_t to append svirt_image_t files. Resolves: rhbz#1358140 - Allow hypervkvp domain to read hugetlbfs dir/files. Resolves: rhbz#1349356 - Allow mdadm daemon to read nvme_device_t blk files Resolves: rhbz#1362564 - Allow selinuxusers and unconfineduser to run oddjob_request Resolves: rhbz#1361636 - Allow sshd server to acces to Crypto Express 4 (CEX4) devices. Resolves: rhbz#1362539 - Fix labeling issue in init.fc file. Path /usr/lib/systemd/fedora-* changed to /usr/lib/systemd/rhel-*. Resolves: rhbz#1363769 - Fix typo in device interfaces Resolves: rhbz#1349058 - Add interfaces for managing ipmi devices Resolves: rhbz#1349058 - Add interfaces to allow mounting/umounting tracefs filesystem Resolves: rhbz#1364380 - Add interfaces to allow rw tracefs filesystem Resolves: rhbz#1364380 - Add interface dev_read_nvme() to allow reading Non-Volatile Memory Host Controller devices. Resolves: rhbz#1362564 - Label /sys/kernel/debug/tracing filesystem Resolves: rhbz#1364380 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857- Dontaudit mock_build_t can list all ptys. Resolves: rhbz#1271209 - Allow ftpd_t to mamange userhome data without any boolean. Resolves: rhbz#1097775 - Add logrotate permissions for creating netlink selinux sockets. Resolves: rhbz#1283134 - Allow lsmd_plugin_t to exec ldconfig. Resolves: rhbz#1238066 - Allow vnstatd domain to read /sys/class/net/ files Resolves: rhbz#1358243 - Remove duplicate allow rules in spamassassin SELinux module Resolves:rhbz#1358175 - Allow spamc_t and spamd_t domains create .spamassassin file in user homedirs Resolves:rhbz#1358175 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857 - Add new MLS attribute to allow relabeling objects higher than system low. This exception is needed for package managers when processing sensitive data. Resolves: rhbz#1330464 - Allow gnome-keyring also manage user_tmp_t sockets. Resolves: rhbz#1257057 - corecmd: Remove fcontext for /etc/sysconfig/libvirtd Resolves:rhbz#1351382- Allow ipa_dnskey domain to search cache dirs Resolves: rhbz#1350957- Allow ipa-dnskey read system state. Reasolves: rhbz#1350957 - Allow dogtag-ipa-ca-renew-agent-submit labeled as certmonger_t to create /var/log/ipa/renew.log file Resolves: rhbz#1350957- Allow firewalld to manage net_conf_t files. Resolves:rhbz#1304723 - Allow logrotate read logs inside containers. Resolves: rhbz#1303514 - Allow sssd to getattr on fs_t Resolves: rhbz#1356082 - Allow opendnssec domain to manage bind chace files Resolves: rhbz#1350957 - Fix typo in rhsmcertd policy module Resolves: rhbz#1329475 - Allow systemd to get status of systemd-logind daemon Resolves: rhbz#1356141 - Label more ndctl devices not just ndctl0 Resolves: rhbz#1355809- Allow rhsmcertd to copy certs into /etc/docker/cert.d - Add interface docker_rw_config() Resolves: rhbz#1344500 - Fix logrotate fc file to label also /var/lib/logrotate/ dir as logrotate_var_lib_t Resolves: rhbz#1355632 - Allow rhsmcertd to read network sysctls Resolves: rhbz#1329475 - Label /var/log/graphite-web dir as httpd_log_t Resolves: rhbz#1310898 - Allow mock to use generic ptys Resolves: rhbz#1271209 - Allow adcli running as sssd_t to write krb5.keytab file. Resolves: rhbz#1356082 - Allow openvswitch connect to openvswitch_port_t type. Resolves: rhbz#1335024 - Add SELinux policy for opendnssec service. Resolves: rhbz#1350957 - Create new SELinux type for /usr/libexec/ipa/ipa-dnskeysyncd Resolves: rhbz#1350957 - label /dev/ndctl0 device as nvram_device_t Resolves: rhbz#1355809- Allow lttng tools to block suspending Resolves: rhbz#1256374 - Allow creation of vpnaas in openstack Resolves: rhbz#1352710 - virt: add strict policy for virtlogd daemon Resolves:rhbz#1311606 - Update makefile to support snapperd_contexts file Resolves: rhbz#1352681- Allow udev to manage systemd-hwdb files - Add interface systemd_hwdb_manage_config() Resolves: rhbz#1350756 - Fix paths to infiniband devices. This allows use more then two infiniband interfaces. Resolves: rhbz#1210263- Allow virtual machines to rw infiniband devices. Resolves: rhbz#1210263 - Allow opensm daemon to rw infiniband_mgmt_device_t Resolves: rhbz#1210263 - Allow systemd_hwdb_t to relabel /etc/udev/hwdb.bin file. Resolves: rhbz#1350756 - Make label for new infiniband_mgmt deivices Resolves: rhbz#1210263- Fix typo in brltty SELinux module - Add new SELinux module sbd Resolves: rhbz#1322725 - Allow pcp dmcache metrics collection Resolves: rhbz#1309883 - Allow pkcs_slotd_t to create dir in /var/lock Add label pkcs_slotd_log_t Resolves: rhbz#1350782 - Allow openvpn to create sock files labeled as openvpn_var_run_t Resolves: rhbz#1328246 - Allow hypervkvp daemon to getattr on all filesystem types. Resolves: rhbz#1349356 - Allow firewalld to create net_conf_t files Resolves: rhbz#1304723 - Allow mock to use lvm Resolves: rhbz#1271209 - Allow keepalived to create netlink generic sockets. Resolves: rhbz#1349809 - Allow mirromanager creating log files in /tmp Resolves:rhbz#1328818 - Rename few modules to make it consistent with source files Resolves: rhbz#1351445 - Allow vmtools_t to transition to rpm_script domain Resolves: rhbz#1342119 - Allow nsd daemon to manage nsd_conf_t dirs and files Resolves: rhbz#1349791 - Allow cluster to create dirs in /var/run labeled as cluster_var_run_t Resolves: rhbz#1346900 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535 - Dontaudit su_role_template interface to getattr /proc/kcore Dontaudit su_role_template interface to getattr /dev/initctl Resolves: rhbz#1086240 - Add interface lvm_getattr_exec_files() Resolves: rhbz#1271209 - Fix typo Compliling vs. Compiling Resolves: rhbz#1351445- Allow krb5kdc_t to communicate with sssd Resolves: rhbz#1319933 - Allow prosody to bind on prosody ports Resolves: rhbz#1304664 - Add dac_override caps for fail2ban-client Resolves: rhbz#1316678 - dontaudit read access for svirt_t on the file /var/db/nscd/group Resolves: rhbz#1301637 - Allow inetd child process to communicate via dbus with systemd-logind Resolves: rhbz#1333726 - Add label for brltty log file Resolves: rhbz#1328818 - Allow dspam to read the passwd file Resolves: rhbz#1286020 - Allow snort_t to communicate with sssd Resolves: rhbz#1284908 - svirt_sandbox_domains need to be able to execmod for badly built libraries. Resolves: rhbz#1206339 - Add policy for lttng-tools package. Resolves: rhbz#1256374 - Make mirrormanager as application domain. Resolves: rhbz#1328234 - Add support for the default lttng-sessiond port - tcp/5345. This port is used by LTTng 2.x central tracing registry session daemon. - Add prosody ports Resolves: rhbz#1304664 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535- Label /var/lib/softhsm as named_cache_t. Allow named_t to manage named_cache_t dirs. Resolves:rhbz#1331315 - Label named-pkcs11 binary as named_exec_t. Resolves: rhbz#1331315 - Allow glusterd daemon to get systemd status Resolves: rhbz#1321785 - Allow logrotate dbus-chat with system_logind daemon Resolves: rhbz#1283134 - Allow pcp_pmlogger to read kernel network state Allow pcp_pmcd to read cron pid files Resolves: rhbz#1336211 - Add interface cron_read_pid_files() Resolves: rhbz#1336211 - Allow pcp_pmlogger to create unix dgram sockets Resolves: rhbz#1336211 - Add hwloc-dump-hwdata SELinux policy Resolves: rhbz#1344054 - Remove non-existing jabberd_spool_t() interface and add new jabbertd_var_spool_t. Resolves: rhbz#1121171 - Remove non-existing interface salk_resetd_systemctl() and replace it with sanlock_systemctl_sanlk_resetd() Resolves: rhbz#1259764 - Create label for openhpid log files. esolves: rhbz#1259764 - Label /var/lib/ganglia as httpd_var_lib_t Resolves: rhbz#1260536 - Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Include patch from distgit repo: policy-RHEL-7.1-flask.patch. Resolves: rhbz#1329560 - Update refpolicy to handle hwloc Resolves: rhbz#1344054 - Label /etc/dhcp/scripts dir as bin_t - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255- Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Allow mongod log to syslog. Resolves: rhbz#1306995 - Allow rhsmcertd connect to port tcp 9090 Resolves: rhbz#1337319 - Label for /bin/mail(x) was removed but /usr/bin/mail(x) not. This path is also needed to remove. Resolves: rhbz#1262483 Resolves: rhbz#1277506 - Label /usr/libexec/mimedefang-wrapper as spamd_exec_t. Resolves: rhbz#1301516 - Add new boolean spamd_update_can_network. Resolves: rhbz#1305469 - Allow rhsmcertd connect to tcp netport_port_t Resolves: rhbz#1329475 - Fix SELinux context for /usr/share/mirrormanager/server/mirrormanager to Label all binaries under dir as mirrormanager_exec_t. Resolves: rhbz#1328234 - Allow prosody to bind to fac_restore tcp port. Resolves: rhbz#1321787 - Allow ninfod to read raw packets Resolves: rhbz#1317964 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1260835 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1271159 - Allow tuned to use policykit. This change is required by cockpit. Resolves: rhbz#1346464 - Allow conman_t to read dir with conman_unconfined_script_t binary files. Resolves: rhbz#1297323 - Allow pegasus to read /proc/sysinfo. Resolves: rhbz#1265883 - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255 - Label tcp ports:16379, 26379 as redis_port_t Resolves: rhbz#1348471 - Allow systemd to relabel /var and /var/lib directories during boot. - Add files_relabel_var_dirs() and files_relabel_var_dirs() interfaces. - Add files_relabelto_var_lib_dirs() interface. - Label tcp port 2004 as mailbox_port_t. Resolves: rhbz#1332843 - Label tcp and udp port 5582 as fac_restore_port_t Resolves: rhbz#1321787 - Allow sysadm_t user to run postgresql-setup. Resolves: rhbz#1282543 - Allow sysadm_t user to dbus chat with oddjob_t. This allows confined admin run oddjob mkhomedirfor script. Resolves: rhbz#1297480 - Update netlink socket classes.- Allow conman to kill conman_unconfined_script. Resolves: rhbz#1297323 - Make conman_unconfined_script_t as init_system_domain. Resolves:rhbz#1297323 - Allow init dbus chat with apmd. Resolves:rhbz#995898 - Patch /var/lib/rpm is symlink to /usr/share/rpm on Atomic, due to this change we need to label also /usr/share/rpm as rpm_var_lib_t. Resolves: rhbz#1233252 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Add mediawiki rules to proper scope Resolves: rhbz#1301186 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Allow mysqld_safe to inherit rlimit information from mysqld Resolves: rhbz#1323673 - Allow collectd_t to stream connect to postgresql. Resolves: rhbz#1344056 - Allow mediawiki-script to read /etc/passwd file. Resolves: rhbz#1301186 - Add filetrans rule that NetworkManager_t can create net_conf_t files in /etc. Resolves: rhbz#1344505 - Add labels for mediawiki123 Resolves: rhbz#1293872 - Fix label for all fence_scsi_check scripts - Allow ip netns to mounton root fs and unmount proc_t fs. Resolves: rhbz#1343776 Resolves: rhbz#1286851 - Allow sysadm_t to run newaliases command. Resolves: rhbz#1344828 - Add interface sysnet_filetrans_named_net_conf() Resolves: rhbz#1344505- Fix several issues related to the SELinux Userspace changes- Allow glusterd domain read krb5_keytab_t files. Resolves: rhbz#1343929 - Fix typo in files_setattr_non_security_dirs. Resolves: rhbz#1115987- Allow tmpreaper_t to read/setattr all non_security_file_type dirs Resolves: rhbz#1115987 - Allow firewalld to create firewalld_var_run_t directory. Resolves: rhbz#1304723 - Add interface firewalld_read_pid_files() Resolves: rhbz#1304723 - Label /usr/libexec/rpm-ostreed as rpm_exec_t. Resolves: rhbz#1340542 - Allow sanlock service to read/write cephfs_t files. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - Add interface files_setattr_non_security_dirs() Resolves: rhbz#1115987 - Add support for onloadfs - Allow iptables to read firewalld pid files. Resolves: rhbz#1304723 - Add SELinux support for ceph filesystem. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) Resolves: rhbz#1236580- Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - New interfaces needed for systemd-machinectl Resolves: rhbz#1236580 - New interfaces needed by systemd-machine Resolves: rhbz#1236580 - Add interface allowing sending and receiving messages from virt over dbus. Resolves: rhbz#1236580 - Backport docker policy from Fedora. Related: #1303123 Resolves: #1341257 - Allow NetworkManager_t and policykit_t read access to systemd-machined pid files. Resolves: rhbz#1236580 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added interfaces needed by new docker policy. Related: rhbz#1303123 - Add support for systemd-machined daemon Resolves: rhbz#1236580 - Allow rpm-ostree domain transition to install_t domain from init_t. Resolves: rhbz#1340542- dnsmasq: allow NetworkManager to control dnsmasq via D-Bus Resolves: rhbz#1336722 - Directory Server (389-ds-base) has been updated to use systemd-ask-password. In order to function correctly we need the following added to dirsrv.te Resolves: rhbz#1333198 - sftpd_* booleans are functionless these days. Resolves: rhbz#1335656 - Label /var/log/ganesha.log as gluster_log_t Allow glusterd_t domain to create glusterd_log_t files. Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737 - Label /usr/libexec/storaged/storaged as lvm_exec_t to run storaged daemon in lvm_t SELinux domain. Resolves: rhbz#1264390 - Allow systemd_hostanmed_t to read /proc/sysinfo labeled as sysctl_t. Resolves: rhbz#1337061 - Revert "Allow all domains some process flags." Resolves: rhbz#1303644 - Revert "Remove setrlimit to all domains." Resolves: rhbz#1303644 - Label /usr/sbin/xrdp* files as bin_t Resolves: rhbz#1276777 - Add mls support for some db classes Resolves: rhbz#1303651 - Allow systemd_resolved_t to check if ipv6 is disabled. Resolves: rhbz#1236579 - Allow systemd_resolved to read systemd_networkd run files. Resolves: rhbz#1236579- Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737- Allow logwatch to domtrans to postqueue Resolves: rhbz#1331542 - Label /var/log/ganesha.log as gluster_log_t - Allow glusterd_t domain to create glusterd_log_t files. - Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow zabbix to connect to postgresql port Resolves: rhbz#1330479 - Add userdom_destroy_unpriv_user_shared_mem() interface. Related: rhbz#1306403 - systemd-logind remove all IPC objects owned by a user on a logout. This covers also SysV memory. This change allows to destroy unpriviledged user SysV shared memory segments. Resolves: rhbz#1306403- We need to restore contexts on /etc/passwd*,/etc/group*,/etc/*shadow* during install phase to get proper labeling for these files until selinux-policy pkgs are installed. Resolves: rhbz#1333952- Add interface glusterd_dontaudit_read_lib_dirs() Resolves: rhbz#1295680 - Dontaudit Occasionally observing AVC's while running geo-rep automation Resolves: rhbz#1295680 - Allow glusterd to manage socket files labeled as glusterd_brick_t. Resolves: rhbz#1331561 - Create new apache content template for files stored in user homedir. This change is needed to make working booleans: - httpd_enable_homedirs - httpd_read_user_content Resolves: rhbz#1246522 - Allow stunnel create log files. Resolves: rhbz#1296851 - Label tcp port 8181 as intermapper_port_t. Resolves: rhbz#1334783 - Label tcp/udp port 2024 as xinuexpansion4_port_t Resolves: rhbz#1334783 - Label tcp port 7002 as afs_pt_port_t Label tcp/udp port 2023 as xinuexpansion3_port_t Resolves: rhbz#1334783 - Dontaudit ldconfig read gluster lib files. Resolves: rhbz#1295680 - Add interface auth_use_nsswitch() to systemd_domain_template. Resolves: rhbz#1236579- Label /usr/bin/ganesha.nfsd as glusterd_exec_t to run ganesha as glusterd_t. Allow glusterd_t stream connect to rpbind_t. Allow cluster_t to create symlink /var/lib/nfs labeled as var_lib_nfs_t. Add interface rpc_filetrans_var_lib_nfs_content() Add new boolean: rpcd_use_fusefs to allow rpcd daemon use fusefs. Resolves: rhbz#1312809 Resolves: rhbz#1323947 - Allow dbus chat between httpd_t and oddjob_t. Resolves: rhbz#1324144 - Label /usr/libexec/ipa/oddjob/org.freeipa.server.conncheck as ipa_helper_exec_t. Resolves: rhbz#1324144 - Label /var/log/ipareplica-conncheck.log file as ipa_log_t Allow ipa_helper_t domain to manage logs labeledas ipa_log_t Allow ipa_helper_t to connect on http and kerberos_passwd ports. Resolves: rhbz#1324144 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow pcp_pmcd_t domain to manage docker lib files. This rule is needed to allow pcp to collect container information when SELinux is enabled. Resolves: rhbz#1309454- Allow runnig php7 in fpm mode. From selinux-policy side, we need to allow httpd to read/write hugetlbfs. Resolves: rhbz#1319442 - Allow openvswitch daemons to run under openvswitch Linux user instead of root. This change needs allow set capabilities: chwon, setgid, setuid, setpcap. Resolves: rhbz#1296640 - Remove ftpd_home_dir() boolean from distro policy. Reason is that we cannot make this working due to m4 macro language limits. Resolves: rhbz#1097775 - /bin/mailx is labeled sendmail_exec_t, and enters the sendmail_t domain on execution. If /usr/sbin/sendmail does not have its own domain to transition to, and is not one of several products whose behavior is allowed by the sendmail_t policy, execution will fail. In this case we need to label /bin/mailx as bin_t. Resolves: rhbz#1262483 - Allow nsd daemon to create log file in /var/log as nsd_log_t Resolves: rhbz#1293140 - Sanlock policy update. - New sub-domain for sanlk-reset daemon Resolves: rhbz#1212324 - Label all run tgtd files, not just socket files Resolves: rhbz#1280280 - Label all run tgtd files, not just socket files. Resolves: rhbz#1280280 - Allow prosody to stream connect to sasl. This will allow using cyrus authentication in prosody. Resolves: rhbz#1321049 - unbound wants to use ephemeral ports as a default configuration. Allow to use also udp sockets. Resolves: rhbz#1318224 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow targetd to read/write to /dev/mapper/control device. Resolves: rhbz#1063714 - Allow KDM to get status about power services. This change allow kdm to be able do shutdown. Resolves: rhbz#1316724 - Allow systemd-resolved daemon creating netlink_route sockets. Resolves:rhbz#1236579 - Allow systemd_resolved_t to read /etc/passwd file. Allow systemd_resolved_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used Resolves: rhbz#1065362 - Label /etc/selinux/(minimum|mls|targeted)/active/ as semanage_store_t Resolves: rhbz#1321943 - Label all nvidia binaries as xserver_exec_t Resolves: rhbz#1322283- Create new permissivedomains CIL module and make it active. Resolves: rhbz#1320451 - Add support for new mock location - /usr/libexec/mock/mock. Resolves: rhbz#1271209 - Allow bitlee to create bitlee_var_t dirs. Resolves: rhbz#1268651 - Allow CIM provider to read sssd public files. Resolves: rhbz#1263339 - Fix some broken interfaces in distro policy. Resolves: rhbz#1121171 - Allow power button to shutdown the laptop. Resolves: rhbz#995898 - Allow lsm plugins to create named fixed disks. Resolves: rhbz#1238066 - Add default labeling for /etc/Pegasus/cimserver_current.conf. It is a correct patch instead of the current /etc/Pegasus/pegasus_current.confResolves: rhbz#1278777 - Allow hyperv domains to rw hyperv devices. Resolves: rhbz#1309361 - Label /var/www/html(/.*)?/wp_backups(/.*)? as httpd_sys_rw_content_t.Resolves: rhbz#1246780 - Create conman_unconfined_script_t type for conman script stored in /use/share/conman/exec/ Resolves: rhbz#1297323 - Fix rule definitions for httpd_can_sendmail boolean. We need to distinguish between base and contrib. - Add support for /dev/mptctl device used to check RAID status. Resolves: rhbz#1258029 - Create hyperv* devices and create rw interfaces for this devices. Resolves: rhbz#1309361 - Add fixes for selinux userspace moving the policy store to /var/lib/selinux. - Remove optional else block for dhcp ping- Allow rsync_export_all_ro boolean to read also non_auth_dirs/files/symlinks. Resolves: rhbz#1263770 - Fix context of "/usr/share/nginx/html". Resolves: rhbz#1261857 - Allow pmdaapache labeled as pcp_pmcd_t access to port 80 for apache diagnostics Resolves: rhbz#1270344 - Allow pmlogger to create pmlogger.primary.socket link file. Resolves: rhbz#1270344 - Label nagios scripts as httpd_sys_script_exec_t. Resolves: rhbz#1260306 - Add dontaudit interface for kdumpctl_tmp_t Resolves: rhbz#1156442 - Allow mdadm read files in EFI partition. Resolves: rhbz#1291801 - Allow nsd_t to bind on nsf_control tcp port. Allow nsd_crond_t to read nsd pid. Resolves: rhbz#1293140 - Label some new nsd binaries as nsd_exec_t Allow nsd domain net_admin cap. Create label nsd_tmp_t for nsd tmp files/dirs Resolves: rhbz#1293140 - Add filename transition that /etc/princap will be created with cupsd_rw_etc_t label in cups_filetrans_named_content() interface. Resolves: rhbz#1265102 - Add missing labeling for /usr/libexec/abrt-hook-ccpp. Resolves: rhbz#1213409 - Allow pcp_pmie and pcp_pmlogger to read all domains state. Resolves: rhbz#1206525 - Label /etc/redis-sentinel.conf as redis_conf_t. Allow redis_t write to redis_conf_t. Allow redis_t to connect on redis tcp port. Resolves: rhbz#1275246 - cockpit has grown content in /var/run directory Resolves: rhbz#1279429 - Allow collectd setgid capability Resolves:#1310898 - Remove declaration of empty booleans in virt policy. Resolves: rhbz#1103153 - Fix typo in drbd policy - Add new drbd file type: drbd_var_run_t. Allow drbd_t to manage drbd_var_run_t files/dirs. Allow drbd_t create drbd_tmp_t files in /tmp. Resolves: rhbz#1134883 - Label /etc/ctdb/events.d/* as ctdb_exec_t. Allow ctdbd_t to setattr on ctdbd_exec_t files. Resolves: rhbz#1293788 - Allow abrt-hook-ccpp to get attributes of all processes because of core_pattern. Resolves: rhbz#1254188 - Allow abrt_t to read sysctl_net_t files. Resolves: rhbz#1254188 - The ABRT coredump handler has code to emulate default core file creation The handler runs in a separate process with abrt_dump_oops_t SELinux process type. abrt-hook-ccpp also saves the core dump file in the very same way as kernel does and a user can specify CWD location for a coredump. abrt-hook-ccpp has been made as a SELinux aware apps to create this coredumps with correct labeling and with this commit the policy rules have been updated to allow access all non security files on a system. - Allow abrt-hook-ccpp to getattr on all executables. - Allow setuid/setgid capabilities for abrt-hook-ccpp. Resolves: rhbz#1254188 - abrt-hook-ccpp needs to have setfscreate access because it is SELinux aware and compute a target labeling. Resolves: rhbz#1254188 - Allow abrt-hook-ccpp to change SELinux user identity for created objects. Resolves: rhbz#1254188 - Dontaudit write access to inherited kdumpctl tmp files. Resolves: rbhz#1156442 - Add interface to allow reading files in efivarfs - contains Linux Kernel configuration options for UEFI systems (UEFI Runtime Variables) Resolves: rhbz#1291801 - Label 8952 tcp port as nsd_control. Resolves: rhbz#1293140 - Allow ipsec to use pam. Resolves: rhbz#1315700 - Allow to log out to gdm after screen was resized in session via vdagent. Resolves: rhbz#1249020 - Allow setrans daemon to read /proc/meminfo. Resolves: rhbz#1316804 - Allow systemd_networkd_t to write kmsg, when kernel was started with following params: systemd.debug systemd.log_level=debug systemd.log_target=kmsg Resolves: rhbz#1298151 - Label tcp port 5355 as llmnr-> Link-Local Multicast Name Resolution Resolves: rhbz#1236579 - Add new selinux policy for systemd-resolved dawmon. Resolves: rhbz#1236579 - Add interface ssh_getattr_server_keys() interface. Resolves: rhbz#1306197 - Allow run sshd-keygen on second boot if first boot fails after some reason and content is not syncedon the disk. These changes are reflecting this commit in sshd. http://pkgs.fedoraproject.org/cgit/rpms/openssh.git/commit/?id=af94f46861844cbd6ba4162115039bebcc8f78ba rhbz#1299106 Resolves: rhbz#1306197 - Allow systemd_notify_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used. Resolves: rhbz#1309417 - Remove bin_t label for /etc/ctdb/events.d/. We need to label this scripts as ctdb_exec_t. Resolves: rhbz#1293788- Prepare selinux-policy package for userspace release 2016-02-23. Resolves: rhbz#1305982- Allow sending dbus msgs between firewalld and system_cronjob domains. Resolves: rhbz#1284902 - Allow zabbix-agentd to connect to following tcp sockets. One of zabbix-agentd functions is get service status of ftp,http,innd,pop,smtp protocols. Resolves: rhbz#1242506 - Add new boolean tmpreaper_use_cifs() to allow tmpreaper to run on local directories being shared with Samba. Resolves: rhbz#1284972 - Add support for systemd-hwdb daemon. Resolves: rhbz#1257940 - Add interface fs_setattr_cifs_dirs(). Resolves: rhbz#1284972- Add new SELinux policy fo targetd daemon. Resolves: rhbz#1063714 - Add new SELinux policy fo ipmievd daemon. Resolves: rhbz#1083031 - Add new SELinux policy fo hsqldb daemon. Resolves: rhbz#1083171 - Add new SELinux policy for blkmapd daemon. Resolves: rhbz#1072997 - Allow p11-child to connect to apache ports. - Label /usr/sbin/lvmlockd binary file as lvm_exec_t. Resolves: rhbz#1278028 - Add interface "lvm_manage_lock" to lvm policy. Resolves: rhbz#1063714- Allow openvswitch domain capability sys_rawio. Resolves: rhbz#1278495- Allow openvswitch to manage hugetlfs files and dirs. Resolves: rhbz#1278495 - Add fs_manage_hugetlbfs_files() interface. Resolves: rhbz#1278495- Allow smbcontrol domain to send sigchld to ctdbd domain. Resolves: #1293784 - Allow openvswitch read/write hugetlb filesystem. Resolves: #1278495Allow hypervvssd to list all mountpoints to have VSS live backup working correctly. Resolves:#1247880- Revert Add missing labeling for /usr/libexec/abrt-hook-ccpp patch Resolves: #1254188- Allow search dirs in sysfs types in kernel_read_security_state. Resolves: #1254188 - Fix kernel_read_security_state interface that source domain of this interface can search sysctl_fs_t dirs. Resolves: #1254188- Add missing labeling for /usr/libexec/abrt-hook-ccpp as a part of #1245477 and #1242467 bugs Resolves: #1254188 - We need allow connect to xserver for all sandbox_x domain because we have one type for all sandbox processes. Resolves:#1261938- Remove labeling for modules_dep_t file contexts to have labeled them as modules_object_t. - Update files_read_kernel_modules() to contain modutils_read_module_deps_files() calling because module deps labeling could remain and it allows to avoid regressions. Resolves:#1266928- We need to require sandbox_web_type attribute in sandbox_x_domain_template(). Resolves: #1261938 - ipsec: The NM helper needs to read the SAs Resolves: #1259786 - ipsec: Allow ipsec management to create ptys Resolves: #1259786- Add temporary fixes for sandbox related to #1103622. It allows to run everything under one sandbox type. Resolves:#1261938 - Allow abrt_t domain to write to kernel msg device. Resolves: #1257828 - Allow rpcbind_t domain to change file owner and group Resolves: #1265266- Allow smbcontrol to create a socket in /var/samba which uses for a communication with smbd, nmbd and winbind. Resolves: #1256459- Allow dirsrv-admin script to read passwd file. Allow dirsrv-admin script to read httpd pid files. Label dirsrv-admin unit file and allow dirsrv-admin domains to use it. Resolves: #1230300 - Allow qpid daemon to connect on amqp tcp port. Resolves: #1261805- Label /etc/ipa/nssdb dir as cert_t Resolves:#1262718 - Do not provide docker policy files which is shipped by docker-selinux.rpm Resolves:#1262812- Add labels for afs binaries: dafileserver, davolserver, salvageserver, dasalvager Resolves: #1192338 - Add lsmd_plugin_t sys_admin capability, Allow lsmd_plugin_t getattr from sysfs filesystem. Resolves: #1238079 - Allow rhsmcertd_t send signull to unconfined_service_t domains. Resolves: #1176078 - Remove file transition from snmp_manage_var_lib_dirs() interface which created snmp_var_lib_t dirs in var_lib_t. - Allow openhpid_t daemon to manage snmp files and dirs. Resolves: #1243902 - Allow mdadm_t domain read/write to general ptys and unallocated ttys. Resolves: #1073314 - Add interface unconfined_server_signull() to allow domains send signull to unconfined_service_t Resolves: #1176078- Allow systemd-udevd to access netlink_route_socket to change names for network interfaces without unconfined.pp module. It affects also MLS. Resolves:#1250456- Fix labeling for fence_scsi_check script Resolves: #1255020 - Allow openhpid to read system state Allow openhpid to connect to tcp http port. Resolves: #1244248 - Allow openhpid to read snmp var lib files. Resolves: #1243902 - Allow openvswitch_t domains read kernel dependencies due to openvswitch run modprobe - Allow unconfined_t domains to create /var/run/xtables.lock with iptables_var_run_t Resolves: #1243403 - Remove bin_t label for /usr/share/cluster/fence_scsi_check\.pl Resolves: #1255020- Fix regexp in chronyd.fc file Resolves: #1243764 - Allow passenger to getattr filesystem xattr Resolves: #1196555 - Label mdadm.conf.anackbak as mdadm_conf_t file. Resolves: #1088904 - Revert "Allow pegasus_openlmi_storage_t create mdadm.conf.anacbak file in /etc." - Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Remove labeling for /var/db/.*\.db as etc_t to label db files as system_db_t. Resolves: #1230877- Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Label /var/run/chrony-helper dir as chronyd_var_run_t. Resolves: #1243764 - Allow dhcpc_t domain transition to chronyd_t Resolves: #1243764- Fix postfix_spool_maildrop_t,postfix_spool_flush_t contexts in postfix.fc file. Resolves: #1252442- Allow exec pidof under hypervkvp domain. Resolves: #1254870 - Allow hypervkvp daemon create connection to the system DBUS Resolves: #1254870- Allow openhpid_t to read system state. Resolves: #1244248 - Added labels for files provided by rh-nginx18 collection Resolves: #1249945 - Dontaudit block_suspend capability for ipa_helper_t, this is kernel bug. Allow ipa_helper_t capability net_admin. Allow ipa_helper_t to list /tmp. Allow ipa_helper_t to read rpm db. Resolves: #1252968 - Allow rhsmcertd exec rhsmcertd_var_run_t files and rhsmcerd_tmp_t files. This rules are in hide_broken_sympthons until we find better solution. Resolves: #1243431 - Allow abrt_dump_oops_t to read proc_security_t files. - Allow abrt_dump_oops to signull all domains Allow abrt_dump_oops to read all domains state Allow abrt_dump_oops to ptrace all domains - Add interface abrt_dump_oops_domtrans() - Add mountpoint dontaudit access check in rhsmcertd policy. Resolves: #1243431 - Allow samba_net_t to manage samba_var_t sock files. Resolves: #1252937 - Allow chrome setcap to itself. Resolves: #1251996 - Allow httpd daemon to manage httpd_var_lib_t lnk_files. Resolves: #1253706 - Allow chronyd exec systemctl Resolves: #1243764 - Add inteface chronyd_signal Allow timemaster_t send generic signals to chronyd_t. Resolves: #1243764 - Added interface fs_dontaudit_write_configfs_dirs - Add label for kernel module dep files in /usr/lib/modules Resolves:#916635 - Allow kernel_t domtrans to abrt_dump_oops_t - Added to files_dontaudit_write_all_mountpoints intefface new dontaudit rule, that domain included this interface dontaudit capability dac_override. - Allow systemd-networkd to send logs to systemd-journald. Resolves: #1236616- Fix label on /var/tmp/kiprop_0 Resolves:#1220763 - Allow lldpad_t to getattr tmpfs_t. Resolves: #1246220 - Label /dev/shm/lldpad.* as lldapd_tmpfs_t Resolves: #1246220 - Allow audisp client to read system state.- Allow pcp_domain to manage pcp_var_lib_t lnk_files. Resolves: #1252341 - Label /var/run/xtables.* as iptables_var_run_t Resolves: #1243403- Add interface to read/write watchdog device - Add labels for /dev/memory_bandwith and /dev/vhci. Thanks ssekidde Resolves:#1210237 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow logrotate to reload services. Resolves: #1242453 - Allow openhpid use libwatchdog plugin. (Allow openhpid_t rw watchdog device) Resolves: #1244260 - Allow openhpid liboa_soap plugin to read generic certs. Resolves: #1244248 - Allow openhpid liboa_soap plugin to read resolv.conf file. Resolves: #1244248 - Label /usr/libexec/chrony-helper as chronyd_exec_t - Allow chronyd_t to read dhcpc state. - Allow chronyd to execute mkdir command.- Allow mdadm to access /dev/random and add support to create own files/dirs as mdadm_tmpfs_t. Resolves:#1073314 - Allow udev, lvm and fsadm to access systemd-cat in /var/tmp/dracut if 'dracut -fv' is executed in MLS. - Allow admin SELinu users to communicate with kernel_t. It is needed to access /run/systemd/journal/stdout if 'dracut -vf' is executed. We allow it for other SELinux users. - Allow sysadm to execute systemd-sysctl in the sysadm_t domain. It is needed for ifup command in MLS mode. - Add fstools_filetrans_named_content_fsadm() and call it for named_filetrans_domain domains. We need to be sure that /run/blkid is created with correct labeling. Resolves:#1183503 - Add support for /etc/sanlock which is writable by sanlock daemon. Resolves:#1231377 - Allow useradd add homedir located in /var/lib/kdcproxy in ipa-server RPM scriplet. Resolves:#1243775 - Allow snapperd to pass data (one way only) via pipe negotiated over dbus Resolves:#1250550 - Allow lsmd also setuid capability. Some commands need to executed under root privs. Other commands are executed under unprivileged user.- Allow openhpid to use libsnmp_bc plugin (allow read snmp lib files). Resolves: #1243902 - Allow lsm_plugin_t to read sysfs, read hwdata, rw to scsi_generic_device Resolves: #1238079 - Allow lsm_plugin_t to rw raw_fixed_disk. Resolves:#1238079 - Allow rhsmcertd to send signull to unconfined_service.- Allow httpd_suexec_t to read and write Apache stream sockets Resolves: #1243569 - Allow qpid to create lnk_files in qpid_var_lib_t Resolves: #1247279- Allow drbd to get attributes from filesystems. - Allow redis to read kernel parameters. Resolves: #1209518 - Allow virt_qemu_ga_t domtrans to passwd_t - Allow audisp_remote_t to start power unit files domain to allow halt system. Resolves: #1186780 - Allow audisp_remote_t to read/write user domain pty. Resolves: #1186780 - Label /usr/sbin/chpasswd as passwd_exec_t. - Allow sysadm to administrate ldap environment and allow to bind ldap port to allow to setup an LDAP server (389ds). Resolves:#1221121- gnome_dontaudit_search_config() needs to be a part of optinal_policy in pegasus.te - Allow pcp_pmcd daemon to read postfix config files. - Allow pcp_pmcd daemon to search postfix spool dirs. Resolves: #1213740 - Added Booleans: pcp_read_generic_logs. Resolves: #1213740 - Allow drbd to read configuration options used when loading modules. Resolves: #1134883 - Allow glusterd to manage nfsd and rpcd services. - Allow glusterd to communicate with cluster domains over stream socket. - glusterd call pcs utility which calls find for cib.* files and runs pstree under glusterd. Dontaudit access to security files and update gluster boolean to reflect these changes.- Allow glusterd to manage nfsd and rpcd services. - Allow networkmanager to communicate via dbus with systemd_hostanmed. Resolves: #1234954 - Allow stream connect logrotate to prosody. - Add prosody_stream_connect() interface. - httpd should be able to send signal/signull to httpd_suexec_t, instead of httpd_suexec_exec_t. - Allow prosody to create own tmp files/dirs. Resolves:#1212498- Allow networkmanager read rfcomm port. Resolves:#1212498 - Remove non exists label. - Fix *_admin intefaces where body is not consistent with header. - Label /usr/afs/ as afs_files_t, Allow afs_bosserver_t create afs_config_t and afs_dbdir_t dirs under afs_files_t, Allow afs_bosserver_t read kerberos config - Remove non exits nfsd_ro_t label. - Make all interfaces related to openshift_cache_t as deprecated. - Add rpm_var_run_t label to rpm_admin header - Add jabberd_lock_t label to jabberd_admin header. - Add samba_unconfined_script_exec_t to samba_admin header. - inn daemon should create innd_log_t objects in var_log_t instead of innd_var_run_t - Fix ctdb policy - Add samba_signull_winbind() - Add samba_signull_unconfined_net() - Allow ctdbd_t send signull to samba_unconfined_net_t. - Allow openshift_initrc_t to communicate with firewalld over dbus Resolves:#1221326- Allow gluster to connect to all ports. It is required by random services executed by gluster. - Add interfaces winbind_signull(), samba_unconfined_net_signull(). - Dontaudit smbd_t block_suspend capability. This is kernel bug. - Allow ctdbd sending signull to process winbind, samba_unconfined_net, to checking if processes exists. - Add tmpreaper booleans to use nfs_t and samba_share_t. - Fix path from /usr/sbin/redis-server to /usr/bin/redis-server - Allow connect ypserv to portmap_port_t - Fix paths in inn policy, Allow innd read innd_log_t dirs, Allow innd execute innd_etc_t files - Add support for openstack-nova-* packages - Allow NetworkManager_t send signull to dnssec_trigger_t. - Allow glusterd to execute showmount in the showmount domain. - Label swift-container-reconciler binary as swift_t. - Allow dnssec_trigger_t relabelfrom dnssec_trigger_var_run_t files. - Add cobbler_var_lib_t to "/var/lib/tftpboot/boot(/.*)?" Resolves:#1213540 - Merge all nova_* labels under one nova_t.- Add logging_syslogd_run_nagios_plugins boolean for rsyslog to allow transition to nagios unconfined plugins Resolves:#1233550 - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/ - Add support for oddjob based helper in FreeIPA. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add nagios_domtrans_unconfined_plugins() interface. - Update mta_filetrans_named_content() interface to cover more db files. Resolves:#1167468 - Add back ftpd_use_passive_mode boolean with fixed description. - Allow pmcd daemon stream connect to mysqld. - Allow pcp domains to connect to own process using unix_stream_socket. Resolves:#1213709 - Allow abrt-upload-watch service to dbus chat with ABRT daemon and fsetid capability to allow run reporter-upload correctly. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add support for oddjob based helper in FreeIPA. - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/- Allow iptables to read ctdbd lib files. Resolves:#1224879 - Add systemd_networkd_t to nsswitch domains. - Allow drbd_t write to fixed_disk_device. Reason: drbdmeta needs write to fixed_disk_device during initialization. Resolves:#1130675 - Allow NetworkManager write to sysfs. - Fix cron_system_cronjob_use_shares boolean to call fs interfaces which contain only entrypoint permission. - Add cron_system_cronjob_use_shares boolean to allow system cronjob to be executed from shares - NFS, CIFS, FUSE. It requires "entrypoint" permissios on nfs_t, cifs_t and fusefs_t SELinux types. - Allow NetworkManager write to sysfs. - Allow ctdb_t sending signull to smbd_t, for checking if smbd process exists. - Dontaudit apache to manage snmpd_var_lib_t files/dirs. - Add interface snmp_dontaudit_manage_snmp_var_lib_files(). - Dontaudit mozilla_plugin_t cap. sys_ptrace. - Rename xodbc-connect port to xodbc_connect - Allow ovsdb-server to connect on xodbc-connect and ovsdb tcp ports. - Allow iscsid write to fifo file kdumpctl_tmp_t. Appears when kdump generates the initramfs during the kernel boot. - Dontaudit chrome to read passwd file. - nrpe needs kill capability to make gluster moniterd nodes working. Resolves:#1235587- We allow can_exec() on ssh_keygen on gluster. But there is a transition defined by init_initrc_domain() because we need to allow execute unconfined services by glusterd. So ssh-keygen ends up with ssh_keygen_t and we need to allow to manage /var/lib/glusterd/geo-replication/secret.pem. - Allow sshd to execute gnome-keyring if there is configured pam_gnome_keyring.so. - Allow gnome-keyring executed by passwd to access /run/user/UID/keyring to change a password. - Label gluster python hooks also as bin_t. - Allow glusterd to interact with gluster tools running in a user domain - Add glusterd_manage_lib_files() interface. - ntop reads /var/lib/ntop/macPrefix.db and it needs dac_override. It has setuid/setgid. - Allow samba_t net_admin capability to make CIFS mount working. - S30samba-start gluster hooks wants to search audit logs. Dontaudit it. Resolves:#1224879- Allow glusterd to send generic signals to systemd_passwd_agent processes. - Allow glusterd to access init scripts/units without defined policy - Allow glusterd to run init scripts. - Allow glusterd to execute /usr/sbin/xfs_dbin glusterd_t domain. Resolves:#1224879- Calling cron_system_entry() in pcp_domain_template needs to be a part of optional_policy block. - Allow samba-net to access /var/lib/ctdbd dirs/files. - Allow glusterd to send a signal to smbd. - Make ctdbd as home manager to access also FUSE. - Allow glusterd to use geo-replication gluster tool. - Allow glusterd to execute ssh-keygen. - Allow glusterd to interact with cluster services. - Allow glusterd to connect to the system DBUS for service (acquire_svc). - Label /dev/log correctly. Resolves:#1230932- Back port the latest F22 changes to RHEL7. It should fix most of RHEL7.2 bugs - Add cgdcbxd policy Resolves:#1072493 - Fix ftp_homedir boolean Resolve:#1097775 - Dontaudit ifconfig writing inhertited /var/log/pluto.log. - Allow cluster domain to dbus chat with systemd-logind. Resolves:#1145215 - Dontaudit write access to inherited kdumpctl tmp files Resolves:#1156442 - Allow isnsd_t to communicate with sssd Resolves:#1167702 - Allow rwho_t to communicate with sssd Resolves:#1167718 - Allow sblim_gatherd_t to communicate with sssd Resolves:#1167732 - Allow pkcs_slotd_t to communicate with sssd Resolves:#1167737 - Allow openvswitch_t to communicate with sssd Resolves:#1167816 - Allow mysqld_safe_t to communicate with sssd Resolves:#1167832 - Allow sshd_keygen_t to communicate with sssd Resolves:#1167840 - Add support for iprdbg logging files in /var/log. Resolves:#1174363 - Allow tmpreaper_t to manage ntp log content Resolves:#1176965 - Allow gssd_t to manage ssh keyring Resolves:#1184791 - Allow httpd_sys_script_t to send system log messages Resolves:#1185231 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow dovecot_t sys_resource capability Resolves:#1191143 - Add support for mongod/mongos systemd unit files. Resolves:#1197038 - Add bacula fixes - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. Resolves:#1203991- Label /usr/libexec/postgresql-ctl as postgresql_exec_t. - Add more restriction on entrypoint for unconfined domains. - Only allow semanage_t to be able to setenforce 0, no all domains that use selinux_semanage interface - Allow all domains to read /dev/urandom. It is needed by all apps/services linked to libgcrypt. There is no harm to allow it by default. - Update policy/mls for sockets related to access perm. Rules were contradictory. - Add nagios_run_pnp4nagios and nagios_run_sudo booleans to allow r un sudo from NRPE utils scripts and allow run nagios in conjunction w ith PNP4Nagios. Resolves:#1201054 - Don't use deprecated userdom_manage_tmpfs_role() interface calliing and use userdom_manage_tmp_role() instead. - Update virt_read_pid_files() interface to allow read also symlinks with virt_var_run_t type - Label /var/lib/tftpboot/aarch64(/.*)? and /var/lib/tftpboot/images2(/.*)? - Add support for iprdbg logging files in /var/log. - Add fixes to rhsmcertd_t - Allow puppetagent_t to transfer firewalld messages over dbus - Add support for /usr/libexec/mongodb-scl-helper RHSCL helper script. - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. - Add support for mongod/mongos systemd unit files. - cloudinit and rhsmcertd need to communicate with dbus - Allow dovecot_t sys_resource capability- ALlow mongod execmem by default. - Update policy/mls for sockets. Rules were contradictory. Resolves:#1207133 - Allow a user to login with different security level via ssh.- Update seutil_manage_config() interface. Resolves:#1185962 - Allow pki-tomcat relabel pki_tomcat_etc_rw_t. - Turn on docker_transition_unconfined by default- Allow virtd to list all mountpoints. Resolves:#1180713- pkcsslotd_lock_t should be an alias for pkcs_slotd_lock_t. - Allow fowner capability for sssd because of selinux_child handling. - ALlow bind to read/write inherited ipsec pipes - Allow hypervkvp to read /dev/urandom and read addition states/config files. - Allow gluster rpm scripletto create glusterd socket with correct labeling. This is a workaround until we get fix in glusterd. - Add glusterd_filetrans_named_pid() interface - Allow radiusd to connect to radsec ports. - Allow setuid/setgid for selinux_child - Allow lsmd plugin to connect to tcp/5988 by default. - Allow lsmd plugin to connect to tcp/5989 by default. - Update ipsec_manage_pid() interface. Resolves:#1184978- Update ipsec_manage_pid() interface. Resolves:#1184978- Allow ntlm_auth running in winbind_helper_t to access /dev/urandom.- Add auditing support for ipsec. Resolves:#1182524 - Label /ostree/deploy/rhel-atomic-host/deploy directory as system_conf_t - Allow netutils chown capability to make tcpdump working with -w- Allow ipsec to execute _updown.netkey script to run unbound-control. - Allow neutron to read rpm DB. - Add additional fixes for hyperkvp * creates new ifcfg-{name} file * Runs hv_set_ifconfig.sh, which does the following * Copies ifcfg-{name} to /etc/sysconfig/network-scripts - Allow svirt to read symbolic links in /sys/fs/cgroups labeled as tmpfs_t - Add labeling for pacemaker.log. - Allow radius to connect/bind radsec ports. - Allow pm-suspend running as virt_qemu_ga to read /var/log/pm-suspend.log - Allow virt_qemu_ga to dbus chat with rpm. - Update virt_read_content() interface to allow read also char devices. - Allow glance-registry to connect to keystone port. Resolves:#1181818- Allow sssd to send dbus all user domains. Resolves:#1172291 - Allow lsm plugin to read certificates. - Fix labeling for keystone CGI scripts. - Make snapperd back as unconfined domain.- Fix bugs in interfaces discovered by sepolicy. - Allow slapd to read /usr/share/cracklib/pw_dict.hwm. - Allow lsm plugins to connect to tcp/18700 by default. - Allow brltty mknod capability to allow create /var/run/brltty/vcsa. - Fix pcp_domain_template() interface. - Fix conman.te. - Allow mon_fsstatd to read /proc/sys/fs/binfmt_misc - Allow glance-scrubber to connect tcp/9191. - Add missing setuid capability for sblim-sfcbd. - Allow pegasus ioctl() on providers. - Add conman_can_network. - Allow chronyd to read chrony conf files located in /run/timemaster/. - Allow radius to bind on tcp/1813 port. - dontaudit block suspend access for openvpn_t - Allow conman to create files/dirs in /tmp. - Update xserver_rw_xdm_keys() interface to have 'setattr'. Resolves:#1172291 - Allow sulogin to read /dev/urandom and /dev/random. - Update radius port definition to have also tcp/18121 - Label prandom as random_device_t. - Allow charon to manage files in /etc/strongimcv labeled as ipsec_conf_t.- Allow virt_qemu_ga_t to execute kmod. - Add missing files_dontaudit_list_security_dirs() for smbd_t in samba_export_all_ro boolean. - Add additionnal MLS attribute for oddjob_mkhomedir to create homedirs. Resolves:#1113725 - Enable OpenStack cinder policy - Add support for /usr/share/vdsm/daemonAdapter - Add support for /var/run/gluster- Remove old pkcsslotd.pp from minimum package - Allow rlogind to use also rlogin ports. - Add support for /usr/libexec/ntpdate-wrapper. Label it as ntpdate_exec_t. - Allow bacula to connect also to postgresql. - Label /usr/libexec/tomcat/server as tomcat_exec_t - Add support for /usr/sbin/ctdbd_wrapper - Add support for /usr/libexec/ppc64-diag/rtas_errd - Allow rpm_script_roles to access system_mail_t - Allow brltty to create /var/run/brltty - Allow lsmd plugin to access netlink_route_socket - Allow smbcontrol to read passwd - Add support for /usr/libexec/sssd/selinux_child and create sssd_selinux_manager_t domain for it Resolves:#1140106 - Allow osad to execute rhn_check - Allow load_policy to rw inherited sssd pipes because of selinux_child - Allow admin SELinux users mounting / as private within a new mount namespace as root in MLS - Add additional fixes for su_restricted_domain_template to make moving to sysadm_r and trying to su working correctly - Add additional booleans substitions- Add seutil_dontaudit_access_check_semanage_module_store() interface Resolves:#1140106 - Update to have all _systemctl() interface also init_reload_services(). - Dontaudit access check on SELinux module store for sssd. - Add labeling for /sbin/iw. - Allow named_filetrans_domain to create ibus directory with correct labeling.- Allow radius to bind tcp/1812 radius port. - Dontaudit list user_tmp files for system_mail_t. - Label virt-who as virtd_exec_t. - Allow rhsmcertd to send a null signal to virt-who running as virtd_t. - Add missing alias for _content_rw_t. Resolves:#1089177 - Allow spamd to access razor-agent.log. - Add fixes for sfcb from libvirt-cim TestOnly bug. - Allow NetworkManager stream connect on openvpn. - Make /usr/bin/vncserver running as unconfined_service_t. - getty_t should be ranged in MLS. Then also local_login_t runs as ranged domain. - Label /etc/docker/certs.d as cert_t.- Label /etc/strongimcv as ipsec_conf_file_t. - Add support for /usr/bin/start-puppet-ca helper script Resolves:#1160727 - Allow rpm scripts to enable/disable transient systemd units. Resolves:#1154613 - Make kpropdas nsswitch domain Resolves:#1153561 - Make all glance domain as nsswitch domains Resolves:#1113281 - Allow selinux_child running as sssd access check on /etc/selinux/targeted/modules/active - Allow access checks on setfiles/load_policy/semanage_lock for selinux_child running as sssd_t Resolves:#1140106- Dontaudit access check on setfiles/load_policy for sssd_t. Resolves:#1140106 - Add kdump_rw_inherited_kdumpctl_tmp_pipes() Resolves:#1156442 - Make linuxptp services as unconfined. - Added new policy linuxptp. Resolves:#1149693 - Label keystone cgi files as keystone_cgi_script_exec_t. Resolves:#1138424 - Make tuned as unconfined domain- Allow guest to connect to libvirt using unix_stream_socket. - Allow all bus client domains to dbus chat with unconfined_service_t. - Allow inetd service without own policy to run in inetd_child_t which is unconfined domain. - Make opensm as nsswitch domain to make it working with sssd. - Allow brctl to read meminfo. - Allow winbind-helper to execute ntlm_auth in the caller domain. Resolves:#1160339 - Make plymouthd as nsswitch domain to make it working with sssd. Resolves:#1160196 - Make drbd as nsswitch domain to make it working with sssd. - Make conman as nsswitch domain to make ipmitool.exp runing as conman_t working. - Add support for /var/lib/sntp directory. - Add fixes to allow docker to create more content in tmpfs ,and donaudit reading /proc - Allow winbind to read usermodehelper - Allow telepathy domains to execute shells and bin_t - Allow gpgdomains to create netlink_kobject_uevent_sockets - Allow mongodb to bind to the mongo port and mongos to run as mongod_t - Allow abrt to read software raid state. - Allow nslcd to execute netstat. - Allow dovecot to create user's home directory when they log into IMAP. - Allow login domains to create kernel keyring with different level.- Allow modemmanger to connectto itself Resolves:#1120152 - Allow pki_tomcat to create link files in /var/lib/pki-ca. Resolves:#1121744 - varnishd needs to have fsetid capability Resolves:#1125165 - Allow snapperd to dbus chat with system cron jobs. Resolves:#1152447 - Allow dovecot to create user's home directory when they log into IMAP Resolves:#1152773 - Add labeling for /usr/sbin/haproxy-systemd-wrapper wrapper to make haproxy running haproxy_t. - ALlow listen and accept on tcp socket for init_t in MLS. Previously it was for xinetd_t. - Allow nslcd to execute netstat. - Add suppor for keepalived unconfined scripts and allow keepalived to read all domain state and kill capability. - Allow nslcd to read /dev/urandom.- Add back kill permisiion for system class Resolves:#1150011- Add back kill permisiion for service class Resolves:#1150011 - Make rhsmcertd_t also as dbus domain. - Allow named to create DNS_25 with correct labeling. - Add cloudform_dontaudit_write_cloud_log() - Call auth_use_nsswitch to apache to read/write cloud-init keys. - Allow cloud-init to dbus chat with certmonger. - Fix path to mon_statd_initrc_t script. - Allow all RHCS services to read system state. - Allow dnssec_trigger_t to execute unbound-control in own domain. - kernel_read_system_state needs to be called with type. Moved it to antivirus.if. - Added policy for mon_statd and mon_procd services. BZ (1077821) - Allow opensm_t to read/write /dev/infiniband/umad1. - Allow mongodb to manage own log files. - Allow neutron connections to system dbus. - Add support for /var/lib/swiftdirectory. - Allow nova-scheduler to read certs. - Allow openvpn to access /sys/fs/cgroup dir. - Allow openvpn to execute systemd-passwd-agent in systemd_passwd_agent_t to make openvpn working with systemd. - Fix samba_export_all_ro/samba_export_all_rw booleans to dontaudit search/read security files. - Add auth_use_nsswitch for portreserve to make it working with sssd. - automount policy is non-base module so it needs to be called in optional block. - ALlow sensord to getattr on sysfs. - Label /usr/share/corosync/corosync as cluster_exec_t. - Allow lmsd_plugin to read passwd file. BZ(1093733) - Allow read antivirus domain all kernel sysctls. - Allow mandb to getattr on file systems - Allow nova-console to connect to mem_cache port. - Make sosreport as unconfined domain. - Allow mondogdb to 'accept' accesses on the tcp_socket port. - ALlow sanlock to send a signal to virtd_t.- Build also MLS policy Resolves:#1138424- Add back kill permisiion for system class - Allow iptables read fail2ban logs. - Fix radius labeled ports - Add userdom_manage_user_tmpfs_files interface - Allow libreswan to connect to VPN via NM-libreswan. - Label 4101 tcp port as brlp port - fix dev_getattr_generic_usb_dev interface - Allow all domains to read fonts - Make sure /run/systemd/generator and system is labeled correctly on creation. - Dontaudit aicuu to search home config dir. - Make keystone_cgi_script_t domain. Resolves:#1138424 - Fix bug in drbd policy, - Added support for cpuplug. - ALlow sanlock_t to read sysfs_t. - Added sendmail_domtrans_unconfined interface - Fix broken interfaces - radiusd wants to write own log files. - Label /usr/libexec/rhsmd as rhsmcertd_exec_t - Allow rhsmcertd send signull to setroubleshoot. - Allow rhsmcertd manage rpm db. - Added policy for blrtty. - Fix keepalived policy - Allow rhev-agentd dbus chat with systemd-logind. - Allow keepalived manage snmp var lib sock files. - Add support for /var/lib/graphite-web - Allow NetworkManager to create Bluetooth SDP sockets - It's going to do the the discovery for DUN service for modems with Bluez 5. - Allow swift to connect to all ephemeral ports by default. - Allow sssd to read selinux config to add SELinux user mapping. - Allow lsmd to search own plguins. - Allow abrt to read /dev/memto generate an unique machine_id and uses sosuploader's algorithm based off dmidecode[1] fields. - ALlow zebra for user/group look-ups. - Allow nova domains to getattr on all filesystems. - Allow collectd sys_ptrace and dac_override caps because of reading of /proc/%i/io for several processes. - Allow pppd to connect to /run/sstpc/sstpc-nm-sstp-service-28025 over unix stream socket. - Allow rhnsd_t to manage also rhnsd config symlinks. - ALlow user mail domains to create dead.letter. - Allow rabbitmq_t read rabbitmq_var_lib_t lnk files. - Allow pki-tomcat to change SELinux object identity. - Allow radious to connect to apache ports to do OCSP check - Allow git cgi scripts to create content in /tmp - Allow cockpit-session to do GSSAPI logins. - Allow sensord read in /proc - Additional access required by usbmuxd- Allow locate to look at files/directories without labels, and chr_file and blk_file on non dev file systems - Label /usr/lib/erlang/erts.*/bin files as bin_t - Add files_dontaudit_access_check_home_dir() inteface. - Allow udev_t mounton udev_var_run_t dirs #(1128618) - Add systemd_networkd_var_run_t labeling for /var/run/systemd/netif and allow systemd-networkd to manage it. - Add init_dontaudit_read_state() interface. - Add label for ~/.local/share/fonts - Allow unconfined_r to access unconfined_service_t. - Allow init to read all config files - Add new interface to allow creation of file with lib_t type - Assign rabbitmq port. - Allow unconfined_service_t to dbus chat with all dbus domains - Add new interfaces to access users keys. - Allow domains to are allowed to mounton proc to mount on files as well as dirs - Fix labeling for HOME_DIR/tmp and HOME_DIR/.tmp directories. - Add a port definition for shellinaboxd - Label ~/tmp and ~/.tmp directories in user tmp dirs as user_tmp_t - Allow userdomains to stream connect to pcscd for smart cards - Allow programs to use pam to search through user_tmp_t dires (/tmp/.X11-unix) - Update to rawhide-contrib changes Resolves:#1123844- Rebase to 3.13.1 which we have in Fedora21 Resolves:#1128284- Back port fixes from Fedora. Mainly OpenStack and Docker fixes- Add policy-rhel-7.1-{base,contrib} patches- Add support for us_cli ports - Fix labeling for /var/run/user//gvfs - add support for tcp/9697 - Additional rules required by openstack, needs backport to F20 and RHEL7 - Additional access required by docker - ALlow motion to use tcp/8082 port - Allow init_t to setattr/relabelfrom dhcp state files - Dontaudit antivirus domains read access on all security files by default - Add missing alias for old amavis_etc_t type - Allow block_suspend cap for haproxy - Additional fixes for instack overcloud - Allow OpenStack to read mysqld_db links and connect to MySQL - Remove dup filename rules in gnome.te - Allow sys_chroot cap for httpd_t and setattr on httpd_log_t - Allow iscsid to handle own unit files - Add iscsi_systemctl() - Allow mongod to create also sock_files in /run with correct labeling - Allow httpd to send signull to apache script domains and don't audit leaks - Allow rabbitmq_beam to connect to httpd port - Allow aiccu stream connect to pcscd - Allow dmesg to read hwdata and memory dev - Allow all freeipmi domains to read/write ipmi devices - Allow sblim_sfcbd to use also pegasus-https port - Allow rabbitmq_epmd to manage rabbit_var_log_t files - Allow chronyd to read /sys/class/hwmon/hwmon1/device/temp2_input - Allow docker to status any unit file and allow it to start generic unit files- Change hsperfdata_root to have as user_tmp_t Resolves:#1076523- Fix Multiple same specifications for /var/named/chroot/dev/zero - Add labels for /var/named/chroot_sdb/dev devices - Add support for strongimcv - Use kerberos_keytab_domains in auth_use_nsswitch - Update auth_use_nsswitch to make all these types as kerberos_keytab_domain to - Allow net_raw cap for neutron_t and send sigkill to dnsmasq - Fix ntp_filetrans_named_content for sntp-kod file - Add httpd_dbus_sssd boolean - Dontaudit exec insmod in boinc policy - Rename kerberos_keytab_domain to kerberos_keytab_domains - Add kerberos_keytab_domain() - Fix kerberos_keytab_template() - Make all domains which use kerberos as kerberos_keytab_domain Resolves:#1083670 - Allow kill capability to winbind_t- varnishd wants chown capability - update ntp_filetrans_named_content() interface - Add additional fixes for neutron_t. #1083335 - Dontaudit getattr on proc_kcore_t - Allow pki_tomcat_t to read ipa lib files - Allow named_filetrans_domain to create /var/cache/ibus with correct labelign - Allow init_t run /sbin/augenrules - Add dev_unmount_sysfs_fs and sysnet_manage_ifconfig_run interfaces - Allow unpriv SELinux user to use sandbox - Add default label for /tmp/hsperfdata_root- Add file subs also for /var/home- Allow xauth_t to read user_home_dir_t lnk_file - Add labeling for lightdm-data - Allow certmonger to manage ipa lib files - Add support for /var/lib/ipa - Allow pegasus to getattr virt_content - Added some new rules to pcp policy - Allow chrome_sandbox to execute config_home_t - Add support for ABRT FAF- Allow kdm to send signull to remote_login_t process - Add gear policy - Turn on gear_port_t - Allow cgit to read gitosis lib files by default - Allow vdagent to read xdm state - Allow NM and fcoeadm to talk together over unix_dgram_socket- Back port fixes for pegasus_openlmi_admin_t from rawhide Resolves:#1080973 - Add labels for ostree - Add SELinux awareness for NM - Label /usr/sbin/pwhistory_helper as updpwd_exec_t- add gnome_append_home_config() - Allow thumb to append GNOME config home files - Allow rasdaemon to rw /dev/cpu//msr - fix /var/log/pki file spec - make bacula_t as auth_nsswitch domain - Identify pki_tomcat_cert_t as a cert_type - Define speech-dispater_exec_t as an application executable - Add a new file context for /var/named/chroot/run directory - update storage_filetrans_all_named_dev for sg* devices - Allow auditctl_t to getattr on all removeable devices - Allow nsswitch_domains to stream connect to nmbd - Allow unprivusers to connect to memcached - label /var/lib/dirsrv/scripts-INSTANCE as bin_t- Allow also unpriv user to run vmtools - Allow secadm to read /dev/urandom and meminfo Resolves:#1079250 - Add booleans to allow docker processes to use nfs and samba - Add mdadm_tmpfs support - Dontaudit net_amdin for /usr/lib/jvm/java-1.7.0-openjdk-1.7.0.51-2.4.5.1.el7.x86_64/jre-abrt/bin/java running as pki_tomcat_t - Allow vmware-user-sui to use user ttys - Allow talk 2 users logged via console too - Allow ftp services to manage xferlog_t - Make all pcp domanis as unconfined for RHEL7.0 beucause of new policies - allow anaconda to dbus chat with systemd-localed- allow anaconda to dbus chat with systemd-localed - Add fixes for haproxy based on bperkins@redhat.com - Allow cmirrord to make dmsetup working - Allow NM to execute arping - Allow users to send messages through talk - Add userdom_tmp_role for secadm_t- Add additional fixes for rtas_errd - Fix transitions for tmp/tmpfs in rtas.te - Allow rtas_errd to readl all sysctls- Add support for /var/spool/rhsm/debug - Make virt_sandbox_use_audit as True by default - Allow svirt_sandbox_domains to ptrace themselves- Allow docker containers to manage /var/lib/docker content- Allow docker to read tmpfs_t symlinks - Allow sandbox svirt_lxc_net_t to talk to syslog and to sssd over stream sockets- Allow collectd to talk to libvirt - Allow chrome_sandbox to use leaked unix_stream_sockets - Dontaudit leaks of sockets into chrome_sandbox_t - If you create a cups directory in /var/cache then it should be labeled cups_rw_etc_t - Run vmtools as unconfined domains - Allow snort to manage its log files - Allow systemd_cronjob_t to be entered via bin_t - Allow procman to list doveconf_etc_t - allow keyring daemon to create content in tmpfs directories - Add proper labelling for icedtea-web - vpnc is creating content in networkmanager var run directory - Label sddm as xdm_exec_t to make KDE working again - Allow postgresql to read network state - Allow java running as pki_tomcat to read network sysctls - Fix cgroup.te to allow cgred to read cgconfig_etc_t - Allow beam.smp to use ephemeral ports - Allow winbind to use the nis to authenticate passwords- Make rtas_errd_t as unconfined domain for F20.It needs additional fixes. It runs rpm at least. - Allow net_admin cap for fence_virtd running as fenced_t - Make abrt-java-connector working - Make cimtest script 03_defineVS.py of ComputerSystem group working - Fix git_system_enable_homedirs boolean - Allow munin mail plugins to read network systcl- Allow vmtools_helper_t to execute bin_t - Add support for /usr/share/joomla - /var/lib/containers should be labeled as openshift content for now - Allow docker domains to talk to the login programs, to allow a process to login into the container - Allow install_t do dbus chat with NM - Fix interface names in anaconda.if - Add install_t for anaconda. A new type is a part of anaconda policy - sshd to read network sysctls- Allow zabbix to send system log msgs - Allow init_t to stream connect to ipsec Resolves:#1060775- Add docker_connect_any boolean- Allow unpriv SELinux users to dbus chat with firewalld - Add lvm_write_metadata() - Label /etc/yum.reposd dir as system_conf_t. Should be safe because system_conf_t is base_ro_file_type - Allow pegasus_openlmi_storage_t to write lvm metadata - Add hide_broken_symptoms for kdumpgui because of systemd bug - Make kdumpgui_t as unconfined domain Resolves:#1044299 - Allow docker to connect to tcp/5000- Allow numad to write scan_sleep_millisecs - Turn on entropyd_use_audio boolean by default - Allow cgred to read /etc/cgconfig.conf because it contains templates used together with rules from /etc/cgrules.conf. - Allow lscpu running as rhsmcertd_t to read /proc/sysinfo - Fix label on irclogs in the homedir - Allow kerberos_keytab_domain domains to manage keys until we get sssd fix - Allow postgresql to use ldap - Add missing syslog-conn port - Add support for /dev/vmcp and /dev/sclp Resolves:#1069310- Modify xdm_write_home to allow create files/links in /root with xdm_home_ - Allow virt domains to read network state Resolves:#1072019- Added pcp rules - dontaudit openshift_cron_t searching random directories, should be back ported to RHEL6 - clean up ctdb.te - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow certmonger to list home dirs- Change userdom_use_user_inherited_ttys to userdom_use_user_ttys for systemd-tty-ask - Add sysnet_filetrans_named_content_ifconfig() interface - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow kerberos keytab domains to manage sssd/userdomain keys" - Allow to run ip cmd in neutron_t domain- Allow block_suspend cap2 for systemd-logind and rw dri device - Add labeling for /usr/libexec/nm-libreswan-service - Allow locallogin to rw xdm key to make Virtual Terminal login providing smartcard pin working - Add xserver_rw_xdm_keys() - Allow rpm_script_t to dbus chat also with systemd-located - Fix ipa_stream_connect_otpd() - update lpd_manage_spool() interface - Allow krb5kdc to stream connect to ipa-otpd - Add ipa_stream_connect_otpd() interface - Allow vpnc to unlink NM pids - Add networkmanager_delete_pid_files() - Allow munin plugins to access unconfined plugins - update abrt_filetrans_named_content to cover /var/spool/debug - Label /var/spool/debug as abrt_var_cache_t - Allow rhsmcertd to connect to squid port - Make docker_transition_unconfined as optional boolean - Allow certmonger to list home dirs- Make snapperd as unconfined domain and add additional fixes for it - Remove nsplugin.pp module on upgrade- Add snapperd_home_t for HOME_DIR/.snapshots directory - Make sosreport as unconfined domain - Allow sosreport to execute grub2-probe - Allow NM to manage hostname config file - Allow systemd_timedated_t to dbus chat with rpm_script_t - Allow lsmd plugins to connect to http/ssh/http_cache ports by default - Add lsmd_plugin_connect_any boolean - Allow mozilla_plugin to attempt to set capabilities - Allow lsdm_plugins to use tcp_socket - Dontaudit mozilla plugin from getattr on /proc or /sys - Dontaudit use of the keyring by the services in a sandbox - Dontaudit attempts to sys_ptrace caused by running ps for mysqld_safe_t - Allow rabbitmq_beam to connect to jabber_interserver_port - Allow logwatch_mail_t to transition to qmail_inject and queueu - Added new rules to pcp policy - Allow vmtools_helper_t to change role to system_r - Allow NM to dbus chat with vmtools - Fix couchdb_manage_files() to allow manage couchdb conf files - Add support for /var/run/redis.sock - dontaudit gpg trying to use audit - Allow consolekit to create log directories and files - Fix vmtools policy to allow user roles to access vmtools_helper_t - Allow block_suspend cap2 for ipa-otpd - Allow pkcsslotd to read users state - Add ioctl to init_dontaudit_rw_stream_socket - Add systemd_hostnamed_manage_config() interface - Remove transition for temp dirs created by init_t - gdm-simple-slave uses use setsockopt - sddm-greater is a xdm type program- Add lvm_read_metadata() - Allow auditadm to search /var/log/audit dir - Add lvm_read_metadata() interface - Allow confined users to run vmtools helpers - Fix userdom_common_user_template() - Generic systemd unit scripts do write check on / - Allow init_t to create init_tmp_t in /tmp.This is for temporary content created by generic unit files - Add additional fixes needed for init_t and setup script running in generic unit files - Allow general users to create packet_sockets - added connlcli port - Add init_manage_transient_unit() interface - Allow init_t (generic unit files) to manage rpc state date as we had it for initrc_t - Fix userdomain.te to require passwd class - devicekit_power sends out a signal to all processes on the message bus when power is going down - Dontaudit rendom domains listing /proc and hittping system_map_t - Dontauit leaks of var_t into ifconfig_t - Allow domains that transition to ssh_t to manipulate its keyring - Define oracleasm_t as a device node - Change to handle /root as a symbolic link for os-tree - Allow sysadm_t to create packet_socket, also move some rules to attributes - Add label for openvswitch port - Remove general transition for files/dirs created in /etc/mail which got etc_aliases_t label. - Allow postfix_local to read .forward in pcp lib files - Allow pegasus_openlmi_storage_t to read lvm metadata - Add additional fixes for pegasus_openlmi_storage_t - Allow bumblebee to manage debugfs - Make bumblebee as unconfined domain - Allow snmp to read etc_aliases_t - Allow lscpu running in pegasus_openlmi_storage_t to read /dev/mem - Allow pegasus_openlmi_storage_t to read /proc/1/environ - Dontaudit read gconf files for cupsd_config_t - make vmtools as unconfined domain - Add vmtools_helper_t for helper scripts. Allow vmtools shutdonw a host and run ifconfig. - Allow collectd_t to use a mysql database - Allow ipa-otpd to perform DNS name resolution - Added new policy for keepalived - Allow openlmi-service provider to manage transitient units and allow stream connect to sssd - Add additional fixes new pscs-lite+polkit support - Add labeling for /run/krb5kdc - Change w3c_validator_tmp_t to httpd_w3c_validator_tmp_t in F20 - Allow pcscd to read users proc info - Dontaudit smbd_t sending out random signuls - Add boolean to allow openshift domains to use nfs - Allow w3c_validator to create content in /tmp - zabbix_agent uses nsswitch - Allow procmail and dovecot to work together to deliver mail - Allow spamd to execute files in homedir if boolean turned on - Allow openvswitch to listen on port 6634 - Add net_admin capability in collectd policy - Fixed snapperd policy - Fixed bugsfor pcp policy - Allow dbus_system_domains to be started by init - Fixed some interfaces - Add kerberos_keytab_domain attribute - Fix snapperd_conf_t def- Addopt corenet rules for unbound-anchor to rpm_script_t - Allow runuser to send send audit messages. - Allow postfix-local to search .forward in munin lib dirs - Allow udisks to connect to D-Bus - Allow spamd to connect to spamd port - Fix syntax error in snapper.te - Dontaudit osad to search gconf home files - Allow rhsmcertd to manage /etc/sysconf/rhn director - Fix pcp labeling to accept /usr/bin for all daemon binaries - Fix mcelog_read_log() interface - Allow iscsid to manage iscsi lib files - Allow snapper domtrans to lvm_t. Add support for /etc/snapper and allow snapperd to manage it. - Make tuned_t as unconfined domain for RHEL7.0 - Allow ABRT to read puppet certs - Add sys_time capability for virt-ga - Allow gemu-ga to domtrans to hwclock_t - Allow additional access for virt_qemu_ga_t processes to read system clock and send audit messages - Fix some AVCs in pcp policy - Add to bacula capability setgid and setuid and allow to bind to bacula ports - Changed label from rhnsd_rw_conf_t to rhnsd_conf_t - Add access rhnsd and osad to /etc/sysconfig/rhn - drbdadm executes drbdmeta - Fixes needed for docker - Allow epmd to manage /var/log/rabbitmq/startup_err file - Allow beam.smp connect to amqp port - Modify xdm_write_home to allow create also links as xdm_home_t if the boolean is on true - Allow init_t to manage pluto.ctl because of init_t instead of initrc_t - Allow systemd_tmpfiles_t to manage all non security files on the system - Added labels for bacula ports - Fix label on /dev/vfio/vfio - Add kernel_mounton_messages() interface - init wants to manage lock files for iscsi- Added osad policy - Allow postfix to deliver to procmail - Allow bumblebee to seng kill signal to xserver - Allow vmtools to execute /usr/bin/lsb_release - Allow docker to write system net ctrls - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix pcp.te - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl- Turn on bacula, rhnsd policy - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl - Fixes for *_admin interfaces - Add pegasus_openlmi_storage_var_run_t type def - Add support for /var/run/openlmi-storage - Allow tuned to create syslog.conf with correct labeling - Add httpd_dontaudit_search_dirs boolean - Add support for winbind.service - ALlow also fail2ban-client to read apache logs - Allow vmtools to getattr on all fs - Add support for dey_sapi port - Add logging_filetrans_named_conf() - Allow passwd_t to use ipc_lock, so that it can change the password in gnome-keyring- Update snapper policy - Allow domains to append rkhunter lib files - Allow snapperd to getattr on all fs - Allow xdm to create /var/gdm with correct labeling - Add label for snapper.log - Allow fail2ban-client to read apache log files - Allow thumb_t to execute dbus-daemon in thumb_t- Allow gdm to create /var/gdm with correct labeling - Allow domains to append rkhunterl lib files. #1057982 - Allow systemd_tmpfiles_t net_admin to communicate with journald - Add interface to getattr on an isid_type for any type of file - Update libs_filetrans_named_content() to have support for /usr/lib/debug directory - Allow initrc_t domtrans to authconfig if unconfined is enabled - Allow docker and mount on devpts chr_file - Allow docker to transition to unconfined_t if boolean set - init calling needs to be optional in domain.te - Allow uncofined domain types to handle transient unit files - Fix labeling for vfio devices - Allow net_admin capability and send system log msgs - Allow lldpad send dgram to NM - Add networkmanager_dgram_send() - rkhunter_var_lib_t is correct type - Back port pcp policy from rawhide - Allow openlmi-storage to read removable devices - Allow system cron jobs to manage rkhunter lib files - Add rkhunter_manage_lib_files() - Fix ftpd_use_fusefs boolean to allow manage also symlinks - Allow smbcontrob block_suspend cap2 - Allow slpd to read network and system state info - Allow NM domtrans to iscsid_t if iscsiadm is executed - Allow slapd to send a signal itself - Allow sslget running as pki_ra_t to contact port 8443, the secure port of the CA. - Fix plymouthd_create_log() interface - Add rkhunter policy with files type definition for /var/lib/rkhunter until it is fixed in rkhunter package - Add mozilla_plugin_exec_t for /usr/lib/firefox/plugin-container - Allow postfix and cyrus-imapd to work out of box - Allow fcoemon to talk with unpriv user domain using unix_stream_socket - Dontaudit domains that are calling into journald to net_admin - Add rules to allow vmtools to do what it does - snapperd is D-Bus service - Allow OpenLMI PowerManagement to call 'systemctl --force reboot' - Add haproxy_connect_any boolean - Allow haproxy also to use http cache port by default Resolves:#1058248- Allow apache to write to the owncloud data directory in /var/www/html... - Allow consolekit to create log dir - Add support for icinga CGI scripts - Add support for icinga - Allow kdumpctl_t to create kdump lock file Resolves:#1055634 - Allow kdump to create lnk lock file - Allow nscd_t block_suspen capability - Allow unconfined domain types to manage own transient unit file - Allow systemd domains to handle transient init unit files - Add interfaces to handle transient- Add cron unconfined role support for uncofined SELinux user - Call corenet_udp_bind_all_ports() in milter.te - Allow fence_virtd to connect to zented port - Fix header for mirrormanager_admin() - Allow dkim-milter to bind udp ports - Allow milter domains to send signull itself - Allow block_suspend for yum running as mock_t - Allow beam.smp to manage couchdb files - Add couchdb_manage_files() - Add labeling for /var/log/php_errors.log - Allow bumblebee to stream connect to xserver - Allow bumblebee to send a signal to xserver - gnome-thumbnail to stream connect to bumblebee - Allow xkbcomp running as bumblebee_t to execute bin_t - Allow logrotate to read squid.conf - Additional rules to get docker and lxc to play well with SELinux - Allow bumbleed to connect to xserver port - Allow pegasus_openlmi_storage_t to read hwdata- Allow init_t to work on transitient and snapshot unit files - Add logging_manage_syslog_config() - Update sysnet_dns_name_resolve() to allow connect to dnssec por - Allow pegasus_openlmi_storage_t to read hwdata Resolves:#1031721 - Fix rhcs_rw_cluster_tmpfs() - Allow fenced_t to bind on zented udp port - Added policy for vmtools - Fix mirrormanager_read_lib_files() - Allow mirromanager scripts running as httpd_t to manage mirrormanager pid files - Allow ctdb to create sock files in /var/run/ctdb - Add sblim_filetrans_named_content() interface - Allow rpm scritplets to create /run/gather with correct labeling - Allow gnome keyring domains to create gnome config dirs - Dontaudit read/write to init stream socket for lsmd_plugin_t - Allow automount to read nfs link files - Allow lsm plugins to read/write lsmd stream socket - Allow certmonger to connect ldap port to make IPA CA certificate renewal working. - Add also labeling for /var/run/ctdb - Add missing labeling for /var/lib/ctdb - ALlow tuned to manage syslog.conf. Should be fixed in tuned. #1030446 - Dontaudit hypervkvp to search homedirs - Dontaudit hypervkvp to search admin homedirs - Allow hypervkvp to execute bin_t and ifconfig in the caller domain - Dontaudit xguest_t to read ABRT conf files - Add abrt_dontaudit_read_config() - Allow namespace-init to getattr on fs - Add thumb_role() also for xguest - Add filename transitions to create .spamassassin with correct labeling - Allow apache domain to read mirrormanager pid files - Allow domains to read/write shm and sem owned by mozilla_plugin_t - Allow alsactl to send a generic signal to kernel_t- Add back rpm_run() for unconfined user- Add missing files_create_var_lib_dirs() - Fix typo in ipsec.te - Allow passwd to create directory in /var/lib - Add filename trans also for event21 - Allow iptables command to read /dev/rand - Add sigkill capabilityfor ipsec_t - Add filename transitions for bcache devices - Add additional rules to create /var/log/cron by syslogd_t with correct labeling - Add give everyone full access to all key rings - Add default lvm_var_run_t label for /var/run/multipathd - Fix log labeling to have correct default label for them after logrotate - Labeled ~/.nv/GLCache as being gstreamer output - Allow nagios_system_plugin to read mrtg lib files - Add mrtg_read_lib_files() - Call rhcs_rw_cluster_tmpfs for dlm_controld - Make authconfing as named_filetrans domain - Allow virsh to connect to user process using stream socket - Allow rtas_errd to read rand/urand devices and add chown capability - Fix labeling from /var/run/net-snmpd to correct /var/run/net-snmp Resolves:#1051497 - Add also chown cap for abrt_upload_watch_t. It already has dac_override - Allow sosreport to manage rhsmcertd pid files - Add rhsmcertd_manage_pid_files() - Allow also setgid cap for rpc.gssd - Dontaudit access check for abrt on cert_t - Allow pegasus_openlmi_system providers to dbus chat with systemd-logind- Fix semanage import handling in spec file- Add default lvm_var_run_t label for /var/run/multipathd Resolves:#1051430 - Fix log labeling to have correct default label for them after logrotate - Add files_write_root_dirs - Add new openflow port label for 6653/tcp and 6633/tcp - Add xserver_manage_xkb_libs() - Label tcp/8891 as milter por - Allow gnome_manage_generic_cache_files also create cache_home_t files - Fix aide.log labeling - Fix log labeling to have correct default label for them after logrotate - Allow mysqld-safe write access on /root to make mysqld working - Allow sosreport domtrans to prelikn - Allow OpenvSwitch to connec to openflow ports - Allow NM send dgram to lldpad - Allow hyperv domains to execute shell - Allow lsmd plugins stream connect to lsmd/init - Allow sblim domains to create /run/gather with correct labeling - Allow httpd to read ldap certs - Allow cupsd to send dbus msgs to process with different MLS level - Allow bumblebee to stream connect to apmd - Allow bumblebee to run xkbcomp - Additional allow rules to get libvirt-lxc containers working with docker - Additional allow rules to get libvirt-lxc containers working with docker - Allow docker to getattr on itself - Additional rules needed for sandbox apps - Allow mozilla_plugin to set attributes on usb device if use_spice boolean enabled - httpd should be able to send signal/signull to httpd_suexec_t - Add more fixes for neturon. Domtrans to dnsmasq, iptables. Make neutron as filenamtrans domain.- Add neutron fixes- Allow sshd to write to all process levels in order to change passwd when running at a level - Allow updpwd_t to downgrade /etc/passwd file to s0, if it is not running with this range - Allow apcuspd_t to status and start the power unit file - Allow udev to manage kdump unit file - Added new interface modutils_dontaudit_exec_insmod - Allow cobbler to search dhcp_etc_t directory - systemd_systemctl needs sys_admin capability - Allow sytemd_tmpfiles_t to delete all directories - passwd to create gnome-keyring passwd socket - Add missing zabbix_var_lib_t type - Fix filename trans for zabbixsrv in zabbix.te - Allow fprintd_t to send syslog messages - Add zabbix_var_lib_t for /var/lib/zabbixsrv, also allow zabix to connect to smtp port - Allow mozilla plugin to chat with policykit, needed for spice - Allow gssprozy to change user and gid, as well as read user keyrings - Label upgrades directory under /var/www as httpd_sys_rw_content_t, add other filetrans rules to label content correctly - Allow polipo to connect to http_cache_ports - Allow cron jobs to manage apache var lib content - Allow yppassword to manage the passwd_file_t - Allow showall_t to send itself signals - Allow cobbler to restart dhcpc, dnsmasq and bind services - Allow certmonger to manage home cert files - Add userdom filename trans for user mail domains - Allow apcuspd_t to status and start the power unit file - Allow cgroupdrulesengd to create content in cgoups directories - Allow smbd_t to signull cluster - Allow gluster daemon to create fifo files in glusterd_brick_t and sock_file in glusterd_var_lib_t - Add label for /var/spool/cron.aquota.user - Allow sandbox_x domains to use work with the mozilla plugin semaphore - Added new policy for speech-dispatcher - Added dontaudit rule for insmod_exec_t in rasdaemon policy - Updated rasdaemon policy - Allow system_mail_t to transition to postfix_postdrop_t - Clean up mirrormanager policy - Allow virt_domains to read cert files, needs backport to RHEL7 - Allow sssd to read systemd_login_var_run_t - Allow irc_t to execute shell and bin-t files: - Add new access for mythtv - Allow rsync_t to manage all non auth files - allow modemmanger to read /dev/urand - Allow sandbox apps to attempt to set and get capabilties- Add labeling for /var/lib/servicelog/servicelog.db-journal - Add support for freeipmi port - Add sysadm_u_default_contexts - Make new type to texlive files in homedir - Allow subscription-manager running as sosreport_t to manage rhsmcertd - Additional fixes for docker.te - Remove ability to do mount/sys_admin by default in virt_sandbox domains - New rules required to run docker images within libivrt - Add label for ~/.cvsignore - Change mirrormanager to be run by cron - Add mirrormanager policy - Fixed bumblebee_admin() and mip6d_admin() - Add log support for sensord - Fix typo in docker.te - Allow amanda to do backups over UDP - Allow bumblebee to read /etc/group and clean up bumblebee.te - type transitions with a filename not allowed inside conditionals - Don't allow virt-sandbox tools to use netlink out of the box, needs back port to RHEL7 - Make new type to texlive files in homedir- Allow freeipmi_ipmidetectd_t to use freeipmi port - Update freeipmi_domain_template() - Allow journalctl running as ABRT to read /run/log/journal - Allow NM to read dispatcher.d directory - Update freeipmi policy - Type transitions with a filename not allowed inside conditionals - Allow tor to bind to hplip port - Make new type to texlive files in homedir - Allow zabbix_agent to transition to dmidecode - Add rules for docker - Allow sosreport to send signull to unconfined_t - Add virt_noatsecure and virt_rlimitinh interfaces - Fix labeling in thumb.fc to add support for /usr/lib64/tumbler-1/tumblerddd support for freeipmi port - Add sysadm_u_default_contexts - Add logging_read_syslog_pid() - Fix userdom_manage_home_texlive() interface - Make new type to texlive files in homedir - Add filename transitions for /run and /lock links - Allow virtd to inherit rlimit information Resolves:#975358- Change labeling for /usr/libexec/nm-dispatcher.action to NetworkManager_exec_t Resolves:#1039879 - Add labeling for /usr/lib/systemd/system/mariadb.service - Allow hyperv_domain to read sysfs - Fix ldap_read_certs() interface to allow acess also link files - Add support for /usr/libexec/pegasus/cmpiLMI_Journald-cimprovagt - Allow tuned to run modprobe - Allow portreserve to search /var/lib/sss dir - Add SELinux support for the teamd package contains team network device control daemon. - Dontaudit access check on /proc for bumblebee - Bumblebee wants to load nvidia modules - Fix rpm_named_filetrans_log_files and wine.te - Add conman policy for rawhide - DRM master and input event devices are used by the TakeDevice API - Clean up bumblebee policy - Update pegasus_openlmi_storage_t policy - Add freeipmi_stream_connect() interface - Allow logwatch read madm.conf to support RAID setup - Add raid_read_conf_files() interface - Allow up2date running as rpm_t create up2date log file with rpm_log_t labeling - add rpm_named_filetrans_log_files() interface - Allow dkim-milter to create files/dirs in /tmp - update freeipmi policy - Add policy for freeipmi services - Added rdisc_admin and rdisc_systemctl interfaces - opensm policy clean up - openwsman policy clean up - ninfod policy clean up - Added new policy for ninfod - Added new policy for openwsman - Added rdisc_admin and rdisc_systemctl interfaces - Fix kernel_dontaudit_access_check_proc() - Add support for /dev/uhid - Allow sulogin to get the attributes of initctl and sys_admin cap - Add kernel_dontaudit_access_check_proc() - Fix dev_rw_ipmi_dev() - Fix new interface in devices.if - DRM master and input event devices are used by the TakeDevice API - add dev_rw_inherited_dri() and dev_rw_inherited_input_dev() - Added support for default conman port - Add interfaces for ipmi devices- Allow sosreport to send a signal to ABRT - Add proper aliases for pegasus_openlmi_service_exec_t and pegasus_openlmi_service_t - Label /usr/sbin/htcacheclean as httpd_exec_t Resolves:#1037529 - Added support for rdisc unit file - Add antivirus_db_t labeling for /var/lib/clamav-unofficial-sigs - Allow runuser running as logrotate connections to system DBUS - Label bcache devices as fixed_disk_device_t - Allow systemctl running in ipsec_mgmt_t to access /usr/lib/systemd/system/ipsec.service - Label /usr/lib/systemd/system/ipsec.service as ipsec_mgmt_unit_file_t- Add back setpgid/setsched for sosreport_t- Added fix for clout_init to transition to rpm_script_t (dwalsh@redhat.com)- Dontaudit openshift domains trying to use rawip_sockets, this is caused by a bad check in the kernel. - Allow git_system_t to read git_user_content if the git_system_enable_homedirs boolean is turned on - Add lsmd_plugin_t for lsm plugins - Allow dovecot-deliver to search mountpoints - Add labeling for /etc/mdadm.conf - Allow opelmi admin providers to dbus chat with init_t - Allow sblim domain to read /dev/urandom and /dev/random - Allow apmd to request the kernel load modules - Add glusterd_brick_t type - label mate-keyring-daemon with gkeyringd_exec_t - Add plymouthd_create_log() - Dontaudit leaks from openshift domains into mail domains, needs back port to RHEL6 - Allow sssd to request the kernel loads modules - Allow gpg_agent to use ssh-add - Allow gpg_agent to use ssh-add - Dontaudit access check on /root for myslqd_safe_t - Allow ctdb to getattr on al filesystems - Allow abrt to stream connect to syslog - Allow dnsmasq to list dnsmasq.d directory - Watchdog opens the raw socket - Allow watchdog to read network state info - Dontaudit access check on lvm lock dir - Allow sosreport to send signull to setroubleshootd - Add setroubleshoot_signull() interface - Fix ldap_read_certs() interface - Allow sosreport all signal perms - Allow sosreport to run systemctl - Allow sosreport to dbus chat with rpm - Add glusterd_brick_t files type - Allow zabbix_agentd to read all domain state - Clean up rtas.if - Allow smoltclient to execute ldconfig - Allow sosreport to request the kernel to load a module - Fix userdom_confined_admin_template() - Add back exec_content boolean for secadm, logadm, auditadm - Fix files_filetrans_system_db_named_files() interface - Allow sulogin to getattr on /proc/kcore - Add filename transition also for servicelog.db-journal - Add files_dontaudit_access_check_root() - Add lvm_dontaudit_access_check_lock() interface- Allow watchdog to read /etc/passwd - Allow browser plugins to connect to bumblebee - New policy for bumblebee and freqset - Add new policy for mip6d daemon - Add new policy for opensm daemon - Allow condor domains to read/write condor_master udp_socket - Allow openshift_cron_t to append to openshift log files, label /var/log/openshift - Add back file_pid_filetrans for /var/run/dlm_controld - Allow smbd_t to use inherited tmpfs content - Allow mcelog to use the /dev/cpu device - sosreport runs rpcinfo - sosreport runs subscription-manager - Allow staff_t to run frequency command - Allow systemd_tmpfiles to relabel log directories - Allow staff_t to read xserver_log file - Label hsperfdata_root as tmp_t- More sosreport fixes to make ABRT working- Fix files_dontaudit_unmount_all_mountpoints() - Add support for 2608-2609 tcp/udp ports - Should allow domains to lock the terminal device - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - We need to require passwd rootok - Fix zebra.fc - Fix dnsmasq_filetrans_named_content() interface - Allow all sandbox domains create content in svirt_home_t - Allow zebra domains also create zebra_tmp_t files in /tmp - Add support for new zebra services:isisd,babeld. Add systemd support for zebra services. - Fix labeling on neutron and remove transition to iconfig_t - abrt needs to read mcelog log file - Fix labeling on dnsmasq content - Fix labeling on /etc/dnsmasq.d - Allow glusterd to relabel own lib files - Allow sandbox domains to use pam_rootok, and dontaudit attempts to unmount file systems, this is caused by a bug in systemd - Allow ipc_lock for abrt to run journalctl- Fix config.tgz- Fix passenger_stream_connect interface - setroubleshoot_fixit wants to read network state - Allow procmail_t to connect to dovecot stream sockets - Allow cimprovagt service providers to read network states - Add labeling for /var/run/mariadb - pwauth uses lastlog() to update system's lastlog - Allow account provider to read login records - Add support for texlive2013 - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - Allow passwd_t to connect to gnome keyring to change password - Update mls config files to have cronjobs in the user domains - Remove access checks that systemd does not actually do- Add support for yubikey in homedir - Add support for upd/3052 port - Allow apcupsd to use PowerChute Network Shutdown - Allow lsmd to execute various lsmplugins - Add labeling also for /etc/watchdog\.d where are watchdog scripts located too - Update gluster_export_all_rw boolean to allow relabel all base file types - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling- Add files_relabel_base_file_types() interface - Allow netlabel-config to read passwd - update gluster_export_all_rw boolean to allow relabel all base file types caused by lsetxattr() - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling - Allow pegasus to domtrans to mount_t - Add labeling for unconfined scripts in /usr/libexec/watchdog/scripts - Add support for unconfined watchdog scripts - Allow watchdog to manage own log files- Add label only for redhat.repo instead of /etc/yum.repos.d. But probably we will need to switch for the directory. - Label /etc/yum.repos.d as system_conf_t - Use sysnet_filetrans_named_content in udev.te instead of generic transition for net_conf_t - Allow dac_override for sysadm_screen_t - Allow init_t to read ipsec_conf_t as we had it for initrc_t. Needed by ipsec unit file. - Allow netlabel-config to read meminfo - Add interface to allow docker to mounton file_t - Add new interface to exec unlabeled files - Allow lvm to use docker semaphores - Setup transitons for .xsessions-errors.old - Change labels of files in /var/lib/*/.ssh to transition properly - Allow staff_t and user_t to look at logs using journalctl - pluto wants to manage own log file - Allow pluto running as ipsec_t to create pluto.log - Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Allow dmidecode to read/write /run/lock/subsys/rhsmcertd - Allow rhsmcertd to manage redhat.repo which is now labeled as system.conf. Allow rhsmcertd to manage all log files. - Additional access for docker - Added more rules to sblim policy - Fix kdumpgui_run_bootloader boolean - Allow dspam to connect to lmtp port - Included sfcbd service into sblim policy - rhsmcertd wants to manaage /etc/pki/consumer dir - Add kdumpgui_run_bootloader boolean - Add support for /var/cache/watchdog - Remove virt_domain attribute for virt_qemu_ga_unconfined_t - Fixes for handling libvirt containes - Dontaudit attempts by mysql_safe to write content into / - Dontaudit attempts by system_mail to modify network config - Allow dspam to bind to lmtp ports - Add new policy to allow staff_t and user_t to look at logs using journalctl - Allow apache cgi scripts to list sysfs - Dontaudit attempts to write/delete user_tmp_t files - Allow all antivirus domains to manage also own log dirs - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Add missing permission checks for nscd- Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Add file transition rules for content created by f5link - Rename quantum_port information to neutron - Allow all antivirus domains to manage also own log dirs - Rename quantum_port information to neutron - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Allow sysadm_t to read login information - Allow systemd_tmpfiles to setattr on var_log_t directories - Udpdate Makefile to include systemd_contexts - Add systemd_contexts - Add fs_exec_hugetlbfs_files() interface - Add daemons_enable_cluster_mode boolean - Fix rsync_filetrans_named_content() - Add rhcs_read_cluster_pid_files() interface - Update rhcs.if with additional interfaces from RHEL6 - Fix rhcs_domain_template() to not create run dirs with cluster_var_run_t - Allow glusterd_t to mounton glusterd_tmp_t - Allow glusterd to unmout al filesystems - Allow xenstored to read virt config - Add label for swift_server.lock and make add filetrans_named_content to make sure content gets created with the correct label - Allow mozilla_plugin_t to mmap hugepages as an executable- Add back userdom_security_admin_template() interface and use it for sysadm_t if sysadm_secadm.pp- Allow sshd_t to read openshift content, needs backport to RHEL6.5 - Label /usr/lib64/sasl2/libsasldb.so.3.0.0 as textrel_shlib_t - Make sur kdump lock is created with correct label if kdumpctl is executed - gnome interface calls should always be made within an optional_block - Allow syslogd_t to connect to the syslog_tls port - Add labeling for /var/run/charon.ctl socket - Add kdump_filetrans_named_content() - Allo setpgid for fenced_t - Allow setpgid and r/w cluster tmpfs for fenced_t - gnome calls should always be within optional blocks - wicd.pid should be labeled as networkmanager_var_run_t - Allow sys_resource for lldpad- Add rtas policy- Allow mailserver_domains to manage and transition to mailman data - Dontaudit attempts by mozilla plugin to relabel content, caused by using mv and cp commands - Allow mailserver_domains to manage and transition to mailman data - Allow svirt_domains to read sysctl_net_t - Allow thumb_t to use tmpfs inherited from the user - Allow mozilla_plugin to bind to the vnc port if running with spice - Add new attribute to discover confined_admins and assign confined admin to it - Fix zabbix to handle attributes in interfaces - Fix zabbix to read system states for all zabbix domains - Fix piranha_domain_template() - Allow ctdbd to create udp_socket. Allow ndmbd to access ctdbd var files. - Allow lldpad sys_rouserce cap due to #986870 - Allow dovecot-auth to read nologin - Allow openlmi-networking to read /proc/net/dev - Allow smsd_t to execute scripts created on the fly labeled as smsd_spool_t - Add zabbix_domain attribute for zabbix domains to treat them together - Add labels for zabbix-poxy-* (#1018221) - Update openlmi-storage policy to reflect #1015067 - Back port piranha tmpfs fixes from RHEL6 - Update httpd_can_sendmail boolean to allow read/write postfix spool maildrop - Add postfix_rw_spool_maildrop_files interface - Call new userdom_admin_user_templat() also for sysadm_secadm.pp - Fix typo in userdom_admin_user_template() - Allow SELinux users to create coolkeypk11sE-Gate in /var/cache/coolkey - Add new attribute to discover confined_admins - Fix labeling for /etc/strongswan/ipsec.d - systemd_logind seems to pass fd to anyone who dbus communicates with it - Dontaudit leaked write descriptor to dmesg- Activate motion policy- Fix gnome_read_generic_data_home_files() - allow openshift_cgroup_t to read/write inherited openshift file types - Remove httpd_cobbler_content * from cobbler_admin interface - Allow svirt sandbox domains to setattr on chr_file and blk_file svirt_sandbox_file_t, so sshd will work within a container - Allow httpd_t to read also git sys content symlinks - Allow init_t to read gnome home data - Dontaudit setroubleshoot_fixit_t execmem, since it does not seem to really need it. - Allow virsh to execute systemctl - Fix for nagios_services plugins - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - Fix hypervkvp.te - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Fix logging policy - Allow syslog to bind to tls ports - Update labeling for /dev/cdc-wdm - Allow to su_domain to read init states - Allow init_t to read gnome home data - Make sure if systemd_logind creates nologin file with the correct label - Clean up ipsec.te- Add auth_exec_chkpwd interface - Fix port definition for ctdb ports - Allow systemd domains to read /dev/urand - Dontaudit attempts for mozilla_plugin to append to /dev/random - Add label for /var/run/charon.* - Add labeling for /usr/lib/systemd/system/lvm2.*dd policy for motion service - Fix for nagios_services plugins - Fix some bugs in zoneminder policy - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - glusterd binds to random unreserved ports - Additional allow rules found by testing glusterfs - apcupsd needs to send a message to all users on the system so needs to look them up - Fix the label on ~/.juniper_networks - Dontaudit attempts for mozilla_plugin to append to /dev/random - Allow polipo_daemon to connect to flash ports - Allow gssproxy_t to create replay caches - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type- init reload from systemd_localed_t - Allow domains that communicate with systemd_logind_sessions to use systemd_logind_t fd - Allow systemd_localed_t to ask systemd to reload the locale. - Add systemd_runtime_unit_file_t type for unit files that systemd creates in memory - Allow readahead to read /dev/urand - Fix lots of avcs about tuned - Any file names xenstored in /var/log should be treated as xenstored_var_log_t - Allow tuned to inderact with hugepages - Allow condor domains to list etc rw dirs- Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Add additional fixes forpegasus_openlmi_account_t - Allow mdadm to read /dev/urand - Allow pegasus_openlmi_storage_t to create mdadm.conf and write it - Add label/rules for /etc/mdadm.conf - Allow pegasus_openlmi_storage_t to transition to fsadm_t - Fixes for interface definition problems - Dontaudit dovecot-deliver to gettatr on all fs dirs - Allow domains to search data_home_t directories - Allow cobblerd to connect to mysql - Allow mdadm to r/w kdump lock files - Add support for kdump lock files - Label zarafa-search as zarafa-indexer - Openshift cgroup wants to read /etc/passwd - Add new sandbox domains for kvm - Allow mpd to interact with pulseaudio if mpd_enable_homedirs is turned on - Fix labeling for /usr/lib/systemd/system/lvm2.* - Add labeling for /usr/lib/systemd/system/lvm2.* - Fix typos to get a new build. We should not cover filename trans rules to prevent duplicate rules - Add sshd_keygen_t policy for sshd-keygen - Fix alsa_home_filetrans interface name and definition - Allow chown for ssh_keygen_t - Add fs_dontaudit_getattr_all_dirs() - Allow init_t to manage etc_aliases_t and read xserver_var_lib_t and chrony keys - Fix up patch to allow systemd to manage home content - Allow domains to send/recv unlabeled traffic if unlabelednet.pp is enabled - Allow getty to exec hostname to get info - Add systemd_home_t for ~/.local/share/systemd directory- Fix lxc labels in config.tgz- Fix labeling for /usr/libexec/kde4/kcmdatetimehelper - Allow tuned to search all file system directories - Allow alsa_t to sys_nice, to get top performance for sound management - Add support for MySQL/PostgreSQL for amavis - Allow openvpn_t to manage openvpn_var_log_t files. - Allow dirsrv_t to create tmpfs_t directories - Allow dirsrv to create dirs in /dev/shm with dirsrv_tmpfs label - Dontaudit leaked unix_stream_sockets into gnome keyring - Allow telepathy domains to inhibit pipes on telepathy domains - Allow cloud-init to domtrans to rpm - Allow abrt daemon to manage abrt-watch tmp files - Allow abrt-upload-watcher to search /var/spool directory - Allow nsswitch domains to manage own process key - Fix labeling for mgetty.* logs - Allow systemd to dbus chat with upower - Allow ipsec to send signull to itself - Allow setgid cap for ipsec_t - Match upstream labeling- Do not build sanbox pkg on MLS- wine_tmp is no longer needed - Allow setroubleshoot to look at /proc - Allow telepathy domains to dbus with systemd logind - Fix handling of fifo files of rpm - Allow mozilla_plugin to transition to itself - Allow certwatch to write to cert_t directories - New abrt application - Allow NetworkManager to set the kernel scheduler - Make wine_domain shared by all wine domains - Allow mdadm_t to read images labeled svirt_image_t - Allow amanda to read /dev/urand - ALlow my_print_default to read /dev/urand - Allow mdadm to write to kdumpctl fifo files - Allow nslcd to send signull to itself - Allow yppasswd to read /dev/urandom - Fix zarafa_setrlimit - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add additional alias for user_tmp_t because wine_tmp_t is no longer used - More handling of ther kernel keyring required by kerberos - New privs needed for init_t when running without transition to initrc_t over bin_t, and without unconfined domain installed- Dontaudit attempts by sosreport to read shadow_t - Allow browser sandbox plugins to connect to cups to print - Add new label mpd_home_t - Label /srv/www/logs as httpd_log_t - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add labels for apache logs under miq package - Allow irc_t to use tcp sockets - fix labels in puppet.if - Allow tcsd to read utmp file - Allow openshift_cron_t to run ssh-keygen in ssh_keygen_t to access host keys - Define svirt_socket_t as a domain_type - Take away transition from init_t to initrc_t when executing bin_t, allow init_t to run chk_passwd_t - Fix label on pam_krb5 helper apps- Allow ldconfig to write to kdumpctl fifo files - allow neutron to connect to amqp ports - Allow kdump_manage_crash to list the kdump_crash_t directory - Allow glance-api to connect to amqp port - Allow virt_qemu_ga_t to read meminfo - Add antivirus_home_t type for antivirus date in HOMEDIRS - Allow mpd setcap which is needed by pulseaudio - Allow smbcontrol to create content in /var/lib/samba - Allow mozilla_exec_t to be used as a entrypoint to mozilla_domtrans_spec - Add additional labeling for qemu-ga/fsfreeze-hook.d scripts - amanda_exec_t needs to be executable file - Allow block_suspend cap for samba-net - Allow apps that read ipsec_mgmt_var_run_t to search ipsec_var_run_t - Allow init_t to run crash utility - Treat usr_t just like bin_t for transitions and executions - Add port definition of pka_ca to port 829 for openshift - Allow selinux_store to use symlinks- Allow block_suspend cap for samba-net - Allow t-mission-control to manage gabble cache files - Allow nslcd to read /sys/devices/system/cpu - Allow selinux_store to use symlinks- Allow xdm_t to transition to itself - Call neutron interfaces instead of quantum - Allow init to change targed role to make uncofined services (xrdp which now has own systemd unit file) working. We want them to have in unconfined_t - Make sure directories in /run get created with the correct label - Make sure /root/.pki gets created with the right label - try to remove labeling for motion from zoneminder_exec_t to bin_t - Allow inetd_t to execute shell scripts - Allow cloud-init to read all domainstate - Fix to use quantum port - Add interface netowrkmanager_initrc_domtrans - Fix boinc_execmem - Allow t-mission-control to read gabble cache home - Add labeling for ~/.cache/telepathy/avatars/gabble - Allow memcache to read sysfs data - Cleanup antivirus policy and add additional fixes - Add boolean boinc_enable_execstack - Add support for couchdb in rabbitmq policy - Add interface couchdb_search_pid_dirs - Allow firewalld to read NM state - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files()- Split out rlogin ports from inetd - Treat files labeld as usr_t like bin_t when it comes to transitions - Allow staff_t to read login config - Allow ipsec_t to read .google authenticator data - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files() - Call the correct interface - corenet_udp_bind_ktalkd_port() - Allow all domains that can read gnome_config to read kde config - Allow sandbox domain to read/write mozilla_plugin_tmpfs_t so pulseaudio will work - Allow mdadm to getattr any file system - Allow a confined domain to executes mozilla_exec_t via dbus - Allow cupsd_lpd_t to bind to the printer port - Dontaudit attempts to bind to ports < 1024 when nis is turned on - Allow apache domain to connect to gssproxy socket - Allow rlogind to bind to the rlogin_port - Allow telnetd to bind to the telnetd_port - Allow ktalkd to bind to the ktalkd_port - Allow cvs to bind to the cvs_port- Cleanup related to init_domain()+inetd_domain fixes - Use just init_domain instead of init_daemon_domain in inetd_core_service_domain - svirt domains neeed to create kobject_uevint_sockets - Lots of new access required for sosreport - Allow tgtd_t to connect to isns ports - Allow init_t to transition to all inetd domains: - openct needs to be able to create netlink_object_uevent_sockets - Dontaudit leaks into ldconfig_t - Dontaudit su domains getattr on /dev devices, move su domains to attribute based calls - Move kernel_stream_connect into all Xwindow using users - Dontaudit inherited lock files in ifconfig o dhcpc_t- Also sock_file trans rule is needed in lsm - Fix labeling for fetchmail pid files/dirs - Add additional fixes for abrt-upload-watch - Fix polipo.te - Fix transition rules in asterisk policy - Add fowner capability to networkmanager policy - Allow polipo to connect to tor ports - Cleanup lsmd.if - Cleanup openhpid policy - Fix kdump_read_crash() interface - Make more domains as init domain - Fix cupsd.te - Fix requires in rpm_rw_script_inherited_pipes - Fix interfaces in lsm.if - Allow munin service plugins to manage own tmpfs files/dirs - Allow virtd_t also relabel unix stream sockets for virt_image_type - Make ktalk as init domain - Fix to define ktalkd_unit_file_t correctly - Fix ktalk.fc - Add systemd support for talk-server - Allow glusterd to create sock_file in /run - Allow xdm_t to delete gkeyringd_tmp_t files on logout - Add fixes for hypervkvp policy - Add logwatch_can_sendmail boolean - Allow mysqld_safe_t to handle also symlinks in /var/log/mariadb - Allow xdm_t to delete gkeyringd_tmp_t files on logout- Add selinux-policy-sandbox pkg0 - Allow rhsmcertd to read init state - Allow fsetid for pkcsslotd - Fix labeling for /usr/lib/systemd/system/pkcsslotd.service - Allow fetchmail to create own pid with correct labeling - Fix rhcs_domain_template() - Allow roles which can run mock to read mock lib files to view results - Allow rpcbind to use nsswitch - Fix lsm.if summary - Fix collectd_t can read /etc/passwd file - Label systemd unit files under dracut correctly - Add support for pam_mount to mount user's encrypted home When a user logs in and logs out using ssh - Add support for .Xauthority-n - Label umount.crypt as lvm_exec_t - Allow syslogd to search psad lib files - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files- Add policy for lsmd - Add support for /var/log/mariadb dir and allow mysqld_safe to list this directory - Update condor_master rules to allow read system state info and allow logging - Add labeling for /etc/condor and allow condor domain to write it (bug) - Allow condor domains to manage own logs - Allow glusterd to read domains state - Fix initial hypervkvp policy - Add policy for hypervkvpd - Fix redis.if summary- Allow boinc to connect to @/tmp/.X11-unix/X0 - Allow beam.smp to connect to tcp/5984 - Allow named to manage own log files - Add label for /usr/libexec/dcc/start-dccifd and domtrans to dccifd_t - Add virt_transition_userdomain boolean decl - Allow httpd_t to sendto unix_dgram sockets on its children - Allow nova domains to execute ifconfig - bluetooth wants to create fifo_files in /tmp - exim needs to be able to manage mailman data - Allow sysstat to getattr on all file systems - Looks like bluetoothd has moved - Allow collectd to send ping packets - Allow svirt_lxc domains to getpgid - Remove virt-sandbox-service labeling as virsh_exec_t, since it no longer does virsh_t stuff - Allow frpintd_t to read /dev/urandom - Allow asterisk_t to create sock_file in /var/run - Allow usbmuxd to use netlink_kobject - sosreport needs to getattr on lots of devices, and needs access to netlink_kobject_uevent_socket - More cleanup of svirt_lxc policy - virtd_lxc_t now talks to dbus - Dontaudit leaked ptmx_t - Allow processes to use inherited fifo files - Allow openvpn_t to connect to squid ports - Allow prelink_cron_system_t to ask systemd to reloaddd miscfiles_dontaudit_access_check_cert() - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files - Allow user roles to connect to the journal socket- selinux_set_enforce_mode needs to be used with type - Add append to the dontaudit for unix_stream_socket of xdm_t leak - Allow xdm_t to create symlinks in log direcotries - Allow login programs to read afs config - Label 10933 as a pop port, for dovecot - New policy to allow selinux_server.py to run as semanage_t as a dbus service - Add fixes to make netlabelctl working on MLS - AVCs required for running sepolicy gui as staff_t - Dontaudit attempts to read symlinks, sepolicy gui is likely to cause this type of AVC - New dbus server to be used with new gui - After modifying some files in /etc/mail, I saw this needed on the next boot - Loading a vm from /usr/tmp with virt-manager - Clean up oracleasm policy for Fedora - Add oracleasm policy written by rlopez@redhat.com - Make postfix_postdrop_t as mta_agent to allow domtrans to system mail if it is executed by apache - Add label for /var/crash - Allow fenced to domtrans to sanclok_t - Allow nagios to manage nagios spool files - Make tfptd as home_manager - Allow kdump to read kcore on MLS system - Allow mysqld-safe sys_nice/sys_resource caps - Allow apache to search automount tmp dirs if http_use_nfs is enabled - Allow crond to transition to named_t, for use with unbound - Allow crond to look at named_conf_t, for unbound - Allow mozilla_plugin_t to transition its home content - Allow dovecot_domain to read all system and network state - Allow httpd_user_script_t to call getpw - Allow semanage to read pid files - Dontaudit leaked file descriptors from user domain into thumb - Make PAM authentication working if it is enabled in ejabberd - Add fixes for rabbit to fix ##992920,#992931 - Allow glusterd to mount filesystems - Loading a vm from /usr/tmp with virt-manager - Trying to load a VM I got an AVC from devicekit_disk for loopcontrol device - Add fix for pand service - shorewall touches own log - Allow nrpe to list /var - Mozilla_plugin_roles can not be passed into lpd_run_lpr - Allow afs domains to read afs_config files - Allow login programs to read afs config - Allow virt_domain to read virt_var_run_t symlinks - Allow smokeping to send its process signals - Allow fetchmail to setuid - Add kdump_manage_crash() interface - Allow abrt domain to write abrt.socket- Add more aliases in pegasus.te - Add more fixes for *_admin interfaces - Add interface fixes - Allow nscd to stream connect to nmbd - Allow gnupg apps to write to pcscd socket - Add more fixes for openlmi provides. Fix naming and support for additionals - Allow fetchmail to resolve host names - Allow firewalld to interact also with lnk files labeled as firewalld_etc_rw_t - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te - Fix corecmd_exec_chroot() - Fix logging_relabel_syslog_pid_socket interface - Fix typo in unconfineduser.te - Allow system_r to access unconfined_dbusd_t to run hp_chec- Allow xdm_t to act as a dbus client to itsel - Allow fetchmail to resolve host names - Allow gnupg apps to write to pcscd socket - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te -httpd_t does access_check on certs- Add support for cmpiLMI_Service-cimprovagt - Allow pegasus domtrans to rpm_t to make pycmpiLMI_Software-cimprovagt running as rpm_t - Label pycmpiLMI_Software-cimprovagt as rpm_exec_t - Add support for pycmpiLMI_Storage-cimprovagt - Add support for cmpiLMI_Networking-cimprovagt - Allow system_cronjob_t to create user_tmpfs_t to make pulseaudio working - Allow virtual machines and containers to run as user doains, needed for virt-sandbox - Allow buglist.cgi to read cpu info- Allow systemd-tmpfile to handle tmp content in print spool dir - Allow systemd-sysctl to send system log messages - Add support for RTP media ports and fmpro-internal - Make auditd working if audit is configured to perform SINGLE action on disk error - Add interfaces to handle systemd units - Make systemd-notify working if pcsd is used - Add support for netlabel and label /usr/sbin/netlabelctl as iptables_exec_t - Instead of having all unconfined domains get all of the named transition rules, - Only allow unconfined_t, init_t, initrc_t and rpm_script_t by default. - Add definition for the salt ports - Allow xdm_t to create link files in xdm_var_run_t - Dontaudit reads of blk files or chr files leaked into ldconfig_t - Allow sys_chroot for useradd_t - Allow net_raw cap for ipsec_t - Allow sysadm_t to reload services - Add additional fixes to make strongswan working with a simple conf - Allow sysadm_t to enable/disable init_t services - Add additional glusterd perms - Allow apache to read lnk files in the /mnt directory - Allow glusterd to ask the kernel to load a module - Fix description of ftpd_use_fusefs boolean - Allow svirt_lxc_net_t to sys_chroot, modify policy to tighten up svirt_lxc_domain capabilties and process controls, but add them to svirt_lxc_net_t - Allow glusterds to request load a kernel module - Allow boinc to stream connect to xserver_t - Allow sblim domains to read /etc/passwd - Allow mdadm to read usb devices - Allow collectd to use ping plugin - Make foghorn working with SNMP - Allow sssd to read ldap certs - Allow haproxy to connect to RTP media ports - Add additional trans rules for aide_db - Add labeling for /usr/lib/pcsd/pcsd - Add labeling for /var/log/pcsd - Add support for pcs which is a corosync and pacemaker configuration tool- Label /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t - Add labeling for /usr/libexec/kde4/polkit-kde-authentication-agent-1 - Allow all domains that can domtrans to shutdown, to start the power services script to shutdown - consolekit needs to be able to shut down system - Move around interfaces - Remove nfsd_rw_t and nfsd_ro_t, they don't do anything - Add additional fixes for rabbitmq_beam to allow getattr on mountpoints - Allow gconf-defaults-m to read /etc/passwd - Fix pki_rw_tomcat_cert() interface to support lnk_files- Add support for gluster ports - Make sure that all keys located in /etc/ssh/ are labeled correctly - Make sure apcuspd lock files get created with the correct label - Use getcap in gluster.te - Fix gluster policy - add additional fixes to allow beam.smp to interact with couchdb files - Additional fix for #974149 - Allow gluster to user gluster ports - Allow glusterd to transition to rpcd_t and add additional fixes for #980683 - Allow tgtd working when accessing to the passthrough device - Fix labeling for mdadm unit files- Add mdadm fixes- Fix definition of sandbox.disabled to sandbox.pp.disabled- Allow mdamd to execute systemctl - Allow mdadm to read /dev/kvm - Allow ipsec_mgmt_t to read l2tpd pid content- Allow nsd_t to read /dev/urand - Allow mdadm_t to read framebuffer - Allow rabbitmq_beam_t to read process info on rabbitmq_epmd_t - Allow mozilla_plugin_config_t to create tmp files - Cleanup openvswitch policy - Allow mozilla plugin to getattr on all executables - Allow l2tpd_t to create fifo_files in /var/run - Allow samba to touch/manage fifo_files or sock_files in a samba_share_t directory - Allow mdadm to connecto its own unix_stream_socket - FIXME: nagios changed locations to /log/nagios which is wrong. But we need to have this workaround for now. - Allow apache to access smokeping pid files - Allow rabbitmq_beam_t to getattr on all filesystems - Add systemd support for iodined - Allow nup_upsdrvctl_t to execute its entrypoint - Allow fail2ban_client to write to fail2ban_var_run_t, Also allow it to use nsswitch - add labeling for ~/.cache/libvirt-sandbox - Add interface to allow domains transitioned to by confined users to send sigchld to screen program - Allow sysadm_t to check the system status of files labeled etc_t, /etc/fstab - Allow systemd_localed to start /usr/lib/systemd/system/systemd-vconsole-setup.service - Allow an domain that has an entrypoint from a type to be allowed to execute the entrypoint without a transition, I can see no case where this is a bad thing, and elminiates a whole class of AVCs. - Allow staff to getsched all domains, required to run htop - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Add prosody policy written by Michael Scherer - Allow nagios plugins to read /sys info - ntpd needs to manage own log files - Add support for HOME_DIR/.IBMERS - Allow iptables commands to read firewalld config - Allow consolekit_t to read utmp - Fix filename transitions on .razor directory - Add additional fixes to make DSPAM with LDA working - Allow snort to read /etc/passwd - Allow fail2ban to communicate with firewalld over dbus - Dontaudit openshift_cgreoup_file_t read/write leaked dev - Allow nfsd to use mountd port - Call th proper interface - Allow openvswitch to read sys and execute plymouth - Allow tmpwatch to read /var/spool/cups/tmp - Add support for /usr/libexec/telepathy-rakia - Add systemd support for zoneminder - Allow mysql to create files/directories under /var/log/mysql - Allow zoneminder apache scripts to rw zoneminder tmpfs - Allow httpd to manage zoneminder lib files - Add zoneminder_run_sudo boolean to allow to start zoneminder - Allow zoneminder to send mails - gssproxy_t sock_file can be under /var/lib - Allow web domains to connect to whois port. - Allow sandbox_web_type to connect to the same ports as mozilla_plugin_t. - We really need to add an interface to corenet to define what a web_client_domain is and - then define chrome_sandbox_t, mozilla_plugin_t and sandbox_web_type to that domain. - Add labeling for cmpiLMI_LogicalFile-cimprovagt - Also make pegasus_openlmi_logicalfile_t as unconfined to have unconfined_domain attribute for filename trans rules - Update policy rules for pegasus_openlmi_logicalfile_t - Add initial types for logicalfile/unconfined OpenLMI providers - mailmanctl needs to read own log - Allow logwatch manage own lock files - Allow nrpe to read meminfo - Allow httpd to read certs located in pki-ca - Add pki_read_tomcat_cert() interface - Add support for nagios openshift plugins - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Shrink the size of policy by moving to attributes, also add dridomain so that mozilla_plugin can follow selinuxuse_dri boolean. - Allow bootloader to manage generic log files - Allow ftp to bind to port 989 - Fix label of new gear directory - Add support for new directory /var/lib/openshift/gears/ - Add openshift_manage_lib_dirs() - allow virtd domains to manage setrans_var_run_t - Allow useradd to manage all openshift content - Add support so that mozilla_plugin_t can use dri devices - Allow chronyd to change the scheduler - Allow apmd to shut downthe system - Devicekit_disk_t needs to manage /etc/fstab- Make DSPAM to act as a LDA working - Allow ntop to create netlink socket - Allow policykit to send a signal to policykit-auth - Allow stapserver to dbus chat with avahi/systemd-logind - Fix labeling on haproxy unit file - Clean up haproxy policy - A new policy for haproxy and placed it to rhcs.te - Add support for ldirectord and treat it with cluster_t - Make sure anaconda log dir is created with var_log_t- Allow lvm_t to create default targets for filesystem handling - Fix labeling for razor-lightdm binaries - Allow insmod_t to read any file labeled var_lib_t - Add policy for pesign - Activate policy for cmpiLMI_Account-cimprovagt - Allow isnsd syscall=listen - /usr/libexec/pegasus/cimprovagt needs setsched caused by sched_setscheduler - Allow ctdbd to use udp/4379 - gatherd wants sys_nice and setsched - Add support for texlive2012 - Allow NM to read file_t (usb stick with no labels used to transfer keys for example) - Allow cobbler to execute apache with domain transition- condor_collector uses tcp/9000 - Label /usr/sbin/virtlockd as virtd_exec_t for now - Allow cobbler to execute ldconfig - Allow NM to execute ssh - Allow mdadm to read /dev/crash - Allow antivirus domains to connect to snmp port - Make amavisd-snmp working correctly - Allow nfsd_t to mounton nfsd_fs_t - Add initial snapper policy - We still need to have consolekit policy - Dontaudit firefox attempting to connect to the xserver_port_t if run within sandbox_web_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow dirsrv to read network state - Fix pki_read_tomcat_lib_files - Add labeling for /usr/libexec/nm-ssh-service - Add label cert_t for /var/lib/ipa/pki-ca/publish - Lets label /sys/fs/cgroup as cgroup_t for now, to keep labels consistant - Allow nfsd_t to mounton nfsd_fs_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow passwd_t to change role to system_r from unconfined_r- Don't audit access checks by sandbox xserver on xdb var_lib - Allow ntop to read usbmon devices - Add labeling for new polcykit authorizor - Dontaudit access checks from fail2ban_client - Don't audit access checks by sandbox xserver on xdb var_lib - Allow apps that connect to xdm stream to conenct to xdm_dbusd_t stream - Fix labeling for all /usr/bim/razor-lightdm-* binaries - Add filename trans for /dev/md126p1- Make vdagent able to request loading kernel module - Add support for cloud-init make it as unconfined domain - Allow snmpd to run smartctl in fsadm_t domain - remove duplicate openshift_search_lib() interface - Allow mysqld to search openshift lib files - Allow openshift cgroup to interact with passedin file descriptors - Allow colord to list directories inthe users homedir - aide executes prelink to check files - Make sure cupsd_t creates content in /etc/cups with the correct label - Lest dontaudit apache read all domains, so passenger will not cause this avc - Allow gssd to connect to gssproxy - systemd-tmpfiles needs to be able to raise the level to fix labeling on /run/setrans in MLS - Allow systemd-tmpfiles to relabel also lock files - Allow useradd to add homdir in /var/lib/openshift - Allow setfiles and semanage to write output to /run/files- Add labeling for /dev/tgt - Dontaudit leak fd from firewalld for modprobe - Allow runuser running as rpm_script_t to create netlink_audit socket - Allow mdadm to read BIOS non-volatile RAM- accountservice watches when accounts come and go in wtmp - /usr/java/jre1.7.0_21/bin/java needs to create netlink socket - Add httpd_use_sasl boolean - Allow net_admin for tuned_t - iscsid needs sys_module to auto-load kernel modules - Allow blueman to read bluetooth conf - Add nova_manage_lib_files() interface - Fix mplayer_filetrans_home_content() - Add mplayer_filetrans_home_content() - mozilla_plugin_config_roles need to be able to access mozilla_plugin_config_t - Revert "Allow thumb_t to append inherited xdm stream socket" - Add iscsi_filetrans_named_content() interface - Allow to create .mplayer with the correct labeling for unconfined - Allow iscsiadmin to create lock file with the correct labeling- Allow wine to manage wine home content - Make amanda working with socket actiovation - Add labeling for /usr/sbin/iscsiadm - Add support for /var/run/gssproxy.sock - dnsmasq_t needs to read sysctl_net_t- Fix courier_domain_template() interface - Allow blueman to write ip_forward - Allow mongodb to connect to mongodb port - Allow mongodb to connect to mongodb port - Allow java to bind jobss_debug port - Fixes for *_admin interfaces - Allow iscsid auto-load kernel modules needed for proper iSCSI functionality - Need to assign attribute for courier_domain to all courier_domains - Fail2ban reads /etc/passwd - postfix_virtual will create new files in postfix_spool_t - abrt triggers sys_ptrace by running pidof - Label ~/abc as mozilla_home_t, since java apps as plugin want to create it - Add passenger fixes needed by foreman - Remove dup interfaces - Add additional interfaces for quantum - Add new interfaces for dnsmasq - Allow passenger to read localization and send signull to itself - Allow dnsmasq to stream connect to quantum - Add quantum_stream_connect() - Make sure that mcollective starts the service with the correct labeling - Add labels for ~/.manpath - Dontaudit attempts by svirt_t to getpw* calls - sandbox domains are trying to look at parent process data - Allow courior auth to create its pid file in /var/spool/courier subdir - Add fixes for beam to have it working with couchdb - Add labeling for /run/nm-xl2tpd.con - Allow apache to stream connect to thin - Add systemd support for amand - Make public types usable for fs mount points - Call correct mandb interface in domain.te - Allow iptables to r/w quantum inherited pipes and send sigchld - Allow ifconfig domtrans to iptables and execute ldconfig - Add labels for ~/.manpath - Allow systemd to read iscsi lib files - seunshare is trying to look at parent process data- Fix openshift_search_lib - Add support for abrt-uefioops-oops - Allow colord to getattr any file system - Allow chrome processes to look at each other - Allow sys_ptrace for abrt_t - Add new policy for gssproxy - Dontaudit leaked file descriptor writes from firewalld - openshift_net_type is interface not template - Dontaudit pppd to search gnome config - Update openshift_search_lib() interface - Add fs_list_pstorefs() - Fix label on libbcm_host.so since it is built incorrectly on raspberry pi, needs back port to F18 - Better labels for raspberry pi devices - Allow init to create devpts_t directory - Temporarily label rasbery pi devices as memory_device_t, needs back port to f18 - Allow sysadm_t to build kernels - Make sure mount creates /var/run/blkid with the correct label, needs back port to F18 - Allow userdomains to stream connect to gssproxy - Dontaudit leaked file descriptor writes from firewalld - Allow xserver to read /dev/urandom - Add additional fixes for ipsec-mgmt - Make SSHing into an Openshift Enterprise Node working- Add transition rules to unconfined domains and to sysadm_t to create /etc/adjtime - with the proper label. - Update files_filetrans_named_content() interface to get right labeling for pam.d conf files - Allow systemd-timedated to create adjtime - Add clock_create_adjtime() - Additional fix ifconfing for #966106 - Allow kernel_t to create boot.log with correct labeling - Remove unconfined_mplayer for which we don't have rules - Rename interfaces - Add userdom_manage_user_home_files/dirs interfaces - Fix files_dontaudit_read_all_non_security_files - Fix ipsec_manage_key_file() - Fix ipsec_filetrans_key_file() - Label /usr/bin/razor-lightdm-greeter as xdm_exec_t instead of spamc_exec_t - Fix labeling for ipse.secrets - Add interfaces for ipsec and labeling for ipsec.info and ipsec_setup.pid - Add files_dontaudit_read_all_non_security_files() interface - /var/log/syslog-ng should be labeled var_log_t - Make ifconfig_var_run_t a mountpoint - Add transition from ifconfig to dnsmasq - Allow ifconfig to execute bin_t/shell_exec_t - We want to have hwdb.bin labeled as etc_t - update logging_filetrans_named_content() interface - Allow systemd_timedate_t to manage /etc/adjtime - Allow NM to send signals to l2tpd - Update antivirus_can_scan_system boolean - Allow devicekit_disk_t to sys_config_tty - Run abrt-harvest programs as abrt_t, and allow abrt_t to list all filesystem directories - Make printing from vmware working - Allow php-cgi from php54 collection to access /var/lib/net-snmp/mib_indexes - Add virt_qemu_ga_data_t for qemu-ga - Make chrome and mozilla able to connect to same ports, add jboss_management_port_t to both - Fix typo in virt.te - Add virt_qemu_ga_unconfined_t for hook scripts - Make sure NetworkManager files get created with the correct label - Add mozilla_plugin_use_gps boolean - Fix cyrus to have support for net-snmp - Additional fixes for dnsmasq and quantum for #966106 - Add plymouthd_create_log() - remove httpd_use_oddjob for which we don't have rules - Add missing rules for httpd_can_network_connect_cobbler - Add missing cluster_use_execmem boolean - Call userdom_manage_all_user_home_type_files/dirs - Additional fix for ftp_home_dir - Fix ftp_home_dir boolean - Allow squit to recv/send client squid packet - Fix nut.te to have nut_domain attribute - Add support for ejabberd; TODO: revisit jabberd and rabbit policy - Fix amanda policy - Add more fixes for domains which use libusb - Make domains which use libusb working correctly - Allow l2tpd to create ipsec key files with correct labeling and manage them - Fix cobbler_manage_lib_files/cobbler_read_lib_files to cover also lnk files - Allow rabbitmq-beam to bind generic node - Allow l2tpd to read ipse-mgmt pid files - more fixes for l2tpd, NM and pppd from #967072- Dontaudit to getattr on dirs for dovecot-deliver - Allow raiudusd server connect to postgresql socket - Add kerberos support for radiusd - Allow saslauthd to connect to ldap port - Allow postfix to manage postfix_private_t files - Add chronyd support for #965457 - Fix labeling for HOME_DIR/\.icedtea - CHange squid and snmpd to be allowed also write own logs - Fix labeling for /usr/libexec/qemu-ga - Allow virtd_t to use virt_lock_t - Allow also sealert to read the policy from the kernel - qemu-ga needs to execute scripts in /usr/libexec/qemu-ga and to use /tmp content - Dontaudit listing of users homedir by sendmail Seems like a leak - Allow passenger to transition to puppet master - Allow apache to connect to mythtv - Add definition for mythtv ports- Add additional fixes for #948073 bug - Allow sge_execd_t to also connect to sge ports - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow sge_execd to bind sge ports. Allow kill capability and reads cgroup files - Remove pulseaudio filetrans pulseaudio_manage_home_dirs which is a part of pulseaudio_manage_home_files - Add networkmanager_stream_connect() - Make gnome-abrt wokring with staff_t - Fix openshift_manage_lib_files() interface - mdadm runs ps command which seems to getattr on random log files - Allow mozilla_plugin_t to create pulseaudit_home_t directories - Allow qemu-ga to shutdown virtual hosts - Add labelling for cupsd-browsed - Add web browser plugins to connect to aol ports - Allow nm-dhcp-helper to stream connect to NM - Add port definition for sge ports- Make sure users and unconfined domains create .hushlogin with the correct label - Allow pegaus to chat with realmd over DBus - Allow cobblerd to read network state - Allow boicn-client to stat on /dev/input/mice - Allow certwatch to read net_config_t when it executes apache - Allow readahead to create /run/systemd and then create its own directory with the correct label- Transition directories and files when in a user_tmp_t directory - Change certwatch to domtrans to apache instead of just execute - Allow virsh_t to read xen lib files - update policy rules for pegasus_openlmi_account_t - Add support for svnserve_tmp_t - Activate account openlmi policy - pegasus_openlmi_domain_template needs also require pegasus_t - One more fix for policykit.te - Call fs_list_cgroups_dirs() in policykit.te - Allow nagios service plugin to read mysql config files - Add labeling for /var/svn - Fix chrome.te - Fix pegasus_openlmi_domain_template() interfaces - Fix dev_rw_vfio_dev definiton, allow virtd_t to read tmpfs_t symlinks - Fix location of google-chrome data - Add support for chome_sandbox to store content in the homedir - Allow policykit to watch for changes in cgroups file system - Add boolean to allow mozilla_plugin_t to use spice - Allow collectd to bind to udp port - Allow collected_t to read all of /proc - Should use netlink socket_perms - Should use netlink socket_perms - Allow glance domains to connect to apache ports - Allow apcupsd_t to manage its log files - Allow chrome objects to rw_inherited unix_stream_socket from callers - Allow staff_t to execute virtd_exec_t for running vms - nfsd_t needs to bind mountd port to make nfs-mountd.service working - Allow unbound net_admin capability because of setsockopt syscall - Fix fs_list_cgroup_dirs() - Label /usr/lib/nagios/plugins/utils.pm as bin_t - Remove uplicate definition of fs_read_cgroup_files() - Remove duplicate definition of fs_read_cgroup_files() - Add files_mountpoint_filetrans interface to be used by quotadb_t and snapperd - Additional interfaces needed to list and read cgroups config - Add port definition for collectd port - Add labels for /dev/ptp* - Allow staff_t to execute virtd_exec_t for running vms- Allow samba-net to also read realmd tmp files - Allow NUT to use serial ports - realmd can be started by systemctl now- Remove userdom_home_manager for xdm_t and move all rules to xserver.te directly - Add new xdm_write_home boolean to allow xdm_t to create files in HOME dirs with xdm_home_t - Allow postfix-showq to read/write unix.showq in /var/spool/postfix/pid - Allow virsh to read xen lock file - Allow qemu-ga to create files in /run with proper labeling - Allow glusterd to connect to own socket in /tmp - Allow glance-api to connect to http port to make glance image-create working - Allow keystonte_t to execute rpm- Fix realmd cache interfaces- Allow tcpd to execute leafnode - Allow samba-net to read realmd cache files - Dontaudit sys_tty_config for alsactl - Fix allow rules for postfix_var_run - Allow cobblerd to read /etc/passwd - Allow pegasus to read exports - Allow systemd-timedate to read xdm state - Allow mout to stream connect to rpcbind - Add labeling just for /usr/share/pki/ca-trust-source instead of /usr/share/pki- Allow thumbnails to share memory with apps which run thumbnails - Allow postfix-postqueue block_suspend - Add lib interfaces for smsd - Add support for nginx - Allow s2s running as jabberd_t to connect to jabber_interserver_port_t - Allow pki apache domain to create own tmp files and execute httpd_suexec - Allow procmail to manger user tmp files/dirs/lnk_files - Add virt_stream_connect_svirt() interface - Allow dovecot-auth to execute bin_t - Allow iscsid to request that kernel load a kernel module - Add labeling support for /var/lib/mod_security - Allow iw running as tuned_t to create netlink socket - Dontaudit sys_tty_config for thumb_t - Add labeling for nm-l2tp-service - Allow httpd running as certwatch_t to open tcp socket - Allow useradd to manager smsd lib files - Allow useradd_t to add homedirs in /var/lib - Fix typo in userdomain.te - Cleanup userdom_read_home_certs - Implement userdom_home_reader_certs_type to allow read certs also on encrypt /home with ecryptfs_t - Allow staff to stream connect to svirt_t to make gnome-boxes working- Allow lvm to create its own unit files - Label /var/lib/sepolgen as selinux_config_t - Add filetrans rules for tw devices - Add transition from cupsd_config_t to cupsd_t- Add filetrans rules for tw devices - Cleanup bad transition lines- Fix lockdev_manage_files() - Allow setroubleshootd to read var_lib_t to make email_alert working - Add lockdev_manage_files() - Call proper interface in virt.te - Allow gkeyring_domain to create /var/run/UID/config/dbus file - system dbus seems to be blocking suspend - Dontaudit attemps to sys_ptrace, which I believe gpsd does not need - When you enter a container from root, you generate avcs with a leaked file descriptor - Allow mpd getattr on file system directories - Make sure realmd creates content with the correct label - Allow systemd-tty-ask to write kmsg - Allow mgetty to use lockdev library for device locking - Fix selinuxuser_user_share_music boolean name to selinuxuser_share_music - When you enter a container from root, you generate avcs with a leaked file descriptor - Make sure init.fc files are labeled correctly at creation - File name trans vconsole.conf - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow certmonger to dbus communicate with realmd - Make realmd working- Fix mozilla specification of homedir content - Allow certmonger to read network state - Allow tmpwatch to read tmp in /var/spool/{cups,lpd} - Label all nagios plugin as unconfined by default - Add httpd_serve_cobbler_files() - Allow mdadm to read /dev/sr0 and create tmp files - Allow certwatch to send mails - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow realmd to run ipa, really needs to be an unconfined_domain - Allow sandbox domains to use inherted terminals - Allow pscd to use devices labeled svirt_image_t in order to use cat cards. - Add label for new alsa pid - Alsa now uses a pid file and needs to setsched - Fix oracleasmfs_t definition - Add support for sshd_unit_file_t - Add oracleasmfs_t - Allow unlabeled_t files to be stored on unlabeled_t filesystems- Fix description of deny_ptrace boolean - Remove allow for execmod lib_t for now - Allow quantum to connect to keystone port - Allow nova-console to talk with mysql over unix stream socket - Allow dirsrv to stream connect to uuidd - thumb_t needs to be able to create ~/.cache if it does not exist - virtd needs to be able to sys_ptrace when starting and stoping containers- Allow alsa_t signal_perms, we probaly should search for any app that can execute something without transition and give it signal_perms... - Add dontaudit for mozilla_plugin_t looking at the xdm_t sockets - Fix deny_ptrace boolean, certain ptrace leaked into the system - Allow winbind to manage kerberos_rcache_host - Allow spamd to create spamd_var_lib_t directories - Remove transition to mozilla_tmp_t by mozilla_t, to allow it to manage the users tmp dirs - Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Call snmp_manage_var_lib_files(fogorn_t) instead of snmp_manage_var_dirs - Fix vmware_role() interface - Fix cobbler_manage_lib_files() interface - Allow nagios check disk plugins to execute bin_t - Allow quantum to transition to openvswitch_t - Allow postdrop to stream connect to postfix-master - Allow quantum to stream connect to openvswitch - Add xserver_dontaudit_xdm_rw_stream_sockets() interface - Allow daemon to send dgrams to initrc_t - Allow kdm to start the power service to initiate a reboot or poweroff- Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Don't audit attempts to write to stream socket of nscld by thumbnailers - Allow git_system_t to read network state - Allow pegasas to execute mount command - Fix desc for drdb_admin - Fix condor_amin() - Interface fixes for uptime, vdagent, vnstatd - Fix labeling for moodle in /var/www/moodle/data - Add interface fixes - Allow bugzilla to read certs - /var/www/moodle needs to be writable by apache - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Fix namespace_init_t to create content with proper labels, and allow it to manage all user content - Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Fix sys_nice for cups_domain - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Kernel_t needs mac_admin in order to support labeled NFS - Fix systemd_dontaudit_dbus_chat() interface - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Allow consolehelper domain to write Xauth files in /root - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Allow consolehelper more access discovered by Tom London - Allow fsdaemon to send signull to all domain - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Fix file_contexts.subs to label /run/lock correctly- Try to label on controlC devices up to 30 correctly - Add mount_rw_pid_files() interface - Add additional mount/umount interfaces needed by mock - fsadm_t sends audit messages in reads kernel_ipc_info when doing livecd-iso-to-disk - Fix tabs - Allow initrc_domain to search rgmanager lib files - Add more fixes which make mock working together with confined users * Allow mock_t to manage rpm files * Allow mock_t to read rpm log files * Allow mock to setattr on tmpfs, devpts * Allow mount/umount filesystems - Add rpm_read_log() interface - yum-cron runs rpm from within it. - Allow tuned to transition to dmidecode - Allow firewalld to do net_admin - Allow mock to unmont tmpfs_t - Fix virt_sigkill() interface - Add additional fixes for mock. Mainly caused by mount running in mock_t - Allow mock to write sysfs_t and mount pid files - Add mailman_domain to mailman_template() - Allow openvswitch to execute shell - Allow qpidd to use kerberos - Allow mailman to use fusefs, needs back port to RHEL6 - Allow apache and its scripts to use anon_inodefs - Add alias for git_user_content_t and git_sys_content_t so that RHEL6 will update to RHEL7 - Realmd needs to connect to samba ports, needs back port to F18 also - Allow colord to read /run/initial-setup- - Allow sanlock-helper to send sigkill to virtd which is registred to sanlock - Add virt_kill() interface - Add rgmanager_search_lib() interface - Allow wdmd to getattr on all filesystems. Back ported from RHEL6- Allow realmd to create tmp files - FIx ircssi_home_t type to irssi_home_t - Allow adcli running as realmd_t to connect to ldap port - Allow NetworkManager to transition to ipsec_t, for running strongswan - Make openshift_initrc_t an lxc_domain - Allow gssd to manage user_tmp_t files - Fix handling of irclogs in users homedir - Fix labeling for drupal an wp-content in subdirs of /var/www/html - Allow abrt to read utmp_t file - Fix openshift policy to transition lnk_file, sock-file an fifo_file when created in a tmpfs_t, needs back port to RHEL6 - fix labeling for (oo|rhc)-restorer-wrapper.sh - firewalld needs to be able to write to network sysctls - Fix mozilla_plugin_dontaudit_rw_sem() interface - Dontaudit generic ipc read/write to a mozilla_plugin for sandbox_x domains - Add mozilla_plugin_dontaudit_rw_sem() interface - Allow svirt_lxc_t to transition to openshift domains - Allow condor domains block_suspend and dac_override caps - Allow condor_master to read passd - Allow condor_master to read system state - Allow NetworkManager to transition to ipsec_t, for running strongswan - Lots of access required by lvm_t to created encrypted usb device - Allow xdm_t to dbus communicate with systemd_localed_t - Label strongswan content as ipsec_exec_mgmt_t for now - Allow users to dbus chat with systemd_localed - Fix handling of .xsession-errors in xserver.if, so kde will work - Might be a bug but we are seeing avc's about people status on init_t:service - Make sure we label content under /var/run/lock as <> - Allow daemon and systemprocesses to search init_var_run_t directory - Add boolean to allow xdm to write xauth data to the home directory - Allow mount to write keys for the unconfined domain - Add unconfined_write_keys() interface- Add labeling for /usr/share/pki - Allow programs that read var_run_t symlinks also read var_t symlinks - Add additional ports as mongod_port_t for 27018, 27019, 28017, 28018 and 28019 ports - Fix labeling for /etc/dhcp directory - add missing systemd_stub_unit_file() interface - Add files_stub_var() interface - Add lables for cert_t directories - Make localectl set-x11-keymap working at all - Allow abrt to manage mock build environments to catch build problems. - Allow virt_domains to setsched for running gdb on itself - Allow thumb_t to execute user home content - Allow pulseaudio running as mozilla_plugin_t to read /run/systemd/users/1000 - Allow certwatch to execut /usr/bin/httpd - Allow cgred to send signal perms to itself, needs back port to RHEL6 - Allow openshift_cron_t to look at quota - Allow cups_t to read inhered tmpfs_t from the kernel - Allow yppasswdd to use NIS - Tuned wants sys_rawio capability - Add ftpd_use_fusefs boolean - Allow dirsrvadmin_t to signal itself- Allow localectl to read /etc/X11/xorg.conf.d directory - Revert "Revert "Fix filetrans rules for kdm creates .xsession-errors"" - Allow mount to transition to systemd_passwd_agent - Make sure abrt directories are labeled correctly - Allow commands that are going to read mount pid files to search mount_var_run_t - label /usr/bin/repoquery as rpm_exec_t - Allow automount to block suspend - Add abrt_filetrans_named_content so that abrt directories get labeled correctly - Allow virt domains to setrlimit and read file_context- Allow nagios to manage nagios spool files - /var/spool/snmptt is a directory which snmdp needs to write to, needs back port to RHEL6 - Add swift_alias.* policy files which contain typealiases for swift types - Add support for /run/lock/opencryptoki - Allow pkcsslotd chown capability - Allow pkcsslotd to read passwd - Add rsync_stub() interface - Allow systemd_timedate also manage gnome config homedirs - Label /usr/lib64/security/pam_krb5/pam_krb5_cchelper as bin_t - Fix filetrans rules for kdm creates .xsession-errors - Allow sytemd_tmpfiles to create wtmp file - Really should not label content under /var/lock, since it could have labels on it different from var_lock_t - Allow systemd to list all file system directories - Add some basic stub interfaces which will be used in PRODUCT policies- Fix log transition rule for cluster domains - Start to group all cluster log together - Dont use filename transition for POkemon Advanced Adventure until a new checkpolicy update - cups uses usbtty_device_t devices - These fixes were all required to build a MLS virtual Machine with single level desktops - Allow domains to transiton using httpd_exec_t - Allow svirt domains to manage kernel key rings - Allow setroubleshoot to execute ldconfig - Allow firewalld to read generate gnome data - Allow bluetooth to read machine-info - Allow boinc domain to send signal to itself - Fix gnome_filetrans_home_content() interface - Allow mozilla_plugins to list apache modules, for use with gxine - Fix labels for POkemon in the users homedir - Allow xguest to read mdstat - Dontaudit virt_domains getattr on /dev/* - These fixes were all required to build a MLS virtual Machine with single level desktops - Need to back port this to RHEL6 for openshift - Add tcp/8891 as milter port - Allow nsswitch domains to read sssd_var_lib_t files - Allow ping to read network state. - Fix typo - Add labels to /etc/X11/xorg.d and allow systemd-timestampd_t to manage them- Adopt swift changes from lhh@redhat.com - Add rhcs_manage_cluster_pid_files() interface - Allow screen domains to configure tty and setup sock_file in ~/.screen directory - ALlow setroubleshoot to read default_context_t, needed to backport to F18 - Label /etc/owncloud as being an apache writable directory - Allow sshd to stream connect to an lxc domain- Allow postgresql to manage rgmanager pid files - Allow postgresql to read ccs data - Allow systemd_domain to send dbus messages to policykit - Add labels for /etc/hostname and /etc/machine-info and allow systemd-hostnamed to create them - All systemd domains that create content are reading the file_context file and setfscreate - Systemd domains need to search through init_var_run_t - Allow sshd to communicate with libvirt to set containers labels - Add interface to manage pid files - Allow NetworkManger_t to read /etc/hostname - Dontaudit leaked locked files into openshift_domains - Add fixes for oo-cgroup-read - it nows creates tmp files - Allow gluster to manage all directories as well as files - Dontaudit chrome_sandbox_nacl_t using user terminals - Allow sysstat to manage its own log files - Allow virtual machines to setrlimit and send itself signals. - Add labeling for /var/run/hplip- Fix POSTIN scriptlet- Merge rgmanger, corosync,pacemaker,aisexec policies to cluster_t in rhcs.pp- Fix authconfig.py labeling - Make any domains that write homedir content do it correctly - Allow glusterd to read/write anyhwere on the file system by default - Be a little more liberal with the rsync log files - Fix iscsi_admin interface - Allow iscsid_t to read /dev/urand - Fix up iscsi domain for use with unit files - Add filename transition support for spamassassin policy - Allow web plugins to use badly formated libraries - Allow nmbd_t to create samba_var_t directories - Add filename transition support for spamassassin policy - Add filename transition support for tvtime - Fix alsa_home_filetrans_alsa_home() interface - Move all userdom_filetrans_home_content() calling out of booleans - Allow logrotote to getattr on all file sytems - Remove duplicate userdom_filetrans_home_content() calling - Allow kadmind to read /etc/passwd - Dontaudit append .xsession-errors file on ecryptfs for policykit-auth - Allow antivirus domain to manage antivirus db links - Allow logrotate to read /sys - Allow mandb to setattr on man dirs - Remove mozilla_plugin_enable_homedirs boolean - Fix ftp_home_dir boolean - homedir mozilla filetrans has been moved to userdom_home_manager - homedir telepathy filetrans has been moved to userdom_home_manager - Remove gnome_home_dir_filetrans() from gnome_role_gkeyringd() - Might want to eventually write a daemon on fusefsd. - Add policy fixes for sshd [net] child from plautrba@redhat.com - Tor uses a new port - Remove bin_t for authconfig.py - Fix so only one call to userdom_home_file_trans - Allow home_manager_types to create content with the correctl label - Fix all domains that write data into the homedir to do it with the correct label - Change the postgresql to use proper boolean names, which is causing httpd_t to - not get access to postgresql_var_run_t - Hostname needs to send syslog messages - Localectl needs to be able to send dbus signals to users - Make sure userdom_filetrans_type will create files/dirs with user_home_t labeling by default - Allow user_home_manger domains to create spam* homedir content with correct labeling - Allow user_home_manger domains to create HOMEDIR/.tvtime with correct labeling - Add missing miscfiles_setattr_man_pages() interface and for now comment some rules for userdom_filetrans_type to make build process working - Declare userdom_filetrans_type attribute - userdom_manage_home_role() needs to be called withoout usertype attribute because of userdom_filetrans_type attribute - fusefsd is mounding a fuse file system on /run/user/UID/gvfs- Man pages are now generated in the build process - Allow cgred to list inotifyfs filesystem- Allow gluster to get attrs on all fs - New access required for virt-sandbox - Allow dnsmasq to execute bin_t - Allow dnsmasq to create content in /var/run/NetworkManager - Fix openshift_initrc_signal() interface - Dontaudit openshift domains doing getattr on other domains - Allow consolehelper domain to communicate with session bus - Mock should not be transitioning to any other domains, we should keep mock_t as mock_t - Update virt_qemu_ga_t policy - Allow authconfig running from realmd to restart oddjob service - Add systemd support for oddjob - Add initial policy for realmd_consolehelper_t which if for authconfig executed by realmd - Add labeling for gnashpluginrc - Allow chrome_nacl to execute /dev/zero - Allow condor domains to read /proc - mozilla_plugin_t will getattr on /core if firefox crashes - Allow condor domains to read /etc/passwd - Allow dnsmasq to execute shell scripts, openstack requires this access - Fix glusterd labeling - Allow virtd_t to interact with the socket type - Allow nmbd_t to override dac if you turned on sharing all files - Allow tuned to created kobject_uevent socket - Allow guest user to run fusermount - Allow openshift to read /proc and locale - Allow realmd to dbus chat with rpm - Add new interface for virt - Remove depracated interfaces - Allow systemd_domains read access on etc, etc_runtime and usr files, also allow them to connect stream to syslog socket - /usr/share/munin/plugins/plugin.sh should be labeled as bin_t - Remove some more unconfined_t process transitions, that I don't believe are necessary - Stop transitioning uncofnined_t to checkpc - dmraid creates /var/lock/dmraid - Allow systemd_localed to creatre unix_dgram_sockets - Allow systemd_localed to write kernel messages. - Also cleanup systemd definition a little. - Fix userdom_restricted_xwindows_user_template() interface - Label any block devices or char devices under /dev/infiniband as fixed_disk_device_t - User accounts need to dbus chat with accountsd daemon - Gnome requires all users to be able to read /proc/1/- virsh now does a setexeccon call - Additional rules required by openshift domains - Allow svirt_lxc_domains to use inherited terminals, needed to make virt-sandbox-service execute work - Allow spamd_update_t to search spamc_home_t - Avcs discovered by mounting an isci device under /mnt - Allow lspci running as logrotate to read pci.ids - Additional fix for networkmanager_read_pid_files() - Fix networkmanager_read_pid_files() interface - Allow all svirt domains to connect to svirt_socket_t - Allow virsh to set SELinux context for a process. - Allow tuned to create netlink_kobject_uevent_socket - Allow systemd-timestamp to set SELinux context - Add support for /var/lib/systemd/linger - Fix ssh_sysadm_login to be working on MLS as expected- Rename files_rw_inherited_tmp_files to files_rw_inherited_tmp_file - Add missing files_rw_inherited_tmp_files interface - Add additional interface for ecryptfs - ALlow nova-cert to connect to postgresql - Allow keystone to connect to postgresql - Allow all cups domains to getattr on filesystems - Allow pppd to send signull - Allow tuned to execute ldconfig - Allow gpg to read fips_enabled - Add additional fixes for ecryptfs - Allow httpd to work with posgresql - Allow keystone getsched and setsched- Allow gpg to read fips_enabled - Add support for /var/cache/realmd - Add support for /usr/sbin/blazer_usb and systemd support for nut - Add labeling for fenced_sanlock and allow sanclok transition to fenced_t - bitlbee wants to read own log file - Allow glance domain to send a signal itself - Allow xend_t to request that the kernel load a kernel module - Allow pacemaker to execute heartbeat lib files - cleanup new swift policy- Fix smartmontools - Fix userdom_restricted_xwindows_user_template() interface - Add xserver_xdm_ioctl_log() interface - Allow Xusers to ioctl lxdm.log to make lxdm working - Add MLS fixes to make MLS boot/log-in working - Add mls_socket_write_all_levels() also for syslogd - fsck.xfs needs to read passwd - Fix ntp_filetrans_named_content calling in init.te - Allow postgresql to create pg_log dir - Allow sshd to read rsync_data_t to make rsync working - Change ntp.conf to be labeled net_conf_t - Allow useradd to create homedirs in /run. ircd-ratbox does this and we should just allow it - Allow xdm_t to execute gstreamer home content - Allod initrc_t and unconfined domains, and sysadm_t to manage ntp - New policy for openstack swift domains - More access required for openshift_cron_t - Use cupsd_log_t instead of cupsd_var_log_t - rpm_script_roles should be used in rpm_run - Fix rpm_run() interface - Fix openshift_initrc_run() - Fix sssd_dontaudit_stream_connect() interface - Fix sssd_dontaudit_stream_connect() interface - Allow LDA's job to deliver mail to the mailbox - dontaudit block_suspend for mozilla_plugin_t - Allow l2tpd_t to all signal perms - Allow uuidgen to read /dev/random - Allow mozilla-plugin-config to read power_supply info - Implement cups_domain attribute for cups domains - We now need access to user terminals since we start by executing a command outside the tty - We now need access to user terminals since we start by executing a command outside the tty - svirt lxc containers want to execute userhelper apps, need these changes to allow this to happen - Add containment of openshift cron jobs - Allow system cron jobs to create tmp directories - Make userhelp_conf_t a config file - Change rpm to use rpm_script_roles - More fixes for rsync to make rsync wokring - Allow logwatch to domtrans to mdadm - Allow pacemaker to domtrans to ifconfig - Allow pacemaker to setattr on corosync.log - Add pacemaker_use_execmem for memcheck-amd64 command - Allow block_suspend capability - Allow create fifo_file in /tmp with pacemaker_tmp_t - Allow systat to getattr on fixed disk - Relabel /etc/ntp.conf to be net_conf_t - ntp_admin should create files in /etc with the correct label - Add interface to create ntp_conf_t files in /etc - Add additional labeling for quantum - Allow quantum to execute dnsmasq with transition- boinc_cliean wants also execmem as boinc projecs have - Allow sa-update to search admin home for /root/.spamassassin - Allow sa-update to search admin home for /root/.spamassassin - Allow antivirus domain to read net sysctl - Dontaudit attempts from thumb_t to connect to ssd - Dontaudit attempts by readahead to read sock_files - Dontaudit attempts by readahead to read sock_files - Create tmpfs file while running as wine as user_tmpfs_t - Dontaudit attempts by readahead to read sock_files - libmpg ships badly created librarie- Change ssh_use_pts to use macro and only inherited sshd_devpts_t - Allow confined users to read systemd_logind seat information - libmpg ships badly created libraries - Add support for strongswan.service - Add labeling for strongswan - Allow l2tpd_t to read network manager content in /run directory - Allow rsync to getattr any file in rsync_data_t - Add labeling and filename transition for .grl-podcasts- mount.glusterfs executes glusterfsd binary - Allow systemd_hostnamed_t to stream connect to systemd - Dontaudit any user doing a access check - Allow obex-data-server to request the kernel to load a module - Allow gpg-agent to manage gnome content (~/.cache/gpg-agent-info) - Allow gpg-agent to read /proc/sys/crypto/fips_enabled - Add new types for antivirus.pp policy module - Allow gnomesystemmm_t caps because of ioprio_set - Make sure if mozilla_plugin creates files while in permissive mode, they get created with the correct label, user_home_t - Allow gnomesystemmm_t caps because of ioprio_set - Allow NM rawip socket - files_relabel_non_security_files can not be used with boolean - Add interface to thumb_t dbus_chat to allow it to read remote process state - ALlow logrotate to domtrans to mdadm_t - kde gnomeclock wants to write content to /tmp- kde gnomeclock wants to write content to /tmp - /usr/libexec/kde4/kcmdatetimehelper attempts to create /root/.kde - Allow blueman_t to rwx zero_device_t, for some kind of jre - Allow mozilla_plugin_t to rwx zero_device_t, for some kind of jre - Ftp full access should be allowed to create directories as well as files - Add boolean to allow rsync_full_acces, so that an rsync server can write all - over the local machine - logrotate needs to rotate logs in openshift directories, needs back port to RHEL6 - Add missing vpnc_roles type line - Allow stapserver to write content in /tmp - Allow gnome keyring to create keyrings dir in ~/.local/share - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Add interface to colord_t dbus_chat to allow it to read remote process state - Allow colord_t to read cupsd_t state - Add mate-thumbnail-font as thumnailer - Allow sectoolm to sys_ptrace since it is looking at other proceses /proc data. - Allow qpidd to list /tmp. Needed by ssl - Only allow init_t to transition to rsync_t domain, not initrc_t. This should be back ported to F17, F18 - - Added systemd support for ksmtuned - Added booleans ksmtuned_use_nfs ksmtuned_use_cifs - firewalld seems to be creating mmap files which it needs to execute in /run /tmp and /dev/shm. Would like to clean this up but for now we will allow - Looks like qpidd_t needs to read /dev/random - Lots of probing avc's caused by execugting gpg from staff_t - Dontaudit senmail triggering a net_admin avc - Change thumb_role to use thumb_run, not sure why we have a thumb_role, needs back port - Logwatch does access check on mdadm binary - Add raid_access_check_mdadm() iterface- Fix systemd_manage_unit_symlinks() interface - Call systemd_manage_unit_symlinks(() which is correct interface - Add filename transition for opasswd - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow sytstemd-timedated to get status of init_t - Add new systemd policies for hostnamed and rename gnomeclock_t to systemd_timedate_t - colord needs to communicate with systemd and systemd_logind, also remove duplicate rules - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow gpg_t to manage all gnome files - Stop using pcscd_read_pub_files - New rules for xguest, dontaudit attempts to dbus chat - Allow firewalld to create its mmap files in tmpfs and tmp directories - Allow firewalld to create its mmap files in tmpfs and tmp directories - run unbound-chkconf as named_t, so it can read dnssec - Colord is reading xdm process state, probably reads state of any apps that sends dbus message - Allow mdadm_t to change the kernel scheduler - mythtv policy - Update mandb_admin() interface - Allow dsspam to listen on own tpc_socket - seutil_filetrans_named_content needs to be optional - Allow sysadm_t to execute content in his homedir - Add attach_queue to tun_socket, new patch from Paul Moore - Change most of selinux configuration types to security_file_type. - Add filename transition rules for selinux configuration - ssh into a box with -X -Y requires ssh_use_ptys - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Allow all unpriv userdomains to send dbus messages to hostnamed and timedated - New allow rules found by Tom London for systemd_hostnamed- Allow systemd-tmpfiles to relabel lpd spool files - Ad labeling for texlive bash scripts - Add xserver_filetrans_fonts_cache_home_content() interface - Remove duplicate rules from *.te - Add support for /var/lock/man-db.lock - Add support for /var/tmp/abrt(/.*)? - Add additional labeling for munin cgi scripts - Allow httpd_t to read munin conf files - Allow certwatch to read meminfo - Fix nscd_dontaudit_write_sock_file() interfac - Fix gnome_filetrans_home_content() to include also "fontconfig" dir as cache_home_t - llow mozilla_plugin_t to create HOMEDIR/.fontconfig with the proper labeling- Allow gnomeclock to talk to puppet over dbus - Allow numad access discovered by Dominic - Add support for HOME_DIR/.maildir - Fix attribute_role for mozilla_plugin_t domain to allow staff_r to access this domain - Allow udev to relabel udev_var_run_t lnk_files - New bin_t file in mcelog- Remove all mcs overrides and replace with t1 != mcs_constrained_types - Add attribute_role for iptables - mcs_process_set_categories needs to be called for type - Implement additional role_attribute statements - Sodo domain is attempting to get the additributes of proc_kcore_t - Unbound uses port 8953 - Allow svirt_t images to compromise_kernel when using pci-passthrough - Add label for dns lib files - Bluetooth aquires a dbus name - Remove redundant files_read_usr_file calling - Remove redundant files_read_etc_file calling - Fix mozilla_run_plugin() - Add role_attribute support for more domains- Mass merge with upstream- Bump the policy version to 28 to match selinux userspace - Rebuild versus latest libsepol- Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Add labeling for /var/named/chroot/etc/localtim- Allow setroubleshoot_fixit to execute rpm - zoneminder needs to connect to httpd ports where remote cameras are listening - Allow firewalld to execute content created in /run directory - Allow svirt_t to read generic certs - Dontaudit leaked ps content to mozilla plugin - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - init scripts are creating systemd_unit_file_t directories- systemd_logind_t is looking at all files under /run/user/apache - Allow systemd to manage all user tmp files - Add labeling for /var/named/chroot/etc/localtime - Allow netlabel_peer_t type to flow over netif_t and node_t, and only be hindered by MLS, need back port to RHEL6 - Keystone is now using a differnt port - Allow xdm_t to use usbmuxd daemon to control sound - Allow passwd daemon to execute gnome_exec_keyringd - Fix chrome_sandbox policy - Add labeling for /var/run/checkquorum-timer - More fixes for the dspam domain, needs back port to RHEL6 - More fixes for the dspam domain, needs back port to RHEL6 - sssd needs to connect to kerberos password port if a user changes his password - Lots of fixes from RHEL testing of dspam web - Allow chrome and mozilla_plugin to create msgq and semaphores - Fixes for dspam cgi scripts - Fixes for dspam cgi scripts - Allow confine users to ptrace screen - Backport virt_qemu_ga_t changes from RHEL - Fix labeling for dspam.cgi needed for RHEL6 - We need to back port this policy to RHEL6, for lxc domains - Dontaudit attempts to set sys_resource of logrotate - Allow corosync to read/write wdmd's tmpfs files - I see a ptrace of mozilla_plugin_t by staff_t, will allow without deny_ptrace being set - Allow cron jobs to read bind config for unbound - libvirt needs to inhibit systemd - kdumpctl needs to delete boot_t files - Fix duplicate gnome_config_filetrans - virtd_lxc_t is using /dev/fuse - Passenger needs to create a directory in /var/log, needs a backport to RHEL6 for openshift - apcupsd can be setup to listen to snmp trafic - Allow transition from kdumpgui to kdumpctl - Add fixes for munin CGI scripts - Allow deltacloud to connect to openstack at the keystone port - Allow domains that transition to svirt domains to be able to signal them - Fix file context of gstreamer in .cache directory - libvirt is communicating with logind - NetworkManager writes to the systemd inhibit pipe- Allow munin disk plugins to get attributes of all directories - Allow munin disk plugins to get attributes of all directorie - Allow logwatch to get attributes of all directories - Fix networkmanager_manage_lib() interface - Fix gnome_manage_config() to allow to manage sock_file - Fix virtual_domain_context - Add support for dynamic DNS for DHCPv6- Allow svirt to use netlink_route_socket which was a part of auth_use_nsswitch - Add additional labeling for /var/www/openshift/broker - Fix rhev policy - Allow openshift_initrc domain to dbus chat with systemd_logind - Allow httpd to getattr passenger log file if run_stickshift - Allow consolehelper-gtk to connect to xserver - Add labeling for the tmp-inst directory defined in pam_namespace.conf - Add lvm_metadata_t labeling for /etc/multipath- consoletype is no longer used- Add label for efivarfs - Allow certmonger to send signal to itself - Allow plugin-config to read own process status - Add more fixes for pacemaker - apache/drupal can run clamscan on uploaded content - Allow chrome_sandbox_nacl_t to read pid 1 content- Fix MCS Constraints to control ingres and egres controls on the network. - Change name of svirt_nokvm_t to svirt_tcg_t - Allow tuned to request the kernel to load kernel modules- Label /var/lib/pgsql/.ssh as ssh_home_t - Add labeling for /usr/bin/pg_ctl - Allow systemd-logind to manage keyring user tmp dirs - Add support for 7389/tcp port - gems seems to be placed in lots of places - Since xdm is running a full session, it seems to be trying to execute lots of executables via dbus - Add back tcp/8123 port as http_cache port - Add ovirt-guest-agent\.pid labeling - Allow xend to run scsi_id - Allow rhsmcertd-worker to read "physical_package_id" - Allow pki_tomcat to connect to ldap port - Allow lpr to read /usr/share/fonts - Allow open file from CD/DVD drive on domU - Allow munin services plugins to talk to SSSD - Allow all samba domains to create samba directory in var_t directories - Take away svirt_t ability to use nsswitch - Dontaudit attempts by openshift to read apache logs - Allow apache to create as well as append _ra_content_t - Dontaudit sendmail_t reading a leaked file descriptor - Add interface to have admin transition /etc/prelink.cache to the proper label - Add sntp support to ntp policy - Allow firewalld to dbus chat with devicekit_power - Allow tuned to call lsblk - Allow tor to read /proc/sys/kernel/random/uuid - Add tor_can_network_relay boolean- Add openshift_initrc_signal() interface - Fix typos - dspam port is treat as spamd_port_t - Allow setroubleshoot to getattr on all executables - Allow tuned to execute profiles scripts in /etc/tuned - Allow apache to create directories to store its log files - Allow all directories/files in /var/log starting with passenger to be labeled passenger_log_t - Looks like apache is sending sinal to openshift_initrc_t now,needs back port to RHEL6 - Allow Postfix to be configured to listen on TCP port 10026 for email from DSPAM - Add filename transition for /etc/tuned/active_profile - Allow condor_master to send mails - Allow condor_master to read submit.cf - Allow condor_master to create /tmp files/dirs - Allow condor_mater to send sigkill to other condor domains - Allow condor_procd sigkill capability - tuned-adm wants to talk with tuned daemon - Allow kadmind and krb5kdc to also list sssd_public_t - Allow accountsd to dbus chat with init - Fix git_read_generic_system_content_files() interface - pppd wants sys_nice by nmcli because of "syscall=sched_setscheduler" - Fix mozilla_plugin_can_network_connect to allow to connect to all ports - Label all munin plugins which are not covered by munin plugins policy as unconfined_munin_plugin_exec_t - dspam wants to search /var/spool for opendkim data - Revert "Add support for tcp/10026 port as dspam_port_t" - Turning on labeled networking requires additional access for netlabel_peer_t; these allow rules need to be back ported to RHEL6 - Allow all application domains to use fifo_files passed in from userdomains, also allow them to write to tmp_files inherited from userdomain - Allow systemd_tmpfiles_t to setattr on mandb_cache_t- consolekit.pp was not removed from the postinstall script- Add back consolekit policy - Silence bootloader trying to use inherited tty - Silence xdm_dbusd_t trying to execute telepathy apps - Fix shutdown avcs when machine has unconfined.pp disabled - The host and a virtual machine can share the same printer on a usb device - Change oddjob to transition to a ranged openshift_initr_exec_t when run from oddjob - Allow abrt_watch_log_t to execute bin_t - Allow chrome sandbox to write content in ~/.config/chromium - Dontaudit setattr on fontconfig dir for thumb_t - Allow lircd to request the kernel to load module - Make rsync as userdom_home_manager - Allow rsync to search automount filesystem - Add fixes for pacemaker- Add support for 4567/tcp port - Random fixes from Tuomo Soini - xdm wants to get init status - Allow programs to run in fips_mode - Add interface to allow the reading of all blk device nodes - Allow init to relabel rpcbind sock_file - Fix labeling for lastlog and faillog related to logrotate - ALlow aeolus_configserver to use TRAM port - Add fixes for aeolus_configserver - Allow snmpd to connect to snmp port - Allow spamd_update to create spamd_var_lib_t directories - Allow domains that can read sssd_public_t files to also list the directory - Remove miscfiles_read_localization, this is defined for all domains- Allow syslogd to request the kernel to load a module - Allow syslogd_t to read the network state information - Allow xdm_dbusd_t connect to the system DBUS - Add support for 7389/tcp port - Allow domains to read/write all inherited sockets - Allow staff_t to read kmsg - Add awstats_purge_apache_log boolean - Allow ksysguardproces to read /.config/Trolltech.conf - Allow passenger to create and append puppet log files - Add puppet_append_log and puppet_create_log interfaces - Add puppet_manage_log() interface - Allow tomcat domain to search tomcat_var_lib_t - Allow pki_tomcat_t to connect to pki_ca ports - Allow pegasus_t to have net_admin capability - Allow pegasus_t to write /sys/class/net//flags - Allow mailserver_delivery to manage mail_home_rw_t lnk_files - Allow fetchmail to create log files - Allow gnomeclock to manage home config in .kde - Allow bittlebee to read kernel sysctls - Allow logrotate to list /root- Fix userhelper_console_role_template() - Allow enabling Network Access Point service using blueman - Make vmware_host_t as unconfined domain - Allow authenticate users in webaccess via squid, using mysql as backend - Allow gathers to get various metrics on mounted file systems - Allow firewalld to read /etc/hosts - Fix cron_admin_role() to make sysadm cronjobs running in the sysadm_t instead of cronjob_t - Allow kdumpgui to read/write to zipl.conf - Commands needed to get mock to build from staff_t in enforcing mode - Allow mdadm_t to manage cgroup files - Allow all daemons and systemprocesses to use inherited initrc_tmp_t files - dontaudit ifconfig_t looking at fifo_files that are leaked to it - Add lableing for Quest Authentication System- Fix filetrans interface definitions - Dontaudit xdm_t to getattr on BOINC lib files - Add systemd_reload_all_services() interface - Dontaudit write access on /var/lib/net-snmp/mib_indexes - Only stop mcsuntrustedproc from relableing files - Allow accountsd to dbus chat with gdm - Allow realmd to getattr on all fs - Allow logrotate to reload all services - Add systemd unit file for radiusd - Allow winbind to create samba pid dir - Add labeling for /var/nmbd/unexpected - Allow chrome and mozilla plugin to connect to msnp ports- Fix storage_rw_inherited_fixed_disk_dev() to cover also blk_file - Dontaudit setfiles reading /dev/random - On initial boot gnomeclock is going to need to be set buy gdm - Fix tftp_read_content() interface - Random apps looking at kernel file systems - Testing virt with lxc requiers additional access for virsh_t - New allow rules requied for latest libvirt, libvirt talks directly to journald,lxc setup tool needs compromize_kernel,and we need ipc_lock in the container - Allow MPD to read /dev/radnom - Allow sandbox_web_type to read logind files which needs to read pulseaudio - Allow mozilla plugins to read /dev/hpet - Add labeling for /var/lib/zarafa-webap - Allow BOINC client to use an HTTP proxy for all connections - Allow rhsmertd to domain transition to dmidecod - Allow setroubleshootd to send D-Bus msg to ABRT- Define usbtty_device_t as a term_tty - Allow svnserve to accept a connection - Allow xend manage default virt_image_t type - Allow prelink_cron_system_t to overide user componant when executing cp - Add labeling for z-push - Gnomeclock sets the realtime clock - Openshift seems to be storing apache logs in /var/lib/openshift/.log/httpd - Allow lxc domains to use /dev/random and /dev/urandom- Add port defintion for tcp/9000 - Fix labeling for /usr/share/cluster/checkquorum to label also checkquorum.wdmd - Add rules and labeling for $HOME/cache/\.gstreamer-.* directory - Add support for CIM provider openlmi-networking which uses NetworkManager dbus API - Allow shorewall_t to create netlink_socket - Allow krb5admind to block suspend - Fix labels on /var/run/dlm_controld /var/log/dlm_controld - Allow krb5kdc to block suspend - gnomessytemmm_t needs to read /etc/passwd - Allow cgred to read all sysctls- Allow all domains to read /proc/sys/vm/overcommit_memory - Make proc_numa_t an MLS Trusted Object - Add /proc/numactl support for confined users - Allow ssh_t to connect to any port > 1023 - Add openvswitch domain - Pulseaudio tries to create directories in gnome_home_t directories - New ypbind pkg wants to search /var/run which is caused by sd_notify - Allow NM to read certs on NFS/CIFS using use_nfs_*, use_samba_* booleans - Allow sanlock to read /dev/random - Treat php-fpm with httpd_t - Allow domains that can read named_conf_t to be able to list the directories - Allow winbind to create sock files in /var/run/samba- Add smsd policy - Add support for OpenShift sbin labelin - Add boolean to allow virt to use rawip - Allow mozilla_plugin to read all file systems with noxattrs support - Allow kerberos to write on anon_inodefs fs - Additional access required by fenced - Add filename transitions for passwd.lock/group.lock - UPdate man pages - Create coolkey directory in /var/cache with the correct label- Fix label on /etc/group.lock - Allow gnomeclock to create lnk_file in /etc - label /root/.pki as a home_cert_t - Add interface to make sure rpcbind.sock is created with the correct label - Add definition for new directory /var/lib/os-probe and bootloader wants to read udev rules - opendkim should be a part of milter - Allow libvirt to set the kernel sched algorythm - Allow mongod to read sysfs_t - Add authconfig policy - Remove calls to miscfiles_read_localization all domains get this - Allow virsh_t to read /root/.pki/ content - Add label for log directory under /var/www/stickshift- Allow getty to setattr on usb ttys - Allow sshd to search all directories for sshd_home_t content - Allow staff domains to send dbus messages to kdumpgui - Fix labels on /etc/.pwd.lock and friends to be passwd_file_t - Dontaudit setfiles reading urand - Add files_dontaudit_list_tmp() for domains to which we added sys_nice/setsched - Allow staff_gkeyringd_t to read /home/$USER/.local/share/keyrings dir - Allow systemd-timedated to read /dev/urandom - Allow entropyd_t to read proc_t (meminfo) - Add unconfined munin plugin - Fix networkmanager_read_conf() interface - Allow blueman to list /tmp which is needed by sys_nic/setsched - Fix label of /etc/mail/aliasesdb-stamp - numad is searching cgroups - realmd is communicating with networkmanager using dbus - Lots of fixes to try to get kdump to work- Allow loging programs to dbus chat with realmd - Make apache_content_template calling as optional - realmd is using policy kit- Add new selinuxuser_use_ssh_chroot boolean - dbus needs to be able to read/write inherited fixed disk device_t passed through it - Cleanup netutils process allow rule - Dontaudit leaked fifo files from openshift to ping - sanlock needs to read mnt_t lnk files - Fail2ban needs to setsched and sys_nice- Change default label of all files in /var/run/rpcbind - Allow sandbox domains (java) to read hugetlbfs_t - Allow awstats cgi content to create tmp files and read apache log files - Allow setuid/setgid for cupsd-config - Allow setsched/sys_nice pro cupsd-config - Fix /etc/localtime sym link to be labeled locale_t - Allow sshd to search postgresql db t since this is a homedir - Allow xwindows users to chat with realmd - Allow unconfined domains to configure all files and null_device_t service- Adopt pki-selinux policy- pki is leaking which we dontaudit until a pki code fix - Allow setcap for arping - Update man pages - Add labeling for /usr/sbin/mcollectived - pki fixes - Allow smokeping to execute fping in the netutils_t domain- Allow mount to relabelfrom unlabeled file systems - systemd_logind wants to send and receive messages from devicekit disk over dbus to make connected mouse working - Add label to get bin files under libreoffice labeled correctly - Fix interface to allow executing of base_ro_file_type - Add fixes for realmd - Update pki policy - Add tftp_homedir boolean - Allow blueman sched_setscheduler - openshift user domains wants to r/w ssh tcp sockets- Additional requirements for disable unconfined module when booting - Fix label of systemd script files - semanage can use -F /dev/stdin to get input - syslog now uses kerberos keytabs - Allow xserver to compromise_kernel access - Allow nfsd to write to mount_var_run_t when running the mount command - Add filename transition rule for bin_t directories - Allow files to read usr_t lnk_files - dhcpc wants chown - Add support for new openshift labeling - Clean up for tunable+optional statements - Add labeling for /usr/sbin/mkhomedir_helper - Allow antivirus domain to managa amavis spool files - Allow rpcbind_t to read passwd - Allow pyzor running as spamc to manage amavis spool- Add interfaces to read kernel_t proc info - Missed this version of exec_all - Allow anyone who can load a kernel module to compromise kernel - Add oddjob_dbus_chat to openshift apache policy - Allow chrome_sandbox_nacl_t to send signals to itself - Add unit file support to usbmuxd_t - Allow all openshift domains to read sysfs info - Allow openshift domains to getattr on all domains- MLS fixes from Dan - Fix name of capability2 secure_firmware->compromise_kerne- Allow xdm to search all file systems - Add interface to allow the config of all files - Add rngd policy - Remove kgpg as a gpg_exec_t type - Allow plymouthd to block suspend - Allow systemd_dbus to config any file - Allow system_dbus_t to configure all services - Allow freshclam_t to read usr_files - varnishd requires execmem to load modules- Allow semanage to verify types - Allow sudo domain to execute user home files - Allow session_bus_type to transition to user_tmpfs_t - Add dontaudit caused by yum updates - Implement pki policy but not activated- tuned wants to getattr on all filesystems - tuned needs also setsched. The build is needed for test day- Add policy for qemu-qa - Allow razor to write own config files - Add an initial antivirus policy to collect all antivirus program - Allow qdisk to read usr_t - Add additional caps for vmware_host - Allow tmpfiles_t to setattr on mandb_cache_t - Dontaudit leaked files into mozilla_plugin_config_t - Allow wdmd to getattr on tmpfs - Allow realmd to use /dev/random - allow containers to send audit messages - Allow root mount any file via loop device with enforcing mls policy - Allow tmpfiles_t to setattr on mandb_cache_t - Allow tmpfiles_t to setattr on mandb_cache_t - Make userdom_dontaudit_write_all_ not allow open - Allow init scripts to read all unit files - Add support for saphostctrl ports- Add kernel_read_system_state to sandbox_client_t - Add some of the missing access to kdumpgui - Allow systemd_dbusd_t to status the init system - Allow vmnet-natd to request the kernel to load a module - Allow gsf-office-thum to append .cache/gdm/session.log - realmd wants to read .config/dconf/user - Firewalld wants sys_nice/setsched - Allow tmpreaper to delete mandb cache files - Firewalld wants sys_nice/setsched - Allow firewalld to perform a DNS name resolution - Allown winbind to read /usr/share/samba/codepages/lowcase.dat - Add support for HTTPProxy* in /etc/freshclam.conf - Fix authlogin_yubike boolean - Extend smbd_selinux man page to include samba booleans - Allow dhcpc to execute consoletype - Allow ping to use inherited tmp files created in init scripts - On full relabel with unconfined domain disabled, initrc was running some chcon's - Allow people who delete man pages to delete mandb cache files- Add missing permissive domains- Add new mandb policy - ALlow systemd-tmpfiles_t to relabel mandb_cache_t - Allow logrotate to start all unit files- Add fixes for ctbd - Allow nmbd to stream connect to ctbd - Make cglear_t as nsswitch_domain - Fix bogus in interfaces - Allow openshift to read/write postfix public pipe - Add postfix_manage_spool_maildrop_files() interface - stickshift paths have been renamed to openshift - gnome-settings-daemon wants to write to /run/systemd/inhibit/ pipes - Update man pages, adding ENTRYPOINTS- Add mei_device_t - Make sure gpg content in homedir created with correct label - Allow dmesg to write to abrt cache files - automount wants to search virtual memory sysctls - Add support for hplip logs stored in /var/log/hp/tmp - Add labeling for /etc/owncloud/config.php - Allow setroubleshoot to send analysys to syslogd-journal - Allow virsh_t to interact with new fenced daemon - Allow gpg to write to /etc/mail/spamassassiin directories - Make dovecot_deliver_t a mail server delivery type - Add label for /var/tmp/DNS25- Fixes for tomcat_domain template interface- Remove init_systemd and init_upstart boolean, Move init_daemon_domain and init_system_domain to use attributes - Add attribute to all base os types. Allow all domains to read all ro base OS types- Additional unit files to be defined as power unit files - Fix more boolean names- Fix boolean name so subs will continue to work- dbus needs to start getty unit files - Add interface to allow system_dbusd_t to start the poweroff service - xdm wants to exec telepathy apps - Allow users to send messages to systemdlogind - Additional rules needed for systemd and other boot apps - systemd wants to list /home and /boot - Allow gkeyringd to write dbus/conf file - realmd needs to read /dev/urand - Allow readahead to delete /.readahead if labeled root_t, might get created before policy is loaded- Fixes to safe more rules - Re-write tomcat_domain_template() - Fix passenger labeling - Allow all domains to read man pages - Add ephemeral_port_t to the 'generic' port interfaces - Fix the names of postgresql booleans- Stop using attributes form netlabel_peer and syslog, auth_use_nsswitch setsup netlabel_peer - Move netlable_peer check out of booleans - Remove call to recvfrom_netlabel for kerberos call - Remove use of attributes when calling syslog call - Move -miscfiles_read_localization to domain.te to save hundreds of allow rules - Allow all domains to read locale files. This eliminates around 1500 allow rules- Cleanup nis_use_ypbind_uncond interface - Allow rndc to block suspend - tuned needs to modify the schedule of the kernel - Allow svirt_t domains to read alsa configuration files - ighten security on irc domains and make sure they label content in homedir correctly - Add filetrans_home_content for irc files - Dontaudit all getattr access for devices and filesystems for sandbox domains - Allow stapserver to search cgroups directories - Allow all postfix domains to talk to spamd- Add interfaces to ignore setattr until kernel fixes this to be checked after the DAC check - Change pam_t to pam_timestamp_t - Add dovecot_domain attribute and allow this attribute block_suspend capability2 - Add sanlock_use_fusefs boolean - numad wants send/recieve msg - Allow rhnsd to send syslog msgs - Make piranha-pulse as initrc domain - Update openshift instances to dontaudit setattr until the kernel is fixed.- Fix auth_login_pgm_domain() interface to allow domains also managed user tmp dirs because of #856880 related to pam_systemd - Remove pam_selinux.8 which conflicts with man page owned by the pam package - Allow glance-api to talk to mysql - ABRT wants to read Xorg.0.log if if it detects problem with Xorg - Fix gstreamer filename trans. interface- Man page fixes by Dan Walsh- Allow postalias to read postfix config files - Allow man2html to read man pages - Allow rhev-agentd to search all mountpoints - Allow rhsmcertd to read /dev/random - Add tgtd_stream_connect() interface - Add cyrus_write_data() interface - Dontaudit attempts by sandboxX clients connectiing to the xserver_port_t - Add port definition for tcp/81 as http_port_t - Fix /dev/twa labeling - Allow systemd to read modules config- Merge openshift policy - Allow xauth to read /dev/urandom - systemd needs to relabel content in /run/systemd directories - Files unconfined should be able to perform all services on all files - Puppet tmp file can be leaked to all domains - Dontaudit rhsmcertd-worker to search /root/.local - Allow chown capability for zarafa domains - Allow system cronjobs to runcon into openshift domains - Allow virt_bridgehelper_t to manage content in the svirt_home_t labeled directories- nmbd wants to create /var/nmbd - Stop transitioning out of anaconda and firstboot, just causes AVC messages - Allow clamscan to read /etc files - Allow bcfg2 to bind cyphesis port - heartbeat should be run as rgmanager_t instead of corosync_t - Add labeling for /etc/openldap/certs - Add labeling for /opt/sartest directory - Make crontab_t as userdom home reader - Allow tmpreaper to list admin_home dir - Add defition for imap_0 replay cache file - Add support for gitolite3 - Allow virsh_t to send syslog messages - allow domains that can read samba content to be able to list the directories also - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd - Separate out sandbox from sandboxX policy so we can disable it by default - Run dmeventd as lvm_t - Mounting on any directory requires setattr and write permissions - Fix use_nfs_home_dirs() boolean - New labels for pam_krb5 - Allow init and initrc domains to sys_ptrace since this is needed to look at processes not owned by uid 0 - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd- Separate sandbox policy into sandbox and sandboxX, and disable sandbox by default on fresh installs - Allow domains that can read etc_t to read etc_runtime_t - Allow all domains to use inherited tmpfiles- Allow realmd to read resolv.conf - Add pegasus_cache_t type - Label /usr/sbin/fence_virtd as virsh_exec_t - Add policy for pkcsslotd - Add support for cpglockd - Allow polkit-agent-helper to read system-auth-ac - telepathy-idle wants to read gschemas.compiled - Allow plymouthd to getattr on fs_t - Add slpd policy - Allow ksysguardproces to read/write config_usr_t- Fix labeling substitution so rpm will label /lib/systemd content correctly- Add file name transitions for ttyACM0 - spice-vdagent(d)'s are going to log over to syslog - Add sensord policy - Add more fixes for passenger policy related to puppet - Allow wdmd to create wdmd_tmpfs_t - Fix labeling for /var/run/cachefilesd\.pid - Add thumb_tmpfs_t files type- Allow svirt domains to manage the network since this is containerized - Allow svirt_lxc_net_t to send audit messages- Make "snmpwalk -mREDHAT-CLUSTER-MIB ...." working - Allow dlm_controld to execute dlm_stonith labeled as bin_t - Allow GFS2 working on F17 - Abrt needs to execute dmesg - Allow jockey to list the contents of modeprobe.d - Add policy for lightsquid as squid_cron_t - Mailscanner is creating files and directories in /tmp - dmesg is now reading /dev/kmsg - Allow xserver to communicate with secure_firmware - Allow fsadm tools (fsck) to read /run/mount contnet - Allow sysadm types to read /dev/kmsg -- Allow postfix, sssd, rpcd to block_suspend - udev seems to need secure_firmware capability - Allow virtd to send dbus messages to firewalld so it can configure the firewall- Fix labeling of content in /run created by virsh_t - Allow condor domains to read kernel sysctls - Allow condor_master to connect to amqp - Allow thumb drives to create shared memory and semaphores - Allow abrt to read mozilla_plugin config files - Add labels for lightsquid - Default files in /opt and /usr that end in .cgi as httpd_sys_script_t, allow - dovecot_auth_t uses ldap for user auth - Allow domains that can read dhcp_etc_t to read lnk_files - Add more then one watchdog device - Allow useradd_t to manage etc_t files so it can rename it and edit them - Fix invalid class dir should be fifo_file - Move /run/blkid to fsadm and make sure labeling is correct- Fix bogus regex found by eparis - Fix manage run interface since lvm needs more access - syslogd is searching cgroups directory - Fixes to allow virt-sandbox-service to manage lxc var run content- Fix Boolean settings - Add new libjavascriptcoregtk as textrel_shlib_t - Allow xdm_t to create xdm_home_t directories - Additional access required for systemd - Dontaudit mozilla_plugin attempts to ipc_lock - Allow tmpreaper to delete unlabeled files - Eliminate screen_tmp_t and allow it to manage user_tmp_t - Dontaudit mozilla_plugin_config_t to append to leaked file descriptors - Allow web plugins to connect to the asterisk ports - Condor will recreate the lock directory if it does not exist - Oddjob mkhomedir needs to connectto user processes - Make oddjob_mkhomedir_t a userdom home manager- Put placeholder back in place for proper numbering of capabilities - Systemd also configures init scripts- Fix ecryptfs interfaces - Bootloader seems to be trolling around /dev/shm and /dev - init wants to create /etc/systemd/system-update.target.wants - Fix systemd_filetrans call to move it out of tunable - Fix up policy to work with systemd userspace manager - Add secure_firmware capability and remove bogus epolwakeup - Call seutil_*_login_config interfaces where should be needed - Allow rhsmcertd to send signal to itself - Allow thin domains to send signal to itself - Allow Chrome_ChildIO to read dosfs_t- Add role rules for realmd, sambagui- Add new type selinux_login_config_t for /etc/selinux//logins/ - Additional fixes for seutil_manage_module_store() - dbus_system_domain() should be used with optional_policy - Fix svirt to be allowed to use fusefs file system - Allow login programs to read /run/ data created by systemd_login - sssd wants to write /etc/selinux//logins/ for SELinux PAM module - Fix svirt to be allowed to use fusefs file system - Allow piranha domain to use nsswitch - Sanlock needs to send Kill Signals to non root processes - Pulseaudio wants to execute /run/user/PID/.orc- Fix saslauthd when it tries to read /etc/shadow - Label gnome-boxes as a virt homedir - Need to allow svirt_t ability to getattr on nfs_t file systems - Update sanlock policy to solve all AVC's - Change confined users can optionally manage virt content - Handle new directories under ~/.cache - Add block suspend to appropriate domains - More rules required for containers - Allow login programs to read /run/ data created by systemd_logind - Allow staff users to run svirt_t processes- Update to upstream- More fixes for systemd to make rawhide booting from Dan Walsh- Add systemd fixes to make rawhide booting- Add systemd_logind_inhibit_var_run_t attribute - Remove corenet_all_recvfrom_unlabeled() for non-contrib policies because we moved it to domain.if for all domain_type - Add interface for mysqld to dontaudit signull to all processes - Label new /var/run/journal directory correctly - Allow users to inhibit suspend via systemd - Add new type for the /var/run/inhibit directory - Add interface to send signull to systemd_login so avahi can send them - Allow systemd_passwd to send syslog messages - Remove corenet_all_recvfrom_unlabeled() calling fro policy files - Allow editparams.cgi running as httpd_bugzilla_script_t to read /etc/group - Allow smbd to read cluster config - Add additional labeling for passenger - Allow dbus to inhibit suspend via systemd - Allow avahi to send signull to systemd_login- Add interface to dontaudit getattr access on sysctls - Allow sshd to execute /bin/login - Looks like xdm is recreating the xdm directory in ~/.cache/ on login - Allow syslog to use the leaked kernel_t unix_dgram_socket from system-jounald - Fix semanage to work with unconfined domain disabled on F18 - Dontaudit attempts by mozilla plugins to getattr on all kernel sysctls - Virt seems to be using lock files - Dovecot seems to be searching directories of every mountpoint - Allow jockey to read random/urandom, execute shell and install third-party drivers - Add aditional params to allow cachedfiles to manage its content - gpg agent needs to read /dev/random - The kernel hands an svirt domains /SYSxxxxx which is a tmpfs that httpd wants to read and write - Add a bunch of dontaudit rules to quiet svirt_lxc domains - Additional perms needed to run svirt_lxc domains - Allow cgclear to read cgconfig - Allow sys_ptrace capability for snmp - Allow freshclam to read /proc - Allow procmail to manage /home/user/Maildir content - Allow NM to execute wpa_cli - Allow amavis to read clamd system state - Regenerate man pages- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Add realmd and stapserver policies - Allow useradd to manage stap-server lib files - Tighten up capabilities for confined users - Label /etc/security/opasswd as shadow_t - Add label for /dev/ecryptfs - Allow condor_startd_t to start sshd with the ranged - Allow lpstat.cups to read fips_enabled file - Allow pyzor running as spamc_t to create /root/.pyzor directory - Add labelinf for amavisd-snmp init script - Add support for amavisd-snmp - Allow fprintd sigkill self - Allow xend (w/o libvirt) to start virtual machines - Allow aiccu to read /etc/passwd - Allow condor_startd to Make specified domain MCS trusted for setting any category set for the processes it executes - Add condor_startd_ranged_domtrans_to() interface - Add ssd_conf_t for /etc/sssd - accountsd needs to fchown some files/directories - Add ICACLient and zibrauserdata as mozilla_filetrans_home_content - SELinux reports afs_t needs dac_override to read /etc/mtab, even though everything works, adding dontaudit - Allow xend_t to read the /etc/passwd file- Until we figure out how to fix systemd issues, allow all apps that send syslog messages to send them to kernel_t - Add init_access_check() interface - Fix label on /usr/bin/pingus to not be labeled as ping_exec_t - Allow tcpdump to create a netlink_socket - Label newusers like useradd - Change xdm log files to be labeled xdm_log_t - Allow sshd_t with privsep to work in MLS - Allow freshclam to update databases thru HTTP proxy - Allow s-m-config to access check on systemd - Allow abrt to read public files by default - Fix amavis_create_pid_files() interface - Add labeling and filename transition for dbomatic.log - Allow system_dbusd_t to stream connect to bluetooth, and use its socket - Allow amavisd to execute fsav - Allow tuned to use sys_admin and sys_nice capabilities - Add php-fpm policy from Bryan - Add labeling for aeolus-configserver-thinwrapper - Allow thin domains to execute shell - Fix gnome_role_gkeyringd() interface description - Lot of interface fixes - Allow OpenMPI job running as condor_startd_ssh_t to manage condor lib files - Allow OpenMPI job to use kerberos - Make deltacloudd_t as nsswitch_domain - Allow xend_t to run lsscsi - Allow qemu-dm running as xend_t to create tun_socket - Add labeling for /opt/brother/Printers(.*/)?inf - Allow jockey-backend to read pyconfig-64.h labeled as usr_t - Fix clamscan_can_scan_system boolean - Allow lpr to connectto to /run/user/$USER/keyring-22uREb/pkcs11- initrc is calling exportfs which is not confined so it attempts to read nfsd_files - Fixes for passenger running within openshift. - Add labeling for all tomcat6 dirs - Add support for tomcat6 - Allow cobblerd to read /etc/passwd - Allow jockey to read sysfs and and execute binaries with bin_t - Allow thum to use user terminals - Allow cgclear to read cgconfig config files - Fix bcf2g.fc - Remove sysnet_dns_name_resolve() from policies where auth_use_nsswitch() is used for other domains - Allow dbomatic to execute ruby - abrt_watch_log should be abrt_domain - Allow mozilla_plugin to connect to gatekeeper port- add ptrace_child access to process - remove files_read_etc_files() calling from all policies which have auth_use_nsswith() - Allow boinc domains to manage boinc_lib_t lnk_files - Add support for boinc-client.service unit file - Add support for boinc.log - Allow mozilla_plugin execmod on mozilla home files if allow_ex - Allow dovecot_deliver_t to read dovecot_var_run_t - Allow ldconfig and insmod to manage kdumpctl tmp files - Move thin policy out from cloudform.pp and add a new thin poli - pacemaker needs to communicate with corosync streams - abrt is now started on demand by dbus - Allow certmonger to talk directly to Dogtag servers - Change labeling for /var/lib/cobbler/webui_sessions to httpd_c - Allow mozila_plugin to execute gstreamer home files - Allow useradd to delete all file types stored in the users hom - rhsmcertd reads the rpm database - Add support for lightdm- Add tomcat policy - Remove pyzor/razor policy - rhsmcertd reads the rpm database - Dontaudit thumb to setattr on xdm_tmp dir - Allow wicd to execute ldconfig in the networkmanager_t domain - Add /var/run/cherokee\.pid labeling - Allow mozilla_plugin to create mozilla_plugin_tmp_t lnk files too - Allow postfix-master to r/w pipes other postfix domains - Allow snort to create netlink_socket - Add kdumpctl policy - Allow firstboot to create tmp_t files/directories - /usr/bin/paster should not be labeled as piranha_exec_t - remove initrc_domain from tomcat - Allow ddclient to read /etc/passwd - Allow useradd to delete all file types stored in the users homedir - Allow ldconfig and insmod to manage kdumpctl tmp files - Firstboot should be just creating tmp_t dirs and xauth should be allowed to write to those - Transition xauth files within firstboot_tmp_t - Fix labeling of /run/media to match /media - Label all lxdm.log as xserver_log_t - Add port definition for mxi port - Allow local_login_t to execute tmux- apcupsd needs to read /etc/passwd - Sanlock allso sends sigkill - Allow glance_registry to connect to the mysqld port - Dontaudit mozilla_plugin trying to getattr on /dev/gpmctl - Allow firefox plugins/flash to connect to port 1234 - Allow mozilla plugins to delete user_tmp_t files - Add transition name rule for printers.conf.O - Allow virt_lxc_t to read urand - Allow systemd_loigind to list gstreamer_home_dirs - Fix labeling for /usr/bin - Fixes for cloudform services * support FIPS - Allow polipo to work as web caching - Allow chfn to execute tmux- Add support for ecryptfs * ecryptfs does not support xattr * we need labeling for HOMEDIR - Add policy for (u)mount.ecryptfs* - Fix labeling of kerbero host cache files, allow rpc.svcgssd to manage host cache - Allow dovecot to manage Maildir content, fix transitions to Maildir - Allow postfix_local to transition to dovecot_deliver - Dontaudit attempts to setattr on xdm_tmp_t, looks like bogus code - Cleanup interface definitions - Allow apmd to change with the logind daemon - Changes required for sanlock in rhel6 - Label /run/user/apache as httpd_tmp_t - Allow thumb to use lib_t as execmod if boolean turned on - Allow squid to create the squid directory in /var with the correct labe - Add a new policy for glusterd from Bryan Bickford (bbickfor@redhat.com) - Allow virtd to exec xend_exec_t without transition - Allow virtd_lxc_t to unmount all file systems- PolicyKit path has changed - Allow httpd connect to dirsrv socket - Allow tuned to write generic kernel sysctls - Dontaudit logwatch to gettr on /dev/dm-2 - Allow policykit-auth to manage kerberos files - Make condor_startd and rgmanager as initrc domain - Allow virsh to read /etc/passwd - Allow mount to mount on user_tmp_t for /run/user/dwalsh/gvfs - xdm now needs to execute xsession_exec_t - Need labels for /var/lib/gdm - Fix files_filetrans_named_content() interface - Add new attribute - initrc_domain - Allow systemd_logind_t to signal, signull, sigkill all processes - Add filetrans rules for etc_runtime files- Rename boolean names to remove allow_- Mass merge with upstream * new policy topology to include contrib policy modules * we have now two base policy patches- Fix description of authlogin_nsswitch_use_ldap - Fix transition rule for rhsmcertd_t needed for RHEL7 - Allow useradd to list nfs state data - Allow openvpn to manage its log file and directory - We want vdsm to transition to mount_t when executing mount command to make sure /etc/mtab remains labeled correctly - Allow thumb to use nvidia devices - Allow local_login to create user_tmp_t files for kerberos - Pulseaudio needs to read systemd_login /var/run content - virt should only transition named system_conf_t config files - Allow munin to execute its plugins - Allow nagios system plugin to read /etc/passwd - Allow plugin to connect to soundd port - Fix httpd_passwd to be able to ask passwords - Radius servers can use ldap for backing store - Seems to need to mount on /var/lib for xguest polyinstatiation to work. - Allow systemd_logind to list the contents of gnome keyring - VirtualGL need xdm to be able to manage content in /etc/opt/VirtualGL - Add policy for isns-utils- Add policy for subversion daemon - Allow boinc to read passwd - Allow pads to read kernel network state - Fix man2html interface for sepolgen-ifgen - Remove extra /usr/lib/systemd/system/smb - Remove all /lib/systemd and replace with /usr/lib/systemd - Add policy for man2html - Fix the label of kerberos_home_t to krb5_home_t - Allow mozilla plugins to use Citrix - Allow tuned to read /proc/sys/kernel/nmi_watchdog - Allow tune /sys options via systemd's tmpfiles.d "w" type- Dontaudit lpr_t to read/write leaked mozilla tmp files - Add file name transition for .grl-podcasts directory - Allow corosync to read user tmp files - Allow fenced to create snmp lib dirs/files - More fixes for sge policy - Allow mozilla_plugin_t to execute any application - Allow dbus to read/write any open file descriptors to any non security file on the system that it inherits to that it can pass them to another domain - Allow mongod to read system state information - Fix wrong type, we should dontaudit sys_admin for xdm_t not xserver_t - Allow polipo to manage polipo_cache dirs - Add jabbar_client port to mozilla_plugin_t - Cleanup procmail policy - system bus will pass around open file descriptors on files that do not have labels on them - Allow l2tpd_t to read system state - Allow tuned to run ls /dev - Allow sudo domains to read usr_t files - Add label to machine-id - Fix corecmd_read_bin_symlinks cut and paste error- Fix pulseaudio port definition - Add labeling for condor_starter - Allow chfn_t to creat user_tmp_files - Allow chfn_t to execute bin_t - Allow prelink_cron_system_t to getpw calls - Allow sudo domains to manage kerberos rcache files - Allow user_mail_domains to work with courie - Port definitions necessary for running jboss apps within openshift - Add support for openstack-nova-metadata-api - Add support for nova-console* - Add support for openstack-nova-xvpvncproxy - Fixes to make privsep+SELinux working if we try to use chage to change passwd - Fix auth_role() interface - Allow numad to read sysfs - Allow matahari-rpcd to execute shell - Add label for ~/.spicec - xdm is executing lspci as root which is requesting a sys_admin priv but seems to succeed without it - Devicekit_disk wants to read the logind sessions file when writing a cd - Add fixes for condor to make condor jobs working correctly - Change label of /var/log/rpmpkgs to cron_log_t - Access requires to allow systemd-tmpfiles --create to work. - Fix obex to be a user application started by the session bus. - Add additional filename trans rules for kerberos - Fix /var/run/heartbeat labeling - Allow apps that are managing rcache to file trans correctly - Allow openvpn to authenticate against ldap server - Containers need to listen to network starting and stopping events- Make systemd unit files less specific- Fix zarafa labeling - Allow guest_t to fix labeling - corenet_tcp_bind_all_unreserved_ports(ssh_t) should be called with the user_tcp_server boolean - add lxc_contexts - Allow accountsd to read /proc - Allow restorecond to getattr on all file sytems - tmpwatch now calls getpw - Allow apache daemon to transition to pwauth domain - Label content under /var/run/user/NAME/keyring* as gkeyringd_tmp_t - The obex socket seems to be a stream socket - dd label for /var/run/nologin- Allow jetty running as httpd_t to read hugetlbfs files - Allow sys_nice and setsched for rhsmcertd - Dontaudit attempts by mozilla_plugin_t to bind to ssdp ports - Allow setfiles to append to xdm_tmp_t - Add labeling for /export as a usr_t directory - Add labels for .grl files created by gstreamer- Add labeling for /usr/share/jetty/bin/jetty.sh - Add jetty policy which contains file type definitios - Allow jockey to use its own fifo_file and make this the default for all domains - Allow mozilla_plugins to use spice (vnc_port/couchdb) - asterisk wants to read the network state - Blueman now uses /var/lib/blueman- Add label for nodejs_debug - Allow mozilla_plugin_t to create ~/.pki directory and content- Add clamscan_can_scan_system boolean - Allow mysqld to read kernel network state - Allow sshd to read/write condor lib files - Allow sshd to read/write condor-startd tcp socket - Fix description on httpd_graceful_shutdown - Allow glance_registry to communicate with mysql - dbus_system_domain is using systemd to lauch applications - add interfaces to allow domains to send kill signals to user mail agents - Remove unnessary access for svirt_lxc domains, add privs for virtd_lxc_t - Lots of new access required for secure containers - Corosync needs sys_admin capability - ALlow colord to create shm - .orc should be allowed to be created by any app that can create gstream home content, thumb_t to be specific - Add boolean to control whether or not mozilla plugins can create random content in the users homedir - Add new interface to allow domains to list msyql_db directories, needed for libra - shutdown has to be allowed to delete etc_runtime_t - Fail2ban needs to read /etc/passwd - Allow ldconfig to create /var/cache/ldconfig - Allow tgtd to read hardware state information - Allow collectd to create packet socket - Allow chronyd to send signal to itself - Allow collectd to read /dev/random - Allow collectd to send signal to itself - firewalld needs to execute restorecon - Allow restorecon and other login domains to execute restorecon- Allow logrotate to getattr on systemd unit files - Add support for tor systemd unit file - Allow apmd to create /var/run/pm-utils with the correct label - Allow l2tpd to send sigkill to pppd - Allow pppd to stream connect to l2tpd - Add label for scripts in /etc/gdm/ - Allow systemd_logind_t to ignore mcs constraints on sigkill - Fix files_filetrans_system_conf_named_files() interface - Add labels for /usr/share/wordpress/wp-includes/*.php - Allow cobbler to get SELinux mode and booleans- Add unconfined_execmem_exec_t as an alias to bin_t - Allow fenced to read snmp var lib files, also allow it to read usr_t - ontaudit access checks on all executables from mozilla_plugin - Allow all user domains to setexec, so that sshd will work properly if it call setexec(NULL) while running withing a user mode - Allow systemd_tmpfiles_t to getattr all pipes and sockets - Allow glance-registry to send system log messages - semanage needs to manage mock lib files/dirs- Add policy for abrt-watch-log - Add definitions for jboss_messaging ports - Allow systemd_tmpfiles to manage printer devices - Allow oddjob to use nsswitch - Fix labeling of log files for postgresql - Allow mozilla_plugin_t to execmem and execstack by default - Allow firewalld to execute shell - Fix /etc/wicd content files to get created with the correct label - Allow mcelog to exec shell - Add ~/.orc as a gstreamer_home_t - /var/spool/postfix/lib64 should be labeled lib_t - mpreaper should be able to list all file system labeled directories - Add support for apache to use openstack - Add labeling for /etc/zipl.conf and zipl binary - Turn on allow_execstack and turn off telepathy transition for final release- More access required for virt_qmf_t - Additional assess required for systemd-logind to support multi-seat - Allow mozilla_plugin to setrlimit - Revert changes to fuse file system to stop deadlock- Allow condor domains to connect to ephemeral ports - More fixes for condor policy - Allow keystone to stream connect to mysqld - Allow mozilla_plugin_t to read generic USB device to support GPS devices - Allow thum to file name transition gstreamer home content - Allow thum to read all non security files - Allow glance_api_t to connect to ephemeral ports - Allow nagios plugins to read /dev/urandom - Allow syslogd to search postfix spool to support postfix chroot env - Fix labeling for /var/spool/postfix/dev - Allow wdmd chown - Label .esd_auth as pulseaudio_home_t - Have no idea why keyring tries to write to /run/user/dwalsh/dconf/user, but we can dontaudit for now- Add support for clamd+systemd - Allow fresclam to execute systemctl to handle clamd - Change labeling for /usr/sbin/rpc.ypasswd.env - Allow yppaswd_t to execute yppaswd_exec_t - Allow yppaswd_t to read /etc/passwd - Gnomekeyring socket has been moved to /run/user/USER/ - Allow samba-net to connect to ldap port - Allow signal for vhostmd - allow mozilla_plugin_t to read user_home_t socket - New access required for secure Linux Containers - zfs now supports xattrs - Allow quantum to execute sudo and list sysfs - Allow init to dbus chat with the firewalld - Allow zebra to read /etc/passwd- Allow svirt_t to create content in the users homedir under ~/.libvirt - Fix label on /var/lib/heartbeat - Allow systemd_logind_t to send kill signals to all processes started by a user - Fuse now supports Xattr Support- upowered needs to setsched on the kernel - Allow mpd_t to manage log files - Allow xdm_t to create /var/run/systemd/multi-session-x - Add rules for missedfont.log to be used by thumb.fc - Additional access required for virt_qmf_t - Allow dhclient to dbus chat with the firewalld - Add label for lvmetad - Allow systemd_logind_t to remove userdomain sock_files - Allow cups to execute usr_t files - Fix labeling on nvidia shared libraries - wdmd_t needs access to sssd and /etc/passwd - Add boolean to allow ftp servers to run in passive mode - Allow namepspace_init_t to relabelto/from a different user system_u from the user the namespace_init running with - Fix using httpd_use_fusefs - Allow chrome_sandbox_nacl to write inherited user tmp files as we allow it for chrome_sandbox- Rename rdate port to time port, and allow gnomeclock to connect to it - We no longer need to transition to ldconfig from rpm, rpm_script, or anaconda - /etc/auto.* should be labeled bin_t - Add httpd_use_fusefs boolean - Add fixes for heartbeat - Allow sshd_t to signal processes that it transitions to - Add condor policy - Allow svirt to create monitors in ~/.libvirt - Allow dovecot to domtrans sendmail to handle sieve scripts - Lot of fixes for cfengine- /var/run/postmaster.* labeling is no longer needed - Alllow drbdadmin to read /dev/urandom - l2tpd_t seems to use ptmx - group+ and passwd+ should be labeled as /etc/passwd - Zarafa-indexer is a socket- Ensure lastlog is labeled correctly - Allow accountsd to read /proc data about gdm - Add fixes for tuned - Add bcfg2 fixes which were discovered during RHEL6 testing - More fixes for gnome-keyring socket being moved - Run semanage as a unconfined domain, and allow initrc_t to create tmpfs_t sym links on shutdown - Fix description for files_dontaudit_read_security_files() interface- Add new policy and man page for bcfg2 - cgconfig needs to use getpw calls - Allow domains that communicate with the keyring to use cache_home_t instead of gkeyringd_tmpt - gnome-keyring wants to create a directory in cache_home_t - sanlock calls getpw- Add numad policy and numad man page - Add fixes for interface bugs discovered by SEWatch - Add /tmp support for squid - Add fix for #799102 * change default labeling for /var/run/slapd.* sockets - Make thumb_t as userdom_home_reader - label /var/lib/sss/mc same as pubconf, so getpw domains can read it - Allow smbspool running as cups_t to stream connect to nmbd - accounts needs to be able to execute passwd on behalf of users - Allow systemd_tmpfiles_t to delete boot flags - Allow dnssec_trigger to connect to apache ports - Allow gnome keyring to create sock_files in ~/.cache - google_authenticator is using .google_authenticator - sandbox running from within firefox is exposing more leaks - Dontaudit thumb to read/write /dev/card0 - Dontaudit getattr on init_exec_t for gnomeclock_t - Allow certmonger to do a transition to certmonger_unconfined_t - Allow dhcpc setsched which is caused by nmcli - Add rpm_exec_t for /usr/sbin/bcfg2 - system cronjobs are sending dbus messages to systemd_logind - Thumnailers read /dev/urand- Allow auditctl getcap - Allow vdagent to use libsystemd-login - Allow abrt-dump-oops to search /etc/abrt - Got these avc's while trying to print a boarding pass from firefox - Devicekit is now putting the media directory under /run/media - Allow thumbnailers to create content in ~/.thumbails directory - Add support for proL2TPd by Dominick Grift - Allow all domains to call getcap - wdmd seems to get a random chown capability check that it does not need - Allow vhostmd to read kernel sysctls- Allow chronyd to read unix - Allow hpfax to read /etc/passwd - Add support matahari vios-proxy-* apps and add virtd_exec_t label for them - Allow rpcd to read quota_db_t - Update to man pages to match latest policy - Fix bug in jockey interface for sepolgen-ifgen - Add initial svirt_prot_exec_t policy- More fixes for systemd from Dan Walsh- Add a new type for /etc/firewalld and allow firewalld to write to this directory - Add definition for ~/Maildir, and allow mail deliver domains to write there - Allow polipo to run from a cron job - Allow rtkit to schedule wine processes - Allow mozilla_plugin_t to acquire a bug, and allow it to transition gnome content in the home dir to the proper label - Allow users domains to send signals to consolehelper domains- More fixes for boinc policy - Allow polipo domain to create its own cache dir and pid file - Add systemctl support to httpd domain - Add systemctl support to polipo, allow NetworkManager to manage the service - Add policy for jockey-backend - Add support for motion daemon which is now covered by zoneminder policy - Allow colord to read/write motion tmpfs - Allow vnstat to search through var_lib_t directories - Stop transitioning to quota_t, from init an sysadm_t- Add svirt_lxc_file_t as a customizable type- Add additional fixes for icmp nagios plugin - Allow cron jobs to open fifo_files from cron, since service script opens /dev/stdin - Add certmonger_unconfined_exec_t - Make sure tap22 device is created with the correct label - Allow staff users to read systemd unit files - Merge in previously built policy - Arpwatch needs to be able to start netlink sockets in order to start - Allow cgred_t to sys_ptrace to look at other DAC Processes- Back port some of the access that was allowed in nsplugin_t - Add definitiona for couchdb ports - Allow nagios to use inherited users ttys - Add git support for mock - Allow inetd to use rdate port - Add own type for rdate port - Allow samba to act as a portmapper - Dontaudit chrome_sandbox attempts to getattr on chr_files in /dev - New fixes needed for samba4 - Allow apps that use lib_t to read lib_t symlinks- Add policy for nove-cert - Add labeling for nova-openstack systemd unit files - Add policy for keystoke- Fix man pages fro domains - Add man pages for SELinux users and roles - Add storage_dev_filetrans_named_fixed_disk() and use it for smartmon - Add policy for matahari-rpcd - nfsd executes mount command on restart - Matahari domains execute renice and setsched - Dontaudit leaked tty in mozilla_plugin_config - mailman is changing to a per instance naming - Add 7600 and 4447 as jboss_management ports - Add fixes for nagios event handlers - Label httpd.event as httpd_exec_t, it is an apache daemon- Add labeling for /var/spool/postfix/dev/log - NM reads sysctl.conf - Iscsi log file context specification fix - Allow mozilla plugins to send dbus messages to user domains that transition to it - Allow mysql to read the passwd file - Allow mozilla_plugin_t to create mozilla home dirs in user homedir - Allow deltacloud to read kernel sysctl - Allow postgresql_t to connectto itselfAllow postgresql_t to connectto itself - Allow postgresql_t to connectto itself - Add login_userdomain attribute for users which can log in using terminal- Allow sysadm_u to reach system_r by default #784011 - Allow nagios plugins to use inherited user terminals - Razor labeling is not used no longer - Add systemd support for matahari - Add port_types to man page, move booleans to the top, fix some english - Add support for matahari-sysconfig-console - Clean up matahari.fc - Fix matahari_admin() interfac - Add labels for/etc/ssh/ssh_host_*.pub keys- Allow ksysguardproces to send system log msgs - Allow boinc setpgid and signull - Allow xdm_t to sys_ptrace to run pidof command - Allow smtpd_t to manage spool files/directories and symbolic links - Add labeling for jetty - Needed changes to get unbound/dnssec to work with openswan- Add user_fonts_t alias xfs_tmp_t - Since depmod now runs as insmod_t we need to write to kernel_object_t - Allow firewalld to dbus chat with networkmanager - Allow qpidd to connect to matahari ports - policykit needs to read /proc for uses not owned by it - Allow systemctl apps to connecto the init stream- Turn on deny_ptrace boolean- Remove pam_selinux.8 man page. There was a conflict.- Add proxy class and read access for gssd_proxy - Separate out the sharing public content booleans - Allow certmonger to execute a script and send signals to apache and dirsrv to reload the certificate - Add label transition for gstream-0.10 and 12 - Add booleans to allow rsync to share nfs and cifs file sytems - chrome_sandbox wants to read the /proc/PID/exe file of the program that executed it - Fix filename transitions for cups files - Allow denyhosts to read "unix" - Add file name transition for locale.conf.new - Allow boinc projects to gconf config files - sssd needs to be able to increase the socket limit under certain loads - sge_execd needs to read /etc/passwd - Allow denyhost to check network state - NetworkManager needs to read sessions data - Allow denyhost to check network state - Allow xen to search virt images directories - Add label for /dev/megaraid_sas_ioctl_node - Add autogenerated man pages- Allow boinc project to getattr on fs - Allow init to execute initrc_state_t - rhev-agent package was rename to ovirt-guest-agent - If initrc_t creates /etc/local.conf then we need to make sure it is labeled correctly - sytemd writes content to /run/initramfs and executes it on shutdown - kdump_t needs to read /etc/mtab, should be back ported to F16 - udev needs to load kernel modules in early system boot- Need to add sys_ptrace back in since reading any content in /proc can cause these accesses - Add additional systemd interfaces which are needed fro *_admin interfaces - Fix bind_admin() interface- Allow firewalld to read urand - Alias java, execmem_mono to bin_t to allow third parties - Add label for kmod - /etc/redhat-lsb contains binaries - Add boolean to allow gitosis to send mail - Add filename transition also for "event20" - Allow systemd_tmpfiles_t to delete all file types - Allow collectd to ipc_lock- make consoletype_exec optional, so we can remove consoletype policy - remove unconfined_permisive.patch - Allow openvpn_t to inherit user home content and tmp content - Fix dnssec-trigger labeling - Turn on obex policy for staff_t - Pem files should not be secret - Add lots of rules to fix AVC's when playing with containers - Fix policy for dnssec - Label ask-passwd directories correctly for systemd- sshd fixes seem to be causing unconfined domains to dyntrans to themselves - fuse file system is now being mounted in /run/user - systemd_logind is sending signals to processes that are dbus messaging with it - Add support for winshadow port and allow iscsid to connect to this port - httpd should be allowed to bind to the http_port_t udp socket - zarafa_var_lib_t can be a lnk_file - A couple of new .xsession-errors files - Seems like user space and login programs need to read logind_sessions_files - Devicekit disk seems to be being launched by systemd - Cleanup handling of setfiles so most of rules in te file - Correct port number for dnssec - logcheck has the home dir set to its cache- Add policy for grindengine MPI jobs- Add new sysadm_secadm.pp module * contains secadm definition for sysadm_t - Move user_mail_domain access out of the interface into the te file - Allow httpd_t to create httpd_var_lib_t directories as well as files - Allow snmpd to connect to the ricci_modcluster stream - Allow firewalld to read /etc/passwd - Add auth_use_nsswitch for colord - Allow smartd to read network state - smartdnotify needs to read /etc/group- Allow gpg and gpg_agent to store sock_file in gpg_secret_t directory - lxdm startup scripts should be labeled bin_t, so confined users will work - mcstransd now creates a pid, needs back port to F16 - qpidd should be allowed to connect to the amqp port - Label devices 010-029 as usb devices - ypserv packager says ypserv does not use tmp_t so removing selinux policy types - Remove all ptrace commands that I believe are caused by the kernel/ps avcs - Add initial Obex policy - Add logging_syslogd_use_tty boolean - Add polipo_connect_all_unreserved bolean - Allow zabbix to connect to ftp port - Allow systemd-logind to be able to switch VTs - Allow apache to communicate with memcached through a sock_file- Fix file_context.subs_dist for now to work with pre usrmove- More /usr move fixes- Add zabbix_can_network boolean - Add httpd_can_connect_zabbix boolean - Prepare file context labeling for usrmove functions - Allow system cronjobs to read kernel network state - Add support for selinux_avcstat munin plugin - Treat hearbeat with corosync policy - Allow corosync to read and write to qpidd shared mem - mozilla_plugin is trying to run pulseaudio - Fixes for new sshd patch for running priv sep domains as the users context - Turn off dontaudit rules when turning on allow_ypbind - udev now reads /etc/modules.d directory- Turn on deny_ptrace boolean for the Rawhide run, so we can test this out - Cups exchanges dbus messages with init - udisk2 needs to send syslog messages - certwatch needs to read /etc/passwd- Add labeling for udisks2 - Allow fsadmin to communicate with the systemd process- Treat Bip with bitlbee policy * Bip is an IRC proxy - Add port definition for interwise port - Add support for ipa_memcached socket - systemd_jounald needs to getattr on all processes - mdadmin fixes * uses getpw - amavisd calls getpwnam() - denyhosts calls getpwall()- Setup labeling of /var/rsa and /var/lib/rsa to allow login programs to write there - bluetooth says they do not use /tmp and want to remove the type - Allow init to transition to colord - Mongod needs to read /proc/sys/vm/zone_reclaim_mode - Allow postfix_smtpd_t to connect to spamd - Add boolean to allow ftp to connect to all ports > 1023 - Allow sendmain to write to inherited dovecot tmp files - setroubleshoot needs to be able to execute rpm to see what version of packages- Merge systemd patch - systemd-tmpfiles wants to relabel /sys/devices/system/cpu/online - Allow deltacloudd dac_override, setuid, setgid caps - Allow aisexec to execute shell - Add use_nfs_home_dirs boolean for ssh-keygen- Fixes to make rawhide boot in enforcing mode with latest systemd changes- Add labeling for /var/run/systemd/journal/syslog - libvirt sends signals to ifconfig - Allow domains that read logind session files to list them- Fixed destined form libvirt-sandbox - Allow apps that list sysfs to also read sympolicy links in this filesystem - Add ubac_constrained rules for chrome_sandbox - Need interface to allow domains to use tmpfs_t files created by the kernel, used by libra - Allow postgresql to be executed by the caller - Standardize interfaces of daemons - Add new labeling for mm-handler - Allow all matahari domains to read network state and etc_runtime_t files- New fix for seunshare, requires seunshare_domains to be able to mounton / - Allow systemctl running as logrotate_t to connect to private systemd socket - Allow tmpwatch to read meminfo - Allow rpc.svcgssd to read supported_krb5_enctype - Allow zarafa domains to read /dev/random and /dev/urandom - Allow snmpd to read dev_snmp6 - Allow procmail to talk with cyrus - Add fixes for check_disk and check_nagios plugins- default trans rules for Rawhide policy - Make sure sound_devices controlC* are labeled correctly on creation - sssd now needs sys_admin - Allow snmp to read all proc_type - Allow to setup users homedir with quota.group- Add httpd_can_connect_ldap() interface - apcupsd_t needs to use seriel ports connected to usb devices - Kde puts procmail mail directory under ~/.local/share - nfsd_t can trigger sys_rawio on tests that involve too many mountpoints, dontaudit for now - Add labeling for /sbin/iscsiuio- Add label for /var/lib/iscan/interpreter - Dont audit writes to leaked file descriptors or redirected output for nacl - NetworkManager needs to write to /sys/class/net/ib*/mode- Allow abrt to request the kernel to load a module - Make sure mozilla content is labeled correctly - Allow tgtd to read system state - More fixes for boinc * allow to resolve dns name * re-write boinc policy to use boinc_domain attribute - Allow munin services plugins to use NSCD services- Allow mozilla_plugin_t to manage mozilla_home_t - Allow ssh derived domain to execute ssh-keygen in the ssh_keygen_t domain - Add label for tumblerd- Fixes for xguest package- Fixes related to /bin, /sbin - Allow abrt to getattr on blk files - Add type for rhev-agent log file - Fix labeling for /dev/dmfm - Dontaudit wicd leaking - Allow systemd_logind_t to look at process info of apps that exchange dbus messages with it - Label /etc/locale.conf correctly - Allow user_mail_t to read /dev/random - Allow postfix-smtpd to read MIMEDefang - Add label for /var/log/suphp.log - Allow swat_t to connect and read/write nmbd_t sock_file - Allow systemd-tmpfiles to setattr for /run/user/gdm/dconf - Allow systemd-tmpfiles to change user identity in object contexts - More fixes for rhev_agentd_t consolehelper policy- Use fs_use_xattr for squashf - Fix procs_type interface - Dovecot has a new fifo_file /var/run/dovecot/stats-mail - Dovecot has a new fifo_file /var/run/stats-mail - Colord does not need to connect to network - Allow system_cronjob to dbus chat with NetworkManager - Puppet manages content, want to make sure it labels everything correctly- Change port 9050 to tor_socks_port_t and then allow openvpn to connect to it - Allow all postfix domains to use the fifo_file - Allow sshd_t to getattr on all file systems in order to generate avc on nfs_t - Allow apmd_t to read grub.cfg - Let firewallgui read the selinux config - Allow systemd-tmpfiles to delete content in /root that has been moved to /tmp - Fix devicekit_manage_pid_files() interface - Allow squid to check the network state - Dontaudit colord getattr on file systems - Allow ping domains to read zabbix_tmp_t files- Allow mcelog_t to create dir and file in /var/run and label it correctly - Allow dbus to manage fusefs - Mount needs to read process state when mounting gluster file systems - Allow collectd-web to read collectd lib files - Allow daemons and system processes started by init to read/write the unix_stream_socket passed in from as stdin/stdout/stderr - Allow colord to get the attributes of tmpfs filesystem - Add sanlock_use_nfs and sanlock_use_samba booleans - Add bin_t label for /usr/lib/virtualbox/VBoxManage- Add ssh_dontaudit_search_home_dir - Changes to allow namespace_init_t to work - Add interface to allow exec of mongod, add port definition for mongod port, 27017 - Label .kde/share/apps/networkmanagement/certificates/ as home_cert_t - Allow spamd and clamd to steam connect to each other - Add policy label for passwd.OLD - More fixes for postfix and postfix maildro - Add ftp support for mozilla plugins - Useradd now needs to manage policy since it calls libsemanage - Fix devicekit_manage_log_files() interface - Allow colord to execute ifconfig - Allow accountsd to read /sys - Allow mysqld-safe to execute shell - Allow openct to stream connect to pcscd - Add label for /var/run/nm-dns-dnsmasq\.conf - Allow networkmanager to chat with virtd_t- Pulseaudio changes - Merge patches- Merge patches back into git repository.- Remove allow_execmem boolean and replace with deny_execmem boolean- Turn back on allow_execmem boolean- Add more MCS fixes to make sandbox working - Make faillog MLS trusted to make sudo_$1_t working - Allow sandbox_web_client_t to read passwd_file_t - Add .mailrc file context - Remove execheap from openoffice domain - Allow chrome_sandbox_nacl_t to read cpu_info - Allow virtd to relabel generic usb which is need if USB device - Fixes for virt.if interfaces to consider chr_file as image file type- Remove Open Office policy - Remove execmem policy- MCS fixes - quota fixes- Remove transitions to consoletype- Make nvidia* to be labeled correctly - Fix abrt_manage_cache() interface - Make filetrans rules optional so base policy will build - Dontaudit chkpwd_t access to inherited TTYS - Make sure postfix content gets created with the correct label - Allow gnomeclock to read cgroup - Fixes for cloudform policy- Check in fixed for Chrome nacl support- Begin removing qemu_t domain, we really no longer need this domain. - systemd_passwd needs dac_overide to communicate with users TTY's - Allow svirt_lxc domains to send kill signals within their container- Remove qemu.pp again without causing a crash- Remove qemu.pp, everything should use svirt_t or stay in its current domain- Allow policykit to talk to the systemd via dbus - Move chrome_sandbox_nacl_t to permissive domains - Additional rules for chrome_sandbox_nacl- Change bootstrap name to nacl - Chrome still needs execmem - Missing role for chrome_sandbox_bootstrap - Add boolean to remove execmem and execstack from virtual machines - Dontaudit xdm_t doing an access_check on etc_t directories- Allow named to connect to dirsrv by default - add ldapmap1_0 as a krb5_host_rcache_t file - Google chrome developers asked me to add bootstrap policy for nacl stuff - Allow rhev_agentd_t to getattr on mountpoints - Postfix_smtpd_t needs access to milters and cleanup seems to read/write postfix_smtpd_t unix_stream_sockets- Fixes for cloudform policies which need to connect to random ports - Make sure if an admin creates modules content it creates them with the correct label - Add port 8953 as a dns port used by unbound - Fix file name transition for alsa and confined users- Turn on mock_t and thumb_t for unconfined domains- Policy update should not modify local contexts- Remove ada policy- Remove tzdata policy - Add labeling for udev - Add cloudform policy - Fixes for bootloader policy- Add policies for nova openstack- Add fixes for nova-stack policy- Allow svirt_lxc_domain to chr_file and blk_file devices if they are in the domain - Allow init process to setrlimit on itself - Take away transition rules for users executing ssh-keygen - Allow setroubleshoot_fixit_t to read /dev/urand - Allow sshd to relbale tunnel sockets - Allow fail2ban domtrans to shorewall in the same way as with iptables - Add support for lnk files in the /var/lib/sssd directory - Allow system mail to connect to courier-authdaemon over an unix stream socket- Add passwd_file_t for /etc/ptmptmp- Dontaudit access checks for all executables, gnome-shell is doing access(EXEC, X_OK) - Make corosync to be able to relabelto cluster lib fies - Allow samba domains to search /var/run/nmbd - Allow dirsrv to use pam - Allow thumb to call getuid - chrome less likely to get mmap_zero bug so removing dontaudit - gimp help-browser has built in javascript - Best guess is that devices named /dev/bsr4096 should be labeled as cpu_device_t - Re-write glance policy- Move dontaudit sys_ptrace line from permissive.te to domain.te - Remove policy for hal, it no longer exists- Don't check md5 size or mtime on certain config files- Remove allow_ptrace and replace it with deny_ptrace, which will remove all ptrace from the system - Remove 2000 dontaudit rules between confined domains on transition and replace with single dontaudit domain domain:process { noatsecure siginh rlimitinh } ;- Fixes for bootloader policy - $1_gkeyringd_t needs to read $HOME/%USER/.local/share/keystore - Allow nsplugin to read /usr/share/config - Allow sa-update to update rules - Add use_fusefs_home_dirs for chroot ssh option - Fixes for grub2 - Update systemd_exec_systemctl() interface - Allow gpg to read the mail spool - More fixes for sa-update running out of cron job - Allow ipsec_mgmt_t to read hardware state information - Allow pptp_t to connect to unreserved_port_t - Dontaudit getattr on initctl in /dev from chfn - Dontaudit getattr on kernel_core from chfn - Add systemd_list_unit_dirs to systemd_exec_systemctl call - Fixes for collectd policy - CHange sysadm_t to create content as user_tmp_t under /tmp- Shrink size of policy through use of attributes for userdomain and apache- Allow virsh to read xenstored pid file - Backport corenetwork fixes from upstream - Do not audit attempts by thumb to search config_home_t dirs (~/.config) - label ~/.cache/telepathy/logger telepathy_logger_cache_home_t - allow thumb to read generic data home files (mime.type)- Allow nmbd to manage sock file in /var/run/nmbd - ricci_modservice send syslog msgs - Stop transitioning from unconfined_t to ldconfig_t, but make sure /etc/ld.so.cache is labeled correctly - Allow systemd_logind_t to manage /run/USER/dconf/user- Fix missing patch from F16- Allow logrotate setuid and setgid since logrotate is supposed to do it - Fixes for thumb policy by grift - Add new nfsd ports - Added fix to allow confined apps to execmod on chrome - Add labeling for additional vdsm directories - Allow Exim and Dovecot SASL - Add label for /var/run/nmbd - Add fixes to make virsh and xen working together - Colord executes ls - /var/spool/cron is now labeled as user_cron_spool_t- Stop complaining about leaked file descriptors during install- Remove java and mono module and merge into execmem- Fixes for thumb policy and passwd_file_t- Fixes caused by the labeling of /etc/passwd - Add thumb.patch to transition unconfined_t to thumb_t for Rawhide- Add support for Clustered Samba commands - Allow ricci_modrpm_t to send log msgs - move permissive virt_qmf_t from virt.te to permissivedomains.te - Allow ssh_t to use kernel keyrings - Add policy for libvirt-qmf and more fixes for linux containers - Initial Polipo - Sanlock needs to run ranged in order to kill svirt processes - Allow smbcontrol to stream connect to ctdbd- Add label for /etc/passwd- Change unconfined_domains to permissive for Rawhide - Add definition for the ephemeral_ports- Make mta_role() active - Allow asterisk to connect to jabber client port - Allow procmail to read utmp - Add NIS support for systemd_logind_t - Allow systemd_logind_t to manage /run/user/$USER/dconf dir which is labeled as config_home_t - Fix systemd_manage_unit_dirs() interface - Allow ssh_t to manage directories passed into it - init needs to be able to create and delete unit file directories - Fix typo in apache_exec_sys_script - Add ability for logrotate to transition to awstat domain- Change screen to use screen_domain attribute and allow screen_domains to read all process domain state - Add SELinux support for ssh pre-auth net process in F17 - Add logging_syslogd_can_sendmail boolean- Add definition for ephemeral ports - Define user_tty_device_t as a customizable_type- Needs to require a new version of checkpolicy - Interface fixes- Allow sanlock to manage virt lib files - Add virt_use_sanlock booelan - ksmtuned is trying to resolve uids - Make sure .gvfs is labeled user_home_t in the users home directory - Sanlock sends kill signals and needs the kill capability - Allow mockbuild to work on nfs homedirs - Fix kerberos_manage_host_rcache() interface - Allow exim to read system state- Allow systemd-tmpfiles to set the correct labels on /var/run, /tmp and other files - We want any file type that is created in /tmp by a process running as initrc_t to be labeled initrc_tmp_t- Allow collectd to read hardware state information - Add loop_control_device_t - Allow mdadm to request kernel to load module - Allow domains that start other domains via systemctl to search unit dir - systemd_tmpfilses, needs to list any file systems mounted on /tmp - No one can explain why radius is listing the contents of /tmp, so we will dontaudit - If I can manage etc_runtime files, I should be able to read the links - Dontaudit hostname writing to mock library chr_files - Have gdm_t setup labeling correctly in users home dir - Label content unde /var/run/user/NAME/dconf as config_home_t - Allow sa-update to execute shell - Make ssh-keygen working with fips_enabled - Make mock work for staff_t user - Tighten security on mock_t- removing unconfined_notrans_t no longer necessary - Clean up handling of secure_mode_insmod and secure_mode_policyload - Remove unconfined_mount_t- Add exim_exec_t label for /usr/sbin/exim_tidydb - Call init_dontaudit_rw_stream_socket() interface in mta policy - sssd need to search /var/cache/krb5rcache directory - Allow corosync to relabel own tmp files - Allow zarafa domains to send system log messages - Allow ssh to do tunneling - Allow initrc scripts to sendto init_t unix_stream_socket - Changes to make sure dmsmasq and virt directories are labeled correctly - Changes needed to allow sysadm_t to manage systemd unit files - init is passing file descriptors to dbus and on to system daemons - Allow sulogin additional access Reported by dgrift and Jeremy Miller - Steve Grubb believes that wireshark does not need this access - Fix /var/run/initramfs to stop restorecon from looking at - pki needs another port - Add more labels for cluster scripts - Allow apps that manage cgroup_files to manage cgroup link files - Fix label on nfs-utils scripts directories - Allow gatherd to read /dev/rand and /dev/urand- pki needs another port - Add more labels for cluster scripts - Fix label on nfs-utils scripts directories - Fixes for cluster - Allow gatherd to read /dev/rand and /dev/urand - abrt leaks fifo files- Add glance policy - Allow mdadm setsched - /var/run/initramfs should not be relabeled with a restorecon run - memcache can be setup to override sys_resource - Allow httpd_t to read tetex data - Allow systemd_tmpfiles to delete kernel modules left in /tmp directory.- Allow Postfix to deliver to Dovecot LMTP socket - Ignore bogus sys_module for lldpad - Allow chrony and gpsd to send dgrams, gpsd needs to write to the real time clock - systemd_logind_t sets the attributes on usb devices - Allow hddtemp_t to read etc_t files - Add permissivedomains module - Move all permissive domains calls to permissivedomain.te - Allow pegasis to send kill signals to other UIDs- Allow insmod_t to use fds leaked from devicekit - dontaudit getattr between insmod_t and init_t unix_stream_sockets - Change sysctl unit file interfaces to use systemctl - Add support for chronyd unit file - Allow mozilla_plugin to read gnome_usr_config - Add policy for new gpsd - Allow cups to create kerberos rhost cache files - Add authlogin_filetrans_named_content, to unconfined_t to make sure shadow and other log files get labeled correctly- Make users_extra and seusers.final into config(noreplace) so semanage users and login does not get overwritten- Add policy for sa-update being run out of cron jobs - Add create perms to postgresql_manage_db - ntpd using a gps has to be able to read/write generic tty_device_t - If you disable unconfined and unconfineduser, rpm needs more privs to manage /dev - fix spec file - Remove qemu_domtrans_unconfined() interface - Make passenger working together with puppet - Add init_dontaudit_rw_stream_socket interface - Fixes for wordpress- Turn on allow_domain_fd_use boolean on F16 - Allow syslog to manage all log files - Add use_fusefs_home_dirs boolean for chrome - Make vdagent working with confined users - Add abrt_handle_event_t domain for ABRT event scripts - Labeled /usr/sbin/rhnreg_ks as rpm_exec_t and added changes related to this change - Allow httpd_git_script_t to read passwd data - Allow openvpn to set its process priority when the nice parameter is used- livecd fixes - spec file fixes- fetchmail can use kerberos - ksmtuned reads in shell programs - gnome_systemctl_t reads the process state of ntp - dnsmasq_t asks the kernel to load multiple kernel modules - Add rules for domains executing systemctl - Bogus text within fc file- Add cfengine policy- Add abrt_domain attribute - Allow corosync to manage cluster lib files - Allow corosync to connect to the system DBUS- Add sblim, uuidd policies - Allow kernel_t dyntrasition to init_t- init_t need setexec - More fixes of rules which cause an explosion in rules by Dan Walsh- Allow rcsmcertd to perform DNS name resolution - Add dirsrvadmin_unconfined_script_t domain type for 389-ds admin scripts - Allow tmux to run as screen - New policy for collectd - Allow gkeyring_t to interact with all user apps - Add rules to allow firstboot to run on machines with the unconfined.pp module removed- Allow systemd_logind to send dbus messages with users - allow accountsd to read wtmp file - Allow dhcpd to get and set capabilities- Fix oracledb_port definition - Allow mount to mounton the selinux file system - Allow users to list /var directories- systemd fixes- Add initial policy for abrt_dump_oops_t - xtables-multi wants to getattr of the proc fs - Smoltclient is connecting to abrt - Dontaudit leaked file descriptors to postdrop - Allow abrt_dump_oops to look at kernel sysctls - Abrt_dump_oops_t reads kernel ring buffer - Allow mysqld to request the kernel to load modules - systemd-login needs fowner - Allow postfix_cleanup_t to searh maildrop- Initial systemd_logind policy - Add policy for systemd_logger and additional proivs for systemd_logind - More fixes for systemd policies- Allow setsched for virsh - Systemd needs to impersonate cups, which means it needs to create tcp_sockets in cups_t domain, as well as manage spool directories - iptables: the various /sbin/ip6?tables.* are now symlinks for /sbin/xtables-multi- A lot of users are running yum -y update while in /root which is causing ldconfig to list the contents, adding dontaudit - Allow colord to interact with the users through the tmpfs file system - Since we changed the label on deferred, we need to allow postfix_qmgr_t to be able to create maildrop_t files - Add label for /var/log/mcelog - Allow asterisk to read /dev/random if it uses TLS - Allow colord to read ini files which are labeled as bin_t - Allow dirsrvadmin sys_resource and setrlimit to use ulimit - Systemd needs to be able to create sock_files for every label in /var/run directory, cupsd being the first. - Also lists /var and /var/spool directories - Add openl2tpd to l2tpd policy - qpidd is reading the sysfs file- Change usbmuxd_t to dontaudit attempts to read chr_file - Add mysld_safe_exec_t for libra domains to be able to start private mysql domains - Allow pppd to search /var/lock dir - Add rhsmcertd policy- Update to upstream- More fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git- Fix spec file to not report Verify errors- Add dspam policy - Add lldpad policy - dovecot auth wants to search statfs #713555 - Allow systemd passwd apps to read init fifo_file - Allow prelink to use inherited terminals - Run cherokee in the httpd_t domain - Allow mcs constraints on node connections - Implement pyicqt policy - Fixes for zarafa policy - Allow cobblerd to send syslog messages- Add policy.26 to the payload - Remove olpc stuff - Remove policygentool- Fixes for zabbix - init script needs to be able to manage sanlock_var_run_... - Allow sandlock and wdmd to create /var/run directories... - mixclip.so has been compiled correctly - Fix passenger policy module name- Add mailscanner policy from dgrift - Allow chrome to optionally be transitioned to - Zabbix needs these rules when starting the zabbix_server_mysql - Implement a type for freedesktop openicc standard (~/.local/share/icc) - Allow system_dbusd_t to read inherited icc_data_home_t files. - Allow colord_t to read icc_data_home_t content. #706975 - Label stuff under /usr/lib/debug as if it was labeled under /- Fixes for sanlock policy - Fixes for colord policy - Other fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Add rhev policy module to modules-targeted.conf- Lot of fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Allow logrotate to execute systemctl - Allow nsplugin_t to getattr on gpmctl - Fix dev_getattr_all_chr_files() interface - Allow shorewall to use inherited terms - Allow userhelper to getattr all chr_file devices - sandbox domains should be able to getattr and dontaudit search of sysctl_kernel_t - Fix labeling for ABRT Retrace Server- Dontaudit sys_module for ifconfig - Make telepathy and gkeyringd daemon working with confined users - colord wants to read files in users homedir - Remote login should be creating user_tmp_t not its own tmp files- Fix label for /usr/share/munin/plugins/munin_* plugins - Add support for zarafa-indexer - Fix boolean description - Allow colord to getattr on /proc/scsi/scsi - Add label for /lib/upstart/init - Colord needs to list /mnt- Forard port changes from F15 for telepathy - NetworkManager should be allowed to use /dev/rfkill - Fix dontaudit messages to say Domain to not audit - Allow telepathy domains to read/write gnome_cache files - Allow telepathy domains to call getpw - Fixes for colord and vnstatd policy- Allow init_t getcap and setcap - Allow namespace_init_t to use nsswitch - aisexec will execute corosync - colord tries to read files off noxattr file systems - Allow init_t getcap and setcap- Add support for ABRT retrace server - Allow user_t and staff_t access to generic scsi to handle locally plugged in scanners - Allow telepath_msn_t to read /proc/PARENT/cmdline - ftpd needs kill capability - Allow telepath_msn_t to connect to sip port - keyring daemon does not work on nfs homedirs - Allow $1_sudo_t to read default SELinux context - Add label for tgtd sock file in /var/run/ - Add apache_exec_rotatelogs interface - allow all zaraha domains to signal themselves, server writes to /tmp - Allow syslog to read the process state - Add label for /usr/lib/chromium-browser/chrome - Remove the telepathy transition from unconfined_t - Dontaudit sandbox domains trying to mounton sandbox_file_t, this is caused by fuse mounts - Allow initrc_t domain to manage abrt pid files - Add support for AEOLUS project - Virt_admin should be allowed to manage images and processes - Allow plymountd to send signals to init - Change labeling of fping6- Add filename transitions- Fixes for zarafa policy - Add support for AEOLUS project - Change labeling of fping6 - Allow plymountd to send signals to init - Allow initrc_t domain to manage abrt pid files - Virt_admin should be allowed to manage images and processes- xdm_t needs getsession for switch user - Every app that used to exec init is now execing systemdctl - Allow squid to manage krb5_host_rcache_t files - Allow foghorn to connect to agentx port - Fixes for colord policy- Add Dan's patch to remove 64 bit variants - Allow colord to use unix_dgram_socket - Allow apps that search pids to read /var/run if it is a lnk_file - iscsid_t creates its own directory - Allow init to list var_lock_t dir - apm needs to verify user accounts auth_use_nsswitch - Add labeling for systemd unit files - Allow gnomeclok to enable ntpd service using systemctl - systemd_systemctl_t domain was added - Add label for matahari-broker.pid file - We want to remove untrustedmcsprocess from ability to read /proc/pid - Fixes for matahari policy - Allow system_tmpfiles_t to delete user_home_t files in the /tmp dir - Allow sshd to transition to sysadm_t if ssh_sysadm_login is turned on- Fix typo- Add /var/run/lock /var/lock definition to file_contexts.subs - nslcd_t is looking for kerberos cc files - SSH_USE_STRONG_RNG is 1 which requires /dev/random - Fix auth_rw_faillog definition - Allow sysadm_t to set attributes on fixed disks - allow user domains to execute lsof and look at application sockets - prelink_cron job calls telinit -u if init is rewritten - Fixes to run qemu_t from staff_t- Fix label for /var/run/udev to udev_var_run_t - Mock needs to be able to read network state- Add file_contexts.subs to handle /run and /run/lock - Add other fixes relating to /run changes from F15 policy- Allow $1_sudo_t and $1_su_t open access to user terminals - Allow initrc_t to use generic terminals - Make Makefile/Rules.modular run sepolgen-ifgen during build to check if files for bugs -systemd is going to be useing /run and /run/lock for early bootup files. - Fix some comments in rlogin.if - Add policy for KDE backlighthelper - sssd needs to read ~/.k5login in nfs, cifs or fusefs file systems - sssd wants to read .k5login file in users homedir - setroubleshoot reads executables to see if they have TEXTREL - Add /var/spool/audit support for new version of audit - Remove kerberos_connect_524() interface calling - Combine kerberos_master_port_t and kerberos_port_t - systemd has setup /dev/kmsg as stderr for apps it executes - Need these access so that init can impersonate sockets on unix_dgram_socket- Remove some unconfined domains - Remove permissive domains - Add policy-term.patch from Dan- Fix multiple specification for boot.log - devicekit leaks file descriptors to setfiles_t - Change all all_nodes to generic_node and all_if to generic_if - Should not use deprecated interface - Switch from using all_nodes to generic_node and from all_if to generic_if - Add support for xfce4-notifyd - Fix file context to show several labels as SystemHigh - seunshare needs to be able to mounton nfs/cifs/fusefs homedirs - Add etc_runtime_t label for /etc/securetty - Fixes to allow xdm_t to start gkeyringd_USERTYPE_t directly - login.krb needs to be able to write user_tmp_t - dirsrv needs to bind to port 7390 for dogtag - Fix a bug in gpg policy - gpg sends audit messages - Allow qpid to manage matahari files- Initial policy for matahari - Add dev_read_watchdog - Allow clamd to connect clamd port - Add support for kcmdatetimehelper - Allow shutdown to setrlimit and sys_nice - Allow systemd_passwd to talk to /dev/log before udev or syslog is running - Purge chr_file and blk files on /tmp - Fixes for pads - Fixes for piranha-pulse - gpg_t needs to be able to encyprt anything owned by the user- mozilla_plugin_tmp_t needs to be treated as user tmp files - More dontaudits of writes from readahead - Dontaudit readahead_t file_type:dir write, to cover up kernel bug - systemd_tmpfiles needs to relabel faillog directory as well as the file - Allow hostname and consoletype to r/w inherited initrc_tmp_t files handline hostname >> /tmp/myhost- Add policykit fixes from Tim Waugh - dontaudit sandbox domains sandbox_file_t:dir mounton - Add new dontaudit rules for sysadm_dbusd_t - Change label for /var/run/faillock * other fixes which relate with this change- Update to upstream - Fixes for telepathy - Add port defition for ssdp port - add policy for /bin/systemd-notify from Dan - Mount command requires users read mount_var_run_t - colord needs to read konject_uevent_socket - User domains connect to the gkeyring socket - Add colord policy and allow user_t and staff_t to dbus chat with it - Add lvm_exec_t label for kpartx - Dontaudit reading the mail_spool_t link from sandbox -X - systemd is creating sockets in avahi_var_run and system_dbusd_var_run- gpg_t needs to talk to gnome-keyring - nscd wants to read /usr/tmp->/var/tmp to generate randomziation in unixchkpwd - enforce MCS labeling on nodes - Allow arpwatch to read meminfo - Allow gnomeclock to send itself signals - init relabels /dev/.udev files on boot - gkeyringd has to transition back to staff_t when it runs commands in bin_t or shell_exec_t - nautilus checks access on /media directory before mounting usb sticks, dontaudit access_check on mnt_t - dnsmasq can run as a dbus service, needs acquire service - mysql_admin should be allowed to connect to mysql service - virt creates monitor sockets in the users home dir- Allow usbhid-ups to read hardware state information - systemd-tmpfiles has moved - Allo cgroup to sys_tty_config - For some reason prelink is attempting to read gconf settings - Add allow_daemons_use_tcp_wrapper boolean - Add label for ~/.cache/wocky to make telepathy work in enforcing mode - Add label for char devices /dev/dasd* - Fix for apache_role - Allow amavis to talk to nslcd - allow all sandbox to read selinux poilcy config files - Allow cluster domains to use the system bus and send each other dbus messages- Update to upstream- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Update to ref policy - cgred needs chown capability - Add /dev/crash crash_dev_t - systemd-readahead wants to use fanotify which means readahead_t needs sys_admin capability- New labeling for postfmulti #675654 - dontaudit xdm_t listing noxattr file systems - dovecot-auth needs to be able to connect to mysqld via the network as well as locally - shutdown is passed stdout to a xdm_log_t file - smartd creates a fixed disk device - dovecot_etc_t contains a lnk_file that domains need to read - mount needs to be able to read etc_runtim_t:lnk_file since in rawhide this is a link created at boot- syslog_t needs syslog capability - dirsrv needs to be able to create /var/lib/snmp - Fix labeling for dirsrv - Fix for dirsrv policy missing manage_dirs_pattern - corosync needs to delete clvm_tmpfs_t files - qdiskd needs to list hugetlbfs - Move setsched to sandbox_x_domain, so firefox can run without network access - Allow hddtemp to read removable devices - Adding syslog and read_policy permissions to policy * syslog Allow unconfined, sysadm_t, secadm_t, logadm_t * read_policy allow unconfined, sysadm_t, secadm_t, staff_t on Targeted allow sysadm_t (optionally), secadm_t on MLS - mdadm application will write into /sys/.../uevent whenever arrays are assembled or disassembled.- Add tcsd policy- ricci_modclusterd_t needs to bind to rpc ports 500-1023 - Allow dbus to use setrlimit to increase resoueces - Mozilla_plugin is leaking to sandbox - Allow confined users to connect to lircd over unix domain stream socket which allow to use remote control - Allow awstats to read squid logs - seunshare needs to manage tmp_t - apcupsd cgi scripts have a new directory- Fix xserver_dontaudit_read_xdm_pid - Change oracle_port_t to oracledb_port_t to prevent conflict with satellite - Allow dovecot_deliver_t to read/write postfix_master_t:fifo_file. * These fifo_file is passed from postfix_master_t to postfix_local_t to dovecot_deliver_t - Allow readahead to manage readahead pid dirs - Allow readahead to read all mcs levels - Allow mozilla_plugin_t to use nfs or samba homedirs- Allow nagios plugin to read /proc/meminfo - Fix for mozilla_plugin - Allow samba_net_t to create /etc/keytab - pppd_t setting up vpns needs to run unix_chkpwd, setsched its process and write wtmp_t - nslcd can read user credentials - Allow nsplugin to delete mozilla_plugin_tmpfs_t - abrt tries to create dir in rpm_var_lib_t - virt relabels fifo_files - sshd needs to manage content in fusefs homedir - mock manages link files in cache dir- nslcd needs setsched and to read /usr/tmp - Invalid call in likewise policy ends up creating a bogus role - Cannon puts content into /var/lib/bjlib that cups needs to be able to write - Allow screen to create screen_home_t in /root - dirsrv sends syslog messages - pinentry reads stuff in .kde directory - Add labels for .kde directory in homedir - Treat irpinit, iprupdate, iprdump services with raid policy- NetworkManager wants to read consolekit_var_run_t - Allow readahead to create /dev/.systemd/readahead - Remove permissive domains - Allow newrole to run namespace_init- Add sepgsql_contexts file- Update to upstream- Add oracle ports and allow apache to connect to them if the connect_db boolean is turned on - Add puppetmaster_use_db boolean - Fixes for zarafa policy - Fixes for gnomeclock poliy - Fix systemd-tmpfiles to use auth_use_nsswitch- gnomeclock executes a shell - Update for screen policy to handle pipe in homedir - Fixes for polyinstatiated homedir - Fixes for namespace policy and other fixes related to polyinstantiation - Add namespace policy - Allow dovecot-deliver transition to sendmail which is needed by sieve scripts - Fixes for init, psad policy which relate with confined users - Do not audit bootloader attempts to read devicekit pid files - Allow nagios service plugins to read /proc- Add firewalld policy - Allow vmware_host to read samba config - Kernel wants to read /proc Fix duplicate grub def in cobbler - Chrony sends mail, executes shell, uses fifo_file and reads /proc - devicekitdisk getattr all file systems - sambd daemon writes wtmp file - libvirt transitions to dmidecode- Add initial policy for system-setup-keyboard which is now daemon - Label /var/lock/subsys/shorewall as shorewall_lock_t - Allow users to communicate with the gpg_agent_t - Dontaudit mozilla_plugin_t using the inherited terminal - Allow sambagui to read files in /usr - webalizer manages squid log files - Allow unconfined domains to bind ports to raw_ip_sockets - Allow abrt to manage rpm logs when running yum - Need labels for /var/run/bittlebee - Label .ssh under amanda - Remove unused genrequires for virt_domain_template - Allow virt_domain to use fd inherited from virtd_t - Allow iptables to read shorewall config- Gnome apps list config_home_t - mpd creates lnk files in homedir - apache leaks write to mail apps on tmp files - /var/stockmaniac/templates_cache contains log files - Abrt list the connects of mount_tmp_t dirs - passwd agent reads files under /dev and reads utmp file - squid apache script connects to the squid port - fix name of plymouth log file - teamviewer is a wine app - allow dmesg to read system state - Stop labeling files under /var/lib/mock so restorecon will not go into this - nsplugin needs to read network state for google talk- Allow xdm and syslog to use /var/log/boot.log - Allow users to communicate with mozilla_plugin and kill it - Add labeling for ipv6 and dhcp- New labels for ghc http content - nsplugin_config needs to read urand, lvm now calls setfscreate to create dev - pm-suspend now creates log file for append access so we remove devicekit_wri - Change authlogin_use_sssd to authlogin_nsswitch_use_ldap - Fixes for greylist_milter policy- Update to upstream - Fixes for systemd policy - Fixes for passenger policy - Allow staff users to run mysqld in the staff_t domain, akonadi needs this - Add bin_t label for /usr/share/kde4/apps/kajongg/kajongg.py - auth_use_nsswitch does not need avahi to read passwords,needed for resolving data - Dontaudit (xdm_t) gok attempting to list contents of /var/account - Telepathy domains need to read urand - Need interface to getattr all file classes in a mock library for setroubleshoot- Update selinux policy to handle new /usr/share/sandbox/start script- Update to upstream - Fix version of policy in spec file- Allow sandbox to run on nfs partitions, fixes for systemd_tmpfs - remove per sandbox domains devpts types - Allow dkim-milter sending signal to itself- Allow domains that transition to ping or traceroute, kill them - Allow user_t to conditionally transition to ping_t and traceroute_t - Add fixes to systemd- tools, including new labeling for systemd-fsck, systemd-cryptsetup- Turn on systemd policy - mozilla_plugin needs to read certs in the homedir. - Dontaudit leaked file descriptors from devicekit - Fix ircssi to use auth_use_nsswitch - Change to use interface without param in corenet to disable unlabelednet packets - Allow init to relabel sockets and fifo files in /dev - certmonger needs dac* capabilities to manage cert files not owned by root - dovecot needs fsetid to change group membership on mail - plymouthd removes /var/log/boot.log - systemd is creating symlinks in /dev - Change label on /etc/httpd/alias to be all cert_t- Fixes for clamscan and boinc policy - Add boinc_project_t setpgid - Allow alsa to create tmp files in /tmp- Push fixes to allow disabling of unlabeled_t packet access - Enable unlabelednet policy- Fixes for lvm to work with systemd- Fix the label for wicd log - plymouthd creates force-display-on-active-vt file - Allow avahi to request the kernel to load a module - Dontaudit hal leaks - Fix gnome_manage_data interface - Add new interface corenet_packet to define a type as being an packet_type. - Removed general access to packet_type from icecast and squid. - Allow mpd to read alsa config - Fix the label for wicd log - Add systemd policy- Fix gnome_manage_data interface - Dontaudit sys_ptrace capability for iscsid - Fixes for nagios plugin policy- Fix cron to run ranged when started by init - Fix devicekit to use log files - Dontaudit use of devicekit_var_run_t for fstools - Allow init to setattr on logfile directories - Allow hald to manage files in /var/run/pm-utils/ dir which is now labeled as devicekit_var_run_t- Fix up handling of dnsmasq_t creating /var/run/libvirt/network - Turn on sshd_forward_ports boolean by default - Allow sysadmin to dbus chat with rpm - Add interface for rw_tpm_dev - Allow cron to execute bin - fsadm needs to write sysfs - Dontaudit consoletype reading /var/run/pm-utils - Lots of new privs fro mozilla_plugin_t running java app, make mozilla_plugin - certmonger needs to manage dirsrv data - /var/run/pm-utils should be labeled as devicekit_var_run_t- fixes to allow /var/run and /var/lock as tmpfs - Allow chrome sandbox to connect to web ports - Allow dovecot to listem on lmtp and sieve ports - Allov ddclient to search sysctl_net_t - Transition back to original domain if you execute the shell- Remove duplicate declaration- Update to upstream - Cleanup for sandbox - Add attribute to be able to select sandbox types- Allow ddclient to fix file mode bits of ddclient conf file - init leaks file descriptors to daemons - Add labels for /etc/lirc/ and - Allow amavis_t to exec shell - Add label for gssd_tmp_t for /var/tmp/nfs_0- Put back in lircd_etc_t so policy will install- Turn on allow_postfix_local_write_mail_spool - Allow initrc_t to transition to shutdown_t - Allow logwatch and cron to mls_read_to_clearance for MLS boxes - Allow wm to send signull to all applications and receive them from users - lircd patch from field - Login programs have to read /etc/samba - New programs under /lib/systemd - Abrt needs to read config files- Update to upstream - Dontaudit leaked sockets from userdomains to user domains - Fixes for mcelog to handle scripts - Apply patch from Ruben Kerkhof - Allow syslog to search spool dirs- Allow nagios plugins to read usr files - Allow mysqld-safe to send system log messages - Fixes fpr ddclient policy - Fix sasl_admin interface - Allow apache to search zarafa config - Allow munin plugins to search /var/lib directory - Allow gpsd to read sysfs_t - Fix labels on /etc/mcelog/triggers to bin_t- Remove saslauthd_tmp_t and transition tmp files to krb5_host_rcache_t - Allow saslauthd_t to create krb5_host_rcache_t files in /tmp - Fix xserver interface - Fix definition of /var/run/lxdm- Turn on mediawiki policy - kdump leaks kdump_etc_t to ifconfig, add dontaudit - uux needs to transition to uucpd_t - More init fixes relabels man,faillog - Remove maxima defs in libraries.fc - insmod needs to be able to create tmpfs_t files - ping needs setcap- Allow groupd transition to fenced domain when executes fence_node - Fixes for rchs policy - Allow mpd to be able to read samba/nfs files- Fix up corecommands.fc to match upstream - Make sure /lib/systemd/* is labeled init_exec_t - mount wants to setattr on all mountpoints - dovecot auth wants to read dovecot etc files - nscd daemon looks at the exe file of the comunicating daemon - openvpn wants to read utmp file - postfix apps now set sys_nice and lower limits - remote_login (telnetd/login) wants to use telnetd_devpts_t and user_devpts_t to work correctly - Also resolves nsswitch - Fix labels on /etc/hosts.* - Cleanup to make upsteam patch work - allow abrt to read etc_runtime_t- Add conflicts for dirsrv package- Update to upstream - Add vlock policy- Fix sandbox to work on nfs homedirs - Allow cdrecord to setrlimit - Allow mozilla_plugin to read xauth - Change label on systemd-logger to syslogd_exec_t - Install dirsrv policy from dirsrv package- Add virt_home_t, allow init to setattr on xserver_tmp_t and relabel it - Udev needs to stream connect to init and kernel - Add xdm_exec_bootloader boolean, which allows xdm to execute /sbin/grub and read files in /boot directory- Allow NetworkManager to read openvpn_etc_t - Dontaudit hplip to write of /usr dirs - Allow system_mail_t to create /root/dead.letter as mail_home_t - Add vdagent policy for spice agent daemon- Dontaudit sandbox sending sigkill to all user domains - Add policy for rssh_chroot_helper - Add missing flask definitions - Allow udev to relabelto removable_t - Fix label on /var/log/wicd.log - Transition to initrc_t from init when executing bin_t - Add audit_access permissions to file - Make removable_t a device_node - Fix label on /lib/systemd/*- Fixes for systemd to manage /var/run - Dontaudit leaks by firstboot- Allow chome to create netlink_route_socket - Add additional MATHLAB file context - Define nsplugin as an application_domain - Dontaudit sending signals from sandboxed domains to other domains - systemd requires init to build /tmp /var/auth and /var/lock dirs - mount wants to read devicekit_power /proc/ entries - mpd wants to connect to soundd port - Openoffice causes a setattr on a lib_t file for normal users, add dontaudit - Treat lib_t and textrel_shlib_t directories the same - Allow mount read access on virtual images- Allow sandbox_x_domains to work with nfs/cifs/fusefs home dirs. - Allow devicekit_power to domtrans to mount - Allow dhcp to bind to udp ports > 1024 to do named stuff - Allow ssh_t to exec ssh_exec_t - Remove telepathy_butterfly_rw_tmp_files(), dev_read_printk() interfaces which are nolonger used - Fix clamav_append_log() intefaces - Fix 'psad_rw_fifo_file' interface- Allow cobblerd to list cobler appache content- Fixup for the latest version of upowed - Dontaudit sandbox sending SIGNULL to desktop apps- Update to upstream-Mount command from a confined user generates setattr on /etc/mtab file, need to dontaudit this access - dovecot-auth_t needs ipc_lock - gpm needs to use the user terminal - Allow system_mail_t to append ~/dead.letter - Allow NetworkManager to edit /etc/NetworkManager/NetworkManager.conf - Add pid file to vnstatd - Allow mount to communicate with gfs_controld - Dontaudit hal leaks in setfiles- Lots of fixes for systemd - systemd now executes readahead and tmpwatch type scripts - Needs to manage random seed- Allow smbd to use sys_admin - Remove duplicate file context for tcfmgr - Update to upstream- Fix fusefs handling - Do not allow sandbox to manage nsplugin_rw_t - Allow mozilla_plugin_t to connecto its parent - Allow init_t to connect to plymouthd running as kernel_t - Add mediawiki policy - dontaudit sandbox sending signals to itself. This can happen when they are running at different mcs. - Disable transition from dbus_session_domain to telepathy for F14 - Allow boinc_project to use shm - Allow certmonger to search through directories that contain certs - Allow fail2ban the DAC Override so it can read log files owned by non root users- Start adding support for use_fusefs_home_dirs - Add /var/lib/syslog directory file context - Add /etc/localtime as locale file context- Turn off default transition to mozilla_plugin and telepathy domains from unconfined user - Turn off iptables from unconfined user - Allow sudo to send signals to any domains the user could have transitioned to. - Passwd in single user mode needs to talk to console_device_t - Mozilla_plugin_t needs to connect to web ports, needs to write to video device, and read alsa_home_t alsa setsup pulseaudio - locate tried to read a symbolic link, will dontaudit - New labels for telepathy-sunshine content in homedir - Google is storing other binaries under /opt/google/talkplugin - bluetooth/kernel is creating unlabeled_t socket that I will allow it to use until kernel fixes bug - Add boolean for unconfined_t transition to mozilla_plugin_t and telepathy domains, turned off in F14 on in F15 - modemmanger and bluetooth send dbus messages to devicekit_power - Samba needs to getquota on filesystems labeld samba_share_t- Dontaudit attempts by xdm_t to write to bin_t for kdm - Allow initrc_t to manage system_conf_t- Fixes to allow mozilla_plugin_t to create nsplugin_home_t directory. - Allow mozilla_plugin_t to create tcp/udp/netlink_route sockets - Allow confined users to read xdm_etc_t files - Allow xdm_t to transition to xauth_t for lxdm program- Rearrange firewallgui policy to be more easily updated to upstream, dontaudit search of /home - Allow clamd to send signals to itself - Allow mozilla_plugin_t to read user home content. And unlink pulseaudio shm. - Allow haze to connect to yahoo chat and messenger port tcp:5050. Bz #637339 - Allow guest to run ps command on its processes by allowing it to read /proc - Allow firewallgui to sys_rawio which seems to be required to setup masqerading - Allow all domains to search through default_t directories, in order to find differnet labels. For example people serring up /foo/bar to be share via samba. - Add label for /var/log/slim.log- Pull in cleanups from dgrift - Allow mozilla_plugin_t to execute mozilla_home_t - Allow rpc.quota to do quotamod- Cleanup policy via dgrift - Allow dovecot_deliver to append to inherited log files - Lots of fixes for consolehelper- Fix up Xguest policy- Add vnstat policy - allow libvirt to send audit messages - Allow chrome-sandbox to search nfs_t- Update to upstream- Add the ability to send audit messages to confined admin policies - Remove permissive domain from cmirrord and dontaudit sys_tty_config - Split out unconfined_domain() calls from other unconfined_ calls so we can d - virt needs to be able to read processes to clearance for MLS- Allow all domains that can use cgroups to search tmpfs_t directory - Allow init to send audit messages- Update to upstream- Allow mdadm_t to create files and sock files in /dev/md/- Add policy for ajaxterm- Handle /var/db/sudo - Allow pulseaudio to read alsa config - Allow init to send initrc_t dbus messagesAllow iptables to read shorewall tmp files Change chfn and passwd to use auth_use_pam so they can send dbus messages to fpr intd label vlc as an execmem_exec_t Lots of fixes for mozilla_plugin to run google vidio chat Allow telepath_msn to execute ldconfig and its own tmp files Fix labels on hugepages Allow mdadm to read files on /dev Remove permissive domains and change back to unconfined Allow freshclam to execute shell and bin_t Allow devicekit_power to transition to dhcpc Add boolean to allow icecast to connect to any port- Merge upstream fix of mmap_zero - Allow mount to write files in debugfs_t - Allow corosync to communicate with clvmd via tmpfs - Allow certmaster to read usr_t files - Allow dbus system services to search cgroup_t - Define rlogind_t as a login pgm- Allow mdadm_t to read/write hugetlbfs- Dominic Grift Cleanup - Miroslav Grepl policy for jabberd - Various fixes for mount/livecd and prelink- Merge with upstream- More access needed for devicekit - Add dbadm policy- Merge with upstream- Allow seunshare to fowner- Allow cron to look at user_cron_spool links - Lots of fixes for mozilla_plugin_t - Add sysv file system - Turn unconfined domains to permissive to find additional avcs- Update policy for mozilla_plugin_t- Allow clamscan to read proc_t - Allow mount_t to write to debufs_t dir - Dontaudit mount_t trying to write to security_t dir- Allow clamscan_t execmem if clamd_use_jit set - Add policy for firefox plugin-container- Fix /root/.forward definition- label dead.letter as mail_home_t- Allow login programs to search /cgroups- Fix cert handling- Fix devicekit_power bug - Allow policykit_auth_t more access.- Fix nis calls to allow bind to ports 512-1024 - Fix smartmon- Allow pcscd to read sysfs - systemd fixes - Fix wine_mmap_zero_ignore boolean- Apply Miroslav munin patch - Turn back on allow_execmem and allow_execmod booleans- Merge in fixes from dgrift repository- Update boinc policy - Fix sysstat policy to allow sys_admin - Change failsafe_context to unconfined_r:unconfined_t:s0- New paths for upstart- New permissions for syslog - New labels for /lib/upstart- Add mojomojo policy- Allow systemd to setsockcon on sockets to immitate other services- Remove debugfs label- Update to latest policy- Fix eclipse labeling from IBMSupportAssasstant packageing- Make boot with systemd in enforcing mode- Update to upstream- Add boolean to turn off port forwarding in sshd.- Add support for ebtables - Fixes for rhcs and corosync policy-Update to upstream-Update to upstream-Update to upstream- Add Zarafa policy- Cleanup of aiccu policy - initial mock policy- Lots of random fixes- Update to upstream- Update to upstream - Allow prelink script to signal itself - Cobbler fixes- Add xdm_var_run_t to xserver_stream_connect_xdm - Add cmorrord and mpd policy from Miroslav Grepl- Fix sshd creation of krb cc files for users to be user_tmp_t- Fixes for accountsdialog - Fixes for boinc- Fix label on /var/lib/dokwiki - Change permissive domains to enforcing - Fix libvirt policy to allow it to run on mls- Update to upstream- Allow procmail to execute scripts in the users home dir that are labeled home_bin_t - Fix /var/run/abrtd.lock label- Allow login programs to read krb5_home_t Resolves: 594833 - Add obsoletes for cachefilesfd-selinux package Resolves: #575084- Allow mount to r/w abrt fifo file - Allow svirt_t to getattr on hugetlbfs - Allow abrt to create a directory under /var/spool- Add labels for /sys - Allow sshd to getattr on shutdown - Fixes for munin - Allow sssd to use the kernel key ring - Allow tor to send syslog messages - Allow iptabels to read usr files - allow policykit to read all domains state- Fix path for /var/spool/abrt - Allow nfs_t as an entrypoint for http_sys_script_t - Add policy for piranha - Lots of fixes for sosreport- Allow xm_t to read network state and get and set capabilities - Allow policykit to getattr all processes - Allow denyhosts to connect to tcp port 9911 - Allow pyranha to use raw ip sockets and ptrace itself - Allow unconfined_execmem_t and gconfsd mechanism to dbus - Allow staff to kill ping process - Add additional MLS rules- Allow gdm to edit ~/.gconf dir Resolves: #590677 - Allow dovecot to create directories in /var/lib/dovecot Partially resolves 590224 - Allow avahi to dbus chat with NetworkManager - Fix cobbler labels - Dontaudit iceauth_t leaks - fix /var/lib/lxdm file context - Allow aiccu to use tun tap devices - Dontaudit shutdown using xserver.log- Fixes for sandbox_x_net_t to match access for sandbox_web_t ++ - Add xdm_etc_t for /etc/gdm directory, allow accountsd to manage this directory - Add dontaudit interface for bluetooth dbus - Add chronyd_read_keys, append_keys for initrc_t - Add log support for ksmtuned Resolves: #586663- Allow boinc to send mail- Allow initrc_t to remove dhcpc_state_t - Fix label on sa-update.cron - Allow dhcpc to restart chrony initrc - Don't allow sandbox to send signals to its parent processes - Fix transition from unconfined_t -> unconfined_mount_t -> rpcd_t Resolves: #589136- Fix location of oddjob_mkhomedir Resolves: #587385 - fix labeling on /root/.shosts and ~/.shosts - Allow ipsec_mgmt_t to manage net_conf_t Resolves: #586760- Dontaudit sandbox trying to connect to netlink sockets Resolves: #587609 - Add policy for piranha- Fixups for xguest policy - Fixes for running sandbox firefox- Allow ksmtuned to use terminals Resolves: #586663 - Allow lircd to write to generic usb devices- Allow sandbox_xserver to connectto unconfined stream Resolves: #585171- Allow initrc_t to read slapd_db_t Resolves: #585476 - Allow ipsec_mgmt to use unallocated devpts and to create /etc/resolv.conf Resolves: #585963- Allow rlogind_t to search /root for .rhosts Resolves: #582760 - Fix path for cached_var_t - Fix prelink paths /var/lib/prelink - Allow confined users to direct_dri - Allow mls lvm/cryptosetup to work- Allow virtd_t to manage firewall/iptables config Resolves: #573585- Fix label on /root/.rhosts Resolves: #582760 - Add labels for Picasa - Allow openvpn to read home certs - Allow plymouthd_t to use tty_device_t - Run ncftool as iptables_t - Allow mount to unmount unlabeled_t - Dontaudit hal leaks- Allow livecd to transition to mount- Update to upstream - Allow abrt to delete sosreport Resolves: #579998 - Allow snmp to setuid and gid Resolves: #582155 - Allow smartd to use generic scsi devices Resolves: #582145- Allow ipsec_t to create /etc/resolv.conf with the correct label - Fix reserved port destination - Allow autofs to transition to showmount - Stop crashing tuned- Add telepathysofiasip policy- Update to upstream - Fix label for /opt/google/chrome/chrome-sandbox - Allow modemmanager to dbus with policykit- Fix allow_httpd_mod_auth_pam to use auth_use_pam(httpd_t) - Allow accountsd to read shadow file - Allow apache to send audit messages when using pam - Allow asterisk to bind and connect to sip tcp ports - Fixes for dovecot 2.0 - Allow initrc_t to setattr on milter directories - Add procmail_home_t for .procmailrc file- Fixes for labels during install from livecd- Fix /cgroup file context - Fix broken afs use of unlabled_t - Allow getty to use the console for s390- Fix cgroup handling adding policy for /cgroup - Allow confined users to write to generic usb devices, if user_rw_noexattrfile boolean set- Merge patches from dgrift- Update upstream - Allow abrt to write to the /proc under any process- Fix ~/.fontconfig label - Add /root/.cert label - Allow reading of the fixed_file_disk_t:lnk_file if you can read file - Allow qemu_exec_t as an entrypoint to svirt_t- Update to upstream - Allow tmpreaper to delete sandbox sock files - Allow chrome-sandbox_t to use /dev/zero, and dontaudit getattr file systems - Fixes for gitosis - No transition on livecd to passwd or chfn - Fixes for denyhosts- Add label for /var/lib/upower - Allow logrotate to run sssd - dontaudit readahead on tmpfs blk files - Allow tmpreaper to setattr on sandbox files - Allow confined users to execute dos files - Allow sysadm_t to kill processes running within its clearance - Add accountsd policy - Fixes for corosync policy - Fixes from crontab policy - Allow svirt to manage svirt_image_t chr files - Fixes for qdisk policy - Fixes for sssd policy - Fixes for newrole policy- make libvirt work on an MLS platform- Add qpidd policy- Update to upstream- Allow boinc to read kernel sysctl - Fix snmp port definitions - Allow apache to read anon_inodefs- Allow shutdown dac_override- Add device_t as a file system - Fix sysfs association- Dontaudit ipsec_mgmt sys_ptrace - Allow at to mail its spool files - Allow nsplugin to search in .pulse directory- Update to upstream- Allow users to dbus chat with xdm - Allow users to r/w wireless_device_t - Dontaudit reading of process states by ipsec_mgmt- Fix openoffice from unconfined_t- Add shutdown policy so consolekit can shutdown system- Update to upstream- Update to upstream- Update to upstream - These are merges of my patches - Remove 389 labeling conflicts - Add MLS fixes found in RHEL6 testing - Allow pulseaudio to run as a service - Add label for mssql and allow apache to connect to this database port if boolean set - Dontaudit searches of debugfs mount point - Allow policykit_auth to send signals to itself - Allow modcluster to call getpwnam - Allow swat to signal winbind - Allow usbmux to run as a system role - Allow svirt to create and use devpts- Add MLS fixes found in RHEL6 testing - Allow domains to append to rpm_tmp_t - Add cachefilesfd policy - Dontaudit leaks when transitioning- Change allow_execstack and allow_execmem booleans to on - dontaudit acct using console - Add label for fping - Allow tmpreaper to delete sandbox_file_t - Fix wine dontaudit mmap_zero - Allow abrt to read var_t symlinks- Additional policy for rgmanager- Allow sshd to setattr on pseudo terms- Update to upstream- Allow policykit to send itself signals- Fix duplicate cobbler definition- Fix file context of /var/lib/avahi-autoipd- Merge with upstream- Allow sandbox to work with MLS- Make Chrome work with staff user- Add icecast policy - Cleanup spec file- Add mcelog policy- Lots of fixes found in F12- Fix rpm_dontaudit_leaks- Add getsched to hald_t - Add file context for Fedora/Redhat Directory Server- Allow abrt_helper to getattr on all filesystems - Add label for /opt/real/RealPlayer/plugins/oggfformat\.so- Add gstreamer_home_t for ~/.gstreamer- Update to upstream- Fix git- Turn on puppet policy - Update to dgrift git policy- Move users file to selection by spec file. - Allow vncserver to run as unconfined_u:unconfined_r:unconfined_t- Update to upstream- Remove most of the permissive domains from F12.- Add cobbler policy from dgrift- add usbmon device - Add allow rulse for devicekit_disk- Lots of fixes found in F12, fixes from Tom London- Cleanups from dgrift- Add back xserver_manage_home_fonts- Dontaudit sandbox trying to read nscd and sssd- Update to upstream- Rename udisks-daemon back to devicekit_disk_t policy- Fixes for abrt calls- Add tgtd policy- Update to upstream release- Add asterisk policy back in - Update to upstream release 2.20091117- Update to upstream release 2.20091117- Fixup nut policy- Update to upstream- Allow vpnc request the kernel to load modules- Fix minimum policy installs - Allow udev and rpcbind to request the kernel to load modules- Add plymouth policy - Allow local_login to sys_admin- Allow cupsd_config to read user tmp - Allow snmpd_t to signal itself - Allow sysstat_t to makedir in sysstat_log_t- Update rhcs policy- Allow users to exec restorecond- Allow sendmail to request kernel modules load- Fix all kernel_request_load_module domains- Fix all kernel_request_load_module domains- Remove allow_exec* booleans for confined users. Only available for unconfined_t- More fixes for sandbox_web_t- Allow sshd to create .ssh directory and content- Fix request_module line to module_request- Fix sandbox policy to allow it to run under firefox. - Dont audit leaks.- Fixes for sandbox- Update to upstream - Dontaudit nsplugin search /root - Dontaudit nsplugin sys_nice- Fix label on /usr/bin/notepad, /usr/sbin/vboxadd-service - Remove policycoreutils-python requirement except for minimum- Fix devicekit_disk_t to getattr on all domains sockets and fifo_files - Conflicts seedit (You can not use selinux-policy-targeted and seedit at the same time.)- Add wordpress/wp-content/uploads label - Fixes for sandbox when run from staff_t- Update to upstream - Fixes for devicekit_disk- More fixes- Lots of fixes for initrc and other unconfined domains- Allow xserver to use netlink_kobject_uevent_socket- Fixes for sandbox- Dontaudit setroubleshootfix looking at /root directory- Update to upsteam- Allow gssd to send signals to users - Fix duplicate label for apache content- Update to upstream- Remove polkit_auth on upgrades- Add back in unconfined.pp and unconfineduser.pp - Add Sandbox unshare- Fixes for cdrecord, mdadm, and others- Add capability setting to dhcpc and gpm- Allow cronjobs to read exim_spool_t- Add ABRT policy- Fix system-config-services policy- Allow libvirt to change user componant of virt_domain- Allow cupsd_config_t to be started by dbus - Add smoltclient policy- Add policycoreutils-python to pre install- Make all unconfined_domains permissive so we can see what AVC's happen- Add pt_chown policy- Add kdump policy for Miroslav Grepl - Turn off execstack boolean- Turn on execstack on a temporary basis (#512845)- Allow nsplugin to connecto the session bus - Allow samba_net to write to coolkey data- Allow devicekit_disk to list inotify- Allow svirt images to create sock_file in svirt_var_run_t- Allow exim to getattr on mountpoints - Fixes for pulseaudio- Allow svirt_t to stream_connect to virtd_t- Allod hald_dccm_t to create sock_files in /tmp- More fixes from upstream- Fix polkit label - Remove hidebrokensymptoms for nss_ldap fix - Add modemmanager policy - Lots of merges from upstream - Begin removing textrel_shlib_t labels, from fixed libraries- Update to upstream- Allow certmaster to override dac permissions- Update to upstream- Fix context for VirtualBox- Update to upstream- Allow clamscan read amavis spool files- Fixes for xguest- fix multiple directory ownership of mandirs- Update to upstream- Add rules for rtkit-daemon- Update to upstream - Fix nlscd_stream_connect- Add rtkit policy- Allow rpcd_t to stream connect to rpcbind- Allow kpropd to create tmp files- Fix last duplicate /var/log/rpmpkgs- Update to upstream * add sssd- Update to upstream * cleanup- Update to upstream - Additional mail ports - Add virt_use_usb boolean for svirt- Fix mcs rules to include chr_file and blk_file- Add label for udev-acl- Additional rules for consolekit/udev, privoxy and various other fixes- New version for upstream- Allow NetworkManager to read inotifyfs- Allow setroubleshoot to run mlocate- Update to upstream- Add fish as a shell - Allow fprintd to list usbfs_t - Allow consolekit to search mountpoints - Add proper labeling for shorewall- New log file for vmware - Allow xdm to setattr on user_tmp_t- Upgrade to upstream- Allow fprintd to access sys_ptrace - Add sandbox policy- Add varnishd policy- Fixes for kpropd- Allow brctl to r/w tun_tap_device_t- Add /usr/share/selinux/packages- Allow rpcd_t to send signals to kernel threads- Fix upgrade for F10 to F11- Add policy for /var/lib/fprint-Remove duplicate line- Allow svirt to manage pci and other sysfs device data- Fix package selection handling- Fix /sbin/ip6tables-save context - Allod udev to transition to mount - Fix loading of mls policy file- Add shorewall policy- Additional rules for fprintd and sssd- Allow nsplugin to unix_read unix_write sem for unconfined_java- Fix uml files to be owned by users- Fix Upgrade path to install unconfineduser.pp when unocnfined package is 3.0.0 or less- Allow confined users to manage virt_content_t, since this is home dir content - Allow all domains to read rpm_script_tmp_t which is what shell creates on redirection- Fix labeling on /var/lib/misc/prelink* - Allow xserver to rw_shm_perms with all x_clients - Allow prelink to execute files in the users home directory- Allow initrc_t to delete dev_null - Allow readahead to configure auditing - Fix milter policy - Add /var/lib/readahead- Update to latest milter code from Paul Howarth- Additional perms for readahead- Allow pulseaudio to acquire_svc on session bus - Fix readahead labeling- Allow sysadm_t to run rpm directly - libvirt needs fowner- Allow sshd to read var_lib symlinks for freenx- Allow nsplugin unix_read and write on users shm and sem - Allow sysadm_t to execute su- Dontaudit attempts to getattr user_tmpfs_t by lvm - Allow nfs to share removable media- Add ability to run postdrop from confined users- Fixes for podsleuth- Turn off nsplugin transition - Remove Konsole leaked file descriptors for release- Allow cupsd_t to create link files in print_spool_t - Fix iscsi_stream_connect typo - Fix labeling on /etc/acpi/actions - Don't reinstall unconfine and unconfineuser on upgrade if they are not installed- Allow audioentroy to read etc files- Add fail2ban_var_lib_t - Fixes for devicekit_power_t- Separate out the ucnonfined user from the unconfined.pp package- Make sure unconfined_java_t and unconfined_mono_t create user_tmpfs_t.- Upgrade to latest upstream - Allow devicekit_disk sys_rawio- Dontaudit binds to ports < 1024 for named - Upgrade to latest upstream- Allow podsleuth to use tmpfs files- Add customizable_types for svirt- Allow setroubelshoot exec* privs to prevent crash from bad libraries - add cpufreqselector- Dontaudit listing of /root directory for cron system jobs- Fix missing ld.so.cache label- Add label for ~/.forward and /root/.forward- Fixes for svirt- Fixes to allow svirt read iso files in homedir- Add xenner and wine fixes from mgrepl- Allow mdadm to read/write mls override- Change to svirt to only access svirt_image_t- Fix libvirt policy- Upgrade to latest upstream- Fixes for iscsid and sssd - More cleanups for upgrade from F10 to Rawhide.- Add pulseaudio, sssd policy - Allow networkmanager to exec udevadm- Add pulseaudio context- Upgrade to latest patches- Fixes for libvirt- Update to Latest upstream- Fix setrans.conf to show SystemLow for s0- Further confinement of qemu images via svirt- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- Allow NetworkManager to manage /etc/NetworkManager/system-connections- add virtual_image_context and virtual_domain_context files- Allow rpcd_t to send signal to mount_t - Allow libvirtd to run ranged- Fix sysnet/net_conf_t- Fix squidGuard labeling- Re-add corenet_in_generic_if(unlabeled_t)* Tue Feb 10 2009 Dan Walsh 3.6.5-2 - Add git web policy- Add setrans contains from upstream- Do transitions outside of the booleans- Allow xdm to create user_tmp_t sockets for switch user to work- Fix staff_t domain- Grab remainder of network_peer_controls patch- More fixes for devicekit- Upgrade to latest upstream- Add boolean to disallow unconfined_t login- Add back transition from xguest to mozilla- Add virt_content_ro_t and labeling for isos directory- Fixes for wicd daemon- More mls/rpm fixes- Add policy to make dbus/nm-applet work- Remove polgen-ifgen from post and add trigger to policycoreutils-python- Add wm policy - Make mls work in graphics mode- Fixed for DeviceKit- Add devicekit policy- Update to upstream- Define openoffice as an x_domain- Fixes for reading xserver_tmp_t- Allow cups_pdf_t write to nfs_t- Remove audio_entropy policy- Update to upstream- Allow hal_acl_t to getattr/setattr fixed_disk- Change userdom_read_all_users_state to include reading symbolic links in /proc- Fix dbus reading /proc information- Add missing alias for home directory content- Fixes for IBM java location- Allow unconfined_r unconfined_java_t- Add cron_role back to user domains- Fix sudo setting of user keys- Allow iptables to talk to terminals - Fixes for policy kit - lots of fixes for booting.- Cleanup policy- Rebuild for Python 2.6- Fix labeling on /var/spool/rsyslog- Allow postgresl to bind to udp nodes- Allow lvm to dbus chat with hal - Allow rlogind to read nfs_t- Fix cyphesis file context- Allow hal/pm-utils to look at /var/run/video.rom - Add ulogd policy- Additional fixes for cyphesis - Fix certmaster file context - Add policy for system-config-samba - Allow hal to read /var/run/video.rom- Allow dhcpc to restart ypbind - Fixup labeling in /var/run- Add certmaster policy- Fix confined users - Allow xguest to read/write xguest_dbusd_t- Allow openoffice execstack/execmem privs- Allow mozilla to run with unconfined_execmem_t- Dontaudit domains trying to write to .xsession-errors- Allow nsplugin to look at autofs_t directory- Allow kerneloops to create tmp files- More alias for fastcgi- Remove mod_fcgid-selinux package- Fix dovecot access- Policy cleanup- Remove Multiple spec - Add include - Fix makefile to not call per_role_expansion- Fix labeling of libGL- Update to upstream- Update to upstream policy- Fixes for confined xwindows and xdm_t- Allow confined users and xdm to exec wm - Allow nsplugin to talk to fifo files on nfs- Allow NetworkManager to transition to avahi and iptables - Allow domains to search other domains keys, coverup kernel bug- Fix labeling for oracle- Allow nsplugin to comminicate with xdm_tmp_t sock_file- Change all user tmpfs_t files to be labeled user_tmpfs_t - Allow radiusd to create sock_files- Upgrade to upstream- Allow confined users to login with dbus- Fix transition to nsplugin- Add file context for /dev/mspblk.*- Fix transition to nsplugin '- Fix labeling on new pm*log - Allow ssh to bind to all nodes- Merge upstream changes - Add Xavier Toth patches- Add qemu_cache_t for /var/cache/libvirt- Remove gamin policy- Add tinyxs-max file system support- Update to upstream - New handling of init scripts- Allow pcsd to dbus - Add memcache policy- Allow audit dispatcher to kill his children- Update to upstream - Fix crontab use by unconfined user- Allow ifconfig_t to read dhcpc_state_t- Update to upstream- Update to upstream- Allow system-config-selinux to work with policykit- Fix novel labeling- Consolodate pyzor,spamassassin, razor into one security domain - Fix xdm requiring additional perms.- Fixes for logrotate, alsa- Eliminate vbetool duplicate entry- Fix xguest -> xguest_mozilla_t -> xguest_openiffice_t - Change dhclient to be able to red networkmanager_var_run- Update to latest refpolicy - Fix libsemanage initial install bug- Add inotify support to nscd- Allow unconfined_t to setfcap- Allow amanda to read tape - Allow prewikka cgi to use syslog, allow audisp_t to signal cgi - Add support for netware file systems- Allow ypbind apps to net_bind_service- Allow all system domains and application domains to append to any log file- Allow gdm to read rpm database - Allow nsplugin to read mplayer config files- Allow vpnc to run ifconfig- Allow confined users to use postgres - Allow system_mail_t to exec other mail clients - Label mogrel_rails as an apache server- Apply unconfined_execmem_exec_t to haskell programs- Fix prelude file context- allow hplip to talk dbus - Fix context on ~/.local dir- Prevent applications from reading x_device- Add /var/lib/selinux context- Update to upstream- Add livecd policy- Dontaudit search of admin_home for init_system_domain - Rewrite of xace interfaces - Lots of new fs_list_inotify - Allow livecd to transition to setfiles_mac- Begin XAce integration- Merge Upstream- Allow amanada to create data files- Fix initial install, semanage setup- Allow system_r for httpd_unconfined_script_t- Remove dmesg boolean - Allow user domains to read/write game data- Change unconfined_t to transition to unconfined_mono_t when running mono - Change XXX_mono_t to transition to XXX_t when executing bin_t files, so gnome-do will work- Remove old booleans from targeted-booleans.conf file- Add boolean to mmap_zero - allow tor setgid - Allow gnomeclock to set clock- Don't run crontab from unconfined_t- Change etc files to config files to allow users to read them- Lots of fixes for confined domains on NFS_t homedir- dontaudit mrtg reading /proc - Allow iscsi to signal itself - Allow gnomeclock sys_ptrace- Allow dhcpd to read kernel network state- Label /var/run/gdm correctly - Fix unconfined_u user creation- Allow transition from initrc_t to getty_t- Allow passwd to communicate with user sockets to change gnome-keyring- Fix initial install- Allow radvd to use fifo_file - dontaudit setfiles reading links - allow semanage sys_resource - add allow_httpd_mod_auth_ntlm_winbind boolean - Allow privhome apps including dovecot read on nfs and cifs home dirs if the boolean is set- Allow nsplugin to read /etc/mozpluggerrc, user_fonts - Allow syslog to manage innd logs. - Allow procmail to ioctl spamd_exec_t- Allow initrc_t to dbus chat with consolekit.- Additional access for nsplugin - Allow xdm setcap/getcap until pulseaudio is fixed- Allow mount to mkdir on tmpfs - Allow ifconfig to search debugfs- Fix file context for MATLAB - Fixes for xace- Allow stunnel to transition to inetd children domains - Make unconfined_dbusd_t an unconfined domain- Fixes for qemu/virtd- Fix bug in mozilla policy to allow xguest transition - This will fix the libsemanage.dbase_llist_query: could not find record value libsemanage.dbase_llist_query: could not query record value (No such file or directory) bug in xguest- Allow nsplugin to run acroread- Add cups_pdf policy - Add openoffice policy to run in xguest- prewika needs to contact mysql - Allow syslog to read system_map files- Change init_t to an unconfined_domain- Allow init to transition to initrc_t on shell exec. - Fix init to be able to sendto init_t. - Allow syslog to connect to mysql - Allow lvm to manage its own fifo_files - Allow bugzilla to use ldap - More mls fixes- fixes for init policy (#436988) - fix build- Additional changes for MLS policy- Fix initrc_context generation for MLS- Fixes for libvirt- Allow bitlebee to read locale_t- More xselinux rules- Change httpd_$1_script_r*_t to httpd_$1_content_r*_t- Prepare policy for beta release - Change some of the system domains back to unconfined - Turn on some of the booleans- Allow nsplugin_config execstack/execmem - Allow nsplugin_t to read alsa config - Change apache to use user content- Add cyphesis policy- Fix Makefile.devel to build mls modules - Fix qemu to be more specific on labeling- Update to upstream fixes- Allow staff to mounton user_home_t- Add xace support- Add fusectl file system- Fixes from yum-cron - Update to latest upstream- Fix userdom_list_user_files- Merge with upstream- Allow udev to send audit messages- Add additional login users interfaces - userdom_admin_login_user_template(staff)- More fixes for polkit- Eliminate transition from unconfined_t to qemu by default - Fixes for gpg- Update to upstream- Fixes for staff_t- Add policy for kerneloops - Add policy for gnomeclock- Fixes for libvirt- Fixes for nsplugin- More fixes for qemu- Additional ports for vnc and allow qemu and libvirt to search all directories- Update to upstream - Add libvirt policy - add qemu policy- Allow fail2ban to create a socket in /var/run- Allow allow_httpd_mod_auth_pam to work- Add audisp policy and prelude- Allow all user roles to executae samba net command- Allow usertypes to read/write noxattr file systems- Fix nsplugin to allow flashplugin to work in enforcing mode- Allow pam_selinux_permit to kill all processes- Allow ptrace or user processes by users of same type - Add boolean for transition to nsplugin- Allow nsplugin sys_nice, getsched, setsched- Allow login programs to talk dbus to oddjob- Add procmail_log support - Lots of fixes for munin- Allow setroubleshoot to read policy config and send audit messages- Allow users to execute all files in homedir, if boolean set - Allow mount to read samba config- Fixes for xguest to run java plugin- dontaudit pam_t and dbusd writing to user_home_t- Update gpg to allow reading of inotify- Change user and staff roles to work correctly with varied perms- Fix munin log, - Eliminate duplicate mozilla file context - fix wpa_supplicant spec- Fix role transition from unconfined_r to system_r when running rpm - Allow unconfined_domains to communicate with user dbus instances- Fixes for xguest- Let all uncofined domains communicate with dbus unconfined- Run rpm in system_r- Zero out customizable types- Fix definiton of admin_home_t- Fix munin file context- Allow cron to run unconfined apps- Modify default login to unconfined_u- Dontaudit dbus user client search of /root- Update to upstream- Fixes for polkit - Allow xserver to ptrace- Add polkit policy - Symplify userdom context, remove automatic per_role changes- Update to upstream - Allow httpd_sys_script_t to search users homedirs- Allow rpm_script to transition to unconfined_execmem_t- Remove user based home directory separation- Remove user specific crond_t- Merge with upstream - Allow xsever to read hwdata_t - Allow login programs to setkeycreate- Update to upstream- Update to upstream- Allow XServer to read /proc/self/cmdline - Fix unconfined cron jobs - Allow fetchmail to transition to procmail - Fixes for hald_mac - Allow system_mail to transition to exim - Allow tftpd to upload files - Allow xdm to manage unconfined_tmp - Allow udef to read alsa config - Fix xguest to be able to connect to sound port- Fixes for hald_mac - Treat unconfined_home_dir_t as a home dir - dontaudit rhgb writes to fonts and root- Fix dnsmasq - Allow rshd full login privs- Allow rshd to connect to ports > 1023- Fix vpn to bind to port 4500 - Allow ssh to create shm - Add Kismet policy- Allow rpm to chat with networkmanager- Fixes for ipsec and exim mail - Change default to unconfined user- Pass the UNK_PERMS param to makefile - Fix gdm location- Make alsa work- Fixes for consolekit and startx sessions- Dontaudit consoletype talking to unconfined_t- Remove homedir_template- Check asound.state- Fix exim policy- Allow tmpreadper to read man_t - Allow racoon to bind to all nodes - Fixes for finger print reader- Allow xdm to talk to input device (fingerprint reader) - Allow octave to run as java- Allow login programs to set ioctl on /proc- Allow nsswitch apps to read samba_var_t- Fix maxima- Eliminate rpm_t:fifo_file avcs - Fix dbus path for helper app- Fix service start stop terminal avc's- Allow also to search var_lib - New context for dbus launcher- Allow cupsd_config_t to read/write usb_device_t - Support for finger print reader, - Many fixes for clvmd - dbus starting networkmanager- Fix java and mono to run in xguest account- Fix to add xguest account when inititial install - Allow mono, java, wine to run in userdomains- Allow xserver to search devpts_t - Dontaudit ldconfig output to homedir- Remove hplip_etc_t change back to etc_t.- Allow cron to search nfs and samba homedirs- Allow NetworkManager to dbus chat with yum-updated- Allow xfs to bind to port 7100- Allow newalias/sendmail dac_override - Allow bind to bind to all udp ports- Turn off direct transition- Allow wine to run in system role- Fix java labeling- Define user_home_type as home_type- Allow sendmail to create etc_aliases_t- Allow login programs to read symlinks on homedirs- Update an readd modules- Cleanup spec file- Allow xserver to be started by unconfined process and talk to tty- Upgrade to upstream to grab postgressql changes- Add setransd for mls policy- Add ldconfig_cache_t- Allow sshd to write to proc_t for afs login- Allow xserver access to urand- allow dovecot to search mountpoints- Fix Makefile for building policy modules- Fix dhcpc startup of service- Fix dbus chat to not happen for xguest and guest users- Fix nagios cgi - allow squid to communicate with winbind- Fixes for ldconfig- Update from upstream- Add nasd support- Fix new usb devices and dmfm- Eliminate mount_ntfs_t policy, merge into mount_t- Allow xserver to write to ramfs mounted by rhgb- Add context for dbus machine id- Update with latest changes from upstream- Fix prelink to handle execmod- Add ntpd_key_t to handle secret data- Add anon_inodefs - Allow unpriv user exec pam_exec_t - Fix trigger- Allow cups to use generic usb - fix inetd to be able to run random apps (git)- Add proper contexts for rsyslogd- Fixes for xguest policy- Allow execution of gconf- Fix moilscanner update problem- Begin adding policy to separate setsebool from semanage - Fix xserver.if definition to not break sepolgen.if- Add new devices- Add brctl policy- Fix root login to include system_r- Allow prelink to read kernel sysctls- Default to user_u:system_r:unconfined_t- fix squid - Fix rpm running as uid- Fix syslog declaration- Allow avahi to access inotify - Remove a lot of bogus security_t:filesystem avcs- Remove ifdef strict policy from upstream- Remove ifdef strict to allow user_u to login- Fix for amands - Allow semanage to read pp files - Allow rhgb to read xdm_xserver_tmp- Allow kerberos servers to use ldap for backing store- allow alsactl to read kernel state- More fixes for alsactl - Transition from hal and modutils - Fixes for suspend resume. - insmod domtrans to alsactl - insmod writes to hal log- Allow unconfined_t to transition to NetworkManager_t - Fix netlabel policy- Update to latest from upstream- Update to latest from upstream- Update to latest from upstream- Allow pcscd_t to send itself signals- Fixes for unix_update - Fix logwatch to be able to search all dirs- Upstream bumped the version- Allow consolekit to syslog - Allow ntfs to work with hal- Allow iptables to read etc_runtime_t- MLS Fixes- Fix path of /etc/lvm/cache directory - Fixes for alsactl and pppd_t - Fixes for consolekit- Allow insmod_t to mount kvmfs_t filesystems- Rwho policy - Fixes for consolekit- fixes for fusefs- Fix samba_net to allow it to view samba_var_t- Update to upstream- Fix Sonypic backlight - Allow snmp to look at squid_conf_t- Fixes for pyzor, cyrus, consoletype on everything installs- Fix hald_acl_t to be able to getattr/setattr on usb devices - Dontaudit write to unconfined_pipes for load_policy- Allow bluetooth to read inotifyfs- Fixes for samba domain controller. - Allow ConsoleKit to look at ttys- Fix interface call- Allow syslog-ng to read /var - Allow locate to getattr on all filesystems - nscd needs setcap- Update to upstream- Allow samba to run groupadd- Update to upstream- Allow mdadm to access generic scsi devices- Fix labeling on udev.tbl dirs- Fixes for logwatch- Add fusermount and mount_ntfs policy- Update to upstream - Allow saslauthd to use kerberos keytabs- Fixes for samba_var_t- Allow networkmanager to setpgid - Fixes for hal_acl_t- Remove disable_trans booleans - hald_acl_t needs to talk to nscd- Fix prelink to be able to manage usr dirs.- Allow insmod to launch init scripts- Remove setsebool policy- Fix handling of unlabled_t packets- More of my patches from upstream- Update to latest from upstream - Add fail2ban policy- Update to remove security_t:filesystem getattr problems- Policy for consolekit- Update to latest from upstream- Revert Nemiver change - Set sudo as a corecmd so prelink will work, remove sudoedit mapping, since this will not work, it does not transition. - Allow samba to execute useradd- Upgrade to the latest from upstream- Add sepolgen support - Add bugzilla policy- Fix file context for nemiver- Remove include sym link- Allow mozilla, evolution and thunderbird to read dev_random. Resolves: #227002 - Allow spamd to connect to smtp port Resolves: #227184 - Fixes to make ypxfr work Resolves: #227237- Fix ssh_agent to be marked as an executable - Allow Hal to rw sound device- Fix spamassisin so crond can update spam files - Fixes to allow kpasswd to work - Fixes for bluetooth- Remove some targeted diffs in file context file- Fix squid cachemgr labeling- Add ability to generate webadm_t policy - Lots of new interfaces for httpd - Allow sshd to login as unconfined_t- Continue fixing, additional user domains- Begin adding user confinement to targeted policy- Fixes for prelink, ktalkd, netlabel- Allow prelink when run from rpm to create tmp files Resolves: #221865 - Remove file_context for exportfs Resolves: #221181 - Allow spamassassin to create ~/.spamassissin Resolves: #203290 - Allow ssh access to the krb tickets - Allow sshd to change passwd - Stop newrole -l from working on non securetty Resolves: #200110 - Fixes to run prelink in MLS machine Resolves: #221233 - Allow spamassassin to read var_lib_t dir Resolves: #219234- fix mplayer to work under strict policy - Allow iptables to use nscd Resolves: #220794- Add gconf policy and make it work with strict- Many fixes for strict policy and by extension mls.- Fix to allow ftp to bind to ports > 1024 Resolves: #219349- Allow semanage to exec it self. Label genhomedircon as semanage_exec_t Resolves: #219421 - Allow sysadm_lpr_t to manage other print spool jobs Resolves: #220080- allow automount to setgid Resolves: #219999- Allow cron to polyinstatiate - Fix creation of boot flags Resolves: #207433- Fixes for irqbalance Resolves: #219606- Fix vixie-cron to work on mls Resolves: #207433Resolves: #218978- Allow initrc to create files in /var directories Resolves: #219227- More fixes for MLS Resolves: #181566- More Fixes polyinstatiation Resolves: #216184- More Fixes polyinstatiation - Fix handling of keyrings Resolves: #216184- Fix polyinstatiation - Fix pcscd handling of terminal Resolves: #218149 Resolves: #218350- More fixes for quota Resolves: #212957- ncsd needs to use avahi sockets Resolves: #217640 Resolves: #218014- Allow login programs to polyinstatiate homedirs Resolves: #216184 - Allow quotacheck to create database files Resolves: #212957- Dontaudit appending hal_var_lib files Resolves: #217452 Resolves: #217571 Resolves: #217611 Resolves: #217640 Resolves: #217725- Fix context for helix players file_context #216942- Fix load_policy to be able to mls_write_down so it can talk to the terminal- Fixes for hwclock, clamav, ftp- Move to upstream version which accepted my patches- Fixes for nvidia driver- Allow semanage to signal mcstrans- Update to upstream- Allow modstorage to edit /etc/fstab file- Fix for qemu, /dev/- Fix path to realplayer.bin- Allow xen to connect to xen port- Allow cups to search samba_etc_t directory - Allow xend_t to list auto_mountpoints- Allow xen to search automount- Fix spec of jre files- Fix unconfined access to shadow file- Allow xend to create files in xen_image_t directories- Fixes for /var/lib/hal- Remove ability for sysadm_t to look at audit.log- Fix rpc_port_types - Add aide policy for mls- Merge with upstream- Lots of fixes for ricci- Allow xen to read/write fixed devices with a boolean - Allow apache to search /var/log- Fix policygentool specfile problem. - Allow apache to send signals to it's logging helpers. - Resolves: rhbz#212731- Add perms for swat- Add perms for swat- Allow daemons to dump core files to /- Fixes for ricci- Allow mount.nfs to work- Allow ricci-modstorage to look at lvm_etc_t- Fixes for ricci using saslauthd- Allow mountpoint on home_dir_t and home_t- Update xen to read nfs files- Allow noxattrfs to associate with other noxattrfs- Allow hal to use power_device_t- Allow procemail to look at autofs_t - Allow xen_image_t to work as a fixed device- Refupdate from upstream- Add lots of fixes for mls cups- Lots of fixes for ricci- Fix number of cats- Update to upstream- More iSCSI changes for #209854- Test ISCSI fixes for #209854- allow semodule to rmdir selinux_config_t dir- Fix boot_runtime_t problem on ppc. Should not be creating these files.- Fix context mounts on reboot - Fix ccs creation of directory in /var/log- Update for tallylog- Allow xend to rewrite dhcp conf files - Allow mgetty sys_admin capability- Make xentapctrl work- Don't transition unconfined_t to bootloader_t - Fix label in /dev/xen/blktap- Patch for labeled networking- Fix crond handling for mls- Update to upstream- Remove bluetooth-helper transition - Add selinux_validate for semanage - Require new version of libsemanage- Fix prelink- Fix rhgb- Fix setrans handling on MLS and useradd- Support for fuse - fix vigr- Fix dovecot, amanda - Fix mls- Allow java execheap for itanium- Update with upstream- mls fixes- Update from upstream- More fixes for mls - Revert change on automount transition to mount- Fix cron jobs to run under the correct context- Fixes to make pppd work- Multiple policy fixes - Change max categories to 1023- Fix transition on mcstransd- Add /dev/em8300 defs- Upgrade to upstream- Fix ppp connections from network manager- Add tty access to all domains boolean - Fix gnome-pty-helper context for ia64- Fixed typealias of firstboot_rw_t- Fix location of xel log files - Fix handling of sysadm_r -> rpm_exec_t- Fixes for autofs, lp- Update from upstream- Fixup for test6- Update to upstream- Update to upstream- Fix suspend to disk problems- Lots of fixes for restarting daemons at the console.- Fix audit line - Fix requires line- Upgrade to upstream- Fix install problems- Allow setroubleshoot to getattr on all dirs to gather RPM data- Set /usr/lib/ia32el/ia32x_loader to unconfined_execmem_exec_t for ia32 platform - Fix spec for /dev/adsp- Fix xen tty devices- Fixes for setroubleshoot- Update to upstream- Fixes for stunnel and postgresql - Update from upstream- Update from upstream - More java fixes- Change allow_execstack to default to on, for RHEL5 Beta. This is required because of a Java compiler problem. Hope to turn off for next beta- Misc fixes- More fixes for strict policy- Quiet down anaconda audit messages- Fix setroubleshootd- Update to the latest from upstream- More fixes for xen- Fix anaconda transitions- yet more xen rules- more xen rules- Fixes for Samba- Fixes for xen- Allow setroubleshootd to send mail- Add nagios policy- fixes for setroubleshoot- Added Paul Howarth patch to only load policy packages shipped with this package - Allow pidof from initrc to ptrace higher level domains - Allow firstboot to communicate with hal via dbus- Add policy for /var/run/ldapi- Fix setroubleshoot policy- Fixes for mls use of ssh - named has a new conf file- Fixes to make setroubleshoot work- Cups needs to be able to read domain state off of printer client- add boolean to allow zebra to write config files- setroubleshootd fixes- Allow prelink to read bin_t symlink - allow xfs to read random devices - Change gfs to support xattr- Remove spamassassin_can_network boolean- Update to upstream - Fix lpr domain for mls- Add setroubleshoot policy- Turn off auditallow on setting booleans- Multiple fixes- Update to upstream- Update to upstream - Add new class for kernel key ring- Update to upstream- Update to upstream- Break out selinux-devel package- Add ibmasmfs- Fix policygentool gen_requires- Update from Upstream- Fix spec of realplay- Update to upstream- Fix semanage- Allow useradd to create_home_dir in MLS environment- Update from upstream- Update from upstream- Add oprofilefs- Fix for hplip and Picasus- Update to upstream- Update to upstream- fixes for spamd- fixes for java, openldap and webalizer- Xen fixes- Upgrade to upstream- allow hal to read boot_t files - Upgrade to upstream- allow hal to read boot_t files- Update from upstream- Fixes for amavis- Update from upstream- Allow auditctl to search all directories- Add acquire service for mono.- Turn off allow_execmem boolean - Allow ftp dac_override when allowed to access users homedirs- Clean up spec file - Transition from unconfined_t to prelink_t- Allow execution of cvs command- Update to upstream- Update to upstream- Fix libjvm spec- Update to upstream- Add xm policy - Fix policygentool- Update to upstream - Fix postun to only disable selinux on full removal of the packages- Allow mono to chat with unconfined- Allow procmail to sendmail - Allow nfs to share dosfs- Update to latest from upstream - Allow selinux-policy to be removed and kernel not to crash- Update to latest from upstream - Add James Antill patch for xen - Many fixes for pegasus- Add unconfined_mount_t - Allow privoxy to connect to httpd_cache - fix cups labeleing on /var/cache/cups- Update to latest from upstream- Update to latest from upstream - Allow mono and unconfined to talk to initrc_t dbus objects- Change libraries.fc to stop shlib_t form overriding texrel_shlib_t- Fix samba creating dirs in homedir - Fix NFS so its booleans would work- Allow secadm_t ability to relabel all files - Allow ftp to search xferlog_t directories - Allow mysql to communicate with ldap - Allow rsync to bind to rsync_port_t- Fixed mailman with Postfix #183928 - Allowed semanage to create file_context files. - Allowed amanda_t to access inetd_t TCP sockets and allowed amanda_recover_t to bind to reserved ports. #149030 - Don't allow devpts_t to be associated with tmp_t. - Allow hald_t to stat all mountpoints. - Added boolean samba_share_nfs to allow smbd_t full access to NFS mounts. - Make mount run in mount_t domain from unconfined_t to prevent mislabeling of /etc/mtab. - Changed the file_contexts to not have a regex before the first ^/[a-z]/ whenever possible, makes restorecon slightly faster. - Correct the label of /etc/named.caching-nameserver.conf - Now label /usr/src/kernels/.+/lib(/.*)? as usr_t instead of /usr/src(/.*)?/lib(/.*)? - I don't think we need anything else under /usr/src hit by this. - Granted xen access to /boot, allowed mounting on xend_var_lib_t, and allowed xenstored_t rw access to the xen device node.- More textrel_shlib_t file path fixes - Add ada support- Get auditctl working in MLS policy- Add mono dbus support - Lots of file_context fixes for textrel_shlib_t in FC5 - Turn off execmem auditallow since they are filling log files- Update to upstream- Allow automount and dbus to read cert files- Fix ftp policy - Fix secadm running of auditctl- Update to upstream- Update to upstream- Fix policyhelp- Fix pam_console handling of usb_device - dontaudit logwatch reading /mnt dir- Update to upstream- Get transition rules to create policy.20 at SystemHigh- Allow secadmin to shutdown system - Allow sendmail to exec newalias- MLS Fixes dmidecode needs mls_file_read_up - add ypxfr_t - run init needs access to nscd - udev needs setuid - another xen log file - Dontaudit mount getattr proc_kcore_t- fix buildroot usage (#185391)- Get rid of mount/fsdisk scan of /dev messages - Additional fixes for suspend/resume- Fake make to rebuild enableaudit.pp- Get xen networking running.- Fixes for Xen - enableaudit should not be the same as base.pp - Allow ps to work for all process- more xen policy fixups- more xen fixage (#184393)- Fix blkid specification - Allow postfix to execute mailman_que- Blkid changes - Allow udev access to usb_device_t - Fix post script to create targeted policy config file- Allow lvm tools to create drevice dir- Add Xen support- Fixes for cups - Make cryptosetup work with hal- Load Policy needs translock- Fix cups html interface- Add hal changes suggested by Jeremy - add policyhelp to point at policy html pages- Additional fixes for nvidia and cups- Update to upstream - Merged my latest fixes - Fix cups policy to handle unix domain sockets- NSCD socket is in nscd_var_run_t needs to be able to search dir- Fixes Apache interface file- Fixes for new version of cups- Turn off polyinstatiate util after FC5- Fix problem with privoxy talking to Tor- Turn on polyinstatiation- Don't transition from unconfined_t to fsadm_t- Fix policy update model.- Update to upstream- Fix load_policy to work on MLS - Fix cron_rw_system_pipes for postfix_postdrop_t - Allow audotmount to run showmount- Fix swapon - allow httpd_sys_script_t to be entered via a shell - Allow httpd_sys_script_t to read eventpolfs- Update from upstream- allow cron to read apache files- Fix vpnc policy to work from NetworkManager- Update to upstream - Fix semoudle polcy- Update to upstream - fix sysconfig/selinux link- Add router port for zebra - Add imaze port for spamd - Fixes for amanda and java- Fix bluetooth handling of usb devices - Fix spamd reading of ~/ - fix nvidia spec- Update to upsteam- Add users_extra files- Update to upstream- Add semodule policy- Update from upstream- Fix for spamd to use razor port- Fixes for mcs - Turn on mount and fsadm for unconfined_t- Fixes for the -devel package- Fix for spamd to use ldap- Update to upstream- Update to upstream - Fix rhgb, and other Xorg startups- Update to upstream- Separate out role of secadm for mls- Add inotifyfs handling- Update to upstream - Put back in changes for pup/zen- Many changes for MLS - Turn on strict policy- Update to upstream- Update to upstream - Fixes for booting and logging in on MLS machine- Update to upstream - Turn off execheap execstack for unconfined users - Add mono/wine policy to allow execheap and execstack for them - Add execheap for Xdm policy- Update to upstream - Fixes to fetchmail,- Update to upstream- Fix for procmail/spamassasin - Update to upstream - Add rules to allow rpcd to work with unlabeled_networks.- Update to upstream - Fix ftp Man page- Update to upstream- fix pup transitions (#177262) - fix xen disks (#177599)- Update to upstream- More Fixes for hal and readahead- Fixes for hal and readahead- Update to upstream - Apply- Add wine and fix hal problems- Handle new location of hal scripts- Allow su to read /etc/mtab- Update to upstream- Fix "libsemanage.parse_module_headers: Data did not represent a module." problem- Allow load_policy to read /etc/mtab- Fix dovecot to allow dovecot_auth to look at /tmp- Allow restorecon to read unlabeled_t directories in order to fix labeling.- Add Logwatch policy- Fix /dev/ub[a-z] file context- Fix library specification - Give kudzu execmem privs- Fix hostname in targeted policy- Fix passwd command on mls- Lots of fixes to make mls policy work- Add dri libs to textrel_shlib_t - Add system_r role for java - Add unconfined_exec_t for vncserver - Allow slapd to use kerberos- Add man pages- Add enableaudit.pp- Fix mls policy- Update mls file from old version- Add sids back in - Rebuild with update checkpolicy- Fixes to allow automount to use portmap - Fixes to start kernel in s0-s15:c0.c255- Add java unconfined/execmem policy- Add file context for /var/cvs - Dontaudit webalizer search of homedir- Update from upstream- Clean up spec - range_transition crond to SystemHigh- Fixes for hal - Update to upstream- Turn back on execmem since we need it for java, firefox, ooffice - Allow gpm to stream socket to itself- fix requirements to be on the actual packages so that policy can get created properly at install time- Allow unconfined_t to execmod texrel_shlib_t- Update to upstream - Turn off allow_execmem and allow_execmod booleans - Add tcpd and automount policies- Add two new httpd booleans, turned off by default * httpd_can_network_relay * httpd_can_network_connect_db- Add ghost for policy.20- Update to upstream - Turn off boolean allow_execstack- Change setrans-mls to use new libsetrans - Add default_context rule for xdm- Change Requires to PreReg for requiring of policycoreutils on install- New upstream releaseAdd xdm policyUpdate from upstreamUpdate from upstreamUpdate from upstream- Also trigger to rebuild policy for versions up to 2.0.7.- No longer installing policy.20 file, anaconda handles the building of the app.- Fixes for dovecot and saslauthd- Cleanup pegasus and named - Fix spec file - Fix up passwd changing applications-Update to latest from upstream- Add rules for pegasus and avahi- Start building MLS Policy- Update to upstream- Turn on bash- Initial version/bin/sh  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0122456789:;<=>?@ABCDEFGHIJKLMNOPQR3.13.1-268.el7    develMakefileexample.fcexample.ifexample.tehtmlNetworkManager.htmlabrt.htmlabrt_dump_oops.htmlabrt_handle_event.htmlabrt_helper.htmlabrt_retrace_coredump.htmlabrt_retrace_worker.htmlabrt_upload_watch.htmlabrt_watch_log.htmlaccountsd.htmlacct.htmladmin_crontab.htmlafs.htmlafs_bosserver.htmlafs_fsserver.htmlafs_kaserver.htmlafs_ptserver.htmlafs_vlserver.htmlaiccu.htmlaide.htmlajaxterm.htmlajaxterm_ssh.htmlalsa.htmlamanda.htmlamanda_recover.htmlamtu.htmlanaconda.htmlanon_sftpd.htmlantivirus.htmlapcupsd.htmlapcupsd_cgi_script.htmlapm.htmlapmd.htmlarpwatch.htmlasterisk.htmlaudisp.htmlaudisp_remote.htmlauditadm.htmlauditadm_screen.htmlauditadm_su.htmlauditadm_sudo.htmlauditctl.htmlauditd.htmlauthconfig.htmlautomount.htmlavahi.htmlawstats.htmlawstats_script.htmlbacula.htmlbacula_admin.htmlbacula_unconfined_script.htmlbcfg2.htmlbitlbee.htmlblkmapd.htmlblktap.htmlblueman.htmlbluetooth.htmlbluetooth_helper.htmlboinc.htmlboinc_project.htmlboltd.htmlbootloader.htmlbrctl.htmlbrltty.htmlbugzilla_script.htmlbumblebee.htmlcachefiles_kernel.htmlcachefilesd.htmlcalamaris.htmlcallweaver.htmlcanna.htmlcardmgr.htmlccs.htmlcdcc.htmlcdrecord.htmlcertmaster.htmlcertmonger.htmlcertmonger_unconfined.htmlcertwatch.htmlcfengine_execd.htmlcfengine_monitord.htmlcfengine_serverd.htmlcgclear.htmlcgconfig.htmlcgdcbxd.htmlcgred.htmlcheckpc.htmlcheckpolicy.htmlchfn.htmlchkpwd.htmlchrome_sandbox.htmlchrome_sandbox_nacl.htmlchronyc.htmlchronyd.htmlchroot_user.htmlcinder_api.htmlcinder_backup.htmlcinder_scheduler.htmlcinder_volume.htmlciped.htmlclogd.htmlcloud_init.htmlcluster.htmlclvmd.htmlcmirrord.htmlcobblerd.htmlcockpit_session.htmlcockpit_ws.htmlcollectd.htmlcollectd_script.htmlcolord.htmlcomsat.htmlcondor_collector.htmlcondor_master.htmlcondor_negotiator.htmlcondor_procd.htmlcondor_schedd.htmlcondor_startd.htmlcondor_startd_ssh.htmlconman.htmlconman_unconfined_script.htmlconsolekit.htmlcontainer.htmlcontainer_auth.htmlcontainer_runtime.htmlcouchdb.htmlcourier_authdaemon.htmlcourier_pcp.htmlcourier_pop.htmlcourier_sqwebmail.htmlcourier_tcpd.htmlcpucontrol.htmlcpufreqselector.htmlcpuplug.htmlcpuspeed.htmlcrack.htmlcrond.htmlcronjob.htmlcrontab.htmlctdbd.htmlcups_pdf.htmlcupsd.htmlcupsd_config.htmlcupsd_lpd.htmlcvs.htmlcvs_script.htmlcyphesis.htmlcyrus.htmldbadm.htmldbadm_sudo.htmldbskkd.htmldcc_client.htmldcc_dbclean.htmldccd.htmldccifd.htmldccm.htmldcerpcd.htmlddclient.htmldeltacloudd.htmldenyhosts.htmldepmod.htmldevicekit.htmldevicekit_disk.htmldevicekit_power.htmldhcpc.htmldhcpd.htmldictd.htmldirsrv.htmldirsrv_snmp.htmldirsrvadmin.htmldirsrvadmin_script.htmldirsrvadmin_unconfined_script.htmldisk_munin_plugin.htmldkim_milter.htmldlm_controld.htmldmesg.htmldmidecode.htmldnsmasq.htmldnssec_trigger.htmldovecot.htmldovecot_auth.htmldovecot_deliver.htmldrbd.htmldspam.htmldspam_script.htmlentropyd.htmleventlogd.htmlevtchnd.htmlexim.htmlfail2ban.htmlfail2ban_client.htmlfcoemon.htmlfenced.htmlfetchmail.htmlfingerd.htmlfirewalld.htmlfirewallgui.htmlfirstboot.htmlfoghorn.htmlfprintd.htmlfreeipmi_bmc_watchdog.htmlfreeipmi_ipmidetectd.htmlfreeipmi_ipmiseld.htmlfreqset.htmlfsadm.htmlfsdaemon.htmlftpd.htmlftpdctl.htmlgames.htmlgames_srv.htmlganesha.htmlgconfd.htmlgconfdefaultsm.htmlgdomap.htmlgeoclue.htmlgetty.htmlgfs_controld.htmlgit_script.htmlgit_session.htmlgit_system.htmlgitosis.htmlglance_api.htmlglance_registry.htmlglance_scrubber.htmlglusterd.htmlgnomesystemmm.htmlgpg.htmlgpg_agent.htmlgpg_helper.htmlgpg_pinentry.htmlgpg_web.htmlgpm.htmlgpsd.htmlgreylist_milter.htmlgroupadd.htmlgroupd.htmlgssd.htmlgssproxy.htmlguest.htmlhaproxy.htmlhddtemp.htmlhostname.htmlhsqldb.htmlhttpd.htmlhttpd_helper.htmlhttpd_passwd.htmlhttpd_php.htmlhttpd_rotatelogs.htmlhttpd_suexec.htmlhttpd_sys_script.htmlhttpd_unconfined_script.htmlhttpd_user_script.htmlhwclock.htmlhwloc_dhwd.htmlhypervkvp.htmlhypervvssd.htmliceauth.htmlicecast.htmlifconfig.htmlindex.htmlinetd.htmlinetd_child.htmlinit.htmlinitrc.htmlinnd.htmlinsmod.htmlinstall.htmliodined.htmliotop.htmlipa_dnskey.htmlipa_helper.htmlipa_otpd.htmlipmievd.htmlipsec.htmlipsec_mgmt.htmliptables.htmlirc.htmlirqbalance.htmlirssi.htmliscsid.htmlisnsd.htmliwhd.htmljabberd.htmljabberd_router.htmljockey.htmljournalctl.htmlkadmind.htmlkdump.htmlkdumpctl.htmlkdumpgui.htmlkeepalived.htmlkeepalived_unconfined_script.htmlkernel.htmlkeyboardd.htmlkeystone.htmlkeystone_cgi_script.htmlkismet.htmlklogd.htmlkmscon.htmlkpatch.htmlkpropd.htmlkrb5kdc.htmlksmtuned.htmlktalkd.htmll2tpd.htmlldconfig.htmllircd.htmllivecd.htmllldpad.htmlload_policy.htmlloadkeys.htmllocal_login.htmllocate.htmllockdev.htmllogadm.htmllogrotate.htmllogrotate_mail.htmllogwatch.htmllogwatch_mail.htmllpd.htmllpr.htmllsassd.htmllsmd.htmllsmd_plugin.htmllttng_sessiond.htmllvm.htmllwiod.htmllwregd.htmllwsmd.htmlmail_munin_plugin.htmlmailman_cgi.htmlmailman_mail.htmlmailman_queue.htmlman2html_script.htmlmandb.htmlmcelog.htmlmdadm.htmlmediawiki_script.htmlmemcached.htmlmencoder.htmlminidlna.htmlminissdpd.htmlmip6d.htmlmirrormanager.htmlmock.htmlmock_build.htmlmodemmanager.htmlmojomojo_script.htmlmon_procd.htmlmon_statd.htmlmongod.htmlmotion.htmlmount.htmlmount_ecryptfs.htmlmozilla.htmlmozilla_plugin.htmlmozilla_plugin_config.htmlmpd.htmlmplayer.htmlmrtg.htmlmscan.htmlmunin.htmlmunin_script.htmlmysqld.htmlmysqld_safe.htmlmysqlmanagerd.htmlmythtv_script.htmlnagios.htmlnagios_admin_plugin.htmlnagios_checkdisk_plugin.htmlnagios_eventhandler_plugin.htmlnagios_mail_plugin.htmlnagios_openshift_plugin.htmlnagios_script.htmlnagios_services_plugin.htmlnagios_system_plugin.htmlnagios_unconfined_plugin.htmlnamed.htmlnamespace_init.htmlncftool.htmlndc.htmlnetlabel_mgmt.htmlnetlogond.htmlnetutils.htmlneutron.htmlnewrole.htmlnfsd.htmlninfod.htmlnmbd.htmlnova.htmlnrpe.htmlnscd.htmlnsd.htmlnsd_crond.htmlnslcd.htmlntop.htmlntpd.htmlnumad.htmlnut_upsd.htmlnut_upsdrvctl.htmlnut_upsmon.htmlnutups_cgi_script.htmlnx_server.htmlnx_server_ssh.htmlobex.htmloddjob.htmloddjob_mkhomedir.htmlopenct.htmlopendnssec.htmlopenhpid.htmlopenshift.htmlopenshift_app.htmlopenshift_cgroup_read.htmlopenshift_cron.htmlopenshift_initrc.htmlopenshift_net_read.htmlopenshift_script.htmlopensm.htmlopenvpn.htmlopenvpn_unconfined_script.htmlopenvswitch.htmlopenwsman.htmloracleasm.htmlosad.htmlpads.htmlpam_console.htmlpam_timestamp.htmlpassenger.htmlpasswd.htmlpcp_pmcd.htmlpcp_pmie.htmlpcp_pmlogger.htmlpcp_pmmgr.htmlpcp_pmproxy.htmlpcp_pmwebd.htmlpcscd.htmlpegasus.htmlpegasus_openlmi_account.htmlpegasus_openlmi_admin.htmlpegasus_openlmi_logicalfile.htmlpegasus_openlmi_services.htmlpegasus_openlmi_storage.htmlpegasus_openlmi_system.htmlpegasus_openlmi_unconfined.htmlpesign.htmlphc2sys.htmlping.htmlpingd.htmlpiranha_fos.htmlpiranha_lvs.htmlpiranha_pulse.htmlpiranha_web.htmlpkcs_slotd.htmlpki_ra.htmlpki_tomcat.htmlpki_tomcat_script.htmlpki_tps.htmlplymouth.htmlplymouthd.htmlpodsleuth.htmlpolicykit.htmlpolicykit_auth.htmlpolicykit_grant.htmlpolicykit_resolve.htmlpolipo.htmlpolipo_session.htmlportmap.htmlportmap_helper.htmlportreserve.htmlpostfix_bounce.htmlpostfix_cleanup.htmlpostfix_local.htmlpostfix_map.htmlpostfix_master.htmlpostfix_pickup.htmlpostfix_pipe.htmlpostfix_postdrop.htmlpostfix_postqueue.htmlpostfix_qmgr.htmlpostfix_showq.htmlpostfix_smtp.htmlpostfix_smtpd.htmlpostfix_virtual.htmlpostgresql.htmlpostgrey.htmlpppd.htmlpptp.htmlprelink.htmlprelink_cron_system.htmlprelude.htmlprelude_audisp.htmlprelude_correlator.htmlprelude_lml.htmlpreupgrade.htmlprewikka_script.htmlprivoxy.htmlprocmail.htmlprosody.htmlpsad.htmlptal.htmlptchown.htmlptp4l.htmlpublicfile.htmlpulseaudio.htmlpuppetagent.htmlpuppetca.htmlpuppetmaster.htmlpwauth.htmlpyicqt.htmlqdiskd.htmlqemu_dm.htmlqmail_clean.htmlqmail_inject.htmlqmail_local.htmlqmail_lspawn.htmlqmail_queue.htmlqmail_remote.htmlqmail_rspawn.htmlqmail_send.htmlqmail_smtpd.htmlqmail_splogger.htmlqmail_start.htmlqmail_tcp_env.htmlqpidd.htmlquota.htmlquota_nld.htmlrabbitmq.htmlracoon.htmlradiusd.htmlradvd.htmlrasdaemon.htmlrdisc.htmlreadahead.htmlrealmd.htmlrealmd_consolehelper.htmlredis.htmlregex_milter.htmlremote_login.htmlrestorecond.htmlrhev_agentd.htmlrhev_agentd_consolehelper.htmlrhgb.htmlrhnsd.htmlrhsmcertd.htmlricci.htmlricci_modcluster.htmlricci_modclusterd.htmlricci_modlog.htmlricci_modrpm.htmlricci_modservice.htmlricci_modstorage.htmlrlogind.htmlrngd.htmlroundup.htmlrpcbind.htmlrpcd.htmlrpm.htmlrpm_script.htmlrshd.htmlrssh.htmlrssh_chroot_helper.htmlrsync.htmlrtas_errd.htmlrtkit_daemon.htmlrun_init.htmlrwho.htmlsamba_net.htmlsamba_unconfined_net.htmlsamba_unconfined_script.htmlsambagui.htmlsandbox.htmlsandbox_min.htmlsandbox_min_client.htmlsandbox_net.htmlsandbox_net_client.htmlsandbox_web.htmlsandbox_web_client.htmlsandbox_x.htmlsandbox_x_client.htmlsandbox_xserver.htmlsanlk_resetd.htmlsanlock.htmlsaslauthd.htmlsbd.htmlsblim_gatherd.htmlsblim_reposd.htmlsblim_sfcbd.htmlsecadm.htmlsecadm_screen.htmlsecadm_su.htmlsecadm_sudo.htmlsectoolm.htmlselinux_munin_plugin.htmlsemanage.htmlsendmail.htmlsensord.htmlsepgsql_ranged_proc.htmlsepgsql_trusted_proc.htmlservices_munin_plugin.htmlsetfiles.htmlsetfiles_mac.htmlsetkey.htmlsetrans.htmlsetroubleshoot_fixit.htmlsetroubleshootd.htmlsetsebool.htmlsftpd.htmlsge_execd.htmlsge_job.htmlsge_job_ssh.htmlsge_shepherd.htmlshorewall.htmlshowmount.htmlslapd.htmlslpd.htmlsmbcontrol.htmlsmbd.htmlsmbmount.htmlsmokeping.htmlsmokeping_cgi_script.htmlsmoltclient.htmlsmsd.htmlsnapperd.htmlsnmpd.htmlsnort.htmlsosreport.htmlsoundd.htmlspamass_milter.htmlspamc.htmlspamd.htmlspamd_update.htmlspc.htmlspeech-dispatcher.htmlsquid.htmlsquid_cron.htmlsquid_script.htmlsrvsvcd.htmlssh.htmlssh_keygen.htmlssh_keysign.htmlsshd.htmlsshd_keygen.htmlsshd_net.htmlsshd_sandbox.htmlsssd.htmlsssd_selinux_manager.htmlstaff.htmlstaff_consolehelper.htmlstaff_dbusd.htmlstaff_gkeyringd.htmlstaff_screen.htmlstaff_seunshare.htmlstaff_ssh_agent.htmlstaff_sudo.htmlstaff_wine.htmlstapserver.htmlstunnel.htmlstyle.csssulogin.htmlsvc_multilog.htmlsvc_run.htmlsvc_start.htmlsvirt.htmlsvirt_kvm_net.htmlsvirt_qemu_net.htmlsvirt_socket.htmlsvirt_tcg.htmlsvnserve.htmlswat.htmlswift.htmlsysadm.htmlsysadm_gkeyringd.htmlsysadm_passwd.htmlsysadm_screen.htmlsysadm_seunshare.htmlsysadm_ssh_agent.htmlsysadm_su.htmlsysadm_sudo.htmlsyslogd.htmlsysstat.htmlsystem_cronjob.htmlsystem_dbusd.htmlsystem_mail.htmlsystem_munin_plugin.htmlsystemd_bootchart.htmlsystemd_hostnamed.htmlsystemd_hwdb.htmlsystemd_initctl.htmlsystemd_localed.htmlsystemd_logger.htmlsystemd_logind.htmlsystemd_machined.htmlsystemd_networkd.htmlsystemd_notify.htmlsystemd_passwd_agent.htmlsystemd_resolved.htmlsystemd_sysctl.htmlsystemd_timedated.htmlsystemd_tmpfiles.htmltangd.htmltargetd.htmltcpd.htmltcsd.htmltelepathy_gabble.htmltelepathy_idle.htmltelepathy_logger.htmltelepathy_mission_control.htmltelepathy_msn.htmltelepathy_salut.htmltelepathy_sofiasip.htmltelepathy_stream_engine.htmltelepathy_sunshine.htmltelnetd.htmltftpd.htmltgtd.htmlthin.htmlthin_aeolus_configserver.htmlthumb.htmltimemaster.htmltlp.htmltmpreaper.htmltomcat.htmltor.htmltraceroute.htmltuned.htmltvtime.htmludev.htmlulogd.htmluml.htmluml_switch.htmlunconfined.htmlunconfined_cronjob.htmlunconfined_dbusd.htmlunconfined_mount.htmlunconfined_munin_plugin.htmlunconfined_sendmail.htmlunconfined_service.htmlupdate_modules.htmlupdfstab.htmlupdpwd.htmlusbmodules.htmlusbmuxd.htmluser.htmluser_dbusd.htmluser_gkeyringd.htmluser_mail.htmluser_screen.htmluser_seunshare.htmluser_ssh_agent.htmluser_wine.htmluseradd.htmlusernetctl.htmlutempter.htmluucpd.htmluuidd.htmluux.htmlvarnishd.htmlvarnishlog.htmlvdagent.htmlvhostmd.htmlvirsh.htmlvirsh_ssh.htmlvirt_bridgehelper.htmlvirt_qemu_ga.htmlvirt_qemu_ga_unconfined.htmlvirt_qmf.htmlvirtd.htmlvirtd_lxc.htmlvirtlogd.htmlvlock.htmlvmtools.htmlvmtools_helper.htmlvmtools_unconfined.htmlvmware.htmlvmware_host.htmlvnstat.htmlvnstatd.htmlvpnc.htmlw3c_validator_script.htmlwatchdog.htmlwatchdog_unconfined.htmlwdmd.htmlwebadm.htmlwebalizer.htmlwebalizer_script.htmlwinbind.htmlwinbind_helper.htmlwine.htmlwireshark.htmlwpa_cli.htmlxauth.htmlxdm.htmlxdm_unconfined.htmlxenconsoled.htmlxend.htmlxenstored.htmlxguest.htmlxguest_dbusd.htmlxguest_gkeyringd.htmlxserver.htmlypbind.htmlyppasswdd.htmlypserv.htmlypxfr.htmlzabbix.htmlzabbix_agent.htmlzabbix_script.htmlzarafa_deliver.htmlzarafa_gateway.htmlzarafa_ical.htmlzarafa_indexer.htmlzarafa_monitor.htmlzarafa_server.htmlzarafa_spooler.htmlzebra.htmlzoneminder.htmlzoneminder_script.htmlzos_remote.htmlincludeMakefileadminadmin.xmlbootloader.ifconsoletype.ifdmesg.ifnetutils.ifsu.ifsudo.ifusermanage.ifappsapps.xmlseunshare.ifbuild.confcontribcontrib.xmlabrt.ifaccountsd.ifacct.ifada.ifafs.ifaiccu.ifaide.ifaisexec.ifajaxterm.ifalsa.ifamanda.ifamavis.ifamtu.ifanaconda.ifantivirus.ifapache.ifapcupsd.ifapm.ifapt.ifarpwatch.ifasterisk.ifauthbind.ifauthconfig.ifautomount.ifavahi.ifawstats.ifbackup.ifbacula.ifbcfg2.ifbind.ifbird.ifbitlbee.ifblkmapd.ifblueman.ifbluetooth.ifboinc.ifboltd.ifbrctl.ifbrltty.ifbugzilla.ifbumblebee.ifcachefilesd.ifcalamaris.ifcallweaver.ifcanna.ifccs.ifcdrecord.ifcertmaster.ifcertmonger.ifcertwatch.ifcfengine.ifcgdcbxd.ifcgroup.ifchrome.ifchronyd.ifcinder.ifcipe.ifclamav.ifclockspeed.ifclogd.ifcloudform.ifcmirrord.ifcobbler.ifcockpit.ifcollectd.ifcolord.ifcomsat.ifcondor.ifconman.ifconsolekit.ifcontainer.ifcorosync.ifcouchdb.ifcourier.ifcpucontrol.ifcpufreqselector.ifcpuplug.ifcron.ifctdb.ifcups.ifcvs.ifcyphesis.ifcyrus.ifdaemontools.ifdante.ifdbadm.ifdbskk.ifdbus.ifdcc.ifddclient.ifddcprobe.ifdenyhosts.ifdevicekit.ifdhcp.ifdictd.ifdirmngr.ifdirsrv-admin.ifdirsrv.ifdistcc.ifdjbdns.ifdkim.ifdmidecode.ifdnsmasq.ifdnssec.ifdnssectrigger.ifdovecot.ifdpkg.ifdrbd.ifdspam.ifentropyd.ifetcd.ifevolution.ifexim.iffail2ban.iffcoe.iffetchmail.iffinger.iffirewalld.iffirewallgui.iffirstboot.iffprintd.iffreeipmi.iffreqset.ifftp.ifgames.ifganesha.ifgatekeeper.ifgdomap.ifgear.ifgeoclue.ifgift.ifgit.ifgitosis.ifglance.ifglusterd.ifgnome.ifgnomeclock.ifgpg.ifgpm.ifgpsd.ifgssproxy.ifguest.ifhadoop.ifhal.ifhddtemp.ifhostapd.ifhowl.ifhsqldb.ifhwloc.ifhypervkvp.ifi18n_input.ificecast.ififplugd.ifimaze.ifinetd.ifinn.ifiodine.ifiotop.ifipa.ifipmievd.ifirc.ifircd.ifirqbalance.ifiscsi.ifisns.ifjabber.ifjava.ifjetty.ifjockey.ifjournalctl.ifkde.ifkdump.ifkdumpgui.ifkeepalived.ifkerberos.ifkerneloops.ifkeyboardd.ifkeystone.ifkismet.ifkmscon.ifkpatch.ifksmtuned.ifktalk.ifkudzu.ifl2tp.ifldap.iflightsquid.iflikewise.iflinuxptp.iflircd.iflivecd.iflldpad.ifloadkeys.iflockdev.iflogrotate.iflogwatch.iflpd.iflsm.iflttng-tools.ifmailman.ifmailscanner.ifman2html.ifmandb.ifmcelog.ifmcollective.ifmediawiki.ifmemcached.ifmilter.ifminidlna.ifminissdpd.ifmip6d.ifmirrormanager.ifmock.ifmodemmanager.ifmojomojo.ifmon_statd.ifmongodb.ifmono.ifmonop.ifmotion.ifmozilla.ifmpd.ifmplayer.ifmrtg.ifmta.ifmunin.ifmysql.ifmythtv.ifnaemon.ifnagios.ifnamespace.ifncftool.ifnessus.ifnetworkmanager.ifninfod.ifnis.ifnova.ifnscd.ifnsd.ifnslcd.ifnsplugin.ifntop.ifntp.ifnumad.ifnut.ifnx.ifoav.ifobex.ifoddjob.ifoident.ifopenca.ifopenct.ifopendnssec.ifopenhpi.ifopenhpid.ifopenshift-origin.ifopenshift.ifopensm.ifopenvpn.ifopenvswitch.ifopenwsman.iforacleasm.ifosad.ifpacemaker.ifpads.ifpassenger.ifpcmcia.ifpcp.ifpcscd.ifpegasus.ifperdition.ifpesign.ifpingd.ifpiranha.ifpkcs.ifpki.ifplymouthd.ifpodsleuth.ifpolicykit.ifpolipo.ifportage.ifportmap.ifportreserve.ifportslave.ifpostfix.ifpostfixpolicyd.ifpostgrey.ifppp.ifprelink.ifprelude.ifprivoxy.ifprocmail.ifprosody.ifpsad.ifptchown.ifpublicfile.ifpulseaudio.ifpuppet.ifpwauth.ifpxe.ifpyzor.ifqemu.ifqmail.ifqpid.ifquantum.ifquota.ifrabbitmq.ifradius.ifradvd.ifraid.ifrasdaemon.ifrazor.ifrdisc.ifreadahead.ifrealmd.ifredis.ifremotelogin.ifresmgr.ifrgmanager.ifrhcs.ifrhev.ifrhgb.ifrhnsd.ifrhsmcertd.ifricci.ifrkhunter.ifrlogin.ifrngd.ifrolekit.ifroundup.ifrpc.ifrpcbind.ifrpm.ifrshd.ifrssh.ifrsync.ifrtas.ifrtkit.ifrwho.ifsamba.ifsambagui.ifsamhain.ifsandbox.ifsandboxX.ifsanlock.ifsasl.ifsbd.ifsblim.ifscreen.ifsectoolm.ifsendmail.ifsensord.ifsetroubleshoot.ifsge.ifshorewall.ifshutdown.ifslocate.ifslpd.ifslrnpull.ifsmartmon.ifsmokeping.ifsmoltclient.ifsmsd.ifsmstools.ifsnapper.ifsnmp.ifsnort.ifsosreport.ifsoundserver.ifspamassassin.ifspeech-dispatcher.ifspeedtouch.ifsquid.ifsssd.ifstapserver.ifstunnel.ifsvnserve.ifswift.ifswift_alias.ifsxid.ifsysstat.iftangd.iftargetd.iftcpd.iftcsd.iftelepathy.iftelnet.iftftp.iftgtd.ifthin.ifthumb.ifthunderbird.iftimidity.iftlp.iftmpreaper.iftomcat.iftor.iftransproxy.iftripwire.iftuned.iftvtime.iftzdata.ifucspitcp.ifulogd.ifuml.ifupdfstab.ifuptime.ifusbmodules.ifusbmuxd.ifuserhelper.ifusernetctl.ifuucp.ifuuidd.ifuwimap.ifvarnishd.ifvbetool.ifvdagent.ifvhostmd.ifvirt.ifvlock.ifvmtools.ifvmware.ifvnstatd.ifvpn.ifw3c.ifwatchdog.ifwdmd.ifwebadm.ifwebalizer.ifwine.ifwireshark.ifwm.ifxen.ifxfs.ifxguest.ifxprint.ifxscreensaver.ifyam.ifzabbix.ifzarafa.ifzebra.ifzoneminder.ifzosremote.ifglobal_booleans.xmlglobal_tunables.xmlkernelkernel.xmlcorecommands.ifcorenetwork.ifdevices.ifdomain.iffiles.iffilesystem.ifkernel.ifmcs.ifmls.ifselinux.ifstorage.ifterminal.ifubac.ifunlabelednet.ifrolesroles.xmlauditadm.iflogadm.ifsecadm.ifstaff.ifsysadm.ifsysadm_secadm.ifunconfineduser.ifunprivuser.ifservicesservices.xmlpostgresql.ifssh.ifxserver.ifsupportall_perms.sptdivert.m4file_patterns.sptipc_patterns.sptloadable_module.sptmisc_macros.sptmisc_patterns.sptmls_mcs_macros.sptobj_perm_sets.sptpolicy.dtdsegenxml.pysegenxml.pycsegenxml.pyoundivert.m4systemsystem.xmlapplication.ifauthlogin.ifclock.iffstools.ifgetty.ifhostname.ifhotplug.ifinit.ifipsec.ifiptables.iflibraries.iflocallogin.iflogging.iflvm.ifmiscfiles.ifmodutils.ifmount.ifnetlabel.ifselinuxutil.ifsetrans.ifsysnetwork.ifsystemd.ifudev.ifunconfined.ifuserdomain.ifpolicy.dtdpolicy.xmlinterface_info/usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/html//usr/share/selinux/devel/include//usr/share/selinux/devel/include/admin//usr/share/selinux/devel/include/apps//usr/share/selinux/devel/include/contrib//usr/share/selinux/devel/include/kernel//usr/share/selinux/devel/include/roles//usr/share/selinux/devel/include/services//usr/share/selinux/devel/include/support//usr/share/selinux/devel/include/system//var/lib/sepolgen/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2noarch-redhat-linux-gnu  directoryASCII textSE Linux policy interface sourceSE Linux policy module sourceHTML document, ASCII textmakefile script, ASCII textC++ source, ASCII textASCII text, with very long linesASCII text, with no line terminatorsPython script, ASCII text executablepython 2.7 byte-compiledXML 1.0 document, ASCII textcannot open (No such file or directory)?p7zXZ !#,q] b2u jӫ`(VYDL#D]-ѿF]5+= W\ Fi,}AϓIKFu g]}RQ/OQʏʀ۱]zu,[4B(ܬPc$]|,͡,ȽɆ`UOؠmwlO ~afe4*(egv*D?f9d2{&'ҰBr# D.94Be^5 ޵0h2 )!~Xd*1;"ǒhl/ 1LsӤ:1jL)fBIj A`M$Pk{IPOd_QP>f;Ld3x՝G$ F<4+zrB+; .>6FVCW1:Wv. /?fڢ9`CƓ>H֪oMwAX%yTHiq BVraa;WDT1.7Q A2{bw:SЫ/+,@PwT%3FHY)G=hs0xՄ{>Kt%haRKt@̳Ǻh%@| azo+(W\`)~gŅN%05G^${jl}sdi攝`i6@}{.\DӲR4>d7BTK ^J3/adU̸ vqORKbJ{ 'w%3apCĀV 20k;=ptdΏ4!>Չx6B{zKG*Ӵg2gĀP!RnQ((3x_[(H(ʣ ʆ,Rt_cOtRƼ8K<%λ}/%y8%$9} Әs"\ @4r RRzۙ(Ԇµ^,?RC;|q|xFdP 5a<;ĢX{`eꗩ:?=18b=ڹܹрtJuZg>5=va5%_yy9(Mfs G7^5]#C땐omph  `vvϢӿ1]dt#W)S=県d4ǡ'$th\T/He8i.Gtd1[lj ֍hZF OAcu~͝NH鿇  Du#wE-jO<:dyzϚ"?xC 5G V;̲^@RfZx[[6JX!d"`0c'^2\*KWy" hq;X ._< \Bad`HHxwA6(iAy]O.l~-AWx?0 G!t?J)(+5n+xؠlo՗ق@UJ=R('eJ@%#Tx9c6ŏ[{"(gI qb(Aqro$>*@V#䟔Gq"9qq6ibMIMwӲɊu'up8:7Ę7n=Um[cNg{jd7׍4ˡ@Ԅ^',/Nنlm{GV堃`BQMMl#NԛhאgrU דF:qHj?0CF~Ud9$2&Vўbi<,NFyꟉ! kY(d .LU]i]Dlc-LP=~eL~u4zP v?д3"[*s3Ƀ̜h_f1n!ThF/e.x~k–P{a޵)<"_@s٧p6C!!r%'j/J]H?0T i&3 D8[)mߓvƞ%j]=hX5+KiRK$$T7ȟu]p;^H}[D#):ڭ*G ^u12}! s9E^Q3^`n48*JAQg "ּ+0Ld{ϜsIKn29QH22o׽Gd8,ױ0tY@ NDi+nGk*oSKz}=J\ H(6Npc3rp}+y8!hod/Ĩ uR |O>ZO1\qb(ݦޡ=d錅"jmgżrǧ4-Xz32m9дQF]@%ijN)B>"6ÌǡqkBnIj'Hle=sڌ7/W!0y;eWU#>~[wC?4ӷ3њRoδAnvg(GElN8E t _bXLΛ'g( qU^#\b,$ѝI )^/Vhg1yi}9eJhN \ѥ{[7)NdAH&kҤ`o?@OR7.gŐ[`L u kb4V{8Im;psQ`4m& hw_XՌIzY27%r;RaBn! 'TETp7vӜ]E;IBJ, ~|ueu(USOSk,`{^9\#eN2uqZh#btϮU+ ;Zn9y /h3sQOPQJ$rzhշ+Z3|} )jf\ 2f4kI*l%E.}Fcs P#W`jBO3'ua8@E4Z.lsɵׂęlk+ )&ƚx]4&]`PR=^f)Z E!1z P]*oott'R7dU>)\Gzp [ṻT{@ Էgs*$bq 1C:s}axr$Ϙh+Ay n3ɉ*d<6erc0.>NZaBO@"Z!Tٟ˳ئJhX0 u2Q.h hpyYr QO*`RBXBz5T]2J]ȰBG&>(xݧݧ[Kϡ5YyzatĎ|)cXhL2qVpcLf !Qh(1Ds*+ѕѸ_̣|"X- 7O*JݽOH?k*cr`Q?&z˒ADLNĝUxh0YC,^Rx$2́Ki!GQKQu.Nҵo:cyչzC>y1:HBwq9ۚ鱳M3{T!@f,6v@\YT|_mqgarFopP< 8T 4 7~]i=ak'9 J[Qtkam'F Ջ?vP#O4kN)Ҭ> #EyVJ¹8mPC{]\mi03o6w{WpY!{(6@-6x8oa2flm8"erI` Wˮ[VIy#f%hIq bБGC^uP꼙4Ѹtvl{eDCN*Rru1^:w8yVH[SGkXCub|]>-d4^_2rgGJfUIeJvX @CZUdqT.'n68Iq([#x+[Pt[#CU5fw:hS#4W0fbV+ }*7L=% [2iOfc,F'H?)=A񣃅P5aĤ3rڽd<=ʞ<˫.n ?a\(,efZ`C 0"n92&wobb^)0j)Di@K`>PfS?eLsA1̺_N1c1'65Ej:DqklP`鏜a(#^A{ԟuxYͿɬ%eM+onhX~Έ̢14 <p1q7mYFXa?kpQw{=퇗gCpPت"=uB0ۮ2ru >E/OtIQi˨C)?gfwS# :>k󚿟؀ nhV績uï.)tp,K@MoKMD#8 Uy_lw9Vxl-Mj>0wUW裚ML-~ :O*5nRp?`CUDI]nƒ87|MRSr6"`{CW<"AqI `Q-No'Ns҄ѠnsjwE@90Sl=dWnwlq𬿤&_ޭɼA룍E`U0IcC-Gr:BFMR'Nras4Y-AVȏ}_EnjxǠe޴~BmQ ԭMs݇B:JHh.1.nwE|-İyuLu %)ܫ;C4Lu(߈ yr}}ދO ufYⷊ-e;L'"~K~Z葁8~8<9`9 Hl] h~?EZuUkYsDmdj/E.}WA8RSࡢYus%)y/(MG  $.$@ ̟o r! VPh78,uڊ_9$Wځ.h9K.@uRx7Ԇ >{1 gunppV.h%/^-L1<)gd OlNkuݳ+ito]a+;bR#877uG6gоRY<6OOx~ٌR̛S;hF:k߀dN rHC")~臕㴕Za}I1̻'w~]'j}4zm^qn;$n>]n;믾Y\l#M0֠$:qQX'] I;DCGUMgn ɖV+xW&dj~nYaWx#89s@UiD~  ͠ ﱁ#AYBlf]”Nk* ;-|y|kdRQ!3g */pRfB'D\}FeA$ ՘vCu]E$,ɨ"<$"t1 XYK6y F# ~'n"7MKtb_yR8D&B>gk8UM*4/b^r b@ڻ C!&,B%(-?m6"5L*SC5[IiA̘/gZK)kAy⾢>$F u68hŊr P|mD#JHGotUڕ*z_Bېvh#!Wo!i'j+0f?m5>Q}Q@JLpK˘Z*y8;qT `qu8ܸgx2Ƨu@,Wz%CGv;Wfs }$.(E"Ký:; DqiJ?%TqĄEvgHs^ `w]"]`aeLvc#etc_N<'_̖ٝЉ=5)K|rp3TZ,&Sd\.gvZ8ڨ4v x.TvOh w$KǝZ%50"2wwpoRJz0D8MTY Qr`I>+g=꬘;e'Eb9 %?2BBz*Q\qL!dNަ:rLLE fo v5Tn b@o|l9g[#[o FhR l /kU1 P(wnh` ~$^3avUxTSrPee@ %7-RJi_8D a5+u]8]|f/XuX֙mڬrtyD?l&LLopG"OibCRof銧x23H=e(#YۙbJG126.Fu$Shɑ )'JjxV/%5٢SJ5 >s ߸WGNK!%;休0řGK?n&`W UPd>H_ #.l#8ɾuqd\=knV ~+R ^RD;Jv~2:tu+ZBvH"FEQhq]~qҏ!ud9݈x` tcFiɶ0{l%w_N8]-/ZXs(*/Yv!uupE9@)W WǺCo#y6&0:?uUGxM})z E/W4)M=(Xwb ROr喔94p'”FC.9 4MGQHyv2ϼ&JIȱ4Yw~3[JURPJ̗YlҘp"YKBE[[k#G\7@/aU;qmW}i4  u)a&gZФ 5ӷU@_vJcGmVj؄8lS:XUq`NŴNQZ'>l~+V׫7w7]; Qrva]9]BzNpFf jgA/q d8(8aF[g jC d쫈hBxvYڿ9Z$U/#qE>Bho5Pг N69U'Yrb G_<*bHS{T~g7R~d9*0Q@O;`g xVP@r,VT4(n>/W&DŽ4LJzt?®R$90W^ 2Cc[HBD8G\V?$ F]M:.OZi02u)㌅+*œ.P(R.W`j}1͊Xbqio'C!vhpZxkdzҭˌ2hyd)ʂ^M4I'9f@&co]!XI6:Z=&kByEv@c  ٹl[O @ZFeWBYWFhao'v o9n'OŐN!f5Q{+R]\030CTo~W[nwBK*)5K4݁m6s~J\+g)MB]*RT2Q@@]P_sć4Y؆XՆ S2 _jB@gr«v;Olj`dE<0{/SQphQ7u {:GK}<*cy2$w/r'F+U@m/LYdž>[֩~!"FgPScPw{cKςB}7DKom}'[ci{QXDWh*}TƇ^xt$p9U}r*vQbmdt@3&+ C "3Ix,h9~y62dP؛s4 2d$H-Џt#(sK1db?8"!lH) E`~[\uwqgn ,$zmRTw,W`O~.v,r '/0MGz4)0H] 3«~P`)hɜhWs4Ybi#Ę8΅dbD+l4.I&i ?i1j]7TR[MGrR`yo| 0lE [y2 ǬDŽx\ '7"&鮱)WOxexϘ ׮}CY;9qYG82ʕi pg9hΑ]׽ fo{AK316ՑCve.sKZ 9dʊ=B+&fNѯ(WJ`񎋤]Om;w[>F𒄫bayPa!ց|#m11zXp4K*-+?[+;R]Ufū+wTyacc^TQ-A(]wqᇾOEѫ:3j &TMFl8y@A%Pu[^jvjU'F URhV#6K%^YSyn5E@<3 Sk[0<7_6R`ne YI;!#e W0_]cXF.$Y[fq֎ *RwHDe*,iK\B;'^r6=i.TӡD-ELwZ^ !enotF]VoވNkiA& Ip:NL/%anA"klrWYZ0SԦvo]Xk~@J20m%\l V9LR |p׃|hq5 Av^N%~sĻ =ӓ>'$\1kB;T:<%ܧJU]EX|"cƬV"vo Yf/K~FM28W<͇dЛagFKf7e $I1t3_{>HP}gbd=$$6 -Fջя4jV/SKfQ\?x.%'5 :gW;taKnzm7UT5X,hD5͗e, +kϞZB-HW9f\ Ƙ|R ~$ҳ^ pE:.~BݖEpq /Z%'Nc;(¦NBH1扂@K#(*FxjT7_N[qWb; 1ֽփlZXG\P/Y!jv\j {NpStA9B" hm+`$K^B _8$?Rڏ҆h(Ig !Ap$fP.j(Qy_UBjger3dZρI܏zE`$:ckoC%;k0ӯךIY-b3Vy3/v))ϵ ' snpM7Bl<6Eoͅn1.`3NB/яogigEoҐMW0]nܓ>|F pwhCx] Ɛ.)w%h?aG]  Oon 7ƿ>=HPR#Ɓ82q?am2jN"".D*Ƃ9P.llJ42t!O? D^ GA%\D %R:c岑eT3/Kgsl*jyI/w(p Q J5ҎԿ6Z 8?Dni tȱ>ZD$a*qF2(A^g/vȸ̏\:w@Be|~Y<\%J۴=k哠61 ]-5AA75=*a:J_C7j1H{!14T!#CIxgѵb ^4N+̚]̆J)璈 V[Lrw~jzxYg:m/ UP_b9'? T?bK1LH< z1cŭE7kyƥbjoܭQ399?].{%^#|5lXe4dK= S,@3W4KzǸ75g.:,c0s";. 0}#;w!6!&[i6Uj=M&")2ڍHmLx9F$h9rgMK]rc_J LJ4b:jD8=*!f-A 6.5M^pMWo1K_Q8Z#oH'm4DW`B/4%'IF@6g?t 1T=7sn2Ȳ#C]Ie}9TT'G  ..fIĦdth :yx]`$Sܙ'"fzh Kxao(} فSB\>v,UeEC؟㗥,4(U0LD= |P9_^+ϦIDD 2{K@v.*)̐q25Lb#Fy.[DM*۩ ,uo8ÕmLЌ",zi9I*Y~F92>K4l(l;Z1}!eR޲P_SPškd<^DGV0 AIXt36̘5WS{xy/lʣ0.IgA![ƈWqd2/n`P.0ԠjzԑР:,9FGI/74YUÍ:%(N~/#EEoҒR5>TQ4NpH{ӏѵJV E`Mͻ8FYУ&Tez~eI6 ]&-P"åH*P_ E͏SĐb  ku~`?tOZcO zk' fݱ:$^;I륜6cn͹M'=++IpImp*2lHd (ȃvs PlGy ckV˝k(غã6Qh*p52bD iuHz ٮ~73kscֺ>#eeXs\, a XTġo;HڶNUV@L[GO#ܿ8Bh R\,I] SC|&Pus*-=~$f|:s&%6lhVx, X1%|.g<$irR!'큤' HKH<`!d?j;5䄥c;F XG: aq3f?9{"-46m&{0>Dޙ&#DMwd:Qذ#*\>|&^P<; BbaꝒjĈEK9oN2R^^rф[-G;G|Fb=pchhQ8dN.ÓG"z~֓#52xIKsX:y4kQ6/Uw~שtD J0U•%G,ʣWi~^1kkͨ#/.^`}҈7L{mz2ʻ iͩATe ۘ(n#1 8B5{ZW=Gtlj ݙ$nt$Vߌ~w!BNŚظI'谇hJݞpwDXJ1ÙUc߂l{("Oea5<ɇOa$$)V@~1K8{G#1zvQ$Nsg߂6O y JlUu kufR$y$#"o/L2;7 MUQ/*=+=Lvtp9reV? C^AL/K5K  1ͅ(>67?hmPlg vPEK/Uz;|nx"MNaT`s)} F㔅w/Qh +w|mZzAfaO5՜Ғ=ԌJqp& ^B3pD@jfqt 8d 0^6SObx?5YcDl/яb{?mg'y3⍸6i-Ow\O$ъVZkf|b+dkz׫KF=s9 ;uuTRxwK~Nnٸ(<1n~>t8U`ތ]_v/ΧrϾQ u .Xs+Ta^K!xPD9`kyMiFR!tM(zL/Z}8x6[I% ؙJP{C~I8YWtA&,?<+ahJ \eތ֚t{8؂BK ږtq֌8TjaDc:SfQX:.L5k^u0~Ej <9UTyH`Sj6 7 _cYqWi3 X Ya 撗!X!Z$ T]KsR˝O) \큁~=V\r^M:0kR\f:?D?.jĖlJwPb&BSa@:E?kSQ%sy&!%+ |6i*eq7 в7)2|&s>Խ e'5o]G>t%]D jjԗ/..g@#_x< :5~g/8[NK~`M+a^-#xV~X?ؔ!zU [T MENV뭘\I$& Eu.3?j.* YDѤt4>+HT#X'.ŜkWL7D/bU3`'L4=SĵEp>@ARˇ='?ו]2ɧ̵rfu@/?'@~ql:$ WdBb9ض3JP8%[v+;8< :!cFs^}mA78C--кM\p{.|-'~XW3'ʩ%P7R&zֆAk75s!b|5:TEW|~oF fwfG|7iVztc]Q^3s "*̦*g\o5b`i}`+Lx @}SaY|my1yEW@|5$C67V`Xgk Z $hthZ(]UoS}*\f|1&zd/e[=-ZV 3</@zʴ$'EQY;QnCҊ/D4ɵ+q+,MPgb7$ *->L,m @?؊a7iaKpYa"M70LECnns*Eˌn" ";+c wh+,ݦg,9Sa8.۵.?1d_$eGq top4H׀WhdTOA0PIb: (!'9ɈW^5e\ײ+K Ua:̷Kk*F :uq,ҼuP#4CpȟeIdCitD]- >THPbΑ/ vvP/wXWr }9MZG罙b2%N bu_HD_!l@Jsy'x>HP`Ŭ?AT㡈7PN9ğWQM[{/HyԚm0byƎQ3pgJ'k )FnJ>f$Y[]AL$i(2(, um~\z!4y'Etj;aj`Zk]tAF#*ݒT!+g@]7.9@^F/OƶZVAٽ yR}QpuTC+8~&uV q‹8XwmCN֏>vڽ烧# _/T :[Ղhȑ6\U^"E*._,}3^VF( S?34j"Ϣ&5/>Qa \6zpI0wO(]vMDH߶mҿD}LaPe*}&xM5j {@mIbvо$X>U:RU*FmDa6Ov8b-0@L͓ĔEiN!zBzk+=nUmxdϴ4VRg,օypHxG,tS >])l8(5vʩ>K򈛹3oM]$V[q'qfﲭ* ytFA#wd06g}3hN h7% @Au⊐v?^L*C6r &šrWm:+Rdgt-%|o!. OܚtHE{G|`nr $}-<52 /\I_v ޹yǥnbWJMrR] 9@Y}W8N%MYT}.q#4T֩1&o[mUGW4Ob5@=U4Ɩ}`B09ڜjj$ĩcKXĦ>~e _2W\D< QLLC}PH2aiP-I}VPc?SyJ5яu,ύKshޗ{nǚ{!x} |uf3QcaA~m/JV;Ÿ"t9v\^vO>`bT%ӯ븣"tY[U{mCL67A\>Qh/q<q+)W2sQs g_b7DԼqM&5Ko en5]YÅ"`-2]Ȫ}"ڞΌ&!Q`|?!s%TdLOu2#^YAΟs@.@t1`brͨNL GG]l!`]K WqvY. $EL V5%e**6"KD\;FN.,%_Xd_| vW9*VX^RTNѽ<"E s!:)BL{Ƭ}m e/& RG~"þ缩  "wGk o`O/RJ,.^RTyެOIO>O OևWk?e, ÖpCJ D5]'Q&vWDH= Мx"籁}杒Tp; 1mXzye?% :ʕs ;dÐA';r\џ4>FG -Eot!LI+9x@߿hZFӓFąh$뻸bi4vq{o=_( %U.dQ JS"Bvm#$ 2(WdzmuJvexr:P!U!e+ɂ)(!BapVׁ~+1A65"×]|<Ս"{m$ @27my> 5}KJOHG z1prh(*dN3(aMnBbP5yӤʕ0aZd>0~ҵ}8HHz=Ty> ~hlB>>uuozG`LO}/qxmu6h!MeN eF?OC6C=ӏ 1d4h`6>bu otX-/g]u힫!U #P5%:$ENOf 5~rӓ[G\@D .ީkaG5]1Y$ No͞ =COК#ƺ44,g0pG Z0('{O;%y.ڧvl|MC 2O5A߉0s(r8pY[lJU/@f~+b%X͒3-w ApJRە(lvge£ J6Ю3qGS7A-BiN l?A=Λ|N ލד B"II8V&ȊkcD]P)V|{:@5κ3^ĉ)7'?[<@ϻPv}Y=ŮIOX`\BUsp0c8‘I= )Vq< 񩋖 8}/e_jH wxEZP?= |J*%;r}hd*NF5U]W:pI Ɖ9Py|q3*',6a;d%3 2ߘO8`m88Y\?0 GdQó:RX36cp9jb ؼtl]m~tEzI*M'׸(5e@, lPd3JE _jIPtlX2T|Bm~Jܦpjr+]2)*mKmQ*raZdA P7AuyewVaWJ+ĊʹT,wL8;_FX7R𳺉²s\M8>=3=;JvS^ y 𪺼ʾÛ5)uHL$ 0$nJch K߱H  ZZؒLhbqPh0:_(.hx%v3EeܝOT馭[)Ot&HV:c%/4v@V e"lt^X`dr".Z jݨ+cio#a~!bchXTD|ds{fhz}`Vˮee:@dsɤ" hj: 8'v Br)M`ԉ?FVAPT`6q9-rKԪJZhWxo||l\pzF!ޞ,!idq-qL`qp."[ U/O' -f*4Hؾ\<>YG6˒Wj36~uʎS5J2clߊGԊ)ޭ"H޻DFsB|\tf݄6gAfM w]ou'EI 7*.D%/ZM2:g C +mEx>}W9Ӭ#bLv/mI., uc.(>D̀+̶kiM([2 eR>^Xb%|[7 @VAFvz#h[+Qcx"[|WU>7]AAƒJ23Hls=(&~*$U _!-/1RDt9M q=RU8 RVYKu5/,01(_0oӘCOv׉`⡣|8*Sh6aTK9I>.+R5biA\԰.d,PS `{ӅQ+6jR8YΤ%l¦M %߅`bIKt%EM,s-"n`@P*,^*O5)~bJ#0i'c|7Y=r`j7+_*R2}("I%PRI !HFԲ.1?~o IzE5^^\2 @ao;n/;Ax_AU ,y a+.rx޳\,YsUm Ewخ@zte"Rf>v!%bN"efe9s5T #bB)O؍fg:O)G|V$D7Ʒ~:[}s~73lWa'b k9a|L3b&^&5ba/(ou+^ԤʴsȈeC!y:x @jy[xPhJ=lh-N!.Q2%кӈiwӲtMJ!8seou;^%l(.5I獃mh|E: I`(+Ap?xE# #^NfMa_5 ʓmwGxܽ J/kt߅-0 =O5%@OqߕQwE\ *^2%K>Zo3m$`~O \i5Zܬ|1'щi [T v B|82<[,VȱئOMv j z-RT5Hgz>~ߖ:rQ`Sj*=uGy1ve)Bv Q&J\0,V=0~/z(Lp리 ~7͞x1,8pdd4 E8ZGSS8NJݬH0PT$I˩lMᝀ jOAn숵A\¢g㊐aC>ǗVߧse. g{MY:4\ډI;ռYV/"ܔEL_&3ZC#:Mnrx_:R0Rę%aG}oC0PgNoĘ~]^W=|*:hhɸ_g kJfN7 CkntGtJڊX| iS˲r_zZ푐2 4Z2r{>iژ\32ٸ>L>+pp9VX  ~+ٕX<ǟrɂ@tJ?^&i<eti* yA]rf9H| S:UZ=nyv/F&?P໳!Isa&lxU`nq7P lu]I["dqAvFQLwη78vߝ꾵6 UI 4Z-cdl50t1]ĂRatFqx[PSF؂.1\po.C%X`\]Sbތ}>=0qO[dTHVQ?S~]ݭ)]TYOY3&1 4>W qٱdX7&g{U }]ܤn_/bgu (/EL[Ts')ѕR{E]Y9 %bu_(շ/iL: I(l |$*<,j:eFMg4UL{[%SP:p3 xp6st0d6zX6-961 ^͡XGg>NmQ{WBzKT::v]9E:N{5H/e90CKKh98>VZ<4fTZA-(jD+0pj {MٱNe!F2-#- ְtjyV,̺艭PCg UD,:0Vѐm}e`#{WݹEn3FGM\<I5w =m w^w*oA.soeE[!Ӌކر~Ƶvb!ظb, -1ei+J_%0G8Ɛ Gk5{g/"X`rGTzRU~9&4;k$L@;=2Ba/ByDQZ)z􂝉 &Mvkw{{Eގua:fP-5*Q$pwq=X Ps1xEi@:t4#'ԝ؋*SePzAq)b^Q϶틳Y \u6Rۻ@|PyJAdR^B}AFjjY؜U8 XFFB-i'AKoxyS4肼Z]/kBxs 1LO!Ы Tib7a!J4h-ePF-`VrRNl;6:h_ն)q+t S"^laa}H%~]&f7}5XWc7~С-j{4T`&dæw)T9h804|WJqC{ftXn>!l7S^8T2299 F_DԩL%6T6i]<}Ioa~ȍCVaUSi#ɝ8ckɶ͜?(D̘6!, 6H Dڏ)!3~K,8|$@7% t=j9e߾TƷ[D!]!/XgRiY]9hb^ an}auar߷p U&pv߂/Y~TXZw(F؞ +QQ}G͎@jշzB9Xrtt7bPS.cYuTt)mOZ +Mˆoz}1͔1mf)1%}(D *%qոݤ+t@ g{0@p:ecYQWl v(@w-M׆`kOk/+ӦKFip2F "Wgab%씜݄xeP^k2v.ћP;t%Wsl|xSJ|7˷^S5WVJZ:pl YoTŴjhȸE萔 RjJ[ȧ(eP2S믹7%i*PC4uQ lxh)}?=51}lSܠ;1ʺTT2CQY?CDqV.}a/ggMuG{'QI{@ %339!VVkЂr,'.gj uαl(ORGٌRu_{rlqLokl 0Y ~jTTG)d\*%泿H_½ڠ [] zh+9t H+ !@Y1Ю۰vZt1ߊ%iE;۵ou>KՄOv%Sz`<_[(JV3D!\)` G]X|[O$ jB A- ?WG(A(g">N\QW6p CS<2pnשh<;@BVƤWz+3gͶX6‰7$)֫6kLw{!M35i~7R#ʇ Myt:Tщ 3A*ys2'qRWњ]3jlYZ!PǤCf!Mל!yRk ,_}-) L W݁sϋJHj ^NYqeHwwϨp|ו@tFv^&Xtg͊I[SE;=۳p?*2Wt4udp._}6/$Y_ ;=fE0$QTo;pw"B|GL0m}n:󋒍kMx2w 0̥lv-#rBE&n0Q;/3'PCP)u z!$J(F`2'0DUA8]31/S #eW +8՛S\"q6 =f:ʝk7ᴥ\d罸L sBTܕ8&xJ qʁzxKïCn )eOFc%Hj_$\.>)Dm päWBOaFlcN` !˰1b(WAmI)(ou0h' WM>W_]MX'`x:MNC!=k`ƚjbo>釸XemzPeV,mJؿ>Dg*M+\ܲD螤fK;G݈}@k F;I5$CXXL=3_H՞T |G-}?Ό_mT`d(uLjq(D5Aß@ǻc}~.6 =[~D5t\)$$>5J`۾J۴v+(Vv*Tur;1#ACl]73 Z蟶s9`@+f.3 R5]3-j _QU*qzQ 3s E@AdY֕6 BL,PwźQ?Wz% X{ .~=uhCEXY85zp5`N2K֍hCVSSƥꁆN8z%9d 32z9 sҭQj,k./Քvxgpw[}ݭ_hi:#2%Qyi@}yG8P.N԰uA[,xrFG=ր>h׺DZm Jnn(g7qRi@2|aV@G_$%sXY?հpJ>߰wEQ_o)"DzQG&ܣMjEZf%h^g@r֥K(1pOpqy.„.44SfCq^[̲c_^<d͏m;!֌h4/pASpXڇrz9- Ӆ,B{&`{obJʂWf;GTdژ|+\q."N|ʼND>SO1nl$^2}xϨ4u)}ʶxk˻cޣ!||!o߀\\oF4^ iOe?>)“q;ٲ9JyRild+}D"V;w[Q*m.Fp_xSTI7DU*H4 ؼgM)A]QpaTP ߿{(<h1*UIK'ǎZ5ж[֞C:kQ_EV5ϓ4 639 TRED&A%ն(H- ? ݫQ c`{* ІԝxG6/D:It_.Ea]^ ` N,_h:sOtT(V E4U!ӆJE-ti7[ѭ!7= tN)㟐(tL^㤞=l@)X +禆F0:ͲXaW/? =)xIpq? K.-m,rه  Y|ҮTrp6lI۵Y;{oVr@GLϨt{3PBZu1W32mYӾQ A Z~W*\ų=ó2)G/9D$O{aA법sB H&Jshz(r{ana҄VFS0Pi@k058;j fvnǴV0!]/oF{YZr۩i{:zh0>Ķ갂9$_%BSD]kƓQM\>ܻl˧lUugy \lSpOZ~34^¡XP:*v-q~Wj*=vGħ2vO;}P/5 bOeq3>-JLJ]tZ$LdKXnqv%s#t,Fuc3]5~7 %a-tnY)3IQ6_{TlrR4m,nN DWQ1ic$x-'/ZOFM3sd mb6'KQiPh&DR%!q~|3g?V~?Dm\Ew4ȬVS䆘_#Ռ Wp=QMme+A@L~3ev-vQ7grw+ .3 Rs֎Ɨˍ(?@'Twm;T9\o zu *N1X^3b@~Av ^$&W&gXKG+,kwrI\wn,LQ],Y u޸2!{+S5]"" ıB;#SvJ6*ag1uC)bOЊ .K%~ +BՒ%wuE˷Af97v! +k?p!5g䙠U#RoAp0p8.$p1./sc+錊3þ14|נuFiȣV%3_}HyB>"Vfvߑg>yM+=_@VE )d Qķ$xo _tȠ+lx&H)]mA`ry\ndP<~kZ esщʓPzE{ Q٪NeŽr(xKFGZ &kE=̃t5iOiHA(ӟ%Y]ݜI f0/жJZ#GIF0eei\#,A U%2 v亩<3-ɿݯAֽBaFoxnMoHO&%2Wx㎕' Hr">i $èL ~irk şDV˱=Ȧ;?Gr*#ϑg6~$NWw(wVP&r=h~ [n0 VB-ȯ3"CFmyφSz<\exs0m.Л{SǤj> OZ|{b_UzZv# z9#U8=vqQF)lM9Fi5Vu=wc*h6RtkGRmo4B; ȣUs(o ֔S[.S0lbW/F.M ')~N\QvB_}1b9x~k]',':zڋ%w'.& 5wwp+w\khTMi] Az87I9o 7LMd$DMxv48js^?`P[mn i"Psƺ e{؋]q"s7­*b.J?Tguȡ{N| nC4soh^h%^kG ZfvB8NؓA}v8m10 M)cGn,xtQ03 ~"V(g!#MjsjMΣ?'($S|R49 ,㺦x-so x'J̯//EP )yۡcQ- T_e!Ǭc8ni5~2[ {,R8ի zp~c ȕ@zΊZ5{5gIZ2vF(3Xi~>9Ʉe^Za$C8 X"khkj&K亐Io ˈ/f,kلB}͟z[/n>G)0_B*D[ӶYHY5TBw>jn-\iv+_e"#0>5Lq%w.)6&'DL?K<ʎڋ@[NMJ$PW%Vx$zt9,& {z+˴ˣn;Kדޏ^vGR4ȫ)O0ÁzsS>$Uɪ w,>\[ud.rFY`f8Hq(k=ڃ5Of\Ȣ͑za|K"`ƾb!d1Cw|||ڒ[ pxJKecWN}CGR˯|x]{+J$:r%Jo,GgXlFO4oh xEX1p72|Uc8y7n fӳ嫕 !j΃8~d k6YܖQobQ0sR ǹ5Qcu@  ƟK  ֩X, (^Ob^*v2i Y{x3(ڵmwƊxj XDMȍ! RqK{ʬ+a_TEVԌFD NUB)v)W l@`xP-؋cAI-볬C_zΐEq'9c !LCԌ|':W^87it ɂѿM4@-vTZY>rTtbjl 67)X@v Iْk/UpLă\ϥvuSr <٢j;-mb:iF 7%r0/KBL{obvkF-.hӧˀ0xoFL14NjGeYmN`s Lc*)>@2SjnIT%+!ZnސiCföHO@fW6{i?I '^vNY0s'f5F֍̉/~~r6 \ŞI f]9/g]?{b=v "koՅQyW]`ZH=WaBgkQ֢% Ѿx _:,I)d`?BRbnS`l/ ukm7ѺIaHQ#`Y'xw_+]/er_"H7)@UZA!7u"6WxK`-Cp܁40e;S704c1!'F,\Mf!-6rp7@UlQA0bgPKN>՜o.oLqn;Ĭk,}jUn3}f{^jfgjtNŽn2$}8mt/_ E$ C{5B}?g!Й}Ce?O)%%k9uw ScNb+YǷހQy@SO]RNjxRk;(8h/Tsgt *2*o4300[^N9'G5 _լ=k~<#KEtG/;x)ߍ!VM0v}ʡ::[z2AHM,u41d7{:@ PkJ~H&+.wsȽq~lgāa΍^# p=g} .jt80~=^l ư\#݁5$[/j 4W?ŕ9gQtHȓ|G p>ir[v-עZ/vH=dܘLz(7hqi< o@N?wRL&S*CD##aMOBp\颗Lu+ ʣꗾP 0܅vG rTg7Fjj!O3(*k6M]h{iɿ˟#76] v;9tfNpȠxcDDLAO*x;i\Qm5>I*iîN1 lJq_K|2yO*XEpyyJ?UGu% ^(}&s5,0a0_AV\zsщ%'brl2kLjoE/ok]@T"ɚS<rE.X;'{j_/o e~+;nU>J7pu X=nA^ZN"sc\TBMc(e1ͻЩl $Es'⡈ΏDF,_j:Qŗ2@0YFvC#Ds=@GUJ?vsYqO>A7#Dr&&Q%V.YT VT2A;KQr*w%88`H:B%0iVLI$шvET- }ו [1Ff\nPxpښU]}5𝎲0ߥn e Qټ&K*ڧ]s߄vSu]-Ei*LO)tVۛ`JWAfC8rd+ew'ŢCJ4"~\F ~@L.վ%8^cWiu[:>a_Z9g#>o\%먍;^E y.A(yV`IN%o^~zzG2+)o#CUPpGu懛5N؊Re[T⬼7;Ժ *NI]xU~Wo)UCZ`+. " S $r\ j":[|T9KdعtpCerHtqbn_MWٹ=y"4Vn"k\l'HY CϡCل CMŝXLn&;Klbͷ"%A:V[O"N< &4(Ju~Y;h ib_KF~ѽ=f d=Guu+"* j< ;<z"h/.Inl`f}VcaFom;ˢx\LpF. E#i/0 @)kcjRݎ׋}5E5WƮNDNn+ՠq˨z/`ʂ|0Ug !Cl/7lB _Ql Z tD~o1JgUe2gỖSV;[ta %# >x,:q&~>sa.W1rbǩc=-nQ[b[#J0}W)|05d(Bh|?b=ݜ.=p7y6AҲPΏo]l-att,Ycs !8bL/̂ t9ai v0.fLU*y_B~tU k~Tl!8*'@,H=SXO~ mlv j^Wt0TuP |_q'gx}^鮔dQI nj9"0YdP̝r) @v2 MabdG@;d(nxT| ] ab<\TEeS#WMj +%lށzxGJ:Q걳kCdtAvŎ`q})]B? 2DuŨTDݴtM鰁,!w&ɪ̃=D7Y9@d3ꨁtr~.]"`.fH8XZ}ƚ0c-UQ9K#L٦bab$'ge-{g|=8_o] :ɏiIO -JtI *ǮEl6) @]]cx ;^[Jzf(FLR9&Bϼ6̪eoPYڻ҄jsy"RENJl5 ةE\ ',ADyjg> gO< +"J /ٷ[hžȶteT'EGu8PnDVS:Z-~ sZWo Xwd]M%kG k 3>^jZv?"ti`߾bCDW6!b}xT5IB(egF;ѤL!?b܁m9(u{ V֝Sbc}UO&^ &p:T"pKЏ4ݧA@M +ZdE [FYI2I,u ўocl@&TX)Ŭ./v6k M':Rk @]IMϺ\U宭D^jdMmiHά X-ɏecq[LR b@(|( (Y:gq9%a!.Opx9p49DBF2既lZ`xn+TB} UZQ/8.lfxܐn 鏁w6Bĥip>^'mǔ=sLQGvk[9w!ӞT1~,Rb[e0%yjk.*}#VO iz0!!Kz8DHO_ 4ٛP(;F}_5iGZ <ž% WU@w)w52nc bh[_|5Ƅx sY^M[8UŰ핓DU8C+l067nSAPBlof2 $LjCiBiN9LRɤqai:RǨ!+D{d7&DSI`)?uzJGKsRkep.5MudIGqM;5@**PNGUgKqM %U>iEx9תQ 3G=69 %~(G oHq=xiejHI%HءھD=oh3.3 oɔOE,y uvBAdGKRYqȷ/ʾ16`ސb#^Q:-Cm7| ?K[>'l4Fjြu6TW]HϘ,ԞC'TK>/xfh9Ğx`(dvH{㌃!YX[&ɶzZR٠l B,@յۥ;g"zdrs/>xm&䍰 (oeMTprn2Qm+t#_h֚"u[^THߘCdwE %Åv] /|*Z@դr({9OQ֥KL؉@n?Ғ2X8(FO$)bj:6P`ځ36*߈W0L},wlRԪuV8ӰcqA(+8 Z|$^pktsa͊F 3wE%"Z7lj1P o=;KMd8xҖY˧n:KĐTN}#IF>,HGE(*I @3*}L6s.DB b91 vDzeRe FA;qd{Qr y]{x/l?(WƦ0d +YL? R-d-/IUa|lZѪTNha缜pќ^2]'7E^,@(KJo}PeWڝ7_~MFǩUP/. 50:0ɧ\G-Y%oh) ßLа%J͋gHQL˔q/ajN?X?'oЈ7:J[`xjk\'h +a=B I$d!#m*ii7q%;J W¿bHq75Y/z# +_f,H6ng=ư&X3ݤ$Y{,.{ }NeˊdJ oBD?K$qL8Q*Bkȓ = ! #hD[t *]=*h{8=g>y1o`ɢ ov!T)ӡĹ ^_ NrA={GšYBPemrxFqh+<\06Lx[IJ;.G_qƩ$y%6ZjtIn=g۰Nt t0P\=ZX5G8V]Q A-}_rI'|3YmZfoJ}E$A﹩Ch{_߉Ӵ,LOґzw}@'(E<`NWp]JqHjV0Ah5193^\`04=c0rI?%%vt%ď1UMG cv|?Wr[feϰiiJC'}Z5-$}\:|Ha*ɂR\:ea-_MH4'Wv[Ve7?B|Byko4 "d0ugwe Ɛ*HUG!9z Ţ9(ǹs rN[5lP\1AnHl x>b@¡]b{!Ik ٿ牌-mB*@l?Y31ʔ6Mw<&fY3go84Lv TE*rcX˴W ~h5s]0-r4YsV?iEgwnf $M*V~JGUj(1?K)8T^x/tLj^7Dy{#v"cL%ma)D={"y *"XbDT6RI;M] A+ @R̈́JƠdi P>ePGDJ6s=!^eO]I]}$H}o}_#<K+$m]| lee).)[B4{iuA_Y}%n*Pd0Oo$5\UmAo6ԌzS9|{~Y ~2-#J柭($x*B20_O^AMv'tw 21Xځ3Q&\Yߠ# T^*wƽ=/IW$ iqYiIˍ++ƮKCJ|@+ @ksJry,1 CbDQ6Y# n*^9xQ$wЍ$` }7n%!L + YV *D|B*t3P(Ի= O{带L;q(d; YH*cLf,N[~)q)ض ],ˈdZO C9PRbrteFjuur&iQ,9{6g筌q7&\iUoj*?ֶ⧅h%h͠)p om0Vt2vbq@{5)'QJ~ljQuk>z{j!AU"<Wjo^ӜN\* oTz$(wQVg_5cۙyo]s`t1isytHaL! wwLVHoÇ?W=i.OWLO||+LcpO5!o^NTlRi_ v͓N.tcy%h_F@jud9,/Ɍ紎!9iLd#譟Nj@G nGu"AP8V80&N+%h|}xo$&$XԼ3}NFJ1$Grf j0`n%Y\m_ۥG'Wj~動*tU?@!>aZ!VkxO|?zְ !Di3JTtbڵry #L|$+%V :g5 <(`"gvg0F@Em;&f:)>pvk~B_'D&ў1>pNPL?iɇmaHK-jg ~oӰ:1Tq;64m!1hF FQFdKBh @GNB^67.2~MT*IOhFiV[Wص[T.\Iƌ?x%בXS{1O;0s%Bl {[k(H?XdqzJc _ɀ|F3ʍuk³ KzzXƴA%=5\Fdxڡ̖lipCb{ĭWKR0x`qW_K)1 sUvݱ,tE>sjkjTY/Bf"gYW;ըMq$j;-WY%*)|Ļިb[Z_i~(ĘIe/*H,vchlR6ڧ R^n -ΌgkbCo~R+6R'U AG!]~\.[u e;$E$yM:Pg1W)hdIB4M|WY cSS]_d͝ҩNAj?O\)2j6eb[$UepF6ǡ:Od_3y$Ydײ#E°_FWJ>E`sR!%\]MΪR^Fg+H3dT9&MڔkJQ/›(X3b%0<~[mLzbgɇ՗5&6mʁl?bH;'2r(o$fL YdjIG`yVfg'Ix,;9t 'k5sW#V ByϮ<I)Zl4T]rَcIJ U:J`,Jv?S`$ŔoYSB3 qRn*GesNѝ!ܧ8n;d>U:dj{!fE0`}tqp uhw0}$;[ 1Cw<{gZ=VOFmPñ A9CK-'q+%CʕRYx&4E]5@՗]5'2l<{g["9[U-b9.e2[zQS fkS䑺{B.&rp+yMcD oPɮ#89ʵp;&;pICR d`^xmSS5ew)QDYՎtlU,8'H]L `]E8Wp?Q5MMh${z4;p}(oּ,*4$JtsnGXbf +F,U;rZOV+f^ q@< ;|WqUems<.3d l-D>YD_%B i ܽcAʟT̼nz%[<4 %*g1v \! zCk U+%L(dY/ 2-Cx@_SI=fP#wiȫBG20mA%O3^q'^+OI6}J t"("̇4jv}7Hd@XjEƏ( WH&殛H<:1Zȶx9/mÁ-S=,^%7{)cH[x+ )JGL4.@~: 9 Ld4&]9A;ĹN;m `P0x.қ5)ސYPS6f*濔F'HQ.CkG2YKE`2>iCN[rr_-+@:VZwI1NԵݚ3\-:ٛQj^({ Ёy(="C"-4cicШϚ~* Lf8$g8 5tnmգ ]W"BjUy.`&강E ME-!.1ۧ_f~gRR?|d!IG3wG+oH`墜HJ"Wu3gZv_++t+}QK)-eoaيZ*Lǝm9dG z55AA)+ #徚-讷PVQ%V4E>)w7¿Ll-%M^"B̮ 0]O%\6 豜 M-_` +p,]Dz 8 m0ct~y1W7".B!îv%' P/5n\[΁hd}h4@t {aȘO;~IpH5BT@2ޛftL'0$#{u;+ N; >ՕQRFK{W}̰ v1Vp>$ޤo+T(gౣ_7B,opRI03$/PlJՍT'T{Bca=\K0u`vu{N`p[L͘m>2a0 yN>;nb8yO“>[o n, *UQޑ7woSH!~,KD^AMV:!auQD ik3,{A&rbƭbb=cGI#-iTfSRØB R4'ܪphlv"E#j)6x英6~ؽ1fn2mNJMΦh0ɲ5% pً4Sk/ի Z.cGS-s9㪆\m]}ؼ ٜ2bξ i]Ƕ=뾌\f77Bp2˞4&Y dVnBۦ#78NbFFp[r1gh,$Tv?ސ)ʽc+twmN j) <(Lew*~LZ/Ɨ*Uey" v7/STؘ}&=Y 1뫜tbH~ی1#c{)=<И3K!ȧ ;C]bKf/DUSfW5ઇ9"g1Ǭr= X. oU? +i8D/j+,AXOn̨W12(<ǥka[U5]ez\9$]HKI"Rg=c G14+QaéVH%O`41T ֤]LJ;< QjCS#a %440Vpdp: cS ZOmTV赦 1-sRXYrJs!{VTA"wzUGݣzn0hȂz2D转[֐r0EM^yDp1)$|Ý^D9VmLRkN֫4T%=2JTj"ơ/X* pj9X8}DAF7ejch<^$@7h'`#;›Yt eu=V[TW+1.*LY?[ߣCaGH\CM%l H|Q!<ˠXL{&hk큛GF.lBg^C!A 5P >0著Y >^E%^6v0>u4NsBݪen8LmyD#p,q{-= G8մSK5rjj`yE?D[%o{/Ui}Jq1vْOlF}'5[o֨vd6?0 MϦ^E0?T? IY94;y9΁7a($^kuk@ss2F٪CH6|1Xق(r/E|ﴌV;PsQ$yPnJWW.HpSÁ`KKmct; 6%@K ZʯTXtw}WG>ʏjͬ)pʥ^p%'7 oMC܆Ϧé46Vl$Rs7iaَ,S~WXb b/f4c9eƋgTQJj8ajC~ՑSǀw*uCCعŎ͉$ͲCvvV1B\l>E'˫h _F.ݪ|w1f#fwV2HS̰a hr~DQQlGG?X>;k0C I0'b~aW$#qȤy\,zX1e?2eg=j3v+,uxm`lK %E]wb l5fd~e6|Lk[s]W,0pP0f4^7ѦeU"T,f17G5z!Kr i7tn9 tTzؙ|\"0uk9ϙ2@tm(;,q2'KXeɉ/Qb![:3%X*^[ `@)TTƛWSzM5گ-CF5ky<9= ?;&,K4 X9 N.mǂ(? YZP6Ơ)ܥ mCcQlH0()HeCk=s7YL#R֧D2fݯ(NEX-o 5`ijlNsÁ?w.@ 6 t=;bKJ SA@':O5k`zŖ[p'iYuh ;F43hlxw|ONhE>w\X^ ~]{kq-E̛ 3o`#DWAX>cx.?|Mw &O`G*.f q؄J߷Vn@(:;{dy&Q$g\(nCmL.^=k TMй)ˈF1Cs=sAHa |/ ܞ P#zO :u`Z ɇ` n=Em&'b^mwP\X*5QBk`uGdVl ݡ'e(Z0S6degUXHX}fأ1XGF5re[{`gL~U:vdQ*}m_o>O|>P@%w]pLq42^̶A84ĶA`l# GCĤ&WD59R=){ =*pmw7(1h-Bin;uKdS1ٜ5ʋ MRXXss[j}i)h" h#hB *K `ڄW1jUYB1fk7F.8C9BVH4oga }jD]<\GUY'#TZ>@1n?^Iwa$n#6`q'a a[ Ӓgwn ahxh0:< G20.|,_CkO~UuLR>BBilU3{s{\9*ϖgBʨOy"YKh(n iՐ¨m(5UEb" nw\k[.[&8 ;}Կ-p*cK]2}MLnM"MldsUsّ:y SH<*­Uc9#'8;R*ut(@KJ#l{"WQs[++$VG <]hR'A&xhf{kfN[ۓ:w7)"6 o,i`Ě4DN̂Uٯ3=yήg]T͋WȠ4rw/_B+\҅D$aro+AN 3g@& JwFmǥ*4QX/<[ÓSNvc wcϱ3Qvu܋fKG!${R;=O5([k6rt+e0p@Le ŗ$Kb,/h1zH@7; 9n#yDw9(0ﴑ@`@Us0xA-||H3FX r(Ӿ0]t4r" &^Ku-j٩1HnlzOGW Kh7{)N6c?ՏQ_}䶔A,'ng~Sy/)TPf:yf\uFqacL{o .|j /\9tqΟnPu*>nuP†*4 VdBoPM+o EmyǕ b=ަ_:"dz, .4K*|H4˘d͒Rg~?‰?~=˥FVH `G@No ՗VS2T;9;Paxr.g@V==qWY<7c}K:W3{\ Dq{4ٶA @d5$#QsMx8aT'f݋cFR#HXE"mNN̊Mvypq)6PIX\Tℓ_I?#2d'Zr'<^Q/D=T߷%nXa~ۋFx}m DDEUj,meZ?r )/}6jtlgUxeX@zfL_I­0E) v#0>dM#TT}?VĖXٌl>E8).s]0P{;}'$z&\{%&qP, 9> hLnf6oΘv.l٧> .4U8O Z2l[;#t1XZ=DurSQa+`Q<4Fleȉ~m;fi4ml%d+ChL;MyL@ZoXM&OPx=!ްpc%>3*VhQswTIq2_>Xaڂ./~ Ap`bר< #dG<5[Mzt)Im6׏@[(㨅7{3Z<Cr{[r}'Qn6Eϼ$U9 nvO_2/ƈ:xӕj` -t˸j@eȃXT$_BBy+#(U&xz7G6SJk7O$"T;60&`qAW(rއOyTǪ_Z7M{KH#H&љsYxS{~!pT)=ɍO+.-SǙ Vn'0'y͕wXt?KJʟw&ءZ^$Ϋb \x ҭ*lW轂H1e| #=XHy: O7;> mϩի'nXe'ۿ􍀔dЀ:;iCbnV64u^+h(% mT`P !62wڻwPxܤ}gˁriuZDQzqa ,4n? ,<68ԦR&!"r9Z͖OSK@);7JWiMk,K~J,Hګ?MFBfhNT!|ymE9/v\kWt`f}r6Nw--|4WK4.1P>e6).Ģ%yb V+F 8=tBLct4[->7DwΒmq:qz x5럦[tM›dȂ'!uTT5QGhff$uڇPּk')իQQ= ">t7 tT<,Z v=.% 50TY@ I:݌h2y]>Z0u )yl qh& [4 ޾DiMjc@g?FD$\ )̚@bBMljzQ1Jmzr to.F?i:TMsyYc9R|;ێ*X'q=*hw$Sн[Eb>[ C"ICN[R %?|ksT+0ѠP7^}֕Avep a8"K!bޤQ4#oߏD5|9@]Q6gXtv*RZQ#Hjb$x+Z§$i]8ODp(LTA-nfORuZtBxZK{4U6n,ݠiq4{8u(r7 1 wěՂ"g&U dn -|VaSIX9hS#֢sÛ[g&V9*dۄ)eɻbjŴ~@(vsWn:o_7Y}4䗟#_ Pj7{HhXϒaa/[9Lx^QJa X \*g\t$MCaR!AIU͏Nz).Y_ d7Y~^MtĊ>![UH'Na,h ;+AN֙۩X7(:9ٶ禫(pVmA( p^QVM|fVwniu oCavJZ aJ ]31uMikdX%ˀ\;o .-d# BMT]/#a Lȍr@͛zgZwЍkHVվ<(].*w |̑ 8318~y ŝϰtytIk #ثτ"CVeRH=Buֺ$*}UOyQyYz[Ϯ4s,坧teG=rr#l}žs!7F'{}3{:>)fɈ\NH+ @ucroe,Uз,G)w%0DuZ~g:E1VOup|{iYݔqK+_zTyiXGQ7vor>k{!u. "2im}{ݮV Ʌ9su9 `ǘeaI"U3-j,i['W]bq R5_+tZ#DA:eTѩ~Mwf3hER(^?~)z@>`b% (qiQ 0)' לyКp0l@K|˓?9; ?F ?G2m;~gg>~$OEɕ~n͘%A;mv%7 #Lvj%ϲ<(}Wc O s ]*$_V4Gh-2px 8CQ-oȂ04K7GgSxlvCم-%31 YH4$>҄Zu&Ǹ;#{M {XI*?)<\52t s1h;J՛1ytlL^<:'P\yB&\u]`ĕY \_/3oλOWBӢ ~oUJQ >bcQEZ[+/l{؞ +MK'`?^B*'֕3&DQu$8= >))^" eC[8̰B%Ըۂفe֩e0vG9dk:G7_a2f &_`j/e:ZX촙XC{ Iy1U$)R1no W*#Y@> kd@oe5 a1Hz=8駃7G8cbx9\)KUTn &͹}lpzy$:8+C;)%W׷ޝYݜrTf zNKq0\^>Fl}TblgLuUpCMm*Im6]0),_>X] z\d_G ) O@?uιBXR 0ud0CYngfÔ\oX-<{? nrb a=;F7C| "T~\t?i{v|`TBH>_9>Xѥd^4ճhE͚vZ:8 n6lEG쳨[!bBsz @'Mɰvfj6N0YxkR• r]eܫfJŘ1b?y! ALS-\'^Й!r@U'}u{/7D'f_$뷂*{5Tи,l^ uQz >УV rGH $o|;Q</sZ&9~WXp VɆZDY=/!L`BD[Aq 6o&Cru6'HџoNDjv> @ t dvl)k|CNJ 鉏 .|&iAE7G=c`[7Td_NwV4jbY)iBx>eƀnI@.cnX!B'yz{<6}kP>6߀Ceu!k&59jQ3jڒ"0UD`R9Wv92pw m+ẜ pא> À@ }S˿֟'DٞErչF2}O-Zcgy3!im v58z# `5Ρ `džkbH2CDՖ!7/͝<,KjDK9*!M&KJ۠[Uj߹=c">fb$sXk T8D fxvc6c#%̡kp-Cς7sN9Oø A4C'X'l1ٖ&>3^Tb5vQ_8shs.\YlFQJ$׃:6E^@2aUFb-ƺ9*J5t9Xgn@m:Z?x(5KI6u,VE$[#u Ж{ʮл}7zJ z`ROz9#_LWi:_őhS)\L0o6NWcфpbl!Ⱦj^N ;mqy_uCd%Vy}| "H2xUJĔ:|Os|҅&_0 c5%֫/7;|CC>ᩃ{Gg G.?&{Vdc@:dCE*T? {Ia@SȯfDԸ2/Ĥܡ02{wFs]*j,2Pލd\aZlc5 L1M@O &DG;}{9$움ȋ/콙bKF,'CVVpjiv3Qv*3 k} lE@ Bd@?yM&|Nխ6epC\٘rR?s(e퓹oDpȁ&zj4 >L̮jfe4JzVsNpBc"RLdb5m;A TѡKXNo]R粠W #\{]XB|(Й'j֛= k="'g|,L> K,^ OHZ(:h=@kl|9zy_ʬUo$̶^*(woFkF]zfJov? ] (s'DGos!ian":7+Rhtݰ= E P7kVN%B}A 6RVO=hogW& [+KzW/3֍lҾo7x1/oZO:252Տ}@|d^*W)f8>/wxesPB,7g1zx|A_xf3{[ֶϓN.dcfZqserN|;߳N(-wcVLo_$+ԦytجR{&MXc|6aCf;3kK:1vm%T8b[kYA˵U=5CB.tu_4Dc!2&+v뤋kxgt?Lvo(S@8/>=^ƽYo {cׅq[$$ﰩ4Ԅ(APiiEGD]6w{S@x9s:F Q㢮]ZI: @3?EwݯWTc[t mkiEL7/Nl:_s^{׿W Ī9zstuM_-ݬL$^!&IOc"V!>p?WFFm:<Y!ȯv{dJax[tdRңxp+۬3JJcXk3-{FUK19bhAIQFҽ'6m8$QRg6Q Ƒ16A%Td C]Oҿ_-!¢`  T F/37ȵO@i+IgW6.أS~u[Hsj]_HPL:ZP}x*\sIY (G.I̫evaV=%AH|`GLЛZ1}DomMia>EcO'ۄiӚwPw]Znuf}?2f_T(-Xt-qi҇ʴ3''Pҿ\l,tn[3He _"mW2|i05 ЭhҤgVj>'1;,!Mf30z&rvr2p0[Vv hmY=1{κ 鄄QA<<6\G&aX+F)Epo(frz]D\&RZBvm@4 ٿxpaC Pdy.ҽ21O3zts-WPA:N8,?2OP$pʾ~l_V\1L 4ټzq^Jd>?scsM!ˑ۷&[x⎸Q فA>?Q tgLV9v_09AܿM. {7c~g 46 m alu sbz`cs~=4lL\) TijC@̜7$.BccT}~[ c<+>ӽ7+u1$ma-c8Ӓ\:m.1m7 PE̐ ȠcϺOoyr?\{ƩUk@+c*qpAB؃uO†t4uxR&ՏC`UhI Q~\pZLvc mcFU*[S6gnVU/f{SY7ytvRxjR)K%\[(&Oq&tDz#N P1)r^J3omR#p/g<aAl DopHh_K:mÊ;lp^"k#q7j@,gX^h2ƕ,C=yNc5$喇4>v8Cy^&gj]^L4+'۟! Ya=niNfʎ</-2d_lA埸%iNޅ:rW`KƚԹFlPM1 RbAQߞ3%jYFz3'z-nYC[ i q/@Zk ";/漾_h5n;!w*v1Hf %ۤrߺ80X%͈+  ![j:$ #i Zb;OYVX#mo;jeb;az|aȯqTA4 TwGʌ2ZM<0v _NkF ">{]7Tk2vSɘcf(Ȥܣ kMz( ˑ]+} mRTU2oНPj@A~p)F`j`>6b /rFClϷ9%-ĈƔiڰ PJ[EWvoLs@CUUl?u#y=KD_gƣiky$Zj6D\9 _.k.xBrvJ>9H'ҧIc/A31D wL-d͘b%BWyNQLzPpE/NMCSJ?IER{L .IMhfw_4LW9K(-[@ :g+_ǁ~鱻;? ([J\wp% MpP_ 5_ !$/e &g93qؾmnv';bC _'_3p^rD?$C 4 mΏR7H)u B["JWVVErw^3*}H[F6q(:+3t\!Z9>%"*l m-kKF2iA;}ѭdJN4\EI"kz{Σ{cDT QYo6, K &ٟ",uJn_&W*mY') f)D'L`M7=TBoVtzG3&F23='5#!%NiH%d"?dCLKU .E*ۗ*[O b!`'uSDj΢zn $ODSdGlѮW,vnNæd>قZ]}Ӽ$/Kۼo!5yf.(~l2R}F9Yrc\jL&Vj Y(oƚ4R$)h#9n1GuW2͘\>r0F4C !ICYm_&h{=NoE+I#DU(V(oa W*%X^ 3^fv XUԸmqHl玻$y~ANNeƹ.I+14O~s ?I5&B~T9 >j8 (|_F+~1qyu)C#1UdCf-5N&Ĕ;-KJ; :w<i- v%~] x< $o@xt\CIpˮP$xPa8@QNn@V]Oj͐/RaA,S'PтW/N3#WA .jl!w "xz3ي]_1ql= ש&t-Q!%'8Z )80 /D _ ~< Ͼ^i"1|֗S {Ͽ~i,/o:JVQz)n-EM6Ni\MYsӐ9{{DSBXvT'RFՑ%IP[ݴ(y^%(>{޲.&kf:;?YԽn~Kt`J Z/7[[M@/]V6!S޵kf|NxlmIkyRV&gLlb$mfaǦ݈"knȁjL^,7qm;v$׊մpm֒4l/qw/ nMOKSSA@?v;y|Ƹ֍zVe ]b8: .tk*-KFIh^Qٙxw̝UD*ĈvJ5 A^}q0ojS "RX,r?|X;I&R>'V;OFցm7pn.['{ae m Ժey@IjHLoXq%}5:s"f0˓Fq{+\\ s9.+~ LyyeMvr6Ż1dá|z2}Tm;K\3,ԚZSys}ͺQ7PDZyfr;4,hh=ٹ"QQ^*(.;r]&,I le0NʥI}۷p]}/mI9ޠ`qNQj{w}f)1ȴhxH:(ϙd?9;znhWh#XqAN ppކF. lj_7i{_`ԔЛ`+SF>\{)B ℤNYo2EX%DEDM,[ܟmy&lӑBS̬~d'[۪L%|SwKMIYȠE#{ߵvR\hN+J{x=L W5Q@WLf:D)#Lޚ7c?fM-a;7vJ#!cFVBq#lme%jvV;~ ooM׉VpW=OPs31INWO5|4 ޣA!ϭ@$!B^I{n3ögPtwሧ"&_( ODݒƂc `9A쎐SDزQ Cv%k6JRd|L5`6ʇyu1wC ˼C--4HWvm*L%enXM C$,c+i~<$ҵ7ӽ!ۙo]t˜iȔi!% J|Fk5[Tv r8L_!ƪD̲/=`Y:2b"&DA]%7@~DuX wn?on}T핾f%1E+zvv|NL60}7GJta3¿xY!;xѰuJON 3};~ڲkYbbhɌWv_b>EZq⦘j1 pFR#J3+o.Uc*} 5`t-ebRs:my_,$`C|YWV1F Ծm+$UԔZl?-> O+K,CTgOjޫ;Cu>zy]caedS@ןSL>t14 /|J <QM(/CuwZ5>ɩMف9E*֘@*iٷ)d_(FT("ErVHK,ٌUф{@ahe0~+Ğ% ]W-ƒ Ht'z[Ob*-:gB:Q"zY9W/n)A&3pv Cg -hB 5eX^kAk2:VZ." Sc0@7*S3w?Ɣ멻_PͣAɯ@-'.N&I4{J#zr P2{[GXkęІMاtgxf.ӂgs$L?9A_+(S';~{Rv|BǗKMy?'tg3(6P{CUl5W~ WIƽʓ .8.9;BٖYx?rU jaQ"@>B#@= hZ# ]SbM Ѭ2gϏ18> HS1Xڵ 3Q*$O*e \h2:x3~Mj9yU`:ZV7lzeRAFV"]-wPmr$(l݃H,ݢՎc,/0 fWkliڴ|ZD` @VF& Dۧa" zӠaJO3f=83h'oL(6Ǻjla$cKr&c,{;Hѱ7FHXw, qR,^AϫOy>GѪpU)3TF-.̵B>;3 *D mxf/J,.0lFb^f(GoYH#j P6d0ev}:PuoRW{:4 ].6 o-]Zmqĕr#ҧ79åq ۦ*t߸8Mub_ө6z@R)!wƨWjl>.BfnSa9)H L 'ö, D%eC,n#M̳mr}W;߇րK0o֊IPNdU_F[/ρp#!%Ce@,sH}Tv N }=d;WA_Fs7V6-J/9@ֺ_K$!n kmN8ʋY U<?Qÿwsr;ycL!QBӁ p:í ~C`_g"adVw{uU+#ؼuk5G# YB}l c6$^;~ EUseY;CR_l+ !AQ & l8YPg:쐚GМűS\/e0|ÌbφD$Q0;Җ>^R'[ @{r[NF+S Obv+GM  &=yv4Kj-d(d{*@c|qEf&Hpxx)ӪFd1 u ms؉`yC5N9-c$ -y%Tҟ_Tklv-Ȋ.n|q3`w?W2 W_L/aɡXs鳶Sb{s~MIuI EHŢO˜L-%8A&ήQ,YPx67lg BHlLʊ ^J,Ş }  llA<4}frcOacݐP`j^?6:%)vmvwx@G׿d[:׊\)P>&xNO,M" %x]ϙGlp3\>kos8\zh(m˷̡9;5;/i 3 *\&S## d.'T^lɹZѴnw\O8#dpAg&jHA{銠r`'>y[4F;%gzn{zI?ڐM602;?)Olpw7!WkĀ5TTn5ל>x]mF%Xf4C3nH"<7=7zq!DEL:*#ٸ`ԵWa5>{vJ ^4P|i&V\ԃbrAlVae .͒EWlBi*<;/5 zW:%urc$O HnrӑFܶXR(W<$ROKN;JffӑG9ZK}\R>.xb99VMJ]Ub<o-~\Y8\Έ׹SD{:ll4"oj#]^+ lG(I?B wByc"{SKY[%>L#>P2e242S'Y[jm[L|.PZ>MS~do,OAUFdN(۾7WkbL1Cl(ȲtJDo,#Gvդ0ঞ0f:hNS# _I-jv#&ū'TZ08U @iw-w>7^В#5D.{kb ٞv,5́~#OfմIvD绿?l^W "nl%/ H+'4f43lD=>1RD;6GnD#Gkrv_)T/p,an(Dr< a*q,Z9XRxc#kdW( C+zrjUH9I2x.KRxz> 2cd~V?;OkcLilF8& \AļM06ṣUY]yb6ktdtUb;`DY9d܁Td㒧T:/3-\OJgp`eq;@' L?ۣ`Jc wsj)6ABۺ81ę0C`m-Þ#u3:K]]dXZY [d,cw|:I+_/D7f)wA˪UYvHmqZJʢ喚Q5CGA[qNF@oh*_1ԡ|h}|4=mŽ,SV>67m:ח`=7^d7Ap!Qޙӭ0g p7^lZ'x"n0m.{; ;kXD[r׿Wo@RiVE 960B1kJ;SP8V%6ǏiUx_gbNC. U *N0#(* kdml~8G =3܆q _h$V^aǹ mcU @sJ^c>:2= ?XXTsz6ej KR $Q9n"-rF maM0P'٧%kA@ N?ˍ)CӞѥ~-&^ZH!f^.?/4|,hjJa8ŜR% CiqkE݀Xxg,VP3/1 ݨsgb|OlHי&deCZ|͜1Qޗt{{ZVE9mF/F) .cbe 4 sԇӏKX;p?V̞/*,cv 9oڽ6|"g?萰L8abIA{zV2&Ǹ ]MIQSS^ w[eۢ;n8Y>p8qͬI1p wd;! }rڅSDu3 v&ꆯjզ*i7 GΨ\t3\q_tN-٢,&I?Tg^ , -'p ^ m'c8 -)?J֋컃g ldlAAN4*ԵЇݵfCv`b;@_9UU,P`VJy 26b̄~WI+ˆA R#:"P2XOuhkܮ Om+H5-`df5.10ϻΉ;m"lbel>P f!zmIS%NCOYá$e(OɭH 6-%t{);g?C6xDxOhpo9`*'3yZW -=ZW[I습j{F9_zµ#/X΋:dp)zc9h: x.i:k<抪tdƾ0$#uI~Pr}K9hCAϫ}̇K^aνdyX5nvȚ?١H|GUBs2T윇bUgYp={Wl\&g%m)Z7-BT\Jk +@َLΡ>.=!K r Q hOsx` U"I*%]lե2%ܖ n*h mޣ3bkeMHv/lQlpޑ95 ɝ-t $ߴ>1׼U-]} kbn=LX,ͩ|2|.*I; JWUmarhIL.3IavLBV ys;]<;Bą?C.I8Ndgo_jiۍ7)+>Xό6Qd{/eM$ ̖ћ_GS}@|;WOS iÅUXM:,u7N%@"$4|̅ݝbWD\sg j%mfgo*r& ^r@X%,%@PoĹ~Ia\D>fQεcxE+-];;}43u 0NSy]+ !jGղcJԐQ@p oRKA*b>Q͝\SȣvfgHԇy8 T?`>["=bU"QPV f9!ֳId zIA7 hJ# u#Kh"Xw9%2hY6AΔ$=р1(`ad26_ն]kț錧h,n92K˙j[ 8NZcjb+=jaN,% hu78^sw,ӈAu%GXb#昄3[|%xLdK-& m"U$jx(P*B% M^P܌ ERM9[HJCA)^L*]ԿSOK8@KCzXڡuNd-t=LpC7+ow~ʣT>{&:#g8>wMȭk`RoBs1\!Ϗx5ēNWB]6>7w MW &oMaڎIZ&RhQ-n/[dV87}ugtk1 1:7-ozPsVJ;;S ( E(y@eUṈxTLoӁ[Rc*ZA8:e|/ %MXf 3dX)*v6\i)dNęFv=3(R2VLinL J5}jS͝Y818p`]f)>2yeP >CE;#u/${yk:֘2!>dN嚸 ryD`gfF&Jљ~s1X]<wEl&rѦ)\z(׽:ai@ķkb,Al@_/tvB: 4C4 D(TѩiUE+ZDō>#D 9 }APOĽU2y̓ӣ#@# [=|IN) 8AC<0IS*3O0 [͸yg!U'3-kޛwiC0Z|vYL't@f%s!fďG5I@mD vҘ*Vt-9{Q̵$Hq?BbVY0PyGz70 ~%c]7LsũYdQ >Zq:BV6Aߟ*tw3>Dp sx<j`bd`]C hʢc9)KxJp~m$q6ٌє}( ` X+}>YCȨDpXw6kT ':O J+؎>YNc 3W~u2}lQ g;X|Ov&lK^ cJ rܶ?mV@)H}$Gx׬<2p?e(6pqvn 'nTIXguLZQ7&a,VaP,ŀXŃQ``{M9 ~n.}~p_fݭf݁~Sު,C>s2d=l,#&֣K#eTnʡ.OGq4t;Z1 ,e(GrͰJyvJkCֆZ2YőAwk6OQV BFLZMDB}qg[!71?ג[︫kLgjsFڏ&s<>by _Q{݉vđ;j[ lj hY]l(NI`U]Bxb~H1 WJi.;S {^<{-25i|6*48fle<b Ğ %ɠM[lV+Qȵ#e&y5RɧsFN,geVW)œpHˬe1>BɰTb8P8 Fnq{|5qtp놊 H.~MNjr?cDPEp@珦 Շ˗><٭Po UAQW'/ğo[V,](ƻZڱ(%H_\ú8]`391[okTc :5bu0 ^v͝CjV!=wo;Z_.> )a$;3%uB`S[U1"`͗ٱ2Ż_ 7S ð$bKi:NA!:ò"9НȿޖG sYjQa4'VhW9Uʭf6^5x]Y?)TU{ő;:Yz>-ys.O(r3W%K2Sr9)! gE&:IJ%[dC4O֕v-+ WPM&u-qismGCÑι}X|$ (0͘8bԀ-:8 |*cm*O'y1#-\qn3w`X*bߋk{.k4T`D+P[~.INqu[v!cdrᣀ "rg䱙Iۛu.\EOY!ǃkO`XRi$9sU]C9M{"I#0 "4'!QM*+{cwẄ^GY.< ΓwJf6S˫^[קA])q MWJ9`њ'=:;Q_~%ZxzMCiaKɋK^Lqsb${8t0NdLХYOa΃ TIlR͌Up%MuX2s%RpM$Ю`@&YItK<'̴l_ˀT$pPmgղ6c}sͷI4W~[88ȯRﬢh J1o줐4~x^T`/5(مa>t9 x0[c96ů?MO1-|䤲\`OJ^,-L d}8 H}!cXYrq J|jrfM9B]4N…-'A>,_ MQ~1>ߜ8Q[!0ZpǧL71AW0r~@~sc/;|ܙV@FZePD#j6^ϳ’^6vj*yul`\bM5N^Nޝ" lf/R"鑶SOXl?={LQnWTYVN`\I2v?&shFw`x8zJ4WÐSZGf 6 )NNT.}W˰o/)>wq`{c"sF!c/LF3nI!Q<^5=[8h$eJSINEXo14 aKZVcQVmR&Pz W\¡HPHӮ Mv 'zȻXT\+,RC-Km./I׎Gi(~/z䄘9A,=VBQcvLƙd/{5q uK 4 OIr>/j,2dZ,4i NU~83`pǷ8LgP9#^ !,MC Vk.$,qv̸C|'AN OCL R-ABnttKpI ~oUh'`c,@P:g*hQ mD]}6XC,BD$pl|YP#&.Vqv Ǚ?S氙-rGWl))| PJe>JR-`E(*kBt#QJ唲4˵eg>ݻu,@pAp4 [/礂Aǯ'uvhTRb[q}:jb>ﴈZ_T R^~\umZ_#Quhɑo| }ģiq*Y} Pr26=s_+[SnDFG4{Seqf˄R+SE;=?/*Fr=?Nfo;!,Lk8^tR &T9^3-u>/~:NԒNh1bm`itN8=\fڴۛpB" /ŭ_4c yҲstTlfFۀhnp;I20%h"CUU&EϠ>X{+'e6ԣo<('Ic}KZl^bl9ko*g)6ȸSh kwcE%Y?3JxC3C^G+Nua!jyҸ (A͐ *#DohyZsrdWX!Pt ;Kn_z!lByG%kgOyYK}l6}ـC C5,M@XJt)kb=qSS?fĈf_`pXێch]?t_+RL-1DwWHTǁ)ET}k!n ~;15z m=y;$ekmLVY-7Hmau Cgu߸bU~rqL@窧wXOorv{-'p'h )v%[$GsLE);ӥ1Gb{x RY><T MlnT][8S]F#S,V7c`v2`+ _e,y,l̚EmmHB#_$=I,0-̥(ŶYsmh[: IxJ6N>oBXU8輴DYѐW9*Z vS,p2#&J+_яE4i"Rtإv;ɷ @w"iGxsH/ombSjflȌ3ΜT)n&a!C2cS ̵q~jw~ѶgUny{o֑t).}"HP[Ji)hQ` LMޢlmQSF{Q)v;ڛb FaC" lîCG~mڃ' 4q@Dekv&"lC&?Y๹@xVڞV֣ ?̫MM3ҚHPEqjw" s51EDs-|0[Ψ G1<<ػ?0ndXX ״!+R-&=|z80䠏*%?W_mq0LqqF f Cef +&[5W.$N?vBt{ޢx28|sP8_ňGtB:$W{ Ȭ#{f?b]6E6VP) 3ML%hYr0 tm6튢H3Wp!}:ԣ1R?W(Nw0TD n,RHC>X!?,!C: Xrczq&!|dCnv޴edƤ3ctO??n-˹1-24fN,gyJw}h:N3.RVjLH { VT)E3$a[z{CU{FA\(|kBz&a 2\GA^ץ*'&|+UWhtl/E'Pz߫ouޚRH$!1\:ڴ( T;e30ρ~!6~K]- k !`:a"!JSZWSLh G8Sr_Dk/WsÊfA&卦uGɀ 'Q˯ˎ9Og 2ήV.&'&"D= R@xli#/=q ]Xp ]%J>OZH,gu,4njo /)2s1,ƅT>8ۂaP3YX<B3j 6,ׄ0b $@?5Qm/ȍ(8e#`(h%F{ae c.QwⴎR  P~Z*#;2p}GCIy8;̪lԴ ߒZ|d^.#O##`M4krʛPd+>r ?& d6kJleg]nا"ȸ.ͿFFEbkWCjRɋVNdպBBesv8?qkr\Q Hyا1[¼l該PcmɝսJc;xRNWzh1(JD$G"g/-햀vy&|* ǒ 4ͶG4!jLo?Nl$WW9&Q##7eYe •QteY#U4l q'S䢛32&)Xlzx#hT8  ߘke[|_Y?&OBg*7ɫ%,+JնE_6m%.882j69:@Td_EQ,P nB4#ut8 bǐRǴV_Z8U"VԨlB s񋦓<03ee*KMr[9×bH49OUQ[eM\O`/ 57LkH̆,y IwuA 2Ņ_9a*dRĵCh@c~=nj8a[ӨX;C9U/p "fB hu}VwGbx'Ǘ@ v]rXUH;kuGSL+p%Z79Δȑ+#)@4%5cSQfOEK7W 166嵻”x `8Jnzӿgc?B"Grͤ+o&dzS'(ۻ7P^ח3 3엨Vs>uQ,]~^!\ z#{l%1k#LH,!{mk]?-%(EVF,'ղnYc4QQdq1hCU CK{ *S/V;W 75*)(Ш?}B[XOb6Y5:RX4.fdGˡ-@]0R0Xc.!&_܂0աa8Ylv)G?jw%90x`yeUBd4_Xq̠ќvQN] ƀ:][NiAwL}jmeϫC)<|n8GPdxJMPwB[|"s C8w43_+pG=sm{*_T/yh$^)>ב5 Aqep LM'C7.XV>%T׵F1J 'oS l`WMNVe{z2c"!bm}F,i}+AbL0n4&0▵qeq+^tM.4=N3@A$iQ>,0 bwĊ;E، O\ŐPe:9QwiJ TtOrJ<_ Xo"=[ M O*a޶|kNņb* Gѐ2?](K~㞖lJ5:cpT 9wW>Bj*͟l8o\NhN@iTMbZ}4k_Ev ;ð08L50 yَe:q}g`G4Xe4O.O2.kxjOYYy{CSyBPJ]6A}-Go FcߑYBMz W'fdfR=5Y)FI0uXnTđ ]D{TcWZNV>ٍvI5 mxݕE0 TzxZR6]`?Zc/PKܛ?PScBUUxEKraܦ0RP[$Ucv뚲Eky}ZbJi挙W{7 }kFOVdPndyUqjԢI33?]$(FB7Jج^ĵPM݇iZ,Ts\vFj }EJK|B8 apoc ,|L[kIash v Op-/24{cWtԞ`l8/N;sCYoh#34# #RZ=r:4DZR'Ûׇjd[>%ڽN/"AA&|'t?q.s8C"l 9)dM|޴t3d)q z˹8kj;L ސH vݷ Dg̡$ dz .mu+R-#RpbpdpbUj)lBcVP X1`T >o]twfkygTC?uR/;n2D"S/xruE=i,Xv\?V#Vfa+tdW}P7N.,>If^ȣ?1ʚalޅaB>Nz:KԄM5:X/hȀ(F,%t1aXG'ABJmg v|̰ W6\I\wm.l;5ԣ^,Qm[o'&Ld!p!SG+ZI鰉 ߸ENqঀ &ۊkstlDfÆ]9< umgT@aZRB94#]&մj9uN&9K>j>V~D+[{0QU}0[) {4G,i*9 MH2F?y@ij2l5-(C= we`:*;jsQFwΠ{ t4wW-<keWկ͝e7l% :DE\ ^AZη{uw``=-t-(B)iטڽ7ۼ'cs<ݣAȧf쒰uloJ?WnBP3]52.M޾ɜZ7j)xBvXCRlp|@|߂w7  LOrr-vM^%v^YcIOa/<,.*Uƕ+,9jԠt:M&QFR.LcL,.t ,{B/)OnU(DxmJm3[ h~|%^?x*eU*ArZFXK%٠fhTử ~Rgƒ2ٳ<_orL]Qq3g /YUF$ (T]SOH6IkĬ}밈n8Q=vǹ & GWY5bk*̟LU_W=yƘҙWl]x5ۧ2r6-!:TKF_hcŐ_5Sp+0'x !عx1gBVjm{ΊPjA*,ׇ *umJD{B'|}&2)ȑeaF~wYcMulw̆E? f*ydO\/SM~|["$}T7%P +`#~ldaVVKD6Gr4? 0 ;dX~:<_@4O}?g.?4&ׂg.Xq̛zAT#E^% =ko'rI>TCL[z:6\Zbo9Yo>ʛ=.JOtZ ˵ZQf&~p D`\8:oTz^6l6 E*d. y:aJ1po V9&&\A->y5{YJ&ѓkQJ_ײzSkς`n Io~e9)z1?ؚ͝%Qu"'gy5Wt-Wv¥ǔ7o ICAk+]:/vqx/y͆ a8 a-!> `@!N8a`U9xF[BvJ4s6Ѧs`#4Z?<󁪖$m+cZ0֞ gOB[12޸E q;tz-kt]lJAX`^HOsLOA?W3 ָYg B*W%e,4³O]I*j1ԊO)i2]p,{k#:&*!G;d7/́^|yc:-W ) а!\R({k:NۦɴϠu:`gjf5PޑC0$ Ȫ)lKAE"5 T#O65?0x*7}[~z$QOa.Gu0싋AݱqLR(ϪE. R$̽)U:c%6& >~m>梛^>H{)w wC]dM5x ǚokd~r9uF;7Rt ѥj\vU\l{);1&g8RRTavk({Q~kH! 7O&׫+2V7BgcIC s>L~0h?1cΧ'=8Tg 'I0קWe9QI%5$595% 9-< 6r?{F'RQ` U"+sQyI!̤|8"NOvk;l#S/?5ȃq8]X lfoor .!$m䦍d 3DLqjOKUQ`>{͖I2e $fRetvJBc(Z77 p_]zc1c?ǣ K=bse{ =?N7{x|Z+Н*ۮ~U2i8 q`oqf]V:{wk6!PT Zs41ڌB_"X5= G.;ƟHq8ܔ6[::;"oA$t6J9v3B;MBr1ʀ)E׃ȡwZfEpdƙӋQSZԐ Kk4OH P^"d;HIW-E;}57 ̞b@SZޕc=!8Z i`&w]W%͖cpNw32 ${" H3[jZw< OZ7.S)Ti[ ,q&²^ #qf-ėt@/)RkKZ“cW6Mb|a@&YBȝ‰S%daK',SϛV#CPSTRی pሟXʭ; +=m nx/G:FY;,\Vڍʐ5m{,"/-g+1~uBWL P{=`u0S")o}XFEj:q)R.0rۍ/,`:|Qw}el(Op ABXu9'QOāv4L A te{8Ǵd3C{tn& djNӪotMKkondL{$bA}/r`bVt{ix-@{`\,&,tCR;Ѩ&B6֓ +)ܾaMq^%u"B-ذ,><0r)&aexiпIJ]wIJq/pֺ#HH dAAQ2̈&x|(_Zf8ڙ85\`Z"r'l:6Pm2tBa8Jg.H?M u"jXmDd%NG_"R+"A(ULK*&1h (E151[ZK=T<%fD.%%ʷ+\g4譤öF.ŰC 晁H %@Rֵb+7FSllbؼ0< faԣE,r>`yqCZ:A6D.Ol59S=5W0{i{Рt(LD!U6mT A{!T w0q`ɷҐp%hmJSI@/! e瓐d9WW&쌖) > %.woZC ZŴ GI:)Йч>%Xca@wBۀ$pLs Mk?(U%؁"$u</jʈ%K-eLn.baY7 xTzi {/Ŷ0`J,OB}u-#/;q|wĝq?D H ߮<23aAW)e`:Uo]bテ_N}6=ljq8c' o%p9ڒ5{@7әh\5)ǭ @| bW͛ޓ0}ޒD;,eM@KBQ\I0cK9\ V%A|yP.6CÆX[dz]]iD*o%LHd#FESHY&=I79rEJ\ NiW{|&Io\c .Kdw-$:HP2eVٍ1I>\a]Z`Á= ux%b ,!3}Qn2w*03iҩ(K =_)l C#$!_[Nο_]4ǥgIr/qh@:QH仝MVUA.Н._^= >NLWak1U+HHuLA$O_t)}PA~";Dmha~ 2;GHY?,hiⱝQ_M<ܺ> V8#U&)ދ4!Z4Cb T߼w:Px )5d)f";XJ!FP7!g-fHs@"H,1.||w#OJũ ao !8 ǘb_ SZ\/A]Arͳ6rQ,#*1(NٷNۀmX(g}zA]I HRHu $ɗc0pFiQ\@yA9NNudFy% [K)qȕnSgⱷm$wmN ޽uʘ@ z wԵB`l =@mCoX8?vc:t̓ߙAH5AKW)r0]<ލl| [ʞ}pO<6v`VxE>흽11y_s.B8 cS?FoD``8WU?R:loC'cʿ++< $rd3Rx}Tֈ,R>dFR}ah.=3%bC_ޢH_aDDdY~1:FrwwiΝ#b&} Dq~7l4͘1Dha梹c6 q!:rot IOYeABj~{1p4k`N qLA&r) 2@/tB(Cm- ֍ZFs˚i "YFc?@-th_r78f: Y^ [2(9kk pVHϻBJ7&$Y.RC2v6J5N&mTBAV:^S-QڌKy.@V#>c8GQ#™B tQz;boj ¦7Ŏ'*m><V=-4{Pd'ulDmgÄ886kVSTl׀ <I=Q ]g}4 sR ׫[ *BԧYej> D U0CI,Pj;.^I?`M ڥSHڨ هJ]t/gU@NJ({NjpNuq.EZPH~%8J(W@܋>ԆeAU °/S7E-rIE <Þ@T#ďP2 u1/}QtħsJL=%%ʅ b͡l֍"0.jvHUKD_\y/ɶk`N (hD.Y;7Kݭ!}m"s5UNyDSVo-EzDi66>8Bpx$-%=(Þr{,8HF刦eXǻ?,d~cZr߬3ԯŏ ? 斓iljqx4Dի*#HZKdzNٗR_5d3)xG $PZO6W*`٭II;һfN{;@3fkmȖY.kg7@S~Um4zhT/%>$/ ҮcmH~qRz z2w7G06BG݊N3OF3&ݦ:2yq=C>$ZӦC18ڊ:pqrNM\\u9]y)DNjCU0/]9,r @7иrCBVO8(>G4Q};uW&21RT'3y{]d!(?F7/\U M@*>_be%ֶ3,ۉ/^wɔ2\0!q·ZP3{ܜ7ysX/ N+^¯SB$f: *֪U]xM@@(.BH@8~տ<}V|~` n `s jV&sё3M³ύ},#{RQx4jf1n^i}tx=ڃ-x~aًY,Dp⊧G;@E'!+OAFF᭮e> Z8YGSxqUر4;;[]Z@W~"2lI2ߙ,юL"T(rJϐlHa#.lnsCʊ5HO;q`>i#΢W XI7זD_ s+3*./j ~N- = t|VpՕbifp:f/8DS$`cmzmycRYs><!‰AlW .Yv FYe{-.B0zZ 95X4;k[mBl RQ&! &,w f4e|(`$?u4?vH"DE){deA ;M@*1t,fm r9hYg: )YN@д&EQi=\p#σb<+_"h3, H30K-KҊrm֤Y`2!gMKqi\Pt@8qAT ;`!TA4$7"(p֚N z"|ΔngNCVuṑzY>+h+5(Hw9Y$Gѷɦ!e1qh&W7%$8'm<!."dF: W|ʷĄq׌!{ta:n$|b3rbCvtE|=oE#Voh -[a;q7.w&Y@p=w_ ײv`Wm;BSm OTg%QiӨLL"!/-ut -'c4ȩߜ$ kKEC}\o;̘'ÝH醫U51Wt:O<Č :QW?rۃ&p>R"х2'l-8+ߚQƋ!>DVXĔĥp4=2˃r k5-AzaAY8Yq YHz8 [fCp}7՝nװF/,`B~ ݊bbRr/сyyH F@_-9$T1q& /|9WU{JʚWRo{c.-uPR\yGvvMjKWRB1Zqt]>]x?c;x#cFf GWDh3 G)Rœ)]О튄1j89"(%[ ኼ&y'? g$̷%̓D [DٸsiԈz (XN9*bPJXXlōFogmO3:;a0ߦ`sHWb쀾:w474癒h/qNc30f3 xW6^O:rb^j䑳-W.#K ١AJ Tee2>Ǡm%9ąi^5pNjqn!(2AujoYy$m*qDFR 3!lE b|ڧgxӲfs!ﯿ)t7'y(X'8T[@0kzKZw8q)JD~cdLlC9} ]HGJu3*BK ׏IeGW7Mʻ@]~v:' *~w򌅋\ gbVDĠwm?Z)l'6a HVA`xZq+̞},k]]5\zd*q䋼])rbҞ63W\d]m}jOXOc?/f3EWg@k. ЌWV1 u a 6B"^yr50o,h XQl+P=Dq=1FO* 쳶l#̞Շe ɗN;./)F ݯ9h`^@sWh$<>o#TIN=ԟV+Fm">[YJx:ΰqL\-Ov^I簛J{@Gë[ R]!RM0[s"$u ⭠t+^=Cm(ajHteXɱsI1Qg``z+˷;d2||F3IO-w!A_&LxO <&pYe>-gXLMhAwR g͎T *ն=?y:'DG1xPyLtZ M7C*lqʺcus}$4&8/:[ WQ}8O~ojY!IP|Tk|[V[/ci ( 'WB"^؄`,r.o,5pMdjzߺ geI(Eyb+gBA^'vSڊcu5F6 LT `|3:Xw0 s|mc`L'0(3 |/~E,dWKв8%s `#5iVǗ%{ۅEdaK/ߘxFj^ ( 噬mH퉹z!ZϔLRkdHDB~ $Zs(]r|5 P9?PDΊKוm?k7:E˓=b[FnSՠi7@CTz ;O}SBfGk4m\B-bC=G% :Mg|/zPrbuKjaUa% :;>uqwq}sl!PsOV=U<SQG=OܸE"Fl?3sJs q6r=ހs4vJ)9`o?pS}(B,2s /˰TvȣUn>l ]I~ޫ7#b47jL3S=XH3r;EAt11%?|[֡+t2LiB|SpjB3iesYi ggaDĉ!& /'HZs81q_x PWL3.,eo!_ HRGO 4Lh]T=dPcqmi="rVSϱ;Vf5 s.\ -<!{UO~ 5^7˽BO>U\ E z9G!05뀑I IjfmLweHeqߤ}[儅gϻ0;Mcl}c5>ͼw9@\w^'1/~xEڡJS`A9ucRcERb 9ypg+Gq/\ͶӒ!-k7tdr(y8땛+dܧ[FC4*z8,^=!k; [&:ÐRXDq<&<?N툃B84Z3ן3r4d: PL(8qG.F3S{H.ϵ'݃>tVyuz'/X6Kw"\Y}(Ԡ擸~Y +qTxNW6bL5%»AYkk'fStPiҩ}-Sխu`4AS FL֛`!i/YBj >53)s:ʯSt(# aGF<+`QWK3a{5/Ebǥ. [9Dv@ ߭iל#ȣY>U@< [s"C@- R`:eb30TF"X Ŕ)j!IpށT6S܊(1MEQ#PdD L@Za6Su+ʋ7bfQ8\OUb< W=di M7G]=e. ߎM2rfhrPo57FWeA<6gG} -wJd|θ !iX֠k˞ ?rvC,n*y%͋ %ȕ8j5?pt =S 9ht5sL1f>7#V{9Un}Ats0ww<}_RݲgUoy$m0MuP/7Salr1b{c{0S*35 jDvԾO~RT #ЯLBPxkPGF5lih>MK30؆0{yJs:jXꮼ6c\o&2b.BBL݉v'&yc\6(Z.%[*\S3+򺚼(unkSoEδcI)$ާ.So \+tu n1;BQ[A;J@C1f_:~I{X XQTC#Srd|FheUQ:W@nNi xy$%;*IѼp$̘]q6,plASH'#fc}\R ;E '\BUѭ 8Z ]OWUh_щbGg\ApB{VB`45/ň{E{~`,z0>i(rtzZY>JM/q36M+ǤgR}"`2 ϖ} b0@%d cql]3YYKtH,ZmcjtK]Moi:1X ^':;)_U^).N@<Γۘq Q3;_قR'X}{h[p_e(<D%B&ޭK?ͰDN#Uؒ@WrWAk Qp!/Bܮ$B"MDcú$T,E{{ 5‡o}LؐxeйUR%-yLA#CwQSFӐ;3`ff#C~@%)2l6h{7ɬpłaQFgΆ^e΃*~1c`5NO'M$C6u2t۶ +xwmKYVa^ ㄅM4]zN{ך#iR3MHe(O4b7Jv/ @K֫ᱢdE;V%ArXU .Ѫ ij画43PXD9 ibgN=هb";eHr^,ڶi1y>̉^լ|jB2L鴈u86#Òj;}PPTʇz>@^M/qx9A)8(.R*aaF0%>}Ql Xlj[ÚoȦj( ~}uX._JWg[n|5k!Zn=E:8s@(8k&A{^qKv'FEs:.|ӏ/"d0 E<[& 6ܿj:CsT|w`3⺿!{ݥFE߻[z&}[6P FFԭHk5VO4Ilv92Nи4cْ$cg`6L70v` o+7@;=ފމy_2IpڻwHhcҐn@DulUn黆ܯtӲ0b'sv @5Yj1s8wSDyIL A!\$];_KJ%I _qY,u2LCŜlNttEE'Rd,ʖyj ;yG>m/%%ڤBH MIU3q^iG%gA^Z,#oT` m`+| ן:,7}[bNLOFjgx*[P&CbPeR0aOQ~ 2H{[^r-z:92?Mиꚿ)jt E 'NNQmi8&v~O[BGām)/U#*:eiH6\K\H&C$['"'S:l/O\aho}86p; Qѵ.qɒJ%+k&HV1bB ZϜ·r% ᘓx(<+X.g,gCB|U0I}dhFsɬY]91^,#򊧴[{Θ&UD SN_0ݠUjߡX:ucˬ8i ך;`}Nz-;Ի--\yv#YV='Wc7'tN C:o*ׁ8T=i8oV?EL{l3-@K  bdDLQF)nkv:-[[myv\j>h|-~MCb:FyVOވ}jp5*94;ՊpM Pi K&07q .w\Hq'܅U3IpU.] ٶ8'tḳpd`pk76bmޝ1tH7A_6 IиiaڀSBؽ_"6T~bוdEMP AeM2L@OaHHP+lp9CT,꽨x1T{)ZZMư^;nO$Y8Y6?&$֦١"Djw;m5n^}QR$aA%$_FzSĭ }W ĝE;%,C sT\vG7†g#YIإjTjRB AszHmӽʐQhm  7؜ ?f$ۂ0<1T{FVonẉe9WD)=ȡ(3<1&6TN|e8J1a>wYKXoD䭮td-0t^lP(<}z\w0 N >; ކ4o m@'ryo! )fy1$s4~0x M~8',oYI7$c!0n(Llk6!{*KxD~WtiWeuR ֍%ɷhab=th9/gL*(Ȁ-p87Z> 7clRH.vr'x5$~[t O|lt7NZ86QވVlrwSc/Ş,euLsGBRqh)FFguƖӐ )EF$~F"،fdk\&|Xpҭ eyxp ^C6B|Q8vUɒGWZOk2)p{A$^P~j;td;@w}>68dvTCj. ~{yHJEw*2^;p[SFXJ=huv%./LWj1&z%AN`@36Mm]CaD] Ngb{*ٱ}CiꄟJR-0G*m`@7B<ʁ9jV aڵ]tx"|Ls4y{=&hI`&7_Nm#6n+j t'L2|'%1ݕj ˆ/"7׍`]ĶdM_um^M,*%L.. 0t E,:+57~&Q#x : M)ry-d[h[lCCwlqmOLo8>4QHV:E$)/ sÇfsr{uFQ=JGD߰★zuCQzZ`>Nh>瓯mg{Ieh I8كJzӻ6:7pʿH3\0ŝ2ic&c#E4HŽ s[asl9p}']nx񕵴\PzCQ u V23t߁3"QڮI8QtP_NQ/CԠ-D$(Ӟ1Ov"c;zĒ%jj{=\5_0HUfCH ǏioHβ|B$#з~ IMEz4ws  aϵ$j>K‡ d/.Vx(FϑݓQCr `SIWٻrugϛhf=Wqj=/ΜZnߎ+s59q $ΤdmD{{c{Z& (W0 WkIEySzBVL? BRyOWS]w rGEqQ#Iy }nīK \~H($Bܣf]*Auqòwir獶<VO.et'}At)ok=?т9eGP[tF*h]y -}A; "[,dM$~}Kz‚Y#!u^/Ъ,9Ҷf;=YO92_h\:E(C BFyD,bWR hsl􊸉կ}@3`$(Є So9p)2_{' :dC;N 8&ruϪwk OEr49W1z$"Ko)vpU I<OmK㴁bXl[mf mj=qUK)a_+b\sw,D̐0Cb>P9 pp7"ƧaW;™$=)JKbpb4udLOe}⯴8X/3-pQ$+SrZZ9>`GK:|- C駽(F*\hsʓHOur\'Ï@6nuY Yv5︧gv}MQٔ64MNxA[6&/S n]$:ݵRqX7SvB!|ټJ>/ ljݟŖVᗑ=BP 3cm (mdSs:=(.!(/hq׿]KĒ:6ܣBcI4pIw? )QL cTfxFpV4fI>m!UwGF%y1lP cԑs߉>{7LG]~Dk^1ϯMj#gIX3Uj=w&e5_7=F T*~x=\|`n4  LR \Ѡj,WRq;NE[9S. 2AFмdωOXu|BkYi(Z"Y,ƄQV-t8ly2$QF9##.tdObB\P_g\%9x( k pQg> 9W(J\o=(߳ǩt~ze 7|G{?dجSl-%V\D7 mTkplj+X$~}%EFLtr9T1D(nl(yzѝWXp S~Hp&ZZQufIXrs;LYVo"鸂)>NC(;qEA2<x_WsqL%HA!i[xd0ӔweB a5!u'GmX]+ IO 04%=[H WAz\Up".ehluˉDbd&eY#g`c@Zi]jt=2D5XL\mӵ|DEOΫ r K#0>\8/e4Q%'/+.qjieoODZKRN"+!;u5ڜե{iŖg 8+BMfs"wƎ*RBօu;OB`e!?B˄i\c: WDD5n]V CTu.#Ry=!͔m-H RJ[?Ux8+̲Hqv}&^4/@C0Rµ+ ~"2J@bMWזXuNԩUTj~ݢ7@yJ!ՁXoҍxJ$)^[q9y:E"wĠbnS0|J2$a) UR2IFOr*:ND r7eՄh:g>d.ov<)#V)$N>[YYNɽ/4  @^e$Gch GPq,W]).wRw+it /Oᘰ 'm@VP ӍFD0֥{%nݷW|%u3;ID|i ld4SmE Y谴:ۦR?3Ƀ<$l܉76{?MK=6i>s9n%ҸfzC5-|'GzgO)p+U,nhtM ۴c3+diIKi_/83ҲOMS}e()ixX%EJQ0[)xg`.h[{}{bN ~e󱳊[ 2=GRyFrF}p R|"0њOvG~ڙVXJ!l1#.,-#kl׶ H8^&' 3L{Y)9f+Om% eK]p$Ye}w[K+UHJ-VbG"Yl4Se]h y/)5@X=DCa3*"ݵW鼢iPB" 8=TmeP +2V\<9o&)w0KᚉaMl2 Y3ٞamҠ,Ya? [^ (&K~WNhQ*eKRI ԭ%g]MP FHP{f so0WyK0؍VdL(Qv|i!R H^le$l0[ߍ~7կ] ¬Jo.sRG[D"?ƋKLASOspu~AVe]#Gxq+hmbu)bN}-lf"Nw^<̡4-SnSfQ= IG` 1W[;yCo9;b_Fm8`ΪU-u%w]Upkcz8 %K7ptƒ &}c ! %.9+39q9xeutQH)6:{sΞ:,@0LVR_柧/*&s b}40,Gnl]F'h1\[π{ udٿN1de(b/vnL.<u <`ɻݿyY@+I;FAkT߆[*tK^S%Kߤx٨{`/*B(628m9kR+ل=BU,N '=#O\J;p[<=nSP7C_z:ė@u&+'(E3OKW/jj֏JJ8}޺A}eYЙP$M}?~<#O:֋%9'^Zw T/%0#{mBVtpNE\;7f]a4>$w[ּCb}[En0HnD \tr^ QyÍ#5p}%9ץxV}LJʟ6|XJMtEWɌD2N\_+S\8F #ҧY6ZiV aYڕ8 ekQ$⦏V^Ձ㘙V;D$*U(S6fsmއy`J2/|5?;D٠ۜFIp]8kĖ,tNUˠZ?VzN8Rb6CJ(;ku2D) P,xFٿ3l\'CQG$:C]<16E! tCB9&_qЃe2k-Gz!V ]מ oTRWPP0(A;{uT0K6D\05|v bAIA<4 ޚ2#}(~1 3|joth's3߭@@j2F=˙UJ3 Z`GC[4UYr0+>idpc+lK+6l=O©fXc0+T˅XayTJ/]E?gs_ 4U?K /u"H=Xn%kg$#Ԁ"n~E`3(j >EjE`E$_ҜWllwg~6l'Gʆs*xd >3r[޺@=& MYp>K3;U[;;:G) tL aXy ѵG ()pZcʗg(*$.zDXBS/t9޶gKL;%_nwqhCEne'?/$;3s5GJ鐯@ݓdgv?nhF.x6@YlLvۍa69Kq:%*WN;ߦIB~/H5@Pǭ-DTj`_OZLZ@Eڒ3lm[׷ '_vOB 4\>V7%IQ粕 ҳ704 'Ů(C5O7Jvh?SڴX%b6 w)j\LJ D$|@L%6L_U9``ȩ jmjGp¤bxDO)ʩ-'Ƅrhɘk0$Œ5f)B/'KgJiyIBl[oҤZ^;m[%Ԭ(h h6eOdxNu{.18@A]X<7($?R`qC~]ſ T|5+ ċZ{j\{#^z"`X]㶚lW$Z+_;Aױ d,oJ߼bt z )j?NmK=`:[0 ~΀%h[M&6zd+(GPf 3@(dqC? ≮:E4pG᷷I$}Q Nܿ1bƸ69o,a>T$>MZ}o"=DK,yܥ>/rX`+w~/5q Q8ry ʮh8J_v<X)Q4&T¸Qho"96pwEW)0ŷHH$$HRyMEA(3rSxF5> kE8ݤPt⽁&{۟F-F|0u 9tO"uk|(+ S K<N+uj\7Vfd0%,pुRh^);ܾ\E~ U !"D|UhWtɼ8Hw ,Yӥp9nKAuZ/=ẃo?ϓ4S؄d7zQ"@M,^Ē%6ezR Z9ΡbXCb)sAG)l(TϤώhO?(#VKx{d<^mě ke_ջQ]Cye}\ԴZs/%iRjz+Og Xrayv=q" 2h6EmJPbx#eQ{Al7!@m)rU_Zv=cvod@x{]ު$;Q8 KrRvco%AX:7j1ޣZ_ H\zW]ϖKMv G dGG@+H3?iF,i4'{A,̅ݛvfp5I~:U*,EcعՑb4C\)Hx^1`K.UngSh.B&'F90*n "WpIa)IF}|BI lYZe|wqJZњ9cQ;ӆ Iz`^Ǒb|޼GI=S[?Xu#Mՠw4kg)}:xEGU$:/kEݮ!B,ۖ1 0>b`P~wծB|%XwEbfꖥnϑU$gW=פe71o,G¯Aln/TMby[VchQMxPޛ5#aA53Ժ힂hVZ>q7?]<qJEsadD ;m+^QydyH(2I(l"/ہ7&?e3#&>KxHEub@+>uy(`5-]JQ@A0PRKGG~jjO4aWA Njet}Y$Son 'ѣ4ze#NOf !lV&TU}rؑ["gq\1ZKB}UOY /N&t{"kݙ?1St)v{lJqZ15Yx 5pf}8PѱT7lD=V-+8 UB}xى8^AZ$3O~q6Y`OgACq<$"yjMIsV£ޱHHՓ{Y,㺢jXbg:oSV+fPJ1FĀYyLDnY*«݂w/b ߔ῞~aqЗ-g̊Jhe_i2~tYJ kG6=6joInoUx: UH`n8nIrLݏ>[;Qj4]lN|os6. +}7h$+{H+heKj`7EYP%V-A[;xL Ik䩕nk&ʩٹjrɩ.a#Xjp݇(V,d,ߪLhd>@?7h0ʑ qgkcAd*"cKN7 'Z&Z![=xX'VeV79VzbsϺ(\-zӯKB_)5԰1F᬴(P'br[.߁*iNl{T!8h[jνo_e;UfŸ*Cd[OUd!Iv7L(wv w^~G҆*{3ͳL^,l1O Ʌ?n(<`}s9-n>g(“E]/.7_)mgX% rlJ{OɷD9uܟ3vDHM*ΧQG8"}:ͭTPnB[E .yEIeS;fBZ4d(za^HPrRMwlM,NDls-JV3Rh&j%X  ёaC0pShNo=T F6ˮN.r -H"۶۷%!+q!Ggq&(YK: é?\e(YhE8FYt[7)MCމ8y3Qϯ\M/zGk5"S n\rjfʁ5 1Kn,ר-C&&T0FPWU3?G$ʀiv:PX-@SDkX%;&T d u]GkЇ\V2I'g& ),&JYu'lt@0 a ˂"܏c GO8Cmɂ#{L>(yM֬NeYzORB@n NSb$VaK4зGsKf,E`.|mT:ZB7zڼz4xI~g)1 Or([wnmo}M*ɥ"l Qa8ZvV\v3Yk.x8*y(hLwS"υ3sX,@l\6Z=#4 V7$ƉL#b)38d2_}%j Rg zͯϤhWPEKHa_[AJ-zZ77;EPiNGa,;+^x]zrLuu[itb7Ϳ_`2^Eðj`Boʟ;3yVOC`6>_' 0 Ni&}jVLL¹n6V F꘿[glbaGq?7DM*L7j(DVq{-_=3a<#Tt2͎vjv^U`3sz$Z nI3M'rϜLKIC;"/Vn,Hю%QH.*НSHppRD&)XPKcLcܮYHȃI72#GsgrT5luii 72laPǪv*`^N'*1S9wGXq$)P-aR1DY w1KFF ߁TFo䎱$)DWևK:de{_R^ w']ΪT qg XΥ9lX:%wov!p|4J\(zZb,ҦX/$ Z }nH'WEq%q5 3i]f3C7ۗ : Z~9+7IGU.BXUZDjFJ#&%Bj]MBLJdw?qUp@IYQBޖqxȂ"ЌNb%ûG(ht 9z@dYR"rv_;p21x` jT@ׁhaeYeެ'Z1*dۡ*or/xTi\2{1@ä]ʩŐzի޿% lN'x0EK0{N}\5HvYT!nԙQ.dCTpfqɱF?ϵ`x<+ UogA^B<ƽD9ﺺ'V\|-+51)YEh1Nv]i] zE ]d`zeS/C[yVXv "_NlO7F Qm$#}ۤmbv]Ex 6N,bhxմ1oZkf.C#.!&k䤙?{<^%!]x869o;(5 {r/Qtȧ?_'} :vteB7>a^v걗VM}ςF()T8&Ri-ԦgKyD಩܈e0qɡݒ s]DlbWQQ'SPNx`qhxHkѳ.rF\$؃0@WV4 '[Zi`p@T\1KyCeP۽wOD`l4cFzu^G5l:t(b{[5K pPVqlU,DoF׺̝y2 {=1fnd*9VQL "_4]`sl GXY*ϜA>\FX2湯"v¥U}ƤXpy[PF>f= 9 $0]@ʃR MmBRdWgP2eWvTzLdjdzYMyE0qg7ULr[4CNKʮ+RR,! ה $R-pu 4"F5X†( 4NGo -@_7xSc>exk?R0.DЋK2FV%Zc[\n*Z+Rذ_gZRTH rϬ!M4#@SmYa>L&m㙺T-KXh,Gc( `vnv=ͯOz' ~ERq;WPu> W0Kp~Ћ1BRzeCoR&XX!TֆoF헕j/q=N~oAWVDDH_S5Q:2BCsJc5'̓6VP%[C9t5"v2252W0A3qNs'$:3 l^lшTފfw,MʓVpCVqYil,&0L,&-ZR蟜 Z9wRrwfrI)"%LT!w ւoQo8W{:*vǾv0bsL9>숓-QfZњO!*z&G&{[12Ztv).IPݐ ԧ6u4eJQeE-1\z6-0mHį5fm0n)@Q"ڧh ?6Y`^Sf$JHퟴ2zoXuk[00u=@A!$֨A'Ҵs:HdEIQA'0A VEڍ`IjvF13c t04EΫYujJre'^{12&bq/\H$щeƁ½Qe W/;xĬKI{]񚽩S ǔ/zQԨUmQJ<|ӬĊB_p)ٓ?<UݓZ Ζ#*Z\tDn1Tѓ2 ?L#s8J? lmk\D Nn!XW#Hz~Vs#Zh,GeqI|c~ YjiM\/T/KASÝzNdz')ҦcS?G]nd6;~FST(Tڅٓmi($SFqUR]ƞWE1?b{x+c译Ok )q˙FCsMF.>dT79;.Z#6s--7=N&CûfJ܏ X-Z7ﱿ5\TOoov}3b8!1!ه`g%2X9G3G@J"M(L¨p Hh/\A&;maUn.kB _rw1ZT/9##$9"!sWǗ(W{50 : oyĚ7wS  m*JKj2ξ/܌N g 2JSNCU;Ń($ 'k[g2¡wA ^]y8YIX59,kH>0mh;`?6'pd8g*9WMSݞeVsU ᙌH^~ =L>oAdC>bʩưӺAJ( e_Je"?lG$ NgY4yE,eKJ R.Hm Gf/ۢ\!IJI,xF@YAySƜwA._U}nܟŐ$(Ec~B(9.soa#i8߶vfRewl5#2-U..:ϸt\ I| Kp@[ee`iQ\lc‚ *gPf{=SWU\ CVAVT\ 4#| ,/PJUU.-ZxɹK Wh1(*҈8=iט] sE=[Hz?+d9MEF=pt/C-yTY83~dM#C?4AN_{ؾ%B&vכ:t",!a0Dk1:b^=\&'W lHW92;~n*9Y4ʀ,у#Ȝ6}7B 2Z\6aNJ%YoҢv$T^9ut}jꧏ!(UT5E eDV:@]R3<%"ۦõ, w!9:DpI*d+ 7 2$졑n׋Nӆ}W[S:b_\T"ࠞajEIdm+lI&ү/A݊'y^ >2iC[ƵNm5U]NhMc@1P{Ο ߲vт[8boL6>P/Wn<֦:A |U݈3WWF^,mQ1d;{D UugE Q {& Ґ]%* =Օ>Hv1%fM_}՟;0 X-^!U "f $"'mz3= d98 w[fŕ z,,ŗif}情 {VkߵƚIi1#CTl\JR@;,fP܇bEм ] v ^Xm%?ޯ̨̝M&2Hb+jIV@qBٰps/cs]^cOq0,Rwᒔ.-vk6|%3n3yb~ad=LG`bcDVWAͳ n}ʼ9 m*.&^y{s['#TC 9scMz7X?˺pI͑fi{DE%c'׮u(u26طM|́ĝJc!&\p~yWbSP:&'ra*Mއ1&8mV< (o..S+ӹoXA:zקIrR Pqn_p经 М4h?xLipR&$6,@ "@.ۘuɈ:C~} *>Q4,w9PB, {[d)A&N'_FlmT"իC'ȭbRVnPVkTJ]ѝ$mHۑsd bN?~ [JKR;؏_@ YcJ<Ow⋭)lNS-3NH`hlaRz"$*J굈" ϊ-|yz]Bܝ?"OZ &B F mia) Ustٻ2[4!.?WUI~G*7 @/:2hrųK$ot(v킔&pܬw3۹4CzS 1^Q5ZUS~Q*m7Wo+ٝi.>SddH\j{ [$e5`|3Br.ݿL5OrzL1YWJ}hzu ! *~m  ԙwdSØWMʓ w/5) 4*SȋF&aor'0Tdu>*Zt/ƇivV~]oGZm~|e A\S* z:t'VF}WQ $G3D}f5%3g[wNH7`1 ׮^Є%A-F:o3hMK5n>pл]TPvOM>͒|ScÜD>C;+nˑKPϾZ;D ECA=8%&S&rT:/-@D^(܉Pbe+e'%X@Чl5ǽXc挩}P{w1*;,i`IېAm=`cHf8ÉМ30c(@PqoXsV"oEO87?ssl.5^m&H 4Sy8^wOFXī,}eu݄WK#YA#RQ۲^yN.)ƜX?1_/Nm! WAMRg#Y0G2 5#5vsTE%!ڕ9Nvmr![vZ "s!#5 6cr { 4䑇`YKm1Ѱ\+n~M Z|”hocob@:h}qFxOiGh&X.<6=T}&<,] @% U5koqACd,VS$`Q]50%҆՝NMJ$GTlTITcl {0 /t6趢4`f9Ŗ2r1I pϣv\xJ69Ni@Q{?ɞKY'xi0aCzi8f$NN?aK/?JO9@hN,Kp_,Ϛ"x/p6PП5?͘gWIpZ VP5wv8drGR?P i!ؗ*jM}W1 'N"\d6k 䋃fCҤ9Ur~nn76AGOQ /xu`jpf0$Յ/aƼq}% }n#'y>et Ni krC^0ZLQ]ofi't ( ?d"Iߍ*U'wFRl,zDvat&{zE]WX %W@Ⱦ# |AS$cv) q*3ؿyg1*tѸǼ-Z}LW( 1!/>qcZ'yҩ1Wr~M9xg{L 8%)xYЇN!L܅RVc%R9h\wwzͬ1u7j9*(5*jܸ۾=77w65&Nk5:<8]s;f/Y!9:S7D>?&1]5?Z 1B)oJIٱoCKT7,0St>2@-P_#cY͘MYCh=Dhe3hݚ-ߣ{oo;KIx~J梣1>Q$k0JE sw,$s6I9p3njfςg'}-4D9Y4,cQV B] h(;C>X W.Vѡ41ר/Xoݻ#%B,`/-JO9[=t ͙'UD9ڍ5k ^DV&L4vS]0zbiC&MF%`woi[f.nqf?h] f(L(h-hX x{`#| h5ܾ ?##mW)>0ǵ[C^$y\+|hb@DRb%1B}J4>Z8np$t,X!f7b>f0 _Ѝ5ר@/gu@j='YCw<{p Y?J ;^=1$(hteV>rZOgfb9JTv1nm* 8 v{̔ah`o1 $ib]$Ϫz Jt{ADˉ`Hz$K)JXEڞJpg^k,OtgcBⅹjܤq DZa`quc? 9 ݆ }OeI'Xҧ(0EM[ӾM&Y _nӵD7Fj)Rr5h3  b]$12yZr!QU 8I+4R[^znvE ʱdiXn.РTGpa\d7{Eh^Vf5`1fPR/S}7χU5bEAh9SЎq8v[@b$Sc6*.ˁ>6:.xo~/'`hpu1ɣY#=~g:=J*D2O^ۆS%u +s.f0 |6劼ZyFCvhr5pt #P:VMV#Oof3͵EyًI!%8!)~d鷤 $irkdtM2wnN:UNKߛ9/ɛ1C%/s0CeVRN7 Z^ uKnIQy*XwY4(mk(BtvZdov1 ʥƩbbvAWH'Ýh6Lvs9 #)ԯFq_EGO̥uJ_'tx\|s'86L7C(g"z53/6SO]SjdWޝC53ëylGS9Նbz.b|翈˟rjJLRt^cIk4h Q\˜ )Me PL3_:ή;hK}`<@s’kE _\ _!i<F8F9J6G+`=;B pA2sW2&J*4nB3٥p@JS\Ã`} iaT)oWx>I}}&-RӨ5''Fy|.MG92-fr03!&{K8f:$/u6#)d;+AZaCB7PLfQ3'_ BI(a>W<%!T|/WZs}AQNR0[dQ ;'|n63ܴ_n}y϶5&p־('P"{}ά(N W=/juX5Uޡ<pw/(NrF$[RF[[m\xbaUJl^it)bEi?bdK AHSHkk)ʻQ+gƏa;EY*;:ڧ|0| ۉ\wK R;#J7}6.n}JiEwL]C2T?b&vVXX\7$rvϽcX&P Ƴ6F]>V#8]P{!J0lt eC(vSo1Sr6; V0 3x w֯Ⱥo7M$] wEUkbфt)8ĆӋ&X!]lvWEKFR`;V\]Fo.X}C3䤐 `,zA eҟ^gpDy=cәXչ_jǾ/1a,L< Wu  qu@H2BiL:"}]B&VBG6\r&~HPي^oZ9]ND Yr2L;DPELss` ~{]Q1x| P([֬8sM=wp&u6Uc쾌adQ.{E;oo"H'g?GЇ=1U`#h& 6xQ La¡玫,3 0AWU޼E5P!yfdz՛;xj:kMk!  DvR͏:sG)/3=NPt 7{nbmU52WK2j] p]q?5uz/qi4a@j!E"SSrۙ͠m9[y*,I<-ܺ 9~C<4a <^gyA(EL+/.=M]**OStƷ7/%|K+>F$ԑ^:HZFIi<f4^+t金*(n5MmgFBtIF ^@k `}-O)C"xAۏ mz^&厊ng  ۡK@A+/LVBVum,x,՟ڏPsT?!s$֐rGy 1t!uO>A3}%;(K:c:F5P,iBN[CDtQc/7d| # M-?2`La۲6H>ЕHI1ł%hא˝jd0Zێ_Y |iH59Ic %.S#u6aOlmnFdmhxg*m NO6S/cqt@}ީ<"2ZW)+I |:} Uce745<~'y5N])S"`2fsJ*ɦ9E_ -/s(]2%./kjJ;F#~<ƞA}TO5x| ŴQ^cMa2e W''ꭂ|eذO%LO-WC%H|*Kv2["D /$6Cޖz82#5ms v(} 根v ]恛CX>ދҔc{In`,:JN7Xr=U/ ƚތ{H QC,JŪNqASnm{6H 1ڥjMABJŤ| ,!pj #y2--*qNyQrޡ6*hj*sWx.Q`+ϙPp񮶨Dߩh|0|Ƨ_뎇Ԍ.ԎoL6x<]ȵl);PyTYT b вPj6| pL87uCG3!T  DeV{#YIYGJ11(㺟 UbnEц=Uϝɑh(jt% o^%㏬`PѸE1.iG&3_!6P4V`{ 3da7 R#IhnZF9IG5zWjzY-k:HŲE\x=h~"P(pc) ̬ +9{v !싌-uݵgD2'.l+~1Pez4Rk( ( =-PA&)OPlmB/ʮ3 ^>++,/ P6v䍟qQjfYO\&6AǔgOK!e#[y8[UAvh ĉ2]#3FVS!T'\QvbIz^`xf2I" t;*Qu{$pD'ޔ_ȝjJ@TSPF۪ōk&FC  Z<~8@"p.:x|V(%TYO j^"S,`IaqB‰Mqhlp' X# ԾXSj"|D5ѵcw>Wg'Z b24~Q1uXY()63a zѥQH5^j#@/'M}![[Ai7RX>qlp=g5G s|Qy(Xb.ƈS<u-T ,J]sG0RDfyIPĕ@Bю' Dtqґ~ְbz: ah)6C(zۘÎ~t"/ P[/7$ЇA`ǿ7K Uū{ 0fhITB K7XuOpj7C`3\q0~eiLq{R%Jda$Gʷ%ǻHY=ֆ%*?4=4%;OK>KTtrr!j(%d+imENy(PوyRzxT@4,:Ղ!i"έ %=?"H6g:VA{;r8ܬ^)"F qsqoSA|%fzhv]OGj_=$܀oR7Y5k}7Y/8w%HZ׳kJ_Ҟ?>6OnBngPfg jJ^`&}ؖ[>H+'mlY U7)@ M[lBܣG^T>YEnzT1l,L. 6Cpav<_,Q85kub508Tz FyvZY3"1fQ="-!+G_>YYߔ"΅֌/-/0h_/~*-|#[JPHRq:RW0|6F;|mᗨxUAbumaf.lbkO*Al|cP)Ei85wD=9R*⵸Bp+ƪe:3T.saCē?紦3UXF˾VlR!q0A[2D`sG0"v<\MM(юB1D"BmLnZT~uGww#Lqqy)z+(?2y#-y~~60B- ^7#֟6ŴVmD]Fmsӝ2F1Sc 2:h7n}j }j1\mnX\EaTмOPDF-B6Zpf>l[~AVG_ӻ:0DmH~0QSp4Y *QWxV}2.0+e>BOi?"FLOZÌxq:dÆ[PC^:VY3)ԄHLir*ԳrH:Lݧޙ!J\ٻMm9:k* yW#sڏe%_]Nϧ/drk kͰG?kz.8,mZP7z=df3ꔥmx{y&D|~>Xa6-=/6رjZ֔/7E.)+A! uTA(Iefp}7WcMw!\F(ݒk0dPY}RpcegpB7 MCz/NjeTvC\p Ot# ßw h;UP"!=" ՠlbH"tR*QF˃X>9J.ynWŔת{>k+P*E3P% fT`j: L8‰ͬ)IeMvϑ֕P֑>9dHwNN[q OXo<4#8 )]_jU+zHR e# U>^s:Z+J8~ 8:-:BT ,lr%yNlj;0P)aaȅo1 Q?PT&N>2ehD4l͘س6+BwIBr9G"J{%.},U'#?ҌI*WS5OY1?Y2@ Yh} &sfՍP(Dl-xMPT|h)٧c-tQ 3N/0M.@Khdtu=#~?XZ"AbtI*t4GSD-%#-6!'hU~BӾ_EKO#E?Zjo= R.<#wi0PO ʳ%Չ3pd9kBOư~5<3+!Wqҏ*XEpcf@y+{b!ЛK ~rɢ8ͻʏt )&9+բJ9m$e8gO uRBx*ˋV>UtODDCtAb*y:G|42p^IShfCYJ[Se_U#9AI.8eϠ lܖ58u;q=6Id@.)IC-Hc@j _vU>{ c޵(D48Jf+tf )1xU"ɯ7 ^kcBȜI\1ʫz\+fJ5l`-&Dqe /p/Y (G5Tժ~ 5{@3Rk*XZj1@W#?󧐞q3z88^ iԖFw ;9AHyj_T-yz|<9!9$Lzi# 䥆Pv)Tl \oT-nt~ LX1&*YhQܭ~Oһyw#u/kAj I}_,)ZJğd}<ġ=_∅7ug,ÝhCƞ~eL-O[ T8v,9"8ȼ ucxBU4:eĘ]wMn)ABUHXqV{)6>C kz߀ǣ Ks}b}Lx"*dՒпz@&{Frf~/;xŸ*Mmqc5;=Q%~3o#ĠfJq'*BY$F1qu3UxHdcxJxKKҚrd\^`2#⋌ |EhJ3*p'CX+b8_$IΏli+O%۲&>km (TԼXQEv)ZB-cPZ/{C/Wt Vy}ɬ; :>ʟϢ!H_* _m16#PA䄒?)sM35'z|EJ5ڀ#ua])g}apVJNA6d*2֩ !#zġX@[u,."k4P(@h=$_ᑙ%^zWÈU@R/"E!Vs"Sts T䎳?X\/<4f/uZL" XIuw.'&12p;mD[U^6`STyEp-EEx(4c |mTŞ81o [ y4_IY>rh'?푉uX++sEVq4u0Zh8 [z*|}g3e֭~SVjtRcA27$>buAb^$tmY-}『`{-1T i׃5 c J7 COV>i)<'\SĭHzEͿ=ir-EKd$6 ;K1~էWO8:e:Wg X+}MaǎVV6]_5vESC[;ƾ! JJ<%jyRV,1pÝ `}R!pJL<t[JBXC sm[k<bO1QKεmniń8&m,;Qrcp~?^h"1t[5[yXiT|"I܄_J ٺ&P9P}+<ҙH_ mHO$LJz(Y6Vŗ`KxxEDؓ)woLsSCÆנc sy\݅ǥF9CbW3lEL)ٺp?RXG]#1-0u'DmqjD]~b;ͫavi] sQg30ˏ;+grQ;KeÆ<3DSjR8$/כXDϥ]ID 'ʻkJ3p`Nqp'tQl<{3ԅfnI$mXk\1!ߒI@B$ R3lϪ#N]ug&NrԺ};s(xFRM"s~uNf=ySI)o,Y(azJ'8]1]IS_ 4DVʳ::nL Dnyl;UmW(s2}ڮց_11lC3 0Р|c%B o e7Ks Evdf4SHנxQU{j[0soh-O2ڎր_8/r~Л5C }bIR`[ }<^E'8Z ŏC,ECǀd]c %(׹yR`=$UKY_E؊{0%hhX-h6Mܽ-D+נ&64|-; |OQ/x M;rۣ2K:mX}(Dd w9IlRΈ2ֽ "zj2|imcUec{՜}Ysjs5 xbU^/O\\~.CLQ`1 nw_l E0ÅldjKO\L;4Ȟu&TeʅMn'/dDnfЙ!TqEzhJJs?Slzֿ6/,P;H!oDL ol*\5h:|Ϥ2Qu0 &85KĺR 3 bk5^r*} Q^"]h Z)x{7Iv+er8rl=cu8z1|ϥLd}=W7yt-x_އU'=H1ɶNpeMX_t$Ъ|PnZVBsiՅ):_q7!/X0 jeK)fP히l_vY12Vf=u XaW#CHkp@y@^3<0wU.+y8ӷ7) At߀Ɩ(z,SeR ➳Pf[ RhR!Ŧd`bktA}.B%e11yA3S'a\AXٔ,?v1+]ȩSri!TdEa1A߸#Y<}FI8ѫ'ξtY( @ ɮpd& [=5 .mY*SxʎA4 CPw"bT}pNEQoId,o^|B5{Nml$g򼖎 KX8sL|GϐUW ) iSP2_$||\Ow{jaz{'*zyP9Ҧ@2RRfh}Z3ci!JF9dqZ}2.YHonE3+nLO^"oP 6h`kaCM=GfI'u?́ R |y( s>,yt9iO.BkC"BsWγ2`^t& &04{0mNkU&n|:K|fz.aYnN"c/hi3n@u:@!Rs3*DSYM/QrY=z DYfi:)j~!Q0FBkF9Z+pwmˊWӻ2gR bU"7j<"Цa/E6OvZXWo\wi {bܛʿ]se[U/ FĿ1FWBk;Gv>>ln1lh1gFO:ݲ*(s;%#ڊJS.<.n6+Ɋ-G]" ',Nn7ɪ %N٩&eTL9n7)76Ԧ ZEpR?͠~9uҟm|-^3V@:񿑰{5MiՈx0GYJ=&N0B4Y'69pVx]c q3$djeph/=8cDUNҷ_䧿<!?{${`s:uv۬I/27:"6Jlm)grKʙcjU,>7 acljӟ[2Ce" q^|3R2m-28z HHի 0KIB6ҙa]~I=usVr"ڗPhLj <*48;'?\;IQ38q"O ~7 \5^ǛY8jXwO+Os[fV~hs 40 zru'm@ϐueJHo ߺJק[.+Ji,rЭ Mޱh;#8a2RQD=%MMX5 ~6ֈOgE?\}GS[7ͬVO$ 8ŖzM{u_ɼd0txiMӆPS=aQ=CI~kF6?-'7H<~mZ?%.j}yO&<|c,a'%MkMm-˜fNUF gHp5%(*J)O"]0%׍5vzlh7s[Tn] QTxwnt3,03 WsVj&H.9nfIMF9eFC:D(=\ښxkug]?`*gPצ?1m精"%9 c(^ v1xFp4,O) .}M_ kÿOlF0k=(xDsw' Y[=^!@_ m2)ْpU4::4<@fhH8i4h_ ICS>1UE8ʐWEAfWuʲzz]udq~%&d|hDS^;r`cf1cYhMtญmJW1A>j(d̛|P."mgߟREhdos? V{̡UU^%Vp47)㧖LQ9>:Op * Gq4Dd 14^jenU~F\!Ɂi+ī#2aDx!.2UDe_#(A}Mm]饺jP4ATr+ol6vN(ʬ|@e ^bd\;%^ :/D[O2|_]&#@?wsr"FޟgǾ҆}݃%ThXm٫MIpQﳃFj%Mh|1u&.a#קPk!Bʠ}Pvw4 $̔`ӎjcK73^>)=z6c v9D136Y1b<8ahdJ3T5=nN8l]e?dCJ8F Aͽ()qhM \Q.j.WvےeDۢmoBUL\M\MEN݇'P' V@ɈJ3ᶥʭs>?#a*XY0M.'N`:̧͌9&t9?^^RNč6]WJ{2J9 HYw:h1vh N^@pF`;ؙ**Sb6ZYe36at"ި2G&#PzLևI=cCN-b(&!lWWqi-e"4wAh)\e3뒉 vS脦k:xctn !4joh*UP/yCMƜ q ?*-! V^y29-ܒ\G')n:!"˦ ;g7O2<-YQN!3Y%CJ =T,6Aai]H(eZ:N> #yH/cXqs`B7q/1?;=iɽjYNp-fgURp|sm"PQ۪aZ>a!0jnr4Q'E$GT$)ՖZ"PB4&jE_KFߴh` ݢO@"Imik)ܥصغA3X ~_s9c?rx.^}[Fy" !XhHɮ)q%|֑TG c{Þ~sl+pƎ5DGUV7'vc4~ 4҃|]`3(P 5?Y!&#Hh5l~uЙH!{ۜtqIms2찕8:[-@d#&c/Q4Q&c~PdnDP5> b VoT 3lOУGz 0GNPKc/ &p?72c30 Z_`r0DW{n=@Cf)z›\zJ[u}#//+as\]O6'ϟ'rkNo~V%lg)Iióa/qzp& 2Ё%wfhur5|<o#FmT:N8{`ح<>Ta&%H7-xN25~ǙFk$4^y_#Rn2jڄxϩKY\@e0LRgpzeƵ 7fUپPEѓbæ&8)05gVծ"':"Z b@v% ׍Ԣ+~yY :-uk9z&-͝S%aU=!InB$d2. UWɶNŘ^kIlaւgZb Yʋ꾥sLu'~.4ijky oHQ`:5S;$$ &TsW^=i,C,Sގ řf~oCkN鬨,ʸv52xMc<3b?\|>Lnl]62 J4^G5=L.ݦO'$.pVs]|pI|XbyәΑn7b)MUCҧw1=WWGhKKe8BlːsP;Սm&&bG6|HU!UvՏ\V*{+HCNA0@.,6ƽ~mr)[DYrW_{"t }]`ҍdB/ Dx" 6zjԟny A' |ڑ]>UCͦg O֪P>0 f%q67j+ͅQ-/钦F4 aꪨkK}-0فA0w(yMJ0?:3_boRZ$ ÖS Xi a|fNxĴA')lޓt|^)8__SA죉 EۿaEF ֶJ;X R@v@Qtug~QʖO=1$Al;55 5k5,r\rɓaC2јǿ-.wl"!F Bw !xnat&aYXᚾ-˶ƹv_CݸKe>Ofh [\=\/?FCI88YbJ9{hyC==h[ڟ7F4D KGA !vQzR@Hv`uqu$#OdM>Nٞ03_@=k/MvIlw"פT *7ىi.o :ȲIb~c=w+Dz%9ޜC3jd[ K/g|obF߃s yꗶͬ(Pi{7WҢSåiguKz]]`洄tTҔv .@K=e.x_jxkg+YZG~uaJ{uZN iVg wu9M?"w킌'%) ̮J`"w/'\» £0YWR<1g)i낪:[kc&5ED`$ͼE/V--%dj\.=ZmY:?&?>Yh [P"s'&*%HI]M U$؛B-ԋdG W@\ y\Qh޻}⮐sT1դc@8ZD4'Q(YWt]8Y&t'ek K5Ogy)6k3B}6U&k"x6NEP?x"h|#BA~+FTQNw ldYIbHANr~M$2cIXe^?GWlz^AkS@2ӱeq;˷2־ZBR8ChBǬG; B#Ֆ^`s]C\]_AQadۮ#W@=hG}쩀cVu/Jоǻm?(f`g6; x]2FIfE(5Yڜbǖ+8ȳ*]z!au`fL,S#D|1/ڒV6WC,8Jh'zKEb)Ou ">S[HuH%ᱩY-;qo8 ;/&$z@*E}͌ I:(3U\↟l(3p¿+|\*S|Z;%nMZ)Y !8;o |?X1ۜKh`'m.e4y۴hofv<\ž؟03'Osc&6ZjЪqQm-5$_BpybZ\?lr*j3jڌ Ilwk|YrNd}$[6ѬJ@nbWgsC?̕'y-gJ+AX{ujt;nE+?Sa'7l["kķzuq!td5HN]{R x4MUUQC5d#8STYkRc tLptq>< uwNjk yr1,WqxuWq'3e' HF+&2(Z^#5n=}2楉 r* 6n8oB+&^3JzF>OvOI'7\ wNR 6B,hQWn Qw?Hkg,4EPč$~`rC9v+W$xKa1r'{Dt23ϙt+ڌts_U~?,AOu VT]``lgY^na)ϸCVF gRs '@y?|!$=sϝ7kU*f̒ҷrvboE)-ƂYr$/m&G. 17Ōn tiPV:C n|7!==lG"]μ,P ۱]'#~6'XlWRGTkyoHHv3#'x R5i΁5|uGf MQӷ"*T@PZ=q;"F<} M!}8%=կbem;:9jdgI i~Ly89_-7~Rg8t9,f H0|Z췃\H@2Mu czğe'4͹P)Z`2 }:""f82EDr3p j<Л^mjx#=1(ǿc4 >kX*S!bdî'sr`z~ljMR-,AH56ԧ).+'hf  7Vz@\!\%XFKGAǣZ}wR:jIjo6EW1lB-yXM4$Z,ޗ #ѿS K>KRX#_sոrX/dJ;Gr5]<`MӟwߪZI!u*ܪnX6gFΟetr~oV@NzA4V`ܗ .e$ 6Uw= feWC7u>%`Dm}6{- VdPuuyi~lj#yA2O:42IM'  o 4Ok'bOˈ~ zc*3UWOKJ}+՘95i_G5l;ܠ731\ (C_:#pf.¬d}ט xAM"ZMSמMkyI )341 VUroj`s S!D2+-Pdg6og 5Vd'i4\cv_0aSS1Ԓp%<;_W͑مD<‰ 2)O>J' B95̌ED)No_&ּGrZ? T=Q*8yƲ'"\d× 3e Ԓ{筮G:aґ"9}ɼ[*\3e/qI·@|7/I/Gۆq(YrF9)΋GŽA.*g7HkY ):Ç4UN ,Ӌ$xtG:[7mkWG´ҌP4[?yȷ65:fs,?d v^Z"` IۀwbؗOmxj0˰ dr 6ͯ%5\iJblh?Z杄zР> ;FoAhl_y6xDbqZC<, l`?-O؊,'.^_,&8p#HKzg'ۜFB٤|AkھEZȗmhDޱ.eA"3jg(ÙHB}׶5PV4T`ū-9y+7Ņ&Hk LT. G+E``A\F(Pѥy?? f`zm5NMh=9@Yp xjk9_V b4'58 xLQ!8q+jjҸ+Jې`Q;H,$-"Zd9րp!: ^%=QErN5/ؔ٪lL7r-k3آֈ+mib+rpJl>!: U,X>[, e-9(ccKEZh ,k>1vPuF{T[K,~5Bz8?I [quKL+Z\t+_zvB$H9Tc9 Ó=a$7Lw˦{ {$d!񾦙V-MHlCYQ{%k??M3?!'6aqDAD8]#tc~ձZLQ]bXoy.Άedp=(^N$~eDF&>#%Qp;q;>)nJ#uڱ1=}pV\qji /2RPߘz?JΕrR٦E ./OY$Ye\R@?G2AkLUl:7wG47^g$A#7kԫ C">cZ ?kzOcbn"l*Ҭ`ȡi\|"u+L5 ^˄~0?w f𫒅`ܮRg*{4YTI{L`d'' NJ3Wor&{T"H@jF3Hs,\Ѿ[6iTnXG'v6c~1G-m%d^ı0{ZS إ1(p[! 6ҫ ~d.:0 d E}^hQ: ~gixxLV/K584JM]iuËnSPh ORtN3o{6~g%pz?v[R&Y[╣ޕKA94*-/=G8z:aAǶx=_YRTaпe2j1#6)fX uχllˡP; ?ݘ7\&Aa/sE~CTB7H:9A0ygPSoi\;p-Mj$,ٱTi^aXN{j/RDDn U'W(Cl>. my81( G]m.7E/fr0*,?eP0Pwge:]xYR5}b\drr[$^]7T !_jx{Tj\UccՅkS˺1..(KhQGApFUu+*U#p]{tL9~Ju8(drYѬ)oQaw37+f|Ftϵ#kfb%Y؉2ij"#M VȄo4d NHNVS"ai6gQe: _'N/\ٽ-J d8Fhk^f~~UbR+1zD¿-8{g2(P`ƕ7|_vúҝnnv7MQtPTwp2p|[fفmWRV=4! ӈf- <-k*%DMaJis]YoD{m bRǭt́ō~df'0{鉾;Fen>bD1,$JD;ލf!` ^dBbH/iS!D2f$=>+QJg TΑ&B4nQ_r' /ϩߨUG6i=@YzėAM{j$GMSo!=&||jf%jsb.i@2*]X zr_9w9de` ӭwK:&.{)ᗧ2C*>*6Ӂ5:ĚmX٨ƝǶT\Oy%tarL&He3'V+y>JMLSX g\BFg&,?oFHQ3?ֽ_/VMOyrjm8d pz|9%~<\%/9_|D {4:<,:?ܝv2B g馺Mף%r%"ۺ3ܠ&8*tv/Psw6L= x^(125bZ92O]k18^z&% gvpqT]IbW GKfCkQrI|8d*S(e (xMo }]{͘9X^4n_W-MlOr aN"9?9m-oRa'D0*5:Fm扒#;R77RK4piTG:,pNJRN7=${ ʈ /e&O-s/ǶGl8 $ l;9)SONew u϶s B6*캤ϕ]@XJ]A @W]Wȵ+7ߺxJFg1ᗟm;uNԝ@b]8>ZbeĞKסRw:[]QfmHWFAb6lwYK!>î^L=.WguijOrxU t޷lhpDpHձAQog>4noz?8{:<1X ZH+s㡍s%>qE7&K\#bt{qIỸZC:!6փr"]-\n;IJ ü8z\ܶ)^"g^TB5{1sj.1޺Tdt{$5Cb5QW/yBpeguec,2(L8[hQQ^ (p 1Չq{9bJ<sՙJHQgpc5Q@9jQ2ýhJ_<p>t9Ms!ξe"B[nZ<547].X̞ `ɉ|aui :Q$V&h>S(-+N4F|13zDC}"E {MGg(6mn#Fe6\Ǐ=C uXPU(sO"=MIWz}k!Ek$ :3ܜY# "dm5dDFsЇ1ߊweZY\G_N;EDX U F uBfHI=T%( t㡣ԟ]q2]huB$cbَaBа(H8SF`q O/Zc2u?9,#de:)b_٠goNGFN"eA[,$(Qʳ=t<ϟ#rcW#5ܰwH(¥kwJv ɍ_EViR3p&Cg+rуqgzȍ GaF ǣwЇ8 Mi,hMF[&!Me0U򁌜D?&of@dF%sy3."vWCZÜ؞{@g1>xmI*u\rYdH$ H%P+Ctx=eeh-Qa9 $*aƧHmeL鱸ʎ]WrPhE]J@C@xDբ}-P]{܍?K6&b`qf˃Lnmԫ](3Arzh<S6AݦI? ׸ɉ*2?Y< nxUG<蛍#ﲸL(mIaf97D<ٗ5#&h,^Rd[vLuGƶ B3%[8ROea!IϰlsaRM9[DJ!?O'bK9{K,o) zVr*b3Qo9P3a rَWdRLĠJʼnU_%"j) =}gOnFNI5W$ |ՉVw4g)eFjM{P('3yïu`q:JkL^RVNpP:ZqgֿysR4M1i?T(,IksMeP("ipѶpy7B[m" 2Lj0[*Pi;F42EaJq]gznrQwnHFv`+C`GoD5Ehv?3)GӶ:IP7YC.`ϕg޶G#L8,2Av4̬>je~ƇƆFgPU%bT7g6?Q,ay\xxޝbӑsZJ7_A.mQQP݌AOȳS|NRCzo xUe;PP!,QSUG׸>{DVij L@4@6vv˙"" ŘA|0*5T)6COKVTؤTIyc6/넰\X=^|p-R В7)@%oN^Y[:Ћz~(eՋ`.{BM-+XZrKOB%==R}=j D[>JTHv:*@65_j\Y CK釸[wWkjz&^}V=6iڴF:!Ln-4 ٮ9f-DN(cbMKV8%cJ~jvceL k">Χ$ñWwe?q)Ѱ3""%Iޞ]Yf[7ME@bZ+;H('81%ʨ/?9s)LVYtE'rg9!*) Ƅ([j>;ЯB:؃$JcJ URjӌrQuaD rCmU-<|FZQKVRfzGLi y7y_٪ Ai#+U%Bz!]A|Xɾ"5k":"JjD nY]0RQ&g)x"Nl "nhe! h=sdzrcQ]Ofd)XC~SNw$TSڈ6!M#S >tRׁɞ%oW @K^Y02C++zpv-d.T~F"޵,'HK ׿u7BH/"Ǟ_}`[I$?j-,LcuM<=,;3vJY#U*Nc<13a5ga?œ9hRDEZ}ia[)dCYx믋m=(9.tb2B{6~Bݴ|'WM\%lAp N *gLcko{c7\'q`{wZv"Q(pR D'A/k)H \FRX`aYGI fj#?{*4`'F Nj@Wac#aUd_|}5IkZm`Pmlu]u⽮V¹י̈ ɹ>˗w8)uS4m?$3rT'S K_qɉ.7j̲çZI%=H X1l=vX,2Ӧ`M\^9У!WJZ~Txnد>: 5u'\`g-s0#Y57D4 VHmd|B^$VLh('d)ɋ7\e@TRt2+#Gm,98b0W\97҃m!UBzpTLBB"~x6V8TN yrZzxv 8Z"'Ssy7I;lT-7P*,hMQXZ_IF#i i؜UQ=љ8APDцey:~#%8Ϋ| Cyс8,TK?X7/%FTP[L,z *>wtȍלd0DƑ,{zj7v^h3\pظ_:NDJ8!h/P]B iWFn ^1@|cWœ/yԛn(f,(:SCͲwIGϓgv[YĕМvK煞ECNp܋r!,1 e6ە+h$,raJ_pg| -ƙoкOP;k_.Q5"Nwmrޢr /ѻ;{Sl z;-]Kڶ/d{ɴ{ 5@.i}8 ZAI@5]GSt-4 +Վ@ԔH0mLN>QQsdAy#05j2vmpS)VfK1WǙP^(q(J)mq0݊ԱC{ӜFu+3I9̉@[}\}G5(_m(ܸt7sw8V=fZj\EFPA{xe+w]HH 19HXLj~r=S PkZo,f:H=B'e=A<[^ثf_\ρe&N2Δ;k5Ĩڝ /3). &02o= @b%uݢպB~}Ba*?) .eu9 w/ ^=%D VN $[r|b{ BC[qK6Ez8~HaPwA4:UשӜe8$~+Qb~Ѯ, W3ٽ<?FfAwJُsnѺ0y MJCigefd>et-u"̑(|~s 5mJF? h&^2.;ByFoWߋLo@wgC9E u6?bܘ d&Twqם9*]*)KvBX1R- ޢ ?# ݹOH9W`>v,Ϊ< y0u߼&0B * y=Pھ!KAH@+JUk dj(ۜҝ2'ͥ&f1`ln y_n"8'M3DMeƏP{]P[I+ȃ pa`\U_-u]x*l`)-ES V~579aY>hiyxP EJJq܋ @]⵱ Vvyw 'yÉw,;١Im_0,dʳ y30o+O#;Sխ!&-)yqa6V,@|WB~oDoH.w7߯H[- Oȑ,ϵ@<@%omr8d9L(Za! Bnhld:k&;@c Rj~hr_co\_LkuI+ތ7?& hTm9Im9og]N D$ ,)7p1@5o ;5qCK+3#T<"\-h;}^ b-F+N-iq[PuzAľɚ||@iYR;]; sqOm'`$74{aNt0-;!}o PkU ]T؂m.MwH-e稵yȑ|ILn3ް'$6eƼt-C'ά_q躜k%';P*J&:ȶsK7*y딲{M$3ZrN|Z1ZfG!f C5u6^ң}^JeU7i[mX ~K:FnjZ}%رD#^a8DMƇ/ws0l~vB̿-I{CȆt@%P@#D~.gUe.JN㊻s6rkt#;1܌%S5K$#? }>' JFƟ,oºlR MsH7mq^O'\?jqsY"ʠc#y;KxsnlԮ6ud:5VMsoW Nt!2zxA42}t`=?o[٢*Y+ЩU:__mf~j3؟葑ARzc+2zW֮cH Xd4h~01 { '-BtsC^[nMxڎ-h?̧_:9$q}dRF_vmM1C`R$ȯM ٥ r`xq(P7E Bݍ 2hkF٭&mPS[} F%7BF7<|Ef"&KɥQ(rD{4?7`ϰJ' {e_ a˔Ia&ru-5}!ކˈ%szuO<]x7-%5A?xFG36;~WP]@ikD%Sܘp%2<>?Σ.< |a撯y~Ј  @,ۜgǜ .}5,T?W\*\6t8-R-#,:AG,5~\Z78=;<z% !kԂH4r8 j6桙Qeнm)]U OA~V/\ m+wO.u95R%{ A/]s*:;6\ 1㲳hdcmg [cGQOfCWԉ7x@xAxVS#jl{5huDcf3ϧ*sjyQ 8HP*2%#a#LH NjddweIyx1IldHIlՑB\mUFƿѝ[Z6y#WkeۿT[lMQ UuYX4aoFaU FevuUGAHb(TB/,)x3S2& r5ZQVC,~X$B8OD¯z"x ouLfB_0sZNO np$"Εlx[&]Zo^>Iޯ:fQ$|/vRK~rӃvD9Hz4O~w8P}sDpezQKYr}gI d86]ErO[\>D$l2 ô 圴(/~_~B c2dq5peNF[ICQA̒i@*vo ~}@ {E-k/2=ZrX`sw NX\m( TFŞR"oN BU7^,KiEan:\Ӭ4'Fm.:l1xJe|S`L90_UÙQgȦx&̙%{UI,L+]O-clv$8+kiDh' }Z{U΀ | wyҟpwT%bQ7<@]nS-,p()KJȉtZQ۔Тl 0A4mwAˏ&^e/㩩X;&4 IуLܦL3ȋݬ,6VJJ'Cc*znEp=ZJle:{Vo'K%D|߇tBi#(ۃU-#Qi%NiVSJy[D^5]e-}&چkvo;7Iy/h?3Mw&_N<:.Vb6,9S=;T͂]khJߛ…ৱ^ټ<˜i&}Fd?XD> 4󟇭9 $ad^l07>Z_~Labʸj.kxF>PU0%tXGb2+ZpφeI4_CW"~\Ct'p8Lm 85\.'J6p!~U= j8Ҙ4u֧H{k =h(:X7n==֢\B)֭urQf ƁpcJ%ƱDI6PF.|~ab<(\lUuc+N4?|l&Ҷe.N9 öGIZ´Om ' 4ɠ#AN@uyN4cu֥\޽:LazOM%I g>;1)99BQ& /n+B@U>ްlp) Bx`6~[(pP 'Lp#Nti`iWW6.>0(*ןly{_J3vo۫[N]AB?eU'm,\.YR8hBE:!Yx QbHK٢D<8fYݜn/~4qkUR7}A}+MU cHClj!c´ΚiNCKGq7 ;2k{q@QyKt);wζq% ƕA%SrJjL${I*Wol^ ֧c\:Zc<砻$d,mш 章g̎ϊIUgE v3l0 sܦ;aAaZUbodGf*oP`oaU|)vODd+vi9d10_Hɭ!OE)Ln)F tR6PakX$Z.n%v>˛]i<`'pDk'A}3՜|b2f{oď C 4`]W"3+qTKjx<$UG;eE'Q%i+7m+0E@Ĺ{rM.6Qԭϴ[iϣgM^O7 9&U+w|48P! mpKX{%Є~J:~KN!0) |zX>*JV?5>%5ִlNt/jC7"{߷e'>XI$  d)Z8r( Fţ b_]9ĽsDCKIJ IlijGEjxZGXsh­xȷEOE0AE`b0g|(kx@ 4 D.J! *A\ nt}/sa 8̏'N~&)y7(׊>k(r493)+,;Տ dž}lwɦs'Vj*d?gr'n.rh1JѲ d.wC]v9WMعfy7( vUW'f\Z1겓t_K6(VuWaŰn6>3mrіGjJh'uaY!ը2Q$fLZR4 ~Y8`[.j.5*E c,}rFVE@@n0Xu'^=UIas̓8W%f 9ħfgajR8o&D&S+祎~Rʠ>7{+=i )>o@c~3^Poz| fwpy&xʐ^9. e%Y9Yva<ƨs o#ndmC:A_ y[{mjLrT?zLW k|rHb=TëP!Uކ&LKfWt65ѧeqQ^´dfS/Pδ0C /e2ޅ#FOZ3-`Y1`;(Q6]Q(]Bj"+aOnx*R3Юxɋ>36sCX;BV]̚OJ 47pZر D2@N؂}sFmՌ}]_&ML? q\TznǃoA5/9pxv29!V ,d'oO+&iO](&[w+20pwGt&Ww2O7vW3iz0BIVDa٤mkWfw\Q|5G,ya#KBʝsw_LQw- ŀNѶCL.Ų 7_E=\R_ T,!ԣ_^PXI0>ax]> H'@tQy5o l 0'x+J~CPhhpHloĻmϛwRHFFɥӧ"Z+ks[dBe&E.sV·(^F+cuF<К皚Q.y[k0FAw5d/ /?-&=pfS=)>\!=z/DZHoמjCa&6nlrǺFXilnV,[wu{y/ ʙz/Wj$hN/K#Vɫ':C g?4kKx;HηS+~tLl8'MX{  ōI|CqᓘI J(\SlBy)lU-=Z&sOh5z\vdS:_@/ůSJ|"J@E@5\<Б"2ڶ;}6Ue L`}vW]/0>+4Vz|NimfZc=!?.B}}ʶ)M7O6??Y?'z'> .iHGdfe**#Np!6%@KfgF ,)[(t8n0bNdTd,%\% +՘fpKyd#zfRƸ׹QL80+oj.7 p3S_w .u^wsx1By) >3tW^{Bf5# *KjyFv8{BzI# k ޫU/PfG&gVu$VϵIbP85D:Wݎ>^'_)\~ -g0T3\,]O,i5Thή['Ͼn;v(>\51ohn߂k9(|@9o?Z9_Jr+4㩵ŠΤ)Ew#YRPrb}{zWkϡWq?i0ڡK+$C1ҊXaN-,MݓTN++#AcaM#t|oZCcYj_:]܎r<2[lLéx"IBG/Kg_'?j""ɮK H>U=xRN;x^Qs@"O`s<]7 _np5VKyѦAZl!^FL*: Iw\"ہsG5bq-l=m)^ ™{/hT5>*P XLAdB[~8W# ^/6CS5$a(\)6bk){QyKS{S #lBt'3ϡ t]oD_u%t"N/Tg>'qYh  f+ ^'dOGHJ,r + +E濬ohk#xˍcמJ4-%uևO_hPd39LFlhH8u4%idY׸3E6k=FP eXP6dvf3H&j}v^16^g4}Q"TAp)5 [mc'K㟒ڑ֬G*^Eivm)wvV&#uu*f .W7O&ZV2(OE,݋&5G`|H k8>aQ,?2TD_o1Efk>4Sg E\P^ۤC&85YChHkoU NHR;ځyz U;y0)5M>_LCFLˣ+KάiUg˛?F87sC)vlwi*K©7oLd`\FC< eFY`[^J,e0ùy'^ែD?{0 "pҝ=4vZih(&C;HRO'Xŝ?aOc}@bMaEh1[qWW@P Pκt"Ѫ~jOϠcwBg?یK@ܾ,V7״`Jd'3^yO2gb5Yd. eY͈,)oMFЄ'ޒ8 š)TLqsYX{R^|iXeԽAJsmF-/MU"f!+ཪNGV0?2 %#e85ft],c M3[ шg+X((҈[d%i/a" 6K7~{HXzhd.2v)3aND5 ڧg(нL^j㙉9.S*W٨ ʶKBsK@I}YS}-yƻN~>!!qϘLIW:G?3mʷh%]=jD3C2[|XoؘBVp}H%dxiOgo }AFIxK|" r.Kb!l;c/p!8 !ԋHҖ̙n! ϓ/۔ R ԋo@/z%]uNcVٺH,_ɤ[tنD'cX|fzcӡ+Qƫ m2j"@X(Q'.l1]]a3~Q3>J1sX!PvٻGj"90UX_{s7|7-}N[.68 Q<^Sœn.[yV<,u@նB}eVAKጢz+:;}(4bDZLTߌhe@Y:9xŹkw,m;sy){H.fDH:&#HGhy>4tŧc9e>O~r!漰.BQ 5~;R6_~tbk/M]`98)ʑoCLD~n4۴2`/#0ڧήf'v[:Kǔ&‰٣Q{[*7cŮNC@ 5f/ ip,޿#&,VOŃgQ Ҷ'X#uM_U"^o\ $ڍU,%c妈4t\6K(& U*She-dc^:RL!p/ˏ6TGD|$P74۬; /\R0l^LrT3Kirn UCxCc(uVC F6B }گ6Uq]엛]Ζrs͚IDW=Pl~Rb0N6y$'Zj}Yi~YR2Dg/ rCBZO? \R0~"l1TG  2J8tM(4L{+.Ӝv+̂cR!" U=iǷ,ubrK:M].uQ Q]#pu>ް,o d]TjF¹Ӛ:^6Y. z,.f>&␘MGHE,wYĖʩ-x.@s̀Yݶh#"G#Z2n_!*8^ Kg*^fO4}79*~κ(PVu91tB7vu, Xj4٣ !ԭ 0pͷ=IiЦ2`F*WC&7OY%ؠqY~뛚;"R)D٨}|aohL68XnܕUjg^3[s2)̫| 7Q(OobsOF扃фzstwS!lTsięb碮טGoSNcv|hͦ5>p==n%H5XfK O /)zu@j;1*^0f&wG8,9"7UУWD*&!S8&?Hµ 43lrzd^ldI$Z}+۸7_V1H|- @5p-]UD_yAxޖqr֜(jwv "qrpvTË{T@x<#@TDrQ$h~W /5䮋Vd4\֌V35zygZZYe݃2 sg810¨_uŚcgCghLxTA9K%( _jyF*լ" b"C|YdG 0Q/jZ7p&{\t{ʋ<< wPqAU6oz|RjbfSAR,-jqN6ګFw$,n>htK2 |]E֘ DxvlJ_ ċ@l\ؼpIlP/ 5Ph:6ͳyp4ܤ(f; fxbV, RcUޓ| bRx{TpLefoRx"bw$0V}LgA'K im>0ڳmH_WIJ[ꗍsQ:wN#& #o6l^cfcwxݴ0/Z^`9,{sy$HZiۤRhJR3K2&G%]ѥJ {9_N(4o1sl vwćO{c]m]3dH/\)F1nat%Ӆb?>Q8bǸ^Alt:T%Mm8Ox jT~g9P}nяc\֌[KD+d$s9Qs. ReD?q~ߌZ:cL;JC59ϊ վy=l>ܦ פZh6f`?JK1-<_q$ͻNDs,N~HF N'E57]sZ!) '`RYl^#r乘!.gHinW]n@yِP<9rcM<ΰR䢴dE*Y߰ ϜZ#zI6[kSÄ[Id3yc:,dE&VU F;jTyɄe5Q}_FSj+0g KcQvhZbD}8y,Ll@l4c|֥Ǐ"D#Ԣ=Hܚ.k "=Yӛ$]lHYT3Wl}֯C,Y•n@!zF6 Y !Di&&S iԿOoA cl,a!]h~\q#%2ec3 @CB^>g vvWX9w@jB|BMɅe%yɤQ١iA|v١Nc/w3t~no^ P&vh pC_AXVlD)R'9ERλ?(N@\oZ-"2-M5'9Yѕ/*R`z1ZiT&@ٛi!i;YOrT;h'ٛꋖzoV=F{1X=$ҫ g;D5?EΡE<$rJo ,ݶqvbh秽px{z,5(G^:,P_U_}x: dB6鞾 ڎ-D]~Otע̺WȢ97V Џ)V&l0Ēӻ?Q!DH-r,nLpye$ҴՉPliy`UMd `r ʹk}9`(JSxI:=&6_EΈ- g߆-8\\"= ZwO̲e!gXi{m;NJ߂! )Nzn@+JhCƼ!HYњ+mr{Lwa#\vQ=V-%Ӝzl}𯺌M+a9lds _:[Hhc@R %,v) ;pmv BX4-mFc&#X@@jz[%*b4эFĴ'ȞHyɐEk_~LZjj0~O5,ҭ" BFUjaVPF NH&{nWE=8B 9rW"Ⴑ]6k!@EYňCQ<)ۦm\z O[_wl]0| "Ij}:ksTbIG֮̀x ccBYQsh suMΥ+TH-f߷<[уՠwhwjd/Gp9ҤqS[׳#Nl~2~u[7J>uQAٹSX*rtds?#5 'TQ-辏j&}{Mr]bۚ'~bk0͡B FMq"C~XDA l~^`h5>10X@fkc;!Sנw @L#;)^Ь@p&h kJ΁q;%'Fш7fBͬ#iWͣ\C<_--5}{O< V\.5?)4 BC*a^Onśvne:'A⯹&iܘiMaT)cϖeԭN9<-@qf)C_S}#2I _ R,Cz~W[N9ңUع ̲[om<|\1,Yʜk2G84SS3.;@EsQd>\Ǐ=H.-cIb?15r) $|UPMt,(J/0IWgoVp?|ߦN_Dƨ[5٧^ Z``S>] 4WC'y6Qbz q3B xq}-rɟf% Nng"Z>Q5ǔ54 ]ZwC4Ity/O%BH7#U%d%POϪK 2<,ܝ{7F8/d5nw6)34QO?ٶ`,}J鑌J 8ALv :s++ +crA \ ,^!WAi*頁FPnaN{pU^OAE;(۠Bf^ ggrJgbuP* ˙0~yN ;I$HGmoذ@^!7I@sQg0KۢS&3_ ' " 51e/ 4ktIy//k͗ L1SM6Sl Cn)|=Pp27f(3u(U* Ljoڰ:"K\U@5'wr؍OzѬqrА>":KZ8Tll̵<F4.z]c6aݥ̖`eS.@^/WHhϨ^Q:#IhH5/!ʍ@a! ~ĕf^  zhHxH,Arۓ eI| ~>yƃ*B)&37?fZpEøٝk=NJOw][\UPO̠GV T(Eԥ;Ktn>!$cf,F͑fsq(#(,-YF{4Ny?'VpLE[k-dž` VS+>Ċ.qp"`:-5DSB2|PϞxW=ggRIzAk#EGd롁|*a132)--X:pP$G0ȴ`iCdq+$rh=oY4~a=ъ5 !C|>D)hb\Z2H$?i "VH{]f޿%%Utdt2cq¢yy!{Fz+N卌^Aj+>[P/V`:f_Ye^WѠcGcV^ՕP23J9'a}kAtT=DEqbNIVFdg<%Yc%ߎI8NLwب3򯷭CCF1f/'BJyI29g4ELbZ7 QrfM0V`$4!iBnS "4%|o-&1A7&Dq%% G'wU $@ B1 OWfD$,DXx/` }h"0ښ tVDxkͫȧص)WcS+LRHAߘ UBg_xݴ3Hĥ%F}$Dv˪nI3rKo%N|dyU$$k8~Dt\ŸtY蛫tt\UjofD7$l$Aބj$i\cĔ[oG#ܖUNAD8e}8,)M,9m3,ҸPE"Î"/f8s&hU|hfJuA_"x7͹Y1@Ga+>&i^=F% /j4a{OsUWHA =dwC(<~BM+*Tce7CSNgN [80F$)-vB8q?4s'-" P+qW$5;wDbO 7ⶶ"hQ@DuoO6E `nxghaRy\/v xTU*(owZSIs* u_Q6.Snn3ǏBl!+DLI"24#_'xΊjS0=[l'V~KJIVY.Sieңz*PJ HT}\8U&-c [|fR*nܜ tP )O#DE@<[A":T3yj 32[zU2>)亓cb@?6:gEF9wfmy?Kq^r @Q@u{*E~TU7Yn3O8g ݪA8 kьN6BNHgm9X^ax&b95޼zWO @8I鱘VF1bg//YJ˙kH< <2"I(`zD|WoZ].#=V) C*"Uـ-fGHz}[ z$Z>ukt{X}~d}|V<\bCnpX Hc FoO dYޕ bwT>aHLSr ߸j`%cq[F tT-d2jp#r: %+#%zOm99zқ^BM_/i4#uO>ű~Pv +H4e%T ;iȔ ~ÚP0κ%.COZ&1Z+OZ>wc&KB0 IwٲFI_yP6ɓi[K.EkVÂO7$gYh EEZFb FÎR40/lN16,"%ݩnx5?clBUKҪ4wjub_[NBJ Fn@pq~:-zF$GҸQ3 p;**(Xrp~+e=Y,b~nΛ*@Iֽxliif*mkX{Dr{7ƴykb@*Qla:R&sɔU5L ?Ej!2VTBm_+fgtƘ;. -R!y0̺"pN9,}uЊXd`%8[,GB] / A":6=hScixߡ.[O2av4C'墤eqY4"NiNxl(>؝QP|5كB@ewJ&pڹR77JhÁ: u%9 (t)Ff 9uJdfvА CB[v=^U19%2@>VZ<"h}wAGا4 8ccAx2^L HiWLT: hDö9\z`nX0 9#YMnd;ǽ/ӲnsPM1(7vuyA[b=aFTW>Ok T"/>{vP$-0.m8 *DJ-nz\}1p)ГP7vebS -X2B L} Ö--<5 &Bzx"1OC% $a:C%TtE UۿӢ?7>-JK3l׼ |=f9~ Ƨ u2EM~Pl|&=nC.*Yq>ޥҘL3dRHoo_ms.&2YmP]oM49un#?nm>BX̷CW lGngEne6J̣N.큘Bqm@,t9`|?3Eя5ˍhcW$lXw\KA|Hu"0i -C$ vKYqF9ٚ ٳXsT2ZDwd&|=yj&4eAeNK&{$U{uzsqN7sb^0FB4)t+9.)(^Fq{lM"3Tj@^]݋Аs蟛WW{r-Λk 5¤%ñY]>oix(F9Ѐ*̞+:,,RmU!hxNL ڢʹEԯdOhYal6=f>%qEI,KX'FGs68@Vt†Ldomxj] >;QT's& gP&b1]Y 0swPi|:7ը0{؀:_rJ3L7CBuG%3h|Y R(H`yKOD$xz ̀֗&۾RAR[g/$wik7j3Aԧm9n}}\xF6'商=؏#5%ք:eq?5%C:Ipa2= *;$bfiUpUx>ZнHWv%Jyr!sXJg7ҕoS/q^s:K#+?G!9BJУq@? N'*O1틊uooSEch"gN6i@_ŻQ0z 3ٙ%]db 霽'Ir;t^dCC1?uk7N])bWW*8 {2@`'A sރYN*p 闲u;;RӋRPlZE)n~qM1Lb4y@-l= 3iKF<ce·eTMąd㽐o'r~ޱz_\/;i #ؓQMC?R\r]>/ݟv/$ -lQpgy+ƈuj̐8Ԭu'xr{ő)8yO5 ɸqN%jAF4X&й߬AlVpN?(_ $Z;x(MNw33Z`}Bxz=&A)mg|O}cC4ưyn Gpwxy~̝]G)}j\'az]>u9wbL4-2~X`dWjZ֧zӢvD*u=i.a6mPrb80쵓iw8lF{̓NVYűuk~YqdPWyDsO1| PN?x*@TftQw}fJk}D[<\.:ܸ'Q 7h![CsoĄ =XP9ݽQI=g̿wK $cnwa]*B{x^. .hDZ2vlbf|ʡ_Tq{% O~ނGNnbk:SvQXe@V2!-x/͹۽L FDT?*[1 psQ ye43Jmkd4a.ՌI/`01%`YCtVD.pXZhLZ+;Motu'@ɍ݌"b. <:õ"&IچQNC, +&N+yOLt6!զbѽxmtdEj00j"tWnp`-~d^;0B S -^J N@eßs[g.m0ݏ%B4B R2_)(*rZaFN*p"vQ$93= ZخiV .,oVUhkɲTH+ѸJLՂ3rI:,]LAy'}q:!2;"29s&M3SCWީp܄X%W30`1GUs8? C<l9M/%{ߓ+lmlÁyp*t8d@s1򍩉+ IcLd2݆d0Wc5)ьS|]^ DOQ~yr::Wg$W\NJ;PV7.y`@AwT˰ fst4N"Rc&nB݆Vm>ĚRAϓ6iDI̘2x %sYl'EZc'lD~&RKmGxaeػ^ bp1tq%c8k!sdEz~_[Q 2uoiZEG"IAe0yB8|7o/Qovܻl#\ņE@~`\FqUVΆ4rNij y=NL1Zyjx+}J~*b@rV!g&:$X7WNҥ{͹OoߠUO&HV$Ke q* 5+VC Gõ3KV+]~`@6ZCÜ'LHyR O-eSU:#SMPd08Of~7f\̘_0!g:{/zNVX@i0g7 `\OyW0te64 b ܇DW{-‹xnuLQE/ԳELR249t WQNtN`3 ! XwYf>KuIs{7,imz]%2~&>7Ϧ9g:ȋ{|߳`ܵ@s>Fu}QׯV*Q230Aôn5O'Vw).II~Xc"]{x6 A`FYⴖwᾚiA?wհ$(ᅵJ.׉#Oz'm{ߜtP!GI#b*;7??j^>:;꬙"[X$#]Z`Yy8yɤ"ceq.G'Uvxح"'kt}'fpQ AL5oJx eˎ,׭,3ŧVh5pwT.‹&"9)cvpstFBIM} ET9y׫N 8n׏Wpf+R '&{GgM :뇽.)6Xlu3^^MIɢXE׹< dr^bujs9ZJ`pp vp?=ǃ٬[ GA=$DOf3& ;fl$S3a2;P#>-!8*@.+E *7fjxۚ}=+s!EM2Dh:! **~v"TV] sÔ`_yȑ!ž2 \R};ۓPq<4qd,XY@` JrJBy⢿Ў}ohf'q^̡ H^v!Wv7RDl9qrPLώWuYkr>aU,t[@E7=xFO{^/I[h:~*!:E*ō׊N&Fsc UٵZ4dහCa(og(Ҙ=5]8 'qXNMSv/őb Ӏ.& )xw  H[N3꺀C_|+Ǣd%4$$wvI lo%JTTd_^=891ʢRX5ys+ >DT-o,(!\3W[~!14( 7$.P=iq Ll~"0i'V͵ίJ$/ZgkS͓> h?XXG!<ԓ0޼ANuZ&Liw N (ݣPYG֧뚽MCm@9fזeW5A-6sEINn5uGsې{bՇ<K:^Jɤ֭g"Bmw[E/r0.?_DF?hRQ iiL2JȩF0Q+h)5̮ٗXlaue;:Y,~xoj;hVNA5D|AL X'w%zR.8v}0]$%eMho4Q9Fz"b0_H=5 :gQK[y TphUֱ Dui͖7u i]mԼCu({Y zs|McPUp;m7Hj ٜJǶ6Ab@Z;޲闱0фEG5q)2s6^u`>31ܫ& zD6aS(k8煉[ѕd1艠t=` |fj÷K]w'○HbJo,W-$+gSۼ h+~tUBPsw`B!Lp~ Z3}sAoG 7=tNɞ$8蹖ds?WD0ȇi \ZٴcK%̫Pym\ZBEˉ 41<7;/}N=M.,M~U^<V w5_Xy( NX $`lKo]/'SufFk]k~1{wh!a?ZJiD (|`O)fg<PoթM9:+ v@e$$"bVUԓ7eAirhj0"LʒLs55H m;Ptaa{ _ tY5- bz{GJjT;0[*fZrUBAAՐ1؀ aqیជTjVp Nj/ɘ0bx~G1rjԄ K{ؘļ EDPZ+e3'ԨC.xvG¬:-yЬ& $j⩻0/ꔟF6Vaz f3l׏Ks?Rq(ZY 7B#M?\O;brV;1y"^am_4}'-}ԒVsp N`oћzd5Fz/c5y쁙/Q 9>r }skBc <qJ{JkS0HAQq$ :U p:ƕ.#Vu.cQG:$e+\b ^rԜ`?σeE'pvt+ֲ%7=@9< kdsCthN)ۥ_^z6}~4LCCǪ ğ󩫇,rg3ZW>VZh)gk=emxO20xN$_3Dч%%Jm+w嗻q~_C $V(fkVU;rqB[CjH4=]2o  Fn+H,6ՠvSQ{;|vZtXB6&?['}[ߒR/Č .>.N,5LCE릡z;NB 8;{yC~~;BF{wbʹ~mG! Ȓ'p~aKj6c ^f*Bt, Ëݽ`&KiRՔT]D?Z(5M=\"xf'=7,fBєW4ױh"O|x k5n 7s94v}Ւ"$._A>,G,L8Bs|$h!Jdq-ߢ"Bg_0= O/Ą+!o(4l ,}jd]):MF&觶oK0tww?8mq-kG!06۩KM%#+Q6}/FŐo*l_c`9Y0O}H{r2Nc>Z2I(T'q;:&nswq@* 1\Џ>p]vIkgdH(]ޥ5!Vy vIm~phD!H?&֋IG7r&a_e`CT#nV5A-CkY_P ulF70}?0|aWe܂!MKۨFU4fnEp4@Kn!K#DΏ*pA 7gַy6HrO%i j)n{ҷ[fLe Xؔy/ص_-B= 5 s Z 0׌?0^]ހ3.(U%.exLXM/JlyLnTfvîY LƆ9(RǠ|YfQuY>XvRmv9"eDVtuwBvwE T0 h yXZPʧ:jю!^(T㬤E̍οyKʽ헯YoRwyP4ߓT5dЯEqAѺNNW`ܥ9 {5W'|<ȼ4P'HWZQ»"'SGuX*,rF.G7q6?;Brͤv]tҝV$vk;F_:܏+սH0c+v:T@``ݴ{n< asui pu2y]-DNawl*ّodEPET ªMޚ\Gyh~,'}T%HUhgfvf2C̭oZ&MOѴxR=+ݒ(6"ń&9MF~ 7uGJ_tC '(Jwe V" Ed"|~O\#NpuY[$o;ד#ClRmvYFqH!]$MxT|#CfjecvWb.Jq'y = 鱯`3 I_|ݳEYc5QmBA)\}փqA R6{kz d]RC gl 'A^_u=r@rDxbPDI~Y7S_|žf6D:/ZA´{R6eEHbOP.W: '[:Uc}Kw)Y ]Gy ^Pp?&,j'ZiqT|?Mց`*C8ZhWGz~tMKA%7GFe)jNyl P)jSguubuA8ɲlZ שF K37$USf:ac/ rDJ6bf2-a4j P%*?G"=׋ë܆t]KG֨wIBI FytoaF/&[۫o@_z[Ivrdd*V^4g&no } ,җRy6tRۯN`׎Sˠ-S|UV/̸h|7CǪWlo#Z3=5u/B;~wP>+bh cn_lgTɥ1T[;=zTsgEQ7J8bb-9mqU4ÏFMe eG,{EjViҊ.?Qҏ6ӿ4;;,ʮHiTj\ԥRPW,UMrzBK&(Pf_ BUGNj=!YhYQ7 :s-@qfcl?υƨ Yۍyg'N~mtPZ ZMFs1`z?y%>dA˗W&uq7TΐHMpF__Fg聨vNF.P8ޣ>qV?B$ZIt݋T(djՓb4 cGDfIC=e 4LI]YSNzQvЃ.`ӃFz۽Z' /+$wyH lORKҞ6frHf#]a(TkP w?{ͳ2`򱉕mxUz 23}8g׾4mK=U+%hT{yoUXc[lj ;|^fE0[px+ȇ!sk?Q:,1Pe=Ѕ8ܯ?`# $=JI< C9+4?֬SޟA,uks\,IkԠ8,Qkn:.`&!7%490mU8ϥ^;qeffxJR)9 g䧖rV$4SS`x?8i,hX_jи'%p>^]….6Ҽw4R^(OgCGlEfHm*tUz| 8{c HWyAyd@*h#)Hj`]/ksÇ7b3#YOHm\] 'HJ&A G?#bf-B|dOF:pZCu;fu m1 ,XU&€9 PxY8ЊuDM%VxuOng&nc:ָ܊`iR t$y4C+Xn\cGOs+Yapd't-@ǩ'Sz ɠآf}/s*C yyۄJ&Fƚ^B XXΒMNÿ8><N/,|p_T i3q\cf1Hi^Qx WZqAb[u&` cUy8͑vv|uS6\2μXɛhwjstȗ:\p85V[3z%HʤY7tgKc#iOҒI}~&VC4d4$2NAy`5SV=]PiPjХP5itsi=WOO~pѴ|fi)Q0r}fELE&uo,K]|cw BgXTsAD7%hQ? c^Pγɜ GoW6WlSp`wˣj3ۘnMfKlzoj'\4PrԪIᗘraqrܢ|('dx(W@.5{Ld`kb FFi2(ӲWG{ U {1OH"jvY@u1.I742$>~4UW4F,C $z j ]}VEede)-Ԕ3aL:0xD9lD AP4ٿT_h _tV^Ө9 _%CPm"ڰOipf|R| 8`ɫ LY٪=ghnQ{m0 :Leala.]ѶX+3}COK W 42 G/*7\-*.9Ti̸,o@ؙ?L o-I._8] I>S|2KDQ| vq "B0NNy~tg:ŔqfcS&l9Chc> ѐއX%tų.WsZ=&^ ieߙH|N66] 6Kdby1 mM⋑:R@}Ѧ>Ōwayew ;aJJwʟQҤV!+&yk#y^ͱЮuң35l[8N3=a.0|4SL|6ޮJ0PHH[Ζ$N]U IK6Jf1p/(|OQ#D4U(;jwOm*)!,I=WMɮ(~f ^Inj\z(O?ۺnJ"{%yU @9)մFpڅH'L0NВlzܵuL%3᎟,דQYY;S$c #Wi8idtȝS[h?).ht:DfNndQEY#;h|mS.6`rqfu)xG6N!fw'TJdaI|φn lF ȃZQ_NuyFg|ݖr-ZzqK1RyTY Pw>Tc˹~HP$#,l %1!ŅgD4#lU{Z\]ő.j8?,1t/>XnxCHwc2wpSÈRId^2X#+'"OT 89REo@^<מĔKYX**qI|Aհ<' -$vRn9[mU夁3R͉K$=#ٶrlk_:Bo^3? *R"O%<uW`)K ORO:l6M-5ܪv-0,f`s/F%J$տz,G}=f'})Jʒ0X4IYo^xAŒgN5Zaػ%baʒuauհ>D8dXE=yߪ)ZH CgS㋭nS&r^L/a 4zF;K?*~wm}7>3Liu4ߌgĭ]Ju a@jT+]Ó_߈lT/Y:{I;''TDG .G"wmRC/X+DA3h7FC%>3P +L?@_sY+ vRۯ~cXQo_e8w懑ëQ;JJ,-YGoL۹!ժ|6 ΋!E$2ߋn_S3Atb0g\g6jenj0QJ(83"'x+>* pz3Vih0=A`e߮'-69ѹ7;1fJM6 z _]fpu :2ϛ0/9XJ1E+sd 'j3r-%(.aiPt 8Gx!®O9zf7` k)[l鮉h{Bas  >m >O<.^C!ҷ8 $@ a+~sqsf۞ǝhHʢay#91y`pDO|IAzJX8_ KꔪMö7 .4YR/= N SC̅9+û?~$z,6!Ȁp׳=;r1q +R/oȟyqZ"4"KFWUMъ@Vg0c= D, |ηiCt4)C=˅<ᳵ\Uvgl.$t?b9|Kd9OԚ*//xB}|30w#⭏b YzV%oa|4 Xk@8T=DcD2=6:hADԴQݒ PƜ'ݴ=%4$ 'PƮ`6-g 6 cw}١H9;9 Z=Byu^&K߱6%%f2_@EQ$-gN2B!kRCQǫEYj&[yPXxP]$b'F:-Spt2/g bR3?UR 4g?K Zq碢" KmO:"d僁M}K[g(P`cBgsȸ'YUcCvǾ,H"dD@丘*0VֶXv䙺{h Ws$QeNbHٰOKdjGd5Ռ #}hED"jZ(cGP( 6|ة`x hlXP%rP\ƚG,4v`:q%#^ 1`7`)Y+`|:Q}*D@=2a7Zg%!CcYO?3ds`dւh,!?w<C2:ct)R 1(w-DުȫV`隿j.-)b`k:T}iP@CFZV'O芨~̾N+΋O,`Bq[(|ϩS t4A͖k3Nr6fۮsڱ%Yj;Q5HRILs\n`H5h/riЪ8P{ɇKy}urb7=с--"a."t4qxcE6J϶=wH{ I* {Qy[ a3(g\rG.\tL9m4SԕW&]9k0ՈNh&16sPu\.m+ "GT3JPWاA,IKMΪ _L|ƺ&~h%Y:F?ЈEFl_YEu/RWpQ?4|"@sJN`BA0y.̀R~K{NX=(.?kxb,+_XkKj9p |xܶϗ5!<LزN}iw<z̧>2hT47dE@Rb JT{Zb˦A/bV! >sLzҗ{흸B4Ckp+M!&E@[iwC𦜫 &d {dXJHi~"Έɝ~F-n4P.RW^sQ{:֤7%>kjȲO+x^iA+6lܧh3K$ЌVᜍqlB ƽ1 tɶ|[DCgQJ8kȧZh»i_Tul[kfO|uhy1Zl]gѻ"47] HNpW*&U*H [L٪6 IP>KTf\V?gK+i&FV xNT6e "@yӖc$Aq;lpQ@˚7ȯel[df4 M mƥTTP~z<`k)ڟQ pHQw6?4W۝]QE'oBp_O ^>+=t"c [ m؋(8'@CV@Ae6PwC*aBײfXC=Jʁq$#T;MէKCCry:.mϙ^Heốw#H~*3ePgf\H)DfJQC]TE~kHF\/[ Z)ͯ&.Ϊr"@?_j+}b-]C wf`XL`ԙ3M-9ī C:wh JTV37g2@4:}sY+teR2 Qo6?xiTg%G'/'Nª{+⹾;+E'qĥVoZ%ϭ@bld$3 BRg'9vVɀ`}h૞!U7wض+US2VB/3NEF,nz=F G86毓9mTSC@U?p%xzuozq{xds' MloV=d/,Gba$*vt1Luez_I2NJφ`j8*ESȋ81蚯4fFEy`ʉz&g]l@9TLk#>A/ =ܢ4jo p(ԮI|dc 跈m@p[OatRz5Z8Ƚŀƹj3higzC=ck.  k_MW+tlMU*@%1DNKf{W)iI 3&f_7"ièO#F1" k[R?+R7E]NjVY5_a҆FtVP]Zyl3[׏iwk6CeJ]{#8=D67wՊU D8m_$1Z3ҌNǓRV/$!x&Z:0I sM7[:qJ:WcdS ިLh2O> l1Jl ںe9o1mg#sfkʁ@Jl1sfvd`HL6uE K!Fi),M!g% -$a2xґ0b|FQCD:_Kq}J8@PmJ$5K7©_MCIBۻ7>u 31!鴓N5%vIT# \߆Y\NI\W@ ?YS~dWFB:O<]NaCjb2DվS3^.#ǹۅ3{Qp`PҾ0UPCg"K n^sr$+Y5Óe"`>(\g91FQ˺(캮^/9R$ ;VDR-Ӿ+Jiq۬Zœ40oPu^Χ ߻U|ɰ$Yѻ:j 6NRn7uu #6?59Iе٫䧽Z u85l Xt8Z2N\ .7V[Qۥ5aeV# ݬ `yk^g!|~g)XxZbÖ cF~lvK?2*y<0.|o zN6WiB,N)P9wrulօaW'MaP+G-H7O7&6rHdr;ErPyjv8NX'1ۚt%;?j)_sNN,G 3=- Or4}̇͞^BY&MiuZŖz> /dY @tЙXa9YC'cX5|yVv"mܰi)߅)w,Z}d4dO>}9RNhݹ 3HFN7jaa]c?r.-p聍  &(/d1RH~t=O)9pCVZT~xIoaر?@s1< Q(P9Ɂ^_10zP9jCs.Jќa7p핦9f_?$x㱙[K. bZ|Ō/ H-pdnUzy1+>tz2TiJe_lrA|KY%xU{KБ8@<!?E C\َ!߇DEC/6^If5X;/c49ONؾ4Xǁ%s׈r;DcIǯVG/j@@^眓W/% Vk Zo?_xPPW"\F?@"#~.zn5w~#nI:" q2;PsvѶ[DxўXPN9֢w=n8nN2?ܢ (s_Gݕ؞Q5L2$SGq#1ֲg&p;?z`-ݗ",Xl0ЊXr8ZpE#sV$5Yل(b3t-p2㮑YB<.pƝ\p@V)s 0Æv`P|c/ahq=$!h4/.D է~"ᯍ3jXs#e_;XۿzGگ} zMCNQsɀW$fQnBEOg8S؅Hak@ '}l Ēưr+xAv_/ZKL@d-\pnR_&8h˅^kɻӭt_aphy j-]etC9@϶*ӏyA]Vf~*= {NO~-}]\N }K]RcMK2P= Zz⌡c_pUT8O4\2j%9sq7g%/$^lL=Idx<k Df8חf;w[5eEa{V~'sz?-i;AA2}AQ`[76J/gNX FL˯Sl/S싉1VBg\zċ&f* ,Ux o?!&g4-`ajGΑ>=vJ;w|W_Vl&CFR}dqTq, zh.L#x53;f |#ðQSI'׊?j8C^QU.1Jێ*xC]-y4\C^ufRɸ ,1% zɷ@d ? …ڰrgm,Q@ DWP8$-:>ytŎuTFBMwƹ5 ڳq9Ӝ݁Y 03oW2#O%Ύ-DIK7\i[O^L׼vn§\"ߡQ݂ߛJ^i5;Dg-T V0gzzX QK%۩̃iMzUNhA"[nHڡ R!>O8uF;FYJ-)DDۈu~$tB>o<{N'(cax5r1^R[Kp4n9=p?0E?4.3 ,\Sdط=`+{:ߔ0x{avuKZZ{$Tcn9ݚ׀Ь֜ϭL I/(('MޙӬdɷ8oMp?j3v2ܙ`3}M2JUtV bX B8a+Vs*bqZ%7VǼ/M_aM ߿XRqJܸf{ބKpǾpB\^,hHHii+QΫpXӊ g bW 0Aė 0y1,pҊyX̊ 5y7/C+<7JrJsc$d/ZO12~7!Ui0ZYJ…;_-;[h'mV1 q-DKXg@J>5ߤ)o"h&-Nj H)ْ9-U c~N8Eu,EPPae5 _NS>kx#P]ȥZs#jև(a G@ũfk?p8f~:???͑C<>$=끩]7RKM&w]ÌUxTen2Mbsb{U<[ҫ?ZRl4>qeck epL-QFX??ؤg%A.mc$1ow)K\-g޻q]KyCʸE13ngg)2ğ|aT;HߐXmcQMGS 9lEc-m*&+ \v2ywu[ceXlye\c ؾ[blRtLgڻFS֍HeCJ7\||1*4Nß;"2Mxl 7sZMڬK @!qkI--#~A] ?:&Nx⮄<[W*Q+c`wp%D23Jw:7j7(b+S 9\hb0%C_V $d^DÐ=,( R,`MG7M2{ uցa}v LBH&r $cp#1BehѲr{ye= t,[m\Z.Wl:cKڼTZJDjA?yu:i>p;*eIBiBM삵J<! ٛd+w{Vjw2:S޵<;M= S 3sha)Mj`}F9 Ld)K٣/xz$;4c1kEN2cꞬkiw(2mf3i0T\,Iy,*t/E/J:&O6z,<"q0pDLMU*?slsc0ߐ !$5DfAdl)5"eU*$^3FT0۱XOCRKd. $ OwB(UI4?Fz`nL&hG,BWcaG3Kxl `-h)Gɰr- }[yNqZ H,0?Ge(tK@P.AŞOk9C\r쮵WHC-w{WA]֔x2+yY1dPe5#AJ̯PqF&/؍ZuJn}jscSG-'LhFqڼl '>žM="g |q`M̀@, org:M A~0z^>6̡= ANL!92{so΀;nMO:긘dm:"I@~p&gѤc`fWCfߗsP2v7RPMe}׳A,esM4W|襫eg_|銕 ^d. v/ܢ <˄;3Wʟ$Of ~u8.䗪~ۑP '?rL U@?A.ŁIܪ0|>ӯvP0oTjG$RkZZM*0hN{2~dvcfYFuQB"#*.9}xK>m|\0S{+`h9viÉW]с ;wRˋ595*ģeaSH1ngqT4ã3G:l 朐X4b.P2xm4Mz?7 8/H.*>^졘(7?eo\`᭷f78y꜄T"@XCF&njezb3Kk'* ~},x$9KW+qV+%,y]e:P bT& ?~mIF8m|h$o}`2S~=iQrn 0tYy Yj]1Y4FƋūJO+DL$8Y2Hl٦{O( EFn2a{}ti-KdL`22W- $BLTꔍ/gm&J]ג߿l4\aʎ vJ9q%}ZLhCдJsOV?rBC'pi^N?ػyxZ JEyY$yZL}I)9^r+:Wp,{ݘ YyX@{MucVqN>`9ͤkycc$uXo}({֔zj:=ٜ]K\^AOR<*83[X&`L.X۶+pu2h }?bj+&m+U!w_z5uK2qLF~pոDkHs1F {lU}~Ɍ+ ӉSU^ bvL?D`un4@/uK`\kdr{nk =N NU6pd{!JJ9,ETo1 rl>3՟B۱B]I)Qg (oec"B*l` ,u:Va bzl/״T0X@$lv>yFU pO"h>؂jW^f{r##L"W# ~{ݜHSwRЖPՃ7XY 8>.jY;A~LL)O.w ;NJs"].Fp]AhC,-JF4:=#myNj {E+T FHj=>1)}a{XlHJMrZJ 4cIt{*؛so@m$8xKIա}{N#<ʎ B>\%@z{R#ZQ/LJi%$>ȹHg:bMj +mto(Ҁي/JA7e,7"`$. A8U#TxnVZ8p@`zj:)n)i[t1 a^iz@*im>rf'eQw Y:o`K,md{u)Y_Cnd.%9Btj0?iHkDJ C1D\>{ӜLgR@qTf|7I= JˠcT FкP24%9j}A<~3~s2~:c/" It!U#e]ޘxǯ:u~1B᳂,jٟwf(;0i-l\cCQ %1tHp5;= 4NphȢIKqy'qڬlLLxNV&3/0[34^=D o"LU=L9- ʖ[G΀8ݘOڄr]j5hDf,XY=d@*8;2SRHPg؁.LQv ȀV?e5 [fפv*h ? UJFvC(*]襟iHnd=Wz peHd%F^yӖԡ`ɹ嚑Db8)_@GkzK0Y5%R*Vc؛S1ʕRZtթDY)-KrW\"(rV$GuDb`;X$_N? C9*ETǢ:),O!H*<>Ds=BGC ?B:n *t5ܶxzoVcN%T˩2+!}0¢mf{ŕd>Hdw $_ 8RZ>)S5j8k%.eJ(LnMѳ箜XYvЧw> vC\bVhW(&T(}!֊J-2{ekmONG=>XDVR=|6.?PG$7Th:Բ |Ƈ$7ڸKc~&GPA!t~'Bq1/qM3J[A.3V:$ɣ[ScL^bsKԇ蚉 5]\$?yQ+\ߞyCv H[ɋ"J{)X tw;Ԓն_dY#ތb^\Sv}3/LS(V$Ȅu@T#nQNuwe8?c,}l 6s|//h9ŵY=kq#[b`ؗ$5W#>j,K]J$KQhc2N!!Xw[)4%u_y9?8K]r5c騅ЋZΎz2=Qۃ^kZЩ3l}=a*r9$['"g-lKζ&C{BL$hZJjk[avWQO+ޮB1N_0 >.U,+mdP>|*K^a'5%'Hp N|BU0/!x<,ďGqd /x^?BjVE*C5lV )ܿesɔgk`H rUalEFKZ~€,)kqvOTp&z[ : " P8NRS$g<D|ؿe%VzS R鴋VrZ*]8L41XAX?YKF!/ /@k]`įXn~Gz/y}Wj5pМ*>!0n凇7*fh[0|wZ_;ZM׃xAW )~?Q܁b#k xP|3.s>#KJ*؍% D1rM:weM%Nt>6@VD؀d£wnj9PZpC 0,(>q,xQܻ;YGR yAwZܛW!qD/|+aK;"爌 |ؿ qSADM>Ŵ<;&j=CB S€ G`2CUQ*cu) J[ocr1=wq y" SDLBto{Ƒg ~(m3C O:1t"%H7=ܣ, ~n)4{֐ X/ǂ>o7bƍt?8L;G*x'_#k u5X"OO60!YR[>#mU$`,J7p2:W[H赮:(" Aɡ#;Pܖ]ԲtlRpb"ZY C:`.([:>9 d[ؚA|ߤkv0 "k.9}@앙/(p{tWh6N rbe_iG)?SQ_JBfN^*G#M=ʑZ}8Egw^u5|B@CjڐEU񸉑@(1 X]Jj r7;tMBDݔ)c礫;ζf%CKAԌ/BB MSa'\-xX%Q)Ďj`Ό"vRuG8C/i!BU4bdVaьF#\%{\DYJn _V]"\QL4faY?͕CbX@ۖIK c?@hڕ?ux+ 5QߚbkbABwws(p T%6%ě3kE؇T:_=(j7tͩT*w.`'ϻ%؋\Yqi򦼑s] `"_4++a)y.''|xέ#l}^1H5w[)^h Ⱥ~CY$yn7atn )LzGM/  ؜LB`3u\&ű@#;qcp5\`;ߧ?oz/5|H*E;貺1ͽt}4NѰ½N2?KK;#Ut5ފqF2* 7`ʯĥ|1x*/ sIp+;zc%%-^1k~}w^jQQԎlDN%׸NJ Kwɐ{Cc ?4$lЀZJ*7&sqg#)I}eĶچ}dĚ'.)ٙдQyދy廟4"(5Z ).Xl]x|FʦFx@XOwl "X@[&\-E$k`#6`#(j6ex&b@Fgt5Nqn~jjŃ=)fqfss=όR 1TES#y7s;xob@9wxP7u)//^ xL#ϗƲW]6O<1"C) OF񱑗t­=!]o8A#$)R,ֆX..?pDI`=c׊Ë+db-07=ۯдi͌:V+ &}L$!1P$+O'Y['cؑResK3Ҿ-=/Z,v0Ľb vL4s KLŽa:Md D?jʿk۹5as 8yBL Hyэ%*) Wn ݠ,ux?W}"ވ6XGc7x:"k@FC4aZ| ؟3B=A9 9@{,w!Jsv: Z/?6t^_!$Cg4ZQ V@k+|Rn;vRS"0#FD"DZkť  q3[LhDf:)2&*4~$_?9z"Zl(>X#(+Q>W#6f#Hp!VH 270 DCjaL)`w;;Iy8ϜD_VN$GIs (omN0 ~f,N8{st|/_LHƎ٤,EAIEN0lv`S_'o?O<ۨ\,  D:Fb#`AjƸĆqInEhmŏ`t!c]EU\@G=sGϨu-7\i ۚ^:k ƺW\;0r%oȼBjLIkڞHvCNHGϴT0!hkOS_1|{ˮlL/)|'xQ$EIX/LM#ق3@1cR = IouO LŤ=_](tesE0z|#lx9VSF@&E!Μ5D@Ch?IֲekW~j\==wMGBK^NXMԢ+/2*K2/5晎pXb:Ys?ڋ`*0"ARȴ_ȉ #W6K?cĢ|&hi~jN:F.^XO[7`9nxU},KKAUUa6:Ԫpy6 3X]:C&'r/I+@eGwf]J0qP=vqv`PaҤvKW1L$ 5iw <c`úڋpok7Cb>B+Ԟ7 wL*Reu 'il3z6PFcεՅDR-3r},]V{pHeóQq1J62j hT:|\-'f 0-=mF@gp+ݬNs5EIZ ,giGbjpZ55fQj ?d '0׮Pׄ^QLw$98Ï]Uz6|L  x~މQZ^"}\NI3h_>st꜐'^'hs:lYWb?bfVx.3/#`Z$`afjc,ؾ ,tFx?(txЯSލР͹?0*5M=׷!cVC Y@jZ%UŠlt$b¥@;vzjt1f*y%΂XOfѰ UBUҠjFBP=F3~ ޟ8Ip7>耔tP}lͩ[+ѮT,E'!upA7 BĴOjyoО<H L"v|% isԘivS|f50Kd%ByB)yI:N"N*Vn;s y܏{T7ɫd=$0gi[TErWCήڏq/DlE%;_'߂UpnjPH|0Uu`Ag*AQ.?N8c0U $>QmV3[;cK9ଟ=HC82p[Ԅ|M>q+ˎ畒T3Wgۼ_T@,Xx |7^'¡4E:x*5ɪ `O _GLtm rF{i:}z NYV/jsn\\ Qи5T~KM5)SVV|7{K]a\jRaK5G!ᆏo1170*];pʃhecXg\w6wJm(+|"NnRΊQه5q:0瀴f֑]?S75L PCxClq8m1zwz@ ku\cX&qձTulxa}Dk'hIIUU`;Ҟ~W -u"%-%ZƧkJ˗0ޮQ.Q3B jeI/wS7+_<lKy,= ч!Uș.A-)hp:6:8kZG'>FF0$2͢h's4[PJWS8+8%Tު+nLɔ ~w~c:Lt`F{Yv}п\[zM yObF)6ӡwCv4q \F8p067 \ٻxd> k׋Eï%Pa̛t[<.vZ1䑼Ts2^I[EƹLfoȃ/6^hoHG~l6){5eieC> =c2E. jحV 1{_h,7(h50[W0 iMnBbW1J#w GdFJoSIױ 2F ~d/yQ%y{:t޹Pj'6S,|9djwW"o5utl|`f߳JzIe*V HgTq\ԗ1dȞOo>(]MN#$Uz]m3/g\ 2[-oqJ{(W!P ,5: cz)_ﻹem(P҇2cu~w"'ZaCƇDhd g 6+Ʀb?|$5F6(,Rd5gD36qoos 4?u!L?J! >-8TrN5=b>ܨ\I*3GGx5;tO_~6DrXY)fq 0Uj3 )Q ܲiu~ Zevs= #Lj+MtJ zqyP-Zj#e: Y􇁯fv[fVS"v@8Vw@+ku3Jen wB3tuTHEWW`lVY t]^n?\{?~zU(,zφׂSPYy-v K{ Oڵ)I8 wѱ>frX46jpu8]8#\EO6_ CS8gg aJTHB{5˖ȸɿ~3˟5tb:]v?:KҰK~)ŠVTq|!vjb}D(ʵ,A_ A8 ܛچE0g|!:U .,gObHj hIJp7Ye>Lgk*R%h͏喉}k(8Gxՙ"e'Z_~8B&( +SjlyC h.ݎf[*@X_8,۵9hQhgrYpϩ_N>Z|Kg :3:t IA]ه8&omSY02FSinnmr[E/żR0 -$RKy==Yj!RIO G NR֘Ňb J=zbi߾m";]>]8 WZh \b0ܴ1aߪ-:&b9όy9@1OCsgM NO"}ċGeZq _wv3K85=>W4J*֭GKJWJYO,k՞7ԛI4b0Hg-9/`aMkDݼy),# 1aL+5'%4Fn&&8aJwXf~6 ،$?N׷ ByUD%45Cu,T "6}$% Xk=i u+MJ6}>-FwĊldxlIab5B.RX2 -pL k(^C`xpK'S!Ĺ궩@wEXݗ'厁pB=kIve75:>JcURS]"_ oXKXpGV|l*wۤ'4 Zd^l gama8;PCAV B7yCH#Tz&F?%ۘh㼾J)0>Ch2&'"ؼkgW}) N|5jh#Qc *"OQO(_/:*$gkz;6?|TV¼'XA65ScDuNдNV!5G@+z)7X1bL?AYAkRg贬WY9]'W}tCre i'ѩQlYjЋpwU*(OQt^(4m?7P o83̓V}j]bَr$O[տ=Na퓟 $Ξv kw'PV#7Y9l7tm"|Uq ꟅJSF3;NzVTW8Fu& \zb[Q 4`&h&8 kѻNq7qsN7{P#CCV"wx0We7+A^~^vso/[Aq13-S;R/b%G2|X~D/\yuxiJnHVџeRA4PWN!$+d:Q؎u;LB̛zVGsmuU̓#|P/fp3$/PdL"˲Bk%d˚" TOS:,Cc>'N ,-^MmHirʨbRiU 7y:L,rh<@`6?ɍګNӑH 5 >CpGc1~)HuiQU0f2 }8$z%!WۂZul#hW vm>zL1ypmbP!jRIB[[ܠ*.jD pF2T< AAM)?BijPMs&=y^lxcD~/w## Q8yxPXV~rȱ_E<ͭ+ΫԩsԢj1hD!؀ &?mΖ:GsYO'بN^()s~G#=' 15M&āJ23os6m\eʲK'bRfH⡴Yގ"O=!pݍ/ej\m8q?]N6(/O 6A.$yeJG`PRJKn΍1Zڛo=c/g+ '@d,x1Zdxjd$IB'-.d8%8p#-|lXNM}6 sVO{ ~+A0yKcu]wCEtj4*oqͅ]#`R9Q 5H.r +#BVAGX*l]\pf6Զ<FA qTuH@K2nɡ_2Cɒ^ @a^ABw_D+F3HFY^>7_9a+0x!3+M SYCuOA)FN[W>8.8#[y(쀼j7aC0M=Bwlj' %L@;*\>`"\:ŤzxJ_{jLJ9ƛ)* gAtmNw^FpRa>@wH WhUyة14`~|6G ۰+j% kb;&5%%kX%LxHPλZ}=ع+d1!p\#9E*i9 2A]EMsNE;E"m"(TÕ\67xNEџBW><2j`kxUJ!#$gHO[Jg6# E\ `l=\7R6Q;Wm?hO-UR-,3 _Fl9}xU,4_RrCNP={4i3ۇ Q 0I1<̡F!!;r%O}8%mN7Ow-8p=ƀ3@jk]}7n39v˷`oH`ZI7l+ȋF\&`y@/=s8(]( K w\?uѭz \l^܍ .uCOκ%6\9VG?47 9qvG^c0q 6QSVš6%]/E˖%zBBOڒHV'\WʹEҖ<,,}=x{k=#.A;h1Dl~*} j k *{?9Ќ}]CBZ * alE@"-\PQ~t-LcMPysr˼8-]yDs1Fv{dS.򘀯Ȼ MϐCwWh} k*ZzS g#n[R􅽒G[]4*%EpI1`HSꢠŜ$_!xf S}E")^pU!7`FnƝeʵrLV[w]%&E^+F.!+=v>nlVQkC|wr1ۧ/*~HU<TCu/塵hU룍”+br?AmsM<- ӭ.JN6-FgϜ*JUGEو_.ħK^$3oǞ$>ڤcxt|!E-z&OZ#Į-kmwY"5Xw *zMOr,~ޡKgRJ38$vM9<4z-nj6mf4Ug,2%4:?u.'!ʹx2p3G 5+1#jP O &hDq9 Um'Sʐ 89Ѕ,'` u]`l+S%r?w-HY.}%}WKi?]U׬0 *^bUam΄N ũbho Tp {)}2մl0 _ٝȷN*b#%1M7s7eTk.r#\ c2* @;b'L@*A.R1vw;;];yEx?7v:`5ZݶTZKڑY t˥t`3 v.Pc꟧ =s9{F!a{40Shщrf]LB^T%&9zN?̫Z\“_WwX{V5'r[qcKRa9})i/*󸞓;X:;}%rN.倓G] g+EDk`a/! AvI61hZ?Iz )xP׃_.1 R_j8մp_d2ȭ%pʁ^ZőgB4!JfѨBe?K@2Eٷ]N(u~DZ ^hhƠSw-mS(sN/J8FWI*\Y̳UBXHm_.bL:q4L/Ⳗm/\$1RN5_|I6 yjrx."=ƇlYPC¡ǯ bE=`Vg4_^ n*\gۖ>9(}{@@ImPBƃ- C?5xsoXwAѵm#1k&O S @![1o!.A/ Hg!?݌g ޴GCb P{X-oWEusѵm+`d: 5EkvWMSC-3iJ!VGz;-5ȓBY-}1]\aNJAJ Ƅ(^ˬ뜵>s/PqvG7EN uv$z#8X垓cSIJ \H qNyQDtYQϱ7Ϻ{-U|24KFսmfΏv}dC4Vi=5zTݰ45=>:h1x"0_7ћ8#͌ f-7L;,0ʓ NI&B{M&^oxaưt'Ԡ ss-aTd8OWwsf!r B=U=G6%ҟb5F6b[y86ۃw'~#:wͿ3w.Vf*c~$Xvt 5˲Eaa {Kl{(HӐQJא#PƠF9ulLCcԴ^_xzM[ ox u,9t@((7"ոaG/ hYR^IAL7 AH <'Bp|ٯiY((JE ƋplSĪRْ.N@` ɜ!00W~[MT rDC5v|ia9r:פ5~2@D(JwGI]ZP0ʾ_}EXo}`Mse(h&:NgmQ'^pT#R- (6ǯeFTx[1Y1HGKy첱|5>Kr@|y{bcx_ﺬ,pPadUɕ?wδð^$h͔̭Yt`0"JO:)&jà$,N(8)>eK.?Fᩕ郉>D!KeĻ"7܁^xZ-WV;aT` ^_ ٻNE#. T1=[ Hfr 42_w@.Xjù!Us\I\H/P?pg`|UzE118($l#0h; nϣ}rDWk bQ$oM=8AWàl9/9\] a'౭n6$*W/:F nդer'qw/ 8(kש.!|uu\Z+C19/e5f1)@bXY:?RP5o`ht+w_RZPL};OMI/kEx(/WO1_Ć/vY4b19f7_ !/<(&`S,U0L81*Av"G1)Օ-$FFa ґ۶I9Ld?!+"Suكz4 nV!wےCc|}ju&aGy,`n-6}ɵ ~̣\@"W)%=k7>h y׺&~_D| I:-V?qIQK0o|,LMSrJn=Rn9IMNL`Q7⭣|ᙃXhk^Zf"_{gLNeJltyF]8[r63mz[jmNZ JjW8e # ǔQsSbOH )9^æ{'"ezC|`&Ss26[J^R'*Ou:9mW9.,.f0 vQжMCsM@Nq{aZiHpWֈ&.d⏚*,e̤e=Am(u(F_ qF@Lu.;Zɶ/>| 9DGDe _𰍜]$Ow$߫Cif˫)[ j/ۥC= Mlm_NgjXF*גLlHEDqyj5g-iH+<v|+1Twalo4{`+K%?"Zdq0+LH$7&7U|i wB.u$:^ex·_H(T)@.fsJR$ :=nSS52~cEA,z?C+^hQM7_kh$g6C 8X(eQٻ@%t{T:JWCvPwmiFQ5vVDu豛mTF%t+YDt\1}mvEY8x B,;$Lnj^LG*0Hc>O!AMXrTy>+9Iy\];|m* V[vc$9t2H飩;/?JgaГ[Di#p*8? ڐ!oKD4[A@b0zce\ xZg3 >-opky`bY5eŧa\FQ ?` @~Jvk7AǨȴ esi 4WJtrSjlI[32vx+6 \;Fx̬Yb18`=j~exePi>bWbGO^Md'ޡo wc'N ToŖѮk9^OeZj|)Q3pngFMQ)<H>dL^Q"Fcȣ|:jTrb/(kaԦqNY|-=9רA_C#~6Nru5rDuۚĞP":^6MP>AI/ޙOCtЯҶ$``#Q}P!fZ]Bh_M{~ANH";OATK|E>̼,NP}IJEԶ8,m¼=HtϻcP+< w6+OܥtfHJ)?b -@wSmu<=߈ l)i)PJ|L Khـ o^ & SqXn,>Psе)/3~$ ~mtIro(rTaJA>p  翍f*Ljj!!vehomLl<tUS]rfh ]qޢ *Po ةpYToΔ kB0Ն=cK1; [RVZAWo@Wn Ofu͆cOh7|81"PI.g N@yC 7;p{=BgB2pBԜq;bas)jd d)WߑѶqEi ?gheA,ظI- se,/q ASxMb.EmĄ=",br Z9znөrjohLTӀ0>|W+¦ֻl eJ \iq6rWeUT4}B7Xpҳ2RD(-wW3>1ŏfnG}L}U L@rs/ծ.njx WK-)Ys(0b8PGEnҧgQ9_*2ruLߨ^d0j|o4 OS܂,|VPp>ɒ i s[i`N$6}#FDH%dM_&hx*0NţF31u+-j/R:B~5o/ØP>%[9vtbOg֩Vj ^ 6G#[Vx &O/CK-xF6$`yonʋ!i8!Y%O/k/'9*KE>_-0&#+/sb:©baʤ-X:XYbf|}`\42#l}`YgNy=MC>bpwTa0d[]ɒפ &lv)@:9IΝ`AU'gd L.dbqvgP!{ >?\9En.7E(VQJi{onPjnD^<=eDa}"pi=gVAb.˭c_d#):H.A'y@'ԗEI(wϐF(^:k '}\FA̠1I8!=l|6jX-̨MN,}ﭟ`Qrȋ'|Ժ+jNP 郕K13[ˏqc:!ߋ"hY˟}%rueJtmkgF-jMDpOv1ӹ~CJ@t՚*F}~U x -MeM3Ix?*C{W~_Q08O&0Q}.6xB <5) _$H%HCX>[ UiQa9 m99*f4Pشv%pH-KhlDD|O*zL_9eU4Ðkay73;{7dYңja~}ӏ2''zB$*i֣2:~`Co>-2G]iajޢU8g̞46aN2}=b6&I#]2XMFWgoԁ{4 ZyvQ˹?dr.wnp Z~y.bQ򕴍zr=mΥ!TCk7JQbAG2ck1q؍S` c߂W#$w>I$ᩔvG9AێH!z4-"\Nli 3*tH].z`tmGuQucjc.T=fPJ_'dSneK8un׃*DkR(aoP݅i7l(45%fM~7SaR]r_>M`2O +/ޙ:I ̓>~_VFPT ġxLs2$4m#׋c6kR?I5/NwenJ%D: i\8u7;+DN3XMoZ.70nHz>f/}Esz< 38g:5+DY&s!xh!vԜH|lK.aQF.jTCzB޸-zRMz]Ո\BKuCM{>m) aHwwK`jox Qآ}lv-Ԍw({RJgkc$WH)hdm}6}U>ƐOosG.͜&\_(]w;T v,VARL (0=@гYyz9cUo18t\\_Wy29xP؅*6L\ 8`F5j(1 ŰTD[\ *RrRFL2JZĩZ9-rym=~P\2:t[O"σ+H ^͠7CZ(McC\?MY-#;I+Z CXR7Ljp!9! =k_laaǕfBqLbt~_؍23p-pH{OIE|WsQau`?~HZHǦ+0+ ("[s`e7e~Σoyc]QH=EB\\mR+EXۺʈ;33ɧ*v戞.oQxsY_U yg aNRnQߕaFjhiZ0tak ?8fVffs'=ّp"m0Q7kEѝө~0b *nAj"\}aQn!VR*/Z`rKgi/(o? ޛl3e0dݱ V+Uq -N'گd_4x0}1,A iIOՁԾ` $H/ßEduiy{&4, Ηn #+ mјd=_Uxa8 r(zSF5l4-Z,%/ݚ"RjWjSƦ8<.Vۀ24D>ίIl=kA)4l8欴#9dC٫BO=FECI-z'nģ)~A$k/ mxyONw:/|F,eJwQe 8 {sϲͺA-i{ }qxwT 65ɺUU+]'\E\BLiu MTPU<2B~ƌR`^Y{2(ֺĭ9:&W-]h_9r v> i `0Q6Q5^t :ɀ.~ZOe!O_P:cai1O+gW˶K8;H6yfo/TS;ހ#ax[)>4tabAT%0ʻSdg|&WȵySKsFQ53Br {^G^:nFt~U$=z̲D;NI ~ΓVELR_uQ; +ERe痧 f]/eSn4m"ȅ\~y.).9*hFA+Y-45=g0K;7dߘIS\>egT- |iq+Uyؘ#t}.i0? 'Wo7xHS3I!Tg>DŪd2Ml)ϽivV&(f@S<56/V= nۺQ"_4E"ٽQHf *n-7FYG?b>!;8R!Œ2yӴ%':#RV^*^=g|ԻVT_+&ڋەDyU+P#,Ei2/^9O_UUCrO^əP5g}7A  E\(t=﫲E(2ݟn>g0S -EM\(D&]7Q%xI'ª۴A,([;|: vu4d=H$u,T.av =⁙X@"גzLK^R' I(9 'O.dq7+EHs3M֏W 4jb׍WS+; kJV&f&ҡX'*؟3o}&7`uP!_[eq+çjBbZҰP1bG: Xr_ ,?hߖmJc`+ 0IdCXr!w(GhvpX[~OldKq=ee=zA+2g!ʼnTTb>'= Wo1JxYE9UA#MEFlZ0PbA\BM)Zh"KB[ 1Ű7Aq_*|Ɲ#/xtr2Vu#S(c3쐾I]1]L؈[4k~Jq`ܵ%w7 2f lHu/cjʌ 4qRbDž6۴G9y"3 ~hchx)gk>^6 PB(AD'_cL-YHT$U*&P65+F`ϴ3dªL ux.ʙko> ;1!$<~[*`-GI5GuO}iPk?8e~fߘ<,۫l՟XMCtUMSZ꠩!\LCV+Pl0];r"_3.{ )Rd GP;ei/\P2r>ܫR-Gˌt *Zmk}"iMHCe,赯xYr\ 448m艢 6rl{y,l0 =c-'* ژ>!:<0\Sx퓧!#!'=bSy){*yID@ yΞ Bya)xR.@R]6 aƻ'7h8m#d EznN 4\ũT^KKk/|؛?_z }pX)y}۹h?Vnw06/OC4A6|B,G,V'~~eM`p\QDePP7}i:hf %QJ7DO7&&,NLĪ[Eϟg4qpDDKs7S"UE) s7*A% SfTѠ2Eݥ([/Dҥ |Rh"&ް-sIդIҴ^Ӽ?x ^= ڏܹȴ#g~i[GA"?i&a1yeeTZ<PM!AͭހH PNy|yLa2LS C_]뱵<[KE6:Pn\.[7A̍ { xU;1JQzY t4sGVNS۾ͼReE|=y0j@1LrQQdCl*4fX;`MעC1>kr-A Lsǣ%ߣ#C-=)3LA3 Ui^)r{3tP8El2kՋq*ǭŤG['V^|YB ? hpd<0ej>z0i.Fnٔ93A!,q #Op@g%Է`EJH8>#UϡvWMbK07="(kzĂL_ғTwҨxQSI0 \m8ŠwlC 4ŭM,dݾN{5 F{t S8x4.ww{z\{-hS gԅI\ļ;Ro5cpθap&-MSG1[\ة,tGֲXh.^v~MI;%ta˃ g$ QDaUs!ø=ӡvx1,fT>x*zSQ;"^kKE@޶i[ $PgːСⳉO:5|wQ_{)pS n[Y=+(_9}E]eq9}{Cݘ9Y;ñd?_ApS?8Ho!$iTLWdsC|şq5 ʾlgC=p َ"6_A?:/<ër̆0SOFЕ#z 3+mS:,7Mw1ݮTNV 9~>9!|!7 /c&p-q(:}[WN2 7,,5Mi / )j/V{Уƅ(!Uo31oFvG~Us8E<F2颈(|tmv4l1<{q aiU2[,c_o%C4̼@t{b=$/C-V")e0i+]%?){Su'%{f9䃟Eی[* ez䆞w8C5%RKABHslÓ`ds%tk8*5#Tr7kLg{5z+ZD9wM?*?WPcvij:BC$E߃lxax 'h LSISI^PxIN'd+`%˅")EYg2.{Mw$4ZI%S' R9)UKVqI'HrM9&vBF01xQ*S]1ps@PX!#GG(ƕ('L@X.$_Ȇ(՛EU*'̃v//<(4;hapK ߴSWSV ]? {֯]sUsxF=9NY]X`RvX<ҍ,>)Kj%A9TޅYʈ1oCuu̙ oKs.0!f?De[6hNIޤe^{7o dO jy2fMH%%$,?S6`j,gvLq]FL5rV2afEa 6y7zL'  ,C.j_!LnHh9qKN?۷c0o6O0swZ4](ކs$:sX%\l ͜5 t@OS1o=tX -Y*ѐF)}B.XGWr]GY{[4j5?mˍ%9tկ*y{dH%G>XbbG oO呫go!7h-m.T}YnA_@c劎Фpñu-@w.F:!_hg =,FsWV}_/2";Y ?[$ K?&|^+lw  4[)* JNT67)ꆖ s6zw͍]-ޭfLUxYZbl/+\b-˔@YeG~Rtg}v6DoL9\ 0ە$+;f2w ӥH13-ȃg KmUѪ W'O!R%s`+5-QJ7g\pV2IY?^ut3wSUl,b*joY7>.k4 DzQHit +6md*k]GkuxsQn60y%6b5*u~AB2]ӕEd{ Z% 6ҋl/зHYw쌡s@n6~?[cxbcsk(K$ȵϨ>6P3:9P-^&\JQ(JYc55]f6r ji_cw8N|٥öܴE-+>_M#υ}cVICu*,~Xcaͱ n ,UԀnBJ/8F*Fi/O@NJmGܖJ8~l݋i/aޱJ>!CԢW+DP  s' Vړ ZO xLq4o⥘ܰM_ŤsZ1eg#٥ fN}>Wȳ{F!\C5{&Qf,Kv>l}!Q CRH;{M0{cRb۰ERNbd *V Ic9"X *€ :O.'?H4AyATWW/-~+鈣 Sx(+HP pexb3gWئdE㦕 _ XT<ݣi9DOgq{{Hzy[* 10 M+yoӲR;S֋-kjWߝ֊A #cq@u e"}g(>95E_=oڼ56@۰@qrӮO?/+ !Iu#RJ-~)VEG Z:B5{/ ڒj@X кYڏov$ye*θ@r'EqUJDKFLKozepEa{|k t 'Ë`jpTj@Hj?B*fG_ԖK3=P}#zPB)mh|TvPL'@}Xr6ۑc >5"̭ob :G88ʦDa>ŋ#zLdNPS cs},HI\0O$ws mո]r"άyViD6us0 œkDdAGarTcլTchHhН89F}/bwpkjKff/}=ˉe8`$m3٧W'1*XMm#Z 8 _U $B$AW^r6k=!Jl&&)f̝wb>wIQVҡBbը\ 6`9QTHE, 'v/6O2"d`Ҷ\)#d,dtsdMV2VV E5>B֟;vTQ[9mOH5cH= H׳~CoڞZV^A7*Sc1fWF(+fJa4,Zmvl;%`A-7 [Ly\^,lN_n](ZGw<!jP^jgUsou,' y0]@?`(VLm-MSůix`)B +d {eW|n_;F:*=`P_W'k!1&1+rq(Pz,}1 w Ou̓Sٰ!`а%.5LR`<<ܮzуdTO:Кuq#5 f]zFV,o/e8!g]PҖJ`pMkdQg//# { v^ӽϊ Be3 ,IѼrlk{jq5= x8)\b~ϔ"D;drY8OGI"UƜsV"zc>|)3ý#l}W IF#3dI"Y rX9a4.*.bzԬ+cRU"UHq2Syފ'qy3m@N8XѲ"JuĿvMOb s+caApFg)>dc 1 e#@ #S$.' 4oEfKrKv]UċYҩ$6*VaÞ Eg2VIqv<hG{Ц: iirbUOjZ:FeXgo>8Zm7QqZf4Z{hDe-4nA/FMO-:3ٗ5*(/, cK:Z˯h3嚸c.hmJnF$HS&Z_q;tH6!) s\_aF@ijβvb ׊}1E! #EsW"Džt qH4G6A TO9vJot^շ*+=k(qJ EP[D.#LmUߤD nʠhp ^[2v:| t}a]IWVq2?fHH7qsw(`LD­+5)?\M|ԚȨ>PDPoR%dfKW  k dg!F7[y,R]U $Lѻ ƕAnhVf~m+9ǴK/0IB;ٞ}>"SSXк˶OZƼbZP];:W% V905mS@v_|g |J1-Tju"1[^?t1:⊒t1nIC(m0qzK;%Rywya1U41eD i#{M+rqՖwS4OCA=w]Uf-A@$ A;( G9Otʈ՛B.퉘6$cA~dW*ETU:Ji&Td4 G~Bu#ob=480aYלu#/-fV% ATܝ[vȏ*c';g/-@%IN}\T|VE}3ݿҩ\eӉ0 5Jmt[;@s[lU@j.OGiߐoX:f[uj("q( Wjxg$V_6bͳjNxްrqLu7uj: B>[ku4${ 7"H#ZLð΋x%>[y̖! ?sSߜaI,Ƨ:(ys\ ,\LPOK ɝޮ}մ?ܩ}!B Q&xȰ"clg!wZ zt`%E<A%C%)ZgEf̎9G `d6f+NݽS+fMTn婓 o!-ŴeIעD9R!BwR\j/E ڒvYĀYpi "+XBSp߾jYY< {:s)DG3w|63zg -MG$͌K.4^}:+(5f5"&ki#&w0%Ĭ!+Ơ3.~;ό10 oˡ0FWP?*R$q?e]o[ӝWfrٶ;WK0IjJܧ!+l`Ux(#cM(UiiieudqNѢ3>Ir{lERϿ;5Ƕ{,S Cr>1(W r1҇jٖ$ȋF h%\-X ^D ߀gB8!ny{:#njMqAmlǛ#OCTd;/gZ.kiFԺuUfEu -L'("NH:闁@sb*3%j!| #MQYJ4$~ $(5t?9؁ ';A@'h}逭$vcG[LҐm&Ry3Ac(sy ^q#|[afR+gd8X32 7~`]Z$&RɾXo a_rS@$9,,6ɦݚFCD}ڙS{zlU ( OV"\-aQeq&M_IKOlol2vZYO,ŠXQ}V"Y ]ɸ{LF+>r*J%^:)lDv.ٜ>N;g0ijđFNǚ ~gsfڂ)Π\ezȿ:[t§D#.Oq}~kي\ߛuZIDƷkbx:^[-}YZ2+JP8|{ QJg cIϪcX ɛ&y%hXGUU/i<85Tx!Z;ҥ( ¡qɜI:a7a_8PGn6vyHJWvb88u/K,9+ zƮTa#^%U $ތֶ2g‹l:$nŽKR)fÜ%MX?J(Z"Y/2SIdwrr9(N!~tP}Nk0EeUs vi*D饛6ڼg]Ko(1ޫp801:w[z[i T9eL")muf2/2]xd;j `fp,ʹ6Y6K`>I"!Uol^ l" N5:OO̭NU"<½%v꣱^ 0ɕq.ڙCxn Ϋ ]F$S%8$:Rd+3F2N6u9D#5񧻾Zo6"j+"MW$i<΂Ah2귵i,u?QY {@7a-25,_Etn[Nd~móc+4o,uu -#[ lQ b(2t`&"($kWM')a,;0)e6؟3eC4@UQ|ńjl?^)~x;q)8.4*cFh;ReŐ3lw:M/pM4$Zn8Y6 #N=8wd6og/A̠/@a,Ͱjju9ۯ0U,@0ɴr+fWhlԕLaO3H`Z7Rԫu?t6SxA8={!H TlfP"*{l*W6_gHj"%M;Rxԃ!Ye>)޹B,cT*HdNxtm 0)_fk/z5|r"<nG-؝䍆yiXPVjhr $:b޼97Kj]orتA@P}r>\Yc?"ʼnG-3'=bv亂5Cyf=7t aXfQU@JlJkBXN(1.ac7qr6˰HTŸFXEJPkS&} P5H`}_INDk8}}_dsGUdق\ p/<ҠP#~ *+.b'3$yW'U/!WJf'ʴ2gʺ'0? P'5w1̘E%hl90`D1H'?uq$B ҍv!B(g;[Kݠ DNO<4ԋ\S(/?++cvTΗyV# \ P:1{Aك 8e "jiBՅ&x{l{܆O?oY3;MG4M5I54v, hQ{pa̝iSWwOR &z=Z曮R6 >)g;4#+uTp l\r.7GeI> 5G=+7xWCD!U[Qe $0/1^dKiQDmS`x OʤOkx_upf0p[;FvH^rbCS(ql;۵7;ǯ7"NSiz碞i.x@cxEL X8aF4ODHg+I eP13vGllch:1IdB:n;|{ ?aǣCU8,Ou9w6GWN?$ \ii:)~1_1`%Kr lԾܮh6 Ch 9;ꦦ"]g].,j75LQ HQ. &imڤ)$ҽ@5 ƛ =,Sn;^ )Smqi Z1> i pтU2YB-4ը 6܂KYQ7`yd1NtNp QA1V*4!ΝCu.9{`~GtLp4٘z$ \#h} sAL/+P\ފ H_+\+2FMk*neR.uV㏷.iGfљw]䶵$^IEZd50UK  isZL E$Nmla D E[zrI;v&V|ɂ/E0&jNVo`@*TW[}Di|D8phb}s6f ?`nCFiЩn#F_"#%DM~ܵg9Pd촸H"wQmKѱCL 8gcO.ڱa"Ow o\PYRLUQ,p)=s˻S䀉*;⠴V9xFIZ-Wlc4 C ph=x' x;=q0y$f,˸qJ)/j捾u{my#[5E8<۲JbҪOP B7zʉ2,+}rpAdCP\Qͅ>D}&z&YJZ ?v1( k}N5G"Ȳ9KESkR3=;n"3:f.[%x=16ΌHI,/e‰*o tgKhdbWf̔bPǺWF23[# p@KiIJEuXWi]w+\t6m $piLgb7<4[*Nja% a(ˆ_z*}k`;soi򟁧 JZ㼨):DÊݸUaC³m䰆hOoI|9LvF1[r^ )T ZqhB z(V?_u(/Ɍ>WD0'7^ǔB;i&T9z6# ^ǔʇu8Ii>Nen钔PJ̤j$2*K`"r x%Ӫ5jY!F$J4lקE<\P㚈OsQ qgLRz睩맋۩ ?6ˣxq5YBw ꓥl܇A( [35"6Rd*;o/jU}!m^E3m{AZ- R w..&ah\p*ezIiS5Jb&Mie`/g1R?GLJ5>U3 X~NA9tIQ+,/i布3-j` Dž$Fג:<ܯ (mL<dkt[LVln"2vbk*&*43@q#3L=8]<ѼMYr{ʋ4\k6 7%n& gY vbm3a,gfs \L;wS&,-n nf C6{ƺq;']hWVZ9`_LqWaF)ruz $2mTSYȰHSGy"f}Fص*xUQڱzu3`|l|6$ZSZe z79d IK5i U΋: eXgK`x#̑uvK yͅ,h{ji%=0L`!A0QﭦuR$SBfFP%>I?O_ 2^LsU*3JЉγHNtS6\yeҶxj]K6aB3nsԁrq;U ʾJq)!IUO+BYf\/HU(#ËEȜ8/>!K,lyƔz ~1_~.6 | ETnfj]mkSNV&8%*{:ۃj?c7邠Ĝf:% , fF'VCx鑶@UHE£X?YO @-VeFʫH (:ٶ ȝH(4~RB;)=TBl2*G0e]SODH^ DDnƾ6~kZU9B95 4lgwn?TjLt|Y)HK[TIbVz*9]A@ ^[PgTAr>8TΗ-Z[ֳ )ͅs67;ݩ0h$ 2, N M ڜz.pޡjڠ5op_1烚пϺ, 5>qr-0!z?W i:$8;CYXF+@!уMTrg  ,꬘p3 BLi옓zӯlz5FvISPX22:1d q*v7{D1$9^@3xZOEo2|?4nyuH|I0IQ ;c"c_LY2{pU-3*51. dGf$Xl%H Ht f1+8`֖tJAsLrXD$yN= ;P^?,iO#@ mY,c,K"Q9PetI餡$]|&k֝[=08WL;ъYn~b\]^Dq&'q )!"ޖCRKy8^1J_ V2аo%SPExdxM\6(`V=(ߕEW6IX&bVBs?2ȪzE͚L&eIF2~)3~Uf&Ec|k@)opx+zykk4zH| V ^)»ؗ``rZJqe"%?=d$MUq(`ʹ7s1XfF\yͦj79-VR9Ow!҅c/ FZURI4FgQSQW ឡtjgmU!FA,%)Dbz=)xߡ֦r0=IV7}'C*aٽ Mܪ~[.pwR 0aHMƢЪq넒Q}Rbrwu< MSuUQ2V⿡?3닍܊@&*!h 0`bzlVYv\%˘-].5&>_!rtäUUpp8@m0Zjl.7~'e:jÞ I^.۬7Gk;~&Xds9T~"kqaߢt&f'"P kw-S(p##iqF: *#%k\9 [i,'4lʬҍ!ub KQиo٭`6<@RxYOj9 #v% +\Ic"eL^̧BY}AfיL6ڱG`(;ŔC`Vosd c d./άuכrK'zA59 DZG)^hHXM )CBMӡ!EtI:悌UI;bˢ}+.^~/h_4-`ݥvD02 8eAmNGlAYQg^hRLlWBLգļ&܀z[=GUm-Wn 6@NE"I~m/Ro툎,.deQQq4(K)W qk :=F K{tk^ux8UJ J{3dNQĴ$??k6jnVƘt#C+'q^>tb=hwd`R6ogPgdW$ Om[C)1bx}3U__)SL7ǶRG$o#XwhwuC'H[O#Q4J&JoB慨GtI?0]:lK,8JW@il  -tt>t3W~f!{x~e׫xS-C߁YF=_dWQ EC!8垿k,%/{IP6Oҭ3J<QƋ0C>.[v`]F 9󤷰5VQMƉ;$c9)vYMfX 6Dɗ'8')'Щ\3*`L%6Js+n^<: QPJK)8U]D9)EՈ`u~RZȟ~$Q$8=M.3e({@4WX&!H]XӞ%C% ?+W:/¸)x8r ̕"i. ; J݋tKdÅ0;b[`h 9[5xhMB3ȡ$n(0BiN|h(\>p|DŽf<V%1 uxx׽X.T>.Pn'tagTi?cAchunr?j5(QWZ(Gr/ә/lo_qSҶ*/ʭ5jm2[ ´]GT'7mgSK~)N粵*@`T KC3(mԣxr]]ej| 7^Mx^%*C# *8lp"/l nk D>pz- mS]Tw楚_`q:Q)0AToCNc1$g Ķ.$hpH5NAkЄ>'nL0& 󿜹pTj$8~*+Ng~S ~`.ׁ~A߀Z@2=',Dg&Q^doDh53CKgH#m.x:s&B ShT;Z̓ai=)Զˑq`t6WN&?[iG+ll#@v'0ֳ-vWdAK Lc &#chC[<ǓOn/o['b H>Ha" r:q#$+ o/%õT=#nhggs5tQ.v 8cʜIazҝZM~*9k9&̬b!g CcE7nl5S)zTKf|D/)M (br"?zĺY>pXmM'ל&nq|!AkM<Ut,sM M kl4.wp(cEX=@g\OkއOA R==wR?r89I SZi7r `Ck:"z=w>PSaZFij 4/gFm?$8 Fvc] ݣ41?̡.jOCTGs*p#LyYHTfZsnz\01q[Y=w&t^uRBTuY4mDHl񐒐r+WT`LpM?hۄ-\ 鯰zqɱkcr*h]Vb" IniB3:g}1?\#CZpsLdv,)n'[gE*D =H1L c ř402R[Uy-@Z5@!^ri`aV/Ɖ%9Y#l!yH0nԫ&B^c Eb9ՊSshO{wXU3is98}:%%=e@'vX3ƓWa)Mt c;\i9`,7|`?Q#Yv1./$9"hD3} D+i `/> :U:2[<e{1́-S9"kC.GpI;n'KTVe3P#rPvSnΔ2ۂȡ1δ^2P4_Y^F=p:InyG\.o(I̴hViX:(!!͂(8_cfV?[|VIL:f J硐*OV{daFw_ŨEt>> mWb|K\C10<}zࣟ D6ńVUޢy-9DOnZF9 G:;CxkgZqYPf،Y[HsMF䆕bh1ܶRv2^찙l["VyYxZ>BB*_{sM+B(PVG6Y}PE{3q"+p! RTWsjeH(-,%MT}J Nm³|Nшt;MOr3Ss;`}? .edH"2f;\(FWR~]J/hw%R}:Tonq +x6ga9ș-Soy|7˟A߅$5_G#Bcu) ޖ[TM׺1*nfLFSY4~c%Yfwdq'&G i(jw .[XP$!ge[#e51ds8& Yn+[]J #UM7R,CJP+b!:*{!duH$1&1w6mTtr{T"f\WNs4zxU0$Zf&X|XXTb!̥Ff2|ԍ:d aI cFW!X-53UW,B4 jl/Oqt5koJPA SBy':lkw;iVP nr5@ޏX \W}%9/Y]wq"4:J"n!+B1Η,l] !Ii F,)#rZ'K'9)ZC]~d[",s T1Eӆ2f$r|U]Xn.] _h0]96isZ (6ayjX[5)0_hBfPY lϒ r=H$}QSWE8tD9}U$#R.?}cE!m%%FfoTysݳ3eR!\c}Uv bz*NVSlEZ?yB$f;բY ;*K0:cB,&e+μBS]5+Z!gf$h O9O/jsz}%{72Ë#+qS%.I*FZT\Z_7Iؑ yXPC?wtKsbļk_3{($/ 1F]¯=sḒ&SҦd^ a# B+q!/yc"'pi XD f@hTty.>;oI/ l+`#`Jr>T+#"f>"O]vkATUjR'Ǔ3)WW2_Fy#^g׮1af/kD-qҹ@,KXIA~3`ϰHKrg->s tnAGN[^4a2G֭Kfۊ2Ӫf ax+bJ*)$=<-Cёrs [=}7ǘeE] #sk) 8eM((wy^:I_ QgNC_jF݊Y4i0,X^s"Z=ee\hFُɴXFb#]Um_Hl:LO T,_Z`g?C5XVnP-;B.o:uW1/0\6?,\MY޳]ʙwauuw ] ޥWgp`!M%eu[%o0k2M5Qp;vҮ]oL;v;fMj_O%gQ߭{v#{zeꞽ-EeO5YOBrz0tNr>a{mEBM1=%B L `l`x^M(SK9W󀝜诂} H+aƍ0 U_CZoA/yAs27B aU4(=:Tߜܡ$Jȵm W # Jaa:,W#'6.ZiwXDFPWҷ|`]0"Sr`eዐ1j7}X>a@pycgm޳f }@ 2IQ@S0t eýFԣ˛pmM[hFCg Ytz#uJ0Ksؽ\1eiWr ft&h9H&Q$,w*,.E}u")cf*WY8oHJϯV$jR$xĠ@p7 Vr;+2v>gF3Hヘ1Aσ7D-@3ڝG2R17S*IAQ xX7J[M_t\vd§ 9 OtS`(Ʋ edd,g݆;U2*N>},u 7*xbw.,V U*|eEXI¦)^-E;?}i7}UǢ YVs;QGSUUc1>y̳r(bEL>5YPQk敀fcz9{չ!UJn^Nq}ڥڶ]:]m~4$2"@n@5!0Piȸaϸ13չԵ x#F%=6M=({)\O3EP$*!FDdj$땊HkM,] z#6h-} Lޠ M_@~SŭSXI^lߝJWj ObzeR˪R_ESM-ie!RhnHun1?^PߞH|̌fyoaæ N$- R'lM^ lR*э=1臂Ϸ1)Ile\+mUWbSK6-bA#GRg]{LS?nȚ[~¸})Jj|~cf xDZI'= ӽ ] # Wu_p$y "wnQIwݴ·$usv@M˗y/%У7/'U`!bu@8i lY .ʬڏduPM1 e|@M|y3G` q !D}D9N\M8m@$}gn{D%U찌*+ 0 o徒I_NI5`zHJNY0+paqMa5.k %Y~dQ@:#荱' :@h2rpS9ù\;S 9wVM,oZ=03'Zcb;TGGA>pApQ ƕ J㾈6$SZPuD,7 \1s>1TYw($Q4nP#ҺL'8X.TgȲ8Ss«R½EDgy9{j9vd\Fi -vQhZ;S[+qѐԭY2C\\N)aE"-@{WKWep}ЙQg۔aĉ d+_˓=^}b5^لVWWXҨ)rq4c*`TmBkKnma-S/sˇ#fL-ְM6Y 2T?g(ܡ-?“mu5qvK˾`dϥ 5*:D=DQ@oA .1q!PN0]"o:ORhSRۡ"NU cͯb\$m.)P9߇tVrJ뼀vHH1l="sU$NzN)ע6Ӵi mV? =v<="f?!qɖ2< ;>a4~^{>~ȫʎ$E%2 RSdV%GpolѪ7zR*N;ߦYE(ʢ`fƗI Һ$߶ғ툿JDh` $K1P5S+^D`?@>H 1Ϥx=]X'Gs&Pg~}8 Un^H1T%Z.0⟘<ȇU2RhB[.PQG;C[__W.4g8 WAʻB:.T̝mC2bz^h< k"m&8 1tTc]_L09_9N] .J.Z# AgCӾ޻~DꆂבAOHVyQA)ɆQLCn*X4Nݑݗ]_=X,`:aK>c}T5L|4Z$797O1ߒ3{% }KrM$$vүu&|ݐ&PJv,/Pk`!@AADOI<_ nJ珌AƴjՆX1hJ|{aqǚyeA>oq4l'* s Z7#R 1As % d=/o&^rk4s 6:/b@x毠DuR;q0#%YZ}lC51&?Qb5*ki *)9*İeb!t헹8 \Jbaf+;8'@ukP9S.3]s:XGzOoZyk4wC,N:}$5j$5pQF): {=ی%ofK41^t5nmOnPidފx\GwJctsaX;}VSZAPC.H;K^QV)=;˟?e AQ xZ72Žfj {5+ "GD,lBn e/TCthiiG~x}÷/NZl\g8.QՅ^BLg?o{^m 9GF#,>R(ؔU|3iJy;Yzia5I_d_1.C9Ÿ4S6һ$:z bpV=5t$>`!=E^f rUĘB[,/;OQeNR҅D8C @~l{5g)jN1ep >`e!EwmfaYK01zDžGyjyOMFKqwrTq\ z;~ u~,XQR̓Wۭ']%OG((*U5.^1?]@`<v٩?k\L$}ֆ Vt.!$ _0~Qj {Ry@;@tp\պ~CtAPZ){/Pq6KZSSu}|F᳒VtAϿT.8 r_tj*z<ɛDPq tqL!_ahd+G_QЖ;B[9O*wLZzL*aB V։$Lȅ1ZL nDṲQ-f6^[6aF%Gk+F92 ~/ś $#=k$/掘K-;*,IDVzң^ dX d${ۤh-U29d 5&%Tluslɛ@s;F=4P|Y2ntf#19MLJ[Hok$vU6y/MpR(;Pvާjl]nCZEo43~@d͖CmV2+G=-Zm Bmc859ǀAt\ItNHr>-,6 j6g VsKgTN6jmZ:CBOa\ThlbS,EUfD.Мvbʖ@Eg: ʈc +wVbk2w]l|Zܿcy Q뀮dD5Q\DvAzX͠dBdԋufN EJHTذb䱘8H E{=0i. ո$1̾=DPEmoঞ ?Tm+. a0U6$Nv ZD(̍>tӺ1Jfjڏ4C•0Qks M2TC3:2o0}{-} ,⾏x^6>)E$OA?3b2jڋFM>8T)']'m+B]h75 BRN])Hn'ݰ <+"1$?6$0}B|}r%mxK҅Š~v:tdm0DG!Jh,T<'6_g{:kKŤ"LJйVr`ܨ2l\zϨ> '&)$S\x+&9"P %Ee:/GdIS- &,n_N@mX 6]*j}=jLGTvB` ֎/X4_fKğܔ|x86w v*Ζ Z;B͜!fh.sx5]ā 09^rwtT#` )ڃϑa~=&ZA$jVɟGSv{fPIf WӺ唍f<NbR^(Q[Ln]4w;'m;‘ _ACHS%L}f5,G1kTi%g >0!ˠReku1w(/|wA.KJC>I7fOwRzg.sC@TͰ,c ;O`cyl0/^hPkTK}X*炠]pai0/ȣDjŤ _"qwnJ!uA DoS" ,rܗ's\4檰RAj2xIf#PH@|Xr߶1N7a֛Tl_pe *V~/5Z\\N@XaP݅F9'^zlū+ҠWY9V?q [,Q !pk%Ҕ0/B^e8T=aUZdq%VT:Mqe~<7LG !AR^tضj$eu.fVUy+EԱK3ZEbJA P4ؿkǾ3V>%Z v_SR4ijQw"(RY}oDҙd0XqW) ' =0V_1 aMaٻ@2-Kh.-9ҝON~4},("C5*?}I+P:dcF[gCl{ըJ%xSIHt=!bfk8~K]A/T֍E;Q 7/!p>Or"h*W79nKV?K35>g҂.?r{U{J!Ǫg=?TqZtf܎$ˎLO{:欄{uZnPGh=ٕ@KӬK;i+r`tn'çs5h/?K]j<ӅрJ?m1wr٨$:cZ(ޢ?*L{CtIO˿W[d"=@T[1+9;)P-Zػm>S٠~DSf3 [0zؘyX3|i7ca冋6pXdU gfM֋k>nĢH (脘NO_=kI"m('" [w+bSlRؙ9q7NI-k3X1ҐDntME:}K z)=ٮReO-~sE`DȁޯJ`ZP]}b9ۘmeLIcA{w+rOu݋yVb1|}2=l,( 'Ed {c7ewjzzQ]|jXzwf$ B{,Π|:% `}!Q#w |i2+0A + -GaM+bR@)gO=G1OMmH#,{1<;A?}ĭ,<%uu^#G٬r8}=`83=Dw*#(Q5vqJY{cqmOO{ko#2~rc?ZfG'❼ʃ(B%Hv}͌*ua\F$p>3gldR_XWbn=Ξx5EB\>+QW$΀-¼϶T!U<IKê3dNhrنiPkCwtTSymkjt14FecusՔT JT״x``LC=mq"CGL?abrI~hdj(O#Ud(xfEnnww.Oig1H:*d+,1V3l"}}:v׿O PzCyTzЀ}*7D =Bi=7& *eYf;wM 7'dcKFHD^4{""`2Qzd@2/rNIԙZCFFgƶh:! ֫i*0kZj]C!r MoG Yiߟ V7l@UzK@z~ˣLw/S c]{3~ 3hYW;u}|E A݄ѻjR(mEYKoW F OƢ %nYt~YLX8 F= L|.E ~-W,:{;HYl I ɪ :DmN%J50.+=-!5Obh IkO 춖TOHRn[ s T75PCbfPk} ~NGDKtӹ9_Kx I;(t'M@'(l $83niҬ;fӦWE\l nX9]LՙRL˶܋#>$D鳭iD3+^2BqK(-Ub斮NRv9 oո;hؠxE 9,K /VoiD)?ȫw-fX'G7h]fJ&1hlltsZC`S]]@-.إ$ v g~CL'ƵAO|DwD4ۑ%cLxpx/PURͶS>G׆`ڽ(9g)Qĸ%))6 foW{@Du`y#ep2t]1ӡj gfÐ,t0agm=خ|~p)`"rd&6dᝠh[@<N4![8VV&-}J0P@UASK)2w*uͣ;w?'p9 wYajw\z¶>w>}}h`{!t=F=by]9q Ԕ5Yw-inx(h8Ȏ̬.-!:DnK8]me w2~N d` )u3Ye,)?EϷֹM`"QqЇ8y+<.AeW@iɑ%zsdd#_M aV*|̲r:E_Pjޫ#.@x׈ǰge)#+O1ǵ0W @G5oiGB>QwȞsL ?Έ .lPK}!Ar)`Yo.M+:6S%\jeok?``K6"4FxM۪%ghPUB(ݏ4i A NZW K/^Y$ͫA1_ Wop4ৠ$kT>oIjOj(AiwlS;zuQ[>MMDn\wu$\[@߷ o+|ՅLe 7_9/"W) /3wߚ>Q{7B֏ )iY"igPj꺧f…#M޼rZIKX<Ϩpֽl)XI+-bwIŹ&8YEg^/_10NFK34IStyݩxFBP_a}ICnUSQ*3sy9Euֶ)UKT1AzAu%ܜ8( JvxzPT8ܷ U3Bd[,`1+>S6oStk(]|y,&#F8tFS6, {R[Qø!HGp% źxνB.gk-!Y`i# 10;2%7cuԭ`Wf`sKH>5{1, $3%&{Ϩ9$6g4GO$Fm"\}[i"ܹ8H^_ޢiX:+]XGB^|n`Ff Hgૻ7GM0sD=ʾܢB#mny%Pl{A$H\&O.khyL ީ +9MRH7EH;1POeնNEGSf8 |4"BNj4ZTtLC,Y] uJ.ml:`x|_+|s(d^{8T F FOF<{KuB]Nԛ>yl-@ih1n闪AHH^HE|;*+Wr>%\0c}_q2'W J *^]hi00fG$CKL:%$ YpP՘\w3PBgpƦ=`[uWyda PM'綂 3LN@*(9gvD6Kw@WҋtGXvIg|3I–+pf"*z(YʋA]UUPKbF9tr5N|:1ňӷ0ob&Q*5j@h?D§o]zϝ9Hݚ}VyTRy=/F\t`*hFL''vTx+3 B*@KRMIܱ<iԔBGd3"n0B4xZ74*`6EWڊG8Yl4P$v#2!rW͸Qpfi_ Ln G/Ah"Z~ny_U"t=.nL 2JTXJٌ-_ n70l{*UO̍@^ U# wǦ԰JDv([þ߯|^ WK@?#ӡ )z1;WtX+}C̫p? OR <5[ex.Lksv'be}ẁ*T֦JdЫ:o['K9s^n+eM?)͎?1Q95l*jo$ J rppq.`?vp{)ZKaGV:VTUǖQ=oab<^x]#/<͌7]՚ƱF7kbQsef[vxYy '_~'۶ 吢&Zӈ( 5V8 5r8JE jiItrPJs.@2ѩE)iړv)dO#\,{n^ NRMm="N^ҬMcqջe"?/Tf`zpG5|}"to'ZKjp yWw?n"pWu%=W -|iypgj ^\QAbLVas+7E%jIҤ2(nj;i/ [2X7tDľSqsO򊉷^pЕ?vNy<:$gJX vmްveZ9G.S?\GhQA^s)w$M)+:] }z'C m@댒5cr&!+g8#8pOjvn%H"qtX-RP΄p-D1tj 6$ ?9TZٿmNv!`P4aOPw.j/S{u}L5j Hvûs4"jmyu0RϜ8#xn5ei 1:xY+ԧ) sR%?V" WwNh#8Y::9.st2bx^3I s$4i+ڹh+>Jr{T㢘4Mgmn/g8 =yQcEǛ+mɊ|x]y f!zfEJ Օ? h~אeN&Ӗ@|Q\Kt$;@ JQN֤>jř w*2rO\#c6W8,7 qk_c<2ۣyAҺP&&HZ;&]Rb[Ai }xŕaI;(fjeec,ny?YsA)v)pX_mm\$+Eh Jäׄ/kt9&AS(-k }K*j~;Z133gu# A+'%A^j/&~wQsu8^T63eiڴp ]8*qTItii( ^& Ƽߎ<,:v 9[ᵱ Ԛ"[`_ 4f66_6T%؛g D5Gl|n}`~D`P`T#IQ#TI[]IŶ,H&vk[UmпO:K8'U0g#U y,{nA}#3yDZW4tM5N%")jl.`5V89=I_j :?O 'tT~Nq8a"u a[ưo2bH ANΖ>rlϙ86 1^a͚H5+&Kh?󖤑~C;|TBtaUqpEU]Kq??ga `DAN;ծu桦 sNVnjz 5,Y 8pq}쯙GóװT4;QQ 63ח<ވBN![*żx& "u_ 2!Vj}!tB_v19D&1p^AЕY`R-cyso|wjc?CHȉ*EnWs]C{ov$tzd8f֒=3㡪NT0_q/Eg-a]g&& $ X,5 ɞ idž ]QY /8b f(`MWD eX?*ݣH@ rHRp+UoDJ-%=x>M"i&tJ1DA? L TynZ{v=+sY˴.l8, W+".FK ]˒fIS͌3J@1p$e(wՇ&BsTlO:j9@ȩU2+[0/ "C1 \%I2KR6ہ,=^8mwYi#u 7e7x.S2Ue QBv!6Sڽk|k;atgO ȆF+̈O.SfK^)tgHAɠǩP_Ixgx*=Ρ#ЀZPn T>Q,o]Lu~^UrAΧd=>|s|^Wz3E-juUeKc*=DC}X%[)wI m!c5`-scA>{J}K#B3^˔2I{Ʊ%bcO;_zϵ O6عYT} Zcʤ(gւ0ڿu$ t qaj5.\cwfByÊڡg6;p/:]b3D9雒g[alJeC^GJGdǣ ?ԅ\ &ZF˷̣u B`[lF" 8$TfpZ)â|3W>]ZBrXD7K7#Sn%]2}yJ@]˭‡{|e~юH{n2t=r{R{}y'NA{j#kqd =rSw/] tgPpGrׄ&Dߓkg!:t5 )ZUyja_:d&+^:30;r­ߕ;>fӣGEATu ;VyMȲTTGS65aW^mMhkOՔc!˚QOAgM-ۀE3c q$TyJK؀;KS0fc#p?t>Ewz1F hJh s\RXf5 l3 kxo{ 36!?K\L552@o;W2T u(wv%M8"gޮ1^k P]uk /5Vuc`%WrȂn`V/̂ߘki&lD 3IA5v^$w +u Jħo8WXZB$`;yG-?x@KmxB?6y *qw炋䉋gm6py7x0-~$,35tP 7g˒&RcqZ o0Gi_hi '8I6͍ PUYO*c0@/ː® +ݓf!UMp3jBKB?n*jͰ+MVB5 ,^ƐNS6="'`iw/Tn6f&!X@3crR!#>5c3HnKytAFU8`e.}Hy•9„{u拉F"R\Na.֭`/:[.Pxx]ڧ1qlE[ƌBf&ZcLV[DBhWߛ^^{05ڮv%W ?# c)+7fR-LPށ6 Z2ik0;z'IxU,>'KrY ;ѓmٴVJ3v@_\[ gw2*RUإg t^1ݾes!T`Pr!vCy0jO| EhrcwR."f'"`p[h}&FyͫsƝMfCkLl$CrЃu\ېd"6=zR DUzq_HVQt$+7w̼PS;F" ™SR[5 jo:?]A)jToD̻l$C(_Bl9k 8s_WiRB*l[r: r(S(Pxy]EA;2mW,?c%1`eUO]t0h=AUtiXc`«jm0x IMf|vl9B憔L;G׋.8QLC qy )>jDU܅y,R>B3잢ٟv 0O24^|F?M_~ܽDRv\*8{[ ZFړw(8Ցx'% .ED6C,55Ptw2nmKՑד3{~eq|l(8Gӏ!\źN m짯MJcV<,dXKᅹ[x:=Q  Nf"K_g׊Ǖ3OxkA!tsWE:X#ث?1+?K%]?O?S0p}sE"H`<RPP*\‰;UYw^0;/wPFi4CyyZ6?2h6Ƴ CwA=˴ }HT ڣ毚{__^JMː5@+ͯ gW JܞjLcR΍+qWH9fgTGVXY"vW?t܀ !'#<ޡ BP?sG3v),r9?_+@uA-s7'e7B%/ u8R`kvzY0N^qiUZ8ZU`pȠKnv8Ͱ- X`{n(a5TSuYWH1| 0%8F>Q-yތ%yX̐2LY/*Na@*v@{ʆM¦ >0"7xNԵMW|n\S1fP!cު}u 3j58&}qz'Mj5vߧW! n>"`s<Vh b*[ СV9܄l=o$'s `bEG>pTpoOG~'ZWSj(]qW)pG#b11ߍ:.nRsOf90SG>K+jmŬtxɟ(xBoI3vC#j( ӣ(eA[dëRfJɊ6Jpg*O={UoI@C+=F߄JgLg7{^A,7~pƏ,s\z`;(8n;_N d`reJ+9%S ;C _Tm_]D>sc72 QrgX5>z; j!\ý5M0B,9NvPf@bcA`"lkAz\üT!(D_9RMՉ&g(Piwb &B D=nЈ0ﳍ,Ѷe+h([E&d, NrO 9ϥ5gzUC{=j5wxEd:Əg Riߘ *d6Ð@MUHM϶;d%`7.(E_VhSei CExxէ;%a1'ާ%NLz'#-| "ՓFPk$n;4@,EqMr,XC,rѺ*$uP,rgZj#叕Em]s@jNQG% ,>QX" k)Ps5?ګm,;e_;~h|HP cL۴Ù&)"!2j;sVghμ *"{#?OC`>dbqK Xێ8_hes![fYջPc֓r4B_C$QP-FЧw0kn]=Mlhj0z4p0%=#xB֟&^,4bg3}]ȄU]q-j0\E( 3]4ۮMخ\އː0^ѐ6ǽZK ڊw^qD Vٖ[i$Lr cagѥÎs1R׼! ab*9j'6icʌ嵞2ԣmT.qHs*$%>6ZQ (got|6uF}-kBݍb}OxJAĩ)w@ηJH}h8],dkDVc?;zU jdSA,ͽE{j$pPE˼6ȃbLcIT.=|uxLmGob 0D~YA>8yŲGk~u©RX,ʞN7JN34CC/*:Vmp+@A41Z /n0J,;߂MUFzhND!.JsRD++q5r6=W2p\b5~=Vgղy4OjAVʈ~ac_?Y6,"n1G辅N:jM^-K ~~, Ӷ-ۼ\1TzGUKa {'"^uZě1. [Իˍ y @PPx _F+$s=y#d&>)|6{gr^A`͈ezPq# 6- ڍ@RՄC@Q$N3A0T"׫Y##\lQh)zjd#Uܠ)%N7:?QOd`.-hIQC%U$7Z Mథ-NPEv"|JSx6+lKA9Vd2^VL(eި >c cj}u .JgóŞmsmmй@)9G vNݵԙZ"a?CtW|vܪG~K 'Q~㬂8Gy`{Kp6wv_lR|B>wC, t`0~5N`~>"91CPNlr~H&vQãqI D9? 0_vGzhӺT(&c:\wo){Vì4)fu5< Y]Rj8Y;;{ƍWnP%,1)M~t#²b~@CL];ș:Iu=Zdv$OH͡ T&23$3CB#@1?D&urQ8=g^F)qz$E)̓]P}}:,wɈ5y|M-a5{PPPe=X0ާ|\$x~Q<@Iq<%/lpjh HE!=# }iC U_^KR?fكs3/Wj})MU,M?+ O5EK"@u7^r>݀PB*3 &wVxx!~Td" s;0u"8童 Ejbd)y3i EM_M"%h:z4Mj4M~ƴ@2\ qb.2fKgts^(Wxp@S X ܜR^ef >^(NDŽE.2[L2.ci:j##&:Jkp>0; ww῿&6O8Lc!,jR,X(z!veuL x 4q[t&B g- CTY6q+R3~"HΛM TD!yf$X/ܿ ɿ/`Тᒨ3ow9GJ*MqEXn 5sk.~$7X0mbt`4?2PcD_$)y>/;n9҆ԓYci;02hZ 52Yi¬T O$PtFLyE2I, /#w c ()s.VMY^?ZGE9pC*O=M$NWnMNFXfް%]_s-wZfe^qslOX9DDmT%^7md)|VꓘW%( ɧ#tޙFݷYY8ѹţ4Q>fթvUIl.pF絖ZH}.g-$(->&|b5ڟ}*kvm,IDAw|@@T5鑣uZP\!I\UpJz;F~`kBz59![!eKJTӯU(@+:D+w7Ǡ/hrDGwhŸ! ߺPTrН: Lpآ Po7RCRQ/ ]'T~ƤO9vHЙHls6iI~jMEa.a1u(rK+ &7j?G|牨0 9rr}YspE j15w U Dž25bq}\I#no]av.0s{ x]9}mۢWWOs6} VeoQM F0X^S DW*\*b=&vV4\R2ޞ-tZ TqA"iyOjlxP>g׌,{Fj2UڂFWN\r /չK%^]%LBE9`TDՔ#o~h?{FL3OǻM9<(PyM[?DqHAp8&6ūWY,Ћ8Eg7iaLo{h0"ԒwBåqzf3\Yy[{N̪[Wf?6jx`ߌlh wPt#ڞm=#ҷz#6ˋ}?96G"KW"C^#33y-)!Oa/x S? 5HRC^~t3A'NapS$jf^NɎZ!<_i &Goq{|lNt g(d4o2RqJAAPau*O=.-{5v8H1 xd*6ѿi&4!`!nI´w:i2g 4إ,U_B*NW_.q`?.\ϛ R|!ꢠ#jt\|#x'ϐ/6R:u()5|v.*#fފ(!S1 v[Wӽ2s_x0nDևMP'L8/3,PE0qv Jdžbwȱjdr.GR."ח`0 U1ޱ`}DnB0l:D{R)rDP85|+Ѐ͗ -B2?ő"a[6,ki}(A@ 5a!FjG(}b/-Gq_sCX&}pfl$lT 'K!̠Tb@@m,S[Hq1 qs &ή'Huby#bQjt< XBݡs F~>?M}ltvLz>zˢ`a|9/VRoF+# q xE0 j`ʅS"_Pnr&vLRd+bf.(}$N%׿8C`:f!3s۴ayWy]ԶK|N)'ROze`R[,%}}sƳ岣=4[%$]a/uMO;-{x + vDi?GKN(=4ȲkvhC!ݳJxO&Wf\E5kR(ׁ^k,,C|$j͡48s^~P/"F`f1 LJCϟD"Jox 7e<|ЃooØLrLNhWc4Bj/mLDɻukxt*0iYI:szdk~:,v`^hVؔ1NeH~rx.rB.4&d-NYXU3.5O/<ĕCH81,GWH4~ .H6 F94 ?};X亷et R_XvfkzMSN[e?͕hg[i<_/֕OC]ti9%ϑK{l<R#ZxM :ԃŒХ_9Pq6[OUR {Sѭ^|I :r=kVt<t"r6B~jM+J[ ;/8,51hgy0zmO,;G"Ĝ #ZM-4`{S4QydK|*bx1˪!#{z:k4]NFpE0 #ϚM[zm<E O0Éjl$JsXebӿUۇZl*B}G*[-ֆi̴Gȼ9{Dhmad:RP )MTP#*kSՌc:޼m{ ҝa>iyb$֛Э`=3+Ij{h' -HH]dN 2mB sUdLq=bmkOvp@3ƍm7o{7"X_#t5$A z4~7U}GP|W0li% v˯GY0YJ;7[SaZt b$|=leJZ]K7.GN2 ٗGJ|jz1nlpbEV1ჿk8$\r?&MƏPrDǶ0*%6}VgOijR4,}Id"]ኣggyG&Z6yIhPѩHq~t>_&ImDp?ꭉI+'0۰ .~>}>\|s0j3_K]l@_g/Q&]aj2Eu13fDuK7WxM@ -䎵_ /wʜF[07 5p Z4b5O5kچ#&']ARd`Np/3Iya+ NkKǢH^jʇùaԽt*ҪCl|QYBԘUŀngzr(AҭN [8Q^Y軎2RFD@J-"9u9>axG1h:H| TPp.%E#hOJ*,"f|7$y[ş&0i>_H cI\Z5a'̂9;قPvʋsE7J[܃#GRΥ?xwe3un⶚APˮ|RZZ vXjvCSYv Wbv:!}I *ZADFe5y-:XҔF.9}Sy$m=q*Zrߓ6:Ӳ.,r5kt9n 俺j)XՌ7W RZ~w\F@#pַcۄ%goLmy >[G aB!qЭ:׊*}-j=7OKnOCq{,%ү<1#>Ye͋oᣏC7R~dZUT4adqwMDd̓rL<W H4-M2+\CV% ivnΙOH8O~H',>a HߣqJ~#+{x8.y rKt/nh _[9Mp^It=w-O.re,o>63WGKN6hj`Hؓj p2wa681ݛ\Do:6u܋90iy<@\QV!ox31':JXpc{OwS 6]j̐jvN?ǡ:ne { :7MMnR(N_ab ];A(xvDa_Qn;"20kFډBm%z#Ɵ0)`ru5GLPiQGVm$ŗ{]GJceM%Y~]TT` ܘi.)Z~Yܦd5Q{)0ob3 ܼƟeZKs|؎Ҍ'09UAWv-ͭSݵ')`p8j6bNÛV^xc? '6]uH ?킬ޒjo,/Yqu \|$hY pF0ȼnlwPWlQ)r5Oq2'9ڼcŴOro:oQťωb$|-S8t;Zp Nc|×꼰:$c8 2ąkO@X (^y%ثg8[CfL))ߛuԓ)㨳UV ]<Đ+be"y`QM )[٠xc: 8e'=+8<%uPh2 aC3i,S/EbMQ1Qk/&oT^>-M(H .;80UjCN[zDo)R2g) dRGROh4@6k өw"|={:oc< <]E+iU͊-RJ̭Sܯ4\-J>@R֓b44m,‚o-d,u x-/KvvL sa )^SbD\.a./5hbi ut{+<ۑ @L+[*NTYn.H;Z\Qo <*ls"9ׯsտ5StxM9[]KOB'F&`7[tP~ 5WSh[K%&:]I#G#)/*֙'oDy\ۻwF<$I`h'<\%s 7\@H`o XY+ڷ*5;fMBKp~bӮ#`:OEޘy+ BNN&VWQ6Y9sly~CIͫgNE7&ެ_b"#cYP):|}@1?6gowƒACla~ZƈR;ʀ0_|M18ZRϪ2T f$CjZ_ʔk@!yw2dlLqpŌݮ]!ⴷU ^0mvqr`($#sUD7)Uy'h$LxSFphrLD,7@TmT(p Q*ڡ IIJ`L+n+9z60dq6P˥h3& hZI潖KL)~i.N>q6%>.y\DL%ŋk] 0ǽ_%Z|B S4`=J eE{v[]\;Bcx{lޫ=\-u$nEbmm|jOp%G&_'jK<Ŀ;&G3Z5 y}dEzض/X#{v >t)ro"g-\^iРcJzhs~4&t 兦&&(Ƈ i]/l#tyw.؞B8$E Q\7*?Zpe[HSe[aĮh,XΚ$OPtDo!9/.f9i($d% CGKq9}J@lJF2^Q^{1L\Hb0$\pf0͹I(5>f(*_ݶ^` %w0x+]6V5}l,ϰMIjgi7r$DIk #c%l afkϓc ׺sY_y=%$W `CTlV6Tqotwt˙0n8l?R8$hHf# Pu4UC25l_')moH:6 7Ety-ɤh!?$ퟤEFvhOd88Q؜Bn\ pS/=%(% |5 L!4ґQn*X{RUxvUL>7og۽ -ig,ߡD i6N`\J=UT?:+ogm /h1(Ħu"di<ʴWn+G[ANB7u4&C/~fĽU|.DX{vlW \7JVm%fS2 ym/zSx8T3D_2{u|F>Ʌӽݽ gj;+{t,C5p& -iOg7AC KvOʗyiy9d ]iB1o>u;~9xA{y{ח!`i&=-HI)"D NYP3K35g"Fڮ'xP V}#st^!n$#Z-5Mc0Z |bY֢u:?@,LgeS3aޘ4fùva'BB=;K\n w:8"-|ۉm -S_ax6uF]p|yƕ\R%&8W33AERX !* >z.NrLyԝ3 ,[n|z2k@t:FR|;7]ֆ 8&@YAnL[+Bԅ[RЛQܦ-3{0]竍_+ž5dj0 imگƞN%]s`j;/ӛ?e~[b8%@FyeX'y[$K4:\*̸(d3|l% OPL 2fRzG_:_^$GQwIX;NKHv2Ɨ0$lZTot} P 7W*q?/WP,ٟ\ڝ}? s*2 U[/KB)}@S\Cגt2H2YPS~N 1cslֳrcs3<8UKaߘSZHK8)t淮f"sq`X F!m]FCD8oEQVEyfK:7$-ڭ 4 2 vր@xeQ N:fx@EIp2vpg$a'ވ{<0jtRqz/=mw oҡh0j_C-z𼑤˂MTp7%}uQERFNĈڋB×ؙrHz˾Fхqr߾&n̟!)1r3~A3CX-$U{[3$KKPlC -EH`9ȏ6ޗIs?+ <Y$/{/MӖ&J Kc aId܊ߢ jfVGsda-X2Knon^FyE/ac~Aǚh=d˿B>-jعa%t|L}[P7k(Nhk(RR-  P(tc\g +xXӼ!=!RJZ\2(h:)hPY3li!C; D䋔%*,]4xeg^SCytZHl8qzi(=gMƮIaLiUVkXn3Vm-$Z?>OKPմνIrBR3+k,,حmSӱ}JEL )&]Ʊ=eG]{' y F·<^sw|Ut7 f'nl[Y۪65ۺm_<ƍmH9Nzb5 `29 =l0Xi]%CqlKhx2MJRM-)/b;XÛt-F7 2*;">^-TAUS#Ԧi_ #]¾5Sӥ}k|Ef/JmN8ɛuG!fc)oR"|SnWHt&B6W^LHYG4 |ۡJ2ܒ/椆)1;4?+U|6$;` gr9,p35ٚOϺzOuT"P5Rq#b#im^#0KdKW߇ Y9Gޫ]aSĹ;E@ 4 Y҆FO'IJY+C͌dAmfg 7\,|`^y^huMH/T7 E?kɀX0qpNM,dIUF?.礰uUMwa~z!3pV~8HkL,P%2^oys'/0y|9)l`" 7e,x/G>=a_`á&}%&In|LB*9bҁ 4@вMGCf8K̊Z@2}gvpE;.tpU p+&lpMz> $%|Xם\LW">r5"'gVF4Izy4zn2\`wLxIXpdօ]iC*aмO$6!z*nQ൤ v_W(V< ߜH8$1L=DG(oizo&VW>Nq"CUgۈ)ˍS֘38KK>!o#{t}--nXocRMfݭy ;;ƛtܼ@u2>(Hw vS L'J\fS@4 io$0Gϕ%pC1@GeTIه ˵12CFk1{YʛT2v+| } ㄉ; HmAQk!8{(&zэ Y&j()\~E6  \;jiZX\˙d~2*夬v054X;\28sT b=iF:Z׋KV-o%(;@_Yd!-BV15b~#QZn;&[ |;EA Z#*Ф I?X39bQbFxi8{Wyl3(%oc^5~蒛fEc )RMΰ#=cE(O%4HZExE~k˲tm?T Z9Z䤟tj);Tj${iOA瑋1բ̇_/PoNVdo * yev.NxDZ$N|Y#J0@W(Lsse౫-?nIoaL#X@PI<*aW#r*a*M]_װ 6MGU]3 5r_9_ʩu %bD}:@d/Iؿv:$vFHE?ZU|Sϵ /;aG2ht1mBЫ ﮊ@s;S@BJ~\U"_)ofA% })D;$Β&Cu r2!vaXc;\AEO~QE+IX큓nµ͈ft q>]zu l2[؁Ecki?`D>D%{xƗ;yYb:l\7G*5̐jpr PQo.ϼRBWAfx=C^5O+vL ߍUNP[Yx~C 6LWD0w6 ^0A%SP vzL{̍(8*߉(NM덚K̏':b(om=Wv [0Q揚0J(a!u3t^Eff׻u=F#ӓp9BL8\2P e5ł!5 fRl]Mwwи u vC[7XO/T@Z|8w6 L[8yե&bZa!^^PC(6[·A"\O~YUX'W"_~ 2(RXX*?d %D "Ƥ0Hd7n&\ڗD9)]$) s[ shAN aqLxzxRX&"@^@y,7Qy$myqv m8|H!* ]^/KiEҔD^ajV6o(vF3!fp5 ֆ*r̐Q~ ?$լuM&AӾ&^r>01tu^7vd#chs `<-QymFBӊyd ;`V~lvN9PBI7SWA-oWN;Ռ #KH7 _^ TϪ,`[&!=H|ncr(0 ;׶>ޝeKLJ(F8! 05bT] ,6o[$/7=]NugY3I U;ۛtt=0Og=IYD=-L-KJ7oBX~!5?bj[;gTc;ך6=.Wph$IyZsWrZrt{ -M_y.!ӳ"hYP|y-r~9!.NGQ) Rռ9T.V0u.  #$\hr+y}S#T8!"+;$di6F%fAY>OX+uDݥuXPs,z}ɲ&{XQӞy`g㘉!+Y69)+&h: QN! |ATNVܩtnzfB'~ˁGc|^,*m~wzn5H<ڂJXތxll-ԶK Y&ϐJKZxJE9JT6>.߷SxM?ekkʲ|NR[t9pcmoٸ ĺn|q=蜝N&dIm.,}*8T">Z{c#jl, (^%_Gatbg a8s#r He[P_\ /ptWɿ": ǥOˬ~ZnTrkô-uMI*k•B ULIP}"rܦJ~hTA]y-Ui{'53~Eo;TBZ8_Q 5gGRQX& SjF6̡=,Gp>/4F&BLwږ$NOt}ȂN .=heW\>4qdL"%b6,vt[JPOb H% 8օ (2H͂ucPp<ɀT5k[23tVMJ88RA_V<"l4EH7luL0oAw";|>&O8axu8U B{kb2%s[YquWK ge]l >t~I7X:dJnw5: _90|ј. SC* ;sBMF ZJ# 㭸973LO$-PB/~Y wo2Qcv&b@y!"r(w ~մ_l9SY|]4Z҂Oz/=> ɢ܀j1yޖ(R]Tso쏋yvn~֪4sڒ(R?v'Yuq uˢaˉ/.TSKU,br!CD@I(Y/M5R<Ԉd [/uy=m#+rK3OSi,8uGjA4>?%tgh&O׵|Hj.6 (Wݐ|2Dٳln[\;I]l|Nz O"U3,OǐYH^IZ=\kS(xAҜՏizF$LOn2g4аG_Wbw<*&Yjܻ=|]lpWsЩU%"V;K'c-Z٥0YZ ݦ@ft- N:R<1BWN$L{219|!(J6v73g/!9h޷lm#^uu>WWڄ~}?eBY:" bKϱzTκ]XL_wduX Cjve??*yF#BZ|osƙ3뾶&Q\jl㜑mdE)S4n`#UĠAMHo p;(REߞCkH!d2;V]r@V#(qr54͚7i<1 .Ďפoͦݑ Z65l)R:rN.}d$9wC+)>9@~گj:r,Ak kqD׫fԲѰ"7L<尀KAG8چz7ӕd g]Mx#Jr,1lY'e\C4yDK=GҨV`Xes T>lU8ʼnN!N&hm?Ky-|c$s$OoĈ͢>H.cYјnZe"xשUE~F4έ3U,׽ tfvvfXϫRs5~vdefMϐgw9}%!.&2Ȓ^4Mm4%,h&:8n& ;{tJ~D B7keg 8D0%hv*g ЧMF jtdJnP;|au`lY_#jF`Y":]D:5۱+.\Myih7Y$[I0X wӼR<el u48USPr f5~j7e) Bht޳To65pD8}3",8 WLcK?6ϭhOmvC\$tCNpsYm$6KcN $ًyˀ8qF] x9ͷA k^kBs5.NSkkNlʩU4k-(vS鼓=RBtZ~_ ^u.N֏c46/D7MDLϹMI{NgG D>v>vǡ/1cKY @-/KMX ^(ߙ]TSͶ1AqefB[cRgYrs)&&+8]S:jv "OLpvRT4|?7Z OB0Eᒹ9t #9t':_3ճ|@\mfnз.h ۝U`d)YTtۡ#}`.d{ۆ;0D&VD.j}dSjp+ڨzhc|~={x_Zsyzݍ&e6VRݥI=YKSΚōgVC.+K=ޘf 'y[`E[ŏLl|ϷHAo?!QJ CK@Zҗ>sW|)N]2f.*@)uO m硳|Sbl6mdL5zo{os6#DB;w3nY A;2xay F3;X*I ]]|@ZWl̚gǷO>ͤX6t4E u'u׽9-]HnyjYawQ{H)kl (B< J@r M銑M(gpL. #4`bQ—|R sD>d9xxUѼBISZ}t̉s8t3ۯMv?-l; s[(ӲZ6K51y:͉oc,W;N[e*?xLhDR -.\~qo&mV>0L6(򮅿ؿj#%א֎},~K%NSypH> \:ֽ8YLXK ea6f?x~l(:["wvKW\(7zƀ%`҅;EI/rc1D"R]0 I$& #'@uf ;dDTżg,'lxh Kwt ^~,}sm2ۜD}Gkx~ ߃r6_g884͝H=si>]r<)WhQ׿ c.L7dNY83++Wyy>=̎i7@ j&6m[!\3R~ް\=jHKYb"?i5 LalUP! ^|(:;.:%U+ +8t?avl LO!*cZqȑE3<9Q\?mA~1uQRzLKE D-9Μ-T* Zx$3JE1&.k3\>4BR' +Ag8HzjU~fA+}uyJ2zCOW"d;q C }O97^7D:bN'l49Lȵbű)$=pzA>ݟhbH 'u@گuEQƫXyߞJ6#ydJ(HvT+KNe9u]uYtS䈃do15#mבmdys8ؙ( Y}_PЎT22[PMŋ$p߮Uɫ9szoEUOWy&"*4<4yO,A. Hy9Zlζ`O}S>˵"Avg;h5c<4yk(9a5*&Cخ7xLPgWUlf.*"kq`0<E}('p8J^C9)]8wIHXel t 9-r+f5RZ!襐ei`jw%R>,}S5w*ACAGBcJ;N7T*2q{D7-y\t@|yF}߼v"%Tm$iW ;c%d#ÙHm$Ӗ=.i7_}Ҝk@]\)H27RC*:}wN3U@"&R~%ŊC]@<>>xiGGHu$*|#}O { &3vbDBxiAL>g;}='9ܼQ:jx 51-('nNKTo/%qt|.1IZ7P9,4$Y5m^0%oX(HKLJ& gƇ}$֒SiYXG2Ƴ!H-5=9oQcK?I.ٶ!<=V,7AS ۩]QʡɩUnj;=:͝i.Kw4n.w M}eN+_^GtaUt @#3k0/|+U@ ACp.#jkgPw_ ?qH*q/aI2Uμ6Ͽ6*o K<(eyMEQ%.iU  /euCb-:DFjW0fiN㗘dDTZIJ}"ưd.woMkg`_AtbUBmT:fK9U4 lD8DMݓ#񑰸i֕7j A _mC\l{LbP74b7c#&'`/5Eo#0hb)<"UM(cMY 팍`$wd`k3Cd( L3mO%!,~洍 X'|3=*0c6u_oFkLudű/Bmǯ#F9ȑ$ҵ< <]ѪXg7o \gF4$xbc_{!Ҋغ_JxG 4E^;t" !c(A)혭ZR5!iV|=OfSbdZ~Yy/d"d䨿g$6L6ꯥ>t;C:ilj]bfÂ07lS~wIT0ҭƌS`QXdൢw(Ԗ~NJ KN1hn6m_B`Z+b8ˋdej3݄E&9Y+CY*e;p2B$R p$$?Frvrķ9XDx"=4q՚TO'HF(@˲SRrPt^_[d ~J}$ w]m~|i ,в}7S*k![K+,[ۚd߹Kzjck[ EhZE j pL1D"&6R +.:u(x+)NՖ2beMo{\K{cj<^;4-(6QVF rBxUB1Ξ|& zr%MפM  K1nj䶼N +!7EmeT*.ne̺b.h%( +7À1zԵh̷u:dzuNʩZ(=;ޚ!n;Bъv9j%,bU",K2Ϗ\'uVc&{5^k*qx (AhzK,+r-F9B5ԎytD}@@?~׎ruj:C-FS! Wpڀ`-F)Z+rhT3P Oy7(]TZ֑ a݊K:ZHx24ˌuUt2=`Nv}!|2E'֡8d OFܥJՃ R?eڡ>h-:y`<"8x5^S (6 S8Pʵ{`uV8',Qm|1]dnsښGH7< fZ5z080)̸% SyZU=畚}IJVpwBZyti.͵ 5ZxydcPO*_ՍMWvob叛]tҖ͵aA}-lI$Gr3(MƍPTaKv=6XIkd֫$ ~~ʻqO7LCv=z`pu_}—Jh;.E (t"#nH4P܀+>ٝ5xL)h~WMrhEeD5FTBx}t+s'shZpqE{պе^&ע :odzδF3D\df5Yk+~[B߱Estnj_E9bdjw:Ơ;8Q~H!@os&uJ<[KKgO>et:-s,S5q@2"}\=Xq/M{v#xS6e\c8miS6ǫy45Uhi\KJ9c5Z8UR1.D+w ,0՗~ &/xOE}V##6Btvr5Ƅv 8'ē~ۥǯ̚„.噡)Mrݏ@95?+t{[.];F:jb# AjpR=k^@4[8qC>qvۄ:(]rVɣo*b)t-wIL')>KTOd;v~B66RHL^p1mb@jT+̂SpNݾON{/:l^CJc]G즧|ONyfP.ȇʙ%K( y=n}qb5!&p}^OoI#Rn@P-.h`V5ʁ/o3eEDFvc tY\)D~1|]># J*mwd:9>N ,@\L Qh(UDFH hLϳ9?F`""{*HBU0n"AAʙ^VHu?'ѢMIZxѣA1 fgL0ى+arrՄy/oEciYyĀv/T, Es&E!v 0 퐏 `34gQBc ڹ6N`Np{@O4G~ Y"E&^DVo 3ѿ8ݚ%B_}$s)?!}3m@Pt5TĘ5܇f5\x1T!fbIMe)6NtkyE {zp{$@o~je=)eL1Ɲ j.w fTZ2ǒж׾)OJr(Y "6"C&g-J~Btbk]VԷ:uuPtd8^VΧPɇQ)|{S"j8Ԃlgh盨 /k҇sdRZ= S$3?QA|^ ITՕi!e|6ճ,ƾߎd#Y;QPojp63 /KPs遜Δqg{QRCkܜ)kz 8j SyU!hǣ?Ch X*(%+S 89ᅭ^HQ4XaY E8>p#++@S@L>E,1ϡL70 \16L$lo7OS:nIncK}c%J9pL_G l?F 0B#̿2ĝ1YzB+>1tM3kkРfX>8t"t q˭EoǬRY-ˁݾ0b+GiЉ$k#Ơ<hՋ?x [篳X9;<'uÑXOfeCfU3H$!F9Th@e)c;C9aձ?򎉳vvAFSe16ȗȐ/53E. ٗlz&)'pm,tg7?RjhIyx4wV{ݾ^ u]N8q3PM=ʧf?%,yn.uJ{َ̛whWBuf-}s3z\79l|{ht|K#d[M5mKJZ†jf[bC+wc1* ]=1c9/C7~6Y\ivG޵nN5[ukb'ND #̸:ԛUQvy9Lc(p'_\b(?sΆ@HٶT DnpȽ<lJ3U D :M>j'8Α|)j6VL .Nf&<1] jr㝵VIȒ'=<cNUZZx~I`eHjVE\hi\r::B21¾6y4ȣ<>z#O#dbie.jpó{ʮ4 .D?&q D04c)jBy絈{(Ҳj{;\M{H3iZIؔ<|-J,8e1v#* ci%cDZwVEH Us/gvzf:lV2A;*-(ShSbKv)4l՘f`++UPT,N7 t$_s{\R헓Y1o"0TB ǭhƠ8`P> Zn2n|s#~IȰ 7Q:(Fm7DxώVA]쵛рU-;L)<Zt2󞨖9HH}ǨKEkHҕL8ʳ#ߓ@ӖE Q˭A?WUu-X>|h{cTEW&TweEykX4kQSzjIs4vSsHTGTY:| Q?5(/X"-t &M@L:j'W.I(py[4P_ׅ`$DF8JM1"xސŏrCYSDY~0eƦ'֦Fl @CnC9dӒx0LZvن͔Nbal^IJR)W9l!$Bَqu|1Pzͫ#{P9$plK_ɣ$ SB.ɿIYj?W+p7*L2j~}D[1ɕ6JPS#'?e9-]t; ~jWvy8?Hxj[́S(^Fi_=1ГaOJzyC\):޴5B6|yd<0#>2 "|Y uebF#ۣ3N/qM˂qMv)8L]xTME,ALdrLD _ 7wmmѮJл7-rn_yeffVl> y.adH%Ьf4׈C%7vR^}ζYZ`0!ig!a}orfKlj k%f2]?IS%`iDAqn%){Jgns^>N7r Z̢؈0rzҀ?64?Gj6!Od'u I{QRHG޺sφM|kiQ?J3U0ݔG_'PЋC!ԴnVN""TtnK[ g:Ш9#6z{uѥqrbWVgfH<\'R,dO<#Bܢp` ˊ:$ ae@@#T R;L""}-BsUuwûKܧ{IaCekIȦoisN6}?rzQI/hlp|Wf-50PVD;jYr3ߗJwo/VCw(NRנfp>M/ldWȩZ*O '?/wy&e %?YsKjoF=jP}Vౡ1g4gf,3///Tr AZTbm:pw poz}AݰN72u(2)H`.LG1Jj) 5rTGV]YڹW6$EDdQdaojBŀY)'ҠMX@#h?WF}hWp $H7ExA|u<+ s7]Lr5㛻Y:Jݧ?vޤ'YI/59#vVbsEwM[|PԛPmX+di5@R$Dֺf"Ӳh1X"R5Jo6Nh-qrP:s'@jHR!jL_8SLŮ L9֏ޅ+ɗdS@s~UQ#1PX\r&{WEzNcrt/(e/ l|py@,9s &A#X'Jsa8VtΒL)¨ ]nb"hN˃*#&3GY-)lׁw$]:l]QVm9p$1H5?f w_=T9dJ>SA^4_r'ݐEdA.2G&81 6 FuQh,iUb'w^\z@IGE9K (8tT8q>wg)JYJ`l FsIFrzx3O3aQ 1z.9 O8}e124X& K*7QN @ @4Bv &k49Q}M^4 Dh5ƌw1U >ičbb/ѩNxp;X2=N4xPlmŖ\V$IK|,k>xA-7Ak$#[WK[5!AWA}m_nd%vR1,zhΊÏy ]$,&¶ț-Ua77u8$3ċxP]xr/޿dΞ{x|&GXN߹Tz#'4JRfB3KW#st7WfW~F֐HesLKKqФcuHk(fctVܝ @fpS{[`ץ]b7mt gyM`л"~ԃXmʋ A3H7-w궅 E~/`lNcKLݱw 4\ef=;(9d#6ܘwz!땒mrYqƐ*[Ϩ_TBm݃}na]!ddv 3$jr\̏Y4ΌIs⎋"Ib8ᾡR6Եs_l@͔rhqZKKBGfT(T^ 9_PSS2g,Y Hb: 7zR3 ruI' ۶mt[4h7c?@SlaX RNF#bx#;xcHnY͇,jS8?~rJ$r2ۥ ;E `e/XPjmshɽ^.L)XBbɷpϠ pp}g=0Ko8 u c(YCWw|pw3o**6!bΊ IBlw %u6!`wY9} ]6;^3SN;yjKw0AER![Pϋ48v2aet];9ɴwgηi #WYU0TJ ybd4KӀ`af,sؙMYqf:t/Xx]"z,.6Eםr:e$e<:z>Mzt&Z\]ǺF0 8WRnJEc+!܆o߇YN91`D4,wr`)Fp٣tIbࣉ' M9ńc5ZDLW3:[$u6Ba:2!YdJ"oZ#M0dxWxSƔq(/WvW7dεkC9EwPYuM(˃t$TI ݄r7/ѳRxD?4=w?#nk#j>SF)2o<*zP=Ls=enU_,_) 6"ŒArtז>oS<_B3(ߣܜ O s!ǝjoч6)<=Ĵ`#)ф@^:RtdhB#,enhg!U+4 κP_xEfcȝ Uulz c機XDnt^EۨG^OO *K;\v0JO8SjnًfZ聼v"QհhW"bXD *zzSB /0HYrmpd06V *ޯeU0 W(vJPntLhR&\*sy&a+:Y^4 07|e[dA3&/u]1 ?aN#?#$qN)AaFz >⻝ 'x^}`L OiyrݝYI/( sӣyQD}2P),jh{F_/@4UВsu9l6[:sg%\]nj㎲Jv%|\P \؉L ]޶w$ J`m:Q.*}:؟捱>|'A$<5@AFu¯-.b}1]-tj紖lGGH&0{h>OR-Il`(h+B<94 FJ=6H8Q47sN9J*u `Ա"6j^O'vJ1t ̠V(lGK Sڐ,b=A//8m*feT~# e;3==ɛ8{\~n|%gHѾ e07RNIt`1"oN&3B>G +jL8Pމك$u 䘲oeͰ =cG_kR ͫJjO0#5a[WW7OP͊uJGބZqfD( t3E)C3 sPlvcĭF6e*M E.xsR/Әc&֛x8 hw`[.-qbQ0Ks͐Qihy_fP(y$ ӱNvZ+-Z2"_bU<* m>W.ڜdyR ܖ̀wX0o Gp{4&ݦ4R7^3_thdۡ1]/bYRMZR%kƱ oo!=c˚v)9N:>nAx$p|‰L)ZKb]7/_D(sYPպx7RAݻ D:TZ?])\{Irq|Lq 9n@0ebjIQN:otnO[-LJ&"ܽP BokG֗y1Y‘% ,jwMj6>W?YT@ ) `B@W}'opӣZOl)X50ꓤYTEρH`AR+t-*x*0 袮c9dkc!q4F7G3J9St 50:q0Frkfƣ%WmS"k']xE|4%ŕvHѵ >\"]Bq? қ ]xd~ [źڀKۂ\2kHkr0b:a&'ĺ喭NbGXD`PBvZ{SpG:Fe++^f橡V^ϧ#voxtK{i2ڭ%P7:nRO~okfFq _9/ytΝ8 Hb)% 4̏omR{f\:L!aw@C|+Ȋ@r|I3KNGQSwo;}]acMB80ɘcy]]~FM 7h, WON{pP%r YL|Z t5YBp=Lj-xcֱs*ֶ^eY!wqM!2|78 vIGcJص_D=PeB/XZ1g4A@6@:/ٲ4# #,筘*oDS^9gq ;sJ۳_ʏ5ĥwU]?:9jnjVDV'lUǠt{ 7,lYnS#:Άj5rT\&&3qtzDKQt . xV=G(O\,NOaJ<1"iR6#<IAb3MJQG*ET{8~>_DYI4g~k5<-ݬfйMv;fq4˅q!WJ7٫; MiS[V_f#bS/ e~At?f eih:eC>XZOkq,Ȇ{"s|:6>VNZME RZS۲Q%NlUPǐΆc[[5 3/Qe{~x`1LGmH;XV(E^][﯒R/k|ŀ)maA\ +]4G}v,y@\ J#U3@n˕[ϯFyEQmR >؜>d֔h[A.sd1I\6s{*֭-ZR+Y,؎J$֞W7]xMiy,Nܻ@K?${[{㪅tƎVs˸a}ѣD*!!p'0_0uRw ӝW@aIѡl7mVnZUd<~6H3|_/GX5Aこ~'gh+7@ gDVan NXȩyf^3e U#<$dQV+d+vlU6;w#ҙZfGf p-S/xwyf)+/bEŚ+CAz T!'! = O'' )P*t,/+|3l|vkVb>̉$bQPui?ҹ3]. *^ Ѓj[psȄ}҇@4R8ԏTw[kL/ k0A'^ !ݥF~.SCLCw=s#xx L &(\mQ9#D +=')C*2bi=(lϧY֗!GZ- +.(#Ғ|$%W *R:Pqqe.sȑӛ`#\76IPm웋`a/A_[ qXɜ}Rsj͑S.@8VɻƧAB,iG{3ײS1'43@m'үWAׂ9j0E[$m',C˜M6_괋Yӻ@4uy'ңS.[S`R`nwr@{贕lb}7#dƩoUƳ9"˥a"d{D0y ##A닍~bMyH~bp a\u^?Zд)!|An/G$ABMKac~rT-wz9o1AhB|S&rl~KbLA s~I'_{]~栀>Y,s(o`>NhٴzUe9WA= [>|NXhc3E-pN/MR8d켄%ҝV_s/qgRb XMK߫U-fNWZ?I_am^V>D;!7vt7c(f~pE% fz^'V[4A[KK~&s*-)FO99}.g9dn;4Uܐei# fY YZޚz5Ǵ]"c&԰ CPo'AŗBz UĦ]Jm̓N+}@*.p~o|kBLѲGSX(ğl/,wqX( rzz p5]bUg377=ulf<iUGvV]<6cvm.tK)9O&T6@&vRS>?Mh\ f/qG't8%&h2g^v*楲覤ww|Gv'HO".twEfCId;}]_3) k8z5 *)AIx Uݜt<75s.x% )pOEM. fetW·ӑ^+>]||ڝϻjM;pM7ŝUfN^;:E![VpCu7nMAԷG49E.k2 ֮oXXР8ߍ~4`oH@q\Z;/pErT}O؎sQ 6ȸFj$++y/Tүi4 c/l?ߧ8'S$ICIgmMԁ}P-Ի&(Y:N'nG)DF֮9QY@̈́*_K6eS~~YH;8SRg36Z_1h'Fъx{Ho!_;3?F-H%^ 3gK9{W.հB]!pƳ-|H!n !a9|^[`Du(}-tQR:ى6fqC,{}x8,#9~vx2W7G.!!HV{`6Dp@M7H,*HX3Hbџ?o\ 35%!2$ԐрZ|[Ƅ;$Ga=&ug{l]#msy \af _TM:6K.ӲyIDakͧSubN>-$ao&O>FIHT/LjJ+ i+biGM32"IL5~H7)`GC\q kFji;ͬE$Ѫ&!l ®]a?jpM`}jaO]_{%b$ۋʵC~J}fH#g Ga['/ڂ' DDT"n¿1l\IjfK !tH0dEKe)"!v5lG4DJ,W"|uMZ5o!a, -jKGE3^e|=1A1tNɑ47hxj,q^ p)8@. !ypvCnۚt}9i~*1khbH {\NF~*ð$6_-lb;7o M;)v,l5p fVޤ=?|]ad')@`BZU5] dF IP>YZa*{\lm*rN1 /Q3Ez:ӗ lPz7zS(}Wl!$g/TM_%m.#&3)~7 ).Aff6ʲscF[ Aɮ&aҊ[qU+Z=:m<+`b+<}Fh :DJײĶuqe^%z?ryN `߹YgYљc@ɂL hQm,!Ql .avmuMChě,5Fn('7vZ@̺vӌH]ܪHٗyQ!:2b~sCBmd.g3E;a0ƣ52HsX~哑ᢳK!7@߂C+bP:*Nw? 1A2|QbaPD E1>!g9Ab|bZ) vY,]^nB~{-O2NQ=W/*W*M?'|=RaڰxEo;=MuHFHAPD$miU^c>֍׫iɳr;w ƗU}l!uHK5[ʊ73W(~8_ͫI.XoX/Մ{ueEiҭQrab+Ů[ &HqFFgB>,FvGDBꬋcb9춴I@x]5e&eB ,jxs<[v&:Y^,x3eϫjfEe?|C3>Kw?qZyY&k@6=z:%51˵hKCϻ=;nk1TGާz8a x(^r'Wk"հ|pVn%FⳎnYE;hEiAk;kGX+3-]M]R¿ɋ k!s.5 K>7|aPJSKUY4xG}CMnYu+ØDxx=>J"'s*1hMdD|F4tq@ա:CD';D Qx\ XXh)E /'ʧ`,n(" 4 R"{}:e-满/POlwi\gϜf D`J.n| @Y/>Ãsه.KoBM^\^ɏ&!ϛO' 2l}P$U9Q~Q[^BѤMq({e|;$d`d/J{VJ8~<'ElH@}\bdWF]Sa%eTɃYu$o2Pn{E1C=[M Hrjl OSKÐ X\\n-gĉ ߖ!▱&6dE^Kv[=o,7{QxJƼ\m(޺gQZFL +-B8G܎+wR5%1&Oj\]zc2IؾV5l 1gVlW+*x ??a)e\ ]JǦ?7ʻHiwTL/:^I !pdA Ð؄',j]v}1++XNFsHM I`a C>r8zvT;\JlZKG9k~1`Rq9Rka¨\ NX/cza!_-a4J|.c8 }wvc?! n#1w`'^(@px'e'rT}0jF`06VH *'}^C} S It3:^LY5'HaG(E Ca{ʎ[2X*.O?J%nJΌ i$OPJMa9Ŕ8!uZr X:ZzHH}1:t9Pj5kէKyE>S?k7ίpDj6gl?MA:AkZ$!1,IŰSE;+"9-ҕ P =K/`cr1Q5+2GsQQzu߁Bu 2AC: 'm'Kj`U1ih~X(Y\ؤ.&(#&Y5}N *"O~Ɵ)4Ḃ=dR=YA=@ N5ם]2V?Y+^ʱw/^K,id&&:_Bdž7ٻ̽ǛVe N.vd4XgmɽTƱru 3 <@vHg-Ͱ` 0Jvw|Ԛoř/rYW{Uߔ(o`%pOKaXDdI`dKܕ*Eg`unޚ&  9x0Q&$*+$̕%ǜK wXSJ?jX%ysr9 K@,ǓXRU* Lw'#}_f8fM6% kܶ[8@qH:oܤ>J&[":+TYKH cSG__87HMU7˂ABjpI2k%uOzU}} beN|?arHgl)(o ns0?p# :hAu6fK~3P\ϫsT ^pY6: ^hWU@(,gս3H70+- bmeM| J//d :F%<HF$nյ8kT~³kf>/*d9?Xmti+x>d#& K}WlCbs`! HnPъ`6lA-7~viK{&-% {Mzȃ]sZX4.%DqwMhWb7/Jˋy.FYv PejM2fYF=Oh.3z<l2*ãq%٘,'s i'QS񯪵pk }8V/%kfiy,wyW];2!k 24ɰQ$yop>H/Cx?ae86}6e.m[&`Zrp1ڊm﷧gp5DFÓ4vã lP+H0KuX~~e1^UPA".L$FpOǟ X^SwK/٢gg:φz ov.ⲑ4PAΈTSMX `"Tj2LLm9͊MQ[,[Z:W"X;W b?x58_E{pX@<ȩ'rs٬!gi;\_}iEOQm IA3~>\<5v SQT:ph@xÉ(p b=zHV9HGO2 t;059\c@Z=RLB$1d.#2YYN7#yMQ` Ͷ6OOIgfrb&Edd6 G%]>!պf![d%-&؃+/o|,7 oH ø+`mZ*JJ#ΧM |4P?qhh[.wWsKHG NQ og,oDTXD<iM9/w{B\iI:A%w%B0VԋE)Ģ P&auw nM"MuIaN+7\HM#;#*'*Z~߲h0ґL=l,{.FVJѕ ToNzO2 ;Fиƃ$@7 )lTQ˗QߑC5t`@8Ὼv|`:76OK!XP-S4. Kl]?ŸtPZNpXz{_,HqK6AĦd;ln>+/GxCҤMf:5+9%EZNqڏb|y.7[L88Oϥ**G֠%䘫j,"q@Ʃ(xKvwfYC\n]2w|5o|MK8Ǧ_pVʛÉL5D`sN8F#FdC(iTsLƕғXbiIx؜˞"tj18#=剆°dk/֖yKnsI,P> !rqYH|us񧭗3vQK YJT=S\=ʭ⷟Ej8Ti9 2jHX[贅fM(;ڣ0fh(9m sZ5E`aנmXG4X `V3&L$xxn^<zɧ:K7mTh\9Zu" 40^AHE(XxH 7Jp'k,i ^$a0Xg{B8VA4fR4 ޯů)O{I=P!p-|cGMтOZ6?7%/,kSHO  3}Pa֗3<,<ߤR&s\K p4w7|QDjeEp7_rǒezf! GsqHyQAbN^mε\A7 PbUٺ4|t7᪂m_By^!cht.BCW՛dUOϢH5/.5vZZQ,=4A?}tha[tKtN"Y~OjnGkMWSa\te|Vv xm [M8Ϸ,Fj>e p0Wq?vn~nQ،qu ~|LBKӈIa0SW):PtEyP `x0 l)c!wzK',UQC$|/'25UmkjuUb?ºݲhذE K (qP՝mVƑ@.6v]{CM+a^tz­e&Ӂge쳕s#Kj1M=eᩱ @&~Dwx)fj}V]_5ty{Ͱy+uM D'.[^o*XMEƳ -}5 cAw'(@!ѕRةezS晕Ԁup՘ªs賊b [lIj#w;//?ayz.幅!]EfXagUn89? *ͰMwB!8Z(d^"]hm@[NN.Gy{ra j{L1 u4!Gn>JH :v'u"_^݀씈:sZdG>974ƾى q7gOMDߜ~վ@5m -1`}Z8ۉxˏJNG~E{㭇/CfxCpP.ArC3U?AA1JfSaCh~CrL_h7r/{*+ꍞ GP W,7sl#[!6tBՄ JX#@Eg.pǔ^!L<#Y3B_nW}p=[ ~llI볉R-#.Ⱐn0جX3bkEaSGs_ncfbpjؔn^׺LY'CSׯ4Hp^XL e(Wr(i#d ®|v^LI2a4ϸwtIN%#f]79N6Bj= Fla GPc$]k7`Kl% ǔf-5pJ*#DR{V}{[ ն&kcy3P'YUR_.o_FDskC֏n3/V96C&ʟ'zsǥ3 g3QN"K=oZ? 7b#JoE6pB-T62 u1eexY +~?d.wmK'=!Ճρ~=U[Ѵ,RHaf=:dzs) dƺU:牓ujDO5l6dt`rf8'G(i8_Jְ]vx<̖Vz2+&m6.eCIvE!dH"$fS{'} Vy/7~ӭ=68鍞(g pmxVg5jg={XqdA#=Ac/c!w@WE S= ha5վl8Q0JTGF=4dא /IhD=%ehb>RV{ޜL{ in߾߷Cq҃*xn8  &gwU&9v'iq끉ZD3 qP#Nu*H3r'|0+k$9Q˰AvJf>2 ?cdJ&qAɐ35$:.ۜ%YҁaYrn{iꪪ<ԺaKDĢDext$ z%J}ji!'y~-fp_H[!o4[nnpƽj9.+iO= (@jFRUhӛĄ@9aTD09e~瘢v A*$Jh?D WjNF3S$Nx0^3=Ta:kEj-E&1 utݚݦ{1:꫹q%\HRJIŽMrh:(omaЈ袨Юw/)*F[Jj}[t;.|&|J &h;drlwf +%.]5 j^=Rk5Q)m9沱eikckG;b`i?4b$ci Tn!膯lj$ZJbnYPr' bK/GɌJuVUMŏjDz% qi- $;/l5Ċ7[2JAۆ֛dEJ*{(.G6g}CiJ|"@%ًɋ[P!:*\/ެ1]:)q})6^ըgMj"G9*K|r)qwDNBC? _nsk*ZeQ 4=d7*)e)Pʏ՟T\q}cn"*=">4csic]NÛ+_lfoô 5qs=1~?Y$ڹZtryxZ'z3#6  Uqy$n: 3_!R 6QV˾>~>šJ.ϋWS}6(|Q& 0#7HX]HV,/'Pv@aԈM&OZ:(ߎT&=mӔ|VZiuȓ!I M)m@:d|)ńO{)IĪL_qܺŮ9&{ۅR? -xI P,܊xdžjCBZ`ޘr](v\p0KO@~qxzaa #ɠBsyőS-+ ^{U޵c9{ da=2$ ;KOMSiӞ0 CGHYb;cf* hOYȦV-IEw(20ϩ3! b =QA?`ug_n\Tly&R/τL6 .mdX^(I(l3/CGOgaq_=c\E͇ >Br^΀we6t3s> %eЗZj%}aH, v~E5^i'fCʁ<|m4єv@k:t+($iH̆qqoHG%: @̼m?+`- K I5j>Ꞿ[6iX.$<Θ8Eg9A D }$z<2TN ==Q%`@$ȍK&xȌ(TMqH *4'vW?`Ԉ zB2"!DNvDLU$*3*b/K im쨤U>T`.ٟA}vy50t#J[7NҌ;R0#\V"%2v4HrpMcBMVYt&`lCo#r{a?ьpʖw:WguuRC5‘HyڄݴGjϼ~W^J? FAp߁ŧowZ;VY.#ة ESC|=w9;ĊV8p!҃"7%ASۖck=>_MAef( ŞH[hGP v!bi6jIN皋q]dAH垿xX(y9SƟN4z-`U-ۊݸ ŧC]!QW]0="0\Ji@U>:(0mUӊ )j4).qvNߘ0!.}?>\S Fݴ?};]5Gfg۹tfctCsԀyINM[3?.s-RogSx)my^XEE)Cـs kej6WX.p0@\c!0?+l_~`(/%QXzK17 2Y..1Һ DLALx-W|#.~=qގsWH 9C՗.`c%+#$7ŝ(fۍe?5 2kG4˿lN 'Z) 0%"%e3AmxTHPI'H:*g`ʭ>p};-9Q$tGXTĮ6m8kg?R17N*l̲ze,ΕuktTe6PgZ|髎/}DV-ѻh)Ce`Cت*]Nt\gT{'\LhI!n(*z?C:\1߿c<5Bn9o@A+dZuq+DIϭ~ʼ + 2U3I0˩{(z՗,ۅ3B\v"7hA`2+k%1ѩڡ]R=R# *2"8`*~az/OCD[ |+(DLHDe&F_9-vz7rħP`ƯMR6Q>%^`pv+^a_o&ʂ{&[VGp$٨CTg{c^4F*m.8sp)=5s#bWduJ& sLHMo&x$ ːK:,Ok>9L²fF;{qv@NN62GEک/bWǨHP=2%tD S_w?~^I k1vXV\]:$m֖")ŖdH=p~lsVbkIqym>;sڷ)] gBP;ɔGnB̙5}mo).Ae m+I&n`<:$철!r#/m$P g ΎQQxjWKJ"HlC5z_:@*. 02D$h|lhI<y>=\0U=;UF+E:?/J&RBԣIo b"jnO BI)@oxHER)&ے)# ?t~c^p^KyTKc>*TEdm m&B[51Ur` Zl4GdL GFAێnk_9wVwr?_,[pQytHtvDjBB6č.^%phޔuĂC>D6rvQ7=-T:4/1U~; [h(ce(v8iQetX̹nǝPD{QM` g.w1X^1oΎ@ .[ qz*1?LJ [Ƥ z|E{}j+bkq@E$k8 J,Ûts q3΀CbOl"68O[1Sm(ӱ7ؤ͞]KfJ䫖O~xgk>l Q'M%bqH4&D˚'4EqGga~M+@'@#QsN}/{fMqy7kH߅Zxj"᧞#0u{ OCJw:~7B0?!xe(t.RɨW &ue n% Ip*wVMeIίR?Y7E\R}}^^dr'pZ(% I2H}}zV*ILxQ0 =ytX}8gL-|D^k=,a?0jm*~H# , $_yP(?V)\dd=.V/$T&kv^'P"Ц o2fN" YuUh*jZt՟%<~.?*?S?=C=SO2烫xD3v#ߊ9]13\% x>߮oW:pQ`7ydYW'=!AʥAOT ΄`ጇImڧA!4E-AzBB\+I`6#6l h,E=5zuVKb:Na׆|s1bEIf4n%߅*M]:l=M a ^6%*X B<ݿVRt \oGNȶ`]pd2Q=t,p.QonN%^TIpHAo,m$E] ۧ|q8NqqSŸDbfKg#:"ʘr \~mI}ɔqْ)Q GNYGv/ߴGhK@&gVb}SMR/n leNKnSN]ucq$?O$n!q)I%< Ly'7ZÚ Qu$@'(Jʋ]1M)C#bBI%櫡%اZk"'q?tE=NW?p.cĊ%vӴk}cm{i/0|4J Yoz\yTy Bmcfa pSǥ*#>hB !BT\P/P z[6 32Ey8\E&9_ _G7O^Y.!ҩ"qD6arV;N)|k!*RO|jx40O$CDkoW3XƵvR ofip 3zҳVNuz쇄%De oy Ueoԯ: : ;W!f~eͮJCn$r=*q~>¦0-jF)|y+=U͌BFEGm 1g u!-&i$،]75 D)b{Vꭚ#" -H2mB cP;d]n_Ɉ(1#w|L#I0<\(1< y.>M⦐#=#2.GD‚_b3C'/೦D0[Wr20AOwӤ&;Olr\/s ܿЛdo}UϿQЦϞ\IA0-c!7alQGJjadg +MO7Oi"xk LC"f)VI/uqQqZΫj1z5izQ%wAԀßKW^c*ڃe[ 2m Gn4 ,Qz+;y}le1y6hjw776ghza+  y_BpUԻ G?FdRu =l!8dYnSܴc_9,1 o{ ЂbY,൲LE i #qYܢUi͹[`";bعީ9A+tltX!'`Xɚ)RBP\U}F<ߐ#Sr '"֥(I-]|͑hNj#94}#9ϣF9c}`%.9bڮBNk/ %,,`e *>B_&%Serlo8G E ÅSb7@Jm..e%wQ2xTpidjVz~r.@̨tkFtgJ,H4Z^GzIpb=a'@@>mkeĸMTbv.CAB`qM Pz x֎`c?{M ɃehgDb =G:O.c@)[(sPy^IQuj.n^%=n:֍qPo, /0[I}? KB O ';@.]zJQRi^hv,LƬh~]N(43CCh U1Q̙z--?H*5sTemAgmJ%tϯ9_o1k"DE[e=^N12,6G^5RJ~JVKE⸬'*w>DHY9jN0Xz_ۅ^Q=tDi$pc<``FЋyp& 6z:k9X~ye,p%Eƈ}ng= F@zJ ~]}l ;l Q:|sB>Ԋ*}/LQ  s-hh) bxJ} %6?"gc9.>J$|(Gl0˧m̒-$h|FuI hoHHx Byg<{8gNs0Mq0:}4^$K?>w ?USIv^sh |Ih+gl;,ZxT #7r dxrLj 5 ٵ_>WmXI$viĒpV 1|xF')/N8?g&]M/Shgiup/vj^SH_'abo1R4esA (af`A]bX7MbY<͓#XP9rM2ENpp4^V?=SQA+n;0NK0rxm;;LNj̦ o Yg.wy3딗/vxk2m_}_#\Tq~nC:m, E :YR. ZԖҪ G6O~lo{oIإ1I9I22mF2qU+(G%w!1b^ ؙӥ:Ab=x7i/O<<"g% #Tj@8xtoa^8@:T|_A\ Ks: C(~cAWӆe=tVIs'j _UyP`s91-{_t`x琖X i%q3˜SWw^jT,'WTk&823M!8bP=31~܅n-0-i CŁ9] [ZIi2ylةb}[mן|PG }z^Ǧ69h-\OJ K"^nKa[ U7lJ 2|OJ˷,Myp,[-y8\=G~=ӷCR.m"|ARDZށ2Wm&)Iк[LRiȨ" y-,M@_E4d_-oF!]$.Yz켯lJp7غ(wiz-. JA86-!/kjOR'XEQKI6?K%S{2fb9؀'{՜OTdexi3W dCM~h ɴkxP r `dՁ?ٿ¡:! s 㓦O}52O@NM!]V)HLcOxU Z ]PXu ݱ, suWwR7O).lB>C3JlQbv . J 锇ͳCs o~L ڢTn]TQ Ǽ4>Ύd uʢ}%d}_ ]Eo=rE Al^-^# j}rNh.ex 5;՗k܇;hܓDdL^U'is(OEXg>d@S\oO|dII\SK4~¬SL 3 zuvH)5(< cDPzoteQgqHH"O#:hS\7^h v y~VsۑV/QEKTwcϹy'qJb!W5?cWr&ڰM?ƟCc٣81%XWoS+rа-W ^tpwokxz3.h1~J #PR%>!x^VQo} O6I!K^@wvQ װ{ 0v,6X- rXi݂nv EW# Q7%նohj!/ц@PH:r'nVlN]BHd cKU9ށDUFzj߆`7'wx.<޻'_L>6Zpԩ #KtcgWJ]ݙo8>wGqymo:Eye}fo@]HqwmıM24HJ*QOڸTh%C*y9r`o~ÖiGޫ qc5Ae()HN5XGhp%ŒoMSqDhxKA<䀲HJ5'7g𒭌c!.]u*ʻʰb?zwb$yhκ_+Wӧ oB#xhjhgE/g&@O r#{MJ;9z-:& #ﰏ{XΑӶ~$m{HPZ{ \zG,3e"?'T@Q"<4Os8-NDXEA=6\+F5#8c;e:75k҉:^12 PV*} ߽AzSCo-LvЊ86w30 W_A PwH;&J\NbFkTWa)M|dl%?vՆ63+ֶXv'Aאl{1mO)=΅u a9-y֢f{u^y$JХB(M=S u=O'$~tۃtQcب k53T?[ Jj'Z8@vEPrHpK7 "g;G3:q?d3.Lp̳K7W_2E [ 5~r d5/^6'SOȣuJ L9_6_]m( TP*ZKy4ːe{nɳG7A)zAÞk);coC{9l}4Fm0 &Ǘűp$0F܂,fE%of5[BZ1|(2PRa8ة=2a+3]4ry`n/(ص=tvtm^ư:?^qzU7tz-ކzFҤQ%oɈ۹Gh rP1L-Jݓ)޹z=Ȧ$rXwH/4+$'H@p+,۴fBVq68ϧ.{ zoߏ;nC 4N5qO}T.}v4HQ9ADD\'5,IHt2 Y?{N$ҡnP~g8& \JיY*nt3WI\L6u)2)jC,oX@-typ4MoI{Q+ PH&儯<¡#L~Pgzbs3m|?M1Py?N1$ 0jS}I`ɻFR(:$t-pH fXQlJ S{W"?=ϛ-< p~ ]gk]+XP Άn. >X+h_Z~R@h r66F{P.HJ!mU'0] U0A!cA|pLV>;@v]ex~$+Mb:ďobz7=bYin9B7=wz \*;P&]#)=E[F <$;z" Iwŗ&gϱͱaR!VRsʂ~{6"\yVn8 |,+Srr`d%NZ՚ⶌob=xu~GcAa/˯k{([%]ā%JϵݞcPXo š ii!!DNRu .UGiuyrG*']0[GW{cA ܢr!v# yIG)!g6B+8tM»؉t"BURQ\ZbT &,|R.21 j  "7?Ѷl Q לSj!wj m~~,vʷïKt\ݩRkHICc'ǕONeE:,rȲ\-Yf9WFŔH* (en3wA P/ J,OD~IzMصkJ+:ۡZC1. a:>!F^l ُ4}L'f5f>(CuuWCi{3PWd)cuEbS "P}G2PlcX& і5ɢ:"w+`o|gVhbLXEȒLE2p~T:iˊZAqaM :%?Jsߣ,GʧwR(ZhN|>'T]{Ŧ“94\6a(^q  J ؾ B"Z*r53g(E8>RFMvI os`S,#/_v^BJ?OD .ڞ( 7U$*ZU-%87&j(((Mf⺄5$4QF_I L4D_0h~20Jl K.݋`!CU/+}!@Ͷ!81WZ&5~Eom ib'֯Xa*6EG3kcr]kN& ^h#R_KƦHsHb\Q~n3Y>8\!M~n^QtxYI΅6jTqg63(^79*ngCP:Գ2#"|K׈ͥm΄~ ԔBf?t*bߡ-/ݕH=[#/[}9'y}(y,+uV0^ROZW:U=-ΤC%D=wsVq+HI LM,+z٠{Me^;VSMR;h)^nPu$䝚"*&BJ Vsۨ]%W@7H'uƷqN8D)X#3 8j=JƘ1:mc(Ql{AW4濸Ofarb%waЊ36I !DNMصE{T'jx5C`f'>==Tp/4d0cV zx `7&KESƭG  Q+wdk;և:~gdTR=7/L6n F9KǨq\k ,"b4>*ց˿h ,K-Uù=?R9BH# ҿ}abY؇>_+HKucA?D105P9( Z1AXTlDA|H{(6}k?l%ل .Z$nuGs@P.޹\4, X):hO A(RIfY"R]2L%\9XWIE)ӄQ@rOi~-jTT;v31 ?p u_e\to3'K ͐0ld0FPሁdGM!- AUORo.K[~7$o'D="^; ?./CZTq q'DjmePXCUA]toU]BI3E4V &53 \ǭ;OM`?v|apzo1ẌLlj|Krm5܄FvP0 ifX۱Ua {PaH=6/7)ЁQ:bp6׉ F- 1`Vоp4wfZSʶX(AF&w­Ǘ1 ?1Klee֬ !#VơӶj{ϓ^!Se> {"qM|j©,*DOE;c'RK> \7 IE.)2:cE#Q9,搔IՎT$t3(4m4eK`qMz<ٯZ>My=<˚wf5bm\.Pb'Me W*zA泽 0VrxcQ\꠪v48jCa"!7c*xq]gdLv }m-x"I& @xqsi)Vo _+X$b([c$4e@M<8yzzIH 3Rz[#aY l2s85}t3U,ĶAgr|٧`lOYafP{(*_c~Vǣ*L&`zp%k,}n@M9Ȃh "[Jq:Ƿ)5 PC4[9/s5h ]m.Tqb0K3l6+䶐y܊ߙ&>bQSRo]e9ߚh/@;6͏%utRݜ녏eg]f|x|(S\w%`=D:Rse=D; ɖUZL\L B&Hd_+3UYEx_ (S]sWb@ P%etmb ɿA$fݬv6?77ήr'~ysѭ&G` ZCyO͌GjW}5mWP#Eo,yt],>0I|ÒH gTd#]8Yq A/3Lc<麊"/Mxf$?DL3с=GWL:%ˠH0mJL6"lߢ_`8n4@Y+곱3pP!ATN=0 %s31H%'Xֱp1`qf E>p,X ߮g]t!{{&u,^iZؾasWC%['[s (-\$$5T sͬVn(}'-\/cPF#g]]D]\NN.72K.C2Ui1 ?QћE>jYao4rݮw{phGue}sֈ #smqh0q65|*X$b {]8cxXj1gޜjCqI;N~!vmS!iuG&nȖL p'Q]\y>M s=u%6%(B63RAQC =v(& tШ,Y}/ʸ}rVe 4Agm|b 3j$}?Ni$sNc:e@0rNloTrhRs\T=׽EQ9fZC/13NdO/3t"-?^F9}㗻fߡLp8-7ÞlDZ-ѯ:<ꨏrF үȾ f0XYw<>yQUtC_\.xv$[{B673Jժp*):ھ؏X&rM]&0Ʒ>׻@C i^0U iOj*3aAoѩi2@ oZlYx +EI9)ԱJEOEePj.it-Dg;O\;ՋW׊?I\ oC?$z*%(hU,* !J5ĺ"`'< !29T弽9}XaNl+瀎UPihO g[ys_m@,VPU"6q,8]PW4hu\N,onR5=^0+!]} cHGF{ρTr3[51<yxkY zѭWn<Y nͶ)4 #=2k0LAԯ 7M(2bKxzBK⹑/rj XXa<M2 4 ))h6jJh|Ċqkqn=@} 쬈|԰*;k?$ brvǯƗ^[jpE:JhFL)I_`hdVT0Han@WPL6']Nl{pT3yH3lzX&#k :YGBJ9=ą?`Wt8/QM~7 [ ZZb;9t_|m-;?p#iKpc i3MvB)tQO~Uհ5?|'hx^兾G@)_Z&JUQ,=n>~$sĀ w2<*rSs4F沫Le4ߝDV {{9emN~<1h僊Y66Y:G:s6Cj~=:-RFݖ8a:a-w( S5ް(OƱC. ޼ L'tWr~7}Ĉ]9L-K5NR.=(అ0OhoV_5KSL>KUS 6"î$tT6Pn̷q&+7ʡ &tȉvῊL`1Pټ1aЭZp2GטJVm bD[$cΞaˈ, Kط:L5ō vHXEG]Β&XDq^ҷoA-Qc%eL{JAre#=ck"4wa7"$= HEqNn?h~$;h#EBujF6Vx-fz1RٽW (z_OJ嶁 Xh0/k{X/ܩG.o!Zq'X!&(]4?-&ۈu*Yy 7ߍ41eƧKJ~ufisQOuX< H9M⡉mOA ٽ2HrR]klԫYl+䂊瀞:^/|QG:`(s[ ToڼxQP/+I2&}5IU84+3\g<|p+$eOK6%@*pNLL6Ɯ,ySޚpogU|_^/؛#ve9F |+MK@lB{6fDPȠ/݂Nyk`QHDyF)5D)ZOk+5%q=.||vym6Bk4QTuuvęu \V {"uf*w?Ij3B+#KWZaGʝj:HlExv{3KÜGMI]{_6u[叧AV㽊+y17 /`|!~{men!:K}A2_EZ|߰$v#][/[DtziT{8ZY/o]otp_:g>^<@``s*bKޗ-m4̰ ە{M!,M3M^9s csPjUS;aevX@6c!;o5c]va:9o d7u q r @iBl?tUpº"; 5{?aEfr( *Ǽq=>ET6 wK#^hHG܃%ؿh e.?'+bI!O; ш3vg:@Nfլ(yJhp7|yGJ O#1fS)`CBa5fnZARݑ8YNv)Hʅ;gP)ӷ×M E Ӎ]tח9п2#/%~w ffoA|c>0҂e n@&>lTgF/IO*QЇ_DgWG,[=mG#aEO鴚a:؂/\)^^Mfn$il[t꿞`h.go}5fBCbS4He7=,bjumdҖnDwܾع] x^C zbKNi rB \ ,mk,'JV)kC%>Va|$ Zaq1t{Нq:asPI #tO$LK*b;=@tŷ4ԋ@҇g-f\СRKSCvC1ދ Wn 7ꅜRS&$i:Q'F{"u_9G[dI;" !jG:[SKhY:iVUfv*і [ǭ)Oz EBRU O(v"`޲h1u[Y,0\q)7O QiQ:>=;9qzQogc7Oј/&90B ɝnPN`S_?WIkR)e(?/)R8m2|kbVbbvh=_ISX V۪I4k%aj~,E*Z ݥajncWI0Kf*XF؈_7M®IT)G'1!v{QƹS;֝ (OVRآqvhYn vXh2]$:S糔4n&Z7}EΠ]~ޡf=$$Mh{שԤmi S ߸ʷ O[&fƤ= ց\0lB#݂m/FղBlWQWnF)iùT>Fv;TE.(RQ1Šߤǐ#/%fU?Lgl0=JJzaZ ̘6v:_;g<ՐvB?}H )/+HQNiWrŏAݱ_rUYoe'BQdaSL̢fʿBX*[̝IqZ, ŕI?)imJ Wyh$H`ToE.)B2-Lݦ I!* mSKOԚCcу7|MB&QoՁKThXcH0|ܷ3AΞB{SӯD2]=J'](XUES͓fJ ߢ 艠7NU|vvv_(aO>Hтޕr ޯze~GZ12XY)15' j#7oJ;\Bo.l yiBVx:+ğ0-_CL#N窰a+$ eyA*%LA>-^P6(,6bN,M[D2ІIxP_30h/ν{Nqlbv1OBm4SD.0a|N5bivlc ]jMдeZD6!FyфJS/NB7Mưv?4 \եP &&poW#÷Ue7Ѽt,{7q0%isg>dɖשݏLxrB.vV%6 c\axw5dfs!z(WD¿H:)5ǘA[ܲ9;M|'1K: K81][)<ɲ,n5NCpbLK {9a}"!4c7wC Ø82b-|eڑʼnswmVhWZ*uRy$ˠe;WGBfT@v0JF<v ^=X5@H)#ƿs%\qD+WX):y҉ Jxr?9wluٔSxj˾8vy =Rɨ-7Ǩriq^"}*(6$A F% OEĭBZ1,&2 ҫdOd""M t3"zV;e,|<]υR.3MA\߀H ,`16AgEjqtj(8M~5mNjG3MZ7;1ݬ˫lV/P#dV }'DldO ݜ&@壽8tqRSM> ]J S]Wx.\k(9CCYM7 Ar}$8Upf.FEa1.ЀZŇJzWGb *r1t:RDc#!9˱+ƒXX #b {.fC_r;L :o==7xf9v^PR EcէVDfy"؏N#ŋa9J}jX5Q}-ޫW4yrˆ JZ`*u:<=;\s8jkt Lz=3{8eٳK̄ j(Sz1q6-#x.?Z$%Q׺i)AeJ%/c W  _xAxxJ#bK*no=DU7;L.T6*cCͣt4@&^vp `Xv7.pk\:PtpLM >~ ]úF@`8`kJq %yp>5ʮɨ`17@բeĘ5 ._b&.s2}~5碜kdQ7_ѺMmޅ?X c~K8AoZ;Z֜jY{$r8&)2;\?Q-[!OwO+W ˪P@D[QKJ( Ӷl H?;,25/cIdKTJ;]YYؽH;Ś\6 @U> PH*zrfB1]ax尚*j@h /3~\ re.gdb ž4rM.g~ aWNzi&KԈeDg,Į5Bd ?3t ֆB/(_jt|k[ .LmASq`CA›u i- H# NЬlN7e=4 5P2 'Z-O'dA;VY6oէNsirŘda8@ʋ(X,Rс ~Q`-x-{<202è!ʣ%Dl@'͑V8&8B]dZs 'pPE'm'JqӲUz8.PktayJ"h&%bi]anlljۍI FěJL (fm1鄿:JnJx[xs0jɣKi)%R7[Q'Prs z [)4Dɼ>&& 0%v @{/ gA3>i|bX f]&=a71yyE_w "!ƹ .0ݵm/]ޟ7@({ɣ=ΥދwyevmbhNi,hRFY,T:tƍ8Uu"òcBݕ+S%8~MǠ$wWZr6{b;^% .]R? .GϬ*DnGݩ0jvޟЁLȭjhG#=xrt+Zixtwey]ke=c3z9zIU5 iܳ +.u H;QѠ[ [-cf(#fRvl赽 3Z7$\-5'|JQU!wP4Ǿm*urc#m2]󚇂%-%_#L `ZK7o}72,`ի_JkcP4C7F\!]BUgn@9_l[ ͍EteO?[q&c'C.HK{ wac`O<_։j{ oc"O-\0q /n&GetcJtd֬sԭԬ?NgYȶqM+L1a~헼2EՃ X\v-(” rQ[$inґ9b)"TeJ of@i}>١$-sZ`w:Û)]YSIX,/ :cU5h?忧uAvZOe\|HI^z[zF_4ub{?u9S/p=",N~cv6tn7`3v@aR (vlEc厊RSrCk= in6Ҩ}!0eRV?G*Y齱iH~]:fj2VnA R+S|X?]w8FIn/Tlu;ߘ4g@Fa/?pHK*6['Y6۞ 6ad~1t|z<Â{~8LS2$+ *`6r ,YvQpI3h<Ԥ#eEdf Ô-Խ}$;rMZ,;)aſn{[B &Ğl0YQL~{L(.^7C/& =60w}ÉIÙgq_kfg(D1Fv_FlO |@;ڛ|Y?6IbܾP>0}%lc8 3lu&qCR]t6drL}sSi5@v3<@2,+ \AE"iNCRG}Nh:FcF`Y8$ٜ8 +*&⦝g~N\¹PLj:@+MN~3MhUk TdI٥]HϲۙYI$(o˺C G7^{5+x([MHi5q!$6 ۀ.D/rr_1Lj;&((2>2[+Q-ӵ߯p}ELhת5S]9'VJAM0Ofd;H(WXS7АJ+M9B]!\V^1vI(]о2Ev{WE2G6G1 kPEo0$dbZademK{BߓS` (<ICO9Ʉ)2'h"GOݔɽ`nTZjf1=e/|ډE(Sf@ʯז8AYտ֨+4dz*Z3qpbʵȖEk3tR֧umɐ8j}8LKEHz.X#ŭW 3W.1{tλ2Y)pŮs`wp,يb%]w\ ϖgšmp'TA30UpVe犟"P07"^N=i!|.NvelR σ7I^-,ҘJᒕr$A^XT)3V/.Ń!Xm~Llj9̶F?#J¹2ocWR)ٰfZ`^VgO<,ZwAUSX[$p]4cWQ拌BÚ7SnHGd_^<7m9x9*@>hhӳrfŞ< ;&puxb8w/w{5gaMLP$ST9pL36ib+`n~Q1$=^L^7;`AZ,kv4NA;b\Ȥ aIK2(ajw~)ى`Q$ŵ=n"=xym:N3x]KVW'KNQo)kmF8+0MeN6BьO "sՆ&LpQm^|pM|8nT2#q!'`Qcdв.EBsk{ꓧWz3 mៜn im)9qb^cV9lm\{O3~sK/P x8kڲЯRe u/lA\7 a?u;R@Ǥra$,wl׾lxW&U'E&[{Ҧnc2 $;;feCsw,9";edǍx dЭtBG92-Û_`/|"}/Jk$:ڬ,3G`xy.bpyj1NqZڍ`6Vri1y}ER}1xi zRqql{ sh]Xחg9jӆ+A{I&-wu aFv .gf(? U`pKiyUuuE(;b6*E\h"x GbK™^њԘ/ޙ%:EW甿%$ V/YCb9,:XbQG (eqB=.a"Yf|ƊN۠y0"C7vzo?c١8lgpu I&ߞ* fL;Ĭ(@sC#&w+`d"~VX*&vhlM DA)PL 39XOe .4k#w^nv2jڃy- W2zz{ }\HZ>d"Q~=3_xI4 ʉ~GEܛQc:, ݿ83GҴNQ3[l8Z.- ų(Px(݇X_ΗJ<`菍B4 4tJ㮺pVB?izWYJV8` nCYR4`|H(>q8ЯL ;TWbG`ە2O{0NpCado[Tjle)=C8g~GYZvWmF.5|bXIrdZ:NoڀE:#:XbC{ k)(xXxe1 Is:ߌ)ߌensg{GVYa՝MŰƠ$tB_ȼ֯;\o϶/[Ypk=֮k XRLVF\T:ttfNK)I*ܻsH&!= 5<'fC1=$D*KR*@@5X)CMÈM"٫T `V%ETxɖ*+]`1-,Z1QLצGu8}m@7c,^gg7iF\D̙S&]wo#Ko7͡.仪qǎp:ə(Ѣ2ԥN3%qS0#HEdgQR["d ݡoV-B aE P!gG ZJys3WjCpC dN;h`{̅6kn;U`  IOqѱ,2ۈб+3Aװ}49zh3K3A5Tll@tڂGI)LI!8C]b:rHn(bܪxz ?Å`fݓmaZ@uKiE UcHUeSsRm?Fv \陶*橑ܨxJKX/bsα _$kTCiZʔ 9\]K9;3K(jD"HHXwU䘠q4Hm|s0\KOǸȊ>8 LM_H mn:R{DLsTT'a|dURw*~~ҩ wjg@gFAJw{Z0o\GjQ;x(IgG 1{ #"\lǬ,kxF P\iwƲ+kU[$3oR;}6۰s^%<6t^T#'5oY֕V헃<6XagƩm1u[%*cx:JdV9]/}5  =M()[*} qKnvo d0F!,.e<1*|efD:og:T+];.սbB{_8 '"k}ptU[0;^+A֨bAЭumҰ@+}<1JD\l\_| pB{ Fp2e0pNoGv\Sis/qA%y>>.x(wE^e3Q!SP$io9zP:܀Fb@Dq O)w+'`yM7mkecV7k 9G we# KUV6_xRP2 Z"1ZPsq={JӺh-$TEQdl|8/312ulxGzNsh #bC*[j[B,;[#,Ig?#*hewX -Y֪D$ɔBZS+SGˊDSKfF*ᕩ Pr!K\n{MMǴZcѺGS2ipGf;ϔh2>tWFLPR 4;Fw}Y4rkҬ9 R(b6LI _+8s]*LI݄z u8 ug  +kqI:d=ρ Â7^k(AL`߶4.,S,)#c'yAJfJiAb~uY}Ry3x&l;49ˍeB(e\NUk]?7s)m (jg Qߧf\I2"Wٝe4;8';S-Q./6:-{#/Fv!^v&*QьV^ bdt;/],c/77O$^499Y-Ö As tH?`٩!&J\$A'+^5b.fsDp UT'ihK[\i4$_ĴsL@YUg{.F?jZ &@9h=Ec!Bj2oKA)1g{'Y:V#|jȬ\QQΕI_tG\"P#ua*+ *Piɀ5/7NvKҊ+1☼%q^:n ,]g/H9zrə+V},/5(`'Z/vr9n #'WKI!)O34/ nm]nMd0PyNqsaY#ݥ=2IÁrr֖srof{PDpGvp9Qˠ5ż)y0 O{:siô]ݾ=0Z_HZnᛊ !3P'č^sv3;9%eI\>i$) ُoU-U4䌠gqTJQjVo#6_t3Ǐ{GA_8uWq jh)B90 }Vr\8VZx=d͢˨׻w_On. +]ϋVV?l㱍p8ݯ֣_@mkp5gKvMqV$p8B_ .grHu!m&:8@T-QiòJi\\]@a}F^ۚ1bd`B_G= aɗпK,3bY*#[JÑI~TBׂXh+q+:J:9q[ QLd, [$B̀~ X3,Wxv]+Q,~m [vÝXSϫLSrCpk< 6 -_U)wD#Ka;+U-3ej5g n*KBD7榻`cɱ;-Nm2_qhº>= ꋢ`_ E1Ty%BR;L&tPlK۾D<#πA3"h J[JGPQF_jjzc$Bڟ>+xk #B,/e`~Xʈ< NO/$j%Ǡ? Z;zb2;dz>KPQ_5"/g}؟^˥W|$SxP߱nBH 1@ k5_o"PFs\89ʘxB TKIf!HeEUau@ƍtVi_aBq06y ȥ L[2y{ϋfۭ|"7ul_qTtsh1ϸ8,PYRmgb)b͵>0Mʟk:pO}Iq9v-ۑ)&+8Q"pBNJIo MVVg$`]kğ3h¢{A?_7ⴚ$T[w?>^V vj&? GθlL-+ UnF73Nֽ-(*F?M'c; [3x R; KSĬCo ~:A.9ALvQl熘۔W fҭ{n6fq:`=Tcp3NcxQWX޴&Bⳃ]?Ϲ׶;n-v!KJ75|(S[ijj̡NS[^$pDe0_K \(+$ ߖ_aֱ䄯YTEQUs$ecʎhqIɵ;ɮ  ˥f'UoM:o*@sn̈8&wҷΣ\B_H깿ݍ3^9uFME;h}\͆bǴP5dA{#jGTe7JwD}N >Rȁ'UI3Dkc|)%E`?jK{u77G^Frȼw]N+`u7'% ?6ia5(#Tؽ RR𗗊W ~,_AϦr|ЖtJ ~5_K _GK}qU2~JjKHbcRxw.Lر#R( k EY5ڗMvL`/ c?9ɲ2>/B/.R,}s1k_G+;;hB!XDh96⦰ڪ!"m.GǤHj[RzL$_䠓m_~xWV'dfPI21G@Ҡ8c^RO*""j=-ZӲXeЉ 5ES=!5zlUjH' @'S~%:QװH *̱6遺Gt>S8]!aE w' h:\eTG_/=>7nT@r@9tocЫ0^S"7CJ|LGi˱NOvS5لW@5Y#Z+O]UW7O pqx1h'{ 0Arr* m[=6'8SD\S QWn@UY9R-ቯVuV#d.Qi\} `:=6MtC˔/-u: OKӫ?4֞ϩ\~|?u,z4ň#H$Z/{d:B-n̸갤tQ&?N#g$j YYW{Z$&һRV)2r׾/JϜ֬o{M488R0=Zf%܊u2bܷ-gІ/g4 R0dqi Ƒ$DOL HF&jnÃs7Qi'`ؼf4M9'-Ö5B`AEhtр5j.$,)ZV%uFтxjK[ m Ќ'a!Bi8z<*r*T`]-ճdw մХXD#_0[r֠t4spءThBYU 9M|,a)Pc"ʿrO91~ HW' +G}J" (1N{qUF0Dbs|T۽\m3@!K\ڨ4-vpo4{ O;"mѡb*UÇ"֣2152:r6(9< -t&Ei< < [ꔿ:A NIJ Ye3~'n=S5U# 1FJM.HxfPeէb h4e.@ʨed5ӰS#}dO=-fD`ӕ :6VYO]")la8I+Nϡ_{$62BFb7:d00{Rq;#-B=OmngbO x {sdF!*q0;28G.(vӋsݦ`%hs17ivVVF3K&:bEky8.$-C^$9-{3腈VTIͭ#iGiHeh7 d I NV *I!*kqs>nce~\H:|:,fJi)w/ש5N_G=Xxl^Gԥ*O|]v6@gQ6hdm.ml& L`(m/^'6Yca٨T~شx]y;I'7V!+t xWvJu+ZJ$WGL˨EEGeZx*bb kCqL >FWd,LnܶJgs{\K Q `2**F8bѺ#hNhճg@t49A\2.j !q<h "hw&`cdNn=˛c T̫RXya^xbp^Iͥ8a"LF;w MvgM_wTnmhQ$ĒLmsVlSQTed(7kwAczPՐDo+#CL.zvt&Z%[6&hڣ&/`WfWqNS\ɓvvPqezAhw炢F)tdk/WvdzetA=^ hȃ̎!ڂ+&q.X7 Ndݔ3fP!M:8ЯПa}>sa|!^JkHD[A#Y\Ajݱ RDOLLmWTAAI?gMWSH}XUß -2銊0fp1g8 /5+~`]3ꋫgF] #}&H"6S[:L,V0Αsd]%Y"NS5#|rC(LZeͣ#25(-ˬ4KAЅeVjc=da`B㝁|/ReX#yH > pn%DC [kCx9cc`ƽLQP@Jj3܅ ݳAz s K<6gߖ+Z7&2n%4Is͞bÂv`W9Ĵ\˽qr'.cĂc3B$oҮG]0@4N TN;c&PGͤOEt#E>~"@VI?QL.(3~˱>*%5Q},L@h>%!#+F`d2Sc7Iವ=YfUXԦplw Njtw -n۬`)䏲<]2sc0aq1~il[Rw,-\?D`ffY;u<#pÏod 7+۞?ח^!YywފL$vU|X4`fple\`V$TLfU.+S7YpT71\ƴ0 c M@)>j^1.)6*@nCyPr8qx|[NRqiY+CFe)Δ47xmľ_<y9mgm|zIIsR;cDl2@ C/QrzӶrMy.Q!_1]iKթf"K\bzRK`'#6 x٣ a vb1aFU뿫0tT&T7tZA ތʑFTKr[ ,ܷV(r8~&饛Үy֫bBR;i]ћ2΢qu E.?E] 5 a9w~Sr3A6N=R70aJMPhE-nX4iq% AZ (=>({kB e)g#Skd) v22hA6>/j( aOϏ[l3d(5X&4݄{m†4҇ڈ5hkG?dkȡQig:WW}\/9M$f?UV)ׄ?<1M3k lƇ {0jEyk塇 LtSuYɡy{j.8v?"UuZ6Ss!auzcRNhS+o! g& /GN.7<4DBC}xY0b2K,]2l\tnࢁ \~"XFKf?z0y@Yq7E', ?L-ο! BTE٦"#SH+oX9w}ɚ,8?.!H Z<,I@W5ۑ演B̝3cSl+ڈ{g gr2k| tTSңH&(a^MwXH>τ/Dh([H1`AřӰ䌬@>Z,4Zx- ?fOjN5ԐCӛzn])4XqfZKWv=Q(P6dC&8ҫr)1]ODc( g^Ҝ'624!OU0Yoѕ3 B<l=<*P͸Jޣm}|:󹱄4ДLԔ=l]65uw_¿Iph!0Bj2x4C\HzI}3D)7Cᛘ[tfcɳSɵj;˜}"O-|.<5wz)ob>g#?߶ԫ*cL!nDh +U-k *Okz wfe~g`5> @Ol/jgpEY6 ʓkJFlV5 ,@<(Twc߂iHlc D7xA-vn@QN !{!՝ecR-Rr4M9΁N5 ԗ Jq]~{A2vaQ*edn(C-lfOv"և5.dIdXAMIvfSaw1P>44z0U KX6Ji+G,]ʖq^6S=Bs-p@ $ƒ旛E 8,7=S];>W`ٿ-.kk.jh;,{8>V*[!|p.".߰o`^!$ͺ{$lmKFgyzbGǥ${؃bQAuS֓\*#FzX'y"4~ Gm~0n!մmHmPrbkHF?eJp/:۫1c+(ń M#cy*[-׷[*c/Y@kr+v%fepHշo;CAzIm\f9>  1T)f^bJZq`Ya95"b-)#OpMKv`71Ks8%S:-/ q8+Ŭ.ī7!&Qw}zC Dp6. mL.@h 0w~DrAQSs܀k}0"KA:@j1gu/)B';&c3odsG$g?kU lsK'58y@00G|Œ)Q1[IuoI 1Jau{2vm>}qPl䧍"~Vi+=Kwm_[!=9# Ewu']=&7M$ dU}ijk &/CTpUTwy< iֈK[_nYJEWQl^$ږ:![^:YË%T2ڐeۘ+.^39>[+ ٥0hl>A3+3)ouc|ចE?jaPQ+[$N*Wk & s" (:BVg[z.09w$rsX3^ZPL+ *~ϒ`{SB3lŁC݅F$RTwEF2Mf9lH/08pjޗ1 /MurNK Eԓj* B_wU=>s0Y8o:t:9nz~BTN Ok -* p4 RY(|gETuv爹Vсêaqs|hi:e{Qы_!I̻9 V#z9r4}v.w*жC26A[56nnM6H񾚺u}E}~Hߗe,UnܙcMe-FkJ?;%GJ Z[on(VO򴶢ˇs&xDE15 ie)dxBȍi~60ɘ^=#|,d, gx Mф5x"/bo֯JmRv7-{s;dDFH; Y{I^uFFf}ZG4ЕK3ʂGA40"W4f Y&KVۻ7[ *FSu=|{0'f^]MTq_Pω$:c@d$xʿ4>Ah'UEt~.u D6Ħ!5BVG3qik/@X2㤇;晚°AFNdBhf"[[t͚&DAn,R i+݄!`5 c}t43؝A Vg~GXgUI]SM쉰;HANV{YLx'h:GG>4BvW;*-uA5p}v(%T +`I|Tr'(m}EplUbiB D¤JMA*Cr$[wbp^X <(xH-fv5g3fiQO0lytHz]f0*[*rEoBB^e;ڴ̲/Z,SH2jg? (2i߭<~6P6{ قHfArfV5n叼bP^BW<cV.B&r/-%4=& cg2?j1 U#QqndqD$/sq9mq@ IZWIV}vR?S.TnfoRE6Qۅ =QZ8tw 1qf\6?e$H s"Q_M`(Įt@Z~8@V.Siޞ)G8S*8oIƎeп~g=4b[aƼ/€Qn3]SsՋ譬wpfHqsu/$?~vBw,)G4|;Trm׎LiѾd oj=ZӸm~L ΂@瘫Q( f53ٕŽk?/xJQ~Xnhvظ^`S5G$|fOO߶G k(#r!ꡗd )/kJΌwQuE!^PUM}CӰMtIpϽ W(Q Ii/%0Z;*д?36t *, K/@ЙOP%I]#e|aG)/2B 6c89<#THp *BTT l?>x7\ 緥1EU B+ʴ ئox*G|䦵¨zR-os5r蒱F#5mtWWM66lR4u @,-Q+ǛR1;5:^}PY@AddՐa9oqS^&tߺ+Ii c}@t\7[7#~)u/@V7[gqa 4NJM3[ f.MvV_,I@l3:Zn=$qJe Ryc![A!P! F_ht. S4 Rn Óʞ(X-,}GSh9hQe4mtXFfAK ,A(fv^TL?$)}2[9ϴD cWBD86XeE-p 8ޘRqiIpe(Ј#UM/l/4'+O+쌼V[RSA47X g{߿' SINM$F3_$|moKh`bIBv)HȏFv)5A?h9U*%Z=V:"2+֒c;"|Gf^pkOiЗB=!v,S0N !BKl. 2ɺ6E3% >L:}J+*I $JǢ&4+C2[DXN'1 >@G{bivaU2xk >]9vs~\A xi#&0p^l} uWT!] ;gŖsGhr\շ5l-v!$)GRt^tyezoGy'yYo/0SEsr}edR%#Xyt X=Qk!+C\D@[::z ~8X8Vnt۫֓+=(yŭHΙHou! Z3D tƴoy*փ0rPyK;7SJP q\:0U)YxLmG6z< o?Fv$lrvQ~9޻="d1|2tOh7Ji. ZG$m {iRp9XBUCs+S,)#'9y_ 3Ogv_!F^ olKԓE2_{bE-f*3o`&jJ[R?oav'uQ%i^X&OvnJ#X|SS>@':E1{*>杍0RnC ȑ?IбWa~Ӿ2U0;z*ѕmo ƎZ|'HŎ^.6.,ۓN=w ȕN'U yisuIg\ZٹLx*Q&g1.Me&Q!+s&T'^ڥ0q*t wWD3!ƿ?d+;U+ P,!>uYhsw-4KV WD(EVQVt.t{O@ +Vi2 "5lV1LpߧxQCK>~aZP +#e:QnƎјTD5E ;쥬sSܭw #WBӘ~夰B7hc -vS@ӔY]Ƨ2Lp/w-g3.vo4k 78­@4qf9t#k?nć)gmR -Si!I03r~.cK\4aŢ1j"V9;IPYh4JS 0bfgW!O~+ZZUi=,}vi: l;aHN=Ȧ0F֪£٬CcIG_GFwLg$ܕ0UJ-/V~B7 wqZ >w4`sLAj7d{@I\Poz F"h'XfL{JR u,HI2:S {N=0jXaGZhp _E4Sh'E4"Vbd¨5s]dzu Ll{qQ- }(FKi| < f MZ@!V/epgA.W)a 5{2Yp\vq2C{o lLdU9zEo=rȳ8}j#qUT^JԮi)֭xdo!j&KYw{~6*5ƭRWKh]M,7V*bt~QY]鄼!#DƨĞYܽ=0t 70[T=&ޏkq[Xd};j rT?@@W9KɱMGk.,q.3~;ɻNv͒.D(\Q-% #.Czw`4*3NA6j jˑa-U#7=v "y{ߧͳl@@p kKHxj>){Ob#C?НěC2Kyg׾|};A@2;+=-E}jxpY/{Ͼˍp=iZԣ_\JI4deU R:m:嫈|HtِUs~a0i>.i¦]aK3}G:At\ؐ+/%!)b35%c0A9)mǧr>OҘDTu@d˓ =H+3%~Q+C i\P4[= '7>é"0#7]=Wy8Hi+&  F+upZ.&Bh?T*}P!}hx4^AB媀9\MMɏuY.\oQ%qsޜCG~ֺS޻ 65T|Z+SY4bq$s ^o`|}F&ZoM,Tp|A`\Dte0=4bSpM`Qrʚ錧i Й!nkw'M%:WLrO\0XvԬ_sb]DJ`c |V`?Ov=JQB^ xW,W$ C'qpї8oƘc`UJ3f>~ghvC@3iZrF~lΖ}Ü 7wa7g~p"z{hL%RD -4mzgmWz59DJ:[+γfl: w#T*;&hL!K;&MhdPTzE#;a4 _+pD>& FS6!GcN.w70ȑ %щ @+c½Ru NAO4,xpx2 v+DHC,\kZ/3I B]ұ&[&IۯQ{?1D3lSP:_z?dnITWm+[xSWcDS}5dҕfBupfNrg&N5jW%2D (wUUN~ޒլv |+_[Z@@;=xQ^Z(ڶ%u2MMBOTފ,i*WZ1TKr@)#ST xͻ5F]Kgt[TD:V_Baq_&'ķC>09QԎgL+GV\$t)ۥ[n#~SVâN O*zq ˫a8/L-(6%ʷ&lsAN+`$,Alq|q ֭Q 3f=/4SnAS_@s_XC T1+E*WѣAf!D'CS2h" Eg(u=޲cWh^ pwad' سuB4,dթal{X D0K GPokIJ+ < d +^1j'Vc=S(;;PH_A*%\4O'19*-8%UGzJ;VeNDZG/{A>eV5"9.2P /4Xxt5FlnIr7"k x4fzlxfXuMlCBۺeW$ųz_f-{RB,ITKUq!EO-~%ZrH| >Ų|YV6" P')qz9mco G.U"gMpX!^ꋖ[Jw^Rb;/dځ{rx~!"׹qkQ~ef֪e ̻ |kVթRC \v^dIA&',{ *2?'{WX6M/Q˭O&11,H5ծuH~Js:6N(/'HB)@Q۟%) zK' =L3Zt\r?^9RҬE* 5m/p&a:,窅vzK 5^!F_FYߵg_=}50#ޭyF2a/@2I/4lW ޳Y>lѮ̺q_CC^i.lQ7s=mx`|bu{5#KiOm#Jm6mםW"9f[Vf'n!o%jd4AMf6^(HBEakw !Ŭ7q:x |'do뎹T^QUCV9]YK'elSW9|jsL7YWʇ:cl-ڐ|_M7dĂha'$~ruze wE2+ L5̦>{׌UDEBu @ +'jLkuDW遃rU W)X"Vv_ uXuym-)wm\!Yk5Rd"Fy*XB&fWLz 8 Sd»)v^ŋn` VF@_C3=˺6ey5ԿCcAm@SIߐЏ:L&4G*5-aiǠE'fnif,/*6Rb$.hxK2$+|I!}gMɂ볨/3̇)"n ^~vU);_~Ҭx)I$_$҅%rcm1QCݭt2!d3Rቤa?F8xeXK{պAoJ;pr1у&lp#*$Q_q9̡(kQ%94ų%?3iP͋ ͮ?ӣ$=_*:ҡiфʶ ` IJ鉖(RKtq~X IS}1isʐΓz \ec7O8vgZ}p$,Z}M$!g#J&ZԊJ$~:L65y bWa \~ڂI 0TfHBA8<>+woj^A.n?{Q[^<Νb r܈KSm'OWb;z O-Mdy!!싀2gr %YpL#묇b;"(BBa!浄#emT7Կ׆ /J! , JM`]y0!.6cX՞+9S&+!TJva?qK4h`c\XBuƎ@3]|ftvRȄj: Q SnFZH,XZكlfK1Jl?'ʸ]iwBT/[q* GE7;F-oOXF~X4ФT4 $nEN˹jKء{5T@ =DFc&xCƧ[pk*ߠ&UP]b t[$j,0~=ܴa;ujX14C~T'b岷v=v y73JIYG'zz[7ĸcCtrgYe߉JNkeHq8_rM0 ֿ`Xڍ(=fs NXLo0H .Ҏ,tuk3kmYS#mn>]FKY{4Ǵ@Aȣn@[+D囙C0+bS\te\lh<'$/WKBj1 K51,ި&eu#YƬ>(pG1Ts7w084N DI^j iDs&gAJ! l8+&+s8_!Ōs3өM-Jζ[|# k7\,qJyh㮋 "B*P(MRab&x->r2w'VE7تqgѿ&/uȢӉ!{ \*dnwp4CȪJz(J!Sכ(by |8&,l2 u48ҙBGdj8W;ӹӛo(j57Ct lBW_=r-,!uMe)vՅ ֏k6:o',jY,gNrIМ,XANj)?9;%:Gu西ޫ ɓf'Zp!P ^((9 JC&_L//P=3*M'5M5B'.T CJIJ'B+geW$g˿vEMS*CqZ;D꜔2E9B@~Giy2?) 9N)1gƠHS;-UK2"%{IUbW]nr0EbQkhE?yTJn -̢ >ڨMPGSP<]tfA>KϕJg`'$);FXxS!PBc1 e~ғH:ӡLЩɌ*́!=ŒnD+hOz3rs'h7k2h\㠚}&2rZUJ^P3zLq}aN^G9W]7KN^Enȁ<JZ=UISsӰ+MAHjקu{ G*E X  <%9x_ 'z0W*.L}ո)ʚU[Oܖ/|.$EiBA K+[g-??@u=\W$p'Rop/k|IV,) Npqjց 'X(rJ[qkB4GN6͡Νo6sWe-,4~qQƕb4ɦ@B"#-#uv,G,uoXFjWW$^Q,+l$oZ  V,K9d, xtJ*opXorw P?<}Dju:xJcUCK7>yz؁uZ*.!ٗ{sp|T7 sP߻lR^Ĥ$VOAd?~ĥU|]HI)3iL0y)I$ [s` ߝJ^5+V5bgG褷,PrwWP~-4`rp1'(L<+<0(IPf U׿tmYHmѐT&,NyV+n*-GdB.OCgYx0Go ]YkDHp;s{J/gn<+NOsc2.%෱Rslx{yj[v ̽Odq}bU b8X )JAxգtؗsZAg,`[cJnT936=m@/縦M3R\ Oj!eA\Sݜ }j;<}@#h^uADxNk%=XvVJ eYDSMQkga[Ě;g?.N<6֬ ByNsQkWVM_q6 …PXUZU"?l$h?J &|hMwy [Oft!^I&֖yZzP 4:X:GFFhK:dY+:J Xn\PĘO^! />!S.Gg_9wDv-." iHQfx 35hQnvJL%5>oJۓ){'uzV٫WHI`E ;r9Ev' w=tE4ڤiFR*!beGBK]m5ò-P=|E3Gh7bf2W%zpV?ڬ4X GҦns5:!*ǂٺ VU>j&4 imh3`ބ [l 3&.ף?|༨ˋ@\/\9\QHW䥤 :[Xp4j;[÷'h1uԶQ.eKfbh6cC_EFh)(#hNͯ?v'D_H.Q.qDE$Lp>C"6Y/ >(y7Ʉ-8,)y_JvnՊ0]3vxݤceC``: 1Y|!|eж2n!0\6HwdCWzmN}e[ = {y ֠P  ]gk{^l@ljW Hzķ0or2u|l侴q5m,0:G'v2%yr²Ztp^504۳.Zڭ׿{|˒sS/44^\pL #>ޘ!39#Sk\D~U4"[`׊mxS-HVRȥ_>5o¾C0/;JJ* 42lƸX#H-}*a9IQ~_]RR/Dlx.9XN'4.=;i9GX+1 i'8BxW&9ox^uZc!3%?7bh7R C|g'ȨZ"[.B;VKŅl-Cg&`Xk5{~\lʦ*88GZA&L{"U$SE-0WQrTi8 M]jMekU;a+'G*rtTP+T+Su =j^v&Q^,vA rf!3\o$'a^pᨅZ҂6-y$q)r e g##%g9٢,W[g~恡3oWH֫"8/hZ(ctj dP{(t@PQA {r)qL# D,͝K/ 5y@h@MY/$ܺKS^\=cT{IEK&s{Xj5HG դP(gezC^sR5= A~8Gҗ|DyazqγpDEM4mk0c2 FHVD3՝Ded?nm ofBhCwsŐ͏ x^E_0Pھ`y[:V= #HkO(W|] ,"%m;R9E=K9Ĉ۪nadt]+5߷.#z< c07+X*ԥ]t7Bdiw*8 `{˘B*{sb$LC;5lkV+^4j3`R\߰R2+r5l,5cDLQ ; {^+2F{̮'+Yb,grPa%L*j\9J=fjÍ##LDY%k>q9m:2Ibz92_6Cl? |y#hҋQv"j2Cw}Toy{U YaA E,K~B/ӿxגFu& i{rdZ&(!yB棜w:hm[r ?];מS IkjiUY$pt2)fwOq-կk"{f-ۀ JS*hmi[0Jy*sO Ӕy ?aT &tbo""滴NVt{A`,l`7 V.1-ogx/:Er0Ź=aیts9 Ahivg/L$ \##,<=[Z|ɵfфk^Bh`nӖ̝ SY kBJmX9 $*բ;CGaTļ[G\"'Ђ(ii'+5( W: I =cΉ=<<Xa,Ah؋Rj+ \},O=ܴq -\O(*tTK%;  vX]t-Daw[sJ XJM DF~zq+.=Z;];v+ lxN!)3 \&=λ#ui^<4|'"29[ZQB k""#3 ʾ-E ;TRGQ{R `x!-Wn |;»nǛSro5t2kPmeǛ65ک1׮{HqiMMx+ FZw1u rɭgW.q)p&9uRkja>j Bb0 BmPzTQ1%'$Zp]*3=S<+$+Pf'fURXcC/ăQp4JkPWj|%iʻȔA**M& XVg 6kKG-dǑHG-N4qC:OD¤Dž7pnj23lߒ9 Оyurv<[dT1l wG1 7B+U!;2ʫ'φx "+q`^^v F-FS|yNq]O;ƠeF@u6=8E*[mThVE IʭcN΋~/PLbI )F.Uvt7 292ϬER16qzV~4R_adOl4,3<)TH\_Z%x*^צ!/L9'\5q˷U(ԦOm+q c!i -F;ڊHh_R3q '8SDTj_J"K#j|nYz4[;oQ4R[Qd#ʺ]W \Rfec=A蟸F8&8^Bw^.R_Eτl2># ysCX~$|BPst,, 4Q ضͲZ_94p xjU$K|农vxe:2)5Q6oISZcn1f@}Ճ˞+أ%s{(z3~X u#&Hxr= q$ӻ8صh,,ϰ2֞#M nB]svmnVkG?EOȦ1%7(pijN2C^\lOu3H c2sYvs2\~0eu\C, uzH:\kr§SLh gg%Q ) [JMW"#?;}' ؠ6wK{$q&|1PR:ьlm 6S9~ =vw,c3:m; ]RYI*Cxv(Ż1tR"v;[KKM[DbLu˶CO (U%~hg'^W2Nbx C`",tt6vz | Cӛ"t熂u=Hî̝=7<:\^$Yge1vKr'R1%eۻ{ԁ#K*xSn[T6.R;PN.{LT)-[(! Ԗv2isqF\o 2m@vĊ2stXfXJomJvlBpH)]0c t ǠjgjʣUAx: V5ۭ>˭IZ6Ubm]=G0rzn٩J[@O ?uozg*\<- $Ƿ-?[gXq[਴Q+ I$6"|\c.s3 5tղNdP8%$NEt46+,7i^%rˣ!Y n`DI}U> PNTxB;ʍńR $mP {_JH TfNTMN>ub!!3rF<AZt"kV:eNB%kGOٞ;o#X?7>JX-ɭV73Lw5*tC0D0 <}Ù>ָ=2\"7$?ө0xgz8؅*6𥞘u#ڼ\=8xj+;A1 i$%g5|9r'&⯕섄E"㋱E}?$? Q "p`*VxhRYh4k Ҙ:kbq*gҁ$;X[rf$<~+aIt 7>ŲAͷB}'̈o  Սn1$K52wgЊqIwOenY.Dl9`$:sNF MGHdfh`[};֪=;mpRWi&1-V5nv] .LU' Y!iƍ0'j/pT,䮩+DD' J!hӜ BD1ݒBc|B7+n(ҙh"Pe9xŸl uL&#|k BE5r<-U6ԏ;L$m3g- a8l0M7hqKz!pg-:G/g>ئK[huzFƷmꫛ2 KGb,5\RDFVB>9ZS6Og϶HW8W ܔk|wXUqƠҸ;I|VȊ @Ԉ4;Z7.Ca|DhtgF靭yQ7A紇p8dHRLlxF|_Ch],HO{t,gAWAL4uBTjIL 6 "EEujX'V=]Us!4N:A 'p* ƶhơ%5x䑂&n `nA`wu #tʒnZYm#ZH:Dwq3ljő"/rв!MԤۧ h6+"!g[jLr ȏW`3GZ}^|6.FZ@ܚ;z簴)9h?@CTE6ZV\,N-¼z]C LҖq81O\Nzf,_Ttbv*0K#1@+ST7Ck22V"le;s.y)qtKcC@R!tn2b\IElYC o,J'h#6]%#O7Ⱥns _,َfkRbQvH׀E%EQrG2m!ICV]\\tv&+ pϡNTNB g1[Pnޚ IBGpuJxڭRc.Rՠ! 6,}6Dss=|HTsdhYԈ:h^.ԴY:֕pݳ[[H.¿)ft4 ,ttFLs#գGY;:GkM'?7zy!#l631ne#9 0E5C=BgcidLcgcZ:Px3(\s KW9m2@d̐,Va МŮݭ=&ږ?t촓fb AM5. ʟ0mo:DChKH.x2W_/IA3XXELBLb Y3 `A@g=m}]|GRsU#5R(yE7o 9PWl"Hhaϋ5-F7_ڡpl> o`Z4߻{7si1AۇS=3tyW!HYŎ?=-M~H1RG]Tb`Z۬t"׈[߷ykEwJ``,4UQ]5+Ӳǻ3xB~ va-wW~ oJ>w)/;h>f $-]1kߤuL}[d$mΝi>]xڄ}3̜mK5^Mza!YBh o>|qW$z5!Kf+Y3 E}%i }5QY/ zjqg..- ZtUG}­';;)ާJn ?,U`8X$ AGzs_~c6bz7]OwA?\Roi,Dp8l:/<3s\]_$QMJ cJMC+)QQ6BC.5g^RYuϟ*e\0(pV ,*r ۥ'y LTA&R'֢4| J{ }8,eMc ӫCM>8~}=0R1._&l}uq鉱 t!*z@6|@?\I4 $M#Gl  | ՕOlQY9` T#"v<7d¹"TbۯHL:/'дJ!@Ls'bN?,%pv@>L t~NLC:J!6pݗr@3]`C۾5ȅs[ @lPl'd@pi>j~GϡCV#2 W-n4USٸ_26Ze|gE\+ Y)KC9RA囈O/e}@XLަ U2;ޏp ҕy.Ɍ$D"/9{X,")KN TAl6%?d<'בZQ´MĝFjgKϖ3L:,0xtGd5H=!H=Y+{a{лfg2BL `l97G@*+m {MBSQP>Pmw:dqKN"!/s(ZjEYItXeg&_JFws 3cQ֛ҁwd xK@r/C]l P4jwx \{o\"yTTz0n.`T`` /Ʀ$~.7em#޴Ecw:FH;f#$x.TQ!鲏oA.dm#j锞O[,r;zgeuR_15)?t;D'{[wF\ASyp@Nb9M,*n+ET&!CڞBMCٯ᳤67RnQ/?yu:hD fH2QIyUækWp/͍Fn&`A'Xw6>kUٟd2pܽ~ƑlZ%`n&р`Wo'ۨ,Ӗ,J8Tj ȼta%h!(93GrP!:.j3|onvj re&2QG0_3|>ƲuX,ΙU;;l )V]zĕC~w,]8+Wi'\C (cIM+g5v_$fІ~Rx 'ݥ2'Yv*8Hh;b;xө# 3E ( %p>\κtsQ?+}M/FJx.m3jz.3Z) ]'~V" (֋m}l+dM\2CS`c&ZJ[6Bboaɰ[UxOZkza]i6+m!et&p9%߇*.ZO=oxΧF_SH>@ pNT, fROs2z+ݘ{+Uņ)?IBY-QUx%3CCEMbJC\QԚuʠ$<>nt,M͚ESՀ}ق}0ypˬ J9fȄ0g6Ly cVU`4uۙ-UE,-GH ׁi͛@y/ q2eڟB?) ڿH2#"&44^G=9eF(6-lbA/2m܊`dpȥnA%yzꕄFUb\lvklbamĞlqIS_[t}!Q5~Igߙ3-V hg{5 Ǡ"ҎSg&<8CfPǸ"y{RBOlz0z{x`jɮ@/*l3VMc•"!ލ.iE␶ d58ٙ[sPMNIH3wQP r}_&XiR*0eT YTE؃ +Z_9 A 'u=,[D,BBtL:g 9!ofʅhR(]n,ߥ.ȅ|fXu.dNnFs,D l nA[r~*Um͍iBƉdLPꂦ^K-* SL |.Ԩ"Ό~A"F$s*u)sLWr95$G n#yI{Oz_>}sIVC{yqaɃ@sz!,P\iڮ9w&C <o8?-;J&Ajm1_&YI,#,QRdFO( 6/'&Mywǩ;t~ms 3}5M($f)U :uI./KBA灳3&@s$KZO`sڬPA 5dA}~N 'as&3jMd#T_!hl LkayfReB-py84$ꞏm)M >2lv޲:Ȕ. 9嫫vA+`+]%EFp c,F[bz]"(H)ϖ94.G*1l <_ 9uca72'҇֟f WkTSz~RJPLa 0` 0IaXvi3'ɥ'1]@~/|/YC9 S,]^ߤR7m $8ִnRkjъGCN6@# xcSU_b|_jCOo] i$/j @V斝+Z^36(IM<̩7jNHb(= ]=dߛ'-owzXE 鱭hJυH|kTo+|zgWM .<@_Y:ȸR]1y:eW'16E]Ql5N}Wn6:gqSˤv4r,fyctms}'dn<#uOB-1ȯFijFQ7ؗ;L+o ѿ+/|Vkl7cEi?ATРsYŤl@f{d.)G:GA"3jzǩ'>(NYk1'AJ6+#VlաF.XX,I/*T@=؆5j/'2;']-K$fjCI69Q[8 -Ҝ=yTYc3 bUV?ˑ.%i;U︋N #Ws"w)\cHyG pW~Z9V뾨$'Yԉq)@F ֋)(e8eG6z]$>N┐0,eP)l{g|鋓Rm&<ϼU4}nX4`i٠0[2^a^?5&+5Wԣ<*vn ;`g(H dF2uPr'H%ڡfAD.03Cky>սe}gZGwb0fb/an3|V5Ljnz+d咧8㻤ZK E߅L7jԬ'Lb4FGad }6/$FmٲMI&bo2"C-A],$_[/WɽhZЩAgLHx]r he`# z{YӅpĵի#%ȍ=.|-\ ̄]kEHv(oSLʼ dOn3~LdqT}v)8}gb6:㲁O$[3:5_R?Ln3rs!V;" ѤT 5mJGdo/O0PZYd&?#2u |`b{7ăW6q F|D Q(a % tosD<냊+Ҋ孴=›U3Q,Ӻj"haQJV ; .$˽%4>|4SLkk4h[ۄ: T&2" +k9R2bI/(P#q?.Ӊ kz Ry#YdEِl;;/dݪz F037V9[h,"?%]^1f X[ v86 Hj-N@,T 9ORM hb4F϶[J\ xjv /TuH6,}#96 F`8Țez*taw7/a;|'F %,U*149aN= r  {tI[YZsN`dfbݦTnVMJ ˺^NʬP]'HM{6 U ǒ߂ tLd&lgS|+Vݢsī|j@t 8@(]yc{9@mNaQts'B6DƄakH۩`x-md|F Cx1~$|{,Z&dMke 3/#?ڀa`MuKέ߄Hw>E"qOu܇6_Y*v_PíTF 3z.|D``r]J]AuJҤi٨"La yIEc :a@$A@ i3C.nF@XmdPW u\?}BxV&_R8 ny]=yt}Nܳ!kcWY֯O/B( P%-'+2*P2y8?4Nl{̓2/B]҇+\mΗꮾ%\!uGy *VdZ[v)\]*F;Btɓ kF }[>)V@zr7VrJ,Eo_ih罢Fn+2q5J-ޟ">\M] NnUZ("Wp:1 Rqn('9=r6|޾2#|ϧ*~4x's=ZPA ;P> AYw>~GV 'f5YL'>އ|Zo .|{=FíqeLNa򚛀"xeLs} Y*rz~T@%$W~:uF1X ?>@؛r!PH/Sy05EYwEz<VrHQg XO V?s(/FQ:+}pyR;#6V2Es2whQ\r2a>J>gsi1e{Cv$?Ρl'.;paG?{ЩK zQ8JDŜ⸘* K!`?954֜mNܱˆ/3MP\2;mje`KqE Rˌ Sc q:i0y ](WpƁ'DaeaFRދ.D9/g qÞw'.zף@8^q1!5֯ JHß`]ZO&_JƷ+'zHŹxd{vI^݂>mu /nkIDLMjL{ƶpL̺/.#YCbPˍa4m%!z$4%v)F=\?W~XA7˟DȫtT1)JQtVw *lİo3Bh45`J D(k*)G{a=#T)agmTK۞r9Ae{کnlB'<)w =Rg7kFTmc$+Ycf73}H3s@mޞ êM̑3N)YOJCyv*8e*%-=?$j a?;4Kóu$uoS_׀Wq Ö\X3΀{Gvũm<`/|>.wrެ _ZEpyFo_[0drd<3NU92劽J(9LDf{4].H~0/j/UúY]Q~H>$QjU_jz!1o-9Y cPnv޳)Z+^F Z)M Z|s`NwTsh@VA\{kˏ Џlr[!E`D14w!Ty 캓L @;ԼU[SPi6-jah7S3TcVQ}"pE^9G?L(pqVbG4K!Z0R<xG:Xǔc,v4`ܶèr(=uP;( 8 t*y N Cav6q\~TӴ渾X VT+ )4K9_^'X{ rꞚ+\V)/d4m4Wc PCۛ4"Hj+= PVa< !Ot(ipŔvtHhTI_pMB!8GL6]D\l)ß G[ް3,OT<ȼڧе^O~G V `X1?. >袁Ӭ(=uOC| omp~l]\!_O 0r+k$ Q gTi9xvt%2(vƻLSJn:\'mY ˛ ZcebAng DL,@0}ü#'DRl=Ѻ+ pc*;ηmds, Fgmj4avR={ɲgx)`m|^E%YSCղ-#ˬw3JJ[`y$O 9YСv,{p[`Wa`%scl$E%7l~r]A8YbqG@d?rht=pYIEYd,aJZM# 47bv Q2%k[ZpHʫ1( _Wf$kf3-cjmP)G/Yg߁cnvw| N'2>V H7!/ȴzRGr;XU rV/8!9E16'JlQH3>,qnioQ&Rsv$ab ,s;ctGtv"7&MC 4~kQSm3M2l2TzqH |)9v7w03:C䞡Q㆐-ͨ*+r2ܱ$zHo%UN3qGĄ8 6ꅁ\^1±~ZGl uX*OᶴNYo<ʡ؁Zl 3cg2A^JX}V@uGي be2> :%!$-ϻ( ۔MW N?IQG7]d{d)3@Y0w"Xrpyh9PIFZWExGZꊸðFwsq[y|S M.EcaulحkLd%|~ݞҍ?GRj-%- ۫G}@NHF<ҙ..zUwp#Ǭ<@'[ɽ}AZƣ5={;d8C=3/mղ"X j;@դo7_ߙr7s+̎f:VN)Ei`-Dcfdf|m. 6dݾ!9WkRq†l'ivYXu>6g'')Gk3wt-pvc6Ǻ9L(F1Y% +x)+}v=¡U24PW1zR’TZ!yJb@u4DMV#>V=ƻ/Ck~bMa"\0rOSHSvd,lmyw;m)R{9-83/խգ#dbEq8Xr+Ut8{if'j=EҡP2IT{i/*]va[pO9*8ǵdKFǑ1V'Z[ĔS sf``0<e斲*{lT[4sX&Gku(Ld}5'M *?"j S4w8ObxtI!~Բz{0_s0Jՠ.ڻmjJF#b{@Tg6x2˝gYe"wKlnIORpZٽ-%UG#VDBgM^4HP8K˃~4HpɰezY߯i{J ޿0%Y2whvCgǻ;FgVXP‚; #OQ˕E>IeI'sK /@ Xv)3_/#=S/ݳ <WHF#֢uMdKn`iVmb`u۾trڍ sV\9ȯ,-ߥh Xb0;Oc"|I;+<_7,xC,͍;6٣^NfbNYk>Mߴ#RuZ6\q=Do^b Fʡj%WhtS),?ۣr<5{zi)ap{sc"~ 'kngg?YoL圤R'jOq`w}1Z4_oBReߞ՚[A(DeaىW+!׃dBq`:;=&DޔN^ԩOM6+{0kﱤy"T(_xW7.*f7F3$vEs`!3 |֔Iy+"RF8vne>:Ucl(5HH>'sJGc%լqrOu~1pěa +)nB(d7%BWAG7PSz<-YP]v'~K60ҀS$Xz9c'Q RpXL#~ܘXϚПtHٜYy;='㡍}%̒i OV؄ 8ŝrL|NG5r(iY.Ǟ[iv]Ɔ3q Wx4d~o}:EBػwUxf>{2"32Y" --4jMpZ|$.#Zz%Įj^%5&jAȱiC ods _h cp&a`r~;FFjz >^b벪Kx)Xlrǫy3ؠ_U*8 y TsUb5GM[-cQOBMZ<u/kKW8$V|L9OOOLkf zB*8U!2ksjں:Qq6Áճ%,O _=@TwD7џ*e!kh 1Ԭ;h62Z&,Mz+noV:,{V)Yk2߰LΫ|L92q k낯_`A?z]`6G`\NGf 6pY8W Ճ_J'r? qsK1Qw]/P?1ujhxQ L -vA%o<@1mnBuSZ;,R ̽1hSG$E 70x[Т mgXvny q`1p`' 6cQ 'W][t1Ş!{Fqšqocj z۳V/}4oe]cr^/Q? ߝfp]5]K&Yujk3en#++fiwDLN%#N@VEGs:~da^}`pFVl`]x,ax!2 "*b8TicpرH#* &558OY ok59jXB|tÖ*'D}{-Pa={ 9Vǰ;vSy.̑v0) M&shٰb3  oOlwm2i&He?'{%Rܪ mIrWy"`9Į@T'ۭ'W/W{ #}Q7twuĵ+!cia N@).ҷP91JYSۉxлx}:!7VElyڣve J7"JpN/ZzhcJzP.!VJRhLy(ڞmZ q6o8Pj+%YZQy%zґh^ f`^k+թn6squ1wEA.OBrrh# t4G~rrcԢAༀvcc9{ ,vE[6sVkxk!:) MN֡zˋ\|4@ٮ@mݻ"8\v#v^dD4Dff340:4[&½ *ˈeQIzco"7 GFEibanQ]hc j4?Z1tu=ۋ^b~KtqrVR瞹 ~3ŋ k|?%Яkv#~S̠ܨ»6ȡN(ΉƐ(ƒ ƾW9Kv]bpZr1uLX}3bQ̱GҰ(q໋:qm:2k?Bw^ֳ.PN~Hk Sxs3HNVՆ@e#pB_HK-yy ?˾tZVJGX)3ɾ(n;<'7hvlf H1‘YK$tweڎ]iPŁPolhHϫEey'󂍬DwN߆TY4E JqTYhY(`9wp-\ л"1&\DEiP"MO t9:t[o׉eG^0DACYx\)FC1y AalERp,D%/ /oЇQ2H y;^ "M68'eJtZX欬&AKtz%jP" 39s.r[99` - wa!X1$C#wI:J8=*l]uk-E K.eH g#Iڴ(5&nFdW t^΃[;S|FXZɑL$65SęxQCU$\;kU4#.#d2bw)&{G ZRVuTxhuCxҀc>jhX%Fޖa~$udWYtF&ܗ?CFuTx5(]nfȫen/;oU):L/-Im|}.RDEvY^x)P'1{ͅ_ÿ0[jFm'd8]JXR CˑN<4}$F7iA@@ B\%ĔKz=J(l+"cdDv@"9V8S݅S#:.˭$az:9^SEYi\|{#7H&v'G<&N!fE?I2qѐǟ0phYZߘŢ;w{FD|l6?OSظZRy/n>rSu1A;~?zC6b趷8/͛ xeϮ ѹ9`cr+%@Kc0499{ܵ"igo(~;#F0@%l{eˆ]xQ`k{ϙwޯb{$Zu'&HsL=<‚U:Qֵ[-D>~> dE{Ӱmyvdeg?Bo)Я lD%i\K| iipU=;(9 &tػcO؃[MOc $%<Sf!!FsO6(|oxַ3TO]Ҙ=;0_RGGr~u)kr9܀V` Q*%c:xIEkucu7< zFgxM9lԮ|>^Z-SW_Ghq.9ѷ-*8Ҽl%%7)/L)eF؟\q_dݨgxzuRu3^a9F`$^O~2ӓf5JSGtj_XD9 ^wLZB׋fLRvOfÈAz2eȱMgm?czx6HT.bJ|2D l22sZ np`KXG^#*O>kueXƲv &)7qn7"Fd'x#w,4  XFfJjB_Ve[X"H5>PdXdSd0$4@`ݫW݌o4 ^ov=}0 oT9ϢR4'<3=ǙQ;߯sLKbc]HESzj\WQa3n굚[Fiiv^>eI(A#w{/ie1Sd*8ܥ0  Y4^,b ;q ϘVn^] /*K}"8b^M1<iHYiL+7Lp[|g4~vѩ/:zu ql9;/ߥJ:MNVD9Wcm:î)6yCQvt|1ȧBSd5?щL !eiPY#kl@'x#ϳf*_5#*dF],1ƺ$B*sNu0 ϙ_'>و8%9=j2gϼRȍM> EΉEnt܈ӀAiIWy ԇ>"vg7gҺ/؄@VT'uY ^L|MI&nab-Wzo 0Ύ]> 1ӪqH*rԟq;}^VʹJ`5IO8Ozx-p*ԄQwךVE0^Rz'0E8\9TTKgrZ%ς x;oõ*&/_iưT_nAQ99gNTM{i7iCV罖mCtO+ua0MCF@9>*BKEʠ<>0wYSKd W0X)[:WW腳pƨ=0)E8zt90Y=`exQ馺`:JRGG]W: OnCN4XAs0,C5;yeJJ4`&/T~u',’FwXyWik/Vnr׽,v)MME(Y_/UBíJ\L6ks0to }xC`**oF*e,U7rƛ5B\+@%N8zUaX7ҾiugQ3!qUp] TEt7~d<Qu!0(po%691snŤ"G˰G0dxauE 80^Θ;!+1R#MfQx&D o<9S[\z3jޗ"ݨ4VK`;؄Xt-= $j+T(9"g,ZL>}R=fEDDu&ZgT,'ͧ:YqogwV׀&CXNgŸ+)G膬Bs-EpŨzIE[5..p,bD`i32t *JG} i*rm4(كH*UD-vnx*NQY/[ Ⱥ|^ n=6ti#~: USHi]9^D];5鐐%" ;(AaWHVb(Vc?*L^4@q&2A&>SH9Q9^q%ɟRӹ"С gF#u4j5U^GI8ce ij5 "5,G#!{%Ӕ g$Qp/pF #Iy=m`\_?qKǥC?K:b`ܡM?2됴e RvۄG ¬͑#W]-,]k{ ԣRB1[Q7ܚ5J RqVk3,7ۙ첉ZMkKiNLUhڼyR0޸3>3+LW5n2IYHyH|@ T2Ո`FlP> Z\Dvalxi`պ%н\d<\UzX̉K}BCEa!;X֊LnϙO`9x0QG&ZZ&"|YhۤY^Knas ;3jC)WWH ]V@ٴk=ַfFD=OACUshp Ja"gDlN'dNWGߓ9X"ψD'w:3z+84V~T7N}X)4EJlF{۾+g9(,2H_͸q !{0(%, dc<ӠZmtSbvtc6*.Mʍ]m tY+,&ޥphDeKvQȺw p.Wdkk\lVɣs[ueb.֜xwSh*` FɠLPcwO]An .|)NMo{g!K‘.G.JE%e][@#x!?JA,KduOіzD6}M0(cSC"Ż\3e s^EXe1If@3j`Π!~j䶔@`o/@Temw|!̔5 v,H.cBwۥ>paWH,[?Q$Xd,8ɢ$kQq`7 /=ÿ(@mZIE**XuU$,T|Q$HuRXIKS!{%Nf`Nul|KZ} W7X}!)0>=k} O^4IYZfOmmճB1*^'Ta3!cd6pR5f ދB] MRn(w >%Oq:rdffhM+z.@t#IJވ άu*}:U/{h(ghWU [O]: a oSn g%56Z6j>}ʋU ;b7G`RmtYq"qz-Ы*$bOvRN?KюqUwfMVj)Fx쵽Ƹ8I̦jim%&^ԭ}oƷZ\Z.zR;w8u%JhmYhgUERmJrO2~6{Ku])5Rw\R =4(-z3-}9\l*ȫ.tJM%9}k'9(ܯ?Nya \>8B=½w{ Ȕ"'0uyf>23,s]-uh#5@]Æڱri^-tXIzrq }KaȞ@mF1Ik/9:ъMUpBGC.8 5}#%ӳ$bޘ>?ZwSdA(9 S| 50&.6,Ev"剓sh$"U.j{9BDL VqbA}7ðk[÷Y౯PȨ5O;b +@Vh/·ʱ9"] jRd =vKsaxU>q96)1`kduE3ϽQࣟe@%c>9 ;қŸ4 eSp64+ {A3 yc;RxTFc'"]51K,( $Y=oDVD (1?ɣemxy|cTr#y!0I4{Ŭ,!ED42~i6m;Z<j|{W."VҡoUv1H UrYٗ%C-L+wv|@[mXX_0Y u)QF 8Y"D?ntj[T坽5}(9$G6IЩ"^>$ j,@:/h2g`W²3E_/LYa(Rq)dY@{yݙYa(]m$u ]avgTyi,wdoդQz[\}ZSNFEb3߼b 6kV_>EQ?a)|1\ FrUʳWCE`\smrb ۍ%& 4:ikΥiGCC n6'UlztlIVռjt1uHO)_XV Z[@A]/ 5yZEq&zɯi׶tߕc') á~[,9 Xob7>9$lyì,0Z6.( Yt>DVgZ2,shDdiw Y3Ƿʑ xHufNE2Ta_gKt_(R3?tZ:KCikp{-w9zcG: &޺b.\9 )#ȸ 5dXrw8JcB<Ѕ9Z}58-K9~;e|տK ,.e+Xf'>}a&6mS`4 U|x͌7XTf,*NV$&E?N|&m֞W/Υ[u i On!S/eTX1!ZN'e#xD- +bSD2fsD]JgVW Ph+^IK-XȮNfe63'>N ,wO7"V^J=VcbY2fuiE,J PQٹ&G@fq0V2!D{)xWÎ.u&`dlCmb9 ? O#TƻJy)X 6%2kQ2`^~}; bu,q[X:2ZO *FǍ );5\kԜvPLKknezÆE Pנlrݙуn/a[1f~ qX`C;01L:=WSLWk٠~Ќƃ#l$dvC 3SwIPFȯjM:'U-"1{]'Už:mb ECyխj-GB'٠XWxz x$_ͪ˵sv b/Qbݔn. mYm^rݩnumz,}aT;?ՈZJ_-D{uD,)}dGƈ*pH2ABf[~V"rQrTCT}7 ǗOE[CW^&BnTJX)w;P֥c=t4?Bs$`<H"zTbǎ!~4Of0}L!Og{퍞~hD͞~fEB\Dɀ@;HƌYTJ] d̥ :y jԾ41|D%1S C;q0ؖX #y ҡLHh.p"^zϑt]m67c$ ]"ZK25Fۆ%<_5} i@vpko3Jdn g'*~Žɉ*z]Y5A"YŃ*ח' Jc !`㪥άcDt* b uwLvӝ~UN^#2UN"(] <xIʴ}_{9|ACW:EvG>sk! /EViM5ܖFG"ߝjl$]9v?Z>wb:?~1ʖ]dv^QDP{L;~H5(VZ`D_TlKAۦzV񄴎*RIYb+Cwޜ{LM;utvw#TS&'Y2.~QZg93x_αfnɣ`W:^#LV6nJ^ė/j=xiRc96HFk0" ]EGbMwW zy29? 9R8=SDiS2)FpsE'UN2AQ7YDLК3wv3 ֲ d3~ȥߕYb^;GMgC %d|Gƫ05 A-ORM& .jْB.'V9!-@NPu>l$ ŭE7ʷ:zEύLJV*^8m=.r$GV"DLTE>YW/1/E]jUm.]ʮM GVBypf'UЬY%BH](y/Ա4w*q 2WC#v\GuGB"ODzE{YTB^,ç 1B85 >9]M%()4< @ hmY,vw0D]G݆dM׼&quSjF]ºe3T Ƴ µ0\O]' bKdy`vmFݰZolk2o߫s}$ I=NxR) HR2lf=' FNX5g{P[sX[(H*lhcA2AZBxN`Ha}(ayzJ Sths01K8?;lxFhM?+D &9?v,2Q'iX5ʱG[%Sd^5J+ =Z%QPoIZ[#CA@ 23xKK[5Mnw:V H2 n9jTYѓo F*2fza,d,u#`ʯԻ)țsw"jأܮ*"*OjDłIg 3fUMRoۡ_iR S{D lV&FwK,΂ZKsr c[{:~ҳW\1KAr& ̨\@0sW7y8`L(Ѱ;x _e@7p&2eR3yB v4y&PkBo84{ɿma" :&`pPnx|z'f/o5u_^lu< 5 ,ʇjhj,Y@hC4Ae);iN;Ӛx>BKJVk. )?vqMg'{o)RY{TA.m߿kv<䪶ި3v[,qStvJ>#S p}y67Pg9".j_I؁,7ye yM믱vLX^wl.:ߥ iT(17)h1pu>*ˈ+me9%mדZ; _Sc1CaS(#+N;_3[:¼ :Ը/F 1YyaX qkD!_6,`nuN6ڨ]AʟfD0ST9'=g^ڋrt^9s7\S %$R9QyO0z%=46l ȟꂃEMA1yNr~ٹ#Ո_j"r"fݿIo܇zl}j0IÞ$);jhʹWhV6CZ`>70Da%'s|dGsBzVofn┖R]w'RaU&[zY[_ܲ'$#j6c/5/|f,ӎMgvB:h2;vTkoxTiUvW+g|Y=b?#hHƭuswp"x>d{>>oG͖<7L+RaMsxv -j67rЉk( YŌo{1H؆Նg.Baʷ3 {WSw1\'R;z||JH \ij[6,Ww3̀$x5n'pO$,41 4 9RF+oMeSEGҰPVժKLw N *,=Qu2*KO/: -G2<7 t4+'0epx+VKkyD:\`'/XZS_o,Io ۲9#;`MCeYԹ)_WR|MP[K'*R{o}3,({MrWӆ:0B/:չ _ BHOiO*l=~'sIT [sMCdo587gϕBڊz %&<W l;u,6qWw13 X汀(8blˁk "_ !騞0|W0>>l_UJY憇x-5k I~H!koPcsSP  RƱ .iBH NI8ʩbe@#VQP~7=iL9|5SBԙ7RQD뛞w:SO%eRU\󖬕2)q*-}:50D RR3aRu>2':KT3(^f/QѮ>l aoxFDj}WOy:bT%d l1wuUAŌ@4{Ak)b;AzZ?z &?b?ow 4:n]Nm`4b(EmBҫ \vT&0F} ^ .p9VV-ׄ0 ޱheN!'U ~mO c+7{Uӡ_~ob)?ZteI/wPvǎxꙗ@{UyΙ|,:<:}=Lz9cG6uNGG v ºA:,Xl8C.0s1 Mz_Bl=u"-? ײD.ݰ|,|{4rry 0M,3{kWy*yܩTFʘ=E@8:O 86da#ŃC=;J*aMG͇xA T V f+TBʲ$=TC(Mu>ĮQl b ЭD - "]I ƒ FO槧즟P7YJg|-gMh!ĒIc(r*M\&4ݯc@χNo]Az=|>hiW#* R('IvnNS6_Ј[{8iw`(1 D?9_D Vʨe(7;`BD\oW45g^^P>Jot@_]`۾g!3pK0FMo 6N7h&$]@H9"&MpW=v @^F8]aB% r |ZO41CTS @uN$Ahang"ZT K^!%fǀNtvzb++`aЇ˛9V IwCIw8ҁZ?}oOJfBcFJchSj<(j7J 5lUꂧKc@B'B&M%Gfz{tNxMcrydO`]7)?Oov?'jpBQB!rݐL[rt_Dx&d 2b\N0b)B|$v8!l,*/թ?_x^֞[Z/olnV9\=rPVEr$;8Iehx<uD]җpoXoUӂBMtꚕ cd~U`>'+l{t8ZyXg:ʔAY9ADSJ@!KG]! ;S?s~:fo=އSi`NUV5}nկ&z€G:P7keTEe}S575w7You{u @tgN_[HeUez " nGJ"!ʌ]Quô6LO}ƃ<)&\ @s}J/~3ȕujlR&H|T{Nߎu"eO`z mƺ`F_҄: -|Qd0*~Vp VbrM7ѽdw]+$EɞvsR4twRXP2P{@WU0Y 1^)AEPY7f7&[ X&e6NA u,%w:z-8O/52+p{ٹ]C~Y=,"D:n"`dOyV'7IurA9bdwGgM܏4ʒ)2" V,b9BfN~.~RѯC2 * x<$B>ޛDQfjrCA{߲F|GS2:dI>\ D Tm?4a:_08}ܮh?J;q赑\$uzE'C ny&@(|*ds3J9Bs):1 ,tjhڷW&qh/sB ~xd㭬B7/0+a?8ƍd{6$1|J2*I^?6>W"r\V#fy|L_"@cjw<&۾8-qi b#hin+ ,!8J< 7BǶu]1鞊:0,P]Ҷ+k*}iz;Q&i)QMb#~/.rqA)_¦oU>2r3rv|քSTR5Lv*cGѳd3\jl2:?%(Wꔯ8:ښ~:W% "´+ҢqxD~g71*ҾJ}-fO,$EM^ؒ( PЉ0ZcaɂI^:1[N~ˍq{ ;;./f-/2-2z7~TgA&@tzf 'X0I|R,>0FeXn`|U~Įg6Ө0,p#݁|nqe,"d[b6ȧN?7!4<:7)h}(htBeHom8+͠LdWu(wvȘv.f r3#Ow߆vJ_WF7zHQz}w#Rʜ?/_{Xd`8eHnQG1|LsLx?[_뇑g;eE~2ڔuQlڥLDԴŷ M)=3lph?Lj^ㇶkPJmSe۝{_@3dg<hۡB޺xBœ%1*?s?a]|o訬أ87u8/ҙ]PJL 41G7j͕ j{k/XdHO<7RFqQGals,VY?,߼8gqv.kOQJZ4Va/FUĢm@td' 4&$Kfc}C=SdC-OHRWI<3Y2LuJz]wStf-bM+/. "Dy^oNO+bN2qf1WTyPǝr==lLzN7LiŘ)t=-T=a JHwNwz$i?@RG R bK_{ 'I)QpJ}zL^͈YȵXE8>Jl+ڽ Tn{a%CE 9(Lu֝dcx!tJUݑ3il2 6Wԙ*rY :dw. vv{y,=L'.>(& S61Vլ pg!XvpTn=UGC.9^v9=t[ID@ޫ*v jSlW:yZdH?s$d-)pA4S'^U|lPrX2.[bxJ">n>k;=2eXs<f[aXY9/+I̱⋩!r^T7L@#`}y'+^Y~; VR<(]9~hUiH~iǴfhC0@| V,'Z1-:ދnQxs^ 5Ilh//tSk>_HQț_YN2 V.4y2OMt';OKZw~?-S!1H:(z-sTFVgPrKlyuNȈ??_ϭuZ [cNTp@eS^Z"I`b2-۹~Ê=Qw֒۠݇@C?E.8*kh7 VUBM6:WH)'وE c ]פ@8C5'iDYqzO zάlvs#weiyiiչ#Pb/Ӭy%EyYKET1HyE07GEn)?0fRyB> CCr2>x Yh*|4F 'h0!YXhy8\<;q*ۡs")h3L\"epy.n#N5FG/|1  kWp4ٍ@5TMT"'FD@3OQC(A;g 2ۑflbť1H>&*=V%g *kFƈA6chɧΊA޵frB $z2TlrB)_.Zv-~̧2Q*vp ΨGT[{T٘ !< &M`ؖg ԠyF&qŻjǰ@6}VcZ \u25!F,4αW5oJ瑯Wϛ#q*\?ĨC;il3躼@ S 71W O8 ́Ɩً >I= ^0NJ$Lp'3}]r(Vr1Yk<`(M+ J%KWZ\6e\6#?3GV €4MdC" v 9WWtB<*/^J VTݪm_μ3xBvoA'Y+Lɦ'?pڿ@x3zs5d?F?=npiW˙;qJPeۢ&m& LyMҌga=%J'N}oq[A)B`bW" (@3du<+Y T-Wj*Rm%,&W&y= k\_{ZUn,ڔ35*6f$GT&ç~I2hw#ĬMט6!;Izq8  6(u2PW*=a]{@.zOw=.F+R_.9ͅ[C^P,ILřHrlI~P^ täOD(9&"R Cp v6ҏ `AtɖYȾsZ7xr!M 峽 z1'k݃N 57Zm-0j>* wHw,#miЉ*VCT2JMIF'9w{Gz2M[4^KRPu:s0糍5Թd (*` QH@ D?=W3"8rb{2T$7+IBN`rǐA) gy, Q/w))rQvBu]F^b iۿgy$*ao[F8jsGP+83ls>!;ueQIEM Ew +hҬlSW'yJj_*}*]~|i,/W[.FvtK+Vo' "p>p3hVo6nZƬT*LPzD*dN=UnMwsze̯{>S@e{ѦPn\~XsS1u{鼦yk\_Yyrw/:IQ?p[("ձav@z[b҅"E◾B7N* z3MRJKnJ9ݕWhg&f0鸜Wfh`zy^NR(jJJqҴ-BQk4gMm_{L8/; Z`8J$%޸$uT +f2qN*Q?/ltiL!%L]؞;me9`n$N}Ds^h6<8Ct2e89l Ic9.bUēP>Չ> J&xR"b*7HFs;Bs<v_H :~d٧`+'vBqiICe[hi;ru`%;:SľK:=ʟ-c`pW-txnàH>%iECCefz3Ӄw﬑_.A:QUd}.EXOǝLQ o z*>2T1A%z`tSkR5l^je6? rG7mp=ϕ[2`Xݥc*}dZ?x,Ҷ/sZ&bn:H;M&ƖyꅓT'@ēd+ i̫cԑFes(8WPjOknхdN!A"V= Wl 3;3} ʾlaA?,Ho_̍_|q`N"|.k +"^̵&ܩßbIE[dF\0& b[Dkۇj!J*3TDqq3wis;/ӎ+?ްM3eӏ 4֨Z,:%Q"1MQ6 oRgs9B;}~H_0GIt?"oЀE ~C SAD|qW}ryZǼ"cYE,?%͐+XqUC[/fk2Wm{O^4lO "0/PUԖ+aCގ֍9rIGEB+Pw ̍1M%ظ8btdhxDU}`: M 3C֚ *>mo8?jra wzTi܆q@*;~Q. SPK;gq^-`x$G@ִ:Ƈ9BQk%<'i TF}`B,pzE;#)#*\$sڔOyҞ$S>hn`_ڪ"IJچ1 7HNPFIp9-ȑz)n 6^̈˾;PCTcPyGPF1]6L'əMYi>6Q`)fr:8ϡgyf ^ە+%w%*EVMze* RdMyk2nqT:b=f:owq xQhb*><(~Ȑs%b{"pm^_0HPAnv. ڄ(y A k3Ws`<+d˕8ByXFeDc]&2_V*$wBM͇=֬6?+r)E't]b{AkBLv,׏ q ,WTp-Hh5"}[2|Sģ`2ކݯ'oPnyOj,֔Up]h;pT"xg(ה8? 2e|*?s : 9I{{U(ADp/qxy֜z07CI1_75pu AScaE&ȩDD  _hA}/͒XV1?Lo*N~)Ez!ҍ _EgQ/WVK=f b)'/Um]DZt%z?eJe{f*ȣm>_̹ޜ^/#Lywɻn*梶:wW/Gmq묖Ǧ.cJ;0z9 o/kMD %AeWdDkYB'f3~?~mJgUt22`FxSǑ%Is:ͤ؝pg~`-ƒ-?s8y BvyvK9123%/k02%`d@ue\8NM$Y.F\AL\(N!y1;Я7>R;~[%!0۹ qR^}Mmp6f)ܺernmiFֈU93Sq l牿z?A7OAvve 4hs1 zܜ@fbxPX ̡:~(^js r:WM0DI+ @h"*`H4E3(AP_Goi)2fW2xGT'^dj)\ǖTG´]>c2iF/yg$D*OZVd&u`hELo%r'lnYKP-[ [# d_Vc A!.I1a'"V7}5 |F#Ws0W&DCݧK-wB6 aK1Qkb"\18W΁f@(I:2<=M0]ik׋it_[ڃaV+3o: D}eT*5klh֣[5˙.>:6K>C%j6 }95K xCk@N!eZbg_Y+n}Ƃ#]Ō"|ǂ ;p}-U$ q6g3sGiBqE>u&/⩊c&R{wS0[J;yƏQ`'É NiuSl~qRDҟRNQ23I>Sy#gO5.YUyl*XJ`_p`{FdyRO$G" ME9 rnȰ 4wP}nlE')*fw H.11pgnnU=_ aߺl\T 3u#[h(LѿT_YT&IgQB+R8|;@3k{mŅ@lsYZ?Ize51>'e1`3 m;5XG܋XzM8m2!{4$#Kn,_i_B1DI}T$EGLq&Ԣr*dz߯ASꡨVL2q` _ΧJblMʹD)/$ (,CXHiÊbM|<}UMEoxh 6G39g-km&"يeܓSԋUx;VͶ_qq'8.|&tæ#Cp>\xmML9*sDă=z#%g 9}ROB~\W{ fOBy6ft*Obƈ̀@ 8 ,_}㺩w+!ZZj XK8έ1/>]%;iB$D+ʼx^x}8 6TKfﷷw6[ה{l5$ [p6Ҵ;͓0L,d| ?V=hs"?y@[c=QϗNyB75 l?r/8-S$lmy26m@lʑh 2cSc9e,e>NqpwaaK)5!q w]V"iyz86!)sT:䉬,AhF% =LU2)$Z}w}R!՟T[\@ "9L熓 \nA7Q nI={+bGF *_9s\HĤ=QH;`=!\&#F !¢!!iU@%J:9QUq؞ GǤ3{=9u4]/^:b%6r xԁSE"pE98Q.85r>W8,A'>:B{< TJ+t^ dGD ";9foԥ6 qŪOpԋ,$R3~+ P瓖~6̽pE}D:6 $yz!$cua^/=QAO`%\bON+L>*kn 0#j=V%5ڮi7qljH9$RV^]@Wy ,5ojHdZceF{Xy Frsbĥh 尪1>ܘH1zxΫřl(o vִ` `r{Tg]5^8OoNb,Op]F.Jm'MK#/X-fa{m;bgj~wFLAP%G{_c~2G1!0Am|S=AvI_f/ŘV>AB_(m#4Y8a+4_$#ږɩæؘ$X3sX( 7pa=Sw?}(R }0\6:3V>"ZA},pHQT\$I[7qXRڧ3 y:&L:pssY-t89јhbp^L>?zK1BCa!8q"}˝xzq+7xYb..Ț ,<-6ε|K{"Pbr{+z :/3~B5G?lxXk6Ș S& Q>d/M=ǸT <ƅ/[\ѵ{셌dsgOeeOMr|@{P5hi,J ѫ} %qsRӳLKQX uX/ҝog"`>#;SYV.{-4<:T_`L PDcQ'X3>te'q?s$mHDHA/#]cm,c:m1Qɸ%:Q[Of"O'.ݺ)v}$OWL)R!/1aгSP(WsFǠ<6BvaA agPjX*+V1лt>7M 'Mfe,j~CNKisһ6G'q}Å PK?0 j{B8\l˵g'PORr5f̬*YɪBb #GNa _vlDrd(ۜCRp 7}2l'Au*24gbwuF߅)!<[G+"р %]_HlǁV/hiөtJF64&ai7"+GHހOdVr֋D;u|R=^72.죪 /*4wed{e?QOuN vA[P &Qa 0DV_^ݦPBO (keG,( 0X(:?Z~`Yq۱Cy}xnIAW|!3l=AJv_Gj X,"X*K&~WIˊ!VůY,y p M0 k#Q>->RRmoL-'\0 \*hlpih8e W%œLY\-pRq' 5 (3_5^OZ^Ga{m#L-xpd,w=M[(ly$ %{ o\P-hj'Ǝ=if8F<{?rzB.!^1i2#7_ E+L֊n_LsG6sTX܉݇~y,ϥ̍Ch7f>|P_ -c4[9qPN]+WSEjfY=rʎ 񀈤0yb,a?f4={OF֜as-/6OI$ES>ӎw];yraׄN0)C\f> %yIBkf5(ï4)T½IDeP˭C}}z 0Ԩ?6^JetJe.=Ju h<2p+z*ϔJz?RƸ!X[?ᓣ";`l3h@i`vb0"~KGܬT*gA%%cRX%bzR|7 ljq.uex 5̓圲Sē;xkZG(JȎ^*rXcJM}{wM 9'o gv*0/b鑗ۨrrcIU*8 3~ j]u 8cMP%G̅#E*_%ڀE*- f|?oôQ+<$߬q* 1 dϯpř0P/PdݶO(9>Ԧ3wsnzZT|/Qr7o}Gsx a+,즨-*D!lST' k^һaQ\zՙ"5Vl>b"[]%)}WRg`M_\mIP{ȕ҄.ϠP.L˺aթ|WyE=&b"iNhn3dJ?SJzBҠqcI4"{F ͘ 'h+VDRa*5*ΡM@UcT֔ʋ 3>IxD[ lFih︠0z tUIUOy mѳ!qu-7-Gh G;fAu4R+(DIn-Un 9dNA"_X.(%b\3 ÏV̾s] 9;Ǵ~&xե"l* ͳKψ}"#P4ll5Z)Zz)JFPؕ4 ع2Ҫ<ܫz.m\ x$0 y=I]}rMBܩ'@Us0\κ7=JpX+;|7 wʥ$tb^;i}H[3bMPmg1]F|zJ}aSGD:ru‡hOC8̎g<\_q :D˓ s}b,̄HK)V;A]ŬCdx qlek=WH9x^kHH&D-psjOY1gy0Mh?RLR?N+@y6{/Aמ%q'#ٍv&.ԶR&{M{Qa\N3kڎ+=Y$ґhmAȨ0؃ѽ.!KM ї)6*4wTu`~ljly3MOyb+){͙Ra&^;J~b f',&v(lюL(i'uIyls$IqG!pKL[ LϿd;9Ƕ3 %.l?O9) z(/L)]cn!x6ǪODQ-9iOhPeg ]70DK UpBbށΜH@W̻W3*ϚGR3x۾][?à(XPDrxQ=Q`j6w˴:-? S,!t~-O=_AnybAO`Ijl|^GZR1Fi=!E:T Nq<J;2 yfYbjTy@5(7β:*a*y^Oa4c ?4HH3ve“0(HS9Us3m wKΛ-^yPbz1-D浬pty.!eztҐahk9R ٮTG9;:<%*+|)-I$BAk4=b*[ٶQҮܤPY(/!g:?;MSg-vpR mYwºN"Rrۯ0q/J R\z@%QH9B$N.SHMr:F9x-P2HR&TJuP< ^h  3n[Vn_5$W"aEi-gⲬ/Xan22 r;їy'0`ԕ3jgvLO|<}PXV=c68Y][((mIߠoZbn&̘{^w~_Я4E"BE o"k0' ytI,$%N^l\pF7jȒ<Kނ~?JPw|k.ZYYiA4,"CrA}m*KKcENϸ5, sJ(nQEg`"dnp񺚎Bb;ɹVɰp|99f#u|.oEIK{E5{rR )~d]ƒl2g6[hO9GGdzz!yiZgU۽&fK:y g+kgOqPHG @ S:5Vӄm%gUOJh!"2XrsуSms\G1{$.b-P2V|QlY6k]|H{ں"KpaEڛmcᲂNָ2f(Z!+fr ncZ`Vn *cQz/M,VD9cB4uYG73[&H7˔h^D~PD)UM$.x,{?p=C Y!w\Q4"sƸ3 ~m1sr_9tC JVGțF5Zd>;ZQ4 0,H04+n/Ku 9(f[ ӘA;BX?P7J{PΡv\,e^.z{==}? zp|Ը1<;!2)6.[v3d+*«8BSGCWLC=,J!jpjqm]\a.|v+!tkb]pD3a(axae}\ ʵ .·1N0P֞2MfLQVc#$- pԬ6LKǏXY" BB's`vq%m.FFI^nK,[W: OxBιxRy>qu YF F_ZqQ8 >̓nhZ9' B) iPkTDT>;X|U6T{?U4?<{wSnbg>Ob3I`*,@NCšӒ(BCKqc76-V119aˋ䯞 UB7(٥J\ Rڏ.=cI`%ӡU W.XD|b(FCdB x HN[M)e:6:@QM6M;\,CAry3flc\ !02=| X 9[KygPN˶>죎C<5l| AN0@@Sh~qcnFG >I\fZ,jFakDi1 GW\e3;/+n!QgaBiݚɕjs:ZR%Ji,4$ex"S<yNyo$*drP32TQ-HߑNYH1?2MtĄ(:옡uӅ ngvIJ@Z5p_xiyB_n9nv">}C'J=?ar@6sAC%Mqu4UseR\+$Ua$o0y"PGWu}c)&a?s~.6:=Skb~?]=LhO>PR T}x]'/~} \;-l(lj8]YF B#u"ߝ@wyE]Jρ'D[00#V[y'Kti 8M,UtT G{mG6t@ɄܕP„{%Q37ںW9k˒nyD R.H}R\2dxD{m6J+ xPD3iɫC\ 1vkԂ앩6(vBf؂7pSi#Nxŀz($T&Vd)etmv%[2hLE]mI=*w沲$}ͅݷr dr{dn›'¸8̪Ãb+<)B)[&ca[TF &YЂ̅#@sǏIfV@{WOqѮ}k!iWqp.{:ȿD- JfD.Ͱaܸi Sݰvx{ݾ:y ͏짙H 0uhAkR)ǛLdKQ{(=Kes0.VoV}+_mH6 -V|6)T4?&clc7Jœ~K j%J4Z$Ls7t$2}a'r×~e is(ա6 <̦lS6tomvNǘR6x TK—8p23+eDO%`Z+W_(E"3uF+Q΁/~aЁpOz-|}q17@Syt VHIc[m\̦Ǹjs ٽSx\>&kHoPjiV_RIb"J؍?$;R?JhpY;z ~h 7 \BS::4c暹T,8yYhԂv"5NF ԰TY/`L`wS.ѕ{Y:8`P-ͷl Оh$oǛhSR!Mqup30s+%j8X-Y,) )_/`qJ;Ht)AlY*вUtwc玢 W'A~@>k 5S%A,yŒcW G)pٓ.G‹1*Tw^Þv.t4.LD?+*9$b+ү~+JR3IpB YRQmEjf~oYa Цp#gQ8ԘVϰ=RmNs?Oh{L[U9b2W٤ 9&mT*P(x(섛ʜU+f35cpBK^Ua2:3[A`Y^ϵW&8DejgbK.UZw67 g\NC…A!bt`1g?zs1`8;p/mMݠzCԂ\톚Y8?T|^V+m13Ihv} :h7V1ReA) CI@ͳwoj$q)Ie{5bdzy{ƜuRȸDZr, ^ܥj9]'^4ۈ!ԂX*Ns͐dmHԉk q%|3:mz,GXyoU,_ESk 58[gǻ9qH·ɂe2GړSREwWj@r|wЌь^5w KwQ 0ܙ_0A|-p =9l3߈ 敕Ucz? ϟg@䤋vYI,y=S ZR^\e0d_Vzc׻ՒrV5r11tP&(8Ndd}1569.6 QV'S">3|ïxLV:J8fGYs+pbБ2oMlFHKvDf "Oc[֏v12x ɭEkz/kגVCRXDߩ(X~ѢH!e؉x%2O !FpBb`~x%Mh,K&x.vB_ׁفʧ\DȉLl>+k# QQ ǑdẕQQJ{?V+[j-lҪGd ,ͦ\;9CDB~8|cse9G!dNy N$^rX uЛRoP :^hu-uW.AAUKx= Y䜦gLp2lo_rc{dXm䟾ΫzSrOgNIG J;dedR"Ǽx6@n8ˍ!d9t%ND3rvbN jRsᘇR&rU7v )EBI`ŖdA WEJa5fXMsFS{+ Suh'1L"DJDύJ8X_#ih.B 1xִY"E[9̡DjLTwj=-H!%=T2T: /e9HS7["8hoc~Bkn5th ‚O+P8ݘҗ^0im\+`rCG/&_E!J¼SpT<ާFXPej jwoyVv.N7&R_:0-s(}0$ *Vue5t6dE}{(:t7?}~}ЀG֤>7TlHMI `~kW`{7ϟBkyblUnPC9%ću$?49N֥659o`ʻ16>YSOc ic^Qr(x(|B$[G Y흅tkZo,Ai8[s8^Vf=w h_<›nF$?toϢzW-F={ e.ᡔuăU2X!HU *a-~W9mBKItUE H7*+ ? yd&&xoy6m9*ex̎ LD!G[B3B#P4aHȿĀc Ԧ#?2ɦ6ْotwfI7B*NccuYVϲ&RM=%45'>@6 L|m@d?""+6Jĩc>3Ti;[L,ӑ8+կ\6TM5a5&%1 )ertYO2;i^x|;1\zk\b&٪<p bb(ow2L#؅Sin8>8}Ey/7 }mبκ|rvW +K%]xM-hi[e~,JYdᇘĊ2r"ْLN0DAn8ȈO 6cۜ;ޒQ& 0zK\cԯHT WNX={(+Q[sFI3LUy~_qG }z0kjXlU=~1:s,e )U!kp繕)].hU`ov\Ft3&P`_.B.7p7Y$g%7؅7 l$£߂zB69!DvϾRy赂'o Ï"`E=fjM_Mϡ'57)he7\bAP ?CUb޶I5н`88ʑof3CK̬ѯ17wdvb5EQ . 6|S^ϱ~E@8#,LMT&Iӗ>_xAi}=:DW:Mv 穘C9DϯVJ0{=O):S t$A| rZ$)uN fԦ%{r=b,\\LHB KȰ8~ 5^]:\e6,d:+te)tIz#<\3{|z'I @Wf2(ȍQ .Wg }oy-bYzr\B>~˲;"6sޣq!\dd#qD%mR7`'R<_ lBG*}7!md>:G# xĹDaá1V9s!0h?Kk^֟KtC&=  P0GF/ɝz@K i_'Zv,.+$,G2s1x^⑺Μ'rQ< p3G}û۞u?,!~r=|n<^uP"z7R57"DALeMm#@.hhk_v@귣INDU֮: l=gR1#o}gFb]N3P3S{,, (|6Lw@RdeȢׇ޽*0WN2 eQ6E{* Fٵn̿il©ZP"GQK[0.T`\[BT A@YA1xF~FX#|:@'UY@i*g4h悬VRC FZ0s ,;R _?˝y  m2oI -bZ_s\kudN{8N>~X]EkjM, ֹ}=O3"ےOe:8c %|#ٷ.^`)-]4E$zztɜ촤rx`t9 F? _i|`܏qo HZmRⓖX p˗Szkn]z5ЇRJz‚b2 $o1ďeE FF?[םHq3x9~ҁB.PtM{n'G#>\dW-lFa{ju0QF:Bx~ toim XRWm';k EC,,}JR4^)NIVapUtZB )\ KUWqD\Y{D\YQeb?|\u.6e4j+6{]]<7x\_"S;C sؑ\0&2uYZ,ӈdS&B)?<Jp۶ y'[Os6 ܈~-ΰ43+$LI#j&rC'=U~R3q VѡЄɆJ{ Gr^|3g5B|#,&s]&K1$蓿|J R8hwՂגdHGVD| x 7h*ȁ"^߿(1E>K1bǴ $ɌMbW2xg1`}*&I8k "w?Y5F'UYaErAgF,ķ<w< )9[8aM]lŊͰSsry[%ŵEt ETa$𞹭Z 6q0oQI6]"$eSآa $B;L VNa6G0a Դ땀$B"5{c4Ar0#Øȃ6aUdO#+T멌3yiB~ s@)@Hފ$1.}/ylg6(6P9.[bԥ"0*Li)k0rIqkEʦ;g%"=ł5q6n[r.1?j=ѹBin-8#6L)VH4=i)31wϚ)'Q(cG;y ̽*(S bdCC qc9QJCS7u:NQr}{[υNiv/cu^>8#s8/9^?C"&>Lw[9Ӓ1,o .t'2OxuZTF2KdIў`$v/'o)N1-ky6p PƣدjjN ǂL%VWd Ra6l~-q&ג &*L8dYrkO龂<"=\D>Lm ꢚ0tnI"G @'A*П' : ]Vr. ah,|^b64sSɛ|\70 78NM}6#f\XTb5;}Z2 (-Zrz11E\1ő*:UoZjF]X1Xd)B)) wjw;Sp\pC]P}F m jQe@k Pd}[(>hE}#@:(1%9!{"|fmKjfǥ'ͥ񒛁+6Bˉlk"/}Ah p%Fs)@V/ +-@H {P&0zȋq~'6`Q \2a_q 䫀/N<c_:? gn Y(2ƙzJ*t9QDL""I=/6=6EPvF8W Ձ3uU j}8>K65dYܨoH[>$:!cqNE|"OuBh CRMnoʒN7w5M7uO24LNtƹ7m6y?‰2 {5 nJ)Ѫ3cwmŬ{f.CY~x+A-fz%GXGN1HY/Gh69e꺎vz/ TǤv.[lv!^ՄoY,qc^d[H>VzO!$&}`*\m LsiŖ07",)k+m "6zajm%-@Z"EzSϯ[P^tVLQax(Sa5mB1b] ǻ $a Į2䥄/ ف7&,5RštBTT8u@~ >{|/ҘH)?_.V$AY\vw|86%4DTsqc'X,HE_:W`Md368ZG(4}BA2Cy}+ei+aAمy=#q  y>+ߧ05ɀY'#Y W{,fXg`Z/ql[݁UM_`PEH lsGുHHqKI&>kr) Vv<nBNZuX¦ǃ'XĉCʑ7dK UlN]&duiR|!Vr 2f֟_@/#/O:'Vz+cr-E ]{d}(BS@jiE/""N ]vCG "VLkQh" aɥ3U9" YZaU;Aqu3Nz EN#%I^pn-8tW_/fI#DXc3C5P!.bE*!hw% ^R1*ڼ%#ϑN`a g/jR|=$J*|yS: 8swa v([4F;OOvQnPzȇL10pɱ*'ln+ݢ`|Oա C!jLDCIpպ*H{z }MA2꟣2U6U*̵X8s|Xcֻ|[̧s$m9?zL*w:Ӓj:2L֩o[ŀrE¡+gUD,9l[ީ[5ȺAŇؖ!p crN=2U2)1%``R(ze2s.̿p%ڱ̺4LbC}]s'hXz%;݃}G4G c֍<5De kWw u^'SRA6jLl\Y5:A$(H6bknH 1/SY}њz"~@j TVbIa `&1C+ڕ4L.l'` ' ZŐ`HRhMʑ Q1^CN GJCAI،8 ϹF?7B/.L([>:JE{.bKŌM bAoy؄c=)@n|lJ(\We)OK;8jo A\icDN4'+py Xa E7U9l-)0w$9XwIP$SG[ocp_f7Y?< _Lʓg3cF ?מ?_z>S[#7ZHbux:7d*,Q+/9% UN!a XI&ҿxiu]tx/%CF4b*{KfOjԿ;M4gGί BϟYǒ{d_}4`_%&&}{=lTלBJǐ:Jk9`B cs$5F<ۍgq:?z(2NvHWЭLJ91p=vMD'|;lv1f=Xh1T{5B[ Lm)Ł ,$Nj~AmdƘqTUrIyY@Askyx>o;{[#@/8;(8̉kr&^GLͰjne}Td˅- x2<0;y((q/J|5A)ײoeY]RSN@XW#Ɂُ2-ljE8H4-[۵B{{'$T9D_P"6 j1걮yPPeiV@P'KL;h;g\ Wva<`**x˕_?u 1H|yw2\V#';EJ6۩JiF"@x6ZX?x򹞠琹m;{ ||Zѣ  W|jQdԄ5uޛ:^BٔWċ֔5c:Y#Ҭ+R"2 &TOIQ=x%1 uƸ>Bߙr:ӧЀ&*cZ!l{OӚ4Tv⪸8v%dpe9쥨ArE58j`ɰzu":nu4Er?{r- ,/]0[PAJ8\1@*W:wK/dS@0<2&CR7pztl#Ž 6CTA$UVڣ]TsZg <ƭS5EkxKP8;3Tf|/n8kO|5&f9Hi7vfk < qR@rzC =뜄lD^JȥrGm,}%82Z2{xBߐp%1_ۅ*uZ<̓*M޶hm4A3]QНgII֠Ou6D u[U m")oVVcA da0/0 -D)0G9.> Zin巛$ d> @6dq.5Pe;t-! \V?6[m4+n 5G%|"CC}[&Pݻ`JSg?AN>Uk"VpZ/WBCdVDU2~.p$ W4M R#vݼS}`.P]@{٭d 1 x:|d#`k'K1Acw{Pхނ)LF)\RZ969b'p Lg+Ӗ/]"x+ mu2t&E^L[p3OT"kœ.}-W WtmB# ᜞an/ g5{r4Qw{u5J#Il^sW ]5ps1GZʑ7VQab "4Eq#,T9N8ɷ.mQ~&~R=LÂPKВ||Jsy)=vLǯu422nW{֮^K݉hs% OsԥijRɹjh˟L9?#rrbr ;R[ `EGn+FMh3PCZV"f/喸:c7}LwtQ3$uF l kT_Rfywǰk隸W`NJX @gtw}*2XM6h$#Z~x=rN5ॶ K!x(?ԽS¨翭h 6堵qn~]aWIɲ+ud:{#rȉxmW:Ѯ`AT:5ŗ}:էYtyo ˎ0I}iҶ$ I|/n$]!])YMwHs!(}*Uъ6H]p ss[ceKB !;{ 1J0d̅B[ϝ3Ab\laB^]H.2aY3U֢&R9 z(UyY縗~-}C!kQ,eN"cz^wyc˵3,;ZpY|.NdgצygRjr%G;o:8o&/L_3;^:IU &Xvne_zıZp'2P0%1mW%?OErWƎ4&g<c]J~!Gu2r5(!܉z,aQ/pHȉTIM;ّDW ̹[^zD}'?m ++` ڟv)cB?SQflR~}ɶdR8L3~ 70NIr +mu <_IUϯq2me׀'ҽqwbAQd"ZTA <y8v~(3ߧbZ-|yV: Ra?L(P^TdD0:eɔ%+YNӐ `c!VUoB4=/\m [>665}S珆r6ԻHXCm"#z҈.g%;O` #ת#U x'<}G L%4ˠ$G5.)c34rN(,+)! IUINS^U5>M̛V єɵ‘EV{ӣmSHu͛y+W634I E6.cA a'O( 7X|?8aYǰz-\6bF.v^! MA7Ő٠߁w} WĴy(U[ؼ"pS9qY" !9xoKq Sg:}wlxy\ٕj`w ␆F-^n F^~5zŦ\-Nƙqnn)[zLr匙)8y/TJd<Kexzwh SJ6%o%))*jKMw9BTe>l^PO7 dAX&O '|E|v[31*oz)yO SY6&zu3Bliy.#^Dش` ʎhɯ@W0*oj~+m1.bMꜺeX!sA(i鞴sV_f]h_/?=F9\C*0:[}YӾ=sÊ׿Pa7_G@[ [0 K4U\q!y$-i러&s= PGE:z hRC}WԬÏ/.C&¶Zu=ln52 j9F(sA 9*P^1~o4Jc4R W᥋$z%>}籠XFsw;)8](Fce>׆Z%'F7~9d0}?>>rt& Xʺ" gG?'#ȳrepα_![V&/[%/Ű,oQ7(*,KJikA+,P#@_`2LCFKم;NP!#8Tg!+'t轵&~HulkVz5nF'}+8C2w! 48ܥk23]]OKP<"Vco',1b+8,ѺP)+;0w֭ne w8)%+w*l^! }mPͻ2xPFɳ'9&Ǵi@p ݙ3W?[j4ݺ[מLQVK~с[Zђ^†"'9&ֺdpQ*) U8%)_`}T-kx%NLpUZ*\YB8:'_8s6(fLCX ! 4ڑ tlrqr~ޚÛ* YƤ5ԙAg-@-AF_Ò367iz҉Nc"4sO6\W/fLVa94jf&Gvzǔ{dc_q(s&B7!8- C,V:1hdBٍxkk+J ՞sycݠ7l qAG֐g4Wlc=BrѿE'}IP~{ i2 ƛptEFd(qTr}vs?Aǹ#0ӏ|n { d#*= sf8+ s&Uef J >[SkuN n!{:e6A* 郋9D &T:zBOVR3FG cżB>|3hR%o,!#W{. RJImryVKBX U"y-^Ն_I~Lްws5Y/o/*7Mk:K,5rĬW/iPzMꏏ,ra-S1Xjh,ȫӿ?n&D KP9ds.6DoיC Sw$z_We7<ϛ-NlQ`;0;.U4?SL,h"f[Vk!V]0L]'T4Zc8~z ޛ[H. fd69$Y9٣̭">TA0eaIwe?r{I>=ߊQF$I75qcAgz%Fn61/&J!s,㕭%44~_H"hAt">ɋV|B;73Tl;x8(7} Jn>':v PhZ=6/p9% >c_I͙c|Pg$_+(l~8ydx4OE{!ɇMa0rY +ݓfpnjI!Qy4^\{ `/1GJ'cALraCфYvM&e\`:tovXVi%/c]F@*/YsL1б!B=vTh/,8CD^XZ*9oR@EÂTiUxsV,q_4\3fpCND,SPg> `ǰvmO :emW6&M>u&Ls ĆwlF-3]x֢QU / Xka_&ZMHe=U!J0G^#u=BJ]OCv*ÀQ *9E'A3GKnc}E35ox&i֕s4nYi"CZ4g 4/J"r3б ă |N#guYs5_o CCldْi~b)A?dȧ,',ǤTfX`4V&8G.mڀu޵]Pro8Y%Hov+-en=5 5dML:G?kMf3D+p5zG;DrV5qT wE42{?'i* mnG8un1Ln?I w &+f/O2R3lVI{RVhU\b\SA%gOᔃD L7Mw 7fl)~RghoRu"=?}*Gn,ȣ [3F8c'H@a?$]v5yFD&q{(WmVW ؕ[_ DƲӫ2d-P$A$%Lץگ0߄B҃@`zww9@ rx$tNWPc} 79^0 +#j$|{䁾 (Kdf1Y]dhP=y#nꈭ7fW5U_JɢwwpFQ ~UlL܂-Gh)k\dg~[Չ:  d({\XLn>l(anPRAV:`[K Ÿ8~M1fc0#Kg 'a.ӱy̩M*c\HM (3 g$,>A`|/1 *G_bARJ這= UJۘ_ewt&) X[A醠bȨseyLsc6]l"c_  z{NڠJ j#!I]I՞ͷ z{ GZnM,XrǸ8f54N|gzSOn2uw5'i\6| )IcVd:&\Bph_3{L L,}: o['>%Η;~Za;2. 0+]8+`ρw,e~WT=MORqx74~ϵZ^g")kat 9h,yݚ/>*xxS ݵ'8.^}la‡Y-@{u19ma k)g`bWqG^[V3d(+1Ţ!- TK $ǻ%mGd#;SC{I7r8M_+ ~(pqu敮Rt7a(9 X6M_i*8u┝9Ķ%T &j,CpJqPuWu1/zBv/CFHP# ' wa¾)җ.5 %¿)nEI]\B^UG%/'tqpEj92*=ySRlo]H8=X}٪r Y^m^,& &N7W:b:wqsFnEkOJ%*xID{կFf`Yb3+2Kؔh=I;1<_ZʅAvc-}'][d$дedVcb <'do?js$7g .I [od;9$"%n F}L̏EN[XAG3%p6i!ŒʸqSf6#&eh&ko[5t{lm֊#co`d eRFQd<"D2DXTݠ眕åߒH',rڜzC{$1Mgjmi+xm5td0v 1Rq_QҍV)^U.)x!]Z <"P.#oͺNS_sRJoc&|JTK 7{E = H+ߛġ 4 HlӠD*6XY}ʭ?ԃI՛,aˏ43Φ(,(jUڼZPorsٻc⬫{ NSQn/_6@-1ŝwj.R5LPbC=x@*ΧCْ`A+܄]v퉜`s1J*@1=i)՗Pۤa /t|:~trk_s;H:j ަzy:fLF9- r# 0K]qraѷn~&{7o>_v>+դ~tahYr('H(^K%\/$*A;Se+lRnv'hk z}pqY+"C =!tM~Y]xep8LJ s' 88(-PABIqZ~Z?̛ߚڠ[{5Ŏ4#Kg^Oc냸 ^z7v:1-6ZMb6fQ| r,!g}^eID|8e=_A?R%~tgZ UEn( s{HT`_Z /%J 65lԮsEv8E+>;Yeѝ|(@cS8;Q*`c 9j`"e$:gC1]NVj :M:`5jV?䯤k]&F_ sJD8ԙM"T9JYlW2cg,ЂkH(} ?}KC`Bw)tp^55]8T4 rV>!PPl_եTp>d%HТ4DkNJf8I!so@ gPfVX6M|un1Moe釵SULmH*RD Bja&mUQ38uH}w\Ѓ۠7U(}EnX551 *`a5rNZPp'>)`X_q3QeI ??7vǣBw2\q+I&;!K46o/ꥆ~OWyvc2Zsщ_z2T5Tpl2@xS *>T:*tXtc@6Vݧ7F5ג:f팩j fej/?!RS`zԪE?寙'jO' {j1qձdPX̹9V]ԝ,OBpㅒv?"M}"V/hb)*$['8n :O/qL*E"P$TAQfRl Xb:Ҵ.d-TYINZy XfCyH_5O4X9n1*C%?q;w3Ӳ ?rS![K\Đ.=~ x!Ҩr idcE^\]|:_o̪ͭz#V71bj2LG[L ^F,=G—~!D:٩u\ <2OJkeb?jHݪ~d9,E=:x?D}9nbb^ _#~usi76kdDv>)o[! WS8MvwPDz>Wqh߲I'*6$V[ǫʊy2N&ˇ# M y"9Z#_9R fX;Oꌔxb&lUo΀4u7Ϝ:؉0#4+B,x+'`z\zV}H:w?(󤱾~/9鮢rT4rH0j1x{j*U!'˄&~us#f>ܵU)mm9dӷv25[NiM )e P'ꫭuˣNM|!@Z)z̏a~gs뽮`fR>Қ x_v^E^p$ޡM"In4SniG=xnK6 h%r@4=E ~̣CzKw./?۫||=c'f7yrbgH=6'YB>]FXĮyl]# ʁNb_6RrXNO F6#zMK)pk5N͉̆4S" ]6)0Jl8CEyp1mt 1p0gZgqW+/".)Ds lT"O>JH$[.p\JD,^n͓>-jv11RO,{z-YĄo5n6'3vF-ڱ?l%Ѹb{nJd eCr19ΆtK~qF x&f-No1UGJ|C6PlD"eOc&9ĄtF!"uz&oLgðE.mrA{:&䩪kOTHϙ5dF^t5q~V_*9WɽE6A띣b Q.kxm丂"p=%NGKI J·OaTb0,+qJW8y!(\_ksڟ&Z T*ʇ)!h?2rJWla<@DBͰXd˦G h-$= Ҷ. e`fh ~P]aCG_8UiRx8ٜƦV+r9S=Mdic; czIMy8DEf*Yn:ESiQcϨ*ޖ&q{%|Gg6(7/mm }6[!@Z==*'kJ; @*{<"8KC(s)E&g졀tc'.E޵ڙ@ ((. /@$<6OFb`,4-O<8h]#R{kP@l]!``-Rl77M.|% 0,@rj{eP{ǃ{]иG6j|W  lE۔FfNy6eS{]w"$?j6[YVpm<7tF}X'bjz38TܹбKσDdM"/x4/s()5eQ)KFnm?RkɀyA dvSzw_SQ!*JGât^ X?uQd:Cf;5 ہJ8Gr{F+1n5HDwB&fYtQRI3A q:p81ffW{]yŊ'ǒ2PWD9Y0)rɰ)d mÛz?0.;Df:#M`Q3PZNewFl73y𱆓6BBNwCp{(.'F}Xk!IW/](^H`\^тhyZf$ `7M?%L( R ߦW27@YhF? Bzڑ9A+Sh&?5ly5, [~gid rʡ4`05g8`"ggKrܔw$Bak7#Flk+tF,x$?>Mꑑ;ͅ=ԭdznF+lU`_Mfצh껵) ;6_@stB,+ cj0)&ϯbruG,]l[8`ƃS+׌8ERd/Z18NZe'9aS h loߋm g/A FHd1{U E>u`O_ʋ52A>T@. \7_7\m>e4&@-EAo?CVX0O"w46{OM#ͼ dkP*RIRYqg+Zu˩hv‚tO)ʋ'.lF+\U oXPqT8 *0$E>tɃ+Dp'6erOQs?mCs #kxD=8FdrYptILOӣ!t eDy&XUV]cJ 4J\=t q58x{"]л:H @vMvp_?E9Q@o[Ι-r=߬G) o7J4|tv$s NP'<ɺRXU,>([EZq%hz(L3c/i$FcPI$ݗiI9avԻBv?odJpbTTݳٱC:8J8V{ q p{|?7tU׮2(h[REiJ&\!a5ֹ>VV#F+)u{$x$JV+0}bφe T*p=;ZluQ? .tK}XH e3S:y:,hBZ ķrDdCѼxBGka{!JL)/4g ͺ9/4$/:'˰Di9VF< ]ugp`K:KdվA;;DVdmꜼŢ jIrd0cI7]r@N"K Ȓ<,iڪp\jkFO (#!r|bu/yk `hJՀ/hWyh"̑RstiT]G8_?wTN'Fo' |$ ,#SF7dY,|xni/hZfo癄am"Pߕ+ƻnI Q72 GS4uOO0>nd3^avni݉qJ c%ƬٚsA606V}@#AӋ66@ߴ,zX(wwXEVLȵ$P^}4 Y! D^ xYF42h{Pɑn(ͥբ"ljmo/\^oApn${ZSݴ'5 ejAdj4_K\}0e/V9tnEw-P{ ʀٰWӃ &+ОI|J)CX0+T!.*Nj+GG@.5qykƨ̢k51[W`Jƒ?RIyv]tx5So_Wᖄ?*z;)@Ygh5T>%IcOx;CC*jOHiǴwlo{/x vb,0?&FyQ8=ys<>D\.Ewh=}iNGu&ABkÕ)nSm܆qe IWuW&AV‚3 ?Ӷ,?g!w2Yu3<_kV)Q${|ˊq1ey1Tk1{L`^/X_#W+^]m{]xawrP?sQJ|O ݌tK93g0?C&Gj_zey?f(WZ?zJ<+neQ.k0okBl9oG?Pd t>6.IsCJKhHHԶRMl']>ѩziuu ɣQz p6 StMiYF>RT N-(8ʼnhA'lGuPCi$Yp{f ׺uVlAsj-@$oO'(У^R!RxDNcPP3uu=0%Kx+&Zw 3PhW'xڟgJI pz*X Z M0𖸞Էij+]adznK8 aFDl>|ztXd?WbUUƿe?'+ZK7,b[/}nqZa' M7B&oݲ^70CP*9¿G[v-Clqϒ.ک5#@W5 Y=? 6+ SwЃƂp( HIm)zӁ'R [C| pwGm.I)X$, U9-u_([dv %!gOSY:Ga&@,۴в]Sci**WŃEJɔ`˂љn-Z>\Q6bcs0"դLy%g>2Q..çYBԉȔo(:~G&fTVԋgrcW j:J?ΐWAGz*RpqGFfZ:. *>!6O:&=G(y/3W ~7Nˉ$DgKӣ@o/R=z8}t:CqW.y`Pokrm@Ȗ̝fFP S=KGx.%k";*P.z҄uV˴v1o;ZGԮᛛF)OB <3vB4)I(c||ʪ+ɀ*N K~{ҭ}dDa] Nnb߻SkR)=ZFR]'zaZ a3?F.1ܤؾ@_>k$H6 j`d a0gg;Aoj:[=ԃ5l.2yv7t)yW}"촠0WÀ >5Qq?E:RlFWR;DlؾK%"g>>;SZu`@g-wD<( ȉčJx)],,F}Ǭ f*Vh\ DM&ш ՟@PT~g *xźU-Z5>5prE6>w攑;OqY0 r+H/ڞPSt\vM}Uγ93(׵sl{Q/- g+3i= av"!aNRe>jHmrt͢*K).>Xx0(BikdfB'7ZΖ.WVv̯{Lsd1x nkC8BI|fJwwTl zjv7Ȍ\j=MZҼ"JxMS\m8l/KoWȾmw В\PL\*w M?ԐAFfqIPOy2]l!^S0Ǜ =oVOBN&A[Z|.zVڶ|PtNγ`TQ&ղY:*_['h<7̥tfۜ jZf`;Xt`i=+ A"0_S3z Q{pb{.EW9F#/ݝl=(0.`⦾ILWcT810o{kZ{9ދ8bu= B΋58vPD4'tvu*{Ҫ-vYvm(fQ B\,^ڷXGbj;& #GB%*Ņ7B eَ##ِّ/}Ȁ瘶ŰW5L6Nqw O㔋heu#QsH1hˠcCcS-I %3nnhδ$?Z,PtBw SU2iX& r/-F1bLۇBthHYϕ~^c{B}TP ֜תu %g "4[7ɾ_1Z@ݷ%)6Gal썐5^Y z9 Kx#8vX#)aͧ<~HJ] RZg^axVg<x~gUB2gr8p1!\Zw!Kݑ+4؆ " IiTֵ+w0\ۋpA#_3oi,oP%:qf; Q\T RUrȿy&6ҿu#._õ-"DS3"BA:^Mc?"J@0rh%Sv*/&8/6՞1woy$L>\ϰ)Dp{UORe>*( Og:E7H܁q hY9]ݓ5].HU#'js$8k, z&n%'Iw̅UnBC*?o"Z  pRRԹxH#j;,䀻O†8Yx`W$-ƒn!7vbu)2} Xf]ml]nY_H}S8\0PwYɒ#`3B:)b}Df"דٻ@I,-OUIH$B^[;碇hgQL'eIW]FgM[>՚()oL 1BsOie -xΏc=.◅u6vH`7JT$ƬCmtV[s):E_+]z*#tmZ/GK}ydronH y,Mr4IQ[.)Ŕi ds ls1Ui>~C9k3;,.)0ܦNDž>_G&i,"[kJʢ 6M`$Ut%TɢI! Uk+5Mm:vX!cV 21ML8E`ɧEYy -|¦"fj'K^>Lx/p0,-4N+>Ԇ/VSaE Ε:f6D]I $x֒khF)- \ S !ƨc&S.cg;uS Rv'5r00"" nw-νQsQҦ' [JW #&LXpbMVddނkrㆼN@3ViLS!Ӫ1lx+i3Y0([i\[6`o]E;&_ZMxZZ찳^ (*vr[#}ÃSH¢4t&B~^HmXя,_TIUCp.7lz4\f;jIP!WcA9Ut1o b9^FT) (}?G/*EpiQ%Fԩo VG5IXaCXT~rL{eFx}[!+ek4mr~`[b5mCHK@ؒ! !ۢȺ!qhp[a%Qz7{*ŒM۫ۗosk!++S)4+)bGeCG78l>W2q(>. j$ߎXt%1}3Э5#jcDp{ &gۙ]nlw,:ir+TDhet"1_(|~([}ugs-[+3\^ڵך9􃵏Х*A8 dGnϧK}jK mK)p\N|e|U&ʜ>q`2確ZiЀbz#J"=ʆ;US 5澝"G:9i5A?8s%tl;~|Xb /Et+龖2+XG3{aZvzÖ- _L) 0y%>Fa:ʸWIg= #(Ϸ<C{*{Ctֻ`l_CRܭYSۓYzݮ:f9|F&ivhICkYzc]'v:r2[3\7eI@GѹAifc$4Up k#mG|B6'ӆȹYƳMg[,]@Hb1Q9QzI/ AGZ#v^;qRžQrx <7|~ ʹKHUPED ;=^fCR}Aռ]I0~+w6أxnG5GDEQ]\BDׇKw54Ga䞜tcojq'rp#౗D#N;sMr.Y!{ȹѦMXSJ&a>rxJnӇbNkq6eqڗJ076 aѡoP,:UVK|Xz=wGyt 6G TchYq'I.oKg\|1PDDƊAjvT GEh^վ%@ڄǽ Imi0tZ$Ub5Q\y-E]8/- * fXsZ=NtX6z!C 2W7~DԶQ!l%OĜāTrNqV]JNGpG[& _[zr7Bs l%]"Gk6(%Ԗ"vf>?jksC0b :33f3n#>:jd9NR >D T*ˀNj% }G%-RnJX,Hhj{!NBP*! ޡqf׀KIP:#MI h;ã *zi9N:I%JgЭeMGĒ}1/ FMWF&o/}P TTT [©*"dQ23xRg0<1-}BqJUe4eN̹(gxGK6Ĭ@" Af Gf?Rd1ҿI R%ӪD.|rq$L"KϡHXRxZ՝+څ9N5qr&k29E@ ꈍWk\Tz}{=[2c&\RC:/go 02Ru MSiM㥨aQ[vwLm R_1[ݔҚ;[ ;»xFZ]B#÷X_4yhþ qc˸`=pM P,*,Prۙ8(O\6z}d=Z`g_LjFscn,iz#nV$] ZQ ^|$}G$iZrz> 3f '+osb5Lt8cH˻\ʢ+ilA@$ Zp#X{vW2ܑ̈PK\jZ^? 9]DVu8˶`eje 虯vhVLe1nTB^\@jM\4::63J\=6ÞPxC[eY/hSFXMN{X>@a'EEp{L C_:~MF >&̜aI.D;25M&RB\qj2+L,##r4r-\7C2hg٥4]~-~Y@fiwAc1Ɔ=>yj?j0/(ۏ2^lҬCۮt]nkAhwT,󞺴N'ܒHE)#LjF:1"jf۟ӭťFr:X`/(2x{%|![JxVAh=4`^m%{QIhrqs# yX=CvXB&B ͎U}sSwZ[Pqhf!& K\oB:#\/jl,c׾A8lߠ'6Eяo}E M7cmَ,`5!G㢯2\~77!WвF:UJ5rU֏$dA0t1w>apU"޶L^(Os1x; 0`>*C=C!t]֊+wb;~Ws#eNRhÃE{F\?"AT.D&v B?X-91- p"*65  X#`YN3~M{ p4a{}!;e:fj*IԳiX,♵4bDEL5c*j{½ӛ\I+>~L6YZ|raܑ6zA^Ǻp^Q,71O}3ީlJɿ{C}ǔ}!@YFqځ;7s6p:NSDȉ jm'WEvb,|Dlۙ-hPfu Smu|[8+`gдaܣ,44h:Te8,e7#G h$t1]9h"T*L%sa+m͊sڰ %K%8^y6Y,toܙjAmbsar6tG6$NQ⮤B˜lp!꫻YS߂*`4Ļo:P^ UtvAj=AZG83VP_qN~=ތ |7l[S< 5$bqu5mK>*h|ERjvpw] Y4 C~A,U]]5Tj)9.~o7HvdW]HYY+)bbS0?S~Sv +ai-t.xcwኍGOh<M 'rhTG*(uJ4A|8@:̀,dۦRW3Br׆p % nonP݅+PN,2νyG bWɇq ^Cy5Myac3Q3)YQ=},ly>XMC7$.Dsڋ}t`R"X .2#}}&"Õo=I+ETENf{,/HUҿ6n*{Mt}ɄGq tQ4j =`iy{cę"mv@S:GpDb%!i|Ze:|;HҴz;5u_v0c؃ǗZbo~' RYfBVCw/,F$`lK-W{``J4BpW<Du8mg]>FxhLN[T9=ٰ(x@ƥxDbEY9&ފ_nzHB%Ydv 0<\#flyn;j>*t(PG4}X1hyN*h RNUzi6DGˉɻKfh\*xask 4{9ja}66MMXjqń1VNCԎ>/S+sE"s_!5>ʹ-UVEG#mA}z Y zGIH#9qݓ#q}lqjT`ڢ~=Ws@En$'&!MGQX삉Ea5WV,N0m;wG1)TcEbܻsєu )H3K$t =Yuu0Gy:r"%Oh^R,Agj CcMO'8?.D9^velUM3Ajocz3|ۓ}[Us5 "F)p@)0\[np/oz +8 d(ťǦ)Olw]R@_Ã!vcaL=ώ=de6RULq9c[gv sPT.}0A~ZZ)è|9 z|9&kg'WۂALf {טil٩3݈;&zJZˍ`Mj撴Lԫ +BݍދJ4rֆRBHTfX9,UVp%X\ ndzL[c`ǃj2>Aq4ZsϰC֟7 ?: 2Ea#SؗhqO 9ʹEĐ ,e+DvԄ"#P_ h|ҎCw"1x:@Da{8onzQhu1wIZz%y#wJ;ܐ2Mr bL !f3Rs#,֦{=1 O%LH#{ϽL F6 axxC{VrJ,ܪ2s栉3"u{Hl=pyO^a YL\SA7Z҆X85 "ocsqmצc[Dt(xZ_nō#ԌYʸTQS^5H j֟5'U\C,?]]1'nW ό_ r577VBuTj>ԪԾ[f?UqW6@b Lni K_@) y`*h6{96*D|0곈!3DRG,?:#dr~&Hż)!31+L4eLEMjș\a(wOe'\jW \gQ랱U 1ĜETŃMyw(j* 1SivŸ#>l_iY'ཹq8gLP)ADv<ĕgˆ8}NMh)|~ZR'na-Tm%.AĄ=%lp#fm!._Ч\s5DWozog}MXl~%t tn*Uxx ,jHz]XM7h*MXAf̵Cs"zR^3K ^]3O,W<w-χwHC-;tt HݕX,%3m ʻC^ ؚC~{%Ԗ׍r;j F8"I%YQܰ%ЮTESڗ9BCzw#:NjPHtO.[3eRs)JX,F G&L򱬯)Ke(\G*y.!d8׉3q~O`Ψ6#KLOT ?/0{og2Bdw 1#/,ZkȆc!vR%g˖ng})N=DqSyWX*5z}?4^טsH B[!uֱ˓ UyDΣ$NVlx֩|t%־Ls*w!2 wW^6ueqZQ?%Rn9ȇ7a *->j%+>R,\鲠Sg'/{ b oB2L1wh we1e!8 + 0񰋔jhR̡"]7\cg&5Mencp6g&d`_d,ɾu%M댞sP9D0ۛHRֲ!9bpEŽuQ˓SFWvoq4eVi*Z9s𥭪 uBd1nPU 2Vk>a- 4 @+| 5VCϺO5hyWwp;jGEUO_AaGrȎZI !~/`"TP!0Id2P$jѕֱՙm>Wﳲ%t нqpE:fd(6ذ/] N"TK0**{?} Vm! v]btmM2qB+T}oiTb*]DA,XdbxL/U+5ab Ë +zt|5a)@k3ĵV@in̊V=wRPT}{64R2\~Jl( a!iqX*{ y9ꤌ#ؑe0 HBve&"g>#-]Z:tsEqtD`~ǦF ސۢkK1| *5$恆}sNiεfnHlJ^hO[jD8Ҫouz4XAacNh߀uN {ɌN殑+qYPB;ds w_7qb Q_F?YO 3WRf0׬uܭStbTZ wQjr ͣZKVԄUOL`\z-,;z'@w女jo0`1צH9RKcJdx>oKAWK>T{. }Xp9bf!, ;$.R ǒH {)^c`q>i9MI̧rZ)./,`YQD`0N EhyYKB?Sb 9$dCM|1_kI! NcӦcBKb!_@0\ۦ2|f{1[U6al/z.ۈɭHdpYc>>0ȯ[-XݥIMrR;\.N YK 9V]~EyfCT=C<Kptݞf?zo%ߢ#K o&9V֏@TO{dGKh(1E rnԪ)&8ی 7P+R7e *,KнAXe(Bwp@q.n=>)"oMOd(3d䨇RGIM]X'O\ò)C4eEZ pfA i8K$;/`eo;)zMaӀSaaĻ8:c )k8FəB2JmTt)"3N5u2ldHhs@kykHR1r-и(4FKP&8t 0k!ݧ_$ @ud-Fj}H:NZEl'QGQM^]kax"!6X։}`lk!^Tj荖mJbO|].p4XϏ)t#g[/F0@;^oA9d4)Oߊٞ;m Lq8gw챙G&Ih=#3_Äٯ-W^"ULRcDR~`MIe&yu.Y;qB  O`$.L;Io_-98o/(;}T(pFZg~ ktkjPeꔸ[꠷Idv%7{&"m\q8̲(/gs-oB( SJʢՃ>${E4P) }D,2;Ie^Fǎpe}A9-r(٣+@Y;P|U ǠU%`H!⏔cn`:>`=pg?>lJp1[CtoVZ{jH_S!_ :RhǕ0pn\ ˨_3{5ZJq\k``{aq3y 'Zob+Y, ~o,2yt<2pI+>F+kl #V>5g $*qvl6&+8نDo: >4j w)^XzgqG|jYDkZsKZŃ.&m<K/E9΄Ƀ].ϊpt}SIeoHz.<G[@KŦ.Z262+$>OĠP=CJWGhxtgL"?J[[;CZAkb dѴh/Lɢ]ʯ6ZH= Glj'99R q/y%>6 3s;[哸wt67pSOooPNLyn?պ9Ȫ53$7jܩnل62F@z+f9M~z@=MnN5;1O?oYfl߾M'$Ҙ~X3p HJ#dd7>&Kwe~z (T ,o>Eaw<}e^ּ̊5{h>2VYeTP@hJp|a?kCO_9Ü vBz6HAEpS?#{dvBCQUou>^R-KgK(c5HpJos6"xp/> u9P¹X[sDf t_{RڟY-iuoO ]G+%Hr"3;s.]*Reuo[g>+~'vF@@v`\Cq2)]pId#/,A t-vٱ3n9*.%y;oT >]<82._UhGEqoD+W|-Ux|)\nXx- HQXsyoAZ!3kÙ3V߃0 h4S 5SaCӾ xdouӫ$+o[O̳# fѲ+?&X;D#B{=% D= :~Pfr\R{%EŗÂbs-eD8=;-(O)685Mf&Ѧw~`<c"p5`$I"!OB4<ũvK T0O>v~8}Q.,)riЩ ( `˃LHJp0ծݓ,CN$/R *N謳YTN2 Zr2 ̈́-Ry~LerܦÆ+dߺ>яmH4WfF, և+-:ɖ<%;57qe(-3bbWUE{ F)&64HޔS!63c Je"OJ~T-# T=~]{U  ?=ow+s,k>nF7JFKIof֚RvG6ɚ@Uq>DqZ<5C:?ǹ02;W;u\YK'~.XU͕x 8=g`vR aw HNȦ0yh+Dr=!N%m!"`7H;o߀>s$\6#69т>աxpPngTP3q$$SW KVonU'뜝F;>% Ǟ ׂ2@\Cy{ַkM|mfJvPLG,bˋ2XH `. {43:"l>ń%eu6ΠbH@.( r! [ԚN,1,EH G<ܓD0JU(n*uiڨd%kU@# ӥHf3 &v+)q3s:\e  dQIagi:@&NtH_T׸M`8^X>j#x jHI^:Ԝɫȅw v&Smg8Hvbr&E.yrk]O^FM6}5|TNiÉw+<.< l%qd:KyG@~}O'ϱ/2u^QI,W/ L/`WLR-@kvZ7uz^>谇 ɠǗ l oPV&[sQڤ@l%xk]3R"9Pswؔ 2C^28@ :ziﻟ܍P:LB!<ߙ'B* 5-veRze5E t~RAQCj> 35I퓪SI>a!:znC2VH=*h v~Le/meB͝fjɝ0&ޒ6i*Emx-/DƲa]ϕ5I$ԧ0j箘^m{~om]aT0OGYrJ J*R5.vnκ ~HA몥I KqlNIMNS]Ya*bHl)5`顑~ - 92ëI$c%-}QnRiEȧr58xL7Ek0~5 qhGqí 2#AG[-ׄ;0"qKE@ ǫ/ޔO V?Xs0E>k5Ul7[_@]dtĜ M\V?<˙AU%͊p!D q)zJu 'tP|  !V3T?&5qgsEChҪg| \ O%.bz5|GZu3<h^|G ."ًBh@_CGgSj:|>ژ@;x%ڎA滺FM!9>r_kO Bg{}}g84TjLuGmn Px rb7##T{<c2dEarSቊU)1D9;Q: )<ūqN^W/ij}M"R5a=;'z *V4-=Yo@0p?!}vOXV:mŽ&20*W$˾>TƠW:zO8X2 n=9a^ࡐ !\^9# ☂ `}RG#E¶eᅉɏi> e 36UQ|8U3V߆ _-=s'7ͩ9ǒ 6{r%3<(ƪgCR fKzlr HΩCsNz˜ ~ăplTƱPXd3@h$\iZ(,) S] UsÅ^k0z6 Exv e FPQ4X>tqX4[4^PLY='/ys_UŖ'sųlǹCL,x4c#>>EDMlLO e8Bzgj(9 EC\imʹsmy07 L"EW:LNͻC_[ƌ `)p{դ,6O/jQ)ĺJiD$_esRRif 5Rp<~).#Y'$EM^JB'pntVy+(X8 &u>F&4"@Qҕ4cStRm0ʧgYOhP@{*ۼ+g%椯$ $p"_kb;ޗdΰ4žh}HpL՚ùyنBց=8K%rq>6j) K¬'JvY x2gx-\?FTa+C";Z]^tK#q8b<%,LFz4c}]iT{\nn;* <_ }tfDO~S N6QdoWءug}q!OgaI|dVKxBVA|r XТ|, )9 s1l e7o*)RI[$1y=3X;!XCdU^5z=88l0 d~sdEhdMh<e=EqLT/xY7\M"\_̋ky(gy)ȏGLax)5rZ6ɤmI Y62:+4|RUrFy4xPeýPÖ LZ&"5'Vxpiq`}{ͥ=ָ9C;Yv^0S> Kz^ 3yA<=)Tݠ61P]R2*/1/,䊾x;. ^_`'j|A*&1F>.xTc9mZ$¡w9B$0) @GxiHF%W'E#W,Ҟ`}`\ju`irz/dx n% c.byxSKRxs (oZdwը_3E6䍈:>5.e7%gx)13>&֨ZJkd::Q1D4\@o9bJء_ ){#hzVfLNiM~}W'B Z^ĭN!b<9a$p[Cc*6 'CrЩj<1^! O& #9 AOVSa3MBxvOC>JsvNz%K>!jH)\zڠו r467YCY -0ύi]{O)A.dV􀺕s94z|~|74`W/uj+#O좉r7(?}Ӝ#a*N/lALW s׋ h&JlH?<eё{ĔwՉ _QU=݈6lɆSث#Q|d+3gWIeFdɽs\ Z Z{]a&\32^)jMUw՞^Y q+P5%egIeiז}I|xŰߡ73n濘uGr?7Hjyx򦢖&kNy()YcUN%6Egd^i~z=A0< S((_vQ`6 àVN$>dz^\<x8=( T&<^We@KNz]d<Y*BR!n?P);z :׸UiHq!|0f8Q6I+cu k5l^h9v;j$ w#RTQ*p,DaP Έ6hKs d>Ycd+mHDmN,%Eo\PvȦz8޾Wɂ"yp$SĊ{1{r]+#59"n.ŸH5/s+WO>ayӏ}xAQS.qR4fa+]E.vPXBp f; { -1aW"!>ó8ˢSPn]8CAf* ͂fpEuԟ"I#:z„R>\Ͼlnx~M'֪&ɑR.!Z%n̑u%4~}K\O(ǃ޿K [~/K%5S8=KKE(! j^2* 7Lo3sѻR GJQӮ+F"x_f}1MODb12(^Zu{UƵgH 0UUtG{pEI:}*О-u]!#vV`w`߬- 8r("Sb:MQ! mS\>w kT(v$H>QYn4oR7a^ @~_p*@re/ژU9mJ(-7$e,[aP$ !lh1 K-lA̒JR0<%ΏT2h>T|dWcEHi1UrIU^5kj_cV:W ܗ" ‚{Y#jŅ?ģXn -6^𗿹5Lg3e$+6q8880JcN?>VqNX#4y4i2`z>[Q4މRz۷4CgZR~ۭǽ~̵RQUTA+zV3K_2X-7 J;%v~Rޞ;go{:a)^1)=Xvͦ.Ϊy, oѦsmIE<įYrVY>qӥe:Bf$w% &6t-l+6튟(sx`2eGצV '@68b{{yH#l.Q)NѯA0 !EBg>Ɍ4Dyk6Rp3P8y+W@O2;&coLc3,9msEm.zx&% qeQ͒b}Sc+ߌNNթ}Qq# FX87n5qw:" 굲ufՓaAK/QT˅j+i]sK;?p=,uOO}a2wXuЮxw23vCgu8 y2.w?]6$W}(k0 LLF[P_N +ou=bs S&TŅ3ͭ:(4P'B(=`ubޫЈMZlۖ#YNpD,O<>ۘeI.[LepN''ngM%k8Ee? K`paBOIзdUJ18((Mbiʹtx3= yڦu^zi/9Vd:U6 )>Y/;oĜF=u:(tUpvx~d +YڢQC0O& 7$H,oJHX羨23 E3i Yu,>r:t;*0plN͆ QlRA%@1|^u]n+)>2䉺ڎDZ*(Q\0qf> ,dK(N8DL9u@ rU=m|/cmMi XPHDBO:Ӫȹ;4,8[8(@[m;~j`}[TNZkcwk#^I\#kXa YLf^]˩ov8$ ڏB׀lc@f&c]*]azv{/O< $7PW)H_QlC9+ Kj:ߝ5!w%&1F_%Cw]Wܢ_X:;?`£tzrWl'IUvyS#-?>@C WFd#䍗SbdaYqA[3WSP&+K2: x,X(#VnZKˬPXhLK;YPNkx=.b8&[$!D}V??A[}+ȩnzίLtsk̵;zPpr$wFfa2O#;N '9TyXe&q'z2 ]{DL 6_c _d(Xn*CJ’PL5d! -CRNOve'ATɹEDv8Cc9^O٫7*>w)OO3@}ĥ'PN`LJ@mUBÿm1m8//uVÖNטA+デM˫NJţ1 I;׷W 0tR65Z"/J"ك?nhL;ɭmkVq8U A1.8D`I>aYɺ4;hMG}LJ)a#BS/ʞ y2\lSCq:2&6^jYXu3 <~pWi AF+j'LW8=,=T{7X_Ԁ=KA,C1}gN, Ï&W0HO$KY̧nq5}>P&f)e :'>Yi>-lCu1ڸߣ']펈{}:&d{ӳJy [,jSsIY'DC*O ssÆ7xu]q(Hm4#_'+.cN]\-m3ݟ ʣF<<1~ԻiS( A!ĴbJ(>qO8|K"B_q5C?*G%GT߶D埧>L_*tU)GTS,6x->~<1 kJFa&1\deVUntz^Dž(gx`cm%jޒ"|Lc d^|$eC, WQ:7rΟ1 zsq~.VK'E3БvN7Wbe<1 Ƽ$皊2",rx>g7Y謔uJ(Blس$=,*ì-k:#khC.O#f\R/f_uVltE B b?Z~U:I8D"!&vI>"sFa,v E+S'"[2+'\*ۑ\g7W7u-jmszvX:QZW^mBp(fFO2B;==05jvo"UO_jVγTrҒKfְ>e])| xqg-Ud:H;zTS e &˃"hVXizM玎g8wۤ#܎FЅ )M6L)VXkܿ>Q8l")fڵkHٗ*2.6)d%y@#|XbV2'-0"?a2jG ;f~y!v\ S4Ko؋6a'ӗ(/}> gjZtzrH̃ـW@q{6TnԑVxR)-ݮNy L%X3Y\K8bgDU*O&>'Z:ӻaL1׶ay(W O{[Y0Dg;ax{ݘ<`oU2;3y~$No&&~IAN/c޳s5LFVKre~zI~v$V#w w ޔ *v'g hyzclA]g/tq#hD B ˪~y&Lܓ?aʣUο_뢱 CqyA zۈ|0 +`;BtJGBL!- @gcE5ȐG$A\ix7zM)l9'}8lkS(a:Q{Ӡ}VkO\Oyo/>˿Yzhc2vh5`B.n?D49*x)`q(ӆY6l!&~7nBNE0kyY#E>Q3!LZH{&|c9teNy8D2-<؟TUM ŦT-3[FXU 4pp0-VpĘ?|$K;tnL<50pH,N@%vTۇP6,o)Cz,Jn)M rC9L9_9ٷN[SV=#yٜaF'*AblFBNj%޵z!]\BMO.$|;|[9C,$7&bVUXR*EW gpb6<}8SoT 2:AMJytEy[P>IkJ{nF;+8NϗM./]冽eZ_=}gX|w /oѵS͞Ga F3D6&&;txAQ9<^cջBFG$mr8&357 *yL$؆[V= G* |B%;mJVEd^Uqt`>)CfIiT)ؖ #."AZ \ڋ8E&=uzt5+A_Y.W+[ŁyMoIW癃xpki;|_S)ΨRaFIgKr ?15˙|C]9崊 iIk0H#|]ԑK!/řuEr,.{kG !ː)biD| Bx4\5-~[ՌڢHO5qh>ٸcd/۪B<ש-}sQa?ƘVgq? ayNj#kӰ#q=2 Vh)Pʰ W+Q.شaެ1)_,dցH)4ܠUIxoݝ>%xl[h<Թ%cL\*Όkx"|%RܜU7{τ|z%a>"M+Չe5h-ށ4}jwIɜJP>lAqAr='7od_E\17T!$T_Wm_ZBnj܇EG.|$Ny{|F-G Mq>s߁P T ҄o#^>k9G_CHx=3"5]:tKA'X~7~[:dG䔺1qBQ^ksYxR"3ǹsXSA]u4lNIY/iqgD (<]iWk/D@"H҈ms嬂]WFlZ%ebQpIǏa9r|Rm #qJ!EÉF.@ |}CdcH qZՃNQnS)hUQv+ly` -^AoI`a}!_CYqQl!0 RW9{˃Xћ^닦Ȃ\BFBCK%{@z$AJ:fvyYVZHb%jxՄ'o*5wl>*)[a'U:j!l^ FV'! +t1QMB2ȝÖ[tk[E֗yh9nv}T 6C—>LK0L{id6櫽RP_e*8:6@"<<$%hbfnޒe3J X;]oҶ zzqxn,~ -6v8^r7y:^>W`oE-qJ1D4 c*tֱtio!>48c?Hb0?? Ή gMz¹'egEMD[mۊ}]hQvYQG6G/Vsd9M5w"YnP uÙ@4ΗS5[p܇^L#c"&c7BlG|+VH6M;\%ȟE 5d+ˤ<lZ~l3N`P `D68{lqjT&76%ҭͯ[Bל@ؖZd D+ɾPzw|w4smT8DYt@ܢkI1՗p8<Z gh8m;e;L!V嗢fD4c5u1 ڠ .OdcNPqRw8[TMOw?Wù!PB5&{ƈ7վ?c˒%%)E{a%L A?G 1"3f3qe0'5}q g䓱T?sL}@!|<Á>Jv0=vͲ|~ǔ <ֹD\1}XM"O`Wvp$W$G*%D/n3\>IPO9pէ=yL }2D?{<RH+KU- O1(Lj*Xo@CP: N.!S8pyy'&V(lM@ yT~aB*ʂT«i+=@8}WlrJR|u| LHqM&i*xޯ8^]ɧo/_{~}~x Tm\Wzcw%LjL' &_Z}4gqYi>˥w= $֮K*Wbz@z IR8YugJUNx6F\kY҃arͶY* /⻓kW%bz3kGv|"yR;*[]~j8!G~+ ^^2WM~T1=U]6],roc J5R >,WKD)5ozWEtY0碇)[)q*RfJ/G˙gIrɀ%DONTe2m5%Zcal1B=k#.^*TPa\HTB,h $nAQ@&M 1wtWFOٲ=&lB܈0r"; tD2Yh e%.g2$8;l?sm`lPLsz^iD:)7]]p"~%7 vwF#r#J^+Gr b<ę4Mb>d/$H9սf^nSh ioE@Si'˱[=(..r;.̶Q0 I8a af⠏٫F>HHv,)u_P:߃\b:ς )n/%4RNSe w"ȕ]}Gz;HB̎Qȓ 6vQ0d))0)idA^f=.Ҧ~58pPH5-EZ/Ye5 X *Wmk̒H;-fD;- q^n{ג+l[4%?L؞b.k5-uhrfTKE(A < OYWN&ln {U.uTucB>m,CQ'_E(\< }M^~C%/?}&B \o.h`^HĬB>qьg}yU%[!IT@Fm)~TR{ g!Ke:{!gs4=+Jn ;c=4_i;rfnJGQ YoӈvڠF{5w?ks8XG5bNAտaL jlN+P%6a|K`ʇqvC,gZ "ԍk3$i븛Mx_Pa eNl_Ugm3Ǭ:bM >Q!q\#K(sefa.GQ^`ebvwnMWrJkc6 AGj4|"uL5K"(~Qʐhy_P^o3ci wT&Il+J*UDx T+VȣN.0| p/ک,v ?ۊʡ)2dX T-~ŰQ3}ǝ dɪxm,*4(o{f!~';έgY6,)g f*jwC85hJ"N/bEx[f~h,DslcfOUI늰3C_[7? ;Á M*:lRxDCB٣fjo1vy@/;&T73NcZd,R m$cQ<\+  \>BXGm&ݹ"ngcR͒iGa1d=ns'2ЏnFOGZr +͠v)qh/?m;V{Wx{FP`lwdVq!4R8u:$f|9-7ygY~spWOc2y ]d31;E]=yـ҉L|R}]ci/tאCPIlot.3}-|F]< ے |Ql8_0'<{t:'v, ixRf']?=ˆ ÅH:)@W@QY[K*v1X6wU8լ_`i&ٓЮHc.aĝ6ԊZB97T׭&Op  P7Xx^'BRKv&{HLq(*NӹN@ ɌqE3Q#ۜ$fiS Chr Xb#&]niۣxuu6eވ'HNͩ*.hEd^"}WT QyJ(QWrr{93ZxDx }8V{H?:3.Bw&~6c>jOkn'΀\2E+_E[ܱ{W+1#e-4#O;GJM1K:+y!Fd,e~Eo{ T7eڃIYGpҝK{:w!idEhH͞F>C:Lɚ~?<_gqs5oBM?0; `*|0PkiҹEhl!&6G<0 _@ $ Oخ3Aܿ[%Gkt"𘂚54_BG\s43h5q#vO_[>eLDZ't|ְFP+\գh)ܛ?#81=HTt̹gDJD.pqpX 7EC86 B:^+FZ:4OّN.n[}oOF in,[)dt-+r3qjpރZioyn^ L>*ŹY}}h%]v;c&l ZËN8T蒮kn?̅nSA=&(֑Ƈmt# j%Ŋ`2 YǚMi4J\6 uXYs&&GPeȥh 2 5d8Fڕn=SXdR(h =^U~akUM#)eii ËPw[L$NOH7FdgsK`-yvzEPyPrp_ OD׀* bD>n").\(su?Fp^"xpDAM6J6_k-׳\є]^]vE1@EtT-{YLh+C_%3@ƭKA,tWʸ_|,*9F`q1w6O?m]0+P&ɩ@B2 &sJ9s%܌w]6+4֢neri h囖&dzĚ-O}OiA0gU?{g@L- M|`/ߪab\mJTtI"=ǔNu<$%.say\Eh,cqyyT#1^Ht#C)B/@KS.__[u5U0Ȳ+1h(M2ogDs=>٘Yu`!eٱ$ͷ. sK=fwX\laC8څO1seZm%@ '5AI04AOx'_2L;W)70uER88^rSug#ցwp@Xۑ3v" W(&nW0kzhN=w{()'ȶ%ÓԦ4b+MCYjct9 "K,%색#"7ZtT+Kx*aN4Am }d~MǖY.꿃YٵT!P!ϬCJ_O>_j'V5~4Ba'reҫ⎍ĝΰ}* ꤤj~R"1bqfmLgͅoT~~).n ^%yVTmn0, N1&u1׏Sڔc8™>#M'^2dpuѝpD59Q,35%~K_ $;%/%ɓs)vڛOKW_R7sͦ %kOz 5ͦLǦbn:֕zl+WRhv>F7%@9Yg.Mʣz"["C&VlME ҥ@%-=]Zm 5\b*Zj+-(~Q\-Bl 8"͐'՜oLrSc 18S;\DyG3U~#yd]F}6OEЬ\i7r /Iٯ"eJ^~ T[FI7GQs DpBґX[Q,B ؃:Mh&9siܕ2@\xu:p8 Rr` CB+^ѹјlzY&uF%y>hא0\BJ!Mi2QDŽdQ%qvP1yuxh#@:_ws7PkIX@17ggvW/zNIxpG4+d.ۿqVF(yj ,]iw٭k $5# ?})<ʒ28js[қGܪ`V#scoԈMS#T=LoV3k8t&?0 u%$RRe\օ;!Q\ˍ#8B[Oa6>0v5e$ !}%ءmG"AZMO0⠭ +oضi]O2|eC\mrw]S@»&X(`a l`fi,H2Ye; l0BQ}:<~폫44 PC,S` ;@Vg wJt+(u2.,$+յmӲ6MI ):sS %1 ;a2MB}35FrEA[U¹M=܆4Y_ە?4~rّSE > '󦣬`J.v$yvģ)CcXCSQ;`v8ōwzO4`̽KX6.؃YQ14E;2g`4g)wNڢ]v3t7O-eCVi*:0K`/\agv%m?m Dq,ҋw .-m}P`BJg9ڀ|Yp+\YA}0K)(DWjRès!?,|CSiMbD3%Elhgdx/s8>|~Ӝʳ-e$!3#Z],;7|c-}N(|bX r9uVD' Cfpm{I%XaYs^Y %ʬ*cz ?׌P6|x ڇ$hŀ!ܒos&d(B˷ܼ2Gw$ϴ<V/!Ad˄o2c wOx#/rxFp1S`ݬ0NEyOX5l;;_2D1u4LvU pA'ez+F"BE"jM Q߉\LMf␐c/~i9J-TނZ5wWk5zs1XMnG69Bj >s03p#4p\<*vaHHQ'hSq|qlGu|,W3_0¬&gf 5p_-^"fCY$նQ[KlMD|`bKWwJ-&u.Rp r'ɳH)}jFrn'?^kJ825jX}ҍ0V:a~PJt+ M8tvsSW@H*y#fa[լ@qH~{ A7N]N f-))XwB,6]W<}[ml֞|R^RY˷DSXPE הC)[G9s?[#{(7,(+94՗C/};C Fn h IۇAgfZw:o>9* u5 pڕ{$Gڥ?=`ZhAgKxhpźiJ<֚ /H"/^_"&X#Tyq^Ἂ 1ضAg"ZoC|*6L,jKAje݉hEO8X!wh,,_uO)S߮Wa6Z.{n TG`hOjZkkQ2:E:ޛ *?yhЀ<MV&kWZ]kKUK^tHj[C\{V\#LYnaʕ)m-Z*3,uqen  <.Ӳ=\ aG,NUI܃43zc9]Ep Wv6@|]83O]soxĬ5YQ+p ^IlNz?$R7P]f.W1T>),Gq*}Va4y˰U #]w4r :~+t|Q-y?2w&]19b¬pbmu0$A&EIWJNl@Me LeFNuC3:s\/%?K,3Mc6m"ʱ 艼*}IG҃">T2s8uhy6hgDD x9>/TghF?Dxq= AQߧ>:DcHwy$53Mh, ̢ $[98X*Q. /g[Zj@u cZv~lL&Y54s+̰we0tn|Hiu()szsxU,AKd٩^jlXYC(hp9{7n [1?~=LAr9y]R'^+1jF-+7 CInSzto,Rj h463L}IJ忊EYxe!`7J:j̵c|۩-@/SطeC*Fj0*ϦqMh#ZUv+3y7_ؒExF0Q{f-wz5JwHMz {1#6Ta84%{m5g,lhc1= n?ogh̘&>5Fp\P7[k&&Up0Ɓ x Z'p%,4rK$E?.t2B*A-;~Jl-s.y5\RK|  x-5LVw-Ɇ7J aK{fy)Q8j6 .WX7$E/2p ؚܡ_yv/b9:޺}oLӹ3#E n>1xJ[n7)DͩH]7' HxX9*(w'mj_uף)&0cjf0X);,Uk";`2 4)"տeVֹLS6$iU m!}FA qڵƆ~O/nFɩrufDKOPCWGmDjiIeђȤpwg:޶YWBBgB%׃ b96٫?[g&7j vACdڅHYUȎ)Ydi2ldYkPSKl^%xYEr q'|/-xFGY^]6&-|(;Q8" k~<7ۂMQs,t ,*ȶoc >:nx<YCֶPp-obՀ4]ީ:bCG>Y٢ܲny dj˾.V^¹"ub `#yD6_Vh&W]5JMF k v5'$pR8U((Hs/;k//j %*şrEU/okn1!R<pݍ 0vM`5Xbs6 "P\۟ϝ搥xӴ=W[q -vKl c02?,|ĝF"0;ppL_b7wQ8G-9iYPNf;ˠXPnGϳ}Υ ʌ`)qy2qjfU|=q; F;.Y 3gck`?T Adc<{MI՘o˵霸U6xC9 Z/ i 2iA#' 10n]`dpKRdܼALh nAjH.j͗v/QDgڽ!gт܏-(~,\QO+ ~q:/0^PݻHخ,0P_۔5,逻;;F~?gk$;rԫ&w 8\-Js:_\ 6`V!ݱa^FD$ss ڏ @[y$z}ehi[##N=qҞߣg t NG-H]pi[W/~d t q.K}-h)qz2C~w;܅5NY`̓B#晀"s28O 2bVa ?sF~5cjB4H_jHfe '+XFh% LB+ t?9xN|Ʋ-%:t{".q9<ЙirsWcp䁨cxz_5cB*/9XX0'C]¼߮,Hd~?eT)7^'h,ިz?wՏ90b[ZB|< TqiHl_&RgmHGI!asu_4JH1N,=B:(V@ʥq1? 5"IG3f^R`J5q E@=n7K%㿓X=aO'*Fs;wܗXQ~Y˛H;s{ #Y. \ Ixj~y-#dO { ~ 0TjKma>OǬS1^T0'҇ _Б9 5*qdIJ({_S%qSLf[,%Up{׳c90;Ι7?ZpbodBO/ S# -EG@jԸwei'\޻3f1Ӄɹ$x^%ᑛc ǛB *ii%ǣOsg3ǃ5ާgN& I06kDu[w*4]VY7Yvnw~.ns`5ԽJ7J D.d5(s2CћG莛ڄ N)R[}l~7naΖ2Qf%[ZyApț2B2>}$D\(۾% o]8-~JJ$z+}89ӎ1STtYZN Ig K'?}cD6*gO k^uƘS D=sScn~ Ht 6ES"5h}J=e'DbV{p&RQoDX>rvʞa&ՎAlS崢uKc!y,ם3l*.v?{|Oincw ]cVga%Wχ+s$H°-6. sM\*4So&%vR8)'5LMWr` b]'߈OSGih2r~^ҹĐ2ra]]SuE|%sFANu&^ Sj8~#Y2*w,>c@}cZ +O>ݳ[FUM0B\U%q6Hu6$T҆K$6Oa=SS tbJf}E%ǓyBgI&c4t vC@TBuT~ɳg+ ':)&zzϦ]e 7BM}g20yY^`ӤPa*w%'( <_r~1X#09`IlǖlL:Ə_ <7:l}<={|J@^~dmqJrtԈ)Gzav,:·3nD^D'FԬ)Aɳ(m`>֚ȅ?a K>½DP\='W?QDSƣݭJ5%6a+U-|TB˝4iHg aF|D]0`# ]NTwrJLO(wv+21N J},lKkCW#\x|Eͪ[7^X2ͼ$;{ pȅ9u7FDQG᫃ N=#z j!R`3 ė4- E7K9>E s) MQ۷Ew%~)4AKSƴџ;V)kr/)J!%f\ ?PtK7Ǟ֔u8,.Iْݺ0]xVC=H:^*; ُADVXA`2bC0ؚ : F7YV&ط/m/#H\ DNk_hйGL50XFp 6t݅m;a{bQs˔+0Q͞k 㻭]p&љ7p\rF-3^ZI<.x4*VFAP{Nj,6@)lm?iQJ\[1Zr|߆jS:~k}ZhR!% iê"$g). EĬk5H5|90$>[̞)@ { j-Dw</'遼㜪!Rqʡ۩zl"HO~J.SR8 wYwڟ]|=s/ބqt3z>Ԣ˯,B {iAf/ ] `tƺ,S1Bq?^⺔@8iwV\F+I8oU5Hta>GO&xγ 52L4E=Nrا5FZq̲QM#29Dƒ%: uxA%HطȮ֟X>&Nc}Ҽǔ>08 tfLrйjS,bsݵZ{b{(@Yv`4} sñ7IYى~K_:bgmdA ,ސ7O`. &2.hEFE355QOMf+nJEzest lY n|E˷.iJ/)̭suj׫Pmib)y6E@ڽqݧiKIDX5aI7GXc&cI>nduhL~aHAaSj %tՒ ȣ)G"KĻ*9zMd;^NXA(݈,JsƸm#) X~{VE-|fPHyAm EW+/U>ŧgn[a9tMJ}s205cMݠ#)˞Qpzs;#l^fNTڨDOWr~$''Vg݅iG IYex$/=Ӆ/u"֫E"s-@áߣbѷ{6'9UOe/&u=C++֐-Y]3RN*AOuA+xEA¼]}$bz9QR O_l< A6)ϧTGq|eɍtlN+tq̯#8;hFrZjV[3%mk t@QU2P*?(ŏnwvV!r)F(3=:[9\T<Wsێ5^ӎ"';xoJ |wx WNF?p 9,\ޓ [k~ԯ:S+f\NZѹzvHL6V.OcU%Tͧ)Ǔ;ЭBҔ HpTcRu_5CzJ^nώ27pbJXH$7GiNNp4%E!3(H̞[zH6p2y?q-#:ExaG#$#/ث~xQ.u M6&#Girg>I|,u`<޷m;TW9G/*~D`ou6mD. do l[M cSFb~#{"cJMpE~ Te7'; SYOŎ"и,>Z.3;׀oo ^ðHB=^1umqbӈ[h нRĠPIt/*'u6TCU\p=GUg{+1z&63u*a##y{秸T7h!BV ;E xSeJlz2K${ x)氺(7Թ >hJƩńqu`u;<IabȤhPyS7Va(Z(l<۰'#ӧmWd?ހUC]n@4bЦ#!O#fVZtcG.[@8rU" ]z) ~]LP,-y0%-YWL>#uJ^BCB\.} - U7Asfވc>w,v(匕wtпbq:}QYY44[wNZ22bvf8Ec$|~leFCU6 <>/Fp53ʞoҢOkdwa9D`uBf*T$W{WD7m=׺JěY7/evdю%d^}pֽ̏WH|ިal.6frZˎ'6_,H\VWNmaͶh'E*;iӧ3KmE6m^wV(ʾi`hyex>ysN"3*vK֙W,Qf?ǘ7.8#LHmMvC_a."?bbW(Na qEԳ<0Dwt˙o/NQRjWƺ,ɝlU@48L*iˍ^wY PL)|[ޚpZ%3U Nn*pC읔 Ey>n) _D`Pxēp&Q b5N,$OIܲg  ͺ\s͓U0 0gMJ Ѩ+-Ӝ,7>Ioȧ]x]b-M'H {J|:F7sY=>;z3X((g +zx1٫qrK&OV#hԓ)z>9.LSg 9h@MTA|-#`]k*Hv.XҁQjwMuГFQx-msK@׵;oH*/, h#YÈ212?9QQй[&0YLo0OfX@fŒ:- I`s0"z3{V#T^YpݵlkwOեM\ȃu Gi"Ư p56i1c_.q lV/7JRҼ!e_8jQ :v+/B'tqw"no{x`ښAZG;S^q%8+H(]$p$^ "ȌcA*fdx5"WJ1p2q1MopjZ#+:i43nސ)}Je Dy{h5?Z.[3c| ݲbjԣϦKA1eL\dsy㲠^WSxj'۞mFW)+˕O8 kxúď9>UAOP;y` !DZׅf̳SHKi1B -Xc_'&\o=om@ ًq\IԤ j75UxB)r$%U`pPե׌HRnYeFm6-HWQ|At)z YZP1ŔH j|"NٜJ PX͋x)Nź- 2$Y.4KY1GZr+^ Eg9.Z*5fZ1ᡦTx֜oB7;nV}n#ȐCN%${ha x}RtGώ\Udj…=(8U <}MUp}BZな?~RSDvp.xY`gŅjs͗+ 0H~Hns< ;Zi6 ]۟=t=D1Oяs׏mf,|}AGZڦh/:7 ϱV$ƥ |'( x FA[)nuN, 6td2\eVFRXd }hל_Rf&C|QPmi)W'wni.%lԪIEf$kXAݠ3%* %KZPC@U'ta4vZ3·COȚ`6fe3Kk1Kym"+I>:*d%~KT*ixOt ~UVaG\g.MIFw9'Jg`9hy5lLb?WTGcFD,UIl a]-^#hhz=imQ%:: .5w"41/[ msUP4z<oBZu[mR \Uw5|?k{9k_t,r1hoo_xUSvM^ؼwypMb'M*@kLSl]bdc٫t?8At15GBwn*6#M ;=yPwCZ*C\r~ b3Ppރv;~G'bgdsh{8;љG sToKh?҅J[C[D+9(jqWYk$_GRA< ІFvg3$?,tyA(*]ъh߽I -cWMkcsݠyZ*jB:B̺GqU&yL<n:6 2gQf3ҵxu^º\8Vn [,IDoW1&c}6.3 &8h7#I?;\bVKR369 0f<%_@qdއaik6ņ|+d.p]_u>u~hZf-N{hc~\FO4KffR^@kQ:DLr3%hdXd=Goq{[*Vй&L Sĺ1r=b檓;DY>eT7UN74O9A9D+koBȷUg.dD=NRV%"zn`D1S TIo7\Ж_MSFYH[sUFm OG LغSsdèzz<xLqg|"D 髢( e:W%\Hk$Oj3zFoHIl8J!kť:$6,!Wt=| q'^JuB?6\YrϿECJcmNpOiX. @pdg #q6 oRpOYqrր'Xy{hboOZg܌-;|$5/WNqya5&|%f5beoN(][`W/XX!b`Y / =/`UlĽ|8_uܺwJ72"B]2{) A#" S27i= t K[uO6DL'U( ~+,WLi\إH)I{'?pYo0IXj{A+8F&n+d(BI(qxȓQzϽb_a85=z8Zշޣ-5ic,jxE٣˼ }?yᔒE/@6\2{&C#p:lh/Z4SCq[6Mbm i>q4]0纓?4on8 tG^TSw [=Q veKb m'sqMs-qR)lk6-DQs88B@9HSK^vrBzs;SUm0-:$Ƙۡ){1O"M{<9"?MmTa'!-F5Ŭdx,Sι#; yxJ Elr*'~g6,:y:El1)>%]٪M&?(U?aQ?LYz^żI9mtrAǧ؏S a 9hா5})C3,VacbރD1ť|WR&$ضD<-s;)JNA_3<҅^)-0mw K;N `b\p+mWݻA`^I^ܩv˂.\p=4U qn%9+ N8+7֧3@UǼӦ[q~Se}Wꪱ1ʂщBZ`\xf)0%bIlsqG0|lL=;mJfs7{[-PdϐNs>oHg,6s `H!>rΤ5X`‚HLA؛FjA9od?P[,S eqE̬LPvaM6+z̓ȴh(!xufrTS~2tjLKJ!I*X Ȋ:J;,Fה*X&b_x]1]5AlZE_6Ox}f)#,KV*=?ӝOڞNsU~P939 bR_W* ^@ ]onG@u' wSAFhFx=0dKLCn'/;2GKn*5L)f!TChzgWD >1zhA^?M/A]8>oo2 )nyx.>Kd}4Pe|%tkFIz2G2$}!Pٖ(hhgs荛Qg!wJxbsQH3jܨl!ʧEָ2\q""8+F< `5u!WXgjo?87yɌtfHZ+f: 38'>Hɍ:H'HPƨ [uR,ӣ%hnLh9IVbоS: Z&8zI0`LX@r#[?/;W2u?1Bz %uSFLoFr߱y+kVؗBZ+f3sT.m6(..$U%@R +Iw$%"k@,Z{93xt:ͩ>4CLg7RE7cD qI~Es@f(ץoˡ9@Hspb"hYC&ckf~qBq9(~Ur j=9B ]=?,ES]\ɦ:mڵq?\b7T+oRT\dw3bF21h/YL?;5lk-gb*qD֒2F"J$D.+j*_ aіKUK:ɑ J{>;Q aN{Z;Ydg̨6U8a$ k?W2J"[t,bcsv3۹cubzgû>9tꬳ /b@* cHЩ~JL&I2T}Fp}A't$>cBд@bPe$vy9\A+ Mcn- yqA~P?iXRӶ \坜u ?nu>ku.:/JJ _( S8ҟn p;M/ 3<=+|dU6-:l}-D6;&Ǒ!}H]'ձT'EcSH<H(kuqI)JC$Q p>0}_WG9G05.=|4wmԔaVe]vNͼiCϽ$cQrXE<,gyCcMjwA>@* TKQ4P5VPm=0 19umX>i"GԾSy]R )|2,⃅-H0BӢPO#A=>Hz~mO䬦fPS-JY? & IO+|ՋYk\I10ȱ[-={jвVm&ZgX '"wy+t븜ϙTnMsŦPH ]R͕e)Ǽ냃bFGߌ^aSvAѸպg[ݸy (:b_ڹktעk}ܡ(Q JlbqZ˜"D60+*浥kN5OSFPӣrAJպF\,`ro%f5ʥ5 ?pU&6 =3Qc琢6W|.TDfGfE)>xeO7fߗ9ٞCp q| Go;]/}۽x@ +CCl],D([1[m]폮R±xdD~]uMs j7)5F$-_./BnZϿΐf'$=Uc.zg1?tЎSۭ kD' Brymw+8&D'ӽ[ \$ eC]T %\S΃OHIJEqmDnƲ] O6em(0z2ȯ1N#vٸr1 yCa|AՒEACQMd m |DcUB 醝Pm*Y~e&qq_mXY iԯhA;Wjhz@"9 +>TڥgE= A C|>ـS)I.I)ICZV F +FFRŶ٭"iϘG_{be3u_J. @l"Okp갎0 `20fzXxZFCr1#qScHG&#_5;_R)h|U"G#5+Adqe+sR6|Q|솔KXB!r E\[ٯu5݅[>au=B.UL y@U.VCn)2I3Y;bv IrC }^I#8R.〱jOK{вٓQa` 힡r!:5p=>a:0#$ڧ<+#WxKjo՗tgّlPc*&d2}A?}e ~6Z;%3:JM=f,LXq5q_SҠ|YE* ҋm FKt9/Ԃa0*}*w]]HL8owduǀ7@7΁x9䅪/ùY+|;JOf? j#ư۵[ Uf i02p?9gf ߣSm =K'`J ZX 5T/71[0oe|nLq0Hj `A!~-'/>(p].HԨ zvKͶÒչ˸눎~rm++ۼ7Ǽ-Qc!xoAel8jn 2"p]QܮmaK)A%7D' ZG^]nQt0PR\J7<鎛tbY%ƛz]j6QW^ ,1Y&._iE>\Ȋ)-xE9GwD'# uQ܌-(7xU-DV7C!>iLF2?-oru$$S!g*ݩ|/ |K KM sV}^I RK%: kOӃLQIUT0yR8FD\YG`YzP  8ߒs-!-AO>0B,eR{E6Uٕ)Ɵ#Pk5q-jA!IUM l="VgmkF\vMTІzs A '%d yh~U U( 띾.I*Rڎ#>E}A9 H9VO?N: 7/($A01zj}.t{S'#2HUT?cw+rMd^{x^GXHP'zs&*a8JeT*요G7NO(ݸ.t8 $UI%#CIςv0G|Qus8)JM5H,eMS?r-ZaNj*w?x\1ߡ/O2!8~ХMAbfF\?*eE\LRGĠ#y1r<@iQ5g)/p,f~M.07XIFkU#~x0RA~5U18c=Y7٣t%+7㿘Ā'<$8xy׳ nNF/Ti=$N{쒳.g #VJl }", WmÂ׷DiJB639TZ#g9Cҟ;ܲB;o.~J0& `{lL\j׬/ՅM7Cp2FB ȸFPΡg܃hLݘIuc0\ъ@ οgop54ϻپ'(?8Mml%tV:̩E$Yz|?FdZϢ8ۓm< ҹ0ʯ`B)7c?8x5mf)+;NFEuf|w2VvPuS|c49"VT.chEKi{xd9U_>2&NOjʁeC&;^yڱ(lb_ p1S9{|sHkx$ SrM26ֲk>3[xׂ(Iy5]*îIC?!Iė8$IE!Y oHxMJp<21%[FŮd ۳@m{յbC KBx4>CʹT8rf {;$ѳ%ooR/Mv~(q-52e.]AF2P:1~E%"z%ϻ&9{BەZ )Y$:BwZ8-:,Mzs1.9»w!?DtCg;ob W4xh3̤7X"s FFi+$-͔M!9|a{и$(&sk9n|uɸ{r_)ZMW>pzsGNΧi2M<ε*"myc=C5&`hM\@|x[rg)2N|f&K[?#7v-kh+<\XߴK?bu;naa6E~!15""_ )֦c7i#b1E?BtnDŽ/Qh7N 'y>. z07RĝVmd{V' B9ӂ뇤nyN*.ƪ?e5k9vub0y"=&na^|nRjֹ2:6B.uu2W 7޲rJ;D/,dF8_C&x;X"sY۬vU&nx`{MϹh$f9olTΔé.>S5R"h'ql(34""9L~)MnG-(`O!Du9\ j֠AAf! $wwmu9Rɛ N% u!ခg'FJ(@T`֠ 2ʌ107nЙAU̥+/Ssƫ!VS;_) F{.Wb^sϻ 3 Đ-ђI-#}xQ ,G"_4޾~ǭ[\Y9 ܷX"i?QI"J0uh0VC"O,%ю%V9:e![I)'V %%O|a_ttlͣ@o=6%p(*3A=,򖒒E"J~ P-XH2BwdIjuǰy VVHжjwFȲ2nzKk%!JTswjݒ^{̬ bÖ4ꄌB6bWD6ot\O%Wʟ:|vw͔pO/q~BQFg.i(n"\ٺeNR 'nTJ`nn P(lKN@ us9Ŗqxɸ!]T HeutN_M\Ӽ2uKut$V|1Y}#N]DPea{p3 m ”NTV Z+`Z,2M%]vZim_\4r!̫f>jhԛd$SY,r P@n|zV43Eik|cIW俒=OeP;0 +ҝNU By)(`Ӫ|(ӗJ;"(骓_Bt ^A;r!j&2Ug)Ӎ{r|vuC[Ü9[E~t?zCkz* ]/#G+_@Lvf*Ëoiwm7Xr;O&c ^CLD֋ ) N͡TEr!ɛx'UQ>_j V.y5ٹo:S} 8^r"i,5Q!Ky0Oe=NA̦M JYJl>twauD98׎w $IxdRZ՟8QT1xTYPZ:U+G2vii8` pkYRS{S xv_sVlTЕK} 4He _Xt[Y.~CER !Lx"/nS0ͼM{7K`Nve+QP9֥Z+۽SϮ~w?ݨaTTl6#m#((r|?;ҠD}"!%(<LnO?PW>16y䚜CqZ9WfH :Z:"*/#D۰90* I7,s$Q\$i6icb䢕SXzhD6(LeI(a^ J# Z>O u410Tw@k;l_ :vwDηµ졏Tb% LB*{TֳgC1_zo-,4Źl^p U[s%-8fyMxx8}WVUV:73ds= 7auϺ8u"N& ȟ| Q?E:7Ӆ˟z1)ݢAK R J O0d{ϟID#5Bi#$%VarXF"gc\='aӑ P, u 裏Of@[ޒHMJΌ y@`~mWPPN3 lsKuT y88l\Zx h۵'_)B@cepbD3Db)A'>k,*YAhw( " rZY@?/t/5`Zxyn[gxOYo_s䏚cr+DN({{$ h`,%kȰhq^Z}| UEu&A, jl4lZE!=KRpKD lmu/v~#X k~ldC` ֪45_r7D>8 o:i}ǭ8)cU>lb{iN@X(\túmA)Zo0⚼0ƊM'nL^;WLs4_75i}2/H[5Lv]=hWЈC1R0*;su+0BA4p:0@[+ȾG8 hGWO 5gK`F&p;=MH5-&5"- &BEyI5%rgV~9(ب8Bylq6^Ո/&b!a1D;oCf&iVB ~r d_#E+@Ĩi|c _\A{6Pk~KR;; l'nBЇ+*6AEbfVZL~Ϥ EӼ)C܋kJţJm ?+UB7ӿ*X)jOx&TOv34J&,VG=((+uLBS^ݬOB|c߂쯠eV30}++Ϸ/!dO $Y1xF_^R@Pq;)YMγo!P`X\@.-u#{5\ fgbSh$"]kn~iaԽJES"S, I]˼vSY#&Kpz̽q?^Xd@ Z{g3"kpDՀ-#˺&o~|κxh)([l1{\x6ƻ) 7(*@4ϥhsєp=prYr}X+aP [ Z@3fBR?ãq7j? T/h]<Vbϸ|_PMR˾U˂*>ɩ+)jkrBe$w94E*mp%ѿrvY} 6 8!px K47'(Ǡ8S3qL/. \†uF;%wRxa6%mзT8b唫FٌiSl}#lj싣޸57pP->ga,J;\5-EP&IzxѦ$~Bju 0iͻ=%)6hfޗF[مw6aX2J ,,)'#؍dBRf3"/# W7a$POAl O^XiDs4䫢C7`! vҁ)}A 5Ҍ#!ghnihC&bT(L+~d0P{\z$̄e>#fAgVh-9QO#'N%1M6)VDP3rFw %~l #(Ji??G%a$2^@l|PqQ % 8 L+"N$S-MɰFTd7Mf c7:&IScF,Xy܈:韠%elŽC~̭}0Xj#}7qhXv~pr!#QƦC].ҙ *ߛ W_MsuL !ֳ?&}Dبt-x?`q$젩 m*<3bz T`MZM FQ-"KμW7^yXPͅiBO0[vNPO[KOv&@؛Fͥ`Tߵe;ైutXŞtW; ~a<N'"4:0(5@#7kk5@JfMH,>BՆxPP\Ntf'C$v'$ 㑫Zj>F:q=hDC@Ѓ~xxY ra55؈J' $͂] ן\ Cbھ:WQK-!G-zV*M'~FXWZY WMKm,=0/'_;^Z؄o0,!u~~mi$)8m CʩVO $py7\|1'/&^^'r1jn^9l|qC7n\[gx!-a Ʊq 8S%u+8Xg rw`2.c u2#9ӏ0xc<}6輇5xqDM'xS6'`]Gd:w2e=sl zژ@a/mV%Ր"1\G*{6C̷|~YMağs@nrwxxkS<_<K +!)Ǖ2?47wS[(qɇN\A-FU/nj|TsÊ7Rw:N󖀳,$}S!WeZcxpFFRH{RIa1K+RЯPku5F'ބY"SG644(q=Ho3i]xSoP4H K2W ۛ Oq 9&NS,ql e};;t+ISOOjt](Z0V)I2)R!eEZ= G 2H>sS >`XUZrsV\|uR3.ךp0X,1 M^+3Ϭ/:mq$u^gs$KԼuywN ޫ: |/My)EdɆO&M08^6sѱE#{&2QNlit&ڶ;$vy?ͻ(%Z賎A9;ldwHy;Uu1 l$Q(rX~#h4Naf? :XCaג?ٴ!޴뷿p7@jWxgdۊ_ZnCc͡p/֢DGɉ78)_%/ fg@(^ˍJ8krp\٩Cj4#l  W{ums\!uePb|(hqXP߰??h*#qxU`u1Zx)q?,=$@T#c.JnEa8`Խ¼ N?ZeUG\ֈܵϕÖІ =7 P:x?hjxV+($ASioWm@vf`G uWSDw1rI+ F£D[iԄfx IH֖Iϝ!/;ʀHOVeM.x [#5nGd3qI;7c['FB-[{g 9^ۣ1cZukGEKWh7-ՍM?h@IJ-{VZt\vG#{f+"Ai<~ +kblzpwM5͜[9&{ e}@~acw#0 RՓ t?( JIͪE~jeFYFs 왘% gf(櫯6keƴvOOoF| ~8FxU.q{HBm/ 4QAڔZBvߝ~z,CӢ(ㅛQ@%t,1vϤL׀pRjp-hj1,p&T/ԁ! V;ziM]($8!:`@r378i{U[g"cw9;\1 mJJjTZQU8=~,^|OQ jRNTh>4E1W4}O\q) v {~B4.wNf qf %1h=6mpP),${X?xՅ%Ar; ޟXSLGޑuٷ5 ]ߕ c,C"Bb_T Q'u4qmz@EzN!&h$m>u83I'2toW f0Z _!7Y3([OjvǼ)DGN89svGBNR$M+a03I-æw[ٺ <26=֝19c7z.Z.rF+S"SY+b8(ڣX~wߡlOTySR<*#cCt!ioeO :+toiQ6+"Z^J¦3J[kpm)J,1sAll"z"2rOWEf`~D 7XlIC~X{Ry涭zY"S"[l]Gɛ&Y,_nE p om+@/XTiyȔF]c3 \ ^eNgB:XN3WMfD/_qs(3 N@D>2.UԉgSN4&s,P;MdiJ \j(ָO?9_ϤF_P 6iuwѢP{MaM<19@Y~wB+9ƢѴSNMkظlyҵ+,6#hEQoj-'G‰Tpvͨ}lև77 EnOL` 0,+ř(d~d8[fh9ѤE]n "p}V~ө-vXvTo N;"snr?* R-h[ZcZ,~[j>[-}P;(nwg[fC#hB[*,}z;_}g ~FSmkp]Eo2*͡TqކjGU@ L_@Sp1.)Mx^=*2S ?F4:j>Fr$܃P^pM~J={Q3uR#8и9hz n+ Ӭ/o*;Vm!Ҍuc@9M p)g1k-)]`nGJ?̓?C^O=2MҽADNXh}PLطP6/M9# e`H^o=ޕWVM[f0uHgWĩcõL◁B+Lw:4FpyPh(}PIn{2$Q_ce8Q$wcY$oTy5ғ1R wWGƾgT/A8{plh%r9F72p W,_q?3TF u)*ǪM8%Ce6b9<> 2< oFU.xg!2PQw@8R N2XRc P2 :+/qe-'x[+a\ZY᫸֢. @GWي[Sjt"}_E"H|A{M6y( N78[^hZ}{,F>pF]+QUWs 3+F߳[TU}CïX7ӛ w9k1b/5H5cV 1gf QIcTO NݼYG/ԫ4M29Ss(?@,/"vSֹ\3{be)4**[v ̋,.),Ǝ*Q!r˔My;^U17Hu&'f UcUԑsCǖ4ݿf~cL)m; lADQ>7ťVFj@ H6~"V&DɦĿ+8V\E~eZxFt1 )ѷ[NcE~º^CnJ؟toA)…a'zߍ@LxPuD3~цE)be}܈ ,s;PtϲIauK3iz'yqC! 1K&nr}羍)p4auZדQ-ӨƋ&~ 6sR >/O6B3)˖N` f3b->^TH?!iIQ&z4S7|G$g\h[gRWISYdfa%m`ȁ+A3y0+[M}:m a;KPb@|EUG$q[(RPLn/.zҋ)Rgv2%k_̶_c]bXqOag{чk%Ɵ,b\/Bt8o3^&RϾT0e~a4?p-d1:G~!HG9l>M 01&s)OUwgPT'/~?uh#yuy-+)*eoW"!B^()/(EDq (]o=A5x]Ģ,[O|O{ MPtj4lzY P)40ؓSSǸ2lm( ^q^<.`c5Xb[jr!`ƛCeZA6sxK nG 4 9W:bF 5kxY|1r6h~|#Kjc /V{큰cbW;5fh^u:UnaE$$B9J;Ӵ{s{l1,̑lq6 &@`(Sj4qHa kOGոiG`ԍ4b0j`t6S0V @X <\ u\_w~lמ~C nqיbHQhB0! 7!Q) D`*m"M<'~:K\ʦߴ&J0ÇW_-i2ޚ7CET"hLFf nɀ:1>#MQKWA8Oy{zNIwEv,j,’lxBu\9.=t;wvM&E.m*rj}S~u&b[m\uYNw(P*jEG=_$%7zhnt*>E6}t^jMbxNĴahr&z:raHJtM&S2@^`#1r  T_DLi;k~NVa"C?Kb L9ؤ~ E.rg?CloLdţCK/rf߂ܒ>[#/ad3_ru2DށWˠŇ/ݐSd1 d;f .ؚg53 #Ot *%f7@[d**Ya>ʹ,an J7Yb⊳Rަ嗅%A}f3Ƈޡha}dK&"i8KL%d NR1sj &p&E`O#ӣ{~E>T`H й:=a$lmo#UK`Bٷ9NcgZ)k3J5QybP6>;s,n⏷OcT𳭝Xd'裸M^+`at{0aA῟k׳.hEX3۬9؏GbOϨl9Mٱ'g{cq; {8O݌;]=Zs{ϟX(?7y,ioQ,*بS~}:3Qhb's[b:'|2˚<|>5נ?`ovUeOMD[\ X@xgR`wUW[p0Ho!q yZb~c2Ar- z5cvS~ssfq,eNֺȚ)U7 ns"NIE t|f EuzͰ\x,UnUw/SUGv䄻z/<K eh6k09 N[Տ|?lEd:"!$b@i(^*fȖrowP;KkԅFzqmEXAuIkq .ޱ+pd21c~X?cΈYyUq%U߫M X˗1(3BfA%//i9݆"F\ Ua{sO!$o 3/EM}O,0k*dO$ `Q6xxu$bŀ莃[d`w2y Eq`yNAzU$dB$;Ҋ>ɨM@x۴,_aO'v\o顅-WacOlhH8괕-MHy&qin4\8pY4vzv 4}G5rZz=!5MG(1aܝǎXg=,PLR&hA6D+rg7Pk>ؙiŴr'rBтxs<]o- g r$o&&_x4"6w(ԣ|?Εź$0xzr:[ڗo~Y1$OaFД照c'6mkm8J;dd %jC!FKsInĴnD4i:KQ-wI):$4xswb1 4zxL=d~5[fz85?g?|P-h`ijY&ˣ2W IB-;<&Z̻J>Tr!͜> b&e w~01\YN'Q{_3)V PrAdEP06V3-y@҇|@Un-+=pwU?9 C5h[NMwT+-~d `4 |ᄀڡrs:N ֞V\cy~ѷd"8u~xS)7`%z~EȘ;6uABڧ *VP(׼&w'Αm[B# a KJ{?\?^ܰ&orF>NZ*3&=oiP}Fr vJ셳JQrKVi%6E!9)n^ff sHzANeIk(VOz6URi#sSk 6  ڎ" Ԩ}GL%?5=#w'mߛi-,mL2~&c\V1X=}$LۻeXc{'K1ߏ{BGW3_ВV[^۴$,v|36;'璒o0RכE$@!6xޔFHS`N ֥U- y/@io:g.:ruSvz1SFy=r>Ò Wb!RWp%Wa}IBKX $> y@B GkSIżp9m|Mp(k1Q[)xj"GF47E=С/ "9=@,ߦqE@8~ӎ~* :D?Z5f* IU_V4hu'8BKeC2= 2@ n85;X}ڦ8wKҿ_2I f k -@ulg+D[[f93qb٧o+vw?awS:V@T jńkc[TX'隧Yx#ZL^{?:-/*5iÝ=}E%Pv^kvB|E΄ Z"=n'3HnyOlS/"|o=͘$0O'=P` h=/6nsM?̲|vuFk]=Q(_\ws\rgpQs}>ݺHCG3%zOJ0" /yVAH|_K.wpTKR}^*%xԖƋ$mw(lq ѤFζl [oD!7kZ$".D`Ծ:YZN %0Am=@<ـʁDiqH~ (" VPjhx.P+aao0}ATF4_er~ϹKy5$ydSYο1⊤iX?f 1 \g7]{B—{43Yۯ5{ǗaH*]Iϴ/7nrˉt INNzJdL\)g9qB^v9R7JC}h_n9Eic O/g;sMfU4ɢiR$K*iMlAT%MIJ{ُF3Ò-tzx-'jW2ax̟|+52tBBEږr\rgyA)Z [G0 6P5H )lV~F ,M^WC3MS7B;e"k:4׌,n~FhRo? ={XhL+.=;xFzXdbQ_nF5NZ<;4~ Ŗw,y oaC0{x#h=?O~㟊Dp ˃#U<ؚ8o9cV02R:}~bx 9nM܀v7~#5jȠڠAgURմFf%1e)>LbTZ%H }Xꀺ}LP2 G!7A3YHsԃG |S@1A8 J pZO6>onFIk<+v^;[ #u@"bDK^ֱ FPtʉAÂ2-h>6f~X|U{@9]o98GÑCp[7s5|/||y|pIJc,v3% =G3̸ZVHPjga%Ac3;Uyc;鬌f#X<|jׯjDҮ/Ѣ #G~R[+1TY&~a*x0:a\UAs 1r[n4E͐# kRyef+HpG2ҽܠܰ{b ZV*p'/iLDTKk@,mC>ſ:;Q3gY_|ڱs^6%lBH1nŴ]|X W@Wubn Zw~aU2XTXN҂XXnR;HEO[\)ksuT.ze8 Me}ѱ¦ʥ^S40& ~ }nP0:TQH% TZB )gD) Q#yI3:bd7fydߚC "]Bؠwv&<(@a'm揕M~3ZA=%Rx xZd.gO짓vaxї3KH?r= Ss7NIu!Ezв>l=c{,pj&G(gtp՘e.sCGn%<_qWUL+0"ePU\ y*{g(~9?_yg+,Z ^'z-*zVק,ns@@ e7AQE觽>,p6IyM poAD#t~1kB;qI~ETrE\jTFN^Bjk)O1lQlS4?9mHTL8|+\Ff4Ri#mЃg!|.m#PU'yNPBNAf?h@cՒLVZtzG$~ZYk˦ eah6ቆ R4LMr bގn)nq}c! Ɩ:eV3|b]1b%~m v M@^"{&Y\T>*k ' 6/+#~c~a6fF"-?ߥ-wϔ$")b[.4hFJ wD$+ _+fI3| Ͻa;g` D%^o]ou, TDz9¢6JcuFȩ=@,t'NesrЏ«ZCRk>24T[wҪQwTDͥO>auwBqM$޶{ >Z! I&C↭/yY9/GbL+@1˖l ~Aڅ}QwWlzq ;7Xф8~>7_LS[pEc lѧUD3Bwyl?sK!k~ 5;ſ-, 5q-3dJ/$v,ON$Dt× >֮ =Aŕ<8$YAT4C}\>3\9Sz PĜ"*/֤,=f'5+n;HMB"Sl\Tی:F+PnJX@J%긐~ϼpstfjTJL7p#560F?a6W$g\C@_"UR5LcMyzv"QbjYB"Ma3g<3|ovCtNX;Neխf4V[tV.n Ý7lbdRJSL`f["8221(J)WV}n$75@}^i/5q3 yj+-R>eG vꚻX@1W{tެIHt,5y('}t,Ij W!ByW݇®P}ʴZazg͞%x],ycC5KʂC@?q+k``#[j~vÐ/\M٥dc /Zd9d=_4}-hd2+bZ#~Z*y3Za.(]Eހ@%9.$%R~ߕ}CgBYGI"`!N#XEL#q+/TFE\A~N /i%hf-߿,:kJ<}NQ7xECԴ=j yFĘ`͐8B;¹Y<Г_ߎ_^چ~ ״z=gH ʤҮc#A:8*>GeT٦sY4sA_d^0D,83j&T}~h:⤹vc2 t^/C.^xo 6FnUײmbIDM+{0z@؞iX=mm OLG_CFG$p$: di Bl(FG[gzw1DsU{zS ;3 OƉg#{m<\u3gH)7iή\y \!`H2P p4;<2!ʣ0m.LTG- { Y#тtrk\L@dI@4 x Y9I8Kϙ3,9Iö=,m8vԤ>Oy b+2Q3xYO 0A!,H^;ӡQ~ ϭ;vl!kA1LslRwΡ06FrЇ}*c|&pcK{elIK3 0Bͅ?bs6F,ljQ7-v^lrnX[zWn$cqJF5iU.U:PٚU|hJ)# J @ ێvxL#86O/qx\S댕sBH) wBah)uy9yfL" kLg~=mxf|d-}ߟ2 IhWKpi8dCXZ LIo6CͧB %DU'OaZk-%)xͺu9!h2)Bݲ(zF3@r`%Hm"qRPA`αڀ~w8x.Onss-d#[;~`c$Ú% 5@Sf-B؍TVt !@Z-L71}څ1~$,LР@9ILVȇ\#dx5 <[t[7΢s$S gyO" 1vI~Ǽ UDžskfF/^Uf ^@F؊w8YU3=c$|~+qd}5UEJXz0<@0j{-)LѻW5?wtn7*t* z0>,\W+];>7sCJV?Y':H4b#m6A'Μbe؎(V:dG(t\N^KTo @+3 5㘲·`Y>B G^%}5 &Weo@ et_#|[L;$O;P[`3bŦ 0prT3U2ϊ-b):ahpRn'ẤQ:.y}_Eɯ]IDhُ{pH]p|]jY(J虘t9=,񎓸*KȌ õ0\V6 t77I rI<Hk4]bVF I>f+ * yrVC|\5-"Q a2 dßɻ\i8ϤŬIq65 dkdҎr0"`@z|uD%%N6F`ؽMw%0ɵÓwUG:o%RoOv<? v^"|2V|_Qy|6t(/sg럑e+%>F xRG]Ži5숎r8]Cdzw))ހ{?Pę.0Euz?k;zW\$,1 lmdUw; ]j43Y~ <\O.q/eN30&RkՎ 2!dd:GQ&&YI¦o`vȇ!Zka(1u"nn_{ȜXi Ƥ1wSanK."BUa5u-cDk,CڋN_R{?=E˰zh8=IB_;lS;rKY ?(KB ],Ћb/^an8%" =f;Jql=v~J@˦c.1R09aZuA nNVORRYAqۀL[0@S\PDz}1YQ {GO`Z6wʙrrY9X[D/8ĥB!!W:_,Wdnl*ApeI/0&>Ur F"'T9IQ#ewR @p~*i|j 8)m3 l=d֕!Aͭv%n>c4n;tNXE mj$h myoUV(#R@Bxmq㡏-odƢ^$е*1G3suN&ꒊ~׏q>2ڸg- 1˴*he Ge/<3W.žB\⻙-IɃ?j-нsCΜՄ9֜Z&RqNn~-f:ܣX%-DVq|(H$B88Vx 8AINycYx̤cv6Qy*#Ű7}>2.PJDuq h{lڔC9)-C`ڮݕ?)'Jz:  Uk8 +.ANgᒓn[XZv cYTh9c6NW V @ &))`G-ws+4K~҃A9cm񦇃=nexnٵ )5dXtl9)YuqBuĔCB{)b@z>͓mk/\p HHYAs+ډ R$qߑT}J}o]*+Q ]5*nIJ1L~ ?zjPDpe@FH vfzf%Q. S||~.UMo#F نA2<˹#N&w 1eT`ɻC;|![)q'b}k%'|W*quT /; j9fHa55~f7Y|E*(y6 QU4H.(i8pܺj䤊iykIIBjmظCN@M ʕay dC#rQirS>-`M "K1!$M~I#=<!LқxRZ\B+20, gZ\Q4*ƯA;HjRōgbqXW cY9SSlIr%etcsK!Ln'M 8|O ?YȝAy qOПf cHB#slǙ"O茦TJ\J~_?@k9kTuK?^$\L>XZ+oU ˬ_.R*jz y]~8d`H(<X_(N+N!I d{,S$7V],&QHOKGXـ FZznl?Y !l"ThL RpL$\MI6Ŭ^3/.JWSUnܭLDiY*CںGM@ z.kÁd90ڣ2]Q2l_dʄ۵.cٶ* abY2r8NbP2_h[ uRX{ Wrg#I|@^18"z `Dڋ緪({v5p~n  ou EIqW|`+.?qnqDC7 bLkJ:+_0fmw âXPNkR:EBxqƁKڪ5,dmB&bktons$O$&$*yYF&J8{(Djv9cEh*MvlPd9-$@K*Ҿcw ۛh~7M[`=ue6M@"?b@veo$jD$Xhay/(F^-CTY< t%#A9$LiVlqұ/۷gĤiWOJ鮱4\t}cQ=ȆُhJRx@72xt۴{ m j#po}DS/j &ZjQ:vA1UC y>c7zb$򀱪W EZw;Obyd}uJ҄ZDp { ~uf?膌: c5xS^ :y>i=a#HE΋{/D9< /Q0(L-)&{n ^CejT_y=AVs6t/`W2+UCI*S=Lv,s{b8!48i{~̅OXQf]^a!tT'd]RNցQpL =.% Y6tw&GBҺY`]oM5E/p=,d(ea#jZ4m˅2MuI)U1dO5F< W7~/)rYqZ7瑾,L=E޷\kQca0/q YJM)$*5j2eT4 Fs6*R@E'psahbzL`У”uDTk)2 ķk[>';PaZYiajhw[.r0W]IdZ&пڊ؞i+~Q䥼﷧ƀZ:o?z.%j Zuwg"$-$oiyC|&ILN=Zpd¡j;>X ֌˩f ~5&كɼc~Zўڤ,1QB>ŋ;8>fgx]N \Uչ3?ZvlH:`#mwAXƘ?$"TvjТF W˷URZJvd8޹d+3 :O.r0MGik R'J = 1N[f1jI?2s.v!=B" GUj$WTR\ ͚ Ea~N}X,sL1wV3 nMFgk_zv0SH>r ESbК>t>qi"xʙg fJk<(ɮ/v qtR3},Aꤱx<.!3Xip\ 5=Y|JUIx=Dt|~,oPt'2ӟN4cm0U+.Fplf+ 44(}xubgYоKCByӒ|tQ -_V!yQ|%UV v)Z+"ʗ7sg%Ny }UL=J%h)>;!pc_hDopAQ'ӓo\&~d3է1p?-ZVo:{%tۘ&3wҐ:xfPa}.'n.T{i_a>6Jd;Q}c]%ER0}WQ$|hA,Iئo[0B?5>RfNDk;՜\2p#c,zţCsH3yqІ/>,DĢ?U-oSH"H*6>/."4ެ^Ω1Ի4"8~쵧A$Li\+\'R\魠{<'B&ˏՃC2@=cctc!|bNXAbƺBbé+p3| x+ieh4tܰ(0^xn_#~i y͘C/,=m/o|Wb[P=XBrd"dʱY@F+f5"4 X^$oC,>*)/z;ZY]֟[σ}t$\1Yq bx?=ֆ'A+bhャ7fTDf-.;9Jc$_9˼.~gYj$_\/5X6hZ? v~PtW) aOWD#I8#e(UfœNQqkW')ri\\MIL GCܕ3tDaHY H'`-7![w/Op2vۼ l~bfdRR[M~d;[5j.[bDk q.L"/L}?Ρ?@YmK LVd)a';۾qmwk^Qle6o`rвUӦ' ^gLin dc4%tB( N۳@HJ$36#85U,{Wlkux@vyT3 L89R%6@&$}gFeT.uy1 3,Px >Fe&ӹdA_>& j~ .DCN ,Dd^CM"HɇP2A<:81U3 z,$@[wV|VLBtSYK<٬8t8^QBoܜn"[Qk!{bpsei46T>#Qq]VF ̂M,O. tA!"a);Nw130u<}FT刡H۪Fό ,keˊ8m剡 қ)Ɠ7}.IJ67ʸ@ۖ*|;M_`v,Vsmu%S Y3Gt̋hVaGFPe<i.2ՓjC+L=JxCQN)M8/?5Pb}ElMڂtwr٩l afoys1:wg6f7ߗV$'m͘b$#^G*l[ uFzBʼ1޷I#%>qǍZ}+`3}kKK*88({94384&1; zz6S>~(bJ+0]Nk3ϱ*N*3>/E.c9K<@UԨӫ[ZG%HwGAt,S]>5TK@P'C+W5C6h&1wұsc+aה;/G[!{ч]GQ?h$ TU{5Ɔv5A4ME~ø11]+|3 x;H8{֡a~ub+WC xeغ)bY=c12l]~Ɩӟ]~)'IX90.Dg5ȎłxF L/E8Z{ LxuX`kC;[hA'YWőPR) ‹4*B$^Z) @',OfNN>E]j̆h-Shi N4P4o]7dX9>=90Pڦu2g:=<` h?XSpr ݡ:xs=C I zs_;W|BѤd+DݶiOpӚv=i+&:t"|l6F2/qC?\h}hMr{-Nq< rW'4 E8w'MB?Ŵ|rLX74L"ܹ5589dnJ r{p}(..E΍yfzuȡ/ s^w 7OO26 2:kX8^J(8߂k{"9ŦꕪEj4(?I㨱%Ъ~d/o2kwYђd_3/sZ k &4hWMSe'#9銈לjnO?SBSE-~iM.3h5-v̽7bL6vOIxKED|UG i&?x8@cr~]#r*=)>Zg ul,c*Ddvy0`u:9P7]pv ^'X%=̦"Rzc&l`qtjqh-j#LNk%u^Ta 4s[/5T4^ًjc $0 )>7%I4_oH`Iw79rtl:5.cF,d 4Vy|Lau, ]37OSDzT5#@XO ]Q}xYB1k__K D(!dXnEP_ CML߅5.n7n|?:C(L.L:GX/k˵7 q9Nǻ]?OLC/l0\PqWgԠR'`㷆noiж >c7*8i~v=iQn=ŇWYΤ%L,pwr^2P?f R87e8Q;$l:nSr)ӛ]k<-$ʼn;j$;_;з3S (EѤ `x'"<f5833O zfkaY 0bƭ2k&:\?1p41leO?z1'QQW&Z+t=A/!wvf<b*R%^B}-_?Ha }p,b+P7E .}TS(G-rF -ю!R|$s OUC_Dwˆ8g>qqI>\V>=yEq|@17oD[};Va[Q@ z . 9ⷤbI61jϠJml_(30]t(ėVAi'pK̈zg%`rzEJD/OxWʎ>ĵ]-1@yِdpo>O<ǾWSՀ)h؜37N-`8 [F7B;x'ʆ@*I(mvPX|Ll)mnO:֧BBScy iʓ\94 50fH{ΜU6S{N薡sUn_z|`ESI D-r >C)pn5+_LpܜpBU_$'= +7'I @g;(PD`f+FkBapk0 3 vpa[s^؋X %>%4paLN/* 5,[e&<0"M& "r|J؇NIaT1Ic܀L/.2XO1!Bno|r5RdErDv JdSnt5l_v$w)VzK/<[mt=Fڨ4 JZ=W}HUnBګC ߢ/ TA}O(铨*Ӧ•i|L{^S.o&٨jR|{wͩ{ >mή4?Heux9EX'm*$~{ ][""pxsrA\PGIxJR",,U4=aDkRdCGf-*%kŷ CIMtXY/kL.FEH -mRI!ܘ/,½8_%+[UqJo%^IA/S?G@ #xPA ݌-fi`W( VIeŊT f1-5ou5/v~F) N9e1~%|E|?9觤_,#+mכ HN {靻mW[yq뒾5KArޏ*VdZQd1#-sLO-lH_ܞrGd##~FvB+7RۊFFU!Owvr=M=1NvPAƝE.xU?2b[SYhV@5r,68y2|eT l6' Z1E۫dOcϖ&#Asv-HOX+!G$;wH#8HZgwWk*b*0֨>hAr!g6 ͅqM41>Sr= <؀ag2QLD\\oj\}@o_p_[,7P^ҠFPUxܡ-IZo@)ְ\`H)$#[ݟTiب=?|܇ g kd8e-h#%B4 3E_'PfxH aXbaH7B4:6eS@qك~)a}Zch,O%_JgY,%H88nn:{ϡ,^:k]aJ`t<{ad_o:l.`2>B>FsMri-i?9_&tblxp<4C-J @ik2P [.@? h;{]k$AqLA0~chU`0ʞ臀|ˡ6X`p`&O,u)Ϊ({ zKq*{w8+kcBhs Ɲǽ9u2N'7NY SvdN @oŇ9 ]q6楅q†XA nlH>8惡.}T䧐(V@H\--ܓ`2c`6{Ip+n "W͡'4,"/eJ>'U;%\EMaEh]_࠲+*صG4 nip8Zm0EZ>AꇆS:S !w֐OHbK )|ު)psv#9 =IRsHueH:֚v;)du[OÁ&ŃԪ4lIMb4UztUiK)ʶTOc,jAǭiňV.0@BDt97*]-0P92NF]hO!XPN.ɧ'Qhwk]5o7W[?9Nr m BJ^|ۏQқv@87P7|ѶCņ!|"1@SV2%>wMU)HwF7b6[HIl2lA1KUG>UKm0>Uc^jN^pSe;ZZڮН6P-7bƸpa9 t*ru 6( ˎ%ő]*K#jpJϳw͆|pL<65b>ѕJep 䫩pd`"ԁxR0GgWS?Ey,v/J; ,pm?OyKb32t3!"`1c$gL/e:TYh1$h^eI Y#a "0l(~P}In/JeQZ%ocÑ?fr0R_w2i<[u3@7E(f2+p,cTcFJeXyL*:|$ %P&C $%BONN4lVFoh UTӕȍ\b`_@::̰\^J?[4#Sz+ɱJͳɎBZ%4<GMzLje0 }J.ь\6]%}L@I:"nbE3sy= }NywA$-ަ=CR;]OFuUo*.- DI3G (LMq 6hukJpq-/iKw'3C[zf{άpj6+38bq޼x2nMy4v,jdgǰ!HxMh* Gq1QIzeE}Z̀7/k'(zQ7&)aR 43#3zbգ8Tu_j) fxs Cp&{9J2 5ANFRnIHgd+ 4S ;'f~/I+m t/(Er6I}\$&$.Zj,Pif:3,78x(l7oHR2}Ž-FIsE=%Lt:Zy_:| j>d\s^iB1#M,Q;b( /C6`7SCiph wҸo=8dQ mnPO+?m8N s~|.5Ӈ7!J3$Ū1=rA'k VhRatF)cƒ]9 299sW =qBy|v=DX Jٵ^_+/{a'{τ)WR_k c f \(< RN;[.̘ux}dF"? b~1mrAh7 P =Pkx(!_&X _s:k׋iʣo3piI*FҠP/NX GgX3 %9,}V#{{Qڬ#' ;a<׹[%AFg쁾NA3n=6î{s[aTB\ :[07kP,yw⦇qhi2<=UO:0p_ӈhqo'Rǿj5 dDjWw`(ؽMAd [)#(nK;ڕiqY`.yS%jnӭgi?,xH};ƃbk7kҺ3Gy S?a7^1f%R,|-',|DW`brS#抻L:/PҮɖ 7KvRЄRi.C.Ӆޠh'#\t^vO†:2BG S9`zLaŇ5h (wB_n /D1+,#z Piy *O@' u༗|8'Z47\o猝CMڽfF4v&* 1CJ~{te )>^Q;"mOXDߪ$Dj)ZϦܪUrZ311P EQa쿲1+ڇ)Um㙑A$F18);PKv*ɃbSՁ i32:qEOl^JA^O_=;X| ˬ$MU˖DQjyoX4eX&t1@xT2i#97%67,,V,ΓVc^qH)H"@[Ngc G.Gƿ0 5N"7DCZjx|iY;7q50 ƞf>Θ SgANk߫W/^ex828|}~&r%;acMߏQ:.~²(?'¾w\LFM#]_z]b\f/F)puǭ153`gI3I ǽ^,R X%]uzy`i"*m)P$aSN2 %C`l zBCЅNTa3N}l^ x(X,<4E77.\ z`N4ٰ wvÄ{UUkiɚQ!<Y]w R7'mgXux!ܫyKd}Xty, MO4#ΛiYR驻(aA74Ms^׭ kf/ig?Т C+P`~)pr^X+m-9a֥鞒pkJJ-֎u,diFY&;ANG?X>%JwCmښ˅ER(sf$wƒs#j@5#xR `j %1UW&3 )0tE>}"' [opŴRZ?QXEU1ܱeW:P^n4S8W@PV |>o'pw|]E1>%݉> >Q=+dT!wY(KslVYG511YY&lдi2xZt>z:a<. ,;b@4=bxab\# _*h:+Wa0MwY,*eSyGSp2!lHLDYefԖsüY,J1ӭrCT#x0=3P^6%ƭ E #0!`rtcW'Jow[Z`B> %LL,8q4]i3ky(goΡhxB/2h?UBUr~oVh,ǏT*^so&_FtƈHrESĜ9U.iEvB|/s*ȩsݑAhhm,pTܒyV%'*2wa]U鈱.Gβ(O>Mrd](j&F1v9ay䅚x>u (kZU xѲ-#<,";HFjskI%~*pnc+p=?@1 ˋuF t|g-;t;HE_͗:Q m,E*NBD}&RtՃϘ&55/ &p(y ]>[ S/KR3 4:0۝=j՝#b&fU$^S.7QR39 !DK rF!uOTCa]_ yЊ8OՊ vwZ-LQĻJI'%\0DZfF[000h,6+\ IIޗ9+ (!GTHo[YP1fxKO'd E7 \cWwC Yp|?QG.B$p:0R(Z0Xł[%㠐i~\¨+l~%gXk06aqYB*Wcan I|E8A3|S&4W'%e!pLwYKxq޲ҲY)_**0*ѫp&jU^懊Dbap\?*r^ a5+A#hlB7ȧ<LFGsU~XdSCywtV\?yH׋99*. ֭[x K `AO{ߣ2(4c?;yOM7n^Ӣ\\cTLٚOm+`4Ԭ6m~m([7(ݚ3$V6nEr6Vtjf(:6ya<. ONJDve=C> y!a>_Zд5>@i6xFG2 [y50`kD}4j8v *g 4>KUs˺a |%iJ3d6lDVBo0C:aKaZ/P7vFhʲ="~ '%BP ν ASߦԭe û3F熊 LIzhnJG`' Spvy>#e]g-OT:r6xT[Jvh2T̔g㜯S3X2Ei&|EN;`JN ΢E[ |m9 We/M2vw> o ۏ^Q3M=* ڻ/lKcg+"ii(m!rEI㛣*=ɢHU`us Oh;2agWKJҳGy X3Rкl8e:LjeuHK._5Ed 4>9"- uI(z6ɇVn0N\[`_n8 =H *ZMf.| {EDYPP .ϱ5M; iI?r+`3FMI/Ɖ?H OJs[/"\TӐ{T2 İQ:ȈX3M4{ /X ,Q{ef.\H5O!,Ǥ1,M˴zNe<@87@>C?+^Yw…9<mp^ǜRgqPN B0xWme-dM.CN +|9r~7#~[L1Ӌ $\\R6a>H΢Y$n-ڮ/;@BLp-o|;VY=קb=_u,M  ',uNA8M0?)C'D MP\M932H,In@\ouMIA9Rk1KʭIȔ͐wBR hyyRJ]9xo~qJgQh1r- %Y! ru4]NF1|@vJ8DDKƚ& _ $|._zqM$Ynr&/48r\!\7̍dw]XJ[젯. krt Ȋ)c%H|Ԛ0޳a ,L0yUCT3p*1g2 4HE@:dx gֺ F鱐ϱ~wE'u!v2y9P9[-~v6"~e[X_48k!`xUpY>τ]:ǂRTƚ6g}\6p&54s uT`RZf\҅Y[_ R pWK.& 8';Rg}ŵh6BF[$x}=-{y5d;";V;,y0>in^3Bs"i(,0d\9@\k>kI<˖H#/˾m|.E(KTTl[(5^W2gO!jWMBʾ~ABg_Z|d~,"+:FXo%peԺ>% rJzx-dCmCaK ]6 ۉ }~u6@Y7[G"€O=/E?Қŧc{ѱpn煁1o/9k@Fh43UWv*e1pPCK 팺VoIBYXOf2{l}s:[}SKM0VD}k gHqxE,I qrf+䂋t'-l k#RۆbzDWMV5a亣W=/B1_x?[kaĬUem8-Ђο-5P8 `lhRu~ƅƐKF.a~}-&s E')RZ? At~݀#&Oؓe\EzC &_xƃއ֞t>WJz_y","rfUC<&$:RA!t"|'/%.GRY(N=4;hzV<:C<pR]H{^j.;?`0:9S[Ls\xfeDwsM'IhS C-SPE*`#z>`̮@P1ڋ0Iǘqg^Sh{U@|Y+M3Qt45ꤨٟ8"/lCL|(]:P0XN ı" jc17.v{Vy76ፌloh.լ#IJD'm ]uآ8ޏ1H5v4= }&Q`Q:I `6>uҕzABM@7@,#l,1 βH3:Ʃap'K`/e8rX <Mg!v7Ixu6 4O;`,yvʶNԇZ:#FB=իJ3Yq#c_vzpgAI@mA!2E8$"r );8cGǸwӻ➷5l@ {&ӗ$vc_$1.P-NyX򥹠]=%@{ F0Vo,`w)654prՔ1(>[^S:q{FD+'}ݹ' c%w/W2#z>:_dze'F KMdg6]Xmv'\hz҅+s*K=߀J¥0B]e"^1wwŋ33wS$Udy2g@Q}=g`WfJIc[z/u)I8Vi{DyrKDzV訜5mIB({{vdCMACI8ߜ6\ɲRr.H ys΄SS3(,ݏ<^^>5a6Ct.77ͮ 0EM;/I_F zd ٙ< 6G}8[NHݼ@5 բ-.-k ߆@}&t{jȪ}u!TنD$!&ևs:m3O Oa>J9$K y>LҒRJB3R(GhPpބH c,c 61"$=Ҍ{DrV|O5Ot%Ny59hX_E(&a/9Vz"8|,cƾO Kx%l%`1 iELyIe*h^f.5%.tMsT# 0 7)ɥO8Abz/M޳TC2o4ǝ׏8 ^x}Ƙ$҉(hh)DR9D)Њ SH쭓8sPwuc+2_>VK&m]auu: WPm}2. Ϋmzj_4N|e Yjg9. (cztݩbÚ˜ ȷjOk.snZ#(9i_}=|,%geY$*%lD6XgJ BbV*qӟhكs} ݝ~0/6JdyB;& ۧMZ$rI8MS\I$ؑ&Ot3GC{R:34ÚDž Z&P[f =aB^nXjL磑sN 5iňvKoTc6eU)VT[JkWfƠ &.Dx!1;⿝v|ma-,Edg8|jϝmCE҆t8ߒ60ܱr!I䚝lGsΥJNwou0.D ; nZOc8%зG5N^v^+9NP+ N{݄H*=. Is6?257X62HL@ƕ~:q?پ7,eyԍ),1y/8V'r D\0j@y#0T_pPm9&vWu`ӗlraq h9!FIpu9>j?$+s $zMۙv޸MdυN3M !HayӁhzݘ~qk_~A" Y/jZXăIԕ:6 } ήIJ: +FuSL ȿD:bګ_?P/gg.f=lL Bm]ejNarvlb|IJWh$0/IF.=gC*$ Cx"fxvÀʯ? -{˫n=m$q~rBgB7jz9B>W8.QAf`p̆\;w*6rKD kCikΜ2,!gs&ذIi-)JVņ_9PgJ6a"FSl7el9K1]-?Bhɢ p0F*y6&m*a nd\Tq˳m?k10zv)Zs{FN:8%A0N>a(:mͮƂa0&A@}SqLs/Đa\ORUwc>TTjs2me@ݎJ~gERk53/sNeSɌ7/߰&@{UB:8P&~`wz*Jq2מI@n X`I<[YOM`a4 |]}}s!M(CEpa) J:D:l]?,/_" }]9 O!*Jwr4HТ GՃOVI#S,2`N)W.TLU$ y;Mro]$/d*$Ip ~*)]CoU<9-]S敦Gv47c-㎾]'<io4*~^UjO7>SK9zSڻtJ ,ݮʲGH kM9@}I#6@95~j*eִ+cRC:y/qjw#xLvLlV4bF H28ľPvUfǎ{c #d[o4~To=/q\@ܴ85_{Řwc/¾Q{WsF.*)wtʞ> A7KxX~#(;۾  ]K7 !UfV7wKFAH]0RuXh~I HoID OnK4y`;Jwĵ[R vF3W/YCɬzY.pd/yt*լ5Je;]nda@[V|Hc[ozs7~%H1J˾ѱi ~mZP35 ٽ25=6wˌf0 čB+z<yŖUZs8հ`J${G-|+^6*uH9bwi@$˥}[/W؍e{NȠs]"V S:~kiY0IJXuh/}s;Z':z56d)tUkH+v7 QT'3$a ۭ_!#9BKKqiOgr5Dn xAǖ]V1:<^l c1"Q"R8L.'zm-#9h/<)gukg7L]a{n<%]u󗆼@40! BSH xMA]=pY*R8}j;isO\.҆\B8pyVI G$!iTJDVŮg\E4 F8M IU(8pzp57A#j\ܘ T J('T{ź=N+鷡Hj>b(¾Ė:+=N4C5Lo Nn r?Қ,c &u$ſ}c>Կ%VD˰u $+phf$My6#9$FkǁVVM%$܏_lQEeLKM庰bYRJa;{Bމ̷755*<¡sʜfYLdܷo3( %2.x%s'63#V(!=ظx CPICb}429M} 0tη">{U3'ےRN8=#蟌~V+Rkp\AOj%|=2B> zv,60߯K"xa1`lJtkn1:U:˭mhfjqF>8r l؛x1嶮/ͤRsJȒѦ*RO[:i:p6k{גLVb$cu~1t/Wtٔj/Hzym>K; z@[8L-'|/ŚO*W :u&7ZDs@ ǧ;RZFCYTX[YT;O$Dݯ(LJ!ܥ̕䕲z鸽~!Sb|7.l-˜og?{] JVSk %weAt< *ϟy\?! p zX5|?~AڮuMpe} R]NF[+UQIl(5?I!JAXۧIK%7@FVH!{ ϑ~Ts¡~K/im L S<*dҏm9M *_BLAD? =Q*@}o%17S[/HyPgըQYL]S&f\v#aEu3ag&x &gOO'a&&8R,^.E8g">}J>~@qphaD؂Q!,H2tkfYMnb]rkV|͞8r T|Ӭ|쒏NMA!_%fNXO;AoLScxPv˳:ڥ= >˻67vSڋS&{7x#|M葮o8JcbCOLWA<&4*y߻ӓg8U|Wm q PJ3-.87hi#eIVkhNj@dc^<⟲U#֍ƉL F!A׫oēvLbS_ve23GޣI5<;!ώ{ )|^rY# R<ЋiK|Uc_@\ duv]yUq$^=ʿq.g9m+L 1zx|oz/GcNLnHFe '8 G &v ߨI=%j%LX25wdhQ ,F= A^qR7䛫jr/ֲ 4 =*" "B N)@֪F쀔? BYM.Ib/) p⳹_S8~3~'%(,Wc}W̮ː95X e_odrm-]C6b$u"oMH /9@MvWqrijrf2X•Y*9L fC ĿbTkD!!5; \ \K<54SyYԩup[Iʻ/Ȳ76a_"$k祃]oRRWndR|{J6P઀P dk<7+ifyut,Z!P3 ~,d3g 'T0z01{#Ql :{47J}zږS:# >Q/rfTF{=[J$\a4c\߿Jgw2xSB?ؽdh^ aY۴5g(P襦֞J'`bshV?7>nLv̝9pyx=Gz(n-gg!_$:uMo$Ęt JpD.Wn];K^~0#E OpO33ӛ(HQNZ}hBvy6ey IphWJkyU4WN'!?W >"!VbןVEc%H3 S,簜%g-6~L6e|F A7[dˢ_\ >OE^L| k}!خSC7)4I'2#%rhea><w/a'F|[03k܃Ǫf_SvDw@iS[YR-> #,Yd b`ͬfvrjg7_YnD>C >H/@3';4dv@z5QRvxM6U?V{ͯ}8@\}oHSZwHIfR jLeel.1u,+Fy|^>&9f55!BcL{#5M#p-T9Wc`ɜ5 ͨexH4PJЈ[.h1}ѽܟ-#XZ1xC*Ei[i6'"89p@Ƀo2}SFVx(e:)qi,{2BڧWo~`<xcԎғNZMaЙug aozSYa %@z"Lc`> Abă^ PT xkpM{>*v-Bu,#/O)ooi_8yjRoRnq8 &ZS Q*X8cc!嬿|SORؓp00vX_ ˻Z FvocgVF^eO h"佭qڧWf)^YlBCp-Ǒ)Iw 9iH15#WG Zv𠷶tjx]܊ŭr-1a+Jrma`x']WL3@m>c@AhVТz˜>`D)KHTdbk Iڌ-l?#]+I_Ss6$<ğYZaWe+bbr-b]U$pExE2{j 8FkcX9SC󫎖Ovڟ շxdɡ-\ uLT{Tpg9X,R=]ےؿA?-<]ͧ6_'2P g#B OpdɎ\;͊ >SYw58Ą"0 DccV%baB>)2OڱHaCB4ckv5bQ ٰ2MMCa"3jo[fH)PpFΰ;O'>t|4qQ VW\+M,&|xe'L  (msJLm9#ŶdC1 IoR'%Yb59PBc"ooogIݭMh+qTf#%&Y3 @=@9rr"3 N/9ҸRi&?A.r56_*v)Z6n&I˥N,d@fz*9\)\УJڦ}X 5hcuW$%;dݙk:X.g~;љЗJQ2V;G 9'[{3Ѷ B%I>dnT5 ҍp>PFp%< Dz ]5Q%<>6_s܎;BfO&fLf>KlEKҽ*EVGwψGl&܂eeR ?@EU3AAΝ](ʕE_Y S::\Tyҙ播J(P԰ J٤ u̗mhNQb]u+A ƟֶUob}ug0C0<ךs(t'$-vK3\t7뙊9f$Cf/5u.qб5#|`,OU.FJ-%F4mLAOAyCt0g8`%jTFjx`!B 1W6`!CӢ$6(n~t$,9" b$ʿ0 b$Az!19_zX껐QHVb~?'TJHLQd^X /۽eTC=u-7$`i%#Gs/`<][uQ4GE; r '셜g_殓ȈGCBo>X'4y{o p楰-z{BK;: t$´{%òUiVxh`F=iRhy0{p2l5bZ!쬡j_>,uig$7"Yk+DUH>I=kN/'5,㷗CZp_yƴD;(yy$Vx-}о/TYo13DTQ&g/Q#&>*m;X7wM89xtr'(. d.Ë`ǦX%3yr2Ĉ=f~<d֣ E\>VL-Jh/mݭa7t;N1Qr`B{Io&bYsZZX63X  !d̖T05]qdd揈u:.:JMn][iG}uщ8mDe:$& f#ҭ@lCt&k+UEԭ= 0Ns 7-WxTl2uGɯCz+#:[p+UB8*> bݍҋui*x~kBoQ9c%?h0j!OyRizdvOXsJdI\oXʊ aPnXy  8XgԼϵ t¥XmMN'o[72H1;`oQ^-"?ԾҷVpqnqYQ1 0S Z=)'|$Ӿ)K.$&}#:Ϯ06`Wv?ws!Z0el iVzd哌37!60iHfĶiܪE@hсk ^"2T_ -7}<>D#R'* xZp4mj+qg~5>8<[?X|h60)?Zh*ZXk٘ySzU"|Qe`{YU ^KE޺R#ASc' }·0jy1RIwؒ\@^cI5r沇0Z3~a&:6X(7z݆`<1T^NJШ?V~ʐ6MWɶ)3_]@8QwM [fn=ʌ iAj EoE3_h4WsY:=6>`Џ9lZ{^lZC*V?AWN4UNjzBHvWuM"e6M蓮Jl)~|>"[=~o?,B3Sk 6G@;Y̩20d[y?HfCb/!-uyk<#+ȫW&|Ka7Р;XOH}6RJuB1Tυ ([BtA)3*~@;j`T5O> 'nn-+dCh GJ#^fҨUm3sݠjM ۆ%("/+U1S,9|?Lbyga(U!q.|;rl4gBc,:bE] of$(G깴/~%hCOLj$K]tOn: zhxJsd*R}8c,,,4: фZuʋqA?P<(p]4Jr;H7gyn(ougտĪOE9׿Y#f)U\z:\ ՋF,[b30ށ{ؾwhŖ-yJ Ý;BdʰԷEPn?SkcL_Ci!bVuV`Y߽ymkGJ0c1hWeq1aLj @"2xTۂ^3?JZH&C[%T03 `B\BFcs):aKSPG} C0Y]$ٿcC[E 0K @ ˧z:dTͽb' qxѝDatphT#en{.,+$J Nml4urw+45a% û;rn:jJ),X ,L45vG!VQm89ūd. ,b{O2@>8cUN61Nk䵊WI+ MhQ5 W.V?r?0K.~,~L_4撶/qxjpnܛB~J+$xO/7y5Jy/>EK$|wy W{@E4FhﻭR=MT@VU!+f'm:9SPzi5Q&м{}ɧv~uAXlѽr Ɍ#Z'3(x.QRlQaUג ܅ZN-Bj'vxZtN?NEB RIZ3-8|6ڤSarꁄ.I2\xym<{,~|ڠ1C R&8ǛT9Rxc"C"tNMS E8` ϖSĂ N螘}H/DZquH>=J268cCff-q!RH zu2( pXfT\,lZᵂΚF})֊0\3YuNCi[6{|_T\MuvS3Xh_.7i1toDKV{GV-V<ȑ 9)PT k_OxU\'/8 c?&D̞,I=Vo =e]mu ~>PeL3٘*xh*vsoqCO4yV0N5$3'P!% ^S,2:wo(ALMf C9' 4q~V (rU 3ojAFfKc=o"vCv M5|OƘ}ct PdG-*NAYynWuL6J09ח]KcW"jW[ 2`Bq}0FNU!RiIιqb%/1e`3x͕y7~$2ipn% ^Ob̃JCȚ#:l-0p/,hP.z qd3Y3Sxf$=#[ub5{ R,XGI{jn5}Vajy"OW1eԞ`$;~[VݴFp/ e c^y6;jN} (K3wN7@@Hz/7+6UNl  =.i"rYYwd/Rz N Z!\wd/>jubkKS ncQæX":5ǟm'Fx_ 'M}7 50`ʄm0#N 5KD2Q,5^ R;$=5>Yg]r $r./No?s2Sn|y|,ԓ?)Dt5 htѲrOZNV;e( !M2Hj9bwoB$Y?z*U͝Lz_%S |btQ <]QgYcG1ptR^F+^9 O!ɏCh@j{juj5"w0RqxaC?iJ]HbFfME:h AZrK-‘J72׋SBzTA]L\IB*7?HjUjR:,vZZ-qK;i(KB%OUʰY/p;IzJ6{p4FIhkۙI@2KR7t}aRҰYWFt)zPwpdjuh`1q?zFV@Bz37 m FkIO\ :F\rK'M xA0v߻֑Xm$EmM9g"5| F4%Fb,Mr"}k@%JSQxlJ'kc`T+NWlQUMgFkoz/kN/$:vKVlZlT'ӪZ/-v!K~z]+cZxt͝1*n}|tхzT:tߛ i(uQXWN݁|S(F-sZ^3b!SfWs4?nmʔV ?t|Nk2n33VmF5p6BVKE&⦏.p~d:C!]î#\U4@b-1W qs TI} 9}9j &wd."@$V;^+b}ΌqhoK}=zG[PKh}ۺa]pvwK'~PMѥ߁rŃsS;4)DqNVELɦ!cpz,_k2XYdkH>M|1%jBW5E"E:Qu@^ \Sъ.7_vgHZ%$C|@X͛)ײw*0s5]P;ϏjBsq)E%q.|m+d)= AW=nZ 씛{ҎKL:Y@KO.!r2#||!ߕOʧxu>*!mHFfrYeGT.*\4vMov#F)9LuZ!w6TiCڭW#l㻔%9f@̍2wTkMS3#><<$^]R|1av)[^"4,[u*onGq/(Fx,DH]1\&0fOB,aj5]!8؈,$ʇBAQW1icˤd ЗNb7P= a+@ SGRϹқ ud 5ȗA-.C87"-ؤ$^Wphst&#M (hd_>~f,:^u[ \|, .Wy>PX}r""raf~l 8(diUan'e/7ea 0o(!/rf? @NVzP/y1SSJ#h#8CJAaA+iHta.p`0L&KAV5@Z9i,B6+;D2.АR , B(*0+84Kw>WD|>>-2Iw.¤.@C{΃y`ٲ V<WC&MW^Aco c.!\-,#_ m]`^eXLF`Nۉr9/8@uo>KU9=R} 6-Pks"bb'TMBx I[PҼ$種>3qۉ*|l}OLBh?&dk"!ԥb> AN0xǐb9[^@Ͼcyi: ?-@/3Yj3:r{MFuW"d= -ֳƟ=d;T97G\P*,ëOC f_2K7hpX0/2bvWQ{ʻجӕ0dJ?-{zLYfpҶp[|":+_9ד?659)2l!||k3Kf&m + XX+9S iXlԁޜ P]=7ltEF͟zKyJ@NJybM+G3%;gsf h.7e~55q[H7䛗XՈ+la 6ߝüuvt؄, f&,QqvP<8EP既3]xC:v7eT\(4R% :C_}}Y]7ID䳱=Y4P-VwŁQ$T?x#t$;}A=h0x=1z퉍R⢬7@o6!B=iܴ+O(ָRϽ36u UP\E0cC'iOЄnID0.3Hob3ybS[mJbS2sWVqHՁ?:GULoѴW/9'@EOH+.v=7 RUfD? m[,R͊ 1\%Ũ?7|8Ql|7nwg)=ܩjwk7}=rn{ۂĪ,\o?{N8yGQ;)e5Xؠ6{3Y2m &/mlt!o]l J4]iuxɲQb|--OIQ^y-c! mx>Rzd7 )IoJxQs\[n qMxsW`ٱQlR.nP WEϙbd尌.0YE,pDs.Ӆ#S :,FDB]=񖬡*E3#"IiH3\6N=G[@XHw}Ak厧btwD"1A+߀&U{ C V0FV!`?EE'c~/IFƼk}k2QHmu? LA&~lv T@/e7|}jra=6aR"^O'gK!  gk|H($ :4ψF-*6vbfp'wo_Uuv :dkH ~-JKWsU ;O)Q18~6Xf_aEp9SC$xe aw^6ɸ]ע_룃T^1|tUE]U֤ӇhHs=2ٝB~O. *"*у37s1+kuYn|y_;_PdV矦e i։ ;%PFR<8cun]##:{_O*8Qݷ ·qGwГR< 4=2h>6{ݿ j,|s'4^Fpn5bLJuej!`Mb;T8ؤ'c'6r|QD7D2ci7i);{z)P{bpFԔ՜4s纬91 /$8e/o׼b8HesEgT=Պ%7@V8*p آNjvq߫ pei[3~}ͩ_2jkU_۬ߜU +?8҇ɲRXY5wt&'V& =4] KhrN,U?KCP;JYE !DF.A*M%WnTGcBN(`:rzg Af|:?ibYADoudjȹu6ՠJgP"uƤ?8 {1\aX>=Y O`[?i0c&x'ʰǜvZKJj Ɇ95tGQI !NWN&K*@}%nۆwAE(S;;v5Lf~bT'Z]m]*:-- Bmݑ7w!u+C79nS?j(3}L;i( H9#6KfcmCO>s!4>& mJYPʆ+6[{vDp-^PnX kuj.o= IW>hj(348%S|^jsyUK+3]ͷ wt֢@PՑ qUZ^%N(q t詯w+@<(T+yVN8t/ee2M5K1EĀܢE\t;z;juvwZ?=멓,ϵ%s P=8_ wGy7]m't۸=3Ā_ʋ߷rړΩ';mCY?}U EL||z-V,Y~`XKt7`YONE a!YfEr}Y.8"܁%z,5qBk**#\YA>9>$no]$騀8wy},)l|? C.#eYسNZ YVнW~wRLf7*y ŤOCt>pf[ppygqrʷ2ʬO+cc8g1 [s6>22l܃熥'(ԁӟǴ^d2eKnJjLaE,r_G5 FwUTՁg3+G.Wy\%##fQSFeUenp\lE_h%Y^K"d14 3fnmZ("z5=lq&,C9K') LT^aBL9?݄ >ݝ<xIvsOx^+RvX#?w&\vqD׷#|Ϣġ6SG,k68H>Pz ~9b٭$Nx}0}`kgObZ[MjFKwK>34\ ¥s%XkUy+X)dV1wg7=xNSz|ئN8oŤ>J|[2ێUQ)@l(̡sȲƵ =O%,Y0wEaBF9>N>nΎba^J/IJ*6Z)zHѰy6H偆AWV1nf"ɀ q@*Ƙ۾$b6DS0z,U\!:UDFdD/t2%IK϶lx'KJ Y{bTeh9E^,P186'~vB/z_L8!*ѹ"Q钚CRc9`y}V nӁ9*΀_D ?5bG$T_]l16s\ 2Uzҍm5$U1z4&q[yud5+w=1+j-5]cmsbŎ/ꐤ{"Fog nZǎxsWG0g~S,63M݈  Btf%Uy)^GSt"{ `_3z5~Bn:h-פfڥ]h}롈e勍T̚UptH)ӅWjr/uX,P򫿺 m/)3 XS!t.U.K@H m+WRՃ,Bn򡣄/zy^WpfA_x`fJH_d=w?Hc{ܥ64u#6Z s @/|r'Vס_&K1OZp&6 aRDsX$a1p: Y jݐKՒvY,[WHh KP$NGD11QL?Mwgu*%g6SdTb#܂#5*Ss+iD LjU<_ׁsA/i;JTjeD]S @W(͚Cxa9Zq0>M\cNJ*);ҦKn|!(@p9!&;լ&ֆ!`n+J?UJrT 1:qD+$c: w<-g(HP6vJ/1v@j@Rj6z #/f0r$/7oFth^(xc9$`%-ٻ}dSTůO;Xd7FNT! )_PɓpGxc9 g7&m?3O"wy+"<$.76P>%[2%,KH2È8p&YG $yTpv?C "#DuQge;@ZaIwτ1.DR3BO uWJiFM#jh?/EL"R+=ReȾ6)*um^\b$U쓁5?,-8+hS*Ԫ:m&&D< $emfT5 gi-.L E/P3pe먋0y2@SS<B ,Q~fꏀBk%6vW#0 ,$cF^wCdWvD Fd燲ͬ9VcmU0aO5Np=J*`YEπvk>=W+#_@.aI_M@يڄfK7zy:udžvv0e #ep`qoj.EDާok^}Z42b4|v͌Py΅=1S.[W?S:€W $s8p,U0(2Ch(Wr1IZ,JN=g@oC EKw8 UWxhX⊶_{У Y6kw FwqW)$<P#a,I̠V8r@jQM_<->Sz_ 9|'>:`j1~X83ONi*Ҁx@X* MD !(.yj\ܦDKJ%e> տg_OQԼw Zqx:1bd^c9SQdS3SCqE$JL [#c-ШK[_y ?CfQFPND;e|F{I-pŌs./w5%;naH9% WF /]Zrב\p%(f2,+<r0?%&XVG/V3af6Xi,El?$0pT.ͤ\KV~q<6l&[zJUEIgX~5hQE!L sXkËA'꫅a:^Dfm B<$JaC ٚŚQgk(mЙ 9 54v̵I5MP2UL0]z װx1tUeoEs(f4$JFKht{4w`X-9E ~M(Wy`+?`DSkln7 [ZTh#m/$ݚNir緥pqc=.I?hy'PQ6҃rVZfxtO8i9浻fn+& <[s>J^4{C1/ᱹdoa, 0"o,Z$K 0)$,aVkpM}J +UI4 ]]: p#z[E=`kX l O[9b3jOmu+Kmb/ǩ.KRb|*k`K$=Ѡss)DDnQ+Ugx8Lf14kr';?2f'yjֵmxH__9ty .u:H5_|KȼςWb41NLwbxH#)UiԻ/< ]HXQZKRm멁_zDsdl[EhYǒ;pf-h(tsQ$Xn_|N%^6をN_ gd*O?W"[y \FM-joy\O/?$9SV}E":j١0X7y8(ӭFnD={hsEfY_kf<}_?$F3$+.;Q Zc՟(̥^`L}?g;5w U)MP짓R<iuj 5@|1TZĦ j$lKcW8n9Ѐpyj|Ja{`~ϲOp۞G415WL+X`^j^gnVܳö'KbRW|6& ];m71-@v l1^ם)M 3bYoJMBNLQ˶sǭ,4"q%HF{ R] \~\r|]$h Er*[=E ű#ĔMhk7JT8mȎ T*ȻMbO&>IX[FNiqhC}}S6}}/x-Ht! &4b5]\uԷ.1|R7A3i\c=%'Wxktwiy[@Bϋ@mYCvX۽oy46BDYLhJ3Q6-Qc 0nNgh@<>Bؓzya+Onu S$".@Qx.ooǦ\HM~}9VVPPg:c娃%XUM79|[02a@: u%CDS(k9gqc=r=W$8VǺT7MV< n|yF6Lt͠@\j }%އ +?9V1Η%Vaf8r?dJn0\3mrC-5*}L.P_M;FC_-w[$iKkt;|`A(s_r&ʄWL,rdS sSS _+..exϨq擱% *h9VrYGHr"V9k-F.A,,2)x/ab (ݑ207 o$oN`s-Z[0_f֩jŦһ=79L QsP w.X0QtPy Z?'e{s Iw..A:VNph (})%J:'^DzR!{ƣ3 ݒ#CMϳeNse o!>[p7~&L{!DdQ$߬^&0;ƸQd,?4cBG Vvi}:nc6cI(%9\qΩ9PU)}&|\/4ia0;ꪧnWUnJnu ~9EtڼlEz4$$hc &pCO\6N.]8e(# 7ҍ1 ܟ7YDmMϐד->zt\t“T\uHT m±GQKֶ];"$D!.2qinŅQ{TOAX1(*?s2! Ӥ>\d(Wo3 y"WcOA !oqe2I'j'L*]ǎYP%zdlLc&{\F.xQF?WDI?Em Ɠ5t}(8E[Ve mkPZИ#ZTSffl0/AnWr .XQH"/u+7u0 `E'T0V2%qfP7OKc|`6޾zۻnS |h7r։"AίԅrYͿLM9rN -Ʋ@W3oV0Do [yIBcAj\FЯ!!ym ]e0V`y.'^tS3eê( į]괔crKd49;<:wvt>%7yJ`cGM# *آ*"x.ַS*-cRnktXJ"< jsi Ln=el_Ѱ1#xweB>Szbߡr/BϮđ0P)zvog([$_qf³1/ԩBUi oZ6VH&g X(]$8 nj;=jZ?2{j3^v<0堤Ƀ ݻ+.>+Jg2csKEC^Obk &~p?2UG@@-&MERqyG“lj_: [fJrN 00hu;Ť.vQ/Z @s} 1>zbifÎ3BD@giPme-Ym%?UzSoaZC?*vh3RABRp?׳9Lm&>K ]nsQtp]| yUK=bԿ iәpnێYCs)9{.Yqj˜2#yTY)t 0D-4́c3ƴH|\|}pxS@0FLT<6E݃-mEw#Jm=}Ŗ73|؋zڒ`e-P v*HDb\bTDz"Gt&} _n9(*'L\8ٿb=3I=qHanyDCt9[8'-W&?n4x]]J9-MT{)g "EM:{-R5EƊD=UawU T1MN636+dL}|+$0ΤU=A9VG 39;cCM5|x,1=3>u3,D=0?(0/oqTҬ=UJAZuI74/K˝8.twŤ716Ijb?3_KD+@.R]ۮbCtW60@"Z #dil:ѱ\f QOu6U23,%#ԭ-:kIm6j02=clکe7뙘6t1*mC8UB%JHD YZeԳ8MW}$JkBZ8*C'}WsmśiqXE6wO"-:o~c+@&QNֹJkH\YVwN|_"޲ oi-#MүVR: ;sƺb߰RPeARK~gXh9^(w_OynI=~?pHל0GUHV3 nfl&9~it1>\,;ϝm|TOgO2(3ớ{CCIJE,|lb6Xj"$ep?z_9iۭCbmFrI 6[" 4e ƙ+c[&Sq̌>(g뚪=8FR(K#]DfbЀ]QAxdt$d &<%1fDثlYII4xn3u,q-4 `ADa$Q~PdL g҇-E3jLnB * >ൈ1Rw̐Vd/ \ukvNjZjQ?6F7x/w*a9\ڹv|Ui3߂p6 n $cqP^VYXVtZlG[(ɜ,a38ϣژ}pl?qk +D zkTظbP@l\wrЩZqlI;UPΗ?P ͅՐ?@;g8XhWk+_ C)w?ĺO>Ӹ 92gK" (bY{\w2l`D߯X^{s3~}GW _~׌zw0!RouI_6%ŞWGӆm7n^p I+7){rB,WY*hltꠃX$Rs2'oٿJOBV &BV(w ?$ۖQ$UT>Y\Yu7* LJ2sՎ`js۶Ey$+š[g\$)I`޿`f7MUT lP=#;(/D^ l62PM-Ylׂvk0)НR%UsL&%h1 NN?ǚU}#e׉cfu8QX6s"=|]Y>EoԶ - |_0r)2wWmU쑌4,?A򊌸@!MU: {Z/ċkgXJA(]8Χ;"_\/.(F-q}V$8NE9 "%ިvDK ~,ی_Wѝ6dxIL)Sܖ bzRg9!g訫͋UxL+f15't`j{-I}XGGћ^#Gy[+OLXL"F)cYЇOӸ_+RCQ![Gۯԩ, #5{hpy3ǜܓN..BY&-!',nPաR(VǛ3-.D|{ǖREEW?Wnq+FO9.A֛l8BD @kHH/(z]U,*=ٞGt_x6^n7?S 󄾼֠f `Rn) 6αL:( Q&2x:0: oS`veaYR\}ӎc ,`‘M8SS%Kh"h/+/kcq.#e 較V#LNZޱaգ2)DWK˟q/~]͇Ch,D6XAlAQptLq&̴/.vFWU"B[E,ضJ(بRa3~szޛA[ΊX Vj[-!aI̤K"*Gev淌(LĉY2Y;Eaм 8vlcCՓd(odG%˸XB"OUi@x)xfq 8?zn6*ohm57[E6cbf7$鼛 ʌ۬B^^\)څK`u V 7\&CU?žSQLѓ9:Iµ>B6UgT8HIhߌ;Vw+$b Ԁd/oyw\ gJoR[A!wߐ?)Qc YFR:nAڇg;αv~[ob+;%K2/8[FMʍgL2=RrNpHCA͍uHMrܮ*yE=d[W/u3,I֥9RCţ "򐸬4_ݡ;0koFP]&8"ۤ}d.: %^P:ɩ@fAbo&2^V{ B\EG/e2U6}g; El;B}b",>z^1 3(+-Y7lƈ^@NÞ( AxP-@`'BPnA! yeVHtqmpgin:[1Ul4e.'|Ջ:.F?4 {S:X _%BbmtN8SReF%р03왂yF2mtXNmiSI9!ЧEC_w]׆8.`tBJ_{ V߳Jࢶo>(koD/Rvt>I`wc"l \JHj,n +V] tyz ίuY›]ˏI>ZH!%^hue!2y_/˰_i㗌 o 0ei|ZYP wO(ֺ,tV}̀ªUmVE!vGvu_XŎlJggl$dk<09(lHo⑥w؞O.<rh!Wa E 6`xk? Sc;q)n?ʫ2mg=,,B獖cudo2yMXYYD]/#kO?m$ Ea"B\Xo[ SHmШV_#Ɵ({[?FȆ0jKDi_udEFSv: ݉ݺ>=:UoZt _ОSڇ|,Zl/3gNKc՛zZf;=݊|; w߄xTV@ۏ1ln "9,av ܙX8%GI\0)gԫ;E}Bn?0 ~<ʸ>S׳MĞp?]s'| AZ,qg[CiOIv |mMoX)/pzFnJ+S=/m>|mm#vp'l-jH=n3/f5\}4YCVnn2 UڒHoxS c&`l5sfj<;90IB gdyܛVn&K뤂 ]8=[aUo:.-Wc;QɦY7OiK"QےЛ"4ge @AQjb`-?M8/ױ]C_ZcP/տItBBzG4O?b-?h#t?@K"Sr! ,GwYRI A-':KeN{]vIX@]ER:QcSylFR΢Yic`cK(  `3#QG#M)Jᤜ*&hI=충-IY1{S/8w*!9bl#Y|μbWZ9iщT$ࡾ*uߗJshqFV_8CU)<@4aDlx5B}ES Ϭ3Awh(>Xqܕ(:R4`<ƋA펲_ CDI!cR5C`G^5<7HGFFgٙVsN-Rקu3sjwυ=q`81 5i\-I~z  >2H+:6|CR8L?m?F^c$u|A8H5ƐRWiN}HO3H3+;|;GNi$p˙XQ;X)G=|6_#3|Oܼ1?(M Pl0С+*_ΗX$lZߐώfݔ'j] 'H{9j-:Ӄ5!|t _!$䉻pOkPr5Cb}қV[Q )1Ch(lfm 6z'JZN\&m6 s^ȫ#]CxQMZTy wjq}h}ۮ1aTd'CTSڴlBHc d e8g"+Xա/Jwɀ@;ٞ{-=ͤF):[Zq$I)ӣOZQ!./wsֹ<9bR_KVp&n{"~}jVNPKy<|r~-H ~1غwB!B"R?Ug2t@b.$mq,oyF'em #ó_8& G_b∫Ix{׬{VuoX" Q/$Rp6Oi6pdjZ2Y"O.yY{o'WF61KVfO gs`F!!wRD}EvU"PLҥkh)lXpSl?5V5>ܥuh _fݛ~Wz8ydI|jg r%f(g)w֘;8}foHߏ\ 0ՈAIٛb^KV7!짷VsPu#8q.IL>}%UťQ/>7B:nQt,zنY9~KG`11fpC%eqQ1culͧCp=|8kj݄do%O{V$n Tnz uG  pyj!OJXg֪d7!J-iq_Κ5NlvĀFL؅4k Ni@}"KNXh6)X^*# I:YAUDUDj!F-ܬrwmoJ.B/^ I^3s״{ԽUL"e :}S<61&)Q85%[˚v[K#9%dt6݂:)FpwC/X( # ،kkujc|Ȣ͐]E:z*Z[{ WYfVA AlB@ een4ʹ"a\\moX/q~S5W-*O}A#uX +3ㇳcCFCdOB>]_>)+=ԽXA =K2`7XBpuzgn;XeQ79f#"G\6h ܮE٣ i_aJV@kO ܙr ® i^{o%S"01|48/,*UV~‹VEJ=Rffmm'oޕ1<@Jjm=iƿc=W֡33%'o> mB[_ iqX`q'II!|Mrӳ lނأD/ ^>ZҜwI!'j6# cQZ5u7Yliz`w]Ukz : ,' G n}FSD+J1 {h* ?a;E ̹"C #lꬌh&^b{ Ow J-.P?- 3!X]Cy ިv!}L3|?G-W`u4\_N֭*(!RW m.\Y C#wv Yոn<'Dҗr0v5[ϫ85`M>Ir#uJUD KQ 3x_1:Ek ВP yAv=I)\R̔`C56ݭil o4=҂U׭2}xbv,)B2'i`LYPw@ q+m6JV-6wlI=! D@T)/ >S#g6vx: hVۈg$7KLѩ4sͲ3I.?\rN%Vt  EX!HR T5^B TSh̯_Lqy'K,9+'\jOdq]ޏf@72P{kB,9o:RE1Gse #x|ay ~w g؀)ul.: 2HJi$?γt"l#.J*cs{nqglBGknyVGWfHA1neGp!!0J.pkY`&у;`g`qYW;{vע\2C#g<4DˏQ!TR9HfAlFQ![\2>g]l͑f呄0i9&\!/p;L܎f #kLC7}ߣ.pYL=[IװCsk?JMX{qDI)i^'Npb,-&+ePQ8}FUsxհ߮= )@2XI2aoʙwn)Ik!:xc ˷Zp>N^f\uØ%97ed̦уAYwH/b|YZ@g p2j/݉ڋG2ʣŪ(&Pп?@4X=M,,=QYV.QEւGOb W{_Chxt%o8ꍚj- XMr:iy%IX@RRwQ /뻊@+Dd)ï}I)r#W'|%TCp.`W~ڥQ*zE1H7^}B6l>]2ߓ)邘}֧F`f@v ,*M ŭK2_/Fg kڤZ5l蜴䓒Jcvs!Zs|_V,#o3ltBGTJb-d!sPzmN"ɡ++sli0ɇ27[!SȈ{J$X O1_V)xOGe^ ;F&@>m~;}`1o{`ȉU *2d/7Xz<)IP -3=Ki,gG R.4'Yb4-"oSja#SW$H@ǓL X B]fUIbXt z_\L.3xTcY"mr6E8X PTM4̦* 7{(774ח |^>XmrĪ(pY_LMn8hm&c #Һ(|Br MUp<ܡv}ӔI,86E *)\)#t"ud^'w 늎>~mі~vkdQyO#3$L-Vb_y537M  #c"E_i$IMFsM8>V#R̄FAZ|[~7+Ԅ0Pd\&wKv 7CVt(x`p$?2>DjFI 7rwR ];@|t"CG1_ܰV/D /®v1T`'Vc2a"Ш$yP++mmrXaKh  ^wdrއjL$]"RWpoo }.J=v&WΜ9hg,P؊۱aٚ(3(«"N@Zj氹a2@GʗFQ hH֛]@~[Ƹ^D2,PC0V ?L/~[\97=@ZG߮\uQf #juB4IͼF=Gq_*[qg7f/ڕġN)K[`Hk2.X$ T?᫶d֞e5Py |h<0W=IRͽyfQ`3 3֖:7ˤw|_l~K28CRz;G MHC7{ `C,CëfM$gӃm)L7L՘j?MvM[zIm Otv>Ar\%7R$..}{+BECY]# !c7W2Ô*3PJ,?zFy01 2dBj{xno2ao1 [ [pzFJ-|I@js.Èa’i!Rۋ8wNuдϙ"ŝLnC(rk~6~T2|ɯ ^"BYM V-xQp@d6dž=rY c~q9:gw77cXbeQ:2=`cJN P0J[ky0=Iki7u`z;06At PQ<:cG }>n@#(! B>kOF UOP'ZK[.k`h9"5--Ol K6InHuȠA̮%& 51w$$7yyo-FޡdHrZՔQEמ-Z }d/8/V9:$N\JKIuv]z7}% qܫy8a߶`h;x<`F,Jq{ 7۬iny !E.eIؒ`0zWԣ>hWZ`:̓H{3Uw3P YK aw"[eQf-|͝7<R u&vD@{DZ#lYO}8sԢwܲԆw ^k}*$&Z[NNM7#߆B5#JQsP rJwǦ<5 c |. Ԑio{3i(lB!+ p+חĈzQQL.rW` %tuE t[b1C(A".6X S +_yyDq6BJݤ~:iV} "9o9ݻ%J\G!fo6R4 |,%)c"1.ý.&8_rE&,]ЈC1T<֠C%Gh^IROϓKF◷jE| w7A:p/@|}nx TG,rq -%D7^#[dc'4a$l<$.SD¦(ik)&y nN4,P=U26@"#uLRHńF^ X3X4uLlD7a [.\9X_2ɖlǠ*`aϿ(6ZS_oZSZPvĕە0(1+mT!Cw5`ƒNd^ J"'-'SdQ rc.ji) 8xCNpf J'*c&2=I%7jʖ(P`H4'Do~ +ӐPOT OI 5O6>pX>@hȃoFjx.H4w"ӟa73+mJ߁\'H98 =H@F6#6B!WA2[sE!O@ȋA|ɴ.qb̹__IFD,k"Hy?]j2?`DR)q3Eʽ6a=_pTq^o!~>M:5ygi?~}T떦nxT{s U*6I݄V²M|/` ?$ 8mc৽'ݧ}TJj>DR>’w, w :@m1߄i"8 ģVAiSۄ WX@#ki_X*9(3;v$o|m$̩mE7+ږۍi ,J;'ސQ=GxqhKy 8v Ān/9G hṂex~fJeKȉPh F:cԑ[$1ra׊uW!݄ k8DIo/dՀvV\aܳz)# m2NS`:L?Bc+QëL%Љ8O2?9k u4fٚ!,u12ܩ*)*7r- d-&Vu ~UV}X0ݪ^#SPVi&C뿇폘r$H4guU&e}[+h":Y#aǪc0>*V \>no1< Jw]a&~4} ^k9& [dGªe钬esY[X9f? <HnU$ۏ?%Qr˦iZjp@-!n_Ym_crzZk=Q0k]ɰ=]w<ignG8OP$A;8)\aGbRƳsj0Z-N֒$jQahtKmV ǀMd^<(ɽ*ܖC@lXHL!GV]3惮krtSئwohڶ<_,L9fT751ZЅY!.rF 0Mˈx;0brt^o"'C}p1)< |xTOAWy;>N723|,mMo*l[}2bed=bh(7٦2a%gL*vw,${9>0Py޷̲|p1Às7P]aDTHiF)sJb)|_2Uё"R=c 5OM ^-r1V|Th$sa@"ʦ\X)GiVcqZsr5#SqV>z1ykUGﬦ I&jBtmQ7xo{UuMЁ7ؔM$ #+H Hڇ1IYxʩ/"5EHR\8u2md]\V__3'eG!VFGӄ5_w 8ibm1/obQ+N 7R(H9͍8lM6+̧AܙhΧŎϰ?OWX1a=0>X$ myP7ɐKrӢ?S֝"z= 9>hhe_Oƭ '%zefH%Fz =/Z2$pI20S8Z OS<$fyz!Aƿɽpza|9X٫A=:%RÀ% &eϝUH7j6+Sx/Ӝi3̷ B98g0F#~^Ӏ(uP&흪IڙlM)s,bZW1¾mx|#BIF_ͬp7.X_r<MԴ]B&QKDy<Y"+$dtSސ=*>}dEWԕt+dRPn]״zHsiF @F ˨` 2̑ t ȸ9R6e{g"Q gyR /iZ;(@c$s6(;Ŭ%4۫w2}FﳖzCm?˔"Md E^f"_U#ny Rj>+AwH,XaSh<U$za)vk(WUqjPlA#\a T Pqbxe95\b{dl w͏6G^z,3\hh-qR K@Ʌ>J_Xzo x¬ >R|XcB1/=h(%kWP/"ͅg#$O L%J؁hQJ?oHZ',eC8cLKӡЎ9:tFek\QcTW5Zbefv(0:ʞ c@/J %j!ڝ+~>ǴKI&ӇPh}S5KШtG?Gg{u˻_<]f;g5K2#d FNqC3FOb}x༤{PJUTvE15R^ĥK%_j;mBRp&:vqA :btEn :7:aiG 0iŹ7O3ֶ7R<1GH]c\-K_;qo8-Dcп@4N u$GPSh7-)^BO:*V\5<[7e."W6E@۪X7 #&뒘[R!%Ph8\MM!,(k 6Aۓ/f}4dq>X!7ڡLY!ΏڨΖ~r3uBCL|ԑ{@Fg+Q҈! ⤔k3yӤMfSK(ػ]٧2M]~zw` eބbc0(eRܬ4떽t%" lBaCM|b.ڕ =^J:AhU3_橂ғKi?c-ר-P;iPs#ua76Vca?:I{Vnzme!ittFxnЀin=qt DgJH= HHa/= _VN}NsU@|C9SaLyrQr1qX,ya^]U C`[~mXq\'Kp 7t5ק+9*5,hDZU"L{_VVo8gm, 0]xw/Z߯b<$Dіa䅰V*["k2[]a8kk- lkp M㇥Y H@-U`#2u&oXYeǶ7Q7ܓDS`7l>kD{~9g~Zљ'-C{@dDID}D"A-0/4q^: B"x| b)A?u!bNQ=W9MS+mZXgA1(L.6$%CB7!xW;HCHsLj8WBhBpxf?ުQmm/L ^?Rt 46:VK!<=}jOB U?õQ,+t U>A{F!*orrE=2lߘh;b9Ӑ:T kz&D-MЧ2$Q`_["/[CvM+8?&!YBp܃Q8D1G, ߚ 4c -֣l7WY1&wv-1ɬ_$9YŦ"h=1q=Ҥ)wW+BH{LT;vI=Oٕ-KeF& K%yHd`Rҋ/ĪW b HjY߄_gqt}oX&3ر< jH`M7ʭz4Ţ ؋(JG慌u}?PC=H/_ݣ=xf^v(4 !q-'G"Q^Q4 bC}AFxJR&e{tdX d ?@3o>(EE9ꭑ?L\n{ty/U͔5ަLZ}E%@.h7_AO@0:4z严 IQYwO^$ip}G5x@%,N`5MF|QLAﲯSW4t_6\`> g+]W< o~y5 *ȒDOglH_. @wj,csu",wއ/R AιEN+)nuȒ5GE4iAfsPLVНsaR;b oTVA6jg`Yv^ͦ)83hqB[ Ce*8 eJe,r\;ă#.܎Q:4, =}[i>Dfc2oL[;PԮ/O% ,Ȭ PQ^Z?FK97/_KScFՉz{Yzn~˦*0cS~f/@lȘSvʀLǒn?,J@ǔtߟ:( SB8_T.j-~c3P:E"f(f1viRL]xDza +>l +鷱zYYzx_E g񾪾^ XAv m~? &"NG/ )µw(V~zn1\/'Z%HL}um|P*I)N[dc:~@pF,UTQDžDZ9?Pu!(8s#[e#ii'qM6u2D HwQC J@0S쀣K=g@h4'qj[9ߌ 8F"x l$!Wqj#r Ls:i\fP4T%rkPEt'r䑴hA1c"Fozb7Ka,Ms̴ф:Q ~#iEhHxrP)" ytvKQМ<=hPICKjݒ0~Gwu BL%SOQ( B*i@/E@Kvudgy~ya6yYHb 0FZm2Ǎ߼as nQ08gN0Ac/vם ]8r, u&AFR;FUHq'2Ur#1SynSs(>kRuA.θ>ɛ@KV AmgCɽآ==4?楟 .͊P1Kɟjg,8ѰFGۥ [H" UxT[x۝rh6< ~_֝i(C)Cz8cׯ*Efoy4KOU(ht`-}sȸ:#tB8JVE~MG': &K %R5>aSjѺVOOhMK(Mկ.A&E9-QlUa$d OF!EqkRl>Ifhb"R1+WFbS&(Hz)Iۼxg[$9Ymy R2l=RM~V# 7?CqJ@RM];͓0C":?݉hd!tur+{epwZ@ ޛoWs{]O<09ýmTlz͈{O٫GYևZO6oTiVVhK/wez RfY:sE- 0VXƣQ`p`Je!Z4H ~BO\p[?AVbg8%'{$uAEWNm\@Eddj Jv5r' %7y \%/'syה}-R@[ +Q.f>!%"Aq Dr!P)yIl!4ir۶9jhɠN1\?tA򰐻 mRҬ]hGlbיmhhhyjq#ZJ8ž%7mF>6WՌblDy?"c쯴R R_jޒQ_U*jЮp&qBiqem6I''4I. 6la?νJh5h@cN=Q$@D7kY6]s_!´BԞ8#NŬ붮(dn,4gĂ3ӨWAO/D&g3=PXbk\kH? 0[bY<Cok ݼM -x7r hvmAf otV'#"h!u1BydĿl47: T<Q)Y^q,X_h هF˄5kN п2 ̟"\˟6lHe=ogW ҷFy teZ:<)>6ͼ#asVh;أO7uZֳl ϶Wb}XX=eq4A"E:(n"5[vȳz3m^$)/aA?9zW5Ho.W4b!?+=It* YԆ&I_y<oX"[?uhXƵ c4=-m᳠Z1drWKu-hd*R m?vUT,ػykNE.C4pZT*RK{@b:MCwأq.\ dNv}9svȽFNYʅ K]%4*=Mxmֲ%/?:lLc $<2fG.`єb*Khpn0OA&{ ' Z?dlavy#(cMӥ] z2n5!k{e|:q-L!PD&<0`hSg@dCaFcndEW,+(TB ?혇N"TK] G5A²"%pUS CO//,W@kV νƋu]5m-JAykSQ{,(=G骈 HOT08)fO h )TrdGi"׹0v U,Q[DJp.atT^Q%:Og#4w)Eu`Ke>1Ge~C YmqAPM}AzD}}O$͘\) pY7_oBXaVࡱTT_8?^簏l9=c2K92s>h`Բ7ҝ>fDPjD>g[p_o@޻`$To[~4?% CMP]aܐeAؚu6%K 7ā]b֢v-$Kαks=Z׀%$9' (Da}6B,*#'ПG"I! ^|It&lz4QB[x1:O)Bdiض6y/g[x(3sGzpW|-bC=8Nup<`,F)w0߯ 3„&K VkzĴr|8k\Ћ'n"-iKp9Vǎ}OAff`*1éai&T ![%Kg$dv쥏DpԬnZzveF4XP-!bIXؽoC'JmϨzvA4]#q4$$Q;euXǘ[Ue:M9PV`o7 _'ԷRj[ۧjܡO8/nح4,CWDh}[wG}tUXǕ~1X,PA"bf/p3%YjLR̈́=FB-|Ck7^g!a.ߺZDHEU:)Em}+b+esqG-w'[vԹ !qyF Ie<$8^^L,^@#[寖d91Tuo*ҍREmrRP56uql$51 MpO g"ПՎ믚DPw*ٮۓY`BkT,ݡ~>9D-Fu/X[tzSi.TX5>l +<=.TOn#D.Ҡ9:n)^ %ZPF I+Hi{5%Bbўd:f^|4f*AFIb_kTY;O>"8Z <8D#[5f,!te`LҼnuZz`3GlL@<r#-ms쓍Ybp5 ^Kjo^X7 tZV #_r2ϣu~k?sU7{>*$xU㵾<=R8"{;Eg*r伤QS]}IU2osI!lF%8/I1?eP$%֚LA!;GuWqfJ7)u'o2׮`V1WxtHD4WPvܦu 6ZPaaA&)q-n $~g&~=ٹ@Lq:"@ v~y8U`{BP)<ȆB?q$dn_tFH8&N{A-iZ?\Y4jʠZcx ԆqЏ!(+rߒش$ҋDR.Q7 cbXI ShcKw'`DFu\hIV4qV*M3+t'RKm$h\@ڞKnC`sp8ѓ`T쮣 evْ* K!jˈu/} #x OWa?P]D߯irQ8ݍOKș9[)Ӑ? k%&HX1@BOTfyw€-gWL3&;tۡw僗 tl .Nd([|FDRMO@>;Bi_4ϙf7Is?76?5(3KAm&"X4ycO(9 .fw¸B K4ˆaFMOf^c;΋DBFc\FvԌ8GT&+x(Tؚ[OrDrD%Е=%|%,!ڦ OD;Y Q=֭!F PƐ%4ule!d-Llf-"]m4DSzZG/?S{1j ?5H̫,00AZ澀Ѽ[ceyv/Ǔ @!\i2^'\dg˚-@>IׄsTE[@xMIfh1@yX9zw&87MLdxd^ђ+@b#qaK59t3ӝz|tfelE7һjL8$qlR[3AyduE{>$ChG͆F .J2Ufr?*O>?O:'$A?ՠ,0Q 2tOuysu?JRtت3up9 .orI¶\*=$ DKSPznNU,`eB"QIwH.q.XpݒLV#P\ued`{OhFm##;G]`Bk%w(pȵAYgٲr=b"D> 3#aVTT]ֆ4`zVNka1s.Y6s2lʛs`%ږ֜Au Q, a9]) _DOky(,o4mJt#*ۅK)M8R4u [T0]hHbź6{:Kˁ;0Ol%hCYqDl!3zȆ~X eW05Q]N- t,<* Zk݂T264<>T|~cpAK'4RD&GgQt^Amn;֧A t+;S`8 0~OPy pm>SD1^mj]?v:I:bwϊVs6{Qg=1}ˆY@fܘJCN;| <^2vY*ӃW=҇_E:~O4i@*+me+t;B.1Y ۚzObYc{3Ϩ8Ӻo)'l9\c':CrNVI3y9]LC4~7ή :twD[ V0 -S׎KPQWb9Sfr HĺӠ&%k!I@cz϶"n?fw֚BH% AT#L7ޯ ̕) "~}4T\Oe|XQ~o[I^!8͸EWfZb:Y^U;YɱH07v\l#/) 9Lo"ۉφց2 RC D?SB)2f*woI\cT.dE~riU#4DC.[Lz:tc0\HN/vtW=eBBӹF댷yQ4ԩ|ު&ak9ncw-<(M/S( {v&tmb#Y&wlҸ2KdbD^p|ui5n]v_$}Xi0u-~ųSq.aY^|$?~p~ea]?Բ;ϧ A`_ *+ugHM=I9@p_co>siMvc.iTWU_vw !jIuikօ~2͗cHsb_ՍE~gR$CбD СisNa[r:0(U~(O6Bt.Ko*U,JRpM",Q>[oU s=R~qeyuR o`lWPjKZ^Coqzx l ?%h4<\w?y)Fۡ 8ŽB&$u[c?*>E/`:XVM.8! jTrD_E,S_ESQs,/V2?&S: &R=TP^vq"  k q=Dj¶L]lHTKVueYX>HChl.'1B ;G_G&9cM}{Hb!8dUY/|JТIk9Ƈ@`XEgSsϟ52Q.]: +h}],fkA #fޗɂP\Z#5&N}tA5Ez bMAY 5.`6ˊfw mKCCս[%zrMB f+iV@m<;6qrSWKe H2]EWLMi IM0WDo>}%HʤGrsL{~:qN6HAҿ!\mO֭p-YMRe陇si8])p&jSjC,\V7+m3IVڱ[s6; ǟa$Y/y[5/<, a(EB]0{M!\05Չ=hW^M[88dHt7R1rzh6o z) KvmHiM8"lah2_ǒw|~ D*QKN="ƚ˄s-;t'836,0^i~~I2rA %c7/((=׃/ٖ2Mw>~.SH݃2mMGėӫxju !Eo L 1# 9M& uWw6}WE45JjUAc1M0vw㎶yZ%Ѓ.g@g/(tDc#|ޘ*5c.1c>@|[$"CTgUp ģfqŴApY׳D(БmsxN ԱH;pnάd=B{h|2w48E!L:5p\O+n#4Y$W J>l8FJޢAs \ör8k@Hj8[EfNN(KttX$%~BR>Cpo7 *\ )?oԸTn 샃REz9"rYP*Cg5&Mv/zH]b|AXɫʚRnxY&Z_ou`Ԩ;Oq6 hz:^hf(v\FZü/\:TQX!HE}4 QX.= [.KX=ϑ(#`AayICכR+i!oCu>Ű!$}CF$<|dp%b%Er=!!ܙ r (k)Ey%0z6a m>I ,)?Ÿ1,otI,Fd,grdHJAd:VպVji* QӻU6vv#HQZcJuU4Y¹ҽl?+6m\4R},KOjzu8@O> k]{8g>e8NʢDn1c}V.=呔o*A-`VjUcFE)B_%$ L`@FZ14}HEC}(c'qLBڶshN|M[?ʑeDփM**X/$hb/nYxn3{iLTIO @nɩ8 w;+x0oOc4ÆP2u(tQItL'yv.dpz!{sz hfGmmz;R?I׸me<;'vpSGSۛ 4wV _D RPxma7 s@De"1Z6\/R.;YMeL arLbf V`Mf5ot g+f:\æF(r+\=/׮/N uw?uT*qQfJ&I>ۿ&vٜ#azOxæKfȠ+-L31a' }&j,gcРvNOJlhOo"=3 9mi7~L6ҹ+P=5v?2mhÔr8Og6gZ u3RsN#sk@;$[ϕ7[gz!"YG=KsF̲4ozj_U9TH[|R@?,eQ[pƒ C'?lW5ؚ;G"gd.|*^ȱN8hњ#;q?&dAgav[eJ  x:yVjf =yG^-ϓscg]g2Ѱ'/SUj7n Јr , KO!e/bK>G.JNFt{%:s%JbӆھFЊؼ ܾ۲>r1r%KH8? 'jZgIj+l#Mrc݇' , Mtv"wj@ sQ~8gal$%{Rۻ7"?pkp?t$,LzYcU^d虘A S"pýnk;a ,Lt'F 4=9NXRE+ȃlqJL$d /kЇj>'MY$ p[鿜#.T]^wɖ|\:\ԥs *JbzTuNA{I(Dpa)ah,IYߥjgQ6ٟ' DwEWBlYD#h5=V0`i<^h=׃2r8| >BW7WG, LM=}ݪDr0YMRll2px*@J-_0! & AgyZ'%D9 dݎc &Ok& g~ 9z2]^ "̴ MɁx/SY rhrW͕\~>8WGA+7;::jLDN*=`MV7U1o{]ȶ)-'rpF,h$s"ԆFLRl! IцtS?:D@pIԧ`%fjUN65NNuc,y'2+>ΐW#-T<6g7$+ǻ0Dy)9  X.3m(zcM{0+d͐Kej<~nԂkt>:׈զtf > PĮG*IڪrI{yĩ5{B>4OǨ"r9DP X$G?+bAޥH\ m{Hȏ,bR+A|5Na]CRJ=5<;+0I5ukBs"l>q*5 64uӯL8ͳi ><p]E3l'6<$FN_,L_E(*QbB&e~k>聇"B1QkJPݝ;8<pMYC8,=9)7ST}"mA)o >H'l=kU/3K~rټJ,.'[)KS H䴺T^{3%xCVy,<1 SU)} d#jCӊh:̏Dg^㢔WYͤR"meʹE.pjx_{-rC5[V=~['Hn-ٶ8`_s D\gk=ܼhEQ=-sl'TvHMA>Nj1- 途W{ˉc a0P@ 7:q_>~QHPN;A==MpՄڻK(#kt-hFaWXtB~,gОəv?ڐۀ.LC1\j"m ʹ}Ĵ3l;~ΙRnxߊUC2֫j ]b3l?_V`t5ba2+F^Y0k Λ# =*f)3 xVNWV]ė L\4a WeU} pN=mJu~20j(Mcme=V;crڔF <:lܳW-?eؿ}bˁ/7NZHoٮ= Ļ vZ a7dV; 6Lh7\wjY-v hKcjAL $SHδBJ4-^ypQCc^ʪ a4RIrLO-j?ݨWx &Uڼ4 6Fze C,Rʲ j_k*"Nj`0xpjb 5 %/uI;G35v35_{t="b :aٷmwV"ˆ`FF* 7D:BtA1 Jw.R# 6JbXݬ"ӏ|&-&68B^< w"y;7Nb[?OPsi')15fg>ܹ ɘf4sfjpޝ}/rK羏Iʥ(}ZYې,SR!^Ivkhf|3;#5.UQA=Mif^|X9+p@Vr9[jsẕaۗ>9vvxWAہfּ$ZUOua oy..FcrhJ uPv^QbzC$9SPn.!ؒ-??b7AUܾ3ZVE7j{Zx6%-39HB^1œ&/մ>-Fh*NdI|`ڱgNEiNg129h|CMp讗~R]69ҨgW?yR eYfacfI^pKPU3j !sR^V 3!= b"Dw/2zOdi+4ZA|7V<í}GFr\EB[>smsw^8y)q1j.nFֆt.)D&x+ۍ_Gi'ɧYVvq;̴LY(u[V*jxI+"&BLͫj~G|.%?|nIiTiXj{O2(O^`X(Ԩ2Ykt)k 'N*FӚiQ#`Vein'>-M UC.|7{.U^I[+' F`yD$LDCJTPtk&p{&!:@dѣI=T`ڤ3 $nNյqIA!ř_%pAXf$YF: x7]w{M} 1Lo{q:+r%0c`K-x>le%ckP){`&oGQ$Id ~M7/t~ @4`a aG%-je*y=_byؠ l(e{d[2lA\94MW%bڂգejl`K h"EKcfD K?&ǥ8 # wW]> QWޫ/nQcۺBŢnB˦CNRõy$TI_O|,W8Hz]6y16IIn5$̉B`:lR|몺vED3C( aTp)M; g NK*2jF>svٜ@L䏊JP02t'>UA˯6X@GBW_rnPm"́#@sXecE=hz]F;l %ۼGpY ,^jS^PWբ"`?6 $<zVQ4N#9Fh@g::sc([TJHJĎ2 q ްZXUb sKt&qwK%(z6tμW5EߥBo{zFeRic%ފ3G eT\R[ܿh. U$IYs:Lޥ4kz?4fQ*ߞ6ћ oN*qʮMhpjno0¦m&J^=Iu^p}_1 Ra}Jz[?.O:֑AՓj|Rl|Q qO%w<B( NzʦF\R]=*OWbh~}(%4R>6[|q]]0&t#6kSl?Xԛcay&JI~GR~d[ 0hWWRYAߕ2S0Q;G:,_ UiiYt ԑ}tT ܶSnh6+(FY-SSp!Q[ M`~R!ͤ21sfKcP+H\iCqkؙɇCx([~aPU#8i >Vsb Dx GPS2:b沙3c)#Tb>,r8E{*Ҥ悔]pPj|3skߤAK5pY(V.+4ew;V?ʂn//>6t~y[`+` #Q|#T-rݨ _ iQ84| MT}oPn/$92sOݞ ?X6ڻzWݒhC ѭ@ϊ;9|ZG r/f5eSaJ̫@xi/)z"<"ƾϨޝۗ4zDӮ Xb[WZM GIzQD[L`Ӂ˂@0h/嵐?{3hT80)EʢWzEj%P +S_2lc1H0&SOy_TTF7UDĕ!+R7X9{vavI|En!8Y:Bbɺ䤍 L4)OfT uau A}=^uy_X3B.팰[LXBuRIYi>ZD%4T*?lo?Rϲ!/t3*n',y*E]t?v٠[̡"j cD@;@ Hunc]<>͠x19 ~HߒbAD؎*;?Rր:=N7 vL&,ZdZlZ~2CT2sl|PDh=NC#@|KԖ>\^;[Z깍Lo%ĩ53Zlf sH@T](^S1a27CBZM-dX8Z㉳z"+_ɮ~a1˃XYTEl(G\*:7 dH3o.7]x( _|h:VF䨵(4fiwEa0 74^2Ag I$ 0ɗMjcwyT\zY6VDa2[NWbqa٘, J{H2=L}) ش}{r?:uv]"i![oz;/E%7r3$,OXJ$_L iB}"}2<)y2œ)r[WS 88،)Yn0RtmNy(HP\F yf/2AjwLdH-@Z"~+"Enx%Egnqjp]:L'\n>H2I BG`_]o9TA ^֍GL ܟ> R&h/_xƛ@d$=ph2X]xԏ^)zч~L 2:7=W6`sE#*̐$4=ɥ# Ip mô_]/jkOiC tБ>A2^iRڢBpS<a/Y{UF7,3aC a`dq[ɇ P/a \v;d6IKJU5eZ@}1UgNAhܘU?9ai 7Ż,z~KN.fȖ+_oyݣ1 1 L– 2ڣ%2-*N^$T"Uc|f]CmOf3 IY{yTICG& o!P.KK(ˆeΘ9&HT`-:w_mj/ӪCr9-y >z3lfb(_UwT8"nWLm%^qK;]Y挬B1hɠ*{zFN&i3"@ItY[KoB׆dUg+{6W?e+Lܧ"܅QVW*fZMP >}q\qaAŰh4Dr+ 'onzi˚I69Xf&in!Dl|LY;7_A_~-[z'd'vf פ*ض2xMDͲy9_M-XOqO ۡnjjd3>kO% q]9~}#8W*S^ 43Yn5߮ǦU_zv,Vہ]wg~2Pi<0EVOr[A0^>kH8̭BKybOUT2?k6vj6T7}6'4+.i۶_.$`3FT\v)ٟEI.8sO5fn#|*[;-V51b\L%bjTBϱ<^DKdzGSkEaƋl|u]F &365Χ͊aFI"(~q9|dm`#oMvƅվ^v53omNR*U9> Y6)ZhS6,Sq0{zܢ?u\l+p|V_Mcl:4~WL.41o۴v3{|l[ m #b?Lm}-#Ő|㧢r,?HE1WiVTXbf `Sx%$-a=*=5zEF'9:?P}KA5 N7'cY\NܝD '168.|er4jp岚1 1b2ǘZz]cr ix%Zy|ǟG}o}ݧ ☏Tk]ʋf|.m@jO+n?#+A%e=8кCo9OjNAIv!F 3Ӯ1& .z=JZU-)%1`:n05Glhf$oZѠ2 B!SLn1cQ[X`GfU4BJ|W\DaA96nwWbY$͒XNwGpe7X:(P0{`}޼, C[ Dץ9hApxc%-ɛU}$I3^M@8 W|6"lՊĵ%^ƾn8x R%"_7jRcT4bl5ئ۹.Km rBIrryn}<2d Kt쌳l>Pˣ&lá }^RYf9#jʮfy?a(.ݫ {7ڬ( MVgHz ډ2oLڶk{s|'K@hf7L *Gohixgeok9O*R+A &6 y \+iZ΅ϨQh| r}&mɳCZtN#LZ"|Gt)rt6 DG`R% SATˋ;4pY,TYO &ܯ'8Cl+3[pյ+1!stg )~7f`-V)cVd.Z?&T#d%\Gj҅L5_T&i2ې{Pt;; x΍ǛV L{2ٓ4$%$)LW:Y+wjH[Zc E| 7T|))jW="Zys>"Mu4 d++_,p`{cG{! @Uxccgyu^Q߮ft-53Swb%YLhs!HΉp wXEJ$H]}cZ2̪)7rCɺGC4Yk0vjyceEV(t6#6ai<)>~wAzLb14?k7[P 2NG˚ Zg_6{hQޓha$cOPZ|CY6e^wvKtY _l 1׌VKx%Ts'.4H!{0C؛g6^go[>ТyF+iXbCˀrZGܜv9^|,| qͪ hQDn*0l2ɤb[QXZV?<9j2+C|AQU$? 2yQ)L6kĨڴEXYM hA&HbިD :LR6vKʲɥm!; } g1!橂Ψ̼鎵?cStv\1eX:){*$hd2xHxV%hcP2'gp PUnZ5J Ɨm$S$*`Y7[]A36&yx*0-IBQg.6o#ȝFdbq-{Q>ѯA%n@% U1 z 8U k0<A u4J]2vSkjf"l2bcȟW|uQ:(T?36eMU:iW Qí_#8.8ֶ{GQnIK6 pBY'!b2_J6Eie~f]Y2&Fx ˩o}Vt>;J眛Wq j(c^vpPEuu"ڣJ|BprDʦk<0ٴGiRӔhDjW&vXe7LfW}(}_DbߜyH ceKs8wp"P1V6FʜÑh:e3|H>TpS1Y:$LOI)GMah'uskQa#QPoVgꚸ_Mhuk.ܞd?V;uu ;+Sl.paJޗ\9ҥ{ߤ#nn]8QK>0J1s¢w۞L ȑI$Rﱶ,>k)=숐wXO%256xb+ʻ.3]C8v ^+kEҫ5>K5X A2"C?X[`s=onŅړ$Ԗ;9cZiҡ' wYa󰘐?@bħoZṶę9.XDZb=uf,)#^֜舒q-9ܼٓlUZ!s 8X_%ʑb3 D%鹀7Ynd.Qǣ #} j9 ?6ʞAh_MD`ȍT,[~7\xR+c֩ʎޭBC_ĝD` h}o=jow'`%5Tk%{ JY^FE l$^[`dvTƀ-#KpiyF(\>u ףhx (}{(JvhH!Q(y8,`  M= 'mEDFkUf+\6/PLjgݶq i+Gx"<U2B]lخ+ڂ3k0)o2 er J r^lxb@ඬ|SGayi˨=,/yXӘ / Ɏ洞m{JgؽS&0aE6a>ŹfZ%1#ցXrEc g@mhcJ~v4HiXA|U`W6z,i.HzyϾ:&olV]c? 927y,tؑgUw hqقRG v0762W. R 42ݠ' $-r]ebV>SFy!F'* b]:R: bΕmfj7s=R9s5W6yzVdRSs~\WO〜V0zM5eL:'a||~ekt*j=7a+ ft$(<êbݷE(Lm>yE);^1/J/3%m,cvXQ~#n#Qt0(1ծ!55k5Dd\)M#C6k'$ ^q2fb m\dgR L} 0B6 #YnhìFM5L2hF81ZRgѪkb챡BY^#ѝ}w G2uVZğ(fmDB;2lAAPeӁ<ɀ #Vơv]H$rG LLW,9kr#mKSP̱dZE0gΥϠ:D\sܷIʽoɸX%={0.dU;Iy*!ܞpFW u屼ۼ=Y1n < H>v_!۾6!{#mq}E/G@NNL gYz7+LO>ո|iX0?$^3()09BjEmAT C|4 ܐKۈվ-F"ue3r3LV_? \yBݳ@pb 2rJ% =T<2־z#ԟfO&7ɭzKtk3UT<]C8.~忢HN5(1punmT93#[ǩ7Kl~[hOQe OڍIqsD6@L&Dxi]^%}1? WJl",l0KsYfb4|j;W 0>$3A96Q@X*K@d9gͯ;h]Z\wIbV.vSl[cDTyex[j 8C§$K 8ҙ)M{NGTkf!(ue޹;2g&L'~4EaɜSŭ`vtm71 M;j6ր?GvyW~~z3 \W.~w1ؖe #dAq/VKmFp׵mK^bstƗ6wi>SMkx-eg zXlfM{/z̳؅E*Zuh9vGqclB=x,, q`=Ʒ*gk0R&f-1|\\- L!z 'Yy2NqDF̽ŚQ  B%3LPLi{g ИdѼg3ה5Z\Fb ;Yp븍"0>0GJYQ-DGcX3 z&BHWCA>H;x66sՒ*wL~qS3R[VB11_o>[6 X#աj֑ 5ʺ 1.ZZ!"!t[d-8}$yqv'd{n%_ ^:Iɏ̎7Jhw)%v1P\CwkZwʲ2c{g4cECb/cP3F4M݀Vv^-5ş+D.\ U^풆5v^24rX7b3 pY2\d-i ՛n Hl)1GBUev"]]Go4;<.i3ޑBgN6=.TA=ㆵrH6 -+S)J\p5t0ٳlr2mIo?:MM﫰7CcA=J]w*rCI\/u eG~ -00*C=T-u@I;/VTc,Ǯ11,>_yAo 6ս]֋XryYi D8Bd2FH:K: 9(x3v  d,?{}Ys6v'R8stnA/f92nBAz?[&)nP?&`m5X }G2mHxR~2v?C<':1|$/W%W 8-K`$mI}r]5Űoh[=\KXDu}h-37] m2rj !pD@ Wҧ }Jœ)s&1& kBO'"qѸBd]ԩIG d) jH,e9/2"vbgƹvDh}]-PHiI56|d)BG4@q~ )PaD~2G> U #Ph p~"E)}ht$ >72>Q|+?ն+(ZiD-43=iY>D %{yG*/QYwiGn"j {>> td!Ý|}Rc2MhOҬ B r3F'B٤)h\UH'4Zz2K1$=ؔhWN)pNTuAI!|<,Y~9{@h!|4[!ШCW[M6U#B*^e*K&1 15Zd<i15ZeLDRKQ3+p'g_SCQp.陊/ ~6.H*ڏ٪'g+7f`D* maO 1swC{G>h+[`q1ЍcsGhkQiLP'nC nT1`){g8v/4iH v3pYqmh)3G866F]vVz . >4*בi$w6b4Lp{u_[6䃘Y!Xtgy9ч^ mbA*\9IA8 uj ۯٿ~-0 3^nL`k܁c* !~6VNmkZ9pr# ˩vٯF we;~@!( P:BQÙfIEtLt,bF}:;\aOU>NeQ{~u_$~@Lc#b>vx%]qUFA->'ڤǰn!<*8vD.?)(-yu;F$BWmAf ؠ"kv8_w SW˾Pzʹc`"d 1S38K !6Ы5qN q8kGs\$ 0h| @BPkrw*Cih"dyb 9gȂׂ)|}轗KɊFU7O0 3QtvOG>o0j0["()&fsŷX疜q5 ƥ8pYP FėB$r`J+/uӤQ9ŗ7-xo t?ˆ6 3}nH>Y5 *vp< V=`QK˙kXc1ы|Ve=%ScSNJBP-5'ߙW:b _9Y(Hg&#0(C9ԿlƮg"oM &-%(GX j۝.ZR{&-JZ%2&QsU9C>>AX$kR;A#zbx}ΔXCU 0cvp4瘓 }\WڣoGf5\a!RVCu_G{U* ?2aO#gϹZ4O18$T,@Cof5[񜖉ȕG yIz }XO(Hľդ,05e&(C2BӑLkl{ x'C>aWO,V,R~뾻f ?)`B n 7(m*U60 N?G;8dol;I+k3e<F2{:$Ih+:d{7%$=xz%ЩyFKmV'j&RF&і~]铧7csodUYlr ~#m6#BvKYRvc`W==dE^Mm$lނ]CZ̼&! j<4>;FG6wqˏ7UexTP)HOe D Zؑ#~7)W \?EIt:a9 ǏS]I0.udAt}.~N{2O -i7&hj>P:.ڀ!K2l]1RCEg24,)ף:\t`hC<w*N5G\Nm (mH6y7hv]2.9>(?׉KcxE zZ6=<})=- ދ;^vjGOx1íK5,#G=vҨ$WGhg^YrO:6HiVͷ?)]X}Yr*T҃VyƵ=1L^Xpk`4,&9)+\&KN, suJePQD=ѥ1gZAIcZ)"6 Iɴ=lT`qpܙS)/;Tū2'ĩ_iA)؝kg#=%1Cgvj@m!gTD ZM-5ӥK6S1BKĠOHS{*V}L]d2o ̪[ i:uDzu80ŗ%cko:  4⅟F4A2F]b3/B.kG&e\빁9?i</QQxfaP Aك屴B\BapC^1B` eGd`}^`qmk8җx9ٯZ=@qۡSqgeKf,]XD5ǹ=#nt֌w̭cF?='4gZsE'N_O7иpd;0Z>=7A-r=ł= \s/HHG_iYT 2_Rc tz?-~z (縯HGg0؛Z31oYKwyFzWa\jDo렏Ӣ5Xߝ18a$uR${3@--u@pniߏbݦX[-(`:St#h9=wqI~*$vj# uUK* ;JN٫n1m' s5=2m̶jz1LSPld;@ϔ v1C<[Ӱݳ:O=*h^c꤆* x&8_,R2_#{b hj(V-E6X왢F.'ưq(Rs=߄,\҉ ` v3SΉ.mt^Tt[-=u^06*mhw4ըYuN}$Iy 6-!%yH@`1KiSސO Xy&(<= So=`^: &OZJdc`ȣrtW疓&= -Z}=zV Ukkq0@rm<.MNzUJZYxѨv:+^TH\`Ë1qpQFHy]eCMCfFA@ް`P^:t&SYDN<+3DXAB/Mon'2A#ս$ebLk$C) '%@n# η4,K/xΗʲαdE%'yyc*  oW&I3?lDqT>ՁPmkd8J v|0ԝ7bėjrQ@[ϔfۺ? #Hf+r0?&BqӞ_U&;-caYx)t辌b`ޯVTfi :`x! voME{q|n;F%#aS{' Dt_pX{y:ڨ͡xZDѻeKV}Z?08`kMu}gZ*3Lv e4B{+v;Xp.nEaa88SoL9{ft4BzRyѻS4w|>>QbbϷk)kPNˏl5p[B I'GcMh(τՀ'ZP"\F3*גsOa[!!&b['8O|'"tx)<}Tp04$ef%'<ًog|h*YGQݢkΘegؾǏ!vXD(D՞CȑIld}Ya`!e凗M̔ЈѺoD-BXu#X ljxq$/) z6bNk=5g )Iecu Xl^׀xU3Ţ#]Kf(lfD&a\U5x+pM>Inf2 K|?n(#-^cxAG"W{fL.p)}"OkDr]#F|y)B#R+q|RvZH -ͣ4fcdN:Jг04 EǽquVCfuao |/'@]J79YNclkG*]KD`ռ`&#hAJwUu kQdf>0 ܭGwPnR᳕f YXH!0bD~wwgͫASBL1{]eYE祱Xi+ݝJ>QYY1px _y5`*if0#\e? ;D.H†;C;{~cRgEW6ɂg@."2Y_^rp/WМVMIOPr[%Lw'ujENB@f6I.{ Iqw>B7as<|M7UHaKMo %&;Y^(BǟK|Bչ/ל>HV Yu+ѼJwvЙWY0JIƒѶR:c!q f.l€_l*)_{P,ft[[q }86;t: ߯E'o D`Ts Ύw-ulUپogJL'u2WwrnۀtAm#i{|f4ŦȴcX53xbqfD!D3v ^NNI[1`ڍ)LX`Zgv8]iqЦ7`fV&}E~ < wX@2+̙U)z)AYNxf6>3'<DI5+=f ׬l8JhjseK1a-?6+$6W̉ :)Lv4"~ae@" =VSȧb*'{k b gWB߶+ &yAb*s-Uw-:Ӻ.FWГG"YWv>6Ы )r4~L:,~  ^RI$<۾ds¥o}4}Y8~oC_7  EG_ʙJ-O1GYѮR16S-x$ Xv[]&v ]#bs, pERO ESGmDrg&9F)3Y/7nN<՛ZlƙْiϟtƦz<ͱ hLRoD?S|&-62cM@_S" Y<ø|UǹGQYf:e ȉ&+S 1} 8Ƹ+fyXE\Z&r[]s ˧W͛"N369K4^1cZ)}3}i**祕l9\5ɍԉI b^X ;@,b#ܵ>)W=a>NcO/Eؿ~-Q0w! `P k[>&VKCW/OLؼqJD~\7`~qeizO]FrSqFܹ\bT|O(3}hSfoAVQ΃*xiOV{D.7JYNsX3xoz-zA;o\U0D 9rِ#֍DLG%#4( ﴍsYqD4iZd%b8V9@o=3f+Aať}S"'0ҝdRxx a|vH9x|Ӯ&9ȧݏPxC~Gl W@lc W`ҵmCcؾjMS ͥ`ʗ|YmFcqoa`zd7 #L%R0YgNKJLJ[x(ݽ2}7@k bveUEmuopM{hoDqثIT"H9*^j=% ǩ.?27*M&~@o\HV':ݥéf#2$!=.? c^&^ZDo,ϿԨl(L48c&EyoM~<=Ct=N߿zA-n"(f_߭q^"up]V`QbJK=:Eլ^[8%ͫLx[BYJ!wTnhKHdyDM:+Uau =e޾ !WȴR75/Q ٮ3=<b%JXbWWz<̮"(" )D +rbw2WrrFdōj X{YL@VAN E?~Gv6 K=jfq~"ȵ<_i xP[ۊ3gUN*j@T@PR{lhMNS g,: wx|jK~(]D["ZSى?Y>KPii= 5#FP%\X$:yYqE&PBqB[eoIr+QM({H" LBgJ .j$ܦcjqx+yo?Flͺr֧.`ߩ\HjM k {(15LNӹ$}CDZo<ӡp\-jJW7] {5٬Ҟ5k^'kڕ16Ds"L/-K4 be"JC8=f`*HݻEf<cl a#r? J%W4k yۦM܃v·7.Ck7g~0$u'l#)7CWDrcSL@Qy+#\,Ȯ ;|r_HӾX'IB:~y4;< ;>w:۲*5[9\U^0l)@9y iAih"HMhųel[f )`{+@ A_Ӫ#YVXQ!nTM`\xg$<| EsISl~R'" te 㚹8fEzW@<zj'5C{o̅/=}EJo:&V= ?'KO<3뙤=3.џ}E& Fәv n[lyc=E2bf!-FĨg!%{B7$ QpA-GR+g"G7xP\y}]ZTj2HObM# 3ԥ+Uׯ*C`_2/.=>ARщ!!,ݎdž2D_M5Yơ hXoԧ By芼˥V(8@?bXplzG/E4%u}`7}wExDbQV}"rd/_<ԻYr I&l7@CF 6QM1SpRGfrGY渤+nT"iQlO؂5$e ?/V&aճU⚬ Y/%]V%T\pf`Ӕ>Q6x8ā;@hNvHW_-Dr?&y`:2nd:6ɏPҽ@@x3lW:OB9K#ŇS6P3[k.)KTD **Zcb|3C ߏ篟 vg-%tPq)bͩ\mxp1d ɋx䳆ch5Iq[G`$Qd! j6{sw0%脶wK jyo,2S@ da5Z=?3G){bJuՂ>hŔg]?%å}߼# MQAsh5[+P{ZA(a\l qШmcZuN9R)+(/)Ɂ7irэ /ֽ񘡪 + l%:t#PA ]ޤ=a<*nPgמ°R}Ho(G& 1T,т> U%c5W{`ȒDl*Aډ𭑞)@UkYmeG^)XL-B9%S|#"$b"XhOF:LrEZyK4;}*s >o8c_p<p[Bs|d(*dft$Z2h:o6k =x-7S6|eӸ`=!H`9ZB9V؏ F3faMm0Ʊ9%Sq2:rDؿ,uOQr+vLɜ4798ho4FP(p!M_[x:1C#14Ax2,n 6MkG,Ⱥ5O|v9, [sqRC#XMUNxCӈ"Xx3 *Upxɹ8iǓw>|n|qJ|ąBa@EzTK=5(I,0mdaϜ:EhJ!F$=( ᨐcpL:!K8B Wd!O$ ٠887$\E2;95֋,A^LQpF`jH74 D/3NhJdɮ'^/`~ZDrH&dC Ѡt,0ܫ)5Sۂuld+[q0|02 zmMTmP?qz>M "/6C-!YIK[򖴕1Ύ%XrɍeM%$షx~@V,8[vYFeDhў^dm2hBӔoG&ʫN ='Jy ,>=VjF1l Oo1k_^$8Wr& 6TsKQj6ld_[ |O"q.+{81F7TA竏!FnHop<Ɯezn(U=wN%X, ՙ~O;)y#_7#U)[&·oԪ&=?;)wJx=ROfA$;áBŲi V9͑O=M`l2rC &" ʃ=ī^ǹp}ɂ=@M} J[L;if:DýN=/#p4g0 GMk5i*76 efgd8)mnGw.gUVϕ\AP?Nh{bnH] 4A)Z#ʄDe]Zsە:4T9~>mZi ,)xW7XrGL3HҘ1'?QO`};+nįn9DzK,T֘F&]U{mQ`Rii[}؈ML˚BF` 2ߟʭmP& ^9ǔ]F ?jɽO*{$;Ѕf-΄]x\3MKm!3x%}OI.~Ja/}K6g3LP2Im7bT^ʊ2pyHN_ ВlDh19ʮMhWqx687RU=(DK0 J6kI`d#뉣%$Ɨi+*m5ռ #@|Cm'lTMQėٳ-3ؾE~@8=ox`'M?zi!w!}H.4k>̲ q%V);|yF3H9:r17-ͼGڜѶONNaBSc/ KhxxKoKgM/W߉)0]\% a蹒W_$hHog[ܨEV'c?Z&}} ێgQ%-lsA@9U|i%Έ*;ⶑ}0Z<!Hf>rͩ9/̓Y <,0KȺ(>CuEW }y nP*}c;G5ѿʘ|/l:{.U{6H-|z,yu5E_=oLzΦԢ1d2緵k~f$ӧo}oNsFKOfHG$g^8tQ7)_ &ayZbSQmk64SkMIBǓL;e7pCHp-BvULFoZIy$usa)t"w!*P xJE.& [9D?3_|oq2Sqh[V6VHzhH'_Ou!,(q":}ihKs2h^kAs\D(Rlΰ;*@ZO)$S_Xh5U y;1$<:1sQW26kTBGՇ:OZ}JT/ҽ˸nH(4 #9[E["5 z1IK"G^CAYV#@,dT%OLpByE .Tg5ZR0.pj%{SY =]|_0nǵygN\+/@e瑗PaMV'~dHSY MrB(lCFhYq_ʎmWOE,f!4ue&mwFTP;S3@zݵ­ %c ׄ,M@';܃g?(PYLe??j^7L ׻vjw0k fd+U2pIaSGAu&$,q+9nZ6YԠN7l/gG{n7 |H quiϻyci{k%7ˁBfGW,ז8c?]39Z>X''oEͼQ[UFHQ NurAߕ,WDZhTyхnx!YuaK榅؟&;[@ʲr&ybY8PI(`qLqꉷ۔z A..:vuדQtHhs]@#T=\XZS: 'X73rHF$y>&8,8|yl7gAρ*@A0b4?0f,1΅vA) ѷeEú"8ֲe~ElՋ5 o 5;-ApVp@d`TP5 vwX z#w:̖rq$7db3 W$F„RMxgOhp9V DwGonHFӕՃo/}춨Ԁ8M孻߶Ȏج~" 3l:Q%rkP hobv574~ (L)'ș.s]GP,[26Ebg$E˻ 7a1ovNRi5FH83I j햴uMɮw.,ʎ1a;+PniSk96 cq'Yt{;;/*d}l!bKe_xvqRIoWp\CɵX- gpTr.r*ۦkML(:lӋ/Reh5DKmR;qapj`F]#KŬ_k)ZGqhh(oҦlԥx c;kdlGԗB.Gא$K(|%M\UW쏜V&Р$3 M>Xh 01ntMN| ; ތКl$; ژGwUdH7x"rIáT/ ^ebЯc~ L,RqSGTa+i=1&i|0>q^px"AU#G@IǼ[V51m̱gP # *(`4lI=jj%蠴%ǶHk,ׁ4) S^D۷v/23Į-Qr\_2%M-ˑ{*%۬'Y2=!0qd34;8mG9w.$K0't1=>+(֍ȊPiX jnG1x4Zr]IN7UCWZsQco#zm9aWaoVU4l4 F un^OM7%6%b'_|EE4 gʳ5Ksv_ Rۢ!xaEL##ӦC@sV>lƙAdez4H%]h~+Qz_*0dݚ-1\B@婊1_Т? i cuV{ӹHY>2,^{ PWVD~; k&mE˸ePxoGīR=JCwE 5f"NؤMrb.Ȝ*7WrX5\ȀCS(/sCՊU\eR?m5Jf%!tBg^ g9,`5z}ykk@e n_$=.`$a ;jiŵN_|h4zpMne! Wk(>y6շQgKWiԜ&AGS\FME_ >WKF.b%pLB~u6=aL^PQCLTXarIUOB\ zC\& ^ )_P[&ڹܩuH>Bnj99GA`qxf@`yE3sbO::\/\H{ͺYfQPf.>W֝9T 21h4W Alrn#~KT8)HfẁwZ9+  ϋb7w6;US\ V N8'UûX&/|@1g9XbihS?bǻ Ql7$ >@:Z=$ |kj&pJƟAm{Ay u@kIGM_6rK|h-TwCr'2U T9TFǟޙ1 XAe֩*]`|iЪ4\R`jBGd +ܗsI/Ɣ8n`C7,_#*&B8Q zKW\ښ _-kz#%ЏM_cbL{wd :"98jSl%/炯mQ5k TQ1i:P5򇏵.X_qW1m<+!齹Oح$%.,"K@sDrw}іO`ө''"sœPyьPؒXAۙ_6F. Eߎz:uG&N-|%LÃtShYXճqܢI,RB04+|CNivF1c&M~dC 9ki} 4٨YCEl[z92;R 6)OF"s[EH1}DXv0_hN"A*)mڬhwhcs׭3>M,7T_o޶J @0-/Te?a`PcRM8ƾj9ga^#sQ#T84z{#mHDŠy``v&w.O!+ 4c C k~,OWp&?RFʝ|d8P!sG{ƭl Yl7'I'ٙ﫯O~I{S*YON^mYڣy;ڙ?MWK m'5:Sox],* N8QK<-d:4N0+W23k&f‰L),7%C zɴS6y)+|2RwỴdu3)M!uޟ|86%~yGB@amoi .] SVbͯPw℩/Z=scDEp$w*Qܔ&%_D^2ΤNjwp$Le -i\|Z7쒍hoq=WѾ!d˲{|B1!c~ MH "o5WN3g `W4P@AQߡ ZZPb)lPkJx\A?3'ƾؓOPb(:2NvƬO cY+E*׉˗CD}hP0TuuЃ.^ntJNV1;p[ÒpE0OB(j A除MSi|u7$g~d䯿Sgvа.\3\PUv܉EYV_ãŭBRargK0&,stv%aU7W, 孄{]hAS|6q1,5:T[mC8\5̩ fFӵQ&u=8H"r Mu|1vVK*:ZMQ;>1={&<-js H 3f6$ĀudQY;9ڂKn)h:r'-Sm?!"x}HG(Bg"=&(՝ \vlzA+BG 6O.)_K+¤:)*5mCLk@# 2hLXjI]ݮLL*_u|Fư}??r1R2wZdws0Q|\e{q #s Yv?#+BLο 7D_#R* ɤC!Ei b"QRE> l)7_@XZNVq*~Do'\ɴᇞi \|yiPH-&_ 9N+ o3r)Uq3DeR#k{CvtdHa)dv6y]S!Zii$ȍE T ߽[[!e#񫚅*}GsyNbWQk ͘~ .cW'S~r|N{aѽ =_E Zkd; ;#jjneې a <|l/o#d788qt1O4l/y>53]g'j]\o-N)%֡ۏ@a֯fS[nğb5{.@fśo t}\='aHT 9D_!nDL 5MX<,1+5B*D[ҖBkNsJ3K" Ddy P tx~9!Jy8:R'(PB *M/ɠC)R>yT@\h 5 `+8*M7t ,Epl'|+u1m인-WgwuU㓥"\죃Y "Uw敉 CnEgٿ'5)w6@΄%HE97^$&mfȫP6# :ط`+X Xݼ+=(YSk:Ju%O#e.\Zymʦ{-p}xxƷk1}{A㈫H &T5B?e9.reD/(.(C`-S8sխqkIf 6\)P_Ǽ$lBkk,Q*MXI#ǝb̡%4EyuӮ"MFn4Ս~"=]pDܵ.mJmNpp;rp)jj#!ߦFl7yz.8d 3wp '.fԸN BNaU8:Ok9 fszy$UϑشRr@XC m2+qQ=2w:UZ* !x`xޒDK̟&+iBO= ֖МKnX̘ggV^<֜jV|!p^i'Y7?W|3Ǥf>s>:T|sF"0YJGLkJ6@յdU "P ;rGG]⿚r8z01Wm5_XFM|X E|}L.biZGn}=:$w?Z0 ;֣PAb <@Ja:Ӌ=uMS#+M"o]U f8Rl$z2 JGHw s`>?(`?dgI ߮ \SQ\QA?|H?P[hs#XRD7Lh[SګOs~\krcI Gis³i^t7J b*HI2ǷmdZ˜CCx)VE=$/&z>ʹvqf9Ab">1y8/+;r +oݰOZ( :Y\ʚbWّUn78R-zLc#e'=K&RIXzoJb3!-oH|<ȣ#=#$|=ɠk]~&@VpIz 8rJDCB:@rtDy<3UZID׎;~AC.Tn8CHa7edX!(q乬NaR`΄Vs̝m.ݫ4lu@a~ 2 +ɬazED=)0=f*a6!6|H}/j|)֜qfua6s9HQ`)93FpUmoSsv-^12SX9?SE^I_ŹQ!fbr+[C璹oQL;>J7u鿳r$kf/'Kc=-U C?QQ9E/ L6(0&D &k!Jߒ(e@B:&j!#<:YMqlkK0&ż?bNX/D !.0 œ7&񑪸Y5L.$;e˭uvO(*ǶZh,hx0ަ ekkkgu/8Xl+8$$u {ˤ4gZv}e1#{p "b]m7\$+0 {W'uEdg H6U" <]ȍ8aNiHw R9#jdZԎl}!IQWkMZQ[yóeFpQN'*Y WQXN aG @ g܉zFVIb? Spou r™Xa^HYMhMs5~ĂTqJ໑ |1fwHi9>XЧ)B/2zB~"} 2yZIbB\,r8Hǂž^Ӗ`^hb ev-J*1.F]Ag 2q)=nR.oę ;kɴ)ۙf`gT9Z,z2ʊ{&KTGPW2tԗʿcÊho39[}]Yc`6 ݑ:Y%=0]Urq᮸Jrʘe+dTF`1NDQe0t:=]v@݀dٷ9VI/06|='PztX%Lq SOUV29 CGa qp~Zi2@^ d o̟YqVBNr\#'3[vGE翝=xq%{˧$b`Z:#]JX(TMYAX0w%o @z4bgRS|_ԝ@ MH/Dyd»",x -Q8ɫFd)lM2D1DԜΗvaWa 7F"F@ %[epGBҐ#βʑmS ,aWtJGy\UI<{֨@AGĀ;s74#U֨{1m5pE[%1ex,߷ELCG-.Rl[{\_症y I7$=~#p:N@*1XeWE,(泞U#I-< u 4=S])91?5^-66qP2QW]q5,+|~`M-|iuO IMFaWQ׃wfKUdݤ)t5e^<11r!,(~Ak? ca{.TˉC}؋Xts{!yV)(yhK 0jWLO](*I_/TQ/~O5XI\ۄLJ:9ivX&"'c(/pwLv' $'lp~hn/䍎mYV^urZ7gS^rE٩b `Z!qtgpX;TKENVze~M]'4 1)c0D˭(9.c7Fޕxq%G"#4g=j5fO@sfAlDۺBpe\c-쵥-nvquRKt :$h纈5Pʌ+8^}",hFB(GS"VW>'Գ ֛#Gyo f,+yDܡB틺#ظ{+ 0ЭNLlkRe^FIBp)%嗐 )rkqZqMQP_f|ȧv+RB5jj(RH-$!NLÃgMtoir\Eǰ[*e]5ȨG ¤UPoW[]aUt_Xa7J^^an4T{n]Fھ>V [LPiXK""jBa۳?Ntʟ`l/ioq'Ђ?kGбVEg„@CEUJ4.cJʊep]eȉ> '(+p{zW@={ }\]AKN2ݾAپ#ݐJ}pA4faT#xGgnu(wB_} Eq )mX~PHSgعJ )iWGEm58y}{,DfOZKOQZ4QB]gI7LZAm=z= V',YeMڲ^ӿ=-7j̔KmHZݽ2/rz">aad#y |ͬчmG)2*26$u5ɛȊR/c4zz~^(~27GN8ԦiOnX\fUCj)go8alF\y8J(s^[-f 7c݉]Q;?,d)?a;tx}faMR`)ʤ!#k/XD_h:1n$nlS(QtXU`\ "A.g,̨rlfr;4$@q:T@t&+/07u"hyۢYy+ʿ$E?Ľ>'SD.mVa_ӧRT cjO홭,}}h@8ɍVf-5ch7 XFJx_Xgh]bQDOiҳ<9!mGlOWz"NS 'G3^VMFuFoMj~IkK^4+HVKtrzMjOi0I]֯\myP7)'46v _ȼ3<+d&)S7%"*tnB3ޖ7%//ۂFcL9? Ȕ2Љ囊rZ8'<Lm򎙾I'Zi獦P~}|yX2R͸3k9o!D,(0\Ycضc.UMaei@gsC$j2N̜?M $OM.$F^_IxvxyϬmgNYe%f.͗.ǨyT.S559 8iEf?V@6:E1C#K~?C s/wiPuctD|5_b:%Zk[t-P~Ѥ߱MKv {`={ˤ_rXL"50:6/fUP|(+8fm*zuI2 l7Iq  FAwwpN>j*elS2ca1F?;;%J=A$'yJ箏솂`K#144T{֯U%JhlFy~=Pͯu2DA:!o\ArϤ<@NS |CKg)q[*Gs_8:sȮ{ѵe-`dW[ +zZǴȴLQآ g˲:Oou6gh f)İtSG&I%M("O0;kB5WCRsiq"Ihͪ55b>k2rȾ6+CKޑbm}\#HqۖCb.I&SY6kd/Iq7GfeAlS 5χkD‰QҠJU܈͛ :p/Ԇ@4٫S2%ƅ_hMp_;6ҊQϘQ=pXCcF[&ԡ`ճ5#'nҲBeVm&(yO ̗`rplvjF<J* W4#.ظ:NV/u7-1Z^GMpo?̓خJRl# sgJ|_U8;g瀱Cft_ Z=+u—`+y I[2RK8v5f{zķxD 4یa[򭝺zԷj&tZ黲.ƶƈݥ7xT\ݞA,tWBJgR{C_ QZ1<wa>HSfoSpA諾}C_:L!7 s&/]uә^̃dPAYfт?sfwfD.Bt'r4c|4JU5o`zaTc#n=zX@EjP(Y=ДV"۵뉘Zޘ3hrq Gx55ݩVcI̦U[Y}`Q&˥. =_kwh ie);]gf{E}0Ԩ%C\YxEY’ A#5J=-s&de Glk; 눩^"NX tSLG6W"*FIN1ڦ)86e*J<(""SJoI]8Dsn༫FH.oF#v.\ ceƜv0`E|qc/UXw颢%@:qwё6 Wٵ[mozbϣj#u z&!LE KwgWFpGڴ&\AY]tCÎ%{8 ,L_\X7MhX@ZRc$ G3B-ۨ7Xt#b.M57Y ^/Ir:5SD.| Dyj̝boR%h%*\!N&U@ n@`a}5{,f"~(hgsnKX{NSO=~"py8"2hOd @Ee:j-U=NQԲW\Ij/ '|իYCk˂̊35GM;SITiL;xnpt rb\&c9*u*A>Pq*Q4^o'J] A%RO3#?tqFAvcWQx`;&uCڳ/4RkI0<*o̢fJ*].?7pxN Hi5#l>x?%CH49p[ 2p>)mԀ_,# "fJ9ʑaw@o4(W3VGokr WQ5JmQ0Og@dgnJr&i$ ϤیQ ݎ7W^f̦hqu /[FbƮ4Oh*KH<ᚏ=p沩m4^&#bVs0Vm<="t&0:+-*y̋ X;mw3V`ύ%9gZ#۩1zGf!aN"iA1K4| dH b7|fTp [#f:¿C6ݵ+aG2K-2ZHNێ]҇ZWǥzQ?| -=c|t: rl`| =,b b__n3dfp-p7E>q!~r,ohBMo30YKTH_x: Ga1l 1KP8+c# HezF#{˨{t*xM~G5;#"F[Xېt%?+g9ism|=x8'qYP>iSyI$NPɳ|jc],4LI햀uXrܞ%SSRo(0X( *h|!Uhp/w|\){鹖<@+4Lt/pi%P},"wXOeF-=$d|?[rtZj!׆>q$fmEZ4 ŒvӄdH3}瓳kGΔvECQ&{xn2M e!"NK2|J:b|d-/t|B=*K<(yl)HN">:!vH~Vo*v~_{3ʡbP?t^6_?ӨNM愎tc57Y#niRyK<ncu{/?Yvv ]Mf<81BmSNog3 C-B)Y@ qg}3AUgbF x0}TR4S-S Fd G+;2ʴQ9^b)HbH.:Cj%$g"H33b;5%#OoPL5n5 i:*1{$[k+y/7xŴ;>ps{;xØg#e@Iè*w3ZX`L@6 LYrg~avw% 7V!M>J/wV;=n^N6AM3 ,\FB @wR@,Ľ$Nj 7^ӵS^1t a8 ti >Vim[S+ W^ {6pDke` Өh#է> ؀DHTfΑQ˭.4җp}Z )c SUIWb1: Ȧ8UnoɅYGJ(e !ZL qxWY_"m 508n,>lג3ђZץf"y `'K?([[ [}^A iqs;krN`Xi8PFY#A!|Ȉc2\>lk1b? ¬ZqQt~VU]?g tu +,>TGoFjE 7J&f:A(<)rBgiݶPѪ#i)+^<IxA|}]W'V[j.|5iUX,D6+A)#bHsQ VVƨ21?Xqw  j{X_vH\Ba#\w&[6׎ѹ(0qE‘$Bfl[NpxM(u*#b=:M0t(wQ[^mEXXW[v-(NfXwg(l ymn CO/GO<ǜ76oqg]~7_lzЌ礑Pm-&@6Li'w VK'^Y J_tS2 KՄO^Hˎq5\! U8o:ՇPʠ!B6(Hv]4oФ #b̺ /A.ͧVJDҫn*\Z{?|/lQŌcH"2r9֦pOA^SoLN,O yj.,Yʣs:G5qk,tY8sļ*SXwIl[SÂtB 9+%C.z 2U"|`ݓ&s4B?v{ױ'(r#T;4l=Jq`c%dr,o25뭻cZԧuO*,pa"U^ه$<@GEnԽW([K8C[ 2y<wrN虞8!LRRPP賘<`)4+ o"GWhǵLņHO*bld4+5J0=5O ?|1ƶeI.j3ҶxHA zT^6h@\G(FT 1΂3NR M*0J\i1v_<nY//$_嚼mF(_$'(xpE8 V`>"&!c4}(3*C;2k 0+@z_"УrDD)E&{}Ce, Nyݩ ?bzx+*9i"[2Uj޾kF@DCtxD#|c?H&*z8x3CZI- 29N_%T|a?-Ϧ=5*dO#eVU{SB<4$bJGz'L䜌S>$wqŪָ6t;g\ٙ}+WmnD-~)\&@N+[ eNŬAz1{ 'XP _d]Z!i2Iq%%T3<&[J3m+R(iGjľYb}~u,}9|џYG+P=y QLJuHX!.LecG(*OWMD^{L!9Ζj!&?$]B!tS-O[I7CI\a@Ue[+\Ap\|} VvDIxa q|9o.C2_{L…?uso(WȂ(;OWJjC>A~Ԏ\wbq[m$vMmE*8Sf4=-n 1M$^O@m ]Ӧ>x--6n39+8OmB]栃Sj7o ߳/5K!oI)S[/t.\/ r!n3Iٟ߻9eĜ!@dk!ٲ gfL谎!3+'.vkK@!91.ky80XJuU%v(@"w1>[ܛL‹"oqoL:?BF$jcR3 $_GO怢/zGb&F'J 1b/QZW|xgp!ŀS\1QF6ehͲ I3zCYkᤞ'xe?,;Ì܀ *63'o , ]_Wg_U^0n(B4_Z" ֯~*K+4UY헖(ç ysz;|l_[} 7 U͈ Vmkﲅ$f!_(&23u g'"Ox%NwJDO)ߚ%FGÙKV##-pl{ޔGzZ~5_+x^'aB`]*nR[pBU:kGƂiKS //wҼ:igFиu\۹+P>\|oO~뙍0X#Ty2;w J1p)RI\Bn`˫1l2%L":fSmj"Z8@24Um\n7O‹Tx?z\R p[l4b U.~}3 v ^7 ge@9 @"1 `ESPOGqtiס~762[u4:Mቃ  /Fo :Wy9ydu8||Q~ '.Wb{rcvCk( |M}åd(t~&a9:yuE R˔̤Ew֟LXc&À2mĴ,[^Q< ZThe`:RȳN5 ot>07FTslg/{w D̬~\nP uD|a'hA-!P)NZ0 '=k#ŗר'IwlF}3Ջ`*Cnt5h)K!uڗVdvaߛUZVdlu):@&ʮt!#zn)ew*Ǐ?+,גT4bî9 7,i k5dQ&E' _9рé ϙkW׼ Gc¢~>lØX%Ot{1{r ɬth:8\ }SwW$5PVߏQ́]MφQ<#L$/Ok'z)K0 M+GX9p75NٷD۵ΟیtNQmf mL_vǤf⬽gWQ@<Fü mEhPfLHM‘0BNpkh=5%!INiǷ1 lیQk/( 6' {AժFmߐM-{.9۫3֑z^x!]!ZE75$vg^HV2J3^Qn|-BF1 h5ʵTX@~r~wbƶcd Waϔws^M|]u T5qAȀ6њ%2p ErԐgm!_&G[Ovq ԔPbT!-ڏ%crHCW WF2@i-|z N^+c|b?7gsOo$У 1(@h)j1?&,§֯ax{[F&~jh5Jr0DF0a|'$]D^Ƹp2{:n?-XuD'ldh}6 xCθ|{ILmw~IrZ /& ~)+cUfyt2{( a,әiZ\9 :|S|.oMeta܇msgzg3+NNrL1t,G1FVd{}fqpT.0HP;޷n4Ga'%ГbNś#6;u KbUet%\V2sbkБTodP0~D%hwdx t9*?a*VzPQ۔|L\Hp<-ԙΨ%HMƎi' @&vBX L-hNLU_޷^N13('s=q`"hʀ۫M_Z bD}.Pi*A* : Add$ifJآU%8,crx-J2T9D#/KqM򠲗nNeL~{͂# "P7TfibÔ#;JtQmTk6juZ3qɟ!J烨?3d+_: zvS`IFz 9 Ylv㍇GF{hrhH?3wUc wkFBH+wYӼz_>{x1Amy5uߦa/ivf/&!3{+BRƟs:5Hg[ tx57%'#0#R/ᣨr'!+L`%Kwh= ojKOcu{<d_2F)(Ѯ4>ZPZwʦ%iޭְ&o8s 7WޮI* ifR=bObxIfFB:\fހ(g6[yC)P!%-Lo^KXXIgj7R1X>CIWm2Jd{Jrl-HVN{@_Z~ B\gj[M50^ *#kQÖY훔P8(KR=/@G{B\7F,D ߽[cQU9(߂ ͻݎt6JYqsu$@$4@W56ł8 tOT#";!Q5qa-!#Q-9evWG?ll]mDIɮtH5;g(RizC8V<Ԫǒo>cV^4W:r|:-[hR "7g:k Opdh,O-ۃR|lwtݰc $5h$M <&Х O]fZ]v8UqQtnNxh$ALw[#3$]ؑ 6KH*>?=S _O^ 5;u`YOTOx&1Ag4G e.9r y4|3Ces;bQsVO,mIQC>ϓC>VdK6Mr1L뉂G*$t]x:X(j QM"#3jX3^}J0΋j{ʤ%9\ bRJgb<тɏž4R4yx+6 #F#_=ifn˕adZ۷o iPEbv2O  IGg2,)៪/ľl?ny*fS%/fl})$pVQQqA1=T5gF}OxD"ktyO8Ҏ{4[I4łpdWGA{P sǓm 倘5Vё_2mg"Ru 5[R+sdbݰa nrmۜs~mYC6Gf* [0+I H&QsfQD/~w䡫F-Y̗9hTt TWzQ ^q`uKHvD"0ilVgIjS_ƏY3h⏦L1}jl$&(Lj[tAAs3Hox4BCXSyC/-5ѦFͮ-&qJ.kB_W Av7#@10\_X:mKyc{ybny|m}uJKނWc={'-a3kB[ xF `/UhfbMB=,< *S٨Wtx>vY\X>Hv韛Eb>(L+棗`m5o~NfaƲ bHiXg6~v߾[~iq7=ݥ /*K]O]Δ4Ua\p](9*Y84m3c5mг*YS T鞘m ?^azc%qy֌qriyExIgmNT6łav+#\qs1!ҷz#kU?N Z?Z~؊MB&ci!MKT"wJIHAY^'߃lk{<~gz@t+qU VJ=//ݻ6}t #J#0Lc{/Ž n/̴<R܌۴5er:̨L 8i;[ոXfHfl&9J6dSEL;v7 -CYyﶀ:gzH{ D.L*;a:[YǹCJ1l\d +(R %cP աupz{i Jmݥn<򇘕@3KyQ 4J;Rˈ6AtJɹ0 J+.-ϒg _-=}aeéU@K1> 7o2r bNoOG;p!F%3ēh~2m{!$`hY[JZdw3x8I[(\JQ'!B1qm,HrB^ȠmIˏ[ BS2.N}PᴦE狘^x|lwL@^ʄ`#%"H'чri=26?:LWޓƓ2T#8q3s;Q?Lli>S&R14/2VB5C:'B;F;D 9WK`|A;}a j|e@ho lX$k݄Z :t2}xfDre2P CcG|<h4%]>@jIH6sS!*ķ;E|MFJк%BBmE˯#*-#P/ ,⭹ ']eM ~׿osT"߻Y-iK꫔F̰ X|/HJg;Y#3 5“,2.,.\ \;}:J.,‰:lUҌȞ0պH.b4fbD޹Aͥ&.ϛ2Ns#l\&BN#ҍ\Jϊ"3ɻU+YڡrB1S(7"X *,HYR, z!к(7f|qCPhD6`G↧TQƧTqдtOÅi}/ԽIKp.{TQOם]Fx]j*O/#%[1s{4R n]oեz7. ʼn =.Z]Fe.#҈[Qؔ᯺ KPܰ~D`#B*'8%C8P9U{G}//gSn5%-hpSqtgH18Cb1=3oxB&m6, Z շ!1AG8Oli uF{ETᇵ{Mrgxx.t iawrsVT"Nj~$Aҡm`}3^J w?}i4HJtSʹ,JG A^YיbV"G(q=Vw%u:)e6:\K6bsn| 8Yp ?tV9z-Z&!^&1{dd3pﯵ g=v'$&!>V=HUնLOs'* ?ie?ʿ{Bn$&A)LJFlkOKxE)x ZrzO-c =|l2Z"nS|/X$_7>zQBĎ(t2܋gȊ75?d~@p_Ԓ1sQ[1%&q[5pRLGk! "Ҟ*o5NSVvFEqzwV1ūKӼx$uZ Gsowj5:܅HC6!P ǁ(5oN\pz{åPa=6\`&` AM B t9_L}.)Ũkd+:ښQ73)^l6Kn3 ]@قUE/26 vzO>-p8?kGur1Z@|pi3!"X9Z'I[k1z;!/Qk+{jvP$]~|"+ $PTXCYGB–AkD#sT֜D-PXӚ4*7/T5sta4kQDY`kZEx DREW ongD^ F̀o{!)s.L:#Y  vͶr8sxb 'uOZt881 r] iX͖ >R+<B{|.bmF#uz7%/\um$z}0AX:E"k%'^`;E|te\sNH\>wsȧFMN J^re]mK 4;놡d&hhEsoUgfK'e;]xQGEj3D`tVJbڟ(~?>;[t\mljY"Sg;cT%4yi* e5k[t"Bz]]_q8nIPvA{%=@F]kWsUg]_F7V-Z(4aˉ4@P#v6L2ąK~h5K[vlE*u$bC,,#fglǓJvҊC]߀=<^k/ nCC#QYΙBrI1 KRepA~LfB5<@3h4^~T\ԭNJ{O9c8Ls^^9g 6* ؔ@ҐBeoF^!O7{ n5`s!X'(]N8e?g NP7G_Fj$ I%-/&=c~$nH$AaȣIʧ4`ej7.S|lxH%.=]SX5ybU6 p.6_3Mti<J"Lo)H"nxIRam7vn/_Z& =}pqMՋY#դk᪀~8 #GD)_}-G7hMy RN1y>h}:jLN跲,&жhcϿ-=a]'MV7Q-;M$ (D҉,@m}t{hq2{h^rYYYdsU&4{SPR d?a6P =UA߯r!]*ĜvB;UB1`/d~)PQ&=@-5$N,iv Дω`Zv:~: &Xru!=:7R,ʚ_T` 5̠΂7 8hZaZKSʕDjbs零{mn}ןRtQ{`yO2tT${|,MCW}beB ZK1=K5BXNY^aF[ az/D"]_)hyqb(fy /pG}8xhKG31Yl*,8§/ix$b$oIg[63XWL5쀏B[ 'r]f`ԪHut;nI ƭ)#l>7|7h5(pb y |΍hۧ h%xSջ-Ŧ=j=4IxrfJnl\Nա6,xWÕEE4Hw-^cO:@Q%IIsGYw{km+3~wd!ʗX{|ڜ1T+6{av;T5bnIZB@AXPr?HںW. <^&R?2{T#'vp,IMk{ KYu EpE!F.OsJK8#r~@F$t p/xH&Z.h8k%~]5:5(MJ(ڣk `¤6U}A:";Zk•>#NR󈼲-@b4ͯ굶䌛iaIIC0kIW[(2$ѭi ׽ 61KӘoiܩ[υb輎u`2X-bR<%Gw{M ,4˰`?qSRgm.[~A_Yc׋OO9m>W'mJxYH:7;r:QEy_EP38=MKgXZ;I&6:6g͉ZU'jif-Lv\fĞ[Id2_J/^DV$subژx.N5oR=#{jm~lCPF 4TEzy}p|S3,e}q#Z39zM= d0 wtv⛂D5U7謕gUP@ʔ[\&[Wh/-DQ,^e1Wert 9 nxev53rmQk)jheUc6ׅ`cF}.uK3=|JDcS-!A!b^JfCFV_j-Sz}rߗ߆Ɓ1WA(ы]*1FJw8&h#FA! >\WFfcjhԼ &2)Pzx5h{j|6SУ #YTqxHa LI^dxIEDawDoSR&č,xePs @ k0l<|t)/yE2պԶOkKNP$ >@\Fn"F !9 1s3 {.Ց4 ik!vOqZˮ^# տ,vk3MBȦNΝWAhRvMUZo̽}&W`3#r܆Zƞ-Ћ]4HM|)I {tlr29wmQҌm3@Io@tѡ?82G5R.|{܊%A掺&q*,$SDAzf5rpxB \h!ba۷*MzO=dD 6ҲXdS9c.M!+Ɂ[R\U+lZ^ dVOX|ŹL!#$&'=\呧#`b/H o|l}Z Q `qʏC]o'~5_ڔhƱ05H_'MNt0[_ZȰaU%yQjBP1~ ZRqW iD:.3ұ .wv8ٿ dND/r;vأ rbŒZ&Qʈq_W\qX(nAdբ=p|^AX{èH%X͠"U3z›Rg"X A '[ڒm͵fQ^Icq\V⽎#Jr^Y\z^Y4PSQQKLPVư>cK)?lmztN+ OWC1=^t &=+-ʚik*ffМ ^kBUfs%~[Z>|/9c@/]w 'UxޓHY|p5+Y9{si $G.";z{@q-=8M]}w\cj%yeJF`An51'ɱ5:6||6q8͑⮶"xsG`'KK/-h_D%H~,MxD 4+reg@$fN4$DryL [(@;x>rvR Ya\[xm:Pe ] y0 *H%_S&4Ƣ##9*XF{ ybæǭc8,(75]fMwU}T:=&6u6I,:o>LW.D\X#ZAz 3 ܠ.K`Mvԟ^:Sn,\~"Y q+¯ [٩W~-Pֹvݱf]ԃP\gx TX[ :74Zw,3k߮%soi$EzgV1= YL߉oͪY$Rsm@ F Y1LZ}ug1jj*lFwg) 6q ,xUweh6U(G)#wKe%dLe'oNjK2)RZF_yӲQKS"Ծd@z3@W-n:7,(XǢ{xp,9)LxŔ3麥!8o \-3e!6Bt.rg ,Iq$mnQk*[);mh}G\oPT }$2-*ֻ#k6D"i}ՁV. _&g2 <)vLH<ޏS/YQ#D<[e(G6ՙRǃj<> mnD# m2Ң*nLPs)vCQB q5[CK5c`|#hݘth| ~L 伭XwΫ-FҜ2)H˒&S#_;0~_ðp#@ʍV= *:NT0JyQ¡LߐP[hb(+)ѵ3)w8S9w/BhzET+ ] 7y-LI?!"9qeuFB|asx _H#Gl˄{mF&33Uˈr…Fj#*f5FqCjz@QmpؿWR-6+&?D}$_ C- n- ?uKBid-,٩E瘫tTx 2}I/YVsq bQ}v?. A}d&CwЙ2[2 1o:XMޖS> jdVT&[C.+ O? l~Xo5hGGft 4q US2 0~f+Ϭ~]Mk՞`-Cҷ?<ɶ7#tO?4͖KM`DaP`A:Oa V죊R?1BOHR@jRg!)|lzE:Ic.Ժ7bgo#j#>v5pܛVh$jVΤc-oe_'WauL~}Wˈ KB 9o׊K5{di9EY$.I, a%xxh{g}񰹷;joٴ/WE[Cgu;8\ʐdlZ[u URzJ1 kݍK2kԊ| ̃7O w[ݏH?d# qLxo%թ'ZS+Y:Tt\)\A>/xf=4F4Z<]n MpoyD.)_ojj6s@ ߚ-G/=\_6} 5ץBH/Ҩ-'N]驉_g 1vO?։npdѻ q8 ۄL\IxbkȪ9+p"+?N APuܪ :67;r, %&j{֛z'(CX8" !p.lHBwzs)Ida[c ,+4$܃SYu]΀ۍEK brv?}#H]fC ? ^ɉK`\'\`q$]@tZLimQfȥ#%]1[|#R+vP=HvFBadO)E)2f} w[+@ h}#3S% >o]ᓁ}$^F`1 &nsqyJwX&@?d)gt/oL~`-Z'oً6OOރ:dI[V wpYg^c9pCI4WDbiwf=ιJf|1V0ۥC" k~5 [r(i8^}#z/`&\2Go+pKw耂@]no ֹ/5Y{B@.K=]~2"Bh&5 f78 iyd!HqyƏyѣ {Gϧ!D=欀쨱{nʮTQٜn+M6QңMX,47OS|b_vt̯ARRxVϩoLJ ghlh)vFdUKw jtx8苮U /`qa͛yS5,_+|ڻwxH2,W :4r8h 00sN?Q ܋&SjZsZ`h1$75Hާs|S IRZc D^65kVfeP~]n|<\ߨt~ MVCwhSKNBuVCۇrމ'\vF3ضy*yuWYj&iIUHE/%yu.fz` 4Y/PGHd8AyE_=7eU xk7!qs-]癊jXB5%1 6WV |~\BHkG VBBF9WCc>4p?:} &/scI2.q\Q󁊤朏.4- Z'PhgR:OB xGA7O"lӻΉ&BXȱP ͗|/KBwe!Ϸi3/FUD՟w5۵˹@En.hkk#+bNb|@S0*xu`{>'mzC'W5|Y ֤yG,;3 `.:s&Qc3 A^Ryp ga{ /ފGNScV?cٵRSL*!};A}nFk6 K鉤(R't%9^C❡y[ FWpd7;ᄊ+Z?9w1hD6lJD}(JP1v׻ȏ*>62?d1`!%{tlzU}˹''!Ï-1W6a_"'#VB59+#T-.(_*vC@do87}ߘ_c}n"q :8 VvGz}*tmIR(rhuzSêT {rh2U#ωC۲W{:u{,I~cCͨlA؎F9C]7Gh/5$;e0vT .F'Oy(_TG~ٔ9SNn1;cR.;/I)!Lj܃1:Hmp<gDpzf_dP_) rFazv+YjW pC)r''NS_Pʅ |q:Z^ӯi/ud~iKZ}fh&U;^}{9Vf'q%iG{vqalyUƹK+FZ#VpT~})h]y)aS/Vwu}ɠ ׊b,\] 9ų%cJ4 4]WMfXf"B=WvP8pBƭ-J5Lw\, E UwI{i=;*AX5G?}JjãR ֩pA]֞U7Uvcņ4>Ԕ`*"lwLR,? S_baJq$Ţ6 2dvR/{p+ɹ[gbZ ,?>sfg*Pc`:,&@$KO}pIQBsRXѥ'I:GAo~R;ȁ5'>EU2Zi7,DATmΝ,.iT,{#i&_`Z+RmWn-.Kry-Kڒ C[/2}c#G?3m-oIhv|Э~iH0X$"QB"43z`uBڄ3FI@JR\}iӋWXnk7{@L|0Tmmxڢ=. =C)[V?1eѮzL)Ԅ3ڔy蚔#5i춍<~X-u 1lԿb fg^ө)7^^V4Yg$UޏDбBhu9_0OX)l5mB+5_i']I~_T*yD 0dPAlKP#~ҏL;th 4W=Q4+\F%# 6D5E>@ʉ02 *tGwFc$zj-ܐ!'VC0!^¼ ѯA-IdT| wΧu-e[#3&́21x#{y#W[00+`-!w>Өu}JY~ٛk߰O,,,W8ĵ][ j8PWq|vhAVb|4t7^uv]WqV~﯂K uo1?Z.dpV;ϸq)@hO%J*pp?uřRil2LARMgeFKSen%aEq҅$*6VAk걧:9IuKyLX&Z2WHv[/*R_038ɪ,̀)c;<_&֖]\ܕhXT?CP`{bO1TwB!q;dSޑf,`}>Qfɇ@CzPZV[3^T)7nV7ˁIPD{N8C`9xȨ0qZfU x#ĨXf]I\CjyO e;+DVG8$OkLMzu'=Mt#k 2vi_˂iQܰԧ"(2 #q;ߢ;]o'=ȺW 9񘙴Gx!DTwZ#dV[p}!|ڍF]"5ג &,9dB=mhvHԴ)lu~Dѷ9ANEZn6<$dnWN:6cjB~@eHkLJwZ@e=%' ij(p8$tO   ] Ns u>[ 9>اt!u"Q 2ԀU>RLϴ;Ю* *EsOL&3ѱ/M^/=<<Ŏ>T2L8@; tf*R"lh1fFUgzSG`MQlPe-b/s@Z!ʺSf?(ƉI\0-1Rӭ_`_T}2iXwU#j H.n2XGn95=ƣ MZvxbT7I23>E)j!B:CU:BLB>?H;A/.Fa2m  y@=˪y?|07 4 Uن4ڏ핶tdC^I>g|.i%LMl4w-cxep =;`ƉSss:-&mh?:ݷe2 אҪ'Y ,!s;5b߸AZj< WGp~)QTNV:NK(^c;ŧbgl9t,?Rp➉dc;C>1pw}]K!1:DtrW~nIgˍy~3D"B*Tr[&EբoHV"l֮>GCWf+/-v@Ðmiin|g5WLnG΃HGZP iFjo0N Ʒl.NW-B፾Izeu8S%mWSTд;:dV SkB&I)! ~P>n9NL9w`| KBI5Y*v{[ֆJӥbAU:P(5GGy/O%aJ< ߠs<`@_NAf`:l4',З<:ֽ&)@\~h^s7%ߠ7v{쁾 rS]]U3m_ &iӝE29yB`8Le4 2dHg#(';n-:y;hc܆Q,2Lwh} "YaZϏpϳ-eݼ;cE3 {h9TxDZX^&N+DV769XoXD+]C]#GkdAj>;8Q~'f:Aa,q=^VM4K`ls1Զ ɑ瞌S֡b^6sɳ~x:Zr˟dE,&:(B0Yw^Ųq:^s٥6 ocP d)UϤɘnSZԿyu3cYp@Z/{g]!]S+E^$.4j#:BZDH$K<9 ]U`Ss̄ !ͧah_R:ZApBHl7f!~:w7s<%pmu9x.  GI]c#>qaKVdh8=A^G|n_䗲tn}@DTT737'0ϑxd#>PfF;5JID%#;';n񎈅U(  p_2_vg77TC92 |+.[8iSSo*(Џ,:tS"b7N h/m_WwfvXF2kyiOy՞5 e?MB2+93U@wGDs(lu_LqQ܆}Jd ^?r& r(]D9-S x2-A+#(R)`<}TWKCKg')p1rcglJUD'蹠`2YxGl"a7&YjˍHG`W|@\.^o>ȁB_+ȭo8H/E_#\2xN,tKZӄQ@ w޽Vv 7ĊwW_dM,*wfr[M"O_ к&?EbHhb,q~R|BSd6,m@'xV{ i3P\h $QÞ!Op 8<* PHBeGMQzO,!=IGSYP*)qM@r"ʘ??D(29WP Qaz3ۀn+vCe+ԭ RJi[Z3룯Oӆ#2Zs]zۈӰ&%H"0Buu"L]}4:R"i9ʖzW+P GN4e<=ЮۙďsR rc?]I V Jck[2òYCв$Ӭ3cAC`vmL d,l8dVM,"cO_9jGƅVwB@']W ew?fথX{"h%Sk4DH_8! $Dc(O)U қwdކ=VsᏹG:ȸ]tu8$dwٳJ2+u3)[I$?E X8[pi<ӯWSQuͶC4Ei Rl hW1)]D:h,X}7!yȽ>=CWqu [~,T_a^=Ou~QNvGA{t| B~p$xJ.3gD4hxTTyYv"h6P|L+)Dp2RHI+@ AB!h)C>+y4IKdB*JJv6?7@JNJ8fS<=ԑ]ᡬ%Լgj о׊M!r4_yt#1y+ zvވt*΢/m3Q:#Eg!4d}5t#CgH]B0Z7fIE9}=@0(]ߥ;y6!ʶP]EA8&~آa߫VA$ގ8_}Y #;a g @bn_L5W&#E8xSIa~ Q1JJ ЈnH` A:۪Xx(Wpv,wڈ)8ځ{2l"z+ P[LLvEI2xuoRF-⛑AZl!0Ab]x4dnL@p@kЭR!; h*p7䐡@%0)vzZqs7*1*c'l {R+_ט(uͪNbtGde}yIg jK\r?dS^ܝ|'ֆWR: +PXeu]jQ ]~4v/m7ŷdr(4%SOK1C ^*pMI{;S|NAbn*M'oE-ᏼ)8-J2F L'~E$M:zЬl E&4vpG:4@V''&KW͏%tWI3KD&rQ>bN²^B]lj jkPKfqثtڝu%"b/$|%C/7@o%*Zf{,@z`Υm,T"p.̘P'SٺTj,nbyeQ2':f.`n3grrJ)a$'h!&T4'||t ;<'DBsu.fky<ɏNH0wvy~6?e(;|(`?WGH P੏;p1 GyT"QA<}+#zch5|B@Mjne ͨUD<1\(KnBy6 #n=ׅw)%Û{0]C?E 8o:nv2 `ZQkVX`7y/H3~B}lih'$e1Tܨ%7KeBv*H;}u\^*e\ /b.G㷍i> !tB!18-ګr:lA ԋGqvt)o֠y>jyQm7&vxu^ zfƉHf,ɞi/-~B qKz$gm`T=OU4Bȁ>s h'&QAR#/8QzLP7bv 1*esgJ -H{fF"8n@w.i=Q:Hz* &Aw˨iQh2?'ȟ{2X2Ci:D[*L=4Ӛqh?9״]N I}^ 1':GUSLMHE准rв+aV]tUI)(fXm}wz؈4 p[kYA0&8ɬ~uXq5 ág-饠#*8NO;epOBatO~dB,R3цCQ"7_z-RȎ܀Jxшa /83/su?>7P p {xxӬׯkR3[ٺSXOf֖Z"Z_d< @ݿZ2'e硗5"%pX*xaPrۋ]oܟ!aҭBnbsqs2ePjJ"7\APUvF>d)@pzXG0/x^1(OK[+EH>@>5V=@" _gJ],y kc?DH*)]VL7b(|g{m1+j,xr[~45pz[J]4Aq{` y~ 5(f9UmtAl^c0U9Mͼ3BPGiE7.XБNƪ:p\ݼHP 3\l3jq&h`,lYxCCMa<[V W ϑ ^9/Ca<Nen02 dM( ~ ,Ds0a )Dg> 4юlp*H>/'1xM f0SMt p};^_33Vkռ/1Q];DZZT5@/>B`TK/QHj^rZ'8 "vߺ믵$9u?g^(+4yjNFA`] (;$ԒU;3g6\4SM%-h`Å`1Q [^B3ed!srMT2K :_I l漋r+؆* `n49Zò1eC5_ɯ闻[^@s(Դ&Yܚ_MM81)[q:chGj*̔㎇j(ȞBKQIaġ\%]E1~ CmT}k2Pg_P:V )T+hLQCԨhɡ/)IPR=< \(l񈂅`moa)Ц\d7+:TC|FVL]jTտzR'ȇ6j7W:(J(Sov,`Mv6Μ!w( 1+T`Rmcp5Fw"~i!gBIe(C#˵maypgD^Kpb{K嶪j6.TZ5*^SBe]Tg8lTIxZT]"Au~طVlX%!rk=gsxJu1y[n;b?%qV?'S̄A[9cPbm<+`[lЫ P2h$T㚜Ky53q Om.H=J~V"tS(!8 Ye( q(aC[RVMu*t(ڼѝlЙvِ+tBZtR'@}?p};&J"=F"*0owg9,1u@R'nBbͩDYe&Pܢb&>Sa]{藃 ,7|4dOhA.ڙ5 1X̱ꧻJW_l0p$O=-9Ip%/'Q/SWzp͖=cmwIib|JTa]0yP[f=k>BGgtճ< ?pׄ@@)r<,)MG `at+@~"Ȗ[x$Q*Ttt!*jƾ!GPke1`2ޅj3=q] z^STb1ڎ("VJl0 Q+"HzlSK:}1b̒yM?6iO=6 9Dž|8ax91_9vR^ א}V?˶Gig[d]GF֯k\X)$*E PE;0ӳ cg?d*qi sKBYqP9D>(v@eVG8;r ԽEXHpgNV$Dz~2 -K S: 7.[]( D=9YieBeQS3g+/V<$굸2q'Dt٧ȠSS~vk5#}9{\h3F埍bS_IxC ފaYQ@'X4J|fg@1Z/G8[I4aة!%V{@BOn~vZY9Ƭ C_r)ylIscxSXZz]3 GoXuAfmzViR#IYBi0z';K$j=[*U>=^gP(I[i(Eq*\2+Q_?P ا$Ze*D2s i[D߽0Y(Ϫ(S6kDW0ZdfL`Vj+Ш$WXBfw-~ad]4^)D zT#9{KJhKV3oH8[Y_ϛM #`nf[* +[6Nm@3> 'SPyctx9KԩH~!mTVE 4NS]C6  7^8']ܰ[u-:eƊs1GowVlUquo^N`fğb,?(su/<<۶j؏7 .] ǰO5wzZʃ+ZdV\)(25@Ct4u<X.B rA!D7ϷN5 =*azȨjsGP޸,:~Wbe+>US("ۿ ~CgHC- %f} иTis* k:z5``63} :rt{4)93ѡMHx,'[`A$:[' ҬB;xAޮIJ ~ѩI$ 4ĴDB ?ݑWܳ.yM 7 @"*qYb=> &\ļ%fg#._!? cP9ajC~]Њ!Zʿߋm鰠J%7JKGy.cS7D[}CՌ?~S՘z>%FWd|[ *:*1?]oռ,GT&}9%H߰󋎠Z̆a -YSuzmkkrQ 9"FڍU9ס"Q3p t$;MXƚ@s螋R>.3CN,YIesa%=zMqo_w]4OhɿM&ğ{ęx-"(iV' -GQ\y"fe ``_EշW[u2w"~d!4!'QGlWvVBޖh8͠ |~W)k&)pp\"GE @7R˞!C+qe31e2Ӥz8cѥU 12i8xr 1@W$X,#GJ8cs/;#_ Ckv1R*M:5MRd#--+myƺd&m,b#xN{d4qڕ.\5Mʕ!4\QX.~T;sO\ *T՟Rd25(=r%i7O`nA7 ,l(kA⊉ %&ܺݰ|6@qJʘYyd)\`? ЖLkC  >jJh9A AM $Hpm2,qG ͅZhH~m" w֖b$…plv%c 4h f j;TNmTW\lH׳_lk h]1 Xr owvFst٤ޮ' SD)Ѣk*qDujm*fE|]b%?- & Su$N:+6;aS6)d*4ymBbaUUه"M4),_x=eoS݊B |4i|ѩi r 7և\k堠2A;:gnF?=СLRirK7F""4ߥkvHe}%m^9bmF}`+Nb_.)<$HrV)3:Jq}JUw1"l~dANŊW%2]B-(n0z>\-4#(mdb͟ex9cG-VJghd\w33B1`*C[ mK匷bqK )h U z55ɸgStP}oU:u+Bڠh |v@T l.@2Nvkysy>mؐbpׅAn<Ǻ*giJ,L9Wo&Bf{CV@pw)S+*7F[z@O }8 dlKqǭa+[&!d֦n 1ON&u^*U, |*׎hG͚1 E>VAELj .@V{EH['NPO*wYwF1涓-ԋ _=XYGȚ޲T 65QLRa )V%(J'X=qFL؟[~#\s9xz ZŠ%8)~6 ǙT+  XH*ʕRxQ3P0tמc;FޑA߻&*, _&-m?7TlfӖoVێޙ50b?VWYb3x E-fXFvfU ɋWY,}ۊQ [8'(R6| /DxP(AYgEټQI}|uZX*\+aKnSG0IQq |\{r(DFr׿}Uk1Ai!,%K9_ʛuČ%Ō@}V/oh3+F $$!7ݞKV1޷bЛ4؊#j垏~PIM;Y6)RZ~L]+9;U7H:΁P=J 8ͦŎxjE{5BAZY39|+H LU$yU.]*c䦠,Z:JiHKdN6&k衜f̤8Sw8c'B )H^H>;Dc`ϝiX|W9>5,Xi|KS!i\%.{ZT`[#ol718kDI>owVωxU٠h%c`(@BB"l_k[cٺ 4>: aÃpx~R}WY{*`4tO Sԙ-+`]dH.QJ{+&nσyCrw"]8Z'^ӒPo8IZ^\?ߌInmq?P <[`܀ SD#7R=LE|wpU&!e/[A[|XJW "XA?飺$B:jE( 4=Iz+/餅t+_M_,O=cg-VOka˨7j3ꪟ %l'$asz" uIZ-~W~!cN\it#FNRS[VR,02 :N$eX&}=Ɖ?wAwanΛU;SUC>' ys h;D 9ƿ}uT`y WRrU"'_Mu5%dOjmv! X16v~S8}rz"CBxP1RV8[?>^Nt1g|ƮdDZ5L<nEAы̓~J Z豊plpz9q;0K{_dt8;:Ze?FF@QU$a)pz~ت 4HvQ#Sxc MAR%l2Ma6r5S}oreN'&CV(yVܵƛ$KgCf\y6q D&MvHvmMn։+>1B$\6#]}Ŭ#LyґϢPaf j-!5Mu>V5oz¶<Ƀؘ@o(YɃ,>l7N!S=7Lj6[w-cZܔf ӄh*Nr '&TtWj#m80vW~9!WW[]$S nw28-sɰ[ϗɇƧ$)"O(@ ԧUcpT}?-Go=C!V,U[DAplXLz{ wϔ{k 3RV,3QOjIjκL,ᣡ?>pwVh1NҘ/CDxX(rs9 kneß~SQm1nRM :e}zNC꧍ %$R G쵝oĝRk,r v{{]L@L:s%u!إ/WH۱Mm+uI?D0e,@؃x| )h%ۍaMSE&dtO&[ s>'l0 ťM Hm>neJ̦F߈$rjgc&88nzMfWΘc3{lob8sd6l@n mS-0C kE7Tː転\Y܇3;J/90-9m$D i?L_Y!㼟YhM"upEo>m=a.y#?7 _+ZvfҒs`Do%$ Q}1%ҖƊX" rf`9lkQ]UU||1v]F7Wꪻ<\`PKğTuϚv >!Z<&*,6O P!-&/I..⡻bXAKd3qǭ~$gli\=c2cxL#?X`~P"Tb; &iP|čdYwY5bm( pYCXo b|ɦ,ņh*&v[pi=5;qN{_Ɇ1 xi>eYfB&YKq`k+9&TjʒJNXuYnJػ *1SE%-M"8BШ#teZ(ע &'=܃Qc6_Ls?'Jpz8r~ ʽ=U3Mվ"l \ۤk/1t]! m:f[S?z[%ZC(bUJ?VتN':W|5frKa|scWS! ZVW&pm1DčK`|է-40~ NFLxoJ)C^x|;AМY :^T.zMA壅Q$%q׉!{sPAUyԌw"%4Pɦ 2ֽFSRk}-D9?$ZDGfEG홙Hh*ґ`dmjfM/O!yJ٨+}K)ateL 73\Xc]M͊ƒ lPP:!6 G_}"jr rn$N4''`3HL)Nzq;Ug? $ee7]3^zen. ϶Ѝ |~YG~/!cDzT7I@\]|q` a$v(p[d@`UipR4H'ks'6@zUp)uϫb+=Yf.EtRM@,Ag]fE1ͪ-YSk8nk~pytPe #;Lqtăd/hg9X}ĺn,Qm[1xL is6[#};,@COI~'GODi4\ DwiW m ~^DE)|Lƚ^8H[h# s2;UKbgJ0Wi[c,}ٚy (u.u-+)zMb0k'GskN 4?6TQȜU3JBo6GxuTu"prw 3@9{ZP²cF{)@J|qlq1Bop3gWXmƐ$,`xzj% 57P]8ןՒ]Bm ANNTC _K.Q--Vgq`)x#r@-H`߄@"h;0g;%^rsP5ڤgtp'++%cJ~'k̬COXuH#X:7m/0rN .څ4Vϔ M*KȻ-6_&DsZ 8Ɵن]D<_v ~~/:>D 7P%ɑ* GRk锜IeEj0TUǩ{3TQQ2_+]^&S Y%" s ?mT 5K_Cz!4>;aVÆ~D/B{OY4 FL_Y+ پVGg DfP{F8U KtZE꜀g/$5wU~6w a2!" FD#G{d~P*a iʒ:D|:q}wx=~AFY:`Cgҩo Gˈ=Ճi y X35EH!^x_18D C5t];quOVO0M#٤ i(UbCCy}K6K6i>#n_H_:S{VWY@t"gEDDg1jcvK$ &e)@-=aYIR pT>(bP(DXGYqB"$- x  .2B՞%Ałd6 ͩGt)?lg18p[_ʅ#ǘlL(w~zd&:b M3yN6S2IXZOYVO=a{J.8IzVa1K- ˡ~h`r "mjnU{4=5f!>*ld$0TS ݦ3B&k%gW]{]VoT#k+(wW1YQO5?RzJn 3;7& g74 -VGhQPkMjP#:{TfSG%sCxSg }2V?][_fG/ٛOޓ2B,`Ig)ْ7'|#o@ `dϲggS,qFI&֔M0 gZY%rv^r(w3!dDG^7O׃rj'398ӉU=|Wקws'YPҬEr':̂Z:3Sz lix@kxv!i8~iKd/˶<"ԃb9w}B0Wb'mMW4^J嗠oyę2931 >,nRxߊ򞮗^M)W>i7,c+*pкKу$䞄#b:0jJLZfZb2O@T k O{[Xb?w+ie(8U0\:;"ZX1`ix:H񏕻*|C>.Hhj+1,-ŠWGP(~':ĒBݥk?`ǒsV2S "~;5A̦{CrvcGtJV _Hkψ-&lx2tvrpl|J:}yea+*2eVxQnab" ~l IOy*(0#P<}ޙMrRBtn6 6ɼ jvD(Uӹh$*9. K9V Nڒiu*"E -n!A}/ˮwusNts Q%?Obdi5oȫMh{Q½ׇ m.dڰ:0qNton;B_n0a,6{*Aևf>"+/Y̢^$P(SUH`S>ЍRid6vi:v!\NNQvJȅ# ͇ͯXϼ,::ʤXk Rru2m>ٸ:M̦E4K&\gN[w/+Eh3xnn6 Oi#>~*GajH질. n #zɒLG3C!Y2b4I`AZesDyjjs9,x<|uXUB>u+^7mow,]>]?B)ĨqG`hn$ 'u7d〥EutYI;L%Ůe {P7w&:n.y=WH)])}1T([4c>˙|Q'gqPY-cNXKQH%i`K6̫_vn[! 'vqRC|Sh=yRȘ1'[+1E+I3v/&{RDhqJfnE7CBWas60ߴ\/|}Ӭ7$6/HKκB4B"۔>#ɯ2s:̊eiR;VeTlv@fb#Ip0lHlE(x9n>;Jfʲt06Fê(: +]AkD 敥&YoCm?D7gy g/KcYmn8cE‰ud 3\tZ,؅ OK RT/̜0Uj: 8QJ.8Bٚm~^b)\ܛ6{ b.$^1‰Y} JTN ,*G|2fX.%FJ֓Ow,*-._` %\uu[5bR( IC Jڕ"2]汪Zy"ƫq)%& B\jeeF=^K֘nU+sC CGίAtj)Hz@1jvN{Fw#s⫍d)IK@UvfXNCܔ,̀d, KXq.L/0kfgƔ² 9c\KBd];%t΁J`vb'bt"8,>䧋OO]42)mQp|s6 }o:XoITAպZ̧IbvBtxk:]Hj-wL{`UJgmw:4:ԝo]iUssw: i끾PcbS1Ĝ&~Lyc1P{\XZ$H aYU;p_K尜w*s?aQ ! .}+xsf Ѡ+T@D=cKw9ҲfXѻAC52eNc:7iXf(EٛHơbq&S6{BSDžC8!*0 F՛uznޛ>BMT:wv y=876:wĻ|8&H1_ W0z*5slI߆Ea~@xƄwU BG'D։ABlyAJɲJoNR_WU$|x[PpJifGx WhI*) GI*L&u;źH8,Ĭ/q L䝩IFR$#7Z;,>Ր?)6?UؘTـS^ >SVa'+ӌcZ,,~թs~JW0XEg,a~8&>FWeM]@EIOvldl-]4=XGIpjD[._ ٟQZ^*{LE?Z(W mb<Fז̧^{oU7"ˀU=D(!za*=M|Z!/*$ &5J:;ȞNq⹁WT_ BtJS83 UPB{m)ےs!勒A>l!l<[cu ɠj粰P6:5kKup҂>OqBu4\Ži: QM-y Tz'J hl`{X{e5sy<\ɐ$p7WcaB\'AKĴH䃀l>FUk])dҞ& ߅81?d*s6F| a HXO19g=+]2_"$'c$4CFvynpr!ӗ!5ꈏM$Q$c{y[1}߱+qhQj3^V(T*Cڐkb̛HΙG@QbV̇9_?R}^Jbcb&iY\a]tva I*|-טq&<%BIS0pB(v2(f6(#f4`DpuQ*mǡ×nzT5E;X<%%%^5Qx!u^ip.[4jl.j;swG#m1S!A;`VQ2qW* ۛR[)F eYkOQ(,܅inxG7mzQdfK`!.3dѣ_OvY]:/m"@ j-_TiqِZBuVTq4x#&{q}]T\Z 1spĒ)øAy>:fY`o#  *u;K*lN]ŷ'Y?vz5'F.H9:jLIcѷT0&p<Z] U01#  !Baf֫iGY\TΫOCN^c!Da<a5閥,h<^Z k^ +rQφ>&0;Ki? HL@Ps24mԝ4" cTd/۵+iG bnؒ"tTycc+e+x%P|q;έ&CPS3j"_eu0~qYx* oR>kOv/9~JGݻ 5ZZ2V_(9R3N'I}r$@ T+<\l#<PC=2*WAF{6$1kmSE86iouE,P!aWަuS:K3?rl'N>Td3~cD,@=ct:O7i?"[zak o+aNDԝ'F+{z9uI2-<q<:ԌF _z446;$hCdr1XH_T=6OWcZ+"h&4ϊY;ncR̘7> b0Bب\6ѹ__OFU+_s#z(84@k31YG'N5 6`Oy庯"p%Ǚ@p/l r(ɳ>m ;(䄸T 3 \ORn}ofڨ?RI 6\[Xn/{Tl*0m@=l I`lLl_yp&ʄebΩ%x%p~v+1U>d8! R[ CC)XۍӅ,/ŴnGN}.dSt$1x̟33I `"H/"9LS Jn ԸׁDRԈ}b?-ml3aq g(s]V^k6~ gs|ĞGp1}T+H.-Ae s96b݁xv6o. ~z˜3aOUT[ ݨg Gլߦh }2{RǶSVVn}RX'AgT$a>{i<5;ۉ}%~*r]{, 2r藨۪%߯7i6HY`ΆUA>em!}弸{6 U/PYCTR9""͇|4񷉄|Sxer"ҔA63c l%9oT ;`ŧ,ftB+L2`R>VB-s+َ1Α@SǎNuѦ&YdS;q狲NWd"i1)M,ê-֢B3z]hɃX"8ots֌Zy@ϔJJmc [ q>lBnD{qC7:X R$K˒hߐ%FXiA \!y#ΊSHt d%~.X&l62>gS5ʇd7Ϙ/B04&H{1Nl0Inkm@>-DuzDذR@(]_,7]tDR2 xiY ٽz CfamWzmk­/R ѹϰ ^Jkp96}n6 Bzbz9z4@/}{Zδerȶz>NFb>F$_+>KO88\ -%"?O+/?~68-RH5`PQAWራn'8 C`ںgI=%ƃhZ?Bvt3VnC"{q sU9~3=&GOXڵ;JBBa!گ0GNSSWaX&TmshM7^pdRE.Vu:(p6;62ZM4:3m ģP0=DH/)'sE#Zy"jDdNFʠ)&LV1}`ӗ L̨+0۽t_LFA+Έ*z~P};mpF m,do mpDˑvhLL vloy:uͫf)wehsy[8}th(A1j3즄G0aTkEPQ^k"$Xl?ޏ+Зo;+O j(07^&ewrް3 s?NoR^{|vit*U67 uQl 0A>fC.^bg8^ptup ˓x{|1obxVA͌뼴*#;PѬ1rG: nŨ{lR@;$S]*;&+ݢZz1-. jri[6WfW6,y_X ARBBAjEt$nnȎf(XOIxz E8w5]Uz`lw,i}(J!.sTd8զ 3d-ܛUD/&ex+6mS~ͺ}!=,aʢdw˫Nz'5# RU]rdj >"=OPHSg NSP#wwiaty6d'Y\/POLl*b``rowc~>.mpY VqXɟat:+SR5mGoOP-QTKM>H~ 'miڃy2 7X1A{CGt:ҽLKby)fV$hD Y@~| *ep˴G =W_C bU^*֐MhHOV4?>U+_e7FpDވ}-lietY4Ŀm&]TTML'p w; oq-mbjcC4tq }jgxޡءWGS؂%=l#˩kF Z*pV?pY yCf\#V+Eмj-Œ@@K~qjk`8w. Z}os?rQA#x9dZM.{d e=3`[M0ov IhxIkP(>Co{7Kf2#\Nڰq4\L6dغSOXl6hڪ`nШH>l*9BYhJ ׄDx;ap=g/6 w=HE2MJӡrAsΤͲ/ayi Ha֫3,gp~k.㽰e%$sD FWAZCdAm 7 H6JBpT 샰|z''7Z[;jG>4[hN2o8=IO]s@s/SpBdƂľec}c qC+xl&8>V YSY~ +kr+Ta8[c8.7w[ѕ*z7;+=d&eE992MS<лݒ;M$D=Z;3x`&%V7"\:aQHw0CaiF>'m/׷J-|b6dq iTvgMԆyn}.3Ԝ)47⹔B=WM?ۦ1\we_'IbRxϾ I# eR_HWE.u8`5H,9˩]?B aSfu~?UБpW,CFǡ,/,L:mJ9U]M &ny`#? 7Ud" {##*KSLzO9\i8~y&Xbr]PG@蒓q'UgԞ΋;ǦtYsu`gRNo`H \2$qgSjcr8&1)q]#W~Xx̕.V՞تHyI1A@ a3LVdҖ %]Kf*@j+oҼl.0owZ "k=D vK9̖9ٻB}aEfcb^튘$ xnR~8>].HEMrJ3 df`leQm7]Aᪧ/P$]bwܬH@pRao]AA$b $WY hG'B5'ԴLv|Vr=`e,w!1Êf~~<"nM>cC7.昙zr5Ž"+mށg#/6va}!aNe-Nv5 9aʆ4I]iDh$z#z(]}yvk/w58 r"JKN*i4kkV7yI[O3Sm_g[f ؓ6D-pMZC !^VI&}LBXH2U?u- PUujBKaA}m)|f̷!1ۿ w'zG.56hyȑ[si>1)e '퟽[#9h okAe{!Bmcd?T[*7$"Z26ٯ$ 7/Btdp:Hx71ߎj*Ҭ lE* BeΝ|L\uިZÀ镍ǿko(ЫfE2M?I[L6IoHM83KXs(aE0CX8!9GVo3j'yF n+!gƔ¶I/\!^y>L-T\GW!IȺBFw|9=]RBaf>Y&_b.+n+]^lL%{`ӗC(/3z 2w̑ iQ_}@_┦V{wsE0mGưȀe`D⥥V,ô|Z{T!]ٽўϕp:5IdX㻦Nvp:;)!H7[&TEz]P?ϊl6J\LpX)d`.~|a1/)M*6\Qvnot…,ʚ!C+_Ђ7| FX .#DcKk d;י" p[m3TϜ}YBoCu9| "/wۻ 5^`3w͐f]s:Ceus-.?M_lpXd$Y G-4%iYR7;1U6$B8XYy~(=|ۆoC$ff_+qx/ ^^`޸7gLhv]\-K"} B]+[b>͟OwVϯ/)zUVLv"UCEMaXZ":-ܫ+{jf>!ϰ#'G3-lE,$>nd_CnqiAP_ȯ>{r5v yĒU c;j]l,w'Jԁ.MP$Hڐ!HkQ\JutfqVy1ʈvdk-H; (ym;0w2nDU tjZ 0#ei ߸_ɀ[(m!F2j~!1vRp+ Ra;O^*'Gmwpvt[|n(}~Cd4E.dǜiO{AwJbIy!kkׯ6.&P;F mp]l}? 3UxBrt*Md0`kpuqo2dgv;XCUdr Ax ]&G |o{]nX ՟(p'FIxp_Е2IXMb|ҫ9< h1eE*UyH-܊U.R 0rh211 ju|xp$8C讝j!{,[ X0w%Rv!5MOM/HW.VmϠ`z ,RdLG;tc%WxF+n s6h Fy,7[Z^TUp:۶-JkM ^ء(|UxЇT˾Mvj"HVÖp/Mu4B$޺zPd~avqV=/ўmEDznI2U*s( dWr IiYwI]Vqn ֫ 캷$D|(x- U.1CSpg7r s2gV.n \vg\Ӄ{o2€8 ږ*39Vp{ufi҇C- XqQYZ|? h]6lF[;!FC ʞcQwN"r>-.3h8ֿhPd~΁dγ˺k6ځR+5^$s||^z/(zc ki;e]Z #J5MRٚ+%?ZYoF nxaLͯ>b"iւ)vMi؀m٘Ot }܊@ũ]ofOM鰮7N ˯澻_2r4 n%kf.1稺iu;RJ#.>TތJMu^)V#J\~V^cIp7odǻ#9 Oі17 t^ kQJO[F=gN9d@w|@{$xt9…_e[/3VFļ"Z UͻLcRGmP~M>u[IώgAv]2BtN}j80]ZNxR$7.6r" hWG+gMKb% 5ca-\Ȝcc{I'Bhi8Fn~wCpCzԺJ3$M_#,` op);u X< (vE^F_c`.]f*aK04WפWd(QW,ir`[DC]ReW' Jκ &hMV)ء,u}{L^i<ݘ$ԩ|o6Ĺt !Fߨ ҟ_ÅOe{Хu} 1˞C&b2'AIPJsܑY @m]24%+ۅz!`Ijz,\ AhD; kV|#c?DbUKIzOI^PW6WʟQ]lUmVV;IYD(;e9 ˂eɵUU7 ]`$_pp$W {WTyPrPv'7m ɶOn٦հKF|Lu:UN{6bxa.J$9Ƙmv+?H;la&zU_>'j׻K?0fKKɗp"P7Pg=FP$TY/q-=%@sԷŠ.cC[Xa-\#y^1MqiΓtCn3;&eEcrgR Zn1CqNLZ1?\GS6-o 8 zc߯B_NUQȺ"Y <?_ H~w ~ iäD^3ǜkFqq;#3 ulQ;@^YmXQ 4R1cq?nFIq98+?# FVm0nA)D.^H,hb4{Q'B7PQ-\rtsҟ}SrOPG6(,Nf",~-E\M{cKZ7%wlBuτfFؠIH ^ZZ=[v X@ϋ(vٲc:۸tDoucΔ*w7N6s)drO lv~ ZukPzPg7I5q^>=n7~YR+̖ JbPkbO$efhjf4Պk#6&a^U*hi0dlzw&}4m [:&G~ ~څl9cl]E[E"*x|{:.% |쟺 73!/w1G C$FoTt YnO!}(`DLVKpk (Tte뮔2;lHskEBû;չn>C*.hyA+l E;nNqɠ[0#ia^%'x=BLX!SXLVqGTgp!DoSD"*: ܰ 5YlSVn3? $M/ UPfF #Jts;嫱4Wf{VAj qBnVzcI}iJ E&;9FޗA `:\Pifn>-R_\q_dw&v{LlЊ{~v䵞cb!Ĝ!rphǍ1no׻9ݑcI싆5.KQ'Zr2h܆= Ӝ$=^ yA_ꬎlrt\T }0$&(UҠsi}O8"IvXQFt*Ʃ!RsVwˁk骧4^]3'F;ƐSiO f2<:}UWiE@sW ì{1F@M|ιAȽUsߣf3$EzYqY$0$L.&-Q?#x((=٠2әRp3<3*hC0hD?p^!Ǹ gif\;+' MSm{D {.CTcѳj+1PJO׍٨kLХIKTCGs: +getΠ,LCgK,lj~uỳ?h7}GuԽ0u+w7"j6 POaȣ{p(EDއ|K9ԸJ6bysG^A3k<HR˨f1ҷUgEْ:>GsƮh^iX|X{ zS(7oRAf펀oC{b.g}2ՐێTȔB70#"ʳ@.-%90b_w7̾_\\d.7iXqMrJEAᕣ{ij@QWJ,f?=fK "n7#qD vLdSqZ+aQ;8W[I)ꔲZ!$,FWi/ߡ,:"5~j3&2IMir~gN"cSKݵ=Zmrla(==PUD O%.&LF,iox{rm A+'=waRʟyRSPmh#,,Z̟A- Hk t~=k>rpg|aUDQ# *oF;5$J ӈyrdӹcSIEȨغ&Au ⸣#{ %u ~ңcYLVlV[rZu]ƾۡoB˱Aª8&j0}` w?ZZ^[H/mMEv\-Up`mخlǤ"0zVK,VTwΉXR W|Hڬηd?Esw)i|_,Fqj&@r%C sءv(8ZqM<WsW/fGڙc xP+W #QcW]6Kp9:wo:3GZTK@wMO]is! G< T'r̍0(~+]VI"cDUB*ijA>PQKjOЭ=IJeN.Ay^ p!c9-+GX eNC} ҋd4DP2YMK R] W}~_vѷdðYb(Q?CVZ'fZ\~/٤% <+meI'>jQw>{6aIR>xm_ :Fz'?F@lʛP >#VqMH/ŋ0x_ ;qVWYh-//bH:jQϻ>ϮCrV%r7M{gB`ܷ|ݔ=d]Zca+_ߦ{ܨYj}ȧ[-i{or=8;G|AzE*ׄ_MI -iԸCtce 3n{D߀X^ǖ5,f 4$/iă :2Z\0w`|^[JEJB7lvg]#KFlfZڜ ޞSla )Qrg~ yQ5||AM (:=%s$]?*!L&:8Vom/Cf<% a\E$\cxN,>ŸGoaY4#`_g?ܞ,\!.4qN 8ˍ{l.$49ڮtO#sӺOwǼ]OKy=?jԁ7 dڢupky3ڌŲ%[zunh?R\i,N~%|(aZ(}% /YK/UG] p͜s'HL6S̡tGXy=ڻE wfٝn0ZM.N\ B8sl 06jCR]b!e}ɢ a`O( .V|k6<>v/SJQg?eOʎo: )[~5#P@jח[!{SNԟn?і2y/v$+nUsa𜢠ʧlČJ3䒷,ly0+:9<@+3a:OtQ_atc!I~9*DqmޮQ:LT&6Oa Љ\u^B4͓b˪tU!wu73,G;P`|+بv5lDk>J8͋?-%b j4J)RüPG9񋈫ق}F1-SDL({i~5zlbH#6x)y2 %:A `:CX'x o Y|g?%Ye~tsFz2*R'D؈E{2:ȿ߸ ם~!pd;LPTɪyx Z(.:<z.\xQmRzMAd&șE!(2%Ta5N:m UP]b cյ39i d }i~dq$PUmair5KIg;uDyVLy6T  3Qo/Rp_gCbG)VNz6a"Ԝ2ʨ0pBNҶLpVXOKM3ƹlldQ*,ޅw!Z/8\桔 >iDBS%5Ġk_eҹ-ՠ-k?sdX!չ;/opQł״95Xkq0;=]~72}/BgQ?sf&NahYpJ1Ml!0WFtʂ08NLﲓ~LnlxS?0CIxsUYO] ch :8Oy(i_%~YN4FBF`Hs{vϟϵ)k0| dߕ-1x6U`skfTotjB$@Ѻ Z.4c洜!).u<(d >V$3|fvސ";M~c!5tBi9c}Ͳ!sI^͎+[~sV2 'D#a;aedGǪ:oy8(\E' 4{`1H%#mtm@я6#_Umh_=?mE|4?;4$Vs#*Z@T與Du8L,uF7 E)*ZPn[K略o^H{b1 P׶E' RolP(찲uzn#1*2Nw_qݛKgGx{\ZEL{[uy)JQZiɔ)O0$ w~Aoϼor0Ntu\5IS/[1K*CqV.6GJ#2I32B$9;?9M\2U`>ҋ%bR* yvΨ90&UNˬO"!\k|o.YD2]I C* c> [~YH6,!0akr`9N;?'+LP ң)::Ђ:n+/o$9\Wf>1BΛ!O枓OUU)UDz-$Z3_ATtc5rF4- حVej!%!Ή:sTWW(ț:6) !VT*f-s ӆf>BSa#ɘQL=?FqbAGC Z&Ѵk`ib/U1+R,y\%>_k0QjQ xs).6NB=H Zcj/@)6--=%D F߬j>SE%Fb!8k0hO]%v,EF"L7 F,v1 $U9GU8)mO;ᖚ6* rCp%~Mp@QtR8 n0~&篚X9\8+yeί"0 7s,}|?z8,=V0nTnwΏGJ:zhI X5-gO`4&1ZWZ(bEr d5idn7w,E,]y{lc%@&r6^.R|e )j9gC+z_h=9##}N<֫kcplm=6?䈃6b{^܃ܫӚS{ ݯa8Sg ;$i֖6sM-jKfVh[/v{2kb) i W!ݰ=fۀvЄ4Ǩ66E.yek\;eZ'Y9y௚I ˻h1Uup0|y+k{1(W^0@f|{9ՎY8JzEvᭊ}\ا{$ihy~ xotɌ/sEIswQ#a6~:&[`e.Q%u\hu$mzr-spSUABBW)sN-À?R>U5*ڟz+gxӕ4 %HƑ:ZU**L=3:du3:H^.('[_U̝!h ӕ-}ݕelp^fhOiCU10?a܀Jj*0E8SN(@>IDehdxTd2^CI1Iz !Q@9LR־G:k,g!RUGDaLZɚL`/M~8/%[CY0 ;Ptvᇳ\{s)u|&l >/=X%{]gFgHhOsP>j'5M' cb{ڻyl Q/΄>C汜Y;Y $ped˛L8>!S7wk/pI3G206ƤESOK K7Fb7(9C~9@jh:9kɲec9/o1z51B(D4ɔdTo ~u֗&JMŨXyCc.97Id!9DZk5jW@.g-ʅF,TQldlP7z{)m }r9.eƉ3b~..`\E'-7ZPa*Z#R_izDlb|,u5ۍ^ pŁ1;r!ұi^9x(bз6;sݼ\Zd!彁98fΥ5wp%ǮVpܽ!7@-lF.Cp?@.+g6ԑa y!/鳧DMNX" }qʒ(nnQtrJqxALFΧ"Hΐ I"N?쯰$ݎA DEK@fY4[,X2"LOؔF=4QrjI<Úx_At ;Kܵ{!#)R_u7r5ft3 uS@ ZI_!6f?v14i$V ߸tP.1ZN9W-Ze1V*毣&7a͞ hm@>(]_BN\ǜ38hV{het4۳` :f$]%WtڙwWIl4 y>J ӁsQ2w'y#]I^KG+^SАC3&,A`p PvG՛,Tym-YL$箯J'EFڤ^pi{>;@Yj^(,`>DA YL rQ6W'7,Zek󋣰RY6*>teǸAV(ƒ:E1fӉ`eI w'K:cCU8XAw(0O`kK%[Z+Eb=~M@L(Z!w+NõhM.0g4q& gFHbcXL\ Z{eFrщWTx,@­㲻/C-v+iwQU!]Hv?T% Qg58ɂiVJW]꤃28m\I}sl FTH@,yHӫ&1ފуԗ s\.5W?lW'#ՓTKMQzܲ@{2bD{>M2s|S5~FajkE5ccBOӾg"F:=']gq *)\a \u)=4^WV>K$ڹ^!+* As̎ID52F\\MF9tj՛b#&r?ğW k`F]'X.7۟E$lg`3ʘfAxJ̕wX3VHC=(5Vq$Dw\{IGD] x[p HwNa.^6 ].aBi݌Pҫ/spͻ2Ur.u9Nރ['jsLJF=x^ϰF2޶c?N,n ˂᰹ZJzN\f:Pth}͗0l{do0rN?kV51LJxf@y+E2yogctCIj=2ۘ{>Zl1L`v,@|6}xɗBgý|ӉnRR鉅9IHZ2)mJ+ҿT KBA;{@'? dS2V_50( U\X[1E vZŸMTkh?9|9׉yM^9~"y+"-AF Ue.7 3c#=綍藆@'_u&?ۂ$m LY[P* rPu͏*hB9/vzB[GU^)-$JQ-ZȨ7M6x[_}" ߤxeYb:dcҵZE"&E~Ǡk ˬـ?4W:S (Ѥv.k[h'`oDス7IoB؃7{)qp`< 'ˍzV!!WWxEѠgHهy"W\ +>!3P'^O.g 41Cqa"eYv A?6z4Ke{?ǞeMIm3_e\,gB& 0"<";m*v"?ݞQ*kH؇vIlr'(I (x[.K֑$i&֨4[GDitEN)%9+.$+,Q!~!n_|疖$.(Kr{(V_Wyj8"q g-+{XpB2ӲxHB7*1Njx0]VMBi-h>zA%nݍ+q}RP ?BRڰC~2%&n'}bBq=RFL@t 9+d}M{8c?7S\Տ"q1ܽ']?ɒ6O\BY5(&28[cD`msI:v"QmF,?:`??FXlj^t?S?ƲYVbwTlv]}Uz2QDƛ^#/O*- /ddC7^Edٳ6(+1-2j/wX{bCp?.? ( j|͔&Hn"D|.s{T;M140Wa޹ITF~ar+i\S"<.o Ƕ)R8lhrlu %6Ǖ%9ݽ]4o!HWØ^E&96C.Ϣm3T!(i@ELDc0鴶ϯEh-[X.2kV j%{αLIOBHY'TmMNK{g)56E|AM!U#ͱS!FXau7TdP:-wODu  AtdfEas7gRI૏9߈~"V]EwGe&k?ڏ^&gj ^g9Y)W)aJgkxIi *kq+)knw!ax% D8}gBb+r]NG,[v(]Z.q{|:-B(;h{d&ժ+ރa+ =,wy'H\Ӳe 3V+=xIݖkr \PTfY;{*[[90Thu BGza%بjuHmW1!_F `BK{RP򚮙W77h~ dn .dkّ;(k ۵)C knч,EE ;BX":k>)qK/4ǣ`k^P„Hw[ɨ] 5a [!kI?:-q{[Ә'3.@zza{+ eE^/.w۶_I˰}ϷWeG{M>%z*DձigyDF~=c?(ثh`FNF76T ¶[TIDQJ$P@OcSGr=cBx1`AuQ =8~tbf Z\VY|Uʋ$U"h飁%/>y};1}+J@`kqFmVhd) ٖ]j%+m7|i?KD BS#6B ᄍRLFpfHN[VBRI(/IWb:YsTɆINb(2nSdĖ}jDWؐ1\ 8M>ɩ 1/x6:]cK+YܻJfԊ8|ß68rfzyuWspaY Nh _X:xZ9β303l,N13q1ooQ||.k(c}D{Pձz%a.mJs: ȔF͖sqQ8R&ɖ2u!eǶ"H!8aHdx3^i,rI?״JLթh[N]q ìL\qRdX`[~ʆX|A./31w!11_TOIH}(KWXPv7Ӌ!h#Քs"I*elt?Y*mL^" `ݨ3Dp0ơ5w%CQYJĪ"dLEkR'({㌹NW4> LV4BIBeї#A/ ssaZu@pq8w'ϲrƮ3Vƨ eK4%~ѓ%ޥzL7: Fn]6[G#M:/]Ip %Ecv_Mn"AlLX. k`$t\bNqB]4wp3Ɛss@YbQVu״ٗ<7c&x(2E\ֹbDRZviϴ*jEoLr\9%yvfWN:gV,Ӥsl}\0$R<};MC\EB{?-WyHsb+HcA=X]{k0ځ acvwkw~zW+%AejwFF XUɃ7`Qh3֡:J0zU8]2+TgdfuZ1A015`ncM;Em]%N6n/ _ze)R{T~|4J A-6YO\!D.Q2VHo|NJMhM4;#cy9}Jw#km{7h46ORֶIL+x3CG1)!s`(>_QgSU81'oGJ}BV\Ce)xK $AnSImA/ʵc({E5&fIKb:w٢,5Awj7')RhܖTŻ8d)e @KmY-jш_]uڜ+.3p7t$5$G$C"}mi!& 5ϙu) -ϩ\tB;X%z\d*vѴ^PEۈM_~kq1ˬ暂^%gU.$ldj0i#tjr]=Hח#B)$* ֎97ka wPS>r[-(L?!7mUIonYC:adQ1,rAL-]*64ĸ.bP̣:Qx& o1m:zr\ҟ f,lR#W1=:)O٧Ka~$K^ ZoZ_GT9GjM+(&V \w$9,qN֊ 2(|Ҥ-"z釱 ͻQN}]=8)pj`ZE5KYNhTE fk+R5=ƒ9\1bw.GpT+=n;v»zRՋ}!6{ugT-_wEA&i)8 ƍF"i:d}=kdU53إ&,hQ<9kØoBZJkߛ[xbi!݀A(^?9)\᰾_9'̫F)_0Z쀽>S0\jQy+%uF#l+@ZtZ`.vbBBFb[p~뱌nsC#{w[QVeQȻY5p`mW7XNZ9ns-ϥ.! N.,VwABe)emv["t9L 2N5o0#]8 s@ 4 H5P/L~/:ZluE18Ptj(ǮCwzDpq2RɏMlKiuPa5r hBfc@HτDYyK&$sPatT>v%eɡsJ~s: bίc|o&nb0l,y@}G|x-հxUO%)au$5DvӡbgmDž[R6wq_C\4HE"gR6p>&)lq%!-Bj_Iܯ ³"BܸNu .}&5RpƂ9lb^ V렑~) GIsk:^򏼾@| DL)lH*>}EpA _\=qNM^hJ{8zWOֿhļS*c/3.g'. 3؍B*p3fJ=tg7ƾ,Om_1Pbxet{ϟ^FtYEvhA*2I]kosXkMF#"4^W" CFtdP jB#'[#Ҡ5+P7 zr5U s 3K{92SSǥ'nSKz+]so)\@qfe ubvE̫֮؞.F`EgY+ty wG>|Ú 9ȤHߝJOrDi_J~6Q5r2.:ݍ{jEG٬NObyEou;%񵏨^WG2#86'[yx*)ᒹBg)/ ~rG5)cl*³+c܈J5O Wz2IdRt=HegiJ6k(Puc7 C~Qm:`KJJq,RT?Y![H8갲N/5F׾>:k0F ;fv;c=-\5ԚY;z t1-حKꈦ?ԒΈڔ,t_rTFz7y`eyc qH7^Oϋeս4>ycw(G^wηL|kC4ޥi1IabMV'L hLJ&@ =LU؈鍞EeE V:if}pTުxA. DU$])yqlECl4)dgI~xKJi. 2C7P⑇'}9Uї9(au.D;j,A{l[ \/aѭeoV oO2 `ŒM`ֈE*Q540raU S B˗wbH'G* >.Wڐ@3IUUwN`q}uyf0R;s?kBEUJbWYS*as x*`?Z_JhMѼ׼b2;e%_Ҿ>7uH%\ 9{V]kStf{UrT,K@ :v ttf$T=˄j,Uf|=]X1g;Aњ) pOb q{o'B?>Jo!ɍs#$"Qx }k0+Db{c:ףj_(?Wy:/w?%VJn,ϽWp8"=d9 HxL5V#޼ BѨn@̌\Ato>F#Y[)OWfˇj2b;XX`+=lSbah(9#t ^h#15 Tۙ~Ռ0QN(b񣎫!@(#!JSp+TƤ*k>icE9U-[0>[.7MGOH~E^!c3%Ý~꽢Ɏ/Mfƶ mk'-f]fpZ"eYXs/b\F@95*Q [9xmYc@NhBcmp8mIդ~ͪ)|9Qe=O5]V P\N?YՍ%^U+>s|)s*\t$SSFnE-(R[hEօ' Zͽt!rJ=uHgӸXy݂Σy3W{`>l~7"J\|a/eXY©TM!?@pWRxөdpIoƆ˹/l[FSQSEd[;/!%N|B*ů'bׂ%;,I q#Ub7wRQcӗMjW c8Ҵ g.~2i#i=󿝢")A#qC5'1١f }MDƙ0kO~S^pUɬ1}FH!6ޓC.޽MD<*CѥK:@RG8<*o M9ɊË{ONeV#؎xȦm5srgS.awbL`VK _q]%"rڇ;1T`:g)/,hh~yGğ,V9Y2g`[Z,c*س'I[!03ݳk* Coo;x #6N.>7=Rwۖ,EP\|.I.mY9+n8"'a7u^%ae~%$މS~GMa;E ^FmW>O'IȥMȝ%ȍ_i^q юGH 8hj~>if|lcMQ]%hq׳w> 2a&G:%摇6\yq /'t,E (浽lg'/)g?߬X Ep=XߋlC87X՗eh5OpfeLhɏ'V1{mpNB KNZ,1_4[f`{IO%{Ueثr*GIxST?v fPzp37H_8a&0lmRmxGT3(d*fBܬJ=" Yzw8d q>A_kv0ף|r,Vk8ZLފS/ԏeu?ߊDR[YvJ~8|5žfTl_>ہ^Lr޸Gǣ ZZZlX@|'E/f7;-`*uol81PWrt0Hޡe QGv QZ#¾8zEςdc4 ]t`ya7!19-rsLfeic c~vm9p;kOgj$6YO fafNBu0,mш.%4}5?ݽ2x|rtaQs[ZӳGcRz'/V;gy@ m;GJͻ"C8{=# 4/<:H(@?zC ϞrϮ2T;~L瓮bl;#LN%n{kBV6NpۂKL#xנ( i(o R#ZK]#KqPm(<_dc0Ա<˰[+M6kGͺjvI@@0!\!A,[!9]m·Uu*ʼSMesUݴE3PM&6~%>鸠lJf\ڙ<  R-vl@`BЬp{U> 6%(.E?W"'g#ܶn*OĠ굙{f9,eۧ䅶o) ӫ7G5jI>Z<;9+&avzeoȐÈ|JLJQ#M,p琅a2kKٵ+ Mx;\N[K6cH{v}uuf-Mg3 wBQK m9O6NnL7JUFdG*5̉& 0uxnn/6=E;z ]M0q ҝ(iOb0Kso ogFl|*Q$3m&uB MX*: ֟m+&>,Z2|WAjYoFkƹ4P DkJŋCֽ|"=|IClFNN7Oݿɧa3 ]d.U@`jgE E>WMI8YwzrFLkn v$etٶ*ftH_8+C(+~BRV6g!0H+ƈW*2C͝bgl@|jhٙj%%zd(G\&krnچ Pn Z^+[M3oFIW<Xr }>ڞ~!V&^j4q =C㌎M/qP37qSP;e*!o{_rr"He1E1?T a\h ;묇P׶Ñ8`+ovZI9l0:˓%XWj(ꤜ:l@8Z0Ri_kI¸l?hl$¿td/}۲񰟓 59i%p{-ꇃG͗+tIc '$A;,!$EVԳ`îHj0݂xJ0% $3ұ߅ W~&1AAFސhu'a?݊ M?%ZHunc9j8#ZVHr1#ֆ5޼ز}ؖV,)kuk4$ S\ Ϙ}s* snd ڌϢ~d[׻}Un yg|%븾RKŲG b'xvgI5}2ekKC!BhvHCl8K%~{^p/CF8:z:.,& 8pBWVh˭zQ3T[jLI 4 MhO0zeBܤgnWy <*Ѥh"+LY yn7p&7ؿ#Lb=RSVW@9uhAPʼnbnYЂ/C@C+!AyvRxՋdlBfhx_phR>Cڑ\ ?u>Y JףUt E}p&n#TcəRFGoV.8V77&./\b=M&- S"׵S2m k c!e;a[ ~ [g~+G-Q ^LG^.X#Q+Hۓ.[-DƇpύ2TL_I_NTnjZy^Z--ˊyI9l"x.E9}hS\Zzd2@ ŀ~>b\{p,A7Y4ӻ4;NT7MgKka/Î#<+lUG7E6pHF!W9?Pa4;(;2_5FqKgZik2_[g`Nΰ7}^$Z~A%HJ"+EYշ_H&Ŗe.!Ң#AcFX r@bv{3>~{yb8@l/3lB(UApoO2j>.o)R "mٝV8TOr*&2[^_shI!w]mKzr1C:>O݋ #y̙QD:)HvX'5GB̺_CEY_-[W~tfWj\rk@ٶ`&x^gi96I[i^6IJ&)6}, ?R0g |clynF_Q;PX%/;KaI°ZNɂ;&FlJ7'-3u36P(uWPD*Sugա"^, 8fcX8鄠3/!PقDԍ&lbaDdH]N>UxV` kU@b!@ss{qq(S'+oM?PM1bfޔh6m[ ܆6JiG:O$V&m0&ea$Lt[:g8C~*ġ$k|RNkɨmq_Þ&N|KYGذEU<7* cz7zIJ 㾟x@N\зA%0A1O1?s>0H|* X plL!8=g>qO,ԇ ("@q T}$?`2\z$v AI#΍OLa,]N;is|!D -eu9 "{ u-J5朢9$] ;wq/R$8pp T>*.Q\ ""ܠ;Q5 aMa[6k!Sf)Jr#+6z=_ 3rHANnݸn1.?^<>mWx] z}Iuَq$$Ȼ;F\Xr:ǏP=ҕrՔymT{wۄ>(6MC}ڱa;~KQ _8?VI*{oH՟V=N P \-ut-sJKQCk}C[Mϯ*o!GpURS]"EL\7c^v5\n/pdƕ>{4Gγ5]t˾ρ}+qzoPWmKKَSCsǾ%s9HI CZ}:isؔ/G-Z_WssH% y[jl9л¡7l=QwU9 d k5RX<ˌ۹l!~5!۩5MusOzuI?>IFuX+<"hX~@Azq3ӔNM)Qkۓ%Dπ}mc( "̈́bv넍Į6tG]0'ܬ/53' v  ȮBg#B̸.8͒-*__KO$;@CV\ÿ@isM$R7gpT^uy6rVsyPR$ʐP{Klm"ٶGDlqVQX8-L9 ՀҾl[1Ex?QQ`Lև;i='KZf=)iZ29Bw\&'0f*䑃)jr 6Ugkg,e>;&MrO^t9:ʬ;"@JK(@=Ϸybwys b;<>{Y:L:0;4-|'-ZnclLذFĎl'8AYxfqV0Di.(}PߦY+i#o/QDԗȬ:C~urtw[Ηz#٘BjF+&!Ƨ>ڹy|w<9ۜO:'"WRByvqN Nݶl=Fm9w??aBT&UFz^D&Uv# >օWhU=M|b'RX}2{hHȳ J^(SW7dfca6QIYK]mJϱ_QK #pf1/rWM# u,#/IfU< OWl\Ҕ<L$^ Vhr2_f{zѧ$Xsrm0%EZ^ Hxڕ>xKycMu[k4xuBY 뭓oM,l 3t EY4D7q#4) AuV~-ൻ Z= M`\"?nDMy5|waUC(\o!ܕ=x8sEwa+r7N}LZnK΅en j7ŗZol.gOZЉȈ}R?2ʤ$F7H Yw7}ZOpzl}-, YL''}V#Uѽ :{Uݮ8UF <5^~aWe^HMyd]BlB<Ξ}a  h_%g ^uitĸ<+ lb*0UB!(KΜ(a!Cc#M>imdq]{S}4.ӗcIzZЪg;ʤPxk5Rk\cs4U JfcEh#3LGndot9c67D!fnr{*=Ve)y,BjwK9'+Jjl,p(Ρ(<  KcLSN7:ex2][z9N~-o}#攝15فQEѬo5}uöYXߪ4!%ep^ t3|WYvC|928#tN@|+CJ @xX'px?/bMbJ]3MgBާ3 j,e_8ğq_hbDd!},zQXJ  lX4\*nstDA˂]`v zZcZd. d[frލtjmK6I[~v|3z2CvD6R јF\GH|CWN찂F)V~&K]N=U赣R<^b /cG4 ]!2”m )C364jwH#95txV 6/#C8<_"fJL{_&,MN<l*pۛ|4Ɉ#5VNh`],fD ӹXsR@`bޛlڇK8%AVQJn=,LJ+œS@K V fef*$P`F|PřdDC!?@(NA9a$WfuQVd]4_1pn_tdfAitCݾ901WKcmh$KM0]z`_AiCG k/~Ħvah ڎϛx'iCn#n dף}qAUqdxjy_v=|a&nVQ?9}:ZJWټvx_Pˏ7c0rݓp(iov}BkV1ZϾ Qbs]> ,UDljFNe R?r ETJm(?@ JvQ$VɸH%%])ikл@e-j=7\ cCc$O"𱬮0ԫb\`B:x@'axO246nq) {+B㋵Fx˄+f)'cNXXDF/7g^.B 'f1I_̩~\lME:,v5gQH$Eaد;D6o@6Y/d?'|6/ .k+jrYsh6ORЗ,G$j`h >y~wd+w4Hn*?jWw+MwZ(FvɛS<}IrYU:7wnRQ?!aV$6AYC$|,u0Ik.\]k'-Tbq;k3պ3 թ(8 Wע2Vɵqj~=1N7ԡ{\B5*+E񢲡ѻs"aFhX[׌d0*U: .w7r?় Q9K\)&2r^ZFJӎ5nZ/4-st>)ꆶۻp;j "biM,Q3 l"Ph+{+ # F ÿs=?GZ3l[ 򼭳Q$ΡAJNGyDC{ђ˰2pAlY8 m1DG0p2FTo*?Ӹ{~Nz)#ѼDDk2V*4EwP&; RӶ< @B\ʁb*4 ӧy^ OBw{e2~ OqİÎ :y"%2 g?-qztg[7r2teϪ3TB\_  F˳"ĥdn'H| $:3GʦV ޑ{Kl#̭nI0,J%++p,vH YsVǷ y2I)E?K:S4'Ϻ<\e=z|L7^7 ;β],1P_AQ/3- khxA& D8K+[ #[{$1S+;E9Xe uBZX 4т:,mRR|Ɇ Li0XJ")Z@ Ѡ3W?W2cj ^G=P%Bw <燐BEm@] z6t`qier$h'0ObUa[D*2JzeÞ̝2ohbC@t[_+KdB cHΨp7jn&՗]&#Bz/e3{ŞsX4Rydf  ʞىkf`ݣll,谪Ko^eThɃ9x?D~ G:I Fv7ϵ̠M_@4y83`/uىf 5j᰽(39`*%Y -Yh/y_m;l7MD xˆ&BN/(JPHX{+H@Xe#gl su7AXB>]_e" ()ssW ơOgPtxӕs?Qf=K㾫n+gO]~H)Ae56t)ji2TMrzT%M}iBz[ q}yfZZV:msv)\K`7:Jӎ(:͝eɠ2&A>KKې{񺓌-"6o"Eٵ*QcidElj\XTQ,)zu%dIhy")#p626S#fŀLP3ln,6ї$1@D,P`앶S@bnLs/_gǪB-lKXÚ~iגR=xVzϻCAA]j'j! L *mڱT{m~*P H4 6hq3\@cNc? G$(is6WlYj @/̕CxLVx g5Ä, <{k?Y &$j9΀孋Fޟ+Aq䏍aa8SBy=hyPX_4N$GӨ 2%=YA @ۘF'ɰD" !TF+r-%iQ5a\{5\H=K7$:w >}-3;Tnwlߗ,c%9Y'|\:趾=ߙ(djnos?Q؛φA)WJԚTr %oLg Up{(^^=Oo *X3ݣ)"GP"{G1fC_Uk,"܁A3Y=  Q ]e@S20VfQbo(CP8nՀD?!|t8krS]f_)R h@dD<s4<]sQA%{Q/Xq ~01.4jҶL FB ;`MbLYp{1t6_=TӨo.FFnشIi)IV:.NJYWvdpLkEfy =W;T g-!~X7y+̰FW׷ֽ Ba<15!ݰ\6M DMR#G]zlP-Mm\1ZO.?H=3߄Ѽ3U b,0**UBIxJ}:DR,Dպ_:+(ܖ^0(*pwDO6&w0 eq-D\ -?I\i:{0 -ee&6B3s?Ͳ|g :Y96mZ?h?aF bkFLOyGwڼ[Й/+Πx\ &uH*j`d#Tӛ@Qr@@NxA[}H!09NP? !DEgRYk[;&4pU!iN9[~UU[|"|1^a8cF֦L0"+K|ib˷YRnuM< <[bz }g~“3aۑj}.-ZJKL#,i(H< Yvf?oEgNoѶ]BsɌ~ JrO|Wf|9~+m d7İiǃFeHnհfnBßfku9ОViw p3Ζ7vcyGGUdT3$2Z9Ռ!O l cC]_|hGl8\gJZYbÕ1=^k^ѠHW-&x$7*7)6nr$26ʵȆq]LO cb4} >5FhV w:O}c!}NMD{k&"$i` fо L 1PCGo JӮ34&ceyon1<Bxp=t뤆w@wQP <({əc*.|kIV+r^5F֛aߠA^(sg&Ei%} |7]}jѮ>>b  K9G:n,`9y3Jf@xSz6q m9ܙA(KO0LH-ħ._v%-H'7>mm(\'$.63ߐopCH[{ⱝ~\:޵i~^q XYb6JYcKo9GRlE9 Q2%J5rbY.a)Eo[$K( v9y&ۚXgB'1QPr 2_jv =YϰUFrޡ؝HjjIgz3XDD=7QN$7"}z@Dp5r1:]~=qjǶt碇 g|s $)P΄@eoTaɔ$-xq@f~ t0*htӬ"ͫݝ ZXysBpV,-Tʑ{assk6_v'fMmTG{YѺ7xeGgHV㰥ӟB)]lo428;1Ze bC_dnH@5̋ y!i  Nb04T(]y %{z{gs/>,8|$.=Qz}1OnT~dބDImJ yaaxVGGeTi{y*jV |G3r1wpRn9@u<2@rI+k(@ȧ[<-4UM8ܷw"aIegܿv:MM"ZykP )r%0 P2+KGyFdVj+8GqgFD_ kfNUQ%Pno{LLjlPT ^'ql3Pn?'LeB`VF0QwTT]Oz͈I6/y),x &A;M_M-논"/OW ,B,5yrrAI {kfe!^6~ 8jL"Ô:ŧ[| 6j&ڌ{Tz5$xhw7r#-_1ϰFbk:LVi(uDk^\߂ïWe'd)}5PM2Xϳ8XDʺ.' 3ʨ fOu]l҇P`(6Vs->bRݲ4a/lc}XJ;at\nd@1P/z奾{.xwùKbQÿCg4ϝ+quQ oN$@(69>ٓ&+«"g#;<\5g(4QYrܧ:ڦsd}UO6efyPF]\B J27%al 0="Zm8ϫ~D.&6d>4Q;VclHZz!JK9]V.􎫇ǗXcq8ZFNFi4kP-oV #n1{.C2(/A V,28rT-~I+%-e~hմ2ȼ=@U68P2"GvY勔FFzLSp[L Dʏ}!E w.S^Em)7ޭbI>TpXr O" Rǜ 8s_ɚZiEefVm{k훅rtfr tRey7t?Trw߅EAQ_vr_KQNZCę,Zj؟[ @(Ȉlلqwvwӽ# zH9t_|*$)C`s+6nIa&&'X*:!ASyĸ Ib)- O( a@_GnRšxʵ3 ~VԈy۱ _`վOݱ7La.йfGIܥ,(񦄣x Cr%/VG'DZdYOƤ8"/' "޹fcx)Ko"D|BiY=dzU1+MaI*.g{ 2MUscl xso 57m }̝ex?_}EDjt1CV @'H +1]³#0i-!G0qu*6\JPv̒7R=J6Dh6FuV`G|bat4.i/@aQ7+i&ZAU#^JT1ܯݧ(pM7OMXq}~ܢ[^"r7|AѣM*6WBnopdEh5K,;.]w/*@(2m^3[T|LY/FtH0q9:T.xZ haMUH>/#߹X`=ASRh%q9,6]lb>j$ƾ&[[Y`{n3$jbY]u׃mzO´~zÕ2BJ,^n\?%UK_}94?^M(+@σjC^Qa)GX>MD[m;IM϶-eCrp?ڀ:ԗ}q:٠̐Pq&ewb\Y?# eX̬|}B5G&(*ўC,D}΄T8c|1_B ,dlyˮKҺi@Z0vUM ?nQHJVE8x0l2ca޴p"yƤmss820+e#Q…_  er7gŝ tVW=qIA$%K(rB_ {T@SIK/f~3&x@6=Ք.X V353m9SΔg@uR'yd\}PIwp=3v;sC֣\Q;[4}4ax NNO&"(E ΚI)mOrd\zQ'ikvLj~A w[bPv._7[l_pe3QL\&fUmkOIN{2pO|qԐLx]FJ0XOxdϽ8n oT iտ~?aLjfdat 51‹o[N\gt+z /vBM0^BjN>ZwYTĝ$Y_*"0 48Y) QPMm=?z膤rf\}zG]ejg+4:zRԑ"+QjO_Dln<&+ Cp]=[鉅u)u6ZQ}-lGOwojʵmX xza9>l 1LHt%:^GA)nqZ6*VBh]`(&dF5Bolx=f`Z ST:k<JRzܻ?e!U&oEJ=eT[yFD7|S O_bu!Аjb$r% {OO%#%PU|UNMЂ)0pjDq&p{/bꀤ)#4R/1c0 ӚD7'FuZĉdn!U: V(x̞rL'P;XKPxtYV]Rsӓ6 u= Vϭq }_LPb`>HX3{[,hAHf_F!_q~*mzĀ enH0hzWz$.r&F&s/j8%8V0LQ9b5swu\4WX،ZGfNLQjWj^޲h5Ҥ{ 1EBD1zI^ >)MۖWal%\Z7֦'4R ?tYOCʌTɂ:nĎqCZt'Йtj`&K42j&k 7vfR4|.VkؗSx;Cۭ`[,ƲdD[kJoÁae#ֈbc/Bj'h%G(:ф;tE.toJ %Jy≘{ o ?P, S&@x `D#MиqR[p_vkmxXFt OYRWxP{?YkiZ :GD [|1Rpyq\LjقXr"/'NDBP1xΰP2zG愎,@%ɰh IE)?;ORX,-Tk\П)̀*s6 Kmh} +EY@P1! Z[\d$s}$l93BYTPɿo4kNw ݍ{m_K:Ԕ G'΅_{.9tpNބodNm.|4*Ҵ-9Yr| Ab|kDt]X2弣j~'_eO@j- Vi@>;mxQ%U[%^Tx2׀`.y˷BGthFt#H_ դS.}`) B $w]rGV~ˆvtdg<*gTe*XUQe/jfq&8}o9sbQDjuf@Z'V!,ʄ}5/яFWQ2z}QEBXj|j#CLhنǓQ?:f=h+w(%*  4sE 7Z]Q{KFt`ɞ+G%~ǀ1zₜB|qXĚN7g&(߁]z%;\%FHV׭o(˜>&x%h@#)/4&E/n[kΖ5cwfJ&Wd|TCf! C"cſwa ؒ P`t/+J! [NNoyTüVjז/XOa4RDHdJZ=5.mh$d m/z[eRz~o)4ZQiN [(DB3Z+#8?PFFn‚z茨NGܮ*%e6 3L88#rK!K. AFB-f/$D2gm~ԚăHcm(%8̜xg^I<\/\li Ӟ f:3J6#|8Flr$ N*$\4hNp)YmHP>X/p&n-.@o{,1- ;,\=q ]v)Yi`Zl\t#Z3b+xT%+un?xL'4BwQp )M]n kwuECʅ+S-ey_j3qe,J=ZrLswy3_i<~0:svZ X'MB#׻or$ KLl b]I7/u%4l}˗Cs8rtN /Qa쿫 q(\'rZBH0<:͑Cl׺`џOA힧,nٿBlEji𵝸Л*c&\ QDO}F'Я1"řWsuUSa}uW|Qn|+Yf#I0<)j mx9FM?Z­JkK_/,=muM6dMW[Xt0W){T޾-)]Xn՚<Ib䬺=QnZt̥bSm'ڳf чd2WZNt?A9@k‚Xܑ=b?GI~/smz6'~]Z}f-a@<}ܖYlpU=m"VAНZN{W^];3&\B0xC-#flXt= *+LͰFF ,#2*#[9:ړՀU/b%@v@&"n횖)@!-genMОgfKRDEkUG˫մGljkKKXcPp ]&7PY=&ft6'KW.hxqoMYH:f|Z]KRy4=De^<krяa3<7t`X7)%zy1X`dUҧzHG]'H1OO2s^FKq@n"Js x*)ޒQ:7a]]^KST^ eS#X$ Xgcb[A+w}k(v2xc 642ys4C=|=bЋ?>KλJ'xcFQ[:ꝍkuÖ=֡n;%~tN!ͿqhwUի΢ºkY{$1tu7 lK%QNt|WϔWn~\a{eL!/n&6%ZTYvQR>ñ4ů:7.WlL#frO 1h1Aͫ\JЅ+,u_+[QC83'j`V u;N۔aM'v$I/HPgUwFK>ƨ..eNA x^=TdZpQ ctʯTȲ6_%;{QNjS.9O#4D0FwtrDHwnR<Bu6 FL< iN[ɢթ9)z|\L0c0f=J;_/" (ɰc{tvlgSfhTviěY&%ۀG^;ˑ 36B] f)5HkʌY#˓Ϝ,sMXj`zp ^cq]]QzE\J <Mb4kSdϨ" /Zg \fwQKn]e[q"'!9ItBkڱܧ*bOc[)l%f!/@| D~-༅(2`իD$]Ӂ"%H^?s^@NPߐ3-O\~\K "| 0(ڳەdL*υ :z/Ӿ$ +Y?p\Ia! jl[~PJ+/dpVvtEW댞"MFm =`5:}NqCb 69| E$ipUO*A8~nagF#jt/kV1cK>p|:>T9]һ}UˣRbӂ0!v9}vp\jq<ƨZ܅ ?79|쩔n=yd%{C-ٝ~%)R~'6DŽ'Gi.t&$5/iYKc'-Jt>셉 J &&n/I:m rXP2M$EOT]ޢeJW&?(b> ![ F2χtfaUq|<4{%ihVH"]{5\ Rm]>f*cm_`8ُ%Rl ]2JYz5u?[z.8΁ XS0^{.- ڇbs؉0i33"TTa־u/%sI;+0d c\H \7P'EmhO %1 ">)=P3+ !hQਫf8zhĂ[)+͆u LF _v)i:H:3\I\ "3WuJl$f\H DLrS @cȴ{^wM{_kgԼv eǮYhE[FMyk#7$?q*ƎR Cq!t45Fޒİ'1=\ecU2X^f=xe1olw[Sy gL&~App~]z S!XtJLFKY/} \=2<7y~z*J]CBvlo6]*Km¤m8׾(XQ:hg*l~STđA)w*ۊ̂GXX[ ӐR%E7 >#k)ŴM(m7΍#EJH-tNx p?Q-+i&@xt&UgJ2,e :_Mfd<*¡V[QLm^i7pׁB#?xQNGL1O+-[,/yW/cIz`/;LųuNU5tc=£ϽH|\3bn-">ߤ[V/!ٞ/ښGo;f("V㚐`rr1ueJٍ.gC1VQ{&aE{ y+J.W|Ce݉<HӊV;3Eɦ)hl2A+|JT%|/ vVZ dۖ8δ>u罅R\PjPoh)Nѯ]ڽXw-BiC#׼醒@.ᡴʔV| 0g\+N! Wxј~ ypZ2s+^[~C~tpq2"'K%gKҊxE[~ǜR1l9DrUh q͞ Rbh5+ػW,&T֪K̭)ߓ%Yp\H80WPdM-fj<ʚN1jg}Ԑ := &+-gE3eexG!)]Kճ)TpLtg9>1zt-vpT+nj]PFPO}~|B-eRWdg6 {4,<e8*E K휶+P's3KP%=u/] ~G r`Z<G2H)el\CHmC0osL\?t$GHScyHg?dzn- e~],@|eX|/R;1݄R H s"0C}NS;\LA|1P M?;'/dIk4.͵'6- E-O{L}kOq4뮡cw\,_\2W?=01OLFXLJ0_ s3KȀgmGQ.k,R(@(FWf,WKO=[lCx~e -:u]ٔFO.2hz8A-ӗ`P Qfֶ9\O'ST:=Za(bq 'b0hH r\HҴ` .UWMCbp)Yg-n%+?_*'? ,RBمvca9_FS9-)\!&x=xQ2 'uRUB*\ZMT^8V:&B+RgU"lS)h`3)&ӤHqg[HpR^sQܫ2D{[GD;ic C@LSv,R{6^E ־1@}UP,A9y [ٹٵҭŦb_P5'.̋/qPC]` G &"j 0#k`C_f.V3["[ "'8dRih=Q04qkNg\VS5Ph>>EikhO1&Dt^ '"-N)!%6̇eG]/wBлW0)PFp1x,GW7fU1oJ>2+xJM;uM(Kn<+7 TyJfn3e?lvqrrc`h0c%OUa61t~+!)vcM!JAMɔ?K LUOu6۹#?M L%"|VʽH9ǕU䯶 q\Q@J_|ZcGZ'GGA]7vvCMV.7#Z `ED #C+d+X2],y,-Bloesoț\Cn"CM5[,Q/!{JΪR[$4>?>i_E/}aHSK ֪DZ, - xZMzVZsd,3c}J CvIM=˼5듹'8I{zgPؼoByve7}NZ0c*a̓x,Vefⵥ3xpvF@_v=ԃTn1 css0 NW2tR]r\6}1qh.*KUvYR:_h%pd䪮CR*O#eޝBCJ\5XtwxijI5A)u;֢^)'Aɣ[Q e]aqxs!, (Ӫ;.!R)jPu*۰7)&MЄ|Kv&K،7!T!5jf`<_A 3gUK}t{C{|e`j؛F>Nϥ/AkMsF&)!{G:+G3F!] -i< _eI!K8eV@-0ģp.vί#`wIgYM5or(:Σ},< i@3:mAصw 7^0kGjwӴɭew9$mOV`x(>ɔt͢I0ͥ!"iF 󴀖@Iȿb/ghH}JYOv/~{&:Âj.T}8nneXni:xܛ:IUlarrx>P Jv2NaBjM9ۊNʸq'$itKx4Ȼ7CntϷjy1~8#jC]\U͎V .ο]/ {tm@ۓi7|Ό]9QRӼo!L"5'w[n3HJXco?T8-ԫ> V4-ӥΚYqI:8#UOCcNH dIZhE\jZ97p} G3]<,O~'H> i(3S.P^qgm$ (7G ce$MbQc!BCh| e O(P#H|m=vT9'?9-Xl.uJD$xIu,&ZKCC@'8 Bt0Q( ĆI`"#wlܘkdIeNK fGPK.߲13Ȑ8(WP 2%{$% !$zok)A 7gYaGyZ7Р'򨕌Rˮ} %^!"ˎ H?3f-걋R2`A1@.}(t3HRQHG#Зɑg4tnq. cW#\I'$!i0ܶRsdEh1]@byQR> (V狋1bwӰ`G~ө]M̽hpƼu[)rcWs&½WcCr&mRrk(T_9 =A\QVÕLbG&oʾ/ ^%CeZ?)K$z f)|7hB,qd@lpJpW ɑd@.I]_˥7l\O xMH. ؎/Ɏ+*ҩ]24!H]-<_2P WVf>`LSiIT^RF3~:E6U/+c"5ZZQ/st5tT!%}AQb64(ًa]A&sX}h|/_8X% c@%#z?_U<0O~B)De86H0Jmo [ҥ$taq˷lҪ$<ܸ.Wͬ=>Jsp5GF 0\7yg|M,> ck~GKs6j5+JKB:s2Ywޠ*ioމn)M!Ja~w^g]M 5ܻ /? "y- }py >,i'}0=Y;Zia!1Z۹Ql%L&SFEXYhOiLPr$mDv>R0ɩ#) z ]z"Er5sE;VQGKm ](m_+`Ibg @t k: bm1:Xq"*9 h#y&Rj z,]7LQ| W ,{lnGŽp + 2Q9[q_Q07R/6j;MqkK}tW\^o'#>\DϪ.z9zW gX$ȫ{L?\p:tUv--l]bz0捑뮬!\uxڛ98v CJEH l2f^ YՙDJ49Th:.\U_B&PAck@yX ղKhC:@_@'AJ$؋G^ $Sy7H{K lo;:B5nU-E[mґ NiTYv0e9ؕD: a$dj<:y'UL hf1TSA.BIRQVVZ9UL;v2an˭/a-(#}]IV5; &'*b%], a1/H&byl"?u|i3J *>}2Z39~'A'mP}fjғ!ːMcjVv,)t&wUϑ"mEFFe}>t*NZ5KgH8gl^NzCވv`orOcF=Y/K%NkV|OTei54nw@\HΊ=X,篟&J} Hu{TqwgmzTGak9{ώ)wzpbOmybbSh]K\eD,YPVFZJヲ C![naz2:ّqDOv*Fhj$L@k[2GQ;};SsZ ,T)CQ=_%waW (3F9AMpNRN͛3 T@]ymeɣ*|=֙ڎj8{J"$,i-Rg֫YWKnu uAi=;y[u_ hX6Jz7Ilfc.Utp.RQ8:>D iS+w5up4[C.!<2azշg!><4ccp>YVO±8%Et8CG%FYor}intkч^BPr y^%RQu&E%{L""}Jo ź'p_Ol\ɅҗqN}H3$O].<$mtWm fMoUv -dtWV`g%}2Nҩ~{Z#w|ǿmJ{[d^dMd VFO hyρ\ –`Vc+M:ae=n|~S!*-;"BfùO V F!n4oMOh*3][J}VX ؂ʖqis,d&sJDQ:8^`ub!?ŴQ{ѝWPGC٣쵖]ٺx4qDQudǜ.RȏaH 9Q׼ *TюzrsG˝OE-mA0t`Rg`(Wu(4m\M(񩺏,|%˴bkP"aR'tퟃ!zs,u ïUӬoW-拥pbF.!)k 6B,Z$* YetȪU*TeV5>ުhLWR-'~2# 8MEa"W~z-n`@.lETfeh*Ғǫ Y)0@`e&B5WBpc2Oh%?.cnl3PG}231+@d+z 'NӰa]$oúom 1E"amЃP%Hjw$TpQ TEj%͵&+ju<.H5f#u[-}(7 :)n'%+e kuyvy*|tQXOva1{6s/p]/BTT"'>"äd[^Գ]״Zfdv@"]aCRQ0A@;gp@#Q{ _? S'!Yhk+h: W &ʐӻ1 i)E3%a+;ƸTX 82ya Tt#dpcʾ FÑ `Bb9XBVJ^[_*SʞΫW^Xdo/F%jњHrCn0n/bFi/RF+l@H|Qf-%#Gl(dy7FvEåu<̇8}no^"!;#6R ^>+k$@DHkEP֯dv/!ȮdtHeP* 8dGvX##/'h-FZ@"՟ڊ.|(2;YMAԊx!0g ~L:E'3B+GqLe&u%Chɚug Twf+\ntlBf?"Rp4R!~OD#~_b<܆` J! 7v*Os‡^H}q࠿oI)ޗ !؟讑S9MJTn!Q9\%XO#4bxs:ն6>i! `x]Փ`% S{\\'ơEE)I0(i, }oE]]s#T1|_nXٞC(K9ৃL 7,̡q6H24zT2U6}`(@BPBSVY=A@ǎi8/'B1k,c-Xc^|y,j:M+ 3NYJ;u:=op8yTx)`LvhxJ*) Z͆c"7F5nр?_[8,&(~P{`v3ք.Lוc` 7nzL<$kmea9ꇡ$["^|4{Sh(P~S`Z7\C@\ױe@IoBc)ݐH}[vX>4뽊*d <:NlzP u/\CS0#:n 77r3Uo#Msm3T ;!{Ck y`K 0.Np!1Eb^㚝I6t d\#bWV`v (S0; %"͛KW~|s5ė*RratI"a7 H_v0W%Xx`a$$_HF5w(>?04:oʦZ爰= -'g[mtPBw8m,Q^\pXlmrS80[V1™uĢ`/X{sp2dJ XHe}1;ȕBUk> P<6&EI΃Q +ܣdw /YØAjI*jE܄za!s<'6tBY?BgP.ZAVv6/PR_Ԋ3pVHbG4c:1 6h3Y"PyE֒|#搨oWE fia/"V?$&2*\t<Qۈ:8XZ fGt>)mùOVzW';~WNE3X{ie骠TڥË@DGwq23u>X\I T($рQdkؽmsF`>l B)4)\;nyqG\EX@_bf4V0CF[+R =RΧ6)xYGW12&Sʙ^L& X{qcx|fg ׽?K!d/&M`D?ktf'^O6\!!^Xvoڨ?5z'MfwÅ.WZO-h).`yE? ]&W'ߚ|G5\YuX*@ H'c}5~Sz0sͫ<<nNwSƂ,GC߰#5(IѺ9|~U~etj yUK:~8M}]ֿ{'f&3+f'ܐ9vpK@S48cƔ6Sd; pengGB'oGK+ ݟ,u=NN$B?OǢv;IIc  mg%wwCaK;QWRr0̭_F$VL>n{Z&zHrV`BЮ" 1@yʔL279Ost/ J}6Lk*EljQܘ9+"@} ?E230ok i8AşF X-Jс9Ai /g,/tHlQuf6_'܀‚)ɴ@·DKk/}*F#@QQ.݉{~nD }TZpE1T3-sl2\L,ؔP\e-^+KO lJCEUoKڌ6V VWmroYBoXZAWM*=D" vcJYRpII|яUyPlznd?Y2Z4w%}*RφiҨ< :|@Dw$`xAsDPEh"t3+Ktѭ?~?!Rm eCN9+Ncrci2[5x`2!{aT'_7ُSROW H=\ >24j*-nHj,ĀOMɯ}$ȃidW\%?K>\,gfM'@!btZS\62hˋS|\-:yx/VnK S @,^y5 .3*6,a1(u1[VOU-IBbѧq\ o#z/0>w{εOeW{;",]W> S )c46mjW $˧ƈHw|ۖ\%s{Y$75fik2fzόjkvCUݷ73LvcdQ!Û`*mk$5ub~mb<]4s!5l3XPr6'ʦ"iAƤEI{3^6ۆF1~gS`!/u15pOI/C? Xxn-[kmV1{n}pR~ZD;4,-۟A))ZeK@g6Qc2= )Ju6l;Q=?D:LKS#e/)`jR;^]n78Eb:$Q%hxfb3Jaoz6ByθY&aD2lM[GHbS³nY)G[͙3 IԳl d-RS/cxO.#ʞ='/Įgkƥ' 3tG[@`Z67'-:DySHqHܺJ~xCi $0b‚qSgj+&c+fѧkҋ"2>Rɨ]X9q.Üa&:,A^!YovY0Uog)5wfEbkQc(SBߪ lD?̜r}J{I> 3*{9JJ? avS9 u cHbW&1,_ asov'xvOO AE3RNZ",$Q׺5<)leQ1gewcN.@"+"hmӹ䀷Sп Aל~ wzu +/hK֛*#0͞\+1+ $ 2, UJIW=>Gr%R'Le#[VQ_.:iĬ@3:@Jv(J \Aϗ.#1ft +.|XL8߫)*bԀmP ć*dO^9C T'-%ƜGOluYSI<;\4}G6.yn2̌ '>hѳ9la֝]D7șqʫ.afIyTN;bb(A񛰺 ,,&(Юz":C3VC,!4#A#:e}i֒ISD@}xs TcYsrBً >{ne!fre6T]]+y uHɹ"m2iw~ "aKю&؃xDS%R0Bb( M/c/?Y9f(Ri)!IPNI.5תK]PWW}TDBZWUh2h=F_*SvaXIC^U*)Lؓu8#lY^]SIiPUK_XSEW f&xB{o-5DFڧ(4?*Ӿ1#G'끵Y0 V4e$7Ҫ H= »^C.HM$1;}]ݬ 3Cl ^ vLb~lr֊XN3>\TKըUǍ607]:>FQ93v`u@Ȥ2dmZDz2eHZph Q/ B:CӀU ٧2T;C0d Ǫزn _NRA8h8K$#%yܐ#G+MHZ&"F^H=8(8bpѮYʥsaK{WIr-:Sf+$1OhJOL/&oD0j r|ԠAڍ8YR*,Jޥzd`CM2+4 ]p O9,) .6&|1l5&n(=U]Q]b) HOj*y*:ҁ6gw5Ion-.7􍷢DL& #zPtie_?튋&}a©<Ֆ we%zӇ&UI'm@o|9LWtT`B y9/{Dɧj)R6-kݖEͦ!n:d YVEb0[Z$chR׏* lOИ5derL5+W~OؗkK-#j2xz^\JW?p FTNSK{-kk4nX[d sbRsoCԄEOxV5?74H`rtrd'R.֔^ rVƒ恣1 \M69ve鈣1=ɀJAog4)wg5ҟ{ZҷrG &Li#9}*2 GAޤաmIᷪNo8ϗ4h_$ HݼH}Eqˆɷk/RnxL]:&8,pۺj.)y*z|suq$P-baBks':݉PĚ&[$O!|1hUbarQ?N8𔰾VSKFH[ U-sw ftii~lJUdpt7+UFz9OE _Ăxzm#8F-X|LUuC9i5~d.G8`ĄlrWV9 4܏w@;ƔEeпףXSnS}?X7B#q&CA*5k0īE>U7ڮ6n9:w`39=,vK~]vȪה 1 DTeHsL]r 6mrˡGSǧ^pU[*Qp(e_jx[54լl_zWuT/=I6$ UZ(<- ձhݯzJlUBU'~7W"%u9?NuZm8oi)![S#h+Lok*p:v'ǣ/+Ҙ1`X&vWctR#V 'R-@ 8yZipHeëzt=&"~n}-| x w@4&ݰ}tCW d/,lҿ%,D N) G:s_XXBj&iD60wuX Cfbn]4pZϿzvH2i7` #9&5^y#TPmmzyiX©5L;]-q{>%_كD@KK`j">euvŽGMUL8'h-ņ"lz#'KkBJ]e3T# B +|܂葨0 ;[Brb"5]/a@ aFNUd=}iA*e>20Iq]48&bP}t5ץe."wVoL2jnТGХP%}j@wmQb+F`ypR0|b#뇓ȫ}.|pSoĥuA$ JIPGQDތUs<Ё+8-Pǣ;[t7$OMH4|,U]3:),T]l_~10pȏ *rM1S{?v-Oz %=3i~}* Gۭܦ]P̖z F+4"Pgqχ O18꒾8A!Ŝrǔ!BR~ D hf( Gk[Q:WD"cn1(! |7թy|iR48*#+lw*;pmї%Y>)}c>Bh~ inYs k dk[Q0+Wtbz!D7ŎY 0m? ^N랥AKT~gz-3w$: -cQujce@}݇ z"\r7~mI#>9`D$.hcyjm|#<&:Z զ R_}.g) `Ct$i;s;7 DK ?x>z1ѼAȑ#!h1$`E81% ےJEsہ&qDVW#׿Fwɭ-B‘y ^"3pLJQm8:.cqk݌k4ɥZ)!)\KWxɀ>2IU1-qϟU{yv.XCYn}Ne` t$qO'Uqa1iK>T8xy>n1ʦ`50AhD DA5ƳLE_Ժn .:uH2Ik3UCCZZ l!n7R6%ޠO\9^48޷:YXoxvharvZIbrO {I@bAZ"/$8W-IQ'8>bwO:A$/P2X0c+l᳸n2S$YJr*3FE<WCnӅ (BF~/,SX@>Lc!5b3χ30{ݢջ 9 虨 xQUo8AjfѢӱ:j,$Ɵ!u\iã=0F'~ñlH {ё?=+J|W@1.}kȸlzbuH9⢊`cXJ>I%{/ ygs'f]q!2rN>퓞:WCށOiA0mC(펒ƕhKv3('QYnt)YS<}B,3[/-='9, ╹w8_D׳Z>`o-0tu_]ҳGȈtKVN**BvVFNR s0(YTJ8IuR峠i& wFvF~,u+yqEC~FZz\?:}[vݚ 8Lqz/ZBɵMb,e!tSYl'H& #&d_B_e4;"z,Xez"ʩ{xm ^kuW3e`DRL0礽N33<^ ay_`]Fd{1*ȅA{>"ŹRϿYRA+VS5Ⱦ̷ɷM#Dr(@"l,D(F4}>0NXR׌G#*'2Aqj֋CaXW'YѲ$%1X"ϟ~SoWxΈ8U`<8K5eKex"xv}qy5 R\@u9#Cn&F XTB{H60H'H^i>+o'Ό93}[ʕԩUj"Ͻܴ$EEJ N;>'^}ߊ?@7l\b}eT:*RH+SٖelioHOT_ȸRb$!g(H̟jq/:߳z985I݀W`%I #1ZHqf8e,2)v2!<#G WIf@j6Ъ[x+<(r=tض!J\a'uM#9 )I|ǦGHQ`}gfD/Y &SP{!} d5]^BlZ1=6[t*ouy`ܹj9Rܪ }wa=:2pAGc &bDol٩_A~rru|Wa,]͗Hg,K/[TkEW.߃o +x|ljRc$ћ:= X}E燯Q\xu:c2+ 45fȭlÊQI *&V;IHVJΨ.'(G,jÁ=)l@+YjޮdD&2S+MЮ}8 W rGHǾix-1#$^(dXꙟ_rPƒ.SJF&gnwmR̤oiB0p.APtHo|k&kI4&%ܬ-h`z–t2v< ,xIJm{52{(sJ(1}9 ȝ{KgeXG_]vRDUW-h$g +Y͙v35nKg05eʓC֯-hqrµCj]azg-"WD$'bwJ_izg` O"$n~ƾ оrfSo$OP8ŷbYtN^ӨɸbOJNqSu$95`B߄"42]T Fu mQ] g㩧LѩmQnT*19VNpY쪩۷Ѷ`iiVtY"0>~0|X!AW LAY/1{~t=@weJSEs;$Ӎ\Kb:]nlŒTSF@ Dgܙ1s d4,!ڐ9Ƿu?0JtP *M ŝ`f/N!(gHmWM6Una&ˏ-1 j}ͥѰӯx {1oJ#=+Sf`R̰_u߻27I9BOG@!r0k Y?+ E MK[Dx{ps$ز &tb]sEI:W[сJ&Tu^"b| 2Ώ ߯8;%ܯFajp(߾V$J~7k@Đc_<<~zhKmm SB~t ot>z{M (R7mȇj\ODB?W-p5xJ&}k֬ 1}H!FNs3&Wc($B^5-6%qZ52 MF}8cF.i ;+y2rvLVP?7_`;r+h`\ي߀ZdQt̆<)墛FsA[ # q> $T5UԗU~7J#CpK_IkE4x‚-FnЎu۷p+,_L&p^ }̞(-X]8"oi wsǺo0u3{Tg;/7S*<0j7T~]!8 N8O ErN\b^;XpApV>|KdƙlRoABQ(5PBr)&C 1]V},6%ZBuyO^c ZQ3ƞG_=a[uu%o "+"n9ǂ(hܞZOKʫxT 5xԆpv=s~5U<}@hm;$H~O hXU%<iSl{(d>ksIR #AהjsD}:ٓ7pT;^..&BF1?+,@5F\xBakG6SY8=JNsr,43ʐ`v-w )T% [* h3*ɅoVM%$kmKi o?o[TV"d]l"Z S\}%R&hW@W4>eh eޙ.6:׿B!~+ƯrEuYzNhXK^ATqe4ǥgOW,yo^P D=̖% VVbᢻ{ ^'8 ^lHԓ.U8f59E JU:c* 㖒4`:So9Qfo?{+}y\C&K8*g gd,h#ǸwW6g"Tdb:)fdc#/c%3={:fc^@]MqZ#3PI]Uv7K^9Axnɑ:Bl)LNu9%2'ܸJJ)b8*I)@\42J1 *5V\WsZ~ i$ 2(IDpp7.rC[v徬YΔ@׺$|<=Gĩ^ľ_ i4F̌q2{6x} ӧJwh8,y%LJ}#"X8s`ƩN/]O9$,Lw8\{^I,纞z؄_{7B@&|Xw o\փ23> mp+{%OAF@#gM\ZHΫ߄QN4./c 4tKR+o{Tc$L>x w`B3WT!l6TKC*^)psU֢+SO<+UJwNŠ"lծbG'LB4^YyTKss/0](ϖ`S糍A/"4[Q;`Ht \N(^t->[U?b1]ẙYiv}e_8h2, (l[Os&I.S/Zf1|4HEs7˴>rn9ܥr%U)+O*g+Mнev$ .VCEHu!m@ībB+4מ^HnMy 6ʈX~V88 L8&;?r'!$Ζ{&u^Sla5}jsKtC}P <ΒW::8 yoaǔ3[.bgU!?H)j?B % Q !n9M$]zo"{IwIˋ a(prR>Qfx" .4|Qsˋ̮hZ5:Yj'E"Cz $W)k+5Z! 6GѲ[>:PIiiaN1(& _"|T6#:V%) @Bէy1*p`sLϿp}o1w a&F}8Z)*:%UA14 {n4OΓ{L:~=Pt?ᧇ !*tcBu*k$PxYmNweTnj|wpz`[gj%x4cea'qqZؐ/$ӱX/MQq4N#NYԴ@6srpu9v},d9M5΅dFX98 +ψ!blBw~=D"دSǭK v! CvKI ަ}ƥ1]>i 6ifp y;ʪ 6FsРp9H셡VȧW<͏f][rz y~ݲ %&aeI#6T4PKfGt,<i.>ь )2E|>3H:C G- }8fhJ1zp;b yub- 2{iF!]aI{@8ucfcxDDķ<dgr BĘ0Kr2N:\kտ8Ibs F'eL8OjÅ\bd=DER o+fW%K.<ӅYpbH_"WLQH#ޥS:YDgw͍#kHIs0)?Xaa3s  f2d=9I{,y"_%" P}du]Sx·1D[QS084wh`/Pqwn%ǹ<֕8s|S`{PΣ~x0ݙ<˒/(n6^pXRY1zlƍŠB._" [$)F ܔ|3}8@?Ҭf Gc1gEa{suъՌ啂F5lJf)H~-1;t)%Z݌2gJ>%tB9O#enV7RvIdڰ`D_)z})#kɯȻĩ[(s0hyi| " Z6Y#-o|4-FUw/]@Pp8: c2%oh͔.h8D0*gIj_ߊ4";J#,ٌTDrDW"M9VQ [iaf ly|?_qR*8D(H[9`'ٛ>$ZOqW8(/qQRM(-v,l>t'$?dWZKbk:2 EsfJit*h==&mM.U@4э[Jl9i'3K`DZ4 Tf/j!д0vm3-ոh{ ҩpq_]P*# ~6}n^LO5%0s<D6]wzQuY*$^As,cP;o57$̝07 vYۧx kw@.ɊܨX\^L:x#{sdY7+c)nx?qw&U6Ox:5`kfjc"%㡎A\n7oHi\yLڸ9wT0NC? `2&cJbC^s#7BhBR9d X6wt.d;)/ 7cYL=>4t*n:ЖIrgmbZeQݫ){$^$IM;i'bwwf 4@-sNMQ(Pn+HĐqQa֏ޥَPE{#&<Ms^+Dp(\/-* *`xa8]r+?Yl0]a9dxdEn5eO(]QnU:Ida|"q4)LЏ)5~Gw$柩yB#6 QVtMG9O Q +pg|z qΜ`)UTJLg}7 -!NKvͦ:VW'ĄqZ6ژP1ƴ<{Zԇc$%prXO3V(6Dbu.X>ZGjYy w.k_dlp{#/!k,OE Kֳ ʯ))sA^?r38<37a>]~= KhG)0>޷ H*J]h3ʜթ3?ԏP7%8C?΃UpQSj,?_WV=. | k:͵ α'9Wzf?͂NI`U^ rԉs 8K5%Yk#)qɺrg7yLA`N:: i*c]eL?qӁ{jX\ l쇣CseتS.ݸܷ,%*JY{r`="p2y"p8j׵ juXGp/ % pMMӎ '`)Ϟu(AOgWv= #' Hj8^xt\h->X<9Yup\(tkC=|@l'A5F2WYp!9_?܏ 1vZH$†G> $^ꋑI8b&?EyzRNv %ء@YMG| kiccU=yF.NIw)[PuRж)cFj5;ʷU5ڕ° s;ct ^, E iV<ᰩC2Nt"3-$+nQ:*)Ҵ40oz.lB"6T|.nTLn5A$3=5 gWgE\t&T4A]ȱٻ"-'Yb] BSaXH8]^$I0G+H_u,z'3!}m:0 A]RGEF)>7k#va1RF$+0= UEJM꛸0"\ֹ(v;GQwC1b ˜kZFwL^@!ޔOG򵾰#~FQ`|pԡq &&na*hM3|$z UE,k t5&}˘>/Fؤ%@y_'1|o([4 hE|f$ɨoCPPop!2-=h(}jޖyw$ZnrQ%a3V7Ղ 傷)kN1{I' L01 LJ9!{fk.lJ&^% .QT |ݘh53 ᇒ0n. q~r!2Daod)C`Dy7jjPc6˦EqWipgܡ}c.B1f;7 :0|%E{eSiXpjn+E֞%DMz-W _@&,_}2ê=< 7 QA;uMfz6 J)dT54` wNBP[NJ1ҔbǻKă.JLYXiZZ;}8^zn$#Q6`=9`Nl8خxWlzξYx'6 5~1`GMhb~q>`l }~t0%jufbڬڲ7?a͌4@E3yoR'(nsVJ1F/ ,w44^r4F!'Wʧg"r9cؖ6YP_ LuW=PG|A}l0`lGWRLL\?tO%rMI"F⮃O6G nAN5@F*5JTa͡c_Yd5 SQAO,/ofu(|E6 Kg&it 3𛴛u9p X&JFe 0Hv.u='pS:BT*m4RJ!,]Ysp ]Q0tf @F4/G{P)""I@> I:c_Snt@N(ءݯFO" +eL"}$E޽6vl}y,jZh2^QxM_rEKX f)WȖuD}k g$I]Q3ϒ)D/'&G昰KKНWffVN]M:Zџ)ɵWasz@tԩFI;#A}$Û3g`^;OA֗\ l4uY}vWs_X`Ϋ嚸 "QP̾Xka`3f%(T؂vjKk%A>$kQ'mAʿȏP%pB z͛Gt 4.ܶQn|U0K:vY8 ԇ,. Qr'A"Wx|?F9& zcXuM163:H4a m}NdY0CLDۏd⒛CFΔqp# eO|X^rq._Q3$Te*K>ā;hPaHy0 j8hF!$1%A#ҹ]oʼq1o'*^ޑک`9#|&c9vۢA#+meeQλ1Jk* И+=CÙ@$oR 㣛k qyj]*7x51*UP<)]sQ Dɇa:g`,jUfR3{jl53$@lV*ű[X<^eRhjH7m%oBAi_u5~c1 Hd4SBVV~,$Ɣ!{PN~pۻr>IF]E:A G(@iT'uO6SA#+)4 Pe([O Us d6>Ldxxz.*0gഛ״Ξ(]rU{ g-ۓ326E>Iܼr\O?SjgvJ*® VoX!-؁$mSlFzB]0Xў|^V$uu!!Ip㬟 "5B)ϜqMl ?lxx.!0wUꕌY9 g𥯇 'ytz--[Ld*ۅS)fJpf1G|O/L[ƢMm@8T=E<7gq9*7v8*y {K?7%4+PCjNB-įEǵOr.UJm:n5oQ]GD+**&Waz5)jT$d/::&ޱǪ=#?v NoWiM7#*,%ͭ3>_*>jұ~>-=_Ƹ7R 40YnX}7nEl) :yS,?f N`BT;.eP/`l /z ?&gci2&ɩˋ 8>}G#ң*%aZĽ2gE5 ַԅ^%@zxZ`%x00 H53 |Xd%JjޟgW{]Jod_uXiT8Î3xS&8coM\ڊȞTmF BD4o.3;[Y YCS$~bX^M/T~ae,$Ck9# =Rc<cP5,sYsͬn~կ1@L#N"O |\V2 }DZ)BZ/?Ά8+ٓumQܵy9ݻPVɼmlߣƥUVlpY7~OcWyYRzEXU$_9tT{C.,l-wf2N+.|ypҾw3MQv5e>MO+;4lQZ6rB ?de%~=> ҇O:˫;ӈ>Lc?J{[WH6{CH O}LL!7͘IVY*78"z4Cv{ÍY5zK 5;. q o߬$NJ5;[TYIlexn\Nt$*sX%\Y5"4@KT6ly;-u^}ȃ[K.>?碍O/W~`q*ݔ/UZi~}!ETUK]]"kĄ01㮊OH,x0ɋg|+ ݂# u-.#HtTDhsd VWaia#cŮG 7']G_dEjѵ )n3p^$*;H%պVU!A _Rp %cF01k#߇GϤEC?΁|{Z5kJ ˲0q=b' h"jtfϭ /暗 s,\gyWow!Ȣ1i`wv~ί~.<0łp|)CIp2W-rv=G^`QsʀH w?S?kiHLɿ>%͒2o6\+k dee7Q5,^  pC$J'X]J& jb_GQi_S5] zݘXP9g׏Pk1'0ɭWHDۘ~A4% HË 57"=rjLᑇ<䢁v|X4|u/rRg%DFyXIhseTpE*6k`f/5v_OT3knR٘齿׹ `ʴWkoCԫh ͩ-ٝf"uW,LD7\>grDΣq;Xc1|LA78Z$0GT00 MP=X=on:i;k'1RO[dpagW`tZ:x̐b0-߹zn:-1rT% s^l"g35k.dlEub J(J 4'5)q}ۤ}ZwG-XOc+2f=Q(4"@c^=҅\jm  Q-G]S GR+7t8=(D傒E=d&MNT|^3!+u=Xf"N$NkIU5Ȣ݄?bs e#S(b"4 '*ib)IΎ<棶c!xG7^\/V#Y6#\RpM.k !5ۊtЌ[{*vRI\HHaW\n+?b*ӫh~1N`+L/OTJrӆɂr=3|ۈ Ƕ?/޼拟bRax/Doe$g1i:-O:8$5np$/ $fcw [^ JV㡤l);`F<9 ՟?Mh7|(n^^׊<(2?xBIv0qg70GN_ x/ O=^T9tD`9p.X?i~jQZ@ Й\ۇ\XZB+1OtR_ɡݝfM1pR5oTu k%8˥m*uSVBPHCbp+ J:y6RgQv1^:fsu sҟ|0ڢk61zcۄAQH]à9- ^h@HQG'3}90nщ H QL.=B;h e2*,kIr\&.>ן `V`O)zL+q+?ڨi7XDaM-p8bECK Vj":!&_B\Mlax)B8VA1axBւ Ǩ\?zQ9yix87 FI:9&dҔp a垣MpR?е{J .vMPL0﷬zhwGC')=G_EbhdOB->/˷5ӸȖ ݻ0vPzT@ʼnȁa6k]-G&e99bK1q4,lkuF?@BDu'%R/Q&v,Vׇyw>Zj^ Ù$f@y% O;j&.3@x}rhKkW",pzjrOnf[f-#c/ޑW`m;?WYQEzt)m)!CG4qKd`=DmE.5*eK?f 3n7W'<{.qJ#MgD"IP["U%92نJ@1 "-sytsiTFMD ۪A x7b{_[(gSN;:Xx᳐扺.i@41{o {ϴW˺|!rޜoxc,ѷ+~Ê2woO$,m,<=ȥVߢ֐SVr=ELt̋LL46p=y` yZr1K>}M:Z]~"X&=Tf_x Ze{k8jL -β &ߝ"`ݦRQcsw6y-7 rV0ȍ>; ÚE=F}^nŘ>8gn Q*bo,DX-8wgk:chl 8OElXP?]V8VdJ`%t^uͨ`ȃğ^nܿ#y2&(=0j/:+Nq^Ev- c]Q⺞apq~f{k07TM%lJIbܯ=6(ͅ~MuΘHs^CƸ| O"h}# T4̋c`6zzVQ0;~;Tvq79J?zl-ܨA.^m8 !fJ츿:O6p#e9 dh /$bL<Y[ ֪7|{uH*[_V -;`tUӍ4lo.<O (p|KxOZIɋ{a ّ4[}%8pB/Dڎ(@2r o'{hl㜇`^Zpn,`r@}SD,^Z]촔Q)c;x;tQO7\d4S05g1 &~  KsO S$$Kc_vގNO= I{%Zx4dI =Eِ&GXZ^b eO"Inm,Bpr4y7R>) DF63i;SyiɀLrt,e9H/Mip|_WS:cĐ`2NwR`:X)TԽ.BP,1٢d4!H6 xJ5ca=*5.oqTYMhZ鯻;F!7\zpزǿhOZ@ $oDvG_ }*fgJ >@&bXwܷbh2"T i/H4PR qUf\f>9H@JC?2.va&ܮFpqow.sxNŕR[Ι-%AoalڮoхyE3udޤ$Kk݀B8mvEIsX>xH[q^PXIӶ{MG`rh'|,Ǜ+I1S2}aҫ>‘1j'v.˔]pᚈd1#nb"ˎNwI=fEZo0Ceݦ03RO5oHK7=fRQeJY llX\%Yn"!w lHG dC͙ .=Hdx|:E/)5ޗ^h88VUSɛ~grLy+;qQ>m5af@8&p DQ@`-Wc-RM̮ 'u-SѤDMvR0b!g 'RX*y/ k0\XO6?a\ij~} d\=WPq:Ȅ=ճg+\ɵYM3fJfl=f4}< ćr%v3~HX=g Qݾf ҩ OmՖ[Y\2{VxlW#Nt57h t?m-\/:y8 =2I-1Qa{|YϴfAB=W9Iu@b7s!YWH'YÜe+rNzfP?GI6\mzȽaC}ٶT)2v[r`\`Op*+$o8(j{ j2z=$7t}qhpV4ab'VRQXA@ϲPms[f +;!T% R'eԦ$v@mr+tBPhh G HqY}}P_a1voQb+ڛ($xt<삌/ Zsge!!;9oyMqLv.V2|-_ jK9at<9Q*Pa,'گ.uyp̙(?[؜oCp):뻙' S5ff'Xh?c$=Yjeo=z7 I Ft=ʗ*Xho/Ln k2v<(]=. ^0b׽a@e_wdւmhcb16]X#8@ oM|-^d/׽YJ mä7؆;:Mڀ&e5.i~R$3d,Jl%qMCX}JAW`@ҨV4LUz!J@M#1#P!-|!>""()bv+sPxxaETg*-ƀWq0w'IX5UbWF6ʂ eBUQMN0/T>m}5.ɿ^vBPƘu֑&qHdbmj{k"/!>B ]_$@"ةhJv e\7ֶ3bބ=v?R7 0iB[I/S"/w1_k'GzSЧ/se1Ld3vvsqG5-]Ô@bK“qV6؟Ɂ⋳4!ɐ]\ U 6H]NYzL;\bciҹzbz/ߥŌV/޳"4t<_h=cˬ+2;g HubFPҊ}ǦrH.v?,h9ń,8xj1ʙo*ݣ gERi*³E v}! e&`/fD$%jN$>joܗ Gop$^ ?kyK BYn6`|C{1&BB+ MXij ;ːdg/vjr|"5{b׈ mM)n tnhf:.|XED}eF2*g:$ Sr&~뭍; _Rܜ1Uh s*$-塰B$PN>θ#{կt8E' mm"|q#kSjB5R( K*|Hf%>s}tggO'Zj6QK-ά;;X| u#k,t.0 2|^rm[2[l75qA[?ZVS̈w\ 0y,g+FTdL %8\ASL9XGFn7Kj@)g;@ Q+Ι}Ś*paP),lGK{B;RHMfZ)<(T k|~|`*a>6DtSWG((H+c4 *jŵں9_u0Möhق(}BpfȖ:hp `C?TQyi8:zwg}.l`p6USkD {]Řg3q}H7-|^ќn(~X,Z7*^ՠ1hM"psc,ap6 A%iHqsNƤ1ל32єavVKp-tp c5~$&4O6LfY_gh^Y F{PT5aC̈́Dp\rkp'`ʔ@90YF>Q9$wP]tM<CԳox[MCXRSR5fƂ< LPUl?keKQ~OBhÁ[*+ 1W_IF\ dv-7:n>K3 䈢+0DS?2,XuG֕wMy$f0n)jL ww }$*0K@e[h. 딗Z9E!O ,b;鋻u=[NFWL (pbHbnA^:1p6 :1 噮´TP FƤYPj ʹj+$̣L殔9Pɍ"Oq#Fꃴ׉y4/)2 _JdiPKp!=g0^(#؁6 wGj=ig8%߆TR7JgjJ6`>sh KiYmEM8CSdxz[]*xZWKNu8{TqHY~xb?Nh[ؠ8 h ??xic|^QoY?&O/#2P w0M#篖^tB}^ۜA[Lk.I?]E6þn`~KNd,Ư9gZJNYBOQ\AmFBem\7*Z Qh=2CQX7]Dx޵ʱPHzه0JZkZvXQ__V;`=ῼ!]dh$r-M;VSvh-5`8e>F=+9.GI^4#/c:i}~XB1 j-mǾ% TA*2Zz[LZ(Ɇ@R΍h} "1zhsƝ͗tƨ~}l\.Ǹ# l_1[7gӷi@[2n߼ʋv( X깁QX'W,T-Enj `)|TwB. ZvzX#4:1~oNjL L"uyK2,LqW>"h ωؒB6H9Z\E-oŨ(dJ9J&p+YmD`tTU@%$Hkg(f^)t2+Ґ=Q#o-8:=i 9tCP0Gx|u<\_=PYL`˾/A^I"$ʴ[C]+а/(fAIQV'4Ys^cɲ$%wTEly.`'w!ESߞ@tnX:w$pjVm[q)uJ+8]wqL܋lO&ؑ˱RB AxI2$+Л"$(hl]Ҹ eq7ìm!cvD(HrMU3*1s3פkQX]ѐݠEp /..++޷J ` %e "]zOqA,0$LCmZy-@W~$~yHNU|ew$>iEtG4"' ;$ !YnC FL\|#NnՁG#9Pn3.Q5W*|er5L^hƣ:n['iW~_|f,'꒿fXl3ejA%6OBs~LMV$.Hp:6byޓy]wB.jiB=u )֗v lQvŔӖ2I_Cx4XH:p{_̼Ss G4r'..&RiI.?ӃZ|t&>_S}%&ZzGl2{>QQ};v:mX !%S/z}]1HGbx< vʱ\}y[e!\ت%1;՟lE?ק1on E}BKl9cWTt 11=͵ D12Wx=  Үe޹$IvG`߹u)I<, N5[C̄qvENqárW{?"_śHH)3oaW 7ՔZh7E;r U6a)Dwns%j0.DD yoXuVO&r6B>ϔ(=2',U0SrCp^ש|#G5-5q%ʋZZgmh UunwV8_}E 0П5ca`ϘWR"r1! %Gob$eL{X& =M_}6?8vN5=ٚXca3 l(&]BGY`^G4u)S;?3rAEԶ_< \qS K5?)8~M04pD,9(eJ/)tB-K6V-4_ 8_\̬U\Qh-bJc(3_CeFǣ]R`i]NdYշSB i&pf(AӵT!ߓ^Zޯ@AQ'f)X/c_+Vے|eN`;TŭN:cٙJkDFRRIonYmۓΒV B.G~[꙳y4Ţ}<Z)3A#<'cYE\2^}s?PyHZX3V-< v~ϢQDFgNnY;v4rmtԄ5p2̕ `!8)}AllSTP΀嘠=E:kG8`%'&%Ȥ ߰Yt#, MG:I3c̐ >0r.T@ ZZL y=lb\񯂐\O!!R~jr@ݕbb)1jhYz%Qrdm],N=ihs>TFMFJhDmaMX8A4n{j Y'@a,v9USZtWVf{U 1)>A|ܻ dR?5}B7LKU-#(p{lΟp b0n{9FB5>} vnذmHVfxX@FiycΎ2e7=!(-ަg0"[,"x^j6-}ѹGFy)YZ]ˊ6X$nL<w&]E-ecUOywe!]`rM=mH /dr~j7Įۭ|sbHZkj@3`؎0֓)1c%Z+0bP4sU}Fd \e/YAE}.b#[> LFq@v7#޽7>t8֓=ڛ+>kΪ X`h> `}*^O} br0_po(j]+ KpIu ^'ZƷ嵀;E,o2jj ZSŭJHgEElNTg>8 &ē I +`2/7bGnQͰuH'Mī53Lug LmVJH,If:x҄b9_7]fR퀫(@6o*RCk. |QEIVT:4 )mɇ%;1zKd&i( -o> -^fAFR}>^eU?2E?Q^Ui{=n>HdgT봟fSF\w0`&9>;>[B@5YXƑr4;a1ҳvLZǔ$tL(qzi.kqξMIٔ׆.&8YW\(req\Z #Q̴tO:-3iLJHfqѬ6xbs2d+lZQ//]&Q%#Ng徾jH&9lԏC={Yo-6zis,רO&}uw $~7VS3A;u{E XD1В%5!ZY򰀗=KU~dVl+n\7|ZQ]hO9QN<J;@Ov/XPng8rY~,S2cv[6y,傷pُETl󽼌 Ldh@Lzéd=bd3p=H`JG0HsܡvV ;So \"r<qy1ǻܞg )SBJV,flV6V/,hkŸM* o:ə<1qZ= /cpT~rK/4U7⧷j%y&ٔ3  (%!7?nNhkzJª؜=;|8l=/Y_NqG)f>&OnCMNՀk5-uZYm":cR'' 90 ,oz'Tuj+ gCPUOg*,]̨?[IPHm?B- jZ8SafגF!5Hc4Q f661YΠK1)xp;sZyj5[k rވzZ5xB>eo u00 &dS<%l-=)`"!2br2OxS/p',~?hIzчA;U?HyZR tR]&,GPxkzݧuiFz%j~$7) St#B`_|Z1 HP0FSJLm1nAm(UՃ ))Nœ6g-pU>N|*ns]}E@jRqCMcc Ϥ6tvbkq1)˪Ϫ&206dtqGkWAuˆ)7p$|fĥ*O]d.|h%n*36&Kaּ%-[}ua+iib}IoHf:1jr>N8?Vɦn}(m\@lxjKf8D 0C0r:F~? t]r^Q"~kH^TE8;_e.:FS.ʒRC= : l2Pz" {>e* 4x*3 mm 5a@XLE? 8o"EȆMږp)5O!Tn*&FLA•3rvfAYULP6}ۘa}!`l)G)JP#6\:Dc{=HCOt* ;\%V.V+'L_:2cbtw.z{lmeBM4Kl5FmA72eb0k1Q=bz`9>wNtQjQ84}1nAᄋ~QvOO>ޜT7pT3(;"{CQ=)JFqq] ϐ?b 7zK(: q->V6] nJ*V/-[DewDb  u=JW>֛Qg+~@E\./JMCRSxz|sD ;\y .tT6f\FQnJN.!L$ٌD:v8\y{e326ZFhN1=U?ؔ\CH12YJ4xGQʻ|@y=D< PFޕz !=Wo}f{sܟ t2Ҋ7>ׅ$iOX.^=iEteXͦ"dke,ͣ 8f.#hRf o/z)V頔@pTr%gԓڼɠ"b8Mi">wa 8=5pk=^ u鳡o?{qS"ԫ SZ1e3Γ3NfCNd:*q&u*'Pd\2 S![3"ppzi0;K{u7SRuϫnNJb >@ʏC6g N؆c.i=i_|dg7w8vndÿAX;K4aZԦtODܰEs&F۠|ay-d}fv_smX{45xIK8\ xkz!"߸ը巆tp:;|&pV^_jY'/ t\0`^i|٠(OT2HD~ݯڄd8Kn3RW_J븇J6+K7 eWP`kCa$2 5X6HR<!(n#c͊Z.;hyW mSO.p߮s~GhƿɅ@ir^?nNC"?}/Ne#P~B˘`ya:6YN&BsG &U9ze$yo>ٸ<./Qx[7ti&~lؼbݑQ!1~z\iib o8pb^c0ZaH9KM&\C2P#P[)䄮ջ%ol Ctφm[RPFJQRַ^=Xs_X+``\xeW7*ϢW,n6]Ah{^~Kqeu5L!J@};UCkn`VIť%il M5WVNuh3-]g@ s}eWDQ15'긒f䡽/L21Jﶊ p_Aom *[UNz2ۗ9U—1͐d1ɞP]ǡ*69,gV7Krܷ m^9=NtbkA tMDVaxaY}'M*& : Unpv`A{l OfnH&o'6ؙf"5߻N5x[h ǺFf3tGg\M?o} *sQun:wآ#/;c0r@xl%vQ@M61n4`j:>@^A SIĩW7 틉@%qVŲE(>\P>c*pK =du2=6BFt< #A#eJ3C)0T›SE.)3u˶XtĈW,TPMevv4A!D(N6PT-̈KiUށbE{DT7Ή3=%F&E.Ʀ+fW@ xtMDL*_ ɲ [dgvbJOOɹb򽝄uXXI^s&]vdP{%?/k6)dim.6b hp͜fSf-<%vE8>!LwNGJ ouPn+ZwqQWWP]dٿTnj?n)u :ƩFbZEʻUz|3P( dz((/&6U"-.ċXyvkä@Ͱ&I=?B1䅼ֶ8]N:[3_s*#8;.eeR\wq$P d1!]mH/!OK͞yi  Ժ H0_2Ka5o̍, X^xڍ>[zmgVepUom-tvTB àSZ4"qΰB#7;BpدoZ2E';!݉g[U;RᙑP`j$kՠuy썘^ߏyo T)Y7 "QJ¯.^nQܥsS6J|VSbg Q]H/">5XS0RƐ ` Su2\arr/D3&gߝLdxLrR/t_m Xr*^N3_[&8 ]@;+^3O-JdhJ#Q.o,/2Ѕ#wvʭDХob>Ft??y/$$ ˩~Տ?sϔe8':fj Bփ؏8Mċd戽E?,:+mjNKh!̽.@DQ%kg3~AIKH`?#R@ѷRIlk-"w6Vw]Ro>d8.:Xv!i %@Z#ώSwx{W v^>$ctANJ BzD=>nyFh6%@ąZP@+}| >C0z~޲'Yh4]k|1"d,îbhX[|%r$f<{9Ҏ%/-70LEvZ{ӷlrn¯jhL((]9(`@Yut/wZozҒVtVu$7%ǀTy彊п̓٦?x3XZEǗF1w)61KόQuAqL5FAݤ:Wvr 4`{^RK*V}lv!=sifwBsppӜwg!ܨAJפkVAb5&síQrp<8X!*[S&M ww+kFnRez/hhp ֤4ЗRʣI9i'jԌtMI&Q0- ǻ6y:(-æ3n-*uGi{!80 A"Z t4h%m8X.X-Hg_*xP,TTUt[^2N$.aQ|`]?R4rج&u2q#Tʮ!DQ(@frEhvp4qQ5Uh1ʜhaCx%\E9XQ{>׿xRW+&ÎKo3)mюER35U#"pĠP"HZ50sBl|Gb9O :Q&Mk?e͞fu'=,$vФ{DnL N= y{)NLxdbŎ7Rӈds+ҽw w_8KX |c0<9Yڗ!Nyhl"v軉`(+H >X.3w݀z o H#!G| PҵVf@`GL|-Qe_BmKk^׍D`dB+E NP̆$ aڠ\q- ",k+\Jyώ:k!-Ox1xiE=#inV݆a%.qGq ǹp4{Uw"( z@Eë(?TXp/2b/P 2(s'MD _7AR!3ʼADsz@{ mKWP{Q}[~ZkJ{A1:_mH1m x2baemX6ș]qYsj޿%\{}.V;f^i:$lv=΍%0N@r&3f|j1#MwORvƘUE-ΝPI_$MvXN Qڧ҅!̴K Lo-KUv93f|6cP!ՑژN GoK2z,z׏zWwa}%z֘ 媛 p,UMlƀL'G5F1շ󎃒jvw%潘$p>i2i k,(4ԇXȤ@X-Ž)i%/ GQ❊zq|1|ېNMpQo-(|p(xlʓ9RԼַrh(D; :80 fi(]vC 78&6f̸q@@{wTJ`A!4T M< v'ʯ6k^˵P(ZhS2*10GdUI:b!7'y6_Bu,+1;š.րUC ԅr\vw_8@>v_{km¯Q6“=D x"}6dTtBO! ӒX}zA`0&Z9x I7=D[8ţ f9s= f-)u18n9_J-bPBk <=S}5h":J8<弍Iba6{7ڤޱXmHJptNuhg_4i7f@ìFw7U.54^)T{߲US<YAGڀwapiE-uΈS׎AJ7GyHʧD+Հ՚J{J-SۛV́3#c.U O֋2peM;@>ӁL6Ġ$8 T^ߤ<TnZ_1 o)k+ {hOxIXyn5Vsq10H*a0LtwvfÃ͘2D-2n"Q UԪ<YOg;#fli )t .$z+[mSt@)zOh +Wljc'pqIJ ِӦ., oq]_6ŏ *`"e!4Sڍ; !\i\_o-M&6~)'/҅RC#tXșR'y =4{ff92sD뭤qT)et+]Qn ܅3,p,+,W%A <""^2; dL*1֩w!m KUOڮ&=.0`9nM VZbXEyrz я.#^`FwmVM/z*y1ٛ7|pN^prM9i9v` dR,`IB䟄~0%)E38|w!eH-[BFCVԭgE%s U?#&폟u 4ޫv в ~(9.4,kqvA,ɥ$Զoa6>@9OՈ>mJtK\>9y̦y6yPGoZZP H:_km ~Y?9?HsKFT"-L=5YoK^X{rSnIW_h|Oi'\јr oV]T؜@iAg nQֲgl^_o`IuTڛW]"`(a&Eklc*jUzdo.kr IՊ*Wҭ]V_ttj ef5Z&ڲI&4)0G 9Ijuj5iP]M[+M{G#'-9wGD\T%j*w1_]HBN=>>#]Vo|4٢a*0Ű[ŷlwzz]FHQ[>CCԿ ~&F_ L ar书P~$N6``;1Ӛw%{͙J_'|0Վ44NM`#"U7 ljMb`*j,1ǁկ0u9bby'PJ{' NΊ* 7eAt(Nd8o\͠šO8wQNUZPo4@n]݆K-P3,Gu!=;ȳo%Pb ?ˤv·Ay*Kv˖Bdv׿^[Mч`LWYk8\!vφ$(s2sG ߤ.!eN~a2s“xM^I ΖxcӵBYIW[R@z@vRh ])2t~%XuZ0)zZ;̂eDc™;c3˻hY[nP 8Вvu!*嗗4zsGii4:X h< N h»uq?V b-# 2](E$?- ,t FY|孺Yԑڴ{ fqvAt*A{PHt9N7gJ(]ni[5\{$ݱ8k _¿yb4Y[Wra3}kQpY%\39習~-޶ 8s4"vGlfb_@GCFqWN]A_[V r%:Sh l>ӪCl8Fr8XY[rl}WF0$[m H>73dv7?L╴P~%`qT(W PJժqxg@Q<`ku ݧʵrz|!0#nM?K$2WC~OHm=%f`)Zx7|ML{:x"؃8\}0pnMx" eΫ"}șN>ɀ7HUlP̽ݗ#Ly_M3&9~B⧃fk],!^ڊv&{"Z\cޣB^A?l;2H;RgC|?N vRϔ i@W}紴S`\F_d| -8Z|rrbgȞd1*ϰsXʴMVl$Ry[(mp96䶂K|γ'~]+2 sY_7ǵ $6t"eGIh=.#"ޘoKe .KB%IT ;v1BpZ̖ܪ[H$ClT̬etzkNUʠ& ߧ1Yzm'c<>s< b6vcN#/PNZ3=w^6"+zx-b,K"d@l W NIº *WtBr%ԥ`N)XNU2ԧH;()n|&6t"^w!Sn!1й+Lnw[//z'# l,q6 źi&49-΀I s#N$K* p8xHN&HLǴ{8Y,U߯cJ21>p֫H=IGވJf Xwr}siXu 1{Ms v>eL0m4<]1 䪬_qQRVڞJ/$i<y"}voٗc]Ap9Yu!b;2p1JR3C5^Eil9 %]}7jjmi ~|l7aә?Gj)UzX*Jd@H`*,ٮ4 -uZ'43ת-D`M7h9ϐ,qjQda(Li3a؞ nhɴ :6/`7xE\Tl^,|ؖ އǼ!]cb%^NiF zgJjW: rE/(]JJE̿z ->dBM˼,gjh鷺闂z lG ^vH0&g$2apwښZA^PXq.81JI'"(wz[dꊩ_s*L+~&> iE}Ur)UlKQA_ri.UMvQdDFY1_( сC~ChԏysK+w+ QMR.l*$oH`}PLzt/(d6ٻL(4L(Ovׇ񨕣C&3*r t MJDLm=[@Zhs^ɬ*56o z\e@wfkVF2N簃[ph~U)%0L.LD71t)p-=LUv(FcS*oIu`~vD$a-KxP΀пTc$=LV @  Iu@n\*,(V?!|謋%J乸p],ј] c? luY+v ~Apn1NQmIS'ڲ`;ܐ UcM=jv[yXevpF|iX7__jHiUREm@s*$hiFτzmNn3T򘣖`6Fl֤[D(e+{J_J,KM汤{a^<}c򣻋@վvR۷ulcSONe{6Қ~<2x2Ahu@nfu `H«:ࠃyPgU`hM`(۟\vG">m*8T^Av,i"wGɐH~·QS4t-G1`ӑ#29chgB){`ZؤYCwI&$ nt7 xnD8$WICz2)wb3*-ArtPp|wsvcr\XD `^ [0AGX(5B-0L~kA⪖ H0`iT앛~liB9g2MOku 9$ zӫD8B+PR?_ l2>GeX9[(b%9*OcR 3]Ak.*Zν8l;ا(Ij_#2l7P PbpHE^6@i܍In[rୠJ&IBTB;WL)eEU8ؖ}O:La1=e1E`̇#WA!kmLÍE"pVhU*i`枖3y$qފč70Ohv[x-qy{ydSUCC0au|bDžM aIR`0[z g{|om?k璩#f- )#H@)a@}"FPUB#IZCl?4/nWf[;M笖ne&k֥!lCEr3b8p8Ӧ/bt!>`$%$>:ϓfdG4*i371Y8 I5 Q:͊ݔч5Q/S V>Acff*- j[teOB76f݂I@>i MhD!a;YUӼn~VWi-* MQ:v[QO5}ZȞ$̻3zֽ j. .1}`RF6ng(oC>:۱} :3:ODlҫ(˩ _q)%R`/S@sI S$VVk sB=^O\4- ~u*!6`~jblORw889l zWL=^ 7J( k0&kiu^,x3D̠~\hN} /89f)BZiТ-pM)Tۚ}4 Z 2A.8_'|]v:e*oK_mAĦEykOy G25~NQ_v-؅cV̇ZL>dv i["˸`^Q)7 #RXH'ǢA-Nc`!En͎ˀӶl]2$*;X-Jgv^Nwǟٶ4w>-Xd4SApB)jiuf3Njm^zWDΏݿw[n@p *>FڢS!ɬRR+fMv1NH2Wf|ªg09 H#\{Nr6ݤANP3᯶jՔ0Omɨ Rc}0 ۩]Gi ?Gf45;j]/5Fc}p3\Vj vSCZPbx7ILt&\: ;9ʨ2c4gUV(> s##qK I 6khe8㕙Sݑg߳$#apr?(8EC!6l%1¢]lϛ==424mقrBEQP ~ w'  Funl1ߖyZP v9u vҦ<Z:ff~")(fnKDm~$;^PŚӳOF)Cg9Z7-yY0LZD2S~e4'~,zE|U3P3w3(R`>h5ޢfVIic\gh'&) &jS} [A^ӓѵ}+ßj.wٕЊ5:%:_uQϣ;UA% gWjD6`9NjPkidû uh|D:NǗ+j>fجLm wa^@z_3{aTf,Me2b}Kx"nS>0WjUNMxe46L9:4 !2bY*wo'ċDquItBUP\~L sl5t/p#qcj޻<\UZn $5圯1liK-!d~\dV>%ߍ:ѳaW}ftATOPO'~c-#dȖ" DtrkP9btDրQid߰mP]kFq$оź˼gdef2ދYkҌ٬ɺJ& ) y} /CK@[ ~e`kӭpw["ɧcp|QN*f W1Ï!R%}w.\@8ʐ…>QUotbIX ?K7ėЇ s9N{n%1Bd@܆Yqc-!V(.A/o4Q_/,RH^]+*˻z>o(J0TU{g#-Ee(׏mNJl;!cQ) 7tNvX}:FtLS@%J w1012p%;B$;VQSy ߃}SfCa-ݚ@N"Gq{А7CLUPc҄ Bcq2PWp -hT8}T-K0ь | IQ l[__V,'-VN^NжlOwX(- TSxfE1Gv]džL fc l%XIİ:<~Yp#}$297v,WгFfoNewЗ-X /p):fG ө  Alx~=WĆ}k] '$^Uc5IL$!'QMIlsՓ:iOR4g#I/ՠ=oDV3= zJ?A% ?qRFǰ4L E"|!+YY9',sK;ay ~Փbz߆vc˷sp;K+ H)WII$F53߼ƌII~w|G0h;H}fbnoE&HeI/Gd$ǟ῁$ eQ]7O2/lsP>mhu==۱;3>㐗ll@jK@h+d#_A(QE.x?ػ*rIXG=K}ª2Φ)4ziy_ ցmg0J&pNw~D`"ȉc<6g6=8(K-t :!ҤM!O4":Ehݖ@oǠoDk,H`Fm6 Sdn=Bd5󌼹DM*;͓9GGE>/ch2pÈ F6F<JҀ:LLnۣ#>Ǫr:'7NijE8w=}`S|X|,_Ϫ9fw~ ])ǫCm,F}@{78a Ϸ0!Lk$~i,S &aӯSk@F"/SX'*;$b6NFWT*=v47?>(#b'3B',\/8عg}6v?+&T%f%Pa1q)Y-g_Tgj,!8]RfԶP f.B| 4N|{l䬓²q־]QiNU+)S$yO;užɑk,c1v$dgFZj=$~WyNemo'G,6[2 ݫ}:dA)eVm5MBV%hfaj*'jG40/^V[F.gsEGCk`KQ=hthx &}"٫Jhj{-\b%"g@ .B.>0rYbWzc{%G3L?c#dD6;N۔uɳ6 Ul)ӵUWI;\ 4Eq/ZVn%mʹw~3 ]Bm.jv[ qbnpoFs6l !C'Ԫ y #k~qM+^Z=}ي5\zH'yh#7:3t[t!cg1'#2+Tb|{5}e3)%(@P*(±&ԖLȜ4&i<5'qpB"W5o1p}~Q>^dɱ@+eܸLS- &Ō3nNuvl^[q@/ ^'BV<ƀQަ+ҏWG1P]܄ؘl^iuf>g<3 *~ݻ '}A>x{ & ]"ef+޶^"BDq6Me\>ULY]3}-a3m}݄)J/Eꂧ$JMJ$Q:kYTr`KmT*))a[ Az4f$Wz LA g>\`iM(7d(dkmfgKY~;WU@W9;jy$@bШE aV>42{di3oT:p|Qh'# H(A1XӝM\. YI >l<);4CзO,JT|ӧ=T M^[L"ST"z<A=x4qyg(/AED LmOpy;Ӷ".V)A BH~c&٤c (z_1UzoVj*" dQk~mcs<\-P yV a"˅(Y52q|_MyIYq,*á JBNUNz;$lxῖU?hcOeǩ&y ۻ;[ *Gq@FğN[S.v숳 P--ٜW@L˪<ߕ\qd>S.W{w VG 1IUb"CwpɨLn R2Nܠ5u @zYS(JFU詼rĤa>+a@1SP {_~jxR r1TZ7XLȨ\^V8TQ dpp4g8EK_{%җ~A4Edsw@]/fˏy.C4U@92uP.mwhZV0e/7q˭/?aѭ@R=nΆVnk<J8NMy8Fծlkhk=]=A0w̩Z ؐ/Yd9B[Sn@7Z_c+]xnI'18=󓇤*9wsU/VR uZz9jKӱ.Z Z!vRrRR(p@Az4RWu-,H!4XEvC_-sr<B٘lX̷G 9qs&R3.6욽3%Xe+ᬩԤJIΦYܲ#s>b;wWH&^YUdeL̍!BS978|dyCр h;)f=)=eӪQ).*mZDMa ߶a(aLþn=80zS*D?UU3Dq]Eݖ_x~d RrdWW} ѹQꑕ_)F`(YJg~L+ fU]b8$*hEUD[A |#0j-67Bw?N߭F+s9=5U6&WnUivfwjvBߴngx9@U\RklluYfp'oaL}8h)mTk?j665{nv?8p?L[ B56 '#~~N\nA`ᇹO$+|; zKeq7vPtk,[3d+ة|&UPe#X\wLO8k0(έoVnY*Dn9Ou KX+I'nCY"qEAmh `,sҏ$x]㳰Q'@beΩPܕs+ aJ|2 E$:7d^7ټ:c~dArh{WnOwl}YC!mLYCQ 5"lR3Ut{n:#Sn a% -2]j꺍sWSu@fM93N f݀5q\nٶs9XW9d0ïZb@ƾlRHsڍnRҧrx{T\E*kӉ`*iL_C*[mH ѳ Cs|@+u1.xX/nX#]"ޠ~ӷo }jѶ0s *-7-F˄Hh侻ú ><~8 QX_dY}@&zUN\@ᴗnRY.5?BJA:ͷGpK3>9EA ӂtqQD7EESKG@m!_!VpY\J3K'Fȿ ,qhu5(d%W :꣋`J:$z9)S49َOX5Dax=4t[V5 5ݽY,0Lrj}jvYͼ9!V6Хf4n;-v^;$V-jo(x:\jT7s %Cc!xB\>z r/J> >|.]-RTU8PY*hZ O>+i. ;C͂ck]@Djį(%Nxne$ds>Wu&K{̙=a"wK JЕ䁆jD,[&صaB-Z'vjd&J[zYK 3SlXY{#,64 5"  (CnܡCė.{ ȤҊ]"Kw0Mcl!k4Ii$ʛ4J. ɂuAk] RJk&:w9tN&xpx\ \o!cE% qB{ o1Xh՗AXWtJi1~89Q_<8Wk,^VkSʗ[xMZ&КI4XO>z֧rauP箎#* | cQ Y]>:+w`cZ\C*Ll@}Pv>^%dr!'f?T^XacH&_/o1,gm׊}^E/mq}O5c%f(l:?Sb4n&ǍA2Yriqz8_ ߆&q qKw?sY^k#ZS4||5]  I1QEXۆrjsrӹтaSrq4P?bPSD}{\k6m' QC$68(9pΓ vmI<`z_J XJXJD'&:VQL_}+EV4Gr̻s\ & u5 K r/yMn.)Wnt=/_kGg5_kOB& SBˤq]%gS/Ve֑M^0ui')!<b]b_ڃiI&N)]<]nSzp#Ayo˅ 7Tr4ʌSbD{/k/U1YY$Q$Vc|~L{˔rjPDӇhBWX~Vc]nf@#3lp]ڄZ,G+Pqm:G&%]H%|-ɨӾl}cDŽlM5e#/U r qNz~ݭۀky:z˧2Y;C+g2\g`!.)#q 'x O;n˺9T?C*\H]+B2EfZJrxnBu$aӚOP0|mT_X1.Ngv4 3G0 iT20GԉgF)^%eT{En Q+6mÑm$n(Ѿy,~+UDL|wkqC[ێwt=.Iw튁.VyͦqH<<8eroZ*Ƨ2BkPzGοAkM=[ڣZ6qgƕm e ~N{s,B׏&avH/Q Hh ?9t;e8C` gm@WP+@u&9g+M(Z{[{9c,&OKt+\H} ~ڎЪp4p/P\bQh~V#Դg4\ I˞‹%^UJt:ѝ+|R3a$ I('̃Иh@wspg_ylLs@͟Δ`OWD$*㬩q?Qi.|%9bln\¬X)dRNk[ʰ؀3Xۖ[\eZUa%@JJNJ)čyjޒ$a/ ͐4*;QS*wty %5[0,޲IF7 1AP=0g0ǟĮ% Ś Y*nu:FfZk-Q}1s&2Tl9bigW:AsYmN!g0t-W^?Elv!ha~0c-&k6N= o[Y eN:7g-mmϱhP6%BJAUo1S0B-;4D2ZzJAE3MTadEdȒ 1n%d5XAyE,+1fgQÏղ+Uua[`{gn:@NE`;,gӲg)0 S8s!`p75_u~vq6H좋J¤;^ :kqbRXb?C .@U> Rd(pR+4.Z?%D }W' l]DyhBGRd^CM6SFLt.s͉H"@9CkShU0't؍`AwF\P\)Yke)!nAԏ4NG:]Gd W@X ,<2m%r ̈Uǟk1*bJ^v3%" @{{1K=|-Ca(#7_k;R];iDF]' s#$gQfp)e:20^9,o w@$x; FX~A\uń<{beZ4ixek@Hjʎ/*wM b ;5ŶѢ&) 6nMy%|K]ɡLG_H|Z8)!TmKGs8 pypK(Լ@ő=5e9lr.c?N[,՛Y-K%6w:>cĞ)l71 ONEc].+qJf+R,87԰*8?V$ZUߒŷ+g`QWkF)qp|L~Rx9[7 cNg{4/X[BYcU|]fիVFHHZ/ՀS_2Tt[P=EvӮoLcՐƙwUv 4In.\K{6܆?]Sjɚ>4znMRmI9[ W(,GM| 9.phMSh_UM92IJe,B~AqP@6F~gEb߇lJŁ(ODz̈Y My6>Y2Aw2V[=6E0L g"~Kf♰Ub:O~ eߠz uv#8qpBKvQ =ӚMdcxN2Y [%if?O}Eϳ7E 0G@?xٕ,YN>JCD:S-PBk~`oCk{qd |قs*F@ "0E z3R_%cv(d`%TO>ӷ0,X˸y SilFEU3gk}F\ֻ*W9F)AK&eR "YJ,[]ՏRGL_)._u xf2S+{>bg So12[#G 6gpIȣc#%F'8Y36}k{v>@)Hʳɀ/-)5`bɠnZ5bNJm|H v&Z+![$aG\$R$pcFmQ z0),퇷 \0-]SQSΪB!'C6u^`['{Rf* ]˸oZ{HNގliޙl +Xvg c)v5f ԵOC7>p5nYce7mPS]q0q $0f% z8LQ9/Xd(FYngH}}Uп4J& â˚y?'^8 ^ohD+ Q^*7۟'u9T|dD4\+LS..1*Bz=A2^պY-~ڑs4Y He{{y`>m?j &YfzDh#3#cCwoTU~" oizCbXsFsb' e.=v[\8,89 8,G 9ikƋVy '@XCN+g?]Θ&zH"}@Ө܌^&Z5&?AOL:`r&{S7 렽=t D 5՜x+3jEEDE\LMƱBƶV%<GW`< [w#qH9!|?5b֠!F` ;o Hv+b=.NMCՇ'y5UF65"X&`OAܦcpI6w~V }4:.`2ٛVt}bsQo|*|pVwnrw~$|nY"7" WɊiYuـՀ{lƣ6#RP#2m9x92c;{N̚nOTu^pos|: 9H&4'j#|P>Atuu).aa'ۺ6Cuj.܆5,%nouWD85ږԔQO? GʤHkl3WF&NjCrϗo +x#L7ij(UD[/5xj߹1S͇TۢN󎧆`.DR5a}7y\m`QizY_]=J<{pwԦba(-iKѺ'[كt:|cq-9f,"-;hECߝ*vZ'ӏIu^EMhVTKd[v8H?) EuDͅ FL r5k2햳y0;R݉\hϮd65'%dT؄-"|Ύz sy*t/p0"6E$r=u-|O8a;}M+-WܭnüU>z@L_LkgB<ҷZN?:b򱫲D(RW>!z+kq=M>ہ|CGHPS~ѯ4q-Ueo  2S ZV*;1cr*@}$O]i8GFZP2/d/e 1B vZI~yd2ӿby9$.RH*ofxWƭKY;3]nfL/i?uF|x;/b#V?%xչǙNCI;(g $)Ak(gqWtp/ưHОΒ'P a .-TH-,d<2ϤxܮFG1mUBs7~WG r\T 9?KWP&d~h7%*x+x>Acb %HT!OzEm<4(;`PsfŧwE0#<1ɭZ3dQuV8a3n)GHlrcPF4bw@vl6#3~|mRE,:7 YP4-Ye egLAI4 jV:yf{o({VAQzvazTQWa5%N*lX 0WH(|r:.'Ž.FQގ34",5A1j> jJ튱PmjfZU&=#UCa?U_}Bzm0ot#ѷ%YDU[YgsC)W>=6h*:m᫞ɂ,/Fԁ_mqz RWI@*F"Hh]0hrL"l} M(D(qG:Й0:J3{"b:=hkKUyF+xJFg =sªA>ד'l3ML6Ĉ_9[Tөvv>y<f"+_P"ŕ0k: `V26P4( ՇOU&h/ӆ>9wR[Ra m'"c<}1$p$IBFg ]UQ=̩9`+./- :MQf(zIڔFoB#mKXި诵S y RAӷ1Z!eD; !vlHN-j[xsIFM ^sŦ H|u͊4#6I8qk۹KAZ.6[ې{0HwOHF~c=_k9X3ͧ(zqѤŧߚ`f N ȕ}O9Oo;^MsC84Y'Ƥh%\޼.8[jjx%1~38U&V0!WZ5thtXqCv"GL>~ ,IȍLg1@U)s)SMD|)udLgT׭Z [!DAU)xLa_e{B\6]W/LÑO8pX/tUAlg-1v>pbu5}ؐb [eM)oBtР7m#9ʠPǻU_S,عJi|wˆ^Ry~oHv ʴyhdBR|#Х ϸ%@P3ǻo OÂb8*dLnYZ K)'K\eCNWQAhm{(+ !<+24oٔY*ǡ<;RqO C8jER[~-ԗ\obtg/ |Qy?-B|:r&ۛgF+Wa~\7:~8fwnJ3aJJ`(5 =2@ȑo_h 2kT),`/5DԮoE‰_trjg٥fGCL9ʑGtZ7s Q ƚ#rƨJ8-KV lb[CdVګx_b'oL%*"ٶ,Jӻp?Vކy5TH)gb\.%՞Sq2MC}CEBdcL|brh[t]I%i6e`D=^m :SQǥ5P"2AWHjYamZ~;b66wTX'J9+p<쒄D~{?SƏE%L<zǛݪM>*$aND:~LxjHJOu|U[cq5运G]b=BEO H&S\ V~U*^5^w8^-7ʯ'%ˈj\ZpʴimY"'H-E@,=eH\ A:i9Ɲo-D$DD*+ß>(& j &Q>x 8oƽHQ)֦MG#?vUozY9eULpz|̖nYs\x X8x5֞nGȴ_k6Hm>d~`!3gĢ% ]BU+?˿ q~vW]#;?2/4?EZhDllj^tFio160頍\VG` ;ǯJv@;u\GZrejP(La+иljVgWL(Nzlw#JS1VY֥`;}eܳ/BU .{0ͻDqWqZ TUsp쾰io/]LvZ؁7wԖd y3d*'wYj-箎,0T4HWF@ڨ%xLWLxR'z+4|1R0L7o`#:j$QS|pFTT%!doQvaҦq+DC .xk2;#J&OKw-/CO%eo*Jp KYwT8Q{B)ۦЋAϯfj?9;2m2 C0?T&6"M`<2 ?<4઴,n ?KsP9 "KL6wFd6S%*ՠDTt2(xNGCZ+0e;ѡ8,騭}>+LHvUUsD33 4sO*Z S%f(KN pݶ%T2x$+"H c&I B)o8P1a^ϟ⇌wHp_Z#BmV`J i?g"6IMt][/&M֐rV[rw0 £8.wZꙻd~ò;ZiJ{bѬ60nĐK%ut#G Q7t>۸[A2n@'?d 6aS .I~\bᘱoF7}Z\zw~FzqnfrX&u 9)6=]'qY*PjUFSLi1FXhAeFғ?}YhKc⑻m/=.BN]Equ/KRJhhf?T^C=ML܇IgH]~Λͺ;!4^-m%V(l\/sXA rZʋ vC`a,h+.zf*Աq$a J@q VZDQ\Z>4q|M p/qFlB}q<"\: Hr5jགྷ}h:Ik(Ǹ)ˬB׋Tx>`.- b !s?H3{&ѿ5.M1ԭf-uyɣQiCaOcv dIRN_czwBwݾIT>m6%91A5(qoUC-a_`s&N #88@gvg$@-·,h ,gнPԤ#seC}/k/*"as^s} CԘ:'w#N .UьP*~HOYmxgmVNavG-̚va/>!spZz9LE*/Z-X > OJeus;Yz7}vXT&w{vӕVT́#G)Mq5qYBikfTvթ|۳lH£+NRѰWEKv3p Cq?/SzgYO3HY1J dPl#NM)(qޛ~)82յD+gi!+臄pK/uOt~x*1v+ (@+1Hh,vB1 ׭96p `w=MҌzQ7%2&?f_qF]CBGJ1V́s._`w= ^&`y> mBzHVs_RfھafwZD7MMd*crqJ1o<Lݷ#[J?iVOi37='6;5߽>~ 4%v )O88-Zj-LQ xw(SߋfT0v:o^g3z 񎶄w-l 5o!?gG EO2ѽd8Yj r:M Ei.!18+71|yf y*nheVq|u21:eo:+IF|[2"g> HWEeµUy3ArvRu/i'Usp1{h=l!! N5[bYGm+ICl -3{J7`v6_!B9xh/f]I6%l\0qW'+d-&gV.bi cHdkƲ{(He;}1'6,ORp ]dɝ0/[ɀi|UM)4[k+5|=\fV(Ëm[˄QfKѐvQnuO%2GDʩn.q-Q"Hi< >.%>ٻM0Jϫ \Ee3 !zvW>ʏS88Yi "-I)~Eۥ@WyIi0L\ibl"{L52>$0_D?xQ h4PŘF@+5¼,a:pW2W *-i^hJ&A\[GĮZ7#=7`+/u"XS, 4< _^A}lL)`PeqQ}z bZe}~]XCNRSHmM)6e^]P>{O^C^ 5SXsA]/Ae ! .H/zS| OA rc!9O0C:X8Y bUPIV>Hڿ-諘-?1WXfRB^2I =_{8ˍ;ހV!9 EO>u<~ُXǬfe.>Z0z*EO'>^Ann) 2DEV P?Ĭ21B6iGPX\C} /'Zy '#A‚Pg{dR< V_޼Kޭ~'2d.Q<%u6WpwYB f0qtI94[{c-@ť*%=h{$2JWjuM1e U8ϡ4J"E7.E Qq|` +Z0ܨc'\mVpӚNګ =J9lTF@vt[2hjSEerd[;wQ=bM_VQ Ǭ"V~?ncI:)Ӿ pLO+^?'o`YԉHٳ؇Al8b/ 3z nO.'1'{3r] 04rYrYQx޹oP~"}`\n I#sV%ga٪ݨE@DTʊk%ĺ285']-,r>PA2[8ajGpHX3=fǒBhǚBP;n1pBrz;k>(_2\'E!>]df-O")sGY3 {U f fy@FMqfOAp%!͝=3r&uRTmݏ)tsS|\(>b3>E] 2錘^4T#3E\Z^4P6 v̽Hg~˕F+6Qw,a,{aF稼| D; -yq LQt&e0\pC#٘VP)Т]`r;/neT8^rV hYR >46o(5t m`yۓ2^P8s§Nf)߱Ɍ(/Q С!IOKLAaِ]Cr;+)5F]jpoֻH2]n'W=WzDti"Qrh?s V5wZIy |.u2\X! ]/+Li_1a% 0J+A98)v)U~#Da)ZGm.ŗXq#M ަH"1P݌ ?9 4#j -& TKrZQyE/pИGu7+>KutiA;M??1EZ,/IbHΎjX_ĪM d;c6/g#Y"P ɚ& D/cC~>6pjKTfĬG$,ر1KYeBIY/V󈅍Q p-搹a̯4PJCx/j/^Gy*LYՈy+v/C!$TOe7R2XÊEC*+/yHo B)e'bu JI1 gv }~}5Za>z#ɧCEe?8>4,?O*&QLUh7 Zصl0V/C_ <1MyS]c*CqHs>Ubj62%"4ΉLClLNg \׏븐ͧ )Аu]On=ZXiLTp]'T Wlc ۖuْD96Iao˅ m5%w`H4GQL٣F7qOAny3~QBX<3D>qdXus8)t:thES65>s:A@ޑ|P:cH{C"$>/45X%ԤT(:l.`wARu҅d< ϠOgҗ4W\1|i|$/c _K@QCZxHvz-5G!..} 7Cᶢy@=R1:7 ǡLLh; Tw/UwS2]ԕG8Ň*Ya'J*!ݍ-) ǞW'.ʾl"1n@Ld 5!UVʵpOwT ȻۚئKsad1܌* dRF%':rIE># 6D@-z$AǣeT@Dϵגrz?]v{Y-5wm'C)nRgGH^&Xf՚*wG4m9>6B|3Zfr9?CPy~]Q:Nkq#n@;@C͐P4>2DZbNi&!Cq'?3J0xD*D/{B 9m¢ap?yջEݤhJ^v˰QVca߶]pq[7hnI~X4FwF 0h9O=RR7` ^{_|:H&jB}J= >,AĆ< #Ji欓WY1iyL\Mgf!Uq6[D7S?-[^uyIk-O{Hf uU?F fMzWpɹù>t]i c6-O/DA)j:&n=p귰f4jC/.@o2-Tx|iFk{f:~%4Y(XExɨoCdh(+ 8#ըXFk~zė7ɶ93Pe*#L9a6%5X2CSk\vER%כiWgEbAzaS]JDd|QEd-R "_ dc6.łh>ͤGg!: bQR _ݶogJ%V#79yX_a-fBE s%Q3l&6-}H|85ھn%At 9!tgR YTv5ws.j)`4N; (wcv:Xփ 8WJH9U9%)\('+[5ҎH09sL8+s4L5jKWӸ}u5R 4TQYV)c;ɃIa3JftiYra?z(:R nJGB'l8`ow3>A¦4kp(Y~&~wsnC KhH>=4F٤QYXfdMETQÒh8-D"L6쫕1mmNcβWvUtw#uMi"UClEKvE>l.* Q+Y,mG|$4YE@ufF]6*;{4Kb=mJNг K4,5x%lARb12!:W-a@9{>r]Vz&5PݍX?vP|mrPU ⢑ݜ 1i[@"Tliw!XLuxPp'^ X{汛9[X@\3 ~u<ײ{qwO!)[✒33C5Nr봑n낵L9UӼ zXp~r09{itzf4`-=n@pХEm^&1I)4鯯F$dȟE  t?ȸΆz&ߞH&[5lվE7]U[d&W lw¿:NbVf2oKSY GŶ ֧!q14qv׶cjY7wBA/n') &pͻ`кlV֊ɀye"b9-kƈ4٥BP9vKD|A2k!)z.% IGѰ=2F"D6M+!*d-EmL⏴"XCU4'iuֽie:2T:<>Zw0gtʊǔ@kXܭRPA~& rǙs:Kmri {cc:G'װ`; ʋ}IwO+Ґ+,`P7O3п G3əJt˥^(ǂ_žOL ѸG[o5\hY,sG 𦝍?DAmg/|Z$Vځ_?ɜhsFٴ]dxm({{X?+mNȴLg6S/`5{ʱAd9$qUfXBEDRg|-Q%n3љ[E=Jz1?!QJ8Euxw6!}LM=+KE)mfikJ^,T&,ӓŨ-9у6lv2!r|w}}#Vߞ@`-bhˡqnE0I軭6'{(W R7Ozb O fUCX24YCcOȗG]78Y  sys(e'KGp-ӆރݎҝE0{ݳBtd[eEn8ș?:b)J T7O:^M{SL훓~2N+ 4Bނ]L7I#%ʚ},B&_g.=s10,Cupvʊ.Cg= FAˆ[T V:sL֖N&'5,{?C1狀I‹ӒΐҽRhn}EIDD*55'خkZUPLEtVtB!Җ=B_$.-:@1{[QH iFW1ü긝tʟx(cl;V|_4 ڷvBXC,{Ŭ07Ԯ[9@ #6>.ţ+ҵAE[`Tf/rF k|+-sF6ʚ`W%=W,ӴĖC9|Ac]cr * N"LyYxG)0۴>wy^E#[l X,SB/¥ D)H3Z2#1}دj@µG`O )U*w|cHynESt}Gҋke>g]5iXQ =܆6Ir=VЫScxLnz)Ula єwb1'+0>ؘ7.q%mQTD* ",N\hNc4t&aQ:p~SPKZc.< ~8J+Ej'!{ (gc;&h29k%ic*13_ppER- ѩ^i~1УwYF+2?GB;O* bE`zusaLh<+BAryuu/]mAR'JfٔށM)n`53$RJwU;pHv%kB _.YDCxLMf1'$ 6h/PYx'HF\>J PȺ!-Urℳ%3TwGrR6('Z&niRXGԝ=*2,g dL&zuڐH̠Fŏ=)P=4ݠ\0DB9_0.j'P:lՓr)g;Nbbrm8o~%;G 怷74{dI}Jiu%G`6i=/3ǜpa6lm>?L8hv'=h>i8֧i"To[vס7w Vt}fN{=Ho+[ρ 5Yŭ+${F0uCQ HlnpKI.lNoAHR˰6C荥#/QA-}`홊-M DoSuxNE"*p{+G!g<-H-xOYt-,quIRdX*T[_Q`]RE ]7l!K%߸FDtQ hn2J3sjX #N:ʢW>^hRVdMrAhD#KPq:A͵ %yBFG(ᵽi!9qn1R(U`/Rg˫ȚG"%rzOX`#nOpsYK2//(&p>[j\SMmVѾ (^y^~?+΂/)m:cxž2%PO~wOX|!QKir9VL tǣFϵ|fPy󧶥L8ǕIK@^zx[@* ?|< {oNXz!{ohF',p72ͩ$6pwH\5A[F8۩PV"]?I `DA}HV{)n6sGw(nd_=aI2QQa@B ʼn(̈½8Y@hpUDlOuە=P'1wOpWY䪱=?5WYwn ~%Ǡnûd(Dxg0; s. 6FMXI. :):&,W?uK'֥w ԙ}- ~5@!RM p,@4Y>Ίm9۹l'Z f$t[ bD;]}oՅ}5.L{&cDi 3m>0xr'uERȹ$T&]oBl}m -Uu2#[4RO/:'N0oPK֞A`lryMNH@-j{9<;zNvːNqp ڐv,E/>Tc9yx0CM>-嵳3EkNP J:u[K\8E ( `"-΀澪o6zˣO) ,3 4[V~ t4e9?ŏw lU䭄/ Ѥ{>c3?m4w"vxO 臒_/qveA?YW`\)Q$^q BbI}PiqvwaPC2QPM[ieAd(jF-Ul{4>T⺈K^55J4ݴFI'E F۳IQ: ّ}~箠]VDCN坘q(WZ_r8{;PNsj5:JPǤ'/[9.b'J_ljT4ɹ?nэ+ dg QA@l3/:s劻z˸)V 4Tɟ ^~^.}ږ>W磖d1m~Uln3 eRWG?_9/TGQma`0EX/Hx:Uj5l"qhQ٤`^*z|ϲx@i!@"c/* UA53Θ ܖPjiSj`QzI#cT%֚ڂ-QAsCFeBkq*,s<&Hyt. /9,ZQl9fK dv±>f #/ k60R`-NqafynP>e}HP#WRHl)<:` ê?lTaJ/j7C2Ds[|% #Z<1AL!ŵ'rwRIlUm($w{h5)+. Z^XrڗҌܧmб췳2xV6n8V us[OgswaEW%i햾kdQ)$~;)(؅3ׂ 1)%R R0=UZhLr{XG6oe~MҍE_L6wbTdm~Kzٙwm3u،DYR/B/4>/#ߎQ ;y2vj$GPþY`+U9*V IF=I(i"Stk2LQ7lu6^K%ú6vI;Hӳoߥ=-kNKY56O.Ia6#'"( t&0C/zT9,^F YTМn~߄w#- \pv?5u嵆j^}O8JnkX %lz8m%'PӌtţQȿ1 ׋_Jh$]@VT_ԏ0i\>O4"T~s"k~~1:5.\LKY Ks!zkc)E>Cem**9up(5h;$oM8?a̷\Vb) ޓsuمM@$6bdG41ᱢ/&$Y@isy0hץ@$e(X+w0LM11PI&O ݛ'-?0_vW45o`_-S,V:&W,icΝp1‰DIqmS\qD8yo/W\j~+Qh]¹ujk+yqLꌽo͞[g@OO65$Oc,VFF/eVKz%=R7#FWp h-; {o UIq>Iy5Q&7,#׽ueQߨ;4RQH52ss*"B{#10:[WH`1-ď-u8zA`$ڊqݘwu~53o u]<>`j+);$5)pW4Xdy-7CJ:H  AE뺄!Ӱ`ñ xI1?|A']#N8:=U|{Vr :"#o36'Pn`NeGhi&T\Ӭv̐a-3P^V E\6SAL;ts//q`bNAmȾɫ/EWωRIx&b├LPUZM8ERR|y!wQ`"Ml~!Dznjާ;M.IR/N۾ 'md:9\dF!Q=zrҶ/YF:tDC=wz%,Pk̪o;Bj>LQxGQ?S2zM|x!!-sJT߮IcWcOB\'Hg_`sUpO3 ɂ w}ق|⭒l>Ɋi O0|`d٪69bB?yRs5HEE$KƩS.+AujA<^@0 ϔ21 C-Ǎg׮gZE+/FsZćD >/t^BHdpBr!ՔaH#_lL=ou-K=|\iګ˻'܍$W&Uy[\y2vD7#C%J-WKƛ swǬ'腵Y+sպOI."ӗ,h1i;x%pLS"bjo[!.(HB}-T= 3zLȤ1W$37.& uO?'\Ih3T1f=KKD/sy/n1"|c[&MwSjsIrAW] }CB'v0\P~e&Az9ނڱy3NiXL(ڔ*ԥ,*V6 !l;3>?tϴzl2PѼo=ٟJ2pnd#.{%Jp @yՓ2[v ^%G㾓!X2y)"$GxPȧjDwv_Xds9wpPi<n-`Y-~i)?rC"ö}^Pd~;Dld WEϻC*ZIS&V*B<@lӇtDA{G6o Y=˳[8%`Uzu~14q[upԞ #.s}hO2< Ev(qɻ[oE\ ?q`.:ղ7t>35Fa?)mjd"끱! ,l5-i\Fˍ߇86h`H}p̓H !Xbd55Xt{}5"_FAbLZILӥElHE,S⎟ %I*0.'9T*%7܃1J2>4n/_"rK 亃/mk3/HCs-gL}/䬖F_#UУBmqػPȍC 6 ItIWnxUv40d95 N׏!  4LO!Ҵ4BOΐff 8Qr^iV]PƇ\\5ze2fy*!8ʮ$-"C!m`^# RD Rީ*{!YX9=Txu]YçKƦJ`ké}XߦvBQcU]Go?()F{6;g/T=2SuTߎA-P@hі}_N1ۮqFgߺ>9c _xVGdsQ-NӮO{&)B%K0L >]cTOA˩luHbbX܊/XPza*xJ8rmiIuȿU ǽ/dFR*nX Mlyt~nˀ yBh$ichˇ"]k=ZbUF9r-kɴRBLN RrPk9\RAxo>b#-Q mZ =KHQ10!&tnHzThQ*=͡F?C>&ԮE|0{,<~?yȫ%\@!`#H`qjdRes/"S u-`_ fCnt{@ܥ3i^sPZ0Zc3<]ۘkHXi1C{dlQ=Z!CC_Qx'Rr߁)Yik7j2?n 2Tv5(<]`[[KTO OK> zgz|"E7#^3֚b㻨sqв}JqPc'׷}I6PHtZFCkBwBDBEklG3׹'M$sP֍:_B^fg`m-gbӨ@[bwk|fPp# ܔ4½Mw>*7lQ 1zta2_hL^6dFa%bqd='\nIx!u09>̳0fEӰy乄.b?eQM6 _[Jn|ZuM"! ``UZ|l͒rg?dCK^|/`4ؘy\%ET͡>qzUz9zW6߸\K3#oKsS᝻\s\v 5tnz~}fxql/vXRFdl %՛ڥ_-`Q^ >B`)]C0j/_ DQ 2>/iдl-`6㗴5f3FR` ~h#0߬AJL6ڵo |3,-E--Ҿ;YYmőr,ӁYۚ3on2d7ԭdKtFjW f@4w 'UjlM8 T&.ć0aj>K)JC]~,Jcɀqt|)JlF/fpN̼b*1g~*4{^%Ʒ63BOFP ܤoʲ킮 =a)͇綺c9ObK?^°Bm58 OLJQM9MCћ| MXic\-y}TxwM`M*A3. k;oޮ$*,fV{3I!|x\wg4V˛]lU$3j҇H4ȏZ+yg;w}{$Z6GA^KMamPX8K}j2gk"ʒKOfL`5y')tI\؛Þ'ɐs6KӎY@-k=L一Dcf8RB9R8k#XKZ9(Ҹxق:Yl3.ly1Z!Y ~ID楃\e,^ >}):""mW5W઺ Sx O8ʺ# #N}Baa,%Ya162gҾ{(]ܲK«!W7 irXC[fQҬ/|£ni!M~jP[)`emx+蠄͐.nC tS;Fs(k yޫlu>'EBV!ԟRP.S[;̈́4q! *TX`˝4+Lq;uVbj*Kխ]K(I٧l *sÿ "|1 ߕt%.ɒ$o5[XbX N<c#+PKn`9`:J"+ &l;_2B g}܁ibvUW,q\\|ZO>8Y$SH=*?7ƲR .M*9>ec_}>Bf BE=sa^eDQn 7:.TuS1;$w'&C-.6I_?+;b$?+`Ïy2W6ՃX\&FjpvwHiIKYk&s֤,(p!>>&!tiGwEX ~ѼEVB]~EyjHCnwnqѯh2acOb.Qy9u)gZZaz#_^Bͣ! EAwjT99miڝԝKOp1ͣ2T6HNӋԑtI>[6w؟ax="CoV>x|itk5Vd~%i^˻Tc3C@ZO,>K~8B;s]bCmٍ( #nZm9˾Wg}S߰\ASG8_!nȒ'}*A R @!J?(@Pи'?[o3jgudPٚ:CHOۉ6` H@ hr2]MJ'kR;<&O~ī8Ye{8O4t7&&O?6*^0f~ߗc_)Q)3`=j NK86O+-*.m$Y+'EJG]B8n/֫X8Y9R5-;aJw}澒3 R;Lߓ^gf2 ls2c\*p MQY2zO- Q\4tܹpi\ i߼tOaj,wV=qr! Vki ZN%IMu; BpMn`^tE,Gz:"ͪ+Qeb\EIpD>Y7%"-jb>):ns|.\k™K*RNء?rq.Rd/(a EӺ`C(Mq<,鞇*==h{ALT7>\"بcԢmO^U+C"M pK!%OQU\}1W(>EͲzo=R֬] PŰ?|!ZAzri#4f/;ی4kDmѢ[ 9* њЮ}k~ޏ$|G8 z-'|6"xF$f_IsQ\CR›,\m ,dg7hj9kPjJ_{xR0(Ehq`Ũ*7r$PK)ɶr =_[*qI͡:ɋ;[i44zL~܌Yv:;cDŽ,͞<$UPS%)DUv:灟C䈗gnLr%=DM0޵yKiBn'{ryn*aD8ӱU۷B+xpKRpg,Y Z\Ks1;%][x (wWm_nۘVsu\;2eeL])ڒ1 託xc"'HM0^e*nЌ΂ ? Aݭgc^9Rdh ErE8Pޱ6byyI{vHՠCe/M"çSsǨv@|&sHiX_6G!Xe4Az"ޔ-LLͰy ֧si{~ybts M!Ʉ*4͵ ^ Mv "ؕ .xwChh7e%T&)2X~dB˜*Һߑ@ ׭9̏#8ҵPӾQw}o`jIMx1 V`)NR>LPŞUqѴ] ,E)v7E%X `SDћ9f-0=odiR(-$Z'$\l N9E1"p$Va}WLE-We7S5>vJa*Fءc ޖ#(a1B7+9x l:ۃ}b]K%ikgn.^ ?J{a5LK1lW#EV+7BFrBxZHz'`R<>%X$V')<Qln 8H³ъ,ARj`m;TT׹#1GcvY:^{RSq3Ч|xT\ qT6B$?Cr[V9'8\~CKKd4 ɪɩ'}(,ݪ[-ɏ챐q,o]!y.KS=+R,޵D 3Òj4Fi[}4C^6wD\4`4IT?c)GL"QI+3:; 82Z¢r$QW-;YM=u;&pM{x,c|ѺXFН3!-塺lSﴟ O`xWT6 2D>1I(32EB81gc,F 52pn.Zݩ`C P,(0c]P26<?~C2""zX Ē!i% '0xr )y ;tm53c$]|AlU_aIg@n:Ng S~cC}a{ݷy_+C2ݰafdҸǒAAQr?]bHE@B8_jyz2vDY\^,ɂi>6̪3diHvS{ kH`'ށ_呹h=p!_t[6FG"'7/VƝ`Y^]soZIl sI%(tPpns }9W#U%߅8]6!tHG^`Jd|ڐ4!~M r3xxxVypK]ur`7:%NjQ FQa|.Aw?3= P(Z@p \mMxz7 w[P2<(`{fco2PӠFC& A!fJ taS"?g;H bҊIR]zMq2WL{J/L~. 4vLܗa%XGRnI b3H/\Pw=9ˌ-X 鸉;j#ë_L4o(ML=!o!' "3p.9[zSAtM.ٹ0\61l:]/uڬYB=Xp)wȾ }@3xZ"v8H-4Q`~r%z~c- '|t.>6 ;ze,:9IGQJP:jq!XGDfpM'"c8&ow7b0_Zp|"Sͫw NHicͥu3"j??O\v{yVtX2r1@qzd3dOV:[ *9r%bBٲsFmV+L;WԗGCh)=*{u|6yG!w3h1c[8Zn ә~9ct 6NnʲRA-Ⱥ)QsPEg5z]n_=>LE^%,{(WMvwdJ*g53ђ .E 2k*K(arA yR#V-)|1wuen'M:hd+҆.R6Ź~'nEv9붋\)?SG7pk'$F$d6{5Gl,mDߌ^,LnjwA=[S;BdF?%d롏%w 6Zg!bGzgL@~+۠UUH#![xyT9:#qm*q!bbW"bBYuHDXCT kPə~2yMf=2{W59qekC#XCl ?cSZF-ʶ(7 3t mVG( yty!8I+>qNPJtVNАq4ЭUAe+ td`i[=7 ӄaMdPIT7pz4k{:$LOԀ{h!Ekhڌc:0M2KN XcJ0ka}zK{V(pd؁= w" 1gfRF_@E\Yb~9~ZH/Z.coxRbfATUst"yUxV/<YHP5HY(!˷a,B"gī^v8#Ja}rw}F]#3^8"ߎ_/mcȒZ$i#Yg=؀W uhou2T8~Qz4Vn'{#V?Dh1ȜՀ?5͓*]ܬ5.^G1OLgbJ&Ytaߢ TEm=cFJM@vDvPAy6} [{V)Wfߺg8 %>p+ }6 b4pTBO^$ xs_dz7s]4=PbBGPe;Cl*Y_12lmV̕Ն>?o n֋7+'% t3%FcpgٳE(l#{{M&"0+<#\3 Y0=*B6߫48Qm&a]btl u\w(E  )]9Or =45@:x]L.[* xHhGu2 h O[+ [ho7:)Cς]0VS;1U[4&x/6!n} PV5bH%cf:q+zk/B(] d$shi߮=_k%w*_NaC`'_?q6|ԋ.s#S۳mH$XiO2iG6fC?=P<2^ m3^W0? Nbuf7ff=7fk jӐrculֵ9׮zTJśl:A'O${)1?L@YA @ì*i[ž}Cwi]GKv 8g} 7 ʢ;%O]Nl = ~/e!e!' W6]H_vqS7\K_ؐkW=;yT!>  ǿ,cA(8tVYQ,^B$E[5y#BEh﬙2Gnlz(blPKӁ-'" v;O uiq 0OsbDR%-^=bvIWTj72U-D_c# +}[&#\2=B|:]5mAUQve頊W7Y)lZ{ZPZnujjGC–L1c\h-+Pk߮#3BRA)`&eB`R 1'Jo-\+B!o* 8}ܭBkNvPl: qaQ ?tQ%!:b#c3$ 6!,pO,^Xԇ0:J@y[x*7Q[< x_C7{VGˢ"u<?#jvLm՛Rፌ,r Iƅ>oA>P( 9}riょY'@]oכ7[ĕ,0.L@cCUPUV֨[ `S3PwYY:|>zkC|[Xq8 {uR^NWT} eM}\\w$a( Y_**G\y>I6$*KvMq+m<\#!Ql9'QBL|WsktaKvҔfVG6,PY@&" Bx {n~+2' #__TiBG-_}IAϲz(A[g|~ .r`ZHÓA 1 xT+8ۻ$:A#O%ZY2-u+ڨ/i4]7Apde~Mf[b [ۯ RG J8PO? q!pS31_0&z-{@hwA1ihl0`seסlMᐁC2dM|_:dS~QSHJ@ڣ*}GpDǠvA&43qP8Eb2*F"mj*|bDBLH24]LM-ue=T:WV vZ#MM!F-C d/ ۧʤ oh_vUVF[Ws;{fJ޼XC[%zRa Y|I[dji2ZD}_5csΤOL(Mf7a #;;ʡ5Zk,x)X#6P٬}zl1yEyD3sk+ |8 Փ1ۂ |%Tis;6?-X#g;g~s:֗S&M!n_ZsN7D| 1gK hR7v#Ӄp{{X Ns70&i/'bg)@=;Ƀ,r+b(xuT-)!U_bs~A&gcP]MX+:N+MkG 8 LPx$ &+@(: MW+Vƾ 0+إ<7#ᖁ)Osʋ}&C=h𷹓d1EH5Ny7j . L{PtdH2ut島~0C~ksAx%"֌Cphr;mG*`jr:Խ%zеƾKxb#X;~ #Op˄Axg ES?a^?l.3Z;"xtԮew-Ju qeHGk$d@-/7ϲ6&RkQ`14%A2xkՁo`s,f!i݂"}ICjmټٗsVI)QzʗJ_7igx@QDRI۶G;ó(fKĜZ Љ[+KSTpdfQ7c9җJF#// /*<|]bY_ CJCP*~-2ėY0./> td벸 /8wAg]+tOji Iqz2fĒ\'e˚zY۽fՁ[(O4 xvTsD h6j-8+pK $e45-C[ƌ13=]bX66@zl]jסc\E<eDgy_{RoC1zcu uqs+%6K0 ;K5@\z0GKxB\u؈,϶&&|3ABڻ[l9?ԭ"hXt#9^ZADŽ|#e`gn\}S%m= Q,=; ^LDk]y+lx4mk贾@9@(t{?溴1-XP-k-ݹZQֆ qԞz`OzUR65|WZDO{?H}`ůI:Euncs5]MZg.~u|)8%ё|g7@yZ9a-0g86I(]j-teh,v-u16P#=)$$ޗnJs*a[0T6/M*""; d`ej4@K4s%WQ0 ~(W4'OB\"kKSQHVT|SU( _fU]-Aψ}~ !]n@7~Iϒro}ikꆈ _ u$S QdW l*H40%hqG-4h=E^\yukwF^X1 g A9?=U^$ҨwVXn+2u) D?T2$"x+ZBM^1t#M?(¼R? lw;sz9:"ji'MN)h ؉5VX;[rWBdCb_Sx`Ġ鍄r}{_Yu3bN 񽺷orPyo>M nWcֿVW[4Փ,Z’rHc'e֍y)h'Őp3uCE^= 4qQ~/iO 6OSASu4H%5,PFs=oڥ%a}Wyݙ::5X] o,P&AXq~Ws|o̫X˾{O̱r`[ i,Qnig\Inr]pdp'Mc\ߐ>dFH}1y*ѹ,:f'=%!?[{#wz:3EXpTk$ȱws!ڣ\ n6/rd$4tw㦲]$Qd,s'W*,SҜēʧ_6?ߜKz-j_.\mO6y&iEvejɾfPi•JBX^urD׵ck`,M{_BGAq+K'жM bx^H9M?A2[&/KeC@l)kV؞VڔDGBnvJ-:<.Nekd&-ۋ{TWe$C#<::HΥ_zlg3Nq6W$dd8$~VL5{-'.*9e;[,O&P1'b|轈v C?qmz0GFҐ#x~G*q|^8/=Ah(E d۰˴+ťl9,TP^at9ǝJJZM29V-OK,jcVD[T.Yba.qayt>vL r)f!a"yJ%C/wiIu3__+բS[lR{Y!CT|yܼ;W70 O~U tK]Juy͂g?AylG/b%Ql@ϳS>FtQ ߳]M_j K)X:w9-98˽1Ҭdʟ`\D9vF#ɇid gbohetIqP+~$b̂m,rKpEoYZ]IlB_ZH , +Gb7i=B[D*>_Cp q}{6ȰIpWXbnzA`!v$ c}^icnwTE4]S  25gOSf6N+vs']ovWqrs)5,mWՒt2`p'\DAxvW5ϤʍMX5qkYQ K0EEKöG4cXǦLTw%c&pI.SfK\#kfo1a<׹.TuzzՄh4MlZ.vb&u{3 RMOȡ{0,ǔmqDyjo+3:k{&,pSu _)4oה5+8ZjWo?wu+ϱr\o[m/4טh/]9>dk`-B7xʇ/SzۑNܵ?KE'"ϡIT2wz*S7^hݵhaŮ,]($CaPSBY|Z_,>my"=+y4EC)aH]6LY043Mbww o&6N5r_:+!-S\_l֥:mScwF *ء -%93MlJK"ZaJw] avx\vDɨ/y3KP1".d k/nJRgT ݟ rW @BY-|+G[3ƪy(sV}Xe7hIF M KIYN_!CA6Δoc೦N'S)-aj*Q@TUI`-'*ڴ&?NC&\ 2{:QQ'᧔Gކ6&R~A5}n Zzm_:u08]_Jq`b9,P Z &j[AfPT /Uȅ!,27ڢ4a??0l\3ISDe[uab6#R`kX?H9 BZv7rn꒳%tѲW!L 8_--"?f s|EIO BEH> ڷ/ QJ!;YMtu bKrS\Xżt2fC ipOCH9av_k:|ه3#󫑇~Զ`Eup|5tޥ,OQ Xa1a bgQu"LPP440D@紂y{43OFA]b[ݶ_~NwEw-9~U F|II+sYR8=D,SZtF8k P9{YFs1^BCwotgr@g7_q?66n~4|T:Ql. )Eo1hxzoӈXT1 6 -Zf ժ#7.H;uĆp;i%w.RD|aϭZrvheI%kET8N L|)l,uɲk}G]IUoC_hWtWFf@llHGJ  fŻ$7CA.!vgk/W,lJT)q>akXA]vHYb.lp4Y~8jDN]Vg'% rO!%"=ryKbс\xIR.~}(:@ I%^4uF+})/@'$m *ŝtcug)OT*iU~^V5%,AT`dO(0$'s'kTNADPaOLtClMKg}ԏN֞l'lE|JJ3d|0Wa oWVSip?xl!6"R1e *elhfbދ,75^ Mw2DeƝM$Z`e" t׉% e! 2P uOwQ|uf63JsvU!QrHnNbl߶64wDK|H >ּ< n|8DhFBr?rs Wc[s_ 1fn~)dlO*Cy6JnA Io=CFWfw0';Ta#+"Jc})oǜ&7Xb"w'swW v3㝉߶4/H6J?G TXL,ב7+ Jñ\<)>+<{[-6 .el#k='^ZPjHQ ZNfcmc'bxhvH]yQr7j8 _:poBğ9_TVlZM`gTt~ +Ψld|i*c{=-*{P& X A\60ÿ#SjS S9و2P_ 9g"hCf[})3Fګ,9DŽ[G3Yze*a@di+^@ nvnSDqNcbH8QhG/?s v~\-*=ʼ J"dimHI=OdJm2*3w$EFDS;8^ WAt'TݧdPmvXڦ _3'd :7D{64_ QZSEfD<9j|ta6Le=6 A"zS7P̏Tb^PgHb*s&%2ǁ;R$e9ZR?kU"PD v#6k3'jh\2b\Z3}VDY>!sZ3 PA7 mZW$鱧FC@ fJ? ǔ%Åk&3*JcY@zڢJt û3&HsIr#&/2wW|:[@T$8@4B2q :RU>w) *uWنԑ dufv-0Ǐ߻O9#s2?,r^l)TaT`m;F(D_H<xXots n<3axf{#y_c*%F`ھ0 9]pzma'JRh"b]i©|>k/Jq`q.w 6BrH蟔GSrl"6ܰ\ZoљI1K.t[ )BJV&w)B{T<(4)DŽHf?2Ű2k%oeF u1l\,ƩdH&r?QZZ+ul淉X5g"n.!O eo v0Nɨ9K<\ [g^-A\>g`م/L z[SQ"úr5\  .rP-7<;/F@.sf9hmW6u)VSp#ͫ,ج>r09 `bzK^54oJNo@* -3t t͆iSѸq;WX]0EcU#˻i6%ش+7>;dxC:O[RT ^f}k%mQFDusQr@t@!CM6R90ynV KA K`ȦBO4pdՓXO P eid`wGQ mX'a0Ȥ>1RDUD|+ހ;>T8ut'n%ڎPĪLUy̠xsl_`cSwBO\EQn farNHcZ+HC\1]ӀLnCE܏ cң)&Q5wjs,V T44ÄPS2sGFKUO&*5PFI4 C&znjِ,-I ܧկdX TkP #&Ys0(|a* 8Fr65tvgs&S+:bC27a_eR:sҕM_ncEE'\g >ٰS}IPLaDalN92tDA&!!Ow(S@ &^}ms/H14{B^AG9 /d&/\BXZ#N\tأXGaZM #!M׌{WXWcV\X;;䙍˹fWZEgg]ZJ a% db[i#%:G#WPl])Fxf$nɰ o>3^@p̤9ïuפڮKP]ʁ!dw]9@ 1RZ-GHzi_lj3P[NNHÏgxzvsD2 ȶ{&dGΫ[9o\aZIPBS*Tvl[nO1ػ+&9LK0-#MsUQzl,F˾2Jh3 G/QPF |A]'6[Tݫ 'H~bc84T_mV`kd8H'4g3OA, ~WSt Y8~(9Z' Ӿ[>F8 p'ԩT$.*$R|ծCH:v;o 51S-MeuujޤvG)4/8R&NFXl20vce(, -fgNL1Xb)wn*ʹ/}”Ż]+6am P0nD,|pon+5y^8?~@NLl>0)Rh JY} t{-1p U5R!|YK*գ"*^g,Di>BdkOu^jA19K+G@j_.ҮZdRA xH5#*%u [3'0akE/m_ТBW)$"/NCֈI7Ԍ:kϞX Ircp!)(z~+nrrU]_#k@0K~֮B(YTt0oq)H]|Žu BA"ؔݣ=vC;U]Y6N|0!1;9( ^$,fqy[.hcHiݯTB294JrozҌ0j%Ɇ`Ùj` (O08T@i|d4j/.O\R*^>*7&XGi-[ z+7p4־Z x_X݅J j%i/|jjnmV=Kc[V; 6gxa:XM\t ~'ޕRbs; xd6>K~%+bʪBLvʤOL??'߀'8~I < h/e&i4Mi6Ôf\* q>yc,_)x T z6UZM К[4[_qB~a%qYybfJ9fLUuj Z81'7ГbH•J*l&և5N/NɦS3\iݚl؊E3U8b ~LCA?"/K(ă{N}Q!]K(p e+3z\Okp0LA M 0]**OI7VZ<Ê v޹7vL PI"@צﮇhŅ)ɐQMs+.3)v>l uHDWUyW@ah ]R6$(ut|ܶs7GJAUGNp58dF/?E|dv# : eur}O"ᣋCbUI΃b#MֽG_T_.szuGd XeAH Ov{񵽁N2&,jh+b[)qNS)|dReUrB[ ]Jg㡸ۓꖶ!kt.!؇`YjBN~BqDG6#b"<37*pV5DSQv\:cXg]X NZFY@vI]%Ɛg7͹o#o.j}#F2eҠ;s +mkl$=0p&а&ſ2ɣKnb>5]o"cٖfc.`( jjKCJ- }=QSj'(I7L{԰gO7bD&hO;Vpcu:oxm))yICWeK>-:z?˅UWl䔗wpMa{ϟS1xy(Lt+a޴cܶ⮣ 8\LnJYY2s2W'i͖, hʈWR6}mAN#] 8%ӄA0U'%'XMsD㔒:q5M֍*{ Q4p Tޗs]ژ-vHK '@mk~RϹ42^'>`x)d: 0[1N5<~  bD|sZ˨|8u?*v(1X}ibi|p>NmQmW‚AgLy402J'/jî±_ T w~ޖԦ$/CL-\#/9G6pNXw]seIkejcUYkƞD:da1?NxʼoQz#@־ҕ[|HLO{>R5^IYn (PBڏqƲ8,(rä? #Άy# X:,5>2ЇY#Q;Yia)^En|[Ob6tH kH` bMLrJ}`*ZP@ksu[>GÉ6VRGS\.TE9h.~4UE?5<㿁F&|]tY#$(Fnaaq PqNW/\|t+>j:nRv85^b1 2ږ"r|RCwo=+кTi6g *93XfLU.1K&L%X~Q?)^5"뭠fB"KC))' Ւm` 5>Jj0찖9.ك{ &DRjN0jtٟHVT Z3/5˽<'&ˑӻZ·!^ lCw—Rݶ/tZLFkGzj0 xո7g&cP%e? >u;F]m fG_D#_QN:3fV_ u1ND8kM N{/y NVN֨eAahIJSʡz NOT/hD,ۜgE$ƂZRm=0+&X'KMMmE1@hDvۼ0 ̊(΍p?aqS|JCU} l)GtBmp QwϘPXf߻z$)%C!'%s׳+(_8 +^o wv n^u)r4pcD$yӠDI5-t\ѬR崑q\q:f9I!dV `^YKsxs? &]#2l) rΥG]Uۘ]jy$|=Aw"[ G=+)*'VOhJ9o,S^.g2Tۜ/[P,+!P*IT@-!:Cƶ `66HX:p'("@f<^Vg Zk -iħ薈`@.:JڱΨO̶?˻_`s; &/m)Q RM)fCqu(WM9 {<[fj6+ _Z7>'Ӈcdy_/py >ŧ|mKyWu9WeS5{tj)>&!U?.N8әcnx 5 ȈK"q5.,`Q?5ol`GYn!$(8+"௶_"ԇ'{>v||g f>:$ )<a{MV\[-Җ_ #Zxfc`[bn1H;kD_Q} Edke/2ګ Tb>:i {q[4ympѭ#M_EM}#sq7~|W(t1.r!=n^m\o\o G(֩Sd21 eLԣ'8V9mO4,쨖汽^)AVM4,5JnD_Yּ~1*{kq TeZxZ4ya'1eWyw ^Em`-/ hN׸{{‡H&~C}aỦ/ EqRV¦.L=gӘ.b_u}E le_]A%J@`[S I^w s\ y[#Do_C `Rx_)jҒbl_: %C]a۶ݧ_K \^ GO<ͻPLu3s;+0)!j @Тt3d cg2  D't<5#ӼE=i)tvy%}hN{WVmEy:Npʳim#}ā aWR>cezޏ*g9PHO^ҵ-d2`/m"΃߿Ymr V47٩je.[3]GFŸ={mJf^~|<'zGݩ۰ :Z&ߗ56LSf0N8A]B0wLy{=XƘdqKdI94+|KWTkQ̀\)OB P8=Zh9I4~10cJ²9qSkGh} .߂7_Bndő0V8_ѳRTzɕ+_qӗE:snA~+m <6Q@4ݜEl5h@3l\8m!gz%Wv&n!·q/A /6З2*ըT8ϚD?{}5xH ]X G(J R<O$79uoY'cy +/-zX}YTQ~u[2ݰ *f Q,bYeH^Ao\yM#%t}E$2Ff"U J%csh] !]_erC/z֕(T7[7?%RO,yO$cTy!UN߻Ĺ):s|Tg>ȋ }#9o(p;VMY@Y²<)YlR4GìiE4S߾ZEDn4#z6,Om//Z#nϙ%C>|C!)JҪ gsvS_7j_ V*Xq#B6LWu.{\rӿeٟy̚sFʐZy 3?6hzZB,Uj,d5݁29_'zo>⳿g*ocz݉;EMծ1 -ןCuB 폵)ڏYh%Փ 5i„?Be (M; Y,r  R\0˻Q*.R qCp¬IF"Ѩ;nM_b0oRvqZ 7ڎmPNΪV(XؐzScEۼs+ZMcXIlMv5;O[ Qh_ыN,uKNڶ ,t/@zmFy^5:$vHf[G9kESOXǝʠY6xsw$PӠ8;WU:PuaUP̏0%XȲfGVFn`Z {$ng{A qxz+z@ N4lw(Tv-8ÞW>OY|'$: R< c[8`d~p_26<~h @D?ǶX~Sl0vă3* =jC]D4& *z+1eMˁsPf,2X>ۖBXR7H e.%Pji5U[R~g&~p^DxxjB12%ʦ-j*h-*)(FNh|/CqPun2hMsh+f?UxϮ,6`MaHMxBłp5&ĄΧv{U=}H_sv@\up`m1-=>&gz!$tţSWbō ںFt`H]T;.VwӰfd*\vLd:h8T:ƴ<ʥtZ$X!v9D^(&קT)_U~)y zki~rEmG h=.Ob*} sU-3I*_]  m*j1\9/7̥O j$wdPiφw`5OU|+ר\\deTp߬M+"'Zj*SNIֱB9g}j VjGH4pY0dEJ͡clŻT!T7)'39bJمe%!<>yXdXwUn? O_ w^γc Z72N,,X۔7W X_!8Aj6GZ0-INwۍ`Ȳrg}$l}*%uk؂O}sA@̽(a +@,&).OI9W燳z!a?pI}Ş*6䣕^ Eh+R-x#(a̯ͼ.<Jf@i<=wJvJs'`FyZ//W:zg˂R~N=G٥o8w fv`=ԁ$8Hab *蒘X=tMdD91w}Bhmy"8:4/Xѥ#vGG^ J XoԿLKVLEue+}m'c#3sYi!SFXd$[x i~N"n7ܛ0Rv+nƄb*KQh&y:DYv 2sAM\Ͳ2ʸ q ̀vG(T}77S&SE?krwBeWvk*fL9rAh3Ss{% \ 7tF%\jծV8QK Pt F EZO7u8:Cab ;1?M2sjxF6/gqP펎'&tm}{ΓCvv[(z >vYH?#oF|l,8P?= <ԚaJօg^%Jx"_vz45EV^걡 bat"ƌ+3c^>bHPYҏώw*N] }omZ'/=qޓ,_a9R1wǣE8LFT"PkE2 IjišrUT\/[`I&qRGeL6,|6P iD~EjMY@S `JGYK 2A7a8>#ZI#?`I gsZ2߻]t%5"'g|zQe\ ȄVuaK:{'|lQ챺vn6Ee A\⫴XH&I3Nj.>3B kՃ.  3ZF)I-kh8XORlUoMU'ϧ((?T11דS wnO|L<7%f?5{af3[Ӑ ;?ABN XCtMRj}G+ӧB3|Bu~] ܏>^ yjl!Uh3?aU,vD n$?jLSpdtp0B~B'ȣl,4 Iv#+mx'^q;Z+V.Fogv50zQ.bv/Uk8bA;udp$4w{~0pVIi&{~eTa r%0-v|#p_҆ĠW9Ȱ0a830t2\})yV~}P\`N96ͱ-nm{9К53~s2rp)n]IVx^fIKnT5\G[3KBSpW eϳ׋Em؜kdx`?DxEAk@4}b5./87@M;YOregAJлƾFDto& A󷔯qPd>,eW)h4a%a`!(3䶁7`rꢾN{Okf/0)i ~,ruD/{t*b5)]Ѣ=phfm Iw[%j؛|}׀Pz&8Om]L7FB1w p}Zt^$pKy3s%6GdHkkI_rHd(kS<| :tU/a[fB.ǔlEOK?2+ś@׭D˦,&2ߓcASR0bܡmoLN-UjvzKD*:DY-% y0^Vj ߔ`3+>wzAF;ZPu6 23 6ZO|\Y=ul :'te$Ŭu"N8":ϰu@ a[Jtp֍ ]FkHle!@ܞI ~ˆl!+*hU3 Wg RL萐ضd+, by[;hz5Upf:FJ7[mqiB !xOɦJ}ϒDxVnKzam6b`8KP*\XwՐO2x裡!2B@ռf˄5}u[U>_7(f|Nxwx. >]Xgɨ(]APǑ#WO?_wG31?CxtrϻQFqL~MK cn<8 #0?W;A9WUݓY=SjoO'/ ߱]?ܷQTICZoۇ-GXVضDMo餒\cb<~͉¦;\N3АeB()2 {>*{/5gU mh:f6"K4mZ?M?^ TW D&v{H5BZ65 "i÷s^?J A"fUغ+gl|~ū\Oǧz"?%^s%yJêzOo@IC)ʥIA(,hWF$6JGG9`'' p @) K>龩ZjĻ^JڹKOif݃2zns:dxZ:\Ȃ[0]8(]Y01ui(9;H)IcCq j)l#c4#X=_hݽ^9C7dIy$AahQ?`01W P!\ Ԧ^ 2ZM+Ep.~]QҲ|A &Κs1 lqyѲsAۨ9{#SLyA<{V@Co}Z5˅̾Q0m35u*yxْHz>\+p %v z!a!>%*3ͷ$!Y"<*RnncWc10zr'2˩b HGRAG@X<_ t{_cIk0Kj;f8C~XzoҩqBͼb'Q,~sd_` o *D7DLSCJ}1AI 61OBQDu7 kĀo})%ޠGK'cK #Z7&]xXY\ }ݪ|ϔ\50 R]F. [b5$hFi 9";' :MZeFݖ&uykk: Pj#dž @T㘽uw`ӄy%&eNP…c҈T=WӅtט%e~wT@7/ayphB 죦A8 XCDOP f@.ĄyYrF$wE 2^u!$z!HٓbF !T\kI\UޯXKǀEH0Y|W~g6zb=VƧ/)rbЮQj ..3>L: qi KKy.ݾZwY60Z,3L0a?ڱԼ댄JޯZ$ BԊ թq/ cp04j'6D]4}p$y;anU`CX 8Il78rrn@sƓNGYWf_Z"acxqe, qԝL3oZŲWkCK!#aazka-)hꘌp!ԢH2^3 F$ߪh!S&H񯞵TAf^1ҦCG DBg͟:;މ 䛍jՄ 3!+4 y`3,grxMšwYx\Vx?ԡ!7ui||?1B*|`<̼Y^/#'9cs ?jQf3hckfhg0ahSLDuC.׷Nh*8n%ظmlo~Ӟ Ƀm$-E-{-zųZsI[7w% $ljc@ŀҮc;rIcO,AcuVB4T7W< \xT QQ:4"8!#jdrD8s?nj$z^:>RҮhiUȘ{yvSѫԮˣ(=3Ȩ{m0 ^NW3jW;( J^~> ]l`2P`.)4UB`+CIHtw{ݲTt@Y jdޯ YVmMhy7ͦԛƼbcE9jэ5 '4xay[B4(<=sqv'X/aGi`0yuٗ#`+f~ kW~)ⱬE~Ŝp8)4 w>E 4cD6'6+?@$ԟ f9V̖c1G_p݊EyRLUpTRRhTZ-1q^;H'cy !X@ZRw]JOvmwVK?6X>w -.}908[u"" ̍"KbY Z6" Qc޾ܑr.nȹd.7jȭnah 0^d,3벙GeЙj?. Eɉ9_q,%}o?k[Nb^Yh?#f b97DE P.` ٽ'b-*_R 5H;lnd T|fF*6Oy Zt6z$F.xv]gs!sc@+(˰œS௱g[^#q7d2cԜc~[\g>`i+4'vϵ1,>ʲ7!)]/\@_◹(5^=zz~>r5b=Y/KxFvVk(ԙ 4h,۷{d+sq/KY)(5Mzv"I@=+6(s,miEidm$Hc4ٶ{V ^ xݾ ~f&'E[Rg.\PXi89_ݻTK4n]MX/ݔ L`^hT|x%@2o6ZjTA5.)Y0A"6_ ~Sm_Y#b;p9'i#JDȹ^{m6z'1yvu{Y}JaA dK߸Bd͉9bQT4l-pqS83'P;%!w y9^<ӛc5ɱH`xp#0qLYpJ9}JSl&ׯYd߿8 ru-:7cm͠Acaa鳦;i~WQ9+ S5 ]X_cFO!yS?gDuTO."“QY&B (}ɂVk@)S9G1'j-8ԏܼGMu d9é}+q8e%{$?}7׊KD9$b rqmWwؾ ZO&*[n<:0h#*g-{Bmj%uClT$3bCߊRw@*9ȧyfj iZNg)5GAX 8>),Ē Akdo'+ w+^agvY(RiqKJY.z1pƺ*Y"e1@|'eiOȖ1LvK -OI*,V2͂%YAʍADSF :͂W0BLwUgEq1 Fl׏butR[21b.7y+e;?D=<b4ExBAhYu?:vnis<6Z;DN]ρXoUDD;vYp:4y*U\]/z WQԭO3!c#/vjb\p$_ AlctlB?t0QbcFFzZ-JCɋCQyDΝdMQW|Gz:ZCCd e) 00:^&qE9/tmDP ;{Z gܤ(DsU_wni~q62 ut)')C<ĕ8xx 3D/6)H3~._0P5iS"q-~S &s%.͒Ʈ>eh-PXb>@C'I5y;pKG3U }tC'Av'"SR -Fpxm0EA %ÿ]MUᄗ}ıwo­ZH&k|mLo(Aer%kL>i){*PU,;sËȑxgw:xb8KYb(ɍҩn b2D}ܳ;Oe mW;xlhzDO\C25 Z0|{TYU@5+& ۮi 8=5<3N<2: 0fe0s%q`NĚ cFVۊ(QDjr{`qJ`4cBX;@Մ?+b?)Q=99YK@|A^SvСDWhT*B~Hir^ `6q΀¾(~rimMr&}~k+nXkM z:~o6ZRd|YW}o=egjWaOijk5d8OL} >ҏߢyѡHiJ8E&ϣ(U4FJP=@nT @)n+- <,>6&7ߺjK/tp<;HAX.7ikiʼnd"sY G' FL4ZE? sѤSc^@ MFAC"̄,ti*0ǛE5RAAHb.J'FN3^3}ީ{(tQa.2B>IFcd$8u[& vrmc/͜~&gE̓%kjTsiAt2XJ)Pq?|uctC:lr-v69@ ʥ9 &]]6%PRbuJO[GNo~\d>SJdpIY>+gN`Im;fWy,k5 S xzpb ݪw. Ǟe羺)w4(f \ɝKBO"4vrɁ@'ĝV\hS=1W/ۨ$V~wQ=ohQGMجak gh4 юJG2B#4ҳ]s=S,X|6k!BȠ g?l%}-#7d5Ͳ9 .R^YEU`LLTd';u3bnz[(*8+NzW_t+̩{,y4Q,cusiug9M NMPQpC-#d|M l>muIeοyf4rY#4vjlŹt$υQd`>8 EYl~5FNrlڀn0ڬqUVNUtpƁ}c=77% c^r.@(J_QLO H qSk ُxCqE&IB-`Fė[;Pm_N߾K,NJ볷d4QtonL#~f7G6q+!١Opmq$ݿCnC|αAԟ1;W8-Y `Q@dԢS'ɀ/kKP=rl0VRar댻wʰ:xN܂Վ䡸ұ~?*zp^%{$HAna(U+N]bf+|;QʤAʛoeuP0Sd"/4s.rD¡FB/w<7{8NֻYʺn܌-$W%4~q 6GpN.:9z˗@%mM,7.~|]XqǻU`ss!f} =uc+8e(\u ([VwpmtRT0=(":h19Õ.+?F'upPhՕz'<-g3">Ƞ![r]̙V:a]Qy_r`lf:O3 !zs}3*XTᐠa wN ŁjoagH#wBpcHD qʵ #pcϦ4;P9N7 8 |2]27I.1` e0gvݓQ ɌAug:(jM1 sF6%Ωf;#&vzZ4ϐ?wrEQy _,f UAG녆NKU`qki?piiiaop{BDoJYAfo+1xdjLGGCcH; `0tHig+}+:{AdIEֲu8*IO >ȱk%!"DS|&`{P^OI!݂l} ?[M PS+"ݒ;1rG#13x#:4J.q~wP:iB%3!phjy. @vP+n}֦-N.P, CvWr(2SM|. mb]zO'49 vCSH<$8 1oJ%n 8[3T]h''gc O[nBHQ4|mX-\4$ަˮv!-C' p>b`}!ܩΆ0'Q{% T9۰5kӃG*?e"w ŠlDf:hZƢ0h@=zD8KgqK6\5L)<;6\oh AVq=d'%X5/w-J{BJ˔ae6]߆[&ItOjɮ%eUJU% hP'iiὈS@=TV13 (U NIx ǣDziȎꩧ~ۢC"LD-Gޖ8|%E!ù_o%Bch[C%YG~$,\x XL6<}Zy%+Z=fyZ%@}&qY$z b`.6 {KWfT(kԀSFc]⸴c^0s%&{Uy 6ȆpϜե{wal{rSs.}BWdiGY_5o?F ^hF "56֗ "mHy1!^ѐȿ %T[m,iFK]yS j/;(xQiwHOD%~N[Б*,@ʰNJ8"c\v}xޛ_%1|S뒟Ԏ ᙖS\&T`9gy`X$ƶ2j. k 6wXI BYU!f qAv,D#Bě} `yRG-(s{3y/5 b#m X)n4NIӈ@ZFk#Q B"C's=}r${Ex_F8Q=qXÃ{yOnkX8_–TazVJ$]2z#ԐU)Bm&rTEm)uD ¯{8V)fcQ }}usj{H G\yH|302PG6\t{H%XjO:ʡB:xZCFNs2Y+9]CVfRe;5" !DϾ0. !(t1o&vy8*FZ{J"O`^(o@!ͮ4T ̕ܘZHy,"vK/ӟ6 $<{{׿L8GjM5\*GKxVXGaxy6%܄1⨁fwA!x36U{KzZ ĭ sh=m۾2tjuo]Q䵡IλBcCDytj%_  'ˇ@ԋT?Pe>Ձ88I@.V(ƹ𗄬c#-ɗ|ydkkMr/.͇pS;3]PߗϽsۡP!fQaaR%谧{CYaģlSb3k)8su 짼Vrqfi0eL -p##?/`?QO2AQct;ID*eg Z\Nei{/0.tb8o db s F@)ŊλRGƢfM #H/ԴL Ÿo2݊創8/fqLZFG%FU2qa^|ZA'"2Ϛ=<.ŰPMaWb.cn&H Gi6M6wciˑ\wԱ2u(tيŇ`nUJYsySXߺ%N:b47J? .FǎTF;F@F7h\dI92 kԻ02U -UbslZ#lj;u&\``FajpE/Fk7Γ1x ][ 9|fkݦgq(!ֽ6b﷕0fUs$9l{z`WAmct}..I1$#tƫw6S&2 ^X!gw^G9 '8 wj.jZb\[gпϠۉk?-p_HDôB5}Qk'm R-EBV㷂t= !NF;9,y~f*,6'X_&j^\,ׂqbj\=?:Bac` xsh~Ý`&~Ok9U%>egXԳ(vwAJsv(_˖7t= U*N@he0`t;&siWU䔉s+M }#( *ĐcHtv?@IRR kE nG{==4W<{nyЈR1N 21T9'zLch帛8{V=tSڏQͫ4xDd6WFt8RQ'Az|}a!R4pdNğ`I.⽴i:K`rdWKъ Ⱦ̥~f=[b5'KȘnb ?bqMQ,m qtRR)km9 f(T1Kut`2r"up`Sҋb8BƝ_`v\F@-xבeߕ5֪zþz_ 2>Uى6HCk/l^/;V&]=i&mYU G]} P6{%NNF}fâp|ͯCD}ݽ  j{谈,<`0C}3{-wAZ?r5dqS]/Tyn˷ ͸vFղMry:E?OPϠFdi \:;e$+)K#v2l,gAm2JD?C|Ixj&v kweDXc̗$Go['R,mng%IYP28g-ř "fΧƟs 1<1+>h=WFcW(c9#WswąזDsdSUt%; hgЪM.I RӺ1?ܔAwh=xU//= X\` @"tqY# R3 t-{!t"IFcjbLL*)͖lj[E5Uz іa.P"~xԜ1圃aG y";35LTf[i'RYoߥFսStG@2XϷOM2v6qv)*OM> _+N5afYL^`^ϱVi FR0H!UXLXY{({ϐa98(L>6_ΑH~ ldٻ=7JVp=-oFm&|lS pc6f1J{aN 2zMCI@͋ZB^`ձ3:+zrlA䓗5_kAV b z*xfR!ݰC+hZX>*f4.{vjQ?~fY,7iVϠL'._t uOB?ƥ1iFmhqJ]#qqD2whabz9򂠋4ZŪe$ra(=O -"ӽ\|ws< !vVya!|Xt>Ғ<}$FD.Gm"VGxC*mm2E#ytK:a?;\?LB͂|^<IM{yZXVZxG*C'Ղ @.} z%UsV!͵~>bVEoST=y965ykU2>'eUlQs? +PW+ɂީq*UQ!ץci:[J8rprHՉZ-KtɘBe¬B툧3~"/DXꍐ{ iK*MrSyH۴)CDHpaGߘwN. 42AC`2(M `@pwj1=.O,䒓*L#ÈO#Q'2ˢ6 (%n ?,I%ST^\< S*ә;nl8?={;\waiH\3EJ9ܾ h'x J6NGE[agZ頤LY_;6s"CLRԵBQ뽷<_tokq*J|fsC{K) Phh:[?Rh[E4SZ֐b* Mo_[UEL+`VMT$=) kOM]WQOjmn`RnY9BwlF̮I[/l"Ej^QMjj5H Y|˜#)Wȓ/beJ4qH>gD4MS iSB?,q RV^%t hי !UYQ!_MDpKi<_^FwڥDdM0ƎBi>")LeHB yx7` >)k:#q*G^A;|pݶCݔAGX1%vmE2׶YQӣ1k\ڭRe)LE#{34ǟ2{ez<+εQassoWAo,jށ@V뜚ؗ=IjY Nh5'~;: ԩuYm ٗޣ' ķ=QG<>iYNM+< Z}5Pؓ?r%hۑ˞0#tm'f\\upRQ&|M=I tVU rX ֔(pn"[K,RéU$cw`#۹Jab^Q3bNHT NIޏ{XSv'lrfxh A%nc Dz\ v @x`X?<)4*s.Mp =kׁ^ 8yb[1:ی B=_C48nHM 9=U\lKlJp^F;yC8|P2M jKRod˄oL3B;t|mu˰76OTQ__;g%āXMR_p_ V=j&|K"d>k3АaKY/oCG7JV;, }A3:ZVHdfL>U']궹?M0ஊylf dNҎ>Ƃ=ͦa;~OG|y*H<8&lMtMA+ Z@J/w"8m:! gʼn1M/bD)a|<knB˖sXd5BS iMBnid LmA tWV#RuxS[2upa,Hc~Pet9&f6Ä(9؟>3nb[w{c!Trum>:fMGj; 9$gkX]e5n#Ҷ1o랒 ) imG4K)IV7mݣ\V#+#GvW/rǑL; 7=⏡M vKŽO7O ʪCANCu={oB!d舛%sg]$ZUYZD)xiP)HQB (Ox+g:]V@YJ(-{?O=Цd}YnaOr>dz Q^5l&X4 G+oQ! h%2c _&cN(Fzs;s'ӮT3E< L4=0On.@Xjq0R6gR=c!P"!AW-`aE21T]A+Zi266B6SQxߡ:u|%"I?~fspA`C8VR,-7Rя/ D١y)Y?J.sXkT_YC,xy}8җnC kϩ}6|m> o ~'VB` h$?S펗+ RV3B1mRXgz=":26B[8/[u/R!Nֱ\ R׫Q>$eJw[I OF ~nKʭFg; DKG,Shx>Bx J+IwSGfxfTWx걬bWJӧP Yc17{\(kPu'F*w.IWXy:`!P!'C;3G1#/G3!')LbdPK 8)L.ƀ%*<ҹ Z+EM#^-)lVrZ!CkrbWU x %o;j)+G!S}Fy p@CK&œvomDㅀUzZ󩅛7ֵEK"L=[!>AZ)' TwMcuA_)U"1dF-aoEoȗy F4wa:BTԏ@LO4 s} H#PYIv߯% .?iܜhF Z2msK|~ vc#`rih53ʎeiHgO@@dW# kvyNdut_b6:sGY?ƻLڭ װ54V@EzM@(`],:ſQG":ڣ HY N|qUC$,OT qC~.Y #8bxdHl}w9i2]D_xɼ_{ih7_e/Q, HMez`r؉ B5qT7Csǥ~b)bƯQTis!oŗ/ݸbf\_kfEՑo%u;8v !b΂/ TצL.n͹I6o$\Fߙ,FHr dR_cK!rSQ2r;) Uh`'Th`Ae hihTgGڱؑ3~~0+n 2hҁR 3/k%uxA<\š0m2~{^otm ;؆FPT!*Xyș̰Cߘ9I γOLj4?2<*nt7t0(1nI" }/ݒeӈ}-0;`H:5Ϯ::dד Sw٨ۦpؠ/HJGݔŊy?[e9M-ѫmPQ 90Mȅ1늈W sqJK2r%# D8\ nJ83 nV^-Q? FۜgZGdJjx:JWczoV ѡgAE0xF`yuOA%C?TBR#D"j0㊑oQ]Y{/䢂9T3ܷ~/mtirԹ%t ` H .ݕWO? `wiaסh2>rFH Fν=,,1`f&4ɻmJn)ls[n;m]p|Zt%XFC#+Ssë9WqTԽ) SZ4Qe\/S}-[7V7sOstB! <ԁ8)ai+}mtt^yכA98ͽ0f'IzbP+,L7F߹T42 5+qtAJW/Mf/~Yۊ:M aa'b6)a>&P$I lA:b|ʗ*<(3&:-D;Pj/V$zFd|#nk<AFcN!)<^=,_;>훠#HWS&z lh+uC;e>Hg0ӄڴuCǪ-ZDWM0'L)6+"w8 KlM챡1'5ԓގD)7_3}ݶ0c{\]D9`v#E/}Űdp^9F.0?]@{IG@* , <7 TsDc w^<9ձ4vkD;x{ݫ6aat (I£K^!Qqu:ѼGKv&/Od9c-}/K&nkKJk-q**WSM|bz_h--ڶ_h} HݜWp1f+! B <ȐYF X(Zޗy+aWw֍r!e-Nm3KV.*I)zr!  :/+g)M<&> E7RR*#(zh-fs~D*R".ݥFCJ[Չi,OXKN'!7z+#x#>e| w3`ۓ^n;X-a>ǖ^)~sp̈́$ v^ɤ 챰p$Oq<)iŧN*|@G @89{ Cr))ҩƏ`lE&'M0pEPs ؋xr|RoXfTZ!NHpYmެ=ؖ*~Ris*`ƺ6`:ls rt}CfUq6Y>f d)0Stݟr͑g*54S60ZR( z' Tf*-H ԹToF.vq+TD 3# V|T}O5{)Xx#%6Ob#O'BW1ܶOK5}YC$^8 NTRFH@`}b;J:x<8gIDJ2x0a?(ÂK),0B!8k(asZ?/~2soX\P11| xZf sQRbL.zy>qj!/xW/ZNhבAQm jK깚ԟ' B7 \Q_ Q~kuyZY L_;KJ$0FN$SA~0"GWڜs^LU!>CS "nmO=C^ \-P?ƽt!ZYI!Ǿ,d^mX:Ai55s4J#a㋆}k+*>)soycKvn~Ǫst$l'13T6uw!S붡K)K9@ *Z]T3ba-80 $>ӵW֗R.Q 0 U)^%҇vCnE汖Ҋw?6S)T跴IH^ v!v׮ d^vip]g?!۩YkU⃼$1x+Gnb6{-.l$Ӟ6)i>WϩH$0~ ؇yh`G=OO]-ֶnʮ*pz U[fЪ9;i-.- VR{ %+ՒDڙ '\#{oM]-!_E43HvSعOaO97:m+bLqc-8|yT:9i_>-jγ⑔(|^vI=R\#ExmŤ'rr s>v=p"RY\c:@i%ķBMs~ͺ(E'E0 AEXIe_?0ӰPqbܚXh?@:% lB:.?n> =0"4,fFы2VSB239Xwyʓwh2LYkL_l[p},H7 {qnYX ƨK0x~+PvCMп)H*A*λ& iFh&ܱz$#=aOqAaK"PƋI[MRc]PQJ/f'\]OZ띂EH4waOFet"IƠvslH&q2/AݞucE8;E|:["ݧ4ppb؟2t: ;Pok1UpeR&)SFSo52/o;Vľi_~fc bTrf6U/MȀ@kضl-{% FѳE!PRJ#=8I/3~sY@ٰ~`So"# J4,XePފh">,O`十$ WqZ_uGâ!y{BeEQgg fx%Fazt/١0^=Ii* v7[idPeolHG6Kx+KaU}[A ojmm0M}oCvzV5 #D@yi4E1=Ʀ>[H@ UPH֢Q4?R>*Q?r[C>#?Љ59^\X:sT#w|lʐufr4icB0tؐr|r:LuU:\pL<xz7V!zx3>8&}b 2}pY0ab=Lo?B\.^[kmH_L Eߨ+s"ٲUqc>! q̨6܇B.VlHِd2}Ynj7{2 `=hZ%_6}bo$͟үy/);UtB]ۖ7;7LM+b3",PO|𞼙߅=UbPk1s vQtoxqcHlj&kKrz&#: r0=XŽ\ӧA9vl[-5޴ڲ'&>1h aQϣ:m$UBkWnFnCǶR#&L4t>:Za}U{L4/_ ;5ظ*՘LK.! 5fl<ZFˎVCX4 4/AZ2Ɛ#,1Gd1~1h sE=O"l]0])M]b*Ԑ¡o8?"cO5Jt7Ĭ FȒ>3m4~.T[4vξ'U;^;Gב^*^& J1;Rz`Vv;a,#Y/c%+p`."q-ݒDPu֟2ّCjynL hʊ ̱0wZ+j{O9Kx1B~:@2g!=įfg=5|CI8˙|kl'@1*]<.eFKIs(-I^pO`g`)L3˩9ޝPuBq+dp@O~u,UPɢm~kQs6bE uwtnڿ[b{5$dj0$:<` Jd.-8sWg?z/4zb@]p3G?)٬]pGhQ,=ilqT1lzs*g*ݖ3Xp^fK o,'ݞu jlzp `*[([e¥8)]wAҏxG"L$aㆩ(5My9 M?dPek4]-ʈ;o*Md%&Lv.z(/g"33yb mhFTd>ea@ } !$ vW}]07l"h6'uy.w͎Q;멚.';&VX mA fm. ŃLGn֊ھ#s(|P**ߖҟد#KM쨉z\ޔ$xFh}s776 \Fy~Tx<87)|oSd$߾>+vYQX?S;օP89P Y(2|NZ9y36dvvm :T)Iy!L=>+A}( 1$b R ߌj]{Z4E>M=@^KP S0QǹM;1WRMHf琧Aw?#vp6Lh3]<$b`.Boԍf4|u$J43%aXouk?zW\2@`Ao8]ɶACe[uYˆGK! ~n!s*D́Ep.4k2ΗEPksXܫUXZ~jԀQA:I˸Lϡ=5nz~cT>r Lxΰ<&pki )6HM#wuψ`Gml1w(,j<13t+x&B0I `Q,R'"ز.Z|PWC 47bEpL'ΒNڍ"6E 8{J}ډ⧇Qa$ǺHv7dY%|.v/fGEId+{oG\c 6jlzM:5  1+C+Z Gq]ݘu" zfIEGlgQS;RQ}@b]埤 S}KC$XMp s;{(_KN6JK >}`GhOE$3B.E^I_KB^\\qKb&>#Ș@3=iCrX< ,J>n-r"굄+qX9C QvWxԍUA, 8Vvނ|}kM;(M#:K#NyI7rr5^)=EAe12%.G +QòmmUBJ '  =?:f U^_ZB9yAzQ:]/X$ q"zxN| ]N;+݅aMPcmr1խ] Ur5@{AG# :V-gN9,s\4d`lQ缔4sz|zZh&malD|Bv25z7a9&n2` AahyRm=(D;^KgO|.p~fWȘK4Cx͍(JB^ׇQ֜Q.~L b{շ" K<ݕ!|R;v9M߮5٭/Cq3H1=?A vHg7o㜛FɥLM]|R 0ӣVnW1YM1=C%- k7j^kM3 ĶbgJNs2`43BYlo!9`in\ Etx,ͤDq0gQRRQ$ \@a%^|;ĸpZCNvJN'/|I8gcCO%9oE7A}Jns_1@H|u9:Ox ˦+J2zWJӲ~k(p9~RYdq/sj:ޯqvS4?DG68vVЋILx9S4*y,xw Ͻ}OF&p$ğ @vt@9t?c3UP$x{>I|I 7}ayp+ :s3$%;e:xZ eKN(`n?O=Tx+`\Ai\u{ 0΋/}~|A)ud8xYv/-ט)oҾy16_~^S{fk)@cbG:l;txFI zGVUbVRUkN^ 豂[ #~[_䊋TO7m)iW !Z~Fpg4 ̩֩{DaÄ1%:ׁ1 0"Lj;j& 4(d>-0Fet mFKeDۨ"( {&33ygҼKD8kobrۭT|CJ:VNy{ />hO 1/ ݄ 1`[tT: 4 歅4GavG.p Ij9-.HP-w$ yv1#G'Z*˷żtQsTIuђ'_@mFs]A<2j_D1jDX0gY;LbuS8w@]?C7*Wq϶MhC%+qkaU=g3)]|oFI t SuPa\v0RJQ-{^%kNmC>`V,p[l(p(8 'EwG;=BV5cՃRis[ᔓ |o3 QFzcgِJ, ]$p9NLuK}ԚmR}ʺ \܈G2sӽw{)*Dh4`AѱQh@+S٢)+Du3;~§T>|U ?̼,i x^šyVNvЙ׉-)K9>d v#WeGm;l&MdvnHҼ+I~TOKSѽ)$Ƌy <Χb']혂 #=Y&S:Qj64 &z~)2i(#:xy:_,OB_Jö CZ G!}LOfsضE}Pk2ɄbpDTʖvJ2>pfU!NCB-={`[_ %q4ek: LB}ZU7/zW[E>1p9wh1ҥ,?\e yj 0?xBdd@[:84+Dx.'6t.?eC2W}/v0ACW4+4*cZ@f:i/i'Ī)aF޺ʀQPjLu< qv=#pbݣ, :g.z59lcW<͎-ԫS Կ 씲 NMrn{""n^η-,wq~I֑q >÷k5 q3"Ғ;;XX= nBj*{tmtek͂7d=)^!̿nU0XjJz ՕJܮ]뻿ko}O+9zURsàq = `2VJ^ b|nfq,jGB7d $w^3[ꌰ +UsA !YV(ݕ|$ob?\6h(xmbiqtvJYގ/I`8wA.Rp\2zM[3":2C9ړA?4ރ&d|QcITeV.3" I0Bi4{G\;s~hibJ%/W h@k=^eH㨞'4aݼ_a&"Dښ/kU^ \8m cgjz|v$7K${S-6Ԏ=;Œ>%Kb`!$`h膘O6 =&?F/^=|d>qE,pAA5H "Wɧknw޼H?3 ; >2 j1ј)3{ ixɍJ{+.nڌ;Vo=KVK3k*ݵ;lU)4@J oapq >ʲyiiX _j |Ւ‘Uq+!Ye桶y1>T ᘇÏn@e\ |K埪eESA5bGGi}qxL~5.`;9& ծLdAJ0FVLbЩ;mHBv @koOBoH/}^ cX|LǞQhBN5w4CP`D4G'SpzS`ŭNLox#txM .(vءt8Ft9C؟`˰_QJ]I0"r=2' v;36;/@TUP)k !d]ېS7UF:'/\ECkim Ÿ6x5t'w-{ }nyOyf y?zr͵ǗjS1 ]W %hM@xr{V%dK`xWRLtV_YF2H OwK at|iX abe%hKfl@x^2AT(pP@_{ˏڗ W'[]`0nmME,"H{FV 8dLм)+8i3ckDVX9(0CMe r O/եH0^I+~ԇ}ݲZGFͪOp;cak-3,%d`!ާBEH'd/a5E+USr(SqH}ma:՜Hpؑ~.k7rX%>zg] k"S&_gƋC{w&5dzj̀I6 \L9t7F/ 2NFT>= ɁxȘB-t &#-"q7r[E ,JV%\v%&^>o"J{vq| X2leɢ*ə=e1tJLuB )̡zH,"u*#|-0 U2ɕf"W~b {OWh7'3Dꗻu -a-!F[%Jv Q(ŞH6\ K*B ANؚ0,d=׃3rq]SXv{ƭ22s+nэ"vyAPr sDB55TDěnI+P,Z|ۉU~m nzuث-A9Ԇɴl%4HԉN-ͮ=ѫ\N)-Zswi U~?L^CS7@IB=7Ȅ=TE'0L'c`QZ;ZRmӜD;|x/iv1y* ʥI0|Jg"zi۞\%: Nca%yefN#=JR7xQ}j: ]Q1ar好 9E'ײSNcb')*U*gvԶ{_q@W#;},P0e{I5mjכnv,/ tg)]xΖӫu/*"1Uψ#(e:Q8jăIM߬GZzx+>ֲq펀 pajz@ذH$v_E-ܽ4o taxոDZ˥ @B6Hw|l浙1GzϷO w1hй"!V*sv_B?H ,BT̼{#C޲`&Ҷن+ (1"&Mf9PdJ92\i[ g( 17Cy{gДx&Fp9vngV-ڼEl07V3){MbZ M@V#bG+@^qo\NxGމd'k(:q#\-Oyf*YR; Sן͡Ut~rVg).Õ> J/@}T>誳 J!ZGӛK nL@Tw8< dg؅R& I^ϗ N0X3YHkt$iHbk~RUܴTf+ v yZ+˚_@1*+JX;U'q So;L0f'!>> Du^2 wDSwϊJA.v iY`X|8 PcWiKX@F$v2sMW N15xG\Zޫ犾Sm0Lh"tո10)0ĴQ7EkLw; R" |f[ 75pj<٧PMWl=33ـd#k''/[6*qjM8G1Eq0IxP jf?X?陇qr 9;ẽ@jꘉk+p0G$:<pOm,YW6TuiZT֯f€ .YMvky&P]L63?C5`=/wu+#xy+րI|X=v‰sݙ~ۇ$, Sxc I/Og$2r&Ps" t(Ծf-w9TQ6F&\MZy6;Kj,:aG۲FTY_m$b0 UIhbq@qxz-2\"}ߴ7g8#l#[Mf|9N60#$|z96dTVtwuԉqUl;c'KYZ%#r g9d{.]_Z7P`ʐҹRv<3*Y~'QڴiBl:~ZHڝ6r̓cXtO `!])?ؙ{wW'3RWt^zb7EdqjjsMi]K E#-b( QahCA1cSw"K|OA[t1ŭ#ԛ[}n(8Ojg$Zqh9Y^-8g*@a1nt#rw=:)P5EVd; $s^h*S]q#hk`O(('lTqz\E[fPĚ1Cbpj1je5o 'q=CkdЦF&C,"3ܫ]ivGbTOEO6kf^A2 O6yKrbBnVȷiν?6Qaz05ӂ|h?giJ/!o{z^OY8-5(6F`N3rk^+rV!1<," 1:`eC?;ܵY|FybqKQ$t"Rf8ҭ;s ;Z񂴀| N`-j{;,czXCx8샃US$Dx:(4r9'tBB l0v.3L؂$ɠeƭ]OY<-8Jɑy;_ov@Ȝ@>H7F N_,YQK~$iywjbT#=FuOT9YsjQ* BxTfN%~q=ƭͳ/ԍY(*z! |2lL-sG{051D.EPwzd~Grj48vwsгMМ\±^Upo?N!'F$p_Lր6&ܱj%df9C5 Cbk*B{'[r;MWPl.85)_ ۠z/5y3>CB(,TYU{rJz(-ܫj9Dy,!1Ɲ~9{(0NYJCmbF~!s]9+ L$%*0ӨCDulC1ű>BȀ5uȢ1C vTNg'nĉAkJk JBf> HS8GV&iJտ.6&L=Hv)p.5ʱ 5)T)edh~0kOJ; uL k7 ,@{b\lDeXV;4Bm!Hkȼ[cUa4hD?+>AL}s/u tvN![qb.&r+FzF>(C #oXI6=wPFn'[|]Dx;(Hj x<~ FKh22t3:'Rb൝USqݫDcꍼA%>ƥ:TI|N>/8G  J*_[%x1h%Da2q&bLE@Ѐ[DT+dY I՗_qa[ú|) ,2<,>'4,JC#oc{* @ Ant4.ċ &@h!?Вf%ƈ}OME.hBz[y aOFmXo7!c8Ԣr:űHhHd'ʚ|~ Laן|o) ~]XW7hgbzQ2;Kǫ%Ê3э0VMX,3`_t-wKKAʘae8{y(?(:V#\&w]|S~Rv4EqH1sZFESPp^&5a8EYHb " 8׵-=+77D":'9^?t6'EBݬՊ&E8Lq[sT&N[v "ϽN(~"hvJt@7ǮP(u* h~v. u,BkLp4$=OrUQq6@:]N7{\͒uqJ텎;l%끁sw0 uFϢ+}h.RDU• zvKJۊ)}cbԈ>')w_C>z9I]r7{=~^l<(YB S4Y(q 1c@}7L{`?IzIe7f8,EОE4Tk:(gUدCuZ"ytjЄCX'`R.r;QSi}HDe\Oqn$h"AU+h0ml4ti)A}azY m3Q`q˜oUJAQp]>ho{3TXAe\#+c&\F#ނKm8Zk9gm7a٤bScm)ѓj~+Vkq^+դ3[2h ;J)>%s#K^H[ yV1xqzV$/3pNg U-;vcYGGz/.~yآ`j-<!Z̡=#c$PvJWҏb[y Yu~ɣi`ޒqI f'Z{Qq~L/J>]vLQa4q: N5[662O睘x0_IN^5'n]Ij!Q˷Z>bẂvx`L6H.H8Kl#6,e`OYyI@wsxS'sb$<88HM@n.Qev»E.ӧNBiX'X‡?+1g7cOnINqj1A xC4|OEAuJ'ypl,d/(_lH\RVܟ} *kxչǃ H5fZ3x_`OxYLuN}3#:Uni`.Oces* *9(hnGMc+Ζ{M'oaQV\-,gk7 t,o^Q|N2S&u=ނf$M~|7|k`߬?u^\ _)[uO;V/o+c]ӊ:fm^ Mi-|TE{ȕ5$0^1TLpt@٬U>VC)9޲䩮G!@ƂC}pw .,TDhZB!ΕbSqa jxOUWeH=:VqwڰZT^qx }_te GW8ZGC\5WدhP.o7d63#q҈(یeWwdQDQt)sU+|nοW5HmpLu/k"u;\x :{nTÍ/lM?w|v̴5{mʫ!T6]6@*\/tGJ=r9{w 5;|F>ɑ(!{ kRʧ vje 5Q@4b$N> /H֒٤ fP9'Sghg`^w-ĈUԷSOW[F_8ϸ7SLS"Dbl~${ع' *:'"va|qUuY0=u]d-"\{ ?ib"vEl>7n'"tPkAeSӟ261U:gWlI?$Z?2gJ(X-JJV{z\,ٮ;B;{i3ܳW@`4F|W]g;= GÞ ]85=|tF"Dz4ɽuXD yT{4щ=~sh;0!)(ژB»݇k Zh:tǴS$;hY;1sa#֗7oYX 9IIXp Ys:AD*n}ՙTc0ux+ C&aёԙ;9ˋ\6;&U6 OÖv·]jۿz #NsaL)<4O 6{Iq::*.ie߂ a<#,f1%T50l)4ȈيDԗ1rS,m^I2 wPBUs$if!gV950KFq>#!{= gl:Ht5ϙOCnQ!gmpr^q$, ox~)tHMwQ>V.I |%}wʷߍ];]9QIau +, h謁"1ՖԥTe5؄TwYb2-7Q=S:o5<5\h}osXHrdY.S|lqwӫ{{D\1[~T5K&1V zJst> A I4`GHWMH.yjƍ9jҭ#< 5'F(ƻqY|.6a]lbVF$W>b6>m3wy?Tgn& dXhK$[UP_ؽϋ2y;8rKlB DSK`/A[\9E AYb0XY\*&v9f> 6^N$u _IfYL%P[1a+@ùO0y^<&1"aenjV@k9V4ۺ\P_?dHPm鲏HvWi&φL±V_uTKdD,G10lz]» r'Rȅۉ'?t\NrT4K׼GF1[!9N*6ߩFkؓl_cd~`ɘZp|_{E;PnhxFG):XJA[R\KpDvy4 S?Rpjhi6|aNޒJqv?g{')pM]:(@Qؒm,Yfij[x8QC?"UFm>w~uVC!R| } *Q**IKӄϿ >|zBc.w.LgC?kL";W~ r>j* F-dm^Ll["x~D}c8s~Wg ۨ1D102j6[I]`Ye6 }ƨ8l3+0xX"Fmql[żm#E#VqT~Mn@/CTMm͞<3 {t[KѠg@~­wTį''^Oo:y8GJf$_GWȊYo\/߸̺Aw!an|3L{*rC;N, t[2iT;#,msWesL(% Z',RgMkH lc-><N132lWA1-*ZE2vUnjѪF_/S hֵ|Ӿ 9]d e|h ǯBwP=z,Y֜Sbz,gv"Ո޼c3_rZQ'ccL%69QO߃~K[v@Vf /|}{*րUݙQ3D._O,d>[t:B*S*\8"]K}*6ajj$a6)ĘA̎c6I$n q6U8tnq 0Xn?sJ 9az{Qkyݛ2bya|k?vUW\Ѱ3y`cD#'AzɉW(X xD)x!5u0}/YO@0"匽rC"D _> : YZ