selinux-policy-devel-3.13.1-268.el7_9.2>t  DH`p_.$ƨHt tQe*u@{Y㝛 plԶO%aRUg{\4Z0)T.aaedשjG?(s!e\+M8BB9P~YD>f?!txދJCi.d{uNOSCةλ:yLQ^mors%̎k\ẠWa#}g5rHb?Y L\X23Ih >A +*.)[ŎOlYN^DQP^,\ %jrP @ѡvA`Wlp}p"cmҊŒ8fJ g4>Q;qR$u<7j*$hCRӨW@4w "j2k2ru lInߊ"a\0MS")}{.[lj6498005cddc2b0f02668d6bc766919b638d39885D_.$ƨr;w~hcCoOtи4SfG eDM8/pG yZ0=`A^'x3"p[ū[KCr19Ŕ鮫?Xot&iƻaGgV p/'+UO0-4 3꠮ž4 #Fڇ:ɖ]VP]BUe-~JvUC:*r`"?Z䖹T0h7vAÀrLl@>"~FM Q$j 3U'n@[Rs>9 ? d * ?pt  TRR !@R +R A,R R PRR2RR@X  M (898:.> G RH RI DRX ՘Y ՜\ հR] R^ 4 b 6d 7Re 7Wf 7Zl 7\t 7tRu LRv b w cpRx xR Cselinux-policy-devel3.13.1268.el7_9.2SELinux policy develSELinux policy development and man page package_3x86-02.bsys.centos.orgpbCentOSGPLv2+CentOS BuildSystem System Environment/Basehttp://oss.tresys.com/repos/refpolicy/linuxnoarchselinuxenabled && /usr/bin/sepolgen-ifgen 2>/dev/null exit 0p R^q'"-%$#5-3z+*I[+b$"""/H(7?#3J2*G"&'KH=()O63>)j&0h&H/0t =/:*8"-%FX n'4$7-#3jMw0>w029!B4%48*K66m3-4('<W -* .&.z.^-2.&3&l!*%Q$$FA":4955K*)-:pP9o/UG6.D)>-(252215<$?R.@C.;E6 7=b,t2615w5O4 ?;5RQ#/@}!;A$q06(4N6j4 "-&h7%=$6zLa,J,g#1/(076E+~47,8JC95F%3 Q%!-S;Q5'-&5%8,+7.adA;HBjHS6,1o"40+./`5Q 9?i6./&95754,!1}'$4.38A-()+CG%0./-74>679,C:p/#0r" J> +w$2; E*yF`*c/0v>7l)4QQ+01 0)-y8.' 0Y8e>g':6(:60+(yBG".')\.k=6@,6_a).I947Gn*I/2'*q!{2 &&.*.LN(C$#-3U)I*A19="69<7 28BF/<260'(#@_-.K:`6&Sn.&,9! &3XP0@z;1E31d$)00313|01(12RV'&6^.'0'22D"2D)f2D)f2!(,-=C74.*h0xI!& .0J.'[EE=?0(-&'W/.U;0AG0J,$/b=8F 2 M)B'(7$6<=677\6S6SS''g37K)&0hN3!Y1I_ /(()4& $p%05BQ58f'$#!r#B--I0}=F0TBM)H#0& $%.:0KJ+6J2r/- 4.2-03-Ah55.1.5-7.]37j$S5i6,549q,,X-J*,+=F0="274:..BCr>*A25G?//-18O%0i'2u(-*(})+!+y() +%$\%B>BW#-'8?9.$:04490#"M.^(FO27'\ NMDYWBbY$5ud/ \6ja 3] Vi1>q)II!5 S =s + [*U/V("3^w-q67A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤A큤__________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________cd065e896d7eb11e238a05b9102359ea370ec75b27785a81935c985899ed2df6846bbdba1149ef9edd39c6f18d37f29e5ed9cb3670521f142ed6d7d2bf9f2b8342d2c3aa4d008aad3243fd00e4723033e27e253289356cdf2cf9ec46135a8327bceb4f36b0f077b7a232a94e214b3b0a5a85152e4d89c193f92ddaba3ede1ad60741f180c9cedfbf6257fcddd021cb1c9dac66d854e30ddc31a8b0a03a96f4092a180804fdd8bef056d772007779b5100a7b6b7dfd41450309aca360a662caf3dd83d7b4cf18c9108c468ad5b9def21b02e82e86eb8428a2ec33cf57629bbcf6eac72aff9420d0dbc0ed9245ec9a9fd5b83c596e8a64b986deba69ee0271fe3cf7fd0beed7c2213580b39c93e2e4415a3f7a18db696a324a4f683f154259a85fd3c037b1b8928f9380bda765484099b106cc7e2dc0f83d47f7228f0d6edb5e52dd8be22179c5786c24580a3e976e89a751e8d5876d76fefcd15c57d69df790b2cd204b508ec95f9d91f0e5c00f15ff3a2baafb77c34e95bc8c6f900cc984ecfa185237009605954c0b119a128b802517cc598c517fa80685d0f5cd3cb5ae63743710ec1da9cc25938e97583c80e27fbb8940e6b8146a61d79cefb1358662d9a32cefeb64dcb8ded56b4d80b7804803bd9946e369fd0f0517618a4d144582d0dc742e7d5723d57ec133db6679b190a4a4c8ed5fe2e2b6ec121de81ae1d58ccad003d48739d805ee1ba3a35a29547ef4f05128d147984eb2ce7a174cf7c55213c99c4af8871ebf9186a402ae9bdf52de780de39ee78779bcd3364eb698c7a6d49b9277277f91d66c3f0b3b81a23739a2b772561ff392bb5c580c959794b3fcf253f86cbf43b53e1cace09ba44418313522bc3b7a8421cb1455bc459c0d41e9127d9093ffcbfce1e78d8b2306537bd17454c7d64f19624487b87110552c78795dcbb8aab7bd9caeeeeb14e4ad6cd6f66f6859302c51cdb948add68bc7de3c38f4da11c012d8e35acb49a64c91c25cdede1f721568da4698dc4bb365bdb1eda5aabb86687f6dcd8868cd7c953b3cbdff8fbfda658e0985b83e7dd42b8e2db320dc43e60ff14255389467a8cc41697144ae87452eb0e5dcae3900a9544810120d63f026cb434c1f1aeb5f67497c6d21a8a34787ceca947bcefdab1b57cf23e682a671548cf9a19ab00bd3102eacce0bb1a3bd073b4ebd3f2f249503922ae62a6a4fd89d47dfcd38345ed3f307f9e8e7f973c72a0a46dcb3547cb739880b1bff81a35262ca67b994486835b1a926d7c5bdeefbfced13da67129ca65e1bfd2bf7f2648074d5d30c2b3179bee79bfcff3df0151cc2313f04b4f43abd22355228030c3af0649d9b884aca40f00692aef4322388385f0d53ffb8c2dd5a53042a42a9c5ff62c48f505c8745324536ccc304cc86684e3a4a79c294100343e2e534c9f14b2fb6390adc6412b554f6a42b37cac74bf6402103eed0dbd5e7a30fb9682f0553c14cd1f711ac6464494f907d2a84165c578bac3e169d0519763f4a0c4cc785efd087b443accf79de26b48d17684f86756b85a879dfe5dc90ea38cd73731dc38a2ad660026f89a91f3cf0022364f3949180faf1533ff0628d01c9fd065f257bfb43e9a524dd86754704d62d14638a16d9fc0844c06b9b6bcc0d1dd5e721e3714ce0ff98f06f5042fe1b01ea8c423b298c728e19267e63e2265ebdc36e78a053cf16a892dffee6567ecb5e1e78e99432b5a865a938154ada6beb05211874fe3e1c822c1cac3fbac30d24deabf30784e6c93c2b9f1ed055ba42995ea657c5e9ba3421e725526663c88e6d13706c3d24b23074673f09035857471f869a73f93064dd8c76d5ba02faad270b83c850ce047b789aab8aad9bc2c0d03529cc5deef94bfcc0e6b1f468c033d33ff31f4574bdf3df93db9942354b649cdc997697d78612f6e60702c1f8b377dc883c36e91faf00058fcb1468be3bdac92a693881dcc19eea2c41badd7597eed4b413e6b0a1b18098ae130dec280521fb528d1c5b7fcb8570ce2e369873527083c0e40671f3fe7fdd227c1ce14694d30681bb14dd58bdc7bda0f215e50e1b2cc882454f297defa33ac8931a3f0b332e9184a7b70b51534d5a656f0182e8ca0c0c3e6f346b2b1ab58610d53f66d45156c8a4787cb4d9afc89a59e21bf26f23a12eac4a65e87bc26f42988329863591e21d8d370644b8ea835658adeb0e19a5febd6fdffa5878b2239df22c3e4cf2aa01263009e37a66d9b5b590b94c9723f3fe3529aace969aa066edccdb4b1d0a5e7a55a7dd14325c55e1a8682e73bec658bd78609ee15b24d0f3dc12c5a5c5051b88f0bb09d8eb4291e4da988980f5073ac446f2632737f0e6da52ec0786eb365b767c37f7fcfb10fab443eae688d14fbe58aac6284652b50f911ad30afbe0bdceb6d6487cdba43662755f7e928bc82a02b10c3d3a26335357b0622195735fc99a9754319fc7a259bc7e393b39f4663173d69125b92ebb3cae118fc1a182c5f736f7c320006c3a15c7547c943e51b9ce447199b93a0577feaaa0fefc2f5cef81a99cf568d6335b61474e5af893e9a0ee708efc6b69081fc81cacb8cc706c598abdd3033714e764f964697ef2da736fc1d2ebca7acb5281ccb0cc389312a6df470610c123c62088d2421c50c2896ba4a58eded079963238bfbc66873ac704d49716af378f91ce27feed07afa6afa0c0d47741b10a34b00299e6ea0c81e0113cfa020eeec7b3ba5976b1c8dae838ed83c94d60914ad2dfe3f05b5b3cc394eefe7040dfd33926a4dd00deef926baa8c736da25e3937c6051d59715d1aef256332a1e707da4d48dd27d98bf534cffcc778803432a565bc25b937fec6ed7bd201158dd7b6a70b82d8704c115ed0b6089452f5b9dd5492839527d11cc548ed2458e0c6d3b6dc8eb9dd61c20c020bfee8292ee2952eda2af8c31a14a6e914896f012acf4b37f1f8ae56cda269a62db84208e6f74188a09e93358b5a6ed7f20fd5ff082e99ee9aed0c974488ba15988815c283e5c8174a807cb273765507bd7f81ccb806c2c07564294d161969ffcaa9c87ec1e011c5205b9a9dfcc442eda726baf5ae3e7d1b7ed34b8605147fb244940dea88d0a905cfc1901fe4e9e9b0a829ee8c5ab30318a10d786775387beefcd80da569f734a39d96292ba92c30433bab0db17189041aa9afb5d771f81f551af449ee93be844941a8058fb69ec8eebffbaf650fad690a5a653e6b90d6ee515125326ce6f2e73ea7173fa339d39cd375d92f4da032c943690264e784b80de0f8c7bd1fa55748574db811bc528fe94d909f0e5493a40aada071ed5152523d4a715a904559791952b3a53f67d6c73dea5d666f8507c5629509d55093db159e252ff3bc829f970340c403fb47b867eed1e525f170452051601addab1451c74933a97441f2e4df7360d69a40c5dd37f229381834e969cfd704f2004d7abd7f66db140af39aff54c14486002fcef4334f52a4307dd8378fdfd1079c31619222be8af4aaf30679daca873b2bdedd9b3d2a8299515b90ca8838fcc2e9a6a41438a2108dd5bcbd42c948bb96d85cc99629d669d1c2862bb2fb61c6547b5c261a342ed721399a39a0b8cd5a090df76588994c22d4ab368891cadc965903bae9581858fec07b009fffc9e032d66d4f60e1598c3c5bdbe639d7cf8de40f9bf2460be4647017ef0b083abf930684b461b8afc8ddac46ae03c114d20744cdc6e540a14fd6f481663a254c34f36c7be304df4df2343e50d53641b95d1b761ffc55d7b297123cd625bc5327bb166c7c69b465bf54178fa99f2f9ba54d70dd90204a8082ee02cccb232cab876c8c9e100d2f2f4ffb5f9d674346812639a9a5afd7258a32c9ec0e6b4c5e98d0efddb5a075e615ebd3639ebf0ca6bf98f1f99bb419d8bfd07899e09e821ce79285b66509b90f14cf9f3eaf5563757c251723ee12acbe9f631f439d4e7799c095978478128906b02f7000f6a70dd0647bb7306facea13f321933a8a89935c9fc7d966b3ce07bbcf058292748f997e628fe95a7496c6afbed64ba8c8abf6107af7c0f1eebe17b6ef649a2d38dd4af25127eb6ed061b6cfda3a882bad2b4bcf0e87c1a6f14d44db962caed222f168854a7263069ae1dbe0fab0532b0e4a4c57294254c04949e441eafe3e5905ae8bcaac23acbefb212be76edc5ccf3b429ad604f5fb8dc8c908e13688cb7cf025f2a39b33597638934b367d5d28486403ec15115153581ec86f3b10997ff64c8a68680ff65a77a64a6eccca3c1404a7990a1cfe98218be2a961d5d081b6ab93fc8d73d83def1a68c3f59aac708f06912cd806c1ed5a52a9ecf989913e0a320b14a5520388ba15c28647270527bff7a5574f5e1ef0c07eede4cac54370a310ec8827b017c8ddbea74bec7979e61fa79105db56359d299587afb64e16e2a0e675a1ff254e36a81eaecf9be7eec28fde2bb199401725ae4df1bd5cfa95b0c46684c9f711820c2ab7b92a5924b18109611197dbe558df2c25d6fc7c290ac4c6f8f574967389945fef7fb099450b6074eb68af0f52f4b873ab10fc3ceb748238e8ce5ebd07c20713e38eb8740fadbab75bbeed3d1898f02a3bc403ee004233e20c629b3e0538eab6723ed953f41e39db145747fca1ef1800584b54857a4526aa17c1b3df7c1eb407deba81890f196a794dff12abc2586c3a1d814e148e9c53ed4f3d258fb21abb95b7c498d03809406dbcc48a12f3ac4be825b610d51963d501cec4e18692882ecc033395e7614b957d04ce98e5e913c2f1034dec6d24cabd303e1ad038c3e52861409f7bab53096c633d1c04ff6bb50b2d34a5375e512383ddf7f77474460053ff0fb264ce800bd91821b831e9f15bfe3cd2e7ae3f433205d789555a4b12b729d56bb985757735a5fd2b9ae46c95d07b317ddf72c797597fc29ef7cd7862e87f5441d9d5c37ddc21d086ffb864e3e5ed5a1d9c879d2ef1eb1f2cb7d8fd90495c70eab95ea0064066f71500f99c62e71494a3777b7e2d161c0d1ba6766fe94632bc258d74b52a60aa4af53ada4cffadd3cba499e283e4afb6317140ec103393fa8cd888100264cfabc0ef94f65b4624b27345745de35af6085cfd2f1ac36c9f416572ee6bd4243461366bc42c3e9a03e704ab64ff84dcbe4bb7d402759c279fd718a4abae9b5249a094ec6586a85565e5aacb1320a496507afa3acc31d3fd9e707f54c99aebb165d26926aa4a2066910ccd9169a03a55d0271b15e2d647a075bcde6c146890d2c471348163e25f8bb0eadfd09b554bb583836096b77e7b4bccd6add26d684f3d5793190ded60e630d4e10997dc17ccf531be8cb53dccf93981ea247481dcba35dc237902a9180513a4c11594ad4e62e44159ee33535dbd729ea794fcfc518f4610bd3fa47ad3df72d2464e7e7fd49defac25af7945c9b871d3f489d3ded8a2e4c5fc593228a8ef6c06b846033e1acfae6c4958835483ffed27084304867a14687df814633677c8cd1f376975589a0ce60b47b300833ce8e176a3bc87a1fd9bb0ff8812319a2ffe95c1e3cb0a352f3e7933721e4d4ab7c9c309a49c939e03e1e555820166292ae450fbd0cbc04de7efd0810152a721d32ab6248a4c830b314bd9f71b7c275cef30de5369e99261ce6e82f4f8114b6d718ad6f52d40de0ff33e3411fad60de92924ccfae597f6726fde3f654b43319479d5458167ec8f2de85abcd648f4cccc6bbd78bd812bb720a2300b75eae5c9a8cbc9631621100eb6e826e9dbbc1c80c77b3b9843c6e252795e3937552d7c3a76057eed1716bf764d4e01a1285c56c91d313e92acc40b6fe5cde368a9262272730bb9bbb47dc8c5e0ba80945eaf45d5bd5207afbad00704744fe0a55c47d1bef8a3de92afd155385205930be35e852d089541b9e544f77bde68596d40be32686f590282d4fab8c27115ee526461236f4266e681bd4f49d0ba2f4ed054075b47c429e0f3bcfcf6bb6631edc55d658d17b767712a639f9d5b0c8d1b83b9833d99799481aeb8cd2a73deaf0cb2cce684b7d7bea1e0064db6e41eed40a5c55ec619d829dfbbc4aeec9765cd69e0e72ce8ffea0288f9c6336b68aa3af34b61a0f3fb21f7d4acc7756493c3005cf073e3aa9b780571f8030d42a8282e475ba246a9d393f2aa2974b076fbc3ba5b2edd9d69a47d433d92cbbe3305adab89c95c7094501e0ad06f61cb970abe55562d662aa7cfa7a7df5d6ee4cc3b56f6402264fa59e58feea25b66a42ecab6811c80b8d4793c9e7377fa1c908adb41c22a9334bb24b5d4b2c763b5e174d5e6994aadbdb5f4f53fd2cc9c491d54a106d59f191e3df01e83459831da2eb94f65e2b56f373a0eabf5db144085398e1aad93a58689a094aa9debf482565718463c751d82d56fe3351a14cd70494f5cd837928f3bab4aec5bb2b52e7d016eb9d3eb1b8a006f22d113a09379b9e370f4e3dcbfbb46581dd279543033f605a7f7c11916df89be3b6ec9a6f5a9c25db83e908e063e52e32c6148425fc44f134cb3aa9e371f67c1a9c5fe2065c616efc19e99e8e772f69efebe36507bdd7fb5a4218babdb91f9b5253f031b94811a98dd64c82790aa29d49921ce6b88d2be620239233a54d509b1417310f0b6dcce2434eb189c26e13c8380f704f75c65e37f3e935d0f6815ece1b7620fde20a4d2b52b6aa7fd394d3a7e1f7bdc89a8e5a89c10afc751eee26a3d9eef132a01a30e315592d029a6de3506de6b593c021e541cd0407d8dfcb7636e26629c7cf240f82786dd462c7e0eb44e2230c82b1d2ac08435574e9a766ed992ed7c5580064f6771765591f5ccbe117b8d381b6866c8696608b560aa6da5081ef68387e41f40a6016183331d2573ef885b3c548966093afab765f43904d26d4dffec297ad94ab2caf181a5c9dd3ecb2a4366d8d470f033511724cccbe30df3f38c1aea7049723f0280914974fa1a070510fbd64b6836e6756d11fa75ea8305c0c89f4c3bbfab57e865f500bd8b19af66b085711036f6688f1a60a37e72621315f2c6a9775716394d1b39037be316a7619619e9cc3d11494d0a66b21c2b342008778a31b435a2907abdcb521f60fc1162cbbc91dcf00a84edf288386ef715e3ce126afeca415216dab1abdad2437b8af85c2b8994005d90acedcec2e96195da40a4e020482e07b2a8f0cf56442c1357210bc2e8062416ba625d36e15d38f6bbaf7f267382d09b14fd16fe72e3808a3251d39953856cd5fef5f048ffaafaa066a72e0761dace84af0579cf91bf21d35a65ab44f3df769a205ac46e4099441b60e313d748fbf68a6178a96a59d1b4a29642ce0d117f36c989edebbddae40abf5170dace1e0c3f6309e2adf72c68c8b132d2ce359a80c342c7e63c1d1309ca6838bebd68938a015b284b530228ff4a00f129c379d5bfa6f78d0011edd9aa63a5c2193ae490fb29127fcaf31d96818fe76fbbd59eaff8ee3f79bad10ed60b6237510a96a79fbea8fff59458625b537f1b5ee2faa76fbf61ae64a0b7b0f931be39e5aae0c6ab5bbe120f26756acb2a69622185d8f961067ca5707a795e44919c9e7c55e7421873e1a72ce63e89e63ed2a8c8d6e53e77926214d9bd6bfbf8ff630ff120039c82d9da492ee17773353131bd9e00d4a157689d62d3c2cbc4cd6e85bc67eb836343c90010a843665fe1bd13bd5709f7c050c887180c8bc8c14f24ec3fbf329d97c381bb85fcfe7ab5483d4a1dc6e549ecc57a12d34583a198537f01854a258ed8117a73278202d64d315d1a79bea1f34ac2cfab960cbdc3d2f6e48e0dcf2e30cb039ca7c240f7c13d53c56e3deba91622321d63d48e24702971f9105a319a25b1dadaf8f89f201ba4748e130f5a190a41f5122f4ec7c55e3c0ea6930edbcaff05516482ad11d5bf7b2faa7354396656b8bce9ebee93b607747da8daaed7b0a43d228b3a4d068a4b24a82828cc5a64267c7cb742f79a3095625dd95e664e21ebe30f3fbe5f77c5a58a7a8bdf4a36d95ac293b9b668f444f62d30c0602b1388598727c30261c69cf4df0f9f4d1bcf95b83e78c6278432fe0c021c438684d19f6b0ad2172231913a54518f597a5ba5b7c9992e964b6797eed6da9012e8bf12e4de83bba951c63cd12ec2443f274a2256f7a11a849c5272a76b58f3e7a92412c34a8055a8d2795339e5f21eb06e77ac8bb5d02914a7e2f0ab4a9bf7902bd2bec47e88bcdbd951b716f278a6a96d27c1267cbefcfb1d9d10312ffa465841f284f1ad8798fce4ea556d4d8f315f730da4dc853ce2dda3900f73c7b5010252c77dcb43dc8f92e98ebbccd0a46e5293fdd5e1bb6a01924ca41dcf23a18e8972920cbb7716f4b82d358b91c343febc6c988188b4721d74109c6d720ef3a66fbfffe0ddb1764cbe171241842a63a1596418fbdaf7f636d0aede81d40a852b5c83c46c77f13036590c71ccfe678cf8e01c25e40513093f61337af3a1fedc16fe375b59d3188c0b78ded3dbe2151b53f5ea068e3df6631b7cafdafbc5ff4c4708b73e92be08210eccc9dfe96861a040afb06198fb9ee358d12ed55d6b807491bd6072a567815e89b3226f9d449020bc1fb26737319b0a97238ebea56da90e86b07a148af095919785fc66ca6be5e203d15b5e0f6d60b3bd4bd777493e3f4480c939587dcd2b5c19e80036c3c9bc2db23bdec1249437307194eef8af1716d6f522c41ced754bc09544d91ddeb9ef095075fc5346640a74b21346b5515dc08d185b62fa190523376d6c58cf91ffdb7cf550a999a44a3e23c23b82056866999425c24d64ff9f3f3a2fde69c5d8b425231617deded0a7e65929127067cd11ba79a435d9b5feb91aa10d10368aeb84d1f4c61e6c9c22107ea8fb3bbc385e76b1deddd2dde4610abd2257bad89e650bae25eb3bdccc75e0cb32e7fb39b989f5f5569281b374cf96811c81934f90095b55b0c19ff554c4988c249f50acf329c0ed7514b39b6c5cb401a4223446ab473f06f06291b377a4f0a90e6311eaa46314d4ccdedb20f14413d6f9d78e9f79fdb4bdd9708a054498b4bd792437189bf48829cbca6770c4f404468da3b73b6505592ad1995ed297b2222d3d1a127146c31e9f79d8f7d9a5f0ba2c22a289edb3b0dc84b4d69d92372b317cd1a6913eea50cf2217a9432f9a8328e610b8c5027948a16c1cfbae14682027c630d8c3405e71038a1854c1688c3ffce857d1f82cbdb3356e08954dffdae4a7ba4ba676cf35c1464ff7520579b8bc11e68d199b1ac69ad6ecc3088ce76ef71c683cdfcd22adb059ae11e6b1594daa59fd68ed8591a7f001753c773cde1a95791b9c9f56a379e10578ada5fb3e7d40cb5550e9cfade6eaf50a0f0fd7410e5f3050df949d25f8130959ffe39d4d0a96f04cdc4324be2c2a09e0c4e194a1e4777adcdf614aabaebb285df8fbeb5b788e468b069a4b6f3bed4ab8a64207ee9fa60af18f6ae2fcfd9ecf21a1a036822789320337449fe60ca4166061123760b19a72863de4c4de5fb2d5ada7b67f8ca2296f77bcb9c6e4d2345ea72e088b5f808ac9bf0aa7721f2932769aed7d2c9d4a15b2c011ed5e41b55fa85b9cf8e91bb3f574d1e098ce72bea3392d7b4521e62d116b2dfbc0547d3446fb6e62cb03e67b1ccab77eb776e52ba088e8ece70d455651924a472019f1e77a8393d11c7b61cfebeeb6bcbb7a99f8c4a0598d37cf6b661bca485db7d6a40c7c35cbb8279b339c103f831068db98f9562bebb381181cb2ad9594310fbd0dd0328c4c0143b001cba56c72c759a49a428288250f55b85fed0f510f1fc43f02889bef506d27a14d1cef64128863fea34626d458ddd53c1283d7886ec703da46c04685e076f7e9392369348833dd52c18cc3b6c5e6c38cfc20928d1b1990b68cc51e4c7f640a149e7902dfa1295cc38f60cfcf38c31f06e9b96d27dbeed846536e3a9734101cba28e868712643e105e427df600f0aa746fe1ed40760739cbe31b5424c7e0392cf282714f46f0eed6b80d142eb35cd8d106e88783b6dd44cd7bbbf474fd90a415cedcd1dbc88329db549ba71ecce17a7d845c57a915fc133cfbb7a98cc91d432aecb6e81f7a0b6b75c2320d85a05d2d71ccfe5892665e03ba1359ad1bad2bb0aec5c1015fc2f4324df428f1dcd10f92d345f91de5517b03fec9a5d94623ec2e2fed6341c27daa5dd377e3f64702c451ee4376a383cbfcab49981669f83881f6ba53a21f6335089a4559a4812912dbf78866084fe8fe5368ef31a9438fcbd03e461f270c26425fdd08ded4a80deba7d741e824469c710517dc90fc5208bfedef1f2edb2b0e32be8df0a573f52c5ecc920463f774f44f1269dcb0f2494b1611f7969bc71cc288f925f9802e04f45d7ba0889ce1c9ad57059d037c84b5f4c1fd4cd53062c6d1a7345e611442d6ec0bcd73eb13a3a0b5ecb1e643c37d7030ad92d4f613bf8c7bbaf3accaa6db8091d17d749289999df1fa11ce67ce2c33443da3c7540425dc13c3b8677e740da4ce01fb9b9213d1cbdcf4bc0e69169dfd3debdaa7de4945d68f8a94ad242deb019d86a26ea0d46ac9719055fb4e80ff27bb42f9e49170bb5f991f6f633dd23a3c3f02a73fb191b24a4b19abdb0a3a27fcad013ee294ec1aabefdcc0c18e50eb86da8d16d668904f27dc732abd5fcd6ed88035051c566fdbc474b1ce533549db5c40e2eb60c958c8b501485c6527d1f58ecc50850cc3b0a0bcbca16fe70f57e1f471b21dbe01f651a8f785669fea8f93bc7941c63fb6b3fdfcdb9226425a500bb9c46b321af5f1bd23106f257960540c6c81c0420217269a3ad6f3a7306901648daa959674572f7eb0fb917f957ad00200a8799cd159c676384b400fbf63cc065aa316c2f91e3633fdd9f08701f6929f351aabe00d78ba78797be7ec11f7129b1fce13dba2cbe12fbf197886edb6d4833e7081244dfefc093a1c16e752fea8cdee1375fe1b2fafec4ac9be5afdd254fda5086f6ffc58bc683b288a9b3a4cc913c7f25160173eef1384c64ea81c22b2c4ff9dfb28fc79ad578b10f1b49d2636bf5a3cee53c94300e980e73bf34fa26eaa15c28ae0df1b8053ec7ebe318a8e98a01de00d8ff277edf4c388a91e6c39eaee470459ad1b4ee446b433ca2bf178361dd6be68a55dd2cc1f3abb54f89df827114cd9ab5c1bbcd303caa29f93dbdec66540298d464bda2b25135d8ee26c492571f37dabfa889094306a3b4027cbdb0e8c96b5dde71722b8e3f465ea578b79ea7cc41b5877a1b822dfa530dd395ca8da00c41b9aa19b84da05517bffed3e1a38828e4de454b950502a1ae2d2e3daa80408bba25c5d13cd31a6bb9119c184d46afd83baaa49043beb7940d40af5a68c70c4e3c8f715997eb4b5e99a6540cd980c972d7ebb2c597b8a0745e3035f9798ed5e4293de9fbfb7ffd95fc2aaadcd669ee84c215851c8a5c2743578c7478647f4f29cca83b9a7af48b97a2c5120c60a7f02c4acabdea0e6687e0a9d5bee5a8f9a57fe7c96637fcb81d55899f7b53fae6d6cd3d0817005b1817d6b89f54612f324290816bd8fa8bf56dba515be264109884e506643cf5ebcc417d96a1700cbbf888309158bbffaa228e5a945f84a878ec7cf18be4e1ed6c4f6b24fef2ca84c03394be4270eeb92345abceda4e541b0a788c7f2f86b9b785896ddd90f637ec1de6c66b766d83cc965cd29cfdf98209a7229f1e91162ae0c04b5e2ae0ffc21af03c2111a0e4427999df9f52f3409414c80d637eabf3172d98bb7157a0ea25c947c244dcaa2221f4979bf91810e9f27c51225dd97ffac3ca4eae44b285b6a32aa35615d6a654a777e0bafdaed2bec077b8f4f3d538f691b6b54514fc8578883983cb46b28eb91655990a31b7b5e10a09b5ed4d4d8ca4c8874e10f06d50bb0170cdd036663aa36b9740d4767faeeab59579059e21c0ce723c26c45a5b4941a3d8424a2d3a9bf603d0ded48fe320abd169bf6fab01333e39b57b0ed75105d913438734d4e3097d322406a8b59bbd2bbbc71713e1c0186eed6c47040feab643c0d39f5d6de1eeccf41e0f870be33bb9211039842da3e75c8b89bd9addcd67999f34e99e56fd2bf7fddac2b232e2ec167d5d24d71c03493c5f408ce3ee9e9351a606c73c5ad0e4f1cd3856c38e6291969f4c62f50606b3c28f2197176e144f438d1c442fb2abbb29520eff9daa6acbd2e91f446e00ec786d7885be79dbcbe28f7f01bd8e92a6c45ad13fc026fab0ca98415541e9969e97f51f4ab1a4f370708ccf3416418d8b7d4b9dd22a823a5496a1ebb30d9071fe9a7674ede85eac9600b271b4eb48059fbb45f8394f2d4e8206478b63e08af7dc65b257ebb89ec9ca1cad0bdae995be7ee359ad5fdc67e8f1a6d3192d15f92b80cf09f9622a2b997654861be168fc97058d326dc349db068e3f3123fb01007a01ee55f271b82ed11cbd3d181a5137c41fb6b46e9e8931be54d38f86c953b2ea60756b02573c6ad559491bb552e7519cc5476af1e7d4777f11e15679f1e678718e5aa3c0a7e3d377ff93a212a11f84919b5e47450c8637f69f4521c1ce823bfb9d92579d0c2734f3ca9856fd42977bfae8271ce5da26a186425de9f00df6ed2b41a63cb50ffb3c19cf592600d1b5f7c3751cf844df80385aa927cd409d404a7c129bed461bf289e0bbfa85ab55d49e96533c08337bb08458eea927103d462924fa4cab85c3b8f27de338d309eba73a0b27ac52504a19f013a15f357ce76803ebc3d486327555abe00feae820dede9785982514dd934e5dc690f45993539508af9823eacb14a54356c1c8e79aac51aa0fe1ce1e4003bfa6cb3b16dcd4978d7df212361224edccda6cdc6fed679ffda9b2c6886c24bed719b4733208ba826852b94ac6510196f183814035b710a4d98f474a70868c482ed8bcd051b45d3c2653ce314f235d940608ac0f700e0210457c84452e19ffedd88df5ccfd3cb87df3843739064f07f4c4e732500f69efcbf952ffb13a32bcb256d225b093304fce579ea0e85c0c2e908886079364159ec62dfd1f44e80f8bb3669348865ad3641950757553af447ebac35c7dd48b39ae88d72d077927d9c45ddb182a9eae825237d54887b11ca4a748faf1ac6915ac84f81c4f8ec536598124ebf9e64d4f90f14c013ae495d2da9953d9be1ab4e23b89c37a69313e8a19c026e4dc88ace8d586887181e36323fc61a97f916a2aff9e1ead265ad4f63e7ebc59f9040e5e7340f57d7e82946f6709d41ed35376d7771f9ab31ce2dd272b6f1d88cb9223b8ef2a95a039ee0ce75da38eb3c9a643aee1f638f6f3a9b2c15177d485d7214d9c24d7a8fe9eeed785101c0ca6c465d395526fbab548728ef4a100e15fcf22a35c68412cce2bb77de55070262785f6d131a5189440effd13230113a26599399258490e0e51f8aef99396613d471e164ee3a094ebde96058d8afe6119881b8b9f0eaf909b1376b082de6579709403efe9485b87ab8a44832bf9a094a2fce53345d11a70f112a1e654f98c79ada56cfe9f4c15d4abb0d462d13bf8102503a772421e046d4783b8267b1414d7f299abac28019783137c4e2178a663167ef50422623166a3db442c8eaf9c34fa90b357bb5c370c2d10fcb0aa0ec8ae0e79024e984279ece2672359ca2361a9c26267bc2aded984f25c85942584b5174c1748ab22a2055ca1bee3f9fb1e45bd7aceabf523e89aaef5dd96bf7248f27e9785e2a666785619ced18736c2c1826fd91c1ceffffacfd7474d22692c94df32921933f6c2ed7facb3b988cab178d9d3fc54d5b21973e07fad312d250f7ffa3afbe6d23f1332d408bc9f1eb75f7654e3d713b7fec4e95a740def043f96a2ed209ebf6d907a0f4917337a0fd3695aa798e10d0a04e80ad04b5839235da1795fd94c970af21b7af0a7cb8f0d57f9be51d7a65ddb218ee5a3a37bae1963b7726bd507be24c09487ecf4c03a826293bd997abe170f0809b48f2aeacd928f561696745785c2a1db58ed5fcfea614c7c498b1e358b224a902acfd84ed0b8104b3a7b0d208157d672d3337945dc2d76518fab8b7d91b3102ede625b4d9154c0beebc6e18de9a67ce9eb0949091f1a6af4ca6c6c9be0deead9b61e6815f9140b3cc21e9a5ff4519a7f861f9995a82dc57e2a2a1bf34b7c2c7b26cba0315b6307a707248ada7c1b5e42e50a57466d33bd6814c72ddc0eec4ddaba4594bc50bda20ea0c7193139fc356b91bc9642f434524dd1f7038cd0e643b9ce0e76dd2344b6753f3974b60e96d17ba2e2c0beaad0f43c42c8e5c87edacf56a53e32a19f604c67d1a4737604b22e73c82883616ab8a1bbce043e36b77669b1a45ac30d1ccdaa8d55737b4cc7f47ace4d6a744610e8b7a7e9e0131e289d1053bc971cd57f82838640ae242aa85c853062cd686bd73a5267f134e22c5531d9a62fc0f3fc06f9a8d831e156cb0cb4aca0e4ac153c7348914e5ab0b960d8c907efa8e4fa6c0a7771991cb502a9d3b51bbf0f85cf5281687cb031799433dfbc212a7ba1eef61e3a460366d33a9620d21c22d999dda11169e6cabec78f1e2722b89b5aebeab4ae69241a24ead44edbf4bdfe812a91b4538a15873faf8ad22b788e639afc917f50c429b96509035d5f7987ebb2cbc28532f86a6ecdf8438c561df8447e8413bdb55b21c1fae04b7ada8bc49dbf4ec4c4f38a2ef7c57d3ea0d378367fe487b1c51c54e33242f8c0dd883e4ae13fe9c8ff07daf0aee7b6bf0607c5e7efea144c1fa902aa8e8f771a5682b6f0a5504c07a7895c87be9cf11bb023912d4803a096e944e6cc33ed8326c5a5781aa49fab8dad29395df051d5144b4daa74bed7eb3c635b6f587f142557644dd05a59c20f2cc51ce1326314e03eb611acf4dbd34ad55c71a1f0a575616ed37c667e96f66309cae8f345d837ff8d1318ed5009b2b15251c04f9238ff5899773e8d0c158064cb8619948a32f6bf442b6677998bda5533d0d7ee06a412da66665aec7b57c33e29243b7a74d83782d3de40f1b7cb9f6a7011da9f3a31a62ce80b7cc2f3e6a0576217ed2b2faaf317288ca3f964bb32bcba4adb70dc507d844a465db787c8b7e8e6fb5998b0ea630eb07633d4bfb895d833a7c6ef08bb30f86962a2685941d58b0a5226cc3040601f2bf49750e725dcf26825b689873f004c9539849e4227c3e4e3baf67e6bc249257a19afb56608917d9c499de12e0cb7365095a23c83d70909ce40aa922a22ce053717918be967d5b58bff610b4a61b296bbaead2cc34999287f29c81ef40a052293324bae3729c25e300248bbf704314eea5275e4fc0e2eee9a3b7ce465a6bad6807f97a671f35faafc56c767055f99b333483fe2e1d05f3cbcc8bd0e73ae59fef44b93d8977df2667b5b39e0ded9d431f17cad797900ec48d410e60d16af32b083f1189b5ed16adf88d5046397b35bb337f591e9790b79a1139d312101bc67757c5e60c5b4b2a78d5d91e117c73f7119e8dea3078113712ea937cfaffc0e9fa965645c8bafb2c7ee5982745be7466d4fd7d338e2dfff6d25873271a0ea1051591f0aeb95f20b1642de52d174fd2982107a0c522b5c6186eb380062779738a12006e588df597c62253da9b2ea0379ee80d2a32afeeeb5a606d1be6f8160408d15ba76267524e3b4ba90916331cef6ea9e8203e50dbbaef428e807a50bab29a237836ead62f763643da024a0e7e135593ab96689f31833cd2e6d6fadd0162febc880a0e47a2a6575096986ddd54e79d57ffadc237d04d5ecc9b3e8e47f3afe4622b46ca86741ce8f705db0fcf88b642c003c53454cd2514708d95c7199ca2c7521d54a96f3ea672cf340c4411c252c7a4b60d6892f12181607c2e2af42f466bf65f0f5f45d45f607d260957c99f9ef11bc0515eabc8e5b54e07fad2b134eebb28416d39d0d60a8976f69c18eb44a51715c9fd9b4276ae9824c3fe35d9368d2a0347a6dceb4c1a79738494d8ec5348ca323a48262a3373602b2e82d022080832d22991be5a3f92e78959d0f8617549f6dc919d83db02a476c371c5d8579bbb4a93678f4b7db19f4bdd62ab2051eff2fd0548e4e051bb28824295c1c67aebc19274afeed9f30e1e77bc39cf3c7b31c92535c48fe791db58fec8ca9e77f2fc9e28cc9ff518bbfee8e5ee8a3cd67f585096a13c6fcaf6ba97e9ffc42deb2e88308254478c5181b9edd8c53981f0262ff4b64dac6d668ae2aca739d87f3683b01b4bbf7079037c5a13fc50fa4ee96df60b76dab92a1fbbd9cdd5492421ff791b90a3f745ae9a8e11a576ef223347803a9fecb2db17bc4dfadee23fffa1917ac040df0ed17dbb8a71cf14dea96563ab6a299d2105c07f243b2a55aaa657e558be8faa4843a4f0a8da315910d68eac628101730d4e171c1beb3035c697daf4ec14edae315f523841599d7f306235d256aabcf7ec8d8f3ec2fb63735109f1f5f79442d9f938f0ca5ccedb74cbe94a02cde3fd4fb22d5ee18c813ded9bc2223a0c7b0351b4580eaecfdea4b26252927e01c9f669eea4211b4af196538187820f15c3ae1c906c659ec12ba4bc7722916dadd8fe1c90273f3aac1ea4f123babe7863afff71cd126439549fffb8df5b343968ed84aa2bad3433b9a518d065a762045729f29d1e64b57a9ead48b6c35a9440ab06284a389178d14ef85f7af4e4d47908ea3894af25b80c4fa3d9cb439b9cfaaa5f20d853ba3aed248fc56856c515c9da811ae572af0cac493ab89fbdc8073cc853708689f9ae5360e00bf34f1ba05ee6f542b3afa3e9e4e80f2489334e46107793fe0d288cff42323c70d65936d7450d0ee77a8f13f0d46a777468c92a8385493b19ac305dbd06022f240c62966e2017a57501cc0d99a77b61d974696803b358e2e89d1cf5a0ee127d2c7ff1b09bdd61efaf0930cc54d36ef282d45672b5320fbb7925da3de0cdcb7c13525c15bcae74f37febd5b99617a915d00a29271a55d0ea22e9df3e1de1e81668cedeb3315584d35ed61426f21f1799e0e8a7f6b0a9ffe76a0eb9b93e35e03bcd9b122438b740be4cc3d2856e6673582897ab01ef9b276af4a30f4b1265702597c214ed227feb346d6f7e816409501bfb844b57cd5698bb2a266d10bcca92a2ab68a372c2938af9d7df5b5cacb0a58fba5403579105e9d72380127f8829a92f08197df3c7ff43dd5deb9ce6dc7497b9f336ac8642fa231dbb65048e91bf4dde9df8bbd825fe1fe481033664c520d16b377b6380b6a46eb4990be66a1d4babaec6e7655f73a50ba221f3fa1230634408a20fed0b6e8e11994f1981c133e2e0ce39769cc456bb93f8bb3dcdc3fdf699013bac1583875cb6a326059ced1d564f571d2820c95d447189122becc9dc5313df1b9742ea9ddc4a504acfc84501163548b9307f07102f71b2ca657d2dd407848891672a7ceb9ab863396ec3ac2a0276688aa6951a0cb542618b5c2a9eb3dfcba0a6cf37bca3dd80d7325a5526c83cfe4d3314d8457dae6e1de3814d16be91e67c677ae7eca0dddab8216ecfb9dac376cf63d66c968b69f25b195aedc993e5666494cf1c528d516f8946daece216617258b595f0c1258709627e95a20ff7128dc20b4faeffd37faa0f166389b41a0c28ba23af9893f19c1530ef533d52b8e84f074690cb6a2326b69e6e9d63056e4b08d3b8f692396cae3340893efdf2e54c467e08bf24b8297a7a61c72b5548afec89678a08e5cc0ce507ec813e3d39a2e27a5888095b5279b8d969aab2753055911ddac0e7a6b00c548385470e52abc4aaabaab2e830cbee63d4419f3e4cdb461242e6d28352646d2526e8367fa1b636f52f7716cf5f833e9a34633cc1457c9f71a90ccaf2550b426554f40af5703b5ccefd083cf554786c1b2bc74ab28f1e2c80588e53aafebdc94c260ba90132e1488c73eb73d1a564e9f04ce8c0582d5fc61371e5f2f4ecb48de16969eb092b798ba3ffdcb9167991c9d62893bf7bd5eb7631f0722048ee19742e2699caddc4cc058804d6890ba6c4ef466cfae2905fe6e75e74acf18ba5ff1001574a66a58738381173c6809fdb8eacdbeb9dca59bee5cc2f562347a09ee01cd1e8ff062869067eaf1e2db9de994a7d6bb1fc0e155b029d60f4f86511ea210a273e19fe573d42679331e210a9e0804598a3bda0bac8a6d3a1f2c0ca3f85b27335dc5ea81a3a77bd4e3cee03184f199939df399590847499fb1d23b41f06f3ebe20450d1aa72f192e233f8c0a56d4f25f95e153f72dff8d09881477422ce1c817bbed2e6925bbfe416726877b42ec8de0fe30c5f7e050219218b21b971289647b59f2e5cb0e3a350045905ce1085dc57a5340221ad0c565d0db6bc1960b0d68a4cb7e67e9e71767ce412822ef520aa9f6b5fd86ff0b0d8fc602bd4d9bfd55157489131a035a82e1547825016d71b6aef94e056db75360c4519ea66043c584ee9ed418ac0a09e80979f3dbed93930b5900426d76ac1a5343f2ded8d9cf6f88cf22f58f374063ca698e2980cfa67a224d1a2a108d7e07d664e3eaa81fa367fec950e641515863683ccd7df9fd16f4b51b7f4283f7f422f5f72a761231e915bb6bc598f446ad52a04a091530dcac899df86ac82d713600761be7fdf38e209b67b5c757aa5c2d67c17f834ceea7355dab93dc3410acc579ecf21867a9ec272d77ac564c70a201e18ee986e671f0f1b54bd5485ca3d6563fe6c860f7913c8895c875961e2d438e068c4f4e702b6385b0a870086e3a26da4191a2113bc56ba8a3cf92eaf4bd03012ac80d9fcda8216419cbc1abd3fcef6b6682fa69b94b0eb0d9742420b8d2a00a5ef264d9bf7a4739221725c235c11475c78ed2191fb98e46145ff3a56f303a4678704dd7671b2276c21b48fde60369f3e3013743f39a50eed88d9d550bf65ca68728f069c5fcf906843ff5412c77ca200ba0654437713ec9c108098434e5683a93fdb550ea202c2a3c4f213c97ffbc87e0ad458561f855058a2e6d19d2f2dc80e737ac122e6e852a08ca1ef3db8208672d5d265dc0f838fa197746f167d75b9f976180cca7debf06b8e14a9c8d1f926e118650295b9db28ab98a8966f352406d05c52661ef3353d8afd5922a36f39640ea2cd79d3a6064b649f139c849ad881f34624d92a73a7c437750778ad47fb468c1b0b9a2ccaf0c0e38f530a7cf9c71bc54c268f45fed2b275c7e6320a896d44a0614d71b06f3c00727ab8f6b677ab031500f372cb0dd64898d76f0a845363bcf830bfba5c65dedaf2d0b1d0cfc728f219982941fcb3dbc103eaac0f3e10300753c9294ce49ce617fa76a2e2f61f61187c76c4818cdc1b9e85b779cd5a71ec0e52aceb67267bd69575cff3b6b8a7bd046ed671da9584216bc73fa899d6c04cff54f6b2c75be188b6e93598d26dbaf42b0466192f244aaad836621956a0eacca16da96b6f07d02833d766bfc28e4a91e89c640edfb4539a11dbe92595933b0265a5830a264583dcab11bba731c8074998b01a8b7c029d96772b15266c33b3d431b0b9ee22edbf5ee80ac98d64ba0a9a7e3621f7c466f731d70709ff890816a50be07364254abd7c003e5dc437ead7ed2b4b2e6224a56eb63d48a58711b0a6081b4ddbcad5074d20d4a8ee2725b4d2afea61aff16e01bf66f976daf18c75dfe4dce08e8390f4221e500ab0b4536ee4ed9390cd3a2e7cb2712018471e63f97f2004333da8b0bc90c4707bd288140794a98adb4c507ac3135b1736cfda21feae25c9db970bcda06842c14a00f7a58490f94af1d6445e7ea8b3e61db3341c0c8c9d520618a5514a17672111a7912ff9e6b66650facdea13593528c0ce94d8c8623ba795faee57fce7d346c15ac341e01546accfd54c4c1f7239c69743a0c1e1f2b1f0162a9bb6b73abf71213a4ef633dcf8f79f3760a6c70a9346b696b9b703881ca0e95b1ba125a767e2ffc6dd34d6e008c5d80a13c54556bf54e5117e5b048c5f5995861cf14f817de5f8b8b80aee070b5aa9fb634773a22550b063b90c32a20eea2fe98416e55c17ddedc7ae052236077aa683868fad5133d2396f2a696a6bf539a97b694e2d8d7e346419b51ecc19879f1a38bc46bddf51030985ed8045b97688b0915dc93b9aeb67e114c1173e8ea82c6a0e8131b4a6a1398b512ed62754bc9df2db0de460772caee7c8a291912172f085948145bd9949dac3fda33b0007206fa51b118160cb0d8e9994f7fbbfc86dcbacd5b5d8ecb2ae2b947f0926ab353ac4147b9abab2d579d721c51bf41a2d517f23cae841e26ce62f2b1894e2f0d023ff8c2cc9a1d4d3d7b845bf491f567eaf4a0ee1743fba06902beaf9448cb8bf543217bbb0d5f0d07080158029bff09856b23f38afcfda6247893eb3ffedcf9101fcfb95ad65626cab5e372e3908ea2dc61ae91ed691b37f3ea3a6115ba7d87c10b22683ade04f321e43c2b5bf9a3383f59d904b15a5a01082e5c8ab750599768da20c3fb23f2a2a9b95cbe8d6d1ca4ce7032a94a05b6c5e97b9fcfa00d32b17f623e0758a710ab6990a6b04306746a1935aff2d7c42ef94c63da4329aa26a8960a847dcdf34aab67de050c073a21ca36241483c8aac0c53d326a205535b88fc6dcd2b10c2edeee3e9b3a6033b04ff0363f007e84b1a03c403e753320df9acf43eff8c9d9eb3b3441ae09a540979f8d73828cbddf259dade00d314091c513577d5732e639943b3dcb029d94cac6be94e63922805b3869e991758a8d885577aa9fbc0e20611383935d9978cf3d5ef7be8d0c5e252de124b670939a69a31d5c407482d2985167bf19b2276572132b5eabedfd26104daf06640fb39d49bdfcfe1413993281775444d06c1224f2acd38c9b12d6ed9c2db5d7dcb63283d0b63e2336f3731270a6ef08fb877a374ae6aa5a3014724d2e826607d5c24db79201e5776a6f9c337252196d3b3b5ad99175980d13685c01e8b7c6c0fa6bdabf15aceea40de16c093caba6756816facdbdc532526b9a772fdfc0a8ccb797e13d413bbc577809f49eb7a183696603d94fd15a2ebb5b671b21c30d61df99ffc03c2c80483dc324020d8d07e67572c2627efb0552bd92dad77cf3ccc1d3c907d07349edd443536ca2fae6ebf8709e8aad054369bd3ed171c0f5e97da632eb870c3ba61430d74cae55bfdb5a0a7b4ecc661e036810bbcf31a2e2d761dc3ccaf9e7af1dfa533f18184778d4983ad4ff78f6e798975205c98a981266000aea2395d420017cf0b31f47b0ec26bef2d57b6c9cd5040be74ecbd9857e3e0c24474c091651d7e99608636dc6679bd5ff38a2b7cbfe98bb60d01ce7ed9cb705e1883eb67bf96e832202f5e3d6e29a09d5d4e6118ddba0461baa6fe12317efb44e22dc1fe32b69ace750d0553ec08dfb78c382a8771b088410bb52909585d86c7794c59faca1e3a38e047ef9e1bb4f5c2bba75c56d4ce73f24f9dfd3c485f9436a003dd967d13bf1f46738600eba216fc8056d7df72849d3503afa7f9ea6ad7665f528bfde0aa6ef060d824790f2dc5242b767b714782c382e95f236c4ef893e57fbef4299f9d20796d93968081b9488ff35baed3b6d14c6b14c52acf77388e9609cd9a304f347478ace22e0050cbd1d8e025b4bc4deda786deca51f0b41c148ae2597f6bf8fa4e7f416fbfdedfa0b6e4ed07beee96a5849b088b15dd5df405e579100b9475250ac8139508c557e80540a1e1cae7e689b3febde9001b7e0cb6e5567076b4bc141bd0a6bf667fcb86e7624884f993cd2130151f7a80558c9a48fd25a3d4527fe43c53fc1a8ba75f963a1ba2af15fff45104741e0f677d34e1449f030acc86b8f372ee2c3148d732ddb515a6187b610aa23252ad4edee41d9b61a7715a26229a9ff50f7c5462e804439f382bc6d8f9533ea143c3d209a7ec40376d72f0aa72897acb85a5852bb0e2a0b006bd55e7a50172cdfccca77732e17165a8b0723201a2cb2a5de1d711552f328275f4c56a7e280cee943025cc078a4be2288aed2f6b7830ec01a08d81f74e809e10c89222b85e2b6e72e53e6279099e0a812e2742a22bd3e5d48a7dd6340df5d7efdefda911054738f0d18fdfc90bb8ffdc53629085677f1bd556cd5a9cf2beedf4923561613ca9e664fca1c6ca119a944bfd7fca8edcd8dc12de291fcfe95e0cd434da1113b654a935924bd702289ea2c2a0d4071fdf7f0db1cdd64e58e91226e178b8cd206f66fe2e3d9d81a4ca0eea26381b7c3cb3aa9c336cfe1ae472b7b6893730dd3d1e68aff0097b22d8d670430f0e7bc21b27fe6490f9597414c158c422ff30bc947b6849504d1df5d222d89436f8593fc8fa921454993586de1ccaa188d62d6aa286cece72544f9ea50c5161b0bb2426af02eec07352ce1a29eeebca473abecfe4251ed003d507f16762d19571da2592bde792b39d194becdc0e0e31fadae0f963c05c2e756b90bbba36e7606ab92f49f84fd48232b38c5da6ad8f41443805fd80fa5acafee2cf48b64216583a1a31770c105629ab3687ad9e35cf5e0535e1339b3ade66d36dd09c5d94cd5ae9e25bf9232ce8af106d5af0a0c3c7b6909023b953dd316e3eb9562245742a6d443d79ba12981d840f55f283642ccffb971ed9af03765751b33780ca2803a02e93f8ac66331bfe5c4d6224deca436abbf06fc6002aa1ba60823f35638e049e3c3dfff5b1db2960a46313020dfc8a47299f44569edccad64bc99078e2265b7972b758f52576d5afc613eecd9c186125923749a3053e6ebf0ba6c365385e7a1ac3d8e75b07a2667cb7e595486c9fdf8f3a01986ecde2c8971a3a34301cfaba14b9c289a1c72c5559d3e9c0bbe10469dc572cbc25e7a030311e2c68ff44316afde5c7df32de40ab537b1767bd0a0ca097298f330972612029de38deaf7ca69fe3ef4e026971fe3fda5ee3fa17e030d905e79696d0c634bd4a4f150bff296e6999840de354c665bde60e0f7b939e2315823f9bf0dd6186f477cc1b16e420aacf567e2a3dba0fcec614a46d047d08b97bab74639d15aaace9b24d37d0c5a05e4adb283984e89d2a5b0151d340ee26e2e7c6ba1edd8b204c4d9ee372c54f38e5b317e99c3ab88a8f41ef4ea5842b2862eee829a912417100a92617747c81b3a26dae0544c7d4ee7584d76a4f173ceaac9c649666d632b89e1991ce75cd614c9ebc16054324ae6e0c69e934d7ae14ab76580d3433d8bcd1363aef520d8c25301e1962c741325b1cdc5932b23010e13b5c46b18d1ce0cece8230d84288fd0f4158a0a2993d74f08462cf84e4bcb70883195fa0dcd7e0664a8383dd99a7bc1dfa75ad60c6a5c4e348a4e46102820e99f7b674c2dff8bd21899dbfd7212e623e4720408608664b3eb030041c935e54ddb43f1e92cc24fc04c9bf8a60787e30683ee9ef3b603f54f5a4bd6257120a5399cd9290ad87f4a56d3269be27915058d1a0938077dddf89dda35b639fc38d0cb746dfb02a485f0bbfefb3a16165f2d9d97e79ac5efdd710c9324bbd502ef3c4c4cca05ec34f62dc1c6e11f1480ed3092773725178da0164ec63a4aa3631a4d39675915e7844e7de51910fd03a7981db034dae72a394150b8652fd01f1458f464b455baf86d41c763e51b826ccf7a81c04a6f6294418cc29c3fda64f8aa531a615515a19338b0706c643eda8584cbc6fb5444227d88fd98315be274082b004d941924c49b2125adab8ca4a6c56866c74fd1737178ec4a960d58da71ca3f85f2968fae55ef5c5ee1b083fe909c3bbea625655ef7212beb6e95fb3a339ea8644e87576df39e235b1fd923d94b0ed574463755545cfdc72db3d1f9380b8bcd510489b0d455aed3207e86edac7515add489d8ef74a12be1c216125e71996e16573a06a71f724a78a8d58777da9d3690de9ad8a8a68e2d1998b466fbae1626fdfcdbae1f659585ed2509c8a95d1c5b68508ec91e0accb664093199ba449a0dc0d3810068bcf2b0a57fc955f06b7196325f1d2f5e948470fd4ec3441b63ad45007224d62f29951ace4d9e5006d00ccbf5ded5a1473ab511a1342940d58b2ec0d71f8007537f1db49468f88406cbd585a23938bf89f50ac9cb7e7b280b9996d2ae491452201cd2960aaff20b6d9b6b9287d27d68beedcd1cc50b49d03c3b54b84e58d8b35ee6f927c8d68543a83cdd6150c0c74019fb9ac57d9367b8c89255b31b5d1bfe541e4fff3407f3ad25adbd8746a69113e0b409639c20b3b7d1e8d5ad303cdb68785fbcfb200d24205a22ba1eaece5fba2d15d953a6a1d978e31b73a8e875d938f46eb9a175722fa29798cd961c532e06a26d89d009cfe60888e32de19b012216ef9dcbdb805e26e750a98ab504ee688c58f3520966ffef2eed721d36fde7009b70f1e505dd42aabb2563f9cd9734031520c8dc5a12eed2450fef65c9e83dea3e271f362a322ed92f79817896c69664865c077d9d4a732c2630ebc0fb21a797a2c01a4b400a2890c6a9c9320f305c5fe27acdefab42106322016048da4eddb9dabf3222e5f5dae9eac0d2b5de6d2b1235696482c65e4107a5e53e3c37f75c2c47866b49a423df3e9a211a5cbc88897df52bdeb3b9f397c97ca2be20dbeec4851dce0873d647b47310e4890070f3d974b097ec6016de4f19f0c2f918baeeba07114bfa6910afa86119c6943defb76c4a0439b8600b9131e3c3385fd6520197b85e054bea0b37bc378cbe7af4961ed71188ff25d1ecd3a713366fbc741b1e16374aeca996a4b690a258e6ea8aeefee97fede99a683697456018e511fb713e0ad332c17d133f13d1fb78b30b165457da04edfe0ef283b840cd65fb45b857ede57801a7cb677680cdb70131f50eab7703777bc731aa1df9e8c94c6eb57a31c293bd478437e428ad653bb4ef449ef5bbd48c24cffa169f60645cccb3db49cffe0f870bc148affb95149abc4f3a38b35ad87879a98736d7686dd9713c2ae87a9442a0f2536a6b6e3a1fdd6fc5f8bf17f492f067c32f639418c890e5f5cf0cce3aafe201b7af11dd7c5c6ea09ed9b4bc4d8771b9ead9ea3f0edf1c195e521912c80cc3c4fee4fd2d14dbe42051cdf799d616dd975e91f012ded575f4a0b69a9d7c8f1a5bb536e155f1fb9d61f35a63d38dfeae35527bff0cd640ee7627933f9a258b92757e390d8b5be57fc28738bc88367638b036e8a91ef686f0f5fa604002e871f0fc53a24b242359435625e2863f4c869ba5cdc8255bf9586dd315387e159473586dd8b9356c9a2313f3da37facd1c221270308c7cb7eaac87a61a923406df3bcbc9420f32ab660b651f42b723a7e44fda7e14fb630fb2d22012c3a2773e1ea1fc4c25c29e18eba54d0f12dd4524584b914e304d4198a2c21c93ac14e4be65bf9682e71234f1231377e51e2075e7b35f6f5d8ba0c9086bfd3991a1485c97b7861f0cdb928bb29caf381b61b04323dfe1919e233ab7b526689fb65ffdeddcb68123c63972a12118df75527230126d51d5b1cbdc90cf5b56715d5900e60a569c153f3f4081438bbdfe6d62d3c8aa0d6ff14fe7989d24f062acbc6696dc6867432bbcb7dca34be9c9f1957b3c333644bd12a3e5e00b37722e91e43a5e4ba86c2de9cab41c68051fde3188fde768d0d0acdc241d8a909cc07710d0eb855fdb0a571968e747dc1a77a9898121386e32747240f7d34de31044333e456251a73da8928f1a456827f69373eb0ba47d760afecc4bc158e7d566cef3e599bc1840918cae42874c6df55fe7b6e635f0dbe6414605b5cfa747fd48cf30e6d7fe487aa285ab029f41fd19c0ecdd20a684eecb03a0d9987a0c0fb90ea080af3dcd556d184c2aa25ab1b3c9fae409634e82cf3e27d1f00165f329501ea2b56eedb99ded4d9ab51731c07da37c89d2f6f5677841599cd125cd5fecae9562ccc9f2c5067ef2a7034a75118512d110aa5e1437bd0aa4474cd6787cc7fb6f5e0c95e6fc0ba4397f4afc21813da97eebb4e806be3db27ba22afb9c0e025d260c0753e8a58b456e547eb8e22ea9016ca46f13757c5ab2dd31ac20d52c18b4b9c73e84bef5f74b46f7efa5dea332046349b0235e48c8d54bc30227a5d70d2a230a28a8d7429aad48c3b2d16344fa5f09e6a658bf8dcfaf7cc4a41938eebe07245c9119cce70a53580cb4805b2ae5432ee262bad2d3b623d81e69ab66b164e5180f8d4193182372c757d3f7c15f3d91d72d637e05ac992db3f8699ec0c4f704c5e765b54a3abd2b78142e21bb4a6a256d1794f0799f1ac95f70ed5f65bb08b225bc75a51a767f4bd75da429d783886bb250ff66cc479e6f467bfa0970b739c8d0528eb062214dc890671f6dd35716143d1e8f4df61a36cf2cd985b04735dc0fcef729ef547e7a213f77db45d2872fd8c574c0c70f6fc96fbb52b87e6d28193d2dec9b9a93ff60076daf5fc36df3fb38fd19b9c33a11a739383235196a05ca0a02ceb924b2519102beef2928256f2c8e5c54193f46beaa18f88eabf03f2a48930de05fc234eecc9e3cdbaac4925d3f1949b765c1295d2af09c4cb745eddb06b0834ae89b300e41f7921d6d03e37c588a3df23c5d5d5774de87df06422cd2589f54bb8745b66d9a40fbcaffe78edd365a5d7a672eb89f02268e3e11b8e118011a3b088ab162d718de73b8850a72f10e3e12691ddebca92eb4a5673f3165e0eb796a8c53f1878ce2c5cb82078450ea6c55b153caf67dbe40b336645fc4436963e3c38bdd0041145fcfcb1e709d031b972a02f86a6ccec5fde5de7de6fd293856f28819dd39e3e83254be4d3f00db21bf64777fc6371cb04721e610196e347f5117d38815cf93639565e548d82a22da795d786e0e37e34350368d128d8f2a2b416d711a045eb6af99bc546fee1f793cadace25cd067a045b216a7efc5dabdece1571f7509debb11af2c15a993f45d47ed49f7d81e660dd3912ca071fb98f018758e9e8a4f38024402c9c1d26424c3b159202020286de8541463b8db905d4accd0e890a0638521861c879bd576d6b6c494ad33d871838c3ca425a1fc574a17d6720bd28f1342283ce5b1c7108ae9406ebd586c6c65452768766a2a04b3644aed69a825a2477d0c050c8dcf8ae536d3067cd84d2d8caf48d151a5a9cf9a9137fbc166b63ccc43a2d2064aa67c1aa3bdce8a29866fbcef9ee45c1486c5249e3eef2f6773942aa08a3e6a393d2b189e466cffa2e7ef540812f7d5b3960ead40a51c69fa1df423f75ebf48ecab24fb57cc2b95fb8ea83e9e9ed93abf86b254d97768b12f28bd11ee1c8f7539a948effb6343dade956faca2cef8519c864580e5c068ee191b08332ac03e45fa4105cd11510d703df722fdac54635abeab63aad805ad888191e1e6e00096c00f0767db4a7f8bfb4565f0632282c74fed391b4da87aaf889bcd77397961d8481f1064c433220bc66bc9ab3f1190dc3e5f882132762e53db1ad8762294a51e09c4502734eb116791a72ead8a7a51eb76223ff6c46b260074a532580a953d9636fbb5b0890985742397a6d848f761618bc6b1c4dc96d53945ed3aa7e2e41222106d14fab6b7321bfa5f9f5f89c77bc0cede85407a06245b22a289141c6c0ecd38c71f4790d32e4d3b7805aee91b6beb9e743f71d45a28d30906feac6936305e80fe02763591abf32358defd38a8ba6a17373852ca0080aaea17396886bfaa867d373ffb95fd9d941073f1b820478a0de34204deeb11704e451ac27eec1f0e906d5763fdf2b2cdfa6af4753f25bd67680a29aab608e19d5e48b66a2d8bcc0d2f1a847388499c577f0ed0fe992310daabd1028770bc3c53153e8e4f07ee57f76aaa9d6b072639ca0057716c49696b9f8421551cf86b4909a6c113b08bcbb937b8c881d2ef2845097772885241074bf59bcfe4b05223fc6c65e1cc52b646c68c11bf601130aea3bee818e925e45eb0d1354a3224492ad6653dbcd3b82f3753ece11216073aa83e240497d2125b4ac9b3d5c10c618624b26edfce419a92bf26645be6cce8e227b9d01f9ec7a34d06f9250e364f3b386dbbc172cb3a35600462e8a5f95e8514b50c5991ff494f278e8c6d9b0427870aa6f81209eef18b6875420014c9b3515c92c5dfd8d88647f8a0fd029f3095ecc5feecb12f520a6293c4298b9ddfea90ff9efdcd6d10c819a3514b294f056f6e323b9b4f3596d0265518a3a6dc9078c0e892759673a9e7fcf4ff61c4cbd944c67578643e91209b0b933f233219bf35a58018f75d99f16590e7dd7430cfbac21c7f609611b4d9049021d93fc2c8a1ddbbaf767b325e9ee0b2d4cd2f89771738bb97ac376c0d53351660d4b5b9253ed02e1cab182df2518106e0c72945d6a49b086907dfc71452fafcaa771febd6be8256d7806ebf48a9d56b74c905d1ef9cafcbdaeaee74cd9f1a03bb78fbe07c1c94d243279ef35d63255bf2986bbc2e2aa870730987b9ae51ca02ec4b55ab03d4150eb2b4245cfb4da5cb9aa07665f8087ce96c4e5cf2249c16b085dc0c7415dcd43a5f342ce7e0034398fcd70ef7970fbd953b922363e1284147c03cfb4403353fe93c28eeaea249610cc6fe968ddd6024149717c81b241d74537cdaa5ee6c0edf7253f234d8524fff1e4f7d2ee7642ee1896d861371d29068a13111d1279328cc8d862618d49fed030a478d8a74195fdac163c94d5e22e46486f3e0ceab9725e4cbc3a76766e968e146b4d525357fdcfa543d508e0cfd58b6fbcf698a0180c6d10f3549256990124022c8336182729738f94d1986804646ff87e48184ff86c12a190ded2e7ee731e964f5f0b83fc323451d59bf485fffb45c001340cb34c2584c39137c385e37316be45773a36bdf506d85953a749b918e26128978638d49d777cafaf536bbb2424c1a5777521de54128b19a1a0ed37b1c9cd2e36b0ef20c4eb250951ffe6479b2b87026d880c5ad1aa64eb92ec393ebd6a2dd621b7ddd3d6461e4e48e105edd8600c23ed92e9f3e360dd9dcd63b79bbeb922a91d39da3f99960b6313106c01eade64f1355a02f3fac4db4de7ea75ec6292ec6a4eba953fc3e8772e2d8dd426fb4e296f0b634994ae184b0681320750ef2963be0d91c2780ef92d09046dc690941298c4ffbc850172c8fc2fe8aa62b7c8cc0d78a4e541b6802986c217da295172c8e2769f2ffcbfb81a0f0ebea7b9f794506b3ca43c6076f04bfbd86704b9e6e7c0dd624c1d93c4faf9fac5d85f9455a946413f6064a44e2140d9e81d1f916bf82fa87f9ddfdeb5fb1df6d06f038c9d30aaa1592941e1fb3c696a05a45bb921bc255dda27af4b01a4cb79a6457a25af2296a584aa3dfb1fad8b4152053515498675fe5df4920c65f52452d0321139297606700684ce01f222c543380da2d2abe4371ecc2c570077862c8c2ef49d73717d3e72eb07566d133bbd8fc61c9fe365e28f67029d6fb1481f18de3f2c569ff83bc39eb5f06ea3f4ecd6d02bae4734df833f417ce21cbee1bc80473cc163abe7c97caa3c13c16a250b50f4175b0bf5d42a5d78570155732538233734e069fe903747c5e17d079c58babb6a0649549ce804d832499abb3c2495874420eaa802c91468ac45c39b6e8cdbc88c83186af1d2c7475188c302dc2b1f349e9b87b3a490453a8a51dcd12570dc98db3c020b846da5733c50bfca829ab235e999edb6ea10963418b3c5282cd72399f42d26736f455db6940d895f90f0d77676c3f9e89031c9821ff7e7d516900ef2d53e7c5fa073222c797790305fd92f37824440388ce000efff05c35bc8f145535f0c50d276050f3a412f288e735cdb6190b4344a4f2a5b58615de8cb4545bdbc84085e9eda1300b8d4d94fb2ad63b79749b0e156ca7de050ace245cfdde111329a57f503ede1495d16b9b4d95f62a03f9bbff663f749ebc43e328d1457ffb112558d098c1bc12dea92b442109bc9c47a85c35c73ade913f5c29d56fa7525d7d14c471c088755363ad5350ee1dc9b645577dc727ce60a470175841bdbae6dc04b7181da46f8cc11c6b1b29aede58bbba975631dedb8a4a05e4b30c4ef4f005191345d0f3c48a19cf42d7d056d9323ec9ba85f095d5b39895e62b4ef95f5d9619cb424b7ebaf38577f27803a695bebec0a901fd0f60f08b3bf279d0d43f88ac424eff3d905b340ef159c3e0a854ead7a9fca194d80f99eba385f14949f2dd18652b5b8082d1601f3c1d34df4ba8774c83fa00c7f33e78a33279e273f28e82005fef1f7de93f984b25a8a72b9136e57760060ba86524ca4bae5522bdb75b1045f3ef656a17f7477be93d4a474201c66ab1836d7769dbdaf0a58b63cc9734754d0825c227619541ad5f265cbb935d8d6972988df05d7d8c0ed4ecf4ff646cfdad8a0ce6ce837bcf601d936b460d91f66e716cc98b0703264c37872402268c44399e2b92d7d9a689da7bbc5de1274c6ceab5f4cf98a6510fdcb0d4175b53408f73f14b55e8f6978d4b3337a94f677c3885151da47d907cafc6d501def8cea2d0af736caa60487e625ee97a48aac164e05fcfa77e0b731a5e031e95b74632fbe41aadb9ba96185f29482d2a322d8bb69f20f48d8e969b46f35e091b0a201b093664ecb644fded470dcebe8a740e7d67d97d7945a8ac2f8f3ec14eb5cf82ace05406deff1fd9313fe02fdbd956612da6c9f7e24de668dfa264c06fe48ace44acfc81d3f5f2e342e79aefb6ab5ce72a69b36a74785b61bb067ec33389bbca6e9746d364c4cbad4f130beaf0ed07b21ced34c825bb2530bb7097112ff7a6482d497828ea1d5fbe12bbab352ce3c11ef014eb6ab3ccfe1eb7521ce4aaaef9938243eb9c523d01d9b0e9ecc692bd76ff12c2c72de6872f7b4d83602a244c26af761b2cd641f0733becb1d82064556f5e23cd6e23a6becc63bbbe7cf9714319217bbd7a07fff8d3905200ac359a19cf860b5e7d443d7c0dd659405ebfe8ecc637de13a1cedd8655932c69eab9a09972ed166240ef97945d05276befc4569ecbae94e1421ac6453b1eb8f3fa557d3bcdb778ab5207f0213555d39a2e104269f2728e028d321f21001850c52026fef512fa837c2d31b85b7213211d0c1e90a96915bbec2dc234e385014af1b53cb938f0f0af05400db7b227b2d88d3bcee829c69e0775b594aa7f4401452345b7751f8db2566819e05bdffefd7d0be361701a5ba3f89f3e57932787684c9661d5ad81ddc70e2ba9bcd0f12b65d1d45aaed068216378b6828b384fd312dd1a2ce4799b43b788e29ba8fa38e4e1c80daa48d676ab1c0c2fd66d5e97641d7a58cc5866fc1342e59791f6bf73c2a05e68790a04e54866deabf9649f394e159d8ca530a57e3ad51690d1632b20c75562bc4e5f18a582d07d4e258da02f98144e1e99f9ba5c20bb28bde58e989ecd9d960a013ec3e7e588d4396f229495689680d6b8feeed38b606b56b1dadb5b93df035dcc28bfa89708e6b3ce57a385dccb52368a30b372bc74c58ee7e2d1bee67f53a3a32952ff0a8171086cabb8ab16ad9cf59a7ec9749ffd43cd283b2ad284c467e00ebf7d41fe60d9df7454aa1abc820eb922b08ea716be424a182bca871f3d918b186bdb911c4942997bea801aff7ce79ec049b5a69b5ba05f0f7650107202dff160fb94d8f4d136c45be9eca43bd15c6fc543124d05d12e6ebe2adfb9af36b2fbd9bd5d10823ddbdbe3cd6488b0927a3de3d0ff0150782de5691909f6f898b30d1f49362a7fed74c780a01fd50bc9fde9b75fb6217a3290d25f636a504e187911aba32aadf66178cb1eb7df044395c16f3b7defd0e0e8207ce9fa626eace7081320f168ca8f8bf7542213cf719b552395806fa8c252a312f58b5b8f3067ec4000a146611dd2f11a85617c6a60910a69739f295627ee03c95fa098873fe9ee4b983086b9a02197e1ff2523aa030921ce626b828cce0f4dfb2f69a40f69522d26ba178edea810e4d70206905977f4dd9871382628e83970f0aec032f6a30f81cd23a4623eaaf578b4a0fefbbcdcdefbc8c0b21cbd6670ad9f0874fd19d1b1a7c071bc50482c34f1ae3813e737400b179a78863850eac2b14aeea6e05f6cb73fe7f12f3c0f9bb76a205bc9f0e9a7c698df913571a313a6157751de06c2dc0ed678c5e2d822efb7f45e5f0a19e43c166d7c4c71f38556ece28afcbdbfa9f69997390110ebe5bf133fbc6152a8e871936954df74b1ef5afdd73ee58cdd081edb6a633cc114d505c49ec17825ba2322efbed69774193f85e1a95f76bcdffa1b35295382136d61f86e922630365370f1814f740fad0bc1c1243ef5b72e3a10cf9ffc1e711e8dc41941674f5ea6d2de76102481956181dc40f31a393cf22d3cb16b6ad95b2e15bb8e55fb72a40eca36376acd2cd50c069f425ca6f4b0a0eb3810a003563c7856d5a9a674795b7ad9ae55a0eb41344bf37d0a579ff95165f24f896a26246dc50bc10919440c46f6944c914460edccc4f4affb10d81bd9b00a609009452e2f5fadc7de1a66f28cb2bf88ecb64d88c508c7dfc38bd4d35561056662f10e39b6ce2172172cf941890a3eba711a05c48cded1b50749ea371c0ee596aaa45c0a6e56cfe9587b13bae93caa904a89327160f0e4190e66dbc3c9b677987a9c5a6822efa7f62aa363fe8cad9730afd421ce1c18884a7532fcdaff9b1aa33ed4d08586bd1ad6ca42ac698e1628241bab69cab4ea8faa21e37900c5e092ca828c8184da6d5c631f0278b693bdd07093526bd5d796cc4a6bc002812ec4b08d89950a10ed0e5e0bd808a6be4042e2ff9b2d00a7a1601a94b2d935d76909e24754a708ea281c83efe1a294cc5160ca109d290bb82ca01e88bb915e1993f25b95d2fa69648fb14af87d3cbdabea2cedd1a2d40bcb858db347bd72b0330711d390fdb3d76dd9bb254614341c25b186dc2c033d8bb930d5f6c373c6fe69c380b648b6ea6bb22c7caa4fd5ce632709471d94643733133a9f513488d8d9daecf7d9b181689dff2ffff960c4712ec831b5115955bec2004212e503fd77e55e7100b8f42a500a314d791efb7bbce3166f0dd492ebd71e879a94fd0a6221debea48465d3e065f40825d61a7dacc841dce1af3ed26b722503ca940bb14892b218f4ba9d516dab5b3fe171542cb885e3f3d4b267c6daa258d6aa1dbc5e769825c2061141f7cbbd316a9189f9d783039768eb82b2defa086c3a989180542a76b0e8fbf849fefc9d1cf01e51e2013b86e0dde521b5e6326424bbf098ffa10753b39cec10a59faf86c78283428123c31a446b4fdde9baf8021244d931eb7a40ec2062e6c1f135656896ef53528e0ff42a839a43949b568fbc4a84ac26c9bf46713e3ff67b50ad6f77fe49bd2ce87f79934dfc35339f5511cc119aab23197289872665625cd4994453b0bb90ab2ebfeab07f3955e65a44f6c36b14ca0a00cedd00c35439f6ec4fa11145b6f11ffdc11a2266bdc3350d9b9a4a7e088ad8fcf12a939f07d43033b85b70753e0a0fa6531c0ea7d86928a8886c20b3984d39789dc49a96f382554ce6cdb79160bc7007162a33e8ed85955ea2189726484b6831adbcd2bf4861c0bf3b5ed1c12e882ad99ff8019081a2455f022fd7f39e571b31d5e93aebfc6292b771c45a39988405b82003e973b16f6e1d955b22494a157ccc938b4cbd2ff30bc47ace13744b942311df58d441eb050836261c1dcc131992868f8b104a11264b8a23ed5e492ccac42da2cd2e87524832e06cc995427511fd18e7da1d31ce0f74ce87de36fa249432f212be150c51e2df3aed7157ec5232bbb19d4ffd0735be3749d39ba6e5a25f6f3a2243ce4f1420269b6ff694723514aa6b19f1fe67814a1931937dba42a91275af2eaf9d09c148754af19702cfd0cfdd3a708acab271a67a0dcd3c8761c8cab6389b3daee6154e8a2ca332e51c68802fb6f6097bb499cc1b7a74519e7dfb124730c37afcc33a329ee8162a37480beed1aaef027eaec9e2c6374e4f4429abbfec20f0b15f151d8e84d9ecbba0906cee1198b615845ccd0840291ae1abbf6cc5fb73a67184a3a053aa043a9dbe66ab0fe7367419ae530ddcf1d3ccfa42cb25c77784f3955cd1004986e4039a1cc29c85bed491ecc4a4dd59968a69b7097f70f47737e94f41b8007462e2511a0adaf65814db95c131d093fe469aeeaf47ea630469ef68533648798671198bea5a14a466de54b3964f854438a8fd32cc7e31f73b27570d1ecab902a2fd08919489345d1bfec03df8719a45c51397dc27342d6aee388fa7c0a132f7bf4e01b306c2ee271b1f037b08a01d48f8a31add3d2e1b212638a4c3f23493e602644bd9786775f1d4d8c681651d7405bd1fb3117a874d315925b2f8e65b534a1dd76499e1c801a7763b9d2b5a6f7ebe39a870836a1311e34a89a0f2ed38d6b7d70e93b675fcf3fc5409af64511b0ea2187bd4cccb5a3dfe1d68c1657404bba58538e019db681182559a35d3c699be8337970d23d61f07678608b1b98d56765f8029ec574485aed456665247899394c4addbbbc2a4ecd13fb254972af157971a00901b9237f2c96fd332a46041752346e37d82e1276ce86dc757bfe9d0b8be499d3fb0f4f4ad4c57a42eeb3645f7396cce4d4a2f4ec464fb9ed98de79ebb9c09e348ff05dbc24a8e2f8289dc4b9745732e051f9345e776b130786fb0c0e2d97be527b04e63ea641620698b9cc394f1f3d061ef20e15db0766eab474e71a123a891b822ed4997adb75e3e63972f06081c222df1ad3c053333a26ecfafb7de26785363e3f13198abf5e10445f4079d47d19a5b335b261fb338e11a9888c885e9e7d16af7d8c0a2bcc8519405659e4758e54e8ce04f8ed79340619b41a69b038ddc2519494672ea27469b4c852c09d7f17ddbaa5d30eca5597f0bb5042edec13a035bc341d57c85c3c74f04c7bc850ac1be6ad9a3c216b660314c2e6182371aa7e277bc385eec50e6ed7c576c5e53b73e40735052419b8caa7d400f6d8e0a1fb295fdd71c65fa8e87a0a187d0da236e2b75fd24e6e0e1dd346402a90a40112ee5cb4384dc683da770275001da1ae2a96725a96efab11ec1d1af754314436724ef70b3371dd5ce02b3056ffa643e9d03c2ba37615ce51518a98f70f9be78199f6d654c93e8e39e4fa30d935abcee974bdac5ae89028313c4d337b46212e978181aa205b670297f6b967e726e0b91229b02c8badbf08adf73968905ff354840ce7544006e84f65c592928215cced3a7e699d731ff70227ae20a8741bb377f0e20854bc328a73189bf8bfb9df4e4c28a19d79cf8c563c8b38e668c0cfa9814a5911f02aa1b580924017264cbe07f311dbe4dc1e0ebcf7b11fa6e5338e79771881883b0152531d0a1989f9f82c12d3aa5b2c7fb9423dd40ff4d6198f11c0e55a3e9b872b7d561b862159a28b218340ed23546437d54f947ffe79fc0defc6a10dbcb2c2612718d2da2cf29aa8431c0e4a594fb4374993445b8909a3de0a5e9a97c48bd2ff68c8c82c0766e0376d1a56eea50870827ec58f049665684ba97a28212167530a3618e8d7be8bce2b3d0b34d40187ad2966d250d7a850120869fbdabb2b6e86833823f056152ac5a3228b76f102c9d1a09bccaf3373a9afc271b4773ed8cd506e0211b8b4279744e5b6069fcd94b4b69bc853ffae4be39c7615aeab9577c5ed292fd8e9c2e1a45aa3539c4747757d39fb22730b07f68b74e49f9fafb1b63737579e92d11f7b6d992617f19127069872dd87af07e3e8377f4dc33da92276c265ff20431410207f12facb3f7feb71bf186455aaef18634d0b30f84fca4ed49bddf64e0706653871df46e832998f3eead97f5565ce97c2a1f7ceb77a479d10e078ee720d3d25a8c88700f901abb334921b1ee5a2de95c5b2ae01b07526fa2fff9d45a448644a2e1becee1912a09245974df732fc46984401c8e63833e4534d73a07fd0ce1d7420888fbd9218c06758c3f05a12cdab1afabf0a4ac9ea279f70da716b57752d862473cb262fd5c380e707054734a522925051573e8d8c853c6c19b5fd726c11c2291c8049b90a072d553f1a4aab845108ac89ff5b496fe00af0298ed5667ab89fe40376122f5c38436c4ebfe333f74cd16036ba270c7269499a743f0fd6db4b2983a6b23822379882f12e794b2bb950d287423c3f7f7c70d376f68d3d3b569225e1b79527881e4f1e37bda784f68b53333cdf60e6f3940cae0868db43c3f5dc703d1b52863e9e63519ded22ad7165b2c8496bbd99a84afbc7489130e52c42b44d6871b9990e05b4271cce557ee18302a2abb933aebcc376902f71b6ff471b9dedf14e142b3da6d8a2c18a193afbba056217b1e2704550ff16c1d7074d4c4a754b099315b94e9c732b8009be114897bf25ebcfdddba3e6b9a97efacefbb582cee6b8c18a49daa32aa79a203965a8a99cace18b31c4dab4760dfaf0b1cc87b386efcac3b58dc796c0b9b39f4cdafe7e9d2d4d961f17e1f5891a43ed4c74e8c6d0d1765a681536617ba0854ca394a954312279c4c9983ca6f27ba4a6d623a47cb0e504d7dff8b63e119b888e7708ed333d0335d5ac962c6320f717956f3ce0ff1035bdbb8153961eacf329ce75a12831ae5999b6771841bed17b8e1bde645c012359bf5ad2211088ee2f691f6e65e8862cde283232b9235b9c7ff5de65b942d6caf9af4306fec550bc263c1bd2855fe410f6a1a455dd32f5a74d4c12af3f77c46ead30d30f2b64865ee26699db22956fe86398142b7b7c5beb86679f1b5a42424105a4df697ef6d2303516332b69068a872fb6738c9becbc6bd7d360e03f8eade4ebe826547f2da0a2485cff790509aeb913665a7bd63457e167f1087725624ba3809576a5c5e0844dd8fb9f031787f73edbb8588eb5118b67adbcca0116650f8cf0842669460397486ae8fa34f6d36bbf43cdb6d313f4835a6ba1d327a042a17c2b5e5bf2988725df3b3d75a6aef737330743828b667923856d1b1b5174822ed2f59ae917e35d5c1e57feb16a58be908dd8498a106527d43277a3c81ced9e96a2042d570cbc6d31a9fddd684c1b1398568fd4f2de2e46d542d0005efb9ab23cb5627aa6ccd835b790bf408994e5a653486acb3e070f6cf79297f3933987275fa73985988fd39b083b6dd1a83c5599027a2933d558ad1208643d2113ac2933b146b3f17ac081425914118df73103eed49526c58ef1216289944a3e2d656fcef6d7214817bd4b1b11984e7caa53a414c5a7ac7c5026c7883ca9e518d3ab495843f5c70eff5a69f3ef5c173c749f502e29a863228a03ad49afa84a7bad6b818d740f2160be5bb8f59230216358d5d515be2f80baa9c19846a359cf14aa65c5d326ada9d114df5adbd67a24bd25d42ddb8e6b21c820786b6a3e836c8e11880096c88a76e6b3465b2d61fb111456da58dcbccf7b19b300c88db34699a9ca265599305c22a780e0e1bed18fec6aa777cbd0e9969533401615f79cacfe402f11629b8122175a8367c1d105de7f6a1cb88225f778cb322e41f990c6409fe24b6ef4b37780c99d8068089bb3a4b778ec63c80f6f8d03343ef3770f288c724cbb375f126c932c4d58bee0dd606045c9a5b27ff0d5597b25f5ec5c232a6a3d697601ce0e6d49be3af9d557b0be1597fcb7a681dd73bafa132de4a34ca6486127234bd0ab6c050df98cf6b0f111f7500652ca14cab4a41fa2d18f1c664626ba70f874a8365ea64d1e1e8a257a1d313a6b652cf6db617dcd22d74378159ef1ce25258c76e1e676aad0722a01e30db706e67788d558e44bd0fb600b177d88096f96dacfd78b58a1537209074a42c22425e297d11704380c9d18a3bd86ce35504f5127815feabcdef91c7a5b0091ee7c195e0268af5ef300a5c9fe1406579ecdcb0915397d14f82ed2bc55f8de4e5abcecdfbc41f9e80a83a072d01418a2a544f718ec3d4f6332d1bb2aebb00c6ca66b9999e6bd2bc490523859f0db1dea63779b9f1f84d52cbf3e7dcede8214080c6b54916f512426bc9447266897ad4078118867e0d6746cd99378ff539066b246ecd123bcb3597c4acc172ea13c1e260468fe12b1696ba737e1984e9b593f774c3db1696be6964319b9f9388707bae3ee0858528e3658741dc271e80974045f3ccdcf5c271fa4458e81023f42761c5eb37375dea4e4d4d8b1de0b4724631cb35b0043e7ac67c4edf767115670eaf50370af4cd2637de6c760e5750b8bda3c5351c16a9a5ebc02e2ea24cd10e9fe31deaf0e250d869f933642bcb9da2dd7ae6d92e3c3242c2ca4908bb60f19d68897616973b67dd1f1b037c460f7181782191858f2003a4146daa41901058972d7baf5088dd5f89f294ddf5d0b6af191f36df14250213469c2735942e825ae6d36406817d2ec872e739cc1cb9f0bee817e95e37bb38c24b9bab958654afa1a38dc4c3155c37d1310f014a5860de0637d0a48d23331bf8afc9f5cef164c130ca4a472b360b92d4552f083d6ffc381f8b033bcc0550c42ea706ca15026f0d4171c06e6e3ed636e2d7cfa92856ef967342076d612e419457b0667c8087f01ebfea10184cb54e7c6df803d8878fc04ec7e45e1705072d1a554a5ead50980fc7dc0443a2f51f64bb73fa10f183be1e8c4368441ddb9cc5c47845c02ab67194a7f27a109036ef7c44c33ea236f799350705cf63fa5a8ed6d8075b8d483c41a589c4ef7efb716cf495f839a1f22ae433f35d4c5abbe7bbcec3a78ad021babf3e0b9ff84130557125622e93b0795670617a426fa536430d1dc22c79ef99b0474f5fc4a7812efe5c9e2e9f1a23edfed2340ce460b118525836600127c410d977d7f2e9a89a6b571289479ee50ec969a026d8054077f783ac7038fc45f1d7972c01d4ff6811fb44dbad8a5de90b39b8a8c055e25ba81b4839725ae5f33875d468fa381a5866ebfa41f21cf2bcd32c0a3e171ca4cd5ee36fda6a7de9f0c630430e796fcae444eddb481d8c61f7c1c1a6b6b6df269eb1c69ddb5d6e2c4bde345e22546ca393c69f48b4d52019f1cd025393fb97d193b53654aa6bf784c660040145a5d5da90092751a9294b526d087323a04313b76cbe6447ab73707f48abe7628a2d8e2b0a5de8dc8e7d4baf10cf6fb714170a8d0e808f9b00d1e3796967ea69bbf899bb84605751b423872250ad5e61d0162613a0876f1c0aa27c7c9dc629bc9ef8fdbcd6abcd26fcdf55e0bb080028cb3de1e3785a3320ee1652bc1a553fde8f73da96ace4c55e5d140bc4211918ed8694dcc5d974ff47276c8c157260e9099cb8042fc9f9a258a6a107023ad1f91a1cef61a74521564bee71c2c055606b183fb3e5f02c21d21f45d8c3dceb63edb8779d4e54668ea48b3d283b141db2e76e2cd4f4f609d47125519bb969771a27a129d82b326cce960126a21be34bcc01bbbda81dbdfc70e2cf40f79d3c7da6f29603a5e52e7f968c8bfc4709adfad10b5d2901740c54625168f306997e9ff6a4dd6b642635308a33e7fa964a666fbf436c2dacc0444c8256f8ddc5cb975510e16e093089030fea08c28cf13a58a35e43883a9feaa5b6552041142f20a916a2b4bb0c0892a4ccf1a8707b3bd537b359cd86f831c655102f69601746ba8a29cd9a089cc3796df03360f77c6727dfe70cf7bd1ee97bd070a1b8ff7798ba8dc2e1ca6f09c1ac987da350d1929136cd346b5347b4aa00aa08b1707ffd7ed550b167233ae883db4791025d4d3f0893cae53d0ee29569290f29b0f73b691f05895c9a2c40357ea89b2fdebe78c41e14f014919d17cbe67b0fe6fa854d65c7a2fa0804dd88d8638caa595e49d2bcb1eb6bb45aa447c4f6ff29d308b7785fa01213a796bf7f61237c38b7d6fa76cb760315659cb37e2c88a9cfa7d48353a5e160709aa599f17ab5076cf9010a1aff139e7d908e73c96c1eeda61568730981f77f749455f6d4efa787d9fd40630cae5ce4d302f7cb502afb8a092b1a0447db8c42d95be45ad25ca5db36cd0f24768173e21b968e7f38503c70bfe56101b8152b3e1a32d922a58fe48f8fa01802d578ffce70178b29fcd877d58d2062a166933fc33d52c611c44d98beefc7a2ddfab7b17a455cabf8acab61554a4c1e649c4d228fea931d30314849cb63eea6684d5410dc66d24fa96739949aa615777b13a0849df0f9b95023bfb065c29379f515d4eb24965f0da79ebfa7af2b3852ee22611953769bc08b0df17def102abf69d9e9d2ab0854760e6ee324c6d35d804f0069d65636227f3004c20e2b74a1666b877e0701f933590c14a0693251fb7588d16d011de7e13d98b07a9935ef81774938d1f8dfb137ef0804e32d54efb3566ef86664a6b8d78d19ff938ca4e067e6c9bd56a635ba2884c97a074fd7e5d32a98c6ac2563323e1d7b40da5cc1f7a66385ef4badc4fb28ea729d6a406b13db81f59251659084f059081828fbc0a287f21a7481d8dbacdb4cd8714741779ce7f0b10d23bffed168fe6f15298797240be1ab25efd139f8f6663e275121659798aa25963f01fb9366b0eea86b68b02f48c74ddfd8f7d326a5bcdd419a78d76dc27507ab0aa42971abb2fb8f1b624d62e13980139cfdec46acd5a48fcfc5b86a5e940a9849b14c16368fbd87c5fb40b8f410d515fd63ddfc55c529e5871a4988f6b1478222f54769ccbe8ee2f3b735fa774ab209ee535a968e7f5c73ae0b5de7c384522f475b368931a1de116ed780a373343da60ddf436d33d075b54dc44383d1b526a931061cebb55f946b2bcde161065cb864915963c35219870dc42e260ab6bb141437565ef9fc46b8e662228db93f8063dea3693be95fa1569f3b3c91b8b67f0b77d4a7523cf67d842d97ff491ac1842f40f10eacde168aec22d2d14732daa332ab4a4c30248538e83dd7afd1ee5d712876feaf7825829e2e7eedfa51679ab1d7c340f9d40420378b49fc3fc42f72a9a0ef50bf647469bdcf7149a89c14818c0ea9b5fee05682c065ca8a9032bb556e10a0a2e7d508f1d60276b6a8186759960374cfed62f261cbbe8b3e77cb01b01c412d961c16cbbff5ec6c655a18f3d99b0b8ba2b4aa9480d626d4534cf488116b5b194add0074a593366f9f4c8ab554393017f7dbcff227adc4f71578342e2d84814a1c949f6d51703ab19ba4460a1548b29a5b52b5214a1bed29e9cc43e8b0590aa3070424a755fbeff2c6ce21c722042d196d7192681845c6f898923b56e5f3a7370eaa6dde6d978e89f788d512a80fc498c33ff338ec7f0c3c600de2bb10c1afe00f096a9ae8df2b5e49cab7828c8b23e925e8b46f8ae63e024d51c5cce6b972e070373aad3419669fce258a3be7b3bbeee648a0c7caae41e311bdc63f25a49691a192ed222014d0071e3d7c64e3592feb0806efb75f5e4af2e6fed4d7d0bd43c4a7c60c815cd80ea50fcf42c7e4f1db51cf0abc3e13f4bf91a41a4fc3dc846fd52471628de83030a44e40e76462c6e3bc2cc3561cfc80134e7d03d955e9d64080cb8010b54d350db79d3f32b95068a570ea03232c72c60631d150f317724b11b487dc910d98e2cb9460ddd235a8dc716278e888689c0d5f78ab3b58c904794b17c4bb64d3d6f28dac34b8a9ee8a1dc6f6bfd1c2e413e4b24ccd3543f6eb8e1b962cf0657bead354f86f08fb83acf0f2d15cdb76cebfbe9efddee249045cc81f0360110d2c9c77265cacf1808e1c01c426620d8e9353ff01078bb31d4e49983b38764b57ede033442be57fe2e7eddbafccba9c67435feef3aa6476bb9f59c22a7186659791f24ea5aa27ff0350e301a756fec499d85eb9faf9d230b40f3982dce8192896f6fae40e80b9e7ea12c5f4d0a31070bfca4ab36898d33f2d5f351ce8cf7e17db47b09b29b6646db4334883c7dead3bc7d0ee01dcae538c3d49b1714f3c113d06102aef49d645173306c4f207ec6eac2475bc8fa26926eaab8daa466e6c34ab10668fa741b86b382e92b2214397f748cd625ba2b58e697d0180c69fda71d034cc0670d4abb988426bd872fd41b642ecbfb6be68dfa4f340707a6b6409871faa6e3067219f101d3cb77ddfff917e482730104661cceb733c1c8990e16b5508a890bb1f9e8d2487295eee1701bcac5abc493de597d5d9cba5cd5af580949919869f4f652c32fabbfa516fd7e11158d2757bcdf0f755df173d3f8a550f91664ee1fbfd1fe2e59ae2715ff9aeea4f6e5041aa73aea79be007519d9e80f3fc68f329869d7f478fe0119f2111f54df2cf7b560fb1b47165ffc114f5cbe2c2859c07c3564d638cf9c85c5b84afdc9e5adc2978b62752b13878a63ee99c68d6b79db08bcbe71bd7d43beac5e3096a2c6a472c0df4bce2087fe04ae6fc39eff4ea505292100fa2e449a20358a447dac2e932e04d7d18ffdbd3f64116e120f3aae0392e635702f6ab8282c7bedeee6904bc2880bd57531f848c8fa136e125585af4a7a7f206ae99a126a67330b01e99d67b16e0f0f06f556418d3eaebac9ecaf854ac4e450620e22a388b25ae4efdcae411eda11fb962a74e49e12de23e88b8e6e8c72121502ca28ab80ec0a5022692b0cc5062a8d2bf2cfc2be101cb922d31a3bb9f5171d85a0a03cc4c51d0a2ce10fea4c1355bb710ada6ec0f11b69a74187f2b1c63f9ba776ee670eedb92f052f1e90992332cd3d3da29b248ecc997d73887e3ff12e12feb5b1939f61c73c0709582ba97883728722837edd1db6f102788d29df604047d15a1852a5dd7fc7c74f30d392c0a8534255713cca7653257ce25fdeced943975bb6ba8593235be0f4f199d174f7843c720ccc6baf0215e17be990c8d2c9236224392020c2760c7d5610f539f02f2d083e892d69f78c18e755a0f356d6c90a8306674d83c32907c66a654183ed03d261ae20ddc26354f38aa3bdf0760380fc09bd7f12b225901dcc213c71318e05bbebd80f524cf5061ec623cf5bc895b4a6077976a7ddfb9c0cd3fa783259354b6a2d9f284552ed221b78d0b55e8eae65c02003e58fb60c50bff4d44d5bbf786a3f5cbd49c3cc914fc3c602d082d7557c3f7ab7ace38536e001bcf52eb0ef80154322b310e2ea795fe7333d0ba333dc1a7a853d0b9825e34ff5cc055917311b257cf36bf141a2decab2f2adcb50466bd0432e09ff47d854ff60e1443cc6d6dacc027bc112c705ab3b6d6c3de3ef5ce27d4d129fdb066237160be102dc61a8690c459a52b319c974404180caf42f8620ff20f9681d46a8953f4291f3de9ff279d00cb82789f9f3390a83d0f9d38050aec674c5c92bff62cf37d43b50905fbfac7db15ec9b8771850627e1f9e770c312d2138fe017e607b8c1642c6193e31f193b69ffac55c595da60862d4d14c2cfe9a6558b3398ed59bc10b4a1822dd6fb02884f6d44ccefd2acae2137921c5c0e61af9b6845095b45d27820b326e1306ee3ae43d05624e3e2bb39362187700f383b59c51594cb7ae9af7a6e004d2ae29e9ed089968a55efcaa2f352623448f5c54666a6b57111956291dcd7f5a4d181bca27e3145020dc777335c523570d541bc674e94c4934374829c23a70308b1932cfc1e5aacd9156d5f73da866de9ec2d3451247e2f3f3002408fb776a822a58c313e8616d49869e70d2e7926ab78c4f2c95e286db19b74770a15064005f43ccac5d10198033f1a16ef1b73e2fd166acebec28a489847a9ec8537747b5c83997872a38527282e648560e37180d3acab42a72ecac8dc39a281f1c19b64c8c71eb8535c29c8f8b60a4aaad677de1e20a0f21a524e0bb3e1e91926c4021f3070eb5de9d98a8df57c41452f66e5ce73d7900307c01ee5e45201abbbf8f49bfeafe78720bb61856e7752389ff5d32b760488343be6f700a1c9e55fd535ec4584387630c08a2a48f89f1e7efab7c9de516fa1771def7e4dbac84f8db1de0015aafbd1f2d74e64e65fe58fc43a36150672689ebdef7b06b565ce79bc4ec2335c89b84780985086a74e81da4c032429d717e5c979d276fea444f6ba91edc42f5caa9dcef02bbd32e44565a745ecc2d53207621ce08ee5421e74da75fed5eb0c36720ac7bf257418746f2b2c0c9be338ceca525bd2d9df8086e4dd1b39c9ca6771ae45bc522b980eff22650f48f22a5c66df99a70d00195f6aa67023b00fa611d4d09cabe9af0010edd6aab27dc4e4815cdd63292e5edb1a572dbf1c307cc0127d6ae1a2edfd548dfbcf3360079f6cb5de7778ead94d8ea779f40a51468df59c9f68f9b642929d27db1b62b28faa2f28889ef015c1b547c2a7fa8b98ceff4c4e721b8d7caac45aec0866c1e62eda03a822517e99d42a6a679d36aea470b4ae2a2f97fef10c28943ea9861b09ba728bb660b6bbe5b2f052c88b744bf24caaae05561feb1a5735f213b9bd71892f0188050dd475e72c9740ae547d17dba345b4fafa7aa952bd9e0639a2d3566ee4e9ad19515d523d2e4f36d26ff1e7ef1b609eb3b126823314ba667be6d09e7c435b4d6e68e5a8f1345e55f2a71d50b8b8b105b87c9be2458431d77b36ccd6f89235c8512dbb2d57f8c59f560879332543b473d0d19165422d731c2350156be4658e3d17ab99a5e2816e0bfeb8868a7cb38627522e5d2d86b7307a41f3ad81341c03ca0d7e571b4dbebf47d47a90638207314b6b00686d4427b56330750f0121d400e9d590df382d206d0d812187260693fd726374ab708767b3ff731a9774e56647d00e850b4e31e47f422588d47691d26fae2c91a9cec647376c3061b1a41f12ad3ea960b18424e474d5462a6b43b3b083d7b8eb3cd3e3fb8ad176138ee32c53af44e90cf24ac6d1b3f3a0fc446c2b2d7211c2136b646c59ef7a8ac5a4faf92f201651879cab5905e6c5ad9b39ee8b357259ac5051ca342f48cb3b5f641e6cd4b740095645d8343e36752b1b57a0f6e303a6a7cf32fc24a3870bc0e3897e96712d82a1225701f8be67aac7299b091e2048947f23a93c985b761fb16454f89dd5cc893f1fa3aa7bd95015c9da68d57bcc35ea31bf25d69551683c6931093b2aadd0f37ed9acf6a408ed91f11101f562a2e2c5f16fdecc66dda489676775b1a2d62b09fe66ff297ccccf99f5aaf8488601f66f11b9cfdd0d91241fed97d3c0088963cfbe070f039e5fcac771780e6b2b245be54f17cfe37e425c0de47acc34e25519300a8afff1f835d63680fd56064190b99b6b0c723e7411d0b183ec38d0aae036bab9785586d3d50a0d062a3038681769da5820da23528c36df7f3c9a828fb0adb085adbe1892570135b9fcb61d795502f612507a641afe9b2b2b93310408eab6a1a581f107de5cf9998413d3c68d6243afa58f2dff4bbb6a97c5c6cfb5f9dc23aa7393ff18ceadaf4bbc3deb8791ab6744ce12d16f90fff60c7d88ad8a30b82042edb1fb6c6411d873e295d3e86ff5ccb94ca3ae8bd5f6b6f6baef56ff9d9f00356a9eaabc41f2f05d94fb7ec0f69329e3ec74e0900a2d326d76e99ea7707e1ce2b7c9e6a3f47ee0d8ab2d7f8cc651eb5cbaa2c6b617062a51b3ac075fadbea8b53d0b781e9091901c608a42fa6a2fb46fa13663a7273defe1808c6027a20202a7fecf228e09b6dc2cc97221bfd0ac131d90c33861c5b993c7248555c7a15c9d90fe9a8c34923b3dedac4a88f8eb0b71d778f94b607d1ec95217f8bd5b03214536d4f7c402c079cf7f67027fa945b4782c2a06ec557cc466964d2bf2cf0ec14ebdfe615cfb1133491ccc415e202f1ab98e3c738ea119238f3ccc569ff46181e0b82c4db4e1d997566979b1005abebc940acb548ae12b96ad19af931e1cad7869c80dd8228e000126b3b93d629afb1aa9f487a25701d6ee99e4cf2f5b9f207f73e11763352830ec4e195996180fc56c5d84d0615352894cf5b67f2b1e91974da5e501a8b09f090edde5e77c5366c947b3a2746ce229b5754f6427e403fcb271e487fccf3d74e0fe67009ce4d32c4fc1808882f1d4b65436887c30ac2a06f8c8c8f48d1dc75e1446f6e02f13305f0ac1c859912dab3370f14e7959902351550bd14b3d5b1b012eaac45fb19825896a5adaac9d3374ff6a40290f56314ae3967fe76610cb84eacd3998c630db20e49958f0d8366044fc900284d5e8db58504fbd6975535a2ee1ead79b6cc88bc6831f661b1fee9d97dcd7f598338c12befa546a75c7bc86c784b367da4df13f70a59c5bf9933e95654b7701b41963d33993a9e0f46e7281411e4e7a3b97906fca7bb82652c94025930124c911c6dd1333e8f7340448aa6fbaa75ba9380a049b41bb86262d4921453133dcce9bd98da9878ff74c6a6ae2b40dd06c1d8a963ad52aef1b26f73e9c57fd52286f2bc6ce8df8781d3c4c68912a05deaf4ef510089374b5a3ea63672190ae97c9a0c79dbd339b36ca5abfece9fbcffc1a6564735f8e5b7ea9ee50b7aa3feee252816e206a7ce1ba545a90f74a20711c831a4554a7c53288733fecbbbf9f48d272d6b65926e6491c7204b34f76048735d6256dc1a9ed16a62193ef707a785456133801b11691fdd576103235c6ba2978ab05ae19878ccadc36f9574c97ce3a5bc3aab4ed3070dbb7ebfae002d7ea4c48794deab0502b6dbe03c1a49ee52728fd3ec92389993e7464e8d8040e60b211d75bcec5adb4a19ca20af1f2232c652fc25159e12e858f3d07f08910093953401a8f70c11236df7992bc2e113e51b20b22a2296639fa6133b6015f802d66852bb2b4b698f1e8a81a76e67687d0b8508a371a3cfb18254265d57413dd9aaae3742eaa265f3456bf9dbdfb08fdf6b477a6a10fdad90e7a3355697aec35bf22a8f84b655ed7fb307d0489142c045faaa914e81c608e59c6f88b82749d9567c46aca74b4e1978b741a44795d277cf7243127e1597f2e5a3ae676b42c162909e2acf12f010fb756d886355f41a24888a64d5dd10af3515f3001e6911908bc84e293c988afbdabb7d440a2ec3de96ec06b56b4b9701e95e5ca10b6589c2733c81269da2cfc17b3d47fa89dd30503200099ee675147c9e6f97da5e3a7856a4decc4b8c165c4ef804f41c533835ac27e46741496675a2431086b71971f0d40370dbbb119242adaf4e729ddf8d1e04b69a669486aff6a0ee039a66c9961c66e0d6d5f78f3a1fff5432c41265936aea1995776862f892861c937f5904d376a339dbf99a02cc9cff84c27f206c5afe488c953a574c797e99f22b5c917e5fd1a90f3c17a4868d0688696a13dc911ff02f1ad4b6203e9d92f77bbe78470dca7c72009d61b3df1e7871b60921a0d54a6ebcaa148260672a3aedff2f9764f8197d9a0b6c934cceb6820a41476eb1b6a9110af53bb182dbf95046145f6bdf102b1cfa86a5afa8b08e603fc927f0460fa9563545c88d7ca5916dfdb5c9b6c767d520679e66bf673ec64502185615b13d9a131fa4651e5c8b40eaa278c771c4fef3acc35ef76d167f79eb68279911984ac9da9e54eb431dd2340ca6c72e04c2da65412db02aaa3246250c507eb8ff42c1d25b629f9340317ce8b71eee0aa0c015b2b905cfa739bcb9db63c6779cbf2a576a132b4028bf070686f89adfaa5ca91fade9b6f6b4df65a63848c502d2d24b94201e4713ecd2aafce1b7eb28ae4f96ab46476eefc5392d6ba2fe7220eb3458363b121c138d122a188c3dc60454f7ef6fbe7479cf56d1a20347d7960a7330ee392fbb02e0d5b59f7881035d8439568b8f438c0d91f38b1467eb4194f28f7a1558882f831aa7bf0679b0059c10180c66abaff9d238887a05ff23493cb18235efb163adc0a06a2c8099bbda391161ad30f52ab2c7627ab44e1ec88fcbfa08277e4418a7a2286601e56877d6269595c4885c64ea809e9c121caa5532d4aaeadb9e9e6651be49f25470bb0dee83448cd59ad75f4cdcdf2d6c3346d6065ca27b286622eb28fee3ce4399894dfbd1846725fad67fa2b818870e0aad72f9499e1fc776431e6fa6a6858f5c6f1f0b56126e8f912a126053d445f27429a596842da82b1c3b8308ffab9ca5d5c88a2d39b0f44968b0ab67222c6b93f8cafda69183c62918e96bd5d949173c140d1f7d0d256ab50c9fcdc61c725a4a1e1f4639c8363ea53abc87a8b8696a1b8dfd51814f19a6bbc18f5c567ee8d89e0a85879c50fc1ac149cba1e9453d5d262d272c3a76a0e254872e1f54e8fa6da6c8d2220605305dc398214609f1e31edd55c8185c46fc00880f28beba2b50b042b26b20d8fd7f26fd662142b0440addcbd3a64e6ee99bb583676f96927d779481a0647ae6a8cc059d35daea794868326bdb485de1940b2a0c5b90489666a5ad85e2a4c336c730d0cc6280111fd237f90c67e4f6815889ffd803bd9cce441ac59e2aadd6e546f9ac17507798d056b2a421d381866b954c30d33a932a629b67e2745913efa188f9bbce163bb69ed44d12c9167c406883793d6e073e31f74637aa4a17c5c1e67bc663294b8f573ebade9b593b1f720c74cc001f07f29d1168caf61ed84f913f70cfa5c6ebbade99e2d4a5a9b2a872a1b1fc75c65337ddb01ea09c027bb0ab8c5bb00cfe363edbbcaaccd3b997cf926dd2ccdc64d98cdaa4389d8e3c46a789810929302c1e8d10c233932e1144928018bde47eaef06a82746533c7a4b9f1b8253c9bdc89e63f7feb3bc7ccc9aee795df2fafc139fc21ea9013ba3a3c248747fa68bb7210b8557073f3fd7cfbcb3a57eab551aead27af9f716c1d528efcf4723c5755ddd767ba5543f9a7b1c112d10174ee53670c3efa51b94b73a0922dd298c2ae4bc7585bafc8404413f0042165cdf82fc68e9466646ef85d2a9b52bf523fe8094b7dd275c84288aa10f6fe14c5dd5f3e8b2e30e2f182083b5a1f4b0072bb58e0004fb9868578a1e1fcb8be370bfec6c5b2d0318eef1e9bb50ab89fd834ab0e625af5527a5e6f82f8a3a405eff949692ed2338cb902ca715293b77dadec10b53bf024f432daa9e080dd7f2810c25b850e8c2e0b405d1375275fa5e832390fdc7373e6977f682b358897fdf88ccd4f323356b80cc556eba9346d54c0472b377c06d453348058467141f388a523f6ee723496005e37bbb98d321df49a1884bc3561c19198cc35f2ff429ea6efe3161f569f92e1da035ff641f28c04a0a8052136df82f8b0447529ae3e27f8a58912e545514146409666760f5425a3225a4c26c143794808a9cba3f10821c3a9a6a419e06c57f5a6dff47370620808ab3cfdb8f2aeaa4c2eeb90405d1ac832bcc1a55bbffa814c3471d27765a5ed6edb3566edd96e20e6f108402df41b49faf48b75484ce9d37936b2f26672e80731901740049f18de88bd5eb2f58dc4afdd7a8f9198992edbed64c2602373c57e2c06bfddc03177ac292e562cbab5e054acd21318a4a10a4805330476c9099e3d7660d79a3b2b8be3c14d05fe246eb1c9964761289d097f71472a6beaa0127023697956632f8ba77250559a15ce9e7f270e6eb1edb62586cfc31cd4fcbed345891201cb9f2834761f84bd88f6ab147e6b3f1ff90139f9c6c4fcca9dca67f6f4474b102eb1d4765f13ddda3746d54e44bdd32806a9a8a179baf0f8d75593777e79ad9eb9a370db4ce21cf5fc496d6e521ddd7f2e86d2fce6bcd92f1dd8028592154f1a8734fedac7795d4c039d5ebd66d4ac8475a137ed935f20c7fad6ec11db1f86058949a36165489f84d9cda1b1bc1d4e247187d32e953e61716bb585c1d0454f7b965292fae8b22536dd70cab60356d1dbd744f7011c840ea57f5b80a17340138bbef39b38a34631fcb4ae8d262656ab1557b3d74e09da980adc68b54c5eb56ba9716374b1522367425691f578ca5d4cfdf22220b7694610d9eff4fad493158fdef22d1c936252b49153004e8c5ae8b53fc55dfc7aee6769d559dc6d0a439d4d709b116e3abb4ead94bc8cda7b0bd12c0a96a151ff242377453f06983beb82d144028101cfc7cb7b12abe9a1ce9de7f714f1c7c24357c98d11145b5a768f01b6e6f2bfa3da6a825728ec4d1186fb56378be287c83bb728ac1f2e844241a0d5cc98b9aab6996b7ecc14b7b499624b294b767111b76681e3bd0002113c7e3206caed1bbaadf9f536c32c97ba20607bd2711ce7fad2a83149529b060620ac3c8be317fcc60c721d23665f16c9e7eb87b8e591da318ca5d60a8cd6c7acc1d3c2d7a06e4483f0186f62e2ba305649189c5e53605892ca44ea79e249bc821f3e82e1c1583e7aadb19f0c574c2e138adaa6efbd425980613fbab36ff49733b6179e15246bc89971830913c0c225e6fd33bab45f351768e60d9016b5dbe6c9f4cce77d160878dc2a27e19edca99840bc821a66df08234e37b482e1cae6644af512098d2495c11ecb228a57c43ec86768f732eaa843d810a0faa286e1fbe63bdc46bf9e852e349d15c0a170c8fffabd3dc7839f6a8190b7184ec66bf453b4eb894885d61e9e21438073e1729f784790935607c7cfded186c2a6b134916d591421f72aef18288cd68f97f0998c659a81d73526766309ac0300415da7b642dfe8ba7e3c9c37af67b4893f119f69985e1e16f4bfc24a1dbb04462575658584d7a752252839e0787f818f41901f5080e1d52f35e165003d5c0f8281cca9a45dc44769f5665d33df75ff7ed753aecec1308e456ddfee4dfb559bb6fb36cfa647b5777228cee24821962f8350ed090a538f12a50724188e273c645315f4da6267f040104edf9029bbb4da1884407f8437f5d1665d870885f1bfcc6b28d3f367465ef32dae8fdb43ffbdeaee77e4193482563fcd3d841e2003850e5a4adfab4a1dab93d42a9d707cc91f5b78382bd068555baee3664a461831989b94c420c1bfc0b53e8e4a1b26a67764ff9d721bd676265bfd2d76548d3ee2aff5fa8c6f28673111195dd8108568c5baeb5928123cc3c1b07c07cfdfb5d1b71a90bc96b083b75ada40678238949c508ba6ce3af28e601b3ff5c087f63876b575fd2eb7323053775f5487a6dabf336946eda37230d3afe6a75e16af37a9193bf5ed51d5efbe577c4527d4cf0d0b8fa8a5f15c3a0c86b2984c2fa556522afdc5cf3989be38b3f1489a775cc80126f4d1a8441834285954db30d2035e886940aa2254c6a7fa3587c874574b47e8979ae0986eb3088e01a1a670b2d7b5f7f042960fea80d5a4b7db00cdcb715765d11897aac6584687657e883a35e36f6bb2e461ef2ffbb4694e11a41c08e8059b623f10c48f63c62fb5a371680dbcbaefc2f43d32e52de3db301729a1b604cf905eaf28e369efd2b04c8a6bb11d60be37de8897e2fd350db4d073e1e0ecdc8d430eadbcce1c2f9483546647d3dbd75abeb905506182853505c63ed3e3fc8bb6c544a55ec2358f987e91434db7b3b17e514d2f48f7319c7ef30eff72cab9a0852645eadbe45f34bd141f5de7b6dd367854ba7fd6658e0ab2ee66dd20f2bbf921f3cc5a0563ec062df41b6c9a4aadd81c262a9683ed1f5beed2cb04acb8ed18581103daeee290630e04d67226f6ac86d5c680cd7cf4c79256d383aad62adb72a01eec6d9f098d5ce17185b645b64c52293358623fcb8c77479dceacd1f35821b2e43b825223eadade6c6fb97aa9226edb450e9c188133f2b5ab21b3600f488f34a18db510c4fb0c894345fc280833c53bb2bcc559bc70effc2b5eca18b6d2a609fba4f8f44f77c93b8ef7d642011a633d790ec454d67642a944ad1d2aa5e96bc51819452dbfd7177f3dd9e1579be6ac226caa88435614d0c29b519def4c5f36f85425bdaf8dbf6e858cd02aca16c6c9d82a0f18c5090080164047f2e975e9ffeac708d3a2b8be97695b2736897676ed49b9dfda9c890da00b0cb6da8a832264cdb48d8779e719246a6a830fd4033094135fd6b9e636240a4e0349526f4536b5bd4b736cdfcd46a88de2344fa8db7a39fceb5b724a9376f7e51aa417f1a10baf63cf530a4e759c4be80b251ee82cb392bbd7183039d952a0d4d1ed64f506d9efe23b37f970187481518b39553343e89b89c2f6dcce66804b8d45e1d55ec1dc36cc679e462ef0170344a83a53bc23044a873d608da8320ac65e235db368ec238efc73a0203508252577fec225b42f66ed7935d065051184cc0371494b774893d57f30bcfbd03c7ab000091123fb60fa23dc7977917000d8e9ddab549cbf957485e17c342807ad67edd3919d1d5c4c847c8eb7c6fb1b6b756bbcaac63bd1cdc9f8d96cc9f91fdca6af5f66e6ddb2355d6387d4229529bedffda6fe0a77c0907cdfcf445c8c720eff421ee021081d34d0b73b54b3d84781a1ada9dc628a4b59f6253f1a3cff7e82c31014abdfb9015711302df5363c688e3232679cfe23c0b273f68c0e161f6548b405e8177ccef5ee92b215d98cc128ec7997bc8f7197c143accb3c720c1f4ed2e331130e4a70df1d89d4ac6bfc50c642cc8cc1b05040cae31594015470b104163e85a9f519ec28427b47a3a8a0b92dac1276436acbb54bac573e9b83af6955baa5e254871e2e681ac5f42219834da9a5411d59f497c6df3a89b46399e8060121f44b73ac189060dcfdc7e66f426462aeb94eb0d7a16135d140ece4e04fab9f317cd83c2da92777bb26d75957c8d170caff2d1572dee417551be25c2b0446cb6bbccead36a25e3a2f523bc9b6fe3537b3fe0aa0918ff2e90d41ab5d8203c9701bc04cc8b426fbb2b25601df442b472e6b5d3c2dde368e1329c36b3915b82af2137dbe48a5ab8cf13af4b255dbd31ea11473575a63c08ff3d36ed69a0982b7e2faf71b27cc091d7944b25c30144c6f1e98e0ff646ca67f3c1eab89ff4d3cfbdcf15e475bdc50b64f802fd83ffc56f99177e399c256d93b6fe616073e922ccea2b52b84eb6e9ed064f7acaa2bf7fec7dd2bee3d796bc0744082041a06cf8f1e45dd44b8bfc02b1a584fd52817f2c16f6d26828f8fe32f5863cd938c5d2c7cab425f6cf1bff7e5c4035ee8bf6cdd48374f49db86ef77444d0b73acabbbe06d193f015aad4dabb76072ce6ae8beaf03e48c627465dda54afd436d47f007c5b1c7b52cf55830d6a3dbcd561bac52be9e131182f46854ba40f55c86c7935413f3c9ebaed553f9b9fafb964f0c5a03ee454b8a21bcef78881b1dcd9e4f0944f5e0dee6770f7d32e058739d6a63eb6e264ada03dc9a30d0b1db52bb8d96dc1f7c6265fd93ec0da79c5898fbf9ebb3dc1bb2ffe8ad5eb8ab90e70f448d5fe3fad48c56d1bfcd93dd5b11f413eaeb15c0056ce58e6652cffa6da783774a82e27db165d9d8363082158db4c2fca14bce0b913326338a952f0c298c13f4e34914b7a30dee0b507de40fa8ad3c2f8f52d1728c2fcf55f6d1ebbd74086b553b14dd513b6350e3a768b8678ca52b18189a5b85564134db150477a016b7824e73e59449451b33fddc3fca5183dc7d9a198d69544c402d09a96e837c02247e4a6130d6eed2a9f2b30c3f738c35d70c85248c3b057359ed5ea1cd52b3d75eb9d54174e6a28ee2c6111a86baa9775f96a245abd0122b84590b748d11e36778668804478853cc95a6b177be3e89ad0d4dd55cf07353cb8977d3bd98060e117840d167f0db84d406970401cb2938b18074c16b36f9fd560d2658a28f3aee83ffb01f39fd96972dbcddd32018d34891143f8288664e979993eba480034fdab02115f30ad476c5814c52236c0351dce3f0dadbe16ad102d558e58e46f4de316d601f1eb8559fd6e7fa0da2edaa56f5a01fe1666e4700cbc5dc1ef9f7674f1fa53a82de533f9084a762ef55562b17634c10f12f1430c0c7be8aa9798546cd20c5eff8408a3cb350afaddd7ee636cd8ec151e393db773f5bbd9e176a34373d86ef942dd0d79b9e271371ed04fc6bee281bbcbc2cb0964bfde1e396a4c18625e8e24c29951cbdc14718e6d5109b0c08565d7735b9bca70a223539dda13c5e09eedc6ac0cfbf99a4807070785cf8dcebbab95d7a05ef72583571f7cf3444111c2d7cf6631862d9975944aad75d7121705fae35559fcc29c10be0ef7945100115b9f3c54195f6ba9878e79c64132a7fe77767413faf8cbbecf2ff69e85ec340b5692343cbd35c12b18aabc308b5d49214f95c8abe9237658b6f43919438f0789c7154d639c21103181eb034aea16574d9b6b961ebaa798d75ac2904f37e5a683dbb687f10e0818620bbadd332c64b26e0a1f4c6f64cfe00b35e9c5c8265032b1bb6ba5b13d924d0d200a10249cf5b69919d56f2f8ee7d0400c4ebf7153181646511f2519b3bca740aec21d724ced7aa4b820ab901cdfea9c89112d9e50021c63c6707ad027f5ca0be19cb4de574ebbafd938b3e9570d8be400d97da0ee86ba610153c7075ffa8b175ef3946454d98d904b82ce7ca96ff4cbac78721ac8c31f05fbb8e42c55b32556888450385e3540e73d58af2f6078582f2e941d213a237de856139ef5954f8af94fa85a9ece6f4b649d63fb0284a9c4fd576ad72a86371c8e8b2f43c27ce93027d0c7593926a6d69e87ea5795b61888c1aa80f605d1ba68fb1af27697f8a409f800b9405fc44a2b70c283d640d237b73b444da8326e7171c2f699e87c63a02d79cc10e62da48ed2f97597ab3c57c2944b11186e1df36974cc03a7c87606755b499406d36a35de4966e5a983e8cf04168af815d21fe1af84864fdbc6fc0b1a881b7f266d8cf96c7b67bd124bb3c785236d119466f2ff51edef931037f4fda1951cc8518579c4fd97d9e6e43c8848d5ec133e47a9aa5bc6f49295e63884fcb22e77fc54e4941241b888a31aa59e107b714f37d474deb8b9a62bd3a6e3867e6b8a972ffcbdd03d0c4880060a0297d9841d384b36f1682bc92768a1aea387214791408a323d534f9a3a362de6cad7bb3b395799a1c98d7ab4b909d19699256f2e028fa054ce49aa8645a150c2dcf0ebbabd87f87c14285b7475ea9fb1a2b772092d94e4a2332122b14c958c48dc2d147d4f797e5cbb1ade04c953f37555803900b7091ad9c274db66dba1ad056534beb09ff8030ec81d88848d7089d787aaaf897a74f9f91692557e5b306cbc359b986356bdfe5682a624c554dc42f3e521c76711beaa01733ba252670a55910720d4e62e0d294f49c7a5be941ab31619b07f28784a8196105c38585c29fbdfdf32b29c9dff18edb10cd5d176199bbec3d9c4b2eb6a5ee2867b255ad92ba3774d2356ce55e4ffee3c5cf8fceed59dda03fa9cda4bd1fc8f7005e2d9b67b2b729af552856a2d69a43380d8e3582bf5a0844ad15b75115a79b3c343c898164ca54480b7c4111b33949585bd30e2e660344012ad27a9e85fdf6ce509e07ea1ad1d81816db8e485d029101155c57641e2839a65c77e5eb43ccd16f81f626bd74c084bacde9e7716266b39a463ab4a1f2055fbdc00c20ea10db76139a5b90e106bfa4a51f41d475c303d094b6aa0303775b834388fee4d6677e18deecb5eaf8c3d591d3cb4c956ae34c7c60fe071f5d3f19cab9a59dd9423c6e88af1fa1223501da07cc214b18724ec1c587951ba0b1dc970bda7dc0ef804fdefebadee0965e023312ab274d01ff551753dc0b7afc85e10b68a9f56428cc2267fab541213b3ce4ce53b48aec637c8ea474774f6bdaa573f4eed9fd4998559a0670d82f622dc57e6e475c63c832aa4b17c31f83ba5d7ca5db9fdc57d4dbc9e8affaad3b65d1b3c4bf0b75df9f602ac32d1ea696219afb6952a294f4b540cce84a33242e065c609afa4e97d83aed8fbc70e410bb4ac1e64656c713f72378bfbae088c13d3e8e1fadbd2f5cfa1718d26c9376cb66449aecd642d476cdd411ab79511ea6608cfc1686b83d4ea4a0f8f197a759b62753860ab0c47b8caa719338d29ee89c6953ed4beebf5685b8b2ba9eb59fcefa66329670c5fe2ca4435c41b5ec4bddd9a69aa5727f8c7026cc337e7f5ea2b85d3e6eadf65d1da59921e9601684cbd6db98176793a8a778e4f97171b0a271463c772de46a0436964b32a57a00ff7e9b78ca13c743767b460bedf3a1d701196e2a87424a7fcdfaf115afcf9476b7992addc11bf5dd4485153818ddfe711c3fc14fb30aa9336100044e5a37d30d6d246459a6c6c38a28b0ee36c5f4ded811a115f23d4853e71cfbc48617fc8d469baeafc65234b2284f93d2a41953de6549f9c41b571867bbb6ff418332d3cbcc109f85d59203bc4d222a70ef70373f65e9cf0780289af7a3d8d168265f3864c5d2e933bacfa2424be11948b89596109584ca6e8ee0144c3d99a82cfab8846844f118601ab906b0b44730d79c9169db3822060b3fe635b51c060ba336c774dd1a5612319c004cd5a626743a468607a7cce9fd29ece8b85e868444b17ce733e80d2eae2e43585ed707a50ce1b2a2173dceff5f35b4dfeb79a69e18ae83d3f8445f0dd7f896096bd7e10383a59f95db4cd85ed6e54ca1cf899e13cd8fcf8d894fdde52f8598fb1581db8f2da9bd57d644127db11aec8803135259c6cad21a3a8cb51b86f5832f74d2d7da4c00ad6e04975e7986d4d7f5182ad6ac51225ea5bf595012f4da7a714ff27a654cbc5614843c848aaa8d1e71be240742e0225408d964430303d332924cf588f4c0bfb75f32c2907095476f00465ce5377a0864ea08f2916a2194b915e61d9829ba0af574d7d8d4fc61be6557c49d9b1893796a674dcd4a2d0ab1540da21721f9ba2889d40d11d15a03f47fb9b4758fb5d396fc3ef09dd2eb17340651bbd4d4d302171b64a5d134a14c2f5761d69baf6e087645f1569ae3c9430bd62569a771c3c9d386357852630d14d59bccaae73e88e79fd335da885dbc26e317a560e886b46237a9bf974c90f17e8d1a3193eb8f6a8a4085fe6afcfc6625155f230cf95e28b02b2aa25a07dd2b9402a7e11a026050b95f200b7f559706d39de6ea5c6a3290939e06c2dca3293634d1380cbea8776653dcd705517ec2d729f81f6402d576f5dabf30f4a8cdc49be08c481f63d7595360804f33291665408c80c03c205b4f72361e2950d32c7279a81d3d6a36479bb03f1ac6bfca0e129b096f3fc11b1a31322a3603bdbcf5f25ef6983aabfde61dbbfb31aebf6a6438c0de64b0fb58146993c8339ed1575816a6db7850ad758ee3d1b493442e12deb80ae936380c081a69dfbe7b86cbb28d5c225733e9c7e7674418cc7696f6bc482688210a51cea3c76ba11c21c21d75191c1f92f2834c1a9f9c6d1be9ad98508e7b4876621c126d0a3b9432e15f6aef3241bebfc3cb8f2dab4b96f97a61ee2e7312845d3614d817793f6c40190d7b17ef2b7bfc8ce665fc927dfd178722fa98d37e58d5c3ea763893f1f46390b9e412bb7b986e6f26e6b4998a7b7252bee2a919d92a4f63bcbccf52f7a4236cac4964dce74ba8572e8481de412bb53a0ec1667d3f64526bce5b1d39b5a49449f20a6d274d55e60b0c722a8c3606a1aed9a73738d634bd51a4b4be81283351fabfe38d8bc07b96495b56be9c69adf49958224936770455c97be2e895476df55af2d69e308a5b1f898d2d60896055b8f95f99cda6c961be77245025b3aae7411644fea5d5ed7c0f9fb6a9d48af4287b4be060236cee349ec67d4e94f6da473e30d4d406d95c62c1e7814aafe12b62e4ebfa9b4421b156a67e6743bb98d4bd17da6eec1e5a6591e5b6215675d6704257ca0cd1f71717e12fb61f365c8309df3e3e7646cf2ca5bf8fbb0e602e769c5510b11bbf114744ee38b80e0200a059a64daa7b699ea04851f976a7ac131cc0e2da1375524def3476375b4c4fc0e8e9e114f8873394b2ae418d4bff3bb202b523d2b7c897bbbac4f2af74dd5887ca6f5bfdc6a379332dd8f0a6a3b5792c1f1921642c1498dc23802f39f4e43e8f51f3415daa93f1985ad00c9e8768cad571d2016f57b05337882a38ad9f4470d205b1eb895de995fe90369bf0b6c0d73c5923465938cf6750d0a46ef63875d8eb0958c48459bae7ed3d0e6f1a4ff0c876e86f23f199e98d6fc6810cc76de5161e8c5d2e502ef34cdae2115a05ce7760248fbf9d29f89d80de97a7c4ce37d6999ed4c65057c55aa5b6295e0897474a4abd86b58a630b5519e24a96a9c36481adf71efddc96315cba56b0e648dbf25530ee8f03c8433265c28cd29475daaa79058194de73ea9f6beecbfbdac88cac419f91c685e36f599e7419d1b68ee540daf765f227cd6e91a6f1a83ac16f7619fa2c96da41337d7228a77a8bbf1659a978bc7c23e5cae67323f20d9d69bf343769ee98114b192c2d8567db0a2347fd93cff02620a59c45887ca6a95b586a04bae80994c31d39264e90306f73714ccddc98ab09f33d46be27789f44508d7a4e0294ddb7a972022adef1feb4bbf80b6acb41388b29fdb5eadb1741d38ae895ec6f034d72efe08fe09efc1063a32664526e718f90d541642e7a88852594ab25eb9eab2c473f4e86ce95f9ebb533d1a8d8a592931632928a08d8377a606e099c8ad9f42dcac63554b356a129a9e9573fcfb207b27baa436c6d4ddb4f8580d914a1263461e304db5e0815f7dd9b755db529032597b77050aa6c653afe3f7d7eac9e3df2d52b926639aa3f51d8cd5471da36ecf408bd859ce900e439901bd20c3c1bf000f6e62cd234e5fa295118a5b5f55100702fdafd43a7398894f4a3dd4f74889d27294143d5f3609d97ac3323c6f3d6ecbe990dcb5d975358f54153f286e78c8cfbc76cf3e2540614252d267ac9327d13fde8abc4b282014be61a11450aa26626c478ccab01c380f39cea9dc5d67501ab68b06bdcdd25871b7f3edfdff804e86957530235d7ea279358e444c2dba830c6fd5daadf7ff821eda6d9c8f6eb4ebad0d80fc45576ab4426f0b390ce9fb42312c23430d040d85efa8cde8e1a3c47a082d33cbea897edf90b00820032156816c8cc1218b9cbc41108f910a9a072afb6d94c20b5daa083a8c6f1e49570a82b779b06e91e01eeec67ad5fcc586401c91030a8300014a92973e2b4653816cfd1866ebe6a07b7b9050176f3f0fd7deb7094b96dca67a7fab85f80275b5616414ba3d11bed295420cb62860d5a01fe557eba85cab0dfbdd4ed1d7f30cdc0540690d7bfc99ff1e594e0dd369785079e2cc436db5a506ed65677921744aab605757d8f99d80cd79397578fa17671b4b70ebdf40a36ec697ece2a6d2b170bd083c0efd515b81acdf56c750064571d635ad50165f1e98519b12655820ef9393b33d71e037d8ae46f6e9ac84b732b21008111b16796ea62181f264aaa19c362b426516c97bbdbbf0b0da0e47f805847067261b62d7d699124645c6a6a983565815e6de4fbc31263380b6dc811fa9d4c1ed15690b2dc7c1afa5a4a810ee69bb8759c898287630273ba24e0a58de5608a0b0f5b0273c930fbc6aeb8b2ec767e4b8cf94740f93edbb0277d158d33a13e5d998b5cec54b5968271a32ce79f80118678f2978011bbaa86de2c5579e966ae17c6dd435279303fcb2d1cfdffafded27c921d1feea042f83e96f01bff7fc98215044eff87f28e65559c9b030a0676eac25552b5961084f162e8bb638d52c81b091ddbdaaf684c6f1cce30ff4c8c60f55148aed8bc5894c22114a2f37c483bd9d9eb809a483f918cd901f9c48251f8dcb19f35d61bf1105ec96e66f22601575a5abeedfd08dc5ec6669790c3b47e557d391adfb259ee0c86566ea1c4a93ad18003cb35a752e91df73a688cd65b92b754071ce3f6328f76c6d6f455eae1c4cd80e2b05cc183e1dadcd83deab48dcf62d191e0f69e1ea30f050b80640b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c645236986f1affba9e034017145436f7519e5681fa5b9940890979fb54be43bbf6f020878743657db91415e4a8fc09e163b187699edef68606efa016c0b74ebe26f020878743657db91415e4a8fc09e163b187699edef68606efa016c0b74ebe23edab1ff7eb6bf33f108e9ac1a08eb16c954b88a844e3119adf5950b44014eb63c8d900fcc619be33d08fd58502389ad641764bcccc2649d0c88659fc24b6d7be234489f88176e66bd858291d9de7054c6bdcedbb9f19ebedfab02d238b3dad79ac6a853e324ff7c5e92f5e9bbbfcda63466ec3e8a17fd9b3247f183465e93ca372fd5afc77f0d7f38658bb86153e8c7472376a5d735412237aea47881eb714ad1ffba188101427d74509d8786310f1e0793a251f31819283664626cbb6286bcdd109bc3de5bef59a8492c6f849e7cf1c2a665d6b5844e749d36a714fc4eb8f652fe79b889ef808d2d515a143bd50327674d18780056158238e627e37eaf784b4505976a7c3561f4c11d3d6507b4c18b802110be70e1266ecd65aa25fca95101a77e1f35756774bd632f5c4eb2c37314911471375f8123b8c3fc9ea3a5c0cc6d9b188fe909be6889a961ab6d53b11520bc8ef965b7387b554bd7c482b02b0f4f80d00110a008aff7aed1c6d66dfb2edfa2605d155c2d97a1c2877fd1bf4d770e6708988dc83ba66d6a40a20293dfee564ed40c41d5e541c2997e512019841b0b19fb878199014dea84874d11e319609135d4251944a93718a1549871f86355fe28ef6282e43d78006dfed31b909d581b41acb46b9a049d7babd678a808a8b42ef723c6b3654d1ff2ac20fe4e91db0ffb8387d06864cabae9e45d13b197ef3dcc5d88c0c453131707868135f170cd3c9683f02d06d3501e764593754b5f089bd7dd2b11d8da24b078973a81d23f56a3cd370391c47ad7ea923f5233254b2c62a41ea39a3c45f364074338dbc792fc2c11e46cd8506f84eec2d00b8b7cd076d84a54a4e74dfb2af63dad0b61ff21f4f95994201c284fe8f586948c544ff57e966e81d01c4e3d56cb060111b09771b67ad0ce7c76f75907623f84b05a05d45611f5bc55eab02c151e601843afc2885ab9824b294c7d32e6352066793e8ccf6663071d70e16fed8696139a12f8dc737261cc47235f1f6043d92c85ee5f87b03e8429862ec396b133cb906d4fc51662f88cdb3cd527f0c6b7012ed9be804ded9422125eb5dc9143c8d61b9b80d5cf522b829938f539a301cd22e79e52f6213df15534953e17076aff00521a5402e73915fd843905ff5a92e6db5564e3ddd38febf2dc5d98f8fed85c6075f8b02b13976a0930190debfc8b9465651dd71ce4610e5dd7b70c4fd455fbd6649d36f54adb32a85ed69d81552ddf2e2878f85120b57279c6f0f73a33836688f5f01e1ec80ba5725affffe64d3ca9d151d5ffbaf1d6317b22@rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootselinux-policy-3.13.1-268.el7_9.2.src.rpmselinux-policy-devel       /bin/sh/usr/bin/makecheckpolicym4policycoreutils-develrpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PartialHardlinkSets)rpmlib(PayloadFilesHavePrefix)selinux-policyrpmlib(PayloadIsXz)2.5-82.5-243.0.4-14.6.0-14.0.4-14.0-13.13.1-268.el7_9.25.2-14.11.3__V ^^x]µ]]{@]{@]]c@]n]V]V]S]R@]Ik]:@]5@]%@]\F@\\9\@\ޢ@\\@\@\7\@\\~d\y\s\k\V\R@\R@\@n@\;(@\2[v[[;@[;@[[R@[t[#@[@[@[[h@[[[9@[@[}P@[{[{[z@[m~@[i[i[i[dC[`O@[]@[Y[6@[3|@[2*["X[d@[[ [ L@[[[@[ZmZȲZZH@Z@ZZz@Zz@ZyZ_:ZWQZV@Z.s@Z)-@Z%8ZZ @ZZNZNYYA@YYW@YW@YYY@Y@Ycl@YP@YJ_YI@YBvY9<@Y6@Y5GY1S@Y0Y.@Y-^Y, @Y, @Y%uYYY@Y@Y@Y.YXQ@XXX@X@X@XXX@XۡXP@XXg@Xg@X~@X@XƉXCXCXX @XXXBXXXs{@XY@XWXRXRXOXJXAb@X@X)@X#X!@XWWSW_@W_@Wv@W;W@WίWW:WQW@WW@W@WW~W@WW~D@W{@Ws@WrfWj}WbW^@WYZ@WYZ@WUeWM|WBW9@W9@W1@W(W V@V@V@V޾V2V@V_VVCV@VZV @VqV }@V }@VBUUU@U@UpUUUUoUoU5@UUȒ@UĝUUWUU@UUK@UUU'Ua@U~@UzUv@UT@U@Tr@T@T@T7TTTC@T@TTT}Tto@TsTk4T`T[bTWn@T?@T>aT6xT6xT@S@SSDSg}@SB@S>S;S:@S9XS5d@S4S2@S0@S,)S*@S)S)S&S&S"@S!S L@SSS@SSc@SSnS @S SK@RRR@RRJ@Ra@RRR&R&RRR=RʚRR@R@R@Rv@Rv@R@RR@R R@R@R|@Rz/@Rz/@RsRpRnQRi RfhR_@R_@R[R[RSRNRNRL RIgRB@RB@R:@R1R-@R-@R(r@R' R%@R7RRNRR@Q@QQdQQ@QQޞ@Q@QکQکQ@QzQQ4Q@@Q@QKQQ@Q@Q@Q@QQ@QQQQ@Q@QQQ@Qzl@Qw@QvwQo@Qo@QnQm=@QkQfQb@Q`@Q^QZ@QQQIQGQ@j@Q9Q8@Q4Q0@Q-@Q& @Q$QQ@QQ@Q @Qh@QsPP@P@PP@P[PP!@P8@PO@P @Pf@PPqP @PP7@P@PPPYP@P@PPPM@PPd@P@PoP{@P{@P@PP5@P@P~P}L@Px@PvPvPuc@Puc@Pr@Pmz@Pmz@Pmz@Pj@Pd?Pd?Pb@PaPaP[@PXb@PWPS@PQPO'PM@PIP@@P>@P8@P7lP2&P2&P,P,P*=P(@P#@P#@P!@P!@P@PkPw@Pw@PP

@NNU@NNl@N@N@NåN@NNNN@NNN@N@NGNGNGN@N@NNS@NS@N^N^N @N @NNj@Nj@NN$@NN@N/N@N@NFNFN@NNN@N@N@N]Ni@Ni@Ni@N|tNyNx@Ns:@NoENoENiNf @N^"@N\N[@NTNS@NS@NC@NBrN:N98@N7N6@N2N.@N*N)f@N(N%qN$ @N@N7@N e@NpNpM@M@Md@Md@MM{@M@M۝M@M@M‘@M@M@M@My@My@M3@M@M@MMM@MMMMTMx@Mx@Mv@MlMbSM[@MRMQ0@MQ0@MJMGMGMA^@M>@M9u@M6@M5M4/@M4/@M0:M,F@M$]@M@M9MMMMM\@M M M@L!L!L@LL@L@L@LOLOL[@L@L@Lr@L L,@L,@Lډ@L7LLLNL@LΫLeL|L@LB@LB@LB@L@LMLL@LdLL{L*@L@L5LLA@LLLL@LcL@L@L@LzL)@L|L|L|L{@LvW@LvW@Ls@Ls@LrbLrbLmLk@LjyLe3Lc@La?@LZLYV@LXLN@LN@LMxLMxLI@LH2LF@LEL=L=L=L;L7@L LT@L@LL@L@L0LLGL@K^K^KKKj@K$@KKK@K@KK@K]K޺K@KtK#@KKՀ@K:@KK͗@KŮ@K\K\K @KKKKK9@KK@KK@K@KKKKrKK~@K,K,K,K@KK8@KKK@KK@KqKqK}+K{@K{@KuBKs@KqN@KjKie@Kf@Ka|@K`*K]KXAKTM@KPXKEKEKEKD{@KC)KA@K;@K2@K0K/c@K+nK*@K(K"4@KK>K>K>JJęJH@JH@JJJ_@J@JjJjJ@Jv@Jv@Jv@Jv@J$J@JJ0@J@J@JG@JG@J@JJ@J@J@JJJ#J@JJJ@J:J@JJQJ@J J J|@JzJyt@Jyt@Jx"JrJrJq@Jn@Jn@JmJhPJeJ\s@JW-@JT@JS8JKOJI@JCfJCfJB@J@J@J?r@J<@J;}J:,@J7@J67J2C@J0J/@J,@J%@JJB@JJMJ J dJ@J@JJ@J*@J*@II@IIA@IIII@I@IIIX@IX@IX@II@I@IcIIo@Io@IzI)@I@IܑI@@II@I@I@IԨIд@I̿In@I3I3I@II@I@IV@IIaIIm@I@I'@II2III@IIIIIIII@III@I1I@III~@I}Iy@Ix_Iw@IuItk@Itk@Io%@Ik0IeIcGIa@I`IVIO@IJ;@IHIAI>]I= @I7@I6tI3I-I@III9@I9@II IP@I@IIg@Ig@HHH@HrH~@H,H@HCHHH @H @Hf@Hf@H@H+H@H׈H׈H7@HBH@HǶH@HH|@HHH@H{@H)HHL@H@H@H@HnH}H|@Ht@HsVHr@Hl@HkmHgy@HcH`H_@H^>HRa@HQHQHO@HFHFH$@DX@DU@DN@DN@DLDH@DGwDGwDDD@@D?D?D;@D;@D:HD:HD2_D1@D1@D-D+@D+@D'D!<@D!<@D!<@DDD@D@D@DDDDDD@D@D@D@D uD $@D D @D @DDDFC@C@C@C@CCCCCR@CCCCC@Ci@CC@C@CtC@C@CC:@CECCC @C @CعCعCعCعCC@C-C-C-C@C@CCǖ@C@CáCáCP@CP@C[C @C @CCg@Cg@CCC!@C~@C,C@CCCCC@CC@C@C@CZCZC @C @CCCf@Cf@Cf@CC@CqCqC @C @C @CCC}@C7@C7@C7@CBCBCYC@C@CC}@CqCqZdenek Pytela - 3.13.1-268.2Zdenek Pytela - 3.13.1-268.1Zdenek Pytela - 3.13.1-268Zdenek Pytela - 3.13.1-267Lukas Vrabec - 3.13.1-266Lukas Vrabec - 3.13.1-265Lukas Vrabec - 3.13.1-264Lukas Vrabec - 3.13.1-263Lukas Vrabec - 3.13.1-262Lukas Vrabec - 3.13.1-261Lukas Vrabec - 3.13.1-260Lukas Vrabec - 3.13.1-259Lukas Vrabec - 3.13.1-258Lukas Vrabec - 3.13.1-257Lukas Vrabec - 3.13.1-256Lukas Vrabec - 3.13.1-255Lukas Vrabec - 3.13.1-254Lukas Vrabec - 3.13.1-253Lukas Vrabec - 3.13.1-252.1Lukas Vrabec - 3.13.1-252Lukas Vrabec - 3.13.1-251Lukas Vrabec - 3.13.1-250Lukas Vrabec - 3.13.1-249Lukas Vrabec - 3.13.1-248Lukas Vrabec - 3.13.1-247Lukas Vrabec - 3.13.1-246Lukas Vrabec - 3.13.1-245Lukas Vrabec - 3.13.1-244Lukas Vrabec - 3.13.1-243Lukas Vrabec - 3.13.1-242Lukas Vrabec - 3.13.1-241Lukas Vrabec - 3.13.1-240Lukas Vrabec - 3.13.1-239Lukas Vrabec - 3.13.1-238Lukas Vrabec - 3.13.1-237Lukas Vrabec - 3.13.1-236Lukas Vrabec - 3.13.1-235Lukas Vrabec - 3.13.1-234Lukas Vrabec - 3.13.1-233Lukas Vrabec - 3.13.1-232Lukas Vrabec - 3.13.1-231Lukas Vrabec - 3.13.1-230Lukas Vrabec - 3.13.1-229.5Lukas Vrabec - 3.13.1-229.4Lukas Vrabec - 3.13.1-229.3Lukas Vrabec - 3.13.1-229.2Lukas Vrabec - 3.13.1-229.1Lukas Vrabec - 3.13.1-229Lukas Vrabec - 3.13.1-228Lukas Vrabec - 3.13.1-227Lukas Vrabec - 3.13.1-226Lukas Vrabec - 3.13.1-225Lukas Vrabec - 3.13.1-224Lukas Vrabec - 3.13.1-223Lukas Vrabec - 3.13.1-222Lukas Vrabec - 3.13.1-221Lukas Vrabec - 3.13.1-220Lukas Vrabec - 3.13.1-219Lukas Vrabec - 3.13.1-218Lukas Vrabec - 3.13.1-217Lukas Vrabec - 3.13.1-216Lukas Vrabec - 3.13.1-215Lukas Vrabec - 3.13.1-214Lukas Vrabec - 3.13.1-213Lukas Vrabec - 3.13.1-212Lukas Vrabec - 3.13.1-211Lukas Vrabec - 3.13.1-210Lukas Vrabec - 3.13.1-209Lukas Vrabec - 3.13.1-208Lukas Vrabec - 3.13.1-207Lukas Vrabec - 3.13.1-206Lukas Vrabec - 3.13.1-205Lukas Vrabec - 3.13.1-204Lukas Vrabec - 3.13.1-203Lukas Vrabec - 3.13.1-202Lukas Vrabec - 3.13.1-201Lukas Vrabec - 3.13.1-200Lukas Vrabec - 3.13.1-199Lukas Vrabec - 3.13.1-198Lukas Vrabec - 3.13.1-197Lukas Vrabec - 3.13.1-196Lukas Vrabec - 3.13.1-195Lukas Vrabec - 3.13.1-194Lukas Vrabec - 3.13.1-193Lukas Vrabec - 3.13.1-192Lukas Vrabec - 3.13.1-191Lukas Vrabec - 3.13.1-190Lukas Vrabec - 3.13.1-189Lukas Vrabec - 3.13.1-188Lukas Vrabec - 3.13.1-187Lukas Vrabec - 3.13.1-186Lukas Vrabec - 3.13.1-185Lukas Vrabec - 3.13.1-184Lukas Vrabec - 3.13.1-183Lukas Vrabec - 3.13.1-182Lukas Vrabec - 3.13.1-181Lukas Vrabec - 3.13.1-180Lukas Vrabec - 3.13.1-179Lukas Vrabec - 3.13.1-178Lukas Vrabec - 3.13.1-177Lukas Vrabec - 3.13.1-176Lukas Vrabec - 3.13.1-175Lukas Vrabec - 3.13.1-174Lukas Vrabec - 3.13.1-173Lukas Vrabec - 3.13.1-172Lukas Vrabec - 3.13.1-171Lukas Vrabec - 3.13.1-170Lukas Vrabec - 3.13.1-169Lukas Vrabec - 3.13.1-168Lukas Vrabec - 3.13.1-167Lukas Vrabec - 3.13.1-166Lukas Vrabec - 3.13.1-165Lukas Vrabec - 3.13.1-164Lukas Vrabec - 3.13.1-163Lukas Vrabec - 3.13.1-162Lukas Vrabec - 3.13.1-161Lukas Vrabec - 3.13.1-160Lukas Vrabec - 3.13.1-159Lukas Vrabec - 3.13.1-158Lukas Vrabec - 3.13.1-157Lukas Vrabec - 3.13.1-156Lukas Vrabec - 3.13.1-155Lukas Vrabec - 3.13.1-154Lukas Vrabec - 3.13.1-153Lukas Vrabec - 3.13.1-152Lukas Vrabec - 3.13.1-151Lukas Vrabec - 3.13.1-150Lukas Vrabec - 3.13.1-149Lukas Vrabec - 3.13.1-148Lukas Vrabec - 3.13.1-147Lukas Vrabec - 3.13.1-146Lukas Vrabec - 3.13.1-145Lukas Vrabec - 3.13.1-144Lukas Vrabec - 3.13.1-143Lukas Vrabec - 3.13.1-142Lukas Vrabec - 3.13.1-141Lukas Vrabec - 3.13.1-140Lukas Vrabec - 3.13.1-139Lukas Vrabec - 3.13.1-138Lukas Vrabec - 3.13.1-137Lukas Vrabec - 3.13.1-136Lukas Vrabec - 3.13.1-135Lukas Vrabec - 3.13.1-134Lukas Vrabec - 3.13.1-133Lukas Vrabec - 3.13.1-132Lukas Vrabec - 3.13.1-131Lukas Vrabec - 3.13.1-130Lukas Vrabec - 3.13.1-129Lukas Vrabec - 3.13.1-128Lukas Vrabec - 3.13.1-127Lukas Vrabec - 3.13.1-126Lukas Vrabec - 3.13.1-125Lukas Vrabec - 3.13.1-124Lukas Vrabec - 3.13.1-123Lukas Vrabec - 3.13.1-122Lukas Vrabec - 3.13.1-120Lukas Vrabec - 3.13.1-119Lukas Vrabec - 3.13.1-118Lukas Vrabec - 3.13.1-117Lukas Vrabec - 3.13.1-116Lukas Vrabec - 3.13.1-115Lukas Vrabec - 3.13.1-114Lukas Vrabec - 3.13.1-113Lukas Vrabec - 3.13.1-112Lukas Vrabec - 3.13.1-111Lukas Vrabec - 3.13.1-110Lukas Vrabec - 3.13.1-109Lukas Vrabec - 3.13.1-108Lukas Vrabec - 3.13.1-107Lukas Vrabec - 3.13.1-106Miroslav Grepl - 3.13.1-105Lukas Vrabec - 3.13.1-104Lukas Vrabec - 3.13.1-103Dan Walsh - 3.13.1-102Lukas Vrabec - 3.13.1-101Lukas Vrabec - 3.13.1-100Lukas Vrabec - 3.13.1-99Lukas Vrabec - 3.13.1-98Lukas Vrabec - 3.13.1-97Lukas Vrabec - 3.13.1-96Lukas Vrabec - 3.13.1-95Lukas Vrabec - 3.13.1-94Lukas Vrabec - 3.13.1-93Lukas Vrabec - 3.13.1-92Lukas Vrabec - 3.13.1-91Lukas Vrabec - 3.13.1-90Lukas Vrabec - 3.13.1-89Lukas Vrabec - 3.13.1-88Lukas Vrabec - 3.13.1-87Lukas Vrabec - 3.13.1-86Lukas Vrabec - 3.13.1-85Lukas Vrabec - 3.13.1-84Lukas Vrabec - 3.13.1-83Lukas Vrabec - 3.13.1-82Lukas Vrabec - 3.13.1-81Lukas Vrabec - 3.13.1-80Petr Lautrbach - 3.13.1-79Lukas Vrabec - 3.13.1-78Lukas Vrabec - 3.13.1-77Lukas Vrabec - 3.13.1-76Lukas Vrabec - 3.13.1-75Lukas Vrabec - 3.13.1-74Lukas Vrabec - 3.13.1-73Lukas Vrabec - 3.13.1-72Lukas Vrabec - 3.13.1-71Lukas Vrabec - 3.13.1-70Lukas Vrabec - 3.13.1-69Lukas Vrabec - 3.13.1-68Lukas Vrabec - 3.13.1-67Petr Lautrbach - 3.13.1-66Lukas Vrabec 3.13.1-65Lukas Vrabec 3.13.1-64Lukas Vrabec 3.13.1-63Lukas Vrabec 3.13.1-62Lukas Vrabec 3.13.1-61Miroslav Grepl 3.13.1-60Miroslav Grepl 3.13.1-59Lukas Vrabec 3.13.1-58Lukas Vrabec 3.13.1-57Miroslav Grepl 3.13.1-56Lukas Vrabec 3.13.1-55Lukas Vrabec 3.13.1-54Lukas Vrabec 3.13.1-53Lukas Vrabec 3.13.1-52Miroslav Grepl 3.13.1-51Lukas Vrabec 3.13.1-50Lukas Vrabec 3.13.1-49Lukas Vrabec 3.13.1-48Lukas Vrabec 3.13.1-47Lukas Vrabec 3.13.1-46Lukas Vrabec 3.13.1-45Lukas Vrabec 3.13.1-44Lukas Vrabec 3.13.1-43Lukas Vrabec 3.13.1-42Lukas Vrabec 3.13.1-41Lukas Vrabec 3.13.1-40Miroslav Grepl 3.13.1-39Lukas Vrabec 3.13.1-38Lukas Vrabec 3.13.1-37Lukas Vrabec 3.13.1-36Lukas Vrabec 3.13.1-35Lukas Vrabec 3.13.1-34Lukas Vrabec 3.13.1-33Lukas Vrabec 3.13.1-32Miroslav Grepl 3.13.1-31Miroslav Grepl 3.13.1-30Miroslav Grepl 3.13.1-29Miroslav Grepl 3.13.1-28Miroslav Grepl 3.13.1-27Miroslav Grepl 3.13.1-26Miroslav Grepl 3.13.1-25Miroslav Grepl 3.13.1-24Miroslav Grepl 3.13.1-23Miroslav Grepl 3.13.1-22Miroslav Grepl 3.13.1-21Miroslav Grepl 3.13.1-20Miroslav Grepl 3.13.1-19Miroslav Grepl 3.13.1-18Miroslav Grepl 3.13.1-17Miroslav Grepl 3.13.1-16Miroslav Grepl 3.13.1-15Miroslav Grepl 3.13.1-14Miroslav Grepl 3.13.1-13Miroslav Grepl 3.13.1-12Miroslav Grepl 3.13.1-11Miroslav Grepl 3.13.1-10Miroslav Grepl 3.13.1-9Miroslav Grepl 3.13.1-8Miroslav Grepl 3.13.1-7Miroslav Grepl 3.13.1-6Miroslav Grepl 3.13.1-5Miroslav Grepl 3.13.1-4Miroslav Grepl 3.13.1-3Miroslav Grepl 3.13.1-2Miroslav Grepl 3.13.1-1Miroslav Grepl 3.12.1-156Miroslav Grepl 3.12.1-155Miroslav Grepl 3.12.1-154Miroslav Grepl 3.12.1-153Miroslav Grepl 3.12.1-152Miroslav Grepl 3.12.1-151Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-149Miroslav Grepl 3.12.1-148Miroslav Grepl 3.12.1-147Miroslav Grepl 3.12.1-146Miroslav Grepl 3.12.1-145Miroslav Grepl 3.12.1-144Lukas Vrabec 3.12.1-143Miroslav Grepl 3.12.1-142Miroslav Grepl 3.12.1-141Miroslav Grepl 3.12.1-140Miroslav Grepl 3.12.1-139Lukas Vrabec 3.12.1-138Miroslav Grepl 3.12.1-137Miroslav Grepl 3.12.1-136Miroslav Grepl 3.12.1-135Miroslav Grepl 3.12.1-134Miroslav Grepl 3.12.1-133Miroslav Grepl 3.12.1-132Miroslav Grepl 3.12.1-131Miroslav Grepl 3.12.1-130Miroslav Grepl 3.12.1-129Miroslav Grepl 3.12.1-128Miroslav Grepl 3.12.1-127Miroslav Grepl 3.12.1-126Miroslav Grepl 3.12.1-125Miroslav Grepl 3.12.1-124Miroslav Grepl 3.12.1-123Miroslav Grepl 3.12.1-122Miroslav Grepl 3.12.1-121Miroslav Grepl 3.12.1-120Miroslav Grepl 3.12.1-119Miroslav Grepl 3.12.1-118Miroslav Grepl 3.12.1-117Miroslav Grepl 3.12.1-116Miroslav Grepl 3.12.1-115Miroslav Grepl 3.12.1-114Miroslav Grepl 3.12.1-113Miroslav Grepl 3.12.1-112Miroslav Grepl 3.12.1-111Miroslav Grepl 3.12.1-110Miroslav Grepl 3.12.1-109Miroslav Grepl 3.12.1-108Miroslav Grepl 3.12.1-107Dan Walsh 3.12.1-106Miroslav Grepl 3.12.1-105Miroslav Grepl 3.12.1-104Miroslav Grepl 3.12.1-103Miroslav Grepl 3.12.1-102Miroslav Grepl 3.12.1-101Miroslav Grepl 3.12.1-100Miroslav Grepl 3.12.1-99Miroslav Grepl 3.12.1-98Miroslav Grepl 3.12.1-97Miroslav Grepl 3.12.1-96Miroslav Grepl 3.12.1-95Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-94Miroslav Grepl 3.12.1-93Miroslav Grepl 3.12.1-92Miroslav Grepl 3.12.1-91Miroslav Grepl 3.12.1-90Miroslav Grepl 3.12.1-89Miroslav Grepl 3.12.1-88Miroslav Grepl 3.12.1-87Miroslav Grepl 3.12.1-86Miroslav Grepl 3.12.1-85Miroslav Grepl 3.12.1-84Miroslav Grepl 3.12.1-83Miroslav Grepl 3.12.1-82Miroslav Grepl 3.12.1-81Miroslav Grepl 3.12.1-80Miroslav Grepl 3.12.1-79Miroslav Grepl 3.12.1-78Miroslav Grepl 3.12.1-77Miroslav Grepl 3.12.1-76Miroslav Grepl 3.12.1-75Miroslav Grepl 3.12.1-74Miroslav Grepl 3.12.1-73Miroslav Grepl 3.12.1-72Miroslav Grepl 3.12.1-71Miroslav Grepl 3.12.1-70Miroslav Grepl 3.12.1-69Miroslav Grepl 3.12.1-68Miroslav Grepl 3.12.1-67Miroslav Grepl 3.12.1-66Miroslav Grepl 3.12.1-65Miroslav Grepl 3.12.1-64Miroslav Grepl 3.12.1-63Miroslav Grepl 3.12.1-62Miroslav Grepl 3.12.1-61Miroslav Grepl 3.12.1-60Miroslav Grepl 3.12.1-59Miroslav Grepl 3.12.1-58Miroslav Grepl 3.12.1-57Miroslav Grepl 3.12.1-56Miroslav Grepl 3.12.1-55Miroslav Grepl 3.12.1-54Miroslav Grepl 3.12.1-53Miroslav Grepl 3.12.1-52Miroslav Grepl 3.12.1-51Miroslav Grepl 3.12.1-50Miroslav Grepl 3.12.1-49Miroslav Grepl 3.12.1-48Miroslav Grepl 3.12.1-47Miroslav Grepl 3.12.1-46Miroslav Grepl 3.12.1-45Miroslav Grepl 3.12.1-44Miroslav Grepl 3.12.1-43Miroslav Grepl 3.12.1-42Miroslav Grepl 3.12.1-41Miroslav Grepl 3.12.1-40Miroslav Grepl 3.12.1-39Miroslav Grepl 3.12.1-38Miroslav Grepl 3.12.1-37Miroslav Grepl 3.12.1-36Miroslav Grepl 3.12.1-35Miroslav Grepl 3.12.1-34Miroslav Grepl 3.12.1-33Miroslav Grepl 3.12.1-32Miroslav Grepl 3.12.1-31Miroslav Grepl 3.12.1-30Miroslav Grepl 3.12.1-29Dan Walsh 3.12.1-28Dan Walsh 3.12.1-27Miroslav Grepl 3.12.1-26Miroslav Grepl 3.12.1-25Miroslav Grepl 3.12.1-24Miroslav Grepl 3.12.1-23Miroslav Grepl 3.12.1-22Miroslav Grepl 3.12.1-21Miroslav Grepl 3.12.1-20Miroslav Grepl 3.12.1-19Miroslav Grepl 3.12.1-18Miroslav Grepl 3.12.1-17Miroslav Grepl 3.12.1-16Miroslav Grepl 3.12.1-15Miroslav Grepl 3.12.1-14Miroslav Grepl 3.12.1-13Miroslav Grepl 3.12.1-12Miroslav Grepl 3.12.1-11Miroslav Grepl 3.12.1-10Miroslav Grepl 3.12.1-9Miroslav Grepl 3.12.1-8Miroslav Grepl 3.12.1-7Miroslav Grepl 3.12.1-6Miroslav Grepl 3.12.1-5Miroslav Grepl 3.12.1-4Miroslav Grepl 3.12.1-3Miroslav Grepl 3.12.1-2Miroslav Grepl 3.12.1-1Dan Walsh 3.11.1-69.1Miroslav Grepl 3.11.1-69Miroslav Grepl 3.11.1-68Miroslav Grepl 3.11.1-67Miroslav Grepl 3.11.1-66Miroslav Grepl 3.11.1-65Miroslav Grepl 3.11.1-64Miroslav Grepl 3.11.1-63Miroslav Grepl 3.11.1-62Miroslav Grepl 3.11.1-61Miroslav Grepl 3.11.1-60Miroslav Grepl 3.11.1-59Miroslav Grepl 3.11.1-58Miroslav Grepl 3.11.1-57Miroslav Grepl 3.11.1-56Miroslav Grepl 3.11.1-55Miroslav Grepl 3.11.1-54Miroslav Grepl 3.11.1-53Miroslav Grepl 3.11.1-52Miroslav Grepl 3.11.1-51Miroslav Grepl 3.11.1-50Miroslav Grepl 3.11.1-49Miroslav Grepl 3.11.1-48Miroslav Grepl 3.11.1-47Miroslav Grepl 3.11.1-46Miroslav Grepl 3.11.1-45Miroslav Grepl 3.11.1-44Miroslav Grepl 3.11.1-43Miroslav Grepl 3.11.1-42Miroslav Grepl 3.11.1-41Miroslav Grepl 3.11.1-40Miroslav Grepl 3.11.1-39Miroslav Grepl 3.11.1-38Miroslav Grepl 3.11.1-37Miroslav Grepl 3.11.1-36Miroslav Grepl 3.11.1-35Miroslav Grepl 3.11.1-34Miroslav Grepl 3.11.1-33Miroslav Grepl 3.11.1-32Miroslav Grepl 3.11.1-31Miroslav Grepl 3.11.1-30Miroslav Grepl 3.11.1-29Miroslav Grepl 3.11.1-28Miroslav Grepl 3.11.1-27Miroslav Grepl 3.11.1-26Miroslav Grepl 3.11.1-25Miroslav Grepl 3.11.1-24Miroslav Grepl 3.11.1-23Miroslav Grepl 3.11.1-22Miroslav Grepl 3.11.1-21Miroslav Grepl 3.11.1-20Miroslav Grepl 3.11.1-19Miroslav Grepl 3.11.1-18Miroslav Grepl 3.11.1-17Miroslav Grepl 3.11.1-16Dan Walsh 3.11.1-15Miroslav Grepl 3.11.1-14Dan Walsh 3.11.1-13Miroslav Grepl 3.11.1-12Miroslav Grepl 3.11.1-11Miroslav Grepl 3.11.1-10Dan Walsh 3.11.1-9Dan Walsh 3.11.1-8Dan Walsh 3.11.1-7Dan Walsh 3.11.1-6Miroslav Grepl 3.11.1-5Miroslav Grepl 3.11.1-4Miroslav Grepl 3.11.1-3Miroslav Grepl 3.11.1-2Miroslav Grepl 3.11.1-1Miroslav Grepl 3.11.1-0Miroslav Grepl 3.11.0-15Miroslav Grepl 3.11.0-14Miroslav Grepl 3.11.0-13Miroslav Grepl 3.11.0-12Fedora Release Engineering - 3.11.0-11Miroslav Grepl 3.11.0-10Miroslav Grepl 3.11.0-9Miroslav Grepl 3.11.0-8Miroslav Grepl 3.11.0-7Miroslav Grepl 3.11.0-6Miroslav Grepl 3.11.0-5Miroslav Grepl 3.11.0-4Miroslav Grepl 3.11.0-3Miroslav Grepl 3.11.0-2Miroslav Grepl 3.11.0-1Miroslav Grepl 3.10.0-128Miroslav Grepl 3.10.0-127Miroslav Grepl 3.10.0-126Miroslav Grepl 3.10.0-125Miroslav Grepl 3.10.0-124Miroslav Grepl 3.10.0-123Miroslav Grepl 3.10.0-122Miroslav Grepl 3.10.0-121Miroslav Grepl 3.10.0-120Miroslav Grepl 3.10.0-119Miroslav Grepl 3.10.0-118Miroslav Grepl 3.10.0-117Miroslav Grepl 3.10.0-116Miroslav Grepl 3.10.0-115Miroslav Grepl 3.10.0-114Miroslav Grepl 3.10.0-113Miroslav Grepl 3.10.0-112Miroslav Grepl 3.10.0-111Miroslav Grepl 3.10.0-110Miroslav Grepl 3.10.0-109Miroslav Grepl 3.10.0-108Miroslav Grepl 3.10.0-107Miroslav Grepl 3.10.0-106Miroslav Grepl 3.10.0-105Miroslav Grepl 3.10.0-104Miroslav Grepl 3.10.0-103Miroslav Grepl 3.10.0-102Miroslav Grepl 3.10.0-101Miroslav Grepl 3.10.0-100Miroslav Grepl 3.10.0-99Miroslav Grepl 3.10.0-98Miroslav Grepl 3.10.0-97Miroslav Grepl 3.10.0-96Miroslav Grepl 3.10.0-95Miroslav Grepl 3.10.0-94Miroslav Grepl 3.10.0-93Miroslav Grepl 3.10.0-92Miroslav Grepl 3.10.0-91Miroslav Grepl 3.10.0-90Miroslav Grepl 3.10.0-89Miroslav Grepl 3.10.0-88Miroslav Grepl 3.10.0-87Miroslav Grepl 3.10.0-86Miroslav Grepl 3.10.0-85Miroslav Grepl 3.10.0-84Miroslav Grepl 3.10.0-83Miroslav Grepl 3.10.0-82Dan Walsh 3.10.0-81.2Miroslav Grepl 3.10.0-81Miroslav Grepl 3.10.0-80Miroslav Grepl 3.10.0-79Miroslav Grepl 3.10.0-78Miroslav Grepl 3.10.0-77Miroslav Grepl 3.10.0-76Miroslav Grepl 3.10.0-75Dan Walsh 3.10.0-74.2Miroslav Grepl 3.10.0-74Miroslav Grepl 3.10.0-73Miroslav Grepl 3.10.0-72Miroslav Grepl 3.10.0-71Miroslav Grepl 3.10.0-70Miroslav Grepl 3.10.0-69Miroslav Grepl 3.10.0-68Miroslav Grepl 3.10.0-67Miroslav Grepl 3.10.0-66Miroslav Grepl 3.10.0-65Miroslav Grepl 3.10.0-64Miroslav Grepl 3.10.0-63Miroslav Grepl 3.10.0-59Miroslav Grepl 3.10.0-58Dan Walsh 3.10.0-57Dan Walsh 3.10.0-56Dan Walsh 3.10.0-55.2Dan Walsh 3.10.0-55.1Miroslav Grepl 3.10.0-55Dan Walsh 3.10.0-54.1Miroslav Grepl 3.10.0-54Dan Walsh 3.10.0-53.1Miroslav Grepl 3.10.0-53Miroslav Grepl 3.10.0-52Miroslav Grepl 3.10.0-51Dan Walsh 3.10.0-50.2Dan Walsh 3.10.0-50.1Miroslav Grepl 3.10.0-50Miroslav Grepl 3.10.0-49Miroslav Grepl 3.10.0-48Miroslav Grepl 3.10.0-47Dan Walsh 3.10.0-46.1Miroslav Grepl 3.10.0-46Dan Walsh 3.10.0-45.1Miroslav Grepl 3.10.0-45Miroslav Grepl 3.10.0-43Miroslav Grepl 3.10.0-42Miroslav Grepl 3.10.0-41Dan Walsh 3.10.0-40.2Miroslav Grepl 3.10.0-40Dan Walsh 3.10.0-39.3Dan Walsh 3.10.0-39.2Dan Walsh 3.10.0-39.1Miroslav Grepl 3.10.0-39Dan Walsh 3.10.0-38.1Miroslav Grepl 3.10.0-38Miroslav Grepl 3.10.0-37Dan Walsh 3.10.0-36.1Miroslav Grepl 3.10.0-36Dan Walsh 3.10.0-35Dan Walsh 3.10.0-34.7Dan Walsh 3.10.0-34.6Dan Walsh 3.10.0-34.4Miroslav Grepl 3.10.0-34.3Dan Walsh 3.10.0-34.2Dan Walsh 3.10.0-34.1Miroslav Grepl 3.10.0-34Miroslav Grepl 3.10.0-33Dan Walsh 3.10.0-31.1Miroslav Grepl 3.10.0-31Miroslav Grepl 3.10.0-29Miroslav Grepl 3.10.0-28Miroslav Grepl 3.10.0-27Miroslav Grepl 3.10.0-26Miroslav Grepl 3.10.0-25Miroslav Grepl 3.10.0-24Miroslav Grepl 3.10.0-23Miroslav Grepl 3.10.0-22Miroslav Grepl 3.10.0-21Dan Walsh 3.10.0-20Miroslav Grepl 3.10.0-19Miroslav Grepl 3.10.0-18Miroslav Grepl 3.10.0-17Miroslav Grepl 3.10.0-16Miroslav Grepl 3.10.0-14Miroslav Grepl 3.10.0-13Miroslav Grepl 3.10.0-12Miroslav Grepl 3.10.0-11Miroslav Grepl 3.10.0-10Miroslav Grepl 3.10.0-9Miroslav Grepl 3.10.0-8Miroslav Grepl 3.10.0-7Miroslav Grepl 3.10.0-6Miroslav Grepl 3.10.0-5Miroslav Grepl 3.10.0-4Miroslav Grepl 3.10.0-3Miroslav Grepl 3.10.0-2Miroslav Grepl 3.10.0-1Miroslav Grepl 3.9.16-30Dan Walsh 3.9.16-29.1Miroslav Grepl 3.9.16-29Dan Walsh 3.9.16-28.1Miroslav Grepl 3.9.16-27Miroslav Grepl 3.9.16-26Miroslav Grepl 3.9.16-25Miroslav Grepl 3.9.16-24Miroslav Grepl 3.9.16-23Miroslav Grepl 3.9.16-22Miroslav Grepl 3.9.16-21Miroslav Grepl 3.9.16-20Miroslav Grepl 3.9.16-19Miroslav Grepl 3.9.16-18Miroslav Grepl 3.9.16-17Dan Walsh 3.9.16-16.1Miroslav Grepl 3.9.16-16Miroslav Grepl 3.9.16-15Miroslav Grepl 3.9.16-14Miroslav Grepl 3.9.16-13Miroslav Grepl 3.9.16-12Miroslav Grepl 3.9.16-11Miroslav Grepl 3.9.16-10Miroslav Grepl 3.9.16-7Miroslav Grepl 3.9.16-6Miroslav Grepl 3.9.16-5Miroslav Grepl 3.9.16-4Miroslav Grepl 3.9.16-3Miroslav Grepl 3.9.16-2Miroslav Grepl 3.9.16-1Miroslav Grepl 3.9.15-5Miroslav Grepl 3.9.15-2Miroslav Grepl 3.9.15-1Fedora Release Engineering - 3.9.14-2Dan Walsh 3.9.14-1Miroslav Grepl 3.9.13-10Miroslav Grepl 3.9.13-9Dan Walsh 3.9.13-8Miroslav Grepl 3.9.13-7Miroslav Grepl 3.9.13-6Miroslav Grepl 3.9.13-5Miroslav Grepl 3.9.13-4Miroslav Grepl 3.9.13-3Miroslav Grepl 3.9.13-2Miroslav Grepl 3.9.13-1Miroslav Grepl 3.9.12-8Miroslav Grepl 3.9.12-7Miroslav Grepl 3.9.12-6Miroslav Grepl 3.9.12-5Dan Walsh 3.9.12-4Dan Walsh 3.9.12-3Dan Walsh 3.9.12-2Miroslav Grepl 3.9.12-1Dan Walsh 3.9.11-2Miroslav Grepl 3.9.11-1Miroslav Grepl 3.9.10-13Dan Walsh 3.9.10-12Miroslav Grepl 3.9.10-11Miroslav Grepl 3.9.10-10Miroslav Grepl 3.9.10-9Miroslav Grepl 3.9.10-8Miroslav Grepl 3.9.10-7Miroslav Grepl 3.9.10-6Miroslav Grepl 3.9.10-5Dan Walsh 3.9.10-4Miroslav Grepl 3.9.10-3Miroslav Grepl 3.9.10-2Miroslav Grepl 3.9.10-1Miroslav Grepl 3.9.9-4Dan Walsh 3.9.9-3Miroslav Grepl 3.9.9-2Miroslav Grepl 3.9.9-1Miroslav Grepl 3.9.8-7Dan Walsh 3.9.8-6Miroslav Grepl 3.9.8-5Miroslav Grepl 3.9.8-4Dan Walsh 3.9.8-3Dan Walsh 3.9.8-2Dan Walsh 3.9.8-1Dan Walsh 3.9.7-10Dan Walsh 3.9.7-9Dan Walsh 3.9.7-8Dan Walsh 3.9.7-7Dan Walsh 3.9.7-6Dan Walsh 3.9.7-5Dan Walsh 3.9.7-4Dan Walsh 3.9.7-3Dan Walsh 3.9.7-2Dan Walsh 3.9.7-1Dan Walsh 3.9.6-3Dan Walsh 3.9.6-2Dan Walsh 3.9.6-1Dan Walsh 3.9.5-11Dan Walsh 3.9.5-10Dan Walsh 3.9.5-9Dan Walsh 3.9.5-8Dan Walsh 3.9.5-7Dan Walsh 3.9.5-6Dan Walsh 3.9.5-5Dan Walsh 3.9.5-4Dan Walsh 3.9.5-3Dan Walsh 3.9.5-2Dan Walsh 3.9.5-1Dan Walsh 3.9.4-3Dan Walsh 3.9.4-2Dan Walsh 3.9.4-1Dan Walsh 3.9.3-4Dan Walsh 3.9.3-3Dan Walsh 3.9.3-2Dan Walsh 3.9.3-1Dan Walsh 3.9.2-1Dan Walsh 3.9.1-3Dan Walsh 3.9.1-2Dan Walsh 3.9.1-1Dan Walsh 3.9.0-2Dan Walsh 3.9.0-1Dan Walsh 3.8.8-21Dan Walsh 3.8.8-20Dan Walsh 3.8.8-19Dan Walsh 3.8.8-18Dan Walsh 3.8.8-17Dan Walsh 3.8.8-16Dan Walsh 3.8.8-15Dan Walsh 3.8.8-14Dan Walsh 3.8.8-13Dan Walsh 3.8.8-12Dan Walsh 3.8.8-11Dan Walsh 3.8.8-10Dan Walsh 3.8.8-9Dan Walsh 3.8.8-8Dan Walsh 3.8.8-7Dan Walsh 3.8.8-6Dan Walsh 3.8.8-5Dan Walsh 3.8.8-4Dan Walsh 3.8.8-3Dan Walsh 3.8.8-2Dan Walsh 3.8.8-1Dan Walsh 3.8.7-3Dan Walsh 3.8.7-2Dan Walsh 3.8.7-1Dan Walsh 3.8.6-3Miroslav Grepl 3.8.6-2Dan Walsh 3.8.6-1Dan Walsh 3.8.5-1Dan Walsh 3.8.4-1Dan Walsh 3.8.3-4Dan Walsh 3.8.3-3Dan Walsh 3.8.3-2Dan Walsh 3.8.3-1Dan Walsh 3.8.2-1Dan Walsh 3.8.1-5Dan Walsh 3.8.1-4Dan Walsh 3.8.1-3Dan Walsh 3.8.1-2Dan Walsh 3.8.1-1Dan Walsh 3.7.19-22Dan Walsh 3.7.19-21Dan Walsh 3.7.19-20Dan Walsh 3.7.19-19Dan Walsh 3.7.19-17Dan Walsh 3.7.19-16Dan Walsh 3.7.19-15Dan Walsh 3.7.19-14Dan Walsh 3.7.19-13Dan Walsh 3.7.19-12Dan Walsh 3.7.19-11Dan Walsh 3.7.19-10Dan Walsh 3.7.19-9Dan Walsh 3.7.19-8Dan Walsh 3.7.19-7Dan Walsh 3.7.19-6Dan Walsh 3.7.19-5Dan Walsh 3.7.19-4Dan Walsh 3.7.19-3Dan Walsh 3.7.19-2Dan Walsh 3.7.19-1Dan Walsh 3.7.18-3Dan Walsh 3.7.18-2Dan Walsh 3.7.18-1Dan Walsh 3.7.17-6Dan Walsh 3.7.17-5Dan Walsh 3.7.17-4Dan Walsh 3.7.17-3Dan Walsh 3.7.17-2Dan Walsh 3.7.17-1Dan Walsh 3.7.16-2Dan Walsh 3.7.16-1Dan Walsh 3.7.15-4Dan Walsh 3.7.15-3Dan Walsh 3.7.15-2Dan Walsh 3.7.15-1Dan Walsh 3.7.14-5Dan Walsh 3.7.14-4Dan Walsh 3.7.14-3Dan Walsh 3.7.14-2Dan Walsh 3.7.14-1Dan Walsh 3.7.13-4Dan Walsh 3.7.13-3Dan Walsh 3.7.13-2Dan Walsh 3.7.13-1Dan Walsh 3.7.12-1Dan Walsh 3.7.11-1Dan Walsh 3.7.10-5Dan Walsh 3.7.10-4Dan Walsh 3.7.10-3Dan Walsh 3.7.10-2Dan Walsh 3.7.10-1Dan Walsh 3.7.9-4Dan Walsh 3.7.9-3Dan Walsh 3.7.9-2Dan Walsh 3.7.9-1Dan Walsh 3.7.8-11Dan Walsh 3.7.8-9Dan Walsh 3.7.8-8Dan Walsh 3.7.8-7Dan Walsh 3.7.8-6Dan Walsh 3.7.8-5Dan Walsh 3.7.8-4Dan Walsh 3.7.8-3Dan Walsh 3.7.8-2Dan Walsh 3.7.8-1Dan Walsh 3.7.7-3Dan Walsh 3.7.7-2Dan Walsh 3.7.7-1Dan Walsh 3.7.6-1Dan Walsh 3.7.5-8Dan Walsh 3.7.5-7Dan Walsh 3.7.5-6Dan Walsh 3.7.5-5Dan Walsh 3.7.5-4Dan Walsh 3.7.5-3Dan Walsh 3.7.5-2Dan Walsh 3.7.5-1Dan Walsh 3.7.4-4Dan Walsh 3.7.4-3Dan Walsh 3.7.4-2Dan Walsh 3.7.4-1Dan Walsh 3.7.3-1Dan Walsh 3.7.1-1Dan Walsh 3.6.33-2Dan Walsh 3.6.33-1Dan Walsh 3.6.32-17Dan Walsh 3.6.32-16Dan Walsh 3.6.32-15Dan Walsh 3.6.32-13Dan Walsh 3.6.32-12Dan Walsh 3.6.32-11Dan Walsh 3.6.32-10Dan Walsh 3.6.32-9Dan Walsh 3.6.32-8Dan Walsh 3.6.32-7Dan Walsh 3.6.32-6Dan Walsh 3.6.32-5Dan Walsh 3.6.32-4Dan Walsh 3.6.32-3Dan Walsh 3.6.32-2Dan Walsh 3.6.32-1Dan Walsh 3.6.31-5Dan Walsh 3.6.31-4Dan Walsh 3.6.31-3Dan Walsh 3.6.31-2Dan Walsh 3.6.30-6Dan Walsh 3.6.30-5Dan Walsh 3.6.30-4Dan Walsh 3.6.30-3Dan Walsh 3.6.30-2Dan Walsh 3.6.30-1Dan Walsh 3.6.29-2Dan Walsh 3.6.29-1Dan Walsh 3.6.28-9Dan Walsh 3.6.28-8Dan Walsh 3.6.28-7Dan Walsh 3.6.28-6Dan Walsh 3.6.28-5Dan Walsh 3.6.28-4Dan Walsh 3.6.28-3Dan Walsh 3.6.28-2Dan Walsh 3.6.28-1Dan Walsh 3.6.27-1Dan Walsh 3.6.26-11Dan Walsh 3.6.26-10Dan Walsh 3.6.26-9Bill Nottingham 3.6.26-8Dan Walsh 3.6.26-7Dan Walsh 3.6.26-6Dan Walsh 3.6.26-5Dan Walsh 3.6.26-4Dan Walsh 3.6.26-3Dan Walsh 3.6.26-2Dan Walsh 3.6.26-1Dan Walsh 3.6.25-1Dan Walsh 3.6.24-1Dan Walsh 3.6.23-2Dan Walsh 3.6.23-1Dan Walsh 3.6.22-3Dan Walsh 3.6.22-1Dan Walsh 3.6.21-4Dan Walsh 3.6.21-3Tom "spot" Callaway 3.6.21-2Dan Walsh 3.6.21-1Dan Walsh 3.6.20-2Dan Walsh 3.6.20-1Dan Walsh 3.6.19-5Dan Walsh 3.6.19-4Dan Walsh 3.6.19-3Dan Walsh 3.6.19-2Dan Walsh 3.6.19-1Dan Walsh 3.6.18-1Dan Walsh 3.6.17-1Dan Walsh 3.6.16-4Dan Walsh 3.6.16-3Dan Walsh 3.6.16-2Dan Walsh 3.6.16-1Dan Walsh 3.6.14-3Dan Walsh 3.6.14-2Dan Walsh 3.6.14-1Dan Walsh 3.6.13-3Dan Walsh 3.6.13-2Dan Walsh 3.6.13-1Dan Walsh 3.6.12-39Dan Walsh 3.6.12-38Dan Walsh 3.6.12-37Dan Walsh 3.6.12-36Dan Walsh 3.6.12-35Dan Walsh 3.6.12-34Dan Walsh 3.6.12-33Dan Walsh 3.6.12-31Dan Walsh 3.6.12-30Dan Walsh 3.6.12-29Dan Walsh 3.6.12-28Dan Walsh 3.6.12-27Dan Walsh 3.6.12-26Dan Walsh 3.6.12-25Dan Walsh 3.6.12-24Dan Walsh 3.6.12-23Dan Walsh 3.6.12-22Dan Walsh 3.6.12-21Dan Walsh 3.6.12-20Dan Walsh 3.6.12-19Dan Walsh 3.6.12-16Dan Walsh 3.6.12-15Dan Walsh 3.6.12-14Dan Walsh 3.6.12-13Dan Walsh 3.6.12-12Dan Walsh 3.6.12-11Dan Walsh 3.6.12-10Dan Walsh 3.6.12-9Dan Walsh 3.6.12-8Dan Walsh 3.6.12-7Dan Walsh 3.6.12-6Dan Walsh 3.6.12-5Dan Walsh 3.6.12-4Dan Walsh 3.6.12-3Dan Walsh 3.6.12-2Dan Walsh 3.6.12-1Dan Walsh 3.6.11-1Dan Walsh 3.6.10-9Dan Walsh 3.6.10-8Dan Walsh 3.6.10-7Dan Walsh 3.6.10-6Dan Walsh 3.6.10-5Dan Walsh 3.6.10-4Dan Walsh 3.6.10-3Dan Walsh 3.6.10-2Dan Walsh 3.6.10-1Dan Walsh 3.6.9-4Dan Walsh 3.6.9-3Dan Walsh 3.6.9-2Dan Walsh 3.6.9-1Dan Walsh 3.6.8-4Dan Walsh 3.6.8-3Dan Walsh 3.6.8-2Dan Walsh 3.6.8-1Dan Walsh 3.6.7-2Dan Walsh 3.6.7-1Dan Walsh 3.6.6-9Dan Walsh 3.6.6-8Fedora Release Engineering - 3.6.6-7Dan Walsh 3.6.6-6Dan Walsh 3.6.6-5Dan Walsh 3.6.6-4Dan Walsh 3.6.6-3Dan Walsh 3.6.6-2Dan Walsh 3.6.6-1Dan Walsh 3.6.5-3Dan Walsh 3.6.5-1Dan Walsh 3.6.4-6Dan Walsh 3.6.4-5Dan Walsh 3.6.4-4Dan Walsh 3.6.4-3Dan Walsh 3.6.4-2Dan Walsh 3.6.4-1Dan Walsh 3.6.3-13Dan Walsh 3.6.3-12Dan Walsh 3.6.3-11Dan Walsh 3.6.3-10Dan Walsh 3.6.3-9Dan Walsh 3.6.3-8Dan Walsh 3.6.3-7Dan Walsh 3.6.3-6Dan Walsh 3.6.3-3Dan Walsh 3.6.3-2Dan Walsh 3.6.3-1Dan Walsh 3.6.2-5Dan Walsh 3.6.2-4Dan Walsh 3.6.2-3Dan Walsh 3.6.2-2Dan Walsh 3.6.2-1Dan Walsh 3.6.1-15Dan Walsh 3.6.1-14Dan Walsh 3.6.1-13Dan Walsh 3.6.1-12Dan Walsh 3.6.1-11Dan Walsh 3.6.1-10Dan Walsh 3.6.1-9Dan Walsh 3.6.1-8Dan Walsh 3.6.1-7Dan Walsh 3.6.1-4Ignacio Vazquez-Abrams - 3.6.1-2Dan Walsh 3.5.13-19Dan Walsh 3.5.13-18Dan Walsh 3.5.13-17Dan Walsh 3.5.13-16Dan Walsh 3.5.13-15Dan Walsh 3.5.13-14Dan Walsh 3.5.13-13Dan Walsh 3.5.13-12Dan Walsh 3.5.13-11Dan Walsh 3.5.13-9Dan Walsh 3.5.13-8Dan Walsh 3.5.13-7Dan Walsh 3.5.13-6Dan Walsh 3.5.13-5Dan Walsh 3.5.13-4Dan Walsh 3.5.13-3Dan Walsh 3.5.13-2Dan Walsh 3.5.13-1Dan Walsh 3.5.12-3Dan Walsh 3.5.12-2Dan Walsh 3.5.12-1Dan Walsh 3.5.11-1Dan Walsh 3.5.10-3Dan Walsh 3.5.10-2Dan Walsh 3.5.10-1Dan Walsh 3.5.9-4Dan Walsh 3.5.9-3Dan Walsh 3.5.9-2Dan Walsh 3.5.9-1Dan Walsh 3.5.8-7Dan Walsh 3.5.8-6Dan Walsh 3.5.8-5Dan Walsh 3.5.8-4Dan Walsh 3.5.8-3Dan Walsh 3.5.8-1Dan Walsh 3.5.7-2Dan Walsh 3.5.7-1Dan Walsh 3.5.6-2Dan Walsh 3.5.6-1Dan Walsh 3.5.5-4Dan Walsh 3.5.5-3Dan Walsh 3.5.5-2Dan Walsh 3.5.4-2Dan Walsh 3.5.4-1Dan Walsh 3.5.3-1Dan Walsh 3.5.2-2Dan Walsh 3.5.1-5Dan Walsh 3.5.1-4Dan Walsh 3.5.1-3Dan Walsh 3.5.1-2Dan Walsh 3.5.1-1Dan Walsh 3.5.0-1Dan Walsh 3.4.2-14Dan Walsh 3.4.2-13Dan Walsh 3.4.2-12Dan Walsh 3.4.2-11Dan Walsh 3.4.2-10Dan Walsh 3.4.2-9Dan Walsh 3.4.2-8Dan Walsh 3.4.2-7Dan Walsh 3.4.2-6Dan Walsh 3.4.2-5Dan Walsh 3.4.2-4Dan Walsh 3.4.2-3Dan Walsh 3.4.2-2Dan Walsh 3.4.2-1Dan Walsh 3.4.1-5Dan Walsh 3.4.1-3Dan Walsh 3.4.1-2Dan Walsh 3.4.1-1Dan Walsh 3.3.1-48Dan Walsh 3.3.1-47Dan Walsh 3.3.1-46Dan Walsh 3.3.1-45Dan Walsh 3.3.1-44Dan Walsh 3.3.1-43Dan Walsh 3.3.1-42Dan Walsh 3.3.1-41Dan Walsh 3.3.1-39Dan Walsh 3.3.1-37Dan Walsh 3.3.1-36Dan Walsh 3.3.1-33Dan Walsh 3.3.1-32Dan Walsh 3.3.1-31Dan Walsh 3.3.1-30Dan Walsh 3.3.1-29Dan Walsh 3.3.1-28Dan Walsh 3.3.1-27Dan Walsh 3.3.1-26Dan Walsh 3.3.1-25Dan Walsh 3.3.1-24Dan Walsh 3.3.1-23Dan Walsh 3.3.1-22Dan Walsh 3.3.1-21Dan Walsh 3.3.1-20Dan Walsh 3.3.1-19Dan Walsh 3.3.1-18Dan Walsh 3.3.1-17Dan Walsh 3.3.1-16Dan Walsh 3.3.1-15Bill Nottingham 3.3.1-14Dan Walsh 3.3.1-13Dan Walsh 3.3.1-12Dan Walsh 3.3.1-11Dan Walsh 3.3.1-10Dan Walsh 3.3.1-9Dan Walsh 3.3.1-8Dan Walsh 3.3.1-6Dan Walsh 3.3.1-5Dan Walsh 3.3.1-4Dan Walsh 3.3.1-2Dan Walsh 3.3.1-1Dan Walsh 3.3.0-2Dan Walsh 3.3.0-1Dan Walsh 3.2.9-2Dan Walsh 3.2.9-1Dan Walsh 3.2.8-2Dan Walsh 3.2.8-1Dan Walsh 3.2.7-6Dan Walsh 3.2.7-5Dan Walsh 3.2.7-3Dan Walsh 3.2.7-2Dan Walsh 3.2.7-1Dan Walsh 3.2.6-7Dan Walsh 3.2.6-6Dan Walsh 3.2.6-5Dan Walsh 3.2.6-4Dan Walsh 3.2.6-3Dan Walsh 3.2.6-2Dan Walsh 3.2.6-1Dan Walsh 3.2.5-25Dan Walsh 3.2.5-24Dan Walsh 3.2.5-22Dan Walsh 3.2.5-21Dan Walsh 3.2.5-20Dan Walsh 3.2.5-19Dan Walsh 3.2.5-18Dan Walsh 3.2.5-17Dan Walsh 3.2.5-16Dan Walsh 3.2.5-15Dan Walsh 3.2.5-14Dan Walsh 3.2.5-13Dan Walsh 3.2.5-12Dan Walsh 3.2.5-11Dan Walsh 3.2.5-10Dan Walsh 3.2.5-9Dan Walsh 3.2.5-8Dan Walsh 3.2.5-7Dan Walsh 3.2.5-6Dan Walsh 3.2.5-5Dan Walsh 3.2.5-4Dan Walsh 3.2.5-3Dan Walsh 3.2.5-2Dan Walsh 3.2.5-1Dan Walsh 3.2.4-5Dan Walsh 3.2.4-4Dan Walsh 3.2.4-3Dan Walsh 3.2.4-1Dan Walsh 3.2.4-1Dan Walsh 3.2.3-2Dan Walsh 3.2.3-1Dan Walsh 3.2.2-1Dan Walsh 3.2.1-3Dan Walsh 3.2.1-1Dan Walsh 3.1.2-2Dan Walsh 3.1.2-1Dan Walsh 3.1.1-1Dan Walsh 3.1.0-1Dan Walsh 3.0.8-30Dan Walsh 3.0.8-28Dan Walsh 3.0.8-27Dan Walsh 3.0.8-26Dan Walsh 3.0.8-25Dan Walsh 3.0.8-24Dan Walsh 3.0.8-23Dan Walsh 3.0.8-22Dan Walsh 3.0.8-21Dan Walsh 3.0.8-20Dan Walsh 3.0.8-19Dan Walsh 3.0.8-18Dan Walsh 3.0.8-17Dan Walsh 3.0.8-16Dan Walsh 3.0.8-15Dan Walsh 3.0.8-14Dan Walsh 3.0.8-13Dan Walsh 3.0.8-12Dan Walsh 3.0.8-11Dan Walsh 3.0.8-10Dan Walsh 3.0.8-9Dan Walsh 3.0.8-8Dan Walsh 3.0.8-7Dan Walsh 3.0.8-5Dan Walsh 3.0.8-4Dan Walsh 3.0.8-3Dan Walsh 3.0.8-2Dan Walsh 3.0.8-1Dan Walsh 3.0.7-10Dan Walsh 3.0.7-9Dan Walsh 3.0.7-8Dan Walsh 3.0.7-7Dan Walsh 3.0.7-6Dan Walsh 3.0.7-5Dan Walsh 3.0.7-4Dan Walsh 3.0.7-3Dan Walsh 3.0.7-2Dan Walsh 3.0.7-1Dan Walsh 3.0.6-3Dan Walsh 3.0.6-2Dan Walsh 3.0.6-1Dan Walsh 3.0.5-11Dan Walsh 3.0.5-10Dan Walsh 3.0.5-9Dan Walsh 3.0.5-8Dan Walsh 3.0.5-7Dan Walsh 3.0.5-6Dan Walsh 3.0.5-5Dan Walsh 3.0.5-4Dan Walsh 3.0.5-3Dan Walsh 3.0.5-2Dan Walsh 3.0.5-1Dan Walsh 3.0.4-6Dan Walsh 3.0.4-5Dan Walsh 3.0.4-4Dan Walsh 3.0.4-3Dan Walsh 3.0.4-2Dan Walsh 3.0.4-1Dan Walsh 3.0.3-6Dan Walsh 3.0.3-5Dan Walsh 3.0.3-4Dan Walsh 3.0.3-3Dan Walsh 3.0.3-2Dan Walsh 3.0.3-1Dan Walsh 3.0.2-9Dan Walsh 3.0.2-8Dan Walsh 3.0.2-7Dan Walsh 3.0.2-5Dan Walsh 3.0.2-4Dan Walsh 3.0.2-3Dan Walsh 3.0.2-2Dan Walsh 3.0.1-5Dan Walsh 3.0.1-4Dan Walsh 3.0.1-3Dan Walsh 3.0.1-2Dan Walsh 3.0.1-1Dan Walsh 2.6.5-3Dan Walsh 2.6.5-2Dan Walsh 2.6.4-7Dan Walsh 2.6.4-6Dan Walsh 2.6.4-5Dan Walsh 2.6.4-2Dan Walsh 2.6.4-1Dan Walsh 2.6.3-1Dan Walsh 2.6.2-1Dan Walsh 2.6.1-4Dan Walsh 2.6.1-2Dan Walsh 2.6.1-1Dan Walsh 2.5.12-12Dan Walsh 2.5.12-11Dan Walsh 2.5.12-10Dan Walsh 2.5.12-8Dan Walsh 2.5.12-5Dan Walsh 2.5.12-4Dan Walsh 2.5.12-3Dan Walsh 2.5.12-2Dan Walsh 2.5.12-1Dan Walsh 2.5.11-8Dan Walsh 2.5.11-7Dan Walsh 2.5.11-6Dan Walsh 2.5.11-5Dan Walsh 2.5.11-4Dan Walsh 2.5.11-3Dan Walsh 2.5.11-2Dan Walsh 2.5.11-1Dan Walsh 2.5.10-2Dan Walsh 2.5.10-1Dan Walsh 2.5.9-6Dan Walsh 2.5.9-5Dan Walsh 2.5.9-4Dan Walsh 2.5.9-3Dan Walsh 2.5.9-2Dan Walsh 2.5.8-8Dan Walsh 2.5.8-7Dan Walsh 2.5.8-6Dan Walsh 2.5.8-5Dan Walsh 2.5.8-4Dan Walsh 2.5.8-3Dan Walsh 2.5.8-2Dan Walsh 2.5.8-1Dan Walsh 2.5.7-1Dan Walsh 2.5.6-1Dan Walsh 2.5.5-2Dan Walsh 2.5.5-1Dan Walsh 2.5.4-2Dan Walsh 2.5.4-1Dan Walsh 2.5.3-3Dan Walsh 2.5.3-2Dan Walsh 2.5.3-1Dan Walsh 2.5.2-6Dan Walsh 2.5.2-5Dan Walsh 2.5.2-4Dan Walsh 2.5.2-3Dan Walsh 2.5.2-2Dan Walsh 2.5.2-1Dan Walsh 2.5.1-5Dan Walsh 2.5.1-4Dan Walsh 2.5.1-2Dan Walsh 2.5.1-1Dan Walsh 2.4.6-20Dan Walsh 2.4.6-19Dan Walsh 2.4.6-18Dan Walsh 2.4.6-17Dan Walsh 2.4.6-16Dan Walsh 2.4.6-15Dan Walsh 2.4.6-14Dan Walsh 2.4.6-13Dan Walsh 2.4.6-12Dan Walsh 2.4.6-11Dan Walsh 2.4.6-10Dan Walsh 2.4.6-9Dan Walsh 2.4.6-8Dan Walsh 2.4.6-7Dan Walsh 2.4.6-6Dan Walsh 2.4.6-5Dan Walsh 2.4.6-4Dan Walsh 2.4.6-3Dan Walsh 2.4.6-1Dan Walsh 2.4.5-4Dan Walsh 2.4.5-3Dan Walsh 2.4.5-2Dan Walsh 2.4.5-1Dan Walsh 2.4.4-2Dan Walsh 2.4.4-2Dan Walsh 2.4.4-1Dan Walsh 2.4.3-13Dan Walsh 2.4.3-12Dan Walsh 2.4.3-11Dan Walsh 2.4.3-10Dan Walsh 2.4.3-9Dan Walsh 2.4.3-8Dan Walsh 2.4.3-7Dan Walsh 2.4.3-6Dan Walsh 2.4.3-5Dan Walsh 2.4.3-4Dan Walsh 2.4.3-3Dan Walsh 2.4.3-2Dan Walsh 2.4.3-1Dan Walsh 2.4.2-8Dan Walsh 2.4.2-7James Antill 2.4.2-6Dan Walsh 2.4.2-5Dan Walsh 2.4.2-4Dan Walsh 2.4.2-3Dan Walsh 2.4.2-2Dan Walsh 2.4.2-1Dan Walsh 2.4.1-5Dan Walsh 2.4.1-4Dan Walsh 2.4.1-3Dan Walsh 2.4.1-2Dan Walsh 2.4-4Dan Walsh 2.4-3Dan Walsh 2.4-2Dan Walsh 2.4-1Dan Walsh 2.3.19-4Dan Walsh 2.3.19-3Dan Walsh 2.3.19-2Dan Walsh 2.3.19-1James Antill 2.3.18-10James Antill 2.3.18-9Dan Walsh 2.3.18-8Dan Walsh 2.3.18-7Dan Walsh 2.3.18-6Dan Walsh 2.3.18-5Dan Walsh 2.3.18-4Dan Walsh 2.3.18-3Dan Walsh 2.3.18-2Dan Walsh 2.3.18-1Dan Walsh 2.3.17-2Dan Walsh 2.3.17-1Dan Walsh 2.3.16-9Dan Walsh 2.3.16-8Dan Walsh 2.3.16-7Dan Walsh 2.3.16-6Dan Walsh 2.3.16-5Dan Walsh 2.3.16-4Dan Walsh 2.3.16-2Dan Walsh 2.3.16-1Dan Walsh 2.3.15-2Dan Walsh 2.3.15-1Dan Walsh 2.3.14-8Dan Walsh 2.3.14-7Dan Walsh 2.3.14-6Dan Walsh 2.3.14-4Dan Walsh 2.3.14-3Dan Walsh 2.3.14-2Dan Walsh 2.3.14-1Dan Walsh 2.3.13-6Dan Walsh 2.3.13-5Dan Walsh 2.3.13-4Dan Walsh 2.3.13-3Dan Walsh 2.3.13-2Dan Walsh 2.3.13-1Dan Walsh 2.3.12-2Dan Walsh 2.3.12-1Dan Walsh 2.3.11-1Dan Walsh 2.3.10-7Dan Walsh 2.3.10-6Dan Walsh 2.3.10-3Dan Walsh 2.3.10-1Dan Walsh 2.3.9-6Dan Walsh 2.3.9-5Dan Walsh 2.3.9-4Dan Walsh 2.3.9-3Dan Walsh 2.3.9-2Dan Walsh 2.3.9-1Dan Walsh 2.3.8-2Dan Walsh 2.3.7-1Dan Walsh 2.3.6-4Dan Walsh 2.3.6-3Dan Walsh 2.3.6-2Dan Walsh 2.3.6-1Dan Walsh 2.3.5-1Dan Walsh 2.3.4-1Dan Walsh 2.3.3-20Dan Walsh 2.3.3-19Dan Walsh 2.3.3-18Dan Walsh 2.3.3-17Dan Walsh 2.3.3-16Dan Walsh 2.3.3-15Dan Walsh 2.3.3-14Dan Walsh 2.3.3-13Dan Walsh 2.3.3-12Dan Walsh 2.3.3-11Dan Walsh 2.3.3-10Dan Walsh 2.3.3-9Dan Walsh 2.3.3-8Dan Walsh 2.3.3-7Dan Walsh 2.3.3-6Dan Walsh 2.3.3-5Dan Walsh 2.3.3-4Dan Walsh 2.3.3-3Dan Walsh 2.3.3-2Dan Walsh 2.3.3-1Dan Walsh 2.3.2-4Dan Walsh 2.3.2-3Dan Walsh 2.3.2-2Dan Walsh 2.3.2-1Dan Walsh 2.3.1-1Dan Walsh 2.2.49-1Dan Walsh 2.2.48-1Dan Walsh 2.2.47-5Dan Walsh 2.2.47-4Dan Walsh 2.2.47-3Dan Walsh 2.2.47-1Dan Walsh 2.2.46-2Dan Walsh 2.2.46-1Dan Walsh 2.2.45-3Dan Walsh 2.2.45-2Dan Walsh 2.2.45-1Dan Walsh 2.2.44-1Dan Walsh 2.2.43-4Dan Walsh 2.2.43-3Dan Walsh 2.2.43-2Dan Walsh 2.2.43-1Dan Walsh 2.2.42-4Dan Walsh 2.2.42-3Dan Walsh 2.2.42-2Dan Walsh 2.2.42-1Dan Walsh 2.2.41-1Dan Walsh 2.2.40-2Dan Walsh 2.2.40-1Dan Walsh 2.2.39-2Dan Walsh 2.2.39-1Dan Walsh 2.2.38-6Dan Walsh 2.2.38-5Dan Walsh 2.2.38-4Dan Walsh 2.2.38-3Dan Walsh 2.2.38-2Dan Walsh 2.2.38-1Dan Walsh 2.2.37-1Dan Walsh 2.2.36-2Dan Walsh 2.2.36-1James Antill 2.2.35-2Dan Walsh 2.2.35-1Dan Walsh 2.2.34-3Dan Walsh 2.2.34-2Dan Walsh 2.2.34-1Dan Walsh 2.2.33-1Dan Walsh 2.2.32-2Dan Walsh 2.2.32-1Dan Walsh 2.2.31-1Dan Walsh 2.2.30-2Dan Walsh 2.2.30-1Dan Walsh 2.2.29-6Russell Coker 2.2.29-5Dan Walsh 2.2.29-4Dan Walsh 2.2.29-3Dan Walsh 2.2.29-2Dan Walsh 2.2.29-1Dan Walsh 2.2.28-3Dan Walsh 2.2.28-2Dan Walsh 2.2.28-1Dan Walsh 2.2.27-1Dan Walsh 2.2.25-3Dan Walsh 2.2.25-2Dan Walsh 2.2.24-1Dan Walsh 2.2.23-19Dan Walsh 2.2.23-18Dan Walsh 2.2.23-17Karsten Hopp 2.2.23-16Dan Walsh 2.2.23-15Dan Walsh 2.2.23-14Dan Walsh 2.2.23-13Dan Walsh 2.2.23-12Jeremy Katz - 2.2.23-11Jeremy Katz - 2.2.23-10Dan Walsh 2.2.23-9Dan Walsh 2.2.23-8Dan Walsh 2.2.23-7Dan Walsh 2.2.23-5Dan Walsh 2.2.23-4Dan Walsh 2.2.23-3Dan Walsh 2.2.23-2Dan Walsh 2.2.23-1Dan Walsh 2.2.22-2Dan Walsh 2.2.22-1Dan Walsh 2.2.21-9Dan Walsh 2.2.21-8Dan Walsh 2.2.21-7Dan Walsh 2.2.21-6Dan Walsh 2.2.21-5Dan Walsh 2.2.21-4Dan Walsh 2.2.21-3Dan Walsh 2.2.21-2Dan Walsh 2.2.21-1Dan Walsh 2.2.20-1Dan Walsh 2.2.19-2Dan Walsh 2.2.19-1Dan Walsh 2.2.18-2Dan Walsh 2.2.18-1Dan Walsh 2.2.17-2Dan Walsh 2.2.16-1Dan Walsh 2.2.15-4Dan Walsh 2.2.15-3Dan Walsh 2.2.15-1Dan Walsh 2.2.14-2Dan Walsh 2.2.14-1Dan Walsh 2.2.13-1Dan Walsh 2.2.12-1Dan Walsh 2.2.11-2Dan Walsh 2.2.11-1Dan Walsh 2.2.10-1Dan Walsh 2.2.9-2Dan Walsh 2.2.9-1Dan Walsh 2.2.8-2Dan Walsh 2.2.7-1Dan Walsh 2.2.6-3Dan Walsh 2.2.6-2Dan Walsh 2.2.6-1Dan Walsh 2.2.5-1Dan Walsh 2.2.4-1Dan Walsh 2.2.3-1Dan Walsh 2.2.2-1Dan Walsh 2.2.1-1Dan Walsh 2.1.13-1Dan Walsh 2.1.12-3Dan Walsh 2.1.11-1Dan Walsh 2.1.10-1Jeremy Katz - 2.1.9-2Dan Walsh 2.1.9-1Dan Walsh 2.1.8-3Dan Walsh 2.1.8-2Dan Walsh 2.1.8-1Dan Walsh 2.1.7-4Dan Walsh 2.1.7-3Dan Walsh 2.1.7-2Dan Walsh 2.1.7-1Dan Walsh 2.1.6-24Dan Walsh 2.1.6-23Dan Walsh 2.1.6-22Dan Walsh 2.1.6-21Dan Walsh 2.1.6-20Dan Walsh 2.1.6-18Dan Walsh 2.1.6-17Dan Walsh 2.1.6-16Dan Walsh 2.1.6-15Dan Walsh 2.1.6-14Dan Walsh 2.1.6-13Dan Walsh 2.1.6-11Dan Walsh 2.1.6-10Dan Walsh 2.1.6-9Dan Walsh 2.1.6-8Dan Walsh 2.1.6-5Dan Walsh 2.1.6-4Dan Walsh 2.1.6-3Dan Walsh 2.1.6-2Dan Walsh 2.1.6-1Dan Walsh 2.1.4-2Dan Walsh 2.1.4-1Dan Walsh 2.1.3-1Jeremy Katz - 2.1.2-3Dan Walsh 2.1.2-2Dan Walsh 2.1.2-1Dan Walsh 2.1.1-3Dan Walsh 2.1.1-2Dan Walsh 2.1.1-1Dan Walsh 2.1.0-3Dan Walsh 2.1.0-2.Dan Walsh 2.1.0-1.Dan Walsh 2.0.11-2.Dan Walsh 2.0.11-1.Dan Walsh 2.0.9-1.Dan Walsh 2.0.8-1.Dan Walsh 2.0.7-3Dan Walsh 2.0.7-2Dan Walsh 2.0.6-2Dan Walsh 2.0.5-4Dan Walsh 2.0.5-1Dan Walsh 2.0.4-1Dan Walsh 2.0.2-2Dan Walsh 2.0.2-1Dan Walsh 2.0.1-2Dan Walsh 2.0.1-1- Allow certmonger add new entries in a generic certificates directory Resolves: rhbz#1879496 - Allow slapd add new entries in ldap certificates directory Resolves: rhbz#1879496 - Add miscfiles_add_entry_generic_cert_dirs() interface Resolves: rhbz#1879496- Allow ssh-keygen create file in /var/lib/glusterd Resolves: rhbz#1867995- Allow rhsmd read process state of all domains and kernel threads Resolves: rhbz#1837461 - Allow ipa-adtrust-install restart sssd and dirsrv services Resolves: rhbz#1820298 - Allow nagios_plugin_domain execute programs in bin directories Resolves: rhbz#1824625 - selinux policy: add the right context for org.freeipa.server.trust-enable-agent Related: rhbz#1820298- Allow chronyd_t domain to exec shell Resolves: rhbz#1775573 - Allow pmie daemon to send signal pcmd daemon Resolves: rhbz#1770123 - Allow auditd poweroff or switch to single mode Resolves: rhbz#1780332- Dontaudit tmpreaper_t getting attributes from sysctl_type files Resolves: rhbz#1765063- Allow tmpreaper_t domain to getattr files labeled as mtrr_device_t Resolves: rhbz#1765063- Allow tmpwatch process labeled as tmpreaper_t domain to execute fuser command Resolves: rhbz#1765063- Update tmpreaper_t policy due to fuser command Resolves: rhbz#1765063- Allow tmpreaper_t domain to read all domains state Resolves: rhbz#1765063- Update sudo_role_template() to allow caller domain to read syslog pid files Resolves: rhbz#1651253- Allow sbd_t domain to check presence of processes labeled as cluster_t Resolves: rhbz#1753623- Allow ganesha_t domain to read system network state and connect to cyphesis_port_t Resolves: rhbz#1653857 - Label /var/log/collectd.log as collectd_log_t - Update gnome_role_template() interface to make working sysadm_u SELinux able to login to X sessions Resolves: rhbz#1688729 - Update collectd policy to allow daemon create /var/log/collectd with collectd_log_t label Resolves: rhbz#1658319 - Update sbd policy to allow manage cgroups Resolves: rhbz#1715136 - Allow sudo userdomain to run rpm related commands - Update rpm_run() interface to avoid duplicate role transition in sudo_role_template Resolves: rhbz#1651253- Update gnome_role_template() interface to make working sysadm_u SELinux able to login to X sessions Resolves: rhbz#1688729 - Update collectd policy to allow daemon create /var/log/collectd with collectd_log_t label Resolves: rhbz#1658319- Update sbd policy to allow manage cgroups Resolves: rhbz#1715136- Allow cupsd_t domain to manage cupsd_tmp_t temp link files Resolves: rhbz#1719754 - Allow svnserve_t domain to read /dev/random Resolves: rhbz#1727458 - Update sudodomains to make working confined users run sudo/su Resolves: rhbz#1699391- Allow virtlockd process read virtlockd.conf file Resolves: rhbz#1714896- Rebuild selinux-policy build because of broken RHEL-7.8 buildrood during build of selinux-policy-3.13.1-253 Resolves: rhbz#1727341- Label user cron spool file with user_cron_spool_t Resolves: rhbz#1727341 - Allow svnserve_t domain to read system state Resolves: rhbz#1727458 - Update svnserve_t policy to make working svnserve hooks Resolves: rhbz#1727458 - Update gnome_role_template() template to allow sysadm_t confined user to login to xsession Resolves: rhbz#1727379 - Update gnome_role_template() to allow _gkeyringd_t domains to chat with systemd_logind over dbus Resolves: rhbz#1727379 - Allow userdomain gkeyringd domain to create stream socket with userdomain Resolves: rhbz#1727379 - Allow cupsd_t to create lnk_files in /tmp. BZ(1401634) Resolves: rhbz#1719754 - Allow mysqld_t domain to manage cluster pid files Resolves: rhbz#1715805 - Relabel /usr/sbin/virtlockd from virt_exec_t to virtlogd_exec_t. Resolves: rhbz#1714896 - Allow systemd_hostnamed_t domain to dbus chat with sosreport_t domain Resolves: rhbz#1705599 - Allow rhsmcertd_t domain to send signull to all domains Resolves: rhbz#1701338 - Allow cloud_init_t domain to ccreate iptables files with correct SELinux label Resolves: rhbz#1699249 - Allow dnsmasq_t domain to manage NetworkManager_var_lib_t files - Allow certmonger to geattr of filesystems BZ(1578755) - Update tomcat_can_network_connect_db boolean to allow tomcat domains also connect to redis ports Resolves: rhbz#1687497 - Allow lograte_t domain to manage collect_rw_content files and dirs Resolves: rhbz#1658319 - Add interface collectd_manage_rw_content() - Allow glusterd_t domain to setpgid Resolves: rhbz#1653857 - Allow sysadm_sudo_t to use SELinux tooling. Resolves: rhbz#1727341 - Allow sysadm_t domain to create netlink selinux sockets Resolves: rhbz#1727379 - Allow systemd_resolved_t to dbusd chat with NetworkManager_t Resolves: rhbz#1723877 - Allow crack_t domain read /et/passwd files Resolves: rhbz#1721093 - Allow sysadm_t domain to dbus chat with rtkit daemon Resolves: rhbz#1720546 - Allow x_userdomains to nnp domain transition to thumb_t domain Resolves: rhbz#1712603 - Dontaudit writing to user home dirs by gnome-keyring-daemon Resolves: rhbz#1703959 - Update logging_send_audit_msgs(sudodomain() to control TTY auditing for netlink socket for audit service Resolves: rhbz#1699391 - Allow systemd_tmpfiles_t domain to relabel from usermodehelper_t files Resolves: rhbz#1699063 - Add interface kernel_relabelfrom_usermodehelper()- Allow sbd_t domain to use nsswitch Resolves: rhbz#1728593- Allow ganesha_t domain to connect to tcp portmap_port_t Resolves: rhbz#1715088- Allow redis to creating tmp files with own label Resolves: rhbz#1646765- Allow ctdb_t domain to manage samba_var_t files/links/sockets and dirs Resolves: rhbz#1716400- Allow nrpe_t domain to read process state of systemd_logind_t - Add interface systemd_logind_read_state() Resolves: rhbz#1653309- Label /etc/rhsm as rhsmcertd_config_t Resolves: rhbz#1703573- Fix typo in gpg SELinux module - Update gpg policy to make ti working with confined users Resolves: rhbz#1535109 - Alow nrpe_t to send signull to sssd domain when nagios_run_sudo boolean is turned on Resolves: rhbz#1653309 - Allow nrpe_t domain to be dbus cliennt Resolves: rhbz#1653309 - Add interface sssd_signull() Resolves: rhbz#1653309 - Update userdomains to allow confined users to create gpg keys Resolves: rhbz#1535109- Allow ngaios to use chown capability Resolves: rhbz#1653309 - Dontaudit gpg_domain to create netlink_audit sockets Resolves: rhbz#1535109 - Update fs_rw_cephfs_files() interface to allow also caller domain to read/write cephpfs_t lnk files Resolves: rhbz#1558836 - Update domain_can_mmap_files() boolean to allow also mmap lnk files- Allow rhsmcertd_t domain to read yum.log file labeled as rpm_log_t Resolves: rhbz#1695342- Update Nagios policy when sudo is used Resolves: rhbz#1653309- Allow modemmanager_t domain to write to raw_ip file labeled as sysfs_t Resolves: rhbz#1676810- Make shell_exec_t type as entrypoint for vmtools_unconfined_t. Resolves: rhbz#1656814- Update vmtools policy Resolves: rhbz#1656814 Allow domain transition from vmtools_t to vmtools_unconfined_t when shell_exec_t is entrypoint. - Allow virt_qemu_ga_t domain to read udev_var_run_t files Resolves: rhbz#1663092 - Update nagios_run_sudo boolean with few allow rules related to accessing sssd Resolves: rhbz#1653309 - Allow nfsd_t to read nvme block devices BZ(1562554) Resolves: rhbz#1655493 - Allow tangd_t domain to bind on tcp ports labeled as tangd_port_t Resolves: rhbz#1650909 - Allow all domains to send dbus msgs to vmtools_unconfined_t processes Resolves: rhbz#1656814 - Label /dev/pkey as crypt_device_t Resolves: rhbz#1623068 - Allow sudodomains to write to systemd_logind_sessions_t pipes. Resolves: rhbz#1687452 - Allow all user domains to read realmd_var_lib_t files and dirs to check if IPA is configured on the system Resolves: rhbz#1667962 - Fixes: xenconsole does not start Resolves: rhbz#1601525 - Label /usr/lib64/libcuda.so.XX.XX library as textrel_shlib_t. Resolves: rhbz#1636197 - Create tangd_port_t with default label tcp/7406 Resolves: rhbz#1650909- named wants to access /proc/sys/net/ipv4/ip_local_port_range to get ehphemeral range. Resolves: rhbz#1683754 - Allow sbd_t domain to bypass permission checks for sending signals Resolves: rhbz#1671132 - Allow sbd_t domain read/write all sysctls Resolves: rhbz#1671132 - Allow kpatch_t domain to communicate with policykit_t domsin over dbus Resolves: rhbz#1602435 - Allow boltd_t to stream connect to sytem dbus Resolves: rhbz#1589086 - Update userdom_admin_user_template() and init_prog_run_bpf() interfaces to make working bpftool for confined admin Resolves: rhbz#1626115 - Update unconfined_dbus_send() interface to allow both direction communication over dbus with unconfined process. Resolves: rhbz#1589086- Allow sbd_t domain read/write all sysctls Resolves: rhbz#1671132 - Allow kpatch_t domain to communicate with policykit_t domsin over dbus Resolves: rhbz#1602435 - Allow boltd_t to stream connect to sytem dbus Resolves: rhbz#1589086 - Update unconfined_dbus_send() interface to allow both direction communication over dbus with unconfined process. Resolves: rhbz#1589086- Update redis_enable_notify() boolean to fix sending e-mail by redis when this boolean is turned on Resolves: rhbz#1646765- Allow virtd_lxc_t domains use BPF Resolves: rhbz#1626115 - F29 NetworkManager implements a new code for IPv4 address conflict detection (RFC 5227) based on n-acd [1], which uses eBPF to process ARP packets from the network. Resolves: rhbz#1626115 - Allow unconfined user all perms under bpf class BZ(1565738 Resolves: rhbz#1626115 - Allow unconfined and sysadm users to use bpftool BZ(1591440) Resolves: rhbz#1626115 - Allow systemd to manage bpf dirs/files Resolves: rhbz#1626115 - Create new type bpf_t and label /sys/fs/bpf with this type Resolves:rhbz#1626115 - Add new interface init_prog_run_bpf() Resolves:rhbz#1626115 - add definition of bpf class and systemd perms Resolves: rhbz#1626115- Update policy with multiple allow rules to make working installing VM in MLS policy Resolves: rhbz#1558121 - Allow virt domain to use interited virtlogd domains fifo_file Resolves: rhbz#1558121 - Allow chonyc_t domain to rw userdomain pipes Resolves: rhbz#1618757 - Add file contexts in ganesha.fc file to label logging ganesha files properly. Resolves: rhbz#1628247- Allow sandbox_xserver_t domain write to user_tmp_t files Resolves: rhbz#1646521 - Allow virt_qemu_ga_t domain to read network state Resolves: rhbz#1630347 - Bolt added d-bus API for force-powering the thunderbolt controller, so system-dbusd needs acces to boltd pipes Resolves: rhbz#1589086 - Add boltd policy Resolves: rhbz#1589086 - Allow virt domains to read/write cephfs filesystems Resolves: rhbz#1558836 - Allow gpg_t to create own tmpfs dirs and sockets Resolves: rhbz#1535109 - Allow gpg_agent_t to send msgs to syslog/journal Resolves: rhbz#1535109 - Allow virtual machine to write to fixed_disk_device_t Resolves: rhbz#1499208 - Update kdump_manage_crash() interface to allow also manage dirs by caller domain Resolves: rhbz#1491585 - Add kpatch policy Resolves: rhbz#1602435 - Label /usr/bin/mysqld_safe_helper as mysqld_exec_t instead of bin_t Resolves: rhbz#1623942 - Allow svnserve_t domain to create in /tmp svn_0 file labeled as krb5_host_rcache_t Resolves: rhbz#1475271 - Allow systemd to mount boltd_var_run_t dirs Resolves: rhbz#1589086 - Allow systemd to mounont boltd lib dirs Resolves: rhbz#1589086 - Allow sysadm_t,staff_t and unconfined_t domain to execute kpatch as kpatch_t domain Resolves: rhbz#1602435 - Allow passwd_t domain chroot - Add miscfiles_filetrans_named_content_letsencrypt() to optional_block - Allow unconfined domains to create letsencrypt directory in /var/lib labeled as cert_t Resolves: rhbz#1447278 - Allow staff_t user to systemctl iptables units. Resolves: rhbz#1360470- Label /usr/bin/mysqld_safe_helper as mysqld_exec_t instead of bin_t Resolves: rhbz#1623942 - Allow svnserve_t domain to create in /tmp svn_0 file labeled as krb5_host_rcache_t Resolves: rhbz#1475271 - Allow passwd_t domain chroot - Add miscfiles_filetrans_named_content_letsencrypt() to optional_block - Allow unconfined domains to create letsencrypt directory in /var/lib labeled as cert_t Resolves: rhbz#1447278 - Allow staff_t user to systemctl iptables units. Resolves: rhbz#1360470- Allow gssd_t domain to manage kernel keyrings of every domain. Resolves: rhbz#1487350 - Add new interface domain_manage_all_domains_keyrings() Resolves: rhbz#1487350- Allow gssd_t domain to read/write kernel keyrings of every domain. Resolves: rhbz#1487350 - Add interface domain_rw_all_domains_keyrings() Resolves: rhbz#1487350- Update snapperd policy to allow snapperd manage all non security dirs. Resolves: rhbz#1619306-Allow nova_t domain to use pam Resolves: rhbz:#1640528 - sysstat: grant sysstat_t the search_dir_perms set Resolves: rhbz#1637416 - Allow cinder_volume_t domain to dbus chat with systemd_logind_t domain Resolves: rhbz#1630318 - Allow staff_t userdomain and confined_admindomain attribute to allow use generic ptys because of new sudo feature 'io logging' Resolves: rhbz#1564470 - Make ganesha policy active again Resolves: rhbz#1511489- Remove disabling ganesha module in pre install phase of installation new selinux-policy package where ganesha is again standalone module Resolves: rhbz#1638257- Allow staff_t userdomain and confined_admindomain attribute to allow use generic ptys because of new sudo feature 'io logging' Resolves: rhbz#1638427- Run ganesha as ganesha_t domain again, revert changes where ganesha is running as nfsd_t Resolves: rhbz#1638257- Fix missing patch in spec file Resolves: rhbz#1635704- Allow cinder_volume_t domain to dbus chat with systemd_logind_t domain Resolves: rhbz#1635704- Allow neutron domain to read/write /var/run/utmp Resolves: rhbz#1630318- Allow tomcat_domain to read /dev/random Resolves: rhbz#1631666 - Allow neutron_t domain to use pam Resolves: rhbz#1630318- Add interface apache_read_tmp_dirs() - Allow dirsrvadmin_script_t domain to list httpd_tmp_t dirs Resolves: rhbz#1622602- Allow tomcat servers to manage usr_t files Resolves: rhbz#1625678 - Dontaudit tomcat serves to append to /dev/random device Resolves: rhbz#1625678 - Allow sys_nice capability to mysqld_t domain - Allow dirsrvadmin_script_t domain to read httpd tmp files Resolves: rhbz#1622602 - Allow syslogd_t domain to manage cert_t files Resolves: rhbz#1615995- Allow sbd_t domain to getattr of all char files in /dev and read sysfs_t files and dirs Resolves: rhbz#1627114 - Expand virt_read_lib_files() interface to allow list dirs with label virt_var_lib_t Resolves: rhbz#1567753- Allow tomcat Tomcat to delete a temporary file used when compiling class files for JSPs. Resolves: rhbz#1625678 - Allow chronyd_t domain to read virt_var_lib_t files - Allow virtual machines to use dri devices. This allows use openCL GPU calculations. BZ(1337333) Resolves: rhbz#1625613 - Allow tomcat services create link file in /tmp Resolves: rhbz#1624289 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322- Make working SELinux sandbox with Wayland. Resolves: rhbz#1624308 - Allow svirt_t domain to mmap svirt_image_t block files Resolves: rhbz#1624224 - Add caps dac_read_search and dav_override to pesign_t domain - Allow iscsid_t domain to mmap userio chr files Resolves: rhbz#1623589 - Add boolean: domain_can_mmap_files. Resolves: rhbz#1460322 - Add execute_no_trans permission to mmap_exec_file_perms pattern - Allow sudodomain to search caller domain proc info - Allow xdm_t domain to mmap and read cert_t files - Replace optional policy blocks to make dbus interfaces effective Resolves: rhbz#1624414 - Add interface dev_map_userio_dev()- Allow readhead_t domain to mmap own pid files Resolves: rhbz#1614169- Allow ovs-vswitchd labeled as openvswitch_t domain communicate with qemu-kvm via UNIX stream socket - Allow httpd_t domain to mmap tmp files Resolves: rhbz#1608355 - Update dirsrv_read_share() interface to allow caller domain to mmap dirsrv_share_t files - Update dirsrvadmin_script_t policy to allow read httpd_tmp_t symlinks - Label /dev/tpmrm[0-9]* as tpm_device_t - Allow semanage_t domain mmap usr_t files Resolves: rhbz#1622607 - Update dev_filetrans_all_named_dev() to allow create event22-30 character files with label event_device_t- Allow nagios_script_t domain to mmap nagios_log_t files Resolves: rhbz#1620013 - Allow nagios_script_t domain to mmap nagios_spool_t files Resolves: rhbz#1620013 - Update userdom_security_admin() and userdom_security_admin_template() to allow use auditctl Resolves: rhbz#1622197 - Update selinux_validate_context() interface to allow caller domain to mmap security_t files Resolves: rhbz#1622061- Allow virtd_t domain to create netlink_socket - Allow rpm_t domain to write to audit - Allow rpm domain to mmap rpm_var_lib_t files Resolves: rhbz#1619785 - Allow nagios_script_t domain to mmap nagios_etc_t files Resolves: rhbz#1620013 - Update nscd_socket_use() to allow caller domain to stream connect to nscd_t Resolves: rhbz#1460715 - Allow secadm_t domain to mmap audit config and log files - Allow insmod_t domain to read iptables pid files - Allow systemd to mounton /etc Resolves: rhbz#1619785- Allow kdumpctl_t domain to getattr fixed disk device in mls Resolves: rhbz#1615342 - Allow initrc_domain to mmap all binaries labeled as systemprocess_entry Resolves: rhbz#1615342- Allow virtlogd to execute itself Resolves: rhbz#1598392- Allow kdumpctl_t domain to manage kdumpctl_tmp_t fifo files Resolves: rhbz#1615342 - Allow kdumpctl to write to files on all levels Resolves: rhbz#1615342 - Fix typo in radius policy Resolves: rhbz#1619197 - Allow httpd_t domain to mmap httpd_config_t files Resolves: rhbz#1615894 - Add interface dbus_acquire_svc_system_dbusd() - Allow sanlock_t domain to connectto to unix_stream_socket Resolves: rhbz#1614965 - Update nfsd_t policy because of ganesha features Resolves: rhbz#1511489 - Allow conman to getattr devpts_t Resolves: rhbz#1377915 - Allow tomcat_domain to connect to smtp ports Resolves: rhbz#1253502 - Allow tomcat_t domain to mmap tomcat_var_lib_t files Resolves: rhbz#1618519 - Allow slapd_t domain to mmap slapd_var_run_t files Resolves: rhbz#1615319 - Allow nagios_t domain to mmap nagios_log_t files Resolves: rhbz#1618675 - Allow nagios to exec itself and mmap nagios spool files BZ(1559683) - Allow nagios to mmap nagios config files BZ(1559683) - Allow kpropd_t domain to mmap krb5kdc_principal_t files Resolves: rhbz#1619252 - Update syslogd policy to make working elasticsearch - Label tcp and udp ports 9200 as wap_wsp_port - Allow few domains to rw inherited kdumpctl tmp pipes Resolves: rhbz#1615342- Allow systemd_dbusd_t domain read/write to nvme devices Resolves: rhbz#1614236 - Allow mysqld_safe_t do execute itself - Allow smbd_t domain to chat via dbus with avahi daemon Resolves: rhbz#1600157 - cupsd_t domain will create /etc/cupsd/ppd as cupsd_etc_rw_t Resolves: rhbz#1452595 - Allow amanda_t domain to getattr on tmpfs filesystem BZ(1527645) Resolves: rhbz#1452444 - Update screen_role_template to allow caller domain to have screen_exec_t as entrypoint do new domain Resolves: rhbz#1384769 - Add alias httpd__script_t to _script_t to make sepolicy generate working Resolves: rhbz#1271324 - Allow kprop_t domain to read network state Resolves: rhbz#1600705 - Allow sysadm_t domain to accept socket Resolves: rhbz#1557299 - Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow sshd_t domain to mmap user_tmp_t files Resolves: rhbz#1613437- Allow kprop_t domain to read network state Resolves: rhbz#1600705- Allow kpropd domain to exec itself Resolves: rhbz#1600705 - Allow ipmievd_t to mmap kernel modules BZ(1552535) - Allow hsqldb_t domain to mmap own temp files Resolves: rhbz#1612143 - Allow hsqldb_t domain to read cgroup files Resolves: rhbz#1612143 - Allow rngd_t domain to read generic certs Resolves: rhbz#1612456 - Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow innd_t domain to mmap own var_lib_t files Resolves: rhbz#1600591 - Update screen_role_temaplate interface Resolves: rhbz#1384769 - Allow cupsd_t to create cupsd_etc_t dirs Resolves: rhbz#1452595 - Allow chronyd_t domain to mmap own tmpfs files Resolves: rhbz#1596563 - Allow cyrus domain to mmap own var_lib_t and var_run files Resolves: rhbz#1610374 - Allow sysadm_t domain to create rawip sockets Resolves: rhbz#1571591 - Allow sysadm_t domain to listen on socket Resolves: rhbz#1557299 - Update sudo_role_template() to allow caller domain also setattr generic ptys Resolves: rhbz#1564470 - Allow netutils_t domain to create bluetooth sockets Resolves: rhbz#1600586- Allow virtlogd_t domain to chat via dbus with systemd_logind Resolves: rhbz#1593740- Allow sblim_sfcbd_t domain to mmap own tmpfs files Resolves: rhbz#1609384 - Update logging_manage_all_logs() interface to allow caller domain map all logfiles Resolves: rhbz#1592028- Dontaudit oracleasm_t domain to request sys_admin capability - Allow iscsid_t domain to load kernel module Resolves: rhbz#1589295 - Update rhcs contexts to reflects the latest fenced changes - Allow httpd_t domain to rw user_tmp_t files Resolves: rhbz#1608355 - /usr/libexec/udisks2/udisksd should be labeled as devicekit_disk_exec_t Resolves: rhbz#1521063 - Allow tangd_t dac_read_search Resolves: rhbz#1607810 - Allow glusterd_t domain to mmap user_tmp_t files - Allow mongodb_t domain to mmap own var_lib_t files Resolves: rhbz#1607729 - Allow iscsid_t domain to mmap sysfs_t files Resolves: rhbz#1602508 - Allow tomcat_domain to search cgroup dirs Resolves: rhbz#1600188 - Allow httpd_t domain to mmap own cache files Resolves: rhbz#1603505 - Allow cupsd_t domain to mmap cupsd_etc_t files Resolves: rhbz#1599694 - Allow kadmind_t domain to mmap krb5kdc_principal_t Resolves: rhbz#1601004 - Allow virtlogd_t domain to read virt_etc_t link files Resolves: rhbz#1598593 - Allow dirsrv_t domain to read crack db Resolves: rhbz#1599726 - Dontaudit pegasus_t to require sys_admin capability Resolves: rhbz#1374570 - Allow mysqld_t domain to exec mysqld_exec_t binary files - Allow abrt_t odmain to read rhsmcertd lib files Resolves: rhbz#1601389 - Allow winbind_t domain to request kernel module loads Resolves: rhbz#1599236 - Allow gpsd_t domain to getsession and mmap own tmpfs files Resolves: rhbz#1598388 - Allow smbd_t send to nmbd_t via dgram sockets BZ(1563791) Resolves: rhbz#1600157 - Allow tomcat_domain to read cgroup_t files Resolves: rhbz#1601151 - Allow varnishlog_t domain to mmap varnishd_var_lib_t files Resolves: rhbz#1600704 - Allow dovecot_auth_t domain to manage also dovecot_var_run_t fifo files. BZ(1320415) Resolves: rhbz#1600692 - Fix ntp SELinux module - Allow innd_t domain to mmap news_spool_t files Resolves: rhbz#1600591 - Allow haproxy daemon to reexec itself. BZ(1447800) Resolves: rhbz#1600578 - Label HOME_DIR/mozilla.pdf file as mozilla_home_t instead of user_home_t Resolves: rhbz#1559859 - Allow pkcs_slotd_t domain to mmap own tmpfs files Resolves: rhbz#1600434 - Allow fenced_t domain to reboot Resolves: rhbz#1293384 - Allow bluetooth_t domain listen on bluetooth sockets BZ(1549247) Resolves: rhbz#1557299 - Allow lircd to use nsswitch. BZ(1401375) - Allow targetd_t domain mmap lvm config files Resolves: rhbz#1546671 - Allow amanda_t domain to read network system state Resolves: rhbz#1452444 - Allow abrt_t domain to read rhsmcertd logs Resolves: rhbz#1492059 - Allow application_domain_type also mmap inherited user temp files BZ(1552765) Resolves: rhbz#1608421 - Allow ipsec_t domain to read l2tpd pid files Resolves: rhbz#1607994 - Allow systemd_tmpfiles_t do mmap system db files - Improve domain_transition_pattern to allow mmap entrypoint bin file. Resolves: rhbz#1460322 - Allow nsswitch_domain to mmap passwd_file_t files BZ(1518655) Resolves: rhbz#1600528 - Dontaudit syslogd to watching top llevel dirs when imfile module is enabled Resolves: rhbz#1601928 - Allow ipsec_t can exec ipsec_exec_t Resolves: rhbz#1600684 - Allow netutils_t domain to mmap usmmon device Resolves: rhbz#1600586 - Allow netlabel_mgmt_t domain to read sssd public files, stream connect to sssd_t BZ(1483655) - Allow userdomain sudo domains to use generic ptys Resolves: rhbz#1564470 - Allow traceroute to create icmp packets Resolves: rhbz#1548350 - Allow systemd domain to mmap lvm config files BZ(1594584) - Add new interface lvm_map_config - refpolicy: Update for kernel sctp support Resolves: rhbz#1597111 Add additional entries to support the kernel SCTP implementation introduced in kernel 4.16- Update oddjob_domtrans_mkhomedir() interface to allow caller domain also mmap oddjob_mkhomedir_exec_t files Resolves: rhbz#1596306 - Update rhcs_rw_cluster_tmpfs() interface to allow caller domain to mmap cluster_tmpfs_t files Resolves: rhbz#1589257 - Allow radiusd_t domain to read network sysctls Resolves: rhbz#1516233 - Allow chronyc_t domain to use nscd shm Resolves: rhbz#1596563 - Label /var/lib/tomcats dir as tomcat_var_lib_t Resolves: rhbz#1596367 - Allow lsmd_t domain to mmap lsmd_plugin_exec_t files Resolves: rhbz#bea0c8174 - Label /usr/sbin/rhn_check-[0-9]+.[0-9]+ as rpm_exec_t Resolves: rhbz#1596509 - Update seutil_exec_loadpolicy() interface to allow caller domain to mmap load_policy_exec_t files Resolves: rhbz#1596072 - Allow xdm_t to read systemd hwdb Resolves: rhbz#1596720 - Allow dhcpc_t domain to mmap files labeled as ping_exec_t Resolves: rhbz#1596065- Allow tangd_t domain to create tcp sockets Resolves: rhbz#1595775 - Update postfix policy to allow postfix_master_t domain to mmap all postfix* binaries Resolves: rhbz#1595328 - Allow amanda_t domain to have setgid capability Resolves: rhbz#1452444 - Update usermanage_domtrans_useradd() to allow caller domain to mmap useradd_exec_t files Resolves: rhbz#1595667- Allow abrt_watch_log_t domain to mmap binaries with label abrt_dump_oops_exec_t Resolves: rhbz#1591191 - Update cups_filetrans_named_content() to allow caller domain create ppd directory with cupsd_etc_rw_t label Resolves: rhbz#1452595 - Allow abrt_t domain to write to rhsmcertd pid files Resolves: rhbz#1492059 - Allow pegasus_t domain to eexec lvm binaries and allow read/write access to lvm control Resolves: rhbz#1463470 - Add vhostmd_t domain to read/write to svirt images Resolves: rhbz#1465276 - Dontaudit action when abrt-hook-ccpp is writing to nscd sockets Resolves: rhbz#1460715 - Update openvswitch policy Resolves: rhbz#1594729 - Update kdump_manage_kdumpctl_tmp_files() interface to allow caller domain also mmap kdumpctl_tmp_t files Resolves: rhbz#1583084 - Allow sssd_t and slpad_t domains to mmap generic certs Resolves: rhbz#1592016 Resolves: rhbz#1592019 - Allow oddjob_t domain to mmap binary files as oddjob_mkhomedir_exec_t files Resolves: rhbz#1592022 - Update dbus_system_domain() interface to allow system_dbusd_t domain to mmap binary file from second parameter Resolves: rhbz#1583080 - Allow chronyc_t domain use inherited user ttys Resolves: rhbz#1593267 - Allow stapserver_t domain to mmap own tmp files Resolves: rhbz#1593122 - Allow sssd_t domain to mmap files labeled as sssd_selinux_manager_exec_t Resolves: rhbz#1592026 - Update policy for ypserv_t domain Resolves: rhbz#1592032 - Allow abrt_dump_oops_t domain to mmap all non security files Resolves: rhbz#1593728 - Allow svirt_t domain mmap svirt_image_t files Resolves: rhbz#1592688 - Allow virtlogd_t domain to write inhibit systemd pipes. Resolves: rhbz#1593740 - Allow sysadm_t and staff_t domains to use sudo io logging Resolves: rhbz#1564470 - Allow sysadm_t domain create sctp sockets Resolves: rhbz#1571591 - Update mount_domtrans() interface to allow caller domain mmap mount_exec_t Resolves: rhbz#1592025 - Allow dhcpc_t to mmap all binaries with label hostname_exec_t, ifconfig_exec_t and netutils_exec_t Resolves: rhbz#1594661- Fix typo in logwatch interface file - Allow spamd_t to manage logwatch_cache_t files/dirs - Allow dnsmasw_t domain to create own tmp files and manage mnt files - Allow fail2ban_client_t to inherit rlimit information from parent process Resolves: rhbz#1513100 - Allow nscd_t to read kernel sysctls Resolves: rhbz#1512852 - Label /var/log/conman.d as conman_log_t Resolves: rhbz#1538363 - Add dac_override capability to tor_t domain Resolves: rhbz#1540711 - Allow certmonger_t to readwrite to user_tmp_t dirs Resolves: rhbz#1543382 - Allow abrt_upload_watch_t domain to read general certs Resolves: rhbz#1545098 - Update postfix_domtrans_master() interface to allow caller domain also mmap postfix_master_exec_t binary Resolves: rhbz#1583087 - Allow postfix_domain to mmap postfix_qmgr_exec_t binaries Resolves: rhbz#1583088 - Allow postfix_domain to mmap postfix_pickup_exec_t binaries Resolves: rhbz#1583091 - Allow chornyd_t read phc2sys_t shared memory Resolves: rhbz#1578883 - Allow virt_qemu_ga_t read utmp Resolves: rhbz#1571202 - Add several allow rules for pesign policy: Resolves: rhbz#1468744 - Allow pesign domain to read /dev/random - Allow pesign domain to create netlink_kobject_uevent_t sockets - Allow pesign domain create own tmp files - Add setgid and setuid capabilities to mysqlfd_safe_t domain Resolves: rhbz#1474440 - Add tomcat_can_network_connect_db boolean Resolves: rhbz#1477948 - Update virt_use_sanlock() boolean to read sanlock state Resolves: rhbz#1448799 - Add sanlock_read_state() interface - Allow postfix_cleanup_t domain to stream connect to all milter sockets BZ(1436026) Resolves: rhbz#1563423 - Update abrt_domtrans and abrt_exec() interfaces to allow caller domain to mmap binary file Resolves:rhbz#1583080 - Update nscd_domtrans and nscd_exec interfaces to allow caller domain also mmap nscd binaries Resolves: rhbz#1583086 - Update snapperd_domtrans() interface to allow caller domain to mmap snapperd_exec_t file Resolves: rhbz#1583802 - Allow zoneminder_t to getattr of fs_t Resolves: rhbz#1585328 - Fix denials during ipa-server-install process on F27+ Resolves: rhbz#1586029 - Allow ipa_dnskey_t to exec ipa_dnskey_exec_t files Resolves: rhbz#1586033 - Allow rhsmcertd_t domain to send signull to postgresql_t domain Resolves: rhbz#1588119 - Allow policykit_t domain to dbus chat with dhcpc_t Resolves: rhbz#1364513 - Adding new boolean keepalived_connect_any() Resolves: rhbz#1443473 - Allow amanda to create own amanda_tmpfs_t files Resolves: rhbz#1452444 - Add amanda_tmpfs_t label. BZ(1243752) - Allow gdomap_t domain to connect to qdomap_port_t Resolves: rhbz#1551944 - Fix typos in sge - Fix typo in openvswitch policy - /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow sshd_keygen_t to execute plymouthd Resolves: rhbz#1583531 - Update seutil_domtrans_setfiles() interface to allow caller domain to do mmap on setfiles_exec_t binary Resolves: rhbz#1583090 - Allow systemd_networkd_t create and relabel tun sockets Resolves: rhbz#1583830 - Allow map audisp_exec_t files fordomains executing this binary Resolves: rhbz#1586042 - Add new interface postgresql_signull() - Add fs_read_xenfs_files() interface.- /usr/libexec/bluetooth/obexd should have only obexd_exec_t instead of bluetoothd_exec_t type - Allow dac override capability to mandb_t domain BZ(1529399) Resolves: rhbz#1423361 - Allow inetd_child process to chat via dbus with abrt Resolves: rhbz#1428805 - Allow zabbix_agent_t domain to connect to redis_port_t Resolves: rhbz#1418860 - Allow rhsmcertd_t domain to read xenfs_t files Resolves: rhbz#1405870 - Allow zabbix_agent_t to run zabbix scripts Resolves: rhbz#1380697 - Allow rabbitmq_t domain to create own tmp files/dirs Resolves: rhbz#1546897 - Allow policykit_t mmap policykit_auth_exec_t files Resolves: rhbz#1583082 - Allow ipmievd_t domain to read general certs Resolves: rhbz#1514591 - Add sys_ptrace capability to pcp_pmie_t domain - Allow squid domain to exec ldconfig Resolves: rhbz#1532017 - Make working gpg agent in gpg_agent_t domain Resolves: rhbz#1535109 - Update gpg SELinux policy module - Allow kexec to read kernel module files in /usr/lib/modules. Resolves: rhbz#1536690 - Allow mailman_domain to read system network state Resolves: rhbz#1413510 - Allow mailman_mail_t domain to search for apache configs Resolves: rhbz#1413510 - Allow openvswitch_t domain to read neutron state and read/write fixed disk devices Resolves: rhbz#1499208 - Allow antivirus_domain to read all domain system state Resolves: rhbz#1560986 - Allow targetd_t domain to red gconf_home_t files/dirs Resolves: rhbz#1546671 - Allow freeipmi domain to map sysfs_t files Resolves: rhbz#1575918 - Label /usr/libexec/bluetooth/obexd as obexd_exec_t Resolves: rhbz#1351750 - Update rhcs SELinux module Resolves: rhbz#1589257 - Allow iscsid_t domain mmap kernel modules Resolves: rhbz#1589295 - Allow iscsid_t domain mmap own tmp files Resolves: rhbz#1589295 - Update iscsid_domtrans() interface to allow mmap iscsid_exec_t binary Resolves: rhbz#1589295 - Update nscd_socket_use interface to allow caller domain also mmap nscd_var_run_t files. Resolves: rhbz#1589271 - Allow nscd_t domain to mmap system_db_t files Resolves: rhbz#1589271 - Add interface nagios_unconfined_signull() - Allow lircd_t domain read sssd public files Add setgid capability to lircd_t domain Resolves: rhbz#1550700 - Add missing requires - Allow tomcat domain sends email Resolves: rhbz#1585184 - Allow memcached_t domain nnp_transition becuase of systemd security features BZ(1514867) Resolves: rhbz#1585714 - Allow kdump_t domain to map /boot files Resolves: rhbz#1588884 - Fix typo in netutils policy - Allow confined users get AFS tokens Resolves: rhbz#1417671 - Allow sysadm_t domain to chat via dbus Resolves: rhbz#1582146 - Associate sysctl_kernel_t type with filesystem attribute - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Add interface dev_map_sysfs - Allow xdm_t domain to execute xdm_var_lib_t files Resolves: rhbz#1589139 - Allow syslogd_t domain to send signull to nagios_unconfined_plugin_t Resolves: rhbz#1569344 - Label /dev/vhost-vsock char device as vhost_device_t - Add files_map_boot_files() interface Resolves: rhbz#1588884 - Update traceroute_t domain to allow create dccp sockets Resolves: rhbz#1548350- Update ctdb domain to support gNFS setup Resolves: rhbz#1576818 - Allow authconfig_t dbus chat with policykit Resolves: rhbz#1551241 - Allow lircd_t domain to read passwd_file_t Resolves: rhbz:#1550700 - Allow lircd_t domain to read system state Resolves: rhbz#1550700 - Allow smbcontrol_t to mmap samba_var_t files and allow winbind create sockets BZ(1559795) Resolves: rhbz#1574521 - Allow tangd_t domain read certs Resolves: rhbz#1509055 - Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow ctdb_t domain modify ctdb_exec_t files Resolves: rhbz#1572584 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Allow SELinux users (except guest and xguest) to using bluetooth sockets Resolves: rhbz#1557299 - Allow confined users to use new socket classes for bluetooth, alg and tcpdiag sockets Resolves: rhbz#1557299 - Fix broken sysadm SELinux module Resolves: rhbz#1557311 - Allow user_t and staff_t domains create netlink tcpdiag sockets Resolves: rhbz#1557281 - Update ssh_domtrans_keygen interface to allow mmap ssh_keygen_exec_t binary file Resolves: rhbz#1583089 - Allow systemd_networkd_t to read/write tun tap devices Resolves: rhbz#1583830 - Add bridge_socket, dccp_socket, ib_socket and mpls_socket to socket_class_set Resolves: rhbz#1583771 - Allow audisp_t domain to mmap audisp_exec_t binary Resolves: rhbz#1583551 - Fix duplicates in sysadm.te file Resolves: rhbz#1307183 - Allow sysadm_u use xdm Resolves: rhbz#1307183 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix duplicates in sysadm.te file Resolves: rhbz#1307183- Allow sysadm_u use xdm Resolves: rhbz#1307183- Allow httpd_sys_script_t to connect to mongodb_port_t if boolean httpd_can_network_connect_db is turned on Resolves: rhbz:#1579219 - Allow chronyc_t to redirect ourput to /var/lib /var/log and /tmp Resolves: rhbz#1574418 - Allow chrome_sandbox_t to mmap tmp files Resolves: rhbz#1574392 - Allow ulogd_t to create netlink_netfilter sockets. Resolves: rhbz#1575924 - Update ulogd SELinux security policy - Allow rhsmcertd_t domain send signull to apache processes Resolves: rhbz#1576555 - Allow freeipmi domain to read sysfs_t files Resolves: rhbz#1575918 - Allow smbcontrol_t to create dirs with samba_var_t label Resolves: rhbz#1574521 - Allow swnserve_t domain to stream connect to sasl domain Resolves: rhbz#1574537 - Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Fix typo in sysnetwork.if file Resolves: rhbz#1581551- Improve procmail_domtrans() to allow mmaping procmail_exec_t - Allow hypervvssd_t domain to read fixed disk devices Resolves: rhbz#1581225 - Improve modutils_domtrans_insmod() interface to mmap insmod_exec_t binaries Resolves: rhbz#1581551 - Improve iptables_domtrans() interface to allow mmaping iptables_exec_t binary Resolves: rhbz#1581551 - Improve auth_domtrans_login_programinterface to allow also mmap login_exec_t binaries Resolves: rhbz#1581551 - Improve auth_domtrans_chk_passwd() interface to allow also mmaping chkpwd_exec_t binaries. Resolves: rhbz#1581551 - Allow mmap dhcpc_exec_t binaries in sysnet_domtrans_dhcpc interface- Add dbus_stream_connect_system_dbusd() interface. - Allow pegasus_t domain to mount tracefs_t filesystem Resolves:rhbz#1374570 - Allow psad_t domain to read all domains state Resolves: rhbz#1558439 - Add net_raw capability to named_t domain BZ(1545586) - Allow tomcat_t domain to connect to mongod_t tcp port Resolves:rhbz#1539748 - Allow dovecot and postfix to connect to systemd stream sockets Resolves: rhbz#1368642 - Label /usr/libexec/bluetooth/obexd as bluetoothd_exec_t to run process as bluetooth_t Resolves:rhbz#1351750 - Rename tang policy to tangd - Add interface systemd_rfkill_domtrans() - Allow users staff and sysadm to run wireshark on own domain Resolves:rhbz#1546362 - Allow systemd-bootchart to create own tmpfs files Resolves:rhbz#1510412- Rename tang policy to tangd - Allow virtd_t domain to relabel virt_var_lib_t files Resolves: rhbz#1558121 - Allow logrotate_t domain to stop services via systemd Resolves: rhbz#1527522 - Add tang policy Resolves: rhbz#1509055 - Allow mozilla_plugin_t to create mozilla.pdf file in user homedir with label mozilla_home_t Resolves: rhbz#1559859 - Improve snapperd SELinux policy Resolves: rhbz#1365555 - Allow snapperd_t daemon to create unlabeled dirs. Resolves: rhbz#1365555 - We have inconsistency in cgi templates with upstream, we use _content_t, but refpolicy use httpd__content_t. Created aliasses to make it consistence Resolves: rhbz#1271324 - Allow Openvswitch adding netdev bridge ovs 2.7.2.10 FDP Resolves: rhbz#1503835 - Add new Boolean tomcat_use_execmem Resolves: rhbz#1565226 - Allow domain transition from logrotate_t to chronyc_t Resolves: rhbz#1568281 - Allow nfsd_t domain to read/write sysctl fs files Resolves: rhbz#1516593 - Allow conman to read system state Resolves: rhbz#1377915 - Allow lircd_t to exec shell and add capabilities dac_read_search and dac_override Resolves: rhbz#1550700 - Allow usbmuxd to access /run/udev/data/+usb:*. Resolves: rhbz#1521054 - Allow abrt_t domain to manage kdump crash files Resolves: rhbz#1491585 - Allow systemd to use virtio console Resolves: rhbz#1558121 - Allow transition from sysadm role into mdadm_t domain. Resolves: rhbz#1551568 - Label /dev/op_panel and /dev/opal-prd as opal_device_t Resolves: rhbz#1537618 - Label /run/ebtables.lock as iptables_var_run_t Resolves: rhbz#1511437 - Allow udev_t domain to manage udev_rules_t char files. Resolves: rhbz#1545094 - Allow nsswitch_domain to read virt_var_lib_t files, because of libvirt NSS plugin. Resolves: rhbz#1567753 - Fix filesystem inteface file, we don't have nsfs_fs_t type, just nsfs_t Resolves: rhbz#1547700 - Allow iptables_t domain to create dirs in etc_t with system_conf_t labels- Add new boolean redis_enable_notify() Resolves: rhbz#1421326 - Label /var/log/shibboleth-www(/.*) as httpd_sys_rw_content_t Resolves: rhbz#1549514 - Add new label for vmtools scripts and label it as vmtools_unconfined_t stored in /etc/vmware-tools/ Resolves: rbhz#1463593 - Remove labeling for /etc/vmware-tools to bin_t it should be vmtools_unconfined_exec_t Resolves: rbhz#1463593- Backport several changes for snapperdfrom Fedora Rawhide Resolves: rhbz#1556798 - Allow snapperd_t to set priority for kernel processes Resolves: rhbz#1556798 - Make ganesha nfs server. Resolves: rhbz#1511489 - Allow vxfs filesystem to use SELinux labels Resolves: rhbz#1482880 - Add map permission to selinux-policy Resolves: rhbz#1460322- Label /usr/libexec/dbus-1/dbus-daemon-launch-helper as dbusd_exec_t to have systemd dbus services running in the correct domain instead of unconfined_service_t if unconfined.pp module is enabled. Resolves: rhbz#1546721- Allow openvswitch_t stream connect svirt_t Resolves: rhbz#1540702- Allow openvswitch domain to manage svirt_tmp_t sock files Resolves: rhbz#1540702 - Fix broken systemd_tmpfiles_run() interface- Allow dirsrv_t domain to create tmp link files Resolves: rhbz#1536011 - Label /usr/sbin/ldap-agent as dirsrv_snmp_exec_t Resolves: rhbz#1428568 - Allow ipsec_mgmt_t execute ifconfig_exec_t binaries - Allow ipsec_mgmt_t nnp domain transition to ifconfig_t Resolves: rhbz#1539416- Allow svirt_domain to create socket files in /tmp with label svirt_tmp_t Resolves: rhbz#1540702 - Allow keepalived_t domain getattr proc filesystem Resolves: rhbz#1477542 - Rename svirt_sandbox_file_t to container_file_t and svirt_lxc_net_t to container_t Resolves: rhbz#1538544 - Allow ipsec_t nnp transistions to domains ipsec_mgmt_t and ifconfig_t Resolves: rhbz:#1539416 - Allow systemd_logind_t domain to bind on dhcpd_port_t,pki_ca_port_t,flash_port_t Resolves: rhbz#1479350- Allow openvswitch_t domain to read cpuid, write to sysfs files and creating openvswitch_tmp_t sockets Resolves: rhbz#1535196 - Add new interface ppp_filetrans_named_content() Resolves: rhbz#1530601 - Allow keepalived_t read sysctl_net_t files Resolves: rhbz#1477542 - Allow puppetmaster_t domtran to puppetagent_t Resolves: rhbz#1376893 - Allow kdump_t domain to read kernel ring buffer Resolves: rhbz#1540004 - Allow ipsec_t domain to exec ifconfig_exec_t binaries. Resolves: rhbz#1539416 - Allow unconfined_domain_typ to create pppd_lock_t directory in /var/lock Resolves: rhbz#1530601 - Allow updpwd_t domain to create files in /etc with shadow_t label Resolves: rhbz#1412838 - Allow iptables sysctl load list support with SELinux enforced Resolves: rhbz#1535572- Allow virt_domains to acces infiniband pkeys. Resolves: rhbz#1533183 - Label /usr/libexec/ipsec/addconn as ipsec_exec_t to run this script as ipsec_t instead of init_t Resolves: rhbz#1535133 - Allow audisp_remote_t domain write to files on all levels Resolves: rhbz#1534924- Allow vmtools_t domain creating vmware_log_t files Resolves: rhbz#1507048 - Allow openvswitch_t domain to acces infiniband devices Resolves: rhbz#1532705- Allow chronyc_t domain to manage chronyd_keys_t files. Resolves: rhbz#1530525 - Make virtlog_t domain system dbus client Resolves: rhbz#1481109 - Update openvswitch SELinux module Resolves: rhbz#1482682 - Allow virtd_t to create also sock_files with label virt_var_run_t Resolves: rhbz#1484075- Allow domains that manage logfiles to man logdirs Resolves: rhbz#1523811- Label /dev/drm_dp_aux* as xserver_misc_device_t Resolves: rhbz#1520897 - Allow sysadm_t to run puppet_exec_t binaries as puppet_t Resolves: rhbz#1255745- Allow tomcat_t to manage pki_tomcat pid files Resolves: rhbz#1478371 - networkmanager: allow talking to openvswitch Resolves: rhbz#1517247 - Allow networkmanager_t and opensm_t to manage subned endports for IPoIB VLANs Resolves: rhbz#1517895 - Allow domains networkmanager_t and opensm_t to control IPoIB VLANs Resolves: rhbz#1517744 - Fix typo in guest interface file Resolves: rhbz#1468254 - Allow isnsd_t domain to accept tcp connections. Resolves: rhbz#1390208- Allow getty to use usbttys Resolves: rhbz#1514235- Allow ldap_t domain to manage also slapd_tmp_t lnk files Resolves: rhbz#1510883 - Allow cluster_t domain creating bundles directory with label var_log_t instead of cluster_var_log_t Resolves: rhbz:#1508360 - Add dac_read_search and dac_override capabilities to ganesha Resolves: rhbz#1483451- Add dependency for policycoreutils-2.5.18 becuase of new cgroup_seclabel policy capability Resolves: rhbz#1510145- Allow jabber domains to connect to postgresql ports Resolves: rhbz#1438489 - Dontaudit accountsd domain creating dirs in /root Resolves: rhbz#1456760 - Dontaudit slapd_t to block suspend system Resolves: rhbz: #1479759 - Allow spamc_t to stream connect to cyrus. Resolves: rhbz#1382955 - allow imapd to read /proc/net/unix file Resolves: rhbz#1393030 - Allow passenger to connect to mysqld_port_t Resolves: rhbz#1433464- Allow chronyc_t domain to use user_ptys Resolves: rhbz#1470150 - allow ptp4l to read /proc/net/unix file - Allow conmand to use usb ttys. Resolves: rhbz#1505121 - Label all files /var/log/opensm.* as opensm_log_t because opensm creating new log files with name opensm-subnet.lst Resolves: rhbz#1505845 - Allow chronyd daemon to execute chronyc. Resolves: rhbz#1508486 - Allow firewalld exec ldconfig. Resolves: rhbz#1375576 - Allow mozilla_plugin_t domain to dbus chat with devicekit Resolves: rhbz#1460477 - Dontaudit leaked logwatch pipes Resolves: rhbz#1450119 - Label /usr/bin/VGAuthService as vmtools_exec_t to confine this daemon. Resolves: rhbz#1507048 - Allow httpd_t domain to execute hugetlbfs_t files Resolves: rhbz#1507682 - Allow nfsd_t domain to read configfs_t files/dirs Resolves: rhbz#1439442 - Hide all allow rules with ptrace inside deny_ptrace boolean Resolves: rhbz#1421075 - Allow tgtd_t domain to read generic certs Resolves: rhbz#1438532 - Allow ptp4l to send msgs via dgram socket to unprivileged user domains Resolves: rhbz#1429853 - Allow dirsrv_snmp_t to use inherited user ptys and read system state Resolves: rhbz#1428568 - Allow glusterd_t domain to create own tmpfs dirs/files Resolves: rhbz#1411310 - Allow keepalived stream connect to snmp Resolves: rhbz#1401556 - After fix in kernel where LSM hooks for dac_override and dac_search_read capability was swaped we need to fix it also in policy Resolves: rhbz#1507089- Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow pegasus_openlmi_services_t to read generic certs Resolves: rhbz#1462292 - Allow ganesha_t domain to read random device Resolves: rhbz#1494382 - Allow zabbix_t domain to change its resource limits Resolves: rhbz:#1504074 - Add new boolean nagios_use_nfs Resolves: rhbz#1504826 - Allow system_mail_t to search network sysctls Resolves: rhbz#1505779 - Add samba_manage_var_dirs() interface - Fix typo bug in virt filecontext file - Allow nagios_script_t to read nagios_spool_t files Resolves: rhbz#1426824 - Allow samba to manage var dirs/files Resolves: rhbz#1415088 - Allow sbd_t to create own sbd_tmpfs_t dirs/files Resolves: rhbz#1380795 - Allow firewalld and networkmanager to chat with hypervkvp via dbus Resolves: rhbz#1377276 - Allow dmidecode to read rhsmcert_log_t files Resolves: rhbz#1300799 - Allow mail system to connect mariadb sockets. Resolves: rhbz#1368642 - Allow logrotate_t to change passwd and reloead services Resolves: rhbz#1450789 - Allow chronyd_t do request kernel module and block_suspend capability Resolves: rhbz#1350765 - Allow system_cronjob_t to create /var/lib/letsencrypt dir with right label Resolves: rhbz#1447278 - Allow httpd_t also read httpd_user_content_type dirs when httpd_enable_homedirs is enables Resolves: rhbz#1491994 - Allow svnserve to use kerberos Resolves: rhbz#1475271 - Allow conman to use ptmx. Add conman_use_nfs boolean Resolves: rhbz#1377915 - Add nnp transition for services using: NoNewPrivileges systemd security feature Resolves: rhbz#1311430 - Add SELinux support for chronyc Resolves: rhbz#1470150 - Add dac_read_search capability to openvswitch_t domain Resolves: rhbz#1501336 - Allow svnserve to manage own svnserve_log_t files/dirs Resolves: rhbz#1480741 - Allow keepalived_t to search network sysctls Resolves: rhbz#1477542 - Allow puppetagent_t domain dbus chat with rhsmcertd_t domain Resolves: rhbz#1446777 - Add dccp_socket into socker_class_set subset Resolves: rhbz#1459941 - Allow iptables_t to run setfiles to restore context on system Resolves: rhbz#1489118 - Label 20514 tcp/udp ports as syslogd_port_t Label 10514 tcp/udp portas as syslog_tls_port_t Resolves: rhbz:#1411400 - Make nnp transition Active Resolves: rhbz#1480518 - Label tcp 51954 as isns_port_t Resolves: rhbz#1390208 - Add dac_read_search capability chkpwd_t Resolves: rhbz#1376991 - Add support for running certbot(letsencrypt) in crontab Resolves: rhbz#1447278 - Add init_nnp_daemon_domain interface - Allow xdm_t to gettattr /dev/loop-control device Resolves: rhbz#1462925 - Allow nnp trasintion for unconfined_service_t Resolves: rhbz#1311430 - Allow unpriv user domains and unconfined_service_t to use chronyc Resolves: rhbz#1470150 - Allow iptables to exec plymouth. Resolves: rhbz#1480374 - Fix typo in fs_unmount_tracefs interface. Resolves: rhbz#1371057 - Label postgresql-check-db-dir as postgresql_exec_t Resolves: rhbz#1490956- We should not ship selinux-policy with permissivedomains enabled. Resolves: rhbz#1494172 - Fix order of installing selinux-policy-sandbox, because of depedencied in sandbox module, selinux-policy-targeted needs to be installed before selinux-policy-sandbox Resolves: rhbz#1492606- Allow tomcat to setsched Resolves: rhbz#1492730 - Fix rules blocking ipa-server upgrade process Resolves: rhbz#1478371 - Add new boolean tomcat_read_rpm_db() Resolves: rhbz#1477887 - Allow tomcat to connect on mysqld tcp ports - Add ctdbd_t domain sys_source capability and allow setrlimit Resolves: rhbz#1491235 - Fix keepalived SELinux module - Allow automount domain to manage mount pid files Resolves: rhbz#1482381 - Allow stunnel_t domain setsched Resolves: rhbz#1479383 - Add keepalived domain setpgid capability Resolves: rhbz#1486638 - Allow tomcat domain to connect to mssql port Resolves: rhbz#1484572 - Remove snapperd_t from unconfined domaines Resolves: rhbz#1365555 - Fix typo bug in apache module Resolves: rhbz#1397311 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Dontaudit that system_mail_t is trying to read /root/ files Resolves: rhbz#1147945 - Make working webadm_t userdomain Resolves: rhbz#1323792 - Allow redis domain to execute shell scripts. Resolves: rhbz#1421326 - Allow system_cronjob_t to create redhat-access-insights.log with var_log_t Resolves: rhbz#1473303 - Add couple capabilities to keepalived domain and allow get attributes of all domains Resolves: rhbz#1429327 - Allow dmidecode read rhsmcertd lock files Resolves: rhbz#1300799 - Add new interface rhsmcertd_rw_lock_files() Resolves: rhbz#1300799 - Label all plymouthd archives as plymouthd_var_log_t Resolves: rhbz#1478323 - Allow cloud_init_t to dbus chat with systemd_timedated_t Resolves: rhbz#1440730 - Allow logrotate_t to write to kmsg Resolves: rhbz#1397744 - Add capability kill to rhsmcertd_t Resolves: rhbz#1398338 - Disable mysqld_safe_t secure mode environment cleansing. Resolves: rhbz#1464063 - Allow winbind to manage smbd_tmp_t files Resolves: rhbz#1475566 - Add interface systemd_tmpfiles_run - End of file cannot be in comment - Allow systemd-logind to use ypbind Resolves: rhbz#1479350 - Add creating opasswd file with shadow_t SELinux label in auth_manage_shadow() interface Resolves: rhbz#1412838 - Allow sysctl_irq_t assciate with proc_t Resolves: rhbz#1485909 - Enable cgourp sec labeling Resolves: rhbz#1485947 - Add cgroup_seclabel policycap. Resolves: rhbz#1485947 - Allow sshd_t domain to send signull to xdm_t processes Resolves: rhbz#1448959 - Allow updpwd_t domain auth file name trans Resolves: rhbz#1412838 - Allow sysadm user to run systemd-tmpfiles Resolves: rbhz#1325364 - Add support labeling for vmci and vsock device Resolves: rhbz#1451358 - Add userdom_dontaudit_manage_admin_files() interface Resolves: rhbz#1323792 - Allow iptables_t domain to read files with modules_conf_t label Resolves: rhbz#1373220 - init: Add NoNewPerms support for systemd. Resolves: rhbz#1480518 - Add nnp_nosuid_transition policycap and related class/perm definitions. Resolves: rhbz#1480518 - refpolicy: Infiniband pkeys and endports Resolves: rhbz#1464484- Allow certmonger using systemctl on pki_tomcat unit files Resolves: rhbz#1481388- Allow targetd_t to create own tmp files. - Dontaudit targetd_t to exec rpm binary file. Resolves: rhbz#1373860 Resolves: rhbz#1424621- Add few rules to make working targetd daemon with SELinux Resolves: rhbz#1373860 - Allow ipmievd_t domain to load kernel modules Resolves: rhbz#1441081 - Allow logrotate to reload transient systemd unit Resolves: rhbz#1440515 - Add certwatch_t domain dac_override and dac_read_search capabilities Resolves: rhbz#1422000 - Allow postgrey to execute bin_t files and add postgrey into nsswitch_domain Resolves: rhbz#1412072 - Allow nscd_t domain to search network sysctls Resolves: rhbz#1432361 - Allow iscsid_t domain to read mount pid files Resolves: rhbz#1482097 - Allow ksmtuned_t domain manage sysfs_t files/dirs Resolves: rhbz#1413865 - Allow keepalived_t domain domtrans into iptables_t Resolves: rhbz#1477719 - Allow rshd_t domain reads net sysctls Resolves: rhbz#1477908 - Add interface seutil_dontaudit_read_module_store() - Update interface lvm_rw_pipes() by adding also open permission - Label /dev/clp device as vfio_device_t Resolves: rhbz#1477624 - Allow ifconfig_t domain unmount fs_t Resolves: rhbz#1477445 - Label /dev/gpiochip* devices as gpio_device_t Resolves: rhbz#1477618 - Add interface dev_manage_sysfs() Resolves: rhbz#1474989- Label /usr/libexec/sudo/sesh as shell_exec_t Resolves: rhbz#1480791- Allow tomcat_t domain couple capabilities to make working tomcat-jsvc Resolves: rhbz#1470735- Allow llpdad send dgram to libvirt Resolves: rhbz#1472722- Add new boolean gluster_use_execmem Resolves: rhbz#1469027 - Allow cluster_t and glusterd_t domains to dbus chat with ganesha service Resolves: rhbz#1468581- Dontaudit staff_t user read admin_home_t files. Resolves: rhbz#1290633- Allow couple rules needed to start targetd daemon with SELinux in enforcing mode Resolves: rhbz#1424621 - Add interface lvm_manage_metadata Resolves: rhbz#1424621- Allow sssd_t to read realmd lib files. Resolves: rhbz#1436689 - Add permission open to files_read_inherited_tmp_files() interface Resolves: rhbz#1290633 Resolves: rhbz#1457106- Allow unconfined_t user all user namespace capabilties. Resolves: rhbz#1461488- Allow httpd_t to read realmd_var_lib_t files Resolves: rhbz#1436689- Allow named_t to bind on udp 4321 port Resolves: rhbz#1312972 - Allow systemd-sysctl cap. sys_ptrace Resolves: rhbz#1458999- Allow pki_tomcat_t execute ldconfig. Resolves: rhbz#1436689- Allow iscsi domain load kernel module. Resolves: rhbz#1457874 - Allow keepalived domain connect to squid tcp port Resolves: rhbz#1457455 - Allow krb5kdc_t domain read realmd lib files. Resolves: rhbz#1436689 - xdm_t should view kernel keys Resolves: rhbz#1432645- Allow tomcat to connect on all unreserved ports - Allow ganesha to connect to all rpc ports Resolves: rhbz#1448090 - Update ganesha with another fixes. Resolves: rhbz#1448090 - Update rpc_read_nfs_state_data() interface to allow read also lnk_files. Resolves: rhbz#1448090 - virt_use_glusterd boolean should be in optional block Update ganesha module to allow create tmp files Resolves: rhbz#1448090 - Hide broken symptoms when machine is configured with network bounding.- Add new boolean virt_use_glusterd Resolves: rhbz#1455994 - Add capability sys_boot for sbd_t domain - Allow sbd_t domain to create rpc sysctls. Resolves: rhbz#1455631 - Allow ganesha_t domain to manage glusterd_var_run_t pid files. Resolves: rhbz#1448090- Create new interface: glusterd_read_lib_files() - Allow ganesha read glusterd lib files. - Allow ganesha read network sysctls Resolves: rhbz#1448090- Add few allow rules to ganesha module Resolves: rhbz#1448090 - Allow condor_master_t to read sysctls. Resolves: rhbz#1277506 - Add dac_override cap to ctdbd_t domain Resolves: rhbz#1435708 - Label 8750 tcp/udp port as dey_keyneg_port_t Resolves: rhbz#1448090- Add ganesha_use_fusefs boolean. Resolves: rhbz#1448090- Allow httpd_t reading kerberos kdc config files Resolves: rhbz#1452215 - Allow tomcat_t domain connect to ibm_dt_2 tcp port. Resolves: rhbz#1447436 - Allow stream connect to initrc_t domains Resolves: rhbz#1447436 - Allow dnsmasq_t domain to read systemd-resolved pid files. Resolves: rhbz#1453114 - Allow tomcat domain name_bind on tcp bctp_port_t Resolves: rhbz#1451757 - Allow smbd_t domain generate debugging files under /var/run/gluster. These files are created through the libgfapi.so library that provides integration of a GlusterFS client in the Samba (vfs_glusterfs) process. Resolves: rhbz#1447669 - Allow condor_master_t write to sysctl_net_t Resolves: rhbz#1277506 - Allow nagios check disk plugin read /sys/kernel/config/ Resolves: rhbz#1277718 - Allow pcp_pmie_t domain execute systemctl binary Resolves: rhbz#1271998 - Allow nagios to connect to stream sockets. Allow nagios start httpd via systemctl Resolves: rhbz#1247635 - Label tcp/udp port 1792 as ibm_dt_2_port_t Resolves: rhbz#1447436 - Add interface fs_read_configfs_dirs() - Add interface fs_read_configfs_files() - Fix systemd_resolved_read_pid interface - Add interface systemd_resolved_read_pid() Resolves: rhbz#1453114 - Allow sshd_net_t domain read/write into crypto devices Resolves: rhbz#1452759 - Label 8999 tcp/udp as bctp_port_t Resolves: rhbz#1451757- nmbd_t needs net_admin capability like smbd Resolves: rhbz#1431859 - Dontaudit net_admin capability for domains postfix_master_t and postfix_qmgr_t Resolves: rhbz#1431859 - Allow rngd domain read sysfs_t Resolves: rhbz#1451735 - Add interface pki_manage_common_files() Resolves: rhbz#1447436 - Allow tomcat_t domain to manage pki_common_t files and dirs Resolves: rhbz#1447436 - Use stricter fc rules for sssd sockets in /var/run Resolves: rhbz#1448060 - Allow certmonger reads httpd_config_t files Resolves: rhbz#1436689 - Allow keepalived_t domain creating netlink_netfilter_socket. Resolves: rhbz#1451684 - Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321- Allow tomcat domain read rpm_var_lib_t files Allow tomcat domain exec rpm_exec_t files Allow tomcat domain name connect on oracle_port_t Allow tomcat domain read cobbler_var_lib_t files. Resolves: rhbz#1451318 - Allow sssd_t domain creating sock files labeled as sssd_var_run_t in /var/run/ Resolves: rhbz#1448056 Resolves: rhbz#1448060 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Make able deply overcloud via neutron_t to label nsfs as fs_t Resolves: rhbz#1373321 - Allow netutils setpcap capability Resolves:1444438- Update targetd policy to accommodate changes in the service Resolves: rhbz#1424621 - Allow tomcat_domain connect to * postgresql_port_t * amqp_port_t Allow tomcat_domain read network sysctls Resolves: rhbz#1450819 - Update virt_rw_stream_sockets_svirt() interface to allow confined users set socket options. Resolves: rhbz#1415841 - Allow radius domain stream connec to postgresql Resolves: rhbz#1446145 - Allow virt_domain to read raw fixed_disk_device_t to make working blockcommit Resolves: rhbz#1449977 - Allow glusterd_t domain start ganesha service Resolves: rhbz#1448090 - Made few cosmetic changes in sssd SELinux module Resolves: rhbz#1448060 - sssd-kcm should not run as unconfined_service_t BZ(1447411) Resolves: rhbz#1448060 - Add sssd_secrets labeling Also add named_filetrans interface to make sure all labels are correct Resolves: rhbz#1448056 - Allow keepalived_t domain read usermodehelper_t Resolves: rhbz#1449769 - Allow tomcat_t domain read pki_common_t files Resolves: rhbz#1447436 - Add interface pki_read_common_files() Resolves: rhbz#1447436- Allow hypervkvp_t domain execute hostname Resolves: rhbz#1449064 - Dontaudit sssd_selinux_manager_t use of net_admin capability Resolves: rhbz#1444955 - Allow tomcat_t stream connect to pki_common_t Resolves: rhbz#1447436 - Dontaudit xguest_t's attempts to listen to its tcp_socket - Allow sssd_selinux_manager_t to ioctl init_t sockets Resolves: rhbz#1436689 - Allow _su_t to create netlink_selinux_socket Resolves rhbz#1146987 - Allow unconfined_t to module_load any file Resolves rhbz#1442994- Improve ipa_cert_filetrans_named_content() interface to also allow caller domain manage ipa_cert_t type. Resolves: rhbz#1436689- Allow pki_tomcat_t domain read /etc/passwd. Resolves: rhbz#1436689 - Allow tomcat_t domain read ipa_tmp_t files Resolves: rhbz#1436689 - Label new path for ipa-otpd Resolves: rhbz#1446353 - Allow radiusd_t domain stream connect to postgresql_t Resolves: rhbz#1446145 - Allow rhsmcertd_t to execute hostname_exec_t binaries. Resolves: rhbz#1445494 - Allow virtlogd to append nfs_t files when virt_use_nfs=1 Resolves: rhbz#1402561- Update tomcat policy to adjust for removing unconfined_domain attr. Resolves: rhbz#1432083 - Allow httpd_t domain read also httpd_user_content_type lnk_files. Resolves: rhbz#1383621 - Allow httpd_t domain create /etc/httpd/alias/ipaseesion.key with label ipa_cert_t Resolves: rhbz#1436689 - Dontaudit _gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Label /var/www/html/nextcloud/data as httpd_sys_rw_content_t Resolves: rhbz#1425530 - Add interface ipa_filetrans_named_content() Resolves: rhbz#1432115 - Allow tomcat use nsswitch Resolves: rhbz#1436689 - Allow certmonger_t start/status generic services Resolves: rhbz#1436689 - Allow dirsrv read cgroup files. Resolves: rhbz#1436689 - Allow ganesha_t domain read/write infiniband devices. Resolves: rhbz#1383784 - Allow sendmail_t domain sysctl_net_t files Resolves: rhbz#1369376 - Allow targetd_t domain read network state and getattr on loop_control_device_t Resolves: rhbz#1373860 - Allow condor_schedd_t domain send mails. Resolves: rhbz#1277506 - Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689 - Allow staff to systemctl virt server when staff_use_svirt=1 Resolves: rhbz#1415841 - Allow unconfined_t create /tmp/ca.p12 file with ipa_tmp_t context Resolves: rhbz#1432115 - Label /sysroot/ostree/deploy/rhel-atomic-host/* as root_t Resolves: rhbz#1428112- Alow certmonger to create own systemd unit files. Resolves: rhbz#1436689- Hide broken symptoms when using kernel 3.10.0-514+ with network bonding. Postfix_picup_t domain requires NET_ADMIN capability which is not really needed. Resolves: rhbz#1431859 - Fix policy to reflect all changes in new IPA release Resolves: rhbz#1432115 Resolves: rhbz#1436689- Allow sbd_t to read/write fixed disk devices Resolves: rhbz#1440165 - Add sys_ptrace capability to radiusd_t domain Resolves: rhbz#1426641 - Allow cockpit_session_t domain connects to ssh tcp ports. Resolves: rhbz#1413509- Update tomcat policy to make working ipa install process Resolves: rhbz#1436689- Allow pcp_pmcd_t net_admin capability. - Allow pcp_pmcd_t read net sysctls - Allow system_cronjob_t create /var/run/pcp with pcp_var_run_t Resolves: rhbz#1336211- Fix all AVC denials during pkispawn of CA Resolves: rhbz#1436383 - Update pki interfaces and tomcat module Resolves: rhbz#1436689- Update pki interfaces and tomcat module Resolves: rhbz#1436689- Dontaudit firewalld wants write to /root Resolves: rhbz#1438708 - Dontaudit firewalld to create dirs in /root/ Resolves: rhbz#1438708 - Allow sendmail to search network sysctls Resolves: rhbz#1369376 - Add interface gssd_noatsecure() Resolves: rhbz#1438036 - Add interface gssproxy_noatsecure() Resolves: rhbz#1438036 - Dontaudit pcp_pmlogger_t search for xserver logs. Allow pcp_pmlogger_t to send signals to unconfined doamins Allow pcp_pmlogger_t to send logs to journals Resolves: rhbz#1379371 - Allow chronyd_t net_admin capability to allow support HW timestamping. Resolves: rhbz#1416015 - Update tomcat policy Resolves: rhbz#1436689 Resolves: rhbz#1436383 - Allow certmonger to start haproxy service Resolves: rhbz#1349394 - Allow init noatsecure for gssd and gssproxy Resolves: rhbz#1438036- geoclue wants to dbus chat with avahi Resolves: rhbz#1434286 - Allow iptables get list of kernel modules Resolves: rhbz#1367520 - Allow unconfined_domain_type to enable/disable transient unit Resolves: rhbz#1337041 - Add interfaces init_enable_transient_unit() and init_disable_transient_unit - Revert "Allow sshd setcap capability. This is needed due to latest changes in sshd" Resolves: rhbz#1435264 - Label sysroot dir under ostree as root_t Resolves: rhbz#1428112- Remove ganesha_t domain from permissive domains. Resolves: rhbz#1436988- Allow named_t domain bind on several udp ports Resolves: rhbz#1312972 - Update nscd_use() interface Resolves: rhbz#1281716 - Allow radius_t domain ptrace Resolves: rhbz#1426641 - Update nagios to allos exec systemctl Resolves: rhbz#1247635 - Update pcp SELinux module to reflect all pcp changes Resolves: rhbz#1271998 - Label /var/lib/ssl_db as squid_cache_t Label /etc/squid/ssl_db as squid_cache_t Resolves: rhbz#1325527 - Allow pcp_pmcd_t domain search for network sysctl Allow pcp_pmcd_t domain sys_ptrace capability Resolves: rhbz#1336211- Allow drbd load modules Resolves: rhbz#1134883 - Revert "Add sys_module capability for drbd Resolves: rhbz#1134883" - Allow stapserver list kernel modules Resolves: rhbz#1325976 - Update targetd policy Resolves: rhbz#1373860 - Add sys_admin capability to amanda Resolves: rhbz#1371561 - Allow hypervvssd_t to read all dirs. Resolves: rhbz#1331309 - Label /run/haproxy.sock socket as haproxy_var_run_t Resolves: rhbz#1386233 - Allow oddjob_mkhomedir_t to mamange autofs_t dirs. Resolves: rhbz#1408819 - Allow tomcat to connect on http_cache_port_t Resolves: rhbz#1432083 - Allow geoclue to send msgs to syslog. Resolves: rhbz#1434286 - Allow condor_master_t domain capability chown. Resolves: rhbz#1277506 - Update mta_filetrans_named_content() interface to allow calling domain create files labeled as etc_aliases_t in dir labeled as etc_mail_t. Resolves: rhbz#1167468 - Allow nova domain search for httpd configuration. Resolves: rhbz#1190761 - Add sys_module capability for drbd Resolves: rhbz#1134883 - Allow user_u users stream connect to dirsrv, Allow sysadm_u and staff_u users to manage dirsrv files Resolves: rhbz#1286474 - Allow systemd_networkd_t communicate with systemd_networkd_t via dbus Resolves: rhbz#1278010- Add haproxy_t domain fowner capability Resolves: rhbz#1386233 - Allow domain transition from ntpd_t to hwclock_t domains Resolves: rhbz#1375624 - Allow cockpit_session_t setrlimit and sys_resource Resolves: rhbz#1402316 - Dontaudit svirt_t read state of libvirtd domain Resolves: rhbz#1426106 - Update httpd and gssproxy modules to reflects latest changes in freeipa Resolves: rhbz#1432115 - Allow iptables read modules_conf_t Resolves: rhbz#1367520- Remove tomcat_t domain from unconfined domains Resolves: rhbz#1432083 - Create new boolean: sanlock_enable_home_dirs() Resolves: rhbz#1432783 - Allow mdadm_t domain to read/write nvme_device_t Resolves: rhbz#1431617 - Remove httpd_user_*_content_t domains from user_home_type attribute. This tighten httpd policy and acces to user data will be more strinct, and also fix mutual influente between httpd_enable_homedirs and httpd_read_user_content Resolves: rhbz#1383621 - Dontaudit domain to create any file in /proc. This is kernel bug. Resolves: rhbz#1412679 - Add interface dev_rw_nvme Resolves: rhbz#1431617- Allow gssproxy to get attributes on all filesystem object types. Resolves: rhbz#1430295 - Allow ganesha to chat with unconfined domains via dbus Resolves: rhbz#1426554 - add the policy required for nextcloud Resolves: rhbz#1425530 - Add nmbd_t capability2 block_suspend Resolves: rhbz#1425357 - Label /var/run/chrony as chronyd_var_run_t Resolves: rhbz#1416015 - Add domain transition from sosreport_t to iptables_t Resolves: rhbz#1359789 - Fix path to /usr/lib64/erlang/erts-5.10.4/bin/epmd Resolves: rhbz:#1332803- Update rpm macros Resolves: rhbz#1380854- Add handling booleans via selinux-policy macros in custom policy spec files. Resolves: rhbz#1380854- Allow openvswitch to load kernel modules Resolves: rhbz#1405479- Allow openvswitch read script state. Resolves: rhbz#1405479- Update ganesha policy Resolves: rhbz#1426554 Resolves: rhbz#1383784 - Allow chronyd to read adjtime Resolves: rhbz#1416015 - Fixes for chrony version 2.2 Resolves: rhbz#1416015 - Add interface virt_rw_stream_sockets_svirt() Resolves: rhbz#1415841 - Label /dev/ss0 as gpfs_device_t Resolves: rhbz#1383784 - Allow staff to rw svirt unix stream sockets. Resolves: rhbz#1415841 - Label /rhev/data-center/mnt as mnt_t Resolves: rhbz#1408275 - Associate sysctl_rpc_t with proc filesystems Resolves: rhbz#1350927 - Add new boolean: domain_can_write_kmsg Resolves: rhbz#1415715- Allow rhsmcertd_t dbus chat with system_cronjob_t Resolves: rhbz#1405341 - Allow openvswitch exec hostname and readinitrc_t files Resolves: rhbz#1405479 - Improve SELinux context for mysql_db_t objects. Resolves: rhbz#1391521 - Allow postfix_postdrop to communicate with postfix_master via pipe. Resolves: rhbz#1379736 - Add radius_use_jit boolean Resolves: rhbz#1426205 - Label /var/lock/subsys/iptables as iptables_lock_t Resolves: rhbz#1405441 - Label /usr/lib64/erlang/erts-5.10.4/bin/epmd as lib_t Resolves: rhbz#1332803 - Allow can_load_kernmodule to load kernel modules. Resolves: rhbz#1423427 Resolves: rhbz#1424621- Allow nfsd_t domain to create sysctls_rpc_t files Resolves: rhbz#1405304 - Allow openvswitch to create netlink generic sockets. Resolves: rhbz#1397974 - Create kernel_create_rpc_sysctls() interface Resolves: rhbz#1405304- Allow nfsd_t domain rw sysctl_rpc_t dirs Resolves: rhbz#1405304 - Allow cgdcbxd_t to manage cgroup files. Resolves: rhbz#1358493 - Allow cmirrord_t domain to create netlink_connector sockets Resolves: rhbz#1412670 - Allow fcoemon to create netlink scsitransport sockets Resolves: rhbz#1362496 - Allow quota_nld_t create netlink_generic sockets Resolves: rhbz#1358679 - Allow cgred_t create netlink_connector sockets Resolves: rhbz#1376357 - Add dhcpd_t domain fowner capability Resolves: rhbz#1358485 - Allow acpid to attempt to connect to the Linux kernel via generic netlink socket. Resolves: rhbz#1358478 - Rename docker module to container module Resolves: rhbz#1386916 - Allow setflies to mount tracefs Resolves: rhbz#1376357 - Allow iptables to read nsfs files. Resolves: rhbz#1411316 - Allow systemd_bootchart_t domain create dgram sockets. Resolves: rhbz#1365953 - Rename docker interfaces to container Resolves: rhbz#1386916- Allow initrc_t domain to run rhel-autorelabel script properly during boot process Resolves: rhbz#1379722 - Allow systemd_initctl_t to create and connect unix_dgram sockets Resolves: rhbz#1365947 - Allow ifconfig_t to mount/unmount nsfs_t filesystem Resolves: rhbz#1349814 - Add interfaces allowing mount/unmount nsfs_t filesystem Resolves: rhbz#1349814- Add interface init_stream_connectto() Resolves:rhbz#1365947 - Allow rhsmcertd domain signull kernel. Resolves: rhbz#1379781 - Allow kdumpgui domain to read nvme device - Allow insmod_t to load kernel modules Resolves: rhbz#1421598 - Add interface files_load_kernel_modules() Resolves: rhbz#1421598 - Add SELinux support for systemd-initctl daemon Resolves:rhbz#1365947 - Add SELinux support for systemd-bootchart Resolves: rhbz#1365953- Allow firewalld to getattr open search read modules_object_t:dir Resolves: rhbz#1418391 - Fix label for nagios plugins in nagios file conxtext file Resolves: rhbz#1277718 - Add sys_ptrace capability to pegasus domain Resolves: rhbz#1381238 - Allow sssd_t domain setpgid Resolves:rhbz#1416780 - After the latest changes in nfsd. We should allow nfsd_t to read raw fixed disk. Resolves: rhbz#1350927 - Allow kdumpgui domain to read nvme device Resolves: rhbz#1415084 - su using libselinux and creating netlink_selinux socket is needed to allow libselinux initialization. Resolves: rhbz#1146987 - Add user namespace capability object classes. Resolves: rhbz#1368057 - Add module_load permission to class system Resolves:rhbz#1368057 - Add the validate_trans access vector to the security class Resolves: rhbz#1368057 - Add "binder" security class and access vectors Resolves: rhbz#1368057 - Allow ifconfig_t domain read nsfs_t Resolves: rhbz#1349814 - Allow ping_t domain to load kernel modules. Resolves: rhbz#1388363- Allow systemd container to read/write usermodehelperstate Resolves: rhbz#1403254 - Label udp ports in range 24007-24027 as gluster_port_t Resolves: rhbz#1404152- Allow glusterd_t to bind on glusterd_port_t udp ports. Resolves: rhbz#1404152 - Revert: Allow glusterd_t to bind on med_tlp port.- Allow glusterd_t to bind on med_tlp port. Resolves: rhbz#1404152 - Update ctdbd_t policy to reflect all changes. Resolves: rhbz#1402451 - Label tcp port 24009 as med_tlp_port_t Resolves: rhbz#1404152 - Issue appears during update directly from RHEL-7.0 to RHEL-7.3 or above. Modules pkcsslotd and vbetools missing in selinux-policy package for RHEL-7.3 which causing warnings during SELinux policy store migration process. Following patch fixes issue by skipping pkcsslotd and vbetools modules migration.- Allow ctdbd_t domain transition to rpcd_t Resolves:rhbz#1402451- Fixes for containers Allow containers to attempt to write to unix_sysctls. Allow cotainers to use the FD's leaked to them from parent processes. Resolves: rhbz#1403254- Allow glusterd_t send signals to userdomain. Label new glusterd binaries as glusterd_exec_t Resolves: rhbz#1404152 - Allow systemd to stop glusterd_t domains. Resolves: rhbz#1400493- Make working CTDB:NFS: CTDB failover from selinux-policy POV Resolves: rhbz#1402451- Add kdump_t domain sys_admin capability Resolves: rhbz#1375963- Allow puppetagent_t to access timedated dbus. Use the systemd_dbus_chat_timedated interface to allow puppetagent_t the access. Resolves: rhbz#1399250- Update systemd on RHEL-7.2 box to version from RHEL-7.3 and then as a separate yum command update the selinux policy systemd will start generating USER_AVC denials and will start returning "Access Denied" errors to DBus clients Resolves: rhbz#1393505- Allow cluster_t communicate to fprintd_t via dbus Resolves: rhbz#1349798- Fix error message during update from RHEL-7.2 to RHEL-7.3, when /usr/sbin/semanage command is not installed and selinux-policy-migrate-local-changes.sh script is executed in %post install phase of selinux-policy package Resolves: rhbz#1392010- Allow GlusterFS with RDMA transport to be started correctly. It requires ipc_lock capability together with rw permission on rdma_cm device. Resolves: rhbz#1384488 - Allow glusterd to get attributes on /sys/kernel/config directory. Resolves: rhbz#1384483- Use selinux-policy-migrate-local-changes.sh instead of migrateStore* macros - Add selinux-policy-migrate-local-changes service Resolves: rhbz#1381588- Allow sssd_selinux_manager_t to manage also dir class. Resolves: rhbz#1368097 - Add interface seutil_manage_default_contexts_dirs() Resolves: rhbz#1368097- Add virt_sandbox_use_nfs -> virt_use_nfs boolean substitution. Resolves: rhbz#1355783- Allow pcp_pmcd_t domain transition to lvm_t Add capability kill and sys_ptrace to pcp_pmlogger_t Resolves: rhbz#1309883- Allow ftp daemon to manage apache_user_content Resolves: rhbz#1097775 - Label /etc/sysconfig/oracleasm as oracleasm_conf_t Resolves: rhbz#1331383 - Allow oracleasm to rw inherited fixed disk device Resolves: rhbz#1331383 - Allow collectd to connect on unix_stream_socket Resolves: rhbz#1377259- Allow iscsid create netlink iscsid sockets. Resolves: rhbz#1358266 - Improve regexp for power_unit_file_t files. To catch just systemd power unit files. Resolves: rhbz#1375462- Update oracleasm SELinux module that can manage oracleasmfs_t blk files. Add dac_override cap to oracleasm_t domain. Resolves: rhbz#1331383 - Add few rules to pcp SELinux module to make ti able to start pcp_pmlogger service Resolves: rhbz#1206525- Add oracleasm_conf_t type and allow oracleasm_t to create /dev/oracleasm Resolves: rhbz#1331383 - Label /usr/share/pcp/lib/pmie as pmie_exec_t and /usr/share/pcp/lib/pmlogger as pmlogger_exec_t Resolves: rhbz#1206525 - Allow mdadm_t to getattr all device nodes Resolves: rhbz#1365171 - Add interface dbus_dontaudit_stream_connect_system_dbusd() Resolves:rhbz#1052880 - Add virt_stub_* interfaces for docker policy which is no longer a part of our base policy. Resolves: rhbz#1372705 - Allow guest-set-user-passwd to set users password. Resolves: rhbz#1369693 - Allow samdbox domains to use msg class Resolves: rhbz#1372677 - Allow domains using kerberos to read also kerberos config dirs Resolves: rhbz#1368492 - Allow svirt_sandbox_domains to r/w onload sockets Resolves: rhbz#1342930 - Add interface fs_manage_oracleasm() Resolves: rhbz#1331383 - Label /dev/kfd as hsa_device_t Resolves: rhbz#1373488 - Update seutil_manage_file_contexts() interface that caller domain can also manage file_context_t dirs Resolves: rhbz#1368097 - Add interface to write to nsfs inodes Resolves: rhbz#1372705 - Allow systemd services to use PrivateNetwork feature Resolves: rhbz#1372705 - Add a type and genfscon for nsfs. Resolves: rhbz#1372705 - Allow run sulogin_t in range mls_systemlow-mls_systemhigh. Resolves: rhbz#1290400- Allow arpwatch to create netlink netfilter sockets. Resolves: rhbz#1358261 - Fix file context for /etc/pki/pki-tomcat/ca/ - new interface oddjob_mkhomedir_entrypoint() - Move label for /var/lib/docker/vfs/ to proper SELinux module - Allow mdadm to get attributes from all devices. - Label /etc/puppetlabs as puppet_etc_t. - Allow systemd-machined to communicate to lxc container using dbus - Allow systemd_resolved to send dbus msgs to userdomains Resolves: rhbz#1236579 - Allow systemd-resolved to read network sysctls Resolves: rhbz#1236579 - Allow systemd_resolved to connect on system bus. Resolves: rhbz#1236579 - Make entrypoint oddjob_mkhomedir_exec_t for unconfined_t - Label all files in /dev/oracleasmfs/ as oracleasmfs_t Resolves: rhbz#1331383- Label /etc/pki/pki-tomcat/ca/ as pki_tomcat_cert_t Resolves:rhbz#1366915 - Allow certmonger to manage all systemd unit files Resolves:rhbz#1366915 - Grant certmonger "chown" capability Resolves:rhbz#1366915 - Allow ipa_helper_t stream connect to dirsrv_t domain Resolves: rhbz#1368418 - Update oracleasm SELinux module Resolves: rhbz#1331383 - label /var/lib/kubelet as svirt_sandbox_file_t Resolves: rhbz#1369159 - Add few interfaces to cloudform.if file Resolves: rhbz#1367834 - Label /var/run/corosync-qnetd and /var/run/corosync-qdevice as cluster_var_run_t. Note: corosync policy is now par of rhcs module Resolves: rhbz#1347514 - Allow krb5kdc_t to read krb4kdc_conf_t dirs. Resolves: rhbz#1368492 - Update networkmanager_filetrans_named_content() interface to allow source domain to create also temad dir in /var/run. Resolves: rhbz#1365653 - Allow teamd running as NetworkManager_t to access netlink_generic_socket to allow multiple network interfaces to be teamed together. Resolves: rhbz#1365653 - Label /dev/oracleasmfs as oracleasmfs_t. Add few interfaces related to oracleasmfs_t type Resolves: rhbz#1331383 - A new version of cloud-init that supports the effort to provision RHEL Atomic on Microsoft Azure requires some a new rules that allows dhclient/dhclient hooks to call cloud-init. Resolves: rhbz#1367834 - Allow iptables to creating netlink generic sockets. Resolves: rhbz#1364359- Allow ipmievd domain to create lock files in /var/lock/subsys/ Resolves:rhbz#1349058 - Update policy for ipmievd daemon. Resolves:rhbz#1349058 - Dontaudit hyperkvp to getattr on non security files. Resolves: rhbz#1349356 - Label /run/corosync-qdevice and /run/corosync-qnetd as corosync_var_run_t Resolves: rhbz#1347514 - Fixed lsm SELinux module - Add sys_admin capability to sbd domain Resolves: rhbz#1322725 - Allow vdagent to comunnicate with systemd-logind via dbus Resolves: rhbz#1366731 - Allow lsmd_plugin_t domain to create fixed_disk device. Resolves: rhbz#1238066 - Allow opendnssec domain to create and manage own tmp dirs/files Resolves: rhbz#1366649 - Allow opendnssec domain to read system state Resolves: rhbz#1366649 - Update opendnssec_manage_config() interface to allow caller domain also manage opendnssec_conf_t dirs Resolves: rhbz#1366649 - Allow rasdaemon to mount/unmount tracefs filesystem. Resolves: rhbz#1364380 - Label /usr/libexec/iptables/iptables.init as iptables_exec_t Allow iptables creating lock file in /var/lock/subsys/ Resolves: rhbz#1367520 - Modify interface den_read_nvme() to allow also read nvme_device_t block files. Resolves: rhbz#1362564 - Label /var/run/storaged as lvm_var_run_t. Resolves: rhbz#1264390 - Allow unconfineduser to run ipa_helper_t. Resolves: rhbz#1361636- Dontaudit mock to write to generic certs. Resolves: rhbz#1271209 - Add labeling for corosync-qdevice and corosync-qnetd daemons, to run as cluster_t Resolves: rhbz#1347514 - Revert "Label corosync-qnetd and corosync-qdevice as corosync_t domain" - Allow modemmanager to write to systemd inhibit pipes Resolves: rhbz#1365214 - Label corosync-qnetd and corosync-qdevice as corosync_t domain Resolves: rhbz#1347514 - Allow ipa_helper to read network state Resolves: rhbz#1361636 - Label oddjob_reqiest as oddjob_exec_t Resolves: rhbz#1361636 - Add interface oddjob_run() Resolves: rhbz#1361636 - Allow modemmanager chat with systemd_logind via dbus Resolves: rhbz#1362273 - Allow NetworkManager chat with puppetagent via dbus Resolves: rhbz#1363989 - Allow NetworkManager chat with kdumpctl via dbus Resolves: rhbz#1363977 - Allow sbd send msgs to syslog Allow sbd create dgram sockets. Allow sbd to communicate with kernel via dgram socket Allow sbd r/w kernel sysctls. Resolves: rhbz#1322725 - Allow ipmievd_t domain to re-create ipmi devices Label /usr/libexec/openipmi-helper as ipmievd_exec_t Resolves: rhbz#1349058 - Allow rasdaemon to use tracefs filesystem. Resolves: rhbz#1364380 - Fix typo bug in dirsrv policy - Some logrotate scripts run su and then su runs unix_chkpwd. Allow logrotate_t domain to check passwd. Resolves: rhbz#1283134 - Add ipc_lock capability to sssd domain. Allow sssd connect to http_cache_t Resolves: rhbz#1362688 - Allow dirsrv to read dirsrv_share_t content Resolves: rhbz#1363662 - Allow virtlogd_t to append svirt_image_t files. Resolves: rhbz#1358140 - Allow hypervkvp domain to read hugetlbfs dir/files. Resolves: rhbz#1349356 - Allow mdadm daemon to read nvme_device_t blk files Resolves: rhbz#1362564 - Allow selinuxusers and unconfineduser to run oddjob_request Resolves: rhbz#1361636 - Allow sshd server to acces to Crypto Express 4 (CEX4) devices. Resolves: rhbz#1362539 - Fix labeling issue in init.fc file. Path /usr/lib/systemd/fedora-* changed to /usr/lib/systemd/rhel-*. Resolves: rhbz#1363769 - Fix typo in device interfaces Resolves: rhbz#1349058 - Add interfaces for managing ipmi devices Resolves: rhbz#1349058 - Add interfaces to allow mounting/umounting tracefs filesystem Resolves: rhbz#1364380 - Add interfaces to allow rw tracefs filesystem Resolves: rhbz#1364380 - Add interface dev_read_nvme() to allow reading Non-Volatile Memory Host Controller devices. Resolves: rhbz#1362564 - Label /sys/kernel/debug/tracing filesystem Resolves: rhbz#1364380 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857- Dontaudit mock_build_t can list all ptys. Resolves: rhbz#1271209 - Allow ftpd_t to mamange userhome data without any boolean. Resolves: rhbz#1097775 - Add logrotate permissions for creating netlink selinux sockets. Resolves: rhbz#1283134 - Allow lsmd_plugin_t to exec ldconfig. Resolves: rhbz#1238066 - Allow vnstatd domain to read /sys/class/net/ files Resolves: rhbz#1358243 - Remove duplicate allow rules in spamassassin SELinux module Resolves:rhbz#1358175 - Allow spamc_t and spamd_t domains create .spamassassin file in user homedirs Resolves:rhbz#1358175 - Allow sshd setcap capability. This is needed due to latest changes in sshd Resolves: rhbz#1357857 - Add new MLS attribute to allow relabeling objects higher than system low. This exception is needed for package managers when processing sensitive data. Resolves: rhbz#1330464 - Allow gnome-keyring also manage user_tmp_t sockets. Resolves: rhbz#1257057 - corecmd: Remove fcontext for /etc/sysconfig/libvirtd Resolves:rhbz#1351382- Allow ipa_dnskey domain to search cache dirs Resolves: rhbz#1350957- Allow ipa-dnskey read system state. Reasolves: rhbz#1350957 - Allow dogtag-ipa-ca-renew-agent-submit labeled as certmonger_t to create /var/log/ipa/renew.log file Resolves: rhbz#1350957- Allow firewalld to manage net_conf_t files. Resolves:rhbz#1304723 - Allow logrotate read logs inside containers. Resolves: rhbz#1303514 - Allow sssd to getattr on fs_t Resolves: rhbz#1356082 - Allow opendnssec domain to manage bind chace files Resolves: rhbz#1350957 - Fix typo in rhsmcertd policy module Resolves: rhbz#1329475 - Allow systemd to get status of systemd-logind daemon Resolves: rhbz#1356141 - Label more ndctl devices not just ndctl0 Resolves: rhbz#1355809- Allow rhsmcertd to copy certs into /etc/docker/cert.d - Add interface docker_rw_config() Resolves: rhbz#1344500 - Fix logrotate fc file to label also /var/lib/logrotate/ dir as logrotate_var_lib_t Resolves: rhbz#1355632 - Allow rhsmcertd to read network sysctls Resolves: rhbz#1329475 - Label /var/log/graphite-web dir as httpd_log_t Resolves: rhbz#1310898 - Allow mock to use generic ptys Resolves: rhbz#1271209 - Allow adcli running as sssd_t to write krb5.keytab file. Resolves: rhbz#1356082 - Allow openvswitch connect to openvswitch_port_t type. Resolves: rhbz#1335024 - Add SELinux policy for opendnssec service. Resolves: rhbz#1350957 - Create new SELinux type for /usr/libexec/ipa/ipa-dnskeysyncd Resolves: rhbz#1350957 - label /dev/ndctl0 device as nvram_device_t Resolves: rhbz#1355809- Allow lttng tools to block suspending Resolves: rhbz#1256374 - Allow creation of vpnaas in openstack Resolves: rhbz#1352710 - virt: add strict policy for virtlogd daemon Resolves:rhbz#1311606 - Update makefile to support snapperd_contexts file Resolves: rhbz#1352681- Allow udev to manage systemd-hwdb files - Add interface systemd_hwdb_manage_config() Resolves: rhbz#1350756 - Fix paths to infiniband devices. This allows use more then two infiniband interfaces. Resolves: rhbz#1210263- Allow virtual machines to rw infiniband devices. Resolves: rhbz#1210263 - Allow opensm daemon to rw infiniband_mgmt_device_t Resolves: rhbz#1210263 - Allow systemd_hwdb_t to relabel /etc/udev/hwdb.bin file. Resolves: rhbz#1350756 - Make label for new infiniband_mgmt deivices Resolves: rhbz#1210263- Fix typo in brltty SELinux module - Add new SELinux module sbd Resolves: rhbz#1322725 - Allow pcp dmcache metrics collection Resolves: rhbz#1309883 - Allow pkcs_slotd_t to create dir in /var/lock Add label pkcs_slotd_log_t Resolves: rhbz#1350782 - Allow openvpn to create sock files labeled as openvpn_var_run_t Resolves: rhbz#1328246 - Allow hypervkvp daemon to getattr on all filesystem types. Resolves: rhbz#1349356 - Allow firewalld to create net_conf_t files Resolves: rhbz#1304723 - Allow mock to use lvm Resolves: rhbz#1271209 - Allow keepalived to create netlink generic sockets. Resolves: rhbz#1349809 - Allow mirromanager creating log files in /tmp Resolves:rhbz#1328818 - Rename few modules to make it consistent with source files Resolves: rhbz#1351445 - Allow vmtools_t to transition to rpm_script domain Resolves: rhbz#1342119 - Allow nsd daemon to manage nsd_conf_t dirs and files Resolves: rhbz#1349791 - Allow cluster to create dirs in /var/run labeled as cluster_var_run_t Resolves: rhbz#1346900 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535 - Dontaudit su_role_template interface to getattr /proc/kcore Dontaudit su_role_template interface to getattr /dev/initctl Resolves: rhbz#1086240 - Add interface lvm_getattr_exec_files() Resolves: rhbz#1271209 - Fix typo Compliling vs. Compiling Resolves: rhbz#1351445- Allow krb5kdc_t to communicate with sssd Resolves: rhbz#1319933 - Allow prosody to bind on prosody ports Resolves: rhbz#1304664 - Add dac_override caps for fail2ban-client Resolves: rhbz#1316678 - dontaudit read access for svirt_t on the file /var/db/nscd/group Resolves: rhbz#1301637 - Allow inetd child process to communicate via dbus with systemd-logind Resolves: rhbz#1333726 - Add label for brltty log file Resolves: rhbz#1328818 - Allow dspam to read the passwd file Resolves: rhbz#1286020 - Allow snort_t to communicate with sssd Resolves: rhbz#1284908 - svirt_sandbox_domains need to be able to execmod for badly built libraries. Resolves: rhbz#1206339 - Add policy for lttng-tools package. Resolves: rhbz#1256374 - Make mirrormanager as application domain. Resolves: rhbz#1328234 - Add support for the default lttng-sessiond port - tcp/5345. This port is used by LTTng 2.x central tracing registry session daemon. - Add prosody ports Resolves: rhbz#1304664 - Allow sssd read also sssd_conf_t dirs Resolves: rhbz#1350535- Label /var/lib/softhsm as named_cache_t. Allow named_t to manage named_cache_t dirs. Resolves:rhbz#1331315 - Label named-pkcs11 binary as named_exec_t. Resolves: rhbz#1331315 - Allow glusterd daemon to get systemd status Resolves: rhbz#1321785 - Allow logrotate dbus-chat with system_logind daemon Resolves: rhbz#1283134 - Allow pcp_pmlogger to read kernel network state Allow pcp_pmcd to read cron pid files Resolves: rhbz#1336211 - Add interface cron_read_pid_files() Resolves: rhbz#1336211 - Allow pcp_pmlogger to create unix dgram sockets Resolves: rhbz#1336211 - Add hwloc-dump-hwdata SELinux policy Resolves: rhbz#1344054 - Remove non-existing jabberd_spool_t() interface and add new jabbertd_var_spool_t. Resolves: rhbz#1121171 - Remove non-existing interface salk_resetd_systemctl() and replace it with sanlock_systemctl_sanlk_resetd() Resolves: rhbz#1259764 - Create label for openhpid log files. esolves: rhbz#1259764 - Label /var/lib/ganglia as httpd_var_lib_t Resolves: rhbz#1260536 - Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Include patch from distgit repo: policy-RHEL-7.1-flask.patch. Resolves: rhbz#1329560 - Update refpolicy to handle hwloc Resolves: rhbz#1344054 - Label /etc/dhcp/scripts dir as bin_t - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255- Allow firewalld_t to create entries in net_conf_t dirs. Resolves: rhbz#1304723 - Allow journalctl to read syslogd_var_run_t files. This allows to staff_t and sysadm_t to read journals Resolves: rhbz#1288255 - Allow mongod log to syslog. Resolves: rhbz#1306995 - Allow rhsmcertd connect to port tcp 9090 Resolves: rhbz#1337319 - Label for /bin/mail(x) was removed but /usr/bin/mail(x) not. This path is also needed to remove. Resolves: rhbz#1262483 Resolves: rhbz#1277506 - Label /usr/libexec/mimedefang-wrapper as spamd_exec_t. Resolves: rhbz#1301516 - Add new boolean spamd_update_can_network. Resolves: rhbz#1305469 - Allow rhsmcertd connect to tcp netport_port_t Resolves: rhbz#1329475 - Fix SELinux context for /usr/share/mirrormanager/server/mirrormanager to Label all binaries under dir as mirrormanager_exec_t. Resolves: rhbz#1328234 - Allow prosody to bind to fac_restore tcp port. Resolves: rhbz#1321787 - Allow ninfod to read raw packets Resolves: rhbz#1317964 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1260835 - Allow pegasus get attributes from qemu binary files. Resolves: rhbz#1271159 - Allow tuned to use policykit. This change is required by cockpit. Resolves: rhbz#1346464 - Allow conman_t to read dir with conman_unconfined_script_t binary files. Resolves: rhbz#1297323 - Allow pegasus to read /proc/sysinfo. Resolves: rhbz#1265883 - Allow sysadm_role to run journalctl_t domain. This allows sysadm user to read journals. Resolves: rhbz#1288255 - Label tcp ports:16379, 26379 as redis_port_t Resolves: rhbz#1348471 - Allow systemd to relabel /var and /var/lib directories during boot. - Add files_relabel_var_dirs() and files_relabel_var_dirs() interfaces. - Add files_relabelto_var_lib_dirs() interface. - Label tcp port 2004 as mailbox_port_t. Resolves: rhbz#1332843 - Label tcp and udp port 5582 as fac_restore_port_t Resolves: rhbz#1321787 - Allow sysadm_t user to run postgresql-setup. Resolves: rhbz#1282543 - Allow sysadm_t user to dbus chat with oddjob_t. This allows confined admin run oddjob mkhomedirfor script. Resolves: rhbz#1297480 - Update netlink socket classes.- Allow conman to kill conman_unconfined_script. Resolves: rhbz#1297323 - Make conman_unconfined_script_t as init_system_domain. Resolves:rhbz#1297323 - Allow init dbus chat with apmd. Resolves:rhbz#995898 - Patch /var/lib/rpm is symlink to /usr/share/rpm on Atomic, due to this change we need to label also /usr/share/rpm as rpm_var_lib_t. Resolves: rhbz#1233252 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Add mediawiki rules to proper scope Resolves: rhbz#1301186 - Dontaudit xguest_gkeyringd_t stream connect to system_dbusd_t Resolves: rhbz#1052880 - Allow mysqld_safe to inherit rlimit information from mysqld Resolves: rhbz#1323673 - Allow collectd_t to stream connect to postgresql. Resolves: rhbz#1344056 - Allow mediawiki-script to read /etc/passwd file. Resolves: rhbz#1301186 - Add filetrans rule that NetworkManager_t can create net_conf_t files in /etc. Resolves: rhbz#1344505 - Add labels for mediawiki123 Resolves: rhbz#1293872 - Fix label for all fence_scsi_check scripts - Allow ip netns to mounton root fs and unmount proc_t fs. Resolves: rhbz#1343776 Resolves: rhbz#1286851 - Allow sysadm_t to run newaliases command. Resolves: rhbz#1344828 - Add interface sysnet_filetrans_named_net_conf() Resolves: rhbz#1344505- Fix several issues related to the SELinux Userspace changes- Allow glusterd domain read krb5_keytab_t files. Resolves: rhbz#1343929 - Fix typo in files_setattr_non_security_dirs. Resolves: rhbz#1115987- Allow tmpreaper_t to read/setattr all non_security_file_type dirs Resolves: rhbz#1115987 - Allow firewalld to create firewalld_var_run_t directory. Resolves: rhbz#1304723 - Add interface firewalld_read_pid_files() Resolves: rhbz#1304723 - Label /usr/libexec/rpm-ostreed as rpm_exec_t. Resolves: rhbz#1340542 - Allow sanlock service to read/write cephfs_t files. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - Add interface files_setattr_non_security_dirs() Resolves: rhbz#1115987 - Add support for onloadfs - Allow iptables to read firewalld pid files. Resolves: rhbz#1304723 - Add SELinux support for ceph filesystem. Resolves: rhbz#1315332 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) Resolves: rhbz#1236580- Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added missing docker interfaces: - docker_typebounds - docker_entrypoint Resolves: rhbz#1236580 - New interfaces needed for systemd-machinectl Resolves: rhbz#1236580 - New interfaces needed by systemd-machine Resolves: rhbz#1236580 - Add interface allowing sending and receiving messages from virt over dbus. Resolves: rhbz#1236580 - Backport docker policy from Fedora. Related: #1303123 Resolves: #1341257 - Allow NetworkManager_t and policykit_t read access to systemd-machined pid files. Resolves: rhbz#1236580 - Fixed to make SELinux work with docker and prctl(NO_NEW_PRIVS) - Added interfaces needed by new docker policy. Related: rhbz#1303123 - Add support for systemd-machined daemon Resolves: rhbz#1236580 - Allow rpm-ostree domain transition to install_t domain from init_t. Resolves: rhbz#1340542- dnsmasq: allow NetworkManager to control dnsmasq via D-Bus Resolves: rhbz#1336722 - Directory Server (389-ds-base) has been updated to use systemd-ask-password. In order to function correctly we need the following added to dirsrv.te Resolves: rhbz#1333198 - sftpd_* booleans are functionless these days. Resolves: rhbz#1335656 - Label /var/log/ganesha.log as gluster_log_t Allow glusterd_t domain to create glusterd_log_t files. Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737 - Label /usr/libexec/storaged/storaged as lvm_exec_t to run storaged daemon in lvm_t SELinux domain. Resolves: rhbz#1264390 - Allow systemd_hostanmed_t to read /proc/sysinfo labeled as sysctl_t. Resolves: rhbz#1337061 - Revert "Allow all domains some process flags." Resolves: rhbz#1303644 - Revert "Remove setrlimit to all domains." Resolves: rhbz#1303644 - Label /usr/sbin/xrdp* files as bin_t Resolves: rhbz#1276777 - Add mls support for some db classes Resolves: rhbz#1303651 - Allow systemd_resolved_t to check if ipv6 is disabled. Resolves: rhbz#1236579 - Allow systemd_resolved to read systemd_networkd run files. Resolves: rhbz#1236579- Allow ganesha-ha.sh script running under unconfined_t domain communicate with glusterd_t domains via dbus. Resolves: rhbz#1336760 - Allow ganesha daemon labeled as glusterd_t create /var/lib/nfs/ganesha dir labeled as var_lib_nfs_t. Resolves: rhbz#1336737- Allow logwatch to domtrans to postqueue Resolves: rhbz#1331542 - Label /var/log/ganesha.log as gluster_log_t - Allow glusterd_t domain to create glusterd_log_t files. - Label /var/run/ganesha.pid as gluster_var_run_t. Resolves: rhbz#1335828 - Allow zabbix to connect to postgresql port Resolves: rhbz#1330479 - Add userdom_destroy_unpriv_user_shared_mem() interface. Related: rhbz#1306403 - systemd-logind remove all IPC objects owned by a user on a logout. This covers also SysV memory. This change allows to destroy unpriviledged user SysV shared memory segments. Resolves: rhbz#1306403- We need to restore contexts on /etc/passwd*,/etc/group*,/etc/*shadow* during install phase to get proper labeling for these files until selinux-policy pkgs are installed. Resolves: rhbz#1333952- Add interface glusterd_dontaudit_read_lib_dirs() Resolves: rhbz#1295680 - Dontaudit Occasionally observing AVC's while running geo-rep automation Resolves: rhbz#1295680 - Allow glusterd to manage socket files labeled as glusterd_brick_t. Resolves: rhbz#1331561 - Create new apache content template for files stored in user homedir. This change is needed to make working booleans: - httpd_enable_homedirs - httpd_read_user_content Resolves: rhbz#1246522 - Allow stunnel create log files. Resolves: rhbz#1296851 - Label tcp port 8181 as intermapper_port_t. Resolves: rhbz#1334783 - Label tcp/udp port 2024 as xinuexpansion4_port_t Resolves: rhbz#1334783 - Label tcp port 7002 as afs_pt_port_t Label tcp/udp port 2023 as xinuexpansion3_port_t Resolves: rhbz#1334783 - Dontaudit ldconfig read gluster lib files. Resolves: rhbz#1295680 - Add interface auth_use_nsswitch() to systemd_domain_template. Resolves: rhbz#1236579- Label /usr/bin/ganesha.nfsd as glusterd_exec_t to run ganesha as glusterd_t. Allow glusterd_t stream connect to rpbind_t. Allow cluster_t to create symlink /var/lib/nfs labeled as var_lib_nfs_t. Add interface rpc_filetrans_var_lib_nfs_content() Add new boolean: rpcd_use_fusefs to allow rpcd daemon use fusefs. Resolves: rhbz#1312809 Resolves: rhbz#1323947 - Allow dbus chat between httpd_t and oddjob_t. Resolves: rhbz#1324144 - Label /usr/libexec/ipa/oddjob/org.freeipa.server.conncheck as ipa_helper_exec_t. Resolves: rhbz#1324144 - Label /var/log/ipareplica-conncheck.log file as ipa_log_t Allow ipa_helper_t domain to manage logs labeledas ipa_log_t Allow ipa_helper_t to connect on http and kerberos_passwd ports. Resolves: rhbz#1324144 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow pcp_pmcd_t domain to manage docker lib files. This rule is needed to allow pcp to collect container information when SELinux is enabled. Resolves: rhbz#1309454- Allow runnig php7 in fpm mode. From selinux-policy side, we need to allow httpd to read/write hugetlbfs. Resolves: rhbz#1319442 - Allow openvswitch daemons to run under openvswitch Linux user instead of root. This change needs allow set capabilities: chwon, setgid, setuid, setpcap. Resolves: rhbz#1296640 - Remove ftpd_home_dir() boolean from distro policy. Reason is that we cannot make this working due to m4 macro language limits. Resolves: rhbz#1097775 - /bin/mailx is labeled sendmail_exec_t, and enters the sendmail_t domain on execution. If /usr/sbin/sendmail does not have its own domain to transition to, and is not one of several products whose behavior is allowed by the sendmail_t policy, execution will fail. In this case we need to label /bin/mailx as bin_t. Resolves: rhbz#1262483 - Allow nsd daemon to create log file in /var/log as nsd_log_t Resolves: rhbz#1293140 - Sanlock policy update. - New sub-domain for sanlk-reset daemon Resolves: rhbz#1212324 - Label all run tgtd files, not just socket files Resolves: rhbz#1280280 - Label all run tgtd files, not just socket files. Resolves: rhbz#1280280 - Allow prosody to stream connect to sasl. This will allow using cyrus authentication in prosody. Resolves: rhbz#1321049 - unbound wants to use ephemeral ports as a default configuration. Allow to use also udp sockets. Resolves: rhbz#1318224 - Allow prosody to listen on port 5000 for mod_proxy65. Resolves: rhbz#1316918 - Allow targetd to read/write to /dev/mapper/control device. Resolves: rhbz#1063714 - Allow KDM to get status about power services. This change allow kdm to be able do shutdown. Resolves: rhbz#1316724 - Allow systemd-resolved daemon creating netlink_route sockets. Resolves:rhbz#1236579 - Allow systemd_resolved_t to read /etc/passwd file. Allow systemd_resolved_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used Resolves: rhbz#1065362 - Label /etc/selinux/(minimum|mls|targeted)/active/ as semanage_store_t Resolves: rhbz#1321943 - Label all nvidia binaries as xserver_exec_t Resolves: rhbz#1322283- Create new permissivedomains CIL module and make it active. Resolves: rhbz#1320451 - Add support for new mock location - /usr/libexec/mock/mock. Resolves: rhbz#1271209 - Allow bitlee to create bitlee_var_t dirs. Resolves: rhbz#1268651 - Allow CIM provider to read sssd public files. Resolves: rhbz#1263339 - Fix some broken interfaces in distro policy. Resolves: rhbz#1121171 - Allow power button to shutdown the laptop. Resolves: rhbz#995898 - Allow lsm plugins to create named fixed disks. Resolves: rhbz#1238066 - Add default labeling for /etc/Pegasus/cimserver_current.conf. It is a correct patch instead of the current /etc/Pegasus/pegasus_current.confResolves: rhbz#1278777 - Allow hyperv domains to rw hyperv devices. Resolves: rhbz#1309361 - Label /var/www/html(/.*)?/wp_backups(/.*)? as httpd_sys_rw_content_t.Resolves: rhbz#1246780 - Create conman_unconfined_script_t type for conman script stored in /use/share/conman/exec/ Resolves: rhbz#1297323 - Fix rule definitions for httpd_can_sendmail boolean. We need to distinguish between base and contrib. - Add support for /dev/mptctl device used to check RAID status. Resolves: rhbz#1258029 - Create hyperv* devices and create rw interfaces for this devices. Resolves: rhbz#1309361 - Add fixes for selinux userspace moving the policy store to /var/lib/selinux. - Remove optional else block for dhcp ping- Allow rsync_export_all_ro boolean to read also non_auth_dirs/files/symlinks. Resolves: rhbz#1263770 - Fix context of "/usr/share/nginx/html". Resolves: rhbz#1261857 - Allow pmdaapache labeled as pcp_pmcd_t access to port 80 for apache diagnostics Resolves: rhbz#1270344 - Allow pmlogger to create pmlogger.primary.socket link file. Resolves: rhbz#1270344 - Label nagios scripts as httpd_sys_script_exec_t. Resolves: rhbz#1260306 - Add dontaudit interface for kdumpctl_tmp_t Resolves: rhbz#1156442 - Allow mdadm read files in EFI partition. Resolves: rhbz#1291801 - Allow nsd_t to bind on nsf_control tcp port. Allow nsd_crond_t to read nsd pid. Resolves: rhbz#1293140 - Label some new nsd binaries as nsd_exec_t Allow nsd domain net_admin cap. Create label nsd_tmp_t for nsd tmp files/dirs Resolves: rhbz#1293140 - Add filename transition that /etc/princap will be created with cupsd_rw_etc_t label in cups_filetrans_named_content() interface. Resolves: rhbz#1265102 - Add missing labeling for /usr/libexec/abrt-hook-ccpp. Resolves: rhbz#1213409 - Allow pcp_pmie and pcp_pmlogger to read all domains state. Resolves: rhbz#1206525 - Label /etc/redis-sentinel.conf as redis_conf_t. Allow redis_t write to redis_conf_t. Allow redis_t to connect on redis tcp port. Resolves: rhbz#1275246 - cockpit has grown content in /var/run directory Resolves: rhbz#1279429 - Allow collectd setgid capability Resolves:#1310898 - Remove declaration of empty booleans in virt policy. Resolves: rhbz#1103153 - Fix typo in drbd policy - Add new drbd file type: drbd_var_run_t. Allow drbd_t to manage drbd_var_run_t files/dirs. Allow drbd_t create drbd_tmp_t files in /tmp. Resolves: rhbz#1134883 - Label /etc/ctdb/events.d/* as ctdb_exec_t. Allow ctdbd_t to setattr on ctdbd_exec_t files. Resolves: rhbz#1293788 - Allow abrt-hook-ccpp to get attributes of all processes because of core_pattern. Resolves: rhbz#1254188 - Allow abrt_t to read sysctl_net_t files. Resolves: rhbz#1254188 - The ABRT coredump handler has code to emulate default core file creation The handler runs in a separate process with abrt_dump_oops_t SELinux process type. abrt-hook-ccpp also saves the core dump file in the very same way as kernel does and a user can specify CWD location for a coredump. abrt-hook-ccpp has been made as a SELinux aware apps to create this coredumps with correct labeling and with this commit the policy rules have been updated to allow access all non security files on a system. - Allow abrt-hook-ccpp to getattr on all executables. - Allow setuid/setgid capabilities for abrt-hook-ccpp. Resolves: rhbz#1254188 - abrt-hook-ccpp needs to have setfscreate access because it is SELinux aware and compute a target labeling. Resolves: rhbz#1254188 - Allow abrt-hook-ccpp to change SELinux user identity for created objects. Resolves: rhbz#1254188 - Dontaudit write access to inherited kdumpctl tmp files. Resolves: rbhz#1156442 - Add interface to allow reading files in efivarfs - contains Linux Kernel configuration options for UEFI systems (UEFI Runtime Variables) Resolves: rhbz#1291801 - Label 8952 tcp port as nsd_control. Resolves: rhbz#1293140 - Allow ipsec to use pam. Resolves: rhbz#1315700 - Allow to log out to gdm after screen was resized in session via vdagent. Resolves: rhbz#1249020 - Allow setrans daemon to read /proc/meminfo. Resolves: rhbz#1316804 - Allow systemd_networkd_t to write kmsg, when kernel was started with following params: systemd.debug systemd.log_level=debug systemd.log_target=kmsg Resolves: rhbz#1298151 - Label tcp port 5355 as llmnr-> Link-Local Multicast Name Resolution Resolves: rhbz#1236579 - Add new selinux policy for systemd-resolved dawmon. Resolves: rhbz#1236579 - Add interface ssh_getattr_server_keys() interface. Resolves: rhbz#1306197 - Allow run sshd-keygen on second boot if first boot fails after some reason and content is not syncedon the disk. These changes are reflecting this commit in sshd. http://pkgs.fedoraproject.org/cgit/rpms/openssh.git/commit/?id=af94f46861844cbd6ba4162115039bebcc8f78ba rhbz#1299106 Resolves: rhbz#1306197 - Allow systemd_notify_t to write to kmsg_device_t when 'systemd.log_target=kmsg' option is used. Resolves: rhbz#1309417 - Remove bin_t label for /etc/ctdb/events.d/. We need to label this scripts as ctdb_exec_t. Resolves: rhbz#1293788- Prepare selinux-policy package for userspace release 2016-02-23. Resolves: rhbz#1305982- Allow sending dbus msgs between firewalld and system_cronjob domains. Resolves: rhbz#1284902 - Allow zabbix-agentd to connect to following tcp sockets. One of zabbix-agentd functions is get service status of ftp,http,innd,pop,smtp protocols. Resolves: rhbz#1242506 - Add new boolean tmpreaper_use_cifs() to allow tmpreaper to run on local directories being shared with Samba. Resolves: rhbz#1284972 - Add support for systemd-hwdb daemon. Resolves: rhbz#1257940 - Add interface fs_setattr_cifs_dirs(). Resolves: rhbz#1284972- Add new SELinux policy fo targetd daemon. Resolves: rhbz#1063714 - Add new SELinux policy fo ipmievd daemon. Resolves: rhbz#1083031 - Add new SELinux policy fo hsqldb daemon. Resolves: rhbz#1083171 - Add new SELinux policy for blkmapd daemon. Resolves: rhbz#1072997 - Allow p11-child to connect to apache ports. - Label /usr/sbin/lvmlockd binary file as lvm_exec_t. Resolves: rhbz#1278028 - Add interface "lvm_manage_lock" to lvm policy. Resolves: rhbz#1063714- Allow openvswitch domain capability sys_rawio. Resolves: rhbz#1278495- Allow openvswitch to manage hugetlfs files and dirs. Resolves: rhbz#1278495 - Add fs_manage_hugetlbfs_files() interface. Resolves: rhbz#1278495- Allow smbcontrol domain to send sigchld to ctdbd domain. Resolves: #1293784 - Allow openvswitch read/write hugetlb filesystem. Resolves: #1278495Allow hypervvssd to list all mountpoints to have VSS live backup working correctly. Resolves:#1247880- Revert Add missing labeling for /usr/libexec/abrt-hook-ccpp patch Resolves: #1254188- Allow search dirs in sysfs types in kernel_read_security_state. Resolves: #1254188 - Fix kernel_read_security_state interface that source domain of this interface can search sysctl_fs_t dirs. Resolves: #1254188- Add missing labeling for /usr/libexec/abrt-hook-ccpp as a part of #1245477 and #1242467 bugs Resolves: #1254188 - We need allow connect to xserver for all sandbox_x domain because we have one type for all sandbox processes. Resolves:#1261938- Remove labeling for modules_dep_t file contexts to have labeled them as modules_object_t. - Update files_read_kernel_modules() to contain modutils_read_module_deps_files() calling because module deps labeling could remain and it allows to avoid regressions. Resolves:#1266928- We need to require sandbox_web_type attribute in sandbox_x_domain_template(). Resolves: #1261938 - ipsec: The NM helper needs to read the SAs Resolves: #1259786 - ipsec: Allow ipsec management to create ptys Resolves: #1259786- Add temporary fixes for sandbox related to #1103622. It allows to run everything under one sandbox type. Resolves:#1261938 - Allow abrt_t domain to write to kernel msg device. Resolves: #1257828 - Allow rpcbind_t domain to change file owner and group Resolves: #1265266- Allow smbcontrol to create a socket in /var/samba which uses for a communication with smbd, nmbd and winbind. Resolves: #1256459- Allow dirsrv-admin script to read passwd file. Allow dirsrv-admin script to read httpd pid files. Label dirsrv-admin unit file and allow dirsrv-admin domains to use it. Resolves: #1230300 - Allow qpid daemon to connect on amqp tcp port. Resolves: #1261805- Label /etc/ipa/nssdb dir as cert_t Resolves:#1262718 - Do not provide docker policy files which is shipped by docker-selinux.rpm Resolves:#1262812- Add labels for afs binaries: dafileserver, davolserver, salvageserver, dasalvager Resolves: #1192338 - Add lsmd_plugin_t sys_admin capability, Allow lsmd_plugin_t getattr from sysfs filesystem. Resolves: #1238079 - Allow rhsmcertd_t send signull to unconfined_service_t domains. Resolves: #1176078 - Remove file transition from snmp_manage_var_lib_dirs() interface which created snmp_var_lib_t dirs in var_lib_t. - Allow openhpid_t daemon to manage snmp files and dirs. Resolves: #1243902 - Allow mdadm_t domain read/write to general ptys and unallocated ttys. Resolves: #1073314 - Add interface unconfined_server_signull() to allow domains send signull to unconfined_service_t Resolves: #1176078- Allow systemd-udevd to access netlink_route_socket to change names for network interfaces without unconfined.pp module. It affects also MLS. Resolves:#1250456- Fix labeling for fence_scsi_check script Resolves: #1255020 - Allow openhpid to read system state Allow openhpid to connect to tcp http port. Resolves: #1244248 - Allow openhpid to read snmp var lib files. Resolves: #1243902 - Allow openvswitch_t domains read kernel dependencies due to openvswitch run modprobe - Allow unconfined_t domains to create /var/run/xtables.lock with iptables_var_run_t Resolves: #1243403 - Remove bin_t label for /usr/share/cluster/fence_scsi_check\.pl Resolves: #1255020- Fix regexp in chronyd.fc file Resolves: #1243764 - Allow passenger to getattr filesystem xattr Resolves: #1196555 - Label mdadm.conf.anackbak as mdadm_conf_t file. Resolves: #1088904 - Revert "Allow pegasus_openlmi_storage_t create mdadm.conf.anacbak file in /etc." - Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Remove labeling for /var/db/.*\.db as etc_t to label db files as system_db_t. Resolves: #1230877- Allow watchdog execute fenced python script. Resolves: #1255020 - Added inferface watchdog_unconfined_exec_read_lnk_files() - Label /var/run/chrony-helper dir as chronyd_var_run_t. Resolves: #1243764 - Allow dhcpc_t domain transition to chronyd_t Resolves: #1243764- Fix postfix_spool_maildrop_t,postfix_spool_flush_t contexts in postfix.fc file. Resolves: #1252442- Allow exec pidof under hypervkvp domain. Resolves: #1254870 - Allow hypervkvp daemon create connection to the system DBUS Resolves: #1254870- Allow openhpid_t to read system state. Resolves: #1244248 - Added labels for files provided by rh-nginx18 collection Resolves: #1249945 - Dontaudit block_suspend capability for ipa_helper_t, this is kernel bug. Allow ipa_helper_t capability net_admin. Allow ipa_helper_t to list /tmp. Allow ipa_helper_t to read rpm db. Resolves: #1252968 - Allow rhsmcertd exec rhsmcertd_var_run_t files and rhsmcerd_tmp_t files. This rules are in hide_broken_sympthons until we find better solution. Resolves: #1243431 - Allow abrt_dump_oops_t to read proc_security_t files. - Allow abrt_dump_oops to signull all domains Allow abrt_dump_oops to read all domains state Allow abrt_dump_oops to ptrace all domains - Add interface abrt_dump_oops_domtrans() - Add mountpoint dontaudit access check in rhsmcertd policy. Resolves: #1243431 - Allow samba_net_t to manage samba_var_t sock files. Resolves: #1252937 - Allow chrome setcap to itself. Resolves: #1251996 - Allow httpd daemon to manage httpd_var_lib_t lnk_files. Resolves: #1253706 - Allow chronyd exec systemctl Resolves: #1243764 - Add inteface chronyd_signal Allow timemaster_t send generic signals to chronyd_t. Resolves: #1243764 - Added interface fs_dontaudit_write_configfs_dirs - Add label for kernel module dep files in /usr/lib/modules Resolves:#916635 - Allow kernel_t domtrans to abrt_dump_oops_t - Added to files_dontaudit_write_all_mountpoints intefface new dontaudit rule, that domain included this interface dontaudit capability dac_override. - Allow systemd-networkd to send logs to systemd-journald. Resolves: #1236616- Fix label on /var/tmp/kiprop_0 Resolves:#1220763 - Allow lldpad_t to getattr tmpfs_t. Resolves: #1246220 - Label /dev/shm/lldpad.* as lldapd_tmpfs_t Resolves: #1246220 - Allow audisp client to read system state.- Allow pcp_domain to manage pcp_var_lib_t lnk_files. Resolves: #1252341 - Label /var/run/xtables.* as iptables_var_run_t Resolves: #1243403- Add interface to read/write watchdog device - Add labels for /dev/memory_bandwith and /dev/vhci. Thanks ssekidde Resolves:#1210237 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow logrotate to reload services. Resolves: #1242453 - Allow openhpid use libwatchdog plugin. (Allow openhpid_t rw watchdog device) Resolves: #1244260 - Allow openhpid liboa_soap plugin to read generic certs. Resolves: #1244248 - Allow openhpid liboa_soap plugin to read resolv.conf file. Resolves: #1244248 - Label /usr/libexec/chrony-helper as chronyd_exec_t - Allow chronyd_t to read dhcpc state. - Allow chronyd to execute mkdir command.- Allow mdadm to access /dev/random and add support to create own files/dirs as mdadm_tmpfs_t. Resolves:#1073314 - Allow udev, lvm and fsadm to access systemd-cat in /var/tmp/dracut if 'dracut -fv' is executed in MLS. - Allow admin SELinu users to communicate with kernel_t. It is needed to access /run/systemd/journal/stdout if 'dracut -vf' is executed. We allow it for other SELinux users. - Allow sysadm to execute systemd-sysctl in the sysadm_t domain. It is needed for ifup command in MLS mode. - Add fstools_filetrans_named_content_fsadm() and call it for named_filetrans_domain domains. We need to be sure that /run/blkid is created with correct labeling. Resolves:#1183503 - Add support for /etc/sanlock which is writable by sanlock daemon. Resolves:#1231377 - Allow useradd add homedir located in /var/lib/kdcproxy in ipa-server RPM scriplet. Resolves:#1243775 - Allow snapperd to pass data (one way only) via pipe negotiated over dbus Resolves:#1250550 - Allow lsmd also setuid capability. Some commands need to executed under root privs. Other commands are executed under unprivileged user.- Allow openhpid to use libsnmp_bc plugin (allow read snmp lib files). Resolves: #1243902 - Allow lsm_plugin_t to read sysfs, read hwdata, rw to scsi_generic_device Resolves: #1238079 - Allow lsm_plugin_t to rw raw_fixed_disk. Resolves:#1238079 - Allow rhsmcertd to send signull to unconfined_service.- Allow httpd_suexec_t to read and write Apache stream sockets Resolves: #1243569 - Allow qpid to create lnk_files in qpid_var_lib_t Resolves: #1247279- Allow drbd to get attributes from filesystems. - Allow redis to read kernel parameters. Resolves: #1209518 - Allow virt_qemu_ga_t domtrans to passwd_t - Allow audisp_remote_t to start power unit files domain to allow halt system. Resolves: #1186780 - Allow audisp_remote_t to read/write user domain pty. Resolves: #1186780 - Label /usr/sbin/chpasswd as passwd_exec_t. - Allow sysadm to administrate ldap environment and allow to bind ldap port to allow to setup an LDAP server (389ds). Resolves:#1221121- gnome_dontaudit_search_config() needs to be a part of optinal_policy in pegasus.te - Allow pcp_pmcd daemon to read postfix config files. - Allow pcp_pmcd daemon to search postfix spool dirs. Resolves: #1213740 - Added Booleans: pcp_read_generic_logs. Resolves: #1213740 - Allow drbd to read configuration options used when loading modules. Resolves: #1134883 - Allow glusterd to manage nfsd and rpcd services. - Allow glusterd to communicate with cluster domains over stream socket. - glusterd call pcs utility which calls find for cib.* files and runs pstree under glusterd. Dontaudit access to security files and update gluster boolean to reflect these changes.- Allow glusterd to manage nfsd and rpcd services. - Allow networkmanager to communicate via dbus with systemd_hostanmed. Resolves: #1234954 - Allow stream connect logrotate to prosody. - Add prosody_stream_connect() interface. - httpd should be able to send signal/signull to httpd_suexec_t, instead of httpd_suexec_exec_t. - Allow prosody to create own tmp files/dirs. Resolves:#1212498- Allow networkmanager read rfcomm port. Resolves:#1212498 - Remove non exists label. - Fix *_admin intefaces where body is not consistent with header. - Label /usr/afs/ as afs_files_t, Allow afs_bosserver_t create afs_config_t and afs_dbdir_t dirs under afs_files_t, Allow afs_bosserver_t read kerberos config - Remove non exits nfsd_ro_t label. - Make all interfaces related to openshift_cache_t as deprecated. - Add rpm_var_run_t label to rpm_admin header - Add jabberd_lock_t label to jabberd_admin header. - Add samba_unconfined_script_exec_t to samba_admin header. - inn daemon should create innd_log_t objects in var_log_t instead of innd_var_run_t - Fix ctdb policy - Add samba_signull_winbind() - Add samba_signull_unconfined_net() - Allow ctdbd_t send signull to samba_unconfined_net_t. - Allow openshift_initrc_t to communicate with firewalld over dbus Resolves:#1221326- Allow gluster to connect to all ports. It is required by random services executed by gluster. - Add interfaces winbind_signull(), samba_unconfined_net_signull(). - Dontaudit smbd_t block_suspend capability. This is kernel bug. - Allow ctdbd sending signull to process winbind, samba_unconfined_net, to checking if processes exists. - Add tmpreaper booleans to use nfs_t and samba_share_t. - Fix path from /usr/sbin/redis-server to /usr/bin/redis-server - Allow connect ypserv to portmap_port_t - Fix paths in inn policy, Allow innd read innd_log_t dirs, Allow innd execute innd_etc_t files - Add support for openstack-nova-* packages - Allow NetworkManager_t send signull to dnssec_trigger_t. - Allow glusterd to execute showmount in the showmount domain. - Label swift-container-reconciler binary as swift_t. - Allow dnssec_trigger_t relabelfrom dnssec_trigger_var_run_t files. - Add cobbler_var_lib_t to "/var/lib/tftpboot/boot(/.*)?" Resolves:#1213540 - Merge all nova_* labels under one nova_t.- Add logging_syslogd_run_nagios_plugins boolean for rsyslog to allow transition to nagios unconfined plugins Resolves:#1233550 - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/ - Add support for oddjob based helper in FreeIPA. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add nagios_domtrans_unconfined_plugins() interface. - Update mta_filetrans_named_content() interface to cover more db files. Resolves:#1167468 - Add back ftpd_use_passive_mode boolean with fixed description. - Allow pmcd daemon stream connect to mysqld. - Allow pcp domains to connect to own process using unix_stream_socket. Resolves:#1213709 - Allow abrt-upload-watch service to dbus chat with ABRT daemon and fsetid capability to allow run reporter-upload correctly. - Add new boolean - httpd_run_ipa to allow httpd process to run IPA helper and dbus chat with oddjob. - Add support for oddjob based helper in FreeIPA. - Allow dnssec_trigger_t create dnssec_trigger_tmp_t files in /var/tmp/- Allow iptables to read ctdbd lib files. Resolves:#1224879 - Add systemd_networkd_t to nsswitch domains. - Allow drbd_t write to fixed_disk_device. Reason: drbdmeta needs write to fixed_disk_device during initialization. Resolves:#1130675 - Allow NetworkManager write to sysfs. - Fix cron_system_cronjob_use_shares boolean to call fs interfaces which contain only entrypoint permission. - Add cron_system_cronjob_use_shares boolean to allow system cronjob to be executed from shares - NFS, CIFS, FUSE. It requires "entrypoint" permissios on nfs_t, cifs_t and fusefs_t SELinux types. - Allow NetworkManager write to sysfs. - Allow ctdb_t sending signull to smbd_t, for checking if smbd process exists. - Dontaudit apache to manage snmpd_var_lib_t files/dirs. - Add interface snmp_dontaudit_manage_snmp_var_lib_files(). - Dontaudit mozilla_plugin_t cap. sys_ptrace. - Rename xodbc-connect port to xodbc_connect - Allow ovsdb-server to connect on xodbc-connect and ovsdb tcp ports. - Allow iscsid write to fifo file kdumpctl_tmp_t. Appears when kdump generates the initramfs during the kernel boot. - Dontaudit chrome to read passwd file. - nrpe needs kill capability to make gluster moniterd nodes working. Resolves:#1235587- We allow can_exec() on ssh_keygen on gluster. But there is a transition defined by init_initrc_domain() because we need to allow execute unconfined services by glusterd. So ssh-keygen ends up with ssh_keygen_t and we need to allow to manage /var/lib/glusterd/geo-replication/secret.pem. - Allow sshd to execute gnome-keyring if there is configured pam_gnome_keyring.so. - Allow gnome-keyring executed by passwd to access /run/user/UID/keyring to change a password. - Label gluster python hooks also as bin_t. - Allow glusterd to interact with gluster tools running in a user domain - Add glusterd_manage_lib_files() interface. - ntop reads /var/lib/ntop/macPrefix.db and it needs dac_override. It has setuid/setgid. - Allow samba_t net_admin capability to make CIFS mount working. - S30samba-start gluster hooks wants to search audit logs. Dontaudit it. Resolves:#1224879- Allow glusterd to send generic signals to systemd_passwd_agent processes. - Allow glusterd to access init scripts/units without defined policy - Allow glusterd to run init scripts. - Allow glusterd to execute /usr/sbin/xfs_dbin glusterd_t domain. Resolves:#1224879- Calling cron_system_entry() in pcp_domain_template needs to be a part of optional_policy block. - Allow samba-net to access /var/lib/ctdbd dirs/files. - Allow glusterd to send a signal to smbd. - Make ctdbd as home manager to access also FUSE. - Allow glusterd to use geo-replication gluster tool. - Allow glusterd to execute ssh-keygen. - Allow glusterd to interact with cluster services. - Allow glusterd to connect to the system DBUS for service (acquire_svc). - Label /dev/log correctly. Resolves:#1230932- Back port the latest F22 changes to RHEL7. It should fix most of RHEL7.2 bugs - Add cgdcbxd policy Resolves:#1072493 - Fix ftp_homedir boolean Resolve:#1097775 - Dontaudit ifconfig writing inhertited /var/log/pluto.log. - Allow cluster domain to dbus chat with systemd-logind. Resolves:#1145215 - Dontaudit write access to inherited kdumpctl tmp files Resolves:#1156442 - Allow isnsd_t to communicate with sssd Resolves:#1167702 - Allow rwho_t to communicate with sssd Resolves:#1167718 - Allow sblim_gatherd_t to communicate with sssd Resolves:#1167732 - Allow pkcs_slotd_t to communicate with sssd Resolves:#1167737 - Allow openvswitch_t to communicate with sssd Resolves:#1167816 - Allow mysqld_safe_t to communicate with sssd Resolves:#1167832 - Allow sshd_keygen_t to communicate with sssd Resolves:#1167840 - Add support for iprdbg logging files in /var/log. Resolves:#1174363 - Allow tmpreaper_t to manage ntp log content Resolves:#1176965 - Allow gssd_t to manage ssh keyring Resolves:#1184791 - Allow httpd_sys_script_t to send system log messages Resolves:#1185231 - Allow apcupsd_t to read /sys/devices Resolves:#1189185 - Allow dovecot_t sys_resource capability Resolves:#1191143 - Add support for mongod/mongos systemd unit files. Resolves:#1197038 - Add bacula fixes - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. Resolves:#1203991- Label /usr/libexec/postgresql-ctl as postgresql_exec_t. - Add more restriction on entrypoint for unconfined domains. - Only allow semanage_t to be able to setenforce 0, no all domains that use selinux_semanage interface - Allow all domains to read /dev/urandom. It is needed by all apps/services linked to libgcrypt. There is no harm to allow it by default. - Update policy/mls for sockets related to access perm. Rules were contradictory. - Add nagios_run_pnp4nagios and nagios_run_sudo booleans to allow r un sudo from NRPE utils scripts and allow run nagios in conjunction w ith PNP4Nagios. Resolves:#1201054 - Don't use deprecated userdom_manage_tmpfs_role() interface calliing and use userdom_manage_tmp_role() instead. - Update virt_read_pid_files() interface to allow read also symlinks with virt_var_run_t type - Label /var/lib/tftpboot/aarch64(/.*)? and /var/lib/tftpboot/images2(/.*)? - Add support for iprdbg logging files in /var/log. - Add fixes to rhsmcertd_t - Allow puppetagent_t to transfer firewalld messages over dbus - Add support for /usr/libexec/mongodb-scl-helper RHSCL helper script. - Added label mysqld_etc_t for /etc/my.cnf.d/ dir. - Add support for mongod/mongos systemd unit files. - cloudinit and rhsmcertd need to communicate with dbus - Allow dovecot_t sys_resource capability- ALlow mongod execmem by default. - Update policy/mls for sockets. Rules were contradictory. Resolves:#1207133 - Allow a user to login with different security level via ssh.- Update seutil_manage_config() interface. Resolves:#1185962 - Allow pki-tomcat relabel pki_tomcat_etc_rw_t. - Turn on docker_transition_unconfined by default- Allow virtd to list all mountpoints. Resolves:#1180713- pkcsslotd_lock_t should be an alias for pkcs_slotd_lock_t. - Allow fowner capability for sssd because of selinux_child handling. - ALlow bind to read/write inherited ipsec pipes - Allow hypervkvp to read /dev/urandom and read addition states/config files. - Allow gluster rpm scripletto create glusterd socket with correct labeling. This is a workaround until we get fix in glusterd. - Add glusterd_filetrans_named_pid() interface - Allow radiusd to connect to radsec ports. - Allow setuid/setgid for selinux_child - Allow lsmd plugin to connect to tcp/5988 by default. - Allow lsmd plugin to connect to tcp/5989 by default. - Update ipsec_manage_pid() interface. Resolves:#1184978- Update ipsec_manage_pid() interface. Resolves:#1184978- Allow ntlm_auth running in winbind_helper_t to access /dev/urandom.- Add auditing support for ipsec. Resolves:#1182524 - Label /ostree/deploy/rhel-atomic-host/deploy directory as system_conf_t - Allow netutils chown capability to make tcpdump working with -w- Allow ipsec to execute _updown.netkey script to run unbound-control. - Allow neutron to read rpm DB. - Add additional fixes for hyperkvp * creates new ifcfg-{name} file * Runs hv_set_ifconfig.sh, which does the following * Copies ifcfg-{name} to /etc/sysconfig/network-scripts - Allow svirt to read symbolic links in /sys/fs/cgroups labeled as tmpfs_t - Add labeling for pacemaker.log. - Allow radius to connect/bind radsec ports. - Allow pm-suspend running as virt_qemu_ga to read /var/log/pm-suspend.log - Allow virt_qemu_ga to dbus chat with rpm. - Update virt_read_content() interface to allow read also char devices. - Allow glance-registry to connect to keystone port. Resolves:#1181818- Allow sssd to send dbus all user domains. Resolves:#1172291 - Allow lsm plugin to read certificates. - Fix labeling for keystone CGI scripts. - Make snapperd back as unconfined domain.- Fix bugs in interfaces discovered by sepolicy. - Allow slapd to read /usr/share/cracklib/pw_dict.hwm. - Allow lsm plugins to connect to tcp/18700 by default. - Allow brltty mknod capability to allow create /var/run/brltty/vcsa. - Fix pcp_domain_template() interface. - Fix conman.te. - Allow mon_fsstatd to read /proc/sys/fs/binfmt_misc - Allow glance-scrubber to connect tcp/9191. - Add missing setuid capability for sblim-sfcbd. - Allow pegasus ioctl() on providers. - Add conman_can_network. - Allow chronyd to read chrony conf files located in /run/timemaster/. - Allow radius to bind on tcp/1813 port. - dontaudit block suspend access for openvpn_t - Allow conman to create files/dirs in /tmp. - Update xserver_rw_xdm_keys() interface to have 'setattr'. Resolves:#1172291 - Allow sulogin to read /dev/urandom and /dev/random. - Update radius port definition to have also tcp/18121 - Label prandom as random_device_t. - Allow charon to manage files in /etc/strongimcv labeled as ipsec_conf_t.- Allow virt_qemu_ga_t to execute kmod. - Add missing files_dontaudit_list_security_dirs() for smbd_t in samba_export_all_ro boolean. - Add additionnal MLS attribute for oddjob_mkhomedir to create homedirs. Resolves:#1113725 - Enable OpenStack cinder policy - Add support for /usr/share/vdsm/daemonAdapter - Add support for /var/run/gluster- Remove old pkcsslotd.pp from minimum package - Allow rlogind to use also rlogin ports. - Add support for /usr/libexec/ntpdate-wrapper. Label it as ntpdate_exec_t. - Allow bacula to connect also to postgresql. - Label /usr/libexec/tomcat/server as tomcat_exec_t - Add support for /usr/sbin/ctdbd_wrapper - Add support for /usr/libexec/ppc64-diag/rtas_errd - Allow rpm_script_roles to access system_mail_t - Allow brltty to create /var/run/brltty - Allow lsmd plugin to access netlink_route_socket - Allow smbcontrol to read passwd - Add support for /usr/libexec/sssd/selinux_child and create sssd_selinux_manager_t domain for it Resolves:#1140106 - Allow osad to execute rhn_check - Allow load_policy to rw inherited sssd pipes because of selinux_child - Allow admin SELinux users mounting / as private within a new mount namespace as root in MLS - Add additional fixes for su_restricted_domain_template to make moving to sysadm_r and trying to su working correctly - Add additional booleans substitions- Add seutil_dontaudit_access_check_semanage_module_store() interface Resolves:#1140106 - Update to have all _systemctl() interface also init_reload_services(). - Dontaudit access check on SELinux module store for sssd. - Add labeling for /sbin/iw. - Allow named_filetrans_domain to create ibus directory with correct labeling.- Allow radius to bind tcp/1812 radius port. - Dontaudit list user_tmp files for system_mail_t. - Label virt-who as virtd_exec_t. - Allow rhsmcertd to send a null signal to virt-who running as virtd_t. - Add missing alias for _content_rw_t. Resolves:#1089177 - Allow spamd to access razor-agent.log. - Add fixes for sfcb from libvirt-cim TestOnly bug. - Allow NetworkManager stream connect on openvpn. - Make /usr/bin/vncserver running as unconfined_service_t. - getty_t should be ranged in MLS. Then also local_login_t runs as ranged domain. - Label /etc/docker/certs.d as cert_t.- Label /etc/strongimcv as ipsec_conf_file_t. - Add support for /usr/bin/start-puppet-ca helper script Resolves:#1160727 - Allow rpm scripts to enable/disable transient systemd units. Resolves:#1154613 - Make kpropdas nsswitch domain Resolves:#1153561 - Make all glance domain as nsswitch domains Resolves:#1113281 - Allow selinux_child running as sssd access check on /etc/selinux/targeted/modules/active - Allow access checks on setfiles/load_policy/semanage_lock for selinux_child running as sssd_t Resolves:#1140106- Dontaudit access check on setfiles/load_policy for sssd_t. Resolves:#1140106 - Add kdump_rw_inherited_kdumpctl_tmp_pipes() Resolves:#1156442 - Make linuxptp services as unconfined. - Added new policy linuxptp. Resolves:#1149693 - Label keystone cgi files as keystone_cgi_script_exec_t. Resolves:#1138424 - Make tuned as unconfined domain- Allow guest to connect to libvirt using unix_stream_socket. - Allow all bus client domains to dbus chat with unconfined_service_t. - Allow inetd service without own policy to run in inetd_child_t which is unconfined domain. - Make opensm as nsswitch domain to make it working with sssd. - Allow brctl to read meminfo. - Allow winbind-helper to execute ntlm_auth in the caller domain. Resolves:#1160339 - Make plymouthd as nsswitch domain to make it working with sssd. Resolves:#1160196 - Make drbd as nsswitch domain to make it working with sssd. - Make conman as nsswitch domain to make ipmitool.exp runing as conman_t working. - Add support for /var/lib/sntp directory. - Add fixes to allow docker to create more content in tmpfs ,and donaudit reading /proc - Allow winbind to read usermodehelper - Allow telepathy domains to execute shells and bin_t - Allow gpgdomains to create netlink_kobject_uevent_sockets - Allow mongodb to bind to the mongo port and mongos to run as mongod_t - Allow abrt to read software raid state. - Allow nslcd to execute netstat. - Allow dovecot to create user's home directory when they log into IMAP. - Allow login domains to create kernel keyring with different level.- Allow modemmanger to connectto itself Resolves:#1120152 - Allow pki_tomcat to create link files in /var/lib/pki-ca. Resolves:#1121744 - varnishd needs to have fsetid capability Resolves:#1125165 - Allow snapperd to dbus chat with system cron jobs. Resolves:#1152447 - Allow dovecot to create user's home directory when they log into IMAP Resolves:#1152773 - Add labeling for /usr/sbin/haproxy-systemd-wrapper wrapper to make haproxy running haproxy_t. - ALlow listen and accept on tcp socket for init_t in MLS. Previously it was for xinetd_t. - Allow nslcd to execute netstat. - Add suppor for keepalived unconfined scripts and allow keepalived to read all domain state and kill capability. - Allow nslcd to read /dev/urandom.- Add back kill permisiion for system class Resolves:#1150011- Add back kill permisiion for service class Resolves:#1150011 - Make rhsmcertd_t also as dbus domain. - Allow named to create DNS_25 with correct labeling. - Add cloudform_dontaudit_write_cloud_log() - Call auth_use_nsswitch to apache to read/write cloud-init keys. - Allow cloud-init to dbus chat with certmonger. - Fix path to mon_statd_initrc_t script. - Allow all RHCS services to read system state. - Allow dnssec_trigger_t to execute unbound-control in own domain. - kernel_read_system_state needs to be called with type. Moved it to antivirus.if. - Added policy for mon_statd and mon_procd services. BZ (1077821) - Allow opensm_t to read/write /dev/infiniband/umad1. - Allow mongodb to manage own log files. - Allow neutron connections to system dbus. - Add support for /var/lib/swiftdirectory. - Allow nova-scheduler to read certs. - Allow openvpn to access /sys/fs/cgroup dir. - Allow openvpn to execute systemd-passwd-agent in systemd_passwd_agent_t to make openvpn working with systemd. - Fix samba_export_all_ro/samba_export_all_rw booleans to dontaudit search/read security files. - Add auth_use_nsswitch for portreserve to make it working with sssd. - automount policy is non-base module so it needs to be called in optional block. - ALlow sensord to getattr on sysfs. - Label /usr/share/corosync/corosync as cluster_exec_t. - Allow lmsd_plugin to read passwd file. BZ(1093733) - Allow read antivirus domain all kernel sysctls. - Allow mandb to getattr on file systems - Allow nova-console to connect to mem_cache port. - Make sosreport as unconfined domain. - Allow mondogdb to 'accept' accesses on the tcp_socket port. - ALlow sanlock to send a signal to virtd_t.- Build also MLS policy Resolves:#1138424- Add back kill permisiion for system class - Allow iptables read fail2ban logs. - Fix radius labeled ports - Add userdom_manage_user_tmpfs_files interface - Allow libreswan to connect to VPN via NM-libreswan. - Label 4101 tcp port as brlp port - fix dev_getattr_generic_usb_dev interface - Allow all domains to read fonts - Make sure /run/systemd/generator and system is labeled correctly on creation. - Dontaudit aicuu to search home config dir. - Make keystone_cgi_script_t domain. Resolves:#1138424 - Fix bug in drbd policy, - Added support for cpuplug. - ALlow sanlock_t to read sysfs_t. - Added sendmail_domtrans_unconfined interface - Fix broken interfaces - radiusd wants to write own log files. - Label /usr/libexec/rhsmd as rhsmcertd_exec_t - Allow rhsmcertd send signull to setroubleshoot. - Allow rhsmcertd manage rpm db. - Added policy for blrtty. - Fix keepalived policy - Allow rhev-agentd dbus chat with systemd-logind. - Allow keepalived manage snmp var lib sock files. - Add support for /var/lib/graphite-web - Allow NetworkManager to create Bluetooth SDP sockets - It's going to do the the discovery for DUN service for modems with Bluez 5. - Allow swift to connect to all ephemeral ports by default. - Allow sssd to read selinux config to add SELinux user mapping. - Allow lsmd to search own plguins. - Allow abrt to read /dev/memto generate an unique machine_id and uses sosuploader's algorithm based off dmidecode[1] fields. - ALlow zebra for user/group look-ups. - Allow nova domains to getattr on all filesystems. - Allow collectd sys_ptrace and dac_override caps because of reading of /proc/%i/io for several processes. - Allow pppd to connect to /run/sstpc/sstpc-nm-sstp-service-28025 over unix stream socket. - Allow rhnsd_t to manage also rhnsd config symlinks. - ALlow user mail domains to create dead.letter. - Allow rabbitmq_t read rabbitmq_var_lib_t lnk files. - Allow pki-tomcat to change SELinux object identity. - Allow radious to connect to apache ports to do OCSP check - Allow git cgi scripts to create content in /tmp - Allow cockpit-session to do GSSAPI logins. - Allow sensord read in /proc - Additional access required by usbmuxd- Allow locate to look at files/directories without labels, and chr_file and blk_file on non dev file systems - Label /usr/lib/erlang/erts.*/bin files as bin_t - Add files_dontaudit_access_check_home_dir() inteface. - Allow udev_t mounton udev_var_run_t dirs #(1128618) - Add systemd_networkd_var_run_t labeling for /var/run/systemd/netif and allow systemd-networkd to manage it. - Add init_dontaudit_read_state() interface. - Add label for ~/.local/share/fonts - Allow unconfined_r to access unconfined_service_t. - Allow init to read all config files - Add new interface to allow creation of file with lib_t type - Assign rabbitmq port. - Allow unconfined_service_t to dbus chat with all dbus domains - Add new interfaces to access users keys. - Allow domains to are allowed to mounton proc to mount on files as well as dirs - Fix labeling for HOME_DIR/tmp and HOME_DIR/.tmp directories. - Add a port definition for shellinaboxd - Label ~/tmp and ~/.tmp directories in user tmp dirs as user_tmp_t - Allow userdomains to stream connect to pcscd for smart cards - Allow programs to use pam to search through user_tmp_t dires (/tmp/.X11-unix) - Update to rawhide-contrib changes Resolves:#1123844- Rebase to 3.13.1 which we have in Fedora21 Resolves:#1128284- Back port fixes from Fedora. Mainly OpenStack and Docker fixes- Add policy-rhel-7.1-{base,contrib} patches- Add support for us_cli ports - Fix labeling for /var/run/user//gvfs - add support for tcp/9697 - Additional rules required by openstack, needs backport to F20 and RHEL7 - Additional access required by docker - ALlow motion to use tcp/8082 port - Allow init_t to setattr/relabelfrom dhcp state files - Dontaudit antivirus domains read access on all security files by default - Add missing alias for old amavis_etc_t type - Allow block_suspend cap for haproxy - Additional fixes for instack overcloud - Allow OpenStack to read mysqld_db links and connect to MySQL - Remove dup filename rules in gnome.te - Allow sys_chroot cap for httpd_t and setattr on httpd_log_t - Allow iscsid to handle own unit files - Add iscsi_systemctl() - Allow mongod to create also sock_files in /run with correct labeling - Allow httpd to send signull to apache script domains and don't audit leaks - Allow rabbitmq_beam to connect to httpd port - Allow aiccu stream connect to pcscd - Allow dmesg to read hwdata and memory dev - Allow all freeipmi domains to read/write ipmi devices - Allow sblim_sfcbd to use also pegasus-https port - Allow rabbitmq_epmd to manage rabbit_var_log_t files - Allow chronyd to read /sys/class/hwmon/hwmon1/device/temp2_input - Allow docker to status any unit file and allow it to start generic unit files- Change hsperfdata_root to have as user_tmp_t Resolves:#1076523- Fix Multiple same specifications for /var/named/chroot/dev/zero - Add labels for /var/named/chroot_sdb/dev devices - Add support for strongimcv - Use kerberos_keytab_domains in auth_use_nsswitch - Update auth_use_nsswitch to make all these types as kerberos_keytab_domain to - Allow net_raw cap for neutron_t and send sigkill to dnsmasq - Fix ntp_filetrans_named_content for sntp-kod file - Add httpd_dbus_sssd boolean - Dontaudit exec insmod in boinc policy - Rename kerberos_keytab_domain to kerberos_keytab_domains - Add kerberos_keytab_domain() - Fix kerberos_keytab_template() - Make all domains which use kerberos as kerberos_keytab_domain Resolves:#1083670 - Allow kill capability to winbind_t- varnishd wants chown capability - update ntp_filetrans_named_content() interface - Add additional fixes for neutron_t. #1083335 - Dontaudit getattr on proc_kcore_t - Allow pki_tomcat_t to read ipa lib files - Allow named_filetrans_domain to create /var/cache/ibus with correct labelign - Allow init_t run /sbin/augenrules - Add dev_unmount_sysfs_fs and sysnet_manage_ifconfig_run interfaces - Allow unpriv SELinux user to use sandbox - Add default label for /tmp/hsperfdata_root- Add file subs also for /var/home- Allow xauth_t to read user_home_dir_t lnk_file - Add labeling for lightdm-data - Allow certmonger to manage ipa lib files - Add support for /var/lib/ipa - Allow pegasus to getattr virt_content - Added some new rules to pcp policy - Allow chrome_sandbox to execute config_home_t - Add support for ABRT FAF- Allow kdm to send signull to remote_login_t process - Add gear policy - Turn on gear_port_t - Allow cgit to read gitosis lib files by default - Allow vdagent to read xdm state - Allow NM and fcoeadm to talk together over unix_dgram_socket- Back port fixes for pegasus_openlmi_admin_t from rawhide Resolves:#1080973 - Add labels for ostree - Add SELinux awareness for NM - Label /usr/sbin/pwhistory_helper as updpwd_exec_t- add gnome_append_home_config() - Allow thumb to append GNOME config home files - Allow rasdaemon to rw /dev/cpu//msr - fix /var/log/pki file spec - make bacula_t as auth_nsswitch domain - Identify pki_tomcat_cert_t as a cert_type - Define speech-dispater_exec_t as an application executable - Add a new file context for /var/named/chroot/run directory - update storage_filetrans_all_named_dev for sg* devices - Allow auditctl_t to getattr on all removeable devices - Allow nsswitch_domains to stream connect to nmbd - Allow unprivusers to connect to memcached - label /var/lib/dirsrv/scripts-INSTANCE as bin_t- Allow also unpriv user to run vmtools - Allow secadm to read /dev/urandom and meminfo Resolves:#1079250 - Add booleans to allow docker processes to use nfs and samba - Add mdadm_tmpfs support - Dontaudit net_amdin for /usr/lib/jvm/java-1.7.0-openjdk-1.7.0.51-2.4.5.1.el7.x86_64/jre-abrt/bin/java running as pki_tomcat_t - Allow vmware-user-sui to use user ttys - Allow talk 2 users logged via console too - Allow ftp services to manage xferlog_t - Make all pcp domanis as unconfined for RHEL7.0 beucause of new policies - allow anaconda to dbus chat with systemd-localed- allow anaconda to dbus chat with systemd-localed - Add fixes for haproxy based on bperkins@redhat.com - Allow cmirrord to make dmsetup working - Allow NM to execute arping - Allow users to send messages through talk - Add userdom_tmp_role for secadm_t- Add additional fixes for rtas_errd - Fix transitions for tmp/tmpfs in rtas.te - Allow rtas_errd to readl all sysctls- Add support for /var/spool/rhsm/debug - Make virt_sandbox_use_audit as True by default - Allow svirt_sandbox_domains to ptrace themselves- Allow docker containers to manage /var/lib/docker content- Allow docker to read tmpfs_t symlinks - Allow sandbox svirt_lxc_net_t to talk to syslog and to sssd over stream sockets- Allow collectd to talk to libvirt - Allow chrome_sandbox to use leaked unix_stream_sockets - Dontaudit leaks of sockets into chrome_sandbox_t - If you create a cups directory in /var/cache then it should be labeled cups_rw_etc_t - Run vmtools as unconfined domains - Allow snort to manage its log files - Allow systemd_cronjob_t to be entered via bin_t - Allow procman to list doveconf_etc_t - allow keyring daemon to create content in tmpfs directories - Add proper labelling for icedtea-web - vpnc is creating content in networkmanager var run directory - Label sddm as xdm_exec_t to make KDE working again - Allow postgresql to read network state - Allow java running as pki_tomcat to read network sysctls - Fix cgroup.te to allow cgred to read cgconfig_etc_t - Allow beam.smp to use ephemeral ports - Allow winbind to use the nis to authenticate passwords- Make rtas_errd_t as unconfined domain for F20.It needs additional fixes. It runs rpm at least. - Allow net_admin cap for fence_virtd running as fenced_t - Make abrt-java-connector working - Make cimtest script 03_defineVS.py of ComputerSystem group working - Fix git_system_enable_homedirs boolean - Allow munin mail plugins to read network systcl- Allow vmtools_helper_t to execute bin_t - Add support for /usr/share/joomla - /var/lib/containers should be labeled as openshift content for now - Allow docker domains to talk to the login programs, to allow a process to login into the container - Allow install_t do dbus chat with NM - Fix interface names in anaconda.if - Add install_t for anaconda. A new type is a part of anaconda policy - sshd to read network sysctls- Allow zabbix to send system log msgs - Allow init_t to stream connect to ipsec Resolves:#1060775- Add docker_connect_any boolean- Allow unpriv SELinux users to dbus chat with firewalld - Add lvm_write_metadata() - Label /etc/yum.reposd dir as system_conf_t. Should be safe because system_conf_t is base_ro_file_type - Allow pegasus_openlmi_storage_t to write lvm metadata - Add hide_broken_symptoms for kdumpgui because of systemd bug - Make kdumpgui_t as unconfined domain Resolves:#1044299 - Allow docker to connect to tcp/5000- Allow numad to write scan_sleep_millisecs - Turn on entropyd_use_audio boolean by default - Allow cgred to read /etc/cgconfig.conf because it contains templates used together with rules from /etc/cgrules.conf. - Allow lscpu running as rhsmcertd_t to read /proc/sysinfo - Fix label on irclogs in the homedir - Allow kerberos_keytab_domain domains to manage keys until we get sssd fix - Allow postgresql to use ldap - Add missing syslog-conn port - Add support for /dev/vmcp and /dev/sclp Resolves:#1069310- Modify xdm_write_home to allow create files/links in /root with xdm_home_ - Allow virt domains to read network state Resolves:#1072019- Added pcp rules - dontaudit openshift_cron_t searching random directories, should be back ported to RHEL6 - clean up ctdb.te - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow certmonger to list home dirs- Change userdom_use_user_inherited_ttys to userdom_use_user_ttys for systemd-tty-ask - Add sysnet_filetrans_named_content_ifconfig() interface - Allow ctdbd to connect own ports - Fix samba_export_all_rw booleanto cover also non security dirs - Allow swift to exec rpm in swift_t and allow to create tmp files/dirs - Allow neutron to create /run/netns with correct labeling - Allow kerberos keytab domains to manage sssd/userdomain keys" - Allow to run ip cmd in neutron_t domain- Allow block_suspend cap2 for systemd-logind and rw dri device - Add labeling for /usr/libexec/nm-libreswan-service - Allow locallogin to rw xdm key to make Virtual Terminal login providing smartcard pin working - Add xserver_rw_xdm_keys() - Allow rpm_script_t to dbus chat also with systemd-located - Fix ipa_stream_connect_otpd() - update lpd_manage_spool() interface - Allow krb5kdc to stream connect to ipa-otpd - Add ipa_stream_connect_otpd() interface - Allow vpnc to unlink NM pids - Add networkmanager_delete_pid_files() - Allow munin plugins to access unconfined plugins - update abrt_filetrans_named_content to cover /var/spool/debug - Label /var/spool/debug as abrt_var_cache_t - Allow rhsmcertd to connect to squid port - Make docker_transition_unconfined as optional boolean - Allow certmonger to list home dirs- Make snapperd as unconfined domain and add additional fixes for it - Remove nsplugin.pp module on upgrade- Add snapperd_home_t for HOME_DIR/.snapshots directory - Make sosreport as unconfined domain - Allow sosreport to execute grub2-probe - Allow NM to manage hostname config file - Allow systemd_timedated_t to dbus chat with rpm_script_t - Allow lsmd plugins to connect to http/ssh/http_cache ports by default - Add lsmd_plugin_connect_any boolean - Allow mozilla_plugin to attempt to set capabilities - Allow lsdm_plugins to use tcp_socket - Dontaudit mozilla plugin from getattr on /proc or /sys - Dontaudit use of the keyring by the services in a sandbox - Dontaudit attempts to sys_ptrace caused by running ps for mysqld_safe_t - Allow rabbitmq_beam to connect to jabber_interserver_port - Allow logwatch_mail_t to transition to qmail_inject and queueu - Added new rules to pcp policy - Allow vmtools_helper_t to change role to system_r - Allow NM to dbus chat with vmtools - Fix couchdb_manage_files() to allow manage couchdb conf files - Add support for /var/run/redis.sock - dontaudit gpg trying to use audit - Allow consolekit to create log directories and files - Fix vmtools policy to allow user roles to access vmtools_helper_t - Allow block_suspend cap2 for ipa-otpd - Allow pkcsslotd to read users state - Add ioctl to init_dontaudit_rw_stream_socket - Add systemd_hostnamed_manage_config() interface - Remove transition for temp dirs created by init_t - gdm-simple-slave uses use setsockopt - sddm-greater is a xdm type program- Add lvm_read_metadata() - Allow auditadm to search /var/log/audit dir - Add lvm_read_metadata() interface - Allow confined users to run vmtools helpers - Fix userdom_common_user_template() - Generic systemd unit scripts do write check on / - Allow init_t to create init_tmp_t in /tmp.This is for temporary content created by generic unit files - Add additional fixes needed for init_t and setup script running in generic unit files - Allow general users to create packet_sockets - added connlcli port - Add init_manage_transient_unit() interface - Allow init_t (generic unit files) to manage rpc state date as we had it for initrc_t - Fix userdomain.te to require passwd class - devicekit_power sends out a signal to all processes on the message bus when power is going down - Dontaudit rendom domains listing /proc and hittping system_map_t - Dontauit leaks of var_t into ifconfig_t - Allow domains that transition to ssh_t to manipulate its keyring - Define oracleasm_t as a device node - Change to handle /root as a symbolic link for os-tree - Allow sysadm_t to create packet_socket, also move some rules to attributes - Add label for openvswitch port - Remove general transition for files/dirs created in /etc/mail which got etc_aliases_t label. - Allow postfix_local to read .forward in pcp lib files - Allow pegasus_openlmi_storage_t to read lvm metadata - Add additional fixes for pegasus_openlmi_storage_t - Allow bumblebee to manage debugfs - Make bumblebee as unconfined domain - Allow snmp to read etc_aliases_t - Allow lscpu running in pegasus_openlmi_storage_t to read /dev/mem - Allow pegasus_openlmi_storage_t to read /proc/1/environ - Dontaudit read gconf files for cupsd_config_t - make vmtools as unconfined domain - Add vmtools_helper_t for helper scripts. Allow vmtools shutdonw a host and run ifconfig. - Allow collectd_t to use a mysql database - Allow ipa-otpd to perform DNS name resolution - Added new policy for keepalived - Allow openlmi-service provider to manage transitient units and allow stream connect to sssd - Add additional fixes new pscs-lite+polkit support - Add labeling for /run/krb5kdc - Change w3c_validator_tmp_t to httpd_w3c_validator_tmp_t in F20 - Allow pcscd to read users proc info - Dontaudit smbd_t sending out random signuls - Add boolean to allow openshift domains to use nfs - Allow w3c_validator to create content in /tmp - zabbix_agent uses nsswitch - Allow procmail and dovecot to work together to deliver mail - Allow spamd to execute files in homedir if boolean turned on - Allow openvswitch to listen on port 6634 - Add net_admin capability in collectd policy - Fixed snapperd policy - Fixed bugsfor pcp policy - Allow dbus_system_domains to be started by init - Fixed some interfaces - Add kerberos_keytab_domain attribute - Fix snapperd_conf_t def- Addopt corenet rules for unbound-anchor to rpm_script_t - Allow runuser to send send audit messages. - Allow postfix-local to search .forward in munin lib dirs - Allow udisks to connect to D-Bus - Allow spamd to connect to spamd port - Fix syntax error in snapper.te - Dontaudit osad to search gconf home files - Allow rhsmcertd to manage /etc/sysconf/rhn director - Fix pcp labeling to accept /usr/bin for all daemon binaries - Fix mcelog_read_log() interface - Allow iscsid to manage iscsi lib files - Allow snapper domtrans to lvm_t. Add support for /etc/snapper and allow snapperd to manage it. - Make tuned_t as unconfined domain for RHEL7.0 - Allow ABRT to read puppet certs - Add sys_time capability for virt-ga - Allow gemu-ga to domtrans to hwclock_t - Allow additional access for virt_qemu_ga_t processes to read system clock and send audit messages - Fix some AVCs in pcp policy - Add to bacula capability setgid and setuid and allow to bind to bacula ports - Changed label from rhnsd_rw_conf_t to rhnsd_conf_t - Add access rhnsd and osad to /etc/sysconfig/rhn - drbdadm executes drbdmeta - Fixes needed for docker - Allow epmd to manage /var/log/rabbitmq/startup_err file - Allow beam.smp connect to amqp port - Modify xdm_write_home to allow create also links as xdm_home_t if the boolean is on true - Allow init_t to manage pluto.ctl because of init_t instead of initrc_t - Allow systemd_tmpfiles_t to manage all non security files on the system - Added labels for bacula ports - Fix label on /dev/vfio/vfio - Add kernel_mounton_messages() interface - init wants to manage lock files for iscsi- Added osad policy - Allow postfix to deliver to procmail - Allow bumblebee to seng kill signal to xserver - Allow vmtools to execute /usr/bin/lsb_release - Allow docker to write system net ctrls - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix pcp.te - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl- Turn on bacula, rhnsd policy - Add support for rhnsd unit file - Add dbus_chat_session_bus() interface - Add dbus_stream_connect_session_bus() interface - Fix logrotate_use_nfs boolean - Add lot of pcp fixes found in RHEL7 - fix labeling for pmie for pcp pkg - Change thumb_t to be allowed to chat/connect with session bus type - Allow call renice in mlocate - Add logrotate_use_nfs boolean - Allow setroubleshootd to read rpc sysctl - Fixes for *_admin interfaces - Add pegasus_openlmi_storage_var_run_t type def - Add support for /var/run/openlmi-storage - Allow tuned to create syslog.conf with correct labeling - Add httpd_dontaudit_search_dirs boolean - Add support for winbind.service - ALlow also fail2ban-client to read apache logs - Allow vmtools to getattr on all fs - Add support for dey_sapi port - Add logging_filetrans_named_conf() - Allow passwd_t to use ipc_lock, so that it can change the password in gnome-keyring- Update snapper policy - Allow domains to append rkhunter lib files - Allow snapperd to getattr on all fs - Allow xdm to create /var/gdm with correct labeling - Add label for snapper.log - Allow fail2ban-client to read apache log files - Allow thumb_t to execute dbus-daemon in thumb_t- Allow gdm to create /var/gdm with correct labeling - Allow domains to append rkhunterl lib files. #1057982 - Allow systemd_tmpfiles_t net_admin to communicate with journald - Add interface to getattr on an isid_type for any type of file - Update libs_filetrans_named_content() to have support for /usr/lib/debug directory - Allow initrc_t domtrans to authconfig if unconfined is enabled - Allow docker and mount on devpts chr_file - Allow docker to transition to unconfined_t if boolean set - init calling needs to be optional in domain.te - Allow uncofined domain types to handle transient unit files - Fix labeling for vfio devices - Allow net_admin capability and send system log msgs - Allow lldpad send dgram to NM - Add networkmanager_dgram_send() - rkhunter_var_lib_t is correct type - Back port pcp policy from rawhide - Allow openlmi-storage to read removable devices - Allow system cron jobs to manage rkhunter lib files - Add rkhunter_manage_lib_files() - Fix ftpd_use_fusefs boolean to allow manage also symlinks - Allow smbcontrob block_suspend cap2 - Allow slpd to read network and system state info - Allow NM domtrans to iscsid_t if iscsiadm is executed - Allow slapd to send a signal itself - Allow sslget running as pki_ra_t to contact port 8443, the secure port of the CA. - Fix plymouthd_create_log() interface - Add rkhunter policy with files type definition for /var/lib/rkhunter until it is fixed in rkhunter package - Add mozilla_plugin_exec_t for /usr/lib/firefox/plugin-container - Allow postfix and cyrus-imapd to work out of box - Allow fcoemon to talk with unpriv user domain using unix_stream_socket - Dontaudit domains that are calling into journald to net_admin - Add rules to allow vmtools to do what it does - snapperd is D-Bus service - Allow OpenLMI PowerManagement to call 'systemctl --force reboot' - Add haproxy_connect_any boolean - Allow haproxy also to use http cache port by default Resolves:#1058248- Allow apache to write to the owncloud data directory in /var/www/html... - Allow consolekit to create log dir - Add support for icinga CGI scripts - Add support for icinga - Allow kdumpctl_t to create kdump lock file Resolves:#1055634 - Allow kdump to create lnk lock file - Allow nscd_t block_suspen capability - Allow unconfined domain types to manage own transient unit file - Allow systemd domains to handle transient init unit files - Add interfaces to handle transient- Add cron unconfined role support for uncofined SELinux user - Call corenet_udp_bind_all_ports() in milter.te - Allow fence_virtd to connect to zented port - Fix header for mirrormanager_admin() - Allow dkim-milter to bind udp ports - Allow milter domains to send signull itself - Allow block_suspend for yum running as mock_t - Allow beam.smp to manage couchdb files - Add couchdb_manage_files() - Add labeling for /var/log/php_errors.log - Allow bumblebee to stream connect to xserver - Allow bumblebee to send a signal to xserver - gnome-thumbnail to stream connect to bumblebee - Allow xkbcomp running as bumblebee_t to execute bin_t - Allow logrotate to read squid.conf - Additional rules to get docker and lxc to play well with SELinux - Allow bumbleed to connect to xserver port - Allow pegasus_openlmi_storage_t to read hwdata- Allow init_t to work on transitient and snapshot unit files - Add logging_manage_syslog_config() - Update sysnet_dns_name_resolve() to allow connect to dnssec por - Allow pegasus_openlmi_storage_t to read hwdata Resolves:#1031721 - Fix rhcs_rw_cluster_tmpfs() - Allow fenced_t to bind on zented udp port - Added policy for vmtools - Fix mirrormanager_read_lib_files() - Allow mirromanager scripts running as httpd_t to manage mirrormanager pid files - Allow ctdb to create sock files in /var/run/ctdb - Add sblim_filetrans_named_content() interface - Allow rpm scritplets to create /run/gather with correct labeling - Allow gnome keyring domains to create gnome config dirs - Dontaudit read/write to init stream socket for lsmd_plugin_t - Allow automount to read nfs link files - Allow lsm plugins to read/write lsmd stream socket - Allow certmonger to connect ldap port to make IPA CA certificate renewal working. - Add also labeling for /var/run/ctdb - Add missing labeling for /var/lib/ctdb - ALlow tuned to manage syslog.conf. Should be fixed in tuned. #1030446 - Dontaudit hypervkvp to search homedirs - Dontaudit hypervkvp to search admin homedirs - Allow hypervkvp to execute bin_t and ifconfig in the caller domain - Dontaudit xguest_t to read ABRT conf files - Add abrt_dontaudit_read_config() - Allow namespace-init to getattr on fs - Add thumb_role() also for xguest - Add filename transitions to create .spamassassin with correct labeling - Allow apache domain to read mirrormanager pid files - Allow domains to read/write shm and sem owned by mozilla_plugin_t - Allow alsactl to send a generic signal to kernel_t- Add back rpm_run() for unconfined user- Add missing files_create_var_lib_dirs() - Fix typo in ipsec.te - Allow passwd to create directory in /var/lib - Add filename trans also for event21 - Allow iptables command to read /dev/rand - Add sigkill capabilityfor ipsec_t - Add filename transitions for bcache devices - Add additional rules to create /var/log/cron by syslogd_t with correct labeling - Add give everyone full access to all key rings - Add default lvm_var_run_t label for /var/run/multipathd - Fix log labeling to have correct default label for them after logrotate - Labeled ~/.nv/GLCache as being gstreamer output - Allow nagios_system_plugin to read mrtg lib files - Add mrtg_read_lib_files() - Call rhcs_rw_cluster_tmpfs for dlm_controld - Make authconfing as named_filetrans domain - Allow virsh to connect to user process using stream socket - Allow rtas_errd to read rand/urand devices and add chown capability - Fix labeling from /var/run/net-snmpd to correct /var/run/net-snmp Resolves:#1051497 - Add also chown cap for abrt_upload_watch_t. It already has dac_override - Allow sosreport to manage rhsmcertd pid files - Add rhsmcertd_manage_pid_files() - Allow also setgid cap for rpc.gssd - Dontaudit access check for abrt on cert_t - Allow pegasus_openlmi_system providers to dbus chat with systemd-logind- Fix semanage import handling in spec file- Add default lvm_var_run_t label for /var/run/multipathd Resolves:#1051430 - Fix log labeling to have correct default label for them after logrotate - Add files_write_root_dirs - Add new openflow port label for 6653/tcp and 6633/tcp - Add xserver_manage_xkb_libs() - Label tcp/8891 as milter por - Allow gnome_manage_generic_cache_files also create cache_home_t files - Fix aide.log labeling - Fix log labeling to have correct default label for them after logrotate - Allow mysqld-safe write access on /root to make mysqld working - Allow sosreport domtrans to prelikn - Allow OpenvSwitch to connec to openflow ports - Allow NM send dgram to lldpad - Allow hyperv domains to execute shell - Allow lsmd plugins stream connect to lsmd/init - Allow sblim domains to create /run/gather with correct labeling - Allow httpd to read ldap certs - Allow cupsd to send dbus msgs to process with different MLS level - Allow bumblebee to stream connect to apmd - Allow bumblebee to run xkbcomp - Additional allow rules to get libvirt-lxc containers working with docker - Additional allow rules to get libvirt-lxc containers working with docker - Allow docker to getattr on itself - Additional rules needed for sandbox apps - Allow mozilla_plugin to set attributes on usb device if use_spice boolean enabled - httpd should be able to send signal/signull to httpd_suexec_t - Add more fixes for neturon. Domtrans to dnsmasq, iptables. Make neutron as filenamtrans domain.- Add neutron fixes- Allow sshd to write to all process levels in order to change passwd when running at a level - Allow updpwd_t to downgrade /etc/passwd file to s0, if it is not running with this range - Allow apcuspd_t to status and start the power unit file - Allow udev to manage kdump unit file - Added new interface modutils_dontaudit_exec_insmod - Allow cobbler to search dhcp_etc_t directory - systemd_systemctl needs sys_admin capability - Allow sytemd_tmpfiles_t to delete all directories - passwd to create gnome-keyring passwd socket - Add missing zabbix_var_lib_t type - Fix filename trans for zabbixsrv in zabbix.te - Allow fprintd_t to send syslog messages - Add zabbix_var_lib_t for /var/lib/zabbixsrv, also allow zabix to connect to smtp port - Allow mozilla plugin to chat with policykit, needed for spice - Allow gssprozy to change user and gid, as well as read user keyrings - Label upgrades directory under /var/www as httpd_sys_rw_content_t, add other filetrans rules to label content correctly - Allow polipo to connect to http_cache_ports - Allow cron jobs to manage apache var lib content - Allow yppassword to manage the passwd_file_t - Allow showall_t to send itself signals - Allow cobbler to restart dhcpc, dnsmasq and bind services - Allow certmonger to manage home cert files - Add userdom filename trans for user mail domains - Allow apcuspd_t to status and start the power unit file - Allow cgroupdrulesengd to create content in cgoups directories - Allow smbd_t to signull cluster - Allow gluster daemon to create fifo files in glusterd_brick_t and sock_file in glusterd_var_lib_t - Add label for /var/spool/cron.aquota.user - Allow sandbox_x domains to use work with the mozilla plugin semaphore - Added new policy for speech-dispatcher - Added dontaudit rule for insmod_exec_t in rasdaemon policy - Updated rasdaemon policy - Allow system_mail_t to transition to postfix_postdrop_t - Clean up mirrormanager policy - Allow virt_domains to read cert files, needs backport to RHEL7 - Allow sssd to read systemd_login_var_run_t - Allow irc_t to execute shell and bin-t files: - Add new access for mythtv - Allow rsync_t to manage all non auth files - allow modemmanger to read /dev/urand - Allow sandbox apps to attempt to set and get capabilties- Add labeling for /var/lib/servicelog/servicelog.db-journal - Add support for freeipmi port - Add sysadm_u_default_contexts - Make new type to texlive files in homedir - Allow subscription-manager running as sosreport_t to manage rhsmcertd - Additional fixes for docker.te - Remove ability to do mount/sys_admin by default in virt_sandbox domains - New rules required to run docker images within libivrt - Add label for ~/.cvsignore - Change mirrormanager to be run by cron - Add mirrormanager policy - Fixed bumblebee_admin() and mip6d_admin() - Add log support for sensord - Fix typo in docker.te - Allow amanda to do backups over UDP - Allow bumblebee to read /etc/group and clean up bumblebee.te - type transitions with a filename not allowed inside conditionals - Don't allow virt-sandbox tools to use netlink out of the box, needs back port to RHEL7 - Make new type to texlive files in homedir- Allow freeipmi_ipmidetectd_t to use freeipmi port - Update freeipmi_domain_template() - Allow journalctl running as ABRT to read /run/log/journal - Allow NM to read dispatcher.d directory - Update freeipmi policy - Type transitions with a filename not allowed inside conditionals - Allow tor to bind to hplip port - Make new type to texlive files in homedir - Allow zabbix_agent to transition to dmidecode - Add rules for docker - Allow sosreport to send signull to unconfined_t - Add virt_noatsecure and virt_rlimitinh interfaces - Fix labeling in thumb.fc to add support for /usr/lib64/tumbler-1/tumblerddd support for freeipmi port - Add sysadm_u_default_contexts - Add logging_read_syslog_pid() - Fix userdom_manage_home_texlive() interface - Make new type to texlive files in homedir - Add filename transitions for /run and /lock links - Allow virtd to inherit rlimit information Resolves:#975358- Change labeling for /usr/libexec/nm-dispatcher.action to NetworkManager_exec_t Resolves:#1039879 - Add labeling for /usr/lib/systemd/system/mariadb.service - Allow hyperv_domain to read sysfs - Fix ldap_read_certs() interface to allow acess also link files - Add support for /usr/libexec/pegasus/cmpiLMI_Journald-cimprovagt - Allow tuned to run modprobe - Allow portreserve to search /var/lib/sss dir - Add SELinux support for the teamd package contains team network device control daemon. - Dontaudit access check on /proc for bumblebee - Bumblebee wants to load nvidia modules - Fix rpm_named_filetrans_log_files and wine.te - Add conman policy for rawhide - DRM master and input event devices are used by the TakeDevice API - Clean up bumblebee policy - Update pegasus_openlmi_storage_t policy - Add freeipmi_stream_connect() interface - Allow logwatch read madm.conf to support RAID setup - Add raid_read_conf_files() interface - Allow up2date running as rpm_t create up2date log file with rpm_log_t labeling - add rpm_named_filetrans_log_files() interface - Allow dkim-milter to create files/dirs in /tmp - update freeipmi policy - Add policy for freeipmi services - Added rdisc_admin and rdisc_systemctl interfaces - opensm policy clean up - openwsman policy clean up - ninfod policy clean up - Added new policy for ninfod - Added new policy for openwsman - Added rdisc_admin and rdisc_systemctl interfaces - Fix kernel_dontaudit_access_check_proc() - Add support for /dev/uhid - Allow sulogin to get the attributes of initctl and sys_admin cap - Add kernel_dontaudit_access_check_proc() - Fix dev_rw_ipmi_dev() - Fix new interface in devices.if - DRM master and input event devices are used by the TakeDevice API - add dev_rw_inherited_dri() and dev_rw_inherited_input_dev() - Added support for default conman port - Add interfaces for ipmi devices- Allow sosreport to send a signal to ABRT - Add proper aliases for pegasus_openlmi_service_exec_t and pegasus_openlmi_service_t - Label /usr/sbin/htcacheclean as httpd_exec_t Resolves:#1037529 - Added support for rdisc unit file - Add antivirus_db_t labeling for /var/lib/clamav-unofficial-sigs - Allow runuser running as logrotate connections to system DBUS - Label bcache devices as fixed_disk_device_t - Allow systemctl running in ipsec_mgmt_t to access /usr/lib/systemd/system/ipsec.service - Label /usr/lib/systemd/system/ipsec.service as ipsec_mgmt_unit_file_t- Add back setpgid/setsched for sosreport_t- Added fix for clout_init to transition to rpm_script_t (dwalsh@redhat.com)- Dontaudit openshift domains trying to use rawip_sockets, this is caused by a bad check in the kernel. - Allow git_system_t to read git_user_content if the git_system_enable_homedirs boolean is turned on - Add lsmd_plugin_t for lsm plugins - Allow dovecot-deliver to search mountpoints - Add labeling for /etc/mdadm.conf - Allow opelmi admin providers to dbus chat with init_t - Allow sblim domain to read /dev/urandom and /dev/random - Allow apmd to request the kernel load modules - Add glusterd_brick_t type - label mate-keyring-daemon with gkeyringd_exec_t - Add plymouthd_create_log() - Dontaudit leaks from openshift domains into mail domains, needs back port to RHEL6 - Allow sssd to request the kernel loads modules - Allow gpg_agent to use ssh-add - Allow gpg_agent to use ssh-add - Dontaudit access check on /root for myslqd_safe_t - Allow ctdb to getattr on al filesystems - Allow abrt to stream connect to syslog - Allow dnsmasq to list dnsmasq.d directory - Watchdog opens the raw socket - Allow watchdog to read network state info - Dontaudit access check on lvm lock dir - Allow sosreport to send signull to setroubleshootd - Add setroubleshoot_signull() interface - Fix ldap_read_certs() interface - Allow sosreport all signal perms - Allow sosreport to run systemctl - Allow sosreport to dbus chat with rpm - Add glusterd_brick_t files type - Allow zabbix_agentd to read all domain state - Clean up rtas.if - Allow smoltclient to execute ldconfig - Allow sosreport to request the kernel to load a module - Fix userdom_confined_admin_template() - Add back exec_content boolean for secadm, logadm, auditadm - Fix files_filetrans_system_db_named_files() interface - Allow sulogin to getattr on /proc/kcore - Add filename transition also for servicelog.db-journal - Add files_dontaudit_access_check_root() - Add lvm_dontaudit_access_check_lock() interface- Allow watchdog to read /etc/passwd - Allow browser plugins to connect to bumblebee - New policy for bumblebee and freqset - Add new policy for mip6d daemon - Add new policy for opensm daemon - Allow condor domains to read/write condor_master udp_socket - Allow openshift_cron_t to append to openshift log files, label /var/log/openshift - Add back file_pid_filetrans for /var/run/dlm_controld - Allow smbd_t to use inherited tmpfs content - Allow mcelog to use the /dev/cpu device - sosreport runs rpcinfo - sosreport runs subscription-manager - Allow staff_t to run frequency command - Allow systemd_tmpfiles to relabel log directories - Allow staff_t to read xserver_log file - Label hsperfdata_root as tmp_t- More sosreport fixes to make ABRT working- Fix files_dontaudit_unmount_all_mountpoints() - Add support for 2608-2609 tcp/udp ports - Should allow domains to lock the terminal device - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - We need to require passwd rootok - Fix zebra.fc - Fix dnsmasq_filetrans_named_content() interface - Allow all sandbox domains create content in svirt_home_t - Allow zebra domains also create zebra_tmp_t files in /tmp - Add support for new zebra services:isisd,babeld. Add systemd support for zebra services. - Fix labeling on neutron and remove transition to iconfig_t - abrt needs to read mcelog log file - Fix labeling on dnsmasq content - Fix labeling on /etc/dnsmasq.d - Allow glusterd to relabel own lib files - Allow sandbox domains to use pam_rootok, and dontaudit attempts to unmount file systems, this is caused by a bug in systemd - Allow ipc_lock for abrt to run journalctl- Fix config.tgz- Fix passenger_stream_connect interface - setroubleshoot_fixit wants to read network state - Allow procmail_t to connect to dovecot stream sockets - Allow cimprovagt service providers to read network states - Add labeling for /var/run/mariadb - pwauth uses lastlog() to update system's lastlog - Allow account provider to read login records - Add support for texlive2013 - More fixes for user config files to make crond_t running in userdomain - Add back disable/reload/enable permissions for system class - Fix manage_service_perms macro - Allow passwd_t to connect to gnome keyring to change password - Update mls config files to have cronjobs in the user domains - Remove access checks that systemd does not actually do- Add support for yubikey in homedir - Add support for upd/3052 port - Allow apcupsd to use PowerChute Network Shutdown - Allow lsmd to execute various lsmplugins - Add labeling also for /etc/watchdog\.d where are watchdog scripts located too - Update gluster_export_all_rw boolean to allow relabel all base file types - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling- Add files_relabel_base_file_types() interface - Allow netlabel-config to read passwd - update gluster_export_all_rw boolean to allow relabel all base file types caused by lsetxattr() - Allow x86_energy_perf tool to modify the MSR - Fix /var/lib/dspam/data labeling - Allow pegasus to domtrans to mount_t - Add labeling for unconfined scripts in /usr/libexec/watchdog/scripts - Add support for unconfined watchdog scripts - Allow watchdog to manage own log files- Add label only for redhat.repo instead of /etc/yum.repos.d. But probably we will need to switch for the directory. - Label /etc/yum.repos.d as system_conf_t - Use sysnet_filetrans_named_content in udev.te instead of generic transition for net_conf_t - Allow dac_override for sysadm_screen_t - Allow init_t to read ipsec_conf_t as we had it for initrc_t. Needed by ipsec unit file. - Allow netlabel-config to read meminfo - Add interface to allow docker to mounton file_t - Add new interface to exec unlabeled files - Allow lvm to use docker semaphores - Setup transitons for .xsessions-errors.old - Change labels of files in /var/lib/*/.ssh to transition properly - Allow staff_t and user_t to look at logs using journalctl - pluto wants to manage own log file - Allow pluto running as ipsec_t to create pluto.log - Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Allow dmidecode to read/write /run/lock/subsys/rhsmcertd - Allow rhsmcertd to manage redhat.repo which is now labeled as system.conf. Allow rhsmcertd to manage all log files. - Additional access for docker - Added more rules to sblim policy - Fix kdumpgui_run_bootloader boolean - Allow dspam to connect to lmtp port - Included sfcbd service into sblim policy - rhsmcertd wants to manaage /etc/pki/consumer dir - Add kdumpgui_run_bootloader boolean - Add support for /var/cache/watchdog - Remove virt_domain attribute for virt_qemu_ga_unconfined_t - Fixes for handling libvirt containes - Dontaudit attempts by mysql_safe to write content into / - Dontaudit attempts by system_mail to modify network config - Allow dspam to bind to lmtp ports - Add new policy to allow staff_t and user_t to look at logs using journalctl - Allow apache cgi scripts to list sysfs - Dontaudit attempts to write/delete user_tmp_t files - Allow all antivirus domains to manage also own log dirs - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Add missing permission checks for nscd- Fix alias decl in corenetwork.te.in - Add support for fuse.glusterfs - Add file transition rules for content created by f5link - Rename quantum_port information to neutron - Allow all antivirus domains to manage also own log dirs - Rename quantum_port information to neutron - Allow pegasus_openlmi_services_t to stream connect to sssd_t- Allow sysadm_t to read login information - Allow systemd_tmpfiles to setattr on var_log_t directories - Udpdate Makefile to include systemd_contexts - Add systemd_contexts - Add fs_exec_hugetlbfs_files() interface - Add daemons_enable_cluster_mode boolean - Fix rsync_filetrans_named_content() - Add rhcs_read_cluster_pid_files() interface - Update rhcs.if with additional interfaces from RHEL6 - Fix rhcs_domain_template() to not create run dirs with cluster_var_run_t - Allow glusterd_t to mounton glusterd_tmp_t - Allow glusterd to unmout al filesystems - Allow xenstored to read virt config - Add label for swift_server.lock and make add filetrans_named_content to make sure content gets created with the correct label - Allow mozilla_plugin_t to mmap hugepages as an executable- Add back userdom_security_admin_template() interface and use it for sysadm_t if sysadm_secadm.pp- Allow sshd_t to read openshift content, needs backport to RHEL6.5 - Label /usr/lib64/sasl2/libsasldb.so.3.0.0 as textrel_shlib_t - Make sur kdump lock is created with correct label if kdumpctl is executed - gnome interface calls should always be made within an optional_block - Allow syslogd_t to connect to the syslog_tls port - Add labeling for /var/run/charon.ctl socket - Add kdump_filetrans_named_content() - Allo setpgid for fenced_t - Allow setpgid and r/w cluster tmpfs for fenced_t - gnome calls should always be within optional blocks - wicd.pid should be labeled as networkmanager_var_run_t - Allow sys_resource for lldpad- Add rtas policy- Allow mailserver_domains to manage and transition to mailman data - Dontaudit attempts by mozilla plugin to relabel content, caused by using mv and cp commands - Allow mailserver_domains to manage and transition to mailman data - Allow svirt_domains to read sysctl_net_t - Allow thumb_t to use tmpfs inherited from the user - Allow mozilla_plugin to bind to the vnc port if running with spice - Add new attribute to discover confined_admins and assign confined admin to it - Fix zabbix to handle attributes in interfaces - Fix zabbix to read system states for all zabbix domains - Fix piranha_domain_template() - Allow ctdbd to create udp_socket. Allow ndmbd to access ctdbd var files. - Allow lldpad sys_rouserce cap due to #986870 - Allow dovecot-auth to read nologin - Allow openlmi-networking to read /proc/net/dev - Allow smsd_t to execute scripts created on the fly labeled as smsd_spool_t - Add zabbix_domain attribute for zabbix domains to treat them together - Add labels for zabbix-poxy-* (#1018221) - Update openlmi-storage policy to reflect #1015067 - Back port piranha tmpfs fixes from RHEL6 - Update httpd_can_sendmail boolean to allow read/write postfix spool maildrop - Add postfix_rw_spool_maildrop_files interface - Call new userdom_admin_user_templat() also for sysadm_secadm.pp - Fix typo in userdom_admin_user_template() - Allow SELinux users to create coolkeypk11sE-Gate in /var/cache/coolkey - Add new attribute to discover confined_admins - Fix labeling for /etc/strongswan/ipsec.d - systemd_logind seems to pass fd to anyone who dbus communicates with it - Dontaudit leaked write descriptor to dmesg- Activate motion policy- Fix gnome_read_generic_data_home_files() - allow openshift_cgroup_t to read/write inherited openshift file types - Remove httpd_cobbler_content * from cobbler_admin interface - Allow svirt sandbox domains to setattr on chr_file and blk_file svirt_sandbox_file_t, so sshd will work within a container - Allow httpd_t to read also git sys content symlinks - Allow init_t to read gnome home data - Dontaudit setroubleshoot_fixit_t execmem, since it does not seem to really need it. - Allow virsh to execute systemctl - Fix for nagios_services plugins - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - Fix hypervkvp.te - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Fix logging policy - Allow syslog to bind to tls ports - Update labeling for /dev/cdc-wdm - Allow to su_domain to read init states - Allow init_t to read gnome home data - Make sure if systemd_logind creates nologin file with the correct label - Clean up ipsec.te- Add auth_exec_chkpwd interface - Fix port definition for ctdb ports - Allow systemd domains to read /dev/urand - Dontaudit attempts for mozilla_plugin to append to /dev/random - Add label for /var/run/charon.* - Add labeling for /usr/lib/systemd/system/lvm2.*dd policy for motion service - Fix for nagios_services plugins - Fix some bugs in zoneminder policy - add type defintion for ctdbd_var_t - Add support for /var/ctdb. Allow ctdb block_suspend and read /etc/passwd file - Allow net_admin/netlink_socket all hyperv_domain domains - Add labeling for zarafa-search.log and zarafa-search.pid - glusterd binds to random unreserved ports - Additional allow rules found by testing glusterfs - apcupsd needs to send a message to all users on the system so needs to look them up - Fix the label on ~/.juniper_networks - Dontaudit attempts for mozilla_plugin to append to /dev/random - Allow polipo_daemon to connect to flash ports - Allow gssproxy_t to create replay caches - Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type- init reload from systemd_localed_t - Allow domains that communicate with systemd_logind_sessions to use systemd_logind_t fd - Allow systemd_localed_t to ask systemd to reload the locale. - Add systemd_runtime_unit_file_t type for unit files that systemd creates in memory - Allow readahead to read /dev/urand - Fix lots of avcs about tuned - Any file names xenstored in /var/log should be treated as xenstored_var_log_t - Allow tuned to inderact with hugepages - Allow condor domains to list etc rw dirs- Fix nscd_shm_use() - Add initial policy for /usr/sbin/hypervvssd in hypervkvp policy which should be renamed to hyperv. Also add hyperv_domain attribute to treat these HyperV services. - Add hypervkvp_unit_file_t type - Add additional fixes forpegasus_openlmi_account_t - Allow mdadm to read /dev/urand - Allow pegasus_openlmi_storage_t to create mdadm.conf and write it - Add label/rules for /etc/mdadm.conf - Allow pegasus_openlmi_storage_t to transition to fsadm_t - Fixes for interface definition problems - Dontaudit dovecot-deliver to gettatr on all fs dirs - Allow domains to search data_home_t directories - Allow cobblerd to connect to mysql - Allow mdadm to r/w kdump lock files - Add support for kdump lock files - Label zarafa-search as zarafa-indexer - Openshift cgroup wants to read /etc/passwd - Add new sandbox domains for kvm - Allow mpd to interact with pulseaudio if mpd_enable_homedirs is turned on - Fix labeling for /usr/lib/systemd/system/lvm2.* - Add labeling for /usr/lib/systemd/system/lvm2.* - Fix typos to get a new build. We should not cover filename trans rules to prevent duplicate rules - Add sshd_keygen_t policy for sshd-keygen - Fix alsa_home_filetrans interface name and definition - Allow chown for ssh_keygen_t - Add fs_dontaudit_getattr_all_dirs() - Allow init_t to manage etc_aliases_t and read xserver_var_lib_t and chrony keys - Fix up patch to allow systemd to manage home content - Allow domains to send/recv unlabeled traffic if unlabelednet.pp is enabled - Allow getty to exec hostname to get info - Add systemd_home_t for ~/.local/share/systemd directory- Fix lxc labels in config.tgz- Fix labeling for /usr/libexec/kde4/kcmdatetimehelper - Allow tuned to search all file system directories - Allow alsa_t to sys_nice, to get top performance for sound management - Add support for MySQL/PostgreSQL for amavis - Allow openvpn_t to manage openvpn_var_log_t files. - Allow dirsrv_t to create tmpfs_t directories - Allow dirsrv to create dirs in /dev/shm with dirsrv_tmpfs label - Dontaudit leaked unix_stream_sockets into gnome keyring - Allow telepathy domains to inhibit pipes on telepathy domains - Allow cloud-init to domtrans to rpm - Allow abrt daemon to manage abrt-watch tmp files - Allow abrt-upload-watcher to search /var/spool directory - Allow nsswitch domains to manage own process key - Fix labeling for mgetty.* logs - Allow systemd to dbus chat with upower - Allow ipsec to send signull to itself - Allow setgid cap for ipsec_t - Match upstream labeling- Do not build sanbox pkg on MLS- wine_tmp is no longer needed - Allow setroubleshoot to look at /proc - Allow telepathy domains to dbus with systemd logind - Fix handling of fifo files of rpm - Allow mozilla_plugin to transition to itself - Allow certwatch to write to cert_t directories - New abrt application - Allow NetworkManager to set the kernel scheduler - Make wine_domain shared by all wine domains - Allow mdadm_t to read images labeled svirt_image_t - Allow amanda to read /dev/urand - ALlow my_print_default to read /dev/urand - Allow mdadm to write to kdumpctl fifo files - Allow nslcd to send signull to itself - Allow yppasswd to read /dev/urandom - Fix zarafa_setrlimit - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add additional alias for user_tmp_t because wine_tmp_t is no longer used - More handling of ther kernel keyring required by kerberos - New privs needed for init_t when running without transition to initrc_t over bin_t, and without unconfined domain installed- Dontaudit attempts by sosreport to read shadow_t - Allow browser sandbox plugins to connect to cups to print - Add new label mpd_home_t - Label /srv/www/logs as httpd_log_t - Add support for /var/lib/php/wsdlcache - Add zarafa_setrlimit boolean - Allow fetchmail to send mails - Add labels for apache logs under miq package - Allow irc_t to use tcp sockets - fix labels in puppet.if - Allow tcsd to read utmp file - Allow openshift_cron_t to run ssh-keygen in ssh_keygen_t to access host keys - Define svirt_socket_t as a domain_type - Take away transition from init_t to initrc_t when executing bin_t, allow init_t to run chk_passwd_t - Fix label on pam_krb5 helper apps- Allow ldconfig to write to kdumpctl fifo files - allow neutron to connect to amqp ports - Allow kdump_manage_crash to list the kdump_crash_t directory - Allow glance-api to connect to amqp port - Allow virt_qemu_ga_t to read meminfo - Add antivirus_home_t type for antivirus date in HOMEDIRS - Allow mpd setcap which is needed by pulseaudio - Allow smbcontrol to create content in /var/lib/samba - Allow mozilla_exec_t to be used as a entrypoint to mozilla_domtrans_spec - Add additional labeling for qemu-ga/fsfreeze-hook.d scripts - amanda_exec_t needs to be executable file - Allow block_suspend cap for samba-net - Allow apps that read ipsec_mgmt_var_run_t to search ipsec_var_run_t - Allow init_t to run crash utility - Treat usr_t just like bin_t for transitions and executions - Add port definition of pka_ca to port 829 for openshift - Allow selinux_store to use symlinks- Allow block_suspend cap for samba-net - Allow t-mission-control to manage gabble cache files - Allow nslcd to read /sys/devices/system/cpu - Allow selinux_store to use symlinks- Allow xdm_t to transition to itself - Call neutron interfaces instead of quantum - Allow init to change targed role to make uncofined services (xrdp which now has own systemd unit file) working. We want them to have in unconfined_t - Make sure directories in /run get created with the correct label - Make sure /root/.pki gets created with the right label - try to remove labeling for motion from zoneminder_exec_t to bin_t - Allow inetd_t to execute shell scripts - Allow cloud-init to read all domainstate - Fix to use quantum port - Add interface netowrkmanager_initrc_domtrans - Fix boinc_execmem - Allow t-mission-control to read gabble cache home - Add labeling for ~/.cache/telepathy/avatars/gabble - Allow memcache to read sysfs data - Cleanup antivirus policy and add additional fixes - Add boolean boinc_enable_execstack - Add support for couchdb in rabbitmq policy - Add interface couchdb_search_pid_dirs - Allow firewalld to read NM state - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files()- Split out rlogin ports from inetd - Treat files labeld as usr_t like bin_t when it comes to transitions - Allow staff_t to read login config - Allow ipsec_t to read .google authenticator data - Allow systemd running as git_systemd to bind git port - Fix mozilla_plugin_rw_tmpfs_files() - Call the correct interface - corenet_udp_bind_ktalkd_port() - Allow all domains that can read gnome_config to read kde config - Allow sandbox domain to read/write mozilla_plugin_tmpfs_t so pulseaudio will work - Allow mdadm to getattr any file system - Allow a confined domain to executes mozilla_exec_t via dbus - Allow cupsd_lpd_t to bind to the printer port - Dontaudit attempts to bind to ports < 1024 when nis is turned on - Allow apache domain to connect to gssproxy socket - Allow rlogind to bind to the rlogin_port - Allow telnetd to bind to the telnetd_port - Allow ktalkd to bind to the ktalkd_port - Allow cvs to bind to the cvs_port- Cleanup related to init_domain()+inetd_domain fixes - Use just init_domain instead of init_daemon_domain in inetd_core_service_domain - svirt domains neeed to create kobject_uevint_sockets - Lots of new access required for sosreport - Allow tgtd_t to connect to isns ports - Allow init_t to transition to all inetd domains: - openct needs to be able to create netlink_object_uevent_sockets - Dontaudit leaks into ldconfig_t - Dontaudit su domains getattr on /dev devices, move su domains to attribute based calls - Move kernel_stream_connect into all Xwindow using users - Dontaudit inherited lock files in ifconfig o dhcpc_t- Also sock_file trans rule is needed in lsm - Fix labeling for fetchmail pid files/dirs - Add additional fixes for abrt-upload-watch - Fix polipo.te - Fix transition rules in asterisk policy - Add fowner capability to networkmanager policy - Allow polipo to connect to tor ports - Cleanup lsmd.if - Cleanup openhpid policy - Fix kdump_read_crash() interface - Make more domains as init domain - Fix cupsd.te - Fix requires in rpm_rw_script_inherited_pipes - Fix interfaces in lsm.if - Allow munin service plugins to manage own tmpfs files/dirs - Allow virtd_t also relabel unix stream sockets for virt_image_type - Make ktalk as init domain - Fix to define ktalkd_unit_file_t correctly - Fix ktalk.fc - Add systemd support for talk-server - Allow glusterd to create sock_file in /run - Allow xdm_t to delete gkeyringd_tmp_t files on logout - Add fixes for hypervkvp policy - Add logwatch_can_sendmail boolean - Allow mysqld_safe_t to handle also symlinks in /var/log/mariadb - Allow xdm_t to delete gkeyringd_tmp_t files on logout- Add selinux-policy-sandbox pkg0 - Allow rhsmcertd to read init state - Allow fsetid for pkcsslotd - Fix labeling for /usr/lib/systemd/system/pkcsslotd.service - Allow fetchmail to create own pid with correct labeling - Fix rhcs_domain_template() - Allow roles which can run mock to read mock lib files to view results - Allow rpcbind to use nsswitch - Fix lsm.if summary - Fix collectd_t can read /etc/passwd file - Label systemd unit files under dracut correctly - Add support for pam_mount to mount user's encrypted home When a user logs in and logs out using ssh - Add support for .Xauthority-n - Label umount.crypt as lvm_exec_t - Allow syslogd to search psad lib files - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files- Add policy for lsmd - Add support for /var/log/mariadb dir and allow mysqld_safe to list this directory - Update condor_master rules to allow read system state info and allow logging - Add labeling for /etc/condor and allow condor domain to write it (bug) - Allow condor domains to manage own logs - Allow glusterd to read domains state - Fix initial hypervkvp policy - Add policy for hypervkvpd - Fix redis.if summary- Allow boinc to connect to @/tmp/.X11-unix/X0 - Allow beam.smp to connect to tcp/5984 - Allow named to manage own log files - Add label for /usr/libexec/dcc/start-dccifd and domtrans to dccifd_t - Add virt_transition_userdomain boolean decl - Allow httpd_t to sendto unix_dgram sockets on its children - Allow nova domains to execute ifconfig - bluetooth wants to create fifo_files in /tmp - exim needs to be able to manage mailman data - Allow sysstat to getattr on all file systems - Looks like bluetoothd has moved - Allow collectd to send ping packets - Allow svirt_lxc domains to getpgid - Remove virt-sandbox-service labeling as virsh_exec_t, since it no longer does virsh_t stuff - Allow frpintd_t to read /dev/urandom - Allow asterisk_t to create sock_file in /var/run - Allow usbmuxd to use netlink_kobject - sosreport needs to getattr on lots of devices, and needs access to netlink_kobject_uevent_socket - More cleanup of svirt_lxc policy - virtd_lxc_t now talks to dbus - Dontaudit leaked ptmx_t - Allow processes to use inherited fifo files - Allow openvpn_t to connect to squid ports - Allow prelink_cron_system_t to ask systemd to reloaddd miscfiles_dontaudit_access_check_cert() - Allow ssh_t to use /dev/ptmx - Make sure /run/pluto dir is created with correct labeling - Allow syslog to run shell and bin_t commands - Allow ip to relabel tun_sockets - Allow mount to create directories in files under /run - Allow processes to use inherited fifo files - Allow user roles to connect to the journal socket- selinux_set_enforce_mode needs to be used with type - Add append to the dontaudit for unix_stream_socket of xdm_t leak - Allow xdm_t to create symlinks in log direcotries - Allow login programs to read afs config - Label 10933 as a pop port, for dovecot - New policy to allow selinux_server.py to run as semanage_t as a dbus service - Add fixes to make netlabelctl working on MLS - AVCs required for running sepolicy gui as staff_t - Dontaudit attempts to read symlinks, sepolicy gui is likely to cause this type of AVC - New dbus server to be used with new gui - After modifying some files in /etc/mail, I saw this needed on the next boot - Loading a vm from /usr/tmp with virt-manager - Clean up oracleasm policy for Fedora - Add oracleasm policy written by rlopez@redhat.com - Make postfix_postdrop_t as mta_agent to allow domtrans to system mail if it is executed by apache - Add label for /var/crash - Allow fenced to domtrans to sanclok_t - Allow nagios to manage nagios spool files - Make tfptd as home_manager - Allow kdump to read kcore on MLS system - Allow mysqld-safe sys_nice/sys_resource caps - Allow apache to search automount tmp dirs if http_use_nfs is enabled - Allow crond to transition to named_t, for use with unbound - Allow crond to look at named_conf_t, for unbound - Allow mozilla_plugin_t to transition its home content - Allow dovecot_domain to read all system and network state - Allow httpd_user_script_t to call getpw - Allow semanage to read pid files - Dontaudit leaked file descriptors from user domain into thumb - Make PAM authentication working if it is enabled in ejabberd - Add fixes for rabbit to fix ##992920,#992931 - Allow glusterd to mount filesystems - Loading a vm from /usr/tmp with virt-manager - Trying to load a VM I got an AVC from devicekit_disk for loopcontrol device - Add fix for pand service - shorewall touches own log - Allow nrpe to list /var - Mozilla_plugin_roles can not be passed into lpd_run_lpr - Allow afs domains to read afs_config files - Allow login programs to read afs config - Allow virt_domain to read virt_var_run_t symlinks - Allow smokeping to send its process signals - Allow fetchmail to setuid - Add kdump_manage_crash() interface - Allow abrt domain to write abrt.socket- Add more aliases in pegasus.te - Add more fixes for *_admin interfaces - Add interface fixes - Allow nscd to stream connect to nmbd - Allow gnupg apps to write to pcscd socket - Add more fixes for openlmi provides. Fix naming and support for additionals - Allow fetchmail to resolve host names - Allow firewalld to interact also with lnk files labeled as firewalld_etc_rw_t - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te - Fix corecmd_exec_chroot() - Fix logging_relabel_syslog_pid_socket interface - Fix typo in unconfineduser.te - Allow system_r to access unconfined_dbusd_t to run hp_chec- Allow xdm_t to act as a dbus client to itsel - Allow fetchmail to resolve host names - Allow gnupg apps to write to pcscd socket - Add labeling for cmpiLMI_Fan-cimprovagt - Allow net_admin for glusterd - Allow telepathy domain to create dconf with correct labeling in /home/userX/.cache/ - Add pegasus_openlmi_system_t - Fix puppet_domtrans_master() to make all puppet calling working in passenger.te -httpd_t does access_check on certs- Add support for cmpiLMI_Service-cimprovagt - Allow pegasus domtrans to rpm_t to make pycmpiLMI_Software-cimprovagt running as rpm_t - Label pycmpiLMI_Software-cimprovagt as rpm_exec_t - Add support for pycmpiLMI_Storage-cimprovagt - Add support for cmpiLMI_Networking-cimprovagt - Allow system_cronjob_t to create user_tmpfs_t to make pulseaudio working - Allow virtual machines and containers to run as user doains, needed for virt-sandbox - Allow buglist.cgi to read cpu info- Allow systemd-tmpfile to handle tmp content in print spool dir - Allow systemd-sysctl to send system log messages - Add support for RTP media ports and fmpro-internal - Make auditd working if audit is configured to perform SINGLE action on disk error - Add interfaces to handle systemd units - Make systemd-notify working if pcsd is used - Add support for netlabel and label /usr/sbin/netlabelctl as iptables_exec_t - Instead of having all unconfined domains get all of the named transition rules, - Only allow unconfined_t, init_t, initrc_t and rpm_script_t by default. - Add definition for the salt ports - Allow xdm_t to create link files in xdm_var_run_t - Dontaudit reads of blk files or chr files leaked into ldconfig_t - Allow sys_chroot for useradd_t - Allow net_raw cap for ipsec_t - Allow sysadm_t to reload services - Add additional fixes to make strongswan working with a simple conf - Allow sysadm_t to enable/disable init_t services - Add additional glusterd perms - Allow apache to read lnk files in the /mnt directory - Allow glusterd to ask the kernel to load a module - Fix description of ftpd_use_fusefs boolean - Allow svirt_lxc_net_t to sys_chroot, modify policy to tighten up svirt_lxc_domain capabilties and process controls, but add them to svirt_lxc_net_t - Allow glusterds to request load a kernel module - Allow boinc to stream connect to xserver_t - Allow sblim domains to read /etc/passwd - Allow mdadm to read usb devices - Allow collectd to use ping plugin - Make foghorn working with SNMP - Allow sssd to read ldap certs - Allow haproxy to connect to RTP media ports - Add additional trans rules for aide_db - Add labeling for /usr/lib/pcsd/pcsd - Add labeling for /var/log/pcsd - Add support for pcs which is a corosync and pacemaker configuration tool- Label /var/lib/ipa/pki-ca/publish as pki_tomcat_cert_t - Add labeling for /usr/libexec/kde4/polkit-kde-authentication-agent-1 - Allow all domains that can domtrans to shutdown, to start the power services script to shutdown - consolekit needs to be able to shut down system - Move around interfaces - Remove nfsd_rw_t and nfsd_ro_t, they don't do anything - Add additional fixes for rabbitmq_beam to allow getattr on mountpoints - Allow gconf-defaults-m to read /etc/passwd - Fix pki_rw_tomcat_cert() interface to support lnk_files- Add support for gluster ports - Make sure that all keys located in /etc/ssh/ are labeled correctly - Make sure apcuspd lock files get created with the correct label - Use getcap in gluster.te - Fix gluster policy - add additional fixes to allow beam.smp to interact with couchdb files - Additional fix for #974149 - Allow gluster to user gluster ports - Allow glusterd to transition to rpcd_t and add additional fixes for #980683 - Allow tgtd working when accessing to the passthrough device - Fix labeling for mdadm unit files- Add mdadm fixes- Fix definition of sandbox.disabled to sandbox.pp.disabled- Allow mdamd to execute systemctl - Allow mdadm to read /dev/kvm - Allow ipsec_mgmt_t to read l2tpd pid content- Allow nsd_t to read /dev/urand - Allow mdadm_t to read framebuffer - Allow rabbitmq_beam_t to read process info on rabbitmq_epmd_t - Allow mozilla_plugin_config_t to create tmp files - Cleanup openvswitch policy - Allow mozilla plugin to getattr on all executables - Allow l2tpd_t to create fifo_files in /var/run - Allow samba to touch/manage fifo_files or sock_files in a samba_share_t directory - Allow mdadm to connecto its own unix_stream_socket - FIXME: nagios changed locations to /log/nagios which is wrong. But we need to have this workaround for now. - Allow apache to access smokeping pid files - Allow rabbitmq_beam_t to getattr on all filesystems - Add systemd support for iodined - Allow nup_upsdrvctl_t to execute its entrypoint - Allow fail2ban_client to write to fail2ban_var_run_t, Also allow it to use nsswitch - add labeling for ~/.cache/libvirt-sandbox - Add interface to allow domains transitioned to by confined users to send sigchld to screen program - Allow sysadm_t to check the system status of files labeled etc_t, /etc/fstab - Allow systemd_localed to start /usr/lib/systemd/system/systemd-vconsole-setup.service - Allow an domain that has an entrypoint from a type to be allowed to execute the entrypoint without a transition, I can see no case where this is a bad thing, and elminiates a whole class of AVCs. - Allow staff to getsched all domains, required to run htop - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Add prosody policy written by Michael Scherer - Allow nagios plugins to read /sys info - ntpd needs to manage own log files - Add support for HOME_DIR/.IBMERS - Allow iptables commands to read firewalld config - Allow consolekit_t to read utmp - Fix filename transitions on .razor directory - Add additional fixes to make DSPAM with LDA working - Allow snort to read /etc/passwd - Allow fail2ban to communicate with firewalld over dbus - Dontaudit openshift_cgreoup_file_t read/write leaked dev - Allow nfsd to use mountd port - Call th proper interface - Allow openvswitch to read sys and execute plymouth - Allow tmpwatch to read /var/spool/cups/tmp - Add support for /usr/libexec/telepathy-rakia - Add systemd support for zoneminder - Allow mysql to create files/directories under /var/log/mysql - Allow zoneminder apache scripts to rw zoneminder tmpfs - Allow httpd to manage zoneminder lib files - Add zoneminder_run_sudo boolean to allow to start zoneminder - Allow zoneminder to send mails - gssproxy_t sock_file can be under /var/lib - Allow web domains to connect to whois port. - Allow sandbox_web_type to connect to the same ports as mozilla_plugin_t. - We really need to add an interface to corenet to define what a web_client_domain is and - then define chrome_sandbox_t, mozilla_plugin_t and sandbox_web_type to that domain. - Add labeling for cmpiLMI_LogicalFile-cimprovagt - Also make pegasus_openlmi_logicalfile_t as unconfined to have unconfined_domain attribute for filename trans rules - Update policy rules for pegasus_openlmi_logicalfile_t - Add initial types for logicalfile/unconfined OpenLMI providers - mailmanctl needs to read own log - Allow logwatch manage own lock files - Allow nrpe to read meminfo - Allow httpd to read certs located in pki-ca - Add pki_read_tomcat_cert() interface - Add support for nagios openshift plugins - Add port definition for redis port - fix selinuxuser_use_ssh_chroot boolean- Shrink the size of policy by moving to attributes, also add dridomain so that mozilla_plugin can follow selinuxuse_dri boolean. - Allow bootloader to manage generic log files - Allow ftp to bind to port 989 - Fix label of new gear directory - Add support for new directory /var/lib/openshift/gears/ - Add openshift_manage_lib_dirs() - allow virtd domains to manage setrans_var_run_t - Allow useradd to manage all openshift content - Add support so that mozilla_plugin_t can use dri devices - Allow chronyd to change the scheduler - Allow apmd to shut downthe system - Devicekit_disk_t needs to manage /etc/fstab- Make DSPAM to act as a LDA working - Allow ntop to create netlink socket - Allow policykit to send a signal to policykit-auth - Allow stapserver to dbus chat with avahi/systemd-logind - Fix labeling on haproxy unit file - Clean up haproxy policy - A new policy for haproxy and placed it to rhcs.te - Add support for ldirectord and treat it with cluster_t - Make sure anaconda log dir is created with var_log_t- Allow lvm_t to create default targets for filesystem handling - Fix labeling for razor-lightdm binaries - Allow insmod_t to read any file labeled var_lib_t - Add policy for pesign - Activate policy for cmpiLMI_Account-cimprovagt - Allow isnsd syscall=listen - /usr/libexec/pegasus/cimprovagt needs setsched caused by sched_setscheduler - Allow ctdbd to use udp/4379 - gatherd wants sys_nice and setsched - Add support for texlive2012 - Allow NM to read file_t (usb stick with no labels used to transfer keys for example) - Allow cobbler to execute apache with domain transition- condor_collector uses tcp/9000 - Label /usr/sbin/virtlockd as virtd_exec_t for now - Allow cobbler to execute ldconfig - Allow NM to execute ssh - Allow mdadm to read /dev/crash - Allow antivirus domains to connect to snmp port - Make amavisd-snmp working correctly - Allow nfsd_t to mounton nfsd_fs_t - Add initial snapper policy - We still need to have consolekit policy - Dontaudit firefox attempting to connect to the xserver_port_t if run within sandbox_web_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow dirsrv to read network state - Fix pki_read_tomcat_lib_files - Add labeling for /usr/libexec/nm-ssh-service - Add label cert_t for /var/lib/ipa/pki-ca/publish - Lets label /sys/fs/cgroup as cgroup_t for now, to keep labels consistant - Allow nfsd_t to mounton nfsd_fs_t - Dontaudit sandbox apps attempting to open user_devpts_t - Allow passwd_t to change role to system_r from unconfined_r- Don't audit access checks by sandbox xserver on xdb var_lib - Allow ntop to read usbmon devices - Add labeling for new polcykit authorizor - Dontaudit access checks from fail2ban_client - Don't audit access checks by sandbox xserver on xdb var_lib - Allow apps that connect to xdm stream to conenct to xdm_dbusd_t stream - Fix labeling for all /usr/bim/razor-lightdm-* binaries - Add filename trans for /dev/md126p1- Make vdagent able to request loading kernel module - Add support for cloud-init make it as unconfined domain - Allow snmpd to run smartctl in fsadm_t domain - remove duplicate openshift_search_lib() interface - Allow mysqld to search openshift lib files - Allow openshift cgroup to interact with passedin file descriptors - Allow colord to list directories inthe users homedir - aide executes prelink to check files - Make sure cupsd_t creates content in /etc/cups with the correct label - Lest dontaudit apache read all domains, so passenger will not cause this avc - Allow gssd to connect to gssproxy - systemd-tmpfiles needs to be able to raise the level to fix labeling on /run/setrans in MLS - Allow systemd-tmpfiles to relabel also lock files - Allow useradd to add homdir in /var/lib/openshift - Allow setfiles and semanage to write output to /run/files- Add labeling for /dev/tgt - Dontaudit leak fd from firewalld for modprobe - Allow runuser running as rpm_script_t to create netlink_audit socket - Allow mdadm to read BIOS non-volatile RAM- accountservice watches when accounts come and go in wtmp - /usr/java/jre1.7.0_21/bin/java needs to create netlink socket - Add httpd_use_sasl boolean - Allow net_admin for tuned_t - iscsid needs sys_module to auto-load kernel modules - Allow blueman to read bluetooth conf - Add nova_manage_lib_files() interface - Fix mplayer_filetrans_home_content() - Add mplayer_filetrans_home_content() - mozilla_plugin_config_roles need to be able to access mozilla_plugin_config_t - Revert "Allow thumb_t to append inherited xdm stream socket" - Add iscsi_filetrans_named_content() interface - Allow to create .mplayer with the correct labeling for unconfined - Allow iscsiadmin to create lock file with the correct labeling- Allow wine to manage wine home content - Make amanda working with socket actiovation - Add labeling for /usr/sbin/iscsiadm - Add support for /var/run/gssproxy.sock - dnsmasq_t needs to read sysctl_net_t- Fix courier_domain_template() interface - Allow blueman to write ip_forward - Allow mongodb to connect to mongodb port - Allow mongodb to connect to mongodb port - Allow java to bind jobss_debug port - Fixes for *_admin interfaces - Allow iscsid auto-load kernel modules needed for proper iSCSI functionality - Need to assign attribute for courier_domain to all courier_domains - Fail2ban reads /etc/passwd - postfix_virtual will create new files in postfix_spool_t - abrt triggers sys_ptrace by running pidof - Label ~/abc as mozilla_home_t, since java apps as plugin want to create it - Add passenger fixes needed by foreman - Remove dup interfaces - Add additional interfaces for quantum - Add new interfaces for dnsmasq - Allow passenger to read localization and send signull to itself - Allow dnsmasq to stream connect to quantum - Add quantum_stream_connect() - Make sure that mcollective starts the service with the correct labeling - Add labels for ~/.manpath - Dontaudit attempts by svirt_t to getpw* calls - sandbox domains are trying to look at parent process data - Allow courior auth to create its pid file in /var/spool/courier subdir - Add fixes for beam to have it working with couchdb - Add labeling for /run/nm-xl2tpd.con - Allow apache to stream connect to thin - Add systemd support for amand - Make public types usable for fs mount points - Call correct mandb interface in domain.te - Allow iptables to r/w quantum inherited pipes and send sigchld - Allow ifconfig domtrans to iptables and execute ldconfig - Add labels for ~/.manpath - Allow systemd to read iscsi lib files - seunshare is trying to look at parent process data- Fix openshift_search_lib - Add support for abrt-uefioops-oops - Allow colord to getattr any file system - Allow chrome processes to look at each other - Allow sys_ptrace for abrt_t - Add new policy for gssproxy - Dontaudit leaked file descriptor writes from firewalld - openshift_net_type is interface not template - Dontaudit pppd to search gnome config - Update openshift_search_lib() interface - Add fs_list_pstorefs() - Fix label on libbcm_host.so since it is built incorrectly on raspberry pi, needs back port to F18 - Better labels for raspberry pi devices - Allow init to create devpts_t directory - Temporarily label rasbery pi devices as memory_device_t, needs back port to f18 - Allow sysadm_t to build kernels - Make sure mount creates /var/run/blkid with the correct label, needs back port to F18 - Allow userdomains to stream connect to gssproxy - Dontaudit leaked file descriptor writes from firewalld - Allow xserver to read /dev/urandom - Add additional fixes for ipsec-mgmt - Make SSHing into an Openshift Enterprise Node working- Add transition rules to unconfined domains and to sysadm_t to create /etc/adjtime - with the proper label. - Update files_filetrans_named_content() interface to get right labeling for pam.d conf files - Allow systemd-timedated to create adjtime - Add clock_create_adjtime() - Additional fix ifconfing for #966106 - Allow kernel_t to create boot.log with correct labeling - Remove unconfined_mplayer for which we don't have rules - Rename interfaces - Add userdom_manage_user_home_files/dirs interfaces - Fix files_dontaudit_read_all_non_security_files - Fix ipsec_manage_key_file() - Fix ipsec_filetrans_key_file() - Label /usr/bin/razor-lightdm-greeter as xdm_exec_t instead of spamc_exec_t - Fix labeling for ipse.secrets - Add interfaces for ipsec and labeling for ipsec.info and ipsec_setup.pid - Add files_dontaudit_read_all_non_security_files() interface - /var/log/syslog-ng should be labeled var_log_t - Make ifconfig_var_run_t a mountpoint - Add transition from ifconfig to dnsmasq - Allow ifconfig to execute bin_t/shell_exec_t - We want to have hwdb.bin labeled as etc_t - update logging_filetrans_named_content() interface - Allow systemd_timedate_t to manage /etc/adjtime - Allow NM to send signals to l2tpd - Update antivirus_can_scan_system boolean - Allow devicekit_disk_t to sys_config_tty - Run abrt-harvest programs as abrt_t, and allow abrt_t to list all filesystem directories - Make printing from vmware working - Allow php-cgi from php54 collection to access /var/lib/net-snmp/mib_indexes - Add virt_qemu_ga_data_t for qemu-ga - Make chrome and mozilla able to connect to same ports, add jboss_management_port_t to both - Fix typo in virt.te - Add virt_qemu_ga_unconfined_t for hook scripts - Make sure NetworkManager files get created with the correct label - Add mozilla_plugin_use_gps boolean - Fix cyrus to have support for net-snmp - Additional fixes for dnsmasq and quantum for #966106 - Add plymouthd_create_log() - remove httpd_use_oddjob for which we don't have rules - Add missing rules for httpd_can_network_connect_cobbler - Add missing cluster_use_execmem boolean - Call userdom_manage_all_user_home_type_files/dirs - Additional fix for ftp_home_dir - Fix ftp_home_dir boolean - Allow squit to recv/send client squid packet - Fix nut.te to have nut_domain attribute - Add support for ejabberd; TODO: revisit jabberd and rabbit policy - Fix amanda policy - Add more fixes for domains which use libusb - Make domains which use libusb working correctly - Allow l2tpd to create ipsec key files with correct labeling and manage them - Fix cobbler_manage_lib_files/cobbler_read_lib_files to cover also lnk files - Allow rabbitmq-beam to bind generic node - Allow l2tpd to read ipse-mgmt pid files - more fixes for l2tpd, NM and pppd from #967072- Dontaudit to getattr on dirs for dovecot-deliver - Allow raiudusd server connect to postgresql socket - Add kerberos support for radiusd - Allow saslauthd to connect to ldap port - Allow postfix to manage postfix_private_t files - Add chronyd support for #965457 - Fix labeling for HOME_DIR/\.icedtea - CHange squid and snmpd to be allowed also write own logs - Fix labeling for /usr/libexec/qemu-ga - Allow virtd_t to use virt_lock_t - Allow also sealert to read the policy from the kernel - qemu-ga needs to execute scripts in /usr/libexec/qemu-ga and to use /tmp content - Dontaudit listing of users homedir by sendmail Seems like a leak - Allow passenger to transition to puppet master - Allow apache to connect to mythtv - Add definition for mythtv ports- Add additional fixes for #948073 bug - Allow sge_execd_t to also connect to sge ports - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow openshift_cron_t to manage openshift_var_lib_t sym links - Allow sge_execd to bind sge ports. Allow kill capability and reads cgroup files - Remove pulseaudio filetrans pulseaudio_manage_home_dirs which is a part of pulseaudio_manage_home_files - Add networkmanager_stream_connect() - Make gnome-abrt wokring with staff_t - Fix openshift_manage_lib_files() interface - mdadm runs ps command which seems to getattr on random log files - Allow mozilla_plugin_t to create pulseaudit_home_t directories - Allow qemu-ga to shutdown virtual hosts - Add labelling for cupsd-browsed - Add web browser plugins to connect to aol ports - Allow nm-dhcp-helper to stream connect to NM - Add port definition for sge ports- Make sure users and unconfined domains create .hushlogin with the correct label - Allow pegaus to chat with realmd over DBus - Allow cobblerd to read network state - Allow boicn-client to stat on /dev/input/mice - Allow certwatch to read net_config_t when it executes apache - Allow readahead to create /run/systemd and then create its own directory with the correct label- Transition directories and files when in a user_tmp_t directory - Change certwatch to domtrans to apache instead of just execute - Allow virsh_t to read xen lib files - update policy rules for pegasus_openlmi_account_t - Add support for svnserve_tmp_t - Activate account openlmi policy - pegasus_openlmi_domain_template needs also require pegasus_t - One more fix for policykit.te - Call fs_list_cgroups_dirs() in policykit.te - Allow nagios service plugin to read mysql config files - Add labeling for /var/svn - Fix chrome.te - Fix pegasus_openlmi_domain_template() interfaces - Fix dev_rw_vfio_dev definiton, allow virtd_t to read tmpfs_t symlinks - Fix location of google-chrome data - Add support for chome_sandbox to store content in the homedir - Allow policykit to watch for changes in cgroups file system - Add boolean to allow mozilla_plugin_t to use spice - Allow collectd to bind to udp port - Allow collected_t to read all of /proc - Should use netlink socket_perms - Should use netlink socket_perms - Allow glance domains to connect to apache ports - Allow apcupsd_t to manage its log files - Allow chrome objects to rw_inherited unix_stream_socket from callers - Allow staff_t to execute virtd_exec_t for running vms - nfsd_t needs to bind mountd port to make nfs-mountd.service working - Allow unbound net_admin capability because of setsockopt syscall - Fix fs_list_cgroup_dirs() - Label /usr/lib/nagios/plugins/utils.pm as bin_t - Remove uplicate definition of fs_read_cgroup_files() - Remove duplicate definition of fs_read_cgroup_files() - Add files_mountpoint_filetrans interface to be used by quotadb_t and snapperd - Additional interfaces needed to list and read cgroups config - Add port definition for collectd port - Add labels for /dev/ptp* - Allow staff_t to execute virtd_exec_t for running vms- Allow samba-net to also read realmd tmp files - Allow NUT to use serial ports - realmd can be started by systemctl now- Remove userdom_home_manager for xdm_t and move all rules to xserver.te directly - Add new xdm_write_home boolean to allow xdm_t to create files in HOME dirs with xdm_home_t - Allow postfix-showq to read/write unix.showq in /var/spool/postfix/pid - Allow virsh to read xen lock file - Allow qemu-ga to create files in /run with proper labeling - Allow glusterd to connect to own socket in /tmp - Allow glance-api to connect to http port to make glance image-create working - Allow keystonte_t to execute rpm- Fix realmd cache interfaces- Allow tcpd to execute leafnode - Allow samba-net to read realmd cache files - Dontaudit sys_tty_config for alsactl - Fix allow rules for postfix_var_run - Allow cobblerd to read /etc/passwd - Allow pegasus to read exports - Allow systemd-timedate to read xdm state - Allow mout to stream connect to rpcbind - Add labeling just for /usr/share/pki/ca-trust-source instead of /usr/share/pki- Allow thumbnails to share memory with apps which run thumbnails - Allow postfix-postqueue block_suspend - Add lib interfaces for smsd - Add support for nginx - Allow s2s running as jabberd_t to connect to jabber_interserver_port_t - Allow pki apache domain to create own tmp files and execute httpd_suexec - Allow procmail to manger user tmp files/dirs/lnk_files - Add virt_stream_connect_svirt() interface - Allow dovecot-auth to execute bin_t - Allow iscsid to request that kernel load a kernel module - Add labeling support for /var/lib/mod_security - Allow iw running as tuned_t to create netlink socket - Dontaudit sys_tty_config for thumb_t - Add labeling for nm-l2tp-service - Allow httpd running as certwatch_t to open tcp socket - Allow useradd to manager smsd lib files - Allow useradd_t to add homedirs in /var/lib - Fix typo in userdomain.te - Cleanup userdom_read_home_certs - Implement userdom_home_reader_certs_type to allow read certs also on encrypt /home with ecryptfs_t - Allow staff to stream connect to svirt_t to make gnome-boxes working- Allow lvm to create its own unit files - Label /var/lib/sepolgen as selinux_config_t - Add filetrans rules for tw devices - Add transition from cupsd_config_t to cupsd_t- Add filetrans rules for tw devices - Cleanup bad transition lines- Fix lockdev_manage_files() - Allow setroubleshootd to read var_lib_t to make email_alert working - Add lockdev_manage_files() - Call proper interface in virt.te - Allow gkeyring_domain to create /var/run/UID/config/dbus file - system dbus seems to be blocking suspend - Dontaudit attemps to sys_ptrace, which I believe gpsd does not need - When you enter a container from root, you generate avcs with a leaked file descriptor - Allow mpd getattr on file system directories - Make sure realmd creates content with the correct label - Allow systemd-tty-ask to write kmsg - Allow mgetty to use lockdev library for device locking - Fix selinuxuser_user_share_music boolean name to selinuxuser_share_music - When you enter a container from root, you generate avcs with a leaked file descriptor - Make sure init.fc files are labeled correctly at creation - File name trans vconsole.conf - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow certmonger to dbus communicate with realmd - Make realmd working- Fix mozilla specification of homedir content - Allow certmonger to read network state - Allow tmpwatch to read tmp in /var/spool/{cups,lpd} - Label all nagios plugin as unconfined by default - Add httpd_serve_cobbler_files() - Allow mdadm to read /dev/sr0 and create tmp files - Allow certwatch to send mails - Fix labeling for nagios plugins - label shared libraries in /opt/google/chrome as testrel_shlib_t- Allow realmd to run ipa, really needs to be an unconfined_domain - Allow sandbox domains to use inherted terminals - Allow pscd to use devices labeled svirt_image_t in order to use cat cards. - Add label for new alsa pid - Alsa now uses a pid file and needs to setsched - Fix oracleasmfs_t definition - Add support for sshd_unit_file_t - Add oracleasmfs_t - Allow unlabeled_t files to be stored on unlabeled_t filesystems- Fix description of deny_ptrace boolean - Remove allow for execmod lib_t for now - Allow quantum to connect to keystone port - Allow nova-console to talk with mysql over unix stream socket - Allow dirsrv to stream connect to uuidd - thumb_t needs to be able to create ~/.cache if it does not exist - virtd needs to be able to sys_ptrace when starting and stoping containers- Allow alsa_t signal_perms, we probaly should search for any app that can execute something without transition and give it signal_perms... - Add dontaudit for mozilla_plugin_t looking at the xdm_t sockets - Fix deny_ptrace boolean, certain ptrace leaked into the system - Allow winbind to manage kerberos_rcache_host - Allow spamd to create spamd_var_lib_t directories - Remove transition to mozilla_tmp_t by mozilla_t, to allow it to manage the users tmp dirs - Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Call snmp_manage_var_lib_files(fogorn_t) instead of snmp_manage_var_dirs - Fix vmware_role() interface - Fix cobbler_manage_lib_files() interface - Allow nagios check disk plugins to execute bin_t - Allow quantum to transition to openvswitch_t - Allow postdrop to stream connect to postfix-master - Allow quantum to stream connect to openvswitch - Add xserver_dontaudit_xdm_rw_stream_sockets() interface - Allow daemon to send dgrams to initrc_t - Allow kdm to start the power service to initiate a reboot or poweroff- Add mising nslcd_dontaudit_write_sock_file() interface - one more fix - Fix pki_read_tomcat_lib_files() interface - Allow certmonger to read pki-tomcat lib files - Allow certwatch to execute bin_t - Allow snmp to manage /var/lib/net-snmp files - Don't audit attempts to write to stream socket of nscld by thumbnailers - Allow git_system_t to read network state - Allow pegasas to execute mount command - Fix desc for drdb_admin - Fix condor_amin() - Interface fixes for uptime, vdagent, vnstatd - Fix labeling for moodle in /var/www/moodle/data - Add interface fixes - Allow bugzilla to read certs - /var/www/moodle needs to be writable by apache - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Fix namespace_init_t to create content with proper labels, and allow it to manage all user content - Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Fix sys_nice for cups_domain - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Kernel_t needs mac_admin in order to support labeled NFS - Fix systemd_dontaudit_dbus_chat() interface - Add interface to dontaudit attempts to send dbus messages to systemd domains, for xguest - Allow consolehelper domain to write Xauth files in /root - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Allow httpd_t to connect to osapi_compute port using httpd_use_openstack bolean - Fixes for dlm_controld - Fix apache_read_sys_content_rw_dirs() interface - Allow logrotate to read /var/log/z-push dir - Allow postfix_postdrop to acces postfix_public socket - Allow sched_setscheduler for cupsd_t - Add missing context for /usr/sbin/snmpd - Allow consolehelper more access discovered by Tom London - Allow fsdaemon to send signull to all domain - Add port definition for osapi_compute port - Allow unconfined to create /etc/hostname with correct labeling - Add systemd_filetrans_named_hostname() interface- Fix file_contexts.subs to label /run/lock correctly- Try to label on controlC devices up to 30 correctly - Add mount_rw_pid_files() interface - Add additional mount/umount interfaces needed by mock - fsadm_t sends audit messages in reads kernel_ipc_info when doing livecd-iso-to-disk - Fix tabs - Allow initrc_domain to search rgmanager lib files - Add more fixes which make mock working together with confined users * Allow mock_t to manage rpm files * Allow mock_t to read rpm log files * Allow mock to setattr on tmpfs, devpts * Allow mount/umount filesystems - Add rpm_read_log() interface - yum-cron runs rpm from within it. - Allow tuned to transition to dmidecode - Allow firewalld to do net_admin - Allow mock to unmont tmpfs_t - Fix virt_sigkill() interface - Add additional fixes for mock. Mainly caused by mount running in mock_t - Allow mock to write sysfs_t and mount pid files - Add mailman_domain to mailman_template() - Allow openvswitch to execute shell - Allow qpidd to use kerberos - Allow mailman to use fusefs, needs back port to RHEL6 - Allow apache and its scripts to use anon_inodefs - Add alias for git_user_content_t and git_sys_content_t so that RHEL6 will update to RHEL7 - Realmd needs to connect to samba ports, needs back port to F18 also - Allow colord to read /run/initial-setup- - Allow sanlock-helper to send sigkill to virtd which is registred to sanlock - Add virt_kill() interface - Add rgmanager_search_lib() interface - Allow wdmd to getattr on all filesystems. Back ported from RHEL6- Allow realmd to create tmp files - FIx ircssi_home_t type to irssi_home_t - Allow adcli running as realmd_t to connect to ldap port - Allow NetworkManager to transition to ipsec_t, for running strongswan - Make openshift_initrc_t an lxc_domain - Allow gssd to manage user_tmp_t files - Fix handling of irclogs in users homedir - Fix labeling for drupal an wp-content in subdirs of /var/www/html - Allow abrt to read utmp_t file - Fix openshift policy to transition lnk_file, sock-file an fifo_file when created in a tmpfs_t, needs back port to RHEL6 - fix labeling for (oo|rhc)-restorer-wrapper.sh - firewalld needs to be able to write to network sysctls - Fix mozilla_plugin_dontaudit_rw_sem() interface - Dontaudit generic ipc read/write to a mozilla_plugin for sandbox_x domains - Add mozilla_plugin_dontaudit_rw_sem() interface - Allow svirt_lxc_t to transition to openshift domains - Allow condor domains block_suspend and dac_override caps - Allow condor_master to read passd - Allow condor_master to read system state - Allow NetworkManager to transition to ipsec_t, for running strongswan - Lots of access required by lvm_t to created encrypted usb device - Allow xdm_t to dbus communicate with systemd_localed_t - Label strongswan content as ipsec_exec_mgmt_t for now - Allow users to dbus chat with systemd_localed - Fix handling of .xsession-errors in xserver.if, so kde will work - Might be a bug but we are seeing avc's about people status on init_t:service - Make sure we label content under /var/run/lock as <> - Allow daemon and systemprocesses to search init_var_run_t directory - Add boolean to allow xdm to write xauth data to the home directory - Allow mount to write keys for the unconfined domain - Add unconfined_write_keys() interface- Add labeling for /usr/share/pki - Allow programs that read var_run_t symlinks also read var_t symlinks - Add additional ports as mongod_port_t for 27018, 27019, 28017, 28018 and 28019 ports - Fix labeling for /etc/dhcp directory - add missing systemd_stub_unit_file() interface - Add files_stub_var() interface - Add lables for cert_t directories - Make localectl set-x11-keymap working at all - Allow abrt to manage mock build environments to catch build problems. - Allow virt_domains to setsched for running gdb on itself - Allow thumb_t to execute user home content - Allow pulseaudio running as mozilla_plugin_t to read /run/systemd/users/1000 - Allow certwatch to execut /usr/bin/httpd - Allow cgred to send signal perms to itself, needs back port to RHEL6 - Allow openshift_cron_t to look at quota - Allow cups_t to read inhered tmpfs_t from the kernel - Allow yppasswdd to use NIS - Tuned wants sys_rawio capability - Add ftpd_use_fusefs boolean - Allow dirsrvadmin_t to signal itself- Allow localectl to read /etc/X11/xorg.conf.d directory - Revert "Revert "Fix filetrans rules for kdm creates .xsession-errors"" - Allow mount to transition to systemd_passwd_agent - Make sure abrt directories are labeled correctly - Allow commands that are going to read mount pid files to search mount_var_run_t - label /usr/bin/repoquery as rpm_exec_t - Allow automount to block suspend - Add abrt_filetrans_named_content so that abrt directories get labeled correctly - Allow virt domains to setrlimit and read file_context- Allow nagios to manage nagios spool files - /var/spool/snmptt is a directory which snmdp needs to write to, needs back port to RHEL6 - Add swift_alias.* policy files which contain typealiases for swift types - Add support for /run/lock/opencryptoki - Allow pkcsslotd chown capability - Allow pkcsslotd to read passwd - Add rsync_stub() interface - Allow systemd_timedate also manage gnome config homedirs - Label /usr/lib64/security/pam_krb5/pam_krb5_cchelper as bin_t - Fix filetrans rules for kdm creates .xsession-errors - Allow sytemd_tmpfiles to create wtmp file - Really should not label content under /var/lock, since it could have labels on it different from var_lock_t - Allow systemd to list all file system directories - Add some basic stub interfaces which will be used in PRODUCT policies- Fix log transition rule for cluster domains - Start to group all cluster log together - Dont use filename transition for POkemon Advanced Adventure until a new checkpolicy update - cups uses usbtty_device_t devices - These fixes were all required to build a MLS virtual Machine with single level desktops - Allow domains to transiton using httpd_exec_t - Allow svirt domains to manage kernel key rings - Allow setroubleshoot to execute ldconfig - Allow firewalld to read generate gnome data - Allow bluetooth to read machine-info - Allow boinc domain to send signal to itself - Fix gnome_filetrans_home_content() interface - Allow mozilla_plugins to list apache modules, for use with gxine - Fix labels for POkemon in the users homedir - Allow xguest to read mdstat - Dontaudit virt_domains getattr on /dev/* - These fixes were all required to build a MLS virtual Machine with single level desktops - Need to back port this to RHEL6 for openshift - Add tcp/8891 as milter port - Allow nsswitch domains to read sssd_var_lib_t files - Allow ping to read network state. - Fix typo - Add labels to /etc/X11/xorg.d and allow systemd-timestampd_t to manage them- Adopt swift changes from lhh@redhat.com - Add rhcs_manage_cluster_pid_files() interface - Allow screen domains to configure tty and setup sock_file in ~/.screen directory - ALlow setroubleshoot to read default_context_t, needed to backport to F18 - Label /etc/owncloud as being an apache writable directory - Allow sshd to stream connect to an lxc domain- Allow postgresql to manage rgmanager pid files - Allow postgresql to read ccs data - Allow systemd_domain to send dbus messages to policykit - Add labels for /etc/hostname and /etc/machine-info and allow systemd-hostnamed to create them - All systemd domains that create content are reading the file_context file and setfscreate - Systemd domains need to search through init_var_run_t - Allow sshd to communicate with libvirt to set containers labels - Add interface to manage pid files - Allow NetworkManger_t to read /etc/hostname - Dontaudit leaked locked files into openshift_domains - Add fixes for oo-cgroup-read - it nows creates tmp files - Allow gluster to manage all directories as well as files - Dontaudit chrome_sandbox_nacl_t using user terminals - Allow sysstat to manage its own log files - Allow virtual machines to setrlimit and send itself signals. - Add labeling for /var/run/hplip- Fix POSTIN scriptlet- Merge rgmanger, corosync,pacemaker,aisexec policies to cluster_t in rhcs.pp- Fix authconfig.py labeling - Make any domains that write homedir content do it correctly - Allow glusterd to read/write anyhwere on the file system by default - Be a little more liberal with the rsync log files - Fix iscsi_admin interface - Allow iscsid_t to read /dev/urand - Fix up iscsi domain for use with unit files - Add filename transition support for spamassassin policy - Allow web plugins to use badly formated libraries - Allow nmbd_t to create samba_var_t directories - Add filename transition support for spamassassin policy - Add filename transition support for tvtime - Fix alsa_home_filetrans_alsa_home() interface - Move all userdom_filetrans_home_content() calling out of booleans - Allow logrotote to getattr on all file sytems - Remove duplicate userdom_filetrans_home_content() calling - Allow kadmind to read /etc/passwd - Dontaudit append .xsession-errors file on ecryptfs for policykit-auth - Allow antivirus domain to manage antivirus db links - Allow logrotate to read /sys - Allow mandb to setattr on man dirs - Remove mozilla_plugin_enable_homedirs boolean - Fix ftp_home_dir boolean - homedir mozilla filetrans has been moved to userdom_home_manager - homedir telepathy filetrans has been moved to userdom_home_manager - Remove gnome_home_dir_filetrans() from gnome_role_gkeyringd() - Might want to eventually write a daemon on fusefsd. - Add policy fixes for sshd [net] child from plautrba@redhat.com - Tor uses a new port - Remove bin_t for authconfig.py - Fix so only one call to userdom_home_file_trans - Allow home_manager_types to create content with the correctl label - Fix all domains that write data into the homedir to do it with the correct label - Change the postgresql to use proper boolean names, which is causing httpd_t to - not get access to postgresql_var_run_t - Hostname needs to send syslog messages - Localectl needs to be able to send dbus signals to users - Make sure userdom_filetrans_type will create files/dirs with user_home_t labeling by default - Allow user_home_manger domains to create spam* homedir content with correct labeling - Allow user_home_manger domains to create HOMEDIR/.tvtime with correct labeling - Add missing miscfiles_setattr_man_pages() interface and for now comment some rules for userdom_filetrans_type to make build process working - Declare userdom_filetrans_type attribute - userdom_manage_home_role() needs to be called withoout usertype attribute because of userdom_filetrans_type attribute - fusefsd is mounding a fuse file system on /run/user/UID/gvfs- Man pages are now generated in the build process - Allow cgred to list inotifyfs filesystem- Allow gluster to get attrs on all fs - New access required for virt-sandbox - Allow dnsmasq to execute bin_t - Allow dnsmasq to create content in /var/run/NetworkManager - Fix openshift_initrc_signal() interface - Dontaudit openshift domains doing getattr on other domains - Allow consolehelper domain to communicate with session bus - Mock should not be transitioning to any other domains, we should keep mock_t as mock_t - Update virt_qemu_ga_t policy - Allow authconfig running from realmd to restart oddjob service - Add systemd support for oddjob - Add initial policy for realmd_consolehelper_t which if for authconfig executed by realmd - Add labeling for gnashpluginrc - Allow chrome_nacl to execute /dev/zero - Allow condor domains to read /proc - mozilla_plugin_t will getattr on /core if firefox crashes - Allow condor domains to read /etc/passwd - Allow dnsmasq to execute shell scripts, openstack requires this access - Fix glusterd labeling - Allow virtd_t to interact with the socket type - Allow nmbd_t to override dac if you turned on sharing all files - Allow tuned to created kobject_uevent socket - Allow guest user to run fusermount - Allow openshift to read /proc and locale - Allow realmd to dbus chat with rpm - Add new interface for virt - Remove depracated interfaces - Allow systemd_domains read access on etc, etc_runtime and usr files, also allow them to connect stream to syslog socket - /usr/share/munin/plugins/plugin.sh should be labeled as bin_t - Remove some more unconfined_t process transitions, that I don't believe are necessary - Stop transitioning uncofnined_t to checkpc - dmraid creates /var/lock/dmraid - Allow systemd_localed to creatre unix_dgram_sockets - Allow systemd_localed to write kernel messages. - Also cleanup systemd definition a little. - Fix userdom_restricted_xwindows_user_template() interface - Label any block devices or char devices under /dev/infiniband as fixed_disk_device_t - User accounts need to dbus chat with accountsd daemon - Gnome requires all users to be able to read /proc/1/- virsh now does a setexeccon call - Additional rules required by openshift domains - Allow svirt_lxc_domains to use inherited terminals, needed to make virt-sandbox-service execute work - Allow spamd_update_t to search spamc_home_t - Avcs discovered by mounting an isci device under /mnt - Allow lspci running as logrotate to read pci.ids - Additional fix for networkmanager_read_pid_files() - Fix networkmanager_read_pid_files() interface - Allow all svirt domains to connect to svirt_socket_t - Allow virsh to set SELinux context for a process. - Allow tuned to create netlink_kobject_uevent_socket - Allow systemd-timestamp to set SELinux context - Add support for /var/lib/systemd/linger - Fix ssh_sysadm_login to be working on MLS as expected- Rename files_rw_inherited_tmp_files to files_rw_inherited_tmp_file - Add missing files_rw_inherited_tmp_files interface - Add additional interface for ecryptfs - ALlow nova-cert to connect to postgresql - Allow keystone to connect to postgresql - Allow all cups domains to getattr on filesystems - Allow pppd to send signull - Allow tuned to execute ldconfig - Allow gpg to read fips_enabled - Add additional fixes for ecryptfs - Allow httpd to work with posgresql - Allow keystone getsched and setsched- Allow gpg to read fips_enabled - Add support for /var/cache/realmd - Add support for /usr/sbin/blazer_usb and systemd support for nut - Add labeling for fenced_sanlock and allow sanclok transition to fenced_t - bitlbee wants to read own log file - Allow glance domain to send a signal itself - Allow xend_t to request that the kernel load a kernel module - Allow pacemaker to execute heartbeat lib files - cleanup new swift policy- Fix smartmontools - Fix userdom_restricted_xwindows_user_template() interface - Add xserver_xdm_ioctl_log() interface - Allow Xusers to ioctl lxdm.log to make lxdm working - Add MLS fixes to make MLS boot/log-in working - Add mls_socket_write_all_levels() also for syslogd - fsck.xfs needs to read passwd - Fix ntp_filetrans_named_content calling in init.te - Allow postgresql to create pg_log dir - Allow sshd to read rsync_data_t to make rsync working - Change ntp.conf to be labeled net_conf_t - Allow useradd to create homedirs in /run. ircd-ratbox does this and we should just allow it - Allow xdm_t to execute gstreamer home content - Allod initrc_t and unconfined domains, and sysadm_t to manage ntp - New policy for openstack swift domains - More access required for openshift_cron_t - Use cupsd_log_t instead of cupsd_var_log_t - rpm_script_roles should be used in rpm_run - Fix rpm_run() interface - Fix openshift_initrc_run() - Fix sssd_dontaudit_stream_connect() interface - Fix sssd_dontaudit_stream_connect() interface - Allow LDA's job to deliver mail to the mailbox - dontaudit block_suspend for mozilla_plugin_t - Allow l2tpd_t to all signal perms - Allow uuidgen to read /dev/random - Allow mozilla-plugin-config to read power_supply info - Implement cups_domain attribute for cups domains - We now need access to user terminals since we start by executing a command outside the tty - We now need access to user terminals since we start by executing a command outside the tty - svirt lxc containers want to execute userhelper apps, need these changes to allow this to happen - Add containment of openshift cron jobs - Allow system cron jobs to create tmp directories - Make userhelp_conf_t a config file - Change rpm to use rpm_script_roles - More fixes for rsync to make rsync wokring - Allow logwatch to domtrans to mdadm - Allow pacemaker to domtrans to ifconfig - Allow pacemaker to setattr on corosync.log - Add pacemaker_use_execmem for memcheck-amd64 command - Allow block_suspend capability - Allow create fifo_file in /tmp with pacemaker_tmp_t - Allow systat to getattr on fixed disk - Relabel /etc/ntp.conf to be net_conf_t - ntp_admin should create files in /etc with the correct label - Add interface to create ntp_conf_t files in /etc - Add additional labeling for quantum - Allow quantum to execute dnsmasq with transition- boinc_cliean wants also execmem as boinc projecs have - Allow sa-update to search admin home for /root/.spamassassin - Allow sa-update to search admin home for /root/.spamassassin - Allow antivirus domain to read net sysctl - Dontaudit attempts from thumb_t to connect to ssd - Dontaudit attempts by readahead to read sock_files - Dontaudit attempts by readahead to read sock_files - Create tmpfs file while running as wine as user_tmpfs_t - Dontaudit attempts by readahead to read sock_files - libmpg ships badly created librarie- Change ssh_use_pts to use macro and only inherited sshd_devpts_t - Allow confined users to read systemd_logind seat information - libmpg ships badly created libraries - Add support for strongswan.service - Add labeling for strongswan - Allow l2tpd_t to read network manager content in /run directory - Allow rsync to getattr any file in rsync_data_t - Add labeling and filename transition for .grl-podcasts- mount.glusterfs executes glusterfsd binary - Allow systemd_hostnamed_t to stream connect to systemd - Dontaudit any user doing a access check - Allow obex-data-server to request the kernel to load a module - Allow gpg-agent to manage gnome content (~/.cache/gpg-agent-info) - Allow gpg-agent to read /proc/sys/crypto/fips_enabled - Add new types for antivirus.pp policy module - Allow gnomesystemmm_t caps because of ioprio_set - Make sure if mozilla_plugin creates files while in permissive mode, they get created with the correct label, user_home_t - Allow gnomesystemmm_t caps because of ioprio_set - Allow NM rawip socket - files_relabel_non_security_files can not be used with boolean - Add interface to thumb_t dbus_chat to allow it to read remote process state - ALlow logrotate to domtrans to mdadm_t - kde gnomeclock wants to write content to /tmp- kde gnomeclock wants to write content to /tmp - /usr/libexec/kde4/kcmdatetimehelper attempts to create /root/.kde - Allow blueman_t to rwx zero_device_t, for some kind of jre - Allow mozilla_plugin_t to rwx zero_device_t, for some kind of jre - Ftp full access should be allowed to create directories as well as files - Add boolean to allow rsync_full_acces, so that an rsync server can write all - over the local machine - logrotate needs to rotate logs in openshift directories, needs back port to RHEL6 - Add missing vpnc_roles type line - Allow stapserver to write content in /tmp - Allow gnome keyring to create keyrings dir in ~/.local/share - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Add interface to colord_t dbus_chat to allow it to read remote process state - Allow colord_t to read cupsd_t state - Add mate-thumbnail-font as thumnailer - Allow sectoolm to sys_ptrace since it is looking at other proceses /proc data. - Allow qpidd to list /tmp. Needed by ssl - Only allow init_t to transition to rsync_t domain, not initrc_t. This should be back ported to F17, F18 - - Added systemd support for ksmtuned - Added booleans ksmtuned_use_nfs ksmtuned_use_cifs - firewalld seems to be creating mmap files which it needs to execute in /run /tmp and /dev/shm. Would like to clean this up but for now we will allow - Looks like qpidd_t needs to read /dev/random - Lots of probing avc's caused by execugting gpg from staff_t - Dontaudit senmail triggering a net_admin avc - Change thumb_role to use thumb_run, not sure why we have a thumb_role, needs back port - Logwatch does access check on mdadm binary - Add raid_access_check_mdadm() iterface- Fix systemd_manage_unit_symlinks() interface - Call systemd_manage_unit_symlinks(() which is correct interface - Add filename transition for opasswd - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow sytstemd-timedated to get status of init_t - Add new systemd policies for hostnamed and rename gnomeclock_t to systemd_timedate_t - colord needs to communicate with systemd and systemd_logind, also remove duplicate rules - Switch gnomeclock_dbus_chat to systemd_dbus_chat_timedated since we have switched the name of gnomeclock - Allow gpg_t to manage all gnome files - Stop using pcscd_read_pub_files - New rules for xguest, dontaudit attempts to dbus chat - Allow firewalld to create its mmap files in tmpfs and tmp directories - Allow firewalld to create its mmap files in tmpfs and tmp directories - run unbound-chkconf as named_t, so it can read dnssec - Colord is reading xdm process state, probably reads state of any apps that sends dbus message - Allow mdadm_t to change the kernel scheduler - mythtv policy - Update mandb_admin() interface - Allow dsspam to listen on own tpc_socket - seutil_filetrans_named_content needs to be optional - Allow sysadm_t to execute content in his homedir - Add attach_queue to tun_socket, new patch from Paul Moore - Change most of selinux configuration types to security_file_type. - Add filename transition rules for selinux configuration - ssh into a box with -X -Y requires ssh_use_ptys - Dontaudit thumb drives trying to bind to udp sockets if nis_enabled is turned on - Allow all unpriv userdomains to send dbus messages to hostnamed and timedated - New allow rules found by Tom London for systemd_hostnamed- Allow systemd-tmpfiles to relabel lpd spool files - Ad labeling for texlive bash scripts - Add xserver_filetrans_fonts_cache_home_content() interface - Remove duplicate rules from *.te - Add support for /var/lock/man-db.lock - Add support for /var/tmp/abrt(/.*)? - Add additional labeling for munin cgi scripts - Allow httpd_t to read munin conf files - Allow certwatch to read meminfo - Fix nscd_dontaudit_write_sock_file() interfac - Fix gnome_filetrans_home_content() to include also "fontconfig" dir as cache_home_t - llow mozilla_plugin_t to create HOMEDIR/.fontconfig with the proper labeling- Allow gnomeclock to talk to puppet over dbus - Allow numad access discovered by Dominic - Add support for HOME_DIR/.maildir - Fix attribute_role for mozilla_plugin_t domain to allow staff_r to access this domain - Allow udev to relabel udev_var_run_t lnk_files - New bin_t file in mcelog- Remove all mcs overrides and replace with t1 != mcs_constrained_types - Add attribute_role for iptables - mcs_process_set_categories needs to be called for type - Implement additional role_attribute statements - Sodo domain is attempting to get the additributes of proc_kcore_t - Unbound uses port 8953 - Allow svirt_t images to compromise_kernel when using pci-passthrough - Add label for dns lib files - Bluetooth aquires a dbus name - Remove redundant files_read_usr_file calling - Remove redundant files_read_etc_file calling - Fix mozilla_run_plugin() - Add role_attribute support for more domains- Mass merge with upstream- Bump the policy version to 28 to match selinux userspace - Rebuild versus latest libsepol- Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Add systemd_status_all_unit_files() interface - Add support for nshadow - Allow sysadm_t to administrate the postfix domains - Add interface to setattr on isid directories for use by tmpreaper - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - Allow sshd_t sys_admin for use with afs logins - Add labeling for /var/named/chroot/etc/localtim- Allow setroubleshoot_fixit to execute rpm - zoneminder needs to connect to httpd ports where remote cameras are listening - Allow firewalld to execute content created in /run directory - Allow svirt_t to read generic certs - Dontaudit leaked ps content to mozilla plugin - Allow sshd_t sys_admin for use with afs logins - Allow systemd to read/write all sysctls - init scripts are creating systemd_unit_file_t directories- systemd_logind_t is looking at all files under /run/user/apache - Allow systemd to manage all user tmp files - Add labeling for /var/named/chroot/etc/localtime - Allow netlabel_peer_t type to flow over netif_t and node_t, and only be hindered by MLS, need back port to RHEL6 - Keystone is now using a differnt port - Allow xdm_t to use usbmuxd daemon to control sound - Allow passwd daemon to execute gnome_exec_keyringd - Fix chrome_sandbox policy - Add labeling for /var/run/checkquorum-timer - More fixes for the dspam domain, needs back port to RHEL6 - More fixes for the dspam domain, needs back port to RHEL6 - sssd needs to connect to kerberos password port if a user changes his password - Lots of fixes from RHEL testing of dspam web - Allow chrome and mozilla_plugin to create msgq and semaphores - Fixes for dspam cgi scripts - Fixes for dspam cgi scripts - Allow confine users to ptrace screen - Backport virt_qemu_ga_t changes from RHEL - Fix labeling for dspam.cgi needed for RHEL6 - We need to back port this policy to RHEL6, for lxc domains - Dontaudit attempts to set sys_resource of logrotate - Allow corosync to read/write wdmd's tmpfs files - I see a ptrace of mozilla_plugin_t by staff_t, will allow without deny_ptrace being set - Allow cron jobs to read bind config for unbound - libvirt needs to inhibit systemd - kdumpctl needs to delete boot_t files - Fix duplicate gnome_config_filetrans - virtd_lxc_t is using /dev/fuse - Passenger needs to create a directory in /var/log, needs a backport to RHEL6 for openshift - apcupsd can be setup to listen to snmp trafic - Allow transition from kdumpgui to kdumpctl - Add fixes for munin CGI scripts - Allow deltacloud to connect to openstack at the keystone port - Allow domains that transition to svirt domains to be able to signal them - Fix file context of gstreamer in .cache directory - libvirt is communicating with logind - NetworkManager writes to the systemd inhibit pipe- Allow munin disk plugins to get attributes of all directories - Allow munin disk plugins to get attributes of all directorie - Allow logwatch to get attributes of all directories - Fix networkmanager_manage_lib() interface - Fix gnome_manage_config() to allow to manage sock_file - Fix virtual_domain_context - Add support for dynamic DNS for DHCPv6- Allow svirt to use netlink_route_socket which was a part of auth_use_nsswitch - Add additional labeling for /var/www/openshift/broker - Fix rhev policy - Allow openshift_initrc domain to dbus chat with systemd_logind - Allow httpd to getattr passenger log file if run_stickshift - Allow consolehelper-gtk to connect to xserver - Add labeling for the tmp-inst directory defined in pam_namespace.conf - Add lvm_metadata_t labeling for /etc/multipath- consoletype is no longer used- Add label for efivarfs - Allow certmonger to send signal to itself - Allow plugin-config to read own process status - Add more fixes for pacemaker - apache/drupal can run clamscan on uploaded content - Allow chrome_sandbox_nacl_t to read pid 1 content- Fix MCS Constraints to control ingres and egres controls on the network. - Change name of svirt_nokvm_t to svirt_tcg_t - Allow tuned to request the kernel to load kernel modules- Label /var/lib/pgsql/.ssh as ssh_home_t - Add labeling for /usr/bin/pg_ctl - Allow systemd-logind to manage keyring user tmp dirs - Add support for 7389/tcp port - gems seems to be placed in lots of places - Since xdm is running a full session, it seems to be trying to execute lots of executables via dbus - Add back tcp/8123 port as http_cache port - Add ovirt-guest-agent\.pid labeling - Allow xend to run scsi_id - Allow rhsmcertd-worker to read "physical_package_id" - Allow pki_tomcat to connect to ldap port - Allow lpr to read /usr/share/fonts - Allow open file from CD/DVD drive on domU - Allow munin services plugins to talk to SSSD - Allow all samba domains to create samba directory in var_t directories - Take away svirt_t ability to use nsswitch - Dontaudit attempts by openshift to read apache logs - Allow apache to create as well as append _ra_content_t - Dontaudit sendmail_t reading a leaked file descriptor - Add interface to have admin transition /etc/prelink.cache to the proper label - Add sntp support to ntp policy - Allow firewalld to dbus chat with devicekit_power - Allow tuned to call lsblk - Allow tor to read /proc/sys/kernel/random/uuid - Add tor_can_network_relay boolean- Add openshift_initrc_signal() interface - Fix typos - dspam port is treat as spamd_port_t - Allow setroubleshoot to getattr on all executables - Allow tuned to execute profiles scripts in /etc/tuned - Allow apache to create directories to store its log files - Allow all directories/files in /var/log starting with passenger to be labeled passenger_log_t - Looks like apache is sending sinal to openshift_initrc_t now,needs back port to RHEL6 - Allow Postfix to be configured to listen on TCP port 10026 for email from DSPAM - Add filename transition for /etc/tuned/active_profile - Allow condor_master to send mails - Allow condor_master to read submit.cf - Allow condor_master to create /tmp files/dirs - Allow condor_mater to send sigkill to other condor domains - Allow condor_procd sigkill capability - tuned-adm wants to talk with tuned daemon - Allow kadmind and krb5kdc to also list sssd_public_t - Allow accountsd to dbus chat with init - Fix git_read_generic_system_content_files() interface - pppd wants sys_nice by nmcli because of "syscall=sched_setscheduler" - Fix mozilla_plugin_can_network_connect to allow to connect to all ports - Label all munin plugins which are not covered by munin plugins policy as unconfined_munin_plugin_exec_t - dspam wants to search /var/spool for opendkim data - Revert "Add support for tcp/10026 port as dspam_port_t" - Turning on labeled networking requires additional access for netlabel_peer_t; these allow rules need to be back ported to RHEL6 - Allow all application domains to use fifo_files passed in from userdomains, also allow them to write to tmp_files inherited from userdomain - Allow systemd_tmpfiles_t to setattr on mandb_cache_t- consolekit.pp was not removed from the postinstall script- Add back consolekit policy - Silence bootloader trying to use inherited tty - Silence xdm_dbusd_t trying to execute telepathy apps - Fix shutdown avcs when machine has unconfined.pp disabled - The host and a virtual machine can share the same printer on a usb device - Change oddjob to transition to a ranged openshift_initr_exec_t when run from oddjob - Allow abrt_watch_log_t to execute bin_t - Allow chrome sandbox to write content in ~/.config/chromium - Dontaudit setattr on fontconfig dir for thumb_t - Allow lircd to request the kernel to load module - Make rsync as userdom_home_manager - Allow rsync to search automount filesystem - Add fixes for pacemaker- Add support for 4567/tcp port - Random fixes from Tuomo Soini - xdm wants to get init status - Allow programs to run in fips_mode - Add interface to allow the reading of all blk device nodes - Allow init to relabel rpcbind sock_file - Fix labeling for lastlog and faillog related to logrotate - ALlow aeolus_configserver to use TRAM port - Add fixes for aeolus_configserver - Allow snmpd to connect to snmp port - Allow spamd_update to create spamd_var_lib_t directories - Allow domains that can read sssd_public_t files to also list the directory - Remove miscfiles_read_localization, this is defined for all domains- Allow syslogd to request the kernel to load a module - Allow syslogd_t to read the network state information - Allow xdm_dbusd_t connect to the system DBUS - Add support for 7389/tcp port - Allow domains to read/write all inherited sockets - Allow staff_t to read kmsg - Add awstats_purge_apache_log boolean - Allow ksysguardproces to read /.config/Trolltech.conf - Allow passenger to create and append puppet log files - Add puppet_append_log and puppet_create_log interfaces - Add puppet_manage_log() interface - Allow tomcat domain to search tomcat_var_lib_t - Allow pki_tomcat_t to connect to pki_ca ports - Allow pegasus_t to have net_admin capability - Allow pegasus_t to write /sys/class/net//flags - Allow mailserver_delivery to manage mail_home_rw_t lnk_files - Allow fetchmail to create log files - Allow gnomeclock to manage home config in .kde - Allow bittlebee to read kernel sysctls - Allow logrotate to list /root- Fix userhelper_console_role_template() - Allow enabling Network Access Point service using blueman - Make vmware_host_t as unconfined domain - Allow authenticate users in webaccess via squid, using mysql as backend - Allow gathers to get various metrics on mounted file systems - Allow firewalld to read /etc/hosts - Fix cron_admin_role() to make sysadm cronjobs running in the sysadm_t instead of cronjob_t - Allow kdumpgui to read/write to zipl.conf - Commands needed to get mock to build from staff_t in enforcing mode - Allow mdadm_t to manage cgroup files - Allow all daemons and systemprocesses to use inherited initrc_tmp_t files - dontaudit ifconfig_t looking at fifo_files that are leaked to it - Add lableing for Quest Authentication System- Fix filetrans interface definitions - Dontaudit xdm_t to getattr on BOINC lib files - Add systemd_reload_all_services() interface - Dontaudit write access on /var/lib/net-snmp/mib_indexes - Only stop mcsuntrustedproc from relableing files - Allow accountsd to dbus chat with gdm - Allow realmd to getattr on all fs - Allow logrotate to reload all services - Add systemd unit file for radiusd - Allow winbind to create samba pid dir - Add labeling for /var/nmbd/unexpected - Allow chrome and mozilla plugin to connect to msnp ports- Fix storage_rw_inherited_fixed_disk_dev() to cover also blk_file - Dontaudit setfiles reading /dev/random - On initial boot gnomeclock is going to need to be set buy gdm - Fix tftp_read_content() interface - Random apps looking at kernel file systems - Testing virt with lxc requiers additional access for virsh_t - New allow rules requied for latest libvirt, libvirt talks directly to journald,lxc setup tool needs compromize_kernel,and we need ipc_lock in the container - Allow MPD to read /dev/radnom - Allow sandbox_web_type to read logind files which needs to read pulseaudio - Allow mozilla plugins to read /dev/hpet - Add labeling for /var/lib/zarafa-webap - Allow BOINC client to use an HTTP proxy for all connections - Allow rhsmertd to domain transition to dmidecod - Allow setroubleshootd to send D-Bus msg to ABRT- Define usbtty_device_t as a term_tty - Allow svnserve to accept a connection - Allow xend manage default virt_image_t type - Allow prelink_cron_system_t to overide user componant when executing cp - Add labeling for z-push - Gnomeclock sets the realtime clock - Openshift seems to be storing apache logs in /var/lib/openshift/.log/httpd - Allow lxc domains to use /dev/random and /dev/urandom- Add port defintion for tcp/9000 - Fix labeling for /usr/share/cluster/checkquorum to label also checkquorum.wdmd - Add rules and labeling for $HOME/cache/\.gstreamer-.* directory - Add support for CIM provider openlmi-networking which uses NetworkManager dbus API - Allow shorewall_t to create netlink_socket - Allow krb5admind to block suspend - Fix labels on /var/run/dlm_controld /var/log/dlm_controld - Allow krb5kdc to block suspend - gnomessytemmm_t needs to read /etc/passwd - Allow cgred to read all sysctls- Allow all domains to read /proc/sys/vm/overcommit_memory - Make proc_numa_t an MLS Trusted Object - Add /proc/numactl support for confined users - Allow ssh_t to connect to any port > 1023 - Add openvswitch domain - Pulseaudio tries to create directories in gnome_home_t directories - New ypbind pkg wants to search /var/run which is caused by sd_notify - Allow NM to read certs on NFS/CIFS using use_nfs_*, use_samba_* booleans - Allow sanlock to read /dev/random - Treat php-fpm with httpd_t - Allow domains that can read named_conf_t to be able to list the directories - Allow winbind to create sock files in /var/run/samba- Add smsd policy - Add support for OpenShift sbin labelin - Add boolean to allow virt to use rawip - Allow mozilla_plugin to read all file systems with noxattrs support - Allow kerberos to write on anon_inodefs fs - Additional access required by fenced - Add filename transitions for passwd.lock/group.lock - UPdate man pages - Create coolkey directory in /var/cache with the correct label- Fix label on /etc/group.lock - Allow gnomeclock to create lnk_file in /etc - label /root/.pki as a home_cert_t - Add interface to make sure rpcbind.sock is created with the correct label - Add definition for new directory /var/lib/os-probe and bootloader wants to read udev rules - opendkim should be a part of milter - Allow libvirt to set the kernel sched algorythm - Allow mongod to read sysfs_t - Add authconfig policy - Remove calls to miscfiles_read_localization all domains get this - Allow virsh_t to read /root/.pki/ content - Add label for log directory under /var/www/stickshift- Allow getty to setattr on usb ttys - Allow sshd to search all directories for sshd_home_t content - Allow staff domains to send dbus messages to kdumpgui - Fix labels on /etc/.pwd.lock and friends to be passwd_file_t - Dontaudit setfiles reading urand - Add files_dontaudit_list_tmp() for domains to which we added sys_nice/setsched - Allow staff_gkeyringd_t to read /home/$USER/.local/share/keyrings dir - Allow systemd-timedated to read /dev/urandom - Allow entropyd_t to read proc_t (meminfo) - Add unconfined munin plugin - Fix networkmanager_read_conf() interface - Allow blueman to list /tmp which is needed by sys_nic/setsched - Fix label of /etc/mail/aliasesdb-stamp - numad is searching cgroups - realmd is communicating with networkmanager using dbus - Lots of fixes to try to get kdump to work- Allow loging programs to dbus chat with realmd - Make apache_content_template calling as optional - realmd is using policy kit- Add new selinuxuser_use_ssh_chroot boolean - dbus needs to be able to read/write inherited fixed disk device_t passed through it - Cleanup netutils process allow rule - Dontaudit leaked fifo files from openshift to ping - sanlock needs to read mnt_t lnk files - Fail2ban needs to setsched and sys_nice- Change default label of all files in /var/run/rpcbind - Allow sandbox domains (java) to read hugetlbfs_t - Allow awstats cgi content to create tmp files and read apache log files - Allow setuid/setgid for cupsd-config - Allow setsched/sys_nice pro cupsd-config - Fix /etc/localtime sym link to be labeled locale_t - Allow sshd to search postgresql db t since this is a homedir - Allow xwindows users to chat with realmd - Allow unconfined domains to configure all files and null_device_t service- Adopt pki-selinux policy- pki is leaking which we dontaudit until a pki code fix - Allow setcap for arping - Update man pages - Add labeling for /usr/sbin/mcollectived - pki fixes - Allow smokeping to execute fping in the netutils_t domain- Allow mount to relabelfrom unlabeled file systems - systemd_logind wants to send and receive messages from devicekit disk over dbus to make connected mouse working - Add label to get bin files under libreoffice labeled correctly - Fix interface to allow executing of base_ro_file_type - Add fixes for realmd - Update pki policy - Add tftp_homedir boolean - Allow blueman sched_setscheduler - openshift user domains wants to r/w ssh tcp sockets- Additional requirements for disable unconfined module when booting - Fix label of systemd script files - semanage can use -F /dev/stdin to get input - syslog now uses kerberos keytabs - Allow xserver to compromise_kernel access - Allow nfsd to write to mount_var_run_t when running the mount command - Add filename transition rule for bin_t directories - Allow files to read usr_t lnk_files - dhcpc wants chown - Add support for new openshift labeling - Clean up for tunable+optional statements - Add labeling for /usr/sbin/mkhomedir_helper - Allow antivirus domain to managa amavis spool files - Allow rpcbind_t to read passwd - Allow pyzor running as spamc to manage amavis spool- Add interfaces to read kernel_t proc info - Missed this version of exec_all - Allow anyone who can load a kernel module to compromise kernel - Add oddjob_dbus_chat to openshift apache policy - Allow chrome_sandbox_nacl_t to send signals to itself - Add unit file support to usbmuxd_t - Allow all openshift domains to read sysfs info - Allow openshift domains to getattr on all domains- MLS fixes from Dan - Fix name of capability2 secure_firmware->compromise_kerne- Allow xdm to search all file systems - Add interface to allow the config of all files - Add rngd policy - Remove kgpg as a gpg_exec_t type - Allow plymouthd to block suspend - Allow systemd_dbus to config any file - Allow system_dbus_t to configure all services - Allow freshclam_t to read usr_files - varnishd requires execmem to load modules- Allow semanage to verify types - Allow sudo domain to execute user home files - Allow session_bus_type to transition to user_tmpfs_t - Add dontaudit caused by yum updates - Implement pki policy but not activated- tuned wants to getattr on all filesystems - tuned needs also setsched. The build is needed for test day- Add policy for qemu-qa - Allow razor to write own config files - Add an initial antivirus policy to collect all antivirus program - Allow qdisk to read usr_t - Add additional caps for vmware_host - Allow tmpfiles_t to setattr on mandb_cache_t - Dontaudit leaked files into mozilla_plugin_config_t - Allow wdmd to getattr on tmpfs - Allow realmd to use /dev/random - allow containers to send audit messages - Allow root mount any file via loop device with enforcing mls policy - Allow tmpfiles_t to setattr on mandb_cache_t - Allow tmpfiles_t to setattr on mandb_cache_t - Make userdom_dontaudit_write_all_ not allow open - Allow init scripts to read all unit files - Add support for saphostctrl ports- Add kernel_read_system_state to sandbox_client_t - Add some of the missing access to kdumpgui - Allow systemd_dbusd_t to status the init system - Allow vmnet-natd to request the kernel to load a module - Allow gsf-office-thum to append .cache/gdm/session.log - realmd wants to read .config/dconf/user - Firewalld wants sys_nice/setsched - Allow tmpreaper to delete mandb cache files - Firewalld wants sys_nice/setsched - Allow firewalld to perform a DNS name resolution - Allown winbind to read /usr/share/samba/codepages/lowcase.dat - Add support for HTTPProxy* in /etc/freshclam.conf - Fix authlogin_yubike boolean - Extend smbd_selinux man page to include samba booleans - Allow dhcpc to execute consoletype - Allow ping to use inherited tmp files created in init scripts - On full relabel with unconfined domain disabled, initrc was running some chcon's - Allow people who delete man pages to delete mandb cache files- Add missing permissive domains- Add new mandb policy - ALlow systemd-tmpfiles_t to relabel mandb_cache_t - Allow logrotate to start all unit files- Add fixes for ctbd - Allow nmbd to stream connect to ctbd - Make cglear_t as nsswitch_domain - Fix bogus in interfaces - Allow openshift to read/write postfix public pipe - Add postfix_manage_spool_maildrop_files() interface - stickshift paths have been renamed to openshift - gnome-settings-daemon wants to write to /run/systemd/inhibit/ pipes - Update man pages, adding ENTRYPOINTS- Add mei_device_t - Make sure gpg content in homedir created with correct label - Allow dmesg to write to abrt cache files - automount wants to search virtual memory sysctls - Add support for hplip logs stored in /var/log/hp/tmp - Add labeling for /etc/owncloud/config.php - Allow setroubleshoot to send analysys to syslogd-journal - Allow virsh_t to interact with new fenced daemon - Allow gpg to write to /etc/mail/spamassassiin directories - Make dovecot_deliver_t a mail server delivery type - Add label for /var/tmp/DNS25- Fixes for tomcat_domain template interface- Remove init_systemd and init_upstart boolean, Move init_daemon_domain and init_system_domain to use attributes - Add attribute to all base os types. Allow all domains to read all ro base OS types- Additional unit files to be defined as power unit files - Fix more boolean names- Fix boolean name so subs will continue to work- dbus needs to start getty unit files - Add interface to allow system_dbusd_t to start the poweroff service - xdm wants to exec telepathy apps - Allow users to send messages to systemdlogind - Additional rules needed for systemd and other boot apps - systemd wants to list /home and /boot - Allow gkeyringd to write dbus/conf file - realmd needs to read /dev/urand - Allow readahead to delete /.readahead if labeled root_t, might get created before policy is loaded- Fixes to safe more rules - Re-write tomcat_domain_template() - Fix passenger labeling - Allow all domains to read man pages - Add ephemeral_port_t to the 'generic' port interfaces - Fix the names of postgresql booleans- Stop using attributes form netlabel_peer and syslog, auth_use_nsswitch setsup netlabel_peer - Move netlable_peer check out of booleans - Remove call to recvfrom_netlabel for kerberos call - Remove use of attributes when calling syslog call - Move -miscfiles_read_localization to domain.te to save hundreds of allow rules - Allow all domains to read locale files. This eliminates around 1500 allow rules- Cleanup nis_use_ypbind_uncond interface - Allow rndc to block suspend - tuned needs to modify the schedule of the kernel - Allow svirt_t domains to read alsa configuration files - ighten security on irc domains and make sure they label content in homedir correctly - Add filetrans_home_content for irc files - Dontaudit all getattr access for devices and filesystems for sandbox domains - Allow stapserver to search cgroups directories - Allow all postfix domains to talk to spamd- Add interfaces to ignore setattr until kernel fixes this to be checked after the DAC check - Change pam_t to pam_timestamp_t - Add dovecot_domain attribute and allow this attribute block_suspend capability2 - Add sanlock_use_fusefs boolean - numad wants send/recieve msg - Allow rhnsd to send syslog msgs - Make piranha-pulse as initrc domain - Update openshift instances to dontaudit setattr until the kernel is fixed.- Fix auth_login_pgm_domain() interface to allow domains also managed user tmp dirs because of #856880 related to pam_systemd - Remove pam_selinux.8 which conflicts with man page owned by the pam package - Allow glance-api to talk to mysql - ABRT wants to read Xorg.0.log if if it detects problem with Xorg - Fix gstreamer filename trans. interface- Man page fixes by Dan Walsh- Allow postalias to read postfix config files - Allow man2html to read man pages - Allow rhev-agentd to search all mountpoints - Allow rhsmcertd to read /dev/random - Add tgtd_stream_connect() interface - Add cyrus_write_data() interface - Dontaudit attempts by sandboxX clients connectiing to the xserver_port_t - Add port definition for tcp/81 as http_port_t - Fix /dev/twa labeling - Allow systemd to read modules config- Merge openshift policy - Allow xauth to read /dev/urandom - systemd needs to relabel content in /run/systemd directories - Files unconfined should be able to perform all services on all files - Puppet tmp file can be leaked to all domains - Dontaudit rhsmcertd-worker to search /root/.local - Allow chown capability for zarafa domains - Allow system cronjobs to runcon into openshift domains - Allow virt_bridgehelper_t to manage content in the svirt_home_t labeled directories- nmbd wants to create /var/nmbd - Stop transitioning out of anaconda and firstboot, just causes AVC messages - Allow clamscan to read /etc files - Allow bcfg2 to bind cyphesis port - heartbeat should be run as rgmanager_t instead of corosync_t - Add labeling for /etc/openldap/certs - Add labeling for /opt/sartest directory - Make crontab_t as userdom home reader - Allow tmpreaper to list admin_home dir - Add defition for imap_0 replay cache file - Add support for gitolite3 - Allow virsh_t to send syslog messages - allow domains that can read samba content to be able to list the directories also - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd - Separate out sandbox from sandboxX policy so we can disable it by default - Run dmeventd as lvm_t - Mounting on any directory requires setattr and write permissions - Fix use_nfs_home_dirs() boolean - New labels for pam_krb5 - Allow init and initrc domains to sys_ptrace since this is needed to look at processes not owned by uid 0 - Add realmd_dbus_chat to allow all apps that use nsswitch to talk to realmd- Separate sandbox policy into sandbox and sandboxX, and disable sandbox by default on fresh installs - Allow domains that can read etc_t to read etc_runtime_t - Allow all domains to use inherited tmpfiles- Allow realmd to read resolv.conf - Add pegasus_cache_t type - Label /usr/sbin/fence_virtd as virsh_exec_t - Add policy for pkcsslotd - Add support for cpglockd - Allow polkit-agent-helper to read system-auth-ac - telepathy-idle wants to read gschemas.compiled - Allow plymouthd to getattr on fs_t - Add slpd policy - Allow ksysguardproces to read/write config_usr_t- Fix labeling substitution so rpm will label /lib/systemd content correctly- Add file name transitions for ttyACM0 - spice-vdagent(d)'s are going to log over to syslog - Add sensord policy - Add more fixes for passenger policy related to puppet - Allow wdmd to create wdmd_tmpfs_t - Fix labeling for /var/run/cachefilesd\.pid - Add thumb_tmpfs_t files type- Allow svirt domains to manage the network since this is containerized - Allow svirt_lxc_net_t to send audit messages- Make "snmpwalk -mREDHAT-CLUSTER-MIB ...." working - Allow dlm_controld to execute dlm_stonith labeled as bin_t - Allow GFS2 working on F17 - Abrt needs to execute dmesg - Allow jockey to list the contents of modeprobe.d - Add policy for lightsquid as squid_cron_t - Mailscanner is creating files and directories in /tmp - dmesg is now reading /dev/kmsg - Allow xserver to communicate with secure_firmware - Allow fsadm tools (fsck) to read /run/mount contnet - Allow sysadm types to read /dev/kmsg -- Allow postfix, sssd, rpcd to block_suspend - udev seems to need secure_firmware capability - Allow virtd to send dbus messages to firewalld so it can configure the firewall- Fix labeling of content in /run created by virsh_t - Allow condor domains to read kernel sysctls - Allow condor_master to connect to amqp - Allow thumb drives to create shared memory and semaphores - Allow abrt to read mozilla_plugin config files - Add labels for lightsquid - Default files in /opt and /usr that end in .cgi as httpd_sys_script_t, allow - dovecot_auth_t uses ldap for user auth - Allow domains that can read dhcp_etc_t to read lnk_files - Add more then one watchdog device - Allow useradd_t to manage etc_t files so it can rename it and edit them - Fix invalid class dir should be fifo_file - Move /run/blkid to fsadm and make sure labeling is correct- Fix bogus regex found by eparis - Fix manage run interface since lvm needs more access - syslogd is searching cgroups directory - Fixes to allow virt-sandbox-service to manage lxc var run content- Fix Boolean settings - Add new libjavascriptcoregtk as textrel_shlib_t - Allow xdm_t to create xdm_home_t directories - Additional access required for systemd - Dontaudit mozilla_plugin attempts to ipc_lock - Allow tmpreaper to delete unlabeled files - Eliminate screen_tmp_t and allow it to manage user_tmp_t - Dontaudit mozilla_plugin_config_t to append to leaked file descriptors - Allow web plugins to connect to the asterisk ports - Condor will recreate the lock directory if it does not exist - Oddjob mkhomedir needs to connectto user processes - Make oddjob_mkhomedir_t a userdom home manager- Put placeholder back in place for proper numbering of capabilities - Systemd also configures init scripts- Fix ecryptfs interfaces - Bootloader seems to be trolling around /dev/shm and /dev - init wants to create /etc/systemd/system-update.target.wants - Fix systemd_filetrans call to move it out of tunable - Fix up policy to work with systemd userspace manager - Add secure_firmware capability and remove bogus epolwakeup - Call seutil_*_login_config interfaces where should be needed - Allow rhsmcertd to send signal to itself - Allow thin domains to send signal to itself - Allow Chrome_ChildIO to read dosfs_t- Add role rules for realmd, sambagui- Add new type selinux_login_config_t for /etc/selinux//logins/ - Additional fixes for seutil_manage_module_store() - dbus_system_domain() should be used with optional_policy - Fix svirt to be allowed to use fusefs file system - Allow login programs to read /run/ data created by systemd_login - sssd wants to write /etc/selinux//logins/ for SELinux PAM module - Fix svirt to be allowed to use fusefs file system - Allow piranha domain to use nsswitch - Sanlock needs to send Kill Signals to non root processes - Pulseaudio wants to execute /run/user/PID/.orc- Fix saslauthd when it tries to read /etc/shadow - Label gnome-boxes as a virt homedir - Need to allow svirt_t ability to getattr on nfs_t file systems - Update sanlock policy to solve all AVC's - Change confined users can optionally manage virt content - Handle new directories under ~/.cache - Add block suspend to appropriate domains - More rules required for containers - Allow login programs to read /run/ data created by systemd_logind - Allow staff users to run svirt_t processes- Update to upstream- More fixes for systemd to make rawhide booting from Dan Walsh- Add systemd fixes to make rawhide booting- Add systemd_logind_inhibit_var_run_t attribute - Remove corenet_all_recvfrom_unlabeled() for non-contrib policies because we moved it to domain.if for all domain_type - Add interface for mysqld to dontaudit signull to all processes - Label new /var/run/journal directory correctly - Allow users to inhibit suspend via systemd - Add new type for the /var/run/inhibit directory - Add interface to send signull to systemd_login so avahi can send them - Allow systemd_passwd to send syslog messages - Remove corenet_all_recvfrom_unlabeled() calling fro policy files - Allow editparams.cgi running as httpd_bugzilla_script_t to read /etc/group - Allow smbd to read cluster config - Add additional labeling for passenger - Allow dbus to inhibit suspend via systemd - Allow avahi to send signull to systemd_login- Add interface to dontaudit getattr access on sysctls - Allow sshd to execute /bin/login - Looks like xdm is recreating the xdm directory in ~/.cache/ on login - Allow syslog to use the leaked kernel_t unix_dgram_socket from system-jounald - Fix semanage to work with unconfined domain disabled on F18 - Dontaudit attempts by mozilla plugins to getattr on all kernel sysctls - Virt seems to be using lock files - Dovecot seems to be searching directories of every mountpoint - Allow jockey to read random/urandom, execute shell and install third-party drivers - Add aditional params to allow cachedfiles to manage its content - gpg agent needs to read /dev/random - The kernel hands an svirt domains /SYSxxxxx which is a tmpfs that httpd wants to read and write - Add a bunch of dontaudit rules to quiet svirt_lxc domains - Additional perms needed to run svirt_lxc domains - Allow cgclear to read cgconfig - Allow sys_ptrace capability for snmp - Allow freshclam to read /proc - Allow procmail to manage /home/user/Maildir content - Allow NM to execute wpa_cli - Allow amavis to read clamd system state - Regenerate man pages- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- Add realmd and stapserver policies - Allow useradd to manage stap-server lib files - Tighten up capabilities for confined users - Label /etc/security/opasswd as shadow_t - Add label for /dev/ecryptfs - Allow condor_startd_t to start sshd with the ranged - Allow lpstat.cups to read fips_enabled file - Allow pyzor running as spamc_t to create /root/.pyzor directory - Add labelinf for amavisd-snmp init script - Add support for amavisd-snmp - Allow fprintd sigkill self - Allow xend (w/o libvirt) to start virtual machines - Allow aiccu to read /etc/passwd - Allow condor_startd to Make specified domain MCS trusted for setting any category set for the processes it executes - Add condor_startd_ranged_domtrans_to() interface - Add ssd_conf_t for /etc/sssd - accountsd needs to fchown some files/directories - Add ICACLient and zibrauserdata as mozilla_filetrans_home_content - SELinux reports afs_t needs dac_override to read /etc/mtab, even though everything works, adding dontaudit - Allow xend_t to read the /etc/passwd file- Until we figure out how to fix systemd issues, allow all apps that send syslog messages to send them to kernel_t - Add init_access_check() interface - Fix label on /usr/bin/pingus to not be labeled as ping_exec_t - Allow tcpdump to create a netlink_socket - Label newusers like useradd - Change xdm log files to be labeled xdm_log_t - Allow sshd_t with privsep to work in MLS - Allow freshclam to update databases thru HTTP proxy - Allow s-m-config to access check on systemd - Allow abrt to read public files by default - Fix amavis_create_pid_files() interface - Add labeling and filename transition for dbomatic.log - Allow system_dbusd_t to stream connect to bluetooth, and use its socket - Allow amavisd to execute fsav - Allow tuned to use sys_admin and sys_nice capabilities - Add php-fpm policy from Bryan - Add labeling for aeolus-configserver-thinwrapper - Allow thin domains to execute shell - Fix gnome_role_gkeyringd() interface description - Lot of interface fixes - Allow OpenMPI job running as condor_startd_ssh_t to manage condor lib files - Allow OpenMPI job to use kerberos - Make deltacloudd_t as nsswitch_domain - Allow xend_t to run lsscsi - Allow qemu-dm running as xend_t to create tun_socket - Add labeling for /opt/brother/Printers(.*/)?inf - Allow jockey-backend to read pyconfig-64.h labeled as usr_t - Fix clamscan_can_scan_system boolean - Allow lpr to connectto to /run/user/$USER/keyring-22uREb/pkcs11- initrc is calling exportfs which is not confined so it attempts to read nfsd_files - Fixes for passenger running within openshift. - Add labeling for all tomcat6 dirs - Add support for tomcat6 - Allow cobblerd to read /etc/passwd - Allow jockey to read sysfs and and execute binaries with bin_t - Allow thum to use user terminals - Allow cgclear to read cgconfig config files - Fix bcf2g.fc - Remove sysnet_dns_name_resolve() from policies where auth_use_nsswitch() is used for other domains - Allow dbomatic to execute ruby - abrt_watch_log should be abrt_domain - Allow mozilla_plugin to connect to gatekeeper port- add ptrace_child access to process - remove files_read_etc_files() calling from all policies which have auth_use_nsswith() - Allow boinc domains to manage boinc_lib_t lnk_files - Add support for boinc-client.service unit file - Add support for boinc.log - Allow mozilla_plugin execmod on mozilla home files if allow_ex - Allow dovecot_deliver_t to read dovecot_var_run_t - Allow ldconfig and insmod to manage kdumpctl tmp files - Move thin policy out from cloudform.pp and add a new thin poli - pacemaker needs to communicate with corosync streams - abrt is now started on demand by dbus - Allow certmonger to talk directly to Dogtag servers - Change labeling for /var/lib/cobbler/webui_sessions to httpd_c - Allow mozila_plugin to execute gstreamer home files - Allow useradd to delete all file types stored in the users hom - rhsmcertd reads the rpm database - Add support for lightdm- Add tomcat policy - Remove pyzor/razor policy - rhsmcertd reads the rpm database - Dontaudit thumb to setattr on xdm_tmp dir - Allow wicd to execute ldconfig in the networkmanager_t domain - Add /var/run/cherokee\.pid labeling - Allow mozilla_plugin to create mozilla_plugin_tmp_t lnk files too - Allow postfix-master to r/w pipes other postfix domains - Allow snort to create netlink_socket - Add kdumpctl policy - Allow firstboot to create tmp_t files/directories - /usr/bin/paster should not be labeled as piranha_exec_t - remove initrc_domain from tomcat - Allow ddclient to read /etc/passwd - Allow useradd to delete all file types stored in the users homedir - Allow ldconfig and insmod to manage kdumpctl tmp files - Firstboot should be just creating tmp_t dirs and xauth should be allowed to write to those - Transition xauth files within firstboot_tmp_t - Fix labeling of /run/media to match /media - Label all lxdm.log as xserver_log_t - Add port definition for mxi port - Allow local_login_t to execute tmux- apcupsd needs to read /etc/passwd - Sanlock allso sends sigkill - Allow glance_registry to connect to the mysqld port - Dontaudit mozilla_plugin trying to getattr on /dev/gpmctl - Allow firefox plugins/flash to connect to port 1234 - Allow mozilla plugins to delete user_tmp_t files - Add transition name rule for printers.conf.O - Allow virt_lxc_t to read urand - Allow systemd_loigind to list gstreamer_home_dirs - Fix labeling for /usr/bin - Fixes for cloudform services * support FIPS - Allow polipo to work as web caching - Allow chfn to execute tmux- Add support for ecryptfs * ecryptfs does not support xattr * we need labeling for HOMEDIR - Add policy for (u)mount.ecryptfs* - Fix labeling of kerbero host cache files, allow rpc.svcgssd to manage host cache - Allow dovecot to manage Maildir content, fix transitions to Maildir - Allow postfix_local to transition to dovecot_deliver - Dontaudit attempts to setattr on xdm_tmp_t, looks like bogus code - Cleanup interface definitions - Allow apmd to change with the logind daemon - Changes required for sanlock in rhel6 - Label /run/user/apache as httpd_tmp_t - Allow thumb to use lib_t as execmod if boolean turned on - Allow squid to create the squid directory in /var with the correct labe - Add a new policy for glusterd from Bryan Bickford (bbickfor@redhat.com) - Allow virtd to exec xend_exec_t without transition - Allow virtd_lxc_t to unmount all file systems- PolicyKit path has changed - Allow httpd connect to dirsrv socket - Allow tuned to write generic kernel sysctls - Dontaudit logwatch to gettr on /dev/dm-2 - Allow policykit-auth to manage kerberos files - Make condor_startd and rgmanager as initrc domain - Allow virsh to read /etc/passwd - Allow mount to mount on user_tmp_t for /run/user/dwalsh/gvfs - xdm now needs to execute xsession_exec_t - Need labels for /var/lib/gdm - Fix files_filetrans_named_content() interface - Add new attribute - initrc_domain - Allow systemd_logind_t to signal, signull, sigkill all processes - Add filetrans rules for etc_runtime files- Rename boolean names to remove allow_- Mass merge with upstream * new policy topology to include contrib policy modules * we have now two base policy patches- Fix description of authlogin_nsswitch_use_ldap - Fix transition rule for rhsmcertd_t needed for RHEL7 - Allow useradd to list nfs state data - Allow openvpn to manage its log file and directory - We want vdsm to transition to mount_t when executing mount command to make sure /etc/mtab remains labeled correctly - Allow thumb to use nvidia devices - Allow local_login to create user_tmp_t files for kerberos - Pulseaudio needs to read systemd_login /var/run content - virt should only transition named system_conf_t config files - Allow munin to execute its plugins - Allow nagios system plugin to read /etc/passwd - Allow plugin to connect to soundd port - Fix httpd_passwd to be able to ask passwords - Radius servers can use ldap for backing store - Seems to need to mount on /var/lib for xguest polyinstatiation to work. - Allow systemd_logind to list the contents of gnome keyring - VirtualGL need xdm to be able to manage content in /etc/opt/VirtualGL - Add policy for isns-utils- Add policy for subversion daemon - Allow boinc to read passwd - Allow pads to read kernel network state - Fix man2html interface for sepolgen-ifgen - Remove extra /usr/lib/systemd/system/smb - Remove all /lib/systemd and replace with /usr/lib/systemd - Add policy for man2html - Fix the label of kerberos_home_t to krb5_home_t - Allow mozilla plugins to use Citrix - Allow tuned to read /proc/sys/kernel/nmi_watchdog - Allow tune /sys options via systemd's tmpfiles.d "w" type- Dontaudit lpr_t to read/write leaked mozilla tmp files - Add file name transition for .grl-podcasts directory - Allow corosync to read user tmp files - Allow fenced to create snmp lib dirs/files - More fixes for sge policy - Allow mozilla_plugin_t to execute any application - Allow dbus to read/write any open file descriptors to any non security file on the system that it inherits to that it can pass them to another domain - Allow mongod to read system state information - Fix wrong type, we should dontaudit sys_admin for xdm_t not xserver_t - Allow polipo to manage polipo_cache dirs - Add jabbar_client port to mozilla_plugin_t - Cleanup procmail policy - system bus will pass around open file descriptors on files that do not have labels on them - Allow l2tpd_t to read system state - Allow tuned to run ls /dev - Allow sudo domains to read usr_t files - Add label to machine-id - Fix corecmd_read_bin_symlinks cut and paste error- Fix pulseaudio port definition - Add labeling for condor_starter - Allow chfn_t to creat user_tmp_files - Allow chfn_t to execute bin_t - Allow prelink_cron_system_t to getpw calls - Allow sudo domains to manage kerberos rcache files - Allow user_mail_domains to work with courie - Port definitions necessary for running jboss apps within openshift - Add support for openstack-nova-metadata-api - Add support for nova-console* - Add support for openstack-nova-xvpvncproxy - Fixes to make privsep+SELinux working if we try to use chage to change passwd - Fix auth_role() interface - Allow numad to read sysfs - Allow matahari-rpcd to execute shell - Add label for ~/.spicec - xdm is executing lspci as root which is requesting a sys_admin priv but seems to succeed without it - Devicekit_disk wants to read the logind sessions file when writing a cd - Add fixes for condor to make condor jobs working correctly - Change label of /var/log/rpmpkgs to cron_log_t - Access requires to allow systemd-tmpfiles --create to work. - Fix obex to be a user application started by the session bus. - Add additional filename trans rules for kerberos - Fix /var/run/heartbeat labeling - Allow apps that are managing rcache to file trans correctly - Allow openvpn to authenticate against ldap server - Containers need to listen to network starting and stopping events- Make systemd unit files less specific- Fix zarafa labeling - Allow guest_t to fix labeling - corenet_tcp_bind_all_unreserved_ports(ssh_t) should be called with the user_tcp_server boolean - add lxc_contexts - Allow accountsd to read /proc - Allow restorecond to getattr on all file sytems - tmpwatch now calls getpw - Allow apache daemon to transition to pwauth domain - Label content under /var/run/user/NAME/keyring* as gkeyringd_tmp_t - The obex socket seems to be a stream socket - dd label for /var/run/nologin- Allow jetty running as httpd_t to read hugetlbfs files - Allow sys_nice and setsched for rhsmcertd - Dontaudit attempts by mozilla_plugin_t to bind to ssdp ports - Allow setfiles to append to xdm_tmp_t - Add labeling for /export as a usr_t directory - Add labels for .grl files created by gstreamer- Add labeling for /usr/share/jetty/bin/jetty.sh - Add jetty policy which contains file type definitios - Allow jockey to use its own fifo_file and make this the default for all domains - Allow mozilla_plugins to use spice (vnc_port/couchdb) - asterisk wants to read the network state - Blueman now uses /var/lib/blueman- Add label for nodejs_debug - Allow mozilla_plugin_t to create ~/.pki directory and content- Add clamscan_can_scan_system boolean - Allow mysqld to read kernel network state - Allow sshd to read/write condor lib files - Allow sshd to read/write condor-startd tcp socket - Fix description on httpd_graceful_shutdown - Allow glance_registry to communicate with mysql - dbus_system_domain is using systemd to lauch applications - add interfaces to allow domains to send kill signals to user mail agents - Remove unnessary access for svirt_lxc domains, add privs for virtd_lxc_t - Lots of new access required for secure containers - Corosync needs sys_admin capability - ALlow colord to create shm - .orc should be allowed to be created by any app that can create gstream home content, thumb_t to be specific - Add boolean to control whether or not mozilla plugins can create random content in the users homedir - Add new interface to allow domains to list msyql_db directories, needed for libra - shutdown has to be allowed to delete etc_runtime_t - Fail2ban needs to read /etc/passwd - Allow ldconfig to create /var/cache/ldconfig - Allow tgtd to read hardware state information - Allow collectd to create packet socket - Allow chronyd to send signal to itself - Allow collectd to read /dev/random - Allow collectd to send signal to itself - firewalld needs to execute restorecon - Allow restorecon and other login domains to execute restorecon- Allow logrotate to getattr on systemd unit files - Add support for tor systemd unit file - Allow apmd to create /var/run/pm-utils with the correct label - Allow l2tpd to send sigkill to pppd - Allow pppd to stream connect to l2tpd - Add label for scripts in /etc/gdm/ - Allow systemd_logind_t to ignore mcs constraints on sigkill - Fix files_filetrans_system_conf_named_files() interface - Add labels for /usr/share/wordpress/wp-includes/*.php - Allow cobbler to get SELinux mode and booleans- Add unconfined_execmem_exec_t as an alias to bin_t - Allow fenced to read snmp var lib files, also allow it to read usr_t - ontaudit access checks on all executables from mozilla_plugin - Allow all user domains to setexec, so that sshd will work properly if it call setexec(NULL) while running withing a user mode - Allow systemd_tmpfiles_t to getattr all pipes and sockets - Allow glance-registry to send system log messages - semanage needs to manage mock lib files/dirs- Add policy for abrt-watch-log - Add definitions for jboss_messaging ports - Allow systemd_tmpfiles to manage printer devices - Allow oddjob to use nsswitch - Fix labeling of log files for postgresql - Allow mozilla_plugin_t to execmem and execstack by default - Allow firewalld to execute shell - Fix /etc/wicd content files to get created with the correct label - Allow mcelog to exec shell - Add ~/.orc as a gstreamer_home_t - /var/spool/postfix/lib64 should be labeled lib_t - mpreaper should be able to list all file system labeled directories - Add support for apache to use openstack - Add labeling for /etc/zipl.conf and zipl binary - Turn on allow_execstack and turn off telepathy transition for final release- More access required for virt_qmf_t - Additional assess required for systemd-logind to support multi-seat - Allow mozilla_plugin to setrlimit - Revert changes to fuse file system to stop deadlock- Allow condor domains to connect to ephemeral ports - More fixes for condor policy - Allow keystone to stream connect to mysqld - Allow mozilla_plugin_t to read generic USB device to support GPS devices - Allow thum to file name transition gstreamer home content - Allow thum to read all non security files - Allow glance_api_t to connect to ephemeral ports - Allow nagios plugins to read /dev/urandom - Allow syslogd to search postfix spool to support postfix chroot env - Fix labeling for /var/spool/postfix/dev - Allow wdmd chown - Label .esd_auth as pulseaudio_home_t - Have no idea why keyring tries to write to /run/user/dwalsh/dconf/user, but we can dontaudit for now- Add support for clamd+systemd - Allow fresclam to execute systemctl to handle clamd - Change labeling for /usr/sbin/rpc.ypasswd.env - Allow yppaswd_t to execute yppaswd_exec_t - Allow yppaswd_t to read /etc/passwd - Gnomekeyring socket has been moved to /run/user/USER/ - Allow samba-net to connect to ldap port - Allow signal for vhostmd - allow mozilla_plugin_t to read user_home_t socket - New access required for secure Linux Containers - zfs now supports xattrs - Allow quantum to execute sudo and list sysfs - Allow init to dbus chat with the firewalld - Allow zebra to read /etc/passwd- Allow svirt_t to create content in the users homedir under ~/.libvirt - Fix label on /var/lib/heartbeat - Allow systemd_logind_t to send kill signals to all processes started by a user - Fuse now supports Xattr Support- upowered needs to setsched on the kernel - Allow mpd_t to manage log files - Allow xdm_t to create /var/run/systemd/multi-session-x - Add rules for missedfont.log to be used by thumb.fc - Additional access required for virt_qmf_t - Allow dhclient to dbus chat with the firewalld - Add label for lvmetad - Allow systemd_logind_t to remove userdomain sock_files - Allow cups to execute usr_t files - Fix labeling on nvidia shared libraries - wdmd_t needs access to sssd and /etc/passwd - Add boolean to allow ftp servers to run in passive mode - Allow namepspace_init_t to relabelto/from a different user system_u from the user the namespace_init running with - Fix using httpd_use_fusefs - Allow chrome_sandbox_nacl to write inherited user tmp files as we allow it for chrome_sandbox- Rename rdate port to time port, and allow gnomeclock to connect to it - We no longer need to transition to ldconfig from rpm, rpm_script, or anaconda - /etc/auto.* should be labeled bin_t - Add httpd_use_fusefs boolean - Add fixes for heartbeat - Allow sshd_t to signal processes that it transitions to - Add condor policy - Allow svirt to create monitors in ~/.libvirt - Allow dovecot to domtrans sendmail to handle sieve scripts - Lot of fixes for cfengine- /var/run/postmaster.* labeling is no longer needed - Alllow drbdadmin to read /dev/urandom - l2tpd_t seems to use ptmx - group+ and passwd+ should be labeled as /etc/passwd - Zarafa-indexer is a socket- Ensure lastlog is labeled correctly - Allow accountsd to read /proc data about gdm - Add fixes for tuned - Add bcfg2 fixes which were discovered during RHEL6 testing - More fixes for gnome-keyring socket being moved - Run semanage as a unconfined domain, and allow initrc_t to create tmpfs_t sym links on shutdown - Fix description for files_dontaudit_read_security_files() interface- Add new policy and man page for bcfg2 - cgconfig needs to use getpw calls - Allow domains that communicate with the keyring to use cache_home_t instead of gkeyringd_tmpt - gnome-keyring wants to create a directory in cache_home_t - sanlock calls getpw- Add numad policy and numad man page - Add fixes for interface bugs discovered by SEWatch - Add /tmp support for squid - Add fix for #799102 * change default labeling for /var/run/slapd.* sockets - Make thumb_t as userdom_home_reader - label /var/lib/sss/mc same as pubconf, so getpw domains can read it - Allow smbspool running as cups_t to stream connect to nmbd - accounts needs to be able to execute passwd on behalf of users - Allow systemd_tmpfiles_t to delete boot flags - Allow dnssec_trigger to connect to apache ports - Allow gnome keyring to create sock_files in ~/.cache - google_authenticator is using .google_authenticator - sandbox running from within firefox is exposing more leaks - Dontaudit thumb to read/write /dev/card0 - Dontaudit getattr on init_exec_t for gnomeclock_t - Allow certmonger to do a transition to certmonger_unconfined_t - Allow dhcpc setsched which is caused by nmcli - Add rpm_exec_t for /usr/sbin/bcfg2 - system cronjobs are sending dbus messages to systemd_logind - Thumnailers read /dev/urand- Allow auditctl getcap - Allow vdagent to use libsystemd-login - Allow abrt-dump-oops to search /etc/abrt - Got these avc's while trying to print a boarding pass from firefox - Devicekit is now putting the media directory under /run/media - Allow thumbnailers to create content in ~/.thumbails directory - Add support for proL2TPd by Dominick Grift - Allow all domains to call getcap - wdmd seems to get a random chown capability check that it does not need - Allow vhostmd to read kernel sysctls- Allow chronyd to read unix - Allow hpfax to read /etc/passwd - Add support matahari vios-proxy-* apps and add virtd_exec_t label for them - Allow rpcd to read quota_db_t - Update to man pages to match latest policy - Fix bug in jockey interface for sepolgen-ifgen - Add initial svirt_prot_exec_t policy- More fixes for systemd from Dan Walsh- Add a new type for /etc/firewalld and allow firewalld to write to this directory - Add definition for ~/Maildir, and allow mail deliver domains to write there - Allow polipo to run from a cron job - Allow rtkit to schedule wine processes - Allow mozilla_plugin_t to acquire a bug, and allow it to transition gnome content in the home dir to the proper label - Allow users domains to send signals to consolehelper domains- More fixes for boinc policy - Allow polipo domain to create its own cache dir and pid file - Add systemctl support to httpd domain - Add systemctl support to polipo, allow NetworkManager to manage the service - Add policy for jockey-backend - Add support for motion daemon which is now covered by zoneminder policy - Allow colord to read/write motion tmpfs - Allow vnstat to search through var_lib_t directories - Stop transitioning to quota_t, from init an sysadm_t- Add svirt_lxc_file_t as a customizable type- Add additional fixes for icmp nagios plugin - Allow cron jobs to open fifo_files from cron, since service script opens /dev/stdin - Add certmonger_unconfined_exec_t - Make sure tap22 device is created with the correct label - Allow staff users to read systemd unit files - Merge in previously built policy - Arpwatch needs to be able to start netlink sockets in order to start - Allow cgred_t to sys_ptrace to look at other DAC Processes- Back port some of the access that was allowed in nsplugin_t - Add definitiona for couchdb ports - Allow nagios to use inherited users ttys - Add git support for mock - Allow inetd to use rdate port - Add own type for rdate port - Allow samba to act as a portmapper - Dontaudit chrome_sandbox attempts to getattr on chr_files in /dev - New fixes needed for samba4 - Allow apps that use lib_t to read lib_t symlinks- Add policy for nove-cert - Add labeling for nova-openstack systemd unit files - Add policy for keystoke- Fix man pages fro domains - Add man pages for SELinux users and roles - Add storage_dev_filetrans_named_fixed_disk() and use it for smartmon - Add policy for matahari-rpcd - nfsd executes mount command on restart - Matahari domains execute renice and setsched - Dontaudit leaked tty in mozilla_plugin_config - mailman is changing to a per instance naming - Add 7600 and 4447 as jboss_management ports - Add fixes for nagios event handlers - Label httpd.event as httpd_exec_t, it is an apache daemon- Add labeling for /var/spool/postfix/dev/log - NM reads sysctl.conf - Iscsi log file context specification fix - Allow mozilla plugins to send dbus messages to user domains that transition to it - Allow mysql to read the passwd file - Allow mozilla_plugin_t to create mozilla home dirs in user homedir - Allow deltacloud to read kernel sysctl - Allow postgresql_t to connectto itselfAllow postgresql_t to connectto itself - Allow postgresql_t to connectto itself - Add login_userdomain attribute for users which can log in using terminal- Allow sysadm_u to reach system_r by default #784011 - Allow nagios plugins to use inherited user terminals - Razor labeling is not used no longer - Add systemd support for matahari - Add port_types to man page, move booleans to the top, fix some english - Add support for matahari-sysconfig-console - Clean up matahari.fc - Fix matahari_admin() interfac - Add labels for/etc/ssh/ssh_host_*.pub keys- Allow ksysguardproces to send system log msgs - Allow boinc setpgid and signull - Allow xdm_t to sys_ptrace to run pidof command - Allow smtpd_t to manage spool files/directories and symbolic links - Add labeling for jetty - Needed changes to get unbound/dnssec to work with openswan- Add user_fonts_t alias xfs_tmp_t - Since depmod now runs as insmod_t we need to write to kernel_object_t - Allow firewalld to dbus chat with networkmanager - Allow qpidd to connect to matahari ports - policykit needs to read /proc for uses not owned by it - Allow systemctl apps to connecto the init stream- Turn on deny_ptrace boolean- Remove pam_selinux.8 man page. There was a conflict.- Add proxy class and read access for gssd_proxy - Separate out the sharing public content booleans - Allow certmonger to execute a script and send signals to apache and dirsrv to reload the certificate - Add label transition for gstream-0.10 and 12 - Add booleans to allow rsync to share nfs and cifs file sytems - chrome_sandbox wants to read the /proc/PID/exe file of the program that executed it - Fix filename transitions for cups files - Allow denyhosts to read "unix" - Add file name transition for locale.conf.new - Allow boinc projects to gconf config files - sssd needs to be able to increase the socket limit under certain loads - sge_execd needs to read /etc/passwd - Allow denyhost to check network state - NetworkManager needs to read sessions data - Allow denyhost to check network state - Allow xen to search virt images directories - Add label for /dev/megaraid_sas_ioctl_node - Add autogenerated man pages- Allow boinc project to getattr on fs - Allow init to execute initrc_state_t - rhev-agent package was rename to ovirt-guest-agent - If initrc_t creates /etc/local.conf then we need to make sure it is labeled correctly - sytemd writes content to /run/initramfs and executes it on shutdown - kdump_t needs to read /etc/mtab, should be back ported to F16 - udev needs to load kernel modules in early system boot- Need to add sys_ptrace back in since reading any content in /proc can cause these accesses - Add additional systemd interfaces which are needed fro *_admin interfaces - Fix bind_admin() interface- Allow firewalld to read urand - Alias java, execmem_mono to bin_t to allow third parties - Add label for kmod - /etc/redhat-lsb contains binaries - Add boolean to allow gitosis to send mail - Add filename transition also for "event20" - Allow systemd_tmpfiles_t to delete all file types - Allow collectd to ipc_lock- make consoletype_exec optional, so we can remove consoletype policy - remove unconfined_permisive.patch - Allow openvpn_t to inherit user home content and tmp content - Fix dnssec-trigger labeling - Turn on obex policy for staff_t - Pem files should not be secret - Add lots of rules to fix AVC's when playing with containers - Fix policy for dnssec - Label ask-passwd directories correctly for systemd- sshd fixes seem to be causing unconfined domains to dyntrans to themselves - fuse file system is now being mounted in /run/user - systemd_logind is sending signals to processes that are dbus messaging with it - Add support for winshadow port and allow iscsid to connect to this port - httpd should be allowed to bind to the http_port_t udp socket - zarafa_var_lib_t can be a lnk_file - A couple of new .xsession-errors files - Seems like user space and login programs need to read logind_sessions_files - Devicekit disk seems to be being launched by systemd - Cleanup handling of setfiles so most of rules in te file - Correct port number for dnssec - logcheck has the home dir set to its cache- Add policy for grindengine MPI jobs- Add new sysadm_secadm.pp module * contains secadm definition for sysadm_t - Move user_mail_domain access out of the interface into the te file - Allow httpd_t to create httpd_var_lib_t directories as well as files - Allow snmpd to connect to the ricci_modcluster stream - Allow firewalld to read /etc/passwd - Add auth_use_nsswitch for colord - Allow smartd to read network state - smartdnotify needs to read /etc/group- Allow gpg and gpg_agent to store sock_file in gpg_secret_t directory - lxdm startup scripts should be labeled bin_t, so confined users will work - mcstransd now creates a pid, needs back port to F16 - qpidd should be allowed to connect to the amqp port - Label devices 010-029 as usb devices - ypserv packager says ypserv does not use tmp_t so removing selinux policy types - Remove all ptrace commands that I believe are caused by the kernel/ps avcs - Add initial Obex policy - Add logging_syslogd_use_tty boolean - Add polipo_connect_all_unreserved bolean - Allow zabbix to connect to ftp port - Allow systemd-logind to be able to switch VTs - Allow apache to communicate with memcached through a sock_file- Fix file_context.subs_dist for now to work with pre usrmove- More /usr move fixes- Add zabbix_can_network boolean - Add httpd_can_connect_zabbix boolean - Prepare file context labeling for usrmove functions - Allow system cronjobs to read kernel network state - Add support for selinux_avcstat munin plugin - Treat hearbeat with corosync policy - Allow corosync to read and write to qpidd shared mem - mozilla_plugin is trying to run pulseaudio - Fixes for new sshd patch for running priv sep domains as the users context - Turn off dontaudit rules when turning on allow_ypbind - udev now reads /etc/modules.d directory- Turn on deny_ptrace boolean for the Rawhide run, so we can test this out - Cups exchanges dbus messages with init - udisk2 needs to send syslog messages - certwatch needs to read /etc/passwd- Add labeling for udisks2 - Allow fsadmin to communicate with the systemd process- Treat Bip with bitlbee policy * Bip is an IRC proxy - Add port definition for interwise port - Add support for ipa_memcached socket - systemd_jounald needs to getattr on all processes - mdadmin fixes * uses getpw - amavisd calls getpwnam() - denyhosts calls getpwall()- Setup labeling of /var/rsa and /var/lib/rsa to allow login programs to write there - bluetooth says they do not use /tmp and want to remove the type - Allow init to transition to colord - Mongod needs to read /proc/sys/vm/zone_reclaim_mode - Allow postfix_smtpd_t to connect to spamd - Add boolean to allow ftp to connect to all ports > 1023 - Allow sendmain to write to inherited dovecot tmp files - setroubleshoot needs to be able to execute rpm to see what version of packages- Merge systemd patch - systemd-tmpfiles wants to relabel /sys/devices/system/cpu/online - Allow deltacloudd dac_override, setuid, setgid caps - Allow aisexec to execute shell - Add use_nfs_home_dirs boolean for ssh-keygen- Fixes to make rawhide boot in enforcing mode with latest systemd changes- Add labeling for /var/run/systemd/journal/syslog - libvirt sends signals to ifconfig - Allow domains that read logind session files to list them- Fixed destined form libvirt-sandbox - Allow apps that list sysfs to also read sympolicy links in this filesystem - Add ubac_constrained rules for chrome_sandbox - Need interface to allow domains to use tmpfs_t files created by the kernel, used by libra - Allow postgresql to be executed by the caller - Standardize interfaces of daemons - Add new labeling for mm-handler - Allow all matahari domains to read network state and etc_runtime_t files- New fix for seunshare, requires seunshare_domains to be able to mounton / - Allow systemctl running as logrotate_t to connect to private systemd socket - Allow tmpwatch to read meminfo - Allow rpc.svcgssd to read supported_krb5_enctype - Allow zarafa domains to read /dev/random and /dev/urandom - Allow snmpd to read dev_snmp6 - Allow procmail to talk with cyrus - Add fixes for check_disk and check_nagios plugins- default trans rules for Rawhide policy - Make sure sound_devices controlC* are labeled correctly on creation - sssd now needs sys_admin - Allow snmp to read all proc_type - Allow to setup users homedir with quota.group- Add httpd_can_connect_ldap() interface - apcupsd_t needs to use seriel ports connected to usb devices - Kde puts procmail mail directory under ~/.local/share - nfsd_t can trigger sys_rawio on tests that involve too many mountpoints, dontaudit for now - Add labeling for /sbin/iscsiuio- Add label for /var/lib/iscan/interpreter - Dont audit writes to leaked file descriptors or redirected output for nacl - NetworkManager needs to write to /sys/class/net/ib*/mode- Allow abrt to request the kernel to load a module - Make sure mozilla content is labeled correctly - Allow tgtd to read system state - More fixes for boinc * allow to resolve dns name * re-write boinc policy to use boinc_domain attribute - Allow munin services plugins to use NSCD services- Allow mozilla_plugin_t to manage mozilla_home_t - Allow ssh derived domain to execute ssh-keygen in the ssh_keygen_t domain - Add label for tumblerd- Fixes for xguest package- Fixes related to /bin, /sbin - Allow abrt to getattr on blk files - Add type for rhev-agent log file - Fix labeling for /dev/dmfm - Dontaudit wicd leaking - Allow systemd_logind_t to look at process info of apps that exchange dbus messages with it - Label /etc/locale.conf correctly - Allow user_mail_t to read /dev/random - Allow postfix-smtpd to read MIMEDefang - Add label for /var/log/suphp.log - Allow swat_t to connect and read/write nmbd_t sock_file - Allow systemd-tmpfiles to setattr for /run/user/gdm/dconf - Allow systemd-tmpfiles to change user identity in object contexts - More fixes for rhev_agentd_t consolehelper policy- Use fs_use_xattr for squashf - Fix procs_type interface - Dovecot has a new fifo_file /var/run/dovecot/stats-mail - Dovecot has a new fifo_file /var/run/stats-mail - Colord does not need to connect to network - Allow system_cronjob to dbus chat with NetworkManager - Puppet manages content, want to make sure it labels everything correctly- Change port 9050 to tor_socks_port_t and then allow openvpn to connect to it - Allow all postfix domains to use the fifo_file - Allow sshd_t to getattr on all file systems in order to generate avc on nfs_t - Allow apmd_t to read grub.cfg - Let firewallgui read the selinux config - Allow systemd-tmpfiles to delete content in /root that has been moved to /tmp - Fix devicekit_manage_pid_files() interface - Allow squid to check the network state - Dontaudit colord getattr on file systems - Allow ping domains to read zabbix_tmp_t files- Allow mcelog_t to create dir and file in /var/run and label it correctly - Allow dbus to manage fusefs - Mount needs to read process state when mounting gluster file systems - Allow collectd-web to read collectd lib files - Allow daemons and system processes started by init to read/write the unix_stream_socket passed in from as stdin/stdout/stderr - Allow colord to get the attributes of tmpfs filesystem - Add sanlock_use_nfs and sanlock_use_samba booleans - Add bin_t label for /usr/lib/virtualbox/VBoxManage- Add ssh_dontaudit_search_home_dir - Changes to allow namespace_init_t to work - Add interface to allow exec of mongod, add port definition for mongod port, 27017 - Label .kde/share/apps/networkmanagement/certificates/ as home_cert_t - Allow spamd and clamd to steam connect to each other - Add policy label for passwd.OLD - More fixes for postfix and postfix maildro - Add ftp support for mozilla plugins - Useradd now needs to manage policy since it calls libsemanage - Fix devicekit_manage_log_files() interface - Allow colord to execute ifconfig - Allow accountsd to read /sys - Allow mysqld-safe to execute shell - Allow openct to stream connect to pcscd - Add label for /var/run/nm-dns-dnsmasq\.conf - Allow networkmanager to chat with virtd_t- Pulseaudio changes - Merge patches- Merge patches back into git repository.- Remove allow_execmem boolean and replace with deny_execmem boolean- Turn back on allow_execmem boolean- Add more MCS fixes to make sandbox working - Make faillog MLS trusted to make sudo_$1_t working - Allow sandbox_web_client_t to read passwd_file_t - Add .mailrc file context - Remove execheap from openoffice domain - Allow chrome_sandbox_nacl_t to read cpu_info - Allow virtd to relabel generic usb which is need if USB device - Fixes for virt.if interfaces to consider chr_file as image file type- Remove Open Office policy - Remove execmem policy- MCS fixes - quota fixes- Remove transitions to consoletype- Make nvidia* to be labeled correctly - Fix abrt_manage_cache() interface - Make filetrans rules optional so base policy will build - Dontaudit chkpwd_t access to inherited TTYS - Make sure postfix content gets created with the correct label - Allow gnomeclock to read cgroup - Fixes for cloudform policy- Check in fixed for Chrome nacl support- Begin removing qemu_t domain, we really no longer need this domain. - systemd_passwd needs dac_overide to communicate with users TTY's - Allow svirt_lxc domains to send kill signals within their container- Remove qemu.pp again without causing a crash- Remove qemu.pp, everything should use svirt_t or stay in its current domain- Allow policykit to talk to the systemd via dbus - Move chrome_sandbox_nacl_t to permissive domains - Additional rules for chrome_sandbox_nacl- Change bootstrap name to nacl - Chrome still needs execmem - Missing role for chrome_sandbox_bootstrap - Add boolean to remove execmem and execstack from virtual machines - Dontaudit xdm_t doing an access_check on etc_t directories- Allow named to connect to dirsrv by default - add ldapmap1_0 as a krb5_host_rcache_t file - Google chrome developers asked me to add bootstrap policy for nacl stuff - Allow rhev_agentd_t to getattr on mountpoints - Postfix_smtpd_t needs access to milters and cleanup seems to read/write postfix_smtpd_t unix_stream_sockets- Fixes for cloudform policies which need to connect to random ports - Make sure if an admin creates modules content it creates them with the correct label - Add port 8953 as a dns port used by unbound - Fix file name transition for alsa and confined users- Turn on mock_t and thumb_t for unconfined domains- Policy update should not modify local contexts- Remove ada policy- Remove tzdata policy - Add labeling for udev - Add cloudform policy - Fixes for bootloader policy- Add policies for nova openstack- Add fixes for nova-stack policy- Allow svirt_lxc_domain to chr_file and blk_file devices if they are in the domain - Allow init process to setrlimit on itself - Take away transition rules for users executing ssh-keygen - Allow setroubleshoot_fixit_t to read /dev/urand - Allow sshd to relbale tunnel sockets - Allow fail2ban domtrans to shorewall in the same way as with iptables - Add support for lnk files in the /var/lib/sssd directory - Allow system mail to connect to courier-authdaemon over an unix stream socket- Add passwd_file_t for /etc/ptmptmp- Dontaudit access checks for all executables, gnome-shell is doing access(EXEC, X_OK) - Make corosync to be able to relabelto cluster lib fies - Allow samba domains to search /var/run/nmbd - Allow dirsrv to use pam - Allow thumb to call getuid - chrome less likely to get mmap_zero bug so removing dontaudit - gimp help-browser has built in javascript - Best guess is that devices named /dev/bsr4096 should be labeled as cpu_device_t - Re-write glance policy- Move dontaudit sys_ptrace line from permissive.te to domain.te - Remove policy for hal, it no longer exists- Don't check md5 size or mtime on certain config files- Remove allow_ptrace and replace it with deny_ptrace, which will remove all ptrace from the system - Remove 2000 dontaudit rules between confined domains on transition and replace with single dontaudit domain domain:process { noatsecure siginh rlimitinh } ;- Fixes for bootloader policy - $1_gkeyringd_t needs to read $HOME/%USER/.local/share/keystore - Allow nsplugin to read /usr/share/config - Allow sa-update to update rules - Add use_fusefs_home_dirs for chroot ssh option - Fixes for grub2 - Update systemd_exec_systemctl() interface - Allow gpg to read the mail spool - More fixes for sa-update running out of cron job - Allow ipsec_mgmt_t to read hardware state information - Allow pptp_t to connect to unreserved_port_t - Dontaudit getattr on initctl in /dev from chfn - Dontaudit getattr on kernel_core from chfn - Add systemd_list_unit_dirs to systemd_exec_systemctl call - Fixes for collectd policy - CHange sysadm_t to create content as user_tmp_t under /tmp- Shrink size of policy through use of attributes for userdomain and apache- Allow virsh to read xenstored pid file - Backport corenetwork fixes from upstream - Do not audit attempts by thumb to search config_home_t dirs (~/.config) - label ~/.cache/telepathy/logger telepathy_logger_cache_home_t - allow thumb to read generic data home files (mime.type)- Allow nmbd to manage sock file in /var/run/nmbd - ricci_modservice send syslog msgs - Stop transitioning from unconfined_t to ldconfig_t, but make sure /etc/ld.so.cache is labeled correctly - Allow systemd_logind_t to manage /run/USER/dconf/user- Fix missing patch from F16- Allow logrotate setuid and setgid since logrotate is supposed to do it - Fixes for thumb policy by grift - Add new nfsd ports - Added fix to allow confined apps to execmod on chrome - Add labeling for additional vdsm directories - Allow Exim and Dovecot SASL - Add label for /var/run/nmbd - Add fixes to make virsh and xen working together - Colord executes ls - /var/spool/cron is now labeled as user_cron_spool_t- Stop complaining about leaked file descriptors during install- Remove java and mono module and merge into execmem- Fixes for thumb policy and passwd_file_t- Fixes caused by the labeling of /etc/passwd - Add thumb.patch to transition unconfined_t to thumb_t for Rawhide- Add support for Clustered Samba commands - Allow ricci_modrpm_t to send log msgs - move permissive virt_qmf_t from virt.te to permissivedomains.te - Allow ssh_t to use kernel keyrings - Add policy for libvirt-qmf and more fixes for linux containers - Initial Polipo - Sanlock needs to run ranged in order to kill svirt processes - Allow smbcontrol to stream connect to ctdbd- Add label for /etc/passwd- Change unconfined_domains to permissive for Rawhide - Add definition for the ephemeral_ports- Make mta_role() active - Allow asterisk to connect to jabber client port - Allow procmail to read utmp - Add NIS support for systemd_logind_t - Allow systemd_logind_t to manage /run/user/$USER/dconf dir which is labeled as config_home_t - Fix systemd_manage_unit_dirs() interface - Allow ssh_t to manage directories passed into it - init needs to be able to create and delete unit file directories - Fix typo in apache_exec_sys_script - Add ability for logrotate to transition to awstat domain- Change screen to use screen_domain attribute and allow screen_domains to read all process domain state - Add SELinux support for ssh pre-auth net process in F17 - Add logging_syslogd_can_sendmail boolean- Add definition for ephemeral ports - Define user_tty_device_t as a customizable_type- Needs to require a new version of checkpolicy - Interface fixes- Allow sanlock to manage virt lib files - Add virt_use_sanlock booelan - ksmtuned is trying to resolve uids - Make sure .gvfs is labeled user_home_t in the users home directory - Sanlock sends kill signals and needs the kill capability - Allow mockbuild to work on nfs homedirs - Fix kerberos_manage_host_rcache() interface - Allow exim to read system state- Allow systemd-tmpfiles to set the correct labels on /var/run, /tmp and other files - We want any file type that is created in /tmp by a process running as initrc_t to be labeled initrc_tmp_t- Allow collectd to read hardware state information - Add loop_control_device_t - Allow mdadm to request kernel to load module - Allow domains that start other domains via systemctl to search unit dir - systemd_tmpfilses, needs to list any file systems mounted on /tmp - No one can explain why radius is listing the contents of /tmp, so we will dontaudit - If I can manage etc_runtime files, I should be able to read the links - Dontaudit hostname writing to mock library chr_files - Have gdm_t setup labeling correctly in users home dir - Label content unde /var/run/user/NAME/dconf as config_home_t - Allow sa-update to execute shell - Make ssh-keygen working with fips_enabled - Make mock work for staff_t user - Tighten security on mock_t- removing unconfined_notrans_t no longer necessary - Clean up handling of secure_mode_insmod and secure_mode_policyload - Remove unconfined_mount_t- Add exim_exec_t label for /usr/sbin/exim_tidydb - Call init_dontaudit_rw_stream_socket() interface in mta policy - sssd need to search /var/cache/krb5rcache directory - Allow corosync to relabel own tmp files - Allow zarafa domains to send system log messages - Allow ssh to do tunneling - Allow initrc scripts to sendto init_t unix_stream_socket - Changes to make sure dmsmasq and virt directories are labeled correctly - Changes needed to allow sysadm_t to manage systemd unit files - init is passing file descriptors to dbus and on to system daemons - Allow sulogin additional access Reported by dgrift and Jeremy Miller - Steve Grubb believes that wireshark does not need this access - Fix /var/run/initramfs to stop restorecon from looking at - pki needs another port - Add more labels for cluster scripts - Allow apps that manage cgroup_files to manage cgroup link files - Fix label on nfs-utils scripts directories - Allow gatherd to read /dev/rand and /dev/urand- pki needs another port - Add more labels for cluster scripts - Fix label on nfs-utils scripts directories - Fixes for cluster - Allow gatherd to read /dev/rand and /dev/urand - abrt leaks fifo files- Add glance policy - Allow mdadm setsched - /var/run/initramfs should not be relabeled with a restorecon run - memcache can be setup to override sys_resource - Allow httpd_t to read tetex data - Allow systemd_tmpfiles to delete kernel modules left in /tmp directory.- Allow Postfix to deliver to Dovecot LMTP socket - Ignore bogus sys_module for lldpad - Allow chrony and gpsd to send dgrams, gpsd needs to write to the real time clock - systemd_logind_t sets the attributes on usb devices - Allow hddtemp_t to read etc_t files - Add permissivedomains module - Move all permissive domains calls to permissivedomain.te - Allow pegasis to send kill signals to other UIDs- Allow insmod_t to use fds leaked from devicekit - dontaudit getattr between insmod_t and init_t unix_stream_sockets - Change sysctl unit file interfaces to use systemctl - Add support for chronyd unit file - Allow mozilla_plugin to read gnome_usr_config - Add policy for new gpsd - Allow cups to create kerberos rhost cache files - Add authlogin_filetrans_named_content, to unconfined_t to make sure shadow and other log files get labeled correctly- Make users_extra and seusers.final into config(noreplace) so semanage users and login does not get overwritten- Add policy for sa-update being run out of cron jobs - Add create perms to postgresql_manage_db - ntpd using a gps has to be able to read/write generic tty_device_t - If you disable unconfined and unconfineduser, rpm needs more privs to manage /dev - fix spec file - Remove qemu_domtrans_unconfined() interface - Make passenger working together with puppet - Add init_dontaudit_rw_stream_socket interface - Fixes for wordpress- Turn on allow_domain_fd_use boolean on F16 - Allow syslog to manage all log files - Add use_fusefs_home_dirs boolean for chrome - Make vdagent working with confined users - Add abrt_handle_event_t domain for ABRT event scripts - Labeled /usr/sbin/rhnreg_ks as rpm_exec_t and added changes related to this change - Allow httpd_git_script_t to read passwd data - Allow openvpn to set its process priority when the nice parameter is used- livecd fixes - spec file fixes- fetchmail can use kerberos - ksmtuned reads in shell programs - gnome_systemctl_t reads the process state of ntp - dnsmasq_t asks the kernel to load multiple kernel modules - Add rules for domains executing systemctl - Bogus text within fc file- Add cfengine policy- Add abrt_domain attribute - Allow corosync to manage cluster lib files - Allow corosync to connect to the system DBUS- Add sblim, uuidd policies - Allow kernel_t dyntrasition to init_t- init_t need setexec - More fixes of rules which cause an explosion in rules by Dan Walsh- Allow rcsmcertd to perform DNS name resolution - Add dirsrvadmin_unconfined_script_t domain type for 389-ds admin scripts - Allow tmux to run as screen - New policy for collectd - Allow gkeyring_t to interact with all user apps - Add rules to allow firstboot to run on machines with the unconfined.pp module removed- Allow systemd_logind to send dbus messages with users - allow accountsd to read wtmp file - Allow dhcpd to get and set capabilities- Fix oracledb_port definition - Allow mount to mounton the selinux file system - Allow users to list /var directories- systemd fixes- Add initial policy for abrt_dump_oops_t - xtables-multi wants to getattr of the proc fs - Smoltclient is connecting to abrt - Dontaudit leaked file descriptors to postdrop - Allow abrt_dump_oops to look at kernel sysctls - Abrt_dump_oops_t reads kernel ring buffer - Allow mysqld to request the kernel to load modules - systemd-login needs fowner - Allow postfix_cleanup_t to searh maildrop- Initial systemd_logind policy - Add policy for systemd_logger and additional proivs for systemd_logind - More fixes for systemd policies- Allow setsched for virsh - Systemd needs to impersonate cups, which means it needs to create tcp_sockets in cups_t domain, as well as manage spool directories - iptables: the various /sbin/ip6?tables.* are now symlinks for /sbin/xtables-multi- A lot of users are running yum -y update while in /root which is causing ldconfig to list the contents, adding dontaudit - Allow colord to interact with the users through the tmpfs file system - Since we changed the label on deferred, we need to allow postfix_qmgr_t to be able to create maildrop_t files - Add label for /var/log/mcelog - Allow asterisk to read /dev/random if it uses TLS - Allow colord to read ini files which are labeled as bin_t - Allow dirsrvadmin sys_resource and setrlimit to use ulimit - Systemd needs to be able to create sock_files for every label in /var/run directory, cupsd being the first. - Also lists /var and /var/spool directories - Add openl2tpd to l2tpd policy - qpidd is reading the sysfs file- Change usbmuxd_t to dontaudit attempts to read chr_file - Add mysld_safe_exec_t for libra domains to be able to start private mysql domains - Allow pppd to search /var/lock dir - Add rhsmcertd policy- Update to upstream- More fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git- Fix spec file to not report Verify errors- Add dspam policy - Add lldpad policy - dovecot auth wants to search statfs #713555 - Allow systemd passwd apps to read init fifo_file - Allow prelink to use inherited terminals - Run cherokee in the httpd_t domain - Allow mcs constraints on node connections - Implement pyicqt policy - Fixes for zarafa policy - Allow cobblerd to send syslog messages- Add policy.26 to the payload - Remove olpc stuff - Remove policygentool- Fixes for zabbix - init script needs to be able to manage sanlock_var_run_... - Allow sandlock and wdmd to create /var/run directories... - mixclip.so has been compiled correctly - Fix passenger policy module name- Add mailscanner policy from dgrift - Allow chrome to optionally be transitioned to - Zabbix needs these rules when starting the zabbix_server_mysql - Implement a type for freedesktop openicc standard (~/.local/share/icc) - Allow system_dbusd_t to read inherited icc_data_home_t files. - Allow colord_t to read icc_data_home_t content. #706975 - Label stuff under /usr/lib/debug as if it was labeled under /- Fixes for sanlock policy - Fixes for colord policy - Other fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Add rhev policy module to modules-targeted.conf- Lot of fixes * http://git.fedorahosted.org/git/?p=selinux-policy.git;a=log- Allow logrotate to execute systemctl - Allow nsplugin_t to getattr on gpmctl - Fix dev_getattr_all_chr_files() interface - Allow shorewall to use inherited terms - Allow userhelper to getattr all chr_file devices - sandbox domains should be able to getattr and dontaudit search of sysctl_kernel_t - Fix labeling for ABRT Retrace Server- Dontaudit sys_module for ifconfig - Make telepathy and gkeyringd daemon working with confined users - colord wants to read files in users homedir - Remote login should be creating user_tmp_t not its own tmp files- Fix label for /usr/share/munin/plugins/munin_* plugins - Add support for zarafa-indexer - Fix boolean description - Allow colord to getattr on /proc/scsi/scsi - Add label for /lib/upstart/init - Colord needs to list /mnt- Forard port changes from F15 for telepathy - NetworkManager should be allowed to use /dev/rfkill - Fix dontaudit messages to say Domain to not audit - Allow telepathy domains to read/write gnome_cache files - Allow telepathy domains to call getpw - Fixes for colord and vnstatd policy- Allow init_t getcap and setcap - Allow namespace_init_t to use nsswitch - aisexec will execute corosync - colord tries to read files off noxattr file systems - Allow init_t getcap and setcap- Add support for ABRT retrace server - Allow user_t and staff_t access to generic scsi to handle locally plugged in scanners - Allow telepath_msn_t to read /proc/PARENT/cmdline - ftpd needs kill capability - Allow telepath_msn_t to connect to sip port - keyring daemon does not work on nfs homedirs - Allow $1_sudo_t to read default SELinux context - Add label for tgtd sock file in /var/run/ - Add apache_exec_rotatelogs interface - allow all zaraha domains to signal themselves, server writes to /tmp - Allow syslog to read the process state - Add label for /usr/lib/chromium-browser/chrome - Remove the telepathy transition from unconfined_t - Dontaudit sandbox domains trying to mounton sandbox_file_t, this is caused by fuse mounts - Allow initrc_t domain to manage abrt pid files - Add support for AEOLUS project - Virt_admin should be allowed to manage images and processes - Allow plymountd to send signals to init - Change labeling of fping6- Add filename transitions- Fixes for zarafa policy - Add support for AEOLUS project - Change labeling of fping6 - Allow plymountd to send signals to init - Allow initrc_t domain to manage abrt pid files - Virt_admin should be allowed to manage images and processes- xdm_t needs getsession for switch user - Every app that used to exec init is now execing systemdctl - Allow squid to manage krb5_host_rcache_t files - Allow foghorn to connect to agentx port - Fixes for colord policy- Add Dan's patch to remove 64 bit variants - Allow colord to use unix_dgram_socket - Allow apps that search pids to read /var/run if it is a lnk_file - iscsid_t creates its own directory - Allow init to list var_lock_t dir - apm needs to verify user accounts auth_use_nsswitch - Add labeling for systemd unit files - Allow gnomeclok to enable ntpd service using systemctl - systemd_systemctl_t domain was added - Add label for matahari-broker.pid file - We want to remove untrustedmcsprocess from ability to read /proc/pid - Fixes for matahari policy - Allow system_tmpfiles_t to delete user_home_t files in the /tmp dir - Allow sshd to transition to sysadm_t if ssh_sysadm_login is turned on- Fix typo- Add /var/run/lock /var/lock definition to file_contexts.subs - nslcd_t is looking for kerberos cc files - SSH_USE_STRONG_RNG is 1 which requires /dev/random - Fix auth_rw_faillog definition - Allow sysadm_t to set attributes on fixed disks - allow user domains to execute lsof and look at application sockets - prelink_cron job calls telinit -u if init is rewritten - Fixes to run qemu_t from staff_t- Fix label for /var/run/udev to udev_var_run_t - Mock needs to be able to read network state- Add file_contexts.subs to handle /run and /run/lock - Add other fixes relating to /run changes from F15 policy- Allow $1_sudo_t and $1_su_t open access to user terminals - Allow initrc_t to use generic terminals - Make Makefile/Rules.modular run sepolgen-ifgen during build to check if files for bugs -systemd is going to be useing /run and /run/lock for early bootup files. - Fix some comments in rlogin.if - Add policy for KDE backlighthelper - sssd needs to read ~/.k5login in nfs, cifs or fusefs file systems - sssd wants to read .k5login file in users homedir - setroubleshoot reads executables to see if they have TEXTREL - Add /var/spool/audit support for new version of audit - Remove kerberos_connect_524() interface calling - Combine kerberos_master_port_t and kerberos_port_t - systemd has setup /dev/kmsg as stderr for apps it executes - Need these access so that init can impersonate sockets on unix_dgram_socket- Remove some unconfined domains - Remove permissive domains - Add policy-term.patch from Dan- Fix multiple specification for boot.log - devicekit leaks file descriptors to setfiles_t - Change all all_nodes to generic_node and all_if to generic_if - Should not use deprecated interface - Switch from using all_nodes to generic_node and from all_if to generic_if - Add support for xfce4-notifyd - Fix file context to show several labels as SystemHigh - seunshare needs to be able to mounton nfs/cifs/fusefs homedirs - Add etc_runtime_t label for /etc/securetty - Fixes to allow xdm_t to start gkeyringd_USERTYPE_t directly - login.krb needs to be able to write user_tmp_t - dirsrv needs to bind to port 7390 for dogtag - Fix a bug in gpg policy - gpg sends audit messages - Allow qpid to manage matahari files- Initial policy for matahari - Add dev_read_watchdog - Allow clamd to connect clamd port - Add support for kcmdatetimehelper - Allow shutdown to setrlimit and sys_nice - Allow systemd_passwd to talk to /dev/log before udev or syslog is running - Purge chr_file and blk files on /tmp - Fixes for pads - Fixes for piranha-pulse - gpg_t needs to be able to encyprt anything owned by the user- mozilla_plugin_tmp_t needs to be treated as user tmp files - More dontaudits of writes from readahead - Dontaudit readahead_t file_type:dir write, to cover up kernel bug - systemd_tmpfiles needs to relabel faillog directory as well as the file - Allow hostname and consoletype to r/w inherited initrc_tmp_t files handline hostname >> /tmp/myhost- Add policykit fixes from Tim Waugh - dontaudit sandbox domains sandbox_file_t:dir mounton - Add new dontaudit rules for sysadm_dbusd_t - Change label for /var/run/faillock * other fixes which relate with this change- Update to upstream - Fixes for telepathy - Add port defition for ssdp port - add policy for /bin/systemd-notify from Dan - Mount command requires users read mount_var_run_t - colord needs to read konject_uevent_socket - User domains connect to the gkeyring socket - Add colord policy and allow user_t and staff_t to dbus chat with it - Add lvm_exec_t label for kpartx - Dontaudit reading the mail_spool_t link from sandbox -X - systemd is creating sockets in avahi_var_run and system_dbusd_var_run- gpg_t needs to talk to gnome-keyring - nscd wants to read /usr/tmp->/var/tmp to generate randomziation in unixchkpwd - enforce MCS labeling on nodes - Allow arpwatch to read meminfo - Allow gnomeclock to send itself signals - init relabels /dev/.udev files on boot - gkeyringd has to transition back to staff_t when it runs commands in bin_t or shell_exec_t - nautilus checks access on /media directory before mounting usb sticks, dontaudit access_check on mnt_t - dnsmasq can run as a dbus service, needs acquire service - mysql_admin should be allowed to connect to mysql service - virt creates monitor sockets in the users home dir- Allow usbhid-ups to read hardware state information - systemd-tmpfiles has moved - Allo cgroup to sys_tty_config - For some reason prelink is attempting to read gconf settings - Add allow_daemons_use_tcp_wrapper boolean - Add label for ~/.cache/wocky to make telepathy work in enforcing mode - Add label for char devices /dev/dasd* - Fix for apache_role - Allow amavis to talk to nslcd - allow all sandbox to read selinux poilcy config files - Allow cluster domains to use the system bus and send each other dbus messages- Update to upstream- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Update to ref policy - cgred needs chown capability - Add /dev/crash crash_dev_t - systemd-readahead wants to use fanotify which means readahead_t needs sys_admin capability- New labeling for postfmulti #675654 - dontaudit xdm_t listing noxattr file systems - dovecot-auth needs to be able to connect to mysqld via the network as well as locally - shutdown is passed stdout to a xdm_log_t file - smartd creates a fixed disk device - dovecot_etc_t contains a lnk_file that domains need to read - mount needs to be able to read etc_runtim_t:lnk_file since in rawhide this is a link created at boot- syslog_t needs syslog capability - dirsrv needs to be able to create /var/lib/snmp - Fix labeling for dirsrv - Fix for dirsrv policy missing manage_dirs_pattern - corosync needs to delete clvm_tmpfs_t files - qdiskd needs to list hugetlbfs - Move setsched to sandbox_x_domain, so firefox can run without network access - Allow hddtemp to read removable devices - Adding syslog and read_policy permissions to policy * syslog Allow unconfined, sysadm_t, secadm_t, logadm_t * read_policy allow unconfined, sysadm_t, secadm_t, staff_t on Targeted allow sysadm_t (optionally), secadm_t on MLS - mdadm application will write into /sys/.../uevent whenever arrays are assembled or disassembled.- Add tcsd policy- ricci_modclusterd_t needs to bind to rpc ports 500-1023 - Allow dbus to use setrlimit to increase resoueces - Mozilla_plugin is leaking to sandbox - Allow confined users to connect to lircd over unix domain stream socket which allow to use remote control - Allow awstats to read squid logs - seunshare needs to manage tmp_t - apcupsd cgi scripts have a new directory- Fix xserver_dontaudit_read_xdm_pid - Change oracle_port_t to oracledb_port_t to prevent conflict with satellite - Allow dovecot_deliver_t to read/write postfix_master_t:fifo_file. * These fifo_file is passed from postfix_master_t to postfix_local_t to dovecot_deliver_t - Allow readahead to manage readahead pid dirs - Allow readahead to read all mcs levels - Allow mozilla_plugin_t to use nfs or samba homedirs- Allow nagios plugin to read /proc/meminfo - Fix for mozilla_plugin - Allow samba_net_t to create /etc/keytab - pppd_t setting up vpns needs to run unix_chkpwd, setsched its process and write wtmp_t - nslcd can read user credentials - Allow nsplugin to delete mozilla_plugin_tmpfs_t - abrt tries to create dir in rpm_var_lib_t - virt relabels fifo_files - sshd needs to manage content in fusefs homedir - mock manages link files in cache dir- nslcd needs setsched and to read /usr/tmp - Invalid call in likewise policy ends up creating a bogus role - Cannon puts content into /var/lib/bjlib that cups needs to be able to write - Allow screen to create screen_home_t in /root - dirsrv sends syslog messages - pinentry reads stuff in .kde directory - Add labels for .kde directory in homedir - Treat irpinit, iprupdate, iprdump services with raid policy- NetworkManager wants to read consolekit_var_run_t - Allow readahead to create /dev/.systemd/readahead - Remove permissive domains - Allow newrole to run namespace_init- Add sepgsql_contexts file- Update to upstream- Add oracle ports and allow apache to connect to them if the connect_db boolean is turned on - Add puppetmaster_use_db boolean - Fixes for zarafa policy - Fixes for gnomeclock poliy - Fix systemd-tmpfiles to use auth_use_nsswitch- gnomeclock executes a shell - Update for screen policy to handle pipe in homedir - Fixes for polyinstatiated homedir - Fixes for namespace policy and other fixes related to polyinstantiation - Add namespace policy - Allow dovecot-deliver transition to sendmail which is needed by sieve scripts - Fixes for init, psad policy which relate with confined users - Do not audit bootloader attempts to read devicekit pid files - Allow nagios service plugins to read /proc- Add firewalld policy - Allow vmware_host to read samba config - Kernel wants to read /proc Fix duplicate grub def in cobbler - Chrony sends mail, executes shell, uses fifo_file and reads /proc - devicekitdisk getattr all file systems - sambd daemon writes wtmp file - libvirt transitions to dmidecode- Add initial policy for system-setup-keyboard which is now daemon - Label /var/lock/subsys/shorewall as shorewall_lock_t - Allow users to communicate with the gpg_agent_t - Dontaudit mozilla_plugin_t using the inherited terminal - Allow sambagui to read files in /usr - webalizer manages squid log files - Allow unconfined domains to bind ports to raw_ip_sockets - Allow abrt to manage rpm logs when running yum - Need labels for /var/run/bittlebee - Label .ssh under amanda - Remove unused genrequires for virt_domain_template - Allow virt_domain to use fd inherited from virtd_t - Allow iptables to read shorewall config- Gnome apps list config_home_t - mpd creates lnk files in homedir - apache leaks write to mail apps on tmp files - /var/stockmaniac/templates_cache contains log files - Abrt list the connects of mount_tmp_t dirs - passwd agent reads files under /dev and reads utmp file - squid apache script connects to the squid port - fix name of plymouth log file - teamviewer is a wine app - allow dmesg to read system state - Stop labeling files under /var/lib/mock so restorecon will not go into this - nsplugin needs to read network state for google talk- Allow xdm and syslog to use /var/log/boot.log - Allow users to communicate with mozilla_plugin and kill it - Add labeling for ipv6 and dhcp- New labels for ghc http content - nsplugin_config needs to read urand, lvm now calls setfscreate to create dev - pm-suspend now creates log file for append access so we remove devicekit_wri - Change authlogin_use_sssd to authlogin_nsswitch_use_ldap - Fixes for greylist_milter policy- Update to upstream - Fixes for systemd policy - Fixes for passenger policy - Allow staff users to run mysqld in the staff_t domain, akonadi needs this - Add bin_t label for /usr/share/kde4/apps/kajongg/kajongg.py - auth_use_nsswitch does not need avahi to read passwords,needed for resolving data - Dontaudit (xdm_t) gok attempting to list contents of /var/account - Telepathy domains need to read urand - Need interface to getattr all file classes in a mock library for setroubleshoot- Update selinux policy to handle new /usr/share/sandbox/start script- Update to upstream - Fix version of policy in spec file- Allow sandbox to run on nfs partitions, fixes for systemd_tmpfs - remove per sandbox domains devpts types - Allow dkim-milter sending signal to itself- Allow domains that transition to ping or traceroute, kill them - Allow user_t to conditionally transition to ping_t and traceroute_t - Add fixes to systemd- tools, including new labeling for systemd-fsck, systemd-cryptsetup- Turn on systemd policy - mozilla_plugin needs to read certs in the homedir. - Dontaudit leaked file descriptors from devicekit - Fix ircssi to use auth_use_nsswitch - Change to use interface without param in corenet to disable unlabelednet packets - Allow init to relabel sockets and fifo files in /dev - certmonger needs dac* capabilities to manage cert files not owned by root - dovecot needs fsetid to change group membership on mail - plymouthd removes /var/log/boot.log - systemd is creating symlinks in /dev - Change label on /etc/httpd/alias to be all cert_t- Fixes for clamscan and boinc policy - Add boinc_project_t setpgid - Allow alsa to create tmp files in /tmp- Push fixes to allow disabling of unlabeled_t packet access - Enable unlabelednet policy- Fixes for lvm to work with systemd- Fix the label for wicd log - plymouthd creates force-display-on-active-vt file - Allow avahi to request the kernel to load a module - Dontaudit hal leaks - Fix gnome_manage_data interface - Add new interface corenet_packet to define a type as being an packet_type. - Removed general access to packet_type from icecast and squid. - Allow mpd to read alsa config - Fix the label for wicd log - Add systemd policy- Fix gnome_manage_data interface - Dontaudit sys_ptrace capability for iscsid - Fixes for nagios plugin policy- Fix cron to run ranged when started by init - Fix devicekit to use log files - Dontaudit use of devicekit_var_run_t for fstools - Allow init to setattr on logfile directories - Allow hald to manage files in /var/run/pm-utils/ dir which is now labeled as devicekit_var_run_t- Fix up handling of dnsmasq_t creating /var/run/libvirt/network - Turn on sshd_forward_ports boolean by default - Allow sysadmin to dbus chat with rpm - Add interface for rw_tpm_dev - Allow cron to execute bin - fsadm needs to write sysfs - Dontaudit consoletype reading /var/run/pm-utils - Lots of new privs fro mozilla_plugin_t running java app, make mozilla_plugin - certmonger needs to manage dirsrv data - /var/run/pm-utils should be labeled as devicekit_var_run_t- fixes to allow /var/run and /var/lock as tmpfs - Allow chrome sandbox to connect to web ports - Allow dovecot to listem on lmtp and sieve ports - Allov ddclient to search sysctl_net_t - Transition back to original domain if you execute the shell- Remove duplicate declaration- Update to upstream - Cleanup for sandbox - Add attribute to be able to select sandbox types- Allow ddclient to fix file mode bits of ddclient conf file - init leaks file descriptors to daemons - Add labels for /etc/lirc/ and - Allow amavis_t to exec shell - Add label for gssd_tmp_t for /var/tmp/nfs_0- Put back in lircd_etc_t so policy will install- Turn on allow_postfix_local_write_mail_spool - Allow initrc_t to transition to shutdown_t - Allow logwatch and cron to mls_read_to_clearance for MLS boxes - Allow wm to send signull to all applications and receive them from users - lircd patch from field - Login programs have to read /etc/samba - New programs under /lib/systemd - Abrt needs to read config files- Update to upstream - Dontaudit leaked sockets from userdomains to user domains - Fixes for mcelog to handle scripts - Apply patch from Ruben Kerkhof - Allow syslog to search spool dirs- Allow nagios plugins to read usr files - Allow mysqld-safe to send system log messages - Fixes fpr ddclient policy - Fix sasl_admin interface - Allow apache to search zarafa config - Allow munin plugins to search /var/lib directory - Allow gpsd to read sysfs_t - Fix labels on /etc/mcelog/triggers to bin_t- Remove saslauthd_tmp_t and transition tmp files to krb5_host_rcache_t - Allow saslauthd_t to create krb5_host_rcache_t files in /tmp - Fix xserver interface - Fix definition of /var/run/lxdm- Turn on mediawiki policy - kdump leaks kdump_etc_t to ifconfig, add dontaudit - uux needs to transition to uucpd_t - More init fixes relabels man,faillog - Remove maxima defs in libraries.fc - insmod needs to be able to create tmpfs_t files - ping needs setcap- Allow groupd transition to fenced domain when executes fence_node - Fixes for rchs policy - Allow mpd to be able to read samba/nfs files- Fix up corecommands.fc to match upstream - Make sure /lib/systemd/* is labeled init_exec_t - mount wants to setattr on all mountpoints - dovecot auth wants to read dovecot etc files - nscd daemon looks at the exe file of the comunicating daemon - openvpn wants to read utmp file - postfix apps now set sys_nice and lower limits - remote_login (telnetd/login) wants to use telnetd_devpts_t and user_devpts_t to work correctly - Also resolves nsswitch - Fix labels on /etc/hosts.* - Cleanup to make upsteam patch work - allow abrt to read etc_runtime_t- Add conflicts for dirsrv package- Update to upstream - Add vlock policy- Fix sandbox to work on nfs homedirs - Allow cdrecord to setrlimit - Allow mozilla_plugin to read xauth - Change label on systemd-logger to syslogd_exec_t - Install dirsrv policy from dirsrv package- Add virt_home_t, allow init to setattr on xserver_tmp_t and relabel it - Udev needs to stream connect to init and kernel - Add xdm_exec_bootloader boolean, which allows xdm to execute /sbin/grub and read files in /boot directory- Allow NetworkManager to read openvpn_etc_t - Dontaudit hplip to write of /usr dirs - Allow system_mail_t to create /root/dead.letter as mail_home_t - Add vdagent policy for spice agent daemon- Dontaudit sandbox sending sigkill to all user domains - Add policy for rssh_chroot_helper - Add missing flask definitions - Allow udev to relabelto removable_t - Fix label on /var/log/wicd.log - Transition to initrc_t from init when executing bin_t - Add audit_access permissions to file - Make removable_t a device_node - Fix label on /lib/systemd/*- Fixes for systemd to manage /var/run - Dontaudit leaks by firstboot- Allow chome to create netlink_route_socket - Add additional MATHLAB file context - Define nsplugin as an application_domain - Dontaudit sending signals from sandboxed domains to other domains - systemd requires init to build /tmp /var/auth and /var/lock dirs - mount wants to read devicekit_power /proc/ entries - mpd wants to connect to soundd port - Openoffice causes a setattr on a lib_t file for normal users, add dontaudit - Treat lib_t and textrel_shlib_t directories the same - Allow mount read access on virtual images- Allow sandbox_x_domains to work with nfs/cifs/fusefs home dirs. - Allow devicekit_power to domtrans to mount - Allow dhcp to bind to udp ports > 1024 to do named stuff - Allow ssh_t to exec ssh_exec_t - Remove telepathy_butterfly_rw_tmp_files(), dev_read_printk() interfaces which are nolonger used - Fix clamav_append_log() intefaces - Fix 'psad_rw_fifo_file' interface- Allow cobblerd to list cobler appache content- Fixup for the latest version of upowed - Dontaudit sandbox sending SIGNULL to desktop apps- Update to upstream-Mount command from a confined user generates setattr on /etc/mtab file, need to dontaudit this access - dovecot-auth_t needs ipc_lock - gpm needs to use the user terminal - Allow system_mail_t to append ~/dead.letter - Allow NetworkManager to edit /etc/NetworkManager/NetworkManager.conf - Add pid file to vnstatd - Allow mount to communicate with gfs_controld - Dontaudit hal leaks in setfiles- Lots of fixes for systemd - systemd now executes readahead and tmpwatch type scripts - Needs to manage random seed- Allow smbd to use sys_admin - Remove duplicate file context for tcfmgr - Update to upstream- Fix fusefs handling - Do not allow sandbox to manage nsplugin_rw_t - Allow mozilla_plugin_t to connecto its parent - Allow init_t to connect to plymouthd running as kernel_t - Add mediawiki policy - dontaudit sandbox sending signals to itself. This can happen when they are running at different mcs. - Disable transition from dbus_session_domain to telepathy for F14 - Allow boinc_project to use shm - Allow certmonger to search through directories that contain certs - Allow fail2ban the DAC Override so it can read log files owned by non root users- Start adding support for use_fusefs_home_dirs - Add /var/lib/syslog directory file context - Add /etc/localtime as locale file context- Turn off default transition to mozilla_plugin and telepathy domains from unconfined user - Turn off iptables from unconfined user - Allow sudo to send signals to any domains the user could have transitioned to. - Passwd in single user mode needs to talk to console_device_t - Mozilla_plugin_t needs to connect to web ports, needs to write to video device, and read alsa_home_t alsa setsup pulseaudio - locate tried to read a symbolic link, will dontaudit - New labels for telepathy-sunshine content in homedir - Google is storing other binaries under /opt/google/talkplugin - bluetooth/kernel is creating unlabeled_t socket that I will allow it to use until kernel fixes bug - Add boolean for unconfined_t transition to mozilla_plugin_t and telepathy domains, turned off in F14 on in F15 - modemmanger and bluetooth send dbus messages to devicekit_power - Samba needs to getquota on filesystems labeld samba_share_t- Dontaudit attempts by xdm_t to write to bin_t for kdm - Allow initrc_t to manage system_conf_t- Fixes to allow mozilla_plugin_t to create nsplugin_home_t directory. - Allow mozilla_plugin_t to create tcp/udp/netlink_route sockets - Allow confined users to read xdm_etc_t files - Allow xdm_t to transition to xauth_t for lxdm program- Rearrange firewallgui policy to be more easily updated to upstream, dontaudit search of /home - Allow clamd to send signals to itself - Allow mozilla_plugin_t to read user home content. And unlink pulseaudio shm. - Allow haze to connect to yahoo chat and messenger port tcp:5050. Bz #637339 - Allow guest to run ps command on its processes by allowing it to read /proc - Allow firewallgui to sys_rawio which seems to be required to setup masqerading - Allow all domains to search through default_t directories, in order to find differnet labels. For example people serring up /foo/bar to be share via samba. - Add label for /var/log/slim.log- Pull in cleanups from dgrift - Allow mozilla_plugin_t to execute mozilla_home_t - Allow rpc.quota to do quotamod- Cleanup policy via dgrift - Allow dovecot_deliver to append to inherited log files - Lots of fixes for consolehelper- Fix up Xguest policy- Add vnstat policy - allow libvirt to send audit messages - Allow chrome-sandbox to search nfs_t- Update to upstream- Add the ability to send audit messages to confined admin policies - Remove permissive domain from cmirrord and dontaudit sys_tty_config - Split out unconfined_domain() calls from other unconfined_ calls so we can d - virt needs to be able to read processes to clearance for MLS- Allow all domains that can use cgroups to search tmpfs_t directory - Allow init to send audit messages- Update to upstream- Allow mdadm_t to create files and sock files in /dev/md/- Add policy for ajaxterm- Handle /var/db/sudo - Allow pulseaudio to read alsa config - Allow init to send initrc_t dbus messagesAllow iptables to read shorewall tmp files Change chfn and passwd to use auth_use_pam so they can send dbus messages to fpr intd label vlc as an execmem_exec_t Lots of fixes for mozilla_plugin to run google vidio chat Allow telepath_msn to execute ldconfig and its own tmp files Fix labels on hugepages Allow mdadm to read files on /dev Remove permissive domains and change back to unconfined Allow freshclam to execute shell and bin_t Allow devicekit_power to transition to dhcpc Add boolean to allow icecast to connect to any port- Merge upstream fix of mmap_zero - Allow mount to write files in debugfs_t - Allow corosync to communicate with clvmd via tmpfs - Allow certmaster to read usr_t files - Allow dbus system services to search cgroup_t - Define rlogind_t as a login pgm- Allow mdadm_t to read/write hugetlbfs- Dominic Grift Cleanup - Miroslav Grepl policy for jabberd - Various fixes for mount/livecd and prelink- Merge with upstream- More access needed for devicekit - Add dbadm policy- Merge with upstream- Allow seunshare to fowner- Allow cron to look at user_cron_spool links - Lots of fixes for mozilla_plugin_t - Add sysv file system - Turn unconfined domains to permissive to find additional avcs- Update policy for mozilla_plugin_t- Allow clamscan to read proc_t - Allow mount_t to write to debufs_t dir - Dontaudit mount_t trying to write to security_t dir- Allow clamscan_t execmem if clamd_use_jit set - Add policy for firefox plugin-container- Fix /root/.forward definition- label dead.letter as mail_home_t- Allow login programs to search /cgroups- Fix cert handling- Fix devicekit_power bug - Allow policykit_auth_t more access.- Fix nis calls to allow bind to ports 512-1024 - Fix smartmon- Allow pcscd to read sysfs - systemd fixes - Fix wine_mmap_zero_ignore boolean- Apply Miroslav munin patch - Turn back on allow_execmem and allow_execmod booleans- Merge in fixes from dgrift repository- Update boinc policy - Fix sysstat policy to allow sys_admin - Change failsafe_context to unconfined_r:unconfined_t:s0- New paths for upstart- New permissions for syslog - New labels for /lib/upstart- Add mojomojo policy- Allow systemd to setsockcon on sockets to immitate other services- Remove debugfs label- Update to latest policy- Fix eclipse labeling from IBMSupportAssasstant packageing- Make boot with systemd in enforcing mode- Update to upstream- Add boolean to turn off port forwarding in sshd.- Add support for ebtables - Fixes for rhcs and corosync policy-Update to upstream-Update to upstream-Update to upstream- Add Zarafa policy- Cleanup of aiccu policy - initial mock policy- Lots of random fixes- Update to upstream- Update to upstream - Allow prelink script to signal itself - Cobbler fixes- Add xdm_var_run_t to xserver_stream_connect_xdm - Add cmorrord and mpd policy from Miroslav Grepl- Fix sshd creation of krb cc files for users to be user_tmp_t- Fixes for accountsdialog - Fixes for boinc- Fix label on /var/lib/dokwiki - Change permissive domains to enforcing - Fix libvirt policy to allow it to run on mls- Update to upstream- Allow procmail to execute scripts in the users home dir that are labeled home_bin_t - Fix /var/run/abrtd.lock label- Allow login programs to read krb5_home_t Resolves: 594833 - Add obsoletes for cachefilesfd-selinux package Resolves: #575084- Allow mount to r/w abrt fifo file - Allow svirt_t to getattr on hugetlbfs - Allow abrt to create a directory under /var/spool- Add labels for /sys - Allow sshd to getattr on shutdown - Fixes for munin - Allow sssd to use the kernel key ring - Allow tor to send syslog messages - Allow iptabels to read usr files - allow policykit to read all domains state- Fix path for /var/spool/abrt - Allow nfs_t as an entrypoint for http_sys_script_t - Add policy for piranha - Lots of fixes for sosreport- Allow xm_t to read network state and get and set capabilities - Allow policykit to getattr all processes - Allow denyhosts to connect to tcp port 9911 - Allow pyranha to use raw ip sockets and ptrace itself - Allow unconfined_execmem_t and gconfsd mechanism to dbus - Allow staff to kill ping process - Add additional MLS rules- Allow gdm to edit ~/.gconf dir Resolves: #590677 - Allow dovecot to create directories in /var/lib/dovecot Partially resolves 590224 - Allow avahi to dbus chat with NetworkManager - Fix cobbler labels - Dontaudit iceauth_t leaks - fix /var/lib/lxdm file context - Allow aiccu to use tun tap devices - Dontaudit shutdown using xserver.log- Fixes for sandbox_x_net_t to match access for sandbox_web_t ++ - Add xdm_etc_t for /etc/gdm directory, allow accountsd to manage this directory - Add dontaudit interface for bluetooth dbus - Add chronyd_read_keys, append_keys for initrc_t - Add log support for ksmtuned Resolves: #586663- Allow boinc to send mail- Allow initrc_t to remove dhcpc_state_t - Fix label on sa-update.cron - Allow dhcpc to restart chrony initrc - Don't allow sandbox to send signals to its parent processes - Fix transition from unconfined_t -> unconfined_mount_t -> rpcd_t Resolves: #589136- Fix location of oddjob_mkhomedir Resolves: #587385 - fix labeling on /root/.shosts and ~/.shosts - Allow ipsec_mgmt_t to manage net_conf_t Resolves: #586760- Dontaudit sandbox trying to connect to netlink sockets Resolves: #587609 - Add policy for piranha- Fixups for xguest policy - Fixes for running sandbox firefox- Allow ksmtuned to use terminals Resolves: #586663 - Allow lircd to write to generic usb devices- Allow sandbox_xserver to connectto unconfined stream Resolves: #585171- Allow initrc_t to read slapd_db_t Resolves: #585476 - Allow ipsec_mgmt to use unallocated devpts and to create /etc/resolv.conf Resolves: #585963- Allow rlogind_t to search /root for .rhosts Resolves: #582760 - Fix path for cached_var_t - Fix prelink paths /var/lib/prelink - Allow confined users to direct_dri - Allow mls lvm/cryptosetup to work- Allow virtd_t to manage firewall/iptables config Resolves: #573585- Fix label on /root/.rhosts Resolves: #582760 - Add labels for Picasa - Allow openvpn to read home certs - Allow plymouthd_t to use tty_device_t - Run ncftool as iptables_t - Allow mount to unmount unlabeled_t - Dontaudit hal leaks- Allow livecd to transition to mount- Update to upstream - Allow abrt to delete sosreport Resolves: #579998 - Allow snmp to setuid and gid Resolves: #582155 - Allow smartd to use generic scsi devices Resolves: #582145- Allow ipsec_t to create /etc/resolv.conf with the correct label - Fix reserved port destination - Allow autofs to transition to showmount - Stop crashing tuned- Add telepathysofiasip policy- Update to upstream - Fix label for /opt/google/chrome/chrome-sandbox - Allow modemmanager to dbus with policykit- Fix allow_httpd_mod_auth_pam to use auth_use_pam(httpd_t) - Allow accountsd to read shadow file - Allow apache to send audit messages when using pam - Allow asterisk to bind and connect to sip tcp ports - Fixes for dovecot 2.0 - Allow initrc_t to setattr on milter directories - Add procmail_home_t for .procmailrc file- Fixes for labels during install from livecd- Fix /cgroup file context - Fix broken afs use of unlabled_t - Allow getty to use the console for s390- Fix cgroup handling adding policy for /cgroup - Allow confined users to write to generic usb devices, if user_rw_noexattrfile boolean set- Merge patches from dgrift- Update upstream - Allow abrt to write to the /proc under any process- Fix ~/.fontconfig label - Add /root/.cert label - Allow reading of the fixed_file_disk_t:lnk_file if you can read file - Allow qemu_exec_t as an entrypoint to svirt_t- Update to upstream - Allow tmpreaper to delete sandbox sock files - Allow chrome-sandbox_t to use /dev/zero, and dontaudit getattr file systems - Fixes for gitosis - No transition on livecd to passwd or chfn - Fixes for denyhosts- Add label for /var/lib/upower - Allow logrotate to run sssd - dontaudit readahead on tmpfs blk files - Allow tmpreaper to setattr on sandbox files - Allow confined users to execute dos files - Allow sysadm_t to kill processes running within its clearance - Add accountsd policy - Fixes for corosync policy - Fixes from crontab policy - Allow svirt to manage svirt_image_t chr files - Fixes for qdisk policy - Fixes for sssd policy - Fixes for newrole policy- make libvirt work on an MLS platform- Add qpidd policy- Update to upstream- Allow boinc to read kernel sysctl - Fix snmp port definitions - Allow apache to read anon_inodefs- Allow shutdown dac_override- Add device_t as a file system - Fix sysfs association- Dontaudit ipsec_mgmt sys_ptrace - Allow at to mail its spool files - Allow nsplugin to search in .pulse directory- Update to upstream- Allow users to dbus chat with xdm - Allow users to r/w wireless_device_t - Dontaudit reading of process states by ipsec_mgmt- Fix openoffice from unconfined_t- Add shutdown policy so consolekit can shutdown system- Update to upstream- Update to upstream- Update to upstream - These are merges of my patches - Remove 389 labeling conflicts - Add MLS fixes found in RHEL6 testing - Allow pulseaudio to run as a service - Add label for mssql and allow apache to connect to this database port if boolean set - Dontaudit searches of debugfs mount point - Allow policykit_auth to send signals to itself - Allow modcluster to call getpwnam - Allow swat to signal winbind - Allow usbmux to run as a system role - Allow svirt to create and use devpts- Add MLS fixes found in RHEL6 testing - Allow domains to append to rpm_tmp_t - Add cachefilesfd policy - Dontaudit leaks when transitioning- Change allow_execstack and allow_execmem booleans to on - dontaudit acct using console - Add label for fping - Allow tmpreaper to delete sandbox_file_t - Fix wine dontaudit mmap_zero - Allow abrt to read var_t symlinks- Additional policy for rgmanager- Allow sshd to setattr on pseudo terms- Update to upstream- Allow policykit to send itself signals- Fix duplicate cobbler definition- Fix file context of /var/lib/avahi-autoipd- Merge with upstream- Allow sandbox to work with MLS- Make Chrome work with staff user- Add icecast policy - Cleanup spec file- Add mcelog policy- Lots of fixes found in F12- Fix rpm_dontaudit_leaks- Add getsched to hald_t - Add file context for Fedora/Redhat Directory Server- Allow abrt_helper to getattr on all filesystems - Add label for /opt/real/RealPlayer/plugins/oggfformat\.so- Add gstreamer_home_t for ~/.gstreamer- Update to upstream- Fix git- Turn on puppet policy - Update to dgrift git policy- Move users file to selection by spec file. - Allow vncserver to run as unconfined_u:unconfined_r:unconfined_t- Update to upstream- Remove most of the permissive domains from F12.- Add cobbler policy from dgrift- add usbmon device - Add allow rulse for devicekit_disk- Lots of fixes found in F12, fixes from Tom London- Cleanups from dgrift- Add back xserver_manage_home_fonts- Dontaudit sandbox trying to read nscd and sssd- Update to upstream- Rename udisks-daemon back to devicekit_disk_t policy- Fixes for abrt calls- Add tgtd policy- Update to upstream release- Add asterisk policy back in - Update to upstream release 2.20091117- Update to upstream release 2.20091117- Fixup nut policy- Update to upstream- Allow vpnc request the kernel to load modules- Fix minimum policy installs - Allow udev and rpcbind to request the kernel to load modules- Add plymouth policy - Allow local_login to sys_admin- Allow cupsd_config to read user tmp - Allow snmpd_t to signal itself - Allow sysstat_t to makedir in sysstat_log_t- Update rhcs policy- Allow users to exec restorecond- Allow sendmail to request kernel modules load- Fix all kernel_request_load_module domains- Fix all kernel_request_load_module domains- Remove allow_exec* booleans for confined users. Only available for unconfined_t- More fixes for sandbox_web_t- Allow sshd to create .ssh directory and content- Fix request_module line to module_request- Fix sandbox policy to allow it to run under firefox. - Dont audit leaks.- Fixes for sandbox- Update to upstream - Dontaudit nsplugin search /root - Dontaudit nsplugin sys_nice- Fix label on /usr/bin/notepad, /usr/sbin/vboxadd-service - Remove policycoreutils-python requirement except for minimum- Fix devicekit_disk_t to getattr on all domains sockets and fifo_files - Conflicts seedit (You can not use selinux-policy-targeted and seedit at the same time.)- Add wordpress/wp-content/uploads label - Fixes for sandbox when run from staff_t- Update to upstream - Fixes for devicekit_disk- More fixes- Lots of fixes for initrc and other unconfined domains- Allow xserver to use netlink_kobject_uevent_socket- Fixes for sandbox- Dontaudit setroubleshootfix looking at /root directory- Update to upsteam- Allow gssd to send signals to users - Fix duplicate label for apache content- Update to upstream- Remove polkit_auth on upgrades- Add back in unconfined.pp and unconfineduser.pp - Add Sandbox unshare- Fixes for cdrecord, mdadm, and others- Add capability setting to dhcpc and gpm- Allow cronjobs to read exim_spool_t- Add ABRT policy- Fix system-config-services policy- Allow libvirt to change user componant of virt_domain- Allow cupsd_config_t to be started by dbus - Add smoltclient policy- Add policycoreutils-python to pre install- Make all unconfined_domains permissive so we can see what AVC's happen- Add pt_chown policy- Add kdump policy for Miroslav Grepl - Turn off execstack boolean- Turn on execstack on a temporary basis (#512845)- Allow nsplugin to connecto the session bus - Allow samba_net to write to coolkey data- Allow devicekit_disk to list inotify- Allow svirt images to create sock_file in svirt_var_run_t- Allow exim to getattr on mountpoints - Fixes for pulseaudio- Allow svirt_t to stream_connect to virtd_t- Allod hald_dccm_t to create sock_files in /tmp- More fixes from upstream- Fix polkit label - Remove hidebrokensymptoms for nss_ldap fix - Add modemmanager policy - Lots of merges from upstream - Begin removing textrel_shlib_t labels, from fixed libraries- Update to upstream- Allow certmaster to override dac permissions- Update to upstream- Fix context for VirtualBox- Update to upstream- Allow clamscan read amavis spool files- Fixes for xguest- fix multiple directory ownership of mandirs- Update to upstream- Add rules for rtkit-daemon- Update to upstream - Fix nlscd_stream_connect- Add rtkit policy- Allow rpcd_t to stream connect to rpcbind- Allow kpropd to create tmp files- Fix last duplicate /var/log/rpmpkgs- Update to upstream * add sssd- Update to upstream * cleanup- Update to upstream - Additional mail ports - Add virt_use_usb boolean for svirt- Fix mcs rules to include chr_file and blk_file- Add label for udev-acl- Additional rules for consolekit/udev, privoxy and various other fixes- New version for upstream- Allow NetworkManager to read inotifyfs- Allow setroubleshoot to run mlocate- Update to upstream- Add fish as a shell - Allow fprintd to list usbfs_t - Allow consolekit to search mountpoints - Add proper labeling for shorewall- New log file for vmware - Allow xdm to setattr on user_tmp_t- Upgrade to upstream- Allow fprintd to access sys_ptrace - Add sandbox policy- Add varnishd policy- Fixes for kpropd- Allow brctl to r/w tun_tap_device_t- Add /usr/share/selinux/packages- Allow rpcd_t to send signals to kernel threads- Fix upgrade for F10 to F11- Add policy for /var/lib/fprint-Remove duplicate line- Allow svirt to manage pci and other sysfs device data- Fix package selection handling- Fix /sbin/ip6tables-save context - Allod udev to transition to mount - Fix loading of mls policy file- Add shorewall policy- Additional rules for fprintd and sssd- Allow nsplugin to unix_read unix_write sem for unconfined_java- Fix uml files to be owned by users- Fix Upgrade path to install unconfineduser.pp when unocnfined package is 3.0.0 or less- Allow confined users to manage virt_content_t, since this is home dir content - Allow all domains to read rpm_script_tmp_t which is what shell creates on redirection- Fix labeling on /var/lib/misc/prelink* - Allow xserver to rw_shm_perms with all x_clients - Allow prelink to execute files in the users home directory- Allow initrc_t to delete dev_null - Allow readahead to configure auditing - Fix milter policy - Add /var/lib/readahead- Update to latest milter code from Paul Howarth- Additional perms for readahead- Allow pulseaudio to acquire_svc on session bus - Fix readahead labeling- Allow sysadm_t to run rpm directly - libvirt needs fowner- Allow sshd to read var_lib symlinks for freenx- Allow nsplugin unix_read and write on users shm and sem - Allow sysadm_t to execute su- Dontaudit attempts to getattr user_tmpfs_t by lvm - Allow nfs to share removable media- Add ability to run postdrop from confined users- Fixes for podsleuth- Turn off nsplugin transition - Remove Konsole leaked file descriptors for release- Allow cupsd_t to create link files in print_spool_t - Fix iscsi_stream_connect typo - Fix labeling on /etc/acpi/actions - Don't reinstall unconfine and unconfineuser on upgrade if they are not installed- Allow audioentroy to read etc files- Add fail2ban_var_lib_t - Fixes for devicekit_power_t- Separate out the ucnonfined user from the unconfined.pp package- Make sure unconfined_java_t and unconfined_mono_t create user_tmpfs_t.- Upgrade to latest upstream - Allow devicekit_disk sys_rawio- Dontaudit binds to ports < 1024 for named - Upgrade to latest upstream- Allow podsleuth to use tmpfs files- Add customizable_types for svirt- Allow setroubelshoot exec* privs to prevent crash from bad libraries - add cpufreqselector- Dontaudit listing of /root directory for cron system jobs- Fix missing ld.so.cache label- Add label for ~/.forward and /root/.forward- Fixes for svirt- Fixes to allow svirt read iso files in homedir- Add xenner and wine fixes from mgrepl- Allow mdadm to read/write mls override- Change to svirt to only access svirt_image_t- Fix libvirt policy- Upgrade to latest upstream- Fixes for iscsid and sssd - More cleanups for upgrade from F10 to Rawhide.- Add pulseaudio, sssd policy - Allow networkmanager to exec udevadm- Add pulseaudio context- Upgrade to latest patches- Fixes for libvirt- Update to Latest upstream- Fix setrans.conf to show SystemLow for s0- Further confinement of qemu images via svirt- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild- Allow NetworkManager to manage /etc/NetworkManager/system-connections- add virtual_image_context and virtual_domain_context files- Allow rpcd_t to send signal to mount_t - Allow libvirtd to run ranged- Fix sysnet/net_conf_t- Fix squidGuard labeling- Re-add corenet_in_generic_if(unlabeled_t)* Tue Feb 10 2009 Dan Walsh 3.6.5-2 - Add git web policy- Add setrans contains from upstream- Do transitions outside of the booleans- Allow xdm to create user_tmp_t sockets for switch user to work- Fix staff_t domain- Grab remainder of network_peer_controls patch- More fixes for devicekit- Upgrade to latest upstream- Add boolean to disallow unconfined_t login- Add back transition from xguest to mozilla- Add virt_content_ro_t and labeling for isos directory- Fixes for wicd daemon- More mls/rpm fixes- Add policy to make dbus/nm-applet work- Remove polgen-ifgen from post and add trigger to policycoreutils-python- Add wm policy - Make mls work in graphics mode- Fixed for DeviceKit- Add devicekit policy- Update to upstream- Define openoffice as an x_domain- Fixes for reading xserver_tmp_t- Allow cups_pdf_t write to nfs_t- Remove audio_entropy policy- Update to upstream- Allow hal_acl_t to getattr/setattr fixed_disk- Change userdom_read_all_users_state to include reading symbolic links in /proc- Fix dbus reading /proc information- Add missing alias for home directory content- Fixes for IBM java location- Allow unconfined_r unconfined_java_t- Add cron_role back to user domains- Fix sudo setting of user keys- Allow iptables to talk to terminals - Fixes for policy kit - lots of fixes for booting.- Cleanup policy- Rebuild for Python 2.6- Fix labeling on /var/spool/rsyslog- Allow postgresl to bind to udp nodes- Allow lvm to dbus chat with hal - Allow rlogind to read nfs_t- Fix cyphesis file context- Allow hal/pm-utils to look at /var/run/video.rom - Add ulogd policy- Additional fixes for cyphesis - Fix certmaster file context - Add policy for system-config-samba - Allow hal to read /var/run/video.rom- Allow dhcpc to restart ypbind - Fixup labeling in /var/run- Add certmaster policy- Fix confined users - Allow xguest to read/write xguest_dbusd_t- Allow openoffice execstack/execmem privs- Allow mozilla to run with unconfined_execmem_t- Dontaudit domains trying to write to .xsession-errors- Allow nsplugin to look at autofs_t directory- Allow kerneloops to create tmp files- More alias for fastcgi- Remove mod_fcgid-selinux package- Fix dovecot access- Policy cleanup- Remove Multiple spec - Add include - Fix makefile to not call per_role_expansion- Fix labeling of libGL- Update to upstream- Update to upstream policy- Fixes for confined xwindows and xdm_t- Allow confined users and xdm to exec wm - Allow nsplugin to talk to fifo files on nfs- Allow NetworkManager to transition to avahi and iptables - Allow domains to search other domains keys, coverup kernel bug- Fix labeling for oracle- Allow nsplugin to comminicate with xdm_tmp_t sock_file- Change all user tmpfs_t files to be labeled user_tmpfs_t - Allow radiusd to create sock_files- Upgrade to upstream- Allow confined users to login with dbus- Fix transition to nsplugin- Add file context for /dev/mspblk.*- Fix transition to nsplugin '- Fix labeling on new pm*log - Allow ssh to bind to all nodes- Merge upstream changes - Add Xavier Toth patches- Add qemu_cache_t for /var/cache/libvirt- Remove gamin policy- Add tinyxs-max file system support- Update to upstream - New handling of init scripts- Allow pcsd to dbus - Add memcache policy- Allow audit dispatcher to kill his children- Update to upstream - Fix crontab use by unconfined user- Allow ifconfig_t to read dhcpc_state_t- Update to upstream- Update to upstream- Allow system-config-selinux to work with policykit- Fix novel labeling- Consolodate pyzor,spamassassin, razor into one security domain - Fix xdm requiring additional perms.- Fixes for logrotate, alsa- Eliminate vbetool duplicate entry- Fix xguest -> xguest_mozilla_t -> xguest_openiffice_t - Change dhclient to be able to red networkmanager_var_run- Update to latest refpolicy - Fix libsemanage initial install bug- Add inotify support to nscd- Allow unconfined_t to setfcap- Allow amanda to read tape - Allow prewikka cgi to use syslog, allow audisp_t to signal cgi - Add support for netware file systems- Allow ypbind apps to net_bind_service- Allow all system domains and application domains to append to any log file- Allow gdm to read rpm database - Allow nsplugin to read mplayer config files- Allow vpnc to run ifconfig- Allow confined users to use postgres - Allow system_mail_t to exec other mail clients - Label mogrel_rails as an apache server- Apply unconfined_execmem_exec_t to haskell programs- Fix prelude file context- allow hplip to talk dbus - Fix context on ~/.local dir- Prevent applications from reading x_device- Add /var/lib/selinux context- Update to upstream- Add livecd policy- Dontaudit search of admin_home for init_system_domain - Rewrite of xace interfaces - Lots of new fs_list_inotify - Allow livecd to transition to setfiles_mac- Begin XAce integration- Merge Upstream- Allow amanada to create data files- Fix initial install, semanage setup- Allow system_r for httpd_unconfined_script_t- Remove dmesg boolean - Allow user domains to read/write game data- Change unconfined_t to transition to unconfined_mono_t when running mono - Change XXX_mono_t to transition to XXX_t when executing bin_t files, so gnome-do will work- Remove old booleans from targeted-booleans.conf file- Add boolean to mmap_zero - allow tor setgid - Allow gnomeclock to set clock- Don't run crontab from unconfined_t- Change etc files to config files to allow users to read them- Lots of fixes for confined domains on NFS_t homedir- dontaudit mrtg reading /proc - Allow iscsi to signal itself - Allow gnomeclock sys_ptrace- Allow dhcpd to read kernel network state- Label /var/run/gdm correctly - Fix unconfined_u user creation- Allow transition from initrc_t to getty_t- Allow passwd to communicate with user sockets to change gnome-keyring- Fix initial install- Allow radvd to use fifo_file - dontaudit setfiles reading links - allow semanage sys_resource - add allow_httpd_mod_auth_ntlm_winbind boolean - Allow privhome apps including dovecot read on nfs and cifs home dirs if the boolean is set- Allow nsplugin to read /etc/mozpluggerrc, user_fonts - Allow syslog to manage innd logs. - Allow procmail to ioctl spamd_exec_t- Allow initrc_t to dbus chat with consolekit.- Additional access for nsplugin - Allow xdm setcap/getcap until pulseaudio is fixed- Allow mount to mkdir on tmpfs - Allow ifconfig to search debugfs- Fix file context for MATLAB - Fixes for xace- Allow stunnel to transition to inetd children domains - Make unconfined_dbusd_t an unconfined domain- Fixes for qemu/virtd- Fix bug in mozilla policy to allow xguest transition - This will fix the libsemanage.dbase_llist_query: could not find record value libsemanage.dbase_llist_query: could not query record value (No such file or directory) bug in xguest- Allow nsplugin to run acroread- Add cups_pdf policy - Add openoffice policy to run in xguest- prewika needs to contact mysql - Allow syslog to read system_map files- Change init_t to an unconfined_domain- Allow init to transition to initrc_t on shell exec. - Fix init to be able to sendto init_t. - Allow syslog to connect to mysql - Allow lvm to manage its own fifo_files - Allow bugzilla to use ldap - More mls fixes- fixes for init policy (#436988) - fix build- Additional changes for MLS policy- Fix initrc_context generation for MLS- Fixes for libvirt- Allow bitlebee to read locale_t- More xselinux rules- Change httpd_$1_script_r*_t to httpd_$1_content_r*_t- Prepare policy for beta release - Change some of the system domains back to unconfined - Turn on some of the booleans- Allow nsplugin_config execstack/execmem - Allow nsplugin_t to read alsa config - Change apache to use user content- Add cyphesis policy- Fix Makefile.devel to build mls modules - Fix qemu to be more specific on labeling- Update to upstream fixes- Allow staff to mounton user_home_t- Add xace support- Add fusectl file system- Fixes from yum-cron - Update to latest upstream- Fix userdom_list_user_files- Merge with upstream- Allow udev to send audit messages- Add additional login users interfaces - userdom_admin_login_user_template(staff)- More fixes for polkit- Eliminate transition from unconfined_t to qemu by default - Fixes for gpg- Update to upstream- Fixes for staff_t- Add policy for kerneloops - Add policy for gnomeclock- Fixes for libvirt- Fixes for nsplugin- More fixes for qemu- Additional ports for vnc and allow qemu and libvirt to search all directories- Update to upstream - Add libvirt policy - add qemu policy- Allow fail2ban to create a socket in /var/run- Allow allow_httpd_mod_auth_pam to work- Add audisp policy and prelude- Allow all user roles to executae samba net command- Allow usertypes to read/write noxattr file systems- Fix nsplugin to allow flashplugin to work in enforcing mode- Allow pam_selinux_permit to kill all processes- Allow ptrace or user processes by users of same type - Add boolean for transition to nsplugin- Allow nsplugin sys_nice, getsched, setsched- Allow login programs to talk dbus to oddjob- Add procmail_log support - Lots of fixes for munin- Allow setroubleshoot to read policy config and send audit messages- Allow users to execute all files in homedir, if boolean set - Allow mount to read samba config- Fixes for xguest to run java plugin- dontaudit pam_t and dbusd writing to user_home_t- Update gpg to allow reading of inotify- Change user and staff roles to work correctly with varied perms- Fix munin log, - Eliminate duplicate mozilla file context - fix wpa_supplicant spec- Fix role transition from unconfined_r to system_r when running rpm - Allow unconfined_domains to communicate with user dbus instances- Fixes for xguest- Let all uncofined domains communicate with dbus unconfined- Run rpm in system_r- Zero out customizable types- Fix definiton of admin_home_t- Fix munin file context- Allow cron to run unconfined apps- Modify default login to unconfined_u- Dontaudit dbus user client search of /root- Update to upstream- Fixes for polkit - Allow xserver to ptrace- Add polkit policy - Symplify userdom context, remove automatic per_role changes- Update to upstream - Allow httpd_sys_script_t to search users homedirs- Allow rpm_script to transition to unconfined_execmem_t- Remove user based home directory separation- Remove user specific crond_t- Merge with upstream - Allow xsever to read hwdata_t - Allow login programs to setkeycreate- Update to upstream- Update to upstream- Allow XServer to read /proc/self/cmdline - Fix unconfined cron jobs - Allow fetchmail to transition to procmail - Fixes for hald_mac - Allow system_mail to transition to exim - Allow tftpd to upload files - Allow xdm to manage unconfined_tmp - Allow udef to read alsa config - Fix xguest to be able to connect to sound port- Fixes for hald_mac - Treat unconfined_home_dir_t as a home dir - dontaudit rhgb writes to fonts and root- Fix dnsmasq - Allow rshd full login privs- Allow rshd to connect to ports > 1023- Fix vpn to bind to port 4500 - Allow ssh to create shm - Add Kismet policy- Allow rpm to chat with networkmanager- Fixes for ipsec and exim mail - Change default to unconfined user- Pass the UNK_PERMS param to makefile - Fix gdm location- Make alsa work- Fixes for consolekit and startx sessions- Dontaudit consoletype talking to unconfined_t- Remove homedir_template- Check asound.state- Fix exim policy- Allow tmpreadper to read man_t - Allow racoon to bind to all nodes - Fixes for finger print reader- Allow xdm to talk to input device (fingerprint reader) - Allow octave to run as java- Allow login programs to set ioctl on /proc- Allow nsswitch apps to read samba_var_t- Fix maxima- Eliminate rpm_t:fifo_file avcs - Fix dbus path for helper app- Fix service start stop terminal avc's- Allow also to search var_lib - New context for dbus launcher- Allow cupsd_config_t to read/write usb_device_t - Support for finger print reader, - Many fixes for clvmd - dbus starting networkmanager- Fix java and mono to run in xguest account- Fix to add xguest account when inititial install - Allow mono, java, wine to run in userdomains- Allow xserver to search devpts_t - Dontaudit ldconfig output to homedir- Remove hplip_etc_t change back to etc_t.- Allow cron to search nfs and samba homedirs- Allow NetworkManager to dbus chat with yum-updated- Allow xfs to bind to port 7100- Allow newalias/sendmail dac_override - Allow bind to bind to all udp ports- Turn off direct transition- Allow wine to run in system role- Fix java labeling- Define user_home_type as home_type- Allow sendmail to create etc_aliases_t- Allow login programs to read symlinks on homedirs- Update an readd modules- Cleanup spec file- Allow xserver to be started by unconfined process and talk to tty- Upgrade to upstream to grab postgressql changes- Add setransd for mls policy- Add ldconfig_cache_t- Allow sshd to write to proc_t for afs login- Allow xserver access to urand- allow dovecot to search mountpoints- Fix Makefile for building policy modules- Fix dhcpc startup of service- Fix dbus chat to not happen for xguest and guest users- Fix nagios cgi - allow squid to communicate with winbind- Fixes for ldconfig- Update from upstream- Add nasd support- Fix new usb devices and dmfm- Eliminate mount_ntfs_t policy, merge into mount_t- Allow xserver to write to ramfs mounted by rhgb- Add context for dbus machine id- Update with latest changes from upstream- Fix prelink to handle execmod- Add ntpd_key_t to handle secret data- Add anon_inodefs - Allow unpriv user exec pam_exec_t - Fix trigger- Allow cups to use generic usb - fix inetd to be able to run random apps (git)- Add proper contexts for rsyslogd- Fixes for xguest policy- Allow execution of gconf- Fix moilscanner update problem- Begin adding policy to separate setsebool from semanage - Fix xserver.if definition to not break sepolgen.if- Add new devices- Add brctl policy- Fix root login to include system_r- Allow prelink to read kernel sysctls- Default to user_u:system_r:unconfined_t- fix squid - Fix rpm running as uid- Fix syslog declaration- Allow avahi to access inotify - Remove a lot of bogus security_t:filesystem avcs- Remove ifdef strict policy from upstream- Remove ifdef strict to allow user_u to login- Fix for amands - Allow semanage to read pp files - Allow rhgb to read xdm_xserver_tmp- Allow kerberos servers to use ldap for backing store- allow alsactl to read kernel state- More fixes for alsactl - Transition from hal and modutils - Fixes for suspend resume. - insmod domtrans to alsactl - insmod writes to hal log- Allow unconfined_t to transition to NetworkManager_t - Fix netlabel policy- Update to latest from upstream- Update to latest from upstream- Update to latest from upstream- Allow pcscd_t to send itself signals- Fixes for unix_update - Fix logwatch to be able to search all dirs- Upstream bumped the version- Allow consolekit to syslog - Allow ntfs to work with hal- Allow iptables to read etc_runtime_t- MLS Fixes- Fix path of /etc/lvm/cache directory - Fixes for alsactl and pppd_t - Fixes for consolekit- Allow insmod_t to mount kvmfs_t filesystems- Rwho policy - Fixes for consolekit- fixes for fusefs- Fix samba_net to allow it to view samba_var_t- Update to upstream- Fix Sonypic backlight - Allow snmp to look at squid_conf_t- Fixes for pyzor, cyrus, consoletype on everything installs- Fix hald_acl_t to be able to getattr/setattr on usb devices - Dontaudit write to unconfined_pipes for load_policy- Allow bluetooth to read inotifyfs- Fixes for samba domain controller. - Allow ConsoleKit to look at ttys- Fix interface call- Allow syslog-ng to read /var - Allow locate to getattr on all filesystems - nscd needs setcap- Update to upstream- Allow samba to run groupadd- Update to upstream- Allow mdadm to access generic scsi devices- Fix labeling on udev.tbl dirs- Fixes for logwatch- Add fusermount and mount_ntfs policy- Update to upstream - Allow saslauthd to use kerberos keytabs- Fixes for samba_var_t- Allow networkmanager to setpgid - Fixes for hal_acl_t- Remove disable_trans booleans - hald_acl_t needs to talk to nscd- Fix prelink to be able to manage usr dirs.- Allow insmod to launch init scripts- Remove setsebool policy- Fix handling of unlabled_t packets- More of my patches from upstream- Update to latest from upstream - Add fail2ban policy- Update to remove security_t:filesystem getattr problems- Policy for consolekit- Update to latest from upstream- Revert Nemiver change - Set sudo as a corecmd so prelink will work, remove sudoedit mapping, since this will not work, it does not transition. - Allow samba to execute useradd- Upgrade to the latest from upstream- Add sepolgen support - Add bugzilla policy- Fix file context for nemiver- Remove include sym link- Allow mozilla, evolution and thunderbird to read dev_random. Resolves: #227002 - Allow spamd to connect to smtp port Resolves: #227184 - Fixes to make ypxfr work Resolves: #227237- Fix ssh_agent to be marked as an executable - Allow Hal to rw sound device- Fix spamassisin so crond can update spam files - Fixes to allow kpasswd to work - Fixes for bluetooth- Remove some targeted diffs in file context file- Fix squid cachemgr labeling- Add ability to generate webadm_t policy - Lots of new interfaces for httpd - Allow sshd to login as unconfined_t- Continue fixing, additional user domains- Begin adding user confinement to targeted policy- Fixes for prelink, ktalkd, netlabel- Allow prelink when run from rpm to create tmp files Resolves: #221865 - Remove file_context for exportfs Resolves: #221181 - Allow spamassassin to create ~/.spamassissin Resolves: #203290 - Allow ssh access to the krb tickets - Allow sshd to change passwd - Stop newrole -l from working on non securetty Resolves: #200110 - Fixes to run prelink in MLS machine Resolves: #221233 - Allow spamassassin to read var_lib_t dir Resolves: #219234- fix mplayer to work under strict policy - Allow iptables to use nscd Resolves: #220794- Add gconf policy and make it work with strict- Many fixes for strict policy and by extension mls.- Fix to allow ftp to bind to ports > 1024 Resolves: #219349- Allow semanage to exec it self. Label genhomedircon as semanage_exec_t Resolves: #219421 - Allow sysadm_lpr_t to manage other print spool jobs Resolves: #220080- allow automount to setgid Resolves: #219999- Allow cron to polyinstatiate - Fix creation of boot flags Resolves: #207433- Fixes for irqbalance Resolves: #219606- Fix vixie-cron to work on mls Resolves: #207433Resolves: #218978- Allow initrc to create files in /var directories Resolves: #219227- More fixes for MLS Resolves: #181566- More Fixes polyinstatiation Resolves: #216184- More Fixes polyinstatiation - Fix handling of keyrings Resolves: #216184- Fix polyinstatiation - Fix pcscd handling of terminal Resolves: #218149 Resolves: #218350- More fixes for quota Resolves: #212957- ncsd needs to use avahi sockets Resolves: #217640 Resolves: #218014- Allow login programs to polyinstatiate homedirs Resolves: #216184 - Allow quotacheck to create database files Resolves: #212957- Dontaudit appending hal_var_lib files Resolves: #217452 Resolves: #217571 Resolves: #217611 Resolves: #217640 Resolves: #217725- Fix context for helix players file_context #216942- Fix load_policy to be able to mls_write_down so it can talk to the terminal- Fixes for hwclock, clamav, ftp- Move to upstream version which accepted my patches- Fixes for nvidia driver- Allow semanage to signal mcstrans- Update to upstream- Allow modstorage to edit /etc/fstab file- Fix for qemu, /dev/- Fix path to realplayer.bin- Allow xen to connect to xen port- Allow cups to search samba_etc_t directory - Allow xend_t to list auto_mountpoints- Allow xen to search automount- Fix spec of jre files- Fix unconfined access to shadow file- Allow xend to create files in xen_image_t directories- Fixes for /var/lib/hal- Remove ability for sysadm_t to look at audit.log- Fix rpc_port_types - Add aide policy for mls- Merge with upstream- Lots of fixes for ricci- Allow xen to read/write fixed devices with a boolean - Allow apache to search /var/log- Fix policygentool specfile problem. - Allow apache to send signals to it's logging helpers. - Resolves: rhbz#212731- Add perms for swat- Add perms for swat- Allow daemons to dump core files to /- Fixes for ricci- Allow mount.nfs to work- Allow ricci-modstorage to look at lvm_etc_t- Fixes for ricci using saslauthd- Allow mountpoint on home_dir_t and home_t- Update xen to read nfs files- Allow noxattrfs to associate with other noxattrfs- Allow hal to use power_device_t- Allow procemail to look at autofs_t - Allow xen_image_t to work as a fixed device- Refupdate from upstream- Add lots of fixes for mls cups- Lots of fixes for ricci- Fix number of cats- Update to upstream- More iSCSI changes for #209854- Test ISCSI fixes for #209854- allow semodule to rmdir selinux_config_t dir- Fix boot_runtime_t problem on ppc. Should not be creating these files.- Fix context mounts on reboot - Fix ccs creation of directory in /var/log- Update for tallylog- Allow xend to rewrite dhcp conf files - Allow mgetty sys_admin capability- Make xentapctrl work- Don't transition unconfined_t to bootloader_t - Fix label in /dev/xen/blktap- Patch for labeled networking- Fix crond handling for mls- Update to upstream- Remove bluetooth-helper transition - Add selinux_validate for semanage - Require new version of libsemanage- Fix prelink- Fix rhgb- Fix setrans handling on MLS and useradd- Support for fuse - fix vigr- Fix dovecot, amanda - Fix mls- Allow java execheap for itanium- Update with upstream- mls fixes- Update from upstream- More fixes for mls - Revert change on automount transition to mount- Fix cron jobs to run under the correct context- Fixes to make pppd work- Multiple policy fixes - Change max categories to 1023- Fix transition on mcstransd- Add /dev/em8300 defs- Upgrade to upstream- Fix ppp connections from network manager- Add tty access to all domains boolean - Fix gnome-pty-helper context for ia64- Fixed typealias of firstboot_rw_t- Fix location of xel log files - Fix handling of sysadm_r -> rpm_exec_t- Fixes for autofs, lp- Update from upstream- Fixup for test6- Update to upstream- Update to upstream- Fix suspend to disk problems- Lots of fixes for restarting daemons at the console.- Fix audit line - Fix requires line- Upgrade to upstream- Fix install problems- Allow setroubleshoot to getattr on all dirs to gather RPM data- Set /usr/lib/ia32el/ia32x_loader to unconfined_execmem_exec_t for ia32 platform - Fix spec for /dev/adsp- Fix xen tty devices- Fixes for setroubleshoot- Update to upstream- Fixes for stunnel and postgresql - Update from upstream- Update from upstream - More java fixes- Change allow_execstack to default to on, for RHEL5 Beta. This is required because of a Java compiler problem. Hope to turn off for next beta- Misc fixes- More fixes for strict policy- Quiet down anaconda audit messages- Fix setroubleshootd- Update to the latest from upstream- More fixes for xen- Fix anaconda transitions- yet more xen rules- more xen rules- Fixes for Samba- Fixes for xen- Allow setroubleshootd to send mail- Add nagios policy- fixes for setroubleshoot- Added Paul Howarth patch to only load policy packages shipped with this package - Allow pidof from initrc to ptrace higher level domains - Allow firstboot to communicate with hal via dbus- Add policy for /var/run/ldapi- Fix setroubleshoot policy- Fixes for mls use of ssh - named has a new conf file- Fixes to make setroubleshoot work- Cups needs to be able to read domain state off of printer client- add boolean to allow zebra to write config files- setroubleshootd fixes- Allow prelink to read bin_t symlink - allow xfs to read random devices - Change gfs to support xattr- Remove spamassassin_can_network boolean- Update to upstream - Fix lpr domain for mls- Add setroubleshoot policy- Turn off auditallow on setting booleans- Multiple fixes- Update to upstream- Update to upstream - Add new class for kernel key ring- Update to upstream- Update to upstream- Break out selinux-devel package- Add ibmasmfs- Fix policygentool gen_requires- Update from Upstream- Fix spec of realplay- Update to upstream- Fix semanage- Allow useradd to create_home_dir in MLS environment- Update from upstream- Update from upstream- Add oprofilefs- Fix for hplip and Picasus- Update to upstream- Update to upstream- fixes for spamd- fixes for java, openldap and webalizer- Xen fixes- Upgrade to upstream- allow hal to read boot_t files - Upgrade to upstream- allow hal to read boot_t files- Update from upstream- Fixes for amavis- Update from upstream- Allow auditctl to search all directories- Add acquire service for mono.- Turn off allow_execmem boolean - Allow ftp dac_override when allowed to access users homedirs- Clean up spec file - Transition from unconfined_t to prelink_t- Allow execution of cvs command- Update to upstream- Update to upstream- Fix libjvm spec- Update to upstream- Add xm policy - Fix policygentool- Update to upstream - Fix postun to only disable selinux on full removal of the packages- Allow mono to chat with unconfined- Allow procmail to sendmail - Allow nfs to share dosfs- Update to latest from upstream - Allow selinux-policy to be removed and kernel not to crash- Update to latest from upstream - Add James Antill patch for xen - Many fixes for pegasus- Add unconfined_mount_t - Allow privoxy to connect to httpd_cache - fix cups labeleing on /var/cache/cups- Update to latest from upstream- Update to latest from upstream - Allow mono and unconfined to talk to initrc_t dbus objects- Change libraries.fc to stop shlib_t form overriding texrel_shlib_t- Fix samba creating dirs in homedir - Fix NFS so its booleans would work- Allow secadm_t ability to relabel all files - Allow ftp to search xferlog_t directories - Allow mysql to communicate with ldap - Allow rsync to bind to rsync_port_t- Fixed mailman with Postfix #183928 - Allowed semanage to create file_context files. - Allowed amanda_t to access inetd_t TCP sockets and allowed amanda_recover_t to bind to reserved ports. #149030 - Don't allow devpts_t to be associated with tmp_t. - Allow hald_t to stat all mountpoints. - Added boolean samba_share_nfs to allow smbd_t full access to NFS mounts. - Make mount run in mount_t domain from unconfined_t to prevent mislabeling of /etc/mtab. - Changed the file_contexts to not have a regex before the first ^/[a-z]/ whenever possible, makes restorecon slightly faster. - Correct the label of /etc/named.caching-nameserver.conf - Now label /usr/src/kernels/.+/lib(/.*)? as usr_t instead of /usr/src(/.*)?/lib(/.*)? - I don't think we need anything else under /usr/src hit by this. - Granted xen access to /boot, allowed mounting on xend_var_lib_t, and allowed xenstored_t rw access to the xen device node.- More textrel_shlib_t file path fixes - Add ada support- Get auditctl working in MLS policy- Add mono dbus support - Lots of file_context fixes for textrel_shlib_t in FC5 - Turn off execmem auditallow since they are filling log files- Update to upstream- Allow automount and dbus to read cert files- Fix ftp policy - Fix secadm running of auditctl- Update to upstream- Update to upstream- Fix policyhelp- Fix pam_console handling of usb_device - dontaudit logwatch reading /mnt dir- Update to upstream- Get transition rules to create policy.20 at SystemHigh- Allow secadmin to shutdown system - Allow sendmail to exec newalias- MLS Fixes dmidecode needs mls_file_read_up - add ypxfr_t - run init needs access to nscd - udev needs setuid - another xen log file - Dontaudit mount getattr proc_kcore_t- fix buildroot usage (#185391)- Get rid of mount/fsdisk scan of /dev messages - Additional fixes for suspend/resume- Fake make to rebuild enableaudit.pp- Get xen networking running.- Fixes for Xen - enableaudit should not be the same as base.pp - Allow ps to work for all process- more xen policy fixups- more xen fixage (#184393)- Fix blkid specification - Allow postfix to execute mailman_que- Blkid changes - Allow udev access to usb_device_t - Fix post script to create targeted policy config file- Allow lvm tools to create drevice dir- Add Xen support- Fixes for cups - Make cryptosetup work with hal- Load Policy needs translock- Fix cups html interface- Add hal changes suggested by Jeremy - add policyhelp to point at policy html pages- Additional fixes for nvidia and cups- Update to upstream - Merged my latest fixes - Fix cups policy to handle unix domain sockets- NSCD socket is in nscd_var_run_t needs to be able to search dir- Fixes Apache interface file- Fixes for new version of cups- Turn off polyinstatiate util after FC5- Fix problem with privoxy talking to Tor- Turn on polyinstatiation- Don't transition from unconfined_t to fsadm_t- Fix policy update model.- Update to upstream- Fix load_policy to work on MLS - Fix cron_rw_system_pipes for postfix_postdrop_t - Allow audotmount to run showmount- Fix swapon - allow httpd_sys_script_t to be entered via a shell - Allow httpd_sys_script_t to read eventpolfs- Update from upstream- allow cron to read apache files- Fix vpnc policy to work from NetworkManager- Update to upstream - Fix semoudle polcy- Update to upstream - fix sysconfig/selinux link- Add router port for zebra - Add imaze port for spamd - Fixes for amanda and java- Fix bluetooth handling of usb devices - Fix spamd reading of ~/ - fix nvidia spec- Update to upsteam- Add users_extra files- Update to upstream- Add semodule policy- Update from upstream- Fix for spamd to use razor port- Fixes for mcs - Turn on mount and fsadm for unconfined_t- Fixes for the -devel package- Fix for spamd to use ldap- Update to upstream- Update to upstream - Fix rhgb, and other Xorg startups- Update to upstream- Separate out role of secadm for mls- Add inotifyfs handling- Update to upstream - Put back in changes for pup/zen- Many changes for MLS - Turn on strict policy- Update to upstream- Update to upstream - Fixes for booting and logging in on MLS machine- Update to upstream - Turn off execheap execstack for unconfined users - Add mono/wine policy to allow execheap and execstack for them - Add execheap for Xdm policy- Update to upstream - Fixes to fetchmail,- Update to upstream- Fix for procmail/spamassasin - Update to upstream - Add rules to allow rpcd to work with unlabeled_networks.- Update to upstream - Fix ftp Man page- Update to upstream- fix pup transitions (#177262) - fix xen disks (#177599)- Update to upstream- More Fixes for hal and readahead- Fixes for hal and readahead- Update to upstream - Apply- Add wine and fix hal problems- Handle new location of hal scripts- Allow su to read /etc/mtab- Update to upstream- Fix "libsemanage.parse_module_headers: Data did not represent a module." problem- Allow load_policy to read /etc/mtab- Fix dovecot to allow dovecot_auth to look at /tmp- Allow restorecon to read unlabeled_t directories in order to fix labeling.- Add Logwatch policy- Fix /dev/ub[a-z] file context- Fix library specification - Give kudzu execmem privs- Fix hostname in targeted policy- Fix passwd command on mls- Lots of fixes to make mls policy work- Add dri libs to textrel_shlib_t - Add system_r role for java - Add unconfined_exec_t for vncserver - Allow slapd to use kerberos- Add man pages- Add enableaudit.pp- Fix mls policy- Update mls file from old version- Add sids back in - Rebuild with update checkpolicy- Fixes to allow automount to use portmap - Fixes to start kernel in s0-s15:c0.c255- Add java unconfined/execmem policy- Add file context for /var/cvs - Dontaudit webalizer search of homedir- Update from upstream- Clean up spec - range_transition crond to SystemHigh- Fixes for hal - Update to upstream- Turn back on execmem since we need it for java, firefox, ooffice - Allow gpm to stream socket to itself- fix requirements to be on the actual packages so that policy can get created properly at install time- Allow unconfined_t to execmod texrel_shlib_t- Update to upstream - Turn off allow_execmem and allow_execmod booleans - Add tcpd and automount policies- Add two new httpd booleans, turned off by default * httpd_can_network_relay * httpd_can_network_connect_db- Add ghost for policy.20- Update to upstream - Turn off boolean allow_execstack- Change setrans-mls to use new libsetrans - Add default_context rule for xdm- Change Requires to PreReg for requiring of policycoreutils on install- New upstream releaseAdd xdm policyUpdate from upstreamUpdate from upstreamUpdate from upstream- Also trigger to rebuild policy for versions up to 2.0.7.- No longer installing policy.20 file, anaconda handles the building of the app.- Fixes for dovecot and saslauthd- Cleanup pegasus and named - Fix spec file - Fix up passwd changing applications-Update to latest from upstream- Add rules for pegasus and avahi- Start building MLS Policy- Update to upstream- Turn on bash- Initial version/bin/sh  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~      !"#$%&'()*+,-./0122456789:;<=>?@ABCDEFGHIJKLMNOPQR3.13.1-268.el7_9.2    develMakefileexample.fcexample.ifexample.tehtmlNetworkManager.htmlabrt.htmlabrt_dump_oops.htmlabrt_handle_event.htmlabrt_helper.htmlabrt_retrace_coredump.htmlabrt_retrace_worker.htmlabrt_upload_watch.htmlabrt_watch_log.htmlaccountsd.htmlacct.htmladmin_crontab.htmlafs.htmlafs_bosserver.htmlafs_fsserver.htmlafs_kaserver.htmlafs_ptserver.htmlafs_vlserver.htmlaiccu.htmlaide.htmlajaxterm.htmlajaxterm_ssh.htmlalsa.htmlamanda.htmlamanda_recover.htmlamtu.htmlanaconda.htmlanon_sftpd.htmlantivirus.htmlapcupsd.htmlapcupsd_cgi_script.htmlapm.htmlapmd.htmlarpwatch.htmlasterisk.htmlaudisp.htmlaudisp_remote.htmlauditadm.htmlauditadm_screen.htmlauditadm_su.htmlauditadm_sudo.htmlauditctl.htmlauditd.htmlauthconfig.htmlautomount.htmlavahi.htmlawstats.htmlawstats_script.htmlbacula.htmlbacula_admin.htmlbacula_unconfined_script.htmlbcfg2.htmlbitlbee.htmlblkmapd.htmlblktap.htmlblueman.htmlbluetooth.htmlbluetooth_helper.htmlboinc.htmlboinc_project.htmlboltd.htmlbootloader.htmlbrctl.htmlbrltty.htmlbugzilla_script.htmlbumblebee.htmlcachefiles_kernel.htmlcachefilesd.htmlcalamaris.htmlcallweaver.htmlcanna.htmlcardmgr.htmlccs.htmlcdcc.htmlcdrecord.htmlcertmaster.htmlcertmonger.htmlcertmonger_unconfined.htmlcertwatch.htmlcfengine_execd.htmlcfengine_monitord.htmlcfengine_serverd.htmlcgclear.htmlcgconfig.htmlcgdcbxd.htmlcgred.htmlcheckpc.htmlcheckpolicy.htmlchfn.htmlchkpwd.htmlchrome_sandbox.htmlchrome_sandbox_nacl.htmlchronyc.htmlchronyd.htmlchroot_user.htmlcinder_api.htmlcinder_backup.htmlcinder_scheduler.htmlcinder_volume.htmlciped.htmlclogd.htmlcloud_init.htmlcluster.htmlclvmd.htmlcmirrord.htmlcobblerd.htmlcockpit_session.htmlcockpit_ws.htmlcollectd.htmlcollectd_script.htmlcolord.htmlcomsat.htmlcondor_collector.htmlcondor_master.htmlcondor_negotiator.htmlcondor_procd.htmlcondor_schedd.htmlcondor_startd.htmlcondor_startd_ssh.htmlconman.htmlconman_unconfined_script.htmlconsolekit.htmlcontainer.htmlcontainer_auth.htmlcontainer_runtime.htmlcouchdb.htmlcourier_authdaemon.htmlcourier_pcp.htmlcourier_pop.htmlcourier_sqwebmail.htmlcourier_tcpd.htmlcpucontrol.htmlcpufreqselector.htmlcpuplug.htmlcpuspeed.htmlcrack.htmlcrond.htmlcronjob.htmlcrontab.htmlctdbd.htmlcups_pdf.htmlcupsd.htmlcupsd_config.htmlcupsd_lpd.htmlcvs.htmlcvs_script.htmlcyphesis.htmlcyrus.htmldbadm.htmldbadm_sudo.htmldbskkd.htmldcc_client.htmldcc_dbclean.htmldccd.htmldccifd.htmldccm.htmldcerpcd.htmlddclient.htmldeltacloudd.htmldenyhosts.htmldepmod.htmldevicekit.htmldevicekit_disk.htmldevicekit_power.htmldhcpc.htmldhcpd.htmldictd.htmldirsrv.htmldirsrv_snmp.htmldirsrvadmin.htmldirsrvadmin_script.htmldirsrvadmin_unconfined_script.htmldisk_munin_plugin.htmldkim_milter.htmldlm_controld.htmldmesg.htmldmidecode.htmldnsmasq.htmldnssec_trigger.htmldovecot.htmldovecot_auth.htmldovecot_deliver.htmldrbd.htmldspam.htmldspam_script.htmlentropyd.htmleventlogd.htmlevtchnd.htmlexim.htmlfail2ban.htmlfail2ban_client.htmlfcoemon.htmlfenced.htmlfetchmail.htmlfingerd.htmlfirewalld.htmlfirewallgui.htmlfirstboot.htmlfoghorn.htmlfprintd.htmlfreeipmi_bmc_watchdog.htmlfreeipmi_ipmidetectd.htmlfreeipmi_ipmiseld.htmlfreqset.htmlfsadm.htmlfsdaemon.htmlftpd.htmlftpdctl.htmlgames.htmlgames_srv.htmlganesha.htmlgconfd.htmlgconfdefaultsm.htmlgdomap.htmlgeoclue.htmlgetty.htmlgfs_controld.htmlgit_script.htmlgit_session.htmlgit_system.htmlgitosis.htmlglance_api.htmlglance_registry.htmlglance_scrubber.htmlglusterd.htmlgnomesystemmm.htmlgpg.htmlgpg_agent.htmlgpg_helper.htmlgpg_pinentry.htmlgpg_web.htmlgpm.htmlgpsd.htmlgreylist_milter.htmlgroupadd.htmlgroupd.htmlgssd.htmlgssproxy.htmlguest.htmlhaproxy.htmlhddtemp.htmlhostname.htmlhsqldb.htmlhttpd.htmlhttpd_helper.htmlhttpd_passwd.htmlhttpd_php.htmlhttpd_rotatelogs.htmlhttpd_suexec.htmlhttpd_sys_script.htmlhttpd_unconfined_script.htmlhttpd_user_script.htmlhwclock.htmlhwloc_dhwd.htmlhypervkvp.htmlhypervvssd.htmliceauth.htmlicecast.htmlifconfig.htmlindex.htmlinetd.htmlinetd_child.htmlinit.htmlinitrc.htmlinnd.htmlinsmod.htmlinstall.htmliodined.htmliotop.htmlipa_dnskey.htmlipa_helper.htmlipa_otpd.htmlipmievd.htmlipsec.htmlipsec_mgmt.htmliptables.htmlirc.htmlirqbalance.htmlirssi.htmliscsid.htmlisnsd.htmliwhd.htmljabberd.htmljabberd_router.htmljockey.htmljournalctl.htmlkadmind.htmlkdump.htmlkdumpctl.htmlkdumpgui.htmlkeepalived.htmlkeepalived_unconfined_script.htmlkernel.htmlkeyboardd.htmlkeystone.htmlkeystone_cgi_script.htmlkismet.htmlklogd.htmlkmscon.htmlkpatch.htmlkpropd.htmlkrb5kdc.htmlksmtuned.htmlktalkd.htmll2tpd.htmlldconfig.htmllircd.htmllivecd.htmllldpad.htmlload_policy.htmlloadkeys.htmllocal_login.htmllocate.htmllockdev.htmllogadm.htmllogrotate.htmllogrotate_mail.htmllogwatch.htmllogwatch_mail.htmllpd.htmllpr.htmllsassd.htmllsmd.htmllsmd_plugin.htmllttng_sessiond.htmllvm.htmllwiod.htmllwregd.htmllwsmd.htmlmail_munin_plugin.htmlmailman_cgi.htmlmailman_mail.htmlmailman_queue.htmlman2html_script.htmlmandb.htmlmcelog.htmlmdadm.htmlmediawiki_script.htmlmemcached.htmlmencoder.htmlminidlna.htmlminissdpd.htmlmip6d.htmlmirrormanager.htmlmock.htmlmock_build.htmlmodemmanager.htmlmojomojo_script.htmlmon_procd.htmlmon_statd.htmlmongod.htmlmotion.htmlmount.htmlmount_ecryptfs.htmlmozilla.htmlmozilla_plugin.htmlmozilla_plugin_config.htmlmpd.htmlmplayer.htmlmrtg.htmlmscan.htmlmunin.htmlmunin_script.htmlmysqld.htmlmysqld_safe.htmlmysqlmanagerd.htmlmythtv_script.htmlnagios.htmlnagios_admin_plugin.htmlnagios_checkdisk_plugin.htmlnagios_eventhandler_plugin.htmlnagios_mail_plugin.htmlnagios_openshift_plugin.htmlnagios_script.htmlnagios_services_plugin.htmlnagios_system_plugin.htmlnagios_unconfined_plugin.htmlnamed.htmlnamespace_init.htmlncftool.htmlndc.htmlnetlabel_mgmt.htmlnetlogond.htmlnetutils.htmlneutron.htmlnewrole.htmlnfsd.htmlninfod.htmlnmbd.htmlnova.htmlnrpe.htmlnscd.htmlnsd.htmlnsd_crond.htmlnslcd.htmlntop.htmlntpd.htmlnumad.htmlnut_upsd.htmlnut_upsdrvctl.htmlnut_upsmon.htmlnutups_cgi_script.htmlnx_server.htmlnx_server_ssh.htmlobex.htmloddjob.htmloddjob_mkhomedir.htmlopenct.htmlopendnssec.htmlopenhpid.htmlopenshift.htmlopenshift_app.htmlopenshift_cgroup_read.htmlopenshift_cron.htmlopenshift_initrc.htmlopenshift_net_read.htmlopenshift_script.htmlopensm.htmlopenvpn.htmlopenvpn_unconfined_script.htmlopenvswitch.htmlopenwsman.htmloracleasm.htmlosad.htmlpads.htmlpam_console.htmlpam_timestamp.htmlpassenger.htmlpasswd.htmlpcp_pmcd.htmlpcp_pmie.htmlpcp_pmlogger.htmlpcp_pmmgr.htmlpcp_pmproxy.htmlpcp_pmwebd.htmlpcscd.htmlpegasus.htmlpegasus_openlmi_account.htmlpegasus_openlmi_admin.htmlpegasus_openlmi_logicalfile.htmlpegasus_openlmi_services.htmlpegasus_openlmi_storage.htmlpegasus_openlmi_system.htmlpegasus_openlmi_unconfined.htmlpesign.htmlphc2sys.htmlping.htmlpingd.htmlpiranha_fos.htmlpiranha_lvs.htmlpiranha_pulse.htmlpiranha_web.htmlpkcs_slotd.htmlpki_ra.htmlpki_tomcat.htmlpki_tomcat_script.htmlpki_tps.htmlplymouth.htmlplymouthd.htmlpodsleuth.htmlpolicykit.htmlpolicykit_auth.htmlpolicykit_grant.htmlpolicykit_resolve.htmlpolipo.htmlpolipo_session.htmlportmap.htmlportmap_helper.htmlportreserve.htmlpostfix_bounce.htmlpostfix_cleanup.htmlpostfix_local.htmlpostfix_map.htmlpostfix_master.htmlpostfix_pickup.htmlpostfix_pipe.htmlpostfix_postdrop.htmlpostfix_postqueue.htmlpostfix_qmgr.htmlpostfix_showq.htmlpostfix_smtp.htmlpostfix_smtpd.htmlpostfix_virtual.htmlpostgresql.htmlpostgrey.htmlpppd.htmlpptp.htmlprelink.htmlprelink_cron_system.htmlprelude.htmlprelude_audisp.htmlprelude_correlator.htmlprelude_lml.htmlpreupgrade.htmlprewikka_script.htmlprivoxy.htmlprocmail.htmlprosody.htmlpsad.htmlptal.htmlptchown.htmlptp4l.htmlpublicfile.htmlpulseaudio.htmlpuppetagent.htmlpuppetca.htmlpuppetmaster.htmlpwauth.htmlpyicqt.htmlqdiskd.htmlqemu_dm.htmlqmail_clean.htmlqmail_inject.htmlqmail_local.htmlqmail_lspawn.htmlqmail_queue.htmlqmail_remote.htmlqmail_rspawn.htmlqmail_send.htmlqmail_smtpd.htmlqmail_splogger.htmlqmail_start.htmlqmail_tcp_env.htmlqpidd.htmlquota.htmlquota_nld.htmlrabbitmq.htmlracoon.htmlradiusd.htmlradvd.htmlrasdaemon.htmlrdisc.htmlreadahead.htmlrealmd.htmlrealmd_consolehelper.htmlredis.htmlregex_milter.htmlremote_login.htmlrestorecond.htmlrhev_agentd.htmlrhev_agentd_consolehelper.htmlrhgb.htmlrhnsd.htmlrhsmcertd.htmlricci.htmlricci_modcluster.htmlricci_modclusterd.htmlricci_modlog.htmlricci_modrpm.htmlricci_modservice.htmlricci_modstorage.htmlrlogind.htmlrngd.htmlroundup.htmlrpcbind.htmlrpcd.htmlrpm.htmlrpm_script.htmlrshd.htmlrssh.htmlrssh_chroot_helper.htmlrsync.htmlrtas_errd.htmlrtkit_daemon.htmlrun_init.htmlrwho.htmlsamba_net.htmlsamba_unconfined_net.htmlsamba_unconfined_script.htmlsambagui.htmlsandbox.htmlsandbox_min.htmlsandbox_min_client.htmlsandbox_net.htmlsandbox_net_client.htmlsandbox_web.htmlsandbox_web_client.htmlsandbox_x.htmlsandbox_x_client.htmlsandbox_xserver.htmlsanlk_resetd.htmlsanlock.htmlsaslauthd.htmlsbd.htmlsblim_gatherd.htmlsblim_reposd.htmlsblim_sfcbd.htmlsecadm.htmlsecadm_screen.htmlsecadm_su.htmlsecadm_sudo.htmlsectoolm.htmlselinux_munin_plugin.htmlsemanage.htmlsendmail.htmlsensord.htmlsepgsql_ranged_proc.htmlsepgsql_trusted_proc.htmlservices_munin_plugin.htmlsetfiles.htmlsetfiles_mac.htmlsetkey.htmlsetrans.htmlsetroubleshoot_fixit.htmlsetroubleshootd.htmlsetsebool.htmlsftpd.htmlsge_execd.htmlsge_job.htmlsge_job_ssh.htmlsge_shepherd.htmlshorewall.htmlshowmount.htmlslapd.htmlslpd.htmlsmbcontrol.htmlsmbd.htmlsmbmount.htmlsmokeping.htmlsmokeping_cgi_script.htmlsmoltclient.htmlsmsd.htmlsnapperd.htmlsnmpd.htmlsnort.htmlsosreport.htmlsoundd.htmlspamass_milter.htmlspamc.htmlspamd.htmlspamd_update.htmlspc.htmlspeech-dispatcher.htmlsquid.htmlsquid_cron.htmlsquid_script.htmlsrvsvcd.htmlssh.htmlssh_keygen.htmlssh_keysign.htmlsshd.htmlsshd_keygen.htmlsshd_net.htmlsshd_sandbox.htmlsssd.htmlsssd_selinux_manager.htmlstaff.htmlstaff_consolehelper.htmlstaff_dbusd.htmlstaff_gkeyringd.htmlstaff_screen.htmlstaff_seunshare.htmlstaff_ssh_agent.htmlstaff_sudo.htmlstaff_wine.htmlstapserver.htmlstunnel.htmlstyle.csssulogin.htmlsvc_multilog.htmlsvc_run.htmlsvc_start.htmlsvirt.htmlsvirt_kvm_net.htmlsvirt_qemu_net.htmlsvirt_socket.htmlsvirt_tcg.htmlsvnserve.htmlswat.htmlswift.htmlsysadm.htmlsysadm_gkeyringd.htmlsysadm_passwd.htmlsysadm_screen.htmlsysadm_seunshare.htmlsysadm_ssh_agent.htmlsysadm_su.htmlsysadm_sudo.htmlsyslogd.htmlsysstat.htmlsystem_cronjob.htmlsystem_dbusd.htmlsystem_mail.htmlsystem_munin_plugin.htmlsystemd_bootchart.htmlsystemd_hostnamed.htmlsystemd_hwdb.htmlsystemd_initctl.htmlsystemd_localed.htmlsystemd_logger.htmlsystemd_logind.htmlsystemd_machined.htmlsystemd_networkd.htmlsystemd_notify.htmlsystemd_passwd_agent.htmlsystemd_resolved.htmlsystemd_sysctl.htmlsystemd_timedated.htmlsystemd_tmpfiles.htmltangd.htmltargetd.htmltcpd.htmltcsd.htmltelepathy_gabble.htmltelepathy_idle.htmltelepathy_logger.htmltelepathy_mission_control.htmltelepathy_msn.htmltelepathy_salut.htmltelepathy_sofiasip.htmltelepathy_stream_engine.htmltelepathy_sunshine.htmltelnetd.htmltftpd.htmltgtd.htmlthin.htmlthin_aeolus_configserver.htmlthumb.htmltimemaster.htmltlp.htmltmpreaper.htmltomcat.htmltor.htmltraceroute.htmltuned.htmltvtime.htmludev.htmlulogd.htmluml.htmluml_switch.htmlunconfined.htmlunconfined_cronjob.htmlunconfined_dbusd.htmlunconfined_mount.htmlunconfined_munin_plugin.htmlunconfined_sendmail.htmlunconfined_service.htmlupdate_modules.htmlupdfstab.htmlupdpwd.htmlusbmodules.htmlusbmuxd.htmluser.htmluser_dbusd.htmluser_gkeyringd.htmluser_mail.htmluser_screen.htmluser_seunshare.htmluser_ssh_agent.htmluser_wine.htmluseradd.htmlusernetctl.htmlutempter.htmluucpd.htmluuidd.htmluux.htmlvarnishd.htmlvarnishlog.htmlvdagent.htmlvhostmd.htmlvirsh.htmlvirsh_ssh.htmlvirt_bridgehelper.htmlvirt_qemu_ga.htmlvirt_qemu_ga_unconfined.htmlvirt_qmf.htmlvirtd.htmlvirtd_lxc.htmlvirtlogd.htmlvlock.htmlvmtools.htmlvmtools_helper.htmlvmtools_unconfined.htmlvmware.htmlvmware_host.htmlvnstat.htmlvnstatd.htmlvpnc.htmlw3c_validator_script.htmlwatchdog.htmlwatchdog_unconfined.htmlwdmd.htmlwebadm.htmlwebalizer.htmlwebalizer_script.htmlwinbind.htmlwinbind_helper.htmlwine.htmlwireshark.htmlwpa_cli.htmlxauth.htmlxdm.htmlxdm_unconfined.htmlxenconsoled.htmlxend.htmlxenstored.htmlxguest.htmlxguest_dbusd.htmlxguest_gkeyringd.htmlxserver.htmlypbind.htmlyppasswdd.htmlypserv.htmlypxfr.htmlzabbix.htmlzabbix_agent.htmlzabbix_script.htmlzarafa_deliver.htmlzarafa_gateway.htmlzarafa_ical.htmlzarafa_indexer.htmlzarafa_monitor.htmlzarafa_server.htmlzarafa_spooler.htmlzebra.htmlzoneminder.htmlzoneminder_script.htmlzos_remote.htmlincludeMakefileadminadmin.xmlbootloader.ifconsoletype.ifdmesg.ifnetutils.ifsu.ifsudo.ifusermanage.ifappsapps.xmlseunshare.ifbuild.confcontribcontrib.xmlabrt.ifaccountsd.ifacct.ifada.ifafs.ifaiccu.ifaide.ifaisexec.ifajaxterm.ifalsa.ifamanda.ifamavis.ifamtu.ifanaconda.ifantivirus.ifapache.ifapcupsd.ifapm.ifapt.ifarpwatch.ifasterisk.ifauthbind.ifauthconfig.ifautomount.ifavahi.ifawstats.ifbackup.ifbacula.ifbcfg2.ifbind.ifbird.ifbitlbee.ifblkmapd.ifblueman.ifbluetooth.ifboinc.ifboltd.ifbrctl.ifbrltty.ifbugzilla.ifbumblebee.ifcachefilesd.ifcalamaris.ifcallweaver.ifcanna.ifccs.ifcdrecord.ifcertmaster.ifcertmonger.ifcertwatch.ifcfengine.ifcgdcbxd.ifcgroup.ifchrome.ifchronyd.ifcinder.ifcipe.ifclamav.ifclockspeed.ifclogd.ifcloudform.ifcmirrord.ifcobbler.ifcockpit.ifcollectd.ifcolord.ifcomsat.ifcondor.ifconman.ifconsolekit.ifcontainer.ifcorosync.ifcouchdb.ifcourier.ifcpucontrol.ifcpufreqselector.ifcpuplug.ifcron.ifctdb.ifcups.ifcvs.ifcyphesis.ifcyrus.ifdaemontools.ifdante.ifdbadm.ifdbskk.ifdbus.ifdcc.ifddclient.ifddcprobe.ifdenyhosts.ifdevicekit.ifdhcp.ifdictd.ifdirmngr.ifdirsrv-admin.ifdirsrv.ifdistcc.ifdjbdns.ifdkim.ifdmidecode.ifdnsmasq.ifdnssec.ifdnssectrigger.ifdovecot.ifdpkg.ifdrbd.ifdspam.ifentropyd.ifetcd.ifevolution.ifexim.iffail2ban.iffcoe.iffetchmail.iffinger.iffirewalld.iffirewallgui.iffirstboot.iffprintd.iffreeipmi.iffreqset.ifftp.ifgames.ifganesha.ifgatekeeper.ifgdomap.ifgear.ifgeoclue.ifgift.ifgit.ifgitosis.ifglance.ifglusterd.ifgnome.ifgnomeclock.ifgpg.ifgpm.ifgpsd.ifgssproxy.ifguest.ifhadoop.ifhal.ifhddtemp.ifhostapd.ifhowl.ifhsqldb.ifhwloc.ifhypervkvp.ifi18n_input.ificecast.ififplugd.ifimaze.ifinetd.ifinn.ifiodine.ifiotop.ifipa.ifipmievd.ifirc.ifircd.ifirqbalance.ifiscsi.ifisns.ifjabber.ifjava.ifjetty.ifjockey.ifjournalctl.ifkde.ifkdump.ifkdumpgui.ifkeepalived.ifkerberos.ifkerneloops.ifkeyboardd.ifkeystone.ifkismet.ifkmscon.ifkpatch.ifksmtuned.ifktalk.ifkudzu.ifl2tp.ifldap.iflightsquid.iflikewise.iflinuxptp.iflircd.iflivecd.iflldpad.ifloadkeys.iflockdev.iflogrotate.iflogwatch.iflpd.iflsm.iflttng-tools.ifmailman.ifmailscanner.ifman2html.ifmandb.ifmcelog.ifmcollective.ifmediawiki.ifmemcached.ifmilter.ifminidlna.ifminissdpd.ifmip6d.ifmirrormanager.ifmock.ifmodemmanager.ifmojomojo.ifmon_statd.ifmongodb.ifmono.ifmonop.ifmotion.ifmozilla.ifmpd.ifmplayer.ifmrtg.ifmta.ifmunin.ifmysql.ifmythtv.ifnaemon.ifnagios.ifnamespace.ifncftool.ifnessus.ifnetworkmanager.ifninfod.ifnis.ifnova.ifnscd.ifnsd.ifnslcd.ifnsplugin.ifntop.ifntp.ifnumad.ifnut.ifnx.ifoav.ifobex.ifoddjob.ifoident.ifopenca.ifopenct.ifopendnssec.ifopenhpi.ifopenhpid.ifopenshift-origin.ifopenshift.ifopensm.ifopenvpn.ifopenvswitch.ifopenwsman.iforacleasm.ifosad.ifpacemaker.ifpads.ifpassenger.ifpcmcia.ifpcp.ifpcscd.ifpegasus.ifperdition.ifpesign.ifpingd.ifpiranha.ifpkcs.ifpki.ifplymouthd.ifpodsleuth.ifpolicykit.ifpolipo.ifportage.ifportmap.ifportreserve.ifportslave.ifpostfix.ifpostfixpolicyd.ifpostgrey.ifppp.ifprelink.ifprelude.ifprivoxy.ifprocmail.ifprosody.ifpsad.ifptchown.ifpublicfile.ifpulseaudio.ifpuppet.ifpwauth.ifpxe.ifpyzor.ifqemu.ifqmail.ifqpid.ifquantum.ifquota.ifrabbitmq.ifradius.ifradvd.ifraid.ifrasdaemon.ifrazor.ifrdisc.ifreadahead.ifrealmd.ifredis.ifremotelogin.ifresmgr.ifrgmanager.ifrhcs.ifrhev.ifrhgb.ifrhnsd.ifrhsmcertd.ifricci.ifrkhunter.ifrlogin.ifrngd.ifrolekit.ifroundup.ifrpc.ifrpcbind.ifrpm.ifrshd.ifrssh.ifrsync.ifrtas.ifrtkit.ifrwho.ifsamba.ifsambagui.ifsamhain.ifsandbox.ifsandboxX.ifsanlock.ifsasl.ifsbd.ifsblim.ifscreen.ifsectoolm.ifsendmail.ifsensord.ifsetroubleshoot.ifsge.ifshorewall.ifshutdown.ifslocate.ifslpd.ifslrnpull.ifsmartmon.ifsmokeping.ifsmoltclient.ifsmsd.ifsmstools.ifsnapper.ifsnmp.ifsnort.ifsosreport.ifsoundserver.ifspamassassin.ifspeech-dispatcher.ifspeedtouch.ifsquid.ifsssd.ifstapserver.ifstunnel.ifsvnserve.ifswift.ifswift_alias.ifsxid.ifsysstat.iftangd.iftargetd.iftcpd.iftcsd.iftelepathy.iftelnet.iftftp.iftgtd.ifthin.ifthumb.ifthunderbird.iftimidity.iftlp.iftmpreaper.iftomcat.iftor.iftransproxy.iftripwire.iftuned.iftvtime.iftzdata.ifucspitcp.ifulogd.ifuml.ifupdfstab.ifuptime.ifusbmodules.ifusbmuxd.ifuserhelper.ifusernetctl.ifuucp.ifuuidd.ifuwimap.ifvarnishd.ifvbetool.ifvdagent.ifvhostmd.ifvirt.ifvlock.ifvmtools.ifvmware.ifvnstatd.ifvpn.ifw3c.ifwatchdog.ifwdmd.ifwebadm.ifwebalizer.ifwine.ifwireshark.ifwm.ifxen.ifxfs.ifxguest.ifxprint.ifxscreensaver.ifyam.ifzabbix.ifzarafa.ifzebra.ifzoneminder.ifzosremote.ifglobal_booleans.xmlglobal_tunables.xmlkernelkernel.xmlcorecommands.ifcorenetwork.ifdevices.ifdomain.iffiles.iffilesystem.ifkernel.ifmcs.ifmls.ifselinux.ifstorage.ifterminal.ifubac.ifunlabelednet.ifrolesroles.xmlauditadm.iflogadm.ifsecadm.ifstaff.ifsysadm.ifsysadm_secadm.ifunconfineduser.ifunprivuser.ifservicesservices.xmlpostgresql.ifssh.ifxserver.ifsupportall_perms.sptdivert.m4file_patterns.sptipc_patterns.sptloadable_module.sptmisc_macros.sptmisc_patterns.sptmls_mcs_macros.sptobj_perm_sets.sptpolicy.dtdsegenxml.pysegenxml.pycsegenxml.pyoundivert.m4systemsystem.xmlapplication.ifauthlogin.ifclock.iffstools.ifgetty.ifhostname.ifhotplug.ifinit.ifipsec.ifiptables.iflibraries.iflocallogin.iflogging.iflvm.ifmiscfiles.ifmodutils.ifmount.ifnetlabel.ifselinuxutil.ifsetrans.ifsysnetwork.ifsystemd.ifudev.ifunconfined.ifuserdomain.ifpolicy.dtdpolicy.xmlinterface_info/usr/share/selinux//usr/share/selinux/devel//usr/share/selinux/devel/html//usr/share/selinux/devel/include//usr/share/selinux/devel/include/admin//usr/share/selinux/devel/include/apps//usr/share/selinux/devel/include/contrib//usr/share/selinux/devel/include/kernel//usr/share/selinux/devel/include/roles//usr/share/selinux/devel/include/services//usr/share/selinux/devel/include/support//usr/share/selinux/devel/include/system//var/lib/sepolgen/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector-strong --param=ssp-buffer-size=4 -grecord-gcc-switches -m64 -mtune=genericcpioxz2noarch-redhat-linux-gnu  directoryASCII textSE Linux policy interface sourceSE Linux policy module sourceHTML document, ASCII textmakefile script, ASCII textC++ source, ASCII textASCII text, with very long linesASCII text, with no line terminatorsPython script, ASCII text executablepython 2.7 byte-compiledXML 1.0 document, ASCII textcannot open (No such file or directory)?p7zXZ !#,] b2u jӫ`(2')bi (ԗЂ:m3s"Z<߀5+Κ a:!X2ƊqJV źZ=![{9>G@\j[Z >OtZS¬m#,ʖ1Uک~֕CS{塾˦î*]X?\3@&.asƀe7~ 1h!U=MD[&G nU}3Fi&Y;&dUO7~Y++U7t֠C@z0I4N1M)(2ɒtQ?I̒>}Z%^:e^y[bD0Q-縼m:RDxBR#ݲ1Y8 Ax M Q E.r7s>jy¢!W1`;RK $'mLcxe.>&V՚O;S %fzhۣ]]lªwq㶖}8/JD*#Nײ@fxy޾~7e25+x*N7)1ZN-FO0nH6dBo$Z5uA 9L󙟡U>2 q);8(-8&am'#=nänEgC D4{@r 8v+]JMww=$6Cy"2=#pFngd魹pAjӣ#=}6*OWQE o 16~` l 6Wv/@=R?"# fZL(ͯV|b9N$TF=.6- N^{kFqqѫvnZQC-&㭾Ӻ]'OMLg1q99T#\?1]Zl <}mD4rS9L7 X~:ysg'9*ZҊMCuB\(L!nl,}\약4e ΂8'NWlK8zRrƐ@QD|O8WL܉@Oof׉H1n W}S C'Tޙf2idUӓ"tHu/DzHsv /p#LߠKvf !e;-v` SaԢj3)|=H}"3Agh-2Jmg++ dWf/RidKIl6CL!?r~#BI8Wd4Kb-!Wsq9z URݛpT/AS>@L62|TwJQ#;64 ŏSL!ߏ+{vb1\}'wo8!ctd (d\LI{diFMZ1bP,o7T*vpbdXV'G1b*)覃ir#]Ŧ2Ǵ,uA6e;^ Ǿ/IGC#"/H¡wEUPO-{cE%GǨZ~A>wIɳB.O|:s3'1GBNȖuItV >a|$+!up%ͳaLc{u$.0Ofy(56$L@\q+FfJT%Xrs5Hcw"m^ JU6Ѯ>_ 9h /.KwUB)]>n+`(eԭ`[c/{/KwDv[ ŗBqF`OF. _gB2Dd&/C`-&2!ܩiDN;gwdPCBçy@HawX!Mko*)J1@吩b-e$O+^:G'yJJJfٳǪxuG" 0KUzjwYJi$LkmJBpE l4çr*X`\쭶+"Zha]ӯav\k&DPҴbaL]FJtAg0@Xr ɎV:a.93GZ/y1K&&[:^iwq?Q)TQpcYYe }U(`c[8CNerW)}"d $d"&0{Pi"UE'nC[_%Z8:땀4Wm/a'bosyo}vP^8g^Mxt-f|LJ%G+p$ruE XsqRu(]ɏk.ilY̫n^$ .yE~JɑvNDdqmU`%AS^7bYc{yHN:xڨ_u{TJ*l%ӹ*i㧄˞0^) jW-̐GK %lfɄgj2&ul8:?)6)jmzS amOnrU#Y{)K3wkf~}pcS8MzE\@ich#0] XXܘϾ..{TIȗ]U9=s\D8 еķ%W4wC X}Aڋb?]7l>hs*m-mQwF|*S$%7ww/;1t`U1$,=ᾭ|,>Ata*0X &uWL8(]2Oy&hފ)IB뿳j#%*$[ui]XD1wrho\xh&bqb}̢|ku7M8N]ء5]ODEɞM&2몞&;TѢv R51$ 5QwSU|^5yM^c=Fwn*D}*8N a߇b͘8m gç9P&t!c~3|ŋlHisi::B̈bSinmʓ(Yyײ՗=3M Y=P0a~ mo{5 |𜋙Om.8$ hJ>b>0<7_. ˉGAI;sPC:O~ʴREpR)t~לGd!׃+dsiTixnhrv-yxCa9itҲZ?z^҈L鈈uC_Ų,İM]KI[15 N3ڏJV^QuZ"TQ0i;[dDKyHXGr$㯳- >r%hy]X@yf5;O?؁<SScxZ$ y-0 >)RӫW:[liu;p$$dYl.7*a&-Xtc ǐr$ҹpe-?l @ԒH&FP3'plƅ8 )\X[è{0@9d\Wo.JlȾfx! ъؙD\3o 1uˍ}>}+?-0RCpd[34/ь>WwU}X~`<= { ..cy %(XCFGxDMѽRxՃȪ>OBTmA{fMC-GE-3OR }fGRjN$wQpRjO|kt-!_ 6/[֠ĜM^(Ffbz6/pw`Eܰ4 0Q䤁Kx̄+fyd3CmZOBJi rFRRRT~-x5x= dch]M"ĤC~n(?KdO`"4hSd'\D(ḞN?/`x ׎*MBT}Fѩ qLD7皩oӑY73y>&.U>c($DO~ ༀi-I$Xo\ L@̀.9Qi;~q7AgMc.}YNLp):d%" }Zy|#'4d.=Tmg~ A}v@46^Zc b? 6=D;cIZO"=Cl`:Z3:ߓj8tvgְiHrVQCm%9;\IoݹFUM` pk4MK+*?~=d#dK pi7a* Ȼ VRyɸZ岍{D[OfvąaƋx'>kp 9-^9e嶹*-RYPԃ]6 Ǯ1D}%APt`TrHnBC"6Q|P1 mG]>W~Pf,q bCVfdh_eNSҽΉ%V~ASʧŞTKk-爙*t͠U鰖PKGSΏy'##}  {8. ]8p, L3gUސd5܂uc㮥So] C;=<=ιt;f֌60<1kJ>JcX* xm }VeOri@&Fh :td8 1[fwՓn5/7Z?cwrTVԗ;pؙ$?) :hϼ}tu4KNӧ2{ A[5+TM(n{26(}Əp`3 З93?^a XX!$Lgbl  4uiiMʉG7!t N>=(ԃCLJP4Vw=/|@i$5jZ麅JChZSַ]R9bgn!"{R0qbVơOWǑV2OAyUwUXh|xبEL Aexr#J(dzko!ٶ=OьQZ=CUia6.[?o3'GD)#:":S=Q9` צفP3wSUL %(1bA7 #g_Εݿrxƃu™L4ڭ=˲YoKΥazW[^jYZb9  FY&UG%Qj˗|7['7f# eӹSDm"Uj29b*ĵ?,4w"ϪtE6%4=hO9zFD)^%-`^DlqՒ7e^x#%\|օKޘ\Ew竈Aav[{k9T*X6|(_wjV?4-V.^V1z_^5]c0RW6_z)`t`BP50 ^}n?N.:D}mAh,n&hp!OI H?Yp: GdQFoجuS7IgܟH%C"19L Ft|hD_ h%AZ/ C?$bMփ3&͔0 f>FCghzNk_Wako:_*pG6t]j'"$:+%'"eWYN^(&,nPYqh3𽉹?d)7\x60gbBR`ݱT-)K>KI4QYZ`"}5% jSMEv7[-|5kݬ!բN@i@pQjrn| XO[BJ`,uD#^dkl8?w.gӹ`Xp/ZPm>;I9puv?WGޞRߧ1)gf=Ԩx٣GGeTco`Z ]S%^*8^f a`fmFמ_@Z0ǪL-q?e>o ʵ&oiM$xaUj3;0 ^<6>oW:OӪ yMakB^dSkc Զ n/=&Jwaӑ@QYY'6ev=<;IUp(]e?o~=o;G](KLnJL!i/wD}GdH`Y]^?.,,o~^"r!0q =z-&@7gйNVJp>qWi4YNAԧ4@lQbOpdh][ǪUVTkP 1`)TTp% zkn ̝ach8 2| +S[A&'Dg4}w4U5h/Gvp>wʘl2ӹ,p|k5)3Kr1iL> ViJYﻑYWe>ɡVQ ȏIlR!g,Oh%tn;<;B<|E_gv( %ptfOXjH6 |/ `:h`eE/6g?tzBo+M c=6J [6i ͈ETYjd|!\d|QHGCv<}b~#/I@H ffïkޚ׍=?Oyjcd䍔șU|PV]I[xbl%1l%$hYI@ ӉL'~(Fl.0gSū;y`JΌ1S|b>Zoa%0pcuM!4A}.Mzu7ڷ'3̖auV%LD4klkMtЭ3L!n[ .9d:6-T 5 bA2D#\`?yGG% ~Κ V ^ Ċ-Uw3y,O8#ߓ;{Rw;A O}n,uQWL1h6\0+!6%`lJvZ1-B\AkkO/v r+Yyx#$Qy{ @3?oK@+zQE &ȹH鿒sT_arFqaQDl|.HfSe;SԜ"*\T[Z2͛iSqIUd˅*CcCyi+*e&s4Z_2֜ce2E?i {ԇ%!#]SpN˯Hm"|!F DpzX.L5X,h77e4LZOpt!^荾J"`LS^K!s( 4VcZ :h})FJ1jPϳ_O@tv(Τv/}vehyvck@@@}/Px ګ(TZ ɑ~|klyݣ g$@_`m}6 0Dv%F CtX͹ĢWyB|Eӹ"rJ|+qٗs;*~8͈| M/~{s4 Rn1mZX}C $)a[-m:I,uVR/UvL m ? 9H9@-7@dUzaEL=n-a:%*7 *w&# 3b! T:?PO!k)5cg)Ghdj,WOڞeD3RUU⒴Zqp&koOup ? ss(sn74SW\$ 8gP͐\Dd(L``Po+fjpA#!(7/=Zٹ M'Y_HkA1ܺ;]]&"?&Z gb3Z̐ҋ˷h =%tR#j:c@2U'}Ҙn<\ b[ph,>LgZW=4Mɉ-6 FP%WƢ6]b-=gPa/f@.)C{2O>Q|f 40lݛ㪝&#É; Zy]? BN}w;Y4~9Q[v=|JV1_v,sLG,Ww̹;ҽ!B#caSg+Y i!cnd~pA1àaUUJգBB)7<@zbW(HyrG4wy)*,%;| ]ۨ>хݗ"rMUb٠)gw-,b{-72ߔ$$Wٛk5kFƸ_�a~u}wR|\(ETv@R^`Ym5?|rF}{7QL.`T9N/%yW7"%pPC7Yye4a[ r\s0E"D!d݊1S/kǂu-*519T1b]dx[ZR,?NAx,1-[BKO֦-abJ [bX4Ŭľ-P$ KIZz]-Be4}M;?H.Yc6 _n/svR+&q%!`U1|5|rnJ/M m1=@6̀bB ˑ'P#(0:ngBn*Hpvu}MJtڑ4Dsku7] Q)̌||5ɔa{c,m:}CmxbΡi.r7:aqHq93wݤ7^σaH ;2WT(N 33+ +Qb WεнRhވH6o6?^W@R*)6+ܝOG\dQk/.,ģc1u>o^s JS(ˣ?ûr\/)uVRe`˱) =zGF:v ɤO߻׌He딸![iq&D7(jbZ9ÓћFSl/:zq \Nxn wHަ\fz*A2f'Q#;{&"%h$ZMeVT{6S-EiFqo)3(鷰x-xԌuWBLd?zbmWjxm`C/iNPigN!փ4if A%+4.H0<"8r/;?fTBne?ȑƭNZ2<._G2OJ/,]m&pG^/q~,]k㌳hB81QyGF ٭k /cMX<-VGFڳ!oYLۍ %';.4crH$m@EQ(XJ:@⎟rLqJБ۪D|/:сk7l=< oQ f15TyU04OӦ^pЉ! !I!sLF` `|Cp-_6`_, ~ٵMIct]*FG|Kh&wwi~E<ߞ*tuxxNg;TIs ~( CD CHf3Ve'h.yqf ꫗A;tC?haȽ*/yM~vcpV6U2/PO!r**4 7kVagzύxI`N*7׺حͻj=݋ rrl}beuhJ@1W0fQŊкz:Wcpsե"vGٻ6]$"h ɱTE5[ ?\֬fr'Wþ bjtAӎaߐ>`ҝ.hݮB sH:m&sJx]\1Q{ l#'MiG!-gv_.s뇁vr|eqJY =F.5,;×SkvlVt:څ,Sǜr]s8J+nϟCc4`9{~dM9< =%ydx!\(&״ 6V5? l>i[- tꚛ)ݩaOE>8 {4͸4vNUxܭ0~*5C=HcD{a]'ɺtOaOx Oj?a*NfroݖZӿo/e_+@GWCҦ5 #PӐ } j0wO mM~J3ۃyZ[2RV֓&KFzzKLVt`Qܾv|IW'b5m\&) uI_bɧ>' {DwTTީ1~PC?*E EOws቗mdL7ַڵL\Qq_`6Tk (gJ#?t] ʺ  O(@ekpGuYNӡ ݷ\I#9JcW1W}Ñ+ O ~_LL zx$1O' ռKcȨ~¡Ő);PvF B8VUy'20vc]R>i)XvٴFN؈Z%f 3Vra9_**N&*ˤS=nH/ -c5m=J-?7J\pMVLyx╍iˑd[ť\&bs~k H)a|飩Nh_&sUu8tz [~a늬+k=X J]ĐԈ_ F }t*&rpLsp=5-fxyT +=x:Ȅ/1;/81rqb{pھfGQd'Jl= IZhOoѩKet1.qfZ .-/m뒻 ?~ r=k"#cPtSݟ[fA8PT%U:/HxJ2\CˠYl]+zߠ+ @({(  Ri/0XM&ђ{}}|݁Q"s iP#ì3>)w<7;n{yjDV*%i.5BP0*X, n2˛pE=ϱ hrg[K/J"~Z#,.gZZg͐AƠ:L+EjS:Y]q=|& 2RG!xnywhk#.r:~`At0%_T,Nwɠ!~Ψn}T>@xI4HIQQ'Oқ65|xj#2!95]Ěߐi'B^^Ri %(/[V=F˄.Xr?"VD Tɉi: >B\Bܵqє5_A\fV:~S;1eKTTUY3/o-ZxnF蹍E r\w@Cq5Syc ng{[-XM6XLNj`] Lh0 Na_yՠ=EߜKWI-]hV/`j}q+I&(iLyW#/}/]B0}73Ii0$gkoI YDGH2 NMb{9bu–$b}p%"{*̸&ً_,Gb>e.HrK, N+~X،}".n;̭ś٬i#ܫ0Ѹ.neux#\u7}ڕ ǐ%l _VV$;"0y7$p:{'"t(PQ5g5J3)WKM/R`"2x =O| lh1pH w =mwcO p)vB۟Iz+ҍ{kY cLaѪM0-,Ssva%G甄IPtOsw\o%>?҈Mlz,S0(k,(qΟ.ޭ&"mK-(Fmd }aWЈߜTgᲘ1S=ubI{dÃ,puGKS.v$hRH vŷ6{F01'߬W 0eC-$;,HS#GC+H{lM`R2FmDvuEf~\o;$( ?ORey)`6ͣtν4>c#GTi#J_=ZC5+^VÀc${cz2@R⌈:0\aT៬"5259uh=+Dv}[.#"@$+v[-ߵR(w93mUQ}tWeEhOyF~$Y|Y37}!dggzk`s3{ĀJX;~:N`@":{¼͂k!691>6o~E!k΂~h-vPЗ\(}Sq~_QFD6+}IӨT'n5YHxkSY;}7D.:ۙbV*b9etj_6yyu %a$8| 3lv[\d:W9]'X7hk%|n>Z]eQ~_E?g7 P/Vf䫟?9,hȦ!*- U`subV@>!LhWz-tbJ D&w$sX~2FXH61RORe}B֯?kE-)x );\?Xp]c[$UmJF Wk+u?Z=ja\.☂SRDI\$VbG  -6iz I&*v mL5Ջn]z剻2aOn>IF#pޒ3z~ÒQyG8 Dv:,*T K /&NȚ~7$ףJ[]ňb^ )D]13Fqޏ r"Bi?8xN}@.H_EH\ߍHߤęF;[>yW369RځTqtnM^𛚵Ed6t[|r3Fx:8Y<:[A8_7Uh`q7'G"+HIHNT"nݟY ^Qcve nHO\D;^BD`K)/qw#5{'3IīDa&Z*!ܹą_\ :ZRJB>wMFO" w2BsJg"q/j0il{ҘBȠO'E`'ngEooy1t ڢ5V筌_z|jwr\Yaxx]k3+מqZ4ԏOMr峩xp|$"&z]0Pq) G9<׿6k2I>{0h *7lr'Ykp^$(SzpؒMT2-Fb! ua!P391(Ce0k9JHd44cr71F%o֜GԝO@Pb5N.a;crCr@50Hab;e>aGv'!)Ąxh=̻A[F4) Ndp^gd |'DZuƩ٣ت'N9'{HmRCj7l8&1iQ I- ?¨Pʗ0v\5n*z<uoπ\cફ@N)\)6B(ЧA$Cc尀Y+QU4P5n؋UF[นv 4qxCзN p0~j!xMfⷑ|aIZjYz70ypTw[ߗ#0~rh~>ArHAzpQJ6cizISW6+<~+o"EH-ijxY<Ō@}*\o{j,'~ЖkS8&rz;CdCnVs cH\KX:0Y!Q㉊/G"fOӃR&X/|n0ltJW9Lt~?Lsp>BݡDmvo"rt26V襼T;qHaogPj~."{c&t osw,5gULw9`Y1)3%ދmRIQi3Pn6G\#y9lyǑCO\8`'fJ4(b RVi; D@"ΎY(SK۾O0{xPb'r޺dّ."Y.?V#mxz&( V҇9٪ۈ _5vG4VPhP!c8F銼P(>A%95 ~kGp:S@PDԖ*$ ثgj{}-gGvMyaLx5yJJmMd`!ͪ&WKψŗ1rJE~7SW%6Cyl(LkF^oLW䇏^%h&=hQeb |>OA^ DT>M"]+e80H%j?POZg=h,mFωt໧!C'sTTu H|fg* ~82Q3_\pş`L͂%jhu\fp gWUW|O~5@"WW]KU_jn5/ex$ICP|XZl~ Z@Aid]ЗXV< KYvkjTt!f㦾 Kn;e6/D?Y} ޔҩ1h8nKt~܊s[EE8E*g#I]K̄ݴK 4^-В 5wB-廙tb`P;޾ea\q^{Pϭo-Y)Ě64A?U=u'1̇%2|nɑ4Mi|2s2i?ًNuNz[}4faN'-D xW$ Rw>·Oi@qaMWIȬ1"JoE4xt5P]zWMj|H0JlA/dF8 v*̧ W?61Yk3[jTrjb@'[.t_9ZsfLzo2t/m?d0}i/9 x.8Y(Zݩo*BAi ȋ22{o5vRtuU,2j5@NFs8z l~w(\9Mɠ[c(BKgtE~B0MW/d69}ז2kx 47pHfUW\2hAX*5`"#n `ݲ6:C(3rl7 T4CZ0WEWܶwP;xn0*o^)N[DwH, YؙVF ݪp{YhJm@oZ500+ uʰ'{ (e_6fnԫ,޺MHHrb8a+#EqUY,hd"t w1z1EV}w-x@ iN/(z'!,%&'h~F(7s6:io0.i\TQX?>$WGfD ur] +L ~I=*:ܮOL9a&'|77ӓɐ (իUw!Io~k_sJ)>=%2zb~32>-H΃ U3a׹3~T>$p\]=q?˕Jy]\yT(ѤH¡`^h{" 8l~춤+ QI 4V#@D%7!SdNlKߜn0E@"~; \͝PUFQCs#`Yw#3Nuo0yc{DrHs͟dlEQ/{$͒A&͖ 6 }󉶈-,ɡ͐|/2#zIL`(i)hsh+O GOl: b}4܆Q5*C"ҌK&m8;DH`|8}l=՞ cztH^m$')~GLx7'攮 X9-r4~OSOx`gڋ$k4p8i)"(;~=\ب\Ξb03^2]ncVXV~H;r*@|2~ҰoD!׀ģ+`yzV=>?RfEe ) U\95y2PL§x0&cF=hXe|bB~gT?CPO+'} 6yUD" D8V+vy$A`cķ4CLh(w6&?2\9MQj_c(3QGhuw蛒5e=nL}J(|e&m**ۮ:]!,\ 6?Ѹĕ$B6Djh=[|KQI&\D|.f LZo•ڀk9]XJb|~̔Wz嗷_G:W>5'=* 6Py ؕ'p<_XG]{"9ik:?5?1}޷u'8Մ rcz}k"RJAn`D L(j'1=ޥ$ 4)fq E`=ʷbՈwW JJM=ɺG/>tTsU>Eg _yz؏(*YugGu$'%G*6 iP5Ìe=`a<Ɉ~حr;OG ɮ RU]J=ztRёBLa?L鬬" EӥO:`kɚAS򾖶>UENn@ld<}q *fkx0)xx\ؤ2YuY,P#!ߛ./jKJ+h_eqH{d^FæB)+[, @A-"lĈ^t-:M*hp:[V*MI9 U-ښyb]<3'a5x4o-l֟@iIWchv=x$(+ \ŶdCcEʔ٪6ZuA%_ԧX 8fX{tJ:0 HwͦDb\?O?cWEIωaE`}?jɗ|#1b!O;`omTJzjEkq ZY!Vg7]wTWA|$I,!s50 V d#H@c5}_$xd7H&1/T C"?)v *eXl],KSH(S<[7A8qzJ U)oo*R%ޮD1N_'YN_9n%Un)ЀO=@myTRa<=Y10NwbLݑy)?g7`G!3WrI% fD~d[ެμpOGp"ѷTH팶* Spv5yo䢫}=߷#{P`oטM27\5~8خ8$k$c$7vm~e}Ɵ 6: LJq}BOJ{:N߆Ib[:mF1 :`f?ôN_]Dp]S ݚQtTwDŽL);HJͦ DE+B_g^' G@V]RB̛iIvCh%m/ G ep<'Lzzx?k'vRiKS`}"bRP.l%ő1+8H{9B?e =қ_߿3pSOp/L*s)ߧTK/E- @-GV_p]M9Z|iYJ^mIMC!AMti^UGc #LNJ Md:i!ٍ * Z0rl>INs1 jy洹 6O¶^NGOKb ;:"XQ=DlETrүԼG%yhXʸF|Ti(Mḥ`2 m=A4},̢xM;뮣1wMbIܳW*\5oO̜byG%6?h\ s{%LL}\26Z )(8B,15hC wyr|A8H 1/7$]۶yIncYE  r̒lD4 -ccLC;͸)IrqI.va?Sg7T3_Kn50y\~i$Hƍ+-0-;1H _Au;T 4fJSʼV8MEVLNd#R24}[sn >fUo 4\ݓe&O,ɘmy%.,hSUt4RD%Fi HGq>n1lƾ*䙸H5DBҥ5xL[ 4W':L2`o*pg(( ţ-A#Az;@<@0袲k##nΚe.<'f7قf[djT |`_G>u{IXߎ3K/9T|ܪxSI;xeQ) /b$DkY1"oLF}^͝+ [ih[DvރZ,55xau%u+IW,qf#Or@Q' KX P3~8xɍ9*(}ʋ[ą҆\ lA#0[F rIJ4:SnJq"8pĝ/w:^C<uA5 [Bg&SON9R( ̛8 k|rfŞ܁tWT´޹`ut@Q\,v$NV;VD&og݄x}+ |Js[OtGYs>{Pj} J.׏AJ? ( ,齔eH ĭ!YeG1Z]#dA+ѨX|o mH?c" 'ug0x0:L;6aw[ MA /|lijC>:޶a{t>J^,Z3)oAZ$< $M'^ ]γܠ{ԝϾU f$KR֝~o5\##6;ׁ<Ŀy2eɤSw4_02 EQj79\JY[bGCcqP#(Ha].evBNzz"}NC&HK+{dړ,a0RC=y5ݚ%wLHC~!VuK@Hٟ^f }st3*ސtgxj l8 Mw8 TgA49u#Y&Y< I~=ljtd"$8-G"{C`X0{VŌJ$rDG;ܼ~hz})CۍGΧۚdDJ0Yp @:)#0I bxEeN7 ae5-uSΤn#]s^5qMD\kND^-隷^U Ps3T 6&! zzd!j/>Q>$>aK#jv5l˽WBޮPr-/#E. Zy. )u;E` 8?KhmYmnn:@{ge~3S Z1M:4TTfs.'Ĉ\0t@:{QDpymvT}F y=pƝذoiZ\j.66DQdor`,c)ߢ"u\  tbɄ0LJEZ~߻ 23e5`_EnԊ_mMPNnbSw׺L_x ވ△ Ega"ֽMP+y99/N,$Cn7[6 V|P3ѵ.HbґmI,j8[bqL>g2%N|BΫo+QAhRO|9(MI^dItjBqKTzp_;nڪbc#:h! [rߤ0f夀tR XXH97ۧxXgsHMN U"RPZ#5;@JPʗ)z(ij|.aO/7 jT^ bv9!3ex/n2^C8~)dj0FySdZ^*#? qА)d^]B [+ߏEc :vi 𻏦 !.a54!\T|^% wq*qPV{3@]~.j v,i nm)YQkXg!0ɹ SZ\3}H.;3!Oz|+])?h ZVyBLE7jX}g_qlGh>W$%ӊ8M_speXr&'-f^$CR?P R"E04`J%ce d{N ,W#,u=_j1DrӁm6}[ʃ~:Jb7_"0&È{K0֪Y&\z7@0ZbUfhżKU& n\ц =}eZos|#<\:b~@2 7ke˓]]EJIAugp%CitF(+4XUD%O~}YQ^31MX͡0?tp^ = u#?cW#S 8 j(,2t/]K+s"(-|g T%*^y4:d*тR?P"S72$=8V@Q'eRoa8BA⭧#5S G,߼5-7{gp/`N/SXkB?Fj3 Z Ȁ8 EHS4z3&ș`)%Hvm2u){H%DP\DQ!ZTZqQdWLUtJTg9b S9=$F#]b.e@՛"N5M򿉳<24cec+<@L?o|gn<&{@ѡVy:d4)2| `\fU_R48&4+ɝ5] 6c,rk鹯<2/vO+Xhgx׫@b5-SFgqZ/ߴnT6Me*sHsJYPSR|߶~S_^^>?\f0;O]G[.iHܾ⋜wK.dAǒ8_92riRZ-RLt7&y/8yЍLNوZ|.nͫEގJ7Gl텢#&2voMB~פ6z l `v e\ ưJB$~pv4+-.K'3:vHb%y͢͝7 e/s>ʥ L(6X¸ =ժf-*rLG/a^Dɸ ᳝Ɲ5 j5,!*:M:5Kg/6x{(LIUprM:J2≈ϛ#'lj*LFl/R)iY!Q2=/(3 m΋`ED=H"P€h"Xa%3YmwoLEх<2'\ y ŨU|n:BzB{ -`NYyD fmx77N<drgpyE0I+ꪫfXzI#)}N4i=_FW0`*eA|g_vMɚaw(uN/Um<)S,AKnAbXHjǞHy$n^]_A!)~GiӿxQ, iRc,%U״e 2NFS>^p)J`v[47JI &=e]}u4d0HJ_ЛQ@i\I(Or٤"m;CϽ9uzq`/,9v9ܝw"v48;jו̫U%yx՝}1K2Bn:.ߺQJ\e-`URT}?/Z8}݊4P}jn~-Ogo…:9tߓZ!=tZp&7w' c_.Ko? 7+ S" y$V d-g|&%P\3Jqg-zX7Fc6LZJxGY&ky= Hi˦XﵽAXDȲR뫚v /yĘfs.{ZԤ܉"liHxɳ~9bM{;kɮ͂mͪ݉%?i?*#/] ( 7읈iho; @%ph~KSNx3= yb]ÜO+ v0 84NtLLN˻uGQ@_QP7#gAJSmԮʣQ[t[j@$0(e{{a;90c6:tڐ_xp\Ĥ@H+?ThI̔UMW ՐSl`JН͓ +'Z#Ա"xx;(*rW@G/fޏ0t#/y##u~K8t_X*x혆wDpH0$m@V-wEaH"֋=D{"rmkb$6DIůcFTl.)&DZQe٘̆8sf5%j V1Yp֘ӊP-@Ďh%EJm(O-Yl nr24%ffWH!Z׌X)3x lKj2pBZeJA/^z"6O6^5Y3Jv^6`>/Q-UhJ%6v&:λ㫔CvsifS9芥$L+7@@n734kE@#({jb0zM+uI|U5Tξ,tIիh[mQx#kRQe qUl4WoAqN 9x*f^nZJ7% @*p ?,l1 m]=l^_u57pޯ_zc*jl\]]4RvlusV2 lM%a@=Y0ύV]eqDy!NQ4n^ģnR(,/wx7ʞϪF=0RԃdY׮ SG=[̍N`]v)ް{oxz-&ȶppMeV8@wZӼ"FuA.`zd7b&.QU\l Bnk벑c`Ey7ds߲-aMPf 7's98cic>xwƒ* Ǒ燥,rFJ=?Х-3im~Kx}Ba/78`f?>“+sp2ab RhnǤI Q+[%)̾A? 3paL>]yM"u8cᒰ"?'`}=ZA!ꝙUwihLv u0t f7}X& 8b߶^^+HNAV+19EƢ}IxET -,0IF @%BI:Q&Q^Kn^6`Yr,TXr<"KnZ8sCsS;-0ě4*;o"sKG.Y]m@6Osn"<V{\{R:3#~@{]NW  A'1п"AWOB,SfWMeMBa]XnP㬠uiVa70+\"(`XpŞV6q6 }=O}~E"V_aAxPTѴk;@jvKL$pBלMkn<yfNbpG]vdrGlkN1MfN[KQ}9@b8)E°ɜUIP4qܯLOO6`IwT |s,1-n]%.HWJJ?(҉^BuY e#\1w))㧬P| {8h`qD -^9m-d@u@<깦Gp [0RZX1r WHE>Պ˼$iKzjVۓyOa%#(:Vʃ4Ln><gȼugd R^T8`a]XLSųĽo<ˌp"quhkmĽu)KxUs u,^:6{LIgy$q8b7N4YX 3! 9r5M܃nxAz>0s^yv_ &FV.)l) Z^ +lVC)\ICuU Oc1VI*{٢i y9Z-\7~|<)A$v=PQlZ6!0QOv*Xc#;,L9iZjfxCDaѲŭk*{.bh$K"@=M% `! ֽwA`ғBH6,vϕ)e p{^<]B9P얍Y-zs@+ Ŭv8=rͻ_n <.h7:X@4ǾMiCG(3HZٰk"K]"1x2K g-Sˊ.-y}߄Q^, q Bwm[G^x.ixTnAGkQ{"bH>Ў xq"Y~f}|yPB/ k FtŻì* 'UOd"nzKlZPm@ e(JIMOJt@=m~$_֮7-WvBiVOT- ]7Dg-h$UMRh9E LϫiQ#qrOx ,g>\5Dy^;B>>Y:hdk+}zBbewZNvD&o1;,C_D:-$1{|ץU$ϣ!=tՆɋk]g?w!6( ئi5V= y0Ȟi{^z&9H n28w-⊜JM'F$} ڛ*;]p]ܢUVds߶HZ)\*O\?2}n:fn !8మ-HtӬ&Q_,!-jRփ}<%P KPU3xVP44h쭻Egi, 36<5PF,')ߔX~Ws O26+FݤZ}12WY̽|nېG[Y bL}N7oxr~TsrHcnflIo(JD9Hl84pKsxM C7(Ua?=ȇU֓tHv8]Hٶ}5$iah 8)z{:'.WfC- # +C|TUf?w )b wcpw5"쭽:Vĺ! "IUQE$<\՟٤/:VN:k~}N٤)*Ph%-(c;PN" qr%!2eKJ={wd@Gw NAb=h 5ݜ!~K1$W]aQ+RQ`=R?%.`#}cH^StJGj}}B&Mo֚o۠e {<#q0yM06Wyw"/gw^hZ)<ޙBRV2K?c (T?,iL Ty?#WbN ;+ `eM IPW,duOYn%fpp_i9Lu{@Y5Gj+dc(hmߙe1pE؞~GBE7p2]xzJiMs_8+3C>l"bt7Kێ=e_ v8lN1/} )10Bø|Ý$Z։sN38qd{H"5Hz[h1bs$^nC_RM 4UCt6 W2ݣyY+2v\*+ C&i1Ƀe!)7QC GNdp.RBB/ Ppz\6BU\aNYBd^aIE zmpoJ}v˝TGش5ԂoK{l;X~"1@^%q8#ہZu7W`79VLheתuӇд%x/ ZU7 $3&w*!jW_֏d'~$YNŹ 9ԗDB/'魦s5 35xD07XWB }DڣKo }`xCP<+Q7BcX]0l6K_Ky -Z>vƓOaUD_ox~#@gl5BV^ ykV:-RWX}s/) j"HLdHTB3!X jg4iF*"Y"2ppK)KD}`#/6x.eΖ'ۖbEx&*®) (9^"XT4YNB̋KJ)CsDUx|Z62m}9LCb>n|GLoރ ^ԡfAcⷂcE:+ϢQ|gp`[iDj6N|/{Ox^Wyɿv'\Qj.MGtXy84bZǪ2 }CιI!@!Zt僔ԚM,}_iڽV%Mr&XhweN+/\w.]l3Ŗűr? :/9^<2!f5ij݁o[)۷ge@">i5"\F4D(f^' xE#zOzȄ$ޙ=NW /4>i;Rwkj.& *KR/U$|QADi+1G!A*AJ`~3r+^r.1񲔝痦V 'Ok$헇Oxlz:>,8 KIr,JLшJ03 t3:޾{[V;rW3?;N83%E{Hw]Cd Ҋy!GA0 \ R_ H+&5yglq@֚L Z4NVOcc9Q}.oFz9Wrxmt;1?3yv0U1(`'"y \@`R\ɅnxJy/F8xT~H-oN8[\gxw;MX ͂<ʚxh?8= ,=(+ q7zZv'1Σ^J0Lw4c@jߞVb l9al={q%L{)Nab>' y4!ā^XdW1՟Vc']2AR%6^}x OPϾgap{' !̬pG{߃' V.YGegy /k@T;t[Or&0W3H߂^2mH\gu/@>8T1 %⅖ۖN38ִCiRu {~y }3,mXWa. چX w_`SOZh?T G?|>:D͹Bqfo T]^2Er "NFHrI]IUorEX{ۅJD0R}YdQሜnI@T0c̒Qfp=tr%'28-:MkAN \sMւN];-E-`Xֻ4z}]fi&vsho saRYM'O"#4yYlD|^\ |x rjuxw*F3?XC:?hz1c@zj%[—Tɟl|Ы|Γ2? Sao=x8r+!N&sI^ y=΢v`O uF v >YwcO pMd׫Y-t'[VIuVISrx4 01`4YS:`4Jдccڻx&jS+;1@[ k?L;Y5o9V*T 8u*v,f^tx-\g9u|Ĺ0hsd`j [l ,\;a<|BKBl"ħU7d~޶8fb$ 0<+Er.նKL:|uM= G}R<찫\KԲlU291X& (jiO] ͅ~u˸?&q4RqtrQyOx >qS`4TJJ:}Z6Bqrg){yd$I\(T/|A#~]̛Ox#Ӄ9"U>H4ge Bvb ~P;alpߦ^/a&rQb7Gld<{ ZW=3R=ph”9 *e2#D|N~c]7)6&i?Nę1Ou+z@$Q_*'uaG9!ɪ]1 ; SV?f)Ԝdf9zӝCP뎨>}㯃8\mN ?^[<%ڷtEV2qi@u#@)*e˟LHVM^"!#$[p [X3@{ǿds@NY=fQ65W'$jS~^4$Q(5\?CRݳ,<-RjYbdwUow!.!)IKxN=bLe B@^"?޻u#MMm7p|yU$?@ P[ %yQDCakzl(Jٍv; ˆ|\#eNѹ$_ۑR mBu_ޔnd#e$+ŃXW:{1Ô1I#eTG>T VsTY֒y#P8ϴM~2 X6F٤UD u8S7> of|][P^pMifWf̼b*0,zc rޙqv8QΗ;7fHJҜՔ쮃#2y+vjNkӡq&n+ v\Zus>(3J{sS7E D)H|~4 6=f&b/^6sh#yR"}-38 +\h . X~^'[u.Iwy60&jG|kk1w4"WE("iB”7KFMnSTo,'k'_8=_زD E{t/-I&Xx56&۩$uPK!G)- Q$Ó|=}+wz0\F9vGR )tj T5?uݯdʩ _Ƣ( ܁;-a2PM*w^8n@'$T( eja,u(lDlh0j20r!p^<]9EjIR]ldNH2 6 pd:Թq300nLpWfPz)zk;&0Sf|3tk_馞\4NZmE\ݧx7eU6u~v>_#/|-_|,ɊdܛUwSoEUp,FQ.5COvSUvETL$~kyayc'uO87xʝrmӃrR'Q@JTrT:` yO'e7Y,Mki}N.+Tu*Z/p6WC1Xh'IWn Bݎ8t"X 07eK9b$~HUS0 yw"AРR8DN 3\#qRCXY *a]l-E)W}C}TCg۳}h/S5mRJxYMDhNFPq# >d3+)jmEV*5 پf p/ĵbeRBy~3U8 4gSe(?yiY<g Ғ 1э\d3{+oOæf4 `ee/UAC᛻,5v@-F~2*h0[SU-@̷mu_/N*U5až`^Fra WKYNs*.l|ͱ. Al Ԕ@6@/l](.*Z[woQ7#[ %v`MBuj|]J{Ni|DFNCh1b6`&OO Rن޹ÃpjVz1VZ]88q@_ʁ)ﷸϤdKn8CdA)>R:эDlEj#L5e.xߛx贋,` VLv5" r6`Ōb<E9^+ !NpdlSJ-<z&FQxJ3S;ֽ0ȽMXF]SZs]b2/1"e'R`7i@ݯ|0Z|T9)3|QܤEGbhdQ@[JrC6.l'ǢxP!^yĀWB*i 3mfyI{d~d FF/n%<%/:<#Mhv`o,&yDž4ѶE1YWBcO:`\אQݯWۢAADh`g<r է~P f(gNIU ֽ(q3[j2)` ߎxuCֈrj[Wx0/8uyC/DIT乁[C#e#xL{l#e.j^g`~.7{.{p?z-3R Sh+-֚ N'ˊ)C9jM#M?3D$rBILpk_#v62}%q_M_8FsPO71|}PEbwEó(=4-MWE+^햣W:cԨ襊;gtrUWҰn?0'ޑFg ⺘^+Z_,8qfiTLy+ʲ9 d l[h0R זa.J#x{,ZddN<+i;D+4 :e*5쌀G|E_nE j8V̄ AbA/=Ykb/w#I2RG1uA(ȷ#[5YL4Ѥ}4E r3LRǘ"p܏2?÷Id,~>K%E_HDޖQJQᲾ$6S49L2/Jl4[5{īH-Y6Eƿ -F8DV;A \ô*Ae)w+B̒')ͥb\I:3s+`?F~똫 x~Bh7'Q*K|zS 5>2k5Zj}LAKI.n]8eQF56i 0l`~5w,n7iUa,\;õ>|XP-t,)P$-m=#1QCk6{Ր+U| :Hau4هC^~[ſu*0-ƪK@.J*Hsz ׎9Q[\<ߠfj0FTVGa:e:E<5r<&7lizWeQ"!s|\exK3iQVHQLq~"_2ډ'uaufK6@[1`d#>#!~me@rvg(/S j**W7ce@C\~ -8;$u,[ `+< g/͛RLyt0/9'4!*{U2TaUL9c>>Go?stfׯ.<2@#t,'*uѥ*6UզoDf Ȩ RH+NXD>^WxDgdpWdNxlux37]/Pm52}Nܿ.;n쏷>egu>notSHVHb2uo8S9e'ǡJMH0xhb;\0l1;m&ۙ;y WK"&8AA`w~O_RhJ 7='=_psx.;3^cO`L7Epo֭q$Ԟ1]uV{(:yo("xTAʻټ5r ϔtʺy&PAt$ƩTe1h^u4!KWKL+A"8 OCҞX Cz ay~U?QH7$BgAe0U\>`Ӡ#0 e=aۜR!v]'._mIUI?5b/b/Z0N?:[Z}q[(JZcˣu'/x >k21~W&شQS uUKsQt}{v;V-ADẵ#rR;X7Ym,[x#^C(F}Ba6w)m?G38r .q$%7wqYE/cXx"ʗA.#c{Ɛ[oCV19Ɏ;49gO;2 @| _+N)-#?!aͣMJ[**xGK{"3xV#pi].| qPX۶?PT6ysW ;k-gK%EGYZ?Z#8v,L^UL6`,((h# VXn[P?'I& hIfWRisMI%W|  O- Qc(9zn>ӧ'яB;J_=װ;g$~ ֲ!>b L)Ø6\2tZ#"sf:˓=pP9 <$qp$quc%_2 w^li i[rrmBrZe3 ϋDvSy3"ERoQ4<#8A4)8 tvtp05he ~YfLfOX+h,nuT ~?[ Fq7A݄'OO7uk8GdlUSZP͜1:b$s]~`hh垙x/:sq;$✢$/!)QXSKe'9Vo6lÁ^D|R*t0CU#6jHflgauCw1!fZQ̭YM+Ac }Eob)? f[duW RH:sJ@At PƠ4 Q햰+c. wvpR=)((fL |) q%az@:mG̕-+rlHZofD䭫;ٝTuP"<6~e#Qϰg t@󠰉 ]q +zTۍW4\$PpvDˇEy'RVfP"B t.c??,%ϐ<?[$f;95tBo/P=∄_B2 :@2 t+u BsUs-Jli?`jyuK,GKlQ&ނ8l:~BmUSaڳ[54JmO~Si\;zd2c. (cNv|p0U2pxTg[X0,XkĎ6a}=mBC6uWjܚHGqHly1)zoUGMuxN5ZݙYdQ<t|O3g]IY;LPҡx1f\G^H4L1P{k['zgܑC_ItiN]kV4reߙko] ~rsJ>, ϖ6F!(Ye,P"eKk-ٿdpgfeFA{> &o7wԄ;D46M+fsI85c)vm?(Ofˋ*dfyGS6aX0dFW2ț: ZtDZ,lڷB>\7>c'cldiQ#`q͵֢ P c mǖ{]zQC$5ϳ$KH9(0Z.q}Iy|6pᖧQ\(jKl~lʹJ0<T~lIE~U:їYFc)L8u%xvzTCVHu9 DOǶ$Ɣ^u;J@ }LL秛& `tpgW$I5GI_.󘳸x2}馢S=Wmo}xZ!rlJBܙec`HntKi1:hV0L׿r ɂ.\z AK6Cdz_V wlѲo ̡ DŽ@[IEHOBH+ƸH3mNkʆ ϛh6y5ܢgKx7H⪉X@ Ӕ8:?')'Qmrz) N(Pyzs\S.kQP7j%J>ϋ_4H7$Awx/&Н-3XHb# O}0Y=ߦ6PݑezC]̧HbޜMO`E8Ft~MM/2VQSN4e3KUڠJ焤(#Uc ,%00d!;/)Cz87|ornBd"Vo)!9hOC7Grfǜ/~FK7yyƂ ۯ/%WNRyۖ|!.Q=IhҍU#n<$ȗTBٶj Ik^}A>o潒e@nDVXϘqp ږG#{X?&T42{7#iH2fK0B1GХ5Xc)0Gh_7On0skn@@HciA(~ A~dY0%{XQ "Mh.v _ ]q8ض^6 Fr5z-P8+y^eGB2G$R-`az^e Grtpy{d4nhARQ8-Pxڨrh 6Ğϗٔe7!q}tTu_Kf/ß Ĺ\I'=2fC3 HiyU^-4w#˅Mp-y+$A(/dc*mOBƪog"alvymE&S- 4hTzDa 6aA0|`Ȓ5 A+;0(Um{fS{Sz0s})H9zVwP9dn_-;5))ڥf&h]:S;,9gHFSuY˹πB^;*ޜ5jEAn/M=݊drkqї!bMA,0B~[ݤ[޸!}a3#yraL+y.|הBg;V8%O0p̯ iĪ=Qw./&s!x~D˅Z5tE<  &X2c_(ok~*gc4Pmoz:C Kg; |ڠx-zG Byt wٵ/*ztO6@B *n >Ԗix k ņ܄͗dCd@]y)c; yc fHCe3L+$:`6H"%p,4**`CL9ӈ4df$sL0'l۝c b0B*F*_s}? | .:p;KS\]?hzsSEGwV{ <:Z\Sg%-d2yL#R$Xɒ?J٬j]'a<"BՅ ())k4T&:3Qé'g6x6G㕡O&ZǪM{vR obٚu%:ov28HϿI7vxzxtQV'4UfMWv(eYm@.:F-DVJ@j|Ŭ3߉ZՉY&yhGPw3_/7 M tg R.o79훿~B#qRE[׹xRԤk^# ؇n@&]]φ_9?krl `5`9ZJZ7Ѳ}ڋ)ÇRhO<*j;/m⁆)#f~S%>mk!xFi,igv鯠yg{itZӧ,a $Dg\0wXW)֙׬ SAgPWEjrPI77:W+E3ZepH{<af_,/4@ JoΤ d_Ee պdh5̊zS+5WٖM"=_{T6:(O)[gG_V[ApOC8J*+"Wb_Lt"!Yp3q zw+O6+m*C.$-tz.9o@z^e"2X.\wx5^xHt6#p95M.̿LYYmG#5lk6QǬ[jqG/i/wѿ gjo4d8iuj{ȘmCӀU>ep'Eu2CK4|8v/MK}lG!경]{h3:A xʵBK " b s؛>.h3JYCǐ]BVq΀?T5HZRv,FO7.޶;Tdx%!wkjTh%k %E[g0/ъL/dk31C|D yZ?тZWЂ1RDoq0`q٢3XzsQ^*gjJ Lq Qk|[odz;9r =%[,AQO0k^.ϭQnn;VQY`Coeg*C>w V:kL]q.9#.%2jDߧ:uK0H*_@@p4)}ː냍ʁ"MScHuӬ(HzKkV.s H\}f2< h.V/!'Zՠ|f:W꜃&qmV߿]7]2v5_^A> :ln:q*ۡ?Akd t9݋b4OOR>9I0\Cm)վ /\ƻ0Yt" 8.ռ%qmйz|&4Ol!N%b*JȤi@2j5}6!81Lk7H\+`Fկy\s&Gf^S*0A%C.>)W\m>w=}X|WlK:ZإBcl跟{} S֢($Őo?d _̧PjA w|Ėz-cZqZ_ӪLp_ݞa&9"VHx/B'qB 4dt"+=@8 nr#b 2Lb&<#/ovÂ!lT\C; ؐݘKE=ES#?8`\}YB:oDlKޘQQ捝ǫ6^ū9Vq mM&8U?pT"EM ~q Z~`wEέS*dgz|A )̵b!'?8SɁ<nF"Mh]% #db&7~wH [c Rb= !YPe0z !/Ơ;BM2ߠHcc]x55Z^=_xLY-*ڲôtI$n&D)G‹;Ϸw j&fbd||fB^twlـeZWMbϺJ({ 22YӼt"g 51T0m)AO ‹S@? "wu }Tek?@RW·(^ I3+> C!)+qJf': c{s@o&ٷn Ji@7UQ *ˬZ+'*>-}-?Va v )p·>S^g@J'%AYi+ DdC0J^ R&Y; XiN"mq281^2pԐ9 T]O@%(<| #| w௉>pɮՎ@2f?48SPVfTq):f(N[IȜP-,S0vUYQ 1^Epj*Ԟ̆ Y49>"7ص+c1&lcy6qjIZU bQB SL>DfTxJ›ǡ6c\\\W_Df4%j{7|twPM=͓a(x-iE-m)s5ơ nX四SG_R𔶾tzo̓S$нE 4c8 wl vK`FAW8#;9u5-PsrV>gTflzݼ2QIv> 9ZމǕ o <:*I蚌#! N_)L"bY%P|~֝C2Adh)EYmT16e= (v:ٮ\JF=ի_Ekem%@<x[h u qYՁ2#(d|{:6额{zGWd^&\Pb!ca#6R|2Et̷q" )qWfXVIP>%c:Gi n `_[{)[YN8NwabrkH8Kqd(h8,H!ʊT<5DBU5lv_rg7\b=ƥ髹!xnQװ;vq($CIU[leoD:7sNUZ->;|VDر{Xv]BHw Tjt2w>m j ??i ^\S; sv B9!!xwJ+|Dʎȼ>7Dd0]=5XX-^d +Zq〩T}!CnJ=u|E M TŚ[]HB:%~Oec0%`Mc-v Kf(z(=I 8 SR@`ZmeQ>V+֖(_c2mНJsh0&+!ڔM@Hkhh"iyhD=\Ղ ]bGfwtP%a :ZvqTَi{3*p 1qOʽ km舘j긎wޤ=ԪaC$o9-JC~^g [ KUNBq p^ukN/?EXb{ўwUdD]aJehF)_݄%tP4 &|=:ĵI"k&@)_tQ_:GWYO/t@R*r7p9Gkm==5]#`<õKD8^0.?sKIV_ږ(BWP,zhh(Kzj3FB KQlkgCFY)bGL^%U[8L>P_m9ٕR(ˡ̈d$1pނ뀤T5;` \/<CX|jFEݐKe^|M58|R<|_i_-*gdÎA0V>`Gx . tM)#Y.Q^&7һ';=&=x@ b}:ד0BAT#*`cger?sVӚEĥ=e@!=jҘߌM.׾/dMF ^~799n4f"tg} ]iW\}GYҏָVqstE,V\e,.Q^^!WɶFGu"A'xo-et*YR^kmZU*P%W)-$LwwNF6ǝ[Tb šQ*;u@UH|Z5&k]+ހNiCجwN7cc}eCp=$Gz%{Y.uB?Rgm:7C|%)߲]H5Zp Hs!RG]  1p*d+͡wi ׮Fcm9$0mzv(3ن;c kl|Y~ lĭ'C yK09s<4ژ@ ,ŷ]J{(uOT- w(f:N&< 5c-84 j׈&LP\2lU2F]|sH]{u- 9g埴5w\ V[Nŷ '}JҖU5:,/j ]Fô_qgHcC0R}̉!Èm3<2c,pxw=Ug-#7*PTFB,#%+K0#{,/ hm,UOJMD2.i?NGX~3VѧTy}dԉd13/Xt1D`'Q{{umz*ho+KbI^yfuVDޭPYVߔ(ZҼ2C0 ҃b1a7`,G_¾' NJۜOx ~?a Pa cf<~Ur6^$O#$7>kY}W+W(Xѭb_e{E=gXӣҼXJ52ܤҜ# 4|QnJmkxE;A ɸP|2h:)~!1CӊHsQ3_uxI.oD%Z[:-g#O]" sm40F⣟<{A&>@O(ة8ڲQ'/W$`WCw:>9b~^.l |{=xLƳF*QlULS0ـZ+/9?#t`lWɑcB@%ff& '51tӬU>rTA tvln83RVXE>|+]y`@O7sl6}UU#UŮkLڐ}yE!%hJ3N} (^( GKp]:4툜OFOU2V%yĎ2 Mc/ ) <yEÈ:moqG|09iIԏ u=VrƬ ICKpT[y6Vr܆ ;[`l%KEt>3S]tez52=ټ%9~KTQ^)āA0JU` Q oY##\mYXWsHGMM2ȸ7cϩA텍[ہFzqnmEGXXw=V^q+Tvf,c)n=WuudDž kBN~D C MVoە j΋+{2$bI / *ҶjmZlUsD M5jH'ō3ǟ2n-gr85 b`{9_Z&? LJ,4jZK)G4 Krv ]F=wRΜE^Rֳp~d<OYBբ'y^6;X(;3ĕQZAU"EP$^̺0ȘCt4Jإp7v2Uu f0Wf8}Pr}v0HYi(NS>H6) n[khzs ~oњ ڨN!+{ *k Lf._Q\N쇾cIE XHMҵ>5dַ& 7s]p`wf1SGH]kp p}غס m@_?>za[am^"Ҝ79fUǴjū3;5-2h[/+UdcI#[V[RYOv3b3#86ex7 MZ@гp}]5A}%/!|L҆wԲpOaEo,Gs8x=|p(#5@~Ok8CA&SBWQnX `Q ՉH^;G(}\5/2|G{1@F $f;X Tّ5,F_,:dܕCr1)4<ޡ 4oR5~rsKW3(DM\O.~9Uv*EӤR)H'@!Z+Mɩ3 >:sVP ڛh# )Q(AG*bGT|Vo\VG”/soUFʩί!@b ꖐW~Cf\OEo bmK9*%<ÃM"(&yc>B[?b}\e>lgc`In:0O #O[AZx`YUKڑN?jjM%~~R}!)BqYt*S0\rhn .H{[UxOf/#y>n~Hz#$3¹0w"%T"{ElSaz~Īb; \2VVObv D hOeW"3+_̚_v ˀ Q4\FUwv9sv4X ~?~S4=8nc&,]^(pL@9kuQE2:jdˋ^0$ &lwLFqf+ BqKR8΢ "+J)E5~5=nd%dhsǩLC8%e8>0g6t倄joLbeS4Ie.+D9R)ݸ"DF=tǾ P=#թyDo?>g_:Gu"o/OXn=O+0+m{YNL 8ȗU{/*cCwďřj O2]Gkp߶[{Jml嫅WPnGngٓ3(ĸ Vߤ"Ž~@2c`U=eh;Yrca:n²}mXYЯ*4 ];_͡Ml762Ħ1D]*\~rf=B?r2,(م@!0/ Q6p< ʤhPA\ZJ;[FP9䳟V%҅WlKR (um+<&ǣ(%Px !7$>.b2[߭{UUP!etőj$=MpvJvjH͵lɟ4@,(5.$Zfb>LO>2<@oJYHF1^09Tgmj&)എ R38 ٤ڵ=Hd nOBʃH`]>K96pH?O*\O>J[AAchֺ ENQ؅"У'42~gJ}x`[b%+sHk5ADINGnidaY_u@zl?d{88A9J8ǗPCq;g{"'A'ҁ!6[2XĊmcF]( Qmx.#xt Z(t fn΀F$87r+GU)|sГzjH Y!1  ϬpSΖ<5?-ډ C[scJIrNz1A7All7iTkL@TY,W~uZZ>U9Hɒ<_<sJI `汷]a{ܝՁ"f߿hLfg9q'a7iX[#U_9P<*mjXGQ.\wDP,\FTjO;4Lu6ljH/ ~alQBeZn'f', 6(K?kRJ[IA/kߟp+Q@tB2r-ZYPp"ComÅI,0^|.θ ʮُXٿ)5,Sm-Ȯ}*\ۺN[R:)}QQP+>d_Uֻg=Ad|1nV}$P.{񿸇~'E-0HUd=t38K7=D6 +mn#NqP& e^kA<б4d3fA~+d ^9W? vO 1.me{^(rvaL4 ˿.Ťޙa-I>ilt"3몰pԁ+C5؛'gUvD8~bcS@?T Jjc{X}IeS_WA?#&v'xr͘Õ, kKcu 'kxy fyEf`Rk6E1yPP27;lQc'd݋~u4HV8/KH+U3tN\3z%rV?Y'R;kͽ%j.4$C&;7Fmr=Nه+89ceX֚SW;d'Z%U;KI)#Ox;P0`Ueɧ7c+R{#WFz7eՀRv鿔}LTAO\`I2ݲBRBRL`1df|UIt)ut@|Kgv߮@Ӓ~kp37G fT !Gk0Yjwpn\O>"GdS@GJV9O$#4F>\HIUy Cͥ~`|$Gk⋳~^2n>ťrCzO5ϵϚh/0Fr xO&5Ndgwl;1,u:F!V )pH&/c"҂d\y2ڹ88D{MKRp@g4\$|&; t)\ީ2]3 Sؙ=''zm_))C& k <_{R\Uq e|'Sb /`2 aִzvxuI 6N0&βIApG^x,q__Bo0~2Mr34g?(%wmo۔h)=e JˆԷ8@vO;aȼ9t?i2뾉֐Br7kW{ .<3"=0ƽ!ˆj=T$HBqT{/݉Nd]Y%"MX,z % 3J A7=7A5H3z:R]TH`{ S@󝸿}eo&XٿUw8rEyI_5Fma9AbY;x8m|ˠ5blLW%8(e'7eȶW}^7hv#>a͡R i׵R,zߏa#HPJvkLT&}K8̌@+719V<Çq iƣ(X^A\jXhȕ1$`@LEn=pxg BK]5|Ȳ|G|]lnc^׻6,~V3' |vl]/q%mxB';"xͫIA凖)D}|ʖQ kAbn-biLa`7k ͑ •8bcq'~ϷDS6Z'ۿNp#Eٓ1+#p~zFGL|m U]:46uv3Y Z:uLlhV.~K;vųe>~O $ >oWmf'0;Ʊi?M'ϧh<;{-1E$/٘h8Ј@Y;8C " U`˯ʏE;s<5:yY7߫F9&ů7P,Wm)(Ł]#/GC2HqՊp@Gv!BGvY2_[ΓӹFkE,vF%yx/i|! 5Wq'b!l<~DrW-f6;E[WN'Jӌ)z rs[$Z- VsQ #I1HLji<Y5t-3]i復 gz=wӭUTr>0$Sx&,.r{;_[ q>C:0:ސnw}ZK'(jCD^Y@jf"4pQjym:1l,ږ36eLj$=H@Ml%{7%.op& a|&g9i ~՛5QRY|!ULu"-;^׻FNNO~$0_H;vD ҡ 6^")t7'k32:B G? :00  BCBزƩHwYONܱ#ɘI#M#1)q-:^^[|0;a@fLH[YQq)C7:xtl !6TijOrCWۇ̱Cg_Z/>0" YJS7sFVlc'<;(Jg *7ubEL܋v]4_>q/840uRbB} c515`b,fJm@׏U+#O pZTXQ!k.%O\2hO$堕Iܝ*f9< ݧۗ$fኪQl<=(yu$R琉[Gp#s#nI4n@sāy0#%o߃\9cHYYL}uL50q[+,O %T~+y{Q@@# On.3;{6уJFvڮWJ ƺy_y53sILԔC HڋtAPߞDf Hn;%Zr"B²Aėr Մ&W!@!Z7ʌ|Е`.l$w3Ý]4t@d}v$OWЦv#?'Q{w)WO$2mHn@2hU>m: o]G.\H7U%ۑ6X&qٔRx`_e QR8> ^It#uqn7)>e:%/bj8!P| ,W Upa[t%)-=D_葱cS~UKwνt/"f8+`:5HHi+>j4R裹d6ݏʛ疡]Ψ o-Cw^ Ndydݸ3sҫMh+pޭsCҜpu{"O6S曗.3e&1'ojR/%jV Tȇy5LaBMQ3%JDž\+sД O'k IQ|R05u Ѯ{YNZ,`I2Zkd)]0:wyŬȿa ׯk 8`Mwdb4f7#~{:? ݝ<HnAu0]X0B+,},;:P&ږ@搲 TKBˬԘ2nůN "3C4qx$<ʿYXNQ%eУW<'Ҕ Is Y\WM5|01>OɣT[E*3ܡ4R/=6n.iHQ^o{(a/%EmBT5 ed _g L)Bo&lq]}O7`czLzD)匜\3t4騿S|mc\ri:Hpn-I/~+^#.=84Vslm1b̹ORZ|Ε4!gQEv@KΧM`礥W[ !ͅ5 RhéjrDȁV&K &Dμ@*",Qbar+Yhb[g5ɹ'O5Qx|XLvWV*/=]"$B| l)玏GHDu3mstvL FEΕ1{È$_ Xq.@9>8e/8RwZ&s%f>>$)T0 1-ĞeT8,ryю$oC Bj*-wť+Z[8C WN x'zHiRnw`@XE#?] ŗ4$ל`xJw(D".Q,J3Tg?p7&\`DB'-blxG$pXH~OHIz  *ʷ7Z>qk⟁f%¬u%M[}0Vle6>WF wW< Em1eg~7&s;BV(nVRD<UN"T*@^łRF:d<% ֎2B^ 5]!壩߫_{w4Cb-Qsڹh#\KQg|vw"$.I_O5%__{z* {P]MdT2ҭGK9y$ ,ܮFk/DoJrzH Q!@K_}7ΘCv"[>%O q"9Rm[=ɇ. Ƴ3\rV8?EpT7z#[ܝ\}$3:,?[aq74NkvǓ$1]Gl7CjEV,p)8 Z#fAd?yǭwj6^Mb2 d-]EXX{gCd3G炘hג.{ŠlYUf""MOj[ҐIFip|Ĕy ¶y ,6Jʕ{nn-F/23 DD[Zvj菤v\:[rg ࣌.ꪟ"E۲ lT%bJr.n-J K%7F!Y2eɃ4-Wcy=RK! LHcd g8'T,S ! `Lb9 !WOKJU[q+yـ_j‘;Y$",=TcE68G*XIlƢ?г*Tubݜ&Fo8 60PsT *\XC> w]t_[+;rYgpy? FCRj շتtE&[Jœ5},hx>ۨw͖EM(Bܜ5dmVٚK9epBrABԿR>ȼt)z՝]6,:p>>WDh:U*w'6|5`>af~#VW$*H^orc&vv[`Kbb0-HI7{[A6U TNRM #)m,BV3lDK4hĦ Ǫs;S!'wm_9>y J?`E;k6c~fY~ =m_CKWT Z~]傪tMr or(_`0ՉG&@v8}z#Zh[%ڜ/uj:ȯl(>d&WʹeGJ<{NH lT22Ug0rf pۜOm*8VZi*k< ^3@Dqf緒 }獱lZTJvtM8S^qlR~*Whxŷ?R" X@GlqO,wǚHx~&Nj2rMmb;PΫO8UOfNu=5P)(_Z4`঎%h_=K@se!9Y݁S1t3ṥ1huNZz0]RmAȞ,ro.r^!Cj '[N_]W: (-PίEz'$"!6er3&_kbR {=g} 0i5D˃cVb{>>_D" %!ss. d)Zp_vؽ:$.N,}nɜ\,w #秴]3YWtDxYS#yLjޓf}2Y y%J6~!.DeQѲŚk`<.݁a;h5X^#峄EoG\Yel hr4ʧD1k,ܓоdĩ!jVo,C{+.De+s:u/l{`!L|hr/EKM%A>A(VjX(TQ T4) @)9Zc bi 0[k':8wSKsG=c,FJ߈k8V/cfD4_i]^^IV=-쓉0nea*&Ȉ,2*Ҝ<؄KLXd.ouih -l@YқДʰ[H~ȋ`eBH=piZve=ÖF.P7'x8JOcNjsk8mWUp4IO}s]1Ld5@N:lnU_M BScSPl<t0L2@ u=jl XO wȮj*hy6˗y(f!:}k| 2Er4?ÛMn|85֞ 'Ԅyk.8e`ׄo!po?D=k4 |SD T1ᖍ9]ڏrېg]UEE~ᶮEܝs) crP]f;7Y%W'j4CZApڂlԂLn tTđkiOjlYQX :D(l`aXv)pB>qwfUۻd7PyE *4?/s<KS޲H{c O.` N Γt(Rgju/V.f=K< .D6wpQErMq 8;tbxIGoH<`՟FMֶȅ7< ,P:A-nD ŧ @ 7՞nT841lҠ<@Zӵqv+XCUR0M`)!kn=KޏP)me6]1p\d;5Th%F% W)~Ku4B-ᵜ縋k/8ShVQf!K:؅] n~;y/qh=)$°Gv9 wu `C >Jz]{KJϡ̵ T3w'`6A$#i}jcfR)B+ozm*+K"5fȹN[ypV#ibR)ـ P, ؞Y@Zb&]e[Ȁ=dſ0ӁXˈΠ̦^?0j HN2ڻ˨fa|p0&ϝxG9@5 JudQ!K-n<ǣmm=Z3^lvtjZ;l"3d_'|4h#!ļ4U$4:I0?}G)cBC9v5 `mb|y^EʚZyxէۣ}m2&ɋX9\i ; 쮄ţ>UXSHn>69 ձۈQukw&eWLL 8[A3R@ toZq.NŜm_/mZY>'NXh!RsR{o%-X+s(| Ǣk0@5NM5^ZBܷqDW!F Q-y&!fF/jH*;-lޖdMΚ)ZGŌIL/^=rl<[lz0q2"|[P U:zFU:vpq7թ1\H]q7s`hק (mDnnZwy=KZU 'm9o% !r u8rї5A](0Kr-ٔ+Âբ } 5>o3s :X-cϚ hytjcFo{Īg4f=nPj2YQ"]tq?q֢QOHCv}@m%zaE >ݲK(`Lpjvo )y`=Ʊ ˆD["}MpɾC1PTe53%~V!GH%#<>7@ڒ{8]$1 "P[]xC)dͫf6ɈW p+*'xY@& VU+OuIJim$mI>Px-mLxX\/2m'X[\"R 3Yz2 b3 ݻ4nXT%K{BO@"M@`?+ LD+yZuڪ2*!K oY?P*+p>mc"~B\l5ji_% a@ω@09x L.E]mY$??%a)Mթn[>'J29)+[B&S)[ZX9>]LRtSN)a$RRV9C+`C'Qo2$TyaFUIxJcZ`u,nb$DhA<}_MSYR!Bb?b tb2^5d4ެeey*&axc_GK!}FoLZfOp mO3W;p2XǜR?05garҽyzLJιv W+mFGk8Bh E- W#H]CXk46P)mUWK{/OebVEK,0_Q J%hN(a^o gH7*-I:gj5zww򤉩tu)؇x AzpړIBzNcWH'B5"/⛊&! DݨXhK8֝TeNTG]z$ AgVoKH1 %arϰ0i+3Qn.5৽%*z\Q=(\&= NK߰<|)ކl`LW@Uc$f]EQMQo`.zy"Lƛ'D6G0"}NͫٽURV#ɂx]Ԋ0+vn`pzUS'w(3ĵqh10ѐ8L 'a˙I-} wq4q/j_ֳpvihUl\ 9 1CgP0G n*slEJ!$.ߝw( w﹦05&leeȓFK*Hf=˜7$gM[ПNK,={\dJ`(Yqzt>t<*zbQzp.I}WÛU ۇD6[ pzzl#RToTp 9,Rkh"QPw, N~}ݯd-)StI}j”A:ciL" B3mE_;hNnToZHK{5 0m^w$1`^heڥMc{"TȱEѳW\ Z'V>Llpy\r6Y=v=‡ͦ[~DVK1D_2&YV߈\W1JI&`8!Jn06(RW&'% mVv眘aԮi8SP)+W*ܣ3ܔޒզYN~-Y?Ata?Ebb Zx%fZjMA\k"xU=Ip̘==Rۭi嬌, &1VF;Nbx/C -z"r`]j1Mb [1G"Yˌ%v/tQw\ Iwŧ}]S! d+pȵ9"[)-;D1!euHs|ch,̜㑯8G-ƲOAn*V-&3bOjog)[<6:P=ʍa(3LK6F(i1 w%)Bt+̤t{$p/S~O$}˞[)İL#`ڸRà0Y"O*`P6($0bP (xS}yWsP>#*QV98^^\\̤{8KDn* 69~Y<'hi8UAV@؉AHI/$%)k\ 6#^|MP?;tg̑#5X!ep ,uZnbv:SK3$ZE^0yM&KOu˱%!Xx#vN}բBLxTߒ5*mNNq!G&A->COܼ @$1{OI"rUk)7_TሎwZӧ+"1zͤ-Ϩ4vmpC?R?mE#q;$g?>?{%d-.?Ԥ q|"y>-Mh$6; 0"UA5-MǦ>IL\:L  iݣnԦM23#)Xx+D^_#wQ29/P[K6ؑL˻#Uȝc#/Pklm'@&{׌{m0i6\}X鐔t5i8o{!{iVqp~u^_zaaǡoD,Ă }Rgz\͇SPzUi]Nˌ"SUJ=7'M-\^w PMU6Ddv2Vw#bL*3¢i^|Ppk6Ojkh+~Izۤ6j]:(gcPc`]ZmRbô a^]݀"H3^h 5VRT]b#̐qʼn +:[>N7Tّ) YI>7ٹ"Ug9L}||oS=_NcuV6Šm0Lo߹:O k[y~tIxwZ<&Nqt(o6j[՗i!(vs|&AfȉZj6-WҀ]1ia m㾒hci&\Jݹy쭅e{ ԕ9>ZnO9F{7-4}n9!e$1a}v?A^,3\sc(Ezط/ {FPmĊ7u=yf>ZS8V5zߕ}L0H2 w}{t/G>(>a7YTᜉmMkmS% f| ~DѴLo lJfe.aS3g`U~0ԉ\sBݕ,h2 g(Lot'Z=Z8[L4Rッ}J_.^R啐'Z%ш=ob\j":SSXFJ?y uc(!iC^ے|{Ƃanx C*\CPW=opٳDuQ_ezdB˷2W:uQ%yV][nhrs)u6rH_>y6sy%v.(AVݕv^oL#ćgLҙLJ4sf/\(>o5JX8rC)ӏFK~ط% F6:$לBM#~.0FDW-Hj=}k"/}fI97,ũ "xA3UԠn2HhC}rTE;7ƣc7}_3KR껉yu/{:{rt݀O#-Bew<& Q74F _gh0G9уubƘU_=0^fkĠv\wHb-} A$H1w78alnȈwތQw/t4|PxXsKUop:SQP!j<0q@24?ʘ >!* qH)X4^U0Ϟ )p"φ@ʆJ6[&yF\ jC}4N C p7E ^l1wd [)[tu_L $ _@)[YL͠dyLUH~5\.nc/_Y[ a F5ra6~rz" N;DqҪR ȕ\w7j͂hNnIk\dEVA=T'sF Iw;(LkˑQg@rOןtn+E =LJtẾwR{CZ ei^*o3";2TN\i~7qnj(;47`2\k C 1'(BG06SX ]?;mb<2ZUO#hocw Mܧ @\-@ B -D Fs~ؿ9B 21N6eJWyb{@g lj)HzU4\1m6=@H>w]M7ۯd z`;5W㋀׶ʈ5.`Na 9LOcubl'ra0a_W,O:~ fݽS-~}4iJ=H*%}iBM`~cЋ&̘#_$P joN"0qx@%6_X+iG|2*p4QT{q@]lQ z6;f3<76.8UBf بr3:~.ꐗk{ÊApRzRbk,M)RIsRJ4˭Sd w;jgGrکAU0((m>`'@Ѓ+ߡ1a7LJXyC瞪9Qpy\8% Xqyuf Ie=KkіGmeY"h(mX[{:p'H3wP;[I -oV#ɿ00Ta@Gk2@޲;ۺbG1E_4tͳB v5~pDdɶ?\!덻gxv18vFН)N!k0!WcPF|dZ7"֏6x@H]OKaCm!IKzm"nt ,F,?0dvYx[:K#9C>NGr=:ˢĬz9} ~F6|>؞4g}hq!l yiaW>-v09hEf hP? Bp$ #{1mB4cZFN4}6wcv|GBݳ r:W}!n)Ordڛ}IA24c6o+PB7]ޕ[>[f߉djnͮV+;:(]R4VRv$`DWTv>~l3QbAH]lyA&gk)1ռd/7kzghsVaBPMaBPeaq~2κ= ڟFwCvqXߞ){S~4zD.jdnVƨg&~Ic-1b/>F#Q!|mFH(S q@wojzlHyJ;uuX|J0ӖlSJ5'h;>͸G~3̝A%U+T~lp୎YPz?^Cu&œ I`+گF\i1L\1Փw$a(qZF]mv2eh1ٽV 2&ީr2kdhQN' ZTɛ?mo"(Mߓ㹔|3I!8W֍?w\aZHejR1sP·uX9cN`+*׸~w;S{C,?oFvA❯Iص}UYՒ;EgjI+,{|X@>Iqנynu.Bc%!Uo N*7gߖY3+z/D^Y 5z12t@`!>ETύ ?+R(bƦRK\[%?ntPzvR"Avix]i2_Z__g[pu-J9Fw3Ƒ ;YtwDvT$b>VsfnXq(Y*`pU \G?J{ݡy[*"qέ5ԕ 1nHBT46_KrAaڶ^x 4jBD/Z;fTol8u%4w.:ev?BjC&'vG1HM6 FzJu!s{|`8i˳R@ Q[)dV$\(}.VYCGu"*-j+*IC{\PXL,Ct> u = SO[85Li1-䕩b./$bL;EZp+mEk7[fZec>ʂPJo'.' puj-}ӛ2̕%ڴS wmi"БWY q20ԯ1k,t氢Oq$S6gB+PaL٪;3Mv,K}M΄C5 JERKN_DM9:qfΏ5CkMR9 ikv[A$w=AZ-A%Y_}d;s3^Q%= %]t\޵9_{#3e/F8CjQo#C_BQQO&2-U"m'Ts~ ,x؂HVT;qxj3 QT*li:iAlCLjA$O Ig&yE"}X;dJvPgBW)wkCh(t0 (HUhj0Bu0or[Cff]7/%&kҍ ɷ( &%ZS!|8d Jc1Sk̸fkN6X*@ d[8gO(ǝR[8_MTqp>4#?M')g"qmp57M\=;oe?׀P5yx:!8MEG[p9!Rm+6u|@rw.1/*M)74TQ gq>^U@(!7Q"a8O!CO/qKL?#({o76챥H~槊!°Mdyhltgר8Nf4 *Ǣ (2V8rET=o S"pGW3bsdu{jN Gg Χ:FB`9opGWL=0hڌ!ص8g$G;w=Ku}PYF2d$UF5h>=Mat⣊ ݧ. BCޮW$hd7}Ҭ DΘߍj6UZA;rq MWή쉝k !HM>eѪ9ċګtި=sm"[/C/*KZWoTكq]a;SYdiŶ[1Pҧ ] 1!ěv?Pr^E2)RTl HOYV\ C•A+Nq44wM&3FI 1j9iM-D'&1(|o'ϩ†Wy0|rRR۫4@\FNӆYsԎHW;'QY2DkD+U]+p`k;Xjo[_~8a LCwv_b"q=SpBJNtgBT`2Y R=x\DYBQۈ ɴM[K0 2f~@8)zJxī33I&Uދp&m Vҝ*#y$]ZQ_JwD[[*D&$(QtҬ֠™M H9TԿ/&E- E@9uP<>H4Kc9(!5ٚ~ $cNO1(W5Wn.#(9xIlz8EO'P}䉦u^!4‰>N$󏀨ޥx2lЂ grdnR.NKzRs0PA9|P!,i"y^Wr'H˪.ƅܻD ov+:<ۂIyG۰WGpvFq{ߣVwFş ΣZN/Y#f}LH u j_~9x{5Jb=O)2 |'B>nBe iCW^07ջ&V%CbQ`P Lժ0<%i4:v W3X-PWGRlӆkX5:z_Sdd͇;9 ~ؔ:ͅkeO}b q&žCPzQ9IT{>$;5nܼNT5HWx:q,3D -;.nj%# G}An)BP7B#enasUgya֪>mil\orxy<[ҳ(S)Vaa>c/^H-xdsY [d)oaE8 Ҕì_HU>Fdō2kqnsҬ2m9ПWk<۷:.1pѫ^$ 46nN3̍s^Jca/& o%lhZnd3q$=[qU؋Q"z3J\>E(L* ;oF ̚@/9dIEEwѣjPhN*hߦxYLVn0ݗ Q5'n@WW,Ɠ0p &$pJT;4`,~J+y`]`+_( :aqv]:2?Gw̠UD$@%v2lɞh<3Yqߝ-/#z04*,g Fdt \.N(1FN U2~+ۖmOYtۓ:"yjx⯩Os0$#8]ws@\H3jA·ю3j [פhxQ4oJ1}͸͞ȅmΕ!/˅+F*-ᆱ@*Y)yF]槾%2rEй6rXz=hCK^թi s:3c0DTbg "ݽ_wx ?kNtC_ m?7:9O4)߅ 62ŝ7էԙTŊKn9=96>,o`>([{ց?uFt$~&1:JT clPI(6l)(ECkv6pE72 ^7t5_yVW` zXuRT F.CB.( [ӵ@ s| [ߠDX>ǟea/sWp$ 嗺ʖh'MW[ef$.޿"9ꏿaPl{/Gߨ3[OmdzdY{"BQ:zK!)[B 1DL$/l=tC}!)dEpk`]jb=5W,3\/>a1QDLNvIO(&J&'/cשtA so%X|MO<7a-D˿NqZ( ugYWy?Ƭ'ј>?J!Xun3B?eM0w{@tIB./*ZN-_4{E^e,ݼitiLp^}^o-s]^¬jp17;헸B S`rŐ W~z*+3+O.Mث%9| Yv Kv՚a |OU5p&PE!՗dpTcUkboZ3fƦ n|Z_S{TA̘ ўEqoq\7e`Ԑi۠%1p\?+ay3°ňM<Ȼa9! ֫?%32xCI<.x6D`jt$G?ߦfÙpnk&-APq:i*s + LGM;ٮk= ̧͗&dkjГ$V_ g WLp7…f,dV[4nL  i||Iq0Md*ڨ`6{k0I˪DO\bbDxB Qcan|bd?-. c1D+?"eĞ׷e>Gx_!}-'Q?h/}ypg:sPRL㋾/N&x7|bo> A/ 7# Q'To~g>Er"j_RQx暍@񇝻R)S}R~izy5 ?4]wwbє72 %Yc2<;)ʹU5ˮ ҊmIH3f*$oobRajp'nLi|V'TVa/*_v6_ȡh>tI}2~R`Ol[1& hR;)5{fOޕ5s Y47˫zE[# 4:ٶ6DZr;SzX( lƋEdU1L$~u$A}qG)bA`₩+ur1G/7uմ_ &%ld _&JBEL-L_/>lpibM^lփ8M9q+OZ%6cQdZ>|m%?R[e[?YaWD>u?#W;߯t,rR|Jm.l8_bE/rs6%=ۭj: :G_ֿa,u*/ T{T/DԓiQ|6V{6*L 2MJɖ wof2z=m*KXShlyd7JUzUׇnL@He6ɯB.l$8ύʥm^-y bϟܹ  ~ABa"_g( 4# V7=cyj&6V~pCI18 r]{E7i:7`򨂘 F:,1rd1 - !IwSN|64.^cY n~, eX1Քc|"*N-&Q/ m!0D (S{pvO9n+eZ6Ko Dz{/-%"bu@ r ^IQ/K.I }/$WaVtп&IuMPFmTW]cOr_xLl&`026Р'(߃.v"S7 nE2Smx'MOn,yg FE ͉W.}{QQ<ݦQ>~eVhiϱUOul0w hQ /&yTJ٬L-s~.& ׶S3+zA'tҫOͱ|ٯo(0\u/ꃰR4 z,L(|Z_G鲬p:In8;=f6% -M+9HM)eN>`4$ --0]tQ#rE涷b*V:OqAK9wB$Ml~1KϠN\E/Y/ zһG95S~VhU/V!*sݘz=@W?Nk%30T2¢ 6VAQֺ2U!.ykCC=B-fU/ɵiܯp*8GăCQ<-w3Cj8'oAJ4aX`[q+.|w0 2rwlqbcx[eol<=>7ZoO )\'jc)Z0sbH 1FNjɞ`ߝqc7GB3|$G<8HUpb+oVlۇ@^$ACO]XR f ~,E fQ&E$r:cu“ QQ둤;řd2ި4C[VZSrc EfA>k-@@\vސ>Fl/@i➆%v zP4>@2;FֈJN%$a0 B|A?.aUbi9?@VϜn%Xɽa{^y%*$6#EŸmJhӞș21=b_d(oFz ) H\)Xb >ruJ&wM.{̓wXr=)p!ԀOຼAzI2&˼UgW%-4J._;YvCc{lZ`1IMq'KXPBzuEX$8Kz$cJ0rc-Uoށ(5 \*֊/5r0 ~a-nZO&$bA{Cju"R8'Jҗ>>?MeX֦Cmsgڦc0Fi ԁDJ'MH %~D10kXju {&Mصc !Jn,?v50uc Sۇ ЫqÃcA$ @T AES|Inu^RGI3}r!kTe(2lqe},-Npt䓧aBtU\M#V j@my]ΎEx`Wu0 (~:3#.{薞2P'hFmjߨPdBfNO7ѳhS\rTpbd}[G]QO<9$Ѹva\ -%j$ͧJ._~F"叡1ju4a-/> `n@:|B&aqFA߿[?0#1~D%xx K!"N0 ,g@wi@G00+gzք%w KFVxlq^~k5u(埏AE}6\،փ7W EGd Z. \6,dG O 3hH@M!ZS}'2z M2hI15mWS옆koJ/NO{rXϫQPEr9va 27wsi#z Msi |털VQ^_r`WwwCQ%B9V?%_*G ŕ\Qp :{gAhGh͌5ׄBjwNy/sá`B BLAA,-E4=b #{l6o|/+*zW*"k '_ n%]rj4)vGS)rgkq `eeԙ3*]Zk 4rt- Gj8D;hb~#i.@hK6@O)<*1B6LGҊVK*JI6߀zx@ oJ, 񱰗gjmc{؈)~Lm`ptcb; b62[!t٣KJ+#y ;.5 H%2zVG2weB?#|ZO_=B,/ݒ_zG5?/n8v^0\j.f-: ^Ϭ)#'S،!s"?H; b {ak,!HZv'8Na^9mW?C %T ؤ3ڴIE) CEf+5 !v:Z=IEG&m-y#[C퓆p%QvY=gM!D3Xg} Lz~+L$*!q.rSz6qGӨTwja6@LJZ/dQ f]16Ž8 s@u 9]z'!:۰.nYZ~:6D2❾s\].fNbNZjCy?7e njBV~qJCHF|WNsWQv3 AaVUhD(ϘaٓYV}M[=h&VAT!R+RՑV)O,*-|?xi+E˦*Eʙ9.چTmy[FQ$lIJl#bs wP(&ІP^<`T,ako(=,*O١7 ? ƇCH|j$$!`Y^ vsxa)KǑp_YLPn(|_UN}%c\g0);N$oM㢢\ 1)B F6$ ܡk`wJe|l&rJ)MC!tшA}W^@}(ѓYe:^X H\1ʓ\2W\Hʃ{)AN\5Nu|E YPԒ]FZLǩC؟"*F}^}<: Ky$ ima'rgND~Nщ~d.)ޛ wr`sl󅯽>C?W[~,5D\z_V X$B&{Eۣh3Ō{ Xʸlk5R;nK_g,ֈ&1(jJlDe-Ď#/ɽ+{@hBD"c%50eRLҫkyO0Z]FE("%jW C@ٳ b=} M(߇ؐqdh~Ag n1 &c͓,1%2W?ߦzڋbLd~|~ ֖ܰ['ܓűoM Fvp,P}EMКxHRWyN^( Ti Ini~ڴde⮺CYEKc9 @IU:Sr|.ol)'!:iF?~bC=Ydۻ ZXxTv HrQV[Y(f! (`Z:i?C y`MtWQ_(v]3iD` ĸ+Gxe_o𼢭 <h _VBr!=뫜gCy7 ~Knld*pH̶.Gӱ^?STDՏ'gi_<|ёš]BpkŔd2 nh+u@ӈC'?Fn =ta.HcEʲI\2މ)Ry\ }m[G.D̐5RKg^9I,Uܒ2}вҭd_%Z;A64W3ČӮ6B9m8~h=!?Q4l0JFk^(& r[0BiM'_lcJ_kr!BK¿|4Qv6ksJy4HإIīnJs{faHv EÉ5)r)3}jwpƒL fexdҳti֟fdqX`c@b.w)cs\;u2ak/ # b~HiksryuCIzýlM$RrfS"aQ7n̷  ̔jOɇ-AwEwPYh =hZ|9zIW72$ngs<,8|DxFf/#gu80mqlx{47~ɕX.դ NIVs7+ ו-%i8m#9r4wkAVs$ۓf8Lk玜#>p auBᾝQi~p/!&$4P#`VUۡu{*w/W߆`Bţ[M<tW4 ƫC 傺t 2RiK9Hڝnẓ |3-Y; "o/dK;ۆ+fP6mfPS"˕X&K) = F:;5ؕ ]sSr',R3m6O/+IG lk|# ={~/b|謹y2ȯn^ q`Gd  S{˜PQw RyIEOY6>v2hfB)}y FgشH8_ ?+:A2lk.k7!SuM&|xۭZv o ~,b"Njj=?5UXS;gh,HkOfIu8<0*~L߈VqͬoF/AZSyBhL*]ui|8^kq0h9 059\c(6ض̄4 )r\=! ȌlS})HwY-/¤S!"b1yB N5aL* rpPvV8vr rg5_>M'=5jӛ|0DD꾼ҿJy1ٱڧ/# HrIƒgo8e;u<&7zmoZBb@:Ma\&Pas?~F䘕m ? w軙bf=,xs# p1[kg!mLۍ-7hm>&P圱&8eB\·X@Yno.t%W4S=q,NO1鱉}9~ RB=eǿ#>jM`Sey^D Ȣa{rB,u0FPJLYG +["nEĨӊ|5)ŴBMHL~ x!BEELi\K'bՕͯe{ 'ϨVxX.U tLDʕIZi,?c{=-`O,܊M$Ӆ>\:J6ÈnEë0Ղ. B")/9ŤT.Q,<  hD0L'8x'Nd@^_J&^\4 n 5 #Y;hLDj(Xz s>!:A56z*Clk*6}l* H]subdJ5LFԺ d]wl' ;(pPl@+B:‡ rȇJN,5KlOEdbP'[xev8GPa(wm񺔰ZJčdYjb&Bd7&A ʱG^AܠFQՊF–{}.%k"ɄiAGi1 j:j1ʟLmggw&xUCĐ U4/wv(:iGNAws*J,oWj഼Ε1ّߙaT;t aŌ YW$M_!tŷ{·5ڢ e8,g+{=վRf(՝VQ;O^ˠE3`g "cסKkx\w$>x+U?ʌזe9m  θ%$'0A޻ [J:? Q#\ȜǗ:OZ`'7]=0L%Z)b8xŷ,,EςPoRhYw:.a/ZC3/lK4A3Z넇J MZw.0kbO08ݡ: nl!@ǎYګh6Ogz # ($߳䖵v"* /{ FO}]'WFh<6r+ (Ģ{c9@=j~nFϫ0`*drq&;y&7y}Zb|`iPF-0: ;n;?.:e(p^NQBV}XvA2جX&u7sF~G,)G+GIY#Wyu H&[O{g^6jA$=&J h'"g稩W}w ~}*r:>4u:ȓFpkH꫐רڣQoh #NXhw׏5kKK"0WZ5s"gVz>sF Jg;?%'f ۵a^&6ꆲsxAz.f2Q=z>:D,l[EL^k^AuҔTqKyiSe=rQG[bk%T+"X"bnN._'y|ܻOY?v:tE""`,NV[|Kҋ >û[|ni٬.N;yU'B.z ehXVFY׵{RG;mHK:9e$[FBoXBF~7Ij7_mj ui뇎UyL\NJkj}|?[%cSdwRqqĆTT5GtYM̍ɛU#c(?Fи@;WݾUN1?[2w&db&уOf-?D==Q~>:eR!N|b$S\6ڻ?dDAN !Y Cc4JxV{t ay%ƵJig8Zu__ss醝 WXd=i7N?@%+8c1T)ᄏQq͑q`vwuOWH;JRZ̾;(zA6c; ӤQʱu_#:04AɺIQ&,F@.4N%T$)%qN}*A+ԢUNfX{9$fڎDR}21I8~[euZDjz~[Tˇ x D\4Ɣ@ӱjny01W!chk)g5I?ЂEZdr,bezߥs\i$`;$W/% R^2:XwjW*DJzQU^ f\r'?x h EMek:p}rԩ>a$Gnߪ'д^ԩz!Ր7l^ hm2!]ŒpboÎ'D1{xonv9{D;rZP6];&䑖6 oCe2o%{! -Jp9_(t?ĥ0HpoɎ3 c[@7+H8Q,⩤ >]$mmO ٧#o ',(V֒& 3s+MƊwLN4*ꃗ"ge4X? !aN!ntڬ NvpN;71 #yڹ6z@2#r/W;pJwGd?R z0V^8x^ʣt[;  Sm^bU'zv9B fKZ @l׷C+LW77e4/+UmɄN`>C 6`o 9V$=\NTe:Hv:ahJSV5]–CrvP)-q=g۠ifPQS:@ PH>c#i#'t$fǦXp(FDz9?P_^Pju΁PtM/ % NB6q4Ӝ~[2\qrB#-{YoN8hw.-4 , 0G6!mUyW82iK"uvia4H v;d@gQ9G leR v*>Vp >|XHQ*dfr:_ωslszg4͖X7QɟP31_0 ]Gk=w=t!MW/Ȏ.9wCg٪uwI=ȇ 6a1w}{"*'$`Z,ٚpB#`H"1EkByS^*EL>Ir&Y(=o#vh7wm9&Y. P/%Nqi>,VZ1d; RVGRFIڝf+/|v#݇N|D$53-V㜣tKBB]=<LK-ϳ}@P $ .W[=?WRl0VL0-c[%'ؑa-&nvaώKH ۏu. E~ a·eC+a.csAOΛiLHe7t^!\5 $#xE(סά=?ٙ\4g#*Wj<SL>u-F8E?̟6*1+Qe0|a}9::㷊K\:]R*A m|eAهF%`>at$ +93}C[mGor:Z ܖsh1{!\i %Gi[+XXl;(z!3 ̸]Y{kSH2QMoF1)󭦕D۫olzD+s$9JۻE#lB¹4CKzK&}p?r[ĒP^YլIxͧh$}jl>qO@Dk"1לo}%S{Z'y4]|9(0 c>|ToK)-ek7Y= TwmVjذ!OO<3-R|C'@KTkي&($_ʓ872H5ϒrh!.AЈ #9IupI\$.ӳzLeΟ(3KY†qWoQ_#)ovPBt}a$% S^;&wj*5I2TKFuqln#fiЄЂɦ?E{@+4 ¤\V厭#/"$@7LA)]Ex٨ZÜNs^B[@D 3UO .Ӟ!&usk:I! #_( Ky{>g.RyhiҶh\ K3 wY7xb^>dm ^^VZ/MD]dD#;,XT7aZpYƬ l am5l* 3h{#5l7Oõ@.Ʃ~kWz1_jۉPO.jo\oh3x/~=:OD6mE/]tbkx.c\ɞPlp-(" 銒~& l#&9'TqyxG5P}ӽ([⧀Qƶp}*kC>1ч[&4R$#0[HD T} vb>,iah޵ I8TT-9f#@J*K3gS~Db٠e^tYbݱgnCl&Yl}X9+1$ڛOꎉ|=L[][p?h0;([n^eRaCW]V5|{:|32ٛ*ay<??sE1gV[ڗԳA(A }QUίlZ;=y2E)C57La\cxrX'G.'JTW-j5k)veeZP/!ELy[e!s-26L1_0r.+& majaC,=|[૤;a~mkY~t>Lle`F쁓lׄkS CY3P+j.[SRLSX e(i:ާ a?[yld2#je|W\Ch;j߰A8BN$q/MxtIW&:F/֐߹s\_nG|>pG&aqayZ5RmjtLt0}glyc2urX W1Oa:"waYy)w5ii*`>Պ;d5.FF^ק޸-$Ƚڻ{Q7z )x.Ȼ)y?"Z'|3 [ՙߙ;CZ `vv}$ bVr*(Ȼ_P "e#PXD{3kA/잗 =*W:Oke'ҷyѺT-Zh8ߥb\-[Tk#/V?"v4CZfʛS;SUJ]w!=zuccIbyߺ( S7RX;K{T?`:y7yV1_V5\rٳVsIdx1 3Xm'#IսY5?./3PQ1bRFXm;yJfOC,gbWԳڏh9,o_S p;gVNyZ~( ?hQ+OtyD LHu;@,Wz9:S\T&|+H*aZn7 Ԡ)BLTt,`t]A=;,~}w<4ijU&?ŗƣRh>t8" S7è վ2`;労^Lךc.̨#-ĵ(&3RJ3uygcJ"abYGKǾLV(qJ53*@94bRsgE7Uz N _ٻmGv 3߯n0Sv pj=o JQ.~ ׷Yj7s؂d^.ך-814|/NA:*y} 1s5CdC-2d1^KC`Ձ<٢8C%EN8pS`kFfs{c߲{>xl_S?;#pg} q mw9d).+ ÁPW´tāuz:(} pXPᩎMϭ>!lYWT S?;A)?BS#7Y: +[Y^Z)t}!\ZK}bPzA*,OinE'5G֩tl18\Dulm  q,kI&/1O?<?JPyp]<&ep N$` 0Sn7LQ{)Q3!]By-|MY5A)Q5H 5 9EjdI6bu{jv.JfrFtQ(Jb@UFk<1&I[5Xѷ?̖\ M P9h&r;ȡ3ާܷ%> c/ޕ4ϴ2kN?VE;"U?q5ƺ 笠dNJr̃B#Q!TsL=kj+mŐ~VF8! JB U,L6 ndӭ *4UKysz2r?DrKe4'DGLE\ "}mxwةMɃdemrl& {^fdu!{Wp!eA@Yɰ:#2Y~(L矁 a'gZE+VzBM)lp>_(q ?%H/-zjI߻N`~vM0Id 9j?:ߜa _,#n:W"ٱ۴z^p~ezp8+# YcN:۾6˟lL]=Y -yPm 9DbG{ڕ9KX5E)gs.MR?8w$ nS6¾f^HzHQՅ)8/=N/!iY H5fK՚va>$Bh558{WDHumΙNW)SressGQqC%DK:" ,OK`j\u o P:$Q+&Q8}c{A DhV]fAa5E=PCtT6"פCMe"oVxm&Gpu'.N360]UkfJ!z}_`<򱓱п|[52c 3_1ę5%{rB|a;k60͖HmMETMt/KBՈ@2UTuv=nA6mM5ꄂ\KS0~A] .+6o/B TkxFxSVbb)# /]I2'ed`GC:W[Y#z𬑹€d?Ǔ@bfvQ@U37r@02~<0F1m]$m$ Op!7xow_Yf^o`57r=o0;\h0~ۗ'!+DVd/ M› J"6xc4 @y~:nk vLdXy(ӂKT>j.:s=џ6Yw;/4SD @ԧw/{ՒMUEҚ()Y3A4Қ{M,.}i+jnbz[s=c U6KOeJbzҨ(]cn"Fާ>LXA?NP\td?gA/X9H.6<*zi-gډ7E2ݶ9;"éyuju6Ii I=44ɟ6U$yMs{5jnBx7V7upIDGU]E\v20᭎22p"-lԊW9zv:6 E z.N6gn| w ȣ$gsvHHJ]r>NNZ9q!C8].MB?BR+,rRhF}Ha脸ՌA8=d=8,ƏW>xZsQ- br0F&]y>$&n`~/+8rW֦F/FBx`Bn1qp#!G0C"@רg%fPT}oaHSV^op\5M, O + Imwv̶c)o`Ak>Tّ9.HV1Q:ˉze ޺ %vEɄ SC,_x9BXq#G f qa%o s&->oNQF^OZ;dŰ8M19wc=qydL^9 h1 CΏukQ?p.{;]CdX3v&0[&7%JF0Q<'rg6B B0>=KOg,\%ߣsFE!WSdw:(;dbk%`ʙ%(@o[#%2bn3I[Z(0q~%)[Me*>}W{p z5MՂ!oG-;O"#Br9/3JO¼%4}$}EC!qMkHׇ)26ˢk35“+rw ݄wᣅ7ZqFIM7L+~:P1Z`:rKΙ/c<ڕRc6EoIEZB6%WEm/(m#` TEO e!^P 9H͐+hb6tBE“#cs~Myǻ%qH&e&TQ.U4Iíu6-+ =9[ |I3+M氼9j۝ rYx)ZEj3 hhpD55L}8}2KMoʴ`E >Ofj.b*ٿ"*._U F.nQ+V{ʗ;zߑ* # _"=xgsGh]^Jol [iNc[ru2 #q}y&8>+{" $^@M{|{6Z :&9VZxzL'WܭO$애43f|79J{fND`"h"Ƅq+!0점! #5= k:aY~<+="\yYd'aߑi%MPj)6GK6!c%HGmxσ%m&ݤyeR6RF62#KD&d{sдOoC="HoNif60DZ3!Ȩ {izノBHF_(`<)?_Y"/D-kek};E=MS#v=:ex!'o,dY:f9 AW>iB5 ;FJqMNf$AofDށ ?NVE<d4%9Sr@Hݢ~sPo,mF (ńR_Z%<( iaWQj\(j2҇\r뽟{- pe֌%/i@ JV咅LzK'\}Z#UGZL np>ߓGD=\Q>7g6^KHw,ßOc\#'.Ii.<|roܦ+v^e?P ~71)0.Nq:iS"J~(=|մ wVV%Z4wPAL1w"2'","[{  q~;T8FVK!Wd u˭xiԾ*].ZiRWǧ,5<6{Iʼ: #N|$Ts3 4ŽAyjfzrѡPoY?/ p2r3O#yV=cZRgN&_ia^XJn?OodבJ08sm5p[f8$ӈ@,Ǩ1qlgf,=:f9gZQ@#;}2@zc_ $ ;W[P-{8A~xl/~,6k1TJfd]CrC!6&Re}G2h9 <pY1g%S eF2 _b@ TbSw4|lT6:SqR빣 R)0uAOK&Y-_Y(y8#u1ǂFw@uS{b:?״Ȇk>j׮OpZPP5?ƮgchMR˂w٤i{ĭCh?|&v3&*(YY>ūj}{vtԏѳ~#܂U O9؄@iWέט{4hӃ{phi{XyؗXԙ2)@URfLXD@A*.8|@A(Zn!"{$T,Nr.RsoozLT[ѓ8Ce,Yݥo=-׈V=QwWjԮ8Y$7FC"bF7k~EV˛,N_a'9'*j2!@1J܋]˟^C -Y3攺.nXZ3׶+92R%c`y[6/P:;܎<g(rܑ1@D檉2IOi[b7xvD4(O`~&?~ysȭuD ]yLmXc`Uh8=pgȾ<5Wj R_>2rhVumǘgMx[e-YBqph:v;҉*1Åo d51Ff1~a0a\{vR)isL l(J>0poJz&/}Nq\62^&EkW+}IdT҂cZ%xtɓ EM !#,pE?z,/}!J- Y% v.)w;iUgsL  sP/(E_kc{h]I=J&}4kWHAM)÷, 31;TgY̐Q;šxg)8=(^,`lЉ BN,~v7hάv5t?ia2R.q0<7}݌! &u"a2(;e\}o3i 0hJ [(W}ey_s =6D+|,n4ϼh,pbZ\|؊+#kdKO蝢_Uľ FJQ>PC9yb`bn13.jkVD=چ/|};=>P,UQ輀П8?Li0z]‘h,+><#h)rR_۱R'Y¦l{y}2T_CSo՝'|/=" dr D9l[Ā]ylvLjHbVu|WSnTO_MEff4? 2`cިI3kg.mkQqND1 =Yg(^ȃB1#@Y(Rfl趃*LCho̤"YvXj^l]-l^u ` 5@¤ Η*g5 9KPh=&gX;H8xdu}&$C#%C ?9.<)3Ѳ&cPc):_ʴ!6 9"[ü\t$6D2F>|Q +a>-a}$Qf/v"bX.8#r_8b8PHe֨6AyJ ߠksJNV?Zԋ~J{ ^->6qc'OnJJ P3{S~B :_)#Q2eHRCvmw(=BLVANJj _c3ʼρ<@i9=2)EKB inZؗ ϿV\pF>oz:K[n{A5%X=vpOyD2Qmkb!3h8Ord"c)e(j1 7qɗk"%'PsJLiJS A ֘^Cu*0}{fBN~P\̀jM;s{35&Cmad{dA+F<&{H^o=w3:U lܕF ~ɶh-e8zo^?!ȈJ.F597(b94{ʒRGϴũPg3‚V@u#5ą^ydηyg)`r(@#~xz3#OLe $XV)d_(y<IsVnPgv6x_bgcMUvk-xwq@BΦlweRnqs.; (8M4sOaʕtb您P pYX;L'NV^ oe;W|TD>41{V6 pIO6`Fhhvm 賃x0 ˎh8#7UqS:o<`#ƁFAQ=/L+ PÔ %rgPbF HVC[B5%CGz/lO'uݏp|a$N0Vu;"|[e2AhV487乃"jٗ*i,i&u%\v%ih- (rz΄>BF<,XQIb:=Z'/TI?쇳}YS(⒦ڡ(fQ0{ÐÍ ب|B2ݍGNr}8n5@ ܉Wjzzx\S}A63gtb3GIcm. Л0IⱕaQZf&th cQFװ( e&% ѡ9ƒl}ϰPn .rs a|@obA1$3A BV>+eJYW>{mϖ-04P1)Qfǹa3v՛^n GC\)80 p )k_tcdvCEE+xm=FC y Z؇IQ8=ά~RTVz=<֊J塶#QLi}zo2YmlI!\;(znֿk@~=!,Ӥqő˫T|a YP"DW 1O*T𽽾i”3~;bi<̊ݫ|R-J EEqʵ!D#z,C69'z=7[y+8Ό>=OIb>Fɿ-Q>+/u(^'T#T}`ȩ7RgJ<;ތUjs bQK'6N1xv_|]y#ߩ>7{#M qmZ vo8&}E]5`XO}HixI\;‘9P Ģep[gc&lȐڿUe,Y)=#e Cpx-W%uG˴/*tJ3Ziƌ]+y]t Z`hSl@p2v+eѰ{>vmh 'T-T(Mu˳zn(hªcJNrMf@P1Y9Yժ\آ[EcO>Yhd4c3gh\.vbhBM5k3MAdWyҚN[DvŪgW4rhB.W".Wm6un㱗+6 0$4f6p,ʋΏ,%MmYF3R[f=}R3 )AĘ4/У"P_Gӯ4؈h[P8om|N<}+0Wڞ'E0z4~+eX좋j%o/til@x>/SQKV5W#Ňj)]&'' .zw8.QԵPN>6 `^W {*34).8iz-h[xv$ |ח琩s_kw$@Hc=L|"Pis}lxyYyԚKqrXF L-ǮBt!]UkO6S9NjMntrͮMY'8"5(t1E0J "? ǷrA:B-3ۺXLׁSZ&a55l\%wʽfdGR8.yA(k+| tTGj|-{vaΠj/DS Z>&#EՇj@_)hن5lX7h2׮R;W1 f=~gM:{+xx} (t{JpSɒ`q}._Έ!=bշ,(E8ivaiÈy-oJIkYփf` A{Z2.~[e1 {b0`]r[&σnP *OFU5ޗW* |]Gw,'F\Ct| 9AٔREsރ0^:O~fA1vx򯜩a}` Iqd%?62!X ؼ>.Zt&`eigOmXC32CiBdZ*>тeH`crscOp0Kd\QY@qevdH'$ ۾kv'm'"W̐_GAᖨֈ(5X ItxqB k·WY>`P)ud*Ĵ<־,.jj{mE PM>dȚ{O1vఇWd$$ 3km5׼F@ر(#z J/aėI`DSGc INQegbpחYc~*r5"w8@Sތ$p^w]1W:0e蠅&VDovjzkV(y72  c{Ļ:;]t݂f||%FQJb/YE~e(fv2g.‰\i$ZI"=G{˥/j'1Cth ̴\FFrħgWRCuڏy N54C5|"KB-|*, '9vp\Kbj@Q@ߒ!Hw{Bu rػFͣuX>:_M:XB8@!e-f`I4u:ઽ~BeUcv5$VDAx 0A,@臫*2HK |$x]M1Sl/v{='NPW-FSZxcC+nikO):vnaVt S8z R4Y eXd ?s, P|o&ӭ?:G^ Re ukkꮤw_ e"% 2Ձ,If75Ql$ 6d E!̌yxp;|(kp:SFNV{YF]cx`ndVqqvmI?O&32Bs/K:ˋ5*`Zeuؙ$? ,h>EڥӤ'Z ёkL(zFHѭ_󰡎r|!*hy5W{k1C4k1b:g% .YF[}e)u|We:2 y|j%~68B^3iâOx,#(#fy+N b~4I(VRwHh^IAjؼG֟>i 㿲Ő6m5E\)ߣIEQ w"ċ[/M8RצZi䕙_'kא j4[ybSJ`ϚkeTt1=eݒIqd8Tt{ N9RaQJxR7ZTrW"Q ^齻h$#{G+Na?G F!#= Er| MIagFuM)B[Gpɬkjñp_Hfٿ#J4;8W)uh1/p,x& h/wWV,w\}f>0AP0t?V±v.dUe ۫^ aʎܲtdBUMD ]9)3z"K$bG+@_ bvNd+sw$Bo1^zAcOն74F{BVWq",+R5+=,t4$3k[=y$)@dѣ `m`R%HzϻkZ%[o2J6hԺǡSʫ yIM/bh٘,:+ {;B?'t9j/9TAb(f`` 2ԌQU.>JR78r،H[&VrOF(u7viAFQA"k𥋆 ?GZ` NH6܈(WPՐJ4q'\t,ar&&HZ]~T+䍟bp<=Hv[i&ͩxNw/>F=4&`E̠V\$7x n?<2kqtۊ~is vOBRws2|_J"2r>@6O% 8qrMd#{[R36#C Om{V7S=Ayg@.{P,fxb} ,uj \L|F@Ƈ B5Qh9jEF){b8yoHtG.w+t- HNat{~ k.;Q]ZY5$V<|Pc!̹oTXz19HMzN ~SmwM{5qE> 9B`ɟ:>Bnvh@u1$Ut0@ĺgt]1 h'{`@f8#T*-k_{؀BaIRMOP'?2o^HF+ X*~ T(\Ъ.YG0B,n#H- )5Ɵ~gCrɤ?Q r2Ʊ`ZY_w 0 Җ*5PhQ'jq@R*!͒lecze+y (o0Z;zԋ; \:'/쿯e=}ōgLX|#^X4]Tÿ"B>p%'?3 ̨4+j圛v`ae_9)O;|c=峜IժC¯>5D$aW=t ,U_Z4uj3PQTSJ:: <܊#܁+Iu0U ûx%_yS*իN(3WϐaLKυ7?W .eo-5jk>]"$eXKx:`]f$k<(tl47}^zw!LG:OFYD:,B?&gUOv5RJ~_i-( e74F᭟F-21ݽB5f괃&*_ZJ$seG#jLP{HG,W8Hj-TfȨ*c^cĿ&{z$q<ceqJ~pqdpq+~!Ƥg;!\k66c%Y~4c ][= ?[ևşh^A>o;zGÛ=+d/)?6R&vE-d%'ʰ˩ 7 ѹ7Ԧ։wLQ3HQGS^(fȵ {ZkG~dd2hL4F~ g(`l>}=K$ІsjHlpnތRJ2 z~x-[fC\5ܼ&@-zcv\˃Ks<|΍+ܹ@"]Z+-oiL.4i*o!1NnZPe_!Q%b?vĮmϧ^'E AF I(sg6>%7ܚ=^`/ޱM.8=6\/d@,뛀û_t'-In Ӏ7BBz5_ſnjk~f~d|{3٬"l|ܰ {  2^^xaW+3z$ U:jq AKgzz t`MN?er2) v˖O:jMn]T<)ѻX6BDD`wEܟQU' r9\. y"BA@::9Q1b܌( #EۑA.zRֽ!PpLЀTOn"*J ͘hk]~E8l>.|A1)r5;(-YCtβKayY{bVi#x'hl?tʃ`=^!ݬvkOeǞp@QbI}`էiDVVhs==ΏMC;k{ľex( > XGa`, r3jO)=1'ES`‡R2 ]aaS@Zpt!"UƘ  R ~gRƊ4h 4K0/>ylLF}EVԌ_&^1X$mgm@J4cKNtX6cӕQ3 OXN_sy2g$*GZb0g5˦߻)"**0o8 oO9[AX$ $V ;-{}12xO'4<Ю̃@myR 9f9=ҙaS3e)߁9Nq%iG)Φ,*uh\Ju] y+&CH7L8 *ܡl1F҅R;1;tph-l8 Ίl}TA-e56^ϺVۼz)]&t>  Z6RFI`^.ҝ_/V1x:JH8[GG>gu&U1ѝT ۈ0L[|EܴɲP>:z ])љ=6K,uEA&{\APO5_ }R&_iǗǤ 11?aSn;cABЍ#U:ﮒPv<0Q)~aS}1`B^\2VD$ok`_Z4nj+*LLaent#?n .f֣уZJAl&kB! ̞!^:AWGH?:4CB5!pXX77S? sSe'QMsǾݮwyRseo|!pKz}1o0M OӘ04xF_u|Z b.(yY Zl *d]GR.*)qP5! SC$AMojoJo%VSIMwV$9[l!עABN?~uN&/@p^A;pg (5=gKǪ[śEBدX.>:ݠ2$Nb? aCDrB?QjuL0Wj#vca) Tu6o),ؖ_;_pH''Df @ vs7WVuȟ$v>^[ e*  XrS\Z#jJm5, _aA#nr#iagc_48(*F0X;]c]KII*.\t fvsO! -2?w_DIOQ'jhԉk$’LZ5}v}v_4TsHJ׍q?'x ՝daŤ4=Nƈ^0*չĺ_wut uGqbz0wF>]L;ϠZ㓬$Pɼ¥lՙ0SfaAT0"eW1ĝDkF~ 5ҪQZy3={@b* ̡pDo/;l:G׳ 1--'>6/,õ?9}HS}tHL.dK>']O4ŀV. gdw~`_ڪ|SF뺜 !){+4;z2iC="Dz<;6<0DPH2y#81O)ڡ̎ɍ*0t8vUO5:8:,cl9zЉ{r3SJu@,`~K^%_L$-ʘ16R++ÜT7~gqm?taf~-4ƍfUYs'^Taj(TG ,)ZvSxc2T? P$n(j̈́ء5(^}0^x`ټb ܒfGcSP~]àעd~M[$-_j&2Pwp!Al3t6 qyEAW"֍*465}J@VB<ʮGtӰUV_LKQnӉ#Q+"-X>V ]s/2uq[X GU{W0h'>HȜ,#LaVBe6`BdE>VOhi?l\Y("mY[X(CF~о\-Hډr*_-v7CT_R3ۦoS,v\r%uӉ3QsUpx#ubI;o6$(oQ\*1~1Z`5}?ojU ]1 zg~3/6&2'CZ]ϔ&{OۋPM~fWAoJ"6!jnBy :Pf *@eOg1/>٣zIa01Z=boH2Š Yඅ򐝲ό7Yq[=L5a]G Bhf̴_lI#ݽc۬*qSYKiė1mݔYֹ#&+')Rb[63"B} ,t*AK&h"l!B/,We"]$.~۶6m:Xo"ow :$lx3È>4yDAnɇa/= iCANWd.=V?l{EYZCĎ2ouOp`Jټ:u [5Há#PcގNw,*cAG\D^rXhGp,މWb5YTybHV, <zpn qhDP<I!݂E; #2Tm]dФ*OǑk\F/LK2L)uif?k\ Nh:P"B&,]x1X q*T+`NaKx\a?&r[֭Cp@7"p̷t қ*߁ h$qڗ 2U yZ'7}iӮі(_kF Bٶj׆n@ЊܴKRZ;-ƥȻڽ"JT`ӟPuR=Zx_H_*^Ptdqy'b* %cZeib.A - 2d.l'ݺ+g]By5![LD0J V D6Jy<Is6y3p]|G'wtBBj,x mĄLr(ZQ>Kf1ʝʍ;,Sd>\iغέGKlQE/ ̫A6>6öK,X9xg%F͹C"|ŷ(UoFnd5ь݌OY$w e\6M6 q-Oϳjk)_mB:W7 ,+ &h 民i<z?&ЛPLx,}n0T]^zL o 4l@mc'd{ӳ(ͮJ z1Wrni%=ʗ`ND,7GQ(sU >nuM)8N Î:f/󊹛=;PMګA%g^ Z(w'GF5q!Vm`KsEy$ .0,EI&))#Wa%l&q>ϤF+oM' T5Z+cOi:︧鉲ס; Ym9 Pewfn ɂo7yYX"tϣCy]Hxܚl) x{cMUwfQ ૾DxlU{?KO\)]V%q1=` ~akB.er6 'mղm]nZ̤ldzXH~YX189k"?n1$`چN<\WV^:tJukC1|E-#\V:|Oa0Oɚ{0Ǚ_輋}Q ֍D@CT8jo^v0'g!EyaB}[ԼN&$w@Dw*Gղcu*.qyJߩlxF8&7ȰIrݼӪthm(.HC1o8WBHak &!ʛ#`31F},^`Ƥ1aڦahx(SO|$tε0ƫW>)SJ[&?^hSEC*uN .) D2A)T.?2 Q cpS(tgf門[r7B|grVJP1縪_Tgr\ H_\嵘^tI"LRMDY:1uwQX hYa22i"\WPT;AOYz\źe14b8`kAKaQtUT2.:>>;'Vkᐺ4Is,~O^?{9 Dnb_F%ƹ^XJ/s4*3iˤߡjm\Pa UkЬafTᜎK!tK#WB1UFU9)u u~yI_uu4eoģ<Ax(6¸?J 9)\yا9(mF)&;g!ļK{{vp صK^2}|\`FMk7خ"jяE EEqc@SK]ʨJɤԀE%-zXCFcd@B'Obv`tsb\3fNm ՛4;2`MzTsx4.ztABȅ4qļsjK+R>ZKR-%O 7?S!Awi̮)v/.媰&6,"XWԨSa<2rz\+ ]²q X&uԘf[-*}"# R&&_$.y>5\S=`y~R )懰?,$-r+~(#"G:{ -(/mhn^%ٽǔ_da֠p&!P*OYRKZIPD pu7d\7ckSL98 @># j&A ]8`xbA6 @ZG|_Itrq,s,Be'ؐ8Mio~dxYRƆA"5O b,XЛ|1UȄA`3tyW2d%DwU! j{K{5qY$ t}r9VH#97gƑ@FL]DBxki9}4^aYd\H .rIJl<}Q+VMm 20F#2Hա'"n2aDU/+lLnhLZ65euH0?yJ䯱E-$`+uLP7߮ 3*[hc36?OJb_0g#] ,fLAo] DOv@h$8pYe7`|ռIV|]O4.~eʼ,<1Jފ-]N EP DB? n2"d^ %^4WF,xW&W f3J}3P1ɓ/=< t&-]6Qr05'~!A\>S*z r-1:uq}Tg{|1:3 q#aA?J"|R'[̥UuViU`i]d~!OHeˎrjJ7BZ+x˄:=G'E1ic7."oI0 ɤҽm_=waݮy)4_S$_BuIhu[SgrNh(`$:ikbЪr@ 9\zOY\u/B±x%8Հs<3ڱ$u/#e )Oc A]V^FnKa)Ƭz2wM6>^ 7SM E-UH;%h #> kcH54(qeNQ0ߑi_X\\.Du뛳C ΁'Q)8@U3HBLvB[ G9o ޺EUϸsa%3Ŵ_eCw%)fpSFp>v<53ن [ i\|Rg[G)lD:g/{-jwZ (iUX{ 63]p "Xف5UbjZw O@.KYr ܗL$9ȫ+65`}Jff&>r?JU6'_5q`-2KzA}2"(U2MXN+ QLJ8PG1SڛNz}rt d̫B6{ESysH?#$p4fNkNT<W ZFRP@?=n jrubPT8 _'`ZX+ HZm%Rpcf !W=8z8Fv(K 4B>,PH:|ՓY}(4} Ċi.q# 9'd)hR_$>_0a}\ ~B8ܛYF^hzw,źn_wwG;h2@oK_> X2o-=7\BxV [XFԬiu- ASNObMH%+MU>aFz5#QӐ5?μuJ~pNBi`+8.n/Wpmnb/5_}Π,AFL;4  ;Jc+[CG)1d`UpӔ렠3Ax-sG02/K0v;p UIr㈌qLjփ98%NjlNfe͚1?n4x,LQkD2_C^/RZtHAe!|q:G~BIcEtQシM[Y bjC{7}cU%(V4dZ' R!~Tr[w Ղ:)uJڟi +K:^3G_qfce+_VgTRc xT4a^ޞw@] fp%_׀@g,M߯zEs%䳏)Fv0R({en!W0b̗Z|wWٹK?' D?lDeLe.Agc k`i{"p:c$, GY!ƹ|-}-1Fɣ$Wށ_m9VInkYa[m*5Fo5@Ŧ_)Nb!(+2[`vWTn>΂ 7Q01nR1omDlT8)ևR]JYx-<ǛT5 FZ[,gaQuF3NӤ5r2Ԣ; Ԡ.g;Jj"P{Y3:4.0_iw9Ox"PK'$wLDaX?[n\鸼~`T Ug\75]{juLvH=IлU9 W;ObCe|2*Ul :_cX^x8ѽ ވ!P3Cb'B1G\षdI͸Z%du%{Y؉Zm/z,lhj `=DpeZ ,Qp'*vyx|fZg?BLM5&iÑ/Z fOVf1[ٕ6 AqVI3wiJvuusÚ 6%o򭸖ǹѬ(I6c#~c變<~EGVM/SpVa.hk?bE~[+wOhm8pNH( ^niѓBS/>^oe,bٷ^6~ ۝n@=p[el1ԕF_W&]W';Ƕ{a{kl "Jڤ@WU#[(,|ql-`tBi Iv3}sD(mdv"PzFʣ^!kcWn* ӓԱ :;Js".ɹ,UZ 1?(م3?Px4)CnP7S09,߮֒JafD Pax7ZIxix,j?#TB~ ͅuB_#H.l|fuUn܉]!ř@?+m@HH2U?̮ v_zU R}/7@20$ ~T!۩sk;8bQvFͱrOq,ھ J } yIuW@M, &Pg_Om;Ľ?aX3 <ۦ<;?:ANOa{lL66DUAÀ|~ZZ, $t^C3ݩDʋ@XbͰ.k;=[ZԮNm>廜V&]{(ΟC3>KW~zKzf`'/[oH T)h04s=?5~%jC=٪BEɌypiݼ if1=:80悬3غjGHtDu&}rM`=kdXx1 -†Ul?q1n:2ghs|Լ"7; 6nc>ƵKpA2!>{+(ϢsDpr=zz'4P[8 rv> טZ``dc Ls3q-4\Bf~o5%hCs&{X{*LW3Vv*j~Pv7H$-v :7`Ѻw_?\qƕ)]B¬xn B36^L~"ThT`rf'%(6;h/J˄۹<ˑrJXxMPT`Eޝ6/`X>9g~<%'LIA綀wх!.s2dz[B{k@X%ȝc<ӴO[ƅ`H6䤞g4xE!gz>PP̅Qķ)8uTkAa!+ya3rQfŠcfF=F%{e;V~s*j٪t@iyZ4Aߩ> 8&E.(*/:xhloɛ""XҴ1J8ڤ;;׺,Nq'6&EҜ)ԆgDtB _.z;к|pB)')Z_P}&嬡O3s"BH# u?W=ZX ` S oJ}rM x@V@F\0_W8O_sK\Egz7tM$SFFHcX[Bs&9/LOX< 4r<>pˮOliofO5Jn~yytzJ͇lI.69gyMWOP&Zj{?mc"(RA)ŖeKcVodkA:ASƨ~q##u2JlcTTx6&$Rgͣb&=~7#APKrnPQAER%'c+9E[ڨ:al;m$B +5gy=I_9>"]V\t&o[IRx^q5f*Dj.CmqݱY:ָթ,e<=[4v(ͥAI Eq!#]J :C'='(gЕCf&JAƖZh_Lޅg2UaYG(=NT-"_e=qp؆8͚&Dq$;]ۦSkW3Ə)*KDVкv7=.Y~/k!O`\T%W03'L)Xa1uu6ʊfBnaJN0&GNQ֦Ns鴏b&|?z?<[| -JAhUHI2P'qQU4.^ VD N>./:M}WLD*;YK!Kֺ(c8ML01QXLZ @o 4JDpN6RX"XD o29<`ZUN3!%](ƿp\vofŕ"Kl, Ve|N8c)d-n/;EF>!H֨GM@s )^>hd :b㋨$8%toOW%%{bPs'u5^9KSÛ$Cp@@a{,WB@xc/ 0aq+on|Q]q z|t(mւn4+z*A!r 4(ATd.e)B=& ŏT|獘\y\D&rzBt?~ZXɂtNw^4'(oknB#cK6jp@Mbң͆ _iևAG b3d^11YE Ep+K^ ;NIi~\tHGv7xMةyVCmz-}jY)vO35K !.;SsԺ}W!\ʻ|g*4Yhq[u tM+܂{j _++^~SS ]SY%Oj6>hCXݮF"^ >6m^\eS2GppX^ `_U$={.Puuog8UN%rM/WuAvbD9&45D,#|F{qHeh@jmV!Z7}CHBP !~٪T``nڝ #2f *XShFj̰PQi9||bXR;5M|ίTJ[s_3gZ{~G@ GHqhϯ tzYq}'!a1>ј@Q ӓ#:SW; [b⅛I!z^qN>険Kz2Rb~m|b!S[?c&~XH~#M+b$x8jo%ϭkicsZfc`ZeLjZ_5 jٛ /Umj-nLEy$Ad"" A bEm?:`fMH3:'~/=1'KSP{J{SZB뜆Һ@S!l? MÛUVM`;p*$nuz;bNY=%:z-ԠW,IM:GQK(~L+b΢NT.3}M0v"1?⥥>|ecĐWfTkJ5ICܫkNJa@VgdO; 9t-c:zvR1ʒo<=ZE1R 1U9*b}2g̈m S zӷɍPԺp'Z$gKَ۝5_D:~x `90elZזʽl\MծtS3.uAGq(^m.*ìISn0elt Ma(r?`G~V' t }"}w.\#ݯ^'LLQJܫuBf)lB{kͼS)ǫBv9@e\`;J1c2@}C.;QmVʵ 6mKV4bnW|BԣbVf_w.|J w`=r+TsΫ{wc^L?9UƐ-hkv=kp4lšR c*|^X>bPy K!nԂ,TYGXjgU"n NYȶqf7Gf'4T>Dv)Nh!RyZ'߳)pJh; #Ґmk*TgL 9Eg:/1qODdJlɺ!egmP[0ﮀLZ`Zb8) ezoZyLF[\f1"GA 2TM-β:$>: Ӕ@bd, @`6DV7EhԁbJ]V6\hr =0Ɂ#rJӌמm3gҥ) V'XB")hDKF_hi6">?jeb>wyc\_q! LWk%?md%<-9q7qkoic^^ {J)Mw5}]%}M[HG`|Z+bnbxC3$MɌ8dA½R|D+-ΕY+)6c2 mW+ׄF - `Y(m ]TɎq ~Z=`zz_:cgqD9(uk8zĭfK`C3, O?}fض;;9l ) &ږY٠g*&JzBa VU>}+BnjAbA+ldB&J ݴ1y_gߥyf c#yi{N8>? RzWmȱWd}:=œ*D OHqHZed^LC!`O! r @cQa1{Sa౧ $^̸̈3Ima$MpjBVm t`"0WOo>Ǎ47J2ֺVpuc3"íTJGa4H2j"Jh8ğ-)ҏXo>^mx)NhҟlAklMStjEthe'a#԰-#[xD?3_6K2zͫZweC_a=Rt<Ψ-='o!fo*gwgX&0D?@6"nqe +^(=_TR%}ԀHn(&ل5)< EZ}dmQ6Y7YNǘ06]ɉO}L ca*܈crM+-tֻOvb4jK=>7AM6+ÝJ.S-PXWemC]3>-H(p{Z~3[®Q5 uw>$Ӭt:q%y mvsrdB./|~03O2U)hCj.StIh_x ˳~^e !ÒP ;go5ݨT}KkϝbIoE>VqV\ZAWVJ+,JsԎ>¤R|}_\ .Hv ?/d%J\o0:tm|nC;gwkz8ӑM&ˣ 1@X|s#Bm|Ɍ)BqӾp,JI1qaU#jیXG)(l QgCc' *hX3F"l ,q2Xbh!:Tre?~bssU6R8v!uGB]:lk Чu"VUo73f/bFn{T@"=po+V%;_9VUi裋Yj678^DDV >1et_V]`zQ?\M{LG-)ќ->HDe;zA#y}z os'ĝiG#@awT#@tL5pƈ"`9ރ):'6_1*.mi܄xt )fsk-90׸(\i_ ~?TލhpHH .y 'PV&O@f?p9sV[lW|S@R sim?`א} Ƚm;r #Xƈ\hv@$ `۸`lYG_]`C)R7rv@v!/~Oo\׌֏M؀c>Mmg4{_?8@ZӲ9#=& DTNʣ LR5c7eeŞTP,gM\B3'vڢd^])+ZqLvs9JrZA[ syLoܲ&!dؔjH;QK-RK߾+`>*^=u,,CAڮbK&'$c\*.r DфPF[+N4`!3䳄'm5xPg%tNp$L@Sed>d5(;̱'֒'_)m}A"^ 7tGh,h͏~+];Ft Dkjp+6&WږXf|%רBjl-?#]5u:߰b6TBSf5|.H @R*.o^M m30XIQ_ǶK,l>|eDT~?/s&Pֽla(voTsA!T5\WzC|\M. Cw- >@#[LfLc@#U*e\EOFr0ʦo! BVvcQ5qYjLjLs w@Ѩh Fs)P`_(4qrE~2{4ϔ 3Z")3 QpqVWt G%W (J< <%mxp>v;6GHѸ`g Y5" ]VciT,\ % K D$~ƹl;)r< ڠ\T2ג"5cpkZU 7Pob6z $džEcs?`j~p\J"ja}̖C;9Ҳtoֿ*35|Dנm\mH:kW-]0n&6L߆/+U> ?04:vN>8 Qձܿ( ꋳl6[;ߞR3u,D}5Ze垇aEer g)rN&XQ&(L(L^ap:-ۏێdZj*f.p 4oԿhVz_ѧ&8<(5x]M0 $lЌY;/r%%9~!IDqUr#T҇^1;l=؂f-ǧ_G:1ǖAs\ݰiI]GL]DAZ[̵6(̰ȭ'FhwX+ =(%Lt~pJm NdJ7]Utx=TxT/WR:bOe =.tsI].MM^NW8ԤZAd371Z]9b0%1u*t`=X}O8PpԐv7?D0:+`d31m3}DˮHH]<‚g&BZf'E~1@J"{+Tw թ{mo~ hXN'w%0w[ִnLo x'4&43)M$ 'F5B#2}oC3)&neb/xpaݮ;ZT 3{r7-B Ԛ|9GDsMxh[Ao+zxgK 0aBf2#lcoͲ댼h*1ul=*RG 5J‹v|CkHhB |9LJP(~7JIx@d#6=uuxv) gڻs>AЗ ۸YU{SK:<܎Y*qtH-0>Y,_ʚ,-E?|@3a=<u*4f;]YOVWp3?+_gAW 8` \gmUѥŌf(V=ʾm{B (위Z"/dYH#W9+"jL_\S+ti;x5FLcm8 !sSJM}|Q믂aEp3FКC$(GM .^mرEDf@\b6Dȃ]?pEtԣ1ONO;"+kIv<Yulްy4=4`/`cX!PϤ-ߧ^XwW̺YFV(: OFڔ ;ʘJpI4B΂tͮDCқđ7{IK*J5sbӺC~ggHo;^'/XHwݦ-?/ *K~.(͑}d7=i9fxph_cLZaQ2O5x[ CX:J| ;dvtټDkҦo]Nmv;uT()Z&/i1_Zbd+!(CF[2mgH߰ǣN1C=H2d1 ¾wr rT?tVJ,w%vu+#-@rlfʄslp ﴞːY͹?JD  9%]3-5?)<9qKWqvd$5J4$.*+;^C͎m-L *˻WX"9 tHi.XkZF 2GGN}h<%la!F.IWQ<p"VBXCM]둬#_.R@h/l~8,%@m٣(c@kK,ݩʞ&5:D }vFn6 KJQawh6d$g0wb"&Q+W+ 9)=,=UKPB=Er4`L@4SQ|K2S2ZbIQ~Eu@ Uɱ$C $;&Wr vaUÛ(ق[lZ2:1ۜ kێw#m;W@!pC)8^uJ~4hTp!yLl 4L%FiNy\I=SFSfF>ds\NYҡ0c!{>7y﬚JB VZ&$kx¿}-i庑ﳕEtXDnU@=::X7M^M`CGNFy`9S[TxlΩz(_ &}<Ǚ?e)-x}oyyї6{ PPH@fJQp{q󩴬WMC}A^'yϨXKEI! bj2pw]O o,,N+IۿQ>1&FؕrR"[p,1.w.SB^V|MX:n?%~zra0W<=r_jPpYdoմ~"ǤkN©Wk ̕ 4hu)- ~ss/T1U]@d|Օl>7 1.j_ 9 C2"?i~ZxX.آ続蓧#w΄;Mok|O:} w~@C{D$+yL6ra>\~ U1S)[=D;1g{ nmEȸ|Y|wdz$ա\?6'Ha] ?x݅z% -~sJ`^laH-7iN04Ny?pe3NN4˭;5 Pqjz+Wށp–1 m)ķb\Ra(LTefqepMy >Hݗj ,-!PմXÞ7ˣI>SK4ߘك~QXp@K1$ZBted,ONXf !h9cNM^%0>}eW{m4̶AGC8{R%[J;;wx[ B}e$t_"m,\0&%-'IT(j)P3'=!4iRxqΔ_&9e胾 $Axsj؛V1mτuCs+Ip=mBeCsV7Σe(Z_y>=x]W7ph&w| 0E2n`Y-Tsp}p @|'( nwd"ʱB.=!9ѽ؉!?]iXE6BjZ 2As1' 6ɤ0YR]VQyҦHdÚ6!"X Y :UH;e CX^)Gh-%Ho+@41oF$2~_hϬ\F{Dz5uiFp`GVJ53)*tlBbtg.?] Q诮^oF(R:!zJ 5wD > qօY=6SO?/K{}+- ;tZ`2f:{kru `ioO .?OY=$ 'qxX2fJ|*ڪCS}^;K,S'#qrۗS ^,a0eR(hCuZPI""X_R)k2[ahJ+3UV㛔AғWRUq%Nԯ Ж@boz06l+H+tRK^KTQ?{vZ=mR6ayhR <߅P (\~ZֈU ֿ@=-^4 0]/KXy`(þt[.NߧJ)Ʒ) VQf: + Umu- ĚQh2z夾!3a N*Bߎ">C@cԎ$/sr|z8R(*ȼ[Υ8^'f?sy"D݋ʵҥ*> .uE$V(ڸPsr.}/}+VHt]CnaI&4U`Q s*zrļ| ^Gjy#`Ty'isɫPEŒR;ҩ~{Z!0Ŧ?".Uf1B7E8erfw{ *w5=PélmD«M0{aSDv0\VHC:ي俔r*}nkuVq\v7Х|ZmqC鵳M՚.CI Zq/בY{tZmH=/$@o0k& a%kMh3y%z5G[]7A"vEh;Mhg.w -aGh}\'~C|eD#0T;n>;(8Bݎv0|GN!lǦL/Yo4%}Z^Θ`H*nހ)_-xwp6C ?XI//` ֖*ՃxoMc2?|{$|Q)p >=ݪZ$Bқ8*5A7oG]I}Sbk7r щG ņ̠bBpFG&94Xq&ob&,%$VV~tE~Zg'~èn(2Ү-"mU:JyUY( CS̾X@6*ꃲTWCf6 Ud^+8N ]zRiROU!xo W~j/-FM`TKma-95U orHb )VV̬' =Y??Wfz{--Gc{fvM gYSsqX|8Dв堫'] !%$ lAs:y*B~1h|/;u3U&pRlWM vЌ;O0ItqZI r/42igIK]|% h\O~q8E!(X3:XnD}q[i<0Wx8j f/0wK:bndB*cBTL5Cx ƭ߼1@4ЀPܠ!8Kw,\P0JumA /< ' Z 3 AL]"!!DʹUXkJcjy-!g2֣/,]?bOvEx(qR)t2f,?M!y.F:hДVyu7{4 tDNYuZu+oK[Z}EU 6@;4>;l4?޼S|@ux o>֩DeP_%8+ Fy*c!U, P_S=q.[LՒ3'(=vpʍ/-Bml/ i~@4*7j*xXy(z >,Ks)>.DNX;,]!AwAّǂXDÿ2_}}*1ʩٽhRL."#-2Bkyy_{rʹ2z$hbԍS0af,}1A'PMqWL| s6]mmT/Oiz/h]"< l.ln9Y*9TQi;-H.bYy%'˘"qCJ#zctQy9һaq߽'rQauV΅6/fant]n@?aP3~ [6LcnP$!*=ΰ[G%7;[eK+mKս#-ۆ9`Xhq;b^ B+a3GcG`NF+钸bf-R׮kH Nש֨8P)%1_)?Q!Z"~$B55Ux> qʒl?^. ro!G3M>|mZs0!/eU:0ϳ*0I2},`d%&Ag:/i.9l8Y{_E<޾o2v:7J+~ey8-}6_ђ]$9JC˴9mSa~ z[HRB"xx;trr"Q,-ZM "ش>%kw+]"76}mHa9O$:67}|T@?dYP/n{NF0Tt Rw-sTЀz_U=R:zو,r4C~<`pNg\mybO](,i,K"(DY.1ZgGʼnO6­}JP'T0,WbWlWq* /ZΉq:~eqS^DwΔfY "n^(c(h˵*Q3tDKf3鼚΃+M=D>m!z@o2SV.toWpFIf3fijQIY C]e6 QH@̑EnT2}3NX^ dK58GGk_)AP6, m k?>8A by)t/DP1P M2܉GBSehvW{SW(JJ|qwcN7Pe=[Uo!201_nzLaSi[Kh` [aAC>:$r5E?=ñY=@ pҌ)v2mfd1ɕ6@I {e(ɯтsKn-˛WNbaN Tk4Z]'@ul_洣=T4n);* Uy;Ət}y`&Wg>ccd|T!m oHȼƏj7v8޳DFnRsKXp}57toLO\.[_yLoaqe귣*) o6<4^' =>/mkdWE'c{x!+$X3mdGd~PYgbB!5H_{S$J_Fr#vnЖjwuncКr^דVQ&䌟oV)O0LQK璨'"2!pnh9t,AO*p7Fr04 C0:_0EPfU*W,5`ڤaJ0{F^2dB4W)S;CVա? f4<x|jO?"r(εez2뇒O[g7Bhr{nVdr7f]?ɪ713ჼC# ˋoH@rĐ.ddM9@}~6 k?nˇh}hHDLͷR]XSF.X]GzbFqTrK)%ۼѽ63дJ%gi? 4 }H().3۲H5 ADZA3B9z18]Zg|~0Sý㩻ms]!큐 $r2ܘ%xk++y Į V|5*e5tc{> k jeΊ#(D701=diY|HU”PkBDMGzvt_Ft NxM~p[D˩ sل:"iSÙ4JnTq dae DO+lZfvȘ'&pUĸh^. ܯ/I?cAEߎryO=9S apYʌBae1f}syMŔUh/\z (Q5YCf^^8v4[ǼQsCm2sc^ׅH7i 8^jo'.WEDžȸ?L#Nˆ& $r \5{^6˱$xsτWto0ٻi"Ӓao!KİP~-w㎗KWњ>ߟLw!3gB! H|eW٘\Ow1fs1+UTygɩL5iM5~DOep,ROnҧmPe.E6d\LȤo-֒s|r01v+zjk"M_X31S|Vؖ+3C"ab|1e|f*5oZ*H*Mo^룖&o2-l00FSb &Ǣ]#LYqam{V0 UkkgO,ԛZ93H#ptߔ'8y֑ ğ9vjfpÛ<^B \>#HjC{.ޟBzko+kFm5> м ^-3&uР-&1- V"I٦|+Nk(vV\w>A=!Hz*2[4` uIHȌ}akCh\`&&"Gdhe7RW}*R7*pnI=*/h>je&[UdbϧAj.C(Z4K۬&.-Nq>!:;ZƑbѹ`ة\qh"hY_O?44],m*_Cj4zgU8- 2gm9Ֆe2Cq÷z_wsp@ J" 8ZEH*^iLyMiwU@ѐ9 ewI͓Nj` /%Xe_%iB8Rr:]3KI1e33NT|ۍᒖȿ(.{58ܳ˜pla0%qKw_1pTGJ <)5ΖCc$ýԃtś}%c5`Vjc.+&=YE.f6;h2pNE3,bruG υHaD0o/'RB%\P5T9ND(pB3N{S%Q l?vZ_40I\}v6ր kiaJjw ri8;vfS0 t'?ڍ(g\~>M$t޾d'ѶōZ?I2%;o[Qˬ'L9m+RDi 1A eϬ)V8PR.-x[Dܖb.eǦ0g:g'h\|%pјK@|ڂ҃B/)Ou:6릾rXf6)tk&0&kOEA<#nk;'/ Zi)?~lD߄hPk`c f'fv%3',¢ 3w-rz>! +%}%[ \Q,;/y #E)'5\S*ITG7.a^μPiUBqۏՕ1ɘwYSҏͳc,L6_>Dۮ[g"OHe~[b4 ^J;eJ"~Jᣀ$#r'8޻`H)C(d5H }őZa dǖ$畩Waף ,*M SSvT3+0'RAD 3҃%<>l?qᚢuG^+*ih\,vOP򃟽% tcQP`-*<yI;b?`6W-`OA㤋F1#9Ll-ST 56?Ϭ v֟p9Er hpOic> M5tw5ȉ3"ܻ{È:ԇ,*#: =/4p7q};j&Du? p-̉i܍yl,z%Mn&pxyjc54.rXW;cT4"%mBCڔA,F E(Qȕ7RM>`$p;ooPRio9L\iUΞ\~(zWWB]gf婯e"|X"!*˜f ~!(${.%Z zyoK~R_1I|Z!xSa^vI~鰤YefNDjaӻkV\r-37+Ku1hrY+{XFX+½=%^ne0 p*W=l"P'$hhTWv0͂G:0< &De`L/9E\lx /~]XwPЇ](6/ζ4k7XbRU^7 L0Jr0 > ,֖UNipjm0Or\s|>G!U fbKǦɳv38X02:U p]yrp':ʵd(ZygcĹduMn2jA_jV2.,n2@$8p^NNTI1D$5Y2>;|wKKAI9MDxW'A^eds~/Q˼/M9;n<ufFjQ~L+wHſAMHG\Rq a&`ZhC3^sa[Iva׆+paY]hS䚝8]'rYyBmewy*7ysWU \JŎ:'L\Dĩ>RLOqNC) Q(5WSms#x%|- 1jFLCI,tO|KHx*:?owcd'8m ݋ ȅ:pzuhzRD!! dvK {<DU'H3^x~W*ATyC $p/Kk|7DX|] YZʹ/x#+oQho͈֯ eZW6t1֊DmG0(gU# Mk ]G,x'*p!\{$ H \c1vၖ-A 5 >m lLRPna-u,Nݣ#qGҴuVVb/*r mWmNxo@J/ $"5|eˍU%#l/q6ŅT%-H׺d)I6Ŕ6<'gӃZ=6vVClF`& cֶwAY ;28~bE϶ؔqo$}`'4RM$/X]v+gyiMx2ۥJ2()>P]Gg+-DZgo#cDBBtq߆t> PL W|ҩJN\h۟y>kJz Lsc{^B#C֬@Y B}6¨d-ܖ1#̙@Pg(,FDu$+bt&3v= b/x8 8~} yF@:L7*i S6~tn y6ڷ $mx5z{h ] y|' Z.#*b~ >WT􎴮o!CG#Se&$kr~$9~{R@ciқLC"\rƝB2E8D%c"N?\V|+>+șhLu dn|1ZՀS҂m uH <y{I*,A:xY] }I5F2jpwh*_]d~ہMq{ztEw{Z/:ÖaE9MDY@2Fy x˅an }>p,o?=Fab=W}Wn1WZSž#컟P|bQ-]S'G29Vʱy.u-Xӕp+5=7 u}`1u>V8`' LO'}wf9KgM3sjg&7_;cwDMhf[i;SRyz-H`-.vyrYsѕX\Tl <"' nmN,ɽxgl݋m$>|cc6F0ZUqV-n7w+Ћ}Vfw7&Sǽ3I4CfNqJLx;DU/#R +3kcUQ>dcu'cDS9A_֯,!ϻb?d:>= [Xۙ"4 Fo9bRWϨz(wф9IXD2[8HrDia3o x.>CCGFNP-MʨIG=ea^^2>/kR8g0 %pJGh`R ȈI[j{5RQѻ6U@Q cb8y{r E2x'nS~K7dZI.䳗6]dOa,Xy8N de&a݅}1>.dw vg1;wr-:zyMNgcP/"|/bn:p-&Bx7 c&Ng_Spʙ3YLst8X i6zs PR=G&5۟Qmbo9DQ=;H#M[o Ɔ 2 [T ±xg ~[  ,^4@Z9%+ (7"K^U{>㞜ի ԥ#?,"XGccva?N\97Yǚ  hգf84m{|:Ħtg%@S5(Jq8YlNџLi] n`DŽ^MlHu?^ |6n3{ wmghNf(D :Ui\CnӇ OvMDV58ӧ?zp5'~b?4h[|D.Ʀcm*SHz#HeEMS6+?Ӆ8x8hgD꿰7o#2Y'U8+炞aJ?D܆M:^Zu:R'(OګntJxMZ- jSFg)qMRy\ MIN3+#8scoC#y$(;ݠjxj&c"Eȣ&5YZ5m#24C$/ ~l,{#1g]x WW]'.m(ٟ_;.vYTټk-M7J %/=Z#E}E۠/hޗ3ܪ;}*6>}&w0?4tLANvS%j5OQng0}X9d P7Ds^wWOEC|۷,!t0.ӫYHx7B;fC}eІcx(,DpԓcK=$*U btTċɿَEj2;›UD810枢e:^ nPc\SF魥I ^!'7g T?*Mf\Ct]Z1R~-UlIW7v+.#~Wf0`I0,BWO[- ]|֙;gm_ lnūq+O1$65ےgF}4[HJ((JQq{'*?겮ZY9JBlu5&Z BH)$uy]r5-1D|]W L@Nbhkqj @2Ri0~a4Z.DRmp'KՏּM #ے5jNtZ+(,W9Dua9߱6[0)F\f!=Kѩ(ޥ:4CC3VL pR!Bc:ߊ]T, b84Cs"?NvFir tłmUyBHsj.$l-}n:4IfI&{ p{ytYuĝ29Z3= VSMۂf7:r0LqsJ;Mj Vv g܉`Wd452 ͉ٛ`dt-Dy$չvU>lfUȑvn8OBjSV4WIf[B[9Ցk%oY1kml]uQ6ƃGpJ76XPB$h2Fi(5T7Fp㹮: `&MYo. Գz\w2ͼbdFzzm=KH5D7q5Yh{hl J!Әx!nTKW3} 8x.}*!{BmHQp§(L6 >veab\TU͕@e}!!d$RZh(5E"MHoHV*r` sD7jd>~js RwjH֛른=xԃ@e\ pl01h%tX^OͅT%%d_7psʌScN)>.Wb匈EhF)aN_/XIG|m9FE) @L$5·[O-"=]Gsvif(#6A!vu5~}Z>zs1MBz%͂U`*i S0’Cɺ[h\lZt.b2fL mOTh2tlpħOF)Lq_XK/ Hs8G!}`EzJjֳ l>Y'~v'?{ hl!G#A!%YMŽk utI6 nU—I.c, W@۸ɕ 4Ik"f [.f:L 4cؖ҃L2+%^ǛK 2JD^a3Q--U??XQwkw6ˮ2 Lte%; )BR,[(XƊD4ڴy߱w:jSYzT L|)qWm\--c="NEY]䥕 t2߱ . 鰨AJH-@}͢?H8{]' .{ͤ lM긩""*-p*C0'ڰmgf>{\abR)BQ@^~nL+86}1:%^5>pLv>=l} B^OABOoɶh*yqFB78Dk%ӡ*̇8oxBOڌW`ntnk%vW.#"Sf=u%h1PM9ged o/=hWALqq* IDqAx.U90q,JB'T!)h!D7}* LqJcncy&ljvG )OZū%1wk^v]ʅ9#" U8Vrt !W(b7$ΜpHt:Ąa_rzk|lJJ{`}/]pwlesq?ns M+ݭ>'h?iŗ}Ja5&۠yAAr"iP:ѳyɝIE)c}sVkk2{,T倞pbZ~pi"V7z۫Av=9эSG8r+80Y)͚C s:aqS S. RMJ|B%  O;4Hw )(D;ʌp ݈?H ͊eÄmo۸OZ3tp/QHn@mpvFa * AvP3 "<K%RmudtVTX1?F<=pi`SJZk{аVeַKQR # q.A^w8[G S1V_ȭ_֓WΖ⟌AN m*:gu\v]s)ȧ/D ퟁs`uC\ck;٥nAB]26PL#3|B-IQY m'GT+ȌA[l i]-ώs]NP%V;U /{hOS6/=D䊪9:a'1v%t3[VWm7?+ G`i]%젿,Ҥh>K% Gv5ݦHz^[S6Ǧl ~Tbzd`e†W'?8&/nvI\AAe EM |9_Avx=cxcq*S%i&؉t27RnWFE1YCB1mY6#Әl[C.ٕGL!4ScS 4vFYUJ=FEcw=T>#{g+v{/0HZI%k%mKIE8}giڙlGFox={ > D ,0i`5AnIFKh./JE5¯;EE ĿצbUeG>,kl-A!dH'Gbc6&SB Qt1?d6;C)k]Ƭ[IOOH* Y >w x?"tuY!|%t->621 T({Q5$UDcte+ Iv&TSpOcIɘ:\҇ Q7B,$輰hv2Bsq3 8}; zén5S|M*ykS5'yg{G™%R=Zꑫ4u^{DLH*& p d/z.`sѥ*@9- iMՖU/fa-"U'zFO;̡z_)Z$4,TO&e[U݈ropQ'_L"d7z{~jZvl&'釠;l*V@ƒVS]߅8n rt6T3%f[FMt!o1ҋ+a6 šQ&nBDd6K}7ASW˦N> S} J8T X9P*IؙyV֥eql&,.76ûS~]I֪AB۞ oCRF"rc>qOCy>GC`3Ǜ*yc#>;C0З=њ !sxYgMgZQQ  wz W#J -'uOI#)#=ݕ&,(wf[aEzVА.'n@AehXfv:J90Av}}''["<*5`kca*)trI=ILJRHp@&Bޭ\mb1FD,(PzS_Dst|lǃƓmTuI;yB0SX8Vgi$ Or-?2b6k(rex]0Y>Y*¹JHT'ї]xYرy3a36q4.0 I>^2ӏ9LJuel+:W KZP d"EV^EO;n9r~Vzocrvڨ)\Dmt-mΒ:g"$8>jo0| 蟝 AbON5ILŷV̾*o|POS#n[&ł>;EWHr%M,5RN;wx_ЎD[˵3DQ+[Yyغᵣ JJ+-npN imHîzJd'Q 8ؾSc1Ba*vd #U, nߛf M!Mf>cx7;rjxQPrTxS"<n2qiAeB;2DM+5?A"4k8impHC5`@]"Mdf]@<,+VQ1^E1ea(`)L.U!lr2BYԧL3]zѡfXJǡ> ?s?B0!ː J܆X#[H9uh$ovV&"rb^ q+&GYt +U$LO.C)o|bn08-L:̫uD+Z:[[kv !`>fNdAYkdh`0ي.}(f s=bVA!. hkЭsK}Qc"oQA+\<$vүR|dرÅc 6'~Wo4s+fɝmdo; 0)6e-Jo& p+"e31}BH ]H^)u<"qb/ H/1r>x̗7ot[^ +R^, z*^oǎg;oj  dc7|kJ\)$!={`Oۛ@#g%ӁvҤed1 | ü 5sP4?>[(9Gs@"{qm2+/L2']!IT,i"a6!{Nuo@ns#Vga^Phc;+tʌW%[Z_o9mfV>Y<-4&Rb뾙~2`HŶVջoyK0+ m s҇CǷ6Ia}-0,@*6Ǔ*߸c$c[jxq1+lpubq'J®05ldY$ >t35yC>4f\UK9WIf`OA[8G<ҙ5+L& #5Jf77(2#@<]~(Kd<()#LqN68JmL@1Kٌ(rF^AqSxf?]+1e+ebK}rf>}n E;(LNyɺgnw1U߾2MA oKS4黎 P"28+4®v("rȊr`?'S /7) r8%bєSWaX/d:Ʈ!jf5wȷ k%%vx.I8V|M |_ߵ=P}cwgDI?kmY *Ls;5Rjc{]ܣF؋kuz8y ">ܡʙH %V (s&1( m7ᓯNKsk.BI"@]zn>"kyR}n {ivBuWu"T_6;cLAMŹW*_>DG t0~#-G:dRM?)kS{~Ǜ^+`ZMtsv>rb Ѫ|ΞP[ 5C?⺾3GSL1uPzCjJ ,/N熁@h+_ *گu2]"M i|05?J1WRUb)5Duh8OH7COV u'*4H9Ɏ{ʨrrg?YԎE ]\Gfc^ sr2KQFN^Ika@V[}C;,&+15yܐS9<{϶&5i^ա{nX:? kum|=p's/!iuN8J%ՑRZze2kMł, o W@f?@4bp6殚 V`Pg*֞* M؜#M 5 nDY"+m-!k\"/JfPlsãVJ$be O XMmWeOy:Y- 1[IN]j8q)Zܬnq~q}9fV|lT+))*8?UZWBn~qYoEB7AWQ*Cp~IeV@, 1dNRU8]TjyՃ?uƂms95{ߙh| cٯitRGzh|{gΦkB/I4fC/ {T |R{5g|$戺WhM4b+Bv0mL : 7|$7D vXAfdGZ잮.xVWIqJYL4{^b͔U80Cm1W㩟I^vZ3>n`vɬ$I? ^c gr&Bsl'g2yLRQ#,!r L&Z}Ahʈ%@"H|2jWY._9VA  3\' ת{.rhSȶoBSoޓMu;>g=t*Xm*/]IGچK̵zsgxsEG D7Y-h2σ2EˏY.%^ iue:{Cc¦(ۅ/e1+MQ#uL\p(ƜRr_4Uٱ@{yYv2l0llER'd(+._J/z J΢9۲( lRΈ7FќP usdCG?50,b쬠=<;/$Sݭo=DĵVoU~gp {X~93G97Qv| jQ\&n^9#VuLfhBvYh8s)N}=.H)8 /~U[TLIӺ'ΎSO RMAm 1*]DuN{h딼TX]vܚ[)4@ ^ ,b5njD>H`YLxYVPtpJ>0L@;(H@]"0$ӧl)EmеS8sQqm3êfywxvi`*4Q^AWzgbi]7Q], 'iҢ0ǀޤ1g^<i^S߁HLDGw񲬰~ V;O6fS-@.g/'Swuzh_sV9_,҈WC~-BLj-Ԏ~kjOt5Mm3XL*ğ@>!$kKDIGka4L>lPF5 [_+9[3q{3 w@LwH-EsܥiƬ3R 9jT"֞/*N{-rs yIQc4-9@!z]$IHqzpK*ck#环9qؾ.vYk^.h[]O4zbA|a FdC"n,p q|AufkVR#j.ոf12t ¡ҏ=~S Me䘝Bw)r5:[JrdB k-ȣƑ I?T.ɟGx7'd8( rOl;$f_/+}QbJ}Rē\쮧gg.~H/ZgԙDW"'OHmCVhugԸƯ'"T 4H0\}z*K)qfm$(̤P$ ְ2ܣ?*6x{~;>^Sݯ0l_IA*p%`)/<'ajCYٺ] $ AJ_T+I#bG-h ӧ@#Z+mPKmOYcYK%'qͿrFkQO8p5dI4O y쮎h%d䒿v#@u_1uFys$k6,&ߑZl΍gL# Rlآ^FU\NXdo䛼$fpV[]Tps DfME7HDLI(+t䩞!f-ŴWVvvV.E,e ΍˸EJ+΀ks5Eֻ$9s̳I8ZKE?L s}|b;&W!]jxk!U{F f1a֍e84rv" Z,&le#K4)1% 6<Ō8'_( b#36rlqd R9u ~Q0n5nfK1$aʳ;mg#Jr.@\ \+>Ae[[mrS.#ߐΩHcS]CEK.ͩ&PⰂih -)Җ-iSO!6aPݣ-H~,%D/H? èJoѱ@)@tøękRWAmV1#k+?:2MlP%џj"n^K.=a 滁b@SŮۃ|lCw!*u_Cy8kq |%A9"y!P8`Dã,W3." N1u$**  &HJ_>OW}7hC!/) XÇ9)2R۶zBǴS@Y\G`jl"; m 뿨1H0al1*E#ZƓ85(SS9$>L&>QT׌\Rz0ʼnՠ{wCfu C~,[ nml-+rKI8}d˄tkk̔ !bJ;yc&-j̆Yi;oNԸ~asu%BZl62E){1HC:6Բڥ?n \K˚D-*HU PG:=6*gf2"&R"rO$qJD5MZsk5w݀4) ٕ{EVkBް1b1Ed7j&N`n=ptЩ~Y,D!~iJ_C@fl׎gRNE<$v˛b<G]G >Q4 )L|v쐘I1{GtR>_>,Mǝsd {LCNRB82ܐJ`d""oGC#Yj*'DyK@C}3rjNfrJ,!Kp0{O^`Y.R,"*-ȳ<ςlX lQH{[ ,UOBEQ٪AFT-#;ؕmq9V>acb3_Wk] O**Dm&_'. )#8<yhD@iQ&ET@%a:${UCJR*(:FhlHw]U똑y٨ }ԢV`Mp1~' m&_$|%ӔYZbυ qD؍c; 䧟{oT%δBY=hm63|I’o-/QIN1 hB]X!]()I.o D;;iJDQ١F>^2hGQ nĉ>3IZ"vYvm} ;)1QCo-VH23,J۔fh:@'T"pmB6,{Y_@WrlIFtOd]KK"OHCKz#U,zaS  /k`蠂'6S&BZvQi.@;0P}1%q5ףBwcLv][(ڢ:[ߡ[63^"| WDaH^F6pmԯօ4{|_;o4vWa6(9Ҩm\:(n4,c wҳ2!Urg+:Y58Mt?>0µEk '/ +Rx@g~] PIJw>!+cF8dS9V` kqDt9H 묑LA~ԜJ) ~6 zPBWx?X | k@(6殽EjuSB;cx?S-A;Io!*-Q^8ZFr=ΒcX"GEpɛN[:%)3ez]/>łoi=5 iQπ<*JTOi.}^~eNsw)_i4q{3{U{O+5&?=r92.M|#VIc;|9i8Bd$Ǯox}hgܪ6_vhpB.rPp`[[ulU8ö.Rqj8|07VAԴ[t@C s&WTFBr> ߢ46M v[֯q^p2PY?#{^1PC9DyT Bz2Gy&ؖyz-T"\Xj@[{ k `F6# ,+m'`94N8 iGQ8>*gz/vx(K>] tE\f\9G͞>)}2`,Y`!\!q%EۧJ/֛dqAG>Hi:;}²=l(}#o늞q1@ڣ18 ג"RgKN%̬'[TӻF3ͤ֙g|3ggǥN[Me:30Sݓ#~<8"KJWκ 2;6գ!^0$}"ˀ\Hœ SZ̡pf,D(#u%sFס(]&C =9@] @pF΍0 N=~pvCu li6NV쯈_\ִ qC5yH}2^sbg1Om%0˶LHhݢ9H8 RA`|! \jWܣp9*T eW;BĄ]?_*!0^qn]¤/}2u}L~sKXvRni;]H1>9w8u& Zs;|N!LD؇2Pr^s&k(ԁ[8vdw5YӃh4yߔ1#?vM`# p[Iꤟw(:0pԳ5iʶӀق*}g N8X6C-vwv9zA^{(QF1YxuږgkwLt%Y-m Dxԩ]SI$L[ڬ,a[R<-vjro|8{#Y S'`ǗU!Dv 9Ĩ|l };Av diCH=S:LCaCy @(r– o7OGG&ID_6-=7ѷ\bkNTpX%j,7DiH9޷Qu59^,{kt  Ճ, "OJK`ޫ6*FQo=a(H-?^ |R Sbg|oxj(Li%E/ fhn߱D7I~bbM5b ڤb(w,w[(HoXK5%݀<#o#(*3l-C#hs ՞*[bG;z([As*԰9pK,5#@-*GvV]b#^uU"zаiX[%XGҐPr.enOȾ*bkce '?&VXKkj6@#sm4{fzZ㟵Im`+2sNTx Q/${/M$8WN˕ =W,1n^2vPREU G PڏD r圚4ߡ^Oy۰];a#X:ŔwƤҿiHltk@s^@VF^ᓊMq G)郾Q9G%i^j=7si\Kު#$H?{/4R&Љh;`O?Jrjn#V [Q Flgx,Ds&'aAvXބ~AJ D!(Qk.TW3cΠGkf_ |k6i; MLaHP,tAqO4 Vv^qY㭑 =*8IKTjܬMx RFc=ȍwl˝Ilek=~l<aIOpaejE8ـ͝Kҷnjwo,,Q}R;w(/΀xWx :y'_p| ER@ݣ!V!J`O;glfVbGKm]F ,6gCkAcl~$es˝uR;'ƣf)!fT'%pݤD]iP(VMI7䕝LCLG$a:P,٫"s^|FWI~b=Zoȇu]!7DKł+ԍܥB;#@";KOhV9E x 4{^Op~1/e Efemyu /E= "Fv61)1b7AQv]">ϧ}-*+Guw;5DIJeD.rП/|m̛ =g7o;g?A0Pc"U0ps4l'5o$1N|D(H^+1Og/A,x¢^Pa?7@@atV8?\}qˌ xI<;w8ꮕGfYɰ#r3&)ĀXT9lm <-W,kE,I{)b}N5o8j6YH0MWoD$pfW<,S8 oTLCG},?lw+"A1^İ`,u"ܠ=U#7.' G𑆒ʐ$tZ:־hfhVpiQK)2=3!VcooYՄoJIȼvwJ;f04j@;~ǨCw^N1 etĸ*O?ĠjWGn&GDu8|uWC{f~.0bn!S69<K]))TKꤰ V_G;L$2)u)J&2CQ {,#KA]*OYϮAY鹡z}edyl8ֹ#_7tNov(|Eі̴㽾t [3lulddh<઺Su[@0 ڨtW P6|s❒Pf)Mwr:  xvhɝQQn `oθ< }?Of.9XoK rZHA(M_{M$xTܾigumvZqJ&shw.PEs */̔F>? 쟏ɝ/0 }Olmޅ=|ߘC}]2<7<|[8 z$t5oDfcDJi3\-^VoՆ. C4C˭ D^6BCekq:X %f3XD''glR?%Ɂt~Ri26NO'ks Wt^\ۼ'=nA(d+zIXh8} J[{UwwAK\ 9s ]5#I7T}y0ʧ'Fcrώ(dȦU7*wOc,t78mn9+8d(PuRmh-IG2Pk̅~\,H `uf+0|ؤT,&ȩ+ ~h}sIymLR n8GDAI^2v^0ȀZWIeZPZGDB#0C[2yIi (O-ZyyFA6&hMnO)GjFE Jju(fm\5}!3mZg5KfPU,MXP9?lC>\ lrh%@i!) _`%ot͇NV{/J'5zBK© qG$HS1}k(뿋JcLvuaHMKvEΟu=Rtr~Fw([+]v\-̜Mpqq/`ŝ?bwX//[ !y"=A4%C !NJm_spQɇ5+ӛ؉{O?sL7PM.gp0|UAcT(8D Hf+ʮ~xΘKjf"eY2eGZ`\A>CqADVKO+<K3m|}FmigDO sd͹{c+3S0)(Uz9INO)a|:%ny6V?^}`GƋĴw[_SRf.1{Vg4A[6<H6"jbza!TV(Sഴ"&.)(.Z\UQ syV~ A&ZPZ?͆x\_Sgnb+tߩ } NQDҺ~oj&3lS&?PSekl- bzmCN7 E]WB48g.ɥs3@MT[;bhT'U$J@R$>Nj4[YU2 !_E?R5Q7%ԅ>H$lVm EX?gMJRd\/ނ"Sx'݋$7F猂zz^I'ABm7va&(hCU޷CbZo!z!)os)'J C[qxTO()yz$'gems]]}< EU6'fQeFmWΐ"@F_砧FynN з:, j;= c8{s@._cK8`^zWf9dp#,ZۥԋZTdoJx ^0; SdMկW||Nm# UThN&24 im(vסi]m,baбU'| Ѥ sDTH2w_?lP[^$Ulo#I(П{"r<U|-sD d%`2_2[$M@fnuYYCh"(T >0oz1oi޵un]&C0O^OHDLV|=Jr1yHi$LBw6VFB_E!Kv|md"? ?5w?,YD\TJz1BL~ͤBl"[;7gUQ/#|hG9pnD]C+D+fQh+!8pMȡ;^5l~g0R  9xPEZTwIVl\݂%= @OfNT?G<ߵ!>!MqC6 G|k %j%aURyng4Rw -]ZY[zQVۉsM_QUiC Te$ um[ԕKNL|Md#v:' vG :' 7^@cшP[]F4A7l:R?A!0D1um-s(]AH\V gY]hᭊLF*1]reX1^BY! -$OڡV^ A3"p-o +,DoY>"J8eV?GIQV;R5EٙLxSK+9P&N<؛R0cv0 QUiRzn^[]Z1AhXp< [w 5wy{cPA=g!ƒP * cE)N F^' ނ(yZH(1TDU[>[hҾ ~#.}mel3Ԯ-M\)>Yki{dř@mzekX KGWL&-~7is@_bRg"s)F< 4/4ȱ`"DSFk͆O25~]X7N@D{+|ʏ˄hgQX1ܴSJ!iVM%zU/hٻj ރad}K+>0 dawWw;We{S:/-[Z񘼵ؼv/6pZM&+Xݎe+;p,4.+bFW(VoLsK`XrC}.!E9Q#ix5u)έRmr%e 0[͓V4-UUn(С&Y7At#G/J? 食i%>꺐0o"䟂zit[@Jȶh Ҟ]/jags,%4:WŁSŨW i9k]gOw˛D&k)[lZ `XN)vhbK\v:A(/8PQ`?[CSK違.]T~Uy6%i zwhAO/s_M5k98мo[t5(蜫_Kr[/ēig8џ@B^Sk+UU$z?Ŀŗ_#VӶ8)B(? Wɤ[nӊb1yx"9Jm|UM٫3uK1U-Omc/孟H~&Ac-E;>S=-i{QVB"gk 04Ko\ ;ߨ7ZVqʔX:tA>KFkJ?X%H5{@vtԒK 8Et@e y`$.)~VI0QsxY2:7什@H)h[85!UK0'T4vi[ʆ,oQ}ׄC1b\%&đ&ouQy2AF+B=_|hZFOcM 8?lÆww )mJc7B6 UZ{7x>ƇAUNxf (,Z)K0 }pYYPֺ9Xg‡rbn&<9"D0{刮M[#'#[dRnw"kg񷊢3N# \O1>;fQ..}]5Ic eQʯ;FyywCY׫E3y,| RsEiwdžu,jNxqc {vgJ 4gPakdIeݵ|8S,tnd 'Ts#۾:'JVl^tN˩I9M6B@j_sx(Y`5Q% )W77Rq'- 3zV;C*xzr ё|:LBY>q%}R. V|dQR9B=v꺙V"fDŽdS:EbǶLOمa&Y}MBUcvؠQ ŝp nmiPM0bzC UdQ';ŏXTM,@ɿG=Kin]tu (^sRfzuyr t(ZcP)dȮ[K$[}0Cx'"L֬J+a'{,E/ϑYxyBbYBg|TqR0ܼRnUVC3Tƺ#uv.#Phj&l3 @7v&b}wbPE x˻Ԋ[AX#3GM)?v:,13//tuz=Q3nߜ$t ^%+8Rn}v"<:s#TMxtNGadb{QKpn:$)9f&4I$'MrkԮ`]܈|u+t B~ rϳMIB3IuMM~\{/id; C?hq)ZrPCi3tna\V?x}xFc LS z uyЧέ2a$+.eOhМwˇʂwDB ^{RW5 IZ `\3NGT mx,VlcIBڔX{^-w Iw6ˌiD.ifd-&e i">p("8UnTqgZ#,hou!Zs\1*EI7ZڼG.xУ#5F`x]!J[ O8 V"c$VU\=}gB#|ͥxP#_N%zJuͲꝺ6i$.́y7 A’66ߕt(K b%Hn~/lCP}'>eKu) zRcőnɳ7۳Px3ܑ򁭹شc6RGj\hޅ^pF`]Ƕsm7smj0$SzG{Xzݖn dw9@ R:hɜ!;ރ na6nSx;MDBjyKdQ6 N-`ӿ:;]ӗ;WqJr$pv3 ld ,g_?Ƴ1=Y=,f$9tծRBu[)Jl3)ӹY-XKGR}@JVSeK1r_; ); GhLѽg$SbrG=f3+fDHEuSTn&g44+z{6dl謻'G*t+s5AȪw띒x@\J^zEX$2A T bNZ㇝O(;g ro[FquFh rA|T@=\}r kj]8yH:B=߅YY{P:% "3z1f XA{W{נp@-[9{>᫭9z/ %/J+V7"jG@E9w^F^pNAglel{nh;%v?Ⱦk8fW~nSPzo0>9>4ꯌލ.U5R"Wm'0,bcHrJ#.JY&z 5K쇣a܏VL0к؜&:ۭee n4 KCZ ;JO ~X ;8ܒQtL;_].wj]OvEX#H.Ea}Gu‹CϠukʟ{+‹>Z5C5X'3l06B协&#Pt)3[en6Juc-s엱R%O6S]>cÊLj (wPA`` xya Tx:zfT!Xhꫭ{sVTgke/+.O!x#]B6C.8z'P#i`זbץ*{qzH`:gO@v$j 'w;uH)f:mksk,3pq).=͡R \AY {Pd,t+j#N$ROꔱq*U'NݎÏ@3̓'|e$5M<Kc"tznxlf]P<SEvo`LLdv Mg+K}Q]~ 08(?hP:ay6}ťqO%nDCta\#'>aM!y%lZ׻ؚ b=$56gҫAʡ@bJK1{`ɪmJVS:I0^|8F@l!+[ 'Oܤ>#}Xjk¶̶ŝ87"¤gqQj^MB):/"v;e~wqjȞpr|p6lg1VZVS2aF%k٧S 8s܌yi|uR(7S672lZ^"5P;Bd0>)mĮBGKrEŵ؊N7ZTMOΚӖu.K'ZI;ga Ts5ԡ,^7Kg^zQ>wҤH:#1AYuWa 絫LuSHhmQ Ŭb6jӞ*!Wzv[]}J rV*f)5(:!_NUj H) [ˆsڥ2{pM(#kT6lZ^sN $Mw=YSzZh%訙C[3jO8JvHa5`DCC6?#,n2\zu$jv`H!VI`K>ۋ'˽Xf%g)Hbw帰oyf0b/dpדJz?TٸĵZ工iAӡY B>f mj̄CLEF'Jd)_z|}؛`8󠄓}m]6Z5l2qs}sKR%k`uzI G+ѷU)͉;w.\w}zq `rve۠42]V!4kgKw;J.6[))ooqn\SdD1͝I 0׆hhvҲtfGBv WI̫0C.T2IѢJ@m$"~_MRHS ><<%o F?LX\OI)^fZ޹|6}]]jF,h-ՠzd&*]s|7.KZP'⁀:"g6I5e \wL|+ի>NT[VmIE`7TZ/@pP&a^|Iݤ=8IU69 ux~6qUɅ "ZbA!}7+{0v8|Pr/eaexMwWա$H0TGq0MdYL; Y׏JHJ>nqΔ4S{ i=Eѭ=v.+vx\NtFjv2F篰.H0k\~1½D`CY1; 7!V) Rz#W Iz"Qhfm:jl)Gi8"rpx{):e 渓%b蹁z"\7jʣ Uy\A39j>j:w"0&шqUE#!OY<* j]0}V[+BGΗz9'2=k#xNXkڦq=^7 uvk@WBsbFNؖ t԰!~U[-+cc;-oɇѥ 1QnEUkˋ:u+>sX4ij&TApY iģd-.XN,Yօ'0+]=q͡^ lY9)fhʢ )ho͙X7z`N2(xj !x0StBi1e)_:~ݟ %~|`a !hUH e$?[?3  vr,7q| )ftK$\|.Z W6&=ǧumwꢫ ]Q*M$GKJhP*’Z˜Xq:>ӊWXo]0^'4wͫ= yU)ֹ#VgէL:UĺN\WBeȮn`p2{Z{(lK?D 5jUln?hW-oOJD7XBzyuJu j&+=}9^(ڨ/ZO"JE~E>t7%ۼДbU4g"ӕeR02r` r1mtG߼(j6Aِ_͇RkHW]V2K[ydX:-sľΈZ!Tlx_{fq#%@_ԕa9ZU&9a>ǥ dB╂V`^ıM8$C'X X7!VdO ,px bsmcGL B,_T3lovX嚨LPm|X -Z[BƲW%׀fj S잲VzJjWI#RR_9ɑ eDjY ŀJ3]> ¦ 5e42X=6s7Ye'ߩ3+t͋b{I]'e;NC ,Vs~QXj$8衭_ǃЭӰ-+0GeCj©B9P!R bVS>%+=/$/}{_bPUj -v"o ci"MosJѪl(X5_ Az۔:˃Cm!dROR2fDqگ)V+ÕS EKrns2{2= 9Kl~[#wvՌG79kd8(Klվ.B0äEB؎PKː<շ*7fKgj;L\Q+';Kѕ R0wQ=/{#v9O?\щC]П?퐚|>3_9.^IɹXIC\0 Kf1&ǫ,HrPF~*(3t \7zYA:AV⿺º EkB X7X۰8X6 iNu2)ͧx?`6imLH"v#vT%Xe\Q\df e>Ÿpשq j0( -z4?%{ܛ#kYi"(۽ȺI'<^ޮ,&hCefrvr86BFVU_F"bˤH39FN$;PY5@U-N&)+mFi^"Rl5mL`O̅ ֿ\yW :.B P ל0q$R'4zC(j U@іEmT=fRgUIb8X9ܻ@0jj魻g5PA9!DB-4.1`%x'#ȗeA5Iօ[A+~~>X4@W5pךrd" e,n\Vrtt7z:puv#t`Yu ,rt՚˱vXly+ʢҘz$@Xi; `6GlVu[xKǃRqnr٨|>X^R!m?qĆqYc =38&R6W/6rRvQ'uW0,60KjC98!+J RlJ;;serqJ+C*& !RcsYJq#wҜA'"/9N؟>0R\mo`ئ@[2 &T-}"m%C sj*{RPPȱ(B s5X‰W0mL_ `+xwbllɣq ʜI6K _*|o-ctK|hTq^MG?"WvU$CZ;*7?k59 A?P Vs)ycd.':%2a9Hù0ԿBW;_ Bʈ-o7VW`Ft0LV~n8OJ gqsqrN! !I#> 6Rn1&x=#I8~jߡNdvh͌0d=S#C? L^vKe[7;r+: %=}MOqFH9I3V_Sf .VӐ(aeCČZRzͅޫm<).l<>(F;xqm͌f2FVJmPqJ&uBEu.莫PԔ^s"ʚ'e6Q؉PX~ IQVP# ¬`1Y씾=* ^n Pedl\?Hɭ;5\/9y@d=ab6U{*5DS E=M0t?hSn go?sCw#}k1՝M8{PC2mzL \eQ`J&N۲ڍ RJ^$E9]fR\2m?ᘗ@"Vߗ| aDYd.5L7޻c~r 0kq|1:3=M.nAz7wg'Z`i߂)PhvWמ2vgd Fk]~``]u#F?)<[ήԊ7sW뿰0^uKђs| RzmȮRgP;m-ZcnjJ%\'W2pUiF [2H9F ]Rhc6_ƕzpֱ\$B"|5IdP!W:іipC۞5 qn RI&9Xka PŏWMڛǬ/-gB 2ݳ@^]GKrʘ4p)n/Mõ䬳̵22%i_q0ڇ=|$%ik e7I,2>T^ȩ},ˉ1z 9Dn|Q 095I7-e]Dה~ܥ7"0ME^ si>N Y%i`""њ3e AH GAIѬ1=3 NڴL *N #!k;\6]8Q\ʯA"O@TLD/6cMSWԹr8=WE: ݱȍkCg>)$LgqG-t gn%@dg9IPO5 xiXD9/.R 4-MRH_%rݳ' ]chɬ_Ǫq4`Yh֨V詿Ʒ63N5`DלMv!#XiΦzL{v? a5!8U"$P>{]B4c;jL2&߄ aEXk]A 3~ עWMQ㡌c& cglagH0o=Ҿd,1k]Jq4Ьye6Vu|ieb Q0%Kd{@a[}pe}w5]7M4M]I`ɐG qVc;oT5$ِH͞+9YZX'\e۰%Dby%GN^48c@=al2= kD߂W#?T=\kb84S.LZ}Mo}iV8?ؽYc vb$A`DR;-%c? D%'*L[E7zلKD$,A#dlLOժI޹U2 es?SP8d[-d[.ka|xAC!}bet)KWA$6^OEZ +(osڏtvˊ55A;-rl=LI ++6?2%vCJ^><2B> jvhSծTK@Eysn<}(Um\!y+"hzq݂IJƻ,4Jt,AcdO7z*8 Uy[K#:K!:kmCöcx8nY~c]nJ",LxN+%o du 7T5 "q?qkЉS7+ >>m_ZS2=|UnWxU79 ~ f_CnȹtIC9uVrv;w"F8 OöJMP28`('xդU5iwh[Z f@4MrwPbZcM0TIַIAX~0Ĭ"Ck#d_fB̹GmΧ /!(:'Tmǿ4Gп90+\s.;k7݉Ϝ0RWN@Q%YqԽM9u1%'L6կ1ca\i$x)q˦\)9 Weċ j( {Jlh5֮DqZ:!SrSn,kZk+#b }$qUj@ dX˩2. ~x' ̝ÈjMkS(gBh^EuJ7D?| AȡVgnʖ~iaN __b 0a!V`0Ŗ۩-/ dR,WD%x-'؊4ZQr3YV}4D piJV"+/B6aѝ8-CJUVī~\6bH /b=Sfy{U{r?_u3= FHC}|}GuE1hHw9aF"DfG\}L,"o;dpEf|e~EfS]iCh>,IԿ /ʶ/#>LfKDTbK'VX6n2 HۙVeO:~_r.Ãtev$?ơaAc>QIqv}mRw<1)[YR셝>u؝I4uP+;O_ L&Ȑ*F͎:3C'n%r=$]~,}𚖱Yus)Ž tPX.#eZ':kקdc#^t"zі2a|t+ [ ]6ܞBVXv  l|nxi> ܪ0'i! ߟ|g/D(u@jEo ja+-ayg}_jljdb@-l=p@ CDŽN| _.C9ri@QdpxkE{k9 Kp Ѳ/VTtD>Txcᑁa'h+L|v{ʐoh<7B2n7 u@Mt0nioݚa57_7]B<?킣 {g0w1&zA`.hķ߫12Q4/q)B{`^+[9TJȕ)Qs Gw?4^ǤW2Tj^G^mL؅owknx |' C(؅)N^WaSmLXO?U׍IeNzV$]ֱ;Hc|R-hQ9JoNT_9({ ćôuK.@~j?#$U(T ٜ|5%_%_v?;k ⍝E\oq5< MszIB * D]U&W,>txqji,80=i~,u2?@^1'N7یkE8J۰K*)QJ."1ߌtt~zjzdOKyEß6çuf7f_W6v|8v7DJѳ֩z`EUKz9*OGi]C=Z4Bs#WPp܊#K'a-ws) ժH$FT/{߉*cw8:t锒̽/3`Jpq7]Pqh ~V80MdK?֘!HEP|SOuG|FUh;7z̐ C4UߚDeqٯV߄cb_}+n-Cyb:86?N>MZSմ4^_ Hq;3VL7뱀7dRy\Y$@[bGqQã%֔3JBcSl w^K7_8d\[Y .)Өfv84a4;c8Fl㈃^7]{#Aׯ<ˣmi͘#\xKgRE_8I|^M0~)JRoɛ Pt@u"ܺ?ut6䪨2oFכV@HEZpnS'擥;VTǤk̀U,PWw$ 1@qP2Ě aKmGZ"66 ٻze;"6| ot :?vlm>Ļ&Dڗ(֭ _=`13} [Y6K^DW]>7#4Гٴ/$Cᜃeb(t^jn`4keUُYaݟɤp/1x8}J}rƭR)NEYdoRAnc)~W.bzZ600[ : 3MsN*#L @$eU5>3+4a$aw)U=g>&NlPE>t7_G鷎o(XEo-2)4|[5me8X6c=[jҒ E'n"_a7*r"<b)V./&YR c|Z[+ X` *2 (ŀs-@J(hu#g# `ҍcy,"b_0xA9ژ-΋ZE_'җɲvRS@1 =fB6a@F#ߜ %ܽƒ_il F/SojD~S']3xFnZc 34nr^Eks4Wk%xRFq&V$Ppc+Pv|uyXd)W B%,m '/"?De9; }^ 왙*;X3S/pK'X~VDTı l?㋯f{J0(LN4שSHS'%ޫ'C!!Ǿ "O]f){ۀ셸o#B;^G\&87GWr2X $G{Ry-^"-ѻEDg::t]6:*m/ynjL l;n+S3$]8젽xT OXQ;jS9ve&%FJ?bGPPˉ5B"F/%iSfh@ܩxhE+RgrϱUZ7ji d9Bxy'Kpe_ǿQs?i*wFC+#r qxcɞ5_:͗iibd R ۱h3!Unc"U1Hi`("[jɰX15!W2ϛ.um)nxR1{5zл9=SP]L.Oi3)"Y PB_Xۇ‹x_}$1*}5(,^N- om @7?ԤE6Oyj g$% kccD7HWǸ1Cyy]Tu(U{@ W 9 b4eJ)2|wCZpw3w>,]TM2@ eK4v\&a\`44T1;\.j'sZdĕBVZ 2 [b6󌬙1ic~:bo4N OYʆ"jCڡGcCLwj9T+YA\/l % G)^h5{]FD?DQTrw}l"~618˦ؙW5MW)7qY\IJ ӱ-|W'XoC5߸ PЊO|H4M:Iٯaj=k` A{zoT sIJ'S({J>ʀ:̍A2 sqV!p<%weD@|b*աgiͲwy9}KD0, ;{!xSBPr~%ݫSV2 ߘ^~md"pOKrH%VJ B -]r\3+T$1іFc N/FG~Q2ކÛWxI*X =%7UF>A6^NV Eʧ*~97k;kK0ȸ􈋺;[VOpfF{[d}q+V)%Cẘ`HwC~&Yˉ-}Ph}=DvQcf!Wj9Of4oulÛkt(M)GHRh+A##Naq%ERjg2z?Ņ-Ϧg7fxO!ۺ;YP}' ,E$'@+:=ky܏uă;|;Z i){ؔ^p8!j)fy$O3?ٓVLJE5>_3jTYS*gȹ mPk S?U)IE$s1>M Xx&Zڔ-@ Z />Hhb1@s߹1^4%c1͍[™Q6kN[CsY|P#QU[x,Uҍ]0jL?`^׷.?-2V{!Vz6E ɳ>ձ3;#V[2A N`HLXM{sWOƩe-$A> T͉>l2'W?lyG6ڂOfw]- 05W3;Y^ Lqf'm DoJ빔[f[4aljrJ<)/ُ0,PZOAFg.gRPlJLK\QPqf 0457G-U@ $9ˆ$]."uSRh@`Zpb}_Ur{'%('4MEڮa]b"n?2@=aFʟ gq/J6jrggJQ.eF/6xE#c" DWO%k1GHKQȺAMIBw&?H*hSO p۶jm$auK߄;d]~{4Vo? B&K4^ pFytks>&3b'Ə`\ue \l0(QIM ̪fq@"I^' ONQ0AmFvQĪ :FSaNTNLkCK.Q")#Gדy/c"5/K+#s-uc~L8l{I<ZI9)Z dʺS`*M+ h(>|Y>Chc쳵">7)hn'{uQKr\C Ofs`0J;nAN$׋0-{Lۇq7'tGRsǟM8,chA  P/\ԙ3 ˔'8̮\ZOF1ki|B1> 0s׳ Vd<{`{y 4[vhJkO^ӽ3}kW( e R'%Mf1 5Mh*1?[(#ƤK0MA@]C?p w|jjy{U`O4;8R T}JFI5+y}(b-I_atqŦ,>)w ݛiI1ݒT 3Js5;TPor0&F^+ X[oZFr)>e+dΒ7/yM왙ފz)QQso{*8.*獆Eff$G͆+~ɝ5MIXкHJ楶uҔ˻7 ʹAzm drتbT,׍>Qk9゗UWHn m I7u4d-a%1n"eGu_dܿaw]Se Hѧ\,FQ .k6*&[sb~t7˧F\:4;튏i2FYçg_.EҬv1Ze;9?||M߫ub> &c?-`6&ն*DUVfoMxYwSѩ@,i\*v;5N+0?^뵜qsl M{MozK=hn)Kي1f`u %qs8U~ IЙY2}Rw@qNYs@qrmHk?a6nڌ>80F߳}a$llK)rf|sjQ?7EeyHޠ:bj'SmrAݩ+ҙRtt4"wl,H0hokA/4PB Ż=pJ)1Hu_%'v:p$ k6Yi؆_h b)c!ۚ'~Hn!m7oW\]6Zכ^W8tH!e7BUfe/fV5BLo|{K`iÕG$9 YcN!.fpۤQT@ucR,*d^ wΩ9 WAm5)#RpW` GgK˺5r#Ns71߁PKFӊ;//!ǼV0;H_7m:y'zT$ۓUW(k)־^ۆӘEMmm)w#+2U(;ZkM:֯VmRv?xV`A$HtNZ{Ch`uEiK^DyG!zȪ2xrc=Vo;JbNteBNa0ܐf(TEo+PmBa͊0կ]gvu>wtkʭ"]*J ry" -:;OtK&W<,6*iDk]>qS(<n(^yAO !E~ CXPaÇ~[^NAjrH8U*Oqƪ >>f K8 %MgD55kNVID14'YTNi}n Vo^ixBWqBns ?^OPWrߴ$}ۼ䑇 I^ dFf3+h(){Ŗ?ڷ_Rd6.@ñSj׋Vϥj>糘{[K!ݸ}N/;J6F+$H[tWa>?H}1h"(/DJ(:W /6'#إP}egGM.dREy{cagqq)OV CaEFJH/vźq,>Y`U#٫uA$E*kK7YV7V†bphHp[CMmD#s>:]_>vUg=d/H꼶6.J[D\̹2⚩ﻍ~([j`ɍqs)s48BxYH ";5iΓ*2Q|B{_$.kgFoJ-Z#v+uRP$* >0,1$u*˭#&6лTjاnPYDa0ܬF ġ-?P$o(&$Sx4 垢#1jHZIL;XBa֪Јyv6 _M kS+(1R1脰xW2sdn {tȀ#Nz N3!07͆\KG(X0&N*XfOq"cM9>`{x8m Z@ `J'n+A<-5s&}5MDF)0YjyHm]ooա?M2<8\D-rudl}9韵"(͘Ia.E!ʽpذ#$19};gSBZKڬ*G3W\ 5(>d,nj E观jC/>{rM}Mݧr-rO 7BRYo*g`jzc;z:1DkX.$90ٹ%ǥbBzyZG}48fn9@ \85LϪioK4و$ ɯQn /(m@Bfz`"Ib;R>OSb*`AdV.Ě$IG/ އx-.ǻ0^$~go bg rV}gD>I\ȟ{uffJ̺Ndzwٸo|}7ݗ&_ o&5T?>d˚i:&9oES;Z +2<9-n=rL%VrpspwJ@۩"5=Y;W[k*E\8 \8 ƷT|Zi* 60JN:JDC>jCvR p,jX)lǓ{oA=Pں6}G쬌p8(w{&fPJN {zh풦z?{ūzusmA +N(d6V|gY'>|jOClޥނ_HXw"ME/R 3Eœ_J#q{Pu8 ) /y#<f(63H8DګShR*b;B(lѱFwh6Q9[;݈{yɀEp+!]T7ttG$ k;ԖS|(9GnVA:[A^pW]8VQY)[o'-wEjcdQ@?gD42t`T$^$_4\(c Mأ쭛qNOHa$BY]a!JDSooKچ=Xq euC7>Ɑ0l;;IN 4hX*]AUQN@흈cqwVѩH^1̰cugZǒg'蓽v僈޷jЅh;F@DW[ nB +NrF%v'N!P궳<6B<hN{"zǎs +a7X,O>E[Au9Ilѯ>41A!7Z+ހN[aukˆ&ux$RGriBH ,(#oD9܊]lTvьkT QK=$5]HwI*"QvTF4yڐ)PnOkg}|q*9w".y~Wǥ2hzt{ڡ\হE5qHxfu_vU¬[,9c mr/N5F* 4dr?4T^'Hl3GG~, ĈY)L6#|YPMA>~cHۀOVvM,'`8yQ&HP͝!;M f.HMXMI;3 ׅ4bjhiXyY kq5@/>.gOz7֠ 3YiH--gBM5'DoCq3SyEGPqիצ~vFg濎РV'C&?,&`5-`k,K7k>!ƥ S;'I 03$uk +9F.|P[ԴZ7A8}_{mD &:~/7w|V,nL@OaE6īZqE',=A1_M?pύk(QN2Pͱcgzqnܬv?xLR:x4Ȭj=0)W|wwi Ԟ~h Ùה- F "_R}*YZ+Ymy&6 &]U_(bv6dVυQQ [c-] mF_Խv T~dԂ^nTb?K7hDR8ey_1KflFXM@Kv=O;-=,}5ΐthG:\M q7:vkrȩŠpTBZZ8Iݓ6"O-Yy/`H6]4q4M t[M|4O_]$3FVktH5OWPB|&vT|IdXq X36Ķw$\϶i]ZeӔ#ؾd#,;)«(.K5Ñ A#*`wN`2H% S2ꮻ{u$;1Z^#$\o^ՄЛfȑ؞&K\ P%̙Ցm<(2Lo*sxF9<4@2{(_G AD5xDG>E/GAhn/A\0K| p/z.̵,$g_/d( Mۨ$7$0vXr>% ?G1O[|B߹M+q:.ӀrsCq~h7 ^Ek3~91Wָxv=`[J9M-W:yƅ>Xoϡ=Yŏuh*\O wnZ{5[a\c'K{N,9pGtxe>o2FN⹠su< k Mq]kjw8z5=}-R=i=( ^dCe-Y1RN}`~;tʩy _f#|hu{O(f @NKVZyMQy0z|l\\TJ7H 9a#Gٌw]Nh󂤶H:K YRћ7ݔ`9J*0Q5=?3G!*N~΄EV_ H@PB4@fqj7_YFc[;7]@EqUZ+܃&297.0TrmZza̞;%M&Cfh"nuԿ4IGa . xX h`|zEH!s3sm|]V*ϲDvJPDD2aZh+2JƦ&eǥE yk.pj!`1_ٕgka=#p< 6Znxu׬J!Nr9>kŏJ砷+y%U='Z aU]5Q՛;E; fe~c:s 8^4l=kCN[~!g\m*455ʴF)~%|QnO *7 @I{wGJ^Zʔ,^#z%y0KwRo2bk&iNE)=sANB}XxNe?˂%=RC2j dǜ$XŮ-&̱4X% Vyw(ddYOWXq$ܰdm(%:YS}W0{{|ƫz.w LS1.U(ϝ17]{{15$s2l!b9{O#1x,K~%_<pA%PfKBgi mOz5#[Ew|ۋ7U.ek#dOAs@%K0UjAtTga{F<^@b/=sNRK%>ge^yBPbqzckld%v+H+U" a 0HJ6Q{˙f+m̪/VX HA0:ζ ?]ML Gy)TOWGZݲ}C눎=iD/7b'+P:[)g- si9ä@rr4M!eUEp"-FUZ#=ew j"7bC*q5pwQn`z7>. #iK g/kVlƈҶ x!j!Tk!v?g 5q=AX Lj4Z |23 V)(:(ÚP+#{ګS'}\Z !VW!fn4jܹ>9/MwT昪ܭ,pޓ7Uu[ֻ3\W91KdC6;0 )~GʍmB6 #ql@4QjF{F(9{ZI2G6 ;k#[W w苙%vSC˃|0҈j=Wh^iԇ8mMڞN`PQm&c|i6'&م(@r8S|{Vӷ Xm+v8FNFnu70r 1=N^׎Ad9s;fHmJdl閸LyZ^ ~ؽ;f!$sz[#Wa;; w4㭍}.KaJW'}tŜY9$cOmȂmSZi_ag勔/* Mo .:~>:baz :& ŬTG7LcN;{_D -{{v\itxO{btHs&Ubn ,piK8iOTTz4"+b|G]?04P{oݩ3"z\wip)!iԃtp*CIckVE/;ԵڣeI4,MRNbr\oA>5>h{u8tp'6"RBM9 >)烆I(p,~=DD? e#fU=BqBCFx a)ڑbƆfV !CG11]R+Tr$఍6l}>: `+;:~F5qS)=#Δ.ZfܥvC> :^WƭT yuD(ַ\\Lkj캕U R:ḛ] I'Cb @TCԠ1sQ^"HfC2&V]7d_s &nh  ZFs68SK"R&f8tl %Ո 2=o؉=$F1j>rs&Os-51SGkHȚrih dHG*M\yG@}뾎I!~]#3rW9+xi\p##˔ƐeX^\$^#y2T g:L{)U?u<@ K<,Y: l"&j\Pm7qۧ',K X"m u$y++w-4-f˕7&\⽖N[BrJT{ ЫJ^*|Ҭ""1b-3p0ty Pʠ QFP (ŧp3RTVU5`oJck Vgdd,6 tXuYA44yʉI[23U¡I&Gˡh_Lj37> IF07*O Xt ю<ߞ6;ש(Y@" V(O*X=9$\Ρ7jvJ]\SX:PMG7אcG>% / -4ǑG"< >bڂq7 _vTrPCw@R+?3j0 g( /g7̴uZYrEN$)0ܢo!4jOiHMѰ3.zekuSj :N69[@um{qv[|t_K)P.?6KV LRiz߷ בgùlzh2Kx#®,}aڗ+ =MʠBE"7m0.{@]Z#.kҖ *YٖGwZ"gH_D8~kJWlߓYA^kڒO-7R4foJq>ߑ4* \G;wˢiE}c@n=zgB:.G OC"F$"! N?l2?}Iڬje+Ǯ 4u^jbӲ8ɺxA~yQE?!w[Y Wۃ*!M^(yD&Qq}Ϗw(lVHRulS/ݭIuD $ER*,:dʃ_GbLAaXY~myN]~ɑBݫr13lޥҿC x\M4LxR-1q= @fhiG%6T12c[.`}\ 0B(ꥭOw[ fZֺoV e}k H6DZ O7u>?&뇑b/_ toMHZ oBhvKDmHju!6*:PݱE?mJ]k6[9(JinMaRtѕ'̄ T }ؐ{V҈;Sf5c-U3Džz)6nu]#_ZTӓ\f>+l[ӥQ\Lu/+J@Ѯh0?mkB)uAwuAΙ` ^3%R\i5`GAУJPD$|f g`)V އcJ$L M>;'Rp) Ç-.Q`t?B@ݒ\W%|c:Ĥ 2rD!wqD|F-oFZ77QJ2hD\79oыGRai@wH׀ a;WJ:Zvws֝Cf]1&4*/,K[˛SᐟMM)Mϣ4 h%f$vrW|*8Y_0XOBYYM]$I;JWS+ N8"_g1F WAR,Ox6?O$w2=c*\$"Ȯ|RBdv` w|#ڲ{!Ş8CVs(0./C"hTL!id+O2;ΒIዣi pʥmߤ[(<}7V1=ԿFIĶu1pKnBBF^_˨[yL -HYoj-vQ3ͱ,f9;,4TvIfpR~"^+x0'o&*PaPlU{Iëb2]t/(CTr,/0,BnO'n_;]_Ske#&M+1-Ig62LOؑ$na;jd>IHcF U\ /"E`袧g87tgRA锰GڧRGpvWC\a=ʣX j<3eOap>|Yvxc~ʔ\*M/`8ʹ;3U<1DOފb7:rhfOGtszeͱ,+$ESr!2RWBM]m}+l W xii>$[/M8жѾӱ*-B6=@UbBhvjUu.F[/4*.M8r;jɗOeYMK'?KXE/8 ч ۫{{f!חy=nƽ-f^8F WST)JH^7Y"k]}39OP*z=EZtk9Cm8 CUdpO5wl|z舥>ݪjBe *?i0757Jq=bkD J+OOhR˹Z-㼈 P!w96ꄑ[sG_kw:c+i 5.V#`ݯ␹C8{SGBVn@+Flv>D048:r.rBqEL2 cg`k5: \hrτdtʶfYˈ<~,DwaJ `[qko5њ-̋+r>:Cc^[$b^޲\cLU `61> E( CXE_3aX7=W%2`FqNsÀMېx4ɓT1'0 VJY(7!VX|ěsJ6`A Q?l"<:\8\8^/ Gsmv*2OSLfgJ%X$1|ܲpd^|K$:X)ͳaُ4{LB?|7W*&ρr^e$h ?b^qњۭDM#m zUI G{T ZZ4br$&_VI.K(_ȭxJI  lYB}UE0 M(e%`3PA,])ui%bYSi9yvvS\%^'];Cd嶭CІ?/JHY"}ԗ3=9>Tq {WxAb=bɜJrttl= soo=9n7%8T|ːb<(FkU+%f&DzwK ӳp*#5b+n"bk09";wxƍ?5b(!9H# v'Tgɛ.߫D4-.É)DlSClh~P''VPs/Ā>S˓iy@zlt3$Ҕru|v fl%g̼ K)wiԟ5 ɗxwp)=>K8z=5Q~xG5,N>[YВǃM [ґ;~k="@~Te l:5`o=xٽ4 r8i,=3dt'IfR|ukl@r_,|3ԟ #1 [JE*S &򓈫ڤ#[ڬEF$`TS͆#XZOD|ߪ>3;2̝LG$ց>ƼnHN[{i ^8 ?5Ybi5͸2YZ zuwhm:ݮ0 Saf)^*Sf"X ܐPo_KXƄR~獟-kL58|OWObpVhPpelHQh}QJ|a۔?bvdE€_2z)P% Pnѱe&p1`D/ 6E_p:8ڼ"&]p 6T9kT͊?i J\NXr(r&BXT"f,Ubջ)]Q]Ygө@vi5mQe,>ՈDB[Rnou0ZIipbPhvTX ſqc4^O yt#L3'9ɽdz׍UmJ)Sbـ2'rjI{ 祕aK Zt~;*-zLwXbu|LhlL(DFc) Vd_|S2CJ+.E!5 |W UXTUaӰ^9q>5H]BvJ}~tȰF`6`|jK$p`fP"L*Sݐ;$b"^q+@c47=$PX[w/4 mG"TH9on ?^ݗuZh&h cݍw [VSߩ_=GH쏞YN2bU/ @mY[jLZWJĻ*8\!엟 U t޻#&fk_n o{ߕh]<&"Yx'@z$A.(ur/3NQL$LY\~:| C(ۮ1@,ʵPU1.˜KN8ES3in_ 5^ ɐ gP"xaBePcA<(J(M.>M E^Y}_(?R%E}~\ɍΠkL{{pE0D~oHzu/E7Y8?l$jUq&Sb?`EsX`6 &AvgWQR;BDqKB? IAx+/۽sq0a6G-' ՟咣8Z|-6>Th,I!n7^+ϡKJ:bǒ8UQ {vG5'ݞBF@}FtXW6[yuVD>$a9 ^t @X&20X?p"WV a -SN*1bP{1BVH;1t(G%k+J^ӣ');m]!ar'YwX@OOk,Ry,v)bڟZ C\'>#`SN>?@ne["p{}$GV'&$yK06" _3suUp7$81$\韒ìa7^C9|X?{a1=IF7qHwތC쨖Da꒡Bg(qCIk"ĕ:Uvk|3JJērJE!z"RJ0HI"Qd^Lxo( r1]=vbr孟/5͌m>y\+qF&' )G'LJVss,#_1ߔX[l)Osgjb9wueS`0Bśi/`Sg8_oNdl.=-;f=ߠÕnG mҔSqr #E3Wb+/DR"tAQSMvez୯yǙ9+^~EPj%IfX;#ʿd{a-!po}[YϤ߷!)Υ~ZEf#(^VvZ:* zYr>*B_2@\SAs]@JP5(f3i SQ+|8Sa;[8p͖X<0>UɗyTth&0~k=U~4!e.cWVe1Q0n.69Y Fq{$B(pc&-gkv}9&ns|#ގq$OpQce[sbE4&bKNXsUߒ}1_O(XS!Ě/媙%{ `z@gz{6nĹqV뗡Æh3TAt /M:q2%jӣzF.y{ld,NQV7]UD=H8&RGַr^ТpL"1gJ#FǟǟI2l^hRIWuRʹ0[NDZ~= bP6 ld,r2 Ю ±/oOa* [Y]! ܦw ycP!T5&s!Yh_WY/kBz̼34h+ͦBq=e#m4ky$ ]JpoKC9}LʝY+6ӥӇ#Lجν=fN(ߴ8lDol S]uw~IZa MW&s(;y "PTBTլJs7@aCi*_E?QX1>S+N= ZCn^ܠ)XjIXa x&o7h$.yu!닢2$؛׹Lyi]:m`"gꕪ r6: F~jt#okטT7ޜ,)4;HqױUtbn.3ݓuP>"2uia) h4.[,)lk`}dbkG.vi|*R8Ϟ)eXQzlCO `9N@CܞPT62LVS`lN=ȍ+*0WL:oYS#o"LeG  .J:м?\L>acJO(ث!`j򹬊cW45Hiۈm-HTaG Gx! B07\&;0hq. |Xhz]ZS9\wnHt4궖ﯔnȆG- A9j-M/q'ʚ-{ϪaZauwe֩$<% >RF0)>0(W{%~p[DR,ru|[YvjP]')2mJ/*JrZ2xKLeLC>EX07bxƬ΃V2qJJ*I =C0;^ lyY-,{5É: xN YHMoЍ'%(Fǟ2M_Ts1] kǛ+Xi.l"ֹdiC&a.'pXZBG@ h0^JIaҟKwNb&I]zMI>av,ai=?TFTMunp3@_(B5KS {aj,s~UώdZWV54Eski#h4ը Pze1:aLoU߸(Yn " < Zy1JdWshVax<M:)7R*|Y5*[.ټYM=^ɹL %xE }?|G5tݐO݊ʸywE92Vq/֑-ٹKk{~a1Z#ZC|KOHu| & GIQiyIlfnEܹxT0rs?)ȃ> 1 cL*{S"j E6,eCyxR9ko/u8WFH7TTJOl>UJ=9Nȡ(G556bf֎@t{I~E^ vXnfoĥ"s\31+>mu!3<c}+5HQN?:>Hh4MnaĻ1Ӵo~"~z+ QYthms#($[+ T4kY1 sj|XlB<)j'杣 ! Y,\ mr֐C%`qPonn@IC\(?}; W mhЙgmBuX~.^ :)Yˋޡ+ixRjw"|yv ()WX~ ur:w "d^^\NI;! :qȒ緪&;Vd$T8̉K| /KG]jFͧSo!KEWaBF8ݣ򂦁(lx-]kJ¦qF@.ʆ=NH~ " 72}%\F֝;ٚt>YIdNy}_xKDSҞ[jxt9ItD BiU-rxWV)/VtǮbALFNmNla2I\[ >~&w4^4޵ZO/rSU% {,4h 7ms #wz=9ҁ0VcHK<]}?4Q&8R92v$~]O [@t a/qCWa8RULg2a[㧣Wcco-No{y<]FE#F1JfH'11 ,re@5K>KF3]R87BI/.8UVV.  G9FvP1̅MVԝ KW b9t#^eӊ/I=^2/нzkțI*x=JѥPE !Xz&MP]o7!s S@XZZUjqPErWen+'&P1 Ez<-]/b\\ڴS `ne轌2R%!24}pEEZdd 8-ށ}F>h&nomϯ9KKKHK0NXտ^yLN4 o=:ܩ[u@iD+[ך/qinn/&-eEfIxζm_#WHkA! JMXkUj?a+yz/~bO|ՙ|q)d:ElD)s5}DR߹H)1(띮8&&s [ֶW'ņQ,MyCn*jcױ-mbx\u:)I USP>|{z\ )Xf1Aԛ>gqpdk+*(]PnѦ쮁4>=[TU93w(RaUh$K' ݗHG*VXZ8F gg^$ ð=˺]g=*PdW ,W,GTC¥̮ChzfQtz/feTz+-N!TtJ8R7W\8(Py- t Ny7~IrQx~0X_ARkE.|ѿArw悮qy$ckj+ϭZ עbvీGcAсjV^*d"N~ Um7K ;WUaņ4g%7<}\dqe9eU1C[0(ǵcC"&ிaO>S;MIodzK{Ҙ8ALM;4v͹ˬZ{[5{U3^.i> vnׄ/FߔkiNH0]yqHmTK+/_S{o,_m'[? rsݡGOKa9;'`~eeGFRQ{˂Yi~ea, 9EJ#?=Eѵe'Dټ6ﶳ V2IIrHJHc "ͥFݗO4apPܷcBqG;<|:uCZaj]VFT˒Kp;hJDv@lK!Q>U1P^{k/!DDuHFMǸx#pi۶%D)l=$C \2ʑf{f2kehJ7VZ~qP" Mm1_$\iX^mlxmzt0I I$&iY{]핖< 7$;edށZ'ǠE;eiX"$oAF['a`Ԏʯwh$M7t&i '_x(~v/5z!&JLĜQfDm08 o?eݻgDU(TrXSSs^EJɐg})<̨*qG4";sNaҌFy&L;(WNN1,@͇U:x: 4|}Gr{juU 8U6*zH[p"Yh^}8L1g(:â7>C.ٚ}|0pr;6$m#Zt=8cSra΅BϦ7#):%Bjf\utbR}YeB&-HnDkމPf׺ ?zN>㶁J A][lw)a 8_w @5=H{̍y2ş Gq*9)L \CraXXqtpF맠m(xs; 5V_*X i  8nz3*fT!ъ5I$<8~0Hɐ˖6R]3Tg$#>mGLmv\$1K㈍ft<0uu{zMN.(ߦ Bp6;=":t{OӴBeƎ!ճm{iuOmq4@h-{_hOU<[ܱ֛a1tYHqfO7q͗R&X#XާY9}%z~]P N:eb 8wB_ǝw*Kx3j\V0n7C\WOuC4 ~ MzVݓ(k2˕9"ϵz$/WుF9P@LJ]͕&N,Ync^鏉צ[*D%9yw|w n7;;RhM,"Gl 8oe%R^_.C(p-'b sW[@k+V|?n_ qgNp[f3^ htcB_E#|eR5[6(ԼO3hv ,  ѭ?whoO5S>z!&[܅L0̓=X_.xnshʵ`ul5SԄ(. ?n7}iiE"vXu@[ ?>3TWVIWKw,w)~Hd$M5>qOiWmh1]p|:C ̵Nqң*[?J o1jã(Dj1JvF=8Zq$НZ?[2r"7n{W޽#3 g m"BPb#%%a%Fc)ۇ3;Ad]=ň8'o0ބ s=>Duy0DG\%=$Hr&p]CLIbl8Z eFyzqsN%z$EfݹP%uCRC7/@dS[#Vu:?DMvT@x,2@B;V6)9=srP:mP(UF:wRiz%ߺ"ϺSbo;[Hdރ^Ӣ2c@='eHu]66 >q-[P.s s2n7}T}\Gvw_ڶm؀"Wrr|O$qWEM?cjv ET;n4[~>nzKY"g '}e%G12t؋K< ];K*PtA܄|xYs?Iq_Ik9ۭRAWh_WZI,g onj|_:G#ps%m^L!?)a\C$dUIܤ^mUR1ρ磞".nSiҶFuwa";=*RZ @]Wia8Y[JFws:#cMih*("WP>BEM PfOǭ1o)g6Uz;uktϡhvz 7 9ݡ#`HrF|K(ބLhNAs~2^mZ݈bOt]D;4a򙓼1˚7 EuOAPzu/T@ڳ-EF^bKDtY}w pbf(DŽXxk쑎}#!S^BӍ.y9V4F %_ڻU%eiEνwm@kh*yHM-x&C-gubܞC\tg~ߒYub׉bh&([ mt8 Od@'_av6vQJPVY7>c4+$2pABr&8f$~^Q\ܤ_RR5_[Zpu-6|w'Y3G5@ 8oC=FC0 n!eABӼz̞›8 |T w0X> ~SKi Poi }*wy#f7.&7gZ~Ps;a菮ѣh69J[:6x!D%'2bKR_Dꅨ?s/4* $p0pzRI8tU.GEV=N} ׹#9XFzW0rz>G]c"8V)-L "aV"}*QٞUŽtzN>D]6/pԥ4iH%3U) KIF+C9fٞc gʾ.Ut>ļ݄W,TcA`W6\zMzZw$ms{hgϸPP|*9д&φ7,*#nc>JӐkNZCwbWԼ`7+l@pL3kVnU`!so6 I_4i;~>Vj.! @TO&# ӨɊ+T_yn.6=nR0n$lMURs}yJxغRK>{-Sq`) ͺ0TXL^s0Vc>ōhE.v$o&S"żyrqM4?<".frA#e³#B0AqۖQ]ʜX4 5HS#~E wEa\P* elk˙wT,H|6X@U⡸3(:m;XŘ4`7Hk@ʒ)/$f/[SSώ?B 6rA"At~ՆUxT t?I6 ͕Bƞ?&16ٮ}Iz-RjOSA7Yљjli5V'D4a븛QozȺ qoyh3ݕ'xH3m[|3b)WVi--٧u[+3 uZ]2ed\6Z&x x56*qo[55_pK;j'pDɺTt@Q#4;/*Ÿ}D&(ggvVK2;].ktAxzLa򤫟q<[d_Zi{9֎N5$U3! -\ݼJ#!b~R a2sI/YC$wV@&wҙe`A?:SGFZ̔pŀߊōS~qf4jŅu!(cfvBǽ [u#EOi Kb:͙id b=1_ `v]fL7:10x[~:).6Ww㳖T a(I[h/ P.Tq_iN)Ip:r=\oy6l3|#cc IRu9AfT-'s66()Z+"` ч?i:OY="1!E%C( >Crk_LW?\uIK ';SDBr ]gk055R7\Y[Qlq} eRfT4#)g1J.K2JF6-_NK%G̬&=zqwP=^l+/MG2Y &#Ayxmu1Zm@M ޔE$C:$&Ţc3x;d7dS+$L_|ɥM|ybw(Ajξ+!%gf(= j/$p+6qt#wV\xvƻ=$n%6"gD ,YxRtiµ8La"{YuJ@>aL9 52\geEQUZ W2 NKHvՇB7'CPR\Pkc5fh^FD5i=P9*zK)d4ɉN/ykwUE+LP6qFVRpeW qΰ<^б'WC,>nnם;6?A|w8~ ajޮsjmS#-n0>&hMc/;瑾SEdש֜N{; Δwł&S?GZY?T?#UMwx:`@Ch]¬\|,qXmhcs{%©3viaU W-hoe.TTM]H6)Alˇt`B eXy_ƻǣuRMI ظ5bh@оg)\5 vU ]r$'=-%weK sxK\6cVl Em}VQf8Y',4GJ^X.UJLݥQn#/j#p:= j n:ua\N6 ysuC&E'H缒r>xsæ:3/prmf~Ux(pwl(?\q6;z?r/皤Ym哘bϤ K_!l8Iv۫UvBy4C:a[(ⓏC>g5Bp:bzsճzj cZq7|z\: DO/@轴dpx.z?s$3Ag',dD>Ԥy:7 qeoZj,$8R-> R5bIUsw4Cx%ܢ4nICWŜ/_CBv[f&u_$1Yd+Q0|v klԘSa\HHIunU T&@k1v`jNT󓍙5`O sl,r? *~_{¿CIL3@Y>żԇ-iQgh^&(kQsɳwST-Jsq #W>^ˣrGP"^/%ZQj;9MMڼ,R#FQE SYM 4Le0B XA2k?5z29<.b䜩 APt~pd+r6r%)3E* 8yuNTєd<[,/*]8{O4LQaCO,{d5f^h}\+|%G;c]^)ixB+6bއ6sjwѐ^B@KZbIV$Ot8Y]eeV?}'l2j6Sd`ϑc7wABNL0Ģ.-6u Z"DpJ#C3l\rAuMӌjNk# ]ћ(!wp'!MNofey"%]0 -3܅}kӂ3@8Tg~yM]!ZG 'ʝKFoMo[l9]$ej@ʽPmf=\H4Mԯ<%EB5Պj`]/m;#nxn&t9ajg\\0{<g1{'n/8WCdr{A.h& Ǣ@  sr\ee7DD<) ۽;~5'2p:cf<ω9_7< wS諔H+9q_K?:E{WR߇͑bH!Nm!r w?ބ˂Yb_c-!q:k,Ɂ7W붵Z3-:2 _fB.虿@ݡo /qt!ٔ*3'Fv[:mɁH? UZ0|f8FwO!uQIKN' *l9Q 6YpEeu$a&QဤXB)*Wx,F&ZTunNdFjSWAh Dzq1KqqҵQ(aѬ3.f!5je,CiDqpsc6dlD3i$RD2j{E_2G7ށcS}+`d8߳7\l|Iz䱨 Fiieqޗo-%!Ϯyv1^F*ZP/|<$s(m$<אz 1X7Χ1hĭR @2?m1W8< E敧yYox]nNyx5̞ =pi@ݠRS nٗp:xTG{tkqpI:#72amD6^^F V,QxFR5t&0v 3CD3@HIVq v"BN֨eӘrYCN Ai(]9[[ &ősUs&WϢ:,'Zi'c)" ߋ8v,?r'7h@EvÙȀc3tH^WؼsJ.&.R_ Iό69]d{@IG A<]YҠ5I xq2jhz3Q!*NIGYP.p)[nbPWKfmޯb\S@ lVe*Ȉ偅+Y-an.dfc?o W f >i7ƕs(H:!Md^ȖX}%)-BDjVC[һ7W)=pApi%]{BK?iGzvټ\9`f7-E5%#N}qwȹcgH]35k#u^+2dk1݊#\Zb̙֠~-Ǿ;#4rtsZQ_ |M!`.uR2k#[B5+Q_C>-vGم?)W?r[S譕 AN2QwϱYQtnDEOT- 'Dz/9ؑ0y p S뼍:p[H`b.6HeKy%}}hMSxhY3`6U=`mU5*yM1 B{?s+? RiX$T+#yP.Nvw)]Y̳ G7B f$4 ,Fk0? 惠h1"dvg#vgSakQEwb8M3RlqzL/*C+{ϸ&p}oy5!o}l4pqWUr>rwӡ[@2ǔ!}>!1'U7ϫ>MZO' my,_59FD$J>_CwæBC|apL''Cp2#`J /GvClqd2:[bUY˫4"K5Ո.K7`Y--u6 iYy^ϩ:R *֨Z;ѷR#;xqauBjBA*$3juR~|ƖrAM%8z#^y}NL]gb!msw}ޅlxن/>[c %͊5 ^P<:T p-`55tCF~D3y6Ho.iY4p(|SOj*иDj%OEш*1q=nӄ u]M#2z`ܫuS#2I ÐYUdT^HJׄqBLIz֤Li2&6 1ÜA cZ/urZoBrϳ.Mb| Z VSi݇tԏɓ\D]C޷|T>"r#J'~lGb-o!ŀIn@:䩷Tm~9lv:pp291yriBqܑ:GhUC_vA2Y {wCnGE OƝ[*S`I%ԝs@m?)c4A*- Z4V5&͠r[?Y3DeUWR/2c[0 ښ) tccf;HK.YvE4Tp: [ !=P@33B{+ha압 ^i])s21"2ŘNY U6CC |9 jѽJڦFD%Q& T*J 8Y9S(s**t뤣LTrP*Ka= 3R)9.ZP| zed8N.UM& "$rfe:YW]5 |̀ >=Cx)}o,7MS3Ӯ.5 T*gBՀ[2sZ?y9\a{k0c ZHupu6W/%"%lw{bqyg)t5@*wgUW&QW¨H5%旇TnƏ4FEp_υNP(,>@~_9?G7 W9&%">D>(pGTR?-XL[^d'hiU\'u^GhCo*xJlڑh vBR\FX<HscuWI/Jdgsi 38W 9"|DZ_!a+nɯYUVfW!/{5eQ=KmvUeRLſ2{ttnB*äol'Uo|g8K5|[ҟ!`{YZ5$WȠRK⾢FgY\I?RD~8LXA*_1+^QH'ívz| n $N<1G;I2đQzpσEm<u ct;qd<ʠ&S7o2f***U Q`ʭ#K,?FB=> GJ%~ 9y/’3iZV6ڮIps, WɔDObXdUVJy./o MhYd"(ŃE2/rּAL NU7@V[ V,Q4d!][-Bpd}nj]*p/`-^~t$Y/ ).40Od-`"-$o׃g7+~'PD'l< I'xҐS;4?!ٖ)s WPMW@fGLθ+ 舠֜'I"hQ '`ߪKɉ>>Q(]jؤ'P0Fn4;Z{3 Yfje&46BD7 ۋYaAȠ9-}W8>}H\,[p?8b0Ub'vb=P0-l'A[S1NWqߗm  lgÞF$Bn9u7F찾 H*/u QTUZaQ恿t@QFj7Kb\O/Zbae4?M0&Zd37y@P`5t<;ێPkk j"  ߒl:;N=~~ M{L,<1M Y 4m}衞xR߃J墓)vx}Cs=桨w?9HW-0ZH)6ZdOϏ`L h-"QsdKH" %`og $MUnn>L}f/g.Q̐/5Bզ)Q_G QlSωRTT * rL|ѐĚ58JP sJm@GvH 855CgCl,R-蒧Y-bjj>8[Gj"rHtc]^vy·L2az0K ?$`BruV1!۷_9gvOHu@IҸJ3w O6{>乂.I:IU'>:% N"P}GJvuيO~F!]Z)5flEZAB7!*M?>9W(zޕG}yDnUeCtt1get@^CE+nL?6X/!e ݨ!lܸ쀭75P sfuIX¼7)ieQwF3N^}KcqRsH#ꍁA3Ԟf цD/yÝ@&Z+6xiÎLg1OYm,SzDնنzLT=kE{#Kv:qJѾMlfNgp4ݍFW94w47;Ka?h1/t~7&HwJ5ģD_gX+us:!.qMǧNBG߾.BظQSM5xYy;ƾCQiѧweEfB/؈J $#jnN,H4●o?PJH,?_tKC"6dzdF&[1Ez3ssQXR_ O]Cg-Ai~T޵G͒<:d4X A=`jdWh/b3B, p'pD..c)RoH|c@G(D./Lȅ^Y Gޯ(+=R̫:Vb m{϶d vf}|?FI5`2l`/bB)½ H <@8{??!kL▬D^Iy=t} zEte0WVNwyVQ-m@!}DZ0 L.7mfeS\L=IY*A s+A7b#yd{"S7œq2KN!FE;}\S I3C I3[W`ןl̤L=ykDcaKeC:VwVSd)Z1h4۶.$vƹN3ik{8(Xb$A(_SY^Y  *|"Ńuo3fn0(gө]:?lfVrpӓ`iy`I}ʍ*jj%Z6R*R}Hbf2Bz!9 "DVyl[R&"ob ɪtR[2׷![Wd29<4Yѽf KO`D6GSCp+`/c߇g)!rZ6ٝ%x5p e:UP7#(T$gB &YkzTe?cJ԰8 &jZv3;OOW 0PR1#P ' #DsJ0{^F䱩sm$iQ_rT{6~ Qc-B{H[:Whu.3 kRDžIw+[tEZ5+,F*ӣ|'ᆭ{-WF۾nDe\|8)CL]Hm?I½1?63F]4Y=l ݪ~u1 $֤#Y.MXmiLP͌|jUCZ"86ltPnxx~`1Z^_C:5nt#|OamfƷߋR::a`v@$RA oG\L1UOrm 4UQyٿǰ(EŀRfkc5kWèWHOk:@# sӛiBFULI'ID-vٌѭ4}|JO)"1Be>l pp,Vw "`8xҞzR*U^ļ73sCM8~H:@ R+ad\kv?O|&4Ly?KT5dlP{L<6W2]2tɒYߋlʞD`-,JJI ݶT-Ql~7c:97;pip<Ԟꨁb޳r׬N\fzhyM'SV*#)^ ]XeϽ݁ㄗowsCgg޼b73']iPPjͼX]L+qpwFdcl܇dTPVw#=G|wj0 dC)sA_` ֹtIW ͪV6ˢK^HV5h7:4.4D.6kFR"5E%̞WF58IJlrk1{IQH $ E9U@"gqH^YL>1R m#Gᄾ^:E%a!2!/{Vc9JqRSYۅ:DiBl/0YyQFa\ ׵̩.U~,{+ C fDFUU[1ȷw6tJ?l*S~⒃qkT?3oĻZb~XF%1]faD {_J(Æ'HӒ@Gc!KWB nf3n:9.O2-:Ꮭ/&Z+ہSa{ µ(7twŠ)3/ Z f$F3AQ䓊"j locY=W>ʹއwbqۆol\X+61'C`x<>;x QoQaDT̻]I43=F ]2N9ShKQOo8H`?Z)@9ӓfAm6+hpZ4 F )4t2{AvMp@6C.%uEpLJON0NčDkGX.œ0Q`1<+ \I+8q"%=bp WF(V`:9;ux&*qnIN ߤ k)[ER691l^ǖ!'ϧFWژ{fFә:I@sDek`vqT'RJt֋pmhz92HH\chuY ̼[̜Შ8[9)Up]PF}+)RL=qIh$) -ȃJ: - 塭`ק9S .ut>\78J7x`EᏐcG8J8 0 ~ٷ̛jV4:}W<aA.'[u&/$ENu/x_]s9]ߋ[T{8LUx-Pu:'-\6Whaގq{%S3ڌlAЎ5<ie,I)ъ^qh'aZ3,rQG?6j&UQuzt:A1^IU%2h|$,|j_+ft[ 9s_kɥҷT#IR9sT/M<[dI?n>s1Ĕd\V~GJ$.H(RtjBv8Qn LoC{5Q*U'}W";Kt'%,\'^y$|>%X-Q+l$#B̉K h:\מI8Hx@iE7WvwuVR &p#B Z5PTcwF/ OQ/ypjLutihSe OZij0"L`l1?|&h]Lffx]V?[ `?'阧Gfm(oDR%@0/gϺ6!(/S@7P(7`OóHF;̳ &Dx/FCq7U  i@B-džhE*}p >ꁓ*lΥ&;fb;o=ѿ8r)S[6:xN"ǧuoamutO!UV@Sqσ͋"єMYRxJm9lj8Vwۂg82[̿zN!W  +n5${\~@i!7nSOD9/->@+%X[΅P[ȷvc?Eww+.d?z>PbJri`#]7`&\b4qՍf8Z/A6v<-E2>s=rD>:FI<}PvY0辬lJCCVe H%D*Ʀd"9^u!oE{a7b+/dtP;=OZStNtbDO&} ryIh,Kޥ l9^baљ jJE##jrkד}?k|'?`*E ÔJ-Q_g+qЮ,ұ1ro+GUKeH0e`Q0D M,ȭ7<=ڏ;!(Ӊj]w(3Mm>OybaS-k|5? 2V@"oVU$oùy3nf[afn$ SRbDVTdLwS *M# sl)'ܴ#!Fpu3uH^F'(:;cK'C7 -+S[az<9eVpAi 9CiQՑ/!p8ы_`EhZ\U=4Kv3%J#;N?i`ofvGzF2vIGYƚ԰*W,8RLr]09NOdqyjηrڛxֶHv9G"S VȱP)Nc$ ++PCSߛcم;> |lrڪ y:XwSa +dIsLv:"y`!˒&=xI%`(m#w$Χea]Fk73QlRM!|_^lHA&HM38:Z7sZst0P6U(1/rxbuN+^G$[kWZ y`ʔ.|lnqӵ%փres0HR}[gmIܗTUr5%N𶭕?)*,4DcFA~áڜcB`)U|漮&z^Ql9md~uM[a*gRҷ&׽CZ$p?R+=ތi__)$PƧ, 1?@~ޘERXc}wEw`M XGB 6,:2-O6GB\DP.;f㬝΋EQѕlKW KFr0p*#O[Vj>uN-uH2 b,(8K贋NO7 V_NMu +_d"6z?[z%9UM3dNXDy-n!H8H7 T6|8 褋8CDJsQ[{4˴Gb cA& EDB&K;[!k 0qwy= Ƥ䢦uD3]=R(LH-d>d񃋾 D)s JU/P;">R۳ʝ*dA Ll0{RЖBlat=|JTj7)) (?FUeՕ#8S-H-[ J2Kؙy-CbTb  g!IA tݭƋ*H@{k8=7i?g6t\b{86.3 +f%[*ku,;^=<2i='s}2u$+}_qF)ieSC̳,T"/vL] H\#~UpT-Oq.lo1Erh897\YE?5<tIa!%`X崚,TJ ;AQ_"ۼ5d&6)L+vH>fwQCL<#T^5%":-緁5Q!-ԇ鞷W g,46^>= "!; nRX0/z)k`<1Oݻьٴ;:7?Ss}áID"y3i 6s28O黺}3f[87),_9n>uS`uqC)$J4s4]?x-{jw#$dFrr]8}j@fDc8 OvsVC "aaM4RݹKk/aخ9TbCbÙȄ>-"ݷckB5hvD얒\W6+y,qISu84maΔK0F3,"c\8YE 99tЂ Lirh<<\gV) ^$o2b$t7sj  (I5Ŕ>^ls=\Å.z.EUZj[7u҉#lg{֔s xe/Qk`Prv_ƺc C 54Ka߳l]nl}$O?CkgO+!|t x9n͸uje`4X]ά`P^ꗲc,aCosw ʩ]FVꖏ jy hzS))J;!r| #>Mk~bJzcYl) j%=V'Dd`}Dޣz t~@nFƮ)`ėc|TڐI;2(%փ Vclh #UimAjؔAݷpwn2q6CeGaCgdg C!nO;?b\7nFLiQ] 7TǤ˕DK c6kX<7 {r &f5H[ @oF)ctŶ#@ ըښ!ǁ"R(KU悌$ʙ8(a6>Eg_O#ZC4:j!3-,-I!IWxk$Wo,]$" =*Љ9e.drdnˆ'$2'P| RD=DbZ\aL:sl-^OkC jc8_307eG9t*&W ,$N&`6qs+8;(5blK\^Rx/:`ݐg4Ө_x3U5~3ğةE6[>6S{:\( n^|7i \U*,%r/X"\8b^řB]tb׵o f-ǜ@TjK|)jc4sbΜRF[U6>k\|K͐AZ,a@Eǻ.Ƞt$s2Zjxk+C%K_q{nݿ8'/V٫̩kFZy)e9/(%h;2\SGhµt6ءK@)oq굘dD9{0Ь6Kq誑P$>Gux}@^eΟD(~{!|CtF1 v~j |=i[O4#êCL/'YF:y)@˽AUcT"x2\[~!JFY;4x7I837Cבu 4x_J5)^nkIKNNu/,C>h$Qxy}jw{ ߣzȬqۗd ϫyL膴 Y!De{a$2 'Ngu!LĘQyjcfw ;U,[a_TP q[x׎X'sY igx|DcYf㰯]!UJa&l5%Hc?aЪxt`PjgK-@^=wWH2Á}T*νvASO=PV(MaZ:jIzT򺻩oQ)/SBx.[E鈥PʈVWj.Gly]Waçu{ XP|!ƂdX^ۗubKPh͢4f~@7]0]Č+ zuE*8ʌzqT"OH͚{ϴ"i J\'96``yCxWlNk07(jEx+d72C0:1ym"8@/>ja}H=.V|vxWnpb=GށJk4y' UϰSz4^Dh#h6z ]bdD8UE%UaLÏX[$D)4F'ꥱxwX4NrE&+M|Yy}96^xpdDS[nMNRuN.iM鶾nt.xo0^P #>`Ίv&:khâAM"8YF[mT^'nju~>Ga./ÿZC_r@4.Xi޴3)Ԕ,.~+•֯qSACd0- ^".A 9H7'6wF\؛FnsOs>A+0=9xsZ_>"ɜ074$UhRj%= ,`^ ]^WԀ],#"Ӂa:";iygIDA ڭs9XpN'J&S@Cv߱l{O rU CĬ}&~j;IYϭG/kqƈ@n*G)t=p_N ֩ NH?ױrk `6.qX $mώ~k DTU^p 溼/CLd}Ey}b0 zUd\b3"ej:*pëƦSOO㧨Ϻ;6dN) 5 :}q]aIARS5> 19G^ ]\CQ~mw0_Z5D`JuUx$6u4t en^ZdAUT7:c*joȣc;Ղ VN4S&RYfHm(eԡ'.>%'i﷙ ?Zr]]6}ATcr!3>{*Us^ӽ&̪,|S4`MˋNN=0<ӣl )Ii-b?F@'~#fqsgFZH8㶹-(@&Ta^c \A;i g*oH!/z:!k`CQeY*)oh^I865_m,z+BݮhrAkyoBxE>], P&oUڮق_6##-1XbLNXX&:}fX#AUq0#~j!Dܣo> 5%!PZoNZxjp>Uu!32',c`xԹ@9g1wTׂoh+h1蔙!`uĵuPNL'EXK- oj~Ԓ+$ FPfh-$<1REd ?,e*0^"^+S=U>L5$‹gzOG^-X 3,Y7Cg8oӹƥ4k@=@ L(B贴jxE B]bRĭdc kx¿h=g9{ի9OԾ> %b*Hj߅j~'EnpF"LJ #nUS!SdiZk>2Je[kZ[f 3lC0毒_o4Z/ A<\LZovW@ȚCmzg= \"jMLbd aNrßeZ4ZQN}2U $yfuetXD&F.C;v Z5߈` 3Yٞ>& OtCPpE%ן_5V-ZbqCWE.'W$8d)7Oޅ:©J%:`(R4Ϝvh!>"ĭHfBPRLUo'{YRsKr1|s6zp9tLVćn w[RlyZdK%OvC[>q$3C{+q &ڂBݲ_З=%VW2xdH6:wC#߂ΈjJA\ 11T_Yey;E}1Bo'A9J'iu' õ#reL ćJ5{tAuB iPݣLg!WGDQ}[!s7c1?R}*n(n^a m@"+ 8" P@Ȋ,l $)I͕A9αIimk2KdFi);ޠ9=)/7!{+zrIhBT*1>Mݜ,QB>LS?z(KdbK4PifKCϋIc,brf"HP&`@hoPr_wEX{f !iBBO XӶ%Im t-I%|6TZԱ0σ'!aF,5ZZ/~M:մSEV\fGD ["/kB׵Mo~j܁롫 @~=v^(s3i'Hd14: baB,Όl~ɛ:4zyQM5eaF.ZtYpݛM'=AC dfP-': *ǥXz57Ҕ.8K8T?` :]Bާ|vP^#3fFg'ToJp>Z; je6:/X^-t4E9P]ZτRiAGK ֗OѿKUIJ~ Y#ޖ-OZGV86dΚ0' tDEBXphD=d5'$}`$*h WoέH̰M?ʒt2nJLm|}=粲ɤ6$?:.zqDAWg齷*9=j 9`2iRpeЪ]'ǖIj `mc#l`ݍX*6 Q@qaoaV׵m\;h!0 LH0-}; tkjɎ@4)bЂ<a`:@??ò3)k4cQ=g]gI#+{^Ӧ]f+xBT5 <\-3^Eu>\S<ԝf~3m,dBx9'vr.~ >s a "0g3doɲJqh^M1[͜sB6覈KrW,j;.C˄AkU{@7c ImZ'S):gQ8^>VFХ Ѹz^>ưc?&LlT!I4=j!aSac ]6S K[C)q*olitkXzЦ)G^ E D'Fv^`"SԨù@o&ݩ;9ts`[q G#j*. }P eXPhW$898سTu$RVf]AgY$- 3z Ɛ#96: ΈKϖ5uuLdLD<5 pYs8|o`T,bp}t&\1WHQ3FAcrwjnh(2Lv~/tk2qXGI1gRCY{߾f%:AĶʋ*i; FFֆ\;˂S"׆);uZ = R4>՛ZKyPHq 5WLs~_fnFr+͈0TY@jm*UBG`3*D&5%j]³nia Q=]c}_ gsޔ6FحCƁ8D?K!-PDcLvtK2==2+X6 1}|t#8ϮՈy%s"IizyFmB)^zhyr B̭ ?kȣ0? 0,˻&?jI!EjY}$Q$/6yhsEwlowM.YSq)Õ))6zIkijܐC(sŤ #/++4XɗEi2ɴđY\m3ԥjĹg[U:b2ܜL8]PTO?9~Cp/7>A/dzJu.v8D\&O tl Oa -J"J|RWyHmwgD0ܪ^z`hX-Ȁ*Buw%&CiϢAwdqS:uq^NbƈA>+;*^'VTOK_AmAIe!siŎ$R畝GgKnCHY -ԭ}idDv|=Y6)k*)rq^q >gf bѠKn!yrEkB&QKJˌ%j|B5/@Aw {s6=akUo._rx t, z}} fu&9 } p#){Km쪜Υ/чӝV:$R *824c i!yQ,+z֒Z3Y,0#I-g+-9Քr߃"&Zel'QX-jN[!sp[Bx19Q vb.i UZ,iH 59Aȏ/2;-c6vodJ tN3S^rBFG_Wx|4z{2朓G|,n||xUvj0A@ƲZ^ݣ7:ȝ_JycG/w1@nx57sin'4oG%7ω`bN}xZ/j-BM@aWK1VKS~VF~>;cKpx<, &8|V;OX H ;'8 ijCJcjYMWSqIĽZLзl*Ƞ9v-pc69mӳ`b>e:I}Y};qpZ˄3t:OI.rDג "[d3PK;pmx/{]ηz`iK7FR.ePpZ!S5o;i\+m #)"?,z , Z*R7^/kT!> |Gc8@&F7 ::UaJ߄ɛo t"txi:Iia<z*٧ʓ6JI^+N>Y3e<"3~39g}H9'IgBy~E٤Ty jéT3nO L(.@Mߴpwf;>ellEFAt-{ UNmZ|Pbn1k.yn*:A2bk\g.)* :H{R1\EeČKr~7"Y>IP;k~׳V&ӡ8};.& %dZ;oPb1RmnZ,q٭dvem >vq@$ktUi1 c?S?X~%,Qﷇ?D&fI*\mǧ״[>ׇ {&=[ר+2ʌ̉ٵ^b #qgf6:~=ٞ85ށԿ,X.%8(:1 eD$dRENݮAxi. U߃?acpiE0W((=Jd2#?) ʾ (,dzJmC&t8Y['k(JT-MehMsjg y>GX(<4\>fjH8iQ <>{U:x9)R1aWtm"XQnln7FA:E5ؚ*PwcoP,h[yFPR2+cw5:F7Ui- ޒSkOAΦ0$,"DGR05+yu,)>^< `:رyVw8cTBӴaͮj:[ʋ##&|NZG~o$]ح<1B[I|&$6`RuUR1~2u33##Yh;LWamD籅-:9SI>Ў[`XTD5h4mg#8J.$ru2ao :>\ 7 hq|7-wQ]3>ff>b r1gΗZg'Ũkxv]`R8u?WqSh { 'kM[ОӎrӰ+'L4md(A64Vm;~{,&[*qfɗ,?S6oRӌcAr]Z~<;sڱ ]xA8i9^^F! dٱLg&q Q,񝜻#|,kqý{=ؚeӛUXԂ[Odv -#$*xɖ? Q4y;?3Fj#J.+?Ξq$/WԁjaniS)-̷by~eBc;sc?&tL`I.O,K#fqרyw_ #J C'cMݾnC`1Zg4)'8d K?r܏ dPKk8e<j,]^ћ4vsHQq1x@@BDQNoq부8O`Z0T^^{nU.xYqgO o^nnTM7ԆfgK`>QmQtXSNˑDVNtkX?K(ZG" 3XR30OlzN9Z;nr` ޶z_3-xTLJ,2943'2 -rf߶jQ6']|sKn43Ԩ>;w BHUz]u$-ɘPxj'RIhEII. \] SuQC&Co$ZG3 8oWv})"+_K<,Be9:,p0ݎ>z}:]JAm-n P蕣'$[c|X @ ·<p's y+{ScU< [b1r;ب\vŻF٦wa laܳM/X/45ΆKV0W6w㼉!q B Cy'%'JTAbS A &Zn$%h*- %UEi!]A K2+'[!_(!YF(",KK_:D[}2[gkH{܁:5͔cM55 8>| *ʗH8.|bO{M  B22-H@9p8c D>8ƍhZT|eÊ;ݨ-#o{Вb~ 0gpN'vZ{]p*i"<6,!uۅK}s؆/EUf]ō&=iGebl3u5|`!0 7|vӌ=&XzD2z m&l8KGfGcf2Qr< ISG-aDNh߀0FJsM̰},bE~٠cث#j+؆ 󃭌Q#p[eB؂1^'D޲mRPhDL~b' & '@CMt! %ayReE7a ^/̙TX=|7F{q- f]v"[Ԯ7y0G`'E;pE)1h͚&Gcb/5G+.H?Bc  WޝW g]T,6f~µy3VG,`X݅x|T.FM\+_﷑iZOeMh^1j1+> 5GRJ[S+KvSYï@B!bd;olͷ6PXA@B/=E`f?>*(E` O GҊoUȎG x eDw:J LWycM*wNwUo s /]&EcG3loh%DJ/`3J< :䡨Hf(K } ҍ^;xBWjddR/pv.d *]6D|O-ُ:EɔvC??8n'r=Y̞($aƅpup}]]86OyBy1$rʛ-˭UZ57`/5B9d ?$uFn@7 v)Ȇz&߆7 U6$V5sU4+Lv" h4'恆_9ۻ oeP:XK =+I45f^%;o;0bǹߎvV 㔎fG*u8O="u'rޭ/U2̜9J|F ,㏺a>ѽ`dt Y(sZ bI~dF/:~escg5PVk첣btI}?zw'BNgCO0Wx? bd.`:e ~yX,@sWa9?@1 T'4[ n?Mww1\?,*Wr|;Sw< |aޖDŏ#{IR s%l(>.[ !k*nzBq찑ɪўYA'$\m*cY*q [O|D9Ƶ#3Ԩm|z?9G"96(CdR@%YCz@!?o$HD9͓ ,_gk7O!e.>o2E'c e2 OO<1US^}| YGxYI#ή&P@ju+bu6Bk`]ށB&FD%C %=78P]"{Q&Bz pJ%6#3i+򼃼#-wYRҊo*PcVJIJr.=>֒Ç+N&l8b̤`+/Ÿ׹kb ljWf~ Rig>0cHN pX[}l/R &̭hI'稘sh3OPG sN=@į+ &N.I/!.@a'maX aϟyJڔO8%Ρ0-c:ɦ`[}%hPeDJd(ה8aXO%"AT1,Od ].!7ؙˏ"00)ꦖ֕>ї^ZmKTID>EQSrR>'}L=uQW[`7p ')e[~9F?Ԕ5; Qt, Zy~uy|ˎEG@_{/&Cݑ g$*\%:岫ܺVĀ,(I'6@t NüKԕ~Jg",$yB(6ϵ-̵TݔѿdchqS:3uC¯cS@m@<>Q[φ]ȓwIAu*Ҧ4LAq!?rTx[Q.&sT[F"ޠ& )8\\7L_%$]}+d@ej k-WvI.8~N4Һ=g |pıxbcPle4mPx_ݐZ 2?RGB>7#ϭ_w/yI9g֝h 0fet0^+LAFgGCBS?⼮Q@F]#g-.f+\[z]68xyfue0䍪Tmbm&|:ބ;չ%93RaRR p<ܯf mAoҾnFf-Ww%tEwÎ0;2x5HsQ62 F7[tfwR6(; :s;M;SEJ}ɯ+~" `a?Hˌkת O}8*]ZSҠ0p_ujܙCZt(N왦0SxG$ gB!ql)fb/B)6T"Q#Du`3Y<:ByvK.:tM!7)ro'{bKg_zɗIbi&zEHDYo.@qx " BŘ!PXȦtil0;qoqje&\Mo@L'ҹ1=3|cUxi1 }={O;J9s=y\CApcD\_ N;n FmE_^pҬ=BϿ[9e׆PAL=:.͜ig\-y+w?lϟh)˾V}0q*Ӎ8juW}0r7dB}X 30[ S'\ (o.Oa7c{ 5> Ӥ9z6".˄YԱ7tdBP`Ɏ8N#%UvHzf"02g_ d/)~ 3#tȖ8J`W8HߟҾ~FtzpA.z]YѬ!?.3F^.nVU #BR,Zׄ\"20![6=zssUYzԜs`\+|= 㙽ϐ2\<@OXSFF?BuQ@x1Uؙ`jnD$eM`Vwn7P& üH.Sɗll僰o3k _Duk+X)3b\3ed㘫 x .s&/ݰP2]_E+bԭQMO偪`JUTUԒo0DV%۹L:\n|8,3([n1--= ϻ ;SmΚH/5WH!s6"1SGLϺ'@ wY: T P-|a}&rBC'vmN%oCa^¥jf95hUPf&ST9KOjk9[pJ,cW?| 7>,vZ"I$ Á1WG%z+KxLj&S{]tG0DT1C 1̞qm6(y-Ȫf Q]JX- -Ζd1D񼊏^j)KA},fd'A_0_4趔my%7kTĵ_s1],\iϽB v.BT t7I0f LQ[hjOo^G(ׂ;c0U,"m.ެ{=ɲ?BGg yNꌩZ(Tg7G<${M+rZ6ONQ ^] &R->kz0T٨4Z'?R2Yn1"KWΪ!Gtrk+] %`̓:A<nٞ̒E3}?#uǁMWbІhѷհA*bR߇jE4]FYFd ˸le3ܭ%fI8_Yc+rq3CBT5c,YJN@j9wAuN7[~*8|UMB3qb́2y[c:Xs)=n4UO)khLe} "Nho/ک愺͎Jä*[Eu%g幫h 6ʬ+P^}m9VPa~DE{Rk3r]Z;hq :?}@Y3+[ζK(E=I ˦\SҶ ~$"_IhݏƑ]$+Ur^>@8o>>i3DSY٩#exn%DP=ZnSn0v<©~(q_0>yb.^9h' ~\W"%c= 8OGv k?>f[(^.=Z/v?7WEVi\ޙ6JeI!! z`9Y?ӻWJKk =/ޝ FΚ?@IHFstTf DvFrZQ[~ *FW?tK];qؠ0ٛJbKQ7VgxC˳TB(sUTJz6ϚDBك:!Ztq=o/R"ІoV ›^Eɠ:)cŮ蓼iqrWxuӈdF] ATSxlƿjS]U:+8\ͧ;fb`L:RC=p 3/=:E\)wRr~qnWxaώdfL@Hҥ=( <#2ĦQsТ7/4Oo9J*w,UtOp7j˲S̼mpZޕy_9NEB p%571RS?vsi ;OYUߛI5f)P͵\D^I UiemvَؚU:,|ێ M= CB]WZsoi}> }Rk%N^?Pgg1L)346Ӏl#60't,SüAP[gU*~tlvH66h;"u2!%qY&f257ڍ>dž޽E)<7-lEY}ͮ\E TafWϫCŹxgsp-jYBYݬ ǀ6s={c!kV+G7ɓ @փT+$D9-@Uo zpRh;PYHQf_ _hXxUVơφ6@AЄ[4'ߵA wΨ'U2\qKC} }-}b`Ni{Op R̂s:n#36OYs *ՉG)'MSQT ISWF,=tߩ,"rm̿<#OyB9K,V,ТzW25ڰN; 9 />}tv"`A7~}]dztuڠ]WMq!XREbWScRL QaL0R Fl!Ke빤JAШ:lQ47_D plX!؞k([=\ݕwfÓۋזIEZsc7-ݐrZZA^=ǀi=pt"xu4(䂀$ô&udp(*WUV';3̯9:@7]ޯfWfH%m2 ҴOqU`Wi{t }u#u&j9ʴ :Va:c$,r,~VՂ\5>%#Ӛ3>)W;Flu%РQ6O*}6EzC&mEqiQ=+{ B ed%'kb0Bl諃f'qe`QʔJQ)a}N" ܛ"R ߠ#AӴߘ A!3D0#>ƾF!%XEUzwr3GbL*7vU߳vi(h/>1ph=7z$AƝ^N":9Tke ޳x1)]+}E]CN$*R.Z /nd5QHړ/|X}bJ LH36.BG292%&[kz9cn cɉ m 5'1?qWl! TDzu@l(/xn+$6Z.>!i~$Vie_Gs%K/dJ롒@ҁt I,)eN~RTETbBg]f ߾>O7¥:\ 4X$c.5N#1} a.\&=*/)%kvMR#: b^q99 E

Tyλ+yXc3bZV*G 2}EBϽe:{vvҁ1_jAxobH-i2`NAmqli~?*j.^97i2 ^yx"Í9 0-B*Oaoll@|{~ցMA PgsJ9Xn/fxu/Mc>ISN!\S{ TWm? &dv(pwg[ 1ĉ5u~H]cek"9 {`mC|4'*1v%0I f9fGal~R}deHM/SsSt3tՓv{4&/u&lGtBzdboS%8B__sZ<rL[-QNr,{aPM>b[j[vY6_p2S0fly`/!plqwԪ?]pEF9N@xCMPL3#n@5Ff߫ߘ`$ ػq8~ Mk]fZ9P6s ԮE#a ,E "-DSt\H> ́nA$ Px vV}YPvm &#jt Vk"(9CM>^-Cs/V!w7|Rά2z? C;9 Sbh:`m5tWc// e(P5SasʾpEyjZ*atPSasO`gm/M{$ovj:mUM1ޝ s(ޗ$af^C&+4 ukgpj=l 'p6BBu or2S& ,qQBˏfre&uL+,u12輎2up%'RdU ]oWb6]4=HSD_9?.NJgOrǕl)**j@+2 FCϜF/o8%0 =¨ƙaM TZNsPXR)b\5G#$#(W{=<^|<%~2[^$V? 95+Y+JX#6X1 F7Y[^:ڸljtU=k,A gv+ $!L[r\M^V۝ZOIvo\~.8Κq=g`rpc-͟5ywh} ,bʼn+|\{GSƀw/ l&v>={bvvqdwU-}vH<=sjSN.u44[srRǑ7,Gm+A*!&(<qmxnPA/n{V@N 9vC [0QljºE\PX YoQCԬL\c{o HMΝFE&щش:9Oco:MD)jm楳 ejXm8w/)KH֣"{WJ Bog_^|g*8i,XuGvVN/ DW:Sv0ϊNEe+ bX>3S8KN7VIz)//e̍3BowXxKp %dO3Iֻo@?oFKu"hfY8QsJdTUc ʛq,GMW0W^PyWxQeN^Ɖ4dyd%5 k]VF&٥8Z΢s-_3'枴a;%# k0S)'P./V9Uqp7B}(QW 5PCzRNsE^yf]D~B8xW4H*|xm>KB|9?KZXipI2aT>5aOC/IQϬjMYeWL1]C}r|L%QgMo|_5 (^a~ !BL]n%toݥjKSv lP>0Ƨ ofVYa֛M GG_> ;0=@< o/s6MX-]؅R(Z1 _!xS.jNgZ"e|S>+_ ̗lN;9;@Z=XH7\qœGľDsBsU1sVѹP(ϡg_G0 O,CŤ=8̈́R_Zoo:t\e> gHPFaR-H1Cޒ%=/Ϭr 帾Q6]'<)YEw$PFHiNOoZ6T1[ wF?ۤcoH,7u{..ұorx+ %Rz&҃t1R\6W#4}s`,wEڼulI$P7Ax!Tz&Xs0O݊L~tC#</@7"llR:K}PvlP*/;~YFܘ"Ѹɯ + j'V'BsƼ٠^|9-UBz,-p0 " a1cg`ͳj1M7z|7 BӍ}$%F=ut~u͆sܓ7k<3o9t>ihu31X5Өz<4GIEVFn?wYb*Cbn)e}~MxN_?I͓|^ !ܻS@pNU"/C{jÏuh7 @W픪n m0U+_.?{ YgH3Ϣ3M-rmV?n"'҇NW ͊z# 1Lsb[IWŐcӨ'`e:c4,wC*O{:/=ELWPu=)GIJΰUf3Оv13#@{2mx,߬%dnGƲj;ocJcB?`qZm0BIǵW0O&dѴ9mRVư(#AnMQA]{ǶiÕīϻh+>ػ3pc5Tߨ{*G)RO"g=`[ C{/"xA)6(e UoOvWDrZv5ρ;qٝt xG 4*ˠӗLu_^MG4Ky~9Ȋ^6-{j|pP띹Z< Y-.=6XߎEauM^>Be}S8;6[ftmـh:%NGw.pd[iR%ݭզ:H(s5j{n@r|;NZj<8Lڒ[DLek,Sc6l6ʛF$ZB0$"NY `K^֪D{J%E -Q: 6-PH ft4V^M4t(>qaL=Y9&Z}@ yp-9ƛ;Lnej }&#섡G&wC9Tj:E63K~|_ެu$>Am8o/V-.7b&%*~(tbA9T.D%O* \"H_329 &1J訐6SN1RӍ. 嵯\s @(/raF[%=ZkjƧ6^ QHIIԘ˴8‚6y0 NJQG}~x*& kbARUdZþ&cyr3g_:2 pd\@i 7yPax Htgէ:DR#Q6W-#WI۾€-Mds4 P_zB ,оNl7,m?4/>KpU+^P*Y9s [ne奬#;bm<~{G[)|~M&#U=xt UKdGi D専j!6,A  ?y* faY7͇O9-Z4;75u> ލe`AoE#(nvme0(22X'P;]T;j2E})'h#L\(W%ξA"9).7 Xҳ-V)!Gc"b8>T LPpI5 ƌ#v#b =j'CJ:V^5)n.TKOR{a8_Z3vh.צ?4wFp/&)YLpychM&4q4qcF1{0Boɔ SK$-XZ\Bn/W^$}Оrv^5yLܧ&an`&/ۊނ~%I9.a:Y]W;@-~mJ kDAH5vk}͔qՖf[yO\ \l]AF*0)߬V%WxH+*E˩l1D1tse~Ht8jLP[8{RE7'&yI\4c㥴^؋ۤ*<:,8 d*hHrWuzvd Fq%)yZOpvWN֒[.9.Y_+T?Y3$3^O#hE[_ hs!㷾̈́3Uɔ_Së6ojuU2}9 ECNo:>Vq.":-uIf njwe3Y4}Ֆ[tccw~!y\ M[gxO2ikzF&' %%(} OgJDcLL{OY/ur6d]OZZ{&S|%e(E΍Ceς?$B:Oi֪[5j m&ǀZ[.F;kխyQ==ꪂ=Y|us|pHNSfl&K*Iw ]~,y['TϿ,Ίqg3#SiI\N9.ÀK3ap5Ul{;5|dqSy#{gmwC;qj'a|Oq_:w؏ e@6N52 ; K&YFDh]n^Mnc@*.W!NߑQ!Bv1shIZw1+teJ'ٺhFv`dJm&H+=16~t2twڷt!xk}w-1#tyKlSwHG6`K]'l^-GCd.kLF1Ԃߑ\t !˽B`jtFb=TO- V۲[V[GZIu >F2ӊ B#v\|Ai{g/'O1~F@fmRLNe\1e  ˈ5QVQi+ES/JYve9KH,$I}jm:2Zi@!=Fd+j; Y0a-JhLF[ͦ,+cI6p}@z£xQ i]VxBDeT4t~01ǃsa mNXc)Vݎ Vx SJ{z}}fQ8t2<xu(i]gHisJݨk3HQ~&W/Mʲܪ't *݇j^ |sj,S<"ײ?-(+k 3ԠE1J#aKσ/!B%D;m= F|t.$!uj?d)G a[.MmB~G2Ħu>{_G.HƐG F7 psDzԸ') L[[Q\dvIo> S}xf:3&u >&F(@_}$]=hw!L9rvt&7,=(潧#f]whOl|g9j"wsh6$ dVTObY*u)o$hLbʵ_e_R>PW_i&u&B]B3RwI6NI}d:+Zw&3'ԩ3mY:F^i{#}7-Y K`S\Y2Qn&*랾{ąxu#G[r?]""e$7zGa 츏՞I^Ԃ0zmtw\9!H9g$<]H2(.o9@Q<lhqTQٷJQ)٭)2ZS Y2 yo?o q`{Gmr6/\zu);>= Ҩ- ^2&B\+LH*BqA1GԴBSUiR0+')T|V /V8 {t;y}5lTRNeƻ7іaZ h(9[IcT5OQdFeq/:߬a mClZP1}=Ӕ8Qp,3i}0 r{F[.j&9EJ#ʮD[Fϼݒ!02Y ߖ;rW#N7KV`%c-j d^;sTQU#."qXV~ ň>q# Ha;,D]߯ pS1c:V{RP9qa) 8}nA'|,Z6ruOG7zNP 23XO`'eD":s.ޛъl[˰] =ى釩\7@{Ob[S]~2gԤٿ.p>D r(jzPRIE˾wUGAsay[`K3ݘr.r0keGѱF/#@ڶ.C :IFƶ{H6NJCihi|Xv|FxWĦWw\&d3WKPy2T1>)%]}(!$X"[OƲyvv8=d ( ^ Fɔ+TָkGj/ӭ7( O~#5m9Pvl'_Is6DN蟬yYZ&d.MF e/dy`Lg1WYQ#PӆS`;`K~jjWfΊ$'h1#xY@8qlirc[7w{J?deFS{ aIR +Dkdd?5׶ yxH:dVLК-bTOoGSͬUq='(^0|4 O!4~&ClI|&v::l93Xt YB:"1IЉW\y$ oO}/ФV>>oWz-*/44SO{bV `*U,7H!K䬚|4X}#N眈h jp9GU$ƴygj^K"N :ѿG7r|T v54<FkU9CMa ;hȢR9Ir4t#^m/liyNU9J'2A2³85VúdD4V$U,nv4;6@`| K, !oq8sT"I,nxmk*,my5j.\-ʙ2u(]BgQ2wrIAVn::",=OpBtUj~?/58S|Mc`Iӱ@s}gcb*tIGv\(n*Y#{Aa f $w.N ޫ}!t(:B k[-gs~7^5cA, Ca<f azy/+wŷQEZ(TQ`R[n('nJfPPoq0F.)34TM5^:|N.ΕHVD#8eL]72г%3SZ kvUA*: Tx{Ӂ`!z͗z}LJJ^=H>d"#ou_`{ߓM{YŗXQheWfYHub 7Ap'v{6Ҕgr$;Ӌ"9.{hQua?X UŦ L8l۾C%l,Cӛe܁Z]!\]NxKDh Y(WwU? nA)>Z.%WTZ7 ֎PGC*~t%`1O8?sX~M]Wê;eWԊREAkytO?|T0GJz{;{7oNxO˖j,A)o@bƫVnP׳sڱo-lҿB65S$l^vP*D'5~s:L ]ݟ^8p8Qq& g=>f ɹ/!2)O" 5Ml;%٤Ym>?4iT9Su |Xp_!OUΤ^nTAIzH.!:HVeåGYē %8lH?mmfcAǰKDi:-gL+$1La,.`0XV\=ُ)~*{}36SV9b=Q3 G T+3J2ܮ9u#^+-EҺ1q*tSjv꞉]0z+yvGOZCIˏ]D3vn7 J2>SPQKh gGVёpyVlݥo XSb ` 4(n;0`(4~y' mb>ZSܝXd<$e{܂`[Z7X LBgs\l?Gk&Hn#i~3|` FC<$ 6*H5"ABzY,\DuH&ŀߟ+O!S6K=yqNxZWĬghMšMT}jho3xʢ0FǑV 覂`j ^禠yq-[=j.GTWJ1N0uQ,N?|3I1Rtk{HSVƥ#3Iw0ܻ|t:M7O""KsK!P:tԽ{x$toڑ̆r]c~ x#boIQX IqRNux{?dէ渡o7W35-9R(8ջZ}i J3Is`~DPRo8&),_ ^9Utgy^|/{(+^Pay=֜΅Hcv9BR[DbJ MX'k/\cs@eVսh,w1kw$2b|^X߶+ȸPU.*=ge6\u%֒| -;xszIXTqgdZ1}t:0!Ob=A$)`5C@8˄?#Ѳ ַnpՀOC"1snmWwgeNn'wO556kig"UԊ(?7Lxg\T[R435L%fd˵Y ]2@mn(Y. E]WZ4H?҅/dHv?Q[1LcnLG0b ?(:8U94vg~\(`6ȌB2TE zAHP`aYW`}mk`ډ|r}qYC>#)Pwo]i]2`{OٔչArz 40#) c3ME^ua4` '/9E?S++ŭi.a%+E^+܁5̾A!(0ǞΩq-CL>YЭKA85gXp`6Hnn?Ed|JYQߵN׳_& |[4]`tk:ej]n(HKhR%t߂gb6fqbY9AEBujd޻ 4s6GR:m@k70$OAGgtD $^Yk-w$iTWi H|eJ p8.\}pmc]帟^EM'ny76ȝ \  l[ [j}WUV'~vzp?I;b4AufsH|vJJٮoXwh((JsK8g.㈏[]>Ah戭4A!L) Tf]8?cqQT3Bv3x^R!8,>ޒ6hѠB?}cӮ&dbAX1Z!rf~03p<6:>s% };l8 F>;(^TZe(+ KN6PLfX>,#¤faE(W]jIs-,&yH E5N Ci$ot s|{"k kW7J&iJ""ϟzʛx}- ']kxy+9+vvMdf JP)g}\. 2Ʃ2m*@oiAھ|S"ZC CBZoDg}˥[_@*)9' 3B,(xڥ_Q݄ae܉c+b{UD;*cfA ٗ٬4 $p֩Aw9̡~B<ȗ'"W >9_ _mjm!_-'`'1k^53Ipp~|F988uʢ;lXuyTviF q|HOek~c571xg9+"I66#TibW!ЈMe4+le9D{+"ﻂ>gNtQ 9/CQu<=^ې|<͙m8' dO]ɒ.8ϽK0hy6JaB O%l#+9Uf6|&"xHyB$ ~eY. !iDeD\LOQ Hc*dXx(xJ2tf SʢgԱgW6QlIQ+޺ tc$>s;vwױȢ T, $vv{"4x Bdߟ=ECTYUhٵ!qnP}! S9v44xV_B|}3/!b1`G9g}%f&u= 0+zpBY(xS91*3HrI!y)E@} QS!Z-P0vvDIn" -ʰQڏNrP;0R4]9].@]hl dA3AS9,WүN? |g 0ڰA3K{@exHiq5:_uu Sh# wؖfd}7jjn$VuYoRM埪J}dLqQONxS MOkĕ 3dI&|ƊdDA~E$"1|3-`U,SG:$/5ϸO5xxwY2'-tĦ FhW'؁C hZrG.=؍Ɖ{f8s+Bke^Ț^Y}Co/&owMK #S~^Q]׆BdR+~RX2bSsZW Q5a;1`*kMPJKSpK Ղ4:] Kvf2?}QsźLǶ!0Xtڏphƿ/t{r"S^˪$A<;)' [[P!06iJ* ٧R ,\ qhK CUu 5.*N't_ ê^ZGC.)V+~9NZyzT{'oq+s8VUu窴\'xKElXfW#wwc4 -+:9y[ziX]< {zk-u6pFjR3̦\qKlp]p#ɱq\Imz_&V[!'n%LȞYDk#Tr3dCH܀mHccJ*xc~W6͑o]H ; Of1O1Y0%F9*L3z_G'p 5ý?)z>x&=)ċSQ5;)Nv;@9Lzl:>\^^j/Y%`s)Ƙ^^_qԛBㅜVCΪ@x KiGSV ,4]yG|*OdTNsH~N9&/ FzOo)wWx:zN(AD{s4C#Out)cr 0_=dRZ u'uFc!]: ]%b1mie7ʘ:\' ϰOk47u`mZ7x|EeX`C ]6*BZ:o" wO)8 8v uL瑲ey'7UaRËS[Bp,vW,.IH'7c riֻφաk, <tfqyf~ -RM]:5CJYNunv'F ,{t@^4 [HGڻPf ?柜|e o)Fcs.ݫN'> obətFe<ʱ( TJ{$S EAw_WZxY:_IHKdk (ux9 [W@>5A?ZЭC qp+Pza/ XOq%;ZkJ(<*74N/8hLL"N$?ϱ`X1U b koz}Rc nbquxr藾ޛM(*{Im=ك {ᨀl;h.@$O-ШTA^+G$yq'Ej{nN!] $ v,`7p [1"+vgiX?r7gp*O(NBLw)%말&mKU5 ؂@^rk{!b{p``Bdz3|=S5D jd  Dla Wf\텢+ѾF\b4_^_#tQT"НJP&aI\ʚ yC%Rʼ! 'O:n|5к؎]ynnfB2|sIB&98p"pu!9򽲃Y[>Qwl-H)(5s<(TVXmAف*\Sa ⨫dT]]|wixZ?Vc!;|t6FkKl˱P;6c>"oS>o9l_5+؜eE *A+eibpj.8b<'c @( :.f;T[ 3 ;0cpAaϴ,&1䜁 $4+eru"_oM,>^ݓrU kɒ<$0m[Q͒ W))BÌ}f.ZjLm܂]2X-nЭxC3=fZw[/ 9FZF~f(L˄yY` GF-Qï*UǨkVZEvB m *qzD`jk0#p-Jwdd8pF9U N.r׋((v)V6o&`qڟ;a׾܅!yy'.8>%.rEfMW~1(s\v'ciԾ,g J̿E;P8hdk"b&7SWͷ} /ŚP2>"YceӞY s} ƑW)G\"OQX F%`u(1pA@wKb Fm $i2ToU7{gB\c yH0+9 睋QVMa=o ?msƓ~d.-NFehhzgoBE28Ⱦ9iɊ;W,+9\>yC<I1BZM¯ɦsdC]̮“N<|v ^R-4]+7(ޤzZ@cI6HDV-A[b4Zc&9[7O&QZ~d˧룉v> rә,tآ _HDA@~{$2AyEkzaD@ ^5}! Ўߗ`g]+ o \L߂k]!Ġ ~D q[06nz먀RIbplH6/T%ܣ[?U,g?PG"_%ʦ>70 .!|nbr,{ (tvu؅ /k$5cNZ]; Cڙv  ۲ 'AcPpkh^P&9?'(`qe HzncE:pR qɊCB}Wa׵ϳzM*Z+:3JVOayHԩ֮_V/&̀@䞞#h_zj%4建װ:sMR!o)R ϹabqʃT=Ŀ)ab䵰 N{;FKy*Xb*tqO;Ԋί[AxH$ywZ밭Raj*]zջ܁K[Շw^44QGW5U)'%R ]8qV~1jI9k;&R}uaj:U]͹-۱L)hTz-eSyraneh216GD8L(cY/\b>f,],b25ZfHhAWDh/ vjKTk:\?r#+orEFi[>"9 lAyp%̬# U-"91Z\*"c!|M8{p+ID\&߂XDŽﱣ+:3­CUp$U]jX]M;4tjEZyJjv^%B6~Z1LdHQu d^Rr-Cpp9yn ]9R1œ?;r0,ixoyUU}7<::5 oĤᔒ^xf\5lr3x 3hf.tpr~ʊLUffg<ƱͳP_f4J4QKwZ#rg/prۚσ/}>€2q8?v9OڞM4ک$cӌf(E=dv`̗A ӣJ })X=w㖽ȼΟf1oۭЕ)]9΀1p٤š1VJj]&rc?74 -p_Ϲ)6< |Pհ5L&/@?W pA+RzE^ߧ3$㈁+mn"!쇋s#Jm ,R2VJ6w<,}S7kP_D.zaE]K4Hw%Gi+=MkL|v">:ŬT1Ccc]Z'g#"K.kD vKܜ~ bJǚyul;)II:1j;+PBދCxϗdvhXt 8cbn@Q4 ',);Krk:Lc>D+xn&{JD4Nd:$A҂^'?+̷`b}(9!:^vhX2;L,>$3ibibt$J4Tg Dž5%'&% 7D*܇`dKf> ~)yE|0V48hc_}eLJ Ю'+u K%4w/5k.G#aOC!n%:Z F()tgM3 'y5b3TY2Aiؖ?w~b…DX-:|q?է1uV1cwη?0( {0}8#t5jxDd'3\rCX4W G6 :_H|XA!a 9jzL#?o㉒v]=ׅO?ߝQ8jt,G_wDL2ߔW# _ҀM*);xu|6N([!h>`ss }Z}9`'G/aMb>43oLQ,;gdi0ZЊܱ|N.3Bq:>깸Ni>'շ)1eDtAHA~orR&G)!+-·h%G#ɼX*Δ4gLԠX9Sʿyx=#dC)GN;?b9,m'B_f ޯ9hFj(*Q(M_@p$`QD3˛qiMܼHV⥐Djh{J7M5Bf+1$%%4I3!ML:O8@$CG׈0џdfkvHv3ɶ,VI@N$t_NaR=Ֆ:%wn_)(e={u=&H/;摙R 㭉{{Ob[0#_lܜ|۠t,$gvV \W\oL銭^d[m7 * ! _R{nTٔy Pqt1݅gyK|ͳV~POš7bNjRD?4גWXt@5hJV4]ub!ֿ)h(L>hv0==6- zZUAb`I54: +#4H+3z `v巉v4q"~Rl,;/_Ũ M^"(^S'7DG^yR~ž!ÍeY(t5K`bX=2غ#)mHO+`{/K:\GЮqo<>$ t!λ;/2)HTf >FPU-M`K/ZzC*Ȳ˽߈YH~'oxL=t Qdkp z[?Fޙ ߲*z}KDAN37]A}1Cesmb-Vx]h1Ȭ7'B7񈿅;vvX;$H2E$'Orck|W+sǜv^(ivCƜ%t@R E tL>@/M 1bJ/8`~eP7ֆz(0O&%c/ nM 3X1O~hq,%$Bc}Nvyߺ ,!?K8v gdAեonm_[n|G\ƵV-IWmo͵l oM󶂣f1>-$a-.r9!26(dؽig|?{|PਾA01~xFKp[K V FUxTByNҵ*wdt;͎j9CV'bCaA]dN3@EgS6ߍmmT,+9YsjH0܀aBclw%~ OR\ Y0*N*'6 %"J߅d!ft}XBmmmpTfYaUżH#Z J"+Kj^S]ƀ#HIO( ʃ}ɨ޿' S,*Q(T]I-lMW(Q,|~hUD{pCڈa#tzsvdF.3>/5,kMr򍙫nzjwiLEjPh#$&t+T,i_{__2]X>䓌"Օ&!)M\F/VVk]?)IPKksCDTnC*9}HK{sxE+pYѵ1#R} ΣӜ=sw8 QMMKW'I_OZ}&~Sln!}ߑmz]6 Z Qlݲdi$kk-m#Urє}rBWy=)3,};V#F QVj 1Y# = <^~ 4]D6/36WգwԌ…‰x)fa_>p8q_7`*DYQ1?w} ATEB5]m 5Ys\ n%K w MKK{ۺ FBp~šcA5Js͢t3\TfKF],Q2TQP;tr%fҪ춙>/[QMΗW'm*B]fQ(rnj7hwKe腊fx $K90/-0j:&B"l(otCVX D2<]8eyTdE0jp)KzƵ`}]L${hJLkMdp4I5澩wR|LD\']d|MKQN`$էQC89G=c&4|9\{Czu?딪N8C'#'J|9g!%#-t{vVQw6vkYy  $οyOc[Bg[Wןgf|*He\V1ȳ~uM#œ4i %4 [ht To !RAI]'sG輎ł"H?|捡Ow$Ua=GFͯ.Ѿ=GDWr T1.=6>8 m1Y|xS8uSm폎@޶@s@2G!RQ,c0%=ڽZB1ɤYllU60йkjQ][s1^RHXE#KۮK.xtZE;Qa~0-AUn`Z@WBF}:8{{P5b'%Ri|ٯf|cR󤝑FC&,74Nu܅IEa 2'\8(HiK9TwٻRXYkk)S(2&wHѵL@f/qL  (3~BXBSS+ m)XD t߆ɘ|5U)}6~)h_"w#I44 yAFHPVk͆F՘Od9b==\!^%Ok:AstWpa9(emTJ39_R{`E'.nJ \#ښ tz1x5B9p \W?%Dք+ID٧M,1B@'9 .{%Eh}|JTՊ HMԎޓ,q;&@v6(^։jfFiiu^F,{} O:Z%$[FQ AB"w]ŖyXl/XCNGʴq>-q/Bv?W؝E켤ox4[p))ӑnfÇF7ȴX Tl\GPhԠC RR16y@:}G6KYV$DpdnFkAoƁ5q3#vN SZ9T` MPKX'}%)F% *BHJR䂊tL44Ghdm4!9ǸR{Y81h|zT%_PON'N*#ivK7@;YXn2lKُr#(%~ߕ͡jWw%/XTyksHt. 3JPWpg) %TOmGl>/3LUt~bmj m~[I7i=\!&oJ"f>+X7;"ţEbс0Gg (5L>EhP`󟶞|Aob1+x;9CB\ w38.<>/*0.c68i/kTY01JMɂ?U ̪%gyj]~Xգ] ([+׶~֙L.'SkQj/S#{@Z#VR)2G]#Jomyt߿Djajt4Gh6z#LJ&V :o u"Έ}ˡz>el2aYJ \=eLsa"#f\Έ4`. A%yJe+ӨW 6lu{2 ] 0߁vMR(MZO𜩤2 -/j]/ a,+MI㡿7fW@fqȎ/SJ,|Fu P~zq6_ D ]~:aL6m`%Mno畂$ B8*ẋ#h=8`41QܼCVNC;HyorS:[2C>mfպW,{s$=/* c5rwBx(̐O%r*Gû|WW}*DQUz JlEG*wTDsPK)*j[ΆoC=_=㈴Ύ2T!\>'y*̤Do-leD >n̒~jKR}|DEL֥|;zh X5MMpTVә L隭NC"Tfu٥+Ŗe/Yafa/Ds*u^;]䃈~t2*mjtcx:t 5NН櫑'<`) 䚺lli'1B5iJ: -A)QWAOc^~&G71bf6=mUkq\KV)#ѵIF*k0gghGǐG (nȎ>,H]Δ94J[3Dofy&$8V%˦\*`WqF @|6_ ^WIdif+0 \_FS494Ǜ˧Jò3P %o;Rp7Vae4[xމzT<uudl%N=Zn20)>Bu枚:NaˠB# Al3xSCTh4l 鱗YsFSx%sŲ#(M]B*ϡMRy3.*Ծ\ UA76F>ծ`L,w6EJ{bGN6qoFd ΜYV'TWfg` ^X H}^|EjݥIZZl*5"5Ul^JK,Hdh/=oB_@ Fٟ,^cb$]Mϔ E,ߌ+H(a^u-ظc8ق\-3MYFu>%⭜S[\Je#Fߚʣ4TP2sj w[l,op 4^<$yGma&w` 稣2j w3gKBl48/[iF8u5=wae}sxτbX?Yz6 ^ΉqnΝ/!1I*1g? b̑X/5-﯇r9pj񶴓Me1*i"pX5e9}%x%"ܮ H@1@<9QK^[@LCio"˴ك V۳1iqZ M减^Y i@BWKx:Q>lUnk_:fvSt3tQ Û 2Yb˖,tou6fsIaXW(ʜfT;;5chG KŖIH~ 2hP {rt4ŬsaЀgB_BozN=tG!.q6!0Hxq7 H@BZ*c|| 6~+^]X}ߜDJ_𡧀;|]Fa_*Qڼ(mz>Eq=]1Z .Eɖ#F8?еb=j-CTއ1Q*Ժx5@}2-G1y$iUP4P)`\EaςGN_ rM3@’2i'rnئ )5ժ jnw1 X+jPٞXK vY~ӠT{uã]`"<^*gTO034ZWzgk]6 qx_6Ѱ:σ_ MX4 =v?85 C~ ~d~tv>#"P!|,Amj}C[7GֱOW?񄏙]9xLAiF >Q裂EDݔWgHˎiU׈8wq>{+EGNͳ_@B[AR?X1ʡ(FU9,ZAA4U<%RjKDN>͋CP7 DSɘjAMQa"!jviYKC6 lt)^q2($MY@Kb@7XBCdut"WYu*S^{Ysr钽vB$a(f;8W7]Mױ@mq)%L{/4ջ$qr>pPyb,|\]3֘< 1ruzfAscu RY}e,^0G$rt*3h4CA0eϫMR&m{PZG̻j<\Qnh{3V:zi*Dk21Ҹ4@ ] YJφQޔM#X2RC9 m A䍒~?Y(v.qA$9b Fcl1F6Dw`@C6qjJ֓OXY6w/׍pnJ*_ZUZUH3߷MPp -7Dy>s\zL[g}ʦpA陀#uͷ,2*}(4-sGέjӇkRFyTq Rk1ʻ6e@ X(G(G8=%:'o9&!lVcvKPrWa(ԭ&NAxJB{ftm TuPZ'Tz 2 1$(ҕZ4lmF Ucs? Ӎg0*[:Y%/#1So#/ Br_

9[+IiKazF$cB#hXff mt#J`Wr|SdWfO &M("Η};b6i8ľPO>Q38)G,v7<N]֪ C lcҖ8]C;b-*J:*| |@b6_9C.]̞nhCj% ?iPVz(D̢ O c$یiȹZ p"=(PJ/ !p\yMK'塣Ê Q ϧCx5_Ѷ{:pHꫥ)fx}Y)[L躨~oWړ&v\b(V E-kU۽VQ5M%C~|\FSHb-o{E˲.QRnwP) FS#Vg`Hꉟ L~ 26sXW3^5'NMLc[}# ?#Xjs$g[56YhC?as:}\tn*j0}%DM\Ս3N]~{F+=> G""Mks _)-C3g]Rm3^,$ڑ#g8]۞ 3f ®':Vخ4A2 ̟,@7%m^{~mze 3f?ݵ#A崾 c ->2~G_(ҁb>; x(_&io LV [س!i|΃NR /E5*yG;cd@rhpOR=o#m Ms8sQrjnv>=#D),R] 5;qL7&# $wvpˠSE@kEkbxhv|PϹ}Y+*m8AL𰾁@\S 5{Q%AR,轅i5 i~~BRnW$@b`U4s)c0ʦ%,nyan OέUQT a*/׎[B 'k!"-fm3rv甊[Zv Ny.PL_1Hע2pƖa9NDETWe1Q-ǾMqĨK eѧRc/_Xdj\+\H0姯?CsR@Š1m4XG)M<.*.`)f> \:e/͉)%QURN%ZOi[m$HV" h:2"XaLFmb#7r]᦬hyKL8hE(+2 \ ю78p,H ^f=I="jDgk3q4֓3ǣ(kA4anq iB!Lg 9ղy/NC,HF &DfdH7`Ɓ8?1;*.%w8 vPV5FW$A˚E;Q_%UbKkp( H Mk0niӋ $(|Nٛ*{CeDD 6A$~ cIU%wӉ&hPK_sKsKvpB 3ƮRחLh%opPȶ\x-e^/?V%11DIU55P7)6p&{kpb%hH>i>"ٮ0ʴ:14/Ktq' : Va=9{(Qh <>՜j|a &<̤̝b#3, ># #+w:{ltkBSn x9p?G?K8MLH?ˇ"@HzLetS.m}N-ҫ* 6. Š| 3}7 j aޒX/oT}Bj1jdಷ9d=zkS"#$juҀ%dU#MEyG/_iԟ ~x lۚ*gr9{o#>IV.O3ݔ 2­|аͯIpaUNE7+sR>4_ŷO n'FM]>9=PD럊iF4IMlnBNZǸYiJNRZ:aI92xP zN(Pΰ&a7żV8ƘS7%.gd(k^j.*y@A3yTa)q3SRSӔ)L>+ TJRAX AQ 2$"n_v >྘b;|Zh*-]!v=l1ގJ2UbN5N[ ن!ly1 k'~"P+AˤvUy$tvz%Wl~UfԏښlRL/__#\\Fh1gdu܌r]]h付0X5bweBW.yhWCٚ8~].E˪knj'bz= 8K}NIqؑvi6DIţe ēC8kF'ţax H_jl0Nɠd*ik0>AMWt"]^񧧷!HY_wkǃmDrM{b;|-p Uy=į78!~&MiTk܉ꬢ}/B7 ]&s&} Pzw0gg[rcSlTRJ,Fk\;QXzN#x'u=| Y7#)]%GPgernu{S!ܣ8'G~=T|"'(O>3ppG\2BfyCKm`/[]LFK.#Z+#w]Tzfp9*G>:?gM91d8U> g>c'9I@MfF|@Ӫp:3GG쾓Q +2)JlsZ˖rоiL!0V6:.ExIx;fH[Ө 9.0NF y8H#6DžHž$?/S(dpл%hϟvvs R!woaJ=Y2T1҆|}YF 睪L'9{dvyoQc?/Jm0߻S*u[DzߔV̰lMR]m%*$ jYo eąY孧VAнތ OW0b8xdαmPwߎ|}m]5ni#+HX`t9j*8Zja=f@P Siwc~*r'5{=.`@AO${'\/t1٠XS`'A('\+^Po,c1Ͱmj뼓^ |Z @3Vr-m\Xc߹zuxh_ x -~v(rMT]'^AH 2A2#FK69f?rR(|u~DXiFQ,4- H8|@'2"A[y([S=gk$4݇QS XWFM`!ɗ*{R"gw7ЖTI@(8*ȏ'&L!gࣛ3 ?m^D+ēz\@Kw1TsZN^ƜԷ{ EǯD-MRL:%Y֩WHJPAnqoy)־nтSrGC`i#ЊjdWrrO^00eXdTD5suPZ$p9Ev=y E/bė=HA:kyB7F &%Ėp0P﷐!NdD' 馭ptde\)я53[텠fcȴU-#Kj_TG A2}$7sO*ۍ)\ ϊ+p+gMt=PYM j# `'8_YvE׉|GEexP~2ZJ^*}j~;zF{gz!$`o>Q3G=f ԹJ!v~tE0e vy2NٮKWћU#VihL}MƩ lD.)'BRbFw}f#q<oTb6vX$y ̎ŇVz߇]FXl5Ї?A s=]Ab4ξEUkN<7 o,+HE;s!ˣlF<v"R7=Sy,&^rQDz_ײ!]d#%q!8-^ Pq 頋?0֏ ?)g U⃻MٵfXW[DW|sq}|\O5[@QkQWg5'#, "_SM=RM{Y/KfVz< UjiM/H^_o,9M{dH%>s bwEut)~nZI ]>q%̡>`Z6Ҝ5Mt\C}]'Y%Ҿ.-K15AJ/Ul],fpÁ]ij{`dX 뾟jg*A\p5z/%%,v#q1g֖R:SVIՙ򎣆%&K -?oV/hD#N10f!&V |H+_zM{wAi84=7X7JX 6__''v %N$èMj YjJu;!Lmn~@?BhOMhĈOcLbH4+q7J?|=/amhiAffKR~#΁]HlJY^KEn}NhP(2OCT3wJq'[J Bmoi˫PLVfD%]h*L|N gVT< VSaSĠ.6974ߑpĵ,X+b;Ȋkh5|.\?_sO a`(/ZWER:*IT)RvdRH-ݹ7ZnOr7׆Ȅ?e$,crua5 Dv.M8k>x vYIwxV8 ԈUM\v`L_ٓ_J J"e^ٴG-۫z*,N)-j*vkes"k8ԉ_Y鞪uZfMBH@Y Thy$:} $ƹ7As Uk&f\@iY!+CrT#HI NsmB=@ " Tٷ'?iuM_@$!ڋM޸nqjmֺBb H+ p2Y|'5m#c:Nn/9W2x0+gCIJLs "!O^BxQgxf y![t~4.ѣ)z/7q-;Y禁5VRW#HPbҳFUV>`+4Yc'sSD ޻Z<&!0`wbSKH)zlИ15E3lR*VJZ>i}=FޓB(ۈ]cU+ KrqcΡ_7VfflMٶK5J0[ WF7^ 9,s [Y@P RCY_cZI e/j^嵌V1Ki`.c>ORf(Y Ws&Z/(njkHa不\#й=I'XM%--^x3'u.#F0ThH?-t.WiKta]Z(2A(߅%@A{dvC Œ~@C|ƝO\y g:o{m.6jjϞpB*Ʊ eȮّɖ~wC7c8!9&~1H0a$ꀔ?Yt:^Zy)fʜ$^EwKK>8dў03מDKr<ۨ^ m*>>^]jKou⨸B", sip)VѢqz勞0'ތ w-CKiqքvoBv3fH[02B,e5mA s d?A]-Xqs'gTm` {\xS͂x¿3 ZVyXu6aK>>~U3'i=3SqٝF}Kud[Y98i ':;N>eiy noFɊIquMזL 94XPTݪIHHld<[Q ԻjPeh`ZΞʁ(G36a@.3 J{XnU%pvf!Y28C)ʹ&wM$8:)BTvٽOQK8G0L|+>8pEe):l ҡ+pz_w\4dzV\o:'XSWv t<|Sa*Zp XRdpSB0gu HE9:NwҏT1ksߝ8 uow£*\ξnKyFxD򲄎nSBN|_to0lj/̧̡f[֔2)ذAs/]F~ bBBx+Vsѣfuj'Ep;k92Jn_kǬړwnK0y󟍈 hQѯ JcHJYjt(5ey!,jTAW[5"dʭ(E^o-%]_hM rQ$ZSCv#v]n" %_W_W𛉮E`"RpiQP$l"$A`>ΕJx &n-/$:BsA.8crrj& S vvxEq5-nKRo`1L3Xxth݇Q kƭXF0߂MPz\-cq1kGeՂ"Ch`mέR05چtƤDd|ʘBal8x*m(Q A/eX̾?oYY]y!;:'H GrUeF"tҽ$RcK2Xꥸ 2ON2zKL'OA+!>yn&!":a;k/ϱ`Sn/vC{e( U#޿}NX^k&P|nOLzNc\l.c2h8TLrE2hRQin=mlZCFyy"S43KQNP9Lv06MIGdJd+vKy 0^h쨐cd6l3-YF;LDaqi `܇c>ݑ,t҃t͓{-"aOi/,> -gj Cw(ԏc|')(:n ٓӈ3!@-|G+ޓ. Ze{,7lTY*_wFnlI4^Y3O[L<7.shx Wt#߬_Gg\%Gz̔#b(BX~x~ |5(LON'}rD{K^24Bw)eNT8rHQ ^v~g@ qSg&Î~GHYiЙUڜ{>.^;AN\9c竉O"ghR)Oz\:>Vsq]ٯdH\lq w3^;NZbPi]^4,/_dxJ[6 "O#,"0v32β4%0n }GsDϚ{t\pf.8%v?X!#efz_N^!q>"*\šݫtpkZX@.w!7xiN+o^wF ӐOT+F fQ.v.$/3/s-'֨hVi:ZǰT&<`^N #vgh_-Xv}o߶9!3$EA:j@'@\m c: jښ)"fHɾDYuwa 79LR7kҷa~ %#A ʯB&^/3 wʼn^XթU,Q]ҍ *½Gw 0=I@ dMd=Ae݊KdmŲ!MGhfBƱy!\ة-sİbcUXI7!$>:*Zujt<"7Uv۳SߊW.c`Ad_b)oLEA+'U+9Q**(PsJ>{JHjзdOX=}A6%3}/1bg {U\u!aMVX6+4[Ŋ|Mh]sD#Y]~I7gVl؁Uz}Nna] ouԋ6]V|uuis@s}A[df'kPy-px>WhQ91YMz[ܺ*By~BI:.`"ZHpEVf,]{~G /0@-t->pa pP !gԙJ2ke2ݥ`/>%蓎3b_A-{t.eUTrQ!eu tx pH XZe%U1.pdzza+׌{1]315\kN&+Ho+gzM78Ebd BI1:yF{4pFO.6W\EqjAs\4ޔ&2iĘ\P~aԚl :o͌/W.3˭UY"SID@gjH'sP4}!26(Ӵrڶ1x5>H%y&L&7&xyava|tPOY)@gEgc췽]mZUN;dܪvA>1]ۦT;;Pd2|me -.]Po&7:y@0~[7y Z%99G7/3ׁ_?^K(AlU[QW@Ht~U_j*`AFv5.6EƮXTM|uKà+iB4"Kmc) 0xUaC_Ih]`' 6DSrde!\k-GE,P.o {}mrtwxio vgo'N_G]>NTt&.SpM]zpclZNv lX7™zo V~UVp5eaf?U& "(_H-m* zκl=@Y]t(zo '-K;O} 6{bB*(xnܸW<}*k#N, [Z Zb-4'c6 ƾ R+=p3zy~~XRQ56vs|:OmqiVmchPoU"/`'){Г:Oz:ݚIuMU8]B2=#FN_DϷ]B:1B<%M}1Bs; !7+|us7zu~ꄱ! le~s Uȣ)L_g1YwQ#ͮg;&u]x4G'ش/@bl2f8 d5 0i EH(cv?U _u! h4+*.vFYlLS4vNa܋ ɠH7W"CMƞ܁y[{T&ӿv:p.h z2>B:(fڷD7;?N0UgXI"iW&^%q+l !5t]ik#ϻ(m+&}| r*Dj6^ eI[ S@[y4ḃ PiBckW",DQRƱIKXN|^HUz4[urL&\ӕI=8C6~8!v0_hm rD=,$"ޖ]OoX033#wQ.td.\AY|WiR^A#V[kss}S6z{VE+NA͇a JY} Pck_.tkI٩p3:89Pт4j[j 0:Xo۠ iZQq*A& \5exqʼnpaUp~0W>b[ ٸNԜL ]=IYMxv8\Vk$%o|%wy[+2zىj(uOI۵jSJLfuwr =vlG$kE=9h ۅNΩ^Dt&E |m񲢎]-]g3kpczr)o. _l,8+??$wDJ}`,8f7ly.MeO5~;r5=&"#Sf2qݴ.s G7#nRIT?(oKUP T,+S1[eXwgkwTjp4]uX1__ʣ^$}m[ [43Rfj2N_H$-~w~RPqpǶ`l,hUVd_݁ XS;7u[2$}Z{__3^If>?xd;b#zftqN%QbEf1W~g@mEEI,{1}"? O<S2P>_Ǔ, ٢*&a1QK+r_}5Pt|#Gn졗b"JBGd:lsжr1[WOAܙC!?.ў%fuU=<t9O- ȷܪkG Ŕ@S^!\}Me/g32U#S#V%h0:|EMSX5^qYAq.yrf 쫧DAW7M.o!KYŅt\,X~B65ks3v-ȕ3Uu6bGk[W:'xYO;s4|ְ6Uk#\{b qW9(~'6SMֶU9+vX,'lIMƟ9 ejrxe| "6Btc3+ةcqD$Rc`X%. 1089TU'V67TGP@0?> OAk:XQ%iVWg;qI5DxYB MrŰeʦ=3 ψܑz2tauAZ(R뚼"O9Wz)q)1ϺD\8r"Tf#b;~!/yr'3: ömsiCLujѮpOO^3G'{Es \ muSg-Qʹ]$59hK .lӌ"3[A1ln׆oFj +;ڎ+[bfy Tcʐg|/RU8M;(</Ql[]_5f'b+% uW )yIhg Zbݎy䇛'}GnB1Liw+Qά#,~:e բ}P>s+u RlV0ͬ18 R3|ÈqжIؙwy_/ҺlzȃPS)Biۼe1 cj"^a.<_ ϙӨfL  u4_U{>Fߵōv&I*PLd:$tx!~fmo]ma26s !Ghf~HXNԼ=Ow$2R)PxWacJ); yV_/W-`&.%Mj7 ;&"Qu_#'9*>DKFaރY0Vt,0m+D-4:rs$Mp{Q]Z8Zu!?el:\wk:bʵ% Di=f¶6flӫ8߇M|`"* =4q8ȮTx*mCx'3#zwd1 d>Ă]bz4] YmשgfDF[^RM]Ȟw9fmh" -\hB%G[V>p#j ɀݯoT,l~//ٌ͗T_Sлxȳs f CIiJ'%9rj|뮞xvf6@Na= 42`.Ŵh3JJhW2 q܎+r/iΔ5$$ C֧ТYdY(/r'{R62ǜ<L(oqģWrm rRYהo_QP_!e㢅$ AZrp_vFv+ɀ oH+0c5ܺo{`ߠFܓ,)wjVmy['-QJ4R.΂%XS yS)Iġ62/pdYqҝ2G[^\TSfy;.9Kz(?'*<*]jrԥƊmƮթHβu4S+DCčC:ʶum k1AN*=D^ ~,sAz*|#3+r[nR{اⵥ'w@V)Sv ze^,"7 r*M>sᤓ)բ݂_oB*ᢵ˲+4'^joWZA_539n,U;g[L{$x)]'b 'N KQCJmK/OH'Q a;rOlqlD蘿ƤH-#RŜ$TPթl!,Z²w# AΰP0i-P IN"2ۥ9Rª>+4.7TB(.bB{RDڐ%6]"exخ+_B{5=CAfQ>y1 dIqW\@Uee<垑M\Ihoɽ'%<5VgJa9ӈp!#Qg\I용tzi;o|=Kpd1vNlXzWq%bwhr5<DVE8䄎F1Ʀԇⷕ#ä[!,`'y w=&ߊE:M$@ޝF:+)fh"J7VFy4g;,:\kh=K|F>=CfŎvNb#µP,ーUC@1*R3\+[M/s\X S`$fՠxs΍y7PgsS1#N{ÜAޘppԽTldC1:,.TGgXpAz?ĹmaX0gҚ'v(ZFI'Ww(O0{wfBw;Rv:=Dgl1 *t|4uPaqs4Y7Hy|ZWao!+!G4u6acd4uc Yt cOe> s`]  ٤P>'vPȏpߕ5ew-J> d)ʫ`enho7Ŀª5(9DI[stij˦ [zBުhHT`|O2{-`# J[& ٱ`™U!<&n/EQ1җgU C;N1oѲ?q]vc%Io~z0ѵuJ[׆sbF03ED (z]$D]ą7 TrR`w"<ͽ⑱ad]cYf(Vat(?2ӏ Px7//;ECtW]{#gy!XL̞oթ~mc%̘BѨ(>8WJ^bIA鄜voRV]B^bI8dW@;|;=4֞m {7 26|_P9V+~ izONfnlv տw킙h#n6"L 퍖`CΨO7j癆7Nu\ (TS !NT.ʪfH![/ L ya \xpfL{DūEa}R+nQ >+ᙍrVCYZհQ^pfҁ9.TIdžOPOC\J+F^If9`v3TDͼ>a*p mtk. %7"ڛ]UzUQ=VȺrwXWhRUxj OEsO, >OM+`qKu'&=N@Q95waֲb鍳FGͶ"P@'`nt,bq+ah8ib{:y`yjtk$(v LR BDbpSQY^ÃO]õ+:9Fse=NpD&='Wp`.H:&!;ݲ4L/i,"ê CkZSK>'y^]VǺX^SG~HOܞ?iG,8候$W;k5pX+6_p CY{_^yu}bJ'C4L&C)p*qĦjr:v~!J~&sЂW ۳P~n|@%Нoe?=':r4 [ɝ=.b9t9{nhM~U(Oi0t)3? ,Xqj/I-V5G ~g-|ك0uN܇J"i DllrYi"V^pbqGm %>N4z2@kƒ E%D8Ν*SE$ԧ X5}y%[t29?ua\OA MHjnQ~M CZhnvc`uѽoъemUid#hN\T$d4>)[]Nܵei04JI}_iR,ZMΡ?&~_60"}eLj< 3 ~ 0ޭ'#$t?=${u'Rc"J:|Xi|݊Lm[ׁDF .l3"N~ٕS5BU̥,p^?>Rj=;1'ȉ}!iUr>e릋sLI bD(Fs%Y4ቮR\b`'ԳBi#=N4|6W])La*KQV^_>Xy7q- HH fWs7VSۇd]M^ե3eomT4&ְ3zJot`F@hQv(#1հ>2{Gdw9K-,ݢuT,hucD5P!*F! ݧ7cq6wE)ȴo@FA!P2֪SEu_OU W-'K <:ES-ݚ;w29wҩ5Ms)@ \bg"$aZCQFfk2y!\pr7;:G!,otݷ)'9%xaJ 2821'5-~d9<+jv,sHiq/Hb5|JM~.{eW>RѱS791֦Un^Pztx,ع1a+ ) 8UtʹOv\Mp{Hje[aOkM,WL {>fQ[ eиm0sZtƊth6ub1,}Csd YR/K#hw'N&H_:U,9C%vVTA)|i^g=Szi_+Id(QIom)N~Ppn~a 5f6‘$!pНWHO:TNߔDG5OWXT40o߭D1S1tMј ,Pk%qq܌"Ds[زpr%2ᑪ(cDcO*lސ IZI:eЫ&qa€D]\5e9:"hpG;t CCx L#8_*.Srs[)`~^OH9.voaoHy9b=fy}j6bcH ;[FY8n]ir]tTɠ}>T tyi_o;"Y+ލJwBD<ĠKYpZCsgY@"hْrUi7 T捞37W>3I(J}@K`-שH(rT MoDV95|MC D|2$o3=)V \l`6~B^-J]8]wdGw`w>"{![)MR}wCFceŗv~|x)@jųBAbgaN7;$qҔt@"j^tRxR]["01Dw$CA BU%6"әbivGϞR&?J=H@VLzT_;ʯo ; ̥[Y=Kj7&Ƌ`;ίM/s6еj2BSB #T-+cJr{iQYHjw_a3hR_ ͈[97(?/\77>OhB,^ 933h]ŅQda)%ɐHpC߮.g? wVvy dW5bϖfIZQ=0G9X7.|ţ(^Ҳ4-0UE= *`1|3\ 1Q;:^Vu;$oTO_wh[.{]Ud腣=N)C @G.5d2# /cF,G|/R!TvQ &˚y> P`͟ vZ,~ЙfsNbAD1iRs]@|c-FG e"flP^b o|U3p>h(Ңǂ+o,_VĽܻ6yP|\ 16<uEC";ww웛%]!虎}-n'c` H#v­{ |p浍kSO76ympP_=eo Utk>YpuHm~PE Yq2I՚ID1i@=vT5}PhYu)y`3x558L31g>EıdLc2|sT! pgqwĬg6媞@uj"I8jB6BxR5+"&FLN&waY#>ckfZpwjUJ 3#I"w',|XO$d /C$x_9}#oB7jAؿ9f=Rq^|˗ g8=t$vϛ`UZg ueh^ވMfU@_j$W|J_YbO|Mi]&koiD'wuW|Ô?/di! Uک,}7JҘ Zrgt=0MxOC!X .5y3s\R\4p?-y"[΁`^js|l#3x= |ujgzVAH Ul6K˃Z&ass+c9;;Ҫyqd=Ƣ$ASs.)R9`;›C@%h]DMT`AA0Y4 xҡ뻁$%CON<2;+ lQC0v=li:f*|Vc"4ڙ+Jy^AU<\Ib_gmtuUc F^aŽL1B:Įb& sM Qg8Ӆ-يҭt.kt=2X_߿:D R R0h=Q磸^$12@okǢ@0 FZ tUrs_Љ`ϾՔio+}P:̞agºA3/p& p7,!=h?*C1|2|eU%~OEm.Z$ZIJU_O8uEߠm]䶡W zYvAnkC+2?e {QieM#Rkrhl "R7.{/S y݊KCɁD8F|c_E^#[KnnA@[ģHZiu=Z$ǻIN{=YN 8$Ӭ.6$ |'_?opAP ~~CqO+[Q6Fu[bvO Є"`GGMpp3IP.^M 8L@TVzE,̠Z)ά~o*TXWm™{/vS#AnMoƗ~@uNQcdC+NE=h=k{(`tۣ>"t`5=R"f *|)Zޜ]}Tݻk9q&sq`5bHKP_-`}u9ze}u j@uϫLחؙg}/./ۋ#$u%Ne#gDb^S$B/_I{*ӒZ [sθ[vS]@P"IsE>&kA׿0ڕ3v`,A-3ߵYGH[/FJrt=}(__Iw?.ՠZR4wIDkYyfa>=RQ *c3`: uOlz;tH[D8o=Κ!&#uL(Ȥ:܂ 6HO7V)pv{)Y"^*Vq7uޢ-5/"zR0 Ǻynie@,+tJ+C+ ֕"*=; C!< S2w6J#=`o=c\i.<0j~cJ+ 9hcBAϗwqhOVskҝ,"*Q;HCOII"ʵvkFd삌+:M^7o<0xA;D ZCo ^k%1 er?SP¶DO`JORs PZ=A$FT eQ  ;ݠ(LtB)[X˒|EC:G푠Co2)Ow au7A.3pg0e _<;fM궈80'r~z~$ 2xs]-j7C- wV&6Tv!|w''4>*7^=+JF'1FV#OsGHѬ"- !J6QnTҩ`>>':CE"!/RM{R5"׭]ze+;:M$vX\x3;EI=}z ,w0 Uc@>SI{fd UHNv e"`L~c'[#fĒbޢB4ҵW*rEY1=rvZa\= qP1T!uQ4AݢpFh60(h^^nZUuW-#SX_RZIy%Xlʈ/@3l^H+w?ѓak; ]) !P=kwvA:VwZ>"m ˒ *C3#v*+,x`TP!Pd7>t"10WuEMP6Sv4]w}|s~ CDj\Rkz=9}#P_Ы鬄eNt-K*+{УeL9ѱݬ3? 5= .Kֈ ҦK%Y ^R>흹CT #!{Xsi8S3ya8Tcf_3Az-OK$z\|c:\WHouɕ/qc84!c=tqcb) †UBA(iM0LRhQ~.CGE`kYL&92g%Y9]GEN&6=[5G^y fxf‚`Tef/)J zZX(`=/7횶fI pi>D9<0ؖ^-ańFz$)N-ؙ\1LW0yO'[`fq{ $F Yg` qS]dS4'UFa|!#!%oʤͧw|%(5REaqE*0O@3޺h-4񾍚 o(1sino^Wt g%]QbN՘^/; @6h kC TnE 2"!q4zM"z[ .O|L,I6U;q3l=Ew# ה٢ՋC&My?!8/ GZ m_W%3=98@5̭5R_M| BT{ozVToWt5*y{bƶ Yv)8`lkiP@-/Yzz.*eŬC0N:zlisUѽeݬЕ]o~B4A'>& W[$~Y9W6BbmA-ch_9 *t 9#P+_ŨfpP˫Ʃno1{q''n#/ IAQr PBڎj?(* yG@lO`S? ՖpBM3&-@OMxqewbyYB;:^#Wח5M)8%o]71 MFSf,'~ 9p0ܩKx!ק%\=+/E osUEef;.-%hf&'أ0[YKɉOY XϝDTpjA`suLlb@ εpx@t טYncl!5vI}K70*H^NY7d)A=YU(H-}ZM8ڼ(p!fk\7U\zVb x(er9{ yɣlqrX)eX6E`MT+F.-`OA~S4!L:ѸM }#)8r½H8aͣIჱy@]5kY"`r A(X׸mO(`_rN|r| O Gqﲨo gKz.q~0PaѷV(Xk36To4v.]ly4OBӌJx&/wez^Bջc w}W9EQSba^4co WriX=V*[6'/6^Pi&UV)W |Yn,Qިb ,#&'o `9yFk-V' ^6QWtX}{o,4I3F1jʆP:|G޽f_UvE9F>6l{*ɓ.wbXb9}+.>b'{xP5G+dJnAR(f VJR99;(bTŽD24ń {_+J71ZlRТiZvZEqg4R+Vj9Q&{vEcڇ|qc̸ɹS+Z`ئ,$͐魯VM`f0*j=9bW;sWqgD2Mi?!^+@8Oc~{G,w?Zx~%'8Ћ?x|P$ kuGGv߰Sy 0כ[em3 }dq$DUλT<}\ fi[ DuPEikqЏ܊٭;^xx0̟tfLcyi_'wa؄uԗ_IKe0PC֍ V+ޣ2 T6AWF%O P95"M'X4_vh<wʲ?%bT9"{vޚL+,|Tѯ?N_⿓2{MCL=ێ 1NF\Vk5,I@HKq(xny}is;G:=К}"Wr/apρ0d=Z̷)lsV dShd%ݰ;Fx}hg8ҽF6I4&ro2QB.ݣj_̬61ݍ6_?wNEUeV44PwbG!;#MEX_f:镛\ j,Uq|>,Sp@ؾlX!`a-\y=NLI^:/l!EL+l\RB=IBd'iچb° mctƨT$HY1OM3<ɲ HifYO"Yo?ұtB<-oJI:Ff (ll ;V6#7kLF(bKQ2t2»ܒ "Nt\\n%po>-nNsKܒ3Q.9ȋ,Zf2U"u.{(*qj]eP5j/S?F ֚CK;2ߩԼU߇h)Sʇ-lMԠWhO'sXUK]k1Ek*iwM&s{} ^-+w8zwJ-8q8:P1#(ie3>O]\2rj-aM:Z:ڔcs_,ӚP 6j*#riT.'ģnQR !y`loJTu }w5l$ !yf,Z !`6oPBQ8ȑ'-Q!sq >zM;W$\ft*cS 6QAq|nGZCpл*)ڈ`Dxjv0nwG:ٕDmʞgdR&&7$Uc9B]X{y"'plK>ӭcbgY8l5*@6ߑ@hm"51L'$o`\jvXmհX7-0E!pçVs?Ar5i7QcC%bF_\ -HAO ^86 8k]YaƔas<7}rxDLHA(F&ߋwʍ .!dpV:Zq[լKollZOۘRK}b.1ހr~#Q.M:g_NAp$H:j8u^wC1bQY@@+"4b]05+7Q UZ(mG/UȄy )3xX Tuؿ4Ht׉q3a݆ERDB-ajF*R)ݔ(=% OsTB|5VD覙+$4C uz# 7uW6 eN;Zg(cK?k\MY˫`%N,ѵ3{-E*XuR)@L^{y2_"3\Lϧ`^%DC9bAӽ=3I lvVĎRH# lGye0/Wb iT!>aő#&;{#z_;$Zڠ#k[_.^#*U,Ύ&C ~GedJi"/%^2nc /%o֨ChMk֚) d shБԉpJ\잏 */Qglj1=NiwY?1N2+҆U?TGtF\բ)J}kEv`/yrFM LyG"$Jjz5o8C7!u8֪ɢU|?L`Ԍ" dV/d'Qa]KLmwtq:W <@.B5 z,c{{U.I0N/֪#ܠǫ&=}|]U ^c u=@ghZD u,8j\KRc&. Kk$L,HnwjV%Ly?+lG`.v%Z* W8rl bOS{L,|u*;" x tFZ^4MP6cLxoF|UXr‹eJk \F 9kQq[p4Gx)|Y>zOl:AvTcjDfs$(qelt]߱cOͥg=w(Ŝ&7D"YRZ, Bg1E^c;̎9&bE\0; EL̂50/Ibc l%#/9]<>Ȭگ1Lh$5r1PYfg_K;6iHG'TvNRC_9 *4UעTcb19H^BQIHlʫG4N=v${Sdao YF6CuNqčv^i]TK\LGmI0{L*~jz8 Xx-Nmf2'\> Vd1XVQɎh7i9pK~ɯ3wT5: @שY#jF:t2|GGcQG a=s2\Ŝt݁`?ME;-4أ0~+S պ)3`6 + 3y.H P6E<YPgBc2Ъu}&@e$C|x%k,iCH(T;/httӋQR 5 Np#JyNP4@Sprо5Lle>%o3٫㗼$-޺|O^Ó.h@1eE5B>Kl6^.8 ;2q\&,̹[pt--Zcch/H! h#Hx -*N3Uѿ̨m2%\.Z,QnvCqm2% TPZ`'L^;樐 }^7h]LGE-rnxQf.T;$NoCŕ&r]5]ǃg N{N3P:"MB1ڨʏ^HA\f #GժZ :CD l;{(xљ8~ID0I|, sx8D4Żd*Vnx'U.{d:NGak]kLO'2Yh=šk\/ͧRC=-(gX.C=t؇;UǕmDnR|IRzaƂLFNJ8ӕ}B DDA4#VcuuY)SdGvZA ;̸f^nֽy|PasVqbj։vHNa͇ELKvwDS#).Lu9+L \IpK7ި&*Y-s[-C[fIN2v12Β"mU|Ӽ'`V+!U@aS>0>k XIq먗܎ÐQ%ߑ!qXݷa,Xڷ>› +3Q0n R2]ъfbRz!%%  G4杗.b‰8{oepo4qW*ڷ Ί0`NcP^iɠ:,s Td}P5t> O mʠNQe%pϘwE(I/.#bRPs'9q@p<۸#:>[ 1/:߇Ҕ~ Z)H |b߼ *zB7בu ( Sh*,`;4l2yRީs䖹hRÃ7$RSIzDo7-z27)ٿqu =]&%ݩԴmQO:6%TKF0G / eMtЅz各1 )bo9Vrv2A~ vgvf@dO<~UPQYm\4Hu ߿[@Ok"n8oMZև#*d#wm߂gH$Tcc3[Ӱg mM;θj(ޙuHFSU?H^rPO%$5 (x._*MIY`;Iy4# " k>(e%L;쬡0|(#D"U:+/Qmh'`Uygaa,׹HF{`²! ʽ14醳4T8(2/81R]&&2UWMǘ)bg͈3 !锲L=pFaO(!m˂C7׃'DTıGN@pqzD 0Tt=N)'U[#ǕZ/f%u=Ғv'oMK"$ݣZr _5[|u48-6Z8sh"g /fNioskO's I%tV_dh@zy{u_L'U =wKվ/L٤]c5moB~1ʑc68Olj3 s$*%k@˨@?׵1@("Z P(S[|iT>@r3eS- $,ikTJ[H $ ӹStâ9g-&=-/2Ԏʅ&.e2t}~7Y,|`u{Z2nUzc.n/uD>/A-7] \dž㧐Lz~,ZLڨ{X7w3,Ö$_ Y$Ej$QR4ݰ9+]XE7}(d/Cϯ3;o3aL?#[HԌnݽC֡(ڄm^ߣRkِLo㙳4à%7b/Qb뤂*J" O*oo*/IHʱbKKˠߣ~xk5J1|)s"R'|-#gEO^IoF²LlMhR3I }GU$<i>܆#oBTh\Q0WцWX!|:@)Y%05u'adk'`(H FA]HwEΈ@azFaATtQ[ oZ2#z_^fWǚ" `FNOfka(EV0miM^N}֧kXjw"*ꥡ ߆8瘯ʈ󇪜h`|. lt^. _F!"1U}U L_ zndᯭ֡!)*s C=g6"(SF˲&9RlֳYruzVL18F|F)LF6/3P93 |V(d#|wŷbPdAm w/(`S bsymdne|GSWu)fz5 Tഌ=?7:<8_>-/*Y&0nLNf]{ 33Gz7Yc{T[\eE iJu`F`wх }[LF\^WaP?{豂[Pn"-?E\xӦ8[i{s^ʎ`aFQ7-GŤ7@ہ;C ƌ[R ,'fPc0VZmu4Z(G;Gra}K&-Zr_'j7%+7xBݧl+eyFOޖ2b {"ߒ{Rc5SG ش%=4U?d#φ o9] ثCb7[EE`TUEa { ](r$#YǚRH^BӞKJÄXt*s^QLf k⬐yvӂʖGmƊ'v͵݅p([JՕ.*9% x(/$I@ۚhRSݫv*s`&FJHg8԰_R JɈ{PQ -2g D]٭_$sa72R-4?r#$ _O0lVmKpqq@.ॲGg 1iF粨XS\WYn* u*$,N|XGi!s8H}>Ivߐ<>L E5>>"QnrϭUIW1@LMK=<{$m/"q;{J8w_`Dse9}(R@7~m N#kd(j3àtJmX4Ktdi&奊2y^^_1FSűs Aklۉ'Rc^ueί8p<=#sI@e'"'f(J# b4ho Ee/?UVe&p7:P-{YK)JH˃N ;{YTMEM.,(^/Խj҆_w>:|*'wGN()/_"Л6+Jo$ix އv3r0@:&I5_GlF-#|=]YO_[/kmV j ާ+7|Mk˞B센/&w\5N2޳'@m#2U"iSgt@] &G+N-BG"6, IFqؽU[O ~vݮ !"=tw2|g!d5F؍'fHZ"]h$Z[. /E eW֟Kn\ȭ(9vT *=xڄ2F :E#\$͘©GSbKϹwhI]dK=cj b7 K-u0Rr\ Ysch@Õ'&LFԜ7m5)` TN~}15Ֆ|?h934ih`?\L1[k Q|Fju($Lv0u.`4KϪF,S̚)>5b5<+8~QBХ/*o%#I!gRH )C]MW<䵯3RUTK2z(wtxc2!X2D!)]. +]*lk˖l~9zlӚ=AFIbBH4:>.b% 8;?~ZоLrlƥ񊔄R=M[=ke;ЎxCe4 I88-/DϝvBL)d0Ɛ`b(E9+vW 8 $WRb>]&3kHjBeՂd#& 7:I *"rd;fD\]Qn(W_ !Ї 0]vn6CeWA3ba_^o,f;F=GM{}_0l7ׅmøEVGtCлѼR't/T-3I:8`q rJkAmf`m)EX6x5'SG %%Pc"Xؐ/}Bܨi,Ɲ[WT15 ="^^kߔvߩRgJBp&["n gCae" ;}^t(\[f˳acяT*%&lWضh$@Zjnuth9_COb2&9W$>ZF*l/;u&z6N^Pg<%x e1B1 9^ ZaCx9z ~ i)-' cʿuϵ1ƁJyt{1=dN}=d^ߣR[O}GAfw# imd+{=,PZJ3QB/za:B+&(謞HOr'C ?MT*?V\ÿ=inK@c0y(8 OiVg _x5!EqCG Rd3'QeP6he\ i1:D7`^.gk;b=HP({Ktb(&H qCGj^C <sw1_JpF5fDKKC/!n="ʯLw~Z^V׿MV(A9AZK>zz\5TR 0n?)wɎa@^< (¬FSUbPӻk DtO&,+H C01l9|Wl[5,P@ZX$*ߣIe\|=q2S\Tl/CD @f<4-LGqI.x  lGg`Jj De7)@?IGOtUC`irP0%@ y_Z$'!hHP{ ,)Pr`^\1ve] ܚzz\$7QUĢ,ͳ MbvF3Q3N+qHj]E>}X#-eZGff[oMgEQqWfc"fSvQv|2D{jȋ'0W6߮Hh<.}ö}-cҼX .ͩȱJq<35>#%e eWLXo`[pH<~4- D$MCGfm jp}ngd8)nZ@rHuIZrW+ډ ю!_9C]/W.F>p+3pӳ}D3׎"چc$Ilv҈Є:aWskzG9LzO6WWې [qhGcpKy߹aEQńlOHs5Szx["5ɣkpK~:X<C<h iE?~w1v'ZGs'0=CjLHO2?ѯiJ;aA{դH#c G9-8 ߞ ª"da *o }uJCJ%͚OcJ[C"I#¬Ek(7&aہxY p㪠.ңq *^@ǦG;_ (^~R rWm?> qOBKGd&Ά%Xu1 JJA=fed])c`VEd]qSCFo@5K?3"Gs~Aw>#t\ Nu-C~'/ŏ)o4g◨\& }(˅1 sʟ0PCaѐ@M6goblbւ$Lv I$3'Lgp-蓂P?{e/(!o8X4Puki*7$ N2`jСPX nNo !"hݬ!ˋ4n177h=/;i m*g1 lL{wzwČdZ$|)c2i`c~rWy'xm6n.,zA:fF|PAG BLNJgD&(&>Rǀ-6`6+`!MQK䕿±3ݓok+-~`U6o:M-(GBQȍ:JI|F@`W&.r\n;O `+1ȼb%9p1 ^ SwѨE51-bĺ´`p͢Orn|nDo${# df 5^LmUDע* QY7_Ⓤ.M)2T_튑 V]!G'X]_;O*hk|DAyb#Q@TyPA&ؼv#>k@t7t/b<9Fu/5Xa܈ācp]QD_خs&i8~(smJR vf/%EP(I T29lȦ@’O^) 3?½h86y+JeR9LR\6ܢC2h4M1;eFS%|~\\\gej\RS=kܻNoSu9ꭄRTq[N&>D7ɿϧP20UN4RS?+Pj~qk\+:Ljda/UצYlY~dեt7mEfGrۥɔosݺ^o[u=D,$f N>rq\;El@m{o1o1:-w $ rIV,XKYc pOω)Q =yfgGWNOjE,"絽4@E$)[?2.:PEV(.S*"0 Ҭ,D]Ǯ2d3ܑÄŬ縟V5Ҧz?چ9M=#+[l+^EE Y3ҟe#^HE:V Ȩ^(6kAd`Pp wҨ$f1T5Y=#^ D//\Өᓷ(": 8σ Fze,yo5aĀ;,ѩ`V%iKRez]Dۼlg ԕ3\^m"*w3\6F?ڒOSAiJ?=ffέ7mP1 2'.r&|;2= et*cޕ^y&ޕ#:Lο`>~WlKG"5;Y 4F`q=>Ɉ}1%E'6Vƍ'IBtt[q@GkvRڴu:lр0m Pa&sxyrI;`>͗8A{= +g+` ZŮ(h1TepC0;>E`62; >F2cu2DO14NUG1?'ՉDcm>T᝞,i~(*A,2'έKix-!xe`@,0A_2 Gpx33b!`N5'9羬b RAZ p4MO yX-a'Lxy6S,z˲6޿Xe?#AQED앇RZO#3&@<jD;9[2Ч]1k6TQ]&ydzuIŶrP^|ttyX9+q(u9!]P#QːaXTg]=J/=VB \\V` (4n0ztHn()<-e-z#Z9Bb<"Д^m}w^v-*iHFB[_j<Y B7X qo{.J}J '}~qmoc5k23)+HS,ƼmnK8WA/X:C"g=<||g?UKi˂_7N;F>fJSDnA}y}{>m:eD053"{k*o8\(M[Z쀂 }[O\17V@S5mݘjKl@zSw!.>YԣJ'+OA8lL  h&󇜛e).Xv@ڴ{+eQrALl?lɼXyl1EѦ[ D7|] lrbfby9Ȼ_̳l AJ*0' 'tq[I巢WO؆yB ~"?/]=[fMK{Ejnrwcf2*Dw.SQ#[UJ@&ӉE!bK/ 4j }*"ȱ,fzSj&3uMƒR}xyLÂ2 >.NSmh>cR!:`^ce&Moo]kA:- rdPbdbV9q/oI#pa4+=rSt#ўA(ɡtv=\"֡+f5NtTRuD4D*ל("ƝMa3ml|Yxn1@j?HTC%yJ#R8[eBuPG;4Gnl=( ATmثd.BL;c>\>uY3eQ@V{lz:[qrhCӫ)1P-[IMW#n wY[|VӐN a?08SmxȬ (^M;}@+A%&Fܧ`k[$Cူ\++5t1)DiIM Į\\]A}J& vi|?[3OO@dqZd]@Mt8R4d{4 :>8xz8'[•v- pd.ad3|_8?WۦN⽧cοRMѴg2 -W;_{% ڠ(0-hB-͞j qj;#5JL޲PtrdhjEaɪz<b#;u2T&mB(͔xX(ݜ~\QX?'VJA5ft6TŵQW"UlyUb_5/QǁdRvpa*$~eǖ[\"u)!1#Nha낲] 79h2X( i:`:_5rEۮ",*یك)ٹ 'Z ȠH<$Az]JHLQ-?@-MNp$sgjX_}Ţmk2+G舊Uzp2+&+AKg[D,RDپ?-e׵1Z }uI g+tNp.1Q%,%i@]X# /?T;n̟w@[(bYþ];\p-{ 4VP{֥&̘P|kβx6ym/tP(>(Kn   -8c({Re=u׸xwz̩=3H2nMy<8%{@ e73P4[;}G5+$# 3@C0#-f&*›Z3aCDECw؂{ʜya& /ATI+x( y/T;~;xv#flQ4gO7{ie~AD-uPLtwH[rT F=h"AQK_[cqghY~M( Pe׭}cW$*} ?%APɨjp}E…aFN|drɝaX3"۔!AZµ4Д5u_|-$'>3-,@W]aG1~WYC/HP5>}c|֎+ [Vn̗e%"%88a} Oݷ.4o^4]6)pn,y\Iae\7E:w^+WEٿ;$DQ4v/Kʕn2w3Z~t0},(fF "^m;Db 8΄Z'Cj2n"k8ۅh*1lPR*;"dPlx1U1PPsT51Lʪ+^'|gcDͨY:e5>3KͲ{k': '36}HeQRo[{ MwR :Z\NՙU~ai i;srCژ @ ` n~0߶RZMPAqFݦs'KB,:JLBg5\}06mWBNsˡ \$h\*X9#D+Vq|]5'M!a9#_ jba JlSlbȮ,ǎ*wܽq>T k2EZ fE-hB>+C.Q_r0 Շ^AFYzSَhk[@Ci-=R0 srL/lPK^FteAm܌AXu0.`fO7}|]ƹhNX>gMrO 6k{8Ym sBAE͗JB) 㹬f*_Q@c` JEwGxt;o d a?X{AEv JЅkYr)Z?k*\2䕂&"u*PFwgZ-1/9!xז7uq{4]ፑB9H&tPK>dAH~b045-*ȁ0>G#Xvg0x4>͠07OމY Jw`kTY Q)9daQ>|%TϘ܇6ĉ4r8c{a?>^B:tM')PkF8)\ XZ ȪGҭz;@O)Q@rOhL^?\,z@v"@ԑŚϽmn`eԔэk$jb%)1#A~/f A?oaK XWL]Zɐk=k ^u[e7 UK1Ҥ_Tۂ[ 5-L'0= Q"6@8n\xV\ d4<8u 4dx}%Ҹ\VהhX]t{'!.1°oJUK$vT Xp@vW}~a̝2Н{]_Fc؂~?ŗ  h)oA%A&ps?p?F8j{ AͨcʼHwp٩:=akﲱ%@.-2VSx 6F,[l9Lp{TXߎ,? 䵤 ]˙;:wQiR=РD$«]4ɑ]D\*%Ï ?[Z=Cml&Jn;'vXAl:e019i]rs=(<ÿkxLᤰ1dxj='z V wEZ LxػɹC#is&_"¡ ,ކQKUĂq0?Q[:U{z 4rIcA!h>95;atyoA`#/P(y]_(%3ɿQ9Si-11= M5EipW 6E (%,m-7= #aQ6l?yR8uū`)̞:qI)-x=3ɸP&Ip ON}=9Lef2Sh_܄ O" ]L5iR(-$#y\ ;~\Bҥpt?3(VNjԎKH?7C f a5J?~v-ea Lof=Q7/ٌWXP+wNѩ_1 )$*RWs,PHQq ZT\oAmJDNK&CktgzyKC+6h6 &t/\}=qqB6f_Yro;1T_ؚZ:9M׽1yփьt7Պ [J_yD!,,i ";eskŊdM#Jj*:} S$#}^"?%-sY"dAE+1 X㨎QEzWF*,"^ J|kqkHl:mڕk)^ οZ r?pOCbCN>.˃SNd#FH)"}_!l*uSe@3+Jϴc&\LJFo<5UVå}Ogt}L fcCFo4)HU0@R)f{WΛ6'DgD>8lOp*QӪә oFa'Ya1! =("s@5>@ƑJ^ cvN"MEz+kw<肋#vq+≞ND异,AͯӟV`c=9bu@gg&V{õc3}mc[]~t6Ua >z'Bn'JkەT8J!M3Fq O񖥛jP򀡘2o%Y{RˑĴ9JAnࠪ@}5,& #^0,NryEQ0CM_M@sx#X; fc`̿?]_8lA8zőV9DzԊ`oq97i-H0TW!I&U5v.EW$*  Fg~oso[sTbTڇM);cogEm C`۩Z:#V b`9*5OPAP.@ÅR)\͞#h?XJj2lҭtuVö /a:EV-8W&͢ Et #ʦ`O3 Hm%f;qƌ!IF*Ω5d~J rFfrWߡm2nfJի|"G)ѫlNWj6G|\~R)T5DЁdۓnt >Di0-DzN1>(~ўeh>uV!rza!0;J"'9m>\w+L&hQ+t>*9bK:2ȩYw,Td G;ed*ӌY 138m%¤ 2f]չk*BbٞK_~_YT%A:[s8 ! 7+wFGnP[t"+//W]{BQW%iO_$RExe鼪}M @VmL,:=m=Tr/!ce:bh΄6Mpym$эhuFzkDE>Ck1Nvq ǃȫRˁDrFX1q*M&~@-lTGJf=.>ȈϋR7:[T'A`@L,7p,E_*nhf|XlLKmdA+)mex[H2^dsS<9h+[GW=X>bv%K vr"bL aiv&.ЂXg_A,Pu1x VfoZ*ˈ~ɍAsd,H-AӣzA+;o1hm_؝K:I[sp G uryJO] #Tt&׵:#*iNtҀ y< φm;@b\i;80Fgv5,-02g|8?ѧ9F4SlX=iD"[=iF$b,bZS"gD2-Y UT<!0$'vcAbM2~!1NR0ns 6:ʓ)S5tV msK?"Wn:A]N_} ]П A!K a:\ 3b:dRtH]p9Q֠ë{HK%}&5Hn8/q9$\E/*#.=Y"q4I%%Q4ɻ΢pɦ:5r dxƨ|wRRJ!r_2D/m˜AҒ94A @*kø/ ˵}Gľ\9,6Yd<9|6-DA+ds [՘P3.Hb1b536Va1/ q/p7t E@IEkis F=jKI"droICj`lЧǦĶ3w9{vwB[;}5MHg^RWnA&} x1ѱ )Gg%H(^֖,j1#ܗԚ~`}xWaOJ.{v]΃͵1t*5ct<"ZZV B>o,uo[i:ZNXMq'DذAλ|ͦO\Lk!ZeKފoTUwfq@Xl{fM60/3 ::*:BLl\ qtޤgr#_Om9)p599bH=zژbK2Xo3Td%rmL Meug,|AA/&ċ+Ÿ7۳'%SE, ҟ| K񥁋̞X2AKv;.y\?bL .2n~O 1${75]W.C%zl$%qw` Ȱi`.oN߫O݃~{'r Ƭ}HaFgSV=qb 8QbØ0kZbm6 ?/аxa+4xPO3Q@vg#5Sݴ|g1- Ta@ ; q9bf}6[dŻ^}Hvw&is-Z -3E4 ^f{9_mV.ꆊ#jXB I~%YTH"r)^4GmYOۥš !O;_X;D o[ @p:0EmԻ=xӹ,.xkc6 ` '|0&,f>:)#tBUV@TC~_*F<,FpV;b{$0DHDn.yzGg5w5K%2wRwAQ}@Xtr#;.1W4ŠA z~xc tA'Aj{a x*]gg3+sR*,E8H3ZeoC6 BXU9>η3`gŅ+2YC6t@W;P8li]~'087o.A>=CQ0.Ph)l>k".3 ^_;]g-T./_AC:e?;GKoJq|n1i2ЌG^(Mx%;*O_[ ^$۽UE &yu]/E(p)þ\+& $PeD^l틷69Kg)M=|?k'KR+xCMqC0yDGg?;FfEō3@ f9V+>.ޗnܙN`<(ma:)TٝrVϪ֍ %j@)wƺNPג"oiԩpNA{u (c2l`lhH^O|Ӈ:H⿳R3ܽѢăscO<>?\Kl,fPQZ<^HlZ~36\zamǏc;`U± |6ڇ x-CnwV֭}-T!8 RAUo#|!>0 1 !/)-(5 "{x 1 *Ar;e۠ PLm!_-8EAЧ߆W`| V U^s w@#2hj*w<H%;##24X,Lm>bg©jrOEeNV,2V#o|[óuSߺpS  Y_M7sZ}3[Š`@q-m|q8Zzۉv8P['@cx!NQo.s11l2weع)iQĎ[MAk6yiqam4ZN]XFnåhiʘ \m2P"Oڞ~oԎxyJBf'Mc#_D;-|S@\mUjzu@ͺ2 Pł񕩏 |ai[*}݀Lo0sL[4yc9Sv<G>|oluÐ ݌tcKrzɑ3=3ƭڶ 5r0_!Gi[:[p"Jb"u*qBJX~'Y)rRgxzp_bj=; dAB~*f퍤I-zUޘ^x aF:O3Fs5Gcήކ.Ks,:s,صhD 罀`՚-#&URsP5u<]hMKe`F5hk1X&8~ G߆5! <Q ZK;:=SOp.DB4r5;Cd޿F,$ȁ <`k6I}H P9*,eE]{ ЙW7/8l\@sgP\}0~WV+6W$xxs˒xw?qD;nP:VO XCN1']/@s~\ALc",w|"BtV&3xm Uek*kblm!ZVn#0Hlߚ,]_Pg_&Vk `!`}d+dLdY){%ҮAm  d7o`.\igeGf0,En_!Sn(A}h-k.5i<ɇL*kwumR1-^jܶ5e(ߌ XSC--#3&=XAs( dFHf8q @ͬy1/E,1~IXEFMVG$LxVFȖ).`Иd Q(!8aOA/YG gjm,#LLO_2giv:tal s MrZ&{paeFLic&arxI-R5 /X2Fי|B }とi88&|Wecٰt.i&UfoU!~)D8P>Tm~D";e` #j+|DrEVf\oطN"P wCs VӂCfVqI88+g)A_O pVd|8'EN||$ M:Jg"3#|Z6ݣ2* 촛 =//3Cbf3Sk6x%{yu?l5柪5KN(/x:(Jƅm,2 8DM?Z644p (6[.ޞo46d>0b9ZP1E&𮋂hT;޾aDK [|fΈ)mh $'K:ڜôPohr!W ː䟤WbQ~8޻]zZ!5$x]= Kre0YP(@ ƦSáW+'e(ɨf_ߺ&_&$!EP&Ͷ.h %tP5 6F< 0N}Cgt#%qapP+ ĠsBo[*v.tq TbPO N+ ނ=qzk+ 4Xxƣ\lt(.-Rǝ\G&H?Ǒ }Դl.3Sio*f$Dy@o07I l>m!]I n+ȕ($1}Zv6߶iNHwAh XG໐$pigub漟9^IѥBS>BC)x̥/8ZzZ2^y4"r5Q}KH@xe\ 34>/4&Bzda>D( O.[ pWQ*9k3Ԑ솫 >$ALM{4nx;&%9@Xy,ӆ,F?OZM}(f1gyMt"If~hU_fsqEkF wI-}48<=kw$IF _fl1vX I;‡nЗXC_l<2 :g`O25F*IA#`ZX|4,G~X{rY۬iHDZeވ,AhC?u&^8yl yRߨQ _:{~bUdcy71-lۍ։Htޚ 0fi|c@zCx"uj5K3L0-[9N*zn!p|hIW^<c=AVc9 2q6cBZvhQ t8L-?vʯo,\>v;3 blpI HJEA魳#QNrF](,4XyVռUPZZY.ypBũ)I>^}d{Vf^YʏC6~T8 p]JveHo9<y~5 4dR80%!{ [F5Ѵ@U?7ٴ9f!*|qí8 b_H6˂,e!6~C8S0M$ 'SƤz)+ex>HmFjp/n20^"dT"#t-B5HѠ%X*œ%x=#prQ>S1aKwt_bޅ$\0pYF4%adRBzܛ&ᓖMq^& B.G$Rf,}*K"OՄ #rk֛NzuH#iwdTEb=v:@c]&J=Ń6uruΙؕEj[5RN*rg͢3L=, Hr,|%VL} GF<#MV(&.2RZўXAMFܟBZm06ר"cp=nNTMP\]ixiU.@6B9j@wYIX]I02gotg$/}@IзhF 1@zp:":*u q=V+s꽟 h^ eKO{ﱏan6$Z#R"<"7/뿚"tX/p$铯u:JA##m3\iOl^ +ɺlIb]Md?n ¬EEA_ MPtC /@K& sj) ٿJ6+7)M7^>,LFƭ~8k~o=oǹI@xYC-l od+s Ǣih@MXj" ܉$2R XnSD]z,9+/RԵv')˂546u);7+^LtjaQlQs~o  0cK>QnfSKw(R ]P\PxK^}A>%v㻚1:pLR^"{R!ߔ'ϒ|=@MKNW9! g@b{ٷ_f"=k2%{/uΪYUy33ac]݌WzZnI).G$eeG3w v2|aR-g`ŝ|-rj8~F* dS1X9EjbLE2~E4ohz\N$>O4o{16$_t.l 6 5t :z(] i)ȂpOhE:ތ!ڰ'jg{{6knWոkwċRk$r}aJq:iQe{n#Nb iGǠyN!tJ[lÑÃJĩ_P :^I/IQ2NB@u% xm?WRTaJ{z$+8j5ՉhE2{*>@?-1zE q8#9?%n-n&]<@*b5d%l 8iڏ?DX`i8E/v@@}rbIU=<^Baz6im5_"EP{}9*p#R`Z7GPy-4YiZ x9#*6ZiuYԠ~/Q`5>{oYc>y4QZhȈ~=tp Ŧ 7uL̽mVFM=1[:vL9('m˄Oů:=-3?~(oe3?㋟bd Sٴ񖁣0 GJЪ5ģ/4tz2N$,'gxtyfxb>?D-Ai{3ǕfK,f`?Q|.Y׮-CFplѓ݅.33vo;O2UlLϡk4 =p1%C2IEm'Q> @͡Rqd3=tLtjsV[Mʎ JiG#~BO7*a 7wy bC=QsQ{k)IiVWFh^'x߄KU^Щt)J1r{gw=s\~8@aj+ge:D`kLx2 rZ~E8T)j4e5B;SdbcPV@|γ0]DbywDߣgDmΠ/*fVS;1r' 9jR4PS`7nK1{@z7bK>%O4|bZ]Ӧ:s},ԐU:=T Vώ¨dJcl&U[.W>ZIJGһ:8u]7LOG[" 2Hu"{Woᨧm0Lcɖ1(N3:mxmr`Dzp/&dV]`RqN$e;1~P>2pMAXi/A|m Z _煍#K<|]ntI5 Z!cudn~tS%Φ { =kRhOQ/0 X Ǥ#<8iQ ND"[Pd`W|O+z_쥜\,KP s/Sav^?O9WX :G@RU? ,&*[X$0iu^Ji3frꔮ.H/LGgDNćJ0̴uŋqf .i4|.vS_ny5rv继Mx(E]9 A;ĐFaǜο}*/ ~ *ӝ'θ,Bx GbTM|@ U+s6W {ق(y1f.*{zQljØo+_)?tZVAp5Y&cKMA֍S"{XY+::ܤoQ"?!2G(l8|FI ha 7X֔=XF-10XI>+&}Y~4~*:8aN 8eFxź1$/3Oeb N?7_J3}5,|T~6#2#;CI_eR"0b$䅤'2=CU^2RM/L zC?CmkyUW5)]W]WԚ?3ns M׳Ւ"[C9shD!k KAF.7DBO8j*RhEy ~p"^[c;7N(,6wbE6"1̄BuΥ՚ש?Yn_OI;~M+(]yD0p>SH<~»˹c-6p@f/ kf(w,C2= $Yi/qU&e͙b'W:`V9-XN8 !|g[H(aK{C'"7_5ƿýTܺy0/b<$2d1|GVUAay6XB7CFP+b&1Cן on7+9^^D3|b,D{x)jD_M.\;}S% os#O1J/NCMyY*])ߓDmaGn31k *=1pU"&w#*RLjK*TxaO6gQKL7;׎gjte8g#A828бV;c.d`:thxADa 5<[tbIp89kV isLp]$0 0l{ .ĝJyyփfad}DžTAfcŽ vw]Pڔ0Wq"sj㝅Og+QkFxXoH|?~]QLI-MgHfg{<\QԼwo'C10&(?l<7]Ѿ9K{ADyL^_wr ;qV_5:lvyס[ ^䯿C4?, %f! h-D&aׇLjd=5b%sxsȪԷ$}_rR \3 ,6kT0;d]σ60fJJXtNrnp{XQJ|ԑEC26!7ǫW^{pFMINq$E#\8-PdCٱk^eHPK&"?$G1MUhEvhm*]u}042ꈙKa_'AM`Ԫv9oR(WSÁt}rUŔ.lvݏIFoPˇZBx8o $ 0 DԷ}!Ǥtie9nP@ǡLܝ&M=Q:dإS;Se/T+ckĈ৶"zj|֣۫+Ҿ_|uwxR.x58DYTOsj̀^kaad .0]DoA6p|D,ʩZr\ʳpe70V}43D/{R7B] j>'Α]mխA İ7a9p&0 RnFsEY%ݺq?;aƙQUܓ|-=e` M~f]t$k6cgYoIYʣ7ò.I^2d՜y 5jxz͡ť1yd<àyt4ʵlU>EƲuOC'\_n&fJ[|"wՌ]+e*;nx| a {|զʚ¾Z|vJz.ٻ*KS`0$^o|T ~ẃRG1 W@ jP5 zK+n1P'f4ЃX=ww>W>5z(-Ms]J}3Xݠy;thEC Q[o/PƳo5vuS*$ǡKt mL3g#1 1); ZFhEs#dV.)0} <}ʩD Yಠq^ h0ͺu̥qC)?H6y8^Pvo5x"1+0(?ԱAĆm: (:8!%o a3"Mg= gI]53'.`ɹix-"‰`GnnMe_n)-4̹~ֺ=-Qˇ$ovZ<3ڬrPh$J5bS+UY, FW+^{ӔyZUK@~DH2|g=ƚGO= KyMeHJAt8䴠YAe& Z]c#w YpwA8O1, H ­=]bВP9!H=D.BZu} 8,M5#$a!eV>C'Z} 7&ur?hgXa` w ]zyrޕ8&t1EG>F|h^H<^\&} 6lN⎩U[K,N8rɽ a Ύw}+\9B[ivWz-"Bv>5/ZDUO"\Ux8a_c1CB5iBQ*c -IP/Q5##(Zq1JNE3!@0Ϫ?~LuNTU!DL+|vmt`05i<(+ Mɑv,|(//b#HѦ2ۉ+dPO`dJxlYDz>pqw˫@6)`ks\Uo(\H#$⪾zGk(o8LNA3PTBΙ3r־noȳ"^K׷[FƗfa?5_c,1k1u[HS>~.Ln7FXJDڄ@Wj|fv:hLXYs]v[בS:vDadޕBBBf>OcGP=NUɯ>ϋ2BOeՆj7vucF)H)]swcr-4upE~a_˵Ok(y}@ t$aJ iufAtrEc\T.!'+"#%ӿg9Y3p)cNzYJt>Up2󎳐+0( ȵOp`D~DC v4h 궱q. "@/:nmͩ?''+R͆,9}wi*"() e^~OwjoPo:S@ShNA safijs!6"j$Ⱥ}*WDbZ/V*s9ܗ+;6i^>FBj{!_a#FV88%V%y9:SҲrK): G7ֳo0ѻb 0j%,B1n((D(*&@D~ғ[ڛeH.b2nyBzDV'K'peDSzV,N7O>.翯8\nU ~lS1SncdXJ"@Glw"JwP>p*|,-\,rNJ*ktQX4B~{aXLCѰL';* 7[^v[ )ӋFsu1! cD_SzEd}!y5O Ǎwl8"#gXs\cu9DOz6O}d'b@#fH{B]kf/;}!f:dEw6rƧCpg:>EI%k%Qk }A+ƟТ&-;,0Ⳮ)!]$W|i\Jοfczܐ)8d=dDUԐ3[[O ҧN5>yQz"[˽pO>1qcT#F*CO;=xݟ:<1q^STMKҼiX8%mcw^+⇮+9;Et_Rmd^Jʞ 7qSjQ"6L姂5ypHfZ/xgI:*!cDSUXqr*"@~KҶj$v/;>w@jdm!9B~\̀3|!A^/#M>QL}!9BsH/I3PDS|-wM˻G Xh`3(X^ 相X<^gE^8>,j$4> tWi鍣C7А.:K׼r |9sl=xƝ0_j"! -1m#h=\ l+a%M5D-;\o,)u&dwէЊe}(0@ل^W1_NL+J .'7(}v:~nM%8uӚ7*4P"@N}TkYj>H\uU5H86ۻ Jmx:Zo=x#΁y0Da"?<Õ3 OrM&.$U,5-_GWП%TD>t5b<^R1Uؤ֡ wp'|PAr!h /C["WpIWE%f,f_|* lr_`)RnwcP7w #$_MnvEp[yj4n;'EXEzH*}~'ձ PxDhK2jшh %#/αkxi^{ :MRh6Y'yvLX;{ lF]FP JE!wb>;w؊-e fZhUr7ah>Aژc-Z pQ'2 s`9 pQ*i ߶ÈVxT2u@v`uOKuDxfهJf.m4Ps (hOoM)i`9:y(dž"! 6[ y2Snb9>qIUkxPkVNVyj_'ھfC5H^"'c=2j\% Xvf޼Q7@fOZKn cdgEY{VI]i+AC 4~~'MJz>Ub*.54˔B(#!"d'Fsmȼ?DVoD~2-ʀ Đ2pv_sSp,}.r[-weZʲYP 4*|?:s<߂},:~bҊ+3o!߻^ 1s۽cnmqxJ^AOu\W!?3~qA OP5gohQ)QZ>nʱeN#Ԯy' eTCN yRN*::U).t3qJt?Lo`khi? {SwX1LR&:H? ^C-A]YzAk "t,Xۮ3hVz-!›NPE;peg ;,bUV/sc(^FMH"kVhJ>J?LڦpX혩6G;}kQȹ$V@]\;sDi&{ rT=PSW'H٣z A@98oprĀjcP=B$WL:̄j ȷ$wA'pakwZF4D;Zd>@}V|FX4 9 @Tˉ};սόk'X ռa KHP9 Mx լf?P%iG\ AbDp-"KiSZ?B5=Aץb.8j1,WA)vrϓ>8+A7b1'w:zV.ߺmc]5Ƃҏ`[gPscysPcI.Q&8[tX ~8{%] '4O F%$,I|/C%6 IDN7?}U>D5H >rG#ҳW"0`uބGZo%0 |*LUQAfdFrC3kˈaϡg8Qw#nk~f3 /%N3wUfǭ%Ex ^N yQM21JOl *Sdq yp_OTlml.ػ>4WFo= 03v=>fl|;Xɶ9dة[ՀrSA簦0Q#ַVN޷` ^OBjq/&WKfP:6iHk=W^0]z+AF|\trW鼸G7НYT# $X 3䶻'-h bI쁵gY;j@pvrR_흚-6-Kv,D>3_0{EĝRI͆| ;N ?Dn/p  @#FN k0zT*O}Ĩ1l.⒒B &5Kȟ,+t\7|4hZjj7 DȨW |%0&՗c-ͯ{ssXZpD ;;uJpO@<*AOxVI>{xvb q;G}X""CXS؈g;ڒ<"1) -o@VFL&RDg9?b!xؘ>D>} A8㬮F&qf^ukSH4ϑ" qٺv;y rl'gHG9?7M.Rٞ?ld> 1'cfTTǙ!5bڼb Fn]~ѣ~ <jeEǚ*ILzH SB(Acyd)rm@~@{G̉+Y+~"4ӐuF7hܪU͚zLxPoڳX:yn %li~~֏l*Zw"d S˜GFQ0n7ǁCRJB5%bv3 |v+ۧ,b,7={r Ym.=-#8wL $~ Ds'v4#Ԕ*Sxst:4 \Z6~gq; 0# ,2me]7»[|e R`h4G?2dw9F(˃E\Pv=E|h֎kmdγ,rA׵w~9IZwJ[Vr&ζ-fkະPӬ!w !"P!/i:{<4dŲ[iG8͎=WØs<*IwjG[Oij0ׄJ ;>p /Z.E. ur["5N uVWf}qeAp-d~]){x`F-hvNF-܎e>Xjzg;&a;hV>oln J ƻ+ Li б,g謑^S_CؐL=7c388g.1+㌢y (0\GAOt|d֛kH%fR\Z"Ktǹߴ\7Q吉Igdo  NU6@P|[Llc\5Φ~֚€ry"%,14ҤT%*LTq~u["?7Rbf)i$%?DD6q3ِǓA#)!qqGc2֐NJV$P)YJorG=e@oz]-#!mEl :.\xثoL 'x9xܦۼTGb>03ǣuu]Ω}]Y1/!,%xZ@Bʴ?:YʶϬR0D#=Y@WW %ؽ#Ey޼+3>6xD1H2 Il@mLfN`,8QMWH@«系9VWЉ꟎AXkcM`J,qkR 'TI#.7tT^fiZ`M_vZHcOћ=t۹T(~L|ć9*v{VF;v =;{ 67 mR+ҙd=w/D&{ )&OXLn5L!W9 a䟥lO);@)@ɀ7/0`JC9̴E-. ٦OJ:jK{v!M{Y?ym^XGRAz%FȒPOi| riamSloAe&I6s*8uv)Bmc뛋_KL=73ʱԏ[2C8ޠo>gܬX [UGв*|sI"c~[O oWa,, TsyC 5 8̢sM?3Ot'*QK0NˡwXtW9 ]b";!+ضT>4qHJi`nj٪~]JN wߛ2A̳WSӋ%Qӿ:;5^neRBR x2?=uw`Dzx=lzR+Q.IN-`8 1/m8n}dpfzo0:Fᶍ?Jkř@VT3Lq1\T;0]I X/m}smןyVv:T p$RxڵC=ٛ)M ⸖E_xsE`UUz Hm<4|Nᰠsch*!7u6^&=,rY~۾}Dmk~) Y]`azYZbDdžj47m=Z_ΉDTHC+ )4]A 3Swm]hVW'&'糆gW?^:?>Ҡ%A(P7m{FǁN2Yf@1Gwލ <9^~7H+ay_[q(̓-啩e\- 芩)Aеλ9O{ ʶV !3+(`7-2)0. &icӻ*ωO|OQsNRt%B4u^l`O*T;gvAzgNW| ɚe0lL`"P<+PfE1O?n; ʼn<5mѵ!YުU:x]9]tJ4Nп8Yًt8.c#M'6!XEЌ:QBz>\9RT߶`$ȏA<^]3XQ[zS⵷ *d DMY!.9kLF6O(UT)ǹY6 "_~]r5Љ?^NCq(ί嫟뿠i\hu̶r i֓|mV9"o} =C\0V")fLd sU4Qe*'9ȉY:`s|Sо#k N:uO  |w{Ӧ+îBf\鉚5^Z}Ꞓ9{s2X!:J[뵽$M:~ڂ8<7{P%K=B1;z0QS]BۉԻ* ?8 8I'ˇ5I.g89͝G * h0UZ=9"+KNْz:@m`м;IQ/b"5Ĥ4*PS?vr= `nJ{>'`|i[NP<ÇUԼA&~,O"1ZGH9PB򩮜\׬@G]ݢJ^Wm9Ǭu_Lm y s @d r0Q"/r`k1UJI]aawh{p/4__;~fyQn\>d:O1<#R T/]Tq̀E6LrN&hAC ~Ahc1~}q荩xQ(->kmr ̋pE;8ZO :.p#ʹ5sd4oe~gB6QA'E~7 npθUR3*̮ES-rc4(L"Tt@vDPlgy qWYpm`>Q?cOYdY_8D2h]j>*O,KYX539}o&Tߘ*vvݓ+ QpNͽ[LYQPlՁ|_kSs۶|Y4+3ywuӉlHN0 ؄ӈ>r7r,b!vz2_$0zd\_,ddeig(-_A8.xӭtGŢ?z4{$ ]ybmBsQ]WX^8)y@%zBOOIpm6(I SX,MCr= im`OZ$zh9+S 3|Xeɏfɤ屫,ѥJ-& ۙC44}cO1t`6`>|qFmrd{G(wߑwOsĐJ}[YNA|}onrGb:QfН_jxx437=(E&79=nj;jrgsz)He4{(y3JX5|RK)Tόt7ߺ&8]HPUnqqpT /]Gd}QƣJ%q}liO3ixA|Dl1$T"u8$c5=H"ypډ+竡a*ՁLlaxĐr C{Җ *0[7uv%6 t|D;~KHRwݼEۉ!L)Yk>J6sd/#@Ղ/>7p`/@1PQ"O4R qOa8-S;6(hp\~u="쉩4I`=JQ1\~SxpY|Wý.K_rbTY4X O?!zz\ 6W1[SZ"l=b"nD ^ܗ6f"iBhFR^gU 9~NF7!19nre91%b-3hD"6 {/D=29bDQ_f:<g2lPGVz+P@ e3*y7_N _bd(6 o.-_T:fvaTJhKkPZagb:lΫu)JӢ?PL?6_DJk C 82R{Ǵ8猪Rϛ&ȵI}QK!%6OD|2~j*_Ny-06_oGu3MxDH aLLAy3:DcXIXkMcYwWOI'QBP:gϡ>W?߳TÎJQ*Ksxgb~Oޣ77;R'L*ױ1HUAnƥRzetC!{g5M9_GVߎ< KH1/?L#_ !,eFfmɫ댸 3Y{՞tcgxfɺ#Mׅx+ stC=̡}gP0ʤAѻX|?(kKېccvRA@n(lOβOc%꜠s:ukZP>Ԡ/cBq0W%]ؽ83(W6eB[WԽ%T)*9gHmUvm1a]!!^zZPGb-XLQKX,󱧁'="5 (Bb$/v>Cs&1FOi|,4.͜[4tDFJ;:jW5kRu\8{! 7ӎIj*-q꺬uW=&tTrTvw3taFhO`|k]UD}K 5̱^ a&Ʀg4'[ -wOԊнƺS[M> *( }X ;)A /rE˥4gplEZ <$:k )M%緟 mx>Pܢ"o+Pf$HC0;kf*J@ļ9O[QcVJ&t{Pϧwo׊TQ(2Sq;śj7?B9t!_hx3֊" %<*9P.LQE?mKfisjc dGslϺ&elL YB]L,H#aԽ7l" +R!pl5& Wûku Z("|~\Kp)bm|`}`ҫ{#I`n7DAuD .s2RիB5+=fM"bC^X24wſ!Ji]CwO~w'm7jZ Vzf iE˅\!FFd- ,Z<0IT/. zFEۘ`Jje$^q lꞁ1d qcxنس%}\ͥ28#UES !Eh֞u|z~1?&%l \wB ˽*b$*lVcO kY@ ]u%M'DU^P.e~}$s~n*r:ʉLx^.M"&(%$3q>\Hkp֏fgS+>Q?v UK)CFS\sUGq$̞d翏7H|+B;Id)ÿ)5'C$?=(-'SdZf'o@#}Ѭ 󿾸v,z wVJ*|f7(&3g9'׌΋tDZ6o+?E%>I8-,"l[ +Η. p#:HsK@7=G\{1@;7v3uoǾt3"5GAx6t붻&<3_b?|X2d=}rz7oSo796e+'[-E_Ժ~\}^ f%l_V&,%,!D61Fn Ly|Rj*NМC<^#TP$cdZq(!.[wKrgm}tIWt;9G&nwH&H+B p0EQjH(جb;1JNlʔ__P@7Mެ7YSy"on>ʶ^A}Ү#z;>L2=8@ 3&I{bxpzikNP;'-8 "~nל/dtw)kwɀؗ5e>SЄXLFJz+ e9+r[}1W0)Uq 7}N?B$"ִ쇌emلf0`offàZZP\D3 mґɝߘG8ېiROَ''l. J#u Av$HBM͹,] X&({3 vJ7١wzI?ۨ!9TMƪE'hXe$RP Ǩ\obȥ\O> J #u&d鈍Q~In 1È9FSz䏐ʅHfȬʱggQ1Ltg dq 7j[$' @e޴"|5ݗr @Y*f`|,U1khJECt5:QgQ5'+% x#Բ{YQgzXv}!7 yEYk/S5RrږoZG1i\2MFhp]QL*2ԛ>)9q8rpN^/ H9(,$dSב?jhNAIK~ۂ(חWm lk朑 <}zXAhQ azI q';voeEg{P;>KnQ"j+Ye@-2.Rif3VC$<~\\0E-asu\= ʻu 82J]/"^\54D9+-r>bVCZ] cиt c0}" Qb!$(WTI+\@\?Dុ~hGv.V^&M!DM&t Y]߯ч Vzڜ #Yޚh谅=6`4+k3A IW TI}pʹvY˽C7hih-zA(#xaݔE/Shi mȡ>~OG[|M!/@[k"rWh;k1KiՉ P?м4?Yeޡww!QSU/{RԆ)`wI  bԧrل~xЧF%?Gr{=!:$fM:ca5`,xfEdjDʥQr1Qe9Mg2)Rl [ͯCiau?̹!HY뽰;ڌqD5l0[ɉϘ iXU!gwdT ہV) ' J(dOFE6Y cJwN>hlmM5JbeijkPQ1XZm^c^o[-$lM;D5S6p]YF,)jN|EzmRfm|fJwx6 \,C  XjFl;&zChձ4 ,9D_g ;L'4iN f fqt.tEG1nǂhp h`|=Th<y[>vjUZ#Ɉ8F׍=fQ$)cr9&[*{'ZM[l *˔^>Ǫ iEL&йɈ73$ V`\A'##ľ0dę5-mU:`{5FIy'1'7hkwT$#Cȿ0P<*ev(UəaO+#.K:^T b] @3;+DžG9k EypG% :m4+~8gbYrc|pPVՙw2YxGu0=Q+**I%;uc-TRV9dSrL3pn֕D`-d0l^Uhgޛh+Z@ֱzJ6@v Wz2 bfMa鳒>M]!M;Š9m%2퓬o*rH &¥۔ʘiT[Dc ԧiZds%lŏ<"_5NK0FSQ*LU#uѤ^ ϖOg\26ycN++q_"9]FDc v dg~O\7E컕r貝&B`g|!{0(9hz x{e\p9eQe.XwN7A[RbGBC41r`N@}ﶄ;D@u;|0ƚt3bdW$\ټв>Jkp%M7z!yV ..O7 (:޷ R |^eґ.]('*px/'~cSKͩ|O9(L?oSZȰ0?bq{oC3g%h-mjdOX~.H,{Q1ShLpƓd!*WٰKCR?i1ḭ &UhXq s\PZul G:'z,QS%yJ֎/c8zCq.j1ɨ}J :H ޻h/o䖽k+8Wz \9i7+/!0H$NyC@89pm)3^|YS.rրyF .B^TpLFu^Y󼛨V.c;J 4uʌE `~44|>}2ZBӟ`e_Gy{Zn))Bp x7+`zAދFIQ~0~q]X vK \C䛄㰅0&3O~6@xsΤG7PoBX&I]D+b x}Tv&{-:w]jE(`-I7X"xёh|Y?.Wxʵ-%V*uN9S5sn1yMX A"J.l9qJA[«p)id4tCk<:E&ќDWD@;}cU܎HYzSeʺ5&u潓Qnxǵӄ!! 3JNf ȎZ䉘^?Khs&{!*#N$+8b 'JmJGڂ!g?홣̥ψ 2i K^Rn\]{t ԯ P:iTM?Z>?:aM$ p2h*n]e4x#1ޓ\_ g? t)*gcǣ4f{>| I qfNGP:Unc՚BPϫ c{-PNJr]?^8}KD0Nqy?}zw3 )i ڼ| kwB|tPR6L)'51u1dW$b|C|n56c#,/Yj;wg#- ;)PH4Km0 ~ hj3 c2d d;7B{e1Y?;VfQdzbETR0pY4>ϵ=.3l^qP!D|6Dj>MxZlg|qő^\Dj f|BJ0qKH tÊ {E0 7BZy@kS./F\3zԘZriC r|1rwāO52Cx8(,H\Ԣh 'pĦ%G_mu|8^g X!,M)d/T`QC/ VL0|C74;u;fܖY8D73qs( >iÅi|E XɆ$9#`[JJ\#41!AM^%]͞4wԵ k6VX'f ,VWE-vF녾NC6 fPH A{m1?و,PXQvܲgP[ !!PXG{-j+am˹w5A :'fd&|00^K;S%Mk _Ax5)Ip*ٲ/Fo'3AL8fȍPUIîkr t= on2W*CWGR5,rERET"4)$r2&.m1m[!<.Dfӌt9VKOc23U9?TŒ~>XyX+ܖ*0^=vJSi7 lTΣ-9{֫0 `u]30W7Fs)`?W J,WF-4swRi?AeJ3Q/ՠ4w n(,IEc;jD,ˈr{k'e<#ǟs60 NbHʿԖH ϷG_Nzq:K!H<=YawM]}1x *fr6+-$`/$tZN;.pC,iK7SjRWX,#sU1~Fpew3kn]0!Ҡ14ύ &x*x>:4p9ˡ%gL03;<Kwt,#H-U@/7ВKOF%`$q5vOU F4ĞgX$XT[͒}}=Ft#3̀|Rp{ЩǭR^9O]Պ0JGEiyesHRx,+(@sʹK3bzp#*EtJ`pʿSyTml^[^!Tk?g2-zџ$ĕq8KίV9K!ZdU&*K0ޛ0֩uz&A4y+i'؆]X[;X 8? LYdp>d=F =&8W!vѻ2:"7*ebqZ-?9bi WK˫u"UI`ncNaC?_ɸ/o2E>"]hzzjP ؔk*b{zƄazozj.XKti&@pssf$c;&ݡ'}\D~>i 'r)?Z;"D$ނѪ]Z ?Ҟ.r:1EV߯-5@P#J(kyvFSjN6|]9 0 8]ׁw21py'R& aECm40Df\OD*n"3m li˾,])#CD6QceZo (@Q ;vZ:ESزW.zv<&֠b9hCݒ0ah2mXe |`] .g_:ȬcD3ٿf/!W;VS}Rֈډ5 W0o%(MpPq-ѹЄد@_PjfaȢ鳤3Nm&K,`cwsx7)BVGTN?م#5a['1sm^;+}5H^U.8}5 |zʘ3?o&ԭu %2 r {{k8Qq+Ɣ**tW b31974@zܭ/Z2wpCxI5r+.hLDD~4$?\!֬5-`$% } j}d?UeZ!;xKR~ոU}Ƽ׃q]uC!>L,߹?*qJ}*jȘl^,5]97 QVL*FJac્ٮn BFJ=?fQl#LKrF{!ۅ *tV)X[)ЯBzR sD^\A :/4}U0.qt*F4| GqK{]I0X+ݘbQk10 KCl-S)߉k,mdh-{fmUSx{);*<R㫃ۻ/` G>jN߁9Rcu 7bw5ܦ˻^B MȎ~m ]Dc]gUOGwo;mЫDj_k ܶy~:K|J"P'c )c]{'te.ĞB/V ORqaլ:)nG8 _E[ڌghwX}qBqdL߾JAg@ZvNz+$ei߼AwN%&($ OVg 7o1Br@dDrUab#]/JU޻&$ 0z@Xn nr=DhhԇV'v"F*+&q ,D =9wfK9{W~8X{~HzY yNƑK|&4d@Gyj^Ks`T4 sLhXJQ%!5X 5>/Hʃal)xS:oglD\t^+M5> _PZ%/Α\Bѝe)AvX݃nQ]Vz/l˜Tm<U1^?['oF`oi<CR/9h;2?8/ :oXi뻢'K-Cn(k }nDf0j6^;-$Mj,|._VA\QwZ&6ǸJDޜ-3)VYm&| Lmw>:6|`KvO-)t=jAd֐t@ רKr~ڀQTH *3jP"] gIYzAMڱZ 7NѪ1G@8ٌE| ޫSދr?K}/N氘Ϫ^//tjڽOv5~5.DMd?`#q;<2;v^{dpI~60<]$e7hîTdIK 韆"?r&% ?ÿ̀ܦIEaڇ"%u# +ۀD?yRՎ-( >ULK)QcF% V ;U;?~^/zZF{n~l/p;mւgW |V4*Yꪹ/m%5f-G3lj1aGkU˦G wA1!I;B9C {k 8*wr;Z5nL;v E[Q穉(]!_G˔Annr5yQ^F12}Z wkPHwK-UQ.\NJ!ܯ|H%p*+5?46t.VŐݕR>T['>"^`/FZ価z\GKK0hϦ6{$R<|ݴ*JO' e$Za\t|Xo0z]WUX|΂;Z3l1k7hT}suE68W0a0FL0Xk+m+=<~!b(FقՄzM+MM{8co9JF2K>8s*g/OF }c2\~D6bٲTR`V%..Pn3O.ПFbPG=W>RUnf[p,H!T/gc0O,FB@[ۋ:rHޔxPeEa^ɈKf/%!eO4I. nd AbIc]v"g;yz\vYme h䂍,Pa)c"HNsÄc^},V$JS/LJ EA" wO ?m(\1y8˿ih.|;K5N X\H1ݸ qlN/^,iʖ,gi.pʿOEզhYpu8ߺ@b,Zy5`Uh0*X3a(S`KDjXiS=Y#l'9JWat^ $ .G*g ^-&%kRoNȨ;qq!_A"`cZ3 Q__&;&@;b>L;at#-$t}kaH{y3\tL쎕O, QԏRQ: Cm74.# oj!MDAyHW=P Lc~ Q +04@䪺Lm2"Z7OmIoK$>F pS7ǡWC&qdzWA2 ]X$&B_ 8 c),@Dll.w];[d @^ FjR<k-;$N6TuC殯 ɭzz<ˁ׹!L$5MQ9Mw(΂j隆jJl8mM]ž-uQ}חX^oh-޺ zT|Cv!Kycjғ n?d8wVVNԺt@{HL7Wr>%fBr .k3lv×ןQLThKn2=%&u!8؛")~m&;@f@P.k1x`j-l{^쀪_ *`u-Xَ݁sA֡( v: [3TA|Ah7|q?rt@X_ʋd#3z_!}ٲtlF7e|EWY}2&ũ"\5/O@󍆪 .f9mM*J<*_ܛEzS`N _rSzc?G6jI6iWy"iIh $TNGFrktaDIv>6؇6MҴda;Фڵc߷ k[G1 S{_8jp,{3cճ;K+Czr>,)\U!ՆCptO=?M)1kqH')x Y 9{Ț$kLnvWQcXNiwǞ8nzѠjA2| uJ$hP<Orه(+TS;1zyV\+X$n>gYqUP5f7 LCi^: =;SD4_=ڵ?unHO+Sd/uAƱoxh ݄۱V|?ŴVrh Gޛ*@,?šl~z4|",N؁vl CV dw䗧;q~ߺf)@}RPj;Iy. q?CqGJ8zMݩ5 B1ѡ))4[sR d9Uw:''irzA@?6F0/;^IpS bj #K+>i}Ğ 7BjK@,iDD}z`A(ʑ6Y A#50nkfqtO1?zj|n3W<~9x;rF{:x'v99O%A?Ӡ؍f'ÛQmD}մ蒝M3VdI-#nRpEI5y|TfZJTgipUvwp y.3\˩anɢTB27Qs#[G 1SfN3RRA'eW"pgE~Da3 v{tv}9cցuB*m@ϧ=t+%u9\׌{Q{6|=ˌLY?L,i}l$#D3AgIBd9;]bP|ow@yy@`Z$1&96p4rnk#UGՙЙ!4EL$sJ0~Qw)pPU}Jy6Hs1}Y__7A5aT-Q\Gж .ˀM]zVESء!,V%Ӻz :oA*yqme^EK &/Wt@ڬ>/X3w #{Y~{͘ejkMܶxHVf^>%)b6"P(:`,&nN(#.ݦ/u 1wҪVސ!^:\ m á2CF}+T⫖}ȴ#2*O^AEPs{Krډm]G8c /{;w)qszDB?{}==>rZC?^dKtֱClXGHX.*&'{M7m׸ O~ D \>tZMimQlw[Nj{_I*{v$ñٓ& 7]U;_ejF0΁LƉRjivCYg؈2@>PEX,'HRHԶM3ɘï7[V 8R{jp >,I˦&.UhxS6S8i5&gTbGv/Oh?{v nGW-B rk@Ys³f9M5S B1zَGUO:A Dj&RÀ -qW6"7jֻk'el_cnjP-׾UF@8qGmJԌx;:!ۀoFE#zkJ"XqJ-5D],Pg5H(#ۚ֠GqY4˛ŎUĪZ4XegԿϗ&Js5v8Tn~6Y2).Na}L,VyZK=+3YjuEp2L34).6&ߒR"? `Aeq7DR*|fCLt92QUVx|@wE1s[OI1X[`,;lKFWҶVUW|_#[QyRIJZWlKN:{=HTrOݣ 7`>(HH#Z_tpy!309"z'x):U'Զ^Em`2+"k"U }>ؿ֎k:Kn$68 IߍpVWu*;{&I{%{ڜ3 pG>"L3!=m ]0 eH\Fw=sg2/~W}D?h8G*BGh>5^Ra.BfM#Ǩ0Fe_k "ylH|fD]Ew1A$|(tI.3{e5`cVȜ5Oڗ(2 AXݙJ( D{l`m.b~7 HBIjYK#!S-Y|h<;!@;Fa3ӌde[~Z3' UᇙrQ"-fc`ֲKyNAkZmG3s:4Za@#OM%1buD_oRKk>;ᕟio;'ݘfEXz |^䡦Ӓs)b=E?2f&j#"bp䂖A?/Iovϥe3@XKN@?B=r&BcK╸OL13Cv-GZI S6Za6Xxfe}eH+I@1VA2< r-N|Qg:1B?x%h'Nw\\#|bsKn6`[vqQg^ n*@J/:H4k:2}[DDVى JҍاgOx3yd>E6*M{CoNO_ +TPu=&~= 3QdqBAR|#ԣh!/M]tkۼ+0K~y ?\a9E3i%J 9#"r5a۵.:8dz>%KU;@VLyDtDJߘ&1 2;2\[0 RA@>#zSe!"|o+z htƩmUT4Tj&Qf؉NebP֛g[q@TDQ.Mb;0;YVә8^s)./%~w700c+ݳXWLڽwq:۱ ߱9`tmyw Ղkoo#EVng*$HR7$d?B?9XK [ sʫKʑv9o:1ݸg~*$کj]aR^?q/R.|9NV"muDa+(A >pKm&[as0=:^\Bo}a$4r~,E|gvIp]xJ%?T34 ЯPH.Q r@Zŷ(S=m0΂5>6^"B}x9G_NG%ڰOG ia.W( Vkٿ$@+Hq+5rFH;ό"ޡ  w;^:a ˜J_f?**[$ץ-RNX51w1%c^6Y8z&Km)jCX25AOLwM;c<_3g9&ώ!0Wu4DC\+/q`0׼[ zT(r2x4`:ta!jh|#ׅ̿ϥ "Q'YxrfPGjŞ[rRo؃qpABvԪ wCx^=)E=e_ˬRkp~G`ޤ9}Yݤٶ%(b@N$u.)+ {&Rk=k'IZSļ5ybgt۩b.XQΚnUy{h;/EuMt^hbXū+-5XV i`YqI¦^gDmHh(Vbo?&V%V?t'*ٺspS{Rx$Gfw8; ʱg  ]TksMBf0_"=/S x\Kd B!$1Wjr Pd^E*qT?s]f&z+R4q `bY!pYH-g<ռ $> af#z= m*=p'hHd0Oд!O\%jZ%2:NA`ИԏVUF?ɫ_rn/^q(ܫ\ hꏺqyrd$lWPP:q'>QsJ@jZ]=JpeÅ͙(V\KELɘAz.si⨄GdI/30{㜵[$÷($+}2/9C>r.ÀK%uS#yҩtVyjݺ40nP>X;&>SUߑw* y'\Qr D;#Ҭjxe޺.bYuQCeϷ}&ly&o,24|zW s>hv4Cp5VtXK.RX~nZ')OlzP,YOx=d10 H8NBm9?֬V>WqH&'u+Oy4ԍ,0קL= ?sMK,Zmą'nBV{̍Dw1'WH|m"flfCdK*x|߃ng&&W4g&yh+W>vN~!Fg 89>*ģ7kf/5/Kx$/+R|6ƓJ+N}%Ԑ+0AHiZX_jsLT )73aDA ?/?hlt=4ARAR \ sϮ BF`_0 ~pO2ow ^ENf2V8 ]T.'ϸK ^' \<Ylxi3il0Ť1k\"]w "d3,I֖L7,*# A!څ2A]l$߼vk]͓V|$[GA}N,Y+rut O|h\@Nwl5M ݔs)*\@C3=8~W)ru&5{3K p=_%Ln;Ⱥ:t)=5Md8l~i\42_~lT$8'n'p~/7jDU )fZٲ-+SS2o`]fÆI,i퟽%TIY#?$Bjpk*+}1s`!Ū=rk16RPË;t ?ʓvhiak%:)wm~Ou!WBG$c(雷 7>,_`TI"1|C)O.5qd"v+֪t&^`'IF)wPDCasFrgԂ/: *.BĦꡆi7 *1G01G-r ҍI"ͦ #* 7S&i[8k.Bp7hޟ\aI;}E#q{M_v"ɾxx\&dq cc ax LO9c^??K ևD9ʚ84Ʒ?2RYۜcLY⳸t=;kK |QZ2*t1kNT)[n<ԴBawvZcOa|bQE9%pH}\d#9ĔAӾtOkW+H͒01\͋}g/.`[؍VVxK#fU!.{i儬[~+*)%RiT9Nțjfd. \M6JfFfޕ>~Y(ߊQ+ΔiHrw8<뱌Ef r^;lWAo17:T A=tC1ث h\獨/3(Mm0 ݼ_V)U<=r*%LE/yj{d:R4Zgd|׽b|& ;AVpIח 1W']:>\p=d}Z։b#W}e<1éG_d2sWYs Yy} \F/VEU؝ٻƺ"fF;rD]aO9l1S+U8(Ϗ.}ZBɐ|Ns;j{eO=+3 ;^5ZJ4 f\6Vs@2<p6/4lҁWgV͖NetE/rNdϭ,Zh1o q8}}cEYq3vEȏ4ë0uV4#k4 Z vp[ O!9kw_ö!eA23{/ (2C%k +':õxa ڦڣnqs( L&%FTMiltPo֭Dx}!!Keᜊz$T1MHg ڄG|Jm٤~rbvRWISJ?z~ >~ȓUn >;Gl `煤±AE}%7@be@˃Υq(at3iڦaBfhc1RW"-[&G8.|Tg"-N:ku .,?ytzwuV8b!97mT 5vUS( 4e |]*;^H[n1wY2T hYl{h(ۚ*h@:x^Df/;Z q\zYs}p6qXZfQ< 8wl^RՔX-0-RWo "- y]k变 A3!&R|)S3qrq ?nv:XIE!ܷZșW5d+:.SRS!0J[DOW'҈t?ua [heEV:fu]thYRŵ%cf@R< oAI¥{ fyų8}JM6&.G;P ;<~@Od/.`jx/F-DJ^6QۨEkZsrP`D@^ϼ,g>w?9 Ʌ_4P;G&:ʕQMIY0{]Q=:=?.OE{:x]f%\K6aʷc0Fw0$gT5dTOr n!K[]E&V8S$ڭ nI‘-G ۩Aȣ:bDĭ'` /֚ F~UkO.ʑQmb)eٯ]*U:i%nj*~, BUcS.o2N\*ˑiD ZxPzέ8grR6X!\&R;!g:ܠ+:)G5Y4;`7J69Va<1-4R0O%vŀuU\bPW%@Ŝw~MNQC*ϚtGgCc"`m&ԥ_-"Z$m6ڏ2z=bo)x/p0ڵ)^8- ԉ:.Ϙ4!Dx=Fb%k~ sS?,7\wLw!ٕ#c?bi/D=`w./p{)ZD-Ɯ HQ!c 28IdG\]R9cOo ۞ @1GկU%5Gby{lƈtˑH &#eP6|$o}T\DefBB{쿕Mz,⬫nO(HO/0|#10SգBQg\Ei[ZR q7QڬO$uŤZ:.Zd-5ƺ%n&ȱSF Ѵ gw:ޮׇT+߮+֊ DYn UI6n.?a M-h|"L:,s_&2e?M3 Dã)1 ˶*)f'-׶>R"K`3 K$#}qk;=lnJOP?mAxqSf>jIO)KF x5Uu_*$J%m$4ucɳ$r |ԉ!O_H_H-0&ܣ0ҍ'E:ft^a?|vD'nu w^^HVy|x^f/9DjSr <?a@uQ ?}( kZdJ{50μy#ك58 z}p78&;Cx/^F-W?[3Ωn,M'jImHh{^Z )ZPg=">d"fpe[Bk}SNJZX3 0FyoDlrky&0hknDhG)ObNmNp_f7 = 5d~M*>L xzǂjYD?p4&Lpcu]4]ƀjƏh1X/ߙ ٵXn`όo#t„k A0 a6Ө_uTVW'9xk?*N"\^|]2|ĞX/ k9/,s{Z{Ft*(6knrpXUW2ܤ8G $5kݤyNzT_\t!**HLY9*8>3?phU8+sqQOq~[P簫X);ZoA*9B*d>)K ,>V XT5UWحܡq+[T{gxV54`=}nBJёLؑQ <A4#>`5P5aKn&cTH#J bSB0 CTƟPz{ [ 6N5/<!kN@cnSq;@v_g˺0y;w 7$PYP}NjX3yu $2(,2_Qbg.LarU\e&H"5nC>9[ȺM9ޑ(DzyzSVD 3  ރڌRz6j ҵBB,Y3sn\ء-oD)[M#KxTs~SV#d)mv`q] 5\`%fo#39}E9k 6Mt%+,;daױďcؔ:ϛ4fJYVK:}>bDNNjX?M޳c[EzY:&1~ l]01Ki}n0,C`l!T N3OvQ "7uѡ}) ty!q4f=fhPO3;ЈsG35BbctʜDԂa">4~sp,}ZADCeB)?F%Sҍ:W,BE&S fA! O(f̅$$TEml߉SZ]ʀr&Hؓ$ma :ԹgEjRՂIC ^T ;7@MzE#ǢIpƓQd_AbҗBLW' 'H&&^ڥ%;>&SA"*K*d]WG\>}ܾ? Y;dy;.`._"2\M a<+]E(f蕋ɽ IyEET"6{/Tu:js$LZLց L\ŇKi7MAK6m`IncCz f\%2,,g^W|<3r^0Lx@!ԭIyDp#U+a5HtyYf͝R["aGMa:cz Ϙ"/gJQ C֗w.2(wœEofuV+@KPC#شj&;R=dyn;4CC=wf>W=q%/&+T$@۬s$~֙z W~B!mͅhH{b2gX(1iNpMu,FZ%e,-xY\NȒshηؾr wAAyw_-$c­3b|R;2(η2DxѲdv/r2m4Vbs7Xqn @, >DIMP:&z{ 4E9%H}v|ρG)|:aRJunAZ7/*szxm>,,+ c37Zgck<`B}~WP5걁ei!< ܂yy G<^1st.:d6yKz> g==(űyHn*_kCWS䑠wbēnqsLiݺ Z¦ևǃWߥ7cRÈD,yI (׵,qz9a o4䌓"zb ̟H(څc#v5G1eW7Ðr^_5|SHVUʒH!kMORd.QŤXi=X8 su0oK+5ꡱ4K3ߠ>oKň&Dxl &, v"&OV'~ilw3X<-"<?].Sɨ'(תKo[-;bf2訉] ghgS?vHD>me4be!IzZ_bg%k)vq8F`RƝTula-H0!J 'Q%Fiv%?AM'1nK\*3Wd] Ph 1Rjǡ *C`72~ TF%ޏM|> O^n3a4ʠ ըΘ+*&y&_!Z>{c 1Ɍq$hco6-s~|/7tJqRftM97:n]cUל=7[`f@'JPχmuȰۖe zc.bcZSYcey>@dsax}?)o}^>7{i THq4bGx7z>u+ +o%∑BمX-.$|S3/ɼV4NeZvvwTer٧cs=igE_rw:mRLZTGL0%{굨+OF?tDlgm ̛tTJ| >)!d})s)L`J}q:/e,:G"\["Bo4<ެV8\8TSHl;zt.,VeTTn(RޕO4U%jZnc>>""~k!+1]~kz6;[Mt${㕘\׷hE0rB/eS(beFV)H[QphSǩ6}8KHޱJ<9HH6h6GT>5CZ i3&D<V84︻^8Hۯ-ݏnU*S Pk껾UvkB y2BϿtYdܫfNE!%Pu/_a߫(L U 1fٝ-<[MxeY*t|K"+7kXGψ?ZTw*.Dz#r%*mߗX 4'^-Q$hw#zv#\Ȍf-%v?]&)x7V u(kV,R83A*q,~qYݗ9d0 \)I^, g6'_j!c o:ޮ)=I4oȦQI'~wn`*ކU?t&s琻{oneX|PQ_-]a\/*"Mv)Z BK>ۓQzhL m ^Gȴ|Ƨ3ߐI12ojOyh6gK*L~|F"tCOA|IL-hAnEuxҺQ)E@1N?3/**<&^5đVTPҫ 45B4Ϳm{Xq>."pR~=(A|%y-F'wouC$d,e7:cD\P#vZku0<NJ"(# =,mJF, VcKvf:qJGOh4R1O9E:-^ާ%eT&@/|!^BZxZ$/TJ.%_y8?ho*EMz86y%w*-F"WfLAX‚DQ_ |+1 [YßtSdr]0f/Z=_B2=wdeuF$bT]6 Wѻ˾w 52 fF!n(g7Cxj' \P܊5͸ZS6F8alKG^0RzN׾-DT|"M6ݓi6*-n˖~2-7% H̖hVQjrƮl&x+ 1Sa8y]u+y6(Q_%[\Lx@O *EB. &<]WZRwhZC0G E%zB[ʫ$I0I KRGQlsI-~b6@Nt}6m ^MxYEܴ8ɔ鲺eGTSk剑 M.bHE n0׽;33rI\ q<MQw,yNAq " (l3ϩ2T{+3w`[Pݸs8'gig؋b!Wel<'^όkNV<_6e'2 Uc"S C9, X HKeM 7el]&Y˻H숣 nt%nrQKUVB`Ŕâ.i!=YBl g o3#^ikl.cz<,C|,%m~v4FKPWn >/Vi2*_]AX.o z@O^ʙ>DG:tc *6Ga7Xc} _4k>Ӟz|i)'gbE^i~D]2o}W F I@cU7>I? v~ |z"ORI83ۦo59b*>k5n!YG@1\5UR+SH=tvGXץCpT{ai} a'XBoљҠdI* ڋFڐ6))ouI|vp|T BttH$* ki6H #X%} sDi-NMF7lT[uilzq#yG *˵ӱ4`XS=#>xY v=' ̢gz ͧhAs%Mh6RK!-+Jk!*:ÍdZ^eeQZ{ 4,eN<.;}sz*/A2m 0zR{EjKG2t(*z6!Q2Btޜ7ɗk賂2̽:nF[\!:B"\khB:uB]jO{cD(<4o'U?֪CW=)U0V1͋9q2@uнMX^% d^\xM/`aE WOu נ^'-0XUH^@@dki`)ݟl a8WßnR艬Yy4.o\oxb:!>?\r2lF4֞-zy zx )wUT9 Y\*`ѳ‰Rgnw23f-m^l: v\LzLJ?5[+sN~^;1t}2de#Tq! و"[vJe5`*t'G`W,;Q/gɸ})A2? -}sAU#'49ELCG|1$m 9NIJRkDsᆑZ>!GǵecfSJdZx% RwFUfƝ:>'2_#w& Pt3'`g:Mg^N-=PAaVJn 牯dҺ(M2P[kLϪwRW ܟqNI *R8:yfKyD;[wqR0TyJ;0S1mz,7" aa8u1xV{X`^tlHQ75v =@V.]J?, z咓am<3ݜ]l`=xrp$tlY# nEZ?#pP @ b2(O':G9?p:RcN{F!J{ŕDRX\ke3kLPށBٞA=wo1;>))]tӂ[O}v;NƳAYyaj ڼ8CP^=usquYv=.i96mcTXVP?g;r%dhKHi9 T}TiiHٗ@ǔ/gq&\Y3jǞ~9Q%`EctƼ)s M"h6Np^XVkD4;ߚ3 /ϩ-411}>^ XLu}4WQ&3ڀ}VNY;:VkG|K#dFصf ;D\ rhu`N>?#2v%\eB ȕܚB3jlH~mgNנE8c+3<&1zi4QSc+`Q1ۇ'q=X  tjwob\%z]upҿhfaJD D? Y֡jnok>JTsuʂM5_5QKw ,3{v~tHJ8j\2%n'ʡ6#t ŘKX"Bjk ӧyץ-) ׬s?܁mR/LZ|7Vᖗ |S_xVkz88G)UAdA%^!V.s.}h0}Bh9sS<~"uCwD#3&38 [w!ͺFf=`"rvj x@=d)S]O{PhNTb k\(%;pΛeƴ:ȥXZ2ub--|•1.m)n6ƘFbypxKÁ[8WOZfx2NؘIq^LF ,y9h4`|^<_p> `.U#u,B(Ѩ$BhbMO晄75vU0 S#ux0#Zך+YA\ XY;5Ez~E^zEZm{щ~L&N)lU[Vs]He0`p[{7 9Th)@{uCC z `h?sO&tL5WhoO'*NȆڛxYɇ-AkWo\ⵌsDYjtj>Mg$r/BƾLUN 4<]gWj(ӌ1;snF Dt;R4l ۰sǃhur['aJQNoڙx gĶH- ,]X9ϳICHa)'hg}ޒ:B[zB2)tSEE{R; fF3DYx7B#3iAXYd!i񚩣^e2?1<9q^xZr'h*,[w(|KL^wc,B=a6o|'S@Tݹb ߭JϡWDK/tEUfqH t ry P %#|D2x1}N}g|57+?H$.Xc*>=sVU{y4[iq?kXo06 Xɬ?б5 4>'gl )~Ɨү ZX$Pʑ;w7=*>J9BTӠ{[8BӊUZ*ؙrwRN+ȗ(gC 㞊@iOeRALӁ0dN׾^yH&:o=0M/fs H˺p ,L,1g&gRz@=$`nĤLo'~"ȀH}3)K(-8I0U,7̓=&ܝoݯ["kʇ1hx'L='ˀ:ߜJ$n>^ Vc?t61fp=9 ~[u]H3hTόtbcR!B@Ԃ:UVO)vOQ!IBE`sYT Ql6P58纗%(e* D(8UwqL6=iWu)ܣRSXZ\'P(:*M PۻXx`4ej=754`'t=[2_粔uՠckxB}r 4,h .i5xTP!*`{6Eb.tS[1]#)O``rbtBt,,Sp{wJ܏ TPd=f.47홼'nC {qX?;L4׏/.Gշq;ĥCx*"bfs֕DAϖF~tȥiiđa=ؖ99bG0XPSpg5(O\X/Gx=F7)Z!~(XAR2JvgQ2qxT!\>jr(FS&S/)%/r;Y E9QtuML΋&'QyzMWK.DV|-2CDl3IИQ;ggm hvɽv0SOo;M$k#b?dM#㣦]뗫Q{&)|O~_kb\@;=T:rRF 1m1$KK' q@N(0q|f^IHΞɌUQ J{3*}ܸTxQPJrXH'P3AkZn ˻?F\Bd?l%[]Z?Jh}7amJWTFmp8Vb bp1M&u@LK2Q<ɢ':иRQMu8}v!H-SmF>#sj/2r]03!,MzNF7,0rp3,Z4/{Hi8\Ͱ[iV83O90 n^3LPA?k qP9\&jX떊?]ZrS+0Fek\oA@7cyMm7i\=8T%!CV0Vvy1S^h~BVcq5ŝ)xZ(SSTyun_rRr+4F[@\31%mKT3>5AA]Gr.r1f~.wɃ!nfs>Nбcl{7z5µ]CI6)Њ 'j.]]2r`mTґ<$_0%p +ڪ,vٻU||~Ft{ֲ3N$CSaO3Q!9/]HKB>\?ֲ3]?p0vxY|Rafu#( XQ^~<`:5)i="=T _FIۛGRw:?Ԑ>t!|~Fu# VS!( wI[4#F>W#8&a2qxxIOOա .TkG4NSbAx,.Ɋ$B72hqj>3ѯ&4p|!Nry.տ7`&+QF7 kB&£V5,Ķ^9m-P82]+f{Q2 [l]]cznUmw/O%˭;fJJ{LOY3'nCcAќBՓY0":¼ :bNs CpE']GeV77 oC.s5Y9}jwVs|kzYo@t=S<$/#Q'؁ W!ͿgBTJ %aGنb!GuYYdgj[f;|UPR: Ӕ9Dž?:9K"jGwu Q8 Dl?^o} WV5ٸ&]W0F^%pnH,uX%VT!濰9^M6 E3:99Jخp=3HSq@2y̓.`0TA7M`4ڨH@p̽L/v%+=ݺEa?f 9RV k \UhInL/9(l+c,C_NE33pLAaěs_1["T^wpq/çؐZ4)9}1OS!S3I86lMz_%Iz`¾]x[k@iZuא6Lp#)6S"=N bc:L,Ux=f>f@.A diяbe 坚 YK/yſM, Be$v[SG aZ:u@;P ч2"A sܚ.쑵'Z'@& = e 63bwV} 9NGh^{|2?E~;q"gpL7M͍u&q1׹+ ] ՆG6PPg{Ƞ$j'3qf/:3`@-G֜,m|_AGxy1pdڈ6joԠFjdR~}UA$1uD76 ߦ8Z=Wqr=G8 FB;Ao`+,c/AZp+7LN}C肷z[Q-BFjT?>;Os_r:M &,*Kx`*t`-z8@7镈$&649@_Ti]\;)Ir}]#(O; ɱc{2x3K$['0TV}/AD_{w\Kוf%'1Ba3#GMΜ! ἠ8h'9=u;,*Ifԯ{: U;|YOVc6d9Lm>&}v^Z[0g/wD3|@zJG34.zcb* Z8SBv+e` Z^uU`t) o-h24E?$rе=TR pl^ (OW[2qyJ2Pm~ѕuP]P=@N c6I/O|PE|C H:B<Z@q݂gօ1hA(ԑIH̽Fxk2};kM055K5/ED% 丠y@JA'!4%h JoBuOη+}KG Dp h^U Ps =Z!8IKbJy #\s\|,2u 7&LZ̀gRm/-#\XָGĆ;RL&R J=Hu}aa85+ƈGdESo("#BW<Ӌ*V-俱ԉmq>}Pp0e@gW:|sbԼE:&Ϳ@b Ik&92 tY|M#ލ A^ް3jޛb>@P zX cɬyQs3do鷗ꖵ.SҾk"<8lU%'t mk#3}WL- nӦ./DTcjT>dЉ<1~;_k1 |$+X*\,hnx鱾z2LKOgp<эaK}1i.;~*{CY|l7y#kASv |crq Ćs%^Rц}$a}J;uEr?ޏ_mN&u:M4%xcpMN}HBkT_}+A,~mNQe^>N-Z[-dFwYXKٸ~yq"?AZ/ȿؙ2Qkca,`j 3͚9V0Kdw|E*̵qozJWHsYT YhPwNܘUg%݀Q (.",o5 ~4tz`%(Dܣ_:3C5J<L_يKC%1͜Sfϙ ɷV:8A; HBf>W.v"ky6U&0#5@}yV/z~4:#LD v;?;t}AC蝯H.Vgx  jU0wpu`GɁoϱ>L4f~d[Dg@_8 xۦ(lq%\v5fŅ5B% xH0T^lNNi-yocJEΘIVRG .TQSty.6ċ$߹i!0jl:q OR  VW*qlӢ0b\WT܂=߲yGKj#*#ÿuoО>o{SMfhф:!(Lyl#'j`@V꜓w`\Y6׭R#LKx;d=ZkQUXqDEIϓĀ]SKhvE M 4eX:巅lF@Ce" C S4Wm@D E,VPe-a>x1]kjxI 2k ^Wz4C~ֶ(DeQD&Ҥ/.aP Għp=:Q"x{M f)7z ?0;|.а' "Y5T?E;IĂ@њ?o$)m`U.$97ӞM 7M[69;AsW!- jy.voΧv.Ev؂Cnw2.ˢX'JqOP\&x]a thR+RVln/ˆYN-@"Yh`\b3{|xWaYIGZE0?L]Ļ 6>請J]TI6sya4h GZJ'u`)KwI{M>rFs1sJZ-G!#x],`A]:M:bM90Bf쨡x!6TC'@1ZUnn'Sv ̋jNl c>)mqrkTdypeQ鷡e@K tN@JOӻ,}ۂ.z6{FK2 _ T%>[K()A;Ba&se5W_i혞2׆W(fOc |QJpɍ0"Bu ?p.݌  XӳKS*8PD5qN:=˫|o]{UAC +Trlqg/j `d.o 9ܙ-. .е3kr~_-< XTP/x' /G1buWYIiNaMQ{۸:3x>3[OgW:l|cެ~[QW!mtDƔ" م_ۄ"@<=yX?Y0l@BG ċq愔=M.({!G`C$K0bMЖ͘ *)ư6P"%K,#)Ļ7\ }G(vv$*>MᳵͰ+j=cMHftk>}l VLfqniD]$d X{GD<W6N{.7Dd^@N%7F`a+9H,u@NJ6C.5 koV)x_CƸ9/SJo+| /tg8G_ /Rښ2a*I(}ԩmQm|6"UDJ2lU#<5ٸqdm{I{ ]/o|g)w@3(̈́S)/ +PݤYhA*>W10Sym+8& `Tﺩ7^2WgQrpz|9盈*S%%G\2ʾnWCylxW_ 'RҨzw( 6Ohgz$0!Sj:Dɹ~̋ !/}$O@#OD Rڶj!.!g;FT4ve幪m. X 0CD@ـʧ/sboN`ar<<݁}N>u%0+Fej`,7s.+p8ҩS1lsgvp̰kCS"9.'_y J9?'O5sN wRVbyM"v}t|BP0=%5xc\G*#?|\QZ+o(B4q#7^'+79x_7:-KY pKv('bGJBͯ$,ǿ<t; -_w/A)nH( iVnOJOw_oSu1r||Ԥ \XK]@T]kǭ? 4]C16B~%nKNA+aB [ n^~2f(MHI&*#:Oֳk9R2kXSvA8C3ƶ2ئht9;ƿ|&F @ŠqJwkh'ᗶyԿ4]WG$?`nؚSQYO;Z"IMB4\ '2XE@u~yf 53;&DW˛]rh2/rUS x"f& '"㢸}4QCq3lH,bWМ5|tCU|aSX$IL?w?t_uSHg'cĽ@ +USV"%I';￟|}C`sՖMw? CY<5:~]Vө9wр0, ͡6!̹y4 |UQP-cɾd7ive} Q 7 >~N.\! ܃]{iͅ9_ jm#?m"+eWƼ}?JZ=Mр>|,HV)P]{;~nFR}cbdxϥ sQ= /R"xҩf+!ARBd^(5~oH({ ROWcf7]]A$/?OJ1k!<22"l=gm[o4Ӽ0Eǩ!!%@2)^w#tokM/; ?-zonP$rϛ`AD:uQv*q|9!,RoL"XZpPeܭӝobʟɁ9w> Js*6G G@zE?7H9RJq_}X&|B5۵Yɟ3 *^<5/KYh=*d/U㑍 ޱ邠O³H Fp|@so ڏuB&E1O3pׄ -i(2aZiT@ ׆c*ȪA5&!\΀ۅKT~xLx¤8Kh%rc.wcpd}M@ Sng2`Y'd[(yȪN#b6r+ J #zRrBSЈdoU;e{< xL;dq厜/&JKZUtlVW}c՜w 7Sl-c|{Q X>A'%[xAǣ)Vb"b\x5nJ p%j|£ TB0iʷ KoQո!9|(jDBnJ(mrj:6a/Ev<ɪ3U"&چ{l[?D'J@t',_I>7oɳL:XB4Q˥`'uz# s0@L|ԍuQ]a2dꇤ~qs67(;gп)F5h{@q  _ɦBx55i#l 59c$ VC K[J 7ȃ|TA MA>Y;\Of`ѧ$[&={@,w([/Z*h,Awu1năN?#QQ7fR4j"q̛!:lcc]ۣsc;ʫ $LmفɅXO$,*r 3+02f߯c`m2Ή'b1g3qJgfDda7{k 3f}1:&v|Ʊ y`0i PJx2z@KP*TsCg5"T_*)[_fO@e!BFx|Cpn)&2ͥX\u3#5}iX<{j1L*a>ϛA -\ұ f 3J>ej:~ᦃ ר<)::S5Iu6vj|eߓx`bT֝J+2,1M>ɊsaGeLs_|'h=7+8/m颫utn x{ 8Y~,ICV97aX%z |T<Ei;=3S*}BYN kY"Ic0o?blONME°a\NF(1uɝ rZhO7't5_-gǙG-Ě1&$?WHQT2nӴW' gc$[ !vz,"v zo*jfyHvP*C@~J$!Y:؄Knm$ύʎѣ5KF`*m0(.g /92ܲ7HhFNk/膠%0?Y15$*BpBewxx%*9' Y6A-܍N}sG&T bS!ܮ_JG !)ݿ1%lA>(RNOwA54]-]N"cǣLIV/̬)~PiLιuibVs\;D}ǼNQ7J[}Y[Fag:?|.:mbozȕJTEaI:ZB O9 4=7V3v,Y-uS^p4f|~з=ӱdx]N#Q_xn'G^E8覟/G]+U X\{9XUEͦBIj&s*:RMӺ($Bߎ8T۞L3 j 2oZfr2b{a.n*D0noF=\n*b\va[J8]9t!UDl(~zHLHad"zyU5-,eilzˁu!G1B> '%PdE>uJTmq839.ȍVKHU B#47x+x_/kUrjzq+nм|x #_,O)- <8DC2L$B!rH \ռQn 3=u&-i&lsXv;rލ&f .jtURlR{~ -v*z#_&OflhF:c=f;&;TstL%iRn 3Wa6H8YD%i[9 =_xdd^،y6 eCD522UPgѪw;alb*0i8z@pF4ai Nsf6;= Ck5Mf*|JEh&۪eH|͒1 bOfdzOg S$z4 X~PoCg+P/ִB:`wUm}z,!TZ*<9+D< 0HgEiq+~+z}.9~|(W>]M"Qe"FN Ǯi7yk='RY=pu!;#Ix5@qRR` ƀ(Vʧ4Zʶ.%=HtD%ʠԴa29aGpjwQBz}sF*cξsh!-M71DC6~A"KҢS:1kc-YedU~f:ѻұ [GYtb\#a5UW39 ,ځ|JFubg0ERA GbI(NɁY'x-#]OH i)X.\IdJE+9rKcNd0b[UQRPWvXEpш5L <9 %5ԧ-:v* !◟ácdݿ b0sFxK:10581+J]iFkX'a& n3ܗsD3t128h O݈kX0WB!~TUoci WK>/@g5Z̲wtJl?r7A"%Yj2`rަub!HRG9g|o.c0O̅ ")!\CkwU'dOpRlyA.+2e;1 9I.ߪO0Yw*6 -iiN*x F:)-ƨC`:ɇEyE>Kv]KVv\V)k-_z5 q;~Z5Q2,=!vѣon_V|hb\&'6ݬq5#R39:UOjv9z27EA&*~cά˝uhngyg?f9vsa Y7e˴V%탓 6ҷ_5 $ (n?r쉆{#/ׯH5)y6zle҃SW}T#Ml}2Ak`d&g-V׮LuZ,QLԚw?lp<υu b;欆nB9;*fE[!֚}’9{)X`DVRM O\ܐ)Jۥ.* (.U&"|ӣ2`jc5)>}e E1(4sǚryaП?UJB3s72yANlPrN\&|c#/fdu(ovb V(K b4c %x,!g𽒠z̡_~W- m(3EzC[z2q'[eprQj&muDV{|f0?cSl2n/$7.5p,S]ƍTi\r*KM)?B)z.?~:;)< g 1cdC7~ <5Wx vo5Qwf }B6YQRU.2 88PF.vuWo \]ɔ1a2JIOY82K_UK E5gbfi{v}J ʆ4骒i%/A7sKz6)і(d*:vN_9st̉' 9@D@Kr9^fn`wDOդ>9}`60n8P;IFa;Os1bdV``KuȐujO[UUrsܕzVHh:'Hjn:szQB-R|Yό* XBw'vd_jmʦ4rOj/xFuMiX!$H5W$XNje. ё$|k28;5J<; +aM;Td5;=xa@ Ӆ**B ddibH|=GQ`kd)<[1@^pbxS=g?չ y)?gY˅XA)ϕ4qiy61}೤/ˬK_+أta plUpex[YF %s42˰2UWV{ٴxօ;Og[1fӷxx˦#-r<"NoZ{nTATUe캀Xudb۹> ^(mfP>yl?&dV(j;f,֐]bZ`s̷ `3Ŷs;%/J#WLi,V1ȍ>2kHoBS揲6}R_|CLgn~3QlgJ}Vf4Q' z1 L^,?Azݤ֨J/~Jˈ*0 OmE?QSРeX*|ZdV[l LAca<N9 lpibo)< '#ٲ@sX2o,@K%KThum$~3ytv_u_ (2.4·d<:v((锹}Ghw]d#ca8}CbU$9%u֠ ~Kb*>"lGrۆ$O&=fJ2a8PKM7;<2_"k=c+$ٺnA5v3Iҗ囓h*sV`!Yp$ k|=⣥JTfnڗբ^7=)6iV61yrq\|sy^ SL=<5(M:zɻ&@[PƇ?GRea=K$E8T /w=1Y)+,mbrv/Qg4^6Sm# 6yz L@C. Yjޯ`.AىT>9fD-1|Wv歘S&ƒy1;(V6KQP!8fજtbm37_Fd^ܿكRwvR/~ؕ2l%RqU|t4AV .&7nD;enդXF&^ԃW6ӷ,J/ABJ;L} jPioКG 2Dq`V'kMݼEF1!g'F^&= Ty b@wS.g-Kr{t?WYjmK2Tr*o+GJӍ(y鐍Evsk;Gػ*PU>dҺ2ȕøNT=_Vk9NѳÌMtHvè XgToǽ7 A2;L޹ϝB`BN%`SHhS'Hʞh7BF[;qܭiY$˷Z]No.y_%i@YAzHudA4e-F+jb4?lAYuV<@t/vLxtUH'ui9VNCMmn4'w \S,U(.hauOt.x=tOSaiYK^"VT$Q;azʡyaŁ)fJ'rӓujm"oFNQe6/v@Hc֦51(|0̌OUkT_+0"TPI''O!x(/"Umӟ jODuIB ד"`h, tق XDcL=qaNTbׁX&Zm"? ”eۆR A'nZ?g;MCQLpS(givNUTnЪkbZ4?a:p\ynWBZj|k/@HP0"m@c}'S6ŝ;7)g=F!EK.f1w"r UxpQs:\Pʻ{L-B~N%eNM/6>1X&i" Zzn`^ȔSSb@%Ce85P^'˟"' V\`UO.:#1]تWG ]Baid~IjqBnYPvdE&+`RD>f8^KVE)Xe932>&C7,@]]3550!>%79,YpQQx[&(%tB{αpPOE)fQi{=oN[IHĬtjfsmuwx$u5B9cjS؄DXẟb^py.:\(հ>T?(FKF\c$&ֵpmp0DH:C_n%9kStRjgql_LBÎD[ץ;$T-M?+@Ihf2Ԣ(F4BŠH$#i}8Γ|0{Nss0dNwt5^.jZVӯ6!Wdt+84H:kPWrQxBqU\׻fÏչܖl&~e:zσǑDCx>әeKDSʝYo΃._Y.Ep!U](Z[SW;ƣ`l)^4QUrd׼[d!Emv,az>L:g'R"8L2LOwD&'ȿ:Ŏa]ƓiO,*JΙyqJѭ?JEl옠 `\iӴ@'SBK7Jߊo#9VBO5p*EA;njFOx=v0챸0 f Y٬j !xËa(C4<wԠXo2:$~ w/钟Yҷ0i fTQݦ+U2C:I4;}[‹l/d3(`LLF;sG$&8ҿxzvlQAY%C/8SL!qS d4%A+葅#oT;D g48qp"VeL}#J4e/jN-2!riPEw=k5!8\хkKuzQ4-ƢTsD;6YlxҲp lYԹ er :|1:Zcυծ`(]ݪp8ohXTFZ1qD ǐ]ڳ\ x/[?KC0ªpBRŜbz):,7R}gx"AaQ # "h nԭGmpBԊ@_rEI+`se/$^(7,P;P(7޹ZTZOa@+99CɿB{^I'?xgtO! L4:.4)r0d0N͸/SD) $k?mي[r'D뽿H'2AH۹|RKЁi8okXZU-Tnp:/)T{;PJ箂fCs/3U'dUmeB,r%N P9!y|@6(aH>IY`sΕnɥ\*RpLz #lQL{ow!#4.[+A6_]D5hzy_HvV*$-3Dnn-^xtqPs@4s]L\C]&mMaŇLuMﲮ)}ts 孶w̒UDaZq#zA@,1S9Eئ + ?5ϿHݲIco ʤQTnmA~,P&I;L.ysV 5TovY(zJhlv2-_k =N>SҪuxZ$,םfۨAۃ^/Q_I+gW8 j^gt^gTP|%mCt\ZApC}*\ /r`~ߨ4.>ݧtph%z>3& Iб"I" t̯, C.Rea_gG05|>J`J$߹oaRST.wɒ C4Yv5m2c;ܼX[z]G|^\&D- 8GjYJ++g5T.uk>sL~9^wS`dS) si0) rU1pr!>1'e Lz , ~ 7X%-gf> FmYv|;Ý]&'v(S iʥd $ʷiKh/K.|M}(6-ۦ[KMNX_JQ?>II+EXL  +}4 *;S8X94u-Әڪ"LxAq32NipN)`9a5%}`)!=AeUK3.>gBlVmw!}Q D^?PL Q(/kYCc~-2sU'K\1x)ЭAK'-IB=܁P-.Q=†U5wzOeTX\a 2ib2mCu֛Όps5ɓ_Y]Ն{*qAƸ(miEZ\ / )UC>XWRln)hf$,B=8qy.pn0ᖃgVfc}YR#x%-lçPi̼haJ}rG6®<+Lٱ>$eҳB޿1"B;M36Ar%2cڂH=.|?3Dn?ȣOwLQm]Mh9`n༡bH'{c-;+n.d7쿷)-ձXJ\ͽMAҜp&=l?iVj=&a S&1L#i`qXCM?]qO$|Cyt5/zŪXɉ7:L6\J6'D˱7&XnX ⥉;O 1O;YJYQ~2Ӭv1,UAa-ב?V:Y+7g ĭW*7M^r|fbX"oS!$^UsMrCb$qDylO ]Lk+x g1I]\7q+)b&>uC0j㖃6H?P) o%*J FMbyX]3rGysbZ>~H$M0eELKJm(~bm}DD zYXLk}6>h]h#?Kn㳁p3RIA*۵$Nݮ,o]C!38V5i7}L"h_ aw)O&k*4ltUX^H>ixǞby5l{c4!CC[;xb dy?/DLqGJ.T6=e9DC#CbA9A::kMָ d4o|]vTdHev3 #jz)LrˊO7:m˸9i+C2%WXdUG*iˉFnrI_1*a.*穯Ǽbs}]^b9Qr{7ZpQ{@x@3ZS&P=t@b\}@9XdȚ~ͨzn˗N Rضyק3}9Z,㖞R]!z :ȴ&.rδXQOO( .G]Oݞ2D:,n%K-uؘ!B8g)tCft'PQ(/oO -]0%sV",$f ?EM^q/Q/eTxKB U%.Rf` @M9h_W5SZW7ѫ8" VxH%mޘ7 P»i8RipK\úwzG WYe[ CDLِ3dp;mfa: ޿!Jsb-} ź– [-|M"(Opr31[=qҢ};GR$s1%4H`v?v?_F4)#莌5bYEJ͜[W}#o-x[eE:*Rav-+е< '!}S1njc9wI.ힳ/+9ϙ``K̙k=1Y;GlÕ !_eGY(%%~6>˱:93D :n:@x2HVL(yTpԹ%V D8UoG"p&RV¯hH4(a&uyj2-u>/;<}Ā֎#5:tkg@a=&aϭa^ k9 jN9CWng0BrQվM2Pw^4o O۶ġQAUf[r外O&ܮ!S|2[VJjLh[fX-!W\L,n$AzX"ƛ\u#/f ԙv˽LF @ϛW e_O?1/Wͩ~5TԯOko\[*Ya?"_0rEn&$3)1wHTiU g,[cQ, >/s w<<.R{1Ny&q8':y?YVp؝h|`F# J߮0E9cJ>̬&Ď u7rnVvDha7]DZ9ĞD\Lbұ!:ݾxo̡83S-{`3Ϣ0OP+=Wmh1[ϋYT| =ލ poK(O{˄QeZ t8- `m|F1d25]4m=tBH;I2>uO;WsVӈlry_0 jEòa厎Gki>tO@fO m񙅢yhN r>sM6ѭjUr|m]R?n5cR72 ƹj8N@_ǩ| P\Fk6ŚXL!Žfݓ ⵉ^iZgDY…b}رOmx,~M8_AX3ڔ+@)<f/z XO-Z{A A J#㼫XGcZphi}f60 Zw1gRh&U՞D+[s-TeQѹީ 䴸3F{PLiCnpg^>e?AKI7jroC9P*@EDV#qqqU3{h(ɫ=h=791i%u:iN/c 'qpB4k6/ЍTbs;V$; } AEUp s+0Ǖb#;tp a}6w]a^QC =7T pZ+\i-!ȑkqwHo1Z/ŞE'nUAƕņ#!G,Pu|)-z e~ YeAA*_2R{Kw򮊎u§HN<~,st%ʅq\By'Te:<ŹjX`u%_!fcY!c0A|:Ub-x;gMNAM`[|lTj*`\sⲪw&?u*f80 r*үn364\-;E B}iMYo܆\mv aJvҸj4v!;dbPW,RD,JZz}I,Wr>tm~76d:]c6X I j][n*Zs-?ʷ$/.cHuǧ_l|2OZ0 /nb*#V6D{Z'pFRiMD0]j "ğlebxV)F[b{>%sYNn/2b# 0-Ԡ 6W#ӂ  r AppO9aYw mtCD G_]h`' ^Uɋ!WH=Ϛ0P }\{u8)>Q&82^ uPRK\F+dWbw=&\Lc ޲?3Ow/NáI?y]ƁN8[oaŁ1.UY1m$N8~|X_>u6ͬi;ksy dY@ÏT5E" o ֆc;~n t?ȟ jԙB(\BZCx~QL]uCdŽjWP1X5&vt%R>tk<2zJuw*ک"lp@EH8K}[Wr!|!lva$肒)mLIp> /&nvNͽR(&Lw]g z>Ʉ#2z ˆ1w/)| yLvE-g괍kܴT@{!P_aD=1O*A ц\+<`̃fQ9nJHmnVr9 ]#@K'!.MyNknXͻ8Ǯ:eG͜Nh?Cggnc< ;5Ƅ4eُs* ITw#+>iy߳w{jikeԺͧ㼈2cIHyj>RS#;mnF!-ŒاWME_7^r.PFQm*{"7:JL?f \\J g_'az=GDМt5{s硁<!X 8^oȑ7/_Q9mChMPC[Jo"]\U&(Fv |hk42r֓GߩkvB+Η"ev bXQ苆l?ڿ9KjT1j풭 VQ;:xj,"m?LāaX}_ʰM$;.ʱ*t-f(|bI[ɭDf!f-+(vJѭu`@i!$|gOŁsjpGUs*`3STǠo<&1 )mIʕ4;yH1pw57MOSTZ;m2j+-}3Q܋@4{jc0H+dy'lݭ=M}v6 _fi-v o-tAKU2˵8B,Lt|^?  `Q(6'dp9lyke)R:ת6%bL]׹asNUdv~-g cϮkRюl?@cM#Gt޾ M(gd ~NlNyj}o7ݼ޻QjXYTF#ju8b˗ii"tbX _}$ 5MWxJRbhcaXޚ)X*f.(?R%b_9@&%"Ӝ&>e70]`Ro:R&=J[U%1вYE˸ץ4l龅4A2]*+iuOۤʌD ˡ=2^%b(O搇M^gd0$';XmȱHT) iָ 0] È9 5L=fܔҞyTuMsj8]cɞ M;p+#;d[Z/Jtl^@^Onn 0|hPnN=K=N0:+557a*ޕNZ5EI -{7hf(h=ūs@ ??Ӥۀi34{OM sVŮ#% /UL 34p 1™" 2AE_Iiozv1IW^vA 5 1&YTMB(ܯL^ǨZut, ICn]amأ#fғuO1)bÀF{zObLoE,prX1O(6 H,nhkso%*2}'n﹩:.F>ڡo$Domu"g<+lTaۣ/-͎wx<Oa%D1Zrᚴ5@ \]7i0hZ(z+^)B{EtYjMN: 0} 9ϦZ:"*BҕS&PLcF?F6yy%;QC#3~W'{TnF)q: dfܷ=-b1FɈANj&ۥZA6 tAL$A uX\R v`=bL(a0k0F n<5MEa4}e 9%O(?X{H5-8ʤ^ kf13_%iBǺp=8Xӝ]h5V3;,Җ/ujU}*"j\~^f9VIaI@!%.x]E Eᗰ [C91l mi,˲n(O}jn_+H?s$'gmd?! \e2cޖ+0zmžl?JxGy[#h1voB 𻧜qlT.ް0Ǯk]*z;I@yԊZ'W"lP>MW¡3̷151 `p5{ÊTA%^C՗0%KGʶهJ3%%v^՗/DFԝV[^ݝ(CαN!{Q9_ĐBrJO ceN 0Y" KDycF%Hм(?5rAM[F W'8Qaw4chbCk c/"YK?Z[\gAzdk>ΕX7sW!ʥ;]RBWe?Z%C4_;^xfVYhT%mفّ-ޝrOv)!⿣+wڰA4o~.Z$M vN@b],ګ$ C\\io҉j5 7\oWR|rMoȯHfr;v]츎oxkV3 ' j,kf"yJ. jW渴)_d|>cVp0їH`,Q vzYAoP)w%)W [uKͺS/ێD68-ՆIy)$Hhցju1rc%9iqtgYENرݴAKiQe*Pj6'"eaX;REovC E.'M^sDO偉ۏ~u^e)wZz&M$Z̰?P±yNR̈́-p ў؀,S5:a?m-w-b J.݁k'4 rf),]b7NW l#i68hE|&NB*%TBS2^^jH4ˡfoȅyeU '* a3vcCGܦp%ׇNF,TbI(XUj;j uʸ琊#9 o whGR:3 ɡT"- dLB `}9ZaN[x|bL45~C_9kD=y{EkL.!KruUdoպ101Ϲ_yToT_}&[|{g_Js#USث>R ~&ȷ;YdS[f׃*O}쟙o"4O5hYmRʴ1IrNFի> wsbЉ \`߷-%UazDUolJPΥ-B:mlJĭ`s6ޟ0bs ù_ SS#Gz E:#XYSm0;~3]hm |*F $1Sٙi:[y]kJj_cDjAs3[,yкw,$n2%UyD<ӘBׄO/% ~ $a;mpV8saPh@uxvdCҔCPj:&*;Dw0BZSqr5u5?pm^sb)l6M9౽:SpnBmAy޽8DLw{sǨiieʩ!b;xsDzMY@e}~9/Cr |RTcG617 &q%p3؈1)P9Vƀ 28q`FgܦBw(A.΃dB~jZTzV4,l>>>t I9ߩ/z ix4VwQ ?JVRpǪT0Re3NX s|)&w f.]86'+]!}Aniaa.-O`p3!M!t&:(?}m`7?(qZ'&R2r {cN2nE%VP /:C * ći/{/Hߗ(]-~x'ĭuMXl}?D{#wH:U쫛L&ǭ'Kn־BU8CER对 ת& e\ P J/ *txjN|Q?"'zv#0BF!_▾L<\Phm @wќYİsi^4Ʈ> ^׃M ?00WO1/_:Z~÷Ry2P0󷡽vw {]Ųq6*tV3Ju/úFy0FFW9 J]l}SPF!8U2/TaF*ԕ`* snތ9Q9Sj~I3݇f7+*#ZC{gF#L{.Mm58dٸw `aYdx-wZI҅" qL‚s#bJUX>FaJju(9'3=1PnR~a=lbm:{<? V %"EvlkDIam]&ӓoQq3=-ZW`' g6$i/8 yt1 /UQI{J! Ȇ #Ď:'vɰR{3c .~dċ_cp'ȝ&zדI;q[#=BhMqշCk9",Dc!4B`Wer}1/?s5څdLjWs@8_>]U1fVPȧHZ{Λ4H[ )jR|CQU!5 I\4K)o5(GpzaC'9™4xؔl.%Y3U*F[E*iBI3z)I0w?<{t |姤: ?yA_ ZI{zA7jxڝb{e>,vI%x (n"mԏaK~.q,Y$-gqJf4ydN(t\R*J!:",u9 83O=/&@b_M,VIRs0wJc5^3M]OaY\qX9feqcOCea/Z+^ي7*qs$@PHps U 'hy}qd]U*8@y !=P,7ޥ2j B00s=1Mf?w2n;s#~sd#zj ddPT6?;vljhz?lһV_R]Bcn뫒DTjBE)v}˚T/h{4 ;c`,T??`YZP^#cݶsDoٓ3E^oq/)rG-I|;$1%^>`r3(H 5v+-q#`4HQ+h䗵c$/z6c1jSB!3KGiXǨӷBS*ϲX5=)1.P[oZMt*ǛM<`r3_Α=8b=^mP.>ё.(*hEGUѾx)*h{þSȀ_|!C>dYlY~Fr5rmg KevT?gX `ix9 `o)Iai6-LxQ__XTM d}Dxr{YG\fBUI #m>_F$yd0qH{@FڏeBG!Y+ `<>FLoDҠvc38|AzÈ&m<7`bǭ\ci׫|%8S$2o0ǤX`c) 6}8+x_K{(J#[3xa:񕨙1'A+N7q/D>U6'gs8䎺d}8V{4ᆇ fYt2CKѝ󹖟0edYr˻b;:z,BQ F@*b0,nџu4%>V W֬#[~XDFv4&+y-e#n^ >@چ9G XDxIg1$W{zX/é~&hsFYeN @Wsܘia/.!`s͘81ѻ%d5> 7QFVA*4W+E^cwuqƁ'Ic.Q6;!c̿ny썼 }.R Q&I,ݶ9PdROfIEZGI&yτMkt_`_,h&wI}*u 3HwgmARKnf+u0KH'?4jˆ9 ;٫ȋ cMUY,=G!./ /u^:VDJ>L~6[ eoҏOx0N1_g@to@iؗ77s}3,MsY5to[7C#eSUѨ}w?]~ZmK\ wcV:vX_oj˂g\xVoy'1M_`ԉ3P@ϯ3uGlR^oMdCvm>÷+NJAInjպ%lpVo=`1\@ 4i s[u~VʫNc&$GV>Q fHY+ll]yݟր ?-ʲ^ֿ\4w qҎ JLN1GBJìMClģj?fE<< vB&ȏ v/y<(+$5ܡk"_{{{UF $K$6BS!goUBQC4$uj9B8Tp'wLJYRwjQE~eѡRԔEW@7ԌHh#B1>E )Bwaz0REpF`r xeSuEuⷖvZ8y8k&C/7,%ʾ0v-ԋ07Y5I;"}9 6W z(*f],4M1U(_J_meO̲R<]r+^e{ք9߻0,pY|驀> 1;*)\PQX@HaL?7r-IXUR0{64pM$ť"MĊOΧuMAsW$kB83gUR=P-է{u{4.ɋMiP9?lj{aq{+vxOd'wlO"K-z_8¨L KB:q򡗭FKZt3ҿ.\ } !g 7E>Mga3XQO":&5AQQ4N> Mx&' 0+'޸[kt[){yhb $jeꀸxdJZmIAsWu*o7Hut#q3Cb=ϱn4|ތdC*ɋhv uUVJPYCE{d4V txW1$\L1NZ|\;?S|@Tk_$ z4(ȅ$dQ SC2KD^-r%_" 94Yc\gyxlq jQL~ sꚁȬZH :cM__;¹U֔| Q WyLq%u~eD40ok^5Ƙ\e"?SvDNJbd G]iV<Ҍ*-a h<0@bk-X@b`FB7'&5q8#ՕkewKJ#w|` K07]*y6Ph9GNE+/r #IUI?|n`C)AFS2e [DGg};@S# \p~Xr\# -MM:siB?LC FTOSPh$KimC9ۻ#" ʆ`!8W}+k;$Jy z|+ >xRV3n0zf3cwB ֠k!rkU ]vGPYy zuTL(g c=m Я__I dF`Iy/BQE(=;ʶ^ULY藱z7~q ir_FM+k^ҒdZRnJ:5EQ_23P'qV `&C-t/P/0`] LnU:h8@7R'yHlIaՓӃYH|yM m!6mU:ٰ{uj.^9,K n +$-BƑY&:|X =Ai OJO/Lg7%+X)ǑxDX%)٫xHT6A3]LUZFv}rM䘱</`:d["p4y\ Rj?iއ&Ȱ;MYZڗ h3fw9\\g^o[syAdUH 2J.h_#jyv1ozҝ @hP؀̌Ŵ&Έ1CD_U)d 5O@'![x=u~<ݍ':<(3\\Jn4D@4YWLLiQ"! `ǺSoqֆ%`i )mnDw OkTfp;f뫳S~𕡦Wػ\c/Uf FJw߫g3BILjIi::)KNt$r}noj$5JIU\Mx⸱S71 efv)ӭ7ˏUMƳ ?yb&8ltSPi=]ZYoGϳtl62e*"b}pov{ٳ oهLxƐՇ#˛G.gnc\U]Bڱ뙞vw+ʺ(C +.<ҘCF"KTޗcJjt^ 㑃/u^TGZPr4p?gBEpbB3!+*?C0`SaEa=\wR;">t s:\vn?#P׆S?~n)MZB~-H1X=<Y=L?1lnLHwyZaDϋG\K<V$y]8c3J3:V ?Ik|?BD~g-E+(>LQ}i*JCK˅*asaܬ8jAOFJD;  ez`N&FDi ,3 Q#Ye1MUQP5a=$*:3; ' XI)F$,"LV=0s%``qtw P[/ܐGpW9~.GDψC|Lӧ@p(._#bv? l5;;ˇ {v ¥5Ca֟ Tt02ac^oPx^]ܕ(Ll/;Z(O_^me!+o%W?V7cXGQi7,iEDeqTYcG{UƲNpG5`sSy.~ڑ,'v1Yْkgֱ<h]zdեɦ3C1 >?6O[㖾tKJ㎓xe[T҄+loC ؋&JnĽP]qb{ՎYe@d9SgiHMg qx(jAhf?OU /zuDal&\x66Ɉy6zT7b5<)_T?~Sv?YS45 U,maҽo졩}+sPDŽ leJ|_F.n";.N@"E+Wb "0잡K;n^ѯ՝pr5f$ o:[/̚=C-kJCr-O_RR({}c>&Yڠ&%6#yh8!+L7˅Q ݶ݄4 Z&?Dan%$xW}@١Fаt;JC#D7x߄4$ג^AS1˅"di4Fnf!E,{b>jLlzڦ~N _OQm<ĜFD 1&,Z -97@q:7nQ L=LuD|ZUOu!1M^f ݻ`i>{C ,qeV.scá1T`/ykL^'0ozB}zr*"C =Gl`Sp'* X&E!2]HX~v7D@/=Rrc؞̔4=

t(vҹTi0_NT(dE6 }&ɣ:XolZz?bf B_n$g۞vʀaPm,YF̶d+}כIaI:-bXa~7>z$4mӃ@IfZa 5noǤRܮE\һ!nQ4e9y^>e;'ױ1Y+ҽk ,@T~܃? lV'f撇ƻGb)HْIh&PVJs'[4qm hh6Dy] p-(H'SsgQAhvP%|v7D+4g9G^A8%H'\&=h'k*? 'U+V8w ~eѹH4p¹犀J۵U\zIZlþM:̓>}|mT \KVg䛅zcChN& 6&ˉ03<9BA >^઎}\!(^K࣋PFsXuAJ.u+}2@3=TջC ZnNyfq69|nG2^FK(S>ʿ hqzهӊ1*e%>}CsRef=?_i j{hr2xd -ڦW .![ewl'Wx?o{L_Q^@'2cݐCZ.+Ϯ`j|y$tz\+cvB2c`O*FI9L]|EDӛZ&jZS3Oj&ීn2upz0OZ縔=rׄ4ܕlh[ p͏,ܿvMn)+Uo!Uʷz[Zߴ+}AiMSpS` ` i:|,}!5#@=7OUW!_(mS&-Lj W"߹Yr`D|Ϛ|R(^U|D6hren {X|og)}b l! $7r|~Z넯ّ3hw">潁r&!qF=}<ٝP:\ \&l/A(u♪f~l ړ}| 9B@ɮ{R y CTk޲8| 1m{qwoK2rδu:CaL)ڨD4^(. Ύg9\ّQJZ~R4rƫЮN׋O E ,U"'_@a&"rgWaDPP ljQL4mϰ6-b}ޕ}aՒqX]iVQlu)uGqUߞ:O`j +fM=ZZYG>-5 Q|#7$aY-ʆ-N+7_,% ͲpmP|Bm2Y+.ND+8Hd<UM+ߐE 8 O @Ҫ\)nIq/2)}WջӸ2'uƣoߤY)])^$'p2 -jqDQ3& ]Z [ cnO+i޸"C,Afԇm2anG&d8)J/y06\4T!xQB3jZZ^qU$ޏ ?ۏb|,{9 4yfݏ`zJe9JX Ym"XgJ[hwaV[ol[Okol3>Ie͠[qݰ3z/],,vAzz_"9&8W+H𞸎07ʑGY_"ɁdI{&ث0#16c<\HBvM*)IE)3$EYK觷4&-wš7Hf4^@޻/x5h}m5[y(K޼,4pz }!FC\ Zz m\?D<2Ql~Ѡ=s c?$OL.ꇆaIIP'גݜKŇG&\"A:,пf5{MH+jD?owO!ozq^.OM\럡Il&Pd} թ m7J`Q1fUd:,~KK;h\zNLt;Z&¥8wW[0XkhVqk1ٔpy=&:+'7INi%bƕk zE֦|:q85LN >Vr]lYJvVP[  %;Ͱq0۲g C6\EIX+#rY%B%T6 [䒺r Dp'Dֽ؆n*,ag9ԢL_;bezEXyeo^nբ8ᎸgXL}ZoޟL JGRGp䠛Md0YyܳA3 5p-jɐN{50 s,+H ˾@3h( Yp0c֍p3Kac*4F!{vܥv`qp Oqn(|沴+KTlϸb;'m'. gA&e fX6uIL''vԜ㽲[MXiLUjn}׏\?JN_šj旀[=A"DŨuC.qo Et7/à|G`>fE%\XeoT*R@ ZJDu7ӫ٦BU'#x.bT!kO+FP})/Њu]c#0=P۵gR6A5GH!ε AXnuhĵ$4=lF?{]K楧s,p2Mv=9:Ԛ !;lԆЧ>G)8/5k/w_𼇿k3LJ|kzbX fP/ˁZkMi9$SMȩ[q6gaL`DX+>i;?56= 2d`ŏ(TK[6k?B:Hz]x%S:7ܰD8U7Gy7{&Gr֓cVm Y֛yL:^sab*h%[k@⤂?ﻊFM"oD[fPNj\HŅ$&FH,#(`wh(=BE,FR* 0io3Ս#{>;>W{xg D=]Qnلe6ѐ`+3l/~c-C-*Hн=j( twĂ$6ͻdR-;f<3'a-,=a)w$CH6o׳S' Mtrw:v7diy~_Sp줎u`!eȀ|;~u|lEGBO"_)9M<\rRV JЈ\kiR/cp^ EH%NqK0vWU7‰.QCHYʨ|l|b 5ᔩٷJ,uu;=w,ͮ3VWɟGF\I+zc;e^L")B2T(8 0C}2Ǜ$[DP̺X]`$jXΜv-xaV$cdn7`.ՖN>~|.N%.薇h2rn_ ]Ÿ!%YrjU]*4d3RxТ 0fȍ G Ӂ-Sh/v1<*Nފc+8;"xS~ e:CX_K? ބbg7&]A1Y٫S*[, eA ɗ쒃Aq%kXZ@;\2БH\hZnfMpVn`T hTGrs GH\,2tHC;ϯpP:^y40wkӗg5Ƀ5G3(lys8R(#ebar`'y0hi~)M%VĊ=%2C#΄{yWKS+eA; 3@aRyEJ<Yh^zּsY&O|ތ Jtg;\ZOnE*hJX?v8g3*P.r D'M rUcqи ˼6f=M$.x$1Ilշ{ Oe等Չ?%2ҜpB۞uγ؜/Խ`Tq^UC\1+ߍH\2^ 3}d`" FdۂeVpc4fTm9uW\S A.QV0_":1jO?T{+?A.;V_oe=!7r9'7r!ar 4xk^M@2-X\pAĠ oV^S, qYp4ynI32*G' &+,P噮:f#5]ڋdh>{ŝ.Ω.Jn%?[>W`U$ogB)|HlEHQD~( 5Omҝq1:{^FecXC6)% {\=ͪ)0 R@vOW#тBۋ@Home:u~P¦'>>Y*:G%@'`\+Uj?ť[&-6\57-JUɇzjshq1dBaҌJ0=[;F1ǟ88x}=#i˼˛gjlgaz q|XӽQ 7mx ^:n@w $r>6 J>4.ȈD&z @tkX 6U;u<쒮6,+U;̝DD|pTVxqӖ'`\4H}#jU+̉:; V*kd~>;NI꺬bًpi*H_wkȅg5;u!!73:T@v*tW.q}CLqxvʿx\z≠CQ* mNq00^}2]`g$aH629~SrӁؿ<:n_n{ ³˺< 3^u2J t78Qmܨ:pg[ŗ/"3Ie8 /SlFO;=4G=RKɈ̢I ? \^ B/^,cMe6Qұr}r8*1IotD=%i2,aϡ'<Ȋk kOkwB %?l"rܵCrD UѲc#' t]3z|/2i c`h^֚-]Ir'AK) ™+n (V{{gmLF@oTL_״yJt;r@2U#$D-H% ͧ7A3g$- SX-Mcjk2dr WeKE$IOEmqa! hH% Z#ڀ0 Sk72-Nd +S9rGywuWG9- ^V}TI`퀌=l74!>pwY#U2)HSMIԌ@Tֹz><n*}`z?_ AJgC.77?ĕZLsRzx%1U(9ob3|LeK 5sYdZg̡Uܮ`11$oTnu6KHF =(|ꥠӰO8ೖOh\xSfGa[BeDz^SM4%OwE==(a]X1a!EງQf8RP{5)6e*-#'/ N@ ^.I ݵH4n]DzK!tG@>0/r.D_=6:Q-`t!.Dud< IDp^|Hݕzco/8Lx !e7-lO2% ޅG MAxjtNoV$ |V{7w\JU~/ۦ/_.!+QNa^Fj 8t8ҍZ -4ΝW(a%,ңMIjR e$wtv9&XCNzH6rwb~ A׀d0{I̜ i<= {k$x"G/\#D"[}N,9r&du綉K#\9bG粌_jyTu]n'hH7;t(f/Si"zbi~s[i >Hl).i'I[?f&>Lj0Th&T?*eXϺQ1} ՔW e3C>;>HUXNΟ܉NL܇fiUo%tϕQ'ta}qTezyo}nvhC5ѱA:ף)ZutcI(Vޅh/ƈq`qBfui%Ael"|rtAԀgKGChlykEjA.L !Dr6m_̓iz }58.I @4Ž*(HV)Ch,<dXP/A8ݝU%֒4-ƫ^f i15&jK{.>$WYyd77+ج܋4m(M') S`×}Wװ9*v;$ Pko34Ж/|^&éb|h`Ԥ\]_C5tVyK7&Bn;ڹstۖWwH3*9;Kg76pyt\𛽓._#w3 #j0!|R,mŢʳDb3~_64쳾m?=TG<7G_, pR{>B&^AIJw . Fͺ*+˼vugtA[؟ËlA=Z:{jH57L"?Ẍܢߍ}LrL^?'ø,{Nj¿Go̕gg[gv`6YlyqzvQFԦW" Ŵ7saM7]z}nRL~)aDA^s48ap*NS 9{fИS/~|L O@~A_'A-"v,nqC#u^\NA~Xd&e`O8 jۇˆOP4K[Y" NpI'eOws]8y%sYoy`feZ$v2秲tA<ҥ_"ǚC9e[{*$p~L?@)u\ejgPpn[z!T1eRo"iKT6Ed%v$TnY[wrwM^j_%PŽ=O-jo +qei?W_WR[࣓$ԯb9[o&EwDBAw Mm3ѓ;&`xK.Ww_b~r?K֖CT=W{Λ >i*' c* qi ;2M~\ٹre%!U]c`w&oAxC)eAPO+MiiI&4D[zT`h5+%[^ǷNC-"KZH k{*޿v|OhI\rFDʿZYK7dl_ mGZdQz:oSٖqˎ.~$SXAk^QMZs[97PU('fyX2`zYM0q,*LԂAMhUSBЪ`,0 X9>]. i.(n*YU_Q2\"k(p ~<h2N8^it+4p*oD@,=WZ *}`~E28eH N5RrȘ>l E5\c"ϖf`i_B*`([{d1sFz0k9z}nE1:0ALicx;|io8P{U>=Rp)e d0 eYX>U2v9|c^/;/=J0>e֍򗐏&͖$(6NtK:0$GӤ$޿kGs W V8VMuJ:= ~LA[9Y],@;693^@7\Z8]R`R#QRAkɞ>ҽR뙨Nkc*g`<YU^]0ǘ:@^PGR G֔M@\3Aj΍z0$'΢څEG !_/t @Xu]FNXL76]A-(M䌖t^i“c ܏AJ͙9π0j,۵>Ɣ\Re 2pv:AU g{"&\R7?"T(}1\hmlm㟻:D͋E gB"/&XJͪ<XSX8D$9`eI7O7y4ߠ-i~,f {kUۈ֯͡[ *;ťd,7k؝"OϱְYrkXgq։xb 䣏#b4=9dOok@ṚS}cW-cL 'PE?x#oMP&u wd Kz]w (7rfT tI?vL:͝ M'+ <|EEd/0ęyж\u* +Xow!g}v09M@k'czS^H=U_XO]8ѡ@?eУ OvGL2)<4rqmb< *n0(͡ιol^ ]*XiN$Q.4EmNQK [3@bRť9uB5ag.S]Ww>~8EY }c,ls" pB0@Pj𑜽 :ydYGS/O\~}#tN !xrTUJ?.ԨaQDUYogS;Pz\X 51ׯM&$ 7Xk5+2d {cD:/-apD[;Se1G e:PO7!ufS! y N%"ȋJ|^zы=#O1(iŒCS=2)6y ٓMZy'¡ +eݕBVwf<\#Zc^AQ\w~,<ՉCsp:h2ӱ<1*eU%zC/Bm:fm)^#˾sf@vUU[e=:Ġ&Xz,`*!H}D1;q;z??*GbkAos5Frg^x7]C^UY' =b1ke@T6K{T? v2 ̀wnL}(0TDYċvO2^F>LÿGPpȺ d[ס9,h(7Gq_]g8AVuco<,3L$ֱϦ'龁9/Tc]UfDRGʭcV#:ODG.a,/oQY=RSQR P1B˽ a5# 0~djs6pvOk b5Dnß)&JJܭmi7^@IiB*kԊpxeb &+OJ/P c|f 9R! 1xn7:V<E~ " IB\W Jzy,0E'PҪI%:1,m`̝ b͓~f9VGa,9n<zU~` x/;ޤtb/G>۩d2>8h`,CJ3΀4䐵F$J@vc[dT|А`oRjxlJګ(u.l 'n·ȶhfT0(Y2عEӔ,@'|/<Z!TGEiWhMqד$%_mHJ~_Zb 3PUg#<| E Wce`%~+B?oK{i/;w}֤.BNW%uUQS;gkVvՙ g;("\6TͬhYM2:Ŏcte;01Н$#ȢL=q ܉5emY1w#c9ϞR"<j?8q"7e\R~2dN )Рn⏡W5Iv_wR!yy9a-` 1'?۷"|_)hx ckaw0?j.B%`Dy'X}(ޱ@R: ⌸Źf%*hE:VtYȅ 6X8eT_C(izۆٖ)Q$%SC,vЄoDŽΈ5$pmq$Dvg(1SS;F@VՅÐ>($̑ ÈbAa[Lf"{m}=܍YE sJ?ҕS_uqTʹ"!KAI\{+m}-=њ.dBŲו!($3q5gpmM5tu 00/{gE5ݡ)NNDk9SRQ@qN' ?= ujD;fH^P*JT/# 1^[\msv Rdxߋh%e]eAkHqWB:"Дp1 n('."N3#Tl]GPb~QnMdSud&}{8Xdi_h/5Ur=LG#1VA.lՍӬM'YP*R^{PXߢ̺OG>#JMI|j 庁Gem@k*3@5!S;)0UdGޮ<`;9lqIx0q[}Q&:ynW_η3QĂ0j6eZ=3+{o>vQyJ2!j4}➿rbQf }TBcW2y#O7 7DfDs?a55}FHzи_B안1ۡ؏,-bZWhր, dT*e'ðyOY9hQҏ-+ۮVe0v]Sj .RtR7H??,S<6D*j.MI`W ̈܌F\ß*@еneJm)f?fvt)BhҔCkOx/ajV@N$?tG( f7qq%¢qzN28 qAm1dߌۄHQ6* pc'uIi1@w9IwOh2C#s/<yMZXo/b'BKIx׋.HMCd:dTzbȹ>X#/Ct^_2.J~tG8BQ3g: +%b#g̟_sv}hRwb&|CU;ޑX[<`ҝ̯Z(w$?DJ =[s4vrkC24yṒM`se˳(ڴMcK92Yڨ8QA(Ûmi%|צaO,d%:1pNOnv-@J7P ,N#!&8tBo:DvEp@*j:oR+Qpq+ANQ{ Lqvo$k5LդLg hZ6O*wC¾loF-WOc$T>"/8>z> Or\\D6&4k9ԣvX7U$YQlךnBOt:9_ BNnRJahe]"`-MJ|6hdD7!~${>E=! ig#Eqtf@,D43ލ+ L.*+0|aIQud缪pX__s <\lTbvJGm4UDlmzPXb iX; Qnt`y!Q4ymgs#XmQ3GB 4y:NTRa:W.е@ L }Y hfp*X`)?$)˭о~R:Jo$_3p BOޏl]F;rsZr\^ZT -rշ:=7,K_(41n-pq!ӔƦmd3E2p#2 l!R4*dy7m1z4Eg hhB˸sSpA68nloBNΙ-Nb],2FT\Ӡfms}ƞ)vw:zJW\CܩnⶨPnY=ϬAZݼ:̙'d\Ox)4ơH8PO5djܯmg2@_ bil " Ӗo"[!&Un(jJgǘ?ٗ<=m2m/[ivo(tTvI1OBrG4#Xp1|$1x ¢Ӎ{L0=B]5$: j&:Kj=z\fATɰJ1Kȟ\CՁYyB saHHzj6 M~*Q+p_;]|nR6>3`4pNL S(=17:ID4=ȓo{j~t^g@a/=Uz!w/SgNbtzF0 CVH~ XL㥺\`p(lDE%K`s-g05HmH^" ck|~6Q Mq^}Z&N8hl&Pbu Vr,)fQEG4c)Qۍ>m gw0?35Ր59yʶſJܱ.%V{moF{_y=\d3f\$ &P' 5- P^;Eʗa,T,'b@J 귖ck"G6fɑd`v&4* |;H(53BZ>sg?v; !?9Ob H t};|z|>>خRO-1/s%4;a@nXBT\/|nͼHV7ri3 S\/S9"7!XSݱVW BKg>>)ƙ9pYO7//ZN[i ğ miQ;WcE$S$Aڴ_䚥*i l1)PYt|~QsR7_iG~8Ŏeh89M& xe(_$Ǿ<& srZJtnC@`W%mJ!8IonbL#{@,0H}֐k[bv*?% <m $mCg1a H2ú*.@9Gc1z( XCmUCI&+Ti-+C 9љx(FvHTGkfMgk͌thK* FJ69 F}LT$PI vy- >{/u䊗VBV>Ddd[cN&@v*|2!~4=Zr0B_@ڈ*6&q2IK\.t:>R -^en@@{QQ)$(dz/s'dAVvע* ~dQ&۳ M Tp2mIqg h_oxB=J\$^3?Ő1J>Y&=IJJ~s?}@?]qpfb@#{EP@tE|'IV Ig5n^3PSl UE 9:WM>]Bi^ R0W͘LWO"i)sT `{4 lH  6י``DU$)bujsZ{~Ć=daBD&QL"u-$$li@BXcB{凑& lo#h`)/d[8~ZA^WI(&sasGrVUW8'To>ATrrMn4g D!A萄,af˰5+TȏÎ26DU0;͛EDhp!=l)!/#̔HXgM q2—p3c窤>NLY tBc9㹵)aň/ӂW< iw- m!O[rZd1n֙{BK]R!i2e-Y L_IhE&"k]RP h9+=֣YEWΕas]A %߈cp2]/+:?J]4ua5^,+A7plPU$Fq;A{ufb%yy$5!ڻ_icsחTHWNb5W f.}Mh$z)_gU%j//CD H|tJF{W֚ԩ@{Lp0VC@ۭ\KM^5j6Ojhovp#o1udv~JUe#\ۀdYyƤXw5tH4CM13ʚߏdmJTjl4[y/~SMQB TJE'i_1ׁN]މXOHKTUn >[C?$bsyپvX⠨jE6޺hHߍH#/)D' μ[O]`!*,wW5% =]ox~ ~)Tnׅ觽v=H݃#gT/"G,_=ȑKւ=:>+De|%;5yxMla(,<dǫ䵡}5cHŌ' D#}5l/z/kX*k 9n[˪oӮ:ϡ LFJ%'@ 9oUŹ@ ̠ l?fe's?Tpry+. @Vw.hn\jJ{CJŏ40.s=Қv-UW ~ V24rР9T'_J|`]lqf*lš"MigwqQ-Xd?zU6z6~.&#uUsL%oag#njq.gӚށ)T@#eL9ho$*to[3ZK0cJ1U1 A0^?: aSN/*u {!ߓ~}|-3j=[<=$ 3@W` Ik*<rQ) NPik]Rmd@B:Hg"6@EX%v~N~"{Wy'FXM3njxiGQ#$4P[\R- #յLyC&-]gs&;EWLSjEu/YK&žMJ0pk tYJ)EJT^_L`OA-\q %M *8 mzzO<`?AɞV9p6der;A&Ćv ض(rM?@&g_)SѴ] ږ|bT9+{iӛEeaϡRrG ^&մˍO:hq͎) ї-x Zm-~%"ZU^3,>H;-u-Rm NuEf5ˤpKg"7Q sfzpiJUO_T/2=^&V#w1#"xX81BE]7?"vCH>Y]R"+~ jBv1  NtKk!oO4"%:q[Z 6t_!82$c$LzYwbR\O}P5L*| cJerwHު+9dH3o_ 1i%ғh)91hr Tc 0# X4{b:V+ 41}`dxTǞ?lrwM/GTo:5ARe7]-j02j| Trg>@su,mn$Lms1TN] {6Vd*4#ufu[޾Q+'ZfO dMOCJbPkVmfP a L~I7bQQi'v](@'&d3up ^D(o m*n' `矘\7mje'& Ft ?E'c aXtQe_arrJ4˅[M[CE3vS$6"V\Y2=)bkGY>֣jƂs>a?̭:,ܼތj hB(MO?u ۭ4+(<t#P3+-B ~cG?44p9xd* BdYΧy5Zf/yPٗH Kg4'd5nkrauVAcDܕ9g7J$SӼt*ߋ띬d`CLz$;t2pgsz'9f?y;?|Oq>?a@w}LX4\(b(ǚY= ކ)Bt]ho {RX$tA HŮfONݎ+q]ϊ$-]tdQsk-~"}UTUSg0 x-B "3MȺ`J*B"-Gv^nP7n-MG6e30bq^??6 <5R3טTHX$d1? f N+~Lm}1Oad-`l+sc4޹|[tlj=M ъm}b1XAjOMЯㄻ NhDR~+)I+zڎ:bۃF/:$lʰ^c%ϟ|u>>3BRۑ@J*|IM]4"MjGbDR DaKJPb'0&ށ1*}5HŠ(_" euAk۽<j5\XU MtF̸ b6 XwBra`˂:^j>z LfDDX҃5qGo"V'#QFQ060tHWF ckFl$R2i:6}}?g PYI:;rҏ@55Q/d ^^BB33%HA|XʄD^}GGh 4'^ bk <#,[:?ȫs̔d.oބ ZQBFp_bN1Iu)M89)a񷴜+[cI?ر`Ѡ0:Ug pyN=s7.zެZڞ]jy[.l:־T-ҳ&2s3\ ?xUM6tT|ǶpCP2ʉ] P '\뱬@m|(= HxRه5-_^są@y;P Wxh²9@i#ѭPd+:Б70j%^27zk. Bp5TX5༮ Td7 ,$:Z0rPd䦨`UhRWŒ4bQomA+1z/7VϦL#&$_߂) R~1uLhN?ΐ1)JEW~ AJi y3](ԯ;=RE+tI*=5Ӷx^` yVPL[p>(1-B`Uytۋ֍7s85BL34awj@\ }Qdn<<l&jfu1c?,Ap@^ZL~+OL%6bMCJڅcOvhv}W Hb>4&!uW91RڀlK&Pj;,M)F0L !JlGO9 $ftX*$IJe}ԂF.?B4Sa#k(F$ǃ|8xpl0Ƕ1hW6`^ie;X]s!3y7ƛDl~sKjֺl/x_8^#QsK;*Hna@^0=0l)?XN-uMki& \R.zrWr9?LekJ3E"B#߁Ԇsz.9p`Ք -"B| [#oE /8F@Wg3(0Fr3Ǭii)=E(w?צ Mqu"] bot+=p䈨Qx%e$RXr_Apxj㓈@TO@~7צ֠eJYr=XNwY3n6) xȦ\ P9/*G#MxVǧ,U趫nM1ukL\٭X ȶ%$oBbr[c3ŀHk| k+iB#ip@ nS- &V;+VfGr%:S"`(l!)-Alv\z5#vӜm]Ϩ';Xbsq%T'Ğq &@Frp^GkO- a:fjY> 僀\7pO+BfV&L***.S`9N\D7RM{/wV $@/P%Aʭ'9EmE4Pɋc+'4 ͫpU?qO}#uWVDG0 [^nuO"?wy:$^m:$@ҳb>sٳ <*| qs"eɢB-5t*\֞A |ҩ9t@tj2$Qb4UMcaO٘س:${+0^m(6<8<ȹvb`?7غM 4ȰxeI=\"\6ʏJi O: &>V B9GYg`[83S\ 6v3ۮԕfe+lrVRj Wp1btz=xyKkH ,Aa?温:1Rŧ0W*3+% )I+\߻$oذ8>>"Ff)9@Q44Eаj=]TTt:-V yxh=-O4D'~AɮJM2!5y5Gf8uʳE[ڔ9s94t8NUs OCGCkF3yKfrO}@L?$ے5vEU$Duם߽ʊo(p(lz.M֟2bD^y/i;pTIܗCiU"2?M 3,WA hZTE1%m6]}lRӑQ#++ƓELhg&&LEk5=䅹[P~Y:6R[s~5cc \eFHeꜮ_ !쾊T[-e)BN|Fܵ?G'# d((Ew'TmxSpU*`0vvd3A=B-W Òm3 Vr҄l}^i,2.p-#kp|(>|M)TqO3v6ǐAZd:5t- f7& ~iYEw?O<gb`MyRܰmOXI[Z.~X v|o Iǜ%M9` ^8Ӳ/V@ :Kܭ[xxIG> >Z6y{y^ˡ[̧T+ :rY/|o2㌂dIGa&nKT3uh!8;?)QMpx Hmd!H_^I t>X3MNI})z}ѿlq?> RZs32zy-Zv<GV$$W] ywc:eg5Xӧ7E-G¯`r&5P%'x70L1"u,;aJYYrGXTӿNfiH&SaT`l;Qw|Ĩ=qf4DUٽ9qv2ZR#9G%~1%H#k]{6F DjC,Ź]L'3g 3 w5 /#D*r%vĠMQ%;\LA]+dt:'J:< F"2X~ 5`u d. h8{@{|b󔡂˹|0h *DG׽& bᱵ.^$g]yDwM_U'P]k3q>}/dv6[#tr#9}K 0i;pؔ:'l7k5 -(ԱNTH^JT,0}RlИ1]ӐuCɤ& Rb|6T2\7`4*(  Bdkݾ-Ej$.H.T G"} eEH%A]R'6[ߢ@<3R_\Rf7&Z'+2IMv .g[yW|[0D']j>k n?܅;>%)q9Aֹ6Ēp  ˏm\& GsTŰ<vkɐku|{>ܡh mBlowkrBr;W?Qۅf r1q~YD㱆FԈIJWBrL'64BYv GwXCӺwOPwXk*x{BpkHtnbu!>VŤ5m~r1`G_%9 ߑw8̲ts_2k.'Gا"D8Z| Ry=Y݃w7)f @*­7J*#/h;]z_ -rcCu)<г6L|J\q*Dƕ:h{XOu/+BӼ;|GP=4Ĝ>z4'Iy=Bf-y҃0y<ȓVX(8B|yYLa(2a@PNՌt’*$Ե0 ?ѕ٦P0a>^ <p\vJRAUL(F*іwtgHaCWZ3 ͍(`X{ř]8Z"-}?Q\k͔d_Onqs0>K}+̲ߵܭDpي> yoAgaHGbE =W{ANvD 6Th=I')3FOYU7 :`YSKj{{a2yݛ4{$X~in.JK32=(tv#m}]˘"F4;jgJ}`<)/j%"r3[]=?St(ظyz<Yf!{m_6\-vAW*Tr`+13x+*J랖UH)5V^>it?&۵hI./'Txd!|*Žں_EЦ9jl/lA*P_r848'-sɢ04=6;q5 B$'.zjjx{B- DțzHg? ){B+(g>\*$AvPEkޔQA`.j|$n5?CHdԪ轥{$GfO))(pVf &cK46VkNY@OX!UbR/^0, &-|#ѱmY)1W4^S.q]m1~^3TozUJf8^o:nnŰQj| 4|g{ /SsDUOWCvE}o5;*Q`Gy-/U7ai[[(y¼^d}[Jo-YWiJK**?8,86;3PA @GzgUSXb1VW5q?[~di\z7X@huʙIa_͙OAmo7sO:u$4Ofþ.@]M2`W.M(k}&:{[ yINFN[ʭӪ"t;߀xqh„MuyIIM^}Ʈ>>cZ;).r"Զ4潍V! 8MJ|i"v|I M;3 z⏄F{17:=s+GaUIir$sFt4[<AdiDxnr,&yD-Pݼo#t"Cv52R}"ҰP=ڹ"@vF.H@,♪71C أ<:y%˲mӶX 'l+@P.#[VX$#m9'@(k}rC6wCut1-/J9;&JMaGOfwS0=iXJ b Bu'Il913r?D(ch&u慮{H*L!CTdtuР$d%cߺ"Y:jK;^yO#mDyYLS g/-R^qS'oNR*НOWW&N4JTҁ.*TgO<I&( 71>@5G-] Lo;pNg1/Vܛ5/ٷsJd ]z}@3 dk +go).rLfM!:[I&Ҏ;؜Бci[{U)"PNBΝ 0@nSPQ\ aмt.&+Gi dʀꦝGeo}(O?UE}a'"c?2 ţJ"f0϶Ln :eQ([L ofn_Cg 0vw P5H!>Wi:Kn;ddlj>} %8j@[fr3c4BE?_Mtz;]Bϰ}xb԰q-X`Z%x}RTÖk+EwWeB`54Qۦn{;Qu ݬؐ6a6@+.I(^} ; 9pӖ%JfX\ Z\h_ԭǁ- Bc󋔟M"9PAa)`9l3NԦ@ľw!p[0B zo s%q~ s>eN,ڦo; Nd$T6+Z:GWR\t"JH= r*k݊YnRXw0TOHh {F[ %3$7|Z }ի<M?v𸨊_ka.$O,)z\͑8f\\ϓͿa=F\+ܰRzl$lpy)I }ǂS[[ gmME=Cbyc$; x7Xs8]:hq@qLq"t K!w0 -~'2X'-ڠ(Fzg^RC O R$y*!2}x3+`"K!.^u5A)nQ5R#{&VTyL|4чjq0B>½y R7FC"RnYн{J#! e68WvYƻݥ΀tBr3T}R2 -g kȩu8mc8S$g?#T1Xw(^5᲻pJ[;W&n0XLiY-KJ#cɱct.zZj(@@a[X{Ѡ-oV?3rKMaoYX[9,iFtݥ%"aVY|<ȄsmOQS,3[^42wwK`~}'PÎ1Pi_䮟;pD.5rƅƞsIY}*wRD;Z:JboĜk+ڗoVd/Ѧvax#&pݒƤp^)HnW\E;"i> 0!Y3vWMng7)]! 7ftsz>IZکIP ժc*F񛺶p_Ȝuoऽ 0i!'@Jl |Õ"Yxw˃iGrIڶ<ݤfSU9mBⰩt\@#? I$9LM4?l$w Z 7a#@lզwo{L >eH8Dv&R3DVJ9bMj+xiBEkN#>[xʈPrҲ]Rʿp .ubXnq& ^!lm@Y [͘"ja΍krdڇӑd8? dГ\^Yٶ򓹛?UrC4J)7*15F xx .SM4<&6,CU0l)ƭYq=0+YXSטs%)qj+4F$$pF6V{q t'{tu*EF?/d+_ N2FƦJfJ$wVq#s@[ȠӋ5> . ^UM .II5~ qG,`*Mj N;dΝ,qsZN7 1OM鳐I461-9kmI9Dj)rNiUJΖ'̝jF&CWE$ ۠9ax h,.7I8!w!t _Lվ occ $}ǀkR 4һ$jQ[%]DBU@FxI9>˰ tw1!춰'3zUd]i 0fkܯ?ѳ TIED/Jy𿜷hb%/{9 >04Ld,tȺt#e:rX𠯄s)?]?0 ~A4_c{^SrEKߑG~#10ZC)kcqy{$}:G=q~`GiCD>pk$2g8gRQk!kh EU˚ |udR;Pl AIF[4l, !rsRM>~o0Yej,`7^.*uNWYDw}!6BKl!c e-;Z } ]~I+aZןBV˒D:9n,Vs rk DXԜ#шS8\툧ugKI1B1AH w7z[\hkkFƍ5,u͞gRc ΓVbr ^^\or^W3{AT\㔔EJڛagf.IxFX|`1|we>v@ D=1He`^:N ̪g3{`V Rugm0 N\f/=$ni<7ms#8uvL"<]izӽNI>|-1VMw[??+2*29?E\1)~{tU Vɵ.q ,?5vpq`P~-)8n|%8x$+R/B&vǹ56'\s e17̴"LPU%Ȉ\V 9"SQM/i@KRa$u`Tedh)`2A:ƕa~13j7-JInz)5rK.겄뗸q眙]L L(#n 91sTqvUYBUV4"͂ZCqq>Ѻ=%gw fez}Ɔ0)5 ۋnVS m'q""S zm:PqxZQJ=ekve5g H@:=+-:w n3hJ\v[%)K6y/[m.ιH>ϛ^R?$:RNo SRs\|$>9YpSaSp[{ր\F4Eq7A{aPPiNM JF EГq3OD":i` ^Mote^Ig"S ~wt{1fx14ZP YnTt]mWY])Baxf՝x,K8rÀ2h:8,),ђ==[x.FO@D񕰻ѐ/; \RJVG% n 1<+=דqbo\{}cAlw^{{Xxi2yufsMڝ?Lc* 421@J$,M~l3 b EzL#8s>`j]3H?! i/෤֚Kk>Ln)d-Jn,s? gCP^|"3ji.|j`wUL'6su}O4Gy*ZeB/l2ζN!TAU ],6l.ՠ$ˡ7|WZk tӨ𘣎6GEyrSzZ@ұK9| >)oے3c/OM2-MaS?#MVƇ/Vuzq-_6 Ȳ7ւb|dZ1>t}g/;SXH4&knG3;K`B c0D~<93 fTo/:0 5^s_sw+G^ҫ}s̤i2s bK ;tsvZP2?kXyK~Zk*bFp;uôeQFlngimͩqyBu!{`@Ie-5JĩPU{ж:;Pc,gQ4׺ =0(F`ʂ}Dck"3`w([ I‚}]]]`t!r BfGmL ϵ]m7 eM4T@CCԳGƅ<ۛ<҃gyM? `᩼I9^~"' T@獒VCI(7.'%0냂7w܁*] nϴ7!aV B\[k_$R`}v)%;O47mF$o(O鳰|HD4B{f^tz%9@F`j£`9fbi \؎&f,%s_H&;䈔Xqky.ԯOˤo>w<u&M$WTKt5ViɸȴhR *G}DliUsE#va1!=g(kdG"hRD@蝫۫hђ3 _)mX+;dNP!i uU"IDB[/^p H rJ􍂌\ sYjn[e >?Tӵ}f2'D< $ԨMڀm(A<=*$D#lEQ?!8b‹hCn6u\JɒB(1RK}ҸsҼ38HB-m}^i]f抦[S辩+!dYQ4u7v &pcT!94)7^vwD=dzD9ڃ&Z>RHZ{`2S]Ψ:71&"q1O'5w/tϫA{AM[W},b]{cj9l[oъX}BԲۤ^N0j|\?@IJ_ͥ2y Go[` 3+\Btd:KMB׺cM~mWNm:7_e@@q>>+5z}Lr j+q(v܌/Npq9qgƚR@DԐAW9G$T=Y{f6Ԃ$Ӹ*6z!{YtWMb!dԧ VoA 6ekI? >!FV3 9u,fxɀa| VCE(=;hlUBy}dMcC/CJ;9MuCN;оiDU7Эǰcz5C)Lhgzhf$Z*{ʾGSԂH=ed~Aݤؤ?m*Q!2,bD:w@J޵13@CD(HRk7R<Ԧs iJ dqM C7Vਯu꽆rs|+\׆x|:z4eY_cc$㜱{26YV-ˠϹZrsǐ'*C¨Q݁ibss,ף`)K۔ڷ0 2\FBMw7 70 -kI֙hZ`} ;DzֶWR &xQZZ{([H\m% ,k2.[!TwH.vBi1vQR{pH @;C5x]uMzb!UOO=do*\KQ7iQ z^L&tQlGm}dLDg_Gj !<*Ta}$5[R¬/s\Ug'0:}[ˈù;r&kPܸNp]~jqnD91b݉mIYyv6L= ue,G-IkJT萛snqӯ ;R-Yx 2zSn7!PƑ1PVZk4qPT ]qO(!(?XeBR6И}̇u%doQ<ЎT"C_|ЄiV W JM`ڧ:619*R3/6|vAl #_Nم'(}W2 §olS X(3kOgT#[a@C8e5W>N#҃VF?.c[ФON *Gx { GuK%G sN#TulEwtZ[I;f1N|.A8mK͓)vG\lugHOaÚ=y"3!5 `!Г h܍tJFM-8^0j.33 ɦ;5Q?yY9g j#˓/):$7nXMޟ|SEPHu_4}}@.?&1+#2G`%#Yj&>?_i|0?ā+$Lb,p~c>V f ^1vwT]#QV*ޖc4BA7%f,L)x۝SAg^P+DwU;NY[bX^Ejaj¾]YKXe t4BKqk7dèGLO ;랜%x8OI,<:yhՠ]ŃU߆ ˛at@s2F9d0gFhNkƬ#Yaթ)FAgfBdMN٘|L"ifN6`UH_eP[P#0\zٜ CU|b!G^<-}_ov:TiTv%JRx:=)dxBpC7 At] AP}[Z!uHoLnW5D/Y@`xԚDK%xdouH|:KBĩeҼ<ÞB| l)ݜ"̎e!gv2 7GﴇF`=M|/Ki`O!_n_{F d6a.s{e'2)BTeHw4Xi?'iDGL˓W&y,@\*_d (,4 ;'&y,fzںph$oi*.<ܱϺcz{`/ cBU9aY3b! "AgD*+2@Ɗ́q\/H  Fv Z@lvj]?wÆ!ՀKx{fjdPM( v8X/d727#<>ꮏ;yJ^`xYDLk -gp0NzpyY ]cEWUnB@2마kmfR _60DKbޢVtσ>3}sTs$ۻޏa#*ϊsM\X8tly} _Ո5?T~6Xz:ܚljdx-O5* FxDfA7G=;MI?,,/.P!]F?j kwx/OQC/j8K4Ml&rRO:i! Bd`ԒxKD%<ؼ?tʳUk; Tی9ܦ`n2[=`>t)7euxr-9W^DbJF5J;Jp/OHO9vfrvQlIQ m6"d1J܏OXN.Ҷf4éD=ٓuvcCݮ9J>ΰ9qW@AΕX/ $'},TrO o)P꾷akX $OMn#!XW/U~~:\@0ȩ8 %%9?:yKӗm{h§X!^AİKPxgSdrvoR[/G%kۣ$0ZC م3 KM\~ﰝHL|,B^S#3Nx[.6~*cBYKE8zyυzxBb02Cb5Fs~~ٹà&%F% սm]Uby7v?<BXﲞC#L>u9~ϭ荱Gsѐ[MKAl%ߢ_b<4lTn7)6m$VEEX_+}+E:Вe`|FUlȫi=3۩4e3zj#eE(ȴ&O9 3eCk ,δH}7r8*fISPRpK v^z9{cX":+V7}H^&ɎhO[Cʑ}}͟*J[Ll&&oL0R1 SAylqWmgD]^VW; . ԟ\3tQ,j!P!oM3}(w@%eHE0]R$9s9Xvkbf;UD=[4bv. p-+_ۧ 㔡!Z)M{:_LL&\Z?d% ;;/N h :>"dQ{@Jפ%jq eC~߿8\/NB2"Lтr$f\#JVjY}04Qv 97#^7{  fom=dWQgTsQxgbPꩂ{<')4r٬lY/1mH"IXNP;(bG-n+LV{Qr]I{y `$fZ~%Eظn\ExYH+SVuJ#B b ח?)LװUS-TTLJE-%8c}92ާ3z;Vr)(<]sPxcYbd > MqNQ PCۜ`e7$tHB1v%@-2{g8 aZ>~ʗ9z0/och`k2 *oPCٚw=e r.pB2UvX?G5n ݲ(gw "|t=R4$ҥK:}y)'ȂX<3˴0o)AV2|oO>bi-*qw] %j-;9OYU\xl֎p?U-؂wW՜Y XΗhqU$Q{l#DYͽ;B0"D${1;JC~'.}J1PN ?:&Aͱ.Dۜ[ѢK}}"U.;n2c3*(,TJzP1qo T[Z{Ezʌ04$|xb?}2~@ b'Ĥe&ZJՂR/nΏra0 pHx.F/gQ^ F?X8 $G9L is۽{vaiЂb)Tt'2y=fyuz'vta(R䍀#o%+BSM(n 9թu@ tw".̓g8 >o. 2j)_'>+8 r"I-)i`ۦȴ̍*A2⩲ӜdPKF CݩN I i¥P*<`HvA1"Ӎn ?R s/i?PcfgΔGo5~nnb[gS)]Ctq3׳UNy`E/=0LN辞@I+\7A$+9I'1|MoA> O=\!?ax1ɻ4&-S5kU,\lIҴ*䡱I;X51IS1:*2yA;ԍh𫷻ޢ&$][ nFDGh/vw&* Iȡmtrx-^RT gc"K"Ȑ1ff=Gj+D܉V4!R֑5D YL>60E6_ɩh5lizho t-PxՁ̸'5ʸ uuk+fc[sTDK&wAkOGr 6HU C}88- P8%{h擺tH8ׁ|{_e| Y8UIyͳiA{Dڀ7^q(PJ#[d Z, 89Oɩ*ܓ{9!ի~ޡ`ڈE@(+H;p)=Zђ_wIb,R}[ =zzaT|NET?ܕ!r{Rq#{ndq0tKj-N ޓa5S v ?Aa_a9o=Ox~!IoBXv|5@ϒ dcL) =!]e[ %tp`f GO34̕eQ >*м^? ^ԩ2E@-)!pe>>~vvձ108u7koXKݫm 1?>*9:HЂ@؁p _ދpT:Ag⹚TJyfHB*q8P+SHGJ:zêG"#'b6=қ6G@ֆ/ͿZn1`o_%\ʸF+jBJ(^@#mOhҐt8w8∬QYGk]V2?4YCOR9\=`!5-&/c?Q 9ϥ:>h |)y,B4)#f^uY-qq͕=B O% #_4Eѭ= h@me4c 톛N0Mp&?262ݔ"o}VlUy&BAV=8 I^'8渀݆f*t[x9V=6-gJ\ulC+a/件=Z*ћ;|svd Us{w u0TD_8mīZu!xD]9>j꩒'EL;3/ O1Xe{Kv%dܔۭXROK0 b9STE8в2?K@ `\TEd`@PO6RFVŘrHtޥZjH009TI:BRd1aSGȉa0~R{J叆"Rh_v:4, 'XiV!9!2̲zXKM(&_i ?5ꮣyo@~O z 8(pٺ^t+;* DY 235)KE@Wkn ,~<9Ji 564h_`xzv閚Q5` kUNwmmdz)uW01d3# S]& og"ހi]Iz#K"Bs+K3wآP\.eq=Eu jV }1cʁ1%c2w*k(,Ǹ:Z5ׇp(D8{$I(]{LF<?}ATZ[ٞ#,BD(GqY(v'ۧ:f聆;{g& Sݎ.K᣹X[rѽ'ȁo IS1Oj v1%DA|>f6lbdgvIo+B~8r+IG}ž4Aֶ5º̀eJ'BY-$`G!G{;(%LO+%n=_y8/-zmzR CI)>̿vĭ, dɵm}Z 9/뷬S,wJ"ƉD7 da."kSΟg"n6Poʢhj1 $à c v3{v\s'=M4],1_OmC hOsca哈(&C|ؗ ~._B4uv! A><3VO~Ƅ:kkfX"J8-90EѩPmw- i1O BBVpƺd[7 D?/mhv(H[mşn6!`G{2&|x ]دu1E RʃTMJZiSC,0u6̩*nσ,.[IX&)6?#JR3aV e {IQ͜ZW1nXdVM"R#XԁnzcmxbΗGDNZ#ZYm ͜?m7ս1L~y_EU:йZ T *ʰ5<ڱo\ ?tFXٴhޡil;s(a">%Z2Ӕ zc*TKŀ4 \X̭B'99 B4Zg%4Jv| ;͘YɫgsY㶬ַ5P4w!c[w!v3d )2 O4-n}4&H:8Cb]&s2F,?ᦂLh^\)icgCpWsI";X O|HNRW]AN6jUmܼIJHU%7Ì\y}۪t '[y,qk^ &տNm"% KhHә=Q1g%kY6C|fZv|6 TaFk]7[ө嬣30XWas7Qϊ# /%k&Y[7VN3Ui=L!nOH0֊`?6ni'x4[.=UC5] O'C|Z?UFѺH$6ϺJZ׃)-[tWBYka;f`5yɦ$s!GT&eDWVSYA}#QjƟ]kK?i} 6=_>a|GsX0fIrgʷ-PxZL Ч-b#@fdM$ڸvg lvgsH#`֎gdFNoVF<¶ђvf.Qnc.N Xa&Vr_X#?oG_joK%\+k s3;XCc䟼Wzd%r ).VR(IA*T 5SP60HGؑ'lR& ! gha6]ݤ|>AD 5'31҈]/2-}XF@f;<0pA`osK:o"51 pn}+I 4Q I9NCmp6&AݼRGhq\?D@\NqzVO3w~ลpjcE`?w6 &'Uݞ # f OWN,v7!yrB(w{sMhuO -礛I[0;mG2$d@,V(ԴJA>D7>U?@ϬEbGWK|T`;FPܕcz,~yV#oLf d Yij^mU߇IȽ` hX5gQB7Dca)U)2o̿1hnZE;s\׈ ÊO %4;T-D2P(|M 2=~=X۬ph𧝄H`$Z)/gQ.J5&N*cD#?tХY! -uW'CX5zv0XUƸp4pFÿy+c_q]lUG5A:EDbG'SЉ|&q9\p dwAF7!Z߅avE.1s0 R| yvD](9#VvQ'_au|.>;9/}bjRИP-T*zc\C rmnM(YqQgˠfJݸoNw%?LAL6l%]D*Gɝ#::|ܲ).DǝHq: 0}[Ҝ7 .R?31 {8 )4 3x!YԺL ]qNх9hLLR\sV2ܺ;W&;/j4^:`zK+鯤@6tJ~uh?zґtγA`-p['bO^x:sn!HJ[3Ґn >ryiɒ9צQ~vE}. ܵR~b L2׊P'Ey?@ (bdFsl1ekh9|HP^F7qw+n |Y= u ϝb gREݑL[1q$ZثB`֌`#lG9"ƌxʨmf2VrVR!572nQ)Iȹaъt5GG2deҽ_a1c:;JUF|s% 2S7?rۧ(օxi]bd,1Z޷> {a HӞXR?x0]sXKp2>`- nUlvyOu}w#02{wbxL}ŔL _-(3)/(S\WJE]t}b^6O?"~8$u]tm 4pzi<o+ė2k3;[qt`IS ƃ8z% J:c `MwbZCP2NWF bj_fujL*zIPN\bq|Ldy6pUkOx, Q%@76 e 4+-u~o'/\ypzmb]5X@%!p{]$5|L6R I# ^(-ɓ6xw Y #}* 3_B:1#$gc+ҨY'#[݀|v3@Bs*Ƚ/R ߌD1pW|U 8HbN?Cͷ<3Mof{1) HRI2o.?П Utr;^>i|&GI<ߨ z:| GŸ4ݹ~fsD4HoۡԢRy}|R ¡M%:\V ymh'x ZAE"^>etְb A rK}+L)pԊ/s낅VmqU6F=aD <}E[V+Wo^w/;ۧNz4>3i͛"l*23 8|sK"&PR )1rnMwضFJ ?eЯ8FNY~ 7|9ܾ Ps)@$qK 04ӥ5dJ܊">SGv'zA2s|\ʘ}2kdR_ 'Z0?BwIYc#UCM]+<vxγ/TOǷ%`chۉhW_JS|7.-ϞKAф}qQH<)x7Ma9hd0/e7ҽrrif8b}mv"ĀBU;'H`ۡoebǧbmHԆ K{0~f=+x3 kj78Nw$Q0auvNMiC>ID"ntuqUVܭOeLXA ΠE>4z*#w=wm ]eM5S r *6> aξ@s#iژ7ps ﰭF˷70_J\teu!~dz8k;)C(EfIֽv>iS,z #C#/B+ @͚C" yjHjicT 1/=+;VqGV2υ3zkxhiȹLܖ:8 Dl?hMwVzL'fp|z~?"GQ "oJ̛5z+nk Iҳt [>w6|آ;_\~v0RYfӸGGߙ, 4đ[k% GhsU鶙?%,*]#b9{ȃLv+{IYaT0q1J;[Ն#;%ImRCOl:m;HAS`:W)sz%|J Bc!*^KM&˂1!xf;u~8lTqt`mjb\}r4#vϹдS]*A n:Wmr7"ҧlŒ4C $6M\絋wf_WI\a̢5vu8T e pfO9p,?/0i7_*HҦm!h@¿SN oN: \~Iv:d՞?>meΝ|b98@4gO`-Ci>?W̾GP~zbv+ 5)#JB`$/3Fu0M~u$7Jw;a94 Jg}UbR2r LeD!uJAKg¿? Kxx n]} s#N5l%$FW9pr&Ouru:B썒M̹3œᓖdK&l^ yҷ$T&%7OF*`WGl]ؒ M bg% ٢tI~&(i_PN$?$@}QpR{{> ҕ@_p>y4mI<ߑDU4հԶ2)>lONs8\TtH+ & S#u_cXzU\,L$E!em:~X 7=IϞ R}د_L#ĬK!H쿃v:J.A4f\BG N,\H@9}Ku/ʳe[PCTH7EY(1{Q&}YwxQ8wg;+1K]SWp771(C!0m<)4_n\͡`ήyDmk}ƣ]4.QK=\}S,lbG?mME="EIu&`JCTe1lF Y%m׾ОJk|;@xM{u7`FB)E658;^dת n'j@||AM0~4j +nx#-ͫ soN[M͟Tc€pC\u/MJ嗏L̂:f]sy@892 -ǟ,=3q>kFDePQKyA}]bm1b؇bP OOBX ,p\LonһH[u~^(Ni}͙Tb^0'wuZ}'ٌ`^i'Ą[f#H 3 /.V*%.Z-,S&ʄEei#! tz$:|Ce{EO=O4ʏ\h$kR45. !}x9LѢ&P4 A@ݨga<= $ _p**3jwQ>Usת 2ףB Tݦo[}Q`wb# epBԊTi#G2 p;Igyc`!`sא=a3202a⌴gUjY5Q DH@px?zG 8 ڞEMw_*'jgsLR4/b}me{,s+#3&@ ~ԋ|EO | XW"mH@HNz@By;h3`ci} c^hAC` AqEŎ:-PNUR^=I -6Ԓ=6_zl)6l, Q2߂ؾB5ʉ@m!\Y0tK va  tuOMH+LJta[aĸ0ͨ/8/ҴOY 6.rrD YI=#@滠J.SEk1ש>+&#x01δE,4Jѥ Iٶ@N XӜ)}A*$E`]wU0-i\CGRKpY1i^G[`raU4WyYmcIKv6`_#I؀ϧ>)c yfZt ˆ!@\E]oF"m^J7T;@|-6,61$cS*mKrmy.`IoK!1Ƽ!nv-(P9ȁGȒ|&" 仏dRCk \<1f.gb{'cL2z="TڡANĉDQ!Yn0)B/zW3v޺*I4;"fen`r IRTȦ$(>  IR_Qd,0$"1.^ 6!˵@#*B+*]~L|;+. |.PnA|04D| QJ} g[-G"d0mI;ΏM/^Q*.kDy!vFUkh6C\Pۘȹ?MU^FK_MPHB7,Zj!?aٞb~. h^YcsBhkAQ#C l/!˻2|s5P" bv,u.\hX]m@,ĵ )!n+֮2uqDǞP}RfaH\ÿr@} 6Bo6U*\J,Utg_$~vgD!Bn -r-%v6򇦨y3큆! &Ь[l 9 ЮfA?eP؂#s#fH 3z{:;G(msg^sX=je> S`)VU2r,T񈣙q! .' Oya+x:  U9FfcJǾf2#:,rve2E7v:uo5HUJK@=$>ݯmҪ 0 EŞ2=RXq9w1\;aDއm`fjHT':0x6J]߿vnx1I_0.v\D& C%;or?pl@k(eKT*蓦΢=ӳKyu!ىPyw࿕SĻ1g4߸cV!i3Rh˴5H8,ՏeӤ6dAeД\0./X.a$ TG2`0ƘqHEiIM6S(ˀYC6ϐ4f Y6KscUn5L|ql֖oINQ\MLIGح\ir^l/6>>CR7mLp!dJyEGZ}HOٴ"뙧$>3 [fܗkk*Ux\!i-1vo~S|7?"6Otw9]&VXlH!'w;&@Uv8fb!NսЯdT՜ND׎&{ $NFyXtׯ 2^kw.ˮk KR2rJ鲤l`Z;bmƺlZz]v"e{aO9znb :ʦ"Mtӌ,%ൻXJQdFbNFgwyJ& R?-Q-uz@xA׍qiLe HfA 0C# {(2liVq 7 @!b8~Ro$R szԟ}ox̩do^00i{,9a*N;-A^1yh6O,Ld`S= Dⲽ`. :XJ$rt<4DNYB.|yp|G jJL,/%H‹>J/3Qq;,|F ٚqXBǚ`?FJ"H~`C\:d~y0 Yʲúس0nZ2p0(/CILr/k 4;醙s!?CM.3vs}S`K8ndnA'ZȀCKμk7yϳO-:B einT5--$ONaЬ /8:e IZh@Acu>!7ʥ'Kָ"k?S>#WM@?Wol/:5뤍{|R T3xcE ~R)yTG5FS:"[쇎Yުb_xxpM'M3ݏA!K܆ [ȩ ˗ll=[[֧,3o%Wr9}IEd p ?t=gbT0hɏC;jGUTӍb>g׵6[(;te}h2eN`0! U"ݰșa(@"/͆BuF?"kch%}$`p&Atm$P5B~T 3vm'O%N6b TSv]}(ٔmdq. n"bJJ02N֎-`JmNjWޫYKEP*ж;6桔 > =cTgEMD_{u< 4'R½ԥGs#5.B֬ߏ^`E|/%Lv q(6+/QsrDGV'-"='L%Bx5_z!dD,P:(Hj^|<UgWOCr}NMf\0دS\2]Kp%zc~z\q=HgfYA&*𞶛ahsq^UFojp2t|e[8j Nx>#XE2eH؂78pQ,fBJc@Nگ'兎n O wH~/ Ah~ؑ!_K We_ۙ._,R{>Mo<wI䘓휧+ٝAstvY9QjA]*cF0DL/"lP0Yf e5s*}>, q9"G6_U@%AdʹLa`~nr9-LR#lqS:*+l9SJ< +:  j~ ڱCo%G?V@V6^W\w^.C_ Z4)Cv =B9-dT`H^5QZ,ن$%GRA7y6@Ƨ,c3v2%@@WK@6$gI`܌ :ؽ<ːhyb}LHwGc{cNx7!1Oo9YZK5C0o< Adi )")1*6U3+x95M+\XY80}4E+vHn Hf@qD(㮯xZiu+ǰ0TP֒trtG<{h|#URm,*[w_޾KO=ȷooA:.цej#{~&GF腞l|1t%\0}Bn_j=fEHgLg4xZ2#x7l&plՒݵR^{K'[l-Ryfbd6$>=C* JQ,Mܫ?b5!i Jb8nLBYm]9T3دBH& rC%V,Xbp5x+(ζmɚfR XJ^UWaqVH^LκNr]EGnւY H"I).<3PkQjvMy|ԻFLUMɝ [ERYK7qxq1w^٫ wzf &6&-Gǚl"+d;H6c'D܄}H%rH &{qH5u>y?A$|P35AEY~K*ƝwFqneqi |4>J] ִǦPp"؈ 3*/o?sB . sӤiP ]؎/+I-㜿=~q=-5x4#vMM<8(4d=d>? -MwSq=) hPPlΡ9v=C2A\:`Gp~ʉ=G@Svҵ7&{Kr;؈.X3Ǎw:Lr.M@Fi(&Ћ0($fLlq+e6#f7Mg dXg\@MfxmɓV;=-.KlQ s|&dobn1yJv @@'D% PYأqH_K%gnS6Sbv^+.f<'h!6Yq>Q=YPSn[ rulRTP:,䓗9VM5^ I3e<}KuPUVp)ȴ F\ȍ}vly6 ^B=)sRa QHÌӹ3Ϲv,:R=AF&ɓ$қJ?f#,]!XjE pe)řB5B_h$@kAYf& g2/Wk}DzF-wgo?]栫0`v(6ZXy&+6[ү' z, '0Ċ  SO1K0}-֨7^ҏGO;USkB_k`'i"EB RJl1^72%T?nA?GGG]mx$5=$ GR&@9x(lL5F!ui -z<޷dF9_x( ɳ Z NcCBʟ'Zn'!Q0̱2R_9EP^۷@xwJH@''hs7Hnjp?DeD)5]woTeru)9)bA]yObjP3rHeTl(g0[0q[ꆩnpNEa aY'es,pc[m; Z,>@Fx B-1]*|%A) T{uem9˼+~f.2jҪx-/Jd={o/ _( o#髨ޞs}⦜My00Jl*z"/%,SJ#3Ƭ+-P 7dgx8zWF3 OZ7Ƃ  +#9r9ǙV 0j~5) CwoxhIiݮqP1y)Bu~a|•ڛ2jԞ fWqH \&,Iυc. >aMFQ};hVOi]R'Ib*\!mC)߁CV卾+FXˆNp<ѶGyϯ8dTŢ" نeƽLuvkBÈg4~cr=cSjN.y~\6Pes5"{BꭒκkL%խ.&!Ry-(ēW8骋bEL pOum_Y5d V{ `;MtjF'v _py-p>Ud"g~/ u>|AJ1!y}R:@qK?Tyc{c+מ0 <^>wc's S9?,OJ.(Ě Piq=v,Hgd3ڦ浹).-Gwq2ztA!drϥ5Q7PQѪY]"b&WpTna.x,k#,f"_@ΦjA^U@: !!f+*"T6Vbp1qFf`x5+o?%ɰ?iNZ Jr;ln|73s8vk H%iV!̀{ ePo]Ĩ6,Ɂ{TEϝSe8-|El`La,7ys:85v}-:k`[@T!;lcT;Eh,x%B&"$0r1G$V@Awa2Ugkh:3ΏbV,/Њ_6oFpG> -?}@-*e |;@4Dc盤ERCw Ovl4?^o8F rƈӌz7%f-v(D7Ub].G>]րqG\J l_b?uq>: FӽLI% Iûgh\끀WCVdͩōl;I\W2r&TM FP#hO<&|M1!8y7.`^d]2Ӥ,y$cBedZ+8f\4y*`Ԁӄ DvwvnN8YLw 8ވMLaNqЀlkKv=^堶sD{/x;ו" ︵p,~F(72(^an}I`aːªYvѤjuglʾv͹xImهY]M&KY͐e `!PoxtSc4rP5?11U~t"JL/qmA $:fpUW>% 5"X! ƍdLFl?|߰%]ػU$h5F>n$`ȩh.OZ_9SJ9cf:x,OX`^VR-i=S5%ۑс3*g~kXX;KBu Vh-Xt<$/2]GE`C~=:zEu !i' D5sK lRa!M%;\i_ἨYl/eg+O7gOF܇S|wMkݳH ot`?$K}d{Db;I`T"&Frԁ>SʸtODd/!:l:h?4HmH1;486:CITiєB"jUȑ_l]2>z-ZgqDCS6ZᦚMO +FRҟm2M}Hs* CEk*r$T91 c=jC*fɢ uިc4U " wG%jL_KhּrApU]U'Wt+p uK'm*~ ܰI JT)]+WXOeyl2bjhim`SWP˲\GJE|^i~CDPchER"cPJw#0ǿ!uW=s%eES#?){%$%$Uzd ܯzwzT`Um_ڐ=r*eUQ0}]%ŴX:oaܓ:4(_ Ta*8:^UD|2XNVn/KvC{}M t-c>ɷY@>=pҠ*&aI^=ᇣ,s@cʹR%bbѾ<97L05!b&렱Xk)튡-TC4|c^wPVԦ*2Y0Yqay, $Rk:4F1)fC*Ut!:5(IaƔ1PX1^j*3{zJl c0Jvul10GJBI3ΆC :#z&Ssa&,D9fIwBO* Ki2U,I¼'\Tȫwڔ姟TC^CIe>1TE\-VvܠFj[[qwCYʾuH3-JsCx#t㢒NQ 6{5u N/BX̤#ϾҺwֹ$fr%=ߛ1 <=.B{c l t'tSD&(ʷC /٤pyyUBTt!$xG r(eZ/&gEyddV!•dFbxXgW0"WqK .bg> ҼaU:MF(byMdŲ t5C bQ$ 7>p3w8~<c._"sc~⋲7oݺ=-12p+9Qǿ&p_qR{a2e&Z3HH(ݭơaf%P+r!鋝.$6g_?a{rEiܚEΰ[CʄX%Lr&( xƵ*bmYOe Q=DH2S!"Om i5H% u9fvuTTWel\'5nkƙ|-盕w(w<} .H.y]u+8>[`I6Ll'SxrEE}zDzG{A]uMQ0dpTW7K.PxMh撵kۤu:((t^xv+K߽KрYZal',; mjÀM3((^텴#WO`}RS`͑Kt"z&ƒm:#1>" $E}`FTɸo(QKmeV9vQNLzsҗ`v~^BR)ǿ,㭃fF$N#A ܱ=z%\s1%-Ϙԩ-[9Ұ*2!)*_@W@H;T,1,Dr/UlGOrz-RPkxt"*sqk;G>2~Hۏv/,5ЬÏ\}{f~ؿ#*=~*&mBk,%#Hh×vwG-B( Ơ 2vOL&#ɷSL}l?nK2i%(:8E.٫p\+JrNfW~$F=יg'5TRbF]S[=@ Urk_(_ aU%:jZT >=7f"4li_Α(@ܟZE<*OkďIGNҼz'Łx~1cy2ں!g]nLLOx=l~s0߉oiH -`m}FrѺm dlX0-8җkҝ+ snUD,ճ񬈥\h#t/NOJ;H1aY#O6Dy3ًodz|_|ؘJ-l栴ښYy fWt]*.wcq7V'/X )*K #޳Fl(Tbl|D o-@IG:ք;c"^hPZ'tG^E~4X+ΜXK8^فd[yVƔ} >-g!Y@%U,Q=Ø#Gn;Ȇ]9jZ736s8 O9w*`` (Zqg&Pi߃[M!@xX[ed(i?h}nCï*ﱙxcKiO%<>'+)P7=yC$EB#m0b>=U?#`;OfFŋƫA4XGZ\$&fUA~X[A@P Ã,\)G qou_8o6ȟ2 \M3X"f^C;PAK<-aZ1yzM%ڳư"Bw*{K 8e)JeqBBB>J ]4p:Ǯb/VӋ3[_y'T.RohǤ.P״I2D:DXۼ,=2_ordI@ed%41Wv[_kQRZKGq}e[B J`S,<Y\oV$(OggaA.2xYw= :iVzdN4;uvGmQ˞DY}#kQ.Wtq<1E2Sf"ll쒁b;Um7uc<. c(Z \ 窏ӰhMP6XnTi2n]g̼ʷ vdYgtB[}zh㸓P3N a'>[PIcg($YwV|Okq\f{1Rf,Am/2 Ⴥ@]2%;7&w)Kwe,i ZYU*UZ(;SzmRe+XXO_8*'PMnq4/.aTg5"]G*|XHobdG8p) t^])ZT;޿O{wdfw8L2 W= t]؀-@6Q2^5S h7d1sR{-G5"Kv^N 'v3)a-+REA"hWґS0K[KK $RP'PP0*(B}*1\ݑ$nK uBeMhTV暂i }oDQ̶R|]C GME?v\5xlWtK6\ $etZ8l{ڒ17NpNBۥG LRo{6 ٻ4NIO%":tơJ=_dbhq\/;qM--;F8b]V*wBbU Ig%|FE25ڸ/Ӷɸ٘Pn Γ(wr]!: C{>B'',澌PZ}-Qŭ#ՀMpJ:Y"+yPt/=)ʣW#8P^~aX OMoBM"9l2 1udH_p[WOH 𐺲osCKBiLna+mwL5uh>JGC?qy\ex-#Ȃ k#͡1zL'&1[W&'ojAc ;=gU{R2v4;:I f}7uݞ9E4O}薚W%{`"91H[A{ o_a@d#\՞ZGr9J3(kZkrbT4,\hf 4Yԯ,5TW8qr+WyQ$.ll%xkJ"~97 8CҺKK-Hs)(YvC5[vo~/zmMye~ae@0ܛP`N*O/b)JfrwԺw:4&Pfj{> 7+<׺'分 i3y jQH9p;i# )uruܿVe՘!/d| Y1-Cۦ2"Vj?X~q~Z;Cj&WI0^-!0gW~LBX#dɝeY!#l@օm?#T9>~S9ŝٍ!RSa߯K|I|#R /|yG*e7c~я(OO[2K!\S3,xj8Uo[- lͅf.ea-ByCGn`[Dx K rECTW$bޞ;Ɍe&BX܀}aRFػьalUk\`n-:AN/3w: MH98b)\e՘ݕ^Hv#vptxZFY@kC&4|ZC_ZYPW9Oьx* 5$%PK%ekcmq~ s]wk!^u[RZsoH}H.^ArD47D<#F}L-)3Y3D&^Čʨ,VƤ5 s3B7o|49x42ׅXJXmZ}1[&8acgM Pio2h~DW 'x"9,0y ۢ Tb|āXٖ2ʣ)x9a!DMAjyK0Ɵ^]kwX3< HFZ)҃)!XfU-"lZp ¶/rƂPh'7W$f#.&> piIc^܏n4H?}`&G鑊-1¥:,IS?طA#r[x26v+9ɔ_6N4c*S¸SPV~z-en6oAAr*_6NP;S>SQؔhj&] ԰oF+Μ]5 z1o{mNH8/xl(EJce-pi#vѮބB bx!%FOqhz^)zh;39?ޛ ˃0 a0Jr93N;G 7ETHLTGI\,jWӾҊSu՚k|đ8evy 4Ma23@,¥)b fXo n_6I?H݂)PY@@INdRnJmQ"ң{W`,[𢳓mpVvN~RPJb_Zew19*#;P?M7<)*A"wDt E"ݷPZ[7 wN|Yy9a歛KC#)1AjU0*r"R/+qD}3 i9q"5۩֖[ @ʘ++MNB\cZ>>:ǻW٢^ʧ9&б)нK,nMluS "Y^o-9'Cu=m]E/ᘡ5;flA jbߘ5 |k/᛬Y+On)8į&h3fEYE$( [ UvOaF 2ar 4ݎG5l!$&שz˙*]*VߺÌͩ5mWm7L"w Q'Df! 6O68+|žr9%adz;T7悃Pز+5'c⳵cn_Ͻsg1񫝋xiWn=e$ml x ˈ{Q)ToweظTiE.\c-ߠ(7֒ <9og xj8RoM!Gtb픬+Ѡ=NV٠͂_l0"u -1Kg>[F9uS<4Q[g)u0t8Ks W j Zz`7Ƶ޺y==W'EYѶrF{qYa^JE!g]Ce_o ]Ѩˡ@e#a53{oKi(0OYE`UO /G?c @e^g}k}ؚ:pת;a gؚ_E}ribZj*UESiO Vq"f?dOe !n?TAPbyG4+T4.599*&e3Ay G I~uT+m6FTⰕ[6w զlJbíOkiyRovu!?n5iMƃ?. Gxwg@l)K0?=:~gfF|܅6lY<( a67gO;E }QL4pyk7\vtDMq7$$!QcgCj zK9˜wJ骠9#}9^0UoG?kl OpϠćD)e dt&m&Ѫ);;`^ u-ZOp/lV^·3v,)t3>oܚ3({ 4 %BX^q* w<&@|s `&jcyjZQ5HޮF5.m f%ەi/DWh5i1u#M@Pa/F7iaǚm8AB/Ozu0vqm'T6J[#wjud}sKT{$bd~G1JnПTÖ=jek`͋ƙdzxaŃ08sy%FGuUOGbQt #_WŸ)l엞PjZ{ASQc)0sXr-+a)=s g7S@ZW2k6kـo:a>zbz×I}a=/un;"\E)8Lޒ™pchNS nn @B̨xQ,,dsAҬ%k(x}Hhvd[JU)ҘB^UfSB3+Ia#EW!*JQY}BF 0|{ zw*N7/:s:m}lWn&@a3+4q'.UӬF_;D2x+匈щJ'zъ50Ȉl꜈d 5A g4XO=}8m/tGb<&R劯%X@ߠStLmGNy\cJ1դ,rEstISe`X@DZ5.na@ikai_/:]GLF_|a tR6mKYQ(qa`=]I]!~ODZ۠Q,~F/ TZ(qAzH*nDX_"lS9)k~:,ܩNrL7ۓj螆Z 88'Z?e9 ̱"obxS' IF'b`tbzuƈ_]j,܉L:CDc2I*8HޮpS}?БG! 3VGT4n'&fc1_,z ԓF3O31 %"1pT*xFDJ&N*$9PWVW58?SDȉ"NW:GmUO]H.(WWmӎxLf˛<aA DXx\ՐFC'ǹ H&KY*EIӅdU~OREu^w< 7owYe8P2yE%{~F| l[߮FD,ˮ,ϹdWYЦI\= m!FiǗ{˦ڣefhq1pwsKB1tThajE ʐs(NGo43QN&q]# r)cZ | :SIgeoK(oIlBνn $޸z@6dH?n0,;ӥߺyX^[;2]5a"@ږ;}8pc}7B iY7:0um[ dz'qcgFgBqjV}ԠFp􌉃)״3ۭlxNwnǸA'^7d ]N ^;' Qr5`#Ѓ?X 0ԟNMg^XuDggSac R'*b3Y/I1Bw<NPP pWiS8FSlH5Dy)*1$qT+?ϗɯ=B3% MtJ!tL! 3j.i<.S_cǒ*V@CG+Cf bz>i0VpGi9"Q~)pHR5 {Hs:D0yh+o*^EYMmu[lK>{uBQ2OH40*.jVSFE\au>k/,`^Y_& G%Тnn=b [yY%\nOÏsTw@gߓ*.@oM{(E ȶxU׋˙ʭ8&Stػ&llഉ7rws.72fQr#\,7mjׁk$pG"ٺ eq>GIՙcM!;owF@,AUtqՖi'}إYb6lu[dS޽R9|3/eu6̱ [)!2I/% |Bؚ=W"Ii>ݩ>5)vov$HPGta[2MCkt2 ]PY1L)TǯLNb.oQZm0Se̳ؓV _g Ljzg>хB6?;wph bS+-]ԥ;0[O7#''S*"`yt} !*LX@6nJqL0yL2LE)z ʉgH`)) u|ݔ>Җe#p[,+6%3y)A >ntR9~kiu*67[[۠fu%IO6xVkEn27T1}oPh@qh3oy#k=R٥yOr ZJ{t#!TU4DGG,Vk[oIZ12ͽܜa?G1KImŻHC^ZokfYQ %^p.p~}2W&DEQ=@}g(wgxT)?"5'49n9Bh~hAs}(-Hɘ{^d#7qpgsQBV''iAVLai/X!loE"Klx+DZO,M@Y2ṱ1t=veCTeRs@E%Y>e=tQr ؝L?CqURuھ`9)*F,nCy@Pǐ!^P}O.Lp3RB问PjY|:B7f#BQZجѿ((MϹ06TNT'^Xf7~$I〫\(_*_-ی~Lkv~t> ~ƃnʠ5l 12z-<+DGt73h'H \`Krzh8=Ju9ChM܎#,]z{4B)fC=̤i1;~A]J0$a4Is3ЧAE7ek`·!ޒȓ7[gʊ#&xzˌx!Mr@4CUcx1&5ɧ-q/!kߢ;L#_L RjftM ~AB(vLjm=d )n]DR՗{1zВW6o#jCAqဃ^s<=MA0&WܻdY( D󩝹g*T2/"ok^Wy"q dcfamro/<$(3f2SX 5u3H!}s*ؗU`7%̺tCj:)QHP5i=zXRo^q <-GlL@>+DaJz)ޗ9bȁLbz2;Nsou;Tb=&ξ*z!0`ܵS '$J)p[FD^K ؝>C7Qu֙uc!""ȯ5.-ԞjQyJE0ٞ Wg~ 6i"-…@YM|哒?}C53W?Zˀ0-~G Dž/(dCV+YUV|^iiߤir{nȊ1 蚡;>8]0`\gm??U)ThE܊=ڦ15_ۄ.+Z4ނRGw;lE`TJ [+[K7wng%2wj65HJolQ ڢ,O6o9c fDzD=Λ~H.Yf eྡ^+:ϒ?_rqqv$.ރEmgDx `;6#_q 7-k&)r>58"pT2 hկ`%xߢ4&p 'H-/k쯪lFi6^AKc,$ؐ>ifD-՛f`9 B s?Ŝ`.xDt:x%@E[w^%z0T|=:F5ht֐HXrin辰m^S`ѥ/QBўW\iV:/ X(\x*7n؆j|f%J{lsl J/1;[sg`ǒH}LbcLnm+>\. ɂS;wƟvb00{k ySAT0bE8oud/͎KL-Je3#"!;v=iJ0Į{RUaGFG> 3 eZnPj"zޓoDOP+w=N 'k2,ϠSR<XV#:8!y k/ާ5zx+,R2Z^քH,7Y9쑴?]@q,I@ÂDq¾|3x }'K) 1dnRAfܤTWhD-$WF}u;tL%!+EӍJS7!C/(`d::`H_}kTC?ƪߓ۰cNB.V;肜cmz\f\b丙|/nqv۹k0+ZSr!Xf#m{6XuEȤJe<=- a\>| ʋb%$w҂'Xڭ5tJ< $GA,Y4H #P*I&Ҵص<엊)un1c{wCА8d\`dBm ypxFLf!έšgz+QQl?_@G~Gb\Ju8iaB?欄'PcYDϗ[?TDZγyPo6j/PxEL|~o1ƲƌJu<Uf:otx!+^-”"UM0ov-#Qf_A< ,!Hu }*\58/NsZr'0H{^z.%G[A_*T=ͷ^J2bojIH'Em1H_ ݞR<7hą ܴ:}ʴ4R|{t'v,;}j\ZBww=tʂ@ʽA,x͟ ֲ/@- yé(Ʉ2]mB_n mGlj55ҝ?FW/xh=}"c;ckƠhQqH-w"V#B qڐ$S"X{^WM=i'{wV@*,Dh“N+:B%]y}کXb:/6W4怂o?;3̓P 0̥զ]0;BR>( #kڜX>e;? {DUPV u)$\[T ,[Wg77د轅`Bouڛ9p"H.7 A*AT:=K=%:\8PZ%JXKFj~.EwAZ +ZCC:`I#u^ZVx-btR&/JpƋT7"_Zκgy Lm8EHn.shsؗk)E\9ӬҒ``7Ju4q5F+2Q9 MZv}5w(7o~: i+(iɪ3#h)=/$i91扟̹]v(g KHJ' HjWDI{i WEiDW_U[[$cIq_ @!sy= ~:S0+`1 G[J6۸Yq 1]ۯ(9` *f[§669)?# cS Djuڇvt录"/0ûfΧ-،&AF19lZlA$wbBWyUԗqCGZHx~+z.t|Iu``_14Ŝ#ѼuϸW j<*"/rH#[GOS‡,Wo+VjwDM#m9O\79a$zN)T:{qu|&;9ްчSlVY9b="v ly;<-YʪJ(#ˋns3!XJZ+ 1D3`W?׃6*3yƀiPv\X )2(vT^n{b0/AxAf{+G.c4`N޺WV8!ѧ ^ZwMZ_>k@2g TM5XRPsT*=a8Zݹ>oG+AP:5VsmL+ǩrSJ ٌ`||C1ΖdܛPvReE{ Sv@)s-9=^sPiD86MJR8Ov' 78H3msb|ʚ4XΕ-kT,߄^|)L6l*]')U+'Ϣf\zFn@!-J\DZ hX'E7uK(* PӠg0{4AX~ش}jjz86h@Epd\yfl3#e%uҪNeqK Px9"xj"6afrXT :J<GHR Wj;e hLL6oAi#3l+ wbL ;I uiER`S.wg}50\ʛq n?fQ#Q#GA7z3q*5ч@4Nj$#(WT.Ip+p~uSNeAQ?bn 0i<\7ψo@b7J">.u[]ZbjH |yh.zCIN%L \œsSt߼bٔ/UCr'%tW,K;@%n8V;/S|i驖hzِF%(mi4etpqFkJd6xd)k_K\I=RQÂ%b=ߥ)tvYyIqN x %zRb8d1-]Y]f11*4lX8'a1CzhjTͦ(f99-t|BYrE CvRvQ!V{lp ﻬ@M'$σ_Ow߹aLeFSEAo%7DڏZ&k1by1Vl |&j$h>3D"t|!ԈB;]&jH}Zs9{ܶ)Ԝ)sN=9fG>OO؅і܄j u$n9ԏљH,oThȺtt$`5M)x0 ޅa\GI42'!Ui9GdLLwq7 PD]U,ֽt+IcVLQ@Q5f3t=1`4N Uvw]Md>, b&wX&#De.Q;9A63̬w2f!ڽD2;ohS)mӎ1^3xy57Fu+ coåah4Gq" F;oFdG0`gF\jC3Eĝܹi9]r(*?9b«ԒeoX~JuH*ۺyZP @~щÇG#sSu݆GŃt-* Hi?҉myU1`W:T&Z0*O8Fوғ}䚼:8D,臛eo<]jZj/׺/X*Q-)@BxH*2TՌ'o.B(奁6,U`s4km`n/D/kΚo?7_{\sRpI O(Wu1;kCe cÅo]=Y G(lE'6|Mr_`beB-)I6,qrjywݐW5Mz Gʈ&92@;DU~|jDh[QhB K3)>7m϶QtxuqV6&qի1eKaV@woNF(XP?k=Ũ Qo|D<֐iZcc[W-Z+!O_;^G`:8:[Z)D1i'FH lR7K/2P;¯upV%y.l˛l9Bjs*i߯/a01C=c04p [EQ2",vvPMڝ 弢}> ;U4%;S@m5ƨf*#/vEVZM0%I6X#{<5&$NгK>TBV_70*渕 uFֆaeo\δC-'r)':UF/p Y@j󨷠G}a87Gᬉ@X";0lr+TmKyT{. 3"KLrLgYNL 89(5?~^5Fp6i3rNe9aP*l ds%:J&pƺ*D{VhO z2ѹI;&EG#qu9JsvĮHQ"oHyD҂5ޕQ?JM-v;oyFEA;F()0PlѠ5oV|Fp@mt1P+wRKEezҀ!9a&k2;< (NWL&j>OȠv5~}"953K[ B6;g!I<{v83)gs+^[C#kx' tyx>ᑀ=h4sOB;e5{ *Rh 7|.[$01}GM4]%8ӎc|oq 15؄*7+Q_}!|kPv>37$,& n_nhP,.Ay*>qz,ڗ91jYpap8;'!.ZU<qRdءTlMwh#{YgE #`R\~sd{HbdzxkmQӟ8蜰5{(A/fxGQ}j0 poFZBxpmi7Ny-Յ?rr ,ڛoA1ri,Vǐy[ox3̺3 F(nnHk>Vы4dOfFI7?ö}mw0(?~r$x)t͢A}/ȆvOImIlQrQ$sw1~̾!X{[']W Z\%f[ӭ3A{dSgS4cp8 C[UqF/ 㗰jUhl҅J)645I{ۦC'FVP{ Sy?a(3ŜacOpUeGBU0 ?"{P"hp+|Ж p~`/&". S߃&0!@AwM&>89z/f.6RD!ޥb֓K-z*32q=WA\oM8d?L51?8xxtѤíR^BŜZI$U5+04wE`\ԓ 3U׶6/w IĜ$20\RiVVPfØ|.4ܽe:ƒVh3" Aa7*n>Xj*Հ n탚jAD_i32GLjX%k\cԫ,4zяvoUuhH24MZO0ѺE6Vz00za}«e5[v\7ʥ> [cV?{6>vim߬W^ jRR՝Z#cիNn4t $0퓧%s37g υBHDW e8 %LagmswXnNN@ |! $f%Z'a$YCH]Yz ʍ%bdR|0;7&xDj4k=$ /F$? NCzF0cVsbgjC/Ɨ_W<RfB8ع̈́?yՃzzjThk^9=>Ɋֲ:hf2WilJ:ZJ|%hcݺמ<y?GWThr}Gj,M727`ZXg 89 + ή3n-}fZEA9n#mvSxMe|v-Z+d:T҈`^>CN%q6";Ҥ]9bE*H,TK<%K3gH7n ;* n ;&G/T.{;Դͼ쟊oˇߠFG~gA & L1?Law WH) '+ ف@SC$6{y,ɜ{l.z5=A6Ȩ+LUJ18kU%>J~-Hjg {c`흁ΥHo:N Iebq=ۑΨ%[yrbP$̻Rzoدp2`If5NjF`Kq(I$)Z.?1Yv#Ճ@!#l*MW"a;-8=mu~l^r eaqcַuؔ*Ost9xpׅ*cgN}ږs;PKD0-0 7˵B[D]fBVuåu8mQɿQpFrW sC"c7K"]Ap(Qѧ^~Zz, CQ{)6ZԆ:3 \WI i0Z]^UX-?PQBe9tp[ ` MĿ_7N|H4ėݽ1,f!4&Kpus-rF$Tj{F3Gep@Zz /%)Ldx @ߚUl =}x?6iK-`!6IXS }YqiB?nbF&L;FVId՟`B2rkB:ߗ9R3޹ h1*R=81".^> 3@uBDh?V| :1CP୦A aJ]ژaFyPh`$fq^tu`C˺A4T=܏(b'"6=D:^<0&Dʘ2hW:1R{ٖvNFUi&f;ݛU /zrc #dePg %B-B|QpRGsV",d䲘X{EgU7uL>Z7,T)n9PNpQ&ǚm+QNÒWA m3 GdHqٍ,RCJ| d) W0ŁhZ_N=]e! (-?mT=fSB56r<Բ|ԩe2 v~1dnoI*F_Yi/X_Mcwet.^՘>bk1/2b]{eWo}nxꬰ9|WkS3 3 +[L"F+93t"6wl@RFW}t/m,{^)+R}Cš/}r8.A*UkhQE³Zc;Q :`L ޒ] a%tƎ 1N%D{({r߳:ۭ(5REƨ'}u&σfߵG__$DX4uk!oV!jq–uoe;.}/3 )1no;.9Y"Ѕ 3s&5,-G?* haLaFC'vPhYdvu2n`4ނ:}ΥpuklUsyHOlUN%t }D𹇠F:DG02:_~O"Kj!>9s|m"]GqPL!"7; u?|Sqv|j37{NGP0o #p2W~r]~nL. %jQ#P}K*lk0,Aza{̫%=}s{b"Ћ;wRN᜾y\Zҽ>JO9T$i?nL?ߪ(;htulhQQKx8un,5̭7 񂁾8NO7T o10 3\Zzrud`2UEwА>A XAj $CyLSke?Sj.)`# WRj[;H{m]`t]nμU01tjI'U5 &$ΰ@KyPMqHhL(r&j.DE\S tL;uy:FԦju-i!Е%;J#0!Q8F.pʈ$bJXL:L7 uI4|eљR~xt^dVe{|WwKAztbEB;Rs\@dPA\؄"f >oL|sh>sGD0U"S0ʨEW]-ܬ1J$haTs]=tc{3^(1:\qetFηO8g$8gA-r XSG5I4>WL{-hta~Y&uH+ĻhZp+eXȜ61 G5GHH)S kcFl&-~y&wW$ 1#ZN$@e9+ߟ) W<@]`׍IlV<&)*D7Tc@tP/ %"=6`1OKawq]{ r"|cMR:P-p\4{ֹZZ|@z_ /noJP] 3}A&nR/ s`;4a@䱽kKm"-4-S2Bi| - 3^vAp_QLNʏ +)ٞ7p߁lCf)k $m RޅcIM-^ȋ0#SN7Rf:e|EH\{u릹rW>>ܽk2xG]1FGY٠FDx i H36j~!hb&6")P!a&N|^$7y `x|'+Cq8;lԽgN ]?3yY1c߭ $aAd"~y7+~BHw[lJX뜶A(X My_#a$x߸xdhqͪAԓ\;-jߗ "Tl64T[Bʎ>l#x` a%5 uU1/Xks{b)Vz s*`K#r3`g\s3!S &/vh4̐ n*6 r` yL.zfDP)$fэs/-U7˹u7qѮQn5C9-6>Q{b(4WLъ% $G=Uk_VpYSгs"qXk#SrK xk!ԬoՄP_qXXb[\>]c/S{`@' -Ҡ&mJTh{"ӽAnxo:.>^g$f+n]-HދnouH}4mbҢO-̊kq2In_r `0BwNߊȁTv-=hتLԅw@ w˙kRq@q3za!)%#–N^3! wQ@G/ۆ㩌JV̹cks'^/G/ NH++p-zL5͖ ٰ:yWQVP!*y<\̧HӓH2@鸐|#A@R rMIho/JV5OSg]qVfj' tlsdaA=Em BL8Җ?+I}}Pڔ!.MoF(P֓ZX< &:hfoy!@1k`EP]:QKnD٠GbgN"ZMSsh ~aqK./< g렙ۖN?ޤaK;3(dcw\}1w̠O{+W8qqmlY+ك&wԾ'e)L`5)ɲ[%m&$#& }{%JjT`,{ahv]@kO).xߺ^]$UTurvJom-_1C]X~ J͚W¶eg} ܩ؅̠EGKpٖ✯Ekť;>ZINzv0/!`SM֌$X9oh3Pրrj8\6U%TegsAUv/R1crp|WΔ4T fdy O 2jM+X𚩺/QNˈV}]sE/U5|>cvF G˫ +JPf<7Rh175r޸"# jCa@;z44+o {O߄<`sj9s3D7.#w*𵻈aӗ̵^ AKWyV\^}^I풫 Oi;B@uA3Ρ f*oO7dS#PL *޺LZuS $&'y_'+1pU]+Vewc"]4?XM}C6~7ɐV>݅H{)fvN6=~3ڹ\ 0{B 3KzW4ȔSx'_xFGq4K85c8lڅu9@m 7TBebʙ_ Xac ASK]7F[rKjhz%Ct5TD#Nre[}6dP.J ͖#=T DR2 ExѼ*v&ĊYI'CNNp@Kfŧ}t!ݹٽG/9 VN!Jir ͔0pJ7lhmaJBS_ M9٪xk2]dM=? /?[ZW(ƘdϨ9+X{=U6[i߷a7@MV&SRD cǴrEW 7'S ,e4S*0}YW*ù֟+Uq`׵Ԧw.?a:I)LWP^\B'}A޽؋*8.ÕRx}Gjߧ˕CiD*Sܵ0q}f)𒴎1c6anj06T咘+DҿPG*ߖM(6^|Y-uqZMa7vn Y}lp&/2/_'o/h IՈ'zVZT,KUEKՓB5Yf Tv1¾12i2 t[z03uX; AJ`3Fba*h&x=38َrXm XP^b4εHkC] Rٕ7^G|E eK[ԅI諮_zMޯ%I8H:, _G%<ޚө%m$kS*Λh ,eq ` ph[fŤxRQ;S((撕I<0D&{d I0˰PvE/1*Rc찌i^qSfi9p-?<<ԕSrUostA)jY~A*Ndiuz߼`r#wWqٗd7 y3_jr-j`xJ0)yFMs#Gf3:W1>6ꠍNg!GfgRΣ#KPqC>#1sKs/p]k0bU/AR/khXz Gq#>8%?|IQq O*|"+H-Y,ˌ F.} 1#Sݯ1פx5Oї:,u*!MmpuWp%IT0hRԥ'gn)gX-⇑ 3hw{_X3);1^l/֘J:x[sRi~kN&mո.eK%/;:)f -+)iUC[Fq@{_AyO 9&|eٝ[$g\kվ\/.=o|a#PAa1@z}gl#ܮfB_lavP#`m2#ql\j˟. )!nڜxYJϚE\YH{!#k_᱓vab?bQG0oroRo`3gu٦Uڊc2Ǽ,N&5pS/{h*<j`7'˥b5ZRg_ΈcucrGAԤWgRf{< #0=@d-b~EP;PbջT pg,g;~JR%bf)beuJiDֺ ~4ݜn=;Y6H1f#8xfl_RHKg)92=SP p tCmqYٽ*y;JL\[eʎfnc0%Y mmF. 夔[_ѷÖoodO7El a[(z Ziʼ:~NLkKA1ӰsdS]]w4D۝PmcKMEYs;lۉ4\{F0xX+ q#!T}zgvBqj8ED1o mך^<w Pyق|8tɡH"#U wNsL#XeT tm:N+}ٝrCC#-.^t; 5 f:gvߟ&(/?bŴ2+;:utgz{atiם|SMRBPkPFbXz cؼzkS`d5U}[ 6 Q!RAk9)2ML,ZL\ Cr|J ]"3˝qIXvY^CF/ VK^yIsfFBHՐl}u=( \,E bԑ6t!SZ3t5;2/6RΤg׏jx(iZh"tҋmN<?͞F0^6 {"6<ڈ@í:D&dA7mpinDL-4B SBfZ2\zv3a9=ɞoSG7T6^^@_ 9!ꈱO;}Vߕ ? Ai66I~USMd&epx1^T%`rwܒx[:@soSxS7'+ow0D?Eg $.նun|_Tl*%yS: ^[?]T˔-4Fa۪DUUb#k]YdRZ$LKgr=tg594; $v{kت;V/A]bu JdA x0." pVU?.+?wdq`ߎPDv2s2Bj+"އ~!q#e:>[iLCH:1Y^MT<ѓ+ҺB-&^bÓhf;XNӢ'r#VJ'M~#i3$t=#93 v 2\vNH`C;3R6ĆyW!l)ed fp [MBƐ -lwy{UKF0Uޔq'f:@ fP?N'j|o|T5iBp|KqO~2H_._^xsPsF"‡mS2aM .6c p"MwD? ?x*vK?͔dfo]7L=feVߴt#a+;qbP!TjN#<>Ȥ¹z/آdf(8pzWve란{I/t?BQO4CSCԌZS㫜 CķX)y?e*B'ZOo?vyN`JtG2 jr4RoPlx>j#XOBtf%FȎ[{t?殷tDxf$#x6ǽ^c.C5/I췋R2kYܖ\oᦐ#[Yk;gz!et[Zel070+1'w&X$qЛ!kehXqjb1mg7a7| =_Vq;}vKۼe:QHh yw9kg{ߎpܫ,@Q:p"mCxM*@7)pRIE%97`=1sdtn^O5HbXC-aqKBl!yTPfoE0Slr?|o<3[7" #`)_^ƙ@ׯ9H EMV+-.K ᪟g^T9M(wP$EEpg3bE͐׶xEʹjxr?Qo97$궩 :5TLrMYr\K睂- h(& 'أaPQ[~mRxN߻vۙ2b[t{.D:y} <`7zLIJrzvY' :b5V};*Ru4'.x`oaNcj9cvyd[C;*|DvjLi}&|Fx_|bp)H^u ,x¯ ̼OO~Ih=(}^ek'  Ӱ]hB>1= n"@^S —dzQÿ:ۘt@ctGB 's. \3ӃK"-Qƨں׵Ts~wxM5 DoZߐ_)WCuCH zpS-'1[#f/'W{mN!"`H,8Kpj羁p=+sq§g2:~eՄwRIQBdT)X8, R}t;'ڧآMcn#;u;È2| nQ/LÅOYebE^TVZ( Y1a0&|ׯl,Y RlN uكٸ3I=BlJ2KO㲽Og]ۢAXQ MB҄#Ba vM by<_=U9F:kq:vO߳H|B`nel ^m\~uxB?Ix901Zo?F} {$DO뉙nEN2(L_aG,+ə'Lx~ŽJлc񤟝v&bl=z_-䛐{Wns 4uB,},yqc0ތxhކ@j; Js,{nj mW[3lA$u=_޼ϕeHLWD*M nVρ@Ɛcg&FyP-=vix9 t1yV.HsT'} @}6̟M}T9h.nO 3Jl;Mr(>A(`3sX>k:V{V)]:htA'cJB5tbdN(aI ^)ft`2(PmuPK\y:6e6m닷wH@1&P=F$QjzOjK@/i.5"e2֫dۭh96E[}?A$aA ihP]Y5T!4ERJ|*L@[M,vlwo<=J{+4BQ9 yVj2 ҔBjrO.єbM0?yg*~qC}Co|ϕU0i+&} &}|cy_gi|훘 oN&;@<]]`Uwţo`.lTPXJ)Z-Ò0g6eF8lw<,i+^+`Rg_/r lQiq:̧CeQ .Ǵ@;&t|ZL|R[rQ*ҾMX%My7r3?b#'\nĒXˢ\A1J!bӉDv_p1K$YS|*]gg88Brad(YBɗ|zwg?vG{qs3+ʺV^JA)MX;m`)s'o173FCS5hSu״/^k#C=EV>סv:.R{pHLgpz;0⫅֫a׫"Wޏ9(UuRBsM|9m\[."t`tNQ@oK2p奇rPEtkN&}qev?`Gjd¦ϕ@>+uLNnO5Ϭ jѪ%@xIo-c~.-|&ѮĊmvl [H,j|]bԶlMO$.Bt b{F7ladsJN͈]A:ɧj&-bXt~˚t-,]XÁ b#Wsf&miY68(Diy*WMt@`LNu~עy=7Cmr=Ll0nM[aK^$Pw["bJY._L9RcPM N0+k>*0ȸAsҪ/0C+' "@3# 3NPv ~Mjܿ`(fLm/)qh;Q_2-HF\kz(}: fwCqP I*CG[y3!Gc~.$.;KN}d1S܈__B.tsϨDO@eJ@Acʍ'7*8#s֫n' 3[2SA Z7T{El"m Aw'@e:n;TMs \)ǎ8Z=ōnC2; up ^9>q<$W0K߉*F ]0'oK8o8%kh\D wO+[2Bk!F}‡+C$Gd"EFԒ-+q#F~t`\p9o7_w9g^nXIR '©xNJC"h.N$"Okےr̶l{ 8L*RaeeA%p/ ˘ O* ףK8~ƄJ6 QJ50I@TǓ#mnTFt]& KW1io)@f1P%`,8I`\DƵ/yJ%r9;[6q($kvR^7M$TR0lU#,켏.~k>l~̍F~T408T@z3j,|1tx,e[Y鯙\%U9+ZПm`2HbH2Q d O+A|| ̀(W(BozjbCwa` aеlCD|ZuIJ]!D倸ك"5e ƞGKj6])T?/*3oQ|ʺ=!,$$ޒwc̃u/6 ->Wօp7Bn?-oOqsg0G SR1]5wf<;oٚz6^->rsDrdDTo ` 1 Fh~.לU2~VaF>U嵫pm[B@+yd%'U^cȺqz]!~siGt$O'FyHK7)k?o aetus_OwTd03[šM-H5#_Yg78ڰs$X4P~_Q Vǭ6wQy\ʞ¼j*u>XAk ޹}^V䅠δFK֪y{˳equ= @p "&N#az| ӭǺ3}rY]nؿz7Pv]IW4@*m,yTxa-X{]Zml-R@^Ć sG9 UǠA 0 _O^8C#wr̉a_T{UǽL#s=5k3h*~2T[Ʉ: ɬVX߃?&YFh69X9t>+h,Zȥq tэCDÎt#QFI1Dsa]Xi6eY^&!œ\t`&#ŒjyEz8 b\6 Kj! Z|/1CuHUp( p\-~/տ-.B3 Frg-U[TA踰{Mn jgUwOّ(!뺯Sw_!݉?ؘ|#2R[ҬEa <ߛꖝMUḀ7 7N1؎D~u.8\d^>vK,,T P#'I]%rF7rV#V1RG;7O6xjbØ^/qX3vdل"QWTӏ=1y sЍ`wgJ*B^4#pdA!5 xrb"^Gmo9ӹr5{+=]Cׁ *p/5S@ Y 1 t4{:>9 C*@r K("%B#4|`CHboҧ3SRCGm:6BEeQlytFzDlϫWGށ9-fs~8Y{ODGsֽ_LoGVuIxwS Xe!>/ ɆˉRMh|`xʢ.0/W/I C>e+:`sRt 3׫ g*gAvDӟU߇)n` S) $TF>ʼn&P "u0WHkΖHUz1nKq 7RiRQR,CA8U7Vh=3]ctAma*Hnqr58}>0i=H[:iLܗ>z :X(hlyGvT =!)0ERc?9R 2r^B5JcGhn 6HOq [zw-s@CH&%7P3!e>S;VGFmgbYBVpMm$_!ΟuI%7&sl3$9:`Sr*ϘF=lC~#,39Q:׋N֌=E1 kSۓ4CqH -<+ז ~?.]&HMg 篶s}}y.4Ag2fcY'm'AKڲj~iOݎN;MWzJ絬WA?]"|n)sѾuR1R=EkGZ"x]s*J=sͩL.yi⦧R~B.(̝֯VQ6eHK 3&@ /H2mjM"$jU D ?㾝Š[ x.Pn lCp1;JJɯnq ml# Ww A59(nlT:3 I=hV>Iudf͖67e*12=)՝+TN#Gv2THr43g+mMLgtEL>rah&O(;@4 .r[w`>dΆ< y45*G廲'j,vyY‹:QJra"`3 At8J9i[,&[5Gj^!"o|^}gdתi;EYKQ]83FY_!>M-Kpqz $,phCon Nuէ&w)1) 2>zC*_::R0P0023t9Өx lS . ؝m~Vsw'4E4s+mwEM$c/$8ې+눮ssoQ;{—dl%28mG 54Y? ,j8+ҖKdRg Ξ{qkB;}D7&,;`]նO8֙T^E ۴olrWq5~KԍRπ@M/'ل7H{\2w E,'mj b9^+_c-I(]u^*:$oP=ִG@|"vVT+1s5>AtklV!%c=@e'Jj~7q8QX ) ѳF-o:Ԣ`Vn>ēm' i *6;WC#uXǭO3E3+]UL, 8XjJ_-YQJ~B;Ur=Юn *Gv]*xsi,2?OeX [.kIc} 1\ÐOB^=U?d@}yeZWw*%;/uaG)aw%X=5/Ot. !Ŷ]"; I^ B&~ï p* YD$ѥ:0Wm{+KZMQ~}7d[a!qR15̌bhCg5 x:e wI(~^_RE>9']w&aL%ƒ]^tШ!CT/Q?;g1=E 7!7U 6$b 2O8à ljG@Ks7W%#ۙWx}x)M)E#AvSC?q'm~~%/ TέzF$uϒ»c]6"Qra͏(T"Y!a,HGwhe"H;Y\,&Փ:҃6v4OăDu1IڜLg[< <΢n^윉TD) P_Ilrc^,DS8&]SN#3EaC r* 9U]zUr?Wcj#΃ *8+t; yXz4K{c Ĕu!K0蒴3^E{v*ɼ b  vVMÐO޹H\Q B]oR>*w Ydo/ V.K[Gh2Yv#~N2nMpGhy&$WROpik qqys`YO"14Sx^j 3 ^!݆08 ;j*a8m,cbj485G`Bah瀴 LN9  SFHTLT6`"BI,XV6NU0r((t;o`>pY:5Ie[KCGmvn!fPGZRU( 4kMˋy{&3v,@A^`^4>#c^E/׋q>[,J yG]pyx@%Dr02v=8`qFl+gWqADJn `d`KDZ_15 m@g Tʩ<ބuz:8qJ/b2Pqo MWßBVTl!T?rD.)T=jsha=?;'_=RJQ+@K~潵4{CY- __x~o^7* y!H꣪r; VY#&[JRB<5luD, 6vB;k$+̕ԫ̬D(}<݉;-%.A@Mp<םNFiRp3tZE\z1_vFԻ ssyJ!p9Sap._=ecK6E.;>᷅m&jIIxj sp ~"m!"rRYx[E6|Yz%$=֋IZeˠD*UGz7G8C;\p6Wd% Ή<] ҰT;+p%[=TrK 1O`-}7d}]z_!~Õw&Ez0IBiҖ[P7ZA_ ?B `ڑ~ |NjA}N6?8Aʰ;E;g4bbwR.\frNr'=~Q08qV]RcrO᛬aOHP¯RWnX>47$M{Eڗni=B8sȱ轃0LB*JCK(p?睟m 9&eyKWP7u:K6.n}9gN׎3GtcT.#n_=]M5mT~{|?SťzMҙ2h^bQ13mco6GC2,B˯MW '-7r[X?tLiQ^NrE> seMRGHrUMc H.&w#NO31Orޟu7w 9SVɂz'G=/nѮ҇nϪz|;‡[.f*}g]<[M3S7-څ$ 'ʬBǐA:;rtn-_[*x9%1W*/Ui:Sֽl}] ;#$$tL#|6ΐ YIz $ZgByS<- k j`l#%J) 346(OblmAF*(CƲf4(L$Y- hѪ|5Qw7 W@i1ʲLao!WzWƵ0IbۆC~cynn sЭ> "Јqƚ.M6Sf>ڲq+5&;uw|H/b"^$\vA?SxShKTuZ#[fc2,= y6ĽJm_֡R <277U,[5ߠZ܋ʩyR7ywg4^@yl4ב(.+34MgC؆y h5ȳc!IGcgQEѨ']o- # |z0vX}Ae!6V|:{m,Y:o /,閞dg!T7mj.(wƢ>MKF7uwWXtJTlq)J(c;3mbSg+U$G3 i֠0BǫЍě"NgRМ`͍LzhmSdIPykCRWD=,IxO{pPwQlV4xme2@npcF YC));NQKТІWӿC4W}Pc#k?!8TPsr0>i\^d`T)һK/Lw,"f"V.L^S? J-7u`OkB !ʳD f< %CQݰ+ҞH0Kv ȂWN5̗[5Tl@IљaH+`87jmh^tZ=z5kW_Txr1F]oOJnn+^W#D>W*LnB-?qKi)Н~ e3" D_vV4;IȑVGS|O%QߓtC+VVP6WCGmeW*X Q+ǛDP)q7 N&2Z\y<ܚXS|i0٬xދJ,?3=!2v{Ű٣k,c}Zثp0Z*u*NAw VmIGr_EQB$EiqH((d| NR7-r&vq찉npib&WZ* Q5_(Jr|_Cd':1p0:^#w9AodۊN>J\/{/}4gY~Z *D-3S!9@cWbQ( cNB٨2i{n\fALnD;RUO݆u|{WB;}{I/ mcBb"qBmuCM^j. JzFz^\r*ܟ?'zb 6LBߝ$+_ &21SۆmPGSuIwH{~G짧#IE .#d083n1'O8EDho-ȤJ2Y͵"x:Q)tP. geLԉU[U5ebE !-9,_1Pnlh( (A#)jp/6>jZRkSO>Rv@6t+ӽ%DFA9/"1FWݴ/`[uԌ$(B7E`DPヿv27%G6SL۴K6zaSV.n2Y+[(7}7UJ[eF\̈l65F1KwΌ*.2!@yEHjVDVS]]O\r2Cѭ֤`'C\c Sq)s8 Ф% >bʖ/@="!ixwJ%f=8Bn ]2/X ,l6 xi| }چO&fEt}ҌnhhRJ貣fՊ䛟 QأFN|cɜxJ=+n&KR@Vu657ŪO + CT2=(G`c-}7T ݿ%u4+˕loBZk%!]'ß| wX61U TcAwhf$BEĜP!o=j2%5qTeIPy:Mǽ7#cJ@{=z],ax$HGh} 8&' ʱ%잍6}{oƷA?,2kY;ߜː(t* MkTs/DaÖ 2&UԠ._`aۤv 2՛Tx5'Zz' |{89^p0QJr 6(\yh=I +mkRh`c5~#i %ks@D)A1.ٕL]A(6u{a7׬Xg}dj*q5埀 6|7[euNA=5̄ոjpֱ$$כ?yI&y&M/BN7;OpBҩŁQvTYd|=S=(DG-=䚉Ulɹ7006V\K-Q;uM1gmV8í>&Y-s!M8lپWtPd z< >]*gl[f&b/*r$0Sdz+= IxΪ7LYJ%3e-ʧ+{)ktU]5j~ <\VJk@}=\({&ɗ{s+urՁ7B)[ښjEg:l={W]w2,}&uI|fac$ץ͏4vtG; =p4` ]Wf]r,EIi`0a <_z99=a-T(S)9*I&I+OFJ uhwI .8|( MQKCyu@SR60K!m\܋HF#T[AVGX8Xb^zǍ(HR©`ƫ΃5|hGЈUFId)ۢ׽ʸe>Qen6"&L0 clXE(J:`ʰ)gC3ݶ\rߥZCZZxU-}H[qa? E#*~5Wթ]|DWJ.= S (YOž%8 U9}hݙ䩶KxwJj]LVίoBtHhyDP\e& '3͈O0<$Fɏ Q1>v 6 `8Ll#킠!wu0E A%Y-'|U.Fne;$+*B[;SGy}s[$nGs#X6;<]J'g0Ts6V^޼Ȁ#`loSվflQ[ "wc9+i5 ,n?(*vQ[Uͣ ܂MRy-^+2*V^`3 l`A0_BƂqn̈|' l.Wױ#CCWw޺`B:JB}u{C`\d@8o xר,q3hHuxIǐKQ2 $83el^e 向M{-G o78Ԁ7H6kc_cKE)y?R@=?>vsK&;c?}3q!A"μ]+aOr@syh$5 ~XciOc w`]e6˚7 ); oJ8c2ۂ .Iqy+RBk3;~xHf%Hkg<"=_{c1C%87= "ϚjhО\"3 uPiG"Go0O~?00A /{ԺȚ QHVk@M!4:lUE`8 &x%g@}*±}Bj9a\֩N>^0VF#x>9{ WA?8/)A}ӕ]e%БҴMiL*5k(+w.#:м$S,!}ħPzeEn?>"~QjR}񳈜räOuR~xSK&;DljJj݂%{ >lǡWm+ |jAj<(M//}ުFE L0d19.0h*ˎO^oHQӝ5\ݳ_e1 I4>q MVo.n g~el+=CV Aiʷc*ud඄,1i !y mɱ7(w]V08sX@~\KС@MÃ23oUzߝU%ݐ;T? 6X0L+X\߾Ij^4(ȬXOiDheYjwȖ?%)4c_IpB Ҍfa߹ C14 p^߄e|n7%D+UpqT?Es ~G`S5xbhwxۼ8_s>D5ϧ&G 䡺Th̻^FĹFdEvF7'{HR46 24C w&}F@ՕnȍuU# Š#`]rG5p;>"_aik0^ FF ].l3+]Oi+`uTi2[:Ą朧|moXRTgr GxF$Hm=o/H.-0}rH+I`FVT9qC[Hܪ2~jRèE_EMt@ ɜqd5 P1TGi_>GG .|%B(Es\_!q#Á#NDCg9LQL<jVƳx{}qQWi~HǶ( Ka}%}+W\X2UuAxP,&HVY<6TXބ )N6Gex=}| ڀQ,`>QHÞ{D 9mQݸ{Y,vC`-Z_7wFC<"F% u,/{u?B,fҬ:܁ ^ ~1\P/DD)^?Ep9Ft2?E;c29+S%FUG\|E%S6eSLv:+̄O֨\c ka.f&ߊP\Z3LN4Dstd>[=18*PW 3;X%-lpO= :}}IKT썣jZ>5$Q6Y6Rx#m71T=Ì{O9K0lk< %6 F2Ւpc5߰}Ow cu103{3.uvP3 H+!W91' o{zS*8.$*5#" rZ]S_ES1q2 VwSwUjyy8}_=?7fW@A38ӽDlS{6޾ְhFamT/̟D(02(ȩG2=I+K-__Niw+9M Us$Yi%A0h_Mm 5~؏qAUyh{Yy4庥LکUJ$'u-br}Č.ˢJW;D<*ғX<T7i2K,M:%B!~4d{~tDQw 78Q S҄[:o/Nu\\'9JyIӴ3L ,:u׵NQO-S+v [8Zr48&flJp!V=dj#pW 4 іحL+:q%Kb=ؘq(]9RW3)3Z?vvgQdb6*ɕE8P/}2"g5OXoNC8b}mёۭ^T͗0(W(#_dx>묀!~4݈^[hYuG!𚝍`Z/q{|e`@'/EHRJ+uب.]xpO}47VPD6*qV ]!\v qje$?m=][Uy ~!JeAʼE`Dv+I ]a<,imrԬY<׎Ab;pc>h#2R {"JU Iwmߢ pս>97e* Dާ-GT.DJBbArjo͜})nM*Ȃ|;|[xSH\V " Q.?$+,U+씄C[FoI_ow7[eD^ ڷmxdjXe.'s+М_pIKgE8\%؃za ņ5=HFTH lRgX/#9[2Ŧ@I߆ۗ@/>r>ZRO-tcͧJ[¸OB$L.Tx6ULh60d%sx)"$[b׳La0[ rVfR\l2l}-P̴h; 6¶Eltg/X6׬5yv¬&Pa[>9WE$i,z$>sUz)ح7M-@rQFK6QC]$#5w֝@;sp_zW ~@߾̨\?(-\Y32ո:O7|,ՆvK#4r>d:o p5r*>9%5mraufUG',:j-NL7C/B-{"LV-5mѿ/&[q/qCt q`rb3C![!)o[8kURto=C)cMv8LK-V* t^WA.*:ڼ;&qAլ|x3MgACZ [59FJTTB@?;LW|}_]A&aEpd\CMtfG;vq9 KKb3^I!ϖ'^ol2[T}rJYOʟ6)1<-YcKllpxzSo'Ro'L:c ƣNm +bk^/=mCi+90V^!%ld, v T|cׂB~܂f RmzjDF(XsS"F us]&, z!zb+ez2-_0 u+=7GgL; }*YVg l{WB:⮰G֢/ՋgاKzQ@%86VX졘o@[ t?!b=u;-߷THbG|~(MCtȫ!L:yh4u̵k8Tŕ>44t`!:?ρƐw)(#ioۅ8MG0z?<Ð_e^'qx~i)ٗw1E8h4.h|v: lP) e1T]pk5 صo# c'=, 0ݏ' l`U ˟m*]4{竇d%gpzdeUj^p oAY(z;Ad8"% }6נ>@qߒZby2TfCPh,VLq15gr_+h̊YD3~yWoQ@kIQ/j%8IV,UG+k9KP)ܵGY#G.XN\Up"3yA#͒l[4KѦRR]`3tino+[{& '^m 9omV%UjjS~][f8%k@ +&0M{' NaVLIc ?yNgmc/ҽ3o:P*|,޵/6M<?|;1˙iL^.޻_,ۺQ(%B+%[v`:+7dz_Um6k|E ib 8 U)_"8MǾ \MgΚ,KA\F`"2 |9_0Gm X*θ"7W}>hhuf4ok~'p3E>rF 1XKW=w?QӦSlIb.Ű^>*"}Bog*|* B bYnigÐLa"vl̕/` 3ɎCB1#QAe-oNApI#2`@Ϊv 36 8AGE<<jP9#*i3])J)#Q0/yLʽU׶7n?j-z(`U+gU uf]2[abd\ ~7ĕˌ*rRw{{7\`jÆjƙG2GV*+oڽ䌽/GKߌ:J2}Gh qU:5 ѵ.C< \ZXOq!vOhڼ%0LìڇkjPBß`:z77$@aRi e\P %GCGIIF&H*%Vs=:R1h|Zjd+EiT),gKr0VsIlR\]e}3޸Âuw)ecXMHv.RGsM!U?s`?vᶥ ՖL!"1 vWXEEYbr!3>AabA&3IFBn5=kzS>4dF)2I3cФG1 <Хl*!]Pd^p :+gۚvD҄UNDnD\{.XwD+.yxò<b=Hc0_G#e=c ZQСoTB{39FD}I90gaۭet/dJ ϘBƜ 8C_q ;^n7h%Uh+tV13/i䟆ɳ.p eh~3%!"5D}FX+1 ۹*ǝ>i@g(ؓ(Sv>Z+{ UZB\ܰ=OBUMv%i$mU@)bCCLE9@X9>(K%+CS*w2L/ NwP1BL_&Σw;N@Rh &GtJ9"J=E܌k({Eȵ紝oN)D У4&6B3H`[BǢh7xk1 q!z Gp$(5gPU ҙzy>iˁ )[(PbwM(`S)F"kq o(q} S]'?J[ myyY]KV'4 8 TV9JK&5I%8h?&s|\uZ'aG^t@!T}jeq$ǚ4|"~I}ƑCb4 3L%Oɜ\ a-UV3ʡz92t)nV9Єxe. +/ p%||d50cDr\񇃙jlM{(O2۬by8~Fwtx)b#s*sX5*X & > OX4_ddKO-(,صl Ŝ,{zeX`%VDp6^gO{>? n65+)XlG MV>|נ yg7Ik ;/>I94 VeeY(.I|7޷2%gf '`7XAyS(ǒ($Q[gue !!*Q4"0::'&;1qxDGR~gL#KD"t Qj>!왋0b/3MDz˰ͱmD_'Kծ֣]ʾoފ*`yo=94p/ʫ+[ 'scJd |'@b+UITdf ]ɑ%`ui-Bzd*{嫃gmi;u/cbNNu~nʖD㛯YeP6fQ>щEZ9ccڿF>$;jmI]AJ1dd=pҎZ(Ƨވ~]I\H;%˫7}>,1[z83}s }䀮Q.g3a>ikԃa\jXݘ_A Qئ8;ug2@:;L0}){r&܁ &O1>~/X y;cDEFdU"·]R65;N\1ۧAB,~UlLonTyAd!pN.:یf)sFV|[#uV ϔˑ4:ݜL}-x~FmKo ϫjFfٵT=`f{c{uk)!Oo <\\%|,%ZW^Mi$.Zpi>:;ykj*7Y!-=$H!>99 @)vo"B?lm~ G ^hIWo/mO4#8s"5N> TW$gWB[`n:ѧq]hn3LqZ?ʒAjm=`o6 wiRS3m4&(L 63Vi2Xv6UhLvh&_)4E @hBat1yi",ZAfemAk2+g*ItJςTOWB,_x!hjf*CGzHo&7W4͔rY|pΦ?cٻ }~r%!QkjY_ݟb]irח-[M]Q68d[ eINfof_)95kK43ѺR#ea е]hδ}Gdc]1uOxԈ2Q1J\0[E\r}:h1!PTQЉ(&FAF=b&(fckJw# bF*j%p]֟'bVbSDDH1L.!H;Pij*jNi{r2pAQnj!e8_/AB z|`b,YKRvSnΝ쁴ml0H YD`jHp!R!MQA1.G+&dđZpCjVƈ.L=LG{Lq{ 8,^ΐՠ}u $2YD`fg{eEfʮuo6u_K_RMˠ;#AO2eۥHmjCxJݳEŮ7 *fZ" &0h?[_I7S],euvY" {̵rZ|Dw*cNtp@5SF?*j C|Yku(%H< g.PbEZM=B5O徾"SdwѰ9eiH%$NW(koƙҗAra߹ӏK}/sX{À0A$O@y]€V}=k rvS\jr ;WO~j pS FˇaPJE \>mdR,r{(~>X7IOed!{>ob}.m}#\9w˯uFû{v]kھZQ.םiTO`A*Ԅ˳9y'U 5yJo2o:hgHp_ɆHÐRZE6 -hQ2@Qxpb)f"6F(ԅ\oaVvGTeM44Vw 8D1$. k~,.tu6BpKTFŒxx7[Co,1l )qʽ \\gt_XּMKg? S{ͥiPCA]3/>q N{K%e1 W aZC/}|?0t\i?Rd2^T^ gu\W4;9B|[dw馹}~tl9)3|ˎMZ뢘=snq.SĄT̅~ W2^V-1µX\ѸS䚏(Oqd1Kp?^7b`6즠R gRm&34M 뻀bp(|Kb}unEVٖHV[N '5SthPt>aSmÓSn9Ϡ<1$$֞(+=pw7K=!U2xtPf#lHêE|iBk7ǮGrMûcxJt`&p{E VLVsV#Q]o)S\.N RY$!GdRLmbIi_ Si:?"\(^ :nT h.fbٲioHW&e^؅v$+cQtX691aڽ^gP?I$M+o?vj!t GX_zaׅtLeVIc[6'`,̠#B8'.85癹Ieɿ:%KI-O;+IݖZG|a1b*FGe!OEs^1u`;(qX5Cw*|^n%a;m5 Q N`j~,{ D3mSg T. ufq ֩ N3f(K4p"^{_ȣ`p y"!h5qpW9ВrO9n H*ތ}O L=w% S{A@x\fzdGMzXO@J99_ -IdcpYҘZ &gۛGE_Lyx].X|uۺ\7,VY;v:S6L 6:Ub>qy>*Kě ?h>݆C(RPoc1 RpgAޕd8OiLKVyƚWX%Q&5'8 )3BnhiX}HMFޙק/sq(F`}ۻhDT^͓z]w@7h`{thToq?}B~΄zy<ޟXA ORx]r  {Z;wßۺ&}ƨ7UW-Ў-X]yC1+.DXk&LkG+;[}&M[9Kƨ0{h =3YX3@Qvl:u ̆{`{S`iR".M[6csö:x|-PВ*ܙ[T'17 2)rZR<%1oTJG p.$tDW$f(B$ęFv +a^ u҂+_+j͏ܭiR5m]s-Ȼ܄?9&+`ёYP+YHJg"3#(g YTqZbEF`U-{pH/"dݷ;-LnN\N[g0 xdLwԣ2sl,viN3J39JKfd+F|y2-QqO7OuQk$,74՗S1af[`3|rY%f̃ɓy&0l+.VQOfk[z8A׽Lw#$h^O/=}QYf>>{ߤ1a.1[׬62>T(F$(!rs='oS:YeU6bEiÝWM- Q֮NH>WZ]:nJ'HN+ 7YfIxhQ~ușQ73FpcwQ _"Fx}ofFDɒd$:sy*HXg; τ!ps;WAs{0jϫf$[8BC3o_ qyVM^ ԠN NE^'=tѹ`#ș"G~išB M:P8T 47<SP: eפܦY.30##jX|ʘx\.b9>փ EG5qxd'i&ɸ7^OoBm^"=q/UJB;;y^wN` `/x=Qr0IV>f1y 5s@j_R@kF!k˲Tᤩ] 9h 'u@k>!run͏qpȏi?m\|XB. {C<-oUa,tHsbkWXeV/i+jn]e;}<9 KLsҴJF׮hqp;eIz=SjV|:d1'J!V8gI$ |[nݎ 2Y49 v|,~hY+@l_^.\B+P얒50'k/L7@jܣ5*>况8le|&JTF4 1_Rb[.v@cdŸ@"`S\Wj =r[x.I۳0:Ƙ]k ![ko?BnX@=#rbzSI@P\bտ %zXQm}@7W۹/ $h >foҮ6~ -Dpo%!Ku y VYc\s+4J62+Srm7bByGF?Qv$84|A\nXEr'}iu oTLOhU̧}CGcAE\NiaklEd'9 XhgOP9M_i]ɿ C,$ H]H XVco%\r== 1_RêϹ' qh䂫x7ѧ]aVoTTU7V)~۰uWOgQb2g\3x6Q@}*jvEZWI;yѬj7~&]9E˫#Jjxeo4wY9uJzF)LǪQ9[]%&; $b ꍈLZcB6 #d!Rv)MqU~\. dIE%S~ɞ>7A& ڸf.nS*bӁ koA/d*9`; OL44tG5X+N:5Ľx:,gYbewwϸ"ruͦzsvLYAr.>"L̤DQAs3md^RR #4>!2}џk4k39b~/_7ZEuT $|UD9ZLfMbﲂj2w9Ksd[L{0EqPN.13H |L(h41^UI fe2pDJFA*;EjQ( W")2yZnjk?U-JA01ʺf2 |g 2@@kό焪@}FI] o786=(TSa`fOh2%p:װW]x0FF,)l$Dp:Wr 3ꃺ +?(VEg3Mo*=gxWn3o;I% 4Ir4&W Mysq|儃Y!7!:6퍉 iNudEqd(`QCarq/ %o?Be6eJHݱwPL?ep!)W/M-^om,$)ٷb0AI#@z8]YddF[!ɄhnTi?aNXo܀pwIU en~ dL@d&c^}S|\J7~h>6yXW`azڄT1#<}p"ҌP[<%Z}"2$w_6 ѳkg5Z/5C{]`scʳ1C"b⨑ݵ:% 1V4)LBK0VY,{G2/ κF"<t;BrRh;AFM&HK^ׂդ+&{#(THlg%x]Uσ#"xLLQ E#>Yt$M( DD dM@.c6`;HEwPY=#8K&;Ё }h[m&YDEp5i#;:&}t _0^SyDWiQ/[v8U V*N ,֘y0,)ZFIj" $z-g |!Sof凉g(!dY_ by@VaAchw 1 mwq؍.PU:HqP|H[#aN!JEާp͖4pKYj/p?c+z,^ {X-WhQ}bZS [MwP48R]r٨ȫ J X6aq|%E%VU$ ͟y/ [W=j 6ClG]R21}FѬg:Jq.>+Vv;"ƌ1.+dzD"p:>GJ"!Z@!M89'D9p$`;w\e,[]DCږ$=kr~i#IAU@R|[OzUdeNbژ@NZ ȓHza3ey@ְ KjQ, 6 < / 3VXrX٥67?:m#j., :범,mPAƉ2DRa?WX|J$(.I$JA_ +㍃7.!;'Up'u1_COyXJ0 {}5s_T%擰Y n+.Ցb T89tYI4-+<9J qQ]`=Xl:P E;tzYz8"8e*Ed^Cnr_lEJy9M{lFP4{.kkl-qzKpIq<"GiX~-..vNR09K_R"Dmbqܿj(X;"dwB455#%"xј:~tU,~iʞC R{jNwЗ^BYHT4搳,HmҾ,^h3)Zo?;L`a >iv1)?NYz\u٬ؤFIaXlq D󩸎{A_cd`nKE?ٜR՚r1Lg8o{*/9Vx:k}W)w4 )aځVp>/wc|Ez"q$x dCE.h% |^#` $#+H6cqui rCwԲ:!`jOh@ $fb' 8] )s+R9&nN-rLMȖ7si?y."g9_h,~̀Jly4:-̿0n% t#.$dE&Vp4r (Fiq@0-sf'z޲GDiiifS deu 2Gq(*F< h!(?@:FӌPFlppFeT{]W^Ž1w9u%P`Yn|!ُEq պzwe\*LTqtO1Ly'֒xzoPB$,\||jiH*ǚ ~wX&ãMALz6|kEpwaWBhHib]gh\=">uӔhXB ѡp]~Ps}hS 8[?dAlDԢ}o0_h]C1DTx| q 7ά3P̔xLdtLJ[QбT=h ْiB r1]n, raz kVטe]& .5(Yv}Hh14=Kl0nkň9A;nםf;p&~>,I:GHH/>w=W#5#ײc֖#u(VHtke&ݒ*xr{̾TYM:IQ1wI{LӖ cAVd1hLkĪ:)OoK$"K'6ZA=e%ϏOI8yΕC߅;+sW,!M)@J"b+!š<9>G%l;+nwbd Qle R,-e zy^-r41xJ lwk\n6 yK9S,5Kz܁־vl$oimdW&V".C貨QX\B!LzXOUEva+}_K4lcMNlG clv?lϯ'|8&F6lb9< ޺#ژhmL"nO.mR8U`,ʡ$jfN÷כ9v[yC'Z9'Z %i3Y2S2>1+{ާ NgY}1>uX i4- 5*#al/v 4P aOFȮT6#_փm97[f"D]6)YSo%b,ՈscWvS$^ ]9W8oC־왏  < #V6Q%=~ul<v ǝUڞ:|hNx1z =Hc?/Rkuo[0c5nǼnU-*Owÿ&%X'f-]Zqe=;歗/kewN~`=H(`Y 1KF*<6o"9m08C"Z65mdyn սׅpܯBrQĽ}u崆<1ۛ>z~ 3W Q]7P8fTX,1 I@56z~No˓1[D; /3.[Ƃ!*#Bh/Ѿ󬙮13fH=ZO)d 84h¿sst\[;͟ըi&#@ 0P&3p)a7vsMZ(rאȚa_-_\R“t.FOĄT;*lKHA OU5`?cU6o /*c(eן% F9E =kuRG `Gɍsa6Ȑn$5- siҫ!99US:7q>IΛĵ ȠurD8bliђ{=Se_+Y/?Gy1lP<Ɣd96Itf #:Pμޞ1I,X=㴾`ė4I?7nϖeYRin~P9SdV柕[Q 6+Y 18;].AY~M^ g0W3P,pFn"upx }蟤/>_Ih}15Z%?24"(bY 5lX劘'bwg'̾:-)Ʊ5>ɂA%fc}Neg$䇽E41T}WbqZǃLyG0" qz%jH`n? 1aygU>## $%u"BF'\}%yN3.l+L1VeLi4: y dbtoXU(?Ƀ{Q0z!W14&`@]"SגyHyr= Fs %ݩ3B&pG˂j&y8:8ɋ _*l <QEa̿ p+/WQ*&%Egs@\.EwPv. s`*زPa](sdz]I9@u?T1i-uS):H䔬S L4慞ThYe#"7vF/2=e8h8첩=L_5TWxL^$Du"Qz~gdZ87c}&_?MÙVaYBnu&"C`ZnGv6.QljwazMι,i?MXmCK]:vl,; eƞ+SEn5LvO UGEHw0~bچ6v hQCtvvkm<9~B2(M2(/MY]9݊O\I8W(IWf\;gUU KYYwhh2Wd`6Z1i`~{nv.ihJvbǩ͵'Wҁ@cF۴!w=‡#g]$%ל#vdEɆ74F܍s/w9霓Վe'XQ2>y2('`;y&hM"7]=,o 6)B)~DhI0{z.5ԬAmVwp0iS0xEdAB{x7k#. ^Rsa60g?2 ' P i\֜73hYNxX\q5OaEw`eCW⃤wy:/j >eˎ ")H&SpK/ړh2aot6SѹFpLS GYӫ'^W~$ ΣA>:b3(+ 6.y?Jؓ:Y4AgIѬ`.";`skR^')p\k̓9S*^WYO3L mcCDuWKMo ~0_oL HۅCq|BlkW^==2boTan]%70]/* r}D35sX1k# q8`_ɘ=3L]E^Pg('JM"0vQ7hcU*-;,U=0f$x`3o}EPY3.[ i1 &.^-~3r$E趣D}{ ?ӟJX{$Y"A u9_oO'@/&\Hӑ.|EG/ѵo3Ĺ6©_x4c.b$9%4 5P^CY fT^Ѓ OC&0&S@ӚMR$ 6tG +k3 \~Q~UF,UbIVۡDeb;rLC.n!Tu<l*Z:-?^(8W|lixex!Fh0&yr?YMl&?~9]](=|3R%&O^hR/dމ7 ũ!8夳?m/LY+]35bfN ϝ7985m/ÚY9DO sbTxL _pB8Rz)ǎ9*)Rˮ#IZJȱD&!ִ KmJ7۔ǠI.Ճ9WP`WNХ7c.(zn1qcV>4$N{i!]~Lƨ;}O5"1rLM#h-XG˚Sn/!?Q=Ԡs ^(W.lK9!W]{M{y1{JထRCFu4,<&YV]Vgx/soqk|5{l^ߟT@?Pܰ 0aG?)լ!%vs?@V'ǀCfث/5he>ʥQmn_?pjZצ8M}m0HY9Ͱʴ5D* ȢezvtS6'b3W(Z< 0ːxMF hPDKaؔqfns^J&MZI/4 9ڲ2艜K\Mbի4r.Xf }бtQ(ra-U&ף0C&12D+V8YqANĨ(S&MH U/r76V.8ns#/^/5RnYO N-35ʧUic~px2֠7r_;[eHs nؗmGY0UG<3%ٴ{:M]`Z zp3e7u5U4 FwߓK3vCGi)iXD#4Q;,2{օ> #Kl53bbN ('Iܓ\P, fRU޷ ŸL$?ă_bs~+O8:Qf?@Zo='re Ϡ4N/B=wStk@7pG5e%)4iH:!14}^>w7q6w%`(B>S}n#`uC B1~w.Y b_9!S h=;ƶvFbqdrA`+hpRiN*bg+%;ѬTH9~bF)j97IMvIH3(`4`\\RqTpH/jEr%AgebUYy19@nhNMC0/HYf5Ku[C 1,sP60Ękbb4-hQ'Twń7W32L}QS:3WVvT؅s,wܽEQ/Lkˊ8d6N+r:B:ַ=ʦ3VR"HkeW-x +ۓ \I)֝;֬83Y/^,|7ihU]ӟt zc4$Ϧ'\AEhh6΢'TՁ@)VcrKC ]KލwlB6)3,% ]|- ]GbֽRڡxkP{z>5( QXi֩!KZSh]eG;S~JT2*qNg]t brJkޣ0Bգ?yT7Sso1KcE޲[UM\|o`,VA;Eu7mH[-CX7ؐ#'N02G]<14jeœVBLwy6gN?~"DW`[IF-?9j_hf d|E>WMɎwp:u-]|LZ6P#T_q. -| eHFwՁo{M@؂A Z֊1F!d٬/@w{jg))v:o+Y&2_Sw)6Sq^]Z46{'sSh[s2Fe9,җMDcDKr)}-JXp !osJ^ݽ|;T03SƍUyXI O49W8K%o3IμztKted }8?B\'νwodafDl7 r!+%f*1@䱰1oO҃ SIEefLw<|Uh",SPY>ׂ}τevjEt(rL?^+~[Y)[-;ɥZ Xl%UXXkyWx|;% =Gz!b :F3$AFAtn}p?/l#!qQA- ϏܭAitc4#'\O2DȀ:Qk}Uj+ݕ=ulpYM$Zry szh I{ɲ|BnĤ2A4ArCvH ~i J`o.Ko %AJg9o EZA53"^!$D&.CkgFI+Hm5mKrY rpC~%qTEr3rkRXq(ع>]o|r)rb /չi,[duۚ}eĨbc)wU<џ1d ,P|k*?~5g%Yv J6ͣG=o9H+2⳹7h`-"aVwWQ ׄN?F,ںsL!}FCGbI&tePdK1.G4ihg@E 1Z{ϰ&od?%L0q3 ]NN DPϤK;w7cn+vﻭ[\L9GZn6o7ƔKcƷυXZkij(P?^dĸe5d~s+O虉zx;.wR V%6"O{HI`uY>V\, Q 4\TAsiӀ[Kh0٥b0T$q>4ԝc!uHph6$|@ ĥ!9ZQ"ws <a 7#Ń/5 t.}\aq&~.K@%γmqw{u[ܝ/lWŁ_-.UƵ\N&$ݐ۳esAFyYf= Gb[{aڮo]Vq},Ed͡)md5 i,^du%iVatݕQ?hĭC_/R$=kKV.6%(?XbH@S.׷{4f8bc0S 3qBE }R5SНP(ى X)޿w+C+P09<[,]NiJ3/|ejS)M8QJSy<?0p,0\>?9xKXwL?QFXfY+ (@C0? S$2pBdkT:!Q榃} *M"l3hVHb>9Es3: %`94Qb 4bL8o.cndS p"[#qZ,\IKrrɥh.Y0{ld玱<\Zp 4f|BwT(uNCGû<|:a@vG>ܽwWj*-coÔY)~#W_؂h޺<e}. '9+W`F̋6ȉj00I. +H"v$K> 2Q9eˠEE|ciŴ n|R <* |Jf7+LCt uJ 0h*o0fa\H.Vxurl帆g]>nQ3:5@@mn_öB$F( ~$$~8FZq3c$?Nrf,:!*=_4Qr-4NhnK,y3Hy܎;ܲn-BO8*// FiUq`Ƭ`Jxh>G!TJGvGFPʣ)aZiFRR®UG [n!幯ha~ v 3BM-&CA`3\Gȵ}*]H'6,xv}["*~~K C ~Γ[~s*_[ ~6w{IHݺ`ʘ@3XnkmFU3e9t!Tǰq5Kݩ,b1v.I*Z -쪌e\۬>C@1?2ҿW9;^}tZeM~VK_O@uuN{m;TBhzBK7N5EF32Usf*"$2=aWh|v%9]t].(hэM_j#l1G'uc!FXPui<,q}=UQdPأ]ڲflj3n[`ጏ*zZtU3ݶ¾kbUv*9o^n"18:-bu:ˋ1T{b/n4ZS{*Tr\#Eyx!A6F7=G3Ʊץia/6, 9@(&p)J@Efݚ_KtvLBҭ+1Dd3b򁷞FVb] R35V]0O=pɼ6CM9>Dob](5[σ\o8}ҞxD@8I0h2m9;~0]d'u(:;6 3 M 7 sa< C3*Wܾa[ÊzLkiE6u6Rwxo~B \@nPd0.HL: v0kͮs겋;7z]IrӬ\3ve-06O]Cw~[ɢAzp-x'NBn92&02h\7ɇ[v[ mlsnb0F6?=#e,ꁽNxpٟe5wYrD]Q^ӫ΄ RB0cpԡBL ɨ6 o&s" [bhrr"y0nJXgtCwtc},V0VzS 3&q_dG{^|%"}=o"ǹ#yFNKmEYͶrZm]=!E1\c62ذmQO^s;(0ý >DK'fC67ub[8xeīm_ P7!iЁ5:N}j2<|[#Beͧm8ag_Ѽ?-ݸ`=q&H0ޖ9h<-};Cf"p50ة[{fzD_c LZoFm5ROڜMupu^W0$Q,l~+h;)=Ȋ:7 msyw׾ .7L'I"Vui{} }mu#\!vm2!Vo.>7WtNL083BZ֖Y_aYahQ<4t>Jw\4siPԡ #قEVf!vЍNHmvwHKY$Fh0ko&b%By?O5GHuIx uP? Ooڜ)p%*o?]=600LA{wYxs%W믆+ eqջs8EL+g6L;It-pi2HuU(\uNFluAv F782]eQJwm=>pJazs^gԟy E QtU(ɛbf|V4U^N~`gڮb&1 @& *µMb{eKg`*e/5̱cD!5lKR`C6t֣KW,,ïGy# LZuyW ]u56DɲZ`aNFl8~" rl.Ņᣧ4mn R96XVQN]&D:_yWp.3[ϚґJnW8rDn`{ ^j[͛ 伢~}^X^̸vgF".cއpVT(*.&63迵>nh[Ys(}bFyFQ2&3:ҟ5nmc"U SoЀDeVlllCLaƐ 3|% :` !aو^ E#=}?n+Ve~,nިX\3Lz-&+{sx퇻WXu{lK|-l/bŰ=wkd{SQr9~mq:i!o0[6ouu]^Sv4}Q,Tα'l݉𣡳/3՗%u9/k oP5ʔjYtbs/g+?1}]նb|>9Mw'0^=֛%9oROkh1s)c_ߠ{[ ˊd"uڴQ<7]z us6~ RJ0f׮z?g{Iw?t@@}I+)DYgD䢟j q'19|_IIz(:XK`/QnfSQ `y>g({c]}\4 ~qX*܁RVx.Igi]TVo#uo/=( =3#~ XaN€$J}M#yC,k"[1G7MdT:ެA#w Uۿ3jZd ax UgKUd$KC _u̷<L<݌ϿJ%HVl>rԠw9ɇe8QFU)_-/>5-2D&/y0;yVf%H闻n3C ON(o~A:h3xfi,9퍡'M_s~'?;7v+d=!:ņ4=tz4ӰCaZ.:$><"_>̓}GA  atO}A)" XZg?2$ծn199- I~xbLHGc,3˜2Z̎ m0TlIg_Ʈks0ݖ`Z}:]$\?ڙRK>SWGncnd}"'#[Z>\]HI Pue"i?Y}/mȿ0zuՀbTmΌX|T~R־KWMvbdV^%dvC,4_ o+7yV7X,r(}UDS#-¾L, ZrxEd@5?4:JZA Iy*|q2-5Rz 66ezXycQ}dE)=k>K!p@|ݼmY\n3r0kgSI_D-'VXw! ,cLGP')v%$?FwY]:qz3}E"n΋{g`?scq1OAdx@FRbV UrqU"~HZ2 o::mD`Ov.82zb*Jfj{[,c1Dإ1@סQݺbS=YnLr/x(SZ*GC@'FzXs𠓠ndCtR*`ϧdP(P@ MZQ@^?kbV$|޳)k r~eGM t;({a=/P@󢡧09NPv.ƴb E6'd < 3 # 'pWVWAf\лI Ϲ2l_XI}U'ieǔj۟ Y) {o' V&YG߶(Ǐ|,VcUd{7I5YWgikrbꮟviмfIfVZ*6A*ՃQ#CYݢ89 'ijO F3adDۯk M<54\&pf ,=u GWMeOn Q,!KǛ SD}W%jYeTdbt.UD Y*$;"GaL^Ϟ=HiVf `E;mP"ٝ 8 'C9t3ii)y+3xi͚i-]K;P¤'GNhDr+ѝJ{[pfe(@j`@lecvP%`H%p!ndz L9hlՁ },AEw]vŦ8̓2G2K 0Qb2M?wʪ6 Џ42>O#+ gK$VѴYH$?AB_g ;d XAm-OB{Ө:Sצ%jzs༐i١ 䢫Sxk,]= 4yu/آ ߻Wqy;$-sPf%2~S(4F#m\%T,rP夻U/nE/3嚢/ReyR̢)QX\8obA}knSP60$MǂQyFR$7G:v(c]'/?*ԥr ]KHœWBrHY,l4"tQ$g{TzJz(F6"713R~s.g#cSYcMIH9ARF$C$҅}QExk #{PgHm%a3e+Qk5`}~!q9B>D|Oc>OO5L>Bĵ>+S.~Д‰ж!M=/ ԉBj`~ߡ$ :o [:mѭa-ey<4a͋9g–92#P%.(ԀXS}784<l"i&,|iX Bv9Z]·mUhF[Fk_ ;ʮI<%W&* J_nV C#&jl5ܠvOɫCx]j@uAoe/JM?ab4~?eOΆW^-0-R#-,:8G3bUG`Al *[ndC9v7 DzO(sg/ڝ5,)" #S]DvX\b̚h W#+:"$/E2 oɆf})&ʩ42B)sa3g##Sspײ!ٯ '(M*#XTMK4A.8`O{z~nyu U,)v@SGs-x|/vw6'7-}io @ TrH!jĂv?PW/E&/4cE_&Or˾2dEGŀ|Jh׺sSjB5 170sӎ 5'-7u8G4 8͟]lСܰ+@xo{j|ً3%K8$ WDl>l:K#X~q`asL2щiRwyѐT=4HBeɳFeF0sfLicai q\xO7XjH ]lٵod2'|~z;iεDᬰ.̥ @SP {,m2 L>؞(ЕM 1\2Qb[aReJC5Z!LX}fxD 3jJu=10DU6!5ujq|FcQJs?He^;GO)܉:[xQ95;N'J XfO^UA9.Nwɕ_yJ(*1pmG;EUhᓦ'F N4\y2wR*D1n_a s''Xwt˯^`˽hx.{VHKa4*MI*"Xx=_)S\%W7{SBbzf`gjVGw}cm[A˵h.#SIQ*QHv5(S^]:m@TIj~O\I#%ħ, B^ Ӓ30 *%•vUq}$Hxʻ>܏Kvi] {xֈFT̚X; j{}l%}=ْ.JOxy\a-D{\/nm4+Mٵ%-Oj[d6ysW+^=d<B&ŪKwRϖ1U.{p10޹TH&.$+MtDYLKbNߗ?B}zdCQw{ +kUZ*0e9NUtp}wTׂY G_:'dV0> <DqMeQ.[#ɼFV-؝A,=rQA(_?hw#I՚7!/F_2BBn,T5i/nAYBK9}XQfp/K}mr֋7?~RWuE V4 oOێ컲(ض׋_YTv70qm4 #kh]Bȧ.AaH" 5  rMD0ls͍"u ځz뮉.;֨`vcf/fŹ6>51'2{$CrN1:夢3/e+tiɏKN^"aEP?IkGN&SdPyHOp\C\#1Bo Pj^~JHH8~'gnyǔk.q%ڒva,xf_?3oqViK cWdhPjma@wn[dBJZZ$\!%QJXjBC̯0ѻ9m]e :O!fHz"?8 Tԥov8oslfB^(DC;WVLNIOJ>6pu'9,baݲJeѥ$2Xo>V2t#Y8y*.}di-KJnW~G2p{^T]־w}%C4Ⰶ"XD BVn"drbh뙄Υ0潠 8*&C%B"OO#ߣ{uގ9QUV=ygU2FSqqJO%$o4AʳxB= 8V~FkuT:4*SBc41D뵞TS Adq?F_ !8o7ԇg>mBR$y@|o+E ʚ9TBԲofDH8wExxS#Dl^tP4k<4&ZŪG3L[ҡcCŽ+ plvd8D͐7u?u ۽Z)iA EaZ&>lrk  UE{n^X誇?FBt }-B\'zƴ@N{W3ŠiePJRgh2reh\wvD6+B|ՖMʏ(T$;?԰JÄ+ey|I+ׅ&fI9"89IbB$k?v^TnhC&UgB?0.RcT?~dN6]*.OߐnYuUVfMp»C"2>_HTԒl/޿_ g$sk,#(Aj v.# L]'@^ZP/^U?hEF=1U=gbMXI뢶޵g1@j(8u 7@Z (hjT[ ^>XJI{!4sN=*j*0Pmh?'4xw5 dO(KnrnBHn>uKg3)\ tv/X{-9LRN&Ӣxk&jK9fm}D DcdΔ{cZk7 +MNlJ5R+< i? 9orV@ ! b[]vٕ%mɆPs 0G5#KZ- BNB[TF; *T)@ A-֒ ɲ.()ʷJh#h&$ɗ"4:}v!jy Bq.hYn<2_sDn Fk] z;άTl.qJ#$i7wۈ:\w;z`} 5zc!ϝ13 ߤJK(6P]9y4SbVQ[\ ϯ[RTI{a%]4%,:S%hs|GjrS5oFV+mq>Ғ$AC3|\(>G԰c,ժ' 8葔 0˨BTuu瑸gnZUEnxh ~j )Lzc{E} :OB= HɇϓZuKa1jE.+<8?{IځF+6<*q@Y:90yvG(ܛOZoakg^?4րw!I\gͣt:7^-\{njHup1탥zOvL`9MzCY=♔ "o){BܼpJL5o_~/w+k`4"}I6ϘܝS G}PYRLlF3x C[߆{3%˅öIe@5ѝa1BLnP , `|lMa='|ә<*,W9}u))LCvbC:@~1SeW:XsD^WmEB"s{T ${QOzGgg{5E|z8~zz>mV-"imĀCP;Ipx&w-#h(S?<1l1AJ-RCt́w1IA!7q>4j]˶\M"0v_94@a6&yO@%h<(:=+0|*zF%vbڗyYf3kio035~3{&`m,'pU8]I -w[3(,OWe*A(Kb1wHQjۑ-b]O(%UU= [ :2V3jLCΞзxζ#3&= -];V cF#Ƽ rK-ġ<;83F,e</ύҷ%Sj #̹\Bʱ'd]27"I yiJ}l6 :^MUl2zxc*]bLK2vܲT>[?޲g6߽m@]8rC<ס5:Mx8o+;{R趷 yڪ8Y2Dgr.anR@qNr$#]_*k画kA;ㅆCr\ %zStXj:Z7c#7les{,8b1W01#B&FC7r\!I}oI/}%t-ӮkJYNp Ձ>64t ̔$ aF55x?6%p2n6r("TӯX܋; 'p(WЄI2[%r6]8d= i\]-lkj*Ei$dEnOy~)"ɽoxRi51mE')'mLM9 q?kHa& R':fyFNHl96[B; jiHskIT__EWG4xer1SnUM BmT꺳"9JVUҳ/5Yl/.7`SWU] dr )f/t|u- ;m5CX:t>KB rTB}$~sH+5~x~_ذϝ݉En>+c-'S,}wz {[ozwK;9(v>vu04Vsu+=cDg 2A"s:*ZPo˩A5E:6N b˧Jt(| {cҍWxRzm*eAtDuZR9}DJO䨕_WZevoB-\9}0MNWm\~A)RH V p@+v)Nq8'xI [K;_+_hm`uVÀ  Gz#⣴cB~V]{?Jge uE`.IDKoؓ/fzQ6s D25(1Tg+ژ RFalmn of^k !(;cZDt(}:TGdqEuv\;lE;uĎԌm%ZwNS_Wˎ@ EۊgBk~ꀌ:7 efًw -lߪ%ͷ!@^VY)j Z&Ȣ7n3GV?ټ'E1|ٶ0McuI9zve(v(! # z,qsy&KN᤿\4TI{4# ?a5?'LZE 0H\TJϨ˝d/?s_-jYyА2 `7m[HFwS<8ڴ}hLG @ώJ綦3> P͔P2=")%y􇠨 .+0k|U=FK 6;I כmQ(HS"/F/(*À) }ne?-mޱ-[άSC :V,Ggv_4 ㆋM9@ .#7c޸eFDHDJ2J#/B6\"-%"t"YxQdG8 jQhdJPiiPI<2l>Mq_<ڕ= )crO|2F VsQ #BR戬T84aƪlQ{ p)>wGL B䋭鐙EVo=` -KI9vB17{?-/eJV Ƨ߯*|Ti"Fj cP3GG+SvUE+!iI0]ڕiITrfNiLPloSvz$B&ipWu} .(S{xNWب>RAguHh'd  X2Is]ΉD;Mhȍx7j -i)pZRbOh[[w E (jw76^Z4#~ .['{\ &$-:Vk<;UUX-}Y/#tdv[DmA#'<%w%'+b% qm )'-oRR(7q:R)Q%M@YPIy#kTeib@,,(W5q x;_RBMPHYO /gY45c\K@WspVEeU$XAY;tr |rv_#~ ]yWށ;sj2s[\N `^dx;/@feOUj56pXfKj}nȑkX۹2Z :B]eejA?a$r%""_-3[BeQꝉr~#[ nw;LؼP0 =`{0Z<N,%[}58ՁS_]l)Ycjg%Y\e@y.*`_crՏ,G];Ԅܲu l|-÷ `߻gdTuBU Aa-%Nrִf@kka4.h@6מl2= 9F*?M5mWQUc#v37FTvLLj)& 7#Ը&R7`]5H&wh8]r}LeԅZ|ვjrGf\tc V>dܕ?liJ ]L7'LpwSQ +]k qV4:SVSFk$L}'b/m ady{x䔱:[I2 Ay"ږZݒ5u@D'EʋZ- ;nCѪq02CB*B*o3O:#ݕ$ [yB~L,j qoÝ7))hE♥/! }Ȍ iX w%O@uTbȨUp7",8=uCm`ZIqYVu2 \J0?ZT-MQ^~9o%fxVrWm%^ ^Lb8+|pF <>NJdew=] J6448uϞjOԋW(m${ۯrڏ7& %(mְܥH]BT7DS!8UNRZ}Ce R{@CFVp9PFN9X{.-ퟖ胊" `-泩4Q|WǧPD3x$;FpKx+wޅfn]Rn^XzbO#BsbKzp<3k#_ѯEw^,K \Uh l"8엛6E,'w]{1m E¥te ac%i)WH`ۂvG=hGI~?x#t'Ch`OYXlL:t!wP2 P'ΗR"Jbrnql~b,;w}mAB 'PjxW&#= =܈ '$ONf5SITkqxJFZ`+M)8)zӟv<wqPlJWC ._."+sOd.Ki, bZsUG"EvO\mɅ X:A5I%U[(&_Ѯc KǕ;/".u:7r@(RO dDT}x4o%o }mQ= _T|ImrOh ߨ! @(V+pmXo[q dӨ :T ]I!rm"sL,]7{7D4.N%5o@r}=u->Z!}ĄQ16یLP5Cd>FG$ε3Wi*[ ($S:&oz(w̑@OTec'3JK)xrlCʩ|AGPbÄnBE@]Ǯ܁-PkxdsUw5RYUe+@2% ,R{kb?c Guw†JTD2BL_c Are,75  S 27mt8i6X1#B%./YaXRO+ xxu&b`fJI5l4nJlv٩y6ie %Za.+WӅ4oa3y`Qϳ<7!:i n~-{ʮ>f:~B)Ƌs%; #pD${afÕ-yU' ECo<ħga<< oHt{;X.)]A>-ޖ㤢C AM`2K2D<G4o^~;Ej׃O!]lTÇV'f"+h.KrQ!r:e@)(T1 d*~CD$# !IY?Ѐ!oΏo͜^2m7#՗[<:p]͂Brž5$:Ҁ4Vފ Tp}4Q~gF s$WLTČjNN+e(goiZM6%,t40w櫈"#ܐ+ #|=v%JFO5lK$OXh }8ZCWXoNځY0Xm4L$Wm  {hkpX`T>bO>`ehh虫ZOM#&+x_A H/wvp1ę^h^|>#Zp)>H{IDKR"^JAOSxc 5;=Z]m+1E ۔ݒ8[>+YgB%5{7 `C3izE*fX!c <kN8`"`%e8V\#u,]o*!`4hC!ݜ7Eϑ.8N)5-l 6%PW$SkMu_h94v' ڝLu5lSMm!^ 0gF aRg|: ]E]0' T~ ٢wNj('WŠ^oE2Fp-oB7X1=oX !7aՁAN7lԀ5R[6pp`\yR`5}("q(ِ&(ijN?Akpl%XR5'H³E%.G u-ժQZE>K/G(J`Z) )7r%9 tCm1_ B29B(mq~5h~PX( Tn~vҨm'QpH s6@Z5,l^F0 oyIՉ?/4mbg^VPtxlI>lz@U.0-r\YwAZN~yq#[ySM"$J6>e!wcyKGt'W`Qܝ?8 ᒸdAbu۪=N;nDKDo'u寥YWSE{GPNHwm6k$`kVӴ/v'JDd𖉲A7 Cz|}i5yWauZ:VrӰ!]'JlƲ xR.z6gpЅED3h^yaT/,/c>J5=QԱCfUIN3^suR4Hh,v3)ްW8|]8_Kz4uogkRko񒞱G/Gqi=I|Fj6ͽ* kzT^BxŞBİ!2D҉D N%6KYRfK9 jq(rGx]qH|W^ iya2)O%V+-?/7u@Z0 Ԡ667%e@P%℮ߑXO+{,7]IpMA0*2fdS" -Fx#M<0A.\NEatR820 A@ itoolP5 &fmuCvGhnqҾK1<'~8xIXJu6BӓN$M_ťlªۜQBTf^.q}yE?*9Ua|zѣGKi,]C34p1v 'SV8K|h==nf¤&|ar;v_IМWe% Qxy: 8\S{ 냌]f3nFCnE`(9Gڰk̃#Ƙgù' A2TNdʵBxE=*dqJoFpv_Qj'pF),w=`\ 0o9ɢJGg@K.w==9N6TzifNE<3\p/w"u^&3o9^4*A -1c]Hii+5 jJ FyQ~Xbٌub+:j>U 6[㭁}wz`C8xF'1NQ)§*B9xHjhowxy[>(hx!"RlC 7!Gզod;+8hA p4^V_*/^)0O*!cKaO;U33W\78ATzưQ s iWg7Y*v/dz%SBS,2!l{;\Q'q/OyfC6scBurX{hrBT$Cx1l/3ә%D7 $o{KӰ!Yӎ"ڕ]E*q/,\ANEG`O@+a0~e%$\jRˠ˾l*KXhF^ڊ;^eBJEE"n>&wJGڣ#9iD"FV'8y{n"x?{j?kc@\AkY4m=<⒥f2Q}?dFAX,h;htc쫹X!j8@GG8!3c˙$X! p$'#AĨ\XP)ll0ĩ$ؚ\׽G5>2aĎ:sѶͭLLXj^2D:v`R.O}plSG(>o^ ΃p"/iF{Ö|,GaWS zAƮnUO]dݐ]s81([f#ƤY }{[A7ji'wfu@-]+8fAfo䃥:ClG̛L)Jp}R+&8鼍]Tu kҴ6\hil^3F8 ^_ "h"X7~܎]@X锐LhջFnH23Kͽ=؏X%۹84ˁŏt B%NBʢ"4YQ1Ioal$"5vkL4} nݼ-#}FJEO=V?)@qpkqY$yv3lwϥU8h*D.!pVJ4N_3 .Gz&RNЯXڍ_q0镾~AqmQ^ct3ixhM!J+Lb}o-W8B+>tzCv~1qN<|.4Ƅ h#?` Cj?Բ_>05P-9K+olZy@. BhO&v &a˽#\^E B~doM Qio -fkCVo^m -Qit ?LEo#~W Sܯ:ĸq4Kp g݅%KLÊBb;2E۴CmT?L.w ,ACʁ Qc2dYͺ=4$`ӃSbw+0#G?4_|=yıq;ZR |gqU-Y'R\Hj/x<+|s#eyzR:13bPoF*By?F׹Ç^*2I-$|n?^P;m!#wYnzć}7m| ʖ1q&.jk/\tnXٕBLLU]$He׮w&;xͧbHK rh6?hBI+o݊j$˜mc}@ 7I'+sU(HE:ΉD_0"lh)ƺX.8hZ6Jk)4/i02(o:j3TW^ľ;smtٳ. nƽcc |þA4&YNC2Ъo37~Ns=F!MRS?[2૷|'M^y(2 ҹib}\f/CzSpt4Aj,ےOkڮm/VG_Lh6&bFT~F?|!->i9`X#XBQ`J߾Vq&D.^Z&dAO]D~x:zlxˆKp|d~fMAʀθ1mˤU81K1w[ +T ޜJQ8`i93 _ZYcŀۮ+O#]4#˸|{zCQ4Οن@y -D=i>TsOmvl9Ж9H_1]Ō$*+]/ #GO!!,tgϸ:Y+)Fѿ4L֒T|ӗfǂLwnnb!g.7O-س5𡑘TQE(VMg7UsDe>C1 "`}LG+$ٽqy1韉Eee: x}3f*!CQ`}[۫i?Z|W_mw1ARU39 &r^V($";"8UƀBY&V~e\?wf݌x{Jz42Ʈ998rQLK #J@`؏5i !0)zä +kR ]="Vt|À/ ~Ȑ"# qr? ^HYxwy]l ߶!miӽEG6mU (W=T ,1I+> cYN6]E 序e"<֖ eLbX}ద/HeEO|y&O) R ~,1#2P CuiG`1c?; v. \ >x?z_|m~;ZW"Kѳ׭kSc@V m&Z¤:lbK,y Vj=#{Џ}iLS<*3j+3b9CZԪ|#<"&3'Y h푳/Cn_PIηalJԽ$v@A3(K s7mil"Zdi넢0=q@$x–!u 3bIڐv?^yʵkSLc< eu;g-tnLǩ&2Ƽᕚ *{7HJ9 8QRVVIK (4t:Oz 6yQ]vsOJHaVlW[{yO_뭏sP=wNZox0 R;w[,A}lz]+^.j#t!Ȇ@ x@90ŠIKGS(G{zQ*5RQyi}~SVP|*P]YJeE(Kmq-$#*-q̏kԺ&{0)3 T -c }Z;d:Lϑ$0X}q낏EP>h&sQE >9,̾պfF$H$MsYczyW`*@&~z٧3}5믧wt4#i8(RZ뼆*J39j|q-UZY$iJ 桠EYkVE {#,}Ol]x([vc^ٲz29vyPJA. Ts\ն^[B+'NK]"R& pT8Ф WA'?YoxV{)R.ɵ=Fi(s ?S'9G*dVnmeC:/ 2J&"?o0'_թ @3y20.F3A6Qyh{ϜO̲ :b& Dƾy9Z*tl,LIxf`;^  UN4ЍrNϘ'a)B|>%SsϝߕS)+t( ]}H ;{{B̨bHQ 1X`"*m1}UK$N:2|F?×FF1y Zi_MkãQƶa} 6TbLwM"E NGbfO)U1Ͻnnmͮ K`Gp'-⻿PfMJL+T!/}#wN h`p= <-#=wnپ<98Oc*lՎ(4$u Uֿk.̍h ߓ,6U^'&lg{/0sV_-qմS.PݏrlMCA0ҼRxvʘ'! .f.vtks"HpRM?wӄv" UDg p5BSa U:D_gGi#PnKM:'ѱ*o|p-m"*&ՎɅ⺲>3_vm[r Dk@fbsq?ߍV]p2Q9,CP_ɃM| Y9L=`k d8]* Π$&̇cy0vէ$o!V [ P:wݽ-M!7I\+OVed,!bIu| 61OWȤf"P{Zm7MQW9[[ E RAn\aȞuKoàc$̎bC3.ȾQ6|}$ĆN'{=ݜjXĵ6s6Tw[NMV~:U[(TsCgDbI >4%"|$491A we xuwt|Qd@: I}lSdW-?rD:;ue7a  iҬ[fbM6~nn%,0 wU=\mƒQ9mIÅsӭDb1Y0`=El58r{a-F@R+vbHe"-'w&۽+u0laҭ_qV_{"ઃ?Q񷯧DO7TӍ&,MaS@NF̵9KGl{U!S8{r& RBn0}Feb;jRBShZ҉g'Ys2jTDY-L _z"0Ψ!rLͤyebrb3潋 K H#yĆΨ Ȱi5S]jjP(jA|-Td헣9 tkhPs/~z;Jo%ZFDDۙe)XO1=M4.Fk͌ɡAYUtg^'ĝj!](1@Z3LCs,plVrBa@ ɣX֎_!$E}\]s77?i9\=@ Enqbϡ*:[ 4VAz E.p^tߠ9́_Gų=ǦߡAp_J \Xm~+#` >YM1-ڵZ~k*f%'.9[|rfr Y"mUwߚON'RNNp]AmT;81E{L)1 sL-ב*s.wx8 J;},Tf͍9*K?E9ir}"_ܬh .w)Gv*KK`q[gf䊒i[#Ikx TMAw]EL,%9 u7dZ* vVjf.~"WJߣw'35 dnS>zoqSH`羱a5M Do`)O 5gOM|n$q`#Ib!9Aij􂦄Z.B2OY ̔k/Qdd9jq0Z |3h/9Oe<%pݘy TOyNY;9` /2Sbj*lYdDw.ddEBx0g;zq-+pփ(oޥ\z9ojnzRE<J$p -h~S?+V7v gui• kzV*@^6mN|Z[G"HrfTUڅPv6STV̹$(F1]j^^Q@).ulH)ac[y2r4vi'mşQY4 P}za9wHorQ .]Qv٬vL6fmF|{rXLv f~au8BtRYZ{B, d:f+^[[0`@|]paV/M =Q&2[vgYYwat7$QIM'Y=, "? nԽO: jV5}EўeCHl'rC ^Hy+lCPvE4(AYf\Y=E[E4Q-"K+*[Õ>!(] ~$\/|qcU\Rq[sF0B<et3" LFF*@|D[vqHoĘi푨B.- ܩhˆCM0{=U^bCa/Y6ڷo< z ߌx W,+q7tJf$QQ]ɘh(VG,&@y,ZCh'(D-nqK+؂#GބᵲΩQ{^aKH9U:\`V_TA!?KHqFZhϾ3^Nv|-W ~~N-{$Z%hd>y٘0#ΠrѬ܆ V,Q&.e+.QmhXBT"xjb)fC|QOZa4+]aPEG jM*Y3'@@38;IgWt<āNQyB1\+n/?N@wy[6c^*(VhݮbU r9uMD7RcӫzahK˕Cܱn*n}ūFNrbw3bٗ5|.s(#-_;#ܞnK,z3삄҂Wu6Zܧ¤S\o}}X~_AUT q~" rTxăD\(QE+E/$P\{*~ӟ3 f.{!9(FIMZ袠S} ϚRyk7d&r)HdEf}U zN0까)!KQ02/&nįe ot}t8NAJCT<L!S >MNe [$F+@`VgEV"wA_S_۩ƻ51khW|IbaA/`7?g822DrMЋY`O0#Y9:* ^#e@~9$sZLdv8SC+q4 Msa]2D~@zwfUK|ͧu 30 >5 Bqλ77_䔔dp$ :>hb{c|eĺ ' @ۏ2ԛ@=R[Yc+}#&8HSJE-7^~+|\sYF6 Fav3I]+sYU &1lf#sҷN-) g;lݬƖS|{[4 (#lE댢$G?J5) -jt.\иh FNVWӸtUSb Ew^xЕ%K#%kS(I dfH2$Q~YivtQ\YDxbໍکL1+ٝaP[ jB1?ARB큅?=M F?zD|zifSK3L MhcF@v@Ɛءx%r2C1p1}lF >Us+21 б  ]~eެCa$[u4]UK!`R,@V"ԗ ;66(LPJ=Y ld˚v:!M}.!pq#o,gN=eߏx4K~P mnQ߬Էl,~g .->K‚վw%e+3* &+A<>~\^YuDj$z<l g-Rr[5w*.s!$Ço}p$0I`ɒZ1 аku,-87̓58%rF&^…6iՋmb J]bt ե$~:Gk)қFtj\"UY/[d ˌ6w9,߶+k'~cW8,-!휤?e;;:RDػ,\\.fK,>5"N'Mqԏ뤤b;p.9/V/gemZ ~ GHIFo21p/M ,;:Gno;GV9DsXVb"?S>L>Q+;a_/B2j͖ag%GI.NTTOh@>ڜh.( AYBџ ~t kԫ'7k%VE4%U靈jQŸD,k>у_ C=|/B{DS3cy)Ih aT`2-+=n!=^B5kt΋ǁr%[" vz%>_Q1izMl. qƺճZQT+ֈ́ҖGDĕC"],ڛ{ԖZHcےSD7o?MТj8;lW䅜ӆ3C"B}BTsꁨIO cRvjL~PqgvSDIa5%싙}f2؋e`s c` 32ºk OA Q0 .ǐԡt5k6 zc2xqn#K4r\RͭԻaB@uoAJL1`1'.ૺը?CPls#k(>}T8]_YcPrDʲ9"g2:#+bs_wHE ryѷ Ax_^Ff`ng Ϭrׁ ci5Ԛg'KEhřT1elQyGN<3" TwwExLCfɾ"0/!ʴ:.Rq&CK2yXgY:8jv5qo0r-s!;|ƤDJ.ma!&PW.yzpzaĐ"mti%:%DwfӮKqRy:zoMB[R^J3 g:Q,0!6{n(BZ\scP R bB6XV `CA50'X'di1~^1RܳM5U8Y9Dy퐶 ϋ.F#CwJB*?0*}e']m0'5{VSC ң}hR5iu QIXIlM]tiM` O3|!5A,xS&3g9BN|Tn <$Wn>A^{85 r`{k ,Oi r4MzN4f!M.%-+o(AOMn꼂K-c"-J z5XrXㅦK;u;fg 2Dݲ (rR/\9bBӯs[ HM4\#$x=Vf8-(6|nl࿲׆*;eNP+1RtkbK6rԳIK£>bAAoa*U/7 P֐u%) ŏc&:cƒxPn>2cbi J5BV7"@-]b>o7eEO ~tbW #\KY$3Qw66m6#c{|7ND4;V*HMlWLב5+e4 o}L K[ȝMT)($2EӬ&D;2h +&P|8tȾAaw=1s|R_v~ Vƙ!|la/hg?8Tҷt=r`r|txRy:{'}DS40/?bPPMܩ\LӠ4\ڠ32CaEms_L FVsC)酹[Ü!9E3lȄAOf7AU.V\֓ 8W*nj%B\6/i^?1Rnl8p*-ΙS&ZͦƐ p>VK[ .^?t* @1曽8j093jBr9}j7CUT\\SUTX #I?NY?b0W~h $哗u4.Mm0gRܕ[<5,<5yi&j3 @u/AظEUiHhX|ItFg[Nomߤ@+֊k A3ThM!i lՌ99d!OYQr#m@eT qD.bzQ[ю(OKT?Oc8ܯxH [+ZX(8UJ lAsG[QLE>V_Hnx^ Qm3NɹgRAC[|"P-_Uy4|a}{(=CUrFSa|$cnt8^J haM!"q?:*betmO̊u˜Bҏld'01:1!vŽqdԍ }κBOO:ȵwN1hշ_5 !byGLs3,D(1ho1_})u%j<}&G>pFʹ%O ulυrl0kJoG¿s][[g~'ibx&R3!}6&SKↂM*Z+=<,[u|WqDw¿HdΒdń$Ws#)#̖wa0/_VQ&[zˊL'8n<_YV8e5&;FnIsREYI 򇸙2Y2ah;(6m*3, NV/¬vYUgn'Ս-"$\^^c)]4³e4f| nBetɉ{G0;D*:v> "I X#> )1 \n' `3!^g9CH곑h\[p,+>A@_gBv %Qج's8+KUR-R@lYV Ssr%9CNTe4g[cM;]\(NWGoEQņ\ʋӜ+Úhw-!+jU0Y̞NM^q)kh7*bĺfG! 4ؿ=kzv!TmOtд0zFYNP h;cmݒKmeM1r3k3OZFJcE!y( bN'߳>d?TՋbCHM[<;vE `DEb @]d |!wF>Úз `&qL 7 貦[6e5>)[moG |f1CL)A$nY޹P O}kV񇤋U+㎣ ř-nv#ZmԴ9}$(y9 chS#ǛF`L̀R {\) [2 n`Ȑ*pNfnK3P ֳB9-cHgd3ٓe*Z?^%K37!C9[(@FCDH͍M B+Hh.7g Wd4xh>\;ʲڴMow4 V $⺭7¬T j.-YC]s[՘eNY%;]hxB8R!-?j W,Q׸XglGG(8 ')`N%Tː?Z/HٜETxï{fӹ=p o2}y/ ӎg ??M̐1% pNlv/NJ3wOd@u;=4q6f`Oz{kh2wFEnKڪrwnqj<1~F}l]IqY)_/h%yN`StL;_IyVHD2Ww 'eP\)ЀhXlQO11Q` ̛`,,k`,l\M ~8\ /k|94 %I̖en!CHrU^R-r.#AcOts&]LK.v04- 8+9ϱ/V2PzG &>MlҹJc )D EqmLJgj5 Q--*JveIʸx/I %[q#Y oa)RNKU{u> "bou͠?<=6+8*y>jHm !e~/Պ g˗g`ZTU+ u-=&$8H^KlͲW)[fQa|C.SY5L痘!?Geulr?~XrQHe{ijiT|Bkn1 S>N8M`)[q' K_Fg"7w Rt?ʃ ɷ+OYG:@  !:wsAfg}ֻB-LfRI,$>Xv*?:Vo]w:upw|U)|Z^&iژ!o_4zSF 6\1Gk#!~'T;af&BRO78Ccq2axa}`*O]`z[;e.!3:놅Z!s_Dx|En9;dV >u%dr.*I¦>n|Z7`,,tZ{aeZ$9x]~]&nPr {rY矢'}=((0UAc|4{96.J(ʜ 1q; WZ+EktvE i$&e3] {K3%&Bk!/lj拊Xz)Z]i3[ݎ}`(*EՂU:oCKe"wN܇={l2?9qkhLw{02}BJ,D?Gkx0&^WRhMsi1Fs`$ t-3xGiɜh:CR'K0fG^ zNiUL,s iZ{< @٦fh*-x@5k;qկ 5"Slϖʁ,f KWd(dx5B{{䓂:*$|Ub=ٟ]T%>dXnHBb-&$\C&Rr_$YK3xzf8l4^&.p%v] w Ddr#-K'd p_;^3~UQHNǝfȔUY d ?Ll^rߞ:"Nk/]6:̱#mʓBnwdډi¯Gu?лX4a_w) 3}Rq趃-HxTYmh&Zu|W' 7Ep)"M_2eԈ踓`"NP8g2x叧n,jɷS j_( 2_2['I`S; Bh;N68jHr7.R 1a>MY  gDGaҷ=FO{Xf^]?]k";BK8Sw? D;%cUxdR R>LbBhA38T氱|,t069 ;H%f >wykLntϘ*`K&>B9)E9MUs+ZaA6r#9>7 z|wRp4]NwH!+NS3'D t:yqi g\09́uDYY6/2he"紛HqVߴ`}(VG܇zJuin;dc^oJ~4Z*,#2|.{(!-#B W5W}1e"fݾЗD-eu~d>SN.%qtphlى Q~lhG3ڄ](klRD,cqe k-u[Q(fG8^y[ w45/hӂJ(ygJ4DV; L&pZ>$Jт=WK ΢?0x 2;S4>ʿ3mDtEMjj:B*ʖY1l`Q(oN%h8( h< , KŔMRs"q ͡tUα-Da;kQKBf##xuCn _f LzTXA柿GlnzQZ ` $}Y[\\"!N"c9̐찣װpGwHz®D8v!1~ygrk ގZp`|u')ۑݠErc W9jUțv&!&`Mc9(%=Pqˮ%lշdD~o(ySJ6}OC*}r?Zx'ƘHjr5jl+@>uu'S(Qvy@%.qgH= _:p@0d"6!0wϕ}w/ GX! g˃ͯ{'v~D]g伝3eŸ6(Rgp./]Ƣ[y+MM^50D>v?hꖢ:+"2i{mL&{mO;B]/:K, f>lLҸ5 #W(Z=9%QG5Z- rC#JȫkAk;XxktA%[Ije h/OJ`2u3ZWp߅I>W*H}]x|Weh txBD]N9-_##yI2\z:_b} )`ɮuK>;AYS-ӛYS(0p;~.*ON薧T+|)uq^"8di&hk,ЌgBkLXu.wF:Yq~=/ Eօ+ip_LMYٴzZҤO9y,Clp ZkY:PO{IGЯ0Hj=٣^8(ϣ)D ໢}lwT9Jj > :^?p^^]yl:ΧGO.>8oe $HdH_c &hi0snX4#(<)${G`ݘ\Y.B|1ѵ;V{mCmrve75S)1޻ @ [aՈ}]q'ڂ1JIۍ|Ȫ2{)g!HXwfPv}:ZGdGͷ3/ZqOx.t4A=O«,ˌךdFȴ= Ws+Ҳ/4㸾"?AC8ć ;C3ך Jx -f,va򠗩ϙBS${9 U7w).aAu>#S덎U_y0& N)hb1q8N%Z(iTfkGK), &EB2 }JU3kKQl (zl0ID$!/*.65Կ e@gLDjoZۑxWl>(nA4_q ~YZ] 0{=`.a줵B#7n5B^PoC/J۾SO |9*13{%eD?"?ElAD ܙb ʎ>y/x1k^8ǴZלq)O=E I! ݬQ"zS%Q{ID ̈E6j9INW{YNm[sHgҴ t$>hh1BUCx #犌l?)ԡR =Z LmlG6=H_(Q]VAG5bDؕc/>v^ 8:fr=;7TAؘWߒ3>Dк}zw( L+Ћ1ѵd>$ 3\~AsEWYr"ݿmշŅZ>H#YjArv,2 ηu8` B(éU*2Px(_ ZP!O%e~EuJWn^&aK_{5qu7r2z(yۿt@FmEdd].+&7LCGXmgB1ϦsX\ɭ^\]9pqp4\z&H!b݀%Evb1s\&§Բ)s%Ί8S,j+yGe&OlzK愮*I=W¥|j\>^CJwy' R]8wZ%j4j2qQ eJfbP%Z{ȽPPU+C"aqoʂ ZGe0k 'V(*o_9̹͌LV5dWW;%W{^TxqXkx]bNӄQ%KA6otѾR ^~1z1i ?&1leRO:!Vg\2)n~{,zY6qKdb` MRR%{6շX&Hx 5`jiTh^-q ML:tzMOhdeй뫆T~WIlNMςk)2PnY c`s]CTl^pu)2 'Fw#Ojnk{<άKuvUDKM]mx_C1Te>w!%\ΒT,02B1;fܵ_A&ԵL*.e,{Pf.i^ 6|f aaeX )'[RE '+ʏI\3}&)-5B|˥̆4x5h=X3Xjn^uZ˻ B1Ʊ1lx_H 4ᔣ*~ى˸rYΌfO+\ ցJ4>uQ x^ #`7"]RDPߤ PX^@o_woRhOkQeEcLm_wYa 0vx%zzh:БĖ pQv&3Q!rdԭnI]FNL #^S**\a:PNXRyK,rNV?ƈAY_¯ƽou~̿PV`&3CLM/֝ /5'n7 ehO)`uӞ(^ e _ bGF3}0"h yKQ4{E$5 ͭfխ?X\ɀ"dShaƽ|lYil7篪|$ l7 L5R` gu?8ʒ5 /[xX $ކU0aFr|fͅ ƨu\#jуCZt2hp.{NmOc?=ڨGi.ji~"Ne\ ?6td78z0]dx/R;2\=9Ema ?pe9gfFÑl_u~P朋^ J " ]~(5eh%ULXiBEЈD}09G{~ L:_W} 5;[ۂHL絝ζ*{Ma*s5( ƻwaZ)sߧ2Zt>!"sN*?ksP, dXm_墂eWj-^cvMjl$g=/+p$7荨(Ч%8H.9YLY6^w Zs- WͶ 96ilC`#wHH}P𾥞kYJ9odm;ѳ<ϥgN!9q Qf CBn |nj(K2Oy8!+GQ_10H,jZ3<\r vD.d2j&2)AHju/9MKβ[kZf3'`eV̽P+ݍɓ}ʼnK֖QgZu>Zmrg,цfy*mvbTQ3IP73l1k1p4K۾I5Nt_e%e\K?s;j囤['IYwk=x [詰h'DT..[Cw|vL7D`vVY#`[q JtyEk0wdPQ^ɍl`7EK .Zi72}Ey]$|S.W_*jA+R0OzOh"_u'9ȸ]rp?P#&zO.,d]U\n5WA]e˖i<`iAgL2O=5|AT^SJBQcJΫ,g{OuE=3D3|U| Ig7z4ֲӐف /;lgf%%۹i. [/K<ڴ_8IRpƓԃ%5˕迱O/ .FƇXnH-CsB`^hE {{aD&ҝXѾ dB*`胚}9ڷ#klqB*V4a~:*8ֵ6)4g4! c9> %2h: A2E)"P 5u,nn^Q @ _QFqg@ x3"|ط&7M '->ɿ&-4xI H59JmkDݲ |Q*& XOzGHD7T De"`oЅWMcShª ahZ^ ZZSE"'䘕Kct7 F5 YI:TeYmw- rFyH3Qqs|dShYfdo2SϘeW$m(BOx{j-ңi .^Fgf$SgI&b;ȬjyRf i vB>f,/R|6 0*bg361a(9{?$kzz*V-L0w(}feP81)z {EvҠ&_Z/kVQ_A+q&;Dm`奒"I ~aewulƳ>lT *rn1w!l1Tg (JZK*Lg//}ii -hӺTC54%nkAH6!i$9w4z Eif$׶ixTFhjբEa;{UŊӆ>/KSbY1(3Q1Av)4Xeqk[t)~I\KVa2=;),{5XPaB> Jp%ׁy0%R ɓɖǭkj(^4?fUfn?_+1+6+@*a,t y؏˯$o #{{6T1`BuAR_%9V`s5&KBN W,ueq"Ufi,ش-EVs^|F;ˁaV{ `=Krǡp{S#2⣧^'hM?E&䨐ESQ(]5 EڵJӭ$YMD9 Y.M$ W5 mU{MIO;]}o/y޾ 튒M_.2]2i'T4\R2 U_@mϽFSЀw@$|sIՀiN+D`ie[X"6Y'=7Mܑݛ'$F5R )ԁ#: ZeVm?ivQ@vpj7Ho~wt`g Hk0g8r]{~@2]sJӇ}P0voIp_$E杦m(( ǸrUnd 'N_8`ܦ9{] */S^\\;ǁ2ia"q: Z\ Ê% lΌznITfp?PƉ 92<¹W,t#>: j9\ZqP]0/o`K:fԺ` IQ͏+}6ha)%( 5]val-9 W9q,%M;3̂>:RsD{h %Z̾F׍7 ⫗AHRS,3wVͮIAugC*%⛑b,D e=)*z-RԯD`.F@L+fN#zLs4?G]' ~4[8z"Yr"aaHuwlke ɥv>BۯBF2 |M@߭\ӷ>}/+]ڥ/Ά,]Da!TD$ Dq/R*%[%|ȇ(4,m7gu$DVȜ!W2E܈{8qQzj)p7J:u1Ff2]Q{jN dPjKZ0ݢ^W<p1GvkuіwBۈ"ӛ&fY\~5~(&^¶Fp7[j Aϯ'sw {iFh5P]l^Oc>hE'ZNm({[ /0gBEfdFg;_َCH xZe/ `Em`KOLmQ~RA,9r{#ǾLjK],dE=E*xM-F2ޓ7M^U#j%R닶>annQ"W2vStz&b]Q~RKbOZW26l)}O CtBM_n?9gStl ^uAG%fIuHY-UKg i j5JV5raU ]C=X`P z3*YRR2G 2닪"zWXc/k_ Ё%fPd@aexIg4b[QfB>g:>Hߑ"]4=DY^IGU[ }zա-U|V@7دf =fdoa[2x@' Uݍ^'Y+-+ MUa̪ Ws]o-ڸgspz/V@SSʯ*¥e,5PU֨gA7zdHtsYTlJ1`՚Y|kkJLpOqcq6t{ C?ޖf/sf$p[J3Os)ֺA9s—< 6Sf|I#c-j/si PXbVy964Ȃ8q]FNei>>U`_jG_( IKN [:OHR.g)&6(X!I(Ja TyLpk7*kI|{M~&9/#[aVA< *--"̨3w[*܍")SI0Cy=z Khb0Ü0};IЬRZh$2 x.wT4᠙4 ҽ*S2BY/bd R.sC̎2wYf=&SAQxAʌc_:"t\w%BJ.#aw93hRz9m?7pDH_qj)8F;ƍ#i~=-/ 5+O@-X7A+߈4D#-X;9MrȼdgxC,}k-fZ[ƸN]U`COdA \ΓvTwx5J1JJma݋J_ݯY Yƕe8WMW3@龄 E0|KN\^`ZPs? %dI<2!%9 _\sDc;K#$v~5!R hu?Bo=  T1cRs_.AQ'=g|&>VhYh₩ofC*ȸ_b(Bz9ȋ@*LLj[_O8d"#iߖ|ՠsGgr3Pj54+תmU.=9'Om4.ckZO 9?(/YkVSjwʓMzCpsA&Oy!4brHDz :SNR3x ,)E:+oY&Ae*S806̟./ʱq˳Ո%qq l0 v)L ' ^SJU$?.$y 7ye޸JSk:}D*SQ5\^Ü>VCs.?{*-q1YLbΆ$e$GZ63BG\8u `ۂ'60*2DZzӣ>'v.067S&~c+ PzI8[U ۟rs^N6iZ\0I7UJI-,D汎UMgOq9:SsXE; g&@d$:C*9mO-Sy)Rm mjRep$ ZO(w(l)Yn:&8t@yF(rgH(??'ŌB>͡`HezIĦ\gڄȟk\ PatItcTpُ?Pi/9PNak;zAF4dc&161"yy0nb?IM`pm%'&l>~vo b ~EHPU?Mƭ>U^5 緺X' q[jb=/éت9 )F{Y~8#XJ`*ٴe7:`SѨࣞgŃ!܂@E\*C_]ژ җulSZ`U.=Jpڢ6bCVq#K;,/"u*e`M(1n&tA_Y<#H\ozMe-Oux=qhՀ"G@ ExaXq5Y'pr7loЖ3t/Vsֽ^ }{>i\N!f+!blkNFnFM[PP[,B];bc%eE83qV)VƋ:^[QrcLL'䔅d.f(ELJ` `f Os/mwI%iOqb|.p~!p ^E>kGcHq)"WwMeDH/T[3\AϼS;{{N⽄Qz̖HhjT3VR>DOcQyh 4bG1 XE6YiP9Z^5*UԸ&vmH z^(V@K73]y5+e扟o‚ɿzOpcS05߽s)K cB7 4Cc&[Į[GAE'j- X32gN>U8vX.o#Æ6U>7* U.@?F4Q$:'ʳ@#ccئfuVJ!M,rNi~D*C5N3jr}s+ͪ}R;?è(8P-e-QarӪ ?Ut1@F?݅N,O.f[Z)giv J& ћ?2nn %Rȝڇ|$@q@XZd`dₗ_^ONgu8j#HkoVvYT=XfΫT)> PNʝ'] 1ߕ)"8t*&x[ TIEsP("xcang4Ay J/@b\0WcJ[|6T!<"1>S '~75;dC_ Ia0QEn8 + '[ijNs0;Yt9Uz< -$YҦ]yl꡺,%ɪ-tN z) F7{( >Ad% F9GC|Hp.)&*imdM|ḙ iFC!?T}]zrDY3.OuyQj q%˒i:BrM&i/:C\kf(pJ}۟$͕\Of\ z&1pke)U88? V93Sy LثJ'-5pŝc}r4=׶,$ SJXV1zN9 H%*K[1 +: ղ BA/P ׶AɃH L;ۗ8K Э)0 %T妮+:hYWm?P0e%펛Rv-X_Mhj5\_MOsj$_+}Ybx!1dgqwV] 󖞖؁Ky)ʏ¥7-aݥtA~˚Xh@_z?-?KٙfKIҕ e0JN u&bJ *T cts0WMfJT]/KNd ywWCғ\~a5 8eI<€<'-88[#yq삎\V.Ȩ$/~qNY15Q"m#7nkn9d,b,c- M=3@){nؒFi aꈀWE۶S􄴋&>5%pǾZPCnj VEo&dUD6!Xˌ}7GݯTWe\3ni'ű<X6E452ʨ{%Z#7;Tz:˲+aŒj%v*Xv> C/DFD[0n-u8OPŎ9K>XEvFwk=gNw#Mq+*W^Vsٓ3KW&XZ>&bq*,hh]ʪ 5d77E&4 Ęi^N {ʗhY9u;/S'*q`' #)-Aq^N}9FE%g!OG蝉Ԓd"I:8'eHbE~R`<~~N!*aLTⲗ\^a)S'436b2R>s?tXo6TW Rd~L5?$aVMm^sp(X3.K%p XǒU8\`=d%4 :]l+3\αqټ緋Խ ]a4yrwkrqWڨ?B2Q wbq.em*U$_Icz%NS0Z\veLT`r'r-p /Ibjst}5,v`qZOM"\q-}e4( mWP; pO%)~ P8b4,Cv{#K 1#HY o^˭v՞z{s7]AErLvv:G])mRX^9!UNQ3Xt~Rǘjl >gjl*Z53 f&P|z \ܓLC /JD}1FU xJ{<ԻfΏd7]\>fξ;LV.!|?v=WQJ]6i``!xfFm=;.e(9ĤQ̬RdnގQ0S(ʽv)ۻ\THdYW{ =8C}VM1~?򏡥8G Jo pEPjeg1> h2>%d> L#aF8h*~A= ]}ZQ7Jyl#5klfڤ{41i#Pҿ;Y$em{ 4GXyn ON2Aꟽ89-3^Ϟ-\_9<7&zRq̮ie:5/쫘@cA~BA)%Whj!uԿĭ'VWGkcx8 %|4W~Lz^e *OuIvb{]~\}a9U- XI9.nK8o#$u^ hT19'Yzhpg#ț3貱qBKXd-!_Y>HD'XWV_HOA-Vl#{)38 JMrZ!xns^)5CG?@k̷ȉn-~0Y lF PE?Bt˺ jΐuI,2dQ0}t!1CqA}`i7mbo(^@"9>;4#H 7DԳA:= Fq.DDo".((?ŕт|^债ԾT,zy}_?.g6X"A`"o;RLDxj ^}ǔ 88fQzq"? MN9w?Z6[eYzT5awՔwtDj!*i;//+`Xfl{vmW1:{PwZ fCML !F7q?7oЧ9Ӿ dG])x2XD.; E[o7< 69@:ӝ!рW3(j-Z=m@ ,8fƘI;`~ kQ߿Ph=lêJH";ppeTS~?d7E߆8W!boo0 \B&o@%1$V@ocP/!"Ѡ-dX{Q?HғA`Lژ[@,^) J|$`w1hcڼ$u6GY@&5`rL5xŽAjXSRW7yߦ;~i :Qwr/x uO̢GƸq (H5sۊ Qox\pUўgnCwD' \|Ǽ= gZAȃ[Oڤ2ߍ87w|ozT+b\_y}Ȟ*4] RÔ+ :=&?Uq.8eNqb|8 Y]w-]AoXP{w]oJ ^˟uFk~V`dZ,渚?G&O|:B.@4c6M$DqK#nd<{QqeE=gS/0cwPY8L^Eߊ us>[&lxL{V¶'+*|QžvmSfDp%5t<7sSVS>#dNKgS[6hn-$#xW1ߊt)U h䢈CXw1}m\_UtLx,\a49/\GO cj_6U.c¸-){x~˄#H<x-3"Rr̽ $+5sid83ޙAQ C#"#G~\fDpdYBW9.Z =V"u(i,2\AIJV"l 7E>tŔ}_v޹{Í%,b \ʸ/+kĆYūDU2{%QZ c jKqE兠L2X*pArD64]<FB%b2iF;dF7X6{-uu~^o/BP`2?^ihUpaA&?PG>O!svnNHf0-$a]s?AMLa@Z/15%Ql{=&4}>PI, ހ./+*U00Lh&f6,v@`nG狹s1eBNŮwaв> +rRօ`chOb3 w8 !# GXRM@Ua~:\Gր>#϶wPȲZgr=¾4o?TUU ̚$ճP$>-.(*)mb.dWH9R ]٣-]}:_-O -N`[YR3*gIMߺQʫ9Ҙ]DSvB5=y]r"m :[Ҿrj~ ܛr-7+64Ϥ)#m0X`S%*(e^{YKK MC"'W;զ4+4Ӥ?0Va!S4N^wDyɒ 6m=@Ra߈=(=@M[HVUVb VʺR|p({'Vns3 [$PΞVD+TU[ b|2k+;Ԋ$Bz2@r<>A ,[mPH!̚ޛD DZoO` fhoMXʾb-L{"/%B'Gt!aMX%qp/qKcuD2l:xg-P+\i0Rdqfu;T^^HK -3i. B8fqEVfu\Blfc!:DRl˧ҎH)7+,o6>gˁ\v p-?ZR7Z$nЩ-j2E1DkC*g@HIxȐiCtK'!F7YT,P&>|;&rz_^ _43z oC饳8eֈn Du5g(|RňTN$dz0jihjYJm;n9Է/ sL Si3\VE7]:;YÆZnd&. /r=0˿ABZI(xtnp|)X7*\=.,Ҵw"tֿ ^R*s$斷wBj.FpRhVin ´߁U& qiv7ftlѸu"Wq.⼠vs¸ڬ]8d"[{~qR41duͩᜂѸ'>b|WkHGshMZد^J5Wګ WC o7(;s4aӖ:71 ŞB)Z?gS-[O vA)րbr`"EVfzbѠGy#ϿD]\3.+*V'cڿ(:R}p]~_ˬY9+#9^bCY(V>>et<8z1aˇ*J:qgev;[sR^"GmQSTe|޹Lz=&{A$uZ[,{%MtW+߀Q@)QnLixX|ižc]J.cKJVs6i*c7g[ްa =A$K*)'?P\0k:$83[˫ƽ-uZӓЊY/s)WWIYh ƍ=J!̦٦s)ІQoXl3e~yOYoQ+S4H8x)|9Ms*HM!҅!8ہ[e5Eˢ4Q.Z pu`qe1׋xk޹4oZc DDP- a7tbT}l!ܖl ]&=E~y ]Bl^cW7 DռzqD'݊(#m,X!ET,/ntnfAƆuN;C 4FJ%wLFy ^' i&?͟?n?;96&[jfbD: xZy?[{ĉM!F i6(܊N½/n|#a[u)OYϡ:4yELQ0uxg8딶T,.nii[:ꉓju[c{Z2$Z~:>4Ng]0#_~q,R@N8ۃ}G˵uOT(Mڥi*)/0dMwL24 %ӀrL`cy=|۷`h=%R=YS y?*#-{'Ax R&%&\)pxs{"`c&ncMN7N :bYPvd>Fv}F,qt+W@.zaVW\vd.^]U-Kr5WN1qA=].\A{`X{ 4v%~20ܺ /JgWhk٣=* O rbŰ ,B:! |gH%ad&ic=>"p="w\_6h.LHRQʭLbzWQ 9)3YO$dN-g38 t[0/XGҀ榫Bd=o2b:l/(?3fby^[i` ou;cϙM}=4{^śMBx\N3j';v|RqBO!^8 [rƴYu~&7K=tpo4۹zIZ#Ffiz MD„5MI9Gq3v]Ԯ1 j`v1dض)氺丢{pOL ?6TQԁ| X u*9"aGkmL.=ub"fM5*oZrL] _=uU A¿z'zȾy*ɌF+rf+&D71Kj.ľ*7Gݍ%V`I x3#%7ۥ[`eY#!̮[  0P=2my1 ݜQ(x DMas2bF4Y"nCՁ f` <'ԌvjUBaߕ%v |AYtq:Y68 _WD *ƞU-!V41*]ޔjp9l0t"J϶T9?m<#Y-k4ڂ~VjN3cT!/eԘQsߝ* jI?Pf$Y*Ӕl/[ %iф3~fc[T=\d}xP{i;ı % X;J`/;1{̼l2;ԕ]˫sX]֡-` ETI? toGp:%k:(r vs,971eY4XGK|FQ nlm)lX9Z=j5$y]\9ASQkgHN Q$_3~^="v,X쪷']Zisog7ǫYvx:uK!n;䭬1w5@݁ÀX>xě*3UUi,|RQ܋?e+!&| |OةNJEj'=@{gG]R2LJBeT‹+h|FHJ|<a)SbDJ[k_$Sٶ8Ⱥ.sFŋJkg38Ƒދ*_(WP?V<=BiuыUPKQ5]SI*Kx៨ P/.DV -Kb'WN 2q@v`*I'N%B}' %ozt.$/~(2eE(P.40C65w&'|T#j> :r?kHij2;.0`<'l^-8|]g;^lIDv{fJ /xml^1+.Y٫1pZ;ƀPFD"3a bLXyUh%;le`=s`GDlg_ O! ]+hviO0&ykmv~'_Iz5{4n-И ŗ- q8-W,Fi)%N Дcl7{x>wkUb@$(" .b~js#Lh`G8B-eo#ɬv>KlG:Vx(HL_łҊ"/oܕ[Ed $t`ǐ'mhР[Sy)O/ L=Dnz/N=B=:3ɝF QaYJ/9Âosz0 !~C(ΚRK~!E$QAEN]R!4^vK ke@Qog}[(+DO\ktưcg%##~뒱&׫OR*^] &%paQ!оZ]6,d`)EͶ"6wA'!2J4Ua&ڎ@\Na|":ƫ3~,>nP{a3kSU~I· |/K~[cj;(e14)Q8%oRy3hprALm?doQ1Lyվ5ǭ&tU9]nB0*N/zb_k4# \!G:5KG_|2v,%C;:cs! ;6 ᨣn=[mi>!KA~۶xsarT^BsJqM̴2LiW9XqU&Υ&WG}H~}& !Kj.S >ko&je}U]xy]J40InȜ;jQCyecAՊޮV4̰$: $zko9U('0wWWv,3izj7teMd-#=v̝[ ũkI?!v %1 Tk8Eۦ:4GֿMSVp$vY&E@[0x8 `[G(%ғP\[2C*:6nv̪Dea~&J6f B]9@Ox_xK_a8$+g=zLH `Wשi)$uwƧ2Q"M `(oxr|D@7̈́>)"u&5vf2kb[F̒R_ Ep - OBcm˙4 7d"'D_(&aM UTݧ;עQB)wS^NXl Y0=Z \d3[lAg_N$x y2@ vO_#{q9Gf=kLeER,Q0Aj ہK<%=НH/w*lJ/{O,E vCpOF*ŷ%ß(7m0ÁzmD4'907eВYZ|;}U2>tU1@ꂻ}=bRm[qA$x㢗[<ˈ|jy ߽H'BdeKmØ* eHV8Wv4ih`3Ń'"wgޗë}9STcݠ9 oƽm4 &"u&*eHW]SbaQw]22,nSY M'VmoLx!"1Чݠ>.JW`eH_Fϛ VM[뭬Yyy(!?ڮ`&5R*TdIHU^~,L("m vݝ!-px\7ċ"D<6Zbc,H9_xAwv\({Y-\$i/m ,=sX3v"I/LS-8Lc'{T>~D5FKJG(j, k>W]p,N)? `y]4#RxB: 9I{eB'vN}C!12&|@4c}vTi)^ -Ww!/w1D$}bR-φiZT_GfhBZ(sӆY_a67Vs&64\(\Ec 1gJpXKM >Klmz"ϷRELjbx蒛_ Pi 3+WB[G㟅 ׳%mP(t|Cϗ#2y1H\;[^{tbW0hXgCh%o_R][=ٿ(eVej޸kΎ!s7f4E),Χ(?,;,QR0 O`$\__k8H*`#l^˟$l,oݦa `\W0E"X 6%#nkMR'Af\WL*s5Vƚ hk y"T_njH%w!#p\.#oH`~n"I$ҽh둵e)/0^ӞNl(>.ar32='pC4o Kn9$vzC!N*zuqs{]TU~?Ž) !6"-_7wO[t*s9 UL㓥iT :{S JI[Qz]]we'Mإˌ Oi$3 }Dh e\-je 6! kʼn~Cm2E4xq?/R!ҭ,mMlWl]9=ÿrn 3UlBs&!q`#+ 1لEi%}{l=˸J>z8MMMx eq9 qcVc[L$f mH"կVz^Ipe$o P!Hmhx}~{j/UZ"McuI(W͛&3ߟoc@k,p:am_S2Pq_A I"&^73x.O\UҾU-Ewq#UP{f牘;D܋w +xrSRsu^GiQVg(J~ 3DjgwtN 2'҉{BlG[f]P&КaT5~#{'-1sJޑEk)xӻ 04&tη$\J8F?K~_pE'8h7gqJu=hd<0/5|t/]p以1L;')q ARs1X74z![j2b⌲ ` HԻ3xE?h2l@'gL߿D[\e ?>,޵p>Fc^aͣ/b}>9##"ˁ<<5ي_P6Tѥڿ_t j߷ʭD5چMl t FgJO[^(I:G wP8O/deٳTmى28.ԑf 0ro!E NyO z)c8Í]9/Pʭ>VsUGV9_쌖~/ؐjB|Ja1RGSp~ Bm:qL,@kVXLRix OD~ <Dz+c2FH<v (wrV喜 eCK^='s1)8w5`I/OjtƇL^w {.KCS u]cZ NQm{Bثo*1ކ# i6| =;O:"D傦7v DZr;i@磖4;y9)GVҝ _;cdMX>XAIfi|{H%% BLr ߬ZulpdT|YrA.sV #Mo\886~CUݣZڛ; ½ơinLJM/鳦)t匼:`leOsC_fr?8n 9ArаYbG| hz5Uw1Rz`wIFT+u]n蒁Zs/dq|΀u/f " 0MPjq GYK,>r^`ߋkΪ=Oo9CI#yB H]Cwr/},Ta6EKAQsPLI_*h+n @D {F)tE\DU'FKb)F^:/nApћgZc==LOp{F$ͥ:`Z'Zy<:]/6 U,F7C쒦4z:B??-_k hna s.;t/$O4[IUX" uF!Y7>zIY)K} _k [A=cwfc@4@zh%%Wj`WY6F5 W."#0G#óE_dw>nhzHz+v#@wϽA TtKM6cq]?7"s4# —.ݖ7XÏV>%Mo/.֖3n5yer}-3_ԴZ\杼dz2= |>_)\)OHOb;UXT܏w6`wl=מ6?sO0/_۪g{WZArt*vV_TU 4/N9UȄ{>j:`Rh8yW: b x0лg j[E?{3( cǧڰa^v¼Ƹ$+'ډ)pAa![PaIa',eWR;6GM&FD,J4KNx .XF~X/ >Ⱥ)D7b=/cP0`M;5.j;- &ĮsGJ$l˹_M߳cn嚓9:cAUprS/Dy1%Z3}U 'vu9j8Ҝ "_ diVp9gwPBE")W!j1>U.z~?oަN/ޛYTH0ӰK &MtuLמSwQtGe)Ar*i|/32m,l3R=n̫B}D]KM?ؠFcphӧci34nkS{_z=g.=tyn7( zOs #U]'ckgޘ!;kwφxi8GzxӚPH*ڄ!b1A6h,[lFkDQ٢D8t/$ TN2Ho~'oFPVwE:/M)(9+U68y,"1[{[*uGЍ)AG>ZIpDIOh†Bp"4-cjqx}2הat M* ϲ Ϯ:q}4gM4D3*™zlC~@a ^:)T=Ӏ LU~?}㻠e&6 Y]q;I:`+P *pxC6t͖[F1?˚<4}Z+OOdDJNֳf|^IV$Z#+uNyśA 0[@QeE!w^kŗ5e"h Q>cƌưMc!@j[G!'S@o]o)-^=c uf,hם"k58[_[&;"-0kdErKѷ̪H[C{92 CU#pzq'i;I܉O25g?i9Кzg[^=,ٜ-:k{r[o|xi?܄g.L=O!`Z@im?g!Ti |΁P.oCb˒q9RmtV&ƁFKwz|uY<Ud3PR`RA(!\nY0fu ׉%PaӢf1aʟA/S%R}jBa`ݤπ>{Q&/jxш`lQ؁fChۘz  B gr^ᬜvVIX7^]2?wў ֱg̡nakzOP"]msbUED2_˄vs|i"2c`=1:\SS|j2#V_6stkuiB5աW=MbV#fkK,zѰA_YY L/GKH߸qXt[p:tkBJQ&*0Q-՘3XJ5,) !?NJTPKY`  $Fj8k܃{^#n"R\! -)'ܢ2O?o40*=S,*15M]C6eiΧ͹)Rg6}$`%CيQ]o =]ӊZxx@tJ꼔B"*7]EF8w!} ܢZ5NGWgd] I]rm1YFibSߙy3vm G$gԯTQjIQ_ K΁zX9x?pCD> AgԅmhDxQUַl;w2L`#9Z{Sc,YFë(Ǔ9 .'jLTY^a p> Qw0}Gª1(A{r젿*7uea _Wͬ}FG3g_һϚucS({7y%4U)Wγ}^ Ulj/S8[+O=~FVCqXў/˔> ׂĽvRV~Z7[C7-AW[nlV\ÝXǦlkǓ/14̺w˳gzX2W/ӉSM3ּ;Zo eG S{ofjբ4Π!l+J Tu=i#0&H߾$ 0czuW[#}U%QJI m{iNIvh{M VY>hPc5`rkɏLZ䞍]qf]L`yc! \Wn|Dbc{Qm! @s|'i`70l=ʼnb]/oT  %8Zm[,$IU]kB#W[kЩ& k0#xɚ6wu9m:)Wzu+qx"Ъ/O,C-٣` qڤj5<[q"5w6]QTQ֕!m3vdl>*ӊYtu_p>#%o_Hr;*l1 bsG.}HPm%fpx)Q  y2qlڍZ犹ۑە'ʅ]S )81M-$*4Gc/?8Vz)؜ åL~=6JE,Tb?v NG2╌l/ '}4*zՉf)tꢮMcc Rje9.ԒOFg#$pyB4'|rB&V. S @x#ĻWƼTDG Jqkݲg t}+=Kl\m{h-۱B7 mWOfq3D!z5P v,jPs!Q[Ù&6O'r/2- _pi2. N(yQ}wqjwT6fö]Xs1i;ۇET$F8C]ŻӽAJbF"y ]Gs k.߼w W`)KQΖFkӉ?9˸(BqƗiڧcm'7zu]qes-~Fs| a:ҥ6(ê1x5I@mvgDa4f EѢtYn| &[𕯥.\WtsnV\m("Kj\ ?JPxVŮ(g:SBၶ1sԊFsO#v8+>Ⴁ[lC[I' Ҫ<#m[4Dk4#ڨ9=ʧS|]މ=C*(;ޅz"F6xC桄=JkUvCi:_QS;_RTZ;ETkg?ǣ=h bC<] !j*i@xFw4t` <\d9`t qѩF^z{C vϻ)gsp_N/s!<;VfCȑk m ȐjG_61(= ճ“<"ʱ<$-g/ <JӜ+%Rc,+#SUI24ÂU޽E`n ֲqaH8|簎gP_~it"A_f DSDqb*݇b`Vl7TgXt}S93w= %u s\Dq>ԟ`A =Bz_BS 0`AZ["+4Qd%%Pzg%\)uRIɴ}U@\3|T 'sekYnL\sQ.7g˵?sː*f8huؘ"S_)/_~N N}G*.PTYt K۬}OO aO2r:}4Rج``^P p4[ZFdh]2~@n&5E0bC7\h~3D|~=}$x# _Uo<@T9b={AW%.nkN(2A'Ai/k8nE9٩i,X$`1wcNEiĞhv5q>ċ:ńosVR;LL#CT@.^lo/q{"NzxFOr Y|8JUyMehң-Y 7rr1DpPJ՞7Y22)K4 eXpgk~/J)HEpQ3E?\ߑɀw [-hrrd[ZQbFj栋gi#_8?ȂOKl;?m#8z|#Ν"^q);Mg5MjX4YHXTOM=k3Au.|یosJylS@/Xwgv〔〭׸zdԁ0cdLr lǯN$>mԀΝsMG/F}૝~[Vemwu^hR&aLim&!#|AAp[ࢢ)"~wWN0~fYkJSȏkXϗE-|te̹5\ s ROw-j` 'BNT_FYď?6^80`J#%Hst<ިWM?0n󰱷=sd7yj܌ ֣\S2U\GlXn\AOȣ&ڜ^u+Y?v?U(g 9̯ e28"K AJ @iREד󅖮-R{Q_DH=`U ~+Y)sA1vro)`-d{۫n}n%s@.<8KH1?D@hn@ʤK l߄D_R4Ba ʸ s@zl>dt%Eh/?`b5™ dd4퟿cgxsd;8vIokVGhb''(|UٿIjռ 2§ 4w챾EG|WlO浵if[wWg`{S 2 ,)ޅ`/2$YG ]7t޿X#]WjcBW/lV}y/^;Vp.61V(C1꜈c=^&f BViˣ"fVLmP) ӣ9='`t9Dǧ=UBJkd# W`4{r jJ!HW[FXf; Qf}8"K/-~_emlEtf8Kuw52b0cߪ^S:n~}Ogx6;)a>iN!5aBg69XkH`}E >_lה|/gIi9 Ma(bp#EꆀӖj 51U_ qghjR!@x(=mQvTT0Ý;p #}w&p},4TwC^7xqqջ(W:l@MUu,qgB}ҹm^`<':+) YКC4:!%=~±X6tC+&:rG&Tt UR䌔RG1ZǤp$,1?T!'|ŽѤEtv5}pG TP6%+최mlSAd2%l'z}6YV|48(VtH]-gݬ 5CìkĐyJq!d4WQK0JnIExrtl qsV{HE~)q#غZQ!6 YjBd66 ]$wڣ-׎bdrP&-d\k{XҌ -.PL:sl+Y%zm,97#ʚnc$uryd:̠F[ ԲF`PW s_dyRA{c̞`7WQ6big'P(Ź1 /d ['@ _-K!i.gnO Vw?;)=;Ix*{IWDgEsaNQ=ҊVpbe|ZZ^5uϲ-D>[)x˃_wzM,yh ?+xHe{,"exe Oρ8> Mcl/ggq (>3d=<"%+oM~~ \*D {_kBJR=@O35qK]{ fC]oO}%/4:}zqEh9sOHi''2 \ڼRβϟ$xYEۜ=!um|-s=hsEa\KD{oD=H C ߽\ /}54U=Iύ;8cgQUd75r郶1L cH{P+7$s0-LjC7,'h 1'm@2%o>L\"m6 -;<;ZgV}laSA=\dt_b`8O3j- pX kE#r%Awoj;w-<ԙů iHs;pD{,/#^[ LxBϿYJlMA_ 5w=+HI$d~t"^OPgV&Ztr8=C+"b2DimVpܞJZ^sՑ V8Z\.,1ZV)qR v<*Ҽ|ƨ{oZWnV?)V/ x H~~cx8d^T!모*Kp Z *]Ƞ pg5HYeϙv.Rc#ΫrZU9grKTGVu^6KK|妶vMPZsGcTْO(M|1IR>A9%j u!W2$yc'&z3|{I[B!$KUYG%kdwxK=BR1@M()k>4 "V{*V"!eg%~wiݡ)5gу}{ɠd =ily- [{+2Pͦ+,4?9'v gGP&sqօcDE7Hw 'T"a$XMї^?h6s|brue>clScɺF>m XXo_)ȡ#k-/(r_ʸy]x&ɳ5~<[P͏@+yǀ|V&{ c߆1'2a+7뉮 {x˦9N{!Na=͕nQ+~Dg`—B)ͼ0\M]|ʪגqT["?>iyC6/`<3q}C׎vy=3aKΒx^c7%) wj:HC_߰b}Mm a}@ |-Q܀ -Gtq|t`lB^X2l"򙋘䘖{7qc(+/CqbE-E.5"p !G*#++Iԉ4#^ #?7KA_K@hp9?0i`_@k܁vzƥפ7!_Gv"SB#I|DT>{u^k8|nִkviBG NWxJncz 7}(1d~h\WcucIjxabbzڽmV둑(ϛNvfޫ Y+fXC%b}QƷۍ[Y=YS3,u`QK} _^KW5FfQ#BlƊ+R8P5Q3 HYXSsi%G3;R+\9[q8*q*<`#x9>HQɩz[ȸ#pmWI]oz#>߁O-ШB(5t7Q5/>Ty#!,vٯ]_~?c…pE5B5W[}F#dOYrd ftl`?%^Z~hm '!%M*`GE؟Qw1AZd_m2E8HQUj0<}lj_O\-J^|W?o*3jfV9\:yՑkۊ១'q*p0+[QӔ-9m^iDaJn̰t,v^A""WN| w="T9 h6~ch˽0F,*OT#@Jˮ?umsBd&TR:c u}4 B0䰶'ɫIRn*8F]/Tm/"ChCm`#]C\?>GHmfc&#nkqG0k,J`2ngBY 4y[ -2>,$uK ȉjt؆9Cקqu䊁5ĞUE*2~[7(P HD㶽l@Q vŃġ~{_.  (帼|8V`3Qt;_Hoq_ ;7=\4Zp~2]\Q%Pǰ K _19l=T;pɏ-y-b7}R6RA,ZG68~akK,R_= Yq~` 4$1-U5K%ctpj.r9FprZs3lnN*6u}2Q%kRBuCT kdZO o <"g,'}UN&*|tҀ  _'r4ʬ\\Pc䖄[$5ʶ6-dmȸJ'xу0q-Z>R7qQ(R+Idx Rz{K.iT(e[l{%{9n0H- o?%W͠-|3ZX铠%IVpGm%fTs ߯ [m@}R$5 }c"[ Z%fO./mw*> '~PoeK}NQ"j{J/5?MֵӅ&JyMM^ mP@ 9zˉ7D1dSvŇXE 6;X,\fXt?4˝c#Q6wm\V֊||.!Rn`8SccoIɱݚI*ޭ A "b>׍*VX L <]M;}HثCB-A= A_ ײye2VY{bmsy白O@oP}6El9]Y!*.iQ gUÅ5"r"?Rو:&ZxJj|}~~({Sțs@%l;/zϰ5 -CQ@3G챢!^Me@ `v@lK'0N<Mey*jPqT= +3:en>/0ɫˊM' @p+'mAˡ/-ĠB0>vxV ]/!! V7/r\_-iY!o=$9 t>4stUE@;/oj-YCZ'9|MK n>r u;`~t>Rll7)EjvFqgRX1ysC5mq/ۥ\&"/-vL~}u?-Քc4.E:E 9j<հ(Ŵ ɚcX͛K2h;;W3-q#ӃP_Ci^̐rPNNR.Pn`ߏN"YD&jt% 38BER~S+RV&O&`9>OR" S1q>Hq̣H17H`nM=Je7 "+ҍqRעoS!тTKJUb GP(ma;~ƌYy3&/߁$,00XQE M7 K.qܪR(JDNw6Njy!$JuyrgڽX/_e[2b*ڠ݅R  f,H. y[wi2|l ඒ%u=1@P8f T ?KF8->'3!h_ ulC#s/ '_K7u~ܸ҅Xx}iWxX*TK~eՄ >zMs[!ўs2g⮚P~;/U%(ʘ%y 6URH;v`K%bk^rdֈ՗( uaV}NoT /U5 #,{ۉī0VŌ}ip"agˁ4zU9XT <@^dGN׾ϑf*AXZW!%]϶w$CӐ.CP Umir8⋮Yt*&֖F)mJ2&-Sn"ʏTQfNp4W# {.c[/r^`hɳ鎣GħCްEz` $Ykhlg^Q1367-kE{:`9#=85BrQ ֻ#Ng垮~ϫ]tve=.[N}_ᦷ~*⢤H@2C m1\㏪ՅDRҨYY$9bc™7 v B[J :64㚯CAD V 6%9*tx]MP bđV.^zLeEԴ“h#>_0QϜR|cJzMܤK 8>A7xK7Ñ N+.tdW(7 "bF 7]~CXJ(٪n:`.^T&땚Eԛ4MH|]rVJK!|Ȗ5 l3#͞㒤VҌuzp9?jtcsM hm "m'nap͎{Zi ZыAP[Y^ȗQ 0b#,A_\>bdVav(a`C\ T9|كZVԄH7F1=LAdd"=T1aË1M=IrVva]ypG7MxI/v5 Z4wީ#AhMf,b % ۞Wcg@I-Ou]ChJ<8B65pՑr|C҄ cȺw%E26J᭴Ef$GTr3ȠWNZCQ/.e~OZ'/HgN溥Y@T;ԛB1iP5]ʶz@F S!;0| bt)#~onCb6Ѕћe,1cU_gZdތ3}?b2\Z}y! .^_83%avN)B]vXٴ??L֚fVK !oگ;2q5}Qqp{iӻ&pEF! ([_̣u# l}u8EN/F= N] ezoblۥz~M(&]-ҿ^\Uo]fQ5t':(uC\5Ҿx7/K ΛLB҉$A,;]JܷYUv V;[ QjKsUߤmQc~ ÞXe acCqb ُ!]Qh%I&9 },A5rX۳Tp0L_(fPr {}G\#t[U}W;'U5RJ휛p;$^wWa \>}|T2,;٦iJxAD6v=))ϝБ!E~;˭g *{AGh,(DHHæ[ m&"FIq > ~uvasN¤f0cP1#*'[fPvEt>|(Ǫ%C\uy.EuEL{yG y g \D4]ձ?_'\ez!鑴)vb)ji*uHn&/GkQyJcmʔ/82"62>N֑VQ/0.b5gbQAM巢<&My)I;}4X2>n^w8U0F|`PjBٸnL| DCek>gk jh{0$No@xsTsqR!pjn{A!6,' B:>-)7v/gec±N`W|~xTqΌ,&+6GGO=+ab\B{[ȷb 7Ia0ۖ!=U-&tu i8I"ZvM?:鮎/hfa߳OS[h@ 9ΗPUm$Bt{7j+ Kpvbc($WJ&cC&rGS5cZݴ'?L=и+"kɕiȖ!=|lۻ%]X 5iJ;2>ULS>k<&8`9r&e,] H)8Y,۷>wΉ'2c)V9'_=h]Nv*@.>'H: /{):ixBaPQQcAP̃&̨ׅLܼWLHW(c/ ~A$Fn([WReoRX@ d?ڦQk93=xkl`[Kh.)ry5Ck75eP MR'EnOX%cTEM63ju+ѐ:-iu©rS]O;VkKmZBOY͹YkRVmad@ G -g0[NjDqDx#%2 P{Y؛fǙو\s_k13F%,[bB .EPᢈ1;z!1eHj"2>!D׿ aܗX@9tt[2xfO;U&14oUTE=OڗcKL&j^ް 'mb\ns{"6+-f7}r#C#1?m1 \}Ţ?F,˳ef7C<E%~=€Zpclzt*BCpw*Q{Ic|q~5;^G.+So4dz<EJ} ^$>p'EI0~ SD)6X,qeFv~){q{g.+T-3y%~g&a ?q,sItwz9 6~̢|1E´cMhwy4p®[I=Fމ BǸl8M#(3EgxR6u4FWC aԶR~˻6sP{cg:yOVʲɼB[ M_}B4 ?BDH+I2VK&iqGU&`O9%(T(>hi:=yKz9[v8 Gwgxcd||HqHZ־˵`cb58ڸvH8dx-a /$o,.f6q~vZ+/DH < _vRƋCc_NI8|r{׈`3g\̯ϩv&X!1y9aW9Y׽O)V@m&1ww=0yt5ߖtDžw7 `ӝ ؁8,'.SCdewb`5c-Jߺ{ucu$I\)aXtN=[<ba|e=_]qC6`~0^睞:U## 7HR6 ɣx㨙?5C._͡V/{{ o!G=I#֨C1^9uxsF.`a2)pu2]GB0U?M1\El;t:Mlb gFCki +!N⋵!ﰙ-]p1cO7_]A"z;S>UX`|wV7z[bc~%Yǧh>iWV1f\M\K]#H;<GQd῁auܩ`̞n!0L$JpNWY b}]`݅^N,QkQM* {ٙ Zo*q  S)Q^p" ObC!GNi1TR+qf,:MWR&{it\Grg{Z 8>is]XgteЊ`ΑEQ!W =ȹ,l9R;ZDŽǡJ~{kHZ|7ܿVB!a@HQ08 ﯐V PE=hۛ ǥZq @AY-]=dZi /SяȞ@ 1~7'7i^6Sh*ar 3?adiCbu6md!P;|ZO[ moiI?c}'w 4a^:wV_]:*Krtg} Th;/!*9p:S)v*jCԝ۰j=^ w J|򽥲y'S*wgGE}6D1bg{][!qZb]R].+3)taͬOi;ξ,ۻbh8͜Y/qӦ\xv^ޜ8 KhLvKм2 2#y|`"t?eM.ok'r!8;[R7%q=)PP*8e~:z!yэDZ?X\ 0 544/lPc}d8!2r8o[vrT>Q4VP=(Z$)^a{ZP߁pSp( λ#P98y=, M#hIܓ70Jq̡=YJBtϺf|@g{I/EZfs4)m}a{d &!cЮ׺TZ/r#Bbn{{ =fDf9l4sF ~pG><MfM 63,!^}ukwGEGK$T&O*-k{+}?)a7!ͮkuDܖ@ rh FѸTį%d_/D6 iy'|AXbŚe(NKLVTFWKKhȤiyP)gF";^u\)c*Al{&=^LStw`!#ʪ{X!.os*$I]JLNvhPiv>W`3RkNvHInb̚~$C+Z+@'tS9B Ԅi@x &D7&;nUVSfe3krf d t 0K5/k= cUz5e.G hz igN56ޢ D w(K8qB^8j`}TJn//5ۚĆuTºM'@8&zNt k; R?WcEI֙^A]Iط67I{&S49-#hCmHNSUDPs/XaNwreݜ)ȋITáK'25SРx[5s̵\surXVLTo0jR!]) 9,}&mYɍ\S,WCk=mfN8R4;9MJ+PXFtRɑ$R%7ƿ&BQe!|ƅZ|nGG{3?y})`9h>i$Nw6djogJ9(+ޚ.7']9>:]7~Ҩ7bG1W J.}߰W'@! k 5!HL*.vjKcS O6 ,ws@锊])˟EQEg /:5-Pa-A+fw YJ['bj7(>!uE;92KSIu :=v&Gc]@Ƽu .aY%?3e@"Pl+yرxZh7FDa׹OvZwP: [Y$nC+3;_҄끗>g$TXCtk6;2E ie$]ʊ;jE]1 Z="qL>Z`z"6)x/ͣx Q,[a3.O6א7@Nhg/31/¶էAhWwc ^2 ޫqėe-kAP;W+4$4*[X B sK0 }M~]KP.5rvNEmlxAMT諥- 噮SX5*kˍ5^EOfy\k%V6q0KwM2av!W~@#cxNejgK.m)uiӊӲty@/oJ7G1(OBK4KM֜% : !y}.KOĆ jUc+ SGQm0#aû<.$ɐ|J(XVjT`1߱Qxo־' 1<ǁ۩\g^, T[R23Yˏ : UO<[ <ǒ 8X*.=A;w1V S3³+o4*i%7%p^3㳌*f8w3AaY}&@ID1kIk,--;T,:D@yXb%cPK&7Sזs(@P|vvEO=DӆNZ# $,$+y~!O9KŮek*q(H;V?7xۤ ۘhGl"8⟫HרO[\4ѯ'\ڶu\oLBgt.+jxqe@?1)H0mr4hT C"Wrᒚ3UCXZ/?@ ݧvDI@vgGw3^`lڹ{GmEAh'Py  Btv~,;8$!'IdpE.h,t,^|af;W vs~"( !%*fV.'& e ‚ \ruu -5\ ^y4djvGFޜʝ9jd?LEKQgNtR%J~TelgdQ y;H5gr/c  Td'P5#02O3lV %HLZEi2U(NA(QU%k ~?<[HH^? a5 j@(F*4(P;XHYh6 xV_dOtq}ɍ*'iܪ+}LlTȲV{)MXX0+/,MG%p? >Z6p+E]F5TwJ-L{䓵'W[Q(x[|A #E7}Kj^~=&^d,w0{b 4i@0T~uPNbp @UtBp{c4؆ sv?|@w+BJidY_›#Wch{ڊ @٨4mاߓ-j24̃1WȏJUja$繝tb7"Cb5Qs’縷j%¶,=sA<_p~"w%b9H;pHڥ|JnyLbNlݏ/xɕ3a ?G:˒Tf5?2;jnMSjCC,7zU?WjH (+cXv0H@C64j~RT̑+CHt238/< qߺ&L-T#xaZ={h R~xe#b BGrPSw|p>"/Z4$&pv4ҖPb)4t~9>5[ʆgX$ ayyO%lNZ)r! 2ɏ'uE06N7x'߆%BOĜBX=M%`lXc7,; ؁d :S`FBTC {,Xn,EL#yV<̏:YF^/'~`H ^ h2*("Ck-`2:PV'8HbrU@0ƕޓx2s0uYZrzmoA!wP]w^.qRؤE& $pvC0 oĵSv,K%l̨B`0mo")G$Oꟿ75T|8T>Bf85 p ʪ/3'νՍu0Zyꯃ$ֳlLMzuj4H]XpvLͽu%hze9V$pl=MJ&cٹZ%'*Qx D)aNTװLZj'E؛U\/lDAE1,e꠽r'q>W]Y M"0`'{U6+˗-CUƈY>އMyǞf[GI;|L3JS~<A%2wPNVNfCWp #L)7iz I7ӔV,엔S[60;MQf5؁p82IjKB2!\)bXjWz6 1]2Auh;D>f٨j{:Rgg{Bijp ]ڍ#y r x5%{SX[_` |n?EK9p`ϹTRQ?yn&OeF4>X.;6xߟ`ijӓ괒qzfiISo;NbugΏ-Z]O* H['mwັ꿦N84:?C $thsr ƭG8^l/ }Mk*\#'z[2%hQjj'l6PZF^WO{N i O#d]WcD#VL]E 3e$7EyuY ᠎Nuy4*hl ~S#`N%4Jb溤|jF:3((lKAוInuw",қbgˠ@0oN]gj.9p)#o+'UrCƤCO8P] E$Ҡ~]x4„kT|F(}$0C륻`T3m^4߰0A 퍟 d' _,@n {\4Ҵ u"'Bŋ@2i:oo!xjkeE> )4n(gXNeYw@LY6#g'JFˉ[ccdsu;9 s>lZJ{~ ouv{_t,|KH| }}/T 8=iuV7vÕhxk+i8uƌ%cB\_4PqezfSnwB:L y0w$}nGȔ<7?(Wj7މH@8 )HdǶiu r3Ӥ\& apܰs4)Ӻ] 7Kh/7oYEH`>7%V !R}u*Aesq1pz}"/R}Oc!Л;[B;=И:ntk-p2ATJBl\t/p#Ej},T749.=$KT<ܑ7 QegpYˑ< %˩E [e4a*xj|2~il3lSM!H6W Mt֐-)+?q?֚tWl_n?v @[ۇ,Mg<㗝hQS^2x]O^J[B wOHڍv 0KqUv7ͧ؜xv只l<]˶Fz.l~~ dV%p٤>w~8 揦S6$_`~, lbw)܏>t^UqT27MdWcH)w6&X|ZycH9ZׯPmm7JA#$ʴSѦH@%m/Ac"A~5>H%$]um"G@$~Q}ƝΗVe=bqKm?oŔFp0 C42)\kpgbW=c4g0<58 ,a1P'F 4985c2Cpki糤~6@K&@2. s͉HlGĢvRND V*QZw9$Eѻ=WZ+:nδyOw0&r6(!g*VpߚGd+; 9C]Njлx} Gs[βzlH ~ǀMLJDY1V,q:_Շ3؜g_xݴHͦM22zTxSf5öe F0i<} z*wȠp vHVu흠% DQUH<^9jԳAߦj)ds.@}}I*I2!/bN׸$'gd wW'х z._\H2EɍÛd]yZ! 7X<vPS܀Ix;~L8tyQQ|v} #ټbY};O\#1 An Ϯ/d ˊ) QD63׹6eH  (K,+Ej oT0TOHc}Ϸ$&Y(=>{N,+zz[9YL߬zaJ'6u 3Nm ~m֩hML@>yЈ28f 鑐'Z6K@n_œ_|6!NnR֠t/Nu]Yj#p9Er%> zQfB$Pq]tJ: hgRfb!ϧ"G 2swdJ6o@qөt;\ S՘^ XR!f7+Xw*k0pkkfDre!,\ vLllՌ74uA9xKz L^h[nvHLs":0D:0ҏ\7t1 y~{m?|d26#t ,t7۽Mev2VK]&=Ió谎?ru=mPb1'aL ֏fN#U11Tb'hj{@dbh;Lh|'2[#':Ӟ%`b@rwcm*qʋM74}lm{KLZzҕSt/d`Cj&e;-nٿh\vD"чu0CNJJ;#£5M_I?_ldwjV"jzq8ϊIvcK'+HR2@mMN7>Qg",`@q>K:\}Oxm:?HT&IM\fl6&6HɌ ^%z|6 9yzr犌JZn$_ui'd Zߡ!5W9G'B E5ym+ *.DSBZru%rc^m#pioOqm5iIϕzZpe i{oGBD/8(NIAM~H!ߓ뙁@Fh:j@ KnUd x0m/P{ouVz[}}ء<ȅ9DskվAkCP $i/ݲp{+V56"xQRgy] cTrx8+w9ߒ0Z #cf$:јuDx;:Q'g0Fm.Tgb } -lf'6CaӶXYNo>NoT¶]ʹc{aXz`nƙTGfCJ;F!vx%Kr_((7k"? RzwI ϑ,yZV͗WBƠr z=318)k5Z\7ub ?YHc],WFD-&?*ҥJ7'焕*0}_ Jx]'ioPxؕ _+5`6-y:mt/DwKn2*|gt T2t;-{0s3=YWNk)pA^K P_XWֵ;8沈*1c8G_"+i9@XN|ǔ$0 dŜ?g<"2ϦkH YCRQF.t=>XݷPK8P CQ_c%eal풭(v>N EGzÀ%u'y1w#>ƩBZx)oUC!5L=A k"FDz̊Z!!rYɂ-]D݄`6SAov]1Wz*6dF"TuNF-KQӾZv{n$D Pɷ,+-BQ^Xi(}kTA&t퓸E}lNLql ͡~ S,[[>lD'8}@cI+X|p1^ZyTcF,L dLMD =O9(SO>L+\j+Y%tQG龆=FFaFq jG+Pԛ,9&M$Ĝg0 0#H'Y mLMs}z$:yufÏ`ԀY'@Hnj6io`SR7oՖT\K(Iᒁ8(tC$&ے_Ͱr5FCEƒ]M_̲opLkzO`vD3QQ K֖` x,_>Gq5sLKmPp9O{[Oږs-D-;xfxE=CGnZd!/(BxYt4?o$iK*^,$9O2,6y]"je׷_ϟw*3 ;T:{('08sgMQ(tn,d;;iC%nEC5/?oC&b# 9g/!#dzLzi-{O!iM%߮!Hu/ [Zh榮}t}pĿda/**Xw/:褲M8<52{!FW|F9K6HK/RxѨFШM$ɍd|ȑ^qY L0N;7nS+ A_HUDY k> h?cC;ЂA85akqm\T'Q-N ?OGjO^!lCvX`,W7. /ojt-WIF&` SC*P ,=]tf˻FV/H:`n&Nʻudjz#O&bu;ւNkYCX_j մjz2aj ߫(m'#nDsB:w QǼp aGhE&(%5',]Do۱bě7ye[ r~HP v,5Ǩzs"cuc$Or(5eKh8(L5/i>=D;a@OiJR Jlr$ .NfzQX)e)$AȿpL: BE2E)ذ'=Lgv-*$t*GtܻDaڽ!c:NE=DÓ2 $œE8i43y1r-f:@`4ɞP?z eQd-G4lwu "Ln$?.1 q[sD\ՄhS|WIgC $VMqI5J'."?aUteWߏٴ X:բ?G: Z[tg.A2y|pdňj| ƫ YQ2x0wRFhG~az* @ Zo8D|yےGܑ]`vC#Lc"*UJT;}])u\^)]G~j Ai_Zr{K=Y{eдzhNd;<8cTaEC5g&tzwV"(3Y$ivW9g@ ̯laL9WFY$V2Lj`<g>&O1" An4Q&%D<-LN ~3H^VҷǵT [ {VrW}7cEy^ Ƅ_SMeWDYs2H4` Qn?dn׌蝚 .ƫR/OًPׯK"6utRP" @jk\AEi}={w8Aa;ADH-䏯5ӏɁhFZ=85_*N:pEL%ivmrށ猟;,F[3۴yX M1^tw7f:`C(!>ڦ<`ŠUK,td'U~60hвMj4M9YJ:p]OAy{Sm8;PS *nVgzJ`)+@sGu*hVU*y57>еl8HmM"4qO4ku݃h<U],پTXHh_x;נe%U)ė9:q/8DHTeMlA/oҽ[ ?:-囃j)qHK954*DVѫ}s )>-1VqjkUlc,BT=Ż\Wq-I#Ss{:; Z?E 7|[F9Xo(!PLc^@ȏW/oZ*-}+ZJ K l,]nzuD ͳ-麻Ҡ1hvxy`CBK# \(.^QAf,Wm\z O@l  u'?Z(mShx68ώ>'g#, c ƝtXE1\;bu_ R4`sRCԜvIJQIoTܭKrݑeiAA]ac: ЍU]!WdӤ0WwA".3U}Thά]='2e"[SjG䔧tw-vU p1|7ߚ'C{\Vׂ~1^SRP{x캴ңɇ ۺ(Ai#?eƽjaV/EQ(5(|NVdu0/m.ލ>8YDDn׈[/DDm er}g[4ve%;)%p6Od׳%!Li?7._]0*zKU6ZmB`F] HB&uQD(ԯ=f.'u||Y3lZ ׼ryK/N{> U&hX!J-skx}0-%|6-*B!a)'+"B6j2 $Zԫ K+qhUҼ8vУӠ^iҝhzSiJ_"ޒ8V7yiyߊWlss\?v?cN`Ss5qX?2o2J6;GIyhmXBLN+-گd4@GRzdJCwdCy^7I}WSbbTo+syіfPWjrtD47/y83*:?ߞvifgUsbxq)L3;X cv4^rbtmUN4O *KcתajՋ9ͫ>W'ơRψY$|l~Oòǧ cqJEhtm3*F"lEE`uEװGwƹ y9 /(!\N^@TVQ:8`uCQ֢8of~Mϙ uB11%=Y MÍY, k9d#5阶) h"ϩAM;'L3hkFK]Բhˏ=7&'e$qÁuixAr.0LgZ?7wl}%/5y)N hZ}E94V)rOW:_>ʃ8j=eGgn67ԑlT{ Ɋ!]mi[+Ԗ.0*ǯ*~u'f;>8y#;C]bW5` ,bv1&C15*%Ü XU0$B>R ʟ>ٹF Ϧ|AyGݔU ʙDo"DF5@us{}q0OI~S0f pN5X؞P45;n Uh1 c|i el^Yk)Zxg-(*& ,u{&2_;0+o8[*q~H̙-ݑ.qc=uag <~)]Pk@/.:A>"M]ԧl(0H ,A0_T:+uoRC neSpdf.}KaQEIxNJj^QW &ntN F= T; }ws+UvUt@L`FC"f?\=O9yu?o3ێćAg=M fld8d&zSb:!Ϡhjz|p_mGYL.xR Z<[RN5Lht0B|lMǿMV`3w(r%)EbVY^v~_]Fj&(G^#3>b"h)iœ[6GtS$?> X'#9wċ y,2 0xCQdj?JiM YhFUDzbAb&ZD"i8΁ZAb@ۨbSQU*oڼ #d[|{\! "A"4Uֿ3uB%{li^:&L'*ۧ+ }4.{ v 83h2Xо,G"rvf4v MAkFN4^N*(j!QRkvwɂ i('v;9je^'YiJCʔ8MC-#6PJ|x:}Vu!ё`"l·C2ޏxx"IU[G >3pMC4/!w+9,%Xw][ IۭtN:|`XTFa:^ks~Us0VKL{N=ݯ:Хȅ,i7+8A' nXߊ꟒ =Eڟmio3tCiEv#9 L3VcKvy{HrdEۏc i9o(AAE 6hn@#gO()Zx%v[&@y2¬ݑO0::VKr::'*f]5o" Sz0&XN8=r% 7`5GCngM_2bc\5)I-Ѐ?;=Lv[ \G.y3yˌIXE@!IGнD?[ojI~@Ȳ^Mzwj#GA6 Dc"C}q"t2tr}Pvfϣ}X?RHa!3-r1;V)XJl- aZuI !n]>G%```ދ v=9s@H-fLř)xm Ch*;xNQQxŦQlh8sjd҄ҡv" Ȗn̟Qu]CJ$b+>.1]lmCa\CBJCEЁ?AVH6Rڎ崀N~+(7!n°cyRnOk LJ~$+t꫓N~n?jyR{;ynH @~/!+[6=7ߖ":|_~;AI;->Pu~y(qAem#d~^fBb$kZ{zhd /,!% 'g8oV>BIsLX0@zCtEN4X{JCULU_='ۮ4"bdL`S/Yxf岿Pb)r_+RWf,SEOjl CAydp@WURE~4_:amg[O$Dڂrh)a(}M@MIRq -m64GJ8ߐ&A=#E[ 364jN<*na^!:{ ƌᙢN_e[Ѡ!ڒ -ϋ{?㗄HiJ'k rm/ A?B0Fࣇr4$ieNr`XPr ]"/޹<$Zs.\o)W]4x@']EֽFxe3C06N4_]x2} )~ui AV"hTii..7lFh22#w`;0vꮯӲKW]04f CFZ1#F'<꽈X 'HF($렲VRyL0`R1Bs[;!K.Zsq'>˵It WWHuBJݰn Xj7G`a'N"IQb\ ALU-6;DL)GńRCaO_ tB,drDh&꺮D;Y_~U젂C2~ÈI;*4ָLÄ?+T/GY31ҩ_ѓC p^Pݐ|#4NiyGYÎ#B00}ޓƋҼt'"hlǍ]5Ql priyEBsNlQ(@tx7ߍsK􋑪 LKǎvuT>De䗟H+Kf3mot;aeޫ|ՉmId~l iSq(klHuۮ%tzB,nsm4BZGA?;2w@0%7O.E`3E8FRVV_2'+dFڣ]:*X34I4[.ymn4yt9Txf`w}^Q5io?aF*T,y䕞ϼ4fv}H]|EGQ({$ :3t ģ)*=0o#!iq_z[U 2l;E7y1&U: 7R ȷB 3wJs{ꆩ^bfή ϾGHa WZgј;[OӔ9(KN|}T˚c7b12Hs.SW`2ږCn=sfJ)JQm<[do+ a2̿."S !4?X~d<G!XG3r6c޴J߸+[-¯/<9@-GSDhbyIYz8&Yu|l)[5QzDJge+rq+448;Ṛ!X v}D k͸vnDsʧӓ'_%ApB).D~* :Qoh撽TT-A y/TAf gh\؃~Dk11\B+l9j[CtYmms$:`.A|] c5n9\ܑU/L1;ozf0)^%80_o1 5Q6ȶ"+FqQ,><F(kBRxscD+Y4veZ(aϬHE2PSb:vKO8_GKRΝ>`I0ibYYFum~>ѓӄqWmg,t!(Zr7_ngQiR,ҪW|KQW;:D#߬V r}.}^hsBckw#9TmB4&˫`|\7둀2{pZaZZnI:L|M ,Flc,j?ŕ㤺1N!dQ2wٵ j8b҇- |/LeJTK/7h܁Ye`A01֍Lmhٱ"@@_Mu]Ef5RT]r%4agdIL}Vu( ^VDZ6gvծ"A$݈غukzY#CY9k϶)~W\J8yR|cS.ӢEfq1X(E;'?2p+/UKVMJFRA= P+ov;)ܾw' v}GfLA qjh 䴛TP- ũz\|ro3 K> M\&gM:F#4V[YݿG=LJfyBe`Na:D`o}S˘S|oH2Hq:zu`hpr(9 *GN iƷ,G{ѬF]\쏫;}s [,0 9/.@ڭ#B ntEL/|_c" }PEC| O|.o?j5Nk}:Y@HL+sY {c G(V1 g. {]Awl/f>Vvadrup#AkZDU2=7+-#SyJ-FO9=p+Iu ͥ2}!CK]E* gxEW@ȑO 4pv[R1ΘN(\LIjB!h$'2k Ǖ !RH{xΜm CY5kB/dF5>['%UM@XryWxQ~|H,&\t5`4)K" *3Y^Yur6`_ե8/;l[1I-E)ĚkۗOVr;Oe(Ft>pn,z{_ޅ Y'}IdWzk:p~aH!vܙyE%vǂJ1;<&_1Q xT&=H006>%}g#/7%-EqEEEJϱOU-z. g!Y]NI #}y5xrk'Rsƞ=1@X̺oX-YPn|\8G~-R߇RQ ūy}'>q1Ыnf X#?jC=n_;g:E϶hM.SǾs n|1˜~@*Of{#3i xse^Kה$@)Rcf+cYNIv{jhiV 0Ⱥ}^G0^,VHiuj*}4Ov69`Vv8pR<rJXy ɶ9*g֡fyePpd[Q(Vx@ "˂w+aD2gyr1-O8\>F`*̀y b / x%e6#MKtmML \4_'n W: XCJQ掋Dd' *m_>?Xa%r=]ٺJHHɯn ~FMI I>NsW.aXa n+Mα0N$TsuZ(9GqH08y R)O#ǒ MH[@C\kzmRi-sbMCzwxnrj-P&ɃIܳu-2A%?/ʍc"QBgoFpBh3~eۧ B$afa&$TUtBG7**t$3Kdr^FRzwnfsXH: ߾6l+k6Wb-Z^RϨYqb 4lp&CV-( nlwJ-]ܾҐbHu3kG Ђ#ޓ},!i3DdKݜ1&R1R,ړe񿃀;VB%#? _バPbsۼV%z~InG7IMْQv@/><끹>a3RAT0:;sW󌐈ӼV0x o@: osLC ՚+8$Vls{ ˚CxA[m LkZ4?Rk,sq/0%ՎDhğ.~Ib>ibH%ɦn}$=Zb@>( 3V`'p}PB3 mKNcBwz,;nY% ?N8bk#Zj :?gY_Eiʒ" h{?MȜ<\͂xYT;8Hoz*pi\pxaY0SB~إƵC9goY/fY/yc{uOn9pp2Z\@OA1jV y*GD) ۴^dg˪G+O4/zf:Ѐtp*Xt DuhL[^T衋QFRw) Y6G 0s||a N%FO *͂Vs\X|ѭi+w .-< guxFEܝ\_]L5]rT&)}N$/;*rjWv.s)0TQZPJ=;וO;Gh=&=A4Qs5y Ʊe»`oPOb~Gcsq*}_剼T4 c"۞e^(*W8a_Q>f? u7Y% /Hc~|ҟVjtoqTQIx o-sBnJo /l~הƪv@oc#"u`3W :pk3;e= Y9O %"D5-^2ʹ. ۮ =?I) jvfTO'aMp@t$$wzjfw0y>˥~5^?X~YLPe6.U{,"RN>"r=b&|ov\ӫ/0l{5XH]ט?[JV>T Q#oS2+۩!YLD^q=l{~b$\=9{.G|+;Qz @ bf'2\ N<6%pTYeπ wwBҖT;K?z1P!ki4 E;!!'LaM݄/mKX_OEYM|ё"g$3m\?*1Z4Z04![lVl92(CTp]Z' #kp-U8R5{Z@rt 'x|StݵkZ PbT-r-_Ks  BBaXWq>}ҡg㩋 C7 Ʊ]$dPBY{4!C9.h~Br~I )2C~XoǢKTU죝yᾠ,2xFSDNAE!V;V#o BkoINJE צ#-ҶD̴MOq"n^*^O4|}˼dd>2oÜwA}"}ZysHXxcIgQw֛\f}/  Xh't 鯄fhŎk'2tg #|SYs]@e'6 >ލ71Wwg?hV’X%C9k<9Xh/ǒxL!1x'\'v:lmTP-ͨp8c F6!RMfrHvm:dm5ݹN5߸qb/Ϋxax;n֦ɑCZUy0E>>.~̼̅'tEh7b'ʦ Ԣ/ܜjou~4 @7>&4/C_$: !J݉Mv})ן(ک:Q(69jo u!Ձ)Z6T V)ffdeMܜܧ(8pQSݟzg!,p擱$HbUG&򠸶^5Dx\\A! c@=짩,[X_şI}aeig4e׾"#Y;zvUE uDzZ='mϬeYV P[5ǶT/cpQI9C*q XH#wcchk+#UC; (6H ̦8R43<{PF\ 45dU %|rz0|T|>Kb4߲_LcCܔ&G qJ)G-N9{cF+s.ADcfYbh e²S2Kڿ/| 4( ;lk,);.k=ⶁmT+>NS\L#X7-=ۨ}4g$)WaH"r%9z7z/̽#E~Yڒ>YtMF 4Wdn9cK+ Iq82lY'!E91JhlKbj0NumWKY߰ $ƊJ7ؚ,nz8O1`*5zDo)[{_iUyMޥuڙ[x"ܞ'<ήNWIYANQ惊HV8oi`c9JF/"kbQDbu_ˏAL 2#6_}1%B,^imԶMdY c>}k\eylsأ'Ēм0lgImx3c/-Ù::^KHδpZ!z7<#%)%_ үt͗Ϧnܱ?ŀZK\ReR-Ȓ&ZڊE(թ)ZTsIT,Ӏ 7EREߴm6лO'Q\ӖRKY.}\H9ԩ?HR"2@ey#䧈& >ˉkg(Pa(Q재Vz k3hOx."*C f-*lS~v#4B<ⓢ;}E[mB>L X9 LսP5ߐD | ;X X.PT]K/Yld6:g?( !PH 3sS态5].m0 3P<Φqn;[t>GSp mtDž[ 6twupzbr.Ϗs)j/C(q=X IwK mڭ>'`Q>.N?5v8H{\]VT:ަyxZH T'.Ew`E®tBzK@J諚z Ɂu]~~'SS|i7eA6 ij}<|0A!k$&%?d1X^[ syagͮd5s_Y^Kw4h:6̸!=+&1Rk%? {I={fJ: teԊ}֩">!9U'J")-W(k`zLu9iXMn}m "H?E!wi:/`^IA`YbSӬ(iJmy;V!9MMlZiߥ٧Dm"kmB&fX qnr( #Hn̆ %k:KNYտ0Kg늇 2"sMު?ѭ +onJFaƷybrt|5gmrK{IRu$oN=q뙆eCa1 ڴP 016M9{}YzV+x#:@sTW[̕oY] *r&ĸ;NZO/.jew+4N8\P"(AWճ^hȘ%Y?$YKGa`@!~L~Ž۟). QAq>:豑uRq"?0 "&֬5TGMTA ;FUzҲЇ%!='wnO${ q^\n| 5{"r -J7dx'_Zk [uӅ> Ey_$ jmvɃ–opn[AmS2U#I 6ģR4{m1o^J_ģ,K_ϗ(b&ߑ_(6~YV䇙]1O)m_H%I﫛${ap$d껳yD3I$ٔdP  YKW !ե1zbV(#kK2c>&wFJ~JU[Tk%g}]J}4;*هĭLWC~f)7*2V.HwabV+۔R C$9Dv'`![Doyp@}ݼ6Q|VmP"ʎ7ro Sh-/-3qXS9C,nwa}XSh|#lN,y%lvPQĆ to:JQZ݌ͷj,Q-/e-!K!R낞ZS&v59 7QD4b.{'o?_ +㷧E)~Hwh1D⃻FMѦdk~)hۧ¬Ď3:ҍ-M4g~?_uĴ6\CB ϖ{櫪mY*3y Г R[:Gu0QxI ?ca u5kyIՁY;܈t.LZAc_gd*wx1 t`ܶi?&MQX!9t;&LahM 4)aĮȓ&O@ӂ23^E`⛗#' 쨏 D^ʷEĠ',C 0V*sw $B6ښ $GF8qo>U$DjG}nU UTf=3|98Gqlv֟\#{־kfިz6<]ڮ?,/Є_E)7'K%ZJd`2ꛊx><ێ*!B |z ]vنvUb:_~W(}?s7fjΏAKW^8L^o*(QW bnKHd&zڼX?Qܡu3I\jHjH XF3{aaEi'a$5X~lvIѫLL/>BZuRx<>jw6/f,fuIR_m̾:ģ`xsv.t)kg5)u?!ÍP(pv2w0Bй g{8]dWIX36a8,nםvP9LɕM6z' 6u(`+k!OS󬡆N'N$P5BW{PHy5ÊHvW P6nXCQ񳷖g=Nn!6:i@֥ڸU3V^mVV'b 9+l{he Sz,~>j|p1H.hAelRX(EngbrD-^T_ƅd_aA5<=Jh6p"(}SKGm q1>AusL*p |]R꙱{iFX<2#/X4jvvf+u 1{מBtjO}ckP~*i"rAV0=ZR\(cdOE}A.\rs =&-!aLgxmAxhW_~LIkY`ٿ5]R,6(֎UV.76ZçruՏ%Ȯ_4n aU!}nΐA+dsq,厉~M Ny#)0Jc[^o9| x`$}2GCG0hG"֦ [qb.wjca<>REʳKK$GRho(, Bǣn" 3{**W(Aչ;kupߞAݷlQe$$3Rr *ZWd҅P>pi@'̸{9wUb ԴJbCR@v#:U2۽wvSnN ̎!$тk ^O$L+dw+3sPe06ی_nDKA )Ek*V_l #vvΊ?OsfUdNNj&0L2WQ1&L,KDžM4r+Rt`G)糂7›W7mܻ71RJ3'B$iiYM|Q3W+qa HC=/f@ss49A=C ?6eU) yB/0M`4:nIґ!4(؍%s!&D#d»K"( ԀS;]:L'K`r)_06OMz1=kP7[JqeyϨzw!ho=ui]i[u@@Ch3Q][@n6>[輎/EG̓bVki -Ld) cFn`$^QDKz4UX,My\NQ~E˗/ 6FP6)Y;,+#ǓW kHhV߬c$Nʀ2:{⢿}o?/|$V0|8m H3 jϜ~.DJ vO-IΨؘ=ooGsQ~b;c'2`xՂ"zV+~˰Ds@J &'``XIJ Ŗuc j?tI!Pܽ8õ6Gyy\ܓ>C\:?||N"SrД_1P@w\ L?l(p#1VXeeo3hc)H$Phlm:@EqA .א+bf.o9CEឞԕne\m~5L8g#QߟEuI\塴P25}"Ac)IyТ,} pЀah7Fn ;X#;[ S?`nDMmI;{ٹx4,7 P+0$f/)kx9Dwz+Û,~8n+l|n[vku")/%hAsfH:mФ"vlt)R0^a{CDz ڡz!yWUK2֬ jw-l$-#x u1Bzz|N$3NݠPQOYB|;_9:ewϵt]iHe#ݜ/k/)QܒIN6 ~_CS0Iw|pֿټ8OWӜ.c/#M6z7 iYqˠ`PQc@I,摺\+]v+ Ӄ:iw@٦(#C9.+~;n*PpzfN ""l޶+g;q( tVbtU cKگl" +^VF"dH^F}??ĸgnX#ɟ*\wQ`9ڙm fOZ?̈́ ;5S*,op2nWzNmQ&.yڗ*J0|sH,iM%S8QS{9U r9`3r<|9=1(<)V( g5-[SNH;h,c߆sAK ,3|c #m)t+AV4"hHI_ƈ?&dlK4o#BmvkN6>GPN Bcx(Pa:ܻeF$ `}(L"_w "`W!('+u%l )-XAEOqgE6z.z`kE݄Ъ^NXWpL7w^c\QXb kVóRiy(jq(qBЎ/ma`ɦ5bWafP3Ie_4y5HQ1Cd Ej0R>Qh{D_q)z9vyv s UKCZv\0ϼ,WX*bJsJɴjq՛xvhl^2ve3ןxcF#t<4O!ebljdK:Iޙf|UB5 fEƌhHؙ;,_ Pފ?$a(pXJ*@ yHa9^QK]A[Ălv u"fU⢸ `A DܣJ\^/hɞUx~C@Ӱ]r_I(&F;#? %}[0x`Ȅ lȉ=& T Tޜ:) &Ipj Xܒ vz^ YW*}iM4ex2mFKC݃#0^.lFT4Qd1=UE!$ʇAN"pXwy3UӶ(jx쬨_JDE'ӶS pK[V7HY-wbSFj*>L{\ϋF+'p=!1є+f |Y Bzd_D#ݰ\A9r:4 8K{!zFR/Q{5"FL"( |vH[iU~].pih_.7*:0軫hˈC.#mݶCY9Ԙ 7wdqgS5v[YAڬT3DWd*o KgpQp7y2.0JUd>xk=8$*>ȕT81ޏsxݳ53Qr3Vn ^G\ğCbm>%zۻH6ezBkV=io'Iх"Hϥ—OxMxoOͩtq}#BW\Ooa$aJe 6v4s~ףC(<<աk o<}- xR)G7߽mY͝P ғSI!3CMO&GJܓ ]32˶$Z{n$m)u(Rs9N֙dlo@c{SsH 9k*i/trQJv[G_( mLҊjY8٣J- =iX\\<yXp])gYirV+HYR{M&|0?%LZD׵PTz!3ЛX # l'fkJRܣa?5ZV5؍oK (/$an vZ:O52+^s߂ɼ5b <!x*  3#˘U]#~/<њ_EQ*j>f6B ,D鍔I2ֲ?pymTN>0Sh:b{ 9aRɀQ؛73og4z/z>RsZ/=0Iv +8`Cfݕ@MvpAڠi(=Җ="¸bgi5: rVYD U쮄T yS >+LO2Ray)ÿkޅL`1UL1tY^WAn꺯pS*91*5m⊶T^ئx +Jfl8\k+oQG f/@XsPPK}PM$\ 6K{Cbb~@Ӯ\Kd٨ 8<޻/f~g*=0 Pqcj8F@׎D2%7kp .eh=|s 0:IBd)UF s#*h 0 ~d޺[ QP"wۂ A: mxu˒c Dx5fпauW|Z^??;Ԑ歔z5u'߶&mT;(SoRJ K=wE~0B|H.2'PW||sL|ݺk+:F ^&۴wD)- GV"%׹IW"=D:%3R`u9~6.S.§=p9*vsոݽ¨ N˲DH Y>%^44cmPN_JO9*`Qr%L+o+#8MW:sԜ87;=N1q-D繨tI{-;L-B޴o !s"΂z?)=ĵ5z۬+"ntق*a}i:e4i~-pAU 8򂓒Ɩ4{7K`U74L\T@ ʟIBJ]Uڇwai>OV^[cdVvﰭFoUJK%Is8rͰNE*2tlL=cCSuf/4nɃECUbXa}#sC Fu*p!mhgH䱀Pl G"pMO;F֩9ow>p̪H!]kQw"'CJ(!:9Y^Ԓ?ry@BVFsmXv;w6Q 7Y fv[lXP.Ӆe$U! a 豑zɁŒ -fR`vJ$_Gעe'\q:PM7"ok eN3HyN ث&=Pڣ ƀ䃾0sgj] <2EÅevH@HW.H{8^mt'扒_j\w.$deVhl쿂lrvϩ㳂M< nQD&z.?خzb=2SeT_S9JK<(U݁$eo3/5wP{B S{t߶"ul_.ZLv1oUq$;@&asq] F{߼ٺ,ā~wGSKciEMJ]whUoBۖN;=xn+>圤R ׇ#\" kA@NrThN[Xr"=:ٞ^D{>0.?d)NrJ>r9FHa-9$W/d7, A' Zzc8 ߻3Dݙʹ~jU 5)~v\3w%d2 wު6:Ew[ZϥXXzB?FDKϐf`L4]s)2Lbo?(U6.kS[9Ј |; B>I& {qzcBPn*.~!ͨ@s8D 0U y$|ξP)$rr5XӸiƸC?"Hь>+Ӯ- wQ|}ࣙސ9DIZPۑḁ_{r@IpQUBHd]ʫU 2.7@s^ #O|*:\Fք ܈Ss&7'R5>e,J^F %C:֗@'Xaq-$K[KR |A80&Ut/Mʼn$d N%Nl0Ll62'lf0T22r!ܩ\2Gu?v^}yܦC:SnlR!&}RB "Uʾ 4PסV] %ZA$(m+q ސ-j=d &shV &٪} C0wb%Й2 " 8~rrYUMZUE:z5'AOk[i Ά|K@TjDC`__AޫFk X$csI;P)"'70+$֋=M#l%Y&%Q9rړy6j.J4TCtqֹUNؒ^WSE(w▿Mnk7 nfx1SВ4,2̖N n)$)R<m~/?zIetb׌ݭөY(90MP]ܾK! >:M7d-%|fR0X7[oaq1tҔo鞦 PqWigr\$؞ܘX؀ vs_\A7ɺHP||!}nKd# & Tm@3:aEC{;AS 2Bp2IvGR{$+D3vr9]g85P a Ϛ%2l@g<'bXub(eY Ml/&Ds).39((v]+EP.uHZ j ~@MS?"K&%}!x۴㩇B@0 1+׌#\&Ի \35RLBilͪg f\P=SAGp'2&=k;qm&Ӗ ~gSgG'XٸQ<16.~_seLuwSB]tCzQ*b+VTWh`nL=*GufKX)5Ͱ@l&zb% [SƟˊ| qYIrB2▖eNAMj~F!@%<:G&J!9/D<ܰ.>K4X"й'@ 1{qL_e|Une/N-w}06:L#XSN{( =~W~Av$$tȿ6Ӈ <\w7m=Ξ-x eBAI+h~qS{[L ڮgr|e2(w$L7%.`Mq ay\f2jS<QKþuyf]}|6Vݟ-K}sQÉ2[,4+$6*\oFH;f./*ؖpRhtz`8ӊC}X5D$xu%~fSi5I9[:hc͢3^2G[*{WM65>R~1K/U>QuSJT9ӖYTUZ 2vKYOP<1s׬TԮv@13hǣF\?2aOgslY4 ~KCT!gA,|j4"W\kZTJ/䑺+D ՝aBipV… {%}$Nū`t~ֺ:e!]]u.GDCcٴԂT[wϩA$ Z䣥l|a*%Pq"rG%(Z&`e0OKrnk=rX.2W^T!+ t{/79>cpnΠ!!P7!`|8%觻%⸽h3~>+F6qˮAFZ4a_NlNs=Eۑၷtΰ K~$r4EA JK oC'W~!Z-Jhi#}a.jlQ,M 7;(ʜe*%;2`yG3[@JB2kuTH |bt(0ozEԖ- (e2XuE>e)9nu\(<V@S%4@)|\W3h47U~kvoFY Zûd@ӆ^2wW*C\no=>3M$M'6ZS۫.MQMjbSy $Ȍ87hƗ?"(ǘsxe z3fZ #]mZ-r^th_ |k"`cͥI$KE`_{`d߫E+lv|OU?;hugKǭHjC-QO꜇Kv>oÒS:cH}gIVOJKk%H~4hl>?<%;\8F Ǿ5Tu:E/'eKͺNBs62-x!7=;"x3@ؚLџC<Q86g;JbzBA^+۱>):Z8S̃rԑ GtB9frgcjVі:"'ӤݘJ(;t}|.K^`=ҐN鶎 AIR۾ +wbT"\x86ۏS|a''(J1/ NTwȺ?ZLZ*[darjۊ?5ʈJ#gb&0Qnwh~!<@uCE-FOV}xzzΚaWLsHwIŨ_V0T47CD*hp,j%'[Z h0-vhYOwq$ Ώ=% ~[EMcÄ25RQ .k6&=j1]sSW;;iV =/1j'xlxpGOKtmT{Pu `:5\L⣚> " םA.TVm@[N5e)- S .4֦EdL|W\X1u Zy̠|}t^O7qM5.m`":[. uOTX\߂u l$i,oMvY0: "Fqgn˿ܪ"*ϭ_y2@ qD3<` KRe s[Ol-5d.|{LR[-lBy⎨ZtzV4z&a~! v⟟>(d'^y{WhnS"xG'Y }a,ϊXj*h9Z+ŏ=}0{_S8뎄U ln:Q*FW_t2 f9d3]C6aykcS0R&+F*F_@|i*/.=32mպy%{<Ж;w)xqSe)Tn2`IAyFXof&6!`{N75 |sdT&~# ? b$`pi82[]ݝ픨?&gDWUM #}c#`.l"aa9IoA,BM>Ɔ}!¨_iT(I.o, Lo6ôڠ{RI(﹕_bPH-'QXz~ l [3ލK]8VѤ{*Hν oNIdLL+G6o~?^@orXrʲmOlf2溟ɛ{.\٩16dWuݴ Z& l+m9 k.=>g& _[dUH9$ؖ $qp v{c%)-ɶw]Y5L|FWI~rtF& o `c唞3]=(] D,=O u]IUNƈpus}?=;1_[d\T'3OlD&W4zh.xRΒ}9q̗_!MhYvh py `XraJTzZ xrs{"jHFvN- A k`!F hS( aftb`6eDc8Hs8uX/|ܚJ@,Y ǰvMjTy>Xڪ T7W&T]8lP? D/!qF籮X! (;X|ӳe~bG>PNR2BjP$g5{]r͂IL9%k.,c 0zsJZH+A7FG״DG; DgҮȄ'_9Ho^]f%=Y\yO+7yz'sfKTj܈0Bïm/pl8 ERcʓbHt"-r0i'08@E*i2ۑ#j Ey+jM*uD"m/1VlGV!0Z$Tp) ޯPs=RNyk+,Ag5k6,2S~Zqg Vvҳ%9%Rj8-lZ+^F0u^!AKWiUr=H^yw nvz.~΁3€@6ظg%`^iL][-ݬ8Έm$3WX۹r. 4}3c&).Y@|jIA~@Ũ'[{7Q"J̡_/9{Pn]gj42C'ZzSg'%|%"#E<-ML HcS Vx?10h5K9 )Mh 6CǍ$pS:LbiFWosZ`[;Ȯd:^AEL#eмkvE[Hu= >̵H:rij}#~80D fn(8הibxcS tvŨ7U3:S\?Н%n@N5.d,O.CҲ-V9^]4 !am֚{ fO/e9HW*(}Jh`+?uy29T473Xؾ0:N;yib?+O\n[SS;1D(l#w lA~h28kz /lijA tzB#AWWа((g+yO\zQ%e?&aʒK7(5Ɍ.探 BTqűl/xqU*,{:J.rf*>FqnW{6vNNV=尊lޫF;{|R@k#t9l.b_ 0J8X^_ RwEtL1W+X1~{u;wn5nԋg6VZ2)ب6XHP7A)WBnOH[`0vFGsWAB*x3@:K'5;$nd'^/8j9gcYs_n2(r遼B4AܧG]z)Z2+0G[qc < ;g^ڹ ȳB<@]~< K,Ez/] 4Yiܯ{tWcWq}'_x劸3onxp_tlMO%븾(:z۫g&ia\y nJ g.- KO;qeoWeQYz(͟^"4Gf&خ=g:\ֈE $$C k]is?%a/>HIH2WmqtԌ)~ Igs!۽ RӸ(vyMYh),CjѩѤ][־+8Cs̈ә6cW`CHp\Z5k&e5kK16,ز|ݡ0YF pdPAy%)Zѕ`ͣ>Rx$dPhՁ]ZÄs)+tT] LM WdZ9;9WV2u|H PzUt3">WkJ݁BO?g0}AbQNJggvԂ㡙 eDwa8;!oTTXܯ[&Fb}4^O}LZ#ݎ< ;Ykj;˝tEbZ@7Bn6ȡ`rGक़#fae!O2Xϫb6F,{Q:jDTExNmMn T{ 1{*T`M];?گҶ◖.J7F¡Egci#7ۥ15Zg|rlsxN`e d,9j7’!&\~pc+FZh| vzY֖>Q7ҚtNqpw]?Lgt%PJRS?V(:pS! NOJVfPl!hV"q_\ryJ,r2Kd& 8bEA1.N]"{kC\|vn-bBy$~ @O 8l=!;h3bb gtcF &pL$~oeS&H,D`)m >U/@T_= ʀF.U$4 j0 K@᩾T l@|J,R=UMA8VΦaBIeR)Lmj/ {@wDЍ<a"û~:ܦ~`p7m8%x~,מ\R ܂@Jo%6 Hd+q ~i$ #恡UpoÒD_ #}9c5U""O]c.t5ק8-*rƩa옭A'XSfm[4bx5&:jC~ZHG5H8=r-C =/ {6"ƽcXF q~]+9x{vIwqһ\N[忁.xI10I̹o;'\*N%¯z7~#O^cY$)}j`h"CyVr]Z(ob=_E %#K޵'7 ϨԔ60X >|0H9kk@53)Cf?U@(4#(c>:l f')muLт#cKcf_!qM7\ƒhdxSg8pQ+X;B?bnkd|czɛ-L# bfn0ı79,mZ= nC b SD1&γ(K^dո-WSUS>lEtIl_;Z Fi(gaOV+0/Ծ|~d|4[UK \Kw~D>]$bPW0 U>@xUޒ";>}F׀xt`0il6mCmȂ8j0rx݃z3>rd~=|\d/(ޟTF愿~,5NI4AHźƺWOҪT`y5e5.,u5US={,ioD`PsB.]q9Щ32CbP M0SB㫰Nt*|bڕNLg8ȭQ<ħQq]^=\#Z6yC0?#+QuSg b-@~PbcD7LXwSKDiGH=X+y5c|y@Ex%ۭux>.Eza첶Ѳep@yjM{_BѮȎN*%w*D4yol!k>L(l/3B&ݤDKS-=C|=VbW7EJI.O6RΘ W84!uU4k.ScEx PN-!srGdoA{F!LHD)gTW|R1\,Lzo}&@kst8hen1EȎiAbf/VkA*o׳!-;F,BlϛcMU>?,xNr'w e*79q#XIJʱ(`UIXc"-W[PWޒɊxDMV!44a %xty[cL>CȘ6Md˟$ z.ZX \Ʌ3d\N2حDq$ܦlI2r}I=u$ gzMܓC2Xel|n7WazŢV %?4@ @2c'''xU$EA$n]R&a@VqQA@.OP;~2ꃦrQJiSo^%/wnxN%+uh~ɡG,.!ŕTyX7eLp,J?jί7ե1Sqh_X4+wMC*u s晖|Â>{3(*b18} fd'S,PNJ窭 :^TIo X~ŸM{blGi{8}JvW*!"`j"񫐅֡Gwzp-hBmN^ 6kIg] ʲ-tGx鹌H=q@cziE1[Re;:ۦ\ TFgAD]|S%^Ҭk yƣ'U*:Cjܨmզ I?;Zq2'M >GOI}F/R3~eUiw'Y\#@3h }[m*RuӒ6G6饮.UHH%ϵS7E+0E{yK׃=>֔z#hKSu~^/%{}$$!S^p^ɓm/ĮdtݼMf'mUxa[5>}Ζ0=]^D }ߘ팋,.οơqܫ=cS?^D[ˈܗiX IW,Ac]hM ؆UT?-U]S`n$IaDoxB53._OEc,!5qhrЀk:[ Sr # ]~AeJga屽(r+ #bԑәu=#c~d5Bfϵ 4ESɸ̚$ғA[ x7NTgAYE;(v+JS?-"yjdbK6>y0df65~}rUԥJ,6Cе8B# @B|Q 1b-vm^qHt7.33a€kTr\ =i>9zuTD@'-kۺڠKfBZA֝F1/ ~)ŞI@ Aɏ/1Ej!T^0]0/l 4W'A $]l6>c?AIʕV^FŠڧ7 'Ne߿E u3mhжcvɮ.}n|R:'iԩ" Sd ZW*{ _Ե#^0Orq<evY@%0-ju捳ǃx0yzc%c.Ѓn~B,yAc{-WlS^usCp2Ń23okcdžEPie }j*` /9="nzCQ@Y,n7Ӈc (:3qvZ- 6jk|4`V@ڞ3FY g_{`ھgϛ q;;Ov2i&»̡.Iq 99 B/cv_I2-ːn@rp#Cf_y'Ny˃d-GUU͢"|8OOy/o왷z8ĭ(rD4Ami +`',Ns^DI}&Ȗk X g6\6;TlG&!m⨡?a1jw՟ ]TԎ=|!-c}/ ۃ|[J xI=z/>2$>[2y%37No/#EL?k.OX{6RBBkgx'k=y>%#sruEyHjr)ɳ56sX?',L#uy0F@ щmJQR=l,0)[ phdMdgCBi{d!l\BoAJ Ӛ2 8a-dٓ1R8ܼs%D|Pخ󶑩*Cz(YmstU4D&idSzג?iy._B>ۄ{%1hJFKFGs Cx)-Zǟ13ڂBH={)%"GW~s(~Us~t̺S[D2_V8)2 7KLft L1OzHa=q^P[7 !Ayj؇gDKR<BBJFQF9[ybsXV_2)?I_ѲsqEAd%YW6q܍RZ)(P٧p9G:n1~۬Rf$H5 lY,W{&f ȱBgxeTߕ>rU'oZa0iKyd:RU%ċ_,C6 f9Q]Ll^n0UQxzX.X#a%Ԛ30tulf ~wJ/I"&/@1 A;uZ,t©*/ׯj֊%:? ( '9MIn,.7sj()"8l2J8lI8a6{Ɨ`̣ѝQñtb^xgٖګ P8oϣ,o>8cf~>̏%&;ͦdJeۍ69ucKy_emR3-O~pn9(T{HJMy%MWLҌUTɕ}"yuLö ~$ dX)Wl%D *?ywꞩu3 UP'4E8 iUwq6vE#$8yn]`Ww 3O)}-rZ:!\F |}y`lѵ)#0ME6n 8؁Ӳ7{D-Bw)G c[b7ʛ fW)X, 0v3?U]CidCמ0j.R/EoxtSxK9Mor.aaHjoϼq|1%fRKCL[sM4+*\RRe3h܁`.Yk\w4\X9Z|}nޤb^]¼ȮVjJ@^ R/+gW9w1G( Akcy6宽^$Jqـç䧑SnWRҕ˿T2r] Ś6H:qKg86S\uvdsvdϯۘg8Fm A@OX'Z &v՜Y{|K[f9}|fl⥎s[8w|?)a$B@y]W.JdE,Wư`G3"R+QHAl?q -ps'Իzy% '* ӄrd72%/ UVNoioV,Яcdl hfy1?C+=jH9NV1$-&h?kcb.> O_n}FPQ~>0,Sd %ʫH$[2L>'4dtدR%re8w;^&ث}&`MD92oV-a 0ϕLb32u/qII}" -APISsqBQpOj.*La>Lz}Upռ(H q[LDO=Jis I^F4N3 M<)W.S?njXV'$7OKrjZB[0;~7@N3p cSݎR-}+x9q_/s#!ƞڻ9%ݭſ$GF>Ȑ +(!H6~&\6*Lc\;W")ڽ[Fc 5{SēArv,ͰK ٩-Y~{QWG_l9rA}]ή$1t'>Я&W*<c>*{isMN ߸2!0E>, ?hCQǁ 'հ&GNK(hB{6+xّR.`"  pꃞt608cu$.-ǤʋHS/ ftyWU/lE>(AlltlmF)MFMU6 $mVWحqo{w#RI>q>=4\.3AhxnC:8)>(Ƭ=T&Ρ4OM3=mqE2,j)sHy EK{Qjv5wb# W4Z0m*N T s}U*:ϣaII'n*_1FV(JQNqxKiCŹ!ޛh~Uiiboɫ1A: Å:P:1i{-%W1h689.K2,i5FcZ|: -Zunٟff?YW'؋UEյ)5G$Qu&M!4g%N 3m37bڊ,bLBۤ<}% "{4(I +#;^$Or?*HFJDfQ;#ɤ[B.*Tዐڟ5;('?0 |qAkl P?DU~3 01b5]$in@M AT(ge5X8K|/]Q#[Vڀ¡Niv|!k&\ԩip|b،[W%l,%ý_RjI.D p@WX+/ ɵQ5 /-ϹT\0@MG;F˴M5dpLyYzwXɷut`W"VѪ6X_v[ jj< `Q:>Qڞ*}ר 2+@}=0~u\o4%j.N8/Lʋ iOwR ?~XF8gkaHTyHO54-zn~`sM^qYE3۠LjB,[7{Wd<͋"󂃅LPYFO ﹲ7埵*YEE&I"ao;۾{?Ez[ytsK\Ĕ&1 &UVox,їraŸP unxB(w87kR1QJы6RE㶔[ 2KːO[ߖ;,g,ɒϭbB¬Fs;2I&.Zb޷7C_nv=,; "+TԧudZ 2ɹX߃a}PzK2gﭵ$T`cT Co P98jM[SG{vPLK nca3dEj`=Dmq=ha$}kI:PĨd4|xAE2ES v^ (K"bP>!s_OuBXlWMݰ9Y\Z>jlB[EE`vu3|!&Д; wKdd( OFauvڌ[I̢$ 7)K`0_Qۈ%[r[4iiePҽ5ֲs-_X|EHVu#A{c>ddQ"|E@2 l_~*K0ʰe:ͭQ.2br#+6|K~/by,_剾uùb ?;e6{.V-?1p^8j+ Ji/0V ݆ṚBk>(7Q3g|*UP֙wCb^0S.[-;Ce'9Np\peMQ J~+\11&Oa\&9a$BTMuY36Hfb .-r-3֒Ĉѷ 7([\@Gֳ>FY24!􉍉!]zN#lvƚ(@#FPGq%(ZEO/i9HsH#HP}+rHB<+YуH k)vS.A[mG%)޹O*x/8i.$]-Cu_ZPoB9FIdVT9I4R`tz.#97Tvq@MMJgQPu!4WSq}g \Ħ a.nw9 9-x`]vRKKwXsqP#fcSJZ "^W@(F"f|!l͇&RFqupݱ__Փ[om1vg FXm<ިޝT@WHHWAm>re(H-8{qKY g@geovN> [,Q9 N8B^Ϙsmrgԃʜ #Z0kV139_٬ `0f0O-ѿ&euqVه^(C%6|Ɓ GPOI K6W Šms- R9yp{T"EDϺu@b>^Ӄ`:BȢ5Tj"4atabfJHʵ]J?Ž7Nr$>;ZLpE(S).댮f#Mz(a)r4_*l^SC3؎3:7iPfJD|Ֆ8d7/:+"6&ҕ#+[kCTi a1+)B<ۂXz*pt1wĨ,Vò$Wa>B(9e>}p[9Nݕ|XJ_\QDu @6^XY8ye\ɮVKěBb'Ӥg$16 b^ZNwB+d<?sE puvƆ9rba)M͟_GHIm q-xĔ1rf٦lhc5,{&hxG~÷ C{GFI6nxVКjYZE/3IOcG MO[WWP4C85sJ.ˋM,,k ^*$,!BtfE6v͑j?Ǩگ >OZ >@En SIp,ʧhRV\n}w_=P˥oҲ^&&zaAgȓnaqzMFA3oVHپA[nc]5͚$J%88o]W9*{̮t},]AVsCNH^I +]-FغO恩x=h&_y̓xԐN^VPG1kt~ pؕOiiD#3wui9u_?P9#3i&VRH9曨O*մqa_-*@H߀eww& =q? u~uÓ@", b/J屏C f -r q.aJ9O/}|ke{ȱVxaRζ=itІoo?]ԝ(PAA-`عQ(:P+;w4 k_K4T$Z!b`ļaο~9pWmeX d[vG Twaޝ^]f\ł,\,y Lpl \u(ݩ%Y \Nq$5B֒Tsq?s8wܚXj92_)@N֫ve2 Q}G]o: ӊPlJqQpu LJ%p_(?& ^T%cpIS?z [}~fϔ5 v( N^!. xy/]ύ5F8n~;Sq*41.kiz"y #Xg¦+}tDIZnFQZVX?]tyEh|\sNdVl9 -JiS]RNkc=?OMlH#J)nP3;3Sw)htkΪrϚvnO.xO 7{',Qm! P]9:)2ejRMuLDz-?~C9(?~׶7QwȤKDNq(:[P q DK!qf6%4 QZ&? " #oɉNm1.%ޛ9 qӮ_AA]P*Edv9^Uɯptyt~9 `t}˼_X/nelqNېdK#-Iû 0s<`⢁j2h eeMSÖ#ڪ݊@aB}*gv(i" QS Mdy1 Vw[_hQ4xzKى2hz=k>ʎ+X/-T%<1m7{H"X6v$$q\+Tn*o/uS"$ Œ* [W>|l|H }3bnSL*}=SKIF#mBsH>e_ۮ# @r"[b '5ZDX BSIw[ZsL_lRc_ ⶐ{bBjڞ0+ F[(S. x^yN{(X4f-پ5sᳺT _F w_:T"p|NJ 2₸_&X:is>:-ݝʅ; Wt/i( hϑ:l*ܫrKVVN-7_B焂v5zaeJ, ࡋ>`R3BY<ETD *ZmZc~OWP)HIA31sNZ< Θr Ȟ,3QJ٪2X㎚ss 9(v`Ȭ&|}}bV9ߖ!u\$u+{vq^UPB6&qݞ]wtԗy$8s q[ț=c']e "PdS0Lex7;DŽb8ɽ:T]JYC\Xӛ-Hi"e*RI`Z NWP3QPVrݎ3b)Nа%WIcY28+ ЯTt%ԝchg3;*J:cjhgV6ǯ5?PA8d}'CsG}a9ဏj3^vz?GsW_m,oZlͼ|ZaWJb$!cDIz31#9ER/{UJA1l H(5ro")߳gr nn,g!3ĵ+ș܎=ˢ-6)"wUo]p&؎GJtn@ZWUgTAb\`kc0޼@#fKh=S7nL$C^*W{`|<Dc|IT{M4v *nsP]r$MLh ̺dXrt0rC]+""N١Ϸaܶn`.I]H}Fc,)D:u.N*mf$=iƹ)R؜ L\/ɩ+4:9G<5vPp}Cc*@Yd311VIrpX|X}\Z6 w ο:-}ʌac]˚,s,!ׇAO~|R2xOPr}Ңͤ o>෱ʏ sy6'*nʣ8!%ڕ,W󃜤ۆ짬6O&NAٮ b)kO/MGMsYt/VJQ:zVR/@PV'TN=XhS:-g`;G¼lAUF#޾pw~d5f=_ (D.F'%+҈w a~>.9ĮP/Ř@;_ i7ߧ&/j.Ϥ" tZQڛ݋?ƠXL51FNOZ/g7}&r-% `Vvە)=baH;jQ2/nr2\Ңgg[Λq#/6b ҃OMDbo3VF N=g[~2sOعPT(;Õ90ɮ⍕WȆY.};f % {l Bdt0yVyWH:RSf,+-"WCĮ%OYk$Kt/y ȝ$7~ jO4mA[!e`еs9 k vVE΂qw> ,qpf8 ns0;A.!v 3kyﰋ, *Ӕ՞R3 2zDpM榁#*z ۯGqo鸘r S%B ".su$SU:`4MY:^+#/_PX䳺=w۠f. 7!RxX6_A *PaEg]"_'Ŧ q͘~:)unMµ蓤EٸT?wp>5eF#'IB;~n@Udpw !KG6زk Dr!_.0kB<4CE]; Ҙ럞)b!MEFe.yWc&VN—ZNJ^l}]`ښ7z*^>h a  EK $l^s[Y*:qA:iy~if&L:#2M2F17X]zf-(GX$tjuYFj+"DG.߿-"s0B0xfݷ.gwv{5 /E\ovʒ& O{o2~֜K+ Gwcc3@mp:bfZUA%k901?jư_eҴX|Mծ *9KQ'Dlĝ85FG.:nfXBQC~]72¿ꀰ G tVPm" #JY qG+98`G Ue;Γ3Eғly܃mN߀W7$@dKh@?ѷkP?y Iiq.P+F]>P0RMW,s"P4|(xXٝiB7v P>6x̹V<$N۞%N ô}uY=Q/NSRce\@ lF< W:/s'fqĪK^q[35ILRG7`0D G3fPD :Bdnd"埗 H"+ǃf֠ԵMȼ|Gpٜ`oRw.:li0.o+rE:~pDڿu+f,{! DR =h%iЈc mXEAaɫdSQF%X%a[E2‚l5+{kA0⽪4pXZFiy&r*ᩦ\a(&tmZsAA_0[Lb'GѧK/ᐔ-Lj޽FKX+rYw[\|ASchKrW!%XI#klIHϠ(/猣#ecBRǰΪKTd(Oƶ<5U>E;H݃qWg5JmɔH:r7FI\uhԔ'c~bsG[V dn}.u #/(4OBiQ| ]Mr@$RgԪnYlZ k22e `s0$o:ls lI1Zɮh+#+>TTBK OW+/8+>0#:m58\i\M% }QHƂ`YT:3lЋ_Q}ci\nt(SĚΰS?9FD,ja5'o)7R h덉ćwCeE{7ڻ?<+kY]G=j?^Pǀw:d5m g}FAlAΝ)`{CS8mqUuINȠXw!l8}jW -;Ƈ󲷟Hl[_Gn9_MRlYUU q[C5FP`&y]fsZ4B^ͯicd 2/ZxʣK%Aղvi!I Z% p?]6W&QެpOP#6' b0BQ29йߵy+Yr^UzdWTF`meݳ~$'d̴~jr|دs#K`)(aiU$[ģuW4:2qթ̲)|zB=!$3 ة?y"?Qn/午ćGj2M6; ѓD/(Ut(\?\l"Txl>e?^ʫq8J9<5:`!.weO =Zk9Sp*%HL X?}ב=H wZIreMzZ Q FW?z.S^/YN)z>6 ߙ̧j#KUsXӎ;آó'^sR2vy/[T>~#1 (J~ahc=}K\a蓬Ke>xU`N><^scH:ŏ7}tL| zKexZ;p`V iiiۖ6mIb'-kq2kNO9;GO(R_6!+.Xk`Dp;|({VA tDm)ؼ߃8 ?}a~;5W};!{;հ1uG= W,%CMզ9Ǯ{K|0U?4wW#3Wbv5OJhZje&Ϧ ,]\AعS0iR%n Zk;8H|;}9ƍp.p͈1|ʈuoSqr`Z?+tMf]Zuk|ySc1h;>4Pi7i`EXn~ fU4(\ `ě،0^!i& ~$1u"jP& MB[}ڜ+rNmY~O*pzTőYYPZ*BpBo|4 /MVt|j3T.@{%B=ՠoBEJ ?D;ه o)xTnZ-"0USz1Cl @ @#W@xnv}Z:T/PL2V3${ vn3 QF?sqo~2\Ņ=QݠLǾXn*)Xuy_㱅'52vЯs(=ݭ4ㇴ'DVa  REx杄9dv4*X i}qL%N Nѡ:߇>gEB bTX%e"[8vQQ3$1>sm7$]hYcɳW aPw&b=7HG"ٟ?GYVל2k"r7ebNVJ8MkiN)%e8rnܞea ZbIF9Wr=W~/gQ)(93shnU@fޭ.j.TC:#I<17?᧽`q7Xq:s+aPrs? QF:c0'>R@TGxϽxdoki.6pƁa1$aJ!7CB-:ի NЎ2'[7[(UBOXϡ J|p͡j_&<>V{{aUhb {A~EY^7ISo-:=cTE%Xk QBV|X_uU"V489͠u^J^x˯BS^/x9f,-(Z'~x%;r3BSL<#DAp2 A`|í[S+!Ld:eZ(IٷBOa kKǚKpok])Jܬr _ 4ue@.Bqc I*l.^82hR|>CwD|YHΓ\ӎ!oDIP<|}.ΠVmtR_fN)\4`K /$I`8I ~wJ]?\,bk%k@i[>E͑iy<H(x^|7r_#+EUhb31-,cK'&L5ZR_SLLfe5ec nkW L0 WPS$]+8"X0xwgD@?'V}\tGM謮Vp?oQ-j!Sש!(]>#݋691rhxEʐiEkǎaǶ*vL5wڴFYyVT\oRi@mpܱ aI?8VS|Q:|(YBO>Cf@)˘Zcp:IȘT!'z_a"Zccӵfq)io:A/k s􍟡CgS  -yo2U7h-pB=~Ẓ/ ͅnҏ!Yb~n_!MI 6>,QRzC/sd4|#0^-}?<_nC j6C{N W,X\u\Y&HtXJ𹰔Pcz5".7=PȺk|Yr:J"-Jw  T0rvZSS#Mufπ~g'@/B)n{ha:(OQb$ deptfͺ1|6vR h nu0`|qzWLh,&k9T ءwUG d&E1},Ȑ2|mިP87qҭ׫@P-+)LUS*F,Z6Znwi\$A SG-6(WPBeD,С sus_]$2t/g4 w)I qL^i-&%q ᝖~qSϦD;{b틉 FlmPTw5 ' Cp' W~D )%%+-\gEǞpնR4?߆gc[qH/xٶ5g厹m&&λ"syq_ϮPѮQm9.J4Cymue%=6 h`B bgSƉ*IpJ.1)U#f Ԯ5N~vtQAS{xIl"2*\a3pwuw c,U}an!!EHxcK|~vFypM-@2 nEF¡$1e1eO5+ӑ#|}0^HH$ΝKoZyL7_Sx02ܭY/Q.3PF" /5aǵt@g4.t?VbqV=Ю6[İ܄c:ư>rn0jF.-P l0@ĈDŽB  X;@Wk][t]SjCYC2Tc-'I"Bzv_] D]ڵ`.I z녰yf+ѩhg}X<̵֝GVzG y}:Ȫ^ a>̝+i0ư8-tÁZOQ 2b{ʣDYm3 XT;|Ї,,*o K-_ o[tۊ%>0+P N47qpa %*;2G!6|aGqae/FF`fporTE|ԇhauzwא(| UAs83T.^'m&:YҸ'r/DqA%n2.eJ-2\}~T\*G/E~Ž(CWV,CKG3wcʺOܹiB [Ohuk׫ AHSo'aC8Jiv渡r@hD.`dTvvx=K϶F}=dU*LaIndުv'Wpf?-- 뙭;L`nb+;Nc7M??I ɥwOB;^̺A.(/(.IBgh׷:x93Sdޗ?&1X!YfPٷC*l[;8 ˊN=6g-9B7x@9kl{|_[@Ɗv4ҮXМ["V6gY{*wN8dJH{0 ".N}lN WLڪ댈6D[ g]r?GhmyZLYJBUXQ"jMA捤g?:H` N{dSOn:BHt8G(-C];P$"1cr_적:v|iDZf&2Aȋi;;C|{X?*e')O\]hBG/*ףFE\|o"|z=TÎ-pԥ G2nӚGRjɥ58ZkiɳGˡHSaiTנL0bȐ_*@w=nTp{[! X0C *!h5w[wr]ĝ>>LB/չ*r=21S}OL&__GZ9SzPRh˸>ճzF`VX0"X(A>̬Sp+I;-w]NG+ PCrOLY첝o5IsqՀ7d7vQroFfv8Abv- _$Ur J&CQwoQSXA݈oW +WS?"K@jK8cX7^)5DO`lOt'?]3IC@\5rZecDٻZn5A gnyHk fRmX-F{4*)JnB:2D!)Sgg /x|zrYɱ.oeVԋ;VLuF^[,Ka dꊐwKje[92O^ !"4I<[N'V]ۆSهyzſ.VW1tP@`q)Gǀ\w஦_+kv7"cV(OƹL 0]qVe^~K3 Sd^d{yӍ,2Drm{ ED">7}2/$M:tO?v 5fԱ=Ug/)׸"3tNHʿ /fht]+)کPkَ0UJϪ'6qy"#3 n9G:b~=_SetKYɁOy^ FcL)Q;ib`,E#Q4Pϒy n'/J)`׎AmmT!'_K+A7֧F8)&= cR %z}nClLy:FuV_5YZh.\w9̥F~yG F*m={X͈klADQ ز11nlUXPezé ?֜L%%/bFMMh{5`kK5[p<\Z$P/J ڡ|l~Ŝps¨'%t({jy ۫˽8dO*޳5 X+R`0rIa%ަčE̟m'e˂>\0yY ^]*a'>Idtk|(`Jk3Zͬ!kVؕhC|!bߣ9\ y˶3#sD&Ri]x"h_tIRy=UwGs5-LJ7H2+" m#–x͵K`jܵPv㖬By]IUj;(Pk#;"+?ꯇkpNE n$:'YGy2{wϩBCT|l:O1?"!u‡nDlhUvM03-Tvupuf2'K(>]ݽΣ.Y1P3 *^gMfa{%`2L(DLkXՒ2sE~ɹ]S.^QN:O/{tEsF9rE?Պ$nl@LK?o =}J?s+uP%|\ΆeG:K_q*Dx`"7^U\5K@5/廬׹"?ӓƢ 9_7 L +,<b'ܖP=xe"Nw0{珵iEPMT^D("렑 y_gf<}?n['{*$~7eNpڌϧw&%GopRU'Wf5HPCXZ t5[}WSVWʜnJ4PHlmܑ^)ئTyTR7?գ>CU $~cV \\N# p+i]x1k}xv*XBO?L47~[;#\F/q4H0 wGsS3R}t3@|%RV@޾@VFA/04%ݿ. M4=*eyx.5CrWY/yYY@jn/kL!quG{rp΢6ҮH ڈ,>5-uMyk\h3{+н[-psGY[(T2T̚6dUvc 7w L4Yy=0iԹR$Fq냈hzڅ_8zBzN{gY u"m[QT[G`iPf3Τ'#X2Q2KN=MPw<+TZ_2fW6XVjU}*ܓym~@Oys4.JEqKqɐ(HWv0ϻf>p1`tYTKp_V^#SByd@zVΓ3ϢbN(*oF;QEEץHKj?H*["S牮^ wRxaFCR:c84tƌ2hc#o:֞(6(_ gV_ @І.{WK#O7,k[鑝Ǫ~t/jgePUd)b&p)ݫ@WIR[0e MJ4'7Ň4}<*tA SguEl 9vy aAU?Z%M @3<.~+bP(6C .JhHT{U( ȏDx%=/rnw>> 8#"߹o  ѳld`eNmؐE3tɉOPWOw&^s-bnTNWc`Tt Ŏ^w}M>d-/Ka.si1 Voɕoo/ ;=g5U0_]6{1a (aȪcBK\pkiOs!}U+{qX݊J| (HܹU)Wcu(ܛ;T *77<6P:}Woαa @?!L6pfR>8A|Nol )lG;î> |76y>`XUdfہoS !dic|gU'ԬOQ;C  BWwICmf%1zY^ tDoa"nW $>]$Lq*;cs|& Մ5XMjcq߃0BTLd ̅@pa :* !K(7$Zo@҃\H.B/|66;>88VD $_tb7cEf L;PY^OTPS0g13D'RnW4q"uкM&YxŤ^?9Yz\3kJʲ%nv(a%F%Q:$ᘓ[g͠Yb8q;nsUv\'pUXH~Uރ!YyÍLߴO rlZReIdUg+z]gܙ&QOsL.BJHFxG66#E˚C]JSoxM9}NfLh&véQ-7-qKQZpCfS?Hy̍ɛi=@c;Nw-i'|LV <`5j:5r=x`iytz1M50g)5Aԣ0͂1$Y}لgzXMj{C|D峎xmf1o(?QqE ]EzV]MR| ǝyެ-^@;f† xG<V %i?V$ʌH?vzgej(C͐8䶇&N̓`zg ǙyW&X,X:Y׷6g־z$VKC3&ZpE=R(1}H ?S>ሚ̜|:@r C85ʮo[PF#ctc*yAr$É{ Xh=@a#C(6-Ds\=7Rw[cwVP;X]VPL.[LuSb!pz<v܅G{aiHdoךfXRRPt4&> S,:1%!ɿ( ".mbQ:bJ2s(.8+Yhen 796u?S*V){ߺꠃD43o*gz&v(DŕòMG3o`+vGȼ?YTO8uɊgԻ.з{㒁wSԏс춭GDe;.ڿ_{xp2&g$/A=6B čUs]Ζsg$_׌9Fѥ_%әtv?U͛΁Ocndf~ a;98 n@nk1=W6/P2*|PրUo4ȒlH!eS8LXl -$kRm{ ް6`^ty3AJr| %l8KoꃅZJvoSpu|Xh@d]JƬM0CwCWV y$8iȃ=OvotdY(Wba9*Oqķ *]BPr1{+2^t)_H7Y`iΆh2 BX;pUH),jaJ<:&Dڬt{?\X s2|W*mx v8DF7/n1p_Gt8Gj~Z q_AyO(2JT+5 |TSƅ!nKSR_5,竀BQt9b (ȨOXqyMvQ#tT(7=80v^pV. M\Bq<V</&g5j:E梂2 'k ɋbx4սR Y4Q'COʰzq2|TȂ:>uA:ǗKyCC~q)6P14K8 Q>'^RK 7Q<'ds SkҿXM#_ks/~9ilS{u_M!A˘Gcseu≅P(mۅ*:I/&?Mݧlo07:B襫ps 5t#դIݱÄQ2cL`\Cˇ,GeV`x A/ %5ޔ9F"ˆECҔLzYUvЋDImk ;f/ETT#0@j>O@J6lF"St="`Z˚ Ig/?-{#/* 6oE׭i.bf ZI>jmԍoq rR ?9gttxIӯ#&#J_an~ғlฐcOF+lq?IfJ"cIrgjGð:X9䡗ڦZX&ZL*Κ/[3Wh=RzD$Aap z+5 '0Ug ෟvV68՟k$WywnF= iKoa2\&b K SJ[{r u_OcErWX ތa6K7}m9Z+Lt\[!WCZW@!S>%k:<¯py=u.S?hTgp? ͺVamzᣌ8_4aJc$j#HyEfX=Mi4*F:#ɘWl.œL_?Br`ފI[mVC Va[_2@_P$f5î$d &:>CP`/hu5BࠚLCJz/;hM/h7:bY]EmNsnZAHBYClFd?(d]RLZBv `-Kp8p!n:l$w_>N'bφ`C֒焙kQ8&9A&'("\P4,2!l<=u pѩ3dof'׵K  {߰&mpR5NQB8bQC,Nb5[+>̥C M$5N>`Ѕ@%_wC/S|9Rʍ0 eVrnnh#|J1׷bc]6=c:)-NOU m%\IT:\)\]Z^8%lNkdcp!έhv-Ai9)ތR{!E&dH*̜upK1$&_wIT7?1ۍ'Xηf?M${2 **}J5(G4cUE …i4S+oK9-no[䝾9cqS(Rv}yPPa`=s߬@| bWTس`E=OڏG \ vo-挛-b(T>^뀀xWk2HpV?k)DZ)Ο [1A9j7 pf/ CT6nqlkJf&J&+(i]:I(MVA Q"c wH C@hʡ-Yln8K߁5FO]ijGХ^7Yw!y׶@vnDQ %-\ uN&K8R_:^Կ q0-+IDQ5PCJmL ira0,Fۗ 7Xyޖw˻Rx42^^<(Jbm;nD>\EdTKTs~a+JgOX}xn?̩W|͒蟋6 ܢGY";L˭7Z `~]®:F ax#U_I39[>IWd{k㈵x˾qTY;^C'>w6CYwyvApkG;[l})M^ U{%T)j:R/2V 2۫v,7UH >R Ạ$5cjk:9&pu?^`!IA;z| }[n 5nWg/O PKHq(ݙUB״*2Ӄ%Hn~ 3iWRYҽf"_v?ӛsx1Yakvu`[6Ґ6p6xo(UޕIR'%(Tz*4EkFt]3B&d=k[`Y4cEgYNj;}MEl@7)Ef`XAnFQ\P'V!HMJ?Rezo2/'8*(=/$tH-Xc% T˝7z萼I4Rgkg`E; z C"kLj%&I wz ?O7K a6Si?7P`#Iz-W41XKhWeNctO٦)Š#:˵ {y`b v5.:[P (L̀QMGk#^~oN).cPnq®an% k?=]KfZoAWuOAy]QGC?^PQ?/Cp9՜  x\)G*/!H0%J z=^7=1h%c"aBPZ7p0Q& y^;`4 BQ5ZM-`t e{a ^0ΐ!\Z85G'}" s'U)~T!Ji5 as~MtX@On,qVxnޒcט6,b4?]*q4Ǚ(VZWb!aBWhS27Lمz"'V8/\9[|Aܒ&UTiAh奩p~Q92s@4ZG2gT&|uXٺ5r7; B_.ĉaBw8_KOgVn_y|b0 x $T`2qv)VQn!}l&QWOQSwc[& hLwft?HY1S,#*Mz#JŢn_ȕM]2cQL$~9t{dM%WMƦ/@n=A= Ev>}*nk^(x)FX#@94#ib8J* ek̀:P|>p6E NukE<5=\Ɔ;đ8$Oa`q^ ZBf]t8p K)e+˕N١Aڜ?}4/7q{d~^<;sf=*d+O5#plo 62M:'Rwy,OE۩aC6yϋ`swq_x۱G(ƽ{ @xYGޛx5K֎tE$]#vv!*0 ç OhVo~`7ЦR5!xCT K``gؤf %'I[s:{DyOϷGE rh)={hg6Bl.h#zZɷo%o&²}"3C3Jp ԛqR7GJvTՎ5Raz+&ъbqɹif[GQUиoj f[Հ|Mpޑn$lK/pr-&>%ȾfjxsnQlIˆ0>ta,Ѿ˝)Z(H`nj|WoSD2`i5*_*EBd^=>`̞p=K̦IO^_Ju2;Y4MO^Ъ!XZLD8}M_7r2VgJj4R)3j`L٥%#-OS$tGȘgGCʩsZhr ߟ\%.|[B6Ix6y{U17n,a6"Ҕ<FL)6WJ *Pn[,@T'J˃cs e6g M`"4[BF1C1IghbПrF.{!3SE񎬔y GCV: ѕ^5PE&D?~6gc%l=0dtYf|{%FA@~rx'dIFBc!Tj}%Cϒlz a%n\Kg:ka?/|1Ol,_lAؐV}:]P Q3'5ijt%+LE;@ wX_*kEFN9Ҥ0De7E64ZT|c4K$@(^D-Y.-pƎZ:{< p@SO#qE,!*GIj{2&aqWs#\e#3\65J7aX>>i>)1M 6M5vbE8J^ ۼrܟ`Fp*>0O=ݥ`r 89RukC!* 6]Ɉzm!ޜUtvv6k]iytEnk8/RV6_ &Px6 75BxJwɪnm=~Q` kc\u>̕=GZr0 {S+nr鉞gyV$~憠[+n)Răo8YR;7⼊.mf2xRhʓ8m~]6jl2MPŸAK: t>aL㵮6: {9o1o{ۭa1kָQM?L=#^^n/;P Jf4w;Y@'"0|Ut8Rl/%G\Rea4L#7롺| }EuKjGb8֜ ȣęjL/ ZJb ]-7(wgG/1|F`AxQnun[\Lk}/#`j]b,Dk wJa03 ⫾(<uYOU-^>6q6i4 AjV1 =Њsp#=wBT̓mW?~;'~ɄFB]o~2-QZrע!2lPd~Ť:%E {ib6 ˚}T~h@,U.*w`+\=f\ԀUTA^_?7 z7J0( _ c ydeb Xڱ 2:_8mSeuBU8a>{gS]i gz)I%޺ B0g 1A5+;f/Z|+F*oZV3?+e &^;kͺ]hdƏ !%/9v3j@;٫NSL%a\7+}dbeH,;md-6^e 4+KM HpGBqgۋԪ5i=Lg|'U\>T2IRu??ڼ1v(9()Wg?+hޤZ;J8ahk_0{-I'/3O6ls֜u.“TO,UlgK\ʖEu]& UQ(ľ_@y90 qkVCYR .pEŇJΣ`BJ# ~6Ia OD3/[q .ECu_=@iџ5uM#՝Y_G׽>*B^RK8Y׏ \]DQ5F9_HAQmWi9nAתAE!!21)*1wCLE+FI>>(twOP2>Dp5s/ho>Ԇw?O(>]V~á,\{ydU K1$r uknxͽ^9J-;km:U?Kϒ Z;9f$dt1!Ld[6 쉻ywv'-;9$A8_y`|$O۹(*D_~1ݵ v@&ji鎽Zv؝K EZy]s^Et) Ƶ]NS=t*~-k9Ql[ާyH~:t8rXݏX#Fz gq=1g0kwh5&mmI~ǃi:C!Dc@"nT@"U!, :~܏#?T1P,V`4wOT==y^8,#YyEx)7 eD5f>[VH([6CחKQ zqs o/iHrBq[WPd Hc\lCBa,O6+7;M0zoK1 a2aַNnA'?CB~}hjTXjU?^ݭ.̪Ӷ0(:3?(_ш)v~ SB8IUUSGn+I5& O}1别q,mٶ)CZ{~ҾIÏG֡vɩE|&]gX9ݛW 1`ޙ(z _%Lni9\FG` 2JS8 nLW ׆I8!Kx6Qq{7zyQkN&hD*U La;Y$@k*Ά׎ AťT' vxA-~(L,ͺRuӍ4/Τa#A=ʺ7\,ltj#HcZ wր %nN,%,_ڽ}MŲVٌ?5}\B$yyQYМa0^PG]ǎaM^u %x@䤲Ǡez^g#dvZi^Daj/OT3nv15A%O!޽.T󦾁| `ܕA}3s/q>3}}Rl=^"re4*O3HJY3&ܱ ! 箻mnY8zU%#r)K}8zBś6X|b?OGWr RLpy ك}Z&VydĉIuikʎhEl7jLc6ˮn>Nx&bRa!OED?0֪:}g5UV [P(HqD)T{ى]2q/)E .2!zm]F;W} b74պR[=6' )<"P3pn/{t )`)k>粊Etc@keWx7J%ƵۣkuMwɎL6l*(sz^!`-Pb򫦵Jӽa:\L7wxgjv@[j~)VV3<'qt8R QϿm) ˗7R{D۵܌ow[&#ڶfbϹ+!)XK^\fBz 8*S1[/NDa`30H=W,,$R2|7Ɓ[3AH;sgM Yݺ"& tbw&y|8-)"4Xy^|s񁙲M9iʐ^Vh041\gCS//X:y[J$ <>8y Csn  jTzZHFĤ$طTTJpȶBP~o Ѧպ}t{Ԡy? 1~nr3>+}4u"3o9b >! W8؝RWϩ7(4kKX.pwiA3W'_۷O5%{Ј2kvzNV30}/.:sS=[sܳ95薍X 3{L>.B+$ X^pKjP4h׻zY6 {C,#4[lRsKLjx$Fݮ`+xr_8Z8E?,@硫52\\a+1A-eFU_fژnO֡&Ik}w dh>͑{ Dw' 諾{Co<^7vcPtjBn飗̕%߱.¨m?N@RǬkZ/m6`xR57Z^$uS7J~zRFR|bNݬJ_`3E 0D7Q)O@Zg_Kljb>{JV{*Kk|IT )j :#16z+zd ;{a.7DC\&-<Lutq~DIhOo`w]VS):3J㪠斬SKP +jcL_>`J`?g,п٠A0@L){vGR5w Q@ӻ%b OvV=l#!f?ӴgtYhw;JF?XC x(Qs$ލ.ԳT@׻΅ 1N5,GFe6pOAQvڨ_`j4]PZUėF*ي2c }LOE8G}M4n3T ]r|B:" 1V kQ_ſJO30%氭ٳ(}2:J/_ `=etUq{~I1POhZo(iTW>ބZl"iH-:aӵ[ ů_p$[AS4Xraz?Ыw($ *?`v2[_eiq1Flw"u)nrwc1e]{WDf`t &]ʤ| ==x2wCR^tP]_LXQ-%Uqe.C\ AB=EmeCcbwңgl;#h mR(YlBuTqEPn$[yMzq!2A3C[{HU!vWFuQ3Mܲe~m +م4tQ 8uk6ωU&cKM-Z/jsUA3[;]}ڸ(*jS6!V +cD'A*'V2npk#~.=(&=% C\k JWfWg-8 h.'8FP3 vM0| *?ًya }YgdPKwbkFU ѓ?AoF93J }2.e֤6[勹~I}pRg5$ NӫN/y%5&^ІoQYL@m)f25lԫOŞ8L&*1CoiB1᰼b8 V2=vW Οl.&tOQ|1+# H<~Ua{[k,X-I@( .* N\Dnt)Kn.rY‰=$B!:x ~de%y(v] ?ZpE2z*'"=rs*/y?tu=&e֎'n9$``LF/=]Ɠh D?йW9hU8fr [oY>L=@NDk GUx>^ cCSS*֨`/=V& R%YyebdQLc& X?E<Xh]M!AN|z./.Br>!h-"T*4EL8zHNH5ĪK&P [Oneg-dP$ ]iiQFE>vkaR(\DY:lFʁ`aؿEfzŌ&U.w۞lAau=:};ʌҏb*Cw~2~8VD~́L^t(!A<' Ό{n`,NvTf({ʴYZw\}IfpD.ۄNNu6M-ldU1ҏ/kQwFߋf`i-N:L .LTSr$Yg+ Ñ +?5x(-u {ed@jg ֜Nye!_/CPmJ8f6#Q jsb>TDX>V0J1kXж>W%mz]jjpDYEIGjb9Adi5Y͌xu`))qkӐ&{n:Y'x pATe(!(1cz` />FvMRlZ(in'W#Uo۔T6V{.g-RcxRɡکKT>~-݊ <%(plqfÎL璋iK9V|27g^ej2q)c)l~B>w$C+l)dsl6_i1,B?h4B׵Nѣ c%IIuYA_A ǩ }aA&M"A_Rn &`Ο YV9 j?D5}MPA Ւh#qA?qHbޡ#|mJFCP1z޲zr'x!:LC4jn6%_KgRWylbK_{⏭u%t.m^/ҳSKٌѼ଱]ˢp~=oX$ET[:HCe%ߦY[?SݘMHAt ,N-Z0TԠZC.7Lo?K{-kj8UbR-rg©LOo7 Xy Z^.4Æ`[ՉMJc̤_(r&L ! * mXK=NZ/w 'Doϫ_¬;%,>r W`c RpB?Nv չw7~)BxyfAq} ZHQe.JS0@Eh8{4xBv4Ife;DS/FWҶu-f{/hw[2JkN_mRHK0lNΌbo]3qGL70Yc.k=qwh<":Zč!D/gV#o +MXQ +nJN}-2슍HgA690NJt–r7)Ϋ_D j^Ē]k~H e;XPc M8q7Ю{}d&=ⴥ\)1; znzh* Wi_s*#&lHH3k3'9Sex:"_kށ}N_Eպ-v=Vmmg**νY_3Ff|7*(?X'Œ6/2'񘫪\BZB֎F4 t.~=?pVoxh02.DG5d (|)=q@Py[㪓H(yJBVvB"%;NRCBםg> ژna 0q-HkUlr0ڥC^ @-hOaz>kV :y="MP0V/!03wxꔻTAĒ?L~ 3A_p@$8*JPb#p(E@S~$"<Wፔb_Oz​Tn;&{_ 0(ܤhηWNdR3("<8ȁ^=_ŬS11HDblT?,mҲ41pcu!: tsl/#sHm^|bMC-eߵ4_*r!/56Qm[gKU,X^͍ۥ2歭ѡ̈́{b C`8W(Ow.tny4f%\E*:bkk5 Fm/j@oѷQ mpN7^yWXMS20nP7rB7X3V?#`pY (zvG׋5AfQWfh;!=r̿S ջN\zՕK˽DzvfAa/Pt(W _1:EX݈t[ʼnRx0fzI0_͓Ct)?O00_'yK+MVO#Yy)-_}aOh2FFujyPӣ%E`B0lSל#;CHBŻj?xige{c16sԓDbe -TRF|]8{ A+?ۦv 5=S< R]uJ-]35?nDFS~ئ $#(-Q{s8W|NBެ<ٖI$&ݩԭ5Ȋɛ)z(wwlzuAU~*@ҏOR+rC_~jBWLҨJt}I OP^JA)<]RvxK ɵsxuUN&Mޙ10.Jxeگ]FÆ2 .#(S_pV(z=NƖB/3(Wǝ|r2p؎cñQq~vߗp!:qCTO1vt֭ϰŌXcyC~d!Uv &t-f!P 6B9aXJ ¨2/x'Lai)>6tr ]48ӶBҖkRhrIQXaeJ, dgbkW8Ū@g@$$K#`@w*3[HR崪&؉;]%jn]Wc(L]gQM7I[dh6*i}JA|{2RuFO^Uj< Xgz dCH[3VBn=44yy"uXc5)y|wVq|zu8ikw9̖9K·h߱RtsƇq7SV),}ςs:\:2=s+hjn7&7ҥV.L62Ω4H9[ Y6=]qiJRL@[kjh1I3Grv|GgvKX ]dFYx7y%iOL]*h%4e\<Ӧw-볼*E 5ƒJhF$*b i=~cN(1Z$&Ad %d 3BxP|oSM r9tO/'٭GhОUP^`QW;ٹ.χB=#Y]fz0EUVOK_x.}M,NOp5G_tagܜם6{&'L,ݯ/~WUOr6Im-~=+ֶu'bi4`Np_6w>w 0H A?!f~I@WhWߤ̺뱼-/ hK}b:F눛9-"ԘuB .g"~EBzDJCO oä>Նi}/_tPݿ^>XJ!ܩo*8SíEX=nKwDmG[ 7G$`CR6! v}:h{CF8od+e:xˌ@IfF)>.#&3l̠V}Blֈa QTT7ݞ6Rّ![:ݶ˜XB8}~zlJ©N>PVaM6`^hek({*Yf\[qɾ/{4h=*/ɓk%OOpU~C=QL'?t;^GΓ\:e [pz U\^*׭pzgF8V6R?(>0Y0igqZ;4a+t*35$%9}I=aE2\7yk%N7YQ|z[aEhS ևăkYxbURz0+f^cݙ̲7G/#g?kY˛A!]{nk9N4<5"5aw1,8M.O}٫Rb1OAL/Gv@'14 ufhL(Vr+,LWCU;3ɹCC.UӯHQ~DI ~G? eD,@RxNs2WGלt* Ӧrf>T:Or0-$qCPV B'N#93mV7խ 6H za]/!5/Bl\-wqk?sq׿/WIfrIP$k#ȋ/}HU"lkou(j(hЍlx$[ѿ, ` }]vO,vB~NqᜭA^j:mSI;y Je$T98껵BW,$D0#-S]-W%꺛b>t`i&dc*CZ0 TnOu8>KAx2tv)*P!7a¥r+^i15-{T0ʆ@^ _|`%uug \Q_ DzȦ%)cW(#BrqAct^蠒dBpJSF0 {5$"Ĥ4ܤ(⍳#g7R};#KV;Α &@ cCUq"i\dU=j$pL%9$vwqb]YԹ$VnK156~M*9]:U8z ejF^)EoG>/S ~&xեk)ͱrC0Tan\x [jݶCqs} D7/0dʷmP]H6& !lZDj)m* <׳H!$kW$Mjs%%%XFX^#]$~KTLK"n;I2c~/F([ǨXXay)ǯ܄EKb/NFM#y5>% ԓǜO e)-"`GHtȼ䂿Ly 9(sBo7VO$y@WF=$#▏ќցpW hI!QONc}vC~l)Ps)}͘Θ\!+FF4^Ql57=3bKOh.N* g'ֆX'QJ4{:΁KKǝy~o7wͻ6vT's=?l&<D2ZdrT|>׽!Ft0@[(wGduW2cM$hC42X$ERkl%$8;FgV)$A{ѣgCGGN-k-¼0B}Y)[Kx"d:lCA1yb]3YƆp*Zt涹5K?áUTd[> 7uN/  uɮ &rOk=΄}e+H3-F{X_\T G6j=dcK?m a;xz.A ~*(;7PqB`*' 6\_(j-gs71ZU/4G4niwOр\U3}W4gX!#-jntFgr>7>FZg[3޹e,ȶcay~8|-mzrA#'qAZYFK"`; (d y4~ n,n5>хZ*xI4}Yk /MTӳu[U7Mimr?IT 6/Ln7&+qZ0n zQAΏ̀Zm ^s1 -cC&[DH"WtK8@PJ/"SYk-!k^IpEEbr\#94k.5pG2)O#P񁯇T^LPw_A.*5=_ 2&u?RpuUg*(-V*Dڊ'-1g^7O9LOeYp_5uP\_UC)5Bġz2?2sP-/* :XMrQY5DWe HCV휲PI{|! ȳPRNćt/9=If4a96[Yr`а*gSJ.;}YBfEe/XIsGܚA^Х`!C=313F/Ry*j­9jZ3u9#%:N<٘XcA;V *uQN_ 쯴im_aJؚfzKӻ"6[궏?vW K]!v"^8/Vp6t 4_19Ӛ0P~Ce=8q2ѝ{@tj'ZcE m#ph˝]y]Ngi̊ݠ*?v)+JH\H\c~Z?<TxY8((F#@jeaK* K:i)] <_p5"&80''vΘBƓ"Pv_ų@T~|u_ 3$b%4jmo \1> &Ɣ6rט#^Hph%%/:6qS~V/xcK|lq<|udGxѓ=T45$^|->vand+XiF/C̸egYۼ\@Aؔ*,UOW~fBwGY|񑞃UZʝc\8i܎Vx$}pyZv-GZ/+sx#er2ZޙH5g/;Z:M{PPb٬L1H?5)ia= FI2'Dz:>N6S^=7ŜJ˾c{3r5{q^X|Q~q6EPw<1o!XE\w>b0,H!>|3 \f0 *B'q]!W>Kt0͗iC0ɖl^L $@rFC([`KeifKwIl4j(Vh؛3|/_o1Iӳ2@Klh>= H0w>pO#[99f^R }pKb(D:a&$P9mTpPc&Uu d^Z@;5X9%mSB yDjoaXF/lZ.e:)c,vSP?s^n֫X_yDDO#h_.LZ8noZ0yKg)^;ICiШc֤Y@Uҟ킢ɛ# rH'+W^,?3*H)<0ȁ#H#m#mŖe٠\j˺Ьx!qUlO\#D*~}rhM4R^\R f^z|>0i,H|]fvAy ˽jWe co?<0`'#q /4pyګR8Bpu^Ql *SDw^:ơ< /Ʊ4ݫOy(m%wNUa.0-ؙu EY) <;5 \ޝRkV%'PO#A;>[{֚~3뀕|f 󽜯la^VG zrn4ڴ'm*RMQ4fPuN SI kN;7"Io g]uëA4 m\==kL(ܱ 4)v49 !E-\fE[$K봁m7g!I] dzwͰecDk_vX[iv.QƄ^7\l`fG}5~:u*k4$`1g4^ ?o!:|b@vNPNZ1#L eU D n?-l'iX\ߧs4,lN-$IrEly~|nquPWM"x,`5یN[02bo^+2vHK.?>y=XD`HSbJ`% QTZoXm  Jaq_r}*R7*F"KŽbH}a x<U3%l iR<sѕAP! wMqtf]nwG b9yeMYjВ ̅oj8`jī=y5썉/FH:|v <`y/^{<^意w~PQT{P4{BP&p$V4'ʳzfLN+ %z{zLQ] 3wȌ8Nɓg]xrN*k1Q脻B2lÏcyg4c$b.islvKD]-}?[֔vX__*Dvi,N B{| EݔJhqdI"|0n}Wߖ{;G_FMÀ4 VݻBh},ko]MUV-66D$&x!&@:sz3$emN] S]b잙jcUPSP_\f\WIPb_6Gbf FZ$_Ъt"/gq%$sF@$_Pz󏁭( a\[|n[3>5Q$&tu?b>%Ґo, .F$ەW}SA&i!~.; _G8sN&ѥ2^nGJ"7Rjg8QԶ Jg%aiN_<vAWo~I*3V]hVMtnb`c πp $}= wo0yOBt I8SwjgLl_lc~=x9mˤ KWaB$TWw)Oc]B*#&@awpx^ˀ$'6 ldSPqĊGt !nEpD=*ln U؅m2xet=[ܺR`nÒi3"89?l%R3n'kڀa4GorN\(l9(:^W3" Rd\\36M=ͤWʿQEi)!L)K*lŔ1$F"e(K-e 6B , q byƦ_ƫiH_z9`FfOYYj"WYSF 6!$9v67Y:qCŨF/o|&8Ax6Mn)^ 9n["\5p٦U[Z= -7=U } 68p6_e]>̏PyN*Wr' =]Y B+k\ wY&2z6e9KJ\KTrg"@2 VVϰƑD\-Ubj7.L\lt|@_[i8%?ΩiݦcvdHeFaj-V8^\FEIٳfhy6OUPAԻWCݨ@V6\̾/NwY~/4i5aZ:6F:]^7dm_P_,2dJ0HT+bwyV85`K^NF\-Cp`6XiR _/U4 g8PX. lcT0v@왴`tD8F-))'Z׷I9V FU83ޱOHo,!/D ϮU~k4yP_ &q_DO,Ïcpd%\[J)v=zwb >.3NB+ALlG40B7%x kg!ngF5Ih@=$C(vˀSR; 9BJN!Ϡ6N=ʯЗac3>o9 }E5΃#mgn-ѹxH^SA0n)1,|F+W`֤r!44 ?dps3ɐ(~CRwELeN-@5R䇕/\s,BؘWLA]kЪ8L|J$&ujO9g]sSJ'"JܛGG< } rWhQv~{7XS!PA@ u#5:ݑf5 p8T649ڀ 4kVl{.*oٲ߳T͑O"WEZYrGȣ1FB~`NL,l\t}e.! b7%yz xM^P}0SuoWf6mѺ_ψ9eL18yWN+fVlIVJՇgP3ԛYkuGBK{YB ^=_Lt Q?)3v{୾Pȇ֊n, ?754=@nn`[z3 32+̯2~EoA>pX~> ܔ$(84'q[8s/iBIލUbr - FI -+8Q*+11aF .a:QI38O蠲I$MmM[ +12aǵ:9)7骖3#llZ &ؑWBIWA&⣄9TE-ͷor3d/ M7m גJ*,VG5}a4m?`B0@ǾT}Uv?]]ċęu;h ǽrN bD )Nێs[I"! xE 褟q|P E*OOD,wЖę VrcQdb}IWS_r2&ۘvbۢ`sm@O[܎K͘Q-gÌżqcٛ y.oo=mwZrT \7?f_ń.Fu}-grP뒒glO$ ViN'(e]/)6')"D80??YAl2£(fgT:+5 Mqp,7t|U7K`g`zYsH*DTlDo{M(F9PPMh.K"}vMv⮹D2ƑBktC%DO|GK{uM[s6e/~.8V|.Z) :19-7H=-3,cJ{YX^J9i&349DH$Ass:fr[V%BtaU c@X<`z2(b-pc^pS T@ nܷOwŏ cvv\2Y^C>ΖĖx w7?|y2z sE^՟UUHHOEjzᓹ'Q0ȑ]5H8PnT/4,6Vd"EHvOnֶ! mx 穞lŸĶƹͷ' Xqs%UJl XiYtvHH I@10Ò/Ÿq 'NN3jA4&VyA/a5*F%$vHMU ekLawsŲ;Yy3<+WF!jŢXv3qҗ&.s`hIwWr&HYU1Wv;Kg'X"Y8_tOF]nIۣHi@ž<+<Wx*O ?c߾`I]Lϼ:']4f([U#~+fDI+/8ҏШ( 7 ĕoW{򨆻Q?D:Y2ta+ u`ʠ*>/[IJSsWkZ/.͟3BY~]&t'Wu7-Ip7JLS^ 9##xY!?v&>~zY\/%O4t0`c{^+_k C gbb7hxq[ RaT:t') r rj;Ԟuiq\5d!۰H9j E53 z+sYᘎ5MQOiZDwWc:!~}Q1KhŘAsFs$9[F|vrXjk"^y䩞 &I‰(q3 czMcB0,vΘ& (QqE]oZ*/QaN)5,ݔRv6Z!X+&iFbA I.Ba2^,'*r%607s mv_{H*Sz⶿"0 @Sp<3U>TGHƸh3)b(< l7͔^>6}vN |/{sVO,\-G\ G˲0!MsD lj 9nw?cΪNq(ʗBNVEAXDۥR.m#bLY` qxTCpCpdyyG2;w$0|"Mʤu|߫vt,6峣h,v)]p)k.] o8J]է*,^&x6,#PGw\.夛kIedKW[@UHNTn)RrV]yPDznY^>}N0Pqksh1-_i kfu/99VEHbjSvlyWStWӕi*ՓW,6XR܌(d}j_L3AQSKUi˃saTx_LE:d]ONw )$XqOuɚHIٰ=00bbъd/m~fscK jƒ=<[93T]49?4,8#Zts8S[~5LqI\4Z+|m-3]虑W.IoݳwU53#,G1~XSi طz|' M5an;G= Wa[::Eomfhi$À>*tBHGܛ/ĩr쇣""R \AP@WMdD()Ki,GɂhLL{#tĴˇ^WyL\L|-fe뱻R9Y & ,-I%g,61=&uf@Gx%ؽ⏕dttzI@upu'$"[twhqs:*W߶To,%`/t%sd'{mwNcD[Cِ*^u%B2"r'=s<Q*\.㸃[&Rb=J[ra>9wƔ)הYj(LޭmzxŖ5*F>u7ʐDܪqH~14謅im&B+ $5onELA~\MFXyk!(I$(L(>^wE ]M1LhB wcS@g\ &X܃q6"J] L"cOFYӁ} }Q$FB|HG;YTp")wVYZyƌe$!\Ա Dfv0,)[փ5L}4( d8$\z^D } =f'H1c ,Λ3.W9@F`e7#d~|ӼdXKwk@vrN0s1 ;[S0 RAtÁS. oJ]^:,<f*gٯ> 9YA>*ĞYWK} 8vL K^_C!$Xub[$;e`"trfZ /X/74ژFD^uڞ*D3 -)BZw-cB26^M0rua`S[TD?ܽ0nq0%u&gk)q0`Iɤ?ϊ֮_\3Q6c*e|)N/s,(?x@CdBת&<1KS HJ?)A'2W=ytbT k7z'WUga߫M J2&tP`Rɯ>Z&x {0U ۲_<]öŜi4s=]; ?#U².xm[5WG )J r'UP]\!פeK%5NMd=\_~ۿ+]:'`Q|=09HBEߘ99Er.%Hqݨ&QMRJ};ShPlk@@mb6Y0Cy(-G^Eл^εRkͷW΀q05dEa\ԬAIh[{.UPb*>$dHOJu TjCL ꓢ ~Q5Α}RCZå޿-fV d̠(Ck7R̵9퇱j, C C=K( o a$DO*j?索WK r[]zrV1Ffc_եk1m~6i|xaNр4͟6ي@9[z z]Lkc)NkluNuL 3\kऑrh']h>ΐ !}iV|0#sE|s55)<.43;ptK:$|TGԟn U$'y4_{ ١¹LJr&^=ӵ @P#$۳В!CzrpZOP׈i#kK4zb.:7e eG"E'q~Cxvil#Tj4MOHh #>>hc:j<>B43 T:uӹ+D0n6: 1՘i߁k:BӼ+ ӚY _.%2Z_y):gѾ -A9BZ0GXf%>Ti"ՃĒKS,7,Xe}S5cx9( ]b7*hČ;V2ǿWe6dE٤~ nCDEru"Kt«X/~̙n!#11f!k>r״SBrځDkD{cwī TEpDd{QzM*c$4/cXV wMnm״E`ՁU_LYbjњSc2G^S 8a+ >ڥw<cF믑L/L[k¶Q&6#i>#5K}ׯ$0ˉ*%38ROeJm:+x3C#/8Tq ~(bF+0Oxbw@NS#o 9Ѷ-.~ٳr ^0nPV%o^_~='Ϳ!6EJuߧet `)Z˗UNKѓ' q/%윴{.S6x4F1? Ǔ\jdoV% A^dB쥙h9,|M/6'u_m[fT ėifrSʍeDoj%dq9ߧ_}륶:|<%<ڏ(ĸKX2ƶ6T]SYʽɂVF( kDV0y, ɢ1  -6}m.rHj]Y0[vٝP=*Ԯ[9sMA7ɫնռekN#݊F-GMLJ zab[V?$ޭHeAO qRF^y%M*#z[ZbP09|Y.bOD\w4Ъ jIk5zӉfʘMUS:]WWR0H@#Yh;C\p'IΜehJYr)PsO65hU5ȦGqS2@sx?t T=+#}(vMHjP% /4- Lp+>D `'[ ,ifyBI'$% _lnuQ{MnbQuZ%[ H^n-M0CHq/瘥'N})ΉUp ї`kd2`Kaakb:+9murKiYù:(YD\K qVuZt] W0a2e|d 1DU.ދȒX)_LRpq́_V[ǎc ?TvY {2xZ-9pˁDݖEuF"l1.pQ pEYt2ۑ7Ȫ00lƢD Pĝ h٫lsvOM XmFOTrP_ujR byl4>Ҋrb%K|;f6]ۃaHmDQ/&B\{hA4{=v<+us"qNw9[hrXI5rErJbhZfR0Ld2*O> F+ WJeZ/sigW 2&Ha.Pkϡoi -/+mHud3>xy(7M>HOX.k6r{|5Tv=vFf:VYbS* uj5*! 8*󋇰֧nsj#:P>V}U^ڙl9E!&sBH xZZ  Ē=Ƙmrv/|[cF?Ss ZBBn}ů@HxmEa {oQRy‹n^?[Άq׍$V*bspkȐ <.?%& %=HU?K|L\*8b4 2VPz!gLنbiFsfΉX #|3GXK2>8./ v>}q~:ydy7`kp|Oe4KC7XeN?#̸'XNWL:zj/pso > CWn^qR޷-,bufӔLDB 3g`voaFEVQ6..2d O:UQ9ay$gh,х \W\kQ1J4W֔#E0Qi%I:O9|¹b2́I, ZȾZ2TyP̔%9QA8īKRp8iս9BŴXgw?^l|АSd,/EGWRk؆8"܌`xdH,nTtxd.G)ƒE P> js'bm]Gxl[ cP_xB?&I-﬿peܿH]v&pW^`{gQ3Bb>rԆO9X `PglcZóbf#B+u( ЩNhjxZ#( +ơX7LvHXW gm|3=Y\UĔ?~9-adco6_7ZQ#5۾GH|/C>*Q^e|M W*\ j̗D0,Q,9KC}!:ޅ:<+- ĮܙCg"13NPT,)C-.Xd&II,kqov$>Nccr,iS/zp#iFēfVw׭)CP,*~JCպB2xr| (Iv86;mj 9뼒5:jœIow;|ȕP7f[E-zk>EFŢ6q s3uDS4+Q֮iaf$ l t:)2D*H1O]o "͑5F2nAzpNQ1,5Vz%+Lzmp "NPk%_64Js>`ZPav{Z{ -\y5!gPG&NT LnΚsJEϲD,υhmV;ST̐s`5Ae$Jj>tKIBq/(B7j¬L4e|]:qfjoxDj2-a-Lto`S,3WzÜ'Vs`sc5܁ؗC> H_n/hJ72OsXW=ιqzbZ E dϰÕ/4ja;^Z ]\5Al) P ԞG`W:iR{~# isq ܛ7F/$Sٰ%$-13̃L%Rq@ ^{Qu_ڑҒOeX{-q?8 W{;iɮnDrE9bt`]<>Z]&|B mU c/5u7߈aeaxu~{C/(Gچ<Ü! B]:FKSõ 9c a)oWoGI 9C˫H 3!)Ov+l]2YЕBaK|j~u.>JЧ|Az* (bNG,9zm#T!h#XEaTz"<^23c5Z"́9 4Ī[*P싅է{dĎp4'BV4$YBLF6[dJ;ӟ >ܿuP6wPFGPb]!C\og7ԏNQO=SR.>jkSu"%6zZb蝯}lMpv+E!kVT$(3| |\]8|Շ0B:{Iw_AG{r`ZNOMA>FV+>;:JQĨlGPϺ9jg6u4LKL;}Z:1,m;Sy,/r+wtȢ^}اvCҤqYk_r_%Yb!JJs8`j!y<-OoЀE7%"-qmx"MB(ϫGS:z%Ϸ~FK7X(/D~A}y\DѪ6pԛz_D;GxvNܔdE;Y?ka`y06a[5`Xu3~ ̍]Ts0RVpVXz\~n"ҴVўB0ӳ"QcQ4ZC&"A̗ * 6X`}mLG3]* huznB̲͠B_ v*>ykيlk<t0N8}[~5,!6PW1%MEa">C6iTIF@בE7XG%r߁u/@x|':'bO=w8H2Opȭ6Nah_+""DS<mtw3&JOXygɏv{InpZlsVc_LyNe2'Gyp flHT=ѪXCqu°@+[.d[䱻e\ yg(uN[<&5ԏ^2r ^G=Q,-2nnw )PQ4ϱ~UPwMlDHyj); IDsn[h tF/9G+7 |TAK11'1`l=(4-dRi#qvZ֢@D4%Y@!&LU)LCmAסݖe*ssGz:ta1Ӥ+\4:oFj >U+GJʺr~noGr}ꅱ.ZDݬɴF -^صsmY㝌P0"X!k jA8Z1B\΢/4}V ;[5~?0^h,u_GPzǚuU<ʪM1fE-Ah\0Q؈Ƥ㚬՞SS'ل~r$y{8~zkuI+Tj= j4"%h݋-z>8wE_/ɼu^ $se8Ϧg_k !%R3(VyklAI7okdWU˹[Ep)ALJ؏ ݼlک良c.聾,;-~e D/"FL*};c↲ {E(2ތAk>Y JU=\,BN~QAt7!^ T@{9_\fSw"?TƂN*Q;-];p^[,ήoȂWYL80<pH+*{Ҧ*A69f ϗ9@qD1\͟xbC+ _atʥ(6;Y%E)I=Bh=ѓ))݊a֌S%12QZ7UA|>tXC<6]KC\~q\c*>r8(m7w;j(Qci7?'әg,9$<\y˦j@[l*Ņ]2^r5\Ij0M1z)$$FC%7ޞ̱{ϵj/&,U\[)e8PlB.Mwt{)8dB; Vˍdz#`Xi"w6/fvsYҗtܯšz Àc;^ DraN.>#+s ȃ);o$*B,nDvx`NU;Yc'͓2tνǿE!nՙ`cR=^3PX)|ة*Ȩ t_>Mn< ӕP;&}"jK~;8Q/yR2/)ͷ_sk_OW!rlXe-'I`oPTk [a8T2>Y~zB*a 4p_fVݔ }뻝gb sx[~4 Ͱ$(MYMf~%ǭlmʯde$xD4t>zh;;:w#4 6ৗjL^%BgX©:* mG1(~-~ʉ}5>_#@x<8m.s<²v<}iUկ"yuq`ˬD9;J9!NA5 ; YO3Ż :zAĆh+'J  ȳzRt\rq7'K?=]1QitV ' p*TwWmd?G4X8 2rD4AAtW}Īl%N8.Q7Г%fd TTdo5Za,J"DϤaP65ڿ2z/r v/[T|&x*EIxM5%3[k0EEyBR*l*H:܃z:1LGǡdsDK {v=XƆQqY~^|^Gc_ӀFDԹC | [w80hVD[;7~m>a&h!T:Pv<\3I#i-yIs& Vg PJ޳@Pci$9-Z"fb냡M\ 'j6{U!#[z|6 0dpqR=p睥^#e]/Iz!NJ}ɭ@n(zZ[psݾS={eu {u%Ɠa&!;9Vڟ‘~R6:((Xpv-w6#15HAG84kо(;Klm؍Q;Ԡq}(/&}YX#tylVݎT$hUg}X/Mq5g;}:%z :wHjW4f/gʠA1%ճS ?+0e"E#]uSvTV -L9 z'h<(7WJ״RnsaVVK d0&7.Jun[wA?OoԸ%Z؅&ļggj$e՘y! - :LL_"%קIjL%vr=!נ EW )]xz SNisWD 6=e2Q3{>͌g+չ@:;9v8q~!>AZYZ(=RnQ /KiĄR5ٝ&Lc^:?ZԟOR2=b+2\pU+Dۼߕ d$ŤT7RL#Irv p3[gToz?'P甎K \ͩ}IY6U8h8" ˆ=Ir AX]>)lp=T }#|'^ߟ0GSlOq18gйa GYIvmm:HZ@ #7oTf? . %\G9W0a#s wFʋz,^kO=TaH e38G7hYmDU9o"4@bN}uɜ^M?WKK.j޶lXdWR#GӴ i@skbUyz {\?d&s?`C+,N0UHP۶iwp'? K^Q?x  Ͻ{SS, 2(E qFl"p="ݏ=ҧ+o.qblu~TewFC!rFgȄzxBm\݈]Tٻk} &c30EUdt#|fBL͚o_fMzM_m%QPĵr;Ii&PC4Kὶmo"0Џs2I;[IFl2(Lji+e- B%("ݯ|M.p&sCnTڏkh%J(:I_Fz>{S N\|R¸s* l gVM ]W}8MXuξ|5!7]:w~y*Sue}afKK[ =4 k~:YN u~KVw0ׇJH,NK5_ZLAc`Mu }>\Ι{oyOKX&DESt ?)Rދ3V޹툮:!8QKܶӮ᰼vlᑊZirǏ>QKG|P~}Pҟ4B旈f%kDi;/'6,N4ZU.|iDT<I䑃]/ :KK> "QRbJewm_٭ռyCipصcH$d Y7TɨNQ6x~a x受yS֝-Tt']`ibF?QIHcA6A*Q,)p^n+(˒X?-c9)IݦE]gвm6Iλg ;gx+`/b7b2?G9c*t^ʇD3*Ei87sL&>VWTG8A6P|BFIC.Ꟈ٢B.[ PF+UCz@V;p s2?u5Ni;dHfmPN#11&pW'r9a@{%ct,Cl qi.Dj`Of`9F?hN7f|2ÅsRKiar z9ܐP$ ;|s=(5zo{q9<[T"f=͗X㩎s2S{d>)k`oQ1RL([Zֲr䨈WI}^2yw|nGBp Iӭfm$(1~XPB0'tRhTLxM(6ѧykㅼV P'Ǭ0%lYpW!vJ}p/|_g:Xa&>0Ƙ);ܧm&υKKLIXvHtvquy|ߧ-\) Z8}dn浴cR$lLmûG-Z|,(!DpVʹ(fKcMķ8㡩RfcD=fGn;D7Ll;} oG$ض`Y5$'2a%3HЩf7H5aEmk2L7vLˆ<f =h$_}>xDk2;Z,/4;2dyZYimsJCr,]e'{{6(&n`,%U뒑z&✺ejRX2¡0) =%0'yҋa%秽L۱̯I"[LuՅF˯Ҍi#'cwya) Tb {EngPӤZOTDu.me-t>0ljp0|Qq[1.[X Xf/7^_NWi͍PG,`J)Cur=`G:WD/f)1~fxn{;x]F!X͝KQ\ ^Ÿ3ȩ(n(wiVi ClGS6t:>L`~lDQۖ誋$cč~t. `k:]# qavUElc U݀oܢʖ8O|d{lIhio$]/T PT]`MB=^E }.~-hE3%.]GqZQSop"@=oljPwBxTZ_/ѓ5J4EIߏLdo+Kx߇e Kѣ'f0'|@N 4IkE'@FBW =M6ϕXdL*E g 6MmEch:!4rs?ve&aۅpbaŚ4l@c!wtKTBA7n0+/pٓ~P}"mȿoP&̊ Va媗AұdJA FUw_09\L_;+Kiz1{$L?/hoyFlԞ+1ɗ[$Dpr'ℸ _jl y+}c\QZcP901αDVz7N҉~e5MYB:mn&|?05a2|ލ¯=C/ܜa1CQZ-P|Jql'U/`Jb&\aִ!lOj*nȋ&5'@q#M&'ǃ>ȡju.]_GNdߦ=t^( oCˬK;eiyV ɒMxͷ+e0r!QZ^5^5ȑtZEډR7ƙY4$t(Êxf%LAZy1*aoI`Y#S̏:Ѿ CZŴW(G*:Mq&\ʛM[r!uD Xݠ{J ΤC_@7^[ww֝/Fu='|@'+tw)&loRL 1ܠ}3 AcxŪS5 )BSʑtUȾS{71(,}hыfFBaf(s TԽ-xCLvYOp+-sI n^ 6m d†Q:b EQ`[53YR!]PHp|npךAG j;L➶ Dk2ѬC]K$ }B3xG/3O#!PM Ogr/m׽sڒ2vHk6WM\Wwtlpod#ߦ?7kE/u-9W2R$=9o9ŐPew$m(n9Ҁi6+@ It~T1i{L5$]-% &U񆓷ԲwdBw=g1N}CP9j>XMAq6A/C+%~_4^7SBqKzf?;j),kToh0XDmu~D>dc iP튼Jvi込{,F˦gZɣ,}6 {v>Uvݨ*("R .nf!Rp-!\ f+N8} Y#cxryNQטDhX]Kt"ra6F-KJG5֮z֋ٿ ?md0O4yDɤx\ey'jدA)ٲ`S-AGVo?lo} '>QexWzN!3`ء$ m\yKы W܃49y&dž)*SP0?CF!fs߂:u*?mZ/2 y-jil6Wyh54+/1j=|ʡj0Bi)  f"e@a??FhI>T՛w aF/-woᯉGB&QO۝jDޫ_nq(My 8hDӑ a~vjW?`j |b4@%%JLHpubg 6d"Yj/戕iDH@}OG|k/* &oy*f` sNu^Ghs.pRlAO"K-q'Kpr"EkGƹLx!y-4F5Ŷ=EiB&8-)A@d+VZڭ ᖻ*M&u"۠滔Td?&$o1S9!MzS$Ye&i8&`,X&Rxh-&?fvg5/X_.0sAL' EG`G9z@E:MS=$"UJbfhmV0B7>DiY7!yh'&2`in\h3d~dTE WFQ' kx 4›t@4…-^mR>'W~'EtV:Q;}Q`#Mƕcn?+Ak ,04Dx*:~}!79%yjΏz%vMIִUf746 Ƚxr{Tȃ ^ULT{9!T+f '_,_^.fBs +͡X8W!ܐ&N 5#T'zDh ۏd:OQ\V2ďd7iݫ"Iyɺ!K Q룵=LZl%z4s͏ @quut ]s!xГsUov>n$X/sVQSO DX>̿E@{\s2cNY ؅"+6\R`e{;/3p ;eU7YýȊK}SgBOaUU@𺪄-s34kERR?ߖ 5 w$LphdJpP3M˸MH99|?!OqZ F3^C'%1NJI(r~C)W2gВ?wI'Uw!}w4oZU93Ƽk/ ^T|@w]ATNgz"Yˮ?%DSO3}kz -CQ#92t ǒa-IgB G# Jg"%<ݲ y}5ݨ5yENNW-xW!גzek8eOov'ké%\(80IGePFzę4?ʸ&/7ra=نu#dP +Crٗ<|f?;wWx2ؗH/E0oQS3OvVQ \@B_y}ii+~s3N;3jr3T|2>p/%آuI̢q'I$ >]卫HjJV4)BmɭaUΛ ROa[-g6VL7Y~TCWmYpDzx4SiBmލUޣEDT;=;v6C6 1M~yi]E Ea u;gMhGy80I)z>O>Syw& f!W|6c"Ug"(ymeА@}ΟKŜcBY4]u^ ~~)"C X/qô੔87y r٫"*DBˑJz#NM˱{2"Dtgo69~U$˾ *f?|]ͭs$Җ-jwJqJ:8&2v0"sjT} ubFb66 >-ҘX נ9'uGB[kAa̽Q>b-T|<5e$qGÞ°/woQfgr˞h\22-fG:;5쵭پM^IS;4;oC!࡛\!*+eƹTF".ձ֥)eO^%9\# ]~\L_B4 ]~S]vByֺ|KeUX U˩_"-q1S>|ń+\qf PKu}0w~4C1p!=VHg7-t|xꢠm๡,Bq?܂_ok;bB¸wL`C,xbi2 8Cʄ2J5;c'uu8,7QF%z !K|FhuF3І7E,P#2:lN<P¬ .pZa;Rg|&OViCr | VbDUCQQə.[Y?냒{-T8;15fg|J@#Y:e3)PZkO 'mZ@O4<>W:Y&!U9/(>l {tVvś]l$R'/#[˛t#hXt_\lVԍ#Ps=2Fm*nbBY]]NuGgt&S<|2j{_$[*T};_nk}ϋGJA%YfM+3UFpF,!Y"%2:O%~?+`;CPAkf {2Y^f 'b0tHn,!Ez!Go1z"gzdx]{YsaA~*W}YPyglCs_q[ݷs=>X ɁL8ц o*mə;xa;N5p~<Pھ)]uŷ%2\" #Ѝ +$M:b EQU‡ Z6ɘiY8X:j- f?36pGIΚ`qLvqUՐA-Ls, + +]l"Ϛu1,ԮaKnN;;KNhN*AW;̔PX*6 !$D97U b_R7&nt;xU?:lA#.ۨ"ϯuj*B g0Jp 4ssM[>9z>s2}ˆMbW`">0}"F\kyd NLJ+jWަuzm_2go:lJkٰR.<ӺKU/ _Nɿ.v\G6`U\vI6w>V\00[:Lc !lY u@Q0c|;*AEnj^nt^oVPza)UeR﫚gj>+G3vCODkrqR{!}e'P&}]E tw诏Fь1'im_% U(d;,Zc3/X(*2WX/jwP2Rtơa}u]vsY-ؗS=qtPbcbDpSP6 S#۲Nz%=^v9/~dC➔W|n%vUQe_}n+I愣L 7`J@Y ׿e'S^`φ|HιdF7KEؖ\|~f{9gH̙SﲪҩG$Q-mѾY"+G͉g3o9)ӥڽ@6 Sa`s;tU!ZH{YjVÁu  ,Ԕ*F8aery kOHeǝڞF=DEۗ ' qVs! ccxxQ<صP|ꂱ3eJT& !q65wĒEV7l Po{\ NdYvFQnJmC6^[C(xGN7c=SGM_XjB g&=f4)u#;NԿ<<7(FE*`$Y=T-||= }difîp;TғD?8剶Cz :% C \e=R{NC2SƵYF0&}/A?e}sj;3(7̩ 'שxG3UT-t?=̞-M;.o7A2 } Nnl fx|RM N#s$i}Vx_7hԦx q[=G G0Lp)hf(lA0'o>P/LTw8GeBZ/?/ky9g=|*?EU/dBmhMuuT(gPQOFpR?o,7FJ{^Gw\3u3"4:RcܵP[g]t\.Iݦ@65: r3ߢ's5\5\^>Q#eƦaص_ TUf:_j^Rπ߷褘2cݓJk!R0#ܟ%I;6.w@2-ϤBt{Olm~rYuQ&J\O;Uf0>Bt%g-] e mtLgOٯ#T=Ôz:W|B]"Fz-CaYX"->Q9t@"/"͵Y4 yPB=sHڕ*b[8Nbv/x4.ltgm&t l=[ n1dMww39!J:o*ķͩȴؿn=DՋe,o &mS"'Bjطu (47 kGBw);$KY IƮ̛X9?aG:snyl_Qۛ,xA />A3u֍R]LP t2FZU0|LU9|]M(@bdž4"И:Pa М&.)wΈ ȩJUӼNܢfr[P}ʳR.—2mطM#|5h[*7 MʡJ`mVJWzF@oRMg@sv^ T4~KU6F6.@.K2JpEa! /FgVW3جY!Fz[0UUw*KUpR#sb{QBokhHw 6ܣ~nޑ^TL5X>uVv$בvp•6zd:<#Fk}#[d4-Nх}}sB%5Gy=>0 Yq%%5s,_ ֠_ h0 Im)Yj~%:C#fL n:)#}L}Ёz9ttlU0xƢZԻS0j@ ^խu]8^O|x}]r{ ic{ C7@E-uSqVtN?pۚ}O 9cmyӾ HOG4W r6I ~F_9M'4Acm'f#:{o(oI6ݭ>- *v@ 2Hs2yHY> @%;GLM/Q*z )%\,FF\>tQ+HU'A{8H;dXWa6 /nEN׫9 x% F!!(]63b3l69ɯv6g6~Vnt<,ė-}wdL~XzpV?@N{0~-#"(+X?N5CqsBvTf%xK8|FS06lcJH&NjT. Js:lM!cɑ\-e-@)z?d@>Em[[{.|| :0U*}|%0>| ~oU#uK{c]Cƺһ<4wi"f0[skKb5YI]=(`eHQ7r7[Bmjƙ*=2'[9NZtD6(;HeM[4E֍z^@ J`qp2g.PΦŒM<{|aye+t6|t93򘾲xG D4,)BWKr`eyOF|*]LOL)$q n|2[Ʉzw]a^lLNϵ-&;1!^I<4s;%%Nj:Ve[̀P-49O3zضa,"XRg[ph-C<~3hlZg#؏L4aqC؏ Tbm";p}R)2dĈ;ެ Ɯj cYu@WM,H5M/{FY㮆ljjŸ40DŽ q({#c1w/^ ݗGq50+xqT^;m<016 Nߧr~XPw 8 OtߢU ܃> "f>n|fY:E0d"$ U%!t(%W\S׿( ñuד:QF qӱ(x>Ĩ dor5bl3F C=[͒fr˂r7|QKBs'C f*j!i%J)sNUYZBCZ߭U" |;dC}O-'s1MMJRBBi/YFKTZ𿎈E0kŒу"f|z/Jq gaEB1MY[/E-cF8smB˜bvW&g|ȏHBٴOTMw$p83:*"'-"GP \Zy+5(-.CqN"g"4?QY:Z(:Ai_(bᾜ9ɄrJ}84bD TyjuڌTp2SPݎʺĘGUs<_OY536ؾx~ϭRW$ 75@Rj//Ŋ=#D4_f3VȀ[^ HB|y[˦ӌ:vJ~d|8϶8+k^߬{v#vDC5N AзuYȵKoIvBt%5pbdD(׬gQMr)dGSFtcET𴆹#Cebɺ:uďLtOclM5O0o?xI gMyY TPe9&[w.b@;|nL|޵LYp0uﱗխQth& \_UIh7jvv HjPZVzXp-(Ӟ| up>无5~~8mr;٨$xu#n䎯,\K¶U,rbypAvSa/UU)!;!<2(y1-YٙhP( [.|rOHN{1zWAR{~]}\@5 'Ԅ~~zgEl݈9P\K|l)S\BohG&7hZ(#3Wt 0L>_w].H8WrNb{)겊%+bR|R33^O~`L :2)cRcx$EX(0t?>kMWp*dӔESo]=k U#>4${Ycȯ&W8Yؚ8Qn[ H&9 m]ma!ϸɹI|s~--"F<}%Ziv~&U6N(h| nPKDXeRd,`':RPHȳ$tֽ ې)_Џ[ .m[}6Hb|3,`)S?2m**xQp#ON0ܥL6_~ FS2٣.D`% m/-rC} #fqR9Oc+_?7%;]p<-B,{lw.-~H z0!ȏpo;R``9 Wl'rNZ{_bacOnܥ">!_Ddm{{ rԼw̅`֘ pp^#SKL}Cj]8Xo] &[!AjU@Auz1j`#GxK8KUZv؀RбjՂVnݐ~&7PQrldbXd,J@-{ڸ)i.hJ*,80@ۉ,7 uFZ >>i50|[c m[=Db X-Oagӹ9];Ã>&]gAgDBLXV5b,#l0gb`Sopk펬B&ӇLwo'+ ayʳ^4JeA~H`-*< ¤o#`-.GӼZG _uy==>ZJ[AB1nUUCeӼ54ۛ# {YQW|2w{nP "i2=cb1N[:VG6E]rM+儫 3l%_!1Y'ޖC&Lg$KJQ?nxJ)Zv`chQj~R_ rp%e%?Mo6V7@3&G* 3uCX8K\3z{duQp4gD d",ZǂrA.AB ׊/AKO^}6\+ [.$@3żи mb*p2]iv;g|ڼ $WR_4?`Ll%%k(j{œS?7QVK3mb>#UURj5$5T_2ɒ1w,ݑz0?Ied%wE)#&-IS/JϘZ1"W.>t۱h<>#!q(#b:Yo78ii[\W~c^ ]g hЉn`+]z )݇GNcK-ί `vPu/$v]HOu,1_ ѵ uW(T25jXI{idP"V^.ʕ3ҹ9i dSk?sqԾ^V&N4e"Cql#,5G{ܥgmAt9k?%ҍymۨe Y9[58VRs~Za_Zk<zgt'*6!ah_dʫ%SrJɴWyij3Ӎ-.c1^ērn^T7veqER#quy@쁣 B jHl[?JYX ?\+Pj؏0Ff@j#~"(R1`2 uɡ2Bc/ '_>^B83=N$2#z6,6& Nc{`IK/rԮyVA4xѿ)0pc1\J)qRU봫piFFD uF}By&ZksY(I P' 4@fzۢVccFK@pk,hzoy GZ:qk 18YURɃg iDpS=Vq#U%z-{4x%vޗ1aզ=ZQA=ܓkPo{XEX=o䛺q֝~th* #aR07B Rvu]d E; hB6)`BwTsgIA ϛ$hmIȿft(!85Z?SXx]ڎgWA@lLM3~H\u bx`^ MשVeOp=rȤ#]wJZ]$3m8iʾ+IF$$M)h.'\ЉnBJw )ԱCp͂P;'킳 D/h5Zfa_ebq>!N_‡M*OĈ`woJˏfuAudxW41,ܚwesIdCojs0Zv0^D yT)4S }r.lW-ξ#MrNAr1O)5nɛNP 1Ʀ0+!V]+Yerk._Mn] a=3Oy-j b"K#dUNmۓJ s"9eFmcY1*p=1W036>&=YaZs:牥` NBYCT-cup<*G ^a&|_/X |'. jr)0Zuq'DAܽD;9Z/6 ^B6{_s%vG'سuF>=wkx❀A܆IІc)%Һc:^GLJ`1V/%2G>ZF9n E[G@Gk$3F6yq8CygG]{0'?g$̚_ƉfNHRĺrQr~C/ޭeEs'D -V$Lym Nڛ"';{k`lQRigvRoЩ{-2ENX88Z݅$49韍|۫&Q_Ҝ}Fbʉ cí B}8HVp4Yeo%ToF۔ sԃoF3U}g X3]b##RivӠ+m~*bUcgFG b1i<% yA䜭CZyJ)W|b*K^hMKI ŰY˰z %ء>IW6&bk9-.+dI DG R98HTU .ٱpfN: ]s4UM"F@MfІC]W{u>Go6r<=OiGFvT$Xw2Ѕc Ra"v y`C+gR)M5x=ʹS !Q ]+#O}<<^kKfp@ޥ5{FN|&~.Yqr:oSO9^UdO1I. wS kD[XEaG !adT> v@9հ'8B<̬; g\)!P$ : -Āl ^ QeC&3[!c)ã\zYJǕ #+v ѹ-X$_ޱP-StE匶~>jz/jz}S37$}(jǿD*)|D>3N*M]S}>}FHrj$ċr1V )i[v$ JЬbFNn/Z}|#+^_0HG.n$ Q(.8ooĶGgj{3/ɄU+@Jӌz~Fv;WS| -h(: nb(֊ bO1N9ƤѼׯ #.:%kM;lHhkrK;LSTm 8YAvXؚfP.cI16%PC&;J?O0&lz*Y8;nzLJ4u9^UAߓHz%'v;A4/BYZpKZ* <]pOUS;e/4h,0̱_Cm*u8;&id5r,q8gi"nf7 WseǬKURcÛd͍U| Þ}#PR@3䊧gI%v΃ھi@"V[ d]W,D*Ú 3tާ:;\u,c%E<^WjЪ'qY.׋I#XVy*n :5:&_K[4ѥ/\CC^ݳqDԝ`}C1&l?u}T|QQ ]7Q?JJ 9TNؙjpklZ2#:auė3-Un/J<Bf"Z0C9TR:(@ ԿzdԀ]jP^qO09'+_Nl|?B5EøEr%A = f,ftV[)AF%FQk"l`GJw>?f<@"dm(&h fT3zyٔ9G-M8UBwޱq?"Luc0Z*/_C=60ӄCZ'oҮ{nAE%b)hr\f_UF<{.DnǨT4$:G~S~>;տ݊&|! ?N9+AiycG1mV}Ari~hZleAQv2o߾@٬$%e9P`&{8?ӌ@R|%W6>*cN@'LsBɞ#%5Wa5bi(OQaõ{PNC&"yR3Ң3^$zYcHήO`c6zSN\<$eG0!" 9fegL:|1!e xTIATEA]OXZn?0Z".2+KWt[rkJz2 WƏ;Pz^BЬZy8)Q!\hb_-|})\$?D?|_ (@tq:>ljy.b򿣔ۋ =϶mpHc552DGS.ߖG k]6;3hGK؃D\brm$]z^DWVO8kI:%' BfNȐiew۹ K@ ; d_"kqѾ OE=iEs޼wzU "F+nKh5/0ͽ.ԱqecJ>"F i?!3"jʌzJYb#35+;dp=(i)}A\ZE4*rZگk?Q]2+vi9~lcE9 0#ӀIt8"7?>T!/v_R?2@5BW!lu.|6 9N%wRی}w4Bk$?q'ĊǠSSq2F`h˯䷤XR瘓 Kܥev ss@=!mTI6',tV*-O'ƛQ~L ֚(Hh#[Bl(Ȱ"[-jbf(O F!a;" ]]Ju{˭"VY,(8Q[=QHdu\\NxIHL] NcHan#_^/RR{ Ry˭ŵ$Ztqlvl̆99Ô!G$;(˘H:~n~$D2dl±b{81It9GљѪ1MPgpЁju &\TN{&TH06g|& "b^lwZN@NXG)PLՐ}ʕueS/ LC FX}Sn:#a!!.aB׺: H6\5s$Xn fMg:*)'$M@4̹Sse3sOGQԻiAX>208|S MJˑC-ǎ!s4z,&Oyn/ݷպԮӲp㹆k'0ζkXq`HbKFh7qKuqEԨHOTK>tfϡ[No>i ¹q_Ȇ1͓]f$%%3Ƒqפ?𬗱;]!¿a"TT/ N W[| *f[yҾTNke6IPQKaHaގb, ҲLTҤ$6^}DIP1,?;$OK*n _QC$@h92`yhwߪDrӿ9Wѧ*<>Ph`_k^Utb)>PgF0,q#cOmN_tu`3gX]xغvyBv¥NUGzr!D@g" _'Į$DPQvM ^ԏĉs݂>N⫿EI;KBU"dEJR51W<ȨZ ?Dqʹv{u7&Ǖʈ56kUMH`v?4p.o>I sM`] f"17y̾*2˪s\$GԪB%h.R32HPį}*Ce{a~T0\(6]ejpt"*v߈M"~˴ukS)O !anK[oV썒\lX5Kc8ck)_4kւ4', .YO9 e| y^cq7rk?"4 _ vCqИ:& 3 s}yje!6Lg` ;@ƲI߫F+ؿ㊟b^b~(W>jG_'Ɖ1]]^X߮6qn9(8+?ؕ.{i#ngÖgSƞӗOEBh}nA{lφWG 'u ]A^mA+~NO6q = wi5>a,rHJqHWaet *$<|;=V4*LcRbÅ]CuUv{H9m0;WBEW%sw_cL+%)2}>͓>)dlUK׭rK0,3"X\`}bߝam6;MmxhHSBSSzSԜTT+_ ܮ{6xb ?-Rɖ_gtVTȋ?qsaYǗ]6։:({ف\4j9%P.]SFBݏK{ܨX1>o$dFo5kFЂY,&I?wgce͓d-.Am{wIpǸ~3$DOQ E$0>gz*Q][S=戮$n"?\>8^g-](k"ӑ=zѷIBඩ0sY̗*ϗ~ǧ*ɠl2333fܡGAM~>^:wK|̝Hvk+S2eQYG=&y9DzP;^`Cϋl@qbK޷Ҡ1>[]wZx>#z}0ɫ^Ø+@Vd2%ӘcJF8-unz=OF!G7 ѹvACǙmdސl/)b;t\>ЏhjT1D`" { l/ dU~Zk#X>P/sU}J*cGf(SQ- HC2pU ΦRya6() 1}yIZL/rQPx'" ;} WFԿjŷ"u3$º+5eiD7PpY¸#b؏5fS[+ArDXyrx)91X1>=-ݤtaGtY 9Pa _w,licD;v~>:A 186Y"[kpp*e,61m$jWXNݻ& ÅppcM|OԋB[i\B /<8[K?K7.Yg䆠ĴY0-4o!ݦ90з|ƾtljd\q?D+vzCl4itY0, +KO ( gyQ-hSs|yo7b99U# f5_CʳU1v9:9D&+0U 4Xt4i! 63bcdOcUstVdU∅#r[*d.!](o5'c$y-vx}BNcv̤يR:tl7Qܭ~1ղ{ojM AMs)[`I3 yrףF7㤎$duGNY|a9xsv4 a`tr0c\∞8$yoDtJ2ߪNrJ#>`#Xŏ}ྡN$rlWvQ<Y4G/p̐Gݠ}W&+s<~p'AAd{iݕ"G\~8w z&/YxoTOb@ςqQ+uz[ 6 `Vu Am[RW\@ȹqgU$ouKE go :V.v-Il@o#}QTu4ZP/YSwjFp7Ti+ıX=a ص}(I$Wm}iXX!hI=y=L?-;G/qX3i+yQDV oLwTDU9=z@1;LwQ ar@?uA"v,{#L**􅏱Ģ`Aq< B&3K[s\Fl%3MV{vwa&DCS*.$ĕzFR8d&%]2ݟh SU #Kq%A6JZaD^'顫(#RB7@P2^ t;ϰ Lɜ)M!zD`{.JrF1&=>@#'b€ ׀FƩa/&'?>˨o󆔩9RGPCmLNh43 tXM  ƧE%wִ5` T c2=lWKu/')gW"366_A5s1T? nrbnzC ku>=9@w:2(M/H,׉cA>4LȘ{O*4֧Av8JGǯn`;: C_3P'HWwdnH N[&UAW$lV ><-&DKɚ!/N| =vFcWvʤL2}g @8.(/ݣy = .C >̷"? eE[ EH Vet.{e~W&L:g͑9Vr*cӮ,ѭ$nS %L蚪Niu\]|vV%Zku=enTQO ~v9a |bFM$/AMx!,N@:b}n,=ńgiбƢ6#9xZ)'7{lV ;:u`A?nE"VؒvVh |x{0B΢y^|B ෨.͌ѽF:e{ВD9od5  o0OZѧL-Nˆl*r:6>DA*7%8N2Nrz;!eƌMb*𠆜Ks@gIM&jWZ|,*ӧz0~jfhJ?V+` X9R(*ӭ@wmn(kaZFĞ?n7_[k+li+k LoDRlaEZ :b8%8.PS4EbG٪ᨻUμ 25lu!j<ԯ,2a@r2pۣi *qv+|'(@0+ȇW}6NG|?k`Դv~0tяzBg$#p~c7U*Ȉg0\& XBO`fpsNKi(HX7- ̏vb%U@P@qjTI;ˁiGd%1B@h=0R±RTE6CKn'.hjx3w{jZZۀ#Ƥj'x|70m93g2zHa88HgcQ\$՛}AX9L{I2=rJ_َ"Gk5VR|Pr4BV!$w~YUQDfi/nv.ڪ{HN_T ,wi4@ C:?>a3b@AWkJi- 6%a~ -D>wݓ9uύ}z-9erJ(ҸՇOQLoU CUt'Ee-Q֟](⸡%4CWs揯}bɈ_ Szr=h N{}TA̅0U!Ohx/,h=|ϝ.-O+5|sX{m3ͺ}+.Ͻ$'#RyUg=]$|P[j#&Ǒ)wvI}fp骝qV 1kTq|U|ѯW:/qd 5hs F!@!SQ (-ӾdD*Ooh7!HԒ|a/?[32FO+JxOW&PDybI'vDK!sL3Rɫ! OѺ)ikBE>VhfS3,HڵhzQH9p]McWZC3TyU*`/g NpWD`S7p >I$ǍV"۸wf-Jp KwUjl }xrOyTc.nNdnIU n/&ԱyOuV=C~Cs ]Im" S ~lhhl;@2Xw:|nEd7my+Z#3ay-qE:SvS+64e˃Љ\M'wh3`vgnܽk9y@'΀ 暴_W*s:.Nynʶ_Ɔ-K[@ k{C$>*Uz`8*ea+8'`!ue=+At&N;rw Ry_QFbL/I{Z (ʕUܗ;|eQ6EQR}NZ-MrWLM.*M-@j 7{/ڐu!G2𬷊@Ǯ.n'hGܳ`Ӷ`o(I|kR$y˜ t?6KÀ ?4)N7[i-b@DF{Scc9@4h<Hx2R uL 'mTqӃNh]C dӂ7'gO@E܂28U$L;6f3F.kog$Lo%4LZ$E[o( rXVl?q;~mdW^2zcT6o-*$(6oE`D#!2^ yb޿x5hHi9zZՃƽ\>K [O{>[?nUs fleŻga}:D}S e$ù.Si`GsX&Dh'. 1s%8BxZd'ãqt2/^4^[֗|Y-_MS5>k<."Dy])|={HpT]8ً+Veqr[J#:-9S;P?}JɁ ]=ɬKw.G)G@̛HDsZ ħ~2bM6 Q}uiw3i>Y 9 Τ'92| c=Tuv>:ܷD-ڝfJ(dV \fie6W'<( '.anO]ՕD6ٕ9ӝ&#[=@ʦwy^3:8hbq-ŅӓsYjPKWQavxPK kCWRwK0&f[z^#Xa%biZT;LRo#tNcРx]WHW}v؟ɰXGn&.46TdRo)6"AUfueWڸ"P<u۞;mz~08[|GHa C \ycsf2Lꅗƥ)㰬 ҭb^ހHH \==o*L%^~L_.ߜ>`,TY~⿝OV;E~Ǫ>5W[:ǔ;MƁatO&лSbP{j v Ӹsd1qQ a #Ç@;sU `_e_Kv'-O"/8U 2fx>?^r1_ɠe4L ^vb -ZuVTk^ +긲uY[ 8j6:O#BPPh5]ɵj*u+M!2Q9󫯈eޒĴ9٪V'b;so4XH zx[ >M5i p_h|P8a憺wF h|1?4{],R2߉oM .Wk`w]EUB8b4ű3 M^|jnaДN fW>|p(jٝ.$XH2rvR|ʶFPgB}) 92}1Қ:;?a쐕5OXw =V%%Y*?k@RPCtX !cv{0njXYUR6fOe|MQ%XM:s$GqVqtv\gz2iiх?HxǡP*[urJ\lt [D,K_ \)oceeXYӦcl Ux-mN $E_L %j̐a߻B]  q!ڬllp]**:jJ7[^8vYS]*i!+?yMº3 l: *'S"#\9w qyIdTS) c6=efcfOIgϑUS\,;B:ٌ{9 e-9 xCB0F]r֨^x0 J6LׇV!0-J \Ce țx6gD:'5*ϟ|02SNΚZ8Q_PrH6I5=Vh1 z(ԾUZ [OMC25J/g`Dfu#J@y(泚t$ RDhOc3K5ҠI+o*{zZC8{A*)śeXLƄ?2.=]κ xc@'vH5N 7c=+#+sz*ØO;)=Zɬ&lu_"9C1nՊ a6h5$2c9w˥G_J!:i/^+tL|9@.ddjO\΍>OlP:qol:ִ|U{h wBȶ9f =*z1NSVbIߛ 987*[\\zIN,KfB-GIy_<Uf:N\Qo9d/G/͙~MͺnK-;6$)MT{x>1Oӳ:dƓQi([\ɀ yeDks<7q8LGLefﬣnWNI2[U^-A`L6Ttj2Gy]>[9@53i5 9{y˯_QGaBalIsR]sr!Ad!R* +ѧH|;ؗ3pH5yCjpb oϚR(z/MX֍Uu_SUW4M^NƃnMZ = v㍜]z#юOO:T.` udpH!jyA13lFQr(^׎Rه}V ?-zC5:yw"v [jK9Bb!|%u9,}Sx"oH lDIhk)' ӥx?Q>)Cn=r'J6N>/Wa"Y86N2nL˞AA \x*F48{kH[B׉*̗yA3_+H`L>QW+E}3aQEdV yA~sWD ' s>UۙKS @,:Mb4R \U$C NKL=pO}?/MK⮟>>&o =2 JWdJD3ݤյLIz$w2+ahY*zVZ("&"䦻I<'!<f0ycAB2ڟyܡt\ 3rmU}#%:"T:v|=R2S͔q $s`vr_Ne^M )/U)FNr 9)gn?[#25Q?/r:!Gb@(N?*JNd?-rЈCpG%EN=3 Al e|/ Ko."czcVgdym+&H1!{?´*[;Bd~K]U٭nF=xv~ RDɥnm{cRǯ- g,Ujj̆67&njw57mH&( uW^ 7 )Ka8J5=sI<(|^I@ߵ) ?r <+[n֛Ymb/xyaҳ/Mů[wP2#"N.C5nlhm[lj/& Y5p07ɳƾA&GcMܛ/AX'u8dsoY/pۂ'E k)hABMu/z7'!wB+2< 1J⾔9=071BCCrI0<>H]2_z4RU )*U Iڙ,M(-a]چ\B-1'UuJ'yN+w:qz;&4W(~ر=ebmpj `GDbg,%)w4 {kR !N ؙZ;mwfiD3y2đK a*"!Y)nۥFvaѽ.; ʋ2*DДgʓuoSG.Je7쨼ظkʚ:ŎZl௻ah2VENѶkJL(C;@B s<~x9R S2]LazQMwӅi3砹8M,($HO?2PT Bg~RZ(H*ڌ.>Is̺X$YB W{WnaU @`$DH*:!#yMnL/5xͳMy[Czio;IAH^](a|1?peAA?`נ5KƩ̾Qf!-e^iX oĔrc? \9XΞF40LJD \;ȷCÅv8 YŻ3ibfڨgG?lR ::Dz-u\%E"Y*^u,rX' D<=??xtsGB`XV, 蕞ӈ?#X0uժ3v-VlR;Kjʢz-I{ mvmS.:`b%ZwC_yB.#%t'**Uu(0. d V](='12'"6>d[zmV rHtS셵x!՞7Za>{rڛqC UțqvI4i䝜ui]a +wZA.\xd1i@ POs!WӚYDŽy|߬ӓIqԇ՟hsQo`P/kPT H44-:gcEԓJ2S4q+xߵذzE(>Xx !J\kuQZ rXf"Fz* -uݪ1f$v>RxXɋ Ӑ'|CbT}/[3g:¸KK]WO Aˋa @`- ̲G#Ӄ% \æKB"<CPR)L}l? I*Xzʺ? ]0DZ݂d4iԅq5VwB9xia'r2 ^\{i1uӰn=1|ﭽ3X^'^qm-<ؠI5I+ntkJ % %\@lp(A9CeShČ;*/ddĘjM1I왟SRZiʖT {qcޏ-Hu@Azfh;+43'0Ex?I" (K1N)[z{aןd0̍yc1bi@=,Bz|u1ٌ BBHV7BWso0 'm-I hgN}m07l|e5vge q79BtEu,ek*n>{UwOx7*1 h?@l"-m+Ka_PMM=Y,yL19ge] cOŔ“x({G#'FG@МsGie ozp`FZzR{HuhCqo}3-9" (r%H$,!1e@bJҧS+U:<OAKnEmK _=H mJ&?t2 /p g{9I=\@Kdd@pWѐEߜjˎVW[V:T#0/4dG If^tP yƶk|W|p-E1xsOIDS L5Gu47(HAIS$, ЍB(7If؇`T3)-I]ѦY<;4vk0pJ3aM&,E+L*3_ꔵ}KtCuW#À nC8.SǂرzR[B%bF8*4M@^ͽ! ѕglnG4"V+3kmj:S'(mOw"EY}ǰ8 ! +>42sGƝF;˜u/n6)^dTSL9`%-H|0ACw,T"#vr<+lpza;e K0Td;2JE3-6\0~{&.55~R5@}9˝,Jb=~SR1ډo=lyER<Y^21DDsZDz_)hI UDx | 9sD9ԕ(}'M;L|ajoci#6 3_ͤCD2}LJ)'%W<Il1T~`+ Rs͚ٹBd0([^ê4&OY;6 yh(Q{ǣ~^ʅ\t/jBG}l=ӋCuPF>cծ 1ADn={f c@HEĕzLE,ˑ"dR.8W}9mX:mB8\I?Kb중4:% T͋M~L6HŽ [\r8%-}ωiOC%mn&8unke?P,W_vFuv?}g(E傚dL%Mv' Wdž٪ZȦ0Tĕ(( g8!`[=pY_RKO%(ᙓi{l>T بwȚnCdflƚ$4=o0]11: 2~Z? Y}M$e;- YsȿǡQ ./5֩,F Ѕ?s&Ma7(Gx1_ T> 230ܑ'1:AHY]9nyFHcFO%؎V1T"k~SM(sK#>b nɣm.%J %RH̄b߀j,7ozl4}--.8z:oHtbO* /$7K̻jFU9繷Nw:LosiԬvx+`a%dL;ފsn^A<ɿC$mE#L̆o神bٙ7F6:-O9_H}x6E"#e$vK- Kk 940x~kˏ%WUǶ=iF^x`m/Q?H8=QkKpљF˵K9&rFĊ;D/I|C~[bj:z!*K`Lқ=qN6VjE;e;T9aחwmJ3ʺ,If/K8:pBy^Fs$ U R`_f<Ǚ)L7h\džRT ٷ nO9>Ӹ#bZj.oqR^pp>.'drPgW/ZY 42J%,UrTL pBoNP\ȥg ִ,eTiI)3),*! U Es#Xg cP~ 6N  Kļ]-VsSo׊%zņ̈́O/-|0wZnNua%ݺPM"[bd .LL|:3ǼJjj| ^.告WA*]+Bew'}MFO#VȢ4["Õ8&5#hf=^L3 ;Q0IE^I"C(m% ,61Һ>,|~ UG}D }tƠO R%oȬ>,,-rz;Ma8q1;VﹷG_2yzPc/YiRuÔl{Pq>sl1D]+B]+I[(RA풫{|A +2e/!KY=jԖt9 rֆxN(fw >T/_bQ+TQh+l]Chh{i2[waߥMfܶG!Ǔ+ k[JvUxXŅ1JyH *٭[x? tD˗8,Pm .A[u'LS9\OBb!Xpx $(]]o܀^aőʔwC*IOVl"1<0rfO0|l_dbK_t(Ep.ɜܖ!jwE&O<6-F1 K̼ Q*O륺R·bJ.I26i^'}@*ӫ30KX K +`Cj9҂1SHRIIZW.3vT$/.HЇW@5)1SF`d@3㔡_ݓ]0WR?>9@2kW7Ƣ6bZSK9|#OAm2븶|;/x~G/m*D{<]v /;ķB9<R&sVq@oNՁDVr=jD-؉ևE&XI]2-oro}?jV,Yk^ռ y犅&p\"R ʅ${/{&'ͬd96ź m95?>`l76?am`n pjZzNɵɌY2HW!A}B%6{KoWG !!)$OS'R]wf%Y(~磐``$œ~2%?NOB= u5@Y>=w(K#='d]ѷϷyy7XW$s~ZT0OI:yx[2_:VX>8Q 36@fLx %.hcjoq>IG3yqnu3+j\:\h>G#Ma}xg(]w4_p8I!2aݝ%?m{ psw y ضi4:M7q*伦J 񗉢Bs{XBEI#K~4m5Pxh2/_I!4-H\^/' 8ۜgT>/N|~ۖ-\<ڭQBܷjm@qH]AVA;yR}SLuDDcdmܫص̶"KPƠehx)c1Dя>%A$GBHZD09`;q s$3vq,[4k؀'4C>IU+H!63<϶HDVlG@(zI&qڰޕw$/fm ruS.0B'_wZ(ʌfZҹx *w4"!}rpbZ8v Z/Z6=bOc=3R|yoawz%#Rv뺓A)go1FG\s+!:oԕ'w˳9W7#hG`cɸB6l[JL.M´5ײMEK@(/Co:ZmFf|eECl|"|TUu"e1C0 fLn̮#1y얓=׋E}酅m{)H];R*Âu 3.(τ\V3v@ѻܯ:J9 j28r\ U&n]`4䖔S?.(T | _yVD\Ҕ񲧀 (gD^E('72k,X*a~܌ /ŰEr`h}DW;Oz}t7|쁁D;p2;FԆ/q- +MVvvG(%ƃtӭau|GIJWo0|9Fhnqc;y@zoŶk^T₣Ir,PSk&p? HƲ\J~ۈ`yXXX@JkrEYf]pnhIDX#RhF oNLj?UX`>u,Z+_/ˢć)#`HM8MfDb^^`vwq?Y2><H/b_ҿU2lyԀ,}TRkR5=J3OP@dŴ d >}*CATT;lpi ybݻI| GhB[?&‹[ѽzʊ.8jW7hVo!+qLP ñn34('OItJ`^ceB!֤1){9(N#sf2ύϭ>|09"srN:" *с"t$rYN]ؿtI( l;VvWC[(Mp^v%:O|wJWvl,TI++X[bވ1wjcưe< VF9lsg2M[ȯէ@O*3eܬ~KWԪQ#"˱G:IJwvڞk25aqcv|?,6 C ϛI] ]Rɏg"ۺauB<dǚwg(I{F Kc E}i? }I*f$:SYH C"IYݦFf&^qaZk*m<Jk}8:xI1+Y=u![ yK>1bw" 2D `ŤaҔؘY66,p[㝐%xtL<y{Z7 ў$U3PXc`@ S=6Xdzȣbu۟&W&qʵL[1R82֊Y}; 41m$*m9(J'ĀqtnYCɸҎדj‡`Fr\mkLq13OÖ.x#d` #= J6$.El~i̥1 zz4\P30p)Ӂ9k5]Z_p&/=',~;LюxxZK鬁f}ߊhlnm@9n\_pdQ[/(ͷ]__WNe dp(!/vSy) 逧띾wQ|k gP .Z`GXfuw}zo۲C9a~xt]* Щ۬:u >ߣ^F"Je_48bjxZmY`ÙN]w gU"#zdfmp >B[ OwiP"]v 2TfbR}ܪ(4 ߽)Mˊ`b!t&@6 >E ơ Vmoޣty~i-A/,0QͣxМ6dߟΎ 6<=G"2?Gwȶs3;(CJ槶Yf{r$%+zqFi)8K/2_2ض D0E&F!^Ѷ.*;Q|}a_Km,jH57Gl(xYgh\5f_s慠e86㰗[zGk#q?/@W3~)y(~z Cڛ]l Ka^C\K+j XxA{% LjNWh'k_dXWbeu"W;zK< _W'?>r4ypD[o07 h,w]8(CW8XO$nq2}G=(Tk1#NxJڙH"UD]ƕ:ܺ'Σ8*Vԉr!/HN<-F`Ó+G] q1x-u@$}J[s0g+_R۵s c=iWIp>95~HTE65Wzgyкӫrp_GRHq4^ 13t儷4dp~[EƘ=;+T2KDcHOTyAnBJhz5)}/"LjdX4­nB&~\G嚇iSYi?B,$Wg~r坍ߘY]u"3Ro ^XGlehU7?5>O%PXUP&%j%pN (;-]׊ƹ p0㛾Q'!i[EQm b?A$C!YAQ GgI?˒#&j,_b t UώOw ;.«>ȩT;Sdv"!gU b+~b=t0o|J!}ɚir'!U'uRK}Nq0pd-n !Y/%:_/Zn}^QAGQ 4f7XWeշ a]:Z`3dWK-3-ɸ=i 'lkifu|/a*Ԟ~#ڨ\YS;1pJt,s$֜.ǚ\qof*4YU+q;y_OhJcbLyhrmzb&s`^YH/F]3 sŁ8C؞7~\)Ba6A7[Jj],VaƋhneiA߱"_E-oOjmͪ Z|lhwMmJum#CNVɼgY%b~+ )YR-IA蜵<+ꢛr$#5wWS >Ğ/*kB XDzC9g%FSG̶ }BI .Y7TM3OC/ 5rroHh3YzbHޯX/TI^/.X[yU0'x [) ̾`fd-2c\=*\6#RI$opw܈п'}i<qMjЂN{F*VЪOriN8{Wy }ewAi~n`PvQBn߽BY]AϟU?6šֶ\uV&tl1Ob3Tf֍)39 y_EagtvpS8O|B+UV. ΥÐ|iwdOr *Ͻ:#oᇨfuKRd2u Ķ[nW޷4%R3Y M<4@ިn>br"qvG T0YЗ>0] Ri~}C.s֦l/Y rH-[ f'&pv T {J,srJjuW&0wKl=n>CNr(|jb)g1GWĴdaR񕅮vPh%N"\GֶIҁuA %&e fg=˓u`|]Zl_S\"SJsBNA5 L qNȧX s%@1wIjX9$rhC.rGP,=PJwm/[/xwK&BC u&of yQ86[a0MЛ?R"Wt>N pϴdYl pY\N)>t1o84;+a vݖ; b% 7{y;HPȿ.s@4~>yZ!f?ϫǹh :=ba<_SN,\6x-lUN+"h*ԘhތtvZ7֝ }mjKD&A_@CE`i v̊N qlU&n5E;Qm'`EQsmt :.ra,8`,60?Y-T}{1eFFIHPXe*^h /4㤠&-+t?΁ @l%Ϛ|w F~\$)ckm#Q9nX؂o g&b,CbS{RM m5V[~^πGhMܜe2bVo6fħR–$/3!{AB[a*zZ9Jrk|ٵk$LœyC>ɴ Q@jovW5RԁHf vԙ i1@CsM 8!$g@-n_s;ᅤP ,x023ʔ$?΢R-d˄$[xu{DX. }t|w0.b N ҨБ e1㧐Mƹ%YVZ5ڟTT0r6O傱8}v98u R)Ld)$p95"׮G~nAdN6Rk =kٕ߳>fg>$q< .vo$yU__)zBLc嶩I:ltcϸgѕ"yhJvyΚƿn丽UEU$nv ”^Yv<= 'S(%Vz%fzB?DZREH,$n;z(dIM# 笾 xowU`^Eތ(Q4Ch;Uz 8`po[m^Թ<@1%) e9+ǩ KvGF+R0 /PRwiplwۀ\tz[-K|7#!&IF.ExiہxUvb3uC:fIM̨XzVܦ,hNr{$_K &VI8=xs&I;z$n^ΐ?0f,]/(MȽ. ¯5$YHx}Fg&WE>jrSL|0urAUy 2}%Y$89Jjِ}!F14R~ðh; sM_/ŨML*d .u )pj(:8FPn/ D ^ dnny rjf!-@G{a*Դ>N/7O&b[tSo]4^ \y"<뎍txH2/:rho]&]*d6Lf{όLJ / $lP]Nz(\,6Ŷ>ZNFC-W2xL`PB68߬5-'!W1A-xe 5&VJ~NI O&+=%&bM?G/+rǛbxkZh)zl6'ASO3(LE'́@$XSm:.@">1^_D&zo#N_ԟ8fh"XoOo"[pA.=OK6GG_q9tKzIH־xޞ @߰EWxhK<j#WF\B+Q916̡y%7dQXPWj$_(htojͲW Dp>7EUE/DIB ^ۗF؅pi~eTpJ*"!+cXl)2wa 4'fQHm5.(;k3P '4J+jrTao$*Ã7|za[+lQ^I?6="V8d1~ֵ٭nK(~wq D%ޜ!4].sފדHbOiHje(Tu:H)*Y B%2A0Z`+MltQUA&@&.<)DLUO ?Dӭ:t#PgSVv|:J8C'ΡVvma I|)$YOP Eݭ'6J~EVy3Oui^#+j%'uL6hgDU>^7g{T S C9#ô4_.ޔrR Sw.?Itjq=JQ*K%Q'1~m@B{#S_JQ hl|0\r; ֻ !Xjp^I|:h=w#qn0^W(x5 ,(jmn4VGO9j:yo]@Rux5Oҧ׶̿d!.+y@;$hG'Jhބ>IhVI~io*j$,(D[+F;ZE]υ.6k_-$=KzBV( y=Ph;~5(مafͳEV?eD/!-~PY.1r<M{1_zMc !<ﻭ&24x_ `3@+q-~Ѕ\`|5]e#Td*YPB{ͷȾvW%iӜՉʁc<4ֹ] DgzXS,N7<\܉zCltIoY<٫BRIRF`g^DԽiBӐZ`ti3\vF1O=5؞Dbu- p.q^g@, 4p9@(p |Qޘ̻'xVJ'W:>լlT<^ >7'1xUyG.Ig bokEC z( 1ci/]YDu>"+ˬs!PCpRg9mƎ[=1Q; Q14,d[(?7tirĽٔ[ד@libS Z7 .oOpI!W "QFf !RdPhĄjE V`λ=zf1MG.F#c^XgHfȳUI0 @"f齈x"aI.gaP.I!R+1"1Tqg-Lz=TW[HKEO7<6tW&oTǔ dn {+/j[|]4PD2S?d,Űu6vId3E(IBx$;Sؽ4ϋ$X&Rl(r4oϼyR< 6E(>\X)DX少W=~Ql4ت^j@FBH Ж&JpX 7pT"qcId]6lq :>j6Uj`&WZbN[UJԊ ;N*rA/Ow00U9NC40&kPI̓}2bµ֓d;G&sAl)CwC?l̤G%F}[E'NS(;`@i܀P/'8}rx@?橒EZ[n 0E#yiJ}8acOx{ޜ #V¬{L{H2pԤࢋO]an?h*`IYzfzVVG!n;B` 24%a7#rv˭=9CKt6#ͬ~Wd}::V,3&ﱃLE0hpDy1ʈQd0 3i}vpV@e:sNIKzGd-b f6j)@&oc<<9th^c5 x#0Gղ$˄jX"Tԉo۴LcV.m w^Tǵ|9itX.X!G*< B*`񺡚,yh/>Wq+Y6c%s媥uwFb," j"?4Lj(V-i JWx%ef2%!^.>4ݡ 迁z:Me~ZpMfSzŐeggbַ_ֽ֮W9g2N${"hjW+ίA>*mvy[pu9: )Ur} UBrCdy`evؐ;72UQřs+TRMDx~6oS 'vч_sT$E%+7!^}Iyj!oا ,ajt69D^{Es*OѨ΀1MmEW;]. ˏh\D9^=n u+M_/gmT]$A%Ųߕ%aaȀwv׹| ݜswxϸw#?~hC(<cPགྷ\)4Ԧ-CGb1ʽ~=U4dž#=2%-.ݨ{wJ ҴrwƨTf*X jq!``PGV;d~JIx-&  hcLZUWeC,{ ~FGabQ,gr%b%!hd5M1l8KwP"Կ8MRj>C,C7 rjӥPL-@P5}Qb p yC#,]Mv,cq-;/ |¡J'm&I=Q7"*=ռsO*;HeR<pe vߒ%Wت4ڱL}ɌtRX6u@C_`U.1v FOL &s$6i;UqCS]ړˍ=1" rlrM=.c'9ŒZAȖ,; +Fn.& jA_|5ݙi )y`i (Ѳ^㉱*cK,;;.3)TDm6wxH,9ϵJ Sm-\Fąm62! #a ]g_)8oO`z*C2u;M~$K 9>! Fq1fk W/ 5b~X0PQonV*Ž58Fz$@^iD4k#qK{b]tvK43MmP8 _ jOv ۹U<*#G*' C zs<Gj͛o>XzbT죆B, '^@i5GA[Z0^u\:zD: v-CHӆCdȱ~/@cua ~P(Ƨ]J&sPԂ"ќPOZq#wC k(&eƕƌP9/E$@f>Hҋ\/*  oƷ~]DCA@Չ2Ӊ$|?s @ifv$J.^%0Vݹwf/3R#G<@d;2IDц"&o\#4e0L4:{\X ݬlĵp?Cζ(pjfoOnSp/eo&NTq>M#&kZxn{@ExP0D}>s F|9*ܴȑRݍ"0fDHR/h(eD*J0UpLJU8\~,*#w9ol1ּB9:FmgĎzL@$(`?1sK^u"i"~3XLN{fR[m/p)VOz-I9qD<"*wuN ]7ahr;߼bvd,6(<-ku1= 腻_~ٓ6rI-j@<? 8WqH}LX ']XA+701➷v*Y\H|;{тJMcѦ-["WWQϻY- SwjM>{ʙ9Z;bӛt' VIv$r[r!2:S&bf:rb8D)2R`m8OkUzY̱Dm_WB- dyEln+c=${0REsSh2 y`0WniqԂ≯LPJRϣiV zl[?7{_A GUyA/5 !%"" ٥FVUEF&&#f* <k=|D׹|ߦhS['d2\98MmOoK:opӂRXg\{FInv9vovBб.na};_\nJ+yfQ ~%5 /ɴ"J ׂdSm ka.~qAI^f6yI"S9Z4,g (#&GKs J'&ɼKhnw4[8C]'.J>bTLdY`N_nߎ |@M1ebQ\U4JVمY돑CP&N@Bb[8ITHoKi(onY7lVnAqȬ!9!9b~'끦w^zĘM~G1nd2YVV+!  c N_ nx|/t.bPG!b(Ŏ+%wJwՇ;t3݃jũBd#c~&WL`Z(Z|ٞ=s-v?ʥS#-J.!!A~Q* _6k9Ch GB*P'Go!W啶hNzHBaSM/CdFT'{gSBe~ }'j7{Wv2CfdK9ү"=Hgqq\+7$M'ʤ9UB;cL9Mc $5{3s iTVZ\xL^SoHGk65Svv;`<:eJSh%%V݈U1!iU9\ icc۠5f_r싊8aSjߔBECÿs~Tv ъ@#&Ɛ|Sf)0l:`üsH(wG= i$@Fƾd] Csl:6kvexoK觛zzq Jo]P"^>1+!^y]'ǡEz1y`Bm->xZ6k˂ Hsfec8Z&`^ö,9ۆ'RCeHRJ|}*Ĉ1Q(PnDz[3R_}LxviUA)j#hcYsnǻ.32Hd|aPͰ>oy8]qoZWxdA= nd)à:jd1oɡ5F3"x⾃ oZ)B(Pjy~H0ij=]]͙r|ݐ;YO1[!]yF84 ;ˋaDc2/rw;4'mDu|1N <tP?)ZqwRU'CW{V`wbOQn&)_y@D=U;0݀0sLHeɐJ): ;,LA*61Tj@<5  )i@P߃8Mo?m: H(d!NjEWyLu`D,sKGH+neUb㠝._:@y&T  g2aEN_Q :Z~L[FAQ } { $n)dB5Bz_oײ̥̓ιP&8IѨfPoXloXi#'qOT[*x1@|t@vMuu>' 183_#vTھX;c.)ȵ4#+Cu KbaP3}-@'#*lcFzvkF^CLb'Ih2* Z^dH[;GCf&9!sg=)#Uu.,EgE(ǂD2)RB 0{01TH&u vl #1.Z)#ӵ1XP|?0訤1Iea8VK| װ\,t]-݋S~ehVmoYj@^{+s0¯b*%NˤP$e23w,{`eEHa, oYm^2;x#v,3Ӣbj|1gV`61JƐ٤R]}[O\Z%Z2"n}s[Q8#alywMߥ]]ķt($**ќn8'a:/,Ex] J{$*gX]۫#&oNJi,Es]H?wu*y}GڠtoaMhjhW|U}JPRfh|n ԣvk)&|. WWɣ/>ؓ_7C48uE\x( s-rF?bilvx=;F!NnywƛB`P'k <8 GU!k$A ?~ַڮ UXPkÕ|b:)_E>$ !PKV3[^#tKdL~Hts!.$tћH!q/>{Lq R:T0Q/\qÙfкw!LA .@,>{GfXɹ*,.(t@Q| uȵh0L_$So&̹׊F2X/Q};x$RæB'kdE0u@oa b:MPc --a!'(-p*bu- ~4U98nơ4.d}'ٹljIK5AdgS"kђ3ixG[3o&xR~|yd!,0/]9f~] l.Z:o (NFԠ GH[a伨TD$YqAޤY?RgVIHԎs^l;I(XBa`d}vtEKA8*>{1xrvg9)ʻJa©qϏE4|O /n1R8E/5:0td[Qy8v_LD=D!"bTuX68P-QǬ9χs[)XH /fv`H7z:@h*_[]y=@?NbLcB$$ݝCK+bUNe Rs ZB?L39qVWWAI\tq!Vg.kΜҭ;i)BM9ׄ}[P MJ[;MZt-#\vo" ~֐3s,^K%\_;.Z\O5V ;WK׿~ 7yCd'@ ~k?ah 432K#LգY0T?ܣN1lwp O/aƋ͒-5/A졐v+jG߭mp>@;6?h0@VY#Pmb Y`C:_66/eL|Lԣ>M1ɿ򶷲D>6< #$ePG~V]>8)ePdޮ}a(^6Q{0B|qꋅc!J-~6]ɜ$NI?~-;o}Wf9N 3'{>2IP\r >pmq K8>X>M< כے@W0xeAKXK29JJbχ?\8y"IlKC~-Q̅N\)?0I؝Bڥ&!K ˗fPqadNC._+io6U4T"k': 2GvUa+SQs@n1i^TfzPưd&mysWTS/W{®,xstG~a \OTpNs^ڊ!{KtA>Mf^^ @W"ȴKJ<ٺ:aSiW+] 00]Oy>]1n&dQW`M vE_/hj=ZBRDYdu 1{f޲ ߭کq!b4F5 >W|,\ʏ0T$A TtCXnDhG&\H>YBA 9w;:jU,:zOdxGH"E`hTuE 6Ӫb?V6zyv\n@2^6}F̡ 0+7(KW9[MvwiG( :poƋS90~vfj(ouTN4n.֥gmLƎh ɣ%ǽ|}&)񀻍 bVT2"x닃(#"13[f#.b_*G>%d7sROqSJ bg,9[nLPe,)* 6qPm8|+GԾY..S; NR{uv i3 VwA"%p.Hx<7N2DCg^R2 Is!.xvnԡL>V 5D:.Zx=Es D['H767lښI;wݗy gg.yt|AYA&YeLj/PxP4 x-~[ ́X:ژ% #~GKRoG^z Źymoe!M aޢGhaWϖ,v}gZ2Oh,a%|Ȓk:E՝|VMuߠ\Ep2O]f_=t1"" 3[[GTEJ@ai})[66X߱5@uPÖ.,'"ᇘ Kh MXT| (K7(M6- 2QW6rčkckOSЉY"TՄ):*:bu+/>++uSY5Hc'`LNk<3X OH8B+\x VDs$?v8|D#懲j.En!6'Aɀzwp\8Sk(TC}Kb)'%܌"M͛XvjP;Ef@["]$y%^5LQV!YqYH)4%i&Q#tv orX~jQ{$O7Wk36$j_ScݸM6)Ӻ?9vE+V1{щC`y9DklKI]Q0YO uIُàN-c# Di`i[l$ͧu.|*h6NqSV$AEU ~p"IO +\X\g-prxu =[K{W+/paLrϕF%N3 |H O_0tC GJgM(͈L/ W{QnL!WO>*v\6j/"fvUoK$LsWgaj{N aB ׉e?$5{;B1γu]49 .v;3Ύ}ef9I׷9l$skŝbTQƈD@]Mǹ?h@g?#1oصt B"Mݥ$nWhY':Z"җ Xbά7ݜHΑsCΰd'VGi{V- P{_xD ^z+B E9Mfe-sqHҐrb&1)R,Oz^oi2ND' v')! ⱹ ȹFG>V%~G9gxߞP qG48?H{H8 8 \T$auvBE8LZR_r/ NѱaWYu?6g ?iAl8۟v("ū)% 6kܛcafco} Oa{>).:'$:Q4pGۻgTbbwG ǿZ-r \RiW{ m+C=.u0l5Q "HAO=B NQvk%Y ~!7=ݘ(Z}MӒułJE qz@&k"aKi)U/nM&4R!˅H,j_gcau<^5Y = MEp B{vGo8a۠-}+]q/囈uuQ3}sZNHV?q{&gٷ-mC˼V'PbE>{P-'f  -Эu3D-E+(Oxg&DY)!۵9;PDez:ߣzJ"$Tns+D7F>mT: .$fl0³)?HPNLJ3ofb5wg83  qrzzIS.j#^/ۣH Ve;Q'mY7qUmF4_#Jev[,2oJz1vߗ?0M{cLS)|,AӘ9V9dڧ]-cZ Ng$!mz(xT3?LjV 2l4c^$χZFڞ Ϲ/ 8j^Siz *5f`C2"2/m$C6S"'EC*5N9qOL| ϸ*@:#N`lεgє}=3m |WR#1& vSjwi":2뭨Dh%bv rLA jn.8*0C+scg(>}dׄdgṼ2(A#Ro!%WϹEۯ> u12iT: z~S`ɶVOPA12l]lEd2Z^U\4Efor:ȉnFj<\!7."g=c1C΅^'r>>#no15 (`UM&[C>WJR?vЃ- 8@'(MpJIfL;Q[I07y N<pVvbu0쫪{p?tՓCRͥ e`7X?u(TonϨ/HQX<ѣӬgQL Ej*1O\[psȉ*Lܷ1U?EڎF)NH ;@&]mr'3Z>=jg(~}xгM&/C%<} ^]~2qu{TEUpNoYU,&Zn"o9G;=6j46lww3:?)XZ|?Sz0'L α)3`@[QZKT%f::|ƯJ)[4޴M%F.}F1L!AEChPҫ{uVfݿiׇ:n˫U^VU 6a^ Z`.ue3Jn9;Hqn i4}&Ěp1^ז[E#0/qc4tEntґ*hx|Mnfyë]xgMz^ۚQhwܦ ~GHla=pj+*M= 0mǭF T 2P`y@[G^&S#$RcL";ڻC#7{),|`Lճ+nTi>UR3dקvh>1I/@=J$nTüjDlMPĹa,(Dy֝z{'!V>QRLEHh!:Pc#ؖF$$"ő6IyF C)M H0 ,VFDTę6pЫض3Tꭐ3#G `S|fL]"(i8<Rcl;fOo4FU~8d7,gY #T ,:Ft鼷uP152͋#,f.s'ꛅP艨>;e*vY^%2E`K{n SoK87k윬4{PQd ?XwtT-DY+R)/ٛf긣L< 5nV^?7Fm!N_|*zvCyO S'JG#M*4+hoS!3hN_ӭO ^{P[xtEO7[sٸ# 1$MA !@6(-|]a"lnyt`Ӽ!~IPe_$2f4?Vud jd+}Q :x!Lǣ8}*\l3?YD<34|CvԞ8B]||hPoh)r0KΓ[Wy^T|u~,b*IVշgJI5X{̈^Ps9&IS[G̢ y |9NK?bR{3 *Q pը4\b?`_5zw!U* 3/\&j{ <5a+I bELfQf׌"+7|fq1~J Uܪ)$ay0ᠼ8Nxg3ps'VuՑTtRJ/%H^̩nᛖ8^L ^S#-rH>:$䡭LekmϩW[jX;%-[Fd(K6FF=A > qݩpfthvCᕂbug(j+Pɛ#x>#ˠNJu*qY;eHԣl2j!X{08S!fUOߌT9VK]k9>+ٍ/cȯ t]D2~+6T&oWrL10P俥7M?J׵ٔS2U5dZe =~:RWȺfvχ5O `1zƧ4Ryہ7p%! s9~X$ $ f}$,U^V΋+an4-nmLd ?{Q<o#~SFMmr[-e\hlR@%)5gHlZq]ڲa_'AKgW]-#_IvКH=aP=vQT~LQ) 7ܒ=Cp c7lL (jD.v6~xqNjGٙ&><$F isKt/~'5X|i%}ܼX-{IqYt[e0y67i o~oj}DSHYiGV#vK`Bra&' ʅYsU %5Fò?.3d;xI>5+ZAOЬm4Cξa  Z1Y :0XTx+@ʣjhxMjl)bw(GOΠ(2V%v>8Jp6Oa" Wx%Pv: {Zs?1PmMbv]\a|7*g,/m|Һ OTMpe؉Gzkij]u=$Ԇ{eK`GJ|05}& *2xk 7La)$˅GM]9hPb"?cVc[ }lL+ɡuZ"6Ut\e0TB!IC&ig83 aU{{˺f2W[k0bV{$UO%Ԍ}ע0ۚi+0_ׅǙt X.ϱ8OicV(ݮG@qBdY>&$M -e=Z/G)~Wu]U8<(P "'HRpfTQso2ѲH6nv=a?6`iHnfdq%=f0uXpa=cd tSo-Ͷt ԏ"zZ&1cH8{-LZ%j#k|s h}eF0J”Q|̙6žON;W}?C%[p!Y"&Ǧi1LűV9fʣ˯!<+[+jY(!I\ۅ3[P3OVjr̵a%!nsigve'x-w_%CZO^Hs%<,Oӂ"V34*BVX"xb/A+Tk?UAwqųyBmNEΡ=:% Pĸx]~UgDYݯr_-Tm8v`V鞼mۚ= U#k+ (Z)^uPxDo(TSP}9r)ܠ(A~^|hJ)YMious,CVXucoL!y' Y`͜\>}HCB#;C"k:= X'^)%)riCCRqy%B^͟[b_$%V3>һSF(~5`~LgEsЀN|H4 0H)V}Vr`5nJe|hSGПKT?q|Bh{J1[ar_!=RQX+os` yc?hۀ wT5"Äk o.<1B1rϥH*#wyBn͚ԏfU{b BwAbN0-2 S2؈ R )}ق>4'"'}"Ҫ\NvIv+:f+mZπbҫxfzwKܖ@?@|_$Ov}@ҞUN1T5̱NR+'epwVR],k 3{4J ("QOdruEcd4aBBg aF/[վM=ơݸu!Do5y(q+Q0X0M~F" \{ `Uљ*KP4A[ҨGa!? 䄽2l"?ֿwIa܊H.BO xgjnrX'89_F }`Y:5r:M\?}poZRJJ,y`m ^R% n=huPqj4 j6'|f4;[ B]hX ǔqqb+-q-o1:G_WYqS-B, 1 X4HKDZ R48%VI{HF6QF,޽XA %i9H X0 *vf/qHMxI)6s۶4mϖfsOQt;v^R0yI͔A~d Ei0YmmH/^b@E@=5L|\kdaae Xj4 UgshOߓ[t^LJARQk z76{N5,{H2.o9 D4㱔qb3CuʚX-_[h-OP %N5.j@odD$m= ӘOB6Ը@ 3VJGȥ'*cX] ğr6. BM y!ɞ B@'N+k_(rA, HYbv˓*C+TAa|ܴCrx#HUhPf "Oa`$ b!Y}zy;oȶV G]h3: vt25m0V45Vsyʵ?PX) $:۫J/M&{_nxҟ1K~q=)V,YRH^Ir?SSV2eB@3s85iO~r[tWt[>odz_,' k"k'UU kFln+N sjBni:{bRUA 3BxŸu;IJ8 ;ٗT^ڝyڳ6nIPvlZ$(g>5mqf1ס!ݲޓN֦43}g|vN˜OKg1a`8plryL96<\/҅lBK_; pwI49G\ʫçÎ+!65睱r37F[e Dcas=:pk\ck fk=ވԜ@==󬘔g4? ~H!Qn67YM7ǾUg͇FDyw35@/tɋ٨ d"1q;o1Pf'Pl4ŸA&VYR̄ BuŔ;ðqpŸ́2(SO'qȣ{ !"K #D)z֙э*؎π8N?'ܻaQE8vq5E[̦s a :b 2I?{<R>"ay4qjjN{a`iG:#1r 7Vԛ &-r'!ր|_إ?H Wwq`IWC6+o0c {P]dF4csB5m@~Rhf}eͰD$ SqE9ъtsW;-ox=ۦ:v=Sz7g-Rm`N0c-`ɿ~^֏M5f693RT`V=ob|_mwY|AV+e`?TBYV<j8 HV zԪ@Qni_9C DF2NEwN6svL1 ϟ.8eI[52Qe{_&qt1^֔]}lI FWx'ˊ?zlYҲ<2 FG>y+jTQ& ܏kHoNӵ\@t;n9ST)9qڶX}ߴ`n{ȻRi{Ű,$%QlЦ=k} gIX{bE6M(:Jm/LK`+G3P{@w#:i`PSO|> &ü`ta 6&= 3;udv@ 蚄7$ %:ğN3mY0OdPw>i<"q \bZ:!:%ݑף/n~ ݮJc_o`2;傫υg|H>Z|h~]Vsj.fuZJa㡯H4Tpcv<D׈mbC?.MP 'K7w4 @bYo.l*RGĒs1 H{"X?sH&UmEqɢVP/?J!l[WD☥&TA 53+(Qb__:UDŇ{8dį(/e6#eo@uY/"o*'؜koijXNb'yLG@̒iu̕X_?a|rE )kHE@XC~^/ -+W"ׂqMŨ2tQWInV4P0ivYxIpqR[3s:? N%wF)'H\F_٣= lڐx | zl~NjQ@`6j'SG\0n{7 'dp#u)Z.zrahsMIoK9#R7QoyW]/Hy>n|)QN$B]IUƸ )~3壗c?4q5M=}Mi  SˍfcR8# ;\'$3s*]2^wQqDY0>=//;da! R#K״GkO7n@f;2 /P s=~T[ 0*+DxM9Xu~rF$`{'N=J ygg!y;J] BK;񉛣CW<A3.?tC/n#pۥlnöļ֤&ԉILI(` 0Hh9a+k;'cHs\U+g \GYi= h-Y?_!v^k% J?Ũ?ٮ/4D0D'9-C}pwP<6 U+ɐ\ +FGcWfdG_CwX2.ɉ(9^hi,mp:hNx_RD<q M )vI\/6̩T,Es$9LWM50_:՛jzewVix쵮p{IP+uC(RdAHrYa9b Y? LdžT Hu,/R' mŠp0q\pw)<~ըhcOxmRҝq &4U|"=3a'q2a9%ԬsThP нX}e1_/~ܻIT8ݒ /|rnk[>/@IUl`hG%ə=+ (D $Blкo/xt/{'_<0 4#e+3'(8$I#ZSv[ Zz0hMZQpݐ{>|85n8x[=]P |() %DnZ\5+Lb|8.[[1]JGf>A46SeоSݦ.*U$1e%R0\03ƅL4k*H ZXPj +BuMM_Ƥ7Dl$3@?*~D3FJh0ڣؠh]&fRr}#9C1Q0oµYX&-<> Ӵj1cw G~]\sYrV f۞=Q\v *)4l (MLqUwLt\>(A$"e?S;%7MѯBM<\iqw2s no.?8[ٙdIc*!JN !Ljvk+f3]^Ʋ. .6{)li]~%]8YUR]/OY e/epKThҾ&Y%09IQNcXpHm7~(Is|tnj !`! (\Gcn<̠N8NLC9VR|(ru!]EƿAD cno!oT Cڲ#c}QŬ'R[^  r` }3ģCNaCA9Xw b>_ gQW_.uctX'_;,ͩ4#!)1]:OERA6uJ R> Sv&nX)kv~^Sᰩj06cO/m~>_5t ]^쨚oEjKEƲk'ν{*ViB`}wIZ|K`)r&Mh8Sp-a, %2@6jc6z|x΄:8RE;.!]B[,')i}~m8)tqҤĽ* _[?ii4Io`4StIfi80$T.lxmJp#4uOj/Q)8XO&y+U<*Zx"WڄX+2q _TWrtp 7 L!zŘZg8zgѬk6D̈^|eG<6e *Q;X =WΝ0d2"eD H\ YYd#(hY}:Ce%PfX2f{/+҇"_X8~"(_jrXmbHN)J-ֳCÀyYBFC=~i6EM< f4guӃ HqwqHқXm>2.KmT5]z-p lvʄCAql1w#evl%bG4"&XhU@WIRȋ!p\݉}C/rX5LqaOP#X#s7?9Gۿ&!ih'ua&9[\Dr"_i ~&Fg+^ߏå8w` GO)ypPia|+t]2 L;T+lD[0)&LV5&zRtbh{Jے%rZ⡟EZweP=z pܟy'D4y)hS˨Y15}l9U=t 0 1րGPb}3jlhߞWuL0QporeS\I+*DxWƓm\V2eL(: QH%Xs(EZ&Kť /R4ࡻ+J+"[?Oz<i88 ,z[XQ&RZ-H16S"Kƅ,04אkNABL4K]\,22S-n;eUEJF8\cmK8[q./lZV\OTưm=M p=st(_W32.IyZȖkXŦhh--^8ܣ@JYi6bu"!ŏa,D/*|EN^0cjh.R.*&P'X[էW ywKk_`V 8pmxw8ugMT@/n!mJ"Z_`LUSk=yW! $w+>\ M"=erqef@J(R͢h9anM dPRTl -M' 5GSpbg=4/os?'=? g4b~gGL:XJzmp)dkjxiisw,l[6 q)qp  Ls|Dk@ #DAk؍Mc7dEDIJSDnk+ڤd6h’a-Cj׍hxy1<_omeW+3]inSV{?*4ҏA9L][9{>/<וؽ~5"u!+2gip{\xۿEs p|Hao87)f b Om2/0YYM7h8$.$ 9KR\/7[61.>_d/B^(, TL| 9c˳aA ID#`Z416;?#~yaMAkbaLKp|1}\/<|ʼng6~ "/7Zb-: Pn( Sk 19\vo9٘H׈Q:y{TuK;W4ࠬ5+I1dkbL;Sg3.Aetl{^}lQR:Zo_K㠓됑 l7F'lٶoxsrz:/W~]I13/Mj]B  _m,tlVҋ-*.?ֱIArU%2y]lDca,(F%ݨXHs1:9ʫZ)͇qLh~DTXxd-E24R0/BL!jw7yDD- >s9=it37#\t.dgFŋBe$u5MNuY'PߴHӇ<ѓ^lMNפ\] eH!T WGE'E7ahzL*"ܺh(Df% T.qa!mm)3 !1kCk_kٔt:Ξx)Yחg#+8:Pzz١S_.(aƇ|C sLcN2/uDuL86*۵`>X[5tXV Ln7#TN"<.Y@0Ҟ2 fPbZLA=Dve_UߞA Bҽ'ķ;x(ƾD-J7x9.k4@+Fqnu4C'_5YT$[^h9H9N \zRu$b>/qKu9=qk? =#k{!iؾ{m%m EBԴ~g-.Wh@/$m!8JD{j8M0~3}.qw޴n"lJQH栠S ="qD'?=r F%~L[Xb ίԤME`J5)CdN.( C!n?p r%K/BK&$^mh_,] r7@zޝ)d?w! W*5aHb+݅UcXi;5Cnug'K7ԄTSr혦67;a.^2]B5=䕦N׺YGu@\\0+FN@+&9Ӊ~G҆odn+o)| pܷ%FA;zw/7%IbHRw("Zxp(UT_Q u }$ǒ֫dH? &l 7=op1^MTQpqڢjz[ YTI9CɞNoxq]LWSy(\"H (3fRG۲K g ӂ6Z7]J43Ǫ%𔲍o<}1]ߪdqivZr0rVms:c-1W GHuW[uf@|$7 [Q"Hos/g{/xoVtsih $NXx !);W1=mV`akwGj'eץm/Bu6_ ~U Mxcߍ~ǝ! >F{^M-,k%Mk$fR!MM%ҳ(Lim戶Iή7A"U Aq +xPA'-Ju4w9*%W P"5@~ϓD\ʹvܺ^VgZFQSt}y2<10tmi䑍 ;m[#bPȊeMD}ߍؘȾ%U1h"7X$ G1 o/fF`Lt1{0Ao a Վ1pG S.!YΝ:a&;I#]ep݈V}bN)Xz˅dp*F 뽤Ept$b0%;acPpE" u}GE^hX ]ұȊCS3D Ug۰ xLe8+fH+e[aSJ:lȥ} ^F`m 뫉}9'ЈJ}^P$5!e6]6Xjn߭H@5pgD*<@bJݴ{rCʜU$•bZSV|F0)1C^YM*CP\砛: 3YǺ> 3(]qm@rǙ9;]}>adOg&p! [SK E|X*.<&b,'Ӓz..L#0Bmo12Z\'ftQOq+A0o+݁x70.67Kj98NWuzn`/ e^2]p8vϡBqWLG=vG[tXN߃llVX+vb1sd UGX3}lT9=%QM]@qvOv_ݷ+[qrzH&|ّX3l(=זb4v[C>V7Wuc$M؜m~:*&3x/Y,;()fgd #/Ik db %H,zNHRl_fU;#꜎,LÀ-$W\2^NDL?ӌ`|| Ͱm^ Ր!dHbĸ2`pGkٓKf=45cig/X`ڼ= vZu|*/Ba@yrz"y q1Z@ V @ms\VjirqR٘H{@m|!ݡDI ηQ|Z#Z]'ߞ_)$a;M"߰.%[(uٱ$TGzM;i3f{8QfY:p?^e䦏NR: >uz,O `$1σxM$!bj)s-@ q7iAPn%^.`f2WCxT>C֝T(ayù53l0&Amk쳾> !Z<@y'}+HeCĄ*CkjqCÕ^ Ѝ }m/*7^qf…=nBz/صс{x8j*+Ac_2sQTIW醝Ɓ ,Kp2-u_愬?/BjVgjQs)[SeEhQ#ˑr7 OPB., tGB;Dw KQmr%oFDFDJ(A03}(Y@J:+ ~ Э9Mu Wn IeF+rAC e$_e5KUOM P.rļxx+SgA%xJy㡍 b$wB4XrGIt85|TV'܊[ِlVB h+8Dz adlAK0i@+&Hy-0K$X* A(T 8q`mR4*w#|(Pu(Rk阧pyXe)|oMeursz^1GBR3V֡ic^[8]CTd&u~{P05F1QT<>uL-bQim۽is|R4d}#Z, >iV WC>D7W6ZW5Aq}fa!ߐkl1>T_q 19# z0׿7QY^^̪XǛyϗsc CNhѨ"PΨv=s{)< `k7S TM6~-M1o^_c;;/ e렙9 -$n5[+WF9*~/y&K:V^3E7 9ϴ@(Rq*xѧKںf,'Uj.0&])ign>bۈbx~݃?M ὨΊzY0ySdQNi:ttؼ3+q=`?2"jk8@%2#p)i&red,J,v~\eƦyn=Bo੠Uv C&L3-575l</+"W:ہ r8x7A߻5/h{+Vɇsbs0K!`r ,*?)⩻^ ;L0-V'80TSFo bO˹']v4WO4K:KLV!R c'&Q>I]=pl\TmB^/X˟2O$z4fO"؃WSc8xxi;pxo xB 䠔bh{.`v2bU  D?cY2#]~'*2-ZMvT*lb/B#϶\PLv%0tHm}Lx1YrPQwqCb"=Zi~dv' o#kb(EL1y<Iɻr`|MDx;U\,>U¾]B]Ky$A'۷һ_:X /Ep\6 (Zgp$f(T3+`5餀CoUb~bt m~-I1s|6"H:[S-L1Pcd&$/^ȩ]~ FĿ: )t s*{IgLh4vRt WěwKT{x|A>¯M5‘p/C-7 "EqռphJD P|r;`LZm C'\","m0ωȲ"1릈lL|.LMEMk!(P>"^@~'-+Aa%q[X{4>ZH"B`S-ouÔηR,6alHBz]ǧDAOB;IeJ!_LjU$u`8!"̘OGgW:} fyp4uy!Epiʝ%NUbX$ړTp9:%!4yT>RӍF{Jɕs0^ֱDjYw[;?Q))b7sI  'UR{CllY8.@NIͼ'/k>d q͖BD)'Ge K]RA+:0;5 M8reiw~eU{D_Iw6+[lʖύRh jo\ZJsJ*t|?̧*fUi3 )lz;snOka-\˯^(%Ŕ?:D;z\̆A=Kd֘#P[EBl)m Jfa1QKJ5}V٬~{z5 Oxzd ߔ)]rz9i8}'}AM 'Kmގ-QE<([g.z9Rq5 ACs:ϥ ca| ۔GY==2}Hz.&|cMSN Q.ފ"cJˡ3A-?1,=lP|P:"_t=I7c]iH #!C ʫudD$GYp0ʍSVf/[g~nYP Hcq+ 7!qgvdZ,Pw <F_ Kг&HsiHQj5[4)y ZXN|Խ-lhHSwVcfB{]ݓU DڜPڎ cq,nXKB%h-c~?ň4d|3Yk DTb D_)mW5F6X4)zC-? cUD'i|ھ7NarЛ )Sa "jɂ XG,} 힏d:9F局9#DV| NtZ9]'i(tY7]# rd@Ѿ{OS Q`FX ykJod p7JH_w&T ~tU2y[p|ȄץY, OV$g+ay;o?Y2'GiB}E]D4C Q;Od;0{2\K9z{+x9|>ly>}1@/ƨ眝GYϢ|yomDZa+,L ľڠ&e#(Lo4[*Y쌜(+];Mho\.W~E`b@3F*2 A 1IOt~%8F5Ayf;pdiMHЩ*-Ӊ]ߢ]/?aX*g#_&ɑȨҤ-f̵^_ EٹPdr;]?AaM37e`gV׈:~w }`ah G=V+qpZyS6\,5%ʋIp8*+,|"5}-HsW*E:Bx9t2O)|)-[ m/MnJ~Za&v &mZ "ٗ%RV֋#5&2lR^͍m1Fu,5=$"A/>H-RA&2Z!/ Ep3h)%'b#@?Q\sЖ Fڙ?+6v'm:YL*u ϸ?*}^APOXT脧.VzȺ'YSq>W3m ^d?eU f1qRT*b- 4 fx6"̈́z4S>wi(L2Ur'4@{ʡlI/į<=%[iVTnblu^Oz5Xit.cez(}wu7V^ &KWX˝0ˆ[}Lq?sm#29VИiLA+T%eVH)Gr$A޵gAE3b[ z{ 3~H׫N 8BI_)`sĦL#U;75@/qywCnwXI/յbuJ7o+ȖGV?9R.xQWcPg?Ɗ8$U$=O:/*$OUS1 ,F&ɟ:kmZl8nv312G/g-V@%4X_tT6e zƂh7|ۑ DNR/g"pz)}Z.Ho~ڝza K~ypDAV01RWܾsU'RB#EX`ƕ1(`Z>0pPӓ5,:[DœlV`٤b <3?[cVYVq,&vt ;@r;(Ax:rɆ;юca }NK0wK=a޴RV3x78p}h( LA=kugE츂A#CCWۈ4s'(lS#mnbO0g;xK8α-&?\jZզ/')3^)Elhq%qi֭uh? (2$I&NjO#Aګ1}7PY +JksUsp ;ܣe^Áwvjz oLE|%?l9[xz:*& LQ'b]]-ԗB̛eбQLZMW6=A ֐iǵҹ?A~DДq*U'Mxy4vʴ.[ qQ<si?TY fN<6iN ڒ=Zx"&pժNh6yX>EK)/[}\Ρtmdz~yΛ=/*0>B<:! >`g^U$|4 f$ZC.<RJI[f =Xn:~^) Ȏ[2}<䆿7c,,\$I sFS=bnATk-N&UNe9WL[K!]hz@cKꅱD$j:j{~mc$Þ)b*kEnvhp/I^xM}ED;*䮘cRudE8[ZD]f#އTi0G*ڡHNűcI:Mj}c6-`ͮKd[m;e"on]w?f^:1DLJR 9 K__(},ȅ9`a0 <'iqa49;2p$6u]Zg;\\4vbWqsG~82,4 l)̀s;:]8j$Bƨ @Q 0Te_jpU/3GE~QOqsp 1cS-6*1sdnChrE,|܈AGHPP&\nsLJ޼N7v j4<3}rӤ$iD2 |dĬX q9aPTiׄ[InQU+}6+Z'R%;/%D3;+G,mIaJjژh'֬9v`[joA78  fy>&["v`׼l9ĭ"W{g_!kh;I˝dF V$&kVV!7Jp3|sⷒJT!ɕ1p>WU po:APE 7)\(n=?o6>)厨3 8ydzem$|{RW@*M+UDBU,׆] *F 4HU8 )&^Y:Ě]OA0S8 6Iȕn DihE A-\ 4#MdVLhlQ)ЕG6ǩn7\ȡ9?;!Wۡ *V̐Ee^\#rkM:QP ww=0"k{TFzz.A391`8t\K=nzLCx"uQf;ndM&A&/}nW]GSm_?Q_%ݡz&8b<o2f[@H 5E}<{*hz0i⇟{/dUU5"l!M=>wԝ5.ql[UТ 2?Ey4Id?a00lxV:Cl{bTQ k#^ϘZ5;Lpp[IG[UN^JN}4h*@?4% jib4}::  ]9S4ޒ҃ͽ~]KK{!7 ,CJ3&}v]taɀ+.P_ _2( ZH ]68JCyel^G?h1_U$|OtЇW_yޏjArD_}0]h]+إ&}2A N+,„)M;83Y~+d!wqZI|u'Q`dʶ2OxlZ[#r+-S&yQ Ap٪7dDlT@Zd"% "_v5S#ՙ+'< L m}e}0Er0{l\jlOOZUrղy #uN(Ҝ.F%6(rS$ϼ1=8N/z(Y*P ğ{t]d>q1:ql4XMmQb"OnAʤi8!>YpM*X0GJ]W;;q4dɝbϤZƝAd +mCh \4k;@ 75xyv_|]Qf('a;;JСɰi{@6[aXqO$_fmL {Pg{̊xDp -- Xtt +뮽^F ^ (&(|Z!iu>'{Fnş%u k qB<((ol~bK79] jqRSPSl?xGbvg,2z"@1ڐ Z݈ga%w WY9l<Ϣ3:SJ[D$5,ek9?DNJj%7 91-8Z2 xFMLj.XsmˠlYJ; Wv{# `}}i1'{z9Sm׋BғZ: 6KR>{hw50V/K$"͜+J^Q2a7TN<3[j$,ȑqw+;/Fz}4&=9wWA} Ⱦ0NӘhBy# \=öi:#hVd?7Wa ߪd74v|ڳ^$ P}6fVc`lx=a!&g AlܪFhdC(u&DtqgZssF}rA:u󮻼 Oϡ߯m :_Q[ARsv-ydF}YN`nNmm7*dyM/'ƿsM1*|ɴ=FGv`ΫJТUKӅ""z1kT*BpQ|Es@_MOfxnY EX5%#i7fõ;%< -#GAau7ر` -:b;+B#=捜ĉػ@m}d˦3daS isٛs9OƟ:/ !TSX l_CHc#. ncPMA~jU;EFB#tmݷmA.sJ 26 kuӚ_ź1'd,vcq |4ɈrDDu<{ $f3 솂AMKJ|¼A1!0p(꫟J2/ϊR"_{(8t)Ue%[ezBq+2FwiُR-ڌlt?Ek{$PvU [وohUEMij2/X":8 J {^L'E@[^JQwկk)}Y2 (O^ʵpA^ѕ๘˞/ޔaAvTd} XFB6B~e;2:]6FT?]xǴKT3 V#Zdٸ#aw=md{DOoW/)#XůGvC#reCXA[ qs>q@ qn3>!U/D(Nea|hdzcծ(E[hucgD? ,bDwoXfzK!29)>ܲ 8=R׶&o6pRa &jGOes᏿iʶVߖ&+RYτtYSG퀵!mcxӂz*@*UfUDg7U찑EӍMjJ1npzvLܜ)P ]X .l%_G],Nـ@wpe%jV,D:t0eNlJG ^ʄS ]b˵,R]?ZfS1G1@jw{-t<9ty|ûuce6dI+>O£ϕUvAe ]k@LMdZ@y]oHO<C3터I·ѯ*#q6c"y?IsE,T'>7&{51Ia]҈ƿU6rOdֿݕurFY xĪkNJBO@$ahY]0 VH] F EnMςkC'XIp_K$6&ۻ@NEIaRn:rY>{PNPnAK5zC8F!W F[4R)℠[d^d zLRm< >/^؈YujVXm:Ugݹb|6xZAK6.ZOLi˷.Qލ^Y@ 5 .Ssٶ"EMe7 e삼Eɬ@)75L|uf)vjĊm;Q&;d͵EK}^r*|*lZXRsw}Hf[s>muT2xDzIԓt`Z K=OMSR7e[s'Em<4m9R>4QƇ._;y[MEOB7,pۭ_%kAzRUB0 VPi ?n>ճ} ֵ xmA|kEj/36·~i@+Gl+Pp*R-f JѡHզګkBbitx~}9s`הT)5&Oe~:z$5#ݵ~4tB-@fig"8v_9R+ARq9*1DQ A}&R4Tt,U?oELHpJG>زCn$tO۲;k&눗X5[˵WWa\%Gy~.ƙLJ MpLE CJ!}dGKU IB1uoԞ7Ki*ңsW~!޺Vw:J>,׵'t}4|wkdȱQj"PH%/btLඇ>O\R-!IŘDl1Lk f~Df\hvDVM'\M-L<.Ѹt VJ@n~!yMq#b5 : u<$I٣t/ L5 OTW0B`N;E+8XG^'7Y'!%uRyB'u1;E_v#6~~:CQBzP8( }BlP(WHb::y^L.pҥ (CgHڡ3WHϐ/42E> 7%Gc>fw{Si8#jx°l[ Tԫj77l/ .k @_\tMz'^ h$r.̥@lԠMm+Hm0CLgMH ) lT"kȊWGV[L(@YZ&'[&2ښ'-EQJ4>Ao˫[7X'$dW['l2"\CcnMcnBSZ 9dm@ 3MZl ԪtA)HڈrN nPmdCMeU۪z8ACRp + yM`sP}^kRx풒("&>SO=;ѱ@(ftm~Ia3W^?Dr6cL,(Z/s%=lȭS.'M]β)%.<ʈ݄Ȅ:XPGizU&6ϒo">Nհլ|.M cO݅1*7p>_Vm%%$%эDZUF']nPoN5abdhCm_ FEe gm41E9Γ*Ke[*>k'衊3TŪUXe̮} V'˹7Ipo@7qb⯽M[RUUcU.-fi2"? e\ eOkV;<ה3hUKomLר ^U c$o {?ʃq?T(Gq"OT]n's TNV.B(7M>ؚk~l۽ϹSh}3\$Aj%};pNy]'+ùP=-/! ۹P H4p:*_MLpKiω 'uC"2dS`uğdGU"iY?v)F_@-,$B]6v5GsGãlj~V1@\-0z_HbW∇w@;bY{#ֽb\K7+'vMhz0s^GD"d/u1ٻSԬv.0|eix/0KyvX7IVUg!@E;IVyx_HtCȅ,q4)^^<◌C3zeFO4=C?ƕ8mkV ܳ(x'+Y%Kl%pW؛ߤu)/?3ddDxu Cصꬃ-NY!R"-_S_]zuBϹB((Q/y93Anʉ2h2h1 W޿[V#6q jl#y *Y{9'tڎ:Pe` o3`]>/jA2FUt)[hS~8Bݗjri yn=4;{3t7$Mm6y^jG)f8௿<󏘁ˆ ERt~[>/jޫ ŜŁ.*\g^ǍcF;r{j%X?<'8tݨ\Z]:EzMmuȦ%$;Yx0uʮ<)Q 2jjꁅ=D]8,ۃ ic0"X-Z}xi [H22>m.!~ɀ}ٓz ӲAfUA>vfGed-Ansl@r3Oݧ5ܺ8.S*8! ;\oA=mGD"$b]|D=+\~O>QdNVJdP̹wg5 r1cԄ#PHQl}lbPXC"/`+be|^x/LCW Q.tk%+V49s3z8`]QbpJ)ٳ*Jh]k*+5,8mZD (X𦹧aAVKƫZ:/-H% \9 WJZG-mVSxt߶ GIֹ&Tc`i[nӾNAp[83 Qti^Y[MnQ8DڝdAw?d'&X4U3e늁mJŻbhpe%nl-!I7- Ovr]1,C Vݍ𖙾uݚ`&"k<~v;W3XΡEzЧ6X 3in[M/]IыJ(  4@q(YL^ZT@- ]쌔̜"<癓y/( I'w#)Ȗ^GſQ^jfIRCqT34Qǐ]01 >8nkR_:rMިN=5v*S LuHm:=PAX#=^~Y osUU^2DMpW[9S_y'UW@mcMߎ//,laȏ:u+Sa=mG6%M . CP_̜8d9&sѼ- lfeP`v {\:ſq" U*/+kxꋘSEҟ b^+rXAzKlznW9v؝zzyg ICW{#>yVmos^z5{ ;hoP1[x嚆ͭX:N}0a|ZOmBf˭s[w"_76kX>v+[Hm5G I^ϼm6DNϱ mUAp s3Y<uzY_jDp@'霒\pki Vcsx8&Y4\ >uy9 Ć4Iwggb&^Lo/H6ʑP/Q7kwwQW{:dO'ylxKӋ <ϞxlQu6Pg 6:;lXsM\Lx(&6<ʺ_?Ⴤdau-gX$h,V_bL|a|,9e#7w!ڴeG6R{-UM@Vut  @'}~DO:LmBVK7B<^ dPW"3{֔&^polqjq F^1~P .p4Nף7QNߊ &dV ` )m1|iWQr)Co׽-ԝadi=-r1}:N;A>!nIz#n#g=yW={j]Uh=,+i&&C/{,pdm7*[` xFuh0sXŗl4V8PB'l[K kMvupEQ5LIh䶆C -妘DM,E2XzhD`kI9fvN^s&iY%Y'`ӸdnLcy=$[Kr"b޴h{% "t'8+sJe)a]iK,VvcAfB.Va%jNx586Γ;uw9`XAbT|t0e̳7/m5tKًyPLL@n=gIUŏ޾}S4C8D0ʊ'g.#`Y# wM{%e&].DN*<+'Wu-;@Q8,)ikj{>y/5lA )bzeތ@7II8D-[OX_qHMJݖ ğJ6m m,D/>&J7u1fR `M M1ڲ"e Ph\v$4ݷ(6 lIM2oAQ (B%;%6VDWqsٞ6[iz( )>:@ &9a=EC͌ԲKj D` ""eh%y+TQ u:NdƟ~Fohti"rohC$roE,#o }hIzU@Cm۱?Ir r㪨cE*|TOBT=Τ0c7OKǖ;?6\ip"eءBrEDXǘĊ4?GJ lf9Tƈd1j5H&ƎA>x;,jp(FWI pEKrz2dM|aX:3V'u;K=0`݂iV}ΙڦNBi/!A̩b"кVb'X?k}t $%]8Vk]٘b,1#4h?dҝ\m-6vڣ2 6L-ir±c!zt`]Z"/pIƑkׁR+_jX]St3˱V}=vTFK4삼O 7`>wFh T#INu< 9(0*EӧZqDvϓtʷGD?AG/-|h#koϛF ^tWk\Ʊj =S!iD<ӊƾÈDF;ԨҦ+N&E@(M<\sJ?5BfCk.״LQޙ$LSĸX+YCܿJbutj@aj"U vZs1P?ˤ6 \8}Eq~] Wy51 >5Fmc&q:eڥd!|Uջ1^*"fUurys@"[ɅnğNbvYA5;\b;Nujvog2 -BsPZ #lp)v(b{L/רtѰ?qy_I06Lmr{\d%i~Í=G~Ք{|( n[$Oqz8c7-䵶X ]Bno Ln@rRg'T@o{]9sºG n Hv  +[Ul!&τE渘~9[+&sRzUs~˙ y=GP5(5xdq#ѕ˹ށ6'L[8b: ӣmCc>lK$[[Wo ~͸!{ ]0 Sމ:Ǚ𧥩\{d`CI<%@Zkk$rby0d@cyhͫUK-FAG{@,k)Z KZؑcCӀ 5>4 b- Ft̖eK*CK }8)zfx֪salE@mZQA~6֦w+X23K¥*4rxJTzs#A4v" 퍎G2eWjx]ja|n|x^ $}$>,yyƾy"bWQD-*d0_iƠ\cp×<Ӳn>F\[vCU_nŊ]4(6í#wO9=`"BcDJ].tֹUB+(+dQEv:tݘ 8'Xxxэ=Kh3܉6 gIq̄ <x K#—M(+7{I=`*4ZH|umTiL?Dn|$חoO&̒p̼j x-& pdž|N xkAIc?$ߟZAbD-Bp0\7Z5UӫcVLj.} *@yv32_ۊAFR!\- >0sJ߈HA7{n &(_G$˨2HɤNh‘HZ';#?V4Wolp !;?e3LNi\PK@6Z8C2vBꬄ͈3䰲[⎞ |B!2fClG9Ԫ_ƶAQ zO[NԫRPܐ[ߴ}x Ck9>2=] S@BdFUf@Cnӈ 8%< zv0PV|Ԍc%i@B܀SHH>?ϐ*VРKVDWֹ&/b+L GB&VKf*JIpL+LawZ'XWY7pVy®,^fi񗋫nOD̩_eKUU R?tjNáO~NY¸Ȝd7WĿ14&~"DQY vYb|/\^`J]ޯcq`Tj*gեbdn>*lX eSEp0œֈT׶fБt!d2Ip3_I-3œ6~s#D*x&:f^=X&DXJVt&גnyٛryOn2e%߸zMycŲQͽ$Ӌ*`9칁Τn@pNq{93luFHFuB#b`L4ݳt%"bK맊u4[*8p-MIDU6G6b&צ7j&-X+8f1,TYx11jN&ȴfr׮|r3@`x 1TJB=.T>Y^>k~kN"*]2j@XFDR2 ,^Q/Ye n~)(u&%^X7 .wHfd؞gbtuX?tAP?=CU@ڇ<o\G>ʵ+ !  c8E(/Oh$4Y:}h!L k"\bE*`}fSY1ÁQH3,HKNOFﺖPYFjˣr0ոeb?°,u\ ( )"8kVIxs2i+%WtW5E`8+҂oaH](80.gp[ݏk+"DH'1#;s*} ɱ:anf{]iAEysZLxQ]h΋^B<\9@-femj9Ւ\[૘*A^+y/QR #vd-RL**,W#=nsdcFQgD{7C+-tγ/!S*;\9G0Bxϖ!|V>N-*+8K: dCbNx .j&b 5Y>D rDUZpe2W}"9#~;HU^ۉmzHr7e ~:t$^P G_\9upaQ-m7M^K;TG30̝‡Y/X4 3TssF`q 䪢oCx@cN)1 kp:mpEzw̐xf DLosygf<IDH*YEabI^Z';ahھ%uh ay1Le #EҊf.ojMaiXD;V+ Ol>G' UɸYѧJk!/*Tp i^섭7wkqǧ% 6v#kPJͬF<\/UƠW#$"3@.j=<Wo"klū5F*-uߜnzD pg@85ݮo3,ƞlQoyp`fF.mS5s4[huT5^!u1Gמ&KU }K\FXPbQZ6Yg LD7k;``HRJcNV|Y:j@nWjoԣ jxS[:-g(:j:яhyw 1TwCq,}{NƧ.NerzZ+jF*WwfG`$:7 gRE' qG.ijXbf s;̟^Qpp& tZ׈:roN;;F/ h9IV,ւō~k=}6&+5Tr / z*)e [iNQ&g_J4y7O!0y16aT5C? eqRO7qd)hUnϸ |„_y /}#' `[L3ӕ?CJJˈDe!O5.#~;bI4[7 <&1 &T2NMq3#FUEٳY J@?PmFy'YHHWJlViN/,*P*uz> A, GC8zben,J <),2JHA;};$q-_r;w%rY|?ױ5 3QN6yBL' \B3`y2weO]Ş6#U ȭ~Zs7_"+ 7-#+HVYhV$`&,#%"kSCss.1m*RQB{Eӎj&мkQRFqw} ֣S$Eu*M-!x2;c`[ƥAة',@T] n0q `b8@CCo= % $1FXSVTʚb^2 =Ϛ( za7 Wٻ`iY c28MWЯ=^Ix̏%lvdڎ[8OԙOh҄v=cQr>63rZ%}͏H]ΕS@sC:(vzՍc2k/Q^~vk#pK r`;cvǑMQ7 [!(JE@jd@-|Mh0c ~q7X6+AÇGFyn 9I~u`EFC-Z$?>iÕc:ډ1 L[g:*'k{Y r0/$U}TT!:NKExaݟ3E3DSnkĬڬ"y$@MH!_:27*_AFx-Wgɠz5Tl=?vaKȜ5vr*/EFI1rlQ4 H'Z[u 8>b%DC 4YK]8~p(֩?~h]6n@b%H; ©M=LW,c3 Q ΀Ԧ\6|~kj?{-O*nBm_/ϫ%G\ivʞVC)쯔/E|CsסHe6oESe\LԱ1SW]ғIŽ%%3(UsFеZKw#>yIU*~5Ӊ}weAa±D Bĩy,$ԕ H^-AJQ!+~2i)[Z-޾?Ġ/:?:_Ҥrca9ꁙxVeSQRb`oF/X<ܪaڝ5xIPlkOֿA)30oR ZwH(p1q:%\4k-Z9 SyCIJ{! @?0K(ӖԇAlp3Tuuu7^>u)JrE?y w:⦒{TrkScqN@L&E j'xҕ7z$66W-Y9`ԛ7&ƽ]'=a2s_@s?h Np`JR>brzڄ~6RHEHs6t_ fEw%<2S(؉ [kC1:/+1}zow>z$A旮=c ga8S) SpPԔ)%>:s·"% Ll)MN-UE]!8Ze{;T[u`4Ԡl-@ 1v/Dn],!͟pHI$^>V1ǯ=Üu%b YhLO`%&$p1 KAύa;<"([WJgw J_f.>&P0n]F4䫕m19y~> &^*aTvE$y^0>c{@#ofW$+TElTܑn|KYAGNY |[ZkR[BB+HϘm,{.\B|"_fA Ś (MbC6W$04[/(?@ѝ'p/ᗥɑ#/j;䟂sKYzlv.61p'\{Q.e)ZsH9*?w6TssF7+B3@%&J`> O<2ja^$[5=-RORI!}8$q ,< tIR=;DMڃ3U毶ɂH+cAZ2?:U>7cFD.`7}v#dZ4v(G8l$1Jh:g>_vT= Uw꫸ć6ÒRx:(ة%p&Dt9* ^ jn<ͭ"J uX>vk&r4ؓ^~< ٱ񂸮2=ĝb587 wgo_lމCFu*Y1HF}G[G06ߥqu*"<^/% fk/7*UU :Aq+J+L2!3_ѝ얁\ӔiƥV!y Pz3Jve>u9 *$AM ra]Y!T ~#G2δb`s`1lAoR2xӟw$ .[V\IuFB`u[qw `QFك3_[CRnV3h<eߪP'9 WȻ;OਝcGI/"D 77k>o4Z[ 3olgT J[˂#iZZ'L #Sƴ{6qf63;}kJ_C]*z&|[W9Eɖ~O޾dKl ȏt gǾ&)IHC.`Š@H{p 9H~WuȞfw#5.xpvM95_p0Il>]1):Bм. ] Z31`av× m2W:\qe+h,7 oߩVx-qDGsԶx^඿Є8ͪUufj;1vdQgPt/Ww׼YU  j#@{HGJaϫrO ٮ Uz.AviJrA7"~_*La.ȺzژXma&۝J،z*tkݺcxD>Ⰺ&7ٵ&v9d"i1G^,521!v}f N4j #;Mg[9r1 Lڑ6H ;Ms>ac>o¶+dʹMcOżqh#Cz͇SSS|5uǠ,#mxg=rhyzݓ36u*WC>)I$Xvq/o'N#M.HBM}?L@Vnp'QF`!<.FC0MgcqioϠoL)nsD<'8O*5 ؞Xn9Dd>?G,Iϴ"F틟A!⑙MI?o<^.yq*}WFk;ۘooeM'rùګ*ĻzE| ƀj-35dn8՝!>^[T|$x 'DgZG^_&dCtFa7J < \XŒE+cF[CH#WpJ ͨi Xs@5)c[>ĝ @t"ܮ:e\ D %u;l69N>%xJw@߭a(pX$\\xZ8r6ŀ :l 4`ԖaBY8wSpDoMD퀄,-JY琖ɗZnUx W[.*9SBKt.}  y2<WyO/ƟJJ}}Kv ONaϠ(x휕.]vZ}POyN˻rb9Yf>бą@ b*IchB( +Yp6.=2z*)2m/14&N,4/q6~"]f_7߆CB( „^V wB,{T?)П?.hZ+c bJ_Fd [5o(2" Q_[('Q?Zӣc+0_6g5NaJp O7c[cwP`9tRv#ڙА$Z_/NJ?N$AYQ^-!>GhrVI|}$^`ie$oFZ$&u=Z6 եsh%hۮ:(9)I.2D5 |ʫ 'M|`|s[?wQ/9U$K0_PdhSY90eDf"myI5o \Je;[eY`So.Ia7jDUѶsD-<LDŽKMˆ|cC8IH.579"=e:˧k8iHsĖ=>׍/pk$%F'@S{/y㳟kw0T%]OYv} zphC 6I=sK٠[Tډȫ9LnkO49X<}wS+A2cxKN.M]jASAɠL$[hsAre;,iLHIVe\XDlW/6n26B%a7,Voe4WBd'fj¿[B{n9QB"ƻ |S2ȄV}Zd`F_l{+ry{GXZPr?H& 59^uyQMnFh'Y"b_p{T_2tBؔlg\gȂ^:qV|F)k݋LKANP1PC{f2$K>+`gfA`េ;1˅(0kS~a8% tDwpwG&"irラ?'(&";"Z2G/f~` 23Tp7ɇ,=ٝ iřRajzS)L[@jD|bOK,fde&QBV+)`tlsXDhtAP<.Va1Tnoc?zȱA ~R6s_@>A/Wb{ X. *o6V N-XK?⪒NIo(h(y]}1 5?{+Șel<-jɨiO"/u7DȧxVE)M` 'q< ITy'=BXMJ?$cZut`",#F`Š(s$1KVKNy4urAgN[N,ɠ/tu Kͽ[Q-(sZZdXQ}ƚ'SV(CsE0cwbb tɥ K<@ڍ`?auVzr2[l/Wk%2/[KԾmTX R-1# -ihvO#շO)m;erYuA9y+JwXɫnczDn_p QOQfO<Y6Q7>+Pl~Vs 7Fb _J,:Z=45QsI?0/WUƏ;U_>S僨-?oyksv1^KMAkt24~1!^+~r7h>c>S0ѸL sV8+q*S=d.ZpK<>@| (5 edS1[3)<`H ˲oKJjPtaݓeTJKj^~.1Qriޠ1#׬|~O wd۷= }2K)ر8Co!@1#fP0}+?\N GOHyV\ 6(z.Ձ E>g+~BsJМy~O.N*mefv`/7.@ {2C=6l8Rn8MLt33;/sxJ(gU(`3x\kyA7ħobi7~O5ʆ؋vUSl=$ruHe pi$X\ QzZ0b w.8_[IRFZ<#w0Mdc3+Rߴ뽿p2ɵሚ8}' n szwUH~EurL%Eq6X8@G^UL%'֜AV(3pȔP6ڰ$vC,؏ =M 0}v =)0Nb >,o3+UE aGb<9kej~Ic2U i# (o֔BuHu/x[DC[ҡlHAn'ټ$V2*7Ƈ 6EDtgusI MagȻ[ /HXIpʩj3 ҕ+7\sZѣ~}ȅgy c0H58y*hHhZp8deSTZ:=~;9vqNdaMV K_kKR,~YGH {>A9(B`2wE>*fyl 5ZA_ KZM5&)?\x! ]$T(ǣԳ(mXʈuph9fEH9}}#[9vV*pZrD[ETSDfn\O ]H`IҤv˿ @IdVBe'$?P jDmºe>jUqEXK~=GM֧k'{"y nR׋G(.C%f<,>^^ eJ v؁ߤ 0SP02,)W&aۗ Y#AhUיN S1J{6:/ʩ sAWCl/[V斎 Hkd40%F)uyf)Hd-o4q Z?9H]&Vg+BaU 8V;qJr< [鼉7yQ&)8R /<O1QhvBnw:=w_ڀ :>]x WuG/bLv6 ;݂yf:1!?lbf|sR]n-1Q(]͍[u|-9+ުyWPqJ72k?^ ;Tg- 6É GB!|*5 Acd:ܯ9 a[-;A TK{((J h#kDRdF-^lTgFq@V%S3ϫvy 5#21 ȅJޅmDxs*JHjmͤ6jf M6Vgd] #}VLY'i@ES;tMpLli+2;-!aij٥ˑ_ St*"[2Wn= iu9/sN[0B4@ze% U& (jA*[29,݉/ a6RuIYU'X &eH~]Wq]~ Ē_49!3,fzpƅEe׏˳07RPm r37^Pj4yovHc^]k֔ DžGSjњ ?| .`bϷ{]9cxkO1ȇФq=tmLFerX {Aney}g1Sõz…hWJ5d/ӪՁ v[AVb<ѯ?)AZ`{ X1My>մ#@=)94/ڂ6%L ?Νъ%&DU굪yޜ {fI; 4!]cVg3e)˫?.[:pb<+4o ۣaJb--.(|vz)JLLaB)%| 5ӌpo}ְ-&k?~@X7s\ƀcd<%[piJ]jFZ-'YHca2;h~>j+ۋ78(R@)rSZ_o,*Ho"S[w[L0:4M{4C×W+1.9)ٱ@r& 5؈z ΘW[ez/jz[2Xl쮯Q{e xrZ+aQ=jGSe\nF)fIp*=$Rf'X\Awky;χ(,Yѥ:oZ,F 1o@aAA$"zGӀSn%Eᐣh5;-QČ#FǎTnBcTD>mt<}ޖ ,t(;\B~lo'np5#u%W_f(J- `6-- g?SY9 /4l01T1.& {XK1awb]>iDEm&[(z$>mttcݵ4%Uv! 4e;FCx91PU_+Jm N&ObЉ}m@;f({Q]TYe fI2Yn.34!C•#H m heLp锠 -dkvgVkr k+QG}OB"aִr TZQ\y눺±O )lJR&| o}rVN1a I V).kVYC[QHy6 QNl|=E_܍sgvíe4q%Գ^[r ru%ٟFnh3 ?R[iۣ XϕWR1;檎EuQiэCh}KOT d )AyGrV>{cSS O~eڥq/^fp-1v4F &&d&ӇSt, @V˨ a8tGP^[ӝk  hsÿSBT:aVOb(.'}%C\bʤ ʉڬw_ĕcS~"3Cv0UJPx5xRT1:?ol9E]vp9GMxtA}K+D1+7mg(uL otWs NC/B#G ,pbSnpԌ<G ^rObʵ\(Q( h̏~6\ueVU!ht#^=n] ?$+ҊA(hڍQ2f&hxE.M,ƺdӻ@1!şAa/'{V99&PGy/D C:}xLzE'LYXR֮Ճx#|;%ىA(=xB)KB9 0Y^kks`vamk(=Z˼XmϷrq ^2>H}&pFu Yg͜| ݙ%8Im}GAUo͆[L)W*AR:`TJ5:s+58&t}}T!5fٿYG_h~d$s`e=vkgNA9zbl# q8# }s [SQ`K)H1T4Bb ˘`(_ El2&ZO ɀ? +`o\|A}K,&&_'vfD-k%)❩0Gd6qUYlf`s>;s2ͨۼ@\( EAs<"4.$l釼eʓ`?QzL}D;X5ZIkd RN;RgAs\e!}4ԲF4.}6h<;^W+9TXx"g"9AYh#VQՀ=ʼnf%6aiMq*c #RI7ꥯCǴYkxxy+)-}`$vkyD}k O#N]sr0bb0ysW)0M?,d0a ;){x#L[H;>J&)u-OIR;S>Zx%B>0EO$x{ÏBH9l="%ӑ~RtTUmDwrm3Bݯrk=WVN>1(ǜ+?`}B)7 OIm.ݷ'o! )&!Shyó2C.ȼ~ z"óvosI~6=a^+:UXG"v74n t H w K|i#(JWƔߜ>%u+]i2]+,3饯dV$I*3*tLy&wIjހTu@-GMS L>{ES95exbZ<ktGN"(kHLUMG+IB&/#E}utU϶T ~v~e<,t E,9EBsV*,ܠ~i@`чZ5QߎOydA<ՅyL&1Px-jK] -G?gleԋEe182$ cq~ճC&V7VzNc)ĻlE\m%%hoگw/;y" ~,Xuzښ,T\)Kp`ʓ =Iz:K4kk)h'j*O~ ZN?eI6Ubf.az_pQ" PIu9&j)4+v24UEcVnYz׍$l4\&F)V IOB<ǰ$ S.Xtqhc4Y}su[ d MRї]y8iP$n9O^YisV\^ ׻ʕRȆ1〺W1C.aT99w7.vJ/S7Cr_tjC0! ]8gAa J+u}?nI<6%ߌ)kn1~L!9[ac~4H>64m5R Vjv ź+Qr@̂]H,1 2H!p`b%'p`Ag>YSg;ҫnLRz,\؛ʊKDO_faП2xZL-Tq$tdYt`mWsΈS\AZ I=Jp/XN̵)5\lyHQ?9:+&OHD (Mcrm~(}7'cR֠e_jj74?tU"E$-23!ʬN5 Zqs^3"Z{Jx4u\;Zx.)@!F@ ܯ[bF!Q h(F1UOV|OVZ 2{,D!}S,~c$7SYSK15 /y|*ve{m2B| WGb-,5lE,S _OmuC}BG!+MI %zVVf  ..M#w8؉vYIzgdfctlL HT@Ȥ+>O}Bxcvѽ<}m<0Uq@yMbԠ58ؤɝ# rϠXY.-mwj9c[h (M"vxxMtR\kTcrM襮og:WS#s>0*m!LLOgLG+>ag(Q\3vDnqF6E ybǛ1xC؋o{y;`Ggã|^^~LjrYNިл;/ypGyZӮ]g(_& +OIKgjk=:Tвfjn{ғ(Ci~Jտy>'qlꪧԊ"M"f([S~Q9N,^spmۺڬSvȲޑ*N<a';;뜃ھ̿pVWnТ5ƇA~[]Jɛһ 9r:!jwro~uZ=pS#5L&پ= BT6c`2xZX*bd,lx:ܛJw_*zo/bHab_u~ٸ"8oIe߳CRE|4,N21KNf=hHJ2Cg=K"NokT>qܓ6fڕw]rEllR*F*2K4-pGJ>wimmO"qM b5Evf?2.ۇp K ylqHFn4g2ʌ є5ng3(:LĒ؟;O5ZtO sn I8cr'U##huUO^J`Oj0#2%GL(.\ifp[N«ƺޫ&98>D'skH J:~b*Q4dcqk:m- 7_Dң% a &`?Q;_Cb^MClRbB1ё+1oI߅HUȆ <|d.e815MXXn~`,G|v씩6w퐖yFe9 C;[F_;rE+=JGdHQrRVs%˭#|!rZCPŐ֍^Q7nIħWS=~@镙f< {y9[f#oH\ d 1G[o~MHb( `",OGmcק2|[xs^y IKAXX/A_}KH+e D+[y;.-;V*Q;]9!BVi`l1JLqmYG@Q;W&ŸziUoݪGBuhtM+>L _d4-{)}H٦s* ʻ} f|wr#hFg7wDNv3Oy밁߾n=:ےV- />P̤lwr 5:/j"l5%X̐<֊?JFzNfWvB+':e\>xZze|KZ5'0W11[O49P'Ts-pr)WxlE``xUR! x3-F w8PSP+p@Tۤ3&% 0Y[-d`X{X4nUOuOQ\Ov,81o9 k ,ϓ Zfr ᒋ)3]ereV_<„m,cG#~S)6 Ƿ2ᓂ!+@n"uo(En$qxR* F3ϖSGQb?@f:\oĚDH}o=1F!9"HmRl$8\?_̉)diԉkLnMJt,#r^OǺCܐm E" >n|Jvˏ,l`sKhl3[\ܨ($2>smLJeŝ67j`'datIޫFX9ƇoQޛnC|aDϣ60t91,HGa; "#|7¨UgO[2Y* xl&O~ߊ|岶cjts2UXq_,\Iq?tR`>dn$ HNg7+PO O$1tseWXzًYNMABB%:K8b :$OrĮfL-y VCPX {bAǸOց~ScxϤ5%1)$3{[m-Js 1~ѣY:{q<-eO),`&~t'UL| Ig EYB8$O1^VD9$4/WhO/ٰ!Eσ_:v+{xPxt`G㴪1sYlEQr3g[2rC%T5N4؝IFw _.6Iܡ@EOnN`Vw$  l29J2 ʼp*m1)2q?fXMz7@o}%}wZs1txs7~c-G_ۦϗbțDnl$ CX^ 8i:?]~:H_ Dso4梪Rg"~֢<bl`9J ݙG_fʧdŠ AnkU8t%;4:[ZR $ * X0;pP=QU0PDKY-8 \am73402O5`J=E9ģ@*dPZun=e7mtr~_G5Q?܎+A˫c#0Z[ɹފĸnE;bXL9FBUM HWJBvA5N}TGNM(D$Nkw_pvrre-$3k@H7)^+*5~=ƃK4'o&1R¥'WqX̞z;72X& 0J݅<\n "_/>nhD?x|ڣ#E0;Js$ŗZ}F- "`ʠgN8Ȕv5=ʆS<)z-:yWN}6Je6Dŵ'ǻAրXk?I0)oI_;m}}l)TR#`\TDqEbePR%k=4gVY֐m0WeX Pb@,q[@"G~ol}g8aZzqSnsٻZ]If2FmD~/$yBDv$>?C˞v=`m]FkK|‘,J&>_Vyde K?__,6 5l$xp͛Jxk;P/-Zxi(J'\NZ^wNX%XJ|Z#ɞ{_XS6*< 񎧾P{z'+Ʃ7Kݞ*s 9!RtczF1pJn&D/t㻟Ӛ6Xj򬸌Pjp/8h"~oo0nF?&2E_08g:L'Ђ?.F'!N yNRxO 2ViץeYn~J¤K$,Ah /'jµMH ҏXFh]7+`Yx;5\A܄,#5-*=eWP=#T+Lj%9j | \zyM~RdE3 EF qlij d*2(B}X9^%F1 06Z4.w{=(ֽѤ{Br.+$EQRJ9|Yhn{nn 97/i1A‡C0 D;I0H.@8*XG2P*i 'CbyQzM{(ݙ1;2mXx&OPܯ)Ї7qdvI2ָy4!+|xi>\Rng-??|x{]3z;*y~l^}>o0NktynY6,g`B~VD8 Lq>zE4hտrx DFŸ}i@dr:%0#mYטZlˮLe).L`v@<&"<*cqqQpp6vI}ZtnlS'*رOx+ v 7Hioy7:&}>¶Dnou820B^!DDoHVC9T;j?VpjC: 5<':P8*+(ή /;u؞}d i8/wj%nf 5bGy>cW|i,HCl5҇R}9ࠡ'tϹZk-Np= ,*^@9b/6-ZG!EePr c jĘ%ʃ/O:7 E[lJ)^r9yKsGU/Emve]֜(G%i(DQP oqlO4`9QuHċߩKUe)&x5`ѷmnrX_.fyKφ.;l-"S[hnk12A#=iM4|WW ҏ#)3+cyd~ v-R'!\Z *|$O$y=9HwpaVQ0!1Ξ8)EZnX{n-yaMt'bJinPlCu`*Nr0qZiv)h'S,衋 渋L.ZVU5Tnp/Æ'Hy034l5q@gmVBH$;}?T"%CE1Z,nd AgAMnmx;\S,qq toD ;5cRU~ L$zG!2`lG:phc ,#iruY-Z~!֗ZaA"QsA&i'dtT*n"wW4k)0C A4p^3fϚ.-'ےI[-LiJ,lɤUO^2~Swv`TQ24] 269"r]E2`3>^7yF1OVD:Pg._Ζ<ۤ%vԐ! P fVi4ކZ’ E*`|SBŽ-͠L˒(4Cz=x~#}wMɀ31q^,rrs:0S4ƺyGhP otf4 n~9jQ<2T`Mf,h7rvD7Wctn"=8X}oF2M..gM\3vMhLg$FT+~d J6MCD0cBJgTqJ  fXSf!g<ڜ";[x/{#ͻG1/D(()FvnZHv )Iq k8r aBdi0E ihRc [̥yHcY:ζFe1l{RG ? T p|.´e#ƽ/3Md!\?rYðWU J鲠*`64xk ΥD7 (z/J/l4L,'C\ Y=G>7xoHs ˳iۚLfy!@$%b-8sцߵ*KNjN6n aєg9:f &z &d[&fF]StUQKH^) x+-ڄx;9Ţ R%pӡV"Ed.f*YzlC-DXش3gkkX|beq9⫳BX5kaauа[J| Te}1? dxFVbWpO  /ꈤ %Җ>sjw{S9xPbjw}\V2Z~Xi,OnJ  HlN'Ɵ8W? Ņ­rȲ$zzn@_Tpsӑ!}dFTCQĴܛo_-;a;~ 5=S1 ͆zHlB:a:| oRI?9co'$<`@YT}|{p] w(@äAB-Fmq!o@ۥvwDnt|S Eda3]e¼_!c+ Yȣ74W7Ida+ʍpya "Z$]Gv[;Kz` /k -r%̃@J 6/8uKhfnCFLS9MVjuӒY퀒ޠpgl.$vWknEP0Ciu8,swgЎRK7dc6<5giaCXQA zxfCZ1]i[4{BbbΖ(#FՇ Ŕt˗97dJ󠋙^k/4yx&~zaO؈Pj 0>+DŽyDIM$tl!xopә\1GP:s% ;#va @\;c ^~*n8cY{6Uo{bm|M(cT,[DoNU0crXD6\[qDa^"+EY!OQ٘f_NLӐp@#nؾ8[U i!sm ,!]PT9D`5vAe-qQ '-ƹZ_iؑ!fWJcEsW (:\5W\zmG{}_&*lcF I7&!"2X[?-EE <1RP}nD\w^-  q̛TD xDbt>>c׊<,uBFt'yxq j\&Doԛ_j McvH@W"ԞWY>dN,P:NN_nN YBX1B.8Ϟ`1gKs5\O#&E_%,j}:[!MA @>DZ(ݢT*r{Ėi C7o5:/d) e`RgǼ@[SD ]K˻*}1 {oחm'"Pܕ_ 1ю. uS6jZԩӝAl"hv0_ӫqOOm$2)cG3wkhz|ȓi^lm\T&V-$$]C/kس>peTJo*aKR|8yAj5n hy6+2 =X'-Rɭh} `d$lؿ&.ָ#džcȘZ]oXǦ,TC{/plSE@\2a[rS+lDRS81Zߏ= ^Y)rJZDf>3/+TO6+ *[$LO<-qˉEz)V,&X/44mĶ~n%vkoa^p'qoMtvt, 7-%3gNV0bt'y$} \j`$хboWEࢮpxD[$cS(~H÷ظnslh?Tzscef)8:c|ˈ6*%^(nbC4-R/}@(٨d}¢0v |iwsrL?3BHeaWgu 1=.*zvA5 Ҫ"h<f;[Mq׳+x^?Tbonʗ! L\h4QajT;XRE;܁uat_ٲb:h/v(!0ԗLXID$> MU5ZrL÷F)K#QWt]UZ6#¨H1mA81Hޖ816jM[р8 "&F,9N?ѥ F&ɩ,G tJUΚ]1I$2Z-ϝ|HVئϻSȍu-P\uBPШRkOCpc9A 3Wi&E`Xwc$kLo!eh:HO˺۸B=J;XPQ*?=ݾ ߶t_N ]`o$llULRTcMдg忧ΡjלrZ fuC9n~w@mqB-LX1xeEq2! fIoXƺ5s35B{GXLyrLcP8k";Hwm^׊ĔAT'>Va=mOh?C,s dJaNGa sHD8c+ZGe#ȔH}..*aʬc-"u1 2]3IHt y7 k`K#X h-tq/ MI/qR3-D;y<6j>O{mMɁBz703Ûе@Vb^n FB%)inK|~ 3׵skgt[u |]>TԒdA)z8*š4cAؔ ][n@G0#yx=SK㬤љT.o ω`Fi+?EJQwҦ|LnP8 24kr q4hj0/IJ.m$J:YA%!yc}3%Yb&(i-Dr$ KAyH]43ͮM[m1-`ßY၂LR/[tdmO>$RuSKkb&81M{AT]H}%gh-oTe풡/g~]p{+`]$] t~$=^v+JN̫~Yٶij^Y#æ<rp,S#5@Q @A (|qigfbev¤ 7ۏEJ_J8_qh+DN*W3)+cDvmg:ivaG# N`3cKK o/)lJki\ںI/{ZP))hUk/ȦyEXm(/L<.*[⥻6_lwhZ:;+?V)=gY|e']7/\ zhD +: YZ