selinux-policy-devel-3.13.1-266.el7>t  DH`p^$ƨ3ucGUYDuZBTފ7oZ&+7pC峒Ef̚oS.Ҳe[!;qٝo-JOJP%E۵?ćyN|AX9hn!L !E{yШ6ޢ7u|1E6'Sl5&BĶl Vf/g豆h>rk)ӯh%~ڎobG:ox;޹P̃p2<"Ew~,DkjB{,Қ6稲\W˜ޭe7j4Dd'J/S1[9c^v9|{ ' flsx] )tM)r1QpN9 Dt#̝Xu_~r%+R(1gq& rʱq)YT;]VT{CѵGWcSMĮH$'?]nFJba4b9c8565c2cb1cf9c14633b8b330f83e0a2f28^$ƨsd&A"o=i㕽PD&DbvՔρL!lJ~Lmv oVod&fS!Z[/x4}"?pkhH.veEѨqyD,AL6UtPB=P(8Tlagl7 (_Fk?>!xpd, ``bT7<ɘ7c:\-!M }lFW|71m*PzNp`JnsHmd >@F܆"NvguI ߑ|+DV&Lm;'8o$cMW֒7z).xA(GoxaGƭ-zޱx E.Nh/z>Q4ܯ&Sx,c5OX@֊^c X-? G7Gyo5wwL3gI!GtMk^?0WY/'um(:3盟ol7ٝ4"=TH<hޭs>9 ? d & ;lp  PRR !<R +R A(R R LRR.RR8P | E (89:-/> DG LRH RI RX 0Y 4\ DR] R^ 0 b 2Od 2e 2f 2l 2t 3Ru HPRv ] w _Rx tLR Cselinux-policy-devel3.13.1266.el7SELinux policy develSELinux policy development and man page package^Ux86-02.bsys.centos.orgptCentOSGPLv2+CentOS BuildSystem System Environment/Basehttp://oss.tresys.com/repos/refpolicy/linuxnoarchselinuxenabled && /usr/bin/sepolgen-ifgen 2>/dev/null exit 0p R^q'"-%$#5-3z+*I[+b$"""/H(7?#3J2*G"&'KH=()O63>)j&0h&H/0t =/:*8"-%FX n'4$7-#3jMw0>w029!B4%48*K66m3-4('<W -* .&.z.^-2.&3&l!*%Q$$FA":4955K*)-:pP9o/UG6.D)>-(252215<$?R.@C.;E6 7=b,t2615w5O4 ?;5RQ#/@}!;A$q06(4N6j4 "-&h7%=$6zLa,J,g#1/(076E+~47,8JC95F%3 Q%!-S;Q5'-&5%8,+7.adA;HBjHS6,1o"40)/`5Q 9?i6./&95754,!1}'$4.38A-()+CG%0./-74>679,C:p/#0r" J> +w$2; E*yF`*c/0v>7l)4QQ+01 0)-y8.' 0Y8e>g':6(:60+(yBG".')\.k=6@,6_a).I947Gn*I/2'*q!{2 &&.*.LN(C$#-3U)I*A19="69<7 28BF/<260'(#@_-.K:`6&Sn.&,9! &3XP0@z;1E31d$)00313|01(12RV'&6^.'0'22D"2D)f2D)f2!(,-=C74.*h0xI!& .0J.'[EE=?0(-&'W/.U;0AG0J,$/b=8Ez2 M)B'(7$6<=677\6S6SS''g37K)&0hN3!Y1I_ /(()4& $p%05BQ58f'$#!r#B--I0}=F0TBM)H#0& $%.:0KJ+6J2r/- 4.2-03-Ah55.1.5-7.]37j$S5i6,549q,,X-J*,+=F0="274:..BCr>*A25G?//-18O%0i'2u(-*(})+!+y() +%$\%B>BW#-'8?9.$:04490#"M.^(FO27'\ NMDYWBbY$5ud/ \6ja 3] Vi1>q)II!5 S =s + [*U/V("3^w-q67A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤^^6^6^6^6^^o^o^o^p^p^p^p^p^p^p^p^p^p^q^q^q^q^q^q^q^q^q^q^r^r^r^r^r^r^r^r^s^s^s^s^s^s^^s^s^s^t^t^t^t^t^t^t^~^~^~^~^~^~^~^~^^^^^^^^^^^t^u^u^u^u^u^u^u^u^v^v^v^v^v^v^v^v^v^w^w^w^w^w^w^w^w^w^w^x^x^x^x^x^x^x^x^y^y^y^y^y^y^y^y^y^z^z^z^z^z^z^z^z^z^{^{^{^{^{^{^{^{^{^|^|^|^|^|^|^|^|^|^|^}^}^}^}^}^}^}^}^~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ ^ ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^#^6^6^6^6^6^6^6^6^6^6^6^"^"^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^6^#cd065e896d7eb11e238a05b9102359ea370ec75b27785a81935c985899ed2df6846bbdba1149ef9edd39c6f18d37f29e5ed9cb3670521f142ed6d7d2bf9f2b8342d2c3aa4d008aad3243fd00e4723033e27e253289356cdf2cf9ec46135a8327bceb4f36b0f077b7a232a94e214b3b0a5a85152e4d89c193f92ddaba3ede1ad67861b841139585f2e2733a1e8793b91a2d85778f092c4b180e7fd409131aa3f9074a12375bad81c4125f3781d9834631e144f7d83b6602aa8927e8f3b2d7f13184792897941e647db7b6e4b0b6b6f8eac74016a1b3b54fcd3af01064c58dfa0a0dec9788ee74c054f679c2f4df38d036096352c0b6710704179537856d8321b890fcd3f8a283297bee593a48783e9479dfdaaeb5002f99fc986990227a592e981965cf82035820838a012d08575b99d8fbefe4881b06b318cfa648b7bf04bb23be90627a9217d781b09b14ae27472e16ea3353746ff6e0594f3059ac36d4c5f2d53040401d2554ad99516de146edf6ad51e69d7d307b6f37df038a8f1b7d8fd80e070a37fd75fefe3aa4221a19f6b65cfb4315ca02d86feca119bb1fbb64791431954755cabe03f23ce1ee1d79a8eca99b8b71e85eb33c0d6786906d0fde06acf0f93c6259b89ea61adbe1ec12d44592c982079f2cda78547bbd6e37186f744e25505a58561f0269bd7570a271de963cc918c8a67a40d64cfb537dbaa3544b1f5183978e8e027a8a58eaad2a7049a2f225c769b20d71e085823dbfee3da823d34c9529bfb13db2169e012b49cf0a93ec99ee1c09b359d71114de6790389af7f5b34d32c4498bf0473cc624923b801cd5ac52228c189ed3710dd7d5dc474048784341560d4105c2b8f2e61ede167a9b80c698f8299191281fe59dea391d1e5eaf07bbe661f6986901e7835be8af16398dbdf5af82fc4213f2538be28c8fa697f0dddc3817dc5d29cd66303bfd5874742d26bd52684c079bda8d17e8c7e26f89984dd5146155295275af20144c7a3cfcfb465bb88045ba3ba6f6bd50ead980264d096fe1b8e4f19327d66fc51bdaae941243b51e465a8aaf71613fc48a17fe60ea6c1484007acd017ccdb80a2eb49b7bc3f59dbb1dcc55cf97c42ca56d2bfc447bc39364373debeba27b8e5b17a59e53f8542691edcc3054489100854c1ea2718a8225be8fb696758e5863fb13b27f3461f5cb553034b17490ca96c63c17db6613a144714abbdaee98d76863c555caf46a3b8c3fa4338f761d02c918493c8b0495a99fad8c24701a6f98cc9cbd593b2eacb67ac7f28847a68acf107eadb08a8c41d9332639a26028ef1b6f58a99ccb83e50fefebc197f4d5b7a84b7cf44444256e983844943657e459630faa5e510a008ea39587da42f9e8514db1777718483e09841dacb1a2a48bd77587b3616cc5964f0d64ab531177af979e3d92358974e29a64fac0c49b89633c8d004186b7fd0ec72ff368044ddd491d1d5a243634648fd93f5e9a33c76d3720deab7cdca0aa4d95ce51be5969ab43fa1aa9564ab267bdedd789965ee1bd5c128c5003970c1db219072d71fc758bd4db1bd01e21047468930a496c239f30d2210d5573d7cc1f5beaac6a58e0a5eabf52f174ffa83392ed1b99ca1e77f8d07fa440ada903aa980ef35c2a21409a9cf4959c41256c0bfbd305c0c00a4a3b223b25b1e56865fb17debec1adaebf80fbcae758d24fec817518c63f05386a6b68f3a3e6e05561322619649556aedff1cafdf6d6d6eb2cf9e1bb1f1d7756cb00aca52b76d0324daa3a4bcb99779f02175964ff345c28ec73ac5e4096681bd25df9fccde65a1e3cd8866dcad9f82d40a2f01d5f60fe28d67c2e57e5a7aed969035fe8223db4696ae88aac83eb4eefe35d75749000b7e327c2dddaeda4f1f12b1373c1190d9c1d1b48ca3c46ef4e753b6f7cf4b264eeefae43850f77689a4f7875fc0f4666abb57fdbfbd7cc46ee8650aeffee823b6d949ce37084a42c2a1c986fc11c0b6468c8c90565308ad9c4456dba09f37586bc33ff701ccde089f8e97b39d119e0e823b66663125f820f5bf5bcee289df4dbf8771701194b75276f93ea22e6ff0cfaed2517eb920d8dcd4b5edc56fb7c8e4ad2f0778158dfde219437476fb4d4b7cfa99f68ca9da3ca9f822c4f9a8cc56e02e5fe4fe2ce33289ea3a49c462da29188a00e25f1a77e8d53cd68f38412c51d9624d5dd28a92af6e6686dfe1a95bd20e3c72c53144cf3fc558341c1952579429cf8fd50ec9dddfd08572c40d14efdcecd5f7b03c4552ef15f6598cb6bc874303d98ee2b93f081fed90050961c927860207f4904914f2b38e6de8a8789823723b964fceaff6a84aee1c57aa6c40dc855210fabb87fe009f857c2ec5955a8a1068e065190db2917a2446a8724eb9a68e59bd96c2d5bfb62cc2caac985948ba911cd2105bdbc59e04ebc36069138cacb3246acd0f05eb25476e201c49605af82586022ae19cecc95ece4fb876115dc82d90fbd4a6fd1bed4c7212de382347246141f3a9d4df4449109e4ab38ae3d6ba9021053312b95e5c93edbf1fe6ca5cb824caf6e8de12953a3ec4193d6279fa91539f883ac620db526d361622df754f3aa5558ed4750e5717842ff31ddf5fc5d0358323a344d0e03dbda14f2e1940460940ef2d94c570da1a4878e7b421de17e0cc8e58b5f7243c3db1cefba1de53afd093df2c22a4845b8e5b858da8d2af46b91f09cbcde5fa9748d704bdd611c11c6a3ec059e4b8f909a4989f763226f4d491ce64891a75a16650c127b211acd64408d921a3b347540dbfc1cfbd4bdc01fafada3d5958796903ead02b22a75966e637db8f6f62aea94373718a769e78f3695826b93aee9c61c58fb7dd640665e757458a355d5db9c10bc86ca4ae005a890555f7ea87aceab306b8431196f8ac3ad092ff44520b675fd745e02484db20b432f9082cea1f2b3177302fff7a9295fe6853a42713263d322b78a826a7a7a064642847842ace394d4c2468f31156d9f6bf878264527d056b0c93c7722f075dcfa0394153b9a82d28fe303a5ea976077da14daf5c9a095d718a8b1fc8786b11670451c1fd5ad5838a58c0598852ba73ff29f92df19733a1878924c4d6e6e1a35a66cd3a124be77d289faaf42fd57faee4f654b76fa2e9e20dd33b47b49d06d3d3119f5b1a473a66118401b1dc6c40fe851fc82edb69a981e57dcd401eee655c1c8c7851c6da41a4540885d489f8e9471a49273f59c3b1d28d5dcb9964ba505fafbe23beb7eb7f5492d43146a5f8b8fde3c61f7b10604f3fa95a653f2a50f5e3a548b29f0ca731270f0bea780258626e21f7c8b72f19cc348899268cc55c7ef9aeef2ab69a0370e0643ed5fd042d42cc7d91b97537c1dceaaf9449b3666b287dada2f7e353573fbf7d4677065b94ab7d9cfc931d4e83c4dde599f8d6a45e40c1e8b944a85ca75e0a71af3f7e5fff13d267a99526c5b68a76be32567d6b9b4a9eb8a17b76d38f10aad396df1c1c59cbef36750e5b6b17b6cd80593c2a038992d93864cca5f151721a02ce40d58c131990fe307232aaf21b5b68ba9118239743dae994038dc7d2ec3628b332a149acc29ed69607a8361e362ce9640555d538f36e2e8577c8273bc2633bcfc31806da2513f28d488708c943bc3eef89b7efce8bbf2f7a68477d35625271d4f604120b74161f958e704da3edc14d1431f45d4e41138ebd9f0f65155beb098fce18e422fdf78041dccbb1d6e5be8786617cb0cd60b2e49ee3e1bb99475207e5b715276e3d5d89d79b7ab0fb995a9da39f50853653f7c227b2f145a1168135a0e3eee764a751a5edc80eed634a4ddb482a77f7100f938276009950b4f0790c7d20e8b610a624f0cead7ee1b9344934102eb0ac1e62d08261ad9062d4ced60d31d72862146f994f664e9143dcec10d8b13553a5168c60f749a0add610ec49d80dfba1a111dc9d15746ed74cdb99a70bfdcd8ed01fdd2e62a46c465757e18e9c5aa05773e38fe600156e896d61d1267109c900b65e019373a8bc5837345e095482c345561e0aea977788a632a1a5b25a637659422bad3286a739dd2ac637645f6388cce41c9e1c894a7078be4491123be7ebee27ee924499784de345c08e7f4d86152772cf0eae541d0bfcd2419032b814ae757db87af3e118b2d40c149467b7bf43ff4584f4bf8121e13f068a3aeb6e39723895c7bb4714fc10e2271b5d81550446729db34f2218199ba355f35fe4af65e9092a0500c47858a1a0114401e59f536d780e4f4c987b1a16fff16e25c2fa028b5d58346cd557e7c8d8beef8fd2127024c374d83412045c52c25b94b98805a28aed910777bace46d94a03e31b71d59ff5664a4d605d2155cbd4f4d72aab45903ed90de4052b0e9de4846bec584e05e9d20998c5c2c5280bcf5ed8a117e3fb8b3a02e254dc009a8b76f2fb06051992d9d07bf40e6755b734204631fdb4e88c262f8b05ad9070820aeef39b893c5705d7140d706a846402b65e0409ccdc4f2bd17a9b31e9daa736c45859ac473033e5bf3bd7848cc9614f2ab46e4defc40bec03b674c4b26f3ac1313d1b081975abc1008a64efca542e0e1e1f98a7f40608874d299bb3596aac036d545a5648ed43aff54523d05757f335b2f6f6851b725e789e6dfc7fff01ec9757185674557220033f1c2ffe6e811ddae7a9163e88721f6d53ea0f42c5d9553c304fca01edfa5bead654970a693cf1ff14738f4a36f012bb5623d34e040598a06e7ce385784a99eecaca34a0c88b9d48e3c966f5f48b2d458042aeaea5391e80c30d139181c16db2b87f59d52a048dbde7ce1d2a3b00a980e7f025f414e1ce49d889fed475f7a9e16d7e13b26ec1554dfa226a91633821486eca3479060e82acd3ad14d264e47b3a6d653fbfe5048e15703aa9525d877a0f5bab898a060fe7bac43727a487dc203fce3d992e6eddf39b777e57b37f3000f03128c093d23ecb614e7c92daee985b858abbd3f10566d03d7d016bc5bbde2230c7d16e156c3abe4dd6cefa23a2256b17daa04818b6f418cd50897edea90c1a2a7fdd95080ccdcb6fff1b031b2595a82f6bbe95569ae28cb0232e177f488a5a71ddef53ee8cdb81f61e3b2ea9a28e6bf05c30775e9e14115cf5664b47c274d6b14326c900cd840660c46eeee3fbbff6d318176c0d124861623e710c4646f3393ea7d19a23eefe7d5c6e82a4a92d58a77f27d2dcfd98314030e6ece0773ff2ba54b3f6eb637c6cf6ebbbb4f42fee4fd34b4c8609cae5404f3c942fb784f5546fb2762337acbeff144f13ada1cbd460eb91b4e9aaad6eb1e1be3fa41924e4c06c4245d2eeaaf24986294c0710d82d22085d33e29821b470e4a9fafd71c21a78905e1e5d84f6a53e30ef4ed0a3459f3e861162e9867952180cdfe1c74e7fd19ce52a6d7668c60a85dfdca5648ff23beefb132b7eadccaf642401e19d8308b3fa03ce42b36a17ab37ebc07a5bf1ae6f38a0c5c54c95be98e1a2479ad66a4de074c9073218b7bc53c1c1dc1e827149beb7af3cbdb46340ccf0af30a852fd1d20039579ab3bcead37dd327d02813e966ffc95d7a1e25f7b76ae7e44e43f23da4ff1d6b77bb7f686678b997bd4ebc3a5d606fb819563194f3fd5dcac55977c9d8ecb28a7c1b2b217de89634691769137e64a28c282052f6cb419239aef48963898033da1e9c97bf0843535cc4cdb110b9612a976d3ce7f5ed3914e0336c3515fcdaeabd7888f4349a5695ff30c1c1ea0e39f920d4d0c0a7fdd63f055555901997dea1d6e836a3005804defb0a36aeb5aa4db6e38c713c164a4557e9f7848016a7dbe615005fc50716fb656ff55cf67c873da22a7b88cdae7708264563dc939c2440a6c8080156aaeb08e2575d0f113cc79fee749d905737d23a03774ceecd2b22b4adad954bb52389f6a5799fb72713218a51ed8a416d0d782ffa8d8f658b3c12c9eec1bfb7a3d29033f96e1476b900c311d46534ee5cd10c0ea6624bfd3f775f29d754c638a8fb1d7ffb498945f0570971a52561e3420fb631459f261caa0eca91fd570ca2dd73fc4ec96dff0335b2088958367a0ce0da682329d33ff4f77337231576fa97ce78e0ff29f2c60eeeccfb5a78aac3814a000e380c06c370e227254fd47f6df7d4f78644fbeabb41a5ab8de1ca89413f46ab4d66d421d493d5b759957b0bbfd7f2d58f6f3b273b13902f5e05b6fc9db7aa215a1acaf2129b0b66d70a138b4d8f893865a6218f3ffe925922aa7f42763d05c77fb2483f805e254a39784fe750917ad2bee60f467aa3e0772653b7b85433c3180e41212e1bb719f1e479f19540013258ac4eac78f05ff74498cf67d22f3a3efc65d177411ede7eb8968dade76456a1ac930e16119e5f0a84eb077eced44a7e55f230cd873170d98eddadfd81bb9d0a5ad01d069e121ba875ddfa838d0fac60c58a263c43614ae7a84fbf214f0b8316524363cd2e6b7968f450a3f352e7a79fe80c15eb23b9c95167731ec5ee1d0e59742421ba5c33fc5dd0e28357ab2a3692e3e7d44186452dc37593864305750a00ec8168c70dcda6122acc5c079d6c8df44f2e00146fe311ecd25163dfd99290cafcfc18da88bc7fc6c9ee0399ff384d0d21b6dd9eea77565ca2de7e9f3b10279073e487d1079cba3bb47537f6fab1951369cc19d69aa4cf4e8db98d7a815a45a707f64f5bd04537200829339dd18b15560b96fd6461dcec8225530e5397ad6d40d981634ea86b18e2b963ac7b01b40d288d1eaa96a71bccc965f152725745a85f40ae28bcb816d9a393dac3bb41fc3aef9e53b9fa1d357a2a83ae756e79f67b7c7e5553f66c07b2db55f5c8526da2c6413a49bb02188e8635c54cc0350e407b7c899ed306318112b39d4f11c39ff637f1ac35024ea8909c64dac44dabc9a26307eb8f681e58ab0a6fb68213b7b7ac7289bc371ad05c6106f33fb248396580bab84e6d1317a6a5c4efb60fb5e8925cadc9e5df4b290ad7a8f084d96e91c23c960b29fe013bdafe91b973bf7a5e49cec2560c3a7770280babe47f8f479ec69295b98ec94956adcab993726635c3ee1a373da6cc68f92c134a4dd36b0465282d1b64559529e03ef21cf2612b04d024f337c05e10cd03d1f3ec25bb99eb0209857ec2b77c5e4711f831dcdfc8ecc4d7491b5737f24e5cfbe949446ba9983218655037c474c6bdd9e4bf4ae358a4a536ac5681879ff771132e4510dc3cda1133e5f15be0fcc006337cb3dd6b32af3763cafa29e459aec114d1048f0e2ab5359db863973ad88712474e85ad28d2a894777ea4edc295629217c3233f0678a227b0e4b5f9034782e589bfb3b921715765257419c2063fd79ef14caf833acf51efc390dcff06cb2b9a452fa928e16862ab7887c1f419298cf809f2765f6076d50a1f1f2815df04206cb2031a9ea0b11176257eca84398b9efe68853e9b9cfa397f367798c8551b393c656e5c50c3a6da75729c665db0456d52e404caff2fa831dd807c4c90acd7f05cdd16bb787ed9e48946eda6b0d4c202324df6ac5e58a8d12353c43d212b2e3eabe17a9f3f65788e5a0107f2d04ffe31897ae30328104e67c3b4607f8ce542d215f38a13ffd3c0efd4cd07968f886d5db501c4f1d194ec081c6d8ec7e99b68f2410a37c5a1c0767e838f7e7e41432dbf83c8ea15035c74e348aba8c2040b03e569e45d92a65c863404c181162bcb469cb0620e033495a24f41cf916787789c24de5cbd8d7440b4e82b18b0f7811cd4afdb6e879073d62e163f4cb9e234a3eeaaf7af67471667131dd62d0daaef7b1bd297cd27b3f351be15dc927501069e61bc03399b896b6a1dff73c303f815025829d61bf80cc73fd736460bf8cf9ebee54c95a33f4dddf1a520cde333e691a2a347dfb4f63ccfd80003ef67e3df287c5388ba9d3a4f9a1e23fb21b72f0a495f9c3172be27d711c5cef4c2476238f4b57eeea9cb1ca9023502b8e8278db520bb458dbb39a4fcede79778062608536ecc8a18d11347c3f0976d468592425013aefc40021ab049d25ae895822b95ef89405cedd89e69da9838f24e0ca2138e2882d52e41fce21ae0a1818ecd06aea0edf0be200d418dc004dacccc7651285259a22f5982343eacc907f0e39de0437735a2a4d0c5c26801bdbeccd44a925c5e2ac84cb4440e630e5690d3e85f4b6280bdfccb7af8b58944ffc5565fac0c31ba0fd4a33261bd13aa063e395ebf937e7efd77686e915f6beff6551e1d2947058d5796c1f9a7d769e1f8ccb9668bc5eed299c94db736a488aa2657475637bd823a1e3ae071fd2ac65d0f0a851c30fcde450de6e429024e3be0b42be458f121bc426c0e5d9f9d5f134d9ef2ec1e36d938d0d604f641e855cfbcbab81ecd2b5b3ebce7dfe9a1d2f6d8bcf72f97b729ed7b2851d6366510d3d5e7e645f2dd0fd5b6ff5f11a746dd974bf25cfac71d35137fcfb2706faa4264247677ee3e2406b6b3e70d60ec24f717c6b4a4f184459ca662b4bc842ccff5bda107f1638b42649b04ea6d3394115021e40aa02f42b78ff5e0b760c01d71d70b41af1af7ec86ad69cc95d3205b83bcacfed0fc9cde6e310944ab1dbc7ca8abaae487af89cfdac52a957e7229341e97f90d3ddf206f173c1d2b7a9153d5d8d4dff6fc6cfe83f1037c5ea6137003b3a1d7a6e99919f0f1f6efb726c7a2e359d30b16d91f608292503f5d0172294faf419b55809a20890d9647905117ad2252051248b8e94614d569779dc613ff81c37d499da69c56860c12815cc04913375c8ee456a7d1a4d0bd615238c30e4680b6442c2ae19269227eaeb431602d1b3093e70f79f523e6fb79bb722a02f606907bbf98b86ce1a0803079f64510a9541a34c73db801e1bd69fd8f814f267a652f156a0a0db5e396fd9c577c74da3067cd74cf93caf5c3926e083d59d348a2e5120c3331bc27e63c7753b7a1583f2cdcb1245d1de031274a9cabe823f6604f380aaa6c78313a7859069ac0da4735220e070b0725ca0c342db27213a2b957f998b7f0e3ec52b2735b4d2614057e2337278a16154a892e89b8a6bca9a99cd7ca467fbcd029e597192338556812e3064cc9aa8082f14092cfb1c9e9dc71039f8d490fe773f872ec7227c939ddb2e884896b8f54e6387fd4dbecf36c9ebb65e16ca96e7867076bf8c4ef757fdf6bc3d6db2c8e7d148ee693d01633d484598429414d9397b9a7ed52f301361de8b3e1d562c10fb990c316eea1f3e59db46256a1831f46113f794b3f8d31f678a70d0543ec4f6273ac77ba61620a6f63ab3452e5c3e7691cbc27533609f2c255060881d2c0a8296019274376779f6eece9351929de71d706ce31144fc26f1f1993da04e691a8059e14b9d958d479d29d5f66588555c448cae6bebc23a7fe8365d9c4700d4b77d268a9e36b3240d9183bb2c7ef6c93daf0f95c67c474ea989061c61185748bb36ac7372f628470a2c7721702f84697149ddf390eaafdb34b4041641244eaf5eaead3242464e924a1e72034a74c3baee72e2c0824fcb8b1ef588bf5e67ee0b14b4a13ec906563947827a311041f7786c34b9113c87c47740f7db188765a4e4568ab2f8d8738e7acdbcb5bcff416613ab5c33d3228b18eae2053713024890cbefad6034735d3509ec39fbe0a3d3d123bd3c2cdcb6d68c8a013cf810dc8f1ec5be08e55c6d39a505ba600b1157e55930a4c92f95b39b96432f18a90e73468f78da0605c6b91e0e8b4a9b11f3dae016cd9f314a0eb9a50c2ac8cfd20cfc874c976ae1de347aa3d0770b85d52b8645c61c71b66fc7a173eb004bc0ae5ff55fa591f60e289e00d2292c7f9e46c07249a2aa7fc075759f180be69e63c68220ae1726ba036bc70839ab22b0b3f467839dc23ff67f0c4c1f34804adafd90428abe0bcaa820ed214738a1101e5fc8ce15dad95ff876affa7987a05b7862439b26fc3c443a74a4c9685f2486e5296b8e7ad180ac0a195bffdc2060b463b3eb25a3668b9430c4dc3c1745413a4fd2271ee1db43a9869093a33e0e2b21e788af7009ed206f7626287804c4a06a436a207367fd597f14ece50b437e854e4d33eb386d2196bf2bccc799140e760b23ea8bd78025eb340a7e53950698f7f94706a63b7103ad442ac3f9689cbd3e3b73d9e9d3ff513475660e098d467af169bc2254ed7ba0a11e230fe751052b33dbd0abad160dda6681f9607199df6c4ae15fc5b125f9c2c5f184df5b96c4b9beb184d65495f56c56c3990bcb2903ddf6863ed518414f3c6c7dff549581add45166fd8fe4ee39edd639093274892450508000f97c2c2f2b222b8b77b16c46d586908ba49319f390462f5b59b87ca14eb87ca4f8504106140c1f53e3e0215bd074b8f845e74211b6bd053a4a61ddf3fabf1becab43850af5b0471bc568da579a4cbec53aa44e692a088d7ea5d6f4f59f33ec3506ef8581a38934b51912eeac3c6ec4c43fad93baadd0e30acf614fbcf7191ade095ed79151ac5ccec877837c2cb433616e612c85e88f6dd97b6245da1c3f16b1f77931bab7a131488b7fa288c96ebc6b05f23a6239a73fb12c0a0b50cd635162a34afe98f0e9ceb59e7c08f678f6ab7b72bddd34f55c0bf425c9ccb914f5016202716d03beb9d60d84fa5d870cede91769f3182c6d7046582f6b14fd5cf625f0182b3156e07e0652ac522be9edb1ee93fbf84ad986feeb00ee9cb6732dead2409f3b2af7fd05c7213a5122916f505823396523e0c0357f1df4bee99b9b5ccfca476301a4e5a60dddefe4710035068c63049a216f0dd168d9225ace63907eaf7e739cac2b38e34d4cbcb0a1a6e09b5e9ee7250da45735ec3fde9c6aab8ecf49a1b370cf6a15e24d54dbb081a74c9407935aab1db8059ebe2528906fc7ad33c9ab3dfdf2be96f519933ac9839e168053ede025adb7cbe16eca81df264ebfdd6e4c0bfa471b9414c002f4603d50ca5997dfb48056e5a2092eb4e955c24594e832a0cc0f9daf683510fc52d3d7690ac7c1eb3276a7ecce31b721703582148f25bfaef8585cc2cf68ddcb71b5bd058e07dd7d94e323275835fcb8ad24b3586ac31a9bbeafd4a1b46fb6ae7793438694d1e614530fbf6ff41cb5e83095d8f4d1270e5ffb87626b8690ebdfc5147c7dd4cb44d629dc531e58b038d0b5c66e16c9538698265f5affce6c2914656174be46d93fdf732284c4aaf43c092cc78821fb937ab9c3ff727909dd24832f8d9e644487ac461e528945eafa587f3a2d83959366caecf5346e5e0919703add7bc952d61f0153babe00d72add308c983813ade750bf04caae955480317638dea3af361ffbf6eb0a4d2547ff7008867353b0e64ec2bd52f32568b448f10d6c0f9482ba5d598e0dca08fd7b31c73c2355b93d49a28c9e709fa1d8a8fa701d2e989ccf519bd7bf63d285bf34594ea71dd0733372570d4d5c61acdc64fd841fd37cd0c5f79ea7cf298a992a692b6f8e79b260ea2c11ca7333a9b85dfda3d55cfb3ec09dbd8f98506541cda15f3b3c4546431b36abefb20ac280350f36cc1b9667d63f8f982a886f83e6da8c9061ff239a6f75a593894f037e4a532022da34121ccf89541821fa2c9a04b5d7cac5d8efab4227a38f96f7547ea57bc25d8367acbc2cbbd1603e2b8addd5492da7f9bc99028a6ccb6abb29dbd5c1ef75c5f40f812b095203935adf09eab20e550ecb40637648ca01a667764c101b77d6c20e3118607aa3ee74e7e456ff4130963ce21dd711fcd895a3993c09326b6e65b47d007bb02bcd513e245d900705fbe6c9322d5600561e4093e4148117e4111f146528534a747181b5aabf7042d0e6e6b8f259c004897ffd2e50b7765cf7fd8ddaab61604c88bd8395ff39c37a244fc40a6ed14b3197fbae7c595f2ec8113a057befeccc20cf7e7b92550650a4f3686468a3cbda1f3eb3f79c3c56deba2139d667ea822169b877076fde4f0ff7f0f81adf9fd814ba9898c8f84d26e4124baee2cf71fba99bf2588e21f003945f686dfce85a3c00b3f6662255f6c38cd349868638f8a8ec90ae93dbe71a01ac28f7324f731911bb3b1a56727e0855191ce057d2fa357ecbd8de8d8349c984a2b77fffab13ac918e173703f37c5a2a10d68bb5c87ca71100130f098aeade125b7749770dbb11195d3781da0f14b94d867c76f69ae3f07f8ca7b5220a7f21477c8b86ee0c145b0569c81c430a97356596d6b37ccd8c6d2b8e64dffebd2491b1cd42c203e6b4d2111ff25467d545b2da829874a375f4c9cfbf5640cb3ea741e1f818dd7a3a4f572a417ac229170d54948c1b7c3232c14481b5d9b933462bf46050e0fd55779a106ab5e386fc58c9dd1a4154de94e227b8caa54aac214d8b7bcabb61a5d8f376f78d96c87b7441b62659b21596f8637b3e0a7c52321c1ad20d9147a89abb1ccd3eb67e01dca7e9c7b847102e9e1451fa1c2ae055974111b06d70f8207c40e86c7c9b9161de5c2116e2f6e6c2e278ad3ccf194bc6466f23b037dcb7ee19796b015be3ef77b7166d3c6e263ca9b5385f98f8ac5150a900580e6c8d90c047eb6d7204f8e9bcf55dd06b2fec710a8d339eaeb8a072f3d56e84a64327f59b1b7d8e2bb24e766f67159130b4418fc39be30182fef28266c24fa5dac55f9fbf4d3aa1bf6890d46611e1b2b56b93596d8d5f6764f87725c781cb64a5c1c239b0f08d2aca7de741f674deb19ac48c18030e04d4b21b8895148a68a812d54c49b0319acf09e41d7499aab3234c1213e7aac81e7dc84383b5934eab99843bcad595f70064444cfc98a66230ba8b931ca6c67d1f8df011208507d071661927d9ac0dcc4e898c44c9ab3397365c4a75e1cbdb12e0f567ce31d8e8d64121e9f2f325bb08a1a13317dfedaa834c83a6c5fe972cd9667dedf91394259eff2c109f9682a832155b86802f8bf33f53009fbfbd8f53633316956c2329daa35c3c492285913e7572297428d025ad7ab97cd4b4c4fd49e96aae6250f347d3fab0fda92e1561154ae4c72129ee30016e6f3f2417fd0e45f395825ce9c103575a63e32d4543d8ca637ee966f42be528429b78cbc37cc5df3c953faf3dc1bb9d81c8a3194f13f5961293048bdb0d6c697ca71d3c9167eba0461942fa6b1899fef86fbe5f425b768250b2790040b5327311663850667258662d14ac580a60b26789ce5e2750fd86defb1c769e7d591d7f02d29389691219e51ae575e5d7b6351407a1ad2a8c89a12f5d4d0baa2f6554b223f76ed1f793ef503ee1402999f8b2c7885a87df3e33487b36031ae6f8fca8db8c3a8bc4ed1a7b52e7209437a4482ba71060d2033ca244d65d70422250513480ad4e3bfce377255167932c85f488800a72e12ddb4255afe2c38f2cc50a6e65c6d27c54c62edf3635555eccdb4ea9054f35e058e90beabf668ca0630b6818a6736ea2865e8770f065f14a6e42ee7aeecf25dc8128a223650c08c57962c36f85d8c559a7b9d33017376ef773edaa22e1a7e6a9a68d12447dc56e49e31426975504cc7303142b27028103dca09e81f6000b3ee7af6dce9366c1939429407017a33e65abb1340cf2dca27fb1cabb2357e344707186ab61b5b8eca4b3b703af85a69b75ac8e0332b65d69d59a9be8094591f28f96223e4c7b5fc013b57f784940997d9896f9ac78ab9417171db1dfdc6a64e42996d167a286e8f8022dee3a271ebbab89afaf3c886f4066085112035fc7f7f1a1112f04c0a02a6be8a86ecfc8d2de6fbb408780d2e41c6b89c6e200fa409b3be2bebf5b3bddce004f85d03a3204467621d76bf3ffce06d54d5ba723c423882d52786a59a373e3a9f7bced88123724cb3896b1aa03982ec4dc4099a6a3305c7ee413f2568ef171715f037b22a2f6ce11ddb3d9221ff76dc2864394028a79dc76fac59f0bf12bccb06d7aeeed34c9ad11515f2c70f23da2a7b0ae646a7bad3a8c6b70a247cd95d2f3c645c4231b8a94b2d4a3a47663e951ff748eb4d6d8b686c0ceb27b8ce088f42135df5b641a4aaa4a1280101191b68e05da6ce0543b2db472b6ee4e0a4ab98fd60078f0c88f1ecc72364fe892674080bb6e26104aa98bddcf8b671461a555326372417300d3727b93a3d96d301fc1dccad85c9ffdb9761b48599eb9a92b7bf3193165b509acc8b93ec78f7225a3616e5eaaca094bb66d815df116795946779ba56acc993eff3fe25d8909364159dfff3cfd9ec30546493a4dc0ac6f1f68048b47d7db946e10151df1c9ff7a1baf183a15a572e09a6e932ccb5fa3c9ced2ce627ecee36edd89e8afd190e71434f1faa4fea57e233f21a706eca41669364404bae8679bd75d26055225b5df8dfd3e64b9e771bec82e35681162ffd1cf407cf0c5771230c9f1cb02da4cf8429f968d215854f085e663b47384a0a0fd9a7350c6bdb686a6ad17c1b2fa0b1068dea7186f162ca3231e34c499118ba07e8d195d71d65c3e729c682f3155893e495653e0b5de2ef5bbc0e1f865e2179e4cd6035bfa620e496cd1fdf29aa519958160d634b67dc82f8b20f125e205e6e2e3b645fb8542c3665a624ca855fbf1b76533d1b829abbe05b6fdc057a7c82f5023a51323230d6729aa98d4b8bf97886dae5944d1e083a1514b21bceb4d875c0fcdabd1a068594bfbf4a17e5700d85d6fe80a74d2a7effdee88c712a0d5c23897d5c58cc8881577465c474eed7137da244012a24b91ba10467f08134ff2d0b9312b982b2afa95e60726abb3b2dfd3a5ef6d1e433e7e3597320d25e2688fc62db70b1e5740645c8d5bb045579e6054a1ffa375953d7f2a21d1eeb1b50b6a5e9bd53c2c958281b622f3820efbcce3a817c9275dc7dca6383eceae3b389f5ab508c1efdd9b1756ba13ee8ca498ecf6c228496c675415fef1342969f6004f602340e041b867db97c747245417812cf875ceb067ec3746b63dbdeae82d98d4340308a6bf49e09b7a061a99dd6907f7369068fa443fb8d3bfc4115a590a78c610501b324e996220ca7d0fc12592d4255001d8e8c4b412bfae72d48c9c744b5905b76178364e86b7d91451897f6258aa0d17955fd01210c40a453d8bd10ed230978ba95fe3b067fc076e099a4f652af1eb872a114ca946391cb5b736f08054559193f0ee14422052e06b823be530e8bc64e5c804b41c9295dec968b24686919c587f5eb6c82a42f15c40ee13e8942816bd354971360a93e2b61c37152db669747698b460231b8438a2a219f5348870d8aaf75f5f4c81ac5a27c07439ee4d219e10f1f8cc130203e1aef6e65dc4b8feb3fcfab9b17eb0845079214062fdaf4a2e1c7ab21dc776d0806892faefe15b88e8a50cb2ec18ca566ab04cf19063fcbac0c392a6aed3bb8388ccc6af3a4f758de8dd04ad93a8424a9eea74578ffad88fda665dac4183ad59037fd143398710ee989b11ca178d352fe38666a6c83a064fa11ee6c6d724612af7e8a6eb51103ad7d21a7cf527e4eb553856dbb27cc7eb4e4bf670da965c143d4e2d4f52ab548620f701899b5b35ad6a1b17c30e6d0eff94a89567a0e9a0218cdb1224d65c253ae9a5546565340de532af97c8992f57099621c9c7fa7e8dae288661c81f6b3dd9bfd5490e2354f830f546992dda2f172ed4428eedb9534a0e363d2e2a975b592046d46167fa98f225bc8f1521e1d2741714ed5aa28ef83f10fe999952eff6702c4bbfc0e98899b28364428c75f43ae91831d910e69ef32395f6a954170d4be8fb9450acdf117a5758d26e37469a990d61094701c5decc16842f467e14fc693b6f293905b5c60595e0ae738f107e7e2f7f9862eeccd2c67553cf1af4018384b73d7bd0d2d4ee8d87dbfde0abcf9c7970db63422decbf58080673e2c531267771af339a4c59fa0c133653951be96f450af99c201829fc1a340d6a9716d44bf59f2d204303365a579a1400e99f535bdc44a704ab9e928bc3098c5522fe6a619c8ba74247d23195e4c011d2fe2bc86b46901e4c4b28aacccbcf45b5a429c492f2bc4725fc8602e436515b117f8e2aa6a852ecb00da5e65d6dc694c446fdb4a692a284da3be62eb42680de58e7838eb3842b18f5da5de364271425ec35d763985b388bbe8f68ac23d2bcc4f3a8872ff159f8cc188ad105f123e7b6efca6e132ebf88b8f665d1066dbcbc72f7429c8982cdd1c625ecd240808739926f68049c8cf9f3e54180b4bcb273c99e6c65e970c2841922149e68486f0d82b31aeb7fd6ce30b9dc75dbf84d091c2dbdf31584eefb668d553def85d5ebbef25c87292d6329a48386fe01db637f4790408bb566f9ba7be1cddbf963155beb15311e67e0a96994e5a504edaf712e0ab833ecf1618461d3222f7235f6b4fd39d6ec9feb1fab2f9ebd674618ac711df78bdc372f71b08f64b30a7bc2cd01bb0b0f7806953755fb700d754f68cf95212012d21333d7b42257ffc7c030f213f4c1dcc022f10910d48f5954fb0179750c43df6b7a3c2fc1861d1d163390051111093c1fdb7abff8840f0a4b86f2a408533a498ab7129149848f047ebbf24e070c82be9ceb9e99581024cc3baaa5b7274b7f900df2fc3fa657ceb3bbca83dbdfa85598569cb701a61d633af428af931b858bf829929b496438882aeac0b2bc30f9aa748f6ed1de42b80e48a10408829a9f21617baf57b4d85cfd5c86e882e656abf72ef17b03d0e29e2ec14c78ceee1be22b4d9720f2f4c7136983ca328471c09e146c94517f3aea348764cae63b20e4c2bbe6305c86ae6ec14e834bf941e163eee373591b8f48d9886d07525b763a7d3845a5b8db21755d08cda258f0b8da8368a57568359b9621c9e01ce7ee20ae53dfdae9b5dbfcbb7301a20187313456eb363f1f7b482a80286065b730d543e4ca2c95ffd8628d08886d69308b686a707527c3af8b7cf978053c4cf10088c5bc04d3b75f29bcbc679774a7b9d497a9753138551eafb21f8abbe46d4824a11725f8fe283545da43def3a80e5964222b067a203106c699dc82b8a9e3c7ba8d87b82a49ec4370980d5766ee43ab7fc7669876d5852790bd1c361de94541b497f9219ac5623f2e65e84cf95b9945e3ff6b547516f0138d1b87e92e611b126d4e755900afdc5f336d71252d2f3099e5dd736628ada13b27e07381607e78db061641f346e054e086b43d2452a9d2c1ab7d0359520bcab4c59ec70f88724757e87f370c268703c754620613242af54684f79bb456aa3b1810398865a6a822a221540f3b593b353b167e557dd3a4b8e79ed438baa178c7d85a695881313072bd58a6a703f01811c5d8a650bd0864a9bc34738aa9b886a095c3761ca88eac9481542d656c084e19a1de5aca995694bd4bc1265e9713ed48eff834cff3188bd8889c04e2c4201f7f4c6f1fbdacf80ecc36a59c63f3bb4a5998f87fa43d7b049f5e320b4d74fad76f2f4d3e03d85f989d8ab1b843ee2722b14fb7fcd19f8124ae9dfd4e6f55ae99c617cfbc0f85fc7d1f0eecf397a72bc470bb16d4fc79bf8d04269fa769a7572517a30b6cd4b1d74912ce4deffd78a8259c3a09c29093a3c997e1d3439d300c945df398ea2d7bee8031c818b6e0e6afb361e77c6be3b1f92ee74556f2c6dcc7eabca8d10dfdc7021dee95a8395b0398dd234368c711273d890070014ffafb932cb89093156c180bc38ff28c73f2949f75d4c62847ac0cee5a3b46e411df2e09130c0b7e09de0eb46821005c46a6a280a01dabc8c905ee3eed998e467ce985f495bb2d9676b6c351fcac0f281c56f0c696e88b82fb760f0bcbc6afbc2dc637b0a6d631001cc21a4fd897aca649bbb65d65a5a3ea57faeb1201791bdd502ee5063dab9df22a23c9ce6bfc5ff3691a9c7635a6f9ae77f1a086da14bd22d235b8447efff645a841439c47bf69df843745369fedd8b5ad3778ec76b0e5cc9e2803962e0e528c408a1c22b4092c1e5262f4fffeb48ced992a0dccf491a93afd51015e84ccc894bdd4bec7868710f16444f57843eea3b56265746427b96a929344a79fab950c71f150039e3452b4a0fb1a868515ea53af9551ebfbf8bedba401fc44de00f1fbdfc04eb7609d75ec9cce78557661555d1c227654ee71bff107c773e0adad09eccded8862acf81f12a19ffafcb0d56f4de56f718592081c6da98f8bd333e76ec8c9d3f7c413ed2cd24e43d0833c1efcdf175ba26e602b4ad87e78938d8a9724fb5a6068c35dd479e5a92d8dce369f719de52766786c4a6c6bfcd500934ae28ddc00d676f927e336d032ae60b3083c9d740aadaf6ea15ba07c54e2232631e6c3cb0e708848188136c38a192ceb5c12903a5aeaa415fa5878451baa4e091905610798fb29b459ab6fbad4e38ae07c4bb4d10e4bad86c714351af514b798c4f670a38b550253677061af77dec5f6cf791f9d4161c6f9dd33caee2c98151197770dde285767869564425169227d596e8d8862f72f07f895cab5036283fbf121fe42f33b7c92550cc551e95c27c0255265e61f846716063dd141af150a4e2f93b00fec4ce679dec4418576b84df3ffe7b6b0502ecdfd7cb0fd962544d01c53e672a648eab1435bd959a6746c0091f0b1e0d7bbcb2295a00c08846c174c8dfa99c33921028397e25f3c2f71641a66d3eb0880fdac723c0976c5e962d04bf33f76d966d299c14b00e0a88894928b7163a1af790bbd3265b0e2b5c86cae893dc2ff46a726309910dbf6c44b6202d90918d4c95f66bcb7895d0a37572b8855489fc6c613141f99dab2033078345d0843c21180f085d7ac7a0af364394a65275ec4c7d92657f57da86ad2d6ccef47a8fe633c1057546aaa354626603eb37466c5c5505ad1fd3404b72fcedb4be39da76fe409b1a529d54e7d8c81fc28887e0b58039f9b482c03bbf509df4d53702c5bc4dee9115a70a23afe47c8bbd9ead8a7dfac44a465aec598cb809e12e77ffc57b1cda750e9f23fcf95ce3d92ec71de7b1f5c2bcd2810144e89e8370800af08be84477dc5e984639c28ef117fc2301c02e56da542cfc7c51ae314ce6cfded14ee37b14f483930b3a94c372efd9edf4abae82374c00702cb2bcca7ef1047374f9ab91a6fd5f8f26c264e0fab12e9565dd410224f6d7431c20ef22a653f9e92c8e1ac54488225fc27995caaf37f3367fdf0181c32c2d23b16429e8fb4be3843a319e597598ef580f7a1c0bd4de581dc830370ba5c1d39b4e4ecb29202819db176e592e607b7fec6cec446142b4fa8418cba96f46e59c4a2f34aaf3cd2add18a6ac9ad8248698921204da7dff081cd465ae38fa74dcd35b8973c3d4ef0e1db565aafddec71d8a97361721f39e5267ae7bc95a919ba4e8338864ded831b0ebd5a789fa21a6f8f870befa63c248be1432e5de839c0bc8a7141c8054e1723b9b1ab6f7bffc75d164a89fa75cb12fe16e53ef88b23c20f4d540338c6932d5c3a01139b52485fb4662c91d174f54412017fc46ff88d2521513edfacc51784b8e195232aca67aeec338bcc559298851e0a9087219029d2ca2d3a3f9f40c2ac5e60016378fd428530ae1ddcc8b2fb5c293e1b2d86b68acf42a55fbe809bbfa2b6981f6f0dc202599cd1381ad13b00656de7dba140f0f79732d1aabb3534ca8a9b18263a9721b446308f4e4de6061accfdfef8fff6d4e8fd9804ff01513dbb8040f24dd37589d5f4f7826b6d13b4d01d4f7f250ef8dfffbbd4bda832473a4500dffc884d53c2db7d1741fc30f146c2c70405836120afa273202f0f0bf72edb886e502b01fc3aeaff93bef116666458c60ce610ac8dc56dfa7caeddd933185678ba40005fef4afdbfd668e7ac66bdedff5c0eebd5ce1e46d185065796e934c9ac27e989cfa770a5e1ba9dbfd694015e03f79b408d6b90b4aadc52ca8f8188e65640e19a15dcd6aec66c47d336ef2318e0214e24f63b2db9debe3bbbbd3857ab77a072745fbc5d5ef6db688a52af5826c0428a38f1142ef9b162e21bf4ce75a50232f3b4658758dcaec199fb4132bdbd30277032f6734442d9f66864fd24cec2b2facdd49b2fb821dcc81985fbccf3d5ef57f9f09fe32d1671cd30371fcd69342323a8c08d0b580c26544f435b57a083b30ad58e336258b37e239f68fd433a4a2c24d1c3b1081edf078e0e1ef839543ffa35ce6fb003f32686db3aed8cbdcd9f659b7ed6e197324d7f4114d40f55d762ad82ec60c21d100671e4eb63c10ce6fe377a50a820f5a38645cccd643643c4361a273a4c0d106f4fc27d4ae6f7b9117083208fc3a5c0fceab35a568088c06da7a43fa96e4f9089ac44e4b5a6743d16c30fbb357d737b304e7da2f45c5b64de0cc67e55b346f8dba7c18f9f19e4541b690dd32e259c761c65b05f7dc62f788bec61d7e469affb75e10b8d4a01cf39d2cda3fad15166ca329637a896616734929dcd741d4a48397265226d8bca6decb1278aa33e974ce77ec9aa7fafa85d42b9fc1cf174e9b10ce86918874479790954b5fec9110e02999bc44e8ada7d2d0bfb4e36b2d8a5c65a2189d6ff2a002828ea068eb9e2dcdbea0a4588321a0f5ed7a024b094a0e27b1d5dc0a06a3b0330bdd6c1a3bbd715aff24acf31efdb97c54661863f269d652618c94395e6e624f197c1eb0e980d45da80bb8af0585ebd31d016623c7594dfba86e4bb70a4dd5e12b82617a7846ab99fad9cc17053481acc67f386e9268bd822d9b6b00ea66d9bbb4b6d7201e2790b620b17e8f4508ba8eb7fbda84256e422603b8c9fd5940dad68f4aa9ec527b94bdcbf8447fa74ffc70ba045a6494c2487efb98131e0aa0c83a4c80f7dc6878051fdbda75af984c8cb71c409f3888e99a299eef07e5b9239b55cf52ec966c9e4701fc571ce3bd8808013839a8ecd2b47c18cde42b757643106b2681254e0982a5c289b29e7a46663135facbc6c9665a205a3cc2fc4791e393a37eb5eec352231e5bc2e55657cd82369c640a54becdbc38f3e00c23b1793c643f283a5fdb859ec5e5e1ffd88879dca3d757f4f133674d91932475295844799493173bb8491139f08077f0966b6fca7741d283a432fe3fbdd24252dd746356861d421321c58775d38d2b35e63cb5f89c4804bd401639d703f87352fd5db53e3e0f551fb59b13600a1d35f75d3cfbd971cd5a21c4ff289933e257b9a3b3da075590f77a0681ad231af5e42ded1b1f9fb91e373e33c4cbb0702aa97c0038e388534034d12c3788364b2f5c48a8d6ff1ed2384c5c3fcfd0c617c929c780a0a8050264a5ae1c5e7ae264f8a9a1a18813b63c7371b8b4c30feb47e807684e3570d5677c646d9cf5841a4e54a9fa52cc92c4bab66409075489760020d2c276e79c7bc879bd33f991b356ad06097adde94b475fa3e9974b1a121895af7e628b62215bf90673ccb01edc63f3956931e26e971729bdc26e30cee9f7980f9bb3d257bf8202f810e2b2c4ccdc0a2493e3dfd7bccc8cd20a7501c58afc40012423efa9aa9cfebc1b4a94c7428c84bb5d518641825ff2213ba6335bf132782b1f32aa17f477826327da676b52ca4a98f1a5fd7183a04dee12531bf4294a4723eac3c7665e0d3bb1079caac5740c18805c32f0598041e5e18dd3b106cb3962585f59229e2d20d2685a1dfeba77b098469b7515610b89611fd2572ff1d2cb8e6bf39375b984722ea643516f515f271e7eaceec2ffa5da949b585a3950fd35ed11195bee7b0da6047430861d548a46682727ca4a09fb432b63d783bb2fd8b7b666d6f09b12b31c600585a04b5ec97d9256d6f0befc7a91c6dc9263374319fe689c7444da07cc0b3123c92d6539497ffb4e89a83d07cb2ed788bfd7e3f7bfd8a78846979643fe71fc57c5d510ae61d4b98fc4e7500a44c7f800580cc4ce464ad20ab7b70b9acd698956abc905a5d34f8f7edad2c1e2aeaf051f7e232971c613bee1d90b75b411ac027342d54b6906baee91efcac17ee0ba97cec6dd03bd97f37b57aabc74853f722afb86f690bb4239e8b23bf30424f670ae58d78771a26dd7e77f6c7356dc869dd122c05602332ee4e8cc62ee43a24e9c508e9d6d8fc0a78121c82fe4598243faeaeabe2496d37b4d364f700d5c28f62e426c9eca71ae1f0480b351349e4d81c30381176157bf6cfe16499b0468df9d313c3428d1e3ad51f6fd68a4d2d6eb1c45020e70570c2d031e27e6451d58481cfb0b9a30c6fc37053a4f1b781507390c193ddd8f2f0e42de59557a93b2a1e45b2fe673303fcbe52e4fa1e2a4a133c8c7ee8542174ce0d40713cf8197b5e9ab65591dd34dfb533fd5931ed0565dcad4e7b85ac64ff60af72375b9c0d334b5dcb51827f7073e9ad9a3fa6b735cfe07cde6a95784544d7c3653eabd273d194d45dcaf8641e91191f4e318aad7d83e09ddfd52754577e040b42d4a753a9606a73eff9ebe17285f09ab65e34244303c3ecf4fc88b0c1b8eb860443bd68bc4ddd7285fb13be19a3ce26ebb82871c626bd088671e5331c4b71b3755f253ecdd9ea3adc04c235487d4fea3340b60eab8929a288b78b9e01dbb8ac9707923d7f5de636cdf497eca3544259a08fb67680f964d3cb774e47b6e96f97054d1e5d7c9dd752d1e67232ce0addb7f8a7b82c4fcdf3b3145c3c6078297b2a0b845ecc99da4bc2b4df204755440e9d6432e468c95d606ce9e2b1d74817ad7a85e2b5f5d51dd4fcdae4819419449bb39e99df44f99c15f4a79913c456714f8e27827612ea68b8d2fae17fb4f1a0a8b437a64e65081d2bc19f8d13d0743e64b6a6ac59e8c1df969c45589959b412562d0bd4d4f33b72ee76b23aeadda3cb02d72379505c6b5372a9ba3644d74d4bf819157533435f81065867a96526b36247f4671d57aa3788fd0b721010f97813bbd87c0e48ee98c6c8884cf54feb3780647b8825ea78964e3ef2526abfa95ad430ff07f616971b3906ff3bd5ffcb818df57b9f0b05660473748aa2240920bca08e9e12fcf5e092f9a1e4034a43ec9a44847c9847f876d1a7067d51f677836bb7223c579da3e993267793182ed42fb7ead310016f1ee386bdecf7f92f6bbaab0dc1812fe6e0b6b7a6ac82486d80f05d042b69165b58ea46b0ebf1be9965d900a285cc76bf963ce6b9b7f3452f63fa751ac77298f4a1b6770c0b97ceb597ab46e3de7c41b8eeedf73158541ea46ae7cbd691d08cf8c06b792107fda19eaeafacdee996995fa8fcc20ef10672024d7ecea55a401a85cd859b35bfc2b041190e841ef37fb99dedb7a375ac67b01eb8a1edec8717ac8bd0a93aac43a84b2fa94eafcb974943363c508c51b38d280eee30237a8e3412b2b864eb84b127bdd581d571a957626db08ea92fe6cdcac3f55857ab5f1f3e45ebee5c972afd50da6b7bcd976d72b158800c888bfe8ca57342fc645d3d2ca5ea1708d9f3efc2242ee92fe8695f53a6c9f285e65d02ac4b0c537d5db61beded92e71401d3fc4476d98734a85cdb125a771629a438736688913a78242e509e067af91af5024793ae13e0fbb55a6d7f2665a9f213f2217d7c132efdf2ece2106190fc1a7ff67f988e5665567e91684455f2bbde2283e34535f739b559a99040d3bc1bee5992ad52a60235838c942e5f0c8c8c0a83788ee696f436f247d7ebb9b08f92a50f4493eebad843902a048cc5cf2b4b76b8d49bac9b5b7f3b8edfe55286271c97c96e100a1d358d6ae8487102967eb8a92eeae4511bcc41147364c7e3316b819d86a2434d8b6cc187d9257da4e237ae91cb21b784b6c04cbcdfbb8f0a3210861d0faba4f3c6ed517d414e85989b427574bc0f758511850e7f8ce9b627746825d6a7dba4e2c3bfbe79fa028c865b506d16706a498d59f4cb320480b0eaf47168cde56ba66055cbd3da9c27e82350f795a87298745fb77953f08080025da7339d7a7adbd23729c402aab89b59767ec0dcb27ee826914a083d00db928c176efa269bcfce1a40e1d8bdfcb181de448ae3178798c9e09aec6f0a6ba14cfcacfa588b027e5d3c4f82542d00104e026d3d32c866d0faa7c79f1c36d8f19ed9ad6f155db6ec66f8e5c4e19fc133c5c333e097197cc034545060d08bdaaddc0e0e65687887b51f817a35361dad4f12c1868938953229ec8f44b5ee278dfdba947eb1dd1ed8116759df6db42d8bfa013d39bfe43607938202f6f5f443ce1b38862252117dcbb02d9d05215bc715c096a5c23306e5a68f24c044400bb30baa330aa894d9f6da9b22aa44ed1dd12a3bf1ac72e8d4e6a7978ea426af63746afcebee27e575aa1f3ed1e19822a9598fa6f525ecfd327ae053d88ebcda0745b0be01c8f0fa816ad032d20aefa4ea210ce9258e53f48c83235c3990ad32094cdbe29de7313012dacce15bb9823c6ebf5af39fa4d6319cab876818362db6948492cf90a2a0cc47ccdf1f6a9e551eef95a192d4c9c203156dd7aa8872e04e0a1bf1b7d2b854de12392385836e0da2268c8c20405ca6627655b0b3516baa55a13ce8001e8087f8712cdc03641e4bf59ed2f0b894ab69d8bd541e41308f5ad8c7500d18507655fc0d52fd9f259902a0e6f0b590758242bfc8d1e603133e9941454748f93412a4383eea840462964405956098c6d684c6595b3487d72a4517c02dbbc0cbe564458fdef00652774fb53bc13503cb167c3dba8efea4a5ac1a69836a7bc96a1ae311a3788ae2d082216824c2a176358ccc33394768d19a425b003284cebc3555a71e871c1a4e74e36a03b325d7e4565a145819a6e2f9f41eb513b095418b6a6587c8d278dab6a8431914c0f03fdf47a962207a60d125e1f8beea38564e93ccdf2e8141c303dd27ae1538df25319553ec99c7c9d015a238b9027925ad6dbe02d5ec6fd96fb978705fb70d3dfbc00ac88700a628dafef32200319aa43898d241092cad2c363d0fe2ce3bc664a60dac841e2dd3591d658e9f3076f96aa04b3756189a7a41697df846a2e63978180a8d7a54d7316a260cf443437d8c854d653d0e24a5bdf4a2adb27df88959191bf1a2003aa660c4adeb8cbc1ec7038c0b5530f725a6bf54b5e5a93f10f70131f7eb773e661be36a94c21aebe3560264827ddf300e49821d2004c8002dea958c37d7c0cd3a58ca4cde7f40c65a525e1b2898ee75bff06cef2fe9717761657c6633a51dc9ce3bae85019b7debabe9a005e517560fa7ed6fb557d266885b5e411e9cd705d564711f44135f93ea5a16250d70b82c872d99143c16b0945d9d3bd5e35a0d0d22b76c89ae791d185d17ca5b1fa8a82af880476e7b5d3cd55c74023e640516508dc9d4222e4f0ae41cc597e042fd408782d1391334798a719e8329ceccfb76de4599b34f00c9a2e263d8882c80b5dca10de8938377400c758c1c628171d6d8c940b298bee77c64a44fa84e58e3bb6d9ec5de23e34197186047e445ba71c5294a3c9aa3f168b78ec7e1a05aca29688a45001d9177d924130dae6142c63a4d80d8fcdf88b7a9b9f78c382351f5b8ee32774c6935068bee078f8c926920067329e3fade9c191306847e8c6ee2f283bc90e1034c01db3cae9acd174eaba232bc6e076f7b810b90fb5b5ea4c1cd2921db97faab5a6c82e7966e23d8cae4453389dba9dc32661a41e5c9bea151d529fb6790e3a1f3e6843f62917c8b8a13fe6cbda3ae8d24be9d1e12d5028f4a27f03c1f509ebdfdef37b1cf2fe6e0271d276575b8dc2374d7ec68c0a6be27ae21816ef5d077c02ee29dad84d44035a498fd15791793b923fdf6046908a74f67a41cff95eb6adc1c766f03912c99bbc981e0a72c3465e284b70f97be40c5786b2d799b466fe741b84047ede9d90da7fbcd8232656833afc4e913d1c164b3e8066752361801f1a61a7ba9d388fcc630ec69ad8e4b0c81959e688de2a6a91953690d25e0337a1a1d7c9be3480a9182943bdd0793c351dc20b349bd1af1a7aec4ace3ad990e143f498920c042b448d2de95defaf5d47d5eab7186dfc952ff681e6920dd62f87ee723e4dc00e5e29d6df6e7237dfe07fb7426c1b042efcf15b6ce853473bf175dc639f969dc3c04d1e16b2eed22c2fb639bc99f81939499957d771973a6042244f71b73e23b790d0ff0e808f8f1101c659e1ede3d4424e011af444bac6f5ddcdb790a6e22b058c868caa8cea258fcc6f0b0d62b0e8d7b53a6b48d1c5898cdeca7ca5e7c4aa0da8412cf7f8df015b5af82336e92917144c659c2adf47b27667b76ba964c1a760cd98f070315f3a182e0d551a95ec5afcc15434699b43e309c02ae81f262de25a4c013a0392ad1af92b54f876a873687cb522fcb1da0e062b43a13253a1998c53bb45b19c22b71f8663afaf2f9174b692482312079d91799c3d8aaff98928c32a62e9c70fecdeb4d7fad509f6ae65b80ad04ad5ccc33818c87b912154a11b22396b341dc25314d89e05162bc69d9972273b124d98b798ce393508d258da73b2505d72882853b3bcf2899844fb917a8d32ec0106893c3bb59471f3af43fb44f9d004350524a6d9fb484d5afa88157d06df505469087d16844c165e07a8f3c155f0fb8894cf76fac123a1f645c698c92670ae79ece290c212ae1accfd53e78a0d2072535b20bf08736090a88bb1571d2c36aa5ed7f1619de01743988ab77f317f91489ba248c4697130fdd6794d184ac660f2db45a4fa0226965bc528c8555f6dda470b0b31433340a725c335aa05371617f08a4145a60bbe4841c01038fc6a8a94df20e19c8c5058abb594b66299a20da9c723de94b07a2bb99488d8eca8057039d1da38c0354f4ca5dfe3159160b7f0d44e3c946200347c5a3cd7b8bd2026967825d49021762bca614aee0a9d80963917fdfd0af574cb57a83e2e85e1074e42f1de09805331a220e823565dc9debca11bca0da40a574e59d65012a7473d10afdef7df12f541cae72b9706efa54677382b49297a4af626d904ad64bdf23e6beda101b40815d64c3edf2252c54fd43d6463e5b8aabe1c0395d809afcdfd26e3e061304bb0c9df39c32084c9e51e875add6c9d090d3f2433bd943bba57354d0554fe92060c9f7200314a78e898f4d0fd9510a316f9fdc8234248d7112d3c569cc56829d003e9332a43773e127791d0010f7ff5203d822d661566b01c56198c8d31196d6f598f172c68c1eb81eaf6311ceb90562e02ee0f457dfe8808d9f886047709ba3dc9d276ccfc91ee45c8a4804a9f55299858e4231e2456a4e8defda8370b97e1df7942439105be9d532b6fe06de598b40060189b85930e65033b972ece40658b05c2116375dacb80d0170047b705a56d56ad4213a6a11e7b7203cd220f4046988789689dea277ab8fddf0c4c3bc4f0bd8a027c2806cb9ea920a1469dc43a3d81dafd705d2d98a03666a52cd195be43529ee3eca456ed2a3040f01da6804df417882375e10fa940e6cba003ffe8fbeccdc3da9b1d08ffbd5615beb5c8908b15db1b6c281f2b022d1811eaaaccd65192f7bffbee7fa997ee9b430fab2f66892d8e501a9b106b3262dc5868f213b06b1c322e867f1beb4f35e1c88d938f5740bba7f2f5ab4d8f5bdbfc0d56cde29e680321d7fde7a22d6dfbcfd44f674edd91a64043a523a4e142ea13425a0083e80eb3e28e92d8b3cae3afb2acab807595ef328d9cf52f49196a43840f5904f3e54db31099e0b613d79afb931f7f7f3caa8c9352d53d9385630a467c409a34fe2c6c7ba2bb3f23f3e0470d4090be8e84400c40af45f0cbc7b597984292628c6928181bf5f25f4fe99697a164000008e1b7a15bf46c92523dcd7eba37eb75b70c47b8138fcd0c133f0271f483921d36f35401ae2d0f36471a2fa00c3133c04abca78640cd0a41ff59300518ee8ee1668947811c71d9ae3ab9cc862f3ceade21b5c06ae9f0bd557011ecf98bb3f25dbd29b06ed356d6193201fc1dde29f3f4bf4b24f2ef37bd123d776eb96a8262f62ad536792d85668676936889f8ae22935160716b03d7789175a80da5927c2dfb32a5626a636a06b284ff241d647fa17ef1bfefb23a8b9018aea0b5f1ab5922d931d32b36bba43ff0c3f789f52d4eb732aa289a46ab0f6fb9f7d8bbac4318398beacb3015731a2b15840110342656f286ee8990f8bf277e98b8c2b3073765c4b4f91fd8387cf180eaa4b862e1ae5e0c4b0ceeae48cf3786291fe883e2ec5da4bc1b2b57111aa949622bdbe38111fd101979dc3cc4465bfdd15b6e3631f45c1602e8d5464e554be5a20955955896ca7489ba4a7fb62b1ca2abf1b0183edd13261e5d34734c53f2cfa97bad47bd5f69641107e245eb73b6b3c7338d4d7a003ee8087e3af2cf53e4214302e090f4839f1d4814f62e69688f5d0e5d49677f5eee5f50a025edd6a399c680ebf1bb29b6412879568a2aec8b0e855719c9472512e9878017b482afe504ff56f12f827873f156885dd8f116958f2e98f2fff65fe321566e1204561490c37c9bde8b8943ae407a0f1f1f8f3b01ddfb4613430674a8e6473ad2af5480c668d9c8fbab85f9589e05d863bc4fb6208eb7d42a4e8331db9828e3783d9aef8df7c3572c8100d21de9c6495191cb4f511556bf02b23b471abdd139ad460e4d870b8f74f7f81da085c624ad83fa4759a1c12eb45d1041a002289bf0899f02beca717e15f383bb70653259b3eb479c662096c906474a4b86580a88ff6152978c4ac2e2c92a43d653627568bf8fdabfbc79c3cdb3b70b82d959e265f054991e1724e0b62184e6e2381a8fac9e36d8e69999310c00826b88fe8c8cebc547b72348dfdd1fa918de585fc900150176f087c2cdc72c2c629f1f5dfdf6e8836449c01472cc1367bb9bfe0bd210e95ad7d7cfc54ae9c6ec07fd4ba10198db36d32292d0e6fc5e0ec74cca3195924bba21475909a80b98075cdf1d51c659ea0c2c8a5fd694a406435f076d603320cabaeb9b9b29a31fa1e63cb8aba92f15b0be37c18d496cd6468286b0424cc00feaf0941604344a28c4f6b1f34c63bc0904269a4d438abe8e9654c342259ff9b28d1c00a70cd3977e68d990c48a21de55dd3618291e06fff1531c801ab27c6be78e7831424653a00a46601e7a381fc41e07ad4cba2974799701793c17bc9a59cc1c9b21a558db8d7ed4049ce35859ce08935b99cc75dd995092f15867fea1ef2233da367455acd92d4172c773fbc825e448a3ccebbcf043bf3a0732a932f21d053bf9751500be30cc4fdfa4801283af7cf360911c0e6268fc1753204d8a90931161a458169be9f7f1fda3747db4f7f011c4ebc4f86e5afc6b203870299e7e2eb2eb76501c24cb2bba53b7fb8a6d511926200b7d527b7f59d759d74a7433133870a5eb41dc20236a371693623d9d3dda0e3884e1652d5bda5878374d0fe962bc7a550b14ddeaa2c514c6ab5b645708f600514a062eb5a5b42eba19ac47acb28c3f3c22123ca0f51c7c96282b87703ff33b616aa56d1c39e378f1dc114eb1dcdd2866070587f87c8f745cf8781cdff166e95e4a80abc278e703eea44bca9abf71dd0e6b2802ac857138804f5913b577b4f33bdd5c1f100654fa70a74fe84da204b2b08c34002ced12081579641619e6738ce38a35c3782ad96e7ca43025980e8e2101da7c7c1a0c6a61a20682976c43ca4774d85747c11ac2962d44afb631c49c026b510e1091e871dbaa4cebbcd08f5dc61c764e2f1d955116ef067ee9dd799f931192b3f2bb06578d0407b0e205917f31192f1071dd7325dd3d99b29ed0d0d337783c074c2e9c0cc0ad8bcc92c573c98f00f117e3c81f801b21f16543bf0e8dfec2c8e5b5562e1bb0297440ae605d28a93628e33b820edfe1dbf7dff30fcb5f1b240f956012a507b7e3f32a4a572d607e24fda47f5815d35939f185076078d7244a0b0ce7130fbb03642d734a9204e6d2fa050965ada70ebe75041809ff3c2fa56db750055e8808f1f2d6a69f047ef1cc5c6f09e5ba384c63dc506e4bbaa5c4da33a62c5331f0f08573d517554af7556642c829044779d9694c035ec9412a31cf38c5ea5d7d14c471c088755363ad5350ee1dc9b645577dc727ce60a470175841bdbae6467cef565c9dc1eda0cf37b2f332672807ba1b40bffb32c3be3821ec2b298617854a2131dcb0723d4c237120a6a235e6e5ab49cbc8cd825d5f42a35927d3b1af381972e205f2f02e830cfeeebe9c2d3c6abbb37488dc22ada7ddcef8de1c644de5d901af1e640636c8643ef821f042a0a95f501d39dd1324e3cd864ab32d1c003f409118ebe6fc654d84ce6d3b3a000ca83d55ae361c3743e22a0be7bd9f5e5ca79567bd34f34b4fd5ccc773aec46bd0fda38bef6f09a70bf09edf982d2e5b3e2ee7731a2590942f912ad39cefb5091cc3c63cd42e2f60b45401dcb4f3cdbec759e56fbba4a1884e65b14fc044eeb114b9981638ac67f5ec6acd78d69c3f61ee77b1d9f0909dd6ec17763a731a7e227eece73e80c2367808a0bde9c7965ec18ea300af9f54bbe6b194f4173577b794c9438b5d2ab0149f84439fea0f2c0cec81eb8f2995f36c7e1e37ec80999a519c3262751771d08900d221bed7926aafc2c2fb1ffe81bd1a38206e99227d7f44b2efe126053f8ac05a50209313f9b847c67782d1575747a56628a36476e8d0020aa074c0de747a81da28781f571e7abef1ff1fc2dc767b068ae46900ab74d138957f6cabc30687c055713a6df3db3c75f3709bd5e42b0a24db7ef20a90dca02ed740e4f0fcb4a75a13b9ceeb0336d2258358f1cf1f9998d35ad4efb68b067d9788cac2d51eb9bd29b041d4025375817a8daebb40ec1236bb2f60395f64db4535f3243a40375926f95f8e2e8cdba096e65aea43c02aa11652b39ec29d9ea16f052dc6076a7418fb19b06860b39cf0c94002528cfdd89939e029a3a70a510b1ace2713c79f79476e786246413661eef61ce9d0da70ce76f655b8584a7616e6650eb0796ca6e88b648b3961cbd0758fb73ebaf45d2e669b8e9e45daadafa4aab920251fc4f407c404cde19297d721c968a220a8cf54f8e137a84ed2afb70a5e2bfa117a99a101374991780dfd6007a9b1d34b4ec173a41492a6d4038530b9a1b3065b286cb97d2d9305c18ee5a1524a41a69e7dbbf4526a547d2e3452caaecd35afc473f2c4215548cf709981696e3e740c9577a317b568ac593cb1b5a109dbb6dcadb3971f7a8a2eba3e5e6bd3f9d87d358db418f8eaba1abaadc28522905bf995f7e5f33406e149724857f81b9fec946a20f20b9971ffc1ed22eae6eaa673f3d92f4dd7c781a279d7f113a28f9c1a4aef4248cfd04d54ee64de75d1092d738b0b983e23c1163159ad7d643d0b55f1702810fb0af739128d0ce4555d16a3fc7dc0abc2636f0414024c5e5295a4868392b9ce4c679e72c2a376c07ddd98ffe05d3f51b6acc0e82f45d0b019f03ac9ec2786ae57ca05893ecf505eb6fbab92c043bf291342ee0244f0eacacd2edf7a6a3cc94c436b541e9c135ba128e3355239838d77355ff81a6aae3aa080903b0634c71b65cf518fae96e36a916b5b09cdb49a1edbc6e5d47832e14d49132a7ad5c8203991b0fc5c31cea755d4c37c5472a1306d29c13b52401dc5fa5550cc216e43e657b2e4a5099f654972fda2b8f16fd9ed813910e36ac23847abdf38cd226d64f2e7be89e156ca612b01d35f79f2fdcfa70e4604c4d230809dda5cabbe4b258f8891d04e76443f5e00d4d7e5238ff20c60f6a2caab45058cea12ab9af77d1c3c264db7b2dbe6658da2db043f8ed769be9cb449482c5f48c2a385a33c2f872d8d8c2d42cb693aa599b83dae22cf1493c1cdbc3e544959c612ac3cc8e2078c9ab839c724a9944a4030483ca2aec6a48b6067c9ca7925a9e01a12fd74edff93b0c442cabc3714205cc7147d0f9784a523a5e7499636e884507b22416f4aa91ac1bdf4cc61ffcb54710a83e3598f0cec0a5e83e584e38a440e9a53ef86f54bbeb15ff9c52d2026af2ae5173bc722493f4ad44aafc793e44e0bded8270413eab1012c18c25465b446ad6ad4d81fd2ab05c49102927ee6be081a2a3ee5b02a3a0b4318425c82122152b0874fd797dbb99c8e5edf504eb648f97bd1ba9dde1c4c27adf4a2c504073b2809aaf505237c020f5291448679f05b21cf3bd53637551e795373755b334e5f95f92cd469f2cb931477140b4df5bad4b0c65bcbdd32a50052437f10af692afb79df0d61b02894eae1c65b1b539e4b5fe1ddd6d8dd003f41ca45ebeba6311ab67dd0bc0de6002e3f224e6e785676ce9047a1b53adce5e8bad7801e8385629754ea80c810dda36fb46682db0705ad583c040d548416bde018d4b9f5c3700fe82beaa3289f8f7d35a090c4536e2c7ff3f55c5ee83ceb63467cec6cbfebf491619352cb53072c013826cb72e9ff71611c02504e3577382de4064688120489924fd3ca91e4262ef1f46f557bc11f422839db34cd66d39370788a3da6e090126bb9388d833982ab7467a1bfe6cf63c4c345df81da930e3bb725d4e7ab669815a6cd4682ecc5fc35ce86de274d7a224ea9a0554d383c11314f95b094cf965fde1e2dcb8c08a41ebca647904ed03063fd54b86e026097d7ed1f26491a3b88bfd0e4f81a932783138e614878a7ab0ec28a13a678a1fd050cb24e5eb17a0e23bf61f9a38462a9b0ee1ae78a8013df881ce8e1463e9868aa82571e204d473531ff447fddc5837acb31090cbd273f8e2f0479677737583b7dc2c844bab10f24c198c8d12fd05dcbc3d3c9b7aa5d51f82e228764b9e9ff5224bcbf86d46e867d5dae7415f65b4f3102c1fb41eb51bed0bb700fa14c52f7139ca1fe842b249ecc50ba24e8eb2b97ace1f2749ae23c08b4a3e7e8d1454b9365ae0dcedfa7e9d054345f90de8ae9875bb2ba83b603eca36fb3e33b807f889b9e667ef2603c4213d05d27da64f19cc71d654b00deb8a7749e2b94816ecaebb1c12717b81118ec127cb3fcbbc8ba0a55c932ac842a37eb640fdf7b95ad93f88858dba2c7cedb2ff64bbe3293dffad5e0039d7ded2fa9371badda0b4d31cb21ae7f7f3c101165af430f1dfa8e03b585a1c36eb846ca56e2043406d69bde3779e0bc01837c8e69d97d144b17d798f19e096855c86dd7cc6ad4916f3e20cb0c81b384b3b89a6b30691f6d74db2757259cabf425c5bb1c71a0c2412fc6e76b467b8c3835e379db036d58d6169372d79f8631e55b6befeb0717a1824e56f023c3945f7d183ba9d8d139388ff53713f225015508cd8387e5f21f3bf67e10cd219b54228e2ce351c68dad3233407a2cb9faae9ecd91b015164203717dd69591838c9a2e69a270a0a18b6b00d1cae8ff3706676fddd3c5407e25030e4ea8e6086632ae4747e795bc5193f85a0d83f65a74c505e9c2489d660bc2977e54aff92b61a85fef551c9c8c9920d51de3aca3b43c6dec0ecfa04cdf9e636a83f293b39bb34425ece0d7fc1baa0b8c5cf2701c2a450238eee46fb57f9bbed86678846114fec6bbbc2bc6331c88f36c8ff2e9068c0bce686c5890d45e97a72682b4b15fc8638d28e48cbacfb628fb5a208719ce0dc16403c21c9d84273fe528ed37ebba4d70be405ade5d8b74dd9dacf89eaab2712fa427e99d89bab6878ed2a11a7fd62498b6955673ae123781a5c494bb4bc66048f813801cce3f8a094d62a54f8787df0fd9d4f551c1f3bcec39e6a218fbf834ae12931ecf0f0fd0d7b43df7f35cfead8d2098da6cd2bc9931b6cbb1afb604862c2e9a4f27f518a712beb48e7a6f5c94dc6851c1c849f9e679a201065f3d949414e45c7a1fcba48de6ebcbfaf4a256124d916b5602f8687c9bc5365171045bbf7646cd24771612e096114dc97f4a5ad53f2d6a81bc3d673e8c94ceca32efcaaeac47919cb0297093f056c9a6be4ffbb3a0d3fd421c73c73b79a4ebe5ea831d07f4acc32ba37cad0ce15eacfbc24ab77e8d5a9306ed472344997b9726c6978dc71738a2d4642dee1bfd30a14b4b77bb0d1e46a7e7b9b0cf1a09238f63a46997ba0381765c8678c94ae71246317310bcee9ff8b659d3274733e7ff72fd55d1e5697b5a155e46ddd677d422efed8be27d8b5268188cfcf61519ded6c2f2089edecc4168020acc36abc6a223b933b7602beaff18d579525bd625f74f977034afa01722e7dea30f626f55c9254e661f02afe6693e2585a4e0b6fe50764aa2ee2b8334dd722e8fdb45a15098885814a0d33e94cad873126cb20abb7c6ab0cea9ec631731bdb92c8f70b7fd3d84769433e5b6edeae50295cf7cfbc59671978bfd1f47f8801df3afc7628cd646c68cfe17909a7f01f6f5d1be88924ce9fc87e144005f12637e02dbdb96ff2866ff2a09959155ada59332cce33261ca4527d651c19cb174a544367cdde5382ee37cbbecbfd12442db376ef1d937dd0a9cba6733608907b9f48695699c98edf9de05cd4d21fcd9c4a0d963ffbe1acfdb2b70816eee3987aaef11a0127cf9675b2fb44c6baf54e27f7b648452d1700cdff1f5f764d1183e3ecfef27bdfefa68b4856ea0c9637cbd703b2b732a276b674f1e131917130737e183d6ead581d68c626e1c61fed6ebb448651d46863fe85fe440468cf7e92a5e1f45773d0e3373505b85d9a6115b2d0e2d3e304cc48cf9d38ff46b0678cafdc0845ba2af93266346677ae36e7180c8c849d626d810793c925a3f59b82b8df70cf6b69dc2e4d29c6984d3e7ef7553c8e3adcb5b1bf9055fb3b3e2b526dd6f6c36c449c025cef67dca5875e4d7f8d8fa06af5088da132dd9208776abade3b41b3449387e29f31ad84cb04493e6ade7bf109eac0c63954c6a1a64a4306c5e59b8fa77ce3f1bca81252b05c7c27161763d4c913a09d5c365355f0e6eb05d5654703918c834cb50793be51e5b1a82b87254b9de239cf8b9158d8fab6c03e4460f0cacdb9087a55047ac170a672cbd3df595bb83bd4e4b27cf03865fce9d9a278b90d1b6c98e6094d1d51d9c816ff258ad3901e0bec42af68992c61add04886a7bbf951b5c1b43d2a5557bc56fec993966c969bbd632fb67515ac66c2846b0f5551105b0f3c9adc7e792321565ddd0e371caa195104acc30dd1720b361def6df9dc0db36020acf65fb48531a05d37ce7ffbe72388b7b85d04ed7bddffefb158d8afe05bad12fae9110c78c145267f226fdd292338405a68fe04fcb880d749d346baf57f65fc348590c8f2e6f618a02811e2285f5c03dc22c9e431208e6c54e9aca38b7c25655901d085afe00187a05da27a4bf46c6fdc573f6777acb3ca6881c1f7b837a9a3a45c70a332992c74f739dda7fb86c8c68427a918f73bc2ae7a050b8d5f507a58256138a71d4849b63909a38368567af0736dc5372350f16cabcb005b90c244f7e48c3cc6807537eee6f6019a487eed75d60835840bbb1e6fb25b7fb3ceabce7fe8f499bb8d34b18a031b71879bdfaef8f351b2e394eb464242408ff2fdd2f01010c2125d7049630f886292aa04b1ac1d62f4926df1361f05294b5b5cde3ffb13b35fdec502f134fb4726fa6e5c45ee7039c3b328887f324da5976f97076e15c384d3d1c6596fab9ed28d935aea7a74d79cb5c383b59632418665d17263481cfe597292a7ff9f8beb5eb229e6085a6803bf7a3037d4fdd66718bf53bbdab0dae5f393580fa6025ff27ec32af1c351b41878f430689902e7f537a0166ec106332e28b4cae50748099584d000d116ce812da2a043da386ad2e999a079090f64d48bea1ae4017a0ea4f3d359a773190276495b5001df46f8ad31f7a713bfc277bc032d45c7be8dc5fc71b9381d472fa38a51254ac703964af2caa39306c721b7d55906d88fb292fc47e9d6f13dd8d91f48371a6346dbfb162ca8f9cdce205a8ef4581a834b15da4d26f9a3bf9303c09f1059c5f7240cc84a9d4bef3808a504eee19ffbcbb4369234f2adcebc155922b1e9aec14ceebf0a9a308a0aba28bfe6deed8adef30d729756ec2009dc67b0ba5fafd60792dcae44136847e05fca7ececd3ddfd98f1e5c63338562bf052006bc361fed0a1154fd4bd14c8b43f61a10c5ce8f3c3e6b001ff89049bdf113fb602ad40460e109d5b7494d7b106bdd869bb175ad7ef950183fd3be944ae9eb58a9046b305346fc9fda39f3a4a9741d64b4749e1747daf0247923d40cbb469dc2325719b53f45a66994f604fc948d1c34bccd6432688d645beb1291cda250255f40383a3978934d91546bf354c24a03a69d8dd6af17512cfd1eb7815176987518c69170b364c32d855a079332cdad2cf5be90df6ce6fe9d10414350d4503df21fea5e4a06e17174d899b42f2aa45acb1b3f213f82c3434e9abb5e2af89740b743da7a0f28a2fec7e1d0f8c1b1b7b8a2f55c052fe1565331e5e7d37751386101ab835efd85fae39336bfd71dfef7972f85cf8965eb706c3d0cb05205e98bd2af1340958263b1731872efc5373feb58ebc2505e9e24f97c9b3cfaf65bc973b383fd79875a702f80852779f222a405bea5ed066a937fbc62b41be089745faf91ff758e08c7bc1ac83c0535ab637c1aa1f3abfcd2c0d7aae46ecddc3b06f6949a153f4389748ca019444c45d008de992dd7b7a7c6aae40e4762fb199942d805f4987d8ca5ce964075946fa62c662ff625d738c36aaba7d64c05248c57c6f12357898dd9b35eae7e00e72501d39a1d14a31e7829dfbab06ab87fbe636125b7e5128f92a0b56d547646ba7a69fe56034dc5753c10b4ddfd0f108082fe7de4257940614b0714cae246966aab17abff36a9b52bfe1a426648c728029f512614194cc2f747bfb88bfd69410800465e0ffc4b97b6c15abe9588b8ac352b1af38b51c98dfd1a1fa4bfe7a52a3a551a1f1e591541e8f20ea386f9f3991fc252ab2e54b51df441e413bb996c92378f20b2a19e3b09c17a02aca3e66f31c41215000b4ad6a1c44ba559d10afb032bcff4a15f9978a6f13b10b25fe0269f47567c4cbdcb229cba972a6b2ad8989796244c0223ae819972c5fc73081e89b57a1ad3fb78f25693301d7c33358bc40b055483e5fcc559aa2cbd580c26739fd82b4a9aca4d4040222a07ecaae4f860015c25b93c9a613516d20d2a60c3d35d219c40c14cde93579e8df9decc6bb4537196ad4c76510872c303b09e93ee1cbecf656823b4df37dbfffc5cd460ea6ff9724072d4c2cf96e490c0f10e942658c55aa62141b30cc20186afab5eb36327b0dc475fc393d030cb419f0a792ddd7d146355de241b8841df70fab84f7292bfa7a1c873b2f51b84f892f97ba00feb82d00c729cbc2b76b79f64b9a903566f96809f9858083cfe81aa32ecb9462824b148b3f5c70eff5a69f3ef5c173c749f502e29a863228a03ad49afa84a7bad6b818d740f2160be5bb8f59230216358d5d515be2f80baa9c19846a359cf14aa65c5d326ada9d114df5adbd67a24bd25d42ddb8e6b21c820786b6a3e836c8e11880096c88a76e6b3465b2d61fb111456da58dcbccf7b19b300c88db34699a9ca265599305c22a780e0e1bed18fec6aa777cbd0e9969533401615f79cacfe402f11629b8122175a8367c1d105de7f6a1cb88225f778cb322e41f990c6409fe24b6ef4b37780c99d8068089bb3a4b778ec63c80f6f8d03343ef3770f288c724cbb375f126c932c4d58bee0dd606045c9a5b27ff0d5597b25f5ec5c232a6a3d697601ce0e6d49be3af9d557b0be1597fcb7a681dd73bafa132de4a34ca6486127234bd0ab6c050df98cf6b0f111f7500652ca14cab4a41fa2d18f1c664626ba70f874a8365ea64d1e1e8a257a1d313a6b652cf6db617dcd22d74378159ef1ce25258c76e1e676aad0722a01e30db706e67788d558e44bd0fb600b177d88096f96dacfd78b58a1537209074a42c22425e297d11704380c9d18a3bd86ce35504f5127815feabcdef91c7a5b0091ee7c195e0268af5ef300a5c9fe1406579ecdcb0915397d14f82ed2bc55f8de4e5abcecdfbc41f9e80a83a072d01418a2a544f718ec3d4f6332d1bb2aebb00c6ca66b9999e6bd2bc490523859f0db1dea63779b9f1f84d52cbf3e7dcede8214080c6b54916f512426bc9447266897ad4078118867e0d6746cd99378ff539066b246ecd123bcb3597c4acc172ea13c1e260468fe12b1696ba737e1984e9b593f774c3db1696be6964319b9f9388707bae3ee0858528e3658741dc271e80974045f3ccdcf5c271fa4458e81023f42761c5eb37375dea4e4d4d8b1de0b4724631cb35b0043e7ac67c4edf767115670eaf50370af4cd2637de6c760e5750b8bda3c5351c16a9a5ebc02e2ea24cd10e9fe31deaf0e250d869f933642bcb9da2dd7ae6d92e3c3242c2ca4908bb60f19d68897616973b67dd1f1b037c460f7181782191858f2003a4146daa41901058972d7baf5088dd5f89f294ddf5d0b6af191f36df14250213469c2735942e825ae6d36406817d2ec872e739cc1cb9f0bee817e95e37bb38c24b9bab958654afa1a38dc4c3155c37d1310f014a5860de0637d0a48d23331bf8afc9f5cef164c130ca4a472b360b92d4552f083d6ffc381f8b033bcc0550c42ea706ca15026f0d4171c06e6e3ed636e2d7cfa92856ef967342076d612e419457b0667c8087f01ebfea10184cb54e7c6df803d8878fc04ec7e45e1705072d1a554a5ead50980fc7dc0443a2f51f64bb73fa10f183be1e8c4368441ddb9cc5c47845c02ab67194a7f27a109036ef7c44c33ea236f799350705cf63fa5a8ed6d8075b8d483c41a589c4ef7efb716cf495f839a1f22ae433f35d4c5abbe7bbcec3a78ad021babf3e0b9ff84130557125622e93b0795670617a426fa536430d1dc22c79ef99b0474f5fc4a7812efe5c9e2e9f1a23edfed2340ce460b118525836600127c410d977d7f2e9a89a6b571289479ee50ec969a026d8054077f783ac7038fc45f1d7972c01d4ff6811fb44dbad8a5de90b39b8a8c055e25ba81b4839725ae5f33875d468fa381a5866ebfa41f21cf2bcd32c0a3e171ca4cd5ee36fda6a7de9f0c630430e796fcae444eddb481d8c61f7c1c1a6b6b6df269eb1c69ddb5d6e2c4bde345e22546ca393c69f48b4d52019f1cd025393fb97d193b53654aa6bf784c660040145a5d5da90092751a9294b526d087323a04313b76cbe6447ab73707f48abe7628a2d8e2b0a5de8dc8e7d4baf10cf6fb714170a8d0e808f9b00d1e3796967ea69bbf899bb84605751b423872250ad5e61d0162613a0876f1c0aa27c7c9dc629bc9ef8fdbcd6abcd26fcdf55e0bb080028cb3de1e3785a3320ee1652bc1a553fde8f73da96ace4c55e5d140bc4211918ed8694dcc5d974ff47276c8c157260e9099cb8042fc9f9a258a6a107023ad1f91a1cef61a74521564bee71c2c055606b183fb3e5f02c21d21f45d8c3dceb63edb8779d4e54668ea48b3d283b141db2e76e2cd4f4f609d47125519bb969771a27a129d82b326cce960126a21be34bcc01bbbda81dbdfc70e2cf40f79d3c7da6f29603a5e52e7f968c8bfc4709adfad10b5d2901740c54625168f306997e9ff6a4dd6b642635308a33e7fa964a666fbf436c2dacc0444c8256f8ddc5cb975510e16e093089030fea08c28cf13a58a35e43883a9feaa5b6552041142f20a916a2b4bb0c0892a4ccf1a8707b3bd537b359cd86f831c655102f69601746ba8a29cd9a089cc3796df03360f77c6727dfe70cf7bd1ee97bd070a1b8ff7798ba8dc2e1ca6f09c1ac987da350d1929136cd346b5347b4aa00aa08b1707ffd7ed550b167233ae883db4791025d4d3f0893cae53d0ee29569290f29b0f73b691f05895c9a2c40357ea89b2fdebe78c41e14f014919d17cbe67b0fe6fa854d65c7a2fa0804dd88d8638caa595e49d2bcb1eb6bb45aa447c4f6ff29d308b7785fa01213a796bf7f61237c38b7d6fa76cb760315659cb37e2c88a9cfa7d48353a5e160709aa599f17ab5076cf9010a1aff139e7d908e73c96c1eeda61568730981f77f749455f6d4efa787d9fd40630cae5ce4d302f7cb502afb8a092b1a0447db8c42d95be45ad25ca5db36cd0f24768173e21b968e7f38503c70bfe56101b8152b3e1a32d922a58fe48f8fa01802d578ffce70178b29fcd877d58d2062a166933fc33d52c611c44d98beefc7a2ddfab7b17a455cabf8acab61554a4c1e649c4d228fea931d30314849cb63eea6684d5410dc66d24fa96739949aa615777b13a0849df0f9b95023bfb065c29379f515d4eb24965f0da79ebfa7af2b3852ee22611953769bc08b0df17def102abf69d9e9d2ab0854760e6ee324c6d35d804f0069d65636227f3004c20e2b74a1666b877e0701f933590c14a0693251fb7588d16d011de7e13d98b07a9935ef81774938d1f8dfb137ef0804e32d54efb3566ef86664a6b8d78d19ff938ca4e067e6c9bd56a635ba2884c97a074fd7e5d32a98c6ac2563323e1d7b40da5cc1f7a66385ef4badc4fb28ea729d6a406b13db81f59251659084f059081828fbc0a287f21a7481d8dbacdb4cd8714741779ce7f0b10d23bffed168fe6f15298797240be1ab25efd139f8f6663e275121659798aa25963f01fb9366b0eea86b68b02f48c74ddfd8f7d326a5bcdd419a78d76dc27507ab0aa42971abb2fb8f1b624d62e13980139cfdec46acd5a48fcfc5b86a5e940a9849b14c16368fbd87c5fb40b8f410d515fd63ddfc55c529e5871a4988f6b1478222f54769ccbe8ee2f3b735fa774ab209ee535a968e7f5c73ae0b5de7c384522f475b368931a1de116ed780a373343da60ddf436d33d075b54dc44383d1b526a931061cebb55f946b2bcde161065cb864915963c35219870dc42e260ab6bb141437565ef9fc46b8e662228db93f8063dea3693be95fa1569f3b3c91b8b67f0b77d4a7523cf67d842d97ff491ac1842f40f10eacde168aec22d2d14732daa332ab4a4c30248538e83dd7afd1ee5d712876feaf7825829e2e7eedfa51679ab1d7c340f9d40420378b49fc3fc42f72a9a0ef50bf647469bdcf7149a89c14818c0ea9b5fee05682c065ca8a9032bb556e10a0a2e7d508f1d60276b6a8186759960374cfed62f261cbbe8b3e77cb01b01c412d961c16cbbff5ec6c655a18f3d99b0b8ba2b4aa9480d626d4534cf488116b5b194add0074a593366f9f4c8ab554393017f7dbcff227adc4f71578342e2d84814a1c949f6d51703ab19ba4460a1548b29a5b52b5214a1bed29e9cc43e8b0590aa3070424a755fbeff2c6ce21c722042d196d7192681845c6f898923b56e5f3a7370eaa6dde6d978e89f788d512a80fc498c33ff338ec7f0c3c600de2bb10c1afe00f096a9ae8df2b5e49cab7828c8b23e925e8b46f8ae63e024d51c5cce6b972e070373aad3419669fce258a3be7b3bbeee648a0c7caae41e311bdc63f25a49691a192ed222014d0071e3d7c64e3592feb0806efb75f5e4af2e6fed4d7d0bd43c4a7c60c815cd80ea50fcf42c7e4f1db51cf0abc3e13f4bf91a41a4fc3dc846fd52471628de83030a44e40e76462c6e3bc2cc3561cfc80134e7d03d955e9d64080cb8010b54d350db79d3f32b95068a570ea03232c72c60631d150f317724b11b487dc910d98e2cb9460ddd235a8dc716278e888689c0d5f78ab3b58c904794b17c4bb64d3d6f28dac34b8a9ee8a1dc6f6bfd1c2e413e4b24ccd3543f6eb8e1b962cf0657bead354f86f08fb83acf0f2d15cdb76cebfbe9efddee249045cc81f0360110d2c9c77265cacf1808e1c01c426620d8e9353ff01078bb31d4e49983b38764b57ede033442be57fe2e7eddbafccba9c67435feef3aa6476bb9f59c22a7186659791f24ea5aa27ff0350e301a756fec499d85eb9faf9d230b40f3982dce8192896f6fae40e80b9e7ea12c5f4d0a31070bfca4ab36898d33f2d5f351ce8cf7e17db47b09b29b6646db4334883c7dead3bc7d0ee01dcae538c3d49b1714f3c113d06102aef49d645173306c4f207ec6eac2475bc8fa26926eaab8daa466e6c34ab10668fa741b86b382e92b2214397f748cd625ba2b58e697d0180c69fda71d034cc0670d4abb988426bd872fd41b642ecbfb6be68dfa4f340707a6b6409871faa6e3067219f101d3cb77ddfff917e482730104661cceb733c1c8990e16b5508a890bb1f9e8d2487295eee1701bcac5abc493de597d5d9cba5cd5af580949919869f4f652c32fabbfa516fd7e11158d2757bcdf0f755df173d3f8a550f91664ee1fbfd1fe2e59ae2715ff9aeea4f6e5041aa73aea79be007519d9e80f3fc68f329869d7f478fe0119f2111f54df2cf7b560fb1b47165ffc114f5cbe2c2859c07c3564d638cf9c85c5b84afdc9e5adc2978b62752b13878a63ee99c68d6b79db08bcbe71bd7d43beac5e3096a2c6a472c0df4bce2087fe04ae6fc39eff4ea505292100fa2e449a20358a447dac2e932e04d7d18ffdbd3f64116e120f3aae0392e635702f6ab8282c7bedeee6904bc2880bd57531f848c8fa136e125585af4a7a7f206ae99a126a67330b01e99d67b16e0f0f06f556418d3eaebac9ecaf854ac4e450620e22a388b25ae4efdcae411eda11fb962a74e49e12de23e88b8e6e8c72121502ca28ab80ec0a5022692b0cc5062a8d2bf2cfc2be101cb922d31a3bb9f5171d85a0a03cc4c51d0a2ce10fea4c1355bb710ada6ec0f11b69a74187f2b1c63f9ba776ee670eedb92f052f1e90992332cd3d3da29b248ecc997d73887e3ff12e12feb5b1939f61c73c0709582ba97883728722837edd1db6f102788d29df604047d15a1852a5dd7fc7c74f30d392c0a8534255713cca7653257ce25fdeced943975bb6ba8593235be0f4f199d174f7843c720ccc6baf0215e17be990c8d2c9236224392020c2760c7d5610f539f02f2d083e892d69f78c18e755a0f356d6c90a8306674d83c32907c66a654183ed03d261ae20ddc26354f38aa3bdf0760380fc09bd7f12b225901dcc213c71318e05bbebd80f524cf5061ec623cf5bc895b4a6077976a7ddfb9c0cd3fa783259354b6a2d9f284552ed221b78d0b55e8eae65c02003e58fb60c50bff4d44d5bbf786a3f5cbd49c3cc914fc3c602d082d7557c3f7ab7ace38536e001bcf52eb0ef80154322b310e2ea795fe7333d0ba333dc1a7a853d0b9825e34ff5cc055917311b257cf36bf141a2decab2f2adcb50466bd0432e09ff47d854ff60e1443cc6d6dacc027bc112c705ab3b6d6c3de3ef5ce27d4d129fdb066237160be102dc61a8690c459a52b319c974404180caf42f8620ff20f9681d46a8953f4291f3de9ff279d00cb82789f9f3390a83d0f9d38050aec674c5c92bff62cf37d43b50905fbfac7db15ec9b8771850627e1f9e770c312d2138fe017e607b8c1642c6193e31f193b69ffac55c595da60862d4d14c2cfe9a6558b3398ed59bc10b4a1822dd6fb02884f6d44ccefd2acae2137921c5c0e61af9b6845095b45d27820b326e1306ee3ae43d05624e3e2bb39362187700f383b59c51594cb7ae9af7a6e004d2ae29e9ed089968a55efcaa2f352623448f5c54666a6b57111956291dcd7f5a4d181bca27e3145020dc777335c523570d541bc674e94c4934374829c23a70308b1932cfc1e5aacd9156d5f73da866de9ec2d3451247e2f3f3002408fb776a822a58c313e8616d49869e70d2e7926ab78c4f2c95e286db19b74770a15064005f43ccac5d10198033f1a16ef1b73e2fd166acebec28a489847a9ec8537747b5c83997872a38527282e648560e37180d3acab42a72ecac8dc39a281f1c19b64c8c71eb8535c29c8f8b60a4aaad677de1e20a0f21a524e0bb3e1e91926c4021f3070eb5de9d98a8df57c41452f66e5ce73d7900307c01ee5e45201abbbf8f49bfeafe78720bb61856e7752389ff5d32b760488343be6f700a1c9e55fd535ec4584387630c08a2a48f89f1e7efab7c9de516fa1771def7e4dbac84f8db1de0015aafbd1f2d74e64e65fe58fc43a36150672689ebdef7b06b565ce79bc4ec2335c89b84780985086a74e81da4c032429d717e5c979d276fea444f6ba91edc42f5caa9dcef02bbd32e44565a745ecc2d53207621ce08ee5421e74da75fed5eb0c36720ac7bf257418746f2b2c0c9be338ceca525bd2d9df8086e4dd1b39c9ca6771ae45bc522b980eff22650f48f22a5c66df99a70d00195f6aa67023b00fa611d4d09cabe9af0010edd6aab27dc4e4815cdd63292e5edb1a572dbf1c307cc0127d6ae1a2edfd548dfbcf3360079f6cb5de7778ead94d8ea779f40a51468df59c9f68f9b642929d27db1b62b28faa2f28889ef015c1b547c2a7fa8b98ceff4c4e721b8d7caac45aec0866c1e62eda03a822517e99d42a6a679d36aea470b4ae2a2f97fef10c28943ea9861b09ba728bb660b6bbe5b2f052c88b744bf24caaae05561feb1a5735f213b9bd71892f0188050dd475e72c9740ae547d17dba345b4fafa7aa952bd9e0639a2d3566ee4e9ad19515d523d2e4f36d26ff1e7ef1b609eb3b126823314ba667be6d09e7c435b4d6e68e5a8f1345e55f2a71d50b8b8b105b87c9be2458431d77b36ccd6f89235c8512dbb2d57f8c59f560879332543b473d0d19165422d731c2350156be4658e3d17ab99a5e2816e0bfeb8868a7cb38627522e5d2d86b7307a41f3ad81341c03ca0d7e571b4dbebf47d47a90638207314b6b00686d4427b56330750f0121d400e9d590df382d206d0d812187260693fd726374ab708767b3ff731a9774e56647d00e850b4e31e47f422588d47691d26fae2c91a9cec647376c3061b1a41f12ad3ea960b18424e474d5462a6b43b3b083d7b8eb3cd3e3fb8ad176138ee32c53af44e90cf24ac6d1b3f3a0fc446c2b2d7211c2136b646c59ef7a8ac5a4faf92f201651879cab5905e6c5ad9b39ee8b357259ac5051ca342f48cb3b5f641e6cd4b740095645d8343e36752b1b57a0f6e303a6a7cf32fc24a3870bc0e3897e96712d82a1225701f8be67aac7299b091e2048947f23a93c985b761fb16454f89dd5cc893f1fa3aa7bd95015c9da68d57bcc35ea31bf25d69551683c6931093b2aadd0f37ed9acf6a408ed91f11101f562a2e2c5f16fdecc66dda489676775b1a2d62b09fe66ff297ccccf99f5aaf8488601f66f11b9cfdd0d91241fed97d3c0088963cfbe070f039e5fcac771780e6b2b245be54f17cfe37e425c0de47acc34e25519300a8afff1f835d63680fd56064190b99b6b0c723e7411d0b183ec38d0aae036bab9785586d3d50a0d062a3038681769da5820da23528c36df7f3c9a828fb0adb085adbe1892570135b9fcb61d795502f612507a641afe9b2b2b93310408eab6a1a581f107de5cf9998413d3c68d6243afa58f2dff4bbb6a97c5c6cfb5f9dc23aa7393ff18ceadaf4bbc3deb8791ab6744ce12d16f90fff60c7d88ad8a30b82042edb1fb6c6411d873e295d3e86ff5ccb94ca3ae8bd5f6b6f6baef56ff9d9f00356a9eaabc41f2f05d94fb7ec0f69329e3ec74e0900a2d326d76e99ea7707e1ce2b7c9e6a3f47ee0d8ab2d7f8cc651eb5cbaa2c6b617062a51b3ac075fadbea8b53d0b781e9091901c608a42fa6a2fb46fa13663a7273defe1808c6027a20202a7fecf228e09b6dc2cc97221bfd0ac131d90c33861c5b993c7248555c7a15c9d90fe9a8c34923b3dedac4a88f8eb0b71d778f94b607d1ec95217f8bd5b03214536d4f7c402c079cf7f67027fa945b4782c2a06ec557cc466964d2bf2cf0ec14ebdfe615cfb1133491ccc415e202f1ab98e3c738ea119238f3ccc569ff46181e0b82c4db4e1d997566979b1005abebc940acb548ae12b96ad19af931e1cad7869c80dd8228e000126b3b93d629afb1aa9f487a25701d6ee99e4cf2f5b9f207f73e11763352830ec4e195996180fc56c5d84d0615352894cf5b67f2b1e91974da5e501a8b09f090edde5e77c5366c947b3a2746ce229b5754f6427e403fcb271e487fccf3d74e0fe67009ce4d32c4fc1808882f1d4b65436887c30ac2a06f8c8c8f48d1dc75e1446f6e02f13305f0ac1c859912dab3370f14e7959902351550bd14b3d5b1b012eaac45fb19825896a5adaac9d3374ff6a40290f56314ae3967fe76610cb84eacd3998c630db20e49958f0d8366044fc900284d5e8db58504fbd6975535a2ee1ead79b6cc88bc6831f661b1fee9d97dcd7f598338c12befa546a75c7bc86c784b367da4df13f70a59c5bf9933e95654b7701b41963d33993a9e0f46e7281411e4e7a3b97906fca7bb82652c94025930124c911c6dd1333e8f7340448aa6fbaa75ba9380a049b41bb86262d4921453133dcce9bd98da9878ff74c6a6ae2b40dd06c1d8a963ad52aef1b26f73e9c57fd52286f2bc6ce8df8781d3c4c68912a05deaf4ef510089374b5a3ea63672190ae97c9a0c79dbd339b36ca5abfece9fbcffc1a6564735f8e5b7ea9ee50b7aa3feee252816e206a7ce1ba545a90f74a20711c831a4554a7c53288733fecbbbf9f48d272d6b65926e6491c7204b34f76048735d6256dc1a9ed16a62193ef707a785456133801b11691fdd576103235c6ba2978ab05ae19878ccadc36f9574c97ce3a5bc3aab4ed3070dbb7ebfae002d7ea4c48794deab0502b6dbe03c1a49ee52728fd3ec92389993e7464e8d8040e60b211d75bcec5adb4a19ca20af1f2232c652fc25159e12e858f3d07f08910093953401a8f70c11236df7992bc2e113e51b20b22a2296639fa6133b6015f802d66852bb2b4b698f1e8a81a76e67687d0b8508a371a3cfb18254265d57413dd9aaae3742eaa265f3456bf9dbdfb08fdf6b477a6a10fdad90e7a3355697aec35bf22a8f84b655ed7fb307d0489142c045faaa914e81c608e59c6f88b82749d9567c46aca74b4e1978b741a44795d277cf7243127e1597f2e5a3ae676b42c162909e2acf12f010fb756d886355f41a24888a64d5dd10af3515f3001e6911908bc84e293c988afbdabb7d440a2ec3de96ec06b56b4b9701e95e5ca10b6589c2733c81269da2cfc17b3d47fa89dd30503200099ee675147c9e6f97da5e3a7856a4decc4b8c165c4ef804f41c533835ac27e46741496675a2431086b71971f0d40370dbbb119242adaf4e729ddf8d1e04b69a669486aff6a0ee039a66c9961c66e0d6d5f78f3a1fff5432c41265936aea1995776862f892861c937f5904d376a339dbf99a02cc9cff84c27f206c5afe488c953a574c797e99f22b5c917e5fd1a90f3c17a4868d0688696a13dc911ff02f1ad4b6203e9d92f77bbe78470dca7c72009d61b3df1e7871b60921a0d54a6ebcaa148260672a3aedff2f9764f8197d9a0b6c934cceb6820a41476eb1b6a9110af53bb182dbf95046145f6bdf102b1cfa86a5afa8b08e603fc927f0460fa9563545c88d7ca5916dfdb5c9b6c767d520679e66bf673ec64502185615b13d9a131fa4651e5c8b40eaa278c771c4fef3acc35ef76d167f79eb68279911984ac9da9e54eb431dd2340ca6c72e04c2da65412db02aaa3246250c507eb8ff42c1d25b629f9340317ce8b71eee0aa0c015b2b905cfa739bcb9db63c6779cbf2a576a132b4028bf070686f89adfaa5ca91fade9b6f6b4df65a63848c502d2d24b94201e4713ecd2aafce1b7eb28ae4f96ab46476eefc5392d6ba2fe7220eb3458363b121c138d122a188c3dc60454f7ef6fbe7479cf56d1a20347d7960a7330ee392fbb02e0d5b59f7881035d8439568b8f438c0d91f38b1467eb4194f28f7a1558882f831aa7bf0679b0059c10180c66abaff9d238887a05ff23493cb18235efb163adc0a06a2c8099bbda391161ad30f52ab2c7627ab44e1ec88fcbfa08277e4418a7a2286601e56877d6269595c4885c64ea809e9c121caa5532d4aaeadb9e9e6651be49f25470bb0dee83448cd59ad75f4cdcdf2d6c3346d6065ca27b286622eb28fee3ce4399894dfbd1846725fad67fa2b818870e0aad72f9499e1fc776431e6fa6a6858f5c6f1f0b56126e8f912a126053d445f27429a596842da82b1c3b8308ffab9ca5d5c88a2d39b0f44968b0ab67222c6b93f8cafda69183c62918e96bd5d949173c140d1f7d0d256ab50c9fcdc61c725a4a1e1f4639c8363ea53abc87a8b8696a1b8dfd51814f19a6bbc18f5c567ee8d89e0a85879c50fc1ac149cba1e9453d5d262d272c3a76a0e254872e1f54e8fa6da6c8d2220605305dc398214609f1e31edd55c8185c46fc00880f28beba2b50b042b26b20d8fd7f26fd662142b0440addcbd3a64e6ee99bb583676f96927d779481a0647ae6a8cc059d35daea794868326bdb485de1940b2a0c5b90489666a5ad85e2a4c336c730d0cc6280111fd237f90c67e4f6815889ffd803bd9cce441ac59e2aadd6e546f9ac17507798d056b2a421d381866b954c30d33a932a629b67e2745913efa188f9bbce163bb69ed44d12c9167c406883793d6e073e31f74637aa4a17c5c1e67bc663294b8f573ebade9b593b1f720c74cc001f07f29d1168caf61ed84f913f70cfa5c6ebbade99e2d4a5a9b2a872a1b1fc75c65337ddb01ea09c027bb0ab8c5bb00cfe363edbbcaaccd3b997cf926dd2ccdc64d98cdaa4389d8e3c46a789810929302c1e8d10c233932e1144928018bde47eaef06a82746533c7a4b9f1b8253c9bdc89e63f7feb3bc7ccc9aee795df2fafc139fc21ea9013ba3a3c248747fa68bb7210b8557073f3fd7cfbcb3a57eab551aead27af9f716c1d528efcf4723c5755ddd767ba5543f9a7b1c112d10174ee53670c3efa51b94b73a0922dd298c2ae4bc7585bafc8404413f0042165cdf82fc68e9466646ef85d2a9b52bf523fe8094b7dd275c84288aa10f6fe14c5dd5f3e8b2e30e2f182083b5a1f4b0072bb58e0004fb9868578a1e1fcb8be370bfec6c5b2d0318eef1e9bb50ab89fd834ab0e625af5527a5e6f82f8a3a405eff949692ed2338cb902ca715293b77dadec10b53bf024f432daa9e080dd7f2810c25b850e8c2e0b405d1375275fa5e832390fdc7373e6977f682b358897fdf88ccd4f323356b80cc556eba9346d54c0472b377c06d453348058467141f388a523f6ee723496005e37bbb98d321df49a1884bc3561c19198cc35f2ff429ea6efe3161f569f92e1da035ff641f28c04a0a8052136df82f8b0447529ae3e27f8a58912e545514146409666760f5425a3225a4c26c143794808a9cba3f10821c3a9a6a419e06c57f5a6dff47370620808ab3cfdb8f2aeaa4c2eeb90405d1ac832bcc1a55bbffa814c3471d27765a5ed6edb3566edd96e20e6f108402df41b49faf48b75484ce9d37936b2f26672e80731901740049f18de88bd5eb2f58dc4afdd7a8f9198992edbed64c2602373c57e2c06bfddc03177ac292e562cbab5e054acd21318a4a10a4805330476c9099e3d7660d79a3b2b8be3c14d05fe246eb1c9964761289d097f71472a6beaa0127023697956632f8ba77250559a15ce9e7f270e6eb1edb62586cfc31cd4fcbed345891201cb9f2834761f84bd88f6ab147e6b3f1ff90139f9c6c4fcca9dca67f6f4474b102eb1d4765f13ddda3746d54e44bdd32806a9a8a179baf0f8d75593777e79ad9eb9a370db4ce21cf5fc496d6e521ddd7f2e86d2fce6bcd92f1dd8028592154f1a8734fedac7795d4c039d5ebd66d4ac8475a137ed935f20c7fad6ec11db1f86058949a36165489f84d9cda1b1bc1d4e247187d32e953e61716bb585c1d0454f7b965292fae8b22536dd70cab60356d1dbd744f7011c840ea57f5b80a17340138bbef39b38a34631fcb4ae8d262656ab1557b3d74e09da980adc68b54c5eb56ba9716374b1522367425691f578ca5d4cfdf22220b7694610d9eff4fad493158fdef22d1c936252b49153004e8c5ae8b53fc55dfc7aee6769d559dc6d0a439d4d709b116e3abb4ead94bc8cda7b0bd12c0a96a151ff242377453f06983beb82d144028101cfc7cb7b12abe9a1ce9de7f714f1c7c24357c98d11145b5a768f01b6e6f2bfa3da6a825728ec4d1186fb56378be287c83bb728ac1f2e844241a0d5cc98b9aab6996b7ecc14b7b499624b294b767111b76681e3bd0002113c7e3206caed1bbaadf9f536c32c97ba20607bd2711ce7fad2a83149529b060620ac3c8be317fcc60c721d23665f16c9e7eb87b8e591da318ca5d60a8cd6c7acc1d3c2d7a06e4483f0186f62e2ba305649189c5e53605892ca44ea79e249bc821f3e82e1c1583e7aadb19f0c574c2e138adaa6efbd425980613fbab36ff49733b6179e15246bc89971830913c0c225e6fd33bab45f351768e60d9016b5dbe6c9f4cce77d160878dc2a27e19edca99840bc821a66df08234e37b482e1cae6644af512098d2495c11ecb228a57c43ec86768f732eaa843d810a0faa286e1fbe63bdc46bf9e852e349d15c0a170c8fffabd3dc7839f6a8190b7184ec66bf453b4eb894885d61e9e21438073e1729f784790935607c7cfded186c2a6b134916d591421f72aef18288cd68f97f0998c659a81d73526766309ac0300415da7b642dfe8ba7e3c9c37af67b4893f119f69985e1e16f4bfc24a1dbb04462575658584d7a752252839e0787f818f41901f5080e1d52f35e165003d5c0f8281cca9a45dc44769f5665d33df75ff7ed753aecec1308e456ddfee4dfb559bb6fb36cfa647b5777228cee24821962f8350ed090a538f12a50724188e273c645315f4da6267f040104edf9029bbb4da1884407f8437f5d1665d870885f1bfcc6b28d3f367465ef32dae8fdb43ffbdeaee77e4193482563fcd3d841e2003850e5a4adfab4a1dab93d42a9d707cc91f5b78382bd068555baee3664a461831989b94c420c1bfc0b53e8e4a1b26a67764ff9d721bd676265bfd2d76548d3ee2aff5fa8c6f28673111195dd8108568c5baeb5928123cc3c1b07c07cfdfb5d1b71a90bc96b083b75ada40678238949c508ba6ce3af28e601b3ff5c087f63876b575fd2eb7323053775f5487a6dabf336946eda37230d3afe6a75e16af37a9193bf5ed51d5efbe577c4527d4cf0d0b8fa8a5f15c3a0c86b2984c2fa556522afdc5cf3989be38b3f1489a775cc80126f4d1a8441834285954db30d2035e886940aa2254c6a7fa3587c874574b47e8979ae0986eb3088e01a1a670b2d7b5f7f042960fea80d5a4b7db00cdcb715765d11897aac6584687657e883a35e36f6bb2e461ef2ffbb4694e11a41c08e8059b623f10c48f63c62fb5a371680dbcbaefc2f43d32e52de3db301729a1b604cf905eaf28e369efd2b04c8a6bb11d60be37de8897e2fd350db4d073e1e0ecdc8d430eadbcce1c2f9483546647d3dbd75abeb905506182853505c63ed3e3fc8bb6c544a55ec2358f987e91434db7b3b17e514d2f48f7319c7ef30eff72cab9a0852645eadbe45f34bd141f5de7b6dd367854ba7fd6658e0ab2ee66dd20f2bbf921f3cc5a0563ec062df41b6c9a4aadd81c262a9683ed1f5beed2cb04acb8ed18581103daeee290630e04d67226f6ac86d5c680cd7cf4c79256d383aad62adb72a01eec6d9f098d5ce17185b645b64c52293358623fcb8c77479dceacd1f35821b2e43b825223eadade6c6fb97aa9226edb450e9c188133f2b5ab21b3600f488f34a18db510c4fb0c894345fc280833c53bb2bcc559bc70effc2b5eca18b6d2a609fba4f8f44f77c93b8ef7d642011a633d790ec454d67642a944ad1d2aa5e96bc51819452dbfd7177f3dd9e1579be6ac226caa88435614d0c29b519def4c5f36f85425bdaf8dbf6e858cd02aca16c6c9d82a0f18c5090080164047f2e975e9ffeac708d3a2b8be97695b2736897676ed49b9dfda9c890da00b0cb6da8a832264cdb48d8779e719246a6a830fd4033094135fd6b9e636240a4e0349526f4536b5bd4b736cdfcd46a88de2344fa8db7a39fceb5b724a9376f7e51aa417f1a10baf63cf530a4e759c4be80b251ee82cb392bbd7183039d952a0d4d1ed64f506d9efe23b37f970187481518b39553343e89b89c2f6dcce66804b8d45e1d55ec1dc36cc679e462ef0170344a83a53bc23044a873d608da8320ac65e235db368ec238efc73a0203508252577fec225b42f66ed7935d065051184cc0371494b774893d57f30bcfbd03c7ab000091123fb60fa23dc7977917000d8e9ddab549cbf957485e17c342807ad67edd3919d1d5c4c847c8eb7c6fb1b6b756bbcaac63bd1cdc9f8d96cc9f91fdca6af5f66e6ddb2355d6387d4229529bedffda6fe0a77c0907cdfcf445c8c720eff421ee021081d34d0b73b54b3d84781a1ada9dc628a4b59f6253f1a3cff7e82c31014abdfb9015711302df5363c688e3232679cfe23c0b273f68c0e161f6548b405e8177ccef5ee92b215d98cc128ec7997bc8f7197c143accb3c720c1f4ed2e331130e4a70df1d89d4ac6bfc50c642cc8cc1b05040cae31594015470b104163e85a9f519ec28427b47a3a8a0b92dac1276436acbb54bac573e9b83af6955baa5e254871e2e681ac5f42219834da9a5411d59f497c6df3a89b46399e8060121f44b73ac189060dcfdc7e66f426462aeb94eb0d7a16135d140ece4e04fab9f317cd83c2da92777bb26d75957c8d170caff2d1572dee417551be25c2b0446cb6bbccead36a25e3a2f523bc9b6fe3537b3fe0aa0918ff2e90d41ab5d8203c9701bc04cc8b426fbb2b25601df442b472e6b5d3c2dde368e1329c36b3915b82af2137dbe48a5ab8cf13af4b255dbd31ea11473575a63c08ff3d36ed69a0982b7e2faf71b27cc091d7944b25c30144c6f1e98e0ff646ca67f3c1eab89ff4d3cfbdcf15e475bdc50b64f802fd83ffc56f99177e399c256d93b6fe616073e922ccea2b52b84eb6e9ed064f7acaa2bf7fec7dd2bee3d796bc0744082041a06cf8f1e45dd44b8bfc02b1a584fd52817f2c16f6d26828f8fe32f5863cd938c5d2c7cab425f6cf1bff7e5c4035ee8bf6cdd48374f49db86ef77444d0b73acabbbe06d193f015aad4dabb76072ce6ae8beaf03e48c627465dda54afd436d47f007c5b1c7b52cf55830d6a3dbcd561bac52be9e131182f46854ba40f55c86c7935413f3c9ebaed553f9b9fafb964f0c5a03ee454b8a21bcef78881b1dcd9e4f0944f5e0dee6770f7d32e058739d6a63eb6e264ada03dc9a30d0b1db52bb8d96dc1f7c6265fd93ec0da79c5898fbf9ebb3dc1bb2ffe8ad5eb8ab90e70f448d5fe3fad48c56d1bfcd93dd5b11f413eaeb15c0056ce58e6652cffa6da783774a82e27db165d9d8363082158db4c2fca14bce0b913326338a952f0c298c13f4e34914b7a30dee0b507de40fa8ad3c2f8f52d1728c2fcf55f6d1ebbd74086b553b14dd513b6350e3a768b8678ca52b18189a5b85564134db150477a016b7824e73e59449451b33fddc3fca5183dc7d9a198d69544c402d09a96e837c02247e4a6130d6eed2a9f2b30c3f738c35d70c85248c3b057359ed5ea1cd52b3d75eb9d54174e6a28ee2c6111a86baa9775f96a245abd0122b84590b748d11e36778668804478853cc95a6b177be3e89ad0d4dd55cf07353cb8977d3bd98060e117840d167f0db84d406970401cb2938b18074c16b36f9fd560d2658a28f3aee83ffb01f39fd96972dbcddd32018d34891143f8288664e979993eba480034fdab02115f30ad476c5814c52236c0351dce3f0dadbe16ad102d558e58e46f4de316d601f1eb8559fd6e7fa0da2edaa56f5a01fe1666e4700cbc5dc1ef9f7674f1fa53a82de533f9084a762ef55562b17634c10f12f1430c0c7be8aa9798546cd20c5eff8408a3cb350afaddd7ee636cd8ec151e393db773f5bbd9e176a34373d86ef942dd0d79b9e271371ed04fc6bee281bbcbc2cb0964bfde1e396a4c18625e8e24c29951cbdc14718e6d5109b0c08565d7735b9bca70a223539dda13c5e09eedc6ac0cfbf99a4807070785cf8dcebbab95d7a05ef72583571f7cf3444111c2d7cf6631862d9975944aad75d7121705fae35559fcc29c10be0ef7945100115b9f3c54195f6ba9878e79c64132a7fe77767413faf8cbbecf2ff69e85ec340b5692343cbd35c12b18aabc308b5d49214f95c8abe9237658b6f43919438f0789c7154d639c21103181eb034aea16574d9b6b961ebaa798d75ac2904f37e5a683dbb687f10e0818620bbadd332c64b26e0a1f4c6f64cfe00b35e9c5c8265032b1bb6ba5b13d924d0d200a10249cf5b69919d56f2f8ee7d0400c4ebf7153181646511f2519b3bca740aec21d724ced7aa4b820ab901cdfea9c89112d9e50021c63c6707ad027f5ca0be19cb4de574ebbafd938b3e9570d8be400d97da0ee86ba610153c7075ffa8b175ef3946454d98d904b82ce7ca96ff4cbac78721ac8c31f05fbb8e42c55b32556888450385e3540e73d58af2f6078582f2e941d213a237de856139ef5954f8af94fa85a9ece6f4b649d63fb0284a9c4fd576ad72a86371c8e8b2f43c27ce93027d0c7593926a6d69e87ea5795b61888c1aa80f605d1ba68fb1af27697f8a409f800b9405fc44a2b70c283d640d237b73b444da8326e7171c2f699e87c63a02d79cc10e62da48ed2f97597ab3c57c2944b11186e1df36974cc03a7c87606755b499406d36a35de4966e5a983e8cf04168af815d21fe1af84864fdbc6fc0b1a881b7f266d8cf96c7b67bd124bb3c785236d119466f2ff51edef931037f4fda1951cc8518579c4fd97d9e6e43c8848d5ec133e47a9aa5bc6f49295e63884fcb22e77fc54e4941241b888a31aa59e107b714f37d474deb8b9a62bd3a6e3867e6b8a972ffcbdd03d0c4880060a0297d9841d384b36f1682bc92768a1aea387214791408a323d534f9a3a362de6cad7bb3b395799a1c98d7ab4b909d19699256f2e028fa054ce49aa8645a150c2dcf0ebbabd87f87c14285b7475ea9fb1a2b772092d94e4a2332122b14c958c48dc2d147d4f797e5cbb1ade04c953f37555803900b7091ad9c274db66dba1ad056534beb09ff8030ec81d88848d7089d787aaaf897a74f9f91692557e5b306cbc359b986356bdfe5682a624c554dc42f3e521c76711beaa01733ba252670a55910720d4e62e0d294f49c7a5be941ab31619b07f28784a8196105c38585c29fbdfdf32b29c9dff18edb10cd5d176199bbec3d9c4b2eb6a5ee2867b255ad92ba3774d2356ce55e4ffee3c5cf8fceed59dda03fa9cda4bd1fc8f7005e2d9b67b2b729af552856a2d69a43380d8e3582bf5a0844ad15b75115a79b3c343c898164ca54480b7c4111b33949585bd30e2e660344012ad27a9e85fdf6ce509e07ea1ad1d81816db8e485d029101155c57641e2839a65c77e5eb43ccd16f81f626bd74c084bacde9e7716266b39a463ab4a1f2055fbdc00c20ea10db76139a5b90e106bfa4a51f41d475c303d094b6aa0303775b834388fee4d6677e18deecb5eaf8c3d591d3cb4c956ae34c7c60fe071f5d3f19cab9a59dd9423c6e88af1fa1223501da07cc214b18724ec1c587951ba0b1dc970bda7dc0ef804fdefebadee0965e023312ab274d01ff551753dc0b7afc85e10b68a9f56428cc2267fab541213b3ce4ce53b48aec637c8ea474774f6bdaa573f4eed9fd4998559a0670d82f622dc57e6e475c63c832aa4b17c31f83ba5d7ca5db9fdc57d4dbc9e8affaad3b65d1b3c4bf0b75df9f602ac32d1ea696219afb6952a294f4b540cce84a33242e065c609afa4e97d83aed8fbc70e410bb4ac1e64656c713f72378bfbae088c13d3e8e1fadbd2f5cfa1718d26c9376cb66449aecd642d476cdd411ab79511ea6608cfc1686b83d4ea4a0f8f197a759b62753860ab0c47b8caa719338d29ee89c6953ed4beebf5685b8b2ba9eb59fcefa66329670c5fe2ca4435c41b5ec4bddd9a69aa5727f8c7026cc337e7f5ea2b85d3e6eadf65d1da59921e9601684cbd6db98176793a8a778e4f97171b0a271463c772de46a0436964b32a57a00ff7e9b78ca13c743767b460bedf3a1d701196e2a87424a7fcdfaf115afcf9476b7992addc11bf5dd4485153818ddfe711c3fc14fb30aa9336100044e5a37d30d6d246459a6c6c38a28b0ee36c5f4ded811a115f23d4853e71cfbc48617fc8d469baeafc65234b2284f93d2a41953de6549f9c41b571867bbb6ff418332d3cbcc109f85d59203bc4d222a70ef70373f65e9cf0780289af7a3d8d168265f3864c5d2e933bacfa2424be11948b89596109584ca6e8ee0144c3d99a82cfab8846844f118601ab906b0b44730d79c9169db3822060b3fe635b51c060ba336c774dd1a5612319c004cd5a626743a468607a7cce9fd29ece8b85e868444b17ce733e80d2eae2e43585ed707a50ce1b2a2173dceff5f35b4dfeb79a69e18ae83d3f8445f0dd7f896096bd7e10383a59f95db4cd85ed6e54ca1cf899e13cd8fcf8d894fdde52f8598fb1581db8f2da9bd57d644127db11aec8803135259c6cad21a3a8cb51b86f5832f74d2d7da4c00ad6e04975e7986d4d7f5182ad6ac51225ea5bf595012f4da7a714ff27a654cbc5614843c848aaa8d1e71be240742e0225408d964430303d332924cf588f4c0bfb75f32c2907095476f00465ce5377a0864ea08f2916a2194b915e61d9829ba0af574d7d8d4fc61be6557c49d9b1893796a674dcd4a2d0ab1540da21721f9ba2889d40d11d15a03f47fb9b4758fb5d396fc3ef09dd2eb17340651bbd4d4d302171b64a5d134a14c2f5761d69baf6e087645f1569ae3c9430bd62569a771c3c9d386357852630d14d59bccaae73e88e79fd335da885dbc26e317a560e886b46237a9bf974c90f17e8d1a3193eb8f6a8a4085fe6afcfc6625155f230cf95e28b02b2aa25a07dd2b9402a7e11a026050b95f200b7f559706d39de6ea5c6a3290939e06c2dca3293634d1380cbea8776653dcd705517ec2d729f81f6402d576f5dabf30f4a8cdc49be08c481f63d7595360804f33291665408c80c03c205b4f72361e2950d32c7279a81d3d6a36479bb03f1ac6bfca0e129b096f3fc11b1a31322a3603bdbcf5f25ef6983aabfde61dbbfb31aebf6a6438c0de64b0fb58146993c8339ed1575816a6db7850ad758ee3d1b493442e12deb80ae936380c081a69dfbe7b86cbb28d5c225733e9c7e7674418cc7696f6bc482688210a51cea3c76ba11c21c21d75191c1f92f2834c1a9f9c6d1be9ad98508e7b4876621c126d0a3b9432e15f6aef3241bebfc3cb8f2dab4b96f97a61ee2e7312845d3614d817793f6c40190d7b17ef2b7bfc8ce665fc927dfd178722fa98d37e58d5c3ea763893f1f46390b9e412bb7b986e6f26e6b4998a7b7252bee2a919d92a4f63bcbccf52f7a4236cac4964dce74ba8572e8481de412bb53a0ec1667d3f64526bce5b1d39b5a49449f20a6d274d55e60b0c722a8c3606a1aed9a73738d634bd51a4b4be81283351fabfe38d8bc07b96495b56be9c69adf49958224936770455c97be2e895476df55af2d69e308a5b1f898d2d60896055b8f95f99cda6c961be77245025b3aae7411644fea5d5ed7c0f9fb6a9d48af4287b4be060236cee349ec67d4e94f6da473e30d4d406d95c62c1e7814aafe12b62e4ebfa9b4421b156a67e6743bb98d4bd17da6eec1e5a6591e5b6215675d6704257ca0cd1f71717e12fb61f365c8309df3e3e7646cf2ca5bf8fbb0e602e769c5510b11bbf114744ee38b80e0200a059a64daa7b699ea04851f976a7ac131cc0e2da1375524def3476375b4c4fc0e8e9e114f8873394b2ae418d4bff3bb202b523d2b7c897bbbac4f2af74dd5887ca6f5bfdc6a379332dd8f0a6a3b5792c1f1921642c1498dc23802f39f4e43e8f51f3415daa93f1985ad00c9e8768cad571d2016f57b05337882a38ad9f4470d205b1eb895de995fe90369bf0b6c0d73c5923465938cf6750d0a46ef63875d8eb0958c48459bae7ed3d0e6f1a4ff0c876e86f23f199e98d6fc6810cc76de5161e8c5d2e502ef34cdae2115a05ce7760248fbf9d29f89d80de97a7c4ce37d6999ed4c65057c55aa5b6295e0897474a4abd86b58a630b5519e24a96a9c36481adf71efddc96315cba56b0e648dbf25530ee8f03c8433265c28cd29475daaa79058194de73ea9f6beecbfbdac88cac419f91c685e36f599e7419d1b68ee540daf765f227cd6e91a6f1a83ac16f7619fa2c96da41337d7228a77a8bbf1659a978bc7c23e5cae67323f20d9d69bf343769ee98114b192c2d8567db0a2347fd93cff02620a59c45887ca6a95b586a04bae80994c31d39264e90306f73714ccddc98ab09f33d46be27789f44508d7a4e0294ddb7a972022adef1feb4bbf80b6acb41388b29fdb5eadb1741d38ae895ec6f034d72efe08fe09efc1063a32664526e718f90d541642e7a88852594ab25eb9eab2c473f4e86ce95f9ebb533d1a8d8a592931632928a08d8377a606e099c8ad9f42dcac63554b356a129a9e9573fcfb207b27baa436c6d4ddb4f8580d914a1263461e304db5e0815f7dd9b755db529032597b77050aa6c653afe3f7d7eac9e3df2d52b926639aa3f51d8cd5471da36ecf408bd859ce900e439901bd20c3c1bf000f6e62cd234e5fa295118a5b5f55100702fdafd43a7398894f4a3dd4f74889d27294143d5f3609d97ac3323c6f3d6ecbe990dcb5d975358f54153f286e78c8cfbc76cf3e2540614252d267ac9327d13fde8abc4b282014be61a11450aa26626c478ccab01c380f39cea9dc5d67501ab68b06bdcdd25871b7f3edfdff804e86957530235d7ea279358e444c2dba830c6fd5daadf7ff821eda6d9c8f6eb4ebad0d80fc45576ab4426f0b390ce9fb42312c23430d040d85efa8cde8e1a3c47a082d33cbea897edf90b00820032156816c8cc1218b9cbc41108f910a9a072afb6d94c20b5daa083a8c6f1e49570a82b779b06e91e01eeec67ad5fcc586401c91030a8300014a92973e2b4653816cfd1866ebe6a07b7b9050176f3f0fd7deb7094b96dca67a7fab85f80275b5616414ba3d11bed295420cb62860d5a01fe557eba85cab0dfbdd4ed1d7f30cdc0540690d7bfc99ff1e594e0dd369785079e2cc436db5a506ed65677921744aab605757d8f99d80cd79397578fa17671b4b70ebdf40a36ec697ece2a6d2b170bd083c0efd515b81acdf56c750064571d635ad50165f1e98519b12655820ef9393b33d71e037d8ae46f6e9ac84b732b21008111b16796ea62181f264aaa19c362b426516c97bbdbbf0b0da0e47f805847067261b62d7d699124645c6a6a983565815e6de4fbc31263380b6dc811fa9d4c1ed15690b2dc7c1afa5a4a810ee69bb8759c898287630273ba24e0a58de5608a0b0f5b0273c930fbc6aeb8b2ec767e4b8cf94740f93edbb0277d158d33a13e5d998b5cec54b5968271a32ce79f80118678f2978011bbaa86de2c5579e966ae17c6dd435279303fcb2d1cfdffafded27c921d1feea042f83e96f01bff7fc98215044eff87f28e65559c9b030a0676eac25552b5961084f162e8bb638d52c81b091ddbdaaf684c6f1cce30ff4c8c60f55148aed8bc5894c22114a2f37c483bd9d9eb809a483f918cd901f9c48251f8dcb19f35d61bf1105ec96e66f22601575a5abeedfd08dc5ec6669790c3b47e557d391adfb259ee0c86566ea1c4a93ad18003cb35a752e91df73a688cd65b92b754071ce3f6328f76c6d6f455eae1c4cd80e2b05cc183e1dadcd83deab48dcf62d191e0f69e1ea30f050b80640b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c645236986f1affba9e034017145436f7519e5681fa5b9940890979fb54be43bbfbe41d7930abb1e0ed6df778369f6ba1a32a75fa283ce82e50f65d95bfb1f8cd2be41d7930abb1e0ed6df778369f6ba1a32a75fa283ce82e50f65d95bfb1f8cd23edab1ff7eb6bf33f108e9ac1a08eb16c954b88a844e3119adf5950b44014eb63c8d900fcc619be33d08fd58502389ad641764bcccc2649d0c88659fc24b6d7be234489f88176e66bd858291d9de7054c6bdcedbb9f19ebedfab02d238b3dad79ac6a853e324ff7c5e92f5e9bbbfcda63466ec3e8a17fd9b3247f183465e93ca372fd5afc77f0d7f38658bb86153e8c7472376a5d735412237aea47881eb714ad1ffba188101427d74509d8786310f1e0793a251f31819283664626cbb6286bcdd109bc3de5bef59a8492c6f849e7cf1c2a665d6b5844e749d36a714fc4eb8f652fe79b889ef808d2d515a143bd50327674d18780056158238e627e37eaf784b4505976a7c3561f4c11d3d6507b4c18b802110be70e1266ecd65aa25fca95101a77e1f35756774bd632f5c4eb2c37314911471375f8123b8c3fc9ea3a5c0cc6d9b188fe909be6889a961ab6d53b11520bc8ef965b7387b554bd7c482b02b0f4f80d00110a008aff7aed1c6d66dfb2edfa2605d155c2d97a1c2877fd1bf4d770e6708988dc83ba66d6a40a20293dfee564ed40c41d5e541c2997e512019841b0b19fb878199014dea84874d11e319609135d4251944a93718a1549871f86355fe28ef6282e43d78006dfed31b909d581b41acb46b9a049d7babd678a808a8b42ef723c6b3654d1ff2ac20fe4e91db0ffb8387d06864cabae9e45d13b197ef3dcccc6b0296da09999c1156c66710e48fad121d7a7eb3f20a9281c83c7715e7f759dd2b11d8da24b078973a81d23f56a3cd370391c47ad7ea923f5233254b2c62a41ea39a3c45f364074338dbc792fc2c11e46cd8506f84eec2d00b8b7cd076d84a54a4e74dfb2af63dad0b61ff21f4f95994201c284fe8f586948c544ff57e966e81d01c4e3d56cb060111b09771b67ad0ce7c76f75907623f84b05a05d45611f5bc55eab02c151e601843afc2885ab9824b294c7d32e6352066793e8ccf6663071d70e16fed8696139a12f8dc737261cc47235f1f6043d92c85ee5f87b03e8429862ec396b133cb906d4fc51662f88cdb3cd527f0c6b7012ed9be804ded9422125eb5dc9143c8d61b9b80d5cf522b829938f539a301cd22e79e52f6213df15534953e17076aff00521a5402e73915fd843905ff5a92e6db5564e3ddd38febf2dc5d98f8fed85c6075f8b02b13976a0930190debfc8b9465651dd71ce4610e5dd7b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c6f0f73a33836688f5f01e1ec80ba5725affffe64d3ca9d151d5ffbaf1d6317b22@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootselinux-policy-3.13.1-266.el7.src.rpmselinux-policy-devel       /bin/sh/usr/bin/makecheckpolicym4policycoreutils-develrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)selinux-policyrpmlib(PayloadIsXz)2.5-82.5-243.0.4-14.6.0-14.0.4-14.0-13.13.1-266.el75.2-14.11.3]µ]]{@]{@]]c@]n]V]V]S]R@]Ik]:@]5@]%@]\F@\\9\@\ޢ@\\@\@\7\@\\~d\y\s\k\V\R@\R@\@n@\;(@\2[v[[;@[;@[[R@[t[#@[@[@[[h@[[[9@[@[}P@[{[{[z@[m~@[i[i[i[dC[`O@[]@[Y[6@[3|@[2*["X[d@[[ [ L@[[[@[ZmZȲZZH@Z@ZZz@Zz@ZyZ_:ZWQZV@Z.s@Z)-@Z%8ZZ @ZZNZNYYA@YYW@YW@YYY@Y@Ycl@YP@YJ_YI@YBvY9<@Y6@Y5GY1S@Y0Y.@Y-^Y, @Y, @Y%uYYY@Y@Y@Y.YXQ@XXX@X@X@XXX@XۡXP@XXg@Xg@X~@X@XƉXCXCXX @XXXBXXXs{@XY@XWXRXRXOXJXAb@X@X)@X#X!@XWWSW_@W_@Wv@W;W@WίWW:WQW@WW@W@WW~W@WW~D@W{@Ws@WrfWj}WbW^@WYZ@WYZ@WUeWM|WBW9@W9@W1@W(W V@V@V@V޾V2V@V_VVCV@VZV @VqV }@V }@VBUUU@U@UpUUUUoUoU5@UUȒ@UĝUUWUU@UUK@UUU'Ua@U~@UzUv@UT@U@Tr@T@T@T7TTTC@T@TTT}Tto@TsTk4T`T[bTWn@T?@T>aT6xT6xT@S@SSDSg}@SB@S>S;S:@S9XS5d@S4S2@S0@S,)S*@S)S)S&S&S"@S!S L@SSS@SSc@SSnS @S SK@RRR@RRJ@Ra@RRR&R&RRR=RʚRR@R@R@Rv@Rv@R@RR@R R@R@R|@Rz/@Rz/@RsRpRnQRi RfhR_@R_@R[R[RSRNRNRL RIgRB@RB@R:@R1R-@R-@R(r@R' R%@R7RRNRR@Q@QQdQQ@QQޞ@Q@QکQکQ@QzQQ4Q@@Q@QKQQ@Q@Q@Q@QQ@QQQQ@Q@QQQ@Qzl@Qw@QvwQo@Qo@QnQm=@QkQfQb@Q`@Q^QZ@QQQIQGQ@j@Q9Q8@Q4Q0@Q-@Q& @Q$QQ@QQ@Q @Qh@QsPP@P@PP@P[PP!@P8@PO@P @Pf@PPqP @PP7@P@PPPYP@P@PPPM@PPd@P@PoP{@P{@P@PP5@P@P~P}L@Px@PvPvPuc@Puc@Pr@Pmz@Pmz@Pmz@Pj@Pd?Pd?Pb@PaPaP[@PXb@PWPS@PQPO'PM@PIP@@P>@P8@P7lP2&P2&P,P,P*=P(@P#@P#@P!@P!@P@PkPw@Pw@PP

@NNU@NNl@N@N@NåN@NNNN@NNN@N@NGNGNGN@N@NNS@NS@N^N^N @N @NNj@Nj@NN$@NN@N/N@N@NFNFN@NNN@N@N@N]Ni@Ni@Ni@N|tNyNx@Ns:@NoENoENiNf @N^"@N\N[@NTNS@NS@NC@NBrN:N98@N7N6@N2N.@N*N)f@N(N%qN$ @N@N7@N e@NpNpM@M@Md@Md@MM{@M@M۝M@M@M‘@M@M@M@My@My@M3@M@M@MMM@MMMMTMx@Mx@Mv@MlMbSM[@MRMQ0@MQ0@MJMGMGMA^@M>@M9u@M6@M5M4/@M4/@M0:M,F@M$]@M@M9MMMMM\@M M M@L!L!L@LL@L@L@LOLOL[@L@L@Lr@L L,@L,@Lډ@L7LLLNL@LΫLeL|L@LB@LB@LB@L@LMLL@LdLL{L*@L@L5LLA@LLLL@LcL@L@L@LzL)@L|L|L|L{@LvW@LvW@Ls@Ls@LrbLrbLmLk@LjyLe3Lc@La?@LZLYV@LXLN@LN@LMxLMxLI@LH2LF@LEL=L=L=L;L7@L LT@L@LL@L@L0LLGL@K^K^KKKj@K$@KKK@K@KK@K]K޺K@KtK#@KKՀ@K:@KK͗@KŮ@K\K\K @KKKKK9@KK@KK@K@KKKKrKK~@K,K,K,K@KK8@KKK@KK@KqKqK}+K{@K{@KuBKs@KqN@KjKie@Kf@Ka|@K`*K]KXAKTM@KPXKEKEKEKD{@KC)KA@K;@K2@K0K/c@K+nK*@K(K"4@KK>K>K>JJęJH@JH@JJJ_@J@JjJjJ@Jv@Jv@Jv@Jv@J$J@JJ0@J@J@JG@JG@J@JJ@J@J@JJJ#J@JJJ@J:J@JJQJ@J J J|@JzJyt@Jyt@Jx"JrJrJq@Jn@Jn@JmJhPJeJ\s@JW-@JT@JS8JKOJI@JCfJCfJB@J@J@J?r@J<@J;}J:,@J7@J67J2C@J0J/@J,@J%@JJB@JJMJ J dJ@J@JJ@J*@J*@II@IIA@IIII@I@IIIX@IX@IX@II@I@IcIIo@Io@IzI)@I@IܑI@@II@I@I@IԨIд@I̿In@I3I3I@II@I@IV@IIaIIm@I@I'@II2III@IIIIIIII@III@I1I@III~@I}Iy@Ix_Iw@IuItk@Itk@Io%@Ik0IeIcGIa@I`IVIO@IJ;@IHIAI>]I= @I7@I6tI3I-I@III9@I9@II IP@I@IIg@Ig@HHH@HrH~@H,H@HCHHH @H @Hf@Hf@H@H+H@H׈H׈H7@HBH@HǶH@HH|@HHH@H{@H)HHL@H@H@H@HnH}H|@Ht@HsVHr@Hl@HkmHgy@HcH`H_@H^>HRa@HQHQHO@HFHFH$@DX@DU@DN@DN@DLDH@DGwDGwDDD@@D?D?D;@D;@D:HD:HD2_D1@D1@D-D+@D+@D'D!<@D!<@D!<@DDD@D@D@DDDDDD@D@D@D@D uD $@D D @D @DDDFC@C@C@C@CCCCCR@CCCCC@Ci@CC@C@CtC@C@CC:@CECCC @C @CعCعCعCعCC@C-C-C-C@C@CCǖ@C@CáCáCP@CP@C[C @C @CCg@Cg@CCC!@C~@C,C@CCCCC@CC@C@C@CZCZC @C @CCCf@Cf@Cf@CC@CqCqC @C @C @CCC}@C7@C7@C7@CBCBCYC@C@CC}@CqCqLukas Vrabec - 3.13.1-266Lukas Vrabec - 3.13.1-265Lukas Vrabec - 3.13.1-264Lukas Vrabec - 3.13.1-263Lukas Vrabec - 3.13.1-262Lukas Vrabec - 3.13.1-261Lukas Vrabec - 3.13.1-260Lukas Vrabec - 3.13.1-259Lukas Vrabec - 3.13.1-258Lukas Vrabec - 3.13.1-257Lukas Vrabec - 3.13.1-256Lukas Vrabec - 3.13.1-255Lukas Vrabec - 3.13.1-254Lukas Vrabec - 3.13.1-253Lukas Vrabec - 3.13.1-252.1Lukas Vrabec - 3.13.1-252Lukas Vrabec - 3.13.1-251Lukas Vrabec - 3.13.1-250Lukas Vrabec - 3.13.1-249Lukas Vrabec - 3.13.1-248Lukas Vrabec - 3.13.1-247Lukas Vrabec - 3.13.1-246Lukas Vrabec - 3.13.1-245Lukas Vrabec - 3.13.1-244Lukas Vrabec - 3.13.1-243Lukas Vrabec - 3.13.1-242Lukas Vrabec - 3.13.1-241Lukas Vrabec - 3.13.1-240Lukas Vrabec - 3.13.1-239Lukas Vrabec - 3.13.1-238Lukas Vrabec - 3.13.1-237Lukas Vrabec - 3.13.1-236Lukas Vrabec - 3.13.1-235Lukas Vrabec - 3.13.1-234Lukas Vrabec - 3.13.1-233Lukas Vrabec - 3.13.1-232Lukas Vrabec - 3.13.1-231Lukas Vrabec - 3.13.1-230Lukas Vrabec - 3.13.1-229.5Lukas Vrabec - 3.13.1-229.4Lukas Vrabec - 3.13.1-229.3Lukas Vrabec - 3.13.1-229.2Lukas Vrabec - 3.13.1-229.1Lukas Vrabec - 3.13.1-229Lukas Vrabec - 3.13.1-228Lukas Vrabec - 3.13.1-227Lukas Vrabec - 3.13.1-226Lukas Vrabec - 3.13.1-225Lukas Vrabec - 3.13.1-224Lukas Vrabec - 3.13.1-223Lukas Vrabec - 3.13.1-222Lukas Vrabec - 3.13.1-221Lukas Vrabec - 3.13.1-220Lukas Vrabec - 3.13.1-219Lukas Vrabec - 3.13.1-218Lukas Vrabec - 3.13.1-217Lukas Vrabec - 3.13.1-216Lukas Vrabec - 3.13.1-215Lukas Vrabec - 3.13.1-214Lukas Vrabec - 3.13.1-213Lukas Vrabec - 3.13.1-212Lukas Vrabec - 3.13.1-211Lukas Vrabec - 3.13.1-210Lukas Vrabec - 3.13.1-209Lukas Vrabec - 3.13.1-208Lukas Vrabec - 3.13.1-207Lukas Vrabec - 3.13.1-206Lukas Vrabec - 3.13.1-205Lukas Vrabec - 3.13.1-204Lukas Vrabec - 3.13.1-203Lukas Vrabec - 3.13.1-202Lukas Vrabec - 3.13.1-201Lukas Vrabec - 3.13.1-200Lukas Vrabec - 3.13.1-199Lukas Vrabec - 3.13.1-198Lukas Vrabec - 3.13.1-197Lukas Vrabec - 3.13.1-196Lukas Vrabec - 3.13.1-195Lukas Vrabec - 3.13.1-194Lukas Vrabec - 3.13.1-193Lukas Vrabec - 3.13.1-192Lukas Vrabec - 3.13.1-191Lukas Vrabec - 3.13.1-190Lukas Vrabec - 3.13.1-189Lukas Vrabec - 3.13.1-188Lukas Vrabec - 3.13.1-187Lukas Vrabec - 3.13.1-186Lukas Vrabec - 3.13.1-185Lukas Vrabec - 3.13.1-184Lukas Vrabec - 3.13.1-183Lukas Vrabec - 3.13.1-182Lukas Vrabec - 3.13.1-181Lukas Vrabec - 3.13.1-180Lukas Vrabec - 3.13.1-179Lukas Vrabec - 3.13.1-178Lukas Vrabec - 3.13.1-177Lukas Vrabec - 3.13.1-176Lukas Vrabec - 3.13.1-175Lukas Vrabec - 3.13.1-174Lukas Vrabec - 3.13.1-173Lukas Vrabec - 3.13.1-172Lukas Vrabec - 3.13.1-171Lukas Vrabec - 3.13.1-170Lukas Vrabec - 3.13.1-169Lukas Vrabec - 3.13.1-168Lukas Vrabec - 3.13.1-167Lukas Vrabec - 3.13.1-166Lukas Vrabec - 3.13.1-165Lukas Vrabec - 3.13.1-164Lukas Vrabec - 3.13.1-163Lukas Vrabec - 3.13.1-162Lukas Vrabec - 3.13.1-161Lukas Vrabec - 3.13.1-160Lukas Vrabec - 3.13.1-159Lukas Vrabec - 3.13.1-158Lukas Vrabec - 3.13.1-157Lukas Vrabec - 3.13.1-156Lukas Vrabec - 3.13.1-155Lukas Vrabec - 3.13.1-154Lukas Vrabec - 3.13.1-153Lukas Vrabec - 3.13.1-152Lukas Vrabec - 3.13.1-151Lukas Vrabec - 3.13.1-150Lukas Vrabec - 3.13.1-149Lukas Vrabec - 3.13.1-148Lukas Vrabec - 3.13.1-147Lukas Vrabec - 3.13.1-146Lukas Vrabec - 3.13.1-145Lukas Vrabec - 3.13.1-144Lukas Vrabec - 3.13.1-143Lukas Vrabec - 3.13.1-142Lukas Vrabec - 3.13.1-141Lukas Vrabec - 3.13.1-140Lukas Vrabec - 3.13.1-139Lukas Vrabec - 3.13.1-138Lukas Vrabec - 3.13.1-137Lukas Vrabec - 3.13.1-136Lukas Vrabec - 3.13.1-135Lukas Vrabec - 3.13.1-134Lukas Vrabec - 3.13.1-133Lukas Vrabec - 3.13.1-132Lukas Vrabec - 3.13.1-131Lukas Vrabec - 3.13.1-130Lukas Vrabec - 3.13.1-129Lukas Vrabec - 3.13.1-128Lukas Vrabec - 3.13.1-127Lukas Vrabec - 3.13.1-126Lukas Vrabec - 3.13.1-125Lukas Vrabec - 3.13.1-124Lukas Vrabec - 3.13.1-123Lukas Vrabec - 3.13.1-122Lukas Vrabec - 3.13.1-120Lukas Vrabec - 3.13.1-119Lukas Vrabec - 3.13.1-118Lukas Vrabec - 3.13.1-117Lukas Vrabec - 3.13.1-116Lukas Vrabec - 3.13.1-115Lukas Vrabec - 3.13.1-114Lukas Vrabec - 3.13.1-113Lukas Vrabec - 3.13.1-112Lukas Vrabec - 3.13.1-111Lukas Vrabec - 3.13.1-110Lukas Vrabec - 3.13.1-109Lukas Vrabec - 3.13.1-108Lukas Vrabec - 3.13.1-107Lukas Vrabec - 3.13.1-106Miroslav Grepl - 3.13.1-105Lukas Vrabec - 3.13.1-104Lukas Vrabec - 3.13.1-103Dan Walsh - 3.13.1-102Lukas Vrabec - 3.13.1-101Lukas Vrabec - 3.13.1-100Lukas Vrabec - 3.13.1-99Lukas Vrabec - 3.13.1-98Lukas Vrabec - 3.13.1-97Lukas Vrabec - 3.13.1-96Lukas Vrabec - 3.13.1-95Lukas Vrabec - 3.13.1-94Lukas Vrabec - 3.13.1-93Lukas Vrabec - 3.13.1-92Lukas Vrabec - 3.13.1-91Lukas Vrabec - 3.13.1-90Lukas Vrabec - 3.13.1-89Lukas Vrabec - 3.13.1-88Lukas Vrabec - 3.13.1-87Lukas Vrabec - 3.13.1-86Lukas Vrabec - 3.13.1-85Lukas Vrabec - 3.13.1-84Lukas Vrabec - 3.13.1-83Lukas Vrabec - 3.13.1-82Lukas Vrabec - 3.13.1-81Lukas Vrabec - 3.13.1-80Petr Lautrbach - 3.13.1-79Lukas Vrabec - 3.13.1-78Lukas Vrabec - 3.13.1-77Lukas Vrabec - 3.13.1-76Lukas Vrabec - 3.13.1-75Lukas Vrabec - 3.13.1-74Lukas Vrabec - 3.13.1-73Lukas Vrabec - 3.13.1-72Lukas Vrabec - 3.13.1-71Lukas Vrabec - 3.13.1-70Lukas Vrabec - 3.13.1-69Lukas Vrabec - 3.13.1-68Lukas Vrabec - 3.13.1-67Petr Lautrbach - 3.13.1-66Lukas Vrabec 3.13.1-65Lukas Vrabec 3.13.1-64Lukas Vrabec 3.13.1-63Lukas Vrabec 3.13.1-62Lukas Vrabec 3.13.1-61Miroslav Grepl 3.13.1-60Miroslav Grepl 3.13.1-59Lukas Vrabec 3.13.1-58Lukas Vrabec 3.13.1-57Miroslav Grepl 3.13.1-56Lukas Vrabec 3.13.1-55Lukas Vrabec 3.13.1-54Lukas Vrabec 3.13.1-53Lukas Vrabec 3.13.1-52Miroslav Grepl 3.13.1-51Lukas Vrabec 3.13.1-50Lukas Vrabec 3.13.1-49Lukas Vrabec 3.13.1-48Lukas Vrabec 3.13.1-47Lukas Vrabec 3.13.1-46Lukas Vrabec 3.13.1-45Lukas Vrabec 3.13.1-44Lukas Vrabec 3.13.1-43Lukas Vrabec 3.13.1-42Lukas Vrabec 3.13.1-41Lukas Vrabec 3.13.1-40Miroslav Grepl 3.13.1-39Lukas Vrabec 3.13.1-38Lukas Vrabec 3.13.1-37Lukas Vrabec 3.13.1-36Lukas Vrabec 3.13.1-35Lukas Vrabec 3.13.1-34Lukas Vrabec 3.13.1-33Lukas Vrabec 3.13.1-32Miroslav Grepl 3.13.1-31Miroslav Grepl 3.13.1-30Miroslav Grepl 3.13.1-29Miroslav Grepl 3.13.1-28Miroslav Grepl 3.13.1-27Miroslav Grepl 3.13.1-26Miroslav Grepl 3.13.1-25Miroslav Grepl 3.13.1-24Miroslav Grepl 3.13.1-23Miroslav Grepl 3.13.1-22Miroslav Grepl 3.13.1-21Miroslav Grepl 3.13.1-20Miroslav Grepl 3.13.1-19Miroslav Grepl 3.13.1-18Miroslav Grepl 3.13.1-17Miroslav Grepl 3.13.1-16Miroslav Grepl 3.13.1-15Miroslav Grepl 3.13.1-14Miroslav Grepl 3.13.1-13Miroslav Grepl 3.13.1-12Miroslav Grepl 3.13.1-11Miroslav Grepl 3.13.1-10Miroslav Grepl 3.13.1-9Miroslav Grepl 3.13.1-8Miroslav Grepl 3.13.1-7Miroslav Grepl 3.13.1-6Miroslav Grepl 3.13.1-5Miroslav Grepl 3.13.1-4Miroslav Grepl 3.13.1-3Miroslav Grepl 3.13.1-2Miroslav Grepl 3.13.1-1Miroslav Grepl 3.12.1-156Miroslav Grepl 3.12.1-155Miroslav Grepl 3.12.1-154Miroslav Grepl 3.12.1-153Miroslav Grepl 3.12.1-152Miroslav Grepl 3.12.1-151Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-148Miroslav Grepl 3.12.1-147Miroslav Grepl 3.12.1-146Miroslav Grepl 3.12.1-145Miroslav Grepl 3.12.1-144Lukas Vrabec 3.12.1-143Miroslav Grepl 3.12.1-142Miroslav Grepl 3.12.1-141Miroslav Grepl 3.12.1-140Miroslav Grepl 3.12.1-139Lukas Vrabec 3.12.1-138Miroslav Grepl 3.12.1-137Miroslav Grepl 3.12.1-136Miroslav Grepl 3.12.1-135Miroslav Grepl 3.12.1-134Miroslav Grepl 3.12.1-133Miroslav Grepl 3.12.1-132Miroslav Grepl 3.12.1-131Miroslav Grepl 3.12.1-130Miroslav Grepl 3.12.1-129Miroslav Grepl 3.12.1-128Miroslav Grepl 3.12.1-127Miroslav Grepl 3.12.1-126Miroslav Grepl 3.12.1-125Miroslav Grepl 3.12.1-124Miroslav Grepl 3.12.1-123Miroslav Grepl 3.12.1-122Miroslav Grepl 3.12.1-121Miroslav Grepl 3.12.1-120Miroslav Grepl 3.12.1-119Miroslav Grepl 3.12.1-118Miroslav Grepl 3.12.1-117Miroslav Grepl 3.12.1-116Miroslav Grepl 3.12.1-115Miroslav Grepl 3.12.1-114Miroslav Grepl 3.12.1-113Miroslav Grepl 3.12.1-112Miroslav Grepl 3.12.1-111Miroslav Grepl 3.12.1-110Miroslav Grepl 3.12.1-109Miroslav Grepl 3.12.1-108Miroslav Grepl 3.12.1-107Dan Walsh 3.12.1-106Miroslav Grepl 3.12.1-105Miroslav Grepl 3.12.1-104Miroslav Grepl 3.12.1-103Miroslav Grepl 3.12.1-102Miroslav Grepl 3.12.1-101Miroslav Grepl 3.12.1-100Miroslav Grepl 3.12.1-99Miroslav Grepl 3.12.1-98Miroslav Grepl 3.12.1-97Miroslav Grepl 3.12.1-96Miroslav Grepl 3.12.1-95Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-93Miroslav Grepl 3.12.1-92Miroslav Grepl 3.12.1-91Miroslav Grepl 3.12.1-90Miroslav Grepl 3.12.1-89Miroslav Grepl 3.12.1-88Miroslav Grepl 3.12.1-87Miroslav Grepl 3.12.1-86Miroslav Grepl 3.12.1-85Miroslav Grepl 3.12.1-84Miroslav Grepl 3.12.1-83Miroslav Grepl 3.12.1-82Miroslav Grepl 3.12.1-81Miroslav Grepl 3.12.1-80Miroslav Grepl 3.12.1-79Miroslav Grepl 3.12.1-78Miroslav Grepl 3.12.1-77Miroslav Grepl 3.12.1-76Miroslav Grepl 3.12.1-75Miroslav Grepl 3.12.1-74Miroslav Grepl 3.12.1-73Miroslav Grepl 3.12.1-72Miroslav Grepl 3.12.1-71Miroslav Grepl 3.12.1-70Miroslav Grepl 3.12.1-69Miroslav Grepl 3.12.1-68Miroslav Grepl 3.12.1-67Miroslav Grepl 3.12.1-66Miroslav Grepl 3.12.1-65Miroslav Grepl 3.12.1-64Miroslav Grepl 3.12.1-63Miroslav Grepl 3.12.1-62Miroslav Grepl 3.12.1-61Miroslav Grepl 3.12.1-60Miroslav Grepl 3.12.1-59Miroslav Grepl 3.12.1-58Miroslav Grepl 3.12.1-57Miroslav Grepl 3.12.1-56Miroslav Grepl 3.12.1-55Miroslav Grepl 3.12.1-54Miroslav Grepl 3.12.1-53Miroslav Grepl 3.12.1-52Miroslav Grepl 3.12.1-51Miroslav Grepl 3.12.1-50Miroslav Grepl 3.12.1-49Miroslav Grepl 3.12.1-48Miroslav Grepl 3.12.1-47Miroslav Grepl 3.12.1-46Miroslav Grepl 3.12.1-45Miroslav Grepl 3.12.1-44Miroslav Grepl 3.12.1-43Miroslav Grepl 3.12.1-42Miroslav Grepl 3.12.1-41Miroslav Grepl 3.12.1-40Miroslav Grepl 3.12.1-39Miroslav Grepl 3.12.1-38Miroslav Grepl 3.12.1-37Miroslav Grepl 3.12.1-36Miroslav Grepl 3.12.1-35Miroslav Grepl 3.12.1-34Miroslav Grepl 3.12.1-33Miroslav Grepl 3.12.1-32Miroslav Grepl 3.12.1-31Miroslav Grepl 3.12.1-30Miroslav Grepl 3.12.1-29Dan Walsh 3.12.1-28Dan Walsh 3.12.1-27Miroslav Grepl 3.12.1-26Miroslav Grepl 3.12.1-25Miroslav Grepl 3.12.1-24Miroslav Grepl 3.12.1-23Miroslav Grepl 3.12.1-22Miroslav Grepl 3.12.1-21Miroslav Grepl 3.12.1-20Miroslav Grepl 3.12.1-19Miroslav Grepl 3.12.1-18Miroslav Grepl 3.12.1-17Miroslav Grepl 3.12.1-16Miroslav Grepl 3.12.1-15Miroslav Grepl 3.12.1-14Miroslav Grepl 3.12.1-13Miroslav Grepl 3.12.1-12Miroslav Grepl 3.12.1-11Miroslav Grepl 3.12.1-10Miroslav Grepl 3.12.1-9Miroslav Grepl 3.12.1-8Miroslav Grepl 3.12.1-7Miroslav Grepl 3.12.1-6Miroslav Grepl 3.12.1-5Miroslav Grepl 3.12.1-4Miroslav Grepl 3.12.1-3Miroslav Grepl 3.12.1-2Miroslav Grepl 3.12.1-1Dan Walsh 3.11.1-69.1Miroslav Grepl 3.11.1-69Miroslav Grepl 3.11.1-68Miroslav Grepl 3.11.1-67Miroslav Grepl 3.11.1-66Miroslav Grepl 3.11.1-65Miroslav Grepl 3.11.1-64Miroslav Grepl 3.11.1-63Miroslav Grepl 3.11.1-62Miroslav Grepl 3.11.1-61Miroslav Grepl 3.11.1-60Miroslav Grepl 3.11.1-59Miroslav Grepl 3.11.1-58Miroslav Grepl 3.11.1-57Miroslav Grepl 3.11.1-56Miroslav Grepl 3.11.1-55Miroslav Grepl 3.11.1-54Miroslav Grepl 3.11.1-53Miroslav Grepl 3.11.1-52Miroslav Grepl 3.11.1-51Miroslav Grepl 3.11.1-50Miroslav Grepl 3.11.1-49Miroslav Grepl 3.11.1-48Miroslav Grepl 3.11.1-47Miroslav Grepl 3.11.1-46Miroslav Grepl 3.11.1-45Miroslav Grepl 3.11.1-44Miroslav Grepl 3.11.1-43Miroslav Grepl 3.11.1-42Miroslav Grepl 3.11.1-41Miroslav Grepl 3.11.1-40Miroslav Grepl 3.11.1-39Miroslav Grepl 3.11.1-38Miroslav Grepl 3.11.1-37Miroslav Grepl 3.11.1-36Miroslav Grepl 3.11.1-35Miroslav Grepl 3.11.1-34Miroslav Grepl 3.11.1-33Miroslav Grepl 3.11.1-32Miroslav Grepl 3.11.1-31Miroslav Grepl 3.11.1-30Miroslav Grepl 3.11.1-29Miroslav Grepl 3.11.1-28Miroslav Grepl 3.11.1-27Miroslav Grepl 3.11.1-26Miroslav Grepl 3.11.1-25Miroslav Grepl 3.11.1-24Miroslav Grepl 3.11.1-23Miroslav Grepl 3.11.1-22Miroslav Grepl 3.11.1-21Miroslav Grepl 3.11.1-20Miroslav Grepl 3.11.1-19Miroslav Grepl 3.11.1-18Miroslav Grepl 3.11.1-17Miroslav Grepl 3.11.1-16Dan Walsh 3.11.1-15Miroslav Grepl 3.11.1-14Dan Walsh 3.11.1-13Miroslav Grepl 3.11.1-12Miroslav Grepl 3.11.1-11Miroslav Grepl 3.11.1-10Dan Walsh 3.11.1-9Dan Walsh 3.11.1-8Dan Walsh 3.11.1-7Dan Walsh 3.11.1-6Miroslav Grepl 3.11.1-5Miroslav Grepl 3.11.1-4Miroslav Grepl 3.11.1-3Miroslav Grepl 3.11.1-2Miroslav Grepl 3.11.1-1Miroslav Grepl 3.11.1-0Miroslav Grepl 3.11.0-15Miroslav Grepl 3.11.0-14Miroslav Grepl 3.11.0-13Miroslav Grepl 3.11.0-12Fedora Release Engineering - 3.11.0-11Miroslav Grepl 3.11.0-10Miroslav Grepl 3.11.0-9Miroslav Grepl 3.11.0-8Miroslav Grepl 3.11.0-7Miroslav Grepl 3.11.0-6Miroslav Grepl 3.11.0-5Miroslav Grepl 3.11.0-4Miroslav Grepl 3.11.0-3Miroslav Grepl 3.11.0-2Miroslav Grepl 3.11.0-1Miroslav Grepl 3.10.0-128Miroslav Grepl 3.10.0-127Miroslav Grepl 3.10.0-126Miroslav Grepl 3.10.0-125Miroslav Grepl 3.10.0-124Miroslav Grepl 3.10.0-123Miroslav Grepl 3.10.0-122Miroslav Grepl 3.10.0-121Miroslav Grepl 3.10.0-120Miroslav Grepl 3.10.0-119Miroslav Grepl 3.10.0-118Miroslav Grepl 3.10.0-117Miroslav Grepl 3.10.0-116Miroslav Grepl 3.10.0-115Miroslav Grepl 3.10.0-114Miroslav Grepl 3.10.0-113Miroslav Grepl 3.10.0-112Miroslav Grepl 3.10.0-111Miroslav Grepl 3.10.0-110Miroslav Grepl 3.10.0-109Miroslav Grepl 3.10.0-108Miroslav Grepl 3.10.0-107Miroslav Grepl 3.10.0-106Miroslav Grepl 3.10.0-105Miroslav Grepl 3.10.0-104Miroslav Grepl 3.10.0-103Miroslav Grepl 3.10.0-102Miroslav Grepl 3.10.0-101Miroslav Grepl 3.10.0-100Miroslav Grepl 3.10.0-99Miroslav Grepl 3.10.0-98Miroslav Grepl 3.10.0-97Miroslav Grepl 3.10.0-96Miroslav Grepl 3.10.0-95Miroslav Grepl 3.10.0-94Miroslav Grepl 3.10.0-93Miroslav Grepl 3.10.0-92Miroslav Grepl 3.10.0-91Miroslav Grepl 3.10.0-90Miroslav Grepl 3.10.0-89Miroslav Grepl 3.10.0-88Miroslav Grepl 3.10.0-87Miroslav Grepl 3.10.0-86Miroslav Grepl 3.10.0-85Miroslav Grepl 3.10.0-84Miroslav Grepl 3.10.0-83Miroslav Grepl 3.10.0-82Dan Walsh 3.10.0-81.2Miroslav Grepl 3.10.0-81Miroslav Grepl 3.10.0-80Miroslav Grepl 3.10.0-79Miroslav Grepl 3.10.0-78Miroslav Grepl 3.10.0-77Miroslav Grepl 3.10.0-76Miroslav Grepl 3.10.0-75Dan Walsh 3.10.0-74.2Miroslav Grepl 3.10.0-74Miroslav Grepl 3.10.0-73Miroslav Grepl 3.10.0-72Miroslav Grepl 3.10.0-71Miroslav Grepl 3.10.0-70Miroslav Grepl 3.10.0-69Miroslav Grepl 3.10.0-68Miroslav Grepl 3.10.0-67Miroslav Grepl 3.10.0-66Miroslav Grepl 3.10.0-65Miroslav Grepl 3.10.0-64Miroslav Grepl 3.10.0-63Miroslav Grepl 3.10.0-59Miroslav Grepl 3.10.0-58Dan Walsh 3.10.0-57Dan Walsh 3.10.0-56Dan Walsh 3.10.0-55.2Dan Walsh 3.10.0-55.1Miroslav Grepl 3.10.0-55Dan Walsh 3.10.0-54.1Miroslav Grepl 3.10.0-54Dan Walsh 3.10.0-53.1Miroslav Grepl 3.10.0-53Miroslav Grepl 3.10.0-52Miroslav Grepl 3.10.0-51Dan Walsh 3.10.0-50.2Dan Walsh 3.10.0-50.1Miroslav Grepl 3.10.0-50Miroslav Grepl 3.10.0-49Miroslav Grepl 3.10.0-48Miroslav Grepl 3.10.0-47Dan Walsh 3.10.0-46.1Miroslav Grepl 3.10.0-46Dan Walsh 3.10.0-45.1Miroslav Grepl 3.10.0-45Miroslav Grepl 3.10.0-43Miroslav Grepl 3.10.0-42Miroslav Grepl 3.10.0-41Dan Walsh 3.10.0-40.2Miroslav Grepl 3.10.0-40Dan Walsh 3.10.0-39.3Dan Walsh 3.10.0-39.2Dan Walsh 3.10.0-39.1Miroslav Grepl 3.10.0-39Dan Walsh 3.10.0-38.1Miroslav Grepl 3.10.0-38Miroslav Grepl 3.10.0-37Dan Walsh 3.10.0-36.1Miroslav Grepl 3.10.0-36Dan Walsh 3.10.0-35Dan Walsh 3.10.0-34.7Dan Walsh 3.10.0-34.6Dan Walsh 3.10.0-34.4Miroslav Grepl 3.10.0-34.3Dan Walsh 3.10.0-34.2Dan Walsh 3.10.0-34.1Miroslav Grepl 3.10.0-34Miroslav Grepl 3.10.0-33Dan Walsh 3.10.0-31.1Miroslav Grepl 3.10.0-31Miroslav Grepl 3.10.0-29Miroslav Grepl 3.10.0-28Miroslav Grepl 3.10.0-27Miroslav Grepl 3.10.0-26Miroslav Grepl 3.10.0-25Miroslav Grepl 3.10.0-24Miroslav Grepl 3.10.0-23Miroslav Grepl 3.10.0-22Miroslav Grepl 3.10.0-21Dan Walsh 3.10.0-20Miroslav Grepl 3.10.0-19Miroslav Grepl 3.10.0-18Miroslav Grepl 3.10.0-17Miroslav Grepl 3.10.0-16Miroslav Grepl 3.10.0-14Miroslav Grepl 3.10.0-13Miroslav Grepl 3.10.0-12Miroslav Grepl 3.10.0-11Miroslav Grepl 3.10.0-10Miroslav Grepl 3.10.0-9Miroslav Grepl 3.10.0-8Miroslav Grepl 3.10.0-7Miroslav Grepl 3.10.0-6Miroslav Grepl 3.10.0-5Miroslav Grepl 3.10.0-4Miroslav Grepl 3.10.0-3Miroslav Grepl 3.10.0-2Miroslav Grepl 3.10.0-1Miroslav Grepl 3.9.16-30Dan Walsh 3.9.16-29.1Miroslav Grepl 3.9.16-29Dan Walsh 3.9.16-28.1Miroslav Grepl 3.9.16-27Miroslav Grepl 3.9.16-26Miroslav Grepl 3.9.16-25Miroslav Grepl 3.9.16-24Miroslav Grepl 3.9.16-23Miroslav Grepl 3.9.16-22Miroslav Grepl 3.9.16-21Miroslav Grepl 3.9.16-20Miroslav Grepl 3.9.16-19Miroslav Grepl 3.9.16-18Miroslav Grepl 3.9.16-17Dan Walsh 3.9.16-16.1Miroslav Grepl 3.9.16-16Miroslav Grepl 3.9.16-15Miroslav Grepl 3.9.16-14Miroslav Grepl 3.9.16-13Miroslav Grepl 3.9.16-12Miroslav Grepl 3.9.16-11Miroslav Grepl 3.9.16-10Miroslav Grepl 3.9.16-7Miroslav Grepl 3.9.16-6Miroslav Grepl 3.9.16-5Miroslav Grepl 3.9.16-4Miroslav Grepl 3.9.16-3Miroslav Grepl 3.9.16-2Miroslav Grepl 3.9.16-1Miroslav Grepl 3.9.15-5Miroslav Grepl 3.9.15-2Miroslav Grepl 3.9.15-1Fedora Release Engineering - 3.9.14-2Dan Walsh 3.9.14-1Miroslav Grepl 3.9.13-10Miroslav Grepl 3.9.13-9Dan Walsh 3.9.13-8Miroslav Grepl 3.9.13-7Miroslav Grepl 3.9.13-6Miroslav Grepl 3.9.13-5Miroslav Grepl 3.9.13-4Miroslav Grepl 3.9.13-3Miroslav Grepl 3.9.13-2Miroslav Grepl 3.9.13-1Miroslav Grepl 3.9.12-8Miroslav Grepl 3.9.12-7Miroslav Grepl 3.9.12-6Miroslav Grepl 3.9.12-5Dan Walsh 3.9.12-4Dan Walsh 3.9.12-3Dan Walsh 3.9.12-2Miroslav Grepl 3.9.12-1Dan Walsh 3.9.11-2Miroslav Grepl 3.9.11-1Miroslav Grepl 3.9.10-13Dan Walsh 3.9.10-12Miroslav Grepl 3.9.10-11Miroslav Grepl 3.9.10-10Miroslav Grepl 3.9.10-9Miroslav Grepl 3.9.10-8Miroslav Grepl 3.9.10-7Miroslav Grepl 3.9.10-6Miroslav Grepl 3.9.10-5Dan Walsh 3.9.10-4Miroslav Grepl 3.9.10-3Miroslav Grepl 3.9.10-2Miroslav Grepl 3.9.10-1Miroslav Grepl 3.9.9-4Dan Walsh 3.9.9-3Miroslav Grepl 3.9.9-2Miroslav Grepl 3.9.9-1Miroslav Grepl 3.9.8-7Dan Walsh 3.9.8-6Miroslav Grepl 3.9.8-5Miroslav Grepl 3.9.8-4Dan Walsh 3.9.8-3Dan Walsh 3.9.8-2Dan Walsh 3.9.8-1Dan Walsh 3.9.7-10Dan Walsh 3.9.7-9Dan Walsh 3.9.7-8Dan Walsh 3.9.7-7Dan Walsh 3.9.7-6Dan Walsh 3.9.7-5Dan Walsh 3.9.7-4Dan Walsh 3.9.7-3Dan Walsh 3.9.7-2Dan Walsh 3.9.7-1Dan Walsh 3.9.6-3Dan Walsh 3.9.6-2Dan Walsh 3.9.6-1Dan Walsh 3.9.5-11Dan Walsh 3.9.5-10Dan Walsh 3.9.5-9Dan Walsh 3.9.5-8Dan Walsh 3.9.5-7Dan Walsh 3.9.5-6Dan Walsh 3.9.5-5Dan Walsh 3.9.5-4Dan Walsh 3.9.5-3Dan Walsh 3.9.5-2Dan Walsh 3.9.5-1Dan Walsh 3.9.4-3Dan Walsh 3.9.4-2Dan Walsh 3.9.4-1Dan Walsh 3.9.3-4Dan Walsh 3.9.3-3Dan Walsh 3.9.3-2Dan Walsh 3.9.3-1Dan Walsh 3.9.2-1Dan Walsh 3.9.1-3Dan Walsh 3.9.1-2Dan Walsh 3.9.1-1Dan Walsh 3.9.0-2Dan Walsh 3.9.0-1Dan Walsh 3.8.8-21Dan Walsh 3.8.8-20Dan Walsh 3.8.8-19Dan Walsh 3.8.8-18Dan Walsh 3.8.8-17Dan Walsh 3.8.8-16Dan Walsh 3.8.8-15Dan Walsh 3.8.8-14Dan Walsh 3.8.8-13Dan Walsh 3.8.8-12Dan Walsh 3.8.8-11Dan Walsh 3.8.8-10Dan Walsh 3.8.8-9Dan Walsh 3.8.8-8Dan Walsh 3.8.8-7Dan Walsh 3.8.8-6Dan Walsh 3.8.8-5Dan Walsh 3.8.8-4Dan Walsh 3.8.8-3Dan Walsh 3.8.8-2Dan Walsh 3.8.8-1Dan Walsh 3.8.7-3Dan Walsh 3.8.7-2Dan Walsh 3.8.7-1Dan Walsh 3.8.6-3Miroslav Grepl 3.8.6-2Dan Walsh 3.8.6-1Dan Walsh 3.8.5-1Dan Walsh 3.8.4-1Dan Walsh 3.8.3-4Dan Walsh 3.8.3-3Dan Walsh 3.8.3-2Dan Walsh 3.8.3-1Dan Walsh 3.8.2-1Dan Walsh 3.8.1-5Dan Walsh 3.8.1-4Dan Walsh 3.8.1-3Dan Walsh 3.8.1-2Dan Walsh 3.8.1-1Dan Walsh 3.7.19-22Dan Walsh 3.7.19-21Dan Walsh 3.7.19-20Dan Walsh 3.7.19-19Dan Walsh 3.7.19-17Dan Walsh 3.7.19-16Dan Walsh 3.7.19-15Dan Walsh 3.7.19-14Dan Walsh 3.7.19-13Dan Walsh 3.7.19-12Dan Walsh 3.7.19-11Dan Walsh 3.7.19-10Dan Walsh 3.7.19-9Dan Walsh 3.7.19-8Dan Walsh 3.7.19-7Dan Walsh 3.7.19-6Dan Walsh 3.7.19-5Dan Walsh 3.7.19-4Dan Walsh 3.7.19-3Dan Walsh 3.7.19-2Dan Walsh 3.7.19-1Dan Walsh 3.7.18-3Dan Walsh 3.7.18-2Dan Walsh 3.7.18-1Dan Walsh 3.7.17-6Dan Walsh 3.7.17-5Dan Walsh 3.7.17-4Dan Walsh 3.7.17-3Dan Walsh 3.7.17-2Dan Walsh 3.7.17-1Dan Walsh 3.7.16-2Dan Walsh 3.7.16-1Dan Walsh 3.7.15-4Dan Walsh 3.7.15-3Dan Walsh 3.7.15-2Dan Walsh 3.7.15-1Dan Walsh 3.7.14-5Dan Walsh 3.7.14-4Dan Walsh 3.7.14-3Dan Walsh 3.7.14-2Dan Walsh 3.7.14-1Dan Walsh 3.7.13-4Dan Walsh 3.7.13-3Dan Walsh 3.7.13-2Dan Walsh 3.7.13-1Dan Walsh 3.7.12-1Dan Walsh 3.7.11-1Dan Walsh 3.7.10-5Dan Walsh 3.7.10-4Dan Walsh 3.7.10-3Dan Walsh 3.7.10-2Dan Walsh 3.7.10-1Dan Walsh 3.7.9-4Dan Walsh 3.7.9-3Dan Walsh 3.7.9-2Dan Walsh 3.7.9-1Dan Walsh 3.7.8-11Dan Walsh 3.7.8-9Dan Walsh 3.7.8-8Dan Walsh 3.7.8-7Dan Walsh 3.7.8-6Dan Walsh 3.7.8-5Dan Walsh 3.7.8-4Dan Walsh 3.7.8-3Dan Walsh 3.7.8-2Dan Walsh 3.7.8-1Dan Walsh 3.7.7-3Dan Walsh 3.7.7-2Dan Walsh 3.7.7-1Dan Walsh 3.7.6-1Dan Walsh 3.7.5-8Dan Walsh 3.7.5-7Dan Walsh 3.7.5-6Dan Walsh 3.7.5-5Dan Walsh 3.7.5-4Dan Walsh 3.7.5-3Dan Walsh 3.7.5-2Dan Walsh 3.7.5-1Dan Walsh 3.7.4-4Dan Walsh 3.7.4-3Dan Walsh 3.7.4-2Dan Walsh 3.7.4-1Dan Walsh 3.7.3-1Dan Walsh 3.7.1-1Dan Walsh 3.6.33-2Dan Walsh 3.6.33-1Dan Walsh 3.6.32-17Dan Walsh 3.6.32-16Dan Walsh 3.6.32-15Dan Walsh 3.6.32-13Dan Walsh 3.6.32-12Dan Walsh 3.6.32-11Dan Walsh 3.6.32-10Dan Walsh 3.6.32-9Dan Walsh 3.6.32-8Dan Walsh 3.6.32-7Dan Walsh 3.6.32-6Dan Walsh 3.6.32-5Dan Walsh 3.6.32-4Dan Walsh 3.6.32-3Dan Walsh 3.6.32-2Dan Walsh 3.6.32-1Dan Walsh 3.6.31-5Dan Walsh 3.6.31-4Dan Walsh 3.6.31-3Dan Walsh 3.6.31-2Dan Walsh 3.6.30-6Dan Walsh 3.6.30-5Dan Walsh 3.6.30-4Dan Walsh 3.6.30-3Dan Walsh 3.6.30-2Dan Walsh 3.6.30-1Dan Walsh 3.6.29-2Dan Walsh 3.6.29-1Dan Walsh 3.6.28-9Dan Walsh 3.6.28-8Dan Walsh 3.6.28-7Dan Walsh 3.6.28-6Dan Walsh 3.6.28-5Dan Walsh 3.6.28-4Dan Walsh 3.6.28-3Dan Walsh 3.6.28-2Dan Walsh 3.6.28-1Dan Walsh 3.6.27-1Dan Walsh 3.6.26-11Dan Walsh 3.6.26-10Dan Walsh 3.6.26-9Bill Nottingham 3.6.26-8Dan Walsh 3.6.26-7Dan Walsh 3.6.26-6Dan Walsh 3.6.26-5Dan Walsh 3.6.26-4Dan Walsh 3.6.26-3Dan Walsh 3.6.26-2Dan Walsh 3.6.26-1Dan Walsh 3.6.25-1Dan Walsh 3.6.24-1Dan Walsh 3.6.23-2Dan Walsh 3.6.23-1Dan Walsh 3.6.22-3Dan Walsh 3.6.22-1Dan Walsh 3.6.21-4Dan Walsh 3.6.21-3Tom "spot" Callaway 3.6.21-2Dan Walsh 3.6.21-1Dan Walsh 3.6.20-2Dan Walsh 3.6.20-1Dan Walsh 3.6.19-5Dan Walsh 3.6.19-4Dan Walsh 3.6.19-3Dan Walsh 3.6.19-2Dan Walsh 3.6.19-1Dan Walsh 3.6.18-1Dan Walsh 3.6.17-1Dan Walsh 3.6.16-4Dan Walsh 3.6.16-3Dan Walsh 3.6.16-2Dan Walsh 3.6.16-1Dan Walsh 3.6.14-3Dan Walsh 3.6.14-2Dan Walsh 3.6.14-1Dan Walsh 3.6.13-3Dan Walsh 3.6.13-2Dan Walsh 3.6.13-1Dan Walsh 3.6.12-39Dan Walsh 3.6.12-38Dan Walsh 3.6.12-37Dan Walsh 3.6.12-36Dan Walsh 3.6.12-35Dan Walsh 3.6.12-34Dan Walsh 3.6.12-33Dan Walsh 3.6.12-31Dan Walsh 3.6.12-30Dan Walsh 3.6.12-29Dan Walsh 3.6.12-28Dan Walsh 3.6.12-27Dan Walsh 3.6.12-26Dan Walsh 3.6.12-25Dan Walsh 3.6.12-24Dan Walsh 3.6.12-23Dan Walsh 3.6.12-22Dan Walsh 3.6.12-21Dan Walsh 3.6.12-20Dan Walsh 3.6.12-19Dan Walsh 3.6.12-16Dan Walsh 3.6.12-15Dan Walsh 3.6.12-14Dan Walsh 3.6.12-13Dan Walsh 3.6.12-12Dan Walsh 3.6.12-11Dan Walsh 3.6.12-10Dan Walsh 3.6.12-9Dan Walsh 3.6.12-8Dan Walsh 3.6.12-7Dan Walsh 3.6.12-6Dan Walsh 3.6.12-5Dan Walsh 3.6.12-4Dan Walsh 3.6.12-3Dan Walsh 3.6.12-2Dan Walsh 3.6.12-1Dan Walsh 3.6.11-1Dan Walsh 3.6.10-9Dan Walsh 3.6.10-8Dan Walsh 3.6.10-7Dan Walsh 3.6.10-6Dan Walsh 3.6.10-5Dan Walsh 3.6.10-4Dan Walsh 3.6.10-3Dan Walsh 3.6.10-2Dan Walsh 3.6.10-1Dan Walsh 3.6.9-4Dan Walsh 3.6.9-3Dan Walsh 3.6.9-2Dan Walsh 3.6.9-1Dan Walsh 3.6.8-4Dan Walsh 3.6.8-3Dan Walsh 3.6.8-2Dan Walsh 3.6.8-1Dan Walsh 3.6.7-2Dan Walsh 3.6.7-1Dan Walsh 3.6.6-9Dan Walsh 3.6.6-8Fedora Release Engineering - 3.6.6-7Dan Walsh 3.6.6-6Dan Walsh 3.6.6-5Dan Walsh 3.6.6-4Dan Walsh 3.6.6-3Dan Walsh 3.6.6-2Dan Walsh 3.6.6-1Dan Walsh 3.6.5-3Dan Walsh 3.6.5-1Dan Walsh 3.6.4-6Dan Walsh 3.6.4-5Dan Walsh 3.6.4-4Dan Walsh 3.6.4-3Dan Walsh 3.6.4-2Dan Walsh 3.6.4-1Dan Walsh 3.6.3-13Dan Walsh 3.6.3-12Dan Walsh 3.6.3-11Dan Walsh 3.6.3-10Dan Walsh 3.6.3-9Dan Walsh 3.6.3-8Dan Walsh 3.6.3-7Dan Walsh 3.6.3-6Dan Walsh 3.6.3-3Dan Walsh 3.6.3-2Dan Walsh 3.6.3-1Dan Walsh 3.6.2-5Dan Walsh 3.6.2-4Dan Walsh 3.6.2-3Dan Walsh 3.6.2-2Dan Walsh 3.6.2-1Dan Walsh 3.6.1-15Dan Walsh 3.6.1-14Dan Walsh 3.6.1-13Dan Walsh 3.6.1-12Dan Walsh 3.6.1-11Dan Walsh 3.6.1-10Dan Walsh 3.6.1-9Dan Walsh 3.6.1-8Dan Walsh 3.6.1-7Dan Walsh 3.6.1-4Ignacio Vazquez-Abrams - 3.6.1-2Dan Walsh 3.5.13-19Dan Walsh 3.5.13-18Dan Walsh 3.5.13-17Dan Walsh 3.5.13-16Dan Walsh 3.5.13-15Dan Walsh 3.5.13-14Dan Walsh 3.5.13-13Dan Walsh 3.5.13-12Dan Walsh 3.5.13-11Dan Walsh 3.5.13-9Dan Walsh 3.5.13-8Dan Walsh 3.5.13-7Dan Walsh 3.5.13-6Dan Walsh 3.5.13-5Dan Walsh 3.5.13-4Dan Walsh 3.5.13-3Dan Walsh 3.5.13-2Dan Walsh 3.5.13-1Dan Walsh 3.5.12-3Dan Walsh 3.5.12-2Dan Walsh 3.5.12-1Dan Walsh 3.5.11-1Dan Walsh 3.5.10-3Dan Walsh 3.5.10-2Dan Walsh 3.5.10-1Dan Walsh 3.5.9-4Dan Walsh 3.5.9-3Dan Walsh 3.5.9-2Dan Walsh 3.5.9-1Dan Walsh 3.5.8-7Dan Walsh 3.5.8-6Dan Walsh 3.5.8-5Dan Walsh 3.5.8-4Dan Walsh 3.5.8-3Dan Walsh 3.5.8-1Dan Walsh 3.5.7-2Dan Walsh 3.5.7-1Dan Walsh 3.5.6-2Dan Walsh 3.5.6-1Dan Walsh 3.5.5-4Dan Walsh 3.5.5-3Dan Walsh 3.5.5-2Dan Walsh 3.5.4-2Dan Walsh 3.5.4-1Dan Walsh 3.5.3-1Dan Walsh 3.5.2-2Dan Walsh 3.5.1-5Dan Walsh 3.5.1-4Dan Walsh 3.5.1-3Dan Walsh 3.5.1-2Dan Walsh 3.5.1-1Dan Walsh 3.5.0-1Dan Walsh 3.4.2-14Dan Walsh 3.4.2-13Dan Walsh 3.4.2-12Dan Walsh 3.4.2-11Dan Walsh 3.4.2-10Dan Walsh 3.4.2-9Dan Walsh 3.4.2-8Dan Walsh 3.4.2-7Dan Walsh 3.4.2-6Dan Walsh 3.4.2-5Dan Walsh 3.4.2-4Dan Walsh 3.4.2-3Dan Walsh 3.4.2-2Dan Walsh 3.4.2-1Dan Walsh 3.4.1-5Dan Walsh 3.4.1-3Dan Walsh 3.4.1-2Dan Walsh 3.4.1-1Dan Walsh 3.3.1-48Dan Walsh 3.3.1-47Dan Walsh 3.3.1-46Dan Walsh 3.3.1-45Dan Walsh 3.3.1-44Dan Walsh 3.3.1-43Dan Walsh 3.3.1-42Dan Walsh 3.3.1-41Dan Walsh 3.3.1-39Dan Walsh 3.3.1-37Dan Walsh 3.3.1-36Dan Walsh 3.3.1-33Dan Walsh 3.3.1-32Dan Walsh 3.3.1-31Dan Walsh 3.3.1-30Dan Walsh 3.3.1-29Dan Walsh 3.3.1-28Dan Walsh 3.3.1-27Dan Walsh 3.3.1-26Dan Walsh 3.3.1-25Dan Walsh 3.3.1-24Dan Walsh 3.3.1-23Dan Walsh 3.3.1-22Dan Walsh 3.3.1-21Dan Walsh 3.3.1-20Dan Walsh 3.3.1-19Dan Walsh 3.3.1-18Dan Walsh 3.3.1-17Dan Walsh 3.3.1-16Dan Walsh 3.3.1-15Bill Nottingham 3.3.1-14Dan Walsh 3.3.1-13Dan Walsh 3.3.1-12Dan Walsh 3.3.1-11Dan Walsh 3.3.1-10Dan Walsh 3.3.1-9Dan Walsh 3.3.1-8Dan Walsh 3.3.1-6Dan Walsh 3.3.1-5Dan Walsh 3.3.1-4Dan Walsh 3.3.1-2Dan Walsh 3.3.1-1Dan Walsh 3.3.0-2Dan Walsh 3.3.0-1Dan Walsh 3.2.9-2Dan Walsh 3.2.9-1Dan Walsh 3.2.8-2Dan Walsh 3.2.8-1Dan Walsh 3.2.7-6Dan Walsh 3.2.7-5Dan Walsh 3.2.7-3Dan Walsh 3.2.7-2Dan Walsh 3.2.7-1Dan Walsh 3.2.6-7Dan Walsh 3.2.6-6Dan Walsh 3.2.6-5Dan Walsh 3.2.6-4Dan Walsh 3.2.6-3Dan Walsh 3.2.6-2Dan Walsh 3.2.6-1Dan Walsh 3.2.5-25Dan Walsh 3.2.5-24Dan Walsh 3.2.5-22Dan Walsh 3.2.5-21Dan Walsh 3.2.5-20Dan Walsh 3.2.5-19Dan Walsh 3.2.5-18Dan Walsh 3.2.5-17Dan Walsh 3.2.5-16Dan Walsh 3.2.5-15Dan Walsh 3.2.5-14Dan Walsh 3.2.5-13Dan Walsh 3.2.5-12Dan Walsh 3.2.5-11Dan Walsh 3.2.5-10Dan Walsh 3.2.5-9Dan Walsh 3.2.5-8Dan Walsh 3.2.5-7Dan Walsh 3.2.5-6Dan Walsh 3.2.5-5Dan Walsh 3.2.5-4Dan Walsh 3.2.5-3Dan Walsh 3.2.5-2Dan Walsh 3.2.5-1Dan Walsh 3.2.4-5Dan Walsh 3.2.4-4Dan Walsh 3.2.4-3Dan Walsh 3.2.4-1Dan Walsh 3.2.4-1Dan Walsh 3.2.3-2Dan Walsh 3.2.3-1Dan Walsh 3.2.2-1Dan Walsh 3.2.1-3Dan Walsh 3.2.1-1Dan Walsh 3.1.2-2Dan Walsh 3.1.2-1Dan Walsh 3.1.1-1Dan Walsh 3.1.0-1Dan Walsh 3.0.8-30Dan Walsh 3.0.8-28Dan Walsh 3.0.8-27Dan Walsh 3.0.8-26Dan Walsh 3.0.8-25Dan Walsh 3.0.8-24Dan Walsh 3.0.8-23Dan Walsh 3.0.8-22Dan Walsh 3.0.8-21Dan Walsh 3.0.8-20Dan Walsh 3.0.8-19Dan Walsh 3.0.8-18Dan Walsh 3.0.8-17Dan Walsh 3.0.8-16Dan Walsh 3.0.8-15Dan Walsh 3.0.8-14Dan Walsh 3.0.8-13Dan Walsh 3.0.8-12Dan Walsh 3.0.8-11Dan Walsh 3.0.8-10Dan Walsh 3.0.8-9Dan Walsh 3.0.8-8Dan Walsh 3.0.8-7Dan Walsh 3.0.8-5Dan Walsh 3.0.8-4Dan Walsh 3.0.8-3Dan Walsh 3.0.8-2Dan Walsh 3.0.8-1Dan Walsh 3.0.7-10Dan Walsh 3.0.7-9Dan Walsh 3.0.7-8Dan Walsh 3.0.7-7Dan Walsh 3.0.7-6Dan Walsh 3.0.7-5Dan Walsh 3.0.7-4Dan Walsh 3.0.7-3Dan Walsh 3.0.7-2Dan Walsh 3.0.7-1Dan Walsh 3.0.6-3Dan Walsh 3.0.6-2Dan Walsh 3.0.6-1Dan Walsh 3.0.5-11Dan Walsh 3.0.5-10Dan Walsh 3.0.5-9Dan Walsh 3.0.5-8Dan Walsh 3.0.5-7Dan Walsh 3.0.5-6Dan Walsh 3.0.5-5Dan Walsh 3.0.5-4Dan Walsh 3.0.5-3Dan Walsh 3.0.5-2Dan Walsh 3.0.5-1Dan Walsh 3.0.4-6Dan Walsh 3.0.4-5Dan Walsh 3.0.4-4Dan Walsh 3.0.4-3Dan Walsh 3.0.4-2Dan Walsh 3.0.4-1Dan Walsh 3.0.3-6Dan Walsh 3.0.3-5Dan Walsh 3.0.3-4Dan Walsh 3.0.3-3Dan Walsh 3.0.3-2Dan Walsh 3.0.3-1Dan Walsh 3.0.2-9Dan Walsh 3.0.2-8Dan Walsh 3.0.2-7Dan Walsh 3.0.2-5Dan Walsh 3.0.2-4Dan Walsh 3.0.2-3Dan Walsh 3.0.2-2Dan Walsh 3.0.1-5Dan Walsh 3.0.1-4Dan Walsh 3.0.1-3Dan Walsh 3.0.1-2Dan Walsh 3.0.1-1Dan Walsh 2.6.5-3Dan Walsh 2.6.5-2Dan Walsh 2.6.4-7Dan Walsh 2.6.4-6Dan Walsh 2.6.4-5Dan Walsh 2.6.4-2Dan Walsh 2.6.4-1Dan Walsh 2.6.3-1Dan Walsh 2.6.2-1Dan Walsh 2.6.1-4Dan Walsh 2.6.1-2Dan Walsh 2.6.1-1Dan Walsh 2.5.12-12Dan Walsh 2.5.12-11Dan Walsh 2.5.12-10Dan Walsh 2.5.12-8Dan Walsh 2.5.12-5Dan Walsh 2.5.12-4Dan Walsh 2.5.12-3Dan Walsh 2.5.12-2Dan Walsh 2.5.12-1Dan Walsh 2.5.11-8Dan Walsh 2.5.11-7Dan Walsh 2.5.11-6Dan Walsh 2.5.11-5Dan Walsh 2.5.11-4Dan Walsh 2.5.11-3Dan Walsh 2.5.11-2Dan Walsh 2.5.11-1Dan Walsh 2.5.10-2Dan Walsh 2.5.10-1Dan Walsh 2.5.9-6Dan Walsh 2.5.9-5Dan Walsh 2.5.9-4Dan Walsh 2.5.9-3Dan Walsh 2.5.9-2Dan Walsh 2.5.8-8Dan Walsh 2.5.8-7Dan Walsh 2.5.8-6Dan Walsh 2.5.8-5Dan Walsh 2.5.8-4Dan Walsh 2.5.8-3Dan Walsh 2.5.8-2Dan Walsh 2.5.8-1Dan Walsh 2.5.7-1Dan Walsh 2.5.6-1Dan Walsh 2.5.5-2Dan Walsh 2.5.5-1Dan Walsh 2.5.4-2Dan Walsh 2.5.4-1Dan Walsh 2.5.3-3Dan Walsh 2.5.3-2Dan Walsh 2.5.3-1Dan Walsh 2.5.2-6Dan Walsh 2.5.2-5Dan Walsh 2.5.2-4Dan Walsh 2.5.2-3Dan Walsh 2.5.2-2Dan Walsh 2.5.2-1Dan Walsh 2.5.1-5Dan Walsh 2.5.1-4Dan Walsh 2.5.1-2Dan Walsh 2.5.1-1Dan Walsh 2.4.6-20Dan Walsh 2.4.6-19Dan Walsh 2.4.6-18Dan Walsh 2.4.6-17Dan Walsh 2.4.6-16Dan Walsh 2.4.6-15Dan Walsh 2.4.6-14Dan Walsh 2.4.6-13Dan Walsh 2.4.6-12Dan Walsh 2.4.6-11Dan Walsh 2.4.6-10Dan Walsh 2.4.6-9Dan Walsh 2.4.6-8Dan Walsh 2.4.6-7Dan Walsh 2.4.6-6Dan Walsh 2.4.6-5Dan Walsh 2.4.6-4Dan Walsh 2.4.6-3Dan Walsh 2.4.6-1Dan Walsh 2.4.5-4Dan Walsh 2.4.5-3Dan Walsh 2.4.5-2Dan Walsh 2.4.5-1Dan Walsh 2.4.4-2Dan Walsh 2.4.4-2Dan Walsh 2.4.4-1Dan Walsh 2.4.3-13Dan Walsh 2.4.3-12Dan Walsh 2.4.3-11Dan Walsh 2.4.3-10Dan Walsh 2.4.3-9Dan Walsh 2.4.3-8Dan Walsh 2.4.3-7Dan Walsh 2.4.3-6Dan Walsh 2.4.3-5Dan Walsh 2.4.3-4Dan Walsh 2.4.3-3Dan Walsh 2.4.3-2Dan Walsh 2.4.3-1Dan Walsh 2.4.2-8Dan Walsh 2.4.2-7James Antill 2.4.2-6Dan Walsh 2.4.2-5Dan Walsh 2.4.2-4Dan Walsh 2.4.2-3Dan Walsh 2.4.2-2Dan Walsh 2.4.2-1Dan Walsh 2.4.1-5Dan Walsh 2.4.1-4Dan Walsh 2.4.1-3Dan Walsh 2.4.1-2Dan Walsh 2.4-4Dan Walsh 2.4-3Dan Walsh 2.4-2Dan Walsh 2.4-1Dan Walsh 2.3.19-4Dan Walsh 2.3.19-3Dan Walsh 2.3.19-2Dan Walsh 2.3.19-1James Antill 2.3.18-10James Antill 2.3.18-9Dan Walsh 2.3.18-8Dan Walsh 2.3.18-7Dan Walsh 2.3.18-6Dan Walsh 2.3.18-5Dan Walsh 2.3.18-4Dan Walsh 2.3.18-3Dan Walsh 2.3.18-2Dan Walsh 2.3.18-1Dan Walsh 2.3.17-2Dan Walsh 2.3.17-1Dan Walsh 2.3.16-9Dan Walsh 2.3.16-8Dan Walsh 2.3.16-7Dan Walsh 2.3.16-6Dan Walsh 2.3.16-5Dan Walsh 2.3.16-4Dan Walsh 2.3.16-2Dan Walsh 2.3.16-1Dan Walsh 2.3.15-2Dan Walsh 2.3.15-1Dan Walsh 2.3.14-8Dan Walsh 2.3.14-7Dan Walsh 2.3.14-6Dan Walsh 2.3.14-4Dan Walsh 2.3.14-3Dan Walsh 2.3.14-2Dan Walsh 2.3.14-1Dan Walsh 2.3.13-6Dan Walsh 2.3.13-5Dan Walsh 2.3.13-4Dan Walsh 2.3.13-3Dan Walsh 2.3.13-2Dan Walsh 2.3.13-1Dan Walsh 2.3.12-2Dan Walsh 2.3.12-1Dan Walsh 2.3.11-1Dan Walsh 2.3.10-7Dan Walsh 2.3.10-6Dan Walsh 2.3.10-3Dan Walsh 2.3.10-1Dan Walsh 2.3.9-6Dan Walsh 2.3.9-5Dan Walsh 2.3.9-4Dan Walsh 2.3.9-3Dan Walsh 2.3.9-2Dan Walsh 2.3.9-1Dan Walsh 2.3.8-2Dan Walsh 2.3.7-1Dan Walsh 2.3.6-4Dan Walsh 2.3.6-3Dan Walsh 2.3.6-2Dan Walsh 2.3.6-1Dan Walsh 2.3.5-1Dan Walsh 2.3.4-1Dan Walsh 2.3.3-20Dan Walsh 2.3.3-19Dan Walsh 2.3.3-18Dan Walsh 2.3.3-17Dan Walsh 2.3.3-16Dan Walsh 2.3.3-15Dan Walsh 2.3.3-14Dan Walsh 2.3.3-13Dan Walsh 2.3.3-12Dan Walsh 2.3.3-11Dan Walsh 2.3.3-10Dan Walsh 2.3.3-9Dan Walsh 2.3.3-8Dan Walsh 2.3.3-7Dan Walsh 2.3.3-6Dan Walsh 2.3.3-5Dan Walsh 2.3.3-4Dan Walsh 2.3.3-3Dan Walsh 2.3.3-2Dan Walsh 2.3.3-1Dan Walsh 2.3.2-4Dan Walsh 2.3.2-3Dan Walsh 2.3.2-2Dan Walsh 2.3.2-1Dan Walsh 2.3.1-1Dan Walsh 2.2.49-1Dan Walsh 2.2.48-1Dan Walsh 2.2.47-5Dan Walsh 2.2.47-4Dan Walsh 2.2.47-3Dan Walsh 2.2.47-1Dan Walsh 2.2.46-2Dan Walsh 2.2.46-1Dan Walsh 2.2.45-3Dan Walsh 2.2.45-2Dan Walsh 2.2.45-1Dan Walsh 2.2.44-1Dan Walsh 2.2.43-4Dan Walsh 2.2.43-3Dan Walsh 2.2.43-2Dan Walsh 2.2.43-1Dan Walsh 2.2.42-4Dan Walsh 2.2.42-3Dan Walsh 2.2.42-2Dan Walsh 2.2.42-1Dan Walsh 2.2.41-1Dan Walsh 2.2.40-2Dan Walsh 2.2.40-1Dan Walsh 2.2.39-2Dan Walsh 2.2.39-1Dan Walsh 2.2.38-6Dan Walsh 2.2.38-5Dan Walsh 2.2.38-4Dan Walsh 2.2.38-3Dan Walsh 2.2.38-2Dan Walsh 2.2.38-1Dan Walsh 2.2.37-1Dan Walsh 2.2.36-2Dan Walsh 2.2.36-1James Antill 2.2.35-2Dan Walsh 2.2.35-1Dan Walsh 2.2.34-3Dan Walsh 2.2.34-2Dan Walsh 2.2.34-1Dan Walsh 2.2.33-1Dan Walsh 2.2.32-2Dan Walsh 2.2.32-1Dan Walsh 2.2.31-1Dan Walsh 2.2.30-2Dan Walsh 2.2.30-1Dan Walsh 2.2.29-6Russell Coker 2.2.29-5Dan Walsh 2.2.29-4Dan Walsh 2.2.29-3Dan Walsh 2.2.29-2Dan Walsh 2.2.29-1Dan Walsh 2.2.28-3Dan Walsh 2.2.28-2Dan Walsh 2.2.28-1Dan Walsh 2.2.27-1Dan Walsh 2.2.25-3Dan Walsh 2.2.25-2Dan Walsh 2.2.24-1Dan Walsh 2.2.23-19Dan Walsh 2.2.23-18Dan Walsh 2.2.23-17Karsten Hopp 2.2.23-16Dan Walsh 2.2.23-15Dan Walsh 2.2.23-14Dan Walsh 2.2.23-13Dan Walsh 2.2.23-12Jeremy Katz - 2.2.23-11Jeremy Katz - 2.2.23-10Dan Walsh 2.2.23-9Dan Walsh 2.2.23-8Dan Walsh 2.2.23-7Dan Walsh 2.2.23-5Dan Walsh 2.2.23-4Dan Walsh 2.2.23-3Dan Walsh 2.2.23-2Dan Walsh 2.2.23-1Dan Walsh 2.2.22-2Dan Walsh 2.2.22-1Dan Walsh 2.2.21-9Dan Walsh 2.2.21-8Dan Walsh 2.2.21-7Dan Walsh 2.2.21-6Dan Walsh 2.2.21-5Dan Walsh 2.2.21-4Dan Walsh 2.2.21-3Dan Walsh 2.2.21-2Dan Walsh 2.2.21-1Dan Walsh 2.2.20-1Dan Walsh 2.2.19-2Dan Walsh 2.2.19-1Dan Walsh 2.2.18-2Dan Walsh 2.2.18-1Dan Walsh 2.2.17-2Dan Walsh 2.2.16-1Dan Walsh 2.2.15-4Dan Walsh 2.2.15-3Dan Walsh 2.2.15-1Dan Walsh 2.2.14-2Dan Walsh 2.2.14-1Dan Walsh 2.2.13-1Dan Walsh 2.2.12-1Dan Walsh 2.2.11-2Dan Walsh 2.2.11-1Dan Walsh 2.2.10-1Dan Walsh 2.2.9-2Dan Walsh 2.2.9-1Dan Walsh 2.2.8-2Dan Walsh 2.2.7-1Dan Walsh 2.2.6-3Dan Walsh 2.2.6-2Dan Walsh 2.2.6-1Dan Walsh 2.2.5-1Dan Walsh 2.2.4-1Dan Walsh 2.2.3-1Dan Walsh 2.2.2-1Dan Walsh 2.2.1-1Dan Walsh 2.1.13-1Dan Walsh 2.1.12-3Dan Walsh 2.1.11-1Dan Walsh 2.1.10-1Jeremy Katz - 2.1.9-2Dan Walsh 2.1.9-1Dan Walsh 2.1.8-3Dan Walsh 2.1.8-2Dan Walsh 2.1.8-1Dan Walsh 2.1.7-4Dan Walsh 2.1.7-3Dan Walsh 2.1.7-2Dan Walsh 2.1.7-1Dan Walsh 2.1.6-24Dan Walsh 2.1.6-23Dan Walsh 2.1.6-22Dan Walsh 2.1.6-21Dan Walsh 2.1.6-20Dan Walsh 2.1.6-18Dan Walsh 2.1.6-17Dan Walsh 2.1.6-16Dan Walsh 2.1.6-15Dan Walsh 2.1.6-14Dan Walsh 2.1.6-13Dan Walsh 2.1.6-11Dan Walsh 2.1.6-10Dan Walsh 2.1.6-9Dan Walsh 2.1.6-8Dan Walsh 2.1.6-5Dan Walsh 2.1.6-4Dan Walsh 2.1.6-3Dan Walsh 2.1.6-2Dan Walsh 2.1.6-1Dan Walsh 2.1.4-2Dan Walsh 2.1.4-1Dan Walsh 2.1.3-1Jeremy Katz - 2.1.2-3Dan Walsh 2.1.2-2Dan Walsh 2.1.2-1Dan Walsh 2.1.1-3Dan Walsh 2.1.1-2Dan Walsh 2.1.1-1Dan Walsh 2.1.0-3Dan Walsh 2.1.0-2.Dan Walsh 2.1.0-1.Dan Walsh 2.0.11-2.Dan Walsh 2.0.11-1.Dan Walsh 2.0.9-1.Dan Walsh 2.0.8-1.Dan Walsh 2.0.7-3Dan Walsh 2.0.7-2Dan Walsh 2.0.6-2Dan Walsh 2.0.5-4Dan Walsh 2.0.5-1Dan Walsh 2.0.4-1Dan Walsh 2.0.2-2Dan Walsh 2.0.2-1Dan Walsh 2.0.1-2Dan Walsh 2.0.1-1- Dontaudit tmpreaper_t getting attributes from sysctl_type files Resolves: rhbz#1765063- Allow tmpreaper_t domain to getattr files labeled as mtrr_device_t Resolves: rhbz#1765063- Allow tmpwatch process labeled as tmpreaper_t domain to execute fuser command Resolves: rhbz#1765063- Update tmpreaper_t policy due to fuser command Resolves: rhbz#1765063- Allow tmpreaper_t domain to read all domains state Resolves: rhbz#1765063- Update sudo_role_template() to allow caller domain to read syslog pid files Resolves: rhbz#1651253- Allow sbd_t domain to check presence of processes labeled as cluster_t Resolves: rhbz#1753623- Allow ganesha_t domain to read system network state and connect to cyphesis_port_t Resolves: rhbz#1653857 - Label /var/log/collectd.log as collectd_log_t - Update gnome_role_template() interface to make working sysadm_u SELinux able to login to X sessions Resolves: rhbz#1688729 - Update collectd policy to allow daemon create /var/log/collectd with collectd_log_t label Resolves: rhbz#1658319 - Update sbd policy to allow manage cgroups Resolves: rhbz#1715136 - Allow sudo userdomain to run rpm related commands - Update rpm_run() interface to avoid duplicate role transition in sudo_role_template Resolves: rhbz#1651253- Update gnome_role_template() interface to make working sysadm_u SELinux able to login to X sessions Resolves: rhbz#1688729 - Update collectd policy to allow daemon create /var/log/collectd with collectd_log_t label Resolves: rhbz#1658319- Update sbd policy to allow manage cgroups Resolves: rhbz#1715136- Allow cupsd_t domain to manage cupsd_tmp_t temp link files Resolves: rhbz#1719754 - Allow svnserve_t domain to read /dev/random Resolves: rhbz#1727458 - Update sudodomains to make working confined users run sudo/su Resolves: rhbz#1699391- Allow virtlockd process read virtlockd.conf file Resolves: rhbz#1714896- Rebuild selinux-policy build because of broken RHEL-7.8 buildrood during build of selinux-policy-3.13.1-253 Resolves: rhbz#1727341- Label user cron spool file with user_cron_spool_t Resolves: rhbz#1727341 - Allow svnserve_t domain to read system state Resolves: rhbz#1727458 - Update svnserve_t policy to make working svnserve hooks Resolves: rhbz#1727458 - Update gnome_role_template() template to allow sysadm_t confined user to login to xsession Resolves: rhbz#1727379 - Update gnome_role_template() to allow _gkeyringd_t domains to chat with systemd_logind over dbus Resolves: rhbz#1727379 - Allow userdomain gkeyringd domain to create stream socket with userdomain Resolves: rhbz#1727379 - Allow cupsd_t to create lnk_files in /tmp. BZ(1401634) Resolves: rhbz#1719754 - Allow mysqld_t domain to manage cluster pid files Resolves: rhbz#1715805 - Relabel /usr/sbin/virtlockd from virt_exec_t to virtlogd_exec_t. Resolves: rhbz#1714896 - Allow systemd_hostnamed_t domain to dbus chat with sosreport_t domain Resolves: rhbz#1705599 - Allow rhsmcertd_t domain to send signull to all domains Resolves: rhbz#1701338 - Allow cloud_init_t domain to ccreate iptables files with correct SELinux label Resolves: rhbz#1699249 - Allow dnsmasq_t domain to manage NetworkManager_var_lib_t files - Allow certmonger to geattr of filesystems BZ(1578755) - Update tomcat_can_network_connect_db boolean to allow tomcat domains also connect to redis ports Resolves: rhbz#1687497 - Allow lograte_t domain to manage collect_rw_content files and dirs Resolves: rhbz#1658319 - Add interface collectd_manage_rw_content() - Allow glusterd_t domain to setpgid Resolves: rhbz#1653857 - Allow sysadm_sudo_t to use SELinux tooling. Resolves: rhbz#1727341 - Allow sysadm_t domain to create netlink selinux sockets Resolves: rhbz#1727379 - Allow systemd_resolved_t to dbusd chat with NetworkManager_t Resolves: rhbz#1723877 - Allow crack_t domain read /et/passwd files Resolves: rhbz#1721093 - Allow sysadm_t domain to dbus chat with rtkit daemon Resolves: rhbz#1720546 - Allow x_userdomains to nnp domain transition to thumb_t domain Resolves: rhbz#1712603 - Dontaudit writing to user home dirs by gnome-keyring-daemon Resolves: rhbz#1703959 - Update logging_send_audit_msgs(sudodomain() to control TTY auditing for netlink socket for audit service Resolves: rhbz#1699391 - Allow systemd_tmpfiles_t domain to relabel from usermodehelper_t files Resolves: rhbz#1699063 - Add interface kernel_relabelfrom_usermodehelper()- Allow sbd_t domain to use nsswitch Resolves: rhbz#1728593- Allow ganesha_t domain to connect to tcp portmap_port_t Resolves: rhbz#1715088- Allow redis to creating tmp files with own label Resolves: rhbz#1646765- Allow ctdb_t domain to manage samba_var_t files/links/sockets and dirs Resolves: rhbz#1716400- Allow nrpe_t domain to read process state of systemd_logind_t - Add interface systemd_logind_read_state() Resolves: rhbz#1653309- Label /etc/rhsm as rhsmcertd_config_t Resolves: rhbz#1703573- Fix typo in gpg SELinux module - Update gpg policy to make ti working with confined users Resolves: rhbz#1535109 - Alow nrpe_t to send signull to sssd domain when nagios_run_sudo boolean is turned on Resolves: rhbz#1653309 - Allow nrpe_t domain to be dbus cliennt Resolves: rhbz#1653309 - Add interface sssd_signull() Resolves: rhbz#1653309 - Update userdomains to allow confined users to create gpg keys Resolves: rhbz#1535109- Allow ngaios to use chown capability Resolves: rhbz#1653309 - Dontaudit gpg_domain to create netlink_audit sockets Resolves: rhbz#1535109 - Update fs_rw_cephfs_files() interface to allow also caller domain to read/write cephpfs_t lnk files Resolves: rhbz#1558836 - Update domain_can_mmap_files() boolean to allow also mmap lnk files- Allow rhsmcertd_t domain to read yum.log file labeled as rpm_log_t Resolves: rhbz#1695342- Update Nagios policy when sudo is used Resolves: rhbz#1653309- Allow modemmanager_t domain to write to raw_ip file labeled as sysfs_t Resolves: rhbz#1676810- Make shell_exec_t type as entrypoint for vmtools_unconfined_t. Resolves: rhbz#1656814- Update vmtools policy Resolves: rhbz#1656814 Allow domain transition from vmtools_t to vmtools_unconfined_t when shell_exec_t is entrypoint. - Allow virt_qemu_ga_t domain to read udev_var_run_t files Resolves: rhbz#1663092 - Update nagios_run_sudo boolean with few allow rules related to accessing sssd Resolves: rhbz#1653309 - Allow nfsd_t to read nvme block devices BZ(1562554) Resolves: rhbz#1655493 - Allow tangd_t domain to bind on tcp ports labeled as tangd_port_t Resolves: rhbz#1650909 - Allow all domains to send dbus msgs to vmtools_unconfined_t processes Resolves: rhbz#1656814 - Label /dev/pkey as crypt_device_t Resolves: rhbz#1623068 - Allow sudodomains to write to systemd_logind_sessions_t pipes. Resolves: rhbz#1687452 - Allow all user domains to read realmd_var_lib_t files and dirs to check if IPA is configured on the system Resolves: rhbz#1667962 - Fixes: xenconsole does not start Resolves: rhbz#1601525 - Label /usr/lib64/libcuda.so.XX.XX library as textrel_shlib_t. Resolves: rhbz#1636197 - Create tangd_port_t with default label tcp/7406 Resolves: rhbz#1650909- named wants to access /proc/sys/net/ipv4/ip_local_port_range to get ehphemeral range. Resolves: rhbz#1683754 - Allow sbd_t domain to bypass permission checks for sending signals Resolves: rhbz#1671132 - Allow sbd_t domain read/write all sysctls Resolves: rhbz#1671132 - Allow kpatch_t domain to communicate with policykit_t domsin over dbus Resolves: rhbz#1602435 - Allow boltd_t to stream connect to sytem dbus Resolves: rhbz#1589086 - Update userdom_admin_user_template() and init_prog_run_bpf() interfaces to make working bpftool for confined admin Resolves: rhbz#1626115 - Update unconfined_dbus_send() interface to allow both direction communication over dbus with unconfined process. Resolves: rhbz#1589086- Allow sbd_t domain read/write all sysctls Resolves: rhbz#1671132 - Allow kpatch_t domain to communicate with policykit_t domsin over dbus Resolves: rhbz#1602435 - Allow boltd_t to stream connect to sytem dbus Resolves: rhbz#1589086 - Update unconfined_dbus_send() interface to allow both direction communication over dbus with unconfined process. Resolves: rhbz#1589086- Update redis_enable_notify() boolean to fix sending e-mail by redis when this boolean is turned on Resolves: rhbz#1646765- Allow virtd_lxc_t domains use BPF Resolves: rhbz#1626115 - F29 NetworkManager implements a new code for IPv4 address conflict detection (RFC 5227) based on n-acd [1], which uses eBPF to process ARP packets from the network. Resolves: rhbz#1626115 - Allow unconfined user all perms under bpf class BZ(1565738 Resolves: rhbz#1626115 - Allow unconfined and sysadm users to use bpftool BZ(1591440) Resolves: rhbz#1626115 - Allow systemd to manage bpf dirs/files Resolves: rhbz#1626115 - Create new type bpf_t and label /sys/fs/bpf with this type Resolves:rhbz#1626115 - Add new interface init_prog_run_bpf() Resolves:rhbz#1626115 - add definition of bpf class and systemd perms Resolves: rhbz#1626115- Update policy with multiple allow rules to make working installing VM in MLS policy Resolves: rhbz#1558121 - Allow virt domain to use interited virtlogd domains fifo_file Resolves: rhbz#1558121 - Allow chonyc_t domain to rw userdomain pipes Resolves: rhbz#1618757 - Add file contexts in ganesha.fc file to label logging ganesha files properly. Resolves: rhbz#1628247- Allow sandbox_xserver_t domain write to user_tmp_t files Resolves: rhbz#1646521 - Allow virt_qemu_ga_t domain to read network state Resolves: rhbz#1630347 - Bolt added d-bus API for force-powering the thunderbolt controller, so system-dbusd needs acces to boltd pipes Resolves: rhbz#1589086 - Add boltd policy Resolves: rhbz#1589086 - Allow virt domains to read/write cephfs filesystems Resolves: rhbz#1558836 - Allow gpg_t to create own tmpfs dirs and sockets Resolves: rhbz#1535109 - Allow gpg_agent_t to send msgs to syslog/journal Resolves: rhbz#1535109 - Allow virtual machine to write to fixed_disk_device_t Resolves: rhbz#1499208 - Update kdump_manage_crash() interface to allow also manage dirs by caller domain Resolves: rhbz#1491585 - Add kpatch policy Resolves: rhbz#1602435 - Label /usr/bin/mysqld_safe_helper as mysqld_exec_t instead of bin_t Resolves: rhbz#1623942 - Allow svnserve_t domain to create in /tmp svn_0 file labeled as krb5_host_rcache_t Resolves: rhbz#1475271 - Allow systemd to mount boltd_var_run_t dirs Resolves: rhbz#1589086 - Allow systemd to mounont boltd lib dirs Resolves: rhbz#1589086 - Allow sysadm_t,staff_t and unconfined_t domain to execute kpatch as kpatch_t domain Resolves: rhbz#1602435 - Allow passwd_t domain chroot - Add miscfiles_filetrans_named_content_letsencrypt() to optional_block - Allow unconfined domains to create letsencrypt directory in /var/lib labeled as cert_t Resolves: rhbz#1447278 - Allow staff_t user to systemctl iptables units. Resolves: rhbz#1360470- Label /usr/bin/mysqld_safe_helper as mysqld_exec_t instead of bin_t Resolves: rhbz#1623942 - Allow svnserve_t domain to create in /tmp svn_0 file labeled as krb5_host_rcache_t Resolves: rhbz#1475271 - Allow passwd_t domain chroot - Add miscfiles_filetrans_named_content_letsencrypt() to optional_block - Allow unconfined domains to create letsencrypt directory in /var/lib labeled as cert_t Resolves: rhbz#1447278 - Allow staff_t user to systemctl iptables units. Resolves: rhbz#1360470- Allow gssd_t domain to manage kernel keyrings of every domain. Resolves: rhbz#1487350 - Add new interface domain_manage_all_domains_keyrings() Resolves: rhbz#1487350- Allow gssd_t domain to read/write kernel keyrings of every domain. Resolves: rhbz#1487350 - Add interface domain_rw_all_domains_keyrings() Resolves: rhbz#1487350- Update snapperd policy to allow snapperd manage all non security dirs. Resolves: rhbz#1619306-Allow nova_t domain to use pam Resolves: rhbz:#1640528 - sysstat: grant sysstat_t the search_dir_perms set Resolves: rhbz#1637416 - Allow cinder_volume_t domain to dbus chat with systemd_logind_t domain Resolves: rhbz#1630318 - Allow staff_t userdomain and confined_admindomain attribute to allow use generic ptys because of new sudo feature 'io logging' Resolves: rhbz#1564470 - Make ganesha policy active again Resolves: rhbz#1511489- Remove disabling ganesha module in pre install phase of installation new selinux-policy package where ganesha is again standalone module Resolves: rhbz#1638257- Allow staff_t userdomain and confined_admindomain attribute to allow use generic ptys because of new sudo feature 'io logging' Resolves: rhbz#1638427- Run ganesha as ganesha_t domain again, revert changes where ganesha is running as nfsd_t Resolves: rhbz#1638257- Fix missing patch in spec file Resolves: rhbz#1635704- Allow cinder_volume_t domain to dbus chat with systemd_logind_t domain Resolves: rhbz#1635704- Allow neutron domain to read/write /var/run/utmp Resolves: rhbz#1630318- Allow tomcat_domain to read /dev/random Resolves: rhbz#1631666 - Allow neutron_t domain to use pam Resolves: rhbz#1630318- Add interface apache_read_tmp_dirs() - Allow dirsrvadmin_script_t domain to list httpd_tmp_t dirs Resolves: rhbz#1622602- Allow tomcat servers to manage usr_t files Resolves: rhbz#1625678 - Dontaudit tomcat serves to append to /dev/random device Resolves: rhbz#1625678 - Allow sys_nice capability to mysqld_t domain - Allow dirsrvadmin_script_t domain to read httpd tmp files Resolves: rhbz#1622602 - Allow syslogd_t domain to manage cert_t files Resolves: rhbz#1615995- Allow sbd_t domain to getattr of all char files in /dev and read sysfs_t files and dirs Resolves: rhbz#1627114 - Expand virt_read_lib_files() interface to allow list dirs with label virt_var_lib_t Resolves: rhbz#1567753- Allow tomcat Tomcat to delete a temporary file used when compiling class files for JSPs. Resolves: rhbz#1625678 - Allow chronyd_t domain to read virt_var_lib_t files - Allow virtual machines to use dri devices. This allows use openCL GPU calculations. BZ(1337333) Resolves: rhbz#1625613 - Allow tomcat services create link file in /tmp Resolves: rhbz#1624289 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322- Make working SELinux sandbox with Wayland. Resolves: rhbz#1624308 - Allow svirt_t domain to mmap svirt_image_t block files Resolves: rhbz#1624224 - Add caps dac_read_search and dav_override to pesign_t domain - Allow iscsid_t domain to mmap userio chr files Resolves: rhbz#1623589 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322 - Add execute_no_trans permission to mmap_exec_file_perms pattern - Allow sudodomain to search caller domain proc info - Allow xdm_t domain to mmap and read cert_t files - Replace optional policy blocks to make dbus interfaces effective Resolves: rhbz#1624414 - Add interface dev_map_userio_dev()- Allow readhead_t domain to mmap own pid files Resolves: rhbz#1614169- Allow ovs-vswitchd labeled as openvswitch_t domain communicate with qemu-kvm via UNIX stream socket - Allow httpd_t domain to mmap tmp files Resolves: rhbz#1608355 - Update dirsrv_read_share() interface to allow caller domain to mmap dirsrv_share_t files - Update dirsrvadmin_script_t policy to allow read httpd_tmp_t symlinks - Label /dev/tpmrm[0-9]* as tpm_device_t - Allow semanage_t domain mmap usr_t files Resolves: rhbz#1622607 - Update dev_filetrans_all_named_dev() to allow create event22-30 character files with label event_device_t- Allow nagios_script_t domain to mmap nagios_log_t files Resolves: rhbz#1620013 - Allow nagios_script_t domain to mmap nagios_spool_t files Resolves: rhbz#1620013 - Update userdom_security_admin() and userdom_security_admin_template() to allow use auditctl Resolves: rhbz#1622197 - Update selinux_validate_context() interface to allow caller domain to mmap security_t files Resolves: rhbz#1622061- Allow virtd_t domain to create netlink_socket - Allow rpm_t domain to write to audit - Allow rpm domain to mmap rpm_var_lib_t files Resolves: rhbz#1619785 - Allow nagios_script_t domain to mmap nagios_etc_t files Resolves: rhbz#1620013 - Update nscd_socket_use() to allow caller domain to stream connect to nscd_t Resolves: rhbz#1460715 - Allow secadm_t domain to mmap audit config and log files - Allow insmod_t domain to read iptables pid files - Allow systemd to mounton /etc Resolves: rhbz#1619785- Allow kdumpctl_t domain to getattr fixed disk device in mls Resolves: rhbz#1615342 - Allow initrc_domain to mmap all binaries labeled as systemprocess_entry Resolves: rhbz#1615342- Allow virtlogd to execute itself Resolves: rhbz#1598392- Allow kdumpctl_t domain to manage kdumpctl_tmp_t fifo files Resolves: rhbz#1615342 - Allow kdumpctl to write to files on all levels Resolves: rhbz#1615342 - Fix typo in radius policy Resolves: rhbz#1619197 - Allow httpd_t domain to mmap httpd_config_t files Resolves: rhbz#1615894 - Add interface dbus_acquire_svc_system_dbusd() - Allow sanlock_t domain to connectto to unix_stream_socket Resolves: rhbz#1614965 - Update nfsd_t policy because of ganesha features Resolves: rhbz#1511489 - Allow conman to getattr devpts_t Resolves: rhbz#1377915 - Allow tomcat_domain to connect to smtp ports Resolves: rhbz#1253502 - Allow tomcat_t domain to mmap tomcat_var_lib_t files Resolves: rhbz#1618519 - Allow slapd_t domain to mmap slapd_var_run_t files Resolves: rhbz#1615319 - Allow nagios_t domain to mmap nagios_log_t files Resolves: rhbz#1618675 - Allow nagios to exec itself and mmap nagios spool files BZ(1559683) - Allow nagios to mmap nagios config files BZ(1559683) - Allow kpropd_t domain to mmap krb5kdc_principal_t files Resolves: rhbz#1619252 - Update syslogd policy to make working elasticsearch - Label tcp and udp ports 9200 as wap_wsp_port - Allow few domains to rw inherited kdumpctl tmp pipes Resolves: rhbz#1615342- Allow systemd_dbusd_t domain read/write to nvme devices Resolves: rhbz#1614236 - Allow mysqld_safe_t do execute itself - Allow smbd_t domain to chat via dbus with avahi daemon Resolves: rhbz#1600157 - cupsd_t domain will create /etc/cupsd/ppd as cupsd_etc_rw_t Resolves: rhbz#1452595 - Allow amanda_t domain to getattr on tmpfs filesystem BZ(1527645) Resolves: rhbz#1452444 - Update screen_role_template to allow caller domain to have screen_exec_t as entrypoint do new domain Resolves: rhbz#1384769 - Add alias httpd__script_t to _script_t to make sepolicy generate working Resolves: rhbz#1271324 - Allow kprop_t domain to read network state Resolves: rhbz#1600705 - Allow sysadm_t domain to accept socket Resolves: rhbz#1557299 - Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow kprop_t domain to read network state Resolves: rhbz#1600705- Allow kpropd domain to exec itself Resolves: rhbz#1600705 - Allow ipmievd_t to mmap kernel modules BZ(1552535) - Allow hsqldb_t domain to mmap own temp files Resolves: rhbz#1612143 - Allow hsqldb_t domain to read cgroup files Resolves: rhbz#1612143 - Allow rngd_t domain to read generic certs Resolves: rhbz#1612456 - Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow virtlogd_t domain to chat via dbus with systemd_logind Resolves: rhbz#1593740- Allow sblim_sfcbd_t domain to mmap own tmpfs files Resolves: rhbz#1609384 - Update logging_manage_all_logs() interface to allow caller domain map all logfiles Resolves: rhbz#1592028- Dontaudit oracleasm_t domain to request sys_admin capability - Allow iscsid_t domain to load kernel module Resolves: rhbz#1589295 - Update rhcs contexts to reflects the latest fenced changes - Allow httpd_t domain to rw user_tmp_t files Resolves: rhbz#1608355 - /usr/libexec/udisks2/udisksd should be labeled as devicekit_disk_exec_t Resolves: rhbz#1521063 - Allow tangd_t dac_read_search Resolves: rhbz#1607810 - Allow glusterd_t domain to mmap user_tmp_t files - Allow mongodb_t domain to mmap own var_lib_t files Resolves: rhbz#1607729 - Allow iscsid_t domain to mmap sysfs_t files Resolves: rhbz#1602508 - Allow tomcat_domain to search cgroup dirs Resolves: rhbz#1600188 - Allow httpd_t domain to mmap own cache files Resolves: rhbz#1603505 - Allow cupsd_t domain to mmap cupsd_etc_t files Resolves: rhbz#1599694 - Allow kadmind_t domain to mmap krb5kdc_principal_t Resolves: rhbz#1601004 - Allow virtlogd_t domain to read virt_etc_t link files Resolves: rhbz#1598593 - Allow dirsrv_t domain to read crack db Resolves: rhbz#1599726 - Dontaudit pegasus_t to require sys_admin capability Resolves: rhbz#1374570 - Allow mysqld_t domain to exec mysqld_exec_t binary files - Allow abrt_t odmain to read rhsmcertd lib files Resolves: rhbz#1601389 - Allow winbind_t domain to request kernel module loads Resolves: rhbz#1599236 - Allow gpsd_t domain to getsession and mmap own tmpfs files Resolves: rhbz#1598388 - Allow smbd_t send to nmbd_t via dgram sockets BZ(1563791) Resolves: rhbz#1600157 - Allow tomcat_domain to read cgroup_t files Resolves: rhbz#1601151 - Allow varnishlog_t domain to mmap varnishd_var_lib_t files Resolves: rhbz#1600704 - Allow dovecot_auth_t domain to manage also dovecot_var_run_t fifo files. BZ(1320415) Resolves: rhbz#1600692 - Fix ntp SELinux module - Allow innd_t domain to mmap news_spool_t files Resolves: rhbz#1600591 - Allow haproxy daemon to reexec itself. BZ(1447800) Resolves: rhbz#1600578 - Label HOME_DIR/mozilla.pdf file as mozilla_home_t instead of user_home_t Resolves: rhbz#1559859 - Allow pkcs_slotd_t domain to mmap own tmpfs files Resolves: rhbz#1600434 - Allow fenced_t domain to reboot Resolves: rhbz#1293384 - Allow bluetooth_t domain listen on bluetooth sockets BZ(1549247) Resolves: rhbz#1557299 - Allow lircd to use nsswitch. BZ(1401375) - Allow targetd_t domain mmap lvm config files Resolves: rhbz#1546671 - Allow amanda_t domain to read network system state Resolves: rhbz#1452444 - Allow abrt_t domain to read rhsmcertd logs Resolves: rhbz#1492059 - Allow application_domain_type also mmap inherited user temp files BZ(1552765) Resolves: rhbz#1608421 - Allow ipsec_t domain to read l2tpd pid files Resolves: rhbz#1607994 - Allow systemd_tmpfiles_t do mmap system db files - Improve domain_transition_pattern to allow mmap entrypoint bin file. Resolves: rhbz#1460322 - Allow nsswitch_domain to mmap passwd_file_t files BZ(1518655) Resolves: rhbz#1600528 - Dontaudit syslogd to watching top llevel dirs when imfile module is enabled Resolves: rhbz#1601928 - Allow ipsec_t can exec ipsec_exec_t Resolves: rhbz#1600684 - Allow netutils_t domain to mmap usmmon device Resolves: rhbz#1600586 - Allow netlabel_mgmt_t domain to read sssd public files, stream connect to sssd_t BZ(1483655) - Allow userdomain sudo domains to use generic ptys Resolves: rhbz#1564470 - Allow traceroute to create icmp packets Resolves: rhbz#1548350 - Allow systemd domain to mmap lvm config files BZ(1594584) - Add new interface lvm_map_config - refpolicy: Update for kernel sctp support Resolves: rhbz#1597111 Add additional entries to support the kernel SCTP implementation introduced in kernel 4.16- Update oddjob_domtrans_mkhomedir() interface to allow caller domain also mmap oddjob_mkhomedir_exec_t files Resolves: rhbz#1596306 - Update rhcs_rw_cluster_tmpfs() interface to allow caller domain to mmap cluster_tmpfs_t files Resolves: rhbz#1589257 - Allow radiusd_t domain to read network sysctls Resolves: rhbz#1516233 - Allow chronyc_t domain to use nscd shm Resolves: rhbz#1596563 - Label /var/lib/tomcats dir as tomcat_var_lib_t Resolves: rhbz#1596367 - Allow lsmd_t domain to mmap lsmd_plugin_exec_t files Resolves: rhbz#bea0c8174 - Label /usr/sbin/rhn_check-[0-9]+.[0-9]+ as rpm_exec_t Resolves: rhbz#1596509 - Update seutil_exec_loadpolicy() interface to allow caller domain to mmap load_policy_exec_t files Resolves: rhbz#1596072 - Allow xdm_t to read systemd hwdb Resolves: rhbz#1596720 - Allow dhcpc_t domain to mmap files labeled as ping_exec_t Resolves: rhbz#1596065- Allow tangd_t domain to create tcp sockets Resolves: rhbz#1595775 - Update postfix policy to allow postfix_master_t domain to mmap all postfix* binaries Resolves: rhbz#1595328 - Allow amanda_t domain to have setgid capability Resolves: rhbz#1452444 - Update usermanage_domtrans_useradd() to allow caller domain to mmap useradd_exec_t files Resolves: rhbz#1595667- Allow abrt_watch_log_t domain to mmap binaries with label abrt_dump_oops_exec_t Resolves: rhbz#1591191 - Update cups_filetrans_named_content() to allow caller domain create ppd directory with cupsd_etc_rw_t label Resolves: rhbz#1452595 - Allow abrt_t domain to write to rhsmcertd pid files Resolves: rhbz#1492059 - Allow pegasus_t domain to eexec lvm binaries and allow read/write access to lvm control Resolves: rhbz#1463470 - Add vhostmd_t domain to read/write to svirt images Resolves: rhbz#1465276 - Dontaudit action when abrt-hook-ccpp is writing to nscd sockets Resolves: rhbz#1460715 - Update openvswitch policy Resolves: rhbz#1594729 - Update kdump_manage_kdumpctl_tmp_files() interface to allow caller domain also mmap kdumpctl_tmp_t files Resolves: rhbz#1583084 - Allow sssd_t and slpad_t domains to mmap generic certs Resolves: rhbz#1592016 Resolves: rhbz#1592019 - Allow oddjob_t domain to mmap binary files as oddjob_mkhomedir_exec_t files Resolves: rhbz#1592022 - Update dbus_system_domain() interface to allow system_dbusd_t domain to mmap binary file from second parameter Resolves: rhbz#1583080 - Allow chronyc_t domain use inherited user ttys Resolves: rhbz#1593267 - Allow stapserver_t domain to mmap own tmp files Resolves: rhbz#1593122 - Allow sssd_t domain to mmap files labeled as sssd_selinux_manager_exec_t Resolves: rhbz#1592026 - Update policy for ypserv_t domain Resolves: rhbz#1592032 - Allow abrt_dump_oops_t domain to mmap all non security files Resolves: rhbz#1593728 - Allow svirt_t domain mmap svirt_image_t files Resolves: rhbz#1592688 - Allow virtlogd_t domain to write inhibit systemd pipes. Resolves: rhbz#1593740 - Allow sysadm_t and staff_t domains to use sudo io logging Resolves: rhbz#1564470 - Allow sysadm_t domain create sctp sockets Resolves: rhbz#1571591 - Update mount_domtrans() interface to allow caller domain mmap mount_exec_t Resolves: rhbz#1592025 - Allow dhcpc_t to mmap all binaries with label hostname_exec_t, ifconfig_exec_t and netutils_exec_t Resolves: rhbz#1594661- Fix typo in logwatch interface file - Allow spamd_t to manage logwatch_cache_t files/dirs - Allow dnsmasw_t domain to create own tmp files and manage mnt files - Allow fail2ban_client_t to inherit rlimit information from parent process Resolves: rhbz#1513100 - Allow nscd_t to read kernel sysctls Resolves: rhbz#1512852 - Label /var/log/conman.d as conman_log_t Resolves: rhbz#1538363 - Add dac_override capability to tor_t domain Resolves: rhbz#1540711 - Allow certmonger_t to readwrite to user_tmp_t dirs Resolves: rhbz#1543382 - Allow abrt_upload_watch_t domain to read general certs Resolves: rhbz#1545098 - Update postfix_domtrans_master() interface to allow caller domain also mmap postfix_master_exec_t binary Resolves: rhbz#1583087 - Allow postfix_domain to mmap postfix_qmgr_exec_t binaries Resolves: rhbz#1583088 - Allow postfix_domain to mmap postfix_pickup_exec_t binaries Resolves: rhbz#1583091 - Allow chornyd_t read phc2sys_t shared memory Resolves: rhbz#1578883 - Allow virt_qemu_ga_t read utmp Resolves: rhbz#1571202 - Add several allow rules for pesign policy: Resolves: rhbz#1468744 - Allow pesign domain to read /dev/random - Allow pesign domain to create netlink_kobject_uevent_t sockets - Allow pesign domain create own tmp files - Add setgid and setuid capabilities to mysqlfd_safe_t domain Resolves: rhbz#1474440 - Add tomcat_can_network_connect_db boolean Resolves: rhbz#1477948 - Update virt_use_sanlock() boolean to read sanlock state Resolves: rhbz#1448799 - Add sanlock_read_state() interface - Allow postfix_cleanup_t domain to stream connect to all milter sockets BZ(1436026) Resolves: rhbz#1563423 - Update abrt_domtrans and abrt_exec() interfaces to allow caller domain to mmap binary file Resolves:rhbz#1583080 - Update nscd_domtrans and nscd_exec interfaces to allow caller domain also mmap nscd binaries Resolves: rhbz#1583086 - Update snapperd_domtrans() interface to allow caller domain to mmap snapperd_exec_t file Resolves: rhbz#1583802 - Allow zoneminder_t to getattr of fs_t Resolves: rhbz#1585328 - Fix denials during ipa-server-install process on F27+ Resolves: rhbz#1586029 - Allow ipa_dnskey_t to exec ipa_dnskey_exec_t files Resolves: rhbz#1586033 - Allow rhsmcertd_t domain to send signull to postgresql_t domain Resolves: rhbz#1588119 - Allow policykit_t domain to dbus chat with dhcpc_t Resolves: rhbz#1364513 - Adding new boolean keepalived_connect_any() Resolves: rhbz#1443473 - Allow amanda to create own amanda_tmpfs_t files Resolves: rhbz#1452444 - Add amanda_tmpfs_t label. BZ(1243752) - Allow gdomap_t domain to connect to qdomap_port_t Resolves: rhbz#1551944 - Fix typos in sge - Fix typo in openvswitch policy - /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow sshd_keygen_t to execute plymouthd Resolves: rhbz#1583531 - Update seutil_domtrans_setfiles() interface to allow caller domain to do mmap on setfiles_exec_t binary Resolves: rhbz#1583090 - Allow systemd_networkd_t create and relabel tun sockets Resolves: rhbz#1583830 - Allow map audisp_exec_t files fordomains executing this binary Resolves: rhbz#1586042 - Add new interface postgresql_signull() - Add fs_read_xenfs_files() interface.- /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow dac override capability to mandb_t domain BZ(1529399) Resolves: rhbz#1423361 - Allow inetd_child process to chat via dbus with abrt Resolves: rhbz#1428805 - Allow zabbix_agent_t domain to connect to redis_port_t Resolves: rhbz#1418860 - Allow rhsmcertd_t domain to read xenfs_t files Resolves: rhbz#1405870 - Allow zabbix_agent_t to run zabbix scripts Resolves: rhbz#1380697 - Allow rabbitmq_t domain to create own tmp files/dirs Resolves: rhbz#1546897 - Allow policykit_t mmap policykit_auth_exec_t files Resolves: rhbz#1583082 - Allow ipmievd_t domain to read general certs Resolves: rhbz#1514591 - Add sys_ptrace capability to pcp_pmie_t domain - Allow squid domain to exec ldconfig Resolves: rhbz#1532017 - Make working gpg agent in gpg_agent_t domain Resolves: rhbz#1535109 - Update gpg SELinux policy module - Allow kexec to read kernel module files in /usr/lib/modules. Resolves: rhbz#1536690 - Allow mailman_domain to read system network state Resolves: rhbz#1413510 - Allow mailman_mail_t domain to search for apache configs Resolves: rhbz#1413510 - Allow openvswitch_t domain to read neutron state and read/write fixed disk devices Resolves: rhbz#1499208 - Allow antivirus_domain to read all domain system state Resolves: rhbz#1560986 - Allow targetd_t domain to red gconf_home_t files/dirs Resolves: rhbz#1546671 - Allow freeipmi domain to map sysfs_t files Resolves: rhbz#1575918 - Label /usr/libexec/bluetooth/obexd as obexd_exec_t Resolves: rhbz#1351750 - Update rhcs SELinux module Resolves: rhbz#1589257 - Allow iscsid_t domain mmap kernel modules Resolves: rhbz#1589295 - Allow iscsid_t domain mmap own tmp files Resolves: rhbz#1589295 - Update iscsid_domtrans() interface to allow mmap iscsid_exec_t binary Resolves: rhbz#1589295 - Update nscd_socket_use interface to allow caller domain also mmap nscd_var_run_t files. Resolves: rhbz#1589271 - Allow nscd_t domain to mmap system_db_t files Resolves: rhbz#1589271 - Add interface nagios_unconfined_signull() - Allow lircd_t domain read sssd public files Add setgid capability to lircd_t domain Resolves: rhbz#1550700 - Add missing requires - Allow tomcat domain sends email Resolves: rhbz#1585184 - Allow memcached_t domain nnp_transition becuase of systemd security features BZ(1514867) Resolves: rhbz#1585714 - Allow kdump_t domain to map /boot files Resolves: rhbz#1588884 - Fix typo in netutils policy - Allow confined users get AFS tokens Resolves: rhbz#1417671 - Allow sysadm_t domain to chat via dbus Resolves: rhbz#1582146 - Associate sysctl_kernel_t type with filesystem attribute - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Add interface dev_map_sysfs - Allow xdm_t domain to execute xdm_var_lib_t files Resolves: rhbz#1589139 - Allow syslogd_t domain to send signull to nagios_unconfined_plugin_t Resolves: rhbz#1569344 - Label /dev/vhost-vsock char device as vhost_device_t - Add files_map_boot_files() interface Resolves: rhbz#1588884 - Update traceroute_t domain to allow create dccp sockets Resolves: rhbz#1548350- Update ctdb domain to support gNFS setup Resolves: rhbz#1576818 - Allow authconfig_t dbus chat with policykit Resolves: rhbz#1551241 - Allow lircd_t domain to read passwd_file_t Resolves: rhbz:#1550700 - Allow lircd_t domain to read system state Resolves: rhbz#1550700 - Allow smbcontrol_t to mmap samba_var_t files and allow winbind create sockets BZ(1559795) Resolves: rhbz#1574521 - Allow tangd_t domain read certs Resolves: rhbz#1509055 - Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow ctdb_t domain modify ctdb_exec_t files Resolves: rhbz#1572584 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Allow SELinux users (except guest and xguest) to using bluetooth sockets Resolves: rhbz#1557299 - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Fix broken sysadm SELinux module Resolves: rhbz#1557311 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Update ssh_domtrans_keygen interface to allow mmap ssh_keygen_exec_t binary file Resolves: rhbz#1583089 - Allow systemd_networkd_t to read/write tun tap devices Resolves: rhbz#1583830 - Add bridge_socket, dccp_socket, ib_socket and mpls_socket to socket_class_set Resolves: rhbz#1583771 - Allow audisp_t domain to mmap audisp_exec_t binary Resolves: rhbz#1583551 - Fix duplicates in sysadm.te file Resolves: rhbz#1307183 - Allow sysadm_u use xdm Resolves: rhbz#1307183 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix duplicates in sysadm.te file Resolves: rhbz#1307183- Allow sysadm_u use xdm Resolves: rhbz#1307183- Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Improve procmail_domtrans() to allow mmaping procmail_exec_t - Allow hypervvssd_t domain to read fixed disk devices Resolves: rhbz#1581225 - Improve modutils_domtrans_insmod() interface to mmap insmod_exec_t binaries Resolves: rhbz#1581551 - Improve iptables_domtrans() interface to allow mmaping iptables_exec_t binary Resolves: rhbz#1581551 - Improve auth_domtrans_login_programinterface to allow also mmap login_exec_t binaries Resolves: rhbz#1581551 - Improve auth_domtrans_chk_passwd() interface to allow also mmaping chkpwd_exec_t binaries. Resolves: rhbz#1581551 - Allow mmap dhcpc_exec_t binaries in sysnet_domtrans_dhcpc interface- Add dbus_stream_connect_system_dbusd() interface. - Allow pegasus_t domain to mount tracefs_t filesystem Resolves:rhbz#1374570 - Allow psad_t domain to read all domains state Resolves: rhbz#1558439 - Add net_raw capability to named_t domain BZ(1545586) - Allow tomcat_t domain to connect to mongod_t tcp port Resolves:rhbz#1539748 - Allow dovecot and postfix to connect to systemd stream sockets Resolves: rhbz#1368642 - Label /usr/libexec/bluetooth/obexd as bluetoothd_exec_t to run process as bluetooth_t Resolves:rhbz#1351750 - Rename tang policy to tangd - Add interface systemd_rfkill_domtrans() - Allow users staff and sysadm to run wireshark on own domain Resolves:rhbz#1546362 - Allow systemd-bootchart to create own tmpfs files Resolves:rhbz#1510412- Rename tang policy to tangd - Allow virtd_t domain to relabel virt_var_lib_t files Resolves: rhbz#1558121 - Allow logrotate_t domain to stop services via systemd Resolves: rhbz#1527522 - Add tang policy Resolves: rhbz#1509055 - Allow mozilla_plugin_t to create mozilla.pdf file in user homedir with label mozilla_home_t Resolves: rhbz#1559859 - Improve snapperd SELinux policy Resolves: rhbz#1365555 - Allow snapperd_t daemon to create unlabeled dirs. Resolves: rhbz#1365555 - We have inconsistency in cgi templates with upstream, we use _content_t, but refpolicy use httpd__content_t. Created aliasses to make it consistence Resolves: rhbz#1271324 - Allow Openvswitch adding netdev bridge ovs 2.7.2.10 FDP Resolves: rhbz#1503835 - Add new Boolean tomcat_use_execmem Resolves: rhbz#1565226 - Allow domain transition from logrotate_t to chronyc_t Resolves: rhbz#1568281 - Allow nfsd_t domain to read/write sysctl fs files Resolves: rhbz#1516593 - Allow conman to read system state Resolves: rhbz#1377915 - Allow lircd_t to exec shell and add capabilities dac_read_search and dac_override Resolves: rhbz#1550700 - Allow usbmuxd to access /run/udev/data/+usb:*. Resolves: rhbz#1521054 - Allow abrt_t domain to manage kdump crash files Resolves: rhbz#1491585 - Allow systemd to use virtio console Resolves: rhbz#1558121 - Allow transition from sysadm role into mdadm_t domain. Resolves: rhbz#1551568 - Label /dev/op_panel and /dev/opal-prd as opal_device_t Resolves: rhbz#1537618 - Label /run/ebtables.lock as iptables_var_run_t Resolves: rhbz#1511437 - Allow udev_t domain to manage udev_rules_t char files. Resolves: rhbz#1545094 - Allow nsswitch_domain to read virt_var_lib_t files, because of libvirt NSS plugin. Resolves: rhbz#1567753 - Fix filesystem inteface file, we don't have nsfs_fs_t type, just nsfs_t Resolves: rhbz#1547700 - Allow iptables_t domain to create dirs in etc_t with system_conf_t labels- Add new boolean redis_enable_notify() Resolves: rhbz#1421326 - Label /var/log/shibboleth-www(/.*) as httpd_sys_rw_content_t Resolves: rhbz#1549514 - Add new label for vmtools scripts and label it as vmtools_unconfined_t stored in /etc/vmware-tools/ Resolves: rbhz#1463593 - Remove labeling for /etc/vmware-tools to bin_t it should be vmtools_unconfined_exec_t Resolves: rbhz#1463593- Backport several changes for snapperdfrom Fedora Rawhide Resolves: rhbz#1556798 - Allow snapperd_t to set priority for kernel processes Resolves: rhbz#1556798 - Make ganesha nfs server. Resolves: rhbz#1511489 - Allow vxfs filesystem to use SELinux labels Resolves: rhbz#1482880 - Add map permission to selinux-policy Resolves: rhbz#1460322- Label /usr/libexec/dbus-1/dbus-daemon-launch-helper as dbusd_exec_t to have systemd dbus services running in the correct domain instead of unconfined_service_t if unconfined.pp module is enabled. Resolves: rhbz#1546721- Allow openvswitch_t stream connect svirt_t Resolves: rhbz#1540702- Allow openvswitch domain to manage svirt_tmp_t sock files Resolves: rhbz#1540702 - Fix broken systemd_tmpfiles_run() interface- Allow dirsrv_t domain to create tmp link files Resolves: rhbz#1536011 - Label /usr/sbin/ldap-agent as dirsrv_snmp_exec_t Resolves: rhbz#1428568 - Allow ipsec_mgmt_t execute ifconfig_exec_t binaries - Allow ipsec_mgmt_t nnp domain transition to ifconfig_t Resolves: rhbz#1539416- Allow svirt_domain to create socket files in /tmp with label svirt_tmp_t Resolves: rhbz#1540702 - Allow keepalived_t domain getattr proc filesystem Resolves: rhbz#1477542 - Rename svirt_sandbox_file_t to container_file_t and svirt_lxc_net_t to container_t Resolves: rhbz#1538544 - Allow ipsec_t nnp transistions to domains ipsec_mgmt_t and ifconfig_t Resolves: rhbz:#1539416 - Allow systemd_logind_t domain to bind on dhcpd_port_t,pki_ca_port_t,flash_port_t Resolves: rhbz#1479350- Allow openvswitch_t domain to read cpuid, write to sysfs files and creating openvswitch_tmp_t sockets Resolves: rhbz#1535196 - Add new interface ppp_filetrans_named_content() Resolves: rhbz#1530601 - Allow keepalived_t read sysctl_net_t files Resolves: rhbz#1477542 - Allow puppetmaster_t domtran to puppetagent_t Resolves: rhbz#1376893 - Allow kdump_t domain to read kernel ring buffer Resolves: rhbz#1540004 - Allow ipsec_t domain to exec ifconfig_exec_t binaries. Resolves: rhbz#1539416 - Allow unconfined_domain_typ to create pppd_lock_t directory in /var/lock Resolves: rhbz#1530601 - Allow updpwd_t domain to create files in /etc with shadow_t label Resolves: rhbz#1412838 - Allow iptables sysctl load list support with SELinux enforced Resolves: rhbz#1535572- Allow virt_domains to acces infiniband pkeys. Resolves: rhbz#1533183 - Label /usr/libexec/ipsec/addconn as ipsec_exec_t to run this script as ipsec_t instead of init_t Resolves: rhbz#1535133 - Allow audisp_remote_t domain write to files on all levels Resolves: rhbz#1534924- Allow vmtools_t domain creating vmware_log_t files Resolves: rhbz#1507048 - Allow openvswitch_t domain to acces infiniband devices Resolves: rhbz#1532705- Allow chronyc_t domain to manage chronyd_keys_t files. Resolves: rhbz#1530525 - Make virtlog_t domain system dbus client Resolves: rhbz#1481109 - Update openvswitch SELinux module Resolves: rhbz#1482682 - Allow virtd_t to create also sock_files with label virt_var_run_t Resolves: rhbz#1484075- Allow domains that manage logfiles to man logdirs Resolves: rhbz#1523811- Label /dev/drm_dp_aux* as xserver_misc_device_t Resolves: rhbz#1520897 - Allow sysadm_t to run puppet_exec_t binaries as puppet_t Resolves: rhbz#1255745- Allow tomcat_t to manage pki_tomcat pid files Resolves: rhbz#1478371 - networkmanager: allow talking to openvswitch Resolves: rhbz#1517247 - Allow networkmanager_t and opensm_t to manage subned endports for IPoIB VLANs Resolves: rhbz#1517895 - Allow domains networkmanager_t and opensm_t to control IPoIB VLANs Resolves: rhbz#1517744 - Fix typo in guest interface file Resolves: rhbz#1468254 - Allow isnsd_t domain to accept tcp connections. Resolves: rhbz#1390208- Allow getty to use usbttys Resolves: rhbz#1514235- Allow ldap_t domain to manage also slapd_tmp_t lnk files Resolves: rhbz#1510883 - Allow cluster_t domain creating bundles directory with label var_log_t instead of cluster_var_log_t Resolves: rhbz:#1508360 - Add dac_read_search and dac_override capabilities to ganesha Resolves: rhbz#1483451- Add dependency for policycoreutils-2.5.18 becuase of new cgroup_seclabel policy capability Resolves: rhbz#1510145- Allow jabber domains to connect to postgresql ports Resolves: rhbz#1438489 - Dontaudit accountsd domain creating dirs in /root Resolves: rhbz#1456760 - Dontaudit slapd_t to block suspend system Resolves: rhbz: #1479759 - Allow spamc_t to stream connect to cyrus. Resolves: rhbz#1382955 - allow imapd to read /proc/net/unix file Resolves: rhbz#1393030 - Allow passenger to connect to mysqld_port_t Resolves: rhbz#1433464- Allow chronyc_t domain to use user_ptys Resolves: rhbz#1470150 - allow ptp4l to read /proc/net/unix file - Allow conmand to use usb ttys. Resolves: rhbz#1505121 - Label all files /var/log/opensm.* as opensm_log_t because opensm creating new log files with name opensm-subnet.lst Resolves: rhbz#1505845 - Allow chronyd daemon to execute chronyc. Resolves: rhbz#1508486 - Allow firewalld exec ldconfig. Resolves: rhbz#1375576 - Allow mozilla_plugin_t domain to dbus chat with devicekit Resolves: rhbz#1460477 - Dontaudit leaked logwatch pipes Resolves: rhbz#1450119 - Label /usr/bin/VGAuthService as vmtools_exec_t to confine this daemon. Resolves: rhbz#1507048 - Allow httpd_t domain to execute hugetlbfs_t files Resolves: rhbz#1507682 - Allow nfsd_t domain to read configfs_t files/dirs Resolves: rhbz#1439442 - Hide all allow rules with ptrace inside deny_ptrace boolean Resolves: rhbz#1421075 - Allow tgtd_t domain to read generic certs Resolves: rhbz#1438532 - Allow ptp4l to send msgs via dgram socket to unprivileged user domains Resolves: rhbz#1429853 - Allow dirsrv_snmp_t to use inherited user ptys and read system state Resolves: rhbz#1428568 - Allow glusterd_t domain to create own tmpfs dirs/files Resolves: rhbz#1411310 - Allow keepalived stream connect to snmp Resolves: rhbz#1401556 - After fix in kernel where LSM hooks for dac_override and dac_search_read capability was swaped we need to fix it also in policy Resolves: rhbz#1507089- Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow chronyd_t do request kernel module and block_suspend capability Resolves: rhbz#1350765 - Allow system_cronjob_t to create /var/lib/letsencrypt dir with right label Resolves: rhbz#1447278 - Allow httpd_t also read httpd_user_content_type dirs when httpd_enable_homedirs is enables Resolves: rhbz#1491994 - Allow svnserve to use kerberos Resolves: rhbz#1475271 - Allow conman to use ptmx. Add conman_use_nfs boolean Resolves: rhbz#1377915 - Add nnp transition for services using: NoNewPrivileges systemd security feature Resolves: rhbz#1311430 - Add SELinux support for chronyc Resolves: rhbz#1470150 - Add dac_read_search capability to openvswitch_t domain Resolves: rhbz#1501336 - Allow svnserve to manage own svnserve_log_t files/dirs Resolves: rhbz#1480741 - Allow keepalived_t to search network sysctls Resolves: rhbz#1477542 - Allow puppetagent_t domain dbus chat with rhsmcertd_t domain Resolves: rhbz#1446777 - Add dccp_socket into socker_class_set subset Resolves: rhbz#1459941 - Allow iptables_t to run setfiles to restore context on system Resolves: rhbz#1489118 - Label 20514 tcp/udp ports as syslogd_port_t Label 10514 tcp/udp portas as syslog_tls_port_t Resolves: rhbz:#1411400 - Make nnp transition Active Resolves: rhbz#1480518 - Label tcp 51954 as isns_port_t Resolves: rhbz#1390208 - Add dac_read_search capability chkpwd_t Resolves: rhbz#1376991 - Add support for running certbot(letsencrypt) in crontab Resolves: rhbz#1447278 - Add init_nnp_daemon_domain interface - Allow xdm_t to gettattr /dev/loop-control device Resolves: rhbz#1462925 - Allow nnp trasintion for unconfined_service_t Resolves: rhbz#1311430 - Allow unpriv user domains and unconfined_service_t to use chronyc Resolves: rhbz#1470150 - Allow iptables to exec plymouth. Resolves: rhbz#1480374 - Fix typo in fs_unmount_tracefs interface. Resolves: rhbz#1371057 - Label postgresql-check-db-dir as postgresql_exec_t Resolves: rhbz#1490956- We should not ship selinux-policy with permissivedomains enabled. Resolves: rhbz#1494172 - Fix order of installing selinux-policy-sandbox, because of depedencied in sandbox module, selinux-policy-targeted needs to be installed before selinux-policy-sandbox Resolves: rhbz#1492606- Allow tomcat to setsched Resolves: rhbz#1492730 - Fix rules blocking ipa-server upgrade process Resolves: rhbz#1478371 - Add new boolean tomcat_read_rpm_db() Resolves: rhbz#1477887 - Allow tomcat to connect on mysqld tcp ports - Add ctdbd_t domain sys_source capability and allow setrlimit Resolves: rhbz#1491235 - Fix keepalived SELinux module - Allow automount domain to manage mount pid files Resolves: rhbz#1482381 - Allow stunnel_t domain setsched Resolves: rhbz#1479383 - Add keepalived domain setpgid capability Resolves: rhbz#1486638 - Allow tomcat domain to connect to mssql port Resolves: rhbz#1484572 - Remove snapperd_t from unconfined domaines Resolves: rhbz#1365555 - Fix typo bug in apache module Resolves: rhbz#1397311 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Add interface systemd_tmpfiles_run - End of file cannot be in comment - Allow systemd-logind to use ypbind Resolves: rhbz#1479350 - Add creating opasswd file with shadow_t SELinux label in auth_manage_shadow() interface Resolves: rhbz#1412838 - Allow sysctl_irq_t assciate with proc_t Resolves: rhbz#1485909 - Enable cgourp sec labeling Resolves: rhbz#1485947 - Add cgroup_seclabel policycap. Resolves: rhbz#1485947 - Allow sshd_t domain to send signull to xdm_t processes Resolves: rhbz#1448959 - Allow updpwd_t domain auth file name trans Resolves: rhbz#1412838 - Allow sysadm user to run systemd-tmpfiles Resolves: rbhz#1325364 - Add support labeling for vmci and vsock device Resolves: rhbz#1451358 - Add userdom_dontaudit_manage_admin_files() interface Resolves: rhbz#1323792 - Allow iptables_t domain to read files with modules_conf_t label Resolves: rhbz#1373220 - init: Add NoNewPerms support for systemd. Resolves: rhbz#1480518 - Add nnp_nosuid_transition policycap and related class/perm definitions. Resolves: rhbz#1480518 - refpolicy: Infiniband pkeys and endports Resolves: rhbz#1464484- Allow certmonger using systemctl on pki_tomcat unit files Resolves: rhbz#1481388- Allow targetd_t to create own tmp files. - Dontaudit targetd_t to exec rpm binary file. Resolves: rhbz#1373860 Resolves: rhbz#1424621- Add few rules to make working targetd daemon with SELinux Resolves: rhbz#1373860 - Allow ipmievd_t domain to load kernel modules Resolves: rhbz#1441081 - Allow logrotate to reload transient systemd unit Resolves: rhbz#1440515 - Add certwatch_t domain dac_override and dac_read_search capabilities Resolves: rhbz#1422000 - Allow postgrey to execute bin_t files and add postgrey into nsswitch_domain Resolves: rhbz#1412072 - Allow nscd_t domain to search network sysctls Resolves: rhbz#1432361 - Allow iscsid_t domain to read mount pid files Resolves: rhbz#1482097 - Allow ksmtuned_t domain manage sysfs_t files/dirs Resolves: rhbz#1413865 - Allow keepalived_t domain domtrans into iptables_t Resolves: rhbz#1477719 - Allow rshd_t domain reads net sysctls Resolves: rhbz#1477908 - Add interface seutil_dontaudit_read_module_store() - Update interface lvm_rw_pipes() by adding also open permission - Label /dev/clp device as vfio_device_t Resolves: rhbz#1477624 - Allow ifconfig_t domain unmount fs_t Resolves: rhbz#1477445 - Label /dev/gpiochip* devices as gpio_device_t Resolves: rhbz#1477618 - Add interface dev_manage_sysfs() Resolves: rhbz#1474989- Label /usr/libexec/sudo/sesh as shell_exec_t Resolves: rhbz#1480791- Allow tomcat_t domain couple capabilities to make working tomcat-jsvc Resolves: rhbz#1470735- Allow llpdad send dgram to libvirt Resolves: rhbz#1472722- Add new boolean gluster_use_execmem Resolves: rhbz#1469027 - Allow cluster_t and glusterd_t domains to dbus chat with ganesha service Resolves: rhbz#1468581- Dontaudit staff_t user read admin_home_t files. Resolves: rhbz#1290633- Allow couple rules needed to start targetd daemon with SELinux in enforcing mode Resolves: rhbz#1424621 - Add interface lvm_manage_metadata Resolves: rhbz#1424621- Allow sssd_t to read realmd lib files. Resolves: rhbz#1436689 - Add permission open to files_read_inherited_tmp_files() interface Resolves: rhbz#1290633 Resolves: rhbz#1457106- Allow unconfined_t user all user namespace capabilties. Resolves: rhbz#1461488- Allow httpd_t to read realmd_var_lib_t files Resolves: rhbz#1436689- Allow named_t to bind on udp 4321 port Resolves: rhbz#1312972 - Allow systemd-sysctl cap. sys_ptrace Resolves: rhbz#1458999- Allow pki_tomcat_t execute ldconfig. Resolves: rhbz#1436689- Allow iscsi domain load kernel module. Resolves: rhbz#1457874 - Allow keepalived domain connect to squid tcp port Resolves: rhbz#1457455 - Allow krb5kdc_t domain read realmd lib files. Resolves: rhbz#1436689 - xdm_t should view kernel keys Resolves: rhbz#1432645- Allow tomcat to connect on all unreserved ports - Allow ganesha to connect to all rpc ports Resolves: rhbz#1448090 - Update ganesha with another fixes. Resolves: rhbz#1448090 - Update rpc_read_nfs_state_data() interface to allow read also lnk_files. Resolves: rhbz#1448090 - virt_use_glusterd boolean should be in optional block Update ganesha module to allow create tmp files Resolves: rhbz#1448090 - Hide broken symptoms when machine is configured with network bounding.- Add new boolean virt_use_glusterd Resolves: rhbz#1455994 - Add capability sys_boot for sbd_t domain - Allow sbd_t domain to create rpc sysctls. Resolves: rhbz#1455631 - Allow ganesha_t domain to manage glusterd_var_run_t pid files. Resolves: rhbz#1448090- Create new interface: glusterd_read_lib_files() - Allow ganesha read glusterd lib files. - Allow ganesha read network sysctls Resolves: rhbz#1448090- Add few allow rules to ganesha module Resolves: rhbz#1448090 - Allow condor_master_t to read sysctls. Resolves: rhbz#1277506 - Add dac_override cap to ctdbd_t domain Resolves: rhbz#1435708 - Label 8750 tcp/udp port as dey_keyneg_port_t Resolves: rhbz#1448090- Add ganesha_use_fusefs boolean. Resolves: rhbz#1448090- Allow httpd_t reading kerberos kdc config files Resolves: rhbz#1452215 - Allow tomcat_t domain connect to ibm_dt_2 tcp port. Resolves: rhbz#1447436 - Allow stream connect to initrc_t domains Resolves: rhbz#1447436 - Allow dnsmasq_t domain to read systemd-resolved pid files. Resolves: rhbz#1453114 - Allow tomcat domain name_bind on tcp bctp_port_t Resolves: rhbz#1451757 - Allow smbd_t domain generate debugging files under /var/run/gluster. These files are created through the libgfapi.so library that provides integration of a GlusterFS client in the Samba (vfs_glusterfs) process. Resolves: rhbz#1447669 - Allow condor_master_t write to sysctl_net_t Resolves: rhbz#1277506 - Allow nagios check disk plugin read /sys/kernel/config/ Resolves: rhbz#1277718 - Allow pcp_pmie_t domain execute systemctl binary Resolves: rhbz#1271998 - Allow nagios to connect to stream sockets. Allow nagios start httpd via systemctl Resolves: rhbz#1247635 - Label tcp/udp port 1792 as ibm_dt_2_port_t Resolves: rhbz#1447436 - Add interface fs_read_configfs_dirs() - Add interface fs_read_configfs_files() - Fix systemd_resolved_read_pid interface - Add interface systemd_resolved_read_pid() Resolves: rhbz#1453114 - Allow sshd_net_t domain read/write into crypto devices Resolves: rhbz#1452759 - Label 8999 tcp/udp as bctp_port_t Resolves: rhbz#1451757- nmbd_t needs net_admin capability like smbd Resolves: rhbz#1431859 - Dontaudit net_admin capability for domains postfix_master_t and postfix_qmgr_t Resolves: rhbz#1431859 - Allow rngd domain read sysfs_t Resolves: rhbz#1451735 - Add interface pki_manage_common_files() Resolves: rhbz#1447436 - Allow tomcat_t domain to manage pki_common_t files and dirs Resolves: rhbz#1447436 - Use stricter fc rules for sssd sockets in /var/run Resolves: rhbz#1448060 - Allow certmonger reads httpd_config_t files Resolves: rhbz#1436689 - Allow keepalived_t domain creating netlink_netfilter_socket. Resolves: rhbz#1451684 - Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321- Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Allow sssd_t domain creating sock files labeled as sssd_var_run_t in /var/run/ Resolves: rhbz#1448056 Resolves: rhbz#1448060 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321 - Allow netutils setpcap capability Resolves:1444438- Update targetd policy to accommodate changes in the service Resolves: rhbz#1424621 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Update virt_rw_stream_sockets_svirt() interface to allow confined users set socket options. Resolves: rhbz#1415841 - Allow radius domain stream connec to postgresql Resolves: rhbz#1446145 - Allow virt_domain to read raw fixed_disk_device_t to make working blockcommit Resolves: rhbz#1449977 - Allow glusterd_t domain start ganesha service Resolves: rhbz#1448090 - Made few cosmetic changes in sssd SELinux module Resolves: rhbz#1448060 - sssd-kcm should not run as unconfined_service_t BZ(1447411) Resolves: rhbz#1448060 - Add sssd_secrets labeling Also add named_filetrans interface to make sure all labels are correct Resolves: rhbz#1448056 - Allow keepalived_t domain read usermodehelper_t Resolves: rhbz#1449769 - Allow tomcat_t domain read pki_common_t files Resolves: rhbz#1447436 - Add interface pki_read_common_files() Resolves: rhbz#1447436- Allow hypervkvp_t domain execute hostname Resolves: rhbz#1449064 - Dontaudit sssd_selinux_manager_t use of net_admin capability Resolves: rhbz#1444955 - Allow tomcat_t stream connect to pki_common_t Resolves: rhbz#1447436 - Dontaudit xguest_t's attempts to listen to its tcp_socket - Allow sssd_selinux_manager_t to ioctl init_t sockets Resolves: rhbz#1436689 - Allow _su_t to create netlink_selinux_socket Resolves rhbz#1146987 - Allow unconfined_t to module_load any file Resolves rhbz#1442994- Improve ipa_cert_filetrans_named_content() interface to also allow caller domain manage ipa_cert_t type. Resolves: rhbz#1436689- Allow pki_tomcat_t domain read /etc/passwd. Resolves: rhbz#1436689 - Allow tomcat_t domain read ipa_tmp_t files Resolves: rhbz#1436689 - Label new path for ipa-otpd Resolves: rhbz#1446353 - Allow radiusd_t domain stream connect to postgresql_t Resolves: rhbz#1446145 - Allow rhsmcertd_t to execute hostname_exec_t binaries. Resolves: rhbz#1445494 - Allow virtlogd to append nfs_t files when virt_use_nfs=1 Resolves: rhbz#1402561- Update tomcat policy to adjust for removing unconfined_domain attr. Resolves: rhbz#1432083 - Allow httpd_t domain read also httpd_user_content_type lnk_files. Resolves: rhbz#1383621 - Allow httpd_t domain create /etc/httpd/alias/ipaseesion.key with label ipa_cert_t Resolves: rhbz#1436689 - Dontaudit _gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Label /var/www/html/nextcloud/data as httpd_sys_rw_content_t Resolves: rhbz#1425530 - Add interface ipa_filetrans_named_content() Resolves: rhbz#1432115 - Allow tomcat use nsswitch Resolves: rhbz#1436689 - Allow certmonger_t start/status generic services Resolves: rhbz#1436689 - Allow dirsrv read cgroup files. Resolves: rhbz#1436689 - Allow ganesha_t domain read/write infiniband devices. Resolves: rhbz#1383784 - Allow sendmail_t domain sysctl_net_t files Resolves: rhbz#1369376 - Allow targetd_t domain read network state and getattr on loop_control_device_t Resolves: rhbz#1373860 - Allow condor_schedd_t domain send mails. Resolves: rhbz#1277506 - Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689 - Allow staff to systemctl virt server when staff_use_svirt=1 Resolves: rhbz#1415841 - Allow unconfined_t create /tmp/ca.p12 file with ipa_tmp_t context Resolves: rhbz#1432115 - Label /sysroot/ostree/deploy/rhel-atomic-host/* as root_t Resolves: rhbz#1428112- Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689- Hide broken symptoms when using kernel 3.10.0-514+ with network bonding. Postfix_picup_t domain requires NET_ADMIN capability which is not really needed. Resolves: rhbz#1431859 - Fix policy to reflect all changes in new IPA release Resolves: rhbz#1432115 Resolves: rhbz#1436689- Allow sbd_t to read/write fixed disk devices Resolves: rhbz#1440165 - Add sys_ptrace capability to radiusd_t domain Resolves: rhbz#1426641 - Allow cockpit_session_t domain connects to ssh tcp ports. Resolves: rhbz#1413509- Update tomcat policy to make working ipa install process Resolves: rhbz#1436689- Allow pcp_pmcd_t net_admin capability. - Allow pcp_pmcd_t read net sysctls - Allow system_cronjob_t create /var/run/pcp with pcp_var_run_t Resolves: rhbz#1336211- Fix all AVC denials during pkispawn of CA Resolves: rhbz#1436383 - Update pki interfaces and tomcat module Resolves: rhbz#1436689- Update pki interfaces and tomcat module Resolves: rhbz#1436689- Dontaudit firewalld wants write to /root Resolves: rhbz#1438708 - Dontaudit firewalld to create dirs in /root/ Resolves: rhbz#1438708 - Allow sendmail to search network sysctls Resolves: rhbz#1369376 - Add interface gssd_noatsecure() Resolves: rhbz#1438036 - Add interface gssproxy_noatsecure() Resolves: rhbz#1438036 - Dontaudit pcp_pmlogger_t search for xserver logs. Allow pcp_pmlogger_t to send signals to unconfined doamins Allow pcp_pmlogger_t to send logs to journals Resolves: rhbz#1379371 - Allow chronyd_t net_admin capability to allow support HW timestamping. Resolves: rhbz#1416015 - Update tomcat policy Resolves: rhbz#1436689 Resolves: rhbz#1436383 - Allow certmonger to start haproxy service Resolves: rhbz#1349394 - Allow init noatsecure for gssd and gssproxy Resolves: rhbz#1438036- geoclue wants to dbus chat with avahi Resolves: rhbz#1434286 - Allow iptables get list of kernel modules Resolves: rhbz#1367520 - Allow unconfined_domain_type to enable/disable transient unit Resolves: rhbz#1337041 - Add interfaces init_enable_transient_unit() and init_disable_transient_unit - Revert "Allow sshd setcap capability. This is needed due to latest changes in sshd" Resolves: rhbz#1435264 - Label sysroot dir under ostree as root_t Resolves: rhbz#1428112- Remove ganesha_t domain from permissive domains. Resolves: rhbz#1436988- Allow named_t domain bind on several udp ports Resolves: rhbz#1312972 - Update nscd_use() interface Resolves: rhbz#1281716 - Allow radius_t domain ptrace Resolves: rhbz#1426641 - Update nagios to allos exec systemctl Resolves: rhbz#1247635 - Update pcp SELinux module to reflect all pcp changes Resolves: rhbz#1271998 - Label /var/lib/ssl_db as squid_cache_t Label /etc/squid/ssl_db as squid_cache_t Resolves: rhbz#1325527 - Allow pcp_pmcd_t domain search for network sysctl Allow pcp_pmcd_t domain sys_ptrace capability Resolves: rhbz#1336211- Allow drbd load modules Resolves: rhbz#1134883 - Revert "Add sys_module capability for drbd Resolves: rhbz#1134883" - Allow stapserver list kernel modules Resolves: rhbz#1325976 - Update targetd policy Resolves: rhbz#1373860 - Add sys_admin capability to amanda Resolves: rhbz#1371561 - Allow hypervvssd_t to read all dirs. Resolves: rhbz#1331309 - Label /run/haproxy.sock socket as haproxy_var_run_t Resolves: rhbz#1386233 - Allow oddjob_mkhomedir_t to mamange autofs_t dirs. Resolves: rhbz#1408819 - Allow tomcat to connect on http_cache_port_t Resolves: rhbz#1432083 - Allow geoclue to send msgs to syslog. Resolves: rhbz#1434286 - Allow condor_master_t domain capability chown. Resolves: rhbz#1277506 - Update mta_filetrans_named_content() interface to allow calling domain create files labeled as etc_aliases_t in dir labeled as etc_mail_t. Resolves: rhbz#1167468 - Allow nova domain search for httpd configuration. Resolves: rhbz#1190761 - Add sys_module capability for drbd Resolves: rhbz#1134883 - Allow user_u users stream connect to dirsrv, Allow sysadm_u and staff_u users to manage dirsrv files Resolves: rhbz#1286474 - Allow systemd_networkd_t communicate with systemd_networkd_t via dbus Resolves: rhbz#1278010- Add haproxy_t domain fowner capability Resolves: rhbz#1386233 - Allow domain transition from ntpd_t to hwclock_t domains Resolves: rhbz#1375624 - Allow cockpit_session_t setrlimit and sys_resource Resolves: rhbz#1402316 - Dontaudit svirt_t read state of libvirtd domain Resolves: rhbz#1426106 - Update httpd and gssproxy modules to reflects latest changes in freeipa Resolves: rhbz#1432115 - Allow iptables read modules_conf_t Resolves: rhbz#1367520- Remove tomcat_t domain from unconfined domains Resolves: rhbz#1432083 - Create new boolean: sanlock_enable_home_dirs() Resolves: rhbz#1432783 - Allow mdadm_t domain to read/write nvme_device_t Resolves: rhbz#1431617 - Remove httpd_user_*_content_t domains from user_home_type attribute. This tighten httpd policy and acces to user data will be more strinct, and also fix mutual influente between httpd_enable_homedirs and httpd_read_user_content Resolves: rhbz#1383621 - Dontaudit domain to create any file in /proc. This is kernel bug. Resolves: rhbz#1412679 - Add interface dev_rw_nvme Resolves: rhbz#1431617- Allow gssproxy to get attributes on all filesystem object types. Resolves: rhbz#1430295 - Allow ganesha to chat with unconfined domains via dbus Resolves: rhbz#1426554 - add the policy required for nextcloud Resolves: rhbz#1425530 - Add nmbd_t capability2 block_suspend Resolves: rhbz#1425357 - Label /var/run/chrony as chronyd_var_run_t Resolves: rhbz#1416015 - Add domain transition from sosreport_t to iptables_t Resolves: rhbz#1359789 - Fix path to /usr/lib64/erlang/erts-5.10.4/bin/epmd Resolves: rhbz:#1332803- Update rpm macros Resolves: rhbz#1380854- Add handling booleans via selinux-policy macros in custom policy spec files. Resolves: rhbz#1380854- Allow openvswitch to load kernel modules Resolves: rhbz#1405479- Allow openvswitch read script state. Resolves: rhbz#1405479- Update ganesha policy Resolves: rhbz#1426554 Resolves: rhbz#1383784 - Allow chronyd to read adjtime Resolves: rhbz#1416015 - Fixes for chrony version 2.2 Resolves: rhbz#1416015 - Add interface virt_rw_stream_sockets_svirt() Resolves: rhbz#1415841 - Label /dev/ss0 as gpfs_device_t Resolves: rhbz#1383784 - Allow staff to rw svirt unix stream sockets. Resolves: rhbz#1415841 - Label /rhev/data-center/mnt as mnt_t Resolves: rhbz#1408275 - Associate sysctl_rpc_t with proc filesystems Resolves: rhbz#1350927 - Add new boolean: domain_can_write_kmsg Resolves: rhbz#1415715- Allow rhsmcertd_t dbus chat with system_cronjob_t Resolves: rhbz#1405341 - Allow openvswitch exec hostname and readinitrc_t files Resolves: rhbz#1405479 - Improve SELinux context for mysql_db_t objects. Resolves: rhbz#1391521 - Allow postfix_postdrop to communicate with postfix_master via pipe. Resolves: rhbz#1379736 - Add radius_use_jit boolean Resolves: rhbz#1426205 - Label /var/lock/subsys/iptables as iptables_lock_t Resolves: rhbz#1405441 - Label /usr/lib64/erlang/erts-5.10.4/bin/epmd as lib_t Resolves: rhbz#1332803 - Allow can_load_kernmodule to load kernel modules. Resolves: rhbz#1423427 Resolves: rhbz#1424621- Allow nfsd_t domain to create sysctls_rpc_t files Resolves: rhbz#1405304 - Allow openvswitch to create netlink generic sockets. Resolves: rhbz#1397974 - Create kernel_create_rpc_sysctls() interface Resolves: rhbz#1405304- Allow nfsd_t domain rw sysctl_rpc_t dirs Resolves: rhbz#1405304 - Allow cgdcbxd_t to manage cgroup files. Resolves: rhbz#1358493 - Allow cmirrord_t domain to create netlink_connector sockets Resolves: rhbz#1412670 - Allow fcoemon to create netlink scsitransport sockets Resolves: rhbz#1362496 - Allow quota_nld_t create netlink_generic sockets Resolves: rhbz#1358679 - Allow cgred_t create netlink_connector sockets Resolves: rhbz#1376357 - Add dhcpd_t domain fowner capability Resolves: rhbz#1358485 - Allow acpid to attempt to connect to the Linux kernel via generic netlink socket. Resolves: rhbz#1358478 - Rename docker module to container module Resolves: rhbz#1386916 - Allow setflies to mount tracefs Resolves: rhbz#1376357 - Allow iptables to read nsfs files. Resolves: rhbz#1411316 - Allow systemd_bootchart_t domain create dgram sockets. Resolves: rhbz#1365953 - Rename docker interfaces to container Resolves: rhbz#1386916- Allow initrc_t domain to run rhel-autorelabel script properly during boot process Resolves: rhbz#1379722 - Allow systemd_initctl_t to create and connect unix_dgram sockets Resolves: rhbz#1365947 - Allow ifconfig_t to mount/unmount nsfs_t filesystem Resolves: rhbz#1349814 - Add interfaces allowing mount/unmount nsfs_t filesystem Resolves: rhbz#1349814- Add interface init_stream_connectto() Resolves:rhbz#1365947 - Allow rhsmcertd domain signull kernel. Resolves: rhbz#1379781 - Allow kdumpgui domain to read nvme device - Allow insmod_t to load kernel modules Resolves: rhbz#1421598 - Add interface files_load_kernel_modules() Resolves: rhbz#1421598 - Add SELinux support for systemd-initctl daemon Resolves:rhbz#1365947 - Add SELinux support for systemd-bootchart Resolves: rhbz#1365953- Allow firewalld to getattr open search read modules_object_t:dir Resolves: rhbz#1418391 - Fix label for nagios plugins in nagios file conxtext file Resolves: rhbz#1277718 - Add sys_ptrace capability to pegasus domain Resolves: rhbz#1381238 - Allow sssd_t domain setpgid Resolves:rhbz#1416780 - After the latest changes in nfsd. We should allow nfsd_t to read raw fixed disk. Resolves: rhbz#1350927 - Allow kdumpgui domain to read nvme device Resolves: rhbz#1415084 - su using libselinux and creating netlink_selinux socket is needed to allow libselinux initialization. Resolves: rhbz#1146987 - Add user namespace capability object classes. Resolves: rhbz#1368057 - Add module_load permission to class system Resolves:rhbz#1368057 - Add the validate_trans access vector to the security class Resolves: rhbz#1368057 - Add "binder" security class and access vectors Resolves: rhbz#1368057 - Allow ifconfig_t domain read nsfs_t Resolves: rhbz#1349814 - Allow ping_t domain to load kernel modules. Resolves: rhbz#1388363- Allow systemd container to read/write usermodehelperstate Resolves: rhbz#1403254 - Label udp ports in range 24007-24027 as gluster_port_t Resolves: rhbz#1404152- Allow glusterd_t to bind on glusterd_port_t udp ports. Resolves: rhbz#1404152 - Revert: Allow glusterd_t to bind on med_tlp port.- Allow glusterd_t to bind on med_tlp port. Resolves: rhbz#1404152 - Update ctdbd_t policy to reflect all changes. Resolves: rhbz#1402451 - Label tcp port 24009 as med_tlp_port_t Resolves: rhbz#1404152 - Issue appears during update directly from RHEL-7.0 to RHEL-7.3 or above. Modules pkcsslotd and vbetools missing in selinux-policy package for RHEL-7.3 which causing warnings during SELinux policy store migration process. Following patch fixes issue by skipping pkcsslotd and vbetools modules migration.- Allow ctdbd_t domain transition to rpcd_t Resolves:rhbz#1402451- Fixes for containers Allow containers to attempt to write to unix_sysctls. Allow cotainers to use the FD's leaked to them from parent processes. Resolves: rhbz#1403254- Allow glusterd_t send signals to userdomain. Label new glusterd binaries as glusterd_exec_t Resolves: rhbz#1404152 - Allow systemd to stop glusterd_t domains. Resolves: rhbz#1400493- Make working CTDB:NFS: CTDB failover from selinux-policy POV Resolves: rhbz#1402451- Add kdump_t domain sys_admin capability Resolves: rhbz#1375963- Allow puppetagent_t to access timedated dbus. Use the systemd_dbus_chat_timedated interface to allow puppetagent_t the access. Resolves: rhbz#1399250- Update systemd on RHEL-7.2 box to version from RHEL-7.3 and then as a separate yum command update the selinux policy systemd will start generating USER_AVC denials and will start returning "Access Denied" errors to DBus clients Resolves: rhbz#1393505- Allow cluster_t communicate to fprintd_t via dbus Resolves: rhbz#1349798- Fix error message during update from RHEL-7.2 to RHEL-7.3, when /usr/sbin/semanage command is not installed and selinux-policy-migrate-local-changes.sh script is executed in %post install phase of selinux-policy package Resolves: rhbz#1392010- Allow GlusterFS with RDMA transport to be started correctly. It requires ipc_lock capability together with rw permission on rdma_cm device. Resolves: rhbz#1384488 - Allow glusterd to get attributes on /sys/kernel/config directory. Resolves: rhbz#1384483- Use selinux-policy-migrate-local-changes.sh instead of migrateStore* macros - Add selinux-policy-migrate-local-changes service Resolves: rhbz#1381588- Allow sssd_selinux_manager_t to manage also dir class. Resolves: rhbz#1368097 - Add interface seutil_manage_default_contexts_dirs() Resolves: rhbz#1368097- Add virt_sandbox_use_nfs -> virt_use_nfs boolean substitution. Resolves: rhbz#1355783- Allow pcp_pmcd_t domain transition to lvm_t Add capability kill and sys_ptrace to pcp_pmlogger_t Resolves: rhbz#1309883- Allow ftp daemon to manage apache_user_content Resolves: rhbz#1097775 - Label /etc/sysconfig/oracleasm as oracleasm_conf_t Resolves: rhbz#1331383 - Allow oracleasm to rw inherited fixed disk device Resolves: rhbz#1331383 - Allow collectd to connect on unix_stream_socket Resolves: rhbz#1377259- Allow iscsid create netlink iscsid sockets. Resolves: rhbz#1358266 - Improve regexp for power_unit_file_t files. To catch just systemd power unit files. Resolves: rhbz#1375462- Update oracleasm SELinux module that can manage oracleasmfs_t blk files. Add dac_override cap to oracleasm_t domain. Resolves: rhbz#1331383 - Add few rules to pcp SELinux module to make ti able to start pcp_pmlogger service Resolves: rhbz#1206525- Add oracleasm_conf_t type and allow oracleasm_t to create /dev/oracleasm Resolves: rhbz#1331383 - Label /usr/share/pcp/lib/pmie as pmie_exec_t and /usr/share/pcp/lib/pmlogger as pmlogger_exec_t Resolves: rhbz#1206525 - Allow mdadm_t to getattr all device nodes Resolves: rhbz#1365171 - Add interface dbus_dontaudit_stream_connect_system_dbusd() Resolves:rhbz#1052880 - Add virt_stub_* interfaces for docker policy which is no longer a part of our base policy. Resolves: rhbz#1372705 - Allow guest-set-user-passwd to set users password. Resolves: rhbz#1369693 - Allow samdbox domains to use msg class Resolves: rhbz#1372677 - Allow domains using kerberos to read also kerberos config dirs Resolves: rhbz#1368492 - Allow svirt_sandbox_domains to r/w onload sockets Resolves: rhbz#1342930 - Add interface fs_manage_oracleasm() Resolves: rhbz#1331383 - Label /dev/kfd as hsa_device_t Resolves: rhbz#1373488 - Update seutil_manage_file_contexts() interface that caller domain can also manage file_context_t dirs Resolves: rhbz#1368097 - Add interface to write to nsfs inodes Resolves: rhbz#1372705 - Allow systemd services to use PrivateNetwork feature Resolves: rhbz#1372705 - Add a type and genfscon for nsfs. Resolves: rhbz#1372705 - Allow run sulogin_t in range mls_systemlow-mls_systemhigh. Resolves: rhbz#1290400- Allow arpwatch to create netlink netfilter sockets. Resolves: rhbz#1358261 - Fix file context for /etc/pki/pki-tomcat/ca/ - new interface oddjob_mkhomedir_entrypoint() - Move label for /var/lib/docker/vfs/ to proper SELinux module - Allow mdadm to get attributes from all devices. - Label /etc/puppetlabs as puppet_etc_t. - Allow systemd-machined to communicate to lxc container using dbus - Allow systemd_resolved to send dbus msgs to userdomains Resolves: rhbz#1236579 - Allow systemd-resolved to read network sysctls Resolves: rhbz#1236579 - Allow systemd_resolved to connect on system bus. Resolves: rhbz#1236579 - Make entrypoint oddjob_mkhomedir_exec_t for unconfined_t - Label all files in /dev/oracleasmfs/ as oracleasmfs_t Resolves: rhbz#1331383- Label /etc/pki/pki-tomcat/ca/ as pki_tomcat_cert_t Resolves:rhbz#1366915 - Allow certmonger to manage all systemd unit files Resolves:rhbz#1366915 - Grant certmonger "chown" capability Resolves:rhbz#1366915 - Allow ipa_helper_t stream connect to dirsrv_t domain Resolves: rhbz#1368418 - Update oracleasm SELinux module Resolves: rhbz#1331383 - label /var/lib/kubelet as svirt_sandbox_file_t Resolves: rhbz#1369159 - Add few interfaces to cloudform.if file Resolves: rhbz#1367834 - Label /var/run/corosync-qnetd and /var/run/corosync-qdevice as cluster_var_run_t. Note: corosync policy is now par of rhcs module Resolves: rhbz#1347514 - Allow krb5kdc_t to read krb4kdc_conf_t dirs. Resolves: rhbz#1368492 - Update networkmanager_filetrans_named_content() interface to allow source domain to create also temad dir in /var/run. Resolves: rhbz#1365653 - Allow teamd running as NetworkManager_t to access netlink_generic_socket to allow multiple network interfaces to be teamed together. Resolves: rhbz#1365653 - Label /dev/oracleasmfs as oracleasmfs_t. Add few interfaces related to oracleasmfs_t type Resolves: rhbz#1331383 - A new version of cloud-init that supports the effort to provision RHEL Atomic on Microsoft Azure requires some a new rules that allows dhclient/dhclient hooks to call cloud-init. Resolves: rhbz#1367834 - Allow iptables to creating netlink generic sockets. Resolves: rhbz#1364359- Allow ipmievd domain to create lock files in /var/lock/subsys/ Resolves:rhbz#1349058 - Update policy for ipmievd daemon. Resolves:rhbz#1349058 - Dontaudit hyperkvp to getattr on non security files. Resolves: rhbz#1349356 - Label /run/corosync-qdevice and /run/corosync-qnetd as corosync_var_run_t Resolves: rhbz#1347514 - Fixed lsm SELinux module - Add sys_admin capability to sbd domain Resolves: rhbz#1322725 - Allow vdagent to comunnicate with systemd-logind via dbus Resolves: rhbz#1366731 - Allow lsmd_plugin_t domain to create fixed_disk device. Resolves: rhbz#1238066 - Allow opendnssec domain to create and manage own tmp dirs/files Resolves: rhbz#1366649 - Allow opendnssec domain to read system state Resolves: rhbz#1366649 - Update opendnssec_manage_config() interface to allow caller domain also manage opendnssec_conf_t dirs Resolves: rhbz#1366649 - Allow rasdaemon to mount/unmount tracefs filesystem. Resolves: rhbz#1364380 - Label /usr/libexec/iptables/iptables.init as iptables_exec_t Allow iptables creating lock file in /var/lock/subsys/ Resolves: rhbz#1367520 - Modify interface den_read_nvme() to allow also read nvme_device_t block files. Resolves: rhbz#1362564 - Label /var/run/storaged as lvm_var_run_t. Resolves: rhbz#1264390 - Allow unconfineduser to run ipa_helper_t. Resolves: rhbz#1361636- Dontaudit mock to write to generic certs. Resolves: rhbz#1271209 - Add labeling for corosync-qdevice and corosync-qnetd daemons, to run as cluster_t Resolves: rhbz#1347514 - Revert "Label corosync-qnetd and corosync-qdevice as corosync_t domain" - Allow modemmanager to write to systemd inhibit pipes Resolves: rhbz#1365214 - Label corosync-qnetd and corosync-qdevice as corosync_t domain Resolves: rhbz#1347514 - Allow ipa_helper to read network state Resolves: rhbz#1361636 - Label oddjob_reqiest as oddjob_exec_t Resolves: rhbz#1361636 - Add interface oddjob_run() Resolves: rhbz#1361636 - Allow modemmanager chat with systemd_logind via dbus Resolves: rhbz#1362273 - Allow NetworkManager chat with puppetagent via dbus Resolves: rhbz#1363989 - Allow NetworkManager chat with kdumpctl via dbus Resolves: rhbz#1363977 - Allow sbd send msgs to syslog Allow sbd create dgram sockets. Allow sbd to communicate with kernel via dgram socket Allow sbd r/w kernel sysctls. Resolves: rhbz#1322725 - Allow ipmievd_t domain to re-create ipmi devices Label /usr/libexec/openipmi-helper as ipmievd_exec_t Resolves: rhbz#1349058 - Allow rasdaemon to use tracefs filesystem. Resolves: rhbz#1364380 - Fix typo bug in dirsrv policy - Some logrotate scripts run su and then su runs unix_chkpwd. Allow logrotate_t domain to check passwd. Resolves: rhbz#1283134 - Add ipc_lock capability to sssd domain. Allow sssd connect to http_cache_t Resolves: rhbz#1362688 - Allow dirsrv to read dirsrv_share_t content Resolves: rhbz#1363662 - Allow virtlogd_t to append svirt_image_t files. Resolves: rhbz#1358140 - Allow hypervkvp domain to read hugetlbfs dir/files. Resolves: rhbz#1349356 - Allow mdadm daemon to read nvme_device_t blk files Resolves: rhbz#1362564 - Allow selinuxusers and unconfineduser to run oddjob_request Resolves: rhbz#1361636 - Allow sshd server to acces to Crypto Express 4 (CEX4) devices. Resolves: rhbz#1362539 - Fix labeling issue in init.fc file. Path /usr/lib/systemd/fedora-* changed to /usr/lib/systemd/rhel-*. Resolves: rhbz#1363769 - Fix typo in device interfaces Resolves: rhbz#1349058 - Add interfaces for managing ipmi devices Resolves: rhbz#1349058 - Add interfaces to allow mounting/umounting tracefs filesystem Resolves: rhbz#1364380 - Add interfaces to allow rw tracefs filesystem Resolves: rhbz#1364380 - Add interface dev_read_nvme() to allow reading Non-Volatile Memory Host Controller devices. Resolves: rhbz#1362564 - Label /sys/kernel/debug/tracing filesystem Resolves: rhbz#1364380 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857- Dontaudit mock_build_t can list all ptys. Resolves: rhbz#1271209 - Allow ftpd_t to mamange userhome data without any boolean. Resolves: rhbz#1097775 - Add logrotate permissions for creating netlink selinux sockets. Resolves: rhbz#1283134 - Allow lsmd_plugin_t to exec ldconfig. Resolves: rhbz#1238066 - Allow vnstatd domain to read /sys/class/net/ files Resolves: rhbz#1358243 - Remove duplicate allow rules in spamassassin SELinux module Resolves:rhbz#1358175 - Allow spamc_t and spamd_t domains create .spamassassin file in user homedirs Resolves:rhbz#1358175 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857 - Add new MLS attribute to allow relabeling objects higher than system low. This exception is needed for package managers when processing sensitive data. Resolves: rhbz#1330464 - Allow gnome-keyring also manage user_tmp_t sockets. Resolves: rhbz#1257057 - corecmd: Remove fcontext for /etc/sysconfig/libvirtd Resolves:rhbz#1351382- Allow ipa_dnskey domain to search cache dirs Resolves: rhbz#1350957- Allow ipa-dnskey read system state. Reasolves: rhbz#1350957 - Allow dogtag-ipa-ca-renew-agent-submit labeled as certmonger_t to create /var/log/ipa/renew.log file Resolves: rhbz#1350957- Allow firewalld to manage net_conf_t files. Resolves:rhbz#1304723 - Allow logrotate read logs inside containers. Resolves: rhbz#1303514 - Allow sssd to getattr on fs_t Resolves: rhbz#1356082 - Allow opendnssec domain to manage bind chace files Resolves: rhbz#1350957 - Fix typo in rhsmcertd policy module Resolves: rhbz#1329475 - Allow systemd to get status of systemd-logind daemon Resolves: rhbz#1356141 - Label more ndctl devices not just ndctl0 Resolves: rhbz#1355809- Allow rhsmcertd to copy certs into /etc/docker/cert.d - Add interface docker_rw_config() Resolves: rhbz#1344500 - Fix logrotate fc file to label also /var/lib/logrotate/ dir as logrotate_var_lib_t Resolves: rhbz#1355632 - Allow rhsmcertd to read network sysctls Resolves: rhbz#1329475 - Label /var/log/graphite-web dir as httpd_log_t Resolves: rhbz#1310898 - Allow mock to use generic ptys Resolves: rhbz#1271209 - Allow adcli running as sssd_t to write krb5.keytab file. Resolves: rhbz#1356082 - Allow openvswitch connect to openvswitch_port_t type. Resolves: rhbz#1335024 - Add SELinux policy for opendnssec service. Resolves: rhbz#1350957 - Create new SELinux type for /usr/libexec/ipa/ipa-dnskeysyncd Resolves: rhbz#1350957 - label /dev/ndctl0 device as nvram_device_t Resolves: rhbz#1355809- Allow lttng tools to block suspending Resolves: rhbz#1256374 - Allow creation of vpnaas in openstack Resolves: rhbz#1352710 - virt: add strict policy for virtlogd daemon Resolves:rhbz#1311606 - Update makefile to support snapperd_contexts file Resolves: rhbz#1352681- Allow udev to manage systemd-hwdb files - Add interface systemd_hwdb_manage_config() Resolves: rhbz#1350756 - Fix paths to infiniband devices. This allows use more then two infiniband interfaces. Resolves: rhbz#1210263- Allow virtual machines to rw infiniband devices. Resolves: rhbz#1210263 - Allow opensm daemon to rw infiniband_mgmt_device_t Resolves: rhbz#1210263 - Allow systemd_hwdb_t to relabel /etc/udev/hwdb.bin file. Resolves: rhbz#1350756 - Make label for new infiniband_mgmt deivices Resolves: rhbz#1210263- Fix typo in brltty SELinux module - Add new SELinux module sbd Resolves: rhbz#1322725 - Allow pcp dmcache metrics collection Resolves: rhbz#1309883 - Allow pkcs_slotd_t to create dir in /var/lock Add label pkcs_slotd_log_t Resolves: rhbz#1350782 - Allow openvpn to create sock files labeled as openvpn_var_run_t Resolves: rhbz#1328246 - Allow hypervkvp daemon to getattr on all filesystem types. Resolves: rhbz#1349356 - Allow firewalld to create net_conf_t files Resolves: rhbz#1304723 - Allow mock to use lvm Resolves: rhbz#1271209 - Allow keepalived to create netlink generic sockets. Resolves: rhbz#1349809 - Allow mirromanager creating log files in /tmp Resolves:rhbz#1328818 - Rename few modules to make it consistent with source files Resolves: rhbz#1351445 - Allow vmtools_t to transition to rpm_script domain Resolves: rhbz#1342119 - Allow nsd daemon to manage nsd_conf_t dirs and files Resolves: rhbz#1349791 - Allow cluster to create dirs in /var/run labeled as cluster_var_run_t Resolves: rhbz#1346900 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535 - Dontaudit su_role_template interface to getattr /proc/kcore Dontaudit su_role_template interface to getattr /dev/initctl Resolves: rhbz#1086240 - Add interface lvm_getattr_exec_files() Resolves: rhbz#1271209 - Fix typo Compliling vs. Compiling Resolves: rhbz#1351445- Allow krb5kdc_t to communicate with sssd Resolves: rhbz#1319933 - Allow prosody to bind on prosody ports Resolves: rhbz#1304664 - Add dac_override caps for fail2ban-client Resolves: rhbz#1316678 - dontaudit read access for svirt_t on the file /var/db/nscd/group Resolves: rhbz#1301637 - Allow inetd child process to communicate via dbus with systemd-logind Resolves: rhbz#1333726 - Add label for brltty log file Resolves: rhbz#1328818 - Allow dspam to read the passwd file Resolves: rhbz#1286020 - Allow snort_t to communicate with sssd Resolves: rhbz#1284908 - svirt_sandbox_domains need to be able to execmod for badly built libraries. Resolves: rhbz#1206339 - Add policy for lttng-tools package. Resolves: rhbz#1256374 - Make mirrormanager as application domain. Resolves: rhbz#1328234 - Add support for the default lttng-sessiond port - tcp/5345. This port is used by LTTng 2.x central tracing registry session daemon. - Add prosody ports Resolves: rhbz#1304664 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535- Label /var/lib/softhsm as named_cache_t. Allow named_t to manage named_cache_t dirs. Resolves:rhbz#1331315 - Label named-pkcs11 binary as named_exec_t. Resolves: rhbz#1331315 - Allow glusterd daemon to get systemd status Resolves: rhbz#1321785 - Allow logrotate dbus-chat with system_logind daemon Resolves: rhbz#1283134 - Allow pcp_pmlogger to read kernel network state Allow pcp_pmcd to read cron pid files Resolves: rhbz#1336211 - Add interface cron_read_pid_files() Resolves: rhbz#1336211 - Allow pcp_pmlogger to create unix dgram sockets Resolves: rhbz#1336211 - Add hwloc-dump-hwdata SELinux policy Resolves: rhbz#1344054 - Remove non-existing jabberd_spool_t() interface and add new jabbertd_var_spool_t. Resolves: rhbz#1121171 - Remove non-existing interface salk_resetd_systemctl() and replace it with sanlock_systemctl_sanlk_resetd() Resolves: rhbz#1259764 - Create label for openhpid log files. esolves: rhbz#1259764 - Label /var/lib/ganglia as httpd_var_lib_t Resolves: rhbz#1260536 - Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Include patch from distgit repo: policy-RHEL-7.1-flask.patch. Resolves: rhbz#1329560 - Update refpolicy to handle hwloc Resolves: rhbz#1344054 - Label /etc/dhcp/scripts dir as bin_t - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255- Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Allow mongod log to syslog. Resolves: rhbz#1306995 - Allow rhsmcertd connect to port tcp 9090 Resolves: rhbz#1337319 - Label for /bin/mail(x) was removed but /usr/bin/mail(x) not. This path is also needed to remove. Resolves: rhbz#1262483 Resolves: rhbz#1277506 - Label /usr/libexec/mimedefang-wrapper as spamd_exec_t. Resolves: rhbz#1301516 - Add new boolean spamd_update_can_network. Resolves: rhbz#1305469 - Allow rhsmcertd connect to tcp netport_port_t Resolves: rhbz#1329475 - Fix SELinux context for /usr/share/mirrormanager/server/mirrormanager to Label all binaries under dir as mirrormanager_exec_t. Resolves: rhbz#1328234 - Allow prosody to bind to fac_restore tcp port. Resolves: rhbz#1321787 - Allow ninfod to read raw packets Resolves: rhbz#1317964 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1260835 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1271159 - Allow tuned to use policykit. This change is required by cockpit. Resolves: rhbz#1346464 - Allow conman_t to read dir with conman_unconfined_script_t binary files. Resolves: rhbz#1297323 - Allow pegasus to read /proc/sysinfo. Resolves: rhbz#1265883 - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255 - Label tcp ports:16379, 26379 as redis_port_t Resolves: rhbz#1348471 - Allow systemd to relabel /var and /var/lib directories during boot. - Add files_relabel_var_dirs() and files_relabel_var_dirs() interfaces. - Add files_relabelto_var_lib_dirs() interface. - Label tcp port 2004 as mailbox_port_t. Resolves: rhbz#1332843 - Label tcp and udp port 5582 as fac_restore_port_t Resolves: rhbz#1321787 - Allow sysadm_t user to run postgresql-setup. Resolves: rhbz#1282543 - Allow sysadm_t user to dbus chat with oddjob_t. This allows confined admin run oddjob mkhomedirfor script. Resolves: rhbz#1297480 - Update netlink socket classes.- Allow conman to kill conman_unconfined_script. Resolves: rhbz#1297323 - Make conman_unconfined_script_t as init_system_domain. Resolves:rhbz#1297323 - Allow init dbus chat with apmd. Resolves:rhbz#995898 - Patch /var/lib/rpm is symlink to /usr/share/rpm on Atomic, due to this change we need to label also /usr/share/rpm as rpm_var_lib_t. Resolves: rhbz#1233252 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Add mediawiki rules to proper scope Resolves: rhbz#1301186 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Allow mysqld_safe to inherit rlimit information from mysqld Resolves: rhbz#1323673 - Allow collectd_t to stream connect to postgresql. Resolves: rhbz#1344056 - Allow mediawiki-script to read /etc/passwd file. Resolves: rhbz#1301186 - Add filetrans rule that NetworkManager_t can create net_conf_t files in /etc. Resolves: rhbz#1344505 - Add labels for mediawiki123 Resolves: rhbz#1293872 - Fix label for all fence_scsi_check scripts - Allow ip netns to mounton root fs and unmount proc_t fs. Resolves: rhbz#1343776 Resolves: rhbz#1286851 - Allow sysadm_t to run newaliases command. Resolves: rhbz#1344828 - Add interface sysnet_filetrans_named_net_conf() Resolves: rhbz#1344505- Fix several issues related to the SELinux Userspace changes- Allow glusterd domain read krb5_keytab_t files. Resolves: rhbz#1343929 - Fix typo in files_setattr_non_security_dirs. Resolves: rhbz#1115987- Allow tmpreaper_t to read/setattr all non_security_file_type dirs Resolves: rhbz#1115987 - Allow firewalld to create firewalld_var_run_t directory. Resolves: rhbz#1304723 - Add interface firewalld_read_pid_files() Resolves: rhbz#1304723 - Label /usr/libexec/rpm-ostreed as rpm_exec_t. Resolves: rhbz#1340542 - Allow sanlock service to read/write cephfs_t files. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - Add interface files_setattr_non_security_dirs() Resolves: rhbz#1115987 - Add support for onloadfs - Allow iptables to read firewalld pid files. Resolves: rhbz#1304723 - Add SELinux support for ceph filesystem. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) Resolves: rhbz#1236580- Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - New interfaces needed for systemd-machinectl Resolves: rhbz#1236580 - New interfaces needed by systemd-machine Resolves: rhbz#1236580 - Add interface allowing sending and receiving messages from virt over dbus. Resolves: rhbz#1236580 - Backport docker policy from Fedora. Related: #1303123 Resolves: #1341257 - Allow NetworkManager_t and policykit_t read access to systemd-machined pid files. Resolves: rhbz#1236580 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added interfaces needed by new docker policy. Related: rhbz#1303123 - Add support for systemd-machined daemon Resolves: rhbz#1236580 - Allow rpm-ostree domain transition to install_t domain from init_t. Resolves: rhbz#1340542- dnsmasq: allow NetworkManager to control dnsmasq via D-Bus Resolves: rhbz#1336722 - Directory Server (389-ds-base) has been updated to use systemd-ask-password. In order to function correctly we need the following added to dirsrv.te Resolves: rhbz#1333198 - sftpd_* booleans are functionless these days. Resolves: rhbz#1335656 - Label /var/log/ganesha.log as gluster_log_t Allow glusterd_t domain to create glusterd_log_t files. Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737 - Label /usr/libexec/storaged/storaged as lvm_exec_t to run storaged daemon in lvm_t SELinux domain. Resolves: rhbz#1264390 - Allow systemd_hostanmed_t to read /proc/sysinfo labeled as sysctl_t. Resolves: rhbz#1337061 - Revert "Allow all domains some process flags." Resolves: rhbz#1303644 - Revert "Remove setrlimit to all domains." Resolves: rhbz#1303644 - Label /usr/sbin/xrdp* files as bin_t Resolves: rhbz#1276777 - Add mls support for some db classes Resolves: rhbz#1303651 - Allow systemd_resolved_t to check if ipv6 is disabled. Resolves: rhbz#1236579 - Allow systemd_resolved to read systemd_networkd run files. Resolves: rhbz#1236579- Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737- Allow logwatch to domtrans to postqueue Resolves: rhbz#1331542 - Label /var/log/ganesha.log as gluster_log_t - Allow glusterd_t domain to create glusterd_log_t files. - Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow zabbix to connect to postgresql port Resolves: rhbz#1330479 - Add userdom_destroy_unpriv_user_shared_mem() interface. Related: rhbz#1306403 - systemd-logind remove all IPC objects owned by a user on a logout. This covers also SysV memory. This change allows to destroy unpriviledged user SysV shared memory segments. Resolves: rhbz#1306403- We need to restore contexts on /etc/passwd*,/etc/group*,/etc/*shadow* during install phase to get proper labeling for these files until selinux-policy pkgs are installed. Resolves: rhbz#1333952- Add interface glusterd_dontaudit_read_lib_dirs() Resolves: rhbz#1295680 - Dontaudit Occasionally observing AVC's while running geo-rep automation Resolves: rhbz#1295680 - Allow glusterd to manage socket files labeled as glusterd_brick_t. Resolves: rhbz#1331561 - Create new apache content template for files stored in user homedir. This change is needed to make working booleans: - httpd_enable_homedirs - httpd_read_user_content Resolves: rhbz#1246522 - Allow stunnel create log files. Resolves: rhbz#1296851 - Label tcp port 8181 as intermapper_port_t. Resolves: rhbz#1334783 - Label tcp/udp port 2024 as xinuexpansion4_port_t Resolves: rhbz#1334783 - Label tcp port 7002 as afs_pt_port_t Label tcp/udp port 2023 as xinuexpansion3_port_t Resolves: rhbz#1334783 - Dontaudit ldconfig read gluster lib files. Resolves: rhbz#1295680 - Add interface auth_use_nsswitch() to systemd_domain_template. Resolves: rhbz#1236579- Label /usr/bin/ganesha.nfsd as glusterd_exec_t to run ganesha as glusterd_t. Allow glusterd_t stream connect to rpbind_t. Allow cluster_t to create symlink /var/lib/nfs labeled as var_lib_nfs_t. Add interface rpc_filetrans_var_lib_nfs_content() Add new boolean: rpcd_use_fusefs to allow rpcd daemon use fusefs. Resolves: rhbz#1312809 Resolves: rhbz#1323947 - Allow dbus chat between httpd_t and oddjob_t. Resolves: rhbz#1324144 - Label /usr/libexec/ipa/oddjob/org.freeipa.server.conncheck as ipa_helper_exec_t. Resolves: rhbz#1324144 - Label /var/log/ipareplica-conncheck.log file as ipa_log_t Allow ipa_helper_t domain to manage logs labeledas ipa_log_t Allow ipa_helper_t to connect on http and kerberos_passwd ports. Resolves: rhbz#1324144 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow pcp_pmcd_t domain to manage docker lib files. This rule is needed to allow pcp to collect container information when SELinux is enabled. Resolves: rhbz#1309454- Allow runnig php7 in fpm mode. From selinux-policy side, we need to allow httpd to read/write hugetlbfs. Resolves: rhbz#1319442 - Allow openvswitch daemons to run under openvswitch Linux user instead of root. This change needs allow set capabilities: chwon, setgid, setuid, setpcap. Resolves: rhbz#1296640 - Remove ftpd_home_dir() boolean from distro policy. Reason is that we cannot make this working due to m4 macro language limits. Resolves: rhbz#1097775 - /bin/mailx is labeled sendmail_exec_t, and enters the sendmail_t domain on execution. If /usr/sbin/sendmail does not have its own domain to transition to, and is not one of several products whose behavior is allowed by the sendmail_t policy, execution will fail. In this case we need to label /bin/mailx as bin_t. Resolves: rhbz#1262483 - Allow nsd daemon to create log file in /var/log as nsd_log_t Resolves: rhbz#1293140 - Sanlock policy update. - New sub-domain for sanlk-reset daemon Resolves: rhbz#1212324 - Label all run tgtd files, not just socket files Resolves: rhbz#1280280 - Label all run tgtd files, not just socket files. Resolves: rhbz#1280280 - Allow prosody to stream connect to sasl. This will allow using cyrus authentication in prosody. Resolves: rhbz#1321049 - unbound wants to use ephemeral ports as a default configuration. Allow to use also udp sockets. Resolves: rhbz#1318224 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow targetd to read/write to /dev/mapper/control device. Resolves: rhbz#1063714 - Allow KDM to get status about power services. This change allow kdm to be able do shutdown. Resolves: rhbz#1316724 - Allow systemd-resolved daemon creating netlink_route sockets. Resolves:rhbz#1236579 - Allow systemd_resolved_t to read /etc/passwd file. Allow systemd_resolved_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used Resolves: rhbz#1065362 - Label /etc/selinux/(minimum|mls|targeted)/active/ as semanage_store_t Resolves: rhbz#1321943 - Label all nvidia binaries as xserver_exec_t Resolves: rhbz#1322283- Create new permissivedomains CIL module and make it active. Resolves: rhbz#1320451 - Add support for new mock location - /usr/libexec/mock/mock. Resolves: rhbz#1271209 - Allow bitlee to create bitlee_var_t dirs. Resolves: rhbz#1268651 - Allow CIM provider to read sssd public files. Resolves: rhbz#1263339 - Fix some broken interfaces in distro policy. Resolves: rhbz#1121171 - Allow power button to shutdown the laptop. Resolves: rhbz#995898 - Allow lsm plugins to create named fixed disks. Resolves: rhbz#1238066 - Add default labeling for /etc/Pegasus/cimserver_current.conf. It is a correct patch instead of the current /etc/Pegasus/pegasus_current.confResolves: rhbz#1278777 - Allow hyperv domains to rw hyperv devices. Resolves: rhbz#1309361 - Label /var/www/html(/.*)?/wp_backups(/.*)? as httpd_sys_rw_content_t.Resolves: rhbz#1246780 - Create conman_unconfined_script_t type for conman script stored in /use/share/conman/exec/ Resolves: rhbz#1297323 - Fix rule definitions for httpd_can_sendmail boolean. We need to distinguish between base and contrib. - Add support for /dev/mptctl device used to check RAID status. Resolves: rhbz#1258029 - Create hyperv* devices and create rw interfaces for this devices. Resolves: rhbz#1309361 - Add fixes for selinux userspace moving the policy store to /var/lib/selinux. - Remove optional else block for dhcp ping- Allow rsync_export_all_ro boolean to read also non_auth_dirs/files/symlinks. Resolves: rhbz#1263770 - Fix context of "/usr/share/nginx/html". Resolves: rhbz#1261857 - Allow pmdaapache labeled as pcp_pmcd_t access to port 80 for apache diagnostics Resolves: rhbz#1270344 - Allow pmlogger to create pmlogger.primary.socket link file. Resolves: rhbz#1270344 - Label nagios scripts as httpd_sys_script_exec_t. Resolves: rhbz#1260306 - Add dontaudit interface for kdumpctl_tmp_t Resolves: rhbz#1156442 - Allow mdadm read files in EFI partition. Resolves: rhbz#1291801 - Allow nsd_t to bind on nsf_control tcp port. Allow nsd_crond_t to read nsd pid. Resolves: rhbz#1293140 - Label some new nsd binaries as nsd_exec_t Allow nsd domain net_admin cap. Create label nsd_tmp_t for nsd tmp files/dirs Resolves: rhbz#1293140 - Add filename transition that /etc/princap will be created with cupsd_rw_etc_t label in cups_filetrans_named_content() interface. Resolves: rhbz#1265102 - Add missing labeling for /usr/libexec/abrt-hook-ccpp. Resolves: rhbz#1213409 - Allow pcp_pmie and pcp_pmlogger to read all domains state. Resolves: rhbz#1206525 - Label /etc/redis-sentinel.conf as redis_conf_t. Allow redis_t write to redis_conf_t. Allow redis_t to connect on redis tcp port. Resolves: rhbz#1275246 - cockpit has grown content in /var/run directory Resolves: rhbz#1279429 - Allow collectd setgid capability Resolves:#1310898 - Remove declaration of empty booleans in virt policy. Resolves: rhbz#1103153 - Fix typo in drbd policy - Add new drbd file type: drbd_var_run_t. Allow drbd_t to manage drbd_var_run_t files/dirs. Allow drbd_t create drbd_tmp_t files in /tmp. Resolves: rhbz#1134883 - Label /etc/ctdb/events.d/* as ctdb_exec_t. Allow ctdbd_t to setattr on ctdbd_exec_t files. Resolves: rhbz#1293788 - Allow abrt-hook-ccpp to get attributes of all processes because of core_pattern. Resolves: rhbz#1254188 - Allow abrt_t to read sysctl_net_t files. Resolves: rhbz#1254188 - The ABRT coredump handler has code to emulate default core file creation The handler runs in a separate process with abrt_dump_oops_t SELinux process type. abrt-hook-ccpp also saves the core dump file in the very same way as kernel does and a user can specify CWD location for a coredump. abrt-hook-ccpp has been made as a SELinux aware apps to create this coredumps with correct labeling and with this commit the policy rules have been updated to allow access all non security files on a system. - Allow abrt-hook-ccpp to getattr on all executables. - Allow setuid/setgid capabilities for abrt-hook-ccpp. Resolves: rhbz#1254188 - abrt-hook-ccpp needs to have setfscreate access because it is SELinux aware and compute a target labeling. Resolves: rhbz#1254188 - Allow abrt-hook-ccpp to change SELinux user identity for created objects. Resolves: rhbz#1254188 - Dontaudit write access to inherited kdumpctl tmp files. Resolves: rbhz#1156442 - Add interface to allow reading files in efivarfs - contains Linux Kernel configuration options for UEFI systems (UEFI Runtime Variables) Resolves: rhbz#1291801 - Label 8952 tcp port as nsd_control. Resolves: rhbz#1293140 - Allow ipsec to use pam. Resolves: rhbz#1315700 - Allow to log out to gdm after screen was resized in session via vdagent. Resolves: rhbz#1249020 - Allow setrans daemon to read /proc/meminfo. Resolves: rhbz#1316804 - Allow systemd_networkd_t to write kmsg, when kernel was started with following params: systemd.debug systemd.log_level=debug systemd.log_target=kmsg Resolves: rhbz#1298151 - Label tcp port 5355 as llmnr-> Link-Local Multicast Name Resolution Resolves: rhbz#1236579 - Add new selinux policy for systemd-resolved dawmon. Resolves: rhbz#1236579 - Add interface ssh_getattr_server_keys() interface. Resolves: rhbz#1306197 - Allow run sshd-keygen on second boot if first boot fails after some reason and content is not syncedon the disk. These changes are reflecting this commit in sshd. http://pkgs.fedoraproject.org/cgit/rpms/openssh.git/commit/?id=af94f46861844cbd6ba4162115039bebcc8f78ba rhbz#1299106 Resolves: rhbz#1306197 - Allow systemd_notify_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used. Resolves: rhbz#1309417 - Remove bin_t label for /etc/ctdb/events.d/. We need to label this scripts as ctdb_exec_t. Resolves: rhbz#1293788- Prepare selinux-policy package for userspace release 2016-02-23. Resolves: rhbz#1305982- Allow sending dbus msgs between firewalld and system_cronjob domains. Resolves: rhbz#1284902 - Allow zabbix-agentd to connect to following tcp sockets. One of zabbix-agentd functions is get service status of ftp,http,innd,pop,smtp protocols. Resolves: rhbz#1242506 - Add new boolean tmpreaper_use_cifs() to allow tmpreaper to run on local directories being shared with Samba. Resolves: rhbz#1284972 - Add support for systemd-hwdb daemon. Resolves: rhbz#1257940 - Add interface fs_setattr_cifs_dirs(). Resolves: rhbz#1284972- Add new SELinux policy fo targetd daemon. Resolves: rhbz#1063714 - Add new SELinux policy fo ipmievd daemon. Resolves: rhbz#1083031 - Add new SELinux policy fo hsqldb daemon. Resolves: rhbz#1083171 - Add new SELinux policy for blkmapd daemon. Resolves: rhbz#1072997 - Allow p11-child to connect to apache ports. - Label /usr/sbin/lvmlockd binary file as lvm_exec_t. Resolves: rhbz#1278028 - Add interface "lvm_manage_lock" to lvm policy. Resolves: rhbz#1063714- Allow openvswitch domain capability sys_rawio. Resolves: rhbz#1278495- Allow openvswitch to manage hugetlfs files and dirs. Resolves: rhbz#1278495 - Add fs_manage_hugetlbfs_files() interface. Resolves: rhbz#1278495- Allow smbcontrol domain to send sigchld to ctdbd domain. Resolves: #1293784 - Allow openvswitch read/write hugetlb filesystem. Resolves: #1278495Allow hypervvssd to list all mountpoints to have VSS live backup working correctly. Resolves:#1247880- Revert Add missing labeling for /usr/libexec/abrt-hook-ccpp patch Resolves: #1254188- Allow search dirs in sysfs types in kernel_read_security_state. Resolves: #1254188 - Fix kernel_read_security_state interface that source domain of this interface can search sysctl_fs_t dirs. Resolves: #1254188- Add missing labeling for /usr/libexec/abrt-hook-ccpp as a part of #1245477 and #1242467 bugs Resolves: #1254188 - We need allow connect to xserver for all sandbox_x domain because we have one type for all sandbox processes. Resolves:#1261938- Remove labeling for modules_dep_t file contexts to have labeled them as modules_object_t. - Update files_read_kernel_modules() to contain modutils_read_module_deps_files() calling because module deps labeling could remain and it allows to avoid regressions. Resolves:#1266928- We need to require sandbox_web_type attribute in sandbox_x_domain_template(). Resolves: #1261938 - ipsec: The NM helper needs to read the SAs Resolves: #1259786 - ipsec: Allow ipsec management to create ptys Resolves: #1259786- Add temporary fixes for sandbox related to #1103622. It allows to run everything under one sandbox type. Resolves:#1261938 - Allow abrt_t domain to write to kernel msg device. Resolves: #1257828 - Allow rpcbind_t domain to change file owner and group Resolves: #1265266- Allow smbcontrol to create a socket in /var/samba which uses for a communication with smbd, nmbd and winbind. Resolves: #1256459- Allow dirsrv-admin script to read passwd file. Allow dirsrv-admin script to read httpd pid files. Label dirsrv-admin unit file and allow dirsrv-admin domains to use it. Resolves: #1230300 - Allow qpid daemon to connect on amqp tcp port. Resolves: #1261805- Label /etc/ipa/nssdb dir as cert_t Resolves:#1262718 - Do not provide docker policy files which is shipped by docker-selinux.rpm Resolves:#1262812- Add labels for afs binaries: dafileserver, davolserver, salvageserver, dasalvager Resolves: #1192338 - Add lsmd_plugin_t sys_admin capability, Allow lsmd_plugin_t getattr from sysfs filesystem. Resolves: #1238079 - Allow rhsmcertd_t send signull to unconfined_service_t domains. Resolves: #1176078 - Remove file transition from snmp_manage_var_lib_dirs() interface which created snmp_var_lib_t dirs in var_lib_t. - Allow openhpid_t daemon to manage snmp files and dirs. Resolves: #1243902 - Allow mdadm_t domain read/write to general ptys and unallocated ttys. Resolves: #1073314 - Add interface unconfined_server_signull() to allow domains send signull to unconfined_service_t Resolves: #1176078- Allow systemd-udevd to access netlink_route_socket to change names for network interfaces without unconfined.pp module. It affects also MLS. Resolves:#1250456- Fix labeling for fence_scsi_check script Resolves: #1255020 - Allow openhpid to read system state Allow openhpid to connect to tcp http port. Resolves: #1244248 - Allow openhpid to read snmp var lib files. Resolves: #1243902 - Allow openvswitch_t domains read kernel dependencies due to openvswitch run modprobe - Allow unconfined_t domains to create /var/run/xtables.lock with iptables_var_run_t Resolves: #1243403 - Remove bin_t label for /usr/share/cluster/fence_scsi_check\.pl Resolves: #1255020- Fix regexp in chronyd.fc file Resolves: #1243764 - Allow passenger to getattr filesystem xattr Resolves: #1196555 - Label mdadm.conf.anackbak as mdadm_conf_t file. Resolves: #1088904 - Revert "Allow pegasus_openlmi_storage_t create mdadm.conf.anacbak file in /etc." - Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Remove labeling for /var/db/.*\.db as etc_t to label db files as system_db_t. Resolves: #1230877- Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Label /var/run/chrony-helper dir as chronyd_var_run_t. Resolves: #1243764 - Allow dhcpc_t domain transition to chronyd_t Resolves: #1243764- Fix postfix_spool_maildrop_t,postfix_spool_flush_t contexts in postfix.fc file. Resolves: #1252442- Allow exec pidof under hypervkvp domain. Resolves: #1254870 - Allow hypervkvp daemon create connection to the system DBUS Resolves: #1254870- Allow openhpid_t to read system state. Resolves: #1244248 - Added labels for files provided by rh-nginx18 collection Resolves: #1249945 - Dontaudit block_suspend capability for ipa_helper_t, this is kernel bug. Allow ipa_helper_t capability net_admin. Allow ipa_helper_t to list /tmp. Allow ipa_helper_t to read rpm db. Resolves: #1252968 - Allow rhsmcertd exec rhsmcertd_var_run_t files and rhsmcerd_tmp_t files. This rules are in hide_broken_sympthons until we find better solution. Resolves: #1243431 - Allow abrt_dump_oops_t to read proc_security_t files. - Allow abrt_dump_oops to signull all domains Allow abrt_dump_oops to read all domains state Allow abrt_dump_oops to ptrace all domains - Add interface abrt_dump_oops_domtrans() - Add mountpoint dontaudit access check in rhsmcertd policy. Resolves: #1243431 - Allow samba_net_t to manage samba_var_t sock files. Resolves: #1252937 - Allow chrome setcap to itself. Resolves: #1251996 - Allow httpd daemon to manage httpd_var_lib_t lnk_files. Resolves: #1253706 - Allow chronyd exec systemctl Resolves: #1243764 - Add inteface chronyd_signal Allow timemaster_t send generic signals to chronyd_t. Resolves: #1243764 - Added interface fs_dontaudit_write_configfs_dirs - Add label for kernel module dep files in /usr/lib/modules Resolves:#916635 - Allow kernel_t domtrans to abrt_dump_oops_t - Added to files_dontaudit_write_all_mountpoints intefface new dontaudit rule, that domain included this interface dontaudit capability dac_override. - Allow systemd-networkd to send logs to systemd-journald. Resolves: #1236616- Fix label on /var/tmp/kiprop_0 Resolves:#1220763 - Allow lldpad_t to getattr tmpfs_t. Resolves: #1246220 - Label /dev/shm/lldpad.* as lldapd_tmpfs_t Resolves: #1246220 - Allow audisp client to read system state.- Allow pcp_domain to manage pcp_var_lib_t lnk_files. Resolves: #1252341 - Label /var/run/xtables.* as iptables_var_run_t Resolves: #1243403- Add interface to read/write watchdog device - Add labels for /dev/memory_bandwith and /dev/vhci. Thanks ssekidde Resolves:#1210237 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow logrotate to reload services. Resolves: #1242453 - Allow openhpid use libwatchdog plugin. (Allow openhpid_t rw watchdog device) Resolves: #1244260 - Allow openhpid liboa_soap plugin to read generic certs. Resolves: #1244248 - Allow openhpid liboa_soap plugin to read resolv.conf file. Resolves: #1244248 - Label /usr/libexec/chrony-helper as chronyd_exec_t - Allow chronyd_t to read dhcpc state. - Allow chronyd to execute mkdir command.- Allow mdadm to access /dev/random and add support to create own files/dirs as mdadm_tmpfs_t. Resolves:#1073314 - Allow udev, lvm and fsadm to access systemd-cat in /var/tmp/dracut if 'dracut -fv' is executed in MLS. - Allow admin SELinu users to communicate with kernel_t. It is needed to access /run/systemd/journal/stdout if 'dracut -vf' is executed. We allow it for other SELinux users. - Allow sysadm to execute systemd-sysctl in the sysadm_t domain. It is needed for ifup command in MLS mode. - Add fstools_filetrans_named_content_fsadm() and call it for named_filetrans_domain domains. We need to be sure that /run/blkid is created with correct labeling. Resolves:#1183503 - Add support for /etc/sanlock which is writable by sanlock daemon. Resolves:#1231377 - Allow useradd add homedir located in /var/lib/kdcproxy in ipa-server RPM scriplet. Resolves:#1243775 - Allow snapperd to pass data (one way only) via pipe negotiated over dbus Resolves:#1250550 - Allow lsmd also setuid capability. Some commands need to executed under root privs. Other commands are executed under unprivileged user.- Allow openhpid to use libsnmp_bc plugin (allow read snmp lib files). Resolves: #1243902 - Allow lsm_plugin_t to read sysfs, read hwdata, rw to scsi_generic_device Resolves: #1238079 - Allow lsm_plugin_t to rw raw_fixed_disk. Resolves:#1238079 - Allow rhsmcertd to send signull to unconfined_service.- Allow httpd_suexec_t to read and write Apache stream sockets Resolves: #1243569 - Allow qpid to create lnk_files in qpid_var_lib_t Resolves: #1247279- Allow drbd to get attributes from filesystems. - Allow redis to read kernel parameters. Resolves: #1209518 - Allow virt_qemu_ga_t domtrans to passwd_t - Allow audisp_remote_t to start power unit files domain to allow halt system. Resolves: #1186780 - Allow audisp_remote_t to read/write user domain pty. Resolves: #1186780 - Label /usr/sbin/chpasswd as passwd_exec_t. - Allow sysadm to administrate ldap environment and allow to bind ldap port to allow to setup an LDAP server (389ds). Resolves:#1221121- gnome_dontaudit_search_config() needs to be a part of optinal_policy in pegasus.te - Allow pcp_pmcd daemon to read postfix config files. - Allow pcp_pmcd daemon to search postfix spool dirs. Resolves: #1213740 - Added Booleans: pcp_read_generic_logs. Resolves: #1213740 - Allow drbd to read configuration options used when loading modules. Resolves: #1134883 - Allow glusterd to manage nfsd and rpcd services. - Allow glusterd to communicate with cluster domains over stream socket. - glusterd call pcs utility which calls find for cib.* files and runs pstree under glusterd. Dontaudit access to security files and update gluster boolean to reflect these changes.- Allow glusterd to manage nfsd and rpcd services. - Allow networkmanager to communicate via dbus with systemd_hostanmed. Resolves: #1234954 - Allow stream connect logrotate to prosody. - Add prosody_stream_connect() interface. - httpd should be able to send signal/signull to httpd_suexec_t, instead of httpd_suexec_exec_t. - Allow prosody to create own tmp files/dirs. Resolves:#1212498- Allow networkmanager read rfcomm port. Resolves:#1212498 - Remove non exists label. - Fix *_admin intefaces where body is not consistent with header. - Label /usr/afs/ as afs_files_t, Allow afs_bosserver_t create afs_config_t and afs_dbdir_t dirs under afs_files_t, Allow afs_bosserver_t read kerberos config - Remove non exits nfsd_ro_t label. - Make all interfaces related to openshift_cache_t as deprecated. - Add rpm_var_run_t label to rpm_admin header - Add jabberd_lock_t label to jabberd_admin header. - Add samba_unconfined_script_exec_t to samba_admin header. - inn daemon should create innd_log_t objects in var_log_t instead of innd_var_run_t - Fix ctdb policy - Add samba_signull_winbind() - Add samba_signull_unconfined_net() - Allow ctdbd_t send signull to samba_unconfined_net_t. - Allow openshift_initrc_t to communicate with firewalld over dbus Resolves:#1221326- Allow gluster to connect to all ports. It is required by random services executed by gluster. - Add interfaces winbind_signull(), samba_unconfined_net_signull(). - Dontaudit smbd_t block_suspend capability. This is kernel bug. - Allow ctdbd sending signull to process winbind, samba_unconfined_net, to checking if processes exists. - Add tmpreaper booleans to use nfs_t and samba_share_t. - Fix path from /usr/sbin/redis-server to /usr/bin/redis-server - Allow connect ypserv to portmap_port_t - Fix paths in inn policy, Allow innd read innd_log_t dirs, Allow innd execute innd_etc_t files - Add support for openstack-nova-* packages - Allow NetworkManager_t send signull to dnssec_trigger_t. - Allow glusterd to execute showmount in the showmount domain. - Label swift-container-reconciler binary as swift_t. - Allow dnssec_trigger_t relabelfrom dnssec_trigger_var_run_t files. - Add cobbler_var_lib_t to "/var/lib/tftpboot/boot(/.*)?" Resolves:#1213540 - Merge all nova_* labels under one nova_t.- Add logging_syslogd_run_nagios_plugins boolean for rsyslog to allow transition to nagios unconfined plugins Resolves:#1233550 - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/ - Add support for oddjob based helper in FreeIPA. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add nagios_domtrans_unconfined_plugins() interface. - Update mta_filetrans_named_content() interface to cover more db files. Resolves:#1167468 - Add back ftpd_use_passive_mode boolean with fixed description. - Allow pmcd daemon stream connect to mysqld. - Allow pcp domains to connect to own process using unix_stream_socket. Resolves:#1213709 - Allow abrt-upload-watch service to dbus chat with ABRT daemon and fsetid capability to allow run reporter-upload correctly. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add support for oddjob based helper in FreeIPA. - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/- Allow iptables to read ctdbd lib files. Resolves:#1224879 - Add systemd_networkd_t to nsswitch domains. - Allow drbd_t write to fixed_disk_device. Reason: drbdmeta needs write to fixed_disk_device during initialization. Resolves:#1130675 - Allow NetworkManager write to sysfs. - Fix cron_system_cronjob_use_shares boolean to call fs interfaces which contain only entrypoint permission. - Add cron_system_cronjob_use_shares boolean to allow system cronjob to be executed from shares - NFS, CIFS, FUSE. It requires "entrypoint" permissios on nfs_t, cifs_t and fusefs_t SELinux types. - Allow NetworkManager write to sysfs. - Allow ctdb_t sending signull to smbd_t, for checking if smbd process exists. - Dontaudit apache to manage snmpd_var_lib_t files/dirs. - Add interface snmp_dontaudit_manage_snmp_var_lib_files(). - Dontaudit mozilla_plugin_t cap. sys_ptrace. - Rename xodbc-connect port to xodbc_connect - Allow ovsdb-server to connect on xodbc-connect and ovsdb tcp ports. - Allow iscsid write to fifo file kdumpctl_tmp_t. Appears when kdump generates the initramfs during the kernel boot. - Dontaudit chrome to read passwd file. - nrpe needs kill capability to make gluster moniterd nodes working. Resolves:#1235587- We allow can_exec() on ssh_keygen on gluster. But there is a transition defined by init_initrc_domain() because we need to allow execute unconfined services by glusterd. So ssh-keygen ends up with ssh_keygen_t and we need to allow to manage /var/lib/glusterd/geo-replication/secret.pem. - Allow sshd to execute gnome-keyring if there is configured pam_gnome_keyring.so. - Allow gnome-keyring executed by passwd to access /run/user/UID/keyring to change a password. - Label gluster python hooks also as bin_t. - Allow glusterd to interact with gluster tools running in a user domain - Add glusterd_manage_lib_files() interface. - ntop reads /var/lib/ntop/macPrefix.db and it needs dac_override. It has setuid/setgid. - Allow samba_t net_admin capability to make CIFS mount working. - S30samba-start gluster hooks wants to search audit logs. Dontaudit it. Resolves:#1224879- Allow glusterd to send generic signals to systemd_passwd_agent processes. - Allow glusterd to access init scripts/units without defined policy - Allow glusterd to run init scripts. - Allow glusterd to execute /usr/sbin/xfs_dbin glusterd_t domain. Resolves:#1224879- Calling cron_system_entry() in pcp_domain_template needs to be a part of optional_policy block. - Allow samba-net to access /var/lib/ctdbd dirs/files. - Allow glusterd to send a signal to smbd. - Make ctdbd as home manager to access also FUSE. - Allow glusterd to use geo-replication gluster tool. - Allow glusterd to execute ssh-keygen. - Allow glusterd to interact with cluster services. - Allow glusterd to connect to the system DBUS for service (acquire_svc). - Label /dev/log correctly. Resolves:#1230932- Back port the latest F22 changes to RHEL7. It should fix most of RHEL7.2 bugs - Add cgdcbxd policy Resolves:#1072493 - Fix ftp_homedir boolean Resolve:#1097775 - Dontaudit ifconfig writing inhertited /var/log/pluto.log. - Allow cluster domain to dbus chat with systemd-logind. Resolves:#1145215 - Dontaudit write access to inherited kdumpctl tmp files Resolves:#1156442 - Allow isnsd_t to communicate with sssd Resolves:#1167702 - Allow rwho_t to communicate with sssd Resolves:#1167718 - Allow sblim_gatherd_t to communicate with sssd Resolves:#1167732 - Allow pkcs_slotd_t to communicate with sssd Resolves:#1167737 - Allow openvswitch_t to communicate with sssd Resolves:#1167816 - Allow mysqld_safe_t to communicate with sssd Resolves:#1167832 - Allow sshd_keygen_t to communicate with sssd Resolves:#1167840 - Add support for iprdbg logging files in /var/log. Resolves:#1174363 - Allow tmpreaper_t to manage ntp log content Resolves:#1176965 - Allow gssd_t to manage ssh keyring Resolves:#1184791 - Allow httpd_sys_script_t to send system log messages Resolves:#1185231 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow dovecot_t sys_resource capability Resolves:#1191143 - Add support for mongod/mongos systemd unit files. Resolves:#1197038 - Add bacula fixes - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. Resolves:#1203991- Label /usr/libexec/postgresql-ctl as postgresql_exec_t. - Add more restriction on entrypoint for unconfined domains. - Only allow semanage_t to be able to setenforce 0, no all domains that use selinux_semanage interface - Allow all domains to read /dev/urandom. It is needed by all apps/services linked to libgcrypt. There is no harm to allow it by default. - Update policy/mls for sockets related to access perm. Rules were contradictory. - Add nagios_run_pnp4nagios and nagios_run_sudo booleans to allow r un sudo from NRPE utils scripts and allow run nagios in conjunction w ith PNP4Nagios. Resolves:#1201054 - Don't use deprecated userdom_manage_tmpfs_role() interface calliing and use userdom_manage_tmp_role() instead. - Update virt_read_pid_files() interface to allow read also symlinks with virt_var_run_t type - Label /var/lib/tftpboot/aarch64(/.*)? and /var/lib/tftpboot/images2(/.*)? - Add support for iprdbg logging files in /var/log. - Add fixes to rhsmcertd_t - Allow puppetagent_t to transfer firewalld messages over dbus - Add support for /usr/libexec/mongodb-scl-helper RHSCL helper script. - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. - Add support for mongod/mongos systemd unit files. - cloudinit and rhsmcertd need to communicate with dbus - Allow dovecot_t sys_resource capability- ALlow mongod execmem by default. - Update policy/mls for sockets. Rules were contradictory. Resolves:#1207133 - Allow a user to login with different security level via ssh.- Update seutil_manage_config() interface. Resolves:#1185962 - Allow pki-tomcat relabel pki_tomcat_etc_rw_t. - Turn on docker_transition_unconfined by default- Allow virtd to list all mountpoints. Resolves:#1180713- pkcsslotd_lock_t should be an alias for pkcs_slotd_lock_t. - Allow fowner capability for sssd because of selinux_child handling. - ALlow bind to read/write inherited ipsec pipes - Allow hypervkvp to read /dev/urandom and read addition states/config files. - Allow gluster rpm scripletto create glusterd socket with correct labeling. This is a workaround until we get fix in glusterd. - Add glusterd_filetrans_named_pid() interface - Allow radiusd to connect to radsec ports. - Allow setuid/setgid for selinux_child - Allow lsmd plugin to connect to tcp/5988 by default. - Allow lsmd plugin to connect to tcp/5989 by default. - Update ipsec_manage_pid() interface. Resolves:#1184978- Update ipsec_manage_pid() interface. Resolves:#1184978- Allow ntlm_auth running in winbind_helper_t to access /dev/urandom.- Add auditing support for ipsec. Resolves:#1182524 - Label /ostree/deploy/rhel-atomic-host/deploy directory as system_conf_t - Allow netutils chown capability to make tcpdump working with -w- Allow ipsec to execute _updown.netkey script to run unbound-control. - Allow neutron to read rpm DB. - Add additional fixes for hyperkvp * creates new ifcfg-{name} file * Runs hv_set_ifconfig.sh, which does the following * Copies ifcfg-{name} to /etc/sysconfig/network-scripts - Allow svirt to read symbolic links in /sys/fs/cgroups labeled as tmpfs_t - Add labeling for pacemaker.log. - Allow radius to connect/bind radsec ports. - Allow pm-suspend running as virt_qemu_ga to read /var/log/pm-suspend.log - Allow virt_qemu_ga to dbus chat with rpm. - Update virt_read_content() interface to allow read also char devices. - Allow glance-registry to connect to keystone port. Resolves:#1181818- Allow sssd to send dbus all user domains. Resolves:#1172291 - Allow lsm plugin to read certificates. - Fix labeling for keystone CGI scripts. - Make snapperd back as unconfined domain.- Fix bugs in interfaces discovered by sepolicy. - Allow slapd to read /usr/share/cracklib/pw_dict.hwm. - Allow lsm plugins to connect to tcp/18700 by default. - Allow brltty mknod capability to allow create /var/run/brltty/vcsa. - Fix pcp_domain_template() interface. - Fix conman.te. - Allow mon_fsstatd to read /proc/sys/fs/binfmt_misc - Allow glance-scrubber to connect tcp/9191. - Add missing setuid capability for sblim-sfcbd. - Allow pegasus ioctl() on providers. - Add conman_can_network. - Allow chronyd to read chrony conf files located in /run/timemaster/. - Allow radius to bind on tcp/1813 port. - dontaudit block suspend access for openvpn_t - Allow conman to create files/dirs in /tmp. - Update xserver_rw_xdm_keys() interface to have 'setattr'. Resolves:#1172291 - Allow sulogin to read /dev/urandom and /dev/random. - Update radius port definition to have also tcp/18121 - Label prandom as random_device_t. - Allow charon to manage files in /etc/strongimcv labeled as ipsec_conf_t.- Allow virt_qemu_ga_t to execute kmod. - Add missing files_dontaudit_list_security_dirs() for smbd_t in samba_export_all_ro boolean. - Add additionnal MLS attribute for oddjob_mkhomedir to create homedirs. Resolves:#1113725 - Enable OpenStack cinder policy - Add support for /usr/share/vdsm/daemonAdapter - Add support for /var/run/gluster- Remove old pkcsslotd.pp from minimum package - Allow rlogind to use also rlogin ports. - Add support for /usr/libexec/ntpdate-wrapper. Label it as ntpdate_exec_t. - Allow bacula to connect also to postgresql. - Label /usr/libexec/tomcat/server as tomcat_exec_t - Add support for /usr/sbin/ctdbd_wrapper - Add support for /usr/libexec/ppc64-diag/rtas_errd - Allow rpm_script_roles to access system_mail_t - Allow brltty to create /var/run/brltty - Allow lsmd plugin to access netlink_route_socket - Allow smbcontrol to read passwd - Add support for /usr/libexec/sssd/selinux_child and create sssd_selinux_manager_t domain for it Resolves:#1140106 - Allow osad to execute rhn_check - Allow load_policy to rw inherited sssd pipes because of selinux_child - Allow admin SELinux users mounting / as private within a new mount namespace as root in MLS - Add additional fixes for su_restricted_domain_template to make moving to sysadm_r and trying to su working correctly - Add additional booleans substitions- Add seutil_dontaudit_access_check_semanage_module_store() interface Resolves:#1140106 - Update to have all _systemctl() interface also init_reload_services(). - Dontaudit access check on SELinux module store for sssd. - Add labeling for /sbin/iw. - Allow named_filetrans_domain to create ibus directory with correct labeling.- Allow radius to bind tcp/1812 radius port. - Dontaudit list user_tmp files for system_mail_t. - Label virt-who as virtd_exec_t. - Allow rhsmcertd to send a null signal to virt-who running as virtd_t. - Add missing alias for _content_rw_t. Resolves:#1089177 - Allow spamd to access razor-agent.log. - Add fixes for sfcb from libvirt-cim TestOnly bug. - Allow NetworkManager stream connect on openvpn. - Make /usr/bin/vncserver running as unconfined_service_t. - getty_t should be ranged in MLS. Then also local_login_t runs as ranged domain. - Label /etc/docker/certs.d as cert_t.- Label /etc/strongimcv as ipsec_conf_file_t. - Add support for /usr/bin/start-puppet-ca helper script Resolves:#1160727 - Allow rpm scripts to enable/disable transient systemd units. Resolves:#1154613 - Make kpropdas nsswitch domain Resolves:#1153561 - Make all glance domain as nsswitch domains Resolves:#1113281 - Allow selinux_child running as sssd access check on /etc/selinux/targeted/modules/active - Allow access checks on setfiles/load_policy/semanage_lock for selinux_child running as sssd_t Resolves:#1140106- Dontaudit access check on setfiles/load_policy for sssd_t. Resolves:#1140106 - Add kdump_rw_inherited_kdumpctl_tmp_pipes() Resolves:#1156442 - Make linuxptp services as unconfined. - Added new policy linuxptp. Resolves:#1149693 - Label keystone cgi files as keystone_cgi_script_exec_t. Resolves:#1138424 - Make tuned as unconfined domain- Allow guest to connect to libvirt using unix_stream_socket. - Allow all bus client domains to dbus chat with unconfined_service_t. - Allow inetd service without own policy to run in inetd_child_t which is unconfined domain. - Make opensm as nsswitch domain to make it working with sssd. - Allow brctl to read meminfo. - Allow winbind-helper to execute ntlm_auth in the caller domain. Resolves:#1160339 - Make plymouthd as nsswitch domain to make it working with sssd. Resolves:#1160196 - Make drbd as nsswitch domain to make it working with sssd. - Make conman as nsswitch domain to make ipmitool.exp runing as conman_t working. - Add support for /var/lib/sntp directory. - Add fixes to allow docker to create more content in tmpfs ,and donaudit reading /proc - Allow winbind to read usermodehelper - Allow telepathy domains to execute shells and bin_t - Allow gpgdomains to create netlink_kobject_uevent_sockets - Allow mongodb to bind to the mongo port and mongos to run as mongod_t - Allow abrt to read software raid state. - Allow nslcd to execute netstat. - Allow dovecot to create user's home directory when they log into IMAP. - Allow login domains to create kernel keyring with different level.- Allow modemmanger to connectto itself Resolves:#1120152 - Allow pki_tomcat to create link files in /var/lib/pki-ca. Resolves:#1121744 - varnishd needs to have fsetid capability Resolves:#1125165 - Allow snapperd to dbus chat with system cron jobs. Resolves:#1152447 - Allow dovecot to create user's home directory when they log into IMAP Resolves:#1152773 - Add labeling for /usr/sbin/haproxy-systemd-wrapper wrapper to make haproxy running haproxy_t. - ALlow listen and accept on tcp socket for init_t in MLS. Previously it was for xinetd_t. - Allow nslcd to execute netstat. - Add suppor for keepalived unconfined scripts and allow keepalived to read all domain state and kill capability. - Allow nslcd to read /dev/urandom.- Add back kill permisiion for system class Resolves:#1150011- Add back kill permisiion for service class Resolves:#1150011 - Make rhsmcertd_t also as dbus domain. - Allow named to create DNS_25 with correct labeling. - Add cloudform_dontaudit_write_cloud_log() - Call auth_use_nsswitch to apache to read/write cloud-init keys. - Allow cloud-init to dbus chat with certmonger. - Fix path to mon_statd_initrc_t script. - Allow all RHCS services to read system state. - Allow dnssec_trigger_t to execute unbound-control in own domain. - kernel_read_system_state needs to be called with type. Moved it to antivirus.if. - Added policy for mon_statd and mon_procd services. BZ (1077821) - Allow opensm_t to read/write /dev/infiniband/umad1. - Allow mongodb to manage own log files. - Allow neutron connections to system dbus. - Add support for /var/lib/swiftdirectory. - Allow nova-scheduler to read certs. - Allow openvpn to access /sys/fs/cgroup dir. - Allow openvpn to execute systemd-passwd-agent in systemd_passwd_agent_t to make openvpn working with systemd. - Fix samba_export_all_ro/samba_export_all_rw booleans to dontaudit search/read security files. - Add auth_use_nsswitch for portreserve to make it working with sssd. - automount policy is non-base module so it needs to be called in optional block. - ALlow sensord to getattr on sysfs. - Label /usr/share/corosync/corosync as cluster_exec_t. - Allow lmsd_plugin to read passwd file. BZ(1093733) - Allow read antivirus domain all kernel sysctls. - Allow mandb to getattr on file systems - Allow nova-console to connect to mem_cache port. - Make sosreport as unconfined domain. - Allow mondogdb to 'accept' accesses on the tcp_socket port. - ALlow sanlock to send a signal to virtd_t.- Build also MLS policy Resolves:#1138424- Add back kill permisiion for system class - Allow iptables read fail2ban logs. - Fix radius labeled ports - Add userdom_manage_user_tmpfs_files interface - Allow libreswan to connect to VPN via NM-libreswan. - Label 4101 tcp port as brlp port - fix dev_getattr_generic_usb_dev interface - Allow all domains to read fonts - Make sure /run/systemd/generator and system is labeled correctly on creation. - Dontaudit aicuu to search home config dir. - Make keystone_cgi_script_t domain. Resolves:#1138424 - Fix bug in drbd policy, - Added support for cpuplug. - ALlow sanlock_t to read sysfs_t. - Added sendmail_domtrans_unconfined interface - Fix broken interfaces - radiusd wants to write own log files. - Label /usr/libexec/rhsmd as rhsmcertd_exec_t - Allow rhsmcertd send signull to setroubleshoot. - Allow rhsmcertd manage rpm db. - Added policy for blrtty. - Fix keepalived policy - Allow rhev-agentd dbus chat with systemd-logind. - Allow keepalived manage snmp var lib sock files. - Add support for /var/lib/graphite-web - Allow NetworkManager to create Bluetooth SDP sockets - It's going to do the the discovery for DUN service for modems with Bluez 5. - Allow swift to connect to all ephemeral ports by default. - Allow sssd to read selinux config to add SELinux user mapping. - Allow lsmd to search own plguins. - Allow abrt to read /dev/memto generate an unique machine_id and uses sosuploader's algorithm based off dmidecode[1] fields. - ALlow zebra for user/group look-ups. - Allow nova domains to getattr on all filesystems. - Allow collectd sys_ptrace and dac_override caps because of reading of /proc/%i/io for several processes. - Allow pppd to connect to /run/sstpc/sstpc-nm-sstp-service-28025 over unix stream socket. - Allow rhnsd_t to manage also rhnsd config symlinks. - ALlow user mail domains to create dead.letter. - Allow rabbitmq_t read rabbitmq_var_lib_t lnk files. - Allow pki-tomcat to change SELinux object identity. - Allow radious to connect to apache ports to do OCSP check - Allow git cgi scripts to create content in /tmp - Allow cockpit-session to do GSSAPI logins. - Allow sensord read in /proc - Additional access required by usbmuxd- Allow locate to look at files/directories without labels, and chr_file and blk_file on non dev file systems - Label /usr/lib/erlang/erts.*/bin files as bin_t - Add files_dontaudit_access_check_home_dir() inteface. - Allow udev_t mounton udev_var_run_t dirs #(1128618) - Add systemd_networkd_var_run_t labeling for /var/run/systemd/netif and allow systemd-networkd to manage it. - Add init_dontaudit_read_state() interface. - Add label for ~/.local/share/fonts - Allow unconfined_r to access unconfined_service_t. - Allow init to read all config files - Add new interface to allow creation of file with lib_t type - Assign rabbitmq port. - Allow unconfined_service_t to dbus chat with all dbus domains - Add new interfaces to access users keys. - Allow domains to are allowed to mounton proc to mount on files as well as dirs - Fix labeling for HOME_DIR/tmp and HOME_DIR/.tmp directories. - Add a port definition for shellinaboxd - Label ~/tmp and ~/.tmp directories in user tmp dirs as user_tmp_t - Allow userdomains to stream connect to pcscd for smart cards - Allow programs to use pam to search through user_tmp_t dires (/tmp/.X11-unix) - Update to rawhide-contrib changes Resolves:#1123844- Rebase to 3.13.1 which we have in Fedora21 Resolves:#1128284- Back port fixes from Fedora. Mainly OpenStack and Docker fixes- Add policy-rhel-7.1-{base,contrib} patches- Add support for us_cli ports - Fix labeling for /var/run/user//gvfs - add support for tcp/9697 - Additional rules required by openstack, needs backport to F20 and RHEL7 - Additional access required by docker - ALlow motion to use tcp/8082 port - Allow init_t to setattr/relabelfrom dhcp state files - Dontaudit antivirus domains read access on all security files by default - Add missing alias for old amavis_etc_t type - Allow block_suspend cap for haproxy - Additional fixes for instack overcloud - Allow OpenStack to read mysqld_db links and connect to MySQL - Remove dup filename rules in gnome.te - Allow sys_chroot cap for httpd_t and setattr on httpd_log_t - Allow iscsid to handle own unit files - Add iscsi_systemctl() - Allow mongod to create also sock_files in /run with correct labeling - Allow httpd to send signull to apache script domains and don't audit leaks - Allow rabbitmq_beam to connect to httpd port - Allow aiccu stream connect to pcscd - Allow dmesg to read hwdata and memory dev - Allow all freeipmi domains to read/write ipmi devices - Allow sblim_sfcbd to use also pegasus-https port - Allow rabbitmq_epmd to manage rabbit_var_log_t files - Allow chronyd to read /sys/class/hwmon/hwmon1/device/temp2_input - Allow docker to status any unit file and allow it to start generic unit files- Change hsperfdata_root to have as user_tmp_t Resolves:#1076523- Fix Multiple same specifications for /var/named/chroot/dev/zero - Add labels for /var/named/chroot_sdb/dev devices - Add support for strongimcv - Use kerberos_keytab_domains in auth_use_nsswitch - Update auth_use_nsswitch to make all these types as kerberos_keytab_domain to - Allow net_raw cap for neutron_t and send sigkill to dnsmasq - Fix ntp_filetrans_named_content for sntp-kod file - Add httpd_dbus_sssd boolean - Dontaudit exec insmod in boinc policy - Rename kerberos_keytab_domain to kerberos_keytab_domains - Add kerberos_keytab_domain() - Fix kerberos_keytab_template() - Make all domains which use kerberos as kerberos_keytab_domain Resolves:#1083670 - Allow kill capability to winbind_t- varnishd wants chown capability - update ntp_filetrans_named_content() interface - Add additional fixes for neutron_t. #1083335 - Dontaudit getattr on proc_kcore_t - Allow pki_tomcat_t to read ipa lib files - Allow named_filetrans_domain to create /var/cache/ibus with correct labelign - Allow init_t run /sbin/augenrules - Add dev_unmount_sysfs_fs and sysnet_manage_ifconfig_run interfaces - Allow unpriv SELinux user to use sandbox - Add default label for /tmp/hsperfdata_root- Add file subs also for /var/home- Allow xauth_t to read user_home_dir_t lnk_file - Add labeling for lightdm-data - Allow certmonger to manage ipa lib files - Add support for /var/lib/ipa - Allow pegasus to getattr virt_content - Added some new rules to pcp policy - Allow chrome_sandbox to execute config_home_t - Add support for ABRT FAF- Allow kdm to send signull to remote_login_t process - Add gear policy - Turn on gear_port_t - Allow cgit to read gitosis lib files by default - Allow vdagent to read xdm state - Allow NM and fcoeadm to talk together over unix_dgram_socket- Back port fixes for pegasus_openlmi_admin_t from rawhide Resolves:#1080973 - Add labels for ostree - Add SELinux awareness for NM - Label /usr/sbin/pwhistory_helper as updpwd_exec_t- add gnome_append_home_config() - Allow thumb to append GNOME config home files - Allow rasdaemon to rw /dev/cpu//msr - fix /var/log/pki file spec - make bacula_t as auth_nsswitch domain - Identify pki_tomcat_cert_t as a cert_type - Define speech-dispater_exec_t as an application executable - Add a new file context for /var/named/chroot/run directory - update storage_filetrans_all_named_dev for sg* devices - Allow auditctl_t to getattr on all removeable devices - Allow nsswitch_domains to stream connect to nmbd - Allow unprivusers to connect to memcached - label /var/lib/dirsrv/scripts-INSTANCE as bin_t- Allow also unpriv user to run vmtools - Allow secadm to read /dev/urandom and meminfo Resolves:#1079250 - Add booleans to allow docker processes to use nfs and samba - Add mdadm_tmpfs support - Dontaudit net_amdin for /usr/lib/jvm/java-1.7.0-openjdk-1.7.0.51-2.4.5.1.el7.x86_64/jre-abrt/bin/java running as pki_tomcat_t - Allow vmware-user-sui to use user ttys - Allow talk 2 users logged via console too - Allow ftp services to manage xferlog_t - Make all pcp domanis as unconfined for RHEL7.0 beucause of new policies - allow anaconda to dbus chat with systemd-localed- allow anaconda to dbus chat with systemd-localed - Add fixes for haproxy based on bperkins@redhat.com - Allow cmirrord to make dmsetup working - Allow NM to execute arping - Allow users to send messages through talk - Add userdom_tmp_role for secadm_t- Add additional fixes for rtas_errd - Fix transitions for tmp/tmpfs in rtas.te - Allow rtas_errd to readl all sysctls- Add support for /var/spool/rhsm/debug - Make virt_sandbox_use_audit as True by default - Allow svirt_sandbox_domains to ptrace themselves- Allow docker containers to manage /var/lib/docker content- Allow docker to read tmpfs_t symlinks - Allow sandbox svirt_lxc_net_t to talk to syslog and to sssd over stream sockets- Allow collectd to talk to libvirt - Allow chrome_sandbox to use leaked unix_stream_sockets - Dontaudit leaks of sockets into chrome_sandbox_t - If you create a cups directory in /var/cache then it should be labeled cups_rw_etc_t - Run vmtools as unconfined domains - Allow snort to manage its log files - Allow systemd_cronjob_t to be entered via bin_t - Allow procman to list doveconf_etc_t - allow keyring daemon to create content in tmpfs directories - Add proper labelling for icedtea-web - vpnc is creating content in networkmanager var run directory - Label sddm as xdm_exec_t to make KDE working again - Allow postgresql to read network state - Allow java running as pki_tomcat to read network sysctls - Fix cgroup.te to allow cgred to read cgconfig_etc_t - Allow beam.smp to use ephemeral ports - Allow winbind to use the nis to authenticate passwords- Make rtas_errd_t as unconfined domain for F20.It needs additional fixes. It runs rpm at least. - Allow net_admin cap for fence_virtd running as fenced_t - Make abrt-java-connector working - Make cimtest script 03_defineVS.py of ComputerSystem group working - Fix git_system_enable_homedirs boolean - Allow munin mail plugins to read network systcl- Allow vmtools_helper_t to execute bin_t - Add support for /usr/share/joomla - /var/lib/containers should be labeled as openshift content for now - Allow docker domains to talk to the login programs, to allow a process to login into the container - Allow install_t do dbus chat with NM - Fix interface names in anaconda.if - Add install_t for anaconda. A new type is a part of anaconda policy - sshd to read network sysctls- Allow zabbix to send system log msgs - Allow init_t to stream connect to ipsec Resolves:#1060775- Add docker_connect_any boolean- Allow unpriv SELinux users to dbus chat with firewalld - Add lvm_write_metadata() - Label /etc/yum.reposd dir as system_conf_t. Should be safe because system_conf_t is base_ro_file_type - Allow pegasus_openlmi_storage_t to write lvm metadata - Add hide_broken_symptoms for kdumpgui because of systemd bug - Make kdumpgui_t as unconfined domain Resolves:#1044299 - Allow docker to connect to tcp/5000- Allow numad to write scan_sleep_millisecs - Turn on entropyd_use_audio boolean by default - Allow cgred to read /etc/cgconfig.conf because it contains templates used together with rules from /etc/cgrules.conf. - Allow lscpu running as rhsmcertd_t to read /proc/sysinfo - Fix label on irclogs in the homedir - Allow kerberos_keytab_domain domains to manage keys until we get sssd fix - Allow postgresql to use ldap - Add missing syslog-conn port - Add support for /dev/vmcp and /dev/sclp Resolves:#1069310- Modify xdm_write_home to allow create files/links in /root with xdm_home_ - Allow virt domains to read network state Resolves:#1072019- Added pcp rules - dontaudit openshift_cron_t searching random directories, should be back ported to RHEL6 - clean up ctdb.te - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow certmonger to list home dirs- Change userdom_use_user_inherited_ttys to userdom_use_user_ttys for systemd-tty-ask - Add sysnet_filetrans_named_content_ifconfig() interface - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow kerberos keytab domains to manage sssd/userdomain keys" - Allow to run ip cmd in neutron_t domain- Allow block_suspend cap2 for systemd-logind and rw dri device - Add labeling for /usr/libexec/nm-libreswan-service - Allow locallogin to rw xdm key to make Virtual Terminal login providing smartcard pin working - Add xserver_rw_xdm_keys() - Allow rpm_script_t to dbus chat also with systemd-located - Fix ipa_stream_connect_otpd() - update lpd_manage_spool() interface - Allow krb5kdc to stream connect to ipa-otpd - Add ipa_stream_connect_otpd() interface - Allow vpnc to unlink NM pids - Add networkmanager_delete_pid_files() - Allow munin plugins to access unconfined plugins - update abrt_filetrans_named_content to cover /var/spool/debug - Label /var/spool/debug as abrt_var_cache_t - Allow rhsmcertd to connect to squid port - Make docker_transition_unconfined as optional boolean - Allow certmonger to list home dirs- Make snapperd as unconfined domain and add additional fixes for it - Remove nsplugin.pp module on upgrade- Add snapperd_home_t for HOME_DIR/.snapshots directory - Make sosreport as unconfined domain - Allow sosreport to execute grub2-probe - Allow NM to manage hostname config file - Allow systemd_timedated_t to dbus chat with rpm_script_t - Allow lsmd plugins to connect to http/ssh/http_cache ports by default - Add lsmd_plugin_connect_any boolean - Allow mozilla_plugin to attempt to set capabilities - Allow lsdm_plugins to use tcp_socket - Dontaudit mozilla plugin from getattr on /proc or /sys - Dontaudit use of the keyring by the services in a sandbox - Dontaudit attempts to sys_ptrace caused by running ps for mysqld_safe_t - Allow rabbitmq_beam to connect to jabber_interserver_port - Allow logwatch_mail_t to transition to qmail_inject and queueu - Added new rules to pcp policy - Allow vmtools_helper_t to change role to system_r - Allow NM to dbus chat with vmtools - Fix couchdb_manage_files() to allow manage couchdb conf files - Add support for /var/run/redis.sock - dontaudit gpg trying to use audit - Allow consolekit to create log directories and files - Fix vmtools policy to allow user roles to access vmtools_helper_t - Allow block_suspend cap2 for ipa-otpd - Allow pkcsslotd to read users state - Add ioctl to init_dontaudit_rw_stream_socket - Add systemd_hostnamed_manage_config() interface - Remove transition for temp dirs created by init_t - gdm-simple-slave uses use setsockopt - sddm-greater is a xdm type program- Add lvm_read_metadata() - Allow auditadm to search /var/log/audit dir - Add lvm_read_metadata() interface - Allow confined users to run vmtools helpers - Fix userdom_common_user_template() - Generic systemd unit scripts do write check on / - Allow init_t to create init_tmp_t in /tmp.This is for temporary content created by generic unit files - Add additional fixes needed for init_t and setup script running in generic unit files - Allow general users to create packet_sockets - added connlcli port - Add init_manage_transient_unit() interface - Allow init_t (generic unit files) to manage rpc state date as we had it for initrc_t - Fix userdomain.te to require passwd class - devicekit_power sends out a signal to all processes on the message bus when power is going down - Dontaudit rendom domains listing /proc and hittping system_map_t - Dontauit leaks of var_t into ifconfig_t - Allow domains that transition to ssh_t to manipulate its keyring - Define oracleasm_t as a device node - Change to handle /root as a symbolic link for os-tree - Allow sysadm_t to create packet_socket, also move some rules to attributes - Add label for openvswitch port - Remove general transition for files/dirs created in /etc/mail which got etc_aliases_t label. - Allow postfix_local to read .forward in pcp lib files - Allow pegasus_openlmi_storage_t to read lvm metadata - Add additional fixes for pegasus_openlmi_storage_t - Allow bumblebee to manage debugfs - Make bumblebee as unconfined domain - Allow snmp to read etc_aliases_t - Allow lscpu running in pegasus_openlmi_storage_t to read /dev/mem - Allow pegasus_openlmi_storage_t to read /proc/1/environ - Dontaudit read gconf files for cupsd_config_t - make vmtools as unconfined domain - Add vmtools_helper_t for helper scripts. Allow vmtools shutdonw a host and run ifconfig. - Allow collectd_t to use a mysql database - Allow ipa-otpd to perform DNS name resolution - Added new policy for keepalived - Allow openlmi-service provider to manage transitient units and allow stream connect to sssd - Add additional fixes new pscs-lite+polkit support - Add labeling for /run/krb5kdc - Change w3c_validator_tmp_t to httpd_w3c_validator_tmp_t in F20 - Allow pcscd to read users proc info - Dontaudit smbd_t sending out random signuls - Add boolean to allow openshift domains to use nfs - Allow w3c_validator to create content in /tmp - zabbix_agent uses nsswitch - Allow procmail and dovecot to work together to deliver mail - Allow spamd to execute files in homedir if boolean turned on - Allow openvswitch to listen on port 6634 - Add net_admin capability in collectd policy - Fixed snapperd policy - Fixed bugsfor pcp policy - Allow dbus_system_domains to be started by init - Fixed some interfaces - Add kerberos_keytab_domain attribute - Fix snapperd_conf_t def- Addopt corenet rules for unbound-anchor to rpm_script_t - Allow runuser to send send audit messages. - Allow postfix-local to search .forward in munin lib dirs - Allow udisks to connect to D-Bus - Allow spamd to connect to spamd port - Fix syntax error in snapper.te - Dontaudit osad to search gconf home files - Allow rhsmcertd to manage /etc/sysconf/rhn director - Fix pcp labeling to accept /usr/bin for all daemon binaries - Fix mcelog_read_log() interface - Allow iscsid to manage iscsi lib files - Allow snapper domtrans to lvm_t. Add support for /etc/snapper and allow snapperd to manage it. - Make tuned_t as unconfined domain for RHEL7.0 - Allow ABRT to read puppet certs - Add sys_time capability for virt-ga - Allow gemu-ga to domtrans to hwclock_t - Allow additional access for virt_qemu_ga_t processes to read system clock and send audit messages - Fix some AVCs in pcp policy - Add to bacula capability setgid and setuid and allow to bind to bacula ports - Changed label from rhnsd_rw_conf_t to rhnsd_conf_t - Add access rhnsd and osad to /etc/sysconfig/rhn - drbdadm executes drbdmeta - Fixes needed for docker - Allow epmd to manage /var/log/rabbitmq/startup_err file - Allow beam.smp connect to amqp port - Modify xdm_write_home to allow create also links as xdm_home_t if the boolean is on true - Allow init_t to manage pluto.ctl because of init_t instead of initrc_t - Allow systemd_tmpfiles_t to manage all non security files on the system - Added labels for bacula ports - Fix label on /dev/vfio/vfio - Add kernel_mounton_messages() interface - init wants to manage lock files for iscsi- Added osad policy - Allow postfix to deliver to procmail - Allow bumblebee to seng kill signal to xserver - Allow vmtools to execute /usr/bin/lsb_release - Allow docker to write system net ctrls - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix pcp.te - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl- Turn on bacula, rhnsd policy - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl - Fixes for *_admin interfaces - Add pegasus_openlmi_storage_var_run_t type def - Add support for /var/run/openlmi-storage - Allow tuned to create syslog.conf with correct labeling - Add httpd_dontaudit_search_dirs boolean - Add support for winbind.service - ALlow also fail2ban-client to read apache logs - Allow vmtools to getattr on all fs - Add support for dey_sapi port - Add logging_filetrans_named_conf() - Allow passwd_t to use ipc_lock, so that it can change the password in gnome-keyring- Update snapper policy - Allow domains to append rkhunter lib files - Allow snapperd to getattr on all fs - Allow xdm to create /var/gdm with correct labeling - Add label for snapper.log - Allow fail2ban-client to read apache log files - Allow thumb_t to execute dbus-daemon in thumb_t- Allow gdm to create /var/gdm with correct labeling - Allow domains to append rkhunterl lib files. #1057982 - Allow systemd_tmpfiles_t net_admin to communicate with journald - Add interface to getattr on an isid_type for any type of file - Update libs_filetrans_named_content() to have support for /usr/lib/debug directory - Allow initrc_t domtrans to authconfig if unconfined is enabled - Allow docker and mount on devpts chr_file - Allow docker to transition to unconfined_t if boolean set - init calling needs to be optional in domain.te - Allow uncofined domain types to handle transient unit files - Fix labeling for vfio devices - Allow net_admin capability and send system log msgs - Allow lldpad send dgram to NM - Add networkmanager_dgram_send() - rkhunter_var_lib_t is correct type - Back port pcp policy from rawhide - Allow openlmi-storage to read removable devices - Allow system cron jobs to manage rkhunter lib files - Add rkhunter_manage_lib_files() - Fix ftpd_use_fusefs boolean to allow manage also symlinks - Allow smbcontrob block_suspend cap2 - Allow slpd to read network and system state info - Allow NM domtrans to iscsid_t if iscsiadm is executed - Allow slapd to send a signal itself - Allow sslget running as pki_ra_t to contact port 8443, the secure port of the CA. - Fix plymouthd_create_log() interface - Add rkhunter policy with files type definition for /var/lib/rkhunter until it is fixed in rkhunter package - Add mozilla_plugin_exec_t for /usr/lib/firefox/plugin-container - Allow postfix and cyrus-imapd to work out of box - Allow fcoemon to talk with unpriv user domain using unix_stream_socket - Dontaudit domains that are calling into journald to net_admin - Add rules to allow vmtools to do what it does - snapperd is D-Bus service - Allow OpenLMI PowerManagement to call 'systemctl --force reboot' - Add haproxy_connect_any boolean - Allow haproxy also to use http cache port by default Resolves:#1058248- Allow apache to write to the owncloud data directory in /var/www/html... - Allow consolekit to create log dir - Add support for icinga CGI scripts - Add support for icinga - Allow kdumpctl_t to create kdump lock file Resolves:#1055634 - Allow kdump to create lnk lock file - Allow nscd_t block_suspen capability - Allow unconfined domain types to manage own transient unit file - Allow systemd domains to handle transient init unit files - Add interfaces to handle transient- Add cron unconfined role support for uncofined SELinux user - Call corenet_udp_bind_all_ports() in milter.te - Allow fence_virtd to connect to zented port - Fix header for mirrormanager_admin() - Allow dkim-milter to bind udp ports - Allow milter domains to send signull itself - Allow block_suspend for yum running as mock_t - Allow beam.smp to manage couchdb files - Add couchdb_manage_files() - Add labeling for /var/log/php_errors.log - Allow bumblebee to stream connect to xserver - Allow bumblebee to send a signal to xserver - gnome-thumbnail to stream connect to bumblebee - Allow xkbcomp running as bumblebee_t to execute bin_t - Allow logrotate to read squid.conf - Additional rules to get docker and lxc to play well with SELinux - Allow bumbleed to connect to xserver port - Allow pegasus_openlmi_storage_t to read hwdata- Allow init_t to work on transitient and snapshot unit files - Add logging_manage_syslog_config() - Update sysnet_dns_name_resolve() to allow connect to dnssec por - Allow pegasus_openlmi_storage_t to read hwdata Resolves:#1031721 - Fix rhcs_rw_cluster_tmpfs() - Allow fenced_t to bind on zented udp port - Added policy for vmtools - Fix mirrormanager_read_lib_files() - Allow mirromanager scripts running as httpd_t to manage mirrormanager pid files - Allow ctdb to create sock files in /var/run/ctdb - Add sblim_filetrans_named_content() interface - Allow rpm scritplets to create /run/gather with correct labeling - Allow gnome keyring domains to create gnome config dirs - Dontaudit read/write to init stream socket for lsmd_plugin_t - Allow automount to read nfs link files - Allow lsm plugins to read/write lsmd stream socket - Allow certmonger to connect ldap port to make IPA CA certificate renewal working. - Add also labeling for /var/run/ctdb - Add missing labeling for /var/lib/ctdb - ALlow tuned to manage syslog.conf. Should be fixed in tuned. #1030446 - Dontaudit hypervkvp to search homedirs - Dontaudit hypervkvp to search admin homedirs - Allow hypervkvp to execute bin_t and ifconfig in the caller domain - Dontaudit xguest_t to read ABRT conf files - Add abrt_dontaudit_read_config() - Allow namespace-init to getattr on fs - Add thumb_role() also for xguest - Add filename transitions to create .spamassassin with correct labeling - Allow apache domain to read mirrormanager pid files - Allow domains to read/write shm and sem owned by mozilla_plugin_t - Allow alsactl to send a generic signal to kernel_t- Add back rpm_run() for unconfined user- Add missing files_create_var_lib_dirs() - Fix typo in ipsec.te - Allow passwd to create directory in /var/lib - Add filename trans also for event21 - Allow iptables command to read /dev/rand - Add sigkill capabilityfor ipsec_t - Add filename transitions for bcache devices - Add additional rules to create /var/log/cron by syslogd_t with correct labeling - Add give everyone full access to all key rings - Add default lvm_var_run_t label for /var/run/multipathd - Fix log labeling to have correct default label for them after logrotate - Labeled ~/.nv/GLCache as being gstreamer output - Allow nagios_system_plugin to read mrtg lib files - Add mrtg_read_lib_files() - Call rhcs_rw_cluster_tmpfs for dlm_controld - Make authconfing as named_filetrans domain - Allow virsh to connect to user process using stream socket - Allow rtas_errd to read rand/urand devices and add chown capability - Fix labeling from /var/run/net-snmpd to correct /var/run/net-snmp Resolves:#1051497 - Add also chown cap for abrt_upload_watch_t. It already has dac_override - Allow sosreport to manage rhsmcertd pid files - Add rhsmcertd_manage_pid_files() - Allow also setgid cap for rpc.gssd - Dontaudit access check for abrt on cert_t - Allow pegasus_openlmi_system providers to dbus chat with systemd-logind- Fix semanage import handling in spec file- Add default lvm_var_run_t label for /var/run/multipathd Resolves:#1051430 - Fix log labeling to have correct default label for them after logrotate - Add files_write_root_dirs - Add new openflow port label for 6653/tcp and 6633/tcp - Add xserver_manage_xkb_libs() - Label tcp/8891 as milter por - Allow gnome_manage_generic_cache_files also create cache_home_t files - Fix aide.log labeling - Fix log labeling to have correct default label for them after logrotate - Allow mysqld-safe write access on /root to make mysqld working - Allow sosreport domtrans to prelikn - Allow OpenvSwitch to connec to openflow ports - Allow NM send dgram to lldpad - Allow hyperv domains to execute shell - Allow lsmd plugins stream connect to lsmd/init - Allow sblim domains to create /run/gather with correct labeling - Allow httpd to read ldap certs - Allow cupsd to send dbus msgs to process with different MLS level - Allow bumblebee to stream connect to apmd - Allow bumblebee to run xkbcomp - Additional allow rules to get libvirt-lxc containers working with docker - Additional allow rules to get libvirt-lxc containers working with docker - Allow docker to getattr on itself - Additional rules needed for sandbox apps - Allow mozilla_plugin to set attributes on usb device if use_spice boolean enabled - httpd should be able to send signal/signull to httpd_suexec_t - Add more fixes for neturon. Domtrans to dnsmasq, iptables. Make neutron as filenamtrans domain.- Add neutron fixes- Allow sshd to write to all process levels in order to change passwd when running at a level - Allow updpwd_t to downgrade /etc/passwd file to s0, if it is not running with this range - Allow apcuspd_t to status and start the power unit file - Allow udev to manage kdump unit file - Added new interface modutils_dontaudit_exec_insmod - Allow cobbler to search dhcp_etc_t directory - systemd_systemctl needs sys_admin capability - Allow sytemd_tmpfiles_t to delete all directories - passwd to create gnome-keyring passwd socket - Add missing zabbix_var_lib_t type - Fix filename trans for zabbixsrv in zabbix.te - Allow fprintd_t to send syslog messages - Add zabbix_var_lib_t for /var/lib/zabbixsrv, also allow zabix to connect to smtp port - Allow mozilla plugin to chat with policykit, needed for spice - Allow gssprozy to change user and gid, as well as read user keyrings - Label upgrades directory under /var/www as httpd_sys_rw_content_t, add other filetrans rules to label content correctly - Allow polipo to connect to http_cache_ports - Allow cron jobs to manage apache var lib content - Allow yppassword to manage the passwd_file_t - Allow showall_t to send itself signals - Allow cobbler to restart dhcpc, dnsmasq and bind services - Allow certmonger to manage home cert files - Add userdom filename trans for user mail domains - Allow apcuspd_t to status and start the power unit file - Allow cgroupdrulesengd to create content in cgoups directories - Allow smbd_t to signull cluster - Allow gluster daemon to create fifo files in glusterd_brick_t and sock_file in glusterd_var_lib_t - Add label for /var/spool/cron.aquota.user - Allow sandbox_x domains to use work with the mozilla plugin semaphore - Added new policy for speech-dispatcher - Added dontaudit rule for insmod_exec_t in rasdaemon policy - Updated rasdaemon policy - Allow system_mail_t to transition to postfix_postdrop_t - Clean up mirrormanager policy - Allow virt_domains to read cert files, needs backport to RHEL7 - Allow sssd to read systemd_login_var_run_t - Allow irc_t to execute shell and bin-t files: - Add new access for mythtv - Allow rsync_t to manage all non auth files - allow modemmanger to read /dev/urand - Allow sandbox apps to attempt to set and get capabilties- Add labeling for /var/lib/servicelog/servicelog.db-journal - Add support for freeipmi port - Add sysadm_u_default_contexts - Make new type to texlive files in homedir - Allow subscription-manager running as sosreport_t to manage rhsmcertd - Additional fixes for docker.te - Remove ability to do mount/sys_admin by default in virt_sandbox domains - New rules required to run docker images within libivrt - Add label for ~/.cvsignore - Change mirrormanager to be run by cron - Add mirrormanager policy - Fixed bumblebee_admin() and mip6d_admin() - Add log support for sensord - Fix typo in docker.te - Allow amanda to do backups over UDP - Allow bumblebee to read /etc/group and clean up bumblebee.te - type transitions with a filename not allowed inside conditionals - Don't allow virt-sandbox tools to use netlink out of the box, needs back port to RHEL7 - Make new type to texlive files in homedir- Allow freeipmi_ipmidetectd_t to use freeipmi port - Update freeipmi_domain_template() - Allow journalctl running as ABRT to read /run/log/journal - Allow NM to read dispatcher.d directory - Update freeipmi policy - Type transitions with a filename not allowed inside conditionals - Allow tor to bind to hplip port - Make new type to texlive files in homedir - Allow zabbix_agent to transition to dmidecode - Add rules for docker - Allow sosreport to send signull to unconfined_t - Add virt_noatsecure and virt_rlimitinh interfaces - Fix labeling in thumb.fc to add support for /usr/lib64/tumbler-1/tumblerddd support for freeipmi port - Add sysadm_u_default_contexts - Add logging_read_syslog_pid() - Fix userdom_manage_home_texlive() interface - Make new type to texlive files in homedir - Add filename transitions for /run and /lock links - Allow virtd to inherit rlimit information Resolves:#975358- Change labeling for /usr/libexec/nm-dispatcher.action to NetworkManager_exec_t Resolves:#1039879 - Add labeling for /usr/lib/systemd/system/mariadb.service - Allow hyperv_domain to read sysfs - Fix ldap_read_certs() interface to allow acess also link files - Add support for /usr/libexec/pegasus/cmpiLMI_Journald-cimprovagt - Allow tuned to run modprobe - Allow portreserve to search /var/lib/sss dir - Add SELinux support for the teamd package contains team network device control daemon. - Dontaudit access check on /proc for bumblebee - Bumblebee wants to load nvidia modules - Fix rpm_named_filetrans_log_files and wine.te - Add conman policy for rawhide - DRM master and input event devices are used by the TakeDevice API - Clean up bumblebee policy - Update pegasus_openlmi_storage_t policy - Add freeipmi_stream_connect() interface - Allow logwatch read madm.conf to support RAID setup - Add raid_read_conf_files() interface - Allow up2date running as rpm_t create up2date log file with rpm_log_t labeling - add rpm_named_filetrans_log_files() interface - Allow dkim-milter to create files/dirs in /tmp - update freeipmi policy - Add policy for freeipmi services - Added rdisc_admin and rdisc_systemctl interfaces - opensm policy clean up - openwsman policy clean up - ninfod policy clean up - Added new policy for ninfod - Added new policy for openwsman - Added rdisc_admin and rdisc_systemctl interfaces - Fix kernel_dontaudit_access_check_proc() - Add support for /dev/uhid - Allow sulogin to get the attributes of initctl and sys_admin cap - Add kernel_dontaudit_access_check_proc() - Fix dev_rw_ipmi_dev() - Fix new interface in devices.if - DRM master and input event devices are used by the TakeDevice API - add dev_rw_inherited_dri() and dev_rw_inherited_input_dev() - Added support for default conman port - Add interfaces for ipmi devices- Allow sosreport to send a signal to ABRT - Add proper aliases for pegasus_openlmi_service_exec_t and pegasus_openlmi_service_t - Label /usr/sbin/htcacheclean as httpd_exec_t Resolves:#1037529 - Added support for rdisc unit file - Add antivirus_db_t labeling for /var/lib/clamav-unofficial-sigs - Allow runuser running as logrotate connections to system DBUS - Label bcache devices as fixed_disk_device_t - Allow systemctl running in ipsec_mgmt_t to access /usr/lib/systemd/system/ipsec.service - Label /usr/lib/systemd/system/ipsec.service as ipsec_mgmt_unit_file_t- Add back setpgid/setsched for sosreport_t- Added fix for clout_init to transition to rpm_script_t (dwalsh@redhat.com)- Dontaudit openshift domains trying to use rawip_sockets, this is caused by a bad check in the kernel. - Allow git_system_t to read git_user_content if the git_system_enable_homedirs boolean is turned on - Add lsmd_plugin_t for lsm plugins - Allow dovecot-deliver to search mountpoints - Add labeling for /etc/mdadm.conf - Allow opelmi admin providers to dbus chat with init_t - Allow sblim domain to read /dev/urandom and /dev/random - Allow apmd to request the kernel load modules - Add glusterd_brick_t type - label mate-keyring-daemon with gkeyringd_exec_t - Add plymouthd_create_log() - Dontaudit leaks from openshift domains into mail domains, needs back port to RHEL6 - Allow sssd to request the kernel loads modules - Allow gpg_agent to use ssh-add - Allow gpg_agent to use ssh-add - Dontaudit access check on /root for myslqd_safe_t - Allow ctdb to getattr on al filesystems - Allow abrt to stream connect to syslog - Allow dnsmasq to list dnsmasq.d directory - Watchdog opens the raw socket - Allow watchdog to read network state info - Dontaudit access check on lvm lock dir - Allow sosreport to send signull to setroubleshootd - Add setroubleshoot_signull() interface - Fix ldap_read_certs() interface - Allow sosreport all signal perms - Allow sosreport to run systemctl - Allow sosreport to dbus chat with rpm - Add glusterd_brick_t files type - Allow zabbix_agentd to read all domain state - Clean up rtas.if - Allow smoltclient to execute ldconfig - Allow sosreport to request the kernel to load a module - Fix userdom_confined_admin_template() - Add back exec_content boolean for secadm, logadm, auditadm - Fix files_filetrans_system_db_named_files() interface - Allow sulogin to getattr on /proc/kcore - Add filename transition also for servicelog.db-journal - Add files_dontaudit_access_check_root() - Add lvm_dontaudit_access_check_lock() interface- Allow watchdog to read /etc/passwd - Allow browser plugins to connect to bumblebee - New policy for bumblebee and freqset - Add new policy for mip6d daemon - Add new policy for opensm daemon - Allow condor domains to read/write condor_master udp_socket - Allow openshift_cron_t to append to openshift log files, label /var/log/openshift - Add back file_pid_filetrans for /var/run/dlm_controld - Allow smbd_t to use inherited tmpfs content - Allow mcelog to use the /dev/cpu device - sosreport runs rpcinfo - sosreport runs subscription-manager - Allow staff_t to run frequency command - Allow systemd_tmpfiles to relabel log directories - Allow staff_t to read xserver_log file - Label hsperfdata_root as tmp_t- More sosreport fixes to make ABRT working- Fix files_dontaudit_unmount_all_mountpoints() - Add support for 2608-2609 tcp/udp ports - Should allow domains to lock the terminal device - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - We need to require passwd rootok - Fix zebra.fc - Fix dnsmasq_filetrans_named_content() interface - Allow all sandbox domains create content in svirt_home_t - Allow zebra domains also create zebra_tmp_t files in /tmp - Add support for new zebra services:isisd,babeld. Add systemd support for zebra services. - Fix labeling on neutron and remove transition to iconfig_t - abrt needs to read mcelog log file - Fix labeling on dnsmasq content - Fix labeling on /etc/dnsmasq.d - Allow glusterd to relabel own lib files - Allow sandbox domains to use pam_rootok, and dontaudit attempts to unmount file systems, this is caused by a bug in systemd - Allow ipc_lock for abrt to run journalctl- Fix config.tgz- Fix passenger_stream_connect interface - setroubleshoot_fixit wants to read network state - Allow procmail_t to connect to dovecot stream sockets - Allow cimprovagt service providers to read network states - Add labeling for /var/run/mariadb - pwauth uses lastlog() to update system's lastlog - Allow account provider to read login records - Add support for texlive2013 - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - Allow passwd_t to connect to gnome keyring to change password - Update mls config files to have cronjobs in the user domains - Remove access checks that systemd does not actually do- Add support for yubikey in homedir - Add support for upd/3052 port - Allow apcupsd to use PowerChute Network Shutdown - Allow lsmd to execute various lsmplugins - Add labeling also for /etc/watchdog\.d where are watchdog scripts located too - Update gluster_export_all_rw boolean to allow relabel all base file types - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling- Add files_relabel_base_file_types() interface - Allow netlabel-config to read passwd - update gluster_export_all_rw boolean to allow relabel all base file types caused by lsetxattr() - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling - Allow pegasus to domtrans to mount_t - Add labeling for unconfined scripts in /usr/libexec/watchdog/scripts - Add support for unconfined watchdog scripts - Allow watchdog to manage own log files- Add label only for redhat.repo instead of /etc/yum.repos.d. But probably we will need to switch for the directory. - Label /etc/yum.repos.d as system_conf_t - Use sysnet_filetrans_named_content in udev.te instead of generic transition for net_conf_t - Allow dac_override for sysadm_screen_t - Allow init_t to read ipsec_conf_t as we had it for initrc_t. Needed by ipsec unit file. - Allow netlabel-config to read meminfo - Add interface to allow docker to mounton file_t - Add new interface to exec unlabeled files - Allow lvm to use docker semaphores - Setup transitons for .xsessions-errors.old - Change labels of files in /var/lib/*/.ssh to transition properly - Allow staff_t and user_t to look at logs using journalctl - pluto wants to manage own log file - Allow pluto running as ipsec_t to create pluto.log - Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Allow dmidecode to read/write /run/lock/subsys/rhsmcertd - Allow rhsmcertd to manage redhat.repo which is now labeled as system.conf. Allow rhsmcertd to manage all log files. - Additional access for docker - Added more rules to sblim policy - Fix kdumpgui_run_bootloader boolean - Allow dspam to connect to lmtp port - Included sfcbd service into sblim policy - rhsmcertd wants to manaage /etc/pki/consumer dir - Add kdumpgui_run_bootloader boolean - Add support for /var/cache/watchdog - Remove virt_domain attribute for virt_qemu_ga_unconfined_t - Fixes for handling libvirt containes - Dontaudit attempts by mysql_safe to write content into / - Dontaudit attempts by system_mail to modify network config - Allow dspam to bind to lmtp ports - Add new policy to allow staff_t and user_t to look at logs using journalctl - Allow apache cgi scripts to list sysfs - Dontaudit attempts to write/delete user_tmp_t files - Allow all antivirus domains to manage also own log dirs - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Add missing permission checks for nscd- Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Add file transition rules for content created by f5link - Rename quantum_port information to neutron - Allow all antivirus domains to manage also own log dirs - Rename quantum_port information to neutron - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Allow sysadm_t to read login information - Allow systemd_tmpfiles to setattr on var_log_t directories - Udpdate Makefile to include systemd_contexts - Add systemd_contexts - Add fs_exec_hugetlbfs_files() interface - Add daemons_enable_cluster_mode boolean - Fix rsync_filetrans_named_content() - Add rhcs_read_cluster_pid_files() interface - Update rhcs.if with additional interfaces from RHEL6 - Fix rhcs_domain_template() to not create run dirs with cluster_var_run_t - Allow glusterd_t to mounton glusterd_tmp_t - Allow glusterd to unmout al filesystems - Allow xenstored to read virt config - Add label for swift_server.lock and make add filetrans_named_content to make sure content gets created with the correct label - Allow mozilla_plugin_t to mmap hugepages as an executable- Add back userdom_security_admin_template() interface and use it for sysadm_t if sysadm_secadm.pp- Allow sshd_t to read openshift content, needs backport to RHEL6.5 - Label /usr/lib64/sasl2/libsasldb.so.3.0.0 as textrel_shlib_t - Make sur kdump lock is created with correct label if kdumpctl is executed - gnome interface calls should always be made within an optional_block - Allow syslogd_t to connect to the syslog_tls port - Add labeling for /var/run/charon.ctl socket - Add kdump_filetrans_named_content() - Allo setpgid for fenced_t - Allow setpgid and r/w cluster tmpfs for fenced_t - gnome calls should always be within optional blocks - wicd.pid should be labeled as networkmanager_var_run_t - Allow sys_resource for lldpad- Add rtas policy- Allow mailserver_domains to manage and transition to mailman data - Dontaudit attempts by mozilla plugin to relabel content, caused by using mv and cp commands - Allow mailserver_domains to manage and transition to mailman data - Allow svirt_domains to read sysctl_net_t - Allow thumb_t to use tmpfs inherited from the user - Allow mozilla_plugin to bind to the vnc port if running with spice - Add new attribute to discover confined_admins and assign confined admin to it - Fix zabbix to handle attributes in interfaces - Fix zabbix to read system states for all zabbix domains - Fix piranha_domain_template() - Allow ctdbd to create udp_socket. Allow ndmbd to access ctdbd var files. - Allow lldpad sys_rouserce cap due to #986870 - Allow dovecot-auth to read nologin - Allow openlmi-networking to read /proc/net/dev - Allow smsd_t to execute scripts created on the fly labeled as smsd_spool_t - Add zabbix_domain attribute for zabbix domains to treat them together - Add labels for zabbix-poxy-* (#1018221) - Update openlmi-storage policy to reflect #1015067 - Back port piranha tmpfs fixes from RHEL6 - Update httpd_can_sendmail boolean to allow read/write postfix spool maildrop - Add postfix_rw_spool_maildrop_files interface - Call new userdom_admin_user_templat() also for sysadm_secadm.pp - Fix typo in userdom_admin_user_template() - Allow SELinux users to create coolkeypk11sE-Gate in /var/cache/coolkey - Add new attribute to discover confined_admins - Fix labeling for /etc/strongswan/ipsec.d - systemd_logind seems to pass fd to anyone who dbus communicates with it - Dontaudit leaked write descriptor to dmesg- Activate motion policy- Fix gnome_read_generic_data_home_files() - allow openshift_cgroup_t to read/write inherited openshift file types - Remove httpd_cobbler_content * from cobbler_admin interface - Allow svirt sandbox domains to setattr on chr_file and blk_file svirt_sandbox_file_t, so sshd will work within a container - Allow httpd_t to read also git sys content symlinks - Allow init_t to read gnome home data - Dontaudit setroubleshoot_fixit_t execmem, since it does not seem to really need it. - Allow virsh to execute systemctl - Fix for nagios_services plugins - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - Fix hypervkvp.te - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Fix logging policy - Allow syslog to bind to tls ports - Update labeling for /dev/cdc-wdm - Allow to su_domain to read init states - Allow init_t to read gnome home data - Make sure if systemd_logind creates nologin file with the correct label - Clean up ipsec.te- Add auth_exec_chkpwd interface - Fix port definition for ctdb ports - Allow systemd domains to read /dev/urand - Dontaudit attempts for mozilla_plugin to append to /dev/random - Add label for /var/run/charon.* - Add labeling for /usr/lib/systemd/system/lvm2.*dd policy for motion service - Fix for nagios_services plugins - Fix some bugs in zoneminder policy - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - glusterd binds to random unreserved ports - Additional allow rules found by testing glusterfs - apcupsd needs to send a message to all users on the system so needs to look them up - Fix the label on ~/.juniper_networks - Dontaudit attempts for mozilla_plugin to append to /dev/random - Allow polipo_daemon to connect to flash ports - Allow gssproxy_t to create replay caches - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type- init reload from systemd_localed_t - Allow domains that communicate with systemd_logind_sessions to use systemd_logind_t fd - Allow systemd_localed_t to ask systemd to reload the locale. - Add systemd_runtime_unit_file_t type for unit files that systemd creates in memory - Allow readahead to read /dev/urand - Fix lots of avcs about tuned - Any file names xenstored in /var/log should be treated as xenstored_var_log_t - Allow tuned to inderact with hugepages - Allow condor domains to list etc rw dirs- Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Add additional fixes forpegasus_openlmi_account_t - Allow mdadm to read /dev/urand - Allow pegasus_openlmi_storage_t to create mdadm.conf and write it - Add label/rules for /etc/mdadm.conf - Allow pegasus_openlmi_storage_t to transition to fsadm_t - Fixes for interface definition problems - Dontaudit dovecot-deliver to gettatr on all fs dirs - Allow domains to search data_home_t directories - Allow cobblerd to connect to mysql - Allow mdadm to r/w kdump lock files - Add support for kdump lock files - Label zarafa-search as zarafa-indexer - Openshift cgroup wants to read /etc/passwd - Add new sandbox domains for kvm - Allow mpd to interact with pulseaudio if mpd_enable_homedirs is turned on - Fix labeling for /usr/lib/systemd/system/lvm2.* - Add labeling for /usr/lib/systemd/system/lvm2.* - Fix typos to get a new build. We should not cover filename trans rules to prevent duplicate rules - Add sshd_keygen_t policy for sshd-keygen - Fix alsa_home_filetrans interface name and definition - Allow chown for ssh_keygen_t - Add fs_dontaudit_getattr_all_dirs() - Allow init_t to manage etc_aliases_t and read xserver_var_lib_t and chrony keys - Fix up patch to allow systemd to manage home content - Allow domains to send/recv unlabeled traffic if unlabelednet.pp is enabled - Allow getty to exec hostname to get info - Add systemd_home_t for ~/.local/share/systemd directory- Fix lxc labels in config.tgz- Fix labeling for /usr/libexec/kde4/kcmdatetimehelper - Allow tuned to search all file system directories - Allow alsa_t to sys_nice, to get top performance for sound management - Add support for MySQL/PostgreSQL for amavis - Allow openvpn_t to manage openvpn_var_log_t files. - Allow dirsrv_t to create tmpfs_t directories - Allow dirsrv to create dirs in /dev/shm with dirsrv_tmpfs label - Dontaudit leaked unix_stream_sockets into gnome keyring - Allow telepathy domains to inhibit pipes on telepathy domains - Allow cloud-init to domtrans to rpm - Allow abrt daemon to manage abrt-watch tmp files - Allow abrt-upload-watcher to search /var/spool directory - Allow nsswitch domains to manage own process key - Fix labeling for mgetty.* logs - Allow systemd to dbus chat with upower - Allow ipsec to send signull to itself - Allow setgid cap for ipsec_t - Match upstream labeling- Do not build sanbox pkg on MLS- wine_tmp is no longer needed - Allow setroubleshoot to look at /proc - Allow telepathy domains to dbus with systemd logind - Fix handling of fifo files of rpm - Allow mozilla_plugin to transition to itself - Allow certwatch to write to cert_t directories - New abrt application - Allow NetworkManager to set the kernel scheduler - Make wine_domain shared by all wine domains - Allow mdadm_t to read images labeled svirt_image_t - Allow amanda to read /dev/urand - ALlow my_print_default to read /dev/urand - Allow mdadm to write to kdumpctl fifo files - Allow nslcd to send signull to itself - Allow yppasswd to read /dev/urandom - Fix zarafa_setrlimit - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add additional alias for user_tmp_t because wine_tmp_t is no longer used - More handling of ther kernel keyring required by kerberos - New privs needed for init_t when running without transition to initrc_t over bin_t, and without unconfined domain installed- Dontaudit attempts by sosreport to read shadow_t - Allow browser sandbox plugins to connect to cups to print - Add new label mpd_home_t - Label /srv/www/logs as httpd_log_t - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add labels for apache logs under miq package - Allow irc_t to use tcp sockets - fix labels in puppet.if - Allow tcsd to read utmp file - Allow openshift_cron_t to run ssh-keygen in ssh_keygen_t to access host keys - Define svirt_socket_t as a domain_type - Take away transition from init_t to initrc_t when executing bin_t, allow init_t to run chk_passwd_t - Fix label on pam_krb5 helper apps- Allow ldconfig to write to kdumpctl fifo files - allow neutron to connect to amqp ports - Allow kdump_manage_crash to list the kdump_crash_t directory - Allow glance-api to connect to amqp port - Allow virt_qemu_ga_t to read meminfo - Add antivirus_home_t type for antivirus date in HOMEDIRS - Allow mpd setcap which is needed by pulseaudio - Allow smbcontrol to create content in /var/lib/samba - Allow mozilla_exec_t to be used as a entrypoint to mozilla_domtrans_spec - Add additional labeling for qemu-ga/fsfreeze-hook.d scripts - amanda_exec_t needs to be executable file - Allow block_suspend cap for samba-net - Allow apps that read ipsec_mgmt_var_run_t to search ipsec_var_run_t - Allow init_t to run crash utility - Treat usr_t just like bin_t for transitions and executions - Add port definition of pka_ca to port 829 for openshift - Allow selinux_store to use symlinks- Allow block_suspend cap for samba-net - Allow t-mission-control to manage gabble cache files - Allow nslcd to read /sys/devices/system/cpu - Allow selinux_store to use symlinks- Allow xdm_t to transition to itself - Call neutron interfaces instead of quantum - Allow init to change targed role to make uncofined services (xrdp which now has own systemd unit file) working. We want them to have in unconfined_t - Make sure directories in /run get created with the correct label - Make sure /root/.pki gets created with the right label - try to remove labeling for motion from zoneminder_exec_t to bin_t - Allow inetd_t to execute shell scripts - Allow cloud-init to read all domainstate - Fix to use quantum port - Add interface netowrkmanager_initrc_domtrans - Fix boinc_execmem - Allow t-mission-control to read gabble cache home - Add labeling for ~/.cache/telepathy/avatars/gabble - Allow memcache to read sysfs data - Cleanup antivirus policy and add additional fixes - Add boolean boinc_enable_execstack - Add support for couchdb in rabbitmq policy - Add interface couchdb_search_pid_dirs - Allow firewalld to read NM state - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files()- Split out rlogin ports from inetd - Treat files labeld as usr_t like bin_t when it comes to transitions - Allow staff_t to read login config - Allow ipsec_t to read .google authenticator data - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files() - Call the correct interface - corenet_udp_bind_ktalkd_port() - Allow all domains that can read gnome_config to read kde config - Allow sandbox domain to read/write mozilla_plugin_tmpfs_t so pulseaudio will work - Allow mdadm to getattr any file system - Allow a confined domain to executes mozilla_exec_t via dbus - Allow cupsd_lpd_t to bind to the printer port - Dontaudit attempts to bind to ports < 1024 when nis is turned on - Allow apache domain to connect to gssproxy socket - Allow rlogind to bind to the rlogin_port - Allow telnetd to bind to the telnetd_port - Allow ktalkd to bind to the ktalkd_port - Allow cvs to bind to the cvs_port- Cleanup related to init_domain()+inetd_domain fixes - Use just init_domain instead of init_daemon_domain in inetd_core_service_domain - svirt domains neeed to create kobject_uevint_sockets - Lots of new access required for sosreport - Allow tgtd_t to connect to isns ports - Allow init_t to transition to all inetd domains: - openct needs to be able to create netlink_object_uevent_sockets - Dontaudit leaks into ldconfig_t - Dontaudit su domains getattr on /dev devices, move su domains to attribute based calls - Move kernel_stream_connect into all Xwindow using users - Dontaudit inherited lock files in ifconfig o dhcpc_t- Also sock_file trans rule is needed in lsm - Fix labeling for fetchmail pid files/dirs - Add additional fixes for abrt-upload-watch - Fix polipo.te - Fix transition rules in asterisk policy - Add fowner capability to networkmanager policy - Allow polipo to connect to tor ports - Cleanup lsmd.if - Cleanup openhpid policy - Fix kdump_read_crash() interface - Make more domains as init domain - Fix cupsd.te - Fix requires in rpm_rw_script_inherited_pipes - Fix interfaces in lsm.if - Allow munin service plugins to manage own tmpfs files/dirs - Allow virtd_t also relabel unix stream sockets for virt_image_type - Make ktalk as init domain - Fix to define ktalkd_unit_file_t correctly - Fix ktalk.fc - Add systemd support for talk-server - Allow glusterd to create sock_file in /run - Allow xdm_t to delete gkeyringd_tmp_t files on logout - Add fixes for hypervkvp policy - Add logwatch_can_sendmail boolean - Allow mysqld_safe_t to handle also symlinks in /var/log/mariadb - Allow xdm_t to delete gkeyringd_tmp_t files on logout- Add selinux-policy-sandbox pkg0 - Allow rhsmcertd to read init state - Allow fsetid for pkcsslotd - Fix labeling for /usr/lib/systemd/system/pkcsslotd.service - Allow fetchmail to create own pid with correct labeling - Fix rhcs_domain_template() - Allow roles which can run mock to read mock lib files to view results - Allow rpcbind to use nsswitch - Fix lsm.if summary - Fix collectd_t can read /etc/passwd file - Label systemd unit files under dracut correctly - Add support for pam_mount to mount user's encrypted home When a user logs in and logs out using ssh - Add support for .Xauthority-n - Label umount.crypt as lvm_exec_t - Allow syslogd to search psad lib files - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files- Add policy for lsmd - Add support for /var/log/mariadb dir and allow mysqld_safe to list this directory - Update condor_master rules to allow read system state info and allow logging - Add labeling for /etc/condor and allow condor domain to write it (bug) - Allow condor domains to manage own logs - Allow glusterd to read domains state - Fix initial hypervkvp policy - Add policy for hypervkvpd - Fix redis.if summary- Allow boinc to connect to @/tmp/.X11-unix/X0 - Allow beam.smp to connect to tcp/5984 - Allow named to manage own log files - Add label for /usr/libexec/dcc/start-dccifd and domtrans to dccifd_t - Add virt_transition_userdomain boolean decl - Allow httpd_t to sendto unix_dgram sockets on its children - Allow nova domains to execute ifconfig - bluetooth wants to create fifo_files in /tmp - exim needs to be able to manage mailman data - Allow sysstat to getattr on all file systems - Looks like bluetoothd has moved - Allow collectd to send ping packets - Allow svirt_lxc domains to getpgid - Remove virt-sandbox-service labeling as virsh_exec_t, since it no longer does virsh_t stuff - Allow frpintd_t to read /dev/urandom - Allow asterisk_t to create sock_file in /var/run - Allow usbmuxd to use netlink_kobject - sosreport needs to getattr on lots of devices, and needs access to netlink_kobject_uevent_socket - More cleanup of svirt_lxc policy - virtd_lxc_t now talks to dbus - Dontaudit leaked ptmx_t - Allow processes to use inherited fifo files - Allow openvpn_t to connect to squid ports - Allow prelink_cron_system_t to ask systemd to reloaddd miscfiles_dontaudit_access_check_cert() - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files - Allow user roles to connect to the journal socket- selinux_set_enforce_mode needs to be used with type - Add append to the dontaudit for unix_stream_socket of xdm_t leak - Allow xdm_t to create symlinks in log direcotries - Allow login programs to read afs config - Label 10933 as a pop port, for dovecot - New policy to allow selinux_server.py to run as semanage_t as a dbus service - Add fixes to make netlabelctl working on MLS - AVCs required for running sepolicy gui as staff_t - Dontaudit attempts to read symlinks, sepolicy gui is likely to cause this type of AVC - New dbus server to be used with new gui - After modifying some files in /etc/mail, I saw this needed on the next boot - Loading a vm from /usr/tmp with virt-manager - Clean up oracleasm policy for Fedora - Add oracleasm policy written by rlopez@redhat.com - Make postfix_postdrop_t as mta_agent to allow domtrans to system mail if it is executed by apache - Add label for /var/crash - Allow fenced to domtrans to sanclok_t - Allow nagios to manage nagios spool files - Make tfptd as home_manager - Allow kdump to read kcore on MLS system - Allow mysqld-safe sys_nice/sys_resource caps - Allow apache to search automount tmp dirs if http_use_nfs is enabled - Allow crond to transition to named_t, for use with unbound - Allow crond to look at named_conf_t, for unbound - Allow mozilla_plugin_t to transition its home content - Allow dovecot_domain to read all system and network state - Allow httpd_user_script_t to call getpw - Allow semanage to read pid files - Dontaudit leaked file descriptors from user domain into thumb - Make PAM authentication working if it is enabled in ejabberd - Add fixes for rabbit to fix ##992920,#992931 - Allow glusterd to mount filesystems - Loading a vm from /usr/tmp with virt-manager - Trying to load a VM I got an AVC from devicekit_disk for loopcontrol device - Add fix for pand service - shorewall touches own log - Allow nrpe to list /var - Mozilla_plugin_roles can not be passed into lpd_run_lpr - Allow afs domains to read afs_config files - Allow login programs to read afs config - Allow virt_domain to read virt_var_run_t symlinks - Allow smokeping to send its process signals - Allow fetchmail to setuid - Add kdump_manage_crash() interface - Allow abrt domain to write abrt.socket- Add more aliases in pegasus.te - Add more fixes for *_admin interfaces - Add interface fixes - Allow nscd to stream connect to nmbd - Allow gnupg apps to write to pcscd socket - Add more fixes for openlmi provides. Fix naming and support for additionals - Allow fetchmail to resolve host names - Allow firewalld to interact also with lnk files labeled as firewalld_etc_rw_t - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te - Fix corecmd_exec_chroot() - Fix logging_relabel_syslog_pid_socket interface - Fix typo in unconfineduser.te - Allow system_r to access unconfined_dbusd_t to run hp_chec- Allow xdm_t to act as a dbus client to itsel - Allow fetchmail to resolve host names - Allow gnupg apps to write to pcscd socket - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te -httpd_t does access_check on certs- Add support for cmpiLMI_Service-cimprovagt - Allow pegasus domtrans to rpm_t to make pycmpiLMI_Software-cimprovagt running as rpm_t - Label pycmpiLMI_Software-cimprovagt as rpm_exec_t - Add support for pycmpiLMI_Storage-cimprovagt - Add support for cmpiLMI_Networking-cimprovagt - Allow system_cronjob_t to create user_tmpfs_t to make pulseaudio working - Allow virtual machines and containers to run as user doains, needed for virt-sandbox - Allow buglist.cgi to read cpu info- Allow systemd-tmpfile to handle tmp content in print spool dir - Allow systemd-sysctl to send system log messages - Add support for RTP media ports and fmpro-internal - Make auditd working if audit is configured to perform SINGLE action on disk error - Add interfaces to handle systemd units - Make systemd-notify working if pcsd is used - Add support for netlabel and label /usr/sbin/netlabelctl as iptables_exec_t - Instead of having all unconfined domains get all of the named transition rules, - Only allow unconfined_t, init_t, initrc_t and rpm_script_t by default. - Add definition for the salt ports - Allow xdm_t to create link files in xdm_var_run_t - Dontaudit reads of blk files or chr files leaked into ldconfig_t - Allow sys_chroot for useradd_t - Allow net_raw cap for ipsec_t - Allow sysadm_t to reload services - Add additional fixes to make strongswan working with a simple conf - Allow sysadm_t to enable/disable init_t services - Add additional glusterd perms - Allow apache to read lnk files in the /mnt directory - Allow glusterd to ask the kernel to load a module - Fix description of ftpd_use_fusefs boolean - Allow svirt_lxc_net_t to sys_chroot, modify policy to tighten up svirt_lxc_domain capabilties and process controls, but add them to svirt_lxc_net_t - Allow glusterds to request load a kernel module - Allow boinc to stream connect to xserver_t - Allow sblim domains to read /etc/passwd - Allow mdadm to read usb devices - Allow collectd to use ping plugin - Make foghorn working with SNMP - Allow sssd to read ldap certs - Allow haproxy to connect to RTP media ports - Add additional trans rules for aide_db - Add labeling for /usr/lib/pcsd/pcsd - Add labeling for /var/log/pcsd - Add support for pcs which is a corosync and pacemaker configuration tool- Label /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t - Add labeling for /usr/libexec/kde4/polkit-kde-authentication-agent-1 - Allow all domains that can domtrans to shutdown, to start the power services script to shutdown - consolekit needs to be able to shut down system - Move around interfaces - Remove nfsd_rw_t and nfsd_ro_t, they don't do anything - Add additional fixes for rabbitmq_beam to allow getattr on mountpoints - Allow gconf-defaults-m to read /etc/passwd - Fix pki_rw_tomcat_cert() interface to support lnk_files- Add support for gluster ports - Make sure that all keys located in /etc/ssh/ are labeled correctly - Make sure apcuspd lock files get created with the correct label - Use getcap in gluster.te - Fix gluster policy - add additional fixes to allow beam.smp to interact with couchdb files - Additional fix for #974149 - Allow gluster to user gluster ports - Allow glusterd to transition to rpcd_t and add additional fixes for #980683 - Allow tgtd working when accessing to the passthrough device - Fix labeling for mdadm unit files- Add mdadm fixes- Fix definition of sandbox.disabled to sandbox.pp.disabled- Allow mdamd to execute systemctl - Allow mdadm to read /dev/kvm - Allow ipsec_mgmt_t to read l2tpd pid content- Allow nsd_t to read /dev/urand - Allow mdadm_t to read framebuffer - Allow rabbitmq_beam_t to read process info on rabbitmq_epmd_t - Allow mozilla_plugin_config_t to create tmp files - Cleanup openvswitch policy - Allow mozilla plugin to getattr on all executables - Allow l2tpd_t to create fifo_files in /var/run - Allow samba to touch/manage fifo_files or sock_files in a samba_share_t directory - Allow mdadm to connecto its own unix_stream_socket - FIXME: nagios changed locations to /log/nagios which is wrong. But we need to have this workaround for now. - Allow apache to access smokeping pid files - Allow rabbitmq_beam_t to getattr on all filesystems - Add systemd support for iodined - Allow nup_upsdrvctl_t to execute its entrypoint - Allow fail2ban_client to write to fail2ban_var_run_t, Also allow it to use nsswitch - add labeling for ~/.cache/libvirt-sandbox - Add interface to allow domains transitioned to by confined users to send sigchld to screen program - Allow sysadm_t to check the system status of files labeled etc_t, /etc/fstab - Allow systemd_localed to start /usr/lib/systemd/system/systemd-vconsole-setup.service - Allow an domain that has an entrypoint from a type to be allowed to execute the entrypoint without a transition, I can see no case where this is a bad thing, and elminiates a whole class of AVCs. - Allow staff to getsched all domains, required to run htop - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Add prosody policy written by Michael Scherer - Allow nagios plugins to read /sys info - ntpd needs to manage own log files - Add support for HOME_DIR/.IBMERS - Allow iptables commands to read firewalld config - Allow consolekit_t to read utmp - Fix filename transitions on .razor directory - Add additional fixes to make DSPAM with LDA working - Allow snort to read /etc/passwd - Allow fail2ban to communicate with firewalld over dbus - Dontaudit openshift_cgreoup_file_t read/write leaked dev - Allow nfsd to use mountd port - Call th proper interface - Allow openvswitch to read sys and execute plymouth - Allow tmpwatch to read /var/spool/cups/tmp - Add support for /usr/libexec/telepathy-rakia - Add systemd support for zoneminder - Allow mysql to create files/directories under /var/log/mysql - Allow zoneminder apache scripts to rw zoneminder tmpfs - Allow httpd to manage zoneminder lib files - Add zoneminder_run_sudo boolean to allow to start zoneminder - Allow zoneminder to send mails - gssproxy_t sock_file can be under /var/lib - Allow web domains to connect to whois port. - Allow sandbox_web_type to connect to the same ports as mozilla_plugin_t. - We really need to add an interface to corenet to define what a web_client_domain is and - then define chrome_sandbox_t, mozilla_plugin_t and sandbox_web_type to that domain. - Add labeling for cmpiLMI_LogicalFile-cimprovagt - Also make pegasus_openlmi_logicalfile_t as unconfined to have unconfined_domain attribute for filename trans rules - Update policy rules for pegasus_openlmi_logicalfile_t - Add initial types for logicalfile/unconfined OpenLMI providers - mailmanctl needs to read own log - Allow logwatch manage own lock files - Allow nrpe to read meminfo - Allow httpd to read certs located in pki-ca - Add pki_read_tomcat_cert() interface - Add support for nagios openshift plugins - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Shrink the size of policy by moving to attributes, also add dridomain so that mozilla_plugin can follow selinuxuse_dri boolean. - Allow bootloader to manage generic log files - Allow ftp to bind to port 989 - Fix label of new gear directory - Add support for new directory /var/lib/openshift/gears/ - Add openshift_manage_lib_dirs() - allow virtd domains to manage setrans_var_run_t - Allow useradd to manage all openshift content - Add support so that mozilla_plugin_t can use dri devices - Allow chronyd to change the scheduler - Allow apmd to shut downthe system - Devicekit_disk_t needs to manage /etc/fstab- Make DSPAM to act as a LDA working - Allow ntop to create netlink socket - Allow policykit to send a signal to policykit-auth - Allow stapserver to dbus chat with avahi/systemd-logind - Fix labeling on haproxy unit file - Clean up haproxy policy - A new policy for haproxy and placed it to rhcs.te - Add support for ldirectord and treat it with cluster_t - Make sure anaconda log dir is created with var_log_t- Allow lvm_t to create default targets for filesystem handling - Fix labeling for razor-lightdm binaries - Allow insmod_t to read any file labeled var_lib_t - Add policy for pesign - Activate policy for cmpiLMI_Account-cimprovagt - Allow isnsd syscall=listen - /usr/libexec/pegasus/cimprovagt needs setsched caused by sched_setscheduler - Allow ctdbd to use udp/4379 - gatherd wants sys_nice and setsched - Add support for texlive2012 - Allow NM to read file_t (usb stick with no labels used to transfer keys for example) - Allow cobbler to execute apache with domain transition- condor_collector uses tcp/9000 - Label /usr/sbin/virtlockd as virtd_exec_t for now - Allow cobbler to execute ldconfig - Allow NM to execute ssh - Allow mdadm to read /dev/crash - Allow antivirus domains to connect to snmp port - Make amavisd-snmp working correctly - Allow nfsd_t to mounton nfsd_fs_t - Add initial snapper policy - We still need to have consolekit policy - Dontaudit firefox attempting to connect to the xserver_port_t if run within sandbox_web_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow dirsrv to read network state - Fix pki_read_tomcat_lib_files - Add labeling for /usr/libexec/nm-ssh-service - Add label cert_t for /var/lib/ipa/pki-ca/publish - Lets label /sys/fs/cgroup as cgroup_t for now, to keep labels consistant - Allow nfsd_t to mounton nfsd_fs_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow passwd_t to change role to system_r from unconfined_r- Don't audit access checks by sandbox xserver on xdb var_lib - Allow ntop to read usbmon devices - Add labeling for new polcykit authorizor - Dontaudit access checks from fail2ban_client - Don't audit access checks by sandbox xserver on xdb var_lib - Allow apps that connect to xdm stream to conenct to xdm_dbusd_t stream - Fix labeling for all /usr/bim/razor-lightdm-* binaries - Add filename trans for /dev/md126p1- Make vdagent able to request loading kernel module - Add support for cloud-init make it as unconfined domain - Allow snmpd to run smartctl in fsadm_t domain - remove duplicate openshift_search_lib() interface - Allow mysqld to search openshift lib files - Allow openshift cgroup to interact with passedin file descriptors - Allow colord to list directories inthe users homedir - aide executes prelink to check files - Make sure cupsd_t creates content in /etc/cups with the correct label - Lest dontaudit apache read all domains, so passenger will not cause this avc - Allow gssd to connect to gssproxy - systemd-tmpfiles needs to be able to raise the level to fix labeling on /run/setrans in MLS - Allow systemd-tmpfiles to relabel also lock files - Allow useradd to add homdir in /var/lib/openshift - Allow setfiles and semanage to write output to /run/files- Add labeling for /dev/tgt - Dontaudit leak fd from firewalld for modprobe - Allow runuser running as rpm_script_t to create netlink_audit socket - Allow mdadm to read BIOS non-volatile RAM- accountservice watches when accounts come and go in wtmp - /usr/java/jre1.7.0_21/bin/java needs to create netlink socket - Add httpd_use_sasl boolean - Allow net_admin for tuned_t - iscsid needs sys_module to auto-load kernel modules - Allow blueman to read bluetooth conf - Add nova_manage_lib_files() interface - Fix mplayer_filetrans_home_content() - Add mplayer_filetrans_home_content() - mozilla_plugin_config_roles need to be able to access mozilla_plugin_config_t - Revert "Allow thumb_t to append inherited xdm stream socket" - Add iscsi_filetrans_named_content() interface - Allow to create .mplayer with the correct labeling for unconfined - Allow iscsiadmin to create lock file with the correct labeling- Allow wine to manage wine home content - Make amanda working with socket actiovation - Add labeling for /usr/sbin/iscsiadm - Add support for /var/run/gssproxy.sock - dnsmasq_t needs to read sysctl_net_t- Fix courier_domain_template() interface - Allow blueman to write ip_forward - Allow mongodb to connect to mongodb port - Allow mongodb to connect to mongodb port - Allow java to bind jobss_debug port - Fixes for *_admin interfaces - Allow iscsid auto-load kernel modules needed for proper iSCSI functionality - Need to assign attribute for courier_domain to all courier_domains - Fail2ban reads /etc/passwd - postfix_virtual will create new files in postfix_spool_t - abrt triggers sys_ptrace by running pidof - Label ~/abc as mozilla_home_t, since java apps as plugin want to create it - Add passenger fixes needed by foreman - Remove dup interfaces - Add additional interfaces for quantum - Add new interfaces for dnsmasq - Allow passenger to read localization and send signull to itself - Allow dnsmasq to stream connect to quantum - Add quantum_stream_connect() - Make sure that mcollective starts the service with the correct labeling - Add labels for ~/.manpath - Dontaudit attempts by svirt_t to getpw* calls - sandbox domains are trying to look at parent process data - Allow courior auth to create its pid file in /var/spool/courier subdir - Add fixes for beam to have it working with couchdb - Add labeling for /run/nm-xl2tpd.con - Allow apache to stream connect to thin - Add systemd support for amand - Make public types usable for fs mount points - Call correct mandb interface in domain.te - Allow iptables to r/w quantum inherited pipes and send sigchld - Allow ifconfig domtrans to iptables and execute ldconfig - Add labels for ~/.manpath - Allow systemd to read iscsi lib files - seunshare is trying to look at parent process data- Fix openshift_search_lib - Add support for abrt-uefioops-oops - Allow colord to getattr any file system - Allow chrome processes to look at each other - Allow sys_ptrace for abrt_t - Add new policy for gssproxy - Dontaudit leaked file descriptor writes from firewalld - openshift_net_type is interface not template - Dontaudit pppd to search gnome config - Update openshift_search_lib() interface - Add fs_list_pstorefs() - Fix label on libbcm_host.so since it is built incorrectly on raspberry pi, needs back port to F18 - Better labels for raspberry pi devices - Allow init to create devpts_t directory - Temporarily label rasbery pi devices as memory_device_t, needs back port to f18 - Allow sysadm_t to build kernels - Make sure mount creates /var/run/blkid with the correct label, needs back port to F18 - Allow userdomains to stream connect to gssproxy - Dontaudit leaked file descriptor writes from firewalld - Allow xserver to read /dev/urandom - Add additional fixes for ipsec-mgmt - Make SSHing into an Openshift Enterprise Node working- Add transition rules to unconfined domains and to sysadm_t to create /etc/adjtime - with the proper label. - Update files_filetrans_named_content() interface to get right labeling for pam.d conf files - Allow systemd-timedated to create adjtime - Add clock_create_adjtime() - Additional fix ifconfing for #966106 - Allow kernel_t to create boot.log with correct labeling - Remove unconfined_mplayer for which we don't have rules - Rename interfaces - Add userdom_manage_user_home_files/dirs interfaces - Fix files_dontaudit_read_all_non_security_files - Fix ipsec_manage_key_file() - Fix ipsec_filetrans_key_file() - Label /usr/bin/razor-lightdm-greeter as xdm_exec_t instead of spamc_exec_t - Fix labeling for ipse.secrets - Add interfaces for ipsec and labeling for ipsec.info and ipsec_setup.pid - Add files_dontaudit_read_all_non_security_files() interface - /var/log/syslog-ng should be labeled var_log_t - Make ifconfig_var_run_t a mountpoint - Add transition from ifconfig to dnsmasq - Allow ifconfig to execute bin_t/shell_exec_t - We want to have hwdb.bin labeled as etc_t - update logging_filetrans_named_content() interface - Allow systemd_timedate_t to manage /etc/adjtime - Allow NM to send signals to l2tpd - Update antivirus_can_scan_system boolean - Allow devicekit_disk_t to sys_config_tty - Run abrt-harvest programs as abrt_t, and allow abrt_t to list all filesystem directories - Make printing from vmware working - Allow php-cgi from php54 collection to access /var/lib/net-snmp/mib_indexes - Add virt_qemu_ga_data_t for qemu-ga - Make chrome and mozilla able to connect to same ports, add jboss_management_port_t to both - Fix typo in virt.te - Add virt_qemu_ga_unconfined_t for hook scripts - Make sure NetworkManager files get created with the correct label - Add mozilla_plugin_use_gps boolean - Fix cyrus to have support for net-snmp - Additional fixes for dnsmasq and quantum for #966106 - Add plymouthd_create_log() - remove httpd_use_oddjob for which we don't have rules - Add missing rules for httpd_can_network_connect_cobbler - Add missing cluster_use_execmem boolean - Call userdom_manage_all_user_home_type_files/dirs - Additional fix for ftp_home_dir - Fix ftp_home_dir boolean - Allow squit to recv/send client squid packet - Fix nut.te to have nut_domain attribute - Add support for ejabberd; TODO: revisit jabberd and rabbit policy - Fix amanda policy - Add more fixes for domains which use libusb - Make domains which use libusb working correctly - Allow l2tpd to create ipsec key files with correct labeling and manage them - Fix cobbler_manage_lib_files/cobbler_read_lib_files to cover also lnk files - Allow rabbitmq-beam to bind generic node - Allow l2tpd to read ipse-mgmt pid files - more fixes for l2tpd, NM and pppd from #967072- Dontaudit to getattr on dirs for dovecot-deliver - Allow raiudusd server connect to postgresql socket - Add kerberos support for radiusd - Allow saslauthd to connect to ldap port - Allow postfix to manage postfix_private_t files - Add chronyd support for #965457 - Fix labeling for HOME_DIR/\.icedtea - CHange squid and snmpd to be allowed also write own logs - Fix labeling for /usr/libexec/qemu-ga - Allow virtd_t to use virt_lock_t - Allow also sealert to read the policy from the kernel - qemu-ga needs to execute scripts in /usr/libexec/qemu-ga and to use /tmp content - Dontaudit listing of users homedir by sendmail Seems like a leak - Allow passenger to transition to puppet master - Allow apache to connect to mythtv - Add definition for mythtv ports- Add additional fixes for #948073 bug - Allow sge_execd_t to also connect to sge ports - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow sge_execd to bind sge ports. Allow kill capability and reads cgroup files - Remove pulseaudio filetrans pulseaudio_manage_home_dirs which is a part of pulseaudio_manage_home_files - Add networkmanager_stream_connect() - Make gnome-abrt wokring with staff_t - Fix openshift_manage_lib_files() interface - mdadm runs ps command which seems to getattr on random log files - Allow mozilla_plugin_t to create pulseaudit_home_t directories - Allow qemu-ga to shutdown virtual hosts - Add labelling for cupsd-browsed - Add web browser plugins to connect to aol ports - Allow nm-dhcp-helper to stream connect to NM - Add port definition for sge ports- Make sure users and unconfined domains create .hushlogin with the correct label - Allow pegaus to chat with realmd over DBus - Allow cobblerd to read network state - Allow boicn-client to stat on /dev/input/mice - Allow certwatch to read net_config_t when it executes apache - Allow readahead to create /run/systemd and then create its own directory with the correct label- Transition directories and files when in a user_tmp_t directory - Change certwatch to domtrans to apache instead of just execute - Allow virsh_t to read xen lib files - update policy rules for pegasus_openlmi_account_t - Add support for svnserve_tmp_t - Activate account openlmi policy - pegasus_openlmi_domain_template needs also require pegasus_t - One more fix for policykit.te - Call fs_list_cgroups_dirs() in policykit.te - Allow nagios service plugin to read mysql config files - Add labeling for /var/svn - Fix chrome.te - Fix pegasus_openlmi_domain_template() interfaces - Fix dev_rw_vfio_dev definiton, allow virtd_t to read tmpfs_t symlinks - Fix location of google-chrome data - Add support for chome_sandbox to store content in the homedir - Allow policykit to watch for changes in cgroups file system - Add boolean to allow mozilla_plugin_t to use spice - Allow collectd to bind to udp port - Allow collected_t to read all of /proc - Should use netlink socket_perms - Should use netlink socket_perms - Allow glance domains to connect to apache ports - Allow apcupsd_t to manage its log files - Allow chrome objects to rw_inherited unix_stream_socket from callers - Allow staff_t to execute virtd_exec_t for running vms - nfsd_t needs to bind mountd port to make nfs-mountd.service working - Allow unbound net_admin capability because of setsockopt syscall - Fix fs_list_cgroup_dirs() - Label /usr/lib/nagios/plugins/utils.pm as bin_t - Remove uplicate definition of fs_read_cgroup_files() - Remove duplicate definition of fs_read_cgroup_files() - Add files_mountpoint_filetrans interface to be used by quotadb_t and snapperd - Additional interfaces needed to list and read cgroups config - Add port definition for collectd port - Add labels for /dev/ptp* - Allow staff_t to execute virtd_exec_t for running vms- Allow samba-net to also read realmd tmp files - Allow NUT to use serial ports - realmd can be started by systemctl now- Remove userdom_home_manager for xdm_t and move all rules to xserver.te directly - Add new xdm_write_home boolean to allow xdm_t to create files in HOME dirs with xdm_home_t - Allow postfix-showq to read/write unix.showq in /var/spool/postfix/pid - Allow virsh to read xen lock file - Allow qemu-ga to create files in /run with proper labeling - Allow glusterd to connect to own socket in /tmp - Allow glance-api to connect to http port to make glance image-create working - Allow keystonte_t to execute rpm- Fix realmd cache interfaces- Allow tcpd to execute leafnode - Allow samba-net to read realmd cache files - Dontaudit sys_tty_config for alsactl - Fix allow rules for postfix_var_run - Allow cobblerd to read /etc/passwd - Allow pegasus to read exports - Allow systemd-timedate to read xdm state - Allow mout to stream connect to rpcbind - Add labeling just for /usr/share/pki/ca-trust-source instead of /usr/share/pki- Allow thumbnails to share memory with apps which run thumbnails - Allow postfix-postqueue block_suspend - Add lib interfaces for smsd - Add support for nginx - Allow s2s running as jabberd_t to connect to jabber_interserver_port_t - Allow pki apache domain to create own tmp files and execute httpd_suexec - Allow procmail to manger user tmp files/dirs/lnk_files - Add virt_stream_connect_svirt() interface - Allow dovecot-auth to execute bin_t - Allow iscsid to request that kernel load a kernel module - Add labeling support for /var/lib/mod_security - Allow iw running as tuned_t to create netlink socket - Dontaudit sys_tty_config for thumb_t - Add labeling for nm-l2tp-service - Allow httpd running as certwatch_t to open tcp socket - Allow useradd to manager smsd lib files - Allow useradd_t to add homedirs in /var/lib - Fix typo in userdomain.te - Cleanup userdom_read_home_certs - Implement userdom_home_reader_certs_type to allow read certs also on encrypt /home with ecryptfs_t - Allow staff to stream connect to svirt_t to make gnome-boxes working- Allow lvm to create its own unit files - Label /var/lib/sepolgen as selinux_config_t - Add filetrans rules for tw devices - Add transition from cupsd_config_t to cupsd_t- Add filetrans rules for tw devices - Cleanup bad transition lines- Fix lockdev_manage_files() - Allow setroubleshootd to read var_lib_t to make email_alert working - Add lockdev_manage_files() - Call proper interface in virt.te - Allow gkeyring_domain to create /var/run/UID/config/dbus file - system dbus seems to be blocking suspend - Dontaudit attemps to sys_ptrace, which I believe gpsd does not need - When you enter a container from root, you generate avcs with a leaked file descriptor - Allow mpd getattr on file system directories - Make sure realmd creates content with the correct label - Allow systemd-tty-ask to write kmsg - Allow mgetty to use lockdev library for device locking - Fix selinuxuser_user_share_music boolean name to selinuxuser_share_music - When you enter a container from root, you generate avcs with a leaked file descriptor - Make sure init.fc files are labeled correctly at creation - File name trans vconsole.conf - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow certmonger to dbus communicate with realmd - Make realmd working- Fix mozilla specification of homedir content - Allow certmonger to read network state - Allow tmpwatch to read tmp in /var/spool/{cups,lpd} - Label all nagios plugin as unconfined by default - Add httpd_serve_cobbler_files() - Allow mdadm to read /dev/sr0 and create tmp files - Allow certwatch to send mails - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow realmd to run ipa, really needs to be an unconfined_domain - Allow sandbox domains to use inherted terminals - Allow pscd to use devices labeled svirt_image_t in order to use cat cards. - Add label for new alsa pid - Alsa now uses a pid file and needs to setsched - Fix oracleasmfs_t definition - Add support for sshd_unit_file_t - Add oracleasmfs_t - Allow unlabeled_t files to be stored on unlabeled_t filesystems- Fix description of deny_ptrace boolean - Remove allow for execmod lib_t for now - Allow quantum to connect to keystone port - Allow nova-console to talk with mysql over unix stream socket - Allow dirsrv to stream connect to uuidd - thumb_t needs to be able to create ~/.cache if it does not exist - virtd needs to be able to sys_ptrace when starting and stoping containers- Allow alsa_t signal_perms, we probaly should search for any app that can execute something without transition and give it signal_perms... - Add dontaudit for mozilla_plugin_t looking at the xdm_t sockets - Fix deny_ptrace boolean, certain ptrace leaked into the system - Allow winbind to manage kerberos_rcache_host - Allow spamd to create spamd_var_lib_t directories - Remove transition to mozilla_tmp_t by mozilla_t, to allow it to manage the users tmp dirs - Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Call snmp_manage_var_lib_files(fogorn_t) instead of snmp_manage_var_dirs - Fix vmware_role() interface - Fix cobbler_manage_lib_files() interface - Allow nagios check disk plugins to execute bin_t - Allow quantum to transition to openvswitch_t - Allow postdrop to stream connect to postfix-master - Allow quantum to stream connect to openvswitch - Add xserver_dontaudit_xdm_rw_stream_sockets() interface - Allow daemon to send dgrams to initrc_t - Allow kdm to start the power service to initiate a reboot or poweroff- Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Don't audit attempts to write to stream socket of nscld by thumbnailers - Allow git_system_t to read network state - Allow pegasas to execute mount command - Fix desc for drdb_admin - Fix condor_amin() - Interface fixes for uptime, vdagent, vnstatd - Fix labeling for moodle in /var/www/moodle/data - Add interface fixes - Allow bugzilla to read certs - /var/www/moodle needs to be writable by apache - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Fix namespace_init_t to create content with proper labels, and allow it to manage all user content - Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Fix sys_nice for cups_domain - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Kernel_t needs mac_admin in order to support labeled NFS - Fix systemd_dontaudit_dbus_chat() interface - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Allow consolehelper domain to write Xauth files in /root - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Allow consolehelper more access discovered by Tom London - Allow fsdaemon to send signull to all domain - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Fix file_contexts.subs to label /run/lock correctly- Try to label on controlC devices up to 30 correctly - Add mount_rw_pid_files() interface - Add additional mount/umount interfaces needed by mock - fsadm_t sends audit messages in reads kernel_ipc_info when doing livecd-iso-to-disk - Fix tabs - Allow initrc_domain to search rgmanager lib files - Add more fixes which make mock working together with confined users * Allow mock_t to manage rpm files * Allow mock_t to read rpm log files * Allow mock to setattr on tmpfs, devpts * Allow mount/umount filesystems - Add rpm_read_log() interface - yum-cron runs rpm from within it. - Allow tuned to transition to dmidecode - Allow firewalld to do net_admin - Allow mock to unmont tmpfs_t - Fix virt_sigkill() interface - Add additional fixes for mock. Mainly caused by mount running in mock_t - Allow mock to write sysfs_t and mount pid files - Add mailman_domain to mailman_template() - Allow openvswitch to execute shell - Allow qpidd to use kerberos - Allow mailman to use fusefs, needs back port to RHEL6 - Allow apache and its scripts to use anon_inodefs - Add alias for git_user_content_t and git_sys_content_t so that RHEL6 will update to RHEL7 - Realmd needs to connect to samba ports, needs back port to F18 also - Allow colord to read /run/initial-setup- - Allow sanlock-helper to send sigkill to virtd which is registred to sanlock - Add virt_kill() interface - Add rgmanager_search_lib() interface - Allow wdmd to getattr on all filesystems. Back ported from RHEL6- Allow realmd to create tmp files - FIx ircssi_home_t type to irssi_home_t - Allow adcli running as realmd_t to connect to ldap port - Allow NetworkManager to transition to ipsec_t, for running strongswan - Make openshift_initrc_t an lxc_domain - Allow gssd to manage user_tmp_t files - Fix handling of irclogs in users homedir - Fix labeling for drupal an wp-content in subdirs of /var/www/html - Allow abrt to read utmp_t file - Fix openshift policy to transition lnk_file, sock-file an fifo_file when created in a tmpfs_t, needs back port to RHEL6 - fix labeling for (oo|rhc)-restorer-wrapper.sh - firewalld needs to be able to write to network sysctls - Fix mozilla_plugin_dontaudit_rw_sem() interface - Dontaudit generic ipc read/write to a mozilla_plugin for sandbox_x domains - Add mozilla_plugin_dontaudit_rw_sem() interface - Allow svirt_lxc_t to transition to openshift domains - Allow condor domains block_suspend and dac_override caps - Allow condor_master to read passd - Allow condor_master to read system state - Allow NetworkManager to transition to ipsec_t, for running strongswan - Lots of access required by lvm_t to created encrypted usb device - Allow xdm_t to dbus communicate with systemd_localed_t - Label strongswan content as ipsec_exec_mgmt_t for now - Allow users to dbus chat with systemd_localed - Fix handling of .xsession-errors in xserver.if, so kde will work - Might be a bug but we are seeing avc's about people status on init_t:service - Make sure we label content under /var/run/lock as <> - Allow daemon and systemprocesses to search init_var_run_t directory - Add boolean to allow xdm to write xauth data to the home directory - Allow mount to write keys for the unconfined domain - Add unconfined_write_keys() interface- Add labeling for /usr/share/pki - Allow programs that read var_run_t symlinks also read var_t symlinks - Add additional ports as mongod_port_t for 27018, 27019, 28017, 28018 and 28019 ports - Fix labeling for /etc/dhcp directory - add missing systemd_stub_unit_file() interface - Add files_stub_var() interface - Add lables for cert_t directories - Make localectl set-x11-keymap working at all - Allow abrt to manage mock build environments to catch build problems. - Allow virt_domains to setsched for running gdb on itself - Allow thumb_t to execute user home content - Allow pulseaudio running as mozilla_plugin_t to read /run/systemd/users/1000 - Allow certwatch to execut /usr/bin/httpd - Allow cgred to send signal perms to itself, needs back port to RHEL6 - Allow openshift_cron_t to look at quota - Allow cups_t to read inhered tmpfs_t from the kernel - Allow yppasswdd to use NIS - Tuned wants sys_rawio capability - Add ftpd_use_fusefs boolean - Allow dirsrvadmin_t to signal itself- Allow localectl to read /etc/X11/xorg.conf.d directory - Revert "Revert "Fix filetrans rules for kdm creates .xsession-errors"" - Allow mount to transition to systemd_passwd_agent - Make sure abrt directories are labeled correctly - Allow commands that are going to read mount pid files to search mount_var_run_t - label /usr/bin/repoquery as rpm_exec_t - Allow automount to block suspend - Add abrt_filetrans_named_content so that abrt directories get labeled correctly - Allow virt domains to setrlimit and read file_context- Allow nagios to manage nagios spool files - /var/spool/snmptt is a directory which snmdp needs to write to, needs back port to RHEL6 - Add swift_alias.* policy files which contain typealiases for swift types - Add support for /run/lock/opencryptoki - Allow pkcsslotd chown capability - Allow pkcsslotd to read passwd - Add rsync_stub() interface - Allow systemd_timedate also manage gnome config homedirs - Label /usr/lib64/security/pam_krb5/pam_krb5_cchelper as bin_t - Fix filetrans rules for kdm creates .xsession-errors - Allow sytemd_tmpfiles to create wtmp file - Really should not label content under /var/lock, since it could have labels on it different from var_lock_t - Allow systemd to list all file system directories - Add some basic stub interfaces which will be used in PRODUCT policies- Fix log transition rule for cluster domains - Start to group all cluster log together - Dont use filename transition for POkemon Advanced Adventure until a new checkpolicy update - cups uses usbtty_device_t devices - These fixes were all required to build a MLS virtual Machine with single level desktops - Allow domains to transiton using httpd_exec_t - Allow svirt domains to manage kernel key rings - Allow setroubleshoot to execute ldconfig - Allow firewalld to read generate gnome data - Allow bluetooth to read machine-info - Allow boinc domain to send signal to itself - Fix gnome_filetrans_home_content() interface - Allow mozilla_plugins to list apache modules, for use with gxine - Fix labels for POkemon in the users homedir - Allow xguest to read mdstat - Dontaudit virt_domains getattr on /dev/* - These fixes were all required to build a MLS virtual Machine with single level desktops - Need to back port this to RHEL6 for openshift - Add tcp/8891 as milter port - Allow nsswitch domains to read sssd_var_lib_t files - Allow ping to read network state. - Fix typo - Add labels to /etc/X11/xorg.d and allow systemd-timestampd_t to manage them- Adopt swift changes from lhh@redhat.com - Add rhcs_manage_cluster_pid_files() interface - Allow screen domains to configure tty and setup sock_file in ~/.screen directory - ALlow setroubleshoot to read default_context_t, needed to backport to F18 - Label /etc/owncloud as being an apache writable directory - Allow sshd to stream connect to an lxc domain- Allow postgresql to manage rgmanager pid files - Allow postgresql to read ccs data - Allow systemd_domain to send dbus messages to policykit - Add labels for /etc/hostname and /etc/machine-info and allow systemd-hostnamed to create them - All systemd domains that create content are reading the file_context file and setfscreate - Systemd domains need to search through init_var_run_t - Allow sshd to communicate with libvirt to set containers labels - Add interface to manage pid files - Allow NetworkManger_t to read /etc/hostname - Dontaudit leaked locked files into openshift_domains - Add fixes for oo-cgroup-read - it nows creates tmp files - Allow gluster to manage all directories as well as files - Dontaudit chrome_sandbox_nacl_t using user terminals - Allow sysstat to manage its own log files - Allow virtual machines to setrlimit and send itself signals. - Add labeling for /var/run/hplip- Fix POSTIN scriptlet- Merge rgmanger, corosync,pacemaker,aisexec policies to cluster_t in rhcs.pp- Fix authconfig.py labeling - Make any domains that write homedir content do it correctly - Allow glusterd to read/write anyhwere on the file system by default - Be a little more liberal with the rsync log files - Fix iscsi_admin interface - Allow iscsid_t to read /dev/urand - Fix up iscsi domain for use with unit files - Add filename transition support for spamassassin policy - Allow web plugins to use badly formated libraries - Allow nmbd_t to create samba_var_t directories - Add filename transition support for spamassassin policy - Add filename transition support for tvtime - Fix alsa_home_filetrans_alsa_home() interface - Move all userdom_filetrans_home_content() calling out of booleans - Allow logrotote to getattr on all file sytems - Remove duplicate userdom_filetrans_home_content() calling - Allow kadmind to read /etc/passwd - Dontaudit append .xsession-errors file on ecryptfs for policykit-auth - Allow antivirus domain to manage antivirus db links - Allow logrotate to read /sys - Allow mandb to setattr on man dirs - Remove mozilla_plugin_enable_homedirs boolean - Fix ftp_home_dir boolean - homedir mozilla filetrans has been moved to userdom_home_manager - homedir telepathy filetrans has been moved to userdom_home_manager - Remove gnome_home_dir_filetrans() from gnome_role_gkeyringd() - Might want to eventually write a daemon on fusefsd. - Add policy fixes for sshd [net] child from plautrba@redhat.com - Tor uses a new port - Remove bin_t for authconfig.py - Fix so only one call to userdom_home_file_trans - Allow home_manager_types to create content with the correctl label - Fix all domains that write data into the homedir to do it with the correct label - Change the postgresql to use proper boolean names, which is causing httpd_t to - not get access to postgresql_var_run_t - Hostname needs to send syslog messages - Localectl needs to be able to send dbus signals to users - Make sure userdom_filetrans_type will create files/dirs with user_home_t labeling by default - Allow user_home_manger domains to create spam* homedir content with correct labeling - Allow user_home_manger domains to create HOMEDIR/.tvtime with correct labeling - Add missing miscfiles_setattr_man_pages() interface and for now comment some rules for userdom_filetrans_type to make build process working - Declare userdom_filetrans_type attribute - userdom_manage_home_role() needs to be called withoout usertype attribute because of userdom_filetrans_type attribute - fusefsd is mounding a fuse file system on /run/user/UID/gvfs- Man pages are now generated in the build process - Allow cgred to list inotifyfs filesystem- Allow gluster to get attrs on all fs - New access required for virt-sandbox - Allow dnsmasq to execute bin_t - Allow dnsmasq to create content in /var/run/NetworkManager - Fix openshift_initrc_signal() interface - Dontaudit openshift domains doing getattr on other domains - Allow consolehelper domain to communicate with session bus - Mock should not be transitioning to any other domains, we should keep mock_t as mock_t - Update virt_qemu_ga_t policy - Allow authconfig running from realmd to restart oddjob service - Add systemd support for oddjob - Add initial policy for realmd_consolehelper_t which if for authconfig executed by realmd - Add labeling for gnashpluginrc - Allow chrome_nacl to execute /dev/zero - Allow condor domains to read /proc - mozilla_plugin_t will getattr on /core if firefox crashes - Allow condor domains to read /etc/passwd - Allow dnsmasq to execute shell scripts, openstack requires this access - Fix glusterd labeling - Allow virtd_t to interact with the socket type - Allow nmbd_t to override dac if you turned on sharing all files - Allow tuned to created kobject_uevent socket - Allow guest user to run fusermount - Allow openshift to read /proc and locale - Allow realmd to dbus chat with rpm - Add new interface for virt - Remove depracated interfaces - Allow systemd_domains read access on etc, etc_runtime and usr files, also allow them to connect stream to syslog socket - /usr/share/munin/plugins/plugin.sh should be labeled as bin_t - Remove some more unconfined_t process transitions, that I don't believe are necessary - Stop transitioning uncofnined_t to checkpc - dmraid creates /var/lock/dmraid - Allow systemd_localed to creatre unix_dgram_sockets - Allow systemd_localed to write kernel messages. - Also cleanup systemd definition a little. - Fix userdom_restricted_xwindows_user_template() interface - Label any block devices or char devices under /dev/infiniband as fixed_disk_device_t - User accounts need to dbus chat with accountsd daemon - Gnome requires all users to be able to read /proc/1/- virsh now does a setexeccon call - Additional rules required by openshift domains - Allow svirt_lxc_domains to use inherited terminals, needed to make virt-sandbox-service execute work - Allow spamd_update_t to search spamc_home_t - Avcs discovered by mounting an isci device under /mnt - Allow lspci running as logrotate to read pci.ids - Additional fix for networkmanager_read_pid_files() - Fix networkmanager_read_pid_files() interface - Allow all svirt domains to connect to svirt_socket_t - Allow virsh to set SELinux context for a process. - Allow tuned to create netlink_kobject_uevent_socket - Allow systemd-timestamp to set SELinux context - Add support for /var/lib/systemd/linger - Fix ssh_sysadm_login to be working on MLS as expected- Rename files_rw_inherited_tmp_files to files_rw_inherited_tmp_file - Add missing files_rw_inherited_tmp_files interface - Add additional interface for ecryptfs - ALlow nova-cert to connect to postgresql - Allow keystone to connect to postgresql - Allow all cups domains to getattr on filesystems - Allow pppd to send signull - Allow tuned to execute ldconfig - Allow gpg to read fips_enabled - Add additional fixes for ecryptfs - Allow httpd to work with posgresql - Allow keystone getsched and setsched- Allow gpg to read fips_enabled - Add support for /var/cache/realmd - Add support for /usr/sbin/blazer_usb and systemd support for nut - Add labeling for fenced_sanlock and allow sanclok transition to fenced_t - bitlbee wants to read own log file - Allow glance domain to send a signal itself - Allow xend_t to request that the kernel load a kernel module - Allow pacemaker to execute heartbeat lib files - cleanup new swift policy- Fix smartmontools - Fix userdom_restricted_xwindows_user_template() interface - Add xserver_xdm_ioctl_log() interface - Allow Xusers to ioctl lxdm.log to make lxdm working - Add MLS fixes to make MLS boot/log-in working - Add mls_socket_write_all_levels() also for syslogd - fsck.xfs needs to read passwd - Fix ntp_filetrans_named_content calling in init.te - Allow postgresql to create pg_log dir - Allow sshd to read rsync_data_t to make rsync working - Change ntp.conf to be labeled net_conf_t - Allow useradd to create homedirs in /run. ircd-ratbox does this and we should just allow it - Allow xdm_t to execute gstreamer home content - Allod initrc_t and unconfined domains, and sysadm_t to manage ntp - New policy for openstack swift domains - More access required for openshift_cron_t - Use cupsd_log_t instead of cupsd_var_log_t - rpm_script_roles should be used in rpm_run - Fix rpm_run() interface - Fix openshift_initrc_run() - Fix sssd_dontaudit_stream_connect() interface - Fix sssd_dontaudit_stream_connect() interface - Allow LDA's job to deliver mail to the mailbox - dontaudit block_suspend for mozilla_plugin_t - Allow l2tpd_t to all signal perms - Allow uuidgen to read /dev/random - Allow mozilla-plugin-config to read power_supply info - Implement cups_domain attribute for cups domains - We now need access to user terminals since we start by executing a command outside the tty - We now need access to user terminals since we start by executing a command outside the tty - svirt lxc containers want to execute userhelper apps, need these changes to allow this to happen - Add containment of openshift cron jobs - Allow system cron jobs to create tmp directories - Make userhelp_conf_t a config file - Change rpm to use rpm_script_roles - More fixes for rsync to make rsync wokring - Allow logwatch to domtrans to mdadm - Allow pacemaker to domtrans to ifconfig - Allow pacemaker to setattr on corosync.log - Add pacemaker_use_execmem for memcheck-amd64 command - Allow block_suspend capability - Allow create fifo_file in /tmp with pacemaker_tmp_t - Allow systat to getattr on fixed disk - Relabel /etc/ntp.conf to be net_conf_t - ntp_admin should create files in /etc with the correct label - Add interface to create ntp_conf_t files in /etc - Add additional labeling for quantum - Allow quantum to execute dnsmasq with transition- boinc_cliean wants also execmem as boinc projecs have - Allow sa-update to search admin home for /root/.spamassassin - Allow sa-update to search admin home for /root/.spamassassin - Allow antivirus domain to read net sysctl - Dontaudit attempts from thumb_t to connect to ssd - Dontaudit attempts by readahead to read sock_files - Dontaudit attempts by readahead to read sock_files - Create tmpfs file while running as wine as user_tmpfs_t - Dontaudit attempts by readahead to read sock_files - libmpg ships badly created librarie- Change ssh_use_pts to use macro and only inherited sshd_devpts_t - Allow confined users to read systemd_logind seat information - libmpg ships badly created libraries - Add support for strongswan.service - Add labeling for strongswan - Allow l2tpd_t to read network manager content in /run directory - Allow rsync to getattr any file in rsync_data_t - Add labeling and filename transition for .grl-podcasts- mount.glusterfs executes glusterfsd binary - Allow systemd_hostnamed_t to stream connect to systemd - Dontaudit any user doing a access check - Allow obex-data-server to request the kernel to load a module - Allow gpg-agent to manage gnome content (~/.cache/gpg-agent-info) - Allow gpg-agent to read /proc/sys/crypto/fips_enabled - Add new types for antivirus.pp policy module - Allow gnomesystemmm_t caps because of ioprio_set - Make sure if mozilla_plugin creates files while in permissive mode, they get created with the correct label, user_home_t - Allow gnomesystemmm_t caps because of ioprio_set - Allow NM rawip socket - files_relabel_non_security_files can not be used with boolean - Add interface to thumb_t dbus_chat to allow it to read remote process state - ALlow logrotate to domtrans to mdadm_t - kde gnomeclock wants to write content to /tmp- kde gnomeclock wants to write content to /tmp - /usr/libexec/kde4/kcmdatetimehelper attempts to create /root/.kde - Allow blueman_t to rwx zero_device_t, for some kind of jre - Allow mozilla_plugin_t to rwx zero_device_t, for some kind of jre - Ftp full access should be allowed to create directories as well as files - Add boolean to allow rsync_full_acces, so that an rsync server can write all - over the local machine - logrotate needs to rotate logs in openshift directories, needs back port to RHEL6 - Add missing vpnc_roles type line - Allow stapserver to write content in /tmp - Allow gnome keyring to create keyrings dir in ~/.local/share - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Add interface to colord_t dbus_chat to allow it to read remote process state - Allow colord_t to read cupsd_t state - Add mate-thumbnail-font as thumnailer - Allow sectoolm to sys_ptrace since it is looking at other proceses /proc data. - Allow qpidd to list /tmp. Needed by ssl - Only allow init_t to transition to rsync_t domain, not initrc_t. This should be back ported to F17, F18 - - Added systemd support for ksmtuned - Added booleans ksmtuned_use_nfs ksmtuned_use_cifs - firewalld seems to be creating mmap files which it needs to execute in /run /tmp and /dev/shm. Would like to clean this up but for now we will allow - Looks like qpidd_t needs to read /dev/random - Lots of probing avc's caused by execugting gpg from staff_t - Dontaudit senmail triggering a net_admin avc - Change thumb_role to use thumb_run, not sure why we have a thumb_role, needs back port - Logwatch does access check on mdadm binary - Add raid_access_check_mdadm() iterface- Fix systemd_manage_unit_symlinks() interface - Call systemd_manage_unit_symlinks(() which is correct interface - Add filename transition for opasswd - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow sytstemd-timedated to get status of init_t - Add new systemd policies for hostnamed and rename gnomeclock_t to systemd_timedate_t - colord needs to communicate with systemd and systemd_logind, also remove duplicate rules - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow gpg_t to manage all gnome files - Stop using pcscd_read_pub_files - New rules for xguest, dontaudit attempts to dbus chat - Allow firewalld to create its mmap files in tmpfs and tmp directories - Allow firewalld to create its mmap files in tmpfs and tmp directories - run unbound-chkconf as named_t, so it can read dnssec - Colord is reading xdm process state, probably reads state of any apps that sends dbus message - Allow mdadm_t to change the kernel scheduler - mythtv policy - Update mandb_admin() interface - Allow dsspam to listen on own tpc_socket - seutil_filetrans_named_content needs to be optional - Allow sysadm_t to execute content in his homedir - Add attach_queue to tun_socket, new patch from Paul Moore - Change most of selinux configuration types to security_file_type. - Add filename transition rules for selinux configuration - ssh into a box with -X -Y requires ssh_use_ptys - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Allow all unpriv userdomains to send dbus messages to hostnamed and timedated - New allow rules found by Tom London for systemd_hostnamed- Allow systemd-tmpfiles to relabel lpd spool files - Ad labeling for texlive bash scripts - Add xserver_filetrans_fonts_cache_home_content() interface - Remove duplicate rules from *.te - Add support for /var/lock/man-db.lock - Add support for /var/tmp/abrt(/.*)? - Add additional labeling for munin cgi scripts - Allow httpd_t to read munin conf files - Allow certwatch to read meminfo - Fix nscd_dontaudit_write_sock_file() interfac - Fix gnome_filetrans_home_content() to include also "fontconfig" dir as cache_home_t - llow mozilla_plugin_t to create HOMEDIR/.fontconfig with the proper labeling- Allow gnomeclock to talk to puppet over dbus - Allow numad access discovered by Dominic - Add support for HOME_DIR/.maildir - Fix attribute_role for mozilla_plugin_t domain to allow staff_r to access this domain - Allow udev to relabel udev_var_run_t lnk_files - New bin_t file in mcelog- Remove all mcs overrides and replace with t1 != mcs_constrained_types - Add attribute_role for iptables - mcs_process_set_categories needs to be called for type - Implement additional role_attribute statements - Sodo domain is attempting to get the additributes of proc_kcore_t - Unbound uses port 8953 - Allow svirt_t images to compromise_kernel when using pci-passthrough - Add label for dns lib files - Bluetooth aquires a dbus name - Remove redundant files_read_usr_file calling - Remove redundant files_read_etc_file calling - Fix mozilla_run_plugin() - Add role_attribute support for more domains- Mass merge with upstream- Bump the policy version to 28 to match selinux userspace - Rebuild versus latest libsepol- Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Add labeling for /var/named/chroot/etc/localtim- Allow setroubleshoot_fixit to execute rpm - zoneminder needs to connect to httpd ports where remote cameras are listening - Allow firewalld to execute content created in /run directory - Allow svirt_t to read generic certs - Dontaudit leaked ps content to mozilla plugin - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - init scripts are creating systemd_unit_file_t directories- systemd_logind_t is looking at all files under /run/user/apache - Allow systemd to manage all user tmp files - Add labeling for /var/named/chroot/etc/localtime - Allow netlabel_peer_t type to flow over netif_t and node_t, and only be hindered by MLS, need back port to RHEL6 - Keystone is now using a differnt port - Allow xdm_t to use usbmuxd daemon to control sound - Allow passwd daemon to execute gnome_exec_keyringd - Fix chrome_sandbox policy - Add labeling for /var/run/checkquorum-timer - More fixes for the dspam domain, needs back port to RHEL6 - More fixes for the dspam domain, needs back port to RHEL6 - sssd needs to connect to kerberos password port if a user changes his password - Lots of fixes from RHEL testing of dspam web - Allow chrome and mozilla_plugin to create msgq and semaphores - Fixes for dspam cgi scripts - Fixes for dspam cgi scripts - Allow confine users to ptrace screen - Backport virt_qemu_ga_t changes from RHEL - Fix labeling for dspam.cgi needed for RHEL6 - We need to back port this policy to RHEL6, for lxc domains - Dontaudit attempts to set sys_resource of logrotate - Allow corosync to read/write wdmd's tmpfs files - I see a ptrace of mozilla_plugin_t by staff_t, will allow without deny_ptrace being set - Allow cron jobs to read bind config for unbound - libvirt needs to inhibit systemd - kdumpctl needs to delete boot_t files - Fix duplicate gnome_config_filetrans - virtd_lxc_t is using /dev/fuse - Passenger needs to create a directory in /var/log, needs a backport to RHEL6 for openshift - apcupsd can be setup to listen to snmp trafic - Allow transition from kdumpgui to kdumpctl - Add fixes for munin CGI scripts - Allow deltacloud to connect to openstack at the keystone port - Allow domains that transition to svirt domains to be able to signal them - Fix file context of gstreamer in .cache directory - libvirt is communicating with logind - NetworkManager writes to the systemd inhibit pipe- Allow munin disk plugins to get attributes of all directories - Allow munin disk plugins to get attributes of all directorie - Allow logwatch to get attributes of all directories - Fix networkmanager_manage_lib() interface - Fix gnome_manage_config() to allow to manage sock_file - Fix virtual_domain_context - Add support for dynamic DNS for DHCPv6- Allow svirt to use netlink_route_socket which was a part of auth_use_nsswitch - Add additional labeling for /var/www/openshift/broker - Fix rhev policy - Allow openshift_initrc domain to dbus chat with systemd_logind - Allow httpd to getattr passenger log file if run_stickshift - Allow consolehelper-gtk to connect to xserver - Add labeling for the tmp-inst directory defined in pam_namespace.conf - Add lvm_metadata_t labeling for /etc/multipath- consoletype is no longer used- Add label for efivarfs - Allow certmonger to send signal to itself - Allow plugin-config to read own process status - Add more fixes for pacemaker - apache/drupal can run clamscan on uploaded content - Allow chrome_sandbox_nacl_t to read pid 1 content- Fix MCS Constraints to control ingres and egres controls on the network. - Change name of svirt_nokvm_t to svirt_tcg_t - Allow tuned to request the kernel to load kernel modules- Label /var/lib/pgsql/.ssh as ssh_home_t - Add labeling for /usr/bin/pg_ctl - Allow systemd-logind to manage keyring user tmp dirs - Add support for 7389/tcp port - gems seems to be placed in lots of places - Since xdm is running a full session, it seems to be trying to execute lots of executables via dbus - Add back tcp/8123 port as http_cache port - Add ovirt-guest-agent\.pid labeling - Allow xend to run scsi_id - Allow rhsmcertd-worker to read "physical_package_id" - Allow pki_tomcat to connect to ldap port - Allow lpr to read /usr/share/fonts - Allow open file from CD/DVD drive on domU - Allow munin services plugins to talk to SSSD - Allow all samba domains to create samba directory in var_t directories - Take away svirt_t ability to use nsswitch - Dontaudit attempts by openshift to read apache logs - Allow apache to create as well as append _ra_content_t - Dontaudit sendmail_t reading a leaked file descriptor - Add interface to have admin transition /etc/prelink.cache to the proper label - Add sntp support to ntp policy - Allow firewalld to dbus chat with devicekit_power - Allow tuned to call lsblk - Allow tor to read /proc/sys/kernel/random/uuid - Add tor_can_network_relay boolean- Add openshift_initrc_signal() interface - Fix typos - dspam port is treat as spamd_port_t - Allow setroubleshoot to getattr on all executables - Allow tuned to execute profiles scripts in /etc/tuned - Allow apache to create directories to store its log files - Allow all directories/files in /var/log starting with passenger to be labeled passenger_log_t - Looks like apache is sending sinal to openshift_initrc_t now,needs back port to RHEL6 - Allow Postfix to be configured to listen on TCP port 10026 for email from DSPAM - Add filename transition for /etc/tuned/active_profile - Allow condor_master to send mails - Allow condor_master to read submit.cf - Allow condor_master to create /tmp files/dirs - Allow condor_mater to send sigkill to other condor domains - Allow condor_procd sigkill capability - tuned-adm wants to talk with tuned daemon - Allow kadmind and krb5kdc to also list sssd_public_t - Allow accountsd to dbus chat with init - Fix git_read_generic_system_content_files() interface - pppd wants sys_nice by nmcli because of "syscall=sched_setscheduler" - Fix mozilla_plugin_can_network_connect to allow to connect to all ports - Label all munin plugins which are not covered by munin plugins policy as unconfined_munin_plugin_exec_t - dspam wants to search /var/spool for opendkim data - Revert "Add support for tcp/10026 port as dspam_port_t" - Turning on labeled networking requires additional access for netlabel_peer_t; these allow rules need to be back ported to RHEL6 - Allow all application domains to use fifo_files passed in from userdomains, also allow them to write to tmp_files inherited from userdomain - Allow systemd_tmpfiles_t to setattr on mandb_cache_t- consolekit.pp was not removed from the postinstall script- Add back consolekit policy - Silence bootloader trying to use inherited tty - Silence xdm_dbusd_t trying to execute telepathy apps - Fix shutdown avcs when machine has unconfined.pp disabled - The host and a virtual machine can share the same printer on a usb device - Change oddjob to transition to a ranged openshift_initr_exec_t when run from oddjob - Allow abrt_watch_log_t to execute bin_t - Allow chrome sandbox to write content in ~/.config/chromium - Dontaudit setattr on fontconfig dir for thumb_t - Allow lircd to request the kernel to load module - Make rsync as userdom_home_manager - Allow rsync to search automount filesystem - Add fixes for pacemaker- Add support for 4567/tcp port - Random fixes from Tuomo Soini - xdm wants to get init status - Allow programs to run in fips_mode - Add interface to allow the reading of all blk device nodes - Allow init to relabel rpcbind sock_file - Fix labeling for lastlog and faillog related to logrotate - ALlow aeolus_configserver to use TRAM port - Add fixes for aeolus_configserver - Allow snmpd to connect to snmp port - Allow spamd_update to create spamd_var_lib_t directories - Allow domains that can read sssd_public_t files to also list the directory - Remove miscfiles_read_localization, this is defined for all domains- Allow syslogd to request the kernel to load a module - Allow syslogd_t to read the network state information - Allow xdm_dbusd_t connect to the system DBUS - Add support for 7389/tcp port - Allow domains to read/write all inherited sockets - Allow staff_t to read kmsg - Add awstats_purge_apache_log boolean - Allow ksysguardproces to read /.config/Trolltech.conf - Allow passenger to create and append puppet log files - Add puppet_append_log and puppet_create_log interfaces - Add puppet_manage_log() interface - Allow tomcat domain to search tomcat_var_lib_t - Allow pki_tomcat_t to connect to pki_ca ports - Allow pegasus_t to have net_admin capability - Allow pegasus_t to write /sys/class/net//flags - Allow mailserver_delivery to manage mail_home_rw_t lnk_files - Allow fetchmail to create log files - Allow gnomeclock to manage home config in .kde - Allow bittlebee to read kernel sysctls - Allow logrotate to list /root- Fix userhelper_console_role_template() - Allow enabling Network Access Point service using blueman - Make vmware_host_t as unconfined domain - Allow authenticate users in webaccess via squid, using mysql as backend - Allow gathers to get various metrics on mounted file systems - Allow firewalld to read /etc/hosts - Fix cron_admin_role() to make sysadm cronjobs running in the sysadm_t instead of cronjob_t - Allow kdumpgui to read/write to zipl.conf - Commands needed to get mock to build from staff_t in enforcing mode - Allow mdadm_t to manage cgroup files - Allow all daemons and systemprocesses to use inherited initrc_tmp_t files - dontaudit ifconfig_t looking at fifo_files that are leaked to it - Add lableing for Quest Authentication System- Fix filetrans interface definitions - Dontaudit xdm_t to getattr on BOINC lib files - Add systemd_reload_all_services() interface - Dontaudit write access on /var/lib/net-snmp/mib_indexes - Only stop mcsuntrustedproc from relableing files - Allow accountsd to dbus chat with gdm - Allow realmd to getattr on all fs - Allow logrotate to reload all services - Add systemd unit file for radiusd - Allow winbind to create samba pid dir - Add labeling for /var/nmbd/unexpected - Allow chrome and mozilla plugin to connect to msnp ports- Fix storage_rw_inherited_fixed_disk_dev() to cover also blk_file - Dontaudit setfiles reading /dev/random - On initial boot gnomeclock is going to need to be set buy gdm - Fix tftp_read_content() interface - Random apps looking at kernel file systems - Testing virt with lxc requiers additional access for virsh_t - New allow rules requied for latest libvirt, libvirt talks directly to journald,lxc setup tool needs compromize_kernel,and we need ipc_lock in the container - Allow MPD to read /dev/radnom - Allow sandbox_web_type to read logind files which needs to read pulseaudio - Allow mozilla plugins to read /dev/hpet - Add labeling for /var/lib/zarafa-webap - Allow BOINC client to use an HTTP proxy for all connections - Allow rhsmertd to domain transition to dmidecod - Allow setroubleshootd to send D-Bus msg to ABRT- Define usbtty_device_t as a term_tty - Allow svnserve to accept a connection - Allow xend manage default virt_image_t type - Allow prelink_cron_system_t to overide user componant when executing cp - Add labeling for z-push - Gnomeclock sets the realtime clock - Openshift seems to be storing apache logs in /var/lib/openshift/.log/httpd - Allow lxc domains to use /dev/random and /dev/urandom- Add port defintion for tcp/9000 - Fix labeling for /usr/share/cluster/checkquorum to label also checkquorum.wdmd - Add rules and labeling for $HOME/cache/\.gstreamer-.* directory - Add support for CIM provider openlmi-networking which uses NetworkManager dbus API - Allow shorewall_t to create netlink_socket - Allow krb5admind to block suspend - Fix labels on /var/run/dlm_controld /var/log/dlm_controld - Allow krb5kdc to block suspend - gnomessytemmm_t needs to read /etc/passwd - Allow cgred to read all sysctls- Allow all domains to read /proc/sys/vm/overcommit_memory - Make proc_numa_t an MLS Trusted Object - Add /proc/numactl support for confined users - Allow ssh_t to connect to any port > 1023 - Add openvswitch domain - Pulseaudio tries to create directories in gnome_home_t directories - New ypbind pkg wants to search /var/run which is caused by sd_notify - Allow NM to read certs on NFS/CIFS using use_nfs_*, use_samba_* booleans - Allow sanlock to read /dev/random - Treat php-fpm with httpd_t - Allow domains that can read named_conf_t to be able to list the directories - Allow winbind to create sock files in /var/run/samba- Add smsd policy - Add support for OpenShift sbin labelin - Add boolean to allow virt to use rawip - Allow mozilla_plugin to read all file systems with noxattrs support - Allow kerberos to write on anon_inodefs fs - Additional access required by fenced - Add filename transitions for passwd.lock/group.lock - UPdate man pages - Create coolkey directory in /var/cache with the correct label- Fix label on /etc/group.lock - Allow gnomeclock to create lnk_file in /etc - label /root/.pki as a home_cert_t - Add interface to make sure rpcbind.sock is created with the correct label - Add definition for new directory /var/lib/os-probe and bootloader wants to read udev rules - opendkim should be a part of milter - Allow libvirt to set the kernel sched algorythm - Allow mongod to read sysfs_t - Add authconfig policy - Remove calls to miscfiles_read_localization all domains get this - Allow virsh_t to read /root/.pki/ content - Add label for log directory under /var/www/stickshift- Allow getty to setattr on usb ttys - Allow sshd to search all directories for sshd_home_t content - Allow staff domains to send dbus messages to kdumpgui - Fix labels on /etc/.pwd.lock and friends to be passwd_file_t - Dontaudit setfiles reading urand - Add files_dontaudit_list_tmp() for domains to which we added sys_nice/setsched - Allow staff_gkeyringd_t to read /home/$USER/.local/share/keyrings dir - Allow systemd-timedated to read /dev/urandom - Allow entropyd_t to read proc_t (meminfo) - Add unconfined munin plugin - Fix networkmanager_read_conf() interface - Allow blueman to list /tmp which is needed by sys_nic/setsched - Fix label of /etc/mail/aliasesdb-stamp - numad is searching cgroups - realmd is communicating with networkmanager using dbus - Lots of fixes to try to get kdump to work- Allow loging programs to dbus chat with realmd - Make apache_content_template calling as optional - realmd is using policy kit- Add new selinuxuser_use_ssh_chroot boolean - dbus needs to be able to read/write inherited fixed disk device_t passed through it - Cleanup netutils process allow rule - Dontaudit leaked fifo files from openshift to ping - sanlock needs to read mnt_t lnk files - Fail2ban needs to setsched and sys_nice- Change default label of all files in /var/run/rpcbind - Allow sandbox domains (java) to read hugetlbfs_t - Allow awstats cgi content to create tmp files and read apache log files - Allow setuid/setgid for cupsd-config - Allow setsched/sys_nice pro cupsd-config - Fix /etc/localtime sym link to be labeled locale_t - Allow sshd to search postgresql db t since this is a homedir - Allow xwindows users to chat with realmd - Allow unconfined domains to configure all files and null_device_t service- Adopt pki-selinux policy- pki is leaking which we dontaudit until a pki code fix - Allow setcap for arping - Update man pages - Add labeling for /usr/sbin/mcollectived - pki fixes - Allow smokeping to execute fping in the netutils_t domain- Allow mount to relabelfrom unlabeled file systems - systemd_logind wants to send and receive messages from devicekit disk over dbus to make connected mouse working - Add label to get bin files under libreoffice labeled correctly - Fix interface to allow executing of base_ro_file_type - Add fixes for realmd - Update pki policy - Add tftp_homedir boolean - Allow blueman sched_setscheduler - openshift user domains wants to r/w ssh tcp sockets- Additional requirements for disable unconfined module when booting - Fix label of systemd script files - semanage can use -F /dev/stdin to get input - syslog now uses kerberos keytabs - Allow xserver to compromise_kernel access - Allow nfsd to write to mount_var_run_t when running the mount command - Add filename transition rule for bin_t directories - Allow files to read usr_t lnk_files - dhcpc wants chown - Add support for new openshift labeling - Clean up for tunable+optional statements - Add labeling for /usr/sbin/mkhomedir_helper - Allow antivirus domain to managa amavis spool files - Allow rpcbind_t to read passwd - Allow pyzor running as spamc to manage amavis spool- Add interfaces to read kernel_t proc info - Missed this version of exec_all - Allow anyone who can load a kernel module to compromise kernel - Add oddjob_dbus_chat to openshift apache policy - Allow chrome_sandbox_nacl_t to send signals to itself - Add unit file support to usbmuxd_t - Allow all openshift domains to read sysfs info - Allow openshift domains to getattr on all domains- MLS fixes from Dan - Fix name of capability2 secure_firmware->compromise_kerne- Allow xdm to search all file systems - Add interface to allow the config of all files - Add rngd policy - Remove kgpg as a gpg_exec_t type - Allow plymouthd to block suspend - Allow systemd_dbus to config any file - Allow system_dbus_t to configure all services - Allow freshclam_t to read usr_files - varnishd requires execmem to load modules- Allow semanage to verify types - Allow sudo domain to execute user home files - Allow session_bus_type to transition to user_tmpfs_t - Add dontaudit caused by yum updates - Implement pki policy but not activated- tuned wants to getattr on all filesystems - tuned needs also setsched. The build is needed for test day- Add policy for qemu-qa - Allow razor to write own config files - Add an initial antivirus policy to collect all antivirus program - Allow qdisk to read usr_t - Add additional caps for vmware_host - Allow tmpfiles_t to setattr on mandb_cache_t - Dontaudit leaked files into mozilla_plugin_config_t - Allow wdmd to getattr on tmpfs - Allow realmd to use /dev/random - allow containers to send audit messages - Allow root mount any file via loop device with enforcing mls policy - Allow tmpfiles_t to setattr on mandb_cache_t - Allow tmpfiles_t to setattr on mandb_cache_t - Make userdom_dontaudit_write_all_ not allow open - Allow init scripts to read all unit files - Add support for saphostctrl ports- Add kernel_read_system_state to sandbox_client_t - Add some of the missing access to kdumpgui - Allow systemd_dbusd_t to status the init system - Allow vmnet-natd to request the kernel to load a module - Allow gsf-office-thum to append .cache/gdm/session.log - realmd wants to read .config/dconf/user - Firewalld wants sys_nice/setsched - Allow tmpreaper to delete mandb cache files - Firewalld wants sys_nice/setsched - Allow firewalld to perform a DNS name resolution - Allown winbind to read /usr/share/samba/codepages/lowcase.dat - Add support for HTTPProxy* in /etc/freshclam.conf - Fix authlogin_yubike boolean - Extend smbd_selinux man page to include samba booleans - Allow dhcpc to execute consoletype - Allow ping to use inherited tmp files created in init scripts - On full relabel with unconfined domain disabled, initrc was running some chcon's - Allow people who delete man pages to delete mandb cache files- Add missing permissive domains- Add new mandb policy - ALlow systemd-tmpfiles_t to relabel mandb_cache_t - Allow logrotate to start all unit files- Add fixes for ctbd - Allow nmbd to stream connect to ctbd - Make cglear_t as nsswitch_domain - Fix bogus in interfaces - Allow openshift to read/write postfix public pipe - Add postfix_manage_spool_maildrop_files() interface - stickshift paths have been renamed to openshift - gnome-settings-daemon wants to write to /run/systemd/inhibit/ pipes - Update man pages, adding ENTRYPOINTS- Add mei_device_t - Make sure gpg content in homedir created with correct label - Allow dmesg to write to abrt cache files - automount wants to search virtual memory sysctls - Add support for hplip logs stored in /var/log/hp/tmp - Add labeling for /etc/owncloud/config.php - Allow setroubleshoot to send analysys to syslogd-journal - Allow virsh_t to interact with new fenced daemon - Allow gpg to write to /etc/mail/spamassassiin directories - Make dovecot_deliver_t a mail server delivery type - Add label for /var/tmp/DNS25- Fixes for tomcat_domain template interface- Remove init_systemd and init_upstart boolean, Move init_daemon_domain and init_system_domain to use attributes - Add attribute to all base os types. Allow all domains to read all ro base OS types- Additional unit files to be defined as power unit files - Fix more boolean names- Fix boolean name so subs will continue to work- dbus needs to start getty unit files - Add interface to allow system_dbusd_t to start the poweroff service - xdm wants to exec telepathy apps - Allow users to send messages to systemdlogind - Additional rules needed for systemd and other boot apps - systemd wants to list /home and /boot - Allow gkeyringd to write dbus/conf file - realmd needs to read /dev/urand - Allow readahead to delete /.readahead if labeled root_t, might get created before policy is loaded- Fixes to safe more rules - Re-write tomcat_domain_template() - Fix passenger labeling - Allow all domains to read man pages - Add ephemeral_port_t to the 'generic' port interfaces - Fix the names of postgresql booleans- Stop using attributes form netlabel_peer and syslog, auth_use_nsswitch setsup netlabel_peer - Move netlable_peer check out of booleans - Remove call to recvfrom_netlabel for kerberos call - Remove use of attributes when calling syslog call - Move -miscfiles_read_localization to domain.te to save hundreds of allow rules - Allow all domains to read locale files. This eliminates around 1500 allow rules- Cleanup nis_use_ypbind_uncond interface - Allow rndc to block suspend - tuned needs to modify the schedule of the kernel - Allow svirt_t domains to read alsa configuration files - ighten security on irc domains and make sure they label content in homedir correctly - Add filetrans_home_content for irc files - Dontaudit all getattr access for devices and filesystems for sandbox domains - Allow stapserver to search cgroups directories - Allow all postfix domains to talk to spamd- Add interfaces to ignore setattr until kernel fixes this to be checked after the DAC check - Change pam_t to pam_timestamp_t - Add dovecot_domain attribute and allow this attribute block_suspend capability2 - Add sanlock_use_fusefs boolean - numad wants send/recieve msg - Allow rhnsd to send syslog msgs - Make piranha-pulse as initrc domain - Update openshift instances to dontaudit setattr until the kernel is fixed.- Fix auth_login_pgm_domain() interface to allow domains also managed user tmp dirs because of #856880 related to pam_systemd - Remove pam_selinux.8 which conflicts with man page owned by the pam package - Allow glance-api to talk to mysql - ABRT wants to read Xorg.0.log if if it detects problem with Xorg - Fix gstreamer filename trans. interface- Man page fixes by Dan Walsh- Allow postalias to read postfix config files - Allow man2html to read man pages - Allow rhev-agentd to search all mountpoints - Allow rhsmcertd to read /dev/random - Add tgtd_stream_connect() interface - Add cyrus_write_data() interface - Dontaudit attempts by sandboxX clients connectiing to the xserver_port_t - Add port definition for tcp/81 as http_port_t - Fix /dev/twa labeling - Allow systemd to read modules config- Merge openshift policy - Allow xauth to read /dev/urandom - systemd needs to relabel content in /run/systemd directories - Files unconfined should be able to perform all services on all files - Puppet tmp file can be leaked to all domains - Dontaudit rhsmcertd-worker to search /root/.local - Allow chown capability for zarafa domains - Allow system cronjobs to runcon into openshift domains - Allow virt_bridgehelper_t to manage content in the svirt_home_t labeled directories- nmbd wants to create /var/nmbd - Stop transitioning out of anaconda and firstboot, just causes AVC messages - Allow clamscan to read /etc files - Allow bcfg2 to bind cyphesis port - heartbeat should be run as rgmanager_t instead of corosync_t - Add labeling for /etc/openldap/certs - Add labeling for /opt/sartest directory - Make crontab_t as userdom home reader - Allow tmpreaper to list admin_home dir - Add defition for imap_0 replay cache file - Add support for gitolite3 - Allow virsh_t to send syslog messages - allow domains that can read samba content to be able to list the directories also - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd - Separate out sandbox from sandboxX policy so we can disable it by default - Run dmeventd as lvm_t - Mounting on any directory requires setattr and write permissions - Fix use_nfs_home_dirs() boolean - New labels for pam_krb5 - Allow init and initrc domains to sys_ptrace since this is needed to look at processes not owned by uid 0 - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd- Separate sandbox policy into sandbox and sandboxX, and disable sandbox by default on fresh installs - Allow domains that can read etc_t to read etc_runtime_t - Allow all domains to use inherited tmpfiles- Allow realmd to read resolv.conf - Add pegasus_cache_t type - Label /usr/sbin/fence_virtd as virsh_exec_t - Add policy for pkcsslotd - Add support for cpglockd - Allow polkit-agent-helper to read system-auth-ac - telepathy-idle wants to read gschemas.compiled - Allow plymouthd to getattr on fs_t - Add slpd policy - Allow ksysguardproces to read/write config_usr_t- Fix labeling substitution so rpm will label /lib/systemd content correctly- Add file name transitions for ttyACM0 - spice-vdagent(d)'s are going to log over to syslog - Add sensord policy - Add more fixes for passenger policy related to puppet - Allow wdmd to create wdmd_tmpfs_t - Fix labeling for /var/run/cachefilesd\.pid - Add thumb_tmpfs_t files type- Allow svirt domains to manage the network since this is containerized - Allow svirt_lxc_net_t to send audit messages- Make "snmpwalk -mREDHAT-CLUSTER-MIB ...." working - Allow dlm_controld to execute dlm_stonith labeled as bin_t - Allow GFS2 working on F17 - Abrt needs to execute dmesg - Allow jockey to list the contents of modeprobe.d - Add policy for lightsquid as squid_cron_t - Mailscanner is creating files and directories in /tmp - dmesg is now reading /dev/kmsg - Allow xserver to communicate with secure_firmware - Allow fsadm tools (fsck) to read /run/mount contnet - Allow sysadm types to read /dev/kmsg -- Allow postfix, sssd, rpcd to block_suspend - udev seems to need secure_firmware capability - Allow virtd to send dbus messages to firewalld so it can configure the firewall- Fix labeling of content in /run created by virsh_t - Allow condor domains to read kernel sysctls - Allow condor_master to connect to amqp - Allow thumb drives to create shared memory and semaphores - Allow abrt to read mozilla_plugin config files - Add labels for lightsquid - Default files in /opt and /usr that end in .cgi as httpd_sys_script_t, allow - dovecot_auth_t uses ldap for user auth - Allow domains that can read dhcp_etc_t to read lnk_files - Add more then one watchdog device - Allow useradd_t to manage etc_t files so it can rename it and edit them - Fix invalid class dir should be fifo_file - Move /run/blkid to fsadm and make sure labeling is correct- Fix bogus regex found by eparis - Fix manage run interface since lvm needs more access - syslogd is searching cgroups directory - Fixes to allow virt-sandbox-service to manage lxc var run content- Fix Boolean settings - Add new libjavascriptcoregtk as textrel_shlib_t - Allow xdm_t to create xdm_home_t directories - Additional access required for systemd - Dontaudit mozilla_plugin attempts to ipc_lock - Allow tmpreaper to delete unlabeled files - Eliminate screen_tmp_t and allow it to manage user_tmp_t - Dontaudit mozilla_plugin_config_t to append to leaked file descriptors - Allow web plugins to connect to the asterisk ports - Condor will recreate the lock directory if it does not exist - Oddjob mkhomedir needs to connectto user processes - Make oddjob_mkhomedir_t a userdom home manager- Put placeholder back in place for proper numbering of capabilities - Systemd also configures init scripts- Fix ecryptfs interfaces - Bootloader seems to be trolling around /dev/shm and /dev - init wants to create /etc/systemd/system-update.target.wants - Fix systemd_filetrans call to move it out of tunable - Fix up policy to work with systemd userspace manager - Add secure_firmware capability and remove bogus epolwakeup - Call seutil_*_login_config interfaces where should be needed - Allow rhsmcertd to send signal to itself - Allow thin domains to send signal to itself - Allow Chrome_ChildIO to read dosfs_t- Add role rules for realmd, sambagui- Add new type selinux_login_config_t for /etc/selinux//logins/ - Additional fixes for seutil_manage_module_store() - dbus_system_domain() should be used with optional_policy - Fix svirt to be allowed to use fusefs file system - Allow login programs to read /run/ data created by systemd_login - sssd wants to write /etc/selinux//logins/ for SELinux PAM module - Fix svirt to be allowed to use fusefs file system - Allow piranha domain to use nsswitch - Sanlock needs to send Kill Signals to non root processes - Pulseaudio wants to execute /run/user/PID/.orc- Fix saslauthd when it tries to read /etc/shadow - Label gnome-boxes as a virt homedir - Need to allow svirt_t ability to getattr on nfs_t file systems - Update sanlock policy to solve all AVC's - Change confined users can optionally manage virt content - Handle new directories under ~/.cache - Add block suspend to appropriate domains - More rules required for containers - Allow login programs to read /run/ data created by systemd_logind - Allow staff users to run svirt_t processes- Update to upstream- More fixes for systemd to make rawhide booting from Dan Walsh- Add systemd fixes to make rawhide booting- Add systemd_logind_inhibit_var_run_t attribute - Remove corenet_all_recvfrom_unlabeled() for non-contrib policies because we moved it to domain.if for all domain_type - Add interface for mysqld to dontaudit signull to all processes - Label new /var/run/journal directory correctly - Allow users to inhibit suspend via systemd - Add new type for the /var/run/inhibit directory - Add interface to send signull to systemd_login so avahi can send them - Allow systemd_passwd to send syslog messages - Remove corenet_all_recvfrom_unlabeled() calling fro policy files - Allow editparams.cgi running as httpd_bugzilla_script_t to read /etc/group - Allow smbd to read cluster config - Add additional labeling for passenger - Allow dbus to inhibit suspend via systemd - Allow avahi to send signull to systemd_login- Add interface to dontaudit getattr access on sysctls - Allow sshd to execute /bin/login - Looks like xdm is recreating the xdm directory in ~/.cache/ on login - Allow syslog to use the leaked kernel_t unix_dgram_socket from system-jounald - Fix semanage to work with unconfined domain disabled on F18 - Dontaudit attempts by mozilla plugins to getattr on all kernel sysctls - Virt seems to be using lock files - Dovecot seems to be searching directories of every mountpoint - Allow jockey to read random/urandom, execute shell and install third-party drivers - Add aditional params to allow cachedfiles to manage its content - gpg agent needs to read /dev/random - The kernel hands an svirt domains /SYSxxxxx which is a tmpfs that httpd wants to read and write - Add a bunch of dontaudit rules to quiet svirt_lxc domains - Additional perms needed to run svirt_lxc domains - Allow cgclear to read cgconfig - Allow sys_ptrace capability for snmp - Allow freshclam to read /proc - Allow procmail to manage /home/user/Maildir content - Allow NM to execute wpa_cli - Allow amavis to read clamd system state - Regenerate man pages- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Add realmd and stapserver policies - Allow useradd to manage stap-server lib files - Tighten up capabilities for confined users - Label /etc/security/opasswd as shadow_t - Add label for /dev/ecryptfs - Allow condor_startd_t to start sshd with the ranged - Allow lpstat.cups to read fips_enabled file - Allow pyzor running as spamc_t to create /root/.pyzor directory - Add labelinf for amavisd-snmp init script - Add support for amavisd-snmp - Allow fprintd sigkill self - Allow xend (w/o libvirt) to start virtual machines - Allow aiccu to read /etc/passwd - Allow condor_startd to Make specified domain MCS trusted for setting any category set for the processes it executes - Add condor_startd_ranged_domtrans_to() interface - Add ssd_conf_t for /etc/sssd - accountsd needs to fchown some files/directories - Add ICACLient and zibrauserdata as mozilla_filetrans_home_content - SELinux reports afs_t needs dac_override to read /etc/mtab, even though everything works, adding dontaudit - Allow xend_t to read the /etc/passwd file- Until we figure out how to fix systemd issues, allow all apps that send syslog messages to send them to kernel_t - Add init_access_check() interface - Fix label on /usr/bin/pingus to not be labeled as ping_exec_t - Allow tcpdump to create a netlink_socket - Label newusers like useradd - Change xdm log files to be labeled xdm_log_t - Allow sshd_t with privsep to work in MLS - Allow freshclam to update databases thru HTTP proxy - Allow s-m-config to access check on systemd - Allow abrt to read public files by default - Fix amavis_create_pid_files() interface - Add labeling and filename transition for dbomatic.log - Allow system_dbusd_t to stream connect to bluetooth, and use its socket - Allow amavisd to execute fsav - Allow tuned to use sys_admin and sys_nice capabilities - Add php-fpm policy from Bryan - Add labeling for aeolus-configserver-thinwrapper - Allow thin domains to execute shell - Fix gnome_role_gkeyringd() interface description - Lot of interface fixes - Allow OpenMPI job running as condor_startd_ssh_t to manage condor lib files - Allow OpenMPI job to use kerberos - Make deltacloudd_t as nsswitch_domain - Allow xend_t to run lsscsi - Allow qemu-dm running as xend_t to create tun_socket - Add labeling for /opt/brother/Printers(.*/)?inf - Allow jockey-backend to read pyconfig-64.h labeled as usr_t - Fix clamscan_can_scan_system boolean - Allow lpr to connectto to /run/user/$USER/keyring-22uREb/pkcs11- initrc is calling exportfs which is not confined so it attempts to read nfsd_files - Fixes for passenger running within openshift. - Add labeling for all tomcat6 dirs - Add support for tomcat6 - Allow cobblerd to read /etc/passwd - Allow jockey to read sysfs and and execute binaries with bin_t - Allow thum to use user terminals - Allow cgclear to read cgconfig config files - Fix bcf2g.fc - Remove sysnet_dns_name_resolve() from policies where auth_use_nsswitch() is used for other domains - Allow dbomatic to execute ruby - abrt_watch_log should be abrt_domain - Allow mozilla_plugin to connect to gatekeeper port- add ptrace_child access to process - remove files_read_etc_files() calling from all policies which have auth_use_nsswith() - Allow boinc domains to manage boinc_lib_t lnk_files - Add support for boinc-client.service unit file - Add support for boinc.log - Allow mozilla_plugin execmod on mozilla home files if allow_ex - Allow dovecot_deliver_t to read dovecot_var_run_t - Allow ldconfig and insmod to manage kdumpctl tmp files - Move thin policy out from cloudform.pp and add a new thin poli - pacemaker needs to communicate with corosync streams - abrt is now started on demand by dbus - Allow certmonger to talk directly to Dogtag servers - Change labeling for /var/lib/cobbler/webui_sessions to httpd_c - Allow mozila_plugin to execute gstreamer home files - Allow useradd to delete all file types stored in the users hom - rhsmcertd reads the rpm database - Add support for lightdm- Add tomcat policy - Remove pyzor/razor policy - rhsmcertd reads the rpm database - Dontaudit thumb to setattr on xdm_tmp dir - Allow wicd to execute ldconfig in the networkmanager_t domain - Add /var/run/cherokee\.pid labeling - Allow mozilla_plugin to create mozilla_plugin_tmp_t lnk files too - Allow postfix-master to r/w pipes other postfix domains - Allow snort to create netlink_socket - Add kdumpctl policy - Allow firstboot to create tmp_t files/directories - /usr/bin/paster should not be labeled as piranha_exec_t - remove initrc_domain from tomcat - Allow ddclient to read /etc/passwd - Allow useradd to delete all file types stored in the users homedir - Allow ldconfig and insmod to manage kdumpctl tmp files - Firstboot should be just creating tmp_t dirs and xauth should be allowed to write to those - Transition xauth files within firstboot_tmp_t - Fix labeling of /run/media to match /media - Label all lxdm.log as xserver_log_t - Add port definition for mxi port - Allow local_login_t to execute tmux- apcupsd needs to read /etc/passwd - Sanlock allso sends sigkill - Allow glance_registry to connect to the mysqld port - Dontaudit mozilla_plugin trying to getattr on /dev/gpmctl - Allow firefox plugins/flash to connect to port 1234 - Allow mozilla plugins to delete user_tmp_t files - Add transition name rule for printers.conf.O - Allow virt_lxc_t to read urand - Allow systemd_loigind to list gstreamer_home_dirs - Fix labeling for /usr/bin - Fixes for cloudform services * support FIPS - Allow polipo to work as web caching - Allow chfn to execute tmux- Add support for ecryptfs * ecryptfs does not support xattr * we need labeling for HOMEDIR - Add policy for (u)mount.ecryptfs* - Fix labeling of kerbero host cache files, allow rpc.svcgssd to manage host cache - Allow dovecot to manage Maildir content, fix transitions to Maildir - Allow postfix_local to transition to dovecot_deliver - Dontaudit attempts to setattr on xdm_tmp_t, looks like bogus code - Cleanup interface definitions - Allow apmd to change with the logind daemon - Changes required for sanlock in rhel6 - Label /run/user/apache as httpd_tmp_t - Allow thumb to use lib_t as execmod if boolean turned on - Allow squid to create the squid directory in /var with the correct labe - Add a new policy for glusterd from Bryan Bickford (bbickfor@redhat.com) - Allow virtd to exec xend_exec_t without transition - Allow virtd_lxc_t to unmount all file systems- PolicyKit path has changed - Allow httpd connect to dirsrv socket - Allow tuned to write generic kernel sysctls - Dontaudit logwatch to gettr on /dev/dm-2 - Allow policykit-auth to manage kerberos files - Make condor_startd and rgmanager as initrc domain - Allow virsh to read /etc/passwd - Allow mount to mount on user_tmp_t for /run/user/dwalsh/gvfs - xdm now needs to execute xsession_exec_t - Need labels for /var/lib/gdm - Fix files_filetrans_named_content() interface - Add new attribute - initrc_domain - Allow systemd_logind_t to signal, signull, sigkill all processes - Add filetrans rules for etc_runtime files- Rename boolean names to remove allow_- Mass merge with upstream * new policy topology to include contrib policy modules * we have now two base policy patches- Fix description of authlogin_nsswitch_use_ldap - Fix transition rule for rhsmcertd_t needed for RHEL7 - Allow useradd to list nfs state data - Allow openvpn to manage its log file and directory - We want vdsm to transition to mount_t when executing mount command to make sure /etc/mtab remains labeled correctly - Allow thumb to use nvidia devices - Allow local_login to create user_tmp_t files for kerberos - Pulseaudio needs to read systemd_login /var/run content - virt should only transition named system_conf_t config files - Allow munin to execute its plugins - Allow nagios system plugin to read /etc/passwd - Allow plugin to connect to soundd port - Fix httpd_passwd to be able to ask passwords - Radius servers can use ldap for backing store - Seems to need to mount on /var/lib for xguest polyinstatiation to work. - Allow systemd_logind to list the contents of gnome keyring - VirtualGL need xdm to be able to manage content in /etc/opt/VirtualGL - Add policy for isns-utils- Add policy for subversion daemon - Allow boinc to read passwd - Allow pads to read kernel network state - Fix man2html interface for sepolgen-ifgen - Remove extra /usr/lib/systemd/system/smb - Remove all /lib/systemd and replace with /usr/lib/systemd - Add policy for man2html - Fix the label of kerberos_home_t to krb5_home_t - Allow mozilla plugins to use Citrix - Allow tuned to read /proc/sys/kernel/nmi_watchdog - Allow tune /sys options via systemd's tmpfiles.d "w" type- Dontaudit lpr_t to read/write leaked mozilla tmp files - Add file name transition for .grl-podcasts directory - Allow corosync to read user tmp files - Allow fenced to create snmp lib dirs/files - More fixes for sge policy - Allow mozilla_plugin_t to execute any application - Allow dbus to read/write any open file descriptors to any non security file on the system that it inherits to that it can pass them to another domain - Allow mongod to read system state information - Fix wrong type, we should dontaudit sys_admin for xdm_t not xserver_t - Allow polipo to manage polipo_cache dirs - Add jabbar_client port to mozilla_plugin_t - Cleanup procmail policy - system bus will pass around open file descriptors on files that do not have labels on them - Allow l2tpd_t to read system state - Allow tuned to run ls /dev - Allow sudo domains to read usr_t files - Add label to machine-id - Fix corecmd_read_bin_symlinks cut and paste error- Fix pulseaudio port definition - Add labeling for condor_starter - Allow chfn_t to creat user_tmp_files - Allow chfn_t to execute bin_t - Allow prelink_cron_system_t to getpw calls - Allow sudo domains to manage kerberos rcache files - Allow user_mail_domains to work with courie - Port definitions necessary for running jboss apps within openshift - Add support for openstack-nova-metadata-api - Add support for nova-console* - Add support for openstack-nova-xvpvncproxy - Fixes to make privsep+SELinux working if we try to use chage to change passwd - Fix auth_role() interface - Allow numad to read sysfs - Allow matahari-rpcd to execute shell - Add label for ~/.spicec - xdm is executing lspci as root which is requesting a sys_admin priv but seems to succeed without it - Devicekit_disk wants to read the logind sessions file when writing a cd - Add fixes for condor to make condor jobs working correctly - Change label of /var/log/rpmpkgs to cron_log_t - Access requires to allow systemd-tmpfiles --create to work. - Fix obex to be a user application started by the session bus. - Add additional filename trans rules for kerberos - Fix /var/run/heartbeat labeling - Allow apps that are managing rcache to file trans correctly - Allow openvpn to authenticate against ldap server - Containers need to listen to network starting and stopping events- Make systemd unit files less specific- Fix zarafa labeling - Allow guest_t to fix labeling - corenet_tcp_bind_all_unreserved_ports(ssh_t) should be called with the user_tcp_server boolean - add lxc_contexts - Allow accountsd to read /proc - Allow restorecond to getattr on all file sytems - tmpwatch now calls getpw - Allow apache daemon to transition to pwauth domain - Label content under /var/run/user/NAME/keyring* as gkeyringd_tmp_t - The obex socket seems to be a stream socket - dd label for /var/run/nologin- Allow jetty running as httpd_t to read hugetlbfs files - Allow sys_nice and setsched for rhsmcertd - Dontaudit attempts by mozilla_plugin_t to bind to ssdp ports - Allow setfiles to append to xdm_tmp_t - Add labeling for /export as a usr_t directory - Add labels for .grl files created by gstreamer- Add labeling for /usr/share/jetty/bin/jetty.sh - Add jetty policy which contains file type definitios - Allow jockey to use its own fifo_file and make this the default for all domains - Allow mozilla_plugins to use spice (vnc_port/couchdb) - asterisk wants to read the network state - Blueman now uses /var/lib/blueman- Add label for nodejs_debug - Allow mozilla_plugin_t to create ~/.pki directory and content- Add clamscan_can_scan_system boolean - Allow mysqld to read kernel network state - Allow sshd to read/write condor lib files - Allow sshd to read/write condor-startd tcp socket - Fix description on httpd_graceful_shutdown - Allow glance_registry to communicate with mysql - dbus_system_domain is using systemd to lauch applications - add interfaces to allow domains to send kill signals to user mail agents - Remove unnessary access for svirt_lxc domains, add privs for virtd_lxc_t - Lots of new access required for secure containers - Corosync needs sys_admin capability - ALlow colord to create shm - .orc should be allowed to be created by any app that can create gstream home content, thumb_t to be specific - Add boolean to control whether or not mozilla plugins can create random content in the users homedir - Add new interface to allow domains to list msyql_db directories, needed for libra - shutdown has to be allowed to delete etc_runtime_t - Fail2ban needs to read /etc/passwd - Allow ldconfig to create /var/cache/ldconfig - Allow tgtd to read hardware state information - Allow collectd to create packet socket - Allow chronyd to send signal to itself - Allow collectd to read /dev/random - Allow collectd to send signal to itself - firewalld needs to execute restorecon - Allow restorecon and other login domains to execute restorecon- Allow logrotate to getattr on systemd unit files - Add support for tor systemd unit file - Allow apmd to create /var/run/pm-utils with the correct label - Allow l2tpd to send sigkill to pppd - Allow pppd to stream connect to l2tpd - Add label for scripts in /etc/gdm/ - Allow systemd_logind_t to ignore mcs constraints on sigkill - Fix files_filetrans_system_conf_named_files() interface - Add labels for /usr/share/wordpress/wp-includes/*.php - Allow cobbler to get SELinux mode and booleans- Add unconfined_execmem_exec_t as an alias to bin_t - Allow fenced to read snmp var lib files, also allow it to read usr_t - ontaudit access checks on all executables from mozilla_plugin - Allow all user domains to setexec, so that sshd will work properly if it call setexec(NULL) while running withing a user mode - Allow systemd_tmpfiles_t to getattr all pipes and sockets - Allow glance-registry to send system log messages - semanage needs to manage mock lib files/dirs- Add policy for abrt-watch-log - Add definitions for jboss_messaging ports - Allow systemd_tmpfiles to manage printer devices - Allow oddjob to use nsswitch - Fix labeling of log files for postgresql - Allow mozilla_plugin_t to execmem and execstack by default - Allow firewalld to execute shell - Fix /etc/wicd content files to get created with the correct label - Allow mcelog to exec shell - Add ~/.orc as a gstreamer_home_t - /var/spool/postfix/lib64 should be labeled lib_t - mpreaper should be able to list all file system labeled directories - Add support for apache to use openstack - Add labeling for /etc/zipl.conf and zipl binary - Turn on allow_execstack and turn off telepathy transition for final release- More access required for virt_qmf_t - Additional assess required for systemd-logind to support multi-seat - Allow mozilla_plugin to setrlimit - Revert changes to fuse file system to stop deadlock- Allow condor domains to connect to ephemeral ports - More fixes for condor policy - Allow keystone to stream connect to mysqld - Allow mozilla_plugin_t to read generic USB device to support GPS devices - Allow thum to file name transition gstreamer home content - Allow thum to read all non security files - Allow glance_api_t to connect to ephemeral ports - Allow nagios plugins to read /dev/urandom - Allow syslogd to search postfix spool to support postfix chroot env - Fix labeling for /var/spool/postfix/dev - Allow wdmd chown - Label .esd_auth as pulseaudio_home_t - Have no idea why keyring tries to write to /run/user/dwalsh/dconf/user, but we can dontaudit for now- Add support for clamd+systemd - Allow fresclam to execute systemctl to handle clamd - Change labeling for /usr/sbin/rpc.ypasswd.env - Allow yppaswd_t to execute yppaswd_exec_t - Allow yppaswd_t to read /etc/passwd - Gnomekeyring socket has been moved to /run/user/USER/ - Allow samba-net to connect to ldap port - Allow signal for vhostmd - allow mozilla_plugin_t to read user_home_t socket - New access required for secure Linux Containers - zfs now supports xattrs - Allow quantum to execute sudo and list sysfs - Allow init to dbus chat with the firewalld - Allow zebra to read /etc/passwd- Allow svirt_t to create content in the users homedir under ~/.libvirt - Fix label on /var/lib/heartbeat - Allow systemd_logind_t to send kill signals to all processes started by a user - Fuse now supports Xattr Support- upowered needs to setsched on the kernel - Allow mpd_t to manage log files - Allow xdm_t to create /var/run/systemd/multi-session-x - Add rules for missedfont.log to be used by thumb.fc - Additional access required for virt_qmf_t - Allow dhclient to dbus chat with the firewalld - Add label for lvmetad - Allow systemd_logind_t to remove userdomain sock_files - Allow cups to execute usr_t files - Fix labeling on nvidia shared libraries - wdmd_t needs access to sssd and /etc/passwd - Add boolean to allow ftp servers to run in passive mode - Allow namepspace_init_t to relabelto/from a different user system_u from the user the namespace_init running with - Fix using httpd_use_fusefs - Allow chrome_sandbox_nacl to write inherited user tmp files as we allow it for chrome_sandbox- Rename rdate port to time port, and allow gnomeclock to connect to it - We no longer need to transition to ldconfig from rpm, rpm_script, or anaconda - /etc/auto.* should be labeled bin_t - Add httpd_use_fusefs boolean - Add fixes for heartbeat - Allow sshd_t to signal processes that it transitions to - Add condor policy - Allow svirt to create monitors in ~/.libvirt - Allow dovecot to domtrans sendmail to handle sieve scripts - Lot of fixes for cfengine- /var/run/postmaster.* labeling is no longer needed - Alllow drbdadmin to read /dev/urandom - l2tpd_t seems to use ptmx - group+ and passwd+ should be labeled as /etc/passwd - Zarafa-indexer is a socket- Ensure lastlog is labeled correctly - Allow accountsd to read /proc data about gdm - Add fixes for tuned - Add bcfg2 fixes which were discovered during RHEL6 testing - More fixes for gnome-keyring socket being moved - Run semanage as a unconfined domain, and allow initrc_t to create tmpfs_t sym links on shutdown - Fix description for files_dontaudit_read_security_files() interface- Add new policy and man page for bcfg2 - cgconfig needs to use getpw calls - Allow domains that communicate with the keyring to use cache_home_t instead of gkeyringd_tmpt - gnome-keyring wants to create a directory in cache_home_t - sanlock calls getpw- Add numad policy and numad man page - Add fixes for interface bugs discovered by SEWatch - Add /tmp support for squid - Add fix for #799102 * change default labeling for /var/run/slapd.* sockets - Make thumb_t as userdom_home_reader - label /var/lib/sss/mc same as pubconf, so getpw domains can read it - Allow smbspool running as cups_t to stream connect to nmbd - accounts needs to be able to execute passwd on behalf of users - Allow systemd_tmpfiles_t to delete boot flags - Allow dnssec_trigger to connect to apache ports - Allow gnome keyring to create sock_files in ~/.cache - google_authenticator is using .google_authenticator - sandbox running from within firefox is exposing more leaks - Dontaudit thumb to read/write /dev/card0 - Dontaudit getattr on init_exec_t for gnomeclock_t - Allow certmonger to do a transition to certmonger_unconfined_t - Allow dhcpc setsched which is caused by nmcli - Add rpm_exec_t for /usr/sbin/bcfg2 - system cronjobs are sending dbus messages to systemd_logind - Thumnailers read /dev/urand- Allow auditctl getcap - Allow vdagent to use libsystemd-login - Allow abrt-dump-oops to search /etc/abrt - Got these avc's while trying to print a boarding pass from firefox - Devicekit is now putting the media directory under /run/media - Allow thumbnailers to create content in ~/.thumbails directory - Add support for proL2TPd by Dominick Grift - Allow all domains to call getcap - wdmd seems to get a random chown capability check that it does not need - Allow vhostmd to read kernel sysctls- Allow chronyd to read unix - Allow hpfax to read /etc/passwd - Add support matahari vios-proxy-* apps and add virtd_exec_t label for them - Allow rpcd to read quota_db_t - Update to man pages to match latest policy - Fix bug in jockey interface for sepolgen-ifgen - Add initial svirt_prot_exec_t policy- More fixes for systemd from Dan Walsh- Add a new type for /etc/firewalld and allow firewalld to write to this directory - Add definition for ~/Maildir, and allow mail deliver domains to write there - Allow polipo to run from a cron job - Allow rtkit to schedule wine processes - Allow mozilla_plugin_t to acquire a bug, and allow it to transition gnome content in the home dir to the proper label - Allow users domains to send signals to consolehelper domains- More fixes for boinc policy - Allow polipo domain to create its own cache dir and pid file - Add systemctl support to httpd domain - Add systemctl support to polipo, allow NetworkManager to manage the service - Add policy for jockey-backend - Add support for motion daemon which is now covered by zoneminder policy - Allow colord to read/write motion tmpfs - Allow vnstat to search through var_lib_t directories - Stop transitioning to quota_t, from init an sysadm_t- Add svirt_lxc_file_t as a customizable type- Add additional fixes for icmp nagios plugin - Allow cron jobs to open fifo_files from cron, since service script opens /dev/stdin - Add certmonger_unconfined_exec_t - Make sure tap22 device is created with the correct label - Allow staff users to read systemd unit files - Merge in previously built policy - Arpwatch needs to be able to start netlink sockets in order to start - Allow cgred_t to sys_ptrace to look at other DAC Processes- Back port some of the access that was allowed in nsplugin_t - Add definitiona for couchdb ports - Allow nagios to use inherited users ttys - Add git support for mock - Allow inetd to use rdate port - Add own type for rdate port - Allow samba to act as a portmapper - Dontaudit chrome_sandbox attempts to getattr on chr_files in /dev - New fixes needed for samba4 - Allow apps that use lib_t to read lib_t symlinks- Add policy for nove-cert - Add labeling for nova-openstack systemd unit files - Add policy for keystoke- Fix man pages fro domains - Add man pages for SELinux users and roles - Add storage_dev_filetrans_named_fixed_disk() and use it for smartmon - Add policy for matahari-rpcd - nfsd executes mount command on restart - Matahari domains execute renice and setsched - Dontaudit leaked tty in mozilla_plugin_config - mailman is changing to a per instance naming - Add 7600 and 4447 as jboss_management ports - Add fixes for nagios event handlers - Label httpd.event as httpd_exec_t, it is an apache daemon- Add labeling for /var/spool/postfix/dev/log - NM reads sysctl.conf - Iscsi log file context specification fix - Allow mozilla plugins to send dbus messages to user domains that transition to it - Allow mysql to read the passwd file - Allow mozilla_plugin_t to create mozilla home dirs in user homedir - Allow deltacloud to read kernel sysctl - Allow postgresql_t to connectto itselfAllow postgresql_t to connectto itself - Allow postgresql_t to connectto itself - Add login_userdomain attribute for users which can log in using terminal- Allow sysadm_u to reach system_r by default #784011 - Allow nagios plugins to use inherited user terminals - Razor labeling is not used no longer - Add systemd support for matahari - Add port_types to man page, move booleans to the top, fix some english - Add support for matahari-sysconfig-console - Clean up matahari.fc - Fix matahari_admin() interfac - Add labels for/etc/ssh/ssh_host_*.pub keys- Allow ksysguardproces to send system log msgs - Allow boinc setpgid and signull - Allow xdm_t to sys_ptrace to run pidof command - Allow smtpd_t to manage spool files/directories and symbolic links - Add labeling for jetty - Needed changes to get unbound/dnssec to work with openswan- Add user_fonts_t alias xfs_tmp_t - Since depmod now runs as insmod_t we need to write to kernel_object_t - Allow firewalld to dbus chat with networkmanager - Allow qpidd to connect to matahari ports - policykit needs to read /proc for uses not owned by it - Allow systemctl apps to connecto the init stream- Turn on deny_ptrace boolean- Remove pam_selinux.8 man page. There was a conflict.- Add proxy class and read access for gssd_proxy - Separate out the sharing public content booleans - Allow certmonger to execute a script and send signals to apache and dirsrv to reload the certificate - Add label transition for gstream-0.10 and 12 - Add booleans to allow rsync to share nfs and cifs file sytems - chrome_sandbox wants to read the /proc/PID/exe file of the program that executed it - Fix filename transitions for cups files - Allow denyhosts to read "unix" - Add file name transition for locale.conf.new - Allow boinc projects to gconf config files - sssd needs to be able to increase the socket limit under certain loads - sge_execd needs to read /etc/passwd - Allow denyhost to check network state - NetworkManager needs to read sessions data - Allow denyhost to check network state - Allow xen to search virt images directories - Add label for /dev/megaraid_sas_ioctl_node - Add autogenerated man pages- Allow boinc project to getattr on fs - Allow init to execute initrc_state_t - rhev-agent package was rename to ovirt-guest-agent - If initrc_t creates /etc/local.conf then we need to make sure it is labeled correctly - sytemd writes content to /run/initramfs and executes it on shutdown - kdump_t needs to read /etc/mtab, should be back ported to F16 - udev needs to load kernel modules in early system boot- Need to add sys_ptrace back in since reading any content in /proc can cause these accesses - Add additional systemd interfaces which are needed fro *_admin interfaces - Fix bind_admin() interface- Allow firewalld to read urand - Alias java, execmem_mono to bin_t to allow third parties - Add label for kmod - /etc/redhat-lsb contains binaries - Add boolean to allow gitosis to send mail - Add filename transition also for "event20" - Allow systemd_tmpfiles_t to delete all file types - Allow collectd to ipc_lock- make consoletype_exec optional, so we can remove consoletype policy - remove unconfined_permisive.patch - Allow openvpn_t to inherit user home content and tmp content - Fix dnssec-trigger labeling - Turn on obex policy for staff_t - Pem files should not be secret - Add lots of rules to fix AVC's when playing with containers - Fix policy for dnssec - Label ask-passwd directories correctly for systemd- sshd fixes seem to be causing unconfined domains to dyntrans to themselves - fuse file system is now being mounted in /run/user - systemd_logind is sending signals to processes that are dbus messaging with it - Add support for winshadow port and allow iscsid to connect to this port - httpd should be allowed to bind to the http_port_t udp socket - zarafa_var_lib_t can be a lnk_file - A couple of new .xsession-errors files - Seems like user space and login programs need to read logind_sessions_files - Devicekit disk seems to be being launched by systemd - Cleanup handling of setfiles so most of rules in te file - Correct port number for dnssec - logcheck has the home dir set to its cache- Add policy for grindengine MPI jobs- Add new sysadm_secadm.pp module * contains secadm definition for sysadm_t - Move user_mail_domain access out of the interface into the te file - Allow httpd_t to create httpd_var_lib_t directories as well as files - Allow snmpd to connect to the ricci_modcluster stream - Allow firewalld to read /etc/passwd - Add auth_use_nsswitch for colord - Allow smartd to read network state - smartdnotify needs to read /etc/group- Allow gpg and gpg_agent to store sock_file in gpg_secret_t directory - lxdm startup scripts should be labeled bin_t, so confined users will work - mcstransd now creates a pid, needs back port to F16 - qpidd should be allowed to connect to the amqp port - Label devices 010-029 as usb devices - ypserv packager says ypserv does not use tmp_t so removing selinux policy types - Remove all ptrace commands that I believe are caused by the kernel/ps avcs - Add initial Obex policy - Add logging_syslogd_use_tty boolean - Add polipo_connect_all_unreserved bolean - Allow zabbix to connect to ftp port - Allow systemd-logind to be able to switch VTs - Allow apache to communicate with memcached through a sock_file- Fix file_context.subs_dist for now to work with pre usrmove- More /usr move fixes- Add zabbix_can_network boolean - Add httpd_can_connect_zabbix boolean - Prepare file context labeling for usrmove functions - Allow system cronjobs to read kernel network state - Add support for selinux_avcstat munin plugin - Treat hearbeat with corosync policy - Allow corosync to read and write to qpidd shared mem - mozilla_plugin is trying to run pulseaudio - Fixes for new sshd patch for running priv sep domains as the users context - Turn off dontaudit rules when turning on allow_ypbind - udev now reads /etc/modules.d directory- Turn on deny_ptrace boolean for the Rawhide run, so we can test this out - Cups exchanges dbus messages with init - udisk2 needs to send syslog messages - certwatch needs to read /etc/passwd- Add labeling for udisks2 - Allow fsadmin to communicate with the systemd process- Treat Bip with bitlbee policy * Bip is an IRC proxy - Add port definition for interwise port - Add support for ipa_memcached socket - systemd_jounald needs to getattr on all processes - mdadmin fixes * uses getpw - amavisd calls getpwnam() - denyhosts calls getpwall()- Setup labeling of /var/rsa and /var/lib/rsa to allow login programs to write there - bluetooth says they do not use /tmp and want to remove the type - Allow init to transition to colord - Mongod needs to read /proc/sys/vm/zone_reclaim_mode - Allow postfix_smtpd_t to connect to spamd - Add boolean to allow ftp to connect to all ports > 1023 - Allow sendmain to write to inherited dovecot tmp files - setroubleshoot needs to be able to execute rpm to see what version of packages- Merge systemd patch - systemd-tmpfiles wants to relabel /sys/devices/system/cpu/online - Allow deltacloudd dac_override, setuid, setgid caps - Allow aisexec to execute shell - Add use_nfs_home_dirs boolean for ssh-keygen- Fixes to make rawhide boot in enforcing mode with latest systemd changes- Add labeling for /var/run/systemd/journal/syslog - libvirt sends signals to ifconfig - Allow domains that read logind session files to list them- Fixed destined form libvirt-sandbox - Allow apps that list sysfs to also read sympolicy links in this filesystem - Add ubac_constrained rules for chrome_sandbox - Need interface to allow domains to use tmpfs_t files created by the kernel, used by libra - Allow postgresql to be executed by the caller - Standardize interfaces of daemons - Add new labeling for mm-handler - Allow all matahari domains to read network state and etc_runtime_t files- New fix for seunshare, requires seunshare_domains to be able to mounton / - Allow systemctl running as logrotate_t to connect to private systemd socket - Allow tmpwatch to read meminfo - Allow rpc.svcgssd to read supported_krb5_enctype - Allow zarafa domains to read /dev/random and /dev/urandom - Allow snmpd to read dev_snmp6 - Allow procmail to talk with cyrus - Add fixes for check_disk and check_nagios plugins- default trans rules for Rawhide policy - Make sure sound_devices controlC* are labeled correctly on creation - sssd now needs sys_admin - Allow snmp to read all proc_type - Allow to setup users homedir with quota.group- Add httpd_can_connect_ldap() interface - apcupsd_t needs to use seriel ports connected to usb devices - Kde puts procmail mail directory under ~/.local/share - nfsd_t can trigger sys_rawio on tests that involve too many mountpoints, dontaudit for now - Add labeling for /sbin/iscsiuio- Add label for /var/lib/iscan/interpreter - Dont audit writes to leaked file descriptors or redirected output for nacl - NetworkManager needs to write to /sys/class/net/ib*/mode- Allow abrt to request the kernel to load a module - Make sure mozilla content is labeled correctly - Allow tgtd to read system state - More fixes for boinc * allow to resolve dns name * re-write boinc policy to use boinc_domain attribute - Allow munin services plugins to use NSCD services- Allow mozilla_plugin_t to manage mozilla_home_t - Allow ssh derived domain to execute ssh-keygen in the ssh_keygen_t domain - Add label for tumblerd- Fixes for xguest package- Fixes related to /bin, /sbin - Allow abrt to getattr on blk files - Add type for rhev-agent log file - Fix labeling for /dev/dmfm - Dontaudit wicd leaking - Allow systemd_logind_t to look at process info of apps that exchange dbus messages with it - Label /etc/locale.conf correctly - Allow user_mail_t to read /dev/random - Allow postfix-smtpd to read MIMEDefang - Add label for /var/log/suphp.log - Allow swat_t to connect and read/write nmbd_t sock_file - Allow systemd-tmpfiles to setattr for /run/user/gdm/dconf - Allow systemd-tmpfiles to change user identity in object contexts - More fixes for rhev_agentd_t consolehelper policy- Use fs_use_xattr for squashf - Fix procs_type interface - Dovecot has a new fifo_file /var/run/dovecot/stats-mail - Dovecot has a new fifo_file /var/run/stats-mail - Colord does not need to connect to network - Allow system_cronjob to dbus chat with NetworkManager - Puppet manages content, want to make sure it labels everything correctly- Change port 9050 to tor_socks_port_t and then allow openvpn to connect to it - Allow all postfix domains to use the fifo_file - Allow sshd_t to getattr on all file systems in order to generate avc on nfs_t - Allow apmd_t to read grub.cfg - Let firewallgui read the selinux config - Allow systemd-tmpfiles to delete content in /root that has been moved to /tmp - Fix devicekit_manage_pid_files() interface - Allow squid to check the network state - Dontaudit colord getattr on file systems - Allow ping domains to read zabbix_tmp_t files- Allow mcelog_t to create dir and file in /var/run and label it correctly - Allow dbus to manage fusefs - Mount needs to read process state when mounting gluster file systems - Allow collectd-web to read collectd lib files - Allow daemons and system processes started by init to read/write the unix_stream_socket passed in from as stdin/stdout/stderr - Allow colord to get the attributes of tmpfs filesystem - Add sanlock_use_nfs and sanlock_use_samba booleans - Add bin_t label for /usr/lib/virtualbox/VBoxManage- Add ssh_dontaudit_search_home_dir - Changes to allow namespace_init_t to work - Add interface to allow exec of mongod, add port definition for mongod port, 27017 - Label .kde/share/apps/networkmanagement/certificates/ as home_cert_t - Allow spamd and clamd to steam connect to each other - Add policy label for passwd.OLD - More fixes for postfix and postfix maildro - Add ftp support for mozilla plugins - Useradd now needs to manage policy since it calls libsemanage - Fix devicekit_manage_log_files() interface - Allow colord to execute ifconfig - Allow accountsd to read /sys - Allow mysqld-safe to execute shell - Allow openct to stream connect to pcscd - Add label for /var/run/nm-dns-dnsmasq\.conf - Allow networkmanager to chat with virtd_t- Pulseaudio changes - Merge patches- Merge patches back into git repository.- Remove allow_execmem boolean and replace with deny_execmem boolean- Turn back on allow_execmem boolean- Add more MCS fixes to make sandbox working - Make faillog MLS trusted to make sudo_$1_t working - Allow sandbox_web_client_t to read passwd_file_t - Add .mailrc file context - Remove execheap from openoffice domain - Allow chrome_sandbox_nacl_t to read cpu_info - Allow virtd to relabel generic usb which is need if USB device - Fixes for virt.if interfaces to consider chr_file as image file type- Remove Open Office policy - Remove execmem policy- MCS fixes - quota fixes- Remove transitions to consoletype- Make nvidia* to be labeled correctly - Fix abrt_manage_cache() interface - Make filetrans rules optional so base policy will build - Dontaudit chkpwd_t access to inherited TTYS - Make sure postfix content gets created with the correct label - Allow gnomeclock to read cgroup - Fixes for cloudform policy- Check in fixed for Chrome nacl support- Begin removing qemu_t domain, we really no longer need this domain. - systemd_passwd needs dac_overide to communicate with users TTY's - Allow svirt_lxc domains to send kill signals within their container- Remove qemu.pp again without causing a crash- Remove qemu.pp, everything should use svirt_t or stay in its current domain- Allow policykit to talk to the systemd via dbus - Move chrome_sandbox_nacl_t to permissive domains - Additional rules for chrome_sandbox_nacl- Change bootstrap name to nacl - Chrome still needs execmem - Missing role for chrome_sandbox_bootstrap - Add boolean to remove execmem and execstack from virtual machines - Dontaudit xdm_t doing an access_check on etc_t directories- Allow named to connect to dirsrv by default - add ldapmap1_0 as a krb5_host_rcache_t file - Google chrome developers asked me to add bootstrap policy for nacl stuff - Allow rhev_agentd_t to getattr on mountpoints - Postfix_smtpd_t needs access to milters and cleanup seems to read/write postfix_smtpd_t unix_stream_sockets- Fixes for cloudform policies which need to connect to random ports - Make sure if an admin creates modules content it creates them with the correct label - Add port 8953 as a dns port used by unbound - Fix file name transition for alsa and confined users- Turn on mock_t and thumb_t for unconfined domains- Policy update should not modify local contexts- Remove ada policy- Remove tzdata policy - Add labeling for udev - Add cloudform policy - Fixes for bootloader policy- Add policies for nova openstack- Add fixes for nova-stack policy- Allow svirt_lxc_domain to chr_file and blk_file devices if they are in the domain - Allow init process to setrlimit on itself - Take away transition rules for users executing ssh-keygen - Allow setroubleshoot_fixit_t to read /dev/urand - Allow sshd to relbale tunnel sockets - Allow fail2ban domtrans to shorewall in the same way as with iptables - Add support for lnk files in the /var/lib/sssd directory - Allow system mail to connect to courier-authdaemon over an unix stream socket- Add passwd_file_t for /etc/ptmptmp- Dontaudit access checks for all executables, gnome-shell is doing access(EXEC, X_OK) - Make corosync to be able to relabelto cluster lib fies - Allow samba domains to search /var/run/nmbd - Allow dirsrv to use pam - Allow thumb to call getuid - chrome less likely to get mmap_zero bug so removing dontaudit - gimp help-browser has built in javascript - Best guess is that devices named /dev/bsr4096 should be labeled as cpu_device_t - Re-write glance policy- Move dontaudit sys_ptrace line from permissive.te to domain.te - Remove policy for hal, it no longer exists- Don't check md5 size or mtime on certain config files- Remove allow_ptrace and replace it with deny_ptrace, which will remove all ptrace from the system - Remove 2000 dontaudit rules between confined domains on transition and replace with single dontaudit domain domain:process { noatsecure siginh rlimitinh } ;- Fixes for bootloader policy - $1_gkeyringd_t needs to read $HOME/%USER/.local/share/keystore - Allow nsplugin to read /usr/share/config - Allow sa-update to update rules - Add use_fusefs_home_dirs for chroot ssh option - Fixes for grub2 - Update systemd_exec_systemctl() interface - Allow gpg to read the mail spool - More fixes for sa-update running out of cron job - Allow ipsec_mgmt_t to read hardware state information - Allow pptp_t to connect to unreserved_port_t - Dontaudit getattr on initctl in /dev from chfn - Dontaudit getattr on kernel_core from chfn - Add systemd_list_unit_dirs to systemd_exec_systemctl call - Fixes for collectd policy - CHange sysadm_t to create content as user_tmp_t under /tmp- Shrink size of policy through use of attributes for userdomain and apache- Allow virsh to read xenstored pid file - Backport corenetwork fixes from upstream - Do not audit attempts by thumb to search config_home_t dirs (~/.config) - label ~/.cache/telepathy/logger telepathy_logger_cache_home_t - allow thumb to read generic data home files (mime.type)- Allow nmbd to manage sock file in /var/run/nmbd - ricci_modservice send syslog msgs - Stop transitioning from unconfined_t to ldconfig_t, but make sure /etc/ld.so.cache is labeled correctly - Allow systemd_logind_t to manage /run/USER/dconf/user- Fix missing patch from F16- Allow logrotate setuid and setgid since logrotate is supposed to do it - Fixes for thumb policy by grift - Add new nfsd ports - Added fix to allow confined apps to execmod on chrome - Add labeling for additional vdsm directories - Allow Exim and Dovecot SASL - Add label for /var/run/nmbd - Add fixes to make virsh and xen working together - Colord executes ls - /var/spool/cron is now labeled as user_cron_spool_t- Stop complaining about leaked file descriptors during install- Remove java and mono module and merge into execmem- Fixes for thumb policy and passwd_file_t- Fixes caused by the labeling of /etc/passwd - Add thumb.patch to transition unconfined_t to thumb_t for Rawhide- Add support for Clustered Samba commands - Allow ricci_modrpm_t to send log msgs - move permissive virt_qmf_t from virt.te to permissivedomains.te - Allow ssh_t to use kernel keyrings - Add policy for libvirt-qmf and more fixes for linux containers - Initial Polipo - Sanlock needs to run ranged in order to kill svirt processes - Allow smbcontrol to stream connect to ctdbd- Add label for /etc/passwd- Change unconfined_domains to permissive for Rawhide - Add definition for the ephemeral_ports- Make mta_role() active - Allow asterisk to connect to jabber client port - Allow procmail to read utmp - Add NIS support for systemd_logind_t - Allow systemd_logind_t to manage /run/user/$USER/dconf dir which is labeled as config_home_t - Fix systemd_manage_unit_dirs() interface - Allow ssh_t to manage directories passed into it - init needs to be able to create and delete unit file directories - Fix typo in apache_exec_sys_script - Add ability for logrotate to transition to awstat domain- Change screen to use screen_domain attribute and allow screen_domains to read all process domain state - Add SELinux support for ssh pre-auth net process in F17 - Add logging_syslogd_can_sendmail boolean- Add definition for ephemeral ports - Define user_tty_device_t as a customizable_type- Needs to require a new version of checkpolicy - Interface fixes- Allow sanlock to manage virt lib files - Add virt_use_sanlock booelan - ksmtuned is trying to resolve uids - Make sure .gvfs is labeled user_home_t in the users home directory - Sanlock sends kill signals and needs the kill capability - Allow mockbuild to work on nfs homedirs - Fix kerberos_manage_host_rcache() interface - Allow exim to read system state- Allow systemd-tmpfiles to set the correct labels on /var/run, /tmp and other files - We want any file type that is created in /tmp by a process running as initrc_t to be labeled initrc_tmp_t- Allow collectd to read hardware state information - Add loop_control_device_t - Allow mdadm to request kernel to load module - Allow domains that start other domains via systemctl to search unit dir - systemd_tmpfilses, needs to list any file systems mounted on /tmp - No one can explain why radius is listing the contents of /tmp, so we will dontaudit - If I can manage etc_runtime files, I should be able to read the links - Dontaudit hostname writing to mock library chr_files - Have gdm_t setup labeling correctly in users home dir - Label content unde /var/run/user/NAME/dconf as config_home_t - Allow sa-update to execute shell - Make ssh-keygen working with fips_enabled - Make mock work for staff_t user - Tighten security on mock_t- removing unconfined_notrans_t no longer necessary - Clean up handling of secure_mode_insmod and secure_mode_policyload - Remove unconfined_mount_t- Add exim_exec_t label for /usr/sbin/exim_tidydb - Call init_dontaudit_rw_stream_socket() interface in mta policy - sssd need to search /var/cache/krb5rcache directory - Allow corosync to relabel own tmp files - Allow zarafa domains to send system log messages - Allow ssh to do tunneling - Allow initrc scripts to sendto init_t unix_stream_socket - Changes to make sure dmsmasq and virt directories are labeled correctly - Changes needed to allow sysadm_t to manage systemd unit files - init is passing file descriptors to dbus and on to system daemons - Allow sulogin additional access Reported by dgrift and Jeremy Miller - Steve Grubb believes that wireshark does not need this access - Fix /var/run/initramfs to stop restorecon from looking at - pki needs another port - Add more labels for cluster scripts - Allow apps that manage cgroup_files to manage cgroup link files - Fix label on nfs-utils scripts directories - Allow gatherd to read /dev/rand and /dev/urand- pki needs another port - Add more labels for cluster scripts - Fix label on nfs-utils scripts directories - Fixes for cluster - Allow gatherd to read /dev/rand and /dev/urand - abrt leaks fifo files- Add glance policy - Allow mdadm setsched - /var/run/initramfs should not be relabeled with a restorecon run - memcache can be setup to override sys_resource - Allow httpd_t to read tetex data - Allow systemd_tmpfiles to delete kernel modules left in /tmp directory.- Allow Postfix to deliver to Dovecot LMTP socket - Ignore bogus sys_module for lldpad - Allow chrony and gpsd to send dgrams, gpsd needs to write to the real time clock - systemd_logind_t sets the attributes on usb devices - Allow hddtemp_t to read etc_t files - Add permissivedomains module - Move all permissive domains calls to permissivedomain.te - Allow pegasis to send kill signals to other UIDs- Allow insmod_t to use fds leaked from devicekit - dontaudit getattr between insmod_t and init_t unix_stream_sockets - Change sysctl unit file interfaces to use systemctl - Add support for chronyd unit file - Allow mozilla_plugin to read gnome_usr_config - Add policy for new gpsd - Allow cups to create kerberos rhost cache files - Add authlogin_filetrans_named_content, to unconfined_t to make sure shadow and other log files get labeled correctly- Make users_extra and seusers.final into config(noreplace) so semanage users and login does not get overwritten- Add policy for sa-update being run out of cron jobs - Add create perms to postgresql_manage_db - ntpd using a gps has to be able to read/write generic tty_device_t - If you disable unconfined and unconfineduser, rpm needs more privs to manage /dev - fix spec file - Remove qemu_domtrans_unconfined() interface - Make passenger working together with puppet - Add init_dontaudit_rw_stream_socket interface - Fixes for wordpress- Turn on allow_domain_fd_use boolean on F16 - Allow syslog to manage all log files - Add use_fusefs_home_dirs boolean for chrome - Make vdagent working with confined users - Add abrt_handle_event_t domain for ABRT event scripts - Labeled /usr/sbin/rhnreg_ks as rpm_exec_t and added changes related to this change - Allow httpd_git_script_t to read passwd data - Allow openvpn to set its process priority when the nice parameter is used- livecd fixes - spec file fixes- fetchmail can use kerberos - ksmtuned reads in shell programs - gnome_systemctl_t reads the process state of ntp - dnsmasq_t asks the kernel to load multiple kernel modules - Add rules for domains executing systemctl - Bogus text within fc file- Add cfengine policy- Add abrt_domain attribute - Allow corosync to manage cluster lib files - Allow corosync to connect to the system DBUS- Add sblim, uuidd policies - Allow kernel_t dyntrasition to init_t- init_t need setexec - More fixes of rules which cause an explosion in rules by Dan Walsh- Allow rcsmcertd to perform DNS name resolution - Add dirsrvadmin_unconfined_script_t domain type for 389-ds admin scripts - Allow tmux to run as screen - New policy for collectd - Allow gkeyring_t to interact with all user apps - Add rules to allow firstboot to run on machines with the unconfined.pp module removed- Allow systemd_logind to send dbus messages with users - allow accountsd to read wtmp file - Allow dhcpd to get and set capabilities- Fix oracledb_port definition - Allow mount to mounton the selinux file system - Allow users to list /var directories- systemd fixes- Add initial policy for abrt_dump_oops_t - xtables-multi wants to getattr of the proc fs - Smoltclient is connecting to abrt - Dontaudit leaked file descriptors to postdrop - Allow abrt_dump_oops to look at kernel sysctls - Abrt_dump_oops_t reads kernel ring buffer - Allow mysqld to request the kernel to load modules - systemd-login needs fowner - Allow postfix_cleanup_t to searh maildrop- Initial systemd_logind policy - Add policy for systemd_logger and additional proivs for systemd_logind - More fixes for systemd policies- Allow setsched for virsh - Systemd needs to impersonate cups, which means it needs to create tcp_sockets in cups_t domain, as well as manage spool directories - iptables: the various /sbin/ip6?tables.* are now symlinks for /sbin/xtables-multi- A lot of users are running yum -y update while in /root which is causing ldconfig to list the contents, adding dontaudit - Allow colord to interact with the users through the tmpfs file system - Since we changed the label on deferred, we need to allow postfix_qmgr_t to be able to create maildrop_t files - Add label for /var/log/mcelog - Allow asterisk to read /dev/random if it uses TLS - Allow colord to read ini files which are labeled as bin_t - Allow dirsrvadmin sys_resource and setrlimit to use ulimit - Systemd needs to be able to create sock_files for every label in /var/run directory, cupsd being the first. - Also lists /var and /var/spool directories - Add openl2tpd to l2tpd policy - qpidd is reading the sysfs file- Change usbmuxd_t to dontaudit attempts to read chr_file - Add mysld_safe_exec_t for libra domains to be able to start private mysql domains - Allow pppd to search /var/lock dir - Add rhsmcertd policy- Update to upstream- More fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git- Fix spec file to not report Verify errors- Add dspam policy - Add lldpad policy - dovecot auth wants to search statfs #713555 - Allow systemd passwd apps to read init fifo_file - Allow prelink to use inherited terminals - Run cherokee in the httpd_t domain - Allow mcs constraints on node connections - Implement pyicqt policy - Fixes for zarafa policy - Allow cobblerd to send syslog messages- Add policy.26 to the payload - Remove olpc stuff - Remove policygentool- Fixes for zabbix - init script needs to be able to manage sanlock_var_run_... - Allow sandlock and wdmd to create /var/run directories... - mixclip.so has been compiled correctly - Fix passenger policy module name- Add mailscanner policy from dgrift - Allow chrome to optionally be transitioned to - Zabbix needs these rules when starting the zabbix_server_mysql - Implement a type for freedesktop openicc standard (~/.local/share/icc) - Allow system_dbusd_t to read inherited icc_data_home_t files. - Allow colord_t to read icc_data_home_t content. #706975 - Label stuff under /usr/lib/debug as if it was labeled under /- Fixes for sanlock policy - Fixes for colord policy - Other fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Add rhev policy module to modules-targeted.conf- Lot of fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Allow logrotate to execute systemctl - Allow nsplugin_t to getattr on gpmctl - Fix dev_getattr_all_chr_files() interface - Allow shorewall to use inherited terms - Allow userhelper to getattr all chr_file devices - sandbox domains should be able to getattr and dontaudit search of sysctl_kernel_t - Fix labeling for ABRT Retrace Server- Dontaudit sys_module for ifconfig - Make telepathy and gkeyringd daemon working with confined users - colord wants to read files in users homedir - Remote login should be creating user_tmp_t not its own tmp files- Fix label for /usr/share/munin/plugins/munin_* plugins - Add support for zarafa-indexer - Fix boolean description - Allow colord to getattr on /proc/scsi/scsi - Add label for /lib/upstart/init - Colord needs to list /mnt- Forard port changes from F15 for telepathy - NetworkManager should be allowed to use /dev/rfkill - Fix dontaudit messages to say Domain to not audit - Allow telepathy domains to read/write gnome_cache files - Allow telepathy domains to call getpw - Fixes for colord and vnstatd policy- Allow init_t getcap and setcap - Allow namespace_init_t to use nsswitch - aisexec will execute corosync - colord tries to read files off noxattr file systems - Allow init_t getcap and setcap- Add support for ABRT retrace server - Allow user_t and staff_t access to generic scsi to handle locally plugged in scanners - Allow telepath_msn_t to read /proc/PARENT/cmdline - ftpd needs kill capability - Allow telepath_msn_t to connect to sip port - keyring daemon does not work on nfs homedirs - Allow $1_sudo_t to read default SELinux context - Add label for tgtd sock file in /var/run/ - Add apache_exec_rotatelogs interface - allow all zaraha domains to signal themselves, server writes to /tmp - Allow syslog to read the process state - Add label for /usr/lib/chromium-browser/chrome - Remove the telepathy transition from unconfined_t - Dontaudit sandbox domains trying to mounton sandbox_file_t, this is caused by fuse mounts - Allow initrc_t domain to manage abrt pid files - Add support for AEOLUS project - Virt_admin should be allowed to manage images and processes - Allow plymountd to send signals to init - Change labeling of fping6- Add filename transitions- Fixes for zarafa policy - Add support for AEOLUS project - Change labeling of fping6 - Allow plymountd to send signals to init - Allow initrc_t domain to manage abrt pid files - Virt_admin should be allowed to manage images and processes- xdm_t needs getsession for switch user - Every app that used to exec init is now execing systemdctl - Allow squid to manage krb5_host_rcache_t files - Allow foghorn to connect to agentx port - Fixes for colord policy- Add Dan's patch to remove 64 bit variants - Allow colord to use unix_dgram_socket - Allow apps that search pids to read /var/run if it is a lnk_file - iscsid_t creates its own directory - Allow init to list var_lock_t dir - apm needs to verify user accounts auth_use_nsswitch - Add labeling for systemd unit files - Allow gnomeclok to enable ntpd service using systemctl - systemd_systemctl_t domain was added - Add label for matahari-broker.pid file - We want to remove untrustedmcsprocess from ability to read /proc/pid - Fixes for matahari policy - Allow system_tmpfiles_t to delete user_home_t files in the /tmp dir - Allow sshd to transition to sysadm_t if ssh_sysadm_login is turned on- Fix typo- Add /var/run/lock /var/lock definition to file_contexts.subs - nslcd_t is looking for kerberos cc files - SSH_USE_STRONG_RNG is 1 which requires /dev/random - Fix auth_rw_faillog definition - Allow sysadm_t to set attributes on fixed disks - allow user domains to execute lsof and look at application sockets - prelink_cron job calls telinit -u if init is rewritten - Fixes to run qemu_t from staff_t- Fix label for /var/run/udev to udev_var_run_t - Mock needs to be able to read network state- Add file_contexts.subs to handle /run and /run/lock - Add other fixes relating to /run changes from F15 policy- Allow $1_sudo_t and $1_su_t open access to user terminals - Allow initrc_t to use generic terminals - Make Makefile/Rules.modular run sepolgen-ifgen during build to check if files for bugs -systemd is going to be useing /run and /run/lock for early bootup files. - Fix some comments in rlogin.if - Add policy for KDE backlighthelper - sssd needs to read ~/.k5login in nfs, cifs or fusefs file systems - sssd wants to read .k5login file in users homedir - setroubleshoot reads executables to see if they have TEXTREL - Add /var/spool/audit support for new version of audit - Remove kerberos_connect_524() interface calling - Combine kerberos_master_port_t and kerberos_port_t - systemd has setup /dev/kmsg as stderr for apps it executes - Need these access so that init can impersonate sockets on unix_dgram_socket- Remove some unconfined domains - Remove permissive domains - Add policy-term.patch from Dan- Fix multiple specification for boot.log - devicekit leaks file descriptors to setfiles_t - Change all all_nodes to generic_node and all_if to generic_if - Should not use deprecated interface - Switch from using all_nodes to generic_node and from all_if to generic_if - Add support for xfce4-notifyd - Fix file context to show several labels as SystemHigh - seunshare needs to be able to mounton nfs/cifs/fusefs homedirs - Add etc_runtime_t label for /etc/securetty - Fixes to allow xdm_t to start gkeyringd_USERTYPE_t directly - login.krb needs to be able to write user_tmp_t - dirsrv needs to bind to port 7390 for dogtag - Fix a bug in gpg policy - gpg sends audit messages - Allow qpid to manage matahari files- Initial policy for matahari - Add dev_read_watchdog - Allow clamd to connect clamd port - Add support for kcmdatetimehelper - Allow shutdown to setrlimit and sys_nice - Allow systemd_passwd to talk to /dev/log before udev or syslog is running - Purge chr_file and blk files on /tmp - Fixes for pads - Fixes for piranha-pulse - gpg_t needs to be able to encyprt anything owned by the user- mozilla_plugin_tmp_t needs to be treated as user tmp files - More dontaudits of writes from readahead - Dontaudit readahead_t file_type:dir write, to cover up kernel bug - systemd_tmpfiles needs to relabel faillog directory as well as the file - Allow hostname and consoletype to r/w inherited initrc_tmp_t files handline hostname >> /tmp/myhost- Add policykit fixes from Tim Waugh - dontaudit sandbox domains sandbox_file_t:dir mounton - Add new dontaudit rules for sysadm_dbusd_t - Change label for /var/run/faillock * other fixes which relate with this change- Update to upstream - Fixes for telepathy - Add port defition for ssdp port - add policy for /bin/systemd-notify from Dan - Mount command requires users read mount_var_run_t - colord needs to read konject_uevent_socket - User domains connect to the gkeyring socket - Add colord policy and allow user_t and staff_t to dbus chat with it - Add lvm_exec_t label for kpartx - Dontaudit reading the mail_spool_t link from sandbox -X - systemd is creating sockets in avahi_var_run and system_dbusd_var_run- gpg_t needs to talk to gnome-keyring - nscd wants to read /usr/tmp->/var/tmp to generate randomziation in unixchkpwd - enforce MCS labeling on nodes - Allow arpwatch to read meminfo - Allow gnomeclock to send itself signals - init relabels /dev/.udev files on boot - gkeyringd has to transition back to staff_t when it runs commands in bin_t or shell_exec_t - nautilus checks access on /media directory before mounting usb sticks, dontaudit access_check on mnt_t - dnsmasq can run as a dbus service, needs acquire service - mysql_admin should be allowed to connect to mysql service - virt creates monitor sockets in the users home dir- Allow usbhid-ups to read hardware state information - systemd-tmpfiles has moved - Allo cgroup to sys_tty_config - For some reason prelink is attempting to read gconf settings - Add allow_daemons_use_tcp_wrapper boolean - Add label for ~/.cache/wocky to make telepathy work in enforcing mode - Add label for char devices /dev/dasd* - Fix for apache_role - Allow amavis to talk to nslcd - allow all sandbox to read selinux poilcy config files - Allow cluster domains to use the system bus and send each other dbus messages- Update to upstream- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Update to ref policy - cgred needs chown capability - Add /dev/crash crash_dev_t - systemd-readahead wants to use fanotify which means readahead_t needs sys_admin capability- New labeling for postfmulti #675654 - dontaudit xdm_t listing noxattr file systems - dovecot-auth needs to be able to connect to mysqld via the network as well as locally - shutdown is passed stdout to a xdm_log_t file - smartd creates a fixed disk device - dovecot_etc_t contains a lnk_file that domains need to read - mount needs to be able to read etc_runtim_t:lnk_file since in rawhide this is a link created at boot- syslog_t needs syslog capability - dirsrv needs to be able to create /var/lib/snmp - Fix labeling for dirsrv - Fix for dirsrv policy missing manage_dirs_pattern - corosync needs to delete clvm_tmpfs_t files - qdiskd needs to list hugetlbfs - Move setsched to sandbox_x_domain, so firefox can run without network access - Allow hddtemp to read removable devices - Adding syslog and read_policy permissions to policy * syslog Allow unconfined, sysadm_t, secadm_t, logadm_t * read_policy allow unconfined, sysadm_t, secadm_t, staff_t on Targeted allow sysadm_t (optionally), secadm_t on MLS - mdadm application will write into /sys/.../uevent whenever arrays are assembled or disassembled.- Add tcsd policy- ricci_modclusterd_t needs to bind to rpc ports 500-1023 - Allow dbus to use setrlimit to increase resoueces - Mozilla_plugin is leaking to sandbox - Allow confined users to connect to lircd over unix domain stream socket which allow to use remote control - Allow awstats to read squid logs - seunshare needs to manage tmp_t - apcupsd cgi scripts have a new directory- Fix xserver_dontaudit_read_xdm_pid - Change oracle_port_t to oracledb_port_t to prevent conflict with satellite - Allow dovecot_deliver_t to read/write postfix_master_t:fifo_file. * These fifo_file is passed from postfix_master_t to postfix_local_t to dovecot_deliver_t - Allow readahead to manage readahead pid dirs - Allow readahead to read all mcs levels - Allow mozilla_plugin_t to use nfs or samba homedirs- Allow nagios plugin to read /proc/meminfo - Fix for mozilla_plugin - Allow samba_net_t to create /etc/keytab - pppd_t setting up vpns needs to run unix_chkpwd, setsched its process and write wtmp_t - nslcd can read user credentials - Allow nsplugin to delete mozilla_plugin_tmpfs_t - abrt tries to create dir in rpm_var_lib_t - virt relabels fifo_files - sshd needs to manage content in fusefs homedir - mock manages link files in cache dir- nslcd needs setsched and to read /usr/tmp - Invalid call in likewise policy ends up creating a bogus role - Cannon puts content into /var/lib/bjlib that cups needs to be able to write - Allow screen to create screen_home_t in /root - dirsrv sends syslog messages - pinentry reads stuff in .kde directory - Add labels for .kde directory in homedir - Treat irpinit, iprupdate, iprdump services with raid policy- NetworkManager wants to read consolekit_var_run_t - Allow readahead to create /dev/.systemd/readahead - Remove permissive domains - Allow newrole to run namespace_init- Add sepgsql_contexts file- Update to upstream- Add oracle ports and allow apache to connect to them if the connect_db boolean is turned on - Add puppetmaster_use_db boolean - Fixes for zarafa policy - Fixes for gnomeclock poliy - Fix systemd-tmpfiles to use auth_use_nsswitch- gnomeclock executes a shell - Update for screen policy to handle pipe in homedir - Fixes for polyinstatiated homedir - Fixes for namespace policy and other fixes related to polyinstantiation - Add namespace policy - Allow dovecot-deliver transition to sendmail which is needed by sieve scripts - Fixes for init, psad policy which relate with confined users - Do not audit bootloader attempts to read devicekit pid files - Allow nagios service plugins to read /proc- Add firewalld policy - Allow vmware_host to read samba config - Kernel wants to read /proc Fix duplicate grub def in cobbler - Chrony sends mail, executes shell, uses fifo_file and reads /proc - devicekitdisk getattr all file systems - sambd daemon writes wtmp file - libvirt transitions to dmidecode- Add initial policy for system-setup-keyboard which is now daemon - Label /var/lock/subsys/shorewall as shorewall_lock_t - Allow users to communicate with the gpg_agent_t - Dontaudit mozilla_plugin_t using the inherited terminal - Allow sambagui to read files in /usr - webalizer manages squid log files - Allow unconfined domains to bind ports to raw_ip_sockets - Allow abrt to manage rpm logs when running yum - Need labels for /var/run/bittlebee - Label .ssh under amanda - Remove unused genrequires for virt_domain_template - Allow virt_domain to use fd inherited from virtd_t - Allow iptables to read shorewall config- Gnome apps list config_home_t - mpd creates lnk files in homedir - apache leaks write to mail apps on tmp files - /var/stockmaniac/templates_cache contains log files - Abrt list the connects of mount_tmp_t dirs - passwd agent reads files under /dev and reads utmp file - squid apache script connects to the squid port - fix name of plymouth log file - teamviewer is a wine app - allow dmesg to read system state - Stop labeling files under /var/lib/mock so restorecon will not go into this - nsplugin needs to read network state for google talk- Allow xdm and syslog to use /var/log/boot.log - Allow users to communicate with mozilla_plugin and kill it - Add labeling for ipv6 and dhcp- New labels for ghc http content - nsplugin_config needs to read urand, lvm now calls setfscreate to create dev - pm-suspend now creates log file for append access so we remove devicekit_wri - Change authlogin_use_sssd to authlogin_nsswitch_use_ldap - Fixes for greylist_milter policy- Update to upstream - Fixes for systemd policy - Fixes for passenger policy - Allow staff users to run mysqld in the staff_t domain, akonadi needs this - Add bin_t label for /usr/share/kde4/apps/kajongg/kajongg.py - auth_use_nsswitch does not need avahi to read passwords,needed for resolving data - Dontaudit (xdm_t) gok attempting to list contents of /var/account - Telepathy domains need to read urand - Need interface to getattr all file classes in a mock library for setroubleshoot- Update selinux policy to handle new /usr/share/sandbox/start script- Update to upstream - Fix version of policy in spec file- Allow sandbox to run on nfs partitions, fixes for systemd_tmpfs - remove per sandbox domains devpts types - Allow dkim-milter sending signal to itself- Allow domains that transition to ping or traceroute, kill them - Allow user_t to conditionally transition to ping_t and traceroute_t - Add fixes to systemd- tools, including new labeling for systemd-fsck, systemd-cryptsetup- Turn on systemd policy - mozilla_plugin needs to read certs in the homedir. - Dontaudit leaked file descriptors from devicekit - Fix ircssi to use auth_use_nsswitch - Change to use interface without param in corenet to disable unlabelednet packets - Allow init to relabel sockets and fifo files in /dev - certmonger needs dac* capabilities to manage cert files not owned by root - dovecot needs fsetid to change group membership on mail - plymouthd removes /var/log/boot.log - systemd is creating symlinks in /dev - Change label on /etc/httpd/alias to be all cert_t- Fixes for clamscan and boinc policy - Add boinc_project_t setpgid - Allow alsa to create tmp files in /tmp- Push fixes to allow disabling of unlabeled_t packet access - Enable unlabelednet policy- Fixes for lvm to work with systemd- Fix the label for wicd log - plymouthd creates force-display-on-active-vt file - Allow avahi to request the kernel to load a module - Dontaudit hal leaks - Fix gnome_manage_data interface - Add new interface corenet_packet to define a type as being an packet_type. - Removed general access to packet_type from icecast and squid. - Allow mpd to read alsa config - Fix the label for wicd log - Add systemd policy- Fix gnome_manage_data interface - Dontaudit sys_ptrace capability for iscsid - Fixes for nagios plugin policy- Fix cron to run ranged when started by init - Fix devicekit to use log files - Dontaudit use of devicekit_var_run_t for fstools - Allow init to setattr on logfile directories - Allow hald to manage files in /var/run/pm-utils/ dir which is now labeled as devicekit_var_run_t- Fix up handling of dnsmasq_t creating /var/run/libvirt/network - Turn on sshd_forward_ports boolean by default - Allow sysadmin to dbus chat with rpm - Add interface for rw_tpm_dev - Allow cron to execute bin - fsadm needs to write sysfs - Dontaudit consoletype reading /var/run/pm-utils - Lots of new privs fro mozilla_plugin_t running java app, make mozilla_plugin - certmonger needs to manage dirsrv data - /var/run/pm-utils should be labeled as devicekit_var_run_t- fixes to allow /var/run and /var/lock as tmpfs - Allow chrome sandbox to connect to web ports - Allow dovecot to listem on lmtp and sieve ports - Allov ddclient to search sysctl_net_t - Transition back to original domain if you execute the shell- Remove duplicate declaration- Update to upstream - Cleanup for sandbox - Add attribute to be able to select sandbox types- Allow ddclient to fix file mode bits of ddclient conf file - init leaks file descriptors to daemons - Add labels for /etc/lirc/ and - Allow amavis_t to exec shell - Add label for gssd_tmp_t for /var/tmp/nfs_0- Put back in lircd_etc_t so policy will install- Turn on allow_postfix_local_write_mail_spool - Allow initrc_t to transition to shutdown_t - Allow logwatch and cron to mls_read_to_clearance for MLS boxes - Allow wm to send signull to all applications and receive them from users - lircd patch from field - Login programs have to read /etc/samba - New programs under /lib/systemd - Abrt needs to read config files- Update to upstream - Dontaudit leaked sockets from userdomains to user domains - Fixes for mcelog to handle scripts - Apply patch from Ruben Kerkhof - Allow syslog to search spool dirs- Allow nagios plugins to read usr files - Allow mysqld-safe to send system log messages - Fixes fpr ddclient policy - Fix sasl_admin interface - Allow apache to search zarafa config - Allow munin plugins to search /var/lib directory - Allow gpsd to read sysfs_t - Fix labels on /etc/mcelog/triggers to bin_t- Remove saslauthd_tmp_t and transition tmp files to krb5_host_rcache_t - Allow saslauthd_t to create krb5_host_rcache_t files in /tmp - Fix xserver interface - Fix definition of /var/run/lxdm- Turn on mediawiki policy - kdump leaks kdump_etc_t to ifconfig, add dontaudit - uux needs to transition to uucpd_t - More init fixes relabels man,faillog - Remove maxima defs in libraries.fc - insmod needs to be able to create tmpfs_t files - ping needs setcap- Allow groupd transition to fenced domain when executes fence_node - Fixes for rchs policy - Allow mpd to be able to read samba/nfs files- Fix up corecommands.fc to match upstream - Make sure /lib/systemd/* is labeled init_exec_t - mount wants to setattr on all mountpoints - dovecot auth wants to read dovecot etc files - nscd daemon looks at the exe file of the comunicating daemon - openvpn wants to read utmp file - postfix apps now set sys_nice and lower limits - remote_login (telnetd/login) wants to use telnetd_devpts_t and user_devpts_t to work correctly - Also resolves nsswitch - Fix labels on /etc/hosts.* - Cleanup to make upsteam patch work - allow abrt to read etc_runtime_t- Add conflicts for dirsrv package- Update to upstream - Add vlock policy- Fix sandbox to work on nfs homedirs - Allow cdrecord to setrlimit - Allow mozilla_plugin to read xauth - Change label on systemd-logger to syslogd_exec_t - Install dirsrv policy from dirsrv package- Add virt_home_t, allow init to setattr on xserver_tmp_t and relabel it - Udev needs to stream connect to init and kernel - Add xdm_exec_bootloader boolean, which allows xdm to execute /sbin/grub and read files in /boot directory- Allow NetworkManager to read openvpn_etc_t - Dontaudit hplip to write of /usr dirs - Allow system_mail_t to create /root/dead.letter as mail_home_t - Add vdagent policy for spice agent daemon- Dontaudit sandbox sending sigkill to all user domains - Add policy for rssh_chroot_helper - Add missing flask definitions - Allow udev to relabelto removable_t - Fix label on /var/log/wicd.log - Transition to initrc_t from init when executing bin_t - Add audit_access permissions to file - Make removable_t a device_node - Fix label on /lib/systemd/*- Fixes for systemd to manage /var/run - Dontaudit leaks by firstboot- Allow chome to create netlink_route_socket - Add additional MATHLAB file context - Define nsplugin as an application_domain - Dontaudit sending signals from sandboxed domains to other domains - systemd requires init to build /tmp /var/auth and /var/lock dirs - mount wants to read devicekit_power /proc/ entries - mpd wants to connect to soundd port - Openoffice causes a setattr on a lib_t file for normal users, add dontaudit - Treat lib_t and textrel_shlib_t directories the same - Allow mount read access on virtual images- Allow sandbox_x_domains to work with nfs/cifs/fusefs home dirs. - Allow devicekit_power to domtrans to mount - Allow dhcp to bind to udp ports > 1024 to do named stuff - Allow ssh_t to exec ssh_exec_t - Remove telepathy_butterfly_rw_tmp_files(), dev_read_printk() interfaces which are nolonger used - Fix clamav_append_log() intefaces - Fix 'psad_rw_fifo_file' interface- Allow cobblerd to list cobler appache content- Fixup for the latest version of upowed - Dontaudit sandbox sending SIGNULL to desktop apps- Update to upstream-Mount command from a confined user generates setattr on /etc/mtab file, need to dontaudit this access - dovecot-auth_t needs ipc_lock - gpm needs to use the user terminal - Allow system_mail_t to append ~/dead.letter - Allow NetworkManager to edit /etc/NetworkManager/NetworkManager.conf - Add pid file to vnstatd - Allow mount to communicate with gfs_controld - Dontaudit hal leaks in setfiles- Lots of fixes for systemd - systemd now executes readahead and tmpwatch type scripts - Needs to manage random seed- Allow smbd to use sys_admin - Remove duplicate file context for tcfmgr - Update to upstream- Fix fusefs handling - Do not allow sandbox to manage nsplugin_rw_t - Allow mozilla_plugin_t to connecto its parent - Allow init_t to connect to plymouthd running as kernel_t - Add mediawiki policy - dontaudit sandbox sending signals to itself. This can happen when they are running at different mcs. - Disable transition from dbus_session_domain to telepathy for F14 - Allow boinc_project to use shm - Allow certmonger to search through directories that contain certs - Allow fail2ban the DAC Override so it can read log files owned by non root users- Start adding support for use_fusefs_home_dirs - Add /var/lib/syslog directory file context - Add /etc/localtime as locale file context- Turn off default transition to mozilla_plugin and telepathy domains from unconfined user - Turn off iptables from unconfined user - Allow sudo to send signals to any domains the user could have transitioned to. - Passwd in single user mode needs to talk to console_device_t - Mozilla_plugin_t needs to connect to web ports, needs to write to video device, and read alsa_home_t alsa setsup pulseaudio - locate tried to read a symbolic link, will dontaudit - New labels for telepathy-sunshine content in homedir - Google is storing other binaries under /opt/google/talkplugin - bluetooth/kernel is creating unlabeled_t socket that I will allow it to use until kernel fixes bug - Add boolean for unconfined_t transition to mozilla_plugin_t and telepathy domains, turned off in F14 on in F15 - modemmanger and bluetooth send dbus messages to devicekit_power - Samba needs to getquota on filesystems labeld samba_share_t- Dontaudit attempts by xdm_t to write to bin_t for kdm - Allow initrc_t to manage system_conf_t- Fixes to allow mozilla_plugin_t to create nsplugin_home_t directory. - Allow mozilla_plugin_t to create tcp/udp/netlink_route sockets - Allow confined users to read xdm_etc_t files - Allow xdm_t to transition to xauth_t for lxdm program- Rearrange firewallgui policy to be more easily updated to upstream, dontaudit search of /home - Allow clamd to send signals to itself - Allow mozilla_plugin_t to read user home content. And unlink pulseaudio shm. - Allow haze to connect to yahoo chat and messenger port tcp:5050. Bz #637339 - Allow guest to run ps command on its processes by allowing it to read /proc - Allow firewallgui to sys_rawio which seems to be required to setup masqerading - Allow all domains to search through default_t directories, in order to find differnet labels. For example people serring up /foo/bar to be share via samba. - Add label for /var/log/slim.log- Pull in cleanups from dgrift - Allow mozilla_plugin_t to execute mozilla_home_t - Allow rpc.quota to do quotamod- Cleanup policy via dgrift - Allow dovecot_deliver to append to inherited log files - Lots of fixes for consolehelper- Fix up Xguest policy- Add vnstat policy - allow libvirt to send audit messages - Allow chrome-sandbox to search nfs_t- Update to upstream- Add the ability to send audit messages to confined admin policies - Remove permissive domain from cmirrord and dontaudit sys_tty_config - Split out unconfined_domain() calls from other unconfined_ calls so we can d - virt needs to be able to read processes to clearance for MLS- Allow all domains that can use cgroups to search tmpfs_t directory - Allow init to send audit messages- Update to upstream- Allow mdadm_t to create files and sock files in /dev/md/- Add policy for ajaxterm- Handle /var/db/sudo - Allow pulseaudio to read alsa config - Allow init to send initrc_t dbus messagesAllow iptables to read shorewall tmp files Change chfn and passwd to use auth_use_pam so they can send dbus messages to fpr intd label vlc as an execmem_exec_t Lots of fixes for mozilla_plugin to run google vidio chat Allow telepath_msn to execute ldconfig and its own tmp files Fix labels on hugepages Allow mdadm to read files on /dev Remove permissive domains and change back to unconfined Allow freshclam to execute shell and bin_t Allow devicekit_power to transition to dhcpc Add boolean to allow icecast to connect to any port- Merge upstream fix of mmap_zero - Allow mount to write files in debugfs_t - Allow corosync to communicate with clvmd via tmpfs - Allow certmaster to read usr_t files - Allow dbus system services to search cgroup_t - Define rlogind_t as a login pgm- Allow mdadm_t to read/write hugetlbfs- Dominic Grift Cleanup - Miroslav Grepl policy for jabberd - Various fixes for mount/livecd and prelink- Merge with upstream- More access needed for devicekit - Add dbadm policy- Merge with upstream- Allow seunshare to fowner- Allow cron to look at user_cron_spool links - Lots of fixes for mozilla_plugin_t - Add sysv file system - Turn unconfined domains to permissive to find additional avcs- Update policy for mozilla_plugin_t- Allow clamscan to read proc_t - Allow mount_t to write to debufs_t dir - Dontaudit mount_t trying to write to security_t dir- Allow clamscan_t execmem if clamd_use_jit set - Add policy for firefox plugin-container- Fix /root/.forward definition- label dead.letter as mail_home_t- Allow login programs to search /cgroups- Fix cert handling- Fix devicekit_power bug - Allow policykit_auth_t more access.- Fix nis calls to allow bind to ports 512-1024 - Fix smartmon- Allow pcscd to read sysfs - systemd fixes - Fix wine_mmap_zero_ignore boolean- Apply Miroslav munin patch - Turn back on allow_execmem and allow_execmod booleans- Merge in fixes from dgrift repository- Update boinc policy - Fix sysstat policy to allow sys_admin - Change failsafe_context to unconfined_r:unconfined_t:s0- New paths for upstart- New permissions for syslog - New labels for /lib/upstart- Add mojomojo policy- Allow systemd to setsockcon on sockets to immitate other services- Remove debugfs label- Update to latest policy- Fix eclipse labeling from IBMSupportAssasstant packageing- Make boot with systemd in enforcing mode- Update to upstream- Add boolean to turn off port forwarding in sshd.- Add support for ebtables - Fixes for rhcs and corosync policy-Update to upstream-Update to upstream-Update to upstream- Add Zarafa policy- Cleanup of aiccu policy - initial mock policy- Lots of random fixes- Update to upstream- Update to upstream - Allow prelink script to signal itself - Cobbler fixes- Add xdm_var_run_t to xserver_stream_connect_xdm - Add cmorrord and mpd policy from Miroslav Grepl- Fix sshd creation of krb cc files for users to be user_tmp_t- Fixes for accountsdialog - Fixes for boinc- Fix label on /var/lib/dokwiki - Change permissive domains to enforcing - Fix libvirt policy to allow it to run on mls- Update to upstream- Allow procmail to execute scripts in the users home dir that are labeled home_bin_t - Fix /var/run/abrtd.lock label- Allow login programs to read krb5_home_t Resolves: 594833 - Add obsoletes for cachefilesfd-selinux package Resolves: #575084- Allow mount to r/w abrt fifo file - Allow svirt_t to getattr on hugetlbfs - Allow abrt to create a directory under /var/spool- Add labels for /sys - Allow sshd to getattr on shutdown - Fixes for munin - Allow sssd to use the kernel key ring - Allow tor to send syslog messages - Allow iptabels to read usr files - allow policykit to read all domains state- Fix path for /var/spool/abrt - Allow nfs_t as an entrypoint for http_sys_script_t - Add policy for piranha - Lots of fixes for sosreport- Allow xm_t to read network state and get and set capabilities - Allow policykit to getattr all processes - Allow denyhosts to connect to tcp port 9911 - Allow pyranha to use raw ip sockets and ptrace itself - Allow unconfined_execmem_t and gconfsd mechanism to dbus - Allow staff to kill ping process - Add additional MLS rules- Allow gdm to edit ~/.gconf dir Resolves: #590677 - Allow dovecot to create directories in /var/lib/dovecot Partially resolves 590224 - Allow avahi to dbus chat with NetworkManager - Fix cobbler labels - Dontaudit iceauth_t leaks - fix /var/lib/lxdm file context - Allow aiccu to use tun tap devices - Dontaudit shutdown using xserver.log- Fixes for sandbox_x_net_t to match access for sandbox_web_t ++ - Add xdm_etc_t for /etc/gdm directory, allow accountsd to manage this directory - Add dontaudit interface for bluetooth dbus - Add chronyd_read_keys, append_keys for initrc_t - Add log support for ksmtuned Resolves: #586663- Allow boinc to send mail- Allow initrc_t to remove dhcpc_state_t - Fix label on sa-update.cron - Allow dhcpc to restart chrony initrc - Don't allow sandbox to send signals to its parent processes - Fix transition from unconfined_t -> unconfined_mount_t -> rpcd_t Resolves: #589136- Fix location of oddjob_mkhomedir Resolves: #587385 - fix labeling on /root/.shosts and ~/.shosts - Allow ipsec_mgmt_t to manage net_conf_t Resolves: #586760- Dontaudit sandbox trying to connect to netlink sockets Resolves: #587609 - Add policy for piranha- Fixups for xguest policy - Fixes for running sandbox firefox- Allow ksmtuned to use terminals Resolves: #586663 - Allow lircd to write to generic usb devices- Allow sandbox_xserver to connectto unconfined stream Resolves: #585171- Allow initrc_t to read slapd_db_t Resolves: #585476 - Allow ipsec_mgmt to use unallocated devpts and to create /etc/resolv.conf Resolves: #585963- Allow rlogind_t to search /root for .rhosts Resolves: #582760 - Fix path for cached_var_t - Fix prelink paths /var/lib/prelink - Allow confined users to direct_dri - Allow mls lvm/cryptosetup to work- Allow virtd_t to manage firewall/iptables config Resolves: #573585- Fix label on /root/.rhosts Resolves: #582760 - Add labels for Picasa - Allow openvpn to read home certs - Allow plymouthd_t to use tty_device_t - Run ncftool as iptables_t - Allow mount to unmount unlabeled_t - Dontaudit hal leaks- Allow livecd to transition to mount- Update to upstream - Allow abrt to delete sosreport Resolves: #579998 - Allow snmp to setuid and gid Resolves: #582155 - Allow smartd to use generic scsi devices Resolves: #582145- Allow ipsec_t to create /etc/resolv.conf with the correct label - Fix reserved port destination - Allow autofs to transition to showmount - Stop crashing tuned- Add telepathysofiasip policy- Update to upstream - Fix label for /opt/google/chrome/chrome-sandbox - Allow modemmanager to dbus with policykit- Fix allow_httpd_mod_auth_pam to use auth_use_pam(httpd_t) - Allow accountsd to read shadow file - Allow apache to send audit messages when using pam - Allow asterisk to bind and connect to sip tcp ports - Fixes for dovecot 2.0 - Allow initrc_t to setattr on milter directories - Add procmail_home_t for .procmailrc file- Fixes for labels during install from livecd- Fix /cgroup file context - Fix broken afs use of unlabled_t - Allow getty to use the console for s390- Fix cgroup handling adding policy for /cgroup - Allow confined users to write to generic usb devices, if user_rw_noexattrfile boolean set- Merge patches from dgrift- Update upstream - Allow abrt to write to the /proc under any process- Fix ~/.fontconfig label - Add /root/.cert label - Allow reading of the fixed_file_disk_t:lnk_file if you can read file - Allow qemu_exec_t as an entrypoint to svirt_t- Update to upstream - Allow tmpreaper to delete sandbox sock files - Allow chrome-sandbox_t to use /dev/zero, and dontaudit getattr file systems - Fixes for gitosis - No transition on livecd to passwd or chfn - Fixes for denyhosts- Add label for /var/lib/upower - Allow logrotate to run sssd - dontaudit readahead on tmpfs blk files - Allow tmpreaper to setattr on sandbox files - Allow confined users to execute dos files - Allow sysadm_t to kill processes running within its clearance - Add accountsd policy - Fixes for corosync policy - Fixes from crontab policy - Allow svirt to manage svirt_image_t chr files - Fixes for qdisk policy - Fixes for sssd policy - Fixes for newrole policy- make libvirt work on an MLS platform- Add qpidd policy- Update to upstream- Allow boinc to read kernel sysctl - Fix snmp port definitions - Allow apache to read anon_inodefs- Allow shutdown dac_override- Add device_t as a file system - Fix sysfs association- Dontaudit ipsec_mgmt sys_ptrace - Allow at to mail its spool files - Allow nsplugin to search in .pulse directory- Update to upstream- Allow users to dbus chat with xdm - Allow users to r/w wireless_device_t - Dontaudit reading of process states by ipsec_mgmt- Fix openoffice from unconfined_t- Add shutdown policy so consolekit can shutdown system- Update to upstream- Update to upstream- Update to upstream - These are merges of my patches - Remove 389 labeling conflicts - Add MLS fixes found in RHEL6 testing - Allow pulseaudio to run as a service - Add label for mssql and allow apache to connect to this database port if boolean set - Dontaudit searches of debugfs mount point - Allow policykit_auth to send signals to itself - Allow modcluster to call getpwnam - Allow swat to signal winbind - Allow usbmux to run as a system role - Allow svirt to create and use devpts- Add MLS fixes found in RHEL6 testing - Allow domains to append to rpm_tmp_t - Add cachefilesfd policy - Dontaudit leaks when transitioning- Change allow_execstack and allow_execmem booleans to on - dontaudit acct using console - Add label for fping - Allow tmpreaper to delete sandbox_file_t - Fix wine dontaudit mmap_zero - Allow abrt to read var_t symlinks- Additional policy for rgmanager- Allow sshd to setattr on pseudo terms- Update to upstream- Allow policykit to send itself signals- Fix duplicate cobbler definition- Fix file context of /var/lib/avahi-autoipd- Merge with upstream- Allow sandbox to work with MLS- Make Chrome work with staff user- Add icecast policy - Cleanup spec file- Add mcelog policy- Lots of fixes found in F12- Fix rpm_dontaudit_leaks- Add getsched to hald_t - Add file context for Fedora/Redhat Directory Server- Allow abrt_helper to getattr on all filesystems - Add label for /opt/real/RealPlayer/plugins/oggfformat\.so- Add gstreamer_home_t for ~/.gstreamer- Update to upstream- Fix git- Turn on puppet policy - Update to dgrift git policy- Move users file to selection by spec file. - Allow vncserver to run as unconfined_u:unconfined_r:unconfined_t- Update to upstream- Remove most of the permissive domains from F12.- Add cobbler policy from dgrift- add usbmon device - Add allow rulse for devicekit_disk- Lots of fixes found in F12, fixes from Tom London- Cleanups from dgrift- Add back xserver_manage_home_fonts- Dontaudit sandbox trying to read nscd and sssd- Update to upstream- Rename udisks-daemon back to devicekit_disk_t policy- Fixes for abrt calls- Add tgtd policy- Update to upstream release- Add asterisk policy back in - Update to upstream release 2.20091117- Update to upstream release 2.20091117- Fixup nut policy- Update to upstream- Allow vpnc request the kernel to load modules- Fix minimum policy installs - Allow udev and rpcbind to request the kernel to load modules- Add plymouth policy - Allow local_login to sys_admin- Allow cupsd_config to read user tmp - Allow snmpd_t to signal itself - Allow sysstat_t to makedir in sysstat_log_t- Update rhcs policy- Allow users to exec restorecond- Allow sendmail to request kernel modules load- Fix all kernel_request_load_module domains- Fix all kernel_request_load_module domains- Remove allow_exec* booleans for confined users. Only available for unconfined_t- More fixes for sandbox_web_t- Allow sshd to create .ssh directory and content- Fix request_module line to module_request- Fix sandbox policy to allow it to run under firefox. - Dont audit leaks.- Fixes for sandbox- Update to upstream - Dontaudit nsplugin search /root - Dontaudit nsplugin sys_nice- Fix label on /usr/bin/notepad, /usr/sbin/vboxadd-service - Remove policycoreutils-python requirement except for minimum- Fix devicekit_disk_t to getattr on all domains sockets and fifo_files - Conflicts seedit (You can not use selinux-policy-targeted and seedit at the same time.)- Add wordpress/wp-content/uploads label - Fixes for sandbox when run from staff_t- Update to upstream - Fixes for devicekit_disk- More fixes- Lots of fixes for initrc and other unconfined domains- Allow xserver to use netlink_kobject_uevent_socket- Fixes for sandbox- Dontaudit setroubleshootfix looking at /root directory- Update to upsteam- Allow gssd to send signals to users - Fix duplicate label for apache content- Update to upstream- Remove polkit_auth on upgrades- Add back in unconfined.pp and unconfineduser.pp - Add Sandbox unshare- Fixes for cdrecord, mdadm, and others- Add capability setting to dhcpc and gpm- Allow cronjobs to read exim_spool_t- Add ABRT policy- Fix system-config-services policy- Allow libvirt to change user componant of virt_domain- Allow cupsd_config_t to be started by dbus - Add smoltclient policy- Add policycoreutils-python to pre install- Make all unconfined_domains permissive so we can see what AVC's happen- Add pt_chown policy- Add kdump policy for Miroslav Grepl - Turn off execstack boolean- Turn on execstack on a temporary basis (#512845)- Allow nsplugin to connecto the session bus - Allow samba_net to write to coolkey data- Allow devicekit_disk to list inotify- Allow svirt images to create sock_file in svirt_var_run_t- Allow exim to getattr on mountpoints - Fixes for pulseaudio- Allow svirt_t to stream_connect to virtd_t- Allod hald_dccm_t to create sock_files in /tmp- More fixes from upstream- Fix polkit label - Remove hidebrokensymptoms for nss_ldap fix - Add modemmanager policy - Lots of merges from upstream - Begin removing textrel_shlib_t labels, from fixed libraries- Update to upstream- Allow certmaster to override dac permissions- Update to upstream- Fix context for VirtualBox- Update to upstream- Allow clamscan read amavis spool files- Fixes for xguest- fix multiple directory ownership of mandirs- Update to upstream- Add rules for rtkit-daemon- Update to upstream - Fix nlscd_stream_connect- Add rtkit policy- Allow rpcd_t to stream connect to rpcbind- Allow kpropd to create tmp files- Fix last duplicate /var/log/rpmpkgs- Update to upstream * add sssd- Update to upstream * cleanup- Update to upstream - Additional mail ports - Add virt_use_usb boolean for svirt- Fix mcs rules to include chr_file and blk_file- Add label for udev-acl- Additional rules for consolekit/udev, privoxy and various other fixes- New version for upstream- Allow NetworkManager to read inotifyfs- Allow setroubleshoot to run mlocate- Update to upstream- Add fish as a shell - Allow fprintd to list usbfs_t - Allow consolekit to search mountpoints - Add proper labeling for shorewall- New log file for vmware - Allow xdm to setattr on user_tmp_t- Upgrade to upstream- Allow fprintd to access sys_ptrace - Add sandbox policy- Add varnishd policy- Fixes for kpropd- Allow brctl to r/w tun_tap_device_t- Add /usr/share/selinux/packages- Allow rpcd_t to send signals to kernel threads- Fix upgrade for F10 to F11- Add policy for /var/lib/fprint-Remove duplicate line- Allow svirt to manage pci and other sysfs device data- Fix package selection handling- Fix /sbin/ip6tables-save context - Allod udev to transition to mount - Fix loading of mls policy file- Add shorewall policy- Additional rules for fprintd and sssd- Allow nsplugin to unix_read unix_write sem for unconfined_java- Fix uml files to be owned by users- Fix Upgrade path to install unconfineduser.pp when unocnfined package is 3.0.0 or less- Allow confined users to manage virt_content_t, since this is home dir content - Allow all domains to read rpm_script_tmp_t which is what shell creates on redirection- Fix labeling on /var/lib/misc/prelink* - Allow xserver to rw_shm_perms with all x_clients - Allow prelink to execute files in the users home directory- Allow initrc_t to delete dev_null - Allow readahead to configure auditing - Fix milter policy - Add /var/lib/readahead- Update to latest milter code from Paul Howarth- Additional perms for readahead- Allow pulseaudio to acquire_svc on session bus - Fix readahead labeling- Allow sysadm_t to run rpm directly - libvirt needs fowner- Allow sshd to read var_lib symlinks for freenx- Allow nsplugin unix_read and write on users shm and sem - Allow sysadm_t to execute su- Dontaudit attempts to getattr user_tmpfs_t by lvm - Allow nfs to share removable media- Add ability to run postdrop from confined users- Fixes for podsleuth- Turn off nsplugin transition - Remove Konsole leaked file descriptors for release- Allow cupsd_t to create link files in print_spool_t - Fix iscsi_stream_connect typo - Fix labeling on /etc/acpi/actions - Don't reinstall unconfine and unconfineuser on upgrade if they are not installed- Allow audioentroy to read etc files- Add fail2ban_var_lib_t - Fixes for devicekit_power_t- Separate out the ucnonfined user from the unconfined.pp package- Make sure unconfined_java_t and unconfined_mono_t create user_tmpfs_t.- Upgrade to latest upstream - Allow devicekit_disk sys_rawio- Dontaudit binds to ports < 1024 for named - Upgrade to latest upstream- Allow podsleuth to use tmpfs files- Add customizable_types for svirt- Allow setroubelshoot exec* privs to prevent crash from bad libraries - add cpufreqselector- Dontaudit listing of /root directory for cron system jobs- Fix missing ld.so.cache label- Add label for ~/.forward and /root/.forward- Fixes for svirt- Fixes to allow svirt read iso files in homedir- Add xenner and wine fixes from mgrepl- Allow mdadm to read/write mls override- Change to svirt to only access svirt_image_t- Fix libvirt policy- Upgrade to latest upstream- Fixes for iscsid and sssd - More cleanups for upgrade from F10 to Rawhide.- Add pulseaudio, sssd policy - Allow networkmanager to exec udevadm- Add pulseaudio context- Upgrade to latest patches- Fixes for libvirt- Update to Latest upstream- Fix setrans.conf to show SystemLow for s0- Further confinement of qemu images via svirt- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- Allow NetworkManager to manage /etc/NetworkManager/system-connections- add virtual_image_context and virtual_domain_context files- Allow rpcd_t to send signal to mount_t - Allow libvirtd to run ranged- Fix sysnet/net_conf_t- Fix squidGuard labeling- Re-add corenet_in_generic_if(unlabeled_t)* Tue Feb 10 2009 Dan Walsh 3.6.5-2 - Add git web policy- Add setrans contains from upstream- Do transitions outside of the booleans- Allow xdm to create user_tmp_t sockets for switch user to work- Fix staff_t domain- Grab remainder of network_peer_controls patch- More fixes for devicekit- Upgrade to latest upstream- Add boolean to disallow unconfined_t login- Add back transition from xguest to mozilla- Add virt_content_ro_t and labeling for isos directory- Fixes for wicd daemon- More mls/rpm fixes- Add policy to make dbus/nm-applet work- Remove polgen-ifgen from post and add trigger to policycoreutils-python- Add wm policy - Make mls work in graphics mode- Fixed for DeviceKit- Add devicekit policy- Update to upstream- Define openoffice as an x_domain- Fixes for reading xserver_tmp_t- Allow cups_pdf_t write to nfs_t- Remove audio_entropy policy- Update to upstream- Allow hal_acl_t to getattr/setattr fixed_disk- Change userdom_read_all_users_state to include reading symbolic links in /proc- Fix dbus reading /proc information- Add missing alias for home directory content- Fixes for IBM java location- Allow unconfined_r unconfined_java_t- Add cron_role back to user domains- Fix sudo setting of user keys- Allow iptables to talk to terminals - Fixes for policy kit - lots of fixes for booting.- Cleanup policy- Rebuild for Python 2.6- Fix labeling on /var/spool/rsyslog- Allow postgresl to bind to udp nodes- Allow lvm to dbus chat with hal - Allow rlogind to read nfs_t- Fix cyphesis file context- Allow hal/pm-utils to look at /var/run/video.rom - Add ulogd policy- Additional fixes for cyphesis - Fix certmaster file context - Add policy for system-config-samba - Allow hal to read /var/run/video.rom- Allow dhcpc to restart ypbind - Fixup labeling in /var/run- Add certmaster policy- Fix confined users - Allow xguest to read/write xguest_dbusd_t- Allow openoffice execstack/execmem privs- Allow mozilla to run with unconfined_execmem_t- Dontaudit domains trying to write to .xsession-errors- Allow nsplugin to look at autofs_t directory- Allow kerneloops to create tmp files- More alias for fastcgi- Remove mod_fcgid-selinux package- Fix dovecot access- Policy cleanup- Remove Multiple spec - Add include - Fix makefile to not call per_role_expansion- Fix labeling of libGL- Update to upstream- Update to upstream policy- Fixes for confined xwindows and xdm_t- Allow confined users and xdm to exec wm - Allow nsplugin to talk to fifo files on nfs- Allow NetworkManager to transition to avahi and iptables - Allow domains to search other domains keys, coverup kernel bug- Fix labeling for oracle- Allow nsplugin to comminicate with xdm_tmp_t sock_file- Change all user tmpfs_t files to be labeled user_tmpfs_t - Allow radiusd to create sock_files- Upgrade to upstream- Allow confined users to login with dbus- Fix transition to nsplugin- Add file context for /dev/mspblk.*- Fix transition to nsplugin '- Fix labeling on new pm*log - Allow ssh to bind to all nodes- Merge upstream changes - Add Xavier Toth patches- Add qemu_cache_t for /var/cache/libvirt- Remove gamin policy- Add tinyxs-max file system support- Update to upstream - New handling of init scripts- Allow pcsd to dbus - Add memcache policy- Allow audit dispatcher to kill his children- Update to upstream - Fix crontab use by unconfined user- Allow ifconfig_t to read dhcpc_state_t- Update to upstream- Update to upstream- Allow system-config-selinux to work with policykit- Fix novel labeling- Consolodate pyzor,spamassassin, razor into one security domain - Fix xdm requiring additional perms.- Fixes for logrotate, alsa- Eliminate vbetool duplicate entry- Fix xguest -> xguest_mozilla_t -> xguest_openiffice_t - Change dhclient to be able to red networkmanager_var_run- Update to latest refpolicy - Fix libsemanage initial install bug- Add inotify support to nscd- Allow unconfined_t to setfcap- Allow amanda to read tape - Allow prewikka cgi to use syslog, allow audisp_t to signal cgi - Add support for netware file systems- Allow ypbind apps to net_bind_service- Allow all system domains and application domains to append to any log file- Allow gdm to read rpm database - Allow nsplugin to read mplayer config files- Allow vpnc to run ifconfig- Allow confined users to use postgres - Allow system_mail_t to exec other mail clients - Label mogrel_rails as an apache server- Apply unconfined_execmem_exec_t to haskell programs- Fix prelude file context- allow hplip to talk dbus - Fix context on ~/.local dir- Prevent applications from reading x_device- Add /var/lib/selinux context- Update to upstream- Add livecd policy- Dontaudit search of admin_home for init_system_domain - Rewrite of xace interfaces - Lots of new fs_list_inotify - Allow livecd to transition to setfiles_mac- Begin XAce integration- Merge Upstream- Allow amanada to create data files- Fix initial install, semanage setup- Allow system_r for httpd_unconfined_script_t- Remove dmesg boolean - Allow user domains to read/write game data- Change unconfined_t to transition to unconfined_mono_t when running mono - Change XXX_mono_t to transition to XXX_t when executing bin_t files, so gnome-do will work- Remove old booleans from targeted-booleans.conf file- Add boolean to mmap_zero - allow tor setgid - Allow gnomeclock to set clock- Don't run crontab from unconfined_t- Change etc files to config files to allow users to read them- Lots of fixes for confined domains on NFS_t homedir- dontaudit mrtg reading /proc - Allow iscsi to signal itself - Allow gnomeclock sys_ptrace- Allow dhcpd to read kernel network state- Label /var/run/gdm correctly - Fix unconfined_u user creation- Allow transition from initrc_t to getty_t- Allow passwd to communicate with user sockets to change gnome-keyring- Fix initial install- Allow radvd to use fifo_file - dontaudit setfiles reading links - allow semanage sys_resource - add allow_httpd_mod_auth_ntlm_winbind boolean - Allow privhome apps including dovecot read on nfs and cifs home dirs if the boolean is set- Allow nsplugin to read /etc/mozpluggerrc, user_fonts - Allow syslog to manage innd logs. - Allow procmail to ioctl spamd_exec_t- Allow initrc_t to dbus chat with consolekit.- Additional access for nsplugin - Allow xdm setcap/getcap until pulseaudio is fixed- Allow mount to mkdir on tmpfs - Allow ifconfig to search debugfs- Fix file context for MATLAB - Fixes for xace- Allow stunnel to transition to inetd children domains - Make unconfined_dbusd_t an unconfined domain- Fixes for qemu/virtd- Fix bug in mozilla policy to allow xguest transition - This will fix the libsemanage.dbase_llist_query: could not find record value libsemanage.dbase_llist_query: could not query record value (No such file or directory) bug in xguest- Allow nsplugin to run acroread- Add cups_pdf policy - Add openoffice policy to run in xguest- prewika needs to contact mysql - Allow syslog to read system_map files- Change init_t to an unconfined_domain- Allow init to transition to initrc_t on shell exec. - Fix init to be able to sendto init_t. - Allow syslog to connect to mysql - Allow lvm to manage its own fifo_files - Allow bugzilla to use ldap - More mls fixes- fixes for init policy (#436988) - fix build- Additional changes for MLS policy- Fix initrc_context generation for MLS- Fixes for libvirt- Allow bitlebee to read locale_t- More xselinux rules- Change httpd_$1_script_r*_t to httpd_$1_content_r*_t- Prepare policy for beta release - Change some of the system domains back to unconfined - Turn on some of the booleans- Allow nsplugin_config execstack/execmem - Allow nsplugin_t to read alsa config - Change apache to use user content- Add cyphesis policy- Fix Makefile.devel to build mls modules - Fix qemu to be more specific on labeling- Update to upstream fixes- Allow staff to mounton user_home_t- Add xace support- Add fusectl file system- Fixes from yum-cron - Update to latest upstream- Fix userdom_list_user_files- Merge with upstream- Allow udev to send audit messages- Add additional login users interfaces - userdom_admin_login_user_template(staff)- More fixes for polkit- Eliminate transition from unconfined_t to qemu by default - Fixes for gpg- Update to upstream- Fixes for staff_t- Add policy for kerneloops - Add policy for gnomeclock- Fixes for libvirt- Fixes for nsplugin- More fixes for qemu- Additional ports for vnc and allow qemu and libvirt to search all directories- Update to upstream - Add libvirt policy - add qemu policy- Allow fail2ban to create a socket in /var/run- Allow allow_httpd_mod_auth_pam to work- Add audisp policy and prelude- Allow all user roles to executae samba net command- Allow usertypes to read/write noxattr file systems- Fix nsplugin to allow flashplugin to work in enforcing mode- Allow pam_selinux_permit to kill all processes- Allow ptrace or user processes by users of same type - Add boolean for transition to nsplugin- Allow nsplugin sys_nice, getsched, setsched- Allow login programs to talk dbus to oddjob- Add procmail_log support - Lots of fixes for munin- Allow setroubleshoot to read policy config and send audit messages- Allow users to execute all files in homedir, if boolean set - Allow mount to read samba config- Fixes for xguest to run java plugin- dontaudit pam_t and dbusd writing to user_home_t- Update gpg to allow reading of inotify- Change user and staff roles to work correctly with varied perms- Fix munin log, - Eliminate duplicate mozilla file context - fix wpa_supplicant spec- Fix role transition from unconfined_r to system_r when running rpm - Allow unconfined_domains to communicate with user dbus instances- Fixes for xguest- Let all uncofined domains communicate with dbus unconfined- Run rpm in system_r- Zero out customizable types- Fix definiton of admin_home_t- Fix munin file context- Allow cron to run unconfined apps- Modify default login to unconfined_u- Dontaudit dbus user client search of /root- Update to upstream- Fixes for polkit - Allow xserver to ptrace- Add polkit policy - Symplify userdom context, remove automatic per_role changes- Update to upstream - Allow httpd_sys_script_t to search users homedirs- Allow rpm_script to transition to unconfined_execmem_t- Remove user based home directory separation- Remove user specific crond_t- Merge with upstream - Allow xsever to read hwdata_t - Allow login programs to setkeycreate- Update to upstream- Update to upstream- Allow XServer to read /proc/self/cmdline - Fix unconfined cron jobs - Allow fetchmail to transition to procmail - Fixes for hald_mac - Allow system_mail to transition to exim - Allow tftpd to upload files - Allow xdm to manage unconfined_tmp - Allow udef to read alsa config - Fix xguest to be able to connect to sound port- Fixes for hald_mac - Treat unconfined_home_dir_t as a home dir - dontaudit rhgb writes to fonts and root- Fix dnsmasq - Allow rshd full login privs- Allow rshd to connect to ports > 1023- Fix vpn to bind to port 4500 - Allow ssh to create shm - Add Kismet policy- Allow rpm to chat with networkmanager- Fixes for ipsec and exim mail - Change default to unconfined user- Pass the UNK_PERMS param to makefile - Fix gdm location- Make alsa work- Fixes for consolekit and startx sessions- Dontaudit consoletype talking to unconfined_t- Remove homedir_template- Check asound.state- Fix exim policy- Allow tmpreadper to read man_t - Allow racoon to bind to all nodes - Fixes for finger print reader- Allow xdm to talk to input device (fingerprint reader) - Allow octave to run as java- Allow login programs to set ioctl on /proc- Allow nsswitch apps to read samba_var_t- Fix maxima- Eliminate rpm_t:fifo_file avcs - Fix dbus path for helper app- Fix service start stop terminal avc's- Allow also to search var_lib - New context for dbus launcher- Allow cupsd_config_t to read/write usb_device_t - Support for finger print reader, - Many fixes for clvmd - dbus starting networkmanager- Fix java and mono to run in xguest account- Fix to add xguest account when inititial install - Allow mono, java, wine to run in userdomains- Allow xserver to search devpts_t - Dontaudit ldconfig output to homedir- Remove hplip_etc_t change back to etc_t.- Allow cron to search nfs and samba homedirs- Allow NetworkManager to dbus chat with yum-updated- Allow xfs to bind to port 7100- Allow newalias/sendmail dac_override - Allow bind to bind to all udp ports- Turn off direct transition- Allow wine to run in system role- Fix java labeling- Define user_home_type as home_type- Allow sendmail to create etc_aliases_t- Allow login programs to read symlinks on homedirs- Update an readd modules- Cleanup spec file- Allow xserver to be started by unconfined process and talk to tty- Upgrade to upstream to grab postgressql changes- Add setransd for mls policy- Add ldconfig_cache_t- Allow sshd to write to proc_t for afs login- Allow xserver access to urand- allow dovecot to search mountpoints- Fix Makefile for building policy modules- Fix dhcpc startup of service- Fix dbus chat to not happen for xguest and guest users- Fix nagios cgi - allow squid to communicate with winbind- Fixes for ldconfig- Update from upstream- Add nasd support- Fix new usb devices and dmfm- Eliminate mount_ntfs_t policy, merge into mount_t- Allow xserver to write to ramfs mounted by rhgb- Add context for dbus machine id- Update with latest changes from upstream- Fix prelink to handle execmod- Add ntpd_key_t to handle secret data- Add anon_inodefs - Allow unpriv user exec pam_exec_t - Fix trigger- Allow cups to use generic usb - fix inetd to be able to run random apps (git)- Add proper contexts for rsyslogd- Fixes for xguest policy- Allow execution of gconf- Fix moilscanner update problem- Begin adding policy to separate setsebool from semanage - Fix xserver.if definition to not break sepolgen.if- Add new devices- Add brctl policy- Fix root login to include system_r- Allow prelink to read kernel sysctls- Default to user_u:system_r:unconfined_t- fix squid - Fix rpm running as uid- Fix syslog declaration- Allow avahi to access inotify - Remove a lot of bogus security_t:filesystem avcs- Remove ifdef strict policy from upstream- Remove ifdef strict to allow user_u to login- Fix for amands - Allow semanage to read pp files - Allow rhgb to read xdm_xserver_tmp- Allow kerberos servers to use ldap for backing store- allow alsactl to read kernel state- More fixes for alsactl - Transition from hal and modutils - Fixes for suspend resume. - insmod domtrans to alsactl - insmod writes to hal log- Allow unconfined_t to transition to NetworkManager_t - Fix netlabel policy- Update to latest from upstream- Update to latest from upstream- Update to latest from upstream- Allow pcscd_t to send itself signals- Fixes for unix_update - Fix logwatch to be able to search all dirs- Upstream bumped the version- Allow consolekit to syslog - Allow ntfs to work with hal- Allow iptables to read etc_runtime_t- MLS Fixes- Fix path of /etc/lvm/cache directory - Fixes for alsactl and pppd_t - Fixes for consolekit- Allow insmod_t to mount kvmfs_t filesystems- Rwho policy - Fixes for consolekit- fixes for fusefs- Fix samba_net to allow it to view samba_var_t- Update to upstream- Fix Sonypic backlight - Allow snmp to look at squid_conf_t- Fixes for pyzor, cyrus, consoletype on everything installs- Fix hald_acl_t to be able to getattr/setattr on usb devices - Dontaudit write to unconfined_pipes for load_policy- Allow bluetooth to read inotifyfs- Fixes for samba domain controller. - Allow ConsoleKit to look at ttys- Fix interface call- Allow syslog-ng to read /var - Allow locate to getattr on all filesystems - nscd needs setcap- Update to upstream- Allow samba to run groupadd- Update to upstream- Allow mdadm to access generic scsi devices- Fix labeling on udev.tbl dirs- Fixes for logwatch- Add fusermount and mount_ntfs policy- Update to upstream - Allow saslauthd to use kerberos keytabs- Fixes for samba_var_t- Allow networkmanager to setpgid - Fixes for hal_acl_t- Remove disable_trans booleans - hald_acl_t needs to talk to nscd- Fix prelink to be able to manage usr dirs.- Allow insmod to launch init scripts- Remove setsebool policy- Fix handling of unlabled_t packets- More of my patches from upstream- Update to latest from upstream - Add fail2ban policy- Update to remove security_t:filesystem getattr problems- Policy for consolekit- Update to latest from upstream- Revert Nemiver change - Set sudo as a corecmd so prelink will work, remove sudoedit mapping, since this will not work, it does not transition. - Allow samba to execute useradd- Upgrade to the latest from upstream- Add sepolgen support - Add bugzilla policy- Fix file context for nemiver- Remove include sym link- Allow mozilla, evolution and thunderbird to read dev_random. Resolves: #227002 - Allow spamd to connect to smtp port Resolves: #227184 - Fixes to make ypxfr work Resolves: #227237- Fix ssh_agent to be marked as an executable - Allow Hal to rw sound device- Fix spamassisin so crond can update spam files - Fixes to allow kpasswd to work - Fixes for bluetooth- Remove some targeted diffs in file context file- Fix squid cachemgr labeling- Add ability to generate webadm_t policy - Lots of new interfaces for httpd - Allow sshd to login as unconfined_t- Continue fixing, additional user domains- Begin adding user confinement to targeted policy- Fixes for prelink, ktalkd, netlabel- Allow prelink when run from rpm to create tmp files Resolves: #221865 - Remove file_context for exportfs Resolves: #221181 - Allow spamassassin to create ~/.spamassissin Resolves: #203290 - Allow ssh access to the krb tickets - Allow sshd to change passwd - Stop newrole -l from working on non securetty Resolves: #200110 - Fixes to run prelink in MLS machine Resolves: #221233 - Allow spamassassin to read var_lib_t dir Resolves: #219234- fix mplayer to work under strict policy - Allow iptables to use nscd Resolves: #220794- Add gconf policy and make it work with strict- Many fixes for strict policy and by extension mls.- Fix to allow ftp to bind to ports > 1024 Resolves: #219349- Allow semanage to exec it self. Label genhomedircon as semanage_exec_t Resolves: #219421 - Allow sysadm_lpr_t to manage other print spool jobs Resolves: #220080- allow automount to setgid Resolves: #219999- Allow cron to polyinstatiate - Fix creation of boot flags Resolves: #207433- Fixes for irqbalance Resolves: #219606- Fix vixie-cron to work on mls Resolves: #207433Resolves: #218978- Allow initrc to create files in /var directories Resolves: #219227- More fixes for MLS Resolves: #181566- More Fixes polyinstatiation Resolves: #216184- More Fixes polyinstatiation - Fix handling of keyrings Resolves: #216184- Fix polyinstatiation - Fix pcscd handling of terminal Resolves: #218149 Resolves: #218350- More fixes for quota Resolves: #212957- ncsd needs to use avahi sockets Resolves: #217640 Resolves: #218014- Allow login programs to polyinstatiate homedirs Resolves: #216184 - Allow quotacheck to create database files Resolves: #212957- Dontaudit appending hal_var_lib files Resolves: #217452 Resolves: #217571 Resolves: #217611 Resolves: #217640 Resolves: #217725- Fix context for helix players file_context #216942- Fix load_policy to be able to mls_write_down so it can talk to the terminal- Fixes for hwclock, clamav, ftp- Move to upstream version which accepted my patches- Fixes for nvidia driver- Allow semanage to signal mcstrans- Update to upstream- Allow modstorage to edit /etc/fstab file- Fix for qemu, /dev/- Fix path to realplayer.bin- Allow xen to connect to xen port- Allow cups to search samba_etc_t directory - Allow xend_t to list auto_mountpoints- Allow xen to search automount- Fix spec of jre files- Fix unconfined access to shadow file- Allow xend to create files in xen_image_t directories- Fixes for /var/lib/hal- Remove ability for sysadm_t to look at audit.log- Fix rpc_port_types - Add aide policy for mls- Merge with upstream- Lots of fixes for ricci- Allow xen to read/write fixed devices with a boolean - Allow apache to search /var/log- Fix policygentool specfile problem. - Allow apache to send signals to it's logging helpers. - Resolves: rhbz#212731- Add perms for swat- Add perms for swat- Allow daemons to dump core files to /- Fixes for ricci- Allow mount.nfs to work- Allow ricci-modstorage to look at lvm_etc_t- Fixes for ricci using saslauthd- Allow mountpoint on home_dir_t and home_t- Update xen to read nfs files- Allow noxattrfs to associate with other noxattrfs- Allow hal to use power_device_t- Allow procemail to look at autofs_t - Allow xen_image_t to work as a fixed device- Refupdate from upstream- Add lots of fixes for mls cups- Lots of fixes for ricci- Fix number of cats- Update to upstream- More iSCSI changes for #209854- Test ISCSI fixes for #209854- allow semodule to rmdir selinux_config_t dir- Fix boot_runtime_t problem on ppc. Should not be creating these files.- Fix context mounts on reboot - Fix ccs creation of directory in /var/log- Update for tallylog- Allow xend to rewrite dhcp conf files - Allow mgetty sys_admin capability- Make xentapctrl work- Don't transition unconfined_t to bootloader_t - Fix label in /dev/xen/blktap- Patch for labeled networking- Fix crond handling for mls- Update to upstream- Remove bluetooth-helper transition - Add selinux_validate for semanage - Require new version of libsemanage- Fix prelink- Fix rhgb- Fix setrans handling on MLS and useradd- Support for fuse - fix vigr- Fix dovecot, amanda - Fix mls- Allow java execheap for itanium- Update with upstream- mls fixes- Update from upstream- More fixes for mls - Revert change on automount transition to mount- Fix cron jobs to run under the correct context- Fixes to make pppd work- Multiple policy fixes - Change max categories to 1023- Fix transition on mcstransd- Add /dev/em8300 defs- Upgrade to upstream- Fix ppp connections from network manager- Add tty access to all domains boolean - Fix gnome-pty-helper context for ia64- Fixed typealias of firstboot_rw_t- Fix location of xel log files - Fix handling of sysadm_r -> rpm_exec_t- Fixes for autofs, lp- Update from upstream- Fixup for test6- Update to upstream- Update to upstream- Fix suspend to disk problems- Lots of fixes for restarting daemons at the console.- Fix audit line - Fix requires line- Upgrade to upstream- Fix install problems- Allow setroubleshoot to getattr on all dirs to gather RPM data- Set /usr/lib/ia32el/ia32x_loader to unconfined_execmem_exec_t for ia32 platform - Fix spec for /dev/adsp- Fix xen tty devices- Fixes for setroubleshoot- Update to upstream- Fixes for stunnel and postgresql - Update from upstream- Update from upstream - More java fixes- Change allow_execstack to default to on, for RHEL5 Beta. This is required because of a Java compiler problem. Hope to turn off for next beta- Misc fixes- More fixes for strict policy- Quiet down anaconda audit messages- Fix setroubleshootd- Update to the latest from upstream- More fixes for xen- Fix anaconda transitions- yet more xen rules- more xen rules- Fixes for Samba- Fixes for xen- Allow setroubleshootd to send mail- Add nagios policy- fixes for setroubleshoot- Added Paul Howarth patch to only load policy packages shipped with this package - Allow pidof from initrc to ptrace higher level domains - Allow firstboot to communicate with hal via dbus- Add policy for /var/run/ldapi- Fix setroubleshoot policy- Fixes for mls use of ssh - named has a new conf file- Fixes to make setroubleshoot work- Cups needs to be able to read domain state off of printer client- add boolean to allow zebra to write config files- setroubleshootd fixes- Allow prelink to read bin_t symlink - allow xfs to read random devices - Change gfs to support xattr- Remove spamassassin_can_network boolean- Update to upstream - Fix lpr domain for mls- Add setroubleshoot policy- Turn off auditallow on setting booleans- Multiple fixes- Update to upstream- Update to upstream - Add new class for kernel key ring- Update to upstream- Update to upstream- Break out selinux-devel package- Add ibmasmfs- Fix policygentool gen_requires- Update from Upstream- Fix spec of realplay- Update to upstream- Fix semanage- Allow useradd to create_home_dir in MLS environment- Update from upstream- Update from upstream- Add oprofilefs- Fix for hplip and Picasus- Update to upstream- Update to upstream- fixes for spamd- fixes for java, openldap and webalizer- Xen fixes- Upgrade to upstream- allow hal to read boot_t files - Upgrade to upstream- allow hal to read boot_t files- Update from upstream- Fixes for amavis- Update from upstream- Allow auditctl to search all directories- Add acquire service for mono.- Turn off allow_execmem boolean - Allow ftp dac_override when allowed to access users homedirs- Clean up spec file - Transition from unconfined_t to prelink_t- Allow execution of cvs command- Update to upstream- Update to upstream- Fix libjvm spec- Update to upstream- Add xm policy - Fix policygentool- Update to upstream - Fix postun to only disable selinux on full removal of the packages- Allow mono to chat with unconfined- Allow procmail to sendmail - Allow nfs to share dosfs- Update to latest from upstream - Allow selinux-policy to be removed and kernel not to crash- Update to latest from upstream - Add James Antill patch for xen - Many fixes for pegasus- Add unconfined_mount_t - Allow privoxy to connect to httpd_cache - fix cups labeleing on /var/cache/cups- Update to latest from upstream- Update to latest from upstream - Allow mono and unconfined to talk to initrc_t dbus objects- Change libraries.fc to stop shlib_t form overriding texrel_shlib_t- Fix samba creating dirs in homedir - Fix NFS so its booleans would work- Allow secadm_t ability to relabel all files - Allow ftp to search xferlog_t directories - Allow mysql to communicate with ldap - Allow rsync to bind to rsync_port_t- Fixed mailman with Postfix #183928 - Allowed semanage to create file_context files. - Allowed amanda_t to access inetd_t TCP sockets and allowed amanda_recover_t to bind to reserved ports. #149030 - Don't allow devpts_t to be associated with tmp_t. - Allow hald_t to stat all mountpoints. - Added boolean samba_share_nfs to allow smbd_t full access to NFS mounts. - Make mount run in mount_t domain from unconfined_t to prevent mislabeling of /etc/mtab. - Changed the file_contexts to not have a regex before the first ^/[a-z]/ whenever possible, makes restorecon slightly faster. - Correct the label of /etc/named.caching-nameserver.conf - Now label /usr/src/kernels/.+/lib(/.*)? as usr_t instead of /usr/src(/.*)?/lib(/.*)? - I don't think we need anything else under /usr/src hit by this. - Granted xen access to /boot, allowed mounting on xend_var_lib_t, and allowed xenstored_t rw access to the xen device node.- More textrel_shlib_t file path fixes - Add ada support- Get auditctl working in MLS policy- Add mono dbus support - Lots of file_context fixes for textrel_shlib_t in FC5 - Turn off execmem auditallow since they are filling log files- Update to upstream- Allow automount and dbus to read cert files- Fix ftp policy - Fix secadm running of auditctl- Update to upstream- Update to upstream- Fix policyhelp- Fix pam_console handling of usb_device - dontaudit logwatch reading /mnt dir- Update to upstream- Get transition rules to create policy.20 at SystemHigh- Allow secadmin to shutdown system - Allow sendmail to exec newalias- MLS Fixes dmidecode needs mls_file_read_up - add ypxfr_t - run init needs access to nscd - udev needs setuid - another xen log file - Dontaudit mount getattr proc_kcore_t- fix buildroot usage (#185391)- Get rid of mount/fsdisk scan of /dev messages - Additional fixes for suspend/resume- Fake make to rebuild enableaudit.pp- Get xen networking running.- Fixes for Xen - enableaudit should not be the same as base.pp - Allow ps to work for all process- more xen policy fixups- more xen fixage (#184393)- Fix blkid specification - Allow postfix to execute mailman_que- Blkid changes - Allow udev access to usb_device_t - Fix post script to create targeted policy config file- Allow lvm tools to create drevice dir- Add Xen support- Fixes for cups - Make cryptosetup work with hal- Load Policy needs translock- Fix cups html interface- Add hal changes suggested by Jeremy - add policyhelp to point at policy html pages- Additional fixes for nvidia and cups- Update to upstream - Merged my latest fixes - Fix cups policy to handle unix domain sockets- NSCD socket is in nscd_var_run_t needs to be able to search dir- Fixes Apache interface file- Fixes for new version of cups- Turn off polyinstatiate util after FC5- Fix problem with privoxy talking to Tor- Turn on polyinstatiation- Don't transition from unconfined_t to fsadm_t- Fix policy update model.- Update to upstream- Fix load_policy to work on MLS - Fix cron_rw_system_pipes for postfix_postdrop_t - Allow audotmount to run showmount- Fix swapon - allow httpd_sys_script_t to be entered via a shell - Allow httpd_sys_script_t to read eventpolfs- Update from upstream- allow cron to read apache files- Fix vpnc policy to work from NetworkManager- Update to upstream - Fix semoudle polcy- Update to upstream - fix sysconfig/selinux link- Add router port for zebra - Add imaze port for spamd - Fixes for amanda and java- Fix bluetooth handling of usb devices - Fix spamd reading of ~/ - fix nvidia spec- Update to upsteam- Add users_extra files- Update to upstream- Add semodule policy- Update from upstream- Fix for spamd to use razor port- Fixes for mcs - Turn on mount and fsadm for unconfined_t- Fixes for the -devel package- Fix for spamd to use ldap- Update to upstream- Update to upstream - Fix rhgb, and other Xorg startups- Update to upstream- Separate out role of secadm for mls- Add inotifyfs handling- Update to upstream - Put back in changes for pup/zen- Many changes for MLS - Turn on strict policy- Update to upstream- Update to upstream - Fixes for booting and logging in on MLS machine- Update to upstream - Turn off execheap execstack for unconfined users - Add mono/wine policy to allow execheap and execstack for them - Add execheap for Xdm policy- Update to upstream - Fixes to fetchmail,- Update to upstream- Fix for procmail/spamassasin - Update to upstream - Add rules to allow rpcd to work with unlabeled_networks.- Update to upstream - Fix ftp Man page- Update to upstream- fix pup transitions (#177262) - fix xen disks (#177599)- Update to upstream- More Fixes for hal and readahead- Fixes for hal and readahead- Update to upstream - Apply- Add wine and fix hal problems- Handle new location of hal scripts- Allow su to read /etc/mtab- Update to upstream- Fix "libsemanage.parse_module_headers: Data did not represent a module." problem- Allow load_policy to read /etc/mtab- Fix dovecot to allow dovecot_auth to look at /tmp- Allow restorecon to read unlabeled_t directories in order to fix labeling.- Add Logwatch policy- Fix /dev/ub[a-z] file context- Fix library specification - Give kudzu execmem privs- Fix hostname in targeted policy- Fix passwd command on mls- Lots of fixes to make mls policy work- Add dri libs to textrel_shlib_t - Add system_r role for java - Add unconfined_exec_t for vncserver - Allow slapd to use kerberos- Add man pages- Add enableaudit.pp- Fix mls policy- Update mls file from old version- Add sids back in - Rebuild with update checkpolicy- Fixes to allow automount to use portmap - Fixes to start kernel in s0-s15:c0.c255- Add java unconfined/execmem policy- Add file context for /var/cvs - Dontaudit webalizer search of homedir- Update from upstream- Clean up spec - range_transition crond to SystemHigh- Fixes for hal - Update to upstream- Turn back on execmem since we need it for java, firefox, ooffice - Allow gpm to stream socket to itself- fix requirements to be on the actual packages so that policy can get created properly at install time- Allow unconfined_t to execmod texrel_shlib_t- Update to upstream - Turn off allow_execmem and allow_execmod booleans - Add tcpd and automount policies- Add two new httpd booleans, turned off by default * httpd_can_network_relay * httpd_can_network_connect_db- Add ghost for policy.20- Update to upstream - Turn off boolean allow_execstack- Change setrans-mls to use new libsetrans - Add default_context rule for xdm- Change Requires to PreReg for requiring of policycoreutils on install- New upstream releaseAdd xdm policyUpdate from upstreamUpdate from upstreamUpdate from upstream- Also trigger to rebuild policy for versions up to 2.0.7.- No longer installing policy.20 file, anaconda handles the building of the app.- Fixes for dovecot and saslauthd- Cleanup pegasus and named - Fix spec file - Fix up passwd changing applications-Update to latest from upstream- Add rules for pegasus and avahi- Start building MLS Policy- Update to upstream- Turn on bash- Initial version/bin/sh  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0122456789:;<=>?@ABCDEFGHIJKLMNOPQR3.13.1-266.el7    develMakefileexample.fcexample.ifexample.tehtmlNetworkManager.htmlabrt.htmlabrt_dump_oops.htmlabrt_handle_event.htmlabrt_helper.htmlabrt_retrace_coredump.htmlabrt_retrace_worker.htmlabrt_upload_watch.htmlabrt_watch_log.htmlaccountsd.htmlacct.htmladmin_crontab.htmlafs.htmlafs_bosserver.htmlafs_fsserver.htmlafs_kaserver.htmlafs_ptserver.htmlafs_vlserver.htmlaiccu.htmlaide.htmlajaxterm.htmlajaxterm_ssh.htmlalsa.htmlamanda.htmlamanda_recover.htmlamtu.htmlanaconda.htmlanon_sftpd.htmlantivirus.htmlapcupsd.htmlapcupsd_cgi_script.htmlapm.htmlapmd.htmlarpwatch.htmlasterisk.htmlaudisp.htmlaudisp_remote.htmlauditadm.htmlauditadm_screen.htmlauditadm_su.htmlauditadm_sudo.htmlauditctl.htmlauditd.htmlauthconfig.htmlautomount.htmlavahi.htmlawstats.htmlawstats_script.htmlbacula.htmlbacula_admin.htmlbacula_unconfined_script.htmlbcfg2.htmlbitlbee.htmlblkmapd.htmlblktap.htmlblueman.htmlbluetooth.htmlbluetooth_helper.htmlboinc.htmlboinc_project.htmlboltd.htmlbootloader.htmlbrctl.htmlbrltty.htmlbugzilla_script.htmlbumblebee.htmlcachefiles_kernel.htmlcachefilesd.htmlcalamaris.htmlcallweaver.htmlcanna.htmlcardmgr.htmlccs.htmlcdcc.htmlcdrecord.htmlcertmaster.htmlcertmonger.htmlcertmonger_unconfined.htmlcertwatch.htmlcfengine_execd.htmlcfengine_monitord.htmlcfengine_serverd.htmlcgclear.htmlcgconfig.htmlcgdcbxd.htmlcgred.htmlcheckpc.htmlcheckpolicy.htmlchfn.htmlchkpwd.htmlchrome_sandbox.htmlchrome_sandbox_nacl.htmlchronyc.htmlchronyd.htmlchroot_user.htmlcinder_api.htmlcinder_backup.htmlcinder_scheduler.htmlcinder_volume.htmlciped.htmlclogd.htmlcloud_init.htmlcluster.htmlclvmd.htmlcmirrord.htmlcobblerd.htmlcockpit_session.htmlcockpit_ws.htmlcollectd.htmlcollectd_script.htmlcolord.htmlcomsat.htmlcondor_collector.htmlcondor_master.htmlcondor_negotiator.htmlcondor_procd.htmlcondor_schedd.htmlcondor_startd.htmlcondor_startd_ssh.htmlconman.htmlconman_unconfined_script.htmlconsolekit.htmlcontainer.htmlcontainer_auth.htmlcontainer_runtime.htmlcouchdb.htmlcourier_authdaemon.htmlcourier_pcp.htmlcourier_pop.htmlcourier_sqwebmail.htmlcourier_tcpd.htmlcpucontrol.htmlcpufreqselector.htmlcpuplug.htmlcpuspeed.htmlcrack.htmlcrond.htmlcronjob.htmlcrontab.htmlctdbd.htmlcups_pdf.htmlcupsd.htmlcupsd_config.htmlcupsd_lpd.htmlcvs.htmlcvs_script.htmlcyphesis.htmlcyrus.htmldbadm.htmldbadm_sudo.htmldbskkd.htmldcc_client.htmldcc_dbclean.htmldccd.htmldccifd.htmldccm.htmldcerpcd.htmlddclient.htmldeltacloudd.htmldenyhosts.htmldepmod.htmldevicekit.htmldevicekit_disk.htmldevicekit_power.htmldhcpc.htmldhcpd.htmldictd.htmldirsrv.htmldirsrv_snmp.htmldirsrvadmin.htmldirsrvadmin_script.htmldirsrvadmin_unconfined_script.htmldisk_munin_plugin.htmldkim_milter.htmldlm_controld.htmldmesg.htmldmidecode.htmldnsmasq.htmldnssec_trigger.htmldovecot.htmldovecot_auth.htmldovecot_deliver.htmldrbd.htmldspam.htmldspam_script.htmlentropyd.htmleventlogd.htmlevtchnd.htmlexim.htmlfail2ban.htmlfail2ban_client.htmlfcoemon.htmlfenced.htmlfetchmail.htmlfingerd.htmlfirewalld.htmlfirewallgui.htmlfirstboot.htmlfoghorn.htmlfprintd.htmlfreeipmi_bmc_watchdog.htmlfreeipmi_ipmidetectd.htmlfreeipmi_ipmiseld.htmlfreqset.htmlfsadm.htmlfsdaemon.htmlftpd.htmlftpdctl.htmlgames.htmlgames_srv.htmlganesha.htmlgconfd.htmlgconfdefaultsm.htmlgdomap.htmlgeoclue.htmlgetty.htmlgfs_controld.htmlgit_script.htmlgit_session.htmlgit_system.htmlgitosis.htmlglance_api.htmlglance_registry.htmlglance_scrubber.htmlglusterd.htmlgnomesystemmm.htmlgpg.htmlgpg_agent.htmlgpg_helper.htmlgpg_pinentry.htmlgpg_web.htmlgpm.htmlgpsd.htmlgreylist_milter.htmlgroupadd.htmlgroupd.htmlgssd.htmlgssproxy.htmlguest.htmlhaproxy.htmlhddtemp.htmlhostname.htmlhsqldb.htmlhttpd.htmlhttpd_helper.htmlhttpd_passwd.htmlhttpd_php.htmlhttpd_rotatelogs.htmlhttpd_suexec.htmlhttpd_sys_script.htmlhttpd_unconfined_script.htmlhttpd_user_script.htmlhwclock.htmlhwloc_dhwd.htmlhypervkvp.htmlhypervvssd.htmliceauth.htmlicecast.htmlifconfig.htmlindex.htmlinetd.htmlinetd_child.htmlinit.htmlinitrc.htmlinnd.htmlinsmod.htmlinstall.htmliodined.htmliotop.htmlipa_dnskey.htmlipa_helper.htmlipa_otpd.htmlipmievd.htmlipsec.htmlipsec_mgmt.htmliptables.htmlirc.htmlirqbalance.htmlirssi.htmliscsid.htmlisnsd.htmliwhd.htmljabberd.htmljabberd_router.htmljockey.htmljournalctl.htmlkadmind.htmlkdump.htmlkdumpctl.htmlkdumpgui.htmlkeepalived.htmlkeepalived_unconfined_script.htmlkernel.htmlkeyboardd.htmlkeystone.htmlkeystone_cgi_script.htmlkismet.htmlklogd.htmlkmscon.htmlkpatch.htmlkpropd.htmlkrb5kdc.htmlksmtuned.htmlktalkd.htmll2tpd.htmlldconfig.htmllircd.htmllivecd.htmllldpad.htmlload_policy.htmlloadkeys.htmllocal_login.htmllocate.htmllockdev.htmllogadm.htmllogrotate.htmllogrotate_mail.htmllogwatch.htmllogwatch_mail.htmllpd.htmllpr.htmllsassd.htmllsmd.htmllsmd_plugin.htmllttng_sessiond.htmllvm.htmllwiod.htmllwregd.htmllwsmd.htmlmail_munin_plugin.htmlmailman_cgi.htmlmailman_mail.htmlmailman_queue.htmlman2html_script.htmlmandb.htmlmcelog.htmlmdadm.htmlmediawiki_script.htmlmemcached.htmlmencoder.htmlminidlna.htmlminissdpd.htmlmip6d.htmlmirrormanager.htmlmock.htmlmock_build.htmlmodemmanager.htmlmojomojo_script.htmlmon_procd.htmlmon_statd.htmlmongod.htmlmotion.htmlmount.htmlmount_ecryptfs.htmlmozilla.htmlmozilla_plugin.htmlmozilla_plugin_config.htmlmpd.htmlmplayer.htmlmrtg.htmlmscan.htmlmunin.htmlmunin_script.htmlmysqld.htmlmysqld_safe.htmlmysqlmanagerd.htmlmythtv_script.htmlnagios.htmlnagios_admin_plugin.htmlnagios_checkdisk_plugin.htmlnagios_eventhandler_plugin.htmlnagios_mail_plugin.htmlnagios_openshift_plugin.htmlnagios_script.htmlnagios_services_plugin.htmlnagios_system_plugin.htmlnagios_unconfined_plugin.htmlnamed.htmlnamespace_init.htmlncftool.htmlndc.htmlnetlabel_mgmt.htmlnetlogond.htmlnetutils.htmlneutron.htmlnewrole.htmlnfsd.htmlninfod.htmlnmbd.htmlnova.htmlnrpe.htmlnscd.htmlnsd.htmlnsd_crond.htmlnslcd.htmlntop.htmlntpd.htmlnumad.htmlnut_upsd.htmlnut_upsdrvctl.htmlnut_upsmon.htmlnutups_cgi_script.htmlnx_server.htmlnx_server_ssh.htmlobex.htmloddjob.htmloddjob_mkhomedir.htmlopenct.htmlopendnssec.htmlopenhpid.htmlopenshift.htmlopenshift_app.htmlopenshift_cgroup_read.htmlopenshift_cron.htmlopenshift_initrc.htmlopenshift_net_read.htmlopenshift_script.htmlopensm.htmlopenvpn.htmlopenvpn_unconfined_script.htmlopenvswitch.htmlopenwsman.htmloracleasm.htmlosad.htmlpads.htmlpam_console.htmlpam_timestamp.htmlpassenger.htmlpasswd.htmlpcp_pmcd.htmlpcp_pmie.htmlpcp_pmlogger.htmlpcp_pmmgr.htmlpcp_pmproxy.htmlpcp_pmwebd.htmlpcscd.htmlpegasus.htmlpegasus_openlmi_account.htmlpegasus_openlmi_admin.htmlpegasus_openlmi_logicalfile.htmlpegasus_openlmi_services.htmlpegasus_openlmi_storage.htmlpegasus_openlmi_system.htmlpegasus_openlmi_unconfined.htmlpesign.htmlphc2sys.htmlping.htmlpingd.htmlpiranha_fos.htmlpiranha_lvs.htmlpiranha_pulse.htmlpiranha_web.htmlpkcs_slotd.htmlpki_ra.htmlpki_tomcat.htmlpki_tomcat_script.htmlpki_tps.htmlplymouth.htmlplymouthd.htmlpodsleuth.htmlpolicykit.htmlpolicykit_auth.htmlpolicykit_grant.htmlpolicykit_resolve.htmlpolipo.htmlpolipo_session.htmlportmap.htmlportmap_helper.htmlportreserve.htmlpostfix_bounce.htmlpostfix_cleanup.htmlpostfix_local.htmlpostfix_map.htmlpostfix_master.htmlpostfix_pickup.htmlpostfix_pipe.htmlpostfix_postdrop.htmlpostfix_postqueue.htmlpostfix_qmgr.htmlpostfix_showq.htmlpostfix_smtp.htmlpostfix_smtpd.htmlpostfix_virtual.htmlpostgresql.htmlpostgrey.htmlpppd.htmlpptp.htmlprelink.htmlprelink_cron_system.htmlprelude.htmlprelude_audisp.htmlprelude_correlator.htmlprelude_lml.htmlpreupgrade.htmlprewikka_script.htmlprivoxy.htmlprocmail.htmlprosody.htmlpsad.htmlptal.htmlptchown.htmlptp4l.htmlpublicfile.htmlpulseaudio.htmlpuppetagent.htmlpuppetca.htmlpuppetmaster.htmlpwauth.htmlpyicqt.htmlqdiskd.htmlqemu_dm.htmlqmail_clean.htmlqmail_inject.htmlqmail_local.htmlqmail_lspawn.htmlqmail_queue.htmlqmail_remote.htmlqmail_rspawn.htmlqmail_send.htmlqmail_smtpd.htmlqmail_splogger.htmlqmail_start.htmlqmail_tcp_env.htmlqpidd.htmlquota.htmlquota_nld.htmlrabbitmq.htmlracoon.htmlradiusd.htmlradvd.htmlrasdaemon.htmlrdisc.htmlreadahead.htmlrealmd.htmlrealmd_consolehelper.htmlredis.htmlregex_milter.htmlremote_login.htmlrestorecond.htmlrhev_agentd.htmlrhev_agentd_consolehelper.htmlrhgb.htmlrhnsd.htmlrhsmcertd.htmlricci.htmlricci_modcluster.htmlricci_modclusterd.htmlricci_modlog.htmlricci_modrpm.htmlricci_modservice.htmlricci_modstorage.htmlrlogind.htmlrngd.htmlroundup.htmlrpcbind.htmlrpcd.htmlrpm.htmlrpm_script.htmlrshd.htmlrssh.htmlrssh_chroot_helper.htmlrsync.htmlrtas_errd.htmlrtkit_daemon.htmlrun_init.htmlrwho.htmlsamba_net.htmlsamba_unconfined_net.htmlsamba_unconfined_script.htmlsambagui.htmlsandbox.htmlsandbox_min.htmlsandbox_min_client.htmlsandbox_net.htmlsandbox_net_client.htmlsandbox_web.htmlsandbox_web_client.htmlsandbox_x.htmlsandbox_x_client.htmlsandbox_xserver.htmlsanlk_resetd.htmlsanlock.htmlsaslauthd.htmlsbd.htmlsblim_gatherd.htmlsblim_reposd.htmlsblim_sfcbd.htmlsecadm.htmlsecadm_screen.htmlsecadm_su.htmlsecadm_sudo.htmlsectoolm.htmlselinux_munin_plugin.htmlsemanage.htmlsendmail.htmlsensord.htmlsepgsql_ranged_proc.htmlsepgsql_trusted_proc.htmlservices_munin_plugin.htmlsetfiles.htmlsetfiles_mac.htmlsetkey.htmlsetrans.htmlsetroubleshoot_fixit.htmlsetroubleshootd.htmlsetsebool.htmlsftpd.htmlsge_execd.htmlsge_job.htmlsge_job_ssh.htmlsge_shepherd.htmlshorewall.htmlshowmount.htmlslapd.htmlslpd.htmlsmbcontrol.htmlsmbd.htmlsmbmount.htmlsmokeping.htmlsmokeping_cgi_script.htmlsmoltclient.htmlsmsd.htmlsnapperd.htmlsnmpd.htmlsnort.htmlsosreport.htmlsoundd.htmlspamass_milter.htmlspamc.htmlspamd.htmlspamd_update.htmlspc.htmlspeech-dispatcher.htmlsquid.htmlsquid_cron.htmlsquid_script.htmlsrvsvcd.htmlssh.htmlssh_keygen.htmlssh_keysign.htmlsshd.htmlsshd_keygen.htmlsshd_net.htmlsshd_sandbox.htmlsssd.htmlsssd_selinux_manager.htmlstaff.htmlstaff_consolehelper.htmlstaff_dbusd.htmlstaff_gkeyringd.htmlstaff_screen.htmlstaff_seunshare.htmlstaff_ssh_agent.htmlstaff_sudo.htmlstaff_wine.htmlstapserver.htmlstunnel.htmlstyle.csssulogin.htmlsvc_multilog.htmlsvc_run.htmlsvc_start.htmlsvirt.htmlsvirt_kvm_net.htmlsvirt_qemu_net.htmlsvirt_socket.htmlsvirt_tcg.htmlsvnserve.htmlswat.htmlswift.htmlsysadm.htmlsysadm_gkeyringd.htmlsysadm_passwd.htmlsysadm_screen.htmlsysadm_seunshare.htmlsysadm_ssh_agent.htmlsysadm_su.htmlsysadm_sudo.htmlsyslogd.htmlsysstat.htmlsystem_cronjob.htmlsystem_dbusd.htmlsystem_mail.htmlsystem_munin_plugin.htmlsystemd_bootchart.htmlsystemd_hostnamed.htmlsystemd_hwdb.htmlsystemd_initctl.htmlsystemd_localed.htmlsystemd_logger.htmlsystemd_logind.htmlsystemd_machined.htmlsystemd_networkd.htmlsystemd_notify.htmlsystemd_passwd_agent.htmlsystemd_resolved.htmlsystemd_sysctl.htmlsystemd_timedated.htmlsystemd_tmpfiles.htmltangd.htmltargetd.htmltcpd.htmltcsd.htmltelepathy_gabble.htmltelepathy_idle.htmltelepathy_logger.htmltelepathy_mission_control.htmltelepathy_msn.htmltelepathy_salut.htmltelepathy_sofiasip.htmltelepathy_stream_engine.htmltelepathy_sunshine.htmltelnetd.htmltftpd.htmltgtd.htmlthin.htmlthin_aeolus_configserver.htmlthumb.htmltimemaster.htmltlp.htmltmpreaper.htmltomcat.htmltor.htmltraceroute.htmltuned.htmltvtime.htmludev.htmlulogd.htmluml.htmluml_switch.htmlunconfined.htmlunconfined_cronjob.htmlunconfined_dbusd.htmlunconfined_mount.htmlunconfined_munin_plugin.htmlunconfined_sendmail.htmlunconfined_service.htmlupdate_modules.htmlupdfstab.htmlupdpwd.htmlusbmodules.htmlusbmuxd.htmluser.htmluser_dbusd.htmluser_gkeyringd.htmluser_mail.htmluser_screen.htmluser_seunshare.htmluser_ssh_agent.htmluser_wine.htmluseradd.htmlusernetctl.htmlutempter.htmluucpd.htmluuidd.htmluux.htmlvarnishd.htmlvarnishlog.htmlvdagent.htmlvhostmd.htmlvirsh.htmlvirsh_ssh.htmlvirt_bridgehelper.htmlvirt_qemu_ga.htmlvirt_qemu_ga_unconfined.htmlvirt_qmf.htmlvirtd.htmlvirtd_lxc.htmlvirtlogd.htmlvlock.htmlvmtools.htmlvmtools_helper.htmlvmtools_unconfined.htmlvmware.htmlvmware_host.htmlvnstat.htmlvnstatd.htmlvpnc.htmlw3c_validator_script.htmlwatchdog.htmlwatchdog_unconfined.htmlwdmd.htmlwebadm.htmlwebalizer.htmlwebalizer_script.htmlwinbind.htmlwinbind_helper.htmlwine.htmlwireshark.htmlwpa_cli.htmlxauth.htmlxdm.htmlxdm_unconfined.htmlxenconsoled.htmlxend.htmlxenstored.htmlxguest.htmlxguest_dbusd.htmlxguest_gkeyringd.htmlxserver.htmlypbind.htmlyppasswdd.htmlypserv.htmlypxfr.htmlzabbix.htmlzabbix_agent.htmlzabbix_script.htmlzarafa_deliver.htmlzarafa_gateway.htmlzarafa_ical.htmlzarafa_indexer.htmlzarafa_monitor.htmlzarafa_server.htmlzarafa_spooler.htmlzebra.htmlzoneminder.htmlzoneminder_script.htmlzos_remote.htmlincludeMakefileadminadmin.xmlbootloader.ifconsoletype.ifdmesg.ifnetutils.ifsu.ifsudo.ifusermanage.ifappsapps.xmlseunshare.ifbuild.confcontribcontrib.xmlabrt.ifaccountsd.ifacct.ifada.ifafs.ifaiccu.ifaide.ifaisexec.ifajaxterm.ifalsa.ifamanda.ifamavis.ifamtu.ifanaconda.ifantivirus.ifapache.ifapcupsd.ifapm.ifapt.ifarpwatch.ifasterisk.ifauthbind.ifauthconfig.ifautomount.ifavahi.ifawstats.ifbackup.ifbacula.ifbcfg2.ifbind.ifbird.ifbitlbee.ifblkmapd.ifblueman.ifbluetooth.ifboinc.ifboltd.ifbrctl.ifbrltty.ifbugzilla.ifbumblebee.ifcachefilesd.ifcalamaris.ifcallweaver.ifcanna.ifccs.ifcdrecord.ifcertmaster.ifcertmonger.ifcertwatch.ifcfengine.ifcgdcbxd.ifcgroup.ifchrome.ifchronyd.ifcinder.ifcipe.ifclamav.ifclockspeed.ifclogd.ifcloudform.ifcmirrord.ifcobbler.ifcockpit.ifcollectd.ifcolord.ifcomsat.ifcondor.ifconman.ifconsolekit.ifcontainer.ifcorosync.ifcouchdb.ifcourier.ifcpucontrol.ifcpufreqselector.ifcpuplug.ifcron.ifctdb.ifcups.ifcvs.ifcyphesis.ifcyrus.ifdaemontools.ifdante.ifdbadm.ifdbskk.ifdbus.ifdcc.ifddclient.ifddcprobe.ifdenyhosts.ifdevicekit.ifdhcp.ifdictd.ifdirmngr.ifdirsrv-admin.ifdirsrv.ifdistcc.ifdjbdns.ifdkim.ifdmidecode.ifdnsmasq.ifdnssec.ifdnssectrigger.ifdovecot.ifdpkg.ifdrbd.ifdspam.ifentropyd.ifetcd.ifevolution.ifexim.iffail2ban.iffcoe.iffetchmail.iffinger.iffirewalld.iffirewallgui.iffirstboot.iffprintd.iffreeipmi.iffreqset.ifftp.ifgames.ifganesha.ifgatekeeper.ifgdomap.ifgear.ifgeoclue.ifgift.ifgit.ifgitosis.ifglance.ifglusterd.ifgnome.ifgnomeclock.ifgpg.ifgpm.ifgpsd.ifgssproxy.ifguest.ifhadoop.ifhal.ifhddtemp.ifhostapd.ifhowl.ifhsqldb.ifhwloc.ifhypervkvp.ifi18n_input.ificecast.ififplugd.ifimaze.ifinetd.ifinn.ifiodine.ifiotop.ifipa.ifipmievd.ifirc.ifircd.ifirqbalance.ifiscsi.ifisns.ifjabber.ifjava.ifjetty.ifjockey.ifjournalctl.ifkde.ifkdump.ifkdumpgui.ifkeepalived.ifkerberos.ifkerneloops.ifkeyboardd.ifkeystone.ifkismet.ifkmscon.ifkpatch.ifksmtuned.ifktalk.ifkudzu.ifl2tp.ifldap.iflightsquid.iflikewise.iflinuxptp.iflircd.iflivecd.iflldpad.ifloadkeys.iflockdev.iflogrotate.iflogwatch.iflpd.iflsm.iflttng-tools.ifmailman.ifmailscanner.ifman2html.ifmandb.ifmcelog.ifmcollective.ifmediawiki.ifmemcached.ifmilter.ifminidlna.ifminissdpd.ifmip6d.ifmirrormanager.ifmock.ifmodemmanager.ifmojomojo.ifmon_statd.ifmongodb.ifmono.ifmonop.ifmotion.ifmozilla.ifmpd.ifmplayer.ifmrtg.ifmta.ifmunin.ifmysql.ifmythtv.ifnaemon.ifnagios.ifnamespace.ifncftool.ifnessus.ifnetworkmanager.ifninfod.ifnis.ifnova.ifnscd.ifnsd.ifnslcd.ifnsplugin.ifntop.ifntp.ifnumad.ifnut.ifnx.ifoav.ifobex.ifoddjob.ifoident.ifopenca.ifopenct.ifopendnssec.ifopenhpi.ifopenhpid.ifopenshift-origin.ifopenshift.ifopensm.ifopenvpn.ifopenvswitch.ifopenwsman.iforacleasm.ifosad.ifpacemaker.ifpads.ifpassenger.ifpcmcia.ifpcp.ifpcscd.ifpegasus.ifperdition.ifpesign.ifpingd.ifpiranha.ifpkcs.ifpki.ifplymouthd.ifpodsleuth.ifpolicykit.ifpolipo.ifportage.ifportmap.ifportreserve.ifportslave.ifpostfix.ifpostfixpolicyd.ifpostgrey.ifppp.ifprelink.ifprelude.ifprivoxy.ifprocmail.ifprosody.ifpsad.ifptchown.ifpublicfile.ifpulseaudio.ifpuppet.ifpwauth.ifpxe.ifpyzor.ifqemu.ifqmail.ifqpid.ifquantum.ifquota.ifrabbitmq.ifradius.ifradvd.ifraid.ifrasdaemon.ifrazor.ifrdisc.ifreadahead.ifrealmd.ifredis.ifremotelogin.ifresmgr.ifrgmanager.ifrhcs.ifrhev.ifrhgb.ifrhnsd.ifrhsmcertd.ifricci.ifrkhunter.ifrlogin.ifrngd.ifrolekit.ifroundup.ifrpc.ifrpcbind.ifrpm.ifrshd.ifrssh.ifrsync.ifrtas.ifrtkit.ifrwho.ifsamba.ifsambagui.ifsamhain.ifsandbox.ifsandboxX.ifsanlock.ifsasl.ifsbd.ifsblim.ifscreen.ifsectoolm.ifsendmail.ifsensord.ifsetroubleshoot.ifsge.ifshorewall.ifshutdown.ifslocate.ifslpd.ifslrnpull.ifsmartmon.ifsmokeping.ifsmoltclient.ifsmsd.ifsmstools.ifsnapper.ifsnmp.ifsnort.ifsosreport.ifsoundserver.ifspamassassin.ifspeech-dispatcher.ifspeedtouch.ifsquid.ifsssd.ifstapserver.ifstunnel.ifsvnserve.ifswift.ifswift_alias.ifsxid.ifsysstat.iftangd.iftargetd.iftcpd.iftcsd.iftelepathy.iftelnet.iftftp.iftgtd.ifthin.ifthumb.ifthunderbird.iftimidity.iftlp.iftmpreaper.iftomcat.iftor.iftransproxy.iftripwire.iftuned.iftvtime.iftzdata.ifucspitcp.ifulogd.ifuml.ifupdfstab.ifuptime.ifusbmodules.ifusbmuxd.ifuserhelper.ifusernetctl.ifuucp.ifuuidd.ifuwimap.ifvarnishd.ifvbetool.ifvdagent.ifvhostmd.ifvirt.ifvlock.ifvmtools.ifvmware.ifvnstatd.ifvpn.ifw3c.ifwatchdog.ifwdmd.ifwebadm.ifwebalizer.ifwine.ifwireshark.ifwm.ifxen.ifxfs.ifxguest.ifxprint.ifxscreensaver.ifyam.ifzabbix.ifzarafa.ifzebra.ifzoneminder.ifzosremote.ifglobal_booleans.xmlglobal_tunables.xmlkernelkernel.xmlcorecommands.ifcorenetwork.ifdevices.ifdomain.iffiles.iffilesystem.ifkernel.ifmcs.ifmls.ifselinux.ifstorage.ifterminal.ifubac.ifunlabelednet.ifrolesroles.xmlauditadm.iflogadm.ifsecadm.ifstaff.ifsysadm.ifsysadm_secadm.ifunconfineduser.ifunprivuser.ifservicesservices.xmlpostgresql.ifssh.ifxserver.ifsupportall_perms.sptdivert.m4file_patterns.sptipc_patterns.sptloadable_module.sptmisc_macros.sptmisc_patterns.sptmls_mcs_macros.sptobj_perm_sets.sptpolicy.dtdsegenxml.pysegenxml.pycsegenxml.pyoundivert.m4systemsystem.xmlapplication.ifauthlogin.ifclock.iffstools.ifgetty.ifhostname.ifhotplug.ifinit.ifipsec.ifiptables.iflibraries.iflocallogin.iflogging.iflvm.ifmiscfiles.ifmodutils.ifmount.ifnetlabel.ifselinuxutil.ifsetrans.ifsysnetwork.ifsystemd.ifudev.ifunconfined.ifuserdomain.ifpolicy.dtdpolicy.xmlinterface_info/usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/html//usr/share/selinux/devel/include//usr/share/selinux/devel/include/admin//usr/share/selinux/devel/include/apps//usr/share/selinux/devel/include/contrib//usr/share/selinux/devel/include/kernel//usr/share/selinux/devel/include/roles//usr/share/selinux/devel/include/services//usr/share/selinux/devel/include/support//usr/share/selinux/devel/include/system//var/lib/sepolgen/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2noarch-redhat-linux-gnu  directoryASCII textSE Linux policy interface sourceSE Linux policy module sourceHTML document, ASCII textmakefile script, ASCII textC++ source, ASCII textASCII text, with very long linesASCII text, with no line terminatorsPython script, ASCII text executablepython 2.7 byte-compiledXML 1.0 document, ASCII textcannot open (No such file or directory)?p7zXZ !#,] b2u jӫ`(%v[yJ<`T\\[%q/Lыؐ`K=$[4?Ke!~L\W Wwωk%A#:M)2U%b&QG+xNc}jv&]/E4caimֶrtfΊSA+I! VJ'YϝE\,՘Z&vŕGS&6(nL40[ja@Dx]?`]Sw{Xhe *+x}gSw0?d"2ȘW}xh5nfx[IqƺQtĂ.bs J%7 uSghyu aOڣ:YME2dS2=kړ:Q-TbV؏_uY'߉܀*#" e~Zy =D+%/In=~JDz&?d]+l,;}a)J9$Ď` DB6GHHڈ}h\,ǰNK/<pq5أNH*7<c%|V_ ksX2`Ե$9.ْAAEPхfmfT\5gW=r]m/iXCxOSm8WH5.vh~VT2xgDw m̳АWbN&o &WvSV$ bhoj t@k.7vrѹY"h:gUID}V&umPKHX.h7W߆#lzїI fye-P\"hĄ꟥ ܪmnUfk[JsQ!zDGJ j#OlL$E$wZJ()gcMm*,jkf?H`dXD(.~2 ~pMшLyg&wN4_3z~gy/z ֧8n:Dj0$gf%^GX"֏{!MPE׸歰&h4Hlvbs@e LecNjա (1VԷ=m~7,YzM08VTozG=O12@@MA]+r|-MiiQ{IO t?Tdmr{~1Cs`d'GtQ7}'X0uO?Yyʍ>-32`bbBkQ# #TTwB_(HS2Yԯ޴*3~QAt5N9S#p†fUT(/qJE{1H:J9x`#*% sm?ySt'XwP<-%|rErYDHDݠg}o]6B/նzt`=R*l?hi(2i6Tѣײe SĤV؃2sD |07)KDWrX ڗ8]eF'g_zKU^F4}˞=H@J;'QZ1:aIJ И=2+KvbfŔ<*ilYjHsT_id0jdŌGkGe< (cH>|~d g R>0 Nو$+Fdu2. wntK[xaOo?څ@sʢK )[Pp_%$Ƥ?g׉E!HҘ^{-lTiaM(i>g_or}1M‘NL@r8ͫX5'ߥZb ƻMcΚ UUH[C{'Q8q~:A-&6iqL9P  WkY0=U]W͗rNM 8b_"A|lw[OuGr) se6d1Y Y<9:{isoLn1053p=RRMa=1o؂ J۬Ϡ67 -QL]OPnRܒ拏e4CG__냘=5G6t&7}XF@ǶbTp('GM#D1YCGhd5B dz)1WE zDg,i͜,~0;3-h1Knv+ e-fiݍ]~fbyOFcs/ڈ ;kǟ 2xz9A);I#P+WIԏ/W0S &Kvqž[. ɛǽWksɐN]iEoLBeȗI1 Fblo/H햾KnEt"8= wv'`; ѐQ$ b_ۘnnvN3*acBQmv9;S~l dEM^ 3>6,pTe$QZ=bq]q٢2JЀQCso\fHs&o0]oVLKl?/m:ۉW#:jL\{mTOL𱖻>l}K (*߀AIMUx j_RtR ؟329j1/I>beQjI5F\R.ܵ:1}k9K'sy}[t' $q,QZwDw w'JihpÍ?x _5@|3ȯ`cI >яrA[ɲzmz榛ܾC0*nqhmL} rCmܓfUB vp2 +"LR_UV 2byONgQZhB[@+kQz1@[yCKo6`; 93Z؜s!䉀)CwOj{uO)!^kM 3_,9isk|2ĖM/(d4r}rH㷺G7 ~|74#+K7_aOҝV#Riͮ2)–#/b ˈ iF@4<_)frc0i۸a 2wyh%%mU`ZW.0RS1}~xb?J~⢳cQ+Ug@0Ã|7jZki}-=Żͅm`f* mG( b 4`(#߄(7o(bac,-9YwxZ_U&t9>Rp .g l0}߰8^yU9 Н\Ms"JHtQB[o=mK~Sd; ؞T"8. |oT eơQ T[p5TN8KoEbf3/YV-3 f_LҡFPnbWۈgcTOwYпvÁ X>qj'jƻ7 F5s(VWw՟?g6.?@Ӵ$=L ~*'S~@"m%3ZiHNS7UMh×r5Kokڡs!GJyupbmHP7hϥˤQ>7)XEk\¯If =,?aS,EBPJٓU mUBc(H `}ڑud"2C#ztbF%rEMAyTG01buں㯕L 8M%2Zlb{[F,(;wSs`ielyUtp}n|KNJ%*Rn3 h̬V<7Dg4JOh<x[%w =L-Q3Y- * .-" Udׁ09y4]۠`L:ccE hHsW,iuh[a;ʘ< Q9G[B́ЃhU@m#s]Y.<9ΉTMjGdp^pR3+[)̵އSWTEPA׎=B8(?ߏ1sf.nS0tdoAsұ`NQG;ÇcۈH:Wu?8U4KY›~Hm/**gwmd.da(&UBkY@ v9l+<6Tya(kD?8y%+0G%~LA\XY&mr1E@'Ho:85uV՗О5>YMH5}²9?H.+ f!M+Xd(6fF9h׫vHWI)AIr4qA(Þ޾!Nbu?sszz`V§]SHh~?tdWFngF<$U 0?kd]y 89R_S7FFպꙏ 2Y9D*$ קӢU}HzFp,\r㛴#,J'nfK 5aV4oZ1HV3L[ %$J4E56ߤ(ZнRayag^tes>+( Pz0<4i"d槶#-bX8>z0KP5uEmXvFF/Ƨa{u~!tg`k5uTA2&E?{|>Oq8ά&aDzlFyLN\t/q@<}hiNzrxCf:ꡬ>6DmGP>, 0Tϐ pGЩ;EQN Fɵ_jIm6 *#Y I/sС/YW3\{ΆTLJF]Se,ҊJ]q1:ov{rJJSqh:rk!Z~J vdRȳHТq! ::O󴻼S3{=U!ٓ}ʃpUhW |EnFW⇝sڻl 5!Ur hYA"I%Z(^sRF*Cv\RK_"\  7& Yt{HWZ9E-(xh&n0 nz?kaУSoV*Ωy?'\ /h\\'1(. bä\6k @ױ@׳tJծ0H2K1A1r{gV@b~9fw:kԟ^H>JnJg w 9zns퓾z8\&|s|B02DL ﹏yk\ Q&M+"t6x[AP9Tse 4=B}̭VG p zZKD-2E*`؍4{NЎE&VOc\u#!4͎`v}'edd'S89;j]3 N&"T aRbÏe9cp\uCJb[r\z\JVaP.Bz7h:gfnп(N#mGί )([ sd\M'[uӞ~E3=sI_he& ue*>'c|PbSY9N;E3~}%4$`y~ڛK9FA\Q~V(q1XF:.3yPu!,ȋX4;Lv_^ C#:!҆ώtp$2jJ}5]uh> K{O1d `y EGl(/mTYzZ &GDPMh#zj@; D&( Qegf/qVuDV%:~F׬HfhNsVfL۝rG\lz>VX&Lz4oMج{O,])^3œt:M|Y {fnDjmڴE]k LGvʕīm}@r\.Ԝ=uO"{qv=3miܣʟdfӯyJ#Mѧ^.Bxˁc-R=<Y!k^<,Uuc"'BbjbmP ?G/T^ZqinM$/=i̾Fk .W|hˀhvy> Jmw0PQE:qZ1^٢~m4Ini^!Z]^ R:ϖ tLSigs_pW7BNAG&h~ګ¿3oiOQVى|_\^%2V54|@Dm=Q^T 1cȼ⩈l}w oV놌ӣ m SKAYYw9- s,\- oQY FLBC4$O@nNFEz6y1Ķ#@Tg܋A_+w\x+vRTU#Ǣ:naY1AMБ w^|١WX]yd?"k)ӔhV/O^i!k1ގ^C<5aK;j)ȵV_ NL@(,;*#9O+9tkD~龡Km'pC~N}yeI#6)8^k]5d| X|20udu<"c!_1.5\q~WHC (KD.}Fo3qUzЌ,<`u1 Pc' LMXH'A(&X~ __3 -P8l=n^r(=UqAr96`@<*JξWxba5uBiR۴ZN8UsҲ:c`bX P4C&r0#_a94SʂMv:Giؑ?{<bN~L#5)WcKyy)3uS Wѯ5$^ !FF d oZk]9ppDFBRp=EBe1zmwNrl/p6Z}95 F̻rsҠzߊݠ%J9g2ivT9O|42?TH^| ^U0)*M"p*STB3j/e;yNepȮhi]_u& dXc%ڠD7A IwVO-8/O;ǵʮ.,u fiKH҄ք燜MxqU'*q1dޛG3C(H_];9hK7>' < $Jotl%NsGX"ָ3V=9Z9a>G9yګ ({BA1¿]o sykP" NMH @%o}Z va|ClT@I3:`^+cj1Lb^8./P+$$䊅"tM#( 2>\&:qư)cH )* Дl A%udN8qoJV]5>^v Puϡ5 YV(@V+y(E,Đ`jzHQڮm"O̫%Mx}+\!M#^?0J Ey<ƼҘWn3on"rH0KR0G_0V˜W=b&wҏ/ ~^ 1JUwJ Qs.@ eYy  9wp%?!hLL,hOgnYEY /bKLV'ij{xMGMpxQD1 jE=P*hKnt*^qŤ:vĉ%YV镺GβXH|M`mNW.~(5I{;bGAnq,8@NswI36NWhmA naA \@B [5@Ry܂GNaAmX3'=`]ĽnQ * ̼*JI˚H"#C$Q(C|i\ݚa;TL3--OCnj4Sj t8iU)] eAZz'ݐINY9`mgH{ԏ(fw&J%Š_*kO2v]6o hZC'a|*wWF gK?ADyG)5 XŅpõpMY$?}c\pl @"g{FLU"VOu\n[*|X'Qf-# vߘlvjr=`h^<dC+/@;CGE^sK+I+pxK@U 1V=kft*|p{ d3.q]ͽ.E20$o!U1ZVp#Sy\d<]bYδQD#]EAu5>&Mi&xWP5F] 9 9`4=# (&VZtTxa1I[.( w8LgIbX 5\{xi/p ",yؙo]d,oN+%I?5oҠ'j[{u!-,-<,$~HIR͒#u䬤 I_ lYB{ [(T߼/ᖤW 樆:[6S˯ #T@$[m8޹hkBfޠ3^M5ӾB?g3rW??ްSԮdW,\Ǥwp>fU(&Q;ȫ<#'S|İCTG𩯙S$Lq&*梂In⽧`1 >Rf%.+qޒUoЛڼ U6F:pLх*Cn[&7e/D腻v£=*.xCcG!gcy$}8!+4ii 5.ý;c0z ʢ†kĤQRV^9,uk{r ='⤥G ')|Njea*!D2䡩Z!κzN?对5 ʈ Dե^*gQ tXԽŔ S>f1F+P&s”I0O"eYs> YU*qsLsmm+0ԉeO]qVo`LVZ+%#%F$̊M3i(䙼k#}+XXj'O4o /͋!E0`&6&\ݿg1 Q7ar]Ϙu{)6qh+5qI1lNrK ^Og.Tܳ3y?_MDV>[ )@2jO7_\6ermek4 6ս{N>A,tڎV{=/*${g)[/a#aOCDy` 'OH!k^emz]ߟnr#;D2rI =S\+tZYRJPeL!8*{VNgQŅ.b#:Ku5U'5nZ32K5D>05l01M]c6U};B|;j᝙uTp}&o}G`!ձQ}`TTJfCm[ZF`0K(@WEC3!K7$zZqcvw`{P|.b%3aB=;㳾i`[R:*~6 |L' 6gJ8ZSlA{rsLDGJn{P&1g$@/Q,pL= MMGT^*t6g.B %Ź9([w[jԈEe2X/ۻdb7\-vk.ב4?\ԻӪdx}w/PZ>əݥ2C*| ڱS%ᘅ )+}5Q=^[A3!H1`R=4cD9<@}4iiLGaV'4pTO;gͽR"'#pLgOn7Bfq ΰq~/Dp\%٧%7+8~p!-I(KO]c:>Xq>2z s z1$)f+Pٴ'ߎ*M?Ssj#eJ v`vŵ3'7$i\fc]k|f=۬XZ ̤N$@\?E-m8'kbFy1e;m2`mzDՁox]L{ \MEb/`D 5;]Жvn3G9ڀ?>f wx aԏ2G@p‚ `Zl2T25JnZX)gQ3C6݃$GzԠ|ـgjP0=V\t%B#Ķ֟>42ތ}h1dߠ~MJsVGT5ZLvg+>e0WN=Fz= -oVxHtH@'սBed/+roFw`W1a/Y+6؊#yPiPP]('3YJ\\5D i{aUs^&%0͏M@_Ai?4ʊ ΗvY(^9 xfYHwd- ^h /Z߸MeZ2с$ocN,,[-8~M|eęGJv8dot_$e8ׇ {(j/+gMn("-IR; 0|ўZxpVc̷T)fؐ"A\?Y +#&ʬ3勒UT 17UkԀp-~iDeReJO DGTA"EI_Gf+5ˮ-GKHdrj1 Ca迻z,LPV-ZI?-d[)D&x ǀDJX^? Tv (3@ڭ+.g}TU'(_~}NWrCB`)SWOL3EnOn2emvc~{~k }3O"g{ZMD;n%.WiJ.&S7~үPB 3@Te  6HTRy?AH4WWן$۰M ZUh1t'Ya:1 +OʂIX>k nOE$DR$V.pAIvo.2p6xw֍æKN(, [ }NOJIKXw`(8_ fOFkC퉥SNFc/lvub&]U1;]>Sy`tkYBG"ֈ2&/Y|-QN$1?+ZJ 1E#<٧CrĶCŖz>[ /ܦygDS'Saz֠jImy|FIF7=j3f(Kr9* o6Kӯ+b5Y1OAS1^G~sHks[hTe"O_VIm0pwI{1֕ h_ۈz7+CR>;9brڕO)̰IʯQ+He2R`ʯ. ld#TeoRz"@0N_Lf +UZ;$9/P8,."u8Ѽ)@>{!5BM nxB O' ՔA_Mn1vOنvs! e5C'Ӫ9]Ӳ cD Jyrjqt.!KQ[{l:fVR!~Bw =ծ]*Lg[]I:$@}8W &SfxU-ˉn΅^:3/.d! !颛!ψ+ Ҵ`cSXKKűN ȮRIenyEB74N~z$.T"04nm/hd)\"y?^C+7Kdv+/\ o2)M 3DiEm(#:'˼Q'9~RG ;s60.6SmA''0aE5SאA4PPq>E%-Cq2{>'?$VYj9iWiNGOG<)g@:CLiεE:B" =Ny!x"tφ8'Be_PT~g`Mo aUJ=BYwRl_(xH`ځDa3&;m";}O4S+fꔧeདp ϰe+U0&,(lZVF \dh8L75/#lqNa`<攇* iQZt^+\50~oe듳&DceIIuXV'3t?zje8.F+f9$?T*/L UʨfV+*U; J5?arWzp+)ۨw{qkcݗB55 h3j3=δ8H^Ob#}o 8Osd=Cڴʼnte]@\H⽄1r* X{$k #Xs'w{g&8#rjwٿ>o~d@P]p'R6&?uGR3j-aMeFǰGNTbYX{=t3WB@ޜ;Y 0ʀqfBҲw bޟs흒fg41-0 vEc߬hn}Zj/ZϞn.7~D~jg~lrirޔ/_kBn܎iW,ofAy45jRߪ߿`{]37oBړV'&t8-~^M/+"Di~@u+銛yg] c{Gc @9A亐)|P]aq:(h)(`gJxPlr{9GHGKGJBdIp@NcdaWihd|컬haXZ{@T&h27׺SÇHdKȭL1Ej4RoR6]n u/`cŔ׌YHg+Q$Txl[~$nThD]W ` >Ӱs¸OlDzOks#KPOMOe+BOc:3:Ѻ7_|F>*_^*jTEW6 9 BbGZl{B[؞qI) -!1mbSB4fepA4S ϫox 77QOz;91*n/ВCXx}leFXB{Vüq_6 {r4H'>!#97uZ]+d*?QB 3>a>MY#} Ze,L:g0;Ts7|A@{^@=CbfoOmflW-4ʽ-*ɨ ϹyǴ!HʤP#Kn.zf 4T&c3lJ"% |Gi[>U?9%_cAWypEԉ-{UiZKtqCe/<\Ek\ x&Z/8+[gߒU%YVD3| +~+HKs->nxr:=EW>I7P %tʹ xg;MK?9;:$nƺ6gS|?Y,.l}c$1 #d@^٫Cd:_ 3F>=`ّ#{zo ?x< ֈnvD5Jc$(Gu-` <׉hkjm?4p;jYm}( /|P(جMYoG8'n@5(Jb]߲cKLhPGSi?q yGtˆ4D@FgX>ruzR^Ʈe5"#a oX\[ijeVG=󛌙2qB 6 f<$  =Ds|y%#[DJ6 <7bcӹލir<ڐ_cn9=;cW^5}u`sgzaoIIK-!Y2&(Aݜy;wI<@W 5dE\m:`.>dz{7:q_6ȈcvjuK]%Ւ0i;Qd(DfH̩o;r~UkXixp3MߚfW_SPw]RI"` t64Eeɚ\hN|&z Lqrju:Qn< mC@ۛwe?ÿ@&ڬYk.8j!R[R57?1]4`4xؔ@i} G6 "6e`6Pc89Vx;=!ɣXK!ֵ,|yVN΋&5@L†\~`e;@(~ۤ2Gp#QIB6GN\]BrASSXj,9},d:|/g >V4 HYQ 43LI%TPvihc&͋w W?zBNe{sYQv4$^@; (TiGͰV!>yܚE5&6YMT?{r JRoQV1Quq*Ub|5;['B2m6;Nf_j*On>~w}KǃsznIxTV]oЙ@'4pfe.jV2'zDyb8Ĵ'"4qMBH;J9.\šZ.sM[&#G WysU/ڷ`mS+S|K@F-JmnEC}DkƋXA]ͪ۔uW1|W j\'g@hJߕq%Hm~K s邽|bdpWw99Z >R4.}tM=郇Vҩs`ܒ#*9 ]Ώ2ݒOb8DW!/;DiE|F!Lub1ǚcBaib]hzi "ر m1JxkDʻk#M)Jna!4EHe:MW+Ԅʭj2A]KmRJ+‥+۾1O*4፪*sd'pV 6>OiǷ4\ j^H| lT>B3wZq><.13!@;Sn2\c"I߱)%k( ")k;?Wwe~Ә"\Oʊa!V> l6o伉bq;TasWed<cdI1B8*O7NhR$_MnD@e|eswk\}4j04ÎÌG>+s",垹akQ@PT W8QOr Yh_Ǚ[: n=yNHe+`=#N.t\Ft@ M}"ek{+2n`ܹ=}{B[V c |Ql.]>7CSmb~V#4ά'gq_ c0(ji>T?Ye%t) u09bi>~$w"k*D\J7{/#ĴyS4Et>Ī-^\[@E_[coڳ? >!:wVS3}4YXԳJޛ(w7w`cu `BVME-r"|+D1KbW*DnE ~%BDU٪Gql]-!yְ$U+j`aD۳|3l)'8YthڧI.$F^ ʪ ҃}Y,x;FLڒ C|L@S<|>|H5X9cJO@@;; Bwi Su6])_H"0>/%^򢶉Zz-Ai!V @> &zl5MD{"k1q黶>64Pk.ccj`(iۂd {zplQgkcs.%(OoRתN)9A:=dbt̏.xuM?ҋJ@QgeW]a!3DAZh{FmpՆ?WZ BȡK|ƾlh뫘T3f'o.2z'$&3GWg1P B9&Tgt–PyN.)}X='3td f|^ @MlU}V(i>|?+S$iG&fVi8"aAdIzMo~~ ǸUqb*p~|?i(6ھ˄WGmiӅ&8 ~Fߗ*8=/|ڲUVՆQZ{8'UBAa9{qfZ#crDox7Zte^ zExJ8ӕ8c}L=팾2)u.PeU5+zDB,ݎ\ Z,42~!3qF?-é{8re2+MрۨVcTj(>9pS&ߨ۴L7 {:oo|Knt\:x ^YIy}Oך=np1=jhT1/ B"^@Zu*ygX<ƙxdEgqQ zmXvˠq>~umW,v}D_# ̒4zm̨~?w"'RgRCfzVZ$ɣp16`6?,κ%S{Z}jB feJp~CB=Y=u9Dp'LTФX tpTXoں y"WK=S1IGV9&Șk->MF$7'06n8bOC-7~1.Gԝw UׅÜc/6d" {'qt%[+Qr/ xj͌4Ç6lٔz ǦJ% VV8gB4gښ k)`׶`_ ӋYY/IQ7W{3Ȅ j"UǁHi]#2[fHYrQūo\c4BzͧX=1Xhy<y٥o0><<}Tk(l>GeHFdi!a&(jJ9yM_,I*TT. 7b5eC+BM+$: EZ>_f)*؉B\e}jnG`9f)p;Dž`W,=J$+*&N=p;7RWЧ%mAֺv q,%8NWd |JS`Lo32N$]Z5M7*k 6:S-&k%2$.Odn. &^BBʤUY.EYt^4gjXCC YgA\|r S;+Ә(4_pYEăˊK"NΌHZufcQ+f1`wWFK?dwP ;ASWs}mߕ#a) 1䎉b"RTd'z8:< 'F9mU0/UAZ-Vma q# us\p!Y=Dл'`eZ6˨ R¡8Px ^MHmhX{d\'.'̨bo 캪(^پsP1g{x@b [Lz~T5EѨߖwӰ*j8~dn=vS.i.U}gm"N 2N#"Sb&o%!q0w3€-'~s #Y?˹`eObB`{NclS/L:,+JS ''Tn!ԣ?2.f<*E(Lmq(Θ&8r5T6OBVuuGaK]]HN8\1t3b]_= i8Ln&>)m퀳~CnBнNq4yM?Mi3L"+g=>x^ifovThە f_AH&l,U'8}h G 5> QoԁeW ZAQqt }$*IR"$O[Iu]Yߪ73P;{$› g߅{uhةUgAWM<1.0Zx*ـ|:u$ЖҼ,C!X *m`\0d~FۭXfq |Lo^€2 Ϡ G0_m[38wATTih.M9_-n2vh{{GS}7m,YxBgE_`0 ޳(UK׬P}0y^P r%@N⣀K+q@7+Ak[d\O"p{ayQ2$ݏ^jUX=Uy ɩ::/wEeʣ&5gf~C}s؅KvQx>D], ɖv֊|LSoNˈr[ 7eY߿\Vgm>U)OvIh>yύ\ƩI@|]sGA5#;~`ic㉋D$U p%Wrak(G^# NTgʣ̬ zȊL.K &љl@f,S&b㈽7V\&<* nnꈄ#C%ܧlSU7`#+iC>SEPxs|`14Qi.$Xlv1?zWzߐJkc٨ר(f\{Eo rɿ=&^ִB͇ /U( *Qr6K(σP9P \Eh/I߄Vy_e퐢/8bkPp &3zYgA Ez˴X/Nc)0B㨟@%By:=zp+,9?ԫ6 )Gi,2(_%Ly~ x6֦N8X09>1 ѝWU֛݇e&85{F# ]F@A*;?㯸KHC3m)h?P~ώy/Ermw}16~81eȁj?պgJXϙuCBRMųIcI@sz{KucQ y NmD}aF%l^"S&IN1;٭+ˌW 6x dmocz3n$_s<MjbB!p'OK3ji4AgI77i |Tn e#;/>6eQ3k5^J["+]< {ݢH\vov]|J2}Ŋn n[A)ҳaid;c :IlU]](ysvj!!LJ~xۂ˧)jN|0 |?P7?"V&s"YѨ|;N 7K$Y"a{!MTY ڜ)'cdm 9N qxhiXAts;Cvl6wBg%T]Ԇ`^Z]BllC[]cKJY&u|S0}NrR+3M(f|M>~75—7πuNy677tMۈ~\ޒ뢛s;?\i 0GflDzL0L͔ PKL3 Xk0jc8rq)տ[=W9!^fv` ļ!j> Yx>}*]YŜ.p`33; F:ΐ6pP_ʯ-]z&Ʈ|9{>b$ E1=A2 \G($xp7fs)]$뤃NZXs1* KRnSN)dOTѱo J܅R6ޥr;æ4HC[s=ASLrI _Yggh ssYlaTS}<ݕF~#~Ӟ*Ѻ)%^ ޫFPsW +ӽkx :جo7Q31]/ #>~!A\;R/Fc oEq2^hjeyyb7̰M%{ާ @+±q3w#.,5َdt&7B7aLcXzkS}|`XfӮ`H[-=5) 휹7&2X[ bݤ,VL[FD\ T, U Y4xo @=y<]?t@P<ʸ:O9O -N `ozDKHF>,@ C;PO*bSz~0pX1Fr`*#/\+Z_L2Z:z±^B=[#'nalFmFr7%y:<tgLx鲴| PCo5Y+ˊs{gP߭Z5D?Pbp1ݍ w\ggKANܗ\uNq (IZ"BUtt7eq.X!X7aǯJ|SGy}Nt旇SK eº!1ṽ31z|>XZ_b^n|ͅ/|Ӣ:#1ѼHJjdת=qXR@KB=`[ <98uU|qvtZtvvsH@.Tͺ0P\W& /V fJi0KC\ow p)yyF h9n9-'*ZHnoPgA/dy׌$PLڀ4xgO G (Q3%Fbl;S#m89DT1uwd@Οtb`ojcxBSɤ~ҷ+ߜ骇59e_yg% W~ 2s^?ğTX,BI 7ZV(s}TAC݈, 2'e@AҋiVwS4ro, DS9it3$jUUzLe%R|`-^ZcrJ ;:Sgqjkq'8R:ԁY(}ShGʖ6O#ڠE;іob@'J` EFl"8KSmf) :nۗ +2B(`X&#,L٠ /i6/YI. P[)7 E.uA7%V6L2Ԃ_i,{Hwcޓ2XA/6w^8lnənXZ\vIvO +fUDߺ7RZ۾FhkLrd'2`W9I)e=p_2SxEl|tI3`@HM2"5Ŋd+n`&9C@2W.dX JDn+orzZ{~$Pr.or^$Uiy3:;hִ21]~(H( iNCgbAvmWz \;0|zT,SK7m{"ZR AbW5j\}f+U$^E d85ϲylęel' }dG+l4h"O-;'yz g<)+IEf wkg"(bSlFq Q_ta-߃z|tsށ&]ni:d po1Hxxfh(4esHEo3`Gdbp0 ÿ4JX.XtetZʘS2'@þVVA~$E@ yAz QΑMw5t|Z^-mXuk8;tq̺L\ 6,RŦUE~50t{R=|g;&"@쾏 1C$plbTxmAеO:OI+Qn엧ͭLjt$)QXJ 8+( s(7%~ P9@$qJzcn$t% X0m.;=P^8D)0K8Cx4_F-EuA(W[H10UggrڗߚT1/H#_ߵ~55hJ˚ȘʐR:Rl߯8]ԝUl`a Td_5"m2П0tU61TqKŋ쾨V)TaCf5vA1j [y DHEr.;Ů),R:pgDtOVM,l%QFɆʹK[X_EJhD#W ]ۅjP٢TJaQ-Eq Jݜz.#z1DW 2=#FYx|%8C`Eye̿NRnfLpP3 +I98^o4(FQbxm-),*= 4L(lre ]v~XDoEiEsU`/sɧ"K G&vqNJ5>b4.t?ytr;nRSE=W}uau7'M.V~\L27q`DEzJ3*9 `Ai *5-C3Jr^"% $yo$ɜ 8YV$s*7f|/["OIR4Y+]p}x\.nNA3§]lдt|rlzx}Lξ m⌄fxrH=3FPgSm~0rۃׂ>7 z4xQoӿ!W޹a ˆ*7M@S? (RMy@ny Fi'X!nJ頚TzEYsHŴK6pO `O3c g8R2BN]]tOIk,08\S=HiU=uK.8E-:pit`\/c\r?Zj.ӻI;FhL7|&ξB o;"m OQM*%fuu22g[;QSˤ~I&YS A/m>amg:8ERQzzU/Fg0VeQ}/?).w{BP,Y_Έ3p"tl]JYg6s`3W@DOHz8js$m)G3yT* Y ꃹ ^Z+]Ö*9ьߨa@otI=Ov jn"5%>#>*fj^XY|{DdFnAb.H6uU9;e0n(AF/:qǦNBWMLJ^19iEBrtJ62 YoVk\Aady=}c3:@SF1rh=$E<ŠgDETř,G Ktu VQ&f!WaԀhVY+zeaIlTӪR&Qt/2L/ Z&>?+GI3#%CY$~v9yC+Gga g"F'J~4N"> Zǟ-irՋ_e+Jgϖ2\p"ª3+l|'7l\MЄ> $bVӟ`J> !SmUאBi nw> R2zM6'lG^L}zv1Aى0.r 5v 㨠qRjL&\ UðyH`%-rDL:+\k7 > &VD[Q?m^ WΆXqפuf d#]_yt4䬿zÓ Q5Us3~6Bvw`]ϩ*qV39`u #wANV*\+a<Ҟov+'gq:)>ݡZoߏ{J ѭebA)c>=hlݪ>bhpiSN{,| M\C97zɯҰ8izyָlL,_$ * ],'9}@HHWQ" #RL+јLIg FkC?rSw zP9. oYzDzmۨ7MET됰`&j`H6ANGfGh9 c&{.O_lxWLD>ȝX[: S |aoq "6T͂ZqRw ,sK표7DO$NqGE@<eS(S?2dqt q*ǧIp W9I{0iG֣4XNf+QӱSmnc/}!@ \zOudfG?ihHNQ'yea  R7H2yJ)zf]t;hG^jqIw:'lܻ)TZ=+H>ʂ/QQ xLx I Z}PUHjvשea,2 ˙w<4yG`\WTHE@ߊ6?8/ҷ2y0ݨ|(~,>hMֻd86ɂH؎GI^S{UVao94\[ZkꜱO`ǂ;nGAUQ|4 Y40 Iٕ+y-FӈH ,G9%gXB/ܗ">ht0(WQU/]`<֕d`p!l !gSTB !`Ϛ}gU!,$mkb):+vF`MCBVDXytZQ/Cu R؂ O20IfctW I|r6aLul;GLIݞrnL~?y(n?Pt6N ^^$nw-` "|vt賻yUƩ-â `Q7k_\:2Ö^E_הy" 9#qٴ!e T mk*ec+h ;;\Fݏwy0j)ha@)`l{f}%n2@ 7S&Mg4 AJǮ{ w:386< ݩPC~nkb* cL#jz]\ExˢMzqOqrȤKv#yK?+!t R(5SAޑ}FRma<*$3gOd0xǭӬj8`bߨvͤ\3ت>L-zvFBe/Ql[hb{) xpɅ➼F&cٴF鼭kFjmeqcbK E*,+gϠ!!x5ʑI@2c "nlķVi `* 4uT 4Pߘ3zgږ0 o?<21a""_vtU'h\mؾpTGƪjk0c2.dӭ[w'?Xr\Ʈ8vqɏfeO6a".05k1W㪄faf^[v].࿷;AtEաlzW*;./o/ F#qrI+=7"LZ|d/D *4r8U ; ;F{j8.XݪwO,9RY-=9:\(WS hBEt E8<EB-Z@.C*p[x*'(+U6 _-M3YbDGm鹖&5! M{@:t/:DaȎ1thP32g ,deګ6!R^::F%N,'ӷ27{#$o/ϒsv#2?rr:7K]lDv<:5mתn Y@w cqKl4rꅞk㻐̃ņ2 qf xa }p%63R_B E&q?Yn(d*"ݜW 1҉Dm yuY@kixa˸:uRxךS-ɵ'3cѴ׾V⪶a|m)AI|UR. ΦHT ȅ >̇8^ Q꙽oH@6y fLgRBbo ̷S~̊;ikt\?>NQ$uМT;;#E"ւ$1Š}$}| '{2@J0G+ Ub^i0u2ǏLqՁYQ--fBpq[%:AG)xإlZrv7&uac w (JmoX%ݚxX@׿7D]koA=1/=3(„"j\"/$Ǭz-q~(iCcHNDw ^ "(9q}{Lj 3TΣT/&>jxrÖe*L!R4N@k4P=|lAtnwꗻ)ﳨVסM\'vBdAIͲGZTfU\xbzO b3kaCJA5-Q"]פ ׵# jY4GxIɟ+CƔt˒@[fgPܓ<[_fD/$]g̵OT(z6XE~G5웪Qˊb6غnpTc '!Ǣ[SC{˘.^ͧShs)O[Y`pBp6wHrXqyPTU,S/FT5GWF=G "2#)mZ&oM5Zێ|)ڇb*;8g;i=ˤV12%#[c&Y.󤪼p;>oΨ6.AY]w{Z+F;삀Ī22G8򽜽.3g9+Y&~-ЌPc~ǚeVG:BH3A7+_q'UwݤC?W+y5#0/qXd] p9Z:PhՇmk*6Ԏ֭VEMc~wױr.{斖 uD"iXs{^ZC7LM<,\ !+X3*fl}we2gຒri֖~IWT p] erK#/G ZVi /g*rվ4 kpuFTt5%:ןBu!P-1mE :V5R}`u,BTF'6~{oRNZA@X>n E& 09j"}_9Ux( (̤pyߎHq6l[LxOIȫpb;}s"޻˹I_˰dR2T2|?Ԛ:JȐ;lӗ v/.&I~ˡzΠkYrUi}xl|j!vt\iLE(pU N"t=GV>;[GpNh{v2@5j2pLȨS@‘_˸H5/[hCO@u!G M0N,8͌3lQI9lJq (xhF?[1h33 ϠQw,e_qdY(,mtD@|m~ʶ򦣬 ڲ­ѻ=wKNBBGHꎒcut-_l@TZ]w18uL>qU*J+`F_9'Yxb}ct#aszTpL*Jqi7n쿝ɅSz3l_\B-/D:ZQjZ9 0&6"P<'J`\BI`-QrVo #%ʃZw+I3R5@왣1K"w(;8ٺ%8xU`kL*j2 3wfN81Uy徚Qdnk\>h9G[$aR2Y_, rmҷokW9´@?Ӳh=PcxzϦ|_6[[3Zu) sb+sT1v_9 0@DVڠv'싄TfԈ-98txD0w{C*M.&QkNl"WFG,ߊa{޵kKU:dfh-= p%DG lZ4B?V_tF%脆4ZfS?dVJ2W1Gk$p_R(߲ ?[N =U $^*uh,dhH#~KDJ5rh'8:+u+RA2lmU۹qT׳؉w(hS̐EFxΞ>ٲiTݢ~bFKŐ `sX]y *z؍q t+=@'`CgnGGWJ2 MVanj,_Ī!Сo Nq5Am6z+-mטIX| ,H@!U,AK2 wdk:4~'P "0B5bjyP0F,6GyPg Czpk/̱lDd!8TjD@P"cQLEMWɧs~o6(5)3 ʽ (649(BFfXǻ!jXVD:Q*ag X _,&* c" "b nC@jCd'*ϾSfY`gǵUkP>S#,b.񃜆$Fmd'GM\`XJٕdXKt{؍U=#'\Od7_glo,2>7,u)eX{\Oזd| 8E##hɥR7X>ۇ+!JXDTcM}}N|fLj2HCep` ޷G݂S Ԛk/u|g4#XVP#} FMܻWOdv;@ Jn\df{kP\Pi-͇$0ݗvI܋_%f / <$(Bm=t)Y 1(*,mb w QpkW1"ʗo@qdWB͠%Gw>sMӥV# z?C0KȬUfJ|Zsn\OO֬Rny\۟%{:Ҧ_1./R/uH&QPh$cӃ/h_@ >6Z C]iZLoKv@Dƚ;[P!)T )ټk]t0/,}  ;hw5ctJ^g jT:rҺⅼU3fWs)b3݆sCefq@᧢v{I/|IR wd>iWZۧ}#(#|RLP?7t9@c,?Rq4D!O[m{'Y.Dmºch9*FeUވ` ֕?lHDD!~c'܆| u#"2ɗe=2z<6L2oLpW<ȋGOg]إF.&Y;y~[ؾ,$k\5Y:_)&%{SaJ=kv9/XR]F_HUh5xr<4#n21~7?T ʥpWSK@'oֆM#k\"+aKY _tx람i,qJJ-~* x=n62C55v>ߚceC2qpE~!/Q#y8^=޲#{<0}NĦ?b%?{ tZ݂0򟓓ǢaJ(CE?qFdƒd<]jmB#ǥ<ʣ]?ٸ_r>`|gˈi^wE1šVŗ^xeq|B|?_ ON7>U/pj?Y qPȶN4_wZTgkQAgQŽo"kQV4DUIҌ~0)}0bы [XNnw639lBQ7B hBCIj9P>pϊB=EΒ=b[*H9BܳpN7X@#, W/lIdsx6Nq@g_>%C]9W3V; |%I ya14DW‰Cyi7':*'x:5 Jbh+-7@~ψAk, ^LM$3qXls_jŕh&z7UZ8QPZ&]mBؙN\oH0(/7c4O\"ȑ5kMu n>P =o%fLGp!̿Jfw=7ڨqИotGpEEk&flECPkrrU΁}=Ǻ4ƯU eyd>-ê$aL1ZЅϓ19oep`(h02ݙlp)Kqj"YeZ4́_D}+q'kN|6 >Dd_8F^e#g!Xu3 䟨oZS8jzu\ٔM^m8_©9&͔ j]}Ʌ}r3` ^]~n?RcSU$Ϊ˙utQo~TV嚤Ȩ|9cm'@.iY5,eM4Z?)Hw(T8Wt7Ќ@`Ըq{Xz.'\6=P !kj:^jDlz2Z=q2b>ʌ&7 v.\.ux/fLћha2W#Q:O)_5>c}8jSX|ML7ogGr|"p apj.Lƍ6f{.-.ImT ԋ6&ޥ Lm<]tj;NP]/&@R1?x߽4]UM%j%(BsCk-0A]Mft(:?;c`Bx6ܥӟFA e{1=ϋ@߿ u#*(R{[pMpc yv%iD$ ᩛss=>yBkDKSҐ|x/Oň\2uκTmүvl}cM~4s9 eQ )}/_Z 6vOsR^Y:tGhZ CzTy$ &Q)~SK+?4Wٖ) H^i2kC#=- fhlM_80^h r\ 0.&yJo@ /mӾLeKf>_kٱVa~Ŀ>\Hx&e8nJ7[& Gx*#_:5|!5qx#ĸaw o[6;[ӧ/%! 0E[1v2A,2@6\vZ|=1}㞻rj f0jg:jsjE셭 ' Yy!'sU+/W^Pk gN"~&/1=[$}AD/')_OcВ[oB'N{i,xcuyՑـT=9|@=uv~Qj϶ n-.-v¶ `4Y扠:Cbv~ hMهd`.>έsUM7+@vbRƝ M'KW06Mz뾊ʕS,9N*RI ? VT-d {䀆 ʅ;)G TRS>ɠ6/3]D{rh{f's&Ǜ(Q8cN0=y?hTyx`q>%T$i>6JLcD3y˓F#xWv S>Cq"Ny l۱D6=)zЍ}uAvu!^|ڡ44H\0,1%!k9[*9,m Ex 8+'5rdLjE= #3>Q)#TlspSv1c2ݚCFJ~W@W]b4y~:ݷ&ź5ȫb%}=c*Mv]6jBXzTps-b6;fYɧ[V%qn"[蘆mMz^?]_j0t~T:tl't)> w}7 +{# m*2j#T E A6G%.#.Q,h"I_[wl{ҁmF"+}zW1oQK.o1(M,o51wГ8d ScN@:l5H3ׇ-SnU6Ve^Z4iJa(_Jl5Y5!ɹ/ܤ!J”@$+ o|NmkS 4 ڇ]eU-eXwFofh 6x.*b&3dAAlt~cqU$E ɱo۾K::{t!bȾq!z؋F-yhV:imǚ4,w)`u6Ӻ%sV Ոlό îKSVdLA㱄T1]yZaIm$W_՗kU-`!8Uਗ਼ޙ.k -j[ Wea?'s䥜ij >,5eə|plXU^ݢPD%'ˣ2 gȼ|\CbNdR|oW:# )[E 擋Rgm}֗x#璯 حھ[<4AG1P rQ~ %RX*pܭ3>? )e76{}BvnE#wrfjU32"Dd&c\& ?k-@oBK;Af5 0V2z2VLi2jvO__[:e2oUZDxGƺbE%S!ZG`J/v#ck lնͩ 3ui7X?pԿ6431G|4Y5C~Rxxڴ9,@VMP)f'ZD1 Y3hMvR~ɝ:ch-zoF h _g1-aV80 ~9Iw ?Ӛ=mhr.^eBv]"G2,̾,[$/Kh–1r`p^Ejګ(d&@9"皾xsYU A4|C5| / ,hԻf_zk%yJT-*&ɕ%bWz sh ru,|,g(% "-JW+=O ®%li -ڀrPpgS$p{ 6N(F ?n_d`p΂Du/V,1JUyRحR &,KYSt8)W6axq;"lh_! |$De Н?:1e#n %:-A*^Ba6#ܳ)qM\rΫFL/|Y} pIm;Sן/ y pWȘ4-/sMa:Rz4m+b=4"SEϣ>N޻k{A[yHɤ!^ع\]<~8ܮV3ث%!qt0!B_H(?c%_6)_/tK>=6,gww`J"n^ʯIӦxRlslcw$*C}>>Mqz?vxZ[ bn.s![tӤčI;;vq+Ѐ]\T}e':&.gU#b\W1+*jI(IJy{/ytTWn-bޱKH& AK8ι&>vo?.7@SxM?FzT+Y?bBs?<%ɾŪU7RZ~Vξ9X^*ԭjG82iؔ_3t*{}ud,\^*{Թg^]Upb(kN ¨A|٧/`o,:ܜ^y/7#q9qڭs{8eE؁LL٢vW2|\'K^ 9ovU α@HM]8xr]S- WS&L@*A8MkP*]G`:wLD#r3g Ï/>)Մģ[!xv8H:3YU>O80N Ř`ir42\eƢBQB=21a1os%7"T#c^E+ \6m-5w{(t(y?QZKҒ^F> rƟqZ~Xt+0vy {qK ;9 QDKTm-ls֕uE #e4Xj/(0`}HC^ݦ`Q+|Df<71?9jtӬŕ.r̕rvgco2oبY&mbVW@53gl](fcUDx=$zNw[C]PFr 7] s}wA[ϥQ4!mC}7M0Ǒ,*SOjC ZZm9I{;NT {CBހ=`.xg)fgw6vHZ|21kMq,߾ՋY'wL9fߦto=)EZmC+ƞ #`OOuR/:eYê- A\reOwVs>V#WIO"qxzh}4 &қއ~rʀuGr*~ qBg[ #ov3CSh4VFĺxUK2"}yM_뗃A?Q` 3K:|ۡCM&zU?imFA!>Ou ; l[,/?D0;~G=(N">Uf40!#F Y@?h郔"ZОcęc|XiW8.m,sca $::pSbKջhU]q_F!AY].O>Q&6bC~O8 FZt@Ϲ8WiZ1VMF4᫒+$;j3)AT#j+,&ּ;A:oO.A!^bH 8350S魌 "HT:~1|2{%HY~6j!Y'?ՇQJ#n_$nU&<ǹoM} g"%*0MӼzVʔ1HIxD =n;r 1 <]lxqC+[ ϙA'd3cgn 0^L`c jvL,=l$ԹV!/f|+Tcr$FT6GS͏&A{i< #ѴL?갬JߋJBLjjRKmD& .pOX>0%O67K7h}KO m's@ G`p@@&C\Ȃ*O2} S]ſ9#I]_{JGUCyNϿ„|3E?y,>WQ #7 RYW)1BzuO'&%-41T+!D}Qx`珄;[P DV砓sXEc+_{@])w- P\ԏ,?4!QQqdn I՞tXVēfW/OR$1B@BhtmY)A|pahʩטRܫ}OԦEtv!҃gۀF@ gkg-%Qk_~;P' )ZYV1Y&Ы@s!KB/г_>3I8?[1'=c+kӷ~7`F ?;^ha)Kf3S_U]`1eYe{gnVwE)(=fni^ŗ#FGw'~6!Ľ]l:4"z,k2v,*xgڟ~=QHqǛLhd~:6z*"gX$a'{Z+ܭ5L8"wF`]/Kv=Dj;{W3q;ŊၺHw34 -4:G6(mJ )NDܤi/ v/(F+i;SyJvJ7\S#T,n7+XmrlT.Lc@Ȳԉ2 P ?WCk,aÜzy<nmZS!2GGU)|B4Vp8Ac|Q0?1ޛMj _S A!,i[(SK]SxYEX@^u {U6w aF3@Œ=LGNvmZ_[A7³lk}X3bm9o iaoBlg݇RIdg~9D;Z87?^ Dލ9k2*'X[A7*}+|@1RH |WֶKAkЬmpHut\Oq[aa`t&?hy`rq@<HjNx"Bu`^H3tI90m vK'+X mxe(0cJA.P>=1yHd&k\Zߩb-qeDfPDڡ٠6:a#X?y#h|u:͵u4Eä'~R>h[Fsp7r%Od\m?"ieǑ"yfRyYXK_0.er:ŽxkmzoKrўA5\\[ۦpGQҾ12-uLiAYͱ9ۀ}*[#? Wjh{iSFq5RY JHRhRK+9;B9݃*1xD ֨_.5zݯ@M2A{2AiICM]l%|ֻؒC;|̊S>GFlUL :=)-YN^P:Zfze/aPۊd;C*K(̨D{k@w逛˵xzǟ!IC!:CD!\-7%4ZP3P3ʠwڸiۮ>xNF. &_KE n0Na*Wv֨Ŷ-!Iv-ȴf~WX58($?99,)%?@AxzK d@ar_cUJԃ)=re2៰@Cm`&[Ha;Ao;L]=>v /xt4[ϨT4-$j)Q+-f.6VPO庼L>Ź%uƳUM`lK>EzGj"-$ݕx,KM$T+mbslG'2N*zKr[ Hu" \aɣm(U8>TX*bɤtTv6.G%WLq !lbx,e' WO }V%HߌKwo(կnkN-379 ց\} ϣwh2țE[Nme`\4MXTM*kXm_~S,y tZ~ I5a9,yHt2>VFdxbQ߈ier!-lI+ƨ BV 2\Ni4Xm5OkP<v.x(0|K]d "q7` REc%Lecw:ԕY6ؤ%LE (] +6uC=ǂ 5N# t?3x&=d&I{'uzJBL߃lpT| :Y\ 6[=HmZO;+}spq!:p Q0J젯-Qݺ8(%J M&r&R1hjPG2ǃH6У ٯEg:.> gs|()Tn075TZuQLڽJa5?Z`v%K6d:UA= \P%YUh'O szptI[d3Pf,7CC}Ywuj8CݡۥQ/JA 8al!ʤv8r_D:A`ā_ .F.Ytn D\7olLM:Z M3R&^6'q6]Ȳ8N[J`\@' Ǒt; AF aN + gQnp x;5o)$eo.'3+p *AcU`BW\14Ֆww my// ]zRnf!*b>3MH\-Xlߞ)zn ɿ}s&dO^9񋋭w1lKAg<\vٛn)*0.z*/*#0zBȎ_q}!_ӲyD.$05b!ΖYh@f{R @$-شħ.yc#0ʧV2fzb4c5@2hc.6$կX4])cx<@x vU/m!,398>(/"H̒\2Ie{x1JsyL pF%:(+r E" rbs/.bퟋ9T.Z]E=zStȍ=(trZiGӨ6YݔkpTO']f4%'<}޻4wzr]L+yÓ#) 텳X{WLZbČ0(u_OEC\gk/E|)yꝹoREo3/j_'x%'dkiv[Gb(JM .4 FTihNdma%_@|*`DiW8I:>6\.㝡\~sUmw)$4,^v HRih߂0 w$S-,ewp&z/ UtRfXe6.4h1Rakt..o 1%`hަz!op_FUVJ653 <5.MwƆ(-4O7b8Ġ]37#H~e Xxp:3v?t/bj XbVW&` DD$_=z37ʬ@ 0uu.y9I2W{TMrPj{t]iݾ18FiY0iuX}Lœ_yHL4tT<$)r>K`vXlzŪ&E|{ 7*5ZiՑ8  HSm+w0/| 111T=%0 /\O`d,7wcz9WzyfZ?RP&z:OUSbr)K.z'oEzbBƮ=nw '[N=*%ݶHL*Am'x1$_#\CuR, ?p[ T~ŒФxg;}p̛[YONc&PSြ<O,?WeU3H5וs-b.dՓ\13Tmd(ei1m;`(:>EE@Xys/q1$EFK_O(0*{||N#k'6K?g*w%@jiU vTb+?mNPݮu`];/K"r FT%vCR~c}5&0B1SkM.ke]G.y7jWa)fn$I ?$71"ׇrjޝ-[w3Q࣮ݜ)#Y:;y򊥓Y*M^_AҸf6?tg?R&o5*JfRnWj-짿DAT(_g[Xӿ(iGO.R2Q8L!^4 *Bٟ @Zv ʯNup;0я7yoK(\Q3Fp {3]0 Wc;ڒ"Ojy2C\Twm 2͜}|!#:[aZ~'u+.*`:R 8ݙWhScW{$!צxՃT`"vvPvݚq Lφ>Mw?(M6ĺyց2iT{a㜃rz#M㨯2[CMgN7J1 GsHAy߾5yCX-msV_ #Q 5^Ǽc.z^79t9@go]tGV{d$HS%=thK+ ܴr|(kc5xŢU[X=)PL8SB.rM]QUJxrA?Ufg2qk V=Lv Wu8(oQϯAi.iwGTwn5麌lXO((BWޓ"26.i&  tn4j6Wpy_9. ZP88Q*"(%_lȠ4Yw#Nq,١?r/8Q*nJ6vOQpgbSRn:flX$"Y3P杝Dʇ*Kg Sņo38l~?fԑɢuM,B,RtY"qc>6WHSps_AT4WL4kNuJnЖKoح'Qf4, $^ ޝh؇Ԛzec ^3REhdۡB?0dwYo#)@vFLYa%k@1NތQ٘՚Lnj&עn;]qܿz]U>+rsxddn& ?mj cmc# ,j:Gt7f,2g쁛2Nw0Ms0/S&DX fmޞ=Ym (IsuqE8,"J|\ubNhr+՛q^":rGh2`nr~%-GFǶv_w֗ 6#Um-lmDMf[_&)O*W}墸f+e9GPk,mc@ uqދ{ONbDFy\IqTIL^ĺl0Vݘ$XBVc^eQ3a7a 78-NX0.:5?*EYȾMD zaw{| 6$ͤM`_ֽлFڪ.JUVڿZ8_ E>695:y0->c@[eFEaoش,Di%&/]m}Z5_XlyяAo,H% owPy+XdVfk7aBJ}Œo#Y23 ڌ(BxDNUVYX²|BVǞQ%3ɏLˤyf YTr(`<1R̕MuO0Dzi;I'ΓHlD·X!,Y4 -"Q;5"e4 2c|L[!0V,Uq<:}~~3*d(i h\r ɑ:4=pZbNec\妯׈@26jPaJbߖڮwDA(^zdP1}gX{d#`z΢fM.53!|Z1<-Bjwb&=ܣK5k_vH]CsemP xZD$%ȆIIeIaQ|! Q%{)'e8bDƤG_ӟŐj_xd{4btQ 75iA%T1ߢ͉F>H?k,z &vDK*gqfR|_K^trɈ|ŵmbj:*Lg"@^gv4*io%(rG<:w]| z6㊔ k v~_yG8P_w,2>I+G}.c|Lσm无EP1k3x"3i*ҥ Q2>dݐö{NeoIK<䄙-%F3߇vKjjrwB%,*o9aghȂfc5kY˯}h8a4Z%cɞXTW1r]$/_1g /dɺc>֢;터 )W!:[`Gk24:KQ:<bbLE,F^4|'Έ<^ W[d097[=LV.`0Cj2",e32`@ z`3}-x@}`DMƜwo-=jy4woB8ؖ0I-=`vJ9H=Pt`)cǔSg.RIݳe0c^*il3œ 8|vMݩ;-a\E򘤴EtBe>F6gg ٍ K4ܳ@ /.rCQMSʹd HQ*pc2ULK>8⿚-k/ѨUV;-)4J?ahD>B,v%+1O'gH^]/ǧl<]M|-hUJ.64Lc@3w/ޥhc:,>#=4/F+_=Ѥ*bc˸`6&8 b !MSkwz7؃&HXuM15pE4>%ߺr>!7UMHJ٬6hˑH+4Rtւz;KZ :S{׊d$7 WBQaVh+:"=o.sxC>yF bc0e6PkWvkCHݔ ',/7 xSRPDi--5IO6db24IvfgB[gB c2.<9fz 'vʺK:2zoi8Osh&,6eͣZb8Ӏh ḰEbV!y =Gc!-=iv<4V0nsK:||"A Is-VrW=m͉T,wȄc}mg+[r?;D]]V?<`iJ2/s^8a(S ~e'sr^Oa}EISGSnzM{Vw՟%?'ݼWkĚHo"}Oq}Q`uMvrt]ȯ[+ϥe`ෂ<|hiђ]s8; Lw.&N7F2BxquhcGS6A.HVQUEL҇$yw"62AUY?AqiRI ̲}CSP3~ MA eN&#sWoõ WzI-2uS%}޸cƳy=;i_X͞H)MlM\7cүfc/Y8,qӛ>\*'D`?@DW y0 Oo|!qjc$u'>vdMB nC(E| ~&87Q'KЮ|6)؈FQ9ݨ-Z<:#\v>X)j]z>s8;7C#7/)lzlg?&?3HWMI,k9Gv6(_Ew5ZҀĪcZ/w' 蝠-@Q@7jNՍ޼n::t!^ya{Aёr%Wu2gS)ٝ<_IBdgD=HyBr. /(/ԅ~ ߅\ j3*BPDR6w I~&z'iG*k9$p|.]v Q)Nڐ<4KZi@ )\ohLRO4<;so|!Af kQh ? "X}aj }a39PC^ν6v;MZTo9)]y ;wRO2<%Jc.}[>Za <W/X٤5g][橌L)3敵vۨb)n Y,8|Kwa&yaihפW>fڦkAѠR!3-iI7cTdt?KͱDqJPam.Īujc{4SnWVjHgyx+a'*] 2xQ@w Ջo+&"T⚼L& !{k $pے\ )gI(Î $TA-B[>~T -|u)Y^bopn!g 0A4޽в .Hcm7i!B5SZrZ9'CXu~_y'tA/àO6 yثK%PTȚ8~/i~}-|<8l^U4;׌h:ƆG'Gb=%x l|azԡ&l j%#wa#$,w6 oGp5)óv)ދk#h OM5E}oPii8N*eOvȷ˱mf]@gqW׃q~Tbq6gчhAG*~xd/Ŕ3YV$|J_THwE/K&TrYJmEV:Q~ȿz Ղz.`O%ǯnzJ&2MW'͈$By6 %Xޢ)%#p1]x(\C)kϢsmDr+fraq(ʹr#Q-fkqvtfz,71DU=UR  %ܧ"Q2wCo؆z=NLK;GWmSFW?:Xzj,N`wb|-WtK\p)a;RZdЁ9M{ڬ8 &@iE)GhuJf)ު^]DRx̞(L0DKJ y-T_NL|{\n(/% m0gZ ONtHLk=z\غg~NX({>6kMS)ɔ3$e|VM1Af$foog 45цUjbN(Κҹf]>jNEݓhewWY  Cf:AH iqpC9#ed`S Vͺ.w^ 18cܦU4Gshyre這|ڵa.:)٠}.BJ}723!,> ?:G?$s@\j$M%+<_BRVǛnK,JxϩE8OX )6۞]-rI pWݪ-X>ԠcS%V_H`EQ_U3Fo53hQ/(Wa`d;$-R8ok-=1DtAX vN9]yW\WbLB(j? cc4@Cj c≙ "Ov@Z`,q)+mQGOHјl #FX% pecX D.]P`IM`;,Ω =W1/aPV.>'$"PwbF*D`莏)sOhvƔذDy# Zs.$ ?mO$GJihw "۵ib=5EY` ȷ ,=#tG&RExө#N|* wRϧ/:=F3MLZڀAG.^0':kV@s) #=B+>D"QDgKvl*gG`{剓KCa$ߍ%:<յ`bx)f%wBf5 Nt'ORxM6ԫK/Zy.aMsr dfhG=$/[کGcۉZɨãGեe~3kUc~*eP m1[EfD7Gd&!^WmV?8}+glCSU't#=J!ζΐM?W_,fy: Y(#5$p:tnjOtAx6_(@,gJϞ:ƫQWtxC'H, j:bG\EI@~'J.9ʸ} аMbxG呖̀(EFHĥm%`tp,XLH)r^(כ| ^&NIטW&3D9(}VU)k s柌7X)K_:A ~K;9`FGpk: Qqd֢.8۲.u@H]t!IJ . v\99rkKĂHT?p.˳ EyL+.INyI6N*p.(Vmf R%T(;Rd0Fk@;hS(eR8;TGad,צxռ\#,XYlkĊQj2=Fі8t_R՚8.[Xj㳛}zE|0oA :>26[] %,MOg*HH>eCK*n4nYEot͓Ԕ9ГM;o"}=C"d7bT-oXHX>` $Ԭ/p!ЇP^K-Y\.B_D-g/\jvjUٜIAINţЍJwhBʎFq9ϱ 5UR3k\ٓAZߵW g)4$ W(fʓI3Kw0 $V@u#`r39%as]ZҷZʕk%URrOm`i.Wc@i"YT'$P: R.+CpP4\s.ɢy="2 kBD3?/DžFa(JqDH_=ѩ_' L_nnw]kR P]qUngi Pv7$p&؇[ýviy/ajgb!JUMd']ꜩ%)owy6C y_ }Bw(7蠟蕵ib¤wڮLnA _񂆂=S_:|^m/mSB ~ײ[A@kѓ[Uu;=n] u!o]`Ŵ~us5CԤİj_*p n) p8rhU -qp#X:,B |cO%3X=3,Wݛ=II^EOj2(Hx8!i6ջz 4=>qՒPz,s/ t´}o|yU(wA>atkxLS6n岵tvD{rh&L*k:^qZv6u\;1_+e1NfvśqSFզɣ@Ǔ KG ޗ^dR UkboU8Φ }>-o2ܿ4ß' BUry{,xi'\VZzpAh3jT7FjJ5j_YѡtF8G@u$2,(T+%흻crۘiSkGB$uX_ZYdti۰0MV7*utUW!O`S* n a$20軴UGJZ:^#U/76NX)vo)xf>YQ1<[NPS~iyJs2}EnB! |3pA%`5 8[+*е9=oMRB+y5MoEV.օ SecDОQi YW֑66^ifiQ1HOc8_d~I>]a+oY4/)uy%t:N$L2-& sLq'^r9THFϹ;;KaH5A\T4hB9qmV_)^UR)W%]"Iia9~]9wry0ԴKO?X9linck3~ )4[DQH;UdnHz[ LtVOz+ށEm:,˷gbd2N۹2Qt|`mR=3f,=ʬL@5tug5"tOLivޞCM_7nr.k:⃌Rqҽ пmI}Zhw*uɨ'w+$UL N}5ӯ8:XEֳJ޹IR⟯%-tFdO"URZK A:\K]Fw=apSWsy^q7pEeOQaFZ6gDvlD$輤DWegM7Uvӄz=Naȸxb5 PDU>ì8CS pи\:dM-ukxK;-܍5*)09y982dΔ1PYPj!ި9w"~g-5]h7DAC^tIudB/J񯰱IQVLFl̊L 1G\e-.knITٸոiGwmg$ڴ&=Yوq>aXVtz]M'xL-jE8V`}mf.U.foD\ Ӂ:ki @,K/Lv9P.]|Ȭ#DI^$y ̔[]]%bQoCV:y8NptToT!h]wA7oˉ?<BbҥWp)[jof&dẍhT15x/jԜ tRDvўL [7aʝ#m̓*Ҷ u)t.G'Z冒[Pl%O|(]Q,݈ <:lp.(!^cpz-qX_|ݾ>GWpȶHlSG"7mlq&Ro~Z|,uTgЙM\4"غV士@ Fjԥfm% |Iݢ˲b:{"=lYhU.QGR`|MPv ’_eys1BYnV!)_ H3&ԖA v\ PwB+^aN+} d%g],Pʝ;Fɤseܾ٫ƺWE(,3S񤣴694+՘:sp^{#WBcӮAD!,L׻ #͟M gwp#[,ܧ5υw Mx0FwJv#GInbξ[<qSu|6r&FC)B q>5Cqy^V`28j[{uv<# jekȁ.Rb -,xm4,Vê"ǽ,'128\li%z`Rx9ȤbX^h#'$Gft+e%l#Qd<4uٜb7BK€2Y)?4aUHXdfoau*MӐEHfpӠʊo!t&#Nö ௜(U1wV*?Uot11J̥{uԀ/wj[B;][#xyX-R o{9ȟr!_03ZYoTO d~Ng@`Ir~]g p/>[B=]\Ѕ؃;@5+/Hwdт`-Qgx9a Q|kep^'Ηy7\;5cij&|@KByURD Zru44(ɀVaŭ`v⟢IWhpKq ի﷩<CyYw$kh҅Ltg$h{Ś+dJ.=j4Mm( (Qةt*Gd{N#CV`;aTQ57Ylֈ; V'B l[bs>#mU|n^ѽ *'9!K9Ȏ?HCDرėOtuz /BÍ|v&[~-LƷt6~G A;)*cѠk{o e+cL(7-%S=7s0S+~&wj¿EáaO)C}"5JBF?q\67Gv@L^Gs Ƴ0RI %QeL۩"|cAҍ0jݗթ|mU5^bmm"/sc=1' $^1_z9BX>/̔8~薒5f,qӎYV;8%p9A9+Mb &;tJy\hGc/6g~Ib={|N։S!Asx#Y酌O~‹*aK+ =K*`>,#"Qk&V{aC'cQPxĘO]'Q/>V\ӯnGQzK';B%Ƙ͵|Ŭ!s)R(ڳ]cyZpP/80d_\rG!nV8\M! :1(,ƫNc|h-rfPmK 12V {@(aɈ1c xwmR:mMdo+ygs7v8Ya4GR'U$JdbAؔҍQϖ7ɮn ծz$,߳W>+ݴ2bH%noϤ@+M€T~w^h旯oaC]ѽ'ObAi?t)F 62fD% 4͊S HLe 14D^8G~W^]F9j!rWec Js@A! hg'"9ej~3,Mm&Fg~;(H׃m29c贓8Hr"N0~ڪ CAAr"{ˎˆ-/+W6x@z߇~lSIZh^r~ͳrpBLu[xͼR׸(Ln&m [ z-'ӭ' dIk`&wF>&ޮɠGh76(f^nupl>&"bQc^Xࡶ>!Ѧ^fuǀM Yi9 יpZI9;JI%acL?o`gI ͹/'-DnA*0B->?}i#ܪ$ʲںdAY5׎#U?1q4>,iZK4 7c89_<Ey:F;P'93v2^ĸ}$>hA#iϐ\bE:gcU撺Qm9-ZW}i=:o-#ē^ Hv43enw?'FFsGŷx278!y7SNK6ݹ*Ux1?=;#kk4Ǘ+ΓM;l`d1 D=gPQ!Ɣm[(z(FmقZ7q1{4AHA Oa3+|ISZOFJ\x jhS싧 ,{ ,Kn/v ٔAyb RIn`*c)D5ݕ0'UZ/i%5 8cm%C.;ϔPX[1tłt+LGbIR2 At7.CIJTZ`fJq}Yj([)(*DQD`_[PQ5.꓾ 1;w?[ۣSX iDmwe'ڶ,IMH= 0+)~q,`=~hXLOKw c}ivQ8|VKO76;Xux_5Qr3jKxU={Υd9cc!s3^55pYIiTSXNĦAӾlen~w=KfϏc뽹u!-H0w(+{EGVTwdOw\2Yf9E'_󡘲띹vEB(~󝏧vE@3m "r dNov[Z8$$%yC/Ĕ7rK@d& ޕPhz>WᏔSJ~aKXyoJXE7%(*dacR2 *Tw_3~G:f%}Y-r$54Rq#;֩If86?/ʒheg4S؎z3T_g]Uۍվ-GLffY#-u(Z1}D/xXxRyDV9[?.*GZJ9S/2ÔDeC'B,YzM)8r~,˫hia< K|L Z8Pc |hTCU@3Uld!JԊ;$Ѝ/ k݉L xӂ&x{fsӼ'Q0 r//E:⧞麓C +u6!?7uQ9xAͱnzW2U2B#sfŢB{1!wҷw!4[^$rcN^+/羙S ŒO_2nއ*|sM0=4GtB1 à{)TnH!}ǚyDIQFc3G]p^֣Bo-ߡ>,3;8w[T/ob I3'Fv'3 %򥞅Ol1AGfLѻHAZze 4qQA(=Scؼ .~* 5̩{"~hy}+D dƲC?of0r˖؎gcPYu@/,Ĝ!Ys)HEf DurvJީ|xd>~(1Mӥ |-cuJDäDGKJ+?`/lFόX5ykt}e8d$B#ӆY(J~=mA,运 ri ߼,yDg>^X&hݡ9QCS"a -wYK/Ļ6e/ss!Kuos[wIFE'd@7࠿3QchsGXJ^pBv0dmsy |Ndޚ oOCfMjÈ"SQrkNuю؛V {UAY | ^>2U[Ig'Z'ZYk4l8,Rsw<ȝ.Ү|n!:-ȿwme?!EW:dЪ|$dA#qQW ,veR`OmlQD.k YS\XoEW>Q=2J>dD [*9/o}9#'?hڝ"Y20\${=h٤l`XK*mw@͢p +hmpc$-xhnyĊQ }7=4?8>ձ\xYf7Fn`jX&%#򻁂z8m{)٢maakE|h-kҝie=-.^٭OU2"95i mn)DVgc^wO9"b?RcbXY]jatd*lVQ=$ZEg@>b"H򎨄ohODYnev~Np=ME.3cߡRNKoL*J)SS3'&N?u{'<!ڠ׶RPC ɶWvLbi![| _;ruؓ/3pWYLC6?ڦo@m$2WN!S>̫qVƇ_y}Ti_~xu4~ Zϕ EaQAEftXx}[)mp0zTV,p`Fod9.٢\14eUЁCr5zT3m#ǭP\ROHxq!l5 SӕG*@g@قlc0[(vEl3H6&æ#7.U[=#b+tG}BI[a΁R{t6M'(I̯yW$ӆw Az9o*膣N9]QmD^qaEJቆ3ݮGnܐw/溺R|nW(@e uv-1˺r(Du'Q)/TnJʦ%Hu l7;ƶb==@Fr͚#A?ŭsRwVlx@ش }!U YE(K+Mn'U\hY ,yȯ'Ҵ"ez!]VC8N2ȬQķWEэzu74sZh`.\< 6"*;2-' 9m҄#!(iWMؔl~[SkWXh;V? u[ .7Oxo+Ze[ ˔GqB\FĔ@ <0*S%]` `"BH%x}VSlĆݦN43ucPƶ{˸?w|Ou>vvscD򎢺} N(gABnNŚԴUH1wms}BR ŸOSDZ%^qf%?ΟDzFQ镟5%z~tNjZL ȐOQ78 .*d ֵW/,qp)MHƠJc\ae#F:O?X sǐ2F91Ds<Ѓ"EB',ңp`bc`s ˫A_q [l~ǣ%u:aLFۜ2'6 ԝ@=5Vݖy!u?wfUK&Lz9`hD,>QwAYgz|?Ot,v BQb֝dv8dW~vEI] غdwQ,G|-8 (:F <[~_y~̜0Qfr.9M}&-$CvZ4Ӡ\Zf'/)NiD[l/ /F2i^u LӋ)Z9^@w/@tteNڒA#8r&L[aUլ`PBkI)Q+ýo ˵F{nm5 Y^V/2,Nfo24`^zԒ>6>0ZþXi+O$a}a:|/DZWcwaHq?kćZQZ#/g* d"G2[fhB*zz?ӂ]]'f4n4G KmE9;@L 92276x p };V+>K` dx" e|r.=nV!`& L:c^ug'r׬ϥ[l3Р\den 孌7c[햺1ą'/9ɜO2AM<<|ع59E|lJ%. A zGJn[ʑpu zC|}[j-9U?$RuGKeV@~J <$ iθH.ž^?:㨱)F3eNeeuEQYJd񅢇!AROl$ң#i*V9͒";t\0pv\؂)LF]ge0AdGdGYP>1:A䰁d2aF𞓟or 9C^CW4MhiFqn,w5ku%Xhd<L尝Nx*ЋS/7F{k9wG4QI5(/9jpu7 ?t&6at: TO+?=0rC=6_ /\$ k1nՀ@bK-M(J$PtEu|ƇO]>ۗfӀF>BgDNCeO^`CjpEk ƫxL:eFJ0ud +M_TW\]э&D{Bb3 Q8R4JmBck5,Ps.Cbq2idh5Hn#Ya:M0!p wSE,SCVA1a[r3ҩr^6:I"Q62o.y~ͳ 徜 ^`PhqEr֑7!敶<0 NT27=ϐ5+G=>Qq|N?o ʼnq|vaZ%Ҏ8yQu \$h|W#X-vL&pT&īv4u0%9sIWDEWw40-~n

M0|Ef`GFD@8nQCn'XBokQ|%e3^#|sӱC"y71az⑴vYv{ý"%=CEid^+]G$KlF0cCHNw"r>*Q2dh;i7yiҹ[G@h]!qPZ4NC9ICܫz%9?hzcrq>HR8,KK~^QН=9'/)k+|#%ÇjL.<H9Лu7+~z }/tu{A2"bYEʡ6&F?N>x*e9RPŏIF54 %++j/Z;&pU `Ĉ;5 1Vۜx'U "􂉅>^;$:vZP70\ a- 'Aǀ•lkgb|0 F٣h5B"?.ԶLY 򀉌:9{q^Pbjc{rJwlz@īaq6mWB(F^ehz6CdlQp C䜐֚Onư]m]bӮAw=)ʦ^44:jtY lO6b [TjM l,|!_,ng v*rrQkn^gKԅ}Wc)"N+xy?κoRYX#[~DoQ~&{6UU(Wbq50QHg(܊k&L7E{W6+ 8@+=?]A0.yDNtiVHNࣰJtBF`u`4.2 cQrXgK: rJ(H 9\hA񞬹' Ign66 &.qwʯ# lڜ_ 룞6h%e%u B`j.פ(AizkҐxU!qpJL )ޙb!ATpYkЌ>> |TuʓM;a׌>6~XQ ԣ"jg+%aCz2"ECw@eWRx¾ P8ـqӬ`dYU0w|wǻN:MJTkJLLޝv!VOx Kv?te½+gqu:QDVeN3R4ur2YAf{` i}}Y Ϻ2|K`B{l4RɽYr0YJHXweӯ}`cM Mr-z i8O:,E> w 48d)G9Ղx~ ^|O4TDI6YGa vH]Oai{-H>qG>,+8 .X jXj("# i?<1ee: ` O~j#ح $> JH2(s-}0+TRIA{g[sYU;$!j>Z4ӿӢ^ ~([)?2۱ć-{=kz`,w=S[K/Û϶ة94`pX=7(1#Ɔ8? B}L;`sz a2^&4iJW윇 ЩFbs-8d TGArE6&fw-P%^uTM- Utz3  n.)RUAcq1kK\8, :l,Jay Zu^,׳6MOyٹG jlKXq`,\Lme ,|9sbSu4cdh˖pE&;"{Y%X@%kR9J "m<,E<Ź+x1w2DքZ>f1;cmMC<uuJFESفѡ>v'HcE{[Fy@Κ%dQ+Ozֻ4ynEj Jבg'MP,\JIHxQ~ OqF7R { Kb;v bWy RtkEr)!ȆF>I\Azqnh a 5XzXh+($GL|otRR~usڲo`: JD mz;Ty^/ao!0Xn+;xa]y ]>y>MJNmۘUh lT9 ?anU!)1<3o؁ @nQIQZ6#$P]0 ˓<~}wk ^:XWVيuSa kSwEn$E'2 }F#q\-QsQ@.Q3e,QbJH +ءh[R+ejr;fJI#dZ@ߵDPG= |XijEe"$OmBіt0'aiH+ڽ4.h% Hef?,5|u,nHlGn?2JZ`\5\ g7KιD5sGFrP8F} Q}8X@ 5rID,׫J+T=<2oS,sLtc[F˻ /Z[aj6!ؖ;c hT#hkt s~[$77lb.کYzj퉑ή횒!yoh X&f*DjYsf3@oԉbupn$ 62!ϔ>m<<#0`RTӎ oe#*6&g8ej&}0ItF6_aƏP$dppU'?Xwfhzx8@l$2׍{zI{G1h2h9xkQ9 ?kkKfp L|=F)^c5#Tba忯KVL[uB33\ߗ3\ؾzg9;`N_i[m//57rxzf QJՊθY\E@t\gAa# 0D3-5Ѫ0a!ؼ3_Okź|#X^-GPvFTnӪ? Yf(bi;;s!}dLew(ݟ[x.]qŭ(-,ӇN3H;x /K[L,HcCTJ~ʱ@O9.sD$ Ak]^RyD= qcZ큈%SrVHaq Bhow .:sâǘ2pS%>\`hOxѾG6C"J&P$ѺvOWY08傆`uE"]wd{NZL滜ܛuЫwN j5d%x2; & `~QIAd aA4e"9?߉RNBͫ.5u}m6h±7 D"&"qV;yx=rK8@qQl*ڟ-60&L:fv y/ "5Az6W-d8s l&@.4YИ3.7ʿM1ak2}%A:t&_?h' r& MA}ޓFay&iޫ\۝xwtK onO 488_]X!܎*>a}d7"KY2W7^iz7QT-X[uEeTN)1Gݝw|õC b4(ʿkZ"/a>a )p3gA;( [jѱwubzZa4Mioi\9_.¤ ѷ28CGHc u`w]kWVj3r򧷴ꛤRN:Ls~R>ؿ[l>,(T(xv+SGqf pܗ3}1ḽ,SIu+4 g#LFhhp->({76aB/B<=,/>jnّUFxr!޼wuA6!ciOc(8_]-~P t~tQlLQoW(+󄐼. ]vZsxz,3*pa$3?6qޅڅ+G蜫ӕ"E]=(.DjK9ZS8g*c(kZ5^Yu}0(&X:>3+8q5^SOpQz'lq#nvKbز9X?@LH|܋?`.v[kƚi}ˎV(6~K=%cY-IgƼTMo@نbmBR$pDg:/;[Ԅ%?|~e\G^2ˬ6y5i~jc٪2@ -4Q񫐆#U#VXYڡ0Sf C<bDs!پUm3R]\V$|(eKa# ) ypY5Eæxj׶U(K⑙y>ry֬ݕiٜߍų9L@E/|ɰ^n&r Vd234Tׄj!$m )U}c_@!vo ;gǬL Ú8n&[<51ca#07lhGp-|-8%Si.KS6y 24'FWk6nYnPL !W>>AZ!\+$-5&~o8__gw7l48'9J7bDHiiG;! EDP-uoR(5vEɛ0r^WϭQtTw"nP fM=]o᮶<5ݠ\Gmbl;!DpNE%,} x) Ci"Ey!2]Janf}VY2ZR^`z e|vNrYEZn5+BءbnڠJ@3 2bk1$diܱ,$R|2=RKq3M]b8ڨg:΂OCkHCXtG膫rezs~Bn#ʻ!y+U8掼z!.MguUȊq<}s ' $y^ 3 E; VB+w{+E4g˚z$*Yh3NF*'9Co t*68>5nAcd9/(?=\S/ywV'nAmtEjxbU6H"OkHG|HolT1Ai3>9PgtN|W6<Zd$YZg=@BҒftQqrI"L*cѩ;e oVeUF/n*կZMF' )7 1[ Wza!i&V)SnW"v`*uՎR-m5%OmB:<] (7S@ k 0ؼzSO^!m3j,Ի(xG"5*ރ+=硞t9we4l1M-XţQS>)V(DЌ2g niP"\Ce(-{̉S+cS< ~=MU8&pd,@[Kzrl4x'#zu3NbJ(qw"fSIo&˓}jsKZ88 %OjEl1݋|ZM< %ko|,3/VCA3G'>ӛ} -g7!DQT@@a},?e=!Fw>E :m+{01]yjfd;lp| 9ex?M\dB$mg‰ :HkI?QB-vB'd812HZt8FoH"ufҩy#3T98Rܬl#9@%].1(5Mw?`'1N=e?I k]HB&l6hrƆd/]D#]ADg,YO .StОQMi#UnD<4SXk3 y+yM*ů%Cg58XeHlu ekv@w3mjaʌ.p:ߣ9DR6̌S9iC3 Y6w/ A0&i%Ve7խ BQ@qTki봨 $":>Q-tD WzE]O|!I=iV wMοэ/)&$Rr݈n/3WibE 5JѮ!qg|*vѦY?k 0+->D4r4c"dl4NsQ+'*F@+#yܜ>O^D5 e&n("m܁ڏN(J14n(wZv%:u9y Z\"|e't<@RY^t-[#Zu m2UǴL{6ЪLE)\>B0oBEL׺:lY4'u?R!-xkցÒ <ًG1uG{%n~ aB2魧SL^+΋ܳ]p桅Q+NZK/=XTWKikL37BMpR\\ƕ8qTyyڽ9Ƨ^d/(ϫ:ڕ 9-}i>VO)^4{aCTܐ e'3@_&('1/:Ʃw~oYI;M^r^Ț0npgPvb˱! P :@2SkЅRKw< .9(ɮQLgلYt&o6jX8ryP5 +7Lo^J 3sOⱍz{aы&+A>+N$xoFc=IcR_,9T9E ƟMBl4ā ITBH ald)z5%)+bo~uUÕ!h6T{]7aOrv ͯS2jeV y =bmp 3rr̽BA\ǵنH]hXdDkR NQ솰0X0#d+$-i/]&dGuZ6? 42GXAo >NxˀCӃAآ3[%)mb\Ux?Y v9Y(#JSɐ kklrwC0+Dݳ1m(@"ֶcU xܷ6,.'"}NL t9$;`&ƩcL &7=7-s6"!jkopӠTrpM]W )|vZ)kt@]hW;Wet<0_ei2Ϙ r0aK(uUkuwpoo7ҏ&@>YWQOwlCP)`/dkXv^ip LV+-u$Ih%Oc'1ݙLб (5#1rRM_p ht/fA_\w} 5:;dU 7!雥׈xXp W=Ÿ,M#V䖼<,X5dĨ\7/qp^;? t<6'!=@m1ttSbx$]IwCW/=ٓB,UR9uc.o w" 3n$H[%* ,tJc eĽgOTLYဓg9=Ȃ A%΋| [n.=@;JCJ"~Mqj䪜vdY vDijB#? LF 3@!qDHZ y!BKR&p';#̭D񗍉 `N K)vN ,+[ A߅_ WIc$O'8^[_ 傩;-OOix&;BoɱKK$߉1\W-=ȼjH(6> 4kI> E@]̻/BfX_]& ZhC~Yqp'm-yFԁ) '9CaZſݤT_6by2Ghji5${S%cPQc !ju)XE!xGjZ*YJo6{u7  [G7hY"!z˾+o9;#n4Z( ƃl /s (}F:촘$4$e `KS uO1;8Y}lտՓmJcS^\46d=h|-oY*#,r[(yŻC }eb"TI^ߠ^uőOOzPpD? w5,0ϧ1Ղbz.2=lU{gFEؕu2r^PޘX:L%%c2@xT݇/v>JM!`e'1 j&%C&>F$E>/*U}{ a%Sfܔ6cf"<6O()NV?.7u$q'xfsm\K'/>ud?3rB+k"s  s&~9xopNFGRܞcaȁc.@\S+<;|m TӽXW-r'Ģ|Qh"# A;@o=M#P#%fmhB/j<]1dd:}ٹ1}G_ LP6s%'ZzMh j=:oG SUCh2=^3 VveSa`J5%X-:hkIXD]yVe: Y+lE A3NĒ!$ H |9CҲt&ĝ{2dmJUXᨕږ:~MBXaoѨЖn:q=;p\)e~m&/B# ~ $$)̬0X-u#{^P\xI{bq8 A9ο3*Pږ,[e˺!EV\W80H ) īix4!YPxO$?hJ;E ֏Ճ.i]Q 9c =y]xC4_Y3/WJ8=F8Kx 9Y0<џ1iݼbz}dEPTwoZE7"U%ȭ і 72  )JNK{ÛZN Q<փk%.ՊCܛXQS(zUX~.K rpSeF<-ݕ:%87u#7%v] -a"^Ͽ/+(uF,lZ`,X!saaۺnbdXM6Ls<?՜Y+D-3r4*Ӑ{O-:x95na8 1Al~jUBQ*^)Vlvǥtmz}+T9ƛIif? !9kr;+}c7uѧ~E!ymi#P赆s }_X*#",Nf]Rc_q]>e-5)έ [:&X]fF6 1H]M4Xc 륇10mN?}GYRrH}xw?4efyuGG>쟛SaQ`abn|ao]>(SeFV57fؒpwA羋T[E7JL)E"ȴmCtx/7MD2Y"u%_HQ0Wp巸`PgSiU8C`3NNBuJ6c%Ӟ!X1`!RŢw7qP{7TY̭~+wbtGH`i^ -浐|̷XĢүp5+X:|Zk&ŸdSqf6'y1."XI~iאSjf8gy'v7C>fv{p3q;>D̾I+VkCQVTi _pny$bkf> yG*I mgFuVGT8.9>fFlebt`ɭA5'cef@ / D_4 GK24U9]Y\;.|5 xVpǸ:WQ} ԑ;#suВ .ΩMlc9f[!h눁".c( 1lN>4.kմA㫨H `SWvEϸ>K!VMnP9怏 3َC<%hܰkA("MKmB7k`5똊< C:"rӄ7#$J7W+7LS1uΙfZqγC %!Nԍ1qO=0 x?k2mdO}Fb?NR2<RǠ2TyAR B&iڒ4e+DH >jj'v_1Eu%K*TM%1|*/5'䂩irQTm+˄Q=IhS9qР2Al@7"igO 44HM2j`swIH,, .`l&-Š⩂K#~5P"+ $Vb"4&;I\ P00U{Vyq;5` 9Xv ꓷ("+{8RXqe3$q/JhmbwM;܍#W&~Jp˒xAk`~d#&ĸ{ }h ckixs(ը@wbn  {$!3 ?&uwS cYKŝ?ta !Tzɪ2wPN!~nBV MunB 7l&"I` ) "DTMOxcZk䔙RC#,l6wz2{O;rbq4;b0$ޜ/zo{[6BtQ'iv!_T/c&&p)9m[WUsFDZ  ;Ѣ`g_NU%xݧY%q" B*/դr,džh/q5G<;V!K`=#Y&Uҳ=VfP_akk1k朮0`n7@̏޴KZ %ӊ^œ)/<SξMb%}"Ec߁|ѣ-X2&uD,c+QPKfbH\/yKLaBg$ewXjG,;TNM6\ zBkz8;{iObOrlfrE %/1цFo)D<Ǚs?9%M0ӯIwK?v;|Dxb9'2^Ȁ?Bu L1Ӱ<3ml`J< \` ́z^,T.OX=e N;M,dn@NCG;BḮ?Jld҈ʘkL~"61mr 29ͼVyCO^OEf'f(p|Fȷ A1#fuw WİP _/0h mK*p57%θG0vSc:K4QЋݙMVj#‡ 8n)Ke"4ҺXuVs*@ǷvJμ'שey) Q-5Zj4C%C.֒K|]q']x"m<]jA+;fǧWP+#Z즯@X%:c~qUn6 #٨hf MqΑ!Q4b '&Xhٿʕe) * umWVpe&Lxr @5H 5Wz0u{6.ˁ|ȶ|~7j>f6 H|l:&M)(Y8^*<Ю}y? 5dH6 v;SJecs==p%п-njr Rː; OpE0MӬǬ_V=C"@-bk޷$-e"aRKP^ (4J }nBpI"|dɿgaZT* -IݽXyT7H㦌ykVC+71~`)pא `$%/1к.O aKFؖtcgߟ=? qWlW5j/ 8QB._ԄE)x|s.vva3O$LS{<gpWQ. .ABHR~xbA~S|EfvZK[]Hsh9G>ZQssujݾ с=7|3_9/U\@>Bz'H&M=NLF<<}Pj&AJ} (7;$+47PncX V&~P mS%q93urmݽ԰Ӯc_kb9wmT=*爠9*Vlhעؾ0=ڍٱB$ ~ɝnVX diѓRJpW:!|uR}Zf^\^-g"Ĉ  b;AY`pC/)\3Qa@%}^v 0DMN@$>I6pǹkO?´jpԳ,Ϥ~DEdNOou?acY?ΕYHcFN/tjQW8Bq9krTDߤhV;;P xĺbA8wdelY3&cIa F~L\ऐ0pswOx N"k{AJ_eorm(&OwQ<XǚS^j! %,gNX`&ZTBvݬx畋HY#U'jH̛&.Ug'1qhê MhZ!hunkwscQGv&܁[':^؝+OdQpmRY-\[Q̾XHC.P@"|ɻ浽G]_ۃW߈ %v$̰V_?PMVD߃`LN?W@m(S.5*w+ wXIce" A`QRBKv)K& 1(ЍR"Eߩ$'q=xaƈKkC-[Aprޭ)pP [԰mXTլqӉ*|q)?^-%v0#ik+P{WW"vq&ϬVR\ @9L͚~BJ믭0:1KA/qcTMƵ;$e嶝h} tq%_ԤCtB0Ur!XQ([6UN}.6ݦ~D_ʄTJICZDiS6j)~u"|g\)iMa+'WLnIj7hlj 9㨻5 X6W5j߿^_n}%tUiKulȻtnZfrM;t=ۆ.T™? '‚V B/chNÏ'*1r.ӟUP6SZ^s9=IK&|7搱7|E~> YHVy1t->$t+SovijO~:(خr:.P$ O ?+$]1:]4Hꃌpѩ uEg}ݯ77ʯc]`ojoWsB٣qQԂ-FѴe=2B*%["(*rPJ/UUOEJmsu,f *R֡ )|W-?GG;*cD9EpD.G˄/ H5? X-yG5BjU!4_BqkhD-pވ#K2ʴBnBRMBXJYDAydT-Ѝ) T9  wmPxWQWl PQ0*.M+P8S2~!|;~PyM}9fG}ֆKU׌OGT_'ƹzɊ+?$|5PV'hEܫ giK[B9eUHS>X& 0UU|(=\x]r֘2X T $ L ;Ѷ=F6ݪÉTb4 G٠?' 7?/ʛ-u5o YHHU!n'^'W*Fꝟq+2NՉgk'p YUe7{ZKy Ez%瑹_ǎGR"t3DdI;w?FArU&Unr,=vS@UE"Mp?'ETG<F6a"[" b> X|m=ӂ>]Fd ƫ7߾I ʵet(\ O %siq[~stbeA6{H)T _ 0 83P(c}"!~j4(,{ =w㋽uF6[|+\pb@a:e5`+6ZB_vqɥ_y^y m8^4y_.G6 wҤ 9g&w.҈F"V@fG%\Sj&W-_ƠyZz-ة3;붏:`*of~ /@5ySx@7JWӼ&1raa׊9F5 w*xXdNvah82ܠ%`]!>G5x[qA.(Vx9s=-/s̿\U۞Lдdد9K+E oq$dSEHBm"onWW˿:|+crW)Of VȒXJ [A0+,X@kzlΏ;˭<77]YamB$_.Ȁ2BmCo@,>UtmuF=ژF=B|b&e^bϻMu`NzJ|ԯu;=5}2> 0R?3gð&/ rEa)6QǒTZOJZUT 7o5 ;9U9 z^<:*Ih,qvTؘKZpBTwAFcK1d֥'F]T_ф iH5Tt #toU5sL h%? Z43T{Dl jDMYC_$\}…R4g7"u % oFDuYݚx쉩lAʟV* @_9aVAKT@c0Or+0T(3G`ؾ7*zLN/pWr%5 eșҷqF05A.y iT6i( ;Ͷ`eZp8Kxqg|'VT, | T :r.wX%aߍ~ g"7llY\H*W3.*Jh6cF)23yOR9y("drD|- -wBdݠ4`L,"?ųVg7]N4J/9wl6>*FCU|8:'$m+ u>QB]2zlE~1+˓*\m.N= 骍}\a9bj\H "a>쨶-+ɉs:GB49.,/87<0})AQ:)dk]ע$VSƚ8JP,ՆGovS/UC}kGzmWBXs{ NY|گn03mJ=ω{Rcd] HFÈ,}qjSpku-.Y; `'+T =~[(sPCm;'J \ :䵬x}Z[T1ɏ`:tM:aF6cSd-t Px):'br+Hp VֱVmn_i[qkW _C>T<l,H֮,)ѱO,̛|gsIruae+='-; ?M@Xp(񮧻SKhֽX$K"i j{%b.Wu*u d_H vu @U[*.&4Y+ )ji`R!ִ+%d _^Ou2$G,RY(\/tl0˚Iႎ\7zZlK%MK=J"l|vjLjEǸ 5`']^oV`߯ u@y;Fm/^/O}t]Sp7يm_ٍ-i$6CҮXwԍ{K)|E1uԠj 2l~^vk;œ +>omvA)J!m;k 9t-#h~hv/֪ ~Y5 XZ÷r>\F4FJ Ieki/90㩤nռmLQ$.$S$-]9U~G{BI)Y{ )]/sѬ'c^A<{BrYEx >)p7H3HFśY:Qfa¯yuw:cS:Sph_.1)AYBIN{R Zadu8B6>!VKpǏW6:_^#T _XCi+˒'WjM ,Te $Le{ l,sTԤQຫMJ:,?fu RT32q'ڪN[ǿ "˳&YqP<oCny%wh4(7z@0g,\GQWBU"51h/ )6aقOrPkxMek7J/X-!.JmԹpgBF#颺Ϧx'#Uo՜̲0!n : Ir2e=ug<)WnoBeot% P\8KȊoɟjDd-=3@Q_P-< ί+"$ٚwY>3) UZL N:5FE$O4}ަ&{ᢓeqk+Y%} 7>^r$]uPح( rAټv8ʶV M"lAΦӧ@]/GAlԘ=34J)l%+8Du"Cokp yk,\Y>ae~A쵙 ɉԷ0iYT nsG,=!AJP}sWD\ƫ9L /~CxjUoo^Xm5Bgvky;QhG[-njT[upL7h=n7ߣ~ĝ@7*% 7Nؿ1#/_!2)hAqoxyНcN.gskQqxuUt |§Wl "4QU%<4Rkd,pM&/+?" V.bms|")kVR-E$? t}遗m( Hsyk<=ݚw. \4=V ӦW^sɒ߂짼ml9QR3N1.Ce  UPL\ngJ92'q6ZyIz`N6)̞B?Ji\ /˽s뻟2jͅ .@QX>r_ȏ$-k)Cc_NҼi+VT\n:rC&_WAK<')oQ>(M+:㪠9myxvnN';e\PWJ`+v;Y4Uɑ5FBFGwq~5!:)atq(ѩ6Xi.8's[k_Y(?"@D68՝ R9m۔$"_rr_; ϱ ΜkBar%>F$̫fhZkڂj::h6YXE4O'"]K ٟo/f+/ qRb3\[wIa啖ͯԱquy:ܤY "yVg@JET*I6BJÕ<6QZAE0#FTfuFz32EYescE?GzeZL@K?(ZR¿Iӭ%ZКѥ/6LoRY+j=kB}R/ar^O|T֮V$B=Ғ4wؒr{[k.N;n;۟A>*cISV4ԌS 7=^ 9Jwж U̘8?Eܳ;9аvxD v&=&VT˷3r*<,{Ϧ59\Fą-,q@#kf&0sٰ̖BI FsO\>t4LQq_%VdOzcb/ 2234mN"ԶA5S VD:d&7BF[RxG|EoD0rY6fkZ4fg3vz6 T?eC2.Ths8#zgg0kww{ Abu K޼5Ӽ@zzXswJ_ aRMWA}Xoփu[HTt9-d5Ն *S/`Q .Yhc;2iPq?o0 ǖȃlnuR`>/]VNtkW0GXG{xk <v~4dLsiUg&Fo\'H(#OXaՃ` 3[zMseH~hM·}!D'@cqȗ]-$=,f S+VNp^SSjsm񶚒>~w<'OG #6XF9  7_`OxK4ZgL#+:sΛ8Lh)_"b܃ۑ?C̽UB![9{iۮ^.6/:l8kCIXA nv h /\LAE' Gஇ Qk˕Ճwd{qM ~joyXYXa |}enSoidT/_vTl'뢟h#sl/ٯa}+u7z~z D<0\:Ly+}NKnټp`"bU)@ GE`4We+Te_MM`|LaV$M V,>t.(p)au'e0mw}t81Gaǟ~54ZS2V$I46wȪﱵѼ CvTݤ S 7㢐=e#XhlEprajIqY"dp7mz:OsR04sR]_2n̺ʎ>-mijG LE@B c`OQ?REz26>g})d-kϟOd5 # M#Z*o[ؠӑc`xhxy x/| VjgmCK_S[_^֩\`&6 [U,8LrL#N]ˍ¹+;luKqc1NC OSuɽTu[#| TR|ӱRG40?YHOM M)N3KJ'uM? àxKI@98B_~KQjƆunзPǠO9s=y08"v7 3%{i.uѲ';@{_NBW^k+ccׇ'"MFS˗)`o =SF T`=2Bt /Шr>:&*f?]j`N;: _d|Nȱa+ hمaoDkwitrHXsZ!(cw0m?0ADMY\C՗ihv6kʑQpfޜuz;|8j-Y#}f=y-^4*bM/ 1#3JGo61٣ IWП!;XZ%Ir2:$"h:֝Jiքҋd0VqrFA .% ~o=2%9Z6@}>r&ahSk3^=$*q!xkL ݇6=ډ  jU;O2\swA47v:1n!fEQlW]31 98O~thoҚl5AQyɰUU񢃬'7e%"leD lw)Tv$Hqg3>[z+ϿQM [~!]s |[,W6-x)l~rQl"82{ՊI|RQ\,`DӠ)O4تП8rh${E2mDNK@Ard,nZDmm& Kjm+A55ԕ;^hi=j(O#8յ_Kٶ(J_WD"4SVҽ$V(y,9PU꩞H Eǒ5<4bnڏ0ج֊pe^N6S EPsR+(mf 3oq!PzxBGmk'ӬM䄙M9M.r6RK1.\TLHDŲk|ȯƴS|,x4SO$y ޙ v:/gr7* *ӿė[e x9P&?Xm@uxG0f)&H"NVR^0Ry=ՔN"|\=q}K@Cg[ℼNuc|!?JDLw.A 9 b9ٲgR*_FC#p^k6N RUo}g͌Q7wp a_*1=mIMs<յ۰ތ.#27+H_0舨p2wV̖, {OULBJ{Ű>mŁ%oGq2~E~5J a]% s"ULNQpt% @*"h@)g9 y. W ظd:h$Ž~xC7ФtĶ\zJ&l9 ]dP|: /áض{#>Qί6(2!y:(AG_1o}<ܢ }l%2;\L jVϸ? rUeyzOa@~8C|3.u#K 1o雜4bP,REjs'i5K47_|PԷ1]T JR=6> 'OߎzP4:to ]a.nܣCN|{ˠGq7`۰7Ĵ"PʶaN8 @ox:Z$ۇ'\)&PegR:ɩ:DW?mg봶,F{ѫ"`4$\'j1ovB_c/h=put-w˝F? aȒ$FURR;+2:jt1+MKğm.g.F-ޫol fɉe*U_uqmm7 oG@M: fExOzljd_!¸L!UHө^ږMfe=$~Ǘ Dvi#MbIw18Z_oP/~8~)aO8%&.#XAT]܊d$Qɠt$#;qz"Jd2e0l*+4\ ^1aA>I&3!;F qa@9m`{' ؜r_A9.lj=-MKϯ\LyҟT]"ozm,@Vg9)j<P H1l01}K/ 4f 2!x&_U %$<9RCD*<У)N(gD0̕4 w-;C/j'R7❱*"3)ǧ:筂{KY0zO;ux\k__`0L=dXi)(~;#ٖ{ ҉^&SK[p΋?v4.Ξ|>pnt+-Kqlx,$UuF+gϚUh}D[#Fow'C5΄X qvλO咈"F3MԬ+h=Gmp^#,J3<%5'(Վ d]N*Eq-.<. !T,w"ڿbiH[fr:B;7mgQTC1UXP:)fpӋnC;-{8[4[oazaӄ̦A=\trE\]%>_gK0*f"G"FAsfI7BN55 )H[|t߸A^ 8(B=pq|Ck"opL^HŒVSșV5ȝU|_=Uh)ROwNb%d'qpuc=Dxi,S[}uMox %"pF^$Xm3W 'RqR7 u|w!Vx6h%~e&&5%:9IՏ Su*:?נ|4gw{"Q#αx v)9BR&a$qy7NТs,@y˘i Cxz, ,짯Pj?C/-w<_ng|-װAAJ!bҫLFb]ji9ɸ|^r^(6if8{B57/IgOp|IPZ]Ҍ1(ּw*YŃ87U{#@6v]rWf}e]97) -J?T S0>|dйqlT4⋖zg;GUf0 T ڨcS\37'Ϭb~9vaO ?EKFH`~s$[w|iGfJ K"aPқ3RšswZҕM[urd% Ό0s'mCR1_j}K`NF$ -&|PKB(z4Ǿj {L&}IS0&yLK񉡓1-hM!orTNJ~Ƀ A$}"83 w WNfp܉34=IXqj:s% qDF $; r$-5mԕQsJJaDg;T sfVEB!3' AGz2[8d8,hC e]+u ^,lt SY+aFE.Ozz`sC}(+ 7xD{K`*4pt1SR|R!%EZZg$QD/خTo̅n,{mt ;bb]LXƴݨBg>٩pl\tx8JVC]S!S8(~28Y!Yuq7ܥ]&4{j`hqã F^ء#i'XV*_AOJ%.)di,ޒIyd6h~.Ů4mi!8ٗNTIg"Iwc_NO/=O/.`X*FC@])E~#myp]1\j*Y% [ !#O@/dm]*/$<'@Kgd4'Ol(p:n¤v6kIl:w~N(aU P=G1A7ݾ xl$G^L};mei+'9xd$ǃTYx:Vxh:&NeH;CjLyˈ|c:*&82,WAf' FIl?!/k %- n<IhŇ 0뼭(06B~ a)3;39A>q$(OԸ¥[ A!B;ˆ,\eqLb?Z$LwgS)1K#HEYB .J5i'^b U(!ႈt]k?]3iO.I?%  ZTG.HT, y(]kT3)" myejXP'JoЮ~ h# _Oo+U jX58;cL'nmz -Iq Z`NH㎢RJUypcBJf˅DR+Ʋ0_&3rOw+UƧf|n9Zp ) ؎ml2މfcoC}K)F4R0iG{O),Sz2``<0>\t-KcbQ"2_pS[e Йh&xcpݲ1pqv x_o#yȏ (qszא/OS4Mj8R ߯ŏEE$K(S'UG}#%fvO>V.#3|i "NϦQS0c\5wXP^z)3pkYHp?d giC_hx gnBdQK+q{mViVj-!kfz[TLr'e5-=|NYd2H__`=,FO+^8kBWmu{?*x]Qѣl9Nb ȜDNs-'&%[\L֒* ; Sg8܅4dۂK{;ur\p F| +pܒELc7*luagm-`i9ƗDR4g 4-Y3bHݙVc"]]VKv;YK}5o~]$9=eve<1.\,Q+xVJ 4H,`QsKa,.)¥IN;Y>A(? G_q!5#ǂ9YMkP;qmeg D!|ksQyo>ŔJ2]@!wab|+2ZmҴyڕH Fz.zKa'UI~՝!5vohN rO] a͎=!\ XX$yr*)mxЋ$~@z8jfaGӼq/AP-EXʤ;$4"hԱ԰oMկ=POGxj䲴O8h'8#O_F޹=Xh12%l,LaI8kU8a 2 ]xO+NUUF'>VFiG*!)oBH qG v:ӰN&_mr[ @uho̥Hi"hWzS;`R\oKȷvd(^ǃZaUYz,!ZjF |3@_#vp,\͎|8M g<"`EG6dFhC: p^ߎklPXSCfau*Ac0chW.Tir@=qi˓{RWgyRaqSVP)<*OzW %2D3 byy,܍ۮɢ1MJYL搉 nQ{8.n{YYqFex^Zp2u: qٵ H \W"}mWx,+ *nb+E`UzxWNlFwB%u|MC׏`?CžlAn%SߒpcD2A3ZyOC!Q_<7AtV=9eR8Dզu\$䦔J@i#E`uquyIDJGp@u+-C5*S̚=m"@lk_\YWCu|=KDŪQg M=Z~vOȸDslmTʁ|s_? >V _y|bQsZJ=I&&/|aԝ5:m%]EHCAg=4Ҭ.9?^$6},SZwú]1QԍQ|]J"*d4\$Yp)ucVfɤC?[5u0-n1BEyBDL1y O' Yy~s3bY[4 C+>~ k:`a \EAJ^#zsP:ߚp7d?9L%P3gQV~cJe0™F.`,7cr3&MQ:b'G[$̽A yHaқɑG ll% |O7VKۚLf0C`K 8u3g]g<ѣ9yzjFl˰E?Y`>?į-KY^(6V~kxG%hf h iX.z r Fׇɵނő"h1wF漢avNKR'ʾİ9 6稭@wLD*$H,_4jV3]˲ۏ"†œjUŻõc6&S[gjA*_<_~4_>Q ȟbGrO9 %@Z*/CeT)lёbE@j׽ՈTVi&_c%l;`5,fKo̱vZTym62Ǎ'Rx> !C=WFqvJ^sC'Y)./Vyx|wӥ;qw";oOм.mmL {px+aN$\bBj)mz mh|?"!x pTW{, ~KTk2f"|T~(v "k\bSywaoM%28R_*ONl L#5dy͝5A  %  ӿLج)3+JΙJv1!$[c'^)]C312P]Z#cÎ^: .Lo|2zT]2YnsjYNo'UU2«բ}wխ&V&܊s_X}xԷi$%cR(Gˡ&=&uLd+DhԌN:d;n k4?Ha.|RuՋs;+,pѳ<Q/<ؔ0?.Q4N㽧F 0:hA*b*iNEo[]A;'My\^(j7rqUZTB 6of4R%+h)uI ,Ҳ`2Eic~r׬؏_{^" $/+ˢ 憘n)|)J\*sJŽwtjilvNp腦XjW@7gk,_0o;zsӄ)N'_<^e~#`r~]J4Ыesˌ\+f!o:2>vGAu-gCU.FIMQw H,56N=x NyNe\ - oAl%N)ȤMk joE#`Ij,+!?@-,#VX8>z1u ׺. 3( Sg!¨:}n˺W>%Z8Q, $r/hq5U2LpdTuOk5̇1wR>8ᖀRyn%']u{&:.f|JI\#1ԺP-[S}ӛw] (,JF1E@3o݌[[s(2o%T~|[8 !n$^jPYt琰I?(hìO5cJ>~0^ؖsͶ/p~`M@q:|/ƫ6 BQΰ6h>HFdһeAحp馜k#3lG\b{,w5%y%EǑ/ [+ 8+vF?;*s9"dW)BS—]"]պi5d0qQpqՏP(Z8 +֗@ WIJ}hgHg)Q|'*!32u=)z\\FΎ`=u$fY}7iPt{֐%^0۷+IǠY3x,_twaT^dd+\lr$MϙGXYbu x8F*0 iԷ/Fb[f[Keպ>>q\9Bs*Pu-Ca0-ı"z̈́]O|88ɸ8,ωG1B81;zQz°3Y-O}_ѡGM`e=!"{W :aŨ L# D)Ti d+^ ~WSu Ԭ+%WP ӈ\ċQ۩3~Fq;!WW]IWCewZqHl+.o8|_ộ+CGO7'rU;Z;ҜX)Way/ЗZk5QD(JO|b,Ιwƽ<.H%$Ghc_USOp5]Б$ l{$ٿF97s7(HEr D:0]7c_nj#TxFP{P>.jn*$D]hy`6@&7DIf/ 0y8M|fh] " 9Oyg@ݔ"}Tj6:bv~ꂓȯN*D;S( @>.QaYo_*ͳ~UX" F7=ԇ'g1*J- YCq#ӎ_(#sܧ_MƩv'ӷOګ 9vf} h(8zK~(GJw8̔3CcD}s4d[6_ņ'Xe%|k|hIgߦ MS³0UHmWMB⥶1URw֦?˴`P[eu*+{+cђ[¾[|mdz3 %(c, YG9]b`z%B43?',IH1\¸(;!i^ ^̀UK p{$ZKYkއFKD~\kKc0(̭*qju¦7P*Wp@&`eKZ?4,m۞2d>B\1=o#;*:aD_fM{yƤhE<݌nRBY tiQ Ȏp@p^qˆEȐf4!s"Jw\bh[rBt(0Sm[!&oK8A엠KK?B+R;uEYƻ7Rj8+t 2M"Tu빪Pޠﭙ Nq#hsR&5d*r1c&-E9E(ցb7Gcc zDQ2y"gV{BP,^-Ti34 d,q#HvoI18VV-EW('ۛ&[7ư[ؚߕ4#ғ +@QL\@H^V~xVoX==XWD. [|3BE[^2TŤd7rB-T" (]T >W'Ev`?Hb sk`i}eW$D2x `*m^d@,;(7?uuN ~+ՙolC$pA+ ZUS,?- 3eNTOP] ~= wNK:#s@mBh_nDzkv@|&b|1j2N!/C vq$yxڂL鎽JQHQf,x1N[\lO=iMjեaWJ%լG[~Qx܌ާ!JaHōfзA\5;Q@vQUrWcH~m#7FFb 8ABunn-]t[T8KI*?Eyq T7wGS&1&iF5"9`,Q-3BdPD_I\2A n).VN$jҌLJ J F/)N.,>z7RaEVZ8E>b9&YqKc]*aÝIE= 8}:H}E6*8ZicU_:iר!^ WK*` 垠MSr.cUa ,m*BkPt0dn91q6}A}WwN\`A4D/PU .m%Q0W,KpE\SB4)X[8_p.ͥFB{YgPugNĹ)I:B1҆O9j$z yI"/\bi 6F\K=Jޓ_C8^re/%~gm uϴ`d/OٝŚn޷O7 wGG "4Qꗨܝϕ?a7tke/c[{šU~ Sa Z ]͠q{i3D=ᗏǵH*Y5p\U_Z-.wދyE-&”]cwjjp%9I!">?SϖGyPp]&'޻] 4Sztr'Ivy8whI{mֵdT8Ø][/@>)P9z9Mys2)Qy9:k녧Xztnet&, 0ejDߚֿgQz[%1'Ŕ_PUTq D֨U:wTƫJ&"[Z,tv>~*&U{gMwV~+9^>h\o@#%ȑEB{;ۜ4=(8BGmR@bHߕmxAQ杴\l`|e@[ {! ?znS#xKᛔ'fc4.WRň3{z׾!}[p}*V_W`؝}H"|d\wdKQ%n"ixs ⯡j2wY-#=˞x4qFӘAYN:xgn ph8p<8 J1Z.5kx>v* ٱ+^eoxEy#Gt}e 6WiAUu(4fN9Oɍ6y30}qYBjP _Gmk={yuX6޼ӛqf= `#˭5em֩IGēNz+ؽ֎ڋX YP#x ^0v{2e2e6rэʟe]D*^dEr)"yc@Pi!% E֣ZQ~#\{^"G1L=HmbGnW3']>f&6j&3uf#iKh% +hM*l^WƀQGM&1e~,j)[ؕp!YKߙJ^nyZC7c40:Cq}Fi;%U=cS[6Ѭb0у!R3p[}nj^IPPEyD"Fp#>ɳQ١&cplEX{0/Eg)6ra2֦!+̒ [3фT[iEu8qK8Nnq, ~NhpC?=}9%@0onh> LJ@z㘹-E0|lv߲in1Tc`Ÿ@:M4 P:Y:|k(V ʞ(jes]΍n)K#Mc9 i6쥋oæ#t'<߮?: $;K-^lJ79jbgZė#92z۵*_[&j.mz: MNYԆtW p2}; cvEy'h=H ,2HJsPgAJmGg<Óyz_6 <ךD;rPKdSZSWLeC)QQk3PǓ'4AFG\6@]筐 d_Gn܋ Nb/kkrdſ"=qdpL#iels1V/\?RW^g[gGAG-W/-.MJA4z-_Fn?-US`p,[ 2"7xd(tV}uLJ(։6t/x*gMB,k*f1b(c &]Z,uyLHq=h"1(50Ww~{R1UpD'V< #d}N4y+gy $(غ@!")ʏ /RnSX"v|4,}C׻Č#r?KËbR2$Рo Շ@yd8P刽P&stю2U_7mA9-$sҘ%P1Llih.@ba3lXHpۤɏDc-r#qEDdfi/XRoQjuL;4c#!u:Ɛzy(:mJ{2qhMCđ')|mm3v\t|TyHW1L+x @N+a"2fBQ ()oR`<+[Y>X&t4ف'ڟ}Rx s Kϓ~̷^jt#b*ieY2cx"å Xf$b("!?\lvvHco:5$Vj_pl]% YWIr/폣08I!@ӟj3d`NL nVDyt>SbKM;Gwb8)e8G`Z+mL31A@4w6qԛ r8CA,)FLEyQ7-#ɞAirl,.0Ͱƌ>gt[p;ƿˢJw#/haܷ4pH3ƾ"HAL^eΛu6mڍz&6bu|kfP x]} Sv-rXj;'ῼ 5. BPlVDX}\ܻS f4TSj`В@/4)+"8ImX| G{G ?"gW*d-] 6oxG 0M}^j+7%y dp+B=Nq1bSwRQT_1֧=S(TB d!9. AOE?K(b`" * AJ &>*uPDQ+Bn2`6S.rNB/l'QuO&C~M[efOICIy&Rr+߼ѥH"ük5cٍ.̋')GX@"ܦ;}/eh G^6vخܭr! U)ekHHz(U^.Sgg7'L3;6 Rv"4 s~ -l|D UV-}Olf7ƶIІo٨sO56Rf~F[ {# b{ӡi/ P{3ҤNNvQ&IjJ?Jǘ)GhB~J{`RlO[ܲ~;?zE*SӘټ4L)<9 (qoISFO5^!\;soV"Z6ODSHkЃ+B{' R-nεs|q-7U^lWHF(!;ٕ x8P/]FFerAR(# V{Sw$0U#lM͝f5VJs1$p5E0z1ZP@ax$zpƕ&*%Bg~d晶~"$ӍQAS2l</'3{4 n9Oߌna*{ h/,V]˷P@ӥmxi5D8p[)xYn)N_j L(80Kseӧ#"қY#` Ah ¦})n)T` {G՛NЁY }83N\R*emͧQ'ɀf I09i_RC, S0{SQ}l""VK4Ppnl({۾xt߸v4A^1Հ)/^\!<֡\dŀ˭cWBq:uZz@&>BV%C.0kPߕA}z^x"|)1J!x#QLͫ%Iؘ/!3ELG}gm_6MK)J%8̳* gQ Svae'"r|̀żoIs'uɣPmQ:iol@Ƌ"^O㮦= #ܽesh%Hn,&@kg J[ e%~w=QSE\I*`B(Ӣ!_jHb9oFE: wEeChW6k]BMtBkTBE 7Act)uܹYczUG^^%)(lcW'RGm^Jd4Oz(ucSҷΣ5̚.$ŏLe}JN }-5E.1d4ZIp૓ǖs`aLɫls9=+Q%SSW Or؍-F>Nu%4fVܸs 59>2D6~Gm$*ty?ӟ߱*J 6Z?@ y^OT]IYSN7xK;DZДTs[l[Uq0$h8jɞC mKf2eԮHTG%yfsy̯3^7GQGd)@q]\ѥ% ;Ge:0U: G9 A /rur}qW:yټ;P Hz|$qk_\0*4}o0wjQE?1f8(-O[X]/?^II+L>%>5x/j#ge ΃GA!FF:?K{0YYK+E=~#vR-? FSOi0 EEƧT|Eb)`^!LFh^޻et>!mQ[.6رȠ*0)|FlH*JS0نu/%[pB%XZx b{#h$RΌnc h*k&d,|HmӹǯfI13ukV.,*>jMj>4]P{3;@pM3<ץ'Ir뀱0wA.pL"F`C̈Tgi7]QI+{|G?|Ӷiم ^͘ǶYɅxꝊ ƥco\!$ lWV7pg1;g<)1֟c nOmnD(?w,dr U[uY%sּR s@%"hyӬT9B4R y@ }!ddIZ=I//` wE(t{P̺\ETQ*YJ/ yjnF4lT tmQs뽒g] 12mkk w5`du a(7n#&T8N0/!2SHTQ%yIiVfIw"㥥`ed摂C8Y. 9bX,:݆9NuN)<+xtn;@ςmkPWy J,p]P9+u^-^YuBwEŗd'z2.D @Hj8.iwιBASfϑ :vm. u1!<܎ΜКy{P>lYM[Rӹly1NDIӭlw޺zM^2'Lim+^,Uvxk_;WVi̕X \N9Y>F{v;6=ޮZ Vu$S+oe5eq6 N7J>p92ucg7Yǰrd-fuSFB`Ky@U|$"K S_(Q-\lDȪ=IHFl>NmJeJeJE٘y*# Fb&NU 7TH3uriO|`z)=ߝ%F\HuR.,kdh$ؕf `\\H 4uca!O,H3s}륜vtdk<)Yz􇤀* ;FGy3ޛ3kAKEN}#PJʭf&xАR)ogό)xG{aYxI-6B0: |POx [iˌ:§T䬆W%= U%Z5Ad6O8`toTvگ2q~9-1y0+Ogfl:OX7^ <XF O n dAܩK`%MF*c+N[*mFa-X??f-ڔ+u^EpRrA "ԻY9ʸ/1dﲤ-^G Tqvb /t.N+S }sN+'yP%K0dZn"4|_BIM8e$cdBq蓻ez!> Uky;W{HҒkjϱ-ObmRQ=YF mX:д=Fj8=Q1ECDoۅXCx 8o^"r7c!;'{Ap!КӧC鑈la eaA85-lQ~uh=OcYgw7WO#!@%f_ 4o:8]A fWR#flb42 F XQF +x ;[űvf 0=a]-u6BDD}w))&LGO)VK{tBdC민'Y~~mf(&j #mWWlj{6ͻ,#sZ'_sݎ)CVӽLgkd>>S]o` `z}z('Y&bJN%|5<HUʠ=ǝyA-@AaY4 ":mԏXe1a{޳A=}cP^=gd $#"?" X ,[/8wDDvW=W$M;ĥdm8FrQTw_cƵu  9^殎ےcq 5@DX!(.i/O7NmLR}?ܸE/PgW9qMȍ64w4 (يsCNQV'/-lh?!,BRp}ฮ)ɂ̉#*C?xodpJU q.-L__& ,>GN}dj5TuU53B()E@7:l}3':QnvQZϚ*A,èBr\\H2v@Bb!{ح[D[ ڋg>}$`z^ʁQܲ+3fvǬpTsM\ff&i z$3Gۡaa'SVk'[ Ċ Ԇ$ hb@.ZʲDMe;}/@cj"-\)ZsQt ]ekAk8>aߔFj9ƒ̜iCUcOԴ3[̠Qk'?DkqgA)qil gV-霮< k-\4.S7p<"Jr䝋ea!E8҇yÒu79W}WqRqTfm8^觥}| HTCVF:^%$KT쉀D̠McՊq~`yҷ.'|31kTD:nη>sEB\ʵ+UtzL k]Tvh(Mr<+J3 ԙ3jFe#{W&K_[ 7Jg3 ,ѡDWbs<0bK,޶{s#ӆ6 !k|]NF +'7Jq &M*=t;ίm|c(|"NNrԳI"(vpW ҫ-psf.SQ^1ۃUf5n(v>@C)wsw-g5TpO#1r,"/yEZ4݅Ϙƙ9A5h21ɮzG"b-*bn>0ĹiQ5=G5#1@jQ6^hnfk k@˂'6/p$ ^M>~yQtyD;y;~ee5w WvՊ`v*AuHC`qlqlj(MPk["BwMfhBTъT>lMhoVmêgW +Ko;ڪ#n f&zd73Py DIk0WM:`"z~:ՏYyĄTuWrRJ9V DveاxPLϏpJT7q?k?2@q@<؏ܥB@y9R:lKy-\YN;g&eH}kkńt,Wwl$%p"/ZRo-nn8bY"k)!F}8lZF= $:ſgJ$a?BRgY }avu lnT 8T#EqM杨QF"֝Ҿ%[xY"4yt]U[6꥽ndqPxs4Ҭڄgxqu@ L8`ʆا|9 gq<3nAq!H2\wFAJV%$3n-,1,1N&fon^&6So9#s}vCI/a,,Àk` GՔ >J툐rxߠKu $b5a55އ˴}Io #l&4҄emdEy_ L cioTA~16HVϩ 8J2`'TăS^a[-\ݠ8]iƸdqi{{l"kel99ySOֵD,ɹV|<a&*HͦC2&5ŷef嬴|| YnC"/灶Ϸ) xyjPrV`Xֆv$nxr "œG:6+ѵ簖WϾl+^>2}|P;*E;r~BxXw.bSqe(!kF@!)P8;đ?T^b,v ~1(T&R[VyU#ʏa|C5GOp+cPc+)^oܶ>= |pVG:w$k5??š&6P1ZhYTDр\Hd& KUn PgvZ =kHIKrӧnPKA|@%b3le|(&2j&VfQ {[bړ~~h37;ΕJ Be_ 9IH?ZqfC6`#hVX(B+TW98}AVG!sV3Bc<=c\(jbP@d@Zg A&"ybRهLjf~^Ii(-rp\q?+PTZ}E˱,tw4ϕwB]#p)TjNqBWxRBF.z62ze3WjIFA p¢8~T+]s!mr'[I; ~ f)`t$@Ӷ~om~MzFMpLxpDtK EEj%n죠޶BFJͽA ^GDr*ɔ`}8C+4mr#8`cG25SmaIt_6D59C/=7a}A1>xOn*zY,02ZICRʖ3[a;o".Q;{bGnēm߽b_ {trSm+{{GE'f?nцm XW\DԆuH\%|i לq Bb {'R6 "[C>{<+@q).dTT*v?E="8gIks~x@sE=enHvӅt;,% c2az6gCzc \o Bӌi@s hRT`@RV?ZѦD$M(8}ùs99H*?$Vr+ٮ@f /Mx$oh֜Y!raR9*Q`>g(Đ+A=f]owoq/3V0xσh?Do5ۭ5_Ԩ)qGc m@QPqnUlޕ?nj?rxwXA;X,"W:+ mډy ΑJ7ϯ)ٜrO{mi+- ?{w!2}3" vkT|8l2Wf8O= )W&^үcTSH)@ZF:`8h(S"eRP0B4) ]Cc]@j'rVkr2-Ų[bn8Ƅjը5ga@fJb'-W΅Ubfݯp"C (;2ga5I"r-k gp/@96Ks2!{+yH3a$уdE+F)3bȺ6 $֥|QLq}## Its@N鹨s5΀gGeRM+3Vyw/fTlGO^+>F n**m+BX6,=6ya!lxZ`V4x/'_r 8IR}rvg#D.i/I ʩǡn⏋Ip) B&玶:4Z?Rxf?F}m=B{(ӳ}pa} RుLG(#H.Mm=',2š5{U:~)"+0=h3M@F MQ>ݸ 5S|ΦqŨZmxR4йYurAjq7q!~%KpVNY/^VL3e!!?0u GYNhh>x =29v\kO 6V*:de9y>bXX/HCto9x]+Dq4"d;ƠH.'P:B/X14 ![O:}n}zlbm-VV@Ϸ;d#>w#ْQjhB]pś s &nG8C[n T064.k?@>>0"\ 8<._xQ/?߅aƦsHC+'\93ŌoQnJEr*[xϾ[X[`q9A\Y<5m:f]ic3)O'6KAYGZnew!Z!kO1Eڧq 0$RdMҾ-Bc8L<#tp\*> 㖇DX`}V&R[28f+LGPQ:GFfj(Râ%Rң9uZ7c=Ѥr^љ[@DUqhǍv3[4So5BKEoܟPj\-2{8.j@-T.#?vVÎh.K|[Uޞ7W}7wBvx*#UthȂ-rZ97 F}[,*SUl%AiUL;)`"t=SN&xnSZ欒G'r@'|$K2>4j%zdmqcJ*{3SZ"2ߑo޳7AfZ#=@[jr7zтM3W8#= 2E\Y>B *S^,S fG++xqQP6Ko^hoCt|6i]8·Rq>|l0^n4 mbUY.;\k"-8Ѹ|D_m@3Uc@Zmua6r"kk6\lMO%Y@Z?YҩKt)VǔeP4nHyM 5G'S]s 0cd2^[ݞuKd>.~YQGf@ؑ$8a Lލs)yDDmԢPITӯ|݀*(oo 1R)Ѭ}]}yHn!# @0Qiu 4zp(E2NsII-$`Cӊ/#MFL(fcXR(zG; *F+fE%8hWT1"&) b-Z%" eRZLK J!Ƒm^)G'Iu1 =ה#ݫ 8^B~Ĕz73X1|E+QY>{˥vp-mgcBgʇ}NhD yba^'RA;T4"skD2r4^y b|i bu/|8 {k"SW*Y! Z*`-}eiaWWE&#}e9x\ZY|DFN Ht oaw~ ^=:Ĝ 7+7 N]?XiX](,oPcb) Nze#?}wONnVBaop1B5E/h7]BN*rM^p1]%=*(闛0!!$(" D;?ArЃ[Awy"U->DWN]oN BbDJp*r$}-O>fvcaib11S喎mWP'7aCDwXdZ*_./^){L/~)?iAKi Oxah(CbLj;G6F,è $s֔gEz! +EoEMJà/Z/1sUEXTfA8UץX2 O8~^M'k~A9:S~B~@YoM4hB.{?/z+z" 4|"i;ZWmn[H>!5ǰFei =P7|I$DPWfߡLST|YܿV kH9 cg:)PLVəi߅ƿϮ+YmT=J CCvɪ3 aM=4*~Rys)qVs)w\aT` ;T1G[;τYNHhy ȯ~a,g#ڙ~Ip$胩?,_m @{jGENL&@wtspjxp E? ?pimj܂9eMU\Bo)ζFY)SzC6P*1lַnTf4`WSK-F BY>˾ܵf?'ߴf4Ze^T%e0;z M=^u_lRU@lW^ G6j S4_6t7ZA}i Xݱb5PԘ/Z״{_N5! #0K*=4ܧdqH\WtuiJqӧLV@OS4/ڲDSKoJ FRYG kAӅϘ3FQ_E} 9_I!W[Pu ]sywW;ήQtc1^> u== j 5gteM|faSj bC`TIxʲĩC{ШI\5@9 Pj4R'I_SP9IFНR) 8GP=>rwSg)9_|b^4z٪ *5; SkuGe;oֱOŚ1)VHL5`A/ LpL^*Ϡ CS2%2cU.׃K!{ 4^0oEJVpt*3Dׄ_ BTfAvRL|-^ۧ^)㉷hFX0٫&T~<޳3-WvYJgURrn54e}N=Qfϋ vc{= @b32|%)`+F.DIߨ#7V5EV7V2?HϢIA"QChqY1,3t[] CL 4YQ5_in=Yx+SogkDRRO!s_72 wjPU2Oqz&<3'i"TK~=8^\51夆1j0K"y9B9zl^=A4x̟Y=i ] +"<$Q9͵6u&͕-H3V? Bl{Pv(#4TZNA/)'b&5˘Tf=$b1Bhr&7ʕ6r.w>#HxbA1-st|s!Qyz%_o@ @|qc[h\s,H vp ^0p(Uy~w^h [uIu|?^<'z<~eC{&,׊+w'AM-TӐjmpSR-yW*qono{@jh;mxԁ"AP$ W={e:Ch8K>à]4$-Tٜ:nteOVGmrc#uqe#7DW4,ClϤ-Έ 9EKd;Z4%$?R7.Y dQ%Hjfu_!^xh9/.w.Sk>,|'jQOTgV!J!Ul nPV,7:}&)!0Q gjpò-0(C4^ Z<8R6C^ɦ hpݒ0ٜ*T\$f&C Tv[vmURv.LTMzk $PAF ZѱXsV-NǛ8fZ z!-zRE]wyG$ωޖo#]uqZlpSi{;EBPP5l"MJ!35Ϲ\X3]App#@F ނ~p0`NW@bG\71 xBlZ'1H[QOޱ,!_*:~/&oщH@)c dȯVQuPJS;?MJQc_RiaNw (ҿfVjF8~s31-ƿ1>ڝa`nFf TZ[,!b2e@P۔; ,JTle=zP'm>Wd RKP>͐C=/JqJ$׍;o~P{4T[ Nlqp1?[d |ՠNsY*m32Lu[ח+ɾ9 Up|+oȻ$@ޝnD^tr*@x$^?6q7q t'n8 aEsXY7>2v8ACESCz[L: ΡJ22ZffIHŷ ߪim2WtR*횋Q&a}I9r 5q媸iXLiI*Ĺyl Y? :`FqA2 V"UP!ˊY%Ut?fS$Xd6gcEdYM=>DH6m/|F#Xhﱆ5Ӳo&PuN5p=YSV'v vL A[b<5m΂s')3C@SP U@,.VMKIKjxMh/c@-b~CSh&7|nGtIvGȕZ?X޿i, ϸ{Tr5噾Ka"7/%!;sL p_f@le3kꖎߚ:j"_hNHfSZT1b<].k\tmAQe9m'v^{!e]t.f .F׼?Qu}2a:"x7H0ɾ.S{-F<֯gJ/%*/m~?@?QxiĮ"L*YCIzLMXsxP05B`/lUr I_,sJv=)\ 5"6]kyIgc.r˝D+KD) $'Dm͂ȝ&mۢ3 \~Xus bS rWP<%. o%޲Q߀ZUbz{ 0(7QQ]dM@d?MGZb*]L]?7vzȝXG魓yjݘ%Ֆv7k-dV nV'Y<(&y;4Yxr@ w* NEB]&AҳC=wf*E2sA!w׎f1+!Iw3ܘ3N'^ߺ {T^Dc*is;KIp !qnZ=.-Ck"ptـ_e x:)6%B Li<H= I K-١".buHc~Ic0BHD2o Q(@k'~@ Bݒ~?q0c)ޚy_jG%75S(6ph;<^M*}{E?(`]XuCy~Xӆv\ Y>\R;}Tc[vlי&T۠ՄGN*a=gp؊rF}w<#Uh^J_Bo^@GIίx}CE3g; >b8ڍ,#&i so*Qg3^2$D{k' /HHͦD%lc B(|Tϧ(*IUFiMn hv+ZRHLN=wq/qI/<1 |NRͥ'۳t Ԭ捞O(s|8WY6lcZQZmՎ^)Vlfp#PR8{Y32e)ESئom*qۿUA3r)l-jHS:QEz#ʎNqN@&-](D?-4 ",&>c_XƌAr U;E *!`Ls9c-/ ܯۆ!-J>Z׋ 'A,GJ+սcUL z:DFGF@tƆ*>\2TL_b oP2bkҀ+[qd㾈œ%ܤ@Gs5Y',œ寱;sN޳bTͻ{\@E~YY81g "אIz{;>HǵwVޑNh3}π~V)F#V*Z=BΐnaGhEz۽ʍ4(ɗP8+HI+"|wN̎2oPUfIHŐ +dݶs*YJeRlfB'9RkPf?k,yF*8H 4g !zw~@.vOb-n I%֗ o]Rr/9Hh(lF#b9J*ʶok ,y'Kel elTx~'EK]$L:T.AH:5!Խa^Jx#;'m<4&m+ZUOڲ[18+7ޘ(HR44D7+ȶ._@oaN #3*L/HdF6mEKD"UP$Yz#>5Ӈ{,|愘ӯ[Ӫ!vn*YAS%V4߬%s1Q &JGxyUm}Ijd:lӾID1C7: A~ e┇ݗXȶldma?$#cN$Q~e2ht'8mlTџwV5r՜R ij묿$kvVBܦM/0S#hkwiNV\v:Tw5PTxy "?s5L(&TDWYw5(!DE5ۯc,ðũ  !4Ĩ!叞"&5*:$4c1{W~O V];lczŀF:Ɉ_}dK_:~Kn-9evYnb^?d8h5bΏ{5tPvOy38wi]ueh%/Ş%iw]br [`2]g"ylk7a* qDO͖%+j6[ #l~Qf-i իoԳpޖ =jΙ ǘʠ%xΎ|'ZP>a}BJ3R7v984/h l @WkHːc sa'N^YEԇ#GrFM&R:$R!sܒ^*@qS2K ޯ2&CcYa~A(޶ً{r/K7cr[W=1z]7IC,< n ]h.FC)]K =ȆNϏ+t@"-UCLД 'i&SIvMdz68FT_w@&JSVSdWƯ} }r+my)-Қ;d1%I9sѢ ~^@b^) ]-jJ9yЍUG,S3 g_9#|˭eK2jhXL&WaOFҊ w|vfM__[/i7d ;.`Ԯ:] ʥ<" wGj\nIO0-~#1yh"G%-CvZ29A c+Ą<gc +S!05M4Q3QY4hm ʲr=ޘx3utBzߔ'Ӭ5mY$ģsO"E[ױ 唯5|ysW闒|Ֆ_\N4)y =DrhjǟL:*ȫ wa y<:HUFJ)@Fq)A-"7"q%q7dvhD̵}B!2U8B3,MA^½qed)U)t9dk#ꦜA9\8$MGx1E?++cIĎ"xt;+a6,-'lT'O`09$,)rL\'+4/kҖa\/qEf%N?2^J);۹^.!;.>r}'o2'4aF41{ !eБځ$2"U-\dS~qG)`"N3AR}g/8ܫꥮa wOdtɶ|U0cIIK" ROͿѵZ~~qMA-@,w3([~XtN~G6w4ֽ[!W3-ďQ1ZM\K@}EOd^yˮ$_/Q3-VJL|Wa dY1Y^ĖZ@,2Pޫ3@ZjsQϻ<<7OTy࿘{M>2M! ތI7]_(pp -ċd3oUVK^3-mF,o*rv|- Ce c~Dk*%숩K ͛4!wi#Z&, PPg#nΌ8Of2f$; Pc͕ɽ>#+qi`G QwA_\e.LbԨ`uNW!~Ca_n-P@&n5})e_M2P;B,4p !krC`מ" h:IR٘k HoAK_C,Ĭ|Gb%5-"5m/5bަ4pJ l;XFzྩmN (I@+:[BUt_)=3.%$UJ .YmzV*x%/:npFWmw{gTuL>8caXȯ=pՍn[*R`~Պǐb0;fǃN%C%,RAۚT$alp[G?krtl{Fq`2iƮr6 =9KѝCž;Wdhjuf 65ιLt ~tD3[LdIX^?2Z}>DEor&-h=}(q9[# J!:~1LADzg77J~5T5Z1+;~UMf^rbs3 6ɗCpg$F *:8pޠix89]Ͻ{VQsPI!OByEп63aL6[ ^Z7hr/9v__d^49kh܈4p,;Ox,m1تbx32RY;]X_9um0z^wAb,Fy+jKzr UGȽ'T`و,PHd*y~o>*״Hu&d.4q_xЄj99OQd {b *i{ޅKHpo9 +F,üL0L}N]o _G%!j+c&yׇ`mlk C< erD6uh6x>f7B[3)K3g6˜.VnAĬ{aT I d Rr)ޟOcI R2'^(isZmym@aޥk/|~'"4o-%Hg[`щ8AF-IRY[}TOOlT}o)OtK"\ѥ6G 6B=1i;!6bBա)ٌɼlԠ.^}3 RԌNw| mB(u`%չ/$χ3iW Lkx6cZ $QDsWO;FZfsS<[u(c &M[fGOPK7^ ` pQu)9\!_VnP`^"<(hmOw\ hiW7Fl2-שbW|Aw}u? {ک$8w*.m+F šF W9BGjZ`ƓCt`XQ~mr{ACqۦth}m]')zV^no%z^0'8Dc_9Ic+"3b-Ae:B<2$T:4-lgC$]^+h@1*fe1($-4U^p E}4"W) 譗.\P- |dstz.L Cƹ tzqL'r~Q"Tv`$am-Y(ư. c)b/'&RS^aUJ B/ r(wҊ[$]a`T"Q.}%K,; ?≦wxN;0KSw8O9̠5bVُn6&Ǔ۵ 6F6(bj R` Qm0 Ώ@mg yisbK9i1@3”>vZMKȹ| GHڠѼT = zrE#v!(Km>Uj[Xیm\0ym`sng@y+7߼Mޝ7 h52Yk IU *i J~!N^㵵jIjGo.GuOtS#Kq37!c:ϲT(c?Z3oU&' Ηg0jw/ {~S^ ^G]8ĺh Qmy9h&4ѯS秚 os\bVyw*MGdiX?B`Z%oMnd@uy{}v8п ?9.{a\X7VlV~ik vdB!?=D~D~GW> ^,0UV-\JMk\*"J"-l6ã +.lMR?FP eLGj(lellقT~(P/+-&!Gu| " `I*nXW(?~.={UncdĻOue^vQpkZ& Ň;!T'p hl)usAmØa'짽SD?b"/mg{N&J{6!Vhm71h M!ڲ9q ){-o#-Zt*Cb:؊԰ l!]cȃ 0v?.LY^kv$U 9aN'3!~xr+=5LU]D>ĘDaS ϖ(ir藟S9}RIfN~ 5oƖJܸJ 6A[z`3Z?!gHp ND^CxnxX]urN WApTv04 ޑ.pm FD|BO\~E^y9aт~ $~˻0Z:ѿQvUPc }4dԱ(:o}(} V"y\&@T' =ȡM̶ *kJa 'duh%36qƩebtVo3=?q5ՙmDX߅4U|}F?[HŲYͯcl]|/.R6Pg)(20*͆ )V]h\:OsI'bE8e_Z,MMRS"|iAh:uE ˦V*BzL %@\ӾCN 04ʝI[&N|PDgqgE͖̊?=YCIz\`16hH{u|;qL܋ <"ۣ'4'8}MidR_8E?|[0NU"? AxdX6 n@, 5riwAΰỶCM0 JO0p;& n `$;3Mʥ[voiɓl!R9w1HĠu`˽YVcmc 9_ ?)x0+qn*  _ͷIݭdžvĘhZt7֜g経Y질Qh ?k5a¬9jwa֋ G6Kf-T~(pRJ$)rv:|] #B)@{ź>_FE &Y|*c% HK ~Fvd؝*8B%[Ýixy[p<=#qq=p LrA-N'Pe8$5v5fAJeFdJ9m֭Ș?`Q!k`MVFtp=І3G|`{nbZk z=/VpB8aotjMz$#Z\cðkm`ltj]z0]ib"l25&lб2&H%0SM>N'xgP*oRGVM{A4=k?Zl6`;?BRfTׅ"%r1(G!~288.V_~GY𽒁)+ 󦻦)~ aS8AXos(^ny4s!}@0Bzd(s6{Wگ)]s B*#yE>{lsҘ+ǒԕ1 K`D\e!,:z&0YDH>X+0 Pje$ĘbB@$Q-#YL{TŻUbO8r|6?61SzR+bkCGxb d0zo# _({h:#|]ق0x.=~h9oR-8&%Px bvV:g/RcIaQ4$S t 9 Mډ -?X// |Ü5rtMNe` ΈcDŽlDMܦкNYO_=J֊.#TT"lˋTӢL)CX%f c}!9Q#Rӎ{Ɏ$XsKLהnHyܫ[ͯI FXg\pQIY-l,|I XA Q dUb3EoNt#gp4"K Ŀ6ՐIU-co7 hcuv^489U;@zVSz1J` ȦRr5i@y@U*'@ ~n{ O6k,Ae`7G͟^G+>kdu+\OgHFt#: \%i7:b2/tͧ.~9`~%uq⽿$iKpltFPp:@ ry#LH zH\<#193n# 콠M5[AJGhUe˭iMԡI1>j(=8J8>ls"yZ0A ̑5R}7yeV/ikX\tiwQ=POqpZ<%Ɋ pwVFxGlawԦݚy-zOa rt'1B9>ػw#5Un}Ri܀N&JM,a~AHS܌ѪftMKSD;}e>M> *3 Tt3d3hQCg͇zX]yBL7 2k+zaQ).|-|?~wa΄ѿk:' zz-,˖}4d/_Fc05Ͼʁ d.D!Lup M=_܈R_|b0{@N|j,a7^DwYl"( #_ܗrL(J>.n%٧Zvj)Mt[һ\t4s"1}]dwB/Tv81'm$2hxW6>jq"'ӻS$\2̮uaKu{PDZ4gTA4SlS:nq+I(}򲶄 CEVK@Yk.`2\|~N8*٣@Ie4׿U2dUc- íCVY\G; pwZWrbh>Ae4Sr` hvnad'lXl6 M/\B>DA@emLC#8 NV~,cU_O^IMPc3KZ Ó<%%**:zC-<tTST-0Jt 9lA2 <:{Ȟ//"Z翧UY`#ئ %]rك4B,ϨV*m&A wWiyMKч}:{7LYe٦Kv!9I5Bo_ M6`ͬVU4GЌ)J.s< ҹZFpu./ʊ3Y؀3YOH5:afnc2R'ZڝAd᧬_JmRś}1ߢtjvSGMAx̊.k{Qܡc?D#R]٬&֙n}y%wC@fD^`xW#ҲP}wyܖ2&.cݠ r8^爍WDϒIpge%D=oi.i(Sqɒx2j7|ãk5>H]CE)ucj7u3 ftm[AQ`}_ӏJ#fJWrˡ^UgEJ;[Kz.~#Qlq׬fK?F `"MbWVzrPy0\dH1*dZ| Ԁe[vΔgؓ rq_Y^Ȳ: og%k]0ɜ2aY8)4/70WYƙ㈔OPaac52[4 w}*9B$xxk!Ryl@|cIcζY t }ܑ_/Lt(~*Yi ;":Q.ijmuEY!ܡhkڛG4̾8 +/4#Ȩ)yҚ}@5Պ~r V'фFXT@*0IY%o.؈Dt8 9~T௷k7ZcLlrF1+@&Oup퓚^3eVVa*65&ڂͺB7Ye0|! -؏ ]K،&bzٛ|K$:]*Xfܐ AV\kYjJ\'ّ<}ZX|DWqM 8Lmm3)I׹k*Ԥ<).(?m ?~\QIZfW9,Ȗ"VnVT!( +HD0$z❀yL"#{2=G風T_~)Xo:}tl{\X&u97|_"By,AHVV0CoQMP :Ab-'IM+4h`7&( ^4:MsZӵfQ<)8򁚣 kmX"gGiI{\6 7wQrRvϿzw.jNpwu"؅hc7yUsc7+ 8 }ܔZδ0L7S˚o9 C0΂7^9AҮx g)19IJUȂ^Q> @n[/Q.u[K4t$F>>ɞ r@d\X@C|:~ڣ~ AY˞~ jL#Je<YW"'VN)EJmm@j<( \54A8* % b݀t/AHkP ٫*bTBV??/dZAcW٩1ϧf[ǁߒ.^9|p^Ц#'}"Y-˗t'jYE{ذ[Uf`)ЕxGYjy~ 3hV51+<he帟Ãv:f*e3(<> CI7 nԯ9[13Xn_nk#s XFaD]~;={K"M=RĐRmt!jG'ɂŨu=U Xl=ܣ`ر8 3\vewf}?E<ܦ\ŇÍLMzdeۉ@ȼGkA4enĕP0!+3>tz7Y1R NI)SWٿbGP;jBs^Ɍkk6bBo$e[|hQZAlR:귪OГSk?3Q(r1L옘1^Lb>X,݂ꢺ́K]|&*hI 4ti δ;҇IAY!ۜF>\a;)0?z23=ߎ?Ze Ѽ2 F!6kөq%`' Ѯ/\24|RPc4)mCc ֢ zH +7~w_:dO>]rL.aKs(j.t%[>8N 2"Mb9^ɯRr2"'0 XC:XiH/v`P52htyh,tl,3@\0 R *=`on~UK#d4ҐӢ1sSOmJ84|&C㋐IK4_sUgXt}P'/Μ\2MW6g04rdr = ;2Y{wkaaޘWKoͤDCl',b\i6lsHvkKs.1>>v_i{EE^_Dp<&øLsG*7,=ї10TRZ;e97Ex̟&qciܑU)| ix>r`WuqΦ/Ⱦ(BQ9u 3N'Pd ^BܧפIf &)o%DЃ?ٿ!O \^V` m8P_ bP>il8O-'H{%a c nnΧTSйԻTMt;*UaCGLGZ[KcnAi7RYhc)*D7r$-_TwI6kKjZM,Iy{6%ug kDKL'Oا^g榉'7zR9<`-X/KH4Ԏ$o߯0IQ }i0_<%2J ~zD Vv1{ۃ־#Eonٹ څ"jh|tLW9qKNo VMs4A8WD_ot7WˬQvƀ!\^s1z*  cpqDj-Fj_Vf4(*BLxQXn&xskDUXnbł$gw줂J Z߀r2.Nqw0'(q$ ԠF98r,.-4G9Y+cNԛڋB]逰V:гk`J]7'dҠ?'2G5؊ꮍT=WlZ!q:{)}QP!x; NrI4P uhhbJ9z=@4\w ͚bpL*'$襤L*z L3hp,8='nϨB"7%gELsJQ}R!OU"hn[^siŕĩwJ,nC$3^ט-Nt?盜bBB@~ nI)3s+0Zw?'j.V*'o^hkUC͏-j&@0BW5f]Spʉ#;KQ7WBIucvz kHvNEn%2XtKԍ7E,k~#|]O)+2M<|7q)ЛG(_ 9)t el41yh wTxG舰GEyʥķӖ8vM0Z'rN EBX Yf)oO]aI,:O z[]P?( jI@%0 !mB9 L8CNݙ :awu.W 7vav4܊_hfRvZ$a}~QZbq5V6]}B-2rɡpWal2\, =ǰޕghZzHy}ՓェXPd,Vq۳kH2'ٮ WX,\7PF, cEt%k†Xk`,%YGwq>OJJmD@?wEO1;" -]>|7;eCw"*V  oH M0e@g>L1a'n ̓'Bȳ8xu5 ^Rp F`J@7TPby1C3^ZهĕZ188ˍN ].oWW I]1c6W^|i9YR $πC{G3 ҧJN{Vԛ>PNK>@?mM45;LN0KI'Zfq^"谏>1;ҏ=z4W̓2@zʩXWŁDϦ܀[2xz [gH6 #ӯ` uztiלU\?Ub6̙_JI4 m w+7UW)wJ[ѕ숇7!w/RXbUrء;яȧ2}{X01fzZug CCJ ËUǭqϫ7,ZR[#W=ps$lV&L\]rZ=I=VZ>쯇]Wm"5:FAڙ"wm씗ԑűnHv[gyA'KSjWv acۧ=~/cӅ| oX5YsS5qZ.Lb-wA8 rnxt(id~wEiC X`XtC,6K%=jpu32|gwPT6=* g5G$7,mPVDeX6m6.tE j Q:#R#0˺k Ԛi3Քl"c!j5af=1kZoPjZM|HJit%3+V4wÿCEWeJbI {eX->4xl7Z5Þ6i&q2gٙe`z8l㴗zFxxN \^ R^,޿bgc=E&[czo(G.Vc䢯[+ؚEV3ݪAf=ʧ#w-[ Rs$8qX뿆%YcK,P?Dl+Ҁ);x3 `k_ q4L"'J{A׺g^AOiz04(ًH'(8痮}3#ܰ%@.6AI=d0 w:uԴ@1s&VX%Ip4rˡ-ršx+X\$0gb^\[_9nk5c¯tO?_!P:UHS[߁q{(;=czO gפc; >_4=w_UQ'}`/#ߦH(5ŬEz}*Pud;/`N'fYЍe4*;>{yp2EDܹS汼9&:jȸ}}X j&:Jr؏Ya{jNx>OQgh4/;j2uHm\J'H A} .gp)Qݽﱏz(* 9)DHfE+"lA-V(llFdϧ|̀g_0P|#@v/S.u<}8B B[CrTDSpt:L<BV·zB(OIBW>Zn 4xj+F(ڦPrib.DEt<'yvԦUU>1v3b"pGwvʕCQ|7\#(;F^A ܧ5lZ c5!ȉע9)B o#[sNtK%oţ(SPBtzNJ$9`rSrVG漫k6u 0xވL / 7 9ʚ戍 nHRFz* ؎7Җ҇logQLڇ,/X8+J8 u}0bdžl+|}1MJדd2PjPN?hEɵfs^-$vcC!tqէaQ{8S=^YDxFv*VDpMCʏL}#xLlK[ir7!KL n'&V 5bTD/RHi(޴0'.@熨EJNdR.TÈLeZ&pb!}1ts/pX,?=^u .T(e4eWB5G&ߞ^/[ָ^"ktqՊ縑UP0<&yƽf3Be6LbиzM,^]3*=.KR)Ź[̼>-6<0lHGt]n,σfs>R#ZB|ID<$ ƔRpy,Tf/3bΡP֬KQޝfv (:1~sF]e-8u͈~>^` q.:PNJ!P_-r ;uqC$W$(WZ\kS`]  (<%4${R#^TсRb->LJ@3ZqDFHj@ù>fqǑ,v@MNGG>L1Lyp>`  {-6S{ř1@Hc%o2|3(< :i>ZF5_ Bqڒ͂62"h e_7BD\|^p i}ǾuXp܍gr]C:2G3-7qDD}1bq>5zt6|l3ĔݣRaDyQdoTq qd!-T]+>F'@ nF܄#օDajXhıiq zx̅S }3-k"~QhпQs!x0CBM%6@TVsC3Rr+w dBED [ާH1k.jmbӗ̿2ғԁ_EtzJ_ yOSr`*vT?Oo#uڌO#uk-D(:b *"-2vn3%S^QE:=(z@7󅗵<[ -fWOMb83Ѡ-/H`="4Z_SkuGL? 4C"UQO| +_w9/2f&+tQrLp +r./76 !8$.ݞ&H԰YUaya`eV:I!SB]c lf xk}Zqgt=IQNRXb։M㰪 'cfz2rñW--YC]tBRI\ҚVhMff)EʖBL*MtUrtZZP2! T4 {=u˱y KK\zHW2V®#UQevF+ny}=kKXņw@hB´uYwJ6 4M0xhϳEtw*bf}E?o]鞊[>Z@kLDҟ0̩U8Yٸ\PPvy -I`٘хNuH' ?Ebv9%a?LxEpV]PUT:X,|TE("sv}e`30ģ^۪˙ m`0O1sDx76esҴjtWaˡDCmaSZe)cpaG(u1Lv=aj!"˓rabiA|;ىº> :>'Z~(8fl%{SJt_f [ߌ"F2~i^n֔D۰v}27^Wcśþ 3OA75T.+c򕯲VnX!4(NAhK=;^",0NM |E}c9j&QwA-YII؇GRɁkPv|} &0PGu.[5#Z8$Mm*mV !{8EW{tX|m_E~g`J6oKkd ~,?)-Q5 .ѱnSRO!9ayK+r"I.4 p \jXR[/xhRsłV2VZÆ%KI${=t+ [`6?Y=x-ohV)<5s gF/neqPl,]ϢO^h.d8ed!~$oMўtmنFBƨ|93c6Y' Y~mc0#d$m@k JՒ-bUv"spE/q\=c"C 2Y`̍0JBY_҃,vw><[e׌uJ'|Esw5\9'@AZA N@3[(݈ZMz=/] '$.HuaTu <Ŋv*5-+N3{ؽʃg#`c/ T@a{Ƚ1W9c.:t5 h>AIER'Irێ֎nIs8qdWR~QZ2+T*XH\!b1U'xgiR\?q4#)\|@տizu'?8L [Z8՜St?9{Ѻ}^B+>{Q+{kzjD'egp-3f]X"MΓiҧI8{?h$c YB^z(m胳h[r܇;}3B 6rjR]FJ4ChzAo2 1NnXqb&(;Uz񡦏rU:tJ/(^Cy1PR`-#[V>]R@\Ng* R~\.v":J1-'`;2F]t3s$bR>E8u~֩!rYJ״1ѫ&Fn0ݗߨbR"o]zw$|_L~PnW|}K[$BdFm]OJQ^̓X›1_5|GP?~y<Qr1" KtW[`#:B#S".ݷ^"+-=ǓPL(Fqr~QEU]IV p^b%;7 ћn&kS{Se,cяp1mёL'kHbo陼j,b}7o_"Ohac']U{UPqYSHh3vżƕ^:ʢuC;g#57@IHę6"%Jd7rܠ[>^BVu\PJATO/))l7 ^,= cy&-Ӧ՘3b-vdiq3lhqJ/nXjt @}6.3^{-`t ÃM |pl+rvPJ zraA*qDĜ'z9uOiMK#-i _w4 ?< e:" DGHXU,0뜄fnUMK6=}}]3wFn3#|wu˲R6e*GϢs| -zWrpKCzg ):ǘf{e,/ VykIց_TjaD[ 2h\SJ* fC xZEV9 1U : 9&l¶xK"A]TإH*ݡ2KۂΣl7ݱ1] {aUpw]QuP?G@D>@D~IћAYE`-VuPݬc)B3f;&<0%H0 /ދHQBWtKA۳scQ&Q4U+T`)6:p2S<{0گuAW rӪڕ*>QQ<!i]Mψ,nNWl) MebF@+,EbT9嚢j-M  8+1k !C?";}*7 OB='\޸]Pȇ:C d-twޖBaYbF4e/ ERirJA-P'J.!.z#G&Me[aua@h+Nex-&Y]p~d3Li 3OlD7۫oI&)| ᘦmRR5}欍BrJ:OF|kJmU稍_?>j6z9BumzളE̺lZo%ۍW"~`:ł퐈n=rj%^Ƒ4( H!ZObT3K[j1/$MTefm4aSJ pPWC g:٧7 :L+:ʺk䧫ٛ@n\ <-/ &=~ǝqQnwfͮ/Uv[d0m>X!W s"Gk)fÀgJu1 fK3ubzҋR#Z'ؿZҷg K̑APX] p`HL\RWo6W_3. .DIEcqɘUBS5y00_;b~W;~%Z?s,||We )d qH?!UjOx`S, <8.y de3fGbO*·$%rX,Nb:"bZP8Ri,|@ o^sJٳ\ حA0QK{< 2BݜE_ަDu"J+k}/ gKCzuSpu_O jDKJR:Z˖g_P#c^yFoj]hD]k2HS8Ԡ?K #8LZj. UӭX. _»YX>p︋L7䕬 W%Ppu*LBђO KW>VCѸ9jvj%P(i18=ҁauiv(F["4RcH*MV itz5{,bzA j45h9fh= :!?v d:BeiH`,ar"7&WޠZ*usDAi*bDZ(NWVv}]#7-Qx%E U`]~7\d0G@o%Pt|iGu }NNIYzVRfC5-uPmdr 1!UŘMhzeI[yhDgpA!J& y FȢBAOsȩu".ӎedhP&,@&dIC^ ;egpv ̜"(wg1fcnƔqD%[Xyž{u˴c|\8ˬ odvܷA#bcbTV0wZ;@r&E!N  \}眒PY1Nen-47*t }jNWTfMx[,\4|=o11 Ʒ! t}]kO6) 5gΰKHk&SOS63A-#&E8?*_5UN Gyiu1O3Ӄy>,EBH9[F݅=^e+{Qsqfh ~U^ S37G1(a$,:v7 z*Cp1`M\4Y)Ƕ/FTu,{fjxWF4썮mm^#mSa,M@lJ"Htw*oHgƛL&(<^tvYOP \kx@0{H >w"'׶{%C۬9}nas3dJIxB썿[B+߂ٜwSa~ uPv-=N8eUJ+*=5W,Z̿q4G2gw'/nԒb^CP^q<ÝZ}6qU&[ ssoIӝPdZM(Ѩ;5p~Ԯ5ϴnSn58Nϔ=bqjv=I@5M3-8Pisլ~Iq.@cFsjpzBd2'}:Y[h-:ܸkPD̑N݈@K}U +zV{Nsk_R&{:`HŌT`A)K$R YM9oPAoȅӚjNX";PX}:튎Z]Jw]NN/\$o&!MVo9V5~7н~t(L[oC/eI3绮6E8\VOѐE)+HO;03r6 1W==۽Bco& "%{QOEbӼ hd(V23`2jIq 'ڋ9Ґe\RmoeNϽF~@e7lECE_M*M\DƂ~kjdFʗ1])msE˴U+]]LP KINKG̏n [?|J$`]91oҗ0)#1N30lnyGUL|A9vy:WǟՁJx {;mƄ]A|ΟZ]sCŕt]*0;+k>[yZAF>g<6Qs/ޔշd27anR)cX' )ʋÍ:RQH2 ~pAjTu55 ?eIR'M k<:)_i^b)jTaW6ԂHY&0 .u.f -ŹK3WNl5qRU=^,Uo_S+/opg&T]1F;I;Ыۉs!~ EŵppmV7ݑVagDԴ&4 8,PYH;}铩%ʜN _=r{leSG=[ޗ:,Z>awN. -WfUm^vi ad&JV^.CDr UAv/Pk aaؗSXĠtގRR9W\$e>ICyQet" k@Q=vBl,m  Z>Ĩ2WoY.MŐfg98DBaB%Nep,k^MvJٚu0i݄jNu*f^5?HftvB,[t`qgJol;"ؐb_l/y;o]Qc.ŮgEB!&su˼Cb~Ʋ =|b0ejWRY*mGbpQ'4ASx 5q@t8*@'D +^.W~ht(bKlY|8#e fq 7.fI9)k#ڎW)d 3<9Q"5Wq@66c+Bμ^p!*bmgxdJiA_#$S5SiaD8 \[A\9Hg/uأp4D`d"S%|?pE$%񔵅pŤZN5%->L>P)CKNk{@f/D;nClc/c!DT9`r\}6|x8&"DCZΥnK)*I~zMudћ8t5+΀8[Vh?jX$骛sPax V r33\m;AϖNj)}trfLzсXV5 ^HO8=f^-wXzJĠ$fٵ8ʤӭO$H+ ̦TΊbT/$SS#L*9 +v8"FqOql7:DZ8!(+wc_Q, 7 U圥++iEKW!3Lc?pXٌv@O}iIqE&7s1@NBlRߴ Ù٣$&B]y> bV3p> ;)aNUY!kwj,;8OR.Z8W Wc&A#@)9!lp}i XF Q BcJ25}@^M":4:B kSLJSo9BQdO;7FV.|9 DAx}?W-m2D] ޫ^dv/pR"mУp;b?ޛ-@^$kխ>X-q eKZ:U@my@|me'3[m62RqTV+hl7hfm`˃6vY߃=m_vȀ>7P p g SCHʢ5/65-V"Y7gz•[ QE),Q{ ǔ"]LJŠ=<_ k/[C5 VK,LN4IS.PSCü%S"֣=uz fICc(=6e?MhzsPNrKUPkm7oBЯ5ئIJό @/ّ(˺n1~~V 7d FTEO~&Y8mVcVh$jf]-]A}d(0B^Zqɐ;d]ȲBӴ.H@BIPM#7s#}S9Nyi!W}ZP&H&|P qOAb~T2^ W]]/t8Avl>X;֖k7Jv &#NRu 6rwwAUȗ#,.=?0Tpu7e$YZ[]kʄ"&d(ٰ& ۏPbc80 RU} 6 1MqЩC;eD C1ֵ1^lVB"9 ijfT\'o-LߠY;hD?ng{#A4A*vroan) yL'M0=hXGX&QrLؤg-@]m?Ҭô<6@Qqڠ[/<6rhRwT>).>Y{>5){Iwiti3`׀T\ ^ NXf_}6Ջ i&V|v3olz15q(~"Hcz+'ntp αZS rsl_[˶$g0K%b#]Q&;7Țp8lO+qd2 I= |s~ìn#ǯ09t#OߞuSr\QA PVDW/-L&5aD"bɳ_zi=% "/di)tp䨏gt^M߂2kgw쐖ua#a0gg>q/0^g W&\! * +a(/+̱/rXoxߪquR\3c[žEJ|cz@3x5IJ2J>?(J`UJk4&U̬nc"n(jr~iT_D YgzuhRh=aVn{ ()Je2{487=ڦ[k<e"_h(:ЈynfA=Gr zcNfS~Z{>&:*;, v#fG=qm?IeOSv%޳+wT23:;5uWg($33. Mxe]& n+ՍlS)יDU3Kg!1I=JQbYmH۪s¿9\ب7vwr'B=2xP48qN#i=˚;kp CʫsX63V 3m*^ ԋ񃅤9Uq?7@?dM/c=B x9s @E,1;L6VuPh} shF 26-Re[Iܩ!8[QwW։Nm1r {RtAnXo-Z~U레 w 6C=)Hր`ؘfF굼==fEfGuVu Temuh⼱){S0%IȸωG+ O[Re2qʱ&@f* %+yV{!$@(D{砸!k9Nű_ ‰r1=mTF9_|NAUз/U☤_.ōO4=o_OJj'v% {/plfG"!Ҟ_o6 zw^X(:]| >V )n#}X/f˺g9=*P.PZ8q;@if|ˊ5/H*9%+0,ceZMS{# >J 2gۏ@UܹiM+Yn##}Î/kq[ *;o'~HհX6P;x>{HIdOC=ʷs4 cزn<(m"F1:nls`*Z}zE$鵫uRSRE挨AAQR,/Q`/1z+ɴ:yH P4&'!Rn3ph_I7GCUVGƿY+A̼ۿ2߻te t ݆ZwY,Q_+3rs@U}b9=@}DC]/4#X6LbVX\ :As&ZĪO{.pu3l;+?~X.=1G#Җo4a/ ܮC_#ii9:6N:}x Ha?e=?ʪBE4CǧKuuRgf#VubQAT/$OT&0|ҠX^'Vצ$sN1xRm҅;@t}(*&q:xgoISGq%28 4Qt́ 4"vZX%2֌1:1x5*9!&Լn'p*\ 9Wvҭϻ^I FLxW|`Z2. [&zEۖ`/>%4<_O2,"i<[8sI%z,&G,W1J_JjD[89Bڝ;õ2:4B 'q a`.vz!+7V0T{8ȁ%:yRΟk_>oK7A GelCW"Bm܂+e-ޯCuq ޳Hd fpLMa!JeڛwK܊0Ɏ_?Mu"^f瀄ZfwN0_ [||*bqsĬC>¹>$UMrP4 mS/~K4Mю8/7Uȋʪ}z@S=Vj25)CXV2F%9^B;j,޳>i0 4"sLfVh^WiWĦ֠H'ekR|jbCӶ({4WLlfAS,]Z%P@$g: wJ0LDݖ3 `48)<bK]K#4ίżB>>"3?P^Ux$ǟMaɍ^> 2b Y}RLj+?iCInN4ewѐj9tvʸ@e {^;{ӂŵXRz7"# Q[=NҜ.Wi#SwY Ve^Ѯ)XX! *g_tA6׊19Vݝ>^,~`/TU?U{m92(-Q HF_P kZ3Ѫ09nW߄YzPզue?6)TAqrPEW Z%(.b=JD@#ORon€0sFh+d"YUC i__6sBvXim\tbOL,'kdϕc)}AIez{WAovu{޲YaP!Ԝx{Hg;mz#ӐA Dq0O|Po"@'HX [(ꕼ?dtڒa~W:M &h_Cj Db]c[ 4Ϊ%%gJy\ƃl+[@iB 8 Vσ==oEzdXi ѨP6jߟna(cla,g_r@yM,H6 Lt/5jKg[I㐪Е˾=&f/HDD=fgg#A&QtxZ^4 " Y|xd f"`0Εrt!N$[Ie3gP;d%+߸X@/VwP^wNyi;b+j!ш#"?a=+,膚NB>VȩUQ%iF1Ǯ;Gj#1°v"&G }}Ź_$6֘1\T=YΎ[%m|aDA }5:v?a ` I7Bg6( ;dƏ]VQyv4Pþc2&Bm 0To+{"ΧCyP ;2$ymU@vfpuX>Q~aB+H%ѩ0р{cgg^h5oQіRXG {REDE;%= [rzZIElXTJB! S ŲgϗKtupu"Rt%/}O,YyD:$Y0|{ʿDnZj.gu~KItZ @-oђ9PDqHUWAFd5ː@54(Qp@:2^2tf +LQ3.ƶaoeW 4^NJj; ~gp_o4)I sXh/溁͞nF19`/'w}$S2@[߲E!c7 $b'vI{,oM3"V,%.~U@8y9d:c& ˚9:~>kp6yQ[aw~X8Gu4dЌ3)92ߦ-@c<ɞݦs>*,1:!;C{ \NIIjqMD,, MIg:`9ۣGٿLH5+?y];Ԑn Q9biɾ޶v=ۖ9Ol(Q{p7>fG?&TՋ*6j* D{I+@=ldz2 qXm߽]t`͍ SL˔lZf)B*eHiO&'}-2H% Er}ŀ nqхBO "?Bu ' .6}TQ||քYQq[q.CQ0@bTv5]UG:.x% Wc*La@xR[%D%21=a*d#awW0+No=-=0_ ~%Cm萣B ~bYOE*r1\ӸspqolnL˒p>k% I]lf@ash(׈ 9Ugfph 'lD_aEh[*Qlœ49u?V{*juaHn$H=mٖ5,5"iEʿ[gg 3'99u`{d8&&ۼjD5*e6ѐP63uS O7GD\ZM.˜AS VԉddE.)\Vbt-#[ڊP;ּ^bч/Eۣ+=h#&,^ 8+SAs]Dn?7w1!:;@dţo״ Xh@ TQg_oKGm_u{-o_=_,1Y:YhR\ jIQB!b9xKwl-h,Fz8*uz X8ZWwwUQA.9u!Gf~EGRTrsr DzaL`XS԰Mi:-(xߵGT m"(wUG_HdRmx|fQ ̪ /J_+inLjӥqu|"b-ʃ"maQޖ|o$W I 䠂AQ2oHl&ͥ)qB6zUuzA|ԦZwn}0kFd\*w'&քJvKbBߑ^IF dǯ /6׋xn3i_7t xphC>lb~'ijM%˾F@SD5O_=+ B<i;ȽKȩ8u &RɿU/DdTwip%MOz\`)˂ֿ_Ȩ^d9{a=ÎBg7ɚlne(X>v+ J@߄/1H9HZu<|Ń]pMx''KB-I}˯JWXG?($18T;4Mc]nC_%5 "X:,>.Dr㍦v੸W̊UeP؎`-w1%#/kV%4%ʴo0( o{% Q rj>Y&%O9B(v0SøsQkFR`|VzhGK(8=ŤV( 'j@tqʧe "~ \m&4e89T(47.â34\_ B `c\)Q+W֗ b)z)9>T60F?ͧe/uO9s#MwQ ( $&O OUs#%6foix-ۤ]eۻ 9Up1b)۱vM(>?`Յ>#/HZ(Jr|+/Qz/7j!_*TjqyxBhdo { 0O ϱ\^qM'3̾)%**6GTw bHݟ| GS}U#@u h1܀ޔޣy?_xz|rA(=D"mVrMӌGNjyUBD֣`«2K{Y?V/9=yڜEa:Y<|Uq_|'9^gb)lMg=b?ˇf4} c|)XmzG%!;nr^dksE/MR@);=y~Q2#6 .ߦo7NOkje۝u vEvXp"FT5>M<=Q}ΏmgIg2Rwu%cʆ;C7M- fƪ5kFW!Yx>~2QO˶7$DJ11G7L쒫K;/+t¹RNdl^O_`M;U t2Sv<x-Q7{{5]cNC1zsBĞjqpbj_ $8TN~ҭ/ډ4K_"%p!ŃփH|Ӣq O1Y C֏Z4a6^ O2q%h<.?s^|pS?4ؚ=wJ!tX&QDtVyXBKkxtdd7DN式8b7.~k+kAr/Ut'p:7Wt`M,C*"{:K^tc{mۗKXA"'l<{10qEMKy=bj|i]"Uf)nefJVZr-@8 >WBTwԵA;ԩYN$6xNCJTkB7=7e,QtyGՖ9Axz-F h=MrŨb=X~)4jCST@d4 3_IZbx[E`0+@"l_-GxU$)8zwҺy4=ğsr Qk݂PwEh0n!WY+p݂J*z:v\a:.3zΠ؅O=?0/WEqR6L 9pJ!ԧ7?BTgȕ k8&z$-9 iiG >ۡ$x/!x;2OTbOb:QI,6) a?ŅM.3^0}%@*7^CvT:vrP;D[7-=樹JltH$eTOfƥ0Ax1b~*yq {O>8MS(Q#]Yn}=ե=rR\G-%#f' W\J@ Benگw4!ݽ -) 8zv0m8=Y]/^Ѽ"/̂1ScELґݪsvؙ{Ϙm|^^h_\you1JHүa]Bj  ԈtQ,hYC?{\JP- XcFR(ԩ*QgQLG'~EK%v>i>>8{Dq( +N~RV9cNȲ;f ͒ W Sn2ehE5ONO,g|=TR= ~+wiP^Z |9f*ٜ|fPY3/͒H2oNAt-T\~q}2U*Āt -"vG!əU]n~DI8㐛*X,#}"1&Qp6U a]f*/> :bX(H|sF'(@qTyfٓzhP FS IEŦh5zU59|:xu2yHDʥۡ)(|)aɇ- g<NjOlNG0૛aaXe!B/ LQ6FTxԛ!ʨ`0oqEFp9@'uj>95 5K:è pZJ]ɯ@IX[ IyѮLrDT!ҞGtv{]bx`I[hv[܎)4/Wxx.LmdTj,gt^ F㫰-_Ǎ_D!g2Ak ?g%~&x{kJ2\ei#&,T 'lQSՙd%xH`*rT? e8S=D5Ļ\95)̸VZxGoBopڟǵ:r8.d{ IT$ 8!kp{6X3achc9T &2Gߊ*o)." zBDƌ;Ie ,?[+rEW#S9;GI8? *gN[Lܺ߀BsJk*}aC.^.W5AxN8["!~$ŠλI<'T"EtC OtphɈc4I,0@__{}Uт%py"+.k0V6ѡ^27TwRK)8xKɪG3yd ӫ~S]Z '4JB &{S3i 7|UϚ,x8M<nl,!CHyXȊYy4Mi Cklmo\"@$E@Gρ7lXLkٖh-;e'u$7~Up9)o茠 b8XS8fK%v 'ǩu+srx o4W\u.t,ʶ2i\BQޙ-G \"נngk9W^ΑX2ЅS@q\ٿY(׌d᳘φOٌT&^OK6oL@ ƃ-5n% M8|4& cab|7 TS䂋 ŚJxEJK؄z7x$Qd!P^weoо5oe6/|Tz0VK9'/ x^c\J8(ti Xm60#ַFP~Uee{6j e Sdr_X!wlxC2ڳj1֞sp}k @8~*QZO?1 dܶ"f.Jp/5KfE;כ"gp'׾&ܛ˶Zx6lT: ĺ^JаFW&.HQMUVt7#;(2g뮅C%PzqQM^ BI0 2GUk4ӂBrb*CLDJ["eF.̴FjQcU2k }_`]qJۅ-jg,r UhZюX;JNr ɺ"n/k201r8I#\Q)ߩ9仺QBW-RuY媗Y!nYg|Rץ}t0_ Å;\M*BA뙟cۢ[0Y:T5t.ƍpo@=p޵s*WZ<8WMaQzwR#_75Ϝ?xy5x8;j5 "aQfJ,+tf1?OՓk}v(L]fŷ0Yxcb +/4G)xʎEŏ{mUg\el۟2ZxNqgd3+Hp h%?]pmB$ sߊVTZ^ wkbQPWA'|!`8j@\ٟzG{hd('UY`my6ԖB(.nwg9^huW_'`P=xbOKZr[h1A"8LnrR]'-YOxAb]ˮ]{?B =ߴ茒[Ȭ-%| 4ƱYh{q-1xr(4n+i9"̆QCD|\;t ΢\Πi2H1O|?Py@/B T{4}.40sVS_jiPrpd.OYGӭETVf/!VA򥔆6MQ88*[t[n6p w/ KjI=NYj_I\G?r V멨E3L]ˮZb6j6խ F8AxƒQ ה}637>0 bCw>h6ֻƻg[7yd٨sg,*V<`c1_w^ytkw"HupӭgB縩~T Sտ[^2dcu ‘|^ɞX9DހăBYrD꘽F+҅q @3@_&b$b] n~ U!`y(E,{yb|eYNv\l:&J-RDFRI r±I&!9 q}សi.(QQznpP2Mj;0K꠯TEs XүU~-É-a2*\y1<˶ Fx3mqefP]$y4<_i @Ę"kڂD@pFxHjϧI)ܮ~Ag*=~9Ӓv=a\ymGJ8戶aBzg=eړdŠ>\vA.y6 u]ex+Ŋ6qPY%qwhVr܇b05LtB1J4v7>w us?\8dVJ@0U9M P H2FR4 ŝ٦Ưo ([<0U0ЦnQ8^Xu6M~iNa0Ŕr]^W = 2=9.C]ԭՓOM O8ƪs8PS6{2Tfb,6`F qvc~jy7 ?m{)KsJfC?G|vsI/qv[# t&+Nšyr7RSfa^HZ %Bڨ|= uv8P`ip%m#zg 6Ī6?:Yh+YzIiT*Cv0-?tkk_/&q%NBLk- O J K=А>sG|%x+h94nM,GqhG d e)ͣC/~s9tx|R.wtk0V}^ fH-%}>~↊~S?Z~%63yBq =^ӏ0-(MrzHWv*HcV0ך򈎇Pvޒ,?<\#ޚ i@8q4B\eA9kWaj=S`|U3D:O T(m92G]ٍas#f"{NT,z5sii?X[(3)[x<}+tzL$ߜJ~ݨ'͐<7>6QM&ꔳSG?5bt?XOZ~Ȏjv62ZjK!fKчyۍK!g2: b9KgY|?3o@ 焹qYJft݄G88^j\H, >5?]9u}$ SK/pxO SĸFIS;*Wz+`djZ"W Ih,xIJzǦ]Uj)Fot0_Yqm/e\AehKoLҥo`|Ԙc,^U-vck.NdFѶ UA-·rޔ:bnkMۖӷXD65=dɆen Ws8XT\FzҴ]E]i&HKwf!{e%-=k.'!԰G -!\S1.?Y?Wwɤj4-=iX[ҫ\W3[*RRN3 |Z Љm/_gN* YB,WS}+WoVYc+z,.>p]TL1Bsg?ր]$ DO!B05ء>F)ém S  4Q7rs\5㤨(7ӄF8 :*F;{&2c_{6ӈ痦F߅w}*3;^=\嘨O$ƄK5׹ V|=u8?DQdmi E4OF%Wb7#$*YߖnYpIڧ%Ew&$% #r 5-7& @yKzZihvF~8úդ8lCJ;zPQJ yG 7_5.|| MaxM8CWq.x")z٥(:}mW8oV$| bt+'nޚX:/,1] < yXRMZ+Π/"kӸv3Rcnh'\o{Rx5;ˢIZ}T5n@ |P#8m# de$_J[:1ϙ@w #ajƪOYp[pqw̍"x(2 [brW ~񬎄AgZPV%q$Kq4ĵMP=@}-V"jus1xXzH&;"e{KKݿ8b3 Zx*mC!0i o1=yǀVOՖ 7+WݠC=ēS4BHlɱ Nn[Cn4ъ{ aW."nE[ifk]*hZS ruAPΧz0dS"^Cv1gd:-J^8XwYnVlFR聜%d1_> R `%9 :Ժ=uW8O$v)oAlʒ{Mֈu%Uܭg?OlDI*>PR{2_'H*S+7 ξpxgLIsƫ?rX7t6?ub*`tYmXsˈ›̷ TGF*#x߅6i@v6 pBxpgt[dž1G6F SwϨ0f:Ftf 55cEYmwk-z~iJJ!{@?[p(E.ZnT8#}?*(>O,fe뎕Q.AY9t@R齨OrS_L]òcvܱOTivleGb_#D);}tt@]m*d>}5? q,?E4,bnI'lhN|fO><)Yie' wح&= ڄO{͙j1,><)7`t,~p&¼M8ci@d$Z5 b|h{Ņ sPFdbyJyQ_OUCc" ~j7WY6]FS+dLD?EA@KrǁGZI^ӌ1htCo`np@s]$?I}|YdmKFY-WX0U%WFJ:dbn,NY9/SMoB;޿n&j@/E~;+Zي2=]7EjYNK)qE`Ӗs[UU-1N=!Bjc7CW踰huݏf'WXI'Ƴ>ۍ'vS7퓵(J\F2I#Tau;1׸CMQ_VhT֔`pft1pv.xEb#H 6L"g'k~k<[ygcS[WMi&Q*]XVόW)$^~.tFvE.USϑG }a,C>6(tʓ3 w C;r#0_eTpS^z1v1Kˮ$Z:ޜؠ su?aBC8ncQiZ4}DZ~q#J.Rl6ZZF3Aʐ5Q/͇7,>fC`F oF@8Ll'vK`3THa΍aGyalJnth4TyS(P*6^,¦Tnuh[)u NDkbsTFWEJCbX1$}-{ ;T}TYhlu s)WQV%*CH H-Z5霩KZOl;2z/O7Z6 ~%fwT$[q AΆp-Aʗ36)$CqJbFHZY1c k6՘rXҪ\nAȢ u3z4h>T&X1?m0f]Σ|4Czts$өnS#%нl^wc:۱"{<+d(wQKjL'&O>F'-}R8(1q4oK$5 ͝-e*&m)"j 1ǀX}k| s]Y Ұ`>:(-U8oO{_NEmEZ ^НɎ:Q#S@& 9 P26F$f"-W6'){g ';%,|^itYш? ;'T,R(R9HB􊯻rmD+J]J\6*zSݹo3䳢R"^]9\d?M2U{6Hw1J 3`ylB4L PGt x͹M>]^ wgۅ.K@Gɽh+ X`%LbZK;˨ U:3_g&tl{b/%:Ƈ ]iB""VRq K;;ݹt{+qvG$aw/#lⱶH%iXx? &tdg .:2eT0{мMc!rsBuGl(j) v(gy4ay:( hj9*3po-N<ŌpE!3Z_QSJ8*=Ci{S|#F1\&ʇ$;&RgJq&,Kx@F|F. qʾf+q툑x A/s&C& dc,㊏ P5v,#U: 0Mzй{MڐD}U w}G,uP>"5}쬡"YVŚY 2{ Ro\%J0DnOulpL&Y~I_T{ϓAyTgѽE+,_HJՋpQ1!@g~8a%h{9xReEJu}$YY |^Oh2|vӴG^A1(l\з#^!t-WQ|24),BԌTB|{cJkdũR&]_DRw?&KȌ.;Պ˨:=]ivo-de{s7y,>j9+ʇWR1mʃ9 (6a9{ĂfoJ]TxP>-8WpXjmxӐ;jQv?B׍leҊ77@@դ$4 *o|-Q{m! g-Z|){ҊL腀sbb_{/x8-Pfz4ӵwYao(ߵo-W4"k0|j?zzK8cp:*VV5sn`k 3[imLf 5hXG EMG$/ˀko!sh#+(UHߏ*RhMPI]Nᵖm",&vr^O8v[-^"C%2K3~~=IzLkv6j>__X}N 4EO0r2uk4qSCCgE]UmVvV'J49 .rVb6*ޜYǿ|V>Jhtj6W9 {%ղ4n֤]/Xɔz'gi-8uY*,7ȯJeG ⻤:U/ [amPw88L\k\nt`&gwC|Yv9,߂qMrfE/@gs?lMٓ]HM0תBg`ߛ?0S/p~Tl*$^0d~zll LoN,T:FllmBmjwz쳽1ԙ'1F^a=bрO7u&B[ RR211q]\¯%/ h-Vi뼍n<g_Dʋ} OQw/eUMZ6w=UGV%jROJb-ޓd^%Z,KxjN+}Cr=oC&9P\G_`'֭ρ%HGALQ^^[+ߑglBPTdYa+Wtҝ YAsƽA!0<+tĴL|MH +% [ycƍ{ r܂[$GOt+?1˖|ԍSz*B^c1O_гh.kVWȟr.iX3?„ZqDQ5H P*և]CSJ (DaaBf'J7/J[o><78$i&a_;2sp3nR|(0ebd_'{KHd{j( xUDY{Ӗ)S%O{`lVuI!1e|'|a0w@eEK\yȞ,V:ЃCX'{|isK*SXco2u+k*E\\LYKWԈyiSS,p|ߚB{ek=x 52U& ['#/A-1dkI٘jeh?+?ߺ{u(9aS:f1C r$4,@짗G7+m)AP VC/qc#ᢳ0V uLc;-US\Rq:z`.7J?tyoڼccsA%\o|".r:)_KCRBv&ôIq ~ c%b0-XG/m>څOW>{xDC~'K`TPr}WX_k\us/S`mV} +0+dNc"6f]OG Kk PH3yE½ BCw D6&j|e8c?>=s,'#Πi5p- a9ɒ%@Ȼ|c-d`,1LM3(|蘘54.eaCqjzk#{kLXp#d<~Y%'Eʅh&1m5X`97z+iʒ8j[#Nܼ``$P=(+hu{)툞?,6\hQb0Lo2sXhDVfF65-%eZ;U{t5Qqc9q)| rOr|] mu%,Fb N97[jtcu7&ʘXeb5,+6 QM9=A1ܫ0[H6ɪWSMz O< DZ^dO]Cw [r3 :RaĘC#yvkd}+d$'  <Θc&:FU?[&_W `gHzL*A?Lv(6֜z/H# V*x 3v}1`1Ey q衋};=4^uzk. 6R$_il p^4?cKOnv|(̹ҍ/4\9']ȺNJÆg}*tS3ӫI ^OL{o~Bun YO<.ր?ZT & \DXC83YRdeTEuZLe*?}s׋3p oR~yMNo o}bzGJoVWP=[#,XfI+2-=wxui-U}s,ȇfꋻ[M̶8$/g2$ ^x\p0SbOU5FsfYG&)' )x}]E C?B`k 5*``(dh%L׍U{}πo1N7dV$f Wâ$ EWo4s""9k0'b^F tCJh/b j!`iКMMyRsIty#TPD!(+e&91 kHΌe5[`P6!/,5|rw+^V1J԰$^z*j+h < ד Q*g,v dBxnsP+2 oLJY Ś;ehCVaNGղ0bƲg- {V2?AA hގ)! :X+%u vcunm-Gt&@lh2Hz c fN7:v9GiDtć\RO7A,ug[Fqa31Sp : 8=窽^NBH;$=ȉ[z颌,7%ۙ%-~{/y՘.؞~ JI" yzZ\ѢwhNCݽmPwFqwneB=Fo~]Tix+v\\(<2z`ekI(s7It?I9"P^'V}"${r 93=EoCӂ==vqi¤Bj_UPz1}B'jD4S(Q=%}Vo_=0),T$>{ߓ4xx@ch}̈́{އ} B˂my\wSpZ8('#ih%_u:Cز9% X^,}B2vkVQIwkh}^<`-[Q+MQATm۫+EQ(N6K  PwE4c..=⏐.5BL0á!$o).5 5k=6ޙA<6%w@i,~/()ªU͵Xg=ۜD߫:V]: 5Զ lD?ȱD܇a,f\hDcxQ$mA}FiKqҳ^=aTBӄ1q?%4 ?U5|YW2z0|.0ԃȃK*i@is/8uDCRf)0#to>nS m )}N_S~!\tc͆6 "OM<>ԮGg/`r:4ee4[%kf,d ;hyNN1 (auKc˺У' iF2Kmd*xr,UD.h57&ZV԰)YƥslǸ`b­qy: 9DƐhSg,N:\꿅]#$ǥ:XnK5 i\%/6P!9s3s9LoUUؒ}&󫱺1fҀ.̍D2byXY.Xh rvBK$!;I&iB e:T_ŕ]zTDgf UfP$Upe^'NdoIa (LHf9`2:$to鉲ߝ>(tOkmÊU N 4 Rt0%1=sjCj@ĩX ySV(` :!^vE 0 5+{N u\REpF⿉|p5|v]r^>^@5k\i:˾R|u`Q#\Kj'FlL8[ 7l"L&?L0^ *Z1Xnfbg0,/Wǔ8 |R(m>,1IG$X.(;Ejx1HJ)OFLיLq~pו c -z"W*e  )m=_ 9QKܷ;9%ܘ"Qʠ3f"7'7C#>1NjQs>Yٔx׷[G18t/?3U] TiQ IT>XŇ 8ԃ]i(Q΢p! rFsDtfjmo 9ç7bR=PÒ9Ǻ*\iVbn?@IM5~1Er#,IrN1\B =TMxw֔I# }?1W'8}3f9mu9i\U"2 {X<@%{U(K%{5RݴGP` M4)6 lE~V ;*<%n֑?(O[ǨZ*j\3Fh81xcn-=dAԗoOe R-:hq 5,dZSQ,npF[^y7I^j܍@d^}s!֟lܕ3.bT&埓bG-$yIkS)}\jD=4o> +}:!NѺA`%pGuaQT] (DƋL`dTwoTie,Rv0 qYd@Kgg d:nʠBUԋp 5B 5y|v_[1l 6oHn!8 )O~?C_w XBC0<7SN\4O#V22luk=.`5)&k~ :ۜ!fZv(Fv,3L_xR6VzY~]Q0w&DiAOu2 [l!ft:5|͛KJ0G81\C M;jEW ! <2P1`sހ#a}`jǰG}lԂ1+˴ -{/ $7[Ck%85#ab2#.A5}ǀ&yP>Rh rl@ B_a˯EcËs^~1Yzt|.+{pUZ`}\( An899gcf3l{qmpw E伶xsI.p[>V]9K^!7O:ʒ joTj4V[0a <9 w>/GK "pV(_ ܕ"}+;ہeƴiq\4>R-RTM Yc ! ҊGeS3* 9Nc~RL?w/mjP6OAS1Ck;R| PǼmq(==bo_Oc8h<ʹׇKA@*zV%2G{dŸkc<݊o)e3EigCbyB mCZB%2F0PTY5+m7̜٩dxm&?hn(a9,^dyfJ^x6U~hr]rFodf5t2t"MJ)uC$:q/ 8GAeR]&P R'4Rnv~6{PzKp7SM~C.\Bc2>nYܯX#_e>6>\K>,5F"_^< ^ĦU ;au{H1ϟ@v&Ddt׆zu~վ"S AF-o_d{$&Mr6gӌb V))pG}!Ω,KIc֬$:SU);$ǏBb[t(Xkŗ5Mvbam7CJkM}D9n,70rGƴGGkr=dϣқekAa( 4[#ΛǍz1.GCx&`D#!TRJLy#TDڻƼf8 l8llBQwP5Dcx?RZ#}h>yFV5.(~N>?lEc_!AfxRBH;*JY7~gkT|1~h a:MВ|,ˆ S^A>d~OQ(@,o]Г{M)/[w_XOuY \ 4VXm<؇ag? Di J1[Ẏ6iZ,VqmmMd^T{[Sҹa <(WMXʋ3+SP}[i?8qxceUZiaY g2^Bz6IؑTUUWߑyӫEx54-bK߂DL5:h n 's\C2Q_We~bv;ߔԂudvZaJө3Pb+ ץVΥg/ V t@۲"b*i y[ ƆN?ǐs6ƶrF;2C p~>C3}d s"[mh$E6]?rSPEjOuWRNدYJ֟Ŷ2m`gSˊ2oI_lXiQ`ӭUG@MwsP7?_/۩%N-cB崤f s8idhQmLyBUI|@k Xcݴ<讀oZ/@'u'L7A͢/}{=,(+i352dgNEFK Ͳu_ Ak0*TѾ<$t5y\anm(mk ن6UDx[۴dK־-mtgň,֖/2=,n^@& E4Fpbt ł@ Bx?M21Jy@>µ6҄-GdWs:ЭIÉܷ̣ɯQi1U &"5v p;q߷C4GRy 'N*m'v$O9dNoF8pM?O2-T‡-཰T3tD5wz5|V(3|(4[`vbCFaQh3;:j/C (^KP*+ZV!յ f7;F@//M̏&1~!CJ%hz`oQ4~htgpM7 1Avz}oViS. Cyg88x~Fgqm+~e$`4x9#?MF6ʸ,}-{o¡Y^$2Akn[ppX>,յL'KiK_4KN @MdI8m?,s-چ^AvF_*w @2PDKV$'|j)P|\kVBa_WWryPOx-bUl/i;8/#5&*f}~w{"pUy~>"ua [E:6jLZ"T dFFQ]:Xdv"v@;Y*1I8IDdM3o^ުREZwE8Vj8N ']mruhV{|g^IZ8s>W!g-qZ1-5tv廌^sSP:Zr©l'k MHq>~}|:2xlVoYꋳSɏ+֙隶c" $#i*Ȭ5 b)OWa2Awnh2߈*3BFV~4esR]%G1$7;zƚF(cy/.4N OT:Aف?=eC.V?iAV]ͅ1:.ijY X8YlUj1X~ $)4(SM'e͛G&̼eqe~ӱxZgg.:}3I&]r[P-˧d?m_俌^Yuv|- ܓ6!|M LW1$Yع ?t&HD vgTqsi7*Χ= -׭+_CtC߬SpZ]g0fTYRMYB w zGk䥙ĨTxE@"̋g.;uM-H)xm1JptW#lF`^< ކ6p9LPڹbx+}OS4\6ykx]Dh80cξw/Ut~'Hs!t~(Oʥ3CbEuuMU_TotTn`Lz!O87#$.uP7Jm(CQS;ҍwU8˻Lm'WEvF 3E[ěg2 7C JopIOFհ QBȹ XF?iɩ~ق"O25Vn)ֳzk,hc|ǂKhg/[DV=y},.-a{3xTOFH ~V' V$\FqBYuKLt>}pk8f޴Gc=-ˑ4k2$ۚX; qSla R'_.4g28j߾YҦH[+|O Dr覍x0T4V lP2Z~꾡H40<SL;4hJX?D]'[ntjkD^/wqط ?rg&^V۬g\?q|F0\D ]FR;d]. %q,?\lآnI4݉1=&X qbF{iAfϝp2Ȯ10f5vʊʏ[nasxB~Y[ʇxN TQnN_qrh |Pzyx F:L. {L4cggBæZS+T,? Ez_vPܤ G@% T݁VS,Ȁ&Z^X+}es J- ÓK)Í"jU7€~{XV.LX2T*Ӛaʎ`Z>loCZG[ aA_QAg׾O@p?)Xu?714jG;MnŖ mL#]h$rƵzCё=_3-D ;1}gH  < n9Qk5(;qTȶD)%AjI6m~v6,: 3=z}Җ+п }Z3;}Pt[W1seI:? ΖL|3;`z+K䲁9|1'̅[l 5cd :D'UseTLM~ :)Ehkno|RIiY)}cjn͚|Xh+Rn 6[IFci9GYk/@ tU$OHe s\ϪH nnezs*Iך IF얨UbQQ?cZmg5w9R~KU4ԅ3\"vX䙴~=WZ9E<&VK7cGHD5EVSM}u"`5w8R02U'?v>`RK;Z"Hci~kv+g, zAcҤD<%S"j޸L. T^c,="+}/+ZF8HU#|}`&!NM2F#cuL!lfSP&ȾW>WNy`gmfe5aWf)FViS]dFN ]˄\{46QTSʴ>fxXpNeU& _P# mQ <ܽt56qCFnXUٟY)3h2+A2+LX[^ Kz4"iQD{<d\ 'p6C{ f OpY,AX(E~FB;s Y}n\ xcJҼvB`rW(*7CdX|eԶTٽ$SH5툞P3dž%L i'Ȁ y5vb޿Oފ5Z5G!p"OY|qRi'(NΧfy6Š4p[D?zȘax0<ʜsMb# U!\d֯=׃? _O8h ObDI ๼axYi\.V$4J2@\yL蘡`aɛw HxhLX &4#mޕ"Eܫ;L xs\ Jr 7Ԝ9žc4/a/e&UuKB#GJGʄ4 x"ݐ&8 ,W,AcqqqG x$$WJʖdn-Ÿ(t-+Fn 'sK bl<凜gs(Y~B#J<@J,CmBR^VRPdrkco=|v"R8 5XmMeȤ *77Pu0ǘ~I2p Nvedm?"J 'w:8b`J"yݡ=ζ~{^M;"}iPđ*my[`و^gG|_}ZW!%LEHfaE\űeY݄ -T#+cXMgSgQ̢@kGD6s囄]3tqEꉲ+M ݢzDT36Zis Wp6 ;Qsp;1*2lvJ;<36{SE˗:vSU)n_^ѭ"[1OAGL+EP!Rݴzulr=+h]pvw?]jJ-##Rܼ)a˾-YN TW<.n0P=0 R-yWƟ+X')jUYӤق2NF,#VyY|)o0 N#2~JNqUT/k n8 ?IXiFaHFU$S4W5/˻`_kA!~6Ejp`߭ F)>ǬNi1r;kTDg1IyMwS] /Q9ܔ7A4,4o %鸞h/ b/.۴W摴TP*QcMkkvZBwvza9%B̶qaVF= {Sn FCB*aNf! DX`2 _X7,M1~ndpD[6٧=Rk\}bJ߬5̄Ĵ#e`I}=hL\*<63642}E֚w=s@:C kv{ =6ЈXf뻈`C<ý9Tur7=^ ;&&y>m&T+;abe>i`5aƄmAb[0 K&LVZY.^$@/ E2vP:|Doa2ѓ {P־'&U)E)'Ul Cz7k*g`~mysACK FZH~kC)u c2͐(a en- / m%E~]".=Јp(|Sa,A'DV図(T 07.H.f>s K_qЁtCTۼu__iތ 6&49!f&\ݞ}:OǙ(|LN\~n\2s6B0 66 )XcP'D7rIk>&ń03dW[GXxr}2OCDΆZ? q5i6B\~D+_| ω_xEf'= 1QB9"f"i<*WVMlYֺ-M!CԧxPqa C/cs7{!R`r\?YB3Jnz5gc032HYD C8fGe Iwl< v_O=0imѺw0)N7H)zED/IVbVڅs)h ?j#?a|5_ %D!4%:?݈\ıy4*Ec}ks􉘔~1 }[PZz*hQ!#!հܲ~#%y*!Z9 Iz ȂNΫS:ε2&#;(Bu"2Y.'0?E[4=R`u ǯ$lmN(bJ~uMG)I9 oϾ0Tg-i[dl[T.gcjaߙ0*k'ș&`'_O^1KОu˖?j9UB =n>ihu9KS60zl*O$)LRKgƳaqx@{H~^e۞{G;E1w?ouI6 <گ_ WfE]nauu* XoQ2ES]urEP30I -ؾwzF+z2*q*,$ k?QؑT&ǡ- #wDTU|%@b+ϰ)DFJ+ǧ <0Hu ˑhprfhI?3xB9bXǛ0`h"G uquQK7Ml>-F,~8uuU1V\VY([Jԫ&]˂{>5܇[os#%IP>%O{3"Sć|5d&2%yIIu@9>OTY GJ@ -Y_(bMOX@wEZ*hMvnuEAb;hذb 2\z6x{C N\;H Fa7SZ*#[4QxI-y'4]?Xki*]8Ź }~ SY3 .Pslz|i= ΉRZ3u8^G*))w1U2X,AcBQxԼ*}S0 y Kg7[7o}D.+ bv8 ;掊'u_'-J1&D =l Q`~١aa a$:P:PJ[Ar ؿ!I p8hH*߮m{RF~𺦩 gy نz?0}a Ԡ/6D5Kk}>ޣ}HZnx䕪򫷐Шv#}`:vu-(.9mB""t`H  vVH[Rh:",(WNC癕'i$v뻒cKeZhsB6`$%Cm&\|GIjv e7Y5FS/ixx[mO`lĘ4\[B}V"@)S|_Yd1}nQ8ݔx \mda4l_ώH߷]vHKӓW e_/ϘOIl98Є;AvV. v108a:~7jeY张\Q^˵QHe?>?C@=7Dz(@|$5xom[4$z|7Ư0<-ALo9*8b "jvT| R`)_3M,88H7ju>n<9߲5:_Ū[l9/}=-:հ?g|]YZF@? Ԑ݄:>T;D9Lat1"|Q^" MևeW43ؖ0 GF(o~tT*eSI 9 .(~ނk9> Ξ: Cmt1+w&OTTv'O; =Oz߲EHY4MbIH,~٥h(G 闭kZ $-J4,b7+>7}XXMGr#f8ƫ.rVFي CuH'DO,@W_̈́,!?(7ےQ D8vb@ ca!2כo/4Vƞ#r no͑`cS٭^8K슂B]OW|a4C4Lv4+wěbD_m*ۋK.M#Wڈ e=z %"ťݜ,y%y@V#>A>7Sb3(%ysDfv;F<^5LS ,`ܾ,>KT4&rX`J즻\z`Ԥ.tjmrrk̿". 9F)E|Ycn-Ϩ^@  j'KҼ=ҙ1E3;L!$`e~b_bH:&j!A*M[4姡#VQM ׬:]L藕eKq'Cnm&\g1^S#:}M_x2П@0ywej5[Aj/՚2l,$ɮ| E1 5/hkwD_U.8K{ |=Uy4FAs18pN!%xp`x\>V V,d)B4v yA[L,?Dχ/)ZPYh)V| bOilEp"rB0 [\1-3S8k±l&M]ܾ^ Wm7 -=utBx34o!o͌ÍRvшt|/$uI/!TmC03Ulgn"Vzۘ)Ol+m>0}vי#t(3 ~tY+xwH]G %FrO[ P|)`hL"2esBln_-!4>H|JP\wfПfl\2ߜPx.hH4u[N皕=ź闐d*/2TSZId-U6{M{PzjHZiVx!Ot}`3j&_'J:mS9b#)0gَƝd4M{鞻{2?$RA r;} ][H1J*c+xiZ`Ҹ@uu_*ֆ1Qx3İъP.7XӲV ~K#:0Hw+&עCnO}uAq(zh8Xlq&<\ąugVH1Q5s5-5te`r9njyM1j9".t -$rz/iރM}'%B0ĕV{E# 1 Gc=ҍ9c O bNS8a9{@ђ}勒n%JpOY&+GIx퇩MFz&Fe<dZޣَ YRW&'0(O2[Y$P Fmَw}j{h;ԊJI.]miӑ۲&i8ʦOjj?_%b݀ACVuVmM׾ۮ_ޜ|FEۺ]Y"nvwD2yQXW/Lv3WbhU]$=qkA6L~yK7#tLn@ Yq|{ K9j__|p: Umg"ګd 2҆(ht =po*JZjx\acAy?I%, w$8Tp-4 >a8c|/D!z=$(>vb:zyHJY1ml8y7FfHJ׬o͟AWojQ<~|ܰP&qƊJH~|Ji$&pHz2_ ۲6V `#6 FBy~ /0eȼD*n^pA) SiX?Le Xѭ΃bX1j /ZiIBRVX?a87 ⒬SԐ~^ͳ''Rsv:x)bL.K7w܈[![As} @!2Ý@-7VmO¬-4űDP;IYfvidpG/0Z<1H¥4&W;b4gvq)8 q%u2Psef[+@szY3>S +8("@HL|}R8x/q9$ {Вˋ4I;'JfigTνnQAa+`H$ID܆r2js6>|&*mlLKՌsn4mtW-O0@QE~`CPy!gy+tIBd5ֹʳ,? X@CrkF@d I8[#M߼{V/H}v-'۝)z}VI'}7FMwRg^aVw8=Q8 T=}uIh/a3I/Z<  #R+Ի:G:{7ʂz^f(ERG!=U%#)6ؒ9e )jʾϚdܱbL%QN/c釶 1Oq<-(Z[XYP&GcrcCd/doVA4}ҫߌUed٬5B*t70c1R[]rI1iMɦ`i<+Cyys]/Fn7A2JX{WLꉷf [q\Z0tc&sșG3]S@ղ'| p6@<ߒ'3cͤrbrO1*s_x8dݓCqrz:Xz/#/Z>U@( A׳ay uְQtms̋HM be*_1UâHͿ ܡa47]D R3¢2=y>Guǜ7u0B?WߍBњP`HF`" D=)\nG6r6"r9KjyCppy[&}'WAU+]Wg}n3p%N*az4f/ǟE;SW@sZTﲗzC%߇+/ ybި|;ϳ!G"V|OQX+RF6 ҐsBJpi@eϨȠJFCVNձTɄtܜkDy )i^Tyg%5Nl2XWTƞK:70AI:|XqWXrUquHh;4$*EI ztVzwowM K.,-VjYWFj.u1. N 릪4#z2ӢƩ%"ЦƀEtƄ8N?gQAdS-$_zh%.v,}MIZ(fhTx^FOz&2H-.|\dJȭС7;?%̏dER]-"AMD rX5GXa1XZu0X-8;+mr`en-DI !BOsWSk4*x |v1^=ta8kҁlb~7t*ߑ9GvZJg.@0 9s4f9SC1J=΀ɺ=*wmҖUUQ}ժz/xJ\ܘc]|N1(z+REb_#2ԍy]Mo\_W&0M uK &jJ/+\u^ʓȺͱg/ݛ:Z|MΧs}=Y*'r(az;1{HV+Fr`TC}TH[bs-:; @@ȫg0FPkLML*pk0&߃{o]+w߃G* b y5(C|s+7#wd}φ畔KO\z{tR]No{0yV;Ϫٌ4l6ipa"8hUa2{ èVakO@ e7HЏ~_U;CĭlSHذ3B5# 1=~vשLtW^>Էbz\[\&e;C"?3oګaZpd*k_{kܹInfnt?k8F/" #~<7$b//ؗjaY`'/qh S섥c&z6~Hu(H3!Fbr?xD{^4U:7慒'Q͂j-l\%|vb-)ny=E)#ЩRTPaK7^sńGe@TFV]j+$JFJp$,(z"fl\ &1_7>1--YlQĜ@pY+ ~?䕮T@;HI4c.X;êG>yrĆ?N*&Y O,#n6gxjtwj':)޻uv/tG+Y7OD`i ):4))T\*0D(IR@[_Z܊%~=ۂv~lXc {He&+nIgNЉy$xyMl(YP"+6iX v8j;aLQՠ)XPP`X~+h/3,)Ge.A U k.Yݽ(S6R AJ6Zv+FpRU\F籃(=T{݃wp8鵷h1kx[+RIDzw~{Teg:01Nv9]#Ǡ*=(l mv !F] 58Y1?ٷDbFvm4۬\YGugmGdӹ{^0-\/Qu[Hq%klTP7>A' 0EbzQ5 ;V@WnxbE:6A80yScl"`zRGQYkP1e:N~C+inuDq=X(|]6P}V$44%^u&`02P2wׇOSh0AKˉ[Ͻr-m;qM9xqS3q/)צT%ʜDe9Ym/(ܕ7qHnJ9zTOԡR{ͫJjm&Nf#_sN x1[,F_u^Ckv{B-o֎bd*"I* V]Lsܨѥavnmu{lIq' pʒxxPb~t[)KS ϲAu$u*D#;z?Fޞ8kM=r=3rnH$MFw5BPό$PTSI9 FUUDp+._j :#^ nSk7~͏Ā}tzݲO ?b | EgZgtu Ѷ$~H/֚lIEn'^opn~1 02g[$?JP읊և/N nXS# AEϘJ4}ȃtaXC4|)@5:퍃:C!4z0輍Po%ĕ`|k-8VOCXSj4/"LsAٷÙ9@m7?hǗ"V5cGZxk} mUSR5q7/$tT9a:[[uaGU` d/׊MRY.g"gs} r;Q>`ǨKVxUB*0L͍hBaqϠQ։zGt9Y% Y.`c෶OL"UC>R5}">d{|~ Uow 3Vh[qóP67P\17>-pkLir(0C47ʎQ|aI)a $$K x^ zا5 k{fk% 5_E oLo mCiG1k̅nuo{&?JL'NJ+{Lt{l(L*j)s ; oAށVCK##Y5fC5Jjj~>C=d3%]poR-Qh[bBjlT `9/#bCunM:J;}m=c>N,9E.lq2GmRud.vwɜmt:1fp>Ƶ1[vBix*FG41ͻڑd-j2'-9Y#JC kx lC?ۖ#"mi0 嚌QHmr}CN@$)o3{T}3NӁn>_uia+dld] ,Cef21zm%oWCpPy?L>4s,zk9&ɪ4rmnCiV}g5VֲrfD" q9<'r1רیArefjo k3INN%ԓ'%Sn_aI^/y;_Tu= S7m }0 %Cѫ* B%S}cQ%(uZH-,Z,?&67 yJ:O"ٸbJwC +fw:S924)KcȂWuse8t`!jy *i]zu^#q˘^p>+>=p¤GpXܞ=yf Sl/}y3u@<AoMઃsNZ6"X659Eu8*ySr2CK@dž]%;zh]vm>q`) 2)~Uqphjݓ YM@%Eҫ/)j7%EM@I]-j!z hA{Q#R3Z|N]:\O,DᵾCiY!D݇_ZxLh*3# rWIq6n{s>uE+a)j:?13ޔ#a4QS ".XvEO,ŖSJSyw =vO%n}b= O[Ztnpj±Ƴ„5R-IBFlW<^YpXh6|0KB P:ИO|Q2 G2p6[9rC2xcm+ݒ0&5k;HJmp*tzH=)(b(ěijC]6.U3p~[{b)4j(06Q,ZUSgc2|inc[ .<.;y\F"j ?`lʷ)>{` p6+#"?i|ck^Eʒ?\b ukԟ{$[Sb 86D(CY`Հ07T>٠] GA;NYa_T&. ֥l Jw > ^:VW3΄\T` $v`!vܷ^:ǹ1^L>sSL#ױKDwb!Ԅp:Q)6So4QGta0hD2(F}ϽZׂ'3[f`ny %4\F}9Lxaĉ3Tk-rW?0JgG ;+N

ߢ"B+c=XF/W|\a: 8gr| ^eD s`$oK$\f x,Ao릚kG y&֠JUN$௯nRȩucm%JnGDtnTM~G=`y)ld0 wF:Z]`B"^uBXjYIR V,F57 pjA)=nRɭW(@nWX62ڋLc9bxؤ@jtn{N Vܶ95 ?ɅE[bs݌ѭ-Or yU'>IE$1J1x\trPO3bŬLUQQn-;9/5ՆoS˲(GklvM$HS eª_7ЎKn5Sm=rdGƘ{3{=~Jh^$r`Y҂(܇\/ժO'&'M߃u3r:X^ [HHA!VV*d@Eym qKd0U83CVIAY;DVnƈ!J}![OI?pHtV\0CzlNԌrP8@N |(թ%v 78-[} 81R>+yR̓=0^L8Z?-iIKUOLB:xc.xnhhOΔ I \ `Bz;LZ2J#?0/*8GSvj[]U^|5g+E;0gG*qz_W.-%e,X.cU\_ 3PnCr]6YdPDfe2K}[Am׸(3Һ<ٚt7=plSّ5efNlo֍yeR9}-Bt/AP .^}zWVa:iD\ -f=5-\)$\vƳݨ`|Ct#. R ]Q!6;.( t yiZTǯ/34dMP`)$aE'lOLr`N1I?5j f}ٓ *fP,ih0ؼu?N{QOo|^Xه'&G|ZY X bKʾ'glS&m >NK{ Nvno/bmdW_282M;#ǻ@N37A8_A51;8?Έ:TL\!I>rV10dnI Ʀ`Tu1QȌ ;Rc 2͝Bed՜8}˺JXb G%U|[lw>}ϘR GvG{S8tpZDLIM<7%!_@u 1gFSr_V4}OAMs[o:4 &뺆70u"'#0CRw!qSL^ 7w,J+x⠻r1kHcWNy.zrz+[p(IQ1DL gUC]ӌ ] ?b`v |0]o}?f}&9bU|7IqfٕeȂ$~g5s$?)`M]cVNxg@I[)=J;c ERTYzWطLdSt;eDשߢpS92xL]Zw GNRfXp䝱<#M!s˔|Kr^Q˔ V'טa:݅mo9)RqH,NʓA\-$(wо^K !g,3_?On (V!B?L*nH=xn;`yf!&fR!I8)XBvne;D_,CvoЊmܩ/MH>IHObvK}oگ|DCfoǺg"ĿCy}.T #j+f{\ hqcb;Jߋk>M6N<* ֪nhdadk} -O>q!XкdYm8:^bjP,fC͎rByv{?!F"ig0O:mP,oW5~-KyE6 ζt' Ұ:;igYSbc)nu,:߉ye<asE]EVMW%v\刻8|Զ'C{1&RA1>]dlK*{W(b 尪yf7PBo$рD0 $䴕O}Z}AmNn;/Bj5B>g E+vj/L]6]j-i3](|迈M=I $ګvnMhi8ܞD^aڣ$Ă{GF0GLOG#:ޥT0??F~)kxv'MWueO8cܖЁ]%Kdžv:'W2t~XcYAB+mY<D/>zn7aED݂`?J1x6MJ'i%wJkV!!@paSw!x(y_Ѿx `suؗ`Uq{Z69GХ5__l~]QyH\Lp0/pʻ:/eU^>4Dc\7c]bAh a}z9u\*"p&K&t+\o, "geCfa`Ӽmrr@*tY胙:z{}ny _ {!2MaiC$V0; fn.W2)vE]OܞkDᇞ+̱a5c7gOл }X2!MY.#pK)'=ꄡV >f zר KwKzݺm0EY73Es$^Đ GZL"ɢ$N HNmGlO]6Sc)Fzԑ=}@(H`,=Q5!̖Oλx3-Q aߌSzФX85,_04(?ܥ#-~<_{?Q_ޢK64")~DV<-xžk]|-!YZ.gJ7W.3=D.ڞ0E g75S'sma_Q %d%ZwACkf:[u;S*MbkQZ!~̘yfqƲOFIydF7 ]t406RM+q?^8d|o.A@eX];tuFiqRX%!8uj[yڽme wkh퇑ӂD1K.vchW]P Rnm57yYNO F`\ y:Sd%tpnͭ_5.}J&2wkƃ^4ecq"Qz hAC\V ܻ`!] [c`t)t 㿰g~͸χ|֚}j6 a}O@PUᒙٚD ;#.q 9BwFm:5(>9wrJ*'0IFm,yэIlad1N/rA`-²vIl.?g672廿1#׉krX=/?z-HWU.;j)VʹK폭ߜN S6fk,+ '.an Os!L4U6~} P$XpDdS2'uLJ~7LQM| :bi*ٌc? AxQd*$6Je}eFW9o\z=n)фD7@,.٫IiQ<({A֘}urAs):uLl3V~<U:!uQr(qVZ4am'L^ g8\rx*+yUh2} ἧrBܘr"^۩b0dpvL\:e-ʱZ /h0drጊShM?Z[_q:ؖʎ{/I'# DpGBs‹RAǹ47A˵}8fyLx"\Xj#y*7ĸ}kRuy^Rw'b XX9I@4mMan2A09缭JO4g']Qq#֛I$^UN0vj9,f;⍄?Yw+r%RFFP;(@)(|H& ||鿥!Q'ulJ"j“*;S3w<M KjaD&  M|T`u X(1ÛeGSXwjκd}-ǭ+>+5l\lMfKQǽ~_BwO?bG(dA_IDxW_0\^w*Ԃ(gTtr\(S։ٿk!nAc\|Ʃu3 lѕyjKR FK&蛿cOYZ 1j?s Sǁ $(.VszVOm_IaZ""VC&bGga %D~=AAٯߞ4p-D7GxYq;sg9sEF&W5,O"JZծnPZo44a ?J2.¬WўAa*"4G?$Cp_ײf_r*k6=ϝitYo5@%rC;"VLo(!"(MHg>mPWtL̹qL>fp * qk(<*0}4)@ &l'Dx%&W *{'T Anwr4$h(/ H7/qtFc;E0gR;Y,ihQ_&xCT7-t]nKB EDGP fQ|ew+t.js#$!Xiwj D߫OM.W5>@QnR%Y ;C|ek8qQ_T^%Q&)\,?(,kD@iZ+Ԭ&G0*/|\B!ű_k .UI/ m~cW$׉ERÇF/j. tkXi Xp6~e?lK+. 8HΠ+ .]Ь<]-ܹɭYzqsMVE+Hp^j@!q%IʖI9]D>1MmvpjY=Z9nն[2iX{,Ve'XWe,ʐ忺^CasG\}-G$RbZ 1lS1Ma}+ÒA`naEͮ;(T< 0s٪>8%+)mC[޼+Mk)MSUSXLDxg l˱:z)"TKS4ׄoV"d#C>C q!{R .k(ƣ8BҴ3]3ida-K]c(?ai`*T6d~Z)0 Ѥyn]i[@.RTZN udz 𜮼5'#ff'JsVyVYDdj :TH|™r%ɦñckpU{ͮ׉ 3Ok~Ŋ%t_KXhfȋ&>D(^y/U_) e"EDt@#LaXtRs/~=n?Bp`O%dѵ7FgwQh"2(Nmo_5|xiݙlXf. X ,~cKT 9"馮/ |+cO,̄v TV1OQB߆Nr>|^#k[y1S.ܽ#Ra8`.-x0IZפN A|%2yCwRr5]K%@xO1oP$7eRyR /QZ@ѐ^MAjb@WcBzSMJFukq3wƣUf 72cacn)R|s$&3^kթ}/NR|_Ũ`RnKB4mz<Uo|UGaM㊷KyeNQ {D/$W߀[hk$9G3Tw{ݣpkRPiʸ_X]:t?^:rnϞv[VMj`4 B#qCa!^c{IU'g-!DmF[+[!mVKC"E;um3$C9 ˯ |k2Tc{֨;8<"Ӹk%y'bٍ7fu亩ꯡgOzxiQ[?\<vٔ4SUo;jyv"F  `\a|(9݀{Yl"HdYOt(.WB &wpp]jGUV/"Ep?'Ӎ#5M#q ^4xJi~jse&5?1&12_*xǰd|X>~VBM*Ҝ2 zc]bKS4Qs[Lb`Pr"͘–nI` D#+z.K m 1{ aі`J7|UA:dm"YBԝ p!|E}H|^513WJt-Al\^jN&Mpտ Z ;֎>آp^>[T&crOqZz$^eP |Q%SZ +cGtiN!\Ɪ'\4`P0-c5eC+2c`0[ѥ3HžBcy;ڛwŠz)4?"S.-tLWJŢ*Rȡҽ wx`@4PG&uUA FjS jts@DDyŌ?A6dA<&PpݧV}6{L6$KqЛa+vmh~?\Wk4T n-۩nvmIi,k;yyz o)z-/"0}8}An/ pr.0"{N,s V`. ה_y=~Wdp(Q$$AI}ډJsUjEؗK#?zc=/riNluP` ͿEƄO6:aȜf)s wHN@!4Kd!J6:#1?*-j[MdO-`*䖐Lxo"hU`[Mvi2e6)^8]vZOD_~&F7 3'.Zw&@5U\?=_2v)ĵ׎6458Q<"]\& s 9IӼ[7߮ۻF^vq2e7!]<*R@c(&Z?"NwLY@FcsgP d^9 @#q Mń>gFeNnbV44 9V$aA4hSrݣ2l[C~).b~yWg̃ulJѶv%̃${4 XP^v8GaaHՇu<k҄Ws3%>7&-vu+cr1TYUjџB>5X7nzTxąvj$ 3Q,b%fiֳ+_uܙq>'YKj@xYFK< i [RW>_`Xl%.'ґ[6r 8[nsoAB:2lc1w~U s_˶9A#o~ >de'Oa[ äw1/2g!g79~$g)KV)x:-MBrؕ~OzfOyQ龹c ~VAuFਸl.~6JӕY+{-iU44V.2Ub0?Bgm}ʌlH3TM\nUaȟ*A>XdJf?b ,k!8}UʤW\!BA;(Pl]AO$!:y]eӒʐ|:~ D9 sC6BZY貊Nh(*<89ЩJxHQR7N!m} ? yt ?T.TOˉ(ay봂L'eH&W82눑mF_Ռ#Y O4n'"h\:tͶv *rJY9RwH4$8 eWp1 +o-{b_q|C;dГQH[ߌź駭9͝u6iↀ'|ł@(i zjxrr&96xB'lQQ:*䌂>y?qi;ߜƭbo*Sdw ׶uBQcDi'SmdێøB*IkBZlh>1tnfRBa6ZMCuhNI4'ZXc>RqWdN %~f$yn|;^9iK6rC\YF Or3L$c/kaYBLE*Y^Yq_]JY-LvP B3kR?%h8 ^"T$7dBi3pA&7 57ky>& xẗ́%歿꼣a$}29٩ybqQR4ͧC'$4Eac7˵dX뭙vjH 5+c=G0OW.MHuQq) 3A?_mN8_^B3I-(<,A'e#s۶:[~ן|SvĽ~ bޚW D:{͟W=G!^rJ  jBbg2W =5`2z^[kģJh6|I{XsmWhQdr3Wbã~(#ieC1k]IC>+`dImR%d9etAo]\g" 0ar?t`آƱ̤G5Z3?^<qY)Z')Opg{]uy{)-BpZweh{(aOŦv}JuMJͼ.8,%:c=!J:&S^KBsPta)w jWqÊ?VUX MXFgUMjp)T==m}+(t?h7S{Xհ#^qS2k>"[py8ۉ-͚I>uSC 6>(3Qd kmPںV[grqFh~*њbkؙmJ>ƼH'"Sɇ'# KZ2=mz/0;ShE}g_#<ͭ2- 0(WʲCdTQS>rD_ wO4u؝ЃwْZYT#Eeh,֑ӑAs'/Q!x&|rJxր}ZNЫ t"+V]g|, uyv} K hei G)~̦\a/Řۯp %[ ޱXT\MQS=Gw٬0jCwYL"(g]q uF%{*y3i#ү/Ga> .%w8$P(Uү^ +w-RD8TS,; % [,c[yJO\Ca$QUgWRgġtw@D)N>O?x|?WsW {a׊N0Yщ%%) "k+R6I;~!sl{hO Zf;ip_5Jɮ*|9pie~z~Jkl ]ܥuYl{#u\ZKiby)|1NWUGĀd֕N-iR-,fZԕ( }e dr_pcgd>hr6bnv6kW&8АgF?8DLaqjvbtZhCCHQNi56ǪW[)bZWYH|Do@4A-/nncCܝG9dVWR%ش1уkE Ȟ'+}(@x| ֯R!8T}lp111!E7p*ʣ!/LILÙMH,~"f?晴gNurIjG*Q4vNb$@.='ҿ ֘}P /]M &0/@ޝ0dE`m3X͒Qԉ/8fFߑQ~7CwqS(C[ eBÙۂQ 6JSX,HCTyf /]Qh߭%',!?k IsXnb7ul~(jޓbqJe6ё6zɖNk'NpՐ G4 /x u _%wE”[xY%??#Oa=k؀tOi-߼cʵt3(rϓ) pL8ޅ:51jW!C: .O)R.\ 68ƅbVWՋmS`* ̝ ?w;E͓OM5q5^Zh.Il c@HgbՅLjb`O+ tHFPEuBfuARt+_IAQ9kptvOfm yٹՅ]pfLnܘ<8YǏ9f]:>mV< p4Cs eԴyraaz-Gc& g3FjUDQNб7[+ .^OS A#f'rP2\ԉ"je {O't0Լ7J8c_nWEC };w{[U6+~N`K j0 oR%}h$F_Ao+՚\a=]\ h'fO?ȊorJWT y X,'5'?ao1ԁq%0ѹPDຳ[whdS%0Va+wEB *Q "DPl3u묏"MQA2H|I6Z9*_=,,Ո jے֦W^P4ĭMWR+7YKS-E;nN;$/GؾIEzM`}KilVhLٕϱְ'3H1X/sT-*ܨ3?>uh&Q|msM&<(cK8e7KѮȆ6o]fdl5p~ <'Ν+ O=>!S/d "yOCMZrU|4+ )rff>'"}r+KnqPKw)[ ơ*MȦpAIhzߍtiJ =a?eJH1}KFR;Y~UY -hVV nGw,S.3?ɲR=6KQw:v%{x!f&iX$gV E|1(&Ѣ*x)fQq|=~}̟u4G::+qoCO/** Jm7ll ò?/gw*]zdC_y5sq1)w`Tt~ ח̗qOQ_^ l{83s:o։f&(bס`=bbh}~Ll޼dQ4jTĂ:㤺J`*miO(|̵4Qc]"H kE"l`?9 m(u9iA֮gd_-9yQYp7/AHGQPg[D]'8у2 WhJ o,e WYj?Zs\ 3F+τ ~:4D2$yt%y0agYxPN%NC{Jͤ7EW[M1N48ăr3b*D7Lܧpː'qZt)W,?l\~zoTnSPGK"cwwǽ[9Y[̰l.ڱ/K[L S|) [7Jw27Ye5ItY;ט>͇ l+T 9.]`Vr.sR|?jp(ǭܼ۳qhc\b>JYZ[vuo, 5_ !9/:Aq3FNyeYs%Iw'zRp!LF ;wTM1n3fpvpqpaEzxERrIlIAe:,{ ܿ(mXBcxE{L|\*n#B@cֱ:."=rH:R`RUDTt.̞8)( KIk[Kϊ[9sgQCMx*ng;H wt9';)w1/j\t :g9rAd+`V =Ge'4I 򎊖$9G&']xNjp7ڤ_|,Rqe'8^¾MѬLO\ј4DȰDqVɷ0VlgnN)cvP]az#2,,/pEb'e&ԀQxo|c3CKG:<N@8Ӝs[hc Mw9~rwуoލU J0 Z;[Z%YT584;԰\4u3(cmk]@ ϱ,;A/cUJ!,4̳RrE%[`*Aw*`vjHANDS\Lkf=Blkɞ=•c̚sP/ +fcgo 0S[2;W8:IR˄F'pTKvC$UfvqWrfpazKWGFKTongΑ<MRaH0&L#*u7E~C0x_Ka5Nʒ'PkC%Y1Oe[xB;q<1^92 G-P8 3urMt"a+1]5-t". ?*M)p~ɮp4 ͔!;Sz0|NJXK?.5fMev(x`+M>kR Y& *N'] šJYlzM5 [lUuJ)Bpt୸sFOخʞ0`D~ZVc-c&hs_*+!-yzQy-CcgghUH6I 8sf]k'm,WX&Ut)ۣqQ26\N~$:UsS 9!|$H-JC| dΦv ]a2;K솤2 w= *s%$ڛ RtG54}cr9Pe<\%t&k"kmOZi a^^'kΫ_5Uyƫ ? _vqhOBG-uqAHT2?W7Dӂ([q&] f[@⠜Kɒҵűߥ v,fE^5=iMă<9EL.$j~"Yь #"',Szv/E7};B|6V&B$.4HߣD :!zH@+ wGԦ2l4(:>Zs~7*8sisT#Ojeeﺴ#6$sA=ԈK^;}I؀FF`9m0O׌/4۷d}UxU}T!Mq >31l`A)Q$} )a8?-a"ю(,Џj:*x@R`c.A|\7z#]‘Hqs-$y }L0GyiQ;cm y 5 uIvҼYU8SBZ+NF<>EJQOhCӘ=`A dZmNb㚠`;ۚ4;Wj3!`Ckv{drHe6F/lVDll)aש aZ* bwJ8-Bpg<ꮍ"U԰| IJwB[8D`6嚈`HsdR{hk+ ?$d,W jFd겑M)cbj˜gY!Dk9{ͨE> h 7v85qz4?}^W*5_&/[tY)K@kf=-u.dQ)ߜ}MCJ̳T2M&_Cjz;!hU؊j @|4M5 9N<^55ؓaN_m\ ;$UCީ m˓>b,Qu&2 bYg% i˂o7 ]#izV~qd _V8O@K C Y/}#1XJ]˵/S꾲cS򯝢ʽrox5t&,=Q]yTyxy#7!bM]HP#h;WVF=Hط0#Bi1%1O7ݜO( x.阙oŨ~*${2[s/d]q0bOH DoJpFj-^_dް"c%Ik}<|_`h] G8Is1i;;'p<0(phb;br%#DUj]%k+u&pv9۔ ýĥQ| @P]_F)X uEF8#xM'^ʖAY}(DsE$i-\e(8PŽ:L7g\35w+?ҕ^QL͜%a,kUb;pp!nnфVwӝ &$s'Of+ 10 'ɼ"ηc3V vue]apOXtMCny_qyy!5n<QJe\Hc `vB};\l|&QFC Zm/ґ"˭{&jDyh y=N3;\t@ҡ !o⠞:0-5;ұ"1HtPwIJ&/jA#{g#cozOxئ]J,} XWWOdW/B  `۟3._XB-/+QCJ/3]-/SlW͔p֝3Uԃ y`5?Yvcje#pȇc\L;Wi5"{VF ;/9!(1/WʃMINH伽o &Z-yj8XMDU8\ 4|'hNi1Ug%6VRj0SX8e0MHnӢ I J14f)W*>C"܋NqgꌟEz7hw* ɢ{/ìmg;`);;4| 3(E4'S,Kb4eAK8l~,-82~:9IŖNުE!tحj $\]<-rn&&A< L?*0-`b-vr!Ǚ(sDELl$=)[&%v:!z"n9oAt&0 e.T?!z}xJ,$lɔ]Cܬ.5骽jS3G "`悌 Ei yk̯R{p9٧$2}%Q9A;k&iRM6U%bG!e+86!ffXCk;\p*OBjrن߷6Jni6J?t*sTpe+r}řy_bP?\Uq ?z#CQ@PI+羷X%zO1x1 j%l2WZ1w:p09Ҁƿ*(n -=iNC3ˁFx"ޓeÔIohA9dUim$Wج<V*=h4S󼔨͌/=x6_mV\Z'1cM$=ZT]\MmL.po>6+<_Lsrs:3pAYgsNQοUfi4fD8\;TE1EF)*%]3T" >K=YJ[XQ+}Gp n8 0()¯Ԯ:e8d X|s&du$=V(R LX.ju Ii[Oaӈqkf=^q͔/ڲ[|;S1R;"qe!KZ~ .q[ߓH8b:)hԕ訉)"  =,[RٯU]Dր_a4A$` Ӊ=VT̴^}dUTJ<.u6|䴳Wi%CFr^!K^%R.>>|tihu!eniXuI27"k: i}$[ yC,FcCRQґm!r^~RdGױu$Rc"?OoqXj'2&U$/HSVdMahj00wƈ}UǚBpK>ۅCʧ+ \ 0Y'~-8Iy (c '1J#Hu `3 q*V3J _,A!#OEޮ".$}&BX[ }gW^>_0Cbi|QK_cfGf[`@EWH$3zg_L-(zTK~Ư'.SS)cBț#d|I/dy=-/X0,:;2٭8ag V*)ṕնVa!$7 t9D6-WS+I*1h!/A^ugӑO1֧S½).-g@Mrv\+;G|UE0~o+-m5K8xMF -^2z =™}M7kfpQ4YljgDy_ȧO:XW /2Q4EyCHؘet-[=e8%|+ϡSzcБۄoRU=1ypFTx֝`PbS>wzsI_L[NUhV(PFUU\3uA[Leש8 qݙ⍟#}<9ܶd^>蹯_ˍ)k+@Ȱ+QXH4BX&D+S"Y _-%Du1Y O]_I!e7͔@N bhƒLasay ѺFM~UdE7xKO?}D;T]=W^iP58ƶǰq28)BWzYnжQMMUߥWvB?|s~GwDf[iI'8mveR[z!bzH) &"6' Օ*0|դd ;xNBѯXͮG{u+ 'p%K3gMgN4)1 w_E{J@ CR~AHc`owgd?䝍]VD%R =˹IGx;z+ }{$%圃 <4iQuGߍ.Ga(+1V@n%aB$a:428{N0 wg+7-4pc$̣U wTNW0ZOa ıM7[}-hՖ8dQb73}dY>΋)CHoX9d\nGoZp%P&p3P=E}10[\AH^LD BpdLHvXOwBseÔSF uVh r }X=(d_Y3q2WMՂl$U23C1,p1Z.<&"!3C# jt|^ἥ4fDaҊP}XbH޻k&w~򊵽-pT^+~AϷU7?=^EJ\9΅hgt@k4o#!as!p'o$-eo޾f*f*Z3Rv82mmݿpŝGɀדdGF2c O|"%Y\%O"8%FO2_DsYښHlkOEPѸᾥ9(}޸P?m@)ٽ RH~=ʙ7[vRfl2yH q\G^,H&Xӵ7:B"/4B.vJ+keX E7W>lmETK.4{&]^_<+c9!|a*=2cXGuaEC1rDel[O@T_H.k!ss$*Pij@'"e v"ib=#i/x[=[ף,0`kŒG3H :Y27X1FC%.O y5+O\mv%x-e<,.opYC/\8T.= CX(h86̷'h MS^~Jfu׍[Gl'rk1!T j$ 70sP5 Byn,nx@RVlGSz1|mH@:Um5=Z{M7 ǰ. v0*e9DVO,TVgԄ\J.11h; OeyaMB].~ `JYȕނ1_ؤNvQt ίHWF`zHcǺnk-m5j]ML&c:yr󾡽Riz> #31LһӷK33J g~bi?O姤Am:oΦw( ZTK n5+fJ]@N7 `Ma"oy# vh,^]=짞`Gx2B(d&Stßw1 %()2?=,cc8BĚ*18jPLdL̸!3oBdKQ|&]R*XGû ԯ +{TL"uK؏ՅW\f}&ϋ/Cy= UR2IS2B=-:S%}6oZX0 }UW!A3NQ\?ZӜۊE Qh.y?``u~ۜ caa t`&qhrEӦ5hsƳUEZ~uFTb[sՕx{֮-*œ 2 Օ&M~N[[5#j6R7xZ`mt'q }'ȳ>NK#Rϐp;nB@@$kSVAa|/Ĺk9H,(,fp:М5EM.O/arYo+Dk 1Amah<+Z‡W88 i|2Y&^}`<60{%B`ީu*A!?&L3Uߧ}b<'T_1:Yb9SL|eX9~N?Il1[JណȨkx=|%e թY?q0n/sOE)OK "(Ӥ۩=mt:ac(W=am< ]]i!Ԧ{i׃q'e`uKWԅR:BSS RqOr]380[E$A7>*4tHj~h6[Yݼ+Rq h,3Ew5+C)W2iUډ8ptٔbK#[N&֦2{X~r"9Fԏsx^>6_otqqAhwcu 2$ǚC0,R(006[Rkfn&eW/Y٘9ΰ83?bĽ `\X"Wv c-5Q hZ_P(BՒ9q,Qt;y92):ctކ/_U/?8 x|Amk5EE']CS>w9,\=/е:Kq} -xQL@TC6ɋS7lRq>.B6?as{0/)aMdnOͬv϶vgBw#{2ُ9C:Gw5{ҰOeACqd=("}uj#D1ځiR+`^OqF9/2 kyk?%Z 6rfHMZ vjlLuweU >r~]21gWky_[C3~7g1>XRO|6 ĠX(H^1@l=q RPZ^oHSCn>R[5?F@ͺK&{ 2V~Ȱ-rZZ&,`1 &jLd8JiwSQI_2+>](="/ y2E`)[OB}g=BsAt9"X +@\r٣ W\Q[XcCo-]mBך=t7Oɖ=\zayWԽx-n}Ը *;&HOfd'W*;$,5ӞZXK5㖍V/k5".isЯ=xNJnr# Eb=iS!`-/yΝRGMI7kvə+wQ]W2xITY$E7o 8f@tRl!g lEM7[ g B0`=UM'3=F"HE% ܝtois(tr+kJЕF)5XZb?,0OQ H=*@lUO$54깰x} r71nzox5"JG: <;Gd>E wv08o'2wnX+Wx?%QXPbR:~j?^4:?^3@2垑N[;232]2ź&7; tPDh\#oІ4܉aᥭKh;0Ɖ1}c9YЪYvhpyL?_Yi^pB$}A)|_{"w/Y4!Urz*+Pñf#.l2BA |&zqP`f 7݅` &5khbXi sr! d w4ϕYCFeNpt28r5j~| D04Sٷ~4f{{jco.}H..nMvj(S+0&UJ#+H5jN,֦o R*u*I w49tsfxnSMTAU+~itAڔnh5Z}6o;tV[lQ6uk?0l"%z+L( >7}7^$ E/KQn7Nbҵ kb,݀d\ˆ*ZV%{Կ68FG5ݴ.g<0T~DO+ Fa:["H`·/$Fa}U }9VhӢ‘1"=A%ej""(.Nl'R=Ͷ1]leCڀD:rjG yM!c !OaC!ETmPȢԚBRRIMTЬI>sSNYv{`IO9c)8fQMKCu e0b gT 2ѻ"n }p9sT#8 h4S.iTؽpDz"r}]غ0l.:tEש4R/!J{aHɔ y;+ sKw"gP!/22.kސFˮice)EsVtŀ^ZNu>dԬq "s#\ A$̶p<a@ъ: 74I-':\Ꮆ'T,DEPQU}"т[IS,V"F}du<.V4լ *l tjw2,6kG8҃pb5lV}MPTCt1+NfAxZ) LD걟)W,p {حK)ΌjTZ:) yiEsp~;>1s0V$l C)rT>/P%'jcBw+ܝ G8(XM~YxFફSU(1V4:8\-H( 34E>Vd$Fg.]tKXX@mx5 hK!LZ&1B'~㴺>ovê-<.tXhin i[2DB/;_imR]H0jVׂfñ=*RQAn;Lg5u/[qczQ|M?<̦CMnqi:曳WQ$c5muִ8nN.s" ܫ2SNJ=X;|)rz4h$T?^dIϺV #n|wrˆMe S({X\xĦ"ةft .zu˩Si;*0d@Gf$9A x IHhxuWn9]& NJ<_Xn+ƢeeL6S9AwX4̗5erʧ600owHXU:Xh[X- +QsuZ ):wae͌bnvNHw.>u=4 |~%X{%QuS oJU{,w9F b+H`Y=# et1 !iv[Y5SA 7(ESf'^ S_7dqFhH7c= bD p )fWJ{/h6g,ՖD?V28kV\e)`"/ƠVW*D}X=(6uq,aLa|v!qX|v"D)اB6$I7uV &I@ҲA%- M%Jj/ieJ E0PJ!׽Y8B@ܖj3C lz؃31}!&0AMWW!FR%F4db@peP]3$D e! ۾A~&xbgb j+9b:ciHfysZ SI޶ܙɨdyIx',BFMH G҇b;b Jz¸2R6,e͆9}+N)6+ L-MӬ歅mJ@j4c .tdHz4yӹU6crv%y'8:fiΙ}"^{0&P7*w1*;8B# ?ԵJW{f!wW h] ́q$ A[d/4S%9 3O sCe,Ky&& mDBb:ABpuFxM30#pWd ir9\@0pH+2+>pDn)̣GlkmWA޸lr +)0u9=^{ϰ6"QǘܓLx ?x 'ƎW}4NQOj8B#bAiKBNf=%r)$>f}SVOl٘9 ] d@hg6)CقA#k58ƣ0_8PCKLB43#M^%/{<:8фO#MF_ZlzH#{,>@mF;?tA{ pp Є sf3*ӯKB_'w\ Q䁅Ξ`|R Ik<#PSOAuˡy/n+w< N^Wobaf޻o*;l-Ȳن,qbɌ!\:,!\nGH4me澮]Mb˜G՚ݯў2R6\8 LȜ keNvYm{"gJxb,,se1Wő9}CVϩ<×åB-jI$k%xEZg¿dyz ́|*;N$ }B0h)Me 60ܬZZqWx{e$>\mHuM"؞ QigKx-]u=I w{0kҬS̝ĺ5NЪ/D4nQZj/"WWFƗm-8Cp%s,ZU[Ł=*DlBl khO퀺xl _џIއz22EAG/FaT0^ktN4q'r=˾IsS%6UHA(ƥsvv{$ ӂ#Gzu(l=%vQkH}dx [ۇ衙mhNb2#*O+м-jMQr< j= Є*.Zoۿ.X19ڨQ(,GP 6c%r܍aۜ<;ּ_imV;+rt؂nDD grfp ht= ӣʁ6[b*6l (L%+a"e9Im+:El;?/!B.9ZE(e؀rH9k={uD:P6|{} ,R_XJl)3<t*&6CQn%?ޅ=Bx`v:1 A)iC?8#!g$kM_/fSt2)$`voR="#p{!Ћ`Dꗾ!1ɲ{*wxee8_\2 fTY[eoY+qV&#xȭ&^Wum@r]rS,'ug($7_pJo'RBWwȏ t 0?w(nf|nannJ1kݸݮ@ LЂI_$kd_7>@|776Kb7ZSR[ioU8{p9H cH;@-,}wz7HORI->R a)5:vnf: Y֨u+?`٧ӳ@aj qS~Cx#QH*kkzb #7{zs&^{7%%x9bᖱ#,d 3$5qWHZE:݂yNfI#AyA(,AK9 RsQ:ڲHkqﭥ+DK: ,'"cWySb2‚)DdJ?'β~Y횘M2 :Zwi\1Z`M4z\ |v6sԂCV%nFI&LL{Z, J5qM IkUrVŬb3 uC]2iڔ1φ+D񽆸5q2fx62!ztWЪ}64pםbV&$ShqYTE`0G:Yxb(<:O$@OŌh"{w8{ąL| eN\_K Ҭpq."BR޾.*@Cv߶)@v^ ꤂Fp4݄a޴&RN(jNjXNX[m:"Gу [AFWv,eLV,΂5(B` (m&k6Ta@Euˬfy%nC Nn޿A}Y(_?1jy֌iXCG\Vi版}E\+m5y"0- BZ <<B|DEi!19 6 nArw6Ut`|(tX@G @K3$T &B: JwBA`WTe*biPƴqOƂ~߹*mϯ-4 W kqJUkB -v,uC:XZ23uI/KL@ ~nvSPKޔ"1** _~9̣n^D==[`[Ma,Si„ j3`§;YL 69( iv[ѹLp៰1p?ӊwe;(>B!ø]DzeRzwU:;ʏ$ I@A=hRuWN#պj幆CgxRrIX_dKoaZ zHǺEr_fgɨ?T?5q-SlLkU0 >E񊛠g}blr b;B)x`OҤ*['ɝIqnB!ӊ3t-0" )zB, PMU~U&so82<I$c;2zNme9CiE$.4TE\А(.{G:XY ]rccEI 4? *S~Cxw~l#aӐߍ|#;<4<ҭ-D@pTIJJ E38.+5dy$MZv)1 m=*#$[L?_ꙇ#։E~W!m-NCO 8:xȂ/ %kHyS: z YNScU7UdC [zNb [o!mܦDˉ+­oWKP f2k,aH˵o~S!&¯8_=]UG wZI]&)& '-j|Q5j=^MYijz tY-hx$-ĜXa º]86&A_ᘦkhWqde"b8̐94q\ֱbL yΥ*9 Hpa܍wBTEl\ad!fCD4s(-z BvN{V>7?_;:6q%InNٺ3-Vӧ3Zc-(&b񰛕pLŃN%6 =i쾆.p9E?_Rd^T!FOW}.D&Zbs_ L>6(YZ?.pNW=d= GN9. } ܴ?alܥ1JWmY`&~L)}7Zc,,12%oyy/!&0ĊCC6ƒtQjc ?sN$MAi4/}$g&N*m6AA^[kT?*jk|fk<p.4TRr5W)5v̿.؈ f hr^sڭLM]{61WFo(P%yMaU_c{!YdDã9TtWݼ%ф5({ܗ'n[?}k}3N9k#N` / u.؏סšGЎ{N/g{pN41̼hE#R~غ(!/>B36Kp,(,}A ZEYdg @6=zyF&1c  j"8@S~6ğesշ 9ml1vC;ӢC_sbYJ"HZDKƁSz{ 1}Ĕ /cN}!4)^fvş S\7Xn $A]?v_1XI7Zg8U3[` -1$8o.){آ8mLqf3P:WhN^8SdL&S-{ i[pʩGzqXPdU _9-~)u2zE͕IU"\KH̳@Бx~VT\&@ag8piÈ`3ьu3/JMᅌ@JA Gǯ l}a KKr;SD9 M-dq\ESE: Q`Q`ݚ,8 M>ևփqN]W}zn+LVz}XEW%lbG: ^U mqIm (?=Ǻ1_2dO_՟*6hF'U(K|l@.) C/!Dҕ^+ N5%;&a#Zt pT,Ә6 C4\\)! !R֭To&ynQ[?1@c4+h HA_{n(]w;gjYDW;>s-,j@*u,jX:SyM AA˅u*Gs#ikAXK$1vt˹^Gج-夬 ӟD#->ܨF1l\q{Y̴J%yImڂȴg^ئ3{Py'v4~W%o`ghҚnh(-IAw;1RGv-+-< \cȗx@n$x(/;/JM<D(gh4@bDN_e9T5Hi6%H-u&@Lj 2.8~yR:YMQ=Smi('Yz0)Dľi䫕&;YһSnDU_^,M^c4%P!{~? K1#_陈tٹ:WRZCwm,o'W~)@_rB0Sd;Q%`>|f߾!d`J91=pmׄ:9Ȼg1Є[z&F qOۓ0 $g~myxoѿj.<(Ϡ aUscI5$VB t<>H]t 9su0;"P nYHObG"/}^'2j![ 6˼ѭ} <&˿aY.+@Z=;囊p~h6-'>ٜ>*_2ZޓG}kDzUùitݦhOt5;Y˥qf|#Ϯo &[Cy͗f,\Jmʏ?_+wkEJǼV!7nXO :#odhy82mD@rv%#'r YqFCwUce}% `z;kHt 4X+b:wUx x>3f {{1&UᰴMA3k2yڱؙ=CtΟ~Cb&T}kmLyU'rZjĀjh\.UgV˔76"q^AayF-bJnZsvPk[~k$1Iv~ Azg9/ 9=\OT&g}`vSև6ahsTnƲF, 򪈡L/i.FJMj[.9eyLEm}ZUF7-eEs$pDz24b1$:+ 5 Fc~i%VEdL%itD_ mGyُԕWŅgcmSX-~p,x3α9{;pMn&T5S-\*YIj:w]YG:e٫z Eո,T#c6V`#&@QL,hI>丙X%p{+q-[Z]⡐%:Z?&M\oMj+Y}l\X׿Pb<*4MRQ'a&/%;R_Qc}fN~lĸ[fTtt֓ҐYMiXqy8[DV(` yk17PlU-^_cyVh7}7QN^J+lv]h+'wɫO=a3ɜz@3#a︨_>! J\Ֆ ,ܦ]07SXEzqei2Q]+vL~TekS'Mn*Ơs5mŴ_ a ,>ޮ;3\,7FCΨӍ g ؤ] /Q3P-~9NY̪m e\ɘa?y+*\Q%`Bb_<iU1RJK7 R9aV!@{Ѣ\%1u"An^i5+ԇkװҚԳ?F^%έK 䎌l Htn#c3yw%r[ʙ%/Q&TT2|ss?53ҙA0Ipv%--|y>CssW,t@9;+xPT0䨓ENʣYI/ t)ߨ]mm0Y0M͋3I47J,I%5WlBЄOm^>X'_BWs!V9ְ؆!e*m#E">[cFfY]5}Bᄇ2X2LD`\gI7:'ÒU#/N,_!/%4n rn3S^9u7@G#0q]sRV{;`"?Kn}h^mA// V]t8Sk2I<ŌHf[˳@ ÎH&>B1NV)n_ P,,Aw:,ć^CURt[<]-钜we4 e9Jؼ9kTI; B5i l _0gco՜4V}i,?цgXhɧVq}a:OJvȺNIĕI.h_Cgd$7e=^2_izC@"# ilqܺj42%ˈ`R/z~'AISj,yRٌ2MЊ&‹ap?6F7y:/QU%vTa'X;&&huo\{6TVz/M6,~@£wZ w J(Uӣ~kS;z ri#Wxe:8}Rf;G\+ahBxd" ~Rܻ8ba?7$05|?^4~k*I/o"|cYt~`_< >\ɤ cѩm 4%.z˯DTzZ{Ⱦ!9MrAKZsVc' ,s|Ȟ/FoKKƅo;LhRQvG|?q+Qc z0HGIV2T ʫv%bf~bBϱ.ƖߦcLv[f> Hdg֣Y KCO%[F͔oL.ǍAqwD|xcrdtb1%V}u#~<\d3M$>";jqb9*C i Wq6f!lU3@דS'ߢ$D0e*>0ЋsT{tF'n[SmtcY'4y!ʷ :_J}ze/f۫N#a'8L^ ^je@tzE8 PW u4XaqZyy ]q\: rY*eeuO#ʩ!t>qwERTr X7j@nA!~{87kWTC?YCQ Òް"?6}Ct$z;Op̲[o1Dx1 /O#AQ(іwp-z:rI1sG\ޜw2's"X`n߾!o&r T SmdG] hPgj> \kUyf#: Uێw89l)֣]Ywāر14$xzaKm xR؉ѫEATXEŸsM9)Gs=Wu~`_*Ʃv8G}ǾKف %ཽ J3f%ÅwB;'<(3C! ZM `aqJ $|B ry;L}4> ^v\`&l< Ɔ/5'VJqScV <&\tʐP{kRAmҷ%Y>*Gw65/F8Z9.D}>qʨU,7Zp1iW4R93P1c7SeDdz7L`.rQul4np^u@$X@9{ۍA)MG2 MLprI**Oll9ãԡCtCO+#֫@-c48yw!1ÉVg4D) /l|VE13U> \}VY r1ֶ5b%l&8,sP0\.uX*sGH۟ұ:H\镴(+MzE=k!>^:@Cdj[m$B9dcqg5Rڎ.xSte<<2|S寵:_'Wd*CSY#cM/%~P~'.96>;;!N^^r"Qe H'cѮe4a1@{e-)Z1^䔰Y濜C.N<ʥulC& 6|Ǩx+7l\Mƕg Kr>Ԥfn}R0Z[Ba")QSd6c0VtgMʵt|e~9`P Oxqtk. P?٩OM׿WoF5܍cAyl["6 `ߨaԒP\-L(1:'ZS0oBHbQ<4~e0;jj0ڶ6Hwg'=P3W]䬄Fܫx\r"^ZWb!ː"mF^!me\:}Ke*u(⻼Gq~qOOH!Ah[5'kFwCZkHvjwtPV!:0MHFHc&{D(Q903ǧKnZj͌/e;[OwK+cpq9y UL:>LX zo]>3^ 뉂5 k4cJ-mU,U}LBYvc lY^TiUo(z 3DVZehm/j:HcK>蕫f#ӏ)HK#;ˑ{" ñ2p YuP=V‡9'TJ|-Z{#nST0T['/oO@$/SҞX.rJZ(#""`vJmlL<4G8iЀBX'F_'G3 74!-Їr*70R?/V'286ETDLS<["f&;͌ M0ږ12T RjZckPl]*FaC5&kӧpMFiB#-"2c֊l J,<ŤGRRڝfe:<~"=2$ކjL }_\J>Eٙҩ3ebd Eh}dq>ȜFg7g;Rʺnehx>`(v2fFB|d !7mˬ#tVL `eW\^N+E4Ste[ZH?ΤJHA':?#כJ0YߐM1IR*:jz=/Bؠz`s[r*v"ꣻRHDI۷ y Ί/϶ftaE@XIXd/繌# Ry]+4y tزR${khݎl_;_5 M?Bf7pi~Og-W'F˟O1ù[(\46t*4:;5#s&=Y_0dU4JDur,ā~S)-i&d;dz?<0 -Fw lK)ߝ]; ĖC&OclMi Y殓TV)!GIyW#.BY[E,?ačSvLw Lr8wHJIc8I;e| AD ip٨Xi=t8ƪ)Ir43t]CoY$ǯ%ru8}  kVPJw? 1Ku3DSx៎؎LsQ(M*j/$ V3np̮r<)RlJ|b|֭~GsRu`YxB\rA~͠'gH]TiK?"?X1"eVoS*|ϾfΰlSu?YÜ0) |<=<Fg)4KtH+K9mKvL)^w #GA3%OWtr=lC^[&ۀ@~gs$zֲ~B1wqloF˰1֠obg}#na5pګ)E;ϗrIIL~[5d7od@X^3VA+yWӢAi@sQWm9MfsٌXϧ^Xc (եudtk멼ǁEyfGB”^qˮ+-ſ4M̌Ax?i=B+MBF"DK0cgT&8شQN 5p|fbd`0L$U`Ӿ]·3ruIܽI`9ls u@-jۅO?@EZ4JZ:!R&pOۂQ[V>Hp1-מѩԴT+cε}e U^@I때Noӝv~c^Ǩqq”V2Vq ]m/đ>4/_4XƂg*v3 XYOYr{U }1t'ɣxtz7j{0`*m|э2Ζ?_WhVE;^PP+C0ȅx< ԀnZF,xN&^1Ոz=8yZy}+a'Grxp@OA٥P\uU_=:TONlҵ)&i̥$pMΆ.W ܜ+lfjƕ )aqk..7!S$guwgi8'Ҹ FXlN-}YVQ*S,Kxٝn:ˁLN&i0G06%ۀˠH &O3#/8}# x8m]kH>2 Q -H4h,$_^zP+aqpz)!+OGZg6>[^f ިhiܭ󳴀iẠl^¼`ɤ@73iQ"3eW,zmׂ^M&O4ze>KGEm*l\&ͪR ,uap3҉snJ ^(׳.)pP}/i{⫍91nRfqr2Ͼ80x8P^n/aŬZp0OLoǀ]mŲ#p`HhoQv:͇٘3k݄m~d%ӮxW{lm^F 9j2"[e'f0QM1nQ:Ȃj_rʳH+b(䉲~CL lν DOObGS!"GNbeIaCٳq)g~?vF@t7=´y4W$gd(sȞ9a~+[58_:dxwNpNwG3Z[ԋG#suaBxamYGWM5#l] h22}FZifF~60Za]PDX‡dxh+#6A\XQK )NMhX?лb 5?JuhTEiW<-1Br0qZ]#HߵW '$80y3_>xY_\O -7O婿|Xp5ö'^R8eI4Pc á@?h@HsPSR+S0hleB{W7`$;nJimCA9d2j TM2D{sb3DAzp,:C6fȇ^8kϩbXִוֹu/sl5M ^82[7uLSvdc~䧍J{Ö\=v@Xd1j&k, ӚA+qD0փPܗ]X6[yvRܮٴzC<>t*X"padpC#i'ĕzx!G5.3J@uv`p lcsw VJ6?E1$&xĸaG'=lȹ)!_ x{̅G oFCgD0ϱ|YOu5f#v䅱Lp.9 #}b 3gT98 ^0!Q|kLA,5*:uB:rpPMڹXO,zU<u}:{NG !d] ZaՂ$X6#luMgɟ|g׌Eu, n3`g\Ѱ;HP62ÞA n\rLLVVtJ e.B.ϔoK" ܼ̋ $xgmhK!"0L}؁Ij.∶ϳY[XZheM aLL'&~-I,bƆX#LCJ _Xor dN$ 3oh28ukаl8';!}x4DϿ8[B?I %Q X l S{x51{=k 'S;?*9ܢYUYz@ЪS2`qQ5 ' +ҋp򩥞\vwV fUS@zve%صj/ R^Eu#bzP9 510[6Q ᄬqj(oYF> /4@B(6`2Is斾@xX=nK_۸qL5(/4t^(evz!&ݱ ԭ+mTLٻڍqhpSeQnC:G=6hJ9G-Me9L::L,Q=È!QiŮǹVS25{>w%"#jbyxWo $]=\aCP2SXb=1]Βk.vqUN3IQK…u;n( ֫E]*ueGBp<R;z1ח:i0 V_-j>= (p`bψ7i 3 S8a SOw'}>QA#΄ox p SqBfR#h`iY:Y0bWֵD&W1u褂dʉ* z&?DٳկP*gNF3Jsi,lˍ?ȷgߜ"GVӒY>&6As yv#$)i"hȊ+,c<*.I\ );A"t`W)b,nlA[dz&š\UkBcvl7 ,*G?;Ƞ7{nϗ!0؂0X3 #_Q*9 "⮂{!R^2h`Hl'YPyA7mZ ?ȳxtN'i!7|\h:alɼn8.sX) 4N Sd-$%J(&9nRWSSgid{P9vDk*yZy W.2anZgA>Kj=w$hs }Mv;A`;&p 7/3o{nyMd [^J"HEӡС7pɽ}tٴlVVИEOXytX[ OBãӪ d`&?wzejoѿ2c4ѬMJ:B|+NYb@L`ccd1A6ɜED*1?C8͂&Jxζdz1H^"+Z {obn"I 8"q $cBjYU7$tDkswj6wrˍOk|9p|Rr7$mn?~dBpn`W..}) IeB6AAӭir}/2= tb٭GʲMZoѷͣޱDs |ʆ"+Ȓ^lUʧ{.cv椈2WǿL,l!1-A5onJMLs |iij<'9H޿ewWg/\Ѝ%ַKi]eƷ"uUO ULX^iir=L9R3 o|R ~grZH{d ëh?$$ԟo *">.7!0*(þ|PAˊí @jÝY'[~yi oHt.+&3ޏ]*@؞ډ :795rԔ)'R +΅XHE|̑FzMU¤Lq+rbsڻADW w^c:{<%l^!Gq/NInxTi#q]{i3=T euG#TL֓{d+>I.j@& 3}(L6Z `'aM!IL 0AבˡmߨvP}eL)~FpnV ^ h/رH7_bB=+FW;wg] j"[NPQR] hk -qZ/u=](E,*&̫@ZF4z콺C !ɲS d7']gA:lm3KaIݼyv$G ņz5ᐗ/40o|r!mOлZP³h&I1L0yFEנ*B:IsI rK(v/Z?~(gtsN:TUx0əeG1q*TJ~^ֽ;:WNF푱QI1fOK%^B ɌqUPbP7&ŷ\|5ź vܓWl_NhZ*E!0nن&:91uqSu?-V޲"!h׈gOxչF>^.+H\{ȖH$*?A *s2ѕA]$CH6?Nc*lV[ 5KKȍ1~0&TyВ4.1HTXk}'@?&[;JVW@oWVjcQZw b( Escmz5mWysW(f@\HՍ|cXqKyuRN0$w.[ </:lxՏ0F!yQ$|[o9ZΑ_J^(a&U^Xw5Nࣼ2@h=a!ՃtJ۵ZϳDrζw[B1NY պ ǖ&2~PkvDyp@RIlފ;jp1]CǾ|J]9Jo^U0Qrh}n돏/zM+j,'?c{QiI;^Eyb_a/M{[IR]c_B~p0&#LIU8st>)(;U 鷻O_v$vp A\wD} 3㶴}:i-ߍBToH*P`+ym.4<*@ mb)B(ѕF踛..mgV)Jf"RV``ozߛ9&"| C #B"P`k q;9m%pI55ëGYb} WR',!=Ww!@a-%-n%~H+ZOT8Iӕ2VgF>*\ =ΫJҤm6:nrcֽ%\p9E<`{E8߭I[xGg?-f1mԽO ~_E'hIvH5$~$< X`¡M,1Ѷ Û6C:}oc47~k \@VD9ֺcjAKG?m†֯6Cʡ l8`#3z Kk"39kiziI+װ҃W #o 5;H",޼i|,Xkz \~'NfY`Ղ`iދ{Hh8zfX-=)N:?kxLCkس'gg֮镴c3~(h2ܭx,'qz~"Дx<)AɴWG̉W8$+h*N&#QM|[x{]3>+ &o%.duur/gfa*YYhAZ *͢7Ak^lL#HZ2M0aʡJ}p)|rV *n%!/efb+Ā*䓀"!?tKpqOLD%׼ܵX4K#=i%Os8&#qe?wڌjXwftQ|Ÿ$NB-~pV?#fla5Nms?Nly0?/ :}hOOpg8?Km%?WzU#^xh5 Bs๮CxSG_xh,|s(&g$I1}]?਀ǯn<}/-" ii dAI,tZ/LjNui ƫ+\ƠHԦc]ڇAFnv ܅(dP" Z{tF=ph܀iӑ5c{gG$#),jlOU>??-"Aۂ2-%XiP۳_bwL@;OfCpUJ,Er ggLkS eyWTQ#[sCmJjpQsCKl.MwƏ5b#Uܖw:ko HSn.} nla ŌK`tތd+ wƲ/{iHs7 P"Ş_j78 nPi%i-fckʟ4kp/W~4@MT4+ .^nF$%XE`Xu// s7"f$˺lJa2?Ji&ubzlh;B?r*BlݝQt ?c[QAрbkU~\0b5\`η^z?J;UNJzna5+VU(*ޣVh7O2oe9>.DKd;FD@mjo;ít3:i1w~3dXF=GJ.]#݇,_w#ߓ!=rngv ›ǸoEГı}ۼƼf"(X \]*$; <3TqSm!"Yb^L|vu"~\]q+pmՑ{G#W)쁾S!W\5gJ)>[LIcPFYI(-nRF>t۽_lX(k| :< rtUgxe?=>k?km]+K++oz3I@ڍ<5l+8ddlZKҮz,/#q%Ub @)b?O*xQ>5$1ojrddލYsx7O!FzK8`c/qF&N8L' FK"Э5AĪ_IL>,㧦k0ws1$."kVJ.8Xp(έk4FqT dtЌ[R{!@{bZS-7ވWܿbmJyHi`"50:0r} ~5^W 2mZ{ܡh jW@o1[K7sB;_r`bFn_,XG.0T@" *@ʃeU<R-@^-/'Rl:>D_] B6fRBʇ=mH3fڈحc,=%`As'olft֢^dIwKEC eDe\^j]WUKڬ4MNxc,E"x[O+գ C#h\iw\%F(3 4vI6> hQߪ<EVa$}[ŬĶW(PӡSu]$!RԦbfr蓘ƬTnvsczBO 51*mDC_SE.incO*Q?o(%1'7j[.0 A ?]H]CGDA7/Ϸv#^|+:ɸ SDB\q&Mmx1~N=W~(hIIC4Ի mh-6$ISR,+ AiQ" d*p^vI (IYA;p^V[$=w\YU``Jcq oXZ.ɽ Cve FnE,Ob~.:K^`:ni "5&Sv>!iͳ [}|O'i^I%\w]bct5E| g`|{Yh`}@YFQz3>P+׺8KƍBnF#cs $ϴ $j+C-ħQB]uAy +Vڝu 9 t SX`9RѢKt@$_ RPuYq}جxҢ.'4I@2 MXOCo k^UY__Y#έ - QE z_3A!`pjHE5b* ]psB@\[!na@d-JwS͘$Iףg./6"T !A)~eJJSNX;LRpZ%+) Zxy/Y˄%hȅQB#d]}&ί1ӜbnlZ]Rj`T/oaEhRրmjj\AB@R%x-? /ᩩdzɮ;۾XG#k!?FH@ 8>WMIel8fddxSBff@|CwԜtK-BVg+owx5Gdη,#ĤZD-0jL$>٦|駚2X-~>h4UI#S geĕ3u;}QL`)L ?om*?T.@_3 D[%ۂÑB>|9j3/+^l< _v$*1ss: q-I?4qz .MԖ^;U!a@+ePZ:TDGҙ4i)ȳ.E  LH$&g7ǖbE e woY?*.+3zUh[לi=_8bQ9\vob%8ܐ%mߨPV_sa޼2`XR v'f_%wمA '%F0S'5~(rC#[IӅ^Gx?XޢƢZ_dUAOBf>"R+ |h'PZs8<黺}mBs%j&3vˣh҉Rc@)T-pCqNCYKcDH)!rm8,"R |'VhJ2N:+.!,eR\Yhȇ1VYB43L0ln MzivAjvJH,IzUa@2^vН[*^L3wID&zyFrZMf@;.W*푸}` kdf-v5TB ]QRV P`P'&8Yv|^|r3ȻHfh!QK_>YKv dv Gr51CF>7 [$tG{U `?_ȩpZz Ay6~"E(ZH6BնZ3dcyFʃC$UgN :Wסy&M}#$9;U*eVA6-kL:s.1%3N3nhɼYNO=osly>Y2(!DOU-Wشh>Aj6'  xXj|Gm>:,/Iwڧ3ޱyї81zir-@Y|dy9KaLY 2Rb4:mNf裀(sn;hoKDYmؖ( Wy?qMݦ MK0#I ww u[Ua= ;>㮓|Ŷ\?&A%K@,5{,(qj6ZDm#e` SG`0Z9.|whp5V0#t[CZD#Y-˩cUBSzmu-0LUm}A@v"&֝KEJbQSf2m`u |vr Cơf2YO7mUADg񟭻Dma2^C;2EAvcrJ Frt "5mMe\!3n~' L SY}ӄ{頏$>4'$|, =.HƝME-}gG:0[s*U0e'(( M*} Й+U%.^}puVãy6=.u)Gv$-/Vpև;PO-; 5Rs50<95 v }$OqZ aϦW Gr w~EB,; ֬I?\籐ڴe"rl9ZiyJ@TR#ɩn0T!.C"m=F"Cf%HjW'F):m@\ms_nAm>A%raȯvFjی.z]= BiM^J+XU AN†+FV.5 p{!"TtCU>o%KoyucWpu/nuZ8Xy6e@`%lfF JDYy/ 5Ilzݍ)rPp<"l|'P}9"3WniтVb?3R?KG)Xa#8;Np*+ChN~i!ڳ!997>%P?4,3lį|I88W }Z[9zwm<"oKn 8-eG0xGx;>CA?bKoLO@{%!E5hީ$})Lovvo6Pg )ٰ {Öq*cV78S+kD8+t5Jq}'lGiĊoEۍ]Wݷ"sO-$6{xi,Akݪ_R/M/IDƊ.4MN: ՚q*ZFpԁQK=rQl -/i75,L0}ƶ1qI)`[:Ubi@8[ $Kh{ )C0~fi [ܫ=s)H3n>z!B %ǥlIn\yQ:8p?l;p9n-XH|ƀq#pJ5H֑(~6";uzF3~xn ۮlpNUh,{O2Z.1}%Fui3{9B'up)@?,/e0p ?Ñab[ &I2)V;sA"-~.ΒoDK~{˞͘_u{>/[ o |^$O7ӣT۽13"gP}kx3.4N&֐p t4w{#ڥL=`o-)&9X|"(P U,z+ߥ˨{*./`KA5Q &Cb rxT:1>˶?ZQ=?Ѫ Ufӌg*"TK fzwY^9g1MdjOf|$k9yebvk(/g=^ 'T[\VQx ڳ=&__\J:ȸ̟̓BrWR i3%Y 4Ok]u5t"E53{- [Xݠ2H8K/ccv2_uH3[. fi;f#(qY48rq4T?՟ouFrI1|jen FdFGVz|G'\KD29)O* 7 QRSscq"*?jSv Q(0[p׫Fd 5H@`X'X\T2*nJp 4F xR-/""%mU86I\H:lLnwN(h+;@vs McWw@[($S(zƙ!qc8#;׃Q.黿K ~2ʎ9@a S4ǀ|J t/[g@spubfn__`x&vt})QR.{ DdE^o"8P@|ȘJs {#PԦe,nrJé/ܘ2NsT5?A87_ 6GĢyvdLwYҶ WϑOT\k]Qi x2X3{~|>:mVqa\([sHqAUׅF+lZV䄬]IpC ??*|1rX$68n"zΤU wj ސ,=Tʋsfn\z'lUVϫ8_(O{W-.zBe/unр#Oa"֜#i7޺!b)Q=ĩiwMc 0l1jH.5sȪ;3~AK>#n&Ė#cGgC֝~=9; #*6ǩ~TDCӁxPZ]BA"F`qS*rnP(h E-׌U鸦 *EkK|0)x@#B:с#Fd*9sQ#kX0R'-od+>MG9u $lj48~F8U{lv-/g/_0Gfy}?ҨJZ;l@[C?TpC>W))v6}\NPuO-͂߸.ID t<ĉo؊FŶm1[Rbtqhr.'lHAۿz0Uo1dᤳ, RI2Ɣՠo7Z_a &*r\:)QQҋսfTD#/_xd+Nƻst@Tb\W3ѯmrxo>kڋ)'foFas'[ \3xy є^H@ OPÉ(h*zMUs*0ߞAD!;u/0p,GB}OtE_Nf[%xLb@{Qi`,i1D8L&ݮYIVA@2l~$2@Pa`|7p23U]AH <|'$-oj|=Vd,.t'ޯ0Dm_ HIfFԨ(Zq' 4$t qA6CT@ݼ$Vf赈_L|I:!:fH@ab1oH>_ ]krs=XN۹}'i6חYX.n-0J@F6)ydwЂvTԓKHYpifȩՆX] Ҟq>$ JU WޘZ;mO,CƻQ,:d '2͒gC9p{ W9ԅ/iR&}{7N?UaNAh? t?g0@ 5_nǨ-xvʔqK ZuPTtJ @ nl+ư+L4+zL&kψf# maM!u,)^ic`ot&Gn# Oj"Ia-H>;_feל ?tة:6DP+ sAYܧ Ծ<'In<7'g^~޲ZO!oՅ3d_͝ !܅W~7pZfM[z}yVl&~q9]9=g~GȁhDZoGoF7<_YPNBVLVҊ J[@:?2&u3xI+YiǺ<[;E6Z_.-|@Yv2ϷB\a_|(("f4S?Ts]]lv˨$s]cl{uAZre7T29 ޸xN E '6,"wBJ-dH@ z:zb%NO8؟̉P?n}V8V" p?eܸɪ \j|:gXbP^Ԫ*uH*"0ZSqMo˲?a'9rngj0r]e3Sk N!%*x($I~:rY99g!Va3U6$扡X=h^r,y+Iٍ6]ږYGcaZj{ʷ`s/1ŸϪX )d]{``w.1K=|=_pQO6ndHQHzpufRCnƝ>Z/T a Q6.$M9tCR-R$UqY´AeajώVQ"fȣ_= D28qˬ4beZ6e,YCԤuoB[Fe$g0'H~[pC&ڋEKs`/Ӗ#dĂLJS#Exߊu-c P0qCBXd,h}*nY"0.s7c SZڧg5ɶ.އW4Ə(ϼп< (⍱د5zaD^mFy͔R\J7pGϛ㍋K$ޤ,x3}2Ę0YhYCVlYm~pV@\+Ʒ!y ;-‹C)?@tRDE7Q:mB~\.InrKxo0k.W_v7Ť5mUjȠ-?7W U#ЅC*愪Pb3rⷘu>p.d l.ZGweI皅Xr I/*(7OhPn7a ,H#ќ00QR?'[JPƾ$Fu"w1 ˎu#'3RN:AyRTy߬Fk'<2jvn/qĉ4*I~)g9uѕu o+58Jfe0;20fdhŨ :Ӟϒ?qP䙧u|ߟ+>,{/] fr QzJ~C½5PL5xTpi¯(}1|(VÁ°O{WG,7b.N?5 NyEm xHGR դYW֯v&VodTtl+8D9lU͓O=cط>&otse1l0[`:.T[K@ Vu~ Jmo߀G#эHh? Sƈ<Ґŷ}{6q$pcƵ.;GhfƱsMgk.UVg%TbiљV( >×T%3ml dnHZr \q;|F3j @$F[ FJ6q|`ØJ.1#SF@,)w__؀P"3cwu|( P-]7p2wW3wpET3h8'_ZЇgrbVT՘q@aEu?U]B$x &0M}89غs%E`KV0Dh.>LE6';;Gīqt1@JYr^c^zu4 OC4n4_IJDux$Py'esxun#/\Ǝ2Ƴ5Hڽ:$L!n BΥL6 {e%wf gȊPNfM=Væ2 Y];;e_G5`1gD.2HnM~d/|?!lY6:2`#?FADV±kn=6\ Pboa|CB5tU#DRw%e͵Kv݇-քZDjK` 씷O %=ZʷrHDܕ˯1=ɳ]Ҿ$ޓ|.Y7t(n,68ҭV\298( '+A8^&|N2񘊶&El¦@,#L~n|Ѣ_ q5&K͢ PQ}E2:ba5`tG/K-.MՆlczVNc3[P` 0]#xʨVZ $,KnS\8#~IPqgh hF(m:Geù@QUobGJ .mqPpuۮXG \Mi Ų%}qIňbewC=F&̆apq td6/H?=cy9U'-YdeaOmPF3=g.Qib`E1'> ~dTު1Al!O 22H QML`{1'SSl\O'+AFM=[(=J<ةӓ6C }Om 1VHIe  2SG"_[~ =8~m܅W'= RqZJQV':nt~M3$3Vu1 i^5@7=/hTfgvKZ,a;Y@>Z݂!9%`BҦCB]HcU˦,GV[B]J2:}*ߣd#hw:*XIC*[GoBSvoa1m3݈3$.v6Z::i);"K${wmrw׌ Ul$7Y^w8+Ĥ p/Ź {z},Sf8\0r!Ka A)%Ӯ7fᢪhOL~#-7S޴J~̞_)\wHj.c&VGPAcpĉp@(Ƈb :C5_"jlVIVGt)E qG[BT,WBBr1L f6mN D'!pNEGp`ID gcoGNd2=H3'6=;H+WiDz 6{ٙ q|Ty6H2/;S*%q><Ǖ$1=,.fW[Fvi#\D=- Pw,޷e~}{?i=Sc?]>@ğ$_}f-V?z3heDz+B-/u}pLָW?Mf 9ȅnXD@ Do3|ֿcq&tPNeoUxSO]㮱|e㤊<8xtK+g,4[G"xH{Q8֓W>m $y6j31䮭!ہb+BJt䛤my 8CNh[0e4B108JW [Tq ! #r +Xq]:9~)7 JFmYwk ,ꮁ~]In4-AjEI65xk2, Q[2WJRFhUz֐\v`]/ʤO)ۘBoL 체y/Ṉr2aOk׿E2YChka<7~F #ƕ:^"~gOOg/ P("Gݍ` @u`RO̖䎄`2jL%[e$s'!;== T%vokWb}k sO<10[ŭGw~+"g.G$rt]ˤɧ.`Ȋ`񣤉}3-*;P͏9!|룈o'˛G*GVO/\F܄v 5KžUɒ8xB)+*|7Ǔ;~nØ8"l5FAr nʝ V8=~gI&̊A65gl7^W*me яFUXmaL1jI.(qS.]GMI$*k15j_b?Q[$LZYM]./dT0{~qpX#M3 ;>,s1 K+~TxܦCݡ++ Q?7Ԅh3#QMJ m=of3KQ*Nک;L CQsZ=&&$ISH/.ޜ9HwTE\΂{nH8!rۋ-]QVo.[%\p!{sDRI;ՅWqGwt#SC=^6Fyo]UrCl;i/&I G&!jm]fz :>ٖS2.Al}T~X2!,X`4%K5 wﵿJT*j!L|fF_S׏īܫAJZHr#]dL$4PbvJYA Pdl>K,BO Y925$Nlf2w# ⮨9]9'<Α #" CWh@5%M(dNBqOJR'26`Bmֳ7/ΟYQ]kvoŢC'K<=߭L܆lNL؄3Æ 64'.Eۗ,hMLh%|ܷ; CD%ҧGKŎʘ-'76 r*| Q}$8 +AءqEuxAtpGCzBl6d!r!K h[ L2^.u F94N}uE\}5 oȐE@ȑRЄRK(LxFP]TvH%(27HH|&\+ :K׏/ka1  GˋO#:rIvFBũt:K s-CQbPM6FȏB-M@FJ.9>Qwhh^+[FSD ߟLTOLÌ۲ĸ.F-~/Gtdʓ U9>w7?Sہs5̾Pش MzgNL&~cre_wu笖}Uo+68xقp}9`}5IUZ(mʛT$۽JjSX)>tCm1[[ =;״LE 7(a3 @_6%EjYl,Xu /\4 tdύ\,.m0!&|FR«=)b5Lp4,Et - +#ƾm)RØD-̼A7_J;1qf^T19Rs ,\WlDVB] A|CU`9ޥR ? xHs/l/_]U:1li9E7_^gfcsM:Ek| iߑ'eH,tp"y1Po{ɸ1{!2AZd?r~ $v99;h:8&~^}o C{W -81}zNi[׭+%k~H[5Cs>&"g7C ⲉ{;j$g%㽙A0z( k!4߼:2ABZcRb)e$-ߎ—W12a5k^T],ppe7΀xɋ|w@jj(b^cW-Ғ}u<6 eF2ƤIQq\FyQo*VrIU⌧ua4>i%÷Ԥoɨn၇ё eO;)LyDaojzƊ}(LG1|'m"z ޹Qɋ;6[*fK~ߞ_6.=4ٻSaRñS>j9tazGey|9q{U'JJ.x'^M%dɷOA@Fy!E@U1k%٣xbzpv=SeνR~Uj qr`jZ@氊|Hd-.)K}g ךhfɔ `>]'9mrI"i׺*/, oAS .bGMa,#o A )t5-R'C $=YOaeqD)Ln-6cTQ% ( Ƃ? .񹉾t\Gq/cy&L.ym^ty!S|mmI(1/O|\MdMqL*K< ]cIGYI w+ y#Tzl9Vǵ\zSϚfЮ-İyOH>P92 9l`gUHntR>G<؅4bZvZJY̳2Z G;*?ӎe->1 ]ٚ_i/-#ᙩϺ[ y%ӖUi Jbgu  Zb}quWc vxؚ#=I): >K8 ᒇ`FbI@J@nv+!`:++P+7?<(7{jxك yP$ ڷeκZCB2cowމӚO8BaCmLJuUH83t"dduߕ2 ~i*}z]= CMѩ+Dgvcq)M1TƕJ^}cscAr K3wau.y7+^Gz;번TR-K ->bzah(z$<;!C [{Bˣ̾8P N0-nta csbUm?Rvr$uQd]QV*mMxƃC01,‐TD"$o-) k'IW&W[xyOd/:35V<ެ8W*1ј 94wF%O@6yTi0޷)Aɘt(%@g9'"D?vIXF<=^[ YM|IGRd DB9?sr><]^g(C oI莖'65;xf C{Kre^W9%9E0OY;&!fjH2/=3u/BT HaM2${.kT<5^{x= pL@8qs3ȩ=Z q-U"\q;T@f2-6wah25ԽLh,W6o /SޫK@TJ i#rA5{Tiv˳߬G=o JTQ=L,Ϻ50|H$oR:P{ԩRckh>Օ!m+ċ`>Wo65 i$>ד" qnp"lNOq0ӳ9Vܢgء{W$$ P~Eb"pX/9G).-D,&{˖Q_Yh-c@81-ݔ)[TECپﮬ OZ`-M۔mɌS -3MO'lqCyLO} LhҸ~׻bbf[6+K,eӡՅYj9B!4PMأ.<"F^ QaW/~IGJMd_Clϰ10I5i~X5!–seyW1zUZS N"-Q(rbT s&$ ߹ !(ocKi\RÚqXmO>y^{*#\`T^&JM!ۇ9ƀ/S^MWa' J ;Q9 139r*&S|_ V'&'bsY&:/is@L;:lB Aj4х[{^e>b^qh,S[t*' =ɽٺk.>z lT A&ݚ7hBccX+ [cU[yF?fm߿+ IShiy䟈UwЖӨ8ڝ<mfkowb(w?N jCy*c02ʼn1UuE Bo;L/"yvkdEI׻d+L/Cj,5)i*0CMm"u{^jЗ< ḧO&ή %g /pONy!$z:{/_Cb@n50+#nBBьp*)<3)%lfqc㈠n)1/Hra[ ^&GN"AȸgDBS \H3ͩ0}*~]ˊrY%wZm(G[ C)f?Ͼy18JE@cBJ΃ 8,DxmZf&e&V?B}OI([R+Vs7sZ<1f +غXsiHRilĖj/_:rܪy'w4JܑkHOq0X3Ou]Ipx{2XjG\z%luI+Wbm٢g1iB~;3dMDd4ISRN6Qt6UNl(뉺+ӡnLg1V/95Wζmf]Oiq0'/ØODmAMa52e6=pFb>>(_,4+Z. ;,&Sz-6MX觀{pn=~;ґ|VHŻE%nJA;g}G021a<dFB SGf؅I׈>XUW0v⢩/<oIːD'pDr:У*d $cvi 5×aɱ]Lѹ,:`I&y:k[LC:Lͱ_̩o)MOijmi =˸;րqp>XO}PdMb-'kHa6--f="n(N[:~kË>;!Ћdg%h((ݿw`K w7g+yIYEW Ƿ`pUmIfqJgx#i&z wy>p c-8=nݶUuhI;NXȾyJ օqQb5N?$-UT(ELpp">S|OFF WT6%Erf|f{}V%HiI''lNA,EJdOG%@VMNyiίŨ{ xiS'fxyFyL0/} uCx.JO)YJCo{<  Y0 ڋXC칝n[G\Iy}4$K^>5yz;EA~05u7 ȫ2<k;7Ov/ GpEY=So'CKэ.xW)Z`1Imv (\MG 5ش tiSq;;1`{ٳ !9*^\Ԅݕmq6g\d{b`.C&Si 3)lEH|MSg-r}VʦX~2]y9y|fm܃xwjdnB Bd_QC; 3WkU :aC$M߭Gmu`}$WS‚L/VJXl3t3K["=({s2= |J[f1?%0Licݨ#׈Ire0xTߍp)t]2AU;M[[z꺃љ⹏⹬C0/QJFs9l:4WThuF Ճ,&D;`{fy$Q!cMnd'σ@u/AFT;Cj*+{.5=~pm% W^.vmR;+ǝ=]$͐L,6vo<HW. U8cӞQ 4yŸIgx]7p"\ѓ Z{QO}G;IE#6۽6owb2 V 9fQpϝ cdA8YTˈBx}^A/cxb 2h@6BXKL&gT<џO,LKa"p ws=O?9Q?]W)QC='WZY>V.KP q@*{bCp#w!jwoUl{v+'faSЃUX#Ȣ$v+Ho𹁱%ۢt!-fV~(ܙfBW,xaXq_ԎvdSȻJ |xiMi2b1H6dkHz9i[A EuCGp%. ~e;1C@fY>1Ga)]p|{.% 53J_t! q:G4$I1ƙ/)嵏1q[ aT#=3gėTZ3z@x#jzlͷ1L--H-LeHjkrb+gXfR7t}ᴖh7 50|)+۹.B0`!z@w$-0PH;:-c~XpQދ+٪e](, ӡ\l zOz{עK`nٔ&L5+)4C V? }%~&Zђ(UyX(r`Xvb Z@Tl$V<]I:,Kl/=54I-/jP7fӌGYZmO;4L Rƒf.UA岑-jI=_~&Vj-t9Qk_xAqۛicrws&Lyjk6dUbu؛yqX*.?N!i3*hEyiŏ&݉6C7y?MBp 53kX >G R](wE(ՙ"DOןsY{a$:N'5c FsNqoqizv :닌ΑTkMU}]oCx;+J)<.慎/Ė$hSPs6Qr,"#'`h'}l*&FZU6VzmiXJ/o9VyJ\LF)<XP7^]׵'uOcf#^X"Gݨ]!_cGM3Dw!l D֢t)*oJ MSH}~*BOF7ityjgnP-a~FBD)[.æߍ+S9B;8Z&xػה*_rw\}6ݍmK 9z,B5{(bSࡢ}j 6P#wb\F1)E~ #Ul) 2؟CiR ЉqbI/5 pKV;E\wz1JP=i3'Tz4VcQBwڼuQv{d'6/uUZ:#Bz]p%ۖCɯ{BhsKx﷩d2j hm !i̎*/{xf=skT[~J5ùm.IxKQAUt>SJ8KrJ >N|qQ4pQ= ]tTJMPӷn1,x^-s `4 kgm}LD+4lMp!0)Jc0$ $'uc5IE[cZ*!c-YޭNEkD̨d~lX"/QRY"h) Gs׿ߏݬȶS:>L+.WN4׆(TWȬ0rq|@ʀ G7v!θO ?MlVMm, sQ*Q0LJ#+IOW0G1]CN'Ú׹p!K.d^++~=F0Ls8T]h$Kށ L=9ItfZ*(h>* ӈbLDFU\7팞;,08?dmVq!Mt9 ӃjM;,Cd ХogJ~)y-$YsuQQO;v)avTU پ*W袔1|LGN4芎cf^;߰菡 )RF9{<%}.UUem`@?\O]Kx Y(&֛΋n} hWƒe6`0:Q:>orAm!L'j@| 4,Eh!*R/^8iXƟerWC<~t+D*c9&΃ߏ:y,0IDT+=`slӲu'mE'(br{^,$_mwed8h~^`+fŅ TuEg4&Pٟ;G&h1#-B7DMn8V[وn!s]OG+ n% ui^~m!i[s0$U1G{EX wJ2vd >,7{:۸iv"iKHY]3d:Ф֗Rτ9 #m ǧS%!ϲ+:!9VRA ;>-XU St'T ,E\Pftf, \OӪ @ſQ^n5_gca(RR F0c8Ø>кO槪@+{M#kJO|:rqr1E-{s!sܢ/rԓ;ohN==+{ckf`q*+sޖ:HtDwiٶ;܈Ӑq(GEj/Dr@ωڵiȺG=w 2‚ |À\CшvxwVt /xnvFs '׭L)PieїS؂Ȼ0:$ܐ@[Z׿QhOy`ʏ(~ 6*͘/+ƈaK;ќY=%!b blO;Tj0aZĜ/Ozs3ɰmj'WB=LJ V6TCms|rДv$ 8{0"BSI̾#ݍ|UnFu?1YSC(MՆՔU-ם82\!n,\c6 O ""xR6!v4gm*󩭜"/Z~IKPc'%2nȧ&"'}cě fVҧ3œJ/y Tm9=lqzǽ`O"Hbǫ=}%V2i76oă^ sPɣ46NHu콅E1="5c9'ri=_װ&Rg#աmovr'9aac;8$9Hxf.ҠX&4"5K;Qh^>? TrSIt坌FSk> fݔ,V( m%H-f]Qh}bEUD>T|V:?A6cjo|^HS jcAqiMY]vϸ$H9MD6ө #IJS>UWNWM<:@\O{'Φ5y|+j}qq9⇚mb-U"/'C](H ڃUHwz*lP3gUb;[|_~%|"Al'gMYflG6*̋X'r'l,l1VWqSƱT>?ׇ#AܜA3OՇFHdUCY@nui#(Q&^|RLX 1Lk8.0ۀt{ص}ý|AnsSy]>Rԥ|c~E>,dŖŕt͘,o1Gs8T/{7=pp};:]Mx_[cWi7ߞv벾ADbT:D!P\ lGĊ%Q5=L٨OT0K8{oLQWX1X (o8Ija-WkyQq^F=?,}BS9p lm24Os9<[(e,#ylr3nnm "yd$a%%wlzw)[`k%FrN('U3Fog~4y6J#9=50Ñڅrkm-<ηIި{gx.[%w5 uvlJ9d8M iI?%ul+솥Fw` ,nB? %Н\j[y^Zx$RXsqk[v$lzci<3l@[Ee7k(/+#G;gʶ Ui='m sCG&~D4s%+e*҄I:s,TI$ * ;"kP<^ޙPQ=wJF#M//Q]6yn:N#-7mYBIT"&zカ(wUL?n^2xAڼcw7o Q7rع˻c{\etP~ܥh!fTgDY4e՟r6~':x>;}\a\˄jo\^@ʨ&àC5XShaceÓ78[PЅ|29LʮK*/F윃E9;Df,9ʨ/L 칉uGک`=q҅[~(ywxHGjLDc|D8ዒE@kBޙF@{Omj#Q:* /R_ h$;R#sh[^6@GCl'fT])U]AsS eup_@UjSĭ"=5:}\W[gE1u)qoX0.ج$TU*\ʹ*,6o^s'vw=B>QV[:y,Da4*g(K% gSX>P6 %47Ef8x·Z/::Έ|ico+%E-׼uGn…x%lƟgY_;P|Vʛ(0?-v\fH >k"yk B(BElT46dg,&,}妘6T"xԮ*2-;.ךQGӉԖܔƒ)+O2 e8Wl|A6k \(;.؈QcaBs;;ߋCs;WE2K q'|x` :v"!j'"#BO%/%GJ|y7  ]'t$zZpP˶[$iR-BG(|hi:)[ N&csv LGÞn7N x¤w{P H% kl O^PJG*Lf x%{uZ]s$HIeܥG g U bSB#-aˆOGeO,n7.6YL%Nڻ8'wO`nZծwp7aYgn1X˜ߌSPtva--\jC$߇_ dŷC΢TN.l:d{ޏWԍnQ=,7T)+iNT4YW3~OVH'An*ǚ1:Y<0~I<  ͙v=)ჶ&C>qb}nX\X^уddc p[%' ,6+5VN~!᯹Lubց<4E@PAn,~0 [2پ`*0(3ɰMmjDJ B{~M;-O1Yzkc0]6I hQzetD/HlSQ5bZ8WK>`5wҺ'k׮`5}7 Y[LOPa4|vG { ;@x}Y9_k)Y: ۑodԒ`4\giz * O%aɨtN3'w̉!Hr]Щr$mqJu8奖3_PƪwL{jѕJUSI@V;c3>iVW{Z~SE`M{)j _DFfgl+TxLSek^ǵ#Okp% ]P'm{e;cld,xׂ4n Z^ zJ[1 zE[iѤ48QT#0Z1luΆp* c+m O"xcu?H'i&xVȩEȈ|Sy4 wG6M؇ERy6ɝA5 SD]~s*h벯<^ke h_ycHfp߱>KyVL'.Dv[$.?DъQ8I(p"w.ZiT\q|&vv-DQk@րQfMXHĤ1FKJQe#Go+1ee Muf"-KC剰+{n $Lri1e22!:o2T-[bؚVړk_]^3Fíu۶&#hpqSmW5К ;tR=Zl)SfŘ6IEʐlޚ y63qF'WÊW#~P,F7(+x0_/3&@ı[~ykv$Pn@ f A^b9dE(1s?[06ݛɢMWKi'9:4ƸD#~VtX@ڲu]93QZ'Ka;GTNE{DKFַed+20Djۭ)% CX <+}KgGg$oxl {G6 5Ο2moG*@_1&Ԝ2JQpn|dPF@J.D'ȹ,=ۀcN0*_}VDF tZlR9YЙ\\!Ak{^>w5^0!o|ErÍ$֤ęcIgԠ3:c*WJytW5)w xuP%HFPI C!/cyi2/D 33Y _mh=#Bg ^W=`5 6?V/hID߫ȸ[=e}eMV{uLdbV,~A-5!=N@K# PN+8TfȼoV${qΝmk‰OGJ`h7v$svk8!X?GW$d/do3^LBzh_/y U4k[Z)W,U!zI!jI~֘1F#R(bX |/d? –YQq},,FCtp֜0KЊ5EOTV1)A W?G$`Ib9#`L=x9}lDkzS I=ME|N)"(ڜ>Y͊Y0 ԃaVhI_߻*5ZCDH0RVj6t :F-¸ԝ P ꭟEdXߥSXANKUiZ[ָ//' Y 5#e#C&fwͷh ˊ |:Iq#K b7mVVN!`uD'CǑA\hXjN!nz.I@㵨9|b=YAWRe@`K99QrO8->ГjK@s P2p7k]v|b^ 8 ;T}~m¡ӻXj*M\a?iD$bRTjc0!dcNi6Oe(Nkc}?oi§o–t9uJ *<1Ӎ* t⾟]vv? Fϡ*q;7"6ln%fLէFN =j$.el}FMWTjOuRd4 p'xHE-.onJ_ZR&vBG?WJuƫ!f9*>ٟ" ktSrvMpn gXy3~zJA.VudqRm &'# b$fx9qWS t\=>{$uIEn%mЧ2vJ'&q}FY55ߘiEl޴{<)Z!~i癁YKBdYwZnnD'ƃLS(^റ{i3g$pٷwA#Y$ԑ 8ߞCV;!1;Irshwsɱp]sX%u!\5h !~Q`Lmkfܩb W8jTVEnuԊ'R=8 DF\^ pZE:F@N&OB|r屜o#vA(!oa˂/֮w͝Ǫ"X)ZW葉]>WNNnOK7&%HC ]/l|I69^؛yng y|x } 'ٺ#F(9짺na+UG\IcYY,IGcSOlZpnSK>;gi% U,%*Iϑn$5CPupD-"~I9F,+kRd(6do-9ٍsRaFқnf٩ (s=@[yVJAuMkOMw0FFYt2#B\dIeҞ\ײV4J4*9z<〉`<"&PB`o F42pkeZ?uqND0׾ϠdḮ%K1,M/po*9|XyCZ-daE㎏hJ_CYz%$7TY-ۓƺaq4+a*[_9V~7= Junk_ r-א0W ,m"G0i}`ʞj~&!%bwX/F?c>⎏G*l%KZ"vrqF: YS!:qaHcy\ X&@Jڙ;[-8KQL4b:NTRbz$ B^O=U[ezw1'hxQ`+HGMցP׽uC1IZ r6IhbvtG#'K?k |Ύmb·3^vBpT^.b`j{M|Q0$9 P/-u6KݖBک#5cf{_hri2z߄7|"p]KwXLQS*K\eq5P7<"k 7 R͔uB^rӸDZ{Orw \9sHDPlqͶ\ADLv" `! "m3? PQ=rJu@!͢|Ͽul<~m8Npj:5: ؽ Z-܄^iZ13d<83슬'?騹s03#''s/Ri8>~z8}"%uˤW@]*K { GYnE!m=U&]be3\*\󿭝=:HJ)4T|˄46XDt"46pኒ&dS |MQȫf&xTѳ1 rȅHko»)En?D^I,,0yՎՂ7x/SXh7w" (HhcVu%1c$BfyXgLŻyD\ R ONl4%\0!9sL_Eo.гN&O0O<adP^':;Ȍ=oJI܉椻$\ 8s I֩NlcT{lZ/~=g z2s>H5vξ<8ƺnu] fU}bĞ(32QMZԺBon9XK5Vػ/}Z7 [=E]B0,j]])sC=4@)Wc/SQeI!{:|lp&@Hنxʾ29قU\YTؗ#`;̕w~- Ǚ ˴y ʼs:;]*3dL6L)Eʦ#i`f.Z%.jn&:f]9rܧF}ChT^<{P?~‘O)&T߾B{_i/ED]*$E[r)iA'1ss@>‰yGH." v3'a2i{cp[XH]Ï 1W .+rz dg>: 彤점a+Y?jh;$[E25Ã^Ӑϖڰ5b#Vǯo7Q[k%0WZ&$KpM֦Z[ bdhR&ZBg2W𳵌a |Osڨ\&#hWSR\Av,le!c^6nI^7K\ƱвVc^g!i}|7 Wa1Y.69.WZܹ7\ÙQc9Puwcq^{g rac,;O3_?wu ];s 09!;эtI"̘(ݲq ZSFEmM n (_sʀ {2n08+ϭC>l["rkS YꥑLy;(ؖΓڷ y;\Bxra~UG|q5 F5ƑVH={B|%e2+SVh$EdG1w԰gڇjǮNsYtYĦ;  #0E( TmxE'uC|=S;{[+Ĥ}⥡Yi'ZM]!KzC^PU-(ѷ9F#İ#[H&㧸cl[؝\8 0 ͋naa}#y /uTd$"nϞD?uyvM+ܸ.Pw֋`Գa܉%vX9F̤J^#c3Xf0y\"Yx${ѣv!dLV%4|h{"5WC2Rh#_ߕ%7IMha zO~%Z Qr#z6ܗT rքZ6tNprlM ֫FlqL}WH^/,.I;%ZcБc6U9.U!Y. aղo'W/S\!q˚lxg=3 Ss󐜯 Gt)4 D'K*X}F+GɽҌg.\jJ2" ;kl_C{xkhn)%a~j֞^ LW#А[:PA"N%kL='\C~|f퀏xYQ YWX,R\@bqhA*.a]#$f3*#_bJ@"refP☤͡tpP$zϸi2YPOR-_Uune ]p.@pMOHKMI7L{VrAѬ%x{|ո/QDetSh}>ӝ|ޞbWt\"wH$ #a[osy0j[Z6WJiN" L!K; [>feı`W (MIW Bqr9*Iɟ$ bYa5, ^߃ûLvO,N,&OdvwL{YW45m:^H=t OjkTKw(L+u-H=yֶT:n4ce=^HK!T,a[U8X tD]xLߵȀ5nf8r!W[b,kqTlbM-R;kao3ɋpwb#_|UACflpt53Keʾp>`Iy4q~d>>Mk,YrK.$*ڼ4aG j_ &9 J<~T`'~oM,`q|hecEi3ƒ<)Wxʻ 0EsnegP^$E;3<;ucGctPuRrA-<԰֮Z)<++a=s lj<(WI|ZsYDӞcP\bѠ\%# JEF ҎFLxbI=91:,)56jn)Aبa͏Io?ߡ/j { V@-{b7z NRvi2?@rAu:˱:Iʿ|zR =@@j D)v3cÃ;fz_wάl& QnN xuJcRZXigK$?z%|~@{ adG]>ቌEUOhЗ\u돦EN\jB~v 8=& $atH䕅yכϝIl|G!a{B_܅mr,̲-P;w/ i;A_u&EAgź э`NdR|1pTv[!}QY'_Z-ۣq욓rZ(̑C_J@*z9z}ZL\|[#uˇQa/(Ge=>o/́fW~o'Hɴo&G/G{:lv NSG媂5OX2:%7o8#H=&q)ypV3iw:΅p*knNz`HL >|C=kIQQNg[&qo ]Qh77_2*Ҩ5!M\FkT)_,Qosk|t Fqɲî@7y!P z<}Ɨzu]V^YLI7M@RT ௕x=߶$B-U͟KF I텶! ΏҩYs$Ј 2Th@K{m丄- u'4%Mo |q6ȴldm-i?t4w^)`4 9T 4_9ٶbTiMw&D8u'Yy sYXMma75vv "bprఽεvHH"lB}B{g雪x$;aK`bܴ1(O:(x j4oe$>/ә|*FSî@^(61 p%EߦqE0Ѱd#e(} s 6"⭦.OH6qsfg$Y,*kw#]|Vpl#i,'ǷBMzU%c{돮q=XFk]/O*]lשD@UU%C1¾.t5Mc9%Lm~%8=pw,D{S)0bm! qОJ$ӓ d$x zȚ?֯dzDm 邮P$?r[c"xɭS=+&wN aWBP/W*gi_0ʤTAD0Y{[ZaJ?.:$Sʎ4ʧXH^K{ Ov,d'ng* t@mZT9=Λ+ϗXl-'ZTdOИvه1}>6G1` expȒ%T,*-9ˊt3ќ =3O7vcΓc vq RsшH<8fQ] bj;Wۜ/I4o 8VKm:G& Fh _O-pi8|YE`ip}B'F7>x2qYh(*:9ho]A=+HE*Ry=l7(M$#+neICrKKY ̼IO[I.'%2݋c@b8xU*'܉0c(hE( P)q*lc/eyǣɅ:'B$j5cS|~e? "$؋4y bGl:/}!v/bS{QSAP)´7ieY=FQ$io;=ye)К71?ulz%< '%} E=} ԝl0Z󢻩E.qm-TQB^buk"hٗu+t g:S8}URhS*(CU_3u]yQ(ESкଖȯa5eanYHhǑgAGfv1LS3tȜ n)݄N#7; \b~¿&w$4]|LzG J.Ȏ#s~6eeOD^xuf [*[ݢ/LCŨܮɇ!F,SnaOtIi&Fč\H )"Т] %0g@,l1+r4j F[AY8gC]h䴢aʆs`lXo}jW(9.MFǑI9sy)тSr]k],sv2l|$ ?ʩi{THONBeOBAt:ӽ|†=*J{n^@PhO<" 4! 9nZs* }"l4=dH>͓NW4zt] ~#{pt0J1"yp25L=H?&r2MyX8/!(}seDEם.P~۝hN@A@(<J@iw9ԥ_W*ѩIu+WĘp3JTW 0;c*j#&=@t`MYs採A$Fp] d5K/l)s )u =t\th. =bEi 2lC?MQCDsvvEDwbS b ^X%E] Ll%8!,p ɜ[R?yٙ*."V 3FOtCdhÖFGch"q5|*bfs\B}c=4$9}? l/9ѧd5޴U Ԅ8EbDHڳ_;wG)$/`ַ,xdZ\rrrIFA_Jr`yW./klNnEӬp`T֊e~ت3GqY Β%,bCHcPt2䌓ܨf f2䐂2WqbNlQ1&&*2,Hґuu0p޳blA3Z +}P#oluC d1nB?nK+ÿ|jSгWV /iQNQWZܦ<%:D4ҙʊQ\S\Ԑ^ i9}|Q;ixsi f5Z4@`; !R*o ٥L<#'w j$v=f޺ip8]A—6B8>ʤ@ -J4 ɡ't=f="'|.0/;R g5B!zڳ F EH2d [4OQ7Qfl $>,naq͚Ӂpdi M@$ɍ !\D}&ZPY)@Ks?\콌c4,!Ibhh`XdJR1tLW")~ů$ 2.l?+E7o.EYɝ6o!AOZH(n 7TGkZkny7:]\]!4~cq* DЧsɞg[@AY$FB~1 R*2.ms6 gNôJ/ [:Q;$WrU.h6D5LCoOV;WoA|}j`Y< 7t돰~ɮ#l{-U?}3m:~MX.sIErLzUm3,42"r["/׹1q $,M{b9i_җg\v4|%B&>gK E,Ӭs`xu>+~#,,Ҿ{y: '_ϋY-QG#eg`킥Cxq dh(8c@ݑh騂â[N%#!5DC2sʠ(b4'AjNXdt`t X pz_/gAW~"8$.P"!_E\GbÅ LOb "0Eć*8LzҮnqG (;/ԃgܱr^{{LՕ;̹N R:K[=k!|'H5+¬ t+褦 +ub5yI1%Wcu*L`ȁp+o=qFj_оQ_o‹=fa7'4)-4 3tnO?mVܰOO";f59]<u.BM&h}o Uk mRУP*ֲ= (T GneLjr;HOCp;,&. 57š@")0nƞӳTs W?^;)T+<9B RXmͪWxIwntDܮ$[s9qn0Q$X0ZyL'zE>(jo譾ةBz8n_,lwte~J}zÇ̀ʣH2%ayT샛 >o$=|oBM f`D{/Hlt2Å_A`KFxN] b)'>7a=|IO^sAܴxsKR^r )詑mܾzQ,kI{ z-(O&;_(T7CdB˴[KYUb'^:.phu| z?CPhʊHS&E-KpilBω@je6LZbkbP7!B&ٛ7(M5-IFi<99^A,XL}H#ʄ@_m۫LB+"˜kYtitJT@lWT.|d. 3ƀ⨪6DI|#+)!vqL!Z%e'!8JlflnQ`:Հ FVs2CϜ9R(&1뭓xUc"W)e#SegYzWIm9Ǯxa_=`L&a㘑" j1c^nh Ft|q^Kv7p6khpG9SGL;D_m 4BAx+:ԤS?q^ɏTPGHtXB_\z2"=f2Æ=Z5s︋%"@X+~ '{^Q?k!9QNyo  c/+$ꃯƏ/1V TF6֎ QIa0SgRi@],>,(ǡ1^Z_/xogkxhL[Vm2̿TJL1F6*=廇l-e_V#جV:A!~-E * + ]~<lCx]>INR3^}6nZ!zH7;)΍ؑ^K8/Wgt/1.pt=}4cDH ufYY>)]Wn ߧs>lNCՕ<*ܶRzwv(/W`^ 0X1a՟( !;;bp ҬRkIH)n#n'/k͈E{aU~)Z8{RAGBVV55DH dҞZWzR$#ʩvY6 _y˷"/ǠŰbCA:iϟ_ [e?LMOBdX|*RZY-b\Ar+HV9tҐ .5MX䏚GE=^T)aYuZT@VbGK;SABdi&IVGk$tDuV;d ^lH:kw*SrӼe3gS9w6fZͭ4=\0||expGMB2q1!mjMa1⏀H!AC Fn%A|bcf~'! X, V%dK!ՙe0~*FhUw?@O!VH՟ZvTp>y^9S*V >FE0gLC'+SJIjb <ϟw THK'72л;ulW 3㜒|eW)! . l?Vo-էxN> fF'8) d֫<1Is921ﻳXw0Yh¦>.r`>( :5҇:>'}Xх!2xqĺ:KPųI ~w?<\;nMxՇ<+6202ѷ5NTg}61V}lUa̯/͉)~q: vi ѫ)d: &)_X^&,D\#2~(SItnO/E7[=?aK!53qjRnj;~e&AS@ ?Me @tQt*ʣgǦjM*`6`yR3gpf ]ytHK(uݺSJ0IxjwsLo"d84Nc}X-07.+v0Kr*Mݴ髺PB{!-B>ĿDCЏc ʐ\h]ulzm)/B|~}:c{F^!,`N y 1O<G@SjDN;P(Lj[nW`y(bx ) a&U3o)-sim. r=bĩrN>qY*Y,Ɍש;MƎsS_%Yx>X^:;A\IbVMttm&kD5'#w\nSt/O[j<ObREϛeoHUg&bN.PL Į@Frƹ'CM\mZ:% I !R`#`㐁q-BaDh0%ғ>}D2ϗ}ި thbpϦ|mqjQs-=#5 F2?ehH{/~mibQ]\KfXoin+m،7vڵ X47KVG[U-2nPlɨ [gJV,e=Dg6,oi޻GZM[/P-Qe=^[CҤϼ$9ȕ5rriw$D-F}ϐi8}Tth-St3P[L$,%ku'Y}">0=Cp%rv2{1T˟Ɔo'eo=iu,+؄۽-H;B;OdE Geȇ'o}9Qz 9"tBRVO%j+(g: |WM>{FhzlvfQi+i/ e0su;} +ǍۍMƱ @?.5NC)uQZ#y)/w<['mO:l[i!m6sRC4ɼXR5o1n\)F̓9 ƱIhfO}8 } XjunfB]SÁ'Bkm{JЗZ(~̛c,C@uLi ,A,ZK??`XޛgIިH̓S W_(%1tE#kl6dE4OĆj_q:Iㄦ<R22p/^ \\!Nl2!|cU&6Q$7F8ro5ȋ48 il!0pbj`klrTxL  GépOfBU˰'bj~kcs 143MfsP+[p3ql fz9x*;cot3ǣNkHSm &:DKG0֌\_qU]\*+1#4UڏGlAqLiDPP mXOt=4C{`]W:[5A؝>.s 6 :5QJ?_xq5l;p7`|d@ U`9xBX )E =zi]AӒiZ.Y6 \9(}|f)9Jb׍ܼI(6nN.]^(خ2zu;1ġH~,"f3X kgy;f~}:켖Zo܁R 6M=c rVYH7`Ix\Jo v@\iqXmizC6B3UuYKFǼJk yZJt5޿aݛr]}r5ۙR5[rgšQŭ,xedGᠫ.Tq! Fƾ\@PI„ cMkŽ?g\)5zDx&k`kRjO!Kd.z|&ubFn˖r,{iB@WV?Mc[a;u7NsH n nܭjkm"xjmqe5.>Gi& o$r֠ 09r)^a}3?cҤ@Gpu7 g. ^.w<$TGSjɁ4F5qfP2JJOZ}t:fP`cnmh!a:s~z0)73M\e!N:ə휥`l'۹O^s.=y2M1N 1-g?$#. Vx8 4",埛IJ꼐WArL}n}bsٷzE*.4ÁTӪv"Tn dsXHVt M9awG3*&М~W"}\|0 .ɶ)3 L'cBd :St [ݔ?}2Ħjh*RNPqϗjOàc\o'ͳY;`g _Pȷ\{-&XhPDz/\ EJY')S,JPj d#{?vMk @ɕKN8}\/8W^%TL@K *âm7NG)z ;򩹫A8DŴY6}{[UGdG{<2wPqgSڦvyfƠ_IK.eNaY$N]ƩQ:eՃ*(T 6z+7s)W-ET=(d;4@Q1VY٤)R5w6䰕[vwi_Ƞ.$p;Csݜ$-Lv)E %ӂsw_.,ڭC"!arI 汼 ;I/?pׇDSc(81gPj'mf6OnCTb9I*yS,㎦1fy{W販5a8{_SoBw{ÓA]r BM$o?Up=>"]c(~s`#[Ojfg+Q)L1Ko)pʐ4b0uEϽO1a%5g.j[ t0KP#Μ6ִenOCTMc6tZqIdZbZ2sVI8׻duDv $gȫNZ3`˫4VkPR{ ! JQ& sK}/='4n۷㚣n:! 5u{Z|W̽$M^E`߆ŢxLȰ܄@'\o0B%?r~[r6</` I*%)ꠃ7)!ׇ$QW@2i$`gtS~t!5sl2BǨi«:'H dU>?XtDH@Dd" k'\mɊN1ۃ{_c4BB.UeY|SJ{eQugrY]X8]ٌglcX1|ns5҆r"ۡyX7. U8גJtE H3s"n*Gق-P ~&2~IW#XhڮL)rM̄'BY*c"4+KZi:o qO@`{X!66m.y@"`Rh>e7XjQ 83|j'uMyN)1VGCD'B1 UzOwvFT kg?m("Oߕaz"N5; ͼ.vg^p(qGX@7=vCSFY"=FVԔ~lzV#ә!NyK ᡀs-]֕H]vQ;#oDG;[T+sʺٰ݂diǡ/xXPÙ("eT8|YѤFx"!c}ac/V2_U?rQ$ˌ#=xeVñw|)xY_/-.PJ?q'W8ےDb@oG][eUZ`P_%)(ȨTpZX<(GB,b[~t[`qPl,T. H򰞽q>SS ԨjdJ'GnSKژc>)e}~Ee2pŃLjHd$ g Vؓ;'IHFcbde+A#*Ѩ/'!h>u/fC|K3WIb#J(&lBlwl_/d_ЄKgAݾkA Ϛ<0G ;O*AC2;z葓`,~+#Az˗>Xh#M\Z@+;a\;n4Tpݠ { =Rk|C'Cmi,6 i_kԐ<"VOHk#:vs :A[[t W%)6wtW2V(Xe6wFT ka>~eZɥ;j3tڵ}4Dƈ ON" 1fR ^6pwJքSr<SG y{ı&5 t~(TkmJIn/[QƓ[i,& ,hR>K?e9V "c<Gg"U訢ܹEMrǽ CEE%LL`Uy Vh{Y|I{2i׶$xWmTn'b0A,L1zڨܦwgƒ"U'9EWmC'o)4 eGK泉\s/GCY/7PBY'A>ᷖ qtS GlT$پA<$y?ޮ)?SG:\8izm 0&r*eO^ ;Bo9-T_%O7J*x^cQ[6y5'V VT8 %w+Jn.*~QcPt2G$zvR<6ԄCا"@/u@ǂ*5.1GTt?Fz(LL 1 "aprif@02N>ІݜpZED0c603Rt@ (k@`_滖 =8IvÃ`SH !Fւ~IJߩ*u jXg/(d2&Z5lHeLO$p }؟M ST!Pu.Ѣ6ogV60>XqWA  Uja*E32.Y%\T+IYEx&$zv v0VjgGzVs@Hk#i?L;B. ፝97Ep^>zN?5]cT3-[U0NJ=-]`1WBՇGޕtʓs5Cd; {BFޖnGuP/Gi09C m@y귏^2YRDJR!B>SA~?d_+p`ƃ\n{,n*E@ЮؐO+OñncZ^"M Rt$,;8,GThcہh[SE'n^!Sjmh+~tFZɲ7s9d Bt7H=|6/tmE|8] T4M3ڋd#V &ގ0:Y.PjW?8)r{$CGf*XI0*S̃qH3:@Ml,C### )Uf8loNJ7D9ىJ!I}5a砾fQ0O7 jRImqp +/߆ޓ^= tB!jC}?Z锊%UvDT0Ŝ e9~>W {F.[ɵejIMnlǷ3_4{!%8dļtL q^Ojx`_3 7iXOHrj:sk-ky q~X,8I* }_B7}1@b1liH郂FTNiן۴am"%V/9fV b762GA[GM,e4)GDAǔ򃲟gTi: eNa+snۊc\P8b?\r /0WjG&.ܨkpãǃO%9``ІkInGó"&L|=u^rXO PY'mמ_p:7mU_fݳM+k̮񵁻fSyDzPS,ܽqߎ=,tV ZʦW& ^ku=ȅ%"^ZW"sRLfX&y#,VOFk^9( s-_0D49GSG **{Ui.H`} 3#Ee{\3[[{؋ᾤ& BM]opH2|Kh}AS(R ",nEĆ5!g,[qhhV3 jb[L}gB:eյ\hUtaȟaTl%n1w *xշCA~1C #bǑ7gIlD>ĸwl Er2ڨ-gRRjfd1V+m\$cRr5dߖ`O:ҐXsU2oΨhIҴ6T *imsmE,7N&jvS*3 xq~{G3pp>l,oD鄀M QV䏶&K^L(=1wsPAx)ssHUW&B] z%;+{t,Tf'1P٬vp~ u%&#lCP$Wy&+Pr%L'͌I;FE--GLYNTO9Pۥ.)%enlCYޢIG-ć=7e>/AEgTtOLܠgwCL/:VM\)l`7JywɍfԒPKn\5 ZGG]b4Ѡ$U6T l"ۢA:NmWk7d, m< 3Mq*h6=DA1Ž9J5v7y űUj9jehnħ R5(OHa*BɼşS() Ή"[ p4,ʄ,%摙B(b_mpuN`dly1Aj1N&rLؿuW 6]s7.esmg%bւq[*0B䭄5fPW^dJLK@i<7kR' {k=莟452g$U.gI0#*_QPVk 2uy&llې r~Qu@11[L~X%~Uygì<'P@쭵u^Ec.Jq7KjXjIƻ;ax!D y'cjbӰUoqeiJ|oiBB0?ʉA2k9ߐv^7-=01eqY6hq Pqқ]-rm/%UBOYUi:8D/ĉ >m>SOм[QT/$glJ<.*e*K]Ԯ};BZGEaEЈxLg .V%6Z{ . /KB'_M3܀ PH,͡zM}lț21ܴEVEA&h]%\P ٹf[c7[+gnA; U݇42f11Cy,Jrlr.5+iY*26t /9L].9!c:$"Ԁꄴ~q^6k^N{V#ˌ&_źXۆE#[@q>olMS EtlӪR9)a <O7"6_3#8/ Y\t=I&:=ξ2Z"] Hxl@kO> ڮyYGWe)Dδ2HqWNh~yJ"uon~ n~#U`.'mષ5C]4[7g*K 4Izm;-y8~FR,WO?W[U<nv dDIl/wPTk&.2nX >*vY8:z3E ? z25v-FdKF9P5\(8 ²?Hb τ$6c?H`<䚄`Q'%P(Zvӭ;Ȝr:91PU\|(/K"X̆8BLۗYij|u1e6O3h|ºڴ>F=^Ϩ]R*^\(YV+-8;(KjuW]S(S ]lĄW`.) ];Sd 2tʧ&:>4VtUg<0NA7Ps~&w 4VZ+\KbzD.c|rf"29K@b ]J10-nT3Oy;;̾?>IH'Wc2G{ja/ ǁ߂/m)9j;l؆+3qA1bpOo{vu*4L̡Ncg+]i*MʆSS̬G-,F[kqK3<$hj(l46=Jܔ3yT ^:BYɛkZ[h ˽-m<]V2'slg@[$}H$e04ɢqv/3 D4̉0ӣihr7+p3lϨ5o8U5F/hK=D@FdJ 1dH#X2LUS+༸tr2܋!a*E߻!dZ'; Jwӭ&uz$[$M2\3eAz|n‰bY-34Y IYpIF r5~sev|G"6 tɧ1 EhPN܇aK 0_Au{F,BIKߑ&CxĤپXzq3 z',=e='PK7 GTmB (VJu/!>h!k_9rg-:qbg"%uxuPx~m_)ބ2lCq춺ߵFVtcyCB |f}Qm*g80w_1Υd}(i1H~ O.{,yqD v862eN]7-/R>֗S0&{l.Ae?͒W?$B$sTTD}]Ɱ@zqC9%\}};5j^OM W$[|$X~nM* AN2{C( > bu/Pf|-Vct U ^gQgg_^cPw+‹~݈(b?e/b6nwJA_^rE_@ 6rlgrm`G >x0oc;$vR!88 7]ݫB ;BhBY6\˵^8뚔jR Ipa8O59#"]h@X#ΐsCr.;A5 Gp0nxubϡ;@):W"+g]{<5=LUg9}1H:q}iuT%W_s_s-93埩^ #oH=~y]$wzƤJsx _IV8+@U\z \Gg1685D+;aĜlYwXqӏ Ljx蛂%T|ppVeL3Ǡi)δ~] loCQJyە[ge6#<4_ۺ;*U+ZV_s iV5DP_[WdE:`ox:?w.!,O ?%$oO%M4刖=KP*z'3]o})Bp:s -Uk vE:TɅK3o^XkV)iF,8n®{@uz"rKb U$>1^ Q3Un^ "TT"0b _ EĥHVGa(l鱵t8R )W:}od_!=o/K[+C嶥S>"=0#14mn I[ô#jz/<{@kg5p!.mkĽQqL$x &tf-w6>4RGmule6694d<5ykcgVŸ8] EE,@|umRU J<_%q=95+Q+VWBi稘%?jL,Bon}n 87K/Jb+Q 017d2;K/p7T$F,\#SdjMZ`χ=rPK : f;t#!$]Df0ق>N2",~!> ZfɎ+阥RK4aQ%|E[F.y{pCy>]L09ˇWq5XXe/Dk|3.t =P_'0/ 3v{nC;@"D7ĬkwE| Q(n{`>md%5k"W k>3)WA\ɿdGZ.)>Ţ&p[l]p%/@sYC#9W܏6Qh}34at-4&)TܒʀH6lX_GKPZ{n:HBdԻA]W.[gC2'0C4qdYL&g  5wnN̷5u̩7?Irf5TCYEUkY(qgjQcC Zrq%a/DE.u}gZ`B|%MZQ*c,SR v&. %ݹ:j_)|6ՓT }5= jo|߳{•ܫW@-Nl2QC}y1uf,={RWᕌ)ٮ*A]61y;u8ւz^;hZp862 oN>^EݢaI'oU "Jम"Bvc l"_Ju9l1Ax?WŴl*j؋,oa`ᏯZE>?V7^sjXpϾ+E-?1bDQ]TBf ]_).xYh u] ]BS~as?˽aOΰ%ѕy7M9Q(6VVZI?Eft.+NF/:,Xs-)2Gp': i 4DFձ+a٣# X DV UGm E:|oMm Qu [$^1ssFM߂F>,aJ@3*{oUxdyBvk8|@ֲ$y<;o*/X(b;Ѻ<w ˕B N#^^$kÆO*] v_MIھ %'1BT%+=uՏR X6j, +{≽5; ;Z&T( D @`KК3_yX"̤cl'܃ܞ?ѥ;p}v)|tf9%ԥ.iϟƺG쇑8ճQ كP5Y3lpɩ0AtHz6uoz~4 2 9)(ß!Q0pXse-jL;[)mmMMwE@@}R }{x9ϝy@z\11O| gX0AXO5Eut|PV!d~=\s1?5a Z|#aѴvJ%H i\}/ ״Nw1?to6M,g~f8ÝQEVt gLnbTHǗ<2z.>KD&fb60Bf=4˶g8Y5-xVMnIJI6DSqY J݅6srDV f3cwda|W'|1*{Y\e5TU5wV'ﮤ<9W3?G`i=ͷ LؗPE?WmJqZ-KjڧLAKptX΢;?e$Ȅ!Ũ}Q 8dR3[#ֲ9ق@Z/a-K6X xy"z4lLPϓ"ԼȭPJ0#[#x,=EFV{0#\-y]D( r!!e8~:VۭgCkt &0Kfyg#ԫ ط".)0|g 5:3>+q@$3fs0(Vh=`(w z0zb]* ȧj9CAST0rN c>s:E_4K|Զe14մ ANRa e6&b08G>ȏε};g"2øpc#%WS%AW7QRҩsErAA@ͺivu&Z&BG>&VuE.}%WQ EpœWBFw ZR=e3gbYheV Ҹ(*`WƠ&kv c #oHa8E?|27thۆ%>#1LLr=__,syv\* v#JZK'FTќ&{sNےTc7z)aۼ>A0l7%fHu.^PY@x8 | LƱ.'?,)- PQKU6訆⚰}@g-DQJ2 ԟYi~gx-VMlE(kYitJS,ŬjJxöb2e@Ag0bBjueeѸ`h63U.N̊D&YC/u3 Qg:x`(@ *[zg f~ ,&-&/ C#$lbfq;ɞɰt>[|BreO%z99goG}[26c^\7:Vi cI(Ğې lU44-I1b5{Z ۆ ތr9,©J{!cgm28\'֑JCOZ545wRZT"]Ӿ1{>F'a$̩nLRP܉U3}u(hY<\ԨOHF)jDu'[۹;Jd^1QC},1ṱA7k10OQ!\ ĵ DZ* fӫs{f{)Îsr(Lƛ:s_VG 1PQ_q[/L56A*pq̍-Nz ~<' 8PG;$ .LOB~#㻒Y$IN0о׵% ;e؞P*O^cms=8Z#&1{Xڬ;y9jmz֚iz#§mjItC2>3 ;SǧL2B6H +]e{ZT'v36Osd(v\V;F=mc/غ o>NSB!rc|@U$r :4T ?PbmᩮxIgS@¢=ΊIT=>}$h5p:&v&*,VZQ!/w-V'7,n,oX%`Uw-Fcl/ᙂX$2(:9w_f~?4U'_)1>> daݡP?.#&TԩKU iHS:7z[% *^$ mߙ*ur4m&in`I{.㴫Ϯ}z|zERhGث^[Lb?-j5Is=̞~Dcn{G.(N{cxD<<"g+# ;$vBKjȽȷ"7i̕8$Pƴʷ_n\JݏSaP>f9,wRL%%] &U_qM0RIЏTO*3|:?PX*ؖ#,L=ʶ{~RsNMMnӼ5;qMY @Z{/d' `>;][`R6YVhFbM;ۆYxDz$2HO; @](-B KTQ&zI%RkCw|+=^R|f'B64!<)B1-5 n;`G(P/0x\p.3 ((Q.;&W}ZR)]*O2>1(6A{sY|Gϛf<U70xE5%($-EՕ:8~f@Su 8#mUl2(I|dG#b{2ND>WGlV:j]\>Ŧ:}XL '-tKM?:O Ik +jrn=$d~b՘:&TݥNʽ_FKl0hDHcHZsZ˺i: i4 N/eT%ʑvG5TeNRUxHW8zr}<<1 LBv0{`$\j@cE"@Rl4WRz4e>U41fHXKxmL^Pt61%5˘qӗ7_Nt%{-ߣ X7H:CO"M e΋ƪ&x#?E~MTS#fj["_lѸN ʼn5u&c'Uew2>WfXǭj>Dž%jU @v@םk-EX(AbN#hxaTT;jߘ4m[)q՜k$(](LW\Tᖎ9z4 ܉dZOܯZu ۋ3oE)uNBwOB#rYQtl)guE1=<ܺ[?8E{ nYC]Gcl"#% L/p<[KOהteUNL13D"c!*v}^y&]5|R!|c ?EUDS_+ yɆm)t(̜)'Cw$``0\ͬg0Z HjuZtqw3k8!vAʷ%&㽂^1?5L|wk4*5|Qd7\pfVsu3٤Iԁ*Qa6ut*c^7[L?K(+Hx n-Tn +U/ffiFEW|poIPMConFpD9ՠBNO!{qn\#VeZ+l=xȄ<(jiۺՅE<nn`vwUmmMK/8V0զͿ->Y~?RYܽM ݑ@M68?7, NEq?.1<..@Egn>=~1<&}z' kJԅ@/>j+&oy>$ IϦ7S VR~ȡkԱ̼Dii &q=l$;mUi -X1lJʳspܒ$RKW\3Eș]Oٟ^J6VDwk\RCNUΊam[,ΣB~_Ň`[@p(=ʟ`2Vvt9/ W,V×a( +EXy=2`3m8@RTv܆-,\y$uT5gL+IךBx@y+$.'?M  \Vn[B$O."d،E0Ytfc\wZ NqEO=S/][uo W۸}Y#ܾ5X:m\I&H֝+ߏ~O;ٍ?_mChTAjsTZ"*M@gg&wNJm\"GWF<س]mus%k?mJӥ"n]wgn^EzUS<NV;b  Jӿo=HLk$vgw9 \N7T4Z9bV2k:{ ' p/dhzW"Y>Y\X)^ Mݱxe&| .1<{;nhAgENc!a`m'؁,]\e> wmZqC ͐G[LQBTjS QS UK2}bCABćc==* uXe ‹@J/5vp|)YS@{2u\7S$W+@ r#ŮVF)ݟ UE4?X$$;p޳Q;yco%0"dׯ)(,v+>Ra-țRVYԣ- vD*gSА/[&&i&k!5쑶K\d*5Z#gž{ q s[qߨHrMu̕\ },.dFl&A*Oѵ_ cw&KEf_G6,Y)|/5fwB]$ջ"n#]HA⣇0 1i]xS^CBˡ g>x򹨈kK^'ud@ ReyWĜRӵ2ytw-b\G+tde3P$qqoRtaߏ";*LϵT0g>f9'ri4lVմǖ}}*CUңx%׌2ky>MNRJgzTc6M vO3 lvXK>M/_Äw&Rآʴ)|3uCm,uO~=$A`麷ԛN dʏwK;rn㏴F/G+R_Tﭤ Z )yΟƓ~,|I(5r2oߊя*DzObӾQy%UUd^TDю55/M7ݜWegt]ܡa-da(`EGv\̱y)HtVي ܺ Zp1|m՛K hy3SX&7~'jV)!HgAJ67Z&ۧnxBqo = GARqd0HL*5\o(CF`ÿ4VH@ѻlcm@-s[jU?dsT oRA+1g%aF~ꚴq%mSOsŘⶔ)P~N#!P<{V A.%',DŽM,EU<<@ 8KK#@*VW3@rrU 3yM X~]okC\V\ !9r#%ҏnDEk`"C^8)^zD??/BYm #Gں!S";~WbUi7p&cH5r)DC,ҊQ}Yg=QWL&V|r*i249|7,t;Ij"#b+8BG>,w! /cY\_0o]CDobGXhϝQhیnDkeGN'Tc(~ 4,usӆy3bÓKDAxrzZ oE,B]cI=cqM@|-}) AD+7lyC aRG?tj쎳&;#w{nω嚻dJhz:W<r9HȧD9Ρ9¾D®T?h@y6 *0tXMuGpX|0ރzPm7Qi~дoCCUgrIT1A6Ν}LCn@Jl7RZKwO6tŀLzRDz>$6j%X??JQQ{]y/vs0 9Xb,8YH|]uq{? KFu\%@.I.ȡm'.SSR$H'gLG~.1H/'M1ytˆ($=5Tk$}u@&ZZ 82Lw㞙4Q饐[rlC1D!t0`v0g^jޝ!E fu!tӎ!f(e.y!u͆x<=razuoDឃWn_!e\<4ڝ$r|6.}%:aW)n$RyhMs:"cު Crt)h(W7m~Cq[ rrh'zɐi"kVp`VTX.RͪX@l"pK/]>i0Y&){œ^쟧ubzHʫ]::0oVXӸOՔ!>z6OS/pm $=1f_1%!rXĆ7䒴)-tκ[vZ͎S,9wzJ?|1I`%y^\wh졑 .R_ZO׭5'q;H*(!vy6G~vŭ`! 5ľk++3?u:NeG\p9\ q,(yTmz9OX ٙ'ϒi6'poME%SF'+>ptkn*R=Z8m}]Kʬ|5I=Eƀ .2_Zt-S^y1qLpCɯU qَB$%j$(6x39, Ya1ͳ֥^*K唵GMxE=F]+,BSQY|xVv|V)tDYQ!QLIQv>9]˄B(@G *5kA[poDHV)zVdF3UؿjB’BEu~]4p8DO~ $M7rt%ƾhl) ]s034!30g"댛lŲ^xWs$< L>]S11J;/9Z bQXzzAEbe|/A?ɡJ%J*4[.ptJ|fx&m{ uRI yH58#=1BXBXA_c &Z=z(~IQ'LJm˦ȓ9\_.F9땞XѮ1buGЗO ŃX^ g|CdnS037u` ⷴ%V`ӊ, 0~j8C g 0r$~=ytY)|qAg8쨭ԭ8]9 E/ 0&}*m'ͿG򪽥arz֜ײM;Bj/jԭmu( dJT4{Cu*p kأo+?9.(ZSS8&}EH.M| o;r$,P@zǖ#Kثʬ k3j K̖)PE  ZF#DҮeS!1pJ X6Jz=,&=[ Ae1SqkxDA|.CZPVy˸=mN{v)v]y:\meeI4:{Vc/Ҭ\PMcF9YX65DK`$jLi?% 3wh*Gs偲%~^n\:W?GaLIה 0wSX '8J(:8WL=K}Qc*irP,fy?䲬SUQ rdZ>!1k,_f>< hzrJ:0f#z1qVdǎz9—!0 9%͜sn_|S]Nv>U53=pLZ@úZx6IȽ/'.%I|ֲ|,J]a=ҽ4=!~٥٦`Ǐ5)svXSXe,j@=]9]R]z%Z=WU/y eb  X0@I!sH ŚR*hΘ>H9=A=Tmrkhb lP m6t04DuZ A$~Y<*'}m]Wsd{*ɻ|EXo96cOřQ&): 910M@j|7/}?}ZLqbGeSu?۱pxv 3ʨ覊L5|V a ~ r qSڝץ`5!ܖcq7dDB˂L萫@TJbe.دvs/,f`{&~*/Ypۧ1¡T7 \!I__LK65M.ZZ1.e/ -]J Vo:ueA~/h[0^8, ŋp0_ۥiodh Y[L4"Wm-)&Enr:Bj$2&ZۛmSS*|⺮qDoi=HMSph3;WN]Z, (7TޣV3铯7e,KdTN|i?&ǂwUWQ1竸zF-tw$+3ɵX(2c<}U\"lY-XԊv]6\`1-IBPG?kOgl W>n\*=Cݖ&i()(UGDZB<&z޷iDZ7crh$A\8.ۂ|.$RfZ^ݙ}) XxxE(Rd*T3ƸP&E֡9N0Z$Ci*e', >^ƃe<򴮀S܀g |(e7U]I[̋ahcMžf^]D57睘Y B)G<31uFdBT{1G MXjwѡ``u=nK$'~8E/jo>1S-pbS AbOruFDR ]30'yPoII] n!W'cAi]3\t%+=կ:@~\mt0 :0IVw8@2E[LB',63HlQ8 %")qa~"_w4T ѣVۘ^\{)yK8u]SƩdCdn"[Qӫݣ <?]lM"yCRʙPݤ.5't8aip產}mĸxP $x͞ 5qa z'gue.Ì~ G%t:U\,|.3KVw(>X w_ڂ:߅HN0Tw54sgbN<.;@djle+ȗƪNֻR['3oPi![&5Li;*A+ /ᑇ97GN%kմ~ܣ?p4L61<>P=m""1, [څnhㇱ11ۡ?Lg:#Vi3tTLx%`GG~"BNa2дi(̸a:Q)Fr .[mJMevOe 8*xΒc7n$!bzIwį{;CiyqfyQ^e2,ȱd3IֈUH3b^l;1:mQґmz\ܕ-k;z3D'g/1-g?eON \O}*RfŕeBMUم!?l`afEK!T%=C쬖Sy& hTOawnCgctDhĞA sn$sP8ݨ89^{3F"c't frlȌyB@ː^wOKr賅ިUX4goVc"RJ÷9nCHQ31 OyK~dfIV'Qqmmcr\YC7:hn^4|TߝAPxԸ?YAK=ϩ +%<^8U PejU:TeϴM-7W@p= gn-7kT[XLYW_?h ik2ZGr(*D_K^2H SJFGKYuh]oz R`Sr,ՠJ)b4AțUܚS4k{5Cg!\A[UR+SrG-_ %Qm5ɧʽ92'$p]C"աM-}_-[ɦ܌Y1!oӇWzh|ĺ#lxoS).VfF}0m*ޥ[ith_*dZӈxK"YΑ^V_R4CݐѦ 6``XOn8$GE(Ho'd ŌM]udTIA IS)վz'x !P𤌘4"rw$(:oQΤB97niT7AMr?o}> &|,0>>WFK!$(;|-h7SsE1]\ }R8ź},ĉGlhhI,pFJź^#E5EZXکVB(/hnW{ADL7t%5cxC۵LS v"bğWQdtJuB >Q0 ETVv76Gw)Զ"~ ήaT Z42P g,WfK7 B D$e%;R7Z"Ļsdڗ+|8kpCr7P3.~P2-/4r׵3Wܱ8&uzLgw1Ď3!3р^<O"i(/XCs .2gSC} `&#ck@?] gS2ՌHBiwvRPi`&~i}GSTG;-wШ3>S^Pz˳OD4 5Ȩj2KY :珳}`hW,90,wU{=(聘&"/mUcSh~sxBxA[#}>҉ ~0&ϵO:,#zAVUuJLɐ^fOH8^jF 2>IjB8 ZZGBm]cY>+("Ay ɢ3!K52ﺝst10`64W9l/}T.(CeE6Q.s tRϮL{ ^tM3qEG8(9a Mzb\)#͝Z1V0$EzCty /H7d[Wn7BA˖kΌy 9@FA#EwT$ ]{4Aϒu2hY{JϨ ºFMgXW~RX[ ՜tb s*MϹ.M)fa2?}wY_&4fhFKZRfXGdN6KxlGuf0*CTD/g9*yfgf"ڒ{vZH {1 1V+P_q.M '[L hlp+6~1ng׍ESY0OvsC+z WV_G,~,RoH5&{z&NYs׉~1Ϥ3Z㭂MepDIʼ>OA442zPg j:B$ a]]EaUehڕ5Jm]B2w@- խ?6 ͷS9Krѻ+5!ao 8Q5UqT>eF~3/րy~%"BA!Y`SbU0e/3^Է ,R5],80UBM' iTsƣ-F)8 ƿGO: ]cOِ_Uv*6z3RǛ[]FpM?G+K32nZT18 cþզaĒ-vN"F!,uqN,Ppa&4XXr'as&`% @XouX("쎂ێK T TyJUTxЉ8@7BbԀvBxXLFT<\_QʶIk2[NBaڍU57'upv.붺fM}E au/)ߝg+f< `T˲Y|fe-83?K$L u*6\2/J%@WVe.o/yuDőzG#c9I ObQbH{]T4Lz /(>. =؞ӂ!n\,cauH!]Q! :8`d 7cGFcɗSp6"+9/E3•Y H2OP*jBxXб/;5Z2̍q=p):0Xi*7pϲ32K. gW a+yTB~b厂h`|Vr*K9ܐeKJ+S;]pƢF0nR_fjw1cc*1sۖ"{GsoOejyUJ3XCX\Cfw1]{f\ƮDY:v;J[mˏ_[udj>\-y4ߩ#Zѭ*7aHp´ٸ95 ȶݎ[MZxzn؁\K^F`VvmcV1J6RXkK2Іla,Mg%̈́砟>܇ #~&<$,Ct6k%QҸS{_03#P[e/> *KXϲ(Dkv\AP հ!^)GMDujFf J2PX`5nP2E; ºviE H;7fݰ.c+fQ~26>J{~%s@Sȿ^J!R {D\KXk&-7c{^9kM!Zto't3—z/WWnCtJ'&p wL? aOd(R?vce.A"*i&h ӚyA6VG3(K4{ 27 @]]MHpR<}W~EſQ2e״ o6GRG`` 3h/|.E8eyOz:>J,}ίۚ*;P7Y Gwr I񹤬vcz6tJ2Erb~7Px{ c+E4k/&N5{KӭS(=CԨ eAAsLE ͑/GG\?܉|)/GG-א¿_ln'WJ|'͞pGa&7>+< fmYh>㬂E޿1.S-Ÿts@ּ) NLOX'cB)/kta {~j-%[u /eX>z6)QPY![ -ߵ1R|1DrOyxtHy/MvS/Jji$$ʔ_A U_  '׋8 w6`$_s͇Y7 <<&ݶjgEH DVNp%C@o v98Pק`Xs~Uf%)X$@0&JRW,ýL* }}J hǻiH/"ɴ\m(237RU;x#@3g,ZysfDl`7 |L ASd/Fk~$]@\xqʅBpu^EdIb0nxn K\-)^:L%VtZ"AhN"(W?2 섥ۿ :fB?vL\6c΁}>.6PLn~ZW-rX"bԔ2N/D-'-lh%aed*|TlB,qW!lBl@<;N`)a>}!%8x<77'z5ؙ6h1:)m ?q况\jKI>\*"[AjlIƶ0Nūߒ/C^J-JV>k3T}K6aD7J's0ZX-xE0Ļ=aKƂV1bj"8H\')r9 +m#_;Vt{N<"̫|z4jmo0F[m! ѭ;3@krc_41CN}n>k~VƈY=oyE ݚUpz:Uq*ǎTl'9Ȫ_M[ 2?eol!iwU)mй( -٪  Hot 1Y4nj.KU$LY#3 Qi8arKsZqJ~Db$׫<롤7iQ4.ܓ>0fZp|iE>Z?/f??E2l4JD[28qI1(VID @arGnYД q pqWq+V%6Uޙ|Z'-PI@[#r,]*x_ R62`%}):$:]^BO^I{-npKxrmrüN8eC*>e_X7FBXe1ĻΌqFjԾuQe|P}'.(*<ŵ+q$>o$"r @ޤ͜!6!yW?;ϔT"eaq Gޝ_0'n @ 'a/x$P?* W^d6ghaA ]׷Tڪ}|s/yɕhTqC!y3b_ e$%Y*U)`s3TwHy=wb<5Ol!KLcqzǴLMQa`Yj\^+5!K?|,謁Bz8<ɨQVkNIZLp093*w(8*hCa:[NR9qwݛ!OLZMn6QdK-7w,Mۣ! -< [R_R 5z{DlHF_4WTUbϲɑQwyD2ZnVEGeA^ PKmyNū%N%aڇqD=r1z޺\:;>=?xG0%͹DcC2F}KvUzLJXH"1Z3 B~M}湏D"ld )Ţ& ^*ݱ&a<=⹢J0* \)/gCCDbZyMdby:nR { |XiG'aݣ7 m$Sr>+) |{Ǻ<w\H$bI h:XS@TDŽRʛIRx|.Rg\vs^xG,*J'sL2dnY@h8O>* VU@ !XYΡun N^FՙoXҗjm9|O=S&p}w%dސSPy^Bp`wՏ\:7.Noن `jBu8\Z?B-q'IgZ[9S7-J#Y7\*A2~ -l Pܧfnݍ[!m q:N#a# !*5Yhx֭QrwŌLj{cT[ax9v= Ct C:cW!ua[%,\Zc^ǀypcHY8>5}JsGHfWb兓 Ԑq9.=9P8)ۏA٫|&#FA/Bx^(Q_> jDV٠cP% / ȚXfaao6Kgl#XbtIA.ciK)W]~1t$PR C i8`qgG13Ub@()ued9cu-ow >JK@ U@܇tnMznlc$V'ΚEC ٵm*! gQb}wy+ ӝgrS`a%{nm'M$bUX@ >`$-t,vsXK5[mBbN%ɷ%d-t@%W7%iXذgM9ߩpUuay k!*y`~ѱZHpnZl'Tee?6/|D*PG`8~st$uśñX;DTշb&jw_: ba9FS2χG67QSTl~Od0s4tt'OиT}dx#l q0:uaQo!rz+OG \ӬuF.ib2f4 6/{ *^%fΎH7KF_0'\|FG̳Ƿ tNKS{ W E"<: > =H,uytBdKQk!c:𼱏,qJ"X\Ii*fl<wRHAs_ Hť>mE KPexiocRDb/6hu&mR}r&q*+mk%8@OU!Nhb=*}M7Ϊ(9'8qPә%Woϡcպ4; VU Q2g:d$\tS٠*n/9mJZ(K=IamU.=G)(㣓 IB>@( Ŏ擽DjLYJu#)TN^NpQQ`Red'X"'nXRrYВ|a3\Hϟ}C 緘=x}!!Ͳ˝2R9N)0o,ԆKʌp(՞ \s#!ei 'j5n<~t)I0-!jLY\Azh fɎ6t^żo}e]螐~۵\+;}g1JWuVRMH~ ܞZ׿kԧ+}QRNW6f'F >ǂ|'nNjFj+|ٶWbQ[N@vCϽ!{L0hd;P&,dmջ?u߷;LA4'6] zC{ `˭˫'(M.3O7@̙k_x:@9?/=p[waMBc_)l=UP۰=rs]c9WmmQOϜ;U'X*i|[t(D BJܬU|AH#RP׌&Rn] @i袨3$=8V$F-yPɕv4S0*'Dd^ 8ѽB49kg1{KR#T .JlJU[ q8Gl#6P/Pl ˾V*F`9a.5-xN߉f%/LuY#U/}laR,[HYk\B()=Q6Rq.{q'*:9ĦnB_1wG UIi,vm:wOwXug}9ЌEQRZ)|䶥ȯ:@~c319~直9ZYpR@꒟k T v'[>q{;mfp{ [ ZMgZ_nlk U7BҐoOWZB/jF:GDHdK][ *PX`od0 .YԼF>KevѹxT!ˉb2QƉGG]_%u/Y/};s}Xil/irǐتxfy5r:ae)ƀ$iLpS! ȆSu rguĪX| ޿w |AWcK! '1>#\w;+) qPz4+yAׇ% 0Uzs F`^%LME@п:GЋѳ # w=:)ur'<ZK͍/,ͤQyܜ;q f헲nBJzA!Su6j/o8$C·%`O@5S>NSNVFd [c/v+7[Dt-S(bh`mK/;p/mi];dDvv];0uKσ55 H MTzʶX eꢋ۷SCp8=4fmSO2Э/w̚fЧne9H,q0Wܠb2T1ퟥA+o9e ;ɬ=邵."^k뽄t`=IY< KlN/,$Jrf}w F!WFjdr+5ZȲ[1):l.|GqD ŋSSIlG#a~'ոPD߈HxwAU%3JF5a;?C в7bQa_u;hN܋R(U$-~%?Uꕋقj]N? !޻PѶ&) 82,Z?4g%ݧg\||@pճါ64y<ۄU=ôHfK<>я0c̲aMoNО.<w͸9}9vSs_$hGSE6I`r P ;7pwTth#~<*ACIQ.9#r /pGVd`gV89ijMxa[AElVgC_zJEgq{QU(Y*YEy#3CL9f!y#|oR p3>m=7P]> 4 oe_C&I{0ϔY4;=q14C&']=߄KdڬYn[P9 )Hq3ca%G/nH?ݝooS҃vHm xCfjme]9[+P;<εD'D$0:6ưN+jn`uUNDmf,,62+=wߍqM;m;ԥ.nѕDط\-FdlvBft΢QbI _KHّYb(zZQ)KK Ejۜ2>6 ;cDA W.JY[M H:"lU,Z#LRO?GL'M(*' X͛ԔW FV~dw _bOee)(Ӊ`zD J~f􏹀Oâ4wH^MN<B&ԈBiV1ĺjCW2D*0ەUf2)k*_*bI wmzDPы'YY(݃3(^7YT6W6LJ{n-v6yCn HtNv $8ϺĔd$ƽHKp{8( C4!b]=rǷr4?|KVsnk;*9":\eUQ5 "iĮ答bT,#3.Dư@}U n!L/'dG R 3@{Qeeb{uF nva. x3+Qb7g"WbDV;MrxUЎcv*?h/Ev5^0 4s:!]VnG%:4 4t)T~Jc!H*#RoyVCDӎ=PWnfzPJ͸kh0*9V=m97'\/,]-5y`qhp$8u$N~Zb(|z+{M_+Bᝬ\Q{7I)DT=0<5o/*!Hx2E&$.AS\-W`BR}N[5 COpjKX =ܕo`W&緶\De00o'23g3 S 3Ĥq߳Щf={uDn[z3APK. !]@v96Uf<Ɔﲘ"12ZHynW ^h$[nuG"Qעχ!>\j4XtŗDu 9/]tkI T~-dKU%L)@ۘw2P9`c濅Dd.g}Tpm,}q_M0<ҡµ.4:_iO:d4<|*ε>P*\f5Uԩt"h8ZDRh2K)|_g, LW^)ƅPͷڈzH1vhds˫Qk]ϘE:N,JJs6ٛݓ}/~aL¬}\ tprfE :T_JaUz$H/v$T! #TPԺe؅D֛;D[n{P|Z|*bJ*o%GȀT?hJ%#ZϨRUgDd(VÚki-aVrZMs0:Wɜ[" jQi%%$E1J3LxP˔/zeTw~3.Yg24мX4;ŗ(h%+ʨ/*^Lz2a pU'"? esN Z-V%ee<0 L&qn]N>Qp;}众:rDKc =%ZNd:WroN @vJKTY3^up}.B4s:nK VOskop'DzY.HW8$ܟٍ{{J.~Tג~h2>Gz[DsB;{-$Z4/o3"71\s4ccJЁwci*iEߝsͅ$KoVZ[,^ж#rQqP&z# ∬I-k&f}wd" Dix}G"ƭ[3̶څ,%ŢPEh A3&>:l[S}|hGEf͋E-}c' `ۯ1mi^R wr(Sq"g he]'e}Ca}J>Z)|IYF9AJ~ߓzzچ1)> ?bU){Mf]̮gԗ8 FerSM^#| A)xPfciKQPWwNht|/PQəQ#KsGkU6zW$g{9q|?LWmmDp=³l"!"j=%f-MVz\%p尫`X&r8ƐB {[؃ddw\lH-(,7smR{ mo8Qу)inQ`赣xgcf+w {RXINꬣ֦㕑,5"q|pJa_1 ^犽-1c- YzJK$pE$2\߫z@1&*ՔK񛰀ؐKddSAS 2BPI jƒ>trFb#IdC.Y@lr4 (v^=1. ~|aK_>j~GbF8l .67-!ԬyX6sc,𳙈E-%~dJv cP 3@H+ю VXٓV>[͕/ԁof+ t;ײdK_;]3 X >6w XރfE;: ФВi,Բ|7d>T%oU-忝"B?| H N^N. rSۦE C՞pN~ M,s6nxgnaZZ (wodɵz< pAh%i%-<:b&k{x),-79Q~PC;|;5g#/3{'k6b?tz#J)dO.b80}#L;k1Ib-E~EZnlYBQH[S۴ fn|}⌱b^bGQ/ɱmNothL^X4ךЗZ $bWQA<7iN_CUԷ2k:cޟ]:@l[.n vB i-1tλoM)cJ.Ɔn;&L80X j(`w3dɴ-Ng'*_WR(;y,"UvE7;Σ`5n~LżZP66܈2"kY6ZȊdT4`8 x+KT35Ms0 z/|o+O,Jx+NuX0,x츜W*(vTf"`H(tAU~٧= H6sQ6[q*9DgڔA~NX:R Kvnϵ+]A,-ُǃUR{*~E·:$!%X8-W|?ip$Eމ??#}Dl8FJ!*l@C#l_ujA6߱(=ĆT5H?xQ?einl}_|d+/! uӔGA{Ty)Hq2'p 2>Þ~~Ͽj [P9 }KӪ` ,D` Us@1L.Mݎ>1;jX@t2מ(Z<}$`atؔYd (@> kj$A2mjV`ǸYy%R`7IkdX_zUo>m8q)ෂښ :-E bx߃kf@|Ozl3؄T} '*mo@ҙmARiWC3HOaLi9` EqP uȷ-/C>xuˆ?^`d˭ϑo1襋iq뷜Q "ȶ֗0t JC%2Gք=:D>T#?5xƭ[ZÎ-f%Xh8k^C!N`dpP 8D"]xwҭ&.6?zcA4+ĔhM\o?"Rɻ葿˵o1Y9u]]sJP'DƗ;Si7NX2dg+\⪼r 6@~hr__TFIίq:,C,uQheó݋O4sh`|Ǽѧj ㉶:S|/h|ћMH!cKKdұRZ08 #5XgBḃX6Eqrm0U"!g(G )I>>~ƀia24#cͬ 8`tc/̋Y8$*xKGi=rI yU{c IJD>&?ojhu$_u k%~퍶t (@?<6^wAL e$6zLdQ\KUJ2>.'!czes[LxpZW C m5ƹC fP[1tENsC12C,'XxYzóy.55L\1uRS5՚Л~ZGoK䙂0rg"COvM#2_c7goC# Z|O\*_Px-rZM˄A]7DHBT\O(ܙ]\܄__+H =Zܥ/[c~Q&ӫ.nىkӷA$ nLڙS@_S 3{Xq.bwøWyt,n%<<#? Y"? _Cj*ʆ Ӊ#&ҺsA ƔN j6R~)b$S{(Y'N":#}fyja2JFq=e_A =FE幖mG| FנnRFd?6V]$cј f&bN#LA/դK*ɤfVXe;zME0Bp*$=rz~xIeh07_7/'F3Ɛt>S#Z"} 7@QRcL2q7Cݢz4> XOa$cP~;a> iT4dG3E> %; [J@BFh,hdM<:OBM "ED~ M|%΍peF4g4 1ԓfr(^fZ\I>;0oIB%3%]!d քpZ{A^`BE3&6HݼyƔY䈻-sI|Zn[qdo*0]-kl#&Mmv9\5mY*ؠjfX9 (JRvA׽)uK h~ciՔUf%#IDchǺU+F1_oD\;IV݅$5/2sŗajz "JK`MشCMB) MxC Y̺+*Ź03HIui#5ո~]TQue;́kQ(T{~W%OfS%'iKjaˈ8Gh;wS Gdl`ѿiU.ƾO+nItLI{qR&iiy.SkiTB* G3 دK|&xs*?%-{G5Ĉ<} `kemKI:vGH W0DE{[iNf'SrccxwEeaffW-]M[Z a'nocg\]Zʳ~%aOjQx;[L'~ehQ7'zB~3|bptۡ#H64πnHBpzKcw"7'( L;R!fj*Lz2ܚ$r #I/r/w F^QP>p Ȇ,iJAW^ z4L}+-LX+Oֱ/E0L `;cfEǘ?TyӨ0:W_,t?ؒ޿(5F_h%rc}axs L 'wPjTmքsOg649ZgP,@IKY"":UҧѢɉvT7ϰ^,D=a:%@] *W{ 5ϻd{>AX>pܪ߰38^[6b*qeTNM^gdǥ[kR!gv2j~nwZo1^/:YT&%67ig3 %~ഐ:|K;$:<-Ũi0FTXVHp މ_9N^3aq.a٫a&"h+ޗzգ Dƈ KekV;(N&:$ӝfwA![m\LrVmkYS&BvcPAk p=pd:\ġ/H`ÿ{N9gJ|By~ u&6̛RL -˵F3掸l$0ב9ݠ5RPvb)+YeH xd L Pgm',{/L1/Cb$I@W*o;5鋠 H[N07;M'J8Z/G3a>9T"L2I9]085Wq#52ؗ&:Ț4ߕ ;:WWS}+~ǜc"Kh("-n1YEmy &)PW=Me$gCE'Se֋R2xWB nGx7붱eďP&}`%,+AvQ9'HtbXYKyqMNX(nMnt"\J,H*}:Dָae!mm5'8>٬B~:/0ڣ`0r!K8eS%B`|L"̹NT\;E2sb_{]G 'w.vAh9ZX9~\^T?OG~Cg||)#X*hsIwO {G5Mf]zP Q6(IjJ/!0+b@s]9 Iԃ:_\//&_&\[>,Ig9})56 N2 kTu*xf5sg-ESMSaB4/[4[$>UHjIe$'KT2yex<]EWM#Wd7He|[U0eTL 8h,ghx@g `Qq=h{iEy;CJ5= m:ƸA ā,mQk)C{黍9F [͛ 4VQ!1YP1|`_ɊQ{c[ŋ,[/Dͫ7FSX՗Y׽ }AʔiN kbhu=xOYGhDw~ 1s7cYLeTfnOnpGochJꯩj{hUbZ0qͷmLe Y 4e3ԧa)+Jk!|*0&J`O-!&4m& u #H(rp|KtutbliC~5]Ij]g*_9p7^GnTV+X샚rޞW{|ݑ(J}RnO>c6B*&} cJD^,k fw.,\90|] =[~ۨS?15YuX\9FɑN?Ǧ9Kt^{2>rUibskZjTL41R}#d~LyY*EG-pe9qep:1Sl1WS=%~' c āu))jQ[S&/EPs P}6_K S; k(,o;#^ӥ &(R;neѾET@>/rl41Fi5x\ #'ύY"@w.Uz OL`5nT[R0`T٩O8lG;|"Vf]_巣UR!xzg 'P6x#By*42;n6d܊! +hDֽW 4fROzɕC gTn2"K6?\ ҽhp`ͥpk( YOcF!֬gzwFB1=^>ur3hDiAMRꬸ9BY`qFlvMU`f99yB4K{0r?Z|j?M5B=Ȼ_.BteϜj}Q٦n ,/&8FnS@A" OTJVVWn.$* ff Zt ֘ՑW m$Y;1q yMM>wRCKG)vr:2=2$^E^XZFjVhcㅐa㊹rR~+}M8s]1?WɻV#fm}0A,~#dk>0[I<MKHN- CĐ}D gc&K'sf:l uۿ㜸9g\38oaRoу9#525l2 bGNʾ2$![]ʅdMQ:[/g.oMa7ʼn'OӞx,w%Q[nw~c̶O:NEzSk\nXu*a?N\<,`|Y>槢M ``HR)5 ^kAk4-u!-+V멲e8AQߺGrh&j‹KGbMܾ-"&Q<\^GѹB4?T)%:[cur-^'RDwql<a]>획՜1W~x.cYqc". h4 @eMrA4L'Ĝ%pUٙG8?5P82]wx'3˥.c䱯i=qHƯ Wh܎,7#^ p} .-ᕦwdݦV={Aڝ|l%m57DtPsC"z-Cqui2Tŏ7rACk(lԪ♷_ռ`y^2I>]2`11R4--QlV"Gڄk fgmg@t΢N . qA FSnXEnU['3D{T +ohGb %&1ңwhq| dsi(&5H!ݣ;h+H)b+kE,1;[*)~je2e kHt*~cwAi Qc6Y-'r" _xBnAR[ 'ov.K` g?Jq?XE Bd-׶1s굇w"ێ5cvR3eO 1lHfAhe7 t.?5oPXCP:;=8F=Z)#s2S,UJ4|Z1{mPIv^1_9M~&:<a%jknNvH/LDx2:\\ Nvt/ZO bq4mIUf2]ۍBJOH$zca.ȆUǍ ݨG0j@ucq5i;qB:'9{7ud"ӯ!As1@SG[_kB>7Sǹ tLJ~Q )M-+l{lqz+AF$=.>|`wk#+>!${uWyr !6AwFˎP)FPۏoԅ(bc%-{8G4' -PNSsb;MB}LjNn,sR :4(T5hوm"{(i] uڰw{x٣s5ʿ8gW3lk4S_i%ZfwzmMAȵ6w k\uwߓ,%w)HCEQ-hȧl+OZ<-(rdVbQ,%ؖqWq%iDq|J@:N(+Y $(a/s4M`0!n#Sw?[ xўռ X@uW d0un `$>D@ ?E8VqOAzhP&ZX߈(T`Zd&C+? F Zt(:8U^Q 7բM^3׽_*M_}!+L;HkuyY:;Sv V!a"ĘjqRTQˠXrR;`3)V?8%Npܗ-,qG;,Ɇ.xiMYq-%+cB3z(0˥~?gnbf80gZ͚PІ})W Aw TŲu-#=߀q$ mRT\Yl˧Ii/!Y?/Q@9! #95)Br)Mzuj@[XZ.YWCOx4Q-M[,bwkߒ2A4-}aUDWF|3XZϹUwXwْPM$6vxpKcn07uCr5mmk)At`#+@Q͵m܆e@\Bt%չl@\9Vu?CޞB;R*F L_aʾ)_}Q f:QL} fy`#P`Gֳz:4zq^$z`KZ~`x@Mu-!&Fӊ yW E%^I5 g&[hM(!R0þ0(W(Pv%Ф>QPKY^lg,`F?> pDtt\zQT;e:r_nkNlB#D*̛ʐՠo 9]c/ƣ Y;Mxi&Z}~9~N*{l LZt=9rۤ52Vb_>n_z$åT5VQ8 kUU4\'0Pf?z0&7^cZ+v<~ ačsE-Tޯ fK W- OG{]_:bx{Ze{$#L+#REy(|1$ȌEՅl\{Kht.!D)I~<"C[MSk'- ݥ2=~Āg^U(I~$z4jG?:G8F9V{'$,- O ;–6r@}#=N_~Ofʣ+QBQ$PG θŀEcxA7C9 >^aVrVqhΓ娾&ė+`֑e=i?*l:=dƋ0,ӟtz-sG4-Åt* }IF_xU9XVS==l=c~⚞:X{}H' ,V1Ohc(d725<~lpvirDn7OwQ|vYOYPH*@4^e«C<^w-&׳.k7ჿb24})^RBڪ 6zi&mч*ӐaɻL$*bi9y[f$`Bg%[^B <ZɗKR#'aRAp/ G-# {@v_J;EX/j]*"AKe]V:Cމ>wc1%c䡱n{#b2}qB/P|tT7%Z',['X/e٨/ƋrTEbdRl86Y}8AUiʟ0} ?3m[ؽJݨ6 `D?[}ަ}1N3)]t08."eX}g 6Ƣ<#,8?ś#YZPQ,+>/bØAuI!{Itbhx= ~eyMظcstWZ\()V1 MI.he:0c˫<𺌧@CǷGZZ^?4a6&r[&Mk5-)!HM<ГTMyXE/S3iJܘȐ ysUA#YOhfFVc'jY*MZc3kR툖|&IށRwk{K-Xl44 x +$H@^^mw8}yJL<Zo /JzYz9+44@AH#Q-ͳ=f!("Dz^,҆~¦D]4A S4[A%}זCKnEB;u &H%/絃Z=A s`8%oy鈵$hѹo1Ot֊D{rr= vS GWn볞c@AA?47YZ H ]$Kp\PP͟-2qj1$b̰ mq6 N32gsC+=o/ژtJfB dDnd'@4Ui:dtq(3W2?&̓a!㣬J*tuφrI 4~C}*lRcLС_T7& 1iF!Ts=x`fFōm;vJ?69jL%IKs:gF02|75_^MbrnrJyS+$?eKlMd{:wPZ` 8V|0̷d u?P+Ҽ0hJMvC&.+a`GM y#]l6h'|>sSr qAOf֊1m8<@>I7[`K_#lziM9NY#3LzSc88 HePNUu}%GI& ?5 A!dOx]+68,"wa6.#䞚 Ng,_d> y8u`4#aegK=WkU|j\lcsN+(j5".l2@ , ?^4hZMK=!ReKV.Ew'k~Yåϫ#QV?}.G@#=Aj܀~74ׇ:xD}\HC}I6љs׃WDVעѠ-MO "A9N4L+vIܧ<ϰ :m[TÇF~)!LqX6Ld+8OQu3(F-~{I.:&:SN3BYFK~l>X3f5 R@wa.Y՘d02G,mTD;M&UJ?\T@@;s70f%]amu C{7"~IC V[rUk\/S@f[_fJ=E ۗ'q&lmA keTS~Rl m^On@2UrahN=3LäW9-ɓт鏑{8-3o` Xzњ@BUؐ~:k up3޲ypXH݊nINWGvS#DAA*\9qm-`gWѯyb| T!WKOCT\jxQb{EhZOx1DADgS! av'h>M mS/,Iq$O=YM%]4s-u6n@@Cv8.v>mX}|K5;74%B3m: ?#KƮBvx֡aPJje-x#]:u<œ[MKL*yF͊+Y acΜҮ@B51pPNCw8-n6pÌ8׽Ma|J֮Nt+ZCៀdEQ/-?zJĘXBLٝAPwX%#}%K+g,׼+]~«q| PA;R'!vsB)sfM)~OhmeDhq^H#^7^jIom=4_@`afϾQ8o2 >*`Dǽѣ%C͎P04&أ_y%cWfJ䙽>Hi*;@ŒL$x^CT;BR~_á6i+mPȣ64=*υ EW8Z{qX"kمD~Mr#_` N-5T]n_aeLKTL}`/M58ڱ"0H*]50fmFTگM$-Gۢbğ'Kdӻ8DiL Fu[r)gBRaǽ?0bOu?: p"A,|vq:Ķ`i0fcwv^%Y^FXVs5 lMQP̿0*"4V%y(RcN RU+G#, K 4*z V_wB쀠XU Gi7ң#]20.لm\]Qnh:cg] uZMF׊Q1C;K {[B?OsV4Ei%r" Dw@@: *U|T*A[p̼oCeW2وNĦܫk_~n;lQXL\#6iuB\Nk"PUG.? m]xDž-bkBwy1#83$mAǯe`ОJsKʸ<ή` ,`CIݷm(ӳ.a;tS Ose@ 6]*{ ռ3^A!OTKM]#k*W,X)D-^G Ȥ"aԝ ΰ jFRqE|5 JsHnwkiYs,<4 ֊O)yq# d1ﴵd ,}ԟChd`:L~C=R y͚,;+v,\|߸ٚe7R]qPTR?W<*v~āo9{rIbN)YN֨h|cv?=˵ߞ@Q4& BX* Q YSDFrM$AiŚt2J5&K>:i:jQ׊9 LoĔ!̢=!FW/тJD~rrɔ< )EmAlup`̜Iu&wLPe'3zRҹFaYv">h_$q{@ЍQ9zd],0.lfnř"ڃuJ9f7V<{hgΟ=렱T~~ Kp[Q\FJV EW,/֥jf vZ qBƣQN iq#vگ_i?>k@!8𗃩jqaVX'=7Z^@`Zǁލ}Isxc8@q}6MSg=N[\u@:nG¬ $N*.e-jht?/r%vN| ߾i(/٭r~59Gr,럼ف-{VcsdKI|'`l,0@oԃΖ+Ր]~2瘃ߧ =6 ZQG1-)q]4հRu3rIJd9WB:ҕbd fP 3ߔO.%͊#=\IKWBZHZG0&q n[҅y%&ߜ:~,ғ0\GuEe܁42"eWDoT0Ė씹X7OXEN}-+Ú@>`d>C'mRO]NIf=^s^ I_>.q_1\b0}RW%5 7FT꫟\Qszcgưt{q6 8E)1,`o*ɥ: tV]:'`KcL@1ϝb';9WL}` c"Q.H13 7)dD͢սȘ_T ܜꥳ;ZAyZlReq-+ ,6I]Ef{3nt Jtr,nk@2 R渣%ȣ} &V)06@.ld{Pٸ9n0>iqok1mz?W~@\lo1o08j3t>BkEh|:lFδN`*P` *djZ9R%+SxaFL\⤳I{-]>piCC=h5iEC"l6:v{&˵fԶ2//@[2&&FL=u7$Ω?D_f,F #)^rHtٮb`Ad16lF y1SiOcEz|s }Ж Tda_qIPmRj@OPMPtdOݘn9n+)$3:A>''ih4%\i0(WQf;F+`j/;iS \"*zJ)zjT覰wyoV?7Ʌc3輡j̘;sh1}r(\- tia/(y!JJ/a@<i5?A $ߨv6ÀqB3>}J\ZH\)wJ?fE1:', < BZvL|zRooE!+9_Y),BHbB"|OY*\T.*u={!?YhaC5 tin5nlŀhn~Mʦ#?Pq (E'U}pMm9 $g4!N@OF䣖~ą(W9C~1nK1uh+C ~Wtv⏵!1B.H%gÊHY]+w~fTgd-wK 0˘4NDɋ@m'7#5v]tLaIU )jtp皴wEX2J||:nj2uWjjM&T0ɐzV=Y#/>|R^\bwgFXgC \O'r X1IȒꪥӋ,N Uq\}CdC"͸$UҀFlTw0 qA}04.!H^Y2A K>C{ߤJ\>ؒLA~QfHn2{39LZQ I|],Q 5DZ؅}q'mD)+Wzv}/ƣخ"FQ15TwQk (JY=-5]AP]4d]. CeW3ƥ P9.#✴FJ|ˀ'C*Eg"_'a 8c/\A2D1+˯+hu4Q-r%(Bd[XGor@'2PeZOB fKXX/OD!gl)՚3b.QiBJʗ+W`KS2 ~_ $x7C/yR\+# !;,KrH)t'UQ=%cnCm(\L1W,ТMXZfJi`R+pݤRh,ϓhN GU Ƚg>[% '!УYgg ݗ^ `Zei Y'Yk^Pd~g=YU VqpXz3b#Y〽 I,h{ӏEo 7*#_=fO5lŒ $EQ/nӁA5Sax Fiq_ }-d&0IP\ Uó ~ǝ,Z} z`^¥[L+ 1=3mw+"ڃcq5⹦R60vL:b1\$}OAU׾ͣpE]U=H1_}mͰѦ}G.m6ONSj*QyG?5 #)lswVݚݝC\$tA#:$JiAs/]P77/xCSo%Q &RoSl[uui|lnϣ®:Ι$sZHQM0Ulrjܐ9>ce$Tx: +@ivD`OX Xi"g{e uh:fHsVojClA(qK}.b6< ؍wI KTZ.C0WK)'Sn0Ϣ٩?us K䟺=d6iҙ;(懭&.3\|7ɧ_4='a8`}* 7{^LiȂq1`)F2 5P`LpY1Ql ?VUYIt{4 WA\7WcೋK_G3s' X<(TDB(ܤ)^}=Ө+UFk; -Ah^,WꝽFQ!߿+9Y5J'LXvuNbt ,Ѝӊ kZ[j$;xxkQW.X4w "ImLn 4]_R/P~u$¾(#"\[;?W'ǎYIR#XdDTG E\A$͗3u?:5.QIݣhзeƐ* z-;Era-K09vH#]]'>)7i3W ,rx?+=wPn/EAQdMC6n7ɮJvFVN \q$Ifg8'=XV)7 3-F@B`4d. k Ben/vy&AX+հX']CSEs_Fx 8)Q* g+jRӴ~97Yk%+Amև44{2-eݨ&}yђOR.=q60SD,נ48A|U T9*joڑm! Ej,Ս@p>H/$:?q?p#,n..Ywu6v2ᦔ9w o$osRBه`o'4WDA=r@(2 ]UGDhkT>QDYPxKQܳNcY#z-nm'jme{b*A n~M`DɌtE#Ґ mE_F@4K&kaɨ *:D>}9GxwсNgM~PcωJH+{otڬ߽Qǭ0uӡhTNA0@s&2,{nC@&^]r]6y6w-ŭvF8еQjR+z?- V:Kȟ?I'|ePqV08}{.a iYfkEjHóJ?p_g=\/u)E"u"U"f_F=k^I(XwqH.{# =ؽ"ICv)e>5zu2v|Olx_4,)w^.SW ҤjiMB06˺O)4)p=dߙZA sԄ5ҵ@Ϥ暏RiS:a=a GyOu_|ː׷7+9D)@Qhc \ вẏ003~@FdL#x|R G>)1YvN,lOk.ILJ7&2٣Ϙ&.{&x2'(,4<`YRzS|ph %:N$lm-E.Y~D2؃.P,ҟMWZA}uS8CƠ%1f.K14z Cέsq&j9\ƾ>  \ MR>k8In=Α/^RTo'5hhLF# ;fybFPX?F٦ȿ ӂUBcᕂx)<YYuA/pg🭧+Kx`ġl OCR̭ѤP!;}xs,e6^צʒ.*N$?~OЁv9xf"OKnC߱^df Q'4!ÆݪO=C+oNpⶢ? YȗdBkfw#Ȱ[+ƀ:b_ARh Wt*P^Ւ`i-gLF*pyE*2(-,J_t2OşOS*?0YU}=lWB}TQ -Ҹ!eh 3ց۶6ԙ}mO%9!H{ 8AiI 7ڎӝzlo H39P0]x~}T’8[+6m SّSdQ&l0㾪%CEDf(~a&SQ':9P S#XZRCI.rݽy$OhmEh~̛_/ ,T/N`Zx(cy]04)_ӷt%уw9'jxV D uM hD ]u TضIH^}8ԠUO3LSКBvfFA}?le˭;|J/'W93p tMmX(^D'1FB`T?sG[r B;N_m'&=tV?l ,yB~4]>:|_FLш:qm%D6wgJj=(!nC2Ofтmc&hWBQ33͢TQ?Gҹ2HE+ԟQ:J*N}y²i |jGIߘ1<K[ho&`JRɛQ(H^|o1Ҍn1czU-~4bN9G7Y M|} ϿeI-yyI p=2E3Kv@acݟT6lU'"6=KU{@ %jE 2f)Pa}ȭd76Vݴ/ `Jb>Uo"o]aqXr?)nľI(mV)z^O#< ^p+xǿqbLWxӲ@suZDީ I-hAL _/}RՎ⃃漎$6a&}?@p搿YDj"+G׻I>;-_~CفvEXeZR;21BthD3 G$Ŕv"Hi,ҕ=9s蚨3iTI}`/~&ue5eXixzT[?"]Da]4Z5 Lz0JA ~v Ze tԠYYQsʣ qu 3S8We "3~zТX%{CI_#>:!Q6y=hY窇8^q)#]+sxǸhdTPH)Z}xEqN/E&<-aL?B ĆOuź[t#OO˽sE<W-|~͜i07u7ýfQ~@83(_>V[Baߒ=ޑ)K],f/s5=]\ę;>!Ӡy~ey" Ns{tLV᭍$U+n-f゜Q ' QK{8ْ F w<"yEG6궨8|tD:n)8GG$$f!޵Jsͼ 18ӢdȰ;H9a#]% 5Fs& H7ډp hLW6k4Na[ƥ_A 쾳sBPM[ZM{S±vH\-W R^K&DMcV%#ѱUHߙ9W||eAzE0PBe"9Mq5A,'&m*^6dGdȫoK]Pu=e>I&HQ&`|K {Ca0wҝw\,4xtD/g=v"I 9]2ן+Zc4{2ˆ {߰!_}A^ίd]ٴQXH {6x2\mX0Z@$1Ja+?T/!w0z"]"LO+JhucTY*,ZpX,Iϩ@#!39܎"=!-_ih/gD`O%Fզb*`hc[㽔_.xŒ9kPVegKkoaI BD}T-3q\Lgφ=g|zOY샴L'“:+O*5h,[s +>gLݿXe>lmHW]qmoQ0XEPET Ynz!Ax\jgWˢ5hdyhᙳsw*bqR:(BVZ^P+ 3,Z.~Eg"1 GǶ?'L5 ߚڕpt#5;#5*)lc=HO*߁cɡ ծOF^ݙ`KS"kP&Z V߭e[9JUf ;3kDʵ0 xҩjsS̵̰t[7VHAz:߼W!N\G/pᱜ(/2_6Qf Fq&R5VNyNkK!8ZߗL 0ɭLX^g2l&ykcʭ~K&eo2նY9ҕc@rOd?"=~Oϫ.9[ c=-\>΋-=0 a \UOw"_KW^æTv??9e3m"x4Yeh&+=b o Z $7˩]L";ÛriD;\XA8Oddo krl)3?=Μ F!CiD%ܡ#+ZQ_bHu7KHٿzKj0ik uMW @q>m <(-nS<. X+gcLB3SV*`5V)9ii]#lT7' ?c;ĪrF'ԭLo4pqUpkʍ$:+92q%3gEލo.lD`Xݒ:c?1Jt/X%> %8#*yVr/A;D^.)}#[4o˛\[@ ͺ.fDdž@O[b:g*K'(%Mа1H13naC m#_); StIy5#Y:7iur16A@C#/:+yOwŽ%r=WVIƧ7ݒ⸵e>̎gqgR:gP%]4JLbW↶fN-$9ڬnm~?}PܗFٞ: u>;n]zg-GvY$"]>>|WL@c_04a9G0Dsl՞ُq~$G^#8'I[UAP6(m,S $%^~](qkbm YXxf_7Q`؆M2B۵ ÷U7K{!g:1̭F于P,߳zfE^8->\2$6z|85MްXŶoG}x)ՙ!y/UOY8i~Ou3•`zKIC=ӇE|tK 5oI؆ IN^pٰo|PS<N.)8I_q`֪W/PN?x? HTtfClWVfШJ^iLaDαOdZ@Qi+uFp "OWme !U/\={n? fO?G&ԇ%2PXK2-[]6%AcbCEbÆEynz&={q~ΥM42 @˪ R*ta«RU eΞH%0f;m8YgŸh\bKWmvsg!!2֡S#$[TOMٗb|ڪi,54Gfd) & YC5LҔ%T<1be]uO ?xXj|,O|zq {ȤSnvT9ѝu@dK qY PTQ8% i Rn0L=< ˆx!pey7YdZ줯gUaU;E '[i[\U/EEzE"@nQ*?NcQp.aҰ Iկnlj𤞿T:M9I ?T.:Ζz3X$ƜrǥKoq,,z r*E} _|].8﹯PjLJ~3YL-{f+}98 Ig0DJ;@ xB=fxÝ [4:諽„ተ$o}yU]Ss)"& rua4Ta4ZUBq}S[S0zg 4ͼZl+xg[ & f'd#2Uɩ"Lé;OֺLUo*[7%VLSg9~>Pc9awҕp\݂vMo<MJE/Vv~ W#5/,ݺ풤?cbՖ Fǹ`Y4/vݝ6 Y#a^9:AW(||zxsR\KDR;&~2%Fdl;"g~ŏl3)rɠqiS!0GğQümI|h-IA;~B4{qvy,Sc_FdTGX^fb%DKo˱G6,=' Q.xXlnrSCoyЭ<3E `q3psBl RAa^g|a|jjUud[%RTC# Y%OKbyӠW7'@%^'"~U劎U1S|$vtλ/:wu%i/[L#ؑ*4xp6=p_\  M a ּΌUCA? }mҷ҈KUď䱝' iUվ?d?}-!,$$n]σ SZ>t;!`7k7H@#н^{Ng./z >4t),IZl?]0ӕ/=Q9K( a(t&W)XRnh1s 5_%lh~5t;Mhy'y; >'6o)O kUGNfʄx_?/ʲG,IgD2Wp-3y;V;3E_uv4z5EU 򎋠qK 1 7;FX]ТtLT1x[MDsų?Rhr[>0 ͶR* hy9λw מKlA `B44}^zl!d2+G9F20K&eM^w&R_eΪ-{(Xz(w,K2L"3:N'j+w{"c=wY02DٕCGՎFs? :_KTajS>0~J'8_hDW,tA^k}ΩɡrmzӰ&oʙgpQ)jYWy.9}QX2w7Wz$cy/U vK l$\:#m*O7+o8f?NcA;D]oL7Չȳyݾf$ytumGޭtq#!c{k73-hG,V^3=$9 .s}죵p=Op0JOZŅ!~J;i-M@5vg2QKܿFhe*gbଢ଼WeMFai1غkϰzIM 쬥hE˴լ{sQü$ύfSw=ʂ%Oz}*%z8z+2jZ׻=LrRx/7fLr37q]ѫ>&8o0>r_usM:.`fi| Co2AB펙ԑD"3}nk~U5/>wN@@!KjN.!D]p86SVmXRdPZbƚhb ^")`x 5'Ԣ8h>GMvuxQI+b|KY4Vʜ`BnIp-IGR.WE7hHho1 k3+Ek)DcB6υb ;`xz@+TM0lrL_q_TTPs+ {f)|~IBI FzfY_zJz繍k7JrGM8uծ(i|%|}2ypwK76@ fdDב~U5Ɉop ("lo`f.lF~i-pPLweq+7E75EҹE[!UnyCSهA>'v^%C7VG\W!֎ǎp]pDx"]Drv<~"-s ~t%91 'lF)8E,g3M İޖE4L+i?B7,m}YD!sp N.k lSs~~(u{8y"o#®f`4{5:2Š 7=?@vqY@.>3(7 @K>vaAi"r.[_|IveLͦAц+ܱ=prolfG2R1>G1^\G35yIVLvt8^^ɘV7>hB~I&ԁEhnƦ_- Ν~X$Q3>~&sj 醁ŻT ړ`5>=q G$Sm>ڏj&&zu?whcEjQM#jZJi/|6f %-/]nPHf#U=/%aH2,,X=ad3^~ߟ>e#lJ;*`| , bQq&x_Ŷ"Gi:%-/x{n)MWO 8_=6fƃQ5YXsƳ0sO8VQju9Hb,(n7]N^V,1R׬"~F!e9~./U g<*Rk'>e /vG@X+^b'> j_cWGIP,VX O($|:+)on` #] M(ߌ1!qH)=27_*/mK_j<B~7oH#j-A Cڱ<Z8TYh>D;@Ɛ^[g܆BXWdo|@-JAT?AJ4k7i+>r{q%RpjKm- }cTٳW]W{U:VNHtODv wg7Rz8_.!}ӥ3}(ua:W^MoK/k=+8Y}ǠWDsAS# p1/dϱsr nwљٝ-0φitA{y(;bb11„0wEɆ՚VA5)1O}(ct,&ǖ {0}J)ˢ,u-yk.[ Z ![NZ<5$]$ƚÑ^d罅jxzzܱq6cO^"NNo;A,[*M`wDoZr]`WD6swpXRZCy+xjSֆI}qFDS֛'G1? " f"sͪyEnC/_IgjE -gQR&@̶9P7MogB(}D'_ %zMcW0/!s,o-^(Y+z3JFj[znXAQ{z?X y S gͮa1o, ʽ響Q޷1L}K+է{RѴW}*JkFGl uAGB6n*I.źV:䩾pv6`@"+2&5r]Yt|@ijՈ,X˶z,:2@5O+x:u1>8 !g]T!IU[7G^4kI4Չndo]e*5?ܲ!epY񞇆ٞQr `@0p:ׄEs+1@R Nb:U:.c IՁc3ڣ}ѪN`E%m ;T`2fU)BVHW,MpXqܑu:"pn a΅&!2mHɯߊó1ip@mAQqv9bow ]}+dS0%%[]v'Y$el"l+s.f<03r+Qy* ;dtE;e|pr)Bs&ۄe2;oSbi9f LʕGvTb'_[K9VMD$!{'fP.m7Ξ $U[VW ,QzكCuW9a u)x'(@v/2M.:C\ zt_.ER@J4ں>XG,_dupZ,斂 pOiP|"XiΠH^ᵞQd,ZW{d#h=bR*rzb@0߱4}8C^p'#(SHN> l4 [V.4<㜒J6 9r\GFL0(#qdW*yScd{OY:8R7p&u{iT0GkxpbrWx&I*׏)Qd, B_SzFͱp\΋g4sU밥J:hAڐ2#&t7ӫXd>yDT}φ; 8+U@$Gie^hJiN,}p)gmW[  rC)xLzfKW“ECpZշhc>ScC gIK+|~e&D:LjΧJVK+|e6i\l2V:ZHjq71t ˔ӖbZo M 7c[Qaita~ hGiaßB&8&6j|9˧A1-GA DC5u.*3/Qn֤ gYoG @o hv|w_ :|0 0uYэɿ&Nf}}@2̦DZ5䕀(ua 0~,-ExZ0h&nwu"+I?'5b #?)Bpz>lZ#SUǂgrf 1qwnKo^CM( jx*ko9-l쮢tY&}0_P6Ħ|۞N^KtOI%{k8;cE}vM3kH[p.Ͳx6Ŧ +c 'F;½4@.,z5g,' 6ϝak[ 'Ɇ+N&5(e&R& σ0gb&ڔ[$]y6 <<(;S*aPE)@3/dgLDF/aP?DU$G^Rl%'մɽ')Mfs Mm_*o> IRD=/[|Y\]";vƶ8t|˜@?\7 bvC=k]Gc~Ѕ$4!64| QN5g%0Y@}`&^g5n)=f?k6:G%QdI(t~['cēg$[GH,Q,lC(@:Ҿ#ۿU&Ouo:7%IU7vb~&4XPsKp{si3ATBX{)ɔ4JC g f/T{4kh~QɄ|K`Rʃ́]eb}DP3o9:ҎLop)1V> %jT {XowEsu?xΙ汩B9uury>!?-Aie\/u$Doԁ\N1,Gf*Q UR8`hj&U g*"=fmdI![ϟNFEkDoV _fvdQTL^wqLY7UK^5?K! 'nf0ѹẉ=EĽk,;w*ܖ[eMY䔵yr)+flt2264@P,XؿGA\= k#}CfEn6]Cl7,6kDpb3BgWRiY|i klA]iiSEÿV^^`rΫFG7 i 71`_G:e.yݩ/o$ı[@WhOדP9i uc3k DR .JZ^DgBCXF0P?"yJXrضK5̴o0iCf-[x6ld)u >6\dỰfNeܿs޼32ffqKkEXP+Q^sb*T[>D3<"m<=(u+Yd`We9]Ӆ>X}.}dOwqKqbHOo;8<ׁnU7_\q_Η ХŭEYTs, iC*Okrj{2AMh{#:X`fI"֙G=e#_ CuXo%)mNDyo=| 6+e*OӞYHCŇ?qe*= Sy{v!_y8* őLZYm>Q{^T1m䒿Gpk)2sRNZF'@gˎ@Ko$N.uecsCeޚlW>Zl|735,$ol6VƷQE']*ȽQ$,DvVt;'[[d$PySqkఌnQϏ֜{{H?hZkyѫ: ~IzQ'ymdF.K↖9=&?sʈ Is3H[Wi0d0 c-bNru#JĠYAu sqv[g muMF#TwX@cEdZi +8e|Ff Dm TAPWVc7R_@+`m$2w#6T ā;krXq@wVZLK%Tb!5%ʉo!2w*p-J:XRd)"IUvF:] !#gXL[ 0ʻS(g3lG8;e[-%.^D3DeRI o-֟j,QI{Rai򑲃Fn NpCWh M%ͤ[T(Z/0YYK*&7Sxe窘._^%w1x _QMt-UKMaxl=۱;+Sn>ޅ? ޕ&ԜҔ@aýaC5@8ꄀqY*, =)f(5lc,FgQ[D/DbUDKaGŎPQ ٝL+s;gc`"W:J>"{kK6 [۸v ULiݚ1BO xNGRD/JA4LK7,@<9a<膾_2oP̞bߝ[8L~=6/p), x=_'B8U:W;wS'$&L5:n`upn ,&ڽɗ$1U%%nhcg"!q蔆^0 }vЊXlmhXKbC3LD^wZkfp6O_֙@Sݢ3IܴK4oVPİ@ +7);`#aO*'XUoeZ'c|*SQ/\Iݜͦgu\@90A3rٝ9z=3o% A3z|LAXQ[q~08qj>B`ZfYQ,¹R(CkŵPQn&@=H ˯%A6Q]xOl@wCAk~+;tk(}$C=_oZSI Tl|^o(Fu9/1e6[!qE\רSZY'ȅrzQ/3g:JV~(fLׅ <_HZgMj_ZdBhQk[:=ׄ'Z_) LTt&_2:L}ؗ9; K [-/k?ФQ210C~۞Od@ r Y]cďR[+"e[\#f#}gڽ6wj߸/Nѹ2: 7.,iIaSswGdN. \*av%= rab{l;gљRv4g1 ZLB]P3-Jv@ g_k*/A$5M*n1WKewE@-@bYϟ(f Y\WP\Hw]ãQ6BIE/ &2ވ )y@WZ@~3 *E9QsM@ipeu9Fv֋ׯA1:~ctJ{s+v oS m ' =AF?1hYբlBIª-X҈496JGUTBr ]'owLJ!ҒI@ #7wRg2!΀sTg-1,*MjnIDXS))fp8=61{`.jꃨٳZ>O5]_.;žxLk {aQ@nk^M(#!oT-enXIK=z, U<Ĭ ѩГB]E:kv8KܹbΞ·h;8̉c:) I }Ę5oTCa 6o5I r?qx@ә&Ru4khXٙZ{T]59 E)An#]Ds)L% 5<)~lb\@ٺ&D׿X瘎_rt=Vx,PC.*a?#?T8|`e ںW֘F_%3D Q &S|%J^瑥x1h24K%šB<躥8Hfy6 X"4; @L';Y}x**ܴ* y!;0?tň*1a~eYqĺ wJY$x loRʎFj~S'XAB6  b|3)6z*ݹOX@i崨lMS8Kf[Gtz4*~2U#s|jxhdC/Mׁ~}(7;1[/^C8ϔ_?\V˸σCCZy ϠY%k.yꪾOiX\*zpW$h iž@…. \:HZ6V_o]PC"!كZ3йL^E~j3p) )z!?NPgjh0ix`үԨAcI"w<:? \&MeN쩗j7/9J_ylœj;R'뷦s,pz2?H8(ZS#GJJsRr|^ xF65pTBn0>8\I۶^C*N,sK;+2AZ(|901 :wT,A Q/1&1yvW$x+kHCdS-O*~Ea~q#⹞ a[M{"lm$1Rog*{~D1xD銪Ĩݐ{zmަvqP\ŭ> 쐫C*d޵ ~\u?f/:F|9AYWP40L;lSӾ`$vD㥤,i"(CV.[m>S1@BA1ޜWz2hS~XM?FsT(Za^ `($ǩC7R‰9TrQ_8?&%ى%餮aI8L'x 0JLEfj( 'gouA2%VJaG'LZ3}>wAJl `Õ2/,+>k`1_E wM'} (h R: W|{lzf񅴚j]p}tůCu͉b+[Yޗ&j9\o3qi&U'.bjOK+u>|#K^)ʕze-[Z7n_Z{W0V((~Iy^ֱH >W -fdi ?)-ϳ2> 89{M̧x~nO&aQ5[w|b1CoȡY?3-ч ߜT4T)%S&8 r2)Gv gDFnD `KH6Td̛=zzu+T0't~4ҝpr'%Hf=1a4=%N)cVX2AY_i OH̗;5J(:C@ŨHA2ڇ3_/!#)^^!޾&ZL LDt361QggC0Ru>᪗kV^Y*rOo, \$3'6gh~ ~&6nUw "bX RKR~:2z/. #x>$&-89- hCz`+W#WPIcV r:.]TgJ91l)E._K)x߀cיPUߑ=B31A/yD ̊ٵo /GoҶ;`hFɼqd(!"Zp=ѲP]+C&F}R]8Y#"{e0: ڐёa BIC߼2m(o:8 yAqҘGsg9eҌC. 0S4̋XP:`^ IǢj2d;<23l"<|~f1{I1s/3DWf|{԰ʔ Tkl D=)MpNvM~3N`Zh;O#zBÒɉ 6BvTgD~j Y/V#0`%QGP*Nx?ӰHC@}2s`/ښӕ*.OjO)T0WoG҆='MTd2~|&;xĝBUx+)^Bb p1 hNH^אdQC-0ы|?a5v']3I _V  JɅ"_"͈_s^$<\ ad1<ݾ;J9F!OyOvfOJ.HNqoi ,^e NY!WJjjwXV y?DȚZCjKQ20ڑG׆k/WjrǬ_Z[T&m/"y-H9pSE ~x(Eoj;[ew `-m2:z*klsֹUyR~ŹHD0"Xh?I U{lQRٕ 8|1VպG!C{Loէ$.ܹy GѶ }l f>* [\1l?AכDf@JAͲ׀*d'9J㽺`N$Kg5FKAuAl9߅T[IJ, WT|d˔͚J}!17e>2 )@ӧkU_ 'bgURJ _&6-* cIj>ȍ/23k Φ ]޷~-,xCD W[n]ɣ? l-. ̙K27 u#F:#s^֛WdOt$~X=h6R /X܏ yF4ӷ{ie18we|xUCeWJw83gy~A\G\~=Яm nYeGFF1c'I-M3in?o wi .,1]UMږ3Ԓd9LA(c\Fľne33?PwAjp)m KE9͔jxG]KSޛ)Y˭$%7z6DZ"Xc5#2#O>ĽLN>E𹤈nqu,^#6W*sq{úbg9^ u.җFԒs2TaAƖ!QI9U'AHBl>b[uFb^)F tېa2ɖj]% cjkF6%"lu;EثY6xiIjg,~MgZ'OK~TYI۩g,Z1nUp~q\Nmqwc;.^gM }UFCaL; _-쨬]_mk}<3?V:8g& ajk1aCIW^u#3"ҭ(ŨZܦ*"OX'p+NTv9B W_96V4<##'%*Tc:p#x;D{KnUbwwlc̵K;ټ9oFu9Vj>g>+HDOh{Vexn-˶Xq0`ƭEUPYL%f%3'zh(񻏈^|9>-3 >(M&^ZM5]fQVtq+ɽIgm$rYb16pSKT͙ظxIOx C2O{ M3ovNubŖ H,Zz"a[o7a =8q Gy.SE|W+\\zHKp3ZVu~wP%ܪ@:8mқ/)?S(| b0}ֿse*=\rRyJՁ>a~rf<m?ZGmwW{vD:s$)Rb@SGǭ-PsRNpգYIE-Nh-nЙc7>G[[C%ȹRL7`5M \5|GD<0[!O1*^8;r6NukC_K ,%zٛW YN) ő's]ֲJ: gCCփ8/v\=[!ĝo@`؞yU}B٪}SzNU&%ދFu_\OAoE?ByI,v)-`4,Аn]uZ8aGؤD @V4krǏ7E4N6k1f̂4I2sq@mcD$?܄էy  K5ޚ XKӠLi%gs,.*~.Ff(Krlic l j͔;51m_-FCVp^FGI=%C]7dN.ɾ&S-l!ʩs:]!=Нs6<3 Q}͸S`麶\u".yp1~>!;18/]|\ny]e_zTqv@V ǾXeMLa0ԫhEX(g2фT͍OyqQukD{.@JKb}\o */JXq.̂X`ax/O< ~ >pϮlD7Zg[gm~*JFX#h!yHt ;Ac(Qyt0g%k`EW0ć"y篬aw l:+P`NƩͭ^n1a9Bػ롻?qy9ݦ.pRӹOaP?6?+#"9 X;qqہz$~q0 S녹%E) [GӤ~X}EČ Vꕦиx< `|dwq4t_4M=}-<m$#H/hz:U{rG0VWj/ɤ:>-5gdCO=f} ij|2d(mREcҠCßD eÙlIjCPl'%6jƛރT"d-] AnWA7h>|PB5GnQWߟL`Z]l36c-8jY&k7!i6guh='a*yP7:jHW4\)珂ERX^U$t'Ria|ua)qQĨQ6Df]cj$X+  .G7%"PK3I쭀L#,LFo"HFWLn #m1)=h(ԃEK^Aα-$h,QPIcfrMp"ߗUg#f$^B7x W(j>pkI4O#&P'OX̕]&OvY*zeoiӚMmp([N> ɴz3Jt0xR*|\kQ!aY՝ryg #(/ ܌:kZ_:ȞrzqR+Sx5U`jؑrVl923sbO%qE=IH0Ϲni-HS)CDu6EKSI i;K}fd:.Ͼ$=_#mii! g$.&kAт6|sW5]00nv }2Xlϯw*"Pk2( 8  z߽i @tϠ@!-"eva-TMy/[/[5hızw@4t]"d#9!u;z(c gM On%̧y>9uR-B̐3F[<70BZUIqy!34tθ~͡cٷQ \8(drC{%dG`3L(j@_FpCz1@@^wt1vʣt5D?{KW$mcǻ22қqP,, dN14P0qڷG Z/I/zs৊ڤ1_m\%2YdD88pppK'lG5@ /29u8i>QCƕ[ߎ,$ Z6wHT*WPP@T νW٫;k?5YRNq kL D<k=W>=iǓN!cHwhWfއ5h[s{PT%h)= ;nմiLD<FVq>Sxo}eN.<ɬZ|kF# LKW/X}cKtBL) ugn0y®HqQ]jJWus?Ղ QBr _w+kޟ)dZ˂QnUY;O U<ӈ=Y1zqpwIt :.+hC0s뛥2vǡMli]qJ6Ȧ\l |7vZ\Q2Eq  u)pMyp4+k/@` Y>Xփb*/.h,=9t$*pax[r_:-Z1Pl IJ{rN8D.BlZ9q &b=_fa&nK-a%[O)/&3ҸETKsWK6!]$i2n7/i%Br.TfPIj`inNkjB!pIʖZ}e}88|o͓-iΤޝ1*=\ʓOh ˈ^p!+LHհ kur[\J0=%%p,jU@4~?u8-3N˂w}NH:" W(~:yi+QUYUXOd$lp73I>mx+_\V6`n'\y5QwV!+ 6 [zm ڤ#.@A0 湮f/15Vz[kmė]H-K竖7q,/)CxTV=Wfp2P :(uư/Rl1x^뱊3oԵ>OC .6|˺uWh鿻|,TIZbLmNLwBB\Ux%Mz S͆@@T"Af+2*XY$5(H]_oyR Q&TB(JApb9OQkjSSJo%,y!4+} iǬe2@UR,xouUs<@v? &3STq“ިǵ!muaM2׽,q %`ʹl0MAdjѓ sD|D>ϻxWJ p9^ZV-2%kȡ|nӖp[lqVdB:ĵ):0@&gCrK-d%Z LTu6K\- 0, rG) ïx\%P'F㹧dL8BoERC`å+2m=Z9p ]ɋYx#1cN$lrk>Q.%u%#w_:G>`I!jd$fi"aB%Z*)\Ƿ4ZsC~YC>V3o~={U {xUxְHKgngU,^bvub&&+$ν#M&V"N4,ԁbcv@~벝92X4h]Rș7 L,t6ϙrC.dta5i tT22zĸHisM ˝j3V?Cn-Y@UB;[2 SeC"|Vv2isZxii(u6|7AI} G F iQDlƫ\N6И G@v9(rY-z=}>a%ѕ-ouuI<"tO4AӦ7*` 50" Jiov Kϯ£uPׯ,"[eP)\@L Gԋ6lQjB>H'ӣ%QewwzFg8 8- O -lH!8͘fqv!ej{G_Xv("˹  vxDhސU$E\grhgrE^Gyp@t-qǥh886ͳ*"ŵ#wF!3r/ AӶ%hdLshW49=n.4zڇ9z*T"H0Q7.ڮ8ϥzrI L¨! =@`ç8mJIyR蝧UmI sle )[T z*Ү;s>~n3@nR~yS5hAm@1[_O(_lX"ȩӋ <[ԭ'UoU@U==sab.UCnIH{<|^\±P1zReo4 WsP=۞|_BR]&@U'\(sgV2JdWp?K 9=_7^:p 0)7/jBTBo:y>Wxd8j VU9#ggxX Wn^XQMCٶXפ=ْ *ϖXTVƯZv|*"W~? \MW^qSt¹.'*E]Sٵu2ܵXĩ u_1 #9=<$ZRj߉>) Gr0qlF܎QbXh$ƄnYw }YƩ ('RfT [6?]Jg=~fkD&W>/8@CE,iMl*Anh rՎ|o{1!dfK*z絠\9jnBLNc lZsrFpizBI][7֤ǵDbdhb&E2W~E[tW^<8k%#tހԔzKa8BcD[@-s˂U,uFFKpE&jN87lLIda`(LilirĆ=v3\Sx#{YYwXVhp#*X:r+U`,ԗI5^q]RBؕhMci7~{c9"4ݨbJsEޞJJeIzB>S') Ɖ[& (b*"ﳓ\aALZ[]A| ;SQWN6#ANU D(3vxvXn_ܙlv~AYB 'ܒ%j-zx T8j]cٻ&.($ >Ys"C ;IAʦ3cT֧݃>e%''NS?ӌ0GR%fT'=.qb/({n2O]ETӴ).el8+ {)0pVt=+9p^S+m q_C[@#~rM@r=j#c nҘY0@vatOf e" r׬hyc.?)T/<>p魘(m|RZ.Z2η\Z6aPY+{vL]mC X=xT=ݚB2{f~L?}ї ߛ]VAbr }i t}F5ɇLL0DllKZq?T?bj<丄x$bW:H%u=ixu7H{rgIOٯWt -i8X$Cbrqҩ kB }W3ZWD(뿢C>2$iGI}p糀Z PID0Z~ͼ6B^AȤj( %?˙ 4&H.>kIFSwz&qh{ ^Vn7'4)7s| \-OBj.ml:S1٦ßc`?J4+L'>2_ӎVaӈYo=O; h`?Ĩ̤.'olXd5+jy98OT!Bd"4kO$`?CZFjr l|8<#DπV15@X6=$oά *NPyx0׸'7b.ӄo0l'}fKOP/7vC#ݤO v$'Q_⨮!+4eupOY]0H.dӼFHxG[:*iW՟tH+ Ni:0 +m n8ms_ͅu+C`ח%zbdK8KrOͬQ`}fi}Rv *XUb} h \L cd NX4PV&N`w2e&e|-4<{Qcvփ#4m"T.NwԍWcK!Aa{cbMW_Pfn+Mr\񽈫(}4V3|^T@ry E̷}mYpи܀z~u#c+$ vd#&mY_YÈbH% jb4 T\bn|LZX()0~˒.>)}vLi0WA1\dʵZ&#6pR |jDc !=23DԩJy9J9X2 l"VX7LAl0L>_ݠN`h;>isNKh.ԝT?s!{l.wD mJ5:9Aڤ]6Y!utVsţᔸsA4v39^ ~I=n} DK1kmbmdžs^\Q6S20}S ߽!K6*1=b0X13f95'OE ]r*/~4!Ls.=fb90rughu{%'*{3h4"vH1>}Rx~T',)pq?PaUSP!1y ãd;gP#9ܷ?4·ЀyZ%S3ij}S_]5o )PmyϺt8f%ł 1N"QөPX;YH*˛]M^ɉtfZ@aGk-h淴qDzaKPz?)| P'}/MKS^:qw#e@7]5W':!Mҥƴ^+ ۦVŲ>Q\o"O&Fzg_b%S<UZٖ·iݍGT᜺t3³/S#߄^5,,t;YKڑx0vW:}Q'tu^j!,gsN (w҅{ [ZH pwiV{=J{޴&=Mɫ >Nj"O.$[4:Ͽ;PJ1ziƇi&ⶬw` fpjFjQ5NIn^g3/9)W^Aȋ28$122T9|cƦ cyjd$}߁h. ⪆(9RSbbM)[_$U@BU)qL8r%Itjq(Qt P+KVw0&;DYL-"}b؍ֹhޚ#N>`T@K%fh#Dh [&K!8Trj)+$bonA(RWKoRC(HM@WŹS^cAe\Ômw3ӕU^w} UJDxnU, lzHĈD.UQ`gY*.Tub>jH>jydQ$̻[{:w֬i8"Xm($/T@0IlR0vHX7l(GK.ȋU꺳@~yr|Q~~~.w 5n,kjJ|2Rl4EVMk:lqCbZ2ֺ!yQ1UE_Cu|A`s+.01L;f&kh2O&k" 5,zP>d>-[Kx={>!ηwn?>NHh=#v4j K#le,tcZn Dݗ`xo)A>ڌE]ߩA$<{lKTlw(;4abHҺhO@Yj 90r6}̦Kd0O1^KdT-_'A1ՠނڵt%(vIQP1뼹$~P|G )%rZY D?nRhZB{PKrEc)<;GmdeFR3DJCPAHY]λ;AݗZ.596J*kW2ql5H2TrʲGEMtF`$ oLӌ-7ZvhbX^!X-$s-6i'&ۛ}b`w}.'S`r2N?D-dij<:dY`=_ +| ZMK7:HMOv9TB~J+, vbQ!PZ޼|Q`JE?a'Kr5;<𑆰u`JQjYL%T9lM瘞t_t:ZT+\E5.(ݭbNwf&bLs>e7SIYV/0?GW,?(X?|6!7eDRD>~G']OW7C`y#:=X|#6ϚXIbD'Z"zɡij߅(.t޻x2)OA IDW iĐy`I^m{N'wTݦ%c ޘYL=ߖޱtP A4ls4ފ8ՏSYOKm͡xUFMF~qa\1b3,Ҍ7t3( m q\WhAUށQxAOA5C3p!F |Q`@{&h 齛9-Egy%ˈ0cN]k{~LdP-xty#5D{q=T ;\IoDɬF! *ڏc]%(.OՔ$%(FD $^egB߬'jq"Cd݇b7]5ǧisIn@cbfwҼekvV>"f͗VGU!jO?8~v2泬G1w$(\x#$GL.EygMU6rK8> ͻw+qƪ^v{W0Ýn([20.3m#i5QQ_7pMFٕB/@O=+`v= 8 4q-:Fi($Pz EV-9W+i֦hwuUIN,u LBW-] *Ί۲Նx_v8C;ZUWx#Mm>}͘R@!68wf^m\˜9UZꕫW^HRN6D`T]bAx|XGjhMNFG&BE|d "fE) `롙kZ]>QfP񄩪sw$)T'b׼!J4Z_^(:QGQu ]}MciIF HVIn(3z'f y5,~GEsqW+nQ97% h{UEݝ:)X$m%-|@ ko讣XygPDڦExY hW[oFԅ*\Y-W8ۈ7]"#]W<"y`җ P=2;C:@wq=G,=EGuc';U,X{ʜC &,3%A !.O_Y@'Q,"4雞Nw @U].id0HtՍ[scجHp[vk#lC_Gǖ2X94[ԃP^jrDȇVs[O ZM֚pikzdֵ}'bFX'?^,@'T =MX*cJo dmd:YU4LvQ孾ڿ5_[oy1vwM|Cg"|(-&}-iB'0v#fJ0Q>uft|i7ȥpb!t@S|,uTph[W؅(_ח/ٝE%++pS2힋^˹{* rLPb ;GQ~N D&c~3pzc.JzRT9| ,MMMpNbX")K;_s=-^qZnV+gu s7L1p~![ļXrc]9O\NӇi4:T=gأtesaQңIiy;,2ވц5iOtEcѸ|=X,u-\7BEm.xP*ܛ?H#7-bT= `b? $$DSb iB ++y/KHJ@{̩i8WjJ\پFhW׉7e XBk(달{ .M}rq۷CŁ5ik o2)6 hX ESQ `ώ7f3&o(ch`|[mm06وԪLǡݻy h?"#m7+n$!kÄ3xoGA۳P-glEz岧 F"KOKcר( 苇wLqL-(=r%giÎr%: 0d; 'FtS$S?`ٱB+1gpRwbTPMȜ-iI'Դ#i^6*ZDDvrE8|AWL2it Q/, c5 4xhI^7%&I !:aAv*k1^է5ePMar*<7hڳ[$CJZ6}Rts94I2MuaM< `('[{3;W(<4^ ?Ȼ;uY6D}0%ZS?s'(U+w|P kAȂjP˪Tq9{| zMۋf5;*Nn CHw1fx9,# ˉʕQ`;Yg̗q z' wS_4aDHC+\meA8O?}`ϕtєCGgj#OƳ hhECP[Pa6t+5d{^mi:03T0'˜j 4Ck.O3m܍I\+wxAvg0=h+[tPK$8m\@3ظ5 6\>t-Uʚ|ƲnM*8L {Յ#EDCeB,Y a oΕjkeo HFQX F5DiSFǂZu +A|?N[ jd)QCH[#g}VS螺z3YØ16/@f3 +4J} S"ӧ"VxF vMBV)AH]Ӛv YIv {!WD?7pyU0 "t@T@$;fQE#s 3?-64w%7֋Fm䩕jhHo{):MFoYּE_Yr3(> |l;/J_hmԀ*4U#Vn:+|$y!%&٥sKVcR ,l) JCum˫XyRpn/ĝ}mⳂqI8? ]VU:x ܧ·G$D؏Z1z.352q^b1j`i '褺lN,ۻDvwihX=t)i%s^,pGHO)L,n%e܎86ʂ8Zq$]JZ0o_,E,eA#bpA&/r'GŤ {+zq·Ifglv+yRTcŬ$E2 hSc{b7ck\Ә'5e&. la ;̏װZƃ㭻\ZeTafC$1.CMbۦW'!xNC7,o3MlũFمJSIlKY8bu@qh*qK H9RN!ݷuKX[n6Dc\yE3|o G'̪aV;<]oKQR0'<>jH͢V]juc"hA5Ula8}Ѥe&g)/R)޿>oi ՇzEFqZ຺yZIJɀ @8U{f5㝲Vabg:Y>_>wPǙƲ?$[{p~DŽ+A `P~ L3(j :2k8qЏкAMA#*;2E4)~>de߷'W`{Oi٠ Ww`$Y*1M ~&U-~dTEG' \%~] Q]#߻o;6=M2AJ{Mz\))Aj;<]xW{"¿Tn983\h ;tP<2y|03u Sm 1JK-ȁNN׾t)ow),qt_ai-{q`-H~d }X?L>L0<< 9evs=\Q ^m6(:0=c=L$[wʑtum@(/6tи_T[{Z5jKO4)IwMH q42r',z@ 9@ '+5=:hin@^Ot^oÎ{]ON ?/h]gD,\y[q3.pe._%c7JEc.}t9}+&RJ'4ryJoԸ$pXtQ1".n8CP=O/H5 Xhbqׯ>:sGf0|8q{?G״[NĊoT)XKop{1J,0m4ad}3պ_Q͸Ep3$I^tXЅ;&\M}kw5:@ǝI_Dj*M t5g;S{_X; Z <}|SL$Ai zdגh@@0PLvYP%> 5McԖF72xKw0]"_R]8 2S7,,P7)~Cfتmr82M/{KXu l& *}Yo~ #i+^F2J n\LSgV Rq-͝R.!vC-tY3könj a?d VÜԈ2&.ƛu{\[ĉ٦ gdOs̃Rܮ0&@y]fk"Ģ}А BPt7!W^˚}B>Hp\+eYiu7X%U7òL`_saga-.VΖE[X!+Ej둑]0~yyr^Z2qs !`I` ڄYs,N].?Y9!|9&K|I7 =ꗒt/,6_Jbeg,H[TE֜k12ku mV~GH8f[⏜hrTڳg -ݮ5~K w^ gzR+>Zfs*`*pv$Ϥ>C'h>]Y-ې8J!tx![2/)m0Febxwį?R͸&f4KAqLC3"bo6v.'7Hgm G&jJt(ӑ]lסkڞ:YBFH-_XSC1K3* 3\@|i=?jнؖa1d(I ]υ?!D7Y©:ɰfB-kWӝ2 c/mԲnP%Tng"YfBFl}PػkFr1쵿 .fz:΀]z}۩wOI[ˍ6ztXXIwh>ć#b;oQ#ϛai6Lu'XROKIY,En4g޵f{?\7qDn㑬5]^ɐU8R6cn̥sU~E[!ܔOVu ٨8KBaTTBp`X~ƟUx%"{3$?;xT᧞|ܻ RV U:mglDlӴT哘مk}p6 ϯ2/J(dkTCg#8ks݌}Ty&[/;l.i4fyʂoӇC&I~8>&z~Sûi&TA0OL¨HHl|_<b=š;3Qm#=0Cx;=Hq6k 'y% A5)V f}L"xA?ÁH|AS-y(FTq!Yx2SZCHE![ 忈03~_ǎ.8 3 ]lUNt;ƒf:3߷S#c A7)iBL5~7TQ5:t\dH* p~r\Qu,)UMQK`Co !\sSu.WiQs8$@frnX&˾pTNm.~ t 6?(QȔ]E$$GҰWw5='[9VRϗaOָ^A x,9o* j >N(޽%2J&j>Ҁm:sq*b#.AL~׉({`'xEGmĜPW6ڡ2\z* âo VJj<(}՞sߨzݒՈ"%8#/Cd(˞Dz-?L-G)q-(=F76*碯Zs}p, 3S}&e:\`8e ~p}i?H|PG!Ң/Q0l@@&-6wv%/x]Y=hr=|3Hq±"Z , )? +$SH@,%))oC`V=]*-f!Ib&a#739^r2OsU%h6_ o,BhT ĊJ1` SU{'jǬ`XtMZq5~(t;} q Ֆ?;D:i_ P5lqɠ.Qz $NkNJjY)5WM20}= jn-Gϫm;"ɟiT>* Y*YNwFm)q9%%)` U:UAa*/4OIUwjQAjsfoҴl`^O#i LXl BqޟA@ ż6@m+>}`ԂAwnbcjD벦n v?VlytC2VUbZݳ5EZh&灦wB7k5["OA/Y p߄iG7neB{/ځ i^};tM$ gإoΓ˟Dzq}kzDC\CQA_l ۭ hZ~{|/p(Bs)UU!Z}ܒAHiQxΚ{ou(^.RUEUȼA7/'*&|h(VdT?K%>-&*4#1SYT3qbn)Zfs̏ ?n@~UL(vR>B1GǼ#\UG###*s#K#tzګu pv#daJ(t4 BZώu2<#@Nk=R*؎}*e. rBU RYF5Aji]`oìY1JKp}=AyE>SOfY\c̴fG(6 4[U`EKCdKnl9@*[]BU=4? D}q I24! -IuIb]Lec&/0ޒG^hMQ].ޮz"G!ƀXRETՑ9Pojd*%{aGK#` c$|MRޱ)iaXS[neNP`ܤ(]GxqMc֟\Aw/$)Z~};{~qq**{bF 2}0Z j:U'bݠ!!?*}ﱏb mOf$ٹt71A԰T: S%I*ApZx*X|) `trTHF]xc݁>t }_~6ZAk۩lA3f~{qt W~0ieϕ߸>ŒVtY[)x&e@oU / .Yj;ᕁ]z:f6? k)LJ2aS ("š}3|tXm BԡP8[,뫞L@2WThP+D{4uˀ:9)H sRYoQσO(@ jn@iiw7w/LH8Z[oF>g1/;qeVO;!&&ިޖuO M P8=gJb:ϥRFF,曵dp<ƪ~.frgzǂ\^v ~c{K"^L^BEU>1bњE .u DbJfI85*'Eg[U0A(̄I b[K/sn7#)LX;=j-#?o/ Hvd)5'Qڤr:3R6QN*HM(?pZz.4C4ZTfIv'r<~νjtL$BC!qŹ ;㿅0ڠQHuDȮV/˝K^g HyCZe=e(엁/&{lrCf2Vb%,/v^N>ӕi*3s85mX8qnqa@@wgJ`8JcK RUNS;uq\"WtAFfj"6]\ͥ .$+ҥ,nׅ_j CY; Zی_`PD[y6[DH2!Lr_SE]1uKQ X˯ 7ίtGUYY  qAjo蓣A/$ŀY_I7wZ6f[qc(ZϛaVASHgNXE`+uIǯ٢HKo$ < >ǫ (6-}8MMt M-e!k.HNɆ;[#։wBdiGQeZ-9FrHh2 *&-tL `k +Ik=e іoi1E=yƙ*Ǐo:)/=YQF s/8pϔ4dq,""ֶ>p#OXWu FŇG:iRzCiT K=1ą&XGVE $ +~qGE}+9W`j2I42 I„Ŕa$_Ϥc]uHt$[(|j6[?]/Pϒ$a?Hjv=dHl>ya W2L=ԜW,i/BO9g.?yƄSo#^`M^] EI:**){ Rʌhf0+h|t|z~90=W(o p|T";)Ϋ{chjpO6lpaviqwJ:ܷB소߯2nz/yn0g tl2^rQAݪk T )Z#ڻu}^ௐ-8_,Cε!`W_y<'xvQ ⣌8F|+E2Ac :Hkbr "Y}#%?D:H߸:0 +֟XR>%N G''g $jh$]uZCc˵-Y."`HfA,U>P0bhBK$ u CW#'YTMtj#̀%(ȶ^z~Q2:kR^ZN2Y<H-[#<ڀ1R5!-I{,YB-X߽ț='ʹ`CA'`dH %ipEG1CKJ=IiQPEu{_z !ǔΨ>إ.'XU2=tV %Lg!:#x)9l {"-1V΋!' s/gK=߷G'M9!mkŸe2+PJi#[Rv5KD^b)Qқ!04 'vʑt!g}0:;U*(jݣVtLQǘ я< ~F]i &V)m5)ߖV뙁JO7cJм%/z+$Z;!^BR/Wwpb`2u1k'-EY~5A>8<ܹ"[x`FJ؉ʹA#Wq\~E}CSl7W5nkY )rNaCK!}gǠSSiÝgX< eΓ9wyOasw;(@Y}$XG]A.ӎ|\K&JC[MVCDJ*o+$ځ\Q m.G֥ݞ=q@`DW%+77.Nhµg0,.~ӷj𙃠C3}czv!9w38b )9$g~f:ǜıկ(#Fp_auW9!G;:(UqrJkBρy:OOA7u(y>҆ 9rR39o]jd=?َ$>FzӌN02h0K.Y֨Ev;H;PhyxiCoֹτ5Ryjh %,;{locMl ]Z%æ7G_?`]hG! W[XP!HxȭO0FޅbR]SG6Ka dUV9JC 훳707V4on pr7]`$u*T;5\ڔP3+151H, O֦b7j3:uO>xzݠ >WSmWXi49%zmQW:HrQ֏\P KԜXjL5pRw,M+UbIZr-3տ&S,A~dz2G}Typ̂;^*oB7m\~t^5P2Q7x Xyk:L}R<9IY)~n:J:f=)X h|9ˉ0 H|nE\ym$ #`SH!Ñ&PIylR7Wf 3hOnY56`n$g@{~r}UIbS1 {XϠ=Zw\tR]=OXIF==vdA4ġsʴmsR* #wlն۟_Uw~\A*+0 f/wɕ$H:썰37\CTɛ 0+Rxp(Jlh[BӺ{Z9,>g@6DC3bNB &_Ȃ`\sD[eSOyTTUv&ϷlusWP192DZ|~߄uXJ`ÿك }  ߭ OF(Bq QZwUœ\FxտxL&W<ڈ!dqtBAtaSt+Rv760NY5YQ{8 -#`YӀ3.z#U6~46wlw <-^#Vx;J\3lSInNlJp6!Wf^I,(f&ӷq}/R +G⼽Ts|im5[2᱑wk4\QڮSsDO3-`TDReR!`_utk;u Rg;f|[%m`碴*V`҇Fa's ZȦ]U@Ƶɐ|e[Jf;I/H9!x"YHё(?ԥ1{Q?[iΏmXSd̮ רco߾OABKPzRH۔uT2lc}Fqw'כbJ=**u8U¸ 0sq$38>ƥ?z5t$vFK"r'#OouƳO 'WK 7/ڙ&eH,P.&J5 r㸙)d{?ʻ o%yuؖ*Y>wfy}Cl3XrI+pO`'l>zƼTY>-n!%*ܵxoy@d<k^[o*W}cj nWbz Ǯ6*O,Nڟ./t,[Ռf ^HYo0fca2Xy\|;B%Se:a`Je9Qy$j?!\9,|@a}$Ѭz1ygw@?-;ts .%g" _[<ހJ?]꼳nѩ<M,RAl}H66?~#""ա ­< Q*a6 n"W?W3jU+߱"šgw}ϕA>_:m[>a Zu?oΎ<\jXkmL6k#Sm}l}O8Ԅ`&anAT=ZP`JT:"04Fb'RZr7hg%uN=w'?ǩχ͟u.MJLԽwz?ر1^rNݤ>7@X8 ( +^&BhO6|]Q4&Ux igƞ %nzbyxqɊĊ1OUN#u x8?;ա>^-TV_3h^BBU._ϢW~ :BAR'|{YY Gcz|~ O=@**FkG:yFG0/> #Yc,cvQn0`ՍӻlF7* $z>ªWJKY@[fE&3p-1c@IW<)n?D]"E_cS6B K0+o(*%1n\UE')[ VOנ$G?fs,!`'[tRe7o<#oN3@x68ˉ7uHNYIXVtz)G~8 S`ܑ .oI8mꡲw4q=' >'V,Ӽʄc!4=k9ג5K8ƫ5dyqvY=-Sc*=ԇps+z2O&)֒ŊC7]A>-V#śYw~ x i!$mŝIPzv8O@*{r<Qp,0˲YɫSacQ~ ͵:@4p#r󄍝t!H॰d`^0@3j %4B>Zo<nTc6DjY*YPH@>meAxRS{};g*Gcדt +:M ל4!c}!wFp4*7Ù6wN)΃5 fٻXDF%{Mq>ɠJV W2@x3O"֣ *Uhq_=?]nG[rh`,ޣq'ʇ|1Ur h=# $_w$aվhl4Z Ρeg_tv0 u= [@Qr ];4\muHa{qY`K p2ibL؆p0ZO+|d7+?tz<]@sGJD—[40 Q<2|*!S If N6$O0/O.CyDM9DT سuY8T?QFQ~SrpHQ)Ʋm]ó >B,lOY?Α|-d>@Y*vE/OmjmZ8ٵUْ0DN8Vc# zgaT z Rddx@_u.w8 dvd\.ZL⟻+VTt>%.gg/OiFD?Z$M^n(9ƒUqkT:٨,q 0ЭZVA[Rql"xcf3H>3qvD+t, ;8>eGȕgd0O &b1|3޼ȕxie_ܿ:W&Og'S/$d#MV]𾐘6Ed욨H)9zk~JAWWM!4L—Mo 2//EQBΜnny<.mP6=Ҳ<ݤf-]D7-2MLĂѶ 2ݦgXbq.!f2ٛ|[k2=rB\SJ[d@8;lp!m|͎'9hL.}ӾDZxLw*TL ;?C&1UV.tpiz8 4W;3ڿ0 rWHmoCWL}\ٱяVxrMЙ~UwA ^[łͪ'9 r[R? zչe$=1裞Bo.V#s 䔣2Bҁei ȶ ! k$!?TD7Opb 2U-D )+&~oA¿$ Zտ֝fm:cTS ' ᰒL$ar|xw4%p,#w{FyQp 6k*;4^Ж{&SDĎ S_ )^vD=&ƕ J9jSvQ lYw#9ؒ_nu H sch=hdJŞ.:"p:L2 D&tXxW 9`Zq :uξ洴A+)Vo->̽.=UJ!V$L=6p@iC'7]뇵sKzoOmhNU^\G.Io7et`B&&96Шw:,~&yΫ'8@/3?=%c8NKudE#\iOsu~ cՓA3i؍쀫Ҳr(4ZeS^7pPz{Wol a+hJ%LԠ217dfX6*;oU8iZ&ʂÌa ,sF11$~,*h|--fPLq;1(k q*3SpcLx"zwvs8]SUjs K;a6ͮ_b'iC,хyP4"v T/5uTI&=!O1TZkRk$y8VV moŞf#fp ӄJ}{k:ʈoҋP\L+VR lvCs@=1.7dH?VGnKK~U\FRY(?&QH l}][RѼx6>nTҐA6r[Iпc*RSˉf3ˋvLR D HRie0ϙ_-fYt!*APkCM}`(JWvɉe(yh(9zS*~{5lτVH%p$})_"re3!E-M\+}.i'Y;ɭC0C O:&+h↓)2 '.Q bрJB `+I9˄z73|fx4)pwv"}eOC@RaΐdlZ Zq dвߝ|7_&U.զQ<._Q_!߼(Tϧ{Rwű-Z%t t0{7~Lѐҁ:o12ݼ&558s!]E2z=mqhտVѻ/g7pp-Y;_"%%^~M5Ε*?wuYLڱVvGrrN +!780`l(qزŝʖU$[cܝv=vc8ti`|JSĿp4hP־y {l/o>#~}6ZDUA0RjP^EFn&x}64>C$Pm~{)~wnb3U["W~Y"FrƓߏbU E'}YfNfl@0"j4RTzfy ҽo^RB)ukymA'DK%:KNQ ^S W9pO暁ѩ{%(̏|I@>; m86iJs1R: h~R{bT )Z\;e7)^')XГΗ*npAv6uIJ҆}6D>Vu3N9C*+$:0$])9!&Xif$ 3gnuϧމ4}yJqjU~drrCǀ˓~T?߸3FH)!k0͓tn.'ET= \s}-bgׂ8(iacaSK{;>iYI$6PMG`eLYC̈e}"4nc4oZJf E\d?;̜ ('KL uݾ9H/rGor)BCSaȽO)Y!j39.kB_BaLii]DT/:Yk e?n{!x}hB =Ls{<(M@;-+ݙx= Ak5,1;vk$3)DGakk7MZ-x11W7s}9rOq b Iފ{e7lh/tֈ4^25mF{-9Jq#ƼaaV:N&az#n 4I 8TswQ"/zlH)(KDk2Y10}|JeR7$wK0Xю `3MSxW{c{OIok!Ww]؎Б{_$sgP>`C>׊P(JCU,:qndDam]E ? Q*-]gPrGDlS HҲiH33'Wi{ dП`k,0P IT2jzH~ؚ= < %@i&e Qf]C6Xwo>_GAhl>aZ/ .Džd/LJ[K F_pUT^NyS%ݦ<+?/ǜ,1h]B~Y-(K@Р<s\qoL8 VNC?2|OPF8vg>bQnrn0m #K2ƀşWנ6mVH$(( T:W?dK&l78|#fgoB H`!x?KoS?NukŏxW {JN$_Yb?ˁ,VQ<V4ѣv4iUrĕvH @"5Ɍo{,!a7'\YN?(L~r\/8wJG&~^8'i{UNe+ū`?GL\ge5l>3z}2xK؟xa)9:'3( WcLaYn@VlktE,Jg!IzO2d~ RW:GeqL чgpϭ5q#]$-X7\X;ف!_,yLع|ή RP t3/WA~rO7i{2YO 4RNzR}JaAd:(0'/H愢^d~JIK3Mqa~-L bd" -'Fe >5J,}gp~ _u>A>@[@jh5{"S'c+ ue4R<x\pxb,U C ׌b ⊐BG0,c3Gn\+֚bn{bk^Ho(wUCAUɱm;yS AaAVS,Z5>?~6MExv2˄<}?{y@}=˹+Ey0/:DvO9rMTw?I ?`[ej(AusuqdtAϷB6\'iPIE e˕}܈Uq|QgsNvy!iz.* /!NcDa~w{NX18O={ "z(ٶ(]6Y<)\(t-2}zY'a=ςgC"'QNKN df3̺?Ei$֬ޗT}⑵rhdS5'XXJ6{d*(Yx* A~QR ]ca43)B4?qtIuk48Z {y1g 1RDX0_~؂Kp^.0,' n4B_$Ec9gW/Py DҜ{ %EBT! x8LPCA!1B~ú2UigKf{f~εB~1Wpn_(vcMJFX-zj $xpYİ¿0GjB[0uS(Km◙^8SO{ߨ:7ѡecE8{H'wc4l?{6>3nkH6Rʙm{ԍƊɖ50<ܩ>.qxbs#) ɝ쥭,8gXCR9|bx(!"F5Tօ\h^ۏw/gg:I;VRF}suV5dz_%;9m-ԥ9;2|V" i;-z@`yjaOl# [q[U.5e ̗" C(yRLyBPs}vW9"fq#RhkNm`|+c1BjK_Ofx߂m.vv#CwVnGF^yA^߉=&k@г">*`DtEBش5U"@AbRbwV9 Q]]7j2PXmFػ®{f|# ־!M5Q{ρ$[UlOcqM2dO³iY*JTx&m QlF(ע %`[1Ǚ7|.lGY] qavI=fگv$/ZcL(1w';yJbe𤢰2AVKUmWN]U8ܰG=ϡFHº1E3@ /QM6Pxc {meMOTrb88+O*] q 4J(-p$b,0JRb#U-C{/.L3@LJɐsGd9gRHfӛȵ 'kp!J7Q-9N`ش1YǶh֪"Dy#p42Dfqm :p"b?5.ڛ@:7MH`kJ4ܒٴp1}V4ܻפb@F0ieRD|Z^up˜'%ùWBUbj#vkwe0G:34t(__ 1V7g uфY hV$_^:s z-|a81iAc6Dw0$W Q@2"7%YQP!Ee3) g-ӏ/ݑ'4tf Xؘ-?:mh2}Ѕ^2?j#NCv>Υͱf*\mfn61@8zԹv/%3G”5?N:}$|[kUZιSid&Vxd/D%/¼$N؊ (P,ق/Rj;mhGȸF3$ }<B0~ZHsͽa K>M>@ٟ 8y,Yӑ_ڌl(N{IIW){P#N hN~ȑ˦?G1^p#K"hUI<;͢AV*AЫuA`"*7> bBxj{$(Et"h'XvyŠ y]q)1[vaMKܾ&(楚L9}rL5Gr1ZJ٢β:`M5d Nͤhvc YT_M\K2>8%IX*Uթ1&{+T TM M4w57!ku_hG4Ŗ/J[Y =lR~s?"D/-2JQ8Ġ%!C,S(D Gs |_ Z۩%ənx %' ibGL^DnNjBme.Ro)7VIM.%qO(5ҙ/,(A/.dM` :R"J702tb8f"bz\i:D.6ڏah4'zKfW#h3$`g}ѸK#Rx @ḛ(_@Y##O=lE09~Q%}t{^qtS);9NSvcTeMdVsF8,;"y&It-Y;Nm`FVIygS RwV1΂T7G\6By,CGD廘P^Q)EdeG[(`Q ĸe3ǘOUюgn1X,aXxUTGDz)8WXuʦn=j+ܙn헲z:[ غgO~Zh7?5_zK OG'g~{VgBxG95߃(9 q%)C-|p`_ŒW.CnlbNC VNT%R-ˣvuޒI.h/iOkM)Dn!=o ?wf ;{ @CJ !IT,{?_ͪ2@'68L,2g=Lq;l5=8mh@҃qY.?z)qwlRgbv^Tb!>6feC|ψ N]IH Q>+F! )D.i\y ݧ @ɔX u)_I&[Zn 12&zRexA@,hD)FA6>)91 b edrL?wn͏:&r+Yf-gLAyGyDgWM~zԵ46{1JIPc='J?w/i; Dr)4Dj<:¿8 T5>f""Yc`'cw&2*[#\GK&SHyAfDy(iFu˺Q ' '5#` Vx{apB16(/xPw9qzU+:rOPR:g9rc)pW*"e»/yV/+NJ2 ~L|tuaή.6Pat4㔘sRփXɭd})naCWg 3"Bv@TS8yOab7֎&@@gU;kDp"4X;F"0!0> MiuwE|/3vM +3mD~/m- a%[={@;ʂL[EF2;ӡQܫVO.Z)&h!!D9#2S+}B(;:oxm6tOrZNrXN*&RCo,ƨ6גXo *nÍ|wXi\R} ?i`|Y!NgIZ"Xۤ(}`RȈArH<2[L$4Wx @[dn^(Ce7O/XԠpɈa+9 ϸhDYJ o߫W F{ɽs??@Nדdʚ@Q_MKB(_>:ܐfP<6g"mQZ< 5ip[i4ӋLA>T2kנ0 lw ׼vcڰ x 셱AaAթgk%Bn#x,UL\{ĭ"'a5 S+;)".d:T:Lqæ\ qXhjJ6;P}%{PX}}Llپ8\,#Pٳg`hD7#3=g)/6j^7Jcl9:7l{>j+Rӊ8*y(sZun'lPCEuhS0PM3eNsKq)Yd-2;vUjKȍKF NH`Ś[ ڷN)=)Y%Lw!c7^k|R|ȁe*wCStPPE;NjåyFƁez*پ]7X>Ho܇g^pHyػ҄n}xX,Bqw (υn0 k# rf7?%ds"rzC\ge|FP t\$-jPj$Z%=GLx:J5RˊOr``:4C~̆qP 8We|''m*>Tg F"YGY dyHkꆀ*Q>N'&ah) `J%^m&ΔoQx/P7!{{=9.2}JBJt+jĹ p io[WD(M^Rj-/}$2m(Ę̓+I7sNM>u _%,1>b= BfK֟ ybU}r/_c!;78нJU3i0\Z_b7OL=ZID$*oo08 5:Q S](G.7m5Ъ=!f9fw P I"=JH\,ֆjФP0{8W6?0lLWkŵ+G7ep ebY@`M=,A* ,WI(L'22" ~uRJH KZOljvBCx )NnvL򾝌ci2"YrR7ii9-K'Px=O< pՈeЧ+p]>Nkq05u3xVr* L 9CQ7^Ǩ}ec H%B/MRF&#zLZ'e+zm4,1T"6Zs .5Udm0$IRl7IH XYkbX۴G`!g?FeBQf."D EQF-jJ=B->p!ՆN-r%sT4]$J[/2;p78. hٔB $_Rrʮi ~1 #&!S' Hn\|b4kvx- mUY1LL= sr\Z/8YWL$Ro=!L O2$KKQ+s59G/;:$ƿ^΂;K%%UߢX>O5#X*s#83:=j=kzzt#R&Y+$lLk*W1ę8L~p Ҟ)çׇf{N6z;a $g>74!";5#Pd0BIPxӴoʕkmpB_>_yo-E?^z@P )F9z.z0{dO@{AtYa>=ji}k,Xw$DГ[*{PΫFf%5`۟ siQmIo zm|2_!}0`*ai;}4v6{=Q_12'pt`;j+9T7U"K!v5ݚ~b @>eXƪK"Q@l FZzwR\k<.akw_)տp>~~fn =Izi jp/8Lv[*I!PҤxG珛 x gw){ެi+9#:9]!G:ŏʵZ[cUp5@2I4"itr'.KU 3 Y«jZ뛰ӁٚvՊ,,z2@6peq^MNpb-}Q[ۂfܾ)uN3tS9i*ɂdԕƯՀs d{o4I0ls҅e[QRyV4]}-^2NP;芝S]`@41xso )  qt e!7MA@!tY*?\)J)f}w2Z9f;hBKm|MmY s _`Gp;]NlMF` ,O%!l{gO@]?Zmޜ3u1cSW] U#omڰ6>ŝ)N^j2)6{ZL6Y֖k=9Eg:k/S9[žU7 Hҡ`n)>g|=Abr9$<\[Ǝr;LD*(ȠLΩ:DZ{hZ)#?;lDV5`Zj&͍ϿNiT?V߄ۉkIPT.]s, ',=v^-tt;9TKPm7yr%{̰=BF>]oJG}yvBDKOU#ÞNte qVATb!õ a.9% zc$v,/Vܿju=/Ӽt ]wWo,5p@$|=4fpiξJ*o F*z#d A%À%pG"=+ 80O3ѠC/\Iע2J֡SķP#A\8Kh|=3i/yUTv~uT\zFh ݈9D\l؅%T2EO墸wC} +SEDڿjKϫ6e-m H3 կN))$tڿZ*tox)T`/,)5G8}]e5UI.)6rSm9A?ow Lk F[:Ӡ!j(#n[wtqW &VN`m*Xٹ}>tYCD^ęY c=C OrZ J&ib#4B=V{L?)(ΠjkzR1$iO'-N%,tVjV=K/ zk&Ik.sR{^R0#:I{/?^v&?vQчcÐ"mwp)Pޛ>!Uۄu .n؎CGAĄ)ʞ?Tq4r疴HWW>XkA-bi[P=Wk XƸQ 7EkU+0̾/f=r2m 6HPD%%)R:^:HVnlg(f+c8sx|P#ޖC{hoJ'?[xy[p&dW7ȕhKZqe~1H貶ɲ'R gga" |~rI!h1#w]ܓ/"UBgAU=UEcW7l]K8BG5>l%6tnuN8}FsTbwJ\|)ignT"ͽ6fx^cΑ_NF 9^ᴝ߾G$7)Hu#5j.sN!q0sѧO6?'zvAM0i8XV8bLg Vŭuu"~cOd]/1s$ gx2\afgbI2Fz$6^R[-L! ϻima}zeah>gVe f,Veqq;rc8Ι:LBħWkո`֣&O^K]L:6ΓQILTqx([(„tKt)`77 d^j龲 ҿ9FjnqRVb0<繬j|v *1ZWDk.$ĀP3A$nW( Y܅0W3 R {N-n]xr鱷@XDK08>GC4#c[q'19r0)}(lbs _Ċ ?B1,uHɃCWNlZEآW'aw TQ["SQS42 <\s ϋO(V"_5v6b7p 6i⤚ nd]a!?&aK@ȫ mhTGpUG&z{/azA}^yDuCaYΫ Ze.%a|ddZϥ)2)е95Fv`0s~-`%pDm 3\"٦;%ȊMkg+I`WW3KH^z;@LY %̨lB.. )Z|TIkmu C7:g,&Xne9ȣk#|R^SPf)5%(J\8ԍ wjÑ|{pMxsd/oZxe5uPNxqT HfBy!VKYUc!S;ĶI ]tAJn:^Zu-X {k;Ej1f#OG=WN 'd;ږW-iZO ;!GhSfȀէ:_b |oTzT n/}j9ВXTȴ?8>be*p=eEK) ~7(cG)ߦcx1g8_8vq][rjeE/kkBߌ-t5vV3֠S\?@_,]( 88^}GORa*]9c]Ɉ _ hY}HU&f,k58 vdoTJ).9ש<8[j/)c`};(H!IJT3*[IBjd*7'n~y)rnLUqa }I[ 0AC*}̋ව9RO*ɮqQ}3u}բ7u+{By@%6 v%APy49{}e;TaP陖YIY5PHKZ|3,x) D;k3}o/o!W%|!8u[$c̍ )}LBE 0A: oοaZP&baZ#ؚo1#8\vqtAu+RJc"疷K=HӾٔ`n2x5ܜ%SqZr,}E6^%zc7%WT5O;ZeF_(!h+Aal7Q 29]r%xŸVUS2h8ѭR`ݷcaeq=FLk{TL#A З>qwJС8(b)ga[7emC`T׊%A1a0䔼chJ{*UI%G_tObsM1Hn\E4EDwQ]viwP&I͎miOq_O&_#ƪ3Fu{jHtr8?AӰ(ñ[Ԫ8ݒ g`U^qf1&f& i~d/~YQUЍk˿aj0ڈM`#=Ǐh'g,֛l1:΅a^'$7ߨ-AZCFv5 "T Ѿhf0V"P,T5[a!:e*؜r1 |ۇ`=.b$]:ߤ I|-NUdjmiVw;ojVU6?sWlZ4`{E۫h)suk?@ $h/p1.V&Q3M\VKy?yBIJ8>:iLxNޘȓ7#§j嚹9Ea͵EeX;Uvz~wcvu7ӣrA!,6p8n;f!K㡉̹6LW6^Lt'&>|Ck_lRz7\NΗqkZ״¨aX8F⥤h T8ܑ2Zjd Wm1!Θ]]!\#Auv=:3Rn@tE Yn ő6H/ W+flK)f^:u69d%"y(XzSe&bP313gRXBLEM$ qX WK^RDkc[ jh&ڸiA-lAزԷRI׏kc6Y2NB}\cgCJaxޜF95wLS籦d7X='lVƣ$ѫDN;Sz@{=.<~[S}Ġ 43ZUknJ{E+HXF|* (%~oLwh[`f cVЋ9`cIEƒ)a6+%'D{G5[Nr5mcvq7JKJt/OgFvN}]j3k$Lb{+>Ø+g74.bMev0QJ_lSiT@`w=t".kvRA_Dtu`E=nC r_ES_r+?.~,APV,HWX:ݬ9='r(s'rC2Q; 2Xd ,s)paB^@(LI/t^W8grV0t}xlJԻ{%{8쫣6Lڻ9Xu:1W #T^%^{GlzƽP!(!qjEkh̉?ج plj)  \I]%ҫ|C) R8׼yj1Ig |*Ws3dȊQgPdL "hACn^ˢHQq6\1mn+{ENu_q]zbń)muT"ӯǗ>?l],E] _".BA%c7z9U7U;T: $H1$}L )b*.f|_AհH뿑= L:XwTrUP]%&\}Lz;aoޢÐP ,$CqvBKxwjr.:;2;L!%yõ,ֱ[(rzNr2iVnX k(&fݧ|5&-V^/؏cR ԼY"$%zBˆkc3`nFdM]t}Ȓ5kb1NUN׀]& 2*sU!=XF-=W|x~\k"w_7T4l-UKK`t}' ZɏNd`\iOӢa!6>",oM  %X ZzBb(ӛt}Z>]y~ϵEŠRS “Y|AxKPkÿ:8-T!w숤% 6P_ݺDT9?n`AU˘Bq.2Մ96O+ML?2bvI56ٖێ͏%:JK"@PrO}_=l[ zXͶ 巐O|ʊN2ͷ]΄zZ;A<&2/¦w0+̂>FhBu=}] y>q&Q]Wcfbg0(Q5"3 uӓ}ۘ]dC" $Q\ΜM`l("Wś;UʣPԜ_`"?SzlOOjz/}$kWq his,u)=:xu00Uv7̖U oz0nP@pbmrƉ~ o5={LlIRs<4HMom/NiGOqeٺ{8-]WW/ĮV>I(R?ڦsׅjHyŅOu~9Ct=?"j r!L IZ a#SQWU*Gu -Rp{6?b/0A M6% e.F6"4Lu MCMbi@q7dMvޮ 3n?iՕ~|,U_9^6#5/~'-ަH mY?^oSL=.X{@Z1yO;.9bs9sp 4yP&Փ:~Koj7IGbYQaBB /X+2hrV{ÂsAjˏ/1?JǴNe)8m4է9,^3eYm7*Dy|V"ѕ\p> nͿYҒ>|tp*;f, H[ѵv(BV#Fyb<ȳɹOl3e:atPS7v~N U3 zPL&zSӽ(ZPk߃ S-E[RXJwX/B=9OJ~~Cy!kbzmTp|ܣmUq3_gζ1UO}[Ǡth^V~ŹGEMU =l)c%[.U664HX[yq4}ͼBdW>b9jNP YÃM~3SՆM 5vz[f;W ם9oѵTyF&'nw}nƗK5}ѰIdQ¹<ۙ4xNlsʛ.UZ( t]3Q 4FY|Gq*dPqMH'=WJ.T#;!G)9b& \V+ \S4O La$VuΐzNǂ:ULCa͍ U|];^xw:|}k8ſo0Kc ~>%FEJ#avwkΈp,-N Y} ,dh hn7|68,u"EЙ2H$1HĿuº۴nyN!g pA{?C-Kz`Ti`qIux-ppסmⶓJdXJ4c݅Ի>M-ѯ˰ {qWഓxۋMu$I6x>x7U^dՂM?Dj[L;`84s.Zךwd4fYA{q=NWT\ՉH'.`9-np$l~ Zop,68`k D(a@T[u[[$w\^,KdH#tR-ı ]g^}M<-L 40kѺzw޻L SNGRʾ#QM)ǓRҨ]T\=݀1s,EN9 )h JBxGP;塒5fUR~}cd6dvv2Ō GgX8axnS ރJS1t U}+X9s|W@Bl$漜,|/, .Yg}sy˓s{LtǣoЌ7L'EOcMZzZܩ ޣup8#ρպox!UC2M6H'aBRh{xIC$I+[l.kNz+?q4*Ы6ĚЭ86.r:D99 DM`ϧs>nyrX_@cy4#D(3psPl@yLapCˋY0P"b$ %:yiڡtx u[`\73mNd23fUeBevt$VvҋJ:TOQ'j`q qHڦoQ xOVqL3.u–L6at*^L?A?p"8:Z#T;d恸1D褸f+("Ý,΂3IjpylTpCRRmzvݨɖ17-p.{U1&R蝮m5glՐ:3?ܧCSmTΥb_#P|_ Tg:0:'F,gArK:+`busxU&Ngcا\,/SJSw%1q,kX'ְ+ sWC#4PնT҄*-'y 9=0W]UFe6n}WMmMcGD#,ݱ5]Yǘ4Qr*ꍩ1m '#68)wvbXDd8e3uIHt:AT(Bj3\VNZRj𞦼/uTse͐G7tϼu S7'F^l߬u[OO9{ 9v_4+=/pS]6K ԌyO*gp ~eꚨjsW@ ς^} 3m3ėR#)l|`7(;!= +MDCbo.{V eT 3# !quK- 7ÎjBj,^x)G3*MhKC)(/{H˂0ʞN"!d1/ '[O@a1`VeEpm-֍5"q% 'f@HMAȂ 9X:ۆ@cT78.t$!P1jݸ\!VlOWdkgW9e4`? F;1^$>(Ds.2pgڂ=3~UZz#j+X#Ҩo}г5`'ۂyk7\ i2Rx;ꏞJ>[ddvpstдۋi8 ˷˦Z uGƊ/INnXSJ%皾^_wJ$K 'Cju.ѳо$O:PW;v~Od&YW$ӫZǨP k}vʦrq2bp22 =Ws+t}|uZlY|*t8$ePM^!s(][+U v*9O6Mkz̍@|YBK'ٱ ^wfg 5# Xlݰix{$nlN"!?IۺEu)#n<9T&6b8ޱ_r|5=4.;?\j-m~)YW̓%vć9c)W^w6uoD=Y .`"RCoOj;-dycuFC"_x:Dc& c?qB90L.v!Fo!J6{~ܐD*pd ^ڒ'$;%{n `<1Ȟp.j'h-{2O Z56ͫ`kUN=v&Eu.<CAlk$ێ|>ҧAE%&^)N5/Y(Ư'EkxӼ (#Gbvk 7QCl? hC_3Sna^G0s+~m~1J&NOg3}ű 'ҊB48 X1ܕIىV90wxJS>5T\ /}[9/RND)ǯ¬Ħobf72lФ9?k}xcE&+upH |NQvNīgirˑPw v p=]^SθO."iB&}0ME1Sbf[5K}L08'rIɘBaxpڡlY"c0ю}2攆/r!d"L7yN;y]UѬ Uil7:s(";-_ܒsÄ/gi:".Qfs+ ?ޓZ6—Ox"[ݘgы\ \]߳u{=)K!}:9aS9t#'ȇc[(}2n ©9@a0v_ #'2'8m|9}JK|O~ $F9ѪA~_\J'ԞGUN-|,؅O_j"~:f-޿3JlǓBb*Qn A%_Jڥcj\Q)w~\տsZhWVK-GP+xsS|6ÊZDp M]_>>*{~:(9A6uSVeAfn$(bd.&{~&]O2ʧ8ţT>ԏrYO ŕ?u PԖfBҋm{`7ySΊ:'c)99Y|0͇¢ݖ$Tz]  pEBkw=ӳg`94=[U2Ѽ^fcjc4|.E;!^XAL<"=NP|l6cw3Ojvǡ6 9z+R/3 i Z[mpT%JžUm76;OM\co/t*TR"F*I4J]$T8ńF_L7匈i1G/K'Nf8i_[E6XnJ9%-Xuq+F^ cwoZ|gH @dkCg^ňmR 2ZjE}#/ΗI"Jn:H%3'aYcͥ;jzb" ğQ)pp$+@@n79>y*V6 絉sr~Fry"[TJ=M9 -DwJ5$L / c蒝շa{xjվ9=X/="#DAϯE$r\':WO&:I}qJZ%U0*miF?1 kt-nbб9t<[+N9#2r񋢜Ka9 ":Ƀi*n:J[{^3lY&ab<_ۚ d&~V'E(5՝`fy53{Aێpcq2X3hXr{˩^>G9T^ƶGֲ= roaʭCm<јsi&g{GM1BH.[l"k۳Aq0@Ozˢ FkN; _Qqt%/EY=9Eg&Jy,[tUyym^?iGvE8en?Er }@|xx t"'fV^yOj$;H݅2Ț *df ?'h_6OBwOf[;PsBԱ!'tO!>yp F\Ƙ#.BA㛆\ j8<Ů?ޥAhA&)qR8'p/_:ČL{@+*n(&m0!NV{\1v;:Ϳ֙!YFZO`S9i{Ԇi䛾K8HZV4`a[e~ZsSH--`bYq~ѭJlSuzCz<MZHBޱwP;&SauEQy"gEPQ%>|zH"zin&8c%{܉xkI@mɯ}Inn^ 5gNP/*L~Ӷꃽ{?d.3AQ,bŅh@,*TT_(+(*A!@h<ݣ0 Lqz%s޸ &Őg<یe$NˢZv7,=^鷦!Qu6:ݣ@ K~b dkW_aL+?ȕ t3|Mw/~Uٽ y(&Zjj u:3>M2hF1ls[ ;5{:P0A&Ïqdc%V44c=aLI9zVMցpo (sPEZ5`U͆1xdl9NYYҐMo/m)]huSg׮MonCq @r4ha29 1 fhqF1HR4v'GqƍAtcDi;d1^O;i@嘤Fu|}W8JJz6ipo1 + ޵a}XE gX@_LB!'7 E/>fAށB#~6fR(9*JYͯb=D BɀbҜdmXM a:MJ1$_Ɨۧ)Ƒ1m(RŪW$, ~KVW>VRYDXB8k-ԪF]$f\oW pOO~=WUJt(i&S;  h?}75L9}rGO4ՖȇY KE^]#j䚨ƻp$:' Fa@'xc7pZ|!UYӨ#c yhhEysu]|PV Bsc0DK5M,Ḭ4l1_~%N!a MVz ;N(n~d=@wpt`_ Xڙ^\tc2M”9R4i) s%KnU :!  6á& kylgN] Bn+F9lsw}tпH~Nw iY|n#dCX[/-Vl(-bbE sybGVw-Y(mTx|1l~O/;Ts*~-T< آ'7j<[N.9& eWJ|zZw}qB^ tY\2aO9b'88WHq xh*#\oIԌޣL D6aCO4 (@'\}dzN|^>{Жnȧ]U. IYNe? f5q#+@TmZ֏ ;|0sYf_beKީ \ص>a!aVc5 +S1)]>[Tl|{_&iĔISr'n2h.=O\l%|8k</nTXx !1kf\pF*2k&qƾ|uZ^~$!DsK& hh*m{ O$K{ƊmIMB͑cW ^oZ͸2`嬎WJͭ8'|u.#ufz8@> z%1IGljqtk+}Uv5|` >uWzJ.̶`d}Ԩ(n0  e*[$3q֢J>gm鹑Y@,]m3Az.*o30mi]߈= y 4G)mҮf,Y6a 4oU_0\I+7y0aH.-B5ɞ7{Xj%Z^nPgɓ?d$b´<fxP Y{-ksMռ ߂%DxKؐ +K/&6b`{La=2:.JjqSq^qSo #ɘX +[?v IC4/&,ݍ_fq,_N*׿r(XaCMgr; L Tr6yRA.tQLR~t 7F3NdRK 2Ңeօ@Je3r|1T&=N-˦j*UВWb `abE?csg4AsW2wj(|-(etL:jX'T6WOiHs+1Eq;:7QoI[B\ŀh T{:jaH94s8hJGw6q)Lȡz6euiՋcn#?gw Z\c5>s!G:oQ0]bh<-[Yؔ]?xCcd%F+峤zQ}v,yh6\wt.E恽–v. . 1"Ү]ʁJX:x#fIc۔p MD"$"d.;w2ay*_ Ĝ>xrq_x_&HpoUzXy;ꌤhdWt }^jAijUe^&f)=̀9k%]nf?]cI\ sp<7gGwȘ(7IG"aɅZMJArC5ǵյ^{{)] -aNo7g5rڔ} _BL(lF\إ-!:ZA.]Uޑ􎟍m{q@V0zCe`h6G">g!Qx?Nl̋N`Ҝal7finG5.Ct6)n J~hNBOɒŒ-[Lf;^'f@zb\hEȳcv3ߠؐk?=;Ab 2v={b"lw +ǓPt~oLJ#S!F]1!)Z^Ag]_ ,by?x4Skۄϔm--n"1Sہ&aQJ/sH٧l̶iH\H}piݤ`C%R_}c׸`Pi2B_V>i1[~M۠D pߵUY/2R}+j(qY|cpvò$|ŕ9ob#ptKD7:g0(dO= [&ƮtFg<{hiQ[~<š~>ud{Q= ce0N;:ţ9tњv5Pi>M+m{[HUl!:?[8 k1sXL `\|&i҂"*7~kc!+;yv7ft=R`OQ͔Bfr= Ӷv7=|`q[=1!WtAʤ:To,#$%ŌϚvy̶YSmQSlZJ?_%(﵏>!;eMK#6>|:wDȏyh':fstѹGvc̾#9 v tIacpz, 'xh _>p16 ]`{ݰJR;#"D)G3;a_ 0#?bp{%`m914L񀸥9QeOKcqO! g17䯮ހ%8Ƈu<Ψ<lSQKrL8[䫿oC,/Tն+TE<7M;Tfq8sώ-U¯ykCy54l_N΂^0t8ǟ) ѿx1,QSn89x!~R=jR2MӍ1 4zW]6VrRbbB2fX;nYPjUWE}Mv0Zjn(> fCzԃuc.^pb>2ƲyjA<Mt_0Hn^RrP!TBQE*`.ȹνLf3u8}dH7q{8qbN>m̜u$iZdnq?xzuC`*Z'qmqU!mO{9jw?>PS?  (IILGd v4,MےC K#EkgY,Vl1wv%|B Z/$t5 !JD\T$'츿}=QaT;4zݚF$Osyi)LYT6n 6kO(ku6uϨP<{Hm12\g0 FaFJ{=ͼ{_y^1 pa=Iye*R͙;d4665VxR`(|!@[VKF(W{z~\a.K2pp}(lDrc];ֆKTo:O,Cj*ݘýROc]=vO&Ocv5jjtgttjD}0!bLp^Lz5/jЈS;ķ9囹Jr9.tc8^GLQ/Wp.*O}=m)7b5LM)^_G<ܜ4O]_Ŗ5Ѱ9.j[h{>Ĝ Y`}BG{xj_§| Ϡ+Yp};9aT"#! Zj&164cJmoT< jV >-,lD*ڔQrd5RXv˫ {9Z $ X/* 2b{4,u  pF i3T*73*&l ,B3ظCCG[/G əAaG*¨^j nQoTkʋ|D?7ҋL₹e7RR4Ū7+\ 2/"HpzUB2BWuc\`VP[)}wIr{;tpbE@\h@HS`TzPk2+>Zo׭rl?%,d=i->hc@)`X%jr%wF;0TZ.ahas0Jys#leJ,i-qa}dLҘ?;\ vlغ1ו򹹔:s6obQݡ i$_Faef0z[6SWf Av |TBa ]9y'O_ʣoBuP㻌S5 (eeydfg^gqk 2 Re? 77kƘb^me{rٌ9pO~aJObCR(fe*ybĘYg,Fi>qF|aZHWu7h,ړ#k\8 1n1 k_-IVM5z3xf!'k-hv]*kqA``((s˸^k(Ô.f_[$0 0T5%~to (]CrSKÖrP !c+̈ea>-%b~{[W{3-않8gQA<lҊ )ԨUgK$9ˮa[ZnWqEĺPnPptJקF׊*!F!ߚۋσwƣP PV'GeÞ T)+q؂9eI-쳋+k/NbF%|F h2Fg(uZhsJ:X `mٌ̡Vdg߮R $zMpCΓVOڛ:uns>Dάphl|Fz𦯿uG_MFoG00ye\ҶF3uI}(LM@HHjce"o~DТ?Y#?3)$y눞K<OX$2A<6y3$tw*:KEmR:jHp046]F xM`A1C˖~5Z :w6Hw3c"(2No[Ҙ;VIP9 8V͢teq?*)W}MS@3[鏠,pS|-Mu~= `wA#>ר <r9@Q4, {5 }*;1Pxaȴ>K ;6-ϥe#ڜ|iaְ0IE+G3c,n=JrګntOMiR t;`<GZcʘa KaUE@.凰SQǑ%<6e/Fm:??ٶi/nLI˫ßf)Euݽ9Yte4||.8GLtybi%X- r6:,vD҉Gfb!ۀNA>9N˛֥VN3N"$ BG3ymbd:unPD֙8P_ІҪv'l0Mq_u9qu"N EXi9g] 1flDE@mqTf͐&M˖E Q`AyWZNe婉ơm"$*1V aa0e8LVN"um* /p6Uio| *HZ^') oU4D/k]:-Z~IfBPLO>w#{d+K{.9u&3o-!1M "5$UR|.D=,|Y΋~_!42=[5N{w6oq=5E{̮:~i[A1}GhANc2k%cn*__ Ԗv1l,2D&=P牃U+1z˨"h27XRySBT >4T@gMlp~<4$}VjH|`uG4LA@,b1BiCk,y hToc 9EMZJdvvYۮݟ҉|h/"c43khO9W컒Jr?L 2}tWUd90-g7{q.Zz)Nq5;0v>੒NW>濹\uX n=5;(ϐX@)sԾ8LE̍@5T3wߥ3ϡEU6˴<.xIJu.(܁N+*$W0k㚐;-8ayTI21I18MZC͠$O:J,򄡯 wtUiK$(M6{]zg1Ibt$7g+l#LW/~1lgaAm S/]01<+͘Кe0e5)3tsK= t 80A ) T"pjmb26ZxwiuFĸ)Ҋ*3,+ׯ`DMEMƫ'x,UO@1¿p۪j `៭^vKx;$.'T/o 'JZ#zE3Ԅ5 |<63Wy'/z,V)M8Zچ|$ ,eN{W-҇ZeG}O&ŵ*KBSW \L|XyI[Kj-)V]~st8=f.VQ-Lܼmb.. Ҥ-ɋ67B_gQQ}) KzCCazrZ̏7y.au}6zxfwIgצS{"cN mtTEti {+#{R8FE|׸-}4);~P8#-|hqP vQB~9K]wyy(\blP7-㌻yAƬ<'s$J͵Bs0qP ^b qU#G6D[G[2ڹUYtm죌_`M,u,S{G K"7H8˔˪aԂ6I?ˢ2#^:x2SBĐ=1sXu"$`](Db y`wiFj8o%qX}v!VAy eqN w@l}$ s}WC;v[kQb y =e@Ls4DMM)SIͅ s30ljx[Wa;ڭ=T` uB'EzQ5+;[(N6<+QXRy۩Պɢ4x ZxX ( zHgӸ5Ad[jkto3$2-ocr+17H oө 9EGLqՔ;6 Y8[å;ͷIAqY姊1 yk\-Q?Pz0+(ɽ n,[ 0W~߰:m'ShMZJ"),`-N3e{2^IubSV7\KBvr؞Sw PHH>i ,PG1o"(DpdL)LۯtDӼ@o\DDXi9C(1J/Z0K`!z}H sb /Sy$ˆZ)my/?^iB%/-z['q78RTVhiV$T&-hSVn,y_LXjs(wGɔNorB\ G8;mثVbg#u.i:۷_4 e ( +] 9b#Uqׁ8|PE,bVFX ɂwmFw%qwI; #@o$I%)80.} Ggha ^ۀshfo/JwWj?Q {6'hيX#&ۚJن-y⶗VfL󏞂/(AW!ˮ+JxV9x[|eS ʞE>B-ORsIc)@Qğwu'O9i !_?.䈏D&e /P5HF|eTRť2ܚ@*S۫JF]"slǞE *rsq;39qSDž#)_Ƣޟ+!q}I2¼=V.b&%D3^z#]ء,wAV-  .Tp8i \gs~_7S"W|Qz4P1CaNSm*f1P,ݨ Tq"luǮ4Jh2qTj'\FusXDӵ6YZ ìhvg51/F+`&{K\[X^i9'A+|f(ذ}2 0_F 9Yc41a3F9}c@NX |O#'Du$v6t&__UXRչ=$tcE(F\DX-/p쀃DM\{>T1|6/c_{W~b)Fv[k'05Wo9~LT=ٰωüUn5g!Bl" f[4O}WQ\SR%N-j`,utBW+ C{ ӆⱷƀr ݒ1ʄ9I٬w/ 1 |:the/`Sd*L_%]"$C~A W5b3P@vL&n.֎"p l>F3 R@R^dSuS R^(͖ ]<9̞.9&)ЂgC\-7 |23T\5T Tw|hL&)kߦl@Cb76? 8hLw;J:2\1.U}K󂡗Rl;x;bEEv ) L±Χk,ǒl*LR1Sٞ,B(eRE3-Uf~vz%kQW,Lڦe%1Vܘm0y̧: mMОAzzH,PbƷAթ!F~F%wBᐴlfH(Kȵym$S92+/&>|.b`3+>g>Ss0= xԔwOl'땫SeT9ab$JLG5^#fg"XjF)y#C|OyB^E!nGfy~|j/'4'QE;p/=*aJU"oT[ JMW9@g$^ s"Qz!-=y@g2ta(B+{81+XcQUNY ȢVaoE;UN͞+ P+Je6nͅI7΃#j,h*.+gu"i6a0eA]BtMھsAD U<*7 Æ5ƙONu#%J'}sYO&@IT05V3w7Ma@AZ^E+z. ~3.>KCq%9;*O%!;{t!&9G;^:l,+V筨 0t7N8b‚UN- {hMF/KRzs/Wf^(@p3s㟣q%J= ok ȉ Sk #z9  ȨC gBcF+-[(Ò뒫"}&W^D H)҈D);:eo !o9eY_КfK(ޤA9tŒ?2kTl+_Ǽ;N vUoaZ35]f>K~m_rޜD0>AԆ }M޴PmBɃ:j02(~w23$7d0-+?M8M*Y{(bt@q'P„)Ç˖~K185"3ɬ]h[rOR&V$ʪ{\Bpst ~`A,=։d%4 anXl%W=xhG*m9z@o2~EEW v{s΅7h焜Gρ@@UH`wm-k@"XG}ci C.*V: h]:oy|̍۳#p&s2z2, R?#@ T> f}t:&eMp?qGV)x{_(62=mAN>QhكH3"]P8أBB=8O<}QCf0`XFd0 0LvN[bxΒ8_o\!6)\uXV$Ekw|[ PpCLZ"^X\O7THK8*;:M p7Rή[ qj(Km_#dS]z9g (t}Q / -q::بhp.YGXa$%l~W"f{W?P"5w|y2ѲOsۋޛ&3i,h% 0RҲxy34ʭh+E }^Y+e>w > 5{$xdc8*qG_TIPXUHX5G!ݓ%oA[`[O H+Lt.}D"z j|‹O~IȩG#-ЁN~zm)g'9*O${?LTxvMnj6'څ's@z/c }el|"Byhc<01O[ޚ0x2<, 4-5yYC6~`*M:cm*6rbMVL F5dРVp8G-'y'"jΧ^(Y&4SORhw9n;k LM`&OT>5L"Yx49m1FٸOJ<2PߩC%pmY=N?qڌYWHYH6_;*ɓ;z|2.N{0ÐZ%Tx E/wHtߴE6)_ߦo(ީ= ԇК2;dѤoBs)eE4(hD|QL~N1IllC-H7i& 4/E#nRo|:rA^UͶB7B3yTW9i9By534ϒR7N0%Ó?܍!&d.rvfIږʖ+ `?NxcŁP;߳ȥÆh6:9k~mf')ne3FIɆͷmOa dk$r(Ƭ > jwM:۪JӨ3W͋u֞++U$Apyĥ:dx{Bʩ0Ca$Bzpbn}%S(y"[@RO E>zWR(a)%%Jobz-h >$JO (g)DEhLNBE:Fӻ\8{Q]vO΀Dmb` ZFB3q~)S^r;]WSp ,K 6-?P~ckC_ 5tՕ~SLN w D|o4o_j7e()K5S;B\HŅ0L.o̹G)֥e|o @UE3ihQn {F{iz 1(j!K1ˡ@v.9{D>N*`{EhxuFUs87'?%]JlJajQ .;soPiրN:g,x3]6I;=hT,}SyIX'{L@۲BZMۯ}}kU_Up&4-^N_ǮA3Nn|U+qHW(Q&3K\%wjr4}&'&olRX3ڐ_Uy#S/0f`*rYfu^,oJ[c9;zx9)F)< R#ѣϦzs\ q+$>[(}p:ṷ?0g(qم[xobI@lhb,Dqeo~.f0k.RW7)i҃͊M 9'ytXMgZ+A $ps`]L$y;i]>#q.GK>u:YTUJƸ<,>SDqmICi&h.:34R>wq65lP >qG(+sRF~;F=mce7}`-HÉd1S\EXZ&1PZH`KQ^yj!u]B"Ǿωf%:VbKM()A wntU^)&\YsRJq,gGȓ:Q) \ >o(f;[NPm* M;]eE=,t\7Vj PU&@+L@jq )>5&}H.[_o>o :)[izt)22n5]I9M[CމcJaG6lPmJ-\[խH Cc-C.IR/fP.Gv{fW=G!)~IUR\!tT?n$&ɕ34;A2ԀȾλ?e|^՛E~sһlVDK[S&T=0wwޯ~As͋+yhVT+-CϠRG3lIܠBwWe_"bc{&"LCe̥Q"{4٭q?a{Y_8׸_ɶ&}FWfљx:ll44j/' /c 6p)_@RD$O2{=c\#SB{eSo`+jma3\3'Uʽ\D2SMv00f\DתH]*xjj7ڡānyL2mF9b#|íH]Ք.V^]:v6N"l_N +G ,%4gnm?_*rpA%h`ލ&1U풡t%}<> @GPQw뽢=)i=|2Ç=ynDqkꑺ2 y-_z|ޏ*xCx~cso g])i0o/K&9w?V޾Vu{qfuAha\e}.dpSt))PφGϣd91;_<؆\.k'+A咱Di} +F!(cW*1INX? ]e{/Q$E*m"VE㒁&/jGyv*Rlh3D^Ov+E$yl >Mwj+2jPSi'M@| 1DQw? abvoMؤ1210[RٙD;(C-MNe!" z?Dj]te,WRfReDԥD,;} pqGnv`1o%(#J#=v?cxVmPv'9 3ߎ)Qو97y܉ͩHs}n☘@&OPRt-?%qoa5(4\?b$'ߡc''nt!xZO6MM.)c'IT dL^a9/ %0`#ܝvS+s0:T2s"Z>ƬQaTlܑa k!.q Wք4BK8kPk 0٭RNNm/_?~v~co^BO}pWVt D PF1eAF0@_6F2 z~S,)6R8ܫ[~H 0z]v&O f"/xLW:*p2(( ߈Cc{tRŕd/>c^Ph8Ƙuuc ޘvEh=ɃPB ȊH `uZRaiz9e[S5Rَb͎NUt9ki3X(증F~Negy1iBwo̜7˼(q1jnp2s =W QPzD:OJEHB6f )>DAJ*nj8C/$i_fA g9aަ,\iBC챽%1QM^њ+1@]t;#in_F5VѤ]#3 t-0}Mi~8̱֧٤{ _.8ohx=/їS*|(?:Q];铝Jp?q`hH4Np6 7@|pX*' Yjꎢh *7K)mcGx5ת[D%N2X'0|pZLA+$^LÎ aUZp؟NO sW.΋7*sP_n8'c dl.&A῕:vJʣGa0o].e\0AU #[~7Ljg@r#M! s( a6J<4< 6EIPvTTmCsHSBr ڕANwu+&X"^#y85N*t&=TJbjo}fkQrbL$G07' N/u|~Z8DrM&I59n> l111hXGO˷W?G/(?AH/Z;oZEAG [6ECwko=%м="+/7 d~o!]kvn>:ڄv/$dX療?>> NP iO0,JM`vf{RsRځz:a-J2Q1lA_x~=XѨCG .Ë~oTٜhǛB/A#W)Ҡs {LBͣȂDLidxh}wƝyȾNȉ)۵ricSl=$([7)MlY3ڇ+_8 N{Upue-zB(#,@Z2W764Vt@R =7#ڟmqו ;ɳ!]Ӡ3lCb}yX æ:-rkd@]SɂP3"p7IpoKʜq R i_>x1:@Ş(9n癓>:L$z ~kv:\UƢ`<(e>|! kefTR77r;:mDHa2 lQr촃3[g-V=QnK`K UŜ]4V:.C8z#ucESTXF<~&QpJJ` we]=H$ ~MI>X=ZHksz"qEGWK+Yܱ|RN`pQt~i:n a@1i wu`I5\-4zeUa p0pFmX ?>]`mc'^.~eWk7wz"J8pLu9nMbJan$aHKM2n T1xSy#C ' B4MǮ?]cҬ ٹ9n"PqnfcR/ud40o= o؞_r9d$ iͿA|moLᙲ1<pA[ 2҈V~IBro`J_g۴I #WρI}e9blSȈvYm2kpnylQL3p3R|V/ pdV1 [9AlVC,Kurs|BHc88࿆荼z)\Itar ѐZ}unM ~e^fvT\30% `i?@teYLֱ~&12T赗O].7KoָmرY?ŗ7_M[Fw N I(1 xU{r-0 N.Bo"ǃ'3ݿǻڤ&~8DrQhg>dP˚=KuXZ< Oef`PEg21Pi<@ɥJ.>UʭrESv0\][] A/>pEEdGR1Jkٜ53pkztr BDpH!@n#Ur ͗>w`F*rYCV]MS?ʼx컼9L,Ø/XiA*d* ʶ Yor%Α#[s[UY T0 J z)O'k΁)sLnE}@ !6 nFsbh) ?2~@]TWX6*nC:ZMbr+P&N1c!?e#5 ̢zi0)Bpgiѣ)ϲ%ed)B6&+8.LNhE4T[H_<*쀟VeЯ4{qކiZ"OwՀ{Z+rF4>&jzrhFE^ g=Nm+S# dɲ~:.>rhU2 Y|EUɽE/GMWUSBv}ތ}W:7< ag}4jܵn6 \L\'~z/!)swӇQ =b).yb6vյMkh IX`qoHu~ӂJٺEKm=>oID =U`[bd(U s}cxs55.롅]oSwI/A=2Eh'ƣ(;xϔ9:-;W0(?;!O}.Ps+C2JdY-韶Q~-lJj $'Q;IG$Ł=Jsf 6",gq7[>LaFȲIX1 9"7]!f+{MMj{t)0MzwIng(N&w'Ӆfݔmm߼j|Owq^˒<_U?tIts57vbV:׉V8y>g~Pc2 >ĐRl_f͏8pO2+(* F<X6OfH͙a(%7bG+t Nu$'sU\?@z36?EŐc?-{<4Ms@5ظ BroJ ^fP~[Bֻfګ@j/0E݄ Wu 8^K5$9B :pX:$Q oi ٞD6<ޞ«~RQ\?Q۲)R;4m]ڼ*uۆnN;P?sWȑ$(S},L-V^)Emdmjy0DrD@@ WRt³*I/:$i̅B7-^Y9[;ǎ,o!K)JH@m7A}=jYp. U&F'dfhr7@RϵѮ0VјCrWIiV*fjYZwh0 W s>c C@M;G[~* JTح_畧QJ_[1NFz"f4E[]3RP'mp"}S- W=N[4w@>7dU`8,v| :|$@^]|YzO&@5MeS{•`{*a oCs3+bzQU R1OW,`e\5my! >țbj}ndes ^f>2 ` :h4g"",.*6o蜟AeCV=,}hPuĿg4A\rPu۽ªj~(w;1>Ug])ʀBh.}6.@d욳{KY_R2A==A"l HWGkn>C _e Fظ}"3aNrRvȐ,Oi" 4=(Fw1cZȩp_LPw*4~/~_')C撪 P" G!K۽ atzۿXiW3hN6.y FنNInԟY5~BUGsB$Vix0DM[BrTvmv%J1Jǀ;w*\\/2Ҝ|[2؅xTY ?J!վ`-cznB}D_#l_`c+IˎrHvq:DpǎHR^c[(Jŀ"4N@~6&oMW9 @-oJ-N~$ekQ#9薃o{@K3+s5[S؊cQBG#ߧ,IFtx_DuFט񧅖%c(e}pxBMrf XbPBXtf%da6֏NF\?]rH ^W»>H7^CaI H%NixuT[=L:G6~F``Mo7HR}='מ^m}p){¤=m56R\"34r. 3C>?{9):y @T  Ԥ˿wW:7/ ' Ifqs @ v}bTayi-$sdb8*&@¹nWŎ'-ÊY1vRR}׾ 'a6&F5wjqwo#:%S8}fVsۮ*u#$Xw+>Z%dF#ㅛhP\mFbEz?:uLm7>(sUiYrJ]ηFE)ԡ̮PϽ4|OR떴' kAjJ6Cb跐(n$cO+rٚ ~/4 Ҡfh+~ },0Qq tQ'ܸkեlT,onH,wsޏF}LtMN;NgNGg6W`.zsѰ 9#3O*NqGk TQ!T7ˉ]a<+a r QE=/١Q0Ԕlpt%g,T(W-dd ox`;Lʌ 3WyJKsq"Xem}u*XCm_$P\,cHD,qɀgl߹8'H^i^ԁo: W֭J&eJhfwY>7 +#aH>KjUk~6 I5S-RAmtW4wT+ =+뵥c)|X +ھ s=^AIs.yIכUȊ cN\f8:'.' Agnܙ!W~>, W3w*vz-knms1<#_!}tQK ָح+C{7ݾ?nP;|/7lL)$$t ro4SP hPYge^3 5 ST^1wfDែGYudm4v ބxXn|1"kOe2sK[ō=o+=/$J{nIW2lfg2}ɧL{:M֪q %eC.Z4ktF"N+b>1cLgE{s9 'B\G ig{>עo,0I/bܙ\\\zbrhU ݁x0rm 6{3+@ܵEDi?t>h'߶~נX.N8 x좗p#>xLqN\ƾ(tiF 5.5І<]˜vbIfŋ0ݞB]=8I؊]s,K?*16{̛_M9k鱌umFNVVnNoòP #h3` {ɝL 쵤G]Zަ8_3,1qse̱Jls5f>9L2vVMMep-L]xoh*m)/6,9KJ:MՍ z4Ur _a&W S:n4&`vZ[^bAH\3^'ljL*<%T9YL|k曽R`Wmxy9iq%B`^P byW1.:v-!:06Z~Rw,|E > ]Ha]5(29F3lI8՞t4XbZ(k|>㪲4n.foդn.o?=B"Os$\LrEO672m`xrg4pN/ARpSӹ f-u2Ji㠔PeOG l*ii<ٶۺ4gM)ptJcDl=HhA~sׇP/jl!2LoVdT9*yߧ!-KZX#"c0Axn 3IAP@I8d= (> 9uˍK߽ du:YQCͷ1!i)&=y[[3~wQllU w/@s$a;WψfestIDD@U$&v` ؊T Z$VM?:k8^/r PK+kz? DߗUqQ’uՔlѧ鵊9V3#\tҤ=UkY_lz0GQ,HY,33P(pJ-+#W5ue:K{Eٽ˭J$jQ' 4’F91绞ёOGHeܲP=!;°܎ P F>JZC\uqb,,.wI%Gmm LSfڬh罦j;e^"!llOCY_BB" mlt/ӏւ;ds5n:/ta!N_kPɚڕV-Q-b^^;IR ~Ǡ؀5Y!Vx):-YNL3Su1N7~W޲ p-aV=M( j{Q$e55ڸǤ151V/%)͞PsvPrQ<#-Y݊2DәGٱգ,FooYWRc\`n5|  NmD—Əg`nQ?Z.9d?nF*H .SDkxYe6C.9'x( zo#V߳)g}xXb[jxJsq+pu[@[BIdq;:J{ ]s5BiE?㸃C\>ƒhk0?\ ,f9tܝ'2¦(j߈ge'(9ŮY5 ,NnюKY{&,g )%v Y>M\J7EZ1 j ?Ldm-F?H%3g==xCYy fCe8d8 K9 e/C=ȭlW P(4H +7u0Vz5@((+8/ϳ61t㼡DVG},M4D1 U)o^& *,B tf*;$ uZHx]fD.~Euhҭ"K'Y\bI mj;1KjmG+= ܛgND86K>A^dEG䴪vc0 }ʷdž@_^#R b;!Qa7Fٔ=[{RC-7v̪~&a^kpM?fdtepT T#rd8zl E$6:h;<:Zf}~]x*;%9<Mr\ɿpu;M48X+t>U7[Qy. _0ݙA2rL#YB1-:9߅͹ $N,&"rvdk!^]$L0֞m+,!숼 5Qi _Pro<:CdStV'>)=ǻHǫP)<[T Ou(UO,(tZyM7F+煶7q'L\ZO4@ڬ&TEF{|7;8p+pޞz&Jh{8#Ebʎm"R^%lItD+iEO(,?AlQ-0f5Y!akS^ |\D{ jG 'r-rZjYJ֞IA=p~@dcf9uMpFlO<:{/==ۛ} ,Kn?E[Dp 4:q *-S)[ZR`pIWlz϶ܠ?YsT>_60 )ĺPx+'<.kZ/;%kj(] ?[ hzhx_ 6SbD͚d=6*IG,E.{g j(2]"TCEV̌ǂu PIuTIM F,"+/~{I$O __Irޞ <+\]u1a> M3PWqjиl?.- 4f)lv;&v0]@vv_E2o>tzf9ZY|{j#U~goK3rHA('UkvY?4A~QYzz)9 Ʌ$(Ŏl-V.}T Rh/$'a'l6 d8ei~|91qs45\1Dˬ4ޗ/^mծdTʝ(EY`I#%Amt֞^n#[O7kcIe^^p @+pOVzP/>HN/GE娆Ú_ Mlo36魣CErۉ쓲w,l"b,:o=GXl]a[ #, &j%qUZܧڄZe' xQ ĖmVIxKMۖQ~1GG`] ';{ Kb򊼥;);CJ_mYb!^'~]/Р\8:C8cKRa˽\ XШ:pA[Q0=g5#?uhf>(!0C.פtiΑ^]M.<-F3O:sXz E+_ _fqmٺX ӑ zԀF3xV۹ѿ@gv Bv"LL>(N'|l,)ud%/i$Qp{U݌@hR4xYT4!.>0nm鐟 #$c1s$ObK [@)jFcچX>f1Ӡvg~=yK3r"qDo@4odY選Ej$,?#GD @v憮 %WE+AN7~EnZ룔0_cmphڹãFOP2c82PIL'?MGq4f.fx?3Rm;Rg(t%N;_8v3W͍bt<ɦǽ(%kcSh3qߵߔrZDۭge˜m9@Z~?Cu'G͝`T6Uf1wqcyߛ>AO,8{Iu ^;ɖjx]L)O:(tyiB«ɻrxZ'1wbA#1S4'л,/QIB=[@+basQ戦]Eʛ 5(g2GJ X5-9X[UO ~Oߨ(xWsB:^vm"b>T6Qؕpœ@4t1*tH=C=%+%/,$'VsOg&rI?&'A؄5F=@kW_l3DEO\@Xf“X@ JvXf(!DXo7al^ ;=LĤwgh?(NXؑG\z @xLW< 4$!qfMRAq;5/2=̉򎦉}r-8R3ӓ# GbL؜~wEyjuReZKϜ\N:L$w7}]? sBfi+#KA?=,˖](ƀW/ѪΨĂfٴF(rQe[HtQ*8@k#+$ReiB~CA]ﴧ2,+_kfD1 uu{;)noa(LUJiX#:׏7M/`귄+ch= ɻ#[S}ryùy|YәT cGi p[Õ܈D[~0+6ЎTe5R|4:rxX~3BR.bzyLGڪ?/M':3 wj &Oaѱ?E;LwUů ܐ. GϬ]u/+P2=W/0e 2 nF=-*\JAV >*!u7?s8 7^.唀&9ǣInfaIDic;+ԂmYRH%Vf_Cֆ*wi೎zk`S&qngG62y^ɵd!l+g:XM;ԕs9v_bDEYc(D({"A+&w* ׵=`HW3b߲AP27ǧܤLEDI)Cnav0rc((GMD@Dx&ص8Psy9' `\EBSӐ5 ԥ\ŗ4uЩOE?u#U%\uU74-;4>x,?e%!N&kZGS!G^/] tɚT!cz\Knwb<^- 2ؚ֩"+:EB3ߦaJ6R۹}AנƅAݚ1R5B~b]+C,dz{.`>j}1.deNVX-`g38Pba 3l.=Mf~eiK#%kEaT_™M$m i==-Ml5Q0#6<Ш;i(6zn1Joټ\kAD 4`p> d.( k /kV{O#z [^\䜰;H(j!6O<|iWEsS"[o:׀4NN!\b$kn=有1H" B7`nfE $Eۡ'z  .w1<8ܐV&\UivF+`Ww!H޻eHgh@G1֪ZU8?SEM~#&`.U0x%ʅS][e4;e2e(5YƧ^&ѕDfn/+dΊ#FdMc0p@@'nh >EvnIJt+̀7݆ u)d% /J9̱bnׇщwVUy-gGRX5sa=K1Ufڦ2 3}c}RHoLʸNHӹR#^_5爕Jg|gQ#ɟƕJ; 7p -~4ZoQ$+J--fTo;/ $ƪm0a BK*2b~aZcW?ʹa @Lꥎ}=AnJe3s(,ho5:pܥeěI8 ._1,g;/ZЙEWo F)~ yYO2M!5(k_>&-0^$)4޹S69[-8O!kX4ш<%Ծʼ y,0Uн\wDzeIzt(5˧뇰6*+jRM]رq^MHD%DtiATD޺Qt˯Xba{8FȾrakd& G>X$R`L lEM<:<ҝ[C+oZ oi1RJMЙЃ3CJ6I3MbED":'UW`Zm/cAML{+f}|!x*P˲tg@3o]gʧv&`f/`{\vx ŵFcOA !w^^wYpg*ɖ)y<[?_wV #1?n6ѸҎ_4w&|ޤzBݭk~ $|g@O Lc[h{?[f_9PߊE849Vx˧m/,߀O;.Aǽc.Ҫ{`p2 cS=Ke f76)#5 O+< 3aخXT0E)XoEft- U1֐Cr%[IN(@U&k&HtKèG#:ăB VQ)ruh@؁aS0C*fҁjaJY?-оD!h5^Gۧ֔m1ދn2̆/L)4l%yLL36P`@` },䕱~_=D3,ۑ= Q@V?U!\ gMɑZ9%i=/D7޿' Q:+\{0Ơ\!ƀ Qpas4U9֖~FX8#&I,䝖Lpp5}I?]I׾9X=BFEݯ]ƈ_ZN;E;"tdGwhOnP^:L_e+R0Żd%)At"^tfO \0^z\3/":f)-yBD)$@O}Is kNw hrgq.sȃҟ&IC/,[mSJʜ_bPcjJ֠e4Pz&d]#pkh S̯myіREc֢mDퟏSڗO/Q9xNaXصp:Yh <2כby~˅ :bgg[nQeZ90KC8=c&& DxH J9k{>(*G Իe i_ 'Ij ደZ3L?@%sMtϔ,ş-!~(PĒ ׅTT>ߜZwaNգnHӱu %tYg?n/tie׭ߢwX0UOQSj)yZjǾuӭCG_vjg{湫p-ȗh!D<ވZj6.;1hT$P6?  y=J)՜'{lzg^(; higaXw a!hؼ`(.a^;ȧ3"~ GXy^PXPdy]Rƙ<Z@{%鏼y]-JȐ(ϺdPY+^O=1 ꛘjЖ;G%>J9t X9gq`Ycj$:bQ裾4"FQҕ٥uݲ>4ق_hm!\Jx ?hSҀ@]?Po=j\tNcCW`}Bަ X5„߲WU_r5I`>-pKZ* }}+ e Fw@/P84Iq,6tSP}@DSWǒE}+j&zeHXj#ɋ+Lct2$*{MWܘRT(. r+ZL|jC4 E+4.ŐbS! Lj1fh0ܧDH;ZdYﱖH> WF }LXMPhRq>Vo.?@s 5l {S`: ][b̑pYg6 , ¶d+f4Dl;SI]@:DCh#f _-V*Ǎ+qEl ME|G-2+9>N@o]z G$wt|舂_$nt )_(j IY A%;.KhJVVQV泂 :1a8¯RHŒY5j8|84O27w58;j>@V짅[`^82}hP&xJբiB L_1A JL'!`[/+k5UyBEJʒG p=~ڠ&A/mx67]q|(Mc]۾Bek/s~E÷=PTā<ټ;~hvgFqv@65f &M ոpTo7n.bbh 52>Yٻ Y9 ਗ਼οE͹MpY]bt9Fs(߹&}/RfT=jꌢ`YVȣLJks-䫸ݤ08 :S KGn'%D|. rҏ:\>) 5\fn\x1)o7fq)T*mB:8|ى$%bA pGb-P/;Zs(?5A6\l ґ=#f\ m>,I(zCWd*uŞ~5pX됽hPI@2O[.+ؾ7>z\;Z, k6}0wA͸$H*24WiK ekE’P D bt~ǚ &2%vGͯ]a֑M9L~z^Z0DKq;(Bpqɾh`9Ǵv{LvZz]]A #=W\% щ$G_c(`׮lj)'dD Zw !X:]QW40vi~ n/m5@c-0;lpC 65MyUskP8~R0Zdh? HN t|ypNt_'t=k1W OiʏMޒ1CށO#  Z5E:Z8Ʌ0J%CE'_ƲpEW[q4֎AA1iyV5q|+&ve[񪚂#~cQߴ|?)Z<9urXG.w .{]t@Z4XQCrբ͆;f$l1MSRZy0]xT xhս7֯icGa(7yye&Xj!9?M1^W -atc]1@eyB~MZ!*0i9E:t NOg@!'cIM`"&9޴M+$# b?x}J%b:8O?vU3ʄ#WyGQ69CSFr""eC] bZ,.]=Qo!T!g:9B9XMvSi$Z"8̀|hW27,^bfAވ` dyE΍dJG>D!ZR*-ōN)A7y7":a`ilC%h(b+68ASo]je|Ĩɯ[ZK.2%@*[)A,rd1b)sšlfkøӟ ]HLut8Qt,)?YǸ0S6ǂ. 32Ofi^(H^ԋ; uiF̛zYu2NSDХF%OP~ɉ=R kMU9V^^fw2+j<]ѯR'Ϝu–jVޱ .r.p5'~"-j߯3 ;>D1j{ȱxӳAh< zh5_eB[N cmF͔㳹to_pUw=Lu)c[]n{Ȍ)Z6Ǝ!uW ¡B1ñ]~; IYtS|@h+d;v7%rGvTg'z| P(|u輴L<Mbv֙zu.X[)svG@϶(NJ*l䭶1y P36 t Ik8NJ+hC"Y.Zw0jE .BR0lI" vwo7hODҧG9zZ<%,Sy'AMCD= 5*7* sz2D?LJdD_.s MT5J~f\- Ry-㎨i5hE<Ķ!k0J0`d+ aÿXmPqωREB픥~Nُ q:R9n;a<5!gƶN_Fp*Qg-Ӻ2c)O{Y<[OGMY axbs!9;`CJ/hf"lUq9S2ڇPl7[vh+kklL=ק 'C.@Q۔Y/2/Ebg7% ]=qcɋ_)o&RoWwA fN8j/zxZ-cm`4w_ gjh4k\Eϰ8Y5zŕY['0iG:gS{p\?)E wvwF]r F73i3gص݈se ib(?5 Cq&kSIoh6 m6ϹDUό 5`Ert>e^G7߿0!=7C>o*4#ݼ15`_d vzPy~zb]`edH|:0 Mu?nw1W%S_;||w覭b/0-v#pn.WH@Lj_sҷa>3װނw?u|(/FeƻD5§aPY?5Nr;熅$0l1;R mz鶩NR7:aYK)8BTgaCwUJ3%} tf/`=:wUkiIW sjIA>m㺿 cee/S*՟VYeH(5^ @%4֔E|Hĵ>¬GOYe6ptI>Z1D͊ , Gҋv,n\sx3`cuk^!Gj_k:&>NЮCtB.ͅk;<}A/Mnxx݄ž]r6+1w̲)0dÖ $oI@8tE@ }qVL{-> o=ہqbOe~L& ^xOD(=^Er"a'V:Ж-(HfsB]>ɲϒ#dX(Wz*?s >.5n?p CfL甮NiTi/4v,5F{@99jhD(7Iֆ#'&r={Vi o >ZbeUI~Pg z}ļ)epkg6jTGu/.缒7ケaJ֌V ;xV!@WCA/O=6(ZFƹTwѹ̡-Q1gEE +x\m{;џ?JLFLD'jX3F`MK F+yh&{Zjx=!^ ,h*;]ZZc+,{ i~ixYdQ#L.}'7I r n :؄COQ4&vbӍͳehOݞ! ;Del瀬ȡ.τiVbRPYh֬j/\-PY[u `FL Vjz55_9[]&vB c*ǐgu 5VxYQxI)FϮyb 9 m zpMS96ԗ)i} G۳Hssqt9B xwmD^-]t]I$:wSF&0w %[7cq&>dg6hna^A0} l8/"Wq8Iq8~1Jǟ*V_RچHGnhxK)D=>pQYʹt|}@rq@̧nA&]x !l\)1W_[-r* 5\j Up5ݰJ^>{?؊i+vCϢoccص_ xR<3M#)D1- VQ ycU%7ك &B 'p摂 ̇[lfak.]"^aF(&&M2W!׉w0u̹/)# 1M>TU%"QbenpKr?,^cFΉ˽L-P[c>Ws_Țg]b=,DY>ՠHeʇ~xes!~pm(j&zo%2\r?[?#QǦRru"b:N('_t]%j n,v뛥Haf DĻCCk28#@RiaB0Nr%S}M*U`YFbY-~At@ʷ9-O>H0ĆXZu\28vSGwOj\˿,q}Q߱VBUCqt$\m0T}8O+#c{ktWIxGC mvy)1%-A@x_);%n7ùx(&BO H KxeCv:ɊsVF i#goGdbГW=ufrl'@񿏽.QpӒxӻ*h+גfo6x^t•M*ئ!CӑՄC:fܛ8rp}Qh"nc(H{I|iyƶ-:w6ALQBQȍJ_1*9kN1MC*t V9OE4U6V!<)?4  rJZJ`j/j~EpQE]nZF`ф#*oDKGTiӕ>p*P#F& Ǒ=Vxg7$ЕI|jJ#c(ߗ5YH9lJ5Lپv48}1G20NrֱA7i 丵x\`̢3powϑ6D {zonj4)X8S8>̨C^y٘o>XIsY֨01~1=vvuo_VȹS;!7H>Ui}QEWp_l<+NU(?}ᅦƟ6kWh&|{9;\pG+`$L.$ `Л zOa{ H.윺pfAH:m_^PL.4ДވU4ZNz`,S>?be=W{Q^jk 7"E %&[D6w+BIg|RKC}OҮJ>P>̱d>Ms5f.jo+xBq. [AMO3r/5D\4x-q#ZT5 ΅ꗲFyz]IejH{I=ZC) yف=qJVJ]Jܩđ#cG>㝥J1X~3#gLk+ZCEue/a.vDpb?JDl&чOɔNΝl IMvx]"J27Dwq N'\"7 3ʹgRX`=_LtDS1oG/j9f/a"ه7a!5P+4Jq9śU >DQflja60xhq'-"$4Aʨ IHc794:O5Ubw_Αӻp| V;?l?U@&ىbel3Y7Ko{pES4/ )x1(Zf oNESMw=! .1x/&MG'V>f2ٯNM|&~Nh3?'" em |O|FDV35Ε6յpFf f{Wrd2`"?H$NfBq.R穷=ij R# ;g0Ne@rvrZ^ls5{PK `|kCf(9բ>8L[žI=A7a"ݰhaӬu[2 ! AB 0BpQFmrH0ner3M&}Aϙ^̜z%؁q!7q]ao̮A?-7s5qT'Ўs'`Z~^xG_6ozWy"^1s4ȧ-bt; W@Y1d~GAoQ8@Ù[I iw948>ڈƢVK鴻uiJ6xER_p.(Smz7/ǽo#B~e)7rYd;1  iŔS/%2X^ztԘt{lzb_5.RB7,ww#'-<ׅI^vNp" mH8G@.Q?G]v.kre܁`wh= +@d]4ȉ6Z)$$:]NP?w42<E8vF=;{moEV{30,u4ۙ6Yhʳ 9 %ΧlI2+,Rڳ"0͕~Ĝb*Cm5p+J1Wy?}80 eå 6OK*\Pȭ`R?@}Pb^`Xո  FnVGZΧi٢~BI5e3{&Lw䔮P@xǡ&p]i7_rׅ|ɣB̘NlBZTCIt[.r9])rjPwJّF& ZUZ!,82qO2/iB ryΦJ!&|feV}<cC!e^C1h=RXjZ)Qqt-˃Y*7I|;c-ŽP*;y#'sγc& ^Em+p)!#;fX, )/Mf7'P#z,|ɸfSȔZEFu8 g4M (j}Evء#SDSmq2du)&c%VàgZ\17cO@Hzy^ YADc'?)诉o6 p/&nmfnlQ,`5^I=)'օ+\&ep"@vMb'Һt֮XHW]T] )ⓘ:(WM++TSL Lp4~Z.F+y})t%R9@X2 "˰S>?ȓ[)TRL? G}L-/뗰{ƿ u-hE׳<5 L}IYSGV)rgy_WNi܎HoJ'?b8H9"ePX;S[0xr}yB^pC]~d ? *4&Lb m?eq4_&Lia'*N\FQd/3}iƽ ݣpQ뫩&1}I\nUq`&3z}Q#@oOsD':ɦ&o΄kF//(1+رTŊDt_dUgPϚU0do{RGk WG=4s}K^sn?;gްJRLlvпqVJ0@y-iC2aFVԧ(T|] cN-[KB@O`G g$_L ."~ވOLH`7fL_eY C /M v:[sSdz{ciBvd茫y{FyS5㙺L"F_O璃jcq2;Ӆt=(|cX}I 팚$:.oc[P0^ &t>  $<5B[Wޒ,|sVdG՜eX[Mɇel|/bN+`8H' azDַz֤S6Z%vВȍ)kn}pH}e} ^{5{˺dij6BCSL_RFp#DĠr~ztZ.uyvj\^|}lڌH I"~1ڡ%ס)Yv z"SN:i rj+\ "WyS L)łր"T|GkWQo~뵅mrjbmq?xϯ Q!;lяN82=NL T;%Ȉ {`n#pel7 D޷nB5vwVfǧ w[nĶ\'?c_/tY]U ΂|&{Z(H4˚eŔ1bׄ.N66%Q?϶r _clŇoxDNt_,]EE;-Ԗ9$o<TY+Xqwq4n4$ Gh3+> ZJ5f=p8* ] LTT>*0@`ƢӸIVGzrD_4岲"˕$#\ȓ‹OSу~?w ,4" d6%e=Z~N]JBgf`n%4Cdty.-D&AG鷙bc*r]2`sD2O%?*)n\=ppvd$!ACG8 MRneFY:t dwt"ܜێ9cX=/m-Y~ lDZ3&XeFQX=BP],@sZH8zbnl6nmx^৹: J4tMVX{D?n_j,' "-!sWOOmcFhve| m4G7Ѳe/6* >_t UJS [>3YU쮇bA-DXW4B'Ÿ_sQN$5\ڀi|ۡwVQ@_+xu{6P=TN+,4$4 'H@T5]g k{v\Bj eytYJH>]feU޻ubԷ&f%eqJY)?'O$ҤGZ r+<ң,d Zf'16dC*NW@VdF Zbס5lZS=Pwe3>έ#QlY}gІ䳎PF.ӦWp)YN5"4[Y 2{C8WZ̵Aԇ;"WH=ufB:+38a)"SO?w|y`Ĭ=qJ a$dE^3WȻ'jǜ\ 9㓈Fi49v΢FaԤ%#5] gV4| '%˕!{|q,dKhAfޫ)M >T8Kv:vU)0O:d }h rb,oH02j|R ~"Gt쎧]^&h9ƚ32 YPv:FȣXX|Fo 5x7DEWL+Ph3KՀA 4`L*D7˘n vrdž!&M$E6UKᇏLnI W //o;B _f"=fKR]L ;Gľ[tjwIa كKfK9XJQ͕ !@_:Wa+ ĩG! wX*u2QNR{jtiwd9/FcJXqz_,QB"_i{I+w"0'yrU^R!fvLv|{Op|8."=֏R&ww|F<sD᥺"5E0јxaTm|f^Ek8pי.d[EL9]|/8,FOg"rCt:dH诞x0S'Q 誧 I @;==sm:-}ui" ER# T7|h%*R=-{|K~ ,ҳp ܫ /2vyD9bNpb&wa2Ւ!2ۉ˟A OL [Y4ZPBWe $mu>ǵPc+("[ou(E$W =^6bBiWh,XЇݞMإ#B}Cwx=>]6inO8CT }e\hݡh! P;65ZJr kh E(ƣ4󇙣V]  #VdIJ.k//CtYƑ;<'E#co"{85'xesBgi*ǪRGpOC BPlπ4&OkY_~]A/;."8`%F 20GK &7f=,=5-~XݱWCT* DD,(g{VƚK<'vbo3DGeO@@rը,cK#@*OH-}nd?^|7*X9TS"B-EБUV!x6I!VLy \b~wKKA$( ;z}hn2*w)©b08HK_*h\4!@f34߇mg:s!{dLlԃRE|4,tMePkf ?Nsr̡ll΋ 4bcidF~\>{ DՐ Q"2s)I&={Yao՚qFԺcR~ )8{Zנ;Y^uGaKIikEv/hZckW|GݟxhldMׂ秿{}n{Z磽2~6#urx3̩sy,1N<6O R2.HZRGN('[HI@srNFJh g;>1BZ R+3@ΆXQ֪ &BhC焦> 2B-,E ό<'S%ڼw#OķEwF(GPSc-gaH0HXBcKKa62LcXy`MU'uy18Tߜ,{l+Pg?Y]o4k3[ A:LӇ;Nx''J?*u|( }3)/XN b Ӂ#+:Y%o7%CXN$ 8ɳK 1kg([Քr>G#_ޝ8 3:Z@7tmE?QeO\a~x˥xp-CQ3Lnl:G^Vh֪ND5̉;RfbJ|#KJ78г-Sǒ)#OJ]4NXwJ-F`e3,i"_iOʪBH\ӡ*|۸c[0-.6ީ!Z36;P)(y  @FR͕K:23U5@%]ps !RV B@o?GG{^sKKlDsm#C;r=sm6Y(,e֜mRZIU2c[oRJmb5Y/ԆgY ěA@IEJ'4,73Qxn{W2ٷ.p1҅ ƅ<bwI–"em_]@/e5⃚CT!N&=Ľ+z8T~CӸᥔ`t݉P!Jo{ '^# 0ڜB^_9yDpNӌI,BD~*- {YgLn+ }Fҡe(h-fԏ6ͻͮVӘ4 n 21YOQfta&9#7L -R3Y.b2 Shs$3*$eQNL 95#^υdjA@몓D֪w8~`fT}gN%ד0ęAk'.(=?ӟw# @eψ&sJx֧ Bjѝ= X5#楺r'iA&Ëh 3'/J?ٓZN rfyd"cj"ܝ`=vz욮:Q@Wb&wYEVl|jU}RA O6ە@C繒{R~2䛟;x%oUH6}8WiZ\u Xp(&>UiR%,>H7d&5?{7;{~jbd0[g$XG\Ѩs[*xU43][BMM+o6ɾ>4L?8CKĈQcWDCY@jz'\PQ𫡅P?[ v; M Q,X8xt!dS4sW]⵵<@pD[_[T&BӠ_oyK79:_icN uf0|PБKxK)Ku%'dY*ēF2E" V\*@3>^\i5*v dV 5f}_ $a`4nǺSInkr]V(os߃3.S j*iA0!S4fz&6n 8uĜ0.Nxqُ4k$2|o4-"LMURϝ&Tl5"z˥tXA_pLy\6~bT\ߵ4asʵ&0`r}g%BwtI"E is& Uv?@oBD Z8,XNI"0Jv}S˳wD%gjh>FQf G<^$Jg߶2xaZ >CVH=~Rvi^+k70 (# ~Wv[> N"I# zJF2سٓMqIsR/.Is'!^<; Wv lv m$Ϸ"W >$ vQCn]F{*@?\u2F{aXoO|þ.&ry(- L% %r7EޣE5?,T9K,ZCmrBXqj@.5<%Ƭuzz8TgS/sS=)Mc6>s e7oP.NSj٤\kؚs_CQ}#<&pBg|TP,W$+S~JN4D&c,o [aF\~bϋMAgkr&@'Ca U1̸! oK6'jQ -zǫSTg-9rYJߓ~qBnp"q[[b6fhͥ/zJF/٨-k(}]o3 PұM"閁rڮd ${w;j?L./$b<\dVs8/XBn[zW yA[,o8^Z+֍V'Xo7R,"S"h.:C=2jOƂ^GoarU>:kp5錱u6B)@D+-H%>n敪yEx(.ˇdi$%|5_' vDs58il jp3a_-A=Rÿ́s7`{O5vm ܞWq-=C::*gpP?i #xn:)\/ *oa LÈj Z5{KŢ>R iPxDR̴7q63=_nc8`֫J]Eǜ1f!_OOLN˓ꔢ)FAM˫;RHz"4 9tWE|03&ۃ_ V(%3 gU2KRWߠcMSJͨRǽfi2ce-fߢʥcA]my!9A/nJ⿑"WÀ#X<ݭ-g/VH"}]u9 - 9A6od1bw$\Sz;okH{'5;G1RMʦlTyÈ 3:Q\Z@2r|zT0Aϐ -,YdZ)4zj8$([l' 98{l,ISwdjbrW\@P9 pix,6&Nt?|;{qECĊ`ȽƧr4iq$; 1v:gH`i:ݻCP#Fvt T̩w_H]@]\%BvS22v[u;k{0}6џ>-*SW&?+1S|AR2IB tp+K"oDR9*O?@ndd=_Śt^4IK0/Ly1>qE~ZʉA$m Z<@5J@YNث6Xe=;vu>ɝxᫀ0`voc 7oa\WeI^%H;3R0*J:PR7n_wM`%NCh>t$r ofȷ^&?А Ŭ:y',ٵ'n cU ;@uP7sCٌMRO rݤ2"㝍 'Sy|GK;h+xJf $:p\an2?۴ B1NDL&At< tg"ks.*i]c"﹢Rb Fh#,7;wC!vA~{iLlRH#hMli5 :xm.dkMɲKaԼ*mbp*>Z<0 h$%–1pfFy\4@ ,56^"wzx6@}>':E=%4'1p/MQT Ns,׬zwL}zfI#84nࠫǬ WvXrqq?bl'Yv}F, tb1_4 ME($ Z"r (2pW* ٬l_1Q_s~5d-v&kCԼ*T* ڗ[H(WfR$~ N53EkH_b6VEʻZ}S7oCKMXm%җW5{@®Uy,@`pU[C ]&.8POn-ݰamV~O$#e}A F"[ ufX^A>pӫ^3 zauGMP'oNrRUwWT3(JQ19<{[rO\#,O|}r Z'l@sݺIԪa]\_?iuOX(DnA36[h.-ʫ?nOg![e#/Ƅc\hOT+nl6lIdu JGGYqpWYӒĊFsf:Bf]CnV:=7*&1RY9/\~hOt,àbǪ Bۛ@>_<)5ʹGޥo"r&cY~GajwG"m\gE):kD⼴d}> !tFp<UAoFta ϬkS&^W[ٽ|E1sT$ܦV`:@@ئS3sw{OK0 9Q4_4&q=Us23/S\RsY'CPXy4wN!=lw=UAt(je!ȥ<^kxRXޮ< 5WU0+;-W/`$.,yluEcڐfǑ\Zp"i[aV#wpk]| jWF }mrL)IzRȰT,}b0)1'óN3іtN)Qo8;7! .'|0Rǂ8cG/s5zݶv2ksH[QdSe\ؿ[4:7 L1Q [ uooȰѓըZ}^³clZ6 jׁw|D_%ۚqb.I@6F:N5k5!T6)|Cb +5.~[pirC&RO6*^ (2 )䥽X8\N!4ʸ4䖢u5FS AэY^  R41P.#e9R\a^ul k϶ضB ŝ"9J0ю0]X~H&I"p3JGVr !>+ m@=E" W;5W͜\s6teISH7;a3\k g[TŌguJu'|;!X 㥒|lb땉_-s$~H\S0>u~Esuk;  =Pϴ O7mllZLnDe}~!YFM\sU2hyclbFJ94MZ[xC#̪csBSSqsS%b{nx+{mL]F9b@eOQ*-e>QJ $}RH1 i\Ҫ=?{} ϦY-s5ŨK$('~ Te#5?sic\I$\(F/e*L|NB$N|H:LpOM$PPĨZ< H+ Ip۩XjSb/)o#4e.]lj/֢x{{x ZwndXA/mKY;j8;}!K.(lO\"F|5O&e?Zz"(sDE]d?¢^5. ~fi=10\O\7cﳥzؙ4V?ͪQTn&[CcHs<ϑpFoŔCxsv^ } Ёn;wˆ (7\V?\o_}fz ǯVxncy>s PyI%op#XV#','W:6/pT[.H=y]pchKLFz7G%/)9U|D"ui4 Ya:r*Sj@&ď4] jx /,=Zf09Xb4cSv3.5m3|A^l1 "bcF9(:֔6ZʗjrI.D s4gג2 EL Auo8 )O6Vї>+~*$3zqMF@ǽ:nagؼ_:ń˘=*dma0Ws܂㵣q+vj2/87Z5Rmg2Mw.Eˉ%R[>}+H^FJ2w4Va؝ղFonLLS C=W[I5p̃<] N7uXƼy#)uf$?R_ ZJ ZRe ObblwׅD$m[eNdWր9`Q\ } 3-uTIy tnڲbjGrDnn,8\0&b;YqWw8;9'ygt΢KKtr+#-oKեnR揈ZK̈́T1yljK?3a+3N#qeWDΡROcNEZ}b;_kmxG[!؀ I^:aF7JG{?҇Ue&*)xD\e2Ҧ)4=&x- t!DP#Ч0L?'WՂ []Kg*~.Dm[aqo-M?Coϻ&ep 2Cͫ[vA?QW}u_Ekva?;!ބ#y}Q s tjCECmMp£[!W~ffm(WIp,߾붡Y 1EdأNTAmzP2m=]c\IW|A"jy!r+uoʈ:sXwTX=eȣLgPf;)y"vh8mӳ7cW%Cr;. s M*/ڎySP.j`n1 tU 'Cy+4^7 f=oj4CiA[Gp/]O^$H()l%daf|q?B vژ3N^-W PyQ" ].`9rU fm1y"?r|Lg~|6(w,L4?`1Se+Im|99_Uk#9De-T;bF_zVQ͓A]3|i7V=e] te3:`q0bA6ujiFi6]Eu|BW /d?՛Ru}u^`kY$*D&+8(H Y.!]Cu7q~6{[I,#֗uWzg5w#Obb^k(}#'N!S;~m>VF#aXvU 9MY Uf3|lI}wjGHzh+3ME;p/ _i*# 6Jgu%M3gXH!-fپf RtAXon{<"<ɮsIDwp0Wd.:D<~+t[נ7)R#B,UߣWPoCe$:ZC^S܍l@]Tu/4&)27vBF Bg_vm+F/ ̪'Vj<M,{,r#Іxt-]D0r{nҼv+86oFļ&~yg܁]@^ G긳~uY)|5U^Phj9i5Cup>XR%i̻bA@]izf'79:yl^{X j[\ 5"o$ ̖ImO1'~u"uwj460&n -C>;ǹBܝn;|bⒶR?n-$ 4 1HMRjpR ̸(=r"U ԏPHQȢH5@SDO`,=d+J4T~Ħ" +g"\D|:B.op`05 L13}K2=7EX8| =: J^zuO\3H#kF~q\V BPhhMP< /SGa=C f7..(ZgWAD4d Scк$ 9|a)1!E4 ?zāYҫIUgCegں 83kXMynDŽn7/r?Z2SusI~1PTV5W_S̍0 i˝4Z:(| K+O]#mcڳ?0#@g)D$JL>a2(ãڃEEq#!~Ϙͬ5%ϭlqYd %=uO'须vUDžYlnU~΀_~OE(Ԥhe- (T}U dg/]47E;B[(*诗uJh+qDY*ؔ4BNt5?ҋ?0o SŏW>\}a?Fs5t'%N`oc/2@|hWyꍉs*}K8.]vW5BDAMT%cmfr# 0ɠpgcɲzi_$@xrҐv+ 2$`R)|LBNp3Z;'d8S@Y 87cָ&~atG(|]o/N(sY֭:iG^LF2y۠bzuL{7tr2f uM4ȴZLAb@vX2d.ҫ_^`  \&Hsvpw+- ]7s^!ǼBJئ"]Mfc=;ohp)G6tnśrigݹ^71tܙ%4JFLp#}mjёbsiG C4SJg8vtM^+?Єu;?K1tp>)lu0#e+Cf'eHoiفP-=/F @bxjg d:c}XOv| [)˶; dW؜ 3Xrk'^-p"4Ta䎩郎ԓU8ޮ0L%^g(""d9؅;4 dUPU5x Z-=u_J܌j*,߾2՟4&`J* Vw\hD`& hHBQ`rG~"p["3S9EBN1/hlZì{J8zq'g)~?IɌ˗cR㱑4׾0Oc7Z;hsՙC ! cA 7%ܢ"(##_HK'M]lTPA!۞Kv42HG"-_Zq"h^8*#@Drm;(DaD.n!C/'3k316l6R{"HVpAWxΙJ UK;֋Y HDn:tQcv>jĩ;˒DsiSZWے}!/i |c20 ~,S531 ~G@]~%Z4Zb ;! `hU*: L qk՜ ;6AQy;`Ip}~`Y88,F|:IR*/&rCy:b O+ ۛ vHbma m ZMI"4y>A(P]X37.rk]rg;hOۜ3oɓNABkvH^1{DO-DgY,'nBq3['ӏyBn KS*51t 7=ޛ _*Τ ~s^h#hM76;&l|@\yR,l.1v $ujAa$>g>"OInl-OBc5?gGQE13 8F [3P!r-ABil\.F|g%Λ>S!"j BI\F a|Np`A-A_)Y9g,c I#G=7ۑYoYp^`W;0P ҳ83ާT!$zz§_v˛1FD2tf0->yN]6C.C'@$+HMtb| Hy3%J1KKi3@[U H[q~ ɺ_}jƟ~"lꦕÝqa@Hr1-]YXA&q{ԡȫB刄"O[!43ͨq d̲/V 1>KpDk*h 0eEA+Bhz!))wm ٝ}!դؤ'h ;/M /o*"Сg30=P\7CB @T;*W'>L+]ۯ/C-%^(8~>'9J)*2"/ 4,=<-˸JQAG)QYO෼Mq?lSwUMy}zА2J3H:>|,87-)G%2Nu5;0$,a[L8mO)u+c9m.C$]f/@!KDg0ɭWBxb?@IU rI!T\qZ5m<{"NF"f)X}L{G{=L¡0oVgЪR 3y*uYD}Ϋ˃lчeqXc1=wb~N'x:@ɈD$(|r fh7ujbbM׊AIHB Q<6@ȩ~Ej!OWAO~yD}ㆽKуA '՟] 型pF(qOC&ʼnLΊ6}"m=]t 틼o7j|_l8j.BqE:Cuc.'A5e~ںa9S*`PC\qq|+a=e\~pꗥ#Xg>Tn`fHA)88bHaͥ Xl)5nenVu=%B/5a8d W')"M_ kEx0k5ف RʒZo>G08" #+6wg60~WR'aϳ5ۉ$,syeO-f;n)b_q~jFB>=n?H[Kk='#0Cry[wLJ`8U? `rypO3\+Zq =E;_;L+Ts >QGpW ; $yONIz<=T_$Ky{qkHfnt q0!8tсg`+F/fUw0PmKc sS׳JB\J]V8e 5},Mz`*thtw[{T1?`I)I)7 Ard]ҬT4uuFƹoJK ŅC>tlw^7'յ? vb Ʉ/M9Z>d8d'%S_ IIdk8Z>e'RK.oB6z? 7/6xѸ$Kia ꅽ%5[ru4ݱF=^o;{Yof6(噓}_SjH\YM֛C0ڼ aCtP P=I/=@+k&vC佯( =gr' = Pic3'l+(ʚӾ݅XP(/ _uQH#Ct3I \^(7'M8CF0^RkU޿t! $? 2 ?m1u^]W,5J2 #\t;4e _ffb)JRS܂ /S5S!c 'z6 9OY4†~_g-l u6*L0vG{mU< QTa\=N$vڼTNO c{uȾY-/$%]R:Һʽg֢{s#[H+2sv njy%,X>@w+M/qYlo⸅.";?[SZs& 쌤2̖-fjxpW\WMHqZ䨡k^_ʺDw5M /34c;ީ 3UY:[ >pmeQ<¶SGsªWGGjciՇ$X4XM 2!p|}K¡n*w] պ n|&3X@%R9mZaWJ0a.UzLE0I4/V'F8y3njS10Ǜ"3ᝢ0iZ0\fngtQ^ 59TBZ>QU{BיxQ21RBFO3]Jf"M|o\PwQKpz44L9<(ȶ真4"$ kZ㣄CeJIJR^bFґl_7و`ɍC=+nNJUzto ]_^/H ?lI|0βz $qK7_=/4I BG擬 Q1s[a} &}JGRvay]΄ԞxN'4YqְNV H?8ntpF|NƀYy~9^}|a@~)p74!^XA"uC1[zAʼnNSz` ;,۰e&߭LcDp̟?5[z@!fɤ;?²YrX^ad7)* ="F(QB)7J̮4A^랏+́x.huDr'Q (7fmC @oI&]וUcNmF吉_BEml8sn( ĩ -2S&gC ^g %WU3mcq_cl=j02e!-$p\_)vlJD4M%e? ;EovD>oGӷn*FVؓdUdr *_=:VKT6QGQ!Z?9ŭ\+n6N&W`-mSmrG[妄ޚL.yK) /aY4ݤ AJD\@KNx2Hnӎ54qkLD} 5f+$;:BCϓр:E0YԚ%tNU)txSM_wJv!,WƌV$hO'İepM:XcׁF;FWnd]?,LH63d^+\\Eu*̹Y5NZuMxZ%V~tj.+ҡN䄶z:Q^a"U뼠^6JMb|{ q~ѫpi`ʞ= օvM Z6nO hyK~Rͦi n&xPD?` {Ej{ZpJr|tY7mi}CV_bizBZꝛP gNr߰ zeO4~ݫff}"xc Jكu}+ xH_95W-[/!F~Aw0na}^`<(G>Bo567$Φ~NKᓇ:m؈g10 6{=m5`}.@憠slS7+*n 2Z:쵚Ӵ]{}vvpsiM.% ~'ER䡽 # UnȏkGޟ/ZaSF,K%\[Oּuz`J0(ʔGL'U>]B:JΈD%Vh=6z8$(k2o E!p,,R)%'fMPnK2`,5cTdZ P\Si(cvϯ<? 5WR_x{_~dJpBº&0!D5y,=TXxckP,b{҉N&LI7PNhYs1f"YY[n_#Yn2B;EYNbm0j+֊,[-kQ;  lS!^ )8MHEF FMdPVT!:!#,0Qχ8IҶ栒krQYqѬL20Yu,4zo[x(ʌDFvPc s|2p(%O MT$e-WmIEܿvuiŅörzu<ړP:͑.1gswM~ lw7ij@pkCD|@ WqtlAMʮnCV/rټB1f@O7c=)PR|!r:Z23 =o(b5ǹIpڝ4Q#5vjvb8(3̈́p iT$AX|Y^`t\(gN݌W,A%|A=J(P5F_v$t˜ t[INbˊ7 +dWlm§}>ZʼB{Ol+ZfrP1VGg.6DjhZZtFR[*6a6, խs_Ttʼnfn ^Fƕďψ2eBv!M/FH#IJ)?9[.4*}%tރxb~][Ɨ?@wpB/{AUmFck%)Vxh&m{dmMnk.7.[ڔ1V/0.GnX7|]I#FSD3X ;dPOZ~E:H`o6G<>t'E͞|SR/Zx`4, 0-Ѯo1?ve ?HP8 \36*<"aLm-73@x/ĞukN~'6-H%3%7ĴE-1G'knG\pJ-(XvmUhorOt|Ǎt^YU̯^d:Hv{a0]mHuR=\u3|Y3XEϟNka.Q,<O~},HRINרcU P~^>xgʚ -Ҍ^jlل#@IZx20WxƉUS\?ޛM\OjB+:9\ûdSC!ڿyNޥ;(S˓=\Ks)y𘳐3ZZXq`*`ƶ)$&3_l7M$ҩR J+V&ϣ S?ғdaȣYi/FIoLcSGCE^/WdTK dt?k@L) -f 4UMk lt>F+VY'z@??GR΋NfU<\=|xvv%u66K4>мV^"t.nE|,Ϳ D;VE+3[{|okBJDN2=^) Y4Wk %uQfObTIg 3 ?„%y B͆n8;]]/97R Uj,ӭ!ꤠR |i <~q3jU~tQ؅@4T;EԠ9f|̏<p?MnDg: X p(Eۂ!l$z&RMlz!="4Sf"E7 /h/29b;ax~Q1}BHPMefXAxsS![ʤ+u0`r<bj4s|GƅH7)<\DPax)8#QջF-ok̉?]dQ%Ga;f0Gk'9epYo[赩y{sG{܀.!g(-i6ɭQNf^pzCݐ(A9y,ii:p 3K7:yiVR?(> .4xSg'OǮӬj^Bn8qKJ7/*/be7a"vjaYhzOt4+}dwK1/;LO޶Ĥ$G:{@ ] 6W\g5@ 7E@t~eC@eO 6! k)i9lzHyIhem>AuWѧ,HWy @\"F(TSj:)ٖ0u@:&CR^0VH=i>,)jO QVd oBy$Zޝ1ܫr^x'ΞG,ҭb辐#A]ˣ7@D iClOz,9t4%dqLjVLΙl_eyB>5Xe@ Ch{ڸiߖngOpq NC}fmfʝ&6i =tsvEύQν*4-[Ww<3xBN5ٳQʭZ Z@~n^N, ÛFͰ.9f6,?/a3(pUt׿O$%Xnpk&5 (9\ $# y7(fU' ?.vR+ h:=?NBgSb0{v+TwIm1|ީzyTtG\z$$m,בCQ:߶ޱI3`R}x 9~"# 5mK*lhv_a@ށ%BEXB3Ez@=Yvٳ@GioC>cf` l0'3 )4Gx>l9VlJO@AjsF6h Aaqqi/=Ht) Ӆ*I4T,HB@z4ޞ1uJR`@4 %*=iwDz. 0(cm>7s W6E_؋MbEv4]!7uX dLEߪt:XAjbZ&IV"ΜJS>era&)_hw0, n<"w,oN$[ϯhA&Yٹԉ{ppzeM4>: ]q06f2(xYJz+y\5@&EanνVjX J xe*#A&+` y]xO+j[lwQT3F9MٔguG܋xk/U$D5:bX݌9SF!]$AD[wB舫p6/)\ݞSvz:r6>]Dlf6o~r=mcgh^ 8&[Mg{ʙ.A)#~ƛ~$fI6O$ò;̝ jՍv@'<ܼh/ro/Fj\KI1X Gtn #מ7W)_#@d //jfI46;79oWM 'ަ6#"Y*bY86!,u.<`ÍwX"FMe&Q^S? 7+P$WafK=9y@sĩ`p~ ZNe<|PXFӶ%6Nik5uś: U ȭ'ŀa/U Cz5X;Wz^WVwX\&&)q|Zʏ)VCw&@lF^yQTb/{(j8tD ODW&VYwݡ?;P'KR%Jrq1} 86N=#r6<{x'pEC2b:ԀQ=, Y|{2cG Wrota2,}ixWFtC tyM/ جsDLB⻟5{#Tjr/ǁo{ !6Ǜ_|X][>q]SS#"jP㭎4ǥP8^ހ?\N|* vЄ&YAT)h:Gip3{JAY}jא+N2$x/]{/1J୮9.C-븾Q0[Fv4wܲfװ1gz@G5v3e%g6S哽؁zfesY sҺU t[Ec7)Lkc88Vz fb0CAD5)|HJe%bS T|`~60?Vuzu')St:APSG]cfUEy>d5;R-uޣdѲ3,?RZ`gqZ6_~b)Ki K~(;i*Qpe8>]AW6ՂJJ n:SHչ0a5J+icoCqĮ渶-@`./LCOV1``Ϭїb ,GXw֦{9w[1uгsG~-|5! nAڿVXf]hax.G'T 3Bn\b.?Vì@( w`ȩ{6?@e]T}u,5$Ξτ%yRqKGUĎj*x LQE f&%Ex3r$8Ŭ''$ r5:_Os#Z^~3ߋ9SF`)T֣*nQy,U\8XT3_ -)!Ծ;䜋Dnvĵ{ wWrń #`+t3`zm:C|H=l߹hp~xYbgꡰCg<ϖJM  Up9E`dI%׍齁/Xo˃뿩{@!5;7%>w_YMaFbJ>TAtnLo;} uA8'̌ފ_%= TYky?hD[GڈVp#B}xӔݽzMKީb$Ww!&kqd LӺG jTۆLZoσ}$q?=L Ձ9֒ LN^e!bwN֏z0T {P28|՘ԯ[5*20C[X!r(,cQt>;9,%>8RoPG$RA{̂mhp'ncF:tz:l9^%Nb{WUP̳ 8i}lJDdz%.6PSЪ0[ 7`=g ]*^ JvՋGU&"rt Qra8m͡q8;`3Sq9%3@AkFE^Y۲0jh(9u]TNP?`c]a;P!{>mU #4X~2iC\K OO]vyChj{-%k[[5?s>SD^O7yjuRrs7OBX-FC~sW5a3!i,F^*HJa~72?lWcrsR8B+EBRf`XnK.;/WZks(r v\)nܼqEB~mkꈒ}3sƴq@e[&$V 94E~e켚|lߧnjqt$ؙ5%w!o mxFH|?CG[A<8 V}٧z6,voZYvapTp-dC*/_'.zvfp zŮy<\!~E@ٳΰjWNߗ=G.|I!;P0F'/Op_mk'Gvn/-'s∪*fͰPGͩ|f*p UHm+U ^ ? Dy\̳"f!Fns6.IZ%K:Mn麔=w8!JD`z~3P0y=MWS$\ө{盲/#ogun#by%N|kK`'QZ\c ICwd#Ze@>g]i|u۷ UmhV߅ _AK?BZ*/9Y;!]9*}Rk;D'T u0L x7:#W0K j\.lZ=]tTŸ)/lC?;XZj>jW"_1ڥz=/:Λ,OX9.Xt]"5R-z#E RȈ!t\[4+j֠_?El*зv9}0ܘ6gC|ƙ` 3koݣƪ܊V`we"[0F & 8WwDqޱl09% WFm1Ww[*SBt]7s .xe nsmŧ=+J2:t@0HhSDg;|oByY. x߱FNZ|ܜڥRӮӻr٭[8h#C8js_}@\h BY5˗HQޕzFQ-嗙0,] `LDRmq1]O7Q) ]8ev3Giyq\tC'di9եvHӭ>ˀ~qL_HYnkG029lZ1>OU8REԂv,5 eR]%^/#E^5D|IX*[wLT*Pywsc2%/%Y1 ҂%JR{Ŷ"n"^[J'5x}+T̶z] Zԡ}Hȕ-2A 6K~8Tq\R f~W=ťl`rCmwg0I `cn 5*! ) NveeLyKoX$H&ys\=G"NfT5y5S gL7esICd" u?aCY[ ے uoKIX>md&t翯Be[+W kxm@UZa1jHͺ^Q=3NEczbxa= O~XK~{'sCHlS=Ŏ;A _\4;V%/wHj)~N c0b<K:BWOzrӄdZIwu'iO=2k-TC8!f9~$V $r`>VX(W# r[Ã䌄ǜ"٤f*\M"9=|G 9}q[^-H"[ dvMQ 7ƹ<}40"\|pR=3V+2D4 s7FJ9Mwta\~iI$` Zrm:&#\ Uݬŕ̇o:OEZ 5i&0 ə /Mron?/j"Hl{7^qsuڭrGN nko6'Drڅ ;4Px|!ywODKш Q/6@=ot*Gi~7e`fw0ħ-5".cY6jҍxILJv7%JR2}tbxSI[[tLq[5,n4Kyw._Vn NZ'\ҒFYzk1MW4_ؙ@rW[bŪ̶hRB0lmѮ4m͍Nt(?[<  _4RGx9ЛTzitBMơ }A^c[/&smQ%&KSi ui"9R}POVGtPQD w?"}73Ң/9b.B!gNZBل]M\ 8gw^$^N6GQj"gep,~ođ'^ߒ&y]_v_vJ$#uW[Xj{g F|i/.ɥ jp7b"4",ư8ha~$jT-vB5f:vhqʐ-XjLr˪ FA<1ܓ>#04X;oYHB]b%h0b;حsoZ[5zcM&&F6OU[@ hmU =1㮙z%"(A/|HQYOJe5oK1AR!7+|Z—>;6zd|o|x"NF{Rm aH#_֋KS `/O찐KiRjgw Ok û4;$aH"ϖk0td^ƍ׿Xxfd^"j@x7 u<7 ~nfumĎ'_lxf,VRc1TP/*!cJ*OJU?˽ߐ7#1/JٳhhRz_ }&PZjuOtEǁ>LAyxΠHxd0ozг:j=!M59JL'ϢOiuKSLiE)Oۓm?`6J_0DE0/tr)*xc`)ꁗ~2H5NIDukwG( gB-{9#u9gWRb)O+a 5ؔYc:L]s _dt[16+kdL&4!rnwL<*8umg+( 0A+ivNCh*J( ?uvVq*~Q1Jײ8;mK|XCߵ]R"HFA6V7%ߙ&60yxD)etf^ ?zȕg \f -Y=uլ'r8`J;)р*_YOlK}D)`Teʑ:R2L:䐸mn%ZFtՆ1߭%xfH/R v#psDvb:+ɠ 2lx6 (MweĈ޹}%EϩhFn4m6T;]uJK|X9\㩁E(5aާWHhƹ7&eEgGdJ?M2d>A?Y 1ۄޯp%vzī.(A)YO 㥚h⛦bW2*/(chdpld̩tGtDM0ي)?<$3i(MJ9ki'T=FռÐG#^epiWۤzh)Ckݽ(|j( s Ԇ]fa2f/x|w"h ~֨H,􏜇(};l#4ߓ܌3 |~(q4Nx*MЯn;xJVCE7ӹg6i/M|peg4!V'J#IlsN||Jo^x6:09ZS*LNrq-ISvq#óc>@+4֫& GŖ]} _ ~?/oe͏@gN>a#s܃soV&Ff@&_KUkJM# p߷QͳPZVjk)Iq?|mdr(I_M(s\ ~1m"uO@.i9}x>Aʹ8(:Q86nn0> \jāĄiA t]+`L:3'_rmJ.;o1oYDNDyOX;7 K}&.((nGm-| A7 1$M`N-V2HQ! 5ص[Y"}i9k;XRoPfwD-s-2cz_lIEVY4[AW|b /Jh-D—s}n>W[@mK9&1tY m+b8]Ü WIQh31EVQb㓽9ڕA.i@T1vX:T N\Cr%0cf- ޮ~.o6Ȼjiy\ViX? |-A? 3Qa'w|—zVs>ИM؊#X,Xk(>Ubdv H(wJa_ bL6hk{jc)rEYgW9(M%$co*s_)}7Q>v [~W6 |POJNgpqzX KA%EOt5U /nb icW)tv}-efsm*Cdu3\7>W[|_J $~xrp v'^>ZiU=7Z3`w_y4_Uթ,Kk-\X`>0VRs'斣h)IGςf|纬Ȏ^FQyS"Uctt4t;y%Vmֹlh[}\Ӌ*>9dk㛇p#(IR0Pבqz:{}4MY&Rɻ0o^BxKѵ ih %VLұQ|!33&k~ኝY񉀣{Y a_\/81@ z&aG'4$_Kg\r d:X)QvTV&nWRL'Ij)/cHֿ̯}w:l瞧fDIAd8iy^=rLB7\".}}wHT$5:fhqޱٽ(*ysH1T]Mpl>AK0хy =ہ,`#N_a ֔DžĒ|)J䟧 zN,;$|CB057 qW}0aXt!|kŊ^[ؿF%"6O|a"6 Yf+$ Nq@=(['NH(L:*͠_Z'IFS6H['k^p>aNUN-mTo/f&xZg>WrF5E+8@N҅Rha^FkKD:T\ޡ< jDQ,Y);c]MfД…o`IUǏ}/RB Ě~?p`_vu>ܼP6"ڢ~N(Pj@2s6hnc;?8Z TS2(͐sSɆ|\ܯg|Fw5ɿ[2ٰ3`o&8سڞ/$ʉYX닺3vDˉKpz s֩Js[ q^1NLNHr%Oml<&~!3X]ugMq5{%)Z} bv]ښr228w| 6]O]Zm " CՐ 4(T~YBZ{F IsWuA\}&++̬#-*rzkxuU0V.HAvy;`ۿ a1XG<uׄL*%S]0ǚbW@w[hf@*2}ߢ>q@fsD~ǝUp}@whGCP]N΍mۏ;}W Թ0.6vw~gCͅ\mr%KP#mŏDC086w<[nVsBq%Z!o=.;?}߫N12y7boˉBȡ]kKb$*FЩn3O2y+5o^pc0颠*G]RM;:aqIՋX)R܉F2.|jmƋy=݃3`ڜU 齣4Rf^K1}/01cV&L쌰Oqψ=ebgVR2O;riܦw<Ԉ<>Zj p.Eƈ\ؚG]ە/e?|jY:³ m 6)orr䁥R|O*)MRC^~#˙`kt8t{DN AM=}cY*ūb&q9Z"!_zBY J>~Zs4 Y@aKthv%z!qߏ:Vr[FԸDѐEPR]ƟX]$6yrƼ^tW{.aYne&-syrg¨LڨAl?.pօ9S.Qt jb+5Sw݃OfnׇsnpS sw}hiJ~tzSVXΧMxIB ]?'J$ !KU>GT%!QENqLIIF~ò x O|Z.2]);f4R8AB]aZy9xwLӲX^#&b`D[I֤ 0e 3!=sJPF4R=#0Fo %YFAvso`k|C42ؤJ)K#mAj;z O~~,Ey([h)H%#Xb ꞯ:Jfޢ 54`l huk?L'OB>-BS( p|c?YrE[h`YE~:Q鍥GrmOaH[2Z'n>& V$t%݂95u?b Rg<㽃h:f|씃θoԮau{k۰g-ς"L0s5( سW5J&t+T2+iX78-+7 ύs7rKАll Wp'{x:.^;QZL>kl茊G #A4BhhJu.g*Sq2J|Ã[֖kX֙N܌*V&4tv =6m!U^"$Iˏ`glv(f _Ae IWN6klΤJe%K q7هU1_ 2LPiG$ M*jN) q2bsXy# $6믐YtQlٝ:s>ppyi${ϠwA%b1U$i@{z:7ÖhXZMv٬0 WRfh0lĸy` URp,OxV1/Ln}b3yYR:>>"cxB3.QuYO8Zbyʗ~&˝D$kG{3L#3b&Uuke؁+Ap?8v"ݘG^Nwa젼!o=^f]OtJ9ޝ> ƒeq|t cMv@ hM))w JkJ[}o ih'5w&%q.Ȗw1uNޢed/$Iw55d7wʉМf;3MU|"J$qC%*W&Ck38 !lZ7+h8EѦ %{#rjfř*‹v; $`8+ (ppĽ`Sbx<3} OhMt>SV%022Liqn4 N^d7sP>F@ݜ6."]xgP,B I!y,a1~;:qĂ"?v埏s!.95b|}->Y/fok}+25"ED֒ ,GT?PLb=>ˑ<Ҫ^?{kl:=)L$u(k}V.CU;^e'򎮽r<kNC0Vmu^m`쏉 a6>+ Ё5'zSE7Y"\=a rSy׋#Rn59,xS*\{Pl&~ jϔ:y)+^єE kl(SAh-s& NӤ*8Hߌ.?h(˘%@e2G@#O]TM+e8|[4Qb_ri=zWrfmĿ ?YuNЫV ,F /FFÛb 𐟼ffzc"|\3TސIfHueU  vu}ʟe@"CCуiȞlRhq*YH,k/֜RcdAdžXDſyQcӸG9 WxÙcNfKG 0s쑅DxG=;DOqFcpߟtiri#3" [*~Y{)ѽM46Թ!7dg!RHWꪧ*[PXc_aG6P)m G$^4Dp MYIA? +a3q}2$@N3dfG.C\_"uI{cpiQuX984SB \w1{?yi/ge?.}8/5h%5u95z!QP@0nITRG HRZ&S8ioq_y1(AOMh$b)QWfƠzAP%њ)؊@R"0h-:1P\'̓ Fj)^{RQea?HCZpZJ#TS*DmRkGvE{y6ӫ",.gphNp.pDr\O&W^.fߐm@چ_/J+՞ L%,J`!,H·ql0)GUN7Uk\U>1s8.NOVY/ʥI ș;j-ELHq5 %2-m=Qr)OSYKY=U|n2FƅbszHW*l,`9Òm|=m6ϡcҘ69. {EQz(:Scr]9ͭ lx^vS d>چW-%OkLbAJ@wrUyl S>뇥K8=EspԯXk8˷!F|稽 [P;̔;NgqE"`XdDdy]O0TenKNY,0%GF}kr2TF 0%1fJ)QA ?.X=lщte-j']& uW@75~Hi괅NG,`j" a(C `s'll1 0?O ( 1 [4b_[D>P4݉~3qcKEBN =M62)eڂ|A Ys.ؔ@"~` ǢU]AJ2U1.fsXEzW$; yƐmNT@.Nߣ5wT~ jh&k08fQj4| H+v!Xx]PE5J1xaP7PG`Y{TrS l f0rZ\0qjX__ʛi_ 1g+:<*U 8DUlH|nVtk/|ޘ24W~}+@6w>H<}Ӡ`H?9:2"i_5*hf` $wzy9DC]s4Y{p&XUg:2 ^~F&X} wMdm H@ @;3:hg8`y^A$5 9 ZVK^\-71ɰ P苴qCI}ջl7zߪu,sGMUX֭n H } B;m/@x89N_ZTԴA|˦z-RvQKy.PTv7FxΗl@5r{| :MvzRhr,m/1mPɐ1{-?[ &ݭs,H&1P1MEID 5;]x37"%6\{ ʎpY#nzMBn^ʅ"Vv l'b~MP?q 7Qz<EqGSzA ~q+N[KN"7Ӕ.\#!$3(sz |U$^EETYfX8cp4M#Sٕ&Wtw+}Ԑ-}ve-v 9koϋsEf k}9i^(H,46ݔж+(LZ!F6:m[.yV<&bt¢s:pKhcRFx̧8Ń-=֔f1^=ҚhK(؄LxU[;\l)Q+e,nB5];XxR$̀yYm}L3.ۉ??Qo*|Q֪f'HcBp|>(>uf tG j8ʟǁs>S3[27rwE*%FR5 )b0 A;>  9(V9hcV?  K%UC0/`,i\Uz3 м/;FJD2Dm(P ]Ks!Hh~&qsp ܽHHL@UYw LprgzdBAgz_v1~\v(v'M JU_j6 6.LWа7?oˇng&2,U`NG1-z\qZ('8{ՠ!ްhKBfdTL΍ɕn)ΜH) l\rRRz?y הBR.e s93 g D\lj&+p#2-X6 l5XU%sJHT_`EԈ?WY,$oZĨw&뛺as<[FQK#3Jv^%Ɠ>G.~+IݷI}eK]ʐ-'ȲZ$R?s=ዧFa?:T:Vp&/IX rfH9ء_hP_^GG iV^ |7|B 40֒B[0 x<==wg Eq`?B 99OˍrbT,wX9t[QOVWt=xTvR[?c=7Ǣo<^n~q+=*A^{T<"rR9oz~*4o>`@}^2p4~G(R3,#cK }cPo:SciO,)l2V5Qn\I*/UL!PDS¡ݤ\"X6ۯcBc״ȃ`Z `hUNF@&"%u:4Z|?)( PSs5NAHhi}[] IUIPl >H8ÝLy~˅ԛLXf@#ȍ C׭8Xl7)M^xmJtK 5wQg܎yHxYRotPU]-2?Q*ֻu?iGt k-ƒo^T!\M^3JIVde\!Ck1"˲qEkv&䍓T%@_ ]M7z#[P;+atYv nsܠQ3poCR#"!ș/PLYߨ1ueROdVDW]jp]AI֔@JęV))UBbl hFYF3y,NS%P rN[T, eTE>w})D{g G5ޚv:ҿ_θ),zEZb%|DN4Rp:u7݅IӾ!6ΰϝ)-ɵ;yraM<޽UT R+ZrnNO->Ie(6\2à T>xMERv̉2y^g"4kEr0erRNw|b;ЭDAI"(!Kqj!5&=1[ 9=^Vp7Ih#$?ooKL]%\:%'\%?W-6ϕ"y-.ٌjwQhm\p>1 IN^6\ܢf?5!l`S)ɾ"af't(w=2O~{)J-oCqdd([)H0j)zpmER5Xk0@K&Ou\~hC,]B LnLĉ2]5uehMIɓQDuY 5CG:ɓXK]V?`c@om 玪/gϻQ >'DPf7y46iwSP~";h⦼cשS]Mnǩzڙ!_xa6ͱ/,$@i>|.e. K~P <ՙ'Fa FmuH$b] )3ͳ k4GM0%;[D  [[,diYYi<޿o[R6+uJڬSWb۩Bjt H}o22Qer~Ƅ'p.Qh^shřs$MO~PݟB,5{C$V^Z@Znԁ-5*}U&polR"[0?8%g.WyvX~1le e"Hxwy-|mLMeJ*zo݌Cݫ")_X/+mTǶMc9MmJd0y {1Z= )R(XIno7= !B|??M%N_ky-]tJ"hCU7Qٔ^f;e,b{Y ,15W-Z{4^6 Y^MkvقQ "ȟ_tC!R#O"I57I bNK9duW_uG&t3zzEw:ӗ/CU-yI]X)*M`F5+V-5 :];\d1T }AFs]d} )D[ߥk5hy@/Z06}JWdӵD=0`¢T7GNf:s>򠍞 .qk̾E]!@(Ց:ޅ58ueO]{x^9[3#Za6UXW5N q7YȆ S#?pWioNmTwٓ~RJh&KDIl6ÊN?h"#cX57y&%G$Y ,Ir-/ҩE/#/h3V;GG)n #8||<-;9r7q-i,\,4.йNRg#>D$vR("ÁS.dZvK"Ӹ)&Ik̆_cg!M< X2\꓆QUnu#ѵNV xhØZ/*,$- Ym-^4ê^{EN'@agu"n@q\ڎ%|e;p!Zgu̎NbU,䅚4Ti(-\M9(SFdi54 s,qOЫ@1*G;t}HU7:h?N#bOb h3JU!Z-Oe Ҥwi\)w.TI~ݢssirt,v G0|y<{0+W\z3t%|rJ#~Up?YN@ HoDR[l'hI]"&+)QMWf) `TEcHX\8ul)T+ۓO)3sƫr}s$UwMpw%G,@WO 6q'i2kBj@J__Hma~򉚁#\ F@۠0-քc=<0|\̡/NM22nC2=r$! ?A95HLSΆZ|{2}f0nLWt J&LH3 )ݢ7[!up0#Cun=I5Q; њKg͗;}1׎!c˿㣝i$8ZBC!t^qBO}׼o|vyL?̈́|[.x,θl<:Y|W ~vrq-}9ύ[UN3rā3F@xͨH*}JlTO ZD\sdJ`>%"tk$߰7fnf}+[}y4/' :('> Kag>X_0]9Khh 'c R,dM1/Xs^nIjҡ}`fD(S$7AཛeυѫsFd/h'헑mpqCGR&C[iΨڨ_H3=w+R㯦ۼF*[4Q|b$v5r7C:Ԟ)utV\4$%=*kN]GlM¤sSTBAk~D) eu߻a:8) lFD6bhתEdd6Bd8Sl"^+>cWvE`P'~hҡh߈z$thBBq0a&TJvzݺN+ h!/N儀- 8,nDN<>}77,BPަŅz?NV}kle//Gxv.{v~~uǝ嬉D΀IE^TLg}?1ێsc4d/0Oݣ=:5- Q7p씗̃!)豲du'e#PjdMZKUMԞ꾣]ʽ (B?b ѶեZ&*z듯Qd~xTJ9?1>wqkIOݗPg:bY5TC]B=^}vyc^3ܕfr3&ElAJ}ᰋ&) žE[‡BmHJVG4_h^ FlT+P}́Ofljo]1?QAkدY?>^7J\zcP^%Dndu-CW~IvO 7熘} rlmOQ3ÿZ>-0xN)4H"^C_ESuDtxZqR7)U }HA#U`"; f4H8lQ$I"9֘!%z+=SUDtkfs <5䴬ɃGZf m[uFǘju`1]y2MWjq#'Ry'U@{'}qxPMgcT[eCzd(| }@Ԇl=Cƅ dt9X3sf&IIۙ܌ J#'Y!gS<̩l-9bT=iZIˬe jvg}9r0x/)bhE \ˎ VuzJ䁝s7S*Q:|^-Fk/a{>gy80u՗HM`Sp nw n b2zi SJ͡} GʼBF"ML91.}x 1Ոv P0c1a*fŜGNi!ͮG3ӮzO_oSNMӴ ]_TFasn/RR!uj7vfV|~l].,Jb]12nSLްI,dt ypPo$HBOPO& DtWꏋL;ۢ5fM/Zފ{2^ՁL I򬉐";6ڗ,њ/c(!ҿ NWڑhk:ː IOZ*=kz]FUPr 8Z0'Pmoţ][S_O^84U #53Q6+IQ ȸ]Cս7Km !_C09Rܷ@#R+ J/ٿ2uǃXIhA;}SGJL wȚXCi`. :ϵbd3}+Y$ heU^.OVmgvpe"ñ;>o7O'#GS*<=>(Q] V mt>B[TEie"'핰J=,*.oI3g! Ȫ c&Lk[3CE[ XJލLbVuԓzO-?I4>$账ߋJNJ/4W+$,$N}2&3Bq[Z_5{1ny[BNw$e0r{EL1/E29CZM?%3BW(i~#Rdm-#ruÃMH0BR51]f%M\'V'PoȘq{Hf}j0'چ;$vfk܋bLI=>yRɐk{j0E ^CDB77M;uZR*(sK]]! #s8R%A񽕳{#ihH tG5'CQ;40Ģ=6-\WN{-HO)r#[F_p dzY/]pI z~EA#Om1^SW 4t{.֎ P(6%gw4NIƿx!9puN~WrY4!^r n{il- l N89U.mVY'-?aҷUX[NO*wr(d8+YWeHv{ 1GUՅM8l\G⫴REJl7F&m:_ZP_@pC `ǠxUZھpiEuv}9FC?VFeE$X˶RWi#ji. b^M`|e*N~Z%^lWc_@mK~4󻨒Ϋ!m7@E fzç5B.\T|LiXtS`4qYJ-m10=xȌѪN,wXԾk895̛utMwY:Kq0 FeC }%&8ɼ0sS}eMtJ'?\DȢ$m]O0xK62+B_I,J9,$[έ>E:|qj_] 7m$ۓ${q<eE}_{Q|_d&L h9 HVJv߀]t/rw*+sxQ#@j @_p%`OC8ey`Ml"ص]IPbK-kGƻѷ\Aݽo9_n/q 0k ]۾gZѤ7E)]Q/лwNpY#W]bC{Cos琂nUϒa cL);_>f"-[P.l%{fAIy \QAGX* Ae GiM-b 'ڋmĎܥ='"#)nE2)祀U A7xz"J]L_#|_4Ayd$ &ȢMKiQs]'=,)#RjVmJYq">]ߜJfտCkQ9>†kvz/4cAݳZg]?+/R"Mс+$HұTk˲tZTɵN7L  9z7콟 3P ]{yԱaɎ.g!+# 7Qnȣ oE.5+*MKqtCeIH`<[|ר SooD8:D$3XWT GBp5? _8qѺu}}Ł?/(6RDJ ;GxF.f'-2:b,U%{fi8I׹Iy2IK!pQ”ݡjAhP+2h)imlØ@ClnH) c4l\(^u%)T!KG2;V}XHV|֙F};WvLq>4Ч ƙXӨլN%۠MF[4:V-w1XЛS,~R׎QJsȖflX݁{uA?S DeVإ _ZWSRA ~.M0Zd U"nߓ0m lN)$)*ȹfݥJ!#fKѶF"(;6mtA.Q| Qϴ^֒P ܀6uUeo*5fI zR_!ۦKGy~XWǙTh >SS= +W ^UQ`<O:WXu|jF1 T7튜$ b\e[h}Xa,!7Pt5 c'5xXsl}|Ҙp_c,][9ȓ6hi4gŧy,[z ;ÚaA@O7^]2Yj/^荏(>MDQS9d~+S53N*zɪP @dtx=rη"y('D@"{oW\awGLg2Dt*ga_hsDubQgP;$Zٮ(1CjfG|6-{C9R;*1U]K5.NR|U¹(F<(4X֯6ǃi{Y*9Ɖ&pkTr'ؗ7Mw Sj7֏F{$E|ڍV|\t'5c/Keѻ l3M3\躩Iyd3t.l-$UnXbOv 5ALTJ}d#Zxgi:em4jKL<'R &Xdz iٴ&Jp4%yTNZ=gI~SÜ}=3 91 -q|SlO1󼑌gT"7$23:eW*m֑u.=VAHkwNZ%Ů1B$?HJ2 6m^#%=“\&xLΠA{! ]f^Ð&e]}\]dEv %'qΈX&]W *rߦjVE~+_:,AtB4 Xs K|>8 >\* .)"rydCs䖡9)_[\nlW|s!YvW+oRx&.JlupSwjHM|IO逺"A}&edgOP@ &nujԐ=]B<؄lPGSNia(I [<;/&nJDb^H#?FBUʡJz}E ˜Uaf(/;m +0mgsq\zU CKm[;w׵>aKNݣsOK /_ q/TE=kwg˨0#,X&O=Io7ZCe,dGiTB<fH~>^`ABL-R؍r(+to4z[5EeUVcN$B? ⌜ ]فJ$eYwTM9h<8׆ P l32//%p 6d$ዃH#< [}F1M ) fFSxUsrG FyZA97u›^n6|YZAyl&KA/UZ9hZPscW >ټp0E?m)]r5 %+ e)(KyWb'` +1)v(cT,i6&{ƛˉۯCaʦGb.]:XUk rØ3tpuEE.HOpLb6ETόb=<9?]M%#]'^| 4w l"NF&:?Ku/٢tjɏAt^‘FQDԇ lh:p*襳Pi 'ly '- a"LN뎆ſ_ԱV~3Vb竿=FЩx6OQ4ђ0*4e0[x䭶I D{65o;EԖk-Oq c z9{*Vh A$&竬NXT7$1&UtC[HqfW~HFY> 9V:W$ A!:L~Q^{鿚làixxfqФR[bdF=Aq;u&[r}N>kwPu*b_C^!*C;F]!kd F6)/.嫾<2S㒐(0m Z@] m@lZB1knt*6";6ۦYĹٖyTh"Hk>([4sT6R35,%1Y=oÄ [y%d@)T , YN8ƅ% IpFR9Ir#pɄGgܑ2G[iLJo5Y[qbY#FJj (ĵ6g%*)'6)' /l4>jf᷸wf]TED!Wo.Q1(>_GL"nKƜޓs+#p*QNѣ>,J@f?M32:5ND!  Ea:(zlǼN~e#Qά|N#Tx)Q\C{ $2X^J܂ ;1iZNE4Ës=}R}!%֯s Hʷj=<Յw1Ȫg|+hfPyrgY=M 6 E9RЪgW|.[weR⍡r4#B4%V.ʖPg 6DoHtvҬ\ks,jKRĂ`yܭM53!P co~4eN V`u]N# V;RV:w2f~/p].q=ޔ' zқ^pFh7PիQqȌ`1 ["~3%̯S_ +jQ':G}]'AcoiD;8X{pAťQ|dAK#RdKGu^ Y0O a)]GtV,.;٦2'OB\2r+ #/u O^ua *XBcp<#*W>r1j9L]Xaobj(.M1iΡeh3>&?{- tOiq!@\ 3ErJ%#h6f]( 6Zw}9̍"B> 1JT*Pq;{;m9g\mOC]39=$/Ҟ/d,ğmo{L1j)m]ko ^ybUiʤpahj0P“^݁"]>Z" rZg&ߋv|)6:5&rww)?;ͭNjfxu4WP38U=L ]m*^1KzFi'7qʀ5|4?)=0rd j6i >@6ֵ$;#J 39srq0FJ')]elluLptS(!C<88oLr!ٍ)s&Mm&]_h(qkV5Exv92Ȱ!TmCҚ %1:^UwJ7rV݀B=(u?p;WW]u[OU8rȾ+Jb@#/ɗW(V :9mvS}3%իp4lVE9u T eE9>{7l5 (oI;ڂF%qz%hK%ג)VAC\ [z:S.>lГ\\S P}8Wڶ.t A2)>iPl aE,9> :EW9}<%6=,qw|s#V8zZlelj9mۼb062N_ ٭d=֢А[@~X=ʊC[Cc31Jw/~PYB׿"ʆ '6k}n*3j*kJOpv`܏ W4 zEZȳ$9\= ʕ5ٶBt5F^ŖJ?j)T@ɀ` H蹢$th,Gi,rr?LW g|5(CgEG$Vr1VtQ=fEO]TA;#1b?I9]# oJ~Q 2zX2[L>Qr;+]u]9:*7_vSyba߆4:jM9_#b2/٢? آ^0]GaLg;`ݛj^ v0GuPݖbOY43ԇe2̶>!d2^mԂ1lMzVN#>9ŪFh2PZeBvMܦd5W/ܮ!ATYW5K:~SJ?Rۣ,Y-@4E  ea27ݩXg*Z,l82)A 0I#ԄX;tElt-j}bYj:!EP#>?g[o/W9,Պ/l؇(Esu͏;ossݓoڬ^v*$LfH&4=b3Je7L']) hs1;;j"GmMyM ="5w;ܮn*g%͜@@zLX05vƯNY𘱑׷I6vӒ l#,yޅ|p[> ކH!W+я,"Դp)BN"'ʶ^:˛bhZ h@j꠪:mGYȔmY~ᎹbU+z%i3 RG&(%#AQOt١^lvtLcT]m:4mpb6iǟ0kn¼Coc8gG^}F;{5`GmO΄8()!; _v\gbQv`1&;_Z2`9[""%Hp78 Q7妀|8!1+Qvfvp]UMIAئrAoe[/ I_㾇QoB5›uejeU\GOAί煀-q ` #rH{Mҗݺ-IZSW{xu_$~h2 |n}iWY#7|WvD-v}/ ^5S<GuwN;n0t\jֳϾPp>/>T|肍r0{\q% Qݰ琧g"mzKJuESY~:_gD2bSX r[(L%3K Mp۶O…x>m|mq4'):[ٗR>8`@p!|2 x rb-*Qa)$hBiד묺GzI Dw`֙yb"83@Uؖ/tܶԊj~ ^"CZ Wa$>gTm> _qo]Ux\ vtwCX>ADKcvQ/Lw<=ĕ$EHl'40,΂kS!}Og8hkSš| ~q#zYEWMtŊmju1o$s% Yq5ŊKF%ܧlFkHBQH_̈́^lOd,n5lW4s"tUқ͐?Rt,Ni2:n&yHn"رi_ELN>9f_ߒiWUݑE{t휀)պnOa%Lmsj<<VwWTµN/Hd-NdkB6AۼABpȜ81z%[M$MK"iO_#׌SD-goUcLٺm:eՇ/!1$ַcV7LwBVikG.>~D-z(\g^7<_?L*o3fmѱ~6nӦd.Vsiڼҭ ?̊;_|ҥ '7)h`tUE"T'0CT*ݐOʑT0hU}GS;{XX=GL @c' wTB]&ـ;N]_FHS!HeQgMuP֫Qx IFCt͉"_Q_I34e" tOm}alG+6R>Qr8 ,|%ɬŢz=e;zYKֶ$rx?TzW0̃~,h @G5_%X2m'E$,m)_(3U2rˤ@K$+Чd!W/QAiRGMq/EL8ya>I"3 ^?eͤ> $l'2f.aoSEtS٢4I2{a۩ˡ?0R}%Fg*dRj}n6&Ïu@37pjBûFIȗ:x&&Y3/17(֗X Qխ71dDTm?yD;i4C7o1fD!bZ@ۋж1EǗ` w˲a*@.c0;br  8boNE[Ѝ'O`# ~5d RN2(KցʵnY7Ѥ[k}9-uYg(ƶu/r^=韒kXL2i@iH_#~SWc/d M9iuPa q/cAIV5^d$WrSx+=~wͦ'6)i,g ΖdE]T3/'oV]kw7C`e]ʺ*8FkJ>' :A|S~j `%5w&t\Anː| x|ACᢝDLΩs Asv%N[h y4[Q|m'_%?<)K{=zQPNFk^#f*b6+XEg\$=ZܳPUwПOgU^ĈA5j{¤L4afR6T嗇hR7]P.)svÍ-G JO%"4PKpgɾq|+,(mwΡI S}F@/~_&%KJLfyJ <9*`q7'Ag{M滋;2b i'02vq[糲O.mV%/P,WeQofM1)[J<-Qg:k _]m!]ElzRf" jΕ,4d@m Z̯Z_* 'Ɖ&u ON qk ,<%x~FQL[~lQ˩RWS  N˟>cPOM5} & tIPv._[Q;L6ZP;̎6AUK#a,\1˨ŵulw1~w;Yi[mu\_ᄦ6;}ؒϊ۴l"( -CqhrMS*;s^UX᲻PGEф[֩يBqی, {͡|׶kGcTF?7pvhN(4F37 - F! po˥)b,hXCl{.^ԫGJ-eIh%SҢbWo͕cpOc!}s䚋ƬIP8#IľZR/2|-_5|m4~({j/bP䣇Ȓߋ 5zѝb%1¸%υ~y(lYسyԢ8~۠JTP#4 mpWς"fBiQnfYCCD/ <胁MĆpBbvIb%je@o, g-D̅N6ȲFAzzP ؔ 2{.jW!DZCR| X*ꊵ$H &{p$t1gHh/O"]>hAG)c57y$=*p|(`/n-ic#7 6 Mqہ-rPq@^wP8Sګhjy!IPs;ԓ^r,vLM3р5'`Ӄ3*_Stv~a (1u{P!ΩwU.V oC߽SH'F- hIP$Sp_nwͪ7 >+E+~8c1wb }sW*413T plCEfO僇7b0ߤXSZQzņơy6^5W0(W^6aOkć+O5]:ƭ/ՅCNhGsl#ĦI>y _y+DoYxMW\UWi.i; 't)_>c ;acy'0Qĝש?Gz'Hk#O)D;hܞ` mD֘h0J5NlLrǽ*Ae VC*buM6 xhJQB:q*9p:p6sAabJ8N\UM U¤-dr@ &]E"])0 Sh,[0dO(x/c֊R{Y$)yan[Ͷ9Haȟd8#B8Qwb6>&KAٔ_#jhfǷB5(r6g (a#zE睮pOe0sf#&e#,>TW B({\Cdf4 :nZ]YW$vp)-cOam HҚFaX0{%b2hd˫|͎>qk"dOX'a%;fSyIWI7(C)-N 3#qk(9wiFʼnWPmFhVae=؄k H!-(\us_.w\_bH2ge'@:W2~d֕42Y k:'e͛H?FG[mn+Fike`z=(OJS !z1#K_uAck 'eQSVo:첷ju -_8"E# ?Sr!q7ׁW_d52/:.PcP Ǜ ;Q=^>l%wndǚVI*o3~3Ȝ"IF"ɉWuS!R)@)'0\?53G?m8*ވSFoh #'Z;Z5UOsVI*ym,vl Cp0)/l>;y陼$0+-6Ak#OvS*݀G\<;FWb(|y= ;?FJgO7IrMPo8'/76u f0U+\<_v$ {Bz<_| !NODʑz)ǥj-ٔ@{pgBMHmm goAًLlR \xx6Z19]^ɁK4f]V \ӁO([[)vQK]7+mBpVO7knnVwje [E~`w2)SM{U;z|ea{3V! u ;l7Iҗ3uc,h6X\…X+|NkktnF"?[)嫫xZVDtN !SVw+=ATHÍhPe)8V><ݵC){ ABgñIk{VBT rqrxoGqAClKܪ4}(=smIgԿc +{*lo윣Ǽ $w-O~j@qoդ L}iuFWw|ј&Eys[4_aOșӉ) C߱ ]'$qLChwfyCm͸޹_g9!{؃R%|WzWcj=VU䜀cXQbw$K)Q\E .֪Ɍ< / T"av#'^D/U뀓‚x8zDhgrsL%NJю+(;A6|#zO 9S %,3Шr- NM1we X3N s!3h-kuVrBH,b/q[E\ݻ(5: W6l/PT32wC{zm-G!T?GP.d5 |_C~*=',>1~z1bn-xMZ]]h8GܬS̑cz>!c5c:wk$nе˃EGcdkm~4s zN}%.^De[du0Ksy1WkB?IsvOo8a !n^" =]OMInwn5g37iǴF=$>G#t%| [CلMFٴ`0bGs&9xvٶ *cx,p/Kb MȏݟԧH`4 + D4[J";oSE;/e넿:2uMdmZ2uPKiq݋Yj!UF~ u&!&@u2k诗GD'9u7pGe}.NRfHofnF3"Ap 9QYRS_5:J֏=a?D:\\7,{Ήj =Mxh*F cL.,!n_qɰF^rg^y9!6YB/峺ؙ:#l#L]!.Po*HE)Pzt͡f~!;6љ u4nvTjf0ekI69l{us5$W 7i=)1ѭ4`pwlꪴ9s$h́˰sѲǠ\,R1>e<z, 0q{b,W| }<a86(?Yqy ^¢š# x.:[RE}͵cuf~fg fǜoTpAv!I:O{Q)G*ZPyĐo/%P7?NtLՐQ%\Kʡe]8 c&!^hEA6)=ڈ2%N`0X৭շA|;DwV &ObH=pۊ=:\ Ę di2SȬq0LL_S9k+כ21gcщW?w(zRB<x${ͪާ4p;/8Do^QJєCyi:ee|ߓO %jG5_;)fR챸m)4 COb[gG;Q<~ccU12 a ]s-PYX?Dh }6': gSD,w06a5V[q4'7^Tj_hYz/1eL6>:|hJ J'a>87Mbj4*p<:fǜ!;0 !OO{к# ,9&y, $tdp>QmxA"x< X/@`/ue})՝*eUb84>CoD^>y1'gǫOn6G!<qysJşy:fTf7DqQG1#LDs}gltHkL/|kv )zK>> c J58.RA\!rzG{50.aiJ/`XMqfW13wc!2_*'&J |cZ> bʺAdZn 1&F8 {Pq^|uӧ]wp\B+?2NYv%$;!`_' swP0U9wF4]p5(8΀,V7]j)uqB'r .6 .EH dJS`u߸"@gגaDdMї{nqGrU3K9.-T>q2K'sd~g'd pX e Y3 ~%g-eHoWt4(/܃j%`ab^ĆmX~f0m=]Q -\ gq"2[ETnK<+G꟥z쏆 qn^"ojO}n˒.Mp2cfH2+ziծ 2IyD%6y6ץr-MfSKڜGp  . ?m(%$uBmo?1fJ7#hwq%y( Pr]C/WKçaI.msξY3 VGAGdz~ 'VtYw4JYCG2zFz u8 K@~@K; eP5,y:!ŋnKHy.n VZ[w-JG+cqfWν0p3,[dCGOJ]c[n`t+XGG҄8F=;aKE0=oGǧ؅o KǀߧYw oٲx vp1$Ts>i`0%7Cy@œ%HdTpTr aH 跱X]aht@BI].:MOd,S}ESPm.bmgt@ KZcǽp YȔL/i"<,T5duSɱNe*@fʃnU$}-^  #Wj$ / ̌-&;+kc'ѻ,)i׉^bXnW&lm?. iB|ãl eV60v:C-G\ԡw2a6뫊:FC>㗹oίDK, 6. "c;UFҖyCM \u@=aSN0C[P0;VQuсG)c*>!I*`>}=L͒O'zh!NsmXd=ye~f۬hXp P_^SY׬*{0dN'ŻzYփg ^^vJ\)vsۋU8'څ{K0ꄁn`]G/yPqׇ 9:: Hpބ.Pp9%aβldn7i[bٓ{WIOlp,#P3r ,64TOKdπsG&&>ioS-o(J17C [̛, ) ϋ "qr>TidgܠF6qwٜE:z W߫ ț7.iYF^}ػiO>u '_vA,izmyvR{Z$h,kE)rʃN'۶2FV4뫝"<e ǐHƾu3OAKYzߐdY*ٯ ^#0xhq[t`*3Nh<:ݡ>TэjtC'J'L2C{`4%n@.,K5 ֓N(^XZwBJ֬WJ#jpH#~ n΢XUAXm^b#X)YZ.f~Z SS`, XRQu[F,`PO^0MosG:{ab{ bw.D1M``揭^+O1DA bt*ܔ ip>H ":[&/h{6:673U${^PUgԦFJr F"[K=YMR~S(W(|⢆j$Ws @M݂[u!؇MS^$m*Se{6bZ BwRjdbpa_g&.͸ml*Myۍd'klG5}M ~Dk{Msդ`P,SQGvU{I.`a><'/&= WU$"Ɨb{bĕMY1ƠEgORd]ra|Q7J5G&,J?Ez{ p;V/0P1/_vLroȜؾo*.LJl,`YwRN:4bW^~t*Myc K!^В miTA*F~e?5)@gXdt[,"Z fny@Z8poTbj!0{"{ۆ/^A&P[*HV40x6LҮ2{]A$z7(݈.q -(^l=2nkɃ 1"$84V7S"A:P c8kj'AnC}/ЄZ` z-,aL̈7;z%H#tzijnob\bG9іNWB&|LEg%%#&y%]5$qKl@D ;#ai'zd|[Ki0‰{_OzsL4gk#AWmP*B)BJ qZM# Cw"د}"G ֙_\В-J+є"HȚy"zT_fS BQpSً aӹ4%)L"+ɪlJLcj95(%U~\D0?/f|dnD~ۥdp2\ihO rP,2c,>yϘ7qݷ6I;0q'et\ʆHUb5VŢDlI~Vf >c`njiUDU{uX~ D0s72d*M@5?ZT_y0nZy>2{{0)P/0:\#`47*\ <]D `d|8&YCh( ^pҟ)^V(7S`5)LxPo*>#ȶMB?G^*,iU<Lj|xk8UM|sE_[oB98(*x8g B\nPQze]Ea D2T}"RTE o@I0UcpWp|Lާ{uM;pk$eBgIFQfWrkzb_d| Y!Q/,eAp>^Vf?:a pQx>A%(>u(3FN FJ||k:̴dLpg !u8}#qJMCQ6 Đ`ئ~{]w~PoQkb}X<g~GKhX|{{?k *3yc$LB-i@,Y_j!| |8V?8,Mdۃ $5 5Q䩾%.\c *ha:Ag+R{̤47!ZxxdW ίݝB?(uu#[Zr Y_C5Ԁ#x lJҢ3 2]4T=oUYA'\vDW6$*A⎳̭buzvd(V\qNS,H|9J) uV *̧׽dw5h'K;r q*,Md<ʵr3 bޥpLف_|],xRJGәQԚ*r FL@+>m渴s\mf=KV#_Gٳ_D D[0Ӷcܜ♓FȾPJhy]s>ç(i?ʩWfJãbĽ2SmHWR 5sYƌMC]?)FHc$}vBlj3aǨ] Ug~P[oMh Ax"yE4 x_ w߼ڏC3pMnkx"ڨ,5grg(Xbݸb>&8ifǯT#AM'b|{S-0SNҫ 3qf^H @2Zk\.02b.q6E,ÀקPEs+ 0gpͯ|T˝Ut9eTY$Q4Ѯ, ҉:wBFQIRmVUkTō_?'-T^ D_K*ZCg|{ŻaY<_V<휞]CS* ֏gŴ5⚢Z)3eF Z)^JعYh ޚ)`mJj~y8AP QR/ԋ{{I 6wJ],Z/p8BH2l8!dɻZxS֑ڦP!'%c6|Tn/9POJ;o ?v0iלdeS~GQB|9H1)r#YxvR6[ :OA 3:C;"7C؁tA_LIve?R b(8d d[p2Q|3Gp72Z" ˺; u aޖ\AZӥi--"bJm[F |.!hQ֍ݐ+BGvWCx?1^n#rS3&IJa @!_*{6 $t̙>)."Tu?V /?bL[%gP#5.ƘgN`va;W;(\o t]䩛脥'c8=8W\O%Ʀ;>.ZYJLy=|w]`᫕o{-[ؾ%9Of?]"pzh_3n3 0ЛF:[.2kbŷS0(j$r`itwdë(1[dZ" =ʿˀ<_R0͟mb6ڡt{Y;M#ۙ v@)b~Aw4 3qY/0O+)eysLM$'0r8"x:ܶdDa d5uV*,}"C?÷)Al^eθWmSK'4ߙ2CzܢLA2c 1Tڊ,3roMm+VbܙZ2M%|@ pKcLv7lN')4WnP`z̷ űǮn 2s0W!s Vӄo\᝝\&N2^4DZQHdRw_"opޯE( } [87ULa# @@>Fdb W!)?ϟ K8m,6k8q^(X3Y O:zٔ^W  dyJ>D;qn afTFh7^-}w½Ȝ\մ|t9.ʊR1kuJuc㍵v;jԸ̨ M's.c}xOI; [6E+:$nY1 2p&\t0kd:GDvtMvfjԤzyĹ췜tRe%7fRPš6Y*\\rɜx%e~_8z C_?K.`%Lu׊rD+Ytv*m#/uqyíM,_e@LtV(izjVhK ! 痵Ep')yjKB::M^lRdo$xM0UT$axĭS os#ϰ]D&<ş-(']֗6 d;T)f˷&,۲*I (. w~=#eqC[I"*mI$Ѐbǰ5AG4-& ;X]p4x5QO˨{xQ`ߗl!v'$Yqwm?v!KTؔkGM/wyTSceϙ8]%dN;!8q?nOޘCь|Bn?kMi9M"HܦR 2PUߎWdRInܕSXZ@q`6o:2@(N]SR^+٪߶ yЇ4 iܴwD &Q {LJs`[=:蒅|=fg{2H~ +PĠaⰬO]ȄrwwMT,t/$Oִ&(T.,Gլ3 ?c )r`!Q_բ`w+l#OmᰓݬDZ,%8/V]q5uM))MN8qJ*-+!k б02ׂ&j[}%店JLO#4f2`rq|lx66xgucaq㓃swҀ^΁Y 9Y *y׫R)vv/Zá0V\xF+Ĉ;k[\= ֗%@`vIɝ=JhCz{HЗT~ق h[n;o:9:UP]pCz´},|WnO+8wRfK`$? 1ZEJM7`hBv.ryHǩuZM mlj_sM6@E6]B^d)X E\a"NIkGE;pRyGifR~:si:0|be6@K0(d&a5Q9hp }[9j)-hoh7Y]( 1Ӿ+z+ړ%6S"Ӣ.eTIS .s 4Е% Ole15ڹ2W5Ii)^u*E$eqcHGħ#M ၊m\&+gSֈ)^M^sc]W wI{3tPN*{6O?$2ӫKop 5|j sCB"lyo$ki=(u]@Yµc q뢩GN=1PuJn`ܳñUwւ,S? ~.B]RxJhZ7@ƙd٢j6j:KS+d6F֖&5̪7Ш0829ՊM-% %1'ouPA6f _x>=^R^#Fr%a*Yk?ak]| ߥ?kuL"r)WΦF9'S0Fa"FJa[L”MiK4[X@v Ɵ'Hn6g#CՓ;vȤz Ԍ?u&Fū/*k&\KA7SWv1OE;kÝ"D_4 L%jϩiZz>v`huPM6 [B&ݑ;c8Khɋ s~O;HP] jr-1ngs!Glfcollo \b,qh2IWu6Xg9?ǩhqhb8l aHtÙCMthun-4pXRA9n v?>~;n~" /K21M5Mb_yh~4hn|L2i#yxZr*`dr5a {K|2"8e51Fc%{X1l :c`ƢA)E!ï$B:7rg4PFT7ACo;W*EEˆmI vsKa0ֿ" Đ%~Gbʧ6Sq혋͈uU:JD2^K3(5N@k 8 B&z+,Jgz|UO> o[ïLM'Bx Zht'x$%W*PGmu':6ļԈ*i`Rg8:tw&n2OL嘲dp7j[ڳ<r`PH VpN%^Zm( KVj#ideW 'xgV|e6.e+DCWn-G-l{BZ6ƤU(gHaNvv/$vZ+N2gV?Fu)ϫ*Oct=3"48()L>*zdOD*{z ='2#?>|LR6 'asNVs"|+PKFȲ|H©)N~ ѧ^{}6/ȫF^F#Xm XP^&yM͡p`JT %#n}UJGe|C$Yyp^-4kؒtmxV|.V̫=x2wAn飼s?آg/v5ʎ%ofyS-j/Ǒ@c8$TgjFXAZ4ܽp @87FߚDuX$%7fͷ);8^ɬ+TAƘ %FGD_`M.sg75} UeK]hpBD`bˁs-ߓKYBǹkL9cupX0_|C#͙w@+;8⾅{%5qUSpEDI :#QiW=U!}c1rVʡ[6ۗGr3hMʾ S(3p>n]9o>._Uaѹ(2^yE%\8mMS~kݶw|U le>JS |ʺ:IN+54JX رЮ sLC@ڕuw5tSGr4-@qYS` } !x${Nr1+E8 j>Ѝ.o`^ȚIw䣈ѕSr&rU6BAũY |G]ղ+j5擈C¨ }p?F+4Qc]V&,׋1(VSV6Ԉ][ԮNvkX|zr]"qQ˚̚J-[7qh1昷0_L ]xTRR"O})90GzzV$*lUArlJWQT2aŔvޝic.&O`Hd후jsDG6L]cG}a1'PȺN' 5*uXJ?6k,O(A <*dx?/yHGa ,R.ل v `>:$:ޔ=kl $duXQ|:N^3"uA,`<(̓0ؤg $GiI )as^GGJ]d O?Kد{fBU%[d^Ԧ;> %r5+N } ؖ^u5Mԫ735oA!k$&O;*ly4M<ǒ`Sc^ tg4?-CIAnG#J TN &,9ݼؔom,KFOjg^edƲ&n]:&{дpJky$yʐ>B`Vb3o񴂳MuqQ!&;*+c}4^q۹s؎3~[D/rKG–L$Az]+걑.O"`CD4}vRǷ*wN0f>=C{ozqD*C:Ѥ @*}Ƚox1e=Psjs]MiCPK߂)RT 8e ,vo ]!B;+tGv2x Wrbڿ^Hz)h>inW4왣¿]3#\,;[ 82brz;4QG}\eɓԮ-51D!ȜKٛ9.NdK`l77v*NJ<ѬP-Tv锖)Hwϱ\쨙t5Un#GTS:%wwW*: LhOe!*>9P_: -uu3 w!<"3j_>&tfo:e`H` # :~3ԔLڟ&lCŴ|Nj䐟&cYW U1RZ܅bЧәMurN!>Et~{A=!Jx]WpVeܖG_jsV\:Wԓ4̔z0 ۨu NN:~< &jyd*[nohO BXG!S7ä$w' P}Gċ/9 ǜ4]]z9D7o@cS1֧azga [Oǰ1kELo)r?tN '$B{Ka7EL{DH4W~uv]m0Nغ'R8bi4 _ZUԮS$W~rCEn+tiEQ;rXnSsS&F Ш %E.ڷ}C<~3FE̓^ݟ|gԏ9yBN^GhbE"َqQcpelY '"{t=7+(:; O3„$IN$4n?>"*0p y׼34'DH-r*L3ρOY.ZZ#G3ъz"edJ! 厵ɫs1;OѦ > c'2 3A)(ikF_ҕ4&(d-J@ t *nהb\ DiGW=nO@7=?@ ݥ_ WgC)  qq`߃tG~A/Yfp~MNYƕr TDyF˺زoe' =s<о~^^IVW+̫ҥ ~>5g >QF %T:aߓbqi)JjGZj|]VkSfiUXr6}SL@D0l֨;̥n~/ͳ+@ǐ@?u./ye4#L^:Ap ovSL$ʉV\+9C>nawJ-<7mm<JX,?])oTZֆu8uIlCLu側X'gzmAjrwӻ1Ɯ5rbKW \h,!b̘httjvEYLd5K҉$'FbrtoAɬ^'fwd$C9IEƾlxfJ_6]7F-OzͶrÂmZ%lhhcI`wPo!neUlY-h'c姻gC!1O\6' %bsd Y^ºbeI`TG `</+Tz(.'OUjME@]mL^Qcn oYId혘}[)gUE.C[`N抰{ל{0nvHofڬG-Rwr%5r `t'g@TTOM%Ӡ@_0q$Csy*8yD_ Q|7n=g:Z9&lXDK4i^p#6$w̼S.Mԡ:sd~b_?t;El׈SdPyӑI᭵j]_gŻꓧх}$S4ĩ ?%y0q /M-'!ބ|&_|syPTRoPF_,ya26սN(g}/q7fI6cX#Zi8Ev 6qzIP`Xa4a\ i\!՟3R,,+aOɲm\=' / uS)G0hc3p1m' jFFuNqL_0A L1W+G8c{dxaTbK0d\/4 : T_+*B  3B!S,Wy mP_%-4sAoJ[`œ"c횿-b\2$-,SErz GjU p;sB?ejQ5l,{.`wVl;6b[D 9;]p-Sl#NlCxԀjSzz!^~* _E2ӆDfs{`(FPɔ+.l'ف }#Hi/[O{6hUQxAoD!Sur!-2AKbŽO2,AݛEಸP2T_!:/{Q^[xV"^w]>=eqCPp<0  Y\qF,R^g'H{+t7")a'Pqyye?7&nSnNNކCjd p |Ju^N;&_[?W v%(`YRD>8 -?޺  iz,POA&j\H_5]犄0""Ime7~Zq3_f1۵Ӽ9eBfl9S3RÈϴ+̒6vFGlgb7?R,qXٮaeihJi~lRN)=͌, .-VHL*tar%4g20,seLèC"*A˗ ;&MBa#$m_̇M^'ԏ)2(K/̭/ȦlY؃GQ8:Ԇ͢щw(43"] thdh~@/z5BUz'T}bX }8yuuǫ/W8<Ղf3^3MDqBS%+SP\%'S7[BRJ`݌+/3ːIbN㎴lUHMOv+nlC FiTZxTW,U4ïi1-^*􊅧Z̻x8Rnx&wN^U/@hN w S"{ohJMvl:n 5F0[b\"W])GyD.gY_բ8a: lA`ԔMc;]C=M97\ =9}KYmjY 6 en{nmSs`"BG=Izx4 R5ɡ!c/G`-isVJ^nxRT;T|>stu' IG<̗o,(x6$O{WyR*@@kL}U%J'MLq-'Njv?%T3i"Z/@U. 8+t-e#KVm'Tk07 %6L7O:PJX%. ːHh4uȱ@QDAv4FFR@0F,;sɁ@L6/A;:.e1V$PtB箧wcSѩ:^@~" I]CX1;[?zv$1chABɰƢI0eR*$L+W|Wzu*vP>?ggj%"yz:GeM Mӗ|" F_5ie{T6$j/p)ٳE|^g^~hU+tŻ[!Qwd{~C8@B9Cs(S^ej!vv}r4_lm_^bOsWqRѾHѽW>6y )D|/p\,iNh@$dB}\s\ o)Sü b!?uAf8pɇ--8a*r=i\/;4i B!KźuGɾ]ܨ(`3lmxŵmpIke6[/ Rl,1T500EO9u=2u"t2.d @ȿH.kSop\uXkÙ eMT|)gpQ`";GZkI`I|"gH_)wE+~o%; sNJ;@Lɓp d[Q""sާuQ{գq[l }'uZ@-R1?rPժ?f sLD/Tbxgs;tFÞ۞2'8طjۦQSs~d%Ģ:<5׽$o2*O5-=֤=崦yؕEɏCov=o@%7UW)QJ)+GaV*|[~fQav`@ʱZئIxD@ڈ^gB|#b˽5t@x虛T8CjZ[䅺~uLI3ntS&b2;8U ,Ֆ;f[{209(GaLR{@GwPQŹWͨ3#-|}Vc0)ꩉrW:xN`-tx/x`,5+giٴ;p.#pOG{ig†@ׂĬ5JWվ{ dD!,tC$+0>eJVGw 7' ņ{ @;Gh{[-%X}܉^E:-f#zG37׆:.̈Q|,hȪbL ?NLXr^b.2Jp$7lɟX";(4e2qVoa`vkQ[ ",zU-ɶ'UzUjW)hcJNKr?>W7(]zVZ5BϽ GC3 \lXꂐ+c} ,w[LECk&7AfSqS %Hζv fnHx7OxVU{' *O.$Ѭ*9xob6?+$bYʎ7QtwV.2E[l`8,.`z]P@5+Yɩ`rqz8{?R?Ҹ\y\OY$&d\,!zf*<*zǙdï@q $l2im±nciDi%}B$=4YԝL̝p[a,%ᾂZ(aC]1YhBm,ql^7D{YM7 d_jl1Ӽ(ড়Jm[<2-? XؐWd P@ N0O(kJKJÉM*뫏 CpA BL 15#`KzmU_w>uONx壾a(YNKDFyΘC(oq[JsRZ$2GMb)u{; _ euֆ>E 2*(!2y{g`Y %&RcK)QߵÓO4fW1UC^b)΃ Q }*xN^w+mh$-\̯ji]PfA6d r3m6eZ T2TĂr|gguI|f ϿZŢx"jۥǿ5舎Kδ}mG/?<O8% KFif# qm)6*iG$0T5E(ULI[o\9ס8vx*zzw,0W*MZ{\.JKxy)Cbc`RaoA>K=H+:uf aT~ QD185Bu_.]&9&FB$i(-b'9GNd۵1L2c>+zW=ۓwYsq[Ɖп4t~A ?<̄X;Jp-Z9Nd.(aSw'V+:8 "R_ˈZ꣖+w뾂i&t|/-e7&/b Þ22+S#6ƙi$G] LU˿hI GV1p}r9U#=+y-hQ>Bs]Pi'gF¿׍cj(3WK6'Gb)^2N^}j+`ȌӏZնm3z,!>fdo>4״,>NILX4h%(=ܓJa{Wb8v9#vH)Fh- :Dd6B:NAg|"V;2eitq&ko*eTQ} .,<|;yxaH4 FgףLwfrv,cdNŐēk W}J6?ɘx"Q3kՀ0 M֕} (tDQbf nW׭$,#j i`|C XĂ`sw 7[ru6Hm_ k*Rг,Cr_ L%\`*&oMs:琋`Me>6σ^Ohīō{|fG{=zdjw $7fA:KtmqLSSl KD39(E` Nu3_ *y*kaBP{([ kxlV6:_F>< 04*B)MdՖ7,-50 l[n m,bX\'sFh\O(8hO8<#Z'`vY:"0iW%n2@d:q,>Y-A=/œ?sK|]C) ҝ/RHTچI~ሎʻV@ƇVr=L9Gྺq=)ّbh7'yc`s(oA ^DPy lK.Ne^T%. cX0b%VO*N#whEХJѲSgmXa'sUk BTP|;>CV[m˶vFX'e75=P0weړW<0.ws"Ƞ's': ?i~CG=ѿ$}@y[]n'' fORVRv;XY5a5a26kGDy,4bY^"^CT450s[oau{Xa4*I583Vz.]oAQقl]>?oWeS|ÍW#r|!hW˂ĺHkY~CcX`J JͫsW^f:Z&)ۭoY^YZC(mf&eO,֙S^{({^Dyhl,wZꏬrA@ʏ k25.njNzPطwhRSmiaXJЛXJ-,0ɐ(Ǥm!~E}+%=34{<-f<>d5=xjf[3۲WCJt Y=`;U_!>p# cB-V / `tEAۇ> cD ȂTO1f091Ę.ΩϱV>:wfxYc^.X"n1 ֘h|"#P'$^-⚨fy*vl`~=jBo5#\zfigHgoχ:[1ɥרNs͗x#Qi :1MXIJFJ\w陼:NBW?k8}XY(}|ө'!2?#$ΝH j30pJ0CABv3zsPbc~ӖelcHyF:G+*֋ ?WOyI|d$>6"{ԡH GIqH=U ~0Y5I" pŏ%X A/t3쯤q|)-bH#ڠ6B9|Ӻ j2{Ryr`7aLTrpVs 깲֐6l@ÖыsߦO:EQ@-d =AR֋.#>5c_}|C6-رhf~?u`KF0Aұev ^g>Q_f]ik=؉K%dBVMIc^F=u"iw#' Ցd߀7K[Ԭ?tE#'ۀ̓Ck¼wЅ}m+9<و&.ls|CXjOt<;/5$Ȃ߷X3589YBD(q([ne.[D`K䡆3L[M7S^ :^ &_njOh`ul;7u ͣp5\,$"ʏ7u%|XkEmBM/R+*q7iXg2{:' ݽJ#ln&$rMD֮)5+I޶qwLt}`-u ZL1%b)[kW/3C ܻ ε}=6-Si*6id(tw;IJU:AʑQ[))D08*ȁpH;4n E08)ԏs=?a[k_h 0Չ KG ̏{>&ghdNȕqcB?*ލy8 g-n4:F>Mݖu) ղ.,lVxWPbϣ;+ۿ형# XqkC=YDN}e?'="5fXϛj 6oA9FDlxI w:I tTv|2']osZ0g⡏0ɂ$wމk77LLH%/1"ACxbk` '+8tXrT]-t٦qpx%Falmac-:>ݤ3x4"9hItaF=ҳ̀7/:BUq3Kc.I>[FQ(Is+RjD<[b5+a4|ho+9j"S.z&.z7nAY r1@`ǡڡ[|AqK>*g3D_p'PI]p|?*AAțwTZ0]e\ -ٔLuz J;II{@Ϧ_ YsaYM۰`%Z!i!P$NHݫОO}u,;dK^ r=?,9eq ?xR%@{..%Ч 67? `,3*)$\@qVGRLo6f'&oEK_ 'DHz`9y O^p!cGNlEanXZt \ncs<7KM[s% ]Q^:#ͯMxW4G4S#j#X P,Xz3Wn5$.8 *3鰤eZM-A7\hlb.l\+!# i%7Z\ Iv04@]Y>MPF^jq"xb{JW~MA7듵PXMƻEa)Qw4`$bzEzIO Ӛ ,=3WHJ`2.{Ph]~܋OV0ӃW=U I2s6x&ϭV;w _d7}U9F.HF^L0_|-)9xV~FkU!{~#/t=JG"]R0%Q6ub Q 7ƯX=`ifWJEExkHFD)ܶqՉ Iß`"n5Tor/q0 Cc8Uf-<qV' K/+q#rN7w(AI)Jo'k)+43D5rZd)5@ 6n;!,eu1%W8*#\Z9'lt1Hҷ,Κlq D H#|//b`Xhv/POr `PUa {?g)wU)gpϑ9פB^ R; iXUg9 H/dm!ENjG(-԰Ic( Y3%*+.I7&Zsw#~YFϛHR$\3?p0 qGkb+y#:\쾲 p4/9g /4tSr8n^nYrCߏD \,&O3j}^0G>WS;&V.@L݁J g{pPiZ8[|c8frK"Gm{YKh9B%%85IؚZnV>3T,Jsڮڰ߼맚Kj[2py|GUqbm=܉tYBܚh p!KY$'v:wmp@ Lzpz|qަYCՏu]d_RRpt j|0s3kݒ#0L^)A߅0'{CH7gTZ{G`[ubF4y}ǣ{֘Z <@e,nSQZTyƦ9ֽMi#z YCdS <3~MXK| DjǔtԿ80Ze^00;DnSԒPd{4.E܇^O<$o=0Ho_!1U A=<܎kh_?YMKD`VK/?b6a2$:}۾-1RE2IDqETa62`.֊.`ֺ}l*D6@*%7CĜd邵G *Nç7E6Y@b!W)x q`$8:].e`y~3]-@aŝKe>%& VV>$ + hWHt ^/- bdc# x.5= m.Lk@*Ôbr'VrPqh|}D⻪8KFݘء{Hߨ W~)  n Lek9}"+ 7I 6kUoў*0oy!tWtfyfJKw$[?Ndj_ U3a_'cpt/w`Ҕn# 0I-t~JS!ï!|S>KMċ 8QP=7A!VJDZ.IG]=p}1jjrzԤ l_}@ { *. K q#ty/\:/*Ŋ!~Vjqɓ['?32;3 N ? [w?mZj =V0hU[ش5LQs2u\#;m̗ :6&S@̸|h@XcU;_M)=?ӣ t7*KV_ÌIAF@dя0,<\oY{b螠_#L[&9Bgmd;j JE%xhD;mw'SF/`]/<;jO2#ZM?ͦ{]N b)8 @0ܷ=}Ғ -cy%g{px_$O!ݾ`jƦEߋk'8(kO u8hXsPܙJBVbY_v1Fmd:+wً 3ʋذW>D3x [jg2Sh9:4# Xdؗݠ1cp{n\<6:Xx-tn:)ՋNHخѸ)hSo&~z*BBp[44T Lt g cPix?};=n6Xg-} 8gg!>z3&xFƀҳ=A6&W/\nq(PA"8S!J3L_C?2<Ѱ9Df+m ,ܯܠo}=; 7D>¡ze"V5]rj:L12Nɳ =(̌h|Y];M[5A$_5OgF7@[m܆Sۧy{ư9 OwZܝݓDgln{J1Tf7`^xKtJe1IxvW#̼YvYөSep:bKT.6p>m6:>\"8z(sxϽиї٢}aڴ'͚=芔~?7f ( >-$CogNr~KV]5Y( ])2OT#v//1 Z磭j"Xi !~lu ck-MlZӋ)xxMHܓ>IN#)G>!?c|>qͳܸ#M\v}Uc94.V=Eˎc8;4Wll΃ުp >"qD~A _(k&r%ld $13߶j 0&xk5L]Mєŝ]`G_.ٵiE\bLA9ɦIx?'ң¿[O.w#AjSeJk,vN/Zt7Aff4͙˶{.'D.#igي \{V/@&</Kی}#s;?FRg313PL5%YVI?Hjlչ ҇5 k[I$O{Q(Rlj[ @ڙc$sikz~Q`.h Ips2b~8AveM=ҕ2߭XfY\vp֒$eU896ƣ } EW>Fϗq1Ӗy0V7|ONT>۞myq縬&tGqK~%mo/ >!y9gnO1Γk/ӵStDubqqPֻ@ʋ ܱ]wę7R I~8AưOfp 5'S0*4D@K=l=?n76~$98?T-, ݫO8]J ITp̂H G^52t u]Qo1/mg[ YE]\5KcPbN[+ [ h |83'hD&̰)^| XH ⋒<^w-OKYuxkrw7fĊD7tF#Erf?)d@A5?\au"M⬼RN T$#^.\dűX/e$Izn杜HU 뀦In%n zz;zJlC9TINL}$]GdAdYЫ>7"Q&S Vf4YYɼFS LEav?XJZj̞sn:S&@rs 8"Tkę>J L (WSYYdΊk)r6\En6*͌f[Si+ ĩbNa;bfh0ffA<}k` $Tg2 OdI;Ql8j+૚'l#p,^nCKZooK ʪW*O1nP33Elv &vXkθH;7ϭ';F{2i-b )v7qgM%M].'o(I'nw!wftH Vwdl7.c*F/Vz٢L=:CǖM)},;;\VJ@6@WK5 A"~\.8KmjDn@^f@@Ƃ/y 2ja3wÙ~LC8 /bz"T*ܿK$E> ) %J }80+L[A偘\:g@w'pHG% x'&)^nn'PtP8m@fʤe;OQNU:A1ߜ&ט8REG~2QMdfv^PKKqᝰnqAUzU_PEq f>;㪙+ _|Go]D sSMJ_>8R[-Mw 4Gs<:D^Kʅy$_@bes"2~t \mP#a>04V, .cKITp"et&rlTr >uAŊ8Gݹf9NRJ/T GY5?ne LheUEaw dMTc7|) g;LVT羏\-6!X詍4r%ɮD3O2K xfA$}?Enp /.E&(PC)m%f#nÒ^{,o/2*܈Y(;#,B)%&?խ'!? N72Tb- n%8m~,Cj~߈ϸ=%,*ajwٴsc*@7tK띠uç|.w'C[ơUGfM߅zׅ3WI!KƺFaMTzGr-:Z<֞tԖ5%D'QYر:Xfpu6zHZx 2QLG;!$;[ZhxN>tbz' ۋ*}ow1A.$)mIB)slNReM V& t$℁oS`~E)fBc8Y5Fydia*x LAcHȗJ^<.{Ǥ;PY]0΢sIJiWNX1w'WD/97I=SFUIRf^m13sNV n)i)PMtd+$t.^طu&r0C]^+{Oк!bgIs FDl@s;m-JoHw6$\/iq;r*o8ׄ`Mz7DpDPdЕ/Px,.b #x͆Mm XaƷ:: 3Zćބ(Hr#19{@$'&A*V8$;_[ a{C!|JVfNJN{X1܂ThZP׀Xjضl {h=5H%t\7|'lxmݶ$~ {7ښݺIs|X!+},Ƽ- QOmSNv'1FDZo8~mYrm'd=R?43bo!,g7$g=m1k&Qտ'gyWPHU)f W_AEqpH騛޳W䏐 x>_J#TP}Z\p#i (9JUe{3ƶcTX1nKq'0ivR,zhK m TQ=0#ր@I -h<}lMqc ѴRAP%~I ?SL@g0;ʱ/%FALڥZɀ毬U/`UPO<ї c׵MBУ;|@n}`~ "ز _6G>1GȎ3n%Hr!2w`xdMKd!-|1aV~('e`_jnhcJ^W=czbI'BUR45opM?}m3t.kD]Yd@1S`}85,c'NڂMߥPCI?"ƕL>ǧ*HiM,B1O\wjQЮ:J$!bZ7Hh`6v|ؗ6 #("eLF ]  "` ϰDFp6 ^ݑh<Ƙ-]:X{eB. qA+/ʩܻZ$ʣ[]ȃI!0e~CVA9̂u#Ъ/\|yAV$/2&IA."a`>M؇9`VدW뀓(! 7kiSǢ]h߆w4Ow(˞`eʗEL{F:ͿVc#+,\ BJ}|'ө"(?qBeX<:HwS2}%zR UQɼk=#H,:R\ vt [, l:1>U$z#_ 3sa FmIx~#wmh"3fe0R+=b9 "[>lvXZԬ1zO“Tx(}Ne $}mC 23}i4m\>슧pكcVC!=|v8Ĭ*DgqNeئmDvk[%l[w.=Y獃MG4v>gUz#UGv$pmvI]4!PataҚ[}bWRhN༵z367O" #ȮMn"}䵧r,e$[B "VW!Y^q/oXD0 S _aVAכ'Qƨ,<&0W|E% iu/YZ 2.c@TrXM9E]xG,\=~YQtoC]!inqh;xN )oUL[+]0aM'慥/+ڴ3vs.{պnAѨ4LyŘP[6W_ PX&$łA`9~^ȩ+DU[}[Q6QnMkC4'P651+UsFS.]!リ0TJ+X;G{Ǫ/lKh5%,>w ZEa4}oH 2ᓞf4fӈܘ[ʯ떞\oQx'l>õxH+-dZN1ȪP"#Hh2$q%6pL*ܤ`}E růcaV1HPа3{2 },ӝI.u#1/Գ)Vyafa۽[NS_@OaZE.rMi(_i䛹"@B_і?Y0 8|9BDl"+r[c: AVVf`-R ?ܼnh|M¶m$~?&&<Pf!0Sdmb%9A3+tc!r%p2D+jWKBń,pJ9sHT]k\ɶjq ax6ڝ[Efۜ9ڑb6t<($%KPP\P YB;ruzK=tբGzGҼkB]''?70mm:5]}6Z,^jT;KB"BW&hl#Ղ^ ,Av-dG)QW^ 26F.ʕ2wuk_ Q-Q= uw`C^.C\ž,_g͙)ȝ~?)7W2]߷]BEx}2"FiEb)V! ;HJ@[ zK f~eݤa Uec@ x%m2.?%44jsaR>2{^ϻ$YGŮD-2v2_.@ɼ-'UO8t<㏂d񼬛EGEڄfTf&ô^$a&j=ϝPxN{m$Ye6q}*\?e0jB-#*Z/3+!4TU0e ΐXr V+A%7مh"$/0s(yʈbqi 8U!S|7w0a=hC 'gVęj/ۙk&dtn3"(ubL8 <%C2m(94.b(ӡ6WxM >?V1K]{ކTKX!oWv,zhn .2^I*?:ְ7/KSN=hד;UP?M>`RLJF=ȍ`xj{*؁ǁ1_wq@!Zy)$"[Mʥ)]X?Ȓ"JR;%1\Ӆ*|+ߴ>z-T*:T769Vu@4*i奮7ހ!;fmr{/O9B 0%@ܩH`ߵڣAV&BK4lcRX6$Q>#%o"STc.j8WVe!R6mfp;Ո-d}AXK1n͸ py2t%#`&ոS-m"M''l&K\A\H0}' n4%?`d Ã; a2' ;P"qUng.u7Vv]2,ҝq1Cl0^w7jXD3RIL.]cjc' ymv㚈:8h 4c8K D5F)I^{8m3f$Pu"oxD31rb).lpZ82#jj"nyJg@at3-M܎ = gf7ޕY8#Y\L'Zx*51W~rge&#}n(G }\g,̡LpWWBiW@YL"+TmR=^8i@# REԂ6 e l{e-Ls^{ H4=TH˝ot߁t 7bKhS]/pȯ֖ `mucל+%z|@ڟ]Z"&u WNy76tc3xJC(Ȭ=x6 C g|Zy X[mЦp_xF:\YjHg|g04R $>ZHoCo!wІ}T<$=y8O[ 9B!&4B65̊F7id+Ym1 !M@mJS*4 f_˴g,)G;G224d=dI4 >%@ˀ㷹zXtC?SwT@depZ'.1{d'>0W DɊjuMci1xGH[4N":{|eͮ.>oQ;VS{suDm`Q.C' aJ qsnGqwkTv|a! :]>W0GCY5PBtlP Go9JqTK@nc FMD%"N<Qm& lE!xڀfN wl:a*/xm# щ0`(w9 _αU2k-]2.J!de) Qu&@d?|-אSVhC!؃M#t WY׷w~ṕĨǰ?hp;Urt3"j0t…+ڍsvϓMN۱߳HR\3QB)]T)CXBf^bW\XQTk A鱛,Z98%&SG+?Re“\JJ\|/GxnbL]6,?P3k6rg8Eo8^5idOЈ.HX-Hmb])"mzB]B?0"0a^/{l3-BUg^n8NJDs؅5s%U9_΢Cq OQPwGɻ 7i%#`RYH)E@4'}<:C:$!8fOZƞt-~|h/Y杢Ѝrinm-0|mˎJ 20Q!QV<8tW1qjeXa6ElG-ԕb/G [kԔ} D\Ч˹1Sb+1B-@ޤV}2]@tx*8h#<x/.iML~_ (LOQW 4z[-$ɜ7|_gWzpN >hDHe/vQW.4& T ʫ&+֝B$OȌ*+ kP)Wr'tY׫WŷFb,~۪eX!5Aav~fy9.d o>FtAQ%mha$!K,86O[.&*=`hE 7l0[yd)9^>e򵚳Y 1|Dw].[c'~54쮀BGAax a|TM;ʎ5SĈnXUu=^SSbiB)<)˓(9Rʌk=ֲ^RDN꘿xD6]AY1O`AvxlwЯugÑ fAh[l6ؔڰCG()#K3Vu+BdYH :q]AFj=L>,`Mzq|#=F8j&FY&ү+(Җ;?۾`šR0;{it4[2|7|+ #tS8gKHHZs;Id[b~X: ^F|c("݅FWޯ .5tHD0)+_ElCƷw7F Ep*cHbf"BwI|e`jv"|2{_2w̎~Z^`~ *b-:Jf؀ftSiB3V @Y?] &gYO0dn|S[vMa4B A׎tgq'iEÇPӬ'(%fvot=~6\UN/"ĭn+4u`7j򸪚= U 90в(c.qh!n\|مڪ?QD3A~ QN7Ct| x'x }kWVTQ>sw0ڸPd i_Fjoowb; ރ8~[/wjl6YvR_TЏmM~Hx-k"y#<6gi4@FAN̛%Gm&X75U΁&8If\Z`g]4i-Kң=by$m ݁et.XBO[{Wuҳ%/^-aԔtqD/m+p@ CдҘ D8AJt`bV3 q(\ /Fm떦QI.YbE{u5;P$RA]9x U5<,vVl-Ae +l ~ GK>KlLJ beo#6fÛټɁo;eUj@ @œcDq55Va)`L֘:$pEk=xƍ/E| )G$ğq6Nvv\rĸX+r4¿n+"-ޚ%Nϖ~ŮAA#jqUxduu JC'}}Sx\G`;s=Qđ NAF=2c<2Qmjw`# d.g7fvHj[՟ k\5HbW>Ǜ9Nyc) '*xbvgM wZş 0ҰjHu*cσMߩЁevfQ`<}@fG4J͍8ΰ4L<6\\Y)^EOWpH. Wjf[ʰM#ݳC k x|BIFM^Z/_mێ7p1^9bX#V :RԶGDPg #K+_O8$ 2C߇TTȆR5ZeYKU87yvU%Xlbf?d7!3v#^}vMOܟ ;a"52uR(1(.x5)xG]8-beM~g_{.f}EQQ=&u2RIOv7NNt4ήV`ۗ (;-FZk10e. E7A.ᤠB*I^nekU)O{B>хìٗ %hDUz2 7/PjEא全)sjȔj̄xhdVjK|uӡbI*g ܜ?+V {[.E9= a];Aj̹۸RI %iPcQzUP f]؃9W[ NDR :#?$ NKNoɦzF 3^W ?~E!c@~ANn8 @|a"%%6.XOmKf;pnHU*N s2jĈo23nfYEyEԾ Msjf6_jrL@%v dLȭ t#JKgqk%zI45~MJt=\K2PijB4n2sȳ>H*t/ L1jq?2b$̛ZAQ@pREב7{n$&eaIPWauJuU8Q3XysozȧxVaw]_́)] 09NRӨèkO 37#H iNK>&~Wz ]D8 tl챀|%&Q\%lʴteD`jwv2zqDwuØ]Xq єvCű_^ي%xb 'ZF*GYbªeT4TWY\[LmoiWll9zޕ6X- ^=`^GM?^,xߚe5zVzLaIjo/Z]q"8`">Lϴ+*V-3U8rb*߷"5x2C2]B{{Tp㫺SĨ{w2}餀Ф%iLѫN=/5OƙJ&Jz/ΧmlhψT\ܨ*n J:KeQ1wƻ,6SG'j>ﯜkeө"90ghyl(KEA=.2~wy^G끉s+sѬ VIɨAr,R܌r;Gb`Qߩ"+؀Xp̚=\DSrlCA1uFX*}fKPl=34]:*(??hq70#H)0mګ3I\# B\+ B]k. V$1KV*NrԯXh^(m O&݁o?ͩ;t3R/91hj[LLwdRGԶ(te P6[e+0\>/i'+ o2Qc)C%GfD O`AUa!%5 [A9ttp0p.j| lA1 ufYI1gebmzJ;W1^%k1AbrAH_LMJq@ @F};0-w;MaMFTo5}ct9j6]NLU)Ք1=cu@ulV2(A3z- } lPNNs{uCFgKY P\l Pyw5.̈>Ug74-L,hNJ@{2"=`;?NOcЎ }[121cD+ Rk.1mG+J ]NJ(L!O/-!!YYdW>^mw_G6[򇔡i Hi֧~yXֹ3,R_4PROsCTjnaVn\pRF+bPdy|44 v\^\fğwJK_RY.wwpOXޤ'f.+4kQB@xl4NG?~g/ǝj%ϕw]*=-L73d-\ @Rc6jЁVЅ^> HI-[*#D*_ʭ!r.斑\hiULqdēJzl9ãhnVM9W@(U}#rzܶXmo5}[A "H!|;9ݱn84H^u z'͋fK+JYC'T+Szm,ȞZ9OqcUl<" oOV"t[w h[rh S0;El@_&&IrOX ]&ePc8jrm]Mb-Pjlስa]jZeQׯGzi(Z/{@'$W$b&ALw%.K"oP;iNϾ:$J 0\IW1FUX7SR,p8W I9$ SEQg2Kaf {jushi\>5>$,{LQf,zOPƩc1GuH_SIq (J3>o8ti'tъ_o~Z>jJĝuXWd]$_n TLSWon)hĭAM.-/4F٩͌27xXfh\QrCG-=.a1`(ksTǒ!0:ݻcg|vXd_[Um-+xbUC}H͂8e ! `Jr4˳$ihcͷN:)jxcz1X_劕ϼw2,(FD(lcJ:Y52N_ ?ua|Cb{w-:qWusF7(zԤ$k3JYUCĦ¬Y;',8bMts|f?&HsÔ=1uFnoL~r!⛩BVs9޻^MKF @ {]zouA$%zBB&PwL7ZbhU|jTY:lF*xQZpWDe8׸Ey q 1p_FrφifPlUJx0vBɔY(^. 8UނfX|A\htw1$AʿK/[վ]h4?D$`и1u)@2Gz_]ObWq.7kq$ZVj=l[mt*Eu H4Šp=&qb1mo{",A^eiO%BK_}=InD%4ܲP5;5&>ŪFX`y,ߪ5;7e.YN!pI{J> l)&9$b6b:f<3:u)i' ,q45ݮ1)L2s0@÷px/LjQ'O |" X0帳XFGC%$dB!fT4! 4$36*K ꘁGΫ"Rղs$b^7nɇ+uo@ 3g^vk)&>s<zlU|C* @9de5c{p2+SHwrjȵRdMT5.vxm#ݔB/H<zO%PeQ(hdKJ7:ޱѡyJ<VzI=F|\zL_Y^}4+.(fU'vLIQ,^&(Z[y򥷶Q%PQdn֒/ }VM2hȊrvedcb_FtzTYj"*9ϞԓyǪǞ5JaOi0ʪT?xJ:F@:H0>i>"s}#Cy̲\N`=E[Ć=kHy䒠+fxi{ܮ* 4~0"SWR}tboh⯣5i?Pw2 yR?GBϱ{k3xq:DSvKؾ?WpjuGZ%t IU75f6B7}Vq2.JpjBF`$֔ *mXEʖE,U$T!t <3~7;ﹷIscyYzR%diIg y1 <& "2ô#]PwR98H}Dl\}_.tEa\n5/ZXv{28~& T2H 4EvhsݡfMfLFMBȻA^>]͝. QMX/ Z<89y43t±ǐ J_[gbz׆.aWr쩠7p c&ʠJC!Xc"-o=9 |@ c2 ҉Ot$0ID+*)OK7(aҌlE}$c B`ThХ(EztLC1q`bYIM3|F֔/Y~S`ܶ1?&8ǀ ўa+s9;=,ojkҧ}]SYȬ“=~6IțK #>H>N'B̾CwX `t|9 is6Ync;(T(9t3J<.?i! !k_q0 Ar9 t6lYtF Қĉؠ6+ܭg6q^'1{v IRBܡP\.HkVZ(P>@AD|py8{ܿ&W)B38:hNքf-`8YiV[Lg7^#*\̗ҽv0Ȳs. A:[6+33yC3[{yK*Sm6;DZ q\'tnx"{H~ҥ QnԢ#[n b9ОJ˲&J*]Xa gTqb:Դ STR -I!CR!T `)awp&za{WclB%49 G.Ryቅh! Iy·<sn:v Yip(=d|ƞ{=+) U-ڭe0L5&wR*rBg,AzMf l!ZYU( Yv0sz>BU 4h%t͉jppLZ@5K)i^IDŽ/WD"Lx_muEne@gs~NN~S4`[?sZ^|;"SfÒ\"Epރ5h=}ܘ]8dW,yI ƞI`}Rb4t|U]$yp_Si#>o!˥Hw . 6JF衰8#HN˸:hYZJc]Ǚ- x{A?wImr w)n6@~{G4Q]{`[Lv%)rlpFqO!$9[Un]&L#o/.Z:VVy*‡?&bASD?Ik4xYmː{`s,V_"u~es˂2Kqca6]e<3~45,6 8"Er)Vm͐28s_B:hhe:Z ̧= -WnXF~L8Zj90]>  Gd##."]4~{ϠRh(dpH k@Jo_6P,Dz ^kp=SX@d~p4^ɖ΂o  nw>u~BGf9rsÿ|i Aqvq\o>$D37b' Ͱ+umVw[ 77;+yL:" ֲ39ǮSha^`5b]~sXqV2 Z70 FE#zN -~zC g*y- eoq.D9e] mi'g%:BS !-I0o8ajc7U)Y3ɞec‘µ&LSàǮttIS#! `48 )`'%']1 U>n [ [z:4%$,[d .q(vjNRoV}Ch}SUDx觀XާxF,=bX8!pjmFz&IeUk4i~Da'lj 2zt|) 1xY=5i4l9c7$6>h"QqxT*m$)lȄn7Vְ+o+-%B"([{k8kK ~TN^M! ߹}TpM|y>\e!~KIYDvh(`Cٿ׭T2~Wųp ک<|J| N*LwXein}`Uf  b<Тk8P+d{"NE,=T|*)n.o6q&ҍFǛa{̐h |`&`fa` AIU-ȆQb;1W 7yPϣh q^/,N%YkHvzj4-n!b:S#%y8ʞ%~XkTs.һ<@kCM$ bNM# ^\)XB:mG_cetgT5 ~zS Ӡ2ՂaHh7+Zs3$w:Bwkztmd7ܢBX*đ]MIiI2oh'̳^ʅ3?y7om&%҃8]inyt%PV%n_C cV:vUAZC&cs69s seGOɣ L(qXHޏJOYQe`fmOw@47 ϐ!d:F55J;'Xh;bQt^YV<0qSIb5fB_nZTW}}̤{p yM/4X]_6 p>DL##>7J}@"e?pQ8^]Dj@dqL&aS.vXၤj2Rc.;q+f#Y{E:59wOd zx.t:``E]].~Z<==[k,D}  e1ha&L;tn@,央Ω7Ubv]F28A_+5}ißه[Fqv 6|@-[@uS;)ސcy2j|~ft;9A`] OӎߺH36kj,46 #hwvv;5&d/n m 7PV-[eg8ΐYY 44Eca<:ǕfəRYނw94^ زV@Q1;x ;$JrZP! gT0%%y*0,pU}J@5˖yAF|R%hAp2àrydfZI妅 vubF+(á1|\Xƶ/9xG{9E. A~JXx aoH$$ogC6E}HR9 q/{%)SBhȢK]y6K!?>(j_2B;džRo,Jl©igS@NE{:(Um^<ӫZO -I0F_X=֚Liេ{L~ >ec3}3?+~Gw{s4oQ $j͈!pdǴ*uWkް?@~ E֚I""rgFSjق*͗kU J@OXbY`nzxJ=WMPt!ףQgiՌPb1ZXe"]D$Fׇd?z֯%I "?&t0rq-}vA)!ľ`309s9UE\΅OԹsšOIDBE[@u+9Έ^:& ?"R9ayyl]%bŖ8 .VJx(ʚZ3:[7cEEd\‘;pF= BPJI n'~͠Sq|cM}S}fo6q$Jk<)Jh>?"QC&$|r<"OXL1P7,N)ycc-su]CSiTO]lN"1ertr=S,rfZSo Lr:agQ 2rvnwR&^L2Ƶ S߼yt=( $!jBAIx  OڷW w;WiB ;HK㓳 wҬsKȃ%f!|`T !מ)Z"\&LͷVȜd1ث^('9'sG(~s@jyC¬7\^gydqj⭵!`[DN&(yy9>,Dj+/bD~\l `n0_(#=?Nqmy(KrI\ urUQ6 ;((\,5vms-[BaXrelEE7hX}Zk8q^gHH4E:,|?ZcʣqSEU/*,vW˛dE;B4u5Wj s8y%=QKuۙU:%u%'f+v.V_Èvı mv:&@V(Tn;m?۲C pbMֽ oft%9H=SmHo1K0q=ߌ4Ee~d2QYO'M筶e e|piAڑ6{|- rg."ix g_aF0c<؛p0krH`Q5k3AZ$ |uW3&w[CAjPLQF6٘x(L"`wY< -򯆗3V.z#LrE8iMu@3Rn΢HM"1dR dͻi(~1j6_z$NJ۶q0l@V$s6q*Wa3X0wf ׍02O(OWiq-=.[ChlNFB}ܐ(™! "3ݹf2TcWĴmphI0?Y7 Ydq\x\1p E=6'ܩ"I U֜,brጙ\ tůb]b}d*m RǷu\,7mbmU7s!+>A1H4?qGtbԩsF7&X3K33|=mEᨆ;ƑL`bvq$t|6Uu֭mqQpmJ]0c{aK-h+N. '*/g{7X1SR =js>q(|K&\^0x9SzfR\bhdE b\!|ׅ;K//KC N]DOR#C~N;WwnP)6s/S+SlQ#mw움wE cjvǐr]<$9wGS <xwKe5͖nyޥz-;&Y ;PA?ĊLaTB:@1CمKz dMEC34CyuP&c{7cN EWr|i%C/*i9tEHumCEW9+.i}{| uGT|u>Y!A =G*.ΪR?*XuSi᲻[P˜pdc fD3":Fl}\Sp9~an'*C_\FY~7P#^\pdpсg*m i?*)k OK aB }2tMm U:Mi<T¢W]`;^9z31}443'ß9gtG7IǺM$2abJ?$g"+O-cHh^!0,ͽEJ#gJ4 }#ק렮?"r]1C-ª~{$Lg9Q+iZl7x18,hANc6ԫv xD*f.dRȝxV &4X6+[/|&}\(`'[REt^Gtp*ivOoq V$BσWebsRCljqaoο=xadfվB TFiGK_-ka"a7˃⤸GT1]]2p+57]wdzUVpx4T$rY (9q? 1eRmx݅n~puU/ _v)@_AgbN)$wkEur# W0t|(݅&A2=M_<LܿUEfZ-¼c[ыǤ2>NBdxco &AZ`lkwskeZJ3B}B^'-W dx9N!mW𢡊Hj[50%N`C;nr(7"8dv  5'vQ5οw|o ߤ("y@绸l)0;EUv/̎ $8޻/d^W$B_CN$y ;uvkq%23t%\{{7.Z B_7DC_[d8;35BPxiѱtg8:Yd~Ť)H{v.ϻ[~6R Eaur`A] u +3 uQ2[O]wper-1yrK$AwV! B YF 3VkBA 3#m䬕#Rsi'PsAe̓ng}[/I*d`#T KBa ou ܵY}?n~f $:iE{ CDdl!EL] Ֆ"u~]]9PT}J뀼_n2ef2|^B7I]HYG:{s!RvdqbeeKDӿ( 䯡wbۗ8  {aAt䌨[% 4(2>~0(H1qQ- [].j{vrw''8%}7 8>Go{ $"r33.}LWH ӗx 鼪#[ @҂YR7 Jӳ`/2ɒQjƅEF%EMWQ-j)DJ*yK)-)^/]' dp$X;wb`:^IGK%Jg.ώc2 EoERL> /8 HFPa֖nX5]xX4 VwKb2l5qsk̈́5WIrũͦVUuڅs`~&D/\xCN吴 V*e<+K79ep+!Z%k[:3/:K<'NF󤷼 r:O:e>Kpзތ~L\:ڀ'kހz;OBPC҆n~uż#u&DhZ>^ڋu} PDnڤ^}@ cso)Ԍu1XSlۍчGM0.cf$qj{17=#!T>Km3d!OM Y30NE:H_rv]wVwXN |bPWPf-ѲpBkjq ]w)IBe~+GpQnh^v>>TLK /KU6x49"0ѸY6dnX$Ny^޽Mv ċHh){o"a=w3XKAAsAZ{; n nqrzgԩ4$?A=mo]e[5%KN:NJU*)7(\l?1,@Q/ *\^ǀ0鿇2+X0O׹;ee7W}K{>͆.+ARXUnm'3hy/ܪ:θlxX]=CM%"=>\4X)~3ѰG_fxSg[GRtg *:<&2 72,*ؓx4M(gң8?XoUNtj~c'. t[^ ӈ"~;?&{De{#(i}Io?՗¯;zYCJ8|Cc{ Kꢩ)+:[E bbֹ.G_Pح}CGT1PT+~'F $/2/PRSSHJi8z2O CzGuE2؎^[ԭ?Sӟl>6շOc7I< {l7(ø]Z'2x/r{^O\WEWoR<:ҌW(qaWvQE(wW>Rru֋.θǛ^T:JGnq+ٲcVȆ`SC\"t]`ǻ\sQ{J!kz:Døa`i'3zyYL 0/ao ccy\{+x!w @퐸0G{uO9 K\y6it]+9-F8@J]M%p?ȨP3igXKI18`D?Hc VRu?i16$yRn1X URNݯ~ןALDߒe^0oۀ.p⇩%<~WpT 'h(t+U:W2C:r7T=9ܟE.G#[9Wb]5xRiFLz?(Lٜ+M s#|MQ.REJw^aDOy*X'虭.##WG@qXܸY`:oOenZ)yFx( 0W@I E%[.&}l Da5Rbjg_GQ_=̠([{VD~ ;nj si-Rjc@C;7DPmG~g5Ң=hFV @%$ x lT Ye_,*?"6G EHoPJp!Ǯ bh?`A-0}nT4̍#׸U]< -??uq+S7wmㇳ.+O {@-{s jTE6- LN4*yoEQ.F&zmڅ&$Vg!"Sb 7JKb<:zI񣻼ܞsjOsߴTN"! ރarx=p}Љ-+,]~,m؉sQdO`F -gfAz-TY(AKimΧ"x^Og(&4ylvhCgTI<$>PK𕰖&+Byu2HSPOn1^\XTzA= AtUܝ#\$3| qXX0LI Q鎺F"=ͩ+@D+EX˫Uş]->^bqyL#3<8&{@Q܌8}ynexޛĥe:*{ᡎyl;B{5"VݮST$a5]n-&yͅOf0ļ ,vmf<|4?B s7)Srml{s+5l,Mu1=[crwy,|Zf@pFR:El)Hꢍfag>dU mǂ:Ltxrh>B`&y[dt!|^YYϘQA.Q:<(k IfnMmVGjrnJ=1<^&1hQqg ^6z$ s!GRnGSrb@k]ˢ_ND'^W%2*)%xQi ;?x`g2md\^ېς 7kcIEE6C?y3yX#L8=,R;*;%b_lI']A%s3籉9(V p. 2zZn봚ZѼ2hd ?4`h<~ϛ;% u ;+b{9]C.x'Jʹ0,zh.p#1lvd}UrR+R5@W}ÀѡICJֽ3.W4DI&q C۶]7%/y:\>um R /R*nQTM])6Y#NxݡoKEHХw{ >[T E1˲; ܖNe #ۻa|0Uoz%xR{K4+0S e z(t_̂jBŒi/&eg?ԯ# /Y[i4">dV݇oT/L\ŵJh0}_IQԙ[&R}٫>7b4 |!N9Dy ýhW:YWw= J]SL·@=5hS(e84hpFNQّMtZ|\"S!?JzkOѥ<7bB; E~JHxN5YE 7AݴmjNb&CNuѼOXMIM`CRNN:N'~e%Q:A-2e5ę2w@&ˬ& G7+h|eBrw|[8&7W4JXu`$Bf5\*Q\f}s'WBQD-2JQZU11ru  IA<.l밆r)q^/ v9bzq4yf&0"A҇{N7_+| cC ?T 3zS(-54$[ycsYSy:NյݝLrzV꒾]\%qCE wQ&η[}ICu@~lEu{{Ƕ>޶wtI zp4RJēm+<|3ۧ/\z7O`lD-T\04*ɐ {֬M]icք*bb}w4Ao4xc(A"Ebφs~9r* # W4}&a?&pCXT z h]4B.TxY-ã9D?s"Inn :SgOo= I $sdۊCS/^N* Ba d) Sѓ,i,b YJpO L)z׼be( Ew$'j2Fqf{q"\ >Kbv3H>M )~}&t; {ΨK!_qumD^:'0뇖mT~?D :ƵG`ejwrZذT^w.8-N#Ϭ̢`1qɢeiB?#Oȍ(O|G KHS;F M,s: t)RY:ڥm:a\p,ЉwbZlt]R&GѾpm.DQ x-VcVDVϼDAl?L%л+h:w1l;Q Dw>qSǝ1d_ ďZkǪ˧2Ŝ$nɕpTa& \0rCU) 8}wB=VJTEu&7;aS;s?flxDSfE a&5@'‚Sgk>fd~ceA<>A09J ƀꔱ6 M9O/™[$\Z[?u˺w]'iG*<zfkAs)6? g Dhh(P[ 04{33=v)D{VuMD[.U|whCUq2IY8G!`5薴zZF&SơJ[|3@؁QA`M"W.N<J"y0",B=hÒYVU X ҫKwa#+ cۑ}sZ3 ZR#p?榞g1¡镵ػ~zzZpV=' Ȧ\ɖM3QE`>L"J|7k⅍j;uϰ^7# lPOYl]KL[6i|?\*ĎcwQ{w*B`_| \7 MzAnϛPaz3LhuwDRq"+=]Jy􂽵 j}Q`Uļ%fw?leٲNMlY(ydI%)AFq͓GQ0SƴjZV밫ƛs[)͙5Y@9brp} %hNuVÊMz|y>Ī4gW\0 \}3Q'˙)93r$H02B Ei(eB|\5GrCRj' (E|&eF;|`& n?֎ST3R|HK(UiWv(#uڤ|Ǐ*ǍJN{9( 3T`Gg(K:Pׄ?D"ۂqj?f/ =:~dg%kv#'x~[ܲ2 N؜ /?)\{fq dHRl"863RrV%,sn̨ERX!Qv@7w[<ZIBrUc;/: @[7E unN@"GLÏ7݃_orXSeF!JU)p+]>kp⸒N}Á=)w`¾&IgQ{'%s}tWm}5NXˀmxE,.M!O,mHyS]rlBo3nCZ^bV9VD)icXZ)7N{i"ݮ<:P=dzvQo@c&&(]|~E҄*聀s.OŨ)̿3t/G-ṵ[] uE{K)@8.f~KCBE ӠLӝ IjrX=BnZ9qiˢ=p eeP/5n+c*fx`,өQ9!Fu!}nOu醧|_qeڛ)ϒ U9r3Ν.*1@ ?-CN%N!0Z^G| V,Vf\LlR#Tߚ> A.YK9ҹK^TҌ Yr5ؽT#7L!ױ"DQxq9=Àr9\"5[HR:*1DcE\06DaɬϹ7)QFWFOj^M2%lp>&H2Dz )фnQseyq݀j4 u(6~4amO^h4^X k[Z ~V4 86SobL4γE?rio@5QX_ʄ{T]i yR b)Ȟ39d1Q5XDhFv3 dcV!Ӄh@MFM7_ZC;a"JK|S)Vg SڙYq!먄:u>|yrIc*<e}"gt,s]})}ṟ \h<ʟknetm嘪˚Į*1I*e(m<~M-% T;QR~7 6Q*%ۚiXjifND{9uBgԙ)3$柽>\CBDxХ 3-~L}(9 ex}ڬ5ƇQ t/IznKstt Y_d̰ɺԙ9!R);CѴZӾ2ɿ*>"MY,%#Hln u'vRAKC*[_Ilx=`KeF=Lg"P] vK#Bcǭ@WW)\4EVQ&uל1գ>p4!fYtpєgle| vgyfdMVB%ꙍf.<ǘ2=J9y7Y!}[TLaGd|;bW`HQO}=m):yݒ@ /oFn1g&-B(Ѥcز\TNAwrC_%)˓xL9[`# d|Je녝ıY?98VBm]ڟ tiH^W ww =xaIb*cF_ؔjrPoޤR`HO[8GjN{וdUY8qDӮHLK#<@+/ܼ8۹eE߭5j\x\w&`0i;13񂧺ltӀCn:[⮙u~ޚW$OG^X琅]IHQQܙFV5c`JCb޶1IfCIԶ,D7lFzt 7JjSJ4ܫI;ήNX/k`ԫLl}9K*ʮ~s5ll4Aw>F @'iL'P9HehH)ފ^!rF xCZt~Ϙ#Q$\0JVqsʔ1}~~J-aW PX􅐿QKtjN'Z f[('kkugeXsP~%`"OZEݵ_W 5*)CҊ3h#7LW =|4b|סQLaԾUʜ`zV2//:ԥ̻\?aq%x=8Sc8DC#sui % ɴҍH_ aOsJQrk"Ѝ 'k#9'r2GҰ"}i%b^ 4^\TS^B6x @B7q]qtUacFG8h5SK zg^㉰YZb"1OfJb~\w QPFO\=c+fOڳŹr;I2@{nCgUk:6WK6uM JU;HRr fz)]wߞ ,eJ9Za@ysdtTni[zy$T$ R>,8^Gb.ߐH#<&)QIiPrA(+^F}fq6U=B! $2HP&z$~*qAeމ+X#/w^ʄA-r p$[Db)7DN/S2J;= u㔤CvaRVl^ǺS+F>?N+ w{01vbG#b)t)ϥ%̀ƾJ3 7>KGP)zΰ[\~gp I؅ =@3W0 D'1hos'xee ғb1 MD`E ad@蛣o$z6.eGVaTB iq@SAo 畟(q/j7a֐-4O`-B_hopJ/>fTwj7L7•uF6 Oh]e_fmw(A6`NRѫY-7qPsY6BM#љ_&%t]꘼fAVhgc1؀a`'ˁSˠXͨLg>Qs9Eꉨ*c%4 e*+XV=?}55:Om_T҉y:v/~m< ":j \OeB{ 1HojOf@E8_?_[P7Yy;)l؀[žE'z'c!B>a#G +G LoqCV&% ,jcfVo@,6ìFglg2a^8ob.ݗJI*]34ٳHPv޻AP yXB{+zxޠ]mΈSI13y?6hF%ea+d"vuM@_ēvb6Y |,Ҥ{7w= =YBQg+BjY ¸1 njz-zMmb*DrOql7#MPDmǩ2+wĢuFY>}@캴VDUVN5kf+#Phˇb?f -<8E.4& cP,u!ԴBVKQ(]qS 01eY ՗A3 yC ]R1NWuLX(U9㉘;CF#D 0^S^ŧ1H3{L1 *]z^5 0~s]NleN~%s(q$.KSds'LjOƘdQG,옹'ޮ^o DvJ΍S{.؛kPF9Z*ڼ7|ƾ,EBBV)IK_:o+^w̴GizW5QEPѶ42R˒Oyc_jy)Qk AʍUSpLfic%[EtU(w=^5E-fH(C텇Sl&)2R#➜ʩ̓s3CMoף{}2\xxַ%ufHs?BC$ӿD8"Nug2Y3+8G9Bq'L ց Ƞ'>I޲.=Z^`qdxG3yOYgn1a3hU"<_SU(؞w> ѫ{8G1_I8G9 P#⒡ u[sw:TWx;28 K B&.`N \`~vfJơ1-⦫fⷖ2\VLc8 _ ==x݃9cdO]_}cemX8d%I`W&(+.63,Y_Dqn?gP9fP؍kyOz~@p?tPɬtִ7o%評=Uhx1Sb#c xɲ6=m XږBz۲6fFTˎ~zNہ@GBh"j{Ă FFKG j^&qĀ0N̂CٙF'쓛~N/v%]Pa[7Pi'6/]s/~0'!OigtAGNP9ֱG|Sxb"fjKll0D✁_o50BV?Kfz1 G+ SNK(yǁӫ]%Lz/4r8}7 V)UUTSI.)yesadzr'w]җbIxUJL%ާ;axNp[28bi~?,l)\pVH )ʸOz2U 1EHI۪#o໺p#~azayZ4z$94j8K@ȍM[Pf3Z.@X[jtMV"3D c*Ǥ PƋ6K I/PYi:=b R<9~vJOP=ZZ֔H/6Dχ0=WU~7=sчg)5^˫KG (:b̳ pAgdՌ=ŝf!+JJϸ?ln1K3(v7=^f o7n1I~&w;E)j||Q3kjz\1^?[ؖ ]\.)4ۖtogr]h+(49,OGT{8`o0]sFr }aj$gx,^~@Go3E1hW4Dю5uax=ŔZmԻLW+_4d\ry-3_ffwȘxapwr̀.ЋC"o2%?YX_L9 5!nJsh' U[~[T*-#DMelNsФǒb_6UAN шH M4Pߎ2$k@1=o԰9b.e;xJ_pt]vPo.2h?h A v3= W2QW!Lx#\M\YcE (8tp#{RX5mtQ\=nB+(V-0iw0^Dq={Qtfc"73E=]H[bg4g^tlg#0)\{Qm/z੶РGQCij"ɍ Vj; v1 &i3NC@D ^9?3D"o.gqHʶ,S0 0h:f^l,gS͐>cFQrC0T@qhlANPW 0+Rh2ZQoU4W*a7⁈&ީ1&VAgS3!rN#0eÌE]٣n֍J(oX3̓,zGgv/CA W/AlMO"INF\YČd"BNfr'(QF0Vyע*McSҴBW!Uyu^F g_9co|8$Wv)$oQ(M N!+E$97NAH7 hiG!ej _ɐ[ Gg<5: :nߌ EajqD-eE9.Ұhau4@;f{QŒ=EAl#Ta$qPbCL ^~'`WTUA/D%0ۥ ]ȥ0a-m${*e{i6GO2/:oJy7fy ˲%ǹB֒H)273AB(ЬSJn #7)Z%5vJI7jt)b.Ӯ AB1Y |cW1NEGOȑ$ i! 1!F]ڌ=Z*,ȌBgey5Lڷc 1|P8 a&zZ8 y" FAv<=pBXw*b[_Acm+%Fbw- hD"E“U;~Ƴ$lߋw򊫜;;VG h\.[-K;\)UAC@p\MJ{ߝ m־xb?(\As:cX_J ק! ( 'I93niʕ?vϥ.UOm=m yZ "4( \*6 m* k2y`&;C^ ƍ@ebݡ:J G}M$ߑŅvœ~TEYzMd+yW.l*6 !Xz$sԵ)z WB ݖ!|pyh$+Z9eq)͐F+Җ"&q;r,Lq\<m-{֡bH]5/-q !]X-mA'`P:/ˇGƊls]LpNW L30851#_ei⸈c>D|s545Ejx1ptg OD%UUv~a}+l7c5׾z7W$tg1[Z^{M_I0S2:lRWxDz,Y&T#fMh{.[epPYQ,c%K u ++UsXtj}."*\7q* k2=eԹ4d ŵ[vS F%lOSVxv&*T?^E2U${ SPAW2N\gfWE֭*1/#(5xM,2TP+Rfmlm*gHb\].ɞ"A`' ,?XbZYde0l;CG2Prg[LqlF\RrP[Diz$+qm)U#2 zџ!(;unH ,+v:E-L}w15w'2UA,Mq ,YJA)x!,4B]xwhn^@/.N,-|xɵ$=l)cꖣhPc|{s6pKЅ9[ pf~Qn 9$U 1ۃNrA|1[vut'[FT;6UyVp'A,GJ")>@Vqတ#𡁭h";j9J^:α"c-5t`n]fT^h][AEM"~~Lu?~}w"9*FwJ+yfq6GpBy%V=>{A> h!@!7{*l-Q~(QS~_g\7(7ǯCd M>q=7 )$LR5>h&Hj aXPq=7]OsWd\$I؜Us"Ɗ(Yڏ˧m!z2"2m'y-d@j$ b ^&^) fO]0SW8}[@UXFnW< U@PTI`,/*Ej7w&0ݧFL NtO8dllQǥ\ ^P(ykwTyYݖD"LNBd1x ]ne𑫎(c4IH-G>ZP6 յE~f  9*L<p{ϸ-sQ$>( >Ql%wZR+nyPޟf(,msn$Ż$"ҘBy:5I3ūg8QA0by7J'Lkc,."SNDE.&~WXI$׮t 76敲p􊊖*{?BΧ*@ Â-vl FozuBG߀;V 2pMr?be oN A*^4 L)%5˫-@(Lc9p\Ǔ~4^zHT"BZdrUhӧ);NGRpИd.?u4zZcsJga '!ˠ] kl+G] 1 yxU  y&,87]T98^at5 9岬=X+Dgo~à0__wvo\E EVbw9Oy3Do%ޖLu3AI0bq$`4-9e6enGG*B"P{c>t>-!` '7۾tNSfv5$: LORfUW0ˀyRܫG9Hh:p /FYtب˂Ǡ1,tr<Ůco%qtٔw. "߲a&F|kZ&my "ˤs.jM (ۑSSڰ)5i0Ӌ o1;Cm¾^1'h$_ gP$9 M.O0RI& Ha޻GEpt%av@, 6j1pE FP[ѹ.6Tݢ&%iYĵ >EltR 4yy~cpL*OPPJ"-\m!WԪ[m>;V<6DV}PGć;MQw腉tk.u) ҧWfQRK|D1\xj~sk)jWAd[+dҴ(9Ƶ84ʄU'} &@K$l#+y.pеCVltds#P*>2wpp% "USO'Ybdli3B:e$՟g8GoւU 4j(!F`şy6%br9=Ӌ0]_B)X72pg=EjT/pfӠnJnz[.!!EX’L虷y*34F7RJhai?US:ck edx7XI3F%R\ՂXmY@Re [t(bKlC.Y=T Q__z٦?// C {wa$iaxl$)1ʳޭv { luE@ ЈS ts l~jө8iU5p󦵊T#$J 9Bq6xaY2vhdkK=w ."I>oC8/EU8AK:WZ ;^%1"7ΕSU)ފ6 }@2M|.6uTɉSŊckĺrIQ1 CU;h$%D r ۖ[dlt_sX)d#jqqSΟ#uW~UEL.h4hD6Am+]} S%4B'@1YkKn8(h{|cUaJN̩>xR-]Y[bڧ+0k%5HԞx%801[`ו?>DI:mWz^ #9tP<$G>x,?u ).D!Gb~2n]/c䚕@/V&z"CV11\_!Qث6#&fXrKpLv$ַ;È 6(7L?te$-mͰ51;Wm5q^}Qzd|r.{D~[7_m3:_pKw{m쭽0-R~6yqI'@Yamm+躬u``*C= ]emODj9>n(ﷷʁ(C|j,1ϟwUA8 m4"d{,~z8?'D<&^~Ɔ:7_ZBDR L6D} RbLEj Vw2#d!r MyM(pq@t#~Bd7(3Z/Ѣ6H@D |&7~):!W y3EI>8&2;!Q1ZKJ~nK=#bT}V;^sbǺTP"&p^װJ#$*O0r,;rM2;#~T+V kzˮns$oLgh4q/.|e^u >{32Rn)rJCޓNU x>JԵFb#!e4.09y%bx.;朓*2 c*;|z[lCGB\j9|`P Gy7!z_TiE<?Pyg-aؽBtjcPn!&BT<* r\D*S`o8͐Qd \cV!>!$>D:c,c: `bO ˻[ex:\5%ZYtbi-։Q@GTqE@;zX 'O^~/*ӏnk'60W&ouUOܰm5XZ]_0;e=fDI럹]aY"f+X_-A%Aٕ,\d@yrt;[n<)4W)Mx)rr+’as[̏ ߻ S%mZܷ^)[Ɛ[2_*,:U[)Tʼqi:K#Y[F3G9[#nSwT#^|6Kg 5gÕ|#b5 TF:C$GӔ7 "SM~L%%I6+K@;q!/_+\s#W$>yUMK~C?ml]@nO.c7W}( /o2*턈`,f4Ǡt.ͬ~3!A|=A) YiAV_)B359fPa{mA5]fD LYBKG5r& 5s ֹ0dVOm8pXЙfm[T";o)T~dܱW_4E1+I$Ȗ`&2/fUr!^Ua;#~IfҳP]mL]+ޖt~j4FXƘ04E56ӄ4t'fw~Th_ɦ"f!_hKL:ů;E& 1 w䪺K&{4R—n~?B@AT;;.Q6-w tvY{Ig}^/iu7P0ژ|ճn)߭ʆ.!"F 8֯ۏ? :'a\eIu5$^o{6݂ SD0=\*ECuMqס7crH.QpUwҒ/ْ/~˂a8 GHnl &"/3%);V`lۇmЌKvq)z0@T#bD>k{HC@Q)~/ZzN`Dߊtf;.2- '5uFQ[C:)+6`(瀻xެK 2rdY8=!/탺Mf^Kv^)R(bȲ1KgG]i҇@6l“RrR:0HiĢVWL wɲ \@-"i4 zq^<>n6_Ɩ>sꊚ}x|0&0\ Ә? ϔn!˹=$Izei#b{F& oo8 O^ۿ0PNqҟw;QZeYQy"T»LK%[J^P>*\H6XߚvYz{$|ʾeG]<5舦ͯ_ޞѼ*x*ͤW)T A Ft1:~> QGJ+*Pܽb Xna 3ޘRU=o sKӒr@ы0ǣX;]!6\H_O#42 U#,3sdCZdԕ`}ӊLOM݊bL(CsnNJ'B ꤻp'ސa J { g8ul[p~A&hf/u˻R> <7_%'qֹۡ#C9 f\_Rc?eB)/LDYF'%?Џ=%uX4溛tts[TkMdk.#P+ĊefQN#>y WŝK(B"9l1Z%{"8;4E15bj>D@lS=o:YZxA -1)^^!-^nSs !Fb&1IT8]Bc\I%$csͪ6<7Y 2}4^v3ͭuuazfL^xy(P:%fr# FN fAwL vތʲK8] sܿ {Huk8-o HnMW8 ;~T>f\%F0" _/ԑg= HD;#að^N^:N!^+΁gjIc3lw Iw䗫Ml.ZMO"lgxNzӒv֥tJ_!! ",m5A8L.$j|EkNrcMN49B# z/[6XH]x+3*cş;܃iT^EbqJf)|Pp^DhmSjV';a(IԦ[,z`-1=xФsu˪ PXHd.՛C~P1rBwWd M&͇yadDὰ:2PYN0q*1̊Z,^Xw*D՗RkF@1I}yGg-SKvp]NVɤy 4A9]ͰNF-oOJ #u6[ DŽDCVv[D2!{@enp?Żº-JOZPϬ/MMT)FXy?4DqPXx\\z T,Q&pldO z_K~*+°/MLk6m+zkjً+t,0<.gBuG`]K"I(H?G?߭u@q1^5] j{vYNH `x(yV@ۣ|ꉖ# B}>;v"ԅVn섦zLMhT-4~7%d\wEQ}|Rl!\٬-V_pj^ȻeDPII-@w/Κ0%]ލO(꠬tq%jВ nͨJC;T]{MpHHXw’|kv9zqׯP닺`2-fN'I/=Q8`U9S#gl>_ 9AFF E*[9LƮ+ܓ T +Žzȸ 2dGAC)-Pљ.ԦA,D0*Չs:kD+&)50M'P04oNӇ@F%T X~0TmǺM=]5< Dd;86""6o+ sx\I܁5#6áqPRյg̩/)6e,Yaw? *|jayл1< 3FXH>`[Y̾~2^捸EWjeuhxĀ}CHIXi@Մ)[~ZwOP$axh(_ >e{?KLJ]y,KW*n4 DmN|qVn Dvy dn!Zޒ&I<4E?U3mqI /wd3L^u18T>4YM.K?љ{y=ͪG ;4'yg\NuuOoog?bwQԇ@2j`=W1!5ż Z?bx+Pvw u&9mfsޢx~?}gǾWS }`29)0Q~J6toY/BvO#0ޅ@Qޞ#5 W'#M[8V8zl~ӷ|ڦq%/l}%&KJ*hUr|eSFɉ"E{v?Չ/ev(}Kh5- JH١Q1Iawoge Rw:"DP!%GTp>Fx*laT/t_fֶx[G򐌜P{ӗm~dT|JVe{d7+bO3J @5 \d:jhپn$̾pE NX Kh2'<Pw]ON3(DJOL&T k>>}_I8/ gp!G>Z.` W]"w~NsC";uSCD7VF?1EC!xy٠׺g)sx"SIn3ș㽸3 8,l1 13L Go`VqN$fP^DZ)4z_ _?u;mQzU!= ~=a W74I%2U2ʦ)aLDYZ踴eIZ Q0q B]y ۔4-`l`)!`F|0h:3I߼d6CedZG`D2ðB%\QY hRgU_uX*\L&Kɿ)U1́jmρ̡=eO`^Z=yɺ𕘆`O-z@M0xÛ?4E,o(LKOb\~+ѭ쁾`~>&'u)^=m 2,њ0Eѕq3aVTp\a%Ů%ra'Fs|u Fut+OB҉s ';t\Z8?#@Ento>,p@}8q"1E1:m3f,IjkVV-y8Ifs/XU'$s_ ǹM#+U$? ѷv}1vnR7'dbe䳶?{Al|Vհ|׉ޝ%RO6ô$3,y\BPO*,jO~8^nC5wJdj MjK'Uwփv+yZ=X3ƺEQCv}'e)oB=KRWs1+YH,oj Ap[؊'2J/f  7mĚ8yqWT%Qm.ct&8RYq ch$taO6LY,I/}x2bS_ey 6A5f\#I.UTq+xzƗTŸ*J 4̟5$ɆR@S!t9bT2i؆tEXrS j63TD׃eiwFg0}c U͈ 5"3Q\{$_C^Cw܌a0M҉];{q!cQj;:ƅ?ۥeIazr)oB>jmo1%sNJ'qa u!r@R{X}5Y^L>;!%b=K6lQ_B,Jg ٱ`teQWL~ՊgF%WƊ9ȉABVgp AqW'I?7Gv{:کE</QR g~{&W'&ۂBQ"ul)_[Qg"q%TkW`$4QfBu]wM3A&Me&t.tU΋a[? -Ԓ |l bq 礡fW6I Kb1{иj9 #2;'`?#J&X}g{j h?kf;g9pfLJ9 17¤_SVbUDMRBfzch)q}a^h[`) 83Hfl:_FXD(jq:{.ҨV^L`^xeǩa `!-ӻRG6V ~@[+Ʋ2 䔲ϻS$r^!3E£ SSW?\\B6L[&c;ur yxWUS^@d` :>t)QmMJÊ,<ةuO.IZOf]gcBޠEp;N6~*]}ΖާLgL_=t `]S #N1#Afu\.ğk<7juY믺U10{thFM u٣xR@rR;]-wٺd䌺0OųE<*L< C.lP+7;P_ zL?b2p8I4R(7#k$6%}b=,WOT9JQ`$%.FOucIraUN S#U>ϚqkՊ:Dz4 Dzq-*Vͪ'N$ApJȑR#AplBsNi?CuWHt57^(Tرu?蒓 Dzk';6b>C/*2m1_tۋv-0c?PU:jb,UvMF $۴b= 8ΡY! n) ˯ ǽ`?韷wmFcFz#@2k+*ؕTfaNM=ؕ{=9Z2z80$r_i>2Q"a]=APUU-rjDIuqE?*ۨN$sHs:Vց/GH$خn] ִow E@<6-F%$L|X$se:hn1_Ŧ^ws6 ۻ̻opիlѤQU,hk_%{Mv y:p2-?;]? 4i*&*4jt JMp%#ZAr 8 @+Gȷ( 7 u8\P/ޡv,/}DՋC2f߅Πmtoz徽I%09Ә悋Lv=K*1^C]kgvvB6%¬8ں+ mH4Wsa(1|G`~A2gA/Z?Hlss_6hKT-JU' ERFqzF^}$ApwQYJSc,tO:dHb"}[+k}<2[IKcUv}+2#jZ|8d0Ih0X+NԪ@N0PxɆ2LԕI5ˏ.Y is4"@Ѝ5D\8[FADѤ1OSuLqd0Djk➲@"4`1S9*Մu|tOW^Bom*J"QC rJكCa%) NVq| +<B/Vqy#!UlJ Ku u߆) wP7ֳvρ1/}͵]B 'm {Px=le?GhbAEMO3f] l̆$K➊HT$/8d$9g/3+?»u#Y4d^ٚhFWƨOSYwS&U_3P%0bW)jwsP)@IÐhdϸ\]hǟlQլZpJznWuՙceԋ|6=S ΙV֣]Y󕅩22Fh$K(4FEzE'\}uFi5Pg-yqx^{H<;AL vn/1&yJE2kwG{ѽ+aF5;zδT`q NgLy_S/^ p`}6 ^g>D B*' p<IjĠ/r#fcRenJ+jHspw-͠TK-9en̘d8Naw}v'C~:;3@QObW -TTuC@f_\ת㫻V]uA}16yn/lk=" ixx/go ռ)>#xhk>xsv~',Yl0( t(qe<)!鿓DhN)WAp9)rrH pkYrZ3R6lUU+,`pz6W¦ bqR*YKX3x(b}>TRt|2I IxنEo1e9ԥw1:"΢o]qwDCŒK-KFFnaHFJ"!o&̶{}j0Ĭb7w#Ы5K.OCRMcFrOXHuZHah)HȨ` % FJm&7tH4~r^:tڄIPѦ"(Ϣ]ū` 8UIN&ͧ(SN tJǹ K26qIݪME0v۝n$Kwe&!ڪZn:o!6PhN8F96|4 .Yg9U(OHx{_W>.}qFywiLy'M 0Rв-D &iW9H8HH¼-R!dQ/oʑ:ԎWy~TQZ8Wʈ7׋̴ֳ暫)@}W6=dAFJ 9pq>2ޖ)~u$.-rSR1 :3 ǡ/A-FAEnQ ) 7,rN@:JzJ\ qO$ =&dqg(^OAߌxp3RA $Խ~lVA3s"='PX:V2lE1(D 0tmuGGua0X@م,ѱ,֦ќ?F@  Eɳ-rxjUUxn?ӥ@[إ$_o)j{z+}ٗ ~>gQU6`).m#mGp Ak/&F+Q8]ebWcwQ7#Fg}ػ4uYƞUx8çEy6.-kڭaĸ_D|Y=H>\רj!8IrƆ2z+lyScKE c 6Sɤ#U[  N-JKC#`W aʸ#qDXV8+ ŎEud]Jҗ90AkKЕ2gК1[)tCYpx=lvWnY>ه;LȤF2,y߬[ ̺v8*xPZ&6b֊P5,|x}.SW~I !.^lIL#Z.'~GWmD̫0/LP\jheh28&UQߎ5ᜉcaQtﻰ'` JjsªukOG4 0'- ـV̄2I%.wbPȪw)hcY~e5T|A7V~nLaNr05pNOMSS]OW/ ^1,M)`[ k) EAci ~a Hm>CDR·m$krBl_H@Z*YQ!m$~Cr4X?ϊ֍PoQ"̈%a *ѽK\-dwevhlA~J~gh}n5k|0@uFL)QSgfD[xψoFV.⪋pRK0(X(W}juvaђlNYҞS3J=SG~OK㹼\`G5g>1)yD$MVpG }4-K{#hq HN?J?IiFdMVt08zfl-XZ`>ŴmR|t ?yGCs1)+@ϣ:i6cu4jsa[bc%%%hź m)9nb;MX舲#)XNl׮XL66q2O'.(NS.^1ٶIc#C}N f'2LEZѻſH2x:66J2|M~~(#lUˊ}M`/3qOx/Ohn$ 1埭w]^֧ d*mPB'1c'v4~WSXޗѲtG+8$Lj_$."nsq}6BP!yBdm[v qS4ؠLBD)P|(FHM<i U$`s+@Z@j|ЌeᝦXь7dU3-pOXez)|v|h=Y]ޜN$$ZbLE$lٟ{.%J"M2$O\,u `JnyՏђYZuJvˆ1>duK(O֩7.^%G|  Sz`2\߰+C|JJ;,ers$$* Jw)Lv --u\R@28֣t#>??8U{VЫDFv9fyC:gP ܖ^e%Ƽ)S6"!V)*²A{. s) c47*/?2 =E_RYE>YBm%UT)avFt *yߖ[fVK+Vb="Iuh/ $P+:^δ^*Q$[dKuJK$O/[G̴(uR': DqPJ6~q~ƽsGe{ؙ-}(L?@ǓYRwȿBM3E|JA1=l$IiBbm|#Hcfo<20] V?FI^!w|@gjm= TLrjcεK=5FߖU~5А6*h<בoa+JDo_kq~n׳یCu2[5n=0?Ь8bRwI a?4NƊc`X gF\.ou|>G]O( tu>YdJb?d{M}+wul7ˤhKo7o9 JGY$E fu|[Kp\ۃGէvw|S+tU1f)>Pd]y`5[-U e XS0tMU쟭eYDU1;̻srhg.qN:Q4 X$Q"SWS N SdV}l/_5?sQ|,Zr+ yQoPZ$7iJ mK)^BY6fC{v#2h"Y2?1)ॆȱExpf a9]!,a(l$\M%B;iϘ%A<+_t" tݶ Vz¬VS18)n%vq0Y$:ּV٘\(GPqЖ'rhu$h&WC_ A6ݝh8UwWq.L J coRwV+gi9A/Gc Z#`n#Z4$Ǹ\U53ꥩl 9՝WNJqZ 6<*^[s+{}Ō³V(|F`;6JQ 0mMk\esjopY.e2D[`gSψ4b㰑RCԒb_6IkX{\JI3c(33t ul/T5&d-z#mX:@^EG"o[[C;"1Fok)2Fr-7섛'0AԀI:Vϲ?2 QT*}|KWfh Tsv59$DdޡNI!bA0gQ]zZrqeU>AsŞ,^FH7ƞ+8%LS:vAzd(G"W qߞ'hÔqduW[ Og.'b|WxV}ư-[]-T(m(wґ-^UGbOXK(Gq{[8gSvtǛ n6mK&mխK#69^;["5$)yG~D ń$Y}O֭N/سhm7,ke$+v L^+qybR"6f H)äKKDt`.*v@:o/d6>+3P#:ۓ0J', oxTLiTV50%4Q~LaS$ъI?WQ&L)Ug%k L/ahͻ*Zašg(`?yYߢ.C`:q(Kq15MJ7^/%=( .ljr}baly@ɩEY9D"8cI>|ĽNW'Y7yX # A~(_p$1p>d5La pw.婠}X L3~I\Ņ0r\7eOfխ}ﷹƿi (kc4ub\L脁8ΑSV"=AF[SeԔpi3@uFசbNP@XHI\zns DƔӾxO Z.ڝF[o)9em /G T-o<@UfTޓZmlJ0gZկ)u&YL|%K ;1[QGeVF J3u4~ľ6z CQ4N=E]jh{Pr܀ֶcP|Z;+w4YAV5%Ǻ1z{FHNM+]PcÙG6;UZLکKU(1tCEsn eDLDR&BxpJ @h^b^(r[mܮ a 藮{X(rǢ<6q{2W?\lUV ݗO?>kV ?BE!y I5&D\NP!c=K<6Sm `<BC?זoZ'QKwǴZ5 P`$lNx$YC-,M$qN*W ptJL ` :sNd0.,h^ڼD [lP"P0;9ʋ=] %.ľm\-k? \y BWՖ!7=H#W, (::)YY頔k "*p{˲ J뵤,3zR~&"/Ɩ03ѭ8BlݜU\T_X6yUSцa,:[,m5yѾ܂.pr&k4"Z,J H%pHjxBg݄Sp9i1̦0=Q/uU8iPF0,,&*0{=4~H DwTZ`G9"A[-<Ɠ;^!<ޠeUOthqTi8\u2NK 䀶e+֩]LE;& NALtqU0Xb zYBU;@M,Д\Ls8rpu>.bگа;< ^*q;M`_rV֝1qlݞ!+El:gc9ou[Jf9g"U `sC.JlHF?’u_-] %V^\*EPnJIOs`/LZͭt-kwU( ^a/ѕ+itPD#`}g^.Ӿ eDBX%S~!cU-/%}Et9փAyd0>= 'RA kTn?e)Hf'0K?;Դj!غďnA5iS]߲fiY0b_!K"ZJނ>YЬ#|:8lj ms\m?(4h=5fV ::n ʫbT}PpT5; (+`\" |LukIaq1[Xqco8n`~tovE/kYtEp-W"O E9@LrIԶhvkjߟ̭VeGWk% W-Z<ΫUgР %zbd)i}d3ljZ(m<*0V $|8tZr-w1#:5 LҼG引aT@93Â5zwlEE;ϭ|Wnཱུ_hT+B 9-iE3( j9{׃`U(2nc bћOuLSM0: N%WW2UB,CsVwG <L?͇~ėX M^3@vY2pNx{pu9 6GqAck[>z[EA~Z`aM×[Cr##Mk[4t(O9퍕T >|dPYߓ̨$W?-b7s;;K߫Ёϩb+gp]q[?sg\YCyРCVPkcb**_th.ټO>7:{.^MʜK㪃dXGte[ϼ`8h*IF*{ؠ^h|:u3tp6bUd eGb5ך+=NdF]ۤ\6i^.Ʉ嚾P5bOa5dPtKTg0-(l/#xfeFݟg!jy]@.!X.8|~BUk< pbXEǷEPWkz$26?@8+8f~QZp&3ҽXy&:T)X_K~wzJ=|x}f)Gm 5kqwpU ުt|A,*h%Ť>>wEhUez!FFқiU L<"@o,|X4P2/, K` fUs ]۔*Q0:n`lOjϑ%"fWIӮj}e[uYc޽HKjlf*E vgs hj/C(On"O+ysI'[MbrIQ[8K tY:"GqbÐF.d%Qp2Ͱ;<">a42rLyS-p%u![q`--6>1 Nzroes]n\ք?]Y#m`6 }'rAK(\5-{H#K +aF O9h{'-CQT ~6%J|EC#2OFWU u#DXrr &K kyÝKůz_DN- fWG7' J j$_/?DPwD-!M;'^Tl$S D$U'_P’b\7"qw @Oo08S}+\z$mpƍ2'̸xIO- "W l`Ok~+z/YmG=>n$/QxjnQL~~dh>kpꨙhrJ:Ci~/%7\8KFB!';͹ 9b14@ᬄ؅2TꁭoGĉpq˜(/#wv2T/`{J.Q2g:ڱqW '+6 4Y4g4 HH;F'Y芰AF\0dL>XRYP)d#LV|p lJopWRhBX2Z[5E1PSi:9fǁ録hBwз4ZW%q&c@\9A}RM0Eaw|\V̝U< ]3InɗrIwh @`(} jB1@Kl"XTugpZ`473F4BI0BüՅ&m*ak~pJ2}dt ӄwblakؔϒ{v@|D#H6³_rm=yO$O[l|p<p>r7KDy`A,c ;.8:}_7w:oݚ *Tx_X_?elRf8|(wƚxnCR81sRjq*Q]&i Lo(]+ 7HkxN0`X^w֔0Qչƛ-RPy) 6ndpgTaSۣ {MPr6w^8XpK'ee@ד przÈ[ 5"'_3\~M/V+6$QEDł6VOl@/Zsޟ> H> |ٵy\Im(qV| Xoʩ1(%LѩXs['LϷ F4[6:@)|Ԫ"&]|K"B ʝʠ/U=pJ<(ꈐkMrz-y Hᒳ}a7/3n 92=Z6F7s՗%% fw0b@R&"g>$E Hv:5/ǏQv@7!ۘ#j|"|Ļa?45$tLgЊ|Hf']Rd'Iz1x* +9+/v)U;ˎ.ѢIպ(3+邺B9m,YX> 2>LMYqOEy0OXMtq6z4[Մ-F4+≇*a1)~hur0Ub\@J雋 ~`yM/y[br؜_'+Ok/"0L2yVav&>A YB)ޔ, #s`W7 ^|l8o1|֬xHxS5 CrVLٷst5ۀsJio苇ehnruD = G悒4hy =fw 8^&fuf.}" v?@q#66 *ACk@Pk]hA5Ud ŪϠX1{D8[Rx>6S<]D%qB L{L-EI_FMbc yd` ] |iZXʶ01b@fByyq*PQ}HRwm.QDpFTc>̡‚rL)&Ath݃}g?D-_/TR="9HDde1[@BX BEiw=E> 3?Ll99p ˒l?4"OC2Yh@$/]u@.% K)G|JNօHZ"UC'B4Z@PEe'`~MVSKEf䕝'VQB*U<.L꘶`w{'ALi3b߸W֒KFݯČsk r-5Knws671ge"g%NU/kSEh$!q`s0Q'끒dpl;T3O')GX/@yd,Q:l #r+Q^y4O-m?f(JvY (o,CQ[2 "iԀf##h!@:fMc&ylGWB0B傽2evA,3IFdY~,-tK@%MPqx`ٲE Rpg&h0t]o@/E'~ :x W)z~T"T(ϰ `};r%ڥUSZ=wzP_P_7f\*#;jOihC'd`Dk%.z:t >-'GBqNty_-0Jh㹩}k5~\5ć8MZV@zV bnz7DkʕN`H}ҡAŰYqâS׿$,6N՘.m]_ ޒx2}JboCFc cњ2$[`lWerYP9Ǜ_\YQO`O!|Am8" imy4Z4F>.iy"JqHQ7M2g=ԇHvQobYkp6 ~T dSͭkDwk0SGM^m_NhpQeffY^4c+"ʾmlg>㖜hbAo b, Īw ZęBOvŋ`G 7GUItr Mf-UT(QS oCbr葛y/Yk q'\3*Fϙᾼz M "Phd2 NVyWYqNѿĕ! PveĆhuþMKgQK0HWBPpJ[6elY:$_Blş>TY'c͚ʅ c5N/1² 8Ϋ{weM9NhAۻM$?Uʓ 1E?( A5 2W.9. UU! uJ>[ 6r/_jqy2g4!o ]aW?jZ+;7 yNJ(ʝsܘ X9V r0QGU920׀lǃn% n޴ӟaq;_'u Ap){}MT(}<)?CRo'(+񫶪+`Zsk5IfѱAE?Ε UFB"C"!@˫pa⾤3ȀiL.S@]KDRHUinkZcp_&{t d=̗b~e#zAX3G̀ d Vvvtʢx?v7/ΞmPVneF},~4sڗ<]K^nO+/HM&X'/aRkQ$#c\/xmac[HFdddݬ&0eڴ]Y™j` u8s[쳚q@`WIJvm.$JxL UHQpϯ0d!ITEq&iar Y$ Ob!;]m"q>U癘2C 'iEL]{ç:Lx J)zK[A *> ۼ %-`RWD[VMYp:zಖܤThʀuUwkKQjo&!NJ嘀Wlj MzRva-dOކleH4 _>kL>{;>PBqw_уC{uЅOBx2yRI[LQ;+^ *jEGKS#BׇT %Hq4?{NǷ0_q:YfdelEvW yz]%{(d-^*tkL֊'M,g_y?g 4$T81a3ue<,^:ؾ۩Rh57$$=t&4Ej>.Nv&J"AE,%%_;X-qYݙ‹KN4w9㒃(huc@Ay3!!l^i(@OD%Tzk \Q a˝ּ }ZYx{{πdϻUYn\d&?3:yQuBR\ 4Z7[r? 4W_2,} }u{|<M^pKWʇ\p:&(KE \jؗO]ŞS`9Aq\ tNL0 #.y#G7N 2$o2jj>`5JZ&+wJT4IBbDIZm$ 4O'P!k2N({4А%E[g،A%}Vg^dwwHg1-!j:jh,z̖7R (Of0,VgO9*(,ӚE er>jS-rC6%yO\vU*Bvް{8v\qkFUxGK(AHi7n "B˦r 1ȨL_+"!څg2I8ݧy[1L$vݺݭd2'w#[?TlBq{  U b>`=S<`pֿ]T7U| $^N!xpTrWc Ɉawg] JXXɹh uS]n _wiL36lI U7##;j8``(;!)2Ge8xI=o\j7&Ix3$"typ D ַ[9 ҉Z-G#6ùe)LIpYeJ-u03GoK܀h-~gu&K0J2b{Ҳyd T+`^Y$чn?fM lޝoMfg]a_mU~@O鲜|"^ɆFԲcjtCG YgGlsb{L=HHU9-b.{ m1Oq9|~G﷉7>$M:M~sׁSh$I`!FjkOJ ʙr-- G-VxD\GO+h\\%P'9jٞd r+"\QrHv;GѪJL{1GG eK*F h㒴?R؆vB`:DF7y[A@wVA.z,^O6NxgQ x&W_%ތ05'>h_}W32Tem& n=j5BIL\yBv%`.Os)X)vm=-}F5yF$%J;;cT黊5RG ]fXFd,g`bN9fP$z $`h]\o'\J9RD8Q%$ LE /P@6!N M } մ/wV $PA9p?$b14MJ(vi"z2DZ{l˜-K 3d5,e M&l5ot݋1uA87GD.HG ӛoNh1pNz3uSh6qaXSV&=u`]!":L`ۯmqGB81{ާ`=_xǸ n<^-D P1@1C K;S4&] U5~o멚01!w kH@w[Br0'57w& /t/X?ڈE%=ؘ@ҴC|\.@-Fg3$eX5'*Q%t uBz| C>3Ã~݌kKQ^+V126)--^)teƘX5ul\WlFsm+{A}d(#cCCWxnA~wfv~ˆ0=~K=P%k@x6bqor0e}CxC'εG2-s ߻CMb7oQ=x+ ܊%j2M]d<#ɴ̰vҩr: KϪ)7jC,ѫ[HϤ,.60s"j=pg_Jb/E u`oC}3 |DHp4 fJ!ߧN$ Th@H(*rгK@;ΒѶ^VkG/"YVPagF+ؘu RZLQ tGmhvGbAE\P(GPG!Z :aٛW.>[GT,R[mJ{Wmg}>FN;K`TD+j}&|]ڶ\c.j>̡a\WT;vT$3ϨfXx,9{GwǶė(ڍ\9=ۋL EL6S4DzfP>ֲ,y&6›+z{'Rx@pPA %p:ΜP+;`.O#Udڏ{$=v7%,QV+=Z V@e3O*XQ?VFopҶ1G 8N~+^K+<\_ .ۜ-꣈ifPpV~$}[jd)-0Ǎ CC:>& @SEryMujx):;ne0@GV;OD®z86l6a/{4۫k&e^,ؾYU mY$V`qsJ-pQ\vix7p+90v K.Stdn'OͮI1D]G2hVsАcoV`3T;La~vR<$Jpv{1Pr_E &GE,nVF!uY+Z=x-!#;p<ҝ. U5p목ܫqNd˃^*1C~'WeTi?*>`g`̞)jxWqt&/I$ Kf@k;ѿݧ 9U*%I^z[ozeݺZ\Ծ/YR爼?1iwl9P"Y8.׬d 7̟ܥArlS89KL:S?AFn 8*YV#{Fީiձ2ܽy!6aK[m8rnJ93Uѥ$fr4!_4tt~Ж]0B&,)Lr_%`ΡGCQUU֑4CU2,uu2?{b֣a8o*!>w=T-N(Gc=~Qsޱٜ{Xz78ꓵan2ST$I(n>xtV%M3P}=v{ PV+=a\JTّ'e9yN/Q'ԎW}= =p62饘rVRح>ئrĴHI{d~IEߎZVlDH[BT!= H";]G;<4WkӬuYSIHgg͂3B|="|D, ,&=}+8@eh鏲pn4g$ih}=y[|Vl-CMHTݨ!c:`Q  3sm)"4ZXDנv_)y/Gu>o$섺?X5%V.ffRis_f1g})8#@]#P/'sƝq\w!!Z<"`kWXO mL&}\u,IqUL;QV~1 (nr-̀{)t)-)k7HQL`ahC~;H8GCojūNj)?6 `8[!_$Pbb}JZ!K~_ >? S} uw>7d73iI"<'P LO=7E99dI4WjU$,g_#<YmVD qZ1 B +}2^&k8>e%r`2"Emh<;OpUQٖhH~\\X`lkt,3|#OC޶g68=n<.-U/9]%&QzETYa)jkEc~k=1.4]xsFSUև\.^8TI GRuHMpo5-_ehQG MQh!t?0?AJyƤ`{EbA0p-& /3F_O1% X^wÙl`կ?,͘ 'Uf4>V"A-M4SZXަ 6Afr 'P#g9Seƪ>Ǖi2U|[;߲ɯ dAwYKs\jfUٶ!-mȫa5Q/E7}2Cz֜l8qr̮Qs)h~y0Ty7Uzfm=(aǁnz`#.{(%3~!خ&c&NFSLfl{-\)}nJ 80'> ; 2ө7gTFuinL/hw%.HZʪq7agWE ڲ+QuWS͓4 `  IqU)r2*;:XUI{o4R 3KW-cfv+3/S co냯"s:O_m+<+ xȎec@E8Le9BxkB)IP,;;BE9<1ȳLQ;ga4}AVJv ;`\kjcFxkPaOBM$\ 3gw@6vM&.Ґޕ {kP P{jlҤ"?_SY3X׎ &h#tkq](EjZN-b?ѤH2ı$4RsWfq|ϊj:('0CqcxPmGe\ F UK1W;Z O-ݤ;j,E(:(7Ht!}wS-QKvYV6L::Zj6m]1\ thxZЅA9ũ[Iz&״{ϭ{гJYDS5i~5OYT[DnSLj&{;6'ɀ%%ޢINgb1L@e=GaU@155ۮJ{ H|jOLoO;a7"*v$\= B 1%@2ì[LM MfFk>? V.'S#$̘@0dW iBwk9띈3;3;b/bz,Xps! n!ZA2#vJVZK`=Yɂ1OcC٬؃X/tq⾕ҭnRf5}}Pc cK*}ލQ2~m#qi̦AĨr,ʹ1yF@A5>d{^ͲBORe=ת#YDt:>'R!x-`@MKsw-ˈ23Ty6pM7Cvz*oJj(wD{b˘0K찂|XnPbueչ7 #C,,3]T^;BwI5y%ݩHE4 B~\%^=ѩ49I/-̩k[؝ۖpS[C(L/i3и.=.η ONX h W`bopH醿`K¼fO E>wT+˺ۈT*t,S8ۛlYߩ5ނQ2Aus@Ovc&2ٌXQ9tl/DʜLM̱W%l9=pvܯ]bN8I}5Ƀu9gibJ.,ϻDBHU(f<ӴfUC|g]Yv=j k'X>D&&*)Ⱦc} @)RR"z3<ڹ`7/|Ef0>${sؾMdR]<(Uή)\Vihb`RNM+F@2h*?>.@.M}G/9Kiw;yN>}^}eq@>  W+?&E{ŽCg5_}DRHb] rF/+L% t}lKQO!;K Rq-H1mG#J!6ێ Mq`Xx:Z)-҅`j=nr sk@ dJ-;LA`(K[K1p_JbJEpwE65m* fm\݉Z}\s^{}g+b9!FKoT~qz*!aoyW*'h!{T%cGSeL_,_bnI }A!ԆqK/W&P>7xK+Y]^vuvII `?9퍏};n:\Jjl 6Fx(ma n  G @P!tܗ8= <]vv}G}I]?~妪fJL¬_wCe>H5]pinʐT6_;446b@= / PL!HA[>wY: 2s&X!}1b;cIN00T(?p莵].O}='*p`)Ey Yk)I>)) .mP"ր/cKmU}dddz_=&>bE5iZAؠ ;kXGWqq7aC&xZkMQ)|z/S7 WlWEӰ_1AKeAsٸ}:IqNlɀW$MRJbuZ)Nۜ(A8];Y/HS3g/<)RܪNesse{c |c~&ϯwCbn1S*Rc4Szt=v:]f~\cW ' W|,÷1!PK-8I䱕`vpGbQtH/':.HyxD44׿hT8R1BEreIdxJcϣ y`HR/@y+Kǧd/ؚ]O `2b@8+%; 1__.+ ,X!L3 nQ/2rg_kEkItե ZIGp-wB(9D4dOl1l:d U ғ>ؚ/Ry Q{g4-%αdrîS&{Lқbk_B-cʦLބWLe3~n+y}1D^S?33\T'}z =9\z}ztaAGU"Ih9dxk|TJK[u~[4XQlj͘`>#YY BlNkL [/^ro D{iR5Fr\sIdShH?\,Q/m'ŎіA.p].ބ͕ Ôg3E 1QvПHJ9a5nNK7@TfF}ƋR|"^qGGZy /Ìt!= &k|N%`6iI *s]@ _DJնAp8;c~J)ds @|':=D2EW C@ c<4nrqx Ce=c`H OTY:Ox⠷ ԥ= ks bM-vLZi amqaMs\143Z Ú-"f,EUa㍷7tDUd*p ;pǵJTzŐxН 6뒃]|U1àԼ #93nt 9B)DauZE a0)[7-xVF`8LCC0{H\E [~& :kS3gΌp~oI"*hZD.&9x?l !k|s֮|d~rnۑu+xJ8V a?j*LB|pN|%jԶq_ zo$k.0fG}GdRAC+ܺ§#o;Jȸgu}%oMw.|cdr@,:7EN%H8)p!EGb`&bMGE~"k9Q(n/n`xA'mM{4Xi ,;f^K~qS 5z`Mi"J/OH1Q0ZbBR I"}#F4BT08?!sQK.UA>ߕa|: L&n6y&\tdtA322E}Jq@mAUwתhw`9c9>ڦxҿ 80m4#7:9jzd8 P׾pwLlnrqZ,L~C4iO:ZLe9Ze,*V`7(Vc>g z_HMlzvODKP]o o4_};dr\XyTv zU,KYJg\|UY.$A`!5O2wU8Ac[Q5ECb UzvZQͪ]=sUftپzGZ,n3PFj/X͛*oҿ>zLr6ipjBoϳJRJGzٯOT b_V3eG.7+h^i?Oq]XMvam2!_āirD6?Ky6B5$ϚxT?K1U 6':N0(#) V+8CԌ ',e;ebd ߺ8z9._E|qjUl I< yU V?k.EVa$3fH.{!a4 #dzY~_oOgk.yNJ;ِiC"'`:bVJ ~'~""އ:x4Yd rG<2F\Jb})ׯcyY@d+₌W{+WxN"^L5-'Iu5ꧺѠķVehlbn+ qou跌cE*mˢYn{ǁ'6'^L,Qm޷`N{CNj6z<^(4xK1}a|:qΨdc8;k )T !eFUA KY$6/[ l6MklTWH|fP!  (7GGΟ9Pw6ͰoU]'w?kЉUGTg8d_F$$Ɓ1Suqm DF|d?Vwq-N{O KU:?HLf+yM U#81v5!4ӂ. iuk7΁y_^.T+(oXհ;M1AUk0{)517 fax)!ʄoF' 0e X2Hf;:ܯ>]IԾ'IznEB]LF8E9d?Od/pg§aDR!RT-Ö kjq*yh8Jzn22sХ^Jm]a\Cmݔe?jdado^WV<fQw#,rX_K-qce9H<̮J7aDU VIt(.CMV' 7e4wA$˽ttJ8NR1Yq Эs rn"Ra؁SImk6vԊilpk4Z߀|B! hfҕ;Rޙ֓M}}:yOV݂&QH>mj4EEWAHap`!, 9#Yo.s -5w B=Ĥ03 r 9;OrR#}S"9hCeDJ$ D] Tar(JSsD~kw<5,̷)X %S+;e !_1| 1}A` H@ 08uh3ܗ>'ȥE$l_>7иnor](&F۾&.Dn[i5)Ol'lu t!_믍j g'N6QzW"mY9y>(KBQ؟2hA1?ehl=VePO-t`~$9,klq`ҿzh.lO49ޟt7&n@1~IqʯBpS{g)iHz,GA QתG֛agXJZ `>J'6 ؐio^s.cDwpEKxЙ t^Ay WU ,Kط׷mG$mQrCpr \ ڹd` HWLT .Uȗja]=:?U%:rE]uhXft٥<Pb/(16gQ"P>/4ޒƖZ#, ewM 㹼#q68ȋ.OJ-&E[XMA"5֋ᵄ_z T8~QDɠj9iYG E 53Ap()LFO,!7. "Z-W4_9nNȃc+T掕Iuq;Tc hw_4ƶ3`.3%xBm7.[3 _.샤ohiڎ/P+B|ӗVݯw $̃T03%n3|Ia GlNai5!u] @RsmUoYެBQZF26:hqXxN"e@p=q)q6:Y;7ןd qT)~@'8VD_oKl|r lcU&;čEWl j傳,/E̛Mz"#`GFɯnZZ`O }-*;PbF`X[H2Kln-&Ot4( 6l2 3@屮E%nùW'032!M:Ji,{Y)BHjWfm_2u }݉ZujXGGZ2ފw ZlU~4ϣƦLGMrDGK< e֗UE3y8^wX-j;|yJŪ4m*гbFWVpX(M>}ve1E7(جcƄJ)Og\ 3!eU)W"~ cĔG0ɺ/U0"|>I1G$*lH1 M`ʸ0,nvsxY`VF3!9u3\OVM*wCCUEp`dhX9ѯBכ 5ՋFuP&dҦha]/LJ4Ӭ+ÂL_kqYc^{#im]"܏)ZR )NzZ<5OWck3-$_6]fpg5}L@k _^%]NW‹Czhbf"+xHjMz_B11z"làCoghb?\`lba$=b ˬ mzQ0H8 &MǛ^_uʋXiL2|֬Xa'L/BvJmlQTbo %-Rhs6*΄#e3L:TɥلgBwm^夈վy$>n.lOy裲6'؛hDPr9   阺.(ulkͮm#Wb?61rF3sA19Lωmgü~ o% ^ Rߔ{ۜrnQGBClYK$yk4{J>HIFRwS$#eҨ/[u!(pi' 0(S|jo&e"klZCo-Q%F= ȫ&2`=Ѫr9蓀8/7~ya9./l Lr_pDH/@a'Pu'lM\d$q4w%̜W[J.%Q[3;!nFyL 4N9V|.RCp&,t)gsmџ`؃g)5jXxA55 sTOڡ9z!D*I+Lt"\ />AcGj ]l }h]fnOl|)M^tʕ,gGS+'1<  闝rD( Tl}Yx1ox#l`U E* PeSҞOFig~oeuog9ŹJ(݆*5Zܵf{d%/&F}(ϰ~'" lXJQY쬴ި &Y#{ jzBIy <8.v0J]Bۏ9C-spwQΑ{Y]9דI{kq &+NPD9ؐ6bTe݂քf:P6Ci>"W aW2,W1!=~%_YmuH,ɺۆ0_/=+iⴚkV-EuB\i{vɥũ `tfrV&0gqc$1e?k cz +zJ!H+[n'~\G_ۢGzGTpKfm ޓf&tO~2GArM9q|q&0]1P}C<ߏnE 1 oYϊ>m~ d?3 }O/0B$X34#UYic:S`8g#ۅO$)㮩G&.j_jL Αc"&)JTY89pɌj8a_ngCS .Y3yEA+7|),+nZ"2hZH2vI[eyQ 1]i]jߋ;'NGȂѳL&em !{(vf_YV\;a2y XyN/@S|uVt.G1PF;.db764O[ tw5rؚY[DDtQs`\Lĩ=&M˘m]DZ0綻gI2 @)g>Vljae/WB4/m&M8=n 8Ƈ$ R!>fDq뎗 ^OBK,Lc=޹t) i)Q\ƒȅo@W+#aO)m GJ(zh2ߺVx!׊9EBJy$^qfu6| c4tֳ} LObp8f" CjÃu"e@d8[0jO Wߝ[ ^ C-DXdkpP'НHY\ann$Y` S;ۙHB0mJaIa0*覧Hᘔ&}%7'{MndW>ųX&!I(6+ ITAֈшej b][%4:@!*AҬŀYxZHtϭA׭glaWQ^)eOfrDnZDePHQ8d3FJ{ sq arF;w6x_ }ODֱ5N[q?@")E4˷&CRJsaTN?@u {(SWىAa+Ԯ㈡w+A W 빊_6= *ZUF!-櫘(U]5WT`mv%9)8!5!vwuyIg Eb=1&DIxiH,V9QJp߻$*;m[FM~I}*",ǍHPߊLDyTh _޿ю{R_Jd`Oroi M}_0`=' k,{is0/k32_ï`߭aғ_4e,bd՝}'n mP &->5c2W_ō"\ݮ5"3Fۅ}QEa7=Iy ])ٳ9P%iW缁ddKl;SEq vꎗ{EN p ܝ(RLԮM]#"0?:p&PL!CQV[pDmrc]Lr!#5/l qܪL}h?.蔏v (!ȗdr%ɰ$?IO/l\$1itJIEl!Qʏ gkI>\A6RT)`5 bA)A;(ͣ1Wa$VPKhHf:[R$GRw<JWѝٮˬS7l{Ag0Qu?&BןR6NlBeN&)HK27cR|7-? G&WWSdf~t_ O*}o wND1WE<֝q<1\$n;VX`5$DH;{O&pI%qcO@8H1C!Z<&' O,#An8)\ɠ TVva¡k~5ω7cYk嶑R}BHȦ#3/K攒MLvI"kC}wiڶrv^&7rH/IDobUmLPЍ_ߪKپFY *Oi gM ?+޺>"sWZVg`1+Ukzg|uP~;6~qv|;2f%G9SFBwFBݷW4 3\)G-75Bw` |izs]U "U` RĞ.BArm-cEÎ (U3o W+@V@]f]R-` С3`lt#5Y۵l?!YnZJ8mݣLK{z5jz+?/;Fׄ[x!-;i\=!| Ɣ9q*q'50 #PkI$`8v*򾙮\vb*fM*磿ɇ8*Ξ!N$9;'R%0E攲;E/h/,ӻJ6>k5N4f=0cSر Ol,] b1+%'+RݤsӕQƕk`E1M|&2kfYLV Y̐M'F !Z[?_t"-b?J{!ʌbbZ|^ʴ8H"z!2chtn iVrWzlll8v)ܶ#2Ţ5hu LsT/<ABWE *+H"&=|v6B(;e*ݝЮlq6+r8[K} c`Ϯ8}Sѡt PׁF: 2KS*&:ޣU[Ms4YYA> Sk-i|J>CYO6k*ąd@ޏkXIt*!ޗV;!q y)EUISK n{Nt~lij.n0bMlyw8$jI-1&G!㻮MFf̴~t/߶$L T+th0 P]78/^K[0Zۋ)4֫rno^C1]0@9ȓI_՘54gص ,fqb;d*] hʎg}"'[ bA-G҃=0O y 92N=E}O_,'xX vҥ]|A^*b+N/Sرe|F#ilp"(_R":2:MI@wiLBeIoE&Fwz0Wb4cvrAQŶnzV |D*&dţ;M(6L: c6^Wj[bw.,U&i&'EC' E%D6 9+RY X&\@|@+͑㤮/?twB2Bf[kAr}#D5O$Nzm0dLG4h)eCX[zs)lt\tK?9iogq\[ѤE9KP/ &*,IHT8 ˁu+z@R|qq hWw7 ̒bz)Q xڒ IlG~p[j 08VhS;ϗު/o?ѽ[@vh[̜KIFm0<>JX-"8 %68m 1eSCժ )#wD9´f /=$,ːoz-f:z?~<m]]w$,:H0jlAɆM@S Y!oK3?No_ZvVZ-[wA-óDE$4~R@j0u@ fpE2(:ޤ?} ?Ӽq5LV)VI7t7a|0%"z(j*gNݰ񀎾FX(AsW9IB\~UZK4sqߑ2{~R_?z2ZW_LQk r/HE =߰")yY/xeBBwKI| 7ʐRzD{FŠ*|dpdPY+ٔ\ȹ{4>T[@9rF|兗!,kwz%TfWq#XQ 6oՇhCߑ7 ]nW-߈%bDˏ#F6"|~n:m-V_eʧ]n8swh"eބ}˺ +?w׬KFVA&F7E * hFyXo-e-g"H@ES3˺_Hބ*zͶkwו) 1dQ1Xr1Vd&| ؊/3 3`=?\V]%0JHϙW]Jn8O[hc 0jCT2!~B2oȉUM08x~]QeDX,2#o4 Ȅe\n@:8 ӥ w&T~LZI0]BN8E숶/6E}e=eVr}m=p6l>n_ }1YN%smDvi"ѬE|xNlX_=I81+wl 3r_R{U ``XEOűi9d0p,s=Т {݂wCNF֡{,ި M"nO\uN=#h,]+I"j^e4RiǻhC7[aO1ﮔtx Ep&&-aGڟ,K8İbC`_$`i0xy1Ɣ(kc *2ڔ&rhp`jQ!'/PS2vKw]Z9Sb~d.7wQZfe #=#bKH%LlM,9gwc!4-^g~` MͽÝ{Jitz1Q|mݨMVE>QvZj2Ú t1$Ui]Q3ǍZⰖݷW>[|5IL˲' ߂CLi L=GIٕ2m%KoxCm?MW5:%O'ٚU<ϱ }<s)RjvmcH]Sо'91+͗Q.X3{`D%4,4$NJ0j s -NVSpqòF%&WŅ<b $2¹mw 8Q=C:gN ϝ nm OJib{2AUM84nau'u1H9hʖKlB:i{h\AZp1 B$`tV+ԞHL9 u7=`Ahm kW ^q,B)-{kՉVg0%5@s~N-5q >~;@g]"ə0ȑ4ؼ<=MDcuV~5o44I  0UzF؁UZXpcC+Wܗ'Q ǁOXɍ %;Bs"JF-ؼ~_7Vռ}Hh;  SceAzcS$zs@j Ѷ 3ם\('3)nX*[Xr>q(Mj2Z{bz{5?]Md +U«܇i;9dK b_xXRCHK'p2fq v$DL,w ~JÁMK/) 9=ICt*mX9/UbQՋ Vx2a}ArF&6 $T{ʥ_Sݐ:4=܌ʾjHɤY?Y_c=r3w| `r ;y`a6>{u MkQÏ1m}z+wW}r>X#,S8I@ f<ЌVyA!PI;&_HJ{˜&ҐW'vpflDq0VC쮧~m|<*CH`\g8+gRqެr6vc;>xXb 자}g 8gD3U{+JZ(+"I6%.L"lpL>S6 g6|PYX$KXA} w2N~rj[6z{Ѓ5&!R6fwIOvurR~P4pOW& Y,Hj\!)<'*`!Uy j|1(Ke?G*<7G#|$?fK >fn& ] ak~{ @H?2H&iEn'І[7nTLO㉁40y/M~#b(#[ SNQ8Po )Rfeo48f% /tJlr+@z5sr޺F^z&8K2& T2Ab{BTSQp5Sio<_p(b}XW-GЉL[% i.f濴V:xi_ )[[YS-ZA$PEs3]dg-Ϭ,NA/6|l&B*f|} uJjB5 7!Po< s(5ǧ>beYU}Usə@i&uOn\GѵڞEM2`ᖧc8n4RNEhD@DEW<,w*j, &L j e?7{fAH]5~UeMN)oBgWƮugާxzebgy;nQݵ? =VÄ_+T03>eSYpklTSky`Eӈʕ$ő)B1,rlK[m<`Nτ(I1 >D"αr|1!E]1AVɻ2=&)SĈˆhH[3\; k;Aްaø1%<%tJȘ ETr짐)^%yk?tݠ7%ZjæX'5HqYQ g/=2 Ì u|VmHz$w }*زrpQ`5.͵ՠm);P"g`u"P PNV`,F8!3gpPXL9QεN"}ӃYYbϷ3 3ZQbB|A3JUlp 1ntdaHzvk3VDdd;#1"TYӶt=ɣO|ӋsZ3T#&U]ï n#k)/JƓ/=lca ?JLv{vGQD|19Sѷ"(P3s<yUeoxO9,ENGq6߳qf,L(ũަS}?ך! ޠM E|ZWYu \>4 .>̼zLqYtd<dja3{(CJ](}YLM_:'G X5u{0d@t@ZfoZ2<:˾G/d@Wc',T|i1;5SJ%L坶Ӭ|2U.;4U\lcX_, g;q&GߔV7_95`mM`-vXvo7M>%A (yq\RDķ!? z%-o.?ޭC;'51s+Reux3/S֟2A7]7"gʛ0 j5+1Isd,@\(XyI6;Issٵ $ƞkcȩ^}>`bY{SYcaAP0?^Gw]@ ;azFWNy( R%dh{%c#?K^,j"#Ӆ#2msDh-f[-?Lڙ7RymypeP1:w@ ;p_bU4!"^ShI '!lJŶΩݰ dzo]cm?$1vU"f [IBu>9N$11C.zy/L!eԕvנL]2ߧZc11Gwt !!,MePvxf>>,^L@6^Ԕ¹0} 󉩽Ų ^G4n&3L?G47@YY?]aّ9Ey6ֹ*a&҂d/ۚ}ur#l T7]S;~*p@rG_B3=gS_%[{iMrBg0 9L/푞!_MpLobM3[zkLeQ V{x}‚]G,t~|OwhF/rn 3oy,AD%Tu¥^8X>H td@6fw :T w纙|* *n%ub)S:F\Je,c*o틕MoM2|>eGrSF6 E ̿EZ.Jgapi,l@i H$WsTc+GkҼqRLՆ GgFXj ā芖lIa›Aba@KTFˇoӨlծ~Luvuj?C_  G`;ٖHߝͿ\CkKΜ=BA)&28oƉck18> SN_#gH'$ r_U'+hsW] ހx.mjKbS)z95`HcjԻڞc:% T{e 5u)֒r62پ/ g.-|~r#VN)A9akb[I~:-jT4buQs*P09fmp4/?Y;/0r1Op#`I7OƳ:/ϭ Y; Ej8D0z$uExnR#(gFX< >3x^Nb~bWۉD\a/IY~E^! )`?'ĽA ϼY l6+LVO\ޮ"YCK$\u{F1PCziH:a&FͧQ_(,˹ )# ;, vΕTweAjGX(IZ_d)k&RK,c&HZ3UB]բ聧8,/^y~BMS](^s*xĢ(j}Nm7ɱ:*A1IX =p, rn@t.9ܕw>(9)7 g(*e.XI@oiago[@\?cryG+zɛ)  lɰqP(:3mӣ:j:lj"<=q ,]`hŨVy|X@֑6SnN[["-+2z mEPWRÁ=x\d5<6b%"} )a[YQRS~RȔEBR,f2=ƞ%]vVlD$8(] OntyDnrՆ D<%&LBtHpm<˳rֲlynԂ+2yVyMfH*(M/ښfgg3>1Iz^SW"- Zav7Nw,e*!CmjNVp"͌Wy|ya%_b{ tg]4}{'D \~Wf z0`Q@1Z{e}P2*;e%".;i$vwA(~ RFǵ3:ՁUӰM>g)#+#|A\cދO|9l$-1iR) ׮Hý7wtC1PͽKf^8S 1U`I )y;^i {=b| r#hդy3%5A?T"yy ` a眺fV1@lɱjh?l`de>wF_u:8@WO=aMpz)rr#ܤ8=6!Tx0` o3DL%d;9&3 ^ڮd;t(OK~OrIq Ҭԓ `U~ _4) dEEPӏ=^DWJIڀ+pAQW۵tL-R1w.Y,&B속83hк`9jXpWmUĊ6)^>t'Y7~śu FEt+VjWi,EST1TD4յ9 ]@XI pܯ"zqo-!`+`7P<ȭhЮ^sgOĸʗpZ T*IK>-iY( 9v֦+=% *F@ _cmFGSQXuM4Bɤ*,H V &BMaQBq?VQԾ`  nPAg,µ bQ JwW)m|IHUttD4C?-l \GG6j+~O+R]ړr!6Q<3}?<DمH$]mٗ"OuSB):r֬fኼ^'am7{}K:ȡ!S=.lK@1,`Q>rõCV,Hl )-Qwk;=}&y Q7֖FD)zPzJ&7-CXu.~Ӂ yL,ȕ=6m8nnjO?j5wx-ri{yM/d݀DAϒ)v8PZ6 `o"q\ZB&,P%FS51zx|}:Y vHe !Ň f4 T:AGtҾ_0< :i[Z;)`HZnI ?blB kyL:d8! k@QSDy}z?2F+r1T( )BVc_ iLZQ!5Q?[?8.K?uB? Όsޘr#CXS9 6CbĶp9="}mR`gǑN7WhCM?>b(?B?02S֑nji. Q&:.d)q]Wom$2(A8>]FO)/o9d#lXήz->G9gGN z6v۳q.oE=t1f0nfA9a."@ѡ !c 9XUzd3*-n~f{8QtKS1a]g9sDޠPM438]eig X2 %)vkM,>P|LQB&!La>NDDRCv<~ۺg}ŌZ (c.]3-d/&# JvhD F&7V:|ï /~D-6zCOlg>s9=' &CcE\өt+y/3DJs$df$O1c>  LuaY53`fULE&?n ==aYUSqyߙE Zy_2@mOػRnry&>::jgb*AyE2!,hv)`' [3zgEArMr4k0Xht1^ږl@;#Wu`NkՒâkh%vNVԞ>l'%ǽ1j>1Oܐ7D\gP#()+᪹9G[2+ n$D jĀ)#XtLNy1 쇍=[;k~m80B;vSE|jQ[^Pq[^gIhc70vsA8dq$vs*ĐD΀sL\q~~ATC)i81$^&^%ͼB :d^~]34@Zn4qՁ̗!ik+ӌ?k4tLo\BP4ond#d N~ϖCcSN(!fWvDOTmF򁱈y&5J3y41gN'n75аw8P4!I/ }o{lՌ !c+bM ;Lb" :r R6"m @NHeAAq YBg/ -: H;%`|_٭:4B¶e %FG#q1f&]-\ʼn_՚6O1-h͐ $R*UHYErQ4%i+}/jڗ ^$lnP-eqnfho: O*p)1 Du47bSf&Іz*{l!QJR jI7A/|[gǒW]D-孏f y+4+8B-Ja£5e!?D9|q#x{I f|ydTp)Qp8K0sy^R̀ՔE2}z4\:J-J!AsAS+^@ ~ /ҽ,WukM g'ّ((v Ԋ.;P&P |6Ns%zQ`EdrA `Cz>6 YI4n'i`/-%li~ޗ]45eOAw^,LpWʆAԚe9g! zI$+ (d)k>Jd&/=XCs 'uPo"`((C0]oyՁP, 4船d{}8gGClEz~W>9*vlmD1E,79;D<^)JU)M0E A ~/v N;oW ;s%c_ҥ?u1c{himLQ Va@NKOKq,Dӏ˵R=R{Z,Goi˵cmsk C8T_rf4.ACuP<5SaUTfT;hKd}H޷9a a;a.ԘWd/)M)aex.[I3w|cz8Fרt"-\D * ;gǿkE{27r UN6pz:b]#Qv@skJEU]!;y3Mu}t[ɴlmɉWKȮ cXD()#rF {& KcPM‡vqPt#lplfcڦ~d,UUCs[ ɺZv|,!,D:] ꫸Z+h2Sۜ"] 6 d<$Ļ6I)b =u =:P gFݵ5k}%e$ 85􌤼na: ?1QVJKli"S eRp2m:+^=o 5(]Y薙λz9ʳmxn6AQDq k.6?#QAu6}٩'9BH09%`Os^Rp/e<ؤ(㖁\|GBH;Y_Ԃe<ɠGCVƋS8p޿ݙΦZ ױ۝GzfTO(KO]qWOzb28|KLX;^P`Л=Li9ө$fcƣ=}'.e2$$ 8j03^V[:|rDmC)8֯igYL܋ADx[c;Ck̈52Ҧr9Z6O3CC<_!dԀE'e 6^ ӪuC'rT-:d\&Q@̇ {lnSB̂*ە$d_Z3\~CVd!95 GBEN7't.nYQ]yq$h{vBDp$nj| r`0:aBDdH{TRS^&RW`Y{jB<(Ri$C#GHy2hjL'}ʧfim2p9eF HuOnMS"TŰ/hC/Nɩgٕ݀ӡF!x )eF8x7C7v{5df RklTWE_H򽡿4c.=s+\U;&4UjTn%H}H`ޅ&4 r>1;ԠYM/Kg'z=X+7h|ct8Ty]3$R!|<;]X$(JzD #~qI"y\Ckm^Qq*ByFxH,,>G/Q)Xꂎ.iv&ܒo3EڇW+r`!5AM}mT\iyב&vtT|ʻĕe%ybq8 WZr92i@&Xm- hO՝QFic-Wr"2UՏ<]YGq \0& jJJO]؛򺰒x;v97@hLខ|Fs{И֐j|\w45~iTC`f.uM ,H¿#4`"2LMO!26u--QͣK-iz<ƣdX],C~zqJ5( M(RԉiY顪='+D =J]kY />OG [3C+u=~8iXi*t[)Z=j#Y8cukx-l oY<j+ZVhӢys+k Imr: (O!}ا,zu6δ2򮊕H.N0IE. ;2JJ䂊Эҷ[eUgFnx=zT)k}XA\̗>{fP5f]W.- XY-]!Ʌ`|I;S3y HV8 g!E/QSgFy:%8sGXǠ%EkQa/!.sd$U:5ى(}"N>^U8YͶΙ;_SnoտҰ( TLwYMkʞƄep̪f3?-yoG4dt=olgűZf(@F ]y-&7<2#!uOw9?F ט1zc9#j0ՏԀy!DP>`,Q0y%W 5~xk٪:7 8zxV#94z !I_w{]ePtN}ѬǎnY[*=Q GSSSYv 5 \|yGUWȋ[q Z䥚WLSE+;1EYI-#泚qsSNwMg\\U(2D2I+W |A,o+Q<]^. NdSSXz"&jkzx׮+Fdj9(֑@鯀%pAb9pz=d?DӋ{+ 8Ե-4[V ZX2vj}L7Pw`kx"5IǷක nf]^˲Μs7 D 4LOVyT"U` ucUVGP1wŸi[gPJ-i\>\[,۪f&jAq t}t_=E8m1u,h%*ep0|W;+mASGHk5b`\8.Ga!ޘL똶G#T_˪+}k>zK\;}Q*DJ/Ow;0^k6q +O$KFQʌ(ъTʼn/[%/'s v㑂.Ccvf?}#7w0`a~Sk A؀>zY ;e *K[G/g =Avh8=+1;Н5N`6}T_o4=Xik iYd/w5y Ar'zc޴}o(n֮A:lSH[pBp69c]RDkT>Ypb@~qV믣]}J8C*o2[ƟLUsCi? vgh@<,U7 奵Ckcc=jsxn1^5O`ҳJO ML#L!'-ޮ,~,yE"9c+P$FF;⹦< U lJ:V4.kX $VB|;q[ըz^rA ask5~7l ֥f>>o#!kAU:rrl!øyg꫄)&9x<s o]Il NsԗKz1pb893&En,]l…3IxE(dZpW?2#Ci_&kF4^ۢ*^_vHShMMtz"lsgBho#݀h1 DR~Nٗ)[U~D @%1NIxQrֳʅA2*g/sRan ̝x``o_k1 fפD Ɣ0[whG}CKTI 5˨Դƫ*0X 1H0[(o}\x=1je!z;ĄY_NUߴ}Fʰt0@9_8 Y{Bqҵ pwfiH1b>)Y8ÀTN͎ez X0k#J)9hµ.ל+Ӻ} $- ˯ha"*mYxbj(GrUv:+EpŞȲERk:On7uP;)Ծ 鵀OUMGrV4ߵ7GIr| .#DsT(^úΜ%!A-pWz+dFh%V$`8iO-"e83tdh:MHIv9UNV×"ļ,z4렒uØ@&`= noZ@ DyrGA͘SO͍w4a/0$YD Rвbk2.= ON- ˙w3𽌮kci6]V6!>ch 1z/pX=ox|YA>f?Wn_I}k~LK.q )?SۆN40,庻<+U%2NoI/}z>W  o?K095 쭲n%860ThHeX{d]DZP} f/~»(Kq Sz{vRzj,^)x6:Gs٨$2oW:4& $~&zMKzaa8 'l}?g J- 1C=`Gœ0s>*6P Q0=5@Ӊt|VWèy.اIz^c6am-Ty x8ݥY_ֲ l%z,]I$$}5|jP"Ǟ7?ȆxջoV .Nɂ[r$m8U*3.FcYr Aۖw% uâ(&kK͐4fg2ݗRx+ /1຾V¾V#)r*|<t҄WrBJ:yvh$_hsE(ѯl >ybΗ8 ïnO?O  VP;lH,wG IٵZ8jʣ$PKzvٙH?Q/7O72D*t9v<[kvZnA QAaYmj!5ypU9{KfĶL3֍.?ɕ-^ ?>=}̉:\z3`WCn-ʜGM'C4 S,e,$U?r'$Q3Q@o}vxWWzVCn=EZQ@0; $AŬq!)g%sfmֺ5*:t;f\f7[. /qBwް70x붺; `RJ]"3x|f w E1.N?DeZxe>˖,SU _'N?ȣg?9?ᄠy;MƼLtt4wמ&_ۛw?Ƶj6ZF 4HbaL_msŜ܆3~)r#jZy^ru&b;/ wg->8R%7c/NkHMBjby' r@ɂ͌^5*f^#s|*ɳd߄Ƣk<&[ 5.b8\ySP`T6O,@q͉?LV X v~h.*CG0,Ͼ 9oUK/נm/up/*RY0޲ B%T옔ݹC`vRj<;_*94V# B/JykV=ŋxg{H:Ҁ1R1d5 !bȁSzd*Ap#-\:snݾVixk%m-V;Q{wE d8 פׅ~D"Q5T"rzT "1AGCB}s6]r{Xe$c(7aX/pֶ"Wp'01=@yZ 2}#&+1kLGMd)8ƈE6t9i+#_`zqdm0/)! |QOhxfMP{U@0ҽF^WY+-n)#[`AfNe?e&r([6z3kH-]o'騇j7et+-\΀*V'P:~R{olk,]]05j>x/Is @  %HB+j ; V<…;OS‘.B? J-U]T;XǶKj^9A>k$&ă}x0*n?s_"{[:# by SAzg,=wE#j,x>B,_nH CF/Ċp ZO 6S߰3fg_l.ԔQչ7.'s6JH4{`-ڂG gx@?/>dl6KX}CSh'׺e#k{KYi&T 'x,`rdh.ZBٖ3i1ݢ0یR0DoМ]ŋ^KyAۡO W9uC3[\8,- DUZ+x1>mʑTT E`K# !J,p j2jʹqwD\PP 08A3fZ< 7^$8MC ߿|m=ysjg~+@1Z_Yʔ mcI.E7iP 3y-W .aJ"T꾳6|T3ڝ%=kL=~>I-Х nu\llGhGyU*>13x7<ɓz1HT "zqx]՝0.%bo k%Ru97N%Hb64˟P 7 ʼndY0*Pv_ sӢab}y g)fwNA7Řc’'"AFb%Q!Bؾ?C&~+%s;!Դh%&SF̓^)hv?dQ\/h3o>dFO8vcXX>EFnc)nJ; -1wkP+f@ ̈́d=[HѪ/g%,9F4'r=;Yޓ/yŽߴ-p s?V@GB;TuT4,jřruzc:ri_)>˕>O|c`݆oQ)> >kwXҦRB6&:Fò4(.E?Z 5J7-f*&F&E"nIȴ.pf3睋"!Q9g @?x!`H%@26y!dkN ]#cN+~禂˹?OϮJ:PSvS,LXyPLR%8 y:QaC&=(g{L誩U, ɿ#~ -s69!zS! ]U .ډFL{#J ڵߒNyG (RbyU?0 0+Rӵ`SF&j >V&9k1 OK75ȆhXPEϴWYn{Lw nJJ!inM'}`<PM<%9Q7DLJBKHh{4-[>ce:N2o$~F{]$o 7?huDehuQ?_]_^ ~kZb$Z=N鱫>1AƀNd @^)pz.L{!ҟ@ xR~poIwl+?H BreaHno9uGubByQ#a#Ij[`9ѽd zFY W;IF7`! 2V^ՙ~ QRl|i~qRY(ڌ"ҶKQ~Z$l ةZ/яJ+96۲1v+Zԉ $tbڸ'IňԄA+OOJWz2ܳlSkE`Jg̙p$UΙR8ɓqJ }ܷJxeB#XG.%$Ij+[K&OX=Oc>,^V2q >\КTPK_[~hs ϊ;=_ZOM+r#Xf!z*H4 I'qG-+n@\D#QHx}~r&u{FݓHmsU 9|eIԨ!_-AuOWԹFm| &sP݆KLXKa6|p #&\ _C=Hj>f@nCpE;'hȓ,|u<m8B`듶(o9,r3\c\mRȹvnjΊN/}!ZQؾ586|`pI[\P[@U |kVa ~E9 gDNO<_k;jG=q?vE4yp Go^ݞd>kB'&=5B6(C 84i=)Q5 ~\(7Y骸$%#IGsK땤sežCE-7s ܶ ;~ly^XD*D٧ !% r$_w@ HqYnsl_$γnIpιcHbhܠV h2׬y5{ʷ49NfBm$ā6,%PZ3XI4#&)}T^#]z*c6>JxeV0!7JaXZON?Y(IY?*P?%:I,ߠR`|N=RjAPed. mWINFK\IB_[WFK2Z3U9TW* s *mYGOLd-#s1iUW^f>ށ<?l$1@@#ᠠsS.)QSWd >aA薽Ҍ/Ҕy2ɪ/Gg,fagMy@2fd#Rkxǡܐ,Ȣ=mkZP)Ԭ|KcĵpS' |o2,d XTYc5~>~.TBpda~"G]WFI\;~B7E7>,>rO&Z}ſ0qg+/)p;J(ýC!hE2L[ǯ]![^TtFR$!;MjWvoQRlE͠A Yq"@ d]p9[ aIxŮ2#u$sZrM]0B(."@6q}`U \Ebns"/]˦ee VuCo"Z+hVQ QNZ+ )29`.z^tCE BWO۞yR(j fڧy2s J!t2eG~C֟R4M("߱'/h錐W Ք.3("Gw7Ïޑ{Z\!wRTc38LxE.l4`,~VvA/N~&Ν >3n-jx +(jaD&^>|o6+t=]?Zߟ/vh#fVutxGM:4J>@[@@.JtMa[NGE/IDK3c :ce(^8D'2(>B| oL$T/y&}h{Lzqkc{܍cQۨk1,#[ڭ "wuRv"r&#ur5n@Ũl?#-uCdkI0E|ҙǽޱo-v&.cJיΦ=~!ٝa-"'ҟ 0 6EZT8b쟇V"t804; +Zc2 ?ؘmY"2sx-N<47kʁ@8F{8Nѻ zžfiĐ=: LpARmxz񝹼g՛đ6-KBtԯ*S2` xdEށbJ!EtAwïHbljL ElA\2vU>"2@АЪFQjäX:6> =h`)Oc 1]-8% ^dY=*}dp.g-%|`t}D,{ת:MyPbг?V]H=Bh Q`wҗ-dU%PMqFhrUIO$ 6f$VL[ax~ RY6&: Xso~6}t)Y4r؀f3Nw@DJܬ'Mw_%Bv/b'măCMrRy0krF'3~n̎xj`k(GUz 8%4"jgߵJ\-:Y#&mWM?tyt*Q`XYO# Z@Rqt k c1 LK<X.H4;< z5äJFsIt0.;to$7|n+ŰV4,bS?3p ġT#ȿ[|@L&Ď)hJ}!y3% 톓Et<#e=TߖBA=nw !terHU^ZާTܛRRM_V,yƈ ϶K`K̍08+.d-3Cz+_9,%?I겼L(Q A{|[0nOiٺ} UQjPQT6̅27VtF*]dh@LG&i08UtLR '/ ۑYTe EZ,jV+*>XƴH| ́(%~REݓwܙGh $\k2K6y0@xR GL^k!ȼOr9dA0E9{a.NWdjFߒCw y-o(Uu[׹I$"C(x; ؎:F=7jP5̇iRKQL'6PL(4'Pc6[qĚxB4";ߋ~_Cп~$١ŝ:ZJJzgira"O&rlwy6y9kr/}zw_Lvxu0p[s!KՅWk+ت8ݔZ<7DoNMfh&t9BR&N鞇\G$G15FqK6r} ߳rfs+3a!I$ ,vYkTKhVhR.h$ZW:T烇V$^ 8{9vmjFn Qd@ 0?^y碋0fTe=桁.qXy$聃M>x|*.V՞.|e?&/PnH]H^~*p7-$5i[tWEKlZ& to-IwRB#yWEℂ7Nf3#Jz, '%GUХ Dl37dך,C#4AxfƑV^i c<c2=[˥P yf+P& -]*7ȠZS&4ǚp˅TNW\Cs)ObjӼ*`7zoo|dWʦ )IlI p3$wy`N=fHU-9XazĨ9*ԝ~51ŽyTYSnD:+i&%#$Oaj,9mW}Xel;W*m1]<6d[9s!7VB7!9w{An|@)XJ @GR*l QHX a{=k3k(<Q²9@_W̭_.ΉFJvk$?Ӛš%[NtU"8o v/1D ,j }, u QcWXA43`?ӂm.ܻ ջTRig ;QVx{ƦљDǢU EƋ^N_d  sgiJ̀]Gk Zb}nq0͕?7qJSs 4ᏉKIez *{/L!p8g^|jCtF+=5,sllutnbI2~>K7 v'x6;4ov6{$>@s4wM1y`ssקoZړx0 5* zK#YCCfe%vk^ i.t*q`cZW,˕}^w|+3't>""H01*<=j })'MrTw;ԨEb|,DT!luc2cb13wG*ݘcnShzr0!ōQ1R X4FKMz富vᡣL!u劤].W 5Ace+N2jȉ׋&N3(O!h35فAHaQx>+U* ;+)׬ؙ2YF~$C"e0Jrm nw TEBSw.wj"ZPsLw$V&셥I]'҄x=Ab<འL1hib#IF=3 [X9M)8OX .lTiޏƙҌ=CwAyK:<ב/9h(bx>OкI1w@`3ڮQk")9$a6䙊i! WRIe?Z<ύ/&MpLHiDI!C0ֲC $MB6P?ĩӈW!{tB6-K;wTSUӤpbknG?vT{m$p?{ R ^_:6H hD1y50W= b|ٰaD>_}Cr ^eNIƄAx}tAhJ/UptN>ĴQ -I3]B^4wzz2ְ]qNlڊ&p" )%dWEP( 0 )|*=P^i; W,.6DSƝZMfro+lNM*)N+NHS0KhyG9窖6]0K|uYllclϒdlc@C+W-3([U*HqNHrG&G頨+jrn-lhG{,Yj+LKm:'L)$]_[?M$ CFFwNqcqLL!֔ȡe־&ĖrGELwL^m[!oNGtJkU!z#4nk,PHNK0#i:gL ~<$жh}CP C6ұ^SCnf3ikՐ9w'T䷩(q抓zgM~mzfBE|DJKv>̒Ѽ4A^oc(f01}@ & {ϔ"ܒb_͍W*NHU.8\_}M*k=m1|<\1Z'9A$dqLHT+(SЬۨ1THY9q:]hN1y8j/mA\&~9),Il(QK~χN C B,Vs٨dXH!p;F&5 ETE&1rYʉ4+ZCniψ$r]ب!^ ָ6)F|O*hhCjBm8 |Au( BVPΤZc@#W "$:Lf"蘃+dmҲSK~^qwYm00һY=ͧյ*6fEn+{ hY]'e\9)a|W-~Yp~KMՙպBN]!N!&_Hb\0GF=.x|#mAG;ESbM$;f b9J"nUz;>Fg2K[kZ寪k9\kn Nd@߆[0EJęݒNetMG b"˳j\c3k7}`F[*B[8}5ӫ0 +Q[_F|'"ʝPY>ɷFd`S$v߃wP;L_$6ct* YBs(gQrFA.Px!^2$Xo<~t,.Z *d:3M6p$Pk$P0!igsMr [C hcUy ۀb, P5nnl2h6L~`+w 4pQva+1coB߄dyAD)ONl&iHc& PomDeyYt7dZbi+#slE#!En7EՖĹdhe~R.D,Bc8VjuX %t,(m(ڑ݊j4ϯ]p¦V~J݌=9VSI|5?"aE7]m 0W7}3UK4Nm7_اlT>q1<9QPQ9E {dloK]ล%A0hq*kTq5,+"'=.ϐ_ G׬ZV쬓1zHPQBKSÛbHn~r %2/T]evRBóщBgj9y5wH\yYynf@]N0j~I2A~2 \lEUwrZCț`b|8oVbԋ$eQRl&l {_VM;ߋUwXyAWR)TUs~"nbD@ʑݠ d舝{4.pC+;9΁lG5ȭ,= .VgYTQDZ[V<ʁ+7U:)&/$;__q lmFPo/[x="?-KYfq+zNZʌ " YD|aO4-C<8Ol5͗bYݠhmˆI?UhHT)2}H323D(_]IoTvGRG( k{w{Hw؝sGl,^kf]-{ܽb(af`.fNFFh ?(;BsF1בֿv-^{I|p+X)2N'OPSP0/n,!+v¡Ugjq_2q5hu)XK>h锚;b5WjX7&[GpPIW9#w%8gN<ᖩV.oSuYCnZj=E噘 @t:\l!a8vW>[3$5!-7&@T5}tT7PI0P :NN?m (Tz/l4UPW55Aލ$T0 řFD?`{%jo28j k\m{P?PHQ#{W`N)Ezu&sr0,b6B+|-?G\ T7-nXc7_ Ǒ# )ӑZ?Hd)tqe#̘$ihHEE$"uV P-c6#Y cC,-ds儤cdpVe;gD_uj bB3MxYiޒB7(-3tgB'+Q3Lwk[;`j՚4|:˥X%,=+EqT5c}ŇY ׬5u ˳iKϊAMI}Tu6E U`W7(LAL.^h"ߓ J"p+H#qֽE&qaFm+ lX OdҦ4U}2a}z|2d CTFK#y*n~"z"q.ܔe$=tpo]T)YFl+k41/1d9`b#?D`?%38Aј=3#:h=ML22.HgLJs dh@3a9Nݑ-+f;/:);$h`ѶZ%A7>￀CNxzmɦ{U3]I^wN0l8}D˕`FKcLc'@?fMc 5;1,'͕T=h$h<&4h珟>݇1t0So\519J~b'̎QwLDI[Z#*WkL楯|1t@~as <^W-ۙn<4./BwǞ{ô|zdNR7$u6p cJHsGכo3J7l)5x2z2lZgbу``{y#ȬqjpQ3ණ=[с'y -.x"Ddy**49PЦ<#\WParI:6;M)xPr?u<3B]|21b;]8'Jcv5c,߬$sskuQc_5p2h o_mb4w@uz9oQԈ^4{rS\#_)E56 !/sf} P?,OWL@IN@nn(8 ߱ P9?ME{R:ʾGu:6¿ ׶*N: xEDg`tWFyZҒ)YE`_\-p,qnet_]>H{Zw:80nc3Of_rQU|V^9" zh,d#- ۱.$ƟlX W9!M>yL&$EH˄"fĐ|ٕq,MIV O:9=tr\3B$jp %y9 27$*獬+~= |sv=UB }mZ?ӌW|ZȽ&t[pyB*ﵒ+M@[0~;1DŽyM۸}e;,%/E d@>F=(|#*FdX/mgz?{u's?9N" (@J #Of楺bv.я1kDdnMKۿ؞=>ɉuR嬊&ܷ&2'9UW AZK$J A;5K49lý(!|({|{~T>كI!\W+`,Ɵy6ǁM.z"h&2rB}xUӉp5UZ>q8iSE r=nOaG? Of߸pRXKPM\[9vtNZKSh:" qA_XܢW,BL3_e.oَW^DLƃWˮSEG)M2>4H,<ĊW 9_DBMzHNtr8[|#{ε4j*GI,3N&)5U3ț~IϊS6$R$,yVaV`ًfܽKLV 0#T[l5Moߘq/birvy2&))f8S@_?C^UU,(Դf(+(s!_RJ$iuڶZG,WA'cm!J1OaxѣZWcBH{ԍ?OeU\]v#Fo-4Ą%#0q((\""fV4n?W$g.U2[#CߓG "]EvbɉF512g;?t.(sR7I#$c!Wu<C*'/ U|',ѭ/kCp7zԩ鎫{gSg\9|0˸u}Y(y6M7?>B8v%,L:^`Қ(\yFgK7ݪH#M_tkzaZQ) fBd,Υ51bDZ>;\^yV:4)$.[y~`d`%R@wpc/Ŵd>k(8+cDȊWg|OR-'lj&΢x#CL 7}HFKtY]{coY1ǹФi$bL‚+Ͱt1^N:t h?,נB)yg\OQ XёKWB,۩ ۛݖ J\Iykw>dn;RɴUXwURKj4Eg;mma{yKO55EMayoѣg<9h96mJhTԆ 4;x++Y%,j Zdny9u`9S0b쏪7I{\@0)7Hz{u䪮 oo,%|`}G ؂Ӎj1FLXT )R Scu<2tE n942B&{TjOBvɗZg./Mէ:GW5 Ԇjy2IL%"p/OVR,v3l }ވ.qͤ1JU+ӣ dmzC< $ HЧ8@9[zo/9Oq$zP9V=g1ALůgڕ0˵?i5S\ 5($ցq9UE7{jWƫU[Me=||&z 6X#<6ښS+x|-^=xF{(dPJQLE  ("dDE<˝pwnMd|->ȞLm HP+6,^a{\ჿ4[*{⪢2[׬VPxlDcܐ Uc6/p>$(Bdnn4+q8+Z9Ů&tz-YBq5П@Bʞa,l7/*i`)KjID$F铖|UJ7 ;ˏ#9bzj"F-T3nf9N~+ DE6; Puz{#!jQMBپi 8`K *QI(bbpXdIMY X NJ 5y'1dF P{L~~lj6,9;VĜ礰IA|{~doH`\yK5yʹdռL N00.k 1yqČ2A2QwA?LX#B};(*cx.',#;.8u(4ޞј[V+f,ۃK|WL3~z ^}W ;o;?|p/4X*Ê^4neD{4\GIj2@<7_$9zWaׁ!%Նf zQnǮ7iE􅙽DuD>Ny%"m~%&1%W tJӗҐ!Mo@jhʓ&T.ઞ<"g듷wFޣ."@ D,{X"uH.Pپ@R <'"](b ,Ie೧ڕHM){Sh,6 nQm} u-aX &HL>Hc|W2ȈoDJgC/D:e?@,E5d!mD $(vYEz AQF1beRҏHhv9H0,lذzyp N#km xD\βS\Χhٲo~{0Oiz}˷bڵU4SuD᧓'_d)l/8lhBKlKybOt9:?=mhdv;@Ӯ;s利⏥zE.m*ȍTn5{x!AtG\5R&w4?ob#S9yb+~A2%18S`]3aYl$Dc^T΢LsmScj\oolO9'$H0ŠlqբO. G؋7z]҈63F@bOgՄ`XU@pIE/mJfiANw} rN@Va/DG*i+%]#-@ 9F쪻mU}2ϹhpdP\晷Hܨe6(I(!2d2ooBfxd3>[,6̔-J͐>jfqymKyҡr'=\Kmy2w_R 2Ѥnʮ¤ZF۪?)Zk5dOnh`/;zUtQ8ߗEֱ=`b簁;r2no&=B*hyZ7e!ؒML-uVϾ"CW^]t6ņNM6["}4`xMǙQDpC9aq"bݜyw  -D^D纛˂U Yl%`ZJ>p+R`ޣ<]ˆ<12;Nl7h#_us/|MC0#S5zt"u|&/r1J,sFwŵc+Sڍ^Uwa7׃E܀zSfmD_W$2ڑA++{J7 ! p?lc:MU-{fPi }+n%e w}[NyH`хPݪ)'ַ:s2Z 9x(}OW6B])Ci8Ā+!"|;\i-t'u#a9Vjl)e}gD]uiDҩ ?9?XDMͥA T(:E(Di{ashKl%jEPŅ7˫l;JkrM˨j>~wn؋`^]PF9Shh ,BI ^KϤ~~Y9g\ '7ຶրQu ͻ뢠ͣ].t+*y,DE `z?S #VS43~>1Oa\' fhw.~ tV 2Dojc0@x5>:"͓[\g_=Dxm Iոǒ6Ҧ~lꀀ3ܲI*Ő06}G #?hE!wa-[2CQVă皀2Ӗ)ߒeeۻ+٪ R\eyQz͜ѳɹaΙS@NOcLiKf]h'QFTG@X#s+P~@Z~҈z?oLLQ40# ܬRw!oip%¡m=O=X7o7-g)PyacvI_@5 ez (N.h!0כ CsI`g.o,EM>.}&K ^\~%`zs]*ۙ)>n)i'Az4b=|.ώ%G]~f4O0d:l' *bלٺ B`D uiocA=O 55R&5KA\~jIʄp s9AP_@}mدeJib3D.+|9d+{E({}*載݂h,*51'|AQ*:G^+8'Vi;f'.OW ^2]G?kڦ%e]90)*^24. 5w/ xj=9z?n|9QK,$9Ȱ7vDP$TX5+|WMzf:HGpEj!WH 9]YR.qNqϼrp(턻cE%`Uk ?ˇ-Պ|XƏNnl*JV5.T8[랐US1StD7χʘɤC0pT;)u[֣ξNԭ2eo)2d K+_;+;QG.OD[~F$̗$e0 5컯\O3+ u-3<7Ϝ&-Qm:Ô3g[c-: PyStrv}=Sj]L)|&fj;>"!eF)۔)e0J3}Nh;Fá7Pf"6^J ]de*ץyHLlrԨ GNV<">"I^G_ş޶`v³&j(fB#1Dle-ּybEظf[rz*4 ݄[K,IK)]ƶ*wKsPzlSlBiV~9U0h.LSL$t-RC~喓G38?PuSv{S kFjb0@,h ʔq. ړ}a#be;e_Q <(c^"^VTh\V6!,\w\A=5$B6nq\LF6,LeiZsUL1a;Vn[R"6ID]@rcSɟrQTT\͇jG@C&;mi.X b Qg8_g6Mh{ 9@ aOe+LнY{=}u8T,Ad*&:4ݳ|3Q̢äz? E}B2a' Ǯu!x@+wܞqDBm;殪En?qDBL=bajRq$@ChT?/9ؗ~GA &X(쮪C:rx7`bL]WI3_^bX^.m`~?wޜ%A7hEj:P/UY+KV;,`7M4d$|ba%Jé̚1-Z v73ʾ(a~S5K`8X ȵnngua'Ŏ;]&P7I'nkȩLiPrzϿFX Tm.Hp[F@8`0R̝\k{Z%*iOrF Yp mvDJG2}}ݵyܶD hHI(n-f-Nb_Pz Uy~BoGUWY~㮠ݳʁFD wk.w6(= 8* ?'[bxlx[vq٭^.2sS d[Z 0LuUҞϱ`pSO5 '. ?Cf HYn/l(p/#a@8͑Pm 4 `R%HvKw$HAuWA?/+7t"^.%1nn֍fЍU!.3))÷"q y-7=+aR!^S:H;P 곴[@Yf>C5AyC-O]S@D C''Z5>ک!/ԁv?HPhX?w[A7zF8` cy(ڲ &s_*mxFhiFjܰsax`cD p\!{3>vڳJ?=%7; Yi6,_sbu]zr>yy8r\F<@c#ۈz\F(^/Vƭc0yhD@?Q ֑wۀq=Ox!yE_tMy Cvf[UP -(7Eqj[ +=k]` I.qS0q)PctbiЋʐ .>`#N\,-bVTFh!) C= KJq?X&W:n4U/@`뵮G{,ujF]\P) Ӛ&cٽD -–%Kp+xZ.#}VWEw+qyR2 /*3mqdqo߾gOQa։A{ &m1#A=|H$Au[$1 1ڈѝ !י uCE~(s r'U^tqq5V3 4L\UWH>ע8 ~ՌBTJ!9Zg<Є& iܜX<36ΟbC|w%l5(y|Xt( ~l\pE]eCg+lَbYhdTӵ<` n:Z`d&D~& 3p(a;4J/-iK<֭I2ok1l_P#y|-ҍ>* ")32Qc1`W'3j,n\s3A7RcXpPY%bH7vsq`-=$c7Ɏv uŌåq6u!Au{ Q)a{ gss h[aTƋǣ9-!vEyusڇr95>SPUyK?Iax$O) & F2a._APqi kP3潞AMe*{'i9Pm!]C3>yR4"aQ7}nx?;;΀߁ |`$2_v?b)ad{!/Sp8a|sBRE EIC- N9H|dEl:PbOp3DL&޷ئ/*1)⁑yqi!(xF&plRB,iٖF(pQƂﴰaLѸ+1,iW5lu͞Z) g ?QLxrd>SZk+$=iį3e*^#=`b%$S7, Qwxg7amyv=!%qpsJ.ьnm&\5)2FNX$ !jQڶvHEJZ8![Hu/)9V(;!x8yl!{fR~m"S.5zy9ly,9@X68(GȮ0t @NcfQf9xeӇ mb5l=2*]W$#}\= "%9{ț5v_!,l̜v(ϳ`0qYEg^C!&{zS~v@-g[XZ{.uJ/^e`-OMXk⠥%Tar{2|j͙[^R ʼnfop.Cޮn wzkIJ 5x:NOПj, w;i+Gp7kܘ \۲)P%弞%w) θ{S0<-1iO/'dW}ʲwY$mpII6cbK&AS{"plhzp̑@tIsֿs ep^~ahx}ڂ1oy~S+ BAv( IKMJS _KMo25;7:/_Ŏ,0X^9fOSbE*¯<8+ݓ$v:1W}H8G6Щɰ+r9އz.(ݠ8%CqOh"[~Ezq#6|?w EYz!ebؚoX 49+]SŜmbC\3ʧ[ TV1Ck&3Yw6LKԚ> f+Snq)K1aTˆ}hU RO,jpUY6plFN׉IOm< x<-}R  )*^C6duσz3H+RKrсgAq·hgFB#X5Xy"3`U?IN;W6LJyINH% ;g/ɿ1ng~9f~`LQOn~E_EƘf#yť~&XMɄG(רT[nUHDf@1כ,W;_GJd(J.:B'#g_v[N밋5Cp^e&]ݹlHh''lCCs(=<%,}n7Wlxp`wXi@Lz2z8)tniكp1=ȸ`[#eELشGk`]]ZCSKTq0 (O%|Kʠ*PmW: >+0CdžiP˘F+^#PCg:BTr[ҵ}.h',4v~jϮJ_@ooyk_t5ۯw^7O\1 zfnqd e'(^VD 鋢f|C|ȍ@MfjhJj:`CdNO _Usm[ʡv{hn =%סp F;uĸ $%Y洸:Se+n^~z!JՓ6 #f^϶- y,t_53h_2X U0>Oʭ;\෿Faԝ&LPj9AP(#DY0Dk*D#TfyGЗfx-%ޭ_Z=ےUmHd`H0¬gF]~ީ|sϒE(mE  B 'I5Ӈݧj"/788ىCb# v`LZAz%Uݿ\d̝+6-e=aHV}FWv㻋yz4^jM{]GpEEA]S+6;bު^I2ǝ1g%J@gʾ&:n@V~oQ_b%!тA}3G$AlʩoT#EUfQ`q C+2#-s61`P8c8X firbfHwh~ݔГlNjw) ^oZ]&4)8.5MKP}sr(S ߞ)4?㈋:??OqǢD}r1TvNcϭN`\0U_ CHUvm7C"T3}e3ʧHJ.i +0Qh]CHF:-1 33Cb];;ѓu U2q 4w"9:hih+Q=9Fvn qoUFvM螄)йQi$ ڹP;+m;27D>inўueٞLV M?ʅX$.N070,ǖBXS``:3ѹ^BRZ׵vZ'+}v2Z+̢EPO`vZQ$J-r&v>$Y)b` 7"zN4;#=' Ke^Dg.֜LZhX!,E .2TiJ#֞A_GdLkY%nJUO VFLkΐBՙ-ٸ wgpY]mdƮײ<651ᇌR%).{VK 05"5pTb9YL$h;rcVmi7A{]t*ϑ_zaԧ k  Rk kYacZS>m{=rpKXD_Hªl5. \psL-!;da D*|ˊYF1+ b4= gEƊ-ՠyGk[u'sIeԃS,a,`<%+Ma:uĩ"ģf*myY aQ^EemZ=GRa #ّ-p] Mŝ&_ϗF?$%<2prkR۴' FM/-w馉P3M8cW2j<ΰ-0A#l_;l4 +8o>]Wsrfv|tjeL^e̵ ^too `ߴȩdd>"<3m MC xu,aGl솧ria;$άYK zn/`e|Hߛx[GW.ȍ7\w#[ޥO"Ҩ-EF=}f͡U4H\{؟(ͥ`$:"rVBa ͳF;Uk٫+Ux!^;qk Qs;7BfdLET[)5f mroh; Yb/OVXC aMLzEDWY;;KZ<K ONfbfӺ[z,3/%~,&fZces ktyx̆C?ؑ)-׭nh7`Z>}ZzDLpw%~3Z7צf/5 ~>Wtjl%Ɔ,*gNa~ZOu0FL1$MnpOչGk- %Wo"WBݳWy?\o.wDj;06(E: ߔM t>P<35=Nj'TF!&r`ChsWB~rjGPD[&ni~><p\Uq3Svwy2`JMÍfI8K&!IAb, O6[Ikm.&SVFǻ+]C<:wb/S"=h+ܢK|}gD.g.X_nm1F/"{5n~&18 3|!OU'CqW~P؄`MHcCqǜAZYY.$%@(yܠ|SvϘDP8v߳ĝ;w@$]^^R@qxU잽dSn]k'*: 8ɤ۷Ա ׫\F͓N!Z0pJ|VJw Cj} ;0zvUtFZgM5,YTak’l*`ZlN5BfXܖF491YT֓RrnF";VVT:+) )zST2ebRzIV_ l"Σ r+؉xi&)f s 7Pi!j*%^Z`DCO؎M1ݴOtjvE C`)O wWk%ToӪǀzDҲ(}z[59[So򅰣Pkju.nWG5hSڔGȰ;YU涎|`ˏW/2B5w D9o:uWbg|A-4E tzp>>1iyL dLiV}`d wq#/[Dc c y$$- 4[LJ:J0fO5HD6>+\a0˾f’P w=ߵH${RyQ*>*H "Ft0,8g8DnTx(z(CcB[GҿP-]*G/BBA|9}'[TlglYT'Z; j'D ֹɯp]榜=l[Ib׊ \WSٟמGzֿDE`=m5$UMo-Җqi_t/(6pM$zZ=]g3⑃$LH0ޱ'Nk,@IŇrj\\BvYGB,9)lv51iYBMd|ljA8GǩQQjfׇJo?hbXzr e Ր_c:Ĥ)[:ʌ"P'7Vm/.45ڝ!-1Dćfk5(QS^E &k(YHS82@6YyG0atKet̲ ;u}ϊ1Bp5*/K 9'CԬSv?տW710;Ӂ4}̵q ̼l=D2=Aq|~Ϭ:z$>v͓N.}'|R1ȞUQEʬUұɥ yCzG*~%6Qx"jN}#Lԧ/v&FF}bLiƛˏ HWePGh 5v}G7k"dsYmcbed$X+ňt?YϣQk1E^RJb1yp- RknJ?koReQd/h}y v_xXtF<;ʧgyC 0qiiHRKz{'hk W}N?/?Nr: GsJ͹D}XEUMSxڤ%>ަIev{8sVCJ\ kksX]^^iF@{' ϸe_f1hyDɟW( ?3+t4gqJhR̠AZ5C _s8\kfNiATJ[<K~庥僥mdYLF䊊L1Yg"NS>ǐ6}3;wg'G޳Ń段bRHnMnH&.S/e^pA#(dyu[:XYMS<R[]fa) Q"RGse%NviB"s"bMH*dn5 ҺLרXFߵHVE+ JDֱj )cX1Ree]A ;I` O"o<*?6XCK"z_=D-*oAax+ΓSZpk2AP̷T{ 4 +!0wO}9⑉:%xBc~(g`/qfE*A{j x1 D;<k XVӕw.6N'zb#OujrX Ҿgoq+2kšS(wpJY2pbti2F5]!k !uقrxAEt#g R$:E )b0`A#Q!䱆.⥪T?v]Api0T޵:ph0l5"catlŋ3s _|DOGq,AwId0BCh7^sqI?"D&5*O ?ΧK,蝆sid>J99X w(hsni,S͋Z1e5…w\86ȏOս  Nb!bϜ{Hd﮲Z{aQ=Q8X- "7WEKZ 6ZJ6+ 06|3+Lo9gk[ce 2e%qw?ԝ2H~meU,-jtkXڋj};L4U7r$RPLvvvu>4@ F Bv".[0=YRJ,~úԘĎ d *b owS0P#vݼc4 H}7O[ 񺅲9nJ@zhE%4ErЖ祤.0~GЋP̎G^~q#q.sw7Mέl汕BTKX r+z99 |-v#J9*lD) 8e#72S0/6J/ajb'm^/9u=PHKT/wӄsOJOY*"rXK{ϣx?%GmぬQ5 琑&\dlb8R >$p d`{4[Մi JtZGQ,Q.Ip];lNb0F(:B<̇pixSU {0aUFO:jcnpDZYX aoי؊tpdAN+L6ql'V ^}ܚ>L[u_\ Dֳ16_Zu"!}Hv|IЂ빫 D{@/73BCc.wclN*4K~)Ih1ɂ|Yi'bar8P}>BW8y)`DI;v^>vXa]Nއ]pb$Q2(_NTl(G8>pq5& ĩ |NYh{/u=xv0ιc-A1&/N*K~cҽJrvζQs.N9F6/є 3п͋cϛ̩1 3(> SR Qļ ?plhxb6 >!DxEuv˕1CP >kF=ƵN8 +s2-,6Z)gY\(W2t<3mFŒ Vَ v8v}7y1tWha{+ /;fC]OiBaߊŁ@0;;ꩻU 5!2 qg#Cٕb~JND?)UTPL2wmg4 Jna38kqc;bpLv dpFB4<7@Ʒ YQA\@a3Q)%I-:MZN6AbP(/*9%N9dswE4yTKq ?0-7D~ !U; %+bcAe6f A+Sj?V U_7P(ͧ pe@de.sv/@'p{Ƭc6[(eGNP:;)α7s|kϗ; 6c'Aɒ63Y\ew5^|HQOR%S^n\@Ăfi u :0,iG}ٍTu+{"G e;UkR%9RMaUB'%OfA=(yKvA^38~&}xH1Kq u:oҧͅ, |d2MUxM0NSğ)`WΔa0&!:m x<{C+s I:y%4KTj]z[5X[lK=j[s;Y \*;@jp-}dK\R;6SwWOݗ 1NZU^ J} o#|a{Q!9!!GEC[ۑ,h?.1u ou0)\@_,BG%YtI>wVs7= FQ','\WA)9o 1buJu Ya jT<2RiB7%/\IPW>6RR.yÕF6 _-81r$xF}4~F#GE@U4YZrAR#GJ kF@#ڈ]"%ɧ'<ϑ4kIQ!+{UD?7={o VƉ3PZ_ LIg$cCc;1ݺqS#Vlb"qNA{I$.;eV !iB壡ߗX4E~]JY5&w3ӉaۣLKS~ySJ‚棲{Y}fL^"6UkO5o<"սH`|?{kMrtn-; F.py=6%QIq9I]}]OA^waɼ\[#4:tLP_,Bw*V!MM\);󂘞g%Hٜ DIqUMBwځ_<\W~.,XI7Ô<=ηD:rm:TJF撟>5vdܥ %AA@.SF˃qW>(?ٔ}fVI!-P8L$ m\B^~SZiS􇪞:$šmc@00tt2.rm?fƵ?m,q=kt 7[/HAY{u%VV@ծKT o (59eB*2uG a.Q?x?^=u.DKvCeqήJmt{EJd4z|ae?9yɨ$irX[띇S7#B(`E4|A'%\1:"qP hٷ W}"GaQʺ֙ӝ܉!Kkێv.Xf=ӝEm.ЗixGE21xb  ~B3(l(J\GņYL=`{\U`Xpma'Ow4Rhɽ;O<KH|ŀ (y4p>o6nx]vlgdM62<ٖ)339vxP%4L,(P0q Nu x_EOp,`&ZM cl 9D D(_L'Fs ]MofO"p Č'I"3c=!u|&t_91njM\83 oIX~;hWtd3F++h0HL~4~ÒX!NT+6`mZ8EEC9Yw: Bp={7[XF.ӺzE:c4`oudjFخ9e25#[v=s;)Q؉ ɖ`(~Ztݿ &*@Z[ļ絖Z՘İ97n ?BOС(*pd00grǝU ;VDq[=gw`Qvm_LTJ[>ۚg&8)nH)@o?\S Yc*ƙ7,x=N#穭;b%{ ݏMۺW.6oUڷ A"tnDzV/^ KpNBX/n՘p_PӮ\Ed SgFި/õp|' ~ # FcJW}5YCVSn?C&p:wkYi<كc{Qzn5&z߻4=Sb((ڮG+!Rb{ >4^v8@9qw/Īy4ߩ y`$ԼbYnr I >A܍__8ُQ@%Z]`!ѪAf-Mr5@[vS;P-s#U\5D$'S};7Y+wnj.-b䐠"KycsY,d溟 (fIP]t"Nw,:ZQ$bY{rTlm( $x*f%wWAu+;OQOVDfbEfm+Yg$x|ZC7 8.-HY? ii1oTvN06gYjf^Ͽs[54p9a`1D)!1~8 -k&%;ur=F Wm֐.|!z4 ]͘AW=tf@@د%G1 IvϖNTSXEc&su5 h]Aac%&rĥF 7WhhiߋI ޳1Ҋx}j.C*a1-bCClžgmo΂۴jWtyJyB=Y0ȍlٯY p"/z*I~nY̤Y"%\Xm oWa?+"ޗM~¤,A'>3Sq6nQR'Tt)L+75qD#yT*e7/5+C|ROS.p~X#5Զ`Eb[ؙVTT&6|.DW:>l4`Zߝ(Et9w结%rQFCy&Vy}j%k#}ZӧC*cEHGVE3FJwȤT9MwDSxƠRK׺c3ιt@W(۲l Hw3Qy:Rg&>fxo Ķ4K#vgTܰ/#;D0áJNW>6oπ;бIs-sǮ**஭iȡZ1rȲL!sFZKkMZF(jѲ*- ?R ʾx²zqK+Frc%wkJaz%RjαFg//j%u|g?%iDق@riY2jaa5^a2KZ=r%#z-v,/aŬKrp}oI F^2$P@馇oVJjWr{JTDaEDĉ#gC:lRHb`t;pje5~č:['ף*;oCl:ƅNBJ3qZKsWD6@~_ 3;Fbf %sr3RHyZb3Kwi"/֨V(\5Y Ӵ8tH1N~B&9uǰ+U^7o">,D9?^V"U6&_w C@D5/Qޭ!A(0pٙMΛ0L-/{Uy .dVff ސqO.=.#E(L)y U<878E={{lߏCXZ^s9< [qSp:hqq5V/VHLm%_v O$ TjG&gPУ}D̩?*0qH&ڧGV_ݷ?ڵ+c,8($k⚡^N` ǻs/(Tx#fr`;E)Zڜ$3kick]`/0QE ^U8ez0tM Gk[HQ |Πyn)oGtC&X8fW, WC˅mOG/C]x܇v5(w4N4xܺ yiA;p؄әC\~JK0$DqVb.m?=Ľ]eÅ{Uu]C\x jZ fdWWjxv-dp"73g[]j[%rq"2)@f-6YF?례 wkixĐ'kC [OiGyP7MfsT *~{[JFXۙ$>6}CJ^dvI)@bd> x3ngSzB)9V/ǝGjȻ "H~JPǻ6^[4_Feʛ Kf[Aקȯ3SIiyb o84m$Zr;DI]Mp$)myW1*&`?MlXc?Qffq  eD:5AY ~@<Ixq{V@[~!AAokIu@Ӡ[XeoSH##3Kb+s ̉`"cs;)) t\PqO38¥Hg=OEk{p-Y.dʗIyBZZSWƓ}hy;!Y4s1ڂ7s˨oӡ) șӒйQI蕑 o?iJzµ僡8ևzbxZ}F;dqdwqo6ua mʢ O9 =CGNDKjyZ[Fل&[xZ!(dΕ4yž=K+T'ʴ/4ȍ{-n la8mf'(PT-ӋmQ%-/>jք1T'>?B2N.8$qV5EJ9^i(@"ep];5:;Aelu6J5% rVg = r\BY[]jB« :~1ܪ;H"6/5@;%Fw;c*a 3e+7'0,)b3X" @+,j A_36rBnKt|_`?#hNl"fȆJ>RK6\սB(*#2|Y:#*gXwE7w k\Hc]媡&?^Ä1QLĠuꔴ }nIR.WK>ӄ>³֍RəPDfK Hg;CwSi#xCө眕kEĨ0ˈ_rl!YObӎNE`L:)XVCC#B B`(I =H4&n-$gNWl>{яE*u~=`elD]MeLlUhµ k灗B_'y/z`]d2#&{ '!6[MO1v4O[D \[tynvVm'ۡ]a6TS#w1^&rF,ԩAvo4i7P*wv錣Dm;SoV4`aY'Xb1`+3J9,@"st'اELWUlЊ_NE7s|?3۳o1Ӟa*r]R$ 0hwlm0 s(cKX:R \2!p{:}ݾ_­quZtoX;ُa2I|rĀҚ=ʆ>U79 [%x?)$:vy Gb>5渡\[|U/SC_XU,!)|phag%ǀՍDWdˀ|Q·9'SԫJ|3}M"l&bp?%R)7.Hze"b矉]EeR9Ӊ/+(z|34BbYXeOL.~]p94/m;gDy\n B$'F= p9FůsKi' (ob|׀ʮ9,X<74KoXA qd+c8-V)=&.A[]~'c4"-]$y[i *jFmrc!Fik)+0?O}>HK@ͱulh#f:gh %25"C@,-|̄YۂlݫH /Վ( wt&I9iNeKd|S#ڇ8WQրBJ"f_rPޟҸ8p XZ[UBn*gJR ` ,;k̰r'ټ \vl!kPw~>PȄOޮl_6 j|,9~սt{s2i'jfڗWj(< psRQncV0e(FgL|:s2_4c7CvRg"\ؙ`*"f\'3з/M[y_ROdXO}f :5<7;zٰe6'0t`HI!zۮ1wr2 i*|:TPy;;=Prxj :[Ȩ_3~E#MWt5[Sm{}O&gދ-ڰXX*SM͝;fp&6PHd&!C£jza)c1] N]9F5| ~`F3.0ľ&.x8)IiI!C3w%JԵvї́p=" /df^+o],ee`= U޴R;Jǵ:R%TnN3?sVlru@h^.P!q(]C)]RlD'^}J"t*wKfk4 JY Dةs֧S,Jpÿ@B=\1&Kkcjem(G1VĀm .i"7R:.fГB=6E1GD{\u,(`B%|7 SgXaڿ)7TQ?ޡي4L'<:V#Nv6!?[=&1:79)u,4/VSwxyh.OF9#kO&hjO HTh̡Pɤ]jK^`5c`?m/#a_/6gɚ݈АWOQVUNXg`mA!I-!jO.(Vlr/WHn3{pDԯ <3\yz+7sƿiNyWJqytT|(†7^해V7B Ss8 i\Ap,kzCk-"lOBXXXvGkckMO}yx@`hr!Tr &"g-x$$(N&SOiĨ"1VTe:w g+OZAyΎeg%y2Ā9x+nsas>c_d+Q~LTTW`tGB֏faBb0: gL9@?Y g(l5M\ڱIxw4kژ$?|HV~* W¨Vқֳ{X8^psVfߐCm<<*|P%6s3MFz!9O eۥk;=`dt TRQOoyЅҵq3`vFsƍ+YȫÀ<*@"_:6b)αDՈ7L 8 ltY_L|DoU*L}jg ؾW )6t$%N)ѭk̚t)|o,>q܂_fq=xÞP{]QSs?G8+M! ;i=I7 WVf&ʚ8z 3Eq&Af}y;sʗk 6Zn!P>52`$lE]T/Ț 6-=y*%y(6<* ϗ)eI'4pڮ&F_~ lo}\a7Ca^mKy>sܣdzs[*?WuW㘥-i+dfZD ˊR 0S`XS/WOb/~ ءCO@  io9_yA<p ש[;b{w0Qoh/N*Z~ _2`:A}|q_Ą@ۉ"|[op$Icfu#Bx{X㰞@Zww@w|[Nޗ `(`ٝ4uꒂ=k=ٛΧwR\UNS}]+p=S^_rCwMSwujc^PNJ\[fzA~3]O,)&D.* _#V5oa* k&8(x 6 0LȦϧT2+^MU +"M^BXCЯ#|Vh2M>+m2@u(j|F{"`jW/eA16Q:9PǢ`' 3t Ӥ .ܶF iB_4ThE+=: ߾cH6Lڝl|~ȵ $0?0!gcR+='KIEנ|; L6)&to4 Q #q?Oې!IX1'}*֑)dc' yϽ"=w_{.X#/>B?#_G)Dv8ѝba,-q ̜ '3(|@NxiUZвK3p}r+@LyɎ\E/!!ܳOOE{*]kVp.. INT586*LVPb1ͼBFRRpq1'jŢ5?@ޣOۢQ ZP* Q%]oC Nm :^6~ehA w[AO#gnclSP7yɊG: ?`HQv!ݺ֔niƼe3 \S7SP}Ac&Q2>Pf2L⽬EZ1Cmir h;ͭzej7uܪF/+c ͹IWML̹'gIE$`䭺ۧ.eP|,dLvqԅ1c8 Uv?Ga= \ >YͤTv6 D_%V3]Ă7XX\ڿP$'{җv&Ow8q3κs+ ?4]8H4~/`C؏::ůpj]hJ4E^ #)[Lf72JdqQX1v.20&[OT) y;lzKv2[i$ɮi`/U*7猲PAa%Krc {#F"͓&ST1w)M")S ɴh㖄k&IL߇M~91N5:h/DBb=ʴ1 g1!u?9aP[Vky䅭}'RL|Zi>`tJ4<LLʦ6t7:c;]m +R/1"yZnGb*4Xe O^Nc!a@_uXPo@;m;<)j4(g+ehL(~ԩ/Ag$Cаk6,O|B5hUdԩ&R]k2d~,6W6+,nƩUف:d'듲Ta2{M!K ce(f*ip\*u)P}z)_f &珖Ns2| }Zq|:H#|dLO]ImݩN18Xݮ[&.7X>VѾ :0HP ا-=tYqWny%`ֽ>6$Sϸtbxcbvȹm;;bUs:z$|lV#:7GsgzeR`U܇te 082\L9ɡ5TBf<$+!XH~&] ,;?-F 4PZ̴}iËӆ=yeŭ3=M/2|<9 T䚉X|[U0kTըTlMq!;zN1m#DY! W]8:l nJPti3Tgȓt`1.xuTy1 NBc+;:ZH zk7+f_(wkOvw )ģcX͈!n1̓cD s")Ac4V (b з;<8:t|' BljW؏Z܉U ~ͥ7| F,|bx;彚H( 2͡hi+挤HI$=x_DSU%(EY %B51^$T̍~NAiR+6uWN>[^S}ȶ=jaVb[Umi^K) x?_EgZTuD4@ #<~5A% XP{Ja9Ac |q >Lt{?19 3[6$/բ䉲|CZܢW`\/$[`E4w8n SrjQw&\b)ÙHzn`J0,[mē.̊@.D͙dBTҳc,IX 㡐'X8"<9ph7@γH2zoCtr挥U'l z6s]1mlLXEZdz';[Tge(Mnk:;ێYn1X7hYиH5Ɓ0 C  lkpB/#ZTyN+rU'"Iq 9߰p!^KB\/zb)fT!?WoAAlʈ3hϦPU+0MB -d6ٞ3?АH(&uAX 6P J=.S$ls `͆b7 ܨ(%qYè7}.=}lfI_|?[gTM ~/7ވKDUP`HD{U|ZUT:y²OZH',a{vS۬3>*弻(PT!k(zT%5<|UAhhY5jQ*~|ĚYE]?A"*^6u=7}G/W.* ?aϬ(v`6ЮvJo`$nDi &]}caf=1kMZǏ˯2}4L2'ac.leA'%ԈZO5"'zڏa^X$Ҝ&1SCk"ԖEM- Ofk YsRq8aQS¨I 7c/sLq]3q-Lrg3qo+ :Bh KpU ]cFT`t8@kI'~P+C<[J@Γ26څ`*>4VY:z>^+gPRMںڛ`+V d֖YD7A.xS'#z ZTͲ;W 7m#9K#!)ah~2 ()Y-":5,^QAxwTF^0ȃʁ,&ob9pDob1n6*8Z&G*A>Eu꺈E@JBnmK> KgHeA[hо*]NdUS<|Ђ4I vDA'W-Pi6$FC4z+.WggՓwybaEٯ<]N)oX.\\̒G7ҫ3K $0wiTVJ:qTB`0Il{P+ay]ѵj:&eI޴׎)MZw^7lL "4Ib>`dbCDЃ9xXuy!p u܈5[ex= ޚ i1Oޫ\cGD1u%cݺBYw3^_$G ސ=k68K=sޑS%Y> 2b_e6C3~+{NQ >:*uEH4987e_L匛^YܗzQU>DrUVtX"h̝ 0-Vw;> W2P$ooVVxFT<[[ZWA)oKY?>UV+Q%.EOgͧ, ;{[6́L^|o$@VU&o\yܻufLdž\) y?Cb àEdOUIct>^ODNp.\gQG|cװgdjB&Zbtf&[hxŶn/r_7+}F$%#.ÍJ+XΘll9%a))vh9vLL7Gf\0T2X5X~{e& s`DzSn<$0~_.|Ƒ{Eʦ[r4O})bpDɬQL=j0_%,,൲TC +;cKSc E]4XUzܨQ2J^v"x=2-(1?nndBoF i : f}F=EĽ(Bm$l 6YN!u ;3vۘLD?Ԧ2h2m E`NREû_l!XN?f!rދ9ܹʠ!y(SERn}Z~&ݹbb<%p!ݫݩ4"Fxg; \1TM8e%nZro0S"% =WnX(x_2 d'8c=gQ.>uNXZg?TWyeS ;"׉Q/lJ $;Yw+C +bu* c+>?B%sbAVAR{tBmۤeD4ΰV2oΪE<954^X̰D ^ it5s ce1fOIM<>U74\YCĕ~j|D$h< ^5<:NJ:UR,[7!d۲o7 `RO-SRuX+'6ɕhI+)ic!E>[qVٶb3>}O1;3ƪGSHVv)?x8ijae>:sц% ے0ĝeB{ }(F):xU|lQ֩#8Xu2]Yy`Şoa_\z~YbWX#Ģໆ 5Sf}] U-HKIH#J;2w]4gÍQwxx$_ n=q MU.Nkj v`s s[H2tyz7MsԛڣKO|-\p5ھB]oZVGޔ^twpęS6x-UtZй_qy{D|A{ F:d0#;V WQwի/7W=ey #9!B̞mRX`56Lv6ySZ[?h?SWv=Ӹl_?sQ(VbTpKpD kmk, ?N]SկyEGu|.-Ys˝X58T:#Lc[rVyXծR>S&Adfg2a6z[i~6ȿRS>E ( L֭"y L-VO(yrUy,%~9Y6m秨OTz7s>{-vL̠?}v&)ֆV=5$Q+I] ٳó2g{ ΫFib%P6Z7v8F.@vJ_@pF䝪UCӢ;~ĨA*C.QXJ [+P  GHD3fRio/YSʌ 3RD7ʸ7ꯍ`c{sp{I(s<J-`NpRt< Vk(>ۂbrjk&8H 9(}TC:|mT1o]ZsiPNZ>C[G[7!BPiEx0tޛPq3DSrZ$ t[>):F͒)e m(TWh5/N/\"df&~+< ^LfvK!fCAEN,YWmvH*ݺ>I~VO b`R#n'}?R;N>9睝Al6znAxLl3H|0bM4vw>}ii^[dMCYr>YiʗsCv i"Yެa _S%w}ubO81Gd>`e6͛18΃%af-RVYhw]Cvӷa[+he/|&Stًd>&ċ p! c+\eR@iH=R'XRYp? FS H0eOŁ=9@e8dQ`H.mJjoᲞJKNW#= pś6ٖ+0[ˡLƚet~'PLQ}Z(V]?r]߈|ixHG\hPA-F(dsG/ؒGbGⲆou:p@Y ~M^6L*eJ!5<՘&Iṑq?Ua qO$8z)%r>V!UTAhjw3whz_&BWXW\: ~$ Hq{~aO(Q;qLpV/ӲE2Q[=Z[Tf C:] $:Ld\+ȸQWV{i|w˷p[D6Z`bge۰4Dt X-`g{spư*%~J|@lkA_{O v2B{#㺺P&kBܢ3XvoDƼ*p&og&3!{4&ڇ(3`:VNQ[쁟;v1 gAwU$=&%P:E+c͖MHYzz "|te_!K!de=0޷3D"'>k-t%?91_,2E8 %IAOK}R-I +#rWl*eBB>ȻmŽSSa/*4Bm h*o][r楏@^>!Uu6R!9 [d4vyFr A=6}5zQicڞPekeiS>!q”J& >CR?_@MOpq\ˁ"b8?˷KȽ#Л'iZT` o:Nћ6 T͵ z>RQ<"}UMb~PLv`7;hteR%EG΍o^-1vr;9}Q=4ޞh6a΄:x{4 K Z?6UvRsl[h! \ (GD*VBq&%_cX&Oz/ ;vAQؕ{3m i;9cGP`f /A(!,n7aHfkMUR{v*@N RjXibD[V>FvVJ;%Y7bD id^=- D:0g2$LW?*/uӓsVyJ0ԞŤI z ]}~TP CkhT:gy%gV9ѣݺC'|Z,Z\8[_aaQ5?2Ķ#Ex APSK1&e0E$\n{LGuq0vC [$ӣ &L Mo2us5j&ƪOuW/wt8bCrN+Dv= ]bKN[ tSx 4֥!e .MJfn~˔/SFtF3_8:EMz8BO>6o]Dn'=G\*FJt(lPQ$:=^# QvZ w)SZ9#4&E_|J$Vk8>"+o!:T}Tl`2YGvI(;g81[|jp9 NGi휒/P\I0>t7-ЗIG%SUX0M4VDy8G蝗qG[}LmS,Aok dq%y4lrP(Ȍl]wO\>p >Nz? +N}F;o<~ET"S6]œwmPVOHDąC  TK/jdAbԗZVtH-}NZ@8dl]'{KX+83hGW9' $V§=LAx)Aքz. _`B a'zA{plvfy0JwE##IW84mGK%,N|r|H+x\!xi|F3| @hOrҳ. ^O|[uXxKS;cC:/`@zK7u&P(X qq[xW3UTJP)#/S= !`R_7I0\"dWṝBTZČ]n%YYOń+,mO]]1?ApI:7EN;W%]d^cQ¨EG|-RE^sA}ag-0(~*pa?O,!qVj7,$CˆswW <\ 2>ĺ^9bD(Sb嘦-'~ `$̥@\2 b' $.вثCtY~tHaȫ vR("LR :i ,oTG/dFRYTOReɿȥ]ZD)A߯ )ˆ5.b~% 78߸$;(qV_\ Qh8;LP„>R7DD/&M=>j|$>bvk~?Q#ᖻU 9ݧ ^˷lhYؽ2r:3~ =N`q< Vbڹ7~`l=d˓lBMP}tYt*8ESkb- K>kc:谧0ޗ:\.v,nkD$[-e?>^] ^};p:~߹i:q<0<^e ljKWdϢťy8:Ԕl:AlG$NKЛc5жh-: i&EK8j~f~{b r_E5m\IG%*wݗRP{^e8Ii3b qļ?s=$K:vEIM+cٻPjWyǍ}N]M}74]@!wJE)o nҍ`-@>.vRqf@=>Trk'uL GD^;nK(h#RS;tx"Y9XK\%VowOq9zҵݎ٭XHGCnVWө) )=ౘM TW{;h8Oeצz÷Wep""E-Jv4Yͬmf PTQU<69 ;MέĂk daچH&w5ŮNSESFt%=s'}5uǎ(<u38Q&v=a1%qƸ4`œI{"t@ʾ_%Y:.U=]ZoZVa׀4}P#\ɖ'7JrƓ%F*U}Xp;8Elr2s۝Q c1âڊM0,>@?3o2{T!4S3Ér79QP3 )SýS/ev>NOCT74 C4.[nH%Zd7|,{qS_rArE(J֞‰֏u0TrPeچNAC3V&$L78v}# ^?߾G&IYr:mk~Se[K˚ELBNW#q2WlIƮ!ElP U^#?rX Nn|w㸫paCJW?c\D of_e\>2US|D6B€X`z ; t~Y쩱tcpr h9Ր(ZjJg_ZZmG&G2Lo)}ޛLx2rjUzwSkK=KU4 ~ XΤEBŖJVB\+ ǝuvq{u[:W v \&0р<ɮH&8+mljlNN2&($}VVNDZDgҵՅNp<|oT)KSc{2ںd3X 9<%u)lPmd1oXM}b){h5kUuY!b='8 <.~3aE{ J`@)#9oꜢLA(w 5Pa:C(wLa}&$E>L-!8Q -%*I*EYg ;< f|i{d hskӄUӲ"Q\Qf~I3Zau6Js{JJjM0sG% k*5a"N7L/sNkE?MjK/ke4kq~xߜVOl)HKN@* VZU,2Zq"KVOrؼg~.,C EVWo=eċ;:xFjv %<-5b]TכX2X*I1,5 brrMa*{V]goyJ0N|u*)| ֔?r.5*kTZyʛb7GԻ=,x,6R()dF xԃX ax_FoϷ(yڢApx8 @4$_$҃!ă^ ,﬽2lD;i I+S(,Msj%{9 "NVšk ѽxT,c<جۉ$O%4K)Alˢk/bS#ZOגٖ4k|e #R`*o,o"4t:;&{3ݰM]gg&\?mBM}ߩ'Dſi5^^ Mn6&T`(6dOsxwjRp$ؼKғ};Iossk 50u XdyFh~kz%0<3Uw/+{&f D|ΜM6]7"zci3u?ӘhEfaB`Х/}]ӐP-xfâRZTk h(q;NXVw + TCu ZoSO7}dװSEG)nlCU}DCtKuY %-YLcO 1>!r Ӗ 'ڈ.BE-E !,U&qWc7{p{q&22?2t{oGGNh k2y'Dt@bqi~tx1q; Sk@ÅlSJߴrɤ 9]2=c>K6Uif nDDؒ6r8\j17U4B>rʇzHʇ:<(s/ܾlHD>)T:U'Q13LqSZ9E# "jp\Fov >䏝bll߱J`"}5bϤ Żu~"DUt_YYoaӬb?mBS'}Zނg@R#x+*?^z۞Dwиw HgfȹAOQY ~\cB/îoiA馮%,Z6pί=n{6r:91:&,?R״_Tv_=밣zX[9A~jvn~W@{h:|Sz:zͅe kURX kVleDo2ЩF]WpzDeb9{N9oxFsd.[vI>Wms^nBST pl@*0P|7@ka^*GﴅjXC!2T斷knBpN'ݣVO<,zmIźq񌥡0l+CgyK9,*w-]kQM.{x͠kh020T `7ʹ6IL?D-Ms[w|^uB{(6v9P%IθU\jTCqw0@}\Դ}0P1dq'=7QynҞm^GbN 2AO(>^]FQt~kxՍB[9AX1F!6(cnqᖥ?Us|(}pN/%ga\ G@JngvkXa~G`%@kH/MCw}IN_9hô᫶~2K9+įzaf l$Z8r7=-9]xGzwkc-ܛA7I(c6f==Frvf=G5 @zb9o@뮙v0:uS{*۪rٲ:S 7LurƋUsq+&Ȣ$,7 B*v dՑ tܦ*0dȬ#yW T# v<ܪMWU]=e->5q2}_#ч V )TͼNz"~yp&I0J9gcg3GUEpZK 'p|WRb`hzBF4V˥CWHVW sW`Ŕf. Ĥ#-(dXJH ҟq}iM gʱX i:NlhdB)Bxi}jԁnF AC-kPreF V5%e>#(e BC\t y9HsRwIdƹZϧc vta,]S-:n1ayaGONd><+Csզ'VR2#aհk@5dce,7/j5vN;ɝbgr6 rOw2쳺$X]VU"0r/5qe\un`j l9+hvdmBu]6}poyz{59GZ;4& =k)\bksY,?(y>ӾM6`3*2FJyV:o><Fؤ <b${LD<4[һ(:U,N-Izk=ܣm==4۳Fv#9h`bM g^3lrȰMN҃n='_Ƅ$$>1BS{4߰ᴢ4߫uuEhj M1 apl5n~ A+OԣC% lwR!\Bvc!pUr2z^\ZfJ:!;k(a!ܒi rХyxe\(R6-ppi$_?Z5H˃H?Jh(b|^"S`6akvb\,ۘaم*{109 &lBsFMہuw1n%W|A8uTc\ oh%UD) Hy`[*P}.kT.P%?62ۊh+L|] ;bhZ :ffͳ5uxף]9əyMd77^5ohCI u+d :T(6X.T||b+wd»}#M5Ib)SC~7N@?[3vQpxb5!ެH&o-W˫}2ICl` 6 vC\ZB#k]2U̙:Ba&c,i$L dskʢx*Xp:𺀱Wr<1NɚHm@3] &:si6EPXm +:Xx>Pe,e6Tn,PF*sԡ[WA`9&VE}>᭶(g{\r^vY @1cԾ|Bڛgf.lup@HZڝfK,5?]s)cqҐd礯}Q",dfD&sQb{#oOZO@+J5e>eb}!gο{- |2\&rң`%Hf# 8d)+oʟ冸&? K2*m.rL%d_dV/$|}O Vp{ذ>wiWl4@{*0+V]2kgڊEK z#6$̆ѯ:hi6 e yO1;/ ؝9ұ/IEp0Թ: 3@-UR@N L xvшZ Ss*O g _c!RMY̑%*;CV2oQ:!ëؘ+Q&PdPZa 9Ȍ/%w'iıB&kU`}_Q2P,ĝ,g{Rɠ?5R]liX/h6D^ot_Ӛ%[yӾ+M!xA/F<RkÛ'h~$,X;Bwb|uda]~,?*bUZB[A໹-j!Ȣ0U;hpd$0%xtU+Wx(yP(i? %qڨCryj?t97jܲ ~"M7YQzAVE24!G4A|Z߂~[ɖ?4v.nHz/GpPܶw%Ry~DX{MjW_q#6A/.H) 71?CR?DxHRa N48S-.B<єŤxG \>չYl>_QG3*,nH 8l&K14woXLW\M6 |>8MA"{z>ZFPc-X*(~F\D~:2,Aۊ)p{' 岤`Ϝ;_^kqhk( + >d ,j^Vn:`=˄9jp,؆B8/ɴJ AJ UʯBr:xH6/Fv<!L ϣc}o>9/S{t[#2Fe  ģFmRLn|UX FlT">STn^@]` g(!LHzz00q1) %ο}n6 vʈlրC^7&hҲ}gijb)X r~0 kА\J{͢2fp ݖ|],6MzLk=HH|Rxî`|ȸ 7i@Ǎo=n&H`D/QxNVW2A8Cql)lI#$)0pF[ I18M4# 9Ab?azYL{Xu'/OTg>wInV¦DqXKdrn3v[GU^k5 z@5=dR˻%JlՂo-*uL;bcC4@Rbuҧ-ߔڬTxΓٕzq9nq-z@1lXsl89$,~u+A4rn@-JU[z${sWֳX+9m FAgqD' hgqɪv] 3]Rij/|_n|_+'# g>* {aH;i+U9(iE'CU K6l^C<>thij5]Fe&;0gY}{s!M=2U6PqjС-u7Kz7ʄ8J+vp@oI࿄%*bԷd-BhL~!:S&F"-Sɮ'hׂI}Z!y=yu9=`)d-vG\mPԇs]\G>qJJ LKr:@(vs}r' C nʁ1iՓq~ wFWɧ c:gG|٩^$Ȟ"lYN ^od5Q9YVi^+*ouAt"wDV@2a&g.n monI RphLBlf ?YgE8( Z?sh A;Q.8e O5(3r8nUHNqQy>W_M>|7. gbF0l&jm 탵7ZLGcۣ-&Qt+s^|g#NeAm&d;iТNncڵ-+%GI/_T+뎍WBZV5s!/>"Q/OX#X8q,y0 QwRE knے3?Bn@/Q0*llF9q1 3yFgo17ᕎ %ZffQf֦϶+iHe. 'JvV~[ آ {! VBS ̏maǥ`I™tJߟb7@s42 PN3H1k1zpEiAw]M1M &@yBQVC\"?[y߳$ Cqi\D{*TH]G GqD(D'"\@p{|9/f3-84زJDΥtS CH6{OK @P ʸ+B2_pĚ`J[X ˴P[o,ěb+IGhn$}F8pM<7.|x{\Dqy,v] ;T*hyhW_!E=nXB~җdO CTdb:*L TM XqE媢yks _\n]/(K(I ܐRrD>EiZ8(ZRRr>;/#?;žɫ):3|"ȹ ! 3CvUWK.b&E0; 7a ?7}$ Ȓϊ 5fAA\|r%D;lAlTD5xuR[HnQAfjN;hg{NA|?0ϐ|Xz"kZA=#l݅ڱ s{#d LxXcyPԃ<5,bP>G ?Λ'tjCCˌܤlWzq޸/2 ٩!V|ÂqΘukO([ 4K5Z \0WGϠӛa|2(S+L /u*|BF3-~h%a6%$gIߤRaΞrf7B[ׅ}(.bπD!F mb\4AK"wC9jV_ch,> ulIJ8dҲG>.")cgoR)R:~9 =Fsqpt{IΈ1ܽSX"Ȭ섈HIA Pp!uH&j_uƨ:z$|9Kc~:`w3/3:zCH_:LMv+~c+->BKez Ա偤>-Lj0u/8q ?Yp\ SC3}2a-``ϹF#@+] -3Q̻>9P{4B^` psKҊ*fMeLߤ`=A?^#`ftx8 MEv8% \ܳ_[ĬD\@TD-r!Od]QPl7"c=,mOC8%x {+ækxϝr)(Cr$[j09rsaןTfLpf/-\;:q!>],IB=lO [ U[K'qqzݼ\URSDpl_Vð:&$8`ViP}Kl#Rkr^s B6×A#^kdT2^:xZB0T;+ &%oYwΒk71sCիaz*3q':WE ^Hawї [n劃H;En+<|`-\ ܢAhiB#s] G$ [T ${Q;T0*&"HHիVFZ7]~,Usk_K&ۨnP#6qi;[Jw_lR.%<+B3^Z5c *N_f"wKK&~90uZPd]D$)T=׃\5G Sw_ q7olb\5TlPnꠄ{$R$ӵx ľш@/GIXu*>Y!i j|;Z ?Dș B{R^lۭ3>2`o,ByJ.>+T;Ҏ,~W42N5t4>OtԘ2#:|7lwC KGKuKMONjot7MCL{xNLx z.šT25 ksNEy&_I +Vi^5CظXQgҀO~T(yDM%^~5%?p$LGclsK*g~5b:9lh td`@6WY/{@_n0absXp+yYXWoEFSɌk{ ɭgꗏs%jAS+3?Ίw-AVⶪ㺫|&.&Qguo}`/MRjRH& NOC`āڹd׿qx=vPm2'+X;?aI!)PyYrn-Ybg<7{+F+/r@0e)gJ0.^e߷bt~C6 JG<8s% 6UU$>1en I^wVC=C]_>ӷUvJ'6Yk͕Ig9 +5pO&'DUnQOyk8b u\A|,bTTSz%V#FW`>7wiiXZi FR;hsWY9PnE'0&'mi8"vpUǹDLWfa,͑)g!UsoaXuJ& FjƊ=YBh[tN ۷KyWkk29fB;y894{@L3s/ң$gKчEՓ5$uyl_GO% eGlFZ&!9aS@w/mI-):ӳ#aYzVXS>jnc+Y||#7hêK[ Fv^hKT ^'ZlHOm/Yy<UAlbe[>7q|Y7rL-|@K4XG*]\K*_dÈAaI^,:h֟Q]J7^{$G+> 1(\V 2mnKCerϥ3 ʋ@(@ycĿ镖G1.Zs Wm&> Kſ,t^4 ILIoD:o%f%~YRG")D>9'l` JeLYсp-'9zH=?ڲE.CKؗyNrp*:i8\}d>k yiJ+"A*rW)4ۢ `Yߒ|&WGb̬asWvcp9H G6}bli;dpI~[I!)S`9)Vm'CɨTNEe5 WMdXc%r&>A}E.e~ť4c%dpfM:Fw*/Fd~hQ?cy0Hm,2>{LM !#A 6F;[JF=áhl@%aaU9 \aVxrꥈӳ&ԡ&JKM_voVaућ)EfXtQ !qU2ߦ86Z_u8|*cAhNxȴlt+]T0O tX)د`<;¯{F^E gx\ױ}6]$<75Y(QMܛ K ;5)f!2u 3%|^F)Uk6coѽ,؎*BChF&p* >đ|"^X.{[}pxWPWiꊽZg" SG8-suqDs*ۑڒXn_p)_Hʒ : )C[TפAGa_XYMW^3Tsla&x1!MGr%js+&\FIB}=LfYtR`0E3ߏ]ldα&MZDOq3|`1]BNc!N4tɔxև3& +9U.['bW ޟ%ё0I> xyۻhxOբx^T6-֋A/nVBccUV:Vٚ~Pu gov.j2 @|" moYU _[J-$ YӓTdTSwt" s]Xr>pI CN'^( {Mhb`X69-?Xc> vj]duB=\',o"rʴ%^]$D  ؠ-v Sƨ= JgGڒh{h6dUe2ie[yB9٪Ϛ/$V8m/c6b?e8YUIT`@˥,AkE#G5&Ev܊Z\1)lvjcnǀ6p+"|cZ2A|eO i/:plwD!dMSLR`9&jL,Ǥ>QL_ `"taqY{OUgQ=,V/ǖ01)B~DYA:VDz"ɴH\V2|&6?EA?Հn8GK`/ks%Rj V FTG}Mm7?;6S5% cG$ r!2VN l:( 쒒??%8:F[x\:}B곎BuSQϭ pG. ]EP ֑Ok"Sj6ACLd̯Ilj银]0؎V;*vnѥHKlt9!cVMrwL.H zk9O_ۓA%:DL`iSZ‘Ƕ*d tN*"OtIDtX(™YSp?Df*{ErsY"ɖݗhL; l zl %Q_6< {jd<}Σp;D_o-߶b៖L.ŷUӟQqg"_pcky'MVUXVːixbt*kH\,VP`,EЙ{B BM7|7AЄ_,3ɝO ˧;2D퉸LI>П1iIHʛ#vԄL TdD7 X5L[?C7B5Ծx6^\yaY9+XM A=jV.r,!pjY~DS$+z-"hk"9p/(']Zwnտ*, (bޑ'bK5anȀ6ć`z֡&|.5wBpel,aʆ,q/Ra|wDF+X$vh @Æ}ߴ0K Yw![s]'}(}]ecWSG.1,4i.:*KIϜmgVl`ٓ z`S|˝|/dC|xz\( d"rnRH-7\[oGA gM?IbF>D )$^LM}rNdB?_^WֽlRQ`-|: f#ɮ4DCS(317HX j2%RiX4Q+FMYJ@T cspnrid.dM3G{]߆d;l3F_ =~ m-TooI׹Ԃ}>io ,!y䡨oD5Kαoe#M޲LklNKۘ8w4/RJ>q7PS+6昩iXc:=ynn ˓bWs4 )?#:9){|i9]P"MBǂ^mI0P8N&1fрPzr9 ^x$3.l#tlײe5\73)-{[TJMψt0{uYآ+)DM1ƣðycp⻘Zr`q{pd2({)&aJn&O $b!%N[WDRck_8#N=Rf6r(|[T6mۂ̡e`x&$MvBM8j "Z`7!XdqGmD nփWWg8VNZi?6=TN$ (SRͮ_ AHRH= Liw,92lǶDӥs1 !2ee6r(:%Yn#+ ĮG;etΝ'6;Ar]`4z wy? 7ۓ :HDGd^Q݉&4R}0W.UQff.e0g 46[7ڡD#~iւVZz[&;9 Q '0Zhk@4hf AO)OkP4%ՎiB&gp[|pN[; TL " br/ҝ"'{ZQke%E@h5gnt\ʷUBҶF疕Lw1_C0tz;vJ+y.V.X;4@Eu]On;lo ) /6X6&IJ5V tL9ͮY*C:3O@JJ!vcNT\hvΜ? >f&QaV*7=>v"\%.3xGG5B@vaq+%3'8JȞ1GCA# b3r:h>邢ߥ#$O߃Q0^{4PwI"vlˣEIC DS4Ey"=7g Cxؾp1/? H \ߵ޺JQ4<0@0--}*b~cHQ0R4&ԨyKSt~;"mP|ITS}yiW%%KNѭѨ`WQ[3[vQKyBZ7䐋)8V%),GxI7,j{^/QwJMVּA>T#=R+dbzHȈ5BojXac>$ <;ĿkA̯D=mm][V ow'Mc-Te{(=!!r_ikRAkCt 3+K~8^ds2 swztVo Z9E]V<>@PeM.A!oq8SKK(~B!4xV5x}[ۢ)V7Ռ7~IONmk,&B{^L}'=Ƨ>7#(zFdB2rb`w 1.v_6x PEJz'O+'m^ʹd< ;]{B0D w fƪ8w)f{Mw$x!1#ʏAm 3`i1ZʫSXFWb9#:l-JJLJ6MJy'vOI{EIيm^e ֳOS(V4Xc?ipWFMAטNI$#1O:8 fn/l^sȷTp%uSjRvJZF&̤u MW!1(ؑuD`W=hp}>fɕW:$-?x&ɣXsHv'J7f2j[hNF(8ԟE-Iǐ`S[3^zGv+̓bz!tw/ju}pVb4vA5a:'|RAܶ*Ԭ'%ɼzB3I nx adS@vw|Dn)C+Ŵia~:aQe.[዇FS*70s> s@[„ٝ6Q&'Xtq=C-IYvOR7Tz DX#BV&,*zA0X\R$Uk0s9bAKCIRn6C(޶nY=qadI=2ĥ&)By0T(JAY#[q>ɸhjF P|xE'Sʨ/wˌ1ETNm?panY7H ?r;z8rCkg^IGH~jnddPU%sF>NR?o$f~>mTل=o@Rho\t>\oK?Qt₪wzz9ӲvOlzN&{O|{!e Ҁӄ[Y9%/0yT)a:=Fr̨[4{$y6WW֡ts!sXm{hn/qn–?FhN+)h?:1QVʵ(vя7~d"P@yf\dֿٺcl%x֜;YǿJv$Fr#s`AV:&MwW=KNxJ0Rb{;fMzGWk8\g0LEbdAPM@iޖr]%*-(ey:b`b:v(آO?Uf Klec,YJk?I^[_}8Œ%L.mJ|,DRSD'u@}FH[&%S{}]gw7RI[C]s#N+mI r6J,_3+;n ^#0ko>yd /& 8>c#6C* 0e% Z8@Z]ƎJh㴣~1Qu/,em}TA*>!Z/~ӟyZ&nCYkHcjv~ϯ]!,%}< '_.=kI5|<);8]Gg&"&ƊE]yX? =PՖcxys8TO  pQ)'dw%vxCb8ȵ ^JSdRiv<*HI̶a;JطQ-!eL`\N:$j= ؂ d #_ Pt`)۝VϤ_WT[-\9ϹE[W琙 b+[ F|- ]xqIDZzǯ(]O al=2>DVw PR H`ur3%fO25a b #tRpK:_X t0˸u* Yh2Ɇ'lW:ޟ,_wA/zt&Szkf&w) Gy‚_T57[#U%FL}g:\2d8J<gF):k31wlL $'ZPh)گ(;HTS-%ϊ3|aw-=d |0st Ԙ0^$p&tUgw5kiʱx{mg8Sf}RC1Uμ7D]ɖ\/)p: KSy>;X^Sѕ!ȲD\M~t j1ˌG2ɹvکvoITEtg$|+DsNx i dҙ(uea'zVK=kŨSh~0 ?l# va1PG s%hő`$'Kehu&N.A/j8Q(uɣlLg0T ,fNO;Y7;bM9TrlZ{]f$W8HctZ !]GA*R'h~Ms2YGF*sLMsp0"n| ;ʂYwWyoN|,WWNKӤzJJNdsqP3] q$;pVR.BzTtIJxx'c춭Z{~,̓HqჟV36 .6 K|b5j,_.TI"哻gvY;O(aUOZNw;;œR GQy>9T,>I8TutT 64.ہֵ?(*X$^oVE% FZw&2I|G`&t'PmZ"h)_ju}a0z"~Ϫj7otAk&4&Ύ{ƍ)o'Fu:G)Ɛô4QVJ7XL2fi@զaY*@?KõIk#[%֖Щ[#Lׄɪn?)R%%+~N׬Ik:J~‡|Y2~*_Grޞ|u ޼,D h?W }.E鰨8Jk1"JȉI-c ^};q|V(1QMk#teTd75pF8|#/)KW@9X\/n^n>r] ]tgX*{ M)ŋiw>\Ahm?7RED e}X-&y>JjW6R75JS wu q\,GĢZ}$%\QTh9Y#Xb.8IkĀ+i6|a̺W !]@}jʞ^Ě6n ׬6wPTՙ@!E?퀈6SQbyH' q۸CVj/~`PJwK"9a | )\& ˦>պ3u'/š~C8NYZaJrF[6 c3ѭڏ0ӨP16qBf;Ad]q( @҅ ;N>Qa"&RE0|B'F vT(V0e^OX3q7& OF2;h ?cЭVd^ ;PFTZ)D#yʪ,Χ k zqθ%n4bi" J|DĽ$ij4"o5;9 k_?[ ׄaɁ_]=^#udjzCLt'!Cd!2cz>M ^n&,|젼$VL= jd,&$ Cjۉ̾,_U ]rs@>aOeVbsViL U 6-rԘV}]5 ,=y~Y/6xU*vjNr[On570U;=nmR_Hi(띑s8E8 Q.ā7^hSb>K(;[isD:٦'!SէAv}%1gn@<9RE[@a QEc+oc>J]ҭ%6MwCXÜb$zWY^[ީ4~1g}}f3C(c;/_Qau4;)n2Kij8V4m+zˆ-i=$O?vQ~ []T8:m!n~g/PN;j;qXת8lj2f1D$.|$}-h2p| GLop~ʒN82UŮq# >Vj{95;b`qW#5! Fk_fmсnȋ[pl7 #cNF ipq L*[BQOVx=an }s8}7\32@,⫘T<@YJRfG5J>c@;]_<œoy'/zFSܶOgf%C5Yc( HvgF0Bd&@p_b_˟jFHFV3h 5uDЪˆmx`ۤ0540h@i_R|_Ũr-u[jj PsZ#!CFqpWH^s:$(eq/,x^ҫυ+bu( ^Ǿ]Gh:oy4y9)6dI|>i1`F3 %g'<\!,PcR l#f$mrv?k[\NwauCQ]n19{~uͰT-@04K 8j]m |95Kko;5r7'& Pk'_Z_ڤ]P ߊҮ!aI O P|.Gfњl*k'4Fy`uMƎ"BЙcDp+Û&OIJ ;f YATT:ʃ|̦7<5OյlPJ9LPvs;al4 & O#P@)Wq|m-#ͅЪ,RgEK)]y4܁8|3?ۦ%w5\.]svx7*JdBA3Ulɻx+/t 657:6_L~*(.hz|#^UƕJ0 's(((=8 Ufz3 匇*Ii* ICNBAlk.ppگ3QspHP٣k"K+;sK.8 D B-73#ĭ/T.܂*ޯÈtH)Cv$}P~>w[֤aTwW"%;㓹\ܧ:tܖs{m [dž0Lim)yriٕ ].L&#!f~+'vgedZ}[Mr,[+pRB9Z曎g[W dy1H[ ־~Kxe_A~EƤ sfڧU70'obd΍ v$ Q?ɜZ޻tT\;iёuwV34\ƖiXJaT}:a3k[ .p=!eH};ÛYtJ7H@IDǏ5VB X0 &Xy,7avO =/Z9Y(;xp @j3xDI"b'Y!:xi8e8oɩa'o9PBGnN(&¶Fʁ92UA#%Nu ,pPցMxˬm]VD9crALjKs_LE<YCy"-J ]j]0,:lop5#Lot}d̿\*sw-JnjN{rؼ̕}9\Zjüg*yXT$tX& K}f4> AޛsI'.AEȆ)k#'%TAu@ੱ̥%Exdh0AvOyH\'sGD ;L;"p?"/gLEAD\⁔f`pUh$`(tW&?ѠVؘ Ph_^-g5pJ;|6Sl5%^CM9v8:sXY=%#\Өbuqg'FJ OK}*v['C+ǽso&  a %1ێj4pM;n_A+zlۤS~JT­ˑ8l?=ďpxYx}Xw!cZ%~x[ 4"_X]v|NA!N'C_Vi4 QK_1 7hJV*UGCsFȢtJJ0YQRĴ ̡I@,Xd `a7z9b)iq{;|ZTw9&k\K)KJ/L`X9p9ELOBoMyjy=-$ma@uGZ~WtA9)h)wnOZCqgE{u, i}2(YM%j|5أDZDpz8V2/ČYnL Zw ˔F썼 +R~*‘lvᄑIX{ij\Tx0o/n/cl6 ̚/ֳ28k$G%WvXUaIp[# לehq,#';_"#1LI:{..pEF0~HܫK1?i $.#,7ߦ4"Si1mn"$b )w!=WPgqiL685)74bWـ9-WzzAUKۺmOKk˴骕>Y*x?Zs\3x$ԆW`q\ O@spDT(p WG ׆bryC$d%ҁ&C͠:p񮣴Ei{VU`12ZNdW"&JM7K7B!쒄"NxM0>(nđaa22{\oo{:n|VCXSj=ىR 0,pstk9acEDJRA[[+'/k-FNR!'-e,:8s@>C:.+Ɣ59];0z{( zg+R FG2azݨ1ӱb⹇^7|,EŮ}NRE}s!K~MLN:gl2Mh qV,02Z{39֠;||G(Ym] Cdz&ou!'ŢM0E5ɽ!w[PeѴ*?yd_= xS6|Q[Wp.o gm=i?}Pcw%ރ.T؟%B\؆и OU[ltYշwd!Jֽ٭Ҝx@% G37hJ <U" bD&pzdur∕{?%hܢlOEZc`&9WmiTҀlm sIᔭ-N,{'Ag.o̽l[Z7FT\t s:P^xȩ&:C9C3ulvB4ۺZcvA":k>QBQp?k|>= s -},0Ĝ_.l^W#yn{^Xzh8cG{=wq iתO騳"iӨOJ<,5l &bp|Q x;]2cSgk}?Ml }7`|-UfTrG"7z9p tҎ $8~r~l?O^#RW%(Bf~*Y8l|WA^TgH_O\${W~cpX&Q'稲OStzci-7Lǎ#嵥a`|eb:| AXd0R4q5dw[P˯,TdkͅahvP$.6Z\r\\'K} "mZ߬]pdMN暩`2զ18]$غl@~v0ї $(i>? wS_ ZLǸw1uuuQig$S%!>{&)`@a*lNb 1smr h7>h`V$"N?'^DfiwbwJt)U Uϖ\ q:oKq;$?ݛd n$/ZvsJ-^ٛ樌Fdo; 0m%R*IH<15Q:Eeu.0C!dOMF $Xi|yfhoS a៺x *U:̗s#ٚQ((i3;7 Rߒ-13T]H4|]3:,MVm,}#x7ndv\n,c֔ov? )$л>G;Q̨/0gT(/[|\ SD!t6':D;h~b^XV/=5oho&_WU։H\d'`45nc;:R~t P tpȘ\SP@}?^SUG%!)>_j3-֢\UÂnD>Gd]@〒ޭ~~9E,⏍E:NhPr_TM=ȺMm?^r^ ձzraJ<$%l1|=> MFsM@y|< HoK԰NoTJ Bic#0hl-p \P Սk:$6Ў3\ƭDÖ{2E>WN 4bKTP'c=Ď^G0`/qhi )`?}kw7WW gSp#PLX2phıR]RY'24XJ_upAe ekYn^T&i7zFTMM\~WHaT3ydP,1pFDmMKӹy4I neF@pLVEa]~ ObG ՝;aB)u-ͬS3u5-}5ʂU]t8fCDWT`If54yj[}9y?fm~@Q(% X[ 7CM]D@}`$ṙqS7_3M5ժn sɇŖ@:12ua]A}ʴQ^_5Kcn5'9? Z 7 ` ?#9)xg^sMae8N!%MJD4v"Ґ P:{7Ӈ]KtwO˃8 nl-EH,Qm"+@"rbK %Q&ɱ3u:?ptPC=.C;aS rU,z(A H&k֫ jAgRrh9 bGH23YXKFkYF9xt+;cRA}Qmk|=Lcu9WQW Dž._&p!5Ró]Ț{sT(˗#3?/"݉T4TMXoa^sP*~5\\h*d;wnk 苨SD ^7ĜnK̥> DžМ07^sV{2R6&qJ9֫ƉH`LBy@sYIШ{|^x/L7.w#LJȕ$FZy/B(;sohYr'ilQ:(VIBN/aNY2l~qܯNG}Z$#:o= 1 |B-$ hot 6vOӤn~TvΫSo`|֜6}I>-t4`pRh*ӎc6 kGf-qz2IN™>/%#;\M$mS}AZ3j] {wׁ*ъ9K[!;; 'axL~DZ0}ůvv2Z<'΄h:7=W_BڽA]ޜ# iQ oS1 Qi#hAF^@M}y9(^̜h_MU KTC:'8iSAk0wLНyoca7$и|#J]4aV5 -)\<%g@$ByLI6ehͲVxe`cLϜęR^4ABb9*CXOһ6>p?dB7p@d+WgyժCeVQЅ&fvCV-^~p8YeGGOqW"Tַ?}vɂiZF |تL)W4G^Eb \7#1v;QUԨI#;Q'l…E~̎R39HO$oa6_軝LF)H_˜CqlX꜂B[46[~RD l:,ԅx"x< TjPaY>Kٞ`K_$yB.WpGg߰}MW (X"0.gQ򕝁R=hgcL՗jM$\cHp}By闼}QV<)s5v .f3OHY?>-Mrn!&p0h ~^1Ve.|\JmH1UYq3F9Iyv)h`P{kqWOMg(`tSGݱPX3gjDQFM:͙lJk+Y0K2p$nɷ2N9)ްf tc8bτ*JwEHA<`^uTUX7#5"-S4qHv$=!sHj81Nk˕.Dw'|M@׉xk#T n" \T eՅ.b3:y("TV}KzTB.7Ozѿ L175|d-i-NM>*%s1ESZh?R BD0U f.a$&⍬7|:N3\ cxh6>xKYr1 }Pg"  S"/QdN;\QGy=mXeκXm _{ms&{?qQQZ7$YoT 9w!l?`ER[X;L{2ZM *}8&c,T17L.h(ԘiIU5s:`Jl$&+5^*/F6<\oEyq9\j>N/MefTG~茦Tsb*Wc@>ʊ1ÆP9T&+ڐr=g\>z^*M 5 Z <oеmxn#lH'W#klf\cR>}a[2~-_Ɍ&% ȶTϿGZfqɟ0%s9\w&rts[gxEBM`qKQS=rA=H`9( ɕ^h4,ueի`mtI2Ì0'rR,t*86Z]!z #oǼ[C϶^}Cr"y@2ƼCYlj V04I gA,P⌱d }4X7 Cp{^!\Az@5{@hy>?م{>23w:A]lBmr/hF{׸ZI-N }pҌa-m㸆vDiҲ!E弾+6=pըD~aqO/a]co}~_,F^좏ɐ]P#VN6=@T(EhuhDFMYSWaܫ4wtq4,Dh4z,͡&?;-2޵y6Z6 قZa26,~&˽{~/YeH?~sדrM~-|89l1ٝjim_"3c5ߑ*sңg]dnoP{BXK<#ΪE[r"$HvReS5Q+B =p+r"}"E=)stMK I;!# MzКҒD;7i߱TH|vrH؁_*K) .J:nc_a/,EHu)|Q~gw'r֩[zZ =\;ⲯqo0hH maJ%E>ϐ њ4Q̿Dsۘ^_ix\Nhh)A"=ˍ36W\H0?.9(GUM75HLp1bJMɢf 5"JkI|4 7AcEQna) 9kQP5 m(Yn/91\TaiUʭi%Ykin* Ď *הHdu`ڪ LwDoɡRUeo@ʒɩK1d$E:k=T`J00ifĿ$spHf-Y|SwyNFb5z^ٚѼaѯ0]IVQPU n GɯB ΐy):FPm"=&}ǖw7-l1(0s,aӚ b1d}rmߔ,rYb_%?êW{'33_v$MqJ0/Fg6 G=K6h_n+C??烬 'J="B_6}5G=VObu(iմXm(n>JEe1/Zvv+)TFy~f RE0/nkJ¾8&f3`CoA:j1+(Ȍ۽ ?OH?h HD|TcCE 565xg;ͧ@QC`%Qmwn{Di'O5&im2|̸6;QcpnNSeAG:pY*u~1 @(%./D87?ȥ/J⡵~$ ۙ4'$s7''1}vfm3-flپ?mKX.&Ñ1J]gsqR;DsAk"} %j]Zюn F?q[B7x?+JKҹ@ $-$t^{sUA\C4iڞg7 %s, \]k0B$Qtzu=#s<3YFdhxiBCֻu'?B2<اM.?װ-OA4`%fk|n [yXP(ATf)oIeʂ[96.$# )W@kĊz  :Ii~kԴDsaCc`'MX9f_&Nފ/))´=Yaij9ĒS%)v,CozjZ*e[{*v-er}߭Wخ1">dߧIk\L`慣Yqr ߖ2j[& F2M[}˼5=GS^G#(٢b^I"`qC LISC8 5D<!-xl yUcBs~Qò %Dn.\1;HkT%\Nb8(at %R G=QÅfH_RF ?[1 &8nysGjfHp*-P}s9!@Dwq;m} \`h(|chݎp*[[99)baҊYBeX#~EBo BS@nyC~%JU3/ PSkΟU>xL+\]vU/~]+;~brltH@"U!-f٬S:tY5 ɢqj12z<< ÐJ04X`jѳ8"&-՝ |o:}f΍dư̈:\Ѕҽ@Bi^é nJ5SR9>8']<IlRנ Xs8g(IY*5ABNET8T%rgDPHb)L60[rk⟆z7bg'3{>$-?/e~1oG-ZbUlg6}}tb\7ذyҽ<8=g zun.6P,uAU9Cb,ʭNᲿXExH_AoHG5 V0ۨPV")qgZTFԐ 0~bFGٯ6q5ٳHik> ^ľI̚ϒKh ~Y)M!Jj?{~pq= eDZ vdDi?X 62e}+ӎfvyS8\|-tck`(~;N).K6\g1Tj_*B]Jk3ʹgE20PG<8/2P7EOWE{ fN- E"PTO=9<]cqMy{h(O0g`_8ۛߏJQI"@?_8E V6k+t960ah$('>GqUdRcc;X-ͦÈ()jɿ$8nPjf]crh,D{W"VV1+5&p|"SYp,"tcN`!+]x9j)%E$Nҟy㺛͜ݼC&́@xPf,0]<@Bo&y6+'P|YIzU*(g׬u-kNiYJDA(\[V :nvjM"'s)c8!iN,D㤉,H8 :–vo0ׇ)I?ʾw4%g@ɞA@Ⱥ4?y<CVMWɽ`QZ{hoϖ bY6ˋs˨K,=UصF?ȹ "d'պv2Hȍ5+]5+սEŶYv̸TmX]5˅LuhlOg |3~]"K<',С[b ^0׬L鯗;?YOJY@5(N tz^O(^k0 E>fE8.\VtA@WO=+x9ƪX#7WR,sܴ([I&[>n|I5}Vr[3=Q! o`FҿW}ƺ.8qc ;lѾp妓hI̊C. tߺM r]oC(8eַX{w1šɽ*VE\ʟ\VJ]fEz 5#!AtoBk8&kp#܇7/¯kX Աn*6Nq41 ,W],ӏθPہC}qS+ DsHcꠢY<<|'l+ ;-vr?ƙ4.|{Rѝ5>)kS';k,W4 Gl?Lx 2w2ޥ6JZj;L4,Cr[ќY3֮Ll"Qy2e*.r.H1`w4\cR}Anmjv*7VĹ5,[>GhJa׋āveT4N2L!Zah\n5ӓNl.xkRAstlm`w_Jƿ:,.˂ܗ[QƸI^_zHgqa@n.LY*ȃD:X8yq4vPV33L]}n+2UUVz"E9k+D:>l^1|JE[R&B/B(Y~d-UpGv.~ךČ r}h=%P]$j ]칪M)xI zbOY;DLNu<,cGΠK؞1]֌%`PҊ .P4y4asE{Mup'ZGy|ׂX0, _lǼ=N{ConzAR =@0oQ9ew BĚ?im&G AJS3uKa\!sp(:IpVQ:5F39 +hdFX߃(etp#GB+q,y1뉛;pа;!3ߩ_٭mͣK@4kW(uf u\]RAM  /d?i<{:6E"Kd"bx0Lj zD}[ٵ\ pݕ6b$C|Rbb]p%GJʹ'&ECf, MLç @|[bNgl4s<@Np'B+ǖRn򬨑m7ңX$rt8*I:&0[0{WE?5Pj }C7>D:豣R$^QHѐ`0ݻ]g.hwXwB&^mU|jƟIɄ'ޕcCsEH9^6\b,1L5gƨoRdY_` D!aju{*״ &˔ϧZ>S/4g@!R.g ʌYꡍ p9ş6`{*3Fh:ZG;~Of3C҃W >+Sϋ &c!|j3d1(k-E֫1$f'F}~:QNРqG%|}sH ƻ5m#~qz"w߷u(vѾ OD_=8EH+G/2 >e?ґ Ԛ)2BNH 3cƢ ;x?d3F.f'*suoC@>>߆yaR3c+ ™rX |ô n<2huN? V[!19O^pJ\e3q1'-54}8f,.jo~kkYuV\°bja\=rCx4(3T`L鞝FJ -ML:,}D 30AlL6Tsq q^FW9[ >S <;\KG!- cv"oS%V1m0Ԟ1` Sҽ5`/HVVԚcˏf佯wdmNj-D /H{K b9́wTȵ"ĘHJg!̶]=&^< 3aתּM )LM4ę]G߳DApURJ8gY-')Ppp4߰\N=&b޶Rj]U2 ilԩ$1-Cˑ}Y||aDc #crY:-x[jAICYMevܷmk1wË)E:%/MN`)u-Du'.r q͐ZP}2͑XzN 1?$\?knVC Mq6nڜ=Ym }ę |opjr姍LSWج~?`Kxͧ&5яo޷{߻D[:+"3Akya5!V[ݔȲ;"H;]8Jki%&Ҹ , fDRݡ2'Jm.mW78ڛggb ZrL,ψ(5 ]1TcnxcM= R{C(P 㝙wDz8T*Ln (LL?Z+ :^#ƈ fKl05桵0[d@C/^|1mVKBd㛃FI㰲-M5- Y{{3Nw`[тKXe5[;P\C\:N܎`k<=8/RBxhBɭ}HAo3Pќ5Do/cjyZ6f1/z9md[%9!1488khPU#ۑR&F*x,Wtڱ>~z26gI*`I)Ye綫 P3[e>JHsSxZ{Y n@cHqƙ`i~en407 R ݤK0Џ"+\t9.Lxf 'lbf3i6PThќeэC#tUH-HF5NgL/HN RwZk-[9z*!;SeF&_^$D\u2$o0B-nk(# Q  q3Vj>_I0 @EBN4bbC/g:5Ql_N=q-]b@~ ,@*!PeO~*g9v{LI&d.cںu _?<\ʢy~g Lc}-* .^l@K +~N,'}_Drn2z_m:GR ݱ U,N#Z+5&ZI7>Ě Ch`/kJ 5beɿzNjjg IW?] Te>iR\DDZ> eԄmmP{kMԍ~1\ZHCja^:h;XI(n}-և Os^ nSrl]'bF6:ytl:~|Y.dZ 4t 3ڧ) :q>.c3f:; 裴$ff"8Xo@xM1n4WCXʇ=2um5#P!gY8 D {3s$qR Ed0냱c:]]Y^Ur@nrWɇ  Aq|GY|iehjyr?pdab 3T}?wY4ީJخ>Ez"5yQWhTC%{3Z>"ٹ$ُ~D839>rnܗ5`«c.1%S]2K5vDl.=EaւDVov`Aj}7]`j%V{iឍcrlR;PLx4a]ۏ境jPD/t9w@d:l|(q (.O7a䵑5Yk  @QRݚcdA?,x;q HOhgΑOA>F7j vg9YUu\sĹ^ߌ1Ů߫tXS1=&x!krxe?-bD'EtK&8Ŀ6*02z5/Oi⠇c΃'7MnsPi𺼢!c87VNhjvsɮN iJ]_bvasʴ*v杯~#Ǎsvo2B?1<QSw?f%;4Yczi?EoIrcfh話y&MtTYҶ-byvgZ/e[KcohT=@X9ŞTVau!hKrݓ iH )qbywBݯϳ2t@(l=bʥYtw|>y}|/zKBK7h ֌WE2ͺ2.pD; < 1*hZ2̢߀XurjDi;aY).4Ɲ )2 .;5URi)`> ߳ڒpto {Ku_9$&c;Yki:bc pX6* ʦ.J-J]O 5$m7a39CNo٭9v>Mz7[Y=XVE 6,Q Vs R][% $ÑZ"lK:եo 9YKE8d>LW$1֤BF֛_ &4s:WBϫkgiFb* %I!_SfTUG?%ZYCH858 wR2Wj,uX(RS1yL;?Fc)CzRuv4D*Be '>nM Q.VI{`C,M2Gyh$= DRNSSGN_ ׬ ܼ^&6y}inadȧ\4ߨ^{ Fm\D s/R,71o\ xuW~Uo׀vEdmn8ޘ_*U;uFK3)޽=|]7Mv.L ,r}l{9s=mb TRO*8aqqKG (+t*x#1ڥ!rB+/8p5ne量_4~3zkE.{?5ltB򓞰\g+Æ|Z>EuV:9oNž,[brnu|= U?pQVY5?fQַm-/##7G3q>3a!pI.VV^ct'+p]/(kםP@_/$jTpQ:i2tm]$NܱLѩwՙd Ngrdc6xT_)e:?@njX-+vnQfW,7ު=ϼ ]j[Ų`L>WJj?١SǯOշH{$x:a z#Z֞_oT`LjeUBaAtS}\$XI9=XZ~BZC| my{N]ɥ^[u=b[E(ml櫍Ĭ?m & "Q`O"!b:4uB=vSp%{#`kj켰aqx?a!'m[iM!^M҆K:'ɑZ>}s85/#Ñ]yr;[@ZYr˖ Sjqi4 lwz A`?-S됨e9 WyOM-izP?oMNFݦfd/Ȇ`m8_{&H_Oy&k1X FQ~P ;q*kUNJ΋/Z*F4@F&r^(IϮBu#%F(8]U'ɹ-De^M6;XfUY]8ʖ%0Y7t|)tJgM75~0o ]rC"^h*9  ,#kf>S=`(3Jܺ,j+Yx o> wzzV?ͤn6y"kyfX'[s7לr%~8RPx%(]vIDmT[H/w@0m߽c_4]x.>N|c^O Tn LnT<5DK4&; a r>j|"MYߦLl9Gtc"3:>}Id58/h=hFh>M0 , !``^ɢ;]W-Mӈj;̪L@:G[< t$U(mO[.t$DU^̅z(I]]rZfnq{O7lE +ۏywr%Wm9y^OaY.TM>! Vu|dA~b`@L@SKV1gĈQrEg Lܠ#=i3yL`An$#scJ ewBOo"mWW5pl"輴tEycp׏^"C'7~{4=,ʜգXڛY~Χ'8^IŸvqq&5To%ʨnh.ҕUXq4P3| .bf6B{ ȫIo )ZFujˈW!Wuadh@J7÷= {O4mJXObϗ/o%A }E.aVʌ5SϗS]˼WN7x2SR 32DȎ>mtoT߮^ʒGHMpp=*bA{#-֧5Œ^jp\b-L̄OfWVÑ&]dFXC , a{Z e(nФyʂ,_+zжӟ }.G8uN}R(J_9Yu#]qK uˬ SFZ1REuL{4ኦWoݬƳ>q47P^1y2GdTm5ʹ EӆϡXB9E^dT J<^P4sHQ4 # 0e̸8H Qr0֋-9tc>(2+EV3!4B%,h`G쨻bO>qVبPpˬGTi=d (1u"Wb/ x4s=lqdf UASWs1)z)|fd)E+) : fCS\ǙP9Cu2;cYS$X5y؄B16%:IlF9> Ìlh>t(M_fq FPkZK9jHTcl^2ۂYpX:e;XQKvGwkb~ c9RK#{W`0Mf WK\?SMC1,-I}<-wήN>%wT꽬QrkCX9<+>!2sx{ u}>B̊ _bNG0FE>2C+ɒ wELkȵ@Ҫj&>nôW&I퐞B'"iFZxMWx\0) s/32pO/&C$i |q!)TP}Ŧ F̗ԫ4_bPP|ԖЈSuOo?ބV(d1D"LK@ *Xן}ż4)`l%(͸j;Q.4>T?<&4b nKoG VtdOE<`ቡȱ0 )Lw:F{lS9;+VGu,*͏p Y$H=W3ĵ mu~߫{)<,7Br͙ul0ny:h)ZYvc?GJ)% _1uQymTrWْĻOIg&Qx@Oz,|af:8Kxci6ӯ`d~r7=1SOQVen"[55D P̷̠K {?aU/HpY}hxD NaFTZO=];sSmPIF̕;HT ;Ub?;熌g(2 HQG,[w9?)XV{]tVh -obr 1WV#kڐ9UڶDn"ăZ"Ő+{;ۖGQ!|l#- GE3j:վiU9j^ZNJ{;:.]λ|\-oI#N\l( nnTMe}2 #DZL7eK% (O0ʇ/ćꦠY#9caeWJͮ2@SYDj#-(Ɓ% WOO/U9E/*L´QyojNLC-8W`y: ;'v.|"qXӰ'O '--[ yX hl&HOuĥ7FEqLcum}rD:kctAF&@+22DyQ,CE;nB#bvg(ؘ_V^̲qs[ [mDާ5I_2Rz=0b/=b .&3区G Hj2\|4u$LT{A5[۝726YO. zbEc! Mh.7Ip>v鵵Z ʐpLG!S/ 'NWcE~~x)Evy/ޯ'ExJ#p} Ɛcy L46m*@fv]A&_ ;_rJ1^3+3Do}Kj6HD !Al\E; L IN5ese#h(Lieܹ' d*GOX[] L=D4'[ut9^ZG8bЧ*4;myf) Q?<71W"v *7j[A|(j\^ɇ攥+h2nJ8|QaAI| "Yey DşB&}|3ddPS&9V=Ymq]#ynUBqp_38;\cOup(jZa3vYӁ? aBQ4/d"*MɦY]1m cE8nj*4WKVR%X&gcc-R3/esUvleau'OBg]ٳ~[7ߊd~x/Z~DWY :d&PVcZZm=,h=éAi\WQ RsR= 0t> GOz&w ٱ{ 81лK1*椅@$L I@=e9}E6fp&|ל;N0+7rn1F^ iyc۵fn@pXܪ"uj`eҲWiC֋d 4GwG`"Ćt75ȑ`֡+]UmD+Xlv-[JI^gP<;[peO%m} X~!{YE S͜y0 HY6aq!>1 VQeF 5rZsWۏ.{`pX%BE_Re#>w, .?t\쭋Հ9 w__h+8tFlֈd=4e߿)|@b&bf'pLDqGJv$nHl|>J'DCl`%;eN{ _ͬ7y0 cB9?Fe/V!ڧ҂̙{\~xHiDpK$D~x Űjx.K拎B&Yh/_?]jJo4D&JIt,+i"$22 8h3H2Rz>.paNk Q/ŗ!wsAw=0^q PA$x~BJ,tyeB)%x\)t˃qSJr3?6 Ϗ.|m (B~Vuor W0#HkTxkE F=YxK6팔#6V!2Aۇ5G9iT,OBMVZO¡]d~mvܶІnYRj`rjf͔'-LXx9 yXP KLNG6{ sc~xp V+Q.} Rrnb+ZDNpqm"ryv&:QU*9ek! M, `hZLh3xuXǩj4S$MMv6(U}_gZE"QC޿Ey&n9So~49/)gꁕj>u٫?[:ׅ!wvЧ6-Qӕ TGh gJ ^J]C|nʈuTtƧ㻷+"im4DD:fe^8y^'F#"W(#Z2Vi3 'MW:Təm{<$ Ә@)gN٣}6h+}-R<^ |e8JmjT&(nPxz"\ZDp{!zRG8 uERK x)q 8Wv@YkdȮ9 Gc "\ h$6 `l.LbBpW$ÉZb' 9 8ֽmMȜVmhZԩ91 ʺģC,j\fy'Ubp%)D':˃vMߑdxq2݄uٳ1ߊ h:׬pQ!˯)w(`8C 6NwmDc=)ԭ 뽄 =Ou!igp)^QM>N~6PQӅ%oۺ> Qp+r uUXfP?.J7JG\4ՁTQ*[GyK,q謔҄V'*yǤq2=a5{p[9o%N|l`hhi:b`Xf&_FXrNe";Zn7zP>;u]MCPZЧCUQP&/JM੆Kxw2Y5Dg|t)$o2AOjLy#-UelӉrIF[QnEz(_-b5[[Ӷ՝WtR!{a 4nfaX{v2(t!?Go tDZH {\1lXV$n3 pr>A#`G(7#dؼrD3B1فiτa =z8^iB@ipw29\!=n PYpN8ީWvkOV $\-04lcL3!]~Xz =ny %LpY xIn&NUVsM{#@yc5,Ļ@LPI!WCf ZW`oW~sƝ!܆0: /\ͷ4 x G)dE #cD,o6+B3z\|(?Up"OD/Y]%zPYh"[]3-lhEF墢ۍsp>E±NCI.ŖMB }Ng$pjAQ^)AfGKU.wr4zIxSjM*\sIgah8f|Fu'bd%tF$vPZfVv>Ԛ18Iy^J$> (Mζ IVmu1VjjᏁԜ'q3Yq%C>Q=FP4L +/ ,tP| :4UoN[ *ٙUiqYlOml-'岃yxxCRٰ_q$u WCbxB1 jdi\s0v؝7k}>'xN}t/~})nj%83@cG>GphHdl@6\󥘖bp7P͝8v/ޯ {w<`(a'\{y 4z[NT- 0o%ݭZ.Cd =h>ϴyhE&<&j2 'Y4܊BӶi@qu18LίfVu4LEqrӏmwл|kr@\BiT;#g l +8VJϬmz?&)J< @;Q9} )F Kp 9MAR}SFb "p _>\eL[ `l :?WTXe?&BNWj1=]ӵ_dyh{-! [;.RG1RK9ЕƱnn)R}&ލ68(J&#!h$8^K\G3.qCZJQ嚙$P)1kM 8?y@b`k!F7F,%pܢ W3U6ddQ/ A59rS;l%d-1_r; O%Ƈ4ԄDc<`-q9Ѡ.#|H,ٴ).4fm&[9RLf ­uW߆@Wp6l AG K9]#PZBUb'qidfBgS+[MԠR8 2B 6T2)`ѻB69ʂVԷ wb8)J$UAY8{bӖ,p{1yi"BI]B 4u ;riRzQ5a'$ak6U:j\QH91ah8TɆҔ׼*n ĖlB[Iˇ:MEԀ+[USdD( n^";a3kҬeU&Z*[%%%iЃxR1_oNn=XB '0V>iKƶݔLD-RX~g6 YxzvMP 0A=yJ̍ $Ճ?>Gݯ-虊c%cWg-}=솉XBDNsp:HH5c!1ގ;0Lj;MB͖g! n&y)UC ]mnM;T2^Ŧŝu->{k2t6uicDN;v`k87b;?$fj|F'HJ! ȚWf`Ҕ{C:V—Sue<\-dtOP#i x8&f6FJ;Z VֽHWˤ 䰃YX3˝37l.' ڭ kI ܖC3y.oLִ*욗Pd şH^Xmbn2*k%|S("JSgȆM`/N QS,5Sɑ>X"@@%&Oaër~cXu8?^t# 5ԕ C8 ɠ,Fc\4 wX,V>Ttb#Z^E-OS4s"h^ͿQD \~ByێV'~F]<+(]@nֱd g 3`c3MQJ$'fƕ14ҬoR,>)CX>{;M7uvLN;,Ng/Qn|80 tf-hUQҰJMP{}=5n!!&2,ȼZA 1 #F(d-4cX1bW9аm{$[> Y[_m&:q7?Ԕڳ(2=D9ua|YBN92pҤ[](==& S女[D '$ E*,2ST2t|˘6O#HTKx&6+ZXDBL?pky~/?<)lܐ"-0}@єI5\s4l\>DU4c;9qv_ؙX\}^G?1v2Q 5A5I0bN׎EaN w/h1o(uH4]N;{_̑ZYPoJϸOnxF<#cykVG --XwxUzݶ.Av3=Șc#kKGB!g}DF54k/vh*;C`A h=eβLi_X0& ۿuڼX휞Vz9mݑfefRotfmVLǡ~. {8:ЌbU*C7,R!>x] Ua9ew$ۑ?K"h_s6_iAu+;@vQfȮi=Îfm)z|4bTh&X>~lVyk,\K}4YJ~Wy*֗B@*ȗ-#Źk^s<&gT4PSk=6{ɹ ZT B ՚% 'N\L1t%PhQH }z|-yTv[RB_k[P9%ȎKAK{mEe<B(4~awp'-5̃ݝl ZSy)Y2z# s{(6D ;?-=>U_r#q?y` :n")魣`"/,RxƲs*٥|zZ n|%+afÃP"UXR@b7]? rӏn߭XFwɊ5;v61ZtoGO4dT[b#BI% ]tʐ)F>fn642,Ui.DQMO5ii5\yD$\*9ٕ5 Vo[ 3<[y%Wj|]T*~iorEdO8k:iTiKN_{-A[ Kn]^UA 9!- Kƒ& [vw[\閔 \o&Op34RJJYτ 3@GD>kI^\a,KC:)[44'p\}DNO_"(u~{ FUSo jQPr[{ C۰ ͟W[F1%e ؙߣnkdVX6n6ȡm0.ަsilYaY#bV$9 ,zV1nʗU6^̡3ٸr8:wPXr9cPXU;J=idvHA>5Mk>(E,S/l;oyޢb%^y 'Mi|,Ʌ?2(45OmǾ6oOEL 9D<^)>*o-:ޱm'ۺROPuhZ O&ZKFoJ˟+hL O*o[ȱZbtR5=1K?燥99<؁9PCey| Ō(lN^Y&1.ἴmm'.oU#W2l.pH@!{<.T\G>tVct(%sDgաVAIV{YS)Xx_OC&c%lvK[0O17!p|dӱGL%E9hAt}w|OLGsDHrT7oaԶ !\<>;jvTT?vg65qX{?< [9Yu> ӿ-xX8GhչLP JgZ/p! %˓??y甔4^w-A9mf ';g8M",wug1uM2L'"J\:)DZ=֍$/XYюrRtمhLm82]wʔ: >@/^B00C9մw5JeLb#!5/0yamN<5 E֟=?ɰ9Fmږ;Y5 dm@NSHV>(^+,tÞϤ1{OO4k <7̽iSpD]Nu ؔU)WI{.UMOH,N&;fkv$mG[6sG|x(ͭO,ؼ,x/M 9Zh nO 5?cT<ny|L`kO)런W`$Ieygn;)1]̑2T KGR<(w#<|oE oL\Q6GA~DY$\ZXw /5ߵ'HbĺxHѡg'K$;E U]h|sovnZ\cm6y/%uAZƪ [A#nzTBOyfwh'︂b b߉M(@ķɾ2*Iz?")tK3Y荳ut.y>;;NwۖҞRތT\O} \BuV2f!L+a! +Y![]a8h;P}~ tc(/=tm_ q,+eՀt)>SRy\-  czx B"-Ԥ9 X*/{R=_V[)Ml({$وµĝ^zyxa"*/4WōqTPtuYb#M |+w;I m; =s&&k<]i8oJgNX>XG-J]v(5Z&H.]L{P ie&8I,<  Y@a珹HޭeٖRJh\Bf7"D {oZ%(7XOW΋\zҘc&U.˰=%Y|qOnP *m,:T[Ek}z*8]Zt qt2SGoMp3bݳ +?Hf ~RXtG "xjhM!|X,ܤ3er|]# @m8aKB2d5˴,i>F©tB1;yI+_Hc 6Oc}ͭF1D'LbQ@ν,\q|Uo!܍QVzK@řSا'gL9-}ޅŋ3BߤjN/~'+3/!C2f0tԴBDLx!yhΡOcD#'aj$(a[ u|K~WDz;yR1/`5A"sUڑ/$Pg5 yFxvazM!Ks?!4e'UOd3}ZjHLp҇ưR^U2Hrvu)d+>CAC> 71u L~}\ls'x3 >Lv锐9&#jn +Ӕ9iaZx (M+$h'nz2ՏAWC:9jzYƽqř7Htk/ap rZwHr`۶_5zts&4륕^CY. V$(sR& I5GVײ30yFfO=#5 ߗdJ!2fI9h v3pZٖxG-[4ʯJ=@[+S$d^KAh;!܇ka;!`Xz I/){귺"U5t\j.;Sc:1HX } ,+}ma/`2aeVP$ĔQ:(@L!z|YHB7-VQrsv:pw*Xd`;ZL>*;`Z?..vUv9R(H687`G'ؒ4YH

7k,9hwkɞPeɑ -oLպɨffWBcVšˊE|#nxa(Tpl$`#f. &)\)3{s-(J${U*kM.'b:}N)x.s4d%H!r`}48sr&KE4&NiUIy@tYX wfQȡbٕ+ߧИ عX9"L]sv tJ=.rhL;i^h[R>I3tU~[㝝"Nj*jJ-zXƜY=lk.S|r+Ai&4)Wm~u }fyw7| P`7aKF7u;wE`^EPQIZ 6vVPYg~shߋcwU\2 $S«y>Mx9qBk/g䦭 5L)-ʓ2[d_y}bfc o{1`z`pD%lpk n,(0,N `@ ϐKjC>8M,3YofU&da Q0_(wՐ Z?{LkI=#}KPO1wZ䡣2QYQU0]Iq(wT!^IH֧(|iFr)Mhp-YIO*Qk=!9e0-`U|`'6Q3gl"VIvgh6\m罳ʽ~Xl˃41 *X1~̲`To|j2+BQ~tYTv![F{Rwfc+_'3 D9Ӹ DVMdVc 50!i_+4o77jlp4tƼ7~h3oxp(>Y#X l}9+& 1N1hp[/]4z{v>ИG`2.눗֝H',H{ %]'E_ǢdBe=P6bSѹ~qu!! nKz9zXRD'reL Knms«' l`iiOo0/%xPʝu0LE~;G~-9FYP2.o|eAHEByɝX, AjX/Մ-% S#dAUB?{%5q-6˜Ŷ ]2]NS_&;Hlu= eɊɺ}xx9 Ky=TA_dSʍPBoo,5L!$b]ekj+4-ydYd`ѻ7;zz/l\L=v<:^#̲b杌SK_J[IiAN~g Ow[ffeFP NT((kmNήH33[&wiz꫉;]1,Ål2:3̹Fi 1u2 ^eJxx-EDwQd 0ٹn kg?Oh[ɐacF &+~VlF :5|ifBq9jX10iœ[0lv5*N=9ZNx=H/4bX'8Mc2 aeUo=\zu 0F1vmCvXK TcJy\h]TB]v,MLQ. ęfSfK1*\]:|۳MFfsSxo>ALR=B48mrANTܙ86.uȂXws3ʈzn|ߕw]-pqLG޸E L>lIb |\π ґI3GըlF.k?r b8 BDBFiE !W$7OBhE[ $li=LՐycA,-*E d6;g#k ߃vj@)""{ĴJ{1/J2Ԓܻ!wD/^ gD׌q$YN#R&_-Os}Ef iU.X)5u$6GbrU F퓞BuZTY(r6~;0$h}|+qVFT֢@oY;uld3dM.mjattצ)[޲jSU[Usp3=aucrZs(EAi3?Y(+9cͩW^+5n HQZJfUeQSsQ 8+YR Z[!8~"0Ի-//[eoA4( K}`y, `ENַ2L(& 1J7 <+'i6v8]1tۋ)vNƵ,o>L')÷ʉ2;ӈ^-_ 69h?!K?G.PO@ȱu<>/äC>9EN uϕW!aFz̞&kp:[]pkY\Glw<$9bM$q< ÜKxѣ H-'bj FN2RjENbZ%I(AgMNlªz֑ AZd?w=5}>&q`qgUgAhp` Ye J,\[љ΍ /X*{f~yZjT#{Q]ne#nX팥`DQg+\:unai/9Ԟ?8]pS+sC=jyn[-aa}Nk̷L^@>otjJA怞`~^QıAXfqM.(}ayy骆|03ϯ<}J({zʮ%S^_vRCG@dCf 9jߍ) 3{ 1۩uJU.9%aٕ92/h*5,kP>N#m4N,Z 0bvJbS=b|O)|sL u7v9R]LlqF ^ ψ/C+ZS]6U*^Θ7sOa@bM3tJG뱝ǰV,'Xi'W1## -|;vNNi/ј™>YgMo(aʾF 3O7as,&+܊1%FNs$l@@t&W/ŠB[Q.=fԛ_` 7 b xޔT`k Wߚ;]z·Yn@%]|8< amԇamC] ki[8L `#o=?ScN@|9X?$݈\Z-WDL A<`:%6DRaud/Ҟd%,M ڕa$bb[x}w!Imο ̯p ~yƻ*MY%L =ualtn(:~REBuh:*R;r&J'p~ەyTY˫or%m]+_lsW0/t@aE6CC"'e#r #wC$Z>3@,@:ŵԸ9muhQqsVO@]3h;v 6 CUrBҾ[ԅH}quwřCv7pAP,UpW~N#B%YX9@3DsTl)ERv) (o}1HH#aң_&ϡ"+iȅD# *!n6V |BȀh.Dc޷2ǿ ΅v\AYPG]MP[o++ԑ[܊etռB>|!prGjdǍr!bv2 Ahj~^;9fam\K89O{ݏ__SS5Eak$ߓfWY1n%R`b8ݡP`DLf%6/:Eq; Csg̎6e]&J@j\īqT .v#Bi9Si5( w\`C+FA㪬J!"Wv )}46m@N^DaR~=] _yΧ2nu׻p_T4Tˇ¬2‘aIU#MO \aZ0-GHjrHIEH?k=dpd!cQ&ܔ >'<1oiQ)Ep^mm/o6fmdBZo1ռCҝdGqb=UZQ%kW״ЦӲ颶VKHrAoq/Q 3gmӻG?eKJ64\&ĔG4AoCiXVTt$&>O^uzqn&)P RrF υym٨˟uMᅦ[V?5 ]f;ƄT@UQqJz!dY |K5S7ɕG#9tVKl;p5!r3M2F\<R'\qmrY,w3?iͰ (ҍzG9E`Ґg-}vTtlz eTKQ]urtvÂO;?{h *`Ou}ҌVR'jwN,X9I!ZiTC 3ꪙ65f㉣Y=hFa 9+&as*.2&H>̡ x:%87%:Lz@\fc9]gj[.2\#4X(,+#>DyqyY 톱Z8h-? NT.R*NM=Hl;:l/y%[YXXPQҥț4nl (޺OwӰYYuV~ڣs0d@7DVギM3*1-?!\E8S$dM'.jG#Y.]ʠwteY-z".4HD3l:DstZ]ѡJ#?=ΒrFT=|ǮR;v g -h)6][ gE_A0zs{v9g! ؀D@)k}kO A%\Ž}'!1?&M}r(a6.)eE*E܈[lKyw`̑7ao}Vk0Ē [ֻFTBe4c*܀nYυJ0Ė ? ׀1n&ޏ1Jbk/$KbX.bga])'&$֕w}gȨkݏḀgN4\0q~j'ȆH,ib}+"_җr)8z՘d(0mwUgHo7v#V1W<'oV 4UJ*|+ 8uQ'+\?+\P&" h9$uk-pWx nоIJKդcZPѹjo@:?cKoO <jSgWLs1ea?,?=XeT)IF>c79kD?%N= (UbykRe `Rb *ͽp5D_Lƞʦ}}@KvaIe~3e H1G0l=a9bi[Mt/$Ka4{:ї9L ߐ3&uD/Uai ] pֶ#wwh/d_p]q ʣ ^IO8C+oA?>% ͓?sB)Ln6 Le􍪏mPpu)鶣sp n& Z,A6NUX[U=} b8]_3}El6`imjP5`i[!&s~f p  n)B^tT6FS{kF+HEt `H* ~WwI5?/:Az|-MGOWvJ{U?tzI*ì*z8>΀?/T8u0Spx]S絖~~㭇-Ll$yoo13n15[?uichO[iG[|wd_ %@Xqǔf)re8їc0k Y3 %?fnSٽ i2IiQb0KT7Tdu-GH|봀WģPL3Heޘ*uj!r}}p(/Vi7ҵ\0[j,I\#|\OJh-Jbo8F lOR ڴIԆd)bRVS Я>467_9q }]ȝ>}z,:3.#-=>^ _1fH2)Ϊ!Jq)@R91(*ة}N'N 5f7-w< Cp{=]_7ӴO.C)ÖFF OcC`;7rm(1.|!vKss(FǪ@> +F+X2S`g䖛kĩi)9/u:(e h _4pb_p.6#SK$Fm}[n(!+-l޷4B 3kև$BtaAF#ᔻa  :Ȥ'oHZw OggEB]!\m-&D)@|O a{( $nV7ZL0b";N^`p"Danp3_Fot&n'm]Ѣ2^yBVmF\}łm*ݩ>cnf NTqwxݭ} "Z Ncjׁ]/BxjY[1)otlyë :TOTJIgH ZoAi gMxD)=J[qrPXOKŘF "мfrAAZ  .ňc ͕:e+RvnER鮲0L䖖RqQj-oS RF#򙷝ڏ9VOsen[׆=Nc+q̊/4Dr%u)K=>Ο 1/yOkUbblo"5Cˁ%KF|k?'su!jt,v~=$6\q LЅ}@?7.Itr%Pp&BazQ%)m=?u8^m}EYG8dfhFr*t19Xnʼn @;$.z6:)L%NlPㄻee6)aCz,6S7(&/Ώ1zYxK7Dx@D_RM)1)ѮF2*M͋`^nS,LRw3&g#d', {JDtAroݤ=g:c.HRa. T"xZ*D,*;#!Vg| qKP8`BJQ\U&7IBJ8RبfFI@qM=`1 xG:bigX.!!|s AƝG c8%_N҅|b,:HT~; ?3lFdzۿ’Ľ/ŕmrvxlR=ӧq֊)I5eGiRʖ Tu9Up:Ȃ&vQ,<=ϨG/Lv;7?5.L\7܈z(s" BvP`^5]ӶI<}#EmDdj 3vp\ۼw|g=Di"M{B?4j'f=Ԅp \E@6I(@Br7}}c&G^IBt#4m ?A)'}dZZUP"o6>:LQ2q?2QuP!%2:~ ,od{S0ZJ#HRՔ5V_tM bD{;G.]͔ŰOKB0UtKy$]\3Jg o&5KE8x`p$%0?؈bsb/4q/WX.4:'N;Gi1סb CJ  E,(?;xD_c>lHi_? Pw#%1VdO9oH|ugz3vRۥx`ău.'H+ 5cu >rT'wA3g&aDF4[5XQ~pT(]r&0Ehe=Tc|(-6R;AK܉`dnrTЄT;Pw31Xp3' Q x$!BJ}2AV1'@!x%q2R!oE@(mpLau]?0늄%'T&pFW= ݙTZ-\)1=VQ{5䔛Zˍ #S*LPyXzC5PːDh=حNPq{44q gy>4< \Rch6gc@Ԁic]_I ;s#7vXiЗQ-Q]٪<˻AtaUg$1<z=Ǒ/dN4Q+f?xwȈ>h4^zK (eV'ۘ(H&=$* Ce:]}Yvt8)z]AHayj>S[l"8W?O1z,GGisA4/yҲ=oBqz 4ZKsX13fb!.+@T,ZED6XvJ2^KyIX}@# (*:E_!(eTHKvT:t!'dhǂ?zLѴ0GQ [1.FCګd-SÀrfЍA:mhU Nn}:R}0^Yσ%qmaQ" (0w^!%j^ _|?p$`6GL=q1O7nPe!28?7#P 5Vl|9<5eP+O0/3ci;3ϹO\0CݾK jF( Cz(}e#\tg%V7= vly2^˯ˬr tpvHIrN2s=L}b-mkSLd@OlI]eMBgsD<5&~@x&^#U9UoxENbvH1,]z=#9bE{M~kI*r9#Mڀp[e@ KWcYE:K^#}]Ǩ&Y PJ[_@^ sv1K lж1ot~bu+7ʲf*8BsaQ;hnx* R9gZ=CZvܡB-3u+nmMf 8 8Y1f luN32$nR_/*cߜL3Al*(92j\AnW=[d[…e% Z4 R^|CoA9c| 5G@gG;^_6׽u![lY @O|b za! MdV J#STtcOKĔΈ/ۜKayeQDV,y \I4/woSW>f';j;SFG04z๵]{0k ٓJRCG:O ?d -jԲ*blOViInSޣC4z&r؉A Gbomv +=>th/ш:G%գPTHs^, ..NnlG=*H=h @LB@U5#NNT۹Ңdvbb'NRGA.| Ԝ(앥qk|'ADhJ飌΁ է^7Ht28ؑ.oSIhr1hv9=JxN.ҧ6'\7 )Hnet Vh$ŽSLRW&%6mkbX5[,0XG[ h[ʻt!go,EQXD$ѠR]4x|6WnƪQ+*soNPRwd&00-ԥ 9Nj3Ϯ^\PJc]^k]F?{7-Nb/b^3-v?PL~Sr<򵞦&6iҶ":ZԽH[W }IsyY LVA,o^y*yWZ:Ψij͟HjC *gƹAPA_libFoWWF$PiTt&A:4q`\&0KpR}~.g+Ϲ䵟3OPsH;MH$W[͹$8g 9 :IhmAX5(-o~876'b!΋D(AG+ҕH0 n Ϥ\:s `$F7+x@ =|[8A`WtzW=4;ΘFͦ :ƺlYPP]ӑS ӵ`,fM"˃ Gy@dIzhLgS \ϜÑmXQW*c;Hirl]<}lp-%S6#%#]0-{*u s_TODjF"YCCϫqt Ũ.hkOvF7ŕ]dˇK+cf JxE嵋Қ(ĄFIT¹:í7LWIS Voh,R"^T$A<4ZȺ.޿ SvXF)Ux<ˣH4 K7| \X64x#/$Q4HQ2N< SA'+s&Z+Gck ; .9qC]^P=$uq .fѝ$F$,I,!;QxGH<Lx!*_wE53H#\쐖.>ߤygbOm=±j"!x2U._YTS8DZ{@n!t?Y d rҐ~jYa%(ɋO U(/ni 6gcФb 6{Ii;{ou(w(ճ/ʞ?1n|]L hsnK)c%M "iO.yTU?lI!iOO C!Ldn§`}o ,1;UcDuQBOIڽn,`{a3Eq+[ݦZtڋu!ۿy=nkdf8c\_Hpzjx͹UF(VI72!Uz3f%1[˜(zca$إBBԂh=o1ORDP'CK+TxI7EX?*;ڌj5J_|" T؀bp>ѹ:U|+6|mC.| Q*NJ}Fk;ķSw5.UAN-̰b&$[,^SSV{,Oj1ƈCԠh"ln@UOBxع(VGg4Bj 0|p9ޔWоvk!r1k¨O*$9Ɠ)JGMP_P 2Yg Ud|F@'PmqnM*OT]oShcLlSu)x2Sx4MX}.hV_+dSNZOw{06 Y_>M>&#%c,W0=w c9U ug(+l4Ѯ.z11a3`N`u{2Cs@uW_I.47og#~rQ(';w; ]sdǂ$sV.dAqsc@xAyR G,Lӄ |@hSx\(%\OKoqAvO eS 7pU 1+WZ9N{Bw޵%ݯp.-rthm5鹞n#hҨg88DaF`|o=xd=f g,N eu4Ea+Хs U/sko9PPlo(7: 31=.O]2BֵOA[sX/}_lޣEi84 .= ]wէcQ&\[lI,eӰBniڭ~RsjќЂU@.h欩j`ぉAQ$ @_/s!' uJ%* o8jlv~tnyU lA.ݳ Uv$_O.[N"<{$$>.?~|䲭{t'CD'R7̒ݲ #x}K4$ %AbXE7/ka p I)ݔxn"0EބqhEwKoZ2 j7M0uȅ%};|rP%b 3Q87(=]|`r(4[мldzIĦ]ȖlKZ $!?*c4)IFҶɠVfqPS!J9tjcvXеIl&.͍Wj4Lj<2&y 7*>cCZt`[FړZҩv޺4"+T^!^:dMe8ֆRH'HY82c>Z5|2 v΢W[.WJuQ(R ?_ĒU˭JL 1uZkf^WȱLj7M9d'w+0#/G~O@>SSqGK %:>/Ԫ=M4|u<Ͼb9M#XuP24IMYYq`m1+DT%M1zJzSR"zn%U|JMY9ORAڎd>$Q(uC=q V8ڼeA^꒫ߕ}>6 1F`j3(4꯰pX/)-{78ܐ' |-7Gz5lOK 6##eZOxT#(‹%a"nj Drƒ( l;8kF>*pQ󷩙k,ڍ{%ct; 9/_buvxjQ?j?5w):ghok3|M$XJ8~;P6ΚQ7t*0>-5ɵV{ϊߛvCޮt+4 "2wDΐ3uzOvp9X^ P"O|[V 2)qR0-3FIvzIu;anRgI򔇔 4-twzA`~o}|.n@$M[9 dFOHl `T[QX).NBs-$H9lGĠIփ}Huk$ Kh{IHR\94qxNh m1Jmq+u*#xE(Ȩ1\k& .cA9 5Tɮ/g@kυ:7]C|䋏$ci.qZիA՞P(>`8׌JrϬCɚ5WY.xg$wmd\@d0xmfQq6,q!ơ8: ]m'qg]ʶ==n#91CN7Ĉj|4TTưgOK !l] "&1 ϨPͮ汔=AACjv祐S(/QGuTIy-<#=p=e.}r$"pxAz5xi\I^JZ$Ҹ5W,xvPx `15hK^}Z@U{dzaϋiwX!Cwf@xбW eU4֣L(&}Vb5!k3NU@^bQ¨ +xΒW;ҡH 7֦eѷNJDװ)] xsƥУ%1F293:'A0P#bka>4H(]}aI/ n@'s}+~ۚ0UqXfg{ 0ez9 1|4EX9XxdFhɷ--!…@_ܞ]2pEO'jaFe*< @џ'9z3pl26׏^jO̗lFr75hJD ۭ>/8h00+ZScX9JnYlŭ3 V!u印!eOsf zWxj8KWf>07*fz&p~|'S0B\Bzض4gE~xgzs+hc4*'Խ@x`OKoϚrQz/'A~*BqެόSWX-?M dY:ׇ(;l[|xw%BLHәu1BDN<*"_W6X_;;.?A{I;e85$je36U_Ws=܎kJ.YQp?DP%[gXo~xN Qy{W{1H4>.8E϶q;޻C^剫:0Q=`1z+BE5V!jfѹdxߠJb"$gscX4&X> e8dv [w%buq_5~NyXʺtn1QȰb[*1G7ҥWOu["RhV(vvGBr'0GhչLGRH~~#RQ(<_Ըh}!h]gԋ~0Py%n]_S"SYyr;Kg qcy#6nBaiO p:*d3h'^G&H:tʅs:Ԋ]!xdjIRI)\$7ߴQbMaVB̄TκX7*X07.PD N6dTX&נCH2GCc=l>9~{Oe߆{rHN/̯=hO/?.t5TBtX|x!RL"k5hޣ-13(NUU z_[_~dZ{bK~w [ S^D=57LO~ !p4(eyx$~1^X뜨A*QhHM,<7WGԶ@ _n O$]~H]ݢ5` I^;{Vz ^DtК;Kf">J8ث;dJe@7ܳ{dD :I˕G+/: n*PѮ%^ b0M͎UǗ[ ]rZq$NzT,&4h@.V"ȸ!Me-M|ي&Q_k#c"w0Zw4J0_:&Cb7LA|T4Q)ື4VkkFpִ4/ :w7 c.] I'}!UzS iW\ ]^]3>*gOrG1aծؽ+.UeS (1MgS0[uFԮv =Z  |+lH8V!jSBDzWPW |S3/WZ6Km<$SF| b[ws|dh#n:٤e^{Vڰ'A!8ʣz h/b@u?Hr^^jy()CocTI~E`>{ZB[xvzt(/(WPOQ [ (9dK ^m6bG*,<1cN\&ڕ?/ᯗr JF=⅛}uP'w!Y{;x~֎4C0*->j C"n_g@$YWs1'&@\ ML<>~(OzRSn:GMA!'힚ҭi ;^ADYS3gxC q :b{ڇgcXQV=D\z~3f.^%J~m1Ķqpυp3l b)XնXJTx,khBn!נKiuohנ" wE}0EsښXa|a4CG~p&O,qw,ౚ{ڑ䭜{Gy,`Sv ~9bN؏~a=@y_DV#l% aW5 YAU CrY+' D7`;[NaIS‹\#:7y -aQ" 7"RG$\&9W=OڷKX "!y h <_ 9ok;vhYF*JJT ͦGɲj,1/}O0[,<&sF3B~92tf<ҭDEu҂˒߉vrSk@\G?30ۭ LAؼH /㙬6]cE#K2S-`d謱+rW+ -.ci=ΒfQڃ56qWZG,k[fkj-~V!и6$@nc1ەCfGEnB:uY[RՊW|qlZwEc`je>Mx-]]K4.Dqa?/*>VBMĆ.-Vt`E:}ϯ 6Y$#i~l@xcQ;JtEA,k2HGM:CJ*k|5B~R"x05ZF3 R8g s>N-%>itt⑐&hm45VIy` `nx&BhQqka`bq}i#4_]63OCe!㮏 4|:8d(u9*8T#k[E?IJB v?1h(5z0*{k&O1fV@@ڣ"6Q/0WHD`O_yC A\ u@ۙofȼd+ QǺaÄ@4TQFVr|ӚTIs[hjb9Q1&qtJ{zS1\O$<Ɉ<9XHv-sLaDh08[KR(93]IG׻4Ec S]' JXei җUxj7.h1lY8etWWi 1RUCl;VM~ʑP!TSJʼnGpS\$=_OV a]'DHwiv>H凘YR#5`#{h{9\!]z;uTi rpqBzRq."u^Fn:[*Ws\J`oOnGTJmP4l)z V_$V5(=0֬Hv]&Wb3`VWFGѯz8%g Қ7~f gc:L!^p鮿Wxt瞢GӞA _;D }GT`͙]b~pbS)Z%u{Ü i&>Ukr%P#g/bc1>[h u:L#7xuHZ``ACO9`M}E2D@< \J\X4L Mp}uiF2RFCUwWQh|j߹5؍;whaL-9ji&ݚU51&c=pɮ[;pRbЬC[6,|nmzTO!D?Q!e3/;4[H}Ff5\V fRT? %kDrQ~[EGd퉳Xo?O6j8]*Y\%#K&N'z[;}wW;#0uΜLé"#.Ѿ-B(L̶YTg3_,7ONn`&^șL 4UE ]SZnqtAN(/.~w E 3?|7vN+8x1üT9J܌}#kԟ4#AFmS8yGbD?K3U jhM:B+ޮFxxQ[8\3챱y~@aj-Vwr;NkrkN죊KvµQT8e}'k05y% C{MGi~a8ظ 2RPb_=Pn{{^rBƆw-eu*->om)E Ta 퍎+8A;_%]b۲$8yo?F脛lv_3tE,)8~ 19MV:f?j #B6wV'VrJVfsv<{EpzuRBB-c/ YU-m!X1ڱ6KAصS0q݀9fKHE8[=d)kU@{(=1& >Jb\Xn􋽢!h  $B"OwЅąfk@{ڗBİKa.Кɇ%vDW4(P+m9U`Gx>JG?]hM]MW9گީ]YTOLT\i羄 }ddЈ5N𿳇ݘ,S߃1"Z~|@<($u! cRmyEo.6p=?(Rp_zyk7qk}2Ds unoB~99X7a&1-;)9s~s>c2DeX`&<ȖA$2@e5Q`$(c rdC o_5sS@,4;H[ 𝧛z$1?|\J ~s7>kQ?9 VSҎGg否@DMUVZk1n ,>`T[eͮ0*_Xp|35F gikC*„l1ӕw,Ÿe풍&Kf}06Gz)BAnA^`W4F)! __X&5c%>87Cr^[%6jR"xF ơta;ז%g0P㐼˖]C!r(b!p#U>j&4uRAqs}Ⱦ\_97M ۵=zŞJP`VԡpsdPjڑGd!OUȷYM)Y|(/B~ssVixʼ~oBemNKs"ۅ CyB@tjg%@I$;{> gOLfg}3^RUԞn2:hI˔LBnn<rr?WOs{m|hV/16+HւX߿>BVR`lMp*GkP߄jH` Ȧ4)ؠLJKYj*#C>mV-$s(v2\;z#繢W,7ѓGN ;w乓_ʋ?QTʲr bZ'"k{qzݹt5nH}St)lQ,tOa&cޓY9/B4GӚ^^ #(0, tXrnržrbCbJ+L 3ߨƕsԧ5;5ՐG\bs/@A~3Ə`[qk1aW"C?S{qĔ<*=j5=yV6Zo똦~)*@8$" aYafUmoK3KrRKLzO4}MT]5y<Tcaã[2ep'^>wӺU ( z`)= 0bi/ۜ$m8mTy*!svOo,cpC'#wr>"9rC:g6"1 Nn9XtMwrQGYiqoF?Ran3ִ ((m3} $`|dY75[Ӛ?~I Y .^#,] x;PDS [1K31iȎL)Ywz;b7Z 0a98} Jc jm 8B\;=_W&ʞfL:z|!S MG=L ǸxI+!p0hblLqkO})E̎"36rp7nttȧ.(Wwp߭%tރ1xHNhe'k+2_5KcĹξE$iN UO$m6c@5&zK--Do jZhzJ}:Xs96dr25Tz)C+v'%\T  c1<˹ױ- ;j. u @?/1 C8&#"-/Atnb׽"e+?q܅^:I4j6i]NQڛ@L۪M,hEcdnDԱrǿ,`R&B}3[}w7I/ bۻGt/BAr"94 bᔲcP(Di`Ԛ,{*x9Db *]&( h.Of6>ʱ9W4uJ&wojyQb*WC {xV*@@}2R&R]dCvx z?@UUB>4QHMvG4r+~նYSF15HYH; ]mu9{*#`nLC N_._tTiY~`~/xu6y< ydA1ÓP IX:n<[7Jre&Oz 2&6;2z @%0 "C-1=$z=Hv '5a!!imWix !יro/.iJ!x=l$TgUlkl^t>#x6{+ؾ xqȠh>7>g_+;ECtw*c(P'FfF@zK[BG[9P2mdMފ3ӣΥyֹGvBJjqkEThS C\QRTz:8O#H+.~̩^%ٞH݁۟_*ÍtSTv'b~Q%Qc⍟.g71_gcY]ޠCxy}+w =cTea;W V]]+&ڗyBv͞]_0}3KKoÎzn=< z[4uW gVl :Tv~~5L&kGޛ6pcF2:{L{Zn]h;GcSy=<1vfH㿣~Xnv!uiN$s. 昲qļ~\_O5udk*3 F],eZ$_N؝<öUugt-F"6<4vFQaX`YZ(JҼۈΕt)<% Ӟ<"$do): IUG0RUE 5NuL"IgKwK6!rjZ!W MpФ`]mLϸt( C3L+mʞleS )$ ʌh5;LB)IE 2C)hQ)(t]8d*JHܶC5gҾC=\~nt%GL9{z>o0[Ƅj*? p 4Xjvjwi[3}4 )m+*6y,?MxJƒM=,B&@\,l6m#[Z|`Ŋ0R 0evU8 &sibŲ/R򍢂_jO Ϯ=Ӹ#qH[>0@^7&MR^BăAK<6s4+mß( CF2DiaBBJ3FT~2qX\z9EsԷHjo78:T]d!ԯ \7qhC V㊮&IE7S#ߏp \| RCELVADjT5ܸtS-I8`:^|rWמ> Ϊr( <0;vYe0~!F ÒYa I-ֽ7sV7{xЩ@q@6u6W؜"e7Dgqc9%Oeņ*!zmV[EAɳmGM뗕o oLl!r`YX̘F7CߖPQ! eSZ^D|r;%'ګKQįQ9'@rqMMV =m2]j(AfA~lgLhş ZG^tU)gQLYR2&Q-hAk[F l`"}!<W|%JVE_l_C]9 оL]N hW 7'9@?"O]a"~.UQMV(Q %;98lh5瑅ܟ9T׬WX=P0xM&@ ZWQeR=pfBr& @ڇr, )V)"Ic[ϓI7tp+ \Q+ʻ=v,j.Bȩ3"~T豸r-KCUgnmE\gEFSywTQ{dl᤺@L)WlG.sI]hyFvz}؋c}M'#lv,T/Q᤟97 9r)l?Kv-,5' &WT5DWz7B֎։_0ELש/ E?[>pe735A?r3 8qny%)9ǹwR n"UHr7k֍&{ͩԝA%&o J%(Mrr6 UkPor_9dLD2ә z`JXt~ՋUb*埱/[.R. ~qȸ ǘWr$qF9%145POCz$NUBM\܆r z^ w,xbEz"MQȤbc~akljwhraIR&tQm]ezW9pXst5.R2ԝ=Nfνl`(i}yAL2>9 - ȋ Y]QZtj)l&j\4z4攩[; DB `12 mݡL2jS\=7c3٢h"c9$M-~] %ط )cc# p0\usga(1a+ G6'([Y&D1*X5>2C+tƌSq.I2[Vv]>p3Q)˻+3Lu!Fݍf-й4xCGi_^ˇ'J Q,05+e2C Oq=Q1TN4& `9/Ak Ӊx[rj6y(brc//6aD_Q=WTV诱Ngd@jKH8Z苛9GeW'M}: ";fQ% ƿG}[Da~?0 Q?GJE ;o6gK{$0_}k|'@gW[z- @iڤwf' ?d:O۔bG#6(1Ѵ*p`( Y%N%-׵>1XyPʳ l_GLE=5Jj̐ N=?UB͜[TЈwrEhHٲpQ=TR(5'M| (ȡ;ÒfΕB3( {NQVX+ʨ3Eo|kl{%` )O&ۺFQ؀,{Ƴiu[ea_ߪ{Thԍ'8m'*|rj&tsbC;K{yI@az*o2-3,>͍ .%zQg@^$c1~x9gM#c4 ޏX̯3f9\cK0]g 52Kw [b!f՚`Zyɧ6W1B"s_lCzfXK+ɶ9kk.#>RB-]9) aC&yїSk{*mCtLG&jVv|=]źJTEi)fuPxZsNiˤĠӌ6!2%_)7.wIu~蝦=5B(CщhImp9[uY&ibY2&N'2|\d耹"wt S O*R8|=X0(En_-wmHEZ8c9yW3KIrACIOF—j>Z]2?" {m"U.ǑK.z^|{ ulP}l~2-r,cX#<Λ?vp)nɢ%OW (bZ !$>urάBZT/49\>kt:>/ʇɊsjPi 1_vo|mUb-'3IJС""iWrFl(Fu [q]5H\Sbk0'yƒ ~\ňMk>NN<;J'm5:q (g6Z& ?vCK%g40  =M(9hȦW;wߑ>җV8@IϠKE3pEPuyBnOޖpb[CUաyEF /eIR\ߣr8^}T{T'O{S%\:GA68v d ׄ-|NPMyT wDT <^PaFI{ :>L[ōG#Vےqma{^0K<Y mr.[xeL{AM[/sB 6qCғ)B̳6[[1\Ie ӑŹ:@HEd{ץgom;HgAϵvMFu%>.ct3YiynBHQyT_"miʯ# if Oe[6* Pù4o H4`S @#{0Jdjl^_ %⤮ lLwH@=yD?Ogqc^xC! 3nKFy] 8W=DPM9,?I_ 3 -p+͂msfrM\ZP%#(ZJ^z9hW< 3rwqEY.Hz4>2J_qͲ+hLBΏq^r˴i QhJ|ȏ"أtbMTVED鎦oF.‘1;x Q(櫏16,]xDR]QYC< {Xv#Z۞f[j" ( 'FmNvhUTmhw/Zb\tPTex˫;w8t;=*X35"maq w>8 fi̍?+bL \*!ƕs*,HhD;]+ESCb31y| g巄0Bm}^hW;{j!c9}b!Ɂ:> %0`7YgNmV׌x}^PL25/uJtqwÆǃIl_}m3hۙT^#:uq‘!%}9 QiDL6&[cg,.bR$BW:CRB\pIMY={r[9lP,I /q#MdOW_A-)*=f,T$z sU3Pû*۶ i_)cHܗ*HuXwWxFs*D=1WCZ[Xlqm^- b@T)njA0¸R?E8Ej _ZmƗ{_wWJaBUYҦ#KVܸ{B@]dQъ;.{|#`g Z\nadR1M y68;<` {N&qܾ# t>/o5TGZ!$~94g<#eK4G2˜~e'6+@q#?} TqVz%1wǂ$; V>y'e?߁@"QK-t$z:.ˤRSFꟛڋ`d̴?3~+D'N\8׀O)@| gEvOѢޘP)PVP|2jBORP.nxfG";i<3 m:Vl%:$a?@zt S Ni¢~0RWULyON!?e|𲼵V}Hڗ[WFە#L AMHƿVɝBme+C?;a9"Ae:٤ |&ņRAs_}À~p@-&8Fhn=xbTIAqK#/jWѤTmۓwǽ^Rr-T2H s4Uy]ZSfp[-U>g/oz,dG۠N 7 /nQvo ;vΣ1Ow:hQ7@HM~QK _f3HH&ϪTV;G{8:|+h$mGz*ڍ*y{.ycr :2Aa6F跨ŸXmD}u*/[c&kGQMFߊW}兔##H"k18t[m S{gdJb]`7JUb`vQg1 o~zo<T+;2rxj uT|fڄu]z,6qtNYNסGЏ#:7ӢAB17O 8ׯ?I#"ŌREUㄲEa+ndi#OmuC >3!PM?hң@R9%")V/U)rx"2"}nښ8"I^r/"<^x.UX^Ƶc<ljb~\8,Dw~*dAy탚@kt97K1\'7NoIZē ˸Ô:\T{]e3ӌ͌E ԬJ#3wⶂ]I^_{ ɕ2{o hptHOd:Z t/V6(Bv8}\u'` g(S44%Eȫ>.3G2 T"]󯑽J:]tkB}DDQah^kQ?f`)!M3!_e̲PLyl6a4fjTovJVN,du& N'S(,$hsw~ZIOg ΰsl!|7i$y1[hw؁dO^مPeVdOt$tN\g4"Z" H*~o u훮\ʉp6^9-NCHmPQRKWL}'Kxb\ *Ɵ͞4d3! ]"Z\6ћd) J:`/h "dKKʽ)3؎Rý߬uutVWS'

]Sv^pGAWAN*,{wswyF&؊;;x+RğZ.^.3Ma.>\k@:tP=-jwSFmB}3isMOX[T ph3`#{&8['8%>3IlD@8EL58Mitqȓo@< HL wVH}-FQQRޫ&SӥHh `ڶK-s4/(:XfHy[8kثjDns "gԒvUMi3a{^#hZZ_-Th:eHp{F1׌$zo63b!*ۥicUs >NX6AWyH7{U D^Qў'ǦsfXpD>epfӰm9Bζ esXdA} p*з!,*B&V2>{sҁ@ZhT dMcg4xmdBgj%/l68 ⫗1ss^f!Cm&GtwuV)z/*f5XTI PX W(TutEڀܠnd9$dgƠyPׇ:> q_r)WNO@dۺAvۋsPSԫv'(k_2|Wg 3ڛ4Z$VDlz3Jd.2n^)2d5}c]miRFLZ.9YfofjDz>n7\(B@w x}է9*rϯ=iy@ZU8m@jo?{9R*k%=kCH\7pzc]*+PC[- 2װc'm bdc){'_IJb;85Lz 2NyiȂk:IfƝ̦礞2χ-)+xd%f⊗FE/,Ff#L3oQS&"6/GR G0C 2qІQ@sp +С5 +-#v|om~VϡEC|#G,Bʶ*؜|S0@Vz=D.)QޛΖ6oFm# O?Ꞁ#McSxk%>.ZVG˄ [$utn\\?/t$b b"]@Vtx6 QcrNz`fŘpW<ﭱh$n 5ITt2N`jԵT&ՠ/ؘ]?> 7&B8J۸0;d@Ȩkn-#9#\#3:9'GF߿Y?>nO`w]E85wwp碕^{OPtF)eBR/ѕ}ܭP%خuRiז*Zaȶ1K&ET 4mo zކ+s2Lҝ ɉҪՌ?vxYU2K)04}jpGn =p5'%PUHsL$`%יqɽ0P  f@"]!R}C`S[;= JFPo_E˔^yv̀0Lxư X7+ u1o.ge=k-z0/b)qt @Ty;1 %O> zHImamm`+]0\m~4 ùf;{OU, R2asԳK&0%0^TƤZQ؈Y/QX]N9Weՠk[5Ii0eDt`-ABA=W']U'[e%Mw/TfB7i_x!oKow(a&``AQ͞J:/'l)_{ZEכq*>hI<)gq }pi0` ߩ~|+OoQ Z&)[Ā.MC=LEUڨJ:t9zM6hũ|RC7Zs̀J?Qg x+ʴ7sHJ2v0G\dW59ӈU"@I~7m):,4fO,(Nv| R?Qz64s!4bIWרHi'^,H +ƞ ZQvo˓ |; +vRf|CeW2sz; ">%T_GpY.d¥S&Z+d56m+_,gT?F`S#$ýPG9AEBF"L8=r-![ q㻏&=cZ?LRbV&0OG,6 3//rcWVk-vcN ]D=ܜ~fYJεz㷃ap"Kd, %)mٞ`lcm;{^ɀP$-pmZ9LdxqHN{IDATb1n *0 :vvo9.TuN-NXA7f}&J{J>66 &30!eCL6tpC@b غ(jg@vU6KߗwRzG$ءVyB\y33t#@) hVn2lR媉8qJy0j!]? %omvtc+<տ+ 6KBA8G9Vqa|}DL(=`) 4])Q J@ܨt3_ڏ&8헅G%?x|h'D*ܱw!o{;qGi$!x(+M=ʕϼWQ;= . Ow)bR6>:a-l6m!/1[$4@r)(B,LN JO~h'6yD{6N 0FA"!yk? b,>_iXg5 3- :Znw\' \΃LBHٗu!65. m֝C ؗg`9t넠x/{À56L6IO)f0d,my(ZNrAߘMohJi| SVTnGrgN4(m(nv*;3Y0ʯOTE37leFmf=.8.(#KX]aR&S,X{S1D23>DJN)ω+u5Oڤ݉/ffr2e{_&pAW:{EUԟez.Ȭ}1*r<;vAZ@;$oi\ɅW/h@4 E1<<RLt}JswGe+uՉDžKǧanXYAŊ6Vdߙ4bGWO<`qe԰{ ׮/u%{lWzi[tF;Li}&~;mM:]rF}TzvRV'TŠE0+QrD34z7b[xU 8/~ 1H"pj-_ҿ?`%̌\礟%P+@e|Sݮ|;a%@BBU[3Ĝ>)&ik)(}% g|  gS>D=Ճ|$]om789KIq@zus0eC% |2D{msݑ7ƳT) w]i< MQug9W7ՔN{i~LA!я?{NڒMz#;]$ [1icgk.>`+P.&7<ΰR֮Fy51'+0?&")(${9o$8Wsk)>jI'nZx ƈ&ԖE_dC(q= t)mc??^8c.[`"ywmf  2D\Br124NӐ.[*å*|%B/&/7YKu˸'%<+d0N+M !,Z d)]V2mH-/ڣHT9#'DkqXB^<*bMhZ+@Ĩ6 K^kyj޽nB^B<1)w_jLQ+6q3z,neM(8Aٚ~6gk@ ٱBFV'cj9=<9,^Feӽf=jjeVX9W03I)6Ìv{s/cSmt4pMBR(*0ߵ?`㞷ҷ],:n9زӭ Y!6&Ze>X_p(UT讒\Ms:1W5Tw`Y^] fǥ 3T@LeuU6½HQ~.#ӰD5E&q4s ;lֆEg*BvoX/s= S5{s Ҕl+L4 Yb~0g[ }<-U6lk|O^Sp*KZA|b\tp Hi,avh`⼱E*pR`9hQ:WV${NN|5KzG|.]WU8wӞit<3= 3 ǐ-$AI.؜! ?UOm]6w94R4\Jj]L\z2+0C}IqUەo)ABJW)HVD԰!FRS#ڶ0U$) l.ڌ4^oJ$1?L;u{ptWoNV[ ]#מUN]w9XV >_ S{tқ1эi,NS+9ϵ-`ϻm@ߛ? 24}%P|%*݄S? Vc]?Og')}Վƻ R@x`5Jm.~7CE?E]?Nr {;V#ﯓ>4+xsM,98÷!C? \CpElߢa gclYlVod0AEi éK  ;us BS5,͹!ƿ-*&|*Wq=UM 񫳞u8rM[ֶbd}a7#9vHZLb9ڂ(01MR6*R<3]:C@ p$7/-[tw*h&;tHe01w`da8G}!CPV./f`ʱJ}j°2\hMQAqn'3 XKK;lqFph&ظYN# =-M{&T Y}L S=_>Xfڒ*;}n=>*ᔣ6?"W+dW*菿0v:SvN[7]3b=ĭ<X(n::Vh|Q  &񕕩jYN5VV(i"G؈Zw>_17_N; &~e"o49. hKr^^"'kUG2 c[[wz!EYO!}3ԯ ~Հ)};Y|M\q/peN)GT.b]>eEg3帐_WQKRCJC!zFzO!i(sK\n$%A;C!gKyR2=p$#S;qwځOSzvU9i L}1a78O(qlK/##;{s+~mΩ-{~bJ1wװ*6srC;=Mr0G.}V(fϵ!=l/پ[#4ʔoo[7.A2;%JT%nNZG3NauX\;|c32 OeI䂣9+à%ἥ??ҋ3]Z'rPi-,A'*30I'(HW=} >n ƷkKnjBp.zh3ՑcEu﷣[czlW-nY8 UJ ]Fgk#ZyvK3Ob?jIa 0L~?X.cu=={I}(u׌,M`wj;x;XV4v{j̷h̲b>gErbIUm%6wppȏ9cG/uh8 \;C[aG5I*w iHT]b k4m fȧ)ܮot':53c;%@cBG~7TǴ>ZU=Y~Xs8§IhplN8XD3`G.5;8X|ys1 z홚%USarbk#rV)&-61eH%Zdt&Efp&fWf+np-z=4ŭs:TlU!֦Rj۶ݎ͟ fȵU&s3;f?Vd?E;̳.a0$s5ЛgSm s`AĢn8BnxW2JAO*GӾ"|Ҿ@})s\7<ӡnhwfQF?l&TPД=u/ @Vf%n|SQR*`Ocx\eUx!\܌*zt^g֦|~cEP4A$>Lu!LtGr^Q+ ՞@Y 䪍Am.rq+3SQ@D:רh$WcBqЇVҸ1ٵ7W.pr%݀%Qw $ouX='r;$؍ y1:{Qxm-Gt(Y[|gVx+=jo['d Y0,x9%"]wG걢U-qBH"Kڎ/xIdTy^nLm $=px6 ZiEWk}1-d ^&+ani.ޅPcɨu;ަJҼ U+UJ;q(:,_v9\4+Rtv3TTm.8 Gxl"nMf$2WITrXݖ o0ã^!%>bւ -"}a[ŢmE z# M9ؿM5*1&gþ~<&?dCR{uVMesc v%T"nd 1 eQk|.+,A%N$n_0mފ0QXlLb-႙-y;ԎĚauSWUA?'W`ڠ.[ SQ ᒏ=s052mvJU5Uj(~c-$UGM>E]Rd8̡qqs[A*iE|`L&Y9/$je朤$xBa_^ IȬF\.E;ʻwC܍pQؾ:]Tx͟ȁ*KI 3fCD/4S'5+\A8`@Xf(I"jˠv>( f$q;o򜺙X>rO7GXMy%e6gm[/X<`yZ%EHc~ 2 (6f⢙"_ኼ7#=nXm]p,8OD\~eB;-^ݯ{jo׹pELС' ÍV%ܾmPſ#=UI"a/K٢2Epb_:PJm3ނ$~]CLVk3(MENd/Wt. P`;ȪG̙rh \֦,5Vs uu'Z^K,3`)Py~搚 *8xΗ}-5<$lZ4 E45HO<-ĠpD9tUzuV^AݱbGu۽ H{&M>hXBB1;5T˞{.W 5&5oQ,Wj a`=϶9qV&ӅַkkW:'D) ]H0uԏ-C@ȩ1qߎ ~n}AWRfG'߲)DxFȨZ\HQ}'Q) @xԦW?rZ᪵;{{zQ/u L)z ( [w/DO4R6ALH}r6R ̾!ꝘAZTLZÆKzVf3Rjk50coUhӗB @5@w qlFw{ІpgIV@HrNd1իguXnȰC!JqQjx~x%U))KqT(鋉U |ȕ{CP`%Ҁ ,w9IG3 HJg-#z[$1M?'49`(!裘n j7Qv)\ "쥓댷_~&yD<[/Y՝U@{1Q\nSTz⇙ϡbTUuK4F?8~=]Zr* \v!4{sdc:U6bshn'*+L߱XI6G7 MS5&g(م@ pz{6_yl O$y]tܼ _zD&SOzx>V}o3:-bz<܏$m4@2 fYbΖbZ%<zD}^ :~9P𨊅u5e0H])""0JWqIuu}Sg|+\-#tTǒ0|V ]Jy7 $yh?5r.tn JK\¹E/ZZwR=,LG:NJ;*!& \RV|Z1XL֨uVLR\iK?vpl#~`%̓ {YAzlEWޭŦO&WxbSgRy>14d":()tj/r0iiů"ht!QHM7NJ:k?5WMVt~^~)]7eH"U/0ͼA =RE$FOhb,S]*ey#sdX%u.8:0 $Ea|?.`C&BS.P I;Nr[P؀O V6LJIj :;}-ylH,w,y;t Uf e?/8 h˷ 2bcZDo:W>x(V,3:`3M2}5Vz æ掘DFYmSGq8d6zb;PA #e"Pl[7G/tr4k&G,[ 栮lRo+͖敷3oAN~J_6 dS,\E,5[;Y P0Tnk:g |;e^K^i??|k0P +ӻ>.pßEͮ% jѯ[xb4cИV>ߣ)w-o1nD3 >_ 񄂰Ín; 2 qr` &z*)}2o5!|\Wz\'WvuO~Tn-v2dq|jL[DN?C`\p};, FvA5ZHliN7uiO6=W~ p9y!OgEa6'uj P%p-F+vLr.w"ǜe Ągb A΅hu g0sb _ *gѠ.i|Ny]O#~+IczYIc}68h$_\%$RɅz1 z{.1%qBQ-Ӳ 4:ϑH}^ |7O*p)+ =@|>%rCSQ<gW%!Hv]Mƞ>+g>s _;PIh=6!@`Pk;4PJ!<4ó#x !Aq kI8Wgً1Y% eo>RE׎q;AYEQ寧[[,S |Ie8 [W5+FALђJE}5d`}J5NsYkJPJ8eZ4ǐp2dFWcssp+YALO8陥4?{ÎSs'Ij@u᐀Ir!^ ߑ%`p [QV6CKұJo\sǕPu h6l%ę! 9rq4F$"$q5=n} n-ш,%|@ѮAeɋKt1E q4f5r#]=,򚵂$7D/9cw0#PZ)9yX @Zd[K40nJK v92D>A{ִChʠM@Ֆg48#Ew>gN,ҋv鳞>^<̺u`#ik+.G۵/*_]tWyy!LbW4zO"4N ! V,{YMkBC`\NUo %f\IoYVnB {ɨQyD50j EdR.̚hg՛l[La>U}Mi7`?>pI4JNG?/Ct BՏaև٪KM)xsg}(}z c :W/#,w(+r)Mz_D=nkl䊴Yfu"t4`!-XQz`| Ii^򞱗nIa : wXUBHT;Y:WO7u>lb]/31-ZU⢹&L[0px>-ۛYGb5P%:Y=wL<h pgtf%{Ǟ.3m+R[}^-x|OgW§‹ՍV1IĚ!\ӛ_o~0GOځU'T?֥Oh%Ad{lTB^AgFuc^74&UǛöם[-cd% 6W$xuT-($KPD&#:x.7hsg7ղ7a̘Oͅbuc~P)\u-Aw#\N(uk?]"JC f/^F ]wVa@5.l|oMtRmhhۤgxͳd)TFtEՉvR~_^3&b K!)NjdIz*7U;]2@E?˘''7\{ 6;MUm&E9Ylw{}OdBE$Az~9G#'m<ۋ[}QQ (35xo.bs1mRIsV~vpru}fgz?i g-jzlI\_g,S>wn'vRIGP(pJWsGdnK'IDკzBl莕{m#Nlel^Q4iR% "K c]W#ŧ¨RG%S=E[07Z+P86o9*|'ID,etH壾gs3pPh<M>}5w<'Qx~N(7W$۬,q"r4]5HaOx|w{es^e$śUEA>YRG]d)v7ˠHc3^՚Bݚw WbvBUQ/d}F(m7SJu Zx8-Խ~߉iE `!xZ0c(+aVb+%iщ_V]wxɜ:t kڎ(4|l*or(d [.1uB?09:aUK* R94 :jR J uR\Z˅B:֮apJ5٘6^[e>yswAΦQUqH疐BhtJWp*1Rq7MQ<^(iEkeI&aZa~2^ ǥ5%b Wlx.\ !$o3@6qd9$Ty{(Urg!ĕѦU[U@wm'9(\B@wõPk&ռ@cp 5&<もf1}nl?YP%;ϰU!:x 鴍CIo@!^q0Ƚ&\UeR-Di!iKVlBZ ,׫D?p./v #o"Б]dJqhT&$\nMW"n޻-53FZQMt|#SS.T\qlM4B;]Lu^67=Ro 5t%tz|,F\O~ ] {I.m#-'Q+l CG"%U+rjC$~ OW2 ɢ^B.|Hl<4|IʩTw! :(߭brw.]M'W7a.' x5\?>EfPΣ|4Ub;~Ȳ<:o>V/)AәauA#{h=%Sd?h8هMJ0FYB6'QB.! 3= \ڂ2B19hx9alJڟ9(X&qT` DHWv 7"6>zBZݵ؜@Xi,ߡ>KnG`#oW&dZ=׶⤞ :!j%Qfp q΍v/Y!'FQEi!> `#6٠ԍ_ ͙G }w sOދ%P߹+CxKLH6dd [u :*Q:2C yak/S dhAp4O0?*y$BMhj?yLjs(@YB5%$S1W[ɕVzkw&̯ܴ6p ؁F? 6O(V>6y5h(GqgiXǰđtv[}PuwSZ$ʲv9L 7SIXypqM(9"-4`הj. v/]@"^T)"YK ;ha)2yyc9*;kW>% :a]لHoarKr_\r%ZDk ޹(tiUEv]ie@pC:Ct  ?Tpf!! ʵjaBG 9&fv1{HqrWK Xt<=:Ŝ=Z_&ޕWckGH*oF8ed{ޱp@Zx 9w|]Μ34D(䠁k˙ VվRsڿ~uxw acI?E~PfJx=yVD;2~J,+7 Wr[c&"Z&#T+f CzV]vCH53KyKm)>þ&j^-rrv9/[5OXǷg?,$Z>{s JmNPz+[/'Nϖ τqє~+g'0u;+{:ˮK'^&ec}&!IqW˳Tq͉)~Bڶve'g>HP{gNMaOX b'á$,WarU D"l9Β+Y^\oT,Pkӱ@u=fl_ Zb Ea#8Ua'έ/Pf@2x\.>p+`M\׎d[Qq}GqR6މAjp`5h8(roUא뤯9 #`4$P⋩'$BQ v`rH2ֵ5LѰ2J+٢)2n]x^ǯcO]B"jh"ANC/ZTt+N^ϻmsx2:O8Y;./8@]yC'n42m L9%I_/Kr^(J 5@ ^7+A;AHf%L}ܒC.Wz+hR-G(֑L"%:1dcrlnAbp z;ſu" 5N`р$z=/20XgAkSOUL2`[c Buf Fudz"H 9 l5}aW".|3 o9.' "̠B,Սve] ^/\.Ujlvɫkiy:`P(ɼ@w@t۶f+eyI>D-lgfk$n gbx9eͩ!beУ:U$%mMm(P-f2j};2b1kP:xo>M8F ;='Ů3V^U]քYX+%44lBƳ] "8pm41 {Np:/B"W&tp/O/mǓqX>qS6ZRԠ &5nr =aàNڇT^vnATΗFߵ퀂HF9VU1҂-*Ms(_46б@KNmrY t:SZM..W tJx:gkVc1ZaD~%햌lTTSU#}fͫi,3<1 (D}UZ:{者_ _)bnJ9H\jl!S ~j{~WrX0-lN?3~U ^i5\O~6^&brSG`җ,-ҹg]c(vCW6Z5GNDž7Ffİ_rn77["W8AXjoWE[cYpLEO2|URj\+ izXn1j`d/m0 $^s"?ZC|^Ok{Nl,ϰR@\ܰ%4S-PT{E!q6kʡ@qmGbuPy"_`y~*E4]u?+S.d_$LiXIxGH ph<1h(~hP7K+dC疊QtUq=8 exbWX3c_#&ىز 1j~'xr`;\O'0`e?үuT`$Mٱ*zuh %D.בVuLV_nQ6kw5,q?D|h|JC躎F-m+sv<sfu"H5"^B!:)d%fhx ߭ [Iڧ]50?$(Z15m%OXa9Sx("ԣ+Ҽ"WÕxNHߠuE,Ѳ Z@}\bD  8K tO6JJn~A]4C*r5 X\rsLGV1edD(ꟽ&{?*WNਨw@ Ћ](~ HS/ho2{R;֏0\ldY HS_]t̪-1Cu<;KNf}ġ+O*$Ql:sI0jE?XO[].t}l{b)j^7"@K),=ݥJ7a&1 #g)̟_XS G~! tP%C~7vL7f\  i?8yשQiJxfJöB|+y&&ϡ99e>ۍ[RT !DjeeǴ}/.}<jl;Ja=T (Lap3[qW,/N.`+Cm275CRD,՗;fTSd {ul5bj{SU711@Lx ,؜f#x]4F;ܵYcZ(%㍥/?ãn#Y'YɋS#p?0Dz׈8aFLEvD׻x mV?^3 X}Gy'B\iFhѺV oR,A}vYY悀ZS-9hHݔZK`a}:YG}ZW*Dn j- q oGMyo]4;ŲZXRۡYgv;;?1!fe^'1N:˃g[Jח{d̾( ǟ~9#(XJ஧T{JTY.3`Z( #[V8:7Z(Q eUfZ& yLmB"IavP.UWWiaSFm P!я-- 2frH.$ {q=෬oy+,kAEHY ,(yJ@^tdE@hxH'?hVBٶB)*vTU=ꍾF&.-zuy3Q81jsoZzfCa?$#Ɛ92F M[q>9/wx5 (h #MVkxoO׾F.Ց6 %@>}r@eQ~zY3BoOm,zx臠ʋN/iI[ose2]3XW%S[/p~R4&.#Q1nW}Vq=KzcY )!:l;;$쌐 @ ̎\/ޑ$'c?cY!3k$wČ*pMxdC;' _^Uܥ'y p'䪣 vT&ϽRYke9X|05a蔀1(zmkEQ*2`MdBӒ+/Gni1KLQe}Roʕms/`t5EiRfg.c>meǺݛqu20ж  )*?/"IgvP(RC?/% 3oft٧r-X"Z6)hJ@b-)4!xnd0˟rk٘WZ&Dr8 gXYMr2KG\s'7d(۳C@#qVů2ʨEK+?^000Kc18 1ɥpϟ#R9z^ oCzg& r!1*q2ޭ/|2rh.f73Xu;5BYMB'ZPad( pIf[+5kyAٮEm.{«P6]0Ko9t)̱Y4If!DRĊ= pp {sHģ҄K;Z{4eKFLmd6Й %~(eݬ!yNG ^u+S0jFp{ze)wS:.}!-1i TSD[M- :F?2rjqPZ=+e=%^. & ιƁ8ьu<57Fr\ĕ·dR8wZ t 0F9n3%7vȄ;9$ y $&p1Yfcɤ78.VJrW~:_ It IESqo$5aBMVJWi, k=zw 'FFa`!'sȔQ#@zR٠l:^dh.ǶoOĽoJK22[D%>'`ۂ-&Hpf0hK٫~ӷs(!t#5֠ gH*(jswSTKZ2xg]-FkՋ x`dAnG/3sqūx7fMLfɀ.lڎz:P|Z#Qd[-DvK'p 00ixYL7ڀ-@)8qni:h5H;na)J CvHMy˟zH>.#*l9Gmzmn-:p-ۓ4pEaW9>~\H@'ʉ{"[$vShzH:]Xf;%I%vS ~S$L-Rfnlg[ }âG59[% :5Y>vQ|GL?z<#62, mz%9J)(|i˔1aQ2Jmƣy(O_I'BHLN[6,U+wmb"./I1!}r|{*FP%eY"1o~=5]l4{V6,K5$,kΫWtJ8,܍/^VH‡ÑoZ<;Q;3P2T.>crMDr_O ;.dY/(aEbx`ɦ3]^۱ܦl{&O1sZH9rg>T[|IsE ԘdP g.<mbN=*@x9S9'o e}W~~W UfQknʰFy˷6S =nP@:[L O$9&23r:C,H*CTeEy09xj@WEVzb_DOt߾p.l;П]Pj^*]FU)^ȏdW] 2烨#Ry!%zOr䍦 7 q\v٠G9}F;핋9+G\ّomEHYyOm)zb(7;ċՏMd~#^ÊXd=33^@`muo\hc={k 6H3JCZd,zr]Og,`KaWv_Rt6 h=K/N@נArvL߉AЭ>u/pF|z$b~{qX|Ln@m{=?*կpVS7 l#5ih Ǿ淇?"סhEwycPϭRu"{` s8rb ϡVvsp-&1SC\<$(V316d@Q]@y+/9_A}Bj]Tl>)a'EOqX˦u"_-M#q)I-=ey Vdb]%k)CmG{/'b$nP͊JA>NBvRcjѝҧ^kh+gQ:}aAF@sh?+!DxO\-9KFԳ5ȟ |ԡ> K,>[,lg!'l{&=ߕ=2QR$wpjy\cW#:Ϫ0=j̎Rwmssa44T Z<(ܝCi;gY?GG且 c5 wT*X ^#d/,  1*aK6v]9\4ө?3$>D5f8 -a!SN1ΛKYsXT^*aVWrH%P+rg*żۗ3lsPl)5(~?ցHl[$fI>Y{̐?TA 5c籈7 FXHG].ͦ pzH|)b9ڨ}NX6Z# :u:wz~jrgvttqb[bހJҿ޴ZLZSLNI U[)6P&[379xBkC'D>"BXLspL_ZhnMo 9.:Fe ̫DYkYsyhrg3΅eA¤icId]hq|;#>c3 }sBsCͭ[ANұܣm [PkWr{{% z"2=9 0Ǥs;Av.EL"(q.k>dkI4M;HIV i k4cVP4,oǜ8Nf23 fh<!48,^,'{U_ ࠌo㠁.?ˍ_ x@fRj<\z\wb þçV9+MEoa{Ó#`t/?u[x 댇{3[:m(`{|-8W#\& cn1;A~Go_S2z&ϤOeel;s(gW6+0k d07eŚAlև<'XX8S?p+z P!~̰%P/ r]` Ok3"p(&e/D/j} 1^Cד?7Z-7P$JZނQmdgѤWAl>8V\+*j"^ȿ%I4y WڜpG˙!F2 Tκ=F#G`9~ Tx-gmf@k_Rh-Q勑\kʚe3Oe#:Y^h*v1̪uQx4 i{ bfdʒ0.=跗ϸj< $t:nv- \,E&Bt72t~/t~xgA8b]IOM\gX?at!hBW0"N+!h@ o.w!^-ǟDR ,o=e(b"Ov#0lߕߥKEtDAPfFs~:fF8EσkY$؅=+li/CF_6 2W$niҘ᜗8]~[XBhAy !Gju%pU Zz$df4d<Ѫ=dgq{<)oEOaw$T)gSV3ܕ_c8fܣǽ "J[-xиPHgfA.O7'<*Š^B(Q&ө{_VHGUP~MY}w# % {qM^Aq(\D"Ext9l\ٮI?:gMrbZuR@AV- 45 9} I)A ";l̼E6rɪ1:H:M yQ.uOb4<1xg3/da2%/[ow+P|7Ox:Y  pEJ^ToVm;I}Ln! əD< ^UEC AEXF&Y!8Xh2t57۽5A6}85ډpYe@b o1o  &P6 u|v-ؖ**:K;W '8p4GtZ#}FO j4lHFn"z`z\0&)x(%胸5~{*/(liI:';Ze4a^Mn,2$3O&Yڏ^_ց(!vCq6xRih) ڔa(dzF0#?B@>%ʽ nΗ "daoo(*KаzSki_+4Yv;xhV蒰 y/#Ln7غI(N T|), md<)㭇Y|Qޔ:_VpoP{%Vۅ-;{ 9s+)(uttlԫ [A6E&tp1ljX%_@wQJ藱qs60rNȨ?fVk9ЀV \mY0.zm^$D+ P[@$aW%cb P:.I;/J.b(ǣOGwlBmmPsk#5c-*aʜ="UlΖԥێNqS};Qgknts NSH*孜KjLn[*a8=w (^KAp,ɠsގĖ?>; gcVyb#hFr+Gt?웥6I83aFZM6SDvXw`yVLuZ&7u@nSDJNk&.m`"nFf5 ߢ@4>_jtYg}K(Q0]ƥ=w)̹y;3x@g`xL v,Vlly\QKa}Oo5ب4sKkCvi"RYl^|fQ|۶*tʻGOoḟXaޑvׄ3}C i&'6լ-ˮf7NMaCcunjSh9mk BD ^*cE(f`;W':֎ SǺG:gma:&Redpf` f^EEe xS'$!f+Fg&/Ը-N,P \4'XbN8b5k8÷x*'  j6F)-3s y,= Tm̲4S6]AL4ɦZfcHF pPM=o;4Nе2떧rԃF#9hf+]1 ^ | }QU8+OJJ|AfYaF?ƹWBRz[LJyč/h3~:jՈ$Um{ӭݱH#5PMhc<S6'T<ڕktmfxo .PnJDi'yF|J&0-/mSíq@ %."xǞi_ux|#cʫ1hȅ;8_2 vLG:uً$Şubٜj1{k:ujVTnt.}y0&Qq,C:zY,:g?Ny-rC#x9q7;EvG~ f.GL1qv ތtǒرMIuUp۴ؒkE)c"(G±y~C%\_:s)؟.OJe/J8 n/z9!UQ D̯|^ ./7j1K! l} wcm$G׮P'l T>I<lNF5-T'޵M5\?p5˂gAe;Vռ !20= ygY WlR j29!<­w[im1FZ7fJ!V6:r,rLNhs+euE=d^Cۋffm--~Fxs?Xq)(}K#MH"}U.C˛8(!d`bM3J AOtոԞ1En ïQ4p% Th']0?Y`c"Sm6]ƖB?+\l^< 5dp{fs%Ohm9kZe*CFDҗ;܊tO,)OJȑ:JpQ-dPNp~\9׍R]=@G4;B*!C%OhȤr5ը!4^Ĭ? cZ>$2=`/962{MdίtW-DyȁQ(x.o V2ɬM#M~KǏ?eXBۢp0\6IvW1S`d˪z,gb;:aJ7Ae}:*rF)^*4ha {w:n~aI=-S EN ~9iZ\p~_͕^|I.sWpYAPh3~6amNҜr~`9OzmcW/OeoQ>1־z'lSigzLf)_G$;WEqh[H"7``:=k4 bv?D;ԟvzE/'Ւ(Je]I"17v&$}, v2p}FDf+R{~_ZzP7hАy%tQ6o~eĭq,nBLJO2=ZRÖhh1! M`(Hc?}{}5+S/@?|i!u4W@"U%dWR};K~}֔siAzyC%}<]vˏ#h枴do6/36 4GY k -zMϔg& np|76m'MT}y5x̃,26U>syv8iѣbDr4ΜSX!b5_Bd7i25 LUPa0ġ"Yo?ztK:(ӈVKW#=@V 6)0܌K EQ6&^&#%Cw$J>z\8P9y(fG)`])=S"킾`vfĤ)a-JWǫ=7-y]}kpw~?ގ" =^c%N\n?`QmQ~ R``?Sn%ڡ".E>΢{>p̵36:-sY*1Ro|.DNw* I嶃e<iUڄ|;ptb yXaqryY6]Ԫ?~pev\ ptmJ \ytYjjb8F+O~8m*;gh@5pOվbܜL=~ i\FVHzbS+!Ohc PW p(T^%ѶݝlW71sbw9?'P2%. "1ey>GeA7} :?Îj @/K>dGa0vgIq}(>hC&`9n=V-N쇯p!8+b45Qe- hP_"#ޡOsMY+̬h$#-ԢGb>H;@p"Ay{yZPre\iz396q[$t_an8f߿Dn$1&u>'aZ+:6 Axy}>*]Z^#@5;R:a@ <q.ȟJ8kj:LC[ 猁[4i5`N{l{=Ф/wA`]t5NT ;宷>.}sj0s6% |U)8'v mKϮ}7ݙ:(~KΖ>Hiz/YG`nD>MN15V9o4HFm9TSV^|Fټ+ ȥRWO_XxlƼaa62>w܏5qq6/uѱboFKոdW Jڥe2eΌkkP2~ءz6@! Sr?~0Uz( ?,2mdgk'hزR8ѹp.pȝ+˅[o}= lgUj2qmxk]q]%}v5WW_@HYC ~BYJh®VҊ'Բr}EC8RPoRH+g'Z%h0:xz0J^ܑym9= ڼ&m_q.JVjV+u6fw`OmH@"ӑgZ>5wr𗝿 P0ZYWv1v9cgon^@oJ戙|3" hf wHvkוp A$]b(b!gGOMnrRJv9$)t70QVai*W1 S=~JE-"D>蘵4fdY;k窨JDbwmcl33>"Ubi5N;ys>ѵgÇ,r"mx؂2o{&TN&j$l d[cnqdeZcJP3֋S%K^_֬;r+>b~Ebb7u=h }(m(9SJ,$yh , 퓸B_q`x/-{@*߾ԡvs"*.!Gˑ*ڟN>H] wb(q.e 'UQIEM!c+~V/ܞi8 &{=g]T3Lpwo8c4𐔠@PMi}bɖ^<⑥=_2|N{խ2fo d1]b ,J9UY~Dʗ:i꾅=uҝoB@3 oC-%dֽ~Jfd!gRƆbQ='Ҏ.N<9}ͷ`iMJel&  *[ ;k+ 6 Z1g?88P6RWesU?eq jXdsLn(Hq gWԏySly'⛠!tJ?9rȍmnV+Z3 foI#ArҊ64I%!MD(L9HMrP i.i}.Ys: Cj]mD`҂"Q'佽\&(+ʺ^Ff@R'jBNZ9 "[㕢Ws]OJ'ӳvAG=]I2zd:G/ V {u#83}6r8HuCT0Q w1@IEy&O "CN)/3}*;tMɢg RZ7  T73;8$ S 7:"Ƌhm]dL/,4sWn̠o܂Ayϡ$t+_:1_n"3p/jBIk2,Qm:%S[o)t|Et;sC%ւ4!} XR7m~ZR{bXE` m[[[(߅Qk3+}ߢI^apq?L_֛h?e,؎ߙ#܇Q7%Dy|!fĘ}yyz\E,?9_$I -X3o"T4St-U)ƨ{.| SmU&&/ A*ICЈIܑc߁ ku)FIFL(x!;EwqX',_9j )b&^䞛s*>yjnGrZo_ Y1z53 9;9H&TX㶽q 1g4 v:W| H-G܊"-قAJa%{d#9w G4sOB]pX$2nJwCt1 5X꫰ mG3t=]46x٭QIqV8eO)1ٞBZY/t]d=VeKr{v 抷 Q_qy&c} q!9-_ٓtbU׷s"WrL|aKI[.*O@8~\S?Y@OS6IP/5\ږrE[i |e Y~,P-ފ6N <ӉD||<~?eA;CZ.hBG&xv' (\dpi>&$Bh+LPsuEBAuē_׾VW迓6^'x<;s|_m *O$ի*śt RdRܥߎzH׆篍QzH9]jҷg@߇Vg RB‰xV=&.a,$nS{)%6.״CҎQ :ҹ>h،3'aџ@ D:8-@_с)ȯkE~>8)&4kt؈ΧT=ՁbU ,RB‹STv}D?w ̑Ūy{&re1rX}ph4^)Ha)E;PUM(]"݃4vX6p_(uйoΑև&~CZq06Ԩ`.Ty}愋Zhmӄ>JGPt-w@R{%M:[] *]F_f؊4gONpyuʒ'[$,ƴE-u'WZ L Ps2] SA]V++(Tj#? OB:yԕO0ViWemOHCt66f"H {![-k, c7V˗hh⁈^Ua S.=CYaaJX8!)g0.K ;B`5C«h(plMc)k֜cC1ѳd>U0Ѧ<>`‘:g!7S &E:$ ^#tMCw!}s]dz|Bvw xjP 9X"u<d͞X};<)])ʞqBC (R5x@ʬ#}EyX%#': z{0čұ7~o>@RK`aqyJ#iM ~v(/xʁa$OĐo]iu"?.!0+ $I2)vm,xo+-a<G ֛ y=Ƥr&eEy|$;֌t-5xK0@BkQi9޿ˎ xrY( 7E uJPvxp7TX|گeLYt{\AogTd Ǣ郉FmՐZ9k| J*@|Np hfk_t<:ՉxE>ViЇ&yj3mVo_dW6iO!P 혈[oo" 71B(CqbnK٪DK 6Tz"*eU3Sls I(b `JsF[>ȯR"v⋱ tΆGΙMHBx,Fg['XZ htrۿpz鶖ۨð;aE[`@g4Vpvap"XujcLX {2s9ݼ.[ |mWȝuIѻ6el`g"Rձ#'~\JByLaU?-^*Db+.&wَ~CpDqɀP=>4rɱ[tj?a~ʜ8 ,^΢ѽ#EhE0^y{D3zr2оG#,gzˆ v+DE)v~>̇Y]5)8r6Wb%qk`.B'1έ ]H тWP0Hq*~V6 ŽTuE@IŻGp|KMtx _yA7K˚ˋߩ;>Cdyc"bTΕ[G׸QaGnȵjSoe!YfQ}{IF̏߻b{ghDMkj`Z&hZY13Ä,^DXYy"m#5& a,&2{}y6 7XggN9](1ÀuxN`Fm}<;O8/)%P q˥=YC*6ǝ u6 -ܒ+|s!NӆMK>;/pc_Ed͐f3*e7{4h`uئ`1s̔$FjowmΓ;cb}N|¬`̖ӫ{txM9U~h Vz#&Rܚ/X5lDbyŘbx$m€j^ڼàKۥ)rpKDjZ7I Fa,X=CL7JpgD<3 `9aZbwr oԓlX*j']^meC%XIVV1xjbaSgm'MUʾaU5 5SW~OaET>N@MڒNdl&*Xg9}ag8Z f(8Og\EeIs.T[ h4eL'| J@EiKyWs\m5)bxܽ >p]ɈŚn9ʷZSȦa9fk+Sڶ^.}pzP,L^EԬ./F^[]8b /}8< װ# t\7F.k@$\77_K;ȄS^s#%k6׾PzPR{q!/G)of"h G)+@akw6[hsC@.E7hs"{>/dxykFs#(v2qSO b1\v|@MQ)pMoR6}ͻEG_H^h0oCGRH'K6eFϲ:N=z9K%i[yZ̙BS :*\!UȷbmP$Ke*8NƦRwD*7C_ސ˧9i䣴{?<\5ޢfWY$BA^͚HR`~2iD?\i .CG8 =VuJو hz0$i)笙g? /L&Pl$fWFi]b~,cUsyCα Rڂ<;^H-eJNq1U}i?Rm^jJf>za..QyZ5j/y~_(uWiR.$D^(͟-#Tc&<_߯9(Y\da pJ=V /j~8M/[o6T2gcƜ8˴0=|$ZbSvAȺk;^19O4qsRJ ydq*˔GF,z˙NԏQ0MO|[qJYs~xg3@.䜽0v*E|/ƖTP9+ M/։o$B.VJ]f)JW]]D@YB\LTM,X4ЬH\0koQ 6iC؊?M}[wfZaiin49S)VRsshHi-J2`$a^U,:<5z>W<]3VC-ӎf{4c0Z"橥+‰Lė `+`څFkT9X2㜑ڟ`erڪ#J;: w|G)A Meiqȋ3/asjhΥzDn$,vuՆ*$/7D-%67r<ѠU:rI'*qtQrF޺E{߆fЁw\YKch_KDY̤9rN"+'JjvC/FN=LpxlqF̫&l[A8CJ?$i9\"v[ȃ"G7hֻPNX8a4 Ap5 f!$?u*7;v'i/1tes.G2TԎ22R&utE/: +K#َ:A`ӽL+ 1).dq 0{gij{*Sv5i/d0G͈|e^-§$BK;y zK;Oa]yJc]qn sf 1>;xRnt)RӍkC!}M@D Y4ܓ9M*U#4BC9~1{avȆ%\<ʩMCECEյhu[Bbb\wZ. +# JXE~bw#QzCmD/c??ms.b"r(9t/m$+Qjuτe gF u1iA Kg[ϳrG_bg#,7g&ҏ`=58.I=7o̞Ar'T")RЧ/rEF&}$:C y|YT L8H$ZG( ةE,LP.ceF/T;X5<0SrǺծKAP ZϾ Is.X$Wmk҃ S~KF&F8neoD,4[G ]/-GWA0 o+mr؀[f) .87Z\\Pn|u.XOc"ӝ|? E4 y$GWAj5OYIryLtyw q N$lEߺy1v5hGf~!oxsv[4HmUȣn n"ɔӱENM>'s0V Q; /y٩C'//8)je+p{H=c[moZΏ2x7]9]F @LT1{`ī{R=}4ę% &qOWGYN^}fL#&9RV,1˙k)$.tyޞ]Ҥt^v} BX!}?l PcRBjޛ+{Ӫ6=5&"Bb7!)(-q;B!P"Ч)V68ר>k4.),台 TքVJF~o)H8u, .FN7CNELԊD [ܚWiB_zvT-!ϗ>fUrKQ,0Zz|i0˭ A)f=}~.WVщk9`WVWɹx+D)L;[lCd1M/kʕVlM,XxbW! l̮1xsNp) OfTQ"4&k _:oSz s/˷˻7n{QI)UmQ{mCDɿ(.&ބљ=oo_pQ5zTrY`T &Es@̃;P>#SOͦz#t}.Ȓ0 $IݻS}D̓k~LЦzBZ#H?u e&}zW<>Ӏ ҙRdhyR?-x -٦8~$E3;hLsR=/5YasNx\cBn+"mz?ֈTkH2wwTUR$L"4Kqp3 X?cDkxKG 鞓Hfb]T.ʸ>z?h,( /%:jGdպkÔ Z_$`uRpKW0yNtCju+o){w_;m(8^(sxe3:v6M{j3x??@"%uBk#+ouT*n5<>wнHCoFR'x3lQ I|Cs><ᇱO /} 3nXuʆ1MB= otȮkD(@ 0/ d4 !_WqoD`=ګQUl:N~^Mbhc9:3mJ>O '2A{i҃(*i6tS\.`P2SҤ] -&t |X4>aDMy#G>M.%`bL.Ŀ^MgwԻծn}T_?*Bslɚ쑔ƌ5_.'DtYhKHV|%DJ?8 k)T~g뭔s|N_73 oDYˢ`bߟ] ĪM굳xGv P_oemslxu))dW҄FXe!H'|}Q`(ݖy߇XfajĘqIm:} 셎rW dRvzIEgrI h͂,^- xz1#l+0GlkLF #mKVr'S P*p[9?ӿJLۼO$!͌+NPx;׶3(@ȸ]ANW^J2?Pe?k`㴟D_2¯=`̃/'jL:v1H$u 鿀\CǶi[Q7&]w099V2S(n o齡,tӳd527C42 G2S=iZj, қ㕕DCDD&PdO Rc"lG%0Fn[ tԼ\a# h_P=AMd˪QgC,}~L|bO3BX>k34ZjFr h{PSA>Ub0Dc:_I7fj|ƘW89~jpocoWB_c@n3ǝ c 4"a!lKB13נvL#X%H.Dҷz ļ*AYpɋ磧 v9F]r=u>n8 !+zX80ņ& ŝ!^N Ks˙- U_)”u-D4oAsk:;p]ۇRc̤r `]ug&fֽ?0XSRⷁߗJ:v.Lu9oHh\9"rmbn2FBgK=$yfT$8U||`^M;8ȥ0Ut8NŞ2*Dߡ ^,tcP] a`^#dJ@jNuyQkH7kU&((͂ Wo$DlJ[2|ldlEso'0O!nss~҂%*8v{`7Y%:(QnA"#p=HѕƜo_\IG^57CXimq!);%cz;J k.Xlۯ[6kx -*4rKP2;~O )ĝ:e#cptQ bx~j!T#.]\As|[2334zG1^K"PZA|V5D.i.?5`OQ!NlRΛ|YܼFsT ]j!D|Y>c^//u-3A'H19(_q[;ΩdC0ىì/NT;}0)7 pSq]tC̳:p4VӈQT RX J,a7=㑮af3u'.Aʇ %s.;mn4 !wHu*IJ$BX? [~'TA o #6iVy G9hc91f "o:=G;n Z>`mW5@O7d7=s_ ()fCz~ hӽR 8W$%jHn PШZ2~г+fӷ|`[%pɧt I[b 6h];-Teh"" `}dωoŷp@7r ,*z]c8/$)ZA"6 dnUӎ_jdPENgܪ,Xptt_:k_z^̦iBC4LTڏ`%j>%or23wa%;0w6F& 2J^ruG s).?=L3+>^&a׃6QHt%FQ6w|f^*MO儊@UĮ/k:= /?Td\J~yLnPG}uL@zĞ%Y(}0L-@p5GA8_ܗ;f5/Z]Y-ؖtNrE9Q"ZEDR Pf"+/bu mؾ:.N 5U9hΛL&,9F930ZlUҙOLࠇ/'[YPh` L- 39ּ,9$H́輙5~^Zmc NR'[K֖dt!NŶ4 *ͭLbAnd0*iYD[Ns2"ub>U[ do!cWRB,שJ(MS Jw[)ʞY$Ttdzא1TX @OÀsvxc(ƙAR?tŬF0)#so ( eKs-]~Vm]֬ iһ埓1*%2M3:xX7aOL:^MsHRVTHu{\䲮 NUd0xkU舄bcɊ3_r9|582q>kkyݐ7k+|M=}br bu`by}GΒo5 ZGo:}4ѷZH WDLXv ,;MBB F)`(D䇡:=ļW[/Q“@JԖ&4y,acpgZ &rQX_SQ<;8Rxȥ(FM}Z5Kv'[u:Hfnzw+.6ho^ٌrM\o§J~KfnP<~chvx-m7?LCk^H_eFI Ia[u%h{[C^PvJRAp^mu+YA&7@[(Adԏ/[ҟ.2JA6*]xB݇0v\kRd XnzݤXmO>IvR.r* 1+;wo!oR]'"0H {B. #.vŪ {X N0N}[:b|_̓?IY;XZ ԃ}'cRzՂcg TV+\p Gm(W)6.#Og.+D\gaAB8NQq{mZ)UhrĄK!;aG{R RvO @"X`cY.:.}-s]UY_38AYw/O=)5ODU+b%l>`,}i_+Bd# .Hz/]};fɇ&'ǶH *eY8 $vKM]Nju$8ڀX ]ءOeK ы)NB3(5Mǭ.":SHJh{3븫݆uX置e#q/ 8w;pE+%cSd"vߥ^EPr'kvgHqa; vh"^w1vy* 2sJhHڏ[La! yvH&?Hpz勢UW.,o]zͨ5C!e̕X͗@Kג3ƹǕ&p}@/ߐ S?:ʘŗ:Fz}͓%F= ٩yL|SR8ܹް;TՇ^ pr44$ضupVZ12d{n40MVYr09|@#Oe.d±xR{x'tĪ!!o5Ѱ1I8tX~I˅|[6^.Yɋcy0gl`2=N>CMnt=q,"eS8Qs8 KG]#z~)Dɛ[N: pxǑ2T  t? %xXMЀjgӤw0nWnej{~l ]Bw91/s#<`}I^3>hJKia&y{Qwꀃ"BNcڍؾ@Ĝ"<#QzC+.) ^YFA9!Jyu-D\!bI5晬u$ YFiS:\;(/SwoM$_;4-<~u7}`)="¦uzgםp H1aiV62 j6ge! 0ri]6Zdʈвtl9fiurjT3-?D{*#vgt-ݷTVM~Ӿ|\4!|v n1"$~D>Y/eK.pZQ?؍=b)xΐ8sVfXgMGڇS_>W*i@t&ZG8c!z:*|M,|kH-Ê|7n푢%VZ]BO(U4^2~k:1 [u=m̓U/sZ[eDR7slӰ}1ۻ+h Rܤ; ռ*,p'66mG9A1ERwJ-uT"] ?*ܬ r:uH#%J,IRI mQDx& IE9? :')Dl]Om&?R!Va=b؎X_A,zKO v2x C@mͯ˨^Tx=%l(Z{~Kn:SL%2_}m,;s4CGߺ\(Y=XX af<3qn9+00xtkaE4y}ͯlԮ؍J0Cɘ%>*,KݖH_qc"~d'E¾ȿt3eU&mrr*S=^(tۤ#Gݝ3h,_ՙ<.m_p dG'q68g[b?_E(eZ'7&g5@Wgzjηl.#AulcOAo;|?P#ˋzB&QOX)(Eq^9otT ((/[:vQ8k@YԢmN) Rx\4&PqAl>=L "8cO#e-%-P@ [vq;r6m]n,-Puz,vL<<~NSX~;ac ɹ]6JYwB>,zؓ٧36v9jTR 7Wlz\ɚÂ[֬8( |l_V2`ZaRE:$ I،?*xG߇hkuxN2 Ap(Ff{EޯMǡ&J49bDw}ɉ6 MwO˛N$MB-rAzH!s~dˈN``*UArry^z)Z+nIgG8? Nl[##ݏGY>F$8 A} ӳD@{DJMk{`AsBqgGGޥ%*l񵶈mݯErAajC2k;AeV;s5sf}]h i~)L5eM]mg#|r ) 4 iOϥ;fI+ u#7(uNT$@cz#fРU`-:K>2 q-Z ͨ)"six\5)}Pre>3j'Oֱ \(R[!gz0l?c(v2BٞCB\)SUV?S9BMoh~ƔXSH%?8֗$bG)C4O ˆ JigP!)"ke/~|K@:>*e4Tϸ؏yN:^/J\ݼ*Xf[pHtˏ G&.ͫ쌳m:p IFۓ3`DJɪ.ڸhGdl vOzQC(ۜ)l 레“VU؀?> (|= 3Z۝lҾ6|23хZ رOh\mƮxD;`٘KXZqmQm Fe/#IqRSr`bf,d(1|tnWh]?S\{;^jk&n/-ȡyU\?/dO1mA޿+>0f"E*{GM/<;9\-+ʑ:!N)M{"!ZA%͆&k5#Y$DB#"  }M~1|c\Nf 62Oʧ+ ȕa![t w7<+T/neʏwF\==Yѝ}.bD<uǓej́+eBm/|}Y3rVbsOM)M YgoTwDO3P2wdd)-(+(7|QKo1oоҤ抶,",}4d8KyCF naڂAI]7 ouޓӀGAh吷;mYISl_Y kS3/$_2+toS +:'zPI7:bq>lng=V,Ktښ(Be>,μ0@YZ !u,:B-N'ltm'IHbiVTDq K駳d: eiVUm^@L ny]+| aR " ێݣ:j.tq¿| )sMSb̯'JA' 'Mo&5Ph{AXc}3G y8{r[V<{@w>kgoi^cല=,Zqnglsp-fVtAr㷐 rߡ(Fbu*4œB# `zǘG;4s2 xIʷ'T5䫖f[bS[Q90!,.EyS5S S8.aMgit(*q0:WYM8iJxa4vQhKƀ,[Ekzkq!Q"%6 R>,a.l1L;@\Y=YF sf[vt)\R01 Rc*mi3ż}럮C95a^aD#K=ے l]OGYd2њNN7~V؃+~IJY`@`TŶiUȁ>6Hbl81T * I ˶ܷzWtR xv`w>}"u~ieNqkq0Y0d)Jޭ$xrk-OD'Cxg/MX0t9+9~c| c5y%goښg߱hRFWt'zw_y"$6xTloJ#lښTjؤ9#Fm#TRvfy?{ $y{ӧ\ZT6q^k,Z%5pϗ3a_ qȊBozb8\{:2';àkHzOb74{Kd\B< }Z=xreLsgFJU#,r<V{U06m 3;{stK_.im8[u zԨ鹈Ed'.(YX/YSeR6VMuy w;U#S I77߇" 5T4j@N 2ux%H7HKJցj;Z bB^}K 3'݋8r^PIDp} $bGyv`SZ!KiѪ018)dTÉȏQyϮCFmĽ46aJDcHFl.u UT279l9%cz~8[)lB\X\fx2]KHFXs!f/آ2r֘]Tw흝wXaϯ `Y6su=v$: ̔h[:ƐOdr8od?EEEӃ,M]kxrBoE B7j4ZxUZN@&*xcyKg*YcM寴~\p89-؁v?Q- Q7Y ܣ M湬&)6\%0ofX%9`7v27KPU(F$5g1[#ǔ̷a\=s5UzT&'?EҐ oA8^&n›roqT9E-| RW Q]=/<<(ץ|ĖG:6,`WwazaZJɿţ:„W= P--g5Jd( :} G#Pp&~Ll$tz)Ua^7NuD&.FZпDwb(E$b;G(q;fr(kx#)LKJToњfTz4Jp{ڮg9%b[Y)PN#}(]\C< I#{ C'Mŝ"dȪOhڮ3|DLwB4B :3pc 8߼(к*K _gT_`!jT>?maU@nXkN.TMɊ\)Rafvnq5C's<oE[6[[pl@5_I:4&9ZKmy]$4rd&@xh4qa*(gb2BР?+Qd%k=*@4QF *V]r Gp.]!j ͎>܆f1ʌ5IkN[?>rc$:V׹뿿U-8-όj~OШem0eڹT:BF]Toe &v45N j#@` rĜ CŞLcB7=Rv2bT]<\|c;/d|x9,B,T9:v7g& 1:E2H^fbiF3tdpÏ=n+p|^%A~dgߐ`[LjƓzMXy6 Ę_&5+vk3)w>6 ~񸮧x+3+x0_~|P{~&3ɝ1ox3#& +x[X &n䛧OB#7z6_nh(:$vFoS\ Âs/;垻80yT@#U|G郥=e؄޲>\9 0|T߷::0a3V4Ђ?Zs:^"PAI#X 0*&Opo^&^~whG~z?BJHFYFG+ f0jzo)Jj0/-q;.IHqgʜ}^K',Xj(SgaÙR׏?_* oL+)5ZP*$2HXsjH (v:z62J2tD]V(i#A˳T/B B`卨S}(HHOW;{Ɯ) ,zr*P`1p{q opmAa쓩>"F?M7dP;ꖐYDb%+ĐD&8{{gm]SD7[ĤBb|xsz\uu7EO} .ҳFkJWAm:G:CooϿx3LIp7s+%ThUR'&9-d%(]PSr[T~3)9y‡6*yqgoR\P$y y[6#f1r"%x^^Lm}tpH>󂧑{]̵*S0Ҽdۅȫlqv P4Krkrou()q ݈>aģ~}mrnJaFmÅKbؐ$oAܕ+rk'g"#M2o>ɐo^,r b#ϢtFf&§TWݙ\Cգ c ;X$y_./>,39Z.ǒ~ |2:L.3S9֛$%+ *Fi>2H/D&yRـX l'6[sQ-_fS``!R7$ɤs8r}k{׮//O ;$Jr;M}zJd‡]uJ䀁{ e@jOR>V̈̄*mQ_18zϪ媆7BYA2Zv5-,<cUC5Ikuzͮ>pV59sp Q15"#2$'S@t_}k*|-$p_&E9ˇipX%G3:6|~>D-[;d>a!"^Gc4H4x(Md669, U\!'(0Š۽G\ B+Π3cߙ,eNܙ#e8ZE#WF]gll,BÂeJ㎈`vZFjSJn3[]xvlH艋@SQTeM#9Yv.[f$:xVKՐ*L'dˡڬ!2 `E.2s,O%s&h(}@D 4: YZ